From fee9d7fb66e1036c2295142d8a45e17e6404f568 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 12:09:45 -0700 Subject: [PATCH 001/737] minor release --- windows/deployment/images/download.png | Bin 0 -> 4561 bytes windows/deployment/upgrade/setupdiag.md | 15 ++++++++++++--- 2 files changed, 12 insertions(+), 3 deletions(-) create mode 100644 windows/deployment/images/download.png diff --git a/windows/deployment/images/download.png b/windows/deployment/images/download.png new file mode 100644 index 0000000000000000000000000000000000000000..df12d22f7ad2540eb9cfc16370cef346d7891cf5 GIT binary patch literal 4561 zcmV;?5iahDP)Px#1ZP1_K>z@;j|==^1poj532;bRa{vGi!~g&e!~vBn4jTXf5oSq5K~#8N?OO?W z6-5%R+zGi85+H=!37{wjMLZBh!BrQZd5MAnJl5h~TOS z2p)K>h+J}q1VRYmOhWGa*#GaDc?^%2kZ3UZ-1$F;m)FzNU0qdwRdvtP$?NIlnv#kt z5ho|HV8O!ghqL}^!GeWGf<-C|78)51CskFAc3H4s!66z(Dv&8A#9g9sS;Vqn!7&;} zs*)=C{O)l1=Kctg;wrt-f&~j^G>lY8PNkJK>at+Lf@3s%PX#{J@E;2nEI35NNoB!; zg*su8sv$5=K5NcnrmoiK;OCzm)Z_WoWfP(Kkc!GJtvd56uNJAm)f^NLNB8q~5r16H z&Q9k?CJ@Qf-C51S&svGacIt+QMZ8LIQBTbQl*??xGTnyuYoY!qdpSOvi|mbrhW$*b zpi;Jsj}tF`1HY&QiD+HUXhJwe^yFFY}kB+w(z01gyq#X81?S)C7qOcGnwDqYAQ*`t-QW z`8rDr6d+j5tWN6Q&?QG?(Z<}S4VsOJ=CcYDr)PYZEsw7}AuD#lae1Crct;Mw!MEgWvfK!FF>W<8Qt$P~&1uemBN6!5C73QJ?+T zpXH3XT;-=xrWNY<4fzcivhsP%Yut7)t-3$;=1?1ljX8wbhJF)JqTQa`FWq9oRq`R4?&$Oo#<`+TYcyFXft$VT2q1k{PzcoWyJDh zGUw-9$;UV@D4A#9)>;N!8K{+fAeQs^y%IG&RTiO-%9x}#6w=by|t_w6(zF}3#R>0|cM72KxUrYPs{`cafo(Uj%v*Cp9$a)-{3j%%46IP? zO9o>;k^nlGep9GCdR36bw((Rlw+nKYq?=pGrw>NSvJsJTHwkDEix>3T2X{ToqbRl-6;S1U{AGf zTb}g4B2Yet)7oS5x|8w@qV%P3fK4DvIU;*GoZZJmi(xJk_ewR1#bv+LQ9QW$&`}5{ zV!tIQ%?8c4EC1k(&wzkQ*R@n%nGHsMa!hs~K$c<_=kVy0I;p+H2D?cPoG?h=ll4L= z`5o3)^?V2Q-3+IDw#od5qvgJ?{_+#{Hdnp8UpZ*b%nKzDL>+^w;gw}arRJT^s{iK9 zQn?g+Ap=~S$K$&dv9?T%mqh6K&7V%ms1J{5r5*^{yOW=+1sMoel&Mu&Wl}TuV)gx| zcQR!4hEtL`qoaiRxk(nXR7-u`Gr!M~v6!0}-6up|?Hj88Cd@A9Jt@6K zWLq&bT=n^ujt2CKL6kvO~lWFEX2P6SNt9U{IcS$TkP9h})?%x>|0Y?u515)fm%2P@*g(yz55 zR2g&^hK$_q#Z>V$$#NDzwn=dCZAUeIT!XB&YjljPe=J6v=u99{Qr}jJP^*&*CHRq@ z685~7>6aoaS0gBeJd0qcV;G#3`V(YlLpQ~ywUXcjgMt}>UM}K0d7pH7BTapG$J~RN zRqXU+1G31b!w8Z(I<-PDG`UJ8lQZl*d0jRLw^u^O?2*n0ti+gW^vnsp7=+^XzzzN0 z0uc=~lO(0!m{cHC?~cB*{fQW5D6_;~SR8%I2Hu17{DL~Y@5O!^8Gj2{wm1UXV}rG* zbp)A`1Q~#hJn`H&Ig*CRT98vNxXl*?ce54yo zB4FWGw3$xKCalIdnCG=0P8&?%MCL_TK&A_$Q4;BR@`Fq%MKu2Kt1Lxy;+76Rk_KYC z!r_(;kB|e?+Dq4PZO#agngQsqlogovO|~3G^goR3%+j}3Frs0+L}cIoD63Mk%T+Vi zc<8A(mDLA#_E&8*%Z$6iWn{Mi^*zKJYe107Vg;b%Ku(3E9RWc}NFDY0waf#{k4hm3 zx^+i^%36fVT(#K{x{C@teXz0@`?|9{4ojzcz=Xk28W3Wg5pdBtT*@w zN=gIDHuOzB^9}EcCy?8&~w z9;Q#6w=CG4Co7RXY=EN~W1Qe221{LxaYn$h2X9h2SpJGld6Ix^@q(UFnPH`khppVZ z66+pzS%5r(eJ9IiMRwjZiLI8UuiaRpG9NE=H`?rR)FiLbr^ZfjH4gt_mV=#=uGjax zKpCnETipim_?_iz>9g%+3bK59Zl#R*LbH_uZio4q1g8!-KR%ix9FqzTJ`cuv0t>tK z0w0+>1SJ)Tg+(Zbr#`4eWT@A$xgCfMm9#cXUSEqS-w4N|z9@6tyqu+7h`ancA>O9{ zajT$cWR1<4W$OEoL}V-y51a5Ii5hWKX#`Rf9xqe1er&M2+||Vo&y+|p-{Sx`B2#s0 z@i+JX#q ztZW0uNM^(aZpVI6xF5iO13PP3*db5`y>Lq_iN-ui&-ickK5b132rR$qrQrgQF8HAx z68PvYi5kCGJbB#CC7GN#G7v=6OT1J10m%g@TU8rupor=KgD4{d8t(Hw6S0v2&lH?k z64F-w2pltqww3-DYFT;YieuV=ib=gC2t@Z>u4UA9sYTKcrSxKCEgR5%$8k+pMB7*d z#8VYANYBE}4UQQ=#kX*lmsg)q8^sY2elqHR5{q0?K?#mLj;A+Q2dUb2+GkJ}BcaJ? z4T8zv)}vf1o7O>HkZrb4N{|f`J6k5cL@l z4m=Sn=@a5)I|9!75fSQ^A}Abv;+I+(%)Q7e+@FIgV$U-P@gNAJ`b+!QBy*u0(HS^?$>jxsbsI=sOLz&tu>L(w~f#_2c7YF#@`Q z-|BYf1CC6mfl?yUj78o09!eKR-P^7YRwrzykfCns5iBo(RLgee%flbQkr|&i@z z9Y<-Ai>S%#N9>p0`stJeOihtRJW$|?5G;@hr{D=;2FjX?T6-wc9D_r3d+VU2a6?R@ zz-hUM;{K-^QGjxi^dEpohO@6=8_P#H0)NTDOv3C&dH9U2q@knO_rd1==DCN|DHp$A z4`*=3`WO6?D?Mi&M2+e$eUP14+Fab)Q@kP5lyzBZT$L5zSSz>WNfJoFJ|y~Asm1c@ z4>?NaY*q%kgW3RD-`+Nt7`wkIUuI zIZr9murF)<9Om{w2M|`-4|AU^s#LzR7r|#Sbbjr;Lo#qK^um&teqz!mfA;kyeC*o; z8nK5a`pcljM{IV|j$n-b^#MFkekx8Lg#iMbES zqOpONa8RD;bme;_IM`VZ&`{8U^=PHQ;V2W!2u3zjX`w)cmsE=@HvQ~Y0cERx=JJz$ zba^#Gq9YxeV1K$HE#&78kTtaeO|X(xjrV_otYed?=6qrZ9vm!omdr5i(LHXHNSB`d0eGv3qfG3`fdTUSF- z*Zd&s*P~-(Gxly9QNkx8vyZ=4D=Wuh??03Kd6K^wKo2kH0F{nt(s5dZ;~ zer*v=MJR%b=lr}H%do!%oSRw5kqm~6b;)P+sV|KFwarNweQKMVZG7H5uklQ6W9o1< ze77Eb8-%*%2ibg)y~iRuE&WGZ8=<)8pNYM{{XVTJ(Xb!XBCY!%)qA_U$njH1!$vt_ z;m;40jJ?|XD4*YySt@ys_I&3PsFs{CA72#&csk2rl#aWxx31(VB+JLfB=_$`?W8i7 z4`!$`7dIR!lugZOaTXdG+=~(R8Sak)w;|l)(JwiDQ^|1-I8HSNp?Gm2=F4E3eLI`g z#eXdPDWMJH-CtZF_t>^zJXTids z6pl%S%oBh*^}#Cw)%%S4fWKUyzcEj;cnsZ4BZvhHe*|jZQ?aD0C!uU$TDAyf;r|@9 v*J&gNkIWl#S%k7+p`P!lELgBmPl)^vVh#pts|Zio00000NkvXXu0mjfU?ZM9 literal 0 HcmV?d00001 diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 70e120e841..1d903718ab 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -18,13 +18,19 @@ ms.localizationpriority: high >[!NOTE] >This is a 300 level topic (moderate advanced).
->See [Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md) for a full list of topics in this article. +>See [Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md) for a full list of topics in this article.
-[SetupDiag.exe](https://go.microsoft.com/fwlink/?linkid=870142) is a standalone diagnostic tool that can be used to obtain details about why a Windows 10 upgrade was unsuccessful. +[![Download SetupDiag](../images/download.png)](https://go.microsoft.com/fwlink/?linkid=870142) + +## About SetupDiag + +Current version of SetupDiag: 1.3.1.0 + +SetupDiag is a standalone diagnostic tool that can be used to obtain details about why a Windows 10 upgrade was unsuccessful. SetupDiag works by examining Windows Setup log files. It attempts to parse these log files to determine the root cause of a failure to update or upgrade the computer to Windows 10. SetupDiag can be run on the computer that failed to update, or you can export logs from the computer to another location and run SetupDiag in offline mode. -See the [Release notes](#release-notes) section at the bottom of this topic for information about updates to this tool. +See the [Release notes](#release-notes) section at the bottom of this topic for information about the latest updates to this tool. ## Requirements @@ -356,6 +362,9 @@ Each rule name and its associated unique rule identifier are listed with a descr ## Release notes +07/16/2018 - SetupDiag v1.3.1 is released with 44 rules, as a standalone tool available from the Download Center. + - This release fixes a problem that can occur when running SetupDiag in online mode on a computer that produces a setupmem.dmp file, but does not have debugger binaries installed. + 07/10/2018 - SetupDiag v1.30 is released with 44 rules, as a standalone tool available from the Download Center. - Bug fix for an over-matched plug-in rule. The rule will now correctly match only critical (setup failure) plug-in issues. - New feature: Ability to output logs in JSON and XML format. From 120449d99eb48b25d368ab7e55d46563b4e01325 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 13:35:49 -0700 Subject: [PATCH 002/737] minor release --- windows/deployment/images/download.png | Bin 4561 -> 5398 bytes windows/deployment/upgrade/setupdiag.md | 12 +++++++++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/windows/deployment/images/download.png b/windows/deployment/images/download.png index df12d22f7ad2540eb9cfc16370cef346d7891cf5..266a2a196beb87cd5126018bfd3dea1bcd998439 100644 GIT binary patch delta 5396 zcmV+v73=EJBbF*5iBL{Q4GJ0x0000DNk~Le0002F0000g2nGNE0PkP=v5_G(e-x`p zL_t(|UhP^3d{kBT{@!FV=^=ptp+o3M??UJ*9YhciL}fumghgBn?7{*Hh=Rnzf}sc^ z5a~(@l2D`uf;2;iKoTGcg!DEuY5Sc!nf#)ETm$PL-TdAs*O~Y3efOSw&Ueav6D`?V zPyih|N-?y17MGQF0qn~%eC6R|B=wBAhDx-+EFAQ?O4F1&Oy&HV}5s{JCNWp7cOGfK!5mDu7-bX{(<}U`aeW>@dT3NGjQqH zL8RP?BjJtktyKrLTegGIXe<%Y4Mv-zh-3V2Iu&Abu7m4W@}q#4e+KpGK=~^A)kVX{ z+k;t+_{F0~vFNoCsNJG1-d(%F77QP;eYIT)4@q(#V3Lr0@F)x-$x9N+-MxYL z`}adq+)cI79IJ(7H_#9cG=vr1UKoc#Z%sxviTs8TTj1*H@iUS;y91#sRw8)uhbkE4t4@spAO&x%+K#$y zTHA>GA0PoG@a47n8QVVgicf9}`!Yt7Nc6^K>b-7@x6^2Z?Hzuc)8*iuxJJ ze%8+>_oPo`f6Et-Dulh?K33$4i%!7qr3*=ZFH~>b0=>siL66ZBP_s!Zj?FI`Z{L$c zp>9MDx$j6Pi8yo=fA7)|TNlov4jiEs>Q44Aa@h4)K)LKXQ`Z#DK1O7*&oBFzb*1Ig z;hb252yt8X8if9nXP{N@XBfeaaPjcKrnysadQTXve-x4!8;fsauIX>3_1)OgM2>V%KA9|dMwU{ z?!x7;f1^y_cTur!T~()MBxm68H>+{wSQsk!HH4G96XLI3$I(qexEmdf%JmyDx`1QW z;M{@zsL{MV&TyWH{d-}}w$j-=5WaN-Zv6Czfy&On_u{;1lxu}y9o z{Le?}QqJ9~|1hR?C*@Q!mjm~9p6gr=+s}QP@bcmfX#P}N)MUE%A2|Y^ z<*O)NQv_NcIJIjhE*w07w8Rwn*7H-P!sW0Nh}av9jKl;uxwyfcW#*o&@bs;UJ?t#cl4h{PF=ud7beJb!dlwsLOoTN(4R@k%p~_=bv1!gc zgnjcR(;-tLHDF{0*fQ4zuPpx#HCy^op=*$II~v~A{LpS_Z-nvsBuVN(ay02Re+1_A zRD>-37*5Wvcyi(-l57*AP91|+r7B2_zRo%Gs8A0aTDuf)Za&25W>6)kK%z-Loh0Q> zI#!M!f_ogF%koO&e+EXZ`u;ue{KBP5_JC*lBkD}JGOoxd=rQgcJn`DADmCx?>@yr# zwTKhuv+mD=XNAge_9&yqiB3d!e`0(=J`Gr{We3{@*IGPwAo{#96OEtfgj|+R6hS$8 zT+~ghcx5m$Q<7K~uge{$NZcbKLjxDUy=-|L4qAqLQIV9De+LBWro-?t z7%=s11{mdE3TBH18MGmnfm?Z3v}a~Mw0a58H8G$maUO82hb<xMZT%TFNe)I#NwdPJsrxTue9#`&zn;h@QLdgi%Jd|Me<+&)3+Ta;O1FPF z1*wce^*VIN+_N#5aXcE8>OY2S#}DH0y02B~QmH{ROx|_^fl;?GVdDXK_*B5j?}Cte z&y2fKcMuk|0xoo>VIMBXr_r%!*rg|OEo22Dk(r#x{guJT zk$3SNYvat!4DR1uwE_o&Dm}zGoOvx|6MIN1a8|E=3ec!WKP!}IT zXcrfJ|M^_FFmoRb`UZ(Hk#O@ai|L0W@xl4q%zR~FVxSUR+sdT}YX*B1{;ejp+qLj; zEFLjLML4OegbuPv2l7VJ+meybB9q}ck1V<094eBtPe>%jwMQ`_za`s3f$|yo@?d0L zcW%#4b?BvwBEM1X>JwK^Y*CULJQN1@*f1A-N4KQ!e4=)ih)z+<|X{CdzO( z&z-@Y>sMHsWTQrFe=vZks49+Gy+wPt_&C6~acwHoM@8o3_}i*ZEdu9FjLSznokcd; z<<)mojVXJ5tmiX4$eD2Ea40A?dQF{;+ZTVrinpgDfB2(+s6L527D>woLpfPK%bWVB z+r2AN7zI0ynXL9%KqdTAN7Bee_>Ucf@tcmouYFgghdkB^L2r#_*>no2NvTNS-rT&( z(TDS}ZE29o5GIx;ccZQ%i*jc2kgD{|b&~Jps;DXik?hM4WcjP3^X z`0I51xMeLqd2JHT@7X=F-?VPaVZqV~4^>$>lU{q+(+t?qJRMe`iUkEN)t}dE0%OU7-SAs&PVk=d!?w zO8_7L`B4uhqJj$__HgSAhIK%QJ1#O0p zqp@8W)qX0@woaz>4|T~(TwH3hjOx?~SAmP8zl`?5ziJMy`>*=(j=X)GGoL_#sa ze;|iV2%yHW+_`)G9zN~U7CUB7#?>QxSRPo_I?B+T(~^}=BWrMGG?L69kvflxkkUrY z!NI@Omt;jN$GQ9ZV90_67_)A_dR|ienH?LMEtx&J2O;qO#d8rn_iY?o8whJ=8sex2 z2|zNB9Yt%{^-s}6ooc_7QA8D??Q#e-e>zqHn`BIJZgrdEWoU$~XyoJEVWpIbh&V;4T}-v%L{%s@iqWi_Wj-p+_jQlf~y%diAxC8YGFUP%?= zm%1uRD{&;3TB??RJB(PqT@iiN>u)L#OpLjX)qm*?kBXHsI%p?7)m16wesf6Ue?J8W zrXQaDxRG4!p1%Z__HI+JqZ;)btRjLJHz|=W_S`9zIUHFECEScu9xZ9hn~~Ag*AYH` z^^txj77;twqioGOsM@w6Tv<;hv6hTEa~u`wH-=*w4<(ZwqW7Q4BgQMdF1%DkbSdYm zUcJd%gX`f3VPY_I;GyUi562SSe|;M@$Ho1@tPwNN?CDXMb~Fsn1qRs&&VDQBa4qM{ zuLVeny{UfqkvSylt8#_oB%9eYnv#bEkKkc)_ks^tZt>7U;uxIWcy^FlFkh8(8lBA9 z%@YN5vI(IVF^_5g{cBNp|8gWI?mfgv&pC@n6epvaH;2#5GeROc;Toy`e~e@X6OvgV z>nk-;t~{1PX-qqgEFn@85|GVF4Lr#^iL)2er6bEBC+;bY*=6&TsU+@2+nv<_wXM#mHOj8MGx$EX2y`;1a5>MU|`|=lu>jqj>928 z(^W~EL4+u2%c7C0w{L~PfB)Kyiy>RMunCceLs*NK!AtA**gQ`nZW>|&PszfPlds^VGDXaP^Ec$q~5s&Gi%ant^8Glk%&aDf7w7GM3&+_u*+wM zL?DfkxB1YQX>bb;F=B?y3&6I&&%)IM!78IP9WquqtCSwM&xT`XzzTddsvjNEtg@Vy z&(-Mol&WXb@7%`Lw_nD-fF%g|;BU&%Y8|y!F+EWRX(!ixfn|f*U=DQ@IItyBZbd1_ zsMBKrOr8eryA#Z*f5}+=d=CUK2t;VWax5A+2-glrsO;!kp%Qg!g(V{mp&w00E9foNLU(IG0fYi~kgfe>uH!R+<0g`epc*!EO7r zS5!8ZACy?GqhX(+%t-0vRVe%B;@hb+aAnUn*7nXy&qDGdU6rsI#Csm3Ni?d}xgGk> zTZN3fvFe@o$e{hoVSZY|Qd{*>I0bW&WqT{4l7`k$;`Z-En4}bF;W*#skHeChh|IfjsMw^n$~fgo_O#e& zq{YRcQVaIe@nmg@Mp^gbSqi1t$}hQRmnS<@IYL%a0x~(q!ssFars?oucw*WoEEl|S z{L7CKvGprdYTOD#mj}bGvN!7Y9fI0j`Xb@#IfSnYe?Xn?1JxlogC&%On{lb&hW-oJ z!PUzLkq5rV`Rzey`TXlhC26y{RxTr}T^4Clrj(_#S8vx%)!3|wSWy^w7_EbT^H-yW ze_N0PcyiW!G#N6QwZ9pMKA(l7OXo2-J8``#YQNrfYpZpv>8Us!^aalC{02@e3%gHU zsDe|>fAJp>bMgpU4u2JCw{OrcwwhQROrn92*`hLacWBXj?2ksZww*B`;7fI0$e}l6 zC*DOS^(GD@8ODJbraa~D^}z}}_1-M7a#V!0GRuiRGwW8`_+gZvUG^U3&Z zjwuk97lYKUvTu<~f~u@3^T^(0eu1p($N(&B$#*3e$5`k9YCb+Eb2w6V`7U~sJ{d2v z$TRl87m_jZDSM7PeH!0Sd4Xff;F)E+e^9Qrhgw@?wotz!vpg$$Q|sDMxW25TI8X?Y zQRI;4vJ!2365Gh9nwK(&F64W*yqctrq~C6H9;vW<#z(lcZH>x`PtIOYWV@0=`!uR# zB$vf4>FKzQvW|Pf)_&0Ad*qU;RLe2luL4Ecvxt&Y9n=$>nPpO z=ID`JM=3|~mq0pnluGF3ijGnbZJu7P=qTkV@q2O|I{sIoEsD`euA_8A3%se5Tu14K yw(_=4avh}`+S*v1w2kpP$#s-w0RINcd;qU9Rnav70000pA``G{QnRyJ4myl>M`P}(GhnLsW(_LLve^qtQ z)5+`UcW`P5|-q4|)C$}O!rfAcD@7OBA1 z925^n_w#lUe_YPaPUlA^5XsZsSV}6!yh?CUPt5_8%WT6k-G=sSq5dd) zIX;_`1HY&QiDiYmyqzIycY{=oP4c2jSvovI{(h04e6%B92FyDo zV2yqgV6+FJ(w~l(hyXXeQ9~w3A3ibp+%^HBI<@tZdoS~srQ7pCLfX>LM`Y2)+@=khjfm#63KOSie3vbcuRI|u zcENFhj-ej1;h{*4P>j?BiOABT2mt}ks7ei^#Na1OB3?$B#u9_y`3%8!b06bxzAjMX zVoZKF#x%hgQh`yQ{n(%7jJaIpr%|RA>h}%#4H&ZWdCY6ve|9jfxiP#d9cT96@8 zFQv+mC7H4&h2+qc$cM`u$i()O<+5XRv^?HD2wZ~sd7q%1l*7;uL7gg{=xzL4edqXS zGjwEHQ-S{c_Xmq*#PVY@=jU9>$2cx1nP=bDS_WJhsFi#mmh>XDHjyex}#6w=bf4#M=8Wkn82DOpy@!p!jl`}X= zzs`O#Z%A8N`)D-ohe?PZG6@}npi{uvp1rk|e1Yc&UK^|&uvWn7dPKEQe=7)VKNO|r?i}F-nX1JV8EN{kcItWJ(W?XG<$-NQ z@++j@ezdf2P4(m-B@xO#MALh zMybqOb3z_mbXfc+B%=(hQ0+?wV?L4qI+%V_s62XAki@p}R5G^}HgIEgY49 z_I(=yK5Huf5?@b~ZHHK6W4!!I`3TN&M<-uNM+p`+VXxXZBqzm7Ld!GDjABG&?{ToqbRl-6;S1U{AGfTb}g4B2Yet)7oS5x|8w@qV%P3fK4DvIU;*GoZZJm zi(xJk_ewR1#bv+LQ9QW$&`}5{V!tIQ%?8c4EC1k(&wzkQ*R@n%nGHsMa!hs~K$c<_ z=kVy0I;p+H2D?cPoG?h=ll4L=`5o3)fAxF^_1z4od$!5^hoj}buKw~9_BL0&yk9wJ z&dduX5JVk=s^OJoN2TVS&Z__B%u=}&dm#f{o5$n36|uHVjF&{{`OTkB$*2#HXr&$q z+PjmVtOXeeSCpw$S!Gf)_hR+^rgt)A^@dZDIisV5`MF6JvQ$fb-7~+>k+GPYe;C~- zL|*M1s{SU-F6TWdS&B=cQ_@O2j0hkcC*+*qK-P-iph5s@r= z;51XueBmn8FUwhjNITz1gRHe{ zbd0QjEJmE@OdwHG-&TrHtCI^Q_>r9w_Pmzqmm(`yBPfMDi(sf@7@U>*e-mV9LpQ~y zwUXcjgMt}>UM}K0d7pH7BTapG$J~RNRqXU+1G31b!w8Z(I<-PDG`UJ8lQZl*d0jRL zw^u^O?2*n0ti+gW^vnsp7=+^XzzzN00uc=~lO(0!m{cHC?~cB*{fQW5D6_;~SR8%I z2Hu17{DL~Y@5O!^8Gj2{f3`RR+GB&YsC5LHk^~umjXd$(H#w4q$Xbw7F5}mnRBe4p z0{GX5zvip&JwTqY7>z&+w`grW6MUo_OCn(5RAe~_91=&zI&nD$M! z97Xg$jO@(Pw^lHsVZ20S-~K48QnJfcGuL?NsW_F@2Y2>YZ8Xb_yTWB;w*d7$#2afs zkji2OpyNPJg`^z;K}kp*_4&2T1Iv#}Aqcv4M}f*(gvwmC*$}#m3Os$VvKRZhvpf$X zEZmwWPxlIzZIk0=fAu}5%TyBXGQI32#=U<;Dv^~&eWYcu<_5>4f?q^K2^Y2UMBN;9 z2C+&Jjcg`h8}5C0e}r5HhlvS-;!FgrH~0ujN(0I^^i4hU4eyF52y8hF1481K-kR9Q zNis%ul!?XMI{~hAJbZtDn?|6kBfaD{lwri^&rhh&J}CX@e~83Eo_?8}isc|l=5DIG z%!eohml*1!l~oE=kdtGesYs93Wmv>y?8&~w9;Q#6w=CG4Co7RXY=EN~W1Qe221{Lx zaYn$h2X9h2SpJGld6Ix^@q(UFnPH`khppVZ66+pzS%5r(eJ9IiMRwjZiLI8UuiaRp zG9NE=H`?rRf7B$e(Wk~va5WD9VU~lPlCIbHyg(VM3R~R<@c5nOYw5G?WeT!92b!z1y%Xb!N#yM?Y_=)!Aw7Z-QHxPG& zDdNX>z}#>IZ;TnltOk6UQUnLl_CBH0Qe@hK40Wt*1I9>Z#0GB1eo?p|z<&cfYgyPK zPzJqle@iQg#ym>T_;2+-ZA}UYEWhfd;R28@_@NyV_~g= zNxdZqME6{-Wz==4MbZzY^kQT!8_<2naZOi5f7@6D#8VYANYBE}4UQQ=#kX*lmsg)q z8^sY2elqHR5{q0?K?#mLj;A+Q2dUb2+GkJ}BcaJ?4T8zv)}vf1o7O>HkZrb4N{|f`5r+76EyEo|EICmotM+M`XW!TuS%)ioQoQ=k1AzjRekFP-ym3^dteldd z-aiqFxFE%|C>Mzv;=N^4QoI~}v4aHbna0JDWf1il5Dq*ME9n#BWIF=R`VkT8mLez| zed3o|8O*)ND%_ugDq_zw3Gzfw?BkfNf8gx95O9cp{jH7cq|6}E8l9XZ(&niNatv9+ z08ie{c)C|h`5yBZOg-J_qo1^6aaAb*55Q+ipYI^KlN01|?jeDt+Y4ka*Q_7d7~sL( z5tOb(Z)EjFCCEH8mn%Xa3=!ymwr8KHmc%1n68Ra zO_4=BP~eFWERYGO;0a*{%9@K>dnnQzgF|(D>!74?LrkK;X}O2u{-+vIfO3-bAAm@P zv#($q%SSi@f62j2!t6$Q_>8Tjf1#t;_rd1==DCN|DHp$A4`*=3`WO6?D?Mi&M2+e$ zeUP14+Fab)Q@kP5lyzBZT$L5zSSz>WNfJoFJ|y~Asm1c@4>?NaY*q%kgW3RD-`j)37gV{T$}@KnD<3 z*$;D{EUHw#vKPT;F?4?IyhAc@F7(2ZmwsZ>Cx7K)kuQT}0t6PMpbfunkf0U4LCK;O&=l(?n7R|Tc>k)~$56PmjftGMkp6GPtdn7p6 zSq{)p(1G=6rNH4R6UzujHdAS#K!ul7iz_z$>{bC~tA6J4lYMk~HA12z9h&70!B+x? z+?<;-FjJ6}Bo6lu1m7)j68k>X4ULIE{rue|KM(i0zhZ#lxGYWaf8mMmr6^a_8YmOx z!Wu{x7qnGzd_KoMTnERo2jz!s?vRNkRv~}-!~Vvc98-Tc=LwQg>=Mew;9+EC z_Qx0jxSv~q=h=+g>Rpzvi&RoS+zU|$yeKP(V!Tr5K0950+)*GtA#PHbg>|8-QR#-@ zOI!14A!Xt%&P^H2e|~1xCvAiMtWPk;q`ZV-C+eS|DRYpKL*22lE0Y^~1j(9VTBddy zxkCk&=79SBOo`5e1@D<0FC9X(a_m5Mxx`N0ciNau0UE@xA4RBZ4d)Y-gZ5X>X(xjr zV_otYed?=6qrZ9vm!omdr5i(LHXHNSB`d0eGv3qfG3`fde_K~WQP=z+>(`@WWHa_| z8&Se1BD0UbRx2yVV(&kb`+1VT89)y&=Kz(CXwq?7s(PVVfG8OI!hUTLO+_ezis$^i z8q2W11)Q5%$dL?&jCILp^r3>6$E%X%VCs`yRo;f(L+~d(NIek;faSk|6H3p%0e{mt^%V3&)JDb(Te=Phdp$;2x zHI*ZCUe3=$oTilH9B`beDy!v^2rt?C&uG1&e&{|YU4Bfh=l>{Y!NQ*uj!A{g6M#DP z!7BpQ`;7X4zg(ZcF;B914Bbp4hy@FO1Zv+?v81afp=@AUwg_e6{~Wc~X(R`a%o}o9 ngtB0vAD-{2ELgBmPl)^vVh#pts|Zio00000NkvXXu0mjfi>aoe diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 1d903718ab..a9b454c671 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -20,7 +20,7 @@ ms.localizationpriority: high >This is a 300 level topic (moderate advanced).
>See [Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md) for a full list of topics in this article.
-[![Download SetupDiag](../images/download.png)](https://go.microsoft.com/fwlink/?linkid=870142) + [![Download SetupDiag](../images/download.png)](https://go.microsoft.com/fwlink/?linkid=870142) ## About SetupDiag @@ -30,6 +30,16 @@ SetupDiag is a standalone diagnostic tool that can be used to obtain details abo SetupDiag works by examining Windows Setup log files. It attempts to parse these log files to determine the root cause of a failure to update or upgrade the computer to Windows 10. SetupDiag can be run on the computer that failed to update, or you can export logs from the computer to another location and run SetupDiag in offline mode. +To quickly use SetupDiag on your current computer: +1. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). +2. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. +3. When SetupDiag has finished downloading, open the **Downloads** folder. If you downloaded the file somewhere else, open that folder instead. +4. Double-click the SetupDiag file. Click **Yes** if you are asked to approve running the program. +5. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. +6. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. +7. Use Notepad or another text file viewer application to open the log file displaying the current date in the name (ex: SetupDiag_17-Jul-2018.log). +8. Review the information to discover if any rules were matched that can tell you why the computer failed to upgrade. For an example, see the [Text log sample](#text-log-sample) below. + See the [Release notes](#release-notes) section at the bottom of this topic for information about the latest updates to this tool. ## Requirements From 516a40ebb1f114654af4bceebee38a04b8da45c3 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 16:26:09 -0700 Subject: [PATCH 003/737] update --- windows/deployment/upgrade/setupdiag.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index a9b454c671..11c041aa61 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -32,13 +32,13 @@ SetupDiag works by examining Windows Setup log files. It attempts to parse these To quickly use SetupDiag on your current computer: 1. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). -2. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. -3. When SetupDiag has finished downloading, open the **Downloads** folder. If you downloaded the file somewhere else, open that folder instead. -4. Double-click the SetupDiag file. Click **Yes** if you are asked to approve running the program. +2. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. You can also save it to a different location if desired by using **Save As**. +3. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left pane. +4. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. 5. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. 6. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. -7. Use Notepad or another text file viewer application to open the log file displaying the current date in the name (ex: SetupDiag_17-Jul-2018.log). -8. Review the information to discover if any rules were matched that can tell you why the computer failed to upgrade. For an example, see the [Text log sample](#text-log-sample) below. +7. Use Notepad or another text file viewer application to open the log file (SetupDiagResults.log). +8. Review the information to discover if any rules were matched that can tell you why the computer failed to upgrade. See the [Text log sample](#text-log-sample) below. See the [Release notes](#release-notes) section at the bottom of this topic for information about the latest updates to this tool. From 8a6c0851ddeead8174c5ad4c0068dc45e958909d Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 16:28:10 -0700 Subject: [PATCH 004/737] update --- windows/deployment/upgrade/setupdiag.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 11c041aa61..0aae00a355 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -7,7 +7,7 @@ ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: deploy author: greg-lindsay -ms.date: 07/10/2018 +ms.date: 07/17/2018 ms.localizationpriority: high --- From eebf26a9081cde52a73de22e141561f71c1d40b2 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 16:35:24 -0700 Subject: [PATCH 005/737] update --- windows/deployment/upgrade/setupdiag.md | 21 ++++++++++++--------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 0aae00a355..f1cadc868c 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -31,16 +31,19 @@ SetupDiag is a standalone diagnostic tool that can be used to obtain details abo SetupDiag works by examining Windows Setup log files. It attempts to parse these log files to determine the root cause of a failure to update or upgrade the computer to Windows 10. SetupDiag can be run on the computer that failed to update, or you can export logs from the computer to another location and run SetupDiag in offline mode. To quickly use SetupDiag on your current computer: -1. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). -2. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. You can also save it to a different location if desired by using **Save As**. -3. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left pane. -4. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. -5. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. -6. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. -7. Use Notepad or another text file viewer application to open the log file (SetupDiagResults.log). -8. Review the information to discover if any rules were matched that can tell you why the computer failed to upgrade. See the [Text log sample](#text-log-sample) below. +1. Verify that your system meets the [requirements](#requirements) described below. If needed, install the [.NET framework 4.6](https://www.microsoft.com/download/details.aspx?id=48137). +2. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). +3. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. You can also save it to a different location if desired by using **Save As**. +4. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left pane. +5. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. +6. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. +7. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. +8. Use Notepad to open the log file: **SetupDiagResults.log**. +9. Review the information that is displayed. If a rule was matched this can tell you why the computer failed to upgrade, and potentially how to fix the problem. See the [Text log sample](#text-log-sample) below. -See the [Release notes](#release-notes) section at the bottom of this topic for information about the latest updates to this tool. +For instructions on how to run the tool in offline more and with more advanced options, see the [Parameters](#parameters) section below. + +See the [Release notes](#release-notes) section at the bottom of this topic for information about recent updates to this tool. ## Requirements From 8d931f475c887f3519580b9474ac1c2fb899cade Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 17 Jul 2018 16:43:48 -0700 Subject: [PATCH 006/737] update --- windows/deployment/upgrade/setupdiag.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index f1cadc868c..640c908099 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -35,11 +35,12 @@ To quickly use SetupDiag on your current computer: 2. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). 3. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. You can also save it to a different location if desired by using **Save As**. 4. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left pane. -5. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. -6. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. -7. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. -8. Use Notepad to open the log file: **SetupDiagResults.log**. -9. Review the information that is displayed. If a rule was matched this can tell you why the computer failed to upgrade, and potentially how to fix the problem. See the [Text log sample](#text-log-sample) below. +5. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. + >Double-clicking the file to run it will automatically close the command window when SetupDiag has completed its analysis. If you wish to keep this window open instead, and review the messages that you see, run the program by typing SetupDiag at the command prompt instead of double-clicking it. You will need to change directories to the location of SetupDiag to run it this way. +1. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. +2. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. +3. Use Notepad to open the log file: **SetupDiagResults.log**. +4. Review the information that is displayed. If a rule was matched this can tell you why the computer failed to upgrade, and potentially how to fix the problem. See the [Text log sample](#text-log-sample) below. For instructions on how to run the tool in offline more and with more advanced options, see the [Parameters](#parameters) section below. From fe4e7c76c681576bf8226083fc829015369d09d1 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 18 Jul 2018 11:16:06 -0700 Subject: [PATCH 007/737] update --- windows/deployment/upgrade/setupdiag.md | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 640c908099..6e2f61c6a9 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -32,19 +32,19 @@ SetupDiag works by examining Windows Setup log files. It attempts to parse these To quickly use SetupDiag on your current computer: 1. Verify that your system meets the [requirements](#requirements) described below. If needed, install the [.NET framework 4.6](https://www.microsoft.com/download/details.aspx?id=48137). -2. Click [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). +2. [Download SetupDiag](https://go.microsoft.com/fwlink/?linkid=870142). 3. If your web browser asks what to do with the file, choose **Save**. By default, the file will be saved to your **Downloads** folder. You can also save it to a different location if desired by using **Save As**. -4. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left pane. -5. Double-click the SetupDiag file to run it. Click **Yes** if you are asked to approve running the program. - >Double-clicking the file to run it will automatically close the command window when SetupDiag has completed its analysis. If you wish to keep this window open instead, and review the messages that you see, run the program by typing SetupDiag at the command prompt instead of double-clicking it. You will need to change directories to the location of SetupDiag to run it this way. -1. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. -2. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. -3. Use Notepad to open the log file: **SetupDiagResults.log**. -4. Review the information that is displayed. If a rule was matched this can tell you why the computer failed to upgrade, and potentially how to fix the problem. See the [Text log sample](#text-log-sample) below. +4. When SetupDiag has finished downloading, open the folder where you downloaded the file. As mentioned above, by default this is your **Downloads** folder which is displayed in File Explorer under **Quick access** in the left navigation pane. +5. Double-click the **SetupDiag** file to run it. Click **Yes** if you are asked to approve running the program. + - Double-clicking the file to run it will automatically close the command window when SetupDiag has completed its analysis. If you wish to keep this window open instead, and review the messages that you see, run the program by typing **SetupDiag** at the command prompt instead of double-clicking it. You will need to change directories to the location of SetupDiag to run it this way. +6. A command window will open while SetupDiag diagnoses your computer. Wait for this to finish. +7. When SetupDiag finishes, two files will be created in the same folder where you double-clicked SetupDiag. One is a configuration file, the other is a log file. +8. Use Notepad to open the log file: **SetupDiagResults.log**. +9. Review the information that is displayed. If a rule was matched this can tell you why the computer failed to upgrade, and potentially how to fix the problem. See the [Text log sample](#text-log-sample) below. -For instructions on how to run the tool in offline more and with more advanced options, see the [Parameters](#parameters) section below. +For instructions on how to run the tool in offline more and with more advanced options, see the [Parameters](#parameters) and [Examples](#examples) sections below. -See the [Release notes](#release-notes) section at the bottom of this topic for information about recent updates to this tool. +The [Release notes](#release-notes) section at the bottom of this topic has information about recent updates to this tool. ## Requirements @@ -63,7 +63,7 @@ See the [Release notes](#release-notes) section at the bottom of this topic for | /Output:\ |
  • This optional parameter enables you to specify the output file for results. This is where you will find what SetupDiag was able to determine. Only text format output is supported. UNC paths will work, provided the context under which SetupDiag runs has access to the UNC path. If the path has a space in it, you must enclose the entire path in double quotes (see the example section below).
  • Default: If not specified, SetupDiag will create the file **SetupDiagResults.log** in the same directory where SetupDiag.exe is run.
| | /Mode:\ |
  • This optional parameter allows you to specify the mode in which SetupDiag will operate: Offline or Online.
  • Offline: tells SetupDiag to run against a set of log files already captured from a failed system. In this mode you can run anywhere you have access to the log files. This mode does not require SetupDiag to be run on the computer that failed to update. When you specify offline mode, you must also specify the /LogsPath: parameter.
  • Online: tells SetupDiag that it is being run on the computer that failed to update. SetupDiag will attempt find log files and resources in standard Windows locations, such as the **%SystemDrive%\$Windows.~bt** directory for setup log files.
  • Log file search paths are configurable in the SetupDiag.exe.config file, under the SearchPath key. Search paths are comma separated. Note: A large number of search paths will extend the time required for SetupDiag to return results.
  • Default: If not specified, SetupDiag will run in Online mode.
| | /LogsPath:\ |
  • This optional parameter is required only when **/Mode:Offline** is specified. This tells SetupDiag.exe where to find the log files. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories. This parameter should be omitted when the **/Mode:Online** is specified.
| -| /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file continuing its results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| +| /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file containing the results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| | /Verbose |
  • This optional parameter will output much more data to the log file produced by SetupDiag.exe. By default SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce a log file with debugging details, which can be useful when reporting a problem with SetupDiag.
| | /Format:\ |
  • This optional parameter can be used to output log files in xml or JSON format. If this parameter is not specified, text format is used by default.
| From 503947c89d6170b4b889d4c0f85aeb027c0b409b Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 18 Jul 2018 14:21:42 -0700 Subject: [PATCH 008/737] update --- windows/deployment/upgrade/setupdiag.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 90965a2bd0..3f9716261b 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -64,7 +64,7 @@ The [Release notes](#release-notes) section at the bottom of this topic has info | /Mode:\ |
  • This optional parameter allows you to specify the mode in which SetupDiag will operate: Offline or Online.
  • Offline: tells SetupDiag to run against a set of log files already captured from a failed system. In this mode you can run anywhere you have access to the log files. This mode does not require SetupDiag to be run on the computer that failed to update. When you specify offline mode, you must also specify the /LogsPath: parameter.
  • Online: tells SetupDiag that it is being run on the computer that failed to update. SetupDiag will attempt find log files and resources in standard Windows locations, such as the **%SystemDrive%\$Windows.~bt** directory for setup log files.
  • Log file search paths are configurable in the SetupDiag.exe.config file, under the SearchPath key. Search paths are comma separated. Note: A large number of search paths will extend the time required for SetupDiag to return results.
  • Default: If not specified, SetupDiag will run in Online mode.
| | /LogsPath:\ |
  • This optional parameter is required only when **/Mode:Offline** is specified. This tells SetupDiag.exe where to find the log files. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories. This parameter should be omitted when the **/Mode:Online** is specified.
| | /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file containing the results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| -| /Verbose |
  • This optional parameter will output much more data to the log file produced by SetupDiag.exe. By default SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce a log file with debugging details, which can be useful when reporting a problem with SetupDiag.
| +| /Verbose |
  • This optional parameter will output much more data to a log file. By default SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce an additional log file with debugging details. These details can be useful when reporting a problem with SetupDiag.
| | /Format:\ |
  • This optional parameter can be used to output log files in xml or JSON format. If this parameter is not specified, text format is used by default.
| ### Examples: From f354a053804c92d22f20a38eeb1f15db23f94760 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 14 Dec 2018 15:03:18 -0800 Subject: [PATCH 009/737] 1.4.0.0 --- windows/deployment/upgrade/setupdiag.md | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 893d357f79..794be7b222 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -7,7 +7,7 @@ ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: deploy author: greg-lindsay -ms.date: 08/16/2018 +ms.date: 12/14/2018 ms.localizationpriority: medium --- @@ -24,7 +24,7 @@ ms.localizationpriority: medium ## About SetupDiag -Current version of SetupDiag: 1.3.1.0 +Current version of SetupDiag: 1.4.0.0 SetupDiag is a standalone diagnostic tool that can be used to obtain details about why a Windows 10 upgrade was unsuccessful. @@ -61,11 +61,14 @@ The [Release notes](#release-notes) section at the bottom of this topic has info | --- | --- | | /? |
  • Displays interactive help
| | /Output:\ |
  • This optional parameter enables you to specify the output file for results. This is where you will find what SetupDiag was able to determine. Only text format output is supported. UNC paths will work, provided the context under which SetupDiag runs has access to the UNC path. If the path has a space in it, you must enclose the entire path in double quotes (see the example section below).
  • Default: If not specified, SetupDiag will create the file **SetupDiagResults.log** in the same directory where SetupDiag.exe is run.
| -| /Mode:\ |
  • This optional parameter allows you to specify the mode in which SetupDiag will operate: Offline or Online.
  • Offline: tells SetupDiag to run against a set of log files already captured from a failed system. In this mode you can run anywhere you have access to the log files. This mode does not require SetupDiag to be run on the computer that failed to update. When you specify offline mode, you must also specify the /LogsPath: parameter.
  • Online: tells SetupDiag that it is being run on the computer that failed to update. SetupDiag will attempt find log files and resources in standard Windows locations, such as the **%SystemDrive%\$Windows.~bt** directory for setup log files.
  • Log file search paths are configurable in the SetupDiag.exe.config file, under the SearchPath key. Search paths are comma separated. Note: A large number of search paths will extend the time required for SetupDiag to return results.
  • Default: If not specified, SetupDiag will run in Online mode.
| | /LogsPath:\ |
  • This optional parameter is required only when **/Mode:Offline** is specified. This tells SetupDiag.exe where to find the log files. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories. This parameter should be omitted when the **/Mode:Online** is specified.
| | /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file containing the results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| | /Verbose |
  • This optional parameter will output much more data to a log file. By default, SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce an additional log file with debugging details. These details can be useful when reporting a problem with SetupDiag.
| | /Format:\ |
  • This optional parameter can be used to output log files in xml or JSON format. If this parameter is not specified, text format is used by default.
| +| /NoTel |
  • This optional parameter tells SetupDiag.exe not to send diagnostic telemetry to Microsoft.
| + +Note: The **/Mode** parameter is deprecated in version 1.4.0.0 of SetupDiag. +- In previous versions, this command was used with the LogsPath parameter to specify that SetupDiag should run in an offline manner to analyze a set of log files that were captured from a different computer. In version 1.4.0.0 when you specify /LogsPath then SetupDiag will automatically run in offline mode, therefore the /Mode parameter is not needed. ### Examples: @@ -75,10 +78,10 @@ In the following example, SetupDiag is run with default parameters (online mode, SetupDiag.exe ``` -In the following example, SetupDiag is specified to run in Online mode (this is the default). It will know where to look for logs on the current (failing) system, so there is no need to gather logs ahead of time. A custom location for results is specified. +In the following example, SetupDiag is run in online mode (this is the default). It will know where to look for logs on the current (failing) system, so there is no need to gather logs ahead of time. A custom location for results is specified. ``` -SetupDiag.exe /Output:C:\SetupDiag\Results.log /Mode:Online +SetupDiag.exe /Output:C:\SetupDiag\Results.log ``` The following example uses the /Output parameter to save results to a path name that contains a space: @@ -90,7 +93,7 @@ SetupDiag /Output:"C:\Tools\SetupDiag\SetupDiag Results\Results.log" The following example specifies that SetupDiag is to run in offline mode, and to process the log files found in **D:\Temp\Logs\LogSet1**. ``` -SetupDiag.exe /Output:C:\SetupDiag\Results.log /Mode:Offline /LogsPath:D:\Temp\Logs\LogSet1 +SetupDiag.exe /Output:C:\SetupDiag\Results.log /LogsPath:D:\Temp\Logs\LogSet1 ``` ## Log files @@ -375,6 +378,14 @@ Each rule name and its associated unique rule identifier are listed with a descr ## Release notes +12/16/2018 - SetupDiag v1.4.0.0 is released with 44 rules, as a standalone tool available from the Download Center. + - This release includes major improvements in rule processing performance: about 3x faster in processing rules! + - The FindDownlevelFailure rule is up to 10x faster. + - New rules have been added to analyze failures upgrading to Windows 10 version 1809. + - A new help link is available for resolving servicing stack failures on the down-level OS when the rule match indicates this type of failure. + - Removed the need to specify /Mode parameter. Now if you specify /LogsPath, it automatically assumes offline mode. + - A few other minor improvements were made in specific rules. + 07/16/2018 - SetupDiag v1.3.1 is released with 44 rules, as a standalone tool available from the Download Center. - This release fixes a problem that can occur when running SetupDiag in online mode on a computer that produces a setupmem.dmp file, but does not have debugger binaries installed. From 34d4a6bdc7c5826fc472899cce7a1698fb0c2ba8 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 18 Dec 2018 12:01:44 -0800 Subject: [PATCH 010/737] setupdiag 1.4 --- windows/deployment/upgrade/setupdiag.md | 30 ++++++++++++++++++++----- 1 file changed, 24 insertions(+), 6 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 794be7b222..b3f10c8d57 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -7,7 +7,7 @@ ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: deploy author: greg-lindsay -ms.date: 12/14/2018 +ms.date: 12/18/2018 ms.localizationpriority: medium --- @@ -368,23 +368,41 @@ Each rule name and its associated unique rule identifier are listed with a descr 40. UpdateAgentExpanderFailure – 66E496B3-7D19-47FA-B19B-4040B9FD17E2 - Matches DPX expander failures in the down-level phase of update from WU. Will output the package name, function, expression and error code. 41. FindFatalPluginFailure – E48E3F1C-26F6-4AFB-859B-BF637DA49636 - - Matches any plug in failure that setupplatform decides is fatal to setup. Will output the plugin name, operation and error code. + - Matches any plug-in failure that setupplatform decides is fatal to setup. Will output the plugin name, operation and error code. 42. AdvancedInstallerFailed - 77D36C96-32BE-42A2-BB9C-AAFFE64FCADC - Indicates critical failure in the AdvancedInstaller while running an installer package, includes the .exe being called, the phase, mode, component and error codes. 43. MigrationAbortedDueToPluginFailure - D07A24F6-5B25-474E-B516-A730085940C9 - - Indicates a critical failure in a migration plugin that causes setup to abort the migration. Will provide the setup operation, plug in name, plug in action and error code. + - Indicates a critical failure in a migration plugin that causes setup to abort the migration. Will provide the setup operation, plug-in name, plug-in action and error code. 44. DISMAddPackageFailed - 6196FF5B-E69E-4117-9EC6-9C1EAB20A3B9 - Indicates a critical failure during a DISM add package operation. Will specify the Package Name, DISM error and add package error code. +45. PlugInComplianceBlock - D912150B-1302-4860-91B5-527907D08960 + - Detects all compat blocks from Server compliance plug-ins. Outputs the block information and remediation. +46. AdvancedInstallerGenericFailure - 4019550D-4CAA-45B0-A222-349C48E86F71 + - Triggers on advanced installer failures in a generic sense, outputting the application called, phase, mode, component and error code. +47. FindMigGatherApplyFailure - A9964E6C-A2A8-45FF-B6B5-25E0BD71428E + - Shows errors when the migration Engine fails out on a gather or apply operation. Indicates the Migration Object (file or registry path), the Migration +48. OptionalComponentFailedToGetOCsFromPackage - D012E2A2-99D8-4A8C-BBB2-088B92083D78 + - Indicates the optional component (OC) migration operation failed to enumerate optional components from an OC Package. Outputs the package name and error code. +49. OptionalComponentOpenPackageFailed - 22952520-EC89-4FBD-94E0-B67DF88347F6 + - Indicates the optional component migration operation failed to open an optional component Package. Outputs the package name and error code. +50. OptionalComponentInitCBSSessionFailed - 63340812-9252-45F3-A0F2-B2A4CA5E9317 + - Indicates corruption in the servicing stack on the down-level system. Outputs the error code encountered while trying to initialize the servicing component on the existing OS. +51. DISMproviderFailure - D76EF86F-B3F8-433F-9EBF-B4411F8141F4 + - Triggers when a DISM provider (plug-in) fails in a critical operation. Outputs the file (plug-in name), function called + error code, and error message from the provider. +52. SysPrepLaunchModuleFailure - 7905655C-F295-45F7-8873-81D6F9149BFD + - Indicates a sysPrep plug-in has failed in a critical operation. Indicates the plug-in name, operation name and error code. +53. UserProvidedDriverInjectionFailure - 2247C48A-7EE3-4037-AFAB-95B92DE1D980 + - A driver provided to setup (via command line input) has failed in some way. Outputs the driver install function and error code. ## Release notes -12/16/2018 - SetupDiag v1.4.0.0 is released with 44 rules, as a standalone tool available from the Download Center. - - This release includes major improvements in rule processing performance: about 3x faster in processing rules! +12/18/2018 - SetupDiag v1.4.0.0 is released with 53 rules, as a standalone tool available from the Download Center. + - This release includes major improvements in rule processing performance: ~3x faster rule processing performance! - The FindDownlevelFailure rule is up to 10x faster. - New rules have been added to analyze failures upgrading to Windows 10 version 1809. - A new help link is available for resolving servicing stack failures on the down-level OS when the rule match indicates this type of failure. - Removed the need to specify /Mode parameter. Now if you specify /LogsPath, it automatically assumes offline mode. - - A few other minor improvements were made in specific rules. + - Some functional and output improvements were made for several rules. 07/16/2018 - SetupDiag v1.3.1 is released with 44 rules, as a standalone tool available from the Download Center. - This release fixes a problem that can occur when running SetupDiag in online mode on a computer that produces a setupmem.dmp file, but does not have debugger binaries installed. From c84b6501db90326c7903f884d29561b69115a21d Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 18 Dec 2018 12:11:04 -0800 Subject: [PATCH 011/737] setupdiag 1.4 --- windows/deployment/deploy-whats-new.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/windows/deployment/deploy-whats-new.md b/windows/deployment/deploy-whats-new.md index 4e9ee7e411..a0d7f4cfa8 100644 --- a/windows/deployment/deploy-whats-new.md +++ b/windows/deployment/deploy-whats-new.md @@ -7,7 +7,7 @@ ms.localizationpriority: medium ms.prod: w10 ms.sitesec: library ms.pagetype: deploy -ms.date: 12/07/2018 +ms.date: 12/18/2018 author: greg-lindsay --- @@ -23,6 +23,10 @@ This topic provides an overview of new solutions and online content related to d - For an all-up overview of new features in Windows 10, see [What's new in Windows 10](https://technet.microsoft.com/itpro/windows/whats-new/index). - For a detailed list of changes to Windows 10 ITPro TechNet library content, see [Online content change history](#online-content-change-history). +## Recent additions to this page + +[SetupDiag](#setupdiag) 1.4 is released. + ## The Modern Desktop Deployment Center The [Modern Desktop Deployment Center](https://docs.microsoft.com/microsoft-365/enterprise/desktop-deployment-center-home) has launched with tons of content to help you with large-scale deployment of Windows 10 and Office 365 ProPlus. @@ -56,6 +60,12 @@ Windows Autopilot streamlines and automates the process of setting up and config Windows Autopilot joins devices to Azure Active Directory (Azure AD), optionally enrolls into MDM services, configures security policies, and sets a custom out-of-box-experience (OOBE) for the end user. For more information, see [Overview of Windows Autopilot](windows-autopilot/windows-autopilot.md). +### SetupDiag + +[SetupDiag](upgrade/setupdiag.md) is a standalone diagnostic tool that can be used to obtain details about why a Windows 10 upgrade was unsuccessful. + +SetupDiag version 1.4 was released on 12/18/2018. + ### Upgrade Readiness The Upgrade Readiness tool moved from public preview to general availability on March 2, 2017. From fd152689337b3356a230b029a538d61deb6f1989 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 18 Dec 2018 12:35:22 -0800 Subject: [PATCH 012/737] removed references to /mode --- windows/deployment/upgrade/setupdiag.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index b3f10c8d57..2382a0a80a 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -61,7 +61,7 @@ The [Release notes](#release-notes) section at the bottom of this topic has info | --- | --- | | /? |
  • Displays interactive help
| | /Output:\ |
  • This optional parameter enables you to specify the output file for results. This is where you will find what SetupDiag was able to determine. Only text format output is supported. UNC paths will work, provided the context under which SetupDiag runs has access to the UNC path. If the path has a space in it, you must enclose the entire path in double quotes (see the example section below).
  • Default: If not specified, SetupDiag will create the file **SetupDiagResults.log** in the same directory where SetupDiag.exe is run.
| -| /LogsPath:\ |
  • This optional parameter is required only when **/Mode:Offline** is specified. This tells SetupDiag.exe where to find the log files. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories. This parameter should be omitted when the **/Mode:Online** is specified.
| +| /LogsPath:\ |
  • This optional parameter tells SetupDiag.exe where to find the log files for an offline analysis. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories.
| | /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file containing the results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| | /Verbose |
  • This optional parameter will output much more data to a log file. By default, SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce an additional log file with debugging details. These details can be useful when reporting a problem with SetupDiag.
| | /Format:\ |
  • This optional parameter can be used to output log files in xml or JSON format. If this parameter is not specified, text format is used by default.
| @@ -114,7 +114,7 @@ When Microsoft Windows encounters a condition that compromises safe system opera If crash dumps [are enabled](https://docs.microsoft.com/windows-hardware/drivers/debugger/enabling-a-kernel-mode-dump-file) on the system, a crash dump file is created. If the bug check occurs during an upgrade, Windows Setup will extract a minidump (setupmem.dmp) file. SetupDiag can also debug these setup related minidumps. To debug a setup related bug check, you must: -- Specify the **/Mode:Offline** and **/LogsPath** parameters. You cannot debug memory dumps in online mode. +- Specify the **/LogsPath** parameter. You cannot debug memory dumps in online mode. - Gather the setup memory dump file (setupmem.dmp) from the failing system. - Setupmem.dmp will be created in either **%SystemDrive%\$Windows.~bt\Sources\Rollback**, or in **%WinDir%\Panther\NewOS\Rollback** depending on when the bug check occurs. - Install the [Windows Debugging Tools](https://docs.microsoft.com/windows-hardware/drivers/debugger/debugger-download-tools) on the computer that runs SetupDiag. @@ -122,7 +122,7 @@ To debug a setup related bug check, you must: In the following example, the **setupmem.dmp** file is copied to the **D:\Dump** directory and the Windows Debugging Tools are installed prior to running SetupDiag: ``` -SetupDiag.exe /Output:C:\SetupDiag\Dumpdebug.log /Mode:Offline /LogsPath:D:\Dump +SetupDiag.exe /Output:C:\SetupDiag\Dumpdebug.log /LogsPath:D:\Dump ``` ## Known issues @@ -138,7 +138,7 @@ The following is an example where SetupDiag is run in offline mode. In this exam The output also provides an error code 0xC1900208 - 0x4000C which corresponds to a compatibility issue as documented in the [Upgrade error codes](upgrade-error-codes.md#result-codes) and [Resolution procedures](resolution-procedures.md#modern-setup-errors) topics in this article. ``` -C:\SetupDiag>SetupDiag.exe /Output:C:\SetupDiag\Results.log /Mode:Offline /LogsPath:C:\Temp\BobMacNeill +C:\SetupDiag>SetupDiag.exe /Output:C:\SetupDiag\Results.log /LogsPath:C:\Temp\BobMacNeill SetupDiag v1.01 Copyright (c) Microsoft Corporation. All rights reserved From f9df450acf6cad167da362ea4cbd1354918f4123 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 18 Dec 2018 13:02:23 -0800 Subject: [PATCH 013/737] updated one line --- windows/deployment/upgrade/setupdiag.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 2382a0a80a..53856948d2 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -140,8 +140,8 @@ The output also provides an error code 0xC1900208 - 0x4000C which corresponds to ``` C:\SetupDiag>SetupDiag.exe /Output:C:\SetupDiag\Results.log /LogsPath:C:\Temp\BobMacNeill -SetupDiag v1.01 -Copyright (c) Microsoft Corporation. All rights reserved +SetupDiag v1.4.0.0 +Copyright (c) Microsoft Corporation. All rights reserved. Searching for setup logs, this can take a minute or more depending on the number and size of the logs...please wait. Found 4 setupact.logs. From 62db25d6d14b27096fe717308a0aa38f44f52c5d Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 17 Jan 2019 09:05:51 -0800 Subject: [PATCH 014/737] new build 011719 --- windows/privacy/TOC.md | 1 + ...ndows-diagnostic-events-and-fields-19H1.md | 5817 +++++++++++++++++ 2 files changed, 5818 insertions(+) create mode 100644 windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md diff --git a/windows/privacy/TOC.md b/windows/privacy/TOC.md index 35561d07af..e2a139c80d 100644 --- a/windows/privacy/TOC.md +++ b/windows/privacy/TOC.md @@ -7,6 +7,7 @@ ### [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md) ### [Diagnostic Data Viewer for PowerShell Overview](Microsoft-DiagnosticDataViewer.md) ## Basic level Windows diagnostic data events and fields +### [Windows 10, version 19H1 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-19H1.md) ### [Windows 10, version 1809 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1809.md) ### [Windows 10, version 1803 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) ### [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md new file mode 100644 index 0000000000..da9e5f277e --- /dev/null +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -0,0 +1,5817 @@ +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 19H1 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +ms.date: 01/17/2019 +--- + + +# Windows 10, version 19H1 basic level Windows diagnostic events and fields + + +> [!IMPORTANT] +> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. + + + **Applies to** + +- Windows 10, version 19H1 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1809 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1809.md) +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Commit + +No content is currently available. + +The following fields are available: + +- **oldId** No content is currently available. +- **txId** No content is currently available. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19A** No content is currently available. +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19A** No content is currently available. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19A** No content is currently available. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19A** No content is currently available. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19A** No content is currently available. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19A** No content is currently available. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19A** No content is currently available. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19A** No content is currently available. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19A** No content is currently available. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19A** No content is currently available. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19A** No content is currently available. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19A** No content is currently available. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19A** No content is currently available. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19A** No content is currently available. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS4** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19A** No content is currently available. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19A** No content is currently available. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageRemove + +This event indicates that the DatasourceDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? +- **TEMP_WuFalseAndCosInbox** No content is currently available. +- **TEMP_WuFalseAndCosOnline** No content is currently available. +- **TEMP_WuFalseAndNoCos** No content is currently available. +- **TEMP_WuTrueAndCosInbox** No content is currently available. +- **TEMP_WuTrueAndCosOnline** No content is currently available. +- **TEMP_WuTrueAndNoCos** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? +- **HasBiosBlockServicing** No content is currently available. +- **HasBiosBlockSwap** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionTestRemove + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.DecisionTestStartSync + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BiosDate** The release date of the BIOS in UTC format. +- **BiosName** The name field from Win32_BIOS. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryTestRemove + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.InventoryTestStartSync + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** No content is currently available. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **DriverTargetRing** No content is currently available. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** No content is currently available. +- **LocationHistoryOnTimeline** No content is currently available. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** If the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** No content is currently available. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** No content is currently available. +- **LocationHistoryOnTimeline** No content is currently available. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **inventoryId** Device ID used for Compatibility testing +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +No content is currently available. + +The following fields are available: + +- **applicableUpdateState** No content is currently available. +- **buildVersion** No content is currently available. +- **clientId** No content is currently available. +- **downloadSource** No content is currently available. +- **downloadtimeInSeconds** No content is currently available. +- **executionID** No content is currently available. +- **executionSequence** No content is currently available. +- **firstMergedExecutionSequence** No content is currently available. +- **firstMergedID** No content is currently available. +- **hrDownloadResult** No content is currently available. +- **hrStatusUpdate** No content is currently available. +- **identityHash** No content is currently available. +- **initiatedOffline** No content is currently available. +- **majorVersion** No content is currently available. +- **minorVersion** No content is currently available. +- **packageArchitecture** No content is currently available. +- **packageLanguage** No content is currently available. +- **packageName** No content is currently available. +- **rebootRequired** No content is currently available. +- **revisionVersion** No content is currently available. +- **stackBuild** No content is currently available. +- **stackMajorVersion** No content is currently available. +- **stackMinorVersion** No content is currently available. +- **stackRevision** No content is currently available. +- **updateName** No content is currently available. +- **updateStartState** No content is currently available. +- **updateTargetState** No content is currently available. + + +## Diagnostic data events + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** No content is currently available. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DisplayAdapterLuid** The display adapter LUID. +- **DriverDate** The date of the display driver. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **GPUDeviceID** The GPU device ID. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPUVendorID** The GPU vendor ID. +- **InterfaceId** The GPU interface ID. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsHwSchSupported** No content is currently available. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSystemID** The subsystem ID. +- **SubVendorID** The GPU sub vendor ID. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **version** The event version. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **AppName** The name of the app that has crashed. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.FileSigningInfoAdd + +This event enumerates the signatures of files, either driver packages or application executables. For driver packages, this data is collected on demand via Telecommand to limit it only to unrecognized driver packages, saving time for the client and space on the server. For applications, this data is collected for up to 10 random executables on a system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **CatalogSigners** Signers from catalog. Each signer starts with Chain. +- **DigestAlgorithm** No content is currently available. +- **DriverPackageStrongName** Optional. Available only if FileSigningInfo is collected on a driver package. +- **EmbeddedSigners** Embedded signers. Each signer starts with Chain. +- **FileName** The file name of the file whose signatures are listed. +- **FileType** Either exe or sys, depending on if a driver package or application executable. +- **InventoryVersion** The version of the inventory file generating the events. +- **Thumbprint** Comma separated hash of the leaf node of each signer. Semicolon is used to separate CatalogSigners from EmbeddedSigners. There will always be a trailing comma. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component +- **ProgramIds** The unique program identifier the driver is associated with + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFileAdd + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BinaryType** No content is currently available. +- **BinFileVersion** No content is currently available. +- **BinProductVersion** No content is currently available. +- **BoeProgramId** No content is currently available. +- **CompanyName** No content is currently available. +- **FileId** No content is currently available. +- **FileVersion** No content is currently available. +- **InventoryVersion** No content is currently available. +- **Language** No content is currently available. +- **LinkDate** No content is currently available. +- **LowerCaseLongPath** No content is currently available. +- **Name** No content is currently available. +- **ProductName** No content is currently available. +- **ProductVersion** No content is currently available. +- **ProgramId** No content is currently available. +- **Size** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **Icon** No content is currently available. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BusReportedDescription** The description of the device reported by the bux. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class GUID from the driver package +- **COMPID** The device setup class guid of the driver loaded for the device. +- **ContainerId** The list of compat ids for the device. +- **Description** System-supplied GUID that uniquely groups the functional devices associated with a single-function or multifunction device installed in the computer. +- **DeviceInterfaceClasses** No content is currently available. +- **DeviceState** The device description. +- **DriverId** DeviceState is a bitmask of the following: DEVICE_IS_CONNECTED 0x0001 (currently only for container). DEVICE_IS_NETWORK_DEVICE 0x0002 (currently only for container). DEVICE_IS_PAIRED 0x0004 (currently only for container). DEVICE_IS_ACTIVE 0x0008 (currently never set). DEVICE_IS_MACHINE 0x0010 (currently only for container). DEVICE_IS_PRESENT 0x0020 (currently always set). DEVICE_IS_HIDDEN 0x0040. DEVICE_IS_PRINTER 0x0080 (currently only for container). DEVICE_IS_WIRELESS 0x0100. DEVICE_IS_WIRELESS_FAT 0x0200. The most common values are therefore: 32 (0x20)= device is present. 96 (0x60)= device is present but hidden. 288 (0x120)= device is a wireless device that is present +- **DriverName** A unique identifier for the driver installed. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage +- **DriverVerDate** Name of the .sys image file (or wudfrd.sys if using user mode driver framework). +- **DriverVerVersion** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **Enumerator** The date of the driver loaded for the device. +- **ExtendedInfs** The extended INF file names. +- **HWID** The version of the driver loaded for the device. +- **Inf** The bus that enumerated the device. +- **InstallState** The device installation state. One of these values: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** List of hardware ids for the device. +- **LowerClassFilters** Lower filter class drivers IDs installed for the device +- **LowerFilters** Lower filter drivers IDs installed for the device +- **Manufacturer** INF file name (the name could be renamed by OS, such as oemXX.inf) +- **MatchingID** Device installation state. +- **Model** The version of the inventory binary generating the events. +- **ParentId** Lower filter class drivers IDs installed for the device. +- **ProblemCode** Lower filter drivers IDs installed for the device. +- **Provider** The device manufacturer. +- **Service** The device service name +- **STACKID** Represents the hardware ID or compatible ID that Windows uses to install a device instance. +- **UpperClassFilters** Upper filter drivers IDs installed for the device +- **UpperFilters** The device model. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **ImageSize** The size of the driver file. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorEndSync + +No content is currently available. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Other events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +No content is currently available. + +The following fields are available: + +- **AudioChannelCount** No content is currently available. +- **AudioSampleRate** No content is currently available. +- **AudioSubtype** No content is currently available. +- **AverageBitrate** No content is currently available. +- **AverageDataRate** No content is currently available. +- **AveragePacketSendTimeInMs** No content is currently available. +- **ConnectorType** No content is currently available. +- **EncodeAverageTimeMS** No content is currently available. +- **EncodeCount** No content is currently available. +- **EncodeMaxTimeMS** No content is currently available. +- **EncodeMinTimeMS** No content is currently available. +- **EncoderCreationTimeInMs** No content is currently available. +- **ErrorSource** No content is currently available. +- **FirstFrameTime** No content is currently available. +- **FirstLatencyMode** No content is currently available. +- **FrameAverageTimeMS** No content is currently available. +- **FrameCount** No content is currently available. +- **FrameMaxTimeMS** No content is currently available. +- **FrameMinTimeMS** No content is currently available. +- **Glitches** No content is currently available. +- **HardwareCursorEnabled** No content is currently available. +- **HDCPState** No content is currently available. +- **HighestBitrate** No content is currently available. +- **HighestDataRate** No content is currently available. +- **LastLatencyMode** No content is currently available. +- **LogTimeReference** No content is currently available. +- **LowestBitrate** No content is currently available. +- **LowestDataRate** No content is currently available. +- **MediaErrorCode** No content is currently available. +- **MiracastEntry** No content is currently available. +- **MiracastM1** No content is currently available. +- **MiracastM2** No content is currently available. +- **MiracastM3** No content is currently available. +- **MiracastM4** No content is currently available. +- **MiracastM5** No content is currently available. +- **MiracastM6** No content is currently available. +- **MiracastM7** No content is currently available. +- **MiracastSessionState** No content is currently available. +- **MiracastStreaming** No content is currently available. +- **ProfileCount** No content is currently available. +- **ProfileCountAfterFiltering** No content is currently available. +- **RefreshRate** No content is currently available. +- **RotationSupported** No content is currently available. +- **RTSPSessionId** No content is currently available. +- **SessionGuid** No content is currently available. +- **SinkHadEdid** No content is currently available. +- **SupportMicrosoftColorSpaceConversion** No content is currently available. +- **SupportsMicrosoftDiagnostics** No content is currently available. +- **SupportsMicrosoftFormatChange** No content is currently available. +- **SupportsMicrosoftLatencyManagement** No content is currently available. +- **SupportsMicrosoftRTCP** No content is currently available. +- **SupportsMicrosoftVideoFormats** No content is currently available. +- **SupportsWiDi** No content is currently available. +- **TeardownErrorCode** No content is currently available. +- **TeardownErrorReason** No content is currently available. +- **UIBCEndState** No content is currently available. +- **UIBCEverEnabled** No content is currently available. +- **UIBCStatus** No content is currently available. +- **VideoBitrate** No content is currently available. +- **VideoCodecLevel** No content is currently available. +- **VideoHeight** No content is currently available. +- **VideoSubtype** No content is currently available. +- **VideoWidth** No content is currently available. +- **WFD2Supported** No content is currently available. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +No content is currently available. + +The following fields are available: + +- **ClientId** No content is currently available. +- **Flags** No content is currently available. +- **FlightId** No content is currently available. +- **Offline** No content is currently available. +- **PolicyPassed** No content is currently available. +- **ReturnCode** No content is currently available. +- **Version** No content is currently available. + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** No content is currently available. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** Number of seconds the update was actively being downloaded. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. +- **AppXScope** Indicates the scope of the app download. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** What is the device model. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started downloading content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HostName** The hostname URL the content is downloading from. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **PackageFullName** The package name of the content. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldTime** Time taken (in seconds) to signal download completion after the last job has completed downloading payload. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **RegulationReason** The reason that the update is regulated +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **Setup360Phase** If the download is for an operating system upgrade, this datapoint indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **SizeCalcTime** Time taken (in seconds) to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in ms) it took to establish the connection prior to beginning downloaded. +- **TotalExpectedBytes** The total count of bytes that the download is expected to be. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UsedDO** Whether the download used the delivery optimization service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** No content is currently available. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DeploymentProviderMode** No content is currently available. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **Mode** No content is currently available. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DeploymentProviderMode** No content is currently available. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **WUDeviceID** The unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **EndpointUrl** The endpoint URL where the device obtains update metadata. This is used to distinguish between test, staging, and production environments. +- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. +- **ExtendedStatusCode** The secondary status code of the event. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast +- **StatusCode** The status code of the event. +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** No content is currently available. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator's last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **capsuleCount** No content is currently available. +- **capsuleFailureCount** No content is currently available. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineResult** Error code from the engine operation. +- **hrLastSandboxError** No content is currently available. +- **initSummary** No content is currently available. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **pluginFailureCount** No content is currently available. +- **pluginsCount** No content is currently available. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +## Windows Store events + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **CategoryId** The Item Category ID. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The product family name of the product being installed. +- **ProductId** The identity of the package or packages being installed. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUpdate** Is this an update? +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNumber** The number of attempts by the user to download. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **fulfillmentPluginId** No content is currently available. +- **FulfillmentPluginId** No content is currently available. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **pluginTelemetryData** No content is currently available. +- **PluginTelemetryData** No content is currently available. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.StateTransition + +No content is currently available. + +The following fields are available: + +- **CatalogId** No content is currently available. +- **FulfillmentPluginId** No content is currently available. +- **HResult** No content is currently available. +- **NewState** No content is currently available. +- **PFN** No content is currently available. +- **PluginLastStage** No content is currently available. +- **PluginTelemetryData** No content is currently available. +- **Prevstate** No content is currently available. +- **ProductId** No content is currently available. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** No content is currently available. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** No content is currently available. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** No content is currently available. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** No content is currently available. +- **predefinedCallerName** The name of the API Caller. +- **restrictedUpload** Is the upload restricted? +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCode** The reason for pausing the download. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Indicates whether the download is happening in the background. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** No content is currently available. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **fileID** The ID of the file being downloaded. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groupID** ID for the group. +- **isEncrypted** Indicates whether the download is encrypted. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **routeToCacheServer** Cache server setting, source, and value. +- **sessionID** The ID for the file download session. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** Indicates whether the download used memory streaming. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **EnterpriseAttributionValue** No content is currently available. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **EnterpriseAttributionValue** No content is currently available. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **EnterpriseAttributionValue** No content is currently available. +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** Reason why the device could not check for updates. +- **detectionBlockingPolicy** State of update action. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session was user initiated. +- **networkStatus** Error info +- **revisionNumber** Update revision number. +- **scanTriggerSource** Source of the triggered scan. +- **updateId** Update ID. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** No content is currently available. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up-to-date + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + + From 17a6787e0ddf7d7b0b3bf20990137909e0262471 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 18 Jan 2019 08:50:56 -0800 Subject: [PATCH 015/737] new build 011819 --- .../basic-level-windows-diagnostic-events-and-fields-19H1.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index da9e5f277e..2fd9b3a25f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/17/2019 +ms.date: 01/18/2019 --- From 10f85d71532329e2429d2585793ca844f988c4d3 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 22 Jan 2019 09:08:29 -0800 Subject: [PATCH 016/737] new build 012219 --- ...windows-diagnostic-events-and-fields-19H1.md | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 2fd9b3a25f..d91af574a8 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/18/2019 +ms.date: 01/22/2019 --- @@ -706,6 +706,8 @@ The following fields are available: - **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? - **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? - **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **SdbDriverBlockServicing** No content is currently available. +- **SdbDriverBlockSwap** No content is currently available. ### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove @@ -3973,12 +3975,12 @@ Ensures Windows Updates are secure and complete. Event helps to identify whether The following fields are available: - **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** The endpoint URL where the device obtains update metadata. This is used to distinguish between test, staging, and production environments. -- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. -- **ExtendedStatusCode** The secondary status code of the event. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. - **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. - **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce +- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). - **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. - **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. @@ -3989,8 +3991,8 @@ The following fields are available: - **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. - **SHA256OfTimestampToken** An encoded string of the timestamp token. - **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast -- **StatusCode** The status code of the event. +- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". +- **StatusCode** Result code of the event (success, cancellation, failure code HResult) - **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. - **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. - **UpdateId** The update ID for a specific piece of content. @@ -4620,6 +4622,7 @@ The following fields are available: - **capsuleFailureCount** No content is currently available. - **detectionSummary** Result of each applicable detection that was run. - **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineBlockReason** No content is currently available. - **hrEngineResult** Error code from the engine operation. - **hrLastSandboxError** No content is currently available. - **initSummary** No content is currently available. From 1ba775d8adb99076810cff923e4afac479822f88 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 23 Jan 2019 08:32:26 -0800 Subject: [PATCH 017/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 56 ++++++++----------- 1 file changed, 24 insertions(+), 32 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index d91af574a8..8af3ec5e62 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/22/2019 +ms.date: 01/23/2019 --- @@ -73,12 +73,12 @@ The following fields are available: ### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Commit -No content is currently available. +This event returns information about the “Commit” operation in AppLockerCSP. The following fields are available: -- **oldId** No content is currently available. -- **txId** No content is currently available. +- **oldId** The unique identifier for the most recent previous CSP transaction. +- **txId** The unique identifier for the current CSP transaction. ### Microsoft.Windows.Security.AppLockerCSP.ClearParams @@ -243,7 +243,7 @@ This event lists the types of objects and how many of each exist on the client d The following fields are available: -- **DatasourceApplicationFile_19A** No content is currently available. +- **DatasourceApplicationFile_19A** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. @@ -251,7 +251,7 @@ The following fields are available: - **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19A** No content is currently available. +- **DatasourceDevicePnp_19A** The count of the number of this particular object type present on this device. - **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. - **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. - **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. @@ -259,7 +259,7 @@ The following fields are available: - **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. - **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. - **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19A** No content is currently available. +- **DatasourceDriverPackage_19A** The count of the number of this particular object type present on this device. - **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. - **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. - **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. @@ -267,7 +267,7 @@ The following fields are available: - **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. - **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. - **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19A** No content is currently available. +- **DataSourceMatchingInfoBlock_19A** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. @@ -275,7 +275,7 @@ The following fields are available: - **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19A** No content is currently available. +- **DataSourceMatchingInfoPassive_19A** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. @@ -283,7 +283,7 @@ The following fields are available: - **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19A** No content is currently available. +- **DataSourceMatchingInfoPostUpgrade_19A** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. @@ -292,7 +292,7 @@ The following fields are available: - **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19A** No content is currently available. +- **DatasourceSystemBios_19A** The count of the number of this particular object type present on this device. - **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. - **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. - **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. @@ -300,7 +300,7 @@ The following fields are available: - **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. - **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. - **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19A** No content is currently available. +- **DecisionApplicationFile_19A** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. @@ -308,7 +308,7 @@ The following fields are available: - **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19A** No content is currently available. +- **DecisionDevicePnp_19A** The count of the number of this particular object type present on this device. - **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. - **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. - **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. @@ -316,7 +316,7 @@ The following fields are available: - **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. - **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19A** No content is currently available. +- **DecisionDriverPackage_19A** The count of the number of this particular object type present on this device. - **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. - **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. - **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. @@ -324,7 +324,7 @@ The following fields are available: - **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. - **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19A** No content is currently available. +- **DecisionMatchingInfoBlock_19A** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. @@ -332,7 +332,7 @@ The following fields are available: - **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19A** No content is currently available. +- **DecisionMatchingInfoPassive_19A** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. @@ -340,7 +340,7 @@ The following fields are available: - **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19A** No content is currently available. +- **DecisionMatchingInfoPostUpgrade_19A** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. @@ -349,7 +349,7 @@ The following fields are available: - **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19A** No content is currently available. +- **DecisionMediaCenter_19A** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. @@ -357,13 +357,13 @@ The following fields are available: - **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19A** No content is currently available. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19A** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The count of the number of this particular object type present on this device. - **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. - **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. - **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. - **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The count of the number of this particular object type present on this device. - **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. - **InventoryApplicationFile** The count of the number of this particular object type present on this device. - **InventoryLanguagePack** The count of the number of this particular object type present on this device. @@ -381,7 +381,7 @@ The following fields are available: - **SystemWim** The total number of objects of this type present on this device. - **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. - **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19A** No content is currently available. +- **Wmdrm_19A** The count of the number of this particular object type present on this device. - **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. - **Wmdrm_19H1** The count of the number of this particular object type present on this device. - **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. @@ -661,12 +661,6 @@ The following fields are available: - **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? - **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? - **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? -- **TEMP_WuFalseAndCosInbox** No content is currently available. -- **TEMP_WuFalseAndCosOnline** No content is currently available. -- **TEMP_WuFalseAndNoCos** No content is currently available. -- **TEMP_WuTrueAndCosInbox** No content is currently available. -- **TEMP_WuTrueAndCosOnline** No content is currently available. -- **TEMP_WuTrueAndNoCos** No content is currently available. ### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove @@ -2300,7 +2294,7 @@ The following fields are available: - **GPUVendorID** The GPU vendor ID. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** No content is currently available. +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? @@ -3408,7 +3402,7 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager -No content is currently available. +This event returns data about the Update Reserve Manager, including whether it’s been initialized. The following fields are available: @@ -4946,10 +4940,8 @@ This event is sent at the beginning of an app install or update to help keep Win The following fields are available: - **CatalogId** The name of the product catalog from which this app was chosen. -- **fulfillmentPluginId** No content is currently available. - **FulfillmentPluginId** No content is currently available. - **PFN** The Package Family Name of the app that is being installed or updated. -- **pluginTelemetryData** No content is currently available. - **PluginTelemetryData** No content is currently available. - **ProductId** The product ID of the app that is being updated or installed. From c19b9d50fcc815ccaaff9aa5c940f2f37fc23303 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 23 Jan 2019 13:16:16 -0800 Subject: [PATCH 018/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 44 +++++++++++++++++++ 1 file changed, 44 insertions(+) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 8af3ec5e62..569959e879 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -3400,6 +3400,16 @@ The following fields are available: - **Result** The HResult error. +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +No content is currently available. + +The following fields are available: + +- **FinalAdjustment** No content is currently available. +- **InitialAdjustment** No content is currently available. + + ### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager This event returns data about the Update Reserve Manager, including whether it’s been initialized. @@ -3415,6 +3425,23 @@ The following fields are available: - **Version** No content is currently available. +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +No content is currently available. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +No content is currently available. + +The following fields are available: + +- **ChangeSize** No content is currently available. +- **PendingHardReserveAdjustment** No content is currently available. +- **UpdateType** No content is currently available. + + ### Value This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. @@ -5273,6 +5300,23 @@ The following fields are available: - **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **EnterpriseAttributionValue** No content is currently available. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + ### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. From 2c981087b5dde7b2480acb1a5e2944687858a59a Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 24 Jan 2019 08:20:29 -0800 Subject: [PATCH 019/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 376 ++++++++++++++---- 1 file changed, 289 insertions(+), 87 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 569959e879..c7d639913e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/23/2019 +ms.date: 01/24/2019 --- @@ -756,7 +756,7 @@ The following fields are available: ### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). @@ -2161,37 +2161,37 @@ The following fields are available: ### CbsServicingProvider.CbsSelectableUpdateChangeV2 -No content is currently available. +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. The following fields are available: -- **applicableUpdateState** No content is currently available. -- **buildVersion** No content is currently available. -- **clientId** No content is currently available. -- **downloadSource** No content is currently available. -- **downloadtimeInSeconds** No content is currently available. -- **executionID** No content is currently available. -- **executionSequence** No content is currently available. -- **firstMergedExecutionSequence** No content is currently available. -- **firstMergedID** No content is currently available. -- **hrDownloadResult** No content is currently available. -- **hrStatusUpdate** No content is currently available. -- **identityHash** No content is currently available. -- **initiatedOffline** No content is currently available. -- **majorVersion** No content is currently available. -- **minorVersion** No content is currently available. -- **packageArchitecture** No content is currently available. -- **packageLanguage** No content is currently available. -- **packageName** No content is currently available. -- **rebootRequired** No content is currently available. -- **revisionVersion** No content is currently available. -- **stackBuild** No content is currently available. -- **stackMajorVersion** No content is currently available. -- **stackMinorVersion** No content is currently available. -- **stackRevision** No content is currently available. -- **updateName** No content is currently available. -- **updateStartState** No content is currently available. -- **updateTargetState** No content is currently available. +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. ## Diagnostic data events @@ -2249,7 +2249,7 @@ The following fields are available: - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **PrivacyBlockedCount** No content is currently available. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. @@ -3300,7 +3300,7 @@ The following fields are available: - **UserInputTime** The amount of time the loader application spent waiting for user input. -## Other events +## Miracast events ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd @@ -3374,72 +3374,85 @@ The following fields are available: - **WFD2Supported** No content is currently available. -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General +## Other events -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -No content is currently available. - -The following fields are available: - -- **FinalAdjustment** No content is currently available. -- **InitialAdjustment** No content is currently available. - - -### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager - -This event returns data about the Update Reserve Manager, including whether it’s been initialized. - -The following fields are available: - -- **ClientId** No content is currently available. -- **Flags** No content is currently available. -- **FlightId** No content is currently available. -- **Offline** No content is currently available. -- **PolicyPassed** No content is currently available. -- **ReturnCode** No content is currently available. -- **Version** No content is currently available. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment +### Microsoft.Windows.IoT.Client.CEPAL.MonitorStarted No content is currently available. -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 No content is currently available. The following fields are available: -- **ChangeSize** No content is currently available. -- **PendingHardReserveAdjustment** No content is currently available. -- **UpdateType** No content is currently available. +- **autoAssignSite** No content is currently available. +- **autoBalancerLevel** No content is currently available. +- **autoBalancerMode** No content is currently available. +- **blockCacheSize** No content is currently available. +- **ClusterAdConfiguration** No content is currently available. +- **clusterAdType** No content is currently available. +- **clusterDumpPolicy** No content is currently available. +- **clusterFunctionalLevel** No content is currently available. +- **clusterGuid** No content is currently available. +- **clusterWitnessType** No content is currently available. +- **countNodesInSite** No content is currently available. +- **crossSiteDelay** No content is currently available. +- **crossSiteThreshold** No content is currently available. +- **crossSubnetDelay** No content is currently available. +- **crossSubnetThreshold** No content is currently available. +- **csvCompatibleFilters** No content is currently available. +- **csvIncompatibleFilters** No content is currently available. +- **csvResourceCount** No content is currently available. +- **currentNodeSite** No content is currently available. +- **dasModeBusType** No content is currently available. +- **downLevelNodeCount** No content is currently available. +- **drainOnShutdown** No content is currently available. +- **dynamicQuorumEnabled** No content is currently available. +- **enforcedAntiAffinity** No content is currently available. +- **genAppNames** No content is currently available. +- **genSvcNames** No content is currently available. +- **hangRecoveryAction** No content is currently available. +- **hangTimeOut** No content is currently available. +- **isCalabria** No content is currently available. +- **isMixedMode** No content is currently available. +- **isRunningDownLevel** No content is currently available. +- **logLevel** No content is currently available. +- **logSize** No content is currently available. +- **lowerQuorumPriorityNodeId** No content is currently available. +- **minNeverPreempt** No content is currently available. +- **minPreemptor** No content is currently available. +- **netftIpsecEnabled** No content is currently available. +- **NodeCount** No content is currently available. +- **nodeId** No content is currently available. +- **nodeResourceCounts** No content is currently available. +- **nodeResourceOnlineCounts** No content is currently available. +- **numberOfSites** No content is currently available. +- **numNodesInNoSite** No content is currently available. +- **plumbAllCrossSubnetRoutes** No content is currently available. +- **preferredSite** No content is currently available. +- **privateCloudWitness** No content is currently available. +- **quarantineDuration** No content is currently available. +- **quarantineThreshold** No content is currently available. +- **quorumArbitrationTimeout** No content is currently available. +- **resiliencyLevel** No content is currently available. +- **resourceCounts** No content is currently available. +- **resourceTypeCounts** No content is currently available. +- **resourceTypes** No content is currently available. +- **resourceTypesPath** No content is currently available. +- **sameSubnetDelay** No content is currently available. +- **sameSubnetThreshold** No content is currently available. +- **secondsInMixedMode** No content is currently available. +- **securityLevel** No content is currently available. +- **securityLevelForStorage** No content is currently available. +- **sharedVolumeBlockCacheSize** No content is currently available. +- **shutdownTimeoutMinutes** No content is currently available. +- **upNodeCount** No content is currently available. +- **useClientAccessNetworksForCsv** No content is currently available. +- **vmIsolationTime** No content is currently available. +- **witnessDatabaseWriteTimeout** No content is currently available. ### Value @@ -5368,6 +5381,22 @@ The following fields are available: - **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +No content is currently available. + +The following fields are available: + +- **DeviceLocalTime** No content is currently available. +- **ETag** No content is currently available. +- **ExitCode** No content is currently available. +- **RebootVersion** No content is currently available. +- **UpdateId** No content is currently available. +- **UpdateRevision** No content is currently available. +- **UserResponseString** No content is currently available. +- **UtcTime** No content is currently available. + + ### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy This event indicates a policy is present that may restrict update activity to outside of active hours. @@ -5798,6 +5827,32 @@ The following fields are available: ## Windows Update mitigation events +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + ### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. @@ -5845,6 +5900,153 @@ The following fields are available: - **WuId** Unique ID for the Windows Update client. +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.BeginScenario + +No content is currently available. + +The following fields are available: + +- **Flags** No content is currently available. +- **HardReserveSize** No content is currently available. +- **HardReserveUsedSpace** No content is currently available. +- **OwningScenarioId** No content is currently available. +- **ReturnCode** No content is currently available. +- **ScenarioId** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.ClearSoftReserve + +No content is currently available. + + + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +No content is currently available. + +The following fields are available: + +- **FinalAdjustment** No content is currently available. +- **InitialAdjustment** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.EndScenario + +No content is currently available. + +The following fields are available: + +- **ActiveScenario** No content is currently available. +- **Flags** No content is currently available. +- **HardReserveSize** No content is currently available. +- **HardReserveUsedSpace** No content is currently available. +- **ReturnCode** No content is currently available. +- **ScenarioId** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +No content is currently available. + +The following fields are available: + +- **FailedExpression** No content is currently available. +- **FailedFile** No content is currently available. +- **FailedFunction** No content is currently available. +- **FailedLine** No content is currently available. +- **ReturnCode** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.InitializeReserves + +No content is currently available. + +The following fields are available: + +- **FallbackInitUsed** No content is currently available. +- **Flags** No content is currently available. +- **HardReserveFinalSize** No content is currently available. +- **HardReserveFinalUsedSpace** No content is currently available. +- **HardReserveInitialSize** No content is currently available. +- **HardReserveInitialUsedSpace** No content is currently available. +- **HardReserveTargetSize** No content is currently available. +- **InitialUserFreeSpace** No content is currently available. +- **PostUpgradeFreeSpace** No content is currently available. +- **SoftReserveFinalSize** No content is currently available. +- **SoftReserveFinalUsedSpace** No content is currently available. +- **SoftReserveInitialSize** No content is currently available. +- **SoftReserveInitialUsedSpace** No content is currently available. +- **SoftReserveTargetSize** No content is currently available. +- **TargetUserFreeSpace** No content is currently available. +- **UpdateScratchFinalUsedSpace** No content is currently available. +- **UpdateScratchInitialUsedSpace** No content is currently available. +- **UpdateScratchReserveFinalSize** No content is currently available. +- **UpdateScratchReserveInitialSize** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** No content is currently available. +- **Flags** No content is currently available. +- **FlightId** No content is currently available. +- **Offline** No content is currently available. +- **PolicyPassed** No content is currently available. +- **ReturnCode** No content is currently available. +- **Version** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +No content is currently available. + +The following fields are available: + +- **Flags** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.ReevaluatePolicy + +No content is currently available. + +The following fields are available: + +- **PolicyChanged** No content is currently available. +- **PolicyFailedEnum** No content is currently available. +- **PolicyPassed** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +No content is currently available. + + + +### Microsoft.Windows.UpdateReserveManager.TurnOffReserves + +No content is currently available. + +The following fields are available: + +- **Flags** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +No content is currently available. + +The following fields are available: + +- **ChangeSize** No content is currently available. +- **PendingHardReserveAdjustment** No content is currently available. +- **UpdateType** No content is currently available. + + ## Winlogon events ### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon From c89d3c9b014105290f2d1732522eaebb88d80c4a Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 24 Jan 2019 12:20:18 -0800 Subject: [PATCH 020/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 170 +++++++++--------- 1 file changed, 85 insertions(+), 85 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index c7d639913e..4f2cd83eb0 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -700,8 +700,6 @@ The following fields are available: - **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? - **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? - **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **SdbDriverBlockServicing** No content is currently available. -- **SdbDriverBlockSwap** No content is currently available. ### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove @@ -845,8 +843,6 @@ The following fields are available: - **Blocking** Is the device blocked from upgrade due to a BIOS block? - **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. - **HasBiosBlock** Does the device have a BIOS block? -- **HasBiosBlockServicing** No content is currently available. -- **HasBiosBlockSwap** No content is currently available. ### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync @@ -1689,8 +1685,8 @@ The following fields are available: - **InkTypeImprovement** Current state of the improve inking and typing setting. - **Location** Current state of the location setting. - **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** No content is currently available. -- **LocationHistoryOnTimeline** No content is currently available. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. @@ -2319,6 +2315,81 @@ The following fields are available: - **WDDMVersion** The Windows Display Driver Model version. +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +No content is currently available. + +The following fields are available: + +- **autoAssignSite** No content is currently available. +- **autoBalancerLevel** No content is currently available. +- **autoBalancerMode** No content is currently available. +- **blockCacheSize** No content is currently available. +- **ClusterAdConfiguration** No content is currently available. +- **clusterAdType** No content is currently available. +- **clusterDumpPolicy** No content is currently available. +- **clusterFunctionalLevel** No content is currently available. +- **clusterGuid** No content is currently available. +- **clusterWitnessType** No content is currently available. +- **countNodesInSite** No content is currently available. +- **crossSiteDelay** No content is currently available. +- **crossSiteThreshold** No content is currently available. +- **crossSubnetDelay** No content is currently available. +- **crossSubnetThreshold** No content is currently available. +- **csvCompatibleFilters** No content is currently available. +- **csvIncompatibleFilters** No content is currently available. +- **csvResourceCount** No content is currently available. +- **currentNodeSite** No content is currently available. +- **dasModeBusType** No content is currently available. +- **downLevelNodeCount** No content is currently available. +- **drainOnShutdown** No content is currently available. +- **dynamicQuorumEnabled** No content is currently available. +- **enforcedAntiAffinity** No content is currently available. +- **genAppNames** No content is currently available. +- **genSvcNames** No content is currently available. +- **hangRecoveryAction** No content is currently available. +- **hangTimeOut** No content is currently available. +- **isCalabria** No content is currently available. +- **isMixedMode** No content is currently available. +- **isRunningDownLevel** No content is currently available. +- **logLevel** No content is currently available. +- **logSize** No content is currently available. +- **lowerQuorumPriorityNodeId** No content is currently available. +- **minNeverPreempt** No content is currently available. +- **minPreemptor** No content is currently available. +- **netftIpsecEnabled** No content is currently available. +- **NodeCount** No content is currently available. +- **nodeId** No content is currently available. +- **nodeResourceCounts** No content is currently available. +- **nodeResourceOnlineCounts** No content is currently available. +- **numberOfSites** No content is currently available. +- **numNodesInNoSite** No content is currently available. +- **plumbAllCrossSubnetRoutes** No content is currently available. +- **preferredSite** No content is currently available. +- **privateCloudWitness** No content is currently available. +- **quarantineDuration** No content is currently available. +- **quarantineThreshold** No content is currently available. +- **quorumArbitrationTimeout** No content is currently available. +- **resiliencyLevel** No content is currently available. +- **resourceCounts** No content is currently available. +- **resourceTypeCounts** No content is currently available. +- **resourceTypes** No content is currently available. +- **resourceTypesPath** No content is currently available. +- **sameSubnetDelay** No content is currently available. +- **sameSubnetThreshold** No content is currently available. +- **secondsInMixedMode** No content is currently available. +- **securityLevel** No content is currently available. +- **securityLevelForStorage** No content is currently available. +- **sharedVolumeBlockCacheSize** No content is currently available. +- **shutdownTimeoutMinutes** No content is currently available. +- **upNodeCount** No content is currently available. +- **useClientAccessNetworksForCsv** No content is currently available. +- **vmIsolationTime** No content is currently available. +- **witnessDatabaseWriteTimeout** No content is currently available. + + ## Fault Reporting events ### Microsoft.Windows.FaultReporting.AppCrashEvent @@ -3258,6 +3329,14 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic +## IoT events + +### Microsoft.Windows.IoT.Client.CEPAL.MonitorStarted + +No content is currently available. + + + ## Kernel events ### IO @@ -3376,85 +3455,6 @@ The following fields are available: ## Other events -### Microsoft.Windows.IoT.Client.CEPAL.MonitorStarted - -No content is currently available. - - - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -No content is currently available. - -The following fields are available: - -- **autoAssignSite** No content is currently available. -- **autoBalancerLevel** No content is currently available. -- **autoBalancerMode** No content is currently available. -- **blockCacheSize** No content is currently available. -- **ClusterAdConfiguration** No content is currently available. -- **clusterAdType** No content is currently available. -- **clusterDumpPolicy** No content is currently available. -- **clusterFunctionalLevel** No content is currently available. -- **clusterGuid** No content is currently available. -- **clusterWitnessType** No content is currently available. -- **countNodesInSite** No content is currently available. -- **crossSiteDelay** No content is currently available. -- **crossSiteThreshold** No content is currently available. -- **crossSubnetDelay** No content is currently available. -- **crossSubnetThreshold** No content is currently available. -- **csvCompatibleFilters** No content is currently available. -- **csvIncompatibleFilters** No content is currently available. -- **csvResourceCount** No content is currently available. -- **currentNodeSite** No content is currently available. -- **dasModeBusType** No content is currently available. -- **downLevelNodeCount** No content is currently available. -- **drainOnShutdown** No content is currently available. -- **dynamicQuorumEnabled** No content is currently available. -- **enforcedAntiAffinity** No content is currently available. -- **genAppNames** No content is currently available. -- **genSvcNames** No content is currently available. -- **hangRecoveryAction** No content is currently available. -- **hangTimeOut** No content is currently available. -- **isCalabria** No content is currently available. -- **isMixedMode** No content is currently available. -- **isRunningDownLevel** No content is currently available. -- **logLevel** No content is currently available. -- **logSize** No content is currently available. -- **lowerQuorumPriorityNodeId** No content is currently available. -- **minNeverPreempt** No content is currently available. -- **minPreemptor** No content is currently available. -- **netftIpsecEnabled** No content is currently available. -- **NodeCount** No content is currently available. -- **nodeId** No content is currently available. -- **nodeResourceCounts** No content is currently available. -- **nodeResourceOnlineCounts** No content is currently available. -- **numberOfSites** No content is currently available. -- **numNodesInNoSite** No content is currently available. -- **plumbAllCrossSubnetRoutes** No content is currently available. -- **preferredSite** No content is currently available. -- **privateCloudWitness** No content is currently available. -- **quarantineDuration** No content is currently available. -- **quarantineThreshold** No content is currently available. -- **quorumArbitrationTimeout** No content is currently available. -- **resiliencyLevel** No content is currently available. -- **resourceCounts** No content is currently available. -- **resourceTypeCounts** No content is currently available. -- **resourceTypes** No content is currently available. -- **resourceTypesPath** No content is currently available. -- **sameSubnetDelay** No content is currently available. -- **sameSubnetThreshold** No content is currently available. -- **secondsInMixedMode** No content is currently available. -- **securityLevel** No content is currently available. -- **securityLevelForStorage** No content is currently available. -- **sharedVolumeBlockCacheSize** No content is currently available. -- **shutdownTimeoutMinutes** No content is currently available. -- **upNodeCount** No content is currently available. -- **useClientAccessNetworksForCsv** No content is currently available. -- **vmIsolationTime** No content is currently available. -- **witnessDatabaseWriteTimeout** No content is currently available. - - ### Value This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. From 69a68a7a7efe6fe5bec75034cec1800f72b2cd64 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 25 Jan 2019 09:07:55 -0800 Subject: [PATCH 021/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 58 +++++++++---------- 1 file changed, 29 insertions(+), 29 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 4f2cd83eb0..5675334faa 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/24/2019 +ms.date: 01/25/2019 --- @@ -858,24 +858,24 @@ The following fields are available: ### Microsoft.Windows.Appraiser.General.DecisionTestRemove -No content is currently available. +This event provides data that allows testing of “Remove” decisions to help keep Windows up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: -- **AppraiserVersion** No content is currently available. +- **AppraiserVersion** The version of the appraiser binary (executable) generating the events. ### Microsoft.Windows.Appraiser.General.DecisionTestStartSync -No content is currently available. +This event provides data that allows testing of “Start Sync” decisions to help keep Windows up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: -- **AppraiserVersion** No content is currently available. +- **AppraiserVersion** The version of the appraiser binary (executable) generating the events. ### Microsoft.Windows.Appraiser.General.GatedRegChange @@ -1046,24 +1046,24 @@ The following fields are available: ### Microsoft.Windows.Appraiser.General.InventoryTestRemove -No content is currently available. +This event provides data that allows testing of “Remove” decisions to help keep Windows up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: -- **AppraiserVersion** No content is currently available. +- **AppraiserVersion** The version of the appraiser binary (executable) generating the events. ### Microsoft.Windows.Appraiser.General.InventoryTestStartSync -No content is currently available. +This event provides data that allows testing of “Start Sync” decisions to help keep Windows up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: -- **AppraiserVersion** No content is currently available. +- **AppraiserVersion** The version of the appraiser binary (executable) generating the events. ### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd @@ -1533,7 +1533,7 @@ This event sends Windows Insider data from customers participating in improvemen The following fields are available: - **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **DriverTargetRing** No content is currently available. +- **DriverTargetRing** Indicates if the device is participating in receiving pre-release drivers and firmware contrent. - **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. - **FlightIds** A list of the different Windows Insider builds on this device. - **FlightingBranchName** The name of the Windows Insider branch currently used by the device. @@ -1850,8 +1850,8 @@ The following fields are available: - **InkTypePersonalization** Current state of the inking and typing personalization setting. - **Location** Current state of the location setting. - **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** No content is currently available. -- **LocationHistoryOnTimeline** No content is currently available. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. @@ -2574,28 +2574,28 @@ The following fields are available: ### Microsoft.Windows.Inventory.Core.InventoryApplicationFileAdd -No content is currently available. +This event provides file-level information about the applications that exist on the system. This event is used to understand the applications on a device to determine if those applications will experience compatibility issues when upgrading Windows. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: -- **BinaryType** No content is currently available. -- **BinFileVersion** No content is currently available. -- **BinProductVersion** No content is currently available. -- **BoeProgramId** No content is currently available. -- **CompanyName** No content is currently available. -- **FileId** No content is currently available. -- **FileVersion** No content is currently available. -- **InventoryVersion** No content is currently available. -- **Language** No content is currently available. -- **LinkDate** No content is currently available. -- **LowerCaseLongPath** No content is currently available. -- **Name** No content is currently available. -- **ProductName** No content is currently available. -- **ProductVersion** No content is currently available. -- **ProgramId** No content is currently available. -- **Size** No content is currently available. +- **BinaryType** The architecture of the binary (executable) file. +- **BinFileVersion** Version information for the binary (executable) file. +- **BinProductVersion** The product version provided by the binary (executable) file. +- **BoeProgramId** The “bag of evidence” program identifier. +- **CompanyName** The company name included in the binary (executable) file. +- **FileId** A pseudonymized (hashed) unique identifier derived from the file itself. +- **FileVersion** The version of the file. +- **InventoryVersion** The version of the inventory component. +- **Language** The language declared in the binary (executable) file. +- **LinkDate** The compiler link date. +- **LowerCaseLongPath** The file path in “long” format. +- **Name** The file name. +- **ProductName** The product name declared in the binary (executable) file. +- **ProductVersion** The product version declared in the binary (executable) file. +- **ProgramId** The program identifier associated with the binary (executable) file. +- **Size** The size of the binary (executable) file. ### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd From d7a06c7cf6a56ebcbc7f249e82b65b597bc6c649 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 28 Jan 2019 11:36:37 -0800 Subject: [PATCH 022/737] new build --- .../basic-level-windows-diagnostic-events-and-fields-19H1.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 5675334faa..e54b7bbbad 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/25/2019 +ms.date: 01/28/2019 --- From 96ab744003029a05fb2d0ea59e3f34af1d22d620 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 1 Feb 2019 09:05:09 -0800 Subject: [PATCH 023/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 153 +++++++++++++++--- 1 file changed, 133 insertions(+), 20 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index e54b7bbbad..feff722d43 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 01/28/2019 +ms.date: 02/01/2019 --- @@ -625,6 +625,17 @@ The following fields are available: - **SoftBlock** The file is softblocked in the SDB and has a warning. +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + ### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync This event indicates that a new set of DecisionApplicationFileAdd events will be sent. @@ -1122,7 +1133,7 @@ The following fields are available: - **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. - **AppraiserProcess** The name of the process that launched Appraiser. - **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** No content is currently available. +- **CensusId** A unique hardware identifier. - **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. - **PCFP** An ID for the system calculated by hashing hardware identifiers. - **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. @@ -1773,7 +1784,7 @@ The following fields are available: - **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. - **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** No content is currently available. +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. - **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. @@ -2155,6 +2166,42 @@ The following fields are available: - **pendingDecision** Indicates the cause of reboot, if applicable. +### CbsServicingProvider.CbsQualityUpdateInstall + +No content is currently available. + +The following fields are available: + +- **buildVersion** No content is currently available. +- **clientId** No content is currently available. +- **corruptionHistoryFlags** No content is currently available. +- **corruptionType** No content is currently available. +- **currentStateEnd** No content is currently available. +- **doqTimeSeconds** No content is currently available. +- **executeTimeSeconds** No content is currently available. +- **failureDetails** No content is currently available. +- **failureSourceEnd** No content is currently available. +- **hrStatusEnd** No content is currently available. +- **initiatedOffline** No content is currently available. +- **majorVersion** No content is currently available. +- **minorVersion** No content is currently available. +- **originalState** No content is currently available. +- **overallTimeSeconds** No content is currently available. +- **planTimeSeconds** No content is currently available. +- **poqTimeSeconds** No content is currently available. +- **postRebootTimeSeconds** No content is currently available. +- **preRebootTimeSeconds** No content is currently available. +- **primitiveExecutionContext** No content is currently available. +- **rebootCount** No content is currently available. +- **rebootTimeSeconds** No content is currently available. +- **resolveTimeSeconds** No content is currently available. +- **revisionVersion** No content is currently available. +- **rptTimeSeconds** No content is currently available. +- **shutdownTimeSeconds** No content is currently available. +- **stackRevision** No content is currently available. +- **stageTimeSeconds** No content is currently available. + + ### CbsServicingProvider.CbsSelectableUpdateChangeV2 This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. @@ -2781,7 +2828,7 @@ The following fields are available: - **COMPID** The device setup class guid of the driver loaded for the device. - **ContainerId** The list of compat ids for the device. - **Description** System-supplied GUID that uniquely groups the functional devices associated with a single-function or multifunction device installed in the computer. -- **DeviceInterfaceClasses** No content is currently available. +- **DeviceInterfaceClasses** The device interfaces that this device implements. - **DeviceState** The device description. - **DriverId** DeviceState is a bitmask of the following: DEVICE_IS_CONNECTED 0x0001 (currently only for container). DEVICE_IS_NETWORK_DEVICE 0x0002 (currently only for container). DEVICE_IS_PAIRED 0x0004 (currently only for container). DEVICE_IS_ACTIVE 0x0008 (currently never set). DEVICE_IS_MACHINE 0x0010 (currently only for container). DEVICE_IS_PRESENT 0x0020 (currently always set). DEVICE_IS_HIDDEN 0x0040. DEVICE_IS_PRINTER 0x0080 (currently only for container). DEVICE_IS_WIRELESS 0x0100. DEVICE_IS_WIRELESS_FAT 0x0200. The most common values are therefore: 32 (0x20)= device is present. 96 (0x60)= device is present but hidden. 288 (0x120)= device is a wireless device that is present - **DriverName** A unique identifier for the driver installed. @@ -3455,6 +3502,28 @@ The following fields are available: ## Other events +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + ### Value This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. @@ -3469,6 +3538,36 @@ The following fields are available: - **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. +### WheaProvider.WheaErrorRecord + +No content is currently available. + +The following fields are available: + +- **creatorId** No content is currently available. +- **CreatorId** No content is currently available. +- **errorFlags** No content is currently available. +- **ErrorFlags** No content is currently available. +- **notifyType** No content is currently available. +- **NotifyType** No content is currently available. +- **partitionId** No content is currently available. +- **PartitionId** No content is currently available. +- **platformId** No content is currently available. +- **PlatformId** No content is currently available. +- **record** No content is currently available. +- **Record** No content is currently available. +- **recordId** No content is currently available. +- **RecordId** No content is currently available. +- **sectionFlags** No content is currently available. +- **SectionFlags** No content is currently available. +- **SectionSeverity** No content is currently available. +- **sectionTypes** No content is currently available. +- **SectionTypes** No content is currently available. +- **severityCount** No content is currently available. +- **timeStamp** No content is currently available. +- **TimeStamp** No content is currently available. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted @@ -3512,6 +3611,17 @@ The following fields are available: - **Time** The time the event was fired. +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + ## Setup events ### SetupPlatformTel.SetupPlatformTelActivityEvent @@ -3828,7 +3938,7 @@ The following fields are available: - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. - **CSIErrorType** The stage of CBS installation where it failed. - **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** No content is currently available. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** The device model. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. @@ -4088,10 +4198,12 @@ The following fields are available: - **PackageCountTotalCanonical** Total number of canonical packages. - **PackageCountTotalDiff** Total number of diff packages. - **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** No content is currently available. - **PackageExpressType** Type of express package. - **PackageSizeCanonical** Size of canonical packages in bytes. - **PackageSizeDiff** Size of diff packages in bytes. - **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** No content is currently available. - **RangeRequestState** Indicates the range request type used. - **RelatedCV** Correlation vector value generated from the latest USO scan. - **Result** Outcome of the download request phase of update. @@ -4106,6 +4218,7 @@ This event collects information regarding the expansion phase of the new Unified The following fields are available: +- **CanonicalRequestedOnError** No content is currently available. - **ElapsedTickCount** Time taken for expand phase. - **EndFreeSpace** Free space after expand phase. - **EndSandboxSize** Sandbox size after expand phase. @@ -4336,7 +4449,7 @@ The following fields are available: - **ResultCode** Result returned by the Facilitator DCAT call. - **Scenario** Dynamic update scenario (Image DU, or Setup DU). - **Type** Type of package that was downloaded. -- **UpdateId** No content is currently available. +- **UpdateId** The ID of the update that was downloaded. ### FacilitatorTelemetry.InitializeDU @@ -4980,9 +5093,9 @@ This event is sent at the beginning of an app install or update to help keep Win The following fields are available: - **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** No content is currently available. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. - **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** No content is currently available. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. - **ProductId** The product ID of the app that is being updated or installed. @@ -5151,7 +5264,7 @@ The following fields are available: - **bytesFromCDN** The number of bytes received from a CDN source. - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** No content is currently available. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. - **bytesRequested** The total number of bytes requested for download. @@ -5181,7 +5294,7 @@ The following fields are available: - **lanConnectionCount** The total number of connections made to peers in the same LAN. - **linkLocalConnectionCount** No content is currently available. - **numPeers** The total number of peers used for this download. -- **numPeersLocal** No content is currently available. +- **numPeersLocal** The total number of local peers used for this download. - **predefinedCallerName** The name of the API Caller. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. @@ -5228,7 +5341,7 @@ The following fields are available: - **doClientVersion** The version of the Delivery Optimization client. - **doErrorCode** The Delivery Optimization error code that was returned. - **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** No content is currently available. +- **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **errorCode** The error code that was returned. - **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. @@ -5383,18 +5496,18 @@ The following fields are available: ### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast -No content is currently available. +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. The following fields are available: -- **DeviceLocalTime** No content is currently available. -- **ETag** No content is currently available. -- **ExitCode** No content is currently available. -- **RebootVersion** No content is currently available. -- **UpdateId** No content is currently available. -- **UpdateRevision** No content is currently available. -- **UserResponseString** No content is currently available. -- **UtcTime** No content is currently available. +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. ### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy From 52d04855120793db0365d00d11cee4e7f6b9ecd6 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 4 Feb 2019 10:30:35 -0800 Subject: [PATCH 024/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 278 ++++++++++-------- 1 file changed, 153 insertions(+), 125 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index feff722d43..3c14a15736 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/01/2019 +ms.date: 02/04/2019 --- @@ -2168,38 +2168,38 @@ The following fields are available: ### CbsServicingProvider.CbsQualityUpdateInstall -No content is currently available. +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. The following fields are available: -- **buildVersion** No content is currently available. -- **clientId** No content is currently available. -- **corruptionHistoryFlags** No content is currently available. -- **corruptionType** No content is currently available. -- **currentStateEnd** No content is currently available. -- **doqTimeSeconds** No content is currently available. -- **executeTimeSeconds** No content is currently available. -- **failureDetails** No content is currently available. -- **failureSourceEnd** No content is currently available. -- **hrStatusEnd** No content is currently available. -- **initiatedOffline** No content is currently available. -- **majorVersion** No content is currently available. -- **minorVersion** No content is currently available. -- **originalState** No content is currently available. -- **overallTimeSeconds** No content is currently available. -- **planTimeSeconds** No content is currently available. -- **poqTimeSeconds** No content is currently available. -- **postRebootTimeSeconds** No content is currently available. -- **preRebootTimeSeconds** No content is currently available. -- **primitiveExecutionContext** No content is currently available. -- **rebootCount** No content is currently available. -- **rebootTimeSeconds** No content is currently available. -- **resolveTimeSeconds** No content is currently available. -- **revisionVersion** No content is currently available. -- **rptTimeSeconds** No content is currently available. -- **shutdownTimeSeconds** No content is currently available. -- **stackRevision** No content is currently available. -- **stageTimeSeconds** No content is currently available. +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. ### CbsServicingProvider.CbsSelectableUpdateChangeV2 @@ -2366,75 +2366,75 @@ The following fields are available: ### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 -No content is currently available. +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. The following fields are available: -- **autoAssignSite** No content is currently available. -- **autoBalancerLevel** No content is currently available. -- **autoBalancerMode** No content is currently available. -- **blockCacheSize** No content is currently available. -- **ClusterAdConfiguration** No content is currently available. -- **clusterAdType** No content is currently available. -- **clusterDumpPolicy** No content is currently available. -- **clusterFunctionalLevel** No content is currently available. -- **clusterGuid** No content is currently available. -- **clusterWitnessType** No content is currently available. -- **countNodesInSite** No content is currently available. -- **crossSiteDelay** No content is currently available. -- **crossSiteThreshold** No content is currently available. -- **crossSubnetDelay** No content is currently available. -- **crossSubnetThreshold** No content is currently available. -- **csvCompatibleFilters** No content is currently available. -- **csvIncompatibleFilters** No content is currently available. -- **csvResourceCount** No content is currently available. -- **currentNodeSite** No content is currently available. -- **dasModeBusType** No content is currently available. -- **downLevelNodeCount** No content is currently available. -- **drainOnShutdown** No content is currently available. -- **dynamicQuorumEnabled** No content is currently available. -- **enforcedAntiAffinity** No content is currently available. -- **genAppNames** No content is currently available. -- **genSvcNames** No content is currently available. -- **hangRecoveryAction** No content is currently available. -- **hangTimeOut** No content is currently available. -- **isCalabria** No content is currently available. -- **isMixedMode** No content is currently available. -- **isRunningDownLevel** No content is currently available. -- **logLevel** No content is currently available. -- **logSize** No content is currently available. -- **lowerQuorumPriorityNodeId** No content is currently available. -- **minNeverPreempt** No content is currently available. -- **minPreemptor** No content is currently available. -- **netftIpsecEnabled** No content is currently available. -- **NodeCount** No content is currently available. -- **nodeId** No content is currently available. -- **nodeResourceCounts** No content is currently available. -- **nodeResourceOnlineCounts** No content is currently available. -- **numberOfSites** No content is currently available. -- **numNodesInNoSite** No content is currently available. -- **plumbAllCrossSubnetRoutes** No content is currently available. -- **preferredSite** No content is currently available. -- **privateCloudWitness** No content is currently available. -- **quarantineDuration** No content is currently available. -- **quarantineThreshold** No content is currently available. -- **quorumArbitrationTimeout** No content is currently available. -- **resiliencyLevel** No content is currently available. -- **resourceCounts** No content is currently available. -- **resourceTypeCounts** No content is currently available. -- **resourceTypes** No content is currently available. -- **resourceTypesPath** No content is currently available. -- **sameSubnetDelay** No content is currently available. -- **sameSubnetThreshold** No content is currently available. -- **secondsInMixedMode** No content is currently available. -- **securityLevel** No content is currently available. -- **securityLevelForStorage** No content is currently available. -- **sharedVolumeBlockCacheSize** No content is currently available. -- **shutdownTimeoutMinutes** No content is currently available. -- **upNodeCount** No content is currently available. -- **useClientAccessNetworksForCsv** No content is currently available. -- **vmIsolationTime** No content is currently available. -- **witnessDatabaseWriteTimeout** No content is currently available. +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. ## Fault Reporting events @@ -3568,6 +3568,32 @@ The following fields are available: - **TimeStamp** No content is currently available. +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **hrspult** No content is currently available. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted @@ -3764,7 +3790,7 @@ The following fields are available: - **BundleRevisionNumber** Identifies the revision number of the content bundle - **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client - **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** No content is currently available. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** Device model as defined in the system bios - **EventInstanceID** A globally unique identifier for event instance - **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. @@ -3786,10 +3812,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashFailures** No content is currently available. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** Indicates the scope of the app download. +- **AppXScope** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -3798,18 +3824,18 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailCount** No content is currently available. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CbsMethod** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **ConnectTime** No content is currently available. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. @@ -3843,7 +3869,7 @@ The following fields are available: - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailCount** No content is currently available. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -4207,6 +4233,7 @@ The following fields are available: - **RangeRequestState** Indicates the range request type used. - **RelatedCV** Correlation vector value generated from the latest USO scan. - **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** No content is currently available. - **ScenarioId** Indicates the update scenario. - **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). - **UpdateId** Unique ID for each update. @@ -5282,6 +5309,7 @@ The following fields are available: - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **expiresAt** No content is currently available. - **fileID** The ID of the file being downloaded. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. @@ -5630,7 +5658,7 @@ The following fields are available: - **EventPublishedTime** Time when this event was generated. - **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** No content is currently available. +- **inapplicableReason** The reason why the update is inapplicable. - **revisionNumber** Update revision number. - **updateId** Unique Windows Update ID. - **updateScenarioType** Update session type. @@ -6037,12 +6065,12 @@ No content is currently available. ### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment -No content is currently available. +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. The following fields are available: -- **FinalAdjustment** No content is currently available. -- **InitialAdjustment** No content is currently available. +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition or removal of optional content. ### Microsoft.Windows.UpdateReserveManager.EndScenario @@ -6061,15 +6089,15 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError -No content is currently available. +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. The following fields are available: -- **FailedExpression** No content is currently available. -- **FailedFile** No content is currently available. -- **FailedFunction** No content is currently available. -- **FailedLine** No content is currently available. -- **ReturnCode** No content is currently available. +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. ### Microsoft.Windows.UpdateReserveManager.InitializeReserves @@ -6105,22 +6133,22 @@ This event returns data about the Update Reserve Manager, including whether it The following fields are available: -- **ClientId** No content is currently available. -- **Flags** No content is currently available. -- **FlightId** No content is currently available. -- **Offline** No content is currently available. -- **PolicyPassed** No content is currently available. -- **ReturnCode** No content is currently available. +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. - **Version** No content is currently available. ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization -No content is currently available. +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. The following fields are available: -- **Flags** No content is currently available. +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. ### Microsoft.Windows.UpdateReserveManager.ReevaluatePolicy @@ -6136,7 +6164,7 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment -No content is currently available. +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. @@ -6155,9 +6183,9 @@ No content is currently available. The following fields are available: -- **ChangeSize** No content is currently available. -- **PendingHardReserveAdjustment** No content is currently available. -- **UpdateType** No content is currently available. +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. ## Winlogon events From 7fba077da2a1231a84cd1f7df3eb213dafe58a1c Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 5 Feb 2019 08:44:22 -0800 Subject: [PATCH 025/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 20 +++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 3c14a15736..84c660017a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/04/2019 +ms.date: 02/05/2019 --- @@ -3812,10 +3812,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** No content is currently available. +- **AppXScope** Indicates the scope of the app download. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -3824,18 +3824,18 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** No content is currently available. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** No content is currently available. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. @@ -3869,7 +3869,7 @@ The following fields are available: - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -4233,7 +4233,7 @@ The following fields are available: - **RangeRequestState** Indicates the range request type used. - **RelatedCV** Correlation vector value generated from the latest USO scan. - **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** No content is currently available. +- **SandboxTaggedForReserves** The sandbox for reserves. - **ScenarioId** Indicates the update scenario. - **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). - **UpdateId** Unique ID for each update. @@ -6139,7 +6139,7 @@ The following fields are available: - **Offline** Indicates whether or the reserve manager is called during offline operations. - **PolicyPassed** Indicates whether the machine is able to use reserves. - **ReturnCode** Return code of the operation. -- **Version** No content is currently available. +- **Version** The version of the Update Reserve Manager. ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization @@ -6179,7 +6179,7 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment -No content is currently available. +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. The following fields are available: From 42fc5689fb6b83944eb5facbe9717f16e6bde48e Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 6 Feb 2019 08:39:31 -0800 Subject: [PATCH 026/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 496 ++++++++++++------ 1 file changed, 337 insertions(+), 159 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 84c660017a..77792963db 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/05/2019 +ms.date: 02/06/2019 --- @@ -81,6 +81,16 @@ The following fields are available: - **txId** The unique identifier for the current CSP transaction. +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + ### Microsoft.Windows.Security.AppLockerCSP.ClearParams Parameters passed to the "Clear" operation for AppLockerCSP. @@ -90,6 +100,21 @@ The following fields are available: - **uri** The URI relative to the %SYSTEM32%\AppLocker folder. +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + ### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart Start of the "ConfigManagerNotification" operation for AppLockerCSP. @@ -144,6 +169,21 @@ The following fields are available: - **uri** URI relative to %SYSTEM32%\AppLocker. +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + ### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. @@ -2239,6 +2279,43 @@ The following fields are available: ## Diagnostic data events +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + ### TelClientSynthetic.ConnectivityHeartBeat_0 This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. @@ -2254,6 +2331,22 @@ The following fields are available: - **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. +### TelClientSynthetic.EventMonitor_0 + +No content is currently available. + +The following fields are available: + +- **ConsumerCount** No content is currently available. +- **EventName** No content is currently available. +- **EventSnFirst** No content is currently available. +- **EventSnLast** No content is currently available. +- **EventStoreCount** No content is currently available. +- **MonitorSn** No content is currently available. +- **TriggerCount** No content is currently available. +- **UploadedCount** No content is currently available. + + ### TelClientSynthetic.HeartBeat_5 This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. @@ -2558,7 +2651,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: - **CatalogSigners** Signers from catalog. Each signer starts with Chain. -- **DigestAlgorithm** No content is currently available. +- **DigestAlgorithm** The pseudonymizing (hashing) algorithm used when the file or package was signed. - **DriverPackageStrongName** Optional. Available only if FileSigningInfo is collected on a driver package. - **EmbeddedSigners** Embedded signers. Each signer starts with Chain. - **FileName** The file name of the file whose signatures are listed. @@ -2702,7 +2795,6 @@ The following fields are available: - **Categories** A comma separated list of functional categories in which the container belongs. - **DiscoveryMethod** The discovery method for the device container. - **FriendlyName** The name of the device container. -- **Icon** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. - **IsActive** Is the device connected, or has it been seen in the last 14 days? - **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. @@ -3354,7 +3446,7 @@ The following fields are available: ### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorEndSync -No content is currently available. +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events has been sent. This data helps ensure the device is up to date. This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). @@ -3380,7 +3472,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic ### Microsoft.Windows.IoT.Client.CEPAL.MonitorStarted -No content is currently available. +This event identifies Windows Internet of Things (IoT) devices which are running the CE PAL subsystem by sending data during CE PAL startup. @@ -3430,77 +3522,164 @@ The following fields are available: ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## Other events + +### Microsoft.Windows.SysReset.FlightUninstallCancel + +No content is currently available. + + + +### Microsoft.Windows.SysReset.FlightUninstallError + No content is currently available. The following fields are available: -- **AudioChannelCount** No content is currently available. -- **AudioSampleRate** No content is currently available. -- **AudioSubtype** No content is currently available. -- **AverageBitrate** No content is currently available. -- **AverageDataRate** No content is currently available. -- **AveragePacketSendTimeInMs** No content is currently available. -- **ConnectorType** No content is currently available. -- **EncodeAverageTimeMS** No content is currently available. -- **EncodeCount** No content is currently available. -- **EncodeMaxTimeMS** No content is currently available. -- **EncodeMinTimeMS** No content is currently available. -- **EncoderCreationTimeInMs** No content is currently available. -- **ErrorSource** No content is currently available. -- **FirstFrameTime** No content is currently available. -- **FirstLatencyMode** No content is currently available. -- **FrameAverageTimeMS** No content is currently available. -- **FrameCount** No content is currently available. -- **FrameMaxTimeMS** No content is currently available. -- **FrameMinTimeMS** No content is currently available. -- **Glitches** No content is currently available. -- **HardwareCursorEnabled** No content is currently available. -- **HDCPState** No content is currently available. -- **HighestBitrate** No content is currently available. -- **HighestDataRate** No content is currently available. -- **LastLatencyMode** No content is currently available. -- **LogTimeReference** No content is currently available. -- **LowestBitrate** No content is currently available. -- **LowestDataRate** No content is currently available. -- **MediaErrorCode** No content is currently available. -- **MiracastEntry** No content is currently available. -- **MiracastM1** No content is currently available. -- **MiracastM2** No content is currently available. -- **MiracastM3** No content is currently available. -- **MiracastM4** No content is currently available. -- **MiracastM5** No content is currently available. -- **MiracastM6** No content is currently available. -- **MiracastM7** No content is currently available. -- **MiracastSessionState** No content is currently available. -- **MiracastStreaming** No content is currently available. -- **ProfileCount** No content is currently available. -- **ProfileCountAfterFiltering** No content is currently available. -- **RefreshRate** No content is currently available. -- **RotationSupported** No content is currently available. -- **RTSPSessionId** No content is currently available. -- **SessionGuid** No content is currently available. -- **SinkHadEdid** No content is currently available. -- **SupportMicrosoftColorSpaceConversion** No content is currently available. -- **SupportsMicrosoftDiagnostics** No content is currently available. -- **SupportsMicrosoftFormatChange** No content is currently available. -- **SupportsMicrosoftLatencyManagement** No content is currently available. -- **SupportsMicrosoftRTCP** No content is currently available. -- **SupportsMicrosoftVideoFormats** No content is currently available. -- **SupportsWiDi** No content is currently available. -- **TeardownErrorCode** No content is currently available. -- **TeardownErrorReason** No content is currently available. -- **UIBCEndState** No content is currently available. -- **UIBCEverEnabled** No content is currently available. -- **UIBCStatus** No content is currently available. -- **VideoBitrate** No content is currently available. -- **VideoCodecLevel** No content is currently available. -- **VideoHeight** No content is currently available. -- **VideoSubtype** No content is currently available. -- **VideoWidth** No content is currently available. -- **WFD2Supported** No content is currently available. +- **ErrorCode** No content is currently available. -## Other events +### Microsoft.Windows.SysReset.FlightUninstallReboot + +No content is currently available. + + + +### Microsoft.Windows.SysReset.FlightUninstallStart + +No content is currently available. + + + +### Microsoft.Windows.SysReset.FlightUninstallUnavailable + +No content is currently available. + +The following fields are available: + +- **AddedProfiles** No content is currently available. +- **MissingExternalStorage** No content is currently available. +- **MissingInfra** No content is currently available. +- **MovedProfiles** No content is currently available. + + +### Microsoft.Windows.SysReset.HasPendingActions + +No content is currently available. + + + +### Microsoft.Windows.SysReset.PBREngineInitFailed + +No content is currently available. + +The following fields are available: + +- **Operation** No content is currently available. + + +### Microsoft.Windows.SysReset.PBREngineInitSucceed + +No content is currently available. + +The following fields are available: + +- **Operation** No content is currently available. + + +### Microsoft.Windows.SysReset.PBRFailedOffline + +No content is currently available. + +The following fields are available: + +- **HRESULT** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + ### Microsoft.Xbox.XamTelemetry.AppActivity @@ -3540,32 +3719,32 @@ The following fields are available: ### WheaProvider.WheaErrorRecord -No content is currently available. +This event collects data about common platform hardware error recorded by the Windows Hardware Error Architecture (WHEA) mechanism. The following fields are available: -- **creatorId** No content is currently available. -- **CreatorId** No content is currently available. -- **errorFlags** No content is currently available. -- **ErrorFlags** No content is currently available. -- **notifyType** No content is currently available. -- **NotifyType** No content is currently available. -- **partitionId** No content is currently available. -- **PartitionId** No content is currently available. -- **platformId** No content is currently available. -- **PlatformId** No content is currently available. -- **record** No content is currently available. -- **Record** No content is currently available. -- **recordId** No content is currently available. -- **RecordId** No content is currently available. -- **sectionFlags** No content is currently available. -- **SectionFlags** No content is currently available. -- **SectionSeverity** No content is currently available. -- **sectionTypes** No content is currently available. -- **SectionTypes** No content is currently available. -- **severityCount** No content is currently available. -- **timeStamp** No content is currently available. -- **TimeStamp** No content is currently available. +- **creatorId** The unique identifier for the entity that created the error record. +- **CreatorId** The unique identifier for the entity that created the error record. +- **errorFlags** Any flags set on the error record. +- **ErrorFlags** Any flags set on the error record. +- **notifyType** The unique identifier for the notification mechanism which reported the error to the operating system. +- **NotifyType** The unique identifier for the notification mechanism which reported the error to the operating system. +- **partitionId** The unique identifier for the partition on which the hardware error occurred. +- **PartitionId** The unique identifier for the partition on which the hardware error occurred. +- **platformId** The unique identifier for the platform on which the hardware error occurred. +- **PlatformId** The unique identifier for the platform on which the hardware error occurred. +- **record** A collection of binary data containing the full error record. +- **Record** A collection of binary data containing the full error record. +- **recordId** The identifier of the error record. +- **RecordId** The identifier of the error record. +- **sectionFlags** The flags for each section recorded in the error record. +- **SectionFlags** The flags for each section recorded in the error record. +- **SectionSeverity** The severity of each individual section. +- **sectionTypes** The unique identifier that represents the type of sections contained in the error record. +- **SectionTypes** The unique identifier that represents the type of sections contained in the error record. +- **severityCount** The severity of each individual section. +- **timeStamp** The error time stamp as recorded in the error record. +- **TimeStamp** The error time stamp as recorded in the error record. ### wilActivity @@ -3584,7 +3763,6 @@ The following fields are available: - **fileName** The file name where the failure occurred. - **function** The function where the failure occurred. - **hresult** The HResult of the overall activity. -- **hrspult** No content is currently available. - **lineNumber** The line number where the failure occurred. - **message** The message of the failure that occurred. - **module** The module where the failure occurred. @@ -4028,7 +4206,7 @@ The following fields are available: - **ClientVersion** Version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. - **CSIErrorType** Stage of CBS installation that failed. -- **DeploymentProviderMode** No content is currently available. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. @@ -4072,7 +4250,7 @@ The following fields are available: - **CmdLineArgs** Command line arguments passed in by the caller. - **EventInstanceID** A globally unique identifier for the event instance. - **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **Mode** No content is currently available. +- **Mode** Indicates the mode that has started. - **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). - **StatusCode** Result code of the event (success, cancellation, failure code HResult). - **WUDeviceID** Unique device ID controlled by the software distribution client. @@ -4090,7 +4268,7 @@ The following fields are available: - **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. - **ClientVersion** Version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DeploymentProviderMode** No content is currently available. +- **DeploymentProviderMode** The mode of operation of the Update Deployment Provider. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. @@ -4792,20 +4970,20 @@ Result of the WaaSMedic operation. The following fields are available: - **callerApplication** The name of the calling application. -- **capsuleCount** No content is currently available. -- **capsuleFailureCount** No content is currently available. +- **capsuleCount** The number of Sediment Pack capsules. +- **capsuleFailureCount** The number of capsule failures. - **detectionSummary** Result of each applicable detection that was run. - **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineBlockReason** No content is currently available. +- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. - **hrEngineResult** Error code from the engine operation. -- **hrLastSandboxError** No content is currently available. -- **initSummary** No content is currently available. +- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. +- **initSummary** Summary data of the initialization method. - **isInteractiveMode** The user started a run of WaaSMedic. - **isManaged** Device is managed for updates. - **isWUConnected** Device is connected to Windows Update. - **noMoreActions** No more applicable diagnostics. -- **pluginFailureCount** No content is currently available. -- **pluginsCount** No content is currently available. +- **pluginFailureCount** The number of plugins that have failed. +- **pluginsCount** The number of plugins. - **qualityAssessmentImpact** WaaS Assessment impact for quality updates. - **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. - **usingBackupFeatureAssessment** Relying on backup feature assessment. @@ -5220,19 +5398,19 @@ The following fields are available: ### Microsoft.Windows.StoreAgent.Telemetry.StateTransition -No content is currently available. +Products in the process of being fulfilled (installed or updated) are maintained in a list. This event is sent any time there is a change in a product's fulfillment status (pending, working, paused, cancelled, or complete), to help keep Windows up to date and secure. The following fields are available: -- **CatalogId** No content is currently available. -- **FulfillmentPluginId** No content is currently available. -- **HResult** No content is currently available. -- **NewState** No content is currently available. -- **PFN** No content is currently available. -- **PluginLastStage** No content is currently available. -- **PluginTelemetryData** No content is currently available. -- **Prevstate** No content is currently available. -- **ProductId** No content is currently available. +- **CatalogId** The ID for the product being installed if the product is from a private catalog, such as the Enterprise catalog. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **HResult** The resulting HResult error/success code of this operation. +- **NewState** The current fulfillment state of this product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginLastStage** The most recent product fulfillment step that the plug-in has reported (different than its state). +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **Prevstate** The previous fulfillment state of this product. +- **ProductId** Product ID of the app that is being updated or installed. ### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest @@ -5257,7 +5435,7 @@ The following fields are available: - **bytesFromCDN** The number of bytes received from a CDN source. - **bytesFromGroupPeers** The number of bytes received from a peer in the same group. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLinkLocalPeers** No content is currently available. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. - **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. @@ -5461,7 +5639,7 @@ This event indicates that the Enhanced Engaged restart "accept automatically" di The following fields are available: - **DeviceLocalTime** The local time on the device sending the event. -- **EnterpriseAttributionValue** No content is currently available. +- **EnterpriseAttributionValue** Indicates whether the Enterprise attribution is on in this dialog box. - **ETag** OneSettings versioning value. - **ExitCode** Indicates how users exited the dialog box. - **RebootVersion** Version of DTE. @@ -5478,7 +5656,7 @@ This event indicates that the Enhanced Engaged restart "restart failed" dialog b The following fields are available: - **DeviceLocalTime** The local time of the device sending the event. -- **EnterpriseAttributionValue** No content is currently available. +- **EnterpriseAttributionValue** Indicates whether the Enterprise attribution is on in this dialog box. - **ETag** OneSettings versioning value. - **ExitCode** Indicates how users exited the dialog box. - **RebootVersion** Version of DTE. @@ -5495,7 +5673,7 @@ This event indicates that the Enhanced Engaged restart "restart imminent" dialog The following fields are available: - **DeviceLocalTime** Time the dialog box was shown on the local device. -- **EnterpriseAttributionValue** No content is currently available. +- **EnterpriseAttributionValue** Indicates whether the Enterprise attribution is on in this dialog box. - **ETag** OneSettings versioning value. - **ExitCode** Indicates how users exited the dialog box. - **RebootVersion** Version of DTE. @@ -6045,21 +6223,21 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.BeginScenario -No content is currently available. +This event is sent when the Update Reserve Manager is called to begin a scenario. The following fields are available: -- **Flags** No content is currently available. -- **HardReserveSize** No content is currently available. -- **HardReserveUsedSpace** No content is currently available. -- **OwningScenarioId** No content is currently available. -- **ReturnCode** No content is currently available. -- **ScenarioId** No content is currently available. +- **Flags** The flags that are passed to the begin scenario function. +- **HardReserveSize** The size of the hard reserve. +- **HardReserveUsedSpace** The used space in the hard reserve. +- **OwningScenarioId** The scenario ID the client that called the begin scenario function. +- **ReturnCode** The return code for the begin scenario operation. +- **ScenarioId** The scenario ID that is internal to the reserve manager. ### Microsoft.Windows.UpdateReserveManager.ClearSoftReserve -No content is currently available. +This event is sent when the Update Reserve Manager clears the contents of the soft reserve. @@ -6075,16 +6253,16 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.EndScenario -No content is currently available. +This event is sent when the Update Reserve Manager ends an active scenario. The following fields are available: -- **ActiveScenario** No content is currently available. -- **Flags** No content is currently available. -- **HardReserveSize** No content is currently available. -- **HardReserveUsedSpace** No content is currently available. -- **ReturnCode** No content is currently available. -- **ScenarioId** No content is currently available. +- **ActiveScenario** The current active scenario. +- **Flags** The flags passed to the end scenario call. +- **HardReserveSize** The size of the hard reserve when the end scenario is called. +- **HardReserveUsedSpace** The used space in the hard reserve when the end scenario is called. +- **ReturnCode** The return code of this operation. +- **ScenarioId** The ID of the internal reserve manager scenario. ### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError @@ -6102,29 +6280,29 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.InitializeReserves -No content is currently available. +This event is sent when reserves are initialized on the device. The following fields are available: -- **FallbackInitUsed** No content is currently available. -- **Flags** No content is currently available. -- **HardReserveFinalSize** No content is currently available. -- **HardReserveFinalUsedSpace** No content is currently available. -- **HardReserveInitialSize** No content is currently available. -- **HardReserveInitialUsedSpace** No content is currently available. -- **HardReserveTargetSize** No content is currently available. -- **InitialUserFreeSpace** No content is currently available. -- **PostUpgradeFreeSpace** No content is currently available. -- **SoftReserveFinalSize** No content is currently available. -- **SoftReserveFinalUsedSpace** No content is currently available. -- **SoftReserveInitialSize** No content is currently available. -- **SoftReserveInitialUsedSpace** No content is currently available. -- **SoftReserveTargetSize** No content is currently available. -- **TargetUserFreeSpace** No content is currently available. -- **UpdateScratchFinalUsedSpace** No content is currently available. -- **UpdateScratchInitialUsedSpace** No content is currently available. -- **UpdateScratchReserveFinalSize** No content is currently available. -- **UpdateScratchReserveInitialSize** No content is currently available. +- **FallbackInitUsed** Indicates whether fallback initialization is used. +- **Flags** The flags used in the initialization of Update Reserve Manager. +- **HardReserveFinalSize** The final size of the hard reserve. +- **HardReserveFinalUsedSpace** The used space in the hard reserve. +- **HardReserveInitialSize** The size of the hard reserve after initialization. +- **HardReserveInitialUsedSpace** The utilization of the hard reserve after initialization. +- **HardReserveTargetSize** The target size that was set for the hard reserve. +- **InitialUserFreeSpace** The user free space during initialization. +- **PostUpgradeFreeSpace** The free space value passed into the Update Reserve Manager to determine reserve sizing post upgrade. +- **SoftReserveFinalSize** The final size of the soft reserve. +- **SoftReserveFinalUsedSpace** The used space in the soft reserve. +- **SoftReserveInitialSize** The soft reserve size after initialization. +- **SoftReserveInitialUsedSpace** The utilization of the soft reserve after initialization. +- **SoftReserveTargetSize** The target size that was set for the soft reserve. +- **TargetUserFreeSpace** The target user free space that was passed into the reserve manager to determine reserve sizing post upgrade. +- **UpdateScratchFinalUsedSpace** The used space in the scratch reserve. +- **UpdateScratchInitialUsedSpace** The utilization of the scratch reserve after initialization. +- **UpdateScratchReserveFinalSize** The utilization of the scratch reserve after initialization. +- **UpdateScratchReserveInitialSize** The size of the scratch reserve after initialization. ### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager @@ -6153,13 +6331,13 @@ The following fields are available: ### Microsoft.Windows.UpdateReserveManager.ReevaluatePolicy -No content is currently available. +This event is sent when the Update Reserve Manager reevaluates policy to determine reserve usage. The following fields are available: -- **PolicyChanged** No content is currently available. -- **PolicyFailedEnum** No content is currently available. -- **PolicyPassed** No content is currently available. +- **PolicyChanged** Indicates whether the policy has changed. +- **PolicyFailedEnum** The reason why the policy failed. +- **PolicyPassed** Indicates whether the policy passed. ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment @@ -6170,11 +6348,11 @@ This event is sent when the Update Reserve Manager removes a pending hard reserv ### Microsoft.Windows.UpdateReserveManager.TurnOffReserves -No content is currently available. +This event is sent when the Update Reserve Manager turns off reserve functionality for certain operations. The following fields are available: -- **Flags** No content is currently available. +- **Flags** Flags used in the turn off reserves function. ### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment From 20958845fe3656864c6472fd8c9f7838b9a8d7b9 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 7 Feb 2019 08:37:17 -0800 Subject: [PATCH 027/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 68 +++++++++---------- 1 file changed, 34 insertions(+), 34 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 77792963db..6dc649099d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/06/2019 +ms.date: 02/07/2019 --- @@ -2333,18 +2333,18 @@ The following fields are available: ### TelClientSynthetic.EventMonitor_0 -No content is currently available. +This event provides statistics for specific diagnostic events. The following fields are available: -- **ConsumerCount** No content is currently available. -- **EventName** No content is currently available. -- **EventSnFirst** No content is currently available. -- **EventSnLast** No content is currently available. -- **EventStoreCount** No content is currently available. -- **MonitorSn** No content is currently available. -- **TriggerCount** No content is currently available. -- **UploadedCount** No content is currently available. +- **ConsumerCount** The number of instances seen in the Event Tracing for Windows consumer. +- **EventName** The name of the event being monitored. +- **EventSnFirst** The expected first event serial number. +- **EventSnLast** The expected last event serial number. +- **EventStoreCount** The number of events reaching the event store. +- **MonitorSn** The serial number of the monitor. +- **TriggerCount** The number of events reaching the trigger buffer. +- **UploadedCount** The number of events uploaded. ### TelClientSynthetic.HeartBeat_5 @@ -3596,76 +3596,76 @@ The following fields are available: ### Microsoft.Windows.SysReset.FlightUninstallCancel -No content is currently available. +This event indicates the customer has cancelled uninstallation of Windows. ### Microsoft.Windows.SysReset.FlightUninstallError -No content is currently available. +This event sends an error code when the Windows uninstallation fails. The following fields are available: -- **ErrorCode** No content is currently available. +- **ErrorCode** Error code for uninstallation failure. ### Microsoft.Windows.SysReset.FlightUninstallReboot -No content is currently available. +This event is sent to signal an upcoming reboot during uninstallation of Windows. ### Microsoft.Windows.SysReset.FlightUninstallStart -No content is currently available. +This event indicates that the Windows uninstallation has started. ### Microsoft.Windows.SysReset.FlightUninstallUnavailable -No content is currently available. +This event sends diagnostic data when the Windows uninstallation is not available. The following fields are available: -- **AddedProfiles** No content is currently available. -- **MissingExternalStorage** No content is currently available. -- **MissingInfra** No content is currently available. -- **MovedProfiles** No content is currently available. +- **AddedProfiles** Indicates that new user profiles have been created since the flight was installed. +- **MissingExternalStorage** Indicates that the external storage used to install the flight is not available. +- **MissingInfra** Indicates that uninstall resources are missing. +- **MovedProfiles** Indicates that the user profile has been moved since the flight was installed. ### Microsoft.Windows.SysReset.HasPendingActions -No content is currently available. +This event is sent when users have actions that will block the uninstall of the latest quality update. ### Microsoft.Windows.SysReset.PBREngineInitFailed -No content is currently available. +This event signals a failed handoff between two recovery binaries. The following fields are available: -- **Operation** No content is currently available. +- **Operation** Legacy customer scenario. ### Microsoft.Windows.SysReset.PBREngineInitSucceed -No content is currently available. +This event signals successful handoff between two recovery binaries. The following fields are available: -- **Operation** No content is currently available. +- **Operation** Legacy customer scenario. ### Microsoft.Windows.SysReset.PBRFailedOffline -No content is currently available. +This event reports the error code when recovery fails. The following fields are available: -- **HRESULT** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **HRESULT** Error code for the failure. +- **PBRType** The recovery scenario. +- **SessionID** The unique ID for the recovery session. ### Microsoft.Xbox.XamTelemetry.AppActivationError @@ -4402,12 +4402,12 @@ The following fields are available: - **PackageCountTotalCanonical** Total number of canonical packages. - **PackageCountTotalDiff** Total number of diff packages. - **PackageCountTotalExpress** Total number of express packages. -- **PackageCountTotalPSFX** No content is currently available. +- **PackageCountTotalPSFX** The total number of PSFX packages. - **PackageExpressType** Type of express package. - **PackageSizeCanonical** Size of canonical packages in bytes. - **PackageSizeDiff** Size of diff packages in bytes. - **PackageSizeExpress** Size of express packages in bytes. -- **PackageSizePSFX** No content is currently available. +- **PackageSizePSFX** The size of PSFX packages, in bytes. - **RangeRequestState** Indicates the range request type used. - **RelatedCV** Correlation vector value generated from the latest USO scan. - **Result** Outcome of the download request phase of update. @@ -5487,7 +5487,7 @@ The following fields are available: - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **expiresAt** No content is currently available. +- **expiresAt** Time when the content will expire from the Delivery Optimization Cache. - **fileID** The ID of the file being downloaded. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. @@ -5498,7 +5498,7 @@ The following fields are available: - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. - **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** No content is currently available. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. - **predefinedCallerName** The name of the API Caller. @@ -5690,7 +5690,7 @@ This event returns information relating to the Enhanced Engaged reboot reminder The following fields are available: - **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **EnterpriseAttributionValue** No content is currently available. +- **EnterpriseAttributionValue** Indicates whether Enterprise attribution is on for this dialog. - **ETag** The OneSettings versioning value. - **ExitCode** Indicates how users exited the reboot reminder dialog box. - **RebootVersion** The version of the DTE (Direct-to-Engaged). From b4323b9fe1355df994b76ef7cb4598d280d48795 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 8 Feb 2019 08:20:41 -0800 Subject: [PATCH 028/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 198 ++++++++++++++++-- 1 file changed, 186 insertions(+), 12 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 6dc649099d..5e8f28e0bf 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/07/2019 +ms.date: 02/08/2019 --- @@ -2347,6 +2347,19 @@ The following fields are available: - **UploadedCount** The number of events uploaded. +### TelClientSynthetic.GetFileInfoAction_FilePathNotApproved_0 + +No content is currently available. + +The following fields are available: + +- **FilePath** No content is currently available. +- **FilePathExpanded** No content is currently available. +- **FilePathExpandedScenario** No content is currently available. +- **ScenarioId** No content is currently available. +- **ScenarioInstanceId** No content is currently available. + + ### TelClientSynthetic.HeartBeat_5 This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. @@ -2401,6 +2414,134 @@ The following fields are available: - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +### TelClientSynthetic.HeartBeat_Agent_5 + +No content is currently available. + +The following fields are available: + +- **ConsumerDroppedCount** No content is currently available. +- **ContainerBufferFullDropCount** No content is currently available. +- **ContainerBufferFullSevilleDropCount** No content is currently available. +- **CriticalDataThrottleDroppedCount** No content is currently available. +- **DecodingDroppedCount** No content is currently available. +- **EtwDroppedBufferCount** No content is currently available. +- **EtwDroppedCount** No content is currently available. +- **EventsForwardedToHost** No content is currently available. +- **FullTriggerBufferDroppedCount** No content is currently available. +- **HeartBeatSequenceNumber** No content is currently available. +- **HostConnectionErrorsCount** No content is currently available. +- **HostConnectionTimeoutsCount** No content is currently available. +- **LastHostConnectionError** No content is currently available. +- **PreviousHeartBeatTime** No content is currently available. +- **ThrottledDroppedCount** No content is currently available. + + +### TelClientSynthetic.HeartBeat_DevHealthMon_5 + +No content is currently available. + +The following fields are available: + +- **HeartBeatSequenceNumber** No content is currently available. +- **PreviousHeartBeatTime** No content is currently available. + + +### TelClientSynthetic.LifetimeManager_ConsumerBaseTimestampChange_0 + +No content is currently available. + +The following fields are available: + +- **NewBaseTime** No content is currently available. +- **NewSystemTime** No content is currently available. +- **OldSystemTime** No content is currently available. + + +### TelClientSynthetic.MatchEngine_ScenarioCompletionThrottled_0 + +No content is currently available. + +The following fields are available: + +- **MaxHourlyCompletionsSetting** No content is currently available. +- **ScenarioId** No content is currently available. +- **ScenarioName** No content is currently available. + + +### TelClientSynthetic.OsEvents_BootStatReset_0 + +No content is currently available. + +The following fields are available: + +- **BootId** No content is currently available. +- **ResetReason** No content is currently available. + + +### TelClientSynthetic.ProducerThrottled_At_TriggerBuffer_0 + +No content is currently available. + +The following fields are available: + +- **BufferSize** No content is currently available. +- **DataType** No content is currently available. +- **EstSeenCount** No content is currently available. +- **EstTopEvent1Count** No content is currently available. +- **EstTopEvent1Name** No content is currently available. +- **EstTopEvent2Count** No content is currently available. +- **EstTopEvent2Name** No content is currently available. +- **Hit** No content is currently available. +- **IKey** No content is currently available. +- **ProviderId** No content is currently available. +- **ProviderName** No content is currently available. +- **Threshold** No content is currently available. + + +### TelClientSynthetic.ProducerThrottled_Event_Rate_0 + +No content is currently available. + +The following fields are available: + +- **EstSeenCount** No content is currently available. +- **EstTopEvent1Count** No content is currently available. +- **EstTopEvent1Name** No content is currently available. +- **EstTopEvent2Count** No content is currently available. +- **EstTopEvent2Name** No content is currently available. +- **EventPerProviderThreshold** No content is currently available. +- **EventRateThreshold** No content is currently available. +- **Hit** No content is currently available. +- **IKey** No content is currently available. +- **ProviderId** No content is currently available. +- **ProviderName** No content is currently available. + + +### TelClientSynthetic.RunExeWithArgsAction_ExeTerminated_0 + +No content is currently available. + +The following fields are available: + +- **ExpandedExeName** No content is currently available. +- **MaximumRuntimeMs** No content is currently available. +- **ScenarioId** No content is currently available. +- **ScenarioInstanceId** No content is currently available. + + +### TelClientSynthetic.RunExeWithArgsAction_ProcessReturnedNonZeroExitCode + +No content is currently available. + +The following fields are available: + +- **ExitCode** No content is currently available. +- **ExpandedExeName** No content is currently available. +- **ScenarioId** No content is currently available. +- **ScenarioInstanceId** No content is currently available. + + ## DxgKernelTelemetry events ### DxgKrnlTelemetry.GPUAdapterInventoryV2 @@ -3668,6 +3809,18 @@ The following fields are available: - **SessionID** The unique ID for the recovery session. +### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption + +No content is currently available. + +The following fields are available: + +- **cbsSessionOption** No content is currently available. +- **errorCode** No content is currently available. +- **meteredConnection** No content is currently available. +- **sessionID** No content is currently available. + + ### Microsoft.Xbox.XamTelemetry.AppActivationError This event indicates whether the system detected an activation error in the app. @@ -3990,10 +4143,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashFailures** No content is currently available. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** Indicates the scope of the app download. +- **AppXScope** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -4002,22 +4155,22 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailCount** No content is currently available. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CbsMethod** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CommonProps** No content is currently available. +- **ConnectTime** No content is currently available. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. +- **DownloadProps** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started downloading content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. @@ -4045,9 +4198,9 @@ The following fields are available: - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulationResult** No content is currently available. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailCount** No content is currently available. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -5485,9 +5638,9 @@ The following fields are available: - **downlinkUsageBps** The download speed (in bytes per second). - **downloadMode** The download mode used for this file download session. - **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **downloadModeSrc** Source of the DownloadMode setting. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **expiresAt** Time when the content will expire from the Delivery Optimization Cache. +- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. - **fileID** The ID of the file being downloaded. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. @@ -5716,6 +5869,26 @@ The following fields are available: - **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + ### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy This event indicates a policy is present that may restrict update activity to outside of active hours. @@ -6285,6 +6458,7 @@ This event is sent when reserves are initialized on the device. The following fields are available: - **FallbackInitUsed** Indicates whether fallback initialization is used. +- **FinalUserFreeSpace** No content is currently available. - **Flags** The flags used in the initialization of Update Reserve Manager. - **HardReserveFinalSize** The final size of the hard reserve. - **HardReserveFinalUsedSpace** The used space in the hard reserve. From e0db6ec4424acaafc6a6de23fe0f4c7a4cfbfa9f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 11 Feb 2019 08:49:04 -0800 Subject: [PATCH 029/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 23 +++++++++++-------- 1 file changed, 13 insertions(+), 10 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 5e8f28e0bf..47fa6009f5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/08/2019 +ms.date: 02/11/2019 --- @@ -749,6 +749,7 @@ The following fields are available: - **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? - **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. - **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? - **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? @@ -4143,10 +4144,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** No content is currently available. +- **AppXScope** Indicates the scope of the app download. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -4155,22 +4156,22 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** No content is currently available. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. -- **CommonProps** No content is currently available. -- **ConnectTime** No content is currently available. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** No content is currently available. +- **DownloadProps** Information about the download operation. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started downloading content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. @@ -4198,9 +4199,9 @@ The following fields are available: - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **RegulationReason** The reason that the update is regulated -- **RegulationResult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -6436,6 +6437,8 @@ The following fields are available: - **HardReserveUsedSpace** The used space in the hard reserve when the end scenario is called. - **ReturnCode** The return code of this operation. - **ScenarioId** The ID of the internal reserve manager scenario. +- **SoftReserveSize** No content is currently available. +- **SoftReserveUsedSpace** No content is currently available. ### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError From 9e6edd0c766f22e95c49f51fbbbeb6cb139f40b1 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 12 Feb 2019 09:03:32 -0800 Subject: [PATCH 030/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 189 +++++++++--------- 1 file changed, 90 insertions(+), 99 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 47fa6009f5..064e2af5d3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/11/2019 +ms.date: 02/12/2019 --- @@ -2350,15 +2350,15 @@ The following fields are available: ### TelClientSynthetic.GetFileInfoAction_FilePathNotApproved_0 -No content is currently available. +This event occurs when the DiagTrack escalation fails due to the scenario requesting a path that is not approved for GetFileInfo actions. The following fields are available: -- **FilePath** No content is currently available. -- **FilePathExpanded** No content is currently available. -- **FilePathExpandedScenario** No content is currently available. -- **ScenarioId** No content is currently available. -- **ScenarioInstanceId** No content is currently available. +- **FilePath** The unexpanded path in the scenario XML. +- **FilePathExpanded** The file path, with environment variables expanded. +- **FilePathExpandedScenario** The file path, with property identifiers and environment variables expanded. +- **ScenarioId** The globally unique identifier (GUID) of the scenario. +- **ScenarioInstanceId** The error code denoting which path failed (internal or external). ### TelClientSynthetic.HeartBeat_5 @@ -2417,130 +2417,130 @@ The following fields are available: ### TelClientSynthetic.HeartBeat_Agent_5 -No content is currently available. +This event sends data about the health and quality of the diagnostic data from the specified device (agent), to help keep Windows up to date. The following fields are available: -- **ConsumerDroppedCount** No content is currently available. -- **ContainerBufferFullDropCount** No content is currently available. -- **ContainerBufferFullSevilleDropCount** No content is currently available. -- **CriticalDataThrottleDroppedCount** No content is currently available. -- **DecodingDroppedCount** No content is currently available. -- **EtwDroppedBufferCount** No content is currently available. -- **EtwDroppedCount** No content is currently available. -- **EventsForwardedToHost** No content is currently available. -- **FullTriggerBufferDroppedCount** No content is currently available. -- **HeartBeatSequenceNumber** No content is currently available. -- **HostConnectionErrorsCount** No content is currently available. -- **HostConnectionTimeoutsCount** No content is currently available. -- **LastHostConnectionError** No content is currently available. -- **PreviousHeartBeatTime** No content is currently available. -- **ThrottledDroppedCount** No content is currently available. +- **ConsumerDroppedCount** The number of events dropped at the consumer layer of the diagnostic data collection client. +- **ContainerBufferFullDropCount** The number of events dropped due to the container buffer being full. +- **ContainerBufferFullSevilleDropCount** The number of “Seville” events dropped due to the container buffer being full. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events dropped due to data throttling. +- **DecodingDroppedCount** The number of events dropped due to decoding failures. +- **EtwDroppedBufferCount** The number of buffers dropped in the ETW (Event Tracing for Windows) session. +- **EtwDroppedCount** The number of events dropped at the ETW (Event Tracing for Windows) layer of the diagnostic data collection client on the user’s device. +- **EventsForwardedToHost** The number of events forwarded from agent (device) to host (server). +- **FullTriggerBufferDroppedCount** The number of events dropped due to the trigger buffer being full. +- **HeartBeatSequenceNumber** The heartbeat sequence number associated with this event. +- **HostConnectionErrorsCount** The number of non-timeout errors encountered in the host (server)/agent (device) socket transport channel. +- **HostConnectionTimeoutsCount** The number of connection timeouts between the host (server) and agent (device). +- **LastHostConnectionError** The last error from a connection between host (server) and agent (device). +- **PreviousHeartBeatTime** The timestamp of the last heartbeat event. +- **ThrottledDroppedCount** The number of events dropped due to throttling of “noisy” providers. ### TelClientSynthetic.HeartBeat_DevHealthMon_5 -No content is currently available. +This event sends data (for Surface Hub devices) to monitor and ensure the correct functioning of those Surface Hub devices. This data helps ensure the device is up-to-date with the latest security and safety features. The following fields are available: -- **HeartBeatSequenceNumber** No content is currently available. -- **PreviousHeartBeatTime** No content is currently available. +- **HeartBeatSequenceNumber** The heartbeat sequence number associated with this event. +- **PreviousHeartBeatTime** The timestamp of the last heartbeat event. ### TelClientSynthetic.LifetimeManager_ConsumerBaseTimestampChange_0 -No content is currently available. +This event sends data when the Windows Diagnostic data collection mechanism detects a timestamp adjustment for incoming diagnostic events. This data is critical for dealing with time changes during diagnostic data analysis, to help keep the device up to date. The following fields are available: -- **NewBaseTime** No content is currently available. -- **NewSystemTime** No content is currently available. -- **OldSystemTime** No content is currently available. +- **NewBaseTime** The new QPC (Query Performance Counter) base time from ETW (Event Tracing for Windows). +- **NewSystemTime** The new system time of the device. +- **OldSystemTime** The previous system time of the device. ### TelClientSynthetic.MatchEngine_ScenarioCompletionThrottled_0 -No content is currently available. +This event sends data when scenario completion is throttled (truncated or otherwise restricted) because the scenario is excessively large. The following fields are available: -- **MaxHourlyCompletionsSetting** No content is currently available. -- **ScenarioId** No content is currently available. -- **ScenarioName** No content is currently available. +- **MaxHourlyCompletionsSetting** The maximum number of scenario completions per hour until throttling kicks in. +- **ScenarioId** The globally unique identifier (GUID) of the scenario being throttled. +- **ScenarioName** The name of the scenario being throttled. ### TelClientSynthetic.OsEvents_BootStatReset_0 -No content is currently available. +This event sends data when the Windows diagnostic data collection mechanism resets the Boot ID. This data helps ensure Windows is up to date. The following fields are available: -- **BootId** No content is currently available. -- **ResetReason** No content is currently available. +- **BootId** The current Boot ID. +- **ResetReason** The reason code for resetting the Boot ID. ### TelClientSynthetic.ProducerThrottled_At_TriggerBuffer_0 -No content is currently available. +This event sends data when a producer is throttled due to the trigger buffer exceeding defined thresholds. The following fields are available: -- **BufferSize** No content is currently available. -- **DataType** No content is currently available. -- **EstSeenCount** No content is currently available. -- **EstTopEvent1Count** No content is currently available. -- **EstTopEvent1Name** No content is currently available. -- **EstTopEvent2Count** No content is currently available. -- **EstTopEvent2Name** No content is currently available. -- **Hit** No content is currently available. -- **IKey** No content is currently available. -- **ProviderId** No content is currently available. -- **ProviderName** No content is currently available. -- **Threshold** No content is currently available. +- **BufferSize** The size of the trigger buffer. +- **DataType** The type of event that this producer generates (Event Tracing for Windows, Time, Synthetic). +- **EstSeenCount** Estimated total number of inputs determining other “Est…” values. +- **EstTopEvent1Count** The count for estimated “noisiest” event from this producer. +- **EstTopEvent1Name** The name for estimated “noisiest” event from this producer. +- **EstTopEvent2Count** The count for estimated second “noisiest” event from this producer. +- **EstTopEvent2Name** The name for estimated second “noisiest” event from this producer. +- **Hit** The number of events seen from this producer. +- **IKey** The IKey identifier of the producer, if available. +- **ProviderId** The provider ID of the producer being throttled. +- **ProviderName** The provider name of the producer being throttled. +- **Threshold** The threshold crossed, which caused the throttling. ### TelClientSynthetic.ProducerThrottled_Event_Rate_0 -No content is currently available. +This event sends data when an event producer is throttled by the Windows Diagnostic data collection mechanism. This data helps ensure Windows is up to date. The following fields are available: -- **EstSeenCount** No content is currently available. -- **EstTopEvent1Count** No content is currently available. -- **EstTopEvent1Name** No content is currently available. -- **EstTopEvent2Count** No content is currently available. -- **EstTopEvent2Name** No content is currently available. -- **EventPerProviderThreshold** No content is currently available. -- **EventRateThreshold** No content is currently available. -- **Hit** No content is currently available. -- **IKey** No content is currently available. -- **ProviderId** No content is currently available. -- **ProviderName** No content is currently available. +- **EstSeenCount** Estimated total number of inputs determining other “Est…” values. +- **EstTopEvent1Count** The count for estimated “noisiest” event from this producer. +- **EstTopEvent1Name** The name for estimated “noisiest” event from this producer. +- **EstTopEvent2Count** The count for estimated second “noisiest” event from this producer. +- **EstTopEvent2Name** The name for estimated second “noisiest” event from this producer. +- **EventPerProviderThreshold** The trigger point for throttling (value for each provider). This value is only applied once EventRateThreshold has been met. +- **EventRateThreshold** The total event rate trigger point for throttling. +- **Hit** The number of events seen from this producer. +- **IKey** The IKey identifier of the producer, if available. +- **ProviderId** The provider ID of the producer being throttled. +- **ProviderName** The provider name of the producer being throttled. ### TelClientSynthetic.RunExeWithArgsAction_ExeTerminated_0 -No content is currently available. +This event sends data when an executable (EXE) file is terminated during escalation because it exceeded its maximum runtime (the maximum amount of time it was expected to run). This data helps ensure Windows is up to date. The following fields are available: -- **ExpandedExeName** No content is currently available. -- **MaximumRuntimeMs** No content is currently available. -- **ScenarioId** No content is currently available. -- **ScenarioInstanceId** No content is currently available. +- **ExpandedExeName** The expanded name of the executable (EXE) file. +- **MaximumRuntimeMs** The maximum runtime (in milliseconds) for this action. +- **ScenarioId** The globally unique identifier (GUID) of the scenario that was terminated. +- **ScenarioInstanceId** The globally unique identifier (GUID) of the scenario instance that was terminated. ### TelClientSynthetic.RunExeWithArgsAction_ProcessReturnedNonZeroExitCode -No content is currently available. +This event sends data when the RunExe process finishes during escalation, but returns a non-zero exit code. This data helps ensure Windows is up to date. The following fields are available: -- **ExitCode** No content is currently available. -- **ExpandedExeName** No content is currently available. -- **ScenarioId** No content is currently available. -- **ScenarioInstanceId** No content is currently available. +- **ExitCode** The exit code of the process +- **ExpandedExeName** The expanded name of the executable (EXE) file. +- **ScenarioId** The globally unique identifier (GUID) of the escalating scenario. +- **ScenarioInstanceId** The globally unique identifier (GUID) of the scenario instance. ## DxgKernelTelemetry events @@ -3812,14 +3812,14 @@ The following fields are available: ### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption -No content is currently available. +This event sends corruption repair diagnostic data when the PBRCorruptionRepairOption encounters a corruption error. The following fields are available: -- **cbsSessionOption** No content is currently available. -- **errorCode** No content is currently available. -- **meteredConnection** No content is currently available. -- **sessionID** No content is currently available. +- **cbsSessionOption** The corruption repair configuration. +- **errorCode** The error code encountered. +- **meteredConnection** Indicates whether the device is connected to a metered network (wired or WiFi). +- **sessionID** The globally unique identifier (GUID) for the session. ### Microsoft.Xbox.XamTelemetry.AppActivationError @@ -4144,10 +4144,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashFailures** No content is currently available. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** Indicates the scope of the app download. +- **AppXScope** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -4156,18 +4156,18 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailCount** No content is currently available. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CbsMethod** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **ConnectTime** No content is currently available. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. @@ -4201,7 +4201,7 @@ The following fields are available: - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailCount** No content is currently available. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -4577,7 +4577,7 @@ This event collects information regarding the expansion phase of the new Unified The following fields are available: -- **CanonicalRequestedOnError** No content is currently available. +- **CanonicalRequestedOnError** Indicates if an error caused a reversion to a different type of compressed update (TRUE or FALSE). - **ElapsedTickCount** Time taken for expand phase. - **EndFreeSpace** Free space after expand phase. - **EndSandboxSize** Sandbox size after expand phase. @@ -6482,21 +6482,6 @@ The following fields are available: - **UpdateScratchReserveInitialSize** The size of the scratch reserve after initialization. -### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager - -This event returns data about the Update Reserve Manager, including whether it’s been initialized. - -The following fields are available: - -- **ClientId** The ID of the caller application. -- **Flags** The enumerated flags used to initialize the manager. -- **FlightId** The flight ID of the content the calling client is currently operating with. -- **Offline** Indicates whether or the reserve manager is called during offline operations. -- **PolicyPassed** Indicates whether the machine is able to use reserves. -- **ReturnCode** Return code of the operation. -- **Version** The version of the Update Reserve Manager. - - ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. @@ -6530,6 +6515,12 @@ This event is sent when the Update Reserve Manager turns off reserve functionali The following fields are available: - **Flags** Flags used in the turn off reserves function. +- **HardReserveSize** No content is currently available. +- **HardReserveUsedSpace** No content is currently available. +- **ScratchReserveSize** No content is currently available. +- **ScratchReserveUsedSpace** No content is currently available. +- **SoftReserveSize** No content is currently available. +- **SoftReserveUsedSpace** No content is currently available. ### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment From b5d294eeddb0e393e0e9562d1200eb622bd1a4ab Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 12 Feb 2019 16:47:39 -0800 Subject: [PATCH 031/737] new build --- ...basic-level-windows-diagnostic-events-and-fields-19H1.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 064e2af5d3..0fa6cf4c9a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -6437,8 +6437,8 @@ The following fields are available: - **HardReserveUsedSpace** The used space in the hard reserve when the end scenario is called. - **ReturnCode** The return code of this operation. - **ScenarioId** The ID of the internal reserve manager scenario. -- **SoftReserveSize** No content is currently available. -- **SoftReserveUsedSpace** No content is currently available. +- **SoftReserveSize** The size of the soft reserve when end scenario is called. +- **SoftReserveUsedSpace** The amount of the soft reserve used when end scenario is called. ### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError @@ -6461,7 +6461,7 @@ This event is sent when reserves are initialized on the device. The following fields are available: - **FallbackInitUsed** Indicates whether fallback initialization is used. -- **FinalUserFreeSpace** No content is currently available. +- **FinalUserFreeSpace** The amount of user free space after initialization. - **Flags** The flags used in the initialization of Update Reserve Manager. - **HardReserveFinalSize** The final size of the hard reserve. - **HardReserveFinalUsedSpace** The used space in the hard reserve. From c0ff6390e9ee613d77ca1caa66d676ab553aba79 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 13 Feb 2019 08:30:52 -0800 Subject: [PATCH 032/737] new build --- ...ndows-diagnostic-events-and-fields-19H1.md | 28 +++++++++---------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index 0fa6cf4c9a..dbaadb2de5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/12/2019 +ms.date: 02/13/2019 --- @@ -4144,10 +4144,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** Number of seconds the update was actively being downloaded. -- **AppXBlockHashFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. For streaming install scenarios, AllContent - non-streaming download, RequiredOnly - streaming download requested content required for launch, AutomaticOnly - streaming download requested automatic streams for the app, and Unknown - for events sent before download scope is determined by the Windows Update client. -- **AppXScope** No content is currently available. +- **AppXScope** Indicates the scope of the app download. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -4156,22 +4156,22 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full-file download or a partial/delta download. -- **CbsMethod** No content is currently available. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** No content is currently available. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. +- **DownloadProps** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started downloading content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. @@ -4201,7 +4201,7 @@ The following fields are available: - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RepeatFailCount** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). @@ -6515,12 +6515,12 @@ This event is sent when the Update Reserve Manager turns off reserve functionali The following fields are available: - **Flags** Flags used in the turn off reserves function. -- **HardReserveSize** No content is currently available. -- **HardReserveUsedSpace** No content is currently available. -- **ScratchReserveSize** No content is currently available. -- **ScratchReserveUsedSpace** No content is currently available. -- **SoftReserveSize** No content is currently available. -- **SoftReserveUsedSpace** No content is currently available. +- **HardReserveSize** The size of the hard reserve when Turn Off is called. +- **HardReserveUsedSpace** The amount of space used by the hard reserve when Turn Off is called +- **ScratchReserveSize** The size of the scratch reserve when Turn Off is called. +- **ScratchReserveUsedSpace** The amount of space used by the scratch reserve when Turn Off is called. +- **SoftReserveSize** The size of the soft reserve when Turn Off is called. +- **SoftReserveUsedSpace** The amount of the soft reserve used when Turn Off is called. ### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment From 4adeb8d342d599d3e2844144dab99820ee0f6819 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 13 Feb 2019 14:03:24 -0800 Subject: [PATCH 033/737] new build --- .../basic-level-windows-diagnostic-events-and-fields-19H1.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index dbaadb2de5..ad1566b7b2 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -4171,7 +4171,7 @@ The following fields are available: - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** What is the device model. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** No content is currently available. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started downloading content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. From b3537b04295e09eadf44cd9b7dcc6eeef5ba2a97 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 15 Feb 2019 09:11:01 -0800 Subject: [PATCH 034/737] new build --- .../basic-level-windows-diagnostic-events-and-fields-19H1.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md index ad1566b7b2..0e7eebb254 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/13/2019 +ms.date: 02/15/2019 --- From 6e0a0fca1b293dc2072fe464355c712c42444f47 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 4 Mar 2019 14:28:11 -0800 Subject: [PATCH 035/737] new build --- ...ndows-diagnostic-events-and-fields-1703.md | 65 +- ...ndows-diagnostic-events-and-fields-1709.md | 10 +- ...ndows-diagnostic-events-and-fields-1803.md | 10 +- ...ndows-diagnostic-events-and-fields-1809.md | 15765 ++++++++-------- 4 files changed, 8183 insertions(+), 7667 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index eaf8f033d0..5dfc2fcfac 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/04/2019 --- @@ -1822,61 +1822,6 @@ The following fields are available: ## Diagnostic data events -### TelClientSynthetic.AbnormalShutdown_0 - -This event sends data about boot IDs for which a normal clean shutdown was not observed, to help keep Windows up to date. - -The following fields are available: - -- **AbnormalShutdownBootId** Retrieves the Boot ID for which the abnormal shutdown was observed. -- **CrashDumpEnabled** Indicates whether crash dumps are enabled. -- **CumulativeCrashCount** Cumulative count of operating system crashes since the BootId reset. -- **CurrentBootId** BootId at the time the abnormal shutdown event was being reported. -- **FirmwareResetReasonEmbeddedController** Firmware-supplied reason for the reset. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional data related to the reset reason provided by the firmware. -- **FirmwareResetReasonPch** Hardware-supplied reason for the reset. -- **FirmwareResetReasonPchAdditional** Additional data related to the reset reason provided by the hardware. -- **FirmwareResetReasonSupplied** Indicates whether the firmware supplied any reset reason. -- **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. -- **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. -- **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. -- **LastBugCheckBootId** The Boot ID of the last captured crash. -- **LastBugCheckCode** Code that indicates the type of error. -- **LastBugCheckContextFlags** Additional crash dump settings. -- **LastBugCheckOriginalDumpType** The type of crash dump the system intended to save. -- **LastBugCheckOtherSettings** Other crash dump settings. -- **LastBugCheckParameter1** The first parameter with additional info on the type of the error. -- **LastBugCheckProgress** Progress towards writing out the last crash dump. -- **LastSuccessfullyShutdownBootId** The Boot ID of the last fully successful shutdown. -- **PowerButtonCumulativePressCount** Indicates the number of times the power button has been pressed ("pressed" not to be confused with "released"). -- **PowerButtonCumulativeReleaseCount** Indicates the number of times the power button has been released ("released" not to be confused with "pressed"). -- **PowerButtonErrorCount** Indicates the number of times there was an error attempting to record Power Button metrics (e.g.: due to a failure to lock/update the bootstat file). -- **PowerButtonLastPressBootId** The Boot ID of the last time the Power Button was detected to have been pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastPressTime** The date and time the Power Button was most recently pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastReleaseBootId** The Boot ID of the last time the Power Button was released ("released" not to be confused with "pressed"). -- **PowerButtonLastReleaseTime** The date and time the Power Button was most recently released ("released" not to be confused with "pressed"). -- **PowerButtonPressCurrentCsPhase** Represents the phase of Connected Standby exit when the power button was pressed. -- **PowerButtonPressIsShutdownInProgress** Indicates whether a system shutdown was in progress at the last time the Power Button was pressed. -- **PowerButtonPressLastPowerWatchdogStage** The last stage completed when the Power Button was most recently pressed. -- **PowerButtonPressPowerWatchdogArmed** Indicates whether or not the watchdog for the monitor was active at the time of the last power button press. -- **TransitionInfoBootId** The Boot ID of the captured transition information. -- **TransitionInfoCSCount** The total number of times the system transitioned from "Connected Standby" mode to "On" when the last marker was saved. -- **TransitionInfoCSEntryReason** Indicates the reason the device last entered "Connected Standby" mode ("entered" not to be confused with "exited"). -- **TransitionInfoCSExitReason** Indicates the reason the device last exited "Connected Standby" mode ("exited" not to be confused with "entered"). -- **TransitionInfoCSInProgress** Indicates whether the system was in or entering Connected Standby mode when the last marker was saved. -- **TransitionInfoLastReferenceTimeChecksum** The checksum of TransitionInfoLastReferenceTimestamp. -- **TransitionInfoLastReferenceTimestamp** The date and time that the marker was last saved. -- **TransitionInfoPowerButtonTimestamp** The most recent date and time when the Power Button was pressed (collected via a different mechanism than PowerButtonLastPressTime). -- **TransitionInfoSleepInProgress** Indicates whether the system was in or entering Sleep mode when the last marker was saved. -- **TransitionInfoSleepTranstionsToOn** The total number of times the system transitioned from Sleep mode to on, when the last marker was saved. -- **TransitionInfoSystemRunning** Indicates whether the system was running when the last marker was saved. -- **TransitionInfoSystemShutdownInProgress** Indicates whether a device shutdown was in progress when the power button was pressed. -- **TransitionInfoUserShutdownInProgress** Indicates whether a user shutdown was in progress when the power button was pressed. -- **TransitionLatestCheckpointId** Represents a unique identifier for a checkpoint during the device state transition. -- **TransitionLatestCheckpointSeqNumber** Represents the chronological sequence number of the checkpoint. -- **TransitionLatestCheckpointType** Represents the type of the checkpoint, which can be the start of a phase, end of a phase, or just informational. - - ### TelClientSynthetic.AuthorizationInfo_RuntimeTransition This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. @@ -6296,6 +6241,12 @@ This event sends data specific to the FixupEditionId mitigation used for OS Upda ## Windows Update Reserve Manager events +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 27fcd87f88..d516d29754 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/04/2019 --- @@ -6514,6 +6514,12 @@ The following fields are available: ## Windows Update Reserve Manager events +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index e3c6418b17..6c84d0381d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/04/2019 --- @@ -7646,6 +7646,12 @@ This event is sent when the Update Reserve Manager returns an error from one of +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 8916790a12..0ed80bd117 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7606 +1,8159 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -audience: ITPro -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -ms.date: 02/15/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **action** The change that was invoked on a device inventory object. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AbnormalShutdown_0 - -This event sends data about boot IDs for which a normal clean shutdown was not observed, to help keep Windows up to date. - -The following fields are available: - -- **AbnormalShutdownBootId** BootId of the abnormal shutdown being reported by this event. -- **AcDcStateAtLastShutdown** Identifies if the device was on battery or plugged in. -- **BatteryLevelAtLastShutdown** The last recorded battery level. -- **BatteryPercentageAtLastShutdown** The battery percentage at the last shutdown. -- **CrashDumpEnabled** Indicates whether crash dumps are enabled. -- **CumulativeCrashCount** Cumulative count of operating system crashes since the BootId reset. -- **CurrentBootId** BootId at the time the abnormal shutdown event was being reported. -- **Firmwaredata->ResetReasonEmbeddedController** The reset reason that was supplied by the firmware. -- **Firmwaredata->ResetReasonEmbeddedControllerAdditional** Additional data related to reset reason provided by the firmware. -- **Firmwaredata->ResetReasonPch** The reset reason that was supplied by the hardware. -- **Firmwaredata->ResetReasonPchAdditional** Additional data related to the reset reason supplied by the hardware. -- **Firmwaredata->ResetReasonSupplied** Indicates whether the firmware supplied any reset reason or not. -- **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. -- **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. -- **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. -- **LastBugCheckBootId** bootId of the last captured crash. -- **LastBugCheckCode** Code that indicates the type of error. -- **LastBugCheckContextFlags** Additional crash dump settings. -- **LastBugCheckOriginalDumpType** The type of crash dump the system intended to save. -- **LastBugCheckOtherSettings** Other crash dump settings. -- **LastBugCheckParameter1** The first parameter with additional info on the type of the error. -- **LastBugCheckProgress** Progress towards writing out the last crash dump. -- **LastBugCheckVersion** The version of the information struct written during the crash. -- **LastSuccessfullyShutdownBootId** BootId of the last fully successful shutdown. -- **LongPowerButtonPressDetected** Identifies if the user was pressing and holding power button. -- **OOBEInProgress** Identifies if the Out-Of-Box-Experience is running. -- **OSSetupInProgress** Identifies if the operating system setup is running. -- **PowerButtonCumulativePressCount** Indicates the number of times the power button has been pressed ("pressed" not to be confused with "released"). -- **PowerButtonCumulativeReleaseCount** Indicates the number of times the power button has been released ("released" not to be confused with "pressed"). -- **PowerButtonErrorCount** Indicates the number of times there was an error attempting to record Power Button metrics (e.g.: due to a failure to lock/update the bootstat file). -- **PowerButtonLastPressBootId** BootId of the last time the Power Button was detected to have been pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastPressTime** Date/time of the last time the Power Button was pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastReleaseBootId** The Boot ID of the last time the Power Button was released ("released" not to be confused with "pressed"). -- **PowerButtonLastReleaseTime** The date and time the Power Button was most recently released ("released" not to be confused with "pressed"). -- **PowerButtonPressCurrentCsPhase** Represents the phase of Connected Standby exit when the power button was pressed. -- **PowerButtonPressIsShutdownInProgress** Indicates whether a system shutdown was in progress at the last time the power button was pressed. -- **PowerButtonPressLastPowerWatchdogStage** The last stage completed when the Power Button was most recently pressed. -- **PowerButtonPressPowerWatchdogArmed** Indicates whether or not the watchdog for the monitor was active at the time of the last power button press. -- **ShutdownDeviceType** Identifies who triggered a shutdown. Is it because of battery, thermal zones, or through a Kernel API. -- **SleepCheckpoint** Provides the last checkpoint when there is a failure during a sleep transition. -- **SleepCheckpointSource** Indicates whether the source is the EFI variable or bootstat file. -- **SleepCheckpointStatus** Indicates whether the checkpoint information is valid. -- **StaleBootStatData** Identifies if the data from bootstat is stale. -- **TransitionInfoBootId** The Boot ID of the captured transition information. -- **TransitionInfoCSCount** The total number of times the system transitioned from "Connected Standby" mode to "On" when the last marker was saved. -- **TransitionInfoCSEntryReason** Indicates the reason the device last entered "Connected Standby" mode ("entered" not to be confused with "exited"). -- **TransitionInfoCSExitReason** Indicates the reason the device last exited "Connected Standby" mode ("exited" not to be confused with "entered"). -- **TransitionInfoCSInProgress** Indicates whether the system was in or entering Connected Standby mode when the last marker was saved. -- **TransitionInfoLastReferenceTimeChecksum** The checksum of TransitionInfoLastReferenceTimestamp. -- **TransitionInfoLastReferenceTimestamp** The date and time that the marker was last saved. -- **TransitionInfoLidState** Describes the state of the laptop lid. -- **TransitionInfoPowerButtonTimestamp** The most recent date and time when the Power Button was pressed (collected via a different mechanism than PowerButtonLastPressTime). -- **TransitionInfoSleepInProgress** Indicates whether the system was in or entering Sleep mode when the last marker was saved. -- **TransitionInfoSleepTranstionsToOn** The total number of times the system transitioned from Sleep mode to on, when the last marker was saved. -- **TransitionInfoSystemRunning** Indicates whether the system was running when the last marker was saved. -- **TransitionInfoSystemShutdownInProgress** Indicates whether a device shutdown was in progress when the power button was pressed. -- **TransitionInfoUserShutdownInProgress** Indicates whether a user shutdown was in progress when the power button was pressed. -- **TransitionLatestCheckpointId** Represents a unique identifier for a checkpoint during the device state transition. -- **TransitionLatestCheckpointSeqNumber** Represents the chronological sequence number of the checkpoint. -- **TransitionLatestCheckpointType** Represents the type of the checkpoint, which can be the start of a phase, end of a phase, or just informational. -- **VirtualMachineId** If the operating system is on a virtual Machine, it gives the virtual Machine ID (GUID) that can be used to correlate events on the host. - - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiSeqId** The event sequence ID. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplayAdapterLuid** The display adapter LUID. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **GPUDeviceID** The GPU device ID. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPURevisionID** The GPU revision ID. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **version** The event version. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **AppName** The name of the app that has crashed. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModName** Exception module name (e.g. bar.dll). -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BusReportedDescription** The description of the device reported by the bux. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Description** The description of the device. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **HWID** A list of hardware IDs for the device. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **ProblemCode** The error code currently returned by the device, if applicable. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKID** The list of hardware IDs for the stack. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilters** The identifiers of the Upper filters installed for the device. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **ImageSize** The size of the driver file. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. -- **Usage** Data about usage for the add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **hr** The HResult of the operation. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **WUDeviceID** The unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** The endpoint URL where the device obtains update metadata. This is used to distinguish between test, staging, and production environments. -- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. -- **ExtendedStatusCode** The secondary status code of the event. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast -- **StatusCode** The status code of the event. -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineResult** Error code from the engine operation. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Windows Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **CategoryId** The Item Category ID. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The product family name of the product being installed. -- **ProductId** The identity of the package or packages being installed. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUpdate** Is this an update? -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNumber** The number of attempts by the user to download. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefinedCallerName** The name of the API Caller. -- **restrictedUpload** Is the upload restricted? -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller object. -- **reasonCode** The reason for pausing the download. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Indicates whether the download is happening in the background. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **fileID** The ID of the file being downloaded. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groupID** ID for the group. -- **isEncrypted** Indicates whether the download is encrypted. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCallerName** Name of the API caller. -- **routeToCacheServer** Cache server setting, source, and value. -- **sessionID** The ID for the file download session. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** Indicates whether the download used memory streaming. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/04/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** No content is currently available. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** No content is currently available. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** No content is currently available. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** No content is currently available. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** No content is currently available. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** No content is currently available. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** No content is currently available. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? +- **CompareExchange128Swpport** No content is currently available. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **VicboseMode** No content is currently available. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndT.ApStamp** No content is currently available. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartT.ApStamp** No content is currently available. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AZureOSIDPresent** No content is currently available. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **AZureVMType** No content is currently available. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDeviceRrotected** No content is currently available. +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnha5Sed** No content is currently available. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **GenuineStateanchNIsPortableOperatingSystem** No content is currently available. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signalure** No content is currently available. +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AdvertisiNgId** No content is currently available. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImpro_ement** No content is currently available. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **Abo_eLockEnabled** No content is currently available. +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDis0layResolutionHorizontal** No content is currently available. +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **ActitityHistoryCollection** No content is currently available. +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluatooth** No content is currently available. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonaliza|ion** No content is currently available. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayeferUpg** No content is currently available. +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). +- **WWPauseState** No content is currently available. + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **invent** No content is currently available. +- **inventoryId** Device ID used for Compatibility testing +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectInstanceId** No content is currently available. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **Can$ollctH¥art$eat@** No content is currently available. +- **Can&erformDiagnosticEscalations** No content is currently available. +- **Can@erformDiagnosticEscalations** No content is currently available. +- **CanollDctWndo‰sAnDlytHcsE‰entL** No content is currently available. +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectCoreTelemetzy** No content is currently available. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanColleCtHeartbeats** No content is currently available. +- **CanCollectNsTelemetry** No content is currently available. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanMepoHtSc$narDos** No content is currently available. +- **CanollÿctAAyTe[emeƒry** No content is currently available. +- **CanPerformDiagngsticEscalations** No content is currently available. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanPerforoDiagnosticEscalations** No content is currently available. +- **CanRepor5Acenarios** No content is currently available. +- **CanReportscenarios** No content is currently available. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **CanþollectOsTelemetry** No content is currently available. +- **Previous&ermissions** No content is currently available. +- **PreviousPermissaons** No content is currently available. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionfromEverythingOff** No content is currently available. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTas{Enasled** No content is currently available. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **CwnsusStartTime** No content is currently available. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. +- **낎茨��彿孔ゟꪜㄒ謡폲��춗** No content is currently available. +- **셨恮띚㓃瘙칌델࠮鎫ꖋ͇��솗π㹆** No content is currently available. +- **㨲⣦豑棽沵湤ས萾盗椺魹㙞** No content is currently available. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **@venStomeRe­etSizeSum** No content is currently available. +- **ࠣ⥶墊뗞ᚄ棛묚ﺪ穢꾜浝返枽탙** No content is currently available. +- **597pressedBytesUploaded** No content is currently available. +- **5ensusExitCode** No content is currently available. +- **5ensusStartTime** No content is currently available. +- **5ensusTaskEnabled** No content is currently available. +- **㉊��ꐔᦵﲉộ恓拥镳ŏ⺃턺맿삷࣫৘彣䞉䮄** No content is currently available. +- **AgentConnectaonErrorsCount** No content is currently available. +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgentConnect⁩onErrorsCount** No content is currently available. +- **AudioInMS** No content is currently available. +- **AudioOutMS** No content is currently available. +- **BackgroundMouseSec** No content is currently available. +- **CensdsExitCode** No content is currently available. +- **CensdsStartTime** No content is currently available. +- **CensdsTaskEnabled** No content is currently available. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **Com`ressedBytesUploaded** No content is currently available. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CompressedBytesUtyPropagatedSec** No content is currently available. +- **ConsdmerDroppedCount** No content is currently available. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **Critical�ataThrottleDroppedCount** No content is currently available. +- **CriticalDataDbDro`pedCount** No content is currently available. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrot4leDroppedCount** No content is currently available. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowAntersCounter** No content is currently available. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CriticalOverflowEuntestCounter** No content is currently available. +- **CriticalOverflowIntersCounter** No content is currently available. +- **CrivicalOverflowEntersCounter** No content is currently available. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDboppedFullCount** No content is currently available. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppeDFailureCount** No content is currently available. +- **DbDroppedFailureCountAgentC** No content is currently available. +- **DbDroppedFullCoun�** No content is currently available. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DbD偲oppedCount** No content is currently available. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **EnteringCriticalOverfl** No content is currently available. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **EventSequence** No content is currently available. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventsPtesistedCount** No content is currently available. +- **EventStoreLifetimeResetCo}nter** No content is currently available. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoReLifetimeResetCounter** No content is currently available. +- **EventStoreRese|Counter** No content is currently available. +- **EventStoreReseSizeSum** No content is currently available. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetdingSum** No content is currently available. +- **EventStoreResetSizesum** No content is currently available. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventStoreResettCounter** No content is currently available. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **FellTriggerBufferDroppedCount** No content is currently available. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **FullTrihgerBufferDroppedCount** No content is currently available. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **Inv,:3tyttpCodeCount** No content is currently available. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **isDefault** No content is currently available. +- **isSuccessful** No content is currently available. +- **Las4Inv(lidttpode** No content is currently available. +- **LastAgentConnectionErroeType** No content is currently available. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSingOffender** No content is currently available. +- **LastEventsizeOffender** No content is currently available. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastEventSizeOffѥnder** No content is currently available. +- **LastInv,:3tyttpCode** No content is currently available. +- **LastInvali$HttpCode** No content is currently available. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxInUseAcenarioCounter** No content is currently available. +- **MaxInUseS75}arioCounter** No content is currently available. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **MaxxrseSum** No content is currently available. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **renderTrigger** No content is currently available. +- **repeatedUploadFailureDropped** No content is currently available. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **RepeatedUploadFailureerDropp** No content is currently available. +- **result** No content is currently available. +- **SettingsHtt0Att%mpt2** No content is currently available. +- **SettingsHttpAtMempts** No content is currently available. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **SettingsyttpAttempts** No content is currently available. +- **SettingsyttpFailures** No content is currently available. +- **SinceFirstInteractivityMS** No content is currently available. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **U0loaderErrorCount** No content is currently available. +- **unteingCriticalOverflowDroppedCounter** No content is currently available. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **ViewFlags** No content is currently available. +- **VobtexHttpResponseFailures** No content is currently available. +- **Vor5exFailuresTimeout** No content is currently available. +- **Vor5exHttpAttempts** No content is currently available. +- **Vor5exHttpFailures4xx** No content is currently available. +- **Vor5exHttpFailures5xx** No content is currently available. +- **Vor5exHttpResponseFailures** No content is currently available. +- **Vor5exHttpResponsesWithDroppedEvents** No content is currently available. +- **VordexHttpAttempts** No content is currently available. +- **VortehFailuresTimeout** No content is currently available. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAtMempts** No content is currently available. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWit�DroppedEvents** No content is currently available. +- **VortexHttpResponsesWitfDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **VortexHttpResponsesWitherDroppEvents** No content is currently available. +- **VortexHvtpAttempts** No content is currently available. +- **VortexyttpAttempts** No content is currently available. +- **VortexyttpFailures4xx** No content is currently available. +- **VortexyttpFailures5xx** No content is currently available. +- **VortexyttpResponseFailures** No content is currently available. +- **VortexyttpResponsesWithDroppedEvents** No content is currently available. +- **Ω霗⺴䷞釬膏੶ˀ䊋䏾៬㝟쀩ﻊႌ᪘绮開웷** No content is currently available. +- **ⴧꈌ噱罼[ᱪ頱찲刕떈ϩꗊ꒶兛槞捖䏛늊邋瑟⌴슰ݎ뜼뱥윞ᶃ** No content is currently available. +- **ꋦɓ☴槼ꏍ䔕趸邽뽎㞖륮獵衻㚔ʅⰤ脝ꁗ㻨剧敳犿矘葹꾇䬝⨘⏇뷮쨢ʜ꟩** No content is currently available. +- **ᤴ䖋叴햢Ѵ갰㹕壑彔蕢㑟䌛݁ꕿ඼丹䆑鱡** No content is currently available. +- **낎茨��彿孔ゟꪜㄒ謡폲��춗** No content is currently available. +- **덀ၫ랫Ƙퟚ᧔퐼㵜킶䆹荸활謁焄㓵犛Ɤ澴㹭ཧ** No content is currently available. +- **롰用᜜™業䬒㥆ἑ��寞⨱ᾝ䞆쨁悺릾䗳** No content is currently available. +- **뤠蔋弌놅똋궑텪邽櫰৳␮媩䉍��녑䍎񳸑** No content is currently available. +- **셨恮띚㓃瘙칌델࠮鎫ꖋ͇��솗π㹆** No content is currently available. +- **즬铗쐌ﰺ읟좌鄀妏 蹤㻇椤㜊䁔鿺䍇趺懤譀뫺◦ɍ煎㟹** No content is currently available. +- **첎艅ꃣ殠ổ⍦ꫭ簆㈺䥲풾Ϊ攝棥��紽鰫꜌ઁ㌲诡ಆᇆ** No content is currently available. +- **斜⤏ܔ馼쯌ℬ壯ꈹ楖뢨┺挖东ⵕ疐﷤㝊䅁荹隼��䎕㹢��⭶ꮬ瀯** No content is currently available. +- **曺跬蝲㥅䬿應鄶뇵鯔㮡侪ч즗퀾祃迼猀亰햗₊珱姰㜔Ⓤ∔痨쌈ꘄ擑蜉滂** No content is currently available. +- **㚡⁓��漭䖾愶툰ꯛ慤־䨃枛䡹ꋷన件Ⴄ棅譟** No content is currently available. +- **㨲⣦豑棽沵湤ས萾盗椺魹㙞** No content is currently available. +- **㰚姗硴龖㾙** No content is currently available. +- **䱉虙璫ຖꍶ搎⪴偩HttpAttempts** No content is currently available. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **ࠣ⥶墊뗞ᚄ棛묚ﺪ穢꾜浝返枽탙** No content is currently available. +- **㉊��ꐔᦵﲉộ恓拥镳ŏ⺃턺맿삷࣫৘彣䞉䮄** No content is currently available. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **repeatedUploadFailureDropped** No content is currently available. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **Ω霗⺴䷞釬膏੶ˀ䊋䏾៬㝟쀩ﻊႌ᪘绮開웷** No content is currently available. +- **ⴧꈌ噱罼[ᱪ頱찲刕떈ϩꗊ꒶兛槞捖䏛늊邋瑟⌴슰ݎ뜼뱥윞ᶃ** No content is currently available. +- **ꋦɓ☴槼ꏍ䔕趸邽뽎㞖륮獵衻㚔ʅⰤ脝ꁗ㻨剧敳犿矘葹꾇䬝⨘⏇뷮쨢ʜ꟩** No content is currently available. +- **ᤴ䖋叴햢Ѵ갰㹕壑彔蕢㑟䌛݁ꕿ඼丹䆑鱡** No content is currently available. +- **덀ၫ랫Ƙퟚ᧔퐼㵜킶䆹荸활謁焄㓵犛Ɤ澴㹭ཧ** No content is currently available. +- **롰用᜜™業䬒㥆ἑ��寞⨱ᾝ䞆쨁悺릾䗳** No content is currently available. +- **뤠蔋弌놅똋궑텪邽櫰৳␮媩䉍��녑䍎񳸑** No content is currently available. +- **즬铗쐌ﰺ읟좌鄀妏 蹤㻇椤㜊䁔鿺䍇趺懤譀뫺◦ɍ煎㟹** No content is currently available. +- **斜⤏ܔ馼쯌ℬ壯ꈹ楖뢨┺挖东ⵕ疐﷤㝊䅁荹隼��䎕㹢��⭶ꮬ瀯** No content is currently available. +- **曺跬蝲㥅䬿應鄶뇵鯔㮡侪ч즗퀾祃迼猀亰햗₊珱姰㜔Ⓤ∔痨쌈ꘄ擑蜉滂** No content is currently available. +- **㚡⁓��漭䖾愶툰ꯛ慤־䨃枛䡹ꋷన件Ⴄ棅譟** No content is currently available. +- **䱉虙璫ຖꍶ搎⪴偩HttpAttempts** No content is currently available. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalDroppedCount** No content is currently available. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** No content is currently available. +- **IsDeviceADDomainJoined** No content is currently available. +- **IsDeviceCloverTrail** No content is currently available. +- **IsDeviceFeatureUpdatingPaused** No content is currently available. +- **IsDeviceNetworkMetered** No content is currently available. +- **IsDeviceOobeBlocked** No content is currently available. +- **IsDeviceRequireUpdateApproval** No content is currently available. +- **IsDeviceSccmManaged** No content is currently available. +- **IsDeviceUninstallActive** No content is currently available. +- **IsDeviceUpdateNotificationLevel** No content is currently available. +- **IsDeviceUpdateServiceManaged** No content is currently available. +- **IsDeviceZeroExhaust** No content is currently available. +- **IsGreaterThanMaxRetry** No content is currently available. +- **IsVolumeLicensed** No content is currently available. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **~ersion** No content is currently available. +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiCeqId** No content is currently available. +- **aiSeqI�** No content is currently available. +- **aiseqId** No content is currently available. +- **aiSeqId** The event sequence ID. +- **bo** No content is currently available. +- **bootId** The system boot ID. +- **BrigesMessVersionViaDDI** No content is currently available. +- **BrightnessversionViaDDI** No content is currently available. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BrightnessVersionViaDtI** No content is currently available. +- **BrightnessVerskonViaDDI** No content is currently available. +- **BrightnessVersmonViaDDI** No content is currently available. +- **BrighvnessVessionViaDDI@WDDMVersionDisplayAdapterLuid** No content is currently available. +- **BrihhtnessVersionViaDDI** No content is currently available. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **ComtutePreemptionLevelTelInvEvntTrigger** No content is currently available. +- **DedicatedSys4emMemoryB** No content is currently available. +- **DedicatedSystemMemmryB** No content is currently available. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedSystemMemosyB** No content is currently available. +- **DedicatedvideoMemoryB** No content is currently available. +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DedicatedVmdeoMemoryB** No content is currently available. +- **DedicatefVideoMemor{B** No content is currently available. +- **DisplayAdapterLuid** The display adapter LUID. +- **DisplayAdaptevLuid** No content is currently available. +- **Dri6erVebsion** No content is currently available. +- **DriferDate** No content is currently available. +- **DriverDate** The date of the display driver. +- **DriverDEte** No content is currently available. +- **DriverRalk** No content is currently available. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DriverVgrsion** No content is currently available. +- **DrivezVersion** No content is currently available. +- **DrivgrRank** No content is currently available. +- **DX10EMDFilePath** No content is currently available. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX11UMDFmlePath** No content is currently available. +- **Dx11UMDVilePath** No content is currently available. +- **DX12UMDFilePaph** No content is currently available. +- **Dx12UMDFilePath** No content is currently available. +- **DX12UMDfilePath** No content is currently available. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX15UMDFilePath** No content is currently available. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **DX9UMDFmlePath** No content is currently available. +- **GPEDeviceID** No content is currently available. +- **GPUDeviceID** The GPU device ID. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPURevmsionID** No content is currently available. +- **GPUVendorID** The GPU vendor ID. +- **I3SoftwAreDåvice** No content is currently available. +- **InterfacaId** No content is currently available. +- **InterfaceId** The GPU interface ID. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsDisplayDevmce** No content is currently available. +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridDiscrgte** No content is currently available. +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IslidHttpDevice** No content is currently available. +- **IsMiracastStpported** No content is currently available. +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatc`LDA** No content is currently available. +- **IsMismatchLdA** No content is currently available. +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMIsmatchLDA** No content is currently available. +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsMsMiracastSupposted** No content is currently available. +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRemovrue,** No content is currently available. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MeasuruEnab|ed** No content is currently available. +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumVadPnTargets** No content is currently available. +- **NumvidPnSources** No content is currently available. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTapgets** No content is currently available. +- **NumVidPnTargets** The number of supported display output targets. +- **ShabedSystemMemoryB** No content is currently available. +- **SharedQystemMemoryB** No content is currently available. +- **SharedRystemMemoRyB** No content is currently available. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **ShaŲedSystemMemoryB** No content is currently available. +- **SubFendorID** No content is currently available. +- **SubSystemAD** No content is currently available. +- **SubSystemID** The subsystem ID. +- **SubSysve}IDEPURevhsionID** No content is currently available. +- **SubVendorID** The GPU sub vendor ID. +- **Teleme|ryEnabled** No content is currently available. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TelInvEvntTrihger** No content is currently available. +- **version** The event version. +- **W6DMVersion** No content is currently available. +- **wDDMVersion** No content is currently available. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **AppName** The name of the app that has crashed. +- **AppQessionGuid** No content is currently available. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTiieStamp** No content is currently available. +- **AppTiíeStamp** No content is currently available. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersioj** No content is currently available. +- **AppVersion** The version of the app that has crashed. +- **BeportId** No content is currently available. +- **Blags** No content is currently available. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriefdlyAppName** No content is currently available. +- **Friendly@ppName** No content is currently available. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **FriendlyporName** No content is currently available. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModFame** No content is currently available. +- **ModName** Exception module name (e.g. bar.dll). +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **MxceptionOffset** No content is currently available. +- **PackageFullName** Store application identity. +- **PackageFunlName** No content is currently available. +- **PackageRelativeAppId** Store application identity. +- **PackageRelativeporId** No content is currently available. +- **PeportId** No content is currently available. +- **porName** No content is currently available. +- **porSessionGuid** No content is currently available. +- **porTimeStamp** No content is currently available. +- **porVersion** No content is currently available. +- **ProbessCreateTime** No content is currently available. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTame** No content is currently available. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **processId** No content is currently available. +- **ProcessId** The ID of the process that has crashed. +- **ReportHd** No content is currently available. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **T!rgetAppId** No content is currently available. +- **TargetAorId** No content is currently available. +- **TargetAorVer** No content is currently available. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **ApSession'uid** No content is currently available. +- **ÇaitingO.PackagefelativeuppId** No content is currently available. +- **IsF!tal** No content is currently available. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **PfocessArghitectuve** No content is currently available. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **RepoftId** No content is currently available. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargepAppVer** No content is currently available. +- **TargetA#Id** No content is currently available. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppIt** No content is currently available. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **InwtallDateFromLinkFile** No content is currently available. +- **Language** The language code of the program. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OsVersionAtInstallTime** No content is currently available. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullFame** No content is currently available. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **ß_TlgCV__** No content is currently available. +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **StoreporType** No content is currently available. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMe|hod** No content is currently available. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **Audio_RenideDriver** No content is currently available. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BusReportedDescription** The description of the device reported by the bux. +- **BusReportelDescription** No content is currently available. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Description** The description of the device. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **Driver^erDate** No content is currently available. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **HWID** A list of hardware IDs for the device. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **Inven|oryVersion** No content is currently available. +- **InvenPoryVersion** No content is currently available. +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **LowerFiltevs** No content is currently available. +- **Manufacturer** The manufacturer of the device. +- **Manunacturer** No content is currently available. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Model** Identifies the model of the device. +- **P** No content is currently available. +- **ParentId** The Device Instance ID of the parent of the device. +- **Pro~ider** No content is currently available. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **ProblemGode** No content is currently available. +- **Provider** Identifies the device provider. +- **Sedvice** No content is currently available. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **baseata** No content is currently available. See [baseata](#baseata). +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackage[trongName** No content is currently available. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **DriverVype** No content is currently available. +- **DrkverIsKernelMode** No content is currently available. +- **ImageSize** The size of the driver file. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **InvgntoryVersion** No content is currently available. +- **Product** The product name that is included in the driver file. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. +- **Wd�Version** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **InwentoryVersion** No content is currently available. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. +- **f** No content is currently available. See [f](#f). + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonEmbeddedControln09eddedBootSequence** No content is currently available. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFr6eRange** No content is currently available. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFr6eRange** No content is currently available. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaun#hPrepared** No content is currently available. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **recoveryEnabled** No content is currently available. +- **Recoveryenabled** No content is currently available. +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **Res}ltCode** No content is currently available. +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **hr** The HResult of the operation. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **[yncType** No content is currently available. +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **ActivityMatghingId** No content is currently available. +- **AllowCachedResu~ts** No content is currently available. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateinfo** No content is currently available. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **BranchRQadinessLevel** No content is currently available. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CadlerApplicationName** No content is currently available. +- **CallerApplicafionName** No content is currently available. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CallerApplicationRame** No content is currently available. +- **canDurapionInSeconds** No content is currently available. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CcanDurationInSeconds** No content is currently available. +- **CcanEnqueueTime** No content is currently available. +- **CcanProps** No content is currently available. +- **CClienVersion** No content is currently available. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVer�ion** No content is currently available. +- **Clientversion** No content is currently available. +- **ClientVersion** The version number of the software distribution client. +- **ClientVersiOn** No content is currently available. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **ContusCode** No content is currently available. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DrivarExclusionPolicy** No content is currently available. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **DriverSyncPassPerformud** No content is currently available. +- **e:4|SInstanceID** No content is currently available. +- **e:4|SScenario** No content is currently available. +- **E~entScenario** No content is currently available. +- **eallerApplicationName** No content is currently available. +- **eClienVersion** No content is currently available. +- **Even5InstanceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenari0** No content is currently available. +- **Eventscenario** No content is currently available. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **EventScenário** No content is currently available. +- **EventScenavio** No content is currently available. +- **ExtendedContusCode** No content is currently available. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedSsatusCode** No content is currently available. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeapureUpdatePause** No content is currently available. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FeatureUpdatePawse** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **I{WUfBDualScanEnabled** No content is currently available. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDtyUScanEnabled** No content is currently available. +- **IsWUfBDualCcanEnabled** No content is currently available. +- **IsWUfbDualScanEnabled** No content is currently available. +- **IsWUfBDualscanEnabled** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **IsWUMcBederatedScanDisabled** No content is currently available. +- **IsWUMcDualScanEnabled** No content is currently available. +- **IsWUMcEnabled** No content is currently available. +- **ITVersion** No content is currently available. +- **ityUpdatePausDeferral** No content is currently available. +- **IwWUfBDualScanEnabled** No content is currently available. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NueFailedMetadataSignatures** No content is currently available. +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfApplicationsCategoryScanEvalunted** No content is currently available. +- **NumberOfLo-l** No content is currently available. +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdadesFromServiceSync** No content is currently available. +- **NumberOfNewupdatesFromServiceSync** No content is currently available. +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumberOfUpdatesEvalunted** No content is currently available. +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PaeseFeatureUpdatesEndTime** No content is currently available. +- **Pau³eQualityUpdatesStartTime** No content is currently available. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesSsartTime** No content is currently available. +- **PauseFeatureUpdatesSta2tTime** No content is currently available. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseFeatureUpdatesStartTiMe** No content is currently available. +- **PauseityUpdatePaussEndTime** No content is currently available. +- **PauseityUpdatePaussStartTime** No content is currently available. +- **PauseQualityUpdatesDndTime** No content is currently available. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesSsartTime** No content is currently available. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatEsStartTime** No content is currently available. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProceosName** No content is currently available. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **ProcessNcme** No content is currently available. +- **ProcessRame** No content is currently available. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **QualityUplatePausmPeriod** No content is currently available. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RelntedCV** No content is currently available. +- **ScanDSrationInSeconds** No content is currently available. +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **SsatusCode** No content is currently available. +- **StatusCodd** No content is currently available. +- **statusCode** No content is currently available. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **Synctate** No content is currently available. +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **TotalNumMetadaTaSignatures** No content is currently available. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDericeID** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDewiceID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumbe2** No content is currently available. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHalhFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXBoockHashFailures** No content is currently available. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **AppXScopr** No content is currently available. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCoqnt** No content is currently available. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **BytesDownnoaded** No content is currently available. +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationname** No content is currently available. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CallerApplictionaName** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCoun.ryCdel** No content is currently available. +- **CDNCoundryCode** No content is currently available. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNd** No content is currently available. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CtatusCode** No content is currently available. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownhoadProps** No content is currently available. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **DownloedPriority** No content is currently available. +- **DventInstanceID** No content is currently available. +- **e:4|SInstanceID** No content is currently available. +- **e:4|SScenario** No content is currently available. +- **E:4|State** No content is currently available. +- **EöentInstanceID** No content is currently available. +- **Eve.tScenario** No content is currently available. +- **EventInst.9ceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventPype** No content is currently available. +- **EventScanario** No content is currently available. +- **eventScenario** No content is currently available. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **EventTypr** No content is currently available. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **Fli.c9BuildNumber** No content is currently available. +- **Fli.c9Id** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HospName** No content is currently available. +- **HostName** The hostname URL the content is downloading from. +- **Hst.Name** No content is currently available. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWQfBEnabled** No content is currently available. +- **IsWUfBDualCcanEnabled** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnablad** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkCst.** No content is currently available. +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **NetworkRestrictiontartus** No content is currently available. +- **oadPriority** No content is currently available. +- **PackageFullName** The package name of the content. +- **PegulationResult** No content is currently available. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldDime** No content is currently available. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **Pst.DnldTime** No content is currently available. +- **PvocessName** No content is currently available. +- **QpdateId** No content is currently available. +- **QualityreUpdaPause** No content is currently available. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePatse** No content is currently available. +- **QualityUpdatePausa** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RdvisionNumber** No content is currently available. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **RegulationReason** The reason that the update is regulated +- **regulationResult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulatIonResult** No content is currently available. +- **RelatedCS** No content is currently available. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RelntedCV** No content is currently available. +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **tartusCdel** No content is currently available. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **tizeCalcTime** No content is currently available. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImporEvent** No content is currently available. +- **UpdateImpornstan** No content is currently available. +- **UpdateImport.9ce** No content is currently available. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDericeID** No content is currently available. +- **WUDeviceId** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CallerApplictionaName** No content is currently available. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CSIErrorTypr** No content is currently available. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **DriverRecoverySds** No content is currently available. +- **EvåntInstanceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventInstapceID** No content is currently available. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **EventTypr** No content is currently available. +- **ExtendedErrorCdel** No content is currently available. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HandlerTypr** No content is currently available. +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsKcfBDualScanEnabled** No content is currently available. +- **IsKcfBEnabled** No content is currently available. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsSuccessFailurePst.Reboot** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **IsWVfBDualScanEnabled** No content is currently available. +- **IsWVfBEnabled** No content is currently available. +- **lundleId** No content is currently available. +- **lundleRepeatFailCount** No content is currently available. +- **lundleRevisionNumber** No content is currently available. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCdel** No content is currently available. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageBullName** No content is currently available. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersaon** No content is currently available. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetingVession** No content is currently available. +- **tartusCdel** No content is currently available. +- **TransactionCdel** No content is currently available. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UpdateImportapce** No content is currently available. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDdviceID** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDevi'eID** No content is currently available. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **RelntedCV** No content is currently available. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **umberOfApplicableUpdates** No content is currently available. +- **WUDeviceID** The unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **CallerLoglicationName** No content is currently available. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. +- **ExtendedStatusCode** The secondary status code of the event. +- **ExtendefStatusCode** No content is currently available. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RcwMode** No content is currently available. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **SedviceGuid** No content is currently available. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **ServiceGuidEndpointUrl** No content is currently available. +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast +- **StatusCode** The status code of the event. +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **essionData** No content is currently available. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **Friled** No content is currently available. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanãeId** No content is currently available. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **value** No content is currently available. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **o-Ste** No content is currently available. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineResult** Error code from the engine operation. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckPar%meter2** No content is currently available. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AggregatedPackageFullNcmes** No content is currently available. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **Bundlele** No content is currently available. +- **CategoryId** The Item Category ID. +- **Categoryle** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **ClientApple** No content is currently available. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **ParentBundlele** No content is currently available. +- **PFN** The product family name of the product being installed. +- **Producele** No content is currently available. +- **ProductId** The identity of the package or packages being installed. +- **S{stemAttemptNumber** No content is currently available. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNaies** No content is currently available. +- **AggregatedpackageFullNames** No content is currently available. +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUp`ate** No content is currently available. +- **IsUpdate** Is this an update? +- **ParentBuneleId** No content is currently available. +- **PFN** Product Family Name of the product being installed. +- **productId** No content is currently available. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNaðes** No content is currently available. +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNumber** The number of attempts by the user to download. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **__TlgCÖ__** No content is currently available. +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsInteragtive** No content is currently available. +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **CatanogId** No content is currently available. +- **CatdlogId** No content is currently available. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **JResult** No content is currently available. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **Producele** No content is currently available. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **categoryId** No content is currently available. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **#dnErrorCounts** No content is currently available. +- **__TlgCVß_** No content is currently available. +- **|anConnectionCount** No content is currently available. +- **0redefinedCallerName** No content is currently available. +- **b6nConnectionCount** No content is currently available. +- **b6nErrorCodes** No content is currently available. +- **b6nErrorCounts** No content is currently available. +- **b6nIp** No content is currently available. +- **b6nUrl** No content is currently available. +- **background** Is the download a background download? +- **bytesFrkmIntPeers** No content is currently available. +- **bytesFromCacheSedver** No content is currently available. +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntÐeers** No content is currently available. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheSarverConnectionCount** No content is currently available. +- **cacheSedverConnectionCount** No content is currently available. +- **cacheServerConndctionCount** No content is currently available. +- **cacheServerConnectionCoujt** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnSonnectionCount** No content is currently available. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dkwnloadModeSrc** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **dowflinkBps** No content is currently available. +- **dow�loadMode** No content is currently available. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **downloadMofeSrc** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConjectionCount** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **internetConnectionCountdownlinkBps** No content is currently available. +- **isEjcrypted** No content is currently available. +- **isEncryptdd** No content is currently available. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefi.edCallerName** No content is currently available. +- **predefinedCallerName** The name of the API Caller. +- **predefinedCalleRName** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **romteToCacheServer** No content is currently available. +- **roupeToCacheServer** No content is currently available. +- **routeTnCacheServer** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **uplinkUsegeBps** No content is currently available. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **backgground** No content is currently available. +- **backgrou|d** No content is currently available. +- **background** Is the download a background download? +- **c`nUrl** No content is currently available. +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorBode** No content is currently available. +- **errorCode** The error code that was returned. +- **expebimentId** No content is currently available. +- **expebimentIderrorCode** No content is currently available. +- **experiientId** No content is currently available. +- **experimenpId** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVp|** No content is currently available. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCod%** No content is currently available. +- **reasonCode** The reason for pausing the download. +- **recsonCodesessiolID** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. +- **updateMD** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **b6nUrl** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bacoground** No content is currently available. +- **bileSizeCaller** No content is currently available. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **costFlaos** No content is currently available. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorC/de** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimejtId** No content is currently available. +- **experimen�Id** No content is currently available. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **fiheID** No content is currently available. +- **fileID** The ID of the file being downloaded. +- **filePat(** No content is currently available. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groqpID** No content is currently available. +- **groupID** ID for the group. +- **isEncrypted** Indicates whether the download is encrypted. +- **isFpn** No content is currently available. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **rimentId** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** Cache server setting, source, and value. +- **sessionID** The ID for the file download session. +- **sessmonID** No content is currently available. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **updateYD** No content is currently available. +- **usedMemoryStream** Indicates whether the download used memory streaming. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **`esponseAize** No content is currently available. +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **eErrorCode** No content is currently available. +- **eErrorCunt** No content is currently available. +- **errorCode** The error code that was returned. +- **errorCode‡httpStatusCodw** No content is currently available. +- **errorCode‡httpSvatusCodw** No content is currently available. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **errorSount** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **f{leID** No content is currently available. +- **fileID** The ID of the file being downloaded. +- **fkleID** No content is currently available. +- **htppStatusCode** No content is currently available. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. +- **swssionIDcdnUrl** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **e:4|SScenario** No content is currently available. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **interactiveelatedCVerrorCode** No content is currently available. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenariotate** No content is currently available. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **defeec-9-0S** No content is currently available. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **Ignorec-9-0SsFoec-start** No content is currently available. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateMd** No content is currently available. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** No content is currently available. +- **Flags** No content is currently available. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From 864408989b0807329b339c128d66e342a0535347 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 4 Mar 2019 14:30:46 -0800 Subject: [PATCH 036/737] new build --- windows/privacy/TOC.md | 2 +- ...dows-diagnostic-events-and-fields-1903.md} | 951 +++++++++++++++++- 2 files changed, 951 insertions(+), 2 deletions(-) rename windows/privacy/{basic-level-windows-diagnostic-events-and-fields-19H1.md => basic-level-windows-diagnostic-events-and-fields-1903.md} (93%) diff --git a/windows/privacy/TOC.md b/windows/privacy/TOC.md index e2a139c80d..cd6466b6eb 100644 --- a/windows/privacy/TOC.md +++ b/windows/privacy/TOC.md @@ -7,7 +7,7 @@ ### [Diagnostic Data Viewer Overview](diagnostic-data-viewer-overview.md) ### [Diagnostic Data Viewer for PowerShell Overview](Microsoft-DiagnosticDataViewer.md) ## Basic level Windows diagnostic data events and fields -### [Windows 10, version 19H1 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-19H1.md) +### [Windows 10, version 1903 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1903.md) ### [Windows 10, version 1809 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1809.md) ### [Windows 10, version 1803 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) ### [Windows 10, version 1709 basic level Windows diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md similarity index 93% rename from windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md rename to windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 0e7eebb254..551c98d759 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-19H1.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -9,7 +9,11 @@ ms.pagetype: security localizationpriority: high author: brianlic-msft ms.author: brianlic -ms.date: 02/15/2019 +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/04/2019 --- @@ -241,6 +245,23 @@ The following fields are available: - **line** Line in the file in the OS code base in which the exception occurs. +### Microsoft.Windows.Security.AppLockerCSP.IsDependencySatisfiedStart + +No content is currently available. + + + +### Microsoft.Windows.Security.AppLockerCSP.IsDependencySatisfiedStop + +No content is currently available. + +The following fields are available: + +- **edpActive** No content is currently available. +- **hr** No content is currently available. +- **internalHr** No content is currently available. + + ### Microsoft.Windows.Security.AppLockerCSP.SetValueParams Parameters passed to the SetValue function of the AppLockerCSP node. @@ -2543,6 +2564,12 @@ The following fields are available: - **ScenarioInstanceId** The globally unique identifier (GUID) of the scenario instance. +### TelClientSynthetic.ServiceMain_DevHealthMonEvent + +No content is currently available. + + + ## DxgKernelTelemetry events ### DxgKrnlTelemetry.GPUAdapterInventoryV2 @@ -3656,6 +3683,7 @@ The following fields are available: - **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. - **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). - **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. - **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. - **UserInputTime** The amount of time the loader application spent waiting for user input. @@ -3736,6 +3764,846 @@ The following fields are available: ## Other events +### Microsoft.Windows.PBR.BitLockerWipeFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.BootState + +No content is currently available. + +The following fields are available: + +- **BsdSummaryInfo** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ClearTPMStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ClientInfo + +No content is currently available. + +The following fields are available: + +- **name** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.DataVolumeCount + +No content is currently available. + +The following fields are available: + +- **count** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.DiskSpaceRequired + +No content is currently available. + +The following fields are available: + +- **numBytes** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.EnterAPI + +No content is currently available. + +The following fields are available: + +- **apiName** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.EnteredOOBE + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.LeaveAPI + +No content is currently available. + +The following fields are available: + +- **apiName** No content is currently available. +- **errorCode** No content is currently available. +- **sessionID** No content is currently available. +- **success** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.OEMExtensionFinished + +No content is currently available. + +The following fields are available: + +- **exitCode** No content is currently available. +- **param** No content is currently available. +- **phase** No content is currently available. +- **script** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timedOut** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.OEMExtensionStarted + +No content is currently available. + +The following fields are available: + +- **param** No content is currently available. +- **phase** No content is currently available. +- **script** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.OperationExecuteFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **index** No content is currently available. +- **operation** No content is currently available. +- **phase** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.OperationExecuteStarted + +No content is currently available. + +The following fields are available: + +- **index** No content is currently available. +- **operation** No content is currently available. +- **phase** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. +- **weight** No content is currently available. + + +### Microsoft.Windows.PBR.OperationQueueConstructFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.OperationQueueConstructStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.PBRClearRollBackEntry + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRClearTPMFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionFailed + +No content is currently available. + +The following fields are available: + +- **HRESULT** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. +- **SPErrorCode** No content is currently available. +- **SPOperation** No content is currently available. +- **SPPhase** No content is currently available. + + +### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionSucceed + +No content is currently available. + +The following fields are available: + +- **CBSPackageCount** No content is currently available. +- **CustomizationPackageCount** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRDriverInjectionFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFailed + +No content is currently available. + +The following fields are available: + +- **ErrorType** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFinalizeNewSystemFailed + +No content is currently available. + +The following fields are available: + +- **HRESULT** No content is currently available. +- **SessionID** No content is currently available. +- **SPErrorCode** No content is currently available. +- **SPOperation** No content is currently available. +- **SPPhase** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFinalizeNewSystemSucceed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFinalUserSelection + +No content is currently available. + +The following fields are available: + +- **PBREraseData** No content is currently available. +- **PBRRecoveryStrategy** No content is currently available. +- **PBRRepartitionDisk** No content is currently available. +- **PBRVariation** No content is currently available. +- **PBRWipeDataDrives** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFormatOSVolumeFailed + +No content is currently available. + +The following fields are available: + +- **JustDeleteFiles** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRFormatOSVolumeSucceed + +No content is currently available. + +The following fields are available: + +- **JustDeleteFiles** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRInstallWinREFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRIOCTLErasureSucceed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRLayoutImageFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRLayoutImageSucceed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBROEM1Failed + +No content is currently available. + +The following fields are available: + +- **HRESULT** No content is currently available. +- **Parameters** No content is currently available. +- **PBRType** No content is currently available. +- **ScriptName** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBROEM2Failed + +No content is currently available. + +The following fields are available: + +- **HRESULT** No content is currently available. +- **Parameters** No content is currently available. +- **PBRType** No content is currently available. +- **ScriptName** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPostApplyFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPostApplyFinished + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPostApplyStarted + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPreApplyFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPreApplyFinished + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRPreApplyStarted + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRReachedOOBE + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRReconstructionInitiated + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRRequirementChecks + +No content is currently available. + +The following fields are available: + +- **DeploymentType** No content is currently available. +- **InstallType** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRRequirementChecksFailed + +No content is currently available. + +The following fields are available: + +- **DiskSpaceAvailable** No content is currently available. +- **DiskSpaceRequired** No content is currently available. +- **ErrorType** No content is currently available. +- **PBRImageVersion** No content is currently available. +- **PBRRecoveryStrategy** No content is currently available. +- **PBRStartedFrom** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRRequirementChecksPassed + +No content is currently available. + +The following fields are available: + +- **OSVersion** No content is currently available. +- **PBRImageType** No content is currently available. +- **PBRImageVersion** No content is currently available. +- **PBRRecoveryStrategy** No content is currently available. +- **PBRStartedFrom** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRRestoreLicenseFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRSucceed + +No content is currently available. + +The following fields are available: + +- **OSVersion** No content is currently available. +- **PBRType** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRUserCancelled + +No content is currently available. + +The following fields are available: + +- **CancelPage** No content is currently available. +- **PBRVariation** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRVersionsMistmatch + +No content is currently available. + +The following fields are available: + +- **OSVersion** No content is currently available. +- **REVersion** No content is currently available. +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PBRWinREInstallationFailed + +No content is currently available. + +The following fields are available: + +- **SessionID** No content is currently available. + + +### Microsoft.Windows.PBR.PhaseFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **phase** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.PhaseStarted + +No content is currently available. + +The following fields are available: + +- **phase** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ReconstructionInfo + +No content is currently available. + +The following fields are available: + +- **numPackagesAbandoned** No content is currently available. +- **numPackagesFailed** No content is currently available. +- **sessionID** No content is currently available. +- **slowMode** No content is currently available. +- **targetVersion** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ResetOptions + +No content is currently available. + +The following fields are available: + +- **overwriteSpace** No content is currently available. +- **preserveWorkplace** No content is currently available. +- **scenario** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. +- **wipeData** No content is currently available. + + +### Microsoft.Windows.PBR.RetryQueued + +No content is currently available. + +The following fields are available: + +- **attempt** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ReturnedToOldOS + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ReturnTaskSchedulingFailed + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **sessionID** No content is currently available. +- **taskName** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.RollbackFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.RollbackStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.ScenarioNotSupported + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **reason** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SessionCreated + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SessionResumed + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SessionSaved + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SetupExecuteFinished + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **systemState** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SetupExecuteStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SetupFinalizeStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SetupOperationFailed + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **sessionID** No content is currently available. +- **setupExecutionOperation** No content is currently available. +- **setupExecutionPhase** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SystemInfoField + +No content is currently available. + +The following fields are available: + +- **name** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. +- **value** No content is currently available. + + +### Microsoft.Windows.PBR.SystemInfoListItem + +No content is currently available. + +The following fields are available: + +- **index** No content is currently available. +- **name** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. +- **value** No content is currently available. + + +### Microsoft.Windows.PBR.SystemInfoSenseFinished + +No content is currently available. + +The following fields are available: + +- **error** No content is currently available. +- **sessionID** No content is currently available. +- **succeeded** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.SystemInfoSenseStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.UserAcknowledgeCleanupWarning + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.UserCancel + +No content is currently available. + +The following fields are available: + +- **pageID** No content is currently available. +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.UserConfirmStart + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.WinREInstallFinished + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **sessionID** No content is currently available. +- **success** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.PBR.WinREInstallStarted + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + +### Microsoft.Windows.Security.WSC.DatastoreMigratedVersion + +No content is currently available. + +The following fields are available: + +- **datastoreisvtype** No content is currently available. +- **datastoremigrated** No content is currently available. +- **status** No content is currently available. + + +### Microsoft.Windows.Security.WSC.GetCallerViaWdsp + +No content is currently available. + +The following fields are available: + +- **callerExe** No content is currently available. + + ### Microsoft.Windows.SysReset.FlightUninstallCancel This event indicates the customer has cancelled uninstallation of Windows. @@ -3781,6 +4649,36 @@ This event is sent when users have actions that will block the uninstall of the +### Microsoft.Windows.SysReset.IndicateLCUWasUninstalled + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. + + +### Microsoft.Windows.SysReset.LCUUninstall + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **packageName** No content is currently available. +- **removalTime** No content is currently available. + + +### Microsoft.Windows.SysReset.PBRBlockedByPolicy + +No content is currently available. + +The following fields are available: + +- **PBRBlocked** No content is currently available. +- **PBRType** No content is currently available. + + ### Microsoft.Windows.SysReset.PBREngineInitFailed This event signals a failed handoff between two recovery binaries. @@ -3810,6 +4708,17 @@ The following fields are available: - **SessionID** The unique ID for the recovery session. +### Microsoft.Windows.SystemReset.EsimPresentCheck + +No content is currently available. + +The following fields are available: + +- **errorCode** No content is currently available. +- **esimPresent** No content is currently available. +- **sessionID** No content is currently available. + + ### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption This event sends corruption repair diagnostic data when the PBRCorruptionRepairOption encounters a corruption error. @@ -3822,6 +4731,16 @@ The following fields are available: - **sessionID** The globally unique identifier (GUID) for the session. +### Microsoft.Windows.SystemReset.RepairNeeded + +No content is currently available. + +The following fields are available: + +- **repairNeeded** No content is currently available. +- **sessionID** No content is currently available. + + ### Microsoft.Xbox.XamTelemetry.AppActivationError This event indicates whether the system detected an activation error in the app. @@ -6407,6 +7326,19 @@ The following fields are available: - **OwningScenarioId** The scenario ID the client that called the begin scenario function. - **ReturnCode** The return code for the begin scenario operation. - **ScenarioId** The scenario ID that is internal to the reserve manager. +- **SoftReserveSize** No content is currently available. +- **SoftReserveUsedSpace** No content is currently available. + + +### Microsoft.Windows.UpdateReserveManager.ClearReserve + +No content is currently available. + +The following fields are available: + +- **FinalReserveUsedSpace** No content is currently available. +- **InitialReserveUsedSpace** No content is currently available. +- **ReserveId** No content is currently available. ### Microsoft.Windows.UpdateReserveManager.ClearSoftReserve @@ -6482,6 +7414,21 @@ The following fields are available: - **UpdateScratchReserveInitialSize** The size of the scratch reserve after initialization. +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. @@ -6530,6 +7477,8 @@ This event is sent when the Update Reserve Manager needs to adjust the size of t The following fields are available: - **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** No content is currently available. +- **Flags** No content is currently available. - **PendingHardReserveAdjustment** The final change to the hard reserve size. - **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. From dd6c267300cadb1974451119e0ee29abdf7746c5 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 5 Mar 2019 08:49:58 -0800 Subject: [PATCH 037/737] new build --- ...ndows-diagnostic-events-and-fields-1809.md | 84 ++++++------------- 1 file changed, 24 insertions(+), 60 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 0ed80bd117..d9c00fdff9 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -516,6 +516,8 @@ The following fields are available: - **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. - **PCFP** The count of the number of this particular object type present on this device. - **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcesqorP2efetchW** No content is currently available. +- **SystemProcessorCompapeExchange** No content is currently available. - **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. - **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. - **SystemProcessorNx** The total number of objects of this type present on this device. @@ -525,6 +527,7 @@ The following fields are available: - **SystemWim** The total number of objects of this type present on this device. - **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. - **SystemWlan** The total number of objects of this type present on this device. +- **SystemWlAn** No content is currently available. - **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. - **Wmdrm_19H1** The count of the number of this particular object type present on this device. - **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. @@ -1363,6 +1366,7 @@ The following fields are available: - **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). - **ram** The amount of memory on the device. - **ramKB** The amount of memory (in KB). +- **virt5al** No content is currently available. - **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). - **virtualKB** The amount of virtual memory (in KB). @@ -2693,10 +2697,8 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: -- **Can$ollctH¥art$eat@** No content is currently available. - **Can&erformDiagnosticEscalations** No content is currently available. - **Can@erformDiagnosticEscalations** No content is currently available. -- **CanollDctWndo‰sAnDlytHcsE‰entL** No content is currently available. - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. @@ -2706,8 +2708,6 @@ The following fields are available: - **CanCollectNsTelemetry** No content is currently available. - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanMepoHtSc$narDos** No content is currently available. -- **CanollÿctAAyTe[emeƒry** No content is currently available. - **CanPerformDiagngsticEscalations** No content is currently available. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. @@ -2715,7 +2715,6 @@ The following fields are available: - **CanRepor5Acenarios** No content is currently available. - **CanReportscenarios** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **CanþollectOsTelemetry** No content is currently available. - **Previous&ermissions** No content is currently available. - **PreviousPermissaons** No content is currently available. - **PreviousPermissions** Bitmask of previous telemetry state. @@ -2738,9 +2737,6 @@ The following fields are available: - **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. - **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. - **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. -- **낎茨��彿孔ゟꪜㄒ謡폲��춗** No content is currently available. -- **셨恮띚㓃瘙칌델࠮鎫ꖋ͇��솗π㹆** No content is currently available. -- **㨲⣦豑棽沵湤ས萾盗椺魹㙞** No content is currently available. ### TelClientSynthetic.HeartBeat_5 @@ -2750,15 +2746,12 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: - **@venStomeRe­etSizeSum** No content is currently available. -- **ࠣ⥶墊뗞ᚄ棛묚ﺪ穢꾜浝返枽탙** No content is currently available. - **597pressedBytesUploaded** No content is currently available. - **5ensusExitCode** No content is currently available. - **5ensusStartTime** No content is currently available. - **5ensusTaskEnabled** No content is currently available. -- **㉊��ꐔᦵﲉộ恓拥镳ŏ⺃턺맿삷࣫৘彣䞉䮄** No content is currently available. - **AgentConnectaonErrorsCount** No content is currently available. - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AgentConnect⁩onErrorsCount** No content is currently available. - **AudioInMS** No content is currently available. - **AudioOutMS** No content is currently available. - **BackgroundMouseSec** No content is currently available. @@ -2773,7 +2766,6 @@ The following fields are available: - **CompressedBytesUtyPropagatedSec** No content is currently available. - **ConsdmerDroppedCount** No content is currently available. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **Critical�ataThrottleDroppedCount** No content is currently available. - **CriticalDataDbDro`pedCount** No content is currently available. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalDataThrot4leDroppedCount** No content is currently available. @@ -2789,13 +2781,12 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppeDFailureCount** No content is currently available. - **DbDroppedFailureCountAgentC** No content is currently available. -- **DbDroppedFullCoun�** No content is currently available. - **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DbD偲oppedCount** No content is currently available. - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverfl** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCoent** No content is currently available. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventSequence** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2828,7 +2819,6 @@ The following fields are available: - **LastEventSingOffender** No content is currently available. - **LastEventsizeOffender** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastEventSizeOffѥnder** No content is currently available. - **LastInv,:3tyttpCode** No content is currently available. - **LastInvali$HttpCode** No content is currently available. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. @@ -2838,6 +2828,7 @@ The following fields are available: - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. - **MaxxrseSum** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. - **renderTrigger** No content is currently available. - **repeatedUploadFailureDropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. @@ -2871,8 +2862,9 @@ The following fields are available: - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResmonseFailures** No content is currently available. +- **VortexHttpResmonsesWithDroppedEvents** No content is currently available. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWit�DroppedEvents** No content is currently available. - **VortexHttpResponsesWitfDroppedEvents** No content is currently available. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - **VortexHttpResponsesWitherDroppEvents** No content is currently available. @@ -2882,23 +2874,6 @@ The following fields are available: - **VortexyttpFailures5xx** No content is currently available. - **VortexyttpResponseFailures** No content is currently available. - **VortexyttpResponsesWithDroppedEvents** No content is currently available. -- **Ω霗⺴䷞釬膏੶ˀ䊋䏾៬㝟쀩ﻊႌ᪘绮開웷** No content is currently available. -- **ⴧꈌ噱罼[ᱪ頱찲刕떈ϩꗊ꒶兛槞捖䏛늊邋瑟⌴슰ݎ뜼뱥윞ᶃ** No content is currently available. -- **ꋦɓ☴槼ꏍ䔕趸邽뽎㞖륮獵衻㚔ʅⰤ脝ꁗ㻨剧敳犿矘葹꾇䬝⨘⏇뷮쨢ʜ꟩** No content is currently available. -- **ᤴ䖋叴햢Ѵ갰㹕壑彔蕢㑟䌛݁ꕿ඼丹䆑鱡** No content is currently available. -- **낎茨��彿孔ゟꪜㄒ謡폲��춗** No content is currently available. -- **덀ၫ랫Ƙퟚ᧔퐼㵜킶䆹荸활謁焄㓵犛Ɤ澴㹭ཧ** No content is currently available. -- **롰用᜜™業䬒㥆ἑ��寞⨱ᾝ䞆쨁悺릾䗳** No content is currently available. -- **뤠蔋弌놅똋궑텪邽櫰৳␮媩䉍��녑䍎񳸑** No content is currently available. -- **셨恮띚㓃瘙칌델࠮鎫ꖋ͇��솗π㹆** No content is currently available. -- **즬铗쐌ﰺ읟좌鄀妏 蹤㻇椤㜊䁔鿺䍇趺懤譀뫺◦ɍ煎㟹** No content is currently available. -- **첎艅ꃣ殠ổ⍦ꫭ簆㈺䥲풾Ϊ攝棥��紽鰫꜌ઁ㌲诡ಆᇆ** No content is currently available. -- **斜⤏ܔ馼쯌ℬ壯ꈹ楖뢨┺挖东ⵕ疐﷤㝊䅁荹隼��䎕㹢��⭶ꮬ瀯** No content is currently available. -- **曺跬蝲㥅䬿應鄶뇵鯔㮡侪ч즗퀾祃迼猀亰햗₊珱姰㜔Ⓤ∔痨쌈ꘄ擑蜉滂** No content is currently available. -- **㚡⁓��漭䖾愶툰ꯛ慤־䨃枛䡹ꋷన件Ⴄ棅譟** No content is currently available. -- **㨲⣦豑棽沵湤ས萾盗椺魹㙞** No content is currently available. -- **㰚姗硴龖㾙** No content is currently available. -- **䱉虙璫ຖꍶ搎⪴偩HttpAttempts** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -2907,8 +2882,6 @@ This event is the telemetry client ARIA heartbeat. The following fields are available: -- **ࠣ⥶墊뗞ᚄ棛묚ﺪ穢꾜浝返枽탙** No content is currently available. -- **㉊��ꐔᦵﲉộ恓拥镳ŏ⺃턺맿삷࣫৘彣䞉䮄** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. @@ -2927,6 +2900,7 @@ The following fields are available: - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** No content is currently available. - **repeatedUploadFailureDropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. @@ -2940,18 +2914,6 @@ The following fields are available: - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **Ω霗⺴䷞釬膏੶ˀ䊋䏾៬㝟쀩ﻊႌ᪘绮開웷** No content is currently available. -- **ⴧꈌ噱罼[ᱪ頱찲刕떈ϩꗊ꒶兛槞捖䏛늊邋瑟⌴슰ݎ뜼뱥윞ᶃ** No content is currently available. -- **ꋦɓ☴槼ꏍ䔕趸邽뽎㞖륮獵衻㚔ʅⰤ脝ꁗ㻨剧敳犿矘葹꾇䬝⨘⏇뷮쨢ʜ꟩** No content is currently available. -- **ᤴ䖋叴햢Ѵ갰㹕壑彔蕢㑟䌛݁ꕿ඼丹䆑鱡** No content is currently available. -- **덀ၫ랫Ƙퟚ᧔퐼㵜킶䆹荸활謁焄㓵犛Ɤ澴㹭ཧ** No content is currently available. -- **롰用᜜™業䬒㥆ἑ��寞⨱ᾝ䞆쨁悺릾䗳** No content is currently available. -- **뤠蔋弌놅똋궑텪邽櫰৳␮媩䉍��녑䍎񳸑** No content is currently available. -- **즬铗쐌ﰺ읟좌鄀妏 蹤㻇椤㜊䁔鿺䍇趺懤譀뫺◦ɍ煎㟹** No content is currently available. -- **斜⤏ܔ馼쯌ℬ壯ꈹ楖뢨┺挖东ⵕ疐﷤㝊䅁荹隼��䎕㹢��⭶ꮬ瀯** No content is currently available. -- **曺跬蝲㥅䬿應鄶뇵鯔㮡侪ч즗퀾祃迼猀亰햗₊珱姰㜔Ⓤ∔痨쌈ꘄ擑蜉滂** No content is currently available. -- **㚡⁓��漭䖾愶툰ꯛ慤־䨃枛䡹ꋷన件Ⴄ棅譟** No content is currently available. -- **䱉虙璫ຖꍶ搎⪴偩HttpAttempts** No content is currently available. ### TelClientSynthetic.HeartBeat_Seville_5 @@ -3519,7 +3481,6 @@ The following fields are available: - **~ersion** No content is currently available. - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiCeqId** No content is currently available. -- **aiSeqI�** No content is currently available. - **aiseqId** No content is currently available. - **aiSeqId** The event sequence ID. - **bo** No content is currently available. @@ -3577,19 +3538,23 @@ The following fields are available: - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsDisplayDevmce** No content is currently available. +- **IsDmsplayDevice** No content is currently available. - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? - **IsHybridDiscrgte** No content is currently available. - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IslidHttpDevice** No content is currently available. +- **IsMiracastScWported** No content is currently available. - **IsMiracastStpported** No content is currently available. - **IsMiracastSupported** Does the GPU support Miracast? - **IsMismatc`LDA** No content is currently available. - **IsMismatchLdA** No content is currently available. - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? - **IsMIsmatchLDA** No content is currently available. +- **IsMPOScWported** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastScWported** No content is currently available. - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsMsMiracastSupposted** No content is currently available. - **IsPostAdapter** Is this GPU the POST GPU in the device? @@ -3598,6 +3563,7 @@ The following fields are available: - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **KMDFmlePath** No content is currently available. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MeasuruEnab|ed** No content is currently available. - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. @@ -3610,7 +3576,6 @@ The following fields are available: - **SharedQystemMemoryB** No content is currently available. - **SharedRystemMemoRyB** No content is currently available. - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **ShaŲedSystemMemoryB** No content is currently available. - **SubFendorID** No content is currently available. - **SubSystemAD** No content is currently available. - **SubSystemID** The subsystem ID. @@ -3618,6 +3583,7 @@ The following fields are available: - **SubVendorID** The GPU sub vendor ID. - **Teleme|ryEnabled** No content is currently available. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTragger** No content is currently available. - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) - **TelInvEvntTrihger** No content is currently available. - **version** The event version. @@ -3715,6 +3681,8 @@ The following fields are available: - **AppTiieStamp** No content is currently available. - **AppTiíeStamp** No content is currently available. - **AppTimeStamp** The date/time stamp of the app. +- **AppTimeSTamp** No content is currently available. +- **AppVerrion** No content is currently available. - **AppVersioj** No content is currently available. - **AppVersion** The version of the app that has crashed. - **BeportId** No content is currently available. @@ -4228,7 +4196,6 @@ The following fields are available: - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. - **WdfVersion** The Windows Driver Framework version. -- **Wd�Version** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove @@ -5112,7 +5079,6 @@ The following fields are available: - **CClienVersion** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVer�ion** No content is currently available. - **Clientversion** No content is currently available. - **ClientVersion** The version number of the software distribution client. - **ClientVersiOn** No content is currently available. @@ -5210,6 +5176,7 @@ The following fields are available: - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). - **QualityUplatePausmPeriod** No content is currently available. +- **QualityWpdatePause** No content is currently available. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RelntedCV** No content is currently available. - **ScanDSrationInSeconds** No content is currently available. @@ -5231,6 +5198,7 @@ The following fields are available: - **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. - **TotalNumMetadaTaSignatures** No content is currently available. - **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WebServicmRetryMethods** No content is currently available. - **WUDericeID** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - **WUDewiceID** No content is currently available. @@ -5303,6 +5271,7 @@ The following fields are available: - **CallerApplictionaName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCotntryCode** No content is currently available. - **CDNCoun.ryCdel** No content is currently available. - **CDNCoundryCode** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. @@ -5378,10 +5347,12 @@ The following fields are available: - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **RdvisionNumber** No content is currently available. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **ReguiationResult** No content is currently available. - **RegulationReason** The reason that the update is regulated - **regulationResult** No content is currently available. - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RegulatIonResult** No content is currently available. +- **ReiatedCV** No content is currently available. - **RelatedCS** No content is currently available. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RelntedCV** No content is currently available. @@ -5531,6 +5502,7 @@ The following fields are available: - **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. - **IsSuccessFailurePst.Reboot** No content is currently available. - **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWufBEnabled** No content is currently available. - **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. - **IsWVfBDualScanEnabled** No content is currently available. - **IsWVfBEnabled** No content is currently available. @@ -7016,7 +6988,6 @@ The following fields are available: - **dkwnloadModeSrc** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **dowflinkBps** No content is currently available. -- **dow�loadMode** No content is currently available. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). - **downloadMode** The download mode used for this file download session. @@ -7111,12 +7082,12 @@ The following fields are available: - **doClientVersion** The version of the Delivery Optimization client. - **doErrorC/de** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. +- **doErrorCoee** No content is currently available. - **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **errorCode** The error code that was returned. - **experimejtId** No content is currently available. -- **experimen�Id** No content is currently available. - **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. - **fiheID** No content is currently available. - **fileID** The ID of the file being downloaded. @@ -7149,21 +7120,15 @@ This event represents a failure to download from a CDN with Delivery Optimizatio The following fields are available: -- **`esponseAize** No content is currently available. - **cdnHeaders** The HTTP headers returned by the CDN. - **cdnIp** The IP address of the CDN. - **cdnUrl** The URL of the CDN. - **eErrorCode** No content is currently available. - **eErrorCunt** No content is currently available. - **errorCode** The error code that was returned. -- **errorCode‡httpStatusCodw** No content is currently available. -- **errorCode‡httpSvatusCodw** No content is currently available. - **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **errorSount** No content is currently available. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **f{leID** No content is currently available. - **fileID** The ID of the file being downloaded. -- **fkleID** No content is currently available. - **htppStatusCode** No content is currently available. - **httpStatusCode** The HTTP status code returned by the CDN. - **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET @@ -7172,7 +7137,6 @@ The following fields are available: - **requestSize** The size of the range requested from the CDN. - **responseSize** The size of the range response received from the CDN. - **sessionID** The ID of the download session. -- **swssionIDcdnUrl** No content is currently available. ### Microsoft.OSG.DU.DeliveryOptClient.JobError From 7a947ae3519aedbde69470085100caf413902771 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 5 Mar 2019 08:50:03 -0800 Subject: [PATCH 038/737] new build --- ...ndows-diagnostic-events-and-fields-1903.md | 22 +++++++++---------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 551c98d759..2c69ccb1c3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -247,19 +247,19 @@ The following fields are available: ### Microsoft.Windows.Security.AppLockerCSP.IsDependencySatisfiedStart -No content is currently available. +Indicates the start of a call to the IsDependencySatisfied function in the Configuration Service Provider (CSP). ### Microsoft.Windows.Security.AppLockerCSP.IsDependencySatisfiedStop -No content is currently available. +Indicates the end of an IsDependencySatisfied function call in the Configuration Service Provider (CSP). The following fields are available: -- **edpActive** No content is currently available. -- **hr** No content is currently available. -- **internalHr** No content is currently available. +- **edpActive** Indicates whether enterprise data protection is active. +- **hr** HRESULT that is reported. +- **internalHr** Internal HRESULT that is reported. ### Microsoft.Windows.Security.AppLockerCSP.SetValueParams @@ -2566,7 +2566,7 @@ The following fields are available: ### TelClientSynthetic.ServiceMain_DevHealthMonEvent -No content is currently available. +This event is a low latency health alert that is part of the 4Nines device health monitoring feature currently available on Surface Hub devices. For a device that is opted in, this event is sent before shutdown to signal that the device is about to be powered down. @@ -3766,14 +3766,14 @@ The following fields are available: ### Microsoft.Windows.PBR.BitLockerWipeFinished -No content is currently available. +This event sends error data after the BitLocker wipe finishes if there were any issues during the wipe. The following fields are available: -- **error** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** The error code if there were any issues during the BitLocker wipe. +- **sessionID** This is the session ID. +- **succeeded** Indicates the BitLocker wipe successful completed. +- **timestamp** Timestamp of the BitLocker wipe. ### Microsoft.Windows.PBR.BootState From bd69c42d7cf792a0f1c46a63f841068d4d16639f Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 6 Mar 2019 08:15:25 -0800 Subject: [PATCH 039/737] Privacy setting --- windows/configuration/TOC.md | 1 + windows/configuration/wcd/wcd-privacy.md | 30 ++++++++++++++++++++++++ windows/configuration/wcd/wcd.md | 3 ++- 3 files changed, 33 insertions(+), 1 deletion(-) create mode 100644 windows/configuration/wcd/wcd-privacy.md diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md index 6be8931eeb..b7102419c7 100644 --- a/windows/configuration/TOC.md +++ b/windows/configuration/TOC.md @@ -102,6 +102,7 @@ #### [OtherAssets](wcd/wcd-otherassets.md) #### [Personalization](wcd/wcd-personalization.md) #### [Policies](wcd/wcd-policies.md) +#### [Privacy](wcd/wcd-privacy.md) #### [ProvisioningCommands](wcd/wcd-provisioningcommands.md) #### [RcsPresence](wcd/wcd-rcspresence.md) #### [SharedPC](wcd/wcd-sharedpc.md) diff --git a/windows/configuration/wcd/wcd-privacy.md b/windows/configuration/wcd/wcd-privacy.md new file mode 100644 index 0000000000..1451f639d8 --- /dev/null +++ b/windows/configuration/wcd/wcd-privacy.md @@ -0,0 +1,30 @@ +--- +title: Privacy (Windows 10) +description: This section describes the Privacy settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: jdeckerMS +ms.localizationpriority: medium +ms.author: jdecker +ms.topic: article +ms.date: 09/06/2017 +--- + +# Privacy (Windows Configuration Designer reference) + +Use **Privacy** to configure settings for app activation with voice. + +## Applies to + +| Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | :---: | :---: | :---: | :---: | :---: | +| All settings | X | X | X | | X | + +## LetAppsActivateWithVoice + +Select between **User is in control**, **Force allow**, or **Force deny**. + +## LetAppsActivateWithVoiceAboveLock + +Select between **User is in control**, **Force allow**, or **Force deny**. \ No newline at end of file diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index c3a9c02907..5f712fd6a9 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -62,8 +62,9 @@ This section describes the settings that you can configure in [provisioning pack | [OtherAssets](wcd-otherassets.md) | | X | | | | | [Personalization](wcd-personalization.md) | X | | | | | | [Policies](wcd-policies.md) | X | X | X | X | X | +| [Privacy](wcd-folders.md) |X | X | X | | X | | [ProvisioningCommands](wcd-provisioningcommands.md) | X | | | | | -[RcsPresence](wcd-rcspresence.md) | | X | | | | +| [RcsPresence](wcd-rcspresence.md) | | X | | | | | [SharedPC](wcd-sharedpc.md) | X | | | | | | [Shell](wcd-shell.md) | | X | | | | | [SMISettings](wcd-smisettings.md) | X | | | | | From c46365464072c7c0be4181132f85d8a14ff78271 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 6 Mar 2019 08:17:45 -0800 Subject: [PATCH 040/737] Privacy added to changed settings --- windows/configuration/wcd/wcd-changes.md | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index b51c2ab60e..7b0376fa7e 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -13,7 +13,13 @@ ms.date: 10/02/2018 # Changes to settings in Windows Configuration Designer -Settings added in Windows 10, version 1809 +## Settings added in Windows 10, version ? + +- [Privacy](wcd-privacy.md) + +## Settings removed in Windows 10, version ? + +## Settings added in Windows 10, version 1809 - [Browser > AllowPrelaunch](wcd-browser.md#allowprelaunch) @@ -74,7 +80,7 @@ Settings added in Windows 10, version 1809 - [WindowsHelloForBusiness](wcd-windowshelloforbusiness.md) -Settings removed in Windows 10, version 1809 +## Settings removed in Windows 10, version 1809 - [CellCore](wcd-cellcore.md) - [Policies > Browser:](wcd-policies.md#browser) From d2a0ddf817893187444845abcc26d145c355b35a Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 6 Mar 2019 08:55:45 -0800 Subject: [PATCH 041/737] new build --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 89 ++++++------------- 4 files changed, 32 insertions(+), 63 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 5dfc2fcfac..326d9590b2 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/04/2019 +ms.date: 03/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index d516d29754..2e4fd66068 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/04/2019 +ms.date: 03/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 6c84d0381d..055c370bdd 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/04/2019 +ms.date: 03/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index d9c00fdff9..f2bfe87d9d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/04/2019 +ms.date: 03/05/2019 --- @@ -311,7 +311,7 @@ The following fields are available: - **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. - **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. - **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS3Setup** No content is currently available. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. - **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. @@ -350,7 +350,7 @@ The following fields are available: - **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. - **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. @@ -363,7 +363,7 @@ The following fields are available: - **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. - **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. @@ -376,7 +376,7 @@ The following fields are available: - **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. - **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. - **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3Setup** No content is currently available. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. @@ -402,7 +402,7 @@ The following fields are available: - **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3Setup** No content is currently available. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. - **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. @@ -441,7 +441,7 @@ The following fields are available: - **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. - **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. - **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS3Setup** No content is currently available. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. - **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. @@ -454,7 +454,7 @@ The following fields are available: - **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. - **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. - **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS3Setup** No content is currently available. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. @@ -467,7 +467,7 @@ The following fields are available: - **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. - **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. - **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3Setup** No content is currently available. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. - **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. @@ -480,7 +480,7 @@ The following fields are available: - **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. - **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. - **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS3Setup** No content is currently available. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. - **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. - **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. @@ -516,8 +516,6 @@ The following fields are available: - **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. - **PCFP** The count of the number of this particular object type present on this device. - **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcesqorP2efetchW** No content is currently available. -- **SystemProcessorCompapeExchange** No content is currently available. - **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. - **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. - **SystemProcessorNx** The total number of objects of this type present on this device. @@ -527,14 +525,13 @@ The following fields are available: - **SystemWim** The total number of objects of this type present on this device. - **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. - **SystemWlan** The total number of objects of this type present on this device. -- **SystemWlAn** No content is currently available. - **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. - **Wmdrm_19H1** The count of the number of this particular object type present on this device. - **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. - **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. - **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. - **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3Setup** No content is currently available. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. - **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. - **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. - **Wmdrm_RS5** The count of the number of this particular object type present on this device. @@ -1366,7 +1363,6 @@ The following fields are available: - **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). - **ram** The amount of memory on the device. - **ramKB** The amount of memory (in KB). -- **virt5al** No content is currently available. - **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). - **virtualKB** The amount of virtual memory (in KB). @@ -1404,7 +1400,6 @@ The following fields are available: - **AppraiserVersion** The version of the Appraiser file generating the events. - **Blocking** Is the upgrade blocked due to the processor? - **CompareExchange128Support** Does the CPU support CompareExchange128? -- **CompareExchange128Swpport** No content is currently available. ### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove @@ -1747,7 +1742,6 @@ The following fields are available: - **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. - **Time** The client time of the event. - **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **VicboseMode** No content is currently available. - **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. @@ -1802,10 +1796,8 @@ The following fields are available: - **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. - **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndT.ApStamp** No content is currently available. - **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. - **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartT.ApStamp** No content is currently available. - **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. - **AppraiserTaskEnabled** Whether the Appraiser task is enabled. - **AppraiserTaskExitCode** The Appraiser task exist code. @@ -1845,9 +1837,7 @@ The following fields are available: - **AADDeviceId** Azure Active Directory device ID. - **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AZureOSIDPresent** No content is currently available. - **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **AZureVMType** No content is currently available. - **CDJType** Represents the type of cloud domain joined for the machine. - **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. - **ContainerType** The type of container, such as process or virtual machine hosted. @@ -1856,7 +1846,6 @@ The following fields are available: - **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false - **IsDERequirementMet** Represents if the device can do device encryption. - **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDeviceRrotected** No content is currently available. - **IsDomainJoined** Indicates whether a machine is joined to a domain. - **IsEDPEnabled** Represents if Enterprise data protected on the device. - **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. @@ -1928,7 +1917,6 @@ The following fields are available: - **SoCName** The firmware manufacturer of the device. - **StudyID** Used to identify retail and non-retail device. - **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnha5Sed** No content is currently available. - **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. - **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. - **TPMManufacturerId** The ID of the TPM manufacturer. @@ -1982,7 +1970,6 @@ The following fields are available: - **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. - **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time - **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **GenuineStateanchNIsPortableOperatingSystem** No content is currently available. - **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). - **InstallLanguage** The first language installed on the user machine. - **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. @@ -2008,7 +1995,6 @@ The following fields are available: - **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. - **ServiceProductKeyID** Retrieves the License key of the KMS - **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signalure** No content is currently available. - **Signature** Retrieves if it is a signature machine sold by Microsoft store. - **SLICStatus** Whether a SLIC table exists on the device. - **SLICVersion** Returns OS type/version from SLIC table. @@ -2024,7 +2010,6 @@ The following fields are available: - **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. - **ActivityHistoryCollection** Current state of the activity history collection setting. - **AdvertisingId** Current state of the advertising ID setting. -- **AdvertisiNgId** No content is currently available. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. - **Bluetooth** Current state of the Bluetooth capability setting. @@ -2038,7 +2023,6 @@ The following fields are available: - **FindMyDevice** Current state of the "find my device" setting. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImpro_ement** No content is currently available. - **InkTypeImprovement** Current state of the improve inking and typing setting. - **Location** Current state of the location setting. - **LocationHistory** Current state of the location history setting. @@ -2109,7 +2093,6 @@ This event is used to gather basic speech settings on the device. The following fields are available: -- **Abo_eLockEnabled** No content is currently available. - **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. - **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. - **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. @@ -2154,7 +2137,6 @@ This event sends data about the logical/physical display size, resolution and nu The following fields are available: -- **InternalPrimaryDis0layResolutionHorizontal** No content is currently available. - **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. - **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. - **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. @@ -2189,14 +2171,12 @@ This event provides information about the current users privacy settings and whe The following fields are available: -- **ActitityHistoryCollection** No content is currently available. - **Activity** Current state of the activity history setting. - **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. - **ActivityHistoryCollection** Current state of the activity history collection setting. - **AdvertisingId** Current state of the advertising ID setting. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. -- **Bluatooth** No content is currently available. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. - **BroadFileSystemAccess** Current state of the broad file system access setting. @@ -2221,7 +2201,6 @@ The following fields are available: - **SensorsCustom** Current state of the custom sensor setting. - **SerialCommunication** Current state of the serial communication setting. - **Sms** Current state of the text messaging setting. -- **SpeechPersonaliza|ion** No content is currently available. - **SpeechPersonalization** Current state of the speech services setting. - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. @@ -2257,7 +2236,6 @@ The following fields are available: - **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). - **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured - **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayeferUpg** No content is currently available. - **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. - **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? - **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? @@ -2278,7 +2256,6 @@ The following fields are available: - **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. - **WUPauseState** Retrieves WU setting to determine if updates are paused. - **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). -- **WWPauseState** No content is currently available. ### Census.Xbox @@ -2469,10 +2446,8 @@ Describes the installation state for all hardware and software components availa The following fields are available: - **action** The change that was invoked on a device inventory object. -- **invent** No content is currently available. - **inventoryId** Device ID used for Compatibility testing - **objectInstanceId** Object identity which is unique within the device scope. -- **objectInstanceId** No content is currently available. - **objectType** Indicates the object type that the event applies to. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. @@ -2697,28 +2672,16 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: -- **Can&erformDiagnosticEscalations** No content is currently available. -- **Can@erformDiagnosticEscalations** No content is currently available. - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectCoreTelemetzy** No content is currently available. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanColleCtHeartbeats** No content is currently available. -- **CanCollectNsTelemetry** No content is currently available. - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagngsticEscalations** No content is currently available. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanPerforoDiagnosticEscalations** No content is currently available. -- **CanRepor5Acenarios** No content is currently available. -- **CanReportscenarios** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **Previous&ermissions** No content is currently available. -- **PreviousPermissaons** No content is currently available. - **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionfromEverythingOff** No content is currently available. - **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. @@ -2730,9 +2693,7 @@ The following fields are available: - **CensusExitCode** Returns last execution codes from census client run. - **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTas{Enasled** No content is currently available. - **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **CwnsusStartTime** No content is currently available. - **LastConnectivityLossTime** Retrieves the last time the device lost free network. - **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. - **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. @@ -2745,26 +2706,17 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: -- **@venStomeRe­etSizeSum** No content is currently available. -- **597pressedBytesUploaded** No content is currently available. -- **5ensusExitCode** No content is currently available. -- **5ensusStartTime** No content is currently available. -- **5ensusTaskEnabled** No content is currently available. - **AgentConnectaonErrorsCount** No content is currently available. - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. - **AudioInMS** No content is currently available. - **AudioOutMS** No content is currently available. - **BackgroundMouseSec** No content is currently available. -- **CensdsExitCode** No content is currently available. -- **CensdsStartTime** No content is currently available. -- **CensdsTaskEnabled** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. - **Com`ressedBytesUploaded** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **CompressedBytesUtyPropagatedSec** No content is currently available. -- **ConsdmerDroppedCount** No content is currently available. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDro`pedCount** No content is currently available. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. @@ -2783,12 +2735,16 @@ The following fields are available: - **DbDroppedFailureCountAgentC** No content is currently available. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **eettingsHttpAttempts** No content is currently available. +- **eettingsHttpFailures** No content is currently available. - **EnteringCriticalOverfl** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedBuffinCount** No content is currently available. - **EtwDroppedCoent** No content is currently available. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventSequence** No content is currently available. +- **EventsPersistedCkunt** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventsPtesistedCount** No content is currently available. - **EventStoreLifetimeResetCo}nter** No content is currently available. @@ -2807,6 +2763,7 @@ The following fields are available: - **FellTriggerBufferDroppedCount** No content is currently available. - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **FullTriggerBuffinDroppedCount** No content is currently available. - **FullTrihgerBufferDroppedCount** No content is currently available. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **Inv,:3tyttpCodeCount** No content is currently available. @@ -2819,6 +2776,7 @@ The following fields are available: - **LastEventSingOffender** No content is currently available. - **LastEventsizeOffender** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastEventSizeOffinder** No content is currently available. - **LastInv,:3tyttpCode** No content is currently available. - **LastInvali$HttpCode** No content is currently available. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. @@ -2865,7 +2823,7 @@ The following fields are available: - **VortexHttpResmonseFailures** No content is currently available. - **VortexHttpResmonsesWithDroppedEvents** No content is currently available. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWitfDroppedEvents** No content is currently available. +- **VortexHttpResponsesWihDroppedEvents** No content is currently available. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - **VortexHttpResponsesWitherDroppEvents** No content is currently available. - **VortexHvtpAttempts** No content is currently available. @@ -3517,22 +3475,28 @@ The following fields are available: - **DrivgrRank** No content is currently available. - **DX10EMDFilePath** No content is currently available. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX10UMDFileTath** No content is currently available. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX11UMDFileTath** No content is currently available. - **DX11UMDFmlePath** No content is currently available. - **Dx11UMDVilePath** No content is currently available. - **DX12UMDFilePaph** No content is currently available. - **Dx12UMDFilePath** No content is currently available. - **DX12UMDfilePath** No content is currently available. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX12UMDFileTath** No content is currently available. - **DX15UMDFilePath** No content is currently available. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **DX9UMDFileTath** No content is currently available. - **DX9UMDFmlePath** No content is currently available. +- **GP]DeviceID** No content is currently available. - **GPEDeviceID** No content is currently available. - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPURevmsionID** No content is currently available. - **GPUVendorID** The GPU vendor ID. +- **I3LDA** No content is currently available. - **I3SoftwAreDåvice** No content is currently available. - **InterfacaId** No content is currently available. - **InterfaceId** The GPU interface ID. @@ -3563,6 +3527,7 @@ The following fields are available: - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **KMDFileTath** No content is currently available. - **KMDFmlePath** No content is currently available. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MeasuruEnab|ed** No content is currently available. @@ -4077,6 +4042,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: +- **basedata** No content is currently available. See [basedata](#basedata). - **BusReportedDescription** The description of the device reported by the bux. - **BusReportelDescription** No content is currently available. - **Class** The device setup class of the driver loaded for the device. @@ -4085,6 +4051,7 @@ The following fields are available: - **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. - **Description** The description of the device. - **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceSta|e** No content is currently available. - **DeviceState** Identifies the current state of the parent (main) device. - **Driver^erDate** No content is currently available. - **DriverId** The unique identifier for the installed driver. @@ -5172,6 +5139,7 @@ The following fields are available: - **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. - **ProcessNcme** No content is currently available. - **ProcessRame** No content is currently available. +- **QualityUpdateDefe2ral** No content is currently available. - **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). @@ -5184,6 +5152,7 @@ The following fields are available: - **ScanEnqueueTime** The number of seconds it took to initialize a scan - **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). - **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceGuld** No content is currently available. - **ServiceUrl** The environment URL a device is configured to scan with - **ShippingMobileOperator** The mobile operator that a device shipped on. - **SsatusCode** No content is currently available. From fa7b429c080d0a15bb6af21ba32d81e4e4c50261 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 6 Mar 2019 08:55:50 -0800 Subject: [PATCH 042/737] new build --- ...ndows-diagnostic-events-and-fields-1903.md | 94 +++++++++++++++++-- 1 file changed, 87 insertions(+), 7 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 2c69ccb1c3..acf6f3f503 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/04/2019 +ms.date: 03/05/2019 --- @@ -2301,6 +2301,76 @@ The following fields are available: ## Diagnostic data events +### TelClientSynthetic.AbnormalShutdown_0 + +This event sends data about boot IDs for which a normal clean shutdown was not observed, to help keep Windows up to date. + +The following fields are available: + +- **AbnormalShutdownBootId** BootId of the abnormal shutdown being reported by this event. +- **AcDcStateAtLastShutdown** Identifies if the device was on battery or plugged in. +- **BatteryLevelAtLastShutdown** The last recorded battery level. +- **BatteryPercentageAtLastShutdown** The battery percentage at the last shutdown. +- **CrashDumpEnabled** Are crash dumps enabled? +- **CumulativeCrashCount** Cumulative count of operating system crashes since the BootId reset. +- **CurrentBootId** BootId at the time the abnormal shutdown event was being reported. +- **Firmwaredata->ResetReasonEmbeddedController** The reset reason that was supplied by the firmware. +- **Firmwaredata->ResetReasonEmbeddedControllerAdditional** Additional data related to reset reason provided by the firmware. +- **Firmwaredata->ResetReasonPch** The reset reason that was supplied by the hardware. +- **Firmwaredata->ResetReasonPchAdditional** Additional data related to the reset reason supplied by the hardware. +- **Firmwaredata->ResetReasonSupplied** Indicates whether the firmware supplied any reset reason or not. +- **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. +- **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. +- **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. +- **LastBugCheckBootId** bootId of the last captured crash. +- **LastBugCheckCode** Code that indicates the type of error. +- **LastBugCheckContextFlags** Additional crash dump settings. +- **LastBugCheckOriginalDumpType** The type of crash dump the system intended to save. +- **LastBugCheckOtherSettings** Other crash dump settings. +- **LastBugCheckParameter1** The first parameter with additional info on the type of the error. +- **LastBugCheckProgress** Progress towards writing out the last crash dump. +- **LastBugCheckVersion** The version of the information struct written during the crash. +- **LastSuccessfullyShutdownBootId** BootId of the last fully successful shutdown. +- **LongPowerButtonPressDetected** Identifies if the user was pressing and holding power button. +- **OOBEInProgress** Identifies if OOBE is running. +- **OSSetupInProgress** Identifies if the operating system setup is running. +- **PowerButtonCumulativePressCount** How many times has the power button been pressed? +- **PowerButtonCumulativeReleaseCount** How many times has the power button been released? +- **PowerButtonErrorCount** Indicates the number of times there was an error attempting to record power button metrics. +- **PowerButtonLastPressBootId** BootId of the last time the power button was pressed. +- **PowerButtonLastPressTime** Date and time of the last time the power button was pressed. +- **PowerButtonLastReleaseBootId** BootId of the last time the power button was released. +- **PowerButtonLastReleaseTime** Date and time of the last time the power button was released. +- **PowerButtonPressCurrentCsPhase** Represents the phase of Connected Standby exit when the power button was pressed. +- **PowerButtonPressIsShutdownInProgress** Indicates whether a system shutdown was in progress at the last time the power button was pressed. +- **PowerButtonPressLastPowerWatchdogStage** Progress while the monitor is being turned on. +- **PowerButtonPressPowerWatchdogArmed** Indicates whether or not the watchdog for the monitor was active at the time of the last power button press. +- **RegKeyLastShutdownBootId** No content is currently available. +- **ShutdownDeviceType** Identifies who triggered a shutdown. Is it because of battery, thermal zones, or through a Kernel API. +- **SleepCheckpoint** Provides the last checkpoint when there is a failure during a sleep transition. +- **SleepCheckpointSource** Indicates whether the source is the EFI variable or bootstat file. +- **SleepCheckpointStatus** Indicates whether the checkpoint information is valid. +- **StaleBootStatData** Identifies if the data from bootstat is stale. +- **TransitionInfoBootId** BootId of the captured transition info. +- **TransitionInfoCSCount** l number of times the system transitioned from Connected Standby mode. +- **TransitionInfoCSEntryReason** Indicates the reason the device last entered Connected Standby mode. +- **TransitionInfoCSExitReason** Indicates the reason the device last exited Connected Standby mode. +- **TransitionInfoCSInProgress** At the time the last marker was saved, the system was in or entering Connected Standby mode. +- **TransitionInfoLastReferenceTimeChecksum** The checksum of TransitionInfoLastReferenceTimestamp, +- **TransitionInfoLastReferenceTimestamp** The date and time that the marker was last saved. +- **TransitionInfoLidState** Describes the state of the laptop lid. +- **TransitionInfoPowerButtonTimestamp** The date and time of the last time the power button was pressed. +- **TransitionInfoSleepInProgress** At the time the last marker was saved, the system was in or entering sleep mode. +- **TransitionInfoSleepTranstionsToOn** Total number of times the device transitioned from sleep mode. +- **TransitionInfoSystemRunning** At the time the last marker was saved, the device was running. +- **TransitionInfoSystemShutdownInProgress** Indicates whether a device shutdown was in progress when the power button was pressed. +- **TransitionInfoUserShutdownInProgress** Indicates whether a user shutdown was in progress when the power button was pressed. +- **TransitionLatestCheckpointId** Represents a unique identifier for a checkpoint during the device state transition. +- **TransitionLatestCheckpointSeqNumber** Represents the chronological sequence number of the checkpoint. +- **TransitionLatestCheckpointType** Represents the type of the checkpoint, which can be the start of a phase, end of a phase, or just informational. +- **VirtualMachineId** If the operating system is on a virtual Machine, it gives the virtual Machine ID (GUID) that can be used to correlate events on the host. + + ### TelClientSynthetic.AuthorizationInfo_RuntimeTransition This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. @@ -3773,7 +3843,7 @@ The following fields are available: - **error** The error code if there were any issues during the BitLocker wipe. - **sessionID** This is the session ID. - **succeeded** Indicates the BitLocker wipe successful completed. -- **timestamp** Timestamp of the BitLocker wipe. +- **timestamp** Time the event occurred. ### Microsoft.Windows.PBR.BootState @@ -3789,7 +3859,7 @@ The following fields are available: ### Microsoft.Windows.PBR.ClearTPMStarted -No content is currently available. +This event sends basic data about the recovery operation on the device to allow investigation. The following fields are available: @@ -3808,6 +3878,16 @@ The following fields are available: - **timestamp** No content is currently available. +### Microsoft.Windows.PBR.Completed + +No content is currently available. + +The following fields are available: + +- **sessionID** No content is currently available. +- **timestamp** No content is currently available. + + ### Microsoft.Windows.PBR.DataVolumeCount No content is currently available. @@ -3836,9 +3916,9 @@ No content is currently available. The following fields are available: -- **apiName** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **apiName** Name of the API command that is about to execute. +- **sessionID** The session ID. +- **timestamp** Time the event occurred. ### Microsoft.Windows.PBR.EnteredOOBE @@ -4586,7 +4666,7 @@ The following fields are available: ### Microsoft.Windows.Security.WSC.DatastoreMigratedVersion -No content is currently available. +This event provides information about the datastore migration and whether it was successful. The following fields are available: From 85d69bae6492fd0cb0442675c074447e30857076 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 6 Mar 2019 09:24:40 -0800 Subject: [PATCH 043/737] DeviceUpdatecenter --- windows/configuration/TOC.md | 1 + windows/configuration/wcd/wcd-changes.md | 1 + .../wcd/wcd-deviceupdatecenter.md | 36 +++++++++++++++++++ windows/configuration/wcd/wcd.md | 1 + 4 files changed, 39 insertions(+) create mode 100644 windows/configuration/wcd/wcd-deviceupdatecenter.md diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md index b7102419c7..6d017d3a92 100644 --- a/windows/configuration/TOC.md +++ b/windows/configuration/TOC.md @@ -79,6 +79,7 @@ #### [DeviceFormFactor](wcd/wcd-deviceformfactor.md) #### [DeviceInfo](wcd/wcd-deviceinfo.md) #### [DeviceManagement](wcd/wcd-devicemanagement.md) +#### [DeviceUpdateCenter](wcd/wcd-deviceupdatecenter.md) #### [DMClient](wcd/wcd-dmclient.md) #### [EditionUpgrade](wcd/wcd-editionupgrade.md) #### [EmbeddedLockdownProfiles](wcd/wcd-embeddedlockdownprofiles.md) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 7b0376fa7e..47da52ab8b 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -15,6 +15,7 @@ ms.date: 10/02/2018 ## Settings added in Windows 10, version ? +- [DeviceUpdateCenter](wcd-deviceupdatecenter.md) - [Privacy](wcd-privacy.md) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd-deviceupdatecenter.md b/windows/configuration/wcd/wcd-deviceupdatecenter.md new file mode 100644 index 0000000000..66331ab161 --- /dev/null +++ b/windows/configuration/wcd/wcd-deviceupdatecenter.md @@ -0,0 +1,36 @@ +--- +title: DeviceUpdateCenter (Windows 10) +description: This section describes the DeviceUpdateCenter settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: jdeckerMS +ms.localizationpriority: medium +ms.author: jdecker +ms.topic: article +ms.date: 09/06/2017 +--- + +# DeviceUpdateCenter (Windows Configuration Designer reference) + +Use **DeviceUpdateCenter** to configure settings for + +## Applies to + +| Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | :---: | :---: | :---: | :---: | :---: | +| All settings | X | | | | | + +## CustomPackageId + + + +## DeviceModelId + + + +## OemPartnerRing + + + +## PublisherId \ No newline at end of file diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index 5f712fd6a9..5b762d47e7 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -39,6 +39,7 @@ This section describes the settings that you can configure in [provisioning pack | [DeviceFormFactor](wcd-deviceformfactor.md) | X | X | X | X | | | [DeviceInfo](wcd-deviceinfo.md) | | X | | | | | [DeviceManagement](wcd-devicemanagement.md) | X | X | X | X | | +| [DeviceUpdateCenter](wcd-deviceupdatecenter.md) | X | | | | | | [DMClient](wcd-dmclient.md) | X | X | X | X | X | | [EditionUpgrade](wcd-editionupgrade.md) | X | X | X | X | | | [EmbeddedLockdownProfiles](wcd-embeddedlockdownprofiles.md) | | X | | | | From ae257a5d27c0b48bcf15104db839b98c4ed8cdde Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 6 Mar 2019 11:01:54 -0800 Subject: [PATCH 044/737] finish DeviceUpdateCenter --- .../configuration/wcd/wcd-deviceupdatecenter.md | 15 +-------------- 1 file changed, 1 insertion(+), 14 deletions(-) diff --git a/windows/configuration/wcd/wcd-deviceupdatecenter.md b/windows/configuration/wcd/wcd-deviceupdatecenter.md index 66331ab161..7417a12104 100644 --- a/windows/configuration/wcd/wcd-deviceupdatecenter.md +++ b/windows/configuration/wcd/wcd-deviceupdatecenter.md @@ -13,7 +13,7 @@ ms.date: 09/06/2017 # DeviceUpdateCenter (Windows Configuration Designer reference) -Use **DeviceUpdateCenter** to configure settings for +Do not use **DeviceUpdateCenter** settings at this time. ## Applies to @@ -21,16 +21,3 @@ Use **DeviceUpdateCenter** to configure settings for | --- | :---: | :---: | :---: | :---: | :---: | | All settings | X | | | | | -## CustomPackageId - - - -## DeviceModelId - - - -## OemPartnerRing - - - -## PublisherId \ No newline at end of file From 94c2799be4a0ca332e0974ab76a946d1524271f9 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 07:49:42 -0700 Subject: [PATCH 045/737] time --- windows/configuration/wcd/wcd-time.md | 30 +++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 windows/configuration/wcd/wcd-time.md diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md new file mode 100644 index 0000000000..1451f639d8 --- /dev/null +++ b/windows/configuration/wcd/wcd-time.md @@ -0,0 +1,30 @@ +--- +title: Privacy (Windows 10) +description: This section describes the Privacy settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: jdeckerMS +ms.localizationpriority: medium +ms.author: jdecker +ms.topic: article +ms.date: 09/06/2017 +--- + +# Privacy (Windows Configuration Designer reference) + +Use **Privacy** to configure settings for app activation with voice. + +## Applies to + +| Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | :---: | :---: | :---: | :---: | :---: | +| All settings | X | X | X | | X | + +## LetAppsActivateWithVoice + +Select between **User is in control**, **Force allow**, or **Force deny**. + +## LetAppsActivateWithVoiceAboveLock + +Select between **User is in control**, **Force allow**, or **Force deny**. \ No newline at end of file From a43f3bf1001164189866202907a91695ff97c092 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 08:09:24 -0700 Subject: [PATCH 046/737] Time --- windows/configuration/TOC.md | 3 ++- windows/configuration/wcd/wcd-changes.md | 1 + windows/configuration/wcd/wcd-time.md | 17 +++++++---------- windows/configuration/wcd/wcd.md | 1 + 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md index 6d017d3a92..b0edfde74e 100644 --- a/windows/configuration/TOC.md +++ b/windows/configuration/TOC.md @@ -116,7 +116,8 @@ #### [TabletMode](wcd/wcd-tabletmode.md) #### [TakeATest](wcd/wcd-takeatest.md) #### [TextInput](wcd/wcd-textinput.md) -#### [Theme](wcd/wcd-theme.md) +#### [Theme](wcd/wcd-theme.md) +#### [Time](wcd/wcd-time.md) #### [UnifiedWriteFilter](wcd/wcd-unifiedwritefilter.md) #### [UniversalAppInstall](wcd/wcd-universalappinstall.md) #### [UniversalAppUninstall](wcd/wcd-universalappuninstall.md) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 47da52ab8b..f235ced4e7 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -17,6 +17,7 @@ ms.date: 10/02/2018 - [DeviceUpdateCenter](wcd-deviceupdatecenter.md) - [Privacy](wcd-privacy.md) +- [Time](wcd-time.md) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index 1451f639d8..d3d0a9c80e 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -1,6 +1,6 @@ --- -title: Privacy (Windows 10) -description: This section describes the Privacy settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. +title: Time (Windows 10) +description: This section describes the Time settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library @@ -11,20 +11,17 @@ ms.topic: article ms.date: 09/06/2017 --- -# Privacy (Windows Configuration Designer reference) - -Use **Privacy** to configure settings for app activation with voice. +Use **Time** to configure settings for time zone setup for Windows 10, version (TBD) and later. ## Applies to | Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | :---: | :---: | :---: | :---: | :---: | -| All settings | X | X | X | | X | +| [ProvisionSetTimeZone](#provisionsettimezone) | X | | | | | -## LetAppsActivateWithVoice +## ProvisionSetTimeZone -Select between **User is in control**, **Force allow**, or **Force deny**. +Set to **True** to skip time zone assignment when the first user signs in. -## LetAppsActivateWithVoiceAboveLock +Set to **False** for time zone assignment to occur when the first user signs in. -Select between **User is in control**, **Force allow**, or **Force deny**. \ No newline at end of file diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index 5b762d47e7..b19b249d08 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -77,6 +77,7 @@ This section describes the settings that you can configure in [provisioning pack | [TakeATest](wcd-takeatest.md) | X | | | | | | [TextInput](wcd-textinput.md) | | X | | | | | [Theme](wcd-theme.md) | | X | | | | +| [Time](wcd-time.md) | X | | | | | | [UnifiedWriteFilter](wcd-unifiedwritefilter.md) | X | | | | X | | [UniversalAppInstall](wcd-universalappinstall.md) | X | X | X | X | X | | [UniversalAppUninstall](wcd-universalappuninstall.md) | X | X | X | X | X | From 5dea266c3da874da90f967c8a0f36e5a33c3a38c Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 08:38:18 -0700 Subject: [PATCH 047/737] fix h1 --- windows/configuration/wcd/wcd-time.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index d3d0a9c80e..52ade98614 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -11,6 +11,8 @@ ms.topic: article ms.date: 09/06/2017 --- +# Time + Use **Time** to configure settings for time zone setup for Windows 10, version (TBD) and later. ## Applies to From 3e645c8e1ad75e02afdbca38a58579c8d476d084 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 12 Mar 2019 08:43:04 -0700 Subject: [PATCH 048/737] new build 3012019 --- ...ndows-diagnostic-events-and-fields-1903.md | 674 ++++++++++++------ 1 file changed, 449 insertions(+), 225 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index acf6f3f503..ac9b7be4f3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/05/2019 +ms.date: 03/12/2019 --- @@ -1744,14 +1744,18 @@ The following fields are available: - **AdvertisingId** Current state of the advertising ID setting. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. +- **AppointmentsSystem** No content is currently available. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. - **BroadFileSystemAccess** Current state of the broad file system access setting. - **CellularData** Current state of the cellular data capability setting. - **Chat** Current state of the chat setting. +- **ChatSystem** Current state of the chat setting. - **Contacts** Current state of the contacts setting. +- **ContactsSystem** No content is currently available. - **DocumentsLibrary** Current state of the documents library setting. - **Email** Current state of the email setting. +- **EmailSystem** No content is currently available. - **FindMyDevice** Current state of the "find my device" setting. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. @@ -1763,6 +1767,7 @@ The following fields are available: - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. +- **PhoneCallHistorySystem** No content is currently available. - **PicturesLibrary** Current state of the pictures library setting. - **Radios** Current state of the radios setting. - **SensorsCustom** Current state of the custom sensor setting. @@ -1772,6 +1777,7 @@ The following fields are available: - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. +- **UserDataTasksSystem** No content is currently available. - **UserNotificationListener** Current state of the notifications setting. - **VideosLibrary** Current state of the videos library setting. - **Webcam** Current state of the camera setting. @@ -1909,14 +1915,18 @@ The following fields are available: - **AdvertisingId** Current state of the advertising ID setting. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. +- **AppointmentsSystem** No content is currently available. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. - **BroadFileSystemAccess** Current state of the broad file system access setting. - **CellularData** Current state of the cellular data capability setting. - **Chat** Current state of the chat setting. +- **ChatSystem** No content is currently available. - **Contacts** Current state of the contacts setting. +- **ContactsSystem** No content is currently available. - **DocumentsLibrary** Current state of the documents library setting. - **Email** Current state of the email setting. +- **EmailSystem** No content is currently available. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. - **InkTypeImprovement** Current state of the improve inking and typing setting. @@ -1928,6 +1938,7 @@ The following fields are available: - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. +- **PhoneCallHistorySystem** No content is currently available. - **PicturesLibrary** Current state of the pictures library setting. - **Radios** Current state of the radios setting. - **SensorsCustom** Current state of the custom sensor setting. @@ -1937,6 +1948,7 @@ The following fields are available: - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. +- **UserDataTasksSystem** No content is currently available. - **UserNotificationListener** Current state of the notifications setting. - **VideosLibrary** Current state of the videos library setting. - **Webcam** Current state of the camera setting. @@ -2345,7 +2357,7 @@ The following fields are available: - **PowerButtonPressIsShutdownInProgress** Indicates whether a system shutdown was in progress at the last time the power button was pressed. - **PowerButtonPressLastPowerWatchdogStage** Progress while the monitor is being turned on. - **PowerButtonPressPowerWatchdogArmed** Indicates whether or not the watchdog for the monitor was active at the time of the last power button press. -- **RegKeyLastShutdownBootId** No content is currently available. +- **RegKeyLastShutdownBootId** The last recorded boot ID. - **ShutdownDeviceType** Identifies who triggered a shutdown. Is it because of battery, thermal zones, or through a Kernel API. - **SleepCheckpoint** Provides the last checkpoint when there is a failure during a sleep transition. - **SleepCheckpointSource** Indicates whether the source is the EFI variable or bootstat file. @@ -3758,6 +3770,59 @@ The following fields are available: - **UserInputTime** The amount of time the loader application spent waiting for user input. +### Microsoft.Windows.Kernel.DeviceConfig.DeviceConfig + +No content is currently available. + +The following fields are available: + +- **ClassGuid** No content is currently available. +- **DeviceInstanceId** No content is currently available. +- **DriverDate** No content is currently available. +- **DriverFlightIds** No content is currently available. +- **DriverInfName** No content is currently available. +- **DriverProvider** No content is currently available. +- **DriverSubmissionId** No content is currently available. +- **DriverVersion** No content is currently available. +- **ExtensionDrivers** No content is currently available. +- **FirstHardwareId** No content is currently available. +- **InboxDriver** No content is currently available. +- **InstallDate** No content is currently available. +- **LastCompatibleId** No content is currently available. +- **Legacy** No content is currently available. +- **NeedReboot** No content is currently available. +- **SetupMode** No content is currently available. +- **StatusCode** No content is currently available. + + +### Microsoft.Windows.Kernel.PnP.AggregateClearDevNodeProblem + +No content is currently available. + +The following fields are available: + +- **Count** No content is currently available. +- **DeviceInstanceId** No content is currently available. +- **LastProblem** No content is currently available. +- **LastProblemStatus** No content is currently available. +- **ServiceName** No content is currently available. + + +### Microsoft.Windows.Kernel.PnP.AggregateSetDevNodeProblem + +No content is currently available. + +The following fields are available: + +- **Count** No content is currently available. +- **DeviceInstanceId** No content is currently available. +- **LastProblem** No content is currently available. +- **LastProblemStatus** No content is currently available. +- **Problem** No content is currently available. +- **ProblemStatus** No content is currently available. +- **ServiceName** No content is currently available. + + ## Miracast events ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd @@ -3834,6 +3899,165 @@ The following fields are available: ## Other events +### MicArrayGeometry + +No content is currently available. + +The following fields are available: + +- **MicCoords** No content is currently available. +- **usFrequencyBandHi** No content is currently available. +- **usFrequencyBandLo** No content is currently available. +- **usMicArrayType** No content is currently available. +- **usNumberOfMicrophones** No content is currently available. +- **usVersion** No content is currently available. +- **wHorizontalAngleBegin** No content is currently available. +- **wHorizontalAngleEnd** No content is currently available. +- **wVerticalAngleBegin** No content is currently available. +- **wVerticalAngleEnd** No content is currently available. + + +### MicCoords + +No content is currently available. + +The following fields are available: + +- **usType** No content is currently available. +- **wHorizontalAngle** No content is currently available. +- **wVerticalAngle** No content is currently available. +- **wXCoord** No content is currently available. +- **wYCoord** No content is currently available. +- **wZCoord** No content is currently available. + + +### Microsoft.Windows.Audio.EndpointBuilder.DeviceInfo + +No content is currently available. + +The following fields are available: + +- **BusEnumeratorName** No content is currently available. +- **ContainerId** No content is currently available. +- **DeviceInstanceId** No content is currently available. +- **EndpointDevnodeId** No content is currently available. +- **endpointEffectClsid** No content is currently available. +- **endpointEffectModule** No content is currently available. +- **EndpointFormFactor** No content is currently available. +- **endpointID** No content is currently available. +- **endpointInstanceId** No content is currently available. +- **Flow** No content is currently available. +- **globalEffectClsid** No content is currently available. +- **globalEffectModule** No content is currently available. +- **HWID** No content is currently available. +- **IsBluetooth** No content is currently available. +- **isFarField** No content is currently available. +- **IsSideband** No content is currently available. +- **IsUSB** No content is currently available. +- **JackSubType** No content is currently available. +- **localEffectClsid** No content is currently available. +- **localEffectModule** No content is currently available. +- **MicArrayGeometry** No content is currently available. See [MicArrayGeometry](#micarraygeometry). +- **modeEffectClsid** No content is currently available. +- **modeEffectModule** No content is currently available. +- **persistentId** No content is currently available. +- **streamEffectClsid** No content is currently available. +- **streamEffectModule** No content is currently available. + + +### Microsoft.Windows.DriverInstall.DeviceInstall + +No content is currently available. + +The following fields are available: + +- **ClassGuid** No content is currently available. +- **ClassLowerFilters** No content is currently available. +- **ClassUpperFilters** No content is currently available. +- **CoInstallers** No content is currently available. +- **ConfigFlags** No content is currently available. +- **DeviceConfigured** No content is currently available. +- **DeviceInstanceId** No content is currently available. +- **DeviceStack** No content is currently available. +- **DriverDate** No content is currently available. +- **DriverDescription** No content is currently available. +- **DriverInfName** No content is currently available. +- **DriverInfSectionName** No content is currently available. +- **DriverPackageId** No content is currently available. +- **DriverProvider** No content is currently available. +- **DriverUpdated** No content is currently available. +- **DriverVersion** No content is currently available. +- **EndTime** No content is currently available. +- **Error** No content is currently available. +- **ExtensionDrivers** No content is currently available. +- **FinishInstallAction** No content is currently available. +- **FinishInstallUI** No content is currently available. +- **FirmwareDate** No content is currently available. +- **FirmwareRevision** No content is currently available. +- **FirmwareVersion** No content is currently available. +- **FirstHardwareId** No content is currently available. +- **FlightIds** No content is currently available. +- **GenericDriver** No content is currently available. +- **Inbox** No content is currently available. +- **InstallDate** No content is currently available. +- **LastCompatibleId** No content is currently available. +- **LegacyInstallReasonError** No content is currently available. +- **LowerFilters** No content is currently available. +- **MatchingDeviceId** No content is currently available. +- **NeedReboot** No content is currently available. +- **OriginalDriverInfName** No content is currently available. +- **ParentDeviceInstanceId** No content is currently available. +- **PendedUntilReboot** No content is currently available. +- **Problem** No content is currently available. +- **ProblemStatus** No content is currently available. +- **SecondaryDevice** No content is currently available. +- **ServiceName** No content is currently available. +- **SetupMode** No content is currently available. +- **StartTime** No content is currently available. +- **SubmissionId** No content is currently available. +- **UpperFilters** No content is currently available. + + +### Microsoft.Windows.DriverInstall.NewDevInstallDeviceEnd + +No content is currently available. + +The following fields are available: + +- **DeviceInstanceId** No content is currently available. +- **DriverUpdated** No content is currently available. +- **Error** No content is currently available. +- **FlightId** No content is currently available. +- **InstallDate** No content is currently available. +- **InstallFlags** No content is currently available. +- **RebootRequired** No content is currently available. +- **RollbackPossible** No content is currently available. +- **WuTargetedHardwareId** No content is currently available. +- **WuUntargetedHardwareId** No content is currently available. + + +### Microsoft.Windows.DriverInstall.NewDevInstallDeviceStart + +No content is currently available. + +The following fields are available: + +- **DeviceInstanceId** No content is currently available. +- **FirstInstallDate** No content is currently available. +- **LastDriverDate** No content is currently available. +- **LastDriverInbox** No content is currently available. +- **LastDriverInfName** No content is currently available. +- **LastDriverVersion** No content is currently available. +- **LastFirmwareDate** No content is currently available. +- **LastFirmwareRevision** No content is currently available. +- **LastFirmwareVersion** No content is currently available. +- **LastInstallDate** No content is currently available. +- **LastMatchingDeviceId** No content is currently available. +- **LastProblem** No content is currently available. +- **LastProblemStatus** No content is currently available. +- **LastSubmissionId** No content is currently available. + + ### Microsoft.Windows.PBR.BitLockerWipeFinished This event sends error data after the BitLocker wipe finishes if there were any issues during the wipe. @@ -3848,7 +4072,7 @@ The following fields are available: ### Microsoft.Windows.PBR.BootState -No content is currently available. +This event sends data on the Windows Recovery Environment (WinRE) boot, which can be used to determine whether the boot was successful. The following fields are available: @@ -3884,8 +4108,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of the push-button reset session. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.DataVolumeCount @@ -3918,7 +4142,7 @@ The following fields are available: - **apiName** Name of the API command that is about to execute. - **sessionID** The session ID. -- **timestamp** Time the event occurred. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.EnteredOOBE @@ -3927,8 +4151,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.LeaveAPI @@ -3937,10 +4161,10 @@ No content is currently available. The following fields are available: -- **apiName** No content is currently available. -- **errorCode** No content is currently available. -- **sessionID** No content is currently available. -- **success** No content is currently available. +- **apiName** Name of the API command that completed. +- **errorCode** Error code if an error occurred during the API call. +- **sessionID** The ID of this push-button reset session. +- **success** Indicates whether the API call was successful. - **timestamp** No content is currently available. @@ -3950,14 +4174,14 @@ No content is currently available. The following fields are available: -- **exitCode** No content is currently available. -- **param** No content is currently available. -- **phase** No content is currently available. -- **script** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timedOut** No content is currently available. -- **timestamp** No content is currently available. +- **exitCode** The exit code from OEM extensibility scripts to push-button reset. +- **param** Parameters used for the OEM extensibility script. +- **phase** Name of the OEM extensibility script phase. +- **script** The path to the OEM extensibility script. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether the OEM extensibility script executed successfully. +- **timedOut** Indicates whether the OEM extensibility script timed out. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.OEMExtensionStarted @@ -3966,11 +4190,11 @@ No content is currently available. The following fields are available: -- **param** No content is currently available. -- **phase** No content is currently available. -- **script** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **param** The parameters used by the OEM extensibility script. +- **phase** The name of the OEM extensibility script phase. +- **script** The path to the OEM extensibility script. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.OperationExecuteFinished @@ -3979,13 +4203,13 @@ No content is currently available. The following fields are available: -- **error** No content is currently available. -- **index** No content is currently available. -- **operation** No content is currently available. -- **phase** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** Indicates the result code of the event. +- **index** The operation index. +- **operation** The name of the operation. +- **phase** The name of the operation phase. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether the operation successfully completed. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.OperationExecuteStarted @@ -3994,12 +4218,12 @@ No content is currently available. The following fields are available: -- **index** No content is currently available. -- **operation** No content is currently available. -- **phase** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. -- **weight** No content is currently available. +- **index** The index of this operation. +- **operation** The name of this operation. +- **phase** The phase of this operation. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Timestamp of this push-button reset event. +- **weight** The weight of the operation used to distribute the change in percentage. ### Microsoft.Windows.PBR.OperationQueueConstructFinished @@ -4008,10 +4232,10 @@ No content is currently available. The following fields are available: -- **error** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** The result code for operation queue construction. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether the operation successfully completed. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.OperationQueueConstructStarted @@ -4020,8 +4244,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.PBRClearRollBackEntry @@ -4030,7 +4254,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRClearTPMFailed @@ -4039,7 +4263,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionFailed @@ -4048,12 +4272,12 @@ No content is currently available. The following fields are available: -- **HRESULT** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. -- **SPErrorCode** No content is currently available. -- **SPOperation** No content is currently available. -- **SPPhase** No content is currently available. +- **HRESULT** Indicates the result code of the event. +- **PBRType** The type of push-button reset. +- **SessionID** The ID of this push-button reset session. +- **SPErrorCode** The error code for the Setup Platform operation. +- **SPOperation** The last Setup Platform operation. +- **SPPhase** The last phase of the Setup Platform operation. ### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionSucceed @@ -4062,10 +4286,10 @@ No content is currently available. The following fields are available: -- **CBSPackageCount** No content is currently available. -- **CustomizationPackageCount** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **CBSPackageCount** The Component Based Servicing package count. +- **CustomizationPackageCount** The Customization package count. +- **PBRType** The type of push-button reset. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRDriverInjectionFailed @@ -4074,7 +4298,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRFailed @@ -4083,9 +4307,9 @@ No content is currently available. The following fields are available: -- **ErrorType** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **ErrorType** The result code for the push-button reset error. +- **PBRType** The type of push-button reset. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRFinalizeNewSystemFailed @@ -4094,11 +4318,11 @@ No content is currently available. The following fields are available: -- **HRESULT** No content is currently available. -- **SessionID** No content is currently available. -- **SPErrorCode** No content is currently available. -- **SPOperation** No content is currently available. -- **SPPhase** No content is currently available. +- **HRESULT** The result error code. +- **SessionID** The ID of this push-button reset session. +- **SPErrorCode** The error code for the Setup Platform operation. +- **SPOperation** The Setup Platform operation. +- **SPPhase** The phase of the Setup Platform operation. ### Microsoft.Windows.PBR.PBRFinalizeNewSystemSucceed @@ -4107,7 +4331,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRFinalUserSelection @@ -4116,12 +4340,12 @@ No content is currently available. The following fields are available: -- **PBREraseData** No content is currently available. -- **PBRRecoveryStrategy** No content is currently available. -- **PBRRepartitionDisk** No content is currently available. -- **PBRVariation** No content is currently available. -- **PBRWipeDataDrives** No content is currently available. -- **SessionID** No content is currently available. +- **PBREraseData** Indicates whether the option to erase data is selected. +- **PBRRecoveryStrategy** The recovery strategy for the push-button reset operation. +- **PBRRepartitionDisk** Indicates whether the user has selected the option to repartition the disk. +- **PBRVariation** Indicates the push-button reset type. +- **PBRWipeDataDrives** Indicates whether the option to wipe the data drives is selected. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRFormatOSVolumeFailed @@ -4130,8 +4354,8 @@ No content is currently available. The following fields are available: -- **JustDeleteFiles** No content is currently available. -- **SessionID** No content is currently available. +- **JustDeleteFiles** Indicates whether disk formatting was skipped. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRFormatOSVolumeSucceed @@ -4150,7 +4374,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRIOCTLErasureSucceed @@ -4159,7 +4383,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRLayoutImageFailed @@ -4168,7 +4392,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRLayoutImageSucceed @@ -4177,7 +4401,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBROEM1Failed @@ -4186,11 +4410,11 @@ No content is currently available. The following fields are available: -- **HRESULT** No content is currently available. -- **Parameters** No content is currently available. -- **PBRType** No content is currently available. -- **ScriptName** No content is currently available. -- **SessionID** No content is currently available. +- **HRESULT** The result error code from the OEM extensibility script. +- **Parameters** The parameters that were passed to the OEM extensibility script. +- **PBRType** The type of push-button reset. +- **ScriptName** The path to the OEM extensibility script. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBROEM2Failed @@ -4199,11 +4423,11 @@ No content is currently available. The following fields are available: -- **HRESULT** No content is currently available. -- **Parameters** No content is currently available. -- **PBRType** No content is currently available. -- **ScriptName** No content is currently available. -- **SessionID** No content is currently available. +- **HRESULT** The result code for the error that occurred while running the OEM extensibility script. +- **Parameters** The parameters to the OEM extensibility script. +- **PBRType** The type of push-button reset. +- **ScriptName** The path to the push-button reset script. +- **SessionID** The ID of the push-button reset session. ### Microsoft.Windows.PBR.PBRPostApplyFailed @@ -4212,7 +4436,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRPostApplyFinished @@ -4221,7 +4445,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRPostApplyStarted @@ -4230,7 +4454,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRPreApplyFailed @@ -4239,7 +4463,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRPreApplyFinished @@ -4248,7 +4472,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRPreApplyStarted @@ -4257,7 +4481,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRReachedOOBE @@ -4275,7 +4499,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRRequirementChecks @@ -4284,10 +4508,10 @@ No content is currently available. The following fields are available: -- **DeploymentType** No content is currently available. -- **InstallType** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **DeploymentType** The type of deployment. +- **InstallType** The type of installation. +- **PBRType** The type of push-button reset. +- **SessionID** The ID for this push-button reset session. ### Microsoft.Windows.PBR.PBRRequirementChecksFailed @@ -4296,14 +4520,14 @@ No content is currently available. The following fields are available: -- **DiskSpaceAvailable** No content is currently available. -- **DiskSpaceRequired** No content is currently available. -- **ErrorType** No content is currently available. -- **PBRImageVersion** No content is currently available. -- **PBRRecoveryStrategy** No content is currently available. +- **DiskSpaceAvailable** The disk space available for the push-button reset. +- **DiskSpaceRequired** The disk space required for the push-button reset. +- **ErrorType** The type of error that occurred during the requirement checks phase of the push-button reset operation. +- **PBRImageVersion** The image version of the push-button reset tool. +- **PBRRecoveryStrategy** The recovery strategy for this phase of push-button reset. - **PBRStartedFrom** No content is currently available. - **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRRequirementChecksPassed @@ -4314,10 +4538,10 @@ The following fields are available: - **OSVersion** No content is currently available. - **PBRImageType** No content is currently available. -- **PBRImageVersion** No content is currently available. +- **PBRImageVersion** The version of the push-button reset image. - **PBRRecoveryStrategy** No content is currently available. - **PBRStartedFrom** No content is currently available. -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRRestoreLicenseFailed @@ -4326,7 +4550,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRSucceed @@ -4336,8 +4560,8 @@ No content is currently available. The following fields are available: - **OSVersion** No content is currently available. -- **PBRType** No content is currently available. -- **SessionID** No content is currently available. +- **PBRType** The type of push-button reset. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRUserCancelled @@ -4346,9 +4570,9 @@ No content is currently available. The following fields are available: -- **CancelPage** No content is currently available. -- **PBRVariation** No content is currently available. -- **SessionID** No content is currently available. +- **CancelPage** The ID of the page where the user clicked Cancel. +- **PBRVariation** The type of push-button reset. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRVersionsMistmatch @@ -4358,8 +4582,8 @@ No content is currently available. The following fields are available: - **OSVersion** No content is currently available. -- **REVersion** No content is currently available. -- **SessionID** No content is currently available. +- **REVersion** The version of Windows Recovery Environment (WinRE). +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRWinREInstallationFailed @@ -4368,7 +4592,7 @@ No content is currently available. The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PhaseFinished @@ -4377,11 +4601,11 @@ No content is currently available. The following fields are available: -- **error** No content is currently available. -- **phase** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** The result code for this phase of push-button reset. +- **phase** The name of this push-button reset phase. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether this phase of push-button reset executed successfully. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.PhaseStarted @@ -4390,9 +4614,9 @@ No content is currently available. The following fields are available: -- **phase** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **phase** The name of this phase of push-button reset. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.ReconstructionInfo @@ -4401,12 +4625,12 @@ No content is currently available. The following fields are available: -- **numPackagesAbandoned** No content is currently available. -- **numPackagesFailed** No content is currently available. -- **sessionID** No content is currently available. -- **slowMode** No content is currently available. +- **numPackagesAbandoned** The number of packages that were abandoned during the reconstruction operation of push-button reset. +- **numPackagesFailed** The number of packages that failed during the reconstruction operation of push-button reset. +- **sessionID** The ID of this push-button reset session. +- **slowMode** The mode of reconstruction. - **targetVersion** No content is currently available. -- **timestamp** No content is currently available. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.ResetOptions @@ -4415,12 +4639,12 @@ No content is currently available. The following fields are available: -- **overwriteSpace** No content is currently available. -- **preserveWorkplace** No content is currently available. -- **scenario** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. -- **wipeData** No content is currently available. +- **overwriteSpace** Indicates whether the option was selected to erase data during push-button reset. +- **preserveWorkplace** Indicates whether the option was selected to reserve the workplace during push-button reset. +- **scenario** The selected scenario for the push-button on reset operation. +- **sessionID** The ID of this push-button on reset session. +- **timestamp** The timestamp of this push-button on reset event. +- **wipeData** Indicates whether the option was selected to wipe additional drives during push-button reset. ### Microsoft.Windows.PBR.RetryQueued @@ -4429,9 +4653,9 @@ No content is currently available. The following fields are available: -- **attempt** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **attempt** The number of retry attempts that were made +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.ReturnedToOldOS @@ -4440,8 +4664,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.ReturnTaskSchedulingFailed @@ -4450,10 +4674,10 @@ No content is currently available. The following fields are available: -- **errorCode** No content is currently available. -- **sessionID** No content is currently available. -- **taskName** No content is currently available. -- **timestamp** No content is currently available. +- **errorCode** The error that occurred while scheduling the task. +- **sessionID** The ID of this push-button reset session. +- **taskName** The name of the task. +- **timestamp** The ID of this push-button reset event. ### Microsoft.Windows.PBR.RollbackFinished @@ -4462,10 +4686,10 @@ No content is currently available. The following fields are available: -- **error** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** Any errors that occurred during rollback to the old operating system. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether the rollback succeeded. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.RollbackStarted @@ -4474,8 +4698,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.ScenarioNotSupported @@ -4484,10 +4708,10 @@ No content is currently available. The following fields are available: -- **errorCode** No content is currently available. -- **reason** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **errorCode** The error that occurred. +- **reason** The reason why this push-button reset scenario is not supported. +- **sessionID** The ID for this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SessionCreated @@ -4496,8 +4720,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SessionResumed @@ -4506,8 +4730,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SessionSaved @@ -4516,8 +4740,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SetupExecuteFinished @@ -4527,8 +4751,8 @@ No content is currently available. The following fields are available: - **sessionID** No content is currently available. -- **systemState** No content is currently available. -- **timestamp** No content is currently available. +- **systemState** Information about the system state of the Setup Platform operation. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SetupExecuteStarted @@ -4537,8 +4761,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.SetupFinalizeStarted @@ -4547,8 +4771,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.SetupOperationFailed @@ -4557,11 +4781,11 @@ No content is currently available. The following fields are available: -- **errorCode** No content is currently available. -- **sessionID** No content is currently available. -- **setupExecutionOperation** No content is currently available. -- **setupExecutionPhase** No content is currently available. -- **timestamp** No content is currently available. +- **errorCode** An error that occurred during the setup phase of push-button reset. +- **sessionID** The ID of this push-button reset session. +- **setupExecutionOperation** The name of the Setup Platform operation. +- **setupExecutionPhase** The phase of the setup operation that failed. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SystemInfoField @@ -4570,10 +4794,10 @@ No content is currently available. The following fields are available: -- **name** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. -- **value** No content is currently available. +- **name** Name of the system information field. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp of this push-button reset event. +- **value** The system information field value. ### Microsoft.Windows.PBR.SystemInfoListItem @@ -4582,11 +4806,11 @@ No content is currently available. The following fields are available: -- **index** No content is currently available. -- **name** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. -- **value** No content is currently available. +- **index** The index number associated with the system information item. +- **name** The name of the list of system information items. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. +- **value** The value of the system information item. ### Microsoft.Windows.PBR.SystemInfoSenseFinished @@ -4595,10 +4819,10 @@ No content is currently available. The following fields are available: -- **error** No content is currently available. -- **sessionID** No content is currently available. -- **succeeded** No content is currently available. -- **timestamp** No content is currently available. +- **error** The error code if an error occurred while querying for system information. +- **sessionID** The ID of this push-button reset session. +- **succeeded** Indicates whether the query for system information was successful. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SystemInfoSenseStarted @@ -4607,8 +4831,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset event. +- **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.UserAcknowledgeCleanupWarning @@ -4617,8 +4841,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.UserCancel @@ -4627,9 +4851,9 @@ No content is currently available. The following fields are available: -- **pageID** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **pageID** The page ID for the page the user canceled. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.UserConfirmStart @@ -4638,8 +4862,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.WinREInstallFinished @@ -4648,10 +4872,10 @@ No content is currently available. The following fields are available: -- **errorCode** No content is currently available. -- **sessionID** No content is currently available. -- **success** No content is currently available. -- **timestamp** No content is currently available. +- **errorCode** Any error that occurred during the Windows Recovery Environment (WinRE) installation. +- **sessionID** The ID of this push-button reset session. +- **success** Indicates whether the Windows Recovery Environment (WinRE) installation successfully completed. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.PBR.WinREInstallStarted @@ -4660,8 +4884,8 @@ No content is currently available. The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The timestamp for this push-button reset event. ### Microsoft.Windows.Security.WSC.DatastoreMigratedVersion @@ -4670,9 +4894,9 @@ This event provides information about the datastore migration and whether it was The following fields are available: -- **datastoreisvtype** No content is currently available. -- **datastoremigrated** No content is currently available. -- **status** No content is currently available. +- **datastoreisvtype** The product category of the datastore. +- **datastoremigrated** The version of the datastore that was migrated. +- **status** The result code of the migration. ### Microsoft.Windows.Security.WSC.GetCallerViaWdsp @@ -4735,28 +4959,28 @@ No content is currently available. The following fields are available: -- **errorCode** No content is currently available. +- **errorCode** The error code if there was a failure during uninstallation of the latest cumulative Windows update package. ### Microsoft.Windows.SysReset.LCUUninstall -No content is currently available. +This event is sent when the latest cumulative Windows update was uninstalled on a device. The following fields are available: -- **errorCode** No content is currently available. -- **packageName** No content is currently available. -- **removalTime** No content is currently available. +- **errorCode** An error that occurred while the Windows update package was being uninstalled. +- **packageName** The name of the Windows update package that is being uninstalled. +- **removalTime** The amount of time it took to uninstall the Windows update package. ### Microsoft.Windows.SysReset.PBRBlockedByPolicy -No content is currently available. +This event is sent when a push-button reset operation is blocked by the System Administrator. The following fields are available: -- **PBRBlocked** No content is currently available. -- **PBRType** No content is currently available. +- **PBRBlocked** Reason the push-button reset operation was blocked. +- **PBRType** The type of push-button reset operation that was blocked. ### Microsoft.Windows.SysReset.PBREngineInitFailed @@ -4790,13 +5014,13 @@ The following fields are available: ### Microsoft.Windows.SystemReset.EsimPresentCheck -No content is currently available. +This event is sent when a device is checked to see whether it has an embedded SIM (eSIM). The following fields are available: -- **errorCode** No content is currently available. -- **esimPresent** No content is currently available. -- **sessionID** No content is currently available. +- **errorCode** Any error that occurred while checking for the presence of an embedded SIM. +- **esimPresent** Indicates whether an embedded SIM is present on the device. +- **sessionID** The ID of this session. ### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption @@ -4813,12 +5037,12 @@ The following fields are available: ### Microsoft.Windows.SystemReset.RepairNeeded -No content is currently available. +This event provides information about whether a system reset needs repair. The following fields are available: -- **repairNeeded** No content is currently available. -- **sessionID** No content is currently available. +- **repairNeeded** Indicates whether there was corruption in the system reset which needs repair. +- **sessionID** The ID of this push-button reset session. ### Microsoft.Xbox.XamTelemetry.AppActivationError @@ -7406,19 +7630,19 @@ The following fields are available: - **OwningScenarioId** The scenario ID the client that called the begin scenario function. - **ReturnCode** The return code for the begin scenario operation. - **ScenarioId** The scenario ID that is internal to the reserve manager. -- **SoftReserveSize** No content is currently available. -- **SoftReserveUsedSpace** No content is currently available. +- **SoftReserveSize** The size of the soft reserve. +- **SoftReserveUsedSpace** The amount of soft reserve space that was used. ### Microsoft.Windows.UpdateReserveManager.ClearReserve -No content is currently available. +This event is sent when the Update Reserve Manager clears one of the reserves. The following fields are available: -- **FinalReserveUsedSpace** No content is currently available. -- **InitialReserveUsedSpace** No content is currently available. -- **ReserveId** No content is currently available. +- **FinalReserveUsedSpace** The amount of used space for the reserve after it was cleared. +- **InitialReserveUsedSpace** The amount of used space for the reserve before it was cleared. +- **ReserveId** The ID of the reserve that needs to be cleared. ### Microsoft.Windows.UpdateReserveManager.ClearSoftReserve @@ -7557,8 +7781,8 @@ This event is sent when the Update Reserve Manager needs to adjust the size of t The following fields are available: - **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **Disposition** No content is currently available. -- **Flags** No content is currently available. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. - **PendingHardReserveAdjustment** The final change to the hard reserve size. - **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. From 6d94f92d119702fd58fb35a2dc28a4b2042b5c0e Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 09:00:25 -0700 Subject: [PATCH 049/737] kick --- windows/configuration/wcd/wcd-time.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index 52ade98614..53ddcd5768 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -13,7 +13,7 @@ ms.date: 09/06/2017 # Time -Use **Time** to configure settings for time zone setup for Windows 10, version (TBD) and later. +Use **Time** to configure settings for time zone setup for Windows 10, version (TBD) and later. ## Applies to From 69c866cdb8abfd71ae970761a553a8904d871876 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 09:11:35 -0700 Subject: [PATCH 050/737] dataclassmapping --- windows/configuration/wcd/wcd-cellular.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/configuration/wcd/wcd-cellular.md b/windows/configuration/wcd/wcd-cellular.md index f6c9545c4a..1019d87dd8 100644 --- a/windows/configuration/wcd/wcd-cellular.md +++ b/windows/configuration/wcd/wcd-cellular.md @@ -52,6 +52,10 @@ Enter the destination path for the BrandingIcon .ico file. Enter the service provider name for the mobile operator. +### DataClassMappingTable + +Enter a customized string for the appropriate [data class](https://docs.microsoft.com/windows/desktop/api/mbnapi/ne-mbnapi-mbn_data_class). + ### NetworkBlockList Enter a comma-separated list of mobile country code (MCC) and mobile network code (MCC) pairs (MCC:MNC). From 0d9297789312bb864eddb6ad42dd1277846cabec Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 09:28:16 -0700 Subject: [PATCH 051/737] enablecortanavoice --- windows/configuration/wcd/wcd-changes.md | 2 ++ windows/configuration/wcd/wcd-oobe.md | 30 +++++++++++++++--------- 2 files changed, 21 insertions(+), 11 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index f235ced4e7..909614945c 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -18,6 +18,8 @@ ms.date: 10/02/2018 - [DeviceUpdateCenter](wcd-deviceupdatecenter.md) - [Privacy](wcd-privacy.md) - [Time](wcd-time.md) +- [Cellular > DataClassMappingTable](wcd-cellular.md#dataclassmappingtable) +- [OOBE > EnableCortanaVoice](wcd-oobe.md#enablecortanavoice) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index 35acf44bc2..8c3e9913d9 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -19,9 +19,27 @@ Use to configure settings for the Out Of Box Experience (OOBE). | Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | :---: | :---: | :---: | :---: | :---: | +| [Desktop > EnableCortanaVoice](#enablecortanavoice) | X | | | | | +| [Desktop > HideOobe](#hided) | X | | | | | | [Mobile > EnforceEnterpriseProvisioning](#nforce) | | X | | | | | [Mobile > HideOobe](#hidem) | | X | | | | -| [Desktop > HideOobe](#hided) | X | | | | | + + + + +## EnableCortanaVoice + +Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default. Select **True** to enable voice-over during OOBE on Windows 10 Pro, Education, and Enterprise. + + +## HideOobe for desktop + +When set to **True**, it hides the interactive OOBE flow for Windows 10. + +>[!NOTE] +>You must create a user account if you set the value to true or the device will not be usable. + +When set to **False**, the OOBE screens are displayed. ## EnforceEnterpriseProvisioning @@ -35,14 +53,4 @@ When set to **False**, it does not force the OOBE flow to the enterprise provisi When set to **True**, it hides the interactive OOBE flow for Windows 10 Mobile. -When set to **False**, the OOBE screens are displayed. - - -## HideOobe for desktop - -When set to **True**, it hides the interactive OOBE flow for Windows 10. - ->[!NOTE] ->You must create a user account if you set the value to true or the device will not be usable. - When set to **False**, the OOBE screens are displayed. \ No newline at end of file From d3b8b81f0229a494b1db52579589ecd2c31bec44 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 12 Mar 2019 11:22:20 -0700 Subject: [PATCH 052/737] tweak --- windows/configuration/wcd/wcd-oobe.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index 8c3e9913d9..b6ca14a3ca 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -29,7 +29,7 @@ Use to configure settings for the Out Of Box Experience (OOBE). ## EnableCortanaVoice -Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default. Select **True** to enable voice-over during OOBE on Windows 10 Pro, Education, and Enterprise. +Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default on Windows 10 Pro, Education, and Enterprise. The voice-over is enabled by default on Windows 10 Home. Select **True** to enable voice-over during OOBE. ## HideOobe for desktop From afc765a3568c666251a9d43ff34e1780826970b2 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 12 Mar 2019 16:33:28 -0700 Subject: [PATCH 053/737] new build 3/12/2019 4:33 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 71 +- ...ndows-diagnostic-events-and-fields-1709.md | 18 +- ...ndows-diagnostic-events-and-fields-1803.md | 16 +- ...ndows-diagnostic-events-and-fields-1809.md | 15449 ++++++++-------- 4 files changed, 7947 insertions(+), 7607 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index ab42290c6b..2e2ac4486f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/12/2019 --- @@ -1822,61 +1822,6 @@ The following fields are available: ## Diagnostic data events -### TelClientSynthetic.AbnormalShutdown_0 - -This event sends data about boot IDs for which a normal clean shutdown was not observed, to help keep Windows up to date. - -The following fields are available: - -- **AbnormalShutdownBootId** Retrieves the Boot ID for which the abnormal shutdown was observed. -- **CrashDumpEnabled** Indicates whether crash dumps are enabled. -- **CumulativeCrashCount** Cumulative count of operating system crashes since the BootId reset. -- **CurrentBootId** BootId at the time the abnormal shutdown event was being reported. -- **FirmwareResetReasonEmbeddedController** Firmware-supplied reason for the reset. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional data related to the reset reason provided by the firmware. -- **FirmwareResetReasonPch** Hardware-supplied reason for the reset. -- **FirmwareResetReasonPchAdditional** Additional data related to the reset reason provided by the hardware. -- **FirmwareResetReasonSupplied** Indicates whether the firmware supplied any reset reason. -- **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. -- **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. -- **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. -- **LastBugCheckBootId** The Boot ID of the last captured crash. -- **LastBugCheckCode** Code that indicates the type of error. -- **LastBugCheckContextFlags** Additional crash dump settings. -- **LastBugCheckOriginalDumpType** The type of crash dump the system intended to save. -- **LastBugCheckOtherSettings** Other crash dump settings. -- **LastBugCheckParameter1** The first parameter with additional info on the type of the error. -- **LastBugCheckProgress** Progress towards writing out the last crash dump. -- **LastSuccessfullyShutdownBootId** The Boot ID of the last fully successful shutdown. -- **PowerButtonCumulativePressCount** Indicates the number of times the power button has been pressed ("pressed" not to be confused with "released"). -- **PowerButtonCumulativeReleaseCount** Indicates the number of times the power button has been released ("released" not to be confused with "pressed"). -- **PowerButtonErrorCount** Indicates the number of times there was an error attempting to record Power Button metrics (e.g.: due to a failure to lock/update the bootstat file). -- **PowerButtonLastPressBootId** The Boot ID of the last time the Power Button was detected to have been pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastPressTime** The date and time the Power Button was most recently pressed ("pressed" not to be confused with "released"). -- **PowerButtonLastReleaseBootId** The Boot ID of the last time the Power Button was released ("released" not to be confused with "pressed"). -- **PowerButtonLastReleaseTime** The date and time the Power Button was most recently released ("released" not to be confused with "pressed"). -- **PowerButtonPressCurrentCsPhase** Represents the phase of Connected Standby exit when the power button was pressed. -- **PowerButtonPressIsShutdownInProgress** Indicates whether a system shutdown was in progress at the last time the Power Button was pressed. -- **PowerButtonPressLastPowerWatchdogStage** The last stage completed when the Power Button was most recently pressed. -- **PowerButtonPressPowerWatchdogArmed** Indicates whether or not the watchdog for the monitor was active at the time of the last power button press. -- **TransitionInfoBootId** The Boot ID of the captured transition information. -- **TransitionInfoCSCount** The total number of times the system transitioned from "Connected Standby" mode to "On" when the last marker was saved. -- **TransitionInfoCSEntryReason** Indicates the reason the device last entered "Connected Standby" mode ("entered" not to be confused with "exited"). -- **TransitionInfoCSExitReason** Indicates the reason the device last exited "Connected Standby" mode ("exited" not to be confused with "entered"). -- **TransitionInfoCSInProgress** Indicates whether the system was in or entering Connected Standby mode when the last marker was saved. -- **TransitionInfoLastReferenceTimeChecksum** The checksum of TransitionInfoLastReferenceTimestamp. -- **TransitionInfoLastReferenceTimestamp** The date and time that the marker was last saved. -- **TransitionInfoPowerButtonTimestamp** The most recent date and time when the Power Button was pressed (collected via a different mechanism than PowerButtonLastPressTime). -- **TransitionInfoSleepInProgress** Indicates whether the system was in or entering Sleep mode when the last marker was saved. -- **TransitionInfoSleepTranstionsToOn** The total number of times the system transitioned from Sleep mode to on, when the last marker was saved. -- **TransitionInfoSystemRunning** Indicates whether the system was running when the last marker was saved. -- **TransitionInfoSystemShutdownInProgress** Indicates whether a device shutdown was in progress when the power button was pressed. -- **TransitionInfoUserShutdownInProgress** Indicates whether a user shutdown was in progress when the power button was pressed. -- **TransitionLatestCheckpointId** Represents a unique identifier for a checkpoint during the device state transition. -- **TransitionLatestCheckpointSeqNumber** Represents the chronological sequence number of the checkpoint. -- **TransitionLatestCheckpointType** Represents the type of the checkpoint, which can be the start of a phase, end of a phase, or just informational. - - ### TelClientSynthetic.AuthorizationInfo_RuntimeTransition This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. @@ -4236,7 +4181,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5127,12 +5072,12 @@ This event lists the reboot reason when an app is going to reboot. The following fields are available: -- **BootId** The boot ID. +- **BootId** The system boot ID. - **BoottimeSinceLastShutdown** The boot time since the last shutdown. - **RebootReason** Reason for the reboot. -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.Partner.ReportApplication @@ -6296,6 +6241,12 @@ This event sends data specific to the FixupEditionId mitigation used for OS Upda ## Windows Update Reserve Manager events +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 658324d8b4..d6a2e128d8 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/12/2019 --- @@ -68,7 +68,7 @@ The following fields are available: - **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. - **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. - **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryLanguagePack** The count of InventoryLanguagePack objects present on this machine. - **InventoryMediaCenter** The count of the number of this particular object type present on this device. - **InventorySystemBios** The count of the number of this particular object type present on this device. - **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. @@ -4128,7 +4128,7 @@ The following fields are available: - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Unique revision number of Update - **ServerId** Identifier for the service to which the software distribution client is connecting, such as Windows Update and Microsoft Store. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **UpdateId** Unique Update ID @@ -4192,7 +4192,7 @@ The following fields are available: - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5298,7 +5298,7 @@ The following fields are available: - **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.Partner.ReportApplication @@ -6514,6 +6514,12 @@ The following fields are available: ## Windows Update Reserve Manager events +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 55e5adf886..e88b4da389 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -7,13 +7,13 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security localizationpriority: high -audience: ITPro author: brianlic-msft ms.author: brianlic manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/15/2019 +audience: ITPro +ms.date: 03/12/2019 --- @@ -4934,7 +4934,7 @@ The following fields are available: - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) - **SystemBIOSMajorRelease** Major release version of the system bios - **SystemBIOSMinorRelease** Minor release version of the system bios - **UpdateId** Identifier associated with the specific piece of content @@ -4997,7 +4997,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5988,7 +5988,7 @@ The following fields are available: - **PertProb** Constant used in algorithm for randomization. -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.StoreActivating @@ -7646,6 +7646,12 @@ This event is sent when the Update Reserve Manager returns an error from one of +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + + + ### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index f8a042ef3d..fd7cd31194 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7536 +1,7913 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -audience: ITPro -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -ms.date: 02/15/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **action** The change that was invoked on a device inventory object. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiSeqId** The event sequence ID. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplayAdapterLuid** The display adapter LUID. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **GPUDeviceID** The GPU device ID. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPURevisionID** The GPU revision ID. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **version** The event version. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **AppName** The name of the app that has crashed. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModName** Exception module name (e.g. bar.dll). -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BusReportedDescription** The description of the device reported by the bux. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Description** The description of the device. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **HWID** A list of hardware IDs for the device. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **ProblemCode** The error code currently returned by the device, if applicable. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKID** The list of hardware IDs for the stack. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilters** The identifiers of the Upper filters installed for the device. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **ImageSize** The size of the driver file. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **hr** The HResult of the operation. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **WUDeviceID** The unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** The endpoint URL where the device obtains update metadata. This is used to distinguish between test, staging, and production environments. -- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. -- **ExtendedStatusCode** The secondary status code of the event. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast -- **StatusCode** The status code of the event. -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineResult** Error code from the engine operation. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Microsoft Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **CategoryId** The Item Category ID. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The product family name of the product being installed. -- **ProductId** The identity of the package or packages being installed. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUpdate** Is this an update? -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNumber** The number of attempts by the user to download. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefinedCallerName** The name of the API Caller. -- **restrictedUpload** Is the upload restricted? -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller object. -- **reasonCode** The reason for pausing the download. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Indicates whether the download is happening in the background. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **fileID** The ID of the file being downloaded. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groupID** ID for the group. -- **isEncrypted** Indicates whether the download is encrypted. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCallerName** Name of the API caller. -- **routeToCacheServer** Cache server setting, source, and value. -- **sessionID** The ID for the file download session. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** Indicates whether the download used memory streaming. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/12/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **inventoryId** Device ID used for Compatibility testing +- **objectIîstanceId** No content is currently available. +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCol|ectCoreTelemetry** No content is currently available. +- **CanCollactCoreTelemetry** No content is currently available. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformDiagnostigEscalations** No content is currently available. +- **CanPerformDkagnosticEscalations** No content is currently available. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScanarios** No content is currently available. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **AgentConnctionErrorsCount** No content is currently available. +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgenticenectionErrorsCount** No content is currently available. +- **CeesusExitCode** No content is currently available. +- **CeesusStartTime** No content is currently available. +- **CeesusTaskEnabled** No content is currently available. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataDbLroppedCount** No content is currently available. +- **CriticalDataDhrottleDroppedCount** No content is currently available. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CriticamOverflowEntersCounter** No content is currently available. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DbDroppedOailureCount** No content is currently available. +- **DbDroppedOullCount** No content is currently available. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DhrottledDroppedCount** No content is currently available. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **Eve~tStoreResetCounter** No content is currently available. +- **EventSC06eLifetimeResetCounter** No content is currently available. +- **EventSC06eResetCounter** No content is currently available. +- **EventSC06eResetSizeSum** No content is currently available. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **icesumerDroppedCount** No content is currently available. +- **icmpressedBytesUploaded** No content is currently available. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastAgenticenectionError** No content is currently available. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **LastreReseizeOffender** No content is currently available. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxActiveAgenticenectionCount** No content is currently available. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **Olags** No content is currently available. +- **OullTriggerBufferDroppedCount** No content is currently available. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xS** No content is currently available. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xS** No content is currently available. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWihDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. +- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. +- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. +- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. +- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. +- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. +- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. +- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. +- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. +- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. +- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). +- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. +- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. +- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterDypeValue** No content is currently available. +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BvightnessVersionViaDDI** No content is currently available. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DisplayAdapterLuid** The display adapter LUID. +- **Driver48,k** No content is currently available. +- **DriverDate** The date of the display driver. +- **DriverRa~k** No content is currently available. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9]MDFilePath** No content is currently available. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **GPUDeviceID** The GPU device ID. +- **GPUPree}ptionLevel** No content is currently available. +- **GPUPreemptionLdvel** No content is currently available. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPUVendoeID** No content is currently available. +- **GPUVendorID** The GPU vendor ID. +- **InterbaceId** No content is currently available. +- **InterfaceId** The GPU interface ID. +- **IqMPOSupported** No content is currently available. +- **IrRemovable** No content is currently available. +- **IsDisp|ayDevice** No content is currently available. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridIntdgrated** No content is currently available. +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOCupported** No content is currently available. +- **IsMPOSuppor|ed** No content is currently available. +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **IsSoftwareDevicg** No content is currently available. +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSyste}ID** No content is currently available. +- **SubSystemID** The subsystem ID. +- **SubVendoeID** No content is currently available. +- **SubVendorID** The GPU sub vendor ID. +- **TelematryEnabled** No content is currently available. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **version** The event version. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **@ackageRelativeAppId** No content is currently available. +- **AppName** The name of the app that has crashed. +- **AppSeqsionGuid** No content is currently available. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **AptName** No content is currently available. +- **DargetAppId** No content is currently available. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModNamevaultsv** No content is currently available. +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **PackageFullName** Store application identity. +- **PackageRelaatieAppId** No content is currently available. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Dedevi.DedeviInventoryChange](#msdedevidedeviinventorychange). + +The following fields are available: + +- **basedata** No content is currently available. See [basedata](#basedata). +- **BusReportedDescription** The description of the device reported by the bux. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **COMPID.Count** No content is currently available. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Description** The description of the device. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **HWID** A list of hardware IDs for the device. +- **HWID.Count** No content is currently available. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **Manufacturer** The manufacturer of the device. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Model** Identifies the model of the device. +- **ParentId** The Device Instance ID of the parent of the device. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **Provider** Identifies the device provider. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **STACKID.Count** No content is currently available. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **ImageSize** The size of the driver file. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersio~** No content is currently available. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. +- **f** No content is currently available. See [f](#f). + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **hr** The HResult of the operation. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **-149ngContextMessage** No content is currently available. +- **3645entContextName** No content is currently available. +- **379rentContextName** No content is currently available. +- **532rentContextName** No content is currently available. +- **677rentContextName** No content is currently available. +- **8108entContextName** No content is currently available. +- **8251entContextName** No content is currently available. +- **902rentContextName** No content is currently available. +- **9567ngContextMessage** No content is currently available. +- **9717ngContextMessage** No content is currently available. +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextMessaon** No content is currently available. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **functige** No content is currently available. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **ori1-0467ngContextMessage** No content is currently available. +- **ori1-1210ngContextMessage** No content is currently available. +- **ori1143-7ngContextMessage** No content is currently available. +- **ori1-1945ngContextMessage** No content is currently available. +- **ori13s090ngContextMessage** No content is currently available. +- **ori1-4671entContextName** No content is currently available. +- **ori1-5108ngContextMessage** No content is currently available. +- **ori1-5686ngContextMessage** No content is currently available. +- **ori1n:667ngContextMessage** No content is currently available. +- **ori1n8488ngContextMessage** No content is currently available. +- **ori1-s4o5ngContextMessage** No content is currently available. +- **ori808467ngContextMessage** No content is currently available. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **Falue** No content is currently available. +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedetadataICabUrl** No content is currently available. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedetadataISignatures** No content is currently available. +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumetadataISignatures** No content is currently available. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumbe2** No content is currently available. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHalhFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXBoockHashFailures** No content is currently available. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **AppXScopr** No content is currently available. +- **B}ndleId** No content is currently available. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCoqnt** No content is currently available. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **BytesDownnoaded** No content is currently available. +- **C`llerApplicationName** No content is currently available. +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationname** No content is currently available. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CalLerApplicationName** No content is currently available. +- **CallerApplictionaName** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCotntryCode** No content is currently available. +- **CDNCoun.ryCdel** No content is currently available. +- **CDNCoundryCode** No content is currently available. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNd** No content is currently available. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CtatusCode** No content is currently available. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownhoadProps** No content is currently available. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **DownloedPriority** No content is currently available. +- **DventInstanceID** No content is currently available. +- **e:4|SInstanceID** No content is currently available. +- **e:4|SScenario** No content is currently available. +- **E:4|State** No content is currently available. +- **EöentInstanceID** No content is currently available. +- **Eve.tScenario** No content is currently available. +- **EventInst.9ceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventInstAnceID** No content is currently available. +- **EventPype** No content is currently available. +- **EventScanario** No content is currently available. +- **eventScenario** No content is currently available. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **EventTypr** No content is currently available. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **Fli.c9BuildNumber** No content is currently available. +- **Fli.c9Id** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HospName** No content is currently available. +- **HostName** The hostname URL the content is downloading from. +- **Hst.Name** No content is currently available. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWQfBEnabled** No content is currently available. +- **IsWUfBDualCcanEnabled** No content is currently available. +- **IsWUfBdualScanEnabled** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnablad** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkCst.** No content is currently available. +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **NetworkRestrictiontartus** No content is currently available. +- **oadPriority** No content is currently available. +- **PackageFullName** The package name of the content. +- **PegulationResult** No content is currently available. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldDime** No content is currently available. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **Pst.DnldTime** No content is currently available. +- **PvocessName** No content is currently available. +- **QpdateId** No content is currently available. +- **QualityreUpdaPause** No content is currently available. +- **QualityUpdatePa}se** No content is currently available. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePatse** No content is currently available. +- **QualityUpdatePausa** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RdvisionNumber** No content is currently available. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **ReguiationResult** No content is currently available. +- **RegulationReason** The reason that the update is regulated +- **regulationResult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulatIonResult** No content is currently available. +- **ReiatedCV** No content is currently available. +- **RelatedCS** No content is currently available. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RelntedCV** No content is currently available. +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **tartusCdel** No content is currently available. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **tizeCalcTime** No content is currently available. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **Upda|eImportance** No content is currently available. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImporEvent** No content is currently available. +- **UpdateImpornstan** No content is currently available. +- **UpdateImport.9ce** No content is currently available. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **Use** No content is currently available. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDericeID** No content is currently available. +- **WUDeviceId** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CallerApplictionaName** No content is currently available. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CSIErrorTypr** No content is currently available. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoverqIds** No content is currently available. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **DriverRecoverySds** No content is currently available. +- **DriverRecownloIds** No content is currently available. +- **EvåntInstanceID** No content is currently available. +- **Even|InstanceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventInstapceID** No content is currently available. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **EventTypr** No content is currently available. +- **ExtendedErrorCdel** No content is currently available. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **ExtendefStatusCode** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdateUause** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HandlerTypr** No content is currently available. +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsKcfBDualScanEnabled** No content is currently available. +- **IsKcfBEnabled** No content is currently available. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsSuccessFailurePostReotId** No content is currently available. +- **IsSuccessFailurePst.Reboot** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWufBEnabled** No content is currently available. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **IsWVfBDualScanEnabled** No content is currently available. +- **IsWVfBEnabled** No content is currently available. +- **lundleId** No content is currently available. +- **lundleRepeatFailCount** No content is currently available. +- **lundleRevisionNumber** No content is currently available. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCdel** No content is currently available. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageBullName** No content is currently available. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdateUause** No content is currently available. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersaon** No content is currently available. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetingVession** No content is currently available. +- **tartusCdel** No content is currently available. +- **TransactionCdel** No content is currently available. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UpdateImportapce** No content is currently available. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDdviceID** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDevi'eID** No content is currently available. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **RelntedCV** No content is currently available. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **umberOfApplicableUpdates** No content is currently available. +- **WUDeviceID** The unique device ID controlled by the software distribution client. +- **xHDeviceID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **CallerLoglicationName** No content is currently available. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. +- **ExtendedStatusCode** The secondary status code of the event. +- **ExtendefStatusCode** No content is currently available. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RcwMode** No content is currently available. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **SedviceGuid** No content is currently available. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **ServiceGuidEndpointUrl** No content is currently available. +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast +- **StatusCode** The status code of the event. +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **essionData** No content is currently available. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **Friled** No content is currently available. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanãeId** No content is currently available. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **value** No content is currently available. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **o-Ste** No content is currently available. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineResult** Error code from the engine operation. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckPar%meter2** No content is currently available. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AggregatedPackageFullNcmes** No content is currently available. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **Bundlele** No content is currently available. +- **CategoryId** The Item Category ID. +- **Categoryle** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **ClientApple** No content is currently available. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **ParentBundlele** No content is currently available. +- **PFN** The product family name of the product being installed. +- **Producele** No content is currently available. +- **ProductId** The identity of the package or packages being installed. +- **S{stemAttemptNumber** No content is currently available. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNaies** No content is currently available. +- **AggregatedpackageFullNames** No content is currently available. +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUp`ate** No content is currently available. +- **IsUpdate** Is this an update? +- **ParentBuneleId** No content is currently available. +- **PFN** Product Family Name of the product being installed. +- **Produc|Id** No content is currently available. +- **productId** No content is currently available. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullLames** No content is currently available. +- **AggregatedPackageFullNaðes** No content is currently available. +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **CategoryIf** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNum`er** No content is currently available. +- **UserAttemptNumber** The number of attempts by the user to download. +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **__TlgCÖ__** No content is currently available. +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsInteragtive** No content is currently available. +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **CatanogId** No content is currently available. +- **CatdlogId** No content is currently available. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **JResult** No content is currently available. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **Producele** No content is currently available. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **categoryId** No content is currently available. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **#dnErrorCounts** No content is currently available. +- **__TlgCVß_** No content is currently available. +- **|anConnectionCount** No content is currently available. +- **}plinkUsageBps** No content is currently available. +- **0redefinedCallerName** No content is currently available. +- **b6nConnectionCount** No content is currently available. +- **b6nErrorCodes** No content is currently available. +- **b6nErrorCounts** No content is currently available. +- **b6nIp** No content is currently available. +- **b6nUrl** No content is currently available. +- **background** Is the download a background download? +- **bytesFrkmIntPeers** No content is currently available. +- **bytesFromCacheSedver** No content is currently available. +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCdN** No content is currently available. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntÐeers** No content is currently available. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheSarverConnectionCount** No content is currently available. +- **cacheSedverConnectionCount** No content is currently available. +- **cacheServerConndctionCount** No content is currently available. +- **cacheServerConnectionCoujt** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnSonnectionCount** No content is currently available. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dkwnloadModeSrc** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **dowflinkBps** No content is currently available. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **doWnloadMode** No content is currently available. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **downloadMofeSrc** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConjectionCount** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **internetConnectionCountdownlinkBps** No content is currently available. +- **isEjcrypted** No content is currently available. +- **isEncryptdd** No content is currently available. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefi.edCallerName** No content is currently available. +- **predefinedCallerName** The name of the API Caller. +- **predefinedCalleRName** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **romteToCacheServer** No content is currently available. +- **roupeToCacheServer** No content is currently available. +- **routeTnCacheServer** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **uplinkUsegeBps** No content is currently available. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **backgground** No content is currently available. +- **backgro}nd** No content is currently available. +- **backgrou|d** No content is currently available. +- **background** Is the download a background download? +- **c`nUrl** No content is currently available. +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorBode** No content is currently available. +- **errorCode** The error code that was returned. +- **expebimentId** No content is currently available. +- **expebimentIderrorCode** No content is currently available. +- **experiientId** No content is currently available. +- **experimenpId** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVp|** No content is currently available. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCod%** No content is currently available. +- **reasonCode** The reason for pausing the download. +- **recsonCodesessiolID** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. +- **updateMD** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **b6nUrl** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bacoground** No content is currently available. +- **bileSizeCaller** No content is currently available. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **costFlaos** No content is currently available. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorC/de** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **doErrorCoee** No content is currently available. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimejtId** No content is currently available. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **faleID** No content is currently available. +- **fiheID** No content is currently available. +- **fileID** The ID of the file being downloaded. +- **filePat(** No content is currently available. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groqpID** No content is currently available. +- **groupID** ID for the group. +- **isEncrypted** Indicates whether the download is encrypted. +- **isFpn** No content is currently available. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **rimentId** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** Cache server setting, source, and value. +- **sessionID** The ID for the file download session. +- **sessmonID** No content is currently available. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **updateYD** No content is currently available. +- **usedMemoryStream** Indicates whether the download used memory streaming. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **eErrorCode** No content is currently available. +- **eErrorCunt** No content is currently available. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **htppStatusCode** No content is currently available. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **e:4|SScenario** No content is currently available. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **interactiveelatedCVerrorCode** No content is currently available. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenariotate** No content is currently available. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **defeec-9-0S** No content is currently available. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **Ignorec-9-0SsFoec-start** No content is currently available. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateMd** No content is currently available. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateAd** No content is currently available. +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From b958493992a0f8e3b9518844f867cc7740444f84 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 12 Mar 2019 16:37:06 -0700 Subject: [PATCH 054/737] new build 3/12/2019 4:37 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 8 +- ...ndows-diagnostic-events-and-fields-1709.md | 10 +- ...ndows-diagnostic-events-and-fields-1803.md | 8 +- ...ndows-diagnostic-events-and-fields-1809.md | 15449 ++++++++-------- 4 files changed, 7926 insertions(+), 7549 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 30e23dda88..2e2ac4486f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/05/2019 +ms.date: 03/12/2019 --- @@ -4181,7 +4181,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5072,12 +5072,12 @@ This event lists the reboot reason when an app is going to reboot. The following fields are available: -- **BootId** The boot ID. +- **BootId** The system boot ID. - **BoottimeSinceLastShutdown** The boot time since the last shutdown. - **RebootReason** Reason for the reboot. -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.Partner.ReportApplication diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 58818d2e66..d6a2e128d8 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/05/2019 +ms.date: 03/12/2019 --- @@ -68,7 +68,7 @@ The following fields are available: - **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. - **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. - **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryLanguagePack** The count of InventoryLanguagePack objects present on this machine. - **InventoryMediaCenter** The count of the number of this particular object type present on this device. - **InventorySystemBios** The count of the number of this particular object type present on this device. - **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. @@ -4128,7 +4128,7 @@ The following fields are available: - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Unique revision number of Update - **ServerId** Identifier for the service to which the software distribution client is connecting, such as Windows Update and Microsoft Store. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **UpdateId** Unique Update ID @@ -4192,7 +4192,7 @@ The following fields are available: - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5298,7 +5298,7 @@ The following fields are available: - **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.Partner.ReportApplication diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 2108b3c666..e88b4da389 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/05/2019 +ms.date: 03/12/2019 --- @@ -4934,7 +4934,7 @@ The following fields are available: - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) - **SystemBIOSMajorRelease** Major release version of the system bios - **SystemBIOSMinorRelease** Minor release version of the system bios - **UpdateId** Identifier associated with the specific piece of content @@ -4997,7 +4997,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). @@ -5988,7 +5988,7 @@ The following fields are available: - **PertProb** Constant used in algorithm for randomization. -## Microsoft Store events +## Windows Store events ### Microsoft.Windows.Store.StoreActivating diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index f8a042ef3d..fd7cd31194 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7536 +1,7913 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -audience: ITPro -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -ms.date: 02/15/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **action** The change that was invoked on a device inventory object. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiSeqId** The event sequence ID. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplayAdapterLuid** The display adapter LUID. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **GPUDeviceID** The GPU device ID. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPURevisionID** The GPU revision ID. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **version** The event version. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **AppName** The name of the app that has crashed. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModName** Exception module name (e.g. bar.dll). -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BusReportedDescription** The description of the device reported by the bux. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Description** The description of the device. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **HWID** A list of hardware IDs for the device. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **ProblemCode** The error code currently returned by the device, if applicable. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKID** The list of hardware IDs for the stack. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilters** The identifiers of the Upper filters installed for the device. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **ImageSize** The size of the driver file. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **hr** The HResult of the operation. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **WUDeviceID** The unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** The endpoint URL where the device obtains update metadata. This is used to distinguish between test, staging, and production environments. -- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. -- **ExtendedStatusCode** The secondary status code of the event. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast -- **StatusCode** The status code of the event. -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineResult** Error code from the engine operation. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Microsoft Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **CategoryId** The Item Category ID. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The product family name of the product being installed. -- **ProductId** The identity of the package or packages being installed. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUpdate** Is this an update? -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNumber** The number of attempts by the user to download. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefinedCallerName** The name of the API Caller. -- **restrictedUpload** Is the upload restricted? -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller object. -- **reasonCode** The reason for pausing the download. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Indicates whether the download is happening in the background. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **fileID** The ID of the file being downloaded. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groupID** ID for the group. -- **isEncrypted** Indicates whether the download is encrypted. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCallerName** Name of the API caller. -- **routeToCacheServer** Cache server setting, source, and value. -- **sessionID** The ID for the file download session. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** Indicates whether the download used memory streaming. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/12/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **inventoryId** Device ID used for Compatibility testing +- **objectIîstanceId** No content is currently available. +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCol|ectCoreTelemetry** No content is currently available. +- **CanCollactCoreTelemetry** No content is currently available. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformDiagnostigEscalations** No content is currently available. +- **CanPerformDkagnosticEscalations** No content is currently available. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScanarios** No content is currently available. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **AgentConnctionErrorsCount** No content is currently available. +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgenticenectionErrorsCount** No content is currently available. +- **CeesusExitCode** No content is currently available. +- **CeesusStartTime** No content is currently available. +- **CeesusTaskEnabled** No content is currently available. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataDbLroppedCount** No content is currently available. +- **CriticalDataDhrottleDroppedCount** No content is currently available. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CriticamOverflowEntersCounter** No content is currently available. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DbDroppedOailureCount** No content is currently available. +- **DbDroppedOullCount** No content is currently available. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DhrottledDroppedCount** No content is currently available. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **Eve~tStoreResetCounter** No content is currently available. +- **EventSC06eLifetimeResetCounter** No content is currently available. +- **EventSC06eResetCounter** No content is currently available. +- **EventSC06eResetSizeSum** No content is currently available. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **icesumerDroppedCount** No content is currently available. +- **icmpressedBytesUploaded** No content is currently available. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastAgenticenectionError** No content is currently available. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **LastreReseizeOffender** No content is currently available. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxActiveAgenticenectionCount** No content is currently available. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **Olags** No content is currently available. +- **OullTriggerBufferDroppedCount** No content is currently available. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xS** No content is currently available. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xS** No content is currently available. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWihDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. +- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. +- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. +- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. +- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. +- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. +- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. +- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. +- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. +- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. +- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). +- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. +- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. +- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterDypeValue** No content is currently available. +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BvightnessVersionViaDDI** No content is currently available. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DisplayAdapterLuid** The display adapter LUID. +- **Driver48,k** No content is currently available. +- **DriverDate** The date of the display driver. +- **DriverRa~k** No content is currently available. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9]MDFilePath** No content is currently available. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **GPUDeviceID** The GPU device ID. +- **GPUPree}ptionLevel** No content is currently available. +- **GPUPreemptionLdvel** No content is currently available. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPUVendoeID** No content is currently available. +- **GPUVendorID** The GPU vendor ID. +- **InterbaceId** No content is currently available. +- **InterfaceId** The GPU interface ID. +- **IqMPOSupported** No content is currently available. +- **IrRemovable** No content is currently available. +- **IsDisp|ayDevice** No content is currently available. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridIntdgrated** No content is currently available. +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOCupported** No content is currently available. +- **IsMPOSuppor|ed** No content is currently available. +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **IsSoftwareDevicg** No content is currently available. +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSyste}ID** No content is currently available. +- **SubSystemID** The subsystem ID. +- **SubVendoeID** No content is currently available. +- **SubVendorID** The GPU sub vendor ID. +- **TelematryEnabled** No content is currently available. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **version** The event version. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **@ackageRelativeAppId** No content is currently available. +- **AppName** The name of the app that has crashed. +- **AppSeqsionGuid** No content is currently available. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **AptName** No content is currently available. +- **DargetAppId** No content is currently available. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModNamevaultsv** No content is currently available. +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **PackageFullName** Store application identity. +- **PackageRelaatieAppId** No content is currently available. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Dedevi.DedeviInventoryChange](#msdedevidedeviinventorychange). + +The following fields are available: + +- **basedata** No content is currently available. See [basedata](#basedata). +- **BusReportedDescription** The description of the device reported by the bux. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **COMPID.Count** No content is currently available. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Description** The description of the device. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **HWID** A list of hardware IDs for the device. +- **HWID.Count** No content is currently available. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **Manufacturer** The manufacturer of the device. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Model** Identifies the model of the device. +- **ParentId** The Device Instance ID of the parent of the device. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **Provider** Identifies the device provider. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **STACKID.Count** No content is currently available. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **ImageSize** The size of the driver file. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersio~** No content is currently available. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. +- **f** No content is currently available. See [f](#f). + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **hr** The HResult of the operation. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **-149ngContextMessage** No content is currently available. +- **3645entContextName** No content is currently available. +- **379rentContextName** No content is currently available. +- **532rentContextName** No content is currently available. +- **677rentContextName** No content is currently available. +- **8108entContextName** No content is currently available. +- **8251entContextName** No content is currently available. +- **902rentContextName** No content is currently available. +- **9567ngContextMessage** No content is currently available. +- **9717ngContextMessage** No content is currently available. +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextMessaon** No content is currently available. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **functige** No content is currently available. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **ori1-0467ngContextMessage** No content is currently available. +- **ori1-1210ngContextMessage** No content is currently available. +- **ori1143-7ngContextMessage** No content is currently available. +- **ori1-1945ngContextMessage** No content is currently available. +- **ori13s090ngContextMessage** No content is currently available. +- **ori1-4671entContextName** No content is currently available. +- **ori1-5108ngContextMessage** No content is currently available. +- **ori1-5686ngContextMessage** No content is currently available. +- **ori1n:667ngContextMessage** No content is currently available. +- **ori1n8488ngContextMessage** No content is currently available. +- **ori1-s4o5ngContextMessage** No content is currently available. +- **ori808467ngContextMessage** No content is currently available. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **Falue** No content is currently available. +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedetadataICabUrl** No content is currently available. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedetadataISignatures** No content is currently available. +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumetadataISignatures** No content is currently available. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumbe2** No content is currently available. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHalhFailures** No content is currently available. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXBoockHashFailures** No content is currently available. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **AppXScopr** No content is currently available. +- **B}ndleId** No content is currently available. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCoqnt** No content is currently available. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **BytesDownnoaded** No content is currently available. +- **C`llerApplicationName** No content is currently available. +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationname** No content is currently available. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CalLerApplicationName** No content is currently available. +- **CallerApplictionaName** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCotntryCode** No content is currently available. +- **CDNCoun.ryCdel** No content is currently available. +- **CDNCoundryCode** No content is currently available. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNd** No content is currently available. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CtatusCode** No content is currently available. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownhoadProps** No content is currently available. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **DownloedPriority** No content is currently available. +- **DventInstanceID** No content is currently available. +- **e:4|SInstanceID** No content is currently available. +- **e:4|SScenario** No content is currently available. +- **E:4|State** No content is currently available. +- **EöentInstanceID** No content is currently available. +- **Eve.tScenario** No content is currently available. +- **EventInst.9ceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventInstAnceID** No content is currently available. +- **EventPype** No content is currently available. +- **EventScanario** No content is currently available. +- **eventScenario** No content is currently available. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **EventTypr** No content is currently available. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **Fli.c9BuildNumber** No content is currently available. +- **Fli.c9Id** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HospName** No content is currently available. +- **HostName** The hostname URL the content is downloading from. +- **Hst.Name** No content is currently available. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWQfBEnabled** No content is currently available. +- **IsWUfBDualCcanEnabled** No content is currently available. +- **IsWUfBdualScanEnabled** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnablad** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkCst.** No content is currently available. +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **NetworkRestrictiontartus** No content is currently available. +- **oadPriority** No content is currently available. +- **PackageFullName** The package name of the content. +- **PegulationResult** No content is currently available. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldDime** No content is currently available. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **Pst.DnldTime** No content is currently available. +- **PvocessName** No content is currently available. +- **QpdateId** No content is currently available. +- **QualityreUpdaPause** No content is currently available. +- **QualityUpdatePa}se** No content is currently available. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePatse** No content is currently available. +- **QualityUpdatePausa** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RdvisionNumber** No content is currently available. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **ReguiationResult** No content is currently available. +- **RegulationReason** The reason that the update is regulated +- **regulationResult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulatIonResult** No content is currently available. +- **ReiatedCV** No content is currently available. +- **RelatedCS** No content is currently available. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RelntedCV** No content is currently available. +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **tartusCdel** No content is currently available. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **tizeCalcTime** No content is currently available. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **Upda|eImportance** No content is currently available. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImporEvent** No content is currently available. +- **UpdateImpornstan** No content is currently available. +- **UpdateImport.9ce** No content is currently available. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **Use** No content is currently available. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDericeID** No content is currently available. +- **WUDeviceId** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCoun.** No content is currently available. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CallerApplictionaName** No content is currently available. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CSIErrorTypr** No content is currently available. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoverqIds** No content is currently available. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **DriverRecoverySds** No content is currently available. +- **DriverRecownloIds** No content is currently available. +- **EvåntInstanceID** No content is currently available. +- **Even|InstanceID** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventInstapceID** No content is currently available. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **EventTypr** No content is currently available. +- **ExtendedErrorCdel** No content is currently available. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **ExtendedtartusCdel** No content is currently available. +- **ExtendefStatusCode** No content is currently available. +- **FeatureUpdatePaser** No content is currently available. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdateUause** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HandlerTypr** No content is currently available. +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsKcfBDualScanEnabled** No content is currently available. +- **IsKcfBEnabled** No content is currently available. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsSuccessFailurePostReotId** No content is currently available. +- **IsSuccessFailurePst.Reboot** No content is currently available. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWufBEnabled** No content is currently available. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **IsWVfBDualScanEnabled** No content is currently available. +- **IsWVfBEnabled** No content is currently available. +- **lundleId** No content is currently available. +- **lundleRepeatFailCount** No content is currently available. +- **lundleRevisionNumber** No content is currently available. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCdel** No content is currently available. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageBullName** No content is currently available. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePaser** No content is currently available. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdateUause** No content is currently available. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCoun.** No content is currently available. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **SericeCGuid** No content is currently available. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersaon** No content is currently available. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetingVession** No content is currently available. +- **tartusCdel** No content is currently available. +- **TransactionCdel** No content is currently available. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UpdateImportapce** No content is currently available. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDdviceID** No content is currently available. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **WUDevi'eID** No content is currently available. +- **WUDviceCID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **RelntedCV** No content is currently available. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **umberOfApplicableUpdates** No content is currently available. +- **WUDeviceID** The unique device ID controlled by the software distribution client. +- **xHDeviceID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **CallerLoglicationName** No content is currently available. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. +- **ExtendedStatusCode** The secondary status code of the event. +- **ExtendefStatusCode** No content is currently available. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RcwMode** No content is currently available. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **SedviceGuid** No content is currently available. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **ServiceGuidEndpointUrl** No content is currently available. +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast +- **StatusCode** The status code of the event. +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **essionData** No content is currently available. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **Friled** No content is currently available. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanãeId** No content is currently available. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **value** No content is currently available. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **o-Ste** No content is currently available. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineResult** Error code from the engine operation. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckPar%meter2** No content is currently available. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AggregatedPackageFullNcmes** No content is currently available. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **Bundlele** No content is currently available. +- **CategoryId** The Item Category ID. +- **Categoryle** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **ClientApple** No content is currently available. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **ParentBundlele** No content is currently available. +- **PFN** The product family name of the product being installed. +- **Producele** No content is currently available. +- **ProductId** The identity of the package or packages being installed. +- **S{stemAttemptNumber** No content is currently available. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNaies** No content is currently available. +- **AggregatedpackageFullNames** No content is currently available. +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUp`ate** No content is currently available. +- **IsUpdate** Is this an update? +- **ParentBuneleId** No content is currently available. +- **PFN** Product Family Name of the product being installed. +- **Produc|Id** No content is currently available. +- **productId** No content is currently available. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullLames** No content is currently available. +- **AggregatedPackageFullNaðes** No content is currently available. +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **CategoryIf** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNum`er** No content is currently available. +- **UserAttemptNumber** The number of attempts by the user to download. +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **__TlgCÖ__** No content is currently available. +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsInteragtive** No content is currently available. +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **CatanogId** No content is currently available. +- **CatdlogId** No content is currently available. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **JResult** No content is currently available. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **Producele** No content is currently available. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **categoryId** No content is currently available. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **#dnErrorCounts** No content is currently available. +- **__TlgCVß_** No content is currently available. +- **|anConnectionCount** No content is currently available. +- **}plinkUsageBps** No content is currently available. +- **0redefinedCallerName** No content is currently available. +- **b6nConnectionCount** No content is currently available. +- **b6nErrorCodes** No content is currently available. +- **b6nErrorCounts** No content is currently available. +- **b6nIp** No content is currently available. +- **b6nUrl** No content is currently available. +- **background** Is the download a background download? +- **bytesFrkmIntPeers** No content is currently available. +- **bytesFromCacheSedver** No content is currently available. +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCdN** No content is currently available. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntÐeers** No content is currently available. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheSarverConnectionCount** No content is currently available. +- **cacheSedverConnectionCount** No content is currently available. +- **cacheServerConndctionCount** No content is currently available. +- **cacheServerConnectionCoujt** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnSonnectionCount** No content is currently available. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dkwnloadModeSrc** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **dowflinkBps** No content is currently available. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **doWnloadMode** No content is currently available. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **downloadMofeSrc** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConjectionCount** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **internetConnectionCountdownlinkBps** No content is currently available. +- **isEjcrypted** No content is currently available. +- **isEncryptdd** No content is currently available. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefi.edCallerName** No content is currently available. +- **predefinedCallerName** The name of the API Caller. +- **predefinedCalleRName** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **romteToCacheServer** No content is currently available. +- **roupeToCacheServer** No content is currently available. +- **routeTnCacheServer** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **uplinkUsegeBps** No content is currently available. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **backgground** No content is currently available. +- **backgro}nd** No content is currently available. +- **backgrou|d** No content is currently available. +- **background** Is the download a background download? +- **c`nUrl** No content is currently available. +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorBode** No content is currently available. +- **errorCode** The error code that was returned. +- **expebimentId** No content is currently available. +- **expebimentIderrorCode** No content is currently available. +- **experiientId** No content is currently available. +- **experimenpId** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVp|** No content is currently available. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCod%** No content is currently available. +- **reasonCode** The reason for pausing the download. +- **recsonCodesessiolID** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. +- **updateMD** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **b6nUrl** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bacoground** No content is currently available. +- **bileSizeCaller** No content is currently available. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **costFlaos** No content is currently available. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorC/de** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **doErrorCoee** No content is currently available. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimejtId** No content is currently available. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **faleID** No content is currently available. +- **fiheID** No content is currently available. +- **fileID** The ID of the file being downloaded. +- **filePat(** No content is currently available. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groqpID** No content is currently available. +- **groupID** ID for the group. +- **isEncrypted** Indicates whether the download is encrypted. +- **isFpn** No content is currently available. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **rimentId** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** Cache server setting, source, and value. +- **sessionID** The ID for the file download session. +- **sessmonID** No content is currently available. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **updateYD** No content is currently available. +- **usedMemoryStream** Indicates whether the download used memory streaming. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **eErrorCode** No content is currently available. +- **eErrorCunt** No content is currently available. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **htppStatusCode** No content is currently available. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **e:4|SScenario** No content is currently available. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **interactiveelatedCVerrorCode** No content is currently available. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenariotate** No content is currently available. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **defeec-9-0S** No content is currently available. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **Ignorec-9-0SsFoec-start** No content is currently available. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateMd** No content is currently available. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateAd** No content is currently available. +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From 172404220c94a5c293ac9af9aa253f8e7dea7d5e Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 07:20:22 -0700 Subject: [PATCH 055/737] add link to customize-oobe --- windows/configuration/wcd/wcd-oobe.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index b6ca14a3ca..ddb01d2e29 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -13,7 +13,7 @@ ms.date: 09/06/2017 # OOBE (Windows Configuration Designer reference) -Use to configure settings for the Out Of Box Experience (OOBE). +Use to configure settings for the [Out Of Box Experience (OOBE)](https://docs.microsoft.com/windows-hardware/customize/desktop/customize-oobe). ## Applies to From eff5194528d223fb57c241491751021f252970a1 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 07:23:55 -0700 Subject: [PATCH 056/737] oobe all editions --- windows/configuration/wcd/wcd-oobe.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index ddb01d2e29..5e91bed7c9 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -29,7 +29,7 @@ Use to configure settings for the [Out Of Box Experience (OOBE)](https://docs.mi ## EnableCortanaVoice -Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default on Windows 10 Pro, Education, and Enterprise. The voice-over is enabled by default on Windows 10 Home. Select **True** to enable voice-over during OOBE. +Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default on Windows 10 Pro, Education, and Enterprise. The voice-over is enabled by default on Windows 10 Home. Select **True** to enable voice-over during OOBE on all Windows 10 editions. ## HideOobe for desktop From 26e3f090475c4bb697652667b7652a88b64ae185 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 07:36:36 -0700 Subject: [PATCH 057/737] storage3d --- windows/configuration/TOC.md | 1 + windows/configuration/wcd/wcd-changes.md | 1 + .../wcd/wcd-storaged3inmodernstandby.md | 25 +++++++++++++++++++ windows/configuration/wcd/wcd.md | 1 + 4 files changed, 28 insertions(+) create mode 100644 windows/configuration/wcd/wcd-storaged3inmodernstandby.md diff --git a/windows/configuration/TOC.md b/windows/configuration/TOC.md index b0edfde74e..c0ad05a8bd 100644 --- a/windows/configuration/TOC.md +++ b/windows/configuration/TOC.md @@ -112,6 +112,7 @@ #### [Start](wcd/wcd-start.md) #### [StartupApp](wcd/wcd-startupapp.md) #### [StartupBackgroundTasks](wcd/wcd-startupbackgroundtasks.md) +#### [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md) #### [SurfaceHubManagement](wcd/wcd-surfacehubmanagement.md) #### [TabletMode](wcd/wcd-tabletmode.md) #### [TakeATest](wcd/wcd-takeatest.md) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 909614945c..962549f74e 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -20,6 +20,7 @@ ms.date: 10/02/2018 - [Time](wcd-time.md) - [Cellular > DataClassMappingTable](wcd-cellular.md#dataclassmappingtable) - [OOBE > EnableCortanaVoice](wcd-oobe.md#enablecortanavoice) +- [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd-storaged3inmodernstandby.md b/windows/configuration/wcd/wcd-storaged3inmodernstandby.md new file mode 100644 index 0000000000..a866ee0dab --- /dev/null +++ b/windows/configuration/wcd/wcd-storaged3inmodernstandby.md @@ -0,0 +1,25 @@ +--- +title: StorageD3InModernStandby (Windows 10) +description: This section describes the StorageD3InModernStandby settings that you can configure in provisioning packages for Windows 10 using Windows Configuration Designer. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: jdeckerMS +ms.localizationpriority: medium +ms.author: jdecker +ms.topic: article +ms.date: 09/06/2017 +--- + +# StorageD3InModernStandby (Windows Configuration Designer reference) + +Use **StorageD3InModernStandby** to enable or disable low power state (D3) during standby. When this setting is configured to **Enable Storage Device D3**, SATA and NVMe devices will be able to enter the D3 state when the system transits to modern standby state, if they are using a Microsoft inbox driver such as StorAHCI, StorNVMe. + +[Learn more about device power states.](https://docs.microsoft.com/windows-hardware/drivers/kernel/device-power-states) + +## Applies to + +| Setting | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | :---: | :---: | :---: | :---: | :---: | +| All settings | X | X | X | | X | + diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index b19b249d08..47631ec5f0 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -72,6 +72,7 @@ This section describes the settings that you can configure in [provisioning pack | [Start](wcd-start.md) | X | X | | | | | [StartupApp](wcd-startupapp.md) | | | | | X | | [StartupBackgroundTasks](wcd-startupbackgroundtasks.md) | | | | | X | +| [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md) |X | X | X | | X | | [SurfaceHubManagement](wcd-surfacehubmanagement.md) | | | X | | | | [TabletMode](wcd-tabletmode.md) |X | X | X | X | | | [TakeATest](wcd-takeatest.md) | X | | | | | From f1f5739a02260dbe008c5c5fd085793535a967f5 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 07:54:18 -0700 Subject: [PATCH 058/737] fix link --- windows/configuration/wcd/wcd-changes.md | 2 +- windows/configuration/wcd/wcd.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 962549f74e..4f84e272f5 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -20,7 +20,7 @@ ms.date: 10/02/2018 - [Time](wcd-time.md) - [Cellular > DataClassMappingTable](wcd-cellular.md#dataclassmappingtable) - [OOBE > EnableCortanaVoice](wcd-oobe.md#enablecortanavoice) -- [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md) +- [StorageD3InModernStandby](wcd-storaged3inmodernstandby.md) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index 47631ec5f0..2c764902cc 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -72,7 +72,7 @@ This section describes the settings that you can configure in [provisioning pack | [Start](wcd-start.md) | X | X | | | | | [StartupApp](wcd-startupapp.md) | | | | | X | | [StartupBackgroundTasks](wcd-startupbackgroundtasks.md) | | | | | X | -| [StorageD3InModernStandby](wcd/wcd-storaged3inmodernstandby.md) |X | X | X | | X | +| [StorageD3InModernStandby](wcd-storaged3inmodernstandby.md) |X | X | X | | X | | [SurfaceHubManagement](wcd-surfacehubmanagement.md) | | | X | | | | [TabletMode](wcd-tabletmode.md) |X | X | X | X | | | [TakeATest](wcd-takeatest.md) | X | | | | | From 7607f7772c32985857bb25f3c7fde47698a18b4f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 13 Mar 2019 08:32:49 -0700 Subject: [PATCH 059/737] new build 3/13/2019 8:32 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 68 +++++++++---------- 1 file changed, 34 insertions(+), 34 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index ac9b7be4f3..cd3421c1a4 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/12/2019 +ms.date: 03/13/2019 --- @@ -1744,7 +1744,7 @@ The following fields are available: - **AdvertisingId** Current state of the advertising ID setting. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. -- **AppointmentsSystem** No content is currently available. +- **AppointmentsSystem** Current state of the calendar setting. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. - **BroadFileSystemAccess** Current state of the broad file system access setting. @@ -1752,10 +1752,10 @@ The following fields are available: - **Chat** Current state of the chat setting. - **ChatSystem** Current state of the chat setting. - **Contacts** Current state of the contacts setting. -- **ContactsSystem** No content is currently available. +- **ContactsSystem** Current state of the Contacts setting. - **DocumentsLibrary** Current state of the documents library setting. - **Email** Current state of the email setting. -- **EmailSystem** No content is currently available. +- **EmailSystem** Current state of the email setting. - **FindMyDevice** Current state of the "find my device" setting. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. @@ -1767,7 +1767,7 @@ The following fields are available: - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. -- **PhoneCallHistorySystem** No content is currently available. +- **PhoneCallHistorySystem** Current state of the call history setting. - **PicturesLibrary** Current state of the pictures library setting. - **Radios** Current state of the radios setting. - **SensorsCustom** Current state of the custom sensor setting. @@ -1777,7 +1777,7 @@ The following fields are available: - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. -- **UserDataTasksSystem** No content is currently available. +- **UserDataTasksSystem** Current state of the tasks setting. - **UserNotificationListener** Current state of the notifications setting. - **VideosLibrary** Current state of the videos library setting. - **Webcam** Current state of the camera setting. @@ -1915,18 +1915,18 @@ The following fields are available: - **AdvertisingId** Current state of the advertising ID setting. - **AppDiagnostics** Current state of the app diagnostics setting. - **Appointments** Current state of the calendar setting. -- **AppointmentsSystem** No content is currently available. +- **AppointmentsSystem** Current state of the calendar setting. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. - **BroadFileSystemAccess** Current state of the broad file system access setting. - **CellularData** Current state of the cellular data capability setting. - **Chat** Current state of the chat setting. -- **ChatSystem** No content is currently available. +- **ChatSystem** Current state of the chat setting. - **Contacts** Current state of the contacts setting. -- **ContactsSystem** No content is currently available. +- **ContactsSystem** Current state of the Contacts setting. - **DocumentsLibrary** Current state of the documents library setting. - **Email** Current state of the email setting. -- **EmailSystem** No content is currently available. +- **EmailSystem** Current state of the email setting. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. - **InkTypeImprovement** Current state of the improve inking and typing setting. @@ -1938,7 +1938,7 @@ The following fields are available: - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. -- **PhoneCallHistorySystem** No content is currently available. +- **PhoneCallHistorySystem** Current state of the call history setting. - **PicturesLibrary** Current state of the pictures library setting. - **Radios** Current state of the radios setting. - **SensorsCustom** Current state of the custom sensor setting. @@ -1948,7 +1948,7 @@ The following fields are available: - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. -- **UserDataTasksSystem** No content is currently available. +- **UserDataTasksSystem** Current state of the tasks setting. - **UserNotificationListener** Current state of the notifications setting. - **VideosLibrary** Current state of the videos library setting. - **Webcam** Current state of the camera setting. @@ -3772,27 +3772,27 @@ The following fields are available: ### Microsoft.Windows.Kernel.DeviceConfig.DeviceConfig -No content is currently available. +This critical device configuration event provides information about drivers for a driver installation that took place within the kernel. The following fields are available: -- **ClassGuid** No content is currently available. -- **DeviceInstanceId** No content is currently available. -- **DriverDate** No content is currently available. -- **DriverFlightIds** No content is currently available. -- **DriverInfName** No content is currently available. -- **DriverProvider** No content is currently available. -- **DriverSubmissionId** No content is currently available. -- **DriverVersion** No content is currently available. -- **ExtensionDrivers** No content is currently available. -- **FirstHardwareId** No content is currently available. -- **InboxDriver** No content is currently available. -- **InstallDate** No content is currently available. -- **LastCompatibleId** No content is currently available. -- **Legacy** No content is currently available. -- **NeedReboot** No content is currently available. -- **SetupMode** No content is currently available. -- **StatusCode** No content is currently available. +- **ClassGuid** The unique ID for the device class. +- **DeviceInstanceId** The unique ID for the device on the system. +- **DriverDate** The date the driver was installed. +- **DriverFlightIds** The IDs for the driver flights. +- **DriverInfName** Driver INF file name. +- **DriverProvider** The driver manufacturer or provider. +- **DriverSubmissionId** The driver submission ID assigned by the hardware developer center. +- **DriverVersion** The driver version number. +- **ExtensionDrivers** The list of extension driver INF files, extension IDs, and associated flight IDs. +- **FirstHardwareId** The ID in the hardware ID list that provides the most specific device description. +- **InboxDriver** Indicates whether the driver package is included with Windows. +- **InstallDate** Date the driver was installed. +- **LastCompatibleId** The ID in the hardware ID list that provides the least specific device description. +- **Legacy** Indicates whether the driver is a legacy driver. +- **NeedReboot** Indicates whether the driver requires a reboot. +- **SetupMode** Indicates whether the device configuration occurred during the initial installation of the device. +- **StatusCode** The NTSTATUS of device configuration operation. ### Microsoft.Windows.Kernel.PnP.AggregateClearDevNodeProblem @@ -5353,7 +5353,7 @@ The following fields are available: - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **SystemBIOSMajorRelease** Major release version of the system bios - **SystemBIOSMinorRelease** Minor release version of the system bios - **UpdateId** Identifier associated with the specific piece of content @@ -5427,7 +5427,7 @@ The following fields are available: - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** An ID that represents which service the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** If the download is for an operating system upgrade, this datapoint indicates which phase of the upgrade is underway. - **ShippingMobileOperator** The mobile operator that a device shipped on. - **SizeCalcTime** Time taken (in seconds) to calculate the total download size of the payload. @@ -5606,7 +5606,7 @@ The following fields are available: - **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. - **RepeatFailCount** Indicates whether this specific piece of content has previously failed. - **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **StatusCode** Result code of the event (success, cancellation, failure code HResult). - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. @@ -5668,7 +5668,7 @@ The following fields are available: - **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. - **RepeatFailCount** Indicates whether this specific piece of content previously failed. - **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **StatusCode** Result code of the event (success, cancellation, failure code HResult). - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. From 36ebe477a6ddc7c10db110d8e58e5adc31f39ef6 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 13 Mar 2019 08:32:57 -0700 Subject: [PATCH 060/737] new build 3/13/2019 8:32 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 4 +- ...ndows-diagnostic-events-and-fields-1709.md | 6 +- ...ndows-diagnostic-events-and-fields-1803.md | 6 +- ...ndows-diagnostic-events-and-fields-1809.md | 64 +++++++------------ 4 files changed, 32 insertions(+), 48 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 2e2ac4486f..3fad353220 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/12/2019 +ms.date: 03/13/2019 --- @@ -4181,7 +4181,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index d6a2e128d8..4a60d0147d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/12/2019 +ms.date: 03/13/2019 --- @@ -4128,7 +4128,7 @@ The following fields are available: - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Unique revision number of Update - **ServerId** Identifier for the service to which the software distribution client is connecting, such as Windows Update and Microsoft Store. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **UpdateId** Unique Update ID @@ -4192,7 +4192,7 @@ The following fields are available: - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index e88b4da389..d472800547 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/12/2019 +ms.date: 03/13/2019 --- @@ -4934,7 +4934,7 @@ The following fields are available: - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **SystemBIOSMajorRelease** Major release version of the system bios - **SystemBIOSMinorRelease** Minor release version of the system bios - **UpdateId** Identifier associated with the specific piece of content @@ -4997,7 +4997,7 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailFlag** Indicates whether this specific piece of content had previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index fd7cd31194..85613743bd 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/12/2019 +ms.date: 03/13/2019 --- @@ -2676,6 +2676,7 @@ The following fields are available: - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. - **CanCol|ectCoreTelemetry** No content is currently available. - **CanCollactCoreTelemetry** No content is currently available. +- **CanCollec|AnyTelemetry** No content is currently available. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. @@ -2721,6 +2722,7 @@ The following fields are available: - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CensusTaskEnavled** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. @@ -3392,6 +3394,7 @@ The following fields are available: - **aiSeqId** The event sequence ID. - **bootId** The system boot ID. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BrightnessVersIonViaDDI** No content is currently available. - **BvightnessVersionViaDDI** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). @@ -3436,9 +3439,12 @@ The following fields are available: - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? - **IsSoftwareDevicg** No content is currently available. +- **KMD@ilePath** No content is currently available. - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumTidPlTarMets** No content is currently available. +- **NumVidPDSouPces** No content is currently available. - **NumVidPnSources** The number of supported display output sources. - **NumVidPnTargets** The number of supported display output targets. - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). @@ -3543,6 +3549,7 @@ The following fields are available: - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. - **AptName** No content is currently available. +- **AptSessionGuid** No content is currently available. - **DargetAppId** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. @@ -3553,16 +3560,23 @@ The following fields are available: - **ModNamevaultsv** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. +- **PaccageFullName** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelaatieAppId** No content is currently available. +- **PackageRelativaAppId** No content is currently available. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. +- **RepkrtId** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargepAppVer** No content is currently available. +- **TargetAppI`** No content is currently available. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported - **TargetAsId** The sequence number for the hanging process. +- **TargetAwId** No content is currently available. +- **TrocessArchitecture** No content is currently available. ## Feature update events @@ -3683,6 +3697,7 @@ The following fields are available: - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateArpLasuModified** No content is currently available. - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. - **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. - **InventoryVersion** The version of the inventory file generating the events. @@ -4505,7 +4520,6 @@ The following fields are available: - **BytesRead** The total number of bytes read from or read by the OS upon system startup. - **BytesWritten** The total number of bytes written to or written by the OS upon system startup. -- **f** No content is currently available. See [f](#f). ### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch @@ -4978,7 +4992,6 @@ The following fields are available: - **BIOSVendor** Vendor of the system BIOS - **BiosVersion** Version of the system BIOS - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumbe2** No content is currently available. - **BundleRevisionNumber** Identifies the revision number of the content bundle - **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client - **ClientVersion** Version number of the software distribution client @@ -4990,7 +5003,7 @@ The following fields are available: - **FlightId** The specific id of the flight the device is getting - **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) - **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc) +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **SystemBIOSMajorRelease** Major release version of the system bios - **SystemBIOSMinorRelease** Minor release version of the system bios - **UpdateId** Identifier associated with the specific piece of content @@ -5007,10 +5020,8 @@ The following fields are available: - **AppXBlockHalhFailures** No content is currently available. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXBoockHashFailures** No content is currently available. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. -- **AppXScopr** No content is currently available. - **B}ndleId** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. @@ -5021,25 +5032,19 @@ The following fields are available: - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle. - **BundleRepeatFailCoqnt** No content is currently available. -- **BundleRepeatFailCoun.** No content is currently available. - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **BytesDownnoaded** No content is currently available. - **C`llerApplicationName** No content is currently available. - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationname** No content is currently available. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CalLerApplicationName** No content is currently available. -- **CallerApplictionaName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCotntryCode** No content is currently available. -- **CDNCoun.ryCdel** No content is currently available. - **CDNCoundryCode** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNd** No content is currently available. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. @@ -5052,24 +5057,17 @@ The following fields are available: - **DownloadProps** Information about the download operation properties in the form of a bitmask. - **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. - **DownloedPriority** No content is currently available. -- **DventInstanceID** No content is currently available. - **e:4|SInstanceID** No content is currently available. - **e:4|SScenario** No content is currently available. - **E:4|State** No content is currently available. - **EöentInstanceID** No content is currently available. -- **Eve.tScenario** No content is currently available. -- **EventInst.9ceID** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventInstAnceID** No content is currently available. -- **EventPype** No content is currently available. - **EventScanario** No content is currently available. - **eventScenario** No content is currently available. - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. - **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **EventTypr** No content is currently available. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **ExtendedtartusCdel** No content is currently available. -- **FeatureUpdatePaser** No content is currently available. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **Fli.c9BuildNumber** No content is currently available. - **Fli.c9Id** No content is currently available. @@ -5082,7 +5080,6 @@ The following fields are available: - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. - **HospName** No content is currently available. - **HostName** The hostname URL the content is downloading from. -- **Hst.Name** No content is currently available. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6. - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update - **IsWQfBEnabled** No content is currently available. @@ -5093,26 +5090,18 @@ The following fields are available: - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkCst.** No content is currently available. - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **NetworkRestrictiontartus** No content is currently available. -- **oadPriority** No content is currently available. - **PackageFullName** The package name of the content. -- **PegulationResult** No content is currently available. - **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. - **PostDnldDime** No content is currently available. - **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. - **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **Pst.DnldTime** No content is currently available. - **PvocessName** No content is currently available. -- **QpdateId** No content is currently available. - **QualityreUpdaPause** No content is currently available. - **QualityUpdatePa}se** No content is currently available. -- **QualityUpdatePaser** No content is currently available. - **QualityUpdatePatse** No content is currently available. - **QualityUpdatePausa** No content is currently available. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RdvisionNumber** No content is currently available. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **ReguiationResult** No content is currently available. - **RegulationReason** The reason that the update is regulated @@ -5120,15 +5109,12 @@ The following fields are available: - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RegulatIonResult** No content is currently available. - **ReiatedCV** No content is currently available. -- **RelatedCS** No content is currently available. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RelntedCV** No content is currently available. -- **RepeatFailCoun.** No content is currently available. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **SericeCGuid** No content is currently available. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. @@ -5138,25 +5124,19 @@ The following fields are available: - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. - **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **tartusCdel** No content is currently available. - **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. - **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **tizeCalcTime** No content is currently available. - **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. - **Upda|eImportance** No content is currently available. - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImporEvent** No content is currently available. - **UpdateImpornstan** No content is currently available. -- **UpdateImport.9ce** No content is currently available. - **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. - **Use** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDericeID** No content is currently available. - **WUDeviceId** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **WUDviceCID** No content is currently available. ### SoftwareUpdateClientTelemetry.DownloadCheckpoint @@ -5360,7 +5340,7 @@ The following fields are available: - **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. - **RepeatFailCount** Indicates whether this specific piece of content has previously failed. - **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **StatusCode** Result code of the event (success, cancellation, failure code HResult). - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. @@ -5420,7 +5400,7 @@ The following fields are available: - **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. - **RepeatFailCount** Indicates whether this specific piece of content previously failed. - **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Windows Store, etc.). +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **StatusCode** Result code of the event (success, cancellation, failure code HResult). - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. @@ -5460,6 +5440,7 @@ The following fields are available: - **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. - **ExtendedStatusCode** The secondary status code of the event. - **ExtendefStatusCode** No content is currently available. +- **imeZoScenario** No content is currently available. - **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. - **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. - **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce @@ -6362,6 +6343,7 @@ The following fields are available: - **Produc|Id** No content is currently available. - **productId** No content is currently available. - **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNueber** No content is currently available. - **SystemAttemptNumber** The number of attempts by the system to acquire this product. - **UserAttemptNumber** The number of attempts by the user to acquire this product - **UserCttemptNumber** No content is currently available. @@ -6782,6 +6764,7 @@ The following fields are available: - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **downloadMofeSrc** No content is currently available. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. - **fileID** The ID of the file being downloaded. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. @@ -6795,6 +6778,7 @@ The following fields are available: - **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. +- **lanConnectionCo}nt** No content is currently available. - **lanConnectionCount** The total number of connections made to peers in the same LAN. - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. From 1d26a3157f7624ed3031a279b6bce5da2c47e91b Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 08:58:11 -0700 Subject: [PATCH 061/737] localpoliciessecurityoptions --- windows/configuration/wcd/wcd-policies.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 5da3446971..8afa0ad845 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -337,6 +337,14 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in 5. Open the project again in Windows Configuration Designer. 6. Export the package. Ensure you do not revisit the created policies under Kiosk Browser or else the null character will be removed. +## LocalPoliciesSecurityOptions + +| Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | --- | :---: | :---: | :---: | :---: | :---: | +| [InteractiveLogon_DoNotDisplayLastSignedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-interactivelogon-donotdisplaylastsignedin) | X | | | | | | +| [Shutdown_AllowSystemtobeShutDownWithoutHavingToLogOn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-shutdown-allowsystemtobeshutdownwithouthavingtologon) | X | | | | | | +| [UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-useraccountcontrol-behavioroftheelevationpromptforstandardusers) | X | | | | | | + ## Location | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | From 7888f4cae72a5805ab9e2a88f391165f26a51370 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 09:10:12 -0700 Subject: [PATCH 062/737] policies > power --- windows/configuration/wcd/wcd-policies.md | 25 +++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 8afa0ad845..b77939b03c 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -351,6 +351,31 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | --- | --- | :---: | :---: | :---: | :---: | :---: | | [EnableLocation](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#location-enablelocation) | Do not use. | | | | | | +## Power + +| Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | +| --- | --- | :---: | :---: | :---: | :---: | :---: | +| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingonbattery) | X | | | | | | +| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingpluggedin) | X | | | | | | +| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutonbattery) | X | | | | | | +| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutpluggedin) | X | | | | | | +| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#energysaverbatterythresholdonbattery) | X | | | | | | +| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#EnergySaverBatteryThresholdPluggedIn) | X | | | | | | +| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutonbattery) | X | | | | | | +| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutpluggedin) | X | | | | | | +| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactiononbattery) | X | | | | | | +| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactionpluggedin) | X | | | | | | +| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactiononbattery) | X | | | | | | +| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactionpluggedin) | X | | | | | | +| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactiononbattery) | X | | | | | | +| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactionpluggedin) | X | | | | | | +| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#StandbyTimeoutOnBattery) | X | | | | | | +| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#standbytimeoutpluggedin) | X | | | | | | +| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeponbattery) | X | | | | | | +| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeppluggedin) | X | | | | | | +| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutonbattery) | X | | | | | | +| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutpluggedin) | X | | | | | | + ## Privacy From 808f6c3224008e30620ed14633a5fedc6a5e8133 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 09:22:32 -0700 Subject: [PATCH 063/737] fix tables --- windows/configuration/wcd/wcd-policies.md | 47 +++++++++++------------ 1 file changed, 23 insertions(+), 24 deletions(-) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index b77939b03c..81758ffcf3 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -341,9 +341,9 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [InteractiveLogon_DoNotDisplayLastSignedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-interactivelogon-donotdisplaylastsignedin) | X | | | | | | -| [Shutdown_AllowSystemtobeShutDownWithoutHavingToLogOn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-shutdown-allowsystemtobeshutdownwithouthavingtologon) | X | | | | | | -| [UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-useraccountcontrol-behavioroftheelevationpromptforstandardusers) | X | | | | | | +| [InteractiveLogon_DoNotDisplayLastSignedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-interactivelogon-donotdisplaylastsignedin) | | X | | | | | +| [Shutdown_AllowSystemtobeShutDownWithoutHavingToLogOn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-shutdown-allowsystemtobeshutdownwithouthavingtologon) | | X | | | | | +| [UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-useraccountcontrol-behavioroftheelevationpromptforstandardusers) | | X | | | | | ## Location @@ -355,27 +355,26 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingonbattery) | X | | | | | | -| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingpluggedin) | X | | | | | | -| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutonbattery) | X | | | | | | -| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutpluggedin) | X | | | | | | -| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#energysaverbatterythresholdonbattery) | X | | | | | | -| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#EnergySaverBatteryThresholdPluggedIn) | X | | | | | | -| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutonbattery) | X | | | | | | -| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutpluggedin) | X | | | | | | -| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactiononbattery) | X | | | | | | -| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactionpluggedin) | X | | | | | | -| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactiononbattery) | X | | | | | | -| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactionpluggedin) | X | | | | | | -| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactiononbattery) | X | | | | | | -| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactionpluggedin) | X | | | | | | -| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#StandbyTimeoutOnBattery) | X | | | | | | -| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#standbytimeoutpluggedin) | X | | | | | | -| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeponbattery) | X | | | | | | -| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeppluggedin) | X | | | | | | -| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutonbattery) | X | | | | | | -| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutpluggedin) | X | | | | | | - +| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingonbattery) | | X | | | | | +| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingpluggedin) | | X | | | | | +| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutonbattery) | | X | | | | | +| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutpluggedin) | | X | | | | | +| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#energysaverbatterythresholdonbattery) | | X | | | | | +| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#EnergySaverBatteryThresholdPluggedIn) | | X | | | | | +| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutonbattery) | | X | | | | | +| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutpluggedin) | | X | | | | | +| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactiononbattery) | | X | | | | | +| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactionpluggedin) | | X | | | | | +| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactiononbattery) | | X | | | | | +| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactionpluggedin) | | X | | | | | +| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactiononbattery) | | X | | | | | +| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactionpluggedin) | | X | | | | | +| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#StandbyTimeoutOnBattery) | | X | | | | | +| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#standbytimeoutpluggedin) | | X | | | | | +| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeponbattery) | | X | | | | | +| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeppluggedin) | | X | | | | | +| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutonbattery) | | X | | | | | +| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutpluggedin) | | X | | | | | ## Privacy From 771968bd6d55abb2a13d63b8706131e0392d1fc1 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 09:33:50 -0700 Subject: [PATCH 064/737] fix power links --- windows/configuration/wcd/wcd-policies.md | 46 +++++++++++------------ 1 file changed, 23 insertions(+), 23 deletions(-) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 81758ffcf3..6841fc2423 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -341,9 +341,9 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [InteractiveLogon_DoNotDisplayLastSignedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-interactivelogon-donotdisplaylastsignedin) | | X | | | | | -| [Shutdown_AllowSystemtobeShutDownWithoutHavingToLogOn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-shutdown-allowsystemtobeshutdownwithouthavingtologon) | | X | | | | | -| [UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-useraccountcontrol-behavioroftheelevationpromptforstandardusers) | | X | | | | | +| [InteractiveLogon_DoNotDisplayLastSignedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-interactivelogon-donotdisplaylastsignedin) | Specify whether the Windows sign-in screen will show the username of the last person who signed in. | X | | | | | +| [Shutdown_AllowSystemtobeShutDownWithoutHavingToLogOn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-shutdown-allowsystemtobeshutdownwithouthavingtologon) | Specify whether a computer can be shut down without signing in. | X | | | | | +| [UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions#localpoliciessecurityoptions-useraccountcontrol-behavioroftheelevationpromptforstandardusers) | Configure how an elevation prompt should behave for standard users. | X | | | | | ## Location @@ -355,26 +355,26 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingonbattery) | | X | | | | | -| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#allowstandbystateswhensleepingpluggedin) | | X | | | | | -| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutonbattery) | | X | | | | | -| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#displayofftimeoutpluggedin) | | X | | | | | -| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#energysaverbatterythresholdonbattery) | | X | | | | | -| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#EnergySaverBatteryThresholdPluggedIn) | | X | | | | | -| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutonbattery) | | X | | | | | -| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#hibernatetimeoutpluggedin) | | X | | | | | -| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactiononbattery) | | X | | | | | -| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectlidcloseactionpluggedin) | | X | | | | | -| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactiononbattery) | | X | | | | | -| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectpowerbuttonactionpluggedin) | | X | | | | | -| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactiononbattery) | | X | | | | | -| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#selectsleepbuttonactionpluggedin) | | X | | | | | -| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#StandbyTimeoutOnBattery) | | X | | | | | -| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#standbytimeoutpluggedin) | | X | | | | | -| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeponbattery) | | X | | | | | -| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#turnoffhybridsleeppluggedin) | | X | | | | | -| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutonbattery) | | X | | | | | -| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#unattendedsleeptimeoutpluggedin) | | X | | | | | +| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingonbattery) | | X | | | | | +| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingpluggedin) | | X | | | | | +| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutonbattery) | | X | | | | | +| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutpluggedin) | | X | | | | | +| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#energysaverbatterythresholdonbattery) | | X | | | | | +| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#EnergySaverBatteryThresholdPluggedIn) | | X | | | | | +| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutonbattery) | | X | | | | | +| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutpluggedin) | | X | | | | | +| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactiononbattery) | | X | | | | | +| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactionpluggedin) | | X | | | | | +| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactiononbattery) | | X | | | | | +| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactionpluggedin) | | X | | | | | +| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactiononbattery) | | X | | | | | +| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactionpluggedin) | | X | | | | | +| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#StandbyTimeoutOnBattery) | | X | | | | | +| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#standbytimeoutpluggedin) | | X | | | | | +| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeponbattery) | | X | | | | | +| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeppluggedin) | | X | | | | | +| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutonbattery) | | X | | | | | +| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutpluggedin) | | X | | | | | ## Privacy From c0baa2a12ee832d58480b021ba967c719747a43f Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 10:19:01 -0700 Subject: [PATCH 065/737] sync --- windows/configuration/wcd/wcd-changes.md | 2 ++ windows/configuration/wcd/wcd-policies.md | 19 ++++++++++--------- 2 files changed, 12 insertions(+), 9 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 4f84e272f5..0100391209 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -20,6 +20,8 @@ ms.date: 10/02/2018 - [Time](wcd-time.md) - [Cellular > DataClassMappingTable](wcd-cellular.md#dataclassmappingtable) - [OOBE > EnableCortanaVoice](wcd-oobe.md#enablecortanavoice) +- [Policies > LocalPoliciesSecurityOptions](wcd-policies.md#localpoliciessecurityoptions) +- [Policies > Power](wcd-policies.md#power) - [StorageD3InModernStandby](wcd-storaged3inmodernstandby.md) ## Settings removed in Windows 10, version ? diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 6841fc2423..1ad4d0c2ac 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -355,15 +355,16 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingonbattery) | | X | | | | | -| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingpluggedin) | | X | | | | | -| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutonbattery) | | X | | | | | -| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutpluggedin) | | X | | | | | -| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#energysaverbatterythresholdonbattery) | | X | | | | | -| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#EnergySaverBatteryThresholdPluggedIn) | | X | | | | | -| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutonbattery) | | X | | | | | -| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutpluggedin) | | X | | | | | -| [SelectLidCloseActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactiononbattery) | | X | | | | | +| [AllowStandbyStatesWhenSleepingOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingonbattery) | Specify whether Windows can use standby states when putting the computer in a sleep state while on battery. | X | | | | | +| [AllowStandbyWhenSleepingPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#allowstandbystateswhensleepingpluggedin) | Specify whether Windows can use standby states when putting the computer in a sleep state while plugged in. | X | | | | | +| [DisplayOffTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutonbattery) | Specify the period of inactivity before Windows turns off the display while on battery. | X | | | | | +| [DisplayOffTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#displayofftimeoutpluggedin) | Specify the period of inactivity before Windows turns off the display while plugged in. | X | | | | | +| [EnergySaverBatteryThresholdOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#energysaverbatterythresholdonbattery) | Specify the battery charge level at which Energy Saver is turned on while on battery. | X | | | | | +| [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#EnergySaverBatteryThresholdPluggedIn) | Specify the battery charge level at which Energy Saver is turned on while plugged in. | X | | | | | +| [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutonbattery) | Specify the period of inactivity before Windows transitions the system to hibernate while on battery. | X | | | | | +| [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutpluggedin) | Specify the period of inactivity before Windows transitions the system to hibernate while plugged in. | X | | | | | +| [RequirePasswordWhenComputerWakesOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakesonbattery) | | X | | | | | +| [RequirePasswordWhenComputerWakesPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakespluggedin) | | X | | | | | | [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactionpluggedin) | | X | | | | | | [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactiononbattery) | | X | | | | | | [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactionpluggedin) | | X | | | | | From 2b70eca0f1d7364025771acfe27cb037e80f366c Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 12:32:01 -0700 Subject: [PATCH 066/737] finish power policies --- windows/configuration/wcd/wcd-policies.md | 27 ++++++++++++----------- 1 file changed, 14 insertions(+), 13 deletions(-) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 1ad4d0c2ac..814e7fbc1d 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -363,19 +363,20 @@ To configure multiple URLs for **Blocked URL Exceptions** or **Blocked URLs** in | [EnergySaverBatteryThresholdPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#EnergySaverBatteryThresholdPluggedIn) | Specify the battery charge level at which Energy Saver is turned on while plugged in. | X | | | | | | [HibernateTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutonbattery) | Specify the period of inactivity before Windows transitions the system to hibernate while on battery. | X | | | | | | [HibernateTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#hibernatetimeoutpluggedin) | Specify the period of inactivity before Windows transitions the system to hibernate while plugged in. | X | | | | | -| [RequirePasswordWhenComputerWakesOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakesonbattery) | | X | | | | | -| [RequirePasswordWhenComputerWakesPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakespluggedin) | | X | | | | | -| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactionpluggedin) | | X | | | | | -| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactiononbattery) | | X | | | | | -| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactionpluggedin) | | X | | | | | -| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactiononbattery) | | X | | | | | -| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactionpluggedin) | | X | | | | | -| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#StandbyTimeoutOnBattery) | | X | | | | | -| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#standbytimeoutpluggedin) | | X | | | | | -| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeponbattery) | | X | | | | | -| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeppluggedin) | | X | | | | | -| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutonbattery) | | X | | | | | -| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutpluggedin) | | X | | | | | +| [RequirePasswordWhenComputerWakesOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakesonbattery) | Specify whether the user is prompted for a password when the system resumes from sleep while on battery. | X | | | | | +| [RequirePasswordWhenComputerWakesPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#requirepasswordwhencomputerwakespluggedin) | Specify whether the user is prompted for a password when the system resumes from sleep while plugged in. | X | | | | | +| [SelectLidCloseActionBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactionpluggedin) | Select the action to be taken when a user closes the lid on a mobile device while on battery. | X | | | | | +| [SelectLidCloseActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectlidcloseactionpluggedin) | Select the action to be taken when a user closes the lid on a mobile device while on plugged in. | X | | | | | +| [SelectPowerButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactiononbattery) | Select the action to be taken when the user presses the power button while on battery. | X | | | | | +| [SelectPowerButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectpowerbuttonactionpluggedin) | Select the action to be taken when the user presses the power button while on plugged in. | X | | | | | +| [SelectSleepButtonActionOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactiononbattery) | Select the action to be taken when the user presses the sleep button while on battery. | X | | | | | +| [SelectSleepButtonActionPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#selectsleepbuttonactionpluggedin) | Select the action to be taken when the user presses the sleep button while plugged in. | X | | | | | +| [StandbyTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#StandbyTimeoutOnBattery) | Specify the period of inactivity before Windows transitions the system to sleep while on battery. | X | | | | | +| [StandbyTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#standbytimeoutpluggedin) | Specify the period of inactivity before Windows transitions the system to sleep while plugged in. | X | | | | | +| [TurnOffHybridSleepOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeponbattery) | Turn off hybrid sleep while on battery. | X | | | | | +| [TurnOffHybridSleepPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#turnoffhybridsleeppluggedin) | Turn off hybrid sleep while plugged in. | X | | | | | +| [UnattendedSleepTimeoutOnBattery](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutonbattery) | Specify the period of inactivity before Windows transitions the system to sleep automatically when a user is not present while on battery. | X | | | | | +| [UnattendedSleepTimeoutPluggedIn](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#unattendedsleeptimeoutpluggedin) | Specify the period of inactivity before Windows transitions the system to sleep automatically when a user is not present while plugged in. | X | | | | | ## Privacy From 93c25b80e4e7a7385419b04495f5217cad0554c1 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Wed, 13 Mar 2019 12:38:00 -0700 Subject: [PATCH 067/737] update timezone --- windows/configuration/wcd/wcd-time.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index 53ddcd5768..57086da3c3 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -23,7 +23,15 @@ Use **Time** to configure settings for time zone setup for Windows 10, version ( ## ProvisionSetTimeZone -Set to **True** to skip time zone assignment when the first user signs in. +Set to **True** to skip time zone assignment when the first user signs in, in which case the device will remain in its default time zone. For the proper configuration, you should also use **Policies > TimeLanguageSettings > ConfigureTimeZone** to set the default time zone. + +>[!TIP] +>Configuring a time zone in **Policies > TimeLanguageSettings > ConfigureTimeZone** accomplishes the same purpose as setting **ProvisionSetTimeZone** to **True**, so you don't need to configure both settings. + +Set to **False** for time zone assignment to occur when the first user signs in. The user will be prompted to select a time zone during first sign-in. + +>[!NOTE] +>Do not set **Time > ProvisionSetTimeZone** to **False** and also set a time zone in **Policies > TimeLanguageSettings > ConfigureTimeZone**. + -Set to **False** for time zone assignment to occur when the first user signs in. From f423a5a632b6148886a3250073ee5ba225d81455 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Fri, 15 Mar 2019 06:13:18 -0700 Subject: [PATCH 068/737] fix cortana voice setting --- windows/configuration/wcd/wcd-oobe.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index 5e91bed7c9..6bf1ca1d44 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -29,7 +29,7 @@ Use to configure settings for the [Out Of Box Experience (OOBE)](https://docs.mi ## EnableCortanaVoice -Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default on Windows 10 Pro, Education, and Enterprise. The voice-over is enabled by default on Windows 10 Home. Select **True** to enable voice-over during OOBE on all Windows 10 editions. +Use this setting to control whether Cortana voice-over is enabled during OOBE. The voice-over is disabled by default on Windows 10 Pro, Education, and Enterprise. The voice-over is enabled by default on Windows 10 Home. Select **True** to enable voice-over during OOBE, or **False** to disable voice-over during OOBE. ## HideOobe for desktop From 4c2d4f7ba9ebcfbb6ab09b4aa7e896c069a0caa3 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 15 Mar 2019 09:16:55 -0700 Subject: [PATCH 069/737] new build 3/15/2019 9:16 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 164 +++++++++++------- 1 file changed, 106 insertions(+), 58 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index cd3421c1a4..2faca0d1a1 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/13/2019 +ms.date: 03/15/2019 --- @@ -3797,30 +3797,30 @@ The following fields are available: ### Microsoft.Windows.Kernel.PnP.AggregateClearDevNodeProblem -No content is currently available. +This event is sent when a problem code is cleared from a device. The following fields are available: -- **Count** No content is currently available. -- **DeviceInstanceId** No content is currently available. -- **LastProblem** No content is currently available. -- **LastProblemStatus** No content is currently available. -- **ServiceName** No content is currently available. +- **Count** The total number of events. +- **DeviceInstanceId** The unique identifier of the device on the system. +- **LastProblem** The previous problem that was cleared. +- **LastProblemStatus** The previous NTSTATUS value that was cleared. +- **ServiceName** The name of the driver or service attached to the device. ### Microsoft.Windows.Kernel.PnP.AggregateSetDevNodeProblem -No content is currently available. +This event is sent when a new problem code is assigned to a device. The following fields are available: -- **Count** No content is currently available. -- **DeviceInstanceId** No content is currently available. -- **LastProblem** No content is currently available. -- **LastProblemStatus** No content is currently available. -- **Problem** No content is currently available. -- **ProblemStatus** No content is currently available. -- **ServiceName** No content is currently available. +- **Count** The total number of events. +- **DeviceInstanceId** The unique identifier of the device in the system. +- **LastProblem** The previous problem code that was set on the device. +- **LastProblemStatus** The previous NTSTATUS value that was set on the device. +- **Problem** The new problem code that was set on the device. +- **ProblemStatus** The new NTSTATUS value that was set on the device. +- **ServiceName** The driver or service name that is attached to the device. ## Miracast events @@ -3901,84 +3901,84 @@ The following fields are available: ### MicArrayGeometry -No content is currently available. +This event provides information about the layout of the individual microphone elements in the microphone array. The following fields are available: -- **MicCoords** No content is currently available. -- **usFrequencyBandHi** No content is currently available. -- **usFrequencyBandLo** No content is currently available. -- **usMicArrayType** No content is currently available. -- **usNumberOfMicrophones** No content is currently available. -- **usVersion** No content is currently available. -- **wHorizontalAngleBegin** No content is currently available. -- **wHorizontalAngleEnd** No content is currently available. -- **wVerticalAngleBegin** No content is currently available. -- **wVerticalAngleEnd** No content is currently available. +- **MicCoords** The location and orientation of the microphone element. +- **usFrequencyBandHi** The high end of the frequency range for the microphone. +- **usFrequencyBandLo** The low end of the frequency range for the microphone. +- **usMicArrayType** The type of the microphone array. +- **usNumberOfMicrophones** The number of microphones in the array. +- **usVersion** The version of the microphone array specification. +- **wHorizontalAngleBegin** The horizontal angle of the start of the working volume (reported as radians times 10,000). +- **wHorizontalAngleEnd** The horizontal angle of the end of the working volume (reported as radians times 10,000). +- **wVerticalAngleBegin** The vertical angle of the start of the working volume (reported as radians times 10,000). +- **wVerticalAngleEnd** The vertical angle of the end of the working volume (reported as radians times 10,000). ### MicCoords -No content is currently available. +This event provides information about the location and orientation of the microphone element. The following fields are available: -- **usType** No content is currently available. -- **wHorizontalAngle** No content is currently available. -- **wVerticalAngle** No content is currently available. -- **wXCoord** No content is currently available. -- **wYCoord** No content is currently available. -- **wZCoord** No content is currently available. +- **usType** The type of microphone. +- **wHorizontalAngle** The horizontal angle of the microphone (reported as radians times 10,000). +- **wVerticalAngle** The vertical angle of the microphone (reported as radians times 10,000). +- **wXCoord** The x-coordinate of the microphone. +- **wYCoord** The y-coordinate of the microphone. +- **wZCoord** The z-coordinate of the microphone. ### Microsoft.Windows.Audio.EndpointBuilder.DeviceInfo -No content is currently available. +This event logs the successful enumeration of an audio endpoint (such as a microphone or speaker) and provides information about the audio endpoint. The following fields are available: -- **BusEnumeratorName** No content is currently available. -- **ContainerId** No content is currently available. -- **DeviceInstanceId** No content is currently available. -- **EndpointDevnodeId** No content is currently available. +- **BusEnumeratorName** The name of the bus enumerator (for example, HDAUDIO or USB). +- **ContainerId** An identifier that uniquely groups the functional devices associated with a single-function or multifunction device. +- **DeviceInstanceId** The unique identifier for this instance of the device. +- **EndpointDevnodeId** The IMMDevice identifier of the associated devnode. - **endpointEffectClsid** No content is currently available. - **endpointEffectModule** No content is currently available. -- **EndpointFormFactor** No content is currently available. -- **endpointID** No content is currently available. -- **endpointInstanceId** No content is currently available. -- **Flow** No content is currently available. +- **EndpointFormFactor** The enumeration value for the form factor of the endpoint device (for example speaker, microphone, remote network device). +- **endpointID** The unique identifier for the audio endpoint. +- **endpointInstanceId** The unique identifier for the software audio endpoint. Used for joining to other audio event. +- **Flow** Indicates whether the endpoint is capture (1) or render (0). - **globalEffectClsid** No content is currently available. - **globalEffectModule** No content is currently available. -- **HWID** No content is currently available. -- **IsBluetooth** No content is currently available. +- **HWID** The hardware identifier for the endpoint. +- **IsBluetooth** Indicates whether the device is a Bluetooth device. - **isFarField** No content is currently available. -- **IsSideband** No content is currently available. -- **IsUSB** No content is currently available. -- **JackSubType** No content is currently available. +- **IsSideband** Indicates whether the device is a sideband device. +- **IsUSB** Indicates whether the device is a USB device. +- **JackSubType** A unique ID representing the KS node type of the endpoint. - **localEffectClsid** No content is currently available. - **localEffectModule** No content is currently available. -- **MicArrayGeometry** No content is currently available. See [MicArrayGeometry](#micarraygeometry). +- **MicArrayGeometry** Describes the microphone array, including the microphone position, coordinates, type, and frequency range. See [MicArrayGeometry](#micarraygeometry). - **modeEffectClsid** No content is currently available. - **modeEffectModule** No content is currently available. -- **persistentId** No content is currently available. +- **persistentId** A unique ID for this endpoint which is retained across migrations. - **streamEffectClsid** No content is currently available. - **streamEffectModule** No content is currently available. ### Microsoft.Windows.DriverInstall.DeviceInstall -No content is currently available. +This critical event sends device instance properties for the driver installation that took place. The following fields are available: -- **ClassGuid** No content is currently available. -- **ClassLowerFilters** No content is currently available. -- **ClassUpperFilters** No content is currently available. -- **CoInstallers** No content is currently available. -- **ConfigFlags** No content is currently available. -- **DeviceConfigured** No content is currently available. -- **DeviceInstanceId** No content is currently available. -- **DeviceStack** No content is currently available. +- **ClassGuid** The unique ID for the device class. +- **ClassLowerFilters** The list of lower filter class drivers. +- **ClassUpperFilters** The list of upper filter class drivers. +- **CoInstallers** The list of coinstallers. +- **ConfigFlags** The device configuration flags. +- **DeviceConfigured** Indicates whether this device was configured through the kernel configuration. +- **DeviceInstanceId** The unique identifier of the device in the system. +- **DeviceStack** The device stack of the driver being installed. - **DriverDate** No content is currently available. - **DriverDescription** No content is currently available. - **DriverInfName** No content is currently available. @@ -5045,6 +5045,34 @@ The following fields are available: - **sessionID** The ID of this push-button reset session. +### Microsoft.Windows.UEFI.ESRT + +No content is currently available. + +The following fields are available: + +- **DriverFirmwareFilename** No content is currently available. +- **DriverFirmwarePolicy** No content is currently available. +- **DriverFirmwareStatus** No content is currently available. +- **DriverFirmwareVersion** No content is currently available. +- **FirmareLastAttemptVersion** No content is currently available. +- **FirmwareId** No content is currently available. +- **FirmwareLastAttemptStatus** No content is currently available. +- **FirmwareLastAttemptVersion** No content is currently available. +- **FirmwareType** No content is currently available. +- **FirmwareVersion** No content is currently available. +- **InitiateUpdate** No content is currently available. +- **LastAttemptDate** No content is currently available. +- **LastAttemptStatus** No content is currently available. +- **LastAttemptVersion** No content is currently available. +- **LowestSupportedFirmwareVersion** No content is currently available. +- **MaxRetryCount** No content is currently available. +- **PartA_PrivTags** No content is currently available. +- **RetryCount** No content is currently available. +- **Status** No content is currently available. +- **UpdateAttempted** No content is currently available. + + ### Microsoft.Xbox.XamTelemetry.AppActivationError This event indicates whether the system detected an activation error in the app. @@ -7165,6 +7193,26 @@ The following fields are available: - **wuDeviceid** The unique device ID used by Windows Update. +### Microsoft.Windows.Update.Orchestrator.DetectionActivity + +No content is currently available. + +The following fields are available: + +- **applicableUpdateIdList** No content is currently available. +- **applicableUpdateList** No content is currently available. +- **durationInSeconds** No content is currently available. +- **expeditedMode** No content is currently available. +- **networkCostPolicy** No content is currently available. +- **scanTriggerSource** No content is currently available. +- **scenario** No content is currently available. +- **scenarioReason** No content is currently available. +- **seekerUpdateIdList** No content is currently available. +- **seekerUpdateList** No content is currently available. +- **services** No content is currently available. +- **wilActivity** No content is currently available. See [wilActivity](#wilactivity). + + ### Microsoft.Windows.Update.Orchestrator.DisplayNeeded This event indicates the reboot was postponed due to needing a display. From 5f6aea33f705ed73bf7902534a6b512d09efa791 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 15 Mar 2019 09:17:00 -0700 Subject: [PATCH 070/737] new build 3/15/2019 9:16 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 19 +- ...ndows-diagnostic-events-and-fields-1709.md | 19 +- ...ndows-diagnostic-events-and-fields-1803.md | 19 +- ...ndows-diagnostic-events-and-fields-1809.md | 175 ++++++------------ 4 files changed, 115 insertions(+), 117 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 3fad353220..4aebdedd33 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/13/2019 +ms.date: 03/15/2019 --- @@ -2954,6 +2954,23 @@ The following fields are available: - **winInetError** The HResult of the operation. +## Other events + +### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted + +No content is currently available. + +The following fields are available: + +- **cleanupTask** No content is currently available. +- **cleanupTaskResult** No content is currently available. +- **deviceEvaluated** No content is currently available. +- **deviceImpacted** No content is currently available. +- **modalAction** No content is currently available. +- **modalResult** No content is currently available. +- **resetSettingsResult** No content is currently available. + + ## Remediation events ### Microsoft.Windows.Remediation.Applicable diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 4a60d0147d..0fa19351b5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/13/2019 +ms.date: 03/15/2019 --- @@ -3107,6 +3107,23 @@ The following fields are available: - **winInetError** The HResult of the operation. +## Other events + +### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted + +No content is currently available. + +The following fields are available: + +- **cleanupTask** No content is currently available. +- **cleanupTaskResult** No content is currently available. +- **deviceEvaluated** No content is currently available. +- **deviceImpacted** No content is currently available. +- **modalAction** No content is currently available. +- **modalResult** No content is currently available. +- **resetSettingsResult** No content is currently available. + + ## Remediation events ### Microsoft.Windows.Remediation.Applicable diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index d472800547..cc061437ac 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/13/2019 +ms.date: 03/15/2019 --- @@ -4061,6 +4061,23 @@ The following fields are available: - **winInetError** The HResult of the operation. +## Other events + +### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted + +No content is currently available. + +The following fields are available: + +- **cleanupTask** No content is currently available. +- **cleanupTaskResult** No content is currently available. +- **deviceEvaluated** No content is currently available. +- **deviceImpacted** No content is currently available. +- **modalAction** No content is currently available. +- **modalResult** No content is currently available. +- **resetSettingsResult** No content is currently available. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 85613743bd..db961c12d8 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/13/2019 +ms.date: 03/15/2019 --- @@ -2208,6 +2208,7 @@ The following fields are available: - **UserNotificationListener** Current state of the notifications setting. - **VideosLibrary** Current state of the videos library setting. - **Webcam** Current state of the camera setting. +- **WiFaDirect** No content is currently available. - **WiFiDirect** Current state of the Wi-Fi direct setting. @@ -2446,8 +2447,8 @@ Describes the installation state for all hardware and software components availa The following fields are available: - **action** The change that was invoked on a device inventory object. +- **cction** No content is currently available. - **inventoryId** Device ID used for Compatibility testing -- **objectIîstanceId** No content is currently available. - **objectInstanceId** Object identity which is unique within the device scope. - **objectType** Indicates the object type that the event applies to. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. @@ -2674,19 +2675,13 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCol|ectCoreTelemetry** No content is currently available. -- **CanCollactCoreTelemetry** No content is currently available. -- **CanCollec|AnyTelemetry** No content is currently available. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformDiagnostigEscalations** No content is currently available. -- **CanPerformDkagnosticEscalations** No content is currently available. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScanarios** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. - **PreviousPermissions** Bitmask of previous telemetry state. - **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. @@ -2713,39 +2708,23 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: -- **AgentConnctionErrorsCount** No content is currently available. - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AgenticenectionErrorsCount** No content is currently available. -- **CeesusExitCode** No content is currently available. -- **CeesusStartTime** No content is currently available. -- **CeesusTaskEnabled** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CensusTaskEnavled** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataDbLroppedCount** No content is currently available. -- **CriticalDataDhrottleDroppedCount** No content is currently available. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **CriticamOverflowEntersCounter** No content is currently available. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. - **DbDroppedCount** Number of events dropped due to DB fullness. - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DbDroppedOailureCount** No content is currently available. -- **DbDroppedOullCount** No content is currently available. - **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DhrottledDroppedCount** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **Eve~tStoreResetCounter** No content is currently available. -- **EventSC06eLifetimeResetCounter** No content is currently available. -- **EventSC06eResetCounter** No content is currently available. -- **EventSC06eResetSizeSum** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. - **EventStoreResetCounter** Number of times event DB was reset. @@ -2756,19 +2735,12 @@ The following fields are available: - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **icesumerDroppedCount** No content is currently available. -- **icmpressedBytesUploaded** No content is currently available. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastAgenticenectionError** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **LastreReseizeOffender** No content is currently available. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxActiveAgenticenectionCount** No content is currently available. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **Olags** No content is currently available. -- **OullTriggerBufferDroppedCount** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. @@ -2780,12 +2752,9 @@ The following fields are available: - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xS** No content is currently available. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xS** No content is currently available. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWihDroppedEvents** No content is currently available. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. @@ -3391,25 +3360,35 @@ The following fields are available: - **AdapterDypeValue** No content is currently available. - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiseqId** No content is currently available. - **aiSeqId** The event sequence ID. +- **AsPostAdapter** No content is currently available. - **bootId** The system boot ID. +- **BrightnessVersion'iaDDI** No content is currently available. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. - **BrightnessVersIonViaDDI** No content is currently available. - **BvightnessVersionViaDDI** No content is currently available. +- **Com2utePreemptionLevel** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DicplayAdapterLuid** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. - **Driver48,k** No content is currently available. - **DriverDate** The date of the display driver. +- **DriverFersion** No content is currently available. - **DriverRa~k** No content is currently available. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFile@ath** No content is currently available. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12EMDFilePath** No content is currently available. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. - **DX9]MDFilePath** No content is currently available. +- **DX9EMDFilePath** No content is currently available. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **G@UVendorID** No content is currently available. - **GPUDeviceID** The GPU device ID. - **GPUPree}ptionLevel** No content is currently available. - **GPUPreemptionLdvel** No content is currently available. @@ -3417,10 +3396,13 @@ The following fields are available: - **GPURevisionID** The GPU revision ID. - **GPUVendoeID** No content is currently available. - **GPUVendorID** The GPU vendor ID. +- **I¤MismatchLDA** No content is currently available. - **InterbaceId** No content is currently available. - **InterfaceId** The GPU interface ID. +- **IÓDisplayDevice** No content is currently available. - **IqMPOSupported** No content is currently available. - **IrRemovable** No content is currently available. +- **IsCoftwareDevice** No content is currently available. - **IsDisp|ayDevice** No content is currently available. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. @@ -3428,7 +3410,9 @@ The following fields are available: - **IsHybridIntdgrated** No content is currently available. - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMicmatchLDA** No content is currently available. - **IsMiracastSupported** Does the GPU support Miracast? +- **IsMism`tchLDA** No content is currently available. - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? - **IsMPOCupported** No content is currently available. - **IsMPOSuppor|ed** No content is currently available. @@ -3447,9 +3431,11 @@ The following fields are available: - **NumVidPDSouPces** No content is currently available. - **NumVidPnSources** The number of supported display output sources. - **NumVidPnTargets** The number of supported display output targets. +- **SharedCystemMemoryB** No content is currently available. - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). - **SubSyste}ID** No content is currently available. - **SubSystemID** The subsystem ID. +- **SubSystemKD** No content is currently available. - **SubVendoeID** No content is currently available. - **SubVendorID** The GPU sub vendor ID. - **TelematryEnabled** No content is currently available. @@ -3558,16 +3544,20 @@ The following fields are available: - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). - **ModNamevaultsv** No content is currently available. +- **ModNaoe** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. - **PaccageFullName** No content is currently available. - **PackageFullName** Store application identity. +- **PackageFuLlName** No content is currently available. - **PackageRelaatieAppId** No content is currently available. - **PackageRelativaAppId** No content is currently available. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateDime** No content is currently available. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. +- **PRocessId** No content is currently available. - **RepkrtId** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. - **TargepAppVer** No content is currently available. @@ -3659,6 +3649,7 @@ The following fields are available: - **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache - **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache - **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **InventoryMiscnfo** No content is currently available. - **Metadata** A count of metadata objects in cache. - **Orphan** A count of orphan file objects in cache. - **Programs** A count of program objects in cache. @@ -3696,6 +3687,7 @@ The following fields are available: - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModifi** No content is currently available. - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 - **InstallDateArpLasuModified** No content is currently available. - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. @@ -3705,14 +3697,17 @@ The following fields are available: - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. +- **Order** No content is currently available. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. - **PackageFullName** The package full name for a Store application. +- **PackagmFullName** No content is currently available. - **ProgramInstanceId** A hash of the file IDs in an app. - **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. - **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Value** No content is currently available. - **Version** The version number of the program. @@ -3902,7 +3897,7 @@ The following fields are available: This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). +This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). The following fields are available: @@ -3929,6 +3924,7 @@ The following fields are available: - **DeviceState** Identifies the current state of the parent (main) device. - **DriverId** The unique identifier for the installed driver. - **DriverName** The name of the driver image file. +- **DriverP!ckageStrongName** No content is currently available. - **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. - **DriverVerDate** The date associated with the driver installed on the device. - **DriverVerVersion** The version number of the driver installed on the device. @@ -3937,11 +3933,13 @@ The following fields are available: - **HWID** A list of hardware IDs for the device. - **HWID.Count** No content is currently available. - **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallCtate** No content is currently available. - **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx - **InventoryVersion** The version number of the inventory process generating the events. - **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. - **LowerFilters** The identifiers of the Lower filters installed for the device. - **Manufacturer** The manufacturer of the device. +- **Manufccturer** No content is currently available. - **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. - **Model** Identifies the model of the device. - **ParentId** The Device Instance ID of the parent of the device. @@ -4534,6 +4532,7 @@ The following fields are available: - **BootStatusPolicy** Identifies the applicable Boot Status Policy. - **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). - **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **Firmw!reResetReasonEmbeddedControllerAdditional** No content is currently available. - **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. - **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. - **FirmwareResetReasonPch** Reason for system reset provided by firmware. @@ -4898,6 +4897,7 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResul|s** No content is currently available. - **AllowCachedResults** Indicates if the scan allowed using cached results. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable - **BiosFamily** The family of the BIOS (Basic Input Output System). @@ -4949,6 +4949,7 @@ The following fields are available: - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan - **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan - **NumFailedetadataISignatures** No content is currently available. +- **NumFailedMetadatabignatures** No content is currently available. - **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. - **Online** Indicates if this was an online scan. - **PausedUpdates** A list of UpdateIds which that currently being paused. @@ -4974,6 +4975,7 @@ The following fields are available: - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. - **TotalNumetadataISignatures** No content is currently available. +- **TotalNumMetadatabignatures** No content is currently available. - **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. - **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5017,12 +5019,10 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHalhFailures** No content is currently available. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. -- **B}ndleId** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5031,46 +5031,29 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCoqnt** No content is currently available. - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **C`llerApplicationName** No content is currently available. - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationname** No content is currently available. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCotntryCode** No content is currently available. -- **CDNCoundryCode** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CtatusCode** No content is currently available. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** The model of the device. -- **DownhoadProps** No content is currently available. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. - **DownloadProps** Information about the download operation properties in the form of a bitmask. - **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **DownloedPriority** No content is currently available. -- **e:4|SInstanceID** No content is currently available. -- **e:4|SScenario** No content is currently available. -- **E:4|State** No content is currently available. -- **EöentInstanceID** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. -- **EventInstAnceID** No content is currently available. -- **EventScanario** No content is currently available. -- **eventScenario** No content is currently available. - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. - **EventType** Identifies the type of the event (Child, Bundle, or Driver). - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **Fli.c9BuildNumber** No content is currently available. -- **Fli.c9Id** No content is currently available. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. @@ -5078,39 +5061,23 @@ The following fields are available: - **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). - **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HospName** No content is currently available. - **HostName** The hostname URL the content is downloading from. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6. - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWQfBEnabled** No content is currently available. -- **IsWUfBDualCcanEnabled** No content is currently available. -- **IsWUfBdualScanEnabled** No content is currently available. - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnablad** No content is currently available. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." - **PackageFullName** The package name of the content. - **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldDime** No content is currently available. - **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. - **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **PvocessName** No content is currently available. -- **QualityreUpdaPause** No content is currently available. -- **QualityUpdatePa}se** No content is currently available. -- **QualityUpdatePatse** No content is currently available. -- **QualityUpdatePausa** No content is currently available. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **ReguiationResult** No content is currently available. - **RegulationReason** The reason that the update is regulated -- **regulationResult** No content is currently available. - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RegulatIonResult** No content is currently available. -- **ReiatedCV** No content is currently available. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RelntedCV** No content is currently available. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. @@ -5118,6 +5085,7 @@ The following fields are available: - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **SonnectTime** No content is currently available. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. @@ -5127,15 +5095,11 @@ The following fields are available: - **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. - **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. - **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **Upda|eImportance** No content is currently available. - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImpornstan** No content is currently available. - **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **Use** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceId** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5204,46 +5168,30 @@ The following fields are available: - **BIOSVendor** The vendor of the BIOS. - **BiosVersion** The version of the BIOS. - **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCoun.** No content is currently available. - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. - **BundleRevisionNumber** Identifies the revision number of the content bundle. - **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CallerApplictionaName** No content is currently available. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. - **CSIErrorType** The stage of CBS installation where it failed. -- **CSIErrorTypr** No content is currently available. - **CurrentMobileOperator** The mobile operator to which the device is currently connected. - **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** The device model. - **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoverqIds** No content is currently available. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **DriverRecoverySds** No content is currently available. -- **DriverRecownloIds** No content is currently available. -- **EvåntInstanceID** No content is currently available. -- **Even|InstanceID** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. -- **EventInstapceID** No content is currently available. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. -- **EventTypr** No content is currently available. -- **ExtendedErrorCdel** No content is currently available. - **ExtendedErrorCode** The extended error code. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **ExtendedtartusCdel** No content is currently available. -- **ExtendefStatusCode** No content is currently available. -- **FeatureUpdatePaser** No content is currently available. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdateUause** No content is currently available. - **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. - **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. - **FlightId** The specific ID of the Windows Insider build the device is getting. - **FlightRing** The ring that a device is on if participating in the Windows Insider Program. - **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HandlerTypr** No content is currently available. - **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. - **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. @@ -5251,36 +5199,20 @@ The following fields are available: - **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. - **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. - **IsFirmware** Indicates whether this update is a firmware update. -- **IsKcfBDualScanEnabled** No content is currently available. -- **IsKcfBEnabled** No content is currently available. - **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsSuccessFailurePostReotId** No content is currently available. -- **IsSuccessFailurePst.Reboot** No content is currently available. - **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWufBEnabled** No content is currently available. - **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **IsWVfBDualScanEnabled** No content is currently available. -- **IsWVfBEnabled** No content is currently available. -- **lundleId** No content is currently available. -- **lundleRepeatFailCount** No content is currently available. -- **lundleRevisionNumber** No content is currently available. - **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. - **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCdel** No content is currently available. - **MsiProductCode** The unique identifier of the MSI installer. -- **PackageBullName** No content is currently available. - **PackageFullName** The package name of the content being installed. - **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. - **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePaser** No content is currently available. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdateUause** No content is currently available. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCoun.** No content is currently available. - **RepeatFailCount** Indicates whether this specific piece of content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. - **RevisionNumber** The revision number of this specific piece of content. -- **SericeCGuid** No content is currently available. - **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). - **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. - **ShippingMobileOperator** The mobile operator that a device shipped on. @@ -5288,21 +5220,13 @@ The following fields are available: - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersaon** No content is currently available. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetingVession** No content is currently available. -- **tartusCdel** No content is currently available. -- **TransactionCdel** No content is currently available. - **TransactionCode** The ID that represents a given MSI installation. - **UpdateId** Unique update ID. - **UpdateID** An identifier associated with the specific piece of content. - **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UpdateImportapce** No content is currently available. - **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDdviceID** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **WUDevi'eID** No content is currently available. -- **WUDviceCID** No content is currently available. ### SoftwareUpdateClientTelemetry.Revert @@ -5437,6 +5361,7 @@ The following fields are available: - **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. - **CallerLoglicationName** No content is currently available. - **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventSbenario** No content is currently available. - **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. - **ExtendedStatusCode** The secondary status code of the event. - **ExtendefStatusCode** No content is currently available. @@ -6157,14 +6082,21 @@ Result of the WaaSMedic operation. The following fields are available: - **callerApplication** The name of the calling application. +- **capsuleCount** The number of Sediment Pack capsules. +- **capsuleFailureCount** The number of capsule failures. - **detectionSummary** Result of each applicable detection that was run. - **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. - **hrEngineResult** Error code from the engine operation. +- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. +- **initSummary** Summary data of the initialization method. - **insufficientSessions** Device not eligible for diagnostics. - **isInteractiveMode** The user started a run of WaaSMedic. - **isManaged** Device is managed for updates. - **isWUConnected** Device is connected to Windows Update. - **noMoreActions** No more applicable diagnostics. +- **pluginFailureCount** The number of plugins that have failed. +- **pluginsCount** The number of plugins. - **qualityAssessmentImpact** WaaS Assessment impact for quality updates. - **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. - **usingBackupFeatureAssessment** Relying on backup feature assessment. @@ -6786,6 +6718,7 @@ The following fields are available: - **predefi.edCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller. - **predefinedCalleRName** No content is currently available. +- **rcdnIp** No content is currently available. - **restrictedUpload** Is the upload restricted? - **romteToCacheServer** No content is currently available. - **roupeToCacheServer** No content is currently available. @@ -6807,10 +6740,13 @@ This event represents a temporary suspension of a download with Delivery Optimiz The following fields are available: +- **AddinType** No content is currently available. - **backgground** No content is currently available. - **backgro}nd** No content is currently available. - **backgrou|d** No content is currently available. - **background** Is the download a background download? +- **BinFileTimestamp** No content is currently available. +- **BinFileVersion** No content is currently available. - **c`nUrl** No content is currently available. - **cdnUrl** The URL of the source CDN (Content Delivery Network). - **errorBode** No content is currently available. @@ -6821,10 +6757,21 @@ The following fields are available: - **experimenpId** No content is currently available. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. - **fileID** The ID of the file being paused. +- **FileId** No content is currently available. +- **FileSize** No content is currently available. - **isVp|** No content is currently available. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. +- **LoadBehavior** No content is currently available. +- **LSID** No content is currently available. +- **OfficeArchitecture** No content is currently available. +- **OutlookCrashingAddin** No content is currently available. - **predefinedCallerName** The name of the API Caller object. +- **ProductCompany** No content is currently available. +- **ProductName** No content is currently available. +- **ProductVersion** No content is currently available. +- **ProgramId** No content is currently available. +- **Provider** No content is currently available. - **reasonCod%** No content is currently available. - **reasonCode** The reason for pausing the download. - **recsonCodesessiolID** No content is currently available. From 095289ebc8c759389688c10cef72c5356807698d Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 18 Mar 2019 06:36:12 -0700 Subject: [PATCH 071/737] update main wcd settings table --- windows/configuration/wcd/wcd-changes.md | 2 ++ windows/configuration/wcd/wcd.md | 29 ++++++++++++------------ 2 files changed, 16 insertions(+), 15 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 0100391209..b846faedb0 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -26,6 +26,8 @@ ms.date: 10/02/2018 ## Settings removed in Windows 10, version ? +- [WLAN](wcd-wlan.md) + ## Settings added in Windows 10, version 1809 diff --git a/windows/configuration/wcd/wcd.md b/windows/configuration/wcd/wcd.md index 2c764902cc..732e57f9cb 100644 --- a/windows/configuration/wcd/wcd.md +++ b/windows/configuration/wcd/wcd.md @@ -24,35 +24,34 @@ This section describes the settings that you can configure in [provisioning pack | [ADMXIngestion](wcd-admxingestion.md) | X | | | | | | [AssignedAccess](wcd-assignedaccess.md) | X | | | X | | | [AutomaticTime](wcd-automatictime.md) | | X | | | | -| [Browser](wcd-browser.md) | X | X | X | X | | +| [Browser](wcd-browser.md) | X | X | X | | | | [CallAndMessagingEnhancement](wcd-callandmessagingenhancement.md) | | X | | | | | [Calling](wcd-calling.md) | | X | | | | | [CellCore](wcd-cellcore.md) | X | X | | | | | [Cellular](wcd-cellular.md) | X | | | | | | [Certificates](wcd-certificates.md) | X | X | X | X | X | | [CleanPC](wcd-cleanpc.md) | X | | | | | -| [Connections](wcd-connections.md) | X | X | X | X | | +| [Connections](wcd-connections.md) | X | X | X | | | | [ConnectivityProfiles](wcd-connectivityprofiles.md) | X | X | X | X | | -| [CountryAndRegion](wcd-countryandregion.md) | X | X | X | X | | +| [CountryAndRegion](wcd-countryandregion.md) | X | X | X | | | | [DesktopBackgroundAndColors](wcd-desktopbackgroundandcolors.md) | X | | | | | | [DeveloperSetup](wcd-developersetup.md) | | | | X | | -| [DeviceFormFactor](wcd-deviceformfactor.md) | X | X | X | X | | +| [DeviceFormFactor](wcd-deviceformfactor.md) | X | X | X | | | | [DeviceInfo](wcd-deviceinfo.md) | | X | | | | | [DeviceManagement](wcd-devicemanagement.md) | X | X | X | X | | | [DeviceUpdateCenter](wcd-deviceupdatecenter.md) | X | | | | | -| [DMClient](wcd-dmclient.md) | X | X | X | X | X | -| [EditionUpgrade](wcd-editionupgrade.md) | X | X | X | X | | +| [DMClient](wcd-dmclient.md) | X | X | X | | X | +| [EditionUpgrade](wcd-editionupgrade.md) | X | X | | X | | | [EmbeddedLockdownProfiles](wcd-embeddedlockdownprofiles.md) | | X | | | | | [FirewallConfiguration](wcd-firewallconfiguration.md) | | | | | X | | [FirstExperience](wcd-firstexperience.md) | | | | X | | -| [Folders](wcd-folders.md) |X | X | X | X | | -| [HotSpot](wcd-hotspot.md) | | | | | | +| [Folders](wcd-folders.md) |X | X | X | | | | [InitialSetup](wcd-initialsetup.md) | | X | | | | | [InternetExplorer](wcd-internetexplorer.md) | | X | | | | | [KioskBrowser](wcd-kioskbrowser.md) | | | | | X | | [Licensing](wcd-licensing.md) | X | | | | | | [Location](wcd-location.md) | | | | | X | -| [Maps](wcd-maps.md) |X | X | X | X | | +| [Maps](wcd-maps.md) |X | X | X | | | | [Messaging](wcd-messaging.md) | | X | | | | | [ModemConfigurations](wcd-modemconfigurations.md) | | X | | | | | [Multivariant](wcd-multivariant.md) | | X | | | | @@ -74,18 +73,18 @@ This section describes the settings that you can configure in [provisioning pack | [StartupBackgroundTasks](wcd-startupbackgroundtasks.md) | | | | | X | | [StorageD3InModernStandby](wcd-storaged3inmodernstandby.md) |X | X | X | | X | | [SurfaceHubManagement](wcd-surfacehubmanagement.md) | | | X | | | -| [TabletMode](wcd-tabletmode.md) |X | X | X | X | | +| [TabletMode](wcd-tabletmode.md) |X | X | X | | | | [TakeATest](wcd-takeatest.md) | X | | | | | | [TextInput](wcd-textinput.md) | | X | | | | | [Theme](wcd-theme.md) | | X | | | | | [Time](wcd-time.md) | X | | | | | | [UnifiedWriteFilter](wcd-unifiedwritefilter.md) | X | | | | X | -| [UniversalAppInstall](wcd-universalappinstall.md) | X | X | X | X | X | -| [UniversalAppUninstall](wcd-universalappuninstall.md) | X | X | X | X | X | -| [WeakCharger](wcd-weakcharger.md) |X | X | X | X | | +| [UniversalAppInstall](wcd-universalappinstall.md) | X | X | X | | X | +| [UniversalAppUninstall](wcd-universalappuninstall.md) | X | X | X | | X | +| [UsbErrorsOEMOverride](wcd-usberrorsoemoverride.md) | X | X | X | | | +| [WeakCharger](wcd-weakcharger.md) |X | X | X | | | | [WindowsHelloForBusiness](wcd-windowshelloforbusiness.md) | X | | | | | | [WindowsTeamSettings](wcd-windowsteamsettings.md) | | | X | | | -| [WLAN](wcd-wlan.md) | | | | X | | -| [Workplace](wcd-workplace.md) |X | X | X | X | X | +| [Workplace](wcd-workplace.md) |X | X | X | | X | From a588eef3d1ab0f5be3a63727d73f6a65b174d713 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 18 Mar 2019 07:02:55 -0700 Subject: [PATCH 072/737] update policies table --- windows/configuration/wcd/wcd-policies.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 814e7fbc1d..bf34e59012 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -154,7 +154,7 @@ PreventTabPreloading | Prevent Microsoft Edge from starting and loading the Star | Setting | Description | Desktop editions | Mobile editions | Surface Hub | HoloLens | IoT Core | | --- | --- | :---: | :---: | :---: | :---: | :---: | -| [AllowCamera](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#camera-allowcamera) | Disable or enable the camera. | X | X | X | X | | +| [AllowCamera](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#camera-allowcamera) | Disable or enable the camera. | X | X | X | | | ## Connectivity @@ -568,7 +568,7 @@ ConfigureTelemetryOptInSettingsUx | This policy setting determines whether peopl | [AllowInternetSharing](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#wifi-allowinternetsharing) | Allow Internet sharing. | X | X | | | | | [AllowManualWiFiConfiguration](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#wifi-allowmanualwificonfiguration) | Allow connecting to Wi-Fi outside of MDM server-installed networks. | | X | | | | | [AllowWiFi](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#wifi-allowwifi) | Allow Wi-Fi connections. | | X | | | | -| [WLANScanMode](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#wifi-wlanscanmode) | Configure the WLAN scanning behavior and how aggressively devices should be actively scanning for Wi-Fi networks to get devices connected. | X | X | X | X | X | +| [WLANScanMode](https://docs.microsoft.com/windows/client-management/mdm/policy-configuration-service-provider#wifi-wlanscanmode) | Configure the WLAN scanning behavior and how aggressively devices should be actively scanning for Wi-Fi networks to get devices connected. | X | X | X | | X | ## WindowsInkWorkspace From 1950fb1506f2687de20e4b46d838ba6d7b9bd4b1 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 18 Mar 2019 09:00:14 -0700 Subject: [PATCH 073/737] new build 3/18/2019 9:00 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 2faca0d1a1..1a86bd7a44 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/15/2019 +ms.date: 03/18/2019 --- From 1dc64b7d1c411e8de476cc69ee71ee0ff7f91dcb Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 18 Mar 2019 09:00:25 -0700 Subject: [PATCH 074/737] new build 3/18/2019 9:00 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 97 ++++++++++--------- 4 files changed, 56 insertions(+), 47 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 4aebdedd33..ed6399b844 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/15/2019 +ms.date: 03/18/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 0fa19351b5..280f37035d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/15/2019 +ms.date: 03/18/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index cc061437ac..f030734e75 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/15/2019 +ms.date: 03/18/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index db961c12d8..57eaedd246 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/15/2019 +ms.date: 03/18/2019 --- @@ -850,6 +850,7 @@ The following fields are available: - **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? - **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? - **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **DriverJlockOverridden** No content is currently available. - **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? - **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? - **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? @@ -1978,6 +1979,7 @@ The following fields are available: - **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. - **LanguagePacks** The list of language packages installed on the device. - **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProducoKzyàPŒïdjstDr})D6ài3êryyjMachineIP** No content is currently available. - **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. - **OSEdition** Retrieves the version of the current OS. - **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc @@ -2028,6 +2030,7 @@ The following fields are available: - **LocationHistory** Current state of the location history setting. - **LocationHistoryCloudSync** Current state of the location history cloud sync setting. - **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **LocTîÿxV4ocationHistory** No content is currently available. - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. @@ -2147,6 +2150,8 @@ The following fields are available: - **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches - **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine - **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **OumberofExternalDisplays** No content is currently available. +- **OumberofInternalDisplays** No content is currently available. - **VRAMDedicated** Retrieves the video RAM in MB. - **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. - **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. @@ -2267,6 +2272,7 @@ The following fields are available: - **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. - **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxConsoleSerialOumber** No content is currently available. - **XboxLiveDeviceId** Retrieves the unique device ID of the console. - **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. @@ -2446,12 +2452,14 @@ Describes the installation state for all hardware and software components availa The following fields are available: +- **ac|ion** No content is currently available. - **action** The change that was invoked on a device inventory object. - **cction** No content is currently available. - **inventoryId** Device ID used for Compatibility testing - **objectInstanceId** Object identity which is unique within the device scope. - **objectType** Indicates the object type that the event applies to. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. +- **synkId** No content is currently available. ## Compatibility events @@ -2709,6 +2717,7 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgentConnectionrrorCsCount** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. @@ -2722,7 +2731,9 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DecodthiDroppedCount** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EnterthiCriticalOverflowDroppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2737,17 +2748,24 @@ The following fields are available: - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastAgentConnectionrrorC** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **MaxInUseScenaryoCounter** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailqreDpopped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **SettthisHttpAttempts** No content is currently available. +- **SettthisHttpFailures** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. +- **TopUploaderrrorCs** No content is currently available. +- **UphoaderErporCount** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. @@ -2756,6 +2774,7 @@ The following fields are available: - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **틠"怀⋖��"ꀀ⋙��"怀⋛"倀⋢** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -2772,6 +2791,7 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to database failures. - **DbDroppedFullCount** Number of events dropped due to database being full. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **Eve~tStoreResetCounter** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times the event store has been reset. - **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. @@ -3358,87 +3378,50 @@ This event sends basic GPU and display driver information to keep Windows and di The following fields are available: -- **AdapterDypeValue** No content is currently available. - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiseqId** No content is currently available. - **aiSeqId** The event sequence ID. -- **AsPostAdapter** No content is currently available. +- **AsMiracastSupported** No content is currently available. - **bootId** The system boot ID. -- **BrightnessVersion'iaDDI** No content is currently available. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **BrightnessVersIonViaDDI** No content is currently available. -- **BvightnessVersionViaDDI** No content is currently available. -- **Com2utePreemptionLevel** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DicplayAdapterLuid** No content is currently available. +- **DisplaqAdapterLuid** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. -- **Driver48,k** No content is currently available. - **DriverDate** The date of the display driver. -- **DriverFersion** No content is currently available. -- **DriverRa~k** No content is currently available. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. - **DX11UMDFile@ath** No content is currently available. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12EMDFilePath** No content is currently available. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9]MDFilePath** No content is currently available. -- **DX9EMDFilePath** No content is currently available. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **G@UVendorID** No content is currently available. - **GPUDeviceID** The GPU device ID. -- **GPUPree}ptionLevel** No content is currently available. -- **GPUPreemptionLdvel** No content is currently available. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. -- **GPUVendoeID** No content is currently available. - **GPUVendorID** The GPU vendor ID. -- **I¤MismatchLDA** No content is currently available. -- **InterbaceId** No content is currently available. - **InterfaceId** The GPU interface ID. -- **IÓDisplayDevice** No content is currently available. -- **IqMPOSupported** No content is currently available. -- **IrRemovable** No content is currently available. -- **IsCoftwareDevice** No content is currently available. -- **IsDisp|ayDevice** No content is currently available. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntdgrated** No content is currently available. - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMicmatchLDA** No content is currently available. - **IsMiracastSupported** Does the GPU support Miracast? -- **IsMism`tchLDA** No content is currently available. - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOCupported** No content is currently available. -- **IsMPOSuppor|ed** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? - **IsRemovable** TRUE if the adapter supports being disabled or removed. - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? -- **IsSoftwareDevicg** No content is currently available. -- **KMD@ilePath** No content is currently available. - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumTidPlTarMets** No content is currently available. -- **NumVidPDSouPces** No content is currently available. - **NumVidPnSources** The number of supported display output sources. - **NumVidPnTargets** The number of supported display output targets. -- **SharedCystemMemoryB** No content is currently available. - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSyste}ID** No content is currently available. - **SubSystemID** The subsystem ID. -- **SubSystemKD** No content is currently available. -- **SubVendoeID** No content is currently available. - **SubVendorID** The GPU sub vendor ID. -- **TelematryEnabled** No content is currently available. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) - **version** The event version. @@ -3540,21 +3523,19 @@ The following fields are available: - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FoiendlyAppName** No content is currently available. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). - **ModNamevaultsv** No content is currently available. -- **ModNaoe** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. - **PaccageFullName** No content is currently available. - **PackageFullName** Store application identity. -- **PackageFuLlName** No content is currently available. - **PackageRelaatieAppId** No content is currently available. - **PackageRelativaAppId** No content is currently available. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateDime** No content is currently available. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. - **PRocessId** No content is currently available. @@ -3567,6 +3548,7 @@ The following fields are available: - **TargetAsId** The sequence number for the hanging process. - **TargetAwId** No content is currently available. - **TrocessArchitecture** No content is currently available. +- **TrocessCreateTime** No content is currently available. ## Feature update events @@ -3908,7 +3890,7 @@ The following fields are available: This event represents the basic metadata about a plug and play (PNP) device and its associated driver. -This event includes fields from [Ms.Dedevi.DedeviInventoryChange](#msdedevidedeviinventorychange). +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: @@ -3932,6 +3914,7 @@ The following fields are available: - **ExtendedInfs** The extended INF file names. - **HWID** A list of hardware IDs for the device. - **HWID.Count** No content is currently available. +- **IlstallStcte** No content is currently available. - **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). - **InstallCtate** No content is currently available. - **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx @@ -3943,12 +3926,16 @@ The following fields are available: - **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. - **Model** Identifies the model of the device. - **ParentId** The Device Instance ID of the parent of the device. +- **Part@_Ms.Devkce.DeviaeInventmryChangg** No content is currently available. See [Part@_Ms.Devkce.DeviaeInventmryChangg](#part@_msdevkcedeviaeinventmrychangg). - **ProblemCode** The error code currently returned by the device, if applicable. - **Provider** Identifies the device provider. - **Service** The name of the device service. +- **STACKAD** No content is currently available. - **STACKID** The list of hardware IDs for the stack. - **STACKID.Count** No content is currently available. +- **UpperAlassFilvers** No content is currently available. - **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilteps** No content is currently available. - **UpperFilters** The identifiers of the Upper filters installed for the device. @@ -4016,6 +4003,8 @@ The following fields are available: - **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. - **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. - **DriverVersion** The version of the driver file. +- **DviverCompany** No content is currently available. +- **Imagesize** No content is currently available. - **ImageSize** The size of the driver file. - **Inf** The name of the INF file. - **InventoryVersion** The version of the inventory file generating the events. @@ -4805,6 +4794,7 @@ The following fields are available: - **originatingContextId** The ID of the originating call context that resulted in the failure. - **originatingContextMessage** The message of the originating call context that resulted in the failure. - **originatingContextName** The name of the originating call context that resulted in the failure. +- **threa0Id** No content is currently available. - **threadId** The ID of the thread on which the activity is executing. @@ -4896,9 +4886,12 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: +- **AativityMatchingId** No content is currently available. - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **ActivityMatcjingId** No content is currently available. - **AllowCachedResul|s** No content is currently available. - **AllowCachedResults** Indicates if the scan allowed using cached results. +- **AllowCachedRmsults** No content is currently available. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. @@ -4922,6 +4915,7 @@ The following fields are available: - **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. - **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. - **DriverSyncPassPerformed** Were drivers scanned this time? +- **DriverSyncPasSPerformed** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. - **ExtendedetadataICabUrl** No content is currently available. @@ -4931,6 +4925,7 @@ The following fields are available: - **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. - **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePerimd** No content is currently available. - **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -4938,10 +4933,12 @@ The following fields are available: - **IntentPFNs** Intended application-set metadata for atomic update scenarios. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEna`led** No content is currently available. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConneativityDetected** No content is currently available. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked @@ -4966,6 +4963,7 @@ The following fields are available: - **ScanDurationInSeconds** The number of seconds a scan took - **ScanEnqueueTime** The number of seconds it took to initialize a scan - **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiaeUrl** No content is currently available. - **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). - **ServiceUrl** The environment URL a device is configured to scan with - **ShippingMobileOperator** The mobile operator that a device shipped on. @@ -5020,6 +5018,7 @@ The following fields are available: - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlocKHashFailures** No content is currently available. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. @@ -5037,6 +5036,7 @@ The following fields are available: - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CallerApplicavionName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. @@ -5077,6 +5077,7 @@ The following fields are available: - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulitionResult** No content is currently available. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. @@ -5179,6 +5180,7 @@ The following fields are available: - **CurrentMobileOperator** The mobile operator to which the device is currently connected. - **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** The device model. +- **DriverPifgBack** No content is currently available. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. @@ -5652,6 +5654,7 @@ The following fields are available: - **Count** The count of applicable OneSettings for the device. - **FlightId** Unique ID for the flight (test instance version). +- **Obj%ctId** No content is currently available. - **ObjectId** The unique value for each Update Agent mode. - **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. - **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. @@ -6666,6 +6669,7 @@ The following fields are available: - **bytesFromCacheServer** Bytes received from a cache host. - **bytesFromCdN** No content is currently available. - **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGpoupPeers** No content is currently available. - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntÐeers** No content is currently available. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. @@ -6703,6 +6707,7 @@ The following fields are available: - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. - **groupConjectionCount** No content is currently available. - **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCnunt** No content is currently available. - **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. - **internetConnectionCountdownlinkBps** No content is currently available. - **isEjcrypted** No content is currently available. @@ -6762,6 +6767,7 @@ The following fields are available: - **isVp|** No content is currently available. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. +- **ksVpn** No content is currently available. - **LoadBehavior** No content is currently available. - **LSID** No content is currently available. - **OfficeArchitecture** No content is currently available. @@ -6827,6 +6833,7 @@ The following fields are available: - **routeToCacheSedver** No content is currently available. - **routeToCacheServer** Cache server setting, source, and value. - **sessionID** The ID for the file download session. +- **sessionIF** No content is currently available. - **sessmonID** No content is currently available. - **setConfigs** A JSON representation of the configurations that have been set, and their sources. - **updateID** The ID of the update being downloaded. @@ -6852,6 +6859,7 @@ The following fields are available: - **htppStatusCode** No content is currently available. - **httpStatusCode** The HTTP status code returned by the CDN. - **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerTyp,** No content is currently available. - **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). - **requestOffset** The byte offset within the file in the sent request. - **requestSize** The size of the range requested from the CDN. @@ -6871,6 +6879,7 @@ The following fields are available: - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. - **fileID** The ID of the file being downloaded. - **jobID** The Windows Update job ID. +- **jobKD** No content is currently available. ## Windows Update events From 2f7c31ab8fea6329c5acb39b99b235deacdbd592 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 19 Mar 2019 08:26:28 -0700 Subject: [PATCH 075/737] version 1903 --- windows/configuration/wcd/wcd-changes.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index b846faedb0..785a38cf30 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -13,7 +13,7 @@ ms.date: 10/02/2018 # Changes to settings in Windows Configuration Designer -## Settings added in Windows 10, version ? +## Settings added in Windows 10, version 1903 - [DeviceUpdateCenter](wcd-deviceupdatecenter.md) - [Privacy](wcd-privacy.md) @@ -24,7 +24,7 @@ ms.date: 10/02/2018 - [Policies > Power](wcd-policies.md#power) - [StorageD3InModernStandby](wcd-storaged3inmodernstandby.md) -## Settings removed in Windows 10, version ? +## Settings removed in Windows 10, version 1903 - [WLAN](wcd-wlan.md) From 630c0fb7caf1bf4a3cb209617ead0a2585959ef8 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 19 Mar 2019 09:08:15 -0700 Subject: [PATCH 076/737] new build 3/19/2019 9:08 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 1a86bd7a44..03eb191a9a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/18/2019 +ms.date: 03/19/2019 --- @@ -3130,6 +3130,8 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: +- **Audio.CaptureDriver** No content is currently available. +- **Audio.RenderDriver** No content is currently available. - **Audio_CaptureDriver** The Audio device capture driver endpoint. - **Audio_RenderDriver** The Audio device render driver endpoint. - **InventoryVersion** The version of the inventory file generating the events. From 98569285e4f4f915486532c0c8f4426902d3a7e7 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 19 Mar 2019 09:08:22 -0700 Subject: [PATCH 077/737] new build 3/19/2019 9:08 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 15708 ++++++++-------- 4 files changed, 7858 insertions(+), 7856 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index ed6399b844..28d0314670 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/18/2019 +ms.date: 03/19/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 280f37035d..16140deb3c 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/18/2019 +ms.date: 03/19/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index f030734e75..cf362ccc46 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/18/2019 +ms.date: 03/19/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 57eaedd246..1daea9d4d6 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7853 +1,7855 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -audience: ITPro -ms.date: 03/18/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **DriverJlockOverridden** No content is currently available. -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProducoKzyàPŒïdjstDr})D6ài3êryyjMachineIP** No content is currently available. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **LocTîÿxV4ocationHistory** No content is currently available. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **OumberofExternalDisplays** No content is currently available. -- **OumberofInternalDisplays** No content is currently available. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFaDirect** No content is currently available. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxConsoleSerialOumber** No content is currently available. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **ac|ion** No content is currently available. -- **action** The change that was invoked on a device inventory object. -- **cction** No content is currently available. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. -- **synkId** No content is currently available. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AgentConnectionrrorCsCount** No content is currently available. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DecodthiDroppedCount** No content is currently available. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EnterthiCriticalOverflowDroppedCounter** No content is currently available. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastAgentConnectionrrorC** No content is currently available. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **MaxInUseScenaryoCounter** No content is currently available. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailqreDpopped** No content is currently available. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **SettthisHttpAttempts** No content is currently available. -- **SettthisHttpFailures** No content is currently available. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **TopUploaderrrorCs** No content is currently available. -- **UphoaderErporCount** No content is currently available. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **틠"怀⋖��"ꀀ⋙��"怀⋛"倀⋢** No content is currently available. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **Eve~tStoreResetCounter** No content is currently available. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability - -Event to indicate that the Coordinator CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** Result of CheckApplicability function. -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. -- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. -- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. -- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. -- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. -- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. -- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. -- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. -- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. -- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. -- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). -- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. -- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. -- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiSeqId** The event sequence ID. -- **AsMiracastSupported** No content is currently available. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplaqAdapterLuid** No content is currently available. -- **DisplayAdapterLuid** The display adapter LUID. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFile@ath** No content is currently available. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **GPUDeviceID** The GPU device ID. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPURevisionID** The GPU revision ID. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **version** The event version. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **@ackageRelativeAppId** No content is currently available. -- **AppName** The name of the app that has crashed. -- **AppSeqsionGuid** No content is currently available. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **AptName** No content is currently available. -- **AptSessionGuid** No content is currently available. -- **DargetAppId** No content is currently available. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FoiendlyAppName** No content is currently available. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModName** Exception module name (e.g. bar.dll). -- **ModNamevaultsv** No content is currently available. -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **PaccageFullName** No content is currently available. -- **PackageFullName** Store application identity. -- **PackageRelaatieAppId** No content is currently available. -- **PackageRelativaAppId** No content is currently available. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **PRocessId** No content is currently available. -- **RepkrtId** No content is currently available. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargepAppVer** No content is currently available. -- **TargetAppI`** No content is currently available. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. -- **TargetAwId** No content is currently available. -- **TrocessArchitecture** No content is currently available. -- **TrocessCreateTime** No content is currently available. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **InventoryMiscnfo** No content is currently available. -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModifi** No content is currently available. -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateArpLasuModified** No content is currently available. -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **Order** No content is currently available. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **PackagmFullName** No content is currently available. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Value** No content is currently available. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **basedata** No content is currently available. See [basedata](#basedata). -- **BusReportedDescription** The description of the device reported by the bux. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **COMPID.Count** No content is currently available. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Description** The description of the device. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverP!ckageStrongName** No content is currently available. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **HWID** A list of hardware IDs for the device. -- **HWID.Count** No content is currently available. -- **IlstallStcte** No content is currently available. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallCtate** No content is currently available. -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **Manufccturer** No content is currently available. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **Part@_Ms.Devkce.DeviaeInventmryChangg** No content is currently available. See [Part@_Ms.Devkce.DeviaeInventmryChangg](#part@_msdevkcedeviaeinventmrychangg). -- **ProblemCode** The error code currently returned by the device, if applicable. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKAD** No content is currently available. -- **STACKID** The list of hardware IDs for the stack. -- **STACKID.Count** No content is currently available. -- **UpperAlassFilvers** No content is currently available. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilteps** No content is currently available. -- **UpperFilters** The identifiers of the Upper filters installed for the device. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - -This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **DviverCompany** No content is currently available. -- **Imagesize** No content is currently available. -- **ImageSize** The size of the driver file. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersio~** No content is currently available. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **Firmw!reResetReasonEmbeddedControllerAdditional** No content is currently available. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **hr** The HResult of the operation. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **-149ngContextMessage** No content is currently available. -- **3645entContextName** No content is currently available. -- **379rentContextName** No content is currently available. -- **532rentContextName** No content is currently available. -- **677rentContextName** No content is currently available. -- **8108entContextName** No content is currently available. -- **8251entContextName** No content is currently available. -- **902rentContextName** No content is currently available. -- **9567ngContextMessage** No content is currently available. -- **9717ngContextMessage** No content is currently available. -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextMessaon** No content is currently available. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **functige** No content is currently available. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **ori1-0467ngContextMessage** No content is currently available. -- **ori1-1210ngContextMessage** No content is currently available. -- **ori1143-7ngContextMessage** No content is currently available. -- **ori1-1945ngContextMessage** No content is currently available. -- **ori13s090ngContextMessage** No content is currently available. -- **ori1-4671entContextName** No content is currently available. -- **ori1-5108ngContextMessage** No content is currently available. -- **ori1-5686ngContextMessage** No content is currently available. -- **ori1n:667ngContextMessage** No content is currently available. -- **ori1n8488ngContextMessage** No content is currently available. -- **ori1-s4o5ngContextMessage** No content is currently available. -- **ori808467ngContextMessage** No content is currently available. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threa0Id** No content is currently available. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **Falue** No content is currently available. -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **AativityMatchingId** No content is currently available. -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **ActivityMatcjingId** No content is currently available. -- **AllowCachedResul|s** No content is currently available. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **AllowCachedRmsults** No content is currently available. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **DriverSyncPasSPerformed** No content is currently available. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedetadataICabUrl** No content is currently available. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePerimd** No content is currently available. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEna`led** No content is currently available. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConneativityDetected** No content is currently available. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedetadataISignatures** No content is currently available. -- **NumFailedMetadatabignatures** No content is currently available. -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiaeUrl** No content is currently available. -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumetadataISignatures** No content is currently available. -- **TotalNumMetadatabignatures** No content is currently available. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlocKHashFailures** No content is currently available. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CallerApplicavionName** No content is currently available. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation properties in the form of a bitmask. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RegulitionResult** No content is currently available. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **SonnectTime** No content is currently available. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPifgBack** No content is currently available. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RelntedCV** No content is currently available. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **umberOfApplicableUpdates** No content is currently available. -- **WUDeviceID** The unique device ID controlled by the software distribution client. -- **xHDeviceID** No content is currently available. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **CallerLoglicationName** No content is currently available. -- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. -- **EventSbenario** No content is currently available. -- **EventScenario** The purpose of this event, such as scan started, scan succeeded, or scan failed. -- **ExtendedStatusCode** The secondary status code of the event. -- **ExtendefStatusCode** No content is currently available. -- **imeZoScenario** No content is currently available. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** The mode of the transport metadata integrity check. 0 = unknown; 1 = ignore; 2 = audit; 3 = enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RcwMode** No content is currently available. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **SedviceGuid** No content is currently available. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **ServiceGuidEndpointUrl** No content is currently available. -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program to which a device may have opted in. Example: Insider Fast -- **StatusCode** The status code of the event. -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageCountTotalPSFX** The total number of PSFX packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **PackageSizePSFX** The size of PSFX packages, in bytes. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **essionData** No content is currently available. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **Friled** No content is currently available. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **Obj%ctId** No content is currently available. -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanãeId** No content is currently available. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **value** No content is currently available. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **o-Ste** No content is currently available. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **capsuleCount** The number of Sediment Pack capsules. -- **capsuleFailureCount** The number of capsule failures. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. -- **hrEngineResult** Error code from the engine operation. -- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. -- **initSummary** Summary data of the initialization method. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **pluginFailureCount** The number of plugins that have failed. -- **pluginsCount** The number of plugins. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckPar%meter2** No content is currently available. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Windows Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AggregatedPackageFullNcmes** No content is currently available. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **Bundlele** No content is currently available. -- **CategoryId** The Item Category ID. -- **Categoryle** No content is currently available. -- **ClientAppId** The identity of the app that initiated this operation. -- **ClientApple** No content is currently available. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **ParentBundlele** No content is currently available. -- **PFN** The product family name of the product being installed. -- **Producele** No content is currently available. -- **ProductId** The identity of the package or packages being installed. -- **S{stemAttemptNumber** No content is currently available. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNaies** No content is currently available. -- **AggregatedpackageFullNames** No content is currently available. -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUp`ate** No content is currently available. -- **IsUpdate** Is this an update? -- **ParentBuneleId** No content is currently available. -- **PFN** Product Family Name of the product being installed. -- **Produc|Id** No content is currently available. -- **productId** No content is currently available. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNueber** No content is currently available. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **UserCttemptNumber** No content is currently available. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullLames** No content is currently available. -- **AggregatedPackageFullNaðes** No content is currently available. -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **CategoryIf** No content is currently available. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNum`er** No content is currently available. -- **UserAttemptNumber** The number of attempts by the user to download. -- **UserCttemptNumber** No content is currently available. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **__TlgCÖ__** No content is currently available. -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsInteragtive** No content is currently available. -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **CatanogId** No content is currently available. -- **CatdlogId** No content is currently available. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **JResult** No content is currently available. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **Producele** No content is currently available. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **categoryId** No content is currently available. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **#dnErrorCounts** No content is currently available. -- **__TlgCVß_** No content is currently available. -- **|anConnectionCount** No content is currently available. -- **}plinkUsageBps** No content is currently available. -- **0redefinedCallerName** No content is currently available. -- **b6nConnectionCount** No content is currently available. -- **b6nErrorCodes** No content is currently available. -- **b6nErrorCounts** No content is currently available. -- **b6nIp** No content is currently available. -- **b6nUrl** No content is currently available. -- **background** Is the download a background download? -- **bytesFrkmIntPeers** No content is currently available. -- **bytesFromCacheSedver** No content is currently available. -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCdN** No content is currently available. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGpoupPeers** No content is currently available. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntÐeers** No content is currently available. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheSarverConnectionCount** No content is currently available. -- **cacheSedverConnectionCount** No content is currently available. -- **cacheServerConndctionCount** No content is currently available. -- **cacheServerConnectionCoujt** No content is currently available. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnSonnectionCount** No content is currently available. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dkwnloadModeSrc** No content is currently available. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **dowflinkBps** No content is currently available. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **doWnloadMode** No content is currently available. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **downloadMofeSrc** No content is currently available. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConjectionCount** No content is currently available. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **internetConnectionCnunt** No content is currently available. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **internetConnectionCountdownlinkBps** No content is currently available. -- **isEjcrypted** No content is currently available. -- **isEncryptdd** No content is currently available. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCo}nt** No content is currently available. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefi.edCallerName** No content is currently available. -- **predefinedCallerName** The name of the API Caller. -- **predefinedCalleRName** No content is currently available. -- **rcdnIp** No content is currently available. -- **restrictedUpload** Is the upload restricted? -- **romteToCacheServer** No content is currently available. -- **roupeToCacheServer** No content is currently available. -- **routeTnCacheServer** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **uplinkUsegeBps** No content is currently available. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **AddinType** No content is currently available. -- **backgground** No content is currently available. -- **backgro}nd** No content is currently available. -- **backgrou|d** No content is currently available. -- **background** Is the download a background download? -- **BinFileTimestamp** No content is currently available. -- **BinFileVersion** No content is currently available. -- **c`nUrl** No content is currently available. -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorBode** No content is currently available. -- **errorCode** The error code that was returned. -- **expebimentId** No content is currently available. -- **expebimentIderrorCode** No content is currently available. -- **experiientId** No content is currently available. -- **experimenpId** No content is currently available. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **FileId** No content is currently available. -- **FileSize** No content is currently available. -- **isVp|** No content is currently available. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **ksVpn** No content is currently available. -- **LoadBehavior** No content is currently available. -- **LSID** No content is currently available. -- **OfficeArchitecture** No content is currently available. -- **OutlookCrashingAddin** No content is currently available. -- **predefinedCallerName** The name of the API Caller object. -- **ProductCompany** No content is currently available. -- **ProductName** No content is currently available. -- **ProductVersion** No content is currently available. -- **ProgramId** No content is currently available. -- **Provider** No content is currently available. -- **reasonCod%** No content is currently available. -- **reasonCode** The reason for pausing the download. -- **recsonCodesessiolID** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. -- **updateMD** No content is currently available. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **b6nUrl** No content is currently available. -- **background** Indicates whether the download is happening in the background. -- **bacoground** No content is currently available. -- **bileSizeCaller** No content is currently available. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **costFlaos** No content is currently available. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorC/de** No content is currently available. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **doErrorCoee** No content is currently available. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimejtId** No content is currently available. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **faleID** No content is currently available. -- **fiheID** No content is currently available. -- **fileID** The ID of the file being downloaded. -- **filePat(** No content is currently available. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groqpID** No content is currently available. -- **groupID** ID for the group. -- **isEncrypted** Indicates whether the download is encrypted. -- **isFpn** No content is currently available. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCallerName** Name of the API caller. -- **rimentId** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** Cache server setting, source, and value. -- **sessionID** The ID for the file download session. -- **sessionIF** No content is currently available. -- **sessmonID** No content is currently available. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **updateYD** No content is currently available. -- **usedMemoryStream** Indicates whether the download used memory streaming. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **eErrorCode** No content is currently available. -- **eErrorCunt** No content is currently available. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **htppStatusCode** No content is currently available. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerTyp,** No content is currently available. -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. -- **jobKD** No content is currently available. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **e:4|SScenario** No content is currently available. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **interactiveelatedCVerrorCode** No content is currently available. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenariotate** No content is currently available. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **defeec-9-0S** No content is currently available. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **Ignorec-9-0SsFoec-start** No content is currently available. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateMd** No content is currently available. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateAd** No content is currently available. -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager - -This event returns data about the Update Reserve Manager, including whether it’s been initialized. - -The following fields are available: - -- **ClientId** The ID of the caller application. -- **Flags** The enumerated flags used to initialize the manager. -- **FlightId** The flight ID of the content the calling client is currently operating with. -- **Offline** Indicates whether or the reserve manager is called during offline operations. -- **PolicyPassed** Indicates whether the machine is able to use reserves. -- **ReturnCode** Return code of the operation. -- **Version** The version of the Update Reserve Manager. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **Disposition** The parameter for the hard reserve adjustment function. -- **Flags** The flags passed to the hard reserve adjustment function. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/19/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **DriverJlockOverridden** No content is currently available. +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **LocTîÿxV4ocationHistory** No content is currently available. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **ÉnternalPrimaryDisplayLogicalDPIY** No content is currently available. +- **IîternalPrimaryDisplayResolutionVertical** No content is currently available. +- **InterjalPrimaryDisplayResolutionHorizontal** No content is currently available. +- **InternalPrimaðyDisplayPhysicalDPIX** No content is currently available. +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicálDPIX** No content is currently available. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **InternalPrimaryDiwplayPhysicalDPIY** No content is currently available. +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **OumberofExternalDisplays** No content is currently available. +- **OumberofInternalDisplays** No content is currently available. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxConsoleSerialOumber** No content is currently available. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **inventoryId** Device ID used for Compatibility testing +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgentConnectionrrorCsCount** No content is currently available. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DecodthiDroppedCount** No content is currently available. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EnterthiCriticalOverflowDroppedCounter** No content is currently available. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastAgentConnectionrrorC** No content is currently available. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **Max8ctiveAgentConnectionCount** No content is currently available. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **MaxInUseScenaryoCounter** No content is currently available. +- **omporessedBytesUploaded** No content is currently available. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailqreDpopped** No content is currently available. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **SettthisHttpAttempts** No content is currently available. +- **SettthisHttpFailures** No content is currently available. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **TopUploaderrrorCs** No content is currently available. +- **UphoaderErporCount** No content is currently available. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWirhDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **Eve~tStoreResetCounter** No content is currently available. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. +- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. +- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. +- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. +- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. +- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. +- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. +- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. +- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. +- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. +- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). +- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. +- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. +- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DedicatedVkdeoMemoryB** No content is currently available. +- **DisplayAdapterLuid** The display adapter LUID. +- **DriverDate** The date of the display driver. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **GPUDeviceID** The GPU device ID. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPUVendorID** The GPU vendor ID. +- **GPUVgndorID** No content is currently available. +- **InterfaceId** The GPU interface ID. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **N}mVidPnSources** No content is currently available. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSystemID** The subsystem ID. +- **SubVendopID** No content is currently available. +- **SubVendorID** The GPU sub vendor ID. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TenemetryEnabled** No content is currently available. +- **TenInvEvntTrigger** No content is currently available. +- **version** The event version. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **AppName** The name of the app that has crashed. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **InventoryMiscnfo** No content is currently available. +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsMAchineContainer** No content is currently available. +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **basedata** No content is currently available. See [basedata](#basedata). +- **BusReportedDescription** The description of the device reported by the bux. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Description** The description of the device. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriveRPackageStrongNaMe** No content is currently available. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **HWID** A list of hardware IDs for the device. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **Manufacturer** The manufacturer of the device. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Model** Identifies the model of the device. +- **ParentId** The Device Instance ID of the parent of the device. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **Provider** Identifies the device provider. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Dri6erCompany** No content is currently available. +- **Driv%rPackageStrongName** No content is currently available. +- **Drive2Name** No content is currently available. +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompa.y** No content is currently available. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSign%d** No content is currently available. +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **DviverCompany** No content is currently available. +- **I.f** No content is currently available. +- **Imagesize** No content is currently available. +- **ImageSize** The size of the driver file. +- **Inf** The name of the INF file. +- **Invento2yVersion** No content is currently available. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersio~** No content is currently available. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **Firmw!reResetReasonEmbeddedControllerAdditional** No content is currently available. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **hr** The HResult of the operation. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **-149ngContextMessage** No content is currently available. +- **3645entContextName** No content is currently available. +- **379rentContextName** No content is currently available. +- **532rentContextName** No content is currently available. +- **677rentContextName** No content is currently available. +- **8108entContextName** No content is currently available. +- **8251entContextName** No content is currently available. +- **902rentContextName** No content is currently available. +- **9567ngContextMessage** No content is currently available. +- **9717ngContextMessage** No content is currently available. +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextMessaon** No content is currently available. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **functige** No content is currently available. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **ori1-0467ngContextMessage** No content is currently available. +- **ori1-1210ngContextMessage** No content is currently available. +- **ori1143-7ngContextMessage** No content is currently available. +- **ori1-1945ngContextMessage** No content is currently available. +- **ori13s090ngContextMessage** No content is currently available. +- **ori1-4671entContextName** No content is currently available. +- **ori1-5108ngContextMessage** No content is currently available. +- **ori1-5686ngContextMessage** No content is currently available. +- **ori1n:667ngContextMessage** No content is currently available. +- **ori1n8488ngContextMessage** No content is currently available. +- **ori1-s4o5ngContextMessage** No content is currently available. +- **ori808467ngContextMessage** No content is currently available. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threa0Id** No content is currently available. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **Falue** No content is currently available. +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **AativityMatchingId** No content is currently available. +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **ActivityMatcjingId** No content is currently available. +- **AllowCachedResul|s** No content is currently available. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **AllowCachedRmsults** No content is currently available. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **DriverSyncPasSPerformed** No content is currently available. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedetadataICabUrl** No content is currently available. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePausePerimd** No content is currently available. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEna`led** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConneativityDetected** No content is currently available. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedetadataISignatures** No content is currently available. +- **NumFailedMetadatabignatures** No content is currently available. +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiaeUrl** No content is currently available. +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumetadataISignatures** No content is currently available. +- **TotalNumMetadatabignatures** No content is currently available. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **VelatedCV** No content is currently available. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlocKHashFailures** No content is currently available. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BundleRevisionumber** No content is currently available. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CallerApplicavionName** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCoun|ryCode** No content is currently available. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FFightBuildNumber** No content is currently available. +- **FFightId** No content is currently available. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HostName** The hostname URL the content is downloading from. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBEnaBled** No content is currently available. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **PackageFullName** The package name of the content. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **RegulationReason** The reason that the update is regulated +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RegulitionResult** No content is currently available. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **RevisionNUmber** No content is currently available. +- **Revisionumber** No content is currently available. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **ServiceGUid** No content is currently available. +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **SonnectTime** No content is currently available. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPifgBack** No content is currently available. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **RelntedCV** No content is currently available. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **umberOfApplicableUpdates** No content is currently available. +- **WUDeviceID** The unique device ID controlled by the software distribution client. +- **xHDeviceID** No content is currently available. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **CallerLoglicationName** No content is currently available. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventSbenario** No content is currently available. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. +- **ExtendefStatusCode** No content is currently available. +- **imeZoScenario** No content is currently available. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RcwMode** No content is currently available. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **SedviceGuid** No content is currently available. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **ServiceGuidEndpointUrl** No content is currently available. +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". +- **StatusCode** Result code of the event (success, cancellation, failure code HResult) +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **essionData** No content is currently available. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **Friled** No content is currently available. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **Obj%ctId** No content is currently available. +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanãeId** No content is currently available. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **value** No content is currently available. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **o-Ste** No content is currently available. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **capsuleCount** The number of Sediment Pack capsules. +- **capsuleFailureCount** The number of capsule failures. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. +- **hrEngineResult** Error code from the engine operation. +- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. +- **initSummary** Summary data of the initialization method. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **pluginFailureCount** The number of plugins that have failed. +- **pluginsCount** The number of plugins. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionbtring** No content is currently available. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckPar%meter2** No content is currently available. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AggregatedPackageFullNcmes** No content is currently available. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **Bundlele** No content is currently available. +- **CategoryId** The Item Category ID. +- **Categoryle** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **ClientApple** No content is currently available. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **ParentBundlele** No content is currently available. +- **PFN** The product family name of the product being installed. +- **Producele** No content is currently available. +- **ProductId** The identity of the package or packages being installed. +- **S{stemAttemptNumber** No content is currently available. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNaies** No content is currently available. +- **AggregatedpackageFullNames** No content is currently available. +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUp`ate** No content is currently available. +- **IsUpdate** Is this an update? +- **ParentBuneleId** No content is currently available. +- **PFN** Product Family Name of the product being installed. +- **Produc|Id** No content is currently available. +- **productId** No content is currently available. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNueber** No content is currently available. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullLames** No content is currently available. +- **AggregatedPackageFullNaðes** No content is currently available. +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AsUpdate** No content is currently available. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **CategoryIf** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNum`er** No content is currently available. +- **UserAttemptNumber** The number of attempts by the user to download. +- **UserCttemptNumber** No content is currently available. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **__TlgCÖ__** No content is currently available. +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsInteragtive** No content is currently available. +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsRestorg** No content is currently available. +- **IsUpdate** Is this an update? +- **KsBundle** No content is currently available. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **CatanogId** No content is currently available. +- **CatdlogId** No content is currently available. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **JResult** No content is currently available. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **Producele** No content is currently available. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **categoryId** No content is currently available. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **#dnErrorCounts** No content is currently available. +- **__TlgCVß_** No content is currently available. +- **|anConnectionCount** No content is currently available. +- **}plinkUsageBps** No content is currently available. +- **0redefinedCallerName** No content is currently available. +- **b6nConnectionCount** No content is currently available. +- **b6nErrorCodes** No content is currently available. +- **b6nErrorCounts** No content is currently available. +- **b6nIp** No content is currently available. +- **b6nUrl** No content is currently available. +- **b9tesFromPeers** No content is currently available. +- **background** Is the download a background download? +- **bytesFrkmIntPeers** No content is currently available. +- **bytesFromCacheSedver** No content is currently available. +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCdN** No content is currently available. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGpoupPeers** No content is currently available. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntÐeers** No content is currently available. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **byTesFromIntPeers** No content is currently available. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheSarverConnectionCount** No content is currently available. +- **cacheSedverConnectionCount** No content is currently available. +- **cacheServerConndctionCount** No content is currently available. +- **cacheServerConnectionCoujt** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnSonnectionCount** No content is currently available. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dkwnloadModeSrc** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **dowflinkBps** No content is currently available. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **doWnloadMode** No content is currently available. +- **downloadModeReason** Reason for the download. +- **downloadModeS2c** No content is currently available. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **downloadMofeSrc** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConjectionCount** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **in4ernetConnectionCount** No content is currently available. +- **internetConnectionCnunt** No content is currently available. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **internetConnectionCountdownlinkBps** No content is currently available. +- **isEjcrypted** No content is currently available. +- **isEncryptdd** No content is currently available. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCo}nt** No content is currently available. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefi.edCallerName** No content is currently available. +- **predefinedCallerName** The name of the API Caller. +- **predefinedCalleRName** No content is currently available. +- **rcdnIp** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **romteToCacheServer** No content is currently available. +- **roupeToCacheServer** No content is currently available. +- **routeTnCacheServer** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **uplinkUsegeBps** No content is currently available. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **AddinType** No content is currently available. +- **backgground** No content is currently available. +- **backgro}nd** No content is currently available. +- **backgrou|d** No content is currently available. +- **background** Is the download a background download? +- **BinFileTimestamp** No content is currently available. +- **BinFileVersion** No content is currently available. +- **c`nUrl** No content is currently available. +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorBode** No content is currently available. +- **errorCode** The error code that was returned. +- **expebimentId** No content is currently available. +- **expebimentIderrorCode** No content is currently available. +- **experiientId** No content is currently available. +- **experimenpId** No content is currently available. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **FileId** No content is currently available. +- **FileSize** No content is currently available. +- **isVp|** No content is currently available. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **ksVpn** No content is currently available. +- **LoadBehavior** No content is currently available. +- **LSID** No content is currently available. +- **OfficeArchitecture** No content is currently available. +- **OutlookCrashingAddin** No content is currently available. +- **predefinedCallerName** The name of the API Caller object. +- **ProductCompany** No content is currently available. +- **ProductName** No content is currently available. +- **ProductVersion** No content is currently available. +- **ProgramId** No content is currently available. +- **Provider** No content is currently available. +- **reasonCod%** No content is currently available. +- **reasonCode** The reason for pausing the download. +- **recsonCodesessiolID** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. +- **updateMD** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **b6nUrl** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bacoground** No content is currently available. +- **bileSizeCaller** No content is currently available. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **costFlaos** No content is currently available. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorC/de** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **doErrorCoee** No content is currently available. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimejtId** No content is currently available. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **expeZone** No content is currently available. +- **faleID** No content is currently available. +- **fiheID** No content is currently available. +- **fileID** The ID of the file being downloaded. +- **filePat(** No content is currently available. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groqpID** No content is currently available. +- **groupID** ID for the group. +- **isEncrypted** Indicates whether the download is encrypted. +- **isFpn** No content is currently available. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCall%rName** No content is currently available. +- **predefinedCallerName** Name of the API caller. +- **rimentId** No content is currently available. +- **routeToCacheSedver** No content is currently available. +- **routeToCacheServer** Cache server setting, source, and value. +- **sessionID** The ID for the file download session. +- **sessionIF** No content is currently available. +- **sessmonID** No content is currently available. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **updateYD** No content is currently available. +- **usedMemoryStream** Indicates whether the download used memory streaming. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **eErrorCode** No content is currently available. +- **eErrorCunt** No content is currently available. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **htppStatusCode** No content is currently available. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerTyp,** No content is currently available. +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. +- **jobKD** No content is currently available. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **e:4|SScenario** No content is currently available. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **fdightID** No content is currently available. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **interactiveelatedCVerrorCode** No content is currently available. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenariotate** No content is currently available. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **defeec-9-0S** No content is currently available. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **Ignorec-9-0SsFoec-start** No content is currently available. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateMd** No content is currently available. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateAd** No content is currently available. +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From b5c7241367bd26ec26531fd4b4ef12db09406e20 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 20 Mar 2019 13:28:09 -0700 Subject: [PATCH 078/737] new build 3/20/2019 1:28 PM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 03eb191a9a..4d3aa705fe 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/19/2019 +ms.date: 03/20/2019 --- From 13be4cc9c4be4531a6c87a10d60c03d49bd7fcd4 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 20 Mar 2019 13:28:16 -0700 Subject: [PATCH 079/737] new build 3/20/2019 1:28 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 125 ++++++++++++++- ...ndows-diagnostic-events-and-fields-1809.md | 145 +++++++----------- 4 files changed, 184 insertions(+), 90 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 28d0314670..0f32a74a67 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/19/2019 +ms.date: 03/20/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 16140deb3c..e7b0b0b20f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/19/2019 +ms.date: 03/20/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index cf362ccc46..c3150d4aeb 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/19/2019 +ms.date: 03/20/2019 --- @@ -1582,6 +1582,50 @@ The following fields are available: - **SLICVersion** Returns OS type/version from SLIC table. +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + ### Census.Processor Provides information on several important data points about Processor settings. @@ -1695,6 +1739,50 @@ The following fields are available: - **SpeechInputLanguages** The Speech Input languages installed on the device. +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + ### Census.VM This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. @@ -2027,6 +2115,41 @@ The following fields are available: - **transactionCanceled** Indicates whether the uninstall was cancelled. +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. + +The following fields are available: + +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. + + ## Deployment extensions ### DeploymentTelemetry.Deployment_End diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 1daea9d4d6..680f731738 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/19/2019 +ms.date: 03/20/2019 --- @@ -502,6 +502,7 @@ The following fields are available: - **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. - **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. - **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **I4BD-B1CFi2vuW9de87ed73cb92d3ca4.amd64fre.rs5_2eu5umeZone** No content is currently available. - **InventoryApplicationFile** The count of the number of this particular object type present on this device. - **InventoryDeviceContainer** A count of device container objects in cache. - **InventoryDevicePnp** A count of device Plug and Play objects in cache. @@ -850,7 +851,6 @@ The following fields are available: - **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? - **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? - **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **DriverJlockOverridden** No content is currently available. - **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? - **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? - **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? @@ -2029,7 +2029,6 @@ The following fields are available: - **LocationHistory** Current state of the location history setting. - **LocationHistoryCloudSync** Current state of the location history cloud sync setting. - **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **LocTîÿxV4ocationHistory** No content is currently available. - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. @@ -2139,12 +2138,7 @@ This event sends data about the logical/physical display size, resolution and nu The following fields are available: -- **ÉnternalPrimaryDisplayLogicalDPIY** No content is currently available. -- **IîternalPrimaryDisplayResolutionVertical** No content is currently available. -- **InterjalPrimaryDisplayResolutionHorizontal** No content is currently available. -- **InternalPrimaðyDisplayPhysicalDPIX** No content is currently available. - **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicálDPIX** No content is currently available. - **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. - **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. - **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. @@ -2152,11 +2146,8 @@ The following fields are available: - **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. - **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . - **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **InternalPrimaryDiwplayPhysicalDPIY** No content is currently available. - **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine - **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **OumberofExternalDisplays** No content is currently available. -- **OumberofInternalDisplays** No content is currently available. - **VRAMDedicated** Retrieves the video RAM in MB. - **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. - **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. @@ -2276,7 +2267,6 @@ The following fields are available: - **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. - **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxConsoleSerialOumber** No content is currently available. - **XboxLiveDeviceId** Retrieves the unique device ID of the console. - **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. @@ -2460,6 +2450,7 @@ The following fields are available: - **inventoryId** Device ID used for Compatibility testing - **objectInstanceId** Object identity which is unique within the device scope. - **objectType** Indicates the object type that the event applies to. +- **objectType(objectInstanceId** No content is currently available. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. @@ -2601,6 +2592,41 @@ The following fields are available: - **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. + +The following fields are available: + +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** The number of seconds required to complete the optional content download. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. + + ## Deployment extensions ### DeploymentTelemetry.Deployment_End @@ -2683,12 +2709,14 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: +- **CanAddMsaToMsTelemetby** No content is currently available. - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanCollectWintowsAnalyticsEvents** No content is currently available. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. - **CanReportScenarios** True if we can report scenario completions, false otherwise. @@ -2718,7 +2746,6 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AgentConnectionrrorCsCount** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. @@ -2732,9 +2759,7 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DecodthiDroppedCount** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EnterthiCriticalOverflowDroppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2749,26 +2774,17 @@ The following fields are available: - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastAgentConnectionrrorC** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **Max8ctiveAgentConnectionCount** No content is currently available. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **MaxInUseScenaryoCounter** No content is currently available. -- **omporessedBytesUploaded** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailqreDpopped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **SettthisHttpAttempts** No content is currently available. -- **SettthisHttpFailures** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. -- **TopUploaderrrorCs** No content is currently available. -- **UphoaderErporCount** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. @@ -2776,7 +2792,6 @@ The following fields are available: - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWirhDroppedEvents** No content is currently available. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. @@ -2794,7 +2809,6 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to database failures. - **DbDroppedFullCount** Number of events dropped due to database being full. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **Eve~tStoreResetCounter** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times the event store has been reset. - **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. @@ -3385,23 +3399,24 @@ The following fields are available: - **aiSeqId** The event sequence ID. - **bootId** The system boot ID. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BrightngssVersionViaDDI** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DedicatedVkdeoMemoryB** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. +- **DriverVgrsion** No content is currently available. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9UMDFilePatè** No content is currently available. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPUVendorID** The GPU vendor ID. -- **GPUVgndorID** No content is currently available. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. @@ -3415,22 +3430,23 @@ The following fields are available: - **IsPostAdapter** Is this GPU the POST GPU in the device? - **IsRemovable** TRUE if the adapter supports being disabled or removed. - **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsRendgrDevice** No content is currently available. - **IsSoftwareDevice** Is this a software implementation of the GPU? - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MeasurgEnabled** No content is currently available. - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **N}mVidPnSources** No content is currently available. - **NumVidPnSources** The number of supported display output sources. - **NumVidPnTargets** The number of supported display output targets. +- **NumVidPnTattets** No content is currently available. - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). - **SubSystemID** The subsystem ID. -- **SubVendopID** No content is currently available. - **SubVendorID** The GPU sub vendor ID. +- **TelemetpyEnabled** No content is currently available. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **TenemetryEnabled** No content is currently available. -- **TenInvEvntTrigger** No content is currently available. - **version** The event version. +- **verskon** No content is currently available. - **WDDMVersion** The Windows Display Driver Model version. @@ -3521,14 +3537,17 @@ The following fields are available: - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. +- **DargetAsId** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModNa-e** No content is currently available. - **ModName** Exception module name (e.g. bar.dll). - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. +- **OodTimeStamp** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. @@ -3620,7 +3639,6 @@ The following fields are available: - **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache - **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache - **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **InventoryMiscnfo** No content is currently available. - **Metadata** A count of metadata objects in cache. - **Orphan** A count of orphan file objects in cache. - **Programs** A count of program objects in cache. @@ -3659,6 +3677,7 @@ The following fields are available: - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLbnkFile** No content is currently available. - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. - **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. - **InventoryVersion** The version of the inventory file generating the events. @@ -3761,7 +3780,6 @@ The following fields are available: - **IsActive** Is the device connected, or has it been seen in the last 14 days? - **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. - **IsMachineContainer** Is the container the root device itself? -- **IsMAchineContainer** No content is currently available. - **IsNetworked** Is this a networked device? - **IsPaired** Does the device container require pairing? - **Manufacturer** The manufacturer name for the device container. @@ -3888,10 +3906,10 @@ The following fields are available: - **Description** The description of the device. - **DeviceInterfaceClasses** The device interfaces that this device implements. - **DeviceState** Identifies the current state of the parent (main) device. +- **DevicmState** No content is currently available. - **DriverId** The unique identifier for the installed driver. - **DriverName** The name of the driver image file. - **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriveRPackageStrongNaMe** No content is currently available. - **DriverVerDate** The date associated with the driver installed on the device. - **DriverVerVersion** The version number of the driver installed on the device. - **Enumerator** Identifies the bus that enumerated the device. @@ -3911,6 +3929,7 @@ The following fields are available: - **Service** The name of the device service. - **STACKID** The list of hardware IDs for the stack. - **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilers** No content is currently available. - **UpperFilters** The identifiers of the Upper filters installed for the device. @@ -3968,30 +3987,20 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **Dri6erCompany** No content is currently available. -- **Driv%rPackageStrongName** No content is currently available. -- **Drive2Name** No content is currently available. - **DriverCheckSum** The checksum of the driver file. -- **DriverCompa.y** No content is currently available. - **DriverCompany** The company name that developed the driver. - **DriverInBox** Is the driver included with the operating system? - **DriverIsKernelMode** Is it a kernel mode driver? - **DriverName** The file name of the driver. - **DriverPackageStrongName** The strong name of the driver package -- **DriverSign%d** No content is currently available. - **DriverSigned** The strong name of the driver package - **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. - **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. - **DriverVersion** The version of the driver file. -- **DviverCompany** No content is currently available. -- **I.f** No content is currently available. -- **Imagesize** No content is currently available. - **ImageSize** The size of the driver file. - **Inf** The name of the INF file. -- **Invento2yVersion** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. - **Product** The product name that is included in the driver file. -- **ProductVersio~** No content is currently available. - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. - **WdfVersion** The Windows Driver Framework version. @@ -4503,7 +4512,6 @@ The following fields are available: - **BootStatusPolicy** Identifies the applicable Boot Status Policy. - **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). - **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **Firmw!reResetReasonEmbeddedControllerAdditional** No content is currently available. - **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. - **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. - **FirmwareResetReasonPch** Reason for system reset provided by firmware. @@ -4736,47 +4744,22 @@ This event provides a Windows Internal Library context used for Product and Serv The following fields are available: -- **-149ngContextMessage** No content is currently available. -- **3645entContextName** No content is currently available. -- **379rentContextName** No content is currently available. -- **532rentContextName** No content is currently available. -- **677rentContextName** No content is currently available. -- **8108entContextName** No content is currently available. -- **8251entContextName** No content is currently available. -- **902rentContextName** No content is currently available. -- **9567ngContextMessage** No content is currently available. -- **9717ngContextMessage** No content is currently available. - **callContext** The function where the failure occurred. - **currentContextId** The ID of the current call context where the failure occurred. - **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextMessaon** No content is currently available. - **currentContextName** The name of the current call context where the failure occurred. - **failureCount** The number of failures for this failure ID. - **failureId** The ID of the failure that occurred. - **failureType** The type of the failure that occurred. - **fileName** The file name where the failure occurred. -- **functige** No content is currently available. - **function** The function where the failure occurred. - **hresult** The HResult of the overall activity. - **lineNumber** The line number where the failure occurred. - **message** The message of the failure that occurred. - **module** The module where the failure occurred. -- **ori1-0467ngContextMessage** No content is currently available. -- **ori1-1210ngContextMessage** No content is currently available. -- **ori1143-7ngContextMessage** No content is currently available. -- **ori1-1945ngContextMessage** No content is currently available. -- **ori13s090ngContextMessage** No content is currently available. -- **ori1-4671entContextName** No content is currently available. -- **ori1-5108ngContextMessage** No content is currently available. -- **ori1-5686ngContextMessage** No content is currently available. -- **ori1n:667ngContextMessage** No content is currently available. -- **ori1n8488ngContextMessage** No content is currently available. -- **ori1-s4o5ngContextMessage** No content is currently available. -- **ori808467ngContextMessage** No content is currently available. - **originatingContextId** The ID of the originating call context that resulted in the failure. - **originatingContextMessage** The message of the originating call context that resulted in the failure. - **originatingContextName** The name of the originating call context that resulted in the failure. -- **threa0Id** No content is currently available. - **threadId** The ID of the thread on which the activity is executing. @@ -4854,7 +4837,6 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: -- **Falue** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -4868,12 +4850,8 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: -- **AativityMatchingId** No content is currently available. - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **ActivityMatcjingId** No content is currently available. -- **AllowCachedResul|s** No content is currently available. - **AllowCachedResults** Indicates if the scan allowed using cached results. -- **AllowCachedRmsults** No content is currently available. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. @@ -4897,17 +4875,14 @@ The following fields are available: - **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. - **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. - **DriverSyncPassPerformed** Were drivers scanned this time? -- **DriverSyncPasSPerformed** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedetadataICabUrl** No content is currently available. - **ExtendedMetadataCabUrl** Hostname that is used to download an update. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. - **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. - **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePerimd** No content is currently available. - **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -4915,20 +4890,16 @@ The following fields are available: - **IntentPFNs** Intended application-set metadata for atomic update scenarios. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEna`led** No content is currently available. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConneativityDetected** No content is currently available. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan - **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedetadataISignatures** No content is currently available. -- **NumFailedMetadatabignatures** No content is currently available. - **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. - **Online** Indicates if this was an online scan. - **PausedUpdates** A list of UpdateIds which that currently being paused. @@ -4945,19 +4916,16 @@ The following fields are available: - **ScanDurationInSeconds** The number of seconds a scan took - **ScanEnqueueTime** The number of seconds it took to initialize a scan - **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiaeUrl** No content is currently available. - **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). - **ServiceUrl** The environment URL a device is configured to scan with - **ShippingMobileOperator** The mobile operator that a device shipped on. - **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncTyp%** No content is currently available. - **SyncType** Describes the type of scan the event was - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumetadataISignatures** No content is currently available. -- **TotalNumMetadatabignatures** No content is currently available. - **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **VelatedCV** No content is currently available. - **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5202,6 +5170,7 @@ The following fields are available: - **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. - **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **rApcessFailurePostReboot** No content is currently available. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RepeatFailCount** Indicates whether this specific piece of content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. @@ -6661,6 +6630,7 @@ The following fields are available: - **b9tesFromPeers** No content is currently available. - **background** Is the download a background download? - **bytesFrkmIntPeers** No content is currently available. +- **bytesFroeIntPeers** No content is currently available. - **bytesFromCacheSedver** No content is currently available. - **bytesFromCacheServer** Bytes received from a cache host. - **bytesFromCdN** No content is currently available. @@ -6704,6 +6674,7 @@ The following fields are available: - **gCurMemoryStreamBytes** Current usage for memory streaming. - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. - **groupConjectionCount** No content is currently available. +- **groupConnectaonCount** No content is currently available. - **groupConnectionCount** The total number of connections made to peers in the same group. - **in4ernetConnectionCount** No content is currently available. - **internetConnectionCnunt** No content is currently available. From 422a14b801f78e8ac4c3c49794b36685f0d4cc91 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 21 Mar 2019 08:18:42 -0700 Subject: [PATCH 080/737] new build 3/21/2019 8:18 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 4d3aa705fe..9e412991e5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/20/2019 +ms.date: 03/21/2019 --- From 9f185a1abed0ba5e92b919925c6c5124b3eff260 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 21 Mar 2019 08:18:49 -0700 Subject: [PATCH 081/737] new build 3/21/2019 8:18 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 69 +------------------ 4 files changed, 4 insertions(+), 71 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 0f32a74a67..8bd5d541d3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/20/2019 +ms.date: 03/21/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index e7b0b0b20f..d36fddc9a7 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/20/2019 +ms.date: 03/21/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index c3150d4aeb..cdb533230d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/20/2019 +ms.date: 03/21/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 680f731738..3f57313fe0 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/20/2019 +ms.date: 03/21/2019 --- @@ -4969,7 +4969,6 @@ The following fields are available: - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlocKHashFailures** No content is currently available. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. @@ -4984,14 +4983,11 @@ The following fields are available: - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. - **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. - **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BundleRevisionumber** No content is currently available. - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CallerApplicavionName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCoun|ryCode** No content is currently available. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. @@ -5007,8 +5003,6 @@ The following fields are available: - **EventType** Identifies the type of the event (Child, Bundle, or Driver). - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FFightBuildNumber** No content is currently available. -- **FFightId** No content is currently available. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. @@ -5021,7 +5015,6 @@ The following fields are available: - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBEnaBled** No content is currently available. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." @@ -5033,19 +5026,14 @@ The following fields are available: - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **RegulationReason** The reason that the update is regulated - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RegulitionResult** No content is currently available. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. -- **RevisionNUmber** No content is currently available. -- **Revisionumber** No content is currently available. - **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **ServiceGUid** No content is currently available. - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **SonnectTime** No content is currently available. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. @@ -5139,7 +5127,6 @@ The following fields are available: - **CurrentMobileOperator** The mobile operator to which the device is currently connected. - **DeploymentProviderMode** The mode of operation of the update deployment provider. - **DeviceModel** The device model. -- **DriverPifgBack** No content is currently available. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. - **EventInstanceID** A globally unique identifier for event instance. @@ -5170,7 +5157,6 @@ The following fields are available: - **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. - **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **rApcessFailurePostReboot** No content is currently available. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **RepeatFailCount** Indicates whether this specific piece of content has previously failed. - **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. @@ -5307,11 +5293,8 @@ The following fields are available: - **IntentPFNs** Intended application-set metadata for atomic update scenarios. - **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **RelntedCV** No content is currently available. - **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **umberOfApplicableUpdates** No content is currently available. - **WUDeviceID** The unique device ID controlled by the software distribution client. -- **xHDeviceID** No content is currently available. ### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity @@ -5321,25 +5304,18 @@ Ensures Windows Updates are secure and complete. Event helps to identify whether The following fields are available: - **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **CallerLoglicationName** No content is currently available. - **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. -- **EventSbenario** No content is currently available. - **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. - **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. -- **ExtendefStatusCode** No content is currently available. -- **imeZoScenario** No content is currently available. - **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. - **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. - **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). - **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. - **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RcwMode** No content is currently available. - **RevisionId** The revision ID for a specific piece of content. - **RevisionNumber** The revision number for a specific piece of content. -- **SedviceGuid** No content is currently available. - **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **ServiceGuidEndpointUrl** No content is currently available. - **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. - **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. - **SHA256OfTimestampToken** An encoded string of the timestamp token. @@ -5496,7 +5472,6 @@ This event sends data for the initialize phase of updating Windows via the new U The following fields are available: - **ErrorCode** The error code returned for the current install phase. -- **essionData** No content is currently available. - **FlightId** Unique ID for each flight. - **FlightMetadata** Contains the FlightId and the build being flighted. - **ObjectId** Unique value for each Update Agent mode. @@ -5578,7 +5553,6 @@ The following fields are available: - **Applicable** The count of mitigations that were applicable to the system and scenario. - **Failed** The count of mitigations that failed. - **FlightId** Unique identifier for each flight. -- **Friled** No content is currently available. - **MitigationScenario** The update scenario in which the mitigations were attempted. - **ObjectId** The unique value for each Update Agent mode. - **RelatedCV** The correlation vector value generated from the latest USO scan. @@ -5614,7 +5588,6 @@ The following fields are available: - **Count** The count of applicable OneSettings for the device. - **FlightId** Unique ID for the flight (test instance version). -- **Obj%ctId** No content is currently available. - **ObjectId** The unique value for each Update Agent mode. - **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. - **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. @@ -5927,11 +5900,9 @@ The following fields are available: - **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. - **FieldName** Retrieves the data point. - **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanãeId** No content is currently available. - **InstanceId** Retrieves a unique identifier for each instance of a setup session. - **ReportId** Retrieves the report ID. - **ScenarioId** Retrieves the deployment scenario. -- **value** No content is currently available. - **Value** Retrieves the value associated with the corresponding FieldName. @@ -6024,7 +5995,6 @@ The following fields are available: - **HostOSBuildNumber** The build number of the previous OS. - **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). - **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **o-Ste** No content is currently available. - **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. - **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. - **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. @@ -6066,7 +6036,6 @@ The following fields are available: - **usingBackupQualityAssessment** Relying on backup quality assessment. - **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. - **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionbtring** No content is currently available. - **versionString** Version of the WaaSMedic engine. - **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. @@ -6081,7 +6050,6 @@ The following fields are available: - **BootId** Uint32 identifying the boot number for this device. - **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckPar%meter2** No content is currently available. - **BugCheckParameter1** Uint64 parameter providing additional information. - **BugCheckParameter2** Uint64 parameter providing additional information. - **BugCheckParameter3** Uint64 parameter providing additional information. @@ -6134,14 +6102,10 @@ This event is sent when an installation or update is canceled by a user or the s The following fields are available: - **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AggregatedPackageFullNcmes** No content is currently available. - **AttemptNumber** Number of retry attempts before it was canceled. - **BundleId** The Item Bundle ID. -- **Bundlele** No content is currently available. - **CategoryId** The Item Category ID. -- **Categoryle** No content is currently available. - **ClientAppId** The identity of the app that initiated this operation. -- **ClientApple** No content is currently available. - **HResult** The result code of the last action performed before this operation. - **IsBundle** Is this a bundle? - **IsInteractive** Was this requested by a user? @@ -6150,11 +6114,8 @@ The following fields are available: - **IsRestore** Is this automatically restoring a previously acquired product? - **IsUpdate** Flag indicating if this is an update. - **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **ParentBundlele** No content is currently available. - **PFN** The product family name of the product being installed. -- **Producele** No content is currently available. - **ProductId** The identity of the package or packages being installed. -- **S{stemAttemptNumber** No content is currently available. - **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. - **UserAttemptNumber** The total number of user attempts at installation before it was canceled. - **WUContentId** The Windows Update content ID. @@ -6220,8 +6181,6 @@ This event is sent after the license is acquired when a product is being install The following fields are available: -- **AggregatedPackageFullNaies** No content is currently available. -- **AggregatedpackageFullNames** No content is currently available. - **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. - **AttemptNumber** The total number of attempts to acquire this product. - **CategoryId** The identity of the package or packages being installed. @@ -6232,17 +6191,11 @@ The following fields are available: - **IsMandatory** Is this a mandatory update? - **IsRemediation** Is this repairing a previous installation? - **IsRestore** Is this happening after a device restore? -- **IsUp`ate** No content is currently available. - **IsUpdate** Is this an update? -- **ParentBuneleId** No content is currently available. - **PFN** Product Family Name of the product being installed. -- **Produc|Id** No content is currently available. -- **productId** No content is currently available. - **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNueber** No content is currently available. - **SystemAttemptNumber** The number of attempts by the system to acquire this product. - **UserAttemptNumber** The number of attempts by the user to acquire this product -- **UserCttemptNumber** No content is currently available. - **WUContentId** The Windows Update content ID. @@ -6252,14 +6205,10 @@ This event is sent after an app is downloaded to help keep Windows up-to-date an The following fields are available: -- **AggregatedPackageFullLames** No content is currently available. -- **AggregatedPackageFullNaðes** No content is currently available. - **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AsUpdate** No content is currently available. - **AttemptNumber** Number of retry attempts before it was canceled. - **BundleId** The identity of the Windows Insider build associated with this product. - **CategoryId** The identity of the package or packages being installed. -- **CategoryIf** No content is currently available. - **ClientAppId** The identity of the app that initiated this operation. - **DownloadSize** The total size of the download. - **ExtendedHResult** Any extended HResult error codes. @@ -6274,9 +6223,7 @@ The following fields are available: - **PFN** The Product Family Name of the app being download. - **ProductId** The Store Product ID for the product being installed. - **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNum`er** No content is currently available. - **UserAttemptNumber** The number of attempts by the user to download. -- **UserCttemptNumber** No content is currently available. - **WUContentId** The Windows Update content ID. @@ -6304,7 +6251,6 @@ This event is sent after a product has been installed to help keep Windows up-to The following fields are available: -- **__TlgCÖ__** No content is currently available. - **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. - **AttemptNumber** The number of retry attempts before it was canceled. - **BundleId** The identity of the build associated with this product. @@ -6314,13 +6260,10 @@ The following fields are available: - **HResult** The result code of the last action performed. - **IsBundle** Is this a bundle? - **IsInteractive** Is this an interactive installation? -- **IsInteragtive** No content is currently available. - **IsMandatory** Is this a mandatory installation? - **IsRemediation** Is this repairing a previous installation? - **IsRestore** Is this automatically restoring a previously acquired product? -- **IsRestorg** No content is currently available. - **IsUpdate** Is this an update? -- **KsBundle** No content is currently available. - **ParentBundleId** The product ID of the parent (if this product is part of a bundle). - **PFN** Product Family Name of the product being installed. - **ProductId** The Store Product ID for the product being installed. @@ -6410,13 +6353,9 @@ This event is sent at the end of an app install or update to help keep Windows u The following fields are available: - **CatalogId** The name of the product catalog from which this app was chosen. -- **CatanogId** No content is currently available. -- **CatdlogId** No content is currently available. - **FailedRetry** Indicates whether the installation or update retry was successful. - **HResult** The HResult code of the operation. -- **JResult** No content is currently available. - **PFN** The Package Family Name of the app that is being installed or updated. -- **Producele** No content is currently available. - **ProductId** The product ID of the app that is being updated or installed. @@ -6483,7 +6422,6 @@ The following fields are available: - **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. - **AttemptNumber** The number of retry attempts before it was canceled. - **BundleId** The identity of the build associated with this product. -- **categoryId** No content is currently available. - **CategoryId** The identity of the package or packages being installed. - **ClientAppId** The identity of the app that initiated this operation. - **HResult** The result code of the last action performed before this operation. @@ -6627,10 +6565,8 @@ The following fields are available: - **b6nErrorCounts** No content is currently available. - **b6nIp** No content is currently available. - **b6nUrl** No content is currently available. -- **b9tesFromPeers** No content is currently available. - **background** Is the download a background download? - **bytesFrkmIntPeers** No content is currently available. -- **bytesFroeIntPeers** No content is currently available. - **bytesFromCacheSedver** No content is currently available. - **bytesFromCacheServer** Bytes received from a cache host. - **bytesFromCdN** No content is currently available. @@ -6639,7 +6575,6 @@ The following fields are available: - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntÐeers** No content is currently available. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **byTesFromIntPeers** No content is currently available. - **bytesFromLinkLocalPeers** The number of bytes received from local peers. - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. @@ -6664,7 +6599,6 @@ The following fields are available: - **downloadMode** The download mode used for this file download session. - **doWnloadMode** No content is currently available. - **downloadModeReason** Reason for the download. -- **downloadModeS2c** No content is currently available. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). - **downloadMofeSrc** No content is currently available. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. @@ -6674,7 +6608,6 @@ The following fields are available: - **gCurMemoryStreamBytes** Current usage for memory streaming. - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. - **groupConjectionCount** No content is currently available. -- **groupConnectaonCount** No content is currently available. - **groupConnectionCount** The total number of connections made to peers in the same group. - **in4ernetConnectionCount** No content is currently available. - **internetConnectionCnunt** No content is currently available. From ad191329006ff8e6fd1c5a568c4de32170994864 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 21 Mar 2019 14:41:16 -0700 Subject: [PATCH 082/737] added IME support --- .../faq-wd-app-guard.md | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 0fe3b780be..92683a153d 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -6,9 +6,9 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha +author: qrscharmed ms.author: justinha -ms.date: 11/07/2017 +ms.date: 03/21/2019 --- # Frequently asked questions - Windows Defender Application Guard @@ -58,6 +58,12 @@ Answering frequently asked questions about Windows Defender Application Guard (A |**A:** |WDAG requires proxies to have a symbolic name, not just an IP address. IP-Literal proxy settings such as “192.168.1.4:81” can be annotated as “itproxy:81” or using a record such as “P19216810010” for a proxy with an IP address of 192.168.100.10. This applies to Windows 10 Enterprise edition, 1709 or higher.|
+| | | +|---|----------------------------| +|**Q:** |Which input Method Editors (IME) in 19H1 are not supported?| +|**A:** |The following Input Method Editors (IME) that are introduced in the Windows 10 May 2019 Update are currently not supported in WDAG.
Vietnam Telex keyboard
Vietnam number key-based keyboard
Hindi phonetic keyboard
Bangla phonetic keyboard
Marathi phonetic keyboard
Telugu phonetic keyboard
Tamil phonetic keyboard
Kannada phonetic keyboard
Malayalam phonetic keyboard
Gujarati phonetic keyboard
Odia phonetic keyboard
Punjabi phonetic keyboard| +
+ | | | |---|----------------------------| |**Q:** |I enabled the hardware acceleration policy on my Windows 10 Enterprise, version 1803 deployment. Why are my users still only getting CPU rendering?| From 1108b06dd4838f30b595649fe8181b4ef13325a3 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 21 Mar 2019 14:41:29 -0700 Subject: [PATCH 083/737] added IME support --- .../windows-defender-application-guard/faq-wd-app-guard.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 92683a153d..402f197bcd 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -60,7 +60,7 @@ Answering frequently asked questions about Windows Defender Application Guard (A | | | |---|----------------------------| -|**Q:** |Which input Method Editors (IME) in 19H1 are not supported?| +|**Q:** |Which Input Method Editors (IME) in 19H1 are not supported?| |**A:** |The following Input Method Editors (IME) that are introduced in the Windows 10 May 2019 Update are currently not supported in WDAG.
Vietnam Telex keyboard
Vietnam number key-based keyboard
Hindi phonetic keyboard
Bangla phonetic keyboard
Marathi phonetic keyboard
Telugu phonetic keyboard
Tamil phonetic keyboard
Kannada phonetic keyboard
Malayalam phonetic keyboard
Gujarati phonetic keyboard
Odia phonetic keyboard
Punjabi phonetic keyboard|
From 591d48f5786610a44662272cbabc1770fc444e74 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 21 Mar 2019 14:42:09 -0700 Subject: [PATCH 084/737] edits --- .../windows-defender-application-guard/faq-wd-app-guard.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 402f197bcd..875de5e08e 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -61,7 +61,7 @@ Answering frequently asked questions about Windows Defender Application Guard (A | | | |---|----------------------------| |**Q:** |Which Input Method Editors (IME) in 19H1 are not supported?| -|**A:** |The following Input Method Editors (IME) that are introduced in the Windows 10 May 2019 Update are currently not supported in WDAG.
Vietnam Telex keyboard
Vietnam number key-based keyboard
Hindi phonetic keyboard
Bangla phonetic keyboard
Marathi phonetic keyboard
Telugu phonetic keyboard
Tamil phonetic keyboard
Kannada phonetic keyboard
Malayalam phonetic keyboard
Gujarati phonetic keyboard
Odia phonetic keyboard
Punjabi phonetic keyboard| +|**A:** |The following Input Method Editors (IME) introduced in Windows 10, version 1903 are currently not supported in WDAG.
Vietnam Telex keyboard
Vietnam number key-based keyboard
Hindi phonetic keyboard
Bangla phonetic keyboard
Marathi phonetic keyboard
Telugu phonetic keyboard
Tamil phonetic keyboard
Kannada phonetic keyboard
Malayalam phonetic keyboard
Gujarati phonetic keyboard
Odia phonetic keyboard
Punjabi phonetic keyboard|
| | | From 5c3f4f8881106b8565a0a047e0f87be09eea16bc Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 25 Mar 2019 07:49:34 -0700 Subject: [PATCH 085/737] add ms.date --- windows/configuration/wcd/wcd-cellular.md | 2 +- windows/configuration/wcd/wcd-changes.md | 2 +- windows/configuration/wcd/wcd-deviceupdatecenter.md | 2 +- windows/configuration/wcd/wcd-oobe.md | 2 +- windows/configuration/wcd/wcd-policies.md | 2 +- windows/configuration/wcd/wcd-privacy.md | 2 +- windows/configuration/wcd/wcd-time.md | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/windows/configuration/wcd/wcd-cellular.md b/windows/configuration/wcd/wcd-cellular.md index 1019d87dd8..9c292c9e3d 100644 --- a/windows/configuration/wcd/wcd-cellular.md +++ b/windows/configuration/wcd/wcd-cellular.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 10/02/2018 +ms.date: 05/21/2019 --- # Cellular (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 785a38cf30..571f137000 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 10/02/2018 +ms.date: 05/21/2019 --- # Changes to settings in Windows Configuration Designer diff --git a/windows/configuration/wcd/wcd-deviceupdatecenter.md b/windows/configuration/wcd/wcd-deviceupdatecenter.md index 7417a12104..09f2af4d12 100644 --- a/windows/configuration/wcd/wcd-deviceupdatecenter.md +++ b/windows/configuration/wcd/wcd-deviceupdatecenter.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 09/06/2017 +ms.date: 05/21/2019 --- # DeviceUpdateCenter (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index 6bf1ca1d44..31af250386 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 09/06/2017 +ms.date: 05/21/2019 --- # OOBE (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index 19bc04a0f5..a2098f93b8 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 10/02/2018 +ms.date: 05/21/2019 --- # Policies (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-privacy.md b/windows/configuration/wcd/wcd-privacy.md index 1451f639d8..ad2a699688 100644 --- a/windows/configuration/wcd/wcd-privacy.md +++ b/windows/configuration/wcd/wcd-privacy.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 09/06/2017 +ms.date: 05/21/2019 --- # Privacy (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index 57086da3c3..b81a6d8f1c 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -8,7 +8,7 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 09/06/2017 +ms.date: 05/21/2019 --- # Time From 970f6486da29a20e6e29ee6da832bf36d7e7a744 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 26 Mar 2019 09:02:03 -0700 Subject: [PATCH 086/737] new build 3/26/2019 9:02 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 9e412991e5..a7a06f32ec 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/21/2019 +ms.date: 03/26/2019 --- From 3e550647faf490d4c9490766f145808fea01430b Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 26 Mar 2019 09:02:11 -0700 Subject: [PATCH 087/737] new build 3/26/2019 9:02 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 37 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 15670 ++++++++-------- 4 files changed, 7949 insertions(+), 7762 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 8bd5d541d3..ae09444cb1 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/21/2019 +ms.date: 03/26/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index d36fddc9a7..494bb5b1d5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/21/2019 +ms.date: 03/26/2019 --- @@ -1912,6 +1912,41 @@ The following fields are available: - **pendingDecision** Indicates the cause of reboot, if applicable. +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. + +The following fields are available: + +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. + + ## Diagnostic data events ### TelClientSynthetic.AuthorizationInfo_RuntimeTransition diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index cdb533230d..38b1e69785 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/21/2019 +ms.date: 03/26/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 3f57313fe0..1fdf4dd009 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7759 +1,7911 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -audience: ITPro -ms.date: 03/21/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **I4BD-B1CFi2vuW9de87ed73cb92d3ca4.amd64fre.rs5_2eu5umeZone** No content is currently available. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **action** The change that was invoked on a device inventory object. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **objectType(objectInstanceId** No content is currently available. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -### CbsServicingProvider.CbsSelectableUpdateChangeV2 - -This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. - -The following fields are available: - -- **applicableUpdateState** Indicates the highest applicable state of the optional content. -- **buildVersion** The build version of the package being installed. -- **clientId** The name of the application requesting the optional content change. -- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. -- **downloadtimeInSeconds** The number of seconds required to complete the optional content download. -- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. -- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. -- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. -- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. -- **hrDownloadResult** The return code of the download operation. -- **hrStatusUpdate** The return code of the servicing operation. -- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. -- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. -- **majorVersion** The major version of the package being installed. -- **minorVersion** The minor version of the package being installed. -- **packageArchitecture** The architecture of the package being installed. -- **packageLanguage** The language of the package being installed. -- **packageName** The name of the package being installed. -- **rebootRequired** Indicates whether a reboot is required to complete the operation. -- **revisionVersion** The revision number of the package being installed. -- **stackBuild** The build number of the servicing stack binary performing the installation. -- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. -- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. -- **stackRevision** The revision number of the servicing stack binary performing the installation. -- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. -- **updateStartState** A value indicating the state of the optional content before the operation started. -- **updateTargetState** A value indicating the desired state of the optional content. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetby** No content is currently available. -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanCollectWintowsAnalyticsEvents** No content is currently available. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability - -Event to indicate that the Coordinator CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** Result of CheckApplicability function. -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. -- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. -- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. -- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. -- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. -- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. -- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. -- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. -- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. -- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. -- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). -- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. -- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. -- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **aiSeqId** The event sequence ID. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **BrightngssVersionViaDDI** No content is currently available. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplayAdapterLuid** The display adapter LUID. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DriverVgrsion** No content is currently available. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX9UMDFilePatè** No content is currently available. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **GPUDeviceID** The GPU device ID. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPURevisionID** The GPU revision ID. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsRendgrDevice** No content is currently available. -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MeasurgEnabled** No content is currently available. -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **NumVidPnTattets** No content is currently available. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetpyEnabled** No content is currently available. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **version** The event version. -- **verskon** No content is currently available. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **AppName** The name of the app that has crashed. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **DargetAsId** No content is currently available. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModNa-e** No content is currently available. -- **ModName** Exception module name (e.g. bar.dll). -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **OodTimeStamp** No content is currently available. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLbnkFile** No content is currently available. -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **basedata** No content is currently available. See [basedata](#basedata). -- **BusReportedDescription** The description of the device reported by the bux. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Description** The description of the device. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DevicmState** No content is currently available. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **HWID** A list of hardware IDs for the device. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **ProblemCode** The error code currently returned by the device, if applicable. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKID** The list of hardware IDs for the stack. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilers** No content is currently available. -- **UpperFilters** The identifiers of the Upper filters installed for the device. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - -This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **ImageSize** The size of the driver file. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **hr** The HResult of the operation. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncTyp%** No content is currently available. -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation properties in the form of a bitmask. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **WUDeviceID** The unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". -- **StatusCode** Result code of the event (success, cancellation, failure code HResult) -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageCountTotalPSFX** The total number of PSFX packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **PackageSizePSFX** The size of PSFX packages, in bytes. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **capsuleCount** The number of Sediment Pack capsules. -- **capsuleFailureCount** The number of capsule failures. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. -- **hrEngineResult** Error code from the engine operation. -- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. -- **initSummary** Summary data of the initialization method. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **pluginFailureCount** The number of plugins that have failed. -- **pluginsCount** The number of plugins. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Windows Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **CategoryId** The Item Category ID. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The product family name of the product being installed. -- **ProductId** The identity of the package or packages being installed. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUpdate** Is this an update? -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNumber** The number of attempts by the user to download. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **#dnErrorCounts** No content is currently available. -- **__TlgCVß_** No content is currently available. -- **|anConnectionCount** No content is currently available. -- **}plinkUsageBps** No content is currently available. -- **0redefinedCallerName** No content is currently available. -- **b6nConnectionCount** No content is currently available. -- **b6nErrorCodes** No content is currently available. -- **b6nErrorCounts** No content is currently available. -- **b6nIp** No content is currently available. -- **b6nUrl** No content is currently available. -- **background** Is the download a background download? -- **bytesFrkmIntPeers** No content is currently available. -- **bytesFromCacheSedver** No content is currently available. -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCdN** No content is currently available. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGpoupPeers** No content is currently available. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntÐeers** No content is currently available. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheSarverConnectionCount** No content is currently available. -- **cacheSedverConnectionCount** No content is currently available. -- **cacheServerConndctionCount** No content is currently available. -- **cacheServerConnectionCoujt** No content is currently available. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnSonnectionCount** No content is currently available. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dkwnloadModeSrc** No content is currently available. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **dowflinkBps** No content is currently available. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **doWnloadMode** No content is currently available. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **downloadMofeSrc** No content is currently available. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConjectionCount** No content is currently available. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **in4ernetConnectionCount** No content is currently available. -- **internetConnectionCnunt** No content is currently available. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **internetConnectionCountdownlinkBps** No content is currently available. -- **isEjcrypted** No content is currently available. -- **isEncryptdd** No content is currently available. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCo}nt** No content is currently available. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefi.edCallerName** No content is currently available. -- **predefinedCallerName** The name of the API Caller. -- **predefinedCalleRName** No content is currently available. -- **rcdnIp** No content is currently available. -- **restrictedUpload** Is the upload restricted? -- **romteToCacheServer** No content is currently available. -- **roupeToCacheServer** No content is currently available. -- **routeTnCacheServer** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **uplinkUsegeBps** No content is currently available. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **AddinType** No content is currently available. -- **backgground** No content is currently available. -- **backgro}nd** No content is currently available. -- **backgrou|d** No content is currently available. -- **background** Is the download a background download? -- **BinFileTimestamp** No content is currently available. -- **BinFileVersion** No content is currently available. -- **c`nUrl** No content is currently available. -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorBode** No content is currently available. -- **errorCode** The error code that was returned. -- **expebimentId** No content is currently available. -- **expebimentIderrorCode** No content is currently available. -- **experiientId** No content is currently available. -- **experimenpId** No content is currently available. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **FileId** No content is currently available. -- **FileSize** No content is currently available. -- **isVp|** No content is currently available. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **ksVpn** No content is currently available. -- **LoadBehavior** No content is currently available. -- **LSID** No content is currently available. -- **OfficeArchitecture** No content is currently available. -- **OutlookCrashingAddin** No content is currently available. -- **predefinedCallerName** The name of the API Caller object. -- **ProductCompany** No content is currently available. -- **ProductName** No content is currently available. -- **ProductVersion** No content is currently available. -- **ProgramId** No content is currently available. -- **Provider** No content is currently available. -- **reasonCod%** No content is currently available. -- **reasonCode** The reason for pausing the download. -- **recsonCodesessiolID** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. -- **updateMD** No content is currently available. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **b6nUrl** No content is currently available. -- **background** Indicates whether the download is happening in the background. -- **bacoground** No content is currently available. -- **bileSizeCaller** No content is currently available. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **costFlaos** No content is currently available. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorC/de** No content is currently available. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **doErrorCoee** No content is currently available. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimejtId** No content is currently available. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **expeZone** No content is currently available. -- **faleID** No content is currently available. -- **fiheID** No content is currently available. -- **fileID** The ID of the file being downloaded. -- **filePat(** No content is currently available. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groqpID** No content is currently available. -- **groupID** ID for the group. -- **isEncrypted** Indicates whether the download is encrypted. -- **isFpn** No content is currently available. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCall%rName** No content is currently available. -- **predefinedCallerName** Name of the API caller. -- **rimentId** No content is currently available. -- **routeToCacheSedver** No content is currently available. -- **routeToCacheServer** Cache server setting, source, and value. -- **sessionID** The ID for the file download session. -- **sessionIF** No content is currently available. -- **sessmonID** No content is currently available. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **updateYD** No content is currently available. -- **usedMemoryStream** Indicates whether the download used memory streaming. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **eErrorCode** No content is currently available. -- **eErrorCunt** No content is currently available. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **htppStatusCode** No content is currently available. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerTyp,** No content is currently available. -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. -- **jobKD** No content is currently available. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **e:4|SScenario** No content is currently available. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **fdightID** No content is currently available. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **interactiveelatedCVerrorCode** No content is currently available. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenariotate** No content is currently available. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **defeec-9-0S** No content is currently available. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **Ignorec-9-0SsFoec-start** No content is currently available. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateMd** No content is currently available. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateAd** No content is currently available. -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager - -This event returns data about the Update Reserve Manager, including whether it’s been initialized. - -The following fields are available: - -- **ClientId** The ID of the caller application. -- **Flags** The enumerated flags used to initialize the manager. -- **FlightId** The flight ID of the content the calling client is currently operating with. -- **Offline** Indicates whether or the reserve manager is called during offline operations. -- **PolicyPassed** Indicates whether the machine is able to use reserves. -- **ReturnCode** Return code of the operation. -- **Version** The version of the Update Reserve Manager. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **Disposition** The parameter for the hard reserve adjustment function. -- **Flags** The flags passed to the hard reserve adjustment function. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/26/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasCitDcta** No content is currently available. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **ActivóNetworkConnection** No content is currently available. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageRemove + +This event indicates that the DatasourceDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **CssociatedDriverIsBlocked** No content is currently available. +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **DviverAvailableInbox** No content is currently available. +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **__TlgCV_** No content is currently available. +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPårmanent** No content is currently available. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConn0ctedCapable** No content is currently available. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProt0cted** No content is currently available. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseD4te** No content is currently available. +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **AMEI0** No content is currently available. +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **__TlggV__** No content is currently available. +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **BluetooÕh** No content is currently available. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHissory** No content is currently available. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevisikn** No content is currently available. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarTrpe** No content is currently available. +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDisp|aySizePhysicalY** No content is currently available. +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisp** No content is currently available. +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLaîguages** No content is currently available. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLalguages** No content is currently available. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostacs** No content is currently available. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appiagnostics** No content is currently available. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkT9peImprovement** No content is currently available. +- **InkT9pePersonalization** No content is currently available. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphona** No content is currently available. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsÃustom** No content is currently available. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **UqerDataTasks** No content is currently available. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **invent¹ryId** No content is currently available. +- **inventoryId** Device ID used for Compatibility testing +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **objmctType** No content is currently available. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. + +The following fields are available: + +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** The number of seconds required to complete the optional content download. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAdd** No content is currently available. +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHe.Debeats** No content is currently available. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalationc** No content is currently available. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermicsions** No content is currently available. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEveryt`ingOff** No content is currently available. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. +- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. +- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. +- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **** No content is currently available. +- **艍ጋⰎჄ↶췸̎耀艊ጀ‏艋ጃᰌი↶** No content is currently available. +- **@쯵￿耀蝉ᄀ〉‭ᢤ↱p** No content is currently available. +- **⬰げㅶ漴䬸穕婒㘳㕡䙤乯欸㉂夷** No content is currently available. +- **㉕睐灆㝎剓畷⽧⽶扙全ぐ⽒灥湐湌䈶灦晋砰っ礯䈱㕪** No content is currently available. +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AgentCoNnectionErrorsCount** No content is currently available. +- **āकĒࠨ婆Pက喬↵갸ژāक** No content is currently available. +- **āकĒࠨ婦Tက** No content is currently available. +- **āकĒࠨ媦\က** No content is currently available. +- **āकĒࠨ宆xက僸↵곌׌** No content is currently available. +- **āकĒࠨ汆 嬨↵꼔** No content is currently available. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CriticalOvErflowEntersCounter** No content is currently available. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DecndingDroppedCount** No content is currently available. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **Ēࠨ⳥ࠥ䃀첤↵쁸拠** No content is currently available. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **FullTrigwerBufferDroppedCount** No content is currently available. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidH4BFCodeCount** No content is currently available. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **ȋ耀耭⬀‧早诉耮⬄怛昡设耯⬈** No content is currently available. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidH4BFCode** No content is currently available. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **ⓅЀ쬐↵삔托ā** No content is currently available. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsH4BFAttempts** No content is currently available. +- **SettingsH4BFFailures** No content is currently available. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexH4BFAttempts** No content is currently available. +- **VortexH4BFFailures4xx** No content is currently available. +- **VortexH4BFFailures5xx** No content is currently available. +- **VortexH4BFResponseFailures** No content is currently available. +- **VortexH4BFResponsesWithDroppedEvents** No content is currently available. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWi|hDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **V聯rtexHttpFailures5xx** No content is currently available. +- **अĒࠨⴅ!₀俨↵겈Ѹ** No content is currently available. +- **ြ갌暠聇⭜搽갌暜聈⭠밾갌** No content is currently available. +- **ေ괔暜耼⬰뀲궄暠耽⬴吳괄暜** No content is currently available. +- **̎耀艊ጀ‏艋ጃᰌი↶** No content is currently available. +- **권擘耩⬔ఫ권擔耪⬘〬권擘耫⬜ﰭ권擔耬⬠�� 擝诚** No content is currently available. +- **곔暜聄⭐к괤暠聅⭔퐻갔暜** No content is currently available. +- **갌暜聘⮠偎갌暠聙⮤鑏갌暜聚** No content is currently available. +- **꺨徠耋** No content is currently available. +- **껨徤而⬬퐱길徠耍⬰耲기徤耎⬴㐳** No content is currently available. +- **꼄ቌāकĒࠨ** No content is currently available. +- **쐴궤暠耿⬼찵곴暜** No content is currently available. +- **乭睱祒ㅡ坘牦晩塴唯㥺扱氫㝬㜸⭗偑圶㍡䈲䔯略儹祘㝈圳㡆晪煥瘰䱫琯汗朸⽦ㅵ歶** No content is currently available. +- **佗䱺䑁⽱橒失猶畓湳硖䭏煲愴呌眹卲愹癦慂㝘㡔䰰⭗偡穭䌹㍧偙** No content is currently available. +- **佱塪癒噲歋㤶癉乴煙瑬睷婇睶杭剓摁乄** No content is currently available. +- **倰煹穑䅣䍏楍桧㥡䙪畴䑕橲䕋甯朱㝗硐⭨渶㕶㈯杖䤸穗䡈㥂㥭㑱㝙** No content is currently available. +- **偊〫祰汓汨兄男捇䉧潗塶睥唴㕺瑰煲焰㕸卩兢㉮** No content is currently available. +- **典止歂㔴ぎ䕅穔䜫㥹地䵭ㅔ煘乓假穑䙭䕱㈰晃卉敳祎煙捺灘橙癭䵈伹ぴ硱** No content is currently available. +- **典㙪獬牵汑ㅘ灢㕌㝶湌㑣㙌捯㑷㈳潏祓㥪戳㉺** No content is currently available. +- **剼↵겤״āकĒࠨ婦T** No content is currently available. +- **匈↵걼بāकĒࠨ媦\က咈↵ڐ** No content is currently available. +- **匷硬䭦兔楰㑔汬㑶儷䱈乥猴㕘晱歈瑘游剏㡸㝩倵** No content is currently available. +- **呅穹敖兌橤㈵汴洲䨶潈乺⭎⭕栫** No content is currently available. +- **呣礲晉坩穑〹ひ䝰ぷ噢晘堳刳噒䩈丵畏兑䩨琳⬹佫搱噈** No content is currently available. +- **啧癃獷奆䕤穱啧晬呈䅌琴䴫桗獍噲瘶㕨橰啪楗佧** No content is currently available. +- **噪兙䑯楓㍈奬慰㝋坣睵潕婤瑚䱊昹伵朱敕杰爸睶** No content is currently available. +- **噶甴う歶㍔䈹㝘潳䍈煆⼹挴⬯㝷祄䈯㝃⼯** No content is currently available. +- **坪䙵失慒獗攱猱塘⽰桪⬲摫倶摘塂䄰䰶⽵歐浪瀷** No content is currently available. +- **堿갌暜聊⭨ⱀ갌暠聋⭬** No content is currently available. +- **塩猯䡦癐㝔祤偪捲浖焷㍁浲祹䕡橆橨瑈坰獕教** No content is currently available. +- **失椷䡔㠱呯⽅䕴慴乊匵戱洱番偓㡤䘳㡪奨楈** No content is currently available. +- **夵楲䑣癳摌六䔴㍍⬶獖晘⽅䅅祸㙖橸佣坂㉵ㅚ慇** No content is currently available. +- **慦㥣㥘硸癒䕎䩪㤰䠯祔う敚⬹户䨳啢䩖䡦䘱桎癆** No content is currently available. +- **扊㍩坒潅㝤児堷䩤㉫硩䠶橗杤橚慃杇橙㉡摔娳** No content is currently available. +- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. +- **敬䉶癷潘場㡌䱥⭬䙐⽹楈堵硪牣㑸䵸䥴㝄噣瑒䠸ㅪ** No content is currently available. +- **昡讱⮮耀耰⬀‧晩讛耱⬄怛暥讐耲⬈** No content is currently available. +- **暜耸⬠蠮궴暠耹⬤뀯괤暜耺⬨氰긔暠** No content is currently available. +- **暜职⭰䱂갌暠聍⭴籃갌暜聎⭸聄** No content is currently available. +- **暜聒⮈챈갌暠聓⮌둉갌暜联** No content is currently available. +- **暠耳⬌ﰩ굔暜耴⬐瀪귤暠耵⬔瀫굄暜耶⬘쐬긔暠耷⬜** No content is currently available. +- **暠聏⭼㑅갌暜聐⮀ᑆ갌暠聑⮄** No content is currently available. +- **术硂瑲⽑㥴䱡偭橏䬷礫癪硷㡲⽰䑇游临㙐橪㑯倴⽓剂** No content is currently available. +- **樲㙘䡌㡘坯歎楈⽹ご㥹湭歆㡨婨⬵啊䍶桊塌吶㥈敍汍㕪刲慄** No content is currently available. +- **毆€ 娠↵꺈࿐** No content is currently available. +- **泆  嚔↵곴बā** No content is currently available. +- **湹䩳⭑晹礰婶啊灋䱸晒㉉㑬ひ⭄㑉慙㝲䡦** No content is currently available. +- **潭晰橷睧䌵** No content is currently available. +- **瀯㉪䡏ㅏ⭕楆摡倶㙑愰佚䍪䤳煃奄硭摍嘯煗㍓唸卆** No content is currently available. +- **灋瘸乏煆䬳桱㕙瘸㑘䙸橧㥶䔵橲㕙楗佧吸⭚獏桗** No content is currently available. +- **獇牅歘䉡汸㉂夸乶坁浂偕㤲塅䩸桑と牚穒癲浕** No content is currently available. +- **獭䭏啪漲睌穩⬫入䨱䈸⽁䑇敉儴慣㙹么䥶晋湋朶剹慷** No content is currently available. +- **瑖穒㍤摧癵摆䑧⭧䍏杭䵫敘煰橲煤橲煤橲煤橲煤橲煤橲煤橲煤橲武** No content is currently available. +- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. +- **穇圹塑⽈潘䉘䉒头㡕湲㠵汪圸夸䑬潕杪䙔戴䑌** No content is currently available. +- **穬⼱䍯昫㤹卲儫⬯牎奦㡈㙸ㄯ時㍊佘䱳伵㠫栱䥦⭦慊祘⽂浶** No content is currently available. +- **ࠣ耀耤⬀‧撡豒耥⬄怛擝豇耦⬈귄擘耧⬌鐩** No content is currently available. +- **̎耀艊ጀ‏艋ጃᰌი↶艌錇萍ƒ** No content is currently available. +- **̎耀艊ጀ‏艋ጃᰌი↶艌錇萍ƒ჌↶ 艍ጋⰎ** No content is currently available. +- **耏⬸찴기徤耐⬼됵기** No content is currently available. +- **耑⭀萶기徤耒⭄࠷기徠耓** No content is currently available. +- **耝⬐�� 拱費Ԗ耀耞** No content is currently available. +- **艋ጃᰌი↶艌錇萍ƒ჌↶ 艍ጋⰎჄ↶** No content is currently available. +- **萍ƒ჌↶ 艍ጋⰎჄ↶᝞耀老⬀‧彵** No content is currently available. +- **萍ƒ჌↶ 艍ጋⰎჄ↶큰̎耀艊** No content is currently available. +- **葊갌暠聕⮔ࡋ갌暜聖⮘豌갌暠聗** No content is currently available. +- **㐰愱啬瑬癏䝒乘慲椰㉑眫䱄晶獶䝅䙗䕫㉡** No content is currently available. +- **䄸䵒䝰ㅹ灌癳噚䥍祫䬵礷楗光摹䑑䡢ㅑ䭱獎伱噺獃䕑济浱桱** No content is currently available. +- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. +- **䍭㐰䕩坶㥆慉塲夶煁椫㝖瀱栲硪爯畉乂㑒㝥昷䕺乍併娴橲䭎改睗畃睯** No content is currently available. +- **䍸欳昷偔坊問扨婔䨷㥗桴塲㍄䵹橥癉嘷䵊噲湥** No content is currently available. +- **䠷坸⽦䄯⽣晵ㄳ卂楖づ睧䤵椹穴䝊潩硍䩢䵎橫㍸牨** No content is currently available. +- **䨵浤汗位㑗䕶㝸䥮敡潱倱偑煥塪晢** No content is currently available. +- **䰶굔暠聁⭄砷곤暜聂⭈8궄暠** No content is currently available. +- **䱥⭫䙐晹楈䠵硨牣㑷噏挶䍈伹桪湣㑸呵㠴乘攸浌䡥穆䱶㕧瑘捷㉌伶穆䡦㕩橶捸砳甴㑚堸** No content is currently available. +- **䱲㝏危㡨呥卐䩯⭒祐汮潧䩑ㅷ歈偤㉱灕⬲穏公** No content is currently available. +- **䴶㑊啥䕪乶汊摉㥐焲楂䜹洳敡⬫灍⭒佦呮敮婪〷朵癹呧煡㙤䤫浨瘹** No content is currently available. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. +- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. +- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. +- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. +- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. +- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. +- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. +- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. +- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. +- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. +- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). +- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. +- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. +- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterT}peValue** No content is currently available. +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **AdapterTyreValue** No content is currently available. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **ComputePreelptionLevel** No content is currently available. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSy{temMemoryB** No content is currently available. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DisplayAdap|erLuid** No content is currently available. +- **DisplayAdapderLuid** No content is currently available. +- **DisplayAdapterLuid** The display adapter LUID. +- **Driver^ersion** No content is currently available. +- **DriverDat** No content is currently available. +- **DriverDate** The date of the display driver. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX1rUMDFilePath** No content is currently available. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **DX9UMDFileXath** No content is currently available. +- **GPUDeviceID** The GPU device ID. +- **GPUDexiceID** No content is currently available. +- **GPUPreelptionLevel** No content is currently available. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPUPzeemptionLevel** No content is currently available. +- **GPURevisionID** The GPU revision ID. +- **GPURexisionID** No content is currently available. +- **GPUVendorID** The GPU vendor ID. +- **InterfaceId** The GPU interface ID. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsDisplayDexice** No content is currently available. +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridDiwcrete** No content is currently available. +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiiacastSupported** No content is currently available. +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOSupport%d** No content is currently available. +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiiacastSupported** No content is currently available. +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRemovableǑBrightnessVersionViaDDIǩ WDDMVersionॠȠDisplayAdapterLuidǷDisplayAdapterLuidȄGPUPreempti** No content is currently available. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsRenderDexice** No content is currently available. +- **IsSoftwareDevace** No content is currently available. +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **IsSoftwareDexice** No content is currently available. +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **Meas}reEnabled** No content is currently available. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MnterfaceId** No content is currently available. +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumVidPnSou** No content is currently available. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemory@** No content is currently available. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSystemID** The subsystem ID. +- **SubVendorID** The GPU sub vendor ID. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TelnveEvntTrigger** No content is currently available. +- **version** The event version. +- **verwion** No content is currently available. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **AppName** The name of the app that has crashed. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **AsFatal** No content is currently available. +- **Exceptio** No content is currently available. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModTimestamp** No content is currently available. +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **ode** No content is currently available. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **targetAppVer** No content is currently available. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **IentoryMiscellaneousOfficeAddIn** No content is currently available. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneiscellaneousOfficeInsights** No content is currently available. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLincFile** No content is currently available. +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsipackageCode** No content is currently available. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSversionAtInstallTime** No content is currently available. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **type** No content is currently available. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **]pperClassFilters** No content is currently available. +- **basedata** No content is currently available. See [basedata](#basedata). +- **BusReportedDescraption** No content is currently available. +- **BusReportedDescription** The description of the device reported by the bux. +- **BusReptrtedDescription** No content is currently available. +- **Clas{Guid** No content is currently available. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **Con|ainerId** No content is currently available. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Descriptaon** No content is currently available. +- **Description** The description of the device. +- **DeviceDriverFlightId** No content is currently available. +- **DeviceExtDriversFlightIds** No content is currently available. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **DriverAd** No content is currently available. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverVer^ersion** No content is currently available. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **FirstInstallDate** No content is currently available. +- **H_ID** No content is currently available. +- **HWID** A list of hardware IDs for the device. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallDate** No content is currently available. +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **Manufacturer** The manufacturer of the device. +- **MatchangID** No content is currently available. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Modeh** No content is currently available. +- **Model** Identifies the model of the device. +- **ParentId** The Device Instance ID of the parent of the device. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **ProblmmCode** No content is currently available. +- **Provider** Identifies the device provider. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. +- **UpxerClassFilters** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DrivdrCompany** No content is currently available. +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **ImageSize** The size of the driver file. +- **ImageSmze** No content is currently available. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. +- **WdfVers-on** No content is currently available. +- **WdfVersÿon** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Valóe** No content is currently available. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BootAttemptCount** No content is currently available. +- **BootStatusPolicy** No content is currently available. +- **BootType** No content is currently available. +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. +- **FirmwareResetReasonEmbeddedController** No content is currently available. +- **FirmwareResetReasonEmbeddedControllerAdditional** No content is currently available. +- **FirmwareResetReasonPch** No content is currently available. +- **FirmwareResetReasonPchAdditional** No content is currently available. +- **FirmwareResetReasonSupplied** No content is currently available. +- **LastBootSucceeded** No content is currently available. +- **LastShutdownSucceeded** No content is currently available. +- **MeasuredLaunchResume** No content is currently available. +- **MenuPolicy** No content is currently available. +- **RecoveryEnabled** No content is currently available. +- **UserInputTime** No content is currently available. + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **Boo|ApplicationId** No content is currently available. +- **BootApplicataonId** No content is currently available. +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **br** No content is currently available. +- **hr** The HResult of the operation. +- **IsLoggingE~abled** No content is currently available. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverGxclusionPolicy** No content is currently available. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePause9-8iod** No content is currently available. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **I#Version** No content is currently available. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBDualScaninabled** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **IsWUfBinabled** No content is currently available. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEval}ated** No content is currently available. +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePause9-8iod** No content is currently available. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **S}ncType** No content is currently available. +- **ScanDuratioInSeconds** No content is currently available. +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanPrps** No content is currently available. +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumMetadataSignatureM** No content is currently available. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **aundleBy1esDownl?aded** No content is currently available. +- **B1ndleRepeatFailCount** No content is currently available. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **Cbs5ethod** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenarao** No content is currently available. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **flightBuildNumber** No content is currently available. +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HostName** The hostname URL the content is downloading from. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWVfBDualScanEnabled** No content is currently available. +- **IsWVfBEnabled** No content is currently available. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **PackageFullName** The package name of the content. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **RegulationReason** The reason that the update is regulated +- **RegulationReóult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RelqtedCV** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **TotalEx8ectedBydes** No content is currently available. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **UsecDO** No content is currently available. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **YsWUfBEnabled** No content is currently available. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **Targeti~gVersion** No content is currently available. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfA0plicableUpdates** No content is currently available. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **WUDeviceID** The unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". +- **StatusCode** Result code of the event (success, cancellation, failure code HResult) +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCCoegoriesSkipped** No content is currently available. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestSsCoe** No content is currently available. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **capsuleCount** The number of Sediment Pack capsules. +- **capsuleFailureCount** The number of capsule failures. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. +- **hrEngineResult** Error code from the engine operation. +- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. +- **initSummary** Summary data of the initialization method. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **pluginFailureCount** The number of plugins that have failed. +- **pluginsCount** The number of plugins. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **CategoryId** The Item Category ID. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The product family name of the product being installed. +- **ProductId** The identity of the package or packages being installed. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUpdate** Is this an update? +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNumber** The number of attempts by the user to download. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AsOnline** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheServerBonnectionCount** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dnErrorCounts** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gdnConnectionCount** No content is currently available. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConnectionCo** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefinedCallerName** The name of the API Caller. +- **restrictedU`load** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCode** The reason for pausing the download. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **ActiveNetworkConnection** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **fileID** The ID of the file being downloaded. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groupID** ID for the group. +- **IsBootCritical** No content is currently available. +- **isEncrypted** Indicates whether the download is encrypted. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **routeToCacheServer** Cache server setting, source, and value. +- **SdbEntries** No content is currently available. +- **sessionID** The ID for the file download session. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** Indicates whether the download used memory streaming. +- **WuDriverCoverage** No content is currently available. +- **WuDriverUpdateId** No content is currently available. +- **WuPopulatedFromId** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **configuredPoliciescsunt** No content is currently available. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From a9b48ce01f125b4d7bf26d5653a34122d743f54b Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 27 Mar 2019 09:03:25 -0700 Subject: [PATCH 088/737] new build 3/27/2019 9:03 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index a7a06f32ec..6d5138182b 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/26/2019 +ms.date: 03/27/2019 --- From 666dcc2f9c959cfcae120ee93a2f71d1b7260c18 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 27 Mar 2019 09:03:35 -0700 Subject: [PATCH 089/737] new build 3/27/2019 9:03 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 15678 ++++++++-------- 4 files changed, 7770 insertions(+), 7914 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index ae09444cb1..1a4810d670 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/26/2019 +ms.date: 03/27/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 494bb5b1d5..0ca537440b 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/26/2019 +ms.date: 03/27/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 38b1e69785..a2d892faf3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/26/2019 +ms.date: 03/27/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 1fdf4dd009..8540ded6cf 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -1,7911 +1,7767 @@ ---- -description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) -keywords: privacy, telemetry -ms.prod: w10 -ms.mktglfcycl: manage -ms.sitesec: library -ms.pagetype: security -localizationpriority: high -author: brianlic-msft -ms.author: brianlic -manager: dansimp -ms.collection: M365-security-compliance -ms.topic: article -audience: ITPro -ms.date: 03/26/2019 ---- - - -# Windows 10, version 1809 basic level Windows diagnostic events and fields - - **Applies to** - -- Windows 10, version 1809 - - -The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. - -The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. - -Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. - -You can learn more about Windows functional and diagnostic data through these articles: - - -- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) -- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) -- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) -- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) -- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - - - -## Account trace logging provider events - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General - -This event provides information about application properties to indicate the successful execution. - -The following fields are available: - -- **AppMode** Indicates the mode the app is being currently run around privileges. -- **ExitCode** Indicates the exit code of the app. -- **Help** Indicates if the app needs to be launched in the help mode. -- **ParseError** Indicates if there was a parse error during the execution. -- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. -- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. -- **TestMode** Indicates whether the app is being run in test mode. - - -### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount - -This event provides information about the properties of user accounts in the Administrator group. - -The following fields are available: - -- **Internal** Indicates the internal property associated with the count group. -- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. -- **Result** The HResult error. - - -## AppLocker events - -### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically - -Automatically closed activity for start/stop operations that aren't explicitly closed. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddParams - -Parameters passed to Add function of the AppLockerCSP Node. - -The following fields are available: - -- **child** The child URI of the node to add. -- **uri** URI of the node relative to %SYSTEM32%/AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.AddStart - -Start of "Add" Operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.AddStop - -End of "Add" Operation for AppLockerCSP Node. - -The following fields are available: - -- **hr** The HRESULT returned by Add function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback - -Result of the 'Rollback' operation in AppLockerCSP. - -The following fields are available: - -- **oldId** Previous id for the CSP transaction. -- **txId** Current id for the CSP transaction. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearParams - -Parameters passed to the "Clear" operation for AppLockerCSP. - -The following fields are available: - -- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStart - -Start of the "Clear" operation for the AppLockerCSP Node. - - - -### Microsoft.Windows.Security.AppLockerCSP.ClearStop - -End of the "Clear" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT reported at the end of the 'Clear' function. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart - -Start of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **NotifyState** State sent by ConfigManager to AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop - -End of the "ConfigManagerNotification" operation for AppLockerCSP. - -The following fields are available: - -- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams - -Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. - -The following fields are available: - -- **NodeId** NodeId passed to CreateNodeInstance. -- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. -- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart - -Start of the "CreateNodeInstance" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop - -End of the "CreateNodeInstance" operation for the AppLockerCSP node - -The following fields are available: - -- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams - -Parameters passed to the DeleteChild function of the AppLockerCSP node. - -The following fields are available: - -- **child** The child URI of the node to delete. -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart - -Start of the "DeleteChild" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop - -End of the "DeleteChild" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies - -Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams - -Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. - -The following fields are available: - -- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart - -Start of the "GetChildNodeNames" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop - -End of the "GetChildNodeNames" operation for the AppLockerCSP node. - -The following fields are available: - -- **child[0]** If function succeeded, the first child's name, else "NA". -- **count** If function succeeded, the number of child node names returned by the function, else 0. -- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.GetLatestId - -The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). - -The following fields are available: - -- **dirId** The latest directory identifier found by GetLatestId. -- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. - - -### Microsoft.Windows.Security.AppLockerCSP.HResultException - -HRESULT thrown by any arbitrary function in AppLockerCSP. - -The following fields are available: - -- **file** File in the OS code base in which the exception occurs. -- **function** Function in the OS code base in which the exception occurs. -- **hr** HRESULT that is reported. -- **line** Line in the file in the OS code base in which the exception occurs. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueParams - -Parameters passed to the SetValue function of the AppLockerCSP node. - -The following fields are available: - -- **dataLength** Length of the value to set. -- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStart - -Start of the "SetValue" operation for the AppLockerCSP node. - - - -### Microsoft.Windows.Security.AppLockerCSP.SetValueStop - -End of the "SetValue" operation for the AppLockerCSP node. - -The following fields are available: - -- **hr** HRESULT returned by the SetValue function in AppLockerCSP. - - -### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies - -EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. - -The following fields are available: - -- **uri** URI for node relative to %SYSTEM32%/AppLocker. - - -## Appraiser events - -### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount - -This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. - -The following fields are available: - -- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. -- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. -- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. -- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. -- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. -- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. -- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. -- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. -- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. -- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. -- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. -- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. -- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. -- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. -- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. -- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. -- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. -- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. -- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. -- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. -- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. -- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. -- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. -- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. -- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. -- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. -- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. -- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. -- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. -- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. -- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. -- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **InventoryApplicationFile** The count of the number of this particular object type present on this device. -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryLanguagePack** The count of the number of this particular object type present on this device. -- **InventoryMediaCenter** The count of the number of this particular object type present on this device. -- **InventorySystemBios** The count of the number of this particular object type present on this device. -- **InventorySystemMachine** The count of the number of this particular object type present on this device. -- **InventorySystemProcessor** The count of the number of this particular object type present on this device. -- **InventoryTest** The count of the number of this particular object type present on this device. -- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. -- **PCFP** The count of the number of this particular object type present on this device. -- **SystemMemory** The count of the number of this particular object type present on this device. -- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. -- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. -- **SystemProcessorNx** The total number of objects of this type present on this device. -- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. -- **SystemProcessorSse2** The total number of objects of this type present on this device. -- **SystemTouch** The count of the number of this particular object type present on this device. -- **SystemWim** The total number of objects of this type present on this device. -- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. -- **SystemWlan** The total number of objects of this type present on this device. -- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1** The count of the number of this particular object type present on this device. -- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. -- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. -- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. -- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5** The count of the number of this particular object type present on this device. -- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. -- **Wmdrm_TH1** The count of the number of this particular object type present on this device. -- **Wmdrm_TH2** The count of the number of this particular object type present on this device. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd - -Represents the basic metadata about specific application files installed on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompatModelIndex** The compatibility prediction for this file. -- **HasCitData** Indicates whether the file is present in CIT data. -- **HasCitDcta** No content is currently available. -- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. -- **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAttempted** This will always be an empty string when sending telemetry. -- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove - -This event indicates that the DatasourceApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync - -This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd - -This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **ActivóNetworkConnection** No content is currently available. -- **AppraiserVersion** The version of the appraiser file generating the events. -- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. -- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. -- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string -- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. -- **IsBootCritical** Indicates whether the device boot is critical. -- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. -- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. -- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. -- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove - -This event indicates that the DatasourceDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync - -This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd - -This event sends compatibility database data about driver packages to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageRemove - -This event indicates that the DatasourceDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync - -This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd - -This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove - -This event indicates that the DataSourceMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync - -This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd - -This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove - -This event indicates that the DataSourceMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync - -This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd - -This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove - -This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd - -This event sends compatibility database information about the BIOS to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove - -This event indicates that the DatasourceSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync - -This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd - -This event sends compatibility decision data about a file to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file that is generating the events. -- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. -- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. -- **DisplayGenericMessage** Will be a generic message be shown for this file? -- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. -- **HardBlock** This file is blocked in the SDB. -- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? -- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? -- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? -- **NeedsDismissAction** Will the file cause an action that can be dimissed? -- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. -- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? -- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. -- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. -- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, -- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. -- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. -- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. -- **SoftBlock** The file is softblocked in the SDB and has a warning. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove - -This event indicates Indicates that the DecisionApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync - -This event indicates that a new set of DecisionApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd - -This event sends compatibility decision data about a PNP device to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? -- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? -- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? -- **BlockingDevice** Is this PNP device blocking upgrade? -- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? -- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? -- **CssociatedDriverIsBlocked** No content is currently available. -- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? -- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. -- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? -- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? -- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? -- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? -- **DviverAvailableInbox** No content is currently available. -- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? -- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? -- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? -- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove - -This event indicates that the DecisionDevicePnp object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync - -The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd - -This event sends decision data about driver package compatibility to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. -- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? -- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? -- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? -- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. -- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? -- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove - -This event indicates that the DecisionDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync - -This event indicates that a new set of DecisionDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd - -This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the appraiser file generating the events. -- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessage** Will a generic message be shown for this block? -- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? -- **SdbBlockUpgrade** Is a matching info block blocking upgrade? -- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? -- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove - -This event indicates that the DecisionMatchingInfoBlock object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync - -This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd - -This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. -- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove - -This event Indicates that the DecisionMatchingInfoPassive object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync - -This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd - -This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? -- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? -- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? -- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove - -This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync - -This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd - -This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? -- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? -- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? -- **MediaCenterInUse** Is Windows Media Center actively being used? -- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? -- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove - -This event indicates that the DecisionMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync - -This event indicates that a new set of DecisionMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd - -This event sends compatibility decision data about the BIOS to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device blocked from upgrade due to a BIOS block? -- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. -- **HasBiosBlock** Does the device have a BIOS block? - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove - -This event indicates that the DecisionSystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync - -This event indicates that a new set of DecisionSystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.GatedRegChange - -This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. - -The following fields are available: - -- **NewData** The data in the registry value after the scan completed. -- **OldData** The previous data in the registry value before the scan ran. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **RegKey** The registry key name for which a result is being sent. -- **RegValue** The registry value for which a result is being sent. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd - -This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **AvDisplayName** If the app is an antivirus app, this is its display name. -- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. -- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. -- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. -- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. -- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. -- **CompanyName** The company name of the vendor who developed this file. -- **FileId** A hash that uniquely identifies a file. -- **FileVersion** The File version field from the file metadata under Properties -> Details. -- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. -- **IsAv** Indicates whether the file an antivirus reporting EXE. -- **LinkDate** The date and time that this file was linked on. -- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. -- **Name** The name of the file that was inventoried. -- **ProductName** The Product name field from the file metadata under Properties -> Details. -- **ProductVersion** The Product version field from the file metadata under Properties -> Details. -- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. -- **Size** The size of the file (in hexadecimal bytes). - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove - -This event indicates that the InventoryApplicationFile object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync - -This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd - -This event sends data about the number of language packs installed on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **HasLanguagePack** Indicates whether this device has 2 or more language packs. -- **LanguagePackCount** The number of language packs are installed. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove - -This event indicates that the InventoryLanguagePack object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync - -This event indicates that a new set of InventoryLanguagePackAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd - -This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **EverLaunched** Has Windows Media Center ever been launched? -- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? -- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? -- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? -- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? -- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? -- **IsSupported** Does the running OS support Windows Media Center? - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove - -This event indicates that the InventoryMediaCenter object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync - -This event indicates that a new set of InventoryMediaCenterAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd - -This event sends basic metadata about the BIOS to determine whether it has a compatibility block. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **biosDate** The release date of the BIOS in UTC format. -- **BiosDate** The release date of the BIOS in UTC format. -- **biosName** The name field from Win32_BIOS. -- **BiosName** The name field from Win32_BIOS. -- **manufacturer** The manufacturer field from Win32_ComputerSystem. -- **Manufacturer** The manufacturer field from Win32_ComputerSystem. -- **model** The model field from Win32_ComputerSystem. -- **Model** The model field from Win32_ComputerSystem. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove - -This event indicates that the InventorySystemBios object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync - -This event indicates that a new set of InventorySystemBiosAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd - -This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BootCritical** Is the driver package marked as boot critical? -- **Build** The build value from the driver package. -- **CatalogFile** The name of the catalog file within the driver package. -- **Class** The device class from the driver package. -- **ClassGuid** The device class unique ID from the driver package. -- **Date** The date from the driver package. -- **Inbox** Is the driver package of a driver that is included with Windows? -- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. -- **Provider** The provider of the driver package. -- **PublishedName** The name of the INF file after it was renamed. -- **Revision** The revision of the driver package. -- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. -- **VersionMajor** The major version of the driver package. -- **VersionMinor** The minor version of the driver package. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove - -This event indicates that the InventoryUplevelDriverPackage object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync - -This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.RunContext - -This event indicates what should be expected in the data payload. - -The following fields are available: - -- **__TlgCV_** No content is currently available. -- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **CensusId** A unique hardware identifier. -- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. -- **Time** The client time of the event. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryAdd - -This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the device from upgrade due to memory restrictions? -- **MemoryRequirementViolated** Was a memory requirement violated? -- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). -- **ram** The amount of memory on the device. -- **ramKB** The amount of memory (in KB). -- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). -- **virtualKB** The amount of virtual memory (in KB). - - -### Microsoft.Windows.Appraiser.General.SystemMemoryRemove - -This event that the SystemMemory object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync - -This event indicates that a new set of SystemMemoryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd - -This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **CompareExchange128Support** Does the CPU support CompareExchange128? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove - -This event indicates that the SystemProcessorCompareExchange object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync - -This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd - -This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **LahfSahfSupport** Does the CPU support LAHF/SAHF? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove - -This event indicates that the SystemProcessorLahfSahf object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync - -This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd - -This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. -- **NXProcessorSupport** Does the processor support NX? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove - -This event indicates that the SystemProcessorNx object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync - -This event indicates that a new set of SystemProcessorNxAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd - -This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **PrefetchWSupport** Does the processor support PrefetchW? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove - -This event indicates that the SystemProcessorPrefetchW object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync - -This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add - -This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked due to the processor? -- **SSE2ProcessorSupport** Does the processor support SSE2? - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove - -This event indicates that the SystemProcessorSse2 object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync - -This event indicates that a new set of SystemProcessorSse2Add events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchAdd - -This event sends data indicating whether the system supports touch, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? -- **MaximumTouches** The maximum number of touch points supported by the device hardware. - - -### Microsoft.Windows.Appraiser.General.SystemTouchRemove - -This event indicates that the SystemTouch object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemTouchStartSync - -This event indicates that a new set of SystemTouchAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimAdd - -This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **IsWimBoot** Is the current operating system running from a compressed WIM file? -- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. - - -### Microsoft.Windows.Appraiser.General.SystemWimRemove - -This event indicates that the SystemWim object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWimStartSync - -This event indicates that a new set of SystemWimAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd - -This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. -- **WindowsNotActivatedDecision** Is the current operating system activated? - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove - -This event indicates that the SystemWindowsActivationStatus object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync - -This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanAdd - -This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? -- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? -- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? -- **WlanExists** Does the device support WLAN at all? -- **WlanModulePresent** Are any WLAN modules present? -- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? - - -### Microsoft.Windows.Appraiser.General.SystemWlanRemove - -This event indicates that the SystemWlan object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.SystemWlanStartSync - -This event indicates that a new set of SystemWlanAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.TelemetryRunHealth - -This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. - -The following fields are available: - -- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. -- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. -- **AppraiserProcess** The name of the process that launched Appraiser. -- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. -- **AuxFinal** Obsolete, always set to false. -- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. -- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. -- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. -- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. -- **InboxDataVersion** The original version of the data files before retrieving any newer version. -- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. -- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. -- **PCFP** An ID for the system calculated by hashing hardware identifiers. -- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. -- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. -- **RunDate** The date that the telemetry run was stated, expressed as a filetime. -- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. -- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. -- **RunResult** The hresult of the Appraiser telemetry run. -- **ScheduledUploadDay** The day scheduled for the upload. -- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. -- **StoreHandleIsNotNull** Obsolete, always set to false -- **TelementrySent** Indicates if telemetry was successfully sent. -- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. -- **Time** The client time of the event. -- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. -- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. - - -### Microsoft.Windows.Appraiser.General.WmdrmAdd - -This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. -- **BlockingApplication** Same as NeedsDismissAction. -- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. -- **WmdrmApiResult** Raw value of the API used to gather DRM state. -- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. -- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. -- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. -- **WmdrmNonPårmanent** No content is currently available. -- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. -- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. - - -### Microsoft.Windows.Appraiser.General.WmdrmRemove - -This event indicates that the Wmdrm object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -### Microsoft.Windows.Appraiser.General.WmdrmStartSync - -This event indicates that a new set of WmdrmAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AppraiserVersion** The version of the Appraiser file that is generating the events. - - -## Census events - -### Census.App - -Provides information on IE and Census versions running on the device - -The following fields are available: - -- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. -- **AppraiserErrorCode** The error code of the last Appraiser run. -- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. -- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. -- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. -- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. -- **AppraiserTaskExitCode** The Appraiser task exist code. -- **AppraiserTaskLastRun** The last runtime for the Appraiser task. -- **CensusVersion** The version of Census that generated the current data for this device. -- **IEVersion** The version of Internet Explorer that is running on the device. - - -### Census.Battery - -This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. - -The following fields are available: - -- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. -- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. -- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. -- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. -- **IsAlwaysOnAlwaysConn0ctedCapable** No content is currently available. -- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. - - -### Census.Camera - -This event sends data about the resolution of cameras on the device, to help keep Windows up to date. - -The following fields are available: - -- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. -- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. - - -### Census.Enterprise - -This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. - -The following fields are available: - -- **AADDeviceId** Azure Active Directory device ID. -- **AzureOSIDPresent** Represents the field used to identify an Azure machine. -- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. -- **CDJType** Represents the type of cloud domain joined for the machine. -- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. -- **ContainerType** The type of container, such as process or virtual machine hosted. -- **EnrollmentType** Defines the type of MDM enrollment on the device. -- **HashedDomain** The hashed representation of the user domain used for login. -- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false -- **IsDERequirementMet** Represents if the device can do device encryption. -- **IsDeviceProt0cted** No content is currently available. -- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption -- **IsDomainJoined** Indicates whether a machine is joined to a domain. -- **IsEDPEnabled** Represents if Enterprise data protected on the device. -- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. -- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID -- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. -- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. -- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier - - -### Census.Firmware - -This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. - -The following fields are available: - -- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). -- **FirmwareReleaseD4te** No content is currently available. -- **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. -- **FirmwareVersion** Represents the version of the current firmware. - - -### Census.Flighting - -This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. - -The following fields are available: - -- **DeviceSampleRate** The telemetry sample rate assigned to the device. -- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **FlightIds** A list of the different Windows Insider builds on this device. -- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. -- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. -- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. -- **SSRK** Retrieves the mobile targeting settings. - - -### Census.Hardware - -This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. - -The following fields are available: - -- **ActiveMicCount** The number of active microphones attached to the device. -- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. -- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. -- **D3DMaxFeatureLevel** Supported Direct3D version. -- **DeviceColor** Indicates a color of the device. -- **DeviceForm** Indicates the form as per the device classification. -- **DeviceName** The device name that is set by the user. -- **DigitizerSupport** Is a digitizer supported? -- **DUID** The device unique ID. -- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). -- **InventoryId** The device ID used for compatibility testing. -- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). -- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) -- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. -- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. -- **OEMModelBaseBoard** The baseboard model used by the OEM. -- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. -- **OEMModelName** The device model name. -- **OEMModelNumber** The device model number. -- **OEMModelSKU** The device edition that is defined by the manufacturer. -- **OEMModelSystemFamily** The system family set on the device by an OEM. -- **OEMModelSystemVersion** The system model version set on the device by the OEM. -- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. -- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. -- **PhoneManufacturer** The friendly name of the phone manufacturer. -- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. -- **SoCName** The firmware manufacturer of the device. -- **StudyID** Used to identify retail and non-retail device. -- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. -- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. -- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. -- **TPMManufacturerId** The ID of the TPM manufacturer. -- **TPMManufacturerVersion** The version of the TPM manufacturer. -- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. -- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? - - -### Census.Memory - -This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. - -The following fields are available: - -- **TotalPhysicalRAM** Represents the physical memory (in MB). -- **TotalVisibleMemory** Represents the memory that is not reserved by the system. - - -### Census.Network - -This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. - -The following fields are available: - -- **AMEI0** No content is currently available. -- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. -- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. -- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. -- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. -- **NetworkAdapterGUID** The GUID of the primary network adapter. -- **NetworkCost** Represents the network cost associated with a connection. -- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. -- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. - - -### Census.OS - -This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. - -The following fields are available: - -- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. -- **AssignedAccessStatus** Kiosk configuration mode. -- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. -- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. -- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time -- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. -- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). -- **InstallLanguage** The first language installed on the user machine. -- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. -- **IsEduData** Returns Boolean if the education data policy is enabled. -- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go -- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. -- **LanguagePacks** The list of language packages installed on the device. -- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. -- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. -- **OSEdition** Retrieves the version of the current OS. -- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc -- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). -- **OSSKU** Retrieves the Friendly Name of OS Edition. -- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. -- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. -- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. -- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. -- **ProductActivationResult** Returns Boolean if the OS Activation was successful. -- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. -- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. -- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. -- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. -- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. -- **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedPCMode** Returns Boolean for education devices used as shared cart -- **Signature** Retrieves if it is a signature machine sold by Microsoft store. -- **SLICStatus** Whether a SLIC table exists on the device. -- **SLICVersion** Returns OS type/version from SLIC table. - - -### Census.PrivacySettings - -This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **__TlggV__** No content is currently available. -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appointments** Current state of the calendar setting. -- **BluetooÕh** No content is currently available. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **FindMyDevice** Current state of the "find my device" setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHissory** No content is currently available. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.Processor - -Provides information on several important data points about Processor settings - -The following fields are available: - -- **KvaShadow** This is the micro code information of the processor. -- **MMSettingOverride** Microcode setting of the processor. -- **MMSettingOverrideMask** Microcode setting override of the processor. -- **PreviousUpdateRevisikn** No content is currently available. -- **PreviousUpdateRevision** Previous microcode revision -- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. -- **ProcessorClockSpeed** Clock speed of the processor in MHz. -- **ProcessorCores** Number of logical cores in the processor. -- **ProcessorIdentifier** Processor Identifier of a manufacturer. -- **ProcessorManufacturer** Name of the processor manufacturer. -- **ProcessorModel** Name of the processor model. -- **ProcessorPhysicalCores** Number of physical cores in the processor. -- **ProcessorUpdateRevision** The microcode revision. -- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status -- **SocketCount** Count of CPU sockets. -- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. - - -### Census.Security - -This event provides information on about security settings used to help keep Windows up to date and secure. - -The following fields are available: - -- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. -- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. -- **DGState** This field summarizes the Device Guard state. -- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. -- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. -- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. -- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. -- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. -- **SModeState** The Windows S mode trail state. -- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. - - -### Census.Speech - -This event is used to gather basic speech settings on the device. - -The following fields are available: - -- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. -- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. -- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. -- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. -- **KeyVer** Version information for the census speech event. -- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). -- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. -- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. -- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. -- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. -- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. - - -### Census.Storage - -This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. - -The following fields are available: - -- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. -- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). -- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. -- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. - - -### Census.Userdefault - -This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. - -The following fields are available: - -- **CalendarTrpe** No content is currently available. -- **CalendarType** The calendar identifiers that are used to specify different calendars. -- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. -- **DefaultBrowserProgId** The ProgramId of the current user's default browser. -- **LongDateFormat** The long date format the user has selected. -- **ShortDateFormat** The short date format the user has selected. - - -### Census.UserDisplay - -This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. - -The following fields are available: - -- **InternalPrimaryDisp|aySizePhysicalY** No content is currently available. -- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. -- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. -- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. -- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. -- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . -- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches -- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine -- **NumberofInternalDisp** No content is currently available. -- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. -- **VRAMDedicated** Retrieves the video RAM in MB. -- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. -- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. - - -### Census.UserNLS - -This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. - -The following fields are available: - -- **DefaultAppLanguage** The current user Default App Language. -- **DisplayLanguage** The current user preferred Windows Display Language. -- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLaîguages** No content is currently available. -- **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLalguages** No content is currently available. -- **SpeechInputLanguages** The Speech Input languages installed on the device. - - -### Census.UserPrivacySettings - -This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. - -The following fields are available: - -- **Activity** Current state of the activity history setting. -- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. -- **ActivityHistoryCollection** Current state of the activity history collection setting. -- **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostacs** No content is currently available. -- **AppDiagnostics** Current state of the app diagnostics setting. -- **Appiagnostics** No content is currently available. -- **Appointments** Current state of the calendar setting. -- **Bluetooth** Current state of the Bluetooth capability setting. -- **BluetoothSync** Current state of the Bluetooth sync capability setting. -- **BroadFileSystemAccess** Current state of the broad file system access setting. -- **CellularData** Current state of the cellular data capability setting. -- **Chat** Current state of the chat setting. -- **Contacts** Current state of the contacts setting. -- **DocumentsLibrary** Current state of the documents library setting. -- **Email** Current state of the email setting. -- **GazeInput** Current state of the gaze input setting. -- **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkT9peImprovement** No content is currently available. -- **InkT9pePersonalization** No content is currently available. -- **InkTypeImprovement** Current state of the improve inking and typing setting. -- **InkTypePersonalization** Current state of the inking and typing personalization setting. -- **Location** Current state of the location setting. -- **LocationHistory** Current state of the location history setting. -- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. -- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphona** No content is currently available. -- **Microphone** Current state of the microphone setting. -- **PhoneCall** Current state of the phone call setting. -- **PhoneCallHistory** Current state of the call history setting. -- **PicturesLibrary** Current state of the pictures library setting. -- **Radios** Current state of the radios setting. -- **SensorsÃustom** No content is currently available. -- **SensorsCustom** Current state of the custom sensor setting. -- **SerialCommunication** Current state of the serial communication setting. -- **Sms** Current state of the text messaging setting. -- **SpeechPersonalization** Current state of the speech services setting. -- **UqerDataTasks** No content is currently available. -- **USB** Current state of the USB setting. -- **UserAccountInformation** Current state of the account information setting. -- **UserDataTasks** Current state of the tasks setting. -- **UserNotificationListener** Current state of the notifications setting. -- **VideosLibrary** Current state of the videos library setting. -- **Webcam** Current state of the camera setting. -- **WiFiDirect** Current state of the Wi-Fi direct setting. - - -### Census.VM - -This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. - -The following fields are available: - -- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. -- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. -- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. -- **IsVDI** Is the device using Virtual Desktop Infrastructure? -- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. -- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. -- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. - - -### Census.WU - -This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. - -The following fields are available: - -- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. -- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). -- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured -- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. -- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? -- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? -- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? -- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? -- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? -- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. -- **OSRollbackCount** The number of times feature updates have rolled back on the device. -- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. -- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . -- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. -- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. -- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. -- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). -- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. -- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. -- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. -- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. -- **WUPauseState** Retrieves WU setting to determine if updates are paused. -- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). - - -### Census.Xbox - -This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. - -The following fields are available: - -- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. -- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. -- **XboxLiveDeviceId** Retrieves the unique device ID of the console. -- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. - - -## Common data extensions - -### Common Data Extensions.app - -Describes the properties of the running application. This extension could be populated by a client app or a web app. - -The following fields are available: - -- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. -- **env** The environment from which the event was logged. -- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. -- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. -- **locale** The locale of the app. -- **name** The name of the app. -- **userId** The userID as known by the application. -- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. - - -### Common Data Extensions.container - -Describes the properties of the container for events logged within a container. - -The following fields are available: - -- **epoch** An ID that's incremented for each SDK initialization. -- **localId** The device ID as known by the client. -- **osVer** The operating system version. -- **seq** An ID that's incremented for each event. -- **type** The container type. Examples: Process or VMHost - - -### Common Data Extensions.cs - -Describes properties related to the schema of the event. - -The following fields are available: - -- **sig** A common schema signature that identifies new and modified event schemas. - - -### Common Data Extensions.device - -Describes the device-related fields. - -The following fields are available: - -- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId -- **make** Device manufacturer. -- **model** Device model. - - -### Common Data Extensions.Envelope - -Represents an envelope that contains all of the common data extensions. - -The following fields are available: - -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. -- **data** Represents the optional unique diagnostic data for a particular event schema. -- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). -- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). -- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). -- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). -- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. -- **iKey** Represents an ID for applications or other logical groupings of events. -- **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. -- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.os - -Describes some properties of the operating system. - -The following fields are available: - -- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. -- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. -- **locale** Represents the locale of the operating system. -- **name** Represents the operating system name. -- **ver** Represents the major and minor version of the extension. - - -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - -### Common Data Extensions.sdk - -Used by platform specific libraries to record fields that are required for a specific SDK. - -The following fields are available: - -- **epoch** An ID that is incremented for each SDK initialization. -- **installId** An ID that's created during the initialization of the SDK for the first time. -- **libVer** The SDK version. -- **seq** An ID that is incremented for each event. - - -### Common Data Extensions.user - -Describes the fields related to a user. - -The following fields are available: - -- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **locale** The language and region. -- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. - - -### Common Data Extensions.utc - -Describes the properties that could be populated by a logging library on Windows. - -The following fields are available: - -- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. -- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number -- **cat** Represents a bitmask of the ETW Keywords associated with the event. -- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. -- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **flags** Represents the bitmap that captures various Windows specific flags. -- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence -- **op** Represents the ETW Op Code. -- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. -- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - - -### Common Data Extensions.xbl - -Describes the fields that are related to XBOX Live. - -The following fields are available: - -- **claims** Any additional claims whose short claim name hasn't been added to this structure. -- **did** XBOX device ID -- **dty** XBOX device type -- **dvr** The version of the operating system on the device. -- **eid** A unique ID that represents the developer entity. -- **exp** Expiration time -- **ip** The IP address of the client device. -- **nbf** Not before time -- **pid** A comma separated list of PUIDs listed as base10 numbers. -- **sbx** XBOX sandbox identifier -- **sid** The service instance ID. -- **sty** The service type. -- **tid** The XBOX Live title ID. -- **tvr** The XBOX Live title version. -- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. -- **xid** A list of base10-encoded XBOX User IDs. - - -## Common data fields - -### Ms.Device.DeviceInventoryChange - -Describes the installation state for all hardware and software components available on a particular device. - -The following fields are available: - -- **action** The change that was invoked on a device inventory object. -- **invent¹ryId** No content is currently available. -- **inventoryId** Device ID used for Compatibility testing -- **objectInstanceId** Object identity which is unique within the device scope. -- **objectType** Indicates the object type that the event applies to. -- **objmctType** No content is currently available. -- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. - - -## Compatibility events - -### Microsoft.Windows.Compatibility.Apphelp.SdbFix - -Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. - -The following fields are available: - -- **AppName** Name of the application impacted by SDB. -- **FixID** SDB GUID. -- **Flags** List of flags applied. -- **ImageName** Name of file. - - -## Component-based servicing events - -### CbsServicingProvider.CbsCapabilityEnumeration - -This event reports on the results of scanning for optional Windows content on Windows Update. - -The following fields are available: - -- **architecture** Indicates the scan was limited to the specified architecture. -- **capabilityCount** The number of optional content packages found during the scan. -- **clientId** The name of the application requesting the optional content. -- **duration** The amount of time it took to complete the scan. -- **hrStatus** The HReturn code of the scan. -- **language** Indicates the scan was limited to the specified language. -- **majorVersion** Indicates the scan was limited to the specified major version. -- **minorVersion** Indicates the scan was limited to the specified minor version. -- **namespace** Indicates the scan was limited to packages in the specified namespace. -- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionFinalize - -This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. - -The following fields are available: - -- **capabilities** The names of the optional content packages that were installed. -- **clientId** The name of the application requesting the optional content. -- **currentID** The ID of the current install session. -- **downloadSource** The source of the download. -- **highestState** The highest final install state of the optional content. -- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. -- **hrStatus** The HReturn code of the install operation. -- **rebootCount** The number of reboots required to complete the install. -- **retryID** The session ID that will be used to retry a failed operation. -- **retryStatus** Indicates whether the install will be retried in the event of failure. -- **stackBuild** The build number of the servicing stack. -- **stackMajorVersion** The major version number of the servicing stack. -- **stackMinorVersion** The minor version number of the servicing stack. -- **stackRevision** The revision number of the servicing stack. - - -### CbsServicingProvider.CbsCapabilitySessionPended - -This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. - -The following fields are available: - -- **clientId** The name of the application requesting the optional content. -- **pendingDecision** Indicates the cause of reboot, if applicable. - - -### CbsServicingProvider.CbsLateAcquisition - -This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. - -The following fields are available: - -- **Features** The list of feature packages that could not be updated. -- **RetryID** The ID identifying the retry attempt to update the listed packages. - - -### CbsServicingProvider.CbsPackageRemoval - -This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build number of the security update being uninstalled. -- **clientId** The name of the application requesting the uninstall. -- **currentStateEnd** The final state of the update after the operation. -- **failureDetails** Information about the cause of a failure, if applicable. -- **failureSourceEnd** The stage during the uninstall where the failure occurred. -- **hrStatusEnd** The overall exit code of the operation. -- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. -- **majorVersion** The major version number of the security update being uninstalled. -- **minorVersion** The minor version number of the security update being uninstalled. -- **originalState** The starting state of the update before the operation. -- **pendingDecision** Indicates the cause of reboot, if applicable. -- **primitiveExecutionContext** The state during system startup when the uninstall was completed. -- **revisionVersion** The revision number of the security update being uninstalled. -- **transactionCanceled** Indicates whether the uninstall was cancelled. - - -### CbsServicingProvider.CbsQualityUpdateInstall - -This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. - -The following fields are available: - -- **buildVersion** The build version number of the update package. -- **clientId** The name of the application requesting the optional content. -- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. -- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. -- **currentStateEnd** The final state of the package after the operation has completed. -- **doqTimeSeconds** The time in seconds spent updating drivers. -- **executeTimeSeconds** The number of seconds required to execute the install. -- **failureDetails** The driver or installer that caused the update to fail. -- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. -- **hrStatusEnd** The return code of the install operation. -- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. -- **majorVersion** The major version number of the update package. -- **minorVersion** The minor version number of the update package. -- **originalState** The starting state of the package. -- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. -- **planTimeSeconds** The time in seconds required to plan the update operations. -- **poqTimeSeconds** The time in seconds processing file and registry operations. -- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. -- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. -- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. -- **rebootCount** The number of reboots required to install the update. -- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. -- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. -- **revisionVersion** The revision version number of the update package. -- **rptTimeSeconds** The time in seconds spent executing installer plugins. -- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. -- **stackRevision** The revision number of the servicing stack. -- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. - - -### CbsServicingProvider.CbsSelectableUpdateChangeV2 - -This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. - -The following fields are available: - -- **applicableUpdateState** Indicates the highest applicable state of the optional content. -- **buildVersion** The build version of the package being installed. -- **clientId** The name of the application requesting the optional content change. -- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. -- **downloadtimeInSeconds** The number of seconds required to complete the optional content download. -- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. -- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. -- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. -- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. -- **hrDownloadResult** The return code of the download operation. -- **hrStatusUpdate** The return code of the servicing operation. -- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. -- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. -- **majorVersion** The major version of the package being installed. -- **minorVersion** The minor version of the package being installed. -- **packageArchitecture** The architecture of the package being installed. -- **packageLanguage** The language of the package being installed. -- **packageName** The name of the package being installed. -- **rebootRequired** Indicates whether a reboot is required to complete the operation. -- **revisionVersion** The revision number of the package being installed. -- **stackBuild** The build number of the servicing stack binary performing the installation. -- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. -- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. -- **stackRevision** The revision number of the servicing stack binary performing the installation. -- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. -- **updateStartState** A value indicating the state of the optional content before the operation started. -- **updateTargetState** A value indicating the desired state of the optional content. - - -## Deployment extensions - -### DeploymentTelemetry.Deployment_End - -This event indicates that a Deployment 360 API has completed. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** Phase in upgrade. -- **RelatedCV** The correction vector (CV) of any other related events -- **Result** End result of the action. - - -### DeploymentTelemetry.Deployment_SetupBoxLaunch - -This event indicates that the Deployment 360 APIs have launched Setup Box. - -The following fields are available: - -- **ClientId** The client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current setup phase. - - -### DeploymentTelemetry.Deployment_SetupBoxResult - -This event indicates that the Deployment 360 APIs have received a return from Setup Box. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **ErrorCode** Error code of the action. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Quiet** Indicates whether Setup will run in quiet mode or full mode. -- **RelatedCV** The correlation vector (CV) of any other related events. -- **SetupMode** The current Setup phase. - - -### DeploymentTelemetry.Deployment_Start - -This event indicates that a Deployment 360 API has been called. - -The following fields are available: - -- **ClientId** Client ID of the user utilizing the D360 API. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **Mode** The current phase of the upgrade. -- **RelatedCV** The correlation vector (CV) of any other related events. - - -## Diagnostic data events - -### TelClientSynthetic.AuthorizationInfo_RuntimeTransition - -This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. - -The following fields are available: - -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.AuthorizationInfo_Startup - -Fired by UTC at startup to signal what data we are allowed to collect. - -The following fields are available: - -- **CanAdd** No content is currently available. -- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. -- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. -- **CanCollectHe.Debeats** No content is currently available. -- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. -- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. -- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. -- **CanPerformDiagnosticEscalationc** No content is currently available. -- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **PreviousPermicsions** No content is currently available. -- **PreviousPermissions** Bitmask of previous telemetry state. -- **TransitionFromEveryt`ingOff** No content is currently available. -- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. - - -### TelClientSynthetic.ConnectivityHeartBeat_0 - -This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. - -The following fields are available: - -- **CensusExitCode** Returns last execution codes from census client run. -- **CensusStartTime** Returns timestamp corresponding to last successful census run. -- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. -- **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. -- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. -- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. -- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. -- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. -- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. - - -### TelClientSynthetic.HeartBeat_5 - -This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. - -The following fields are available: - -- **** No content is currently available. -- **艍ጋⰎჄ↶췸̎耀艊ጀ‏艋ጃᰌი↶** No content is currently available. -- **@쯵￿耀蝉ᄀ〉‭ᢤ↱p** No content is currently available. -- **⬰げㅶ漴䬸穕婒㘳㕡䙤乯欸㉂夷** No content is currently available. -- **㉕睐灆㝎剓畷⽧⽶扙全ぐ⽒灥湐湌䈶灦晋砰っ礯䈱㕪** No content is currently available. -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AgentCoNnectionErrorsCount** No content is currently available. -- **āकĒࠨ婆Pက喬↵갸ژāक** No content is currently available. -- **āकĒࠨ婦Tက** No content is currently available. -- **āकĒࠨ媦\က** No content is currently available. -- **āकĒࠨ宆xက僸↵곌׌** No content is currently available. -- **āकĒࠨ汆 嬨↵꼔** No content is currently available. -- **CensusExitCode** The last exit code of the Census task. -- **CensusStartTime** Time of last Census run. -- **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **CriticalOvErflowEntersCounter** No content is currently available. -- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbDroppedCount** Number of events dropped due to DB fullness. -- **DbDroppedFailureCount** Number of events dropped due to DB failures. -- **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecndingDroppedCount** No content is currently available. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **Ēࠨ⳥ࠥ䃀첤↵쁸拠** No content is currently available. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. -- **EventStoreResetCounter** Number of times event DB was reset. -- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventSubStoreResetCounter** Number of times event DB was reset. -- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **FullTrigwerBufferDroppedCount** No content is currently available. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidH4BFCodeCount** No content is currently available. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **ȋ耀耭⬀‧早诉耮⬄怛昡设耯⬈** No content is currently available. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidH4BFCode** No content is currently available. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **ⓅЀ쬐↵삔托ā** No content is currently available. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsH4BFAttempts** No content is currently available. -- **SettingsH4BFFailures** No content is currently available. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexH4BFAttempts** No content is currently available. -- **VortexH4BFFailures4xx** No content is currently available. -- **VortexH4BFFailures5xx** No content is currently available. -- **VortexH4BFResponseFailures** No content is currently available. -- **VortexH4BFResponsesWithDroppedEvents** No content is currently available. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWi|hDroppedEvents** No content is currently available. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **V聯rtexHttpFailures5xx** No content is currently available. -- **अĒࠨⴅ!₀俨↵겈Ѹ** No content is currently available. -- **ြ갌暠聇⭜搽갌暜聈⭠밾갌** No content is currently available. -- **ေ괔暜耼⬰뀲궄暠耽⬴吳괄暜** No content is currently available. -- **̎耀艊ጀ‏艋ጃᰌი↶** No content is currently available. -- **권擘耩⬔ఫ권擔耪⬘〬권擘耫⬜ﰭ권擔耬⬠�� 擝诚** No content is currently available. -- **곔暜聄⭐к괤暠聅⭔퐻갔暜** No content is currently available. -- **갌暜聘⮠偎갌暠聙⮤鑏갌暜聚** No content is currently available. -- **꺨徠耋** No content is currently available. -- **껨徤而⬬퐱길徠耍⬰耲기徤耎⬴㐳** No content is currently available. -- **꼄ቌāकĒࠨ** No content is currently available. -- **쐴궤暠耿⬼찵곴暜** No content is currently available. -- **乭睱祒ㅡ坘牦晩塴唯㥺扱氫㝬㜸⭗偑圶㍡䈲䔯略儹祘㝈圳㡆晪煥瘰䱫琯汗朸⽦ㅵ歶** No content is currently available. -- **佗䱺䑁⽱橒失猶畓湳硖䭏煲愴呌眹卲愹癦慂㝘㡔䰰⭗偡穭䌹㍧偙** No content is currently available. -- **佱塪癒噲歋㤶癉乴煙瑬睷婇睶杭剓摁乄** No content is currently available. -- **倰煹穑䅣䍏楍桧㥡䙪畴䑕橲䕋甯朱㝗硐⭨渶㕶㈯杖䤸穗䡈㥂㥭㑱㝙** No content is currently available. -- **偊〫祰汓汨兄男捇䉧潗塶睥唴㕺瑰煲焰㕸卩兢㉮** No content is currently available. -- **典止歂㔴ぎ䕅穔䜫㥹地䵭ㅔ煘乓假穑䙭䕱㈰晃卉敳祎煙捺灘橙癭䵈伹ぴ硱** No content is currently available. -- **典㙪獬牵汑ㅘ灢㕌㝶湌㑣㙌捯㑷㈳潏祓㥪戳㉺** No content is currently available. -- **剼↵겤״āकĒࠨ婦T** No content is currently available. -- **匈↵걼بāकĒࠨ媦\က咈↵ڐ** No content is currently available. -- **匷硬䭦兔楰㑔汬㑶儷䱈乥猴㕘晱歈瑘游剏㡸㝩倵** No content is currently available. -- **呅穹敖兌橤㈵汴洲䨶潈乺⭎⭕栫** No content is currently available. -- **呣礲晉坩穑〹ひ䝰ぷ噢晘堳刳噒䩈丵畏兑䩨琳⬹佫搱噈** No content is currently available. -- **啧癃獷奆䕤穱啧晬呈䅌琴䴫桗獍噲瘶㕨橰啪楗佧** No content is currently available. -- **噪兙䑯楓㍈奬慰㝋坣睵潕婤瑚䱊昹伵朱敕杰爸睶** No content is currently available. -- **噶甴う歶㍔䈹㝘潳䍈煆⼹挴⬯㝷祄䈯㝃⼯** No content is currently available. -- **坪䙵失慒獗攱猱塘⽰桪⬲摫倶摘塂䄰䰶⽵歐浪瀷** No content is currently available. -- **堿갌暜聊⭨ⱀ갌暠聋⭬** No content is currently available. -- **塩猯䡦癐㝔祤偪捲浖焷㍁浲祹䕡橆橨瑈坰獕教** No content is currently available. -- **失椷䡔㠱呯⽅䕴慴乊匵戱洱番偓㡤䘳㡪奨楈** No content is currently available. -- **夵楲䑣癳摌六䔴㍍⬶獖晘⽅䅅祸㙖橸佣坂㉵ㅚ慇** No content is currently available. -- **慦㥣㥘硸癒䕎䩪㤰䠯祔う敚⬹户䨳啢䩖䡦䘱桎癆** No content is currently available. -- **扊㍩坒潅㝤児堷䩤㉫硩䠶橗杤橚慃杇橙㉡摔娳** No content is currently available. -- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. -- **敬䉶癷潘場㡌䱥⭬䙐⽹楈堵硪牣㑸䵸䥴㝄噣瑒䠸ㅪ** No content is currently available. -- **昡讱⮮耀耰⬀‧晩讛耱⬄怛暥讐耲⬈** No content is currently available. -- **暜耸⬠蠮궴暠耹⬤뀯괤暜耺⬨氰긔暠** No content is currently available. -- **暜职⭰䱂갌暠聍⭴籃갌暜聎⭸聄** No content is currently available. -- **暜聒⮈챈갌暠聓⮌둉갌暜联** No content is currently available. -- **暠耳⬌ﰩ굔暜耴⬐瀪귤暠耵⬔瀫굄暜耶⬘쐬긔暠耷⬜** No content is currently available. -- **暠聏⭼㑅갌暜聐⮀ᑆ갌暠聑⮄** No content is currently available. -- **术硂瑲⽑㥴䱡偭橏䬷礫癪硷㡲⽰䑇游临㙐橪㑯倴⽓剂** No content is currently available. -- **樲㙘䡌㡘坯歎楈⽹ご㥹湭歆㡨婨⬵啊䍶桊塌吶㥈敍汍㕪刲慄** No content is currently available. -- **毆€ 娠↵꺈࿐** No content is currently available. -- **泆  嚔↵곴बā** No content is currently available. -- **湹䩳⭑晹礰婶啊灋䱸晒㉉㑬ひ⭄㑉慙㝲䡦** No content is currently available. -- **潭晰橷睧䌵** No content is currently available. -- **瀯㉪䡏ㅏ⭕楆摡倶㙑愰佚䍪䤳煃奄硭摍嘯煗㍓唸卆** No content is currently available. -- **灋瘸乏煆䬳桱㕙瘸㑘䙸橧㥶䔵橲㕙楗佧吸⭚獏桗** No content is currently available. -- **獇牅歘䉡汸㉂夸乶坁浂偕㤲塅䩸桑と牚穒癲浕** No content is currently available. -- **獭䭏啪漲睌穩⬫入䨱䈸⽁䑇敉儴慣㙹么䥶晋湋朶剹慷** No content is currently available. -- **瑖穒㍤摧癵摆䑧⭧䍏杭䵫敘煰橲煤橲煤橲煤橲煤橲煤橲煤橲煤橲武** No content is currently available. -- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. -- **穇圹塑⽈潘䉘䉒头㡕湲㠵汪圸夸䑬潕杪䙔戴䑌** No content is currently available. -- **穬⼱䍯昫㤹卲儫⬯牎奦㡈㙸ㄯ時㍊佘䱳伵㠫栱䥦⭦慊祘⽂浶** No content is currently available. -- **ࠣ耀耤⬀‧撡豒耥⬄怛擝豇耦⬈귄擘耧⬌鐩** No content is currently available. -- **̎耀艊ጀ‏艋ጃᰌი↶艌錇萍ƒ** No content is currently available. -- **̎耀艊ጀ‏艋ጃᰌი↶艌錇萍ƒ჌↶ 艍ጋⰎ** No content is currently available. -- **耏⬸찴기徤耐⬼됵기** No content is currently available. -- **耑⭀萶기徤耒⭄࠷기徠耓** No content is currently available. -- **耝⬐�� 拱費Ԗ耀耞** No content is currently available. -- **艋ጃᰌი↶艌錇萍ƒ჌↶ 艍ጋⰎჄ↶** No content is currently available. -- **萍ƒ჌↶ 艍ጋⰎჄ↶᝞耀老⬀‧彵** No content is currently available. -- **萍ƒ჌↶ 艍ጋⰎჄ↶큰̎耀艊** No content is currently available. -- **葊갌暠聕⮔ࡋ갌暜聖⮘豌갌暠聗** No content is currently available. -- **㐰愱啬瑬癏䝒乘慲椰㉑眫䱄晶獶䝅䙗䕫㉡** No content is currently available. -- **䄸䵒䝰ㅹ灌癳噚䥍祫䬵礷楗光摹䑑䡢ㅑ䭱獎伱噺獃䕑济浱桱** No content is currently available. -- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. -- **䍭㐰䕩坶㥆慉塲夶煁椫㝖瀱栲硪爯畉乂㑒㝥昷䕺乍併娴橲䭎改睗畃睯** No content is currently available. -- **䍸欳昷偔坊問扨婔䨷㥗桴塲㍄䵹橥癉嘷䵊噲湥** No content is currently available. -- **䠷坸⽦䄯⽣晵ㄳ卂楖づ睧䤵椹穴䝊潩硍䩢䵎橫㍸牨** No content is currently available. -- **䨵浤汗位㑗䕶㝸䥮敡潱倱偑煥塪晢** No content is currently available. -- **䰶굔暠聁⭄砷곤暜聂⭈8궄暠** No content is currently available. -- **䱥⭫䙐晹楈䠵硨牣㑷噏挶䍈伹桪湣㑸呵㠴乘攸浌䡥穆䱶㕧瑘捷㉌伶穆䡦㕩橶捸砳甴㑚堸** No content is currently available. -- **䱲㝏危㡨呥卐䩯⭒祐汮潧䩑ㅷ歈偤㉱灕⬲穏公** No content is currently available. -- **䴶㑊啥䕪乶汊摉㥐焲楂䜹洳敡⬫灍⭒佦呮敮婪〷朵癹呧煡㙤䤫浨瘹** No content is currently available. - - -### TelClientSynthetic.HeartBeat_Aria_5 - -This event is the telemetry client ARIA heartbeat. - -The following fields are available: - -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped at the database layer. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. -- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. -- **EventStoreResetSizeSum** Size of event store reset in bytes. -- **EventsUploaded** Number of events uploaded. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. -- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting OneSettings service. -- **TopUploaderErrors** List of top errors received from the upload endpoint. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. -- **UploaderErrorCount** Number of errors received from the upload endpoint. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -### TelClientSynthetic.HeartBeat_Seville_5 - -This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. - -The following fields are available: - -- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. -- **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. -- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. -- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. -- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). -- **DbCriticalDroppedCount** Total number of dropped critical events in event database. -- **DbDroppedCount** Number of events dropped due to database being full. -- **DbDroppedFailureCount** Number of events dropped due to database failures. -- **DbDroppedFullCount** Number of events dropped due to database being full. -- **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). -- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. -- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. -- **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). -- **EventStoreResetCounter** Number of times the event database was reset. -- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. -- **EventsUploaded** Number of events uploaded. -- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. -- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. -- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. -- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. -- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). -- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). -- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. -- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. -- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. -- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. -- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. -- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. -- **VortexFailuresTimeout** Number of time out failures received from Vortex. -- **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. -- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. - - -## Direct to update events - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability - -Event to indicate that the Coordinator CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** Result of CheckApplicability function. -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. -- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. -- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. -- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. -- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. -- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. -- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. -- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. -- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. -- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. -- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). -- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. -- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. -- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure - -This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector -- **hResult** HRESULT of the failure - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess - -This event indicates that the Coordinator Cleanup call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run -- **ClientID** Client ID being run -- **CoordinatorVersion** Coordinator version of DTU -- **CV** Correlation vector - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess - -This event indicates that the Coordinator Commit call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess - -This event indicates that the Coordinator Download call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinate version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess - -This event indicates that the Coordinator HandleShutdown call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess - -This event indicates that the Coordinator Initialize call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure - -This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack - -This event indicates that the Coordinator's progress callback has been called. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** Client ID being run. -- **CoordinatorVersion** Coordinator version of DTU. -- **CV** Correlation vector. -- **DeployPhase** Current Deploy Phase. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess - -This event indicates that the Coordinator SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** Campaign ID being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection - -This event indicates that the user selected an option on the Reboot UI. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **rebootUiSelection** Selection on the Reboot UI. - - -### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess - -This event indicates that the Coordinator WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess - -This event indicates that the Handler CheckApplicabilityInternal call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result of the applicability check. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess - -This event indicates that the Handler CheckApplicability call succeeded. - -The following fields are available: - -- **ApplicabilityResult** The result code indicating whether the update is applicable. -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess - -This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess - -This event indicates that the Handler Commit call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run.run -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **CV_new** New correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure - -This event indicates that the Handler Download and Extract cab call failed. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess - -This event indicates that the Handler Download and Extract cab call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess - -This event indicates that the Handler Download call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess - -This event indicates that the Handler Initialize call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess - -This event indicates that the Coordinator Install call succeeded. - -The following fields are available: - -- **CampaignID** ID of the update campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess - -This event indicates that the Handler SetCommitReady call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure - -This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. - -The following fields are available: - -- **CampaignID** The ID of the campaigning being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. -- **hResult** The HRESULT of the failure. - - -### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess - -This event indicates that the Handler WaitForRebootUi call succeeded. - -The following fields are available: - -- **CampaignID** ID of the campaign being run. -- **ClientID** ID of the client receiving the update. -- **CoordinatorVersion** Coordinator version of Direct to Update. -- **CV** Correlation vector. - - -## DxgKernelTelemetry events - -### DxgKrnlTelemetry.GPUAdapterInventoryV2 - -This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. - -The following fields are available: - -- **AdapterT}peValue** No content is currently available. -- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. -- **AdapterTyreValue** No content is currently available. -- **aiSeqId** The event sequence ID. -- **bootId** The system boot ID. -- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **ComputePreelptionLevel** No content is currently available. -- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedicatedSy{temMemoryB** No content is currently available. -- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DisplayAdap|erLuid** No content is currently available. -- **DisplayAdapderLuid** No content is currently available. -- **DisplayAdapterLuid** The display adapter LUID. -- **Driver^ersion** No content is currently available. -- **DriverDat** No content is currently available. -- **DriverDate** The date of the display driver. -- **DriverRank** The rank of the display driver. -- **DriverVersion** The display driver version. -- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. -- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. -- **DX1rUMDFilePath** No content is currently available. -- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **DX9UMDFileXath** No content is currently available. -- **GPUDeviceID** The GPU device ID. -- **GPUDexiceID** No content is currently available. -- **GPUPreelptionLevel** No content is currently available. -- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. -- **GPUPzeemptionLevel** No content is currently available. -- **GPURevisionID** The GPU revision ID. -- **GPURexisionID** No content is currently available. -- **GPUVendorID** The GPU vendor ID. -- **InterfaceId** The GPU interface ID. -- **IsDisplayDevice** Does the GPU have displaying capabilities? -- **IsDisplayDexice** No content is currently available. -- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridDiwcrete** No content is currently available. -- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsLDA** Is the GPU comprised of Linked Display Adapters? -- **IsMiiacastSupported** No content is currently available. -- **IsMiracastSupported** Does the GPU support Miracast? -- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMPOSupport%d** No content is currently available. -- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? -- **IsMsMiiacastSupported** No content is currently available. -- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? -- **IsPostAdapter** Is this GPU the POST GPU in the device? -- **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRemovableǑBrightnessVersionViaDDIǩ WDDMVersionॠȠDisplayAdapterLuidǷDisplayAdapterLuidȄGPUPreempti** No content is currently available. -- **IsRenderDevice** Does the GPU have rendering capabilities? -- **IsRenderDexice** No content is currently available. -- **IsSoftwareDevace** No content is currently available. -- **IsSoftwareDevice** Is this a software implementation of the GPU? -- **IsSoftwareDexice** No content is currently available. -- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **Meas}reEnabled** No content is currently available. -- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? -- **MnterfaceId** No content is currently available. -- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. -- **NumVidPnSou** No content is currently available. -- **NumVidPnSources** The number of supported display output sources. -- **NumVidPnTargets** The number of supported display output targets. -- **SharedSystemMemory@** No content is currently available. -- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). -- **SubSystemID** The subsystem ID. -- **SubVendorID** The GPU sub vendor ID. -- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **TelnveEvntTrigger** No content is currently available. -- **version** The event version. -- **verwion** No content is currently available. -- **WDDMVersion** The Windows Display Driver Model version. - - -## Failover Clustering events - -### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 - -This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. - -The following fields are available: - -- **autoAssignSite** The cluster parameter: auto site. -- **autoBalancerLevel** The cluster parameter: auto balancer level. -- **autoBalancerMode** The cluster parameter: auto balancer mode. -- **blockCacheSize** The configured size of the block cache. -- **ClusterAdConfiguration** The ad configuration of the cluster. -- **clusterAdType** The cluster parameter: mgmt_point_type. -- **clusterDumpPolicy** The cluster configured dump policy. -- **clusterFunctionalLevel** The current cluster functional level. -- **clusterGuid** The unique identifier for the cluster. -- **clusterWitnessType** The witness type the cluster is configured for. -- **countNodesInSite** The number of nodes in the cluster. -- **crossSiteDelay** The cluster parameter: CrossSiteDelay. -- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. -- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. -- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. -- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. -- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. -- **csvResourceCount** The number of resources in the cluster. -- **currentNodeSite** The name configured for the current site for the cluster. -- **dasModeBusType** The direct storage bus type of the storage spaces. -- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. -- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. -- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. -- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. -- **genAppNames** The win32 service name of a clustered service. -- **genSvcNames** The command line of a clustered genapp. -- **hangRecoveryAction** The cluster parameter: hang recovery action. -- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. -- **isCalabria** Specifies whether storage spaces direct is enabled. -- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. -- **isRunningDownLevel** Identifies if the current node is running down-level. -- **logLevel** Specifies the granularity that is logged in the cluster log. -- **logSize** Specifies the size of the cluster log. -- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. -- **minNeverPreempt** The cluster parameter: minimum never preempt. -- **minPreemptor** The cluster parameter: minimum preemptor priority. -- **netftIpsecEnabled** The parameter: netftIpsecEnabled. -- **NodeCount** The number of nodes in the cluster. -- **nodeId** The current node number in the cluster. -- **nodeResourceCounts** Specifies the number of node resources. -- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. -- **numberOfSites** The number of different sites. -- **numNodesInNoSite** The number of nodes not belonging to a site. -- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. -- **preferredSite** The preferred site location. -- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. -- **quarantineDuration** The quarantine duration. -- **quarantineThreshold** The quarantine threshold. -- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. -- **resiliencyLevel** Specifies the level of resiliency. -- **resourceCounts** Specifies the number of resources. -- **resourceTypeCounts** Specifies the number of resource types in the cluster. -- **resourceTypes** Data representative of each resource type. -- **resourceTypesPath** Data representative of the DLL path for each resource type. -- **sameSubnetDelay** The cluster parameter: same subnet delay. -- **sameSubnetThreshold** The cluster parameter: same subnet threshold. -- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). -- **securityLevel** The cluster parameter: security level. -- **securityLevelForStorage** The cluster parameter: security level for storage. -- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. -- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. -- **upNodeCount** Specifies the number of nodes that are up (online). -- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. -- **vmIsolationTime** The cluster parameter: VM isolation time. -- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. - - -## Fault Reporting events - -### Microsoft.Windows.FaultReporting.AppCrashEvent - -This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. - -The following fields are available: - -- **AppName** The name of the app that has crashed. -- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimeStamp** The date/time stamp of the app. -- **AppVersion** The version of the app that has crashed. -- **AsFatal** No content is currently available. -- **Exceptio** No content is currently available. -- **ExceptionCode** The exception code returned by the process that has crashed. -- **ExceptionOffset** The address where the exception had occurred. -- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. -- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **ModName** Exception module name (e.g. bar.dll). -- **ModTimestamp** No content is currently available. -- **ModTimeStamp** The date/time stamp of the module. -- **ModVersion** The version of the module that has crashed. -- **ode** No content is currently available. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessId** The ID of the process that has crashed. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **targetAppVer** No content is currently available. -- **TargetAppVer** The specific version of the application being reported -- **TargetAsId** The sequence number for the hanging process. - - -## Feature update events - -### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered - -This event indicates that the uninstall was properly configured and that a system reboot was initiated. - - - -### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked - -This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. - - - -## Hang Reporting events - -### Microsoft.Windows.HangReporting.AppHangEvent - -This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. - -The following fields are available: - -- **AppName** The name of the app that has hung. -- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. -- **AppVersion** The version of the app that has hung. -- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. -- **PackageFullName** Store application identity. -- **PackageRelativeAppId** Store application identity. -- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessCreateTime** The time of creation of the process that has hung. -- **ProcessId** The ID of the process that has hung. -- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargetAppId** The kernel reported AppId of the application being reported. -- **TargetAppVer** The specific version of the application being reported. -- **TargetAsId** The sequence number for the hanging process. -- **TypeCode** Bitmap describing the hang type. -- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. -- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. -- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. -- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. - - -## Inventory events - -### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum - -This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. - -The following fields are available: - -- **Device** A count of device objects in cache. -- **DeviceCensus** A count of device census objects in cache. -- **DriverPackageExtended** A count of driverpackageextended objects in cache. -- **File** A count of file objects in cache. -- **FileSigningInfo** A count of file signing objects in cache. -- **Generic** A count of generic objects in cache. -- **HwItem** A count of hwitem objects in cache. -- **IentoryMiscellaneousOfficeAddIn** No content is currently available. -- **InventoryApplication** A count of application objects in cache. -- **InventoryApplicationAppV** A count of application AppV objects in cache. -- **InventoryApplicationDriver** A count of application driver objects in cache -- **InventoryApplicationFile** A count of application file objects in cache. -- **InventoryApplicationFramework** A count of application framework objects in cache -- **InventoryApplicationShortcut** A count of application shortcut objects in cache -- **InventoryDeviceContainer** A count of device container objects in cache. -- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. -- **InventoryDeviceMediaClass** A count of device media objects in cache. -- **InventoryDevicePnp** A count of device Plug and Play objects in cache. -- **InventoryDeviceUsbHubClass** A count of device usb objects in cache -- **InventoryDriverBinary** A count of driver binary objects in cache. -- **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneiscellaneousOfficeInsights** No content is currently available. -- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache -- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. -- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache -- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache -- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache -- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache -- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache -- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache -- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache -- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache -- **Metadata** A count of metadata objects in cache. -- **Orphan** A count of orphan file objects in cache. -- **Programs** A count of program objects in cache. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo - -Diagnostic data about the inventory cache. - -The following fields are available: - -- **CacheFileSize** Size of the cache. -- **InventoryVersion** Inventory version of the cache. -- **TempCacheCount** Number of temp caches created. -- **TempCacheDeletedCount** Number of temp caches deleted. - - -### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions - -This event sends inventory component versions for the Device Inventory data. - -The following fields are available: - -- **aeinv** The version of the App inventory component. -- **devinv** The file version of the Device inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd - -This event sends basic metadata about an application on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. -- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). -- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLincFile** No content is currently available. -- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. -- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InventoryVersion** The version of the inventory file generating the events. -- **Language** The language code of the program. -- **MsipackageCode** No content is currently available. -- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiProductCode** A GUID that describe the MSI Product. -- **Name** The name of the application. -- **OSversionAtInstallTime** No content is currently available. -- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **PackageFullName** The package full name for a Store application. -- **ProgramInstanceId** A hash of the file IDs in an app. -- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDirPath** The path to the root directory where the program was installed. -- **Source** How the program was installed (for example, ARP, MSI, Appx). -- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **type** No content is currently available. -- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. -- **Version** The version number of the program. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd - -This event represents what drivers an application installs. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. -- **ProgramIds** The unique program identifier the driver is associated with. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync - -The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory component. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd - -This event provides the basic metadata about the frameworks an application may depend on. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **FileId** A hash that uniquely identifies a file. -- **Frameworks** The list of frameworks this file depends on. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync - -This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync - -This event indicates that a new set of InventoryApplicationAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd - -This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Categories** A comma separated list of functional categories in which the container belongs. -- **DiscoveryMethod** The discovery method for the device container. -- **FriendlyName** The name of the device container. -- **InventoryVersion** The version of the inventory file generating the events. -- **IsActive** Is the device connected, or has it been seen in the last 14 days? -- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. -- **IsMachineContainer** Is the container the root device itself? -- **IsNetworked** Is this a networked device? -- **IsPaired** Does the device container require pairing? -- **Manufacturer** The manufacturer name for the device container. -- **ModelId** A unique model ID. -- **ModelName** The model name. -- **ModelNumber** The model number for the device container. -- **PrimaryCategory** The primary category for the device container. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove - -This event indicates that the InventoryDeviceContainer object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync - -This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd - -This event retrieves information about what sensor interfaces are available on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. -- **ActivityDetection** Indicates if an Activity Detection sensor is found. -- **AmbientLight** Indicates if an Ambient Light sensor is found. -- **Barometer** Indicates if a Barometer sensor is found. -- **Custom** Indicates if a Custom sensor is found. -- **EnergyMeter** Indicates if an Energy sensor is found. -- **FloorElevation** Indicates if a Floor Elevation sensor is found. -- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. -- **GravityVector** Indicates if a Gravity Detector sensor is found. -- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. -- **Humidity** Indicates if a Humidity sensor is found. -- **InventoryVersion** The version of the inventory file generating the events. -- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. -- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. -- **Orientation** Indicates if an Orientation sensor is found. -- **Pedometer** Indicates if a Pedometer sensor is found. -- **Proximity** Indicates if a Proximity sensor is found. -- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. -- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. -- **Temperature** Indicates if a Temperature sensor is found. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync - -This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd - -This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 -- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 -- **Audio_CaptureDriver** The Audio device capture driver endpoint. -- **Audio_RenderDriver** The Audio device render driver endpoint. -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove - -This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync - -This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. - -This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd - -This event represents the basic metadata about a plug and play (PNP) device and its associated driver. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **]pperClassFilters** No content is currently available. -- **basedata** No content is currently available. See [basedata](#basedata). -- **BusReportedDescraption** No content is currently available. -- **BusReportedDescription** The description of the device reported by the bux. -- **BusReptrtedDescription** No content is currently available. -- **Clas{Guid** No content is currently available. -- **Class** The device setup class of the driver loaded for the device. -- **ClassGuid** The device class unique identifier of the driver package loaded on the device. -- **COMPID** The list of “Compatible IDs” for this device. -- **Con|ainerId** No content is currently available. -- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Descriptaon** No content is currently available. -- **Description** The description of the device. -- **DeviceDriverFlightId** No content is currently available. -- **DeviceExtDriversFlightIds** No content is currently available. -- **DeviceInterfaceClasses** The device interfaces that this device implements. -- **DeviceState** Identifies the current state of the parent (main) device. -- **DriverAd** No content is currently available. -- **DriverId** The unique identifier for the installed driver. -- **DriverName** The name of the driver image file. -- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVer^ersion** No content is currently available. -- **DriverVerDate** The date associated with the driver installed on the device. -- **DriverVerVersion** The version number of the driver installed on the device. -- **Enumerator** Identifies the bus that enumerated the device. -- **ExtendedInfs** The extended INF file names. -- **FirstInstallDate** No content is currently available. -- **H_ID** No content is currently available. -- **HWID** A list of hardware IDs for the device. -- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallDate** No content is currently available. -- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx -- **InventoryVersion** The version number of the inventory process generating the events. -- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. -- **LowerFilters** The identifiers of the Lower filters installed for the device. -- **Manufacturer** The manufacturer of the device. -- **MatchangID** No content is currently available. -- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Modeh** No content is currently available. -- **Model** Identifies the model of the device. -- **ParentId** The Device Instance ID of the parent of the device. -- **ProblemCode** The error code currently returned by the device, if applicable. -- **ProblmmCode** No content is currently available. -- **Provider** Identifies the device provider. -- **Service** The name of the device service. -- **STACKID** The list of hardware IDs for the stack. -- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. -- **UpperFilters** The identifiers of the Upper filters installed for the device. -- **UpxerClassFilters** No content is currently available. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove - -This event indicates that the InventoryDevicePnpRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync - -This event indicates that a new set of InventoryDevicePnpAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd - -This event sends basic metadata about the USB hubs on the device. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. -- **TotalUserConnectablePorts** Total number of connectable USB ports. -- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. - - -### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync - -This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. - -This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd - -This event provides the basic metadata about driver binaries running on the system. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **DrivdrCompany** No content is currently available. -- **DriverCheckSum** The checksum of the driver file. -- **DriverCompany** The company name that developed the driver. -- **DriverInBox** Is the driver included with the operating system? -- **DriverIsKernelMode** Is it a kernel mode driver? -- **DriverName** The file name of the driver. -- **DriverPackageStrongName** The strong name of the driver package -- **DriverSigned** The strong name of the driver package -- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. -- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. -- **DriverVersion** The version of the driver file. -- **ImageSize** The size of the driver file. -- **ImageSmze** No content is currently available. -- **Inf** The name of the INF file. -- **InventoryVersion** The version of the inventory file generating the events. -- **Product** The product name that is included in the driver file. -- **ProductVersion** The product version that is included in the driver file. -- **Service** The name of the service that is installed for the device. -- **WdfVersion** The Windows Driver Framework version. -- **WdfVers-on** No content is currently available. -- **WdfVersÿon** No content is currently available. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove - -This event indicates that the InventoryDriverBinary object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync - -This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd - -This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Class** The class name for the device driver. -- **ClassGuid** The class GUID for the device driver. -- **Date** The driver package date. -- **Directory** The path to the driver package. -- **DriverInBox** Is the driver included with the operating system? -- **Inf** The INF name of the driver package. -- **InventoryVersion** The version of the inventory file generating the events. -- **Provider** The provider for the driver package. -- **SubmissionId** The HLK submission ID for the driver package. -- **Version** The version of the driver package. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove - -This event indicates that the InventoryDriverPackageRemove object is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync - -This event indicates that a new set of InventoryDriverPackageAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory file generating the events. - - -### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. - - - -### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace - -This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. - - - -### Microsoft.Windows.Inventory.General.AppHealthStaticAdd - -This event sends details collected for a specific application on the source device. - -The following fields are available: - -- **AhaVersion** The binary version of the App Health Analyzer tool. -- **ApplicationErrors** The count of application errors from the event log. -- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). -- **device_level** Various JRE/JAVA versions installed on a particular device. -- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. -- **Jar** Flag to determine if an app has a Java JAR file dependency. -- **Jre** Flag to determine if an app has JRE framework dependency. -- **Jre_version** JRE versions an app has declared framework dependency for. -- **Name** Name of the application. -- **NonDPIAware** Flag to determine if an app is non-DPI aware. -- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. -- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. -- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. -- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. -- **VB6** Flag to determine if an app is based on VB6 framework. -- **VB6v2** Additional flag to determine if an app is based on VB6 framework. -- **Version** Version of the application. -- **VersionCheck** Flag to determine if an app has a static dependency on OS version. -- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. - - -### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync - -This event indicates the beginning of a series of AppHealthStaticAdd events. - -The following fields are available: - -- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. -- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. -- **Enhanced** Indicates the presence of the 'enhanced' command line argument. -- **StartTime** UTC date and time at which this event was sent. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd - -Provides data on the installed Office Add-ins. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **AddinCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInCLSID** The class identifier key for the Microsoft Office add-in. -- **AddInId** The identifier for the Microsoft Office add-in. -- **AddinType** The type of the Microsoft Office add-in. -- **BinFileTimestamp** The timestamp of the Office add-in. -- **BinFileVersion** The version of the Microsoft Office add-in. -- **Description** Description of the Microsoft Office add-in. -- **FileId** The file identifier of the Microsoft Office add-in. -- **FileSize** The file size of the Microsoft Office add-in. -- **FriendlyName** The friendly name for the Microsoft Office add-in. -- **FullPath** The full path to the Microsoft Office add-in. -- **InventoryVersion** The version of the inventory binary generating the events. -- **LoadBehavior** Integer that describes the load behavior. -- **LoadTime** Load time for the Office add-in. -- **OfficeApplication** The Microsoft Office application associated with the add-in. -- **OfficeArchitecture** The architecture of the add-in. -- **OfficeVersion** The Microsoft Office version for this add-in. -- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. -- **ProductCompany** The name of the company associated with the Office add-in. -- **ProductName** The product name associated with the Microsoft Office add-in. -- **ProductVersion** The version associated with the Office add-in. -- **ProgramId** The unique program identifier of the Microsoft Office add-in. -- **Provider** Name of the provider for this add-in. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd - -Provides data on the Office identifiers. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device -- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device -- **OMID** Identifier for the Office SQM Machine -- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit -- **OTenantId** Unique GUID representing the Microsoft O365 Tenant -- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 -- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd - -Provides data on Office-related Internet Explorer features. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. -- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. -- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag -- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request -- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) -- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts -- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords -- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control -- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted -- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) -- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL -- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior -- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows -- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd - -This event provides insight data on the installed Office products - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OfficeApplication** The name of the Office application. -- **OfficeArchitecture** The bitness of the Office application. -- **OfficeVersion** The version of the Office application. -- **Valóe** No content is currently available. -- **Value** The insights collected about this entity. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync - -This diagnostic event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd - -Describes Office Products installed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. -- **OC2rApps** A GUID the describes the Office Click-To-Run apps -- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus -- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word -- **OProductCodes** A GUID that describes the Office MSI products - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd - -This event describes various Office settings - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **BrowserFlags** Browser flags for Office-related products -- **ExchangeProviderFlags** Provider policies for Office Exchange -- **InventoryVersion** The version of the inventory binary generating the events. -- **SharedComputerLicensing** Office shared computer licensing policies - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync - -Indicates a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd - -This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Design** Count of files with design issues found. -- **Design_x64** Count of files with 64 bit design issues found. -- **DuplicateVBA** Count of files with duplicate VBA code. -- **HasVBA** Count of files with VBA code. -- **Inaccessible** Count of files that were inaccessible for scanning. -- **InventoryVersion** The version of the inventory binary generating the events. -- **Issues** Count of files with issues detected. -- **Issues_x64** Count of files with 64-bit issues detected. -- **IssuesNone** Count of files with no issues detected. -- **IssuesNone_x64** Count of files with no 64-bit issues detected. -- **Locked** Count of files that were locked, preventing scanning. -- **NoVBA** Count of files with no VBA inside. -- **Protected** Count of files that were password protected, preventing scanning. -- **RemLimited** Count of files that require limited remediation changes. -- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. -- **RemSignificant** Count of files that require significant remediation changes. -- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. -- **Score** Overall compatibility score calculated for scanned content. -- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. -- **Total** Total number of files scanned. -- **Validation** Count of files that require additional manual validation. -- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd - -This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Count** Count of total Microsoft Office VBA rule violations -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync - -This event indicates that a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **InventoryVersion** The version of the inventory binary generating the events. - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd - -Provides data on Unified Update Platform (UUP) products and what version they are at. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **Identifier** UUP identifier -- **LastActivatedVersion** Last activated version -- **PreviousVersion** Previous version -- **Source** UUP source -- **Version** UUP version - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove - -Indicates that this particular data object represented by the objectInstanceId is no longer present. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync - -Diagnostic event to indicate a new sync is being generated for this object type. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.Checksum - -This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. - -The following fields are available: - -- **CensusId** A unique hardware identifier. -- **ChecksumDictionary** A count of each operating system indicator. -- **PCFP** Equivalent to the InventoryId field that is found in other core events. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd - -These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - -The following fields are available: - -- **IndicatorValue** The indicator value. -- **Value** Describes an operating system indicator that may be relevant for the device upgrade. - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove - -This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync - -This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. - -This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). - - - -## Kernel events - -### IO - -This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. - -The following fields are available: - -- **BootAttemptCount** No content is currently available. -- **BootStatusPolicy** No content is currently available. -- **BootType** No content is currently available. -- **BytesRead** The total number of bytes read from or read by the OS upon system startup. -- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. -- **FirmwareResetReasonEmbeddedController** No content is currently available. -- **FirmwareResetReasonEmbeddedControllerAdditional** No content is currently available. -- **FirmwareResetReasonPch** No content is currently available. -- **FirmwareResetReasonPchAdditional** No content is currently available. -- **FirmwareResetReasonSupplied** No content is currently available. -- **LastBootSucceeded** No content is currently available. -- **LastShutdownSucceeded** No content is currently available. -- **MeasuredLaunchResume** No content is currently available. -- **MenuPolicy** No content is currently available. -- **RecoveryEnabled** No content is currently available. -- **UserInputTime** No content is currently available. - - -### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch - -OS information collected during Boot, used to evaluate the success of the upgrade process. - -The following fields are available: - -- **Boo|ApplicationId** No content is currently available. -- **BootApplicataonId** No content is currently available. -- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. -- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. -- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootStatusPolicy** Identifies the applicable Boot Status Policy. -- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). -- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. -- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPch** Reason for system reset provided by firmware. -- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. -- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). -- **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. -- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. -- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. -- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). -- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. -- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). -- **RecoveryEnabled** Indicates whether recovery is enabled. -- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. -- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. -- **UserInputTime** The amount of time the loader application spent waiting for user input. - - -## Miracast events - -### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd - -This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session - -The following fields are available: - -- **AudioChannelCount** The number of audio channels. -- **AudioSampleRate** The sample rate of audio in terms of samples per second. -- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. -- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. -- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. -- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. -- **ConnectorType** The type of connector used during the Miracast session. -- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. -- **EncodeCount** The count of total frames encoded in the session. -- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. -- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. -- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. -- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. -- **FirstFrameTime** The time (tick count) when the first frame is sent. -- **FirstLatencyMode** The first latency mode. -- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. -- **FrameCount** The total number of frames processed. -- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. -- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. -- **Glitches** The number of frames that failed to be delivered on time. -- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. -- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. -- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. -- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. -- **LastLatencyMode** The last reported latency mode. -- **LogTimeReference** The reference time, in tick counts. -- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. -- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. -- **MediaErrorCode** The error code reported by the media session, if applicable. -- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. -- **MiracastM1** The time (tick count) when the M1 request was sent. -- **MiracastM2** The time (tick count) when the M2 request was sent. -- **MiracastM3** The time (tick count) when the M3 request was sent. -- **MiracastM4** The time (tick count) when the M4 request was sent. -- **MiracastM5** The time (tick count) when the M5 request was sent. -- **MiracastM6** The time (tick count) when the M6 request was sent. -- **MiracastM7** The time (tick count) when the M7 request was sent. -- **MiracastSessionState** The state of the Miracast session when the connection ended. -- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. -- **ProfileCount** The count of profiles generated from the receiver M4 response. -- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. -- **RefreshRate** The refresh rate set on the remote display. -- **RotationSupported** Indicates if the Miracast receiver supports display rotation. -- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. -- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. -- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. -- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. -- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. -- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. -- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. -- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. -- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. -- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. -- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. -- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. -- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. -- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. -- **UIBCStatus** The result code reported by the UIBC setup process. -- **VideoBitrate** The starting bitrate for the video encoder. -- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. -- **VideoHeight** The height of encoded video frames. -- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. -- **VideoWidth** The width of encoded video frames. -- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. - - -## OneDrive events - -### Microsoft.OneDrive.Sync.Setup.APIOperation - -This event includes basic data about install and uninstall OneDrive API operations. - -The following fields are available: - -- **APIName** The name of the API. -- **Duration** How long the operation took. -- **IsSuccess** Was the operation successful? -- **ResultCode** The result code. -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.EndExperience - -This event includes a success or failure summary of the installation. - -The following fields are available: - -- **APIName** The name of the API. -- **HResult** HResult of the operation -- **IsSuccess** Whether the operation is successful or not -- **ScenarioName** The name of the scenario. - - -### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation - -This event is related to the OS version when the OS is upgraded with OneDrive installed. - -The following fields are available: - -- **CurrentOneDriveVersion** The current version of OneDrive. -- **CurrentOSBuildBranch** The current branch of the operating system. -- **CurrentOSBuildNumber** The current build number of the operating system. -- **CurrentOSVersion** The current version of the operating system. -- **HResult** The HResult of the operation. -- **SourceOSBuildBranch** The source branch of the operating system. -- **SourceOSBuildNumber** The source build number of the operating system. -- **SourceOSVersion** The source version of the operating system. - - -### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation - -This event is related to registering or unregistering the OneDrive update task. - -The following fields are available: - -- **APIName** The name of the API. -- **IsSuccess** Was the operation successful? -- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. -- **ScenarioName** The name of the scenario. -- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. - - -### Microsoft.OneDrive.Sync.Updater.ComponentInstallState - -This event includes basic data about the installation state of dependent OneDrive components. - -The following fields are available: - -- **ComponentName** The name of the dependent component. -- **isInstalled** Is the dependent component installed? - - -### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus - -This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken - -The following fields are available: - -- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. -- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. - - -### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult - -This event sends information describing the result of the update. - -The following fields are available: - -- **br** No content is currently available. -- **hr** The HResult of the operation. -- **IsLoggingE~abled** No content is currently available. -- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. -- **UpdaterVersion** The version of the updater. - - -### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult - -This event determines the status when downloading the OneDrive update configuration file. - -The following fields are available: - -- **hr** The HResult of the operation. - - -### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus - -This event determines the error code that was returned when verifying Internet connectivity. - -The following fields are available: - -- **winInetError** The HResult of the operation. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - -## Setup events - -### SetupPlatformTel.SetupPlatformTelActivityEvent - -This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time - - -### SetupPlatformTel.SetupPlatformTelActivityStarted - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - -The following fields are available: - -- **Name** The name of the dynamic update type. Example: GDR driver - - -### SetupPlatformTel.SetupPlatformTelActivityStopped - -This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. - - - -### SetupPlatformTel.SetupPlatformTelEvent - -This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. - -The following fields are available: - -- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. - - -## Software update events - -### SoftwareUpdateClientTelemetry.CheckForUpdates - -Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. -- **AllowCachedResults** Indicates if the scan allowed using cached results. -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BranchReadinessLevel** The servicing branch configured on the device. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). -- **DeferredUpdates** Update IDs which are currently being deferred until a later time -- **DeviceModel** What is the device model. -- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. -- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverGxclusionPolicy** No content is currently available. -- **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExtendedMetadataCabUrl** Hostname that is used to download an update. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. -- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. -- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePause9-8iod** No content is currently available. -- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **I#Version** No content is currently available. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBDualScaninabled** No content is currently available. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **IsWUfBinabled** No content is currently available. -- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MSIError** The last error that was encountered during a scan for updates. -- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEval}ated** No content is currently available. -- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked -- **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan -- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. -- **Online** Indicates if this was an online scan. -- **PausedUpdates** A list of UpdateIds which that currently being paused. -- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. -- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePause9-8iod** No content is currently available. -- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **S}ncType** No content is currently available. -- **ScanDuratioInSeconds** No content is currently available. -- **ScanDurationInSeconds** The number of seconds a scan took -- **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanPrps** No content is currently available. -- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). -- **ServiceUrl** The environment URL a device is configured to scan with -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **SyncType** Describes the type of scan the event was -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatureM** No content is currently available. -- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. -- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Commit - -This event tracks the commit process post the update installation when software update client is trying to update the device. - -The following fields are available: - -- **BiosFamily** Device family as defined in the system BIOS -- **BiosName** Name of the system BIOS -- **BiosReleaseDate** Release date of the system BIOS -- **BiosSKUNumber** Device SKU as defined in the system BIOS -- **BIOSVendor** Vendor of the system BIOS -- **BiosVersion** Version of the system BIOS -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRevisionNumber** Identifies the revision number of the content bundle -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** Version number of the software distribution client -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** Device model as defined in the system bios -- **EventInstanceID** A globally unique identifier for event instance -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". -- **FlightId** The specific id of the flight the device is getting -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **SystemBIOSMajorRelease** Major release version of the system bios -- **SystemBIOSMinorRelease** Minor release version of the system bios -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Download - -Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). - -The following fields are available: - -- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. -- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. -- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. -- **AppXDownloadScope** Indicates the scope of the download for application content. -- **AppXScope** Indicates the scope of the app download. -- **aundleBy1esDownl?aded** No content is currently available. -- **B1ndleRepeatFailCount** No content is currently available. -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. -- **BundleId** Identifier associated with the specific content bundle. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). -- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. -- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **Cbs5ethod** No content is currently available. -- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. -- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. -- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. -- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. -- **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **DeviceModel** The model of the device. -- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation properties in the form of a bitmask. -- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenarao** No content is currently available. -- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. -- **EventType** Identifies the type of the event (Child, Bundle, or Driver). -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **flightBuildNumber** No content is currently available. -- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlightId** The specific ID of the flight (pre-release build) the device is getting. -- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). -- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **HostName** The hostname URL the content is downloading from. -- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. -- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update -- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWVfBDualScanEnabled** No content is currently available. -- **IsWVfBEnabled** No content is currently available. -- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. -- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) -- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." -- **PackageFullName** The package name of the content. -- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. -- **RegulationReason** The reason that the update is regulated -- **RegulationReóult** No content is currently available. -- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. -- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RelqtedCV** No content is currently available. -- **RepeatFailCount** Indicates whether this specific content has previously failed. -- **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionNumber** The revision number of the specified piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. -- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. -- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. -- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. -- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalEx8ectedBydes** No content is currently available. -- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. -- **UpdateId** An identifier associated with the specific piece of content. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsecDO** No content is currently available. -- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. -- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **YsWUfBEnabled** No content is currently available. - - -### SoftwareUpdateClientTelemetry.DownloadCheckpoint - -This event provides a checkpoint between each of the Windows Update download phases for UUP content - -The following fields are available: - -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed -- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough -- **FileId** A hash that uniquely identifies a file -- **FileName** Name of the downloaded file -- **FlightId** The unique identifier for each flight -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RevisionNumber** Unique revision number of Update -- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) -- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) -- **UpdateId** Unique Update ID -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### SoftwareUpdateClientTelemetry.DownloadHeartbeat - -This event allows tracking of ongoing downloads and contains data to explain the current state of the download - -The following fields are available: - -- **BytesTotal** Total bytes to transfer for this content -- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat -- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client -- **ClientVersion** The version number of the software distribution client -- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat -- **CurrentError** Last (transient) error encountered by the active download -- **DownloadFlags** Flags indicating if power state is ignored -- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) -- **EventType** Possible values are "Child", "Bundle", or "Driver" -- **FlightId** The unique identifier for each flight -- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" -- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any -- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any -- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) -- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one -- **ResumeCount** Number of times this active download has resumed from a suspended state -- **RevisionNumber** Identifies the revision number of this specific piece of content -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) -- **SuspendCount** Number of times this active download has entered a suspended state -- **SuspendReason** Last reason for why this active download entered a suspended state -- **UpdateId** Identifier associated with the specific piece of content -- **WUDeviceID** Unique device id controlled by the software distribution client - - -### SoftwareUpdateClientTelemetry.Install - -This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. - -The following fields are available: - -- **BiosFamily** The family of the BIOS (Basic Input Output System). -- **BiosName** The name of the device BIOS. -- **BiosReleaseDate** The release date of the device BIOS. -- **BiosSKUNumber** The sku number of the device BIOS. -- **BIOSVendor** The vendor of the BIOS. -- **BiosVersion** The version of the BIOS. -- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **ClientVersion** The version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. -- **CSIErrorType** The stage of CBS installation where it failed. -- **CurrentMobileOperator** The mobile operator to which the device is currently connected. -- **DeploymentProviderMode** The mode of operation of the update deployment provider. -- **DeviceModel** The device model. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **EventType** Possible values are Child, Bundle, or Driver. -- **ExtendedErrorCode** The extended error code. -- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. -- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. -- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). -- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether this update is a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. -- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. -- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. -- **MsiAction** The stage of MSI installation where it failed. -- **MsiProductCode** The unique identifier of the MSI installer. -- **PackageFullName** The package name of the content being installed. -- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. -- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. -- **RevisionNumber** The revision number of this specific piece of content. -- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). -- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. -- **ShippingMobileOperator** The mobile operator that a device shipped on. -- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). -- **SystemBIOSMajorRelease** Major version of the BIOS. -- **SystemBIOSMinorRelease** Minor version of the BIOS. -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **Targeti~gVersion** No content is currently available. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **TransactionCode** The ID that represents a given MSI installation. -- **UpdateId** Unique update ID. -- **UpdateID** An identifier associated with the specific piece of content. -- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. -- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. -- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### SoftwareUpdateClientTelemetry.Revert - -Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **CSIErrorType** Stage of CBS installation that failed. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **EventType** Event type (Child, Bundle, Release, or Driver). -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** The identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.TaskRun - -Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CmdLineArgs** Command line arguments passed in by the caller. -- **EventInstanceID** A globally unique identifier for the event instance. -- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.Uninstall - -Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). - -The following fields are available: - -- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. -- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. -- **BundleRevisionNumber** Identifies the revision number of the content bundle. -- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. -- **ClientVersion** Version number of the software distribution client. -- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. -- **DriverPingBack** Contains information about the previous driver and system state. -- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. -- **EventInstanceID** A globally unique identifier for event instance. -- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). -- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. -- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FlightBuildNumber** Indicates the build number of the flight. -- **FlightId** The specific ID of the flight the device is getting. -- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). -- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. -- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. -- **IsFirmware** Indicates whether an update was a firmware update. -- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. -- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. -- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. -- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. -- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. -- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. -- **RepeatFailCount** Indicates whether this specific piece of content previously failed. -- **RevisionNumber** Identifies the revision number of this specific piece of content. -- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). -- **StatusCode** Result code of the event (success, cancellation, failure code HResult). -- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. -- **UpdateId** Identifier associated with the specific piece of content. -- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). -- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. -- **WUDeviceID** Unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateDetected - -This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. - -The following fields are available: - -- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. -- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. -- **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfA0plicableUpdates** No content is currently available. -- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. -- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. -- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). -- **WUDeviceID** The unique device ID controlled by the software distribution client. - - -### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity - -Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. - -The following fields are available: - -- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. -- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. -- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. -- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. -- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. -- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. -- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). -- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. -- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. -- **RevisionId** The revision ID for a specific piece of content. -- **RevisionNumber** The revision number for a specific piece of content. -- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store -- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. -- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. -- **SHA256OfTimestampToken** An encoded string of the timestamp token. -- **SignatureAlgorithm** The hash algorithm for the metadata signature. -- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". -- **StatusCode** Result code of the event (success, cancellation, failure code HResult) -- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. -- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. -- **UpdateId** The update ID for a specific piece of content. -- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. - - -## System Resource Usage Monitor events - -### Microsoft.Windows.Srum.Sdp.CpuUsage - -This event provides information on CPU usage. - -The following fields are available: - -- **UsageMax** The maximum of hourly average CPU usage. -- **UsageMean** The mean of hourly average CPU usage. -- **UsageMedian** The median of hourly average CPU usage. -- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. -- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. - - -### Microsoft.Windows.Srum.Sdp.NetworkUsage - -This event provides information on network usage. - -The following fields are available: - -- **AdapterGuid** The unique ID of the adapter. -- **BytesTotalMax** The maximum of the hourly average bytes total. -- **BytesTotalMean** The mean of the hourly average bytes total. -- **BytesTotalMedian** The median of the hourly average bytes total. -- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. -- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. -- **LinkSpeed** The adapter link speed. - - -## Update events - -### Update360Telemetry.Revert - -This event sends data relating to the Revert phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the Revert phase. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RebootRequired** Indicates reboot is required. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **RevertResult** The result code returned for the Revert operation. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentCommit - -This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentDownloadRequest - -This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. - -The following fields are available: - -- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. -- **DownloadRequests** Number of times a download was retried. -- **ErrorCode** The error code returned for the current download request phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique ID for each flight. -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCCoegoriesSkipped** No content is currently available. -- **PackageCountOptional** Number of optional packages requested. -- **PackageCountRequired** Number of required packages requested. -- **PackageCountTotal** Total number of packages needed. -- **PackageCountTotalCanonical** Total number of canonical packages. -- **PackageCountTotalDiff** Total number of diff packages. -- **PackageCountTotalExpress** Total number of express packages. -- **PackageCountTotalPSFX** The total number of PSFX packages. -- **PackageExpressType** Type of express package. -- **PackageSizeCanonical** Size of canonical packages in bytes. -- **PackageSizeDiff** Size of diff packages in bytes. -- **PackageSizeExpress** Size of express packages in bytes. -- **PackageSizePSFX** The size of PSFX packages, in bytes. -- **RangeRequestSsCoe** No content is currently available. -- **RangeRequestState** Indicates the range request type used. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the download request phase of update. -- **SandboxTaggedForReserves** The sandbox for reserves. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentExpand - -This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ElapsedTickCount** Time taken for expand phase. -- **EndFreeSpace** Free space after expand phase. -- **EndSandboxSize** Sandbox size after expand phase. -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **StartFreeSpace** Free space before expand phase. -- **StartSandboxSize** Sandbox size after expand phase. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentFellBackToCanonical - -This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **ObjectId** Unique value for each Update Agent mode. -- **PackageCount** Number of packages that feel back to canonical. -- **PackageList** PackageIds which fell back to canonical. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInitialize - -This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **FlightId** Unique ID for each flight. -- **FlightMetadata** Contains the FlightId and the build being flighted. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** Outcome of the install phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentInstall - -This event sends data for the install phase of updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current install phase. -- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. -- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). -- **InternalFailureResult** Indicates a non-fatal error from a plugin. -- **ObjectId** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** The result for the current install phase. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMerge - -The UpdateAgentMerge event sends data on the merge phase when updating Windows. - -The following fields are available: - -- **ErrorCode** The error code returned for the current merge phase. -- **FlightId** Unique ID for each flight. -- **MergeId** The unique ID to join two update sessions being merged. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Related correlation vector value. -- **Result** Outcome of the merge phase of the update. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentMitigationResult - -This event sends data indicating the result of each update agent mitigation. - -The following fields are available: - -- **Applicable** Indicates whether the mitigation is applicable for the current update. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightId** Unique identifier for each flight. -- **Index** The mitigation index of this particular mitigation. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly name of the mitigation. -- **ObjectId** Unique value for each Update Agent mode. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **UpdateId** Unique ID for each Update. - - -### Update360Telemetry.UpdateAgentMitigationSummary - -This event sends a summary of all the update agent mitigations available for an this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **Failed** The count of mitigations that failed. -- **FlightId** Unique identifier for each flight. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** The HResult of this operation. -- **ScenarioId** The update agent scenario ID. -- **SessionId** Unique value for each update attempt. -- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). -- **Total** Total number of mitigations that were available. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. - -The following fields are available: - -- **FlightId** Unique ID for each flight. -- **Mode** Indicates the mode that has started. -- **ObjectId** Unique value for each Update Agent mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **Version** Version of update - - -### Update360Telemetry.UpdateAgentOneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **Count** The count of applicable OneSettings for the device. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. -- **Values** The values sent back to the device, if applicable. - - -### Update360Telemetry.UpdateAgentPostRebootResult - -This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. - -The following fields are available: - -- **ErrorCode** The error code returned for the current post reboot phase. -- **FlightId** The specific ID of the Windows Insider build the device is getting. -- **ObjectId** Unique value for each Update Agent mode. -- **PostRebootResult** Indicates the Hresult. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. - - -### Update360Telemetry.UpdateAgentReboot - -This event sends information indicating that a request has been sent to suspend an update. - -The following fields are available: - -- **ErrorCode** The error code returned for the current reboot. -- **FlightId** Unique ID for the flight (test instance version). -- **ObjectId** The unique value for each Update Agent mode. -- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. -- **Result** The HResult of the event. -- **ScenarioId** The ID of the update scenario. -- **SessionId** The ID of the update attempt. -- **UpdateId** The ID of the update. - - -### Update360Telemetry.UpdateAgentSetupBoxLaunch - -The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. - -The following fields are available: - -- **ContainsExpressPackage** Indicates whether the download package is express. -- **FlightId** Unique ID for each flight. -- **FreeSpace** Free space on OS partition. -- **InstallCount** Number of install attempts using the same sandbox. -- **ObjectId** Unique value for each Update Agent mode. -- **Quiet** Indicates whether setup is running in quiet mode. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **SandboxSize** Size of the sandbox. -- **ScenarioId** Indicates the update scenario. -- **SessionId** Unique value for each update attempt. -- **SetupMode** Mode of setup to be launched. -- **UpdateId** Unique ID for each Update. -- **UserSession** Indicates whether install was invoked by user actions. - - -## Update notification events - -### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat - -This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. - -The following fields are available: - -- **CampaignConfigVersion** Configuration version for the current campaign. -- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). -- **ConfigCatalogVersion** Current catalog version of UNP. -- **ContentVersion** Content version for the current campaign on UNP. -- **CV** Correlation vector. -- **DetectorVersion** Most recently run detector version for the current campaign on UNP. -- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. -- **PackageVersion** Current UNP package version. - - -## Upgrade events - -### FacilitatorTelemetry.DCATDownload - -This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **DownloadSize** Download size of payload. -- **ElapsedTime** Time taken to download payload. -- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. -- **ResultCode** Result returned by the Facilitator DCAT call. -- **Scenario** Dynamic update scenario (Image DU, or Setup DU). -- **Type** Type of package that was downloaded. -- **UpdateId** The ID of the update that was downloaded. - - -### FacilitatorTelemetry.DUDownload - -This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. - -The following fields are available: - -- **DownloadRequestAttributes** The attributes sent for download. -- **PackageCategoriesFailed** Lists the categories of packages that failed to download. -- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. -- **ResultCode** The result of the event execution. -- **Scenario** Identifies the active Download scenario. -- **Url** The URL the download request was sent to. -- **Version** Identifies the version of Facilitator used. - - -### FacilitatorTelemetry.InitializeDU - -This event determines whether devices received additional or critical supplemental content during an OS upgrade. - -The following fields are available: - -- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. -- **DownloadRequestAttributes** The attributes we send to DCAT. -- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **Url** The Delivery Catalog (DCAT) URL we send the request to. -- **Version** Version of Facilitator. - - -### Setup360Telemetry.Downlevel - -This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the downlevel OS. -- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). -- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). -- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** An ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. - - -### Setup360Telemetry.Finalize - -This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.OsUninstall - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PostRebootInstall - -This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback -- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. - - -### Setup360Telemetry.PreDownloadQuiet - -This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreDownloadUX - -This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **HostOSBuildNumber** The build number of the previous operating system. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). -- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). -- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** ID that uniquely identifies a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.PreInstallQuiet - -This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. -- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -### Setup360Telemetry.PreInstallUX - -This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. - -The following fields are available: - -- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. -- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** Windows Update client ID. - - -### Setup360Telemetry.Setup360 - -This event sends data about OS deployment scenarios, to help keep Windows up-to-date. - -The following fields are available: - -- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FieldName** Retrieves the data point. -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **ReportId** Retrieves the report ID. -- **ScenarioId** Retrieves the deployment scenario. -- **Value** Retrieves the value associated with the corresponding FieldName. - - -### Setup360Telemetry.Setup360DynamicUpdate - -This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. - -The following fields are available: - -- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. -- **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **Operation** Facilitator’s last known operation (scan, download, etc.). -- **ReportId** ID for tying together events stream side. -- **ResultCode** Result returned for the entire setup operation. -- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). -- **ScenarioId** Identifies the update scenario. -- **TargetBranch** Branch of the target OS. -- **TargetBuild** Build of the target OS. - - -### Setup360Telemetry.Setup360MitigationResult - -This event sends data indicating the result of each setup mitigation. - -The following fields are available: - -- **Applicable** TRUE if the mitigation is applicable for the current update. -- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **CommandCount** The number of command operations in the mitigation entry. -- **CustomCount** The number of custom operations in the mitigation entry. -- **FileCount** The number of file operations in the mitigation entry. -- **FlightData** The unique identifier for each flight (test release). -- **Index** The mitigation index of this particular mitigation. -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **Name** The friendly (descriptive) name of the mitigation. -- **OperationIndex** The mitigation operation index (in the event of a failure). -- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). -- **RegistryCount** The number of registry operations in the mitigation entry. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). - - -### Setup360Telemetry.Setup360MitigationSummary - -This event sends a summary of all the setup mitigations available for this update. - -The following fields are available: - -- **Applicable** The count of mitigations that were applicable to the system and scenario. -- **ClientId** The Windows Update client ID passed to Setup. -- **Failed** The count of mitigations that failed. -- **FlightData** The unique identifier for each flight (test release). -- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. -- **MitigationScenario** The update scenario in which the mitigations were attempted. -- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. -- **Result** HResult of this operation. -- **ScenarioId** Setup360 flow type. -- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). -- **Total** The total number of mitigations that were available. - - -### Setup360Telemetry.Setup360OneSettings - -This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. - -The following fields are available: - -- **ClientId** The Windows Update client ID passed to Setup. -- **Count** The count of applicable OneSettings for the device. -- **FlightData** The ID for the flight (test instance version). -- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. -- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. -- **ReportId** The Update ID passed to Setup. -- **Result** The HResult of the event error. -- **ScenarioId** The update scenario ID. -- **Values** Values sent back to the device, if applicable. - - -### Setup360Telemetry.UnexpectedEvent - -This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. - -The following fields are available: - -- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FlightData** Unique value that identifies the flight. -- **HostOSBuildNumber** The build number of the previous OS. -- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). -- **InstanceId** A unique GUID that identifies each instance of setuphost.exe -- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. -- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. -- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. -- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. -- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. -- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). -- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. -- **TestId** A string to uniquely identify a group of events. -- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. - - -## Windows as a Service diagnostic events - -### Microsoft.Windows.WaaSMedic.SummaryEvent - -Result of the WaaSMedic operation. - -The following fields are available: - -- **callerApplication** The name of the calling application. -- **capsuleCount** The number of Sediment Pack capsules. -- **capsuleFailureCount** The number of capsule failures. -- **detectionSummary** Result of each applicable detection that was run. -- **featureAssessmentImpact** WaaS Assessment impact for feature updates. -- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. -- **hrEngineResult** Error code from the engine operation. -- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. -- **initSummary** Summary data of the initialization method. -- **insufficientSessions** Device not eligible for diagnostics. -- **isInteractiveMode** The user started a run of WaaSMedic. -- **isManaged** Device is managed for updates. -- **isWUConnected** Device is connected to Windows Update. -- **noMoreActions** No more applicable diagnostics. -- **pluginFailureCount** The number of plugins that have failed. -- **pluginsCount** The number of plugins. -- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. -- **usingBackupFeatureAssessment** Relying on backup feature assessment. -- **usingBackupQualityAssessment** Relying on backup quality assessment. -- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. -- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. -- **versionString** Version of the WaaSMedic engine. -- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. - - -## Windows Error Reporting events - -### Microsoft.Windows.WERVertical.OSCrash - -This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. - -The following fields are available: - -- **BootId** Uint32 identifying the boot number for this device. -- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. -- **BugCheckParameter1** Uint64 parameter providing additional information. -- **BugCheckParameter2** Uint64 parameter providing additional information. -- **BugCheckParameter3** Uint64 parameter providing additional information. -- **BugCheckParameter4** Uint64 parameter providing additional information. -- **DumpFileAttributes** Codes that identify the type of data contained in the dump file -- **DumpFileSize** Size of the dump file -- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise -- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). - - -## Windows Error Reporting MTT events - -### Microsoft.Windows.WER.MTT.Denominator - -This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. - -The following fields are available: - -- **DPRange** Maximum mean value range. -- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. -- **Value** Standard UTC emitted DP value structure See [Value](#value). - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -## Windows Store events - -### Microsoft.Windows.Store.StoreActivating - -This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. - - - -### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation - -This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The Item Bundle ID. -- **CategoryId** The Item Category ID. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Was this a mandatory update? -- **IsRemediation** Was this a remediation install? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Flag indicating if this is an update. -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The product family name of the product being installed. -- **ProductId** The identity of the package or packages being installed. -- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. -- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds - -This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare - -This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. - - - -### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation - -This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. -- **AttemptNumber** Total number of installation attempts. -- **BundleId** The identity of the Windows Insider build that is associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Was this requested by a user? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this an automatic restore of a previously acquired product? -- **IsUpdate** Is this a product update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of all packages to be downloaded and installed. -- **PreviousHResult** The previous HResult code. -- **PreviousInstallState** Previous installation state before it was canceled. -- **ProductId** The name of the package or packages requested for installation. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. -- **UserAttemptNumber** Total number of user attempts to install before it was canceled. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest - -This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Product ID of the app being installed. -- **HResult** HResult code of the action being performed. -- **IsBundle** Is this a bundle? -- **PackageFamilyName** The name of the package being installed. -- **ProductId** The Store Product ID of the product being installed. -- **SkuId** Specific edition of the item being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense - -This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. -- **AttemptNumber** The total number of attempts to acquire this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** HResult code to show the result of the operation (success/failure). -- **IsBundle** Is this a bundle? -- **IsInteractive** Did the user initiate the installation? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this happening after a device restore? -- **IsUpdate** Is this an update? -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to acquire this product. -- **UserAttemptNumber** The number of attempts by the user to acquire this product -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndDownload - -This event is sent after an app is downloaded to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** Number of retry attempts before it was canceled. -- **BundleId** The identity of the Windows Insider build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **DownloadSize** The total size of the download. -- **ExtendedHResult** Any extended HResult error codes. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this initiated by the user? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this a restore of a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The parent bundle ID (if it's part of a bundle). -- **PFN** The Product Family Name of the app being download. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The number of attempts by the system to download. -- **UserAttemptNumber** The number of attempts by the user to download. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate - -This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds - -This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed before this operation. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndInstall - -This event is sent after a product has been installed to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **ExtendedHResult** The extended HResult error code. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this an interactive installation? -- **IsMandatory** Is this a mandatory installation? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this automatically restoring a previously acquired product? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** Product Family Name of the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates - -This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AsOnline** No content is currently available. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractive** Is this user requested? -- **IsOnline** Is the request doing an online check? - - -### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages - -This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData - -This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **ProductId** The Store Product ID for the product being installed. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of system attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare - -This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. - -The following fields are available: - -- **HResult** The result code of the last action performed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete - -This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FailedRetry** Indicates whether the installation or update retry was successful. -- **HResult** The HResult code of the operation. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate - -This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The name of the product catalog from which this app was chosen. -- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. -- **PFN** The Package Family Name of the app that is being installed or updated. -- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. -- **ProductId** The product ID of the app that is being updated or installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest - -This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **BundleId** The identity of the build associated with this product. -- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specific edition ID being installed. -- **VolumePath** The disk path of the installation. - - -### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation - -This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The total number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The Product Full Name. -- **PreviousHResult** The result code of the last action performed before this operation. -- **PreviousInstallState** Previous state before the installation or update was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector of a previous performed action on this product. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation - -This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. - -The following fields are available: - -- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. -- **AttemptNumber** The number of retry attempts before it was canceled. -- **BundleId** The identity of the build associated with this product. -- **CategoryId** The identity of the package or packages being installed. -- **ClientAppId** The identity of the app that initiated this operation. -- **HResult** The result code of the last action performed before this operation. -- **IsBundle** Is this a bundle? -- **IsInteractive** Is this user requested? -- **IsMandatory** Is this a mandatory update? -- **IsRemediation** Is this repairing a previous installation? -- **IsRestore** Is this restoring previously acquired content? -- **IsUpdate** Is this an update? -- **IsUserRetry** Did the user initiate the retry? -- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). -- **PFN** The name of the package or packages requested for install. -- **PreviousHResult** The previous HResult error code. -- **PreviousInstallState** Previous state before the installation was paused. -- **ProductId** The Store Product ID for the product being installed. -- **RelatedCV** Correlation Vector for the original install before it was resumed. -- **ResumeClientId** The ID of the app that initiated the resume operation. -- **SystemAttemptNumber** The total number of system attempts. -- **UserAttemptNumber** The total number of user attempts. -- **WUContentId** The Windows Update content ID. - - -### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest - -This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **ProductId** The Store Product ID for the product being installed. - - -### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest - -This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **CatalogId** The Store Catalog ID for the product being installed. -- **ProductId** The Store Product ID for the product being installed. -- **SkuId** Specfic edition of the app being updated. - - -### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest - -This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. - -The following fields are available: - -- **PFamN** The name of the app that is requested for update. - - -## Windows System Kit events - -### Microsoft.Windows.Kits.WSK.WskImageCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. - -The following fields are available: - -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskImageCustomization - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. - -The following fields are available: - -- **CustomizationMode** Indicates the mode of the customization (new or updating). -- **CustomizationType** Indicates the type of customization (drivers or apps). -- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. -- **WskVersion** The version of the Windows System Kit being used. - - -### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate - -This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. - -The following fields are available: - -- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. -- **OsEdition** The Operating System Edition that the workspace will target. -- **Phase** The image creation phase. Values are “Start” or “End”. -- **WorkspaceArchitecture** The operating system architecture that the workspace will target. -- **WorkspaceOsEdition** The operating system edition that the workspace will target. -- **WskVersion** The version of the Windows System Kit being used. - - -## Windows Update Delivery Optimization events - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled - -This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download being done in the background? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller. -- **reasonCode** Reason the action or event occurred. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the file download session. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted - -This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **bytesFromCacheServer** Bytes received from a cache host. -- **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. -- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. -- **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. -- **bytesFromPeers** The number of bytes received from a peer in the same LAN. -- **bytesRequested** The total number of bytes requested for download. -- **cacheServerBonnectionCount** No content is currently available. -- **cacheServerConnectionCount** Number of connections made to cache hosts. -- **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. -- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. -- **cdnIp** The IP address of the source CDN. -- **cdnUrl** Url of the source Content Distribution Network (CDN). -- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dnErrorCounts** No content is currently available. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). -- **downlinkUsageBps** The download speed (in bytes per second). -- **downloadMode** The download mode used for this file download session. -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. -- **fileID** The ID of the file being downloaded. -- **fileSize** The size of the file being downloaded. -- **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gdnConnectionCount** No content is currently available. -- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConnectionCo** No content is currently available. -- **groupConnectionCount** The total number of connections made to peers in the same group. -- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. -- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. -- **numPeers** The total number of peers used for this download. -- **numPeersLocal** The total number of local peers used for this download. -- **predefinedCallerName** The name of the API Caller. -- **restrictedU`load** No content is currently available. -- **restrictedUpload** Is the upload restricted? -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **totalTimeMs** Duration of the download (in seconds). -- **updateID** The ID of the update being downloaded. -- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkUsageBps** The upload speed (in bytes per second). -- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused - -This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **background** Is the download a background download? -- **cdnUrl** The URL of the source CDN (Content Delivery Network). -- **errorCode** The error code that was returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being paused. -- **isVpn** Is the device connected to a Virtual Private Network? -- **jobID** Identifier for the Windows Update job. -- **predefinedCallerName** The name of the API Caller object. -- **reasonCode** The reason for pausing the download. -- **routeToCacheServer** The cache server setting, source, and value. -- **sessionID** The ID of the download session. -- **updateID** The ID of the update being paused. - - -### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted - -This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **ActiveNetworkConnection** No content is currently available. -- **background** Indicates whether the download is happening in the background. -- **bytesRequested** Number of bytes requested for the download. -- **cdnUrl** The URL of the source Content Distribution Network (CDN). -- **costFlags** A set of flags representing network cost. -- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). -- **diceRoll** Random number used for determining if a client will use peering. -- **doClientVersion** The version of the Delivery Optimization client. -- **doErrorCode** The Delivery Optimization error code that was returned. -- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). -- **downloadModeReason** Reason for the download. -- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **errorCode** The error code that was returned. -- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. -- **fileID** The ID of the file being downloaded. -- **filePath** The path to where the downloaded file will be written. -- **fileSize** Total file size of the file that was downloaded. -- **fileSizeCaller** Value for total file size provided by our caller. -- **groupID** ID for the group. -- **IsBootCritical** No content is currently available. -- **isEncrypted** Indicates whether the download is encrypted. -- **isVpn** Indicates whether the device is connected to a Virtual Private Network. -- **jobID** The ID of the Windows Update job. -- **peerID** The ID for this delivery optimization client. -- **predefinedCallerName** Name of the API caller. -- **routeToCacheServer** Cache server setting, source, and value. -- **SdbEntries** No content is currently available. -- **sessionID** The ID for the file download session. -- **setConfigs** A JSON representation of the configurations that have been set, and their sources. -- **updateID** The ID of the update being downloaded. -- **usedMemoryStream** Indicates whether the download used memory streaming. -- **WuDriverCoverage** No content is currently available. -- **WuDriverUpdateId** No content is currently available. -- **WuPopulatedFromId** No content is currently available. - - -### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication - -This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. - -The following fields are available: - -- **cdnHeaders** The HTTP headers returned by the CDN. -- **cdnIp** The IP address of the CDN. -- **cdnUrl** The URL of the CDN. -- **errorCode** The error code that was returned. -- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET -- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). -- **requestOffset** The byte offset within the file in the sent request. -- **requestSize** The size of the range requested from the CDN. -- **responseSize** The size of the range response received from the CDN. -- **sessionID** The ID of the download session. - - -### Microsoft.OSG.DU.DeliveryOptClient.JobError - -This event represents a Windows Update job error. It allows for investigation of top errors. - -The following fields are available: - -- **cdnIp** The IP Address of the source CDN (Content Delivery Network). -- **doErrorCode** Error code returned for delivery optimization. -- **errorCode** The error code returned. -- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. -- **fileID** The ID of the file being downloaded. -- **jobID** The Windows Update job ID. - - -## Windows Update events - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary - -This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **activated** Whether the entire device manifest update is considered activated and in use. -- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. -- **flightId** Unique ID for each flight. -- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. -- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. -- **objectId** Unique value for each diagnostics session. -- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **scenarioId** Indicates the update scenario. -- **sessionId** Unique value for each update session. -- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. -- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. -- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. -- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. -- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. -- **updateId** The unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit - -This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** The unique GUID for each diagnostics session. -- **relatedCV** A correlation vector value generated from the latest USO scan. -- **result** Outcome of the initialization of the session. -- **scenarioId** Identifies the Update scenario. -- **sessionId** The unique value for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest - -This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **objectId** Unique value for each Update Agent mode. -- **packageCountOptional** Number of optional packages requested. -- **packageCountRequired** Number of required packages requested. -- **packageCountTotal** Total number of packages needed. -- **packageCountTotalCanonical** Total number of canonical packages. -- **packageCountTotalDiff** Total number of diff packages. -- **packageCountTotalExpress** Total number of express packages. -- **packageSizeCanonical** Size of canonical packages in bytes. -- **packageSizeDiff** Size of diff packages in bytes. -- **packageSizeExpress** Size of express packages in bytes. -- **rangeRequestState** Represents the state of the download range request. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the download request phase of update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize - -This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current session initialization. -- **flightId** The unique identifier for each flight. -- **flightMetadata** Contains the FlightId and the build being flighted. -- **objectId** Unique value for each Update Agent mode. -- **relatedCV** Correlation vector value generated from the latest USO scan. -- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). -- **sessionId** Unique value for each Update Agent mode attempt. -- **updateId** Unique ID for each update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall - -This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **errorCode** The error code returned for the current install phase. -- **flightId** The unique identifier for each flight (pre-release builds). -- **objectId** The unique identifier for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **result** Outcome of the install phase of the update. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart - -This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. - -The following fields are available: - -- **flightId** The unique identifier for each flight (pre-release builds). -- **mode** Indicates the active Update Agent mode. -- **objectId** Unique value for each diagnostics session. -- **relatedCV** Correlation vector value generated from the latest scan. -- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. -- **sessionId** The unique identifier for each update session. -- **updateId** The unique identifier for each Update. - - -### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed - -This event indicates that a notification dialog box is about to be displayed to user. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. -- **DaysSinceRebootRequired** Number of days since restart was required. -- **DeviceLocalTime** The local time on the device sending the event. -- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. -- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. -- **ETag** OneSettings versioning value. -- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. -- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. -- **NotificationUxState** Indicates which dialog box is shown. -- **NotificationUxStateString** Indicates which dialog box is shown. -- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). -- **RebootVersion** Version of DTE. -- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog - -This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose on this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog - -This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog - -This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time of the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in this dialog box. -- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog - -This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. - -The following fields are available: - -- **DeviceLocalTime** Time the dialog box was shown on the local device. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the dialog box. -- **RebootVersion** Version of DTE. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that user chose in this dialog box. -- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog - -This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. - -The following fields are available: - -- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). -- **ETag** The OneSettings versioning value. -- **ExitCode** Indicates how users exited the reboot reminder dialog box. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. -- **UserResponseString** The option chosen by the user on the reboot dialog box. -- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). - - -### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast - -This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. - -The following fields are available: - -- **DeviceLocalTime** The local time on the device sending the event. -- **ETag** OneSettings versioning value. -- **ExitCode** Indicates how users exited the pop-up banner. -- **RebootVersion** The version of the reboot logic. -- **UpdateId** The ID of the update that is pending restart to finish installation. -- **UpdateRevision** The revision of the update that is pending restart to finish installation. -- **UserResponseString** The option that the user chose in the pop-up banner. -- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. - - -### Microsoft.Windows.Update.NotificationUx.RebootScheduled - -Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. -- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. -- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). -- **rebootState** The current state of the restart. -- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. -- **revisionNumber** Revision number of the update that is getting installed with this restart. -- **scheduledRebootTime** Time of the scheduled restart. -- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. -- **updateId** ID of the update that is getting installed with this restart. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy - -This event indicates a policy is present that may restrict update activity to outside of active hours. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours - -This event indicates that update activity was blocked because it is within the active hours window. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel - -This event indicates that Windows Update activity was blocked due to low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** Device ID. - - -### Microsoft.Windows.Update.Orchestrator.DeferRestart - -This event indicates that a restart required for installing updates was postponed. - -The following fields are available: - -- **displayNeededReason** List of reasons for needing display. -- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). -- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). -- **gameModeReason** Name of the executable that caused the game mode state check to start. -- **ignoredReason** List of reasons that were intentionally ignored. -- **IgnoreReasonsForRestart** List of reasons why restart was deferred. -- **revisionNumber** Update ID revision number. -- **systemNeededReason** List of reasons why system is needed. -- **updateId** Update ID. -- **updateScenarioType** Update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Detection - -This event indicates that a scan for a Windows Update occurred. - -The following fields are available: - -- **deferReason** The reason why the device could not check for updates. -- **detectionBlockingPolicy** The Policy that blocked detection. -- **detectionBlockreason** The reason detection did not complete. -- **detectionRetryMode** Indicates whether we will try to scan again. -- **errorCode** The error code returned for the current process. -- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. -- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. -- **interactive** Indicates whether the user initiated the session. -- **networkStatus** Indicates if the device is connected to the internet. -- **revisionNumber** The Update revision number. -- **scanTriggerSource** The source of the triggered scan. -- **updateId** The unique identifier of the Update. -- **updateScenarioType** Identifies the type of update session being performed. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DisplayNeeded - -This event indicates the reboot was postponed due to needing a display. - -The following fields are available: - -- **displayNeededReason** Reason the display is needed. -- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue - - -### Microsoft.Windows.Update.Orchestrator.Download - -This event sends launch data for a Windows Update download to help keep Windows up to date. - -The following fields are available: - -- **deferReason** Reason for download not completing. -- **errorCode** An error code represented as a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the session is user initiated. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit - -This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUEnabled - -This event indicates that Inbox DTU functionality was enabled. - -The following fields are available: - -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.DTUInitiated - -This event indicates that Inbox DTU functionality was intiated. - -The following fields are available: - -- **dtuErrorCode** Return code from creating the DTU Com Server. -- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels - -This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. - -The following fields are available: - -- **configVersion** The escalation configuration version on the device. -- **downloadElapsedTime** Indicates how long since the download is required on device. -- **downloadRiskLevel** At-risk level of download phase. -- **installElapsedTime** Indicates how long since the install is required on device. -- **installRiskLevel** The at-risk level of install phase. -- **isSediment** Assessment of whether is device is at risk. -- **scanElapsedTime** Indicates how long since the scan is required on device. -- **scanRiskLevel** At-risk level of the scan phase. -- **wuDeviceid** Device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask - -This event indicated that USO failed to add a trigger time to a task. - -The following fields are available: - -- **errorCode** The Windows Update error code. -- **wuDeviceid** The Windows Update device ID. - - -### Microsoft.Windows.Update.Orchestrator.FlightInapplicable - -This event indicates that the update is no longer applicable to this device. - -The following fields are available: - -- **EventPublishedTime** Time when this event was generated. -- **flightID** The specific ID of the Windows Insider build. -- **inapplicableReason** The reason why the update is inapplicable. -- **revisionNumber** Update revision number. -- **updateId** Unique Windows Update ID. -- **updateScenarioType** Update session type. -- **UpdateStatus** Last status of update. -- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **wuDeviceid** Unique Device ID. - - -### Microsoft.Windows.Update.Orchestrator.InitiatingReboot - -This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. - -The following fields are available: - -- **EventPublishedTime** Time of the event. -- **flightID** Unique update ID -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. -- **revisionNumber** Revision number of the update. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.Install - -This event sends launch data for a Windows Update install to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **errorCode** The error code reppresented by a hexadecimal value. -- **eventScenario** End-to-end update session ID. -- **flightID** The ID of the Windows Insider build the device is getting. -- **flightUpdate** Indicates whether the update is a Windows Insider build. -- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. -- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. -- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. -- **installRebootinitiatetime** The time it took for a reboot to be attempted. -- **interactive** Identifies if session is user initiated. -- **minutesToCommit** The time it took to install updates. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.LowUptimes - -This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. - -The following fields are available: - -- **availableHistoryMinutes** The number of minutes available from the local machine activity history. -- **isLowUptimeMachine** Is the machine considered low uptime or not. -- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. -- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. -- **uptimeMinutes** Number of minutes of uptime measured. -- **wuDeviceid** Unique device ID for Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection - -This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. - -The following fields are available: - -- **externalOneshotupdate** The last time a task-triggered scan was completed. -- **interactiveOneshotupdate** The last time an interactive scan was completed. -- **oldlastscanOneshotupdate** The last time a scan completed successfully. -- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). - - -### Microsoft.Windows.Update.Orchestrator.PreShutdownStart - -This event is generated before the shutdown and commit operations. - -The following fields are available: - -- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - - -### Microsoft.Windows.Update.Orchestrator.RebootFailed - -This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. - -The following fields are available: - -- **batteryLevel** Current battery capacity in mWh or percentage left. -- **deferReason** Reason for install not completing. -- **EventPublishedTime** The time that the reboot failure occurred. -- **flightID** Unique update ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. -- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RefreshSettings - -This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. - -The following fields are available: - -- **errorCode** Hex code for the error message, to allow lookup of the specific error. -- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. -- **settingsETag** Version identifier for the settings. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask - -This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. - -The following fields are available: - -- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. -- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. -- **RebootTaskRestoredTime** Time at which this reboot task was restored. -- **wuDeviceid** Device ID for the device on which the reboot is restored. - - -### Microsoft.Windows.Update.Orchestrator.ScanTriggered - -This event indicates that Update Orchestrator has started a scan operation. - -The following fields are available: - -- **errorCode** The error code returned for the current scan operation. -- **eventScenario** Indicates the purpose of sending this event. -- **interactive** Indicates whether the scan is interactive. -- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. -- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. -- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. -- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. -- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. -- **scanTriggerSource** Indicates what caused the scan. -- **updateScenarioType** The update session type. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.StickUpdate - -This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.SystemNeeded - -This event sends data about why a device is unable to reboot, to help keep Windows up to date. - -The following fields are available: - -- **eventScenario** End-to-end update session ID. -- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. -- **revisionNumber** Update revision number. -- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours - -This event indicates that update activity was stopped due to active hours starting. - -The following fields are available: - -- **activeHoursEnd** The end of the active hours window. -- **activeHoursStart** The start of the active hours window. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel - -This event is sent when update activity was stopped due to a low battery level. - -The following fields are available: - -- **batteryLevel** The current battery charge capacity. -- **batteryLevelThreshold** The battery capacity threshold to stop update activity. -- **updatePhase** The current state of the update process. -- **wuDeviceid** The device identifier. - - -### Microsoft.Windows.Update.Orchestrator.UnstickUpdate - -This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. - -The following fields are available: - -- **updateId** Identifier associated with the specific piece of content. -- **wuDeviceid** Unique device ID controlled by the software distribution client. - - -### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh - -This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. - -The following fields are available: - -- **configuredPoliciescount** Number of policies on the device. -- **configuredPoliciescsunt** No content is currently available. -- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). -- **policyCacherefreshtime** Time when policy cache was refreshed. -- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired - -This event sends data about whether an update required a reboot to help keep Windows up to date. - -The following fields are available: - -- **flightID** The specific ID of the Windows Insider build the device is getting. -- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. -- **revisionNumber** Update revision number. -- **updateId** Update ID. -- **updateScenarioType** The update session type. -- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. -- **wuDeviceid** Unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed - -This event sends information about an update that encountered problems and was not able to complete. - -The following fields are available: - -- **errorCode** The error code encountered. -- **wuDeviceid** The ID of the device in which the error occurred. - - -### Microsoft.Windows.Update.Orchestrator.UsoSession - -This event represents the state of the USO service at start and completion. - -The following fields are available: - -- **activeSessionid** A unique session GUID. -- **eventScenario** The state of the update action. -- **interactive** Is the USO session interactive? -- **lastErrorcode** The last error that was encountered. -- **lastErrorstate** The state of the update when the last error was encountered. -- **sessionType** A GUID that refers to the update session type. -- **updateScenarioType** A descriptive update session type. -- **wuDeviceid** The Windows Update device GUID. - - -### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState - -This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. - -The following fields are available: - -- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. -- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. -- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. -- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. -- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. -- **ETag** The Entity Tag that represents the OneSettings version. -- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. -- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. -- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. -- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. -- **RebootVersion** The version of the DTE (Direct-to-Engaged). -- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. -- **UpdateId** The ID of the update that is waiting for reboot to finish installation. -- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded - -This event is sent when a security update has successfully completed. - -The following fields are available: - -- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. - - -### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled - -This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. - -The following fields are available: - -- **activeHoursApplicable** Indicates whether Active Hours applies on this device. -- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. -- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. -- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. -- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. -- **rebootState** Current state of the reboot. -- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. -- **revisionNumber** Revision number of the OS. -- **scheduledRebootTime** Time scheduled for the reboot. -- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. -- **updateId** Identifies which update is being scheduled. -- **wuDeviceid** The unique device ID used by Windows Update. - - -### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask - -This event is sent when MUSE broker schedules a task. - -The following fields are available: - -- **TaskArgument** The arguments with which the task is scheduled. -- **TaskName** Name of the task. - - -### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled - -This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. - -The following fields are available: - -- **activeHoursApplicable** Is the restart respecting Active Hours? -- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. -- **rebootArgument** The arguments that are passed to the OS for the restarted. -- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? -- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. -- **rebootState** The state of the restart. -- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. -- **revisionNumber** The revision number of the OS being updated. -- **scheduledRebootTime** Time of the scheduled reboot -- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. -- **updateId** The Windows Update device GUID. -- **wuDeviceid** The Windows Update device GUID. - - -## Windows Update mitigation events - -### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages - -This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. - -The following fields are available: - -- **ClientId** The client ID used by Windows Update. -- **FlightId** The ID of each Windows Insider build the device received. -- **InstanceId** A unique device ID that identifies each update instance. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **MountedImageCount** The number of mounted images. -- **MountedImageMatches** The number of mounted image matches. -- **MountedImagesFailed** The number of mounted images that could not be removed. -- **MountedImagesRemoved** The number of mounted images that were successfully removed. -- **MountedImagesSkipped** The number of mounted images that were not found. -- **RelatedCV** The correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each Windows Update. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints - -This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. - -The following fields are available: - -- **ClientId** Unique identifier for each flight. -- **FlightId** Unique GUID that identifies each instances of setuphost.exe. -- **InstanceId** The update scenario in which the mitigation was executed. -- **MitigationScenario** Correlation vector value generated from the latest USO scan. -- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. -- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. -- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. -- **ReparsePointsSkipped** HResult of this operation. -- **Result** ID indicating the mitigation scenario. -- **ScenarioId** Indicates whether the scenario was supported. -- **ScenarioSupported** Unique value for each update attempt. -- **SessionId** Unique ID for each Update. -- **UpdateId** Unique ID for the Windows Update client. -- **WuId** Unique ID for the Windows Update client. - - -### Mitigation360Telemetry.MitigationCustom.FixupEditionId - -This event sends data specific to the FixupEditionId mitigation used for OS updates. - -The following fields are available: - -- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **EditionIdUpdated** Determine whether EditionId was changed. -- **FlightId** Unique identifier for each flight. -- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. -- **MitigationScenario** The update scenario in which the mitigation was executed. -- **ProductEditionId** Expected EditionId value based on GetProductInfo. -- **ProductType** Value returned by GetProductInfo. -- **RegistryEditionId** EditionId value in the registry. -- **RelatedCV** Correlation vector value generated from the latest USO scan. -- **Result** HResult of this operation. -- **ScenarioId** ID indicating the mitigation scenario. -- **ScenarioSupported** Indicates whether the scenario was supported. -- **SessionId** Unique value for each update attempt. -- **UpdateId** Unique ID for each update. -- **WuId** Unique ID for the Windows Update client. - - -## Windows Update Reserve Manager events - -### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. - -The following fields are available: - -- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. -- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. - - -### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError - -This event is sent when the Update Reserve Manager returns an error from one of its internal functions. - -The following fields are available: - -- **FailedExpression** The failed expression that was returned. -- **FailedFile** The binary file that contained the failed function. -- **FailedFunction** The name of the function that originated the failure. -- **FailedLine** The line number of the failure. -- **ReturnCode** The return code of the function. - - -### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager - -This event returns data about the Update Reserve Manager, including whether it’s been initialized. - -The following fields are available: - -- **ClientId** The ID of the caller application. -- **Flags** The enumerated flags used to initialize the manager. -- **FlightId** The flight ID of the content the calling client is currently operating with. -- **Offline** Indicates whether or the reserve manager is called during offline operations. -- **PolicyPassed** Indicates whether the machine is able to use reserves. -- **ReturnCode** Return code of the operation. -- **Version** The version of the Update Reserve Manager. - - -### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization - -This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. - -The following fields are available: - -- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. - - -### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. - - - -### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment - -This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. - -The following fields are available: - -- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. -- **Disposition** The parameter for the hard reserve adjustment function. -- **Flags** The flags passed to the hard reserve adjustment function. -- **PendingHardReserveAdjustment** The final change to the hard reserve size. -- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. - - -## Winlogon events - -### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon - -This event signals the completion of the setup process. It happens only once during the first logon. - - - -## XBOX events - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - - +--- +description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. +title: Windows 10, version 1809 basic diagnostic events and fields (Windows 10) +keywords: privacy, telemetry +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +localizationpriority: high +author: brianlic-msft +ms.author: brianlic +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +audience: ITPro +ms.date: 03/27/2019 +--- + + +# Windows 10, version 1809 basic level Windows diagnostic events and fields + + **Applies to** + +- Windows 10, version 1809 + + +The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. + +The Basic level helps to identify problems that can occur on a particular device hardware or software configuration. For example, it can help determine if crashes are more frequent on devices with a specific amount of memory or that are running a particular driver version. This helps Microsoft fix operating system or app problems. + +Use this article to learn about diagnostic events, grouped by event area, and the fields within each event. A brief description is provided for each field. Every event generated includes common data, which collects device data. + +You can learn more about Windows functional and diagnostic data through these articles: + + +- [Windows 10, version 1803 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1803.md) +- [Windows 10, version 1709 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1709.md) +- [Windows 10, version 1703 basic diagnostic events and fields](basic-level-windows-diagnostic-events-and-fields-1703.md) +- [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) +- [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) + + + + +## Account trace logging provider events + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General + +This event provides information about application properties to indicate the successful execution. + +The following fields are available: + +- **AppMode** Indicates the mode the app is being currently run around privileges. +- **ExitCode** Indicates the exit code of the app. +- **Help** Indicates if the app needs to be launched in the help mode. +- **ParseError** Indicates if there was a parse error during the execution. +- **RightsAcquired** Indicates if the right privileges were acquired for successful execution. +- **RightsWereEnabled** Indicates if the right privileges were enabled for successful execution. +- **TestMode** Indicates whether the app is being run in test mode. + + +### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.GetCount + +This event provides information about the properties of user accounts in the Administrator group. + +The following fields are available: + +- **Internal** Indicates the internal property associated with the count group. +- **LastError** The error code (if applicable) for the cause of the failure to get the count of the user account. +- **Result** The HResult error. + + +## AppLocker events + +### Microsoft.Windows.Security.AppLockerCSP.ActivityStoppedAutomatically + +Automatically closed activity for start/stop operations that aren't explicitly closed. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddParams + +Parameters passed to Add function of the AppLockerCSP Node. + +The following fields are available: + +- **child** The child URI of the node to add. +- **uri** URI of the node relative to %SYSTEM32%/AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.AddStart + +Start of "Add" Operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.AddStop + +End of "Add" Operation for AppLockerCSP Node. + +The following fields are available: + +- **hr** The HRESULT returned by Add function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CAppLockerCSP::Rollback + +Result of the 'Rollback' operation in AppLockerCSP. + +The following fields are available: + +- **oldId** Previous id for the CSP transaction. +- **txId** Current id for the CSP transaction. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearParams + +Parameters passed to the "Clear" operation for AppLockerCSP. + +The following fields are available: + +- **uri** The URI relative to the %SYSTEM32%\AppLocker folder. + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStart + +Start of the "Clear" operation for the AppLockerCSP Node. + + + +### Microsoft.Windows.Security.AppLockerCSP.ClearStop + +End of the "Clear" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT reported at the end of the 'Clear' function. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStart + +Start of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **NotifyState** State sent by ConfigManager to AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.ConfigManagerNotificationStop + +End of the "ConfigManagerNotification" operation for AppLockerCSP. + +The following fields are available: + +- **hr** HRESULT returned by the ConfigManagerNotification function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceParams + +Parameters passed to the CreateNodeInstance function of the AppLockerCSP node. + +The following fields are available: + +- **NodeId** NodeId passed to CreateNodeInstance. +- **nodeOps** NodeOperations parameter passed to CreateNodeInstance. +- **uri** URI passed to CreateNodeInstance, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStart + +Start of the "CreateNodeInstance" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.CreateNodeInstanceStop + +End of the "CreateNodeInstance" operation for the AppLockerCSP node + +The following fields are available: + +- **hr** HRESULT returned by the CreateNodeInstance function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildParams + +Parameters passed to the DeleteChild function of the AppLockerCSP node. + +The following fields are available: + +- **child** The child URI of the node to delete. +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStart + +Start of the "DeleteChild" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.DeleteChildStop + +End of the "DeleteChild" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the DeleteChild function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.EnumPolicies + +Logged URI relative to %SYSTEM32%\AppLocker, if the Plugin GUID is null, or the CSP doesn't believe the old policy is present. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesParams + +Parameters passed to the GetChildNodeNames function of the AppLockerCSP node. + +The following fields are available: + +- **uri** URI relative to %SYSTEM32%/AppLocker for MDM node. + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStart + +Start of the "GetChildNodeNames" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.GetChildNodeNamesStop + +End of the "GetChildNodeNames" operation for the AppLockerCSP node. + +The following fields are available: + +- **child[0]** If function succeeded, the first child's name, else "NA". +- **count** If function succeeded, the number of child node names returned by the function, else 0. +- **hr** HRESULT returned by the GetChildNodeNames function of AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.GetLatestId + +The result of 'GetLatestId' in AppLockerCSP (the latest time stamped GUID). + +The following fields are available: + +- **dirId** The latest directory identifier found by GetLatestId. +- **id** The id returned by GetLatestId if id > 0 - otherwise the dirId parameter. + + +### Microsoft.Windows.Security.AppLockerCSP.HResultException + +HRESULT thrown by any arbitrary function in AppLockerCSP. + +The following fields are available: + +- **file** File in the OS code base in which the exception occurs. +- **function** Function in the OS code base in which the exception occurs. +- **hr** HRESULT that is reported. +- **line** Line in the file in the OS code base in which the exception occurs. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueParams + +Parameters passed to the SetValue function of the AppLockerCSP node. + +The following fields are available: + +- **dataLength** Length of the value to set. +- **uri** The node URI to that should contain the value, relative to %SYSTEM32%\AppLocker. + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStart + +Start of the "SetValue" operation for the AppLockerCSP node. + + + +### Microsoft.Windows.Security.AppLockerCSP.SetValueStop + +End of the "SetValue" operation for the AppLockerCSP node. + +The following fields are available: + +- **hr** HRESULT returned by the SetValue function in AppLockerCSP. + + +### Microsoft.Windows.Security.AppLockerCSP.TryRemediateMissingPolicies + +EntryPoint of fix step or policy remediation, includes URI relative to %SYSTEM32%\AppLocker that needs to be fixed. + +The following fields are available: + +- **uri** URI for node relative to %SYSTEM32%/AppLocker. + + +## Appraiser events + +### Microsoft.Windows.Appraiser.General.ChecksumTotalPictureCount + +This event lists the types of objects and how many of each exist on the client device. This allows for a quick way to ensure that the records present on the server match what is present on the client. + +The following fields are available: + +- **DatasourceApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **DatasourceApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DatasourceApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS1** The total DataSourceDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DatasourceDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS1** The total DataSourceDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DatasourceDriverPackage_RS2** The total DataSourceDriverPackage objects targeting Windows 10, version 1703 on this device. +- **DatasourceDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS1** The total DataSourceMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPassive_RS2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS1** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS2** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3** The total DataSourceMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DataSourceMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DataSourceMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19ASetup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_19H1Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS1** The total DatasourceSystemBios objects targeting Windows 10 version 1607 present on this device. +- **DatasourceSystemBios_RS2** The total DatasourceSystemBios objects targeting Windows 10 version 1703 present on this device. +- **DatasourceSystemBios_RS3** The total DatasourceSystemBios objects targeting Windows 10 version 1709 present on this device. +- **DatasourceSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS4Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_RS5Setup** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DatasourceSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS2** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH1** The count of the number of this particular object type present on this device. +- **DecisionApplicationFile_TH2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS1** The total DecisionDevicePnp objects targeting Windows 10 version 1607 on this device. +- **DecisionDevicePnp_RS2** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH1** The count of the number of this particular object type present on this device. +- **DecisionDevicePnp_TH2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS1** The total DecisionDriverPackage objects targeting Windows 10 version 1607 on this device. +- **DecisionDriverPackage_RS2** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH1** The count of the number of this particular object type present on this device. +- **DecisionDriverPackage_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS1** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1607 present on this device. +- **DecisionMatchingInfoBlock_RS2** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1703 present on this device. +- **DecisionMatchingInfoBlock_RS3** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1709 present on this device. +- **DecisionMatchingInfoBlock_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS4** The total DecisionMatchingInfoBlock objects targeting Windows 10 version 1803 present on this device. +- **DecisionMatchingInfoBlock_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoBlock_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS1** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPassive_RS2** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPassive_RS3** The total DecisionMatchingInfoPassive objects targeting Windows 10 version 1803 on this device. +- **DecisionMatchingInfoPassive_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPassive_TH2** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_19H1Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS1** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1607 on this device. +- **DecisionMatchingInfoPostUpgrade_RS2** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1703 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3** The total DecisionMatchingInfoPostUpgrade objects targeting Windows 10 version 1709 on this device. +- **DecisionMatchingInfoPostUpgrade_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH1** The count of the number of this particular object type present on this device. +- **DecisionMatchingInfoPostUpgrade_TH2** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19ASetup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_19H1Setup** The total DecisionMediaCenter objects targeting the next release of Windows on this device. +- **DecisionMediaCenter_RS1** The total DecisionMediaCenter objects targeting Windows 10 version 1607 present on this device. +- **DecisionMediaCenter_RS2** The total DecisionMediaCenter objects targeting Windows 10 version 1703 present on this device. +- **DecisionMediaCenter_RS3** The total DecisionMediaCenter objects targeting Windows 10 version 1709 present on this device. +- **DecisionMediaCenter_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS4** The total DecisionMediaCenter objects targeting Windows 10 version 1803 present on this device. +- **DecisionMediaCenter_RS4Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_RS5Setup** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH1** The count of the number of this particular object type present on this device. +- **DecisionMediaCenter_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19ASetup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_19H1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_19H1Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS1** The total DecisionSystemBios objects targeting Windows 10 version 1607 on this device. +- **DecisionSystemBios_RS2** The total DecisionSystemBios objects targeting Windows 10 version 1703 on this device. +- **DecisionSystemBios_RS3** The total DecisionSystemBios objects targeting Windows 10 version 1709 on this device. +- **DecisionSystemBios_RS3Setup** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_RS4** The total DecisionSystemBios objects targeting Windows 10 version, 1803 present on this device. +- **DecisionSystemBios_RS4Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_RS5Setup** The total DecisionSystemBios objects targeting the next release of Windows on this device. +- **DecisionSystemBios_TH1** The count of the number of this particular object type present on this device. +- **DecisionSystemBios_TH2** The count of the number of this particular object type present on this device. +- **DecisionSystemProcessor_RS2** The count of the number of this particular object type present on this device. +- **DecisionTest_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **InventoryApplicationFile** The count of the number of this particular object type present on this device. +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryLanguagePack** The count of the number of this particular object type present on this device. +- **InventoryMediaCenter** The count of the number of this particular object type present on this device. +- **InventorySystemBios** The count of the number of this particular object type present on this device. +- **InventorySystemMachine** The count of the number of this particular object type present on this device. +- **InventorySystemProcessor** The count of the number of this particular object type present on this device. +- **InventoryTest** The count of the number of this particular object type present on this device. +- **InventoryUplevelDriverPackage** The count of the number of this particular object type present on this device. +- **PCFP** The count of the number of this particular object type present on this device. +- **SystemMemory** The count of the number of this particular object type present on this device. +- **SystemProcessorCompareExchange** The count of the number of this particular object type present on this device. +- **SystemProcessorLahfSahf** The count of the number of this particular object type present on this device. +- **SystemProcessorNx** The total number of objects of this type present on this device. +- **SystemProcessorPrefetchW** The total number of objects of this type present on this device. +- **SystemProcessorSse2** The total number of objects of this type present on this device. +- **SystemTouch** The count of the number of this particular object type present on this device. +- **SystemWim** The total number of objects of this type present on this device. +- **SystemWindowsActivationStatus** The count of the number of this particular object type present on this device. +- **SystemWlan** The total number of objects of this type present on this device. +- **Wmdrm_19ASetup** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1** The count of the number of this particular object type present on this device. +- **Wmdrm_19H1Setup** The total Wmdrm objects targeting the next release of Windows on this device. +- **Wmdrm_RS1** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS2** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3** An ID for the system, calculated by hashing hardware identifiers. +- **Wmdrm_RS3Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS4** The total Wmdrm objects targeting Windows 10, version 1803 present on this device. +- **Wmdrm_RS4Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5** The count of the number of this particular object type present on this device. +- **Wmdrm_RS5Setup** The count of the number of this particular object type present on this device. +- **Wmdrm_TH1** The count of the number of this particular object type present on this device. +- **Wmdrm_TH2** The count of the number of this particular object type present on this device. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileAdd + +Represents the basic metadata about specific application files installed on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompatModelIndex** The compatibility prediction for this file. +- **HasCitData** Indicates whether the file is present in CIT data. +- **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. +- **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAttempted** This will always be an empty string when sending telemetry. +- **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileRemove + +This event indicates that the DatasourceApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceApplicationFileStartSync + +This event indicates that a new set of DatasourceApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd + +This event sends compatibility data for a Plug and Play device, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **AppraiserVersion** The version of the appraiser file generating the events. +- **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. +- **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. +- **CosDeviceSolutionUrl** Microsoft.Windows.Appraiser.General.DatasourceDevicePnpAdd . Empty string +- **CosPopulatedFromId** The expected uplevel driver matching ID based on driver coverage data. +- **IsBootCritical** Indicates whether the device boot is critical. +- **UplevelInboxDriver** Indicates whether there is a driver uplevel for this device. +- **WuDriverCoverage** Indicates whether there is a driver uplevel for this device, according to Windows Update. +- **WuDriverUpdateId** The Windows Update ID of the applicable uplevel driver. +- **WuPopulatedFromId** The expected uplevel driver matching ID based on driver coverage from Windows Update. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpRemove + +This event indicates that the DatasourceDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDevicePnpStartSync + +This event indicates that a new set of DatasourceDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageAdd + +This event sends compatibility database data about driver packages to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageRemove + +This event indicates that the DatasourceDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceDriverPackageStartSync + +This event indicates that a new set of DatasourceDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockAdd + +This event sends blocking data about any compatibility blocking entries hit on the system that are not directly related to specific applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockRemove + +This event indicates that the DataSourceMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoBlockStartSync + +This event indicates that a full set of DataSourceMatchingInfoBlockStAdd events have been sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveAdd + +This event sends compatibility database information about non-blocking compatibility entries on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveRemove + +This event indicates that the DataSourceMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPassiveStartSync + +This event indicates that a new set of DataSourceMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeAdd + +This event sends compatibility database information about entries requiring reinstallation after an upgrade on the system that are not keyed by either applications or devices, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeRemove + +This event indicates that the DataSourceMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DataSourceMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DataSourceMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosAdd + +This event sends compatibility database information about the BIOS to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosRemove + +This event indicates that the DatasourceSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DatasourceSystemBiosStartSync + +This event indicates that a new set of DatasourceSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileAdd + +This event sends compatibility decision data about a file to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file that is generating the events. +- **BlockAlreadyInbox** The uplevel runtime block on the file already existed on the current OS. +- **BlockingApplication** Indicates whether there are any application issues that interfere with the upgrade due to the file in question. +- **DisplayGenericMessage** Will be a generic message be shown for this file? +- **DisplayGenericMessageGated** Indicates whether a generic message be shown for this file. +- **HardBlock** This file is blocked in the SDB. +- **HasUxBlockOverride** Does the file have a block that is overridden by a tag in the SDB? +- **MigApplication** Does the file have a MigXML from the SDB associated with it that applies to the current upgrade mode? +- **MigRemoval** Does the file have a MigXML from the SDB that will cause the app to be removed on upgrade? +- **NeedsDismissAction** Will the file cause an action that can be dimissed? +- **NeedsInstallPostUpgradeData** After upgrade, the file will have a post-upgrade notification to install a replacement for the app. +- **NeedsNotifyPostUpgradeData** Does the file have a notification that should be shown after upgrade? +- **NeedsReinstallPostUpgradeData** After upgrade, this file will have a post-upgrade notification to reinstall the app. +- **NeedsUninstallAction** The file must be uninstalled to complete the upgrade. +- **SdbBlockUpgrade** The file is tagged as blocking upgrade in the SDB, +- **SdbBlockUpgradeCanReinstall** The file is tagged as blocking upgrade in the SDB. It can be reinstalled after upgrade. +- **SdbBlockUpgradeUntilUpdate** The file is tagged as blocking upgrade in the SDB. If the app is updated, the upgrade can proceed. +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the SDB. It does not block upgrade. +- **SdbReinstallUpgradeWarn** The file is tagged as needing to be reinstalled after upgrade with a warning in the SDB. It does not block upgrade. +- **SoftBlock** The file is softblocked in the SDB and has a warning. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileRemove + +This event indicates Indicates that the DecisionApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionApplicationFileStartSync + +This event indicates that a new set of DecisionApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpAdd + +This event sends compatibility decision data about a PNP device to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **AssociatedDriverIsBlocked** Is the driver associated with this PNP device blocked? +- **AssociatedDriverWillNotMigrate** Will the driver associated with this plug-and-play device migrate? +- **BlockAssociatedDriver** Should the driver associated with this PNP device be blocked? +- **BlockingDevice** Is this PNP device blocking upgrade? +- **BlockUpgradeIfDriverBlocked** Is the PNP device both boot critical and does not have a driver included with the OS? +- **BlockUpgradeIfDriverBlockedAndOnlyActiveNetwork** Is this PNP device the only active network device? +- **DisplayGenericMessage** Will a generic message be shown during Setup for this PNP device? +- **DisplayGenericMessageGated** Indicates whether a generic message will be shown during Setup for this PNP device. +- **DriverAvailableInbox** Is a driver included with the operating system for this PNP device? +- **DriverAvailableOnline** Is there a driver for this PNP device on Windows Update? +- **DriverAvailableUplevel** Is there a driver on Windows Update or included with the operating system for this PNP device? +- **DriverBlockOverridden** Is there is a driver block on the device that has been overridden? +- **NeedsDismissAction** Will the user would need to dismiss a warning during Setup for this device? +- **NotRegressed** Does the device have a problem code on the source OS that is no better than the one it would have on the target OS? +- **SdbDeviceBlockUpgrade** Is there an SDB block on the PNP device that blocks upgrade? +- **SdbDriverBlockOverridden** Is there an SDB block on the PNP device that blocks upgrade, but that block was overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpRemove + +This event indicates that the DecisionDevicePnp object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDevicePnpStartSync + +The DecisionDevicePnpStartSync event indicates that a new set of DecisionDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageAdd + +This event sends decision data about driver package compatibility to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for this driver package. +- **DriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? +- **DriverIsDeviceBlocked** Was the driver package was blocked because of a device block? +- **DriverIsDriverBlocked** Is the driver package blocked because of a driver block? +- **DriverIsTroubleshooterBlocked** Indicates whether the driver package is blocked because of a troubleshooter block. +- **DriverShouldNotMigrate** Should the driver package be migrated during upgrade? +- **SdbDriverBlockOverridden** Does the driver package have an SDB block that blocks it from migrating, but that block has been overridden? + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageRemove + +This event indicates that the DecisionDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionDriverPackageStartSync + +This event indicates that a new set of DecisionDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockAdd + +This event sends compatibility decision data about blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the appraiser file generating the events. +- **BlockingApplication** Are there are any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessage** Will a generic message be shown for this block? +- **NeedsUninstallAction** Does the user need to take an action in setup due to a matching info block? +- **SdbBlockUpgrade** Is a matching info block blocking upgrade? +- **SdbBlockUpgradeCanReinstall** Is a matching info block blocking upgrade, but has the can reinstall tag? +- **SdbBlockUpgradeUntilUpdate** Is a matching info block blocking upgrade but has the until update tag? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockRemove + +This event indicates that the DecisionMatchingInfoBlock object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoBlockStartSync + +This event indicates that a new set of DecisionMatchingInfoBlockAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveAdd + +This event sends compatibility decision data about non-blocking entries on the system that are not keyed by either applications or devices, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Are there any application issues that interfere with upgrade due to matching info blocks? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown due to matching info blocks. +- **MigApplication** Is there a matching info block with a mig for the current mode of upgrade? + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveRemove + +This event Indicates that the DecisionMatchingInfoPassive object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPassiveStartSync + +This event indicates that a new set of DecisionMatchingInfoPassiveAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeAdd + +This event sends compatibility decision data about entries that require reinstall after upgrade. It's used to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **NeedsInstallPostUpgradeData** Will the file have a notification after upgrade to install a replacement for the app? +- **NeedsNotifyPostUpgradeData** Should a notification be shown for this file after upgrade? +- **NeedsReinstallPostUpgradeData** Will the file have a notification after upgrade to reinstall the app? +- **SdbReinstallUpgrade** The file is tagged as needing to be reinstalled after upgrade in the compatibility database (but is not blocking upgrade). + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeRemove + +This event indicates that the DecisionMatchingInfoPostUpgrade object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMatchingInfoPostUpgradeStartSync + +This event indicates that a new set of DecisionMatchingInfoPostUpgradeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterAdd + +This event sends decision data about the presence of Windows Media Center, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **BlockingApplication** Is there any application issues that interfere with upgrade due to Windows Media Center? +- **MediaCenterActivelyUsed** If Windows Media Center is supported on the edition, has it been run at least once and are the MediaCenterIndicators are true? +- **MediaCenterIndicators** Do any indicators imply that Windows Media Center is in active use? +- **MediaCenterInUse** Is Windows Media Center actively being used? +- **MediaCenterPaidOrActivelyUsed** Is Windows Media Center actively being used or is it running on a supported edition? +- **NeedsDismissAction** Are there any actions that can be dismissed coming from Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterRemove + +This event indicates that the DecisionMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionMediaCenterStartSync + +This event indicates that a new set of DecisionMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosAdd + +This event sends compatibility decision data about the BIOS to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device blocked from upgrade due to a BIOS block? +- **DisplayGenericMessageGated** Indicates whether a generic offer block message will be shown for the bios. +- **HasBiosBlock** Does the device have a BIOS block? + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosRemove + +This event indicates that the DecisionSystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.DecisionSystemBiosStartSync + +This event indicates that a new set of DecisionSystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.GatedRegChange + +This event sends data about the results of running a set of quick-blocking instructions, to help keep Windows up to date. + +The following fields are available: + +- **NewData** The data in the registry value after the scan completed. +- **OldData** The previous data in the registry value before the scan ran. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **RegKey** The registry key name for which a result is being sent. +- **RegValue** The registry value for which a result is being sent. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileAdd + +This event represents the basic metadata about a file on the system. The file must be part of an app and either have a block in the compatibility database or be part of an antivirus program. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **AvDisplayName** If the app is an antivirus app, this is its display name. +- **AvProductState** Indicates whether the antivirus program is turned on and the signatures are up to date. +- **BinaryType** A binary type. Example: UNINITIALIZED, ZERO_BYTE, DATA_ONLY, DOS_MODULE, NE16_MODULE, PE32_UNKNOWN, PE32_I386, PE32_ARM, PE64_UNKNOWN, PE64_AMD64, PE64_ARM64, PE64_IA64, PE32_CLR_32, PE32_CLR_IL, PE32_CLR_IL_PREFER32, PE64_CLR_64. +- **BinFileVersion** An attempt to clean up FileVersion at the client that tries to place the version into 4 octets. +- **BinProductVersion** An attempt to clean up ProductVersion at the client that tries to place the version into 4 octets. +- **BoeProgramId** If there is no entry in Add/Remove Programs, this is the ProgramID that is generated from the file metadata. +- **CompanyName** The company name of the vendor who developed this file. +- **FileId** A hash that uniquely identifies a file. +- **FileVersion** The File version field from the file metadata under Properties -> Details. +- **HasUpgradeExe** Indicates whether the antivirus app has an upgrade.exe file. +- **IsAv** Indicates whether the file an antivirus reporting EXE. +- **LinkDate** The date and time that this file was linked on. +- **LowerCaseLongPath** The full file path to the file that was inventoried on the device. +- **Name** The name of the file that was inventoried. +- **ProductName** The Product name field from the file metadata under Properties -> Details. +- **ProductVersion** The Product version field from the file metadata under Properties -> Details. +- **ProgramId** A hash of the Name, Version, Publisher, and Language of an application used to identify it. +- **Size** The size of the file (in hexadecimal bytes). + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileRemove + +This event indicates that the InventoryApplicationFile object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryApplicationFileStartSync + +This event indicates indicates that a new set of InventoryApplicationFileAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackAdd + +This event sends data about the number of language packs installed on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **HasLanguagePack** Indicates whether this device has 2 or more language packs. +- **LanguagePackCount** The number of language packs are installed. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackRemove + +This event indicates that the InventoryLanguagePack object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryLanguagePackStartSync + +This event indicates that a new set of InventoryLanguagePackAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterAdd + +This event sends true/false data about decision points used to understand whether Windows Media Center is used on the system, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **EverLaunched** Has Windows Media Center ever been launched? +- **HasConfiguredTv** Has the user configured a TV tuner through Windows Media Center? +- **HasExtendedUserAccounts** Are any Windows Media Center Extender user accounts configured? +- **HasWatchedFolders** Are any folders configured for Windows Media Center to watch? +- **IsDefaultLauncher** Is Windows Media Center the default app for opening music or video files? +- **IsPaid** Is the user running a Windows Media Center edition that implies they paid for Windows Media Center? +- **IsSupported** Does the running OS support Windows Media Center? + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterRemove + +This event indicates that the InventoryMediaCenter object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryMediaCenterStartSync + +This event indicates that a new set of InventoryMediaCenterAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosAdd + +This event sends basic metadata about the BIOS to determine whether it has a compatibility block. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **biosDate** The release date of the BIOS in UTC format. +- **BiosDate** The release date of the BIOS in UTC format. +- **biosName** The name field from Win32_BIOS. +- **BiosName** The name field from Win32_BIOS. +- **manufacturer** The manufacturer field from Win32_ComputerSystem. +- **Manufacturer** The manufacturer field from Win32_ComputerSystem. +- **model** The model field from Win32_ComputerSystem. +- **Model** The model field from Win32_ComputerSystem. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosRemove + +This event indicates that the InventorySystemBios object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventorySystemBiosStartSync + +This event indicates that a new set of InventorySystemBiosAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageAdd + +This event is only runs during setup. It provides a listing of the uplevel driver packages that were downloaded before the upgrade. Is critical to understanding if failures in setup can be traced to not having sufficient uplevel drivers before the upgrade. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BootCritical** Is the driver package marked as boot critical? +- **Build** The build value from the driver package. +- **CatalogFile** The name of the catalog file within the driver package. +- **Class** The device class from the driver package. +- **ClassGuid** The device class unique ID from the driver package. +- **Date** The date from the driver package. +- **Inbox** Is the driver package of a driver that is included with Windows? +- **OriginalName** The original name of the INF file before it was renamed. Generally a path under $WINDOWS.~BT\Drivers\DU. +- **Provider** The provider of the driver package. +- **PublishedName** The name of the INF file after it was renamed. +- **Revision** The revision of the driver package. +- **SignatureStatus** Indicates if the driver package is signed. Unknown = 0, Unsigned = 1, Signed = 2. +- **VersionMajor** The major version of the driver package. +- **VersionMinor** The minor version of the driver package. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageRemove + +This event indicates that the InventoryUplevelDriverPackage object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.InventoryUplevelDriverPackageStartSync + +This event indicates that a new set of InventoryUplevelDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.RunContext + +This event indicates what should be expected in the data payload. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the currently running version of Appraiser was built. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **CensusId** A unique hardware identifier. +- **Context** Indicates what mode Appraiser is running in. Example: Setup or Telemetry. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **Subcontext** Indicates what categories of incompatibilities appraiser is scanning for. Can be N/A, Resolve, or a semicolon-delimited list that can include App, Dev, Sys, Gat, or Rescan. +- **Time** The client time of the event. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryAdd + +This event sends data on the amount of memory on the system and whether it meets requirements, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the device from upgrade due to memory restrictions? +- **MemoryRequirementViolated** Was a memory requirement violated? +- **pageFile** The current committed memory limit for the system or the current process, whichever is smaller (in bytes). +- **ram** The amount of memory on the device. +- **ramKB** The amount of memory (in KB). +- **virtual** The size of the user-mode portion of the virtual address space of the calling process (in bytes). +- **virtualKB** The amount of virtual memory (in KB). + + +### Microsoft.Windows.Appraiser.General.SystemMemoryRemove + +This event that the SystemMemory object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemMemoryStartSync + +This event indicates that a new set of SystemMemoryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeAdd + +This event sends data indicating whether the system supports the CompareExchange128 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **CompareExchange128Support** Does the CPU support CompareExchange128? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeRemove + +This event indicates that the SystemProcessorCompareExchange object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorCompareExchangeStartSync + +This event indicates that a new set of SystemProcessorCompareExchangeAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfAdd + +This event sends data indicating whether the system supports the LahfSahf CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **LahfSahfSupport** Does the CPU support LAHF/SAHF? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfRemove + +This event indicates that the SystemProcessorLahfSahf object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorLahfSahfStartSync + +This event indicates that a new set of SystemProcessorLahfSahfAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxAdd + +This event sends data indicating whether the system supports the NX CPU requirement, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **NXDriverResult** The result of the driver used to do a non-deterministic check for NX support. +- **NXProcessorSupport** Does the processor support NX? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxRemove + +This event indicates that the SystemProcessorNx object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorNxStartSync + +This event indicates that a new set of SystemProcessorNxAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWAdd + +This event sends data indicating whether the system supports the PrefetchW CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **PrefetchWSupport** Does the processor support PrefetchW? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWRemove + +This event indicates that the SystemProcessorPrefetchW object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorPrefetchWStartSync + +This event indicates that a new set of SystemProcessorPrefetchWAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Add + +This event sends data indicating whether the system supports the SSE2 CPU requirement, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked due to the processor? +- **SSE2ProcessorSupport** Does the processor support SSE2? + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2Remove + +This event indicates that the SystemProcessorSse2 object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemProcessorSse2StartSync + +This event indicates that a new set of SystemProcessorSse2Add events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchAdd + +This event sends data indicating whether the system supports touch, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IntegratedTouchDigitizerPresent** Is there an integrated touch digitizer? +- **MaximumTouches** The maximum number of touch points supported by the device hardware. + + +### Microsoft.Windows.Appraiser.General.SystemTouchRemove + +This event indicates that the SystemTouch object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemTouchStartSync + +This event indicates that a new set of SystemTouchAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimAdd + +This event sends data indicating whether the operating system is running from a compressed Windows Imaging Format (WIM) file, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **IsWimBoot** Is the current operating system running from a compressed WIM file? +- **RegistryWimBootValue** The raw value from the registry that is used to indicate if the device is running from a WIM. + + +### Microsoft.Windows.Appraiser.General.SystemWimRemove + +This event indicates that the SystemWim object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWimStartSync + +This event indicates that a new set of SystemWimAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusAdd + +This event sends data indicating whether the current operating system is activated, to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **WindowsIsLicensedApiValue** The result from the API that's used to indicate if operating system is activated. +- **WindowsNotActivatedDecision** Is the current operating system activated? + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusRemove + +This event indicates that the SystemWindowsActivationStatus object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWindowsActivationStatusStartSync + +This event indicates that a new set of SystemWindowsActivationStatusAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanAdd + +This event sends data indicating whether the system has WLAN, and if so, whether it uses an emulated driver that could block an upgrade, to help keep Windows up-to-date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **Blocking** Is the upgrade blocked because of an emulated WLAN driver? +- **HasWlanBlock** Does the emulated WLAN driver have an upgrade block? +- **WlanEmulatedDriver** Does the device have an emulated WLAN driver? +- **WlanExists** Does the device support WLAN at all? +- **WlanModulePresent** Are any WLAN modules present? +- **WlanNativeDriver** Does the device have a non-emulated WLAN driver? + + +### Microsoft.Windows.Appraiser.General.SystemWlanRemove + +This event indicates that the SystemWlan object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.SystemWlanStartSync + +This event indicates that a new set of SystemWlanAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.TelemetryRunHealth + +This event indicates the parameters and result of a telemetry (diagnostic) run. This allows the rest of the data sent over the course of the run to be properly contextualized and understood, which is then used to keep Windows up to date. + +The following fields are available: + +- **AppraiserBranch** The source branch in which the version of Appraiser that is running was built. +- **AppraiserDataVersion** The version of the data files being used by the Appraiser telemetry run. +- **AppraiserProcess** The name of the process that launched Appraiser. +- **AppraiserVersion** The file version (major, minor and build) of the Appraiser DLL, concatenated without dots. +- **AuxFinal** Obsolete, always set to false. +- **AuxInitial** Obsolete, indicates if Appraiser is writing data files to be read by the Get Windows 10 app. +- **DeadlineDate** A timestamp representing the deadline date, which is the time until which appraiser will wait to do a full scan. +- **EnterpriseRun** Indicates if the telemetry run is an enterprise run, which means appraiser was run from the command line with an extra enterprise parameter. +- **FullSync** Indicates if Appraiser is performing a full sync, which means that full set of events representing the state of the machine are sent. Otherwise, only the changes from the previous run are sent. +- **InboxDataVersion** The original version of the data files before retrieving any newer version. +- **IndicatorsWritten** Indicates if all relevant UEX indicators were successfully written or updated. +- **InventoryFullSync** Indicates if inventory is performing a full sync, which means that the full set of events representing the inventory of machine are sent. +- **PCFP** An ID for the system calculated by hashing hardware identifiers. +- **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. +- **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. +- **RunDate** The date that the telemetry run was stated, expressed as a filetime. +- **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. +- **RunOnline** Indicates if appraiser was able to connect to Windows Update and theefore is making decisions using up-to-date driver coverage information. +- **RunResult** The hresult of the Appraiser telemetry run. +- **ScheduledUploadDay** The day scheduled for the upload. +- **SendingUtc** Indicates if the Appraiser client is sending events during the current telemetry run. +- **StoreHandleIsNotNull** Obsolete, always set to false +- **TelementrySent** Indicates if telemetry was successfully sent. +- **ThrottlingUtc** Indicates if the Appraiser client is throttling its output of CUET events to avoid being disabled. This increases runtime but also telemetry reliability. +- **Time** The client time of the event. +- **VerboseMode** Indicates if appraiser ran in Verbose mode, which is a test-only mode with extra logging. +- **WhyFullSyncWithoutTablePrefix** Indicates the reason or reasons that a full sync was generated. + + +### Microsoft.Windows.Appraiser.General.WmdrmAdd + +This event sends data about the usage of older digital rights management on the system, to help keep Windows up to date. This data does not indicate the details of the media using the digital rights management, only whether any such files exist. Collecting this data was critical to ensuring the correct mitigation for customers, and should be able to be removed once all mitigations are in place. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. +- **BlockingApplication** Same as NeedsDismissAction. +- **NeedsDismissAction** Indicates if a dismissible message is needed to warn the user about a potential loss of data due to DRM deprecation. +- **WmdrmApiResult** Raw value of the API used to gather DRM state. +- **WmdrmCdRipped** Indicates if the system has any files encrypted with personal DRM, which was used for ripped CDs. +- **WmdrmIndicators** WmdrmCdRipped OR WmdrmPurchased. +- **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. +- **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. +- **WmdrmPurchased** Indicates if the system has any files with permanent licenses. + + +### Microsoft.Windows.Appraiser.General.WmdrmRemove + +This event indicates that the Wmdrm object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +### Microsoft.Windows.Appraiser.General.WmdrmStartSync + +This event indicates that a new set of WmdrmAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AppraiserVersion** The version of the Appraiser file that is generating the events. + + +## Census events + +### Census.App + +Provides information on IE and Census versions running on the device + +The following fields are available: + +- **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. +- **AppraiserErrorCode** The error code of the last Appraiser run. +- **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. +- **AppraiserRunIsInProgressOrCrashed** Flag that indicates if the Appraiser run is in progress or has crashed. +- **AppraiserRunStartTimeStamp** The start time of the last Appraiser run. +- **AppraiserTaskEnabled** Whether the Appraiser task is enabled. +- **AppraiserTaskExitCode** The Appraiser task exist code. +- **AppraiserTaskLastRun** The last runtime for the Appraiser task. +- **CensusVersion** The version of Census that generated the current data for this device. +- **IEVersion** The version of Internet Explorer that is running on the device. + + +### Census.Battery + +This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. + +The following fields are available: + +- **InternalBatteryCapablities** Represents information about what the battery is capable of doing. +- **InternalBatteryCapacityCurrent** Represents the battery's current fully charged capacity in mWh (or relative). Compare this value to DesignedCapacity  to estimate the battery's wear. +- **InternalBatteryCapacityDesign** Represents the theoretical capacity of the battery when new, in mWh. +- **InternalBatteryNumberOfCharges** Provides the number of battery charges. This is used when creating new products and validating that existing products meets targeted functionality performance. +- **IsAlwaysOnAlwaysConnectedCapable** Represents whether the battery enables the device to be AlwaysOnAlwaysConnected . Boolean value. + + +### Census.Camera + +This event sends data about the resolution of cameras on the device, to help keep Windows up to date. + +The following fields are available: + +- **FrontFacingCameraResolution** Represents the resolution of the front facing camera in megapixels. If a front facing camera does not exist, then the value is 0. +- **RearFacingCameraResolution** Represents the resolution of the rear facing camera in megapixels. If a rear facing camera does not exist, then the value is 0. + + +### Census.Enterprise + +This event sends data about Azure presence, type, and cloud domain use in order to provide an understanding of the use and integration of devices in an enterprise, cloud, and server environment. + +The following fields are available: + +- **AADDeviceId** Azure Active Directory device ID. +- **AzureOSIDPresent** Represents the field used to identify an Azure machine. +- **AzureVMType** Represents whether the instance is Azure VM PAAS, Azure VM IAAS or any other VMs. +- **CDJType** Represents the type of cloud domain joined for the machine. +- **CommercialId** Represents the GUID for the commercial entity which the device is a member of.  Will be used to reflect insights back to customers. +- **ContainerType** The type of container, such as process or virtual machine hosted. +- **EnrollmentType** Defines the type of MDM enrollment on the device. +- **HashedDomain** The hashed representation of the user domain used for login. +- **IsCloudDomainJoined** Is this device joined to an Azure Active Directory (AAD) tenant? true/false +- **IsDERequirementMet** Represents if the device can do device encryption. +- **IsDeviceProtected** Represents if Device protected by BitLocker/Device Encryption +- **IsDomainJoined** Indicates whether a machine is joined to a domain. +- **IsEDPEnabled** Represents if Enterprise data protected on the device. +- **IsMDMEnrolled** Whether the device has been MDM Enrolled or not. +- **MPNId** Returns the Partner ID/MPN ID from Regkey. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DeployID +- **SCCMClientId** This ID correlate systems that send data to Compat Analytics (OMS) and other OMS based systems with systems in an Enterprise SCCM environment. +- **ServerFeatures** Represents the features installed on a Windows   Server. This can be used by developers and administrators who need to automate the process of determining the features installed on a set of server computers. +- **SystemCenterID** The SCCM ID is an anonymized one-way hash of the Active Directory Organization identifier + + +### Census.Firmware + +This event sends data about the BIOS and startup embedded in the device, to help keep Windows up to date. + +The following fields are available: + +- **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). +- **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. +- **FirmwareVersion** Represents the version of the current firmware. + + +### Census.Flighting + +This event sends Windows Insider data from customers participating in improvement testing and feedback programs, to help keep Windows up to date. + +The following fields are available: + +- **DeviceSampleRate** The telemetry sample rate assigned to the device. +- **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **FlightIds** A list of the different Windows Insider builds on this device. +- **FlightingBranchName** The name of the Windows Insider branch currently used by the device. +- **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. +- **MSA_Accounts** Represents a list of hashed IDs of the Microsoft Accounts that are flighting (pre-release builds) on this device. +- **SSRK** Retrieves the mobile targeting settings. + + +### Census.Hardware + +This event sends data about the device, including hardware type, OEM brand, model line, model, telemetry level setting, and TPM support, to help keep Windows up to date. + +The following fields are available: + +- **ActiveMicCount** The number of active microphones attached to the device. +- **ChassisType** Represents the type of device chassis, such as desktop or low profile desktop. The possible values can range between 1 - 36. +- **ComputerHardwareID** Identifies a device class that is represented by a hash of different SMBIOS fields. +- **D3DMaxFeatureLevel** Supported Direct3D version. +- **DeviceColor** Indicates a color of the device. +- **DeviceForm** Indicates the form as per the device classification. +- **DeviceName** The device name that is set by the user. +- **DigitizerSupport** Is a digitizer supported? +- **DUID** The device unique ID. +- **Gyroscope** Indicates whether the device has a gyroscope (a mechanical component that measures and maintains orientation). +- **InventoryId** The device ID used for compatibility testing. +- **Magnetometer** Indicates whether the device has a magnetometer (a mechanical component that works like a compass). +- **NFCProximity** Indicates whether the device supports NFC (a set of communication protocols that helps establish communication when applicable devices are brought close together.) +- **OEMDigitalMarkerFileName** The name of the file placed in the \Windows\system32\drivers directory that specifies the OEM and model name of the device. +- **OEMManufacturerName** The device manufacturer name. The OEMName for an inactive device is not reprocessed even if the clean OEM name is changed at a later date. +- **OEMModelBaseBoard** The baseboard model used by the OEM. +- **OEMModelBaseBoardVersion** Differentiates between developer and retail devices. +- **OEMModelName** The device model name. +- **OEMModelNumber** The device model number. +- **OEMModelSKU** The device edition that is defined by the manufacturer. +- **OEMModelSystemFamily** The system family set on the device by an OEM. +- **OEMModelSystemVersion** The system model version set on the device by the OEM. +- **OEMOptionalIdentifier** A Microsoft assigned value that represents a specific OEM subsidiary. +- **OEMSerialNumber** The serial number of the device that is set by the manufacturer. +- **PhoneManufacturer** The friendly name of the phone manufacturer. +- **PowerPlatformRole** The OEM preferred power management profile. It's used to help to identify the basic form factor of the device. +- **SoCName** The firmware manufacturer of the device. +- **StudyID** Used to identify retail and non-retail device. +- **TelemetryLevel** The telemetry level the user has opted into, such as Basic or Enhanced. +- **TelemetryLevelLimitEnhanced** The telemetry level for Windows Analytics-based solutions. +- **TelemetrySettingAuthority** Determines who set the telemetry level, such as GP, MDM, or the user. +- **TPMManufacturerId** The ID of the TPM manufacturer. +- **TPMManufacturerVersion** The version of the TPM manufacturer. +- **TPMVersion** The supported Trusted Platform Module (TPM) on the device. If no TPM is present, the value is 0. +- **VoiceSupported** Does the device have a cellular radio capable of making voice calls? + + +### Census.Memory + +This event sends data about the memory on the device, including ROM and RAM, to help keep Windows up to date. + +The following fields are available: + +- **TotalPhysicalRAM** Represents the physical memory (in MB). +- **TotalVisibleMemory** Represents the memory that is not reserved by the system. + + +### Census.Network + +This event sends data about the mobile and cellular network used by the device (mobile service provider, network, device ID, and service cost factors), to help keep Windows up to date. + +The following fields are available: + +- **IMEI0** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **IMEI1** Represents the International Mobile Station Equipment Identity. This number is usually unique and used by the mobile operator to distinguish different phone hardware. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. The two fields represent phone with dual sim coverage. +- **MCC0** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MCC1** Represents the Mobile Country Code (MCC). It used with the Mobile Network Code (MNC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. +- **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. +- **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. +- **NetworkAdapterGUID** The GUID of the primary network adapter. +- **NetworkCost** Represents the network cost associated with a connection. +- **SPN0** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. +- **SPN1** Retrieves the Service Provider Name (SPN). For example, these might be AT&T, Sprint, T-Mobile, or Verizon. The two fields represent phone with dual sim coverage. + + +### Census.OS + +This event sends data about the operating system such as the version, locale, update service configuration, when and how it was originally installed, and whether it is a virtual device, to help keep Windows up to date. + +The following fields are available: + +- **ActivationChannel** Retrieves the retail license key or Volume license key for a machine. +- **AssignedAccessStatus** Kiosk configuration mode. +- **CompactOS** Indicates if the Compact OS feature from Win10 is enabled. +- **DeveloperUnlockStatus** Represents if a device has been developer unlocked by the user or Group Policy. +- **DeviceTimeZone** The time zone that is set on the device. Example: Pacific Standard Time +- **GenuineState** Retrieves the ID Value specifying the OS Genuine check. +- **InstallationType** Retrieves the type of OS installation. (Clean, Upgrade, Reset, Refresh, Update). +- **InstallLanguage** The first language installed on the user machine. +- **IsDeviceRetailDemo** Retrieves if the device is running in demo mode. +- **IsEduData** Returns Boolean if the education data policy is enabled. +- **IsPortableOperatingSystem** Retrieves whether OS is running Windows-To-Go +- **IsSecureBootEnabled** Retrieves whether Boot chain is signed under UEFI. +- **LanguagePacks** The list of language packages installed on the device. +- **LicenseStateReason** Retrieves why (or how) a system is licensed or unlicensed. The HRESULT may indicate an error code that indicates a key blocked error, or it may indicate that we are running an OS License granted by the MS store. +- **OA3xOriginalProductKey** Retrieves the License key stamped by the OEM to the machine. +- **OSEdition** Retrieves the version of the current OS. +- **OSInstallType** Retrieves a numeric description of what install was used on the device i.e. clean, upgrade, refresh, reset, etc +- **OSOOBEDateTime** Retrieves Out of Box Experience (OOBE) Date in Coordinated Universal Time (UTC). +- **OSSKU** Retrieves the Friendly Name of OS Edition. +- **OSSubscriptionStatus** Represents the existing status for enterprise subscription feature for PRO machines. +- **OSSubscriptionTypeId** Returns boolean for enterprise subscription feature for selected PRO machines. +- **OSTimeZoneBiasInMins** Retrieves the time zone set on machine. +- **OSUILocale** Retrieves the locale of the UI that is currently used by the OS. +- **ProductActivationResult** Returns Boolean if the OS Activation was successful. +- **ProductActivationTime** Returns the OS Activation time for tracking piracy issues. +- **ProductKeyID2** Retrieves the License key if the machine is updated with a new license key. +- **RACw7Id** Retrieves the Microsoft Reliability Analysis Component (RAC) Win7 Identifier. RAC is used to monitor and analyze system usage and reliability. +- **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. +- **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. +- **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedPCMode** Returns Boolean for education devices used as shared cart +- **Signature** Retrieves if it is a signature machine sold by Microsoft store. +- **SLICStatus** Whether a SLIC table exists on the device. +- **SLICVersion** Returns OS type/version from SLIC table. + + +### Census.PrivacySettings + +This event provides information about the device level privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represent the authority that set the value. The effective consent (first 8 bits) is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority (last 8 bits) is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = system, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **FindMyDevice** Current state of the "find my device" setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud sync setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.Processor + +Provides information on several important data points about Processor settings + +The following fields are available: + +- **KvaShadow** This is the micro code information of the processor. +- **MMSettingOverride** Microcode setting of the processor. +- **MMSettingOverrideMask** Microcode setting override of the processor. +- **PreviousUpdateRevision** Previous microcode revision +- **ProcessorArchitecture** Retrieves the processor architecture of the installed operating system. +- **ProcessorClockSpeed** Clock speed of the processor in MHz. +- **ProcessorCores** Number of logical cores in the processor. +- **ProcessorIdentifier** Processor Identifier of a manufacturer. +- **ProcessorManufacturer** Name of the processor manufacturer. +- **ProcessorModel** Name of the processor model. +- **ProcessorPhysicalCores** Number of physical cores in the processor. +- **ProcessorUpdateRevision** The microcode revision. +- **ProcessorUpdateStatus** Enum value that represents the processor microcode load status +- **SocketCount** Count of CPU sockets. +- **SpeculationControl** Indicates whether the system has enabled protections needed to validate the speculation control vulnerability. + + +### Census.Security + +This event provides information on about security settings used to help keep Windows up to date and secure. + +The following fields are available: + +- **AvailableSecurityProperties** This field helps to enumerate and report state on the relevant security properties for Device Guard. +- **CGRunning** Credential Guard isolates and hardens key system and user secrets against compromise, helping to minimize the impact and breadth of a Pass the Hash style attack in the event that malicious code is already running via a local or network based vector. This field tells if Credential Guard is running. +- **DGState** This field summarizes the Device Guard state. +- **HVCIRunning** Hypervisor Code Integrity (HVCI) enables Device Guard to help protect kernel mode processes and drivers from vulnerability exploits and zero days. HVCI uses the processor’s functionality to force all software running in kernel mode to safely allocate memory. This field tells if HVCI is running. +- **IsSawGuest** Indicates whether the device is running as a Secure Admin Workstation Guest. +- **IsSawHost** Indicates whether the device is running as a Secure Admin Workstation Host. +- **RequiredSecurityProperties** Describes the required security properties to enable virtualization-based security. +- **SecureBootCapable** Systems that support Secure Boot can have the feature turned off via BIOS. This field tells if the system is capable of running Secure Boot, regardless of the BIOS setting. +- **SModeState** The Windows S mode trail state. +- **VBSState** Virtualization-based security (VBS) uses the hypervisor to help protect the kernel and other parts of the operating system. Credential Guard and Hypervisor Code Integrity (HVCI) both depend on VBS to isolate/protect secrets, and kernel-mode code integrity validation. VBS has a tri-state that can be Disabled, Enabled, or Running. + + +### Census.Speech + +This event is used to gather basic speech settings on the device. + +The following fields are available: + +- **AboveLockEnabled** Cortana setting that represents if Cortana can be invoked when the device is locked. +- **GPAllowInputPersonalization** Indicates if a Group Policy setting has enabled speech functionalities. +- **HolographicSpeechInputDisabled** Holographic setting that represents if the attached HMD devices have speech functionality disabled by the user. +- **HolographicSpeechInputDisabledRemote** Indicates if a remote policy has disabled speech functionalities for the HMD devices. +- **KeyVer** Version information for the census speech event. +- **KWSEnabled** Cortana setting that represents if a user has enabled the "Hey Cortana" keyword spotter (KWS). +- **MDMAllowInputPersonalization** Indicates if an MDM policy has enabled speech functionalities. +- **RemotelyManaged** Indicates if the device is being controlled by a remote administrator (MDM or Group Policy) in the context of speech functionalities. +- **SpeakerIdEnabled** Cortana setting that represents if keyword detection has been trained to try to respond to a single user's voice. +- **SpeechServicesEnabled** Windows setting that represents whether a user is opted-in for speech services on the device. +- **SpeechServicesValueSource** Indicates the deciding factor for the effective online speech recognition privacy policy settings: remote admin, local admin, or user preference. + + +### Census.Storage + +This event sends data about the total capacity of the system volume and primary disk, to help keep Windows up to date. + +The following fields are available: + +- **PrimaryDiskTotalCapacity** Retrieves the amount of disk space on the primary disk of the device in MB. +- **PrimaryDiskType** Retrieves an enumerator value of type STORAGE_BUS_TYPE that indicates the type of bus to which the device is connected. This should be used to interpret the raw device properties at the end of this structure (if any). +- **StorageReservePassedPolicy** Indicates whether the Storage Reserve policy, which ensures that updates have enough disk space and customers are on the latest OS, is enabled on this device. +- **SystemVolumeTotalCapacity** Retrieves the size of the partition that the System volume is installed on in MB. + + +### Census.Userdefault + +This event sends data about the current user's default preferences for browser and several of the most popular extensions and protocols, to help keep Windows up to date. + +The following fields are available: + +- **CalendarType** The calendar identifiers that are used to specify different calendars. +- **DefaultApp** The current uer's default program selected for the following extension or protocol: .html, .htm, .jpg, .jpeg, .png, .mp3, .mp4, .mov, .pdf. +- **DefaultBrowserProgId** The ProgramId of the current user's default browser. +- **LongDateFormat** The long date format the user has selected. +- **ShortDateFormat** The short date format the user has selected. + + +### Census.UserDisplay + +This event sends data about the logical/physical display size, resolution and number of internal/external displays, and VRAM on the system, to help keep Windows up to date. + +The following fields are available: + +- **InternalPrimaryDisplayLogicalDPIX** Retrieves the logical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayLogicalDPIY** Retrieves the logical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIX** Retrieves the physical DPI in the x-direction of the internal display. +- **InternalPrimaryDisplayPhysicalDPIY** Retrieves the physical DPI in the y-direction of the internal display. +- **InternalPrimaryDisplayResolutionHorizontal** Retrieves the number of pixels in the horizontal direction of the internal display. +- **InternalPrimaryDisplayResolutionVertical** Retrieves the number of pixels in the vertical direction of the internal display. +- **InternalPrimaryDisplaySizePhysicalH** Retrieves the physical horizontal length of the display in mm. Used for calculating the diagonal length in inches . +- **InternalPrimaryDisplaySizePhysicalY** Retrieves the physical vertical length of the display in mm. Used for calculating the diagonal length in inches +- **NumberofExternalDisplays** Retrieves the number of external displays connected to the machine +- **NumberofInternalDisplays** Retrieves the number of internal displays in a machine. +- **VRAMDedicated** Retrieves the video RAM in MB. +- **VRAMDedicatedSystem** Retrieves the amount of memory on the dedicated video card. +- **VRAMSharedSystem** Retrieves the amount of RAM memory that the video card can use. + + +### Census.UserNLS + +This event sends data about the default app language, input, and display language preferences set by the user, to help keep Windows up to date. + +The following fields are available: + +- **DefaultAppLanguage** The current user Default App Language. +- **DisplayLanguage** The current user preferred Windows Display Language. +- **HomeLocation** The current user location, which is populated using GetUserGeoId() function. +- **KeyboardInputLaîguages** No content is currently available. +- **KeyboardInputLanguages** The Keyboard input languages installed on the device. +- **SpeechInputLalguages** No content is currently available. +- **SpeechInputLanguages** The Speech Input languages installed on the device. + + +### Census.UserPrivacySettings + +This event provides information about the current users privacy settings and whether device-level access was granted to these capabilities. Not all settings are applicable to all devices. Each field records the consent state for the corresponding privacy setting. The consent state is encoded as a 16-bit signed integer, where the first 8 bits represents the effective consent value, and the last 8 bits represents the authority that set the value. The effective consent is one of the following values: -3 = unexpected consent value, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = undefined, 1 = allow, 2 = deny, 3 = prompt. The consent authority is one of the following values: -3 = unexpected authority, -2 = value was not requested, -1 = an error occurred while attempting to retrieve the value, 0 = user, 1 = a higher authority (a gating setting, the system-wide setting, or a group policy), 2 = advertising ID group policy, 3 = advertising ID policy for child account, 4 = privacy setting provider doesn't know the actual consent authority, 5 = consent was not configured and a default set in code was used, 6 = system default, 7 = organization policy, 8 = OneSettings. + +The following fields are available: + +- **Activity** Current state of the activity history setting. +- **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. +- **ActivityHistoryCollection** Current state of the activity history collection setting. +- **AdvertisingId** Current state of the advertising ID setting. +- **AppDiagnostacs** No content is currently available. +- **AppDiagnostics** Current state of the app diagnostics setting. +- **Appiagnostics** No content is currently available. +- **Appointments** Current state of the calendar setting. +- **Bluetooth** Current state of the Bluetooth capability setting. +- **BluetoothSync** Current state of the Bluetooth sync capability setting. +- **BroadFileSystemAccess** Current state of the broad file system access setting. +- **CellularData** Current state of the cellular data capability setting. +- **Chat** Current state of the chat setting. +- **Contacts** Current state of the contacts setting. +- **DocumentsLibrary** Current state of the documents library setting. +- **Email** Current state of the email setting. +- **GazeInput** Current state of the gaze input setting. +- **HumanInterfaceDevice** Current state of the human interface device setting. +- **InkT9peImprovement** No content is currently available. +- **InkT9pePersonalization** No content is currently available. +- **InkTypeImprovement** Current state of the improve inking and typing setting. +- **InkTypePersonalization** Current state of the inking and typing personalization setting. +- **Location** Current state of the location setting. +- **LocationHistory** Current state of the location history setting. +- **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. +- **LocationHistoryOnTimeline** Current state of the location history on timeline setting. +- **Microphona** No content is currently available. +- **Microphone** Current state of the microphone setting. +- **PhoneCall** Current state of the phone call setting. +- **PhoneCallHistory** Current state of the call history setting. +- **PicturesLibrary** Current state of the pictures library setting. +- **Radios** Current state of the radios setting. +- **SensorsÃustom** No content is currently available. +- **SensorsCustom** Current state of the custom sensor setting. +- **SerialCommunication** Current state of the serial communication setting. +- **Sms** Current state of the text messaging setting. +- **SpeechPersonalization** Current state of the speech services setting. +- **UqerDataTasks** No content is currently available. +- **USB** Current state of the USB setting. +- **UserAccountInformation** Current state of the account information setting. +- **UserDataTasks** Current state of the tasks setting. +- **UserNotificationListener** Current state of the notifications setting. +- **VideosLibrary** Current state of the videos library setting. +- **Webcam** Current state of the camera setting. +- **WiFiDirect** Current state of the Wi-Fi direct setting. + + +### Census.VM + +This event sends data indicating whether virtualization is enabled on the device, and its various characteristics, to help keep Windows up to date. + +The following fields are available: + +- **CloudService** Indicates which cloud service, if any, that this virtual machine is running within. +- **HyperVisor** Retrieves whether the current OS is running on top of a Hypervisor. +- **IOMMUPresent** Represents if an input/output memory management unit (IOMMU) is present. +- **IsVDI** Is the device using Virtual Desktop Infrastructure? +- **IsVirtualDevice** Retrieves that when the Hypervisor is Microsoft's Hyper-V Hypervisor or other Hv#1 Hypervisor, this field will be set to FALSE for the Hyper-V host OS and TRUE for any guest OS's. This field should not be relied upon for non-Hv#1 Hypervisors. +- **SLATSupported** Represents whether Second Level Address Translation (SLAT) is supported by the hardware. +- **VirtualizationFirmwareEnabled** Represents whether virtualization is enabled in the firmware. + + +### Census.WU + +This event sends data about the Windows update server and other App store policies, to help keep Windows up to date. + +The following fields are available: + +- **AppraiserGatedStatus** Indicates whether a device has been gated for upgrading. +- **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). +- **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured +- **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. +- **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? +- **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? +- **OSAssessmentForQualityUpdate** Is the device on the latest quality update? +- **OSAssessmentForSecurityUpdate** Is the device on the latest security update? +- **OSAssessmentQualityOutOfDate** How many days has it been since a the last quality update was released but the device did not install it? +- **OSAssessmentReleaseInfoTime** The freshness of release information used to perform an assessment. +- **OSRollbackCount** The number of times feature updates have rolled back on the device. +- **OSRolledBack** A flag that represents when a feature update has rolled back during setup. +- **OSUninstalled** A flag that represents when a feature update is uninstalled on a device . +- **OSWUAutoUpdateOptions** Retrieves the auto update settings on the device. +- **OSWUAutoUpdateOptionsSource** The source of auto update setting that appears in the OSWUAutoUpdateOptions field. For example: Group Policy (GP), Mobile Device Management (MDM), and Default. +- **UninstallActive** A flag that represents when a device has uninstalled a previous upgrade recently. +- **UpdateServiceURLConfigured** Retrieves if the device is managed by Windows Server Update Services (WSUS). +- **WUDeferUpdatePeriod** Retrieves if deferral is set for Updates. +- **WUDeferUpgradePeriod** Retrieves if deferral is set for Upgrades. +- **WUDODownloadMode** Retrieves whether DO is turned on and how to acquire/distribute updates Delivery Optimization (DO) allows users to deploy previously downloaded WU updates to other devices on the same network. +- **WUMachineId** Retrieves the Windows Update (WU) Machine Identifier. +- **WUPauseState** Retrieves WU setting to determine if updates are paused. +- **WUServer** Retrieves the HTTP(S) URL of the WSUS server that is used by Automatic Updates and API callers (by default). + + +### Census.Xbox + +This event sends data about the Xbox Console, such as Serial Number and DeviceId, to help keep Windows up to date. + +The following fields are available: + +- **XboxConsolePreferredLanguage** Retrieves the preferred language selected by the user on Xbox console. +- **XboxConsoleSerialNumber** Retrieves the serial number of the Xbox console. +- **XboxLiveDeviceId** Retrieves the unique device ID of the console. +- **XboxLiveSandboxId** Retrieves the developer sandbox ID if the device is internal to Microsoft. + + +## Common data extensions + +### Common Data Extensions.app + +Describes the properties of the running application. This extension could be populated by a client app or a web app. + +The following fields are available: + +- **asId** An integer value that represents the app session. This value starts at 0 on the first app launch and increments after each subsequent app launch per boot session. +- **env** The environment from which the event was logged. +- **expId** Associates a flight, such as an OS flight, or an experiment, such as a web site UX experiment, with an event. +- **id** Represents a unique identifier of the client application currently loaded in the process producing the event; and is used to group events together and understand usage pattern, errors by application. +- **locale** The locale of the app. +- **name** The name of the app. +- **userId** The userID as known by the application. +- **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. + + +### Common Data Extensions.container + +Describes the properties of the container for events logged within a container. + +The following fields are available: + +- **epoch** An ID that's incremented for each SDK initialization. +- **localId** The device ID as known by the client. +- **osVer** The operating system version. +- **seq** An ID that's incremented for each event. +- **type** The container type. Examples: Process or VMHost + + +### Common Data Extensions.cs + +Describes properties related to the schema of the event. + +The following fields are available: + +- **sig** A common schema signature that identifies new and modified event schemas. + + +### Common Data Extensions.device + +Describes the device-related fields. + +The following fields are available: + +- **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId +- **make** Device manufacturer. +- **model** Device model. + + +### Common Data Extensions.Envelope + +Represents an envelope that contains all of the common data extensions. + +The following fields are available: + +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. +- **data** Represents the optional unique diagnostic data for a particular event schema. +- **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). +- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). +- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). +- **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). +- **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). +- **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). +- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. +- **iKey** Represents an ID for applications or other logical groupings of events. +- **name** Represents the uniquely qualified name for the event. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. +- **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.os + +Describes some properties of the operating system. + +The following fields are available: + +- **bootId** An integer value that represents the boot session. This value starts at 0 on first boot after OS install and increments after every reboot. +- **expId** Represents the experiment ID. The standard for associating a flight, such as an OS flight (pre-release build), or an experiment, such as a web site UX experiment, with an event is to record the flight / experiment IDs in Part A of the common schema. +- **locale** Represents the locale of the operating system. +- **name** Represents the operating system name. +- **ver** Represents the major and minor version of the extension. + + +### Common Data Extensions.receipts + +Represents various time information as provided by the client and helps for debugging purposes. + +The following fields are available: + +- **originalTime** The original event time. +- **uploadTime** The time the event was uploaded. + + +### Common Data Extensions.sdk + +Used by platform specific libraries to record fields that are required for a specific SDK. + +The following fields are available: + +- **epoch** An ID that is incremented for each SDK initialization. +- **installId** An ID that's created during the initialization of the SDK for the first time. +- **libVer** The SDK version. +- **seq** An ID that is incremented for each event. + + +### Common Data Extensions.user + +Describes the fields related to a user. + +The following fields are available: + +- **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **locale** The language and region. +- **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. + + +### Common Data Extensions.utc + +Describes the properties that could be populated by a logging library on Windows. + +The following fields are available: + +- **aId** Represents the ETW ActivityId. Logged via TraceLogging or directly via ETW. +- **bSeq** Upload buffer sequence number in the format: buffer identifier:sequence number +- **cat** Represents a bitmask of the ETW Keywords associated with the event. +- **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. +- **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **flags** Represents the bitmap that captures various Windows specific flags. +- **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence +- **op** Represents the ETW Op Code. +- **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. +- **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. + + +### Common Data Extensions.xbl + +Describes the fields that are related to XBOX Live. + +The following fields are available: + +- **claims** Any additional claims whose short claim name hasn't been added to this structure. +- **did** XBOX device ID +- **dty** XBOX device type +- **dvr** The version of the operating system on the device. +- **eid** A unique ID that represents the developer entity. +- **exp** Expiration time +- **ip** The IP address of the client device. +- **nbf** Not before time +- **pid** A comma separated list of PUIDs listed as base10 numbers. +- **sbx** XBOX sandbox identifier +- **sid** The service instance ID. +- **sty** The service type. +- **tid** The XBOX Live title ID. +- **tvr** The XBOX Live title version. +- **uts** A bit field, with 2 bits being assigned to each user ID listed in xid. This field is omitted if all users are retail accounts. +- **xid** A list of base10-encoded XBOX User IDs. + + +## Common data fields + +### Ms.Device.DeviceInventoryChange + +Describes the installation state for all hardware and software components available on a particular device. + +The following fields are available: + +- **action** The change that was invoked on a device inventory object. +- **inventoryId** Device ID used for Compatibility testing +- **objectInstanceId** Object identity which is unique within the device scope. +- **objectType** Indicates the object type that the event applies to. +- **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. + + +## Compatibility events + +### Microsoft.Windows.Compatibility.Apphelp.SdbFix + +Product instrumentation for helping debug/troubleshoot issues with inbox compatibility components. + +The following fields are available: + +- **AppName** Name of the application impacted by SDB. +- **FixID** SDB GUID. +- **Flags** List of flags applied. +- **ImageName** Name of file. + + +## Component-based servicing events + +### CbsServicingProvider.CbsCapabilityEnumeration + +This event reports on the results of scanning for optional Windows content on Windows Update. + +The following fields are available: + +- **architecture** Indicates the scan was limited to the specified architecture. +- **capabilityCount** The number of optional content packages found during the scan. +- **clientId** The name of the application requesting the optional content. +- **duration** The amount of time it took to complete the scan. +- **hrStatus** The HReturn code of the scan. +- **language** Indicates the scan was limited to the specified language. +- **majorVersion** Indicates the scan was limited to the specified major version. +- **minorVersion** Indicates the scan was limited to the specified minor version. +- **namespace** Indicates the scan was limited to packages in the specified namespace. +- **sourceFilter** A bitmask indicating the scan checked for locally available optional content. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionFinalize + +This event provides information about the results of installing or uninstalling optional Windows content from Windows Update. + +The following fields are available: + +- **capabilities** The names of the optional content packages that were installed. +- **clientId** The name of the application requesting the optional content. +- **currentID** The ID of the current install session. +- **downloadSource** The source of the download. +- **highestState** The highest final install state of the optional content. +- **hrLCUReservicingStatus** Indicates whether the optional content was updated to the latest available version. +- **hrStatus** The HReturn code of the install operation. +- **rebootCount** The number of reboots required to complete the install. +- **retryID** The session ID that will be used to retry a failed operation. +- **retryStatus** Indicates whether the install will be retried in the event of failure. +- **stackBuild** The build number of the servicing stack. +- **stackMajorVersion** The major version number of the servicing stack. +- **stackMinorVersion** The minor version number of the servicing stack. +- **stackRevision** The revision number of the servicing stack. + + +### CbsServicingProvider.CbsCapabilitySessionPended + +This event provides information about the results of installing optional Windows content that requires a reboot to keep Windows up to date. + +The following fields are available: + +- **clientId** The name of the application requesting the optional content. +- **pendingDecision** Indicates the cause of reboot, if applicable. + + +### CbsServicingProvider.CbsLateAcquisition + +This event sends data to indicate if some Operating System packages could not be updated as part of an upgrade, to help keep Windows up to date. + +The following fields are available: + +- **Features** The list of feature packages that could not be updated. +- **RetryID** The ID identifying the retry attempt to update the listed packages. + + +### CbsServicingProvider.CbsPackageRemoval + +This event provides information about the results of uninstalling a Windows Cumulative Security Update to help keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build number of the security update being uninstalled. +- **clientId** The name of the application requesting the uninstall. +- **currentStateEnd** The final state of the update after the operation. +- **failureDetails** Information about the cause of a failure, if applicable. +- **failureSourceEnd** The stage during the uninstall where the failure occurred. +- **hrStatusEnd** The overall exit code of the operation. +- **initiatedOffline** Indicates if the uninstall was initiated for a mounted Windows image. +- **majorVersion** The major version number of the security update being uninstalled. +- **minorVersion** The minor version number of the security update being uninstalled. +- **originalState** The starting state of the update before the operation. +- **pendingDecision** Indicates the cause of reboot, if applicable. +- **primitiveExecutionContext** The state during system startup when the uninstall was completed. +- **revisionVersion** The revision number of the security update being uninstalled. +- **transactionCanceled** Indicates whether the uninstall was cancelled. + + +### CbsServicingProvider.CbsQualityUpdateInstall + +This event reports on the performance and reliability results of installing Servicing content from Windows Update to keep Windows up to date. + +The following fields are available: + +- **buildVersion** The build version number of the update package. +- **clientId** The name of the application requesting the optional content. +- **corruptionHistoryFlags** A bitmask of the types of component store corruption that have caused update failures on the device. +- **corruptionType** An enumeration listing the type of data corruption responsible for the current update failure. +- **currentStateEnd** The final state of the package after the operation has completed. +- **doqTimeSeconds** The time in seconds spent updating drivers. +- **executeTimeSeconds** The number of seconds required to execute the install. +- **failureDetails** The driver or installer that caused the update to fail. +- **failureSourceEnd** An enumeration indicating at what phase of the update a failure occurred. +- **hrStatusEnd** The return code of the install operation. +- **initiatedOffline** A true or false value indicating whether the package was installed into an offline Windows Imaging Format (WIM) file. +- **majorVersion** The major version number of the update package. +- **minorVersion** The minor version number of the update package. +- **originalState** The starting state of the package. +- **overallTimeSeconds** The time (in seconds) to perform the overall servicing operation. +- **planTimeSeconds** The time in seconds required to plan the update operations. +- **poqTimeSeconds** The time in seconds processing file and registry operations. +- **postRebootTimeSeconds** The time (in seconds) to do startup processing for the update. +- **preRebootTimeSeconds** The time (in seconds) between execution of the installation and the reboot. +- **primitiveExecutionContext** An enumeration indicating at what phase of shutdown or startup the update was installed. +- **rebootCount** The number of reboots required to install the update. +- **rebootTimeSeconds** The time (in seconds) before startup processing begins for the update. +- **resolveTimeSeconds** The time in seconds required to resolve the packages that are part of the update. +- **revisionVersion** The revision version number of the update package. +- **rptTimeSeconds** The time in seconds spent executing installer plugins. +- **shutdownTimeSeconds** The time (in seconds) required to do shutdown processing for the update. +- **stackRevision** The revision number of the servicing stack. +- **stageTimeSeconds** The time (in seconds) required to stage all files that are part of the update. + + +### CbsServicingProvider.CbsSelectableUpdateChangeV2 + +This event reports the results of enabling or disabling optional Windows Content to keep Windows up to date. + +The following fields are available: + +- **applicableUpdateState** Indicates the highest applicable state of the optional content. +- **buildVersion** The build version of the package being installed. +- **clientId** The name of the application requesting the optional content change. +- **downloadSource** Indicates if optional content was obtained from Windows Update or a locally accessible file. +- **downloadtimeInSeconds** The number of seconds required to complete the optional content download. +- **executionID** A unique ID used to identify events associated with a single servicing operation and not reused for future operations. +- **executionSequence** A counter that tracks the number of servicing operations attempted on the device. +- **firstMergedExecutionSequence** The value of a pervious executionSequence counter that is being merged with the current operation, if applicable. +- **firstMergedID** A unique ID of a pervious servicing operation that is being merged with this operation, if applicable. +- **hrDownloadResult** The return code of the download operation. +- **hrStatusUpdate** The return code of the servicing operation. +- **identityHash** A pseudonymized (hashed) identifier for the Windows Package that is being installed or uninstalled. +- **initiatedOffline** Indicates whether the operation was performed against an offline Windows image file or a running instance of Windows. +- **majorVersion** The major version of the package being installed. +- **minorVersion** The minor version of the package being installed. +- **packageArchitecture** The architecture of the package being installed. +- **packageLanguage** The language of the package being installed. +- **packageName** The name of the package being installed. +- **rebootRequired** Indicates whether a reboot is required to complete the operation. +- **revisionVersion** The revision number of the package being installed. +- **stackBuild** The build number of the servicing stack binary performing the installation. +- **stackMajorVersion** The major version number of the servicing stack binary performing the installation. +- **stackMinorVersion** The minor version number of the servicing stack binary performing the installation. +- **stackRevision** The revision number of the servicing stack binary performing the installation. +- **updateName** The name of the optional Windows Operation System feature being enabled or disabled. +- **updateStartState** A value indicating the state of the optional content before the operation started. +- **updateTargetState** A value indicating the desired state of the optional content. + + +## Deployment extensions + +### DeploymentTelemetry.Deployment_End + +This event indicates that a Deployment 360 API has completed. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** Phase in upgrade. +- **RelatedCV** The correction vector (CV) of any other related events +- **Result** End result of the action. + + +### DeploymentTelemetry.Deployment_SetupBoxLaunch + +This event indicates that the Deployment 360 APIs have launched Setup Box. + +The following fields are available: + +- **ClientId** The client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current setup phase. + + +### DeploymentTelemetry.Deployment_SetupBoxResult + +This event indicates that the Deployment 360 APIs have received a return from Setup Box. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **ErrorCode** Error code of the action. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Quiet** Indicates whether Setup will run in quiet mode or full mode. +- **RelatedCV** The correlation vector (CV) of any other related events. +- **SetupMode** The current Setup phase. + + +### DeploymentTelemetry.Deployment_Start + +This event indicates that a Deployment 360 API has been called. + +The following fields are available: + +- **ClientId** Client ID of the user utilizing the D360 API. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **Mode** The current phase of the upgrade. +- **RelatedCV** The correlation vector (CV) of any other related events. + + +## Diagnostic data events + +### TelClientSynthetic.AuthorizationInfo_RuntimeTransition + +This event sends data indicating that a device has undergone a change of telemetry opt-in level detected at UTC startup, to help keep Windows up to date. The telemetry opt-in level signals what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.AuthorizationInfo_Startup + +Fired by UTC at startup to signal what data we are allowed to collect. + +The following fields are available: + +- **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. +- **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. +- **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. +- **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. +- **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. +- **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **PreviousPermissions** Bitmask of previous telemetry state. +- **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. + + +### TelClientSynthetic.ConnectivityHeartBeat_0 + +This event sends data about the connectivity status of the Connected User Experience and Telemetry component that uploads telemetry events. If an unrestricted free network (such as Wi-Fi) is available, this event updates the last successful upload time. Otherwise, it checks whether a Connectivity Heartbeat event was fired in the past 24 hours, and if not, it fires an event. A Connectivity Heartbeat event also fires when a device recovers from costed network to free network. + +The following fields are available: + +- **CensusExitCode** Returns last execution codes from census client run. +- **CensusStartTime** Returns timestamp corresponding to last successful census run. +- **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. +- **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. +- **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. +- **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. +- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. +- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. +- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. + + +### TelClientSynthetic.HeartBeat_5 + +This event sends data about the health and quality of the diagnostic data from the given device, to help keep Windows up to date. It also enables data analysts to determine how 'trusted' the data is from a given device. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **CensusExitCode** The last exit code of the Census task. +- **CensusStartTime** Time of last Census run. +- **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CriticalOvErflowEntersCounter** No content is currently available. +- **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbDroppedCount** Number of events dropped due to DB fullness. +- **DbDroppedFailureCount** Number of events dropped due to DB failures. +- **DbDroppedFullCount** Number of events dropped due to DB fullness. +- **DecndingDroppedCount** No content is currently available. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. +- **EventStoreResetCounter** Number of times event DB was reset. +- **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventSubStoreResetCounter** Number of times event DB was reset. +- **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **FullTrigwerBufferDroppedCount** No content is currently available. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidH4BFCodeCount** No content is currently available. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidH4BFCode** No content is currently available. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsH4BFAttempts** No content is currently available. +- **SettingsH4BFFailures** No content is currently available. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexH4BFAttempts** No content is currently available. +- **VortexH4BFFailures4xx** No content is currently available. +- **VortexH4BFFailures5xx** No content is currently available. +- **VortexH4BFResponseFailures** No content is currently available. +- **VortexH4BFResponsesWithDroppedEvents** No content is currently available. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWi|hDroppedEvents** No content is currently available. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Aria_5 + +This event is the telemetry client ARIA heartbeat. + +The following fields are available: + +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped at the database layer. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times the event store has been reset. +- **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. +- **EventStoreResetSizeSum** Size of event store reset in bytes. +- **EventsUploaded** Number of events uploaded. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. +- **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting OneSettings service. +- **TopUploaderErrors** List of top errors received from the upload endpoint. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. +- **UploaderErrorCount** Number of errors received from the upload endpoint. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +### TelClientSynthetic.HeartBeat_Seville_5 + +This event is sent by the universal telemetry client (UTC) as a heartbeat signal for Sense. + +The following fields are available: + +- **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host or agent channel. +- **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDroppedCount** Number of events dropped at consumer layer of the telemetry client. +- **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDataThrottleDroppedCount** Number of critical data sampled events dropped due to throttling. +- **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event database. +- **DailyUploadQuotaInBytes** Daily upload quota for Sense in bytes (only in in-proc mode). +- **DbCriticalDroppedCount** Total number of dropped critical events in event database. +- **DbDroppedCount** Number of events dropped due to database being full. +- **DbDroppedFailureCount** Number of events dropped due to database failures. +- **DbDroppedFullCount** Number of events dropped due to database being full. +- **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **DiskSizeInBytes** Size of event store for Sense in bytes (only in in-proc mode). +- **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EtwDroppedBufferCount** Number of buffers dropped in the universal telemetry client (UTC) event tracing for Windows (ETW) session. +- **EtwDroppedCount** Number of events dropped at the event tracing for Windows (ETW) layer of telemetry client. +- **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLifetimeResetCounter** Number of times event the database was reset for the lifetime of the universal telemetry client (UTC). +- **EventStoreResetCounter** Number of times the event database was reset. +- **EventStoreResetSizeSum** Total size of the event database across all resets reports in this instance. +- **EventsUploaded** Number of events uploaded. +- **Flags** Flags indicating device state, such as network state, battery state, and opt-in state. +- **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. +- **LastEventSizeOffender** Event name of last event which exceeded the maximum event size. +- **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxActiveAgentConnectionCount** Maximum number of active agents during this heartbeat timeframe. +- **NormalUploadTimerMillis** Number of milliseconds between each upload of normal events for SENSE (only in in-proc mode). +- **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). +- **RepeatedUploadFailureDropped** Number of events lost due to repeated failed uploaded attempts. +- **SettingsHttpAttempts** Number of attempts to contact OneSettings service. +- **SettingsHttpFailures** Number of failures from contacting the OneSettings service. +- **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **TopUploaderErrors** Top uploader errors, grouped by endpoint and error type. +- **UploaderDroppedCount** Number of events dropped at the uploader layer of the telemetry client. +- **UploaderErrorCount** Number of input for the TopUploaderErrors mode estimation. +- **VortexFailuresTimeout** Number of time out failures received from Vortex. +- **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. +- **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. +- **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. + + +## Direct to update events + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicability + +Event to indicate that the Coordinator CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** Result of CheckApplicability function. +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **IsDeviceAADDomainJoined** Indicates whether the device is logged in to the AAD (Azure Active Directory) domain. +- **IsDeviceADDomainJoined** Indicates whether the device is logged in to the AD (Active Directory) domain. +- **IsDeviceCloverTrail** Indicates whether the device has a Clover Trail system installed. +- **IsDeviceFeatureUpdatingPaused** Indicates whether Feature Update is paused on the device. +- **IsDeviceNetworkMetered** Indicates whether the device is connected to a metered network. +- **IsDeviceOobeBlocked** Indicates whether user approval is required to install updates on the device. +- **IsDeviceRequireUpdateApproval** Indicates whether user approval is required to install updates on the device. +- **IsDeviceSccmManaged** Indicates whether the device is running the Microsoft SCCM (System Center Configuration Manager) to keep the operating system and applications up to date. +- **IsDeviceUninstallActive** Indicates whether the OS (operating system) on the device was recently updated. +- **IsDeviceUpdateNotificationLevel** Indicates whether the device has a set policy to control update notifications. +- **IsDeviceUpdateServiceManaged** Indicates whether the device uses WSUS (Windows Server Update Services). +- **IsDeviceZeroExhaust** Indicates whether the device subscribes to the Zero Exhaust policy to minimize connections from Windows to Microsoft. +- **IsGreaterThanMaxRetry** Indicates whether the DTU (Direct to Update) service has exceeded its maximum retry count. +- **IsVolumeLicensed** Indicates whether a volume license was used to authenticate the operating system or applications on the device. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCheckApplicabilityGenericFailure + +This event indicatse that we have received an unexpected error in the Direct to Update (DTU) Coordinators CheckApplicability call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Cleanup call. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector +- **hResult** HRESULT of the failure + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCleanupSuccess + +This event indicates that the Coordinator Cleanup call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run +- **ClientID** Client ID being run +- **CoordinatorVersion** Coordinator version of DTU +- **CV** Correlation vector + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Commit call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorCommitSuccess + +This event indicates that the Coordinator Commit call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Download call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Download call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorDownloadSuccess + +This event indicates that the Coordinator Download call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator HandleShutdown call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinate version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorHandleShutdownSuccess + +This event indicates that the Coordinator HandleShutdown call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Initialize call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInitializeSuccess + +This event indicates that the Coordinator Initialize call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Coordinator Install call. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallIgnoredFailure + +This event indicates that we have received an error in the Direct to Update (DTU) Coordinator Install call that will be ignored. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorProgressCallBack + +This event indicates that the Coordinator's progress callback has been called. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** Client ID being run. +- **CoordinatorVersion** Coordinator version of DTU. +- **CV** Correlation vector. +- **DeployPhase** Current Deploy Phase. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorSetCommitReadySuccess + +This event indicates that the Coordinator SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiNotShown + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** Campaign ID being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSelection + +This event indicates that the user selected an option on the Reboot UI. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **rebootUiSelection** Selection on the Reboot UI. + + +### Microsoft.Windows.DirectToUpdate.DTUCoordinatorWaitForRebootUiSuccess + +This event indicates that the Coordinator WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler CheckApplicabilityInternal call. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilityInternalSuccess + +This event indicates that the Handler CheckApplicabilityInternal call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result of the applicability check. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckApplicabilitySuccess + +This event indicates that the Handler CheckApplicability call succeeded. + +The following fields are available: + +- **ApplicabilityResult** The result code indicating whether the update is applicable. +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCheckIfCoordinatorMinApplicableVersionSuccess + +This event indicates that the Handler CheckIfCoordinatorMinApplicableVersion call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **CheckIfCoordinatorMinApplicableVersionResult** Result of CheckIfCoordinatorMinApplicableVersion function. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Commit call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerCommitSuccess + +This event indicates that the Handler Commit call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run.run +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **CV_new** New correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabFailure + +This event indicates that the Handler Download and Extract cab call failed. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_failureReason** Reason why the update download and extract process failed. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadAndExtractCabSuccess + +This event indicates that the Handler Download and Extract cab call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Download call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerDownloadSuccess + +This event indicates that the Handler Download call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Initialize call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extract. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInitializeSuccess + +This event indicates that the Handler Initialize call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **DownloadAndExtractCabFunction_hResult** HRESULT of the download and extraction. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler Install call. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerInstallSuccess + +This event indicates that the Coordinator Install call succeeded. + +The following fields are available: + +- **CampaignID** ID of the update campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerSetCommitReadySuccess + +This event indicates that the Handler SetCommitReady call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiGenericFailure + +This event indicates that we have received an unexpected error in the Direct to Update (DTU) Handler WaitForRebootUi call. + +The following fields are available: + +- **CampaignID** The ID of the campaigning being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. +- **hResult** The HRESULT of the failure. + + +### Microsoft.Windows.DirectToUpdate.DTUHandlerWaitForRebootUiSuccess + +This event indicates that the Handler WaitForRebootUi call succeeded. + +The following fields are available: + +- **CampaignID** ID of the campaign being run. +- **ClientID** ID of the client receiving the update. +- **CoordinatorVersion** Coordinator version of Direct to Update. +- **CV** Correlation vector. + + +## DxgKernelTelemetry events + +### DxgKrnlTelemetry.GPUAdapterInventoryV2 + +This event sends basic GPU and display driver information to keep Windows and display drivers up-to-date. + +The following fields are available: + +- **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. +- **aiSeqId** The event sequence ID. +- **bootId** The system boot ID. +- **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DisplayAdapterLuid** The display adapter LUID. +- **DriverDate** The date of the display driver. +- **DriverRank** The rank of the display driver. +- **DriverVersion** The display driver version. +- **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. +- **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. +- **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **GPUDeviceID** The GPU device ID. +- **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. +- **GPURevisionID** The GPU revision ID. +- **GPUVendorID** The GPU vendor ID. +- **InterfaceId** The GPU interface ID. +- **IsDisplayDevice** Does the GPU have displaying capabilities? +- **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsLDA** Is the GPU comprised of Linked Display Adapters? +- **IsMiracastSupported** Does the GPU support Miracast? +- **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMPOSupported** Does the GPU support Multi-Plane Overlays? +- **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? +- **IsPostAdapter** Is this GPU the POST GPU in the device? +- **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDevice** Does the GPU have rendering capabilities? +- **IsSoftwareDevice** Is this a software implementation of the GPU? +- **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? +- **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. +- **NumVidPnSources** The number of supported display output sources. +- **NumVidPnTargets** The number of supported display output targets. +- **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). +- **SubSystemID** The subsystem ID. +- **SubVendorID** The GPU sub vendor ID. +- **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **version** The event version. +- **WDDMVersion** The Windows Display Driver Model version. + + +## Failover Clustering events + +### Microsoft.Windows.Server.FailoverClusteringCritical.ClusterSummary2 + +This event returns information about how many resources and of what type are in the server cluster. This data is collected to keep Windows Server safe, secure, and up to date. The data includes information about whether hardware is configured correctly, if the software is patched correctly, and assists in preventing crashes by attributing issues (like fatal errors) to workloads and system configurations. + +The following fields are available: + +- **autoAssignSite** The cluster parameter: auto site. +- **autoBalancerLevel** The cluster parameter: auto balancer level. +- **autoBalancerMode** The cluster parameter: auto balancer mode. +- **blockCacheSize** The configured size of the block cache. +- **ClusterAdConfiguration** The ad configuration of the cluster. +- **clusterAdType** The cluster parameter: mgmt_point_type. +- **clusterDumpPolicy** The cluster configured dump policy. +- **clusterFunctionalLevel** The current cluster functional level. +- **clusterGuid** The unique identifier for the cluster. +- **clusterWitnessType** The witness type the cluster is configured for. +- **countNodesInSite** The number of nodes in the cluster. +- **crossSiteDelay** The cluster parameter: CrossSiteDelay. +- **crossSiteThreshold** The cluster parameter: CrossSiteThreshold. +- **crossSubnetDelay** The cluster parameter: CrossSubnetDelay. +- **crossSubnetThreshold** The cluster parameter: CrossSubnetThreshold. +- **csvCompatibleFilters** The cluster parameter: ClusterCsvCompatibleFilters. +- **csvIncompatibleFilters** The cluster parameter: ClusterCsvIncompatibleFilters. +- **csvResourceCount** The number of resources in the cluster. +- **currentNodeSite** The name configured for the current site for the cluster. +- **dasModeBusType** The direct storage bus type of the storage spaces. +- **downLevelNodeCount** The number of nodes in the cluster that are running down-level. +- **drainOnShutdown** Specifies whether a node should be drained when it is shut down. +- **dynamicQuorumEnabled** Specifies whether dynamic Quorum has been enabled. +- **enforcedAntiAffinity** The cluster parameter: enforced anti affinity. +- **genAppNames** The win32 service name of a clustered service. +- **genSvcNames** The command line of a clustered genapp. +- **hangRecoveryAction** The cluster parameter: hang recovery action. +- **hangTimeOut** Specifies the “hang time out” parameter for the cluster. +- **isCalabria** Specifies whether storage spaces direct is enabled. +- **isMixedMode** Identifies if the cluster is running with different version of OS for nodes. +- **isRunningDownLevel** Identifies if the current node is running down-level. +- **logLevel** Specifies the granularity that is logged in the cluster log. +- **logSize** Specifies the size of the cluster log. +- **lowerQuorumPriorityNodeId** The cluster parameter: lower quorum priority node ID. +- **minNeverPreempt** The cluster parameter: minimum never preempt. +- **minPreemptor** The cluster parameter: minimum preemptor priority. +- **netftIpsecEnabled** The parameter: netftIpsecEnabled. +- **NodeCount** The number of nodes in the cluster. +- **nodeId** The current node number in the cluster. +- **nodeResourceCounts** Specifies the number of node resources. +- **nodeResourceOnlineCounts** Specifies the number of node resources that are online. +- **numberOfSites** The number of different sites. +- **numNodesInNoSite** The number of nodes not belonging to a site. +- **plumbAllCrossSubnetRoutes** The cluster parameter: plumb all cross subnet routes. +- **preferredSite** The preferred site location. +- **privateCloudWitness** Specifies whether a private cloud witness exists for this cluster. +- **quarantineDuration** The quarantine duration. +- **quarantineThreshold** The quarantine threshold. +- **quorumArbitrationTimeout** In the event of an arbitration event, this specifies the quorum timeout period. +- **resiliencyLevel** Specifies the level of resiliency. +- **resourceCounts** Specifies the number of resources. +- **resourceTypeCounts** Specifies the number of resource types in the cluster. +- **resourceTypes** Data representative of each resource type. +- **resourceTypesPath** Data representative of the DLL path for each resource type. +- **sameSubnetDelay** The cluster parameter: same subnet delay. +- **sameSubnetThreshold** The cluster parameter: same subnet threshold. +- **secondsInMixedMode** The amount of time (in seconds) that the cluster has been in mixed mode (nodes with different operating system versions in the same cluster). +- **securityLevel** The cluster parameter: security level. +- **securityLevelForStorage** The cluster parameter: security level for storage. +- **sharedVolumeBlockCacheSize** Specifies the block cache size for shared for shared volumes. +- **shutdownTimeoutMinutes** Specifies the amount of time it takes to time out when shutting down. +- **upNodeCount** Specifies the number of nodes that are up (online). +- **useClientAccessNetworksForCsv** The cluster parameter: use client access networks for CSV. +- **vmIsolationTime** The cluster parameter: VM isolation time. +- **witnessDatabaseWriteTimeout** Specifies the timeout period for writing to the quorum witness database. + + +## Fault Reporting events + +### Microsoft.Windows.FaultReporting.AppCrashEvent + +This event sends data about crashes for both native and managed applications, to help keep Windows up to date. The data includes information about the crashing process and a summary of its exception record. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the crash to the Watson service, and the WER event will contain the same ReportID (see field 14 of crash event, field 19 of WER event) as the crash event for the crash being reported. AppCrash is emitted once for each crash handled by WER (e.g. from an unhandled exception or FailFast or ReportException). Note that Generic Watson event types (e.g. from PLM) that may be considered crashes\" by a user DO NOT emit this event. + +The following fields are available: + +- **AppName** The name of the app that has crashed. +- **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimeStamp** The date/time stamp of the app. +- **AppVersion** The version of the app that has crashed. +- **AsFatal** No content is currently available. +- **Exceptio** No content is currently available. +- **ExceptionCode** The exception code returned by the process that has crashed. +- **ExceptionOffset** The address where the exception had occurred. +- **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. +- **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **ModName** Exception module name (e.g. bar.dll). +- **ModTimestamp** No content is currently available. +- **ModTimeStamp** The date/time stamp of the module. +- **ModVersion** The version of the module that has crashed. +- **ode** No content is currently available. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessId** The ID of the process that has crashed. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **targetAppVer** No content is currently available. +- **TargetAppVer** The specific version of the application being reported +- **TargetAsId** The sequence number for the hanging process. + + +## Feature update events + +### Microsoft.Windows.Upgrade.Uninstall.UninstallFinalizedAndRebootTriggered + +This event indicates that the uninstall was properly configured and that a system reboot was initiated. + + + +### Microsoft.Windows.Upgrade.Uninstall.UninstallGoBackButtonClicked + +This event sends basic metadata about the starting point of uninstalling a feature update, which helps ensure customers can safely revert to a well-known state if the update caused any problems. + + + +## Hang Reporting events + +### Microsoft.Windows.HangReporting.AppHangEvent + +This event sends data about hangs for both native and managed applications, to help keep Windows up to date. It does not contain any Watson bucketing information. The bucketing information is recorded in a Windows Error Reporting (WER) event that is generated when the WER client reports the hang to the Watson service, and the WER event will contain the same ReportID (see field 13 of hang event, field 19 of WER event) as the hang event for the hang being reported. AppHang is reported only on PC devices. It handles classic Win32 hangs and is emitted only once per report. Some behaviors that may be perceived by a user as a hang are reported by app managers (e.g. PLM/RM/EM) as Watson Generics and will not produce AppHang events. + +The following fields are available: + +- **AppName** The name of the app that has hung. +- **AppSessionGuid** GUID made up of process id used as a correlation vector for process instances in the telemetry backend. +- **AppVersion** The version of the app that has hung. +- **IsFatal** True/False based on whether the hung application caused the creation of a Fatal Hang Report. +- **PackageFullName** Store application identity. +- **PackageRelativeAppId** Store application identity. +- **ProcessArchitecture** Architecture of the hung process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessCreateTime** The time of creation of the process that has hung. +- **ProcessId** The ID of the process that has hung. +- **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargetAppId** The kernel reported AppId of the application being reported. +- **TargetAppVer** The specific version of the application being reported. +- **TargetAsId** The sequence number for the hanging process. +- **TypeCode** Bitmap describing the hang type. +- **WaitingOnAppName** If this is a cross process hang waiting for an application, this has the name of the application. +- **WaitingOnAppVersion** If this is a cross process hang, this has the version of the application for which it is waiting. +- **WaitingOnPackageFullName** If this is a cross process hang waiting for a package, this has the full name of the package for which it is waiting. +- **WaitingOnPackageRelativeAppId** If this is a cross process hang waiting for a package, this has the relative application id of the package. + + +## Inventory events + +### Microsoft.Windows.Inventory.Core.AmiTelCacheChecksum + +This event captures basic checksum data about the device inventory items stored in the cache for use in validating data completeness for Microsoft.Windows.Inventory.Core events. The fields in this event may change over time, but they will always represent a count of a given object. + +The following fields are available: + +- **Device** A count of device objects in cache. +- **DeviceCensus** A count of device census objects in cache. +- **DriverPackageExtended** A count of driverpackageextended objects in cache. +- **File** A count of file objects in cache. +- **FileSigningInfo** A count of file signing objects in cache. +- **Generic** A count of generic objects in cache. +- **HwItem** A count of hwitem objects in cache. +- **IentoryMiscellaneousOfficeAddIn** No content is currently available. +- **InventoryApplication** A count of application objects in cache. +- **InventoryApplicationAppV** A count of application AppV objects in cache. +- **InventoryApplicationDriver** A count of application driver objects in cache +- **InventoryApplicationFile** A count of application file objects in cache. +- **InventoryApplicationFramework** A count of application framework objects in cache +- **InventoryApplicationShortcut** A count of application shortcut objects in cache +- **InventoryDeviceContainer** A count of device container objects in cache. +- **InventoryDeviceInterface** A count of Plug and Play device interface objects in cache. +- **InventoryDeviceMediaClass** A count of device media objects in cache. +- **InventoryDevicePnp** A count of device Plug and Play objects in cache. +- **InventoryDeviceUsbHubClass** A count of device usb objects in cache +- **InventoryDriverBinary** A count of driver binary objects in cache. +- **InventoryDriverPackage** A count of device objects in cache. +- **InventoryMiscellaneiscellaneousOfficeInsights** No content is currently available. +- **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache +- **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. +- **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache +- **InventoryMiscellaneousOfficeIESettings** A count of office ie settings objects in cache +- **InventoryMiscellaneousOfficeInsights** A count of office insights objects in cache +- **InventoryMiscellaneousOfficeProducts** A count of office products objects in cache +- **InventoryMiscellaneousOfficeSettings** A count of office settings objects in cache +- **InventoryMiscellaneousOfficeVBA** A count of office vba objects in cache +- **InventoryMiscellaneousOfficeVBARuleViolations** A count of office vba rule violations objects in cache +- **InventoryMiscellaneousUUPInfo** A count of uup info objects in cache +- **Metadata** A count of metadata objects in cache. +- **Orphan** A count of orphan file objects in cache. +- **Programs** A count of program objects in cache. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheFileInfo + +Diagnostic data about the inventory cache. + +The following fields are available: + +- **CacheFileSize** Size of the cache. +- **InventoryVersion** Inventory version of the cache. +- **TempCacheCount** Number of temp caches created. +- **TempCacheDeletedCount** Number of temp caches deleted. + + +### Microsoft.Windows.Inventory.Core.AmiTelCacheVersions + +This event sends inventory component versions for the Device Inventory data. + +The following fields are available: + +- **aeinv** The version of the App inventory component. +- **devinv** The file version of the Device inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationAdd + +This event sends basic metadata about an application on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **HiddenArp** Indicates whether a program hides itself from showing up in ARP. +- **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). +- **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 +- **InstallDateFromLincFile** No content is currently available. +- **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. +- **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InventoryVersion** The version of the inventory file generating the events. +- **Language** The language code of the program. +- **MsipackageCode** No content is currently available. +- **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiProductCode** A GUID that describe the MSI Product. +- **Name** The name of the application. +- **OSversionAtInstallTime** No content is currently available. +- **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **PackageFullName** The package full name for a Store application. +- **ProgramInstanceId** A hash of the file IDs in an app. +- **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDirPath** The path to the root directory where the program was installed. +- **Source** How the program was installed (for example, ARP, MSI, Appx). +- **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. +- **type** No content is currently available. +- **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. +- **Version** The version number of the program. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverAdd + +This event represents what drivers an application installs. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. +- **ProgramIds** The unique program identifier the driver is associated with. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationDriverStartSync + +The InventoryApplicationDriverStartSync event indicates that a new set of InventoryApplicationDriverStartAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory component. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkAdd + +This event provides the basic metadata about the frameworks an application may depend on. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **FileId** A hash that uniquely identifies a file. +- **Frameworks** The list of frameworks this file depends on. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationFrameworkStartSync + +This event indicates that a new set of InventoryApplicationFrameworkAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationRemove + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryApplicationStartSync + +This event indicates that a new set of InventoryApplicationAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerAdd + +This event sends basic metadata about a device container (such as a monitor or printer as opposed to a Plug and Play device) to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Categories** A comma separated list of functional categories in which the container belongs. +- **DiscoveryMethod** The discovery method for the device container. +- **FriendlyName** The name of the device container. +- **InventoryVersion** The version of the inventory file generating the events. +- **IsActive** Is the device connected, or has it been seen in the last 14 days? +- **IsConnected** For a physically attached device, this value is the same as IsPresent. For wireless a device, this value represents a communication link. +- **IsMachineContainer** Is the container the root device itself? +- **IsNetworked** Is this a networked device? +- **IsPaired** Does the device container require pairing? +- **Manufacturer** The manufacturer name for the device container. +- **ModelId** A unique model ID. +- **ModelName** The model name. +- **ModelNumber** The model number for the device container. +- **PrimaryCategory** The primary category for the device container. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerRemove + +This event indicates that the InventoryDeviceContainer object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceContainerStartSync + +This event indicates that a new set of InventoryDeviceContainerAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceAdd + +This event retrieves information about what sensor interfaces are available on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Accelerometer3D** Indicates if an Accelerator3D sensor is found. +- **ActivityDetection** Indicates if an Activity Detection sensor is found. +- **AmbientLight** Indicates if an Ambient Light sensor is found. +- **Barometer** Indicates if a Barometer sensor is found. +- **Custom** Indicates if a Custom sensor is found. +- **EnergyMeter** Indicates if an Energy sensor is found. +- **FloorElevation** Indicates if a Floor Elevation sensor is found. +- **GeomagneticOrientation** Indicates if a Geo Magnetic Orientation sensor is found. +- **GravityVector** Indicates if a Gravity Detector sensor is found. +- **Gyrometer3D** Indicates if a Gyrometer3D sensor is found. +- **Humidity** Indicates if a Humidity sensor is found. +- **InventoryVersion** The version of the inventory file generating the events. +- **LinearAccelerometer** Indicates if a Linear Accelerometer sensor is found. +- **Magnetometer3D** Indicates if a Magnetometer3D sensor is found. +- **Orientation** Indicates if an Orientation sensor is found. +- **Pedometer** Indicates if a Pedometer sensor is found. +- **Proximity** Indicates if a Proximity sensor is found. +- **RelativeOrientation** Indicates if a Relative Orientation sensor is found. +- **SimpleDeviceOrientation** Indicates if a Simple Device Orientation sensor is found. +- **Temperature** Indicates if a Temperature sensor is found. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceInterfaceStartSync + +This event indicates that a new set of InventoryDeviceInterfaceAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassAdd + +This event sends additional metadata about a Plug and Play device that is specific to a particular class of devices to help keep Windows up to date while reducing overall size of data payload. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **audio.captureDriver** Audio device capture driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14887.1000:hdaudio\func_01 +- **audio.renderDriver** Audio device render driver. Example: hdaudio.inf:db04a16ce4e8d6ee:HdAudModel:10.0.14889.1001:hdaudio\func_01 +- **Audio_CaptureDriver** The Audio device capture driver endpoint. +- **Audio_RenderDriver** The Audio device render driver endpoint. +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassRemove + +This event indicates that the InventoryDeviceMediaClassRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceMediaClassStartSync + +This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. + +This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpAdd + +This event represents the basic metadata about a plug and play (PNP) device and its associated driver. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **]pperClassFilters** No content is currently available. +- **basedata** No content is currently available. See [basedata](#basedata). +- **BusReportedDescraption** No content is currently available. +- **BusReportedDescription** The description of the device reported by the bux. +- **BusReptrtedDescription** No content is currently available. +- **Clas{Guid** No content is currently available. +- **Class** The device setup class of the driver loaded for the device. +- **ClassGuid** The device class unique identifier of the driver package loaded on the device. +- **COMPID** The list of “Compatible IDs” for this device. +- **Con|ainerId** No content is currently available. +- **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. +- **Descriptaon** No content is currently available. +- **Description** The description of the device. +- **DeviceDriverFlightId** No content is currently available. +- **DeviceExtDriversFlightIds** No content is currently available. +- **DeviceInterfaceClasses** The device interfaces that this device implements. +- **DeviceState** Identifies the current state of the parent (main) device. +- **DriverAd** No content is currently available. +- **DriverId** The unique identifier for the installed driver. +- **DriverName** The name of the driver image file. +- **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverVer^ersion** No content is currently available. +- **DriverVerDate** The date associated with the driver installed on the device. +- **DriverVerVersion** The version number of the driver installed on the device. +- **Enumerator** Identifies the bus that enumerated the device. +- **ExtendedInfs** The extended INF file names. +- **FirstInstallDate** No content is currently available. +- **H_ID** No content is currently available. +- **HWID** A list of hardware IDs for the device. +- **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). +- **InstallDate** No content is currently available. +- **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx +- **InventoryVersion** The version number of the inventory process generating the events. +- **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. +- **LowerFilters** The identifiers of the Lower filters installed for the device. +- **Manufacturer** The manufacturer of the device. +- **MatchangID** No content is currently available. +- **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. +- **Modeh** No content is currently available. +- **Model** Identifies the model of the device. +- **ParentId** The Device Instance ID of the parent of the device. +- **ProblemCode** The error code currently returned by the device, if applicable. +- **ProblmmCode** No content is currently available. +- **Provider** Identifies the device provider. +- **Service** The name of the device service. +- **STACKID** The list of hardware IDs for the stack. +- **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. +- **UpperFilters** The identifiers of the Upper filters installed for the device. +- **UpxerClassFilters** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove + +This event indicates that the InventoryDevicePnpRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync + +This event indicates that a new set of InventoryDevicePnpAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassAdd + +This event sends basic metadata about the USB hubs on the device. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. +- **TotalUserConnectablePorts** Total number of connectable USB ports. +- **TotalUserConnectableTypeCPorts** Total number of connectable USB Type C ports. + + +### Microsoft.Windows.Inventory.Core.InventoryDeviceUsbHubClassStartSync + +This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. + +This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryAdd + +This event provides the basic metadata about driver binaries running on the system. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **DrivdrCompany** No content is currently available. +- **DriverCheckSum** The checksum of the driver file. +- **DriverCompany** The company name that developed the driver. +- **DriverInBox** Is the driver included with the operating system? +- **DriverIsKernelMode** Is it a kernel mode driver? +- **DriverName** The file name of the driver. +- **DriverPackageStrongName** The strong name of the driver package +- **DriverSigned** The strong name of the driver package +- **DriverTimeStamp** The low 32 bits of the time stamp of the driver file. +- **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. +- **DriverVersion** The version of the driver file. +- **ImageSize** The size of the driver file. +- **ImageSmze** No content is currently available. +- **Inf** The name of the INF file. +- **InventoryVersion** The version of the inventory file generating the events. +- **Product** The product name that is included in the driver file. +- **ProductVersion** The product version that is included in the driver file. +- **Service** The name of the service that is installed for the device. +- **WdfVersion** The Windows Driver Framework version. +- **WdfVers-on** No content is currently available. +- **WdfVersÿon** No content is currently available. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove + +This event indicates that the InventoryDriverBinary object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryStartSync + +This event indicates that a new set of InventoryDriverBinaryAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageAdd + +This event sends basic metadata about drive packages installed on the system to help keep Windows up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Class** The class name for the device driver. +- **ClassGuid** The class GUID for the device driver. +- **Date** The driver package date. +- **Directory** The path to the driver package. +- **DriverInBox** Is the driver included with the operating system? +- **Inf** The INF name of the driver package. +- **InventoryVersion** The version of the inventory file generating the events. +- **Provider** The provider for the driver package. +- **SubmissionId** The HLK submission ID for the driver package. +- **Version** The version of the driver package. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageRemove + +This event indicates that the InventoryDriverPackageRemove object is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.InventoryDriverPackageStartSync + +This event indicates that a new set of InventoryDriverPackageAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory file generating the events. + + +### Microsoft.Windows.Inventory.Core.StartUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. + + + +### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace + +This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. + + + +### Microsoft.Windows.Inventory.General.AppHealthStaticAdd + +This event sends details collected for a specific application on the source device. + +The following fields are available: + +- **AhaVersion** The binary version of the App Health Analyzer tool. +- **ApplicationErrors** The count of application errors from the event log. +- **Bitness** The architecture type of the application (16 Bit or 32 bit or 64 bit). +- **device_level** Various JRE/JAVA versions installed on a particular device. +- **ExtendedProperties** Attribute used for aggregating all other attributes under this event type. +- **Jar** Flag to determine if an app has a Java JAR file dependency. +- **Jre** Flag to determine if an app has JRE framework dependency. +- **Jre_version** JRE versions an app has declared framework dependency for. +- **Name** Name of the application. +- **NonDPIAware** Flag to determine if an app is non-DPI aware. +- **NumBinaries** Count of all binaries (.sys,.dll,.ini) from application install location. +- **RequiresAdmin** Flag to determine if an app requests admin privileges for execution. +- **RequiresAdminv2** Additional flag to determine if an app requests admin privileges for execution. +- **RequiresUIAccess** Flag to determine if an app is based on UI features for accessibility. +- **VB6** Flag to determine if an app is based on VB6 framework. +- **VB6v2** Additional flag to determine if an app is based on VB6 framework. +- **Version** Version of the application. +- **VersionCheck** Flag to determine if an app has a static dependency on OS version. +- **VersionCheckv2** Additional flag to determine if an app has a static dependency on OS version. + + +### Microsoft.Windows.Inventory.General.AppHealthStaticStartSync + +This event indicates the beginning of a series of AppHealthStaticAdd events. + +The following fields are available: + +- **AllowTelemetry** Indicates the presence of the 'allowtelemetry' command line argument. +- **CommandLineArgs** Command line arguments passed when launching the App Health Analyzer executable. +- **Enhanced** Indicates the presence of the 'enhanced' command line argument. +- **StartTime** UTC date and time at which this event was sent. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInAdd + +Provides data on the installed Office Add-ins. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **AddinCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInCLSID** The class identifier key for the Microsoft Office add-in. +- **AddInId** The identifier for the Microsoft Office add-in. +- **AddinType** The type of the Microsoft Office add-in. +- **BinFileTimestamp** The timestamp of the Office add-in. +- **BinFileVersion** The version of the Microsoft Office add-in. +- **Description** Description of the Microsoft Office add-in. +- **FileId** The file identifier of the Microsoft Office add-in. +- **FileSize** The file size of the Microsoft Office add-in. +- **FriendlyName** The friendly name for the Microsoft Office add-in. +- **FullPath** The full path to the Microsoft Office add-in. +- **InventoryVersion** The version of the inventory binary generating the events. +- **LoadBehavior** Integer that describes the load behavior. +- **LoadTime** Load time for the Office add-in. +- **OfficeApplication** The Microsoft Office application associated with the add-in. +- **OfficeArchitecture** The architecture of the add-in. +- **OfficeVersion** The Microsoft Office version for this add-in. +- **OutlookCrashingAddin** Indicates whether crashes have been found for this add-in. +- **ProductCompany** The name of the company associated with the Office add-in. +- **ProductName** The product name associated with the Microsoft Office add-in. +- **ProductVersion** The version associated with the Office add-in. +- **ProgramId** The unique program identifier of the Microsoft Office add-in. +- **Provider** Name of the provider for this add-in. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeAddInStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersAdd + +Provides data on the Office identifiers. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OAudienceData** Sub-identifier for Microsoft Office release management, identifying the pilot group for a device +- **OAudienceId** Microsoft Office identifier for Microsoft Office release management, identifying the pilot group for a device +- **OMID** Identifier for the Office SQM Machine +- **OPlatform** Whether the installed Microsoft Office product is 32-bit or 64-bit +- **OTenantId** Unique GUID representing the Microsoft O365 Tenant +- **OVersion** Installed version of Microsoft Office. For example, 16.0.8602.1000 +- **OWowMID** Legacy Microsoft Office telemetry identifier (SQM Machine ID) for WoW systems (32-bit Microsoft Office on 64-bit Windows) + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIdentifiersStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsAdd + +Provides data on Office-related Internet Explorer features. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OIeFeatureAddon** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_ADDON_MANAGEMENT feature lets applications hosting the WebBrowser Control to respect add-on management selections made using the Add-on Manager feature of Internet Explorer. Add-ons disabled by the user or by administrative group policy will also be disabled in applications that enable this feature. +- **OIeMachineLockdown** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_LOCALMACHINE_LOCKDOWN feature is enabled, Internet Explorer applies security restrictions on content loaded from the user's local machine, which helps prevent malicious behavior involving local files. +- **OIeMimeHandling** Flag indicating which Microsoft Office products have this setting enabled. When the FEATURE_MIME_HANDLING feature control is enabled, Internet Explorer handles MIME types more securely. Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeMimeSniffing** Flag indicating which Microsoft Office products have this setting enabled. Determines a file's type by examining its bit signature. Windows Internet Explorer uses this information to determine how to render the file. The FEATURE_MIME_SNIFFING feature, when enabled, allows to be set differently for each security zone by using the URLACTION_FEATURE_MIME_SNIFFING URL action flag +- **OIeNoAxInstall** Flag indicating which Microsoft Office products have this setting enabled. When a webpage attempts to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request. When a webpage tries to load or install an ActiveX control that isn't already installed, the FEATURE_RESTRICT_ACTIVEXINSTALL feature blocks the request +- **OIeNoDownload** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_RESTRICT_FILEDOWNLOAD feature blocks file download requests that navigate to a resource, that display a file download dialog box, or that are not initiated explicitly by a user action (for example, a mouse click or key press). Only applies to Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2) +- **OIeObjectCaching** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_OBJECT_CACHING feature prevents webpages from accessing or instantiating ActiveX controls cached from different domains or security contexts +- **OIePasswordDisable** Flag indicating which Microsoft Office products have this setting enabled. After Windows Internet Explorer 6 for Windows XP Service Pack 2 (SP2), Internet Explorer no longer allows usernames and passwords to be specified in URLs that use the HTTP or HTTPS protocols. URLs using other protocols, such as FTP, still allow usernames and passwords +- **OIeSafeBind** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SAFE_BINDTOOBJECT feature performs additional safety checks when calling MonikerBindToObject to create and initialize Microsoft ActiveX controls. Specifically, prevent the control from being created if COMPAT_EVIL_DONT_LOAD is in the registry for the control +- **OIeSecurityBand** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_SECURITYBAND feature controls the display of the Internet Explorer Information bar. When enabled, the Information bar appears when file download or code installation is restricted +- **OIeUncSaveCheck** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_UNC_SAVEDFILECHECK feature enables the Mark of the Web (MOTW) for local files loaded from network locations that have been shared by using the Universal Naming Convention (UNC) +- **OIeValidateUrl** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_VALIDATE_NAVIGATE_URL feature control prevents Windows Internet Explorer from navigating to a badly formed URL +- **OIeWebOcPopup** Flag indicating which Microsoft Office products have this setting enabled. The FEATURE_WEBOC_POPUPMANAGEMENT feature allows applications hosting the WebBrowser Control to receive the default Internet Explorer pop-up window management behavior +- **OIeWinRestrict** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_WINDOW_RESTRICTIONS feature adds several restrictions to the size and behavior of popup windows +- **OIeZoneElevate** Flag indicating which Microsoft Office products have this setting enabled. When enabled, the FEATURE_ZONE_ELEVATION feature prevents pages in one zone from navigating to pages in a higher security zone unless the navigation is generated by the user + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeIESettingsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsAdd + +This event provides insight data on the installed Office products + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OfficeApplication** The name of the Office application. +- **OfficeArchitecture** The bitness of the Office application. +- **OfficeVersion** The version of the Office application. +- **Valóe** No content is currently available. +- **Value** The insights collected about this entity. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeInsightsStartSync + +This diagnostic event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsAdd + +Describes Office Products installed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. +- **OC2rApps** A GUID the describes the Office Click-To-Run apps +- **OC2rSkus** Comma-delimited list (CSV) of Office Click-To-Run products installed on the device. For example, Office 2016 ProPlus +- **OMsiApps** Comma-delimited list (CSV) of Office MSI products installed on the device. For example, Microsoft Word +- **OProductCodes** A GUID that describes the Office MSI products + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeProductsStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsAdd + +This event describes various Office settings + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **BrowserFlags** Browser flags for Office-related products +- **ExchangeProviderFlags** Provider policies for Office Exchange +- **InventoryVersion** The version of the inventory binary generating the events. +- **SharedComputerLicensing** Office shared computer licensing policies + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeSettingsStartSync + +Indicates a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAAdd + +This event provides a summary rollup count of conditions encountered while performing a local scan of Office files, analyzing for known VBA programmability compatibility issues between legacy office version and ProPlus, and between 32 and 64-bit versions + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Design** Count of files with design issues found. +- **Design_x64** Count of files with 64 bit design issues found. +- **DuplicateVBA** Count of files with duplicate VBA code. +- **HasVBA** Count of files with VBA code. +- **Inaccessible** Count of files that were inaccessible for scanning. +- **InventoryVersion** The version of the inventory binary generating the events. +- **Issues** Count of files with issues detected. +- **Issues_x64** Count of files with 64-bit issues detected. +- **IssuesNone** Count of files with no issues detected. +- **IssuesNone_x64** Count of files with no 64-bit issues detected. +- **Locked** Count of files that were locked, preventing scanning. +- **NoVBA** Count of files with no VBA inside. +- **Protected** Count of files that were password protected, preventing scanning. +- **RemLimited** Count of files that require limited remediation changes. +- **RemLimited_x64** Count of files that require limited remediation changes for 64-bit issues. +- **RemSignificant** Count of files that require significant remediation changes. +- **RemSignificant_x64** Count of files that require significant remediation changes for 64-bit issues. +- **Score** Overall compatibility score calculated for scanned content. +- **Score_x64** Overall 64-bit compatibility score calculated for scanned content. +- **Total** Total number of files scanned. +- **Validation** Count of files that require additional manual validation. +- **Validation_x64** Count of files that require additional manual validation for 64-bit issues. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsAdd + +This event provides data on Microsoft Office VBA rule violations, including a rollup count per violation type, giving an indication of remediation requirements for an organization. The event identifier is a unique GUID, associated with the validation rule + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Count** Count of total Microsoft Office VBA rule violations +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBARuleViolationsStartSync + +This event indicates that a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousOfficeVBAStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **InventoryVersion** The version of the inventory binary generating the events. + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoAdd + +Provides data on Unified Update Platform (UUP) products and what version they are at. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **Identifier** UUP identifier +- **LastActivatedVersion** Last activated version +- **PreviousVersion** Previous version +- **Source** UUP source +- **Version** UUP version + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoRemove + +Indicates that this particular data object represented by the objectInstanceId is no longer present. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.General.InventoryMiscellaneousUUPInfoStartSync + +Diagnostic event to indicate a new sync is being generated for this object type. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.Checksum + +This event summarizes the counts for the InventoryMiscellaneousUexIndicatorAdd events. + +The following fields are available: + +- **CensusId** A unique hardware identifier. +- **ChecksumDictionary** A count of each operating system indicator. +- **PCFP** Equivalent to the InventoryId field that is found in other core events. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorAdd + +These events represent the basic metadata about the OS indicators installed on the system which are used for keeping the device up to date. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + +The following fields are available: + +- **IndicatorValue** The indicator value. +- **Value** Describes an operating system indicator that may be relevant for the device upgrade. + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorRemove + +This event is a counterpart to InventoryMiscellaneousUexIndicatorAdd that indicates that the item has been removed. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +### Microsoft.Windows.Inventory.Indicators.InventoryMiscellaneousUexIndicatorStartSync + +This event indicates that a new set of InventoryMiscellaneousUexIndicatorAdd events will be sent. + +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). + + + +## Kernel events + +### IO + +This event indicates the number of bytes read from or read by the OS and written to or written by the OS upon system startup. + +The following fields are available: + +- **BootAttemptCount** No content is currently available. +- **BootStatusPolicy** No content is currently available. +- **BootType** No content is currently available. +- **BytesRead** The total number of bytes read from or read by the OS upon system startup. +- **BytesWritten** The total number of bytes written to or written by the OS upon system startup. +- **FirmwareResetReasonEmbeddedController** No content is currently available. +- **FirmwareResetReasonEmbeddedControllerAdditional** No content is currently available. +- **FirmwareResetReasonPch** No content is currently available. +- **FirmwareResetReasonPchAdditional** No content is currently available. +- **FirmwareResetReasonSupplied** No content is currently available. +- **LastBootSucceeded** No content is currently available. +- **LastShutdownSucceeded** No content is currently available. +- **MeasuredLaunchResume** No content is currently available. +- **MenuPolicy** No content is currently available. +- **RecoveryEnabled** No content is currently available. +- **UserInputTime** No content is currently available. + + +### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch + +OS information collected during Boot, used to evaluate the success of the upgrade process. + +The following fields are available: + +- **Boo|ApplicationId** No content is currently available. +- **BootApplicataonId** No content is currently available. +- **BootApplicationId** This field tells us what the OS Loader Application Identifier is. +- **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. +- **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootStatusPolicy** Identifies the applicable Boot Status Policy. +- **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). +- **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. +- **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPch** Reason for system reset provided by firmware. +- **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. +- **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). +- **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. +- **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. +- **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. +- **MeasuredLaunchPrepared** This field tells us if the OS launch was initiated using Measured/Secure Boot over DRTM (Dynamic Root of Trust for Measurement). +- **MeasuredLaunchResume** This field tells us if Dynamic Root of Trust for Measurement (DRTM) was used when resuming from hibernation. +- **MenuPolicy** Type of advanced options menu that should be shown to the user (Legacy, Standard, etc.). +- **RecoveryEnabled** Indicates whether recovery is enabled. +- **SecureLaunchPrepared** This field indicates if DRTM was prepared during boot. +- **TcbLaunch** Indicates whether the Trusted Computing Base was used during the boot flow. +- **UserInputTime** The amount of time the loader application spent waiting for user input. + + +## Miracast events + +### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd + +This event sends data at the end of a Miracast session that helps determine RTSP related Miracast failures along with some statistics about the session + +The following fields are available: + +- **AudioChannelCount** The number of audio channels. +- **AudioSampleRate** The sample rate of audio in terms of samples per second. +- **AudioSubtype** The unique subtype identifier of the audio codec (encoding method) used for audio encoding. +- **AverageBitrate** The average video bitrate used during the Miracast session, in bits per second. +- **AverageDataRate** The average available bandwidth reported by the WiFi driver during the Miracast session, in bits per second. +- **AveragePacketSendTimeInMs** The average time required for the network to send a sample, in milliseconds. +- **ConnectorType** The type of connector used during the Miracast session. +- **EncodeAverageTimeMS** The average time to encode a frame of video, in milliseconds. +- **EncodeCount** The count of total frames encoded in the session. +- **EncodeMaxTimeMS** The maximum time to encode a frame, in milliseconds. +- **EncodeMinTimeMS** The minimum time to encode a frame, in milliseconds. +- **EncoderCreationTimeInMs** The time required to create the video encoder, in milliseconds. +- **ErrorSource** Identifies the component that encountered an error that caused a disconnect, if applicable. +- **FirstFrameTime** The time (tick count) when the first frame is sent. +- **FirstLatencyMode** The first latency mode. +- **FrameAverageTimeMS** Average time to process an entire frame, in milliseconds. +- **FrameCount** The total number of frames processed. +- **FrameMaxTimeMS** The maximum time required to process an entire frame, in milliseconds. +- **FrameMinTimeMS** The minimum time required to process an entire frame, in milliseconds. +- **Glitches** The number of frames that failed to be delivered on time. +- **HardwareCursorEnabled** Indicates if hardware cursor was enabled when the connection ended. +- **HDCPState** The state of HDCP (High-bandwidth Digital Content Protection) when the connection ended. +- **HighestBitrate** The highest video bitrate used during the Miracast session, in bits per second. +- **HighestDataRate** The highest available bandwidth reported by the WiFi driver, in bits per second. +- **LastLatencyMode** The last reported latency mode. +- **LogTimeReference** The reference time, in tick counts. +- **LowestBitrate** The lowest video bitrate used during the Miracast session, in bits per second. +- **LowestDataRate** The lowest video bitrate used during the Miracast session, in bits per second. +- **MediaErrorCode** The error code reported by the media session, if applicable. +- **MiracastEntry** The time (tick count) when the Miracast driver was first loaded. +- **MiracastM1** The time (tick count) when the M1 request was sent. +- **MiracastM2** The time (tick count) when the M2 request was sent. +- **MiracastM3** The time (tick count) when the M3 request was sent. +- **MiracastM4** The time (tick count) when the M4 request was sent. +- **MiracastM5** The time (tick count) when the M5 request was sent. +- **MiracastM6** The time (tick count) when the M6 request was sent. +- **MiracastM7** The time (tick count) when the M7 request was sent. +- **MiracastSessionState** The state of the Miracast session when the connection ended. +- **MiracastStreaming** The time (tick count) when the Miracast session first started processing frames. +- **ProfileCount** The count of profiles generated from the receiver M4 response. +- **ProfileCountAfterFiltering** The count of profiles after filtering based on available bandwidth and encoder capabilities. +- **RefreshRate** The refresh rate set on the remote display. +- **RotationSupported** Indicates if the Miracast receiver supports display rotation. +- **RTSPSessionId** The unique identifier of the RTSP session. This matches the RTSP session ID for the receiver for the same session. +- **SessionGuid** The unique identifier of to correlate various Miracast events from a session. +- **SinkHadEdid** Indicates if the Miracast receiver reported an EDID. +- **SupportMicrosoftColorSpaceConversion** Indicates whether the Microsoft color space conversion for extra color fidelity is supported by the receiver. +- **SupportsMicrosoftDiagnostics** Indicates whether the Miracast receiver supports the Microsoft Diagnostics Miracast extension. +- **SupportsMicrosoftFormatChange** Indicates whether the Miracast receiver supports the Microsoft Format Change Miracast extension. +- **SupportsMicrosoftLatencyManagement** Indicates whether the Miracast receiver supports the Microsoft Latency Management Miracast extension. +- **SupportsMicrosoftRTCP** Indicates whether the Miracast receiver supports the Microsoft RTCP Miracast extension. +- **SupportsMicrosoftVideoFormats** Indicates whether the Miracast receiver supports Microsoft video format for 3:2 resolution. +- **SupportsWiDi** Indicates whether Miracast receiver supports Intel WiDi extensions. +- **TeardownErrorCode** The error code reason for teardown provided by the receiver, if applicable. +- **TeardownErrorReason** The text string reason for teardown provided by the receiver, if applicable. +- **UIBCEndState** Indicates whether UIBC was enabled when the connection ended. +- **UIBCEverEnabled** Indicates whether UIBC was ever enabled. +- **UIBCStatus** The result code reported by the UIBC setup process. +- **VideoBitrate** The starting bitrate for the video encoder. +- **VideoCodecLevel** The encoding level used for encoding, specific to the video subtype. +- **VideoHeight** The height of encoded video frames. +- **VideoSubtype** The unique subtype identifier of the video codec (encoding method) used for video encoding. +- **VideoWidth** The width of encoded video frames. +- **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. + + +## OneDrive events + +### Microsoft.OneDrive.Sync.Setup.APIOperation + +This event includes basic data about install and uninstall OneDrive API operations. + +The following fields are available: + +- **APIName** The name of the API. +- **Duration** How long the operation took. +- **IsSuccess** Was the operation successful? +- **ResultCode** The result code. +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.EndExperience + +This event includes a success or failure summary of the installation. + +The following fields are available: + +- **APIName** The name of the API. +- **HResult** HResult of the operation +- **IsSuccess** Whether the operation is successful or not +- **ScenarioName** The name of the scenario. + + +### Microsoft.OneDrive.Sync.Setup.OSUpgradeInstallationOperation + +This event is related to the OS version when the OS is upgraded with OneDrive installed. + +The following fields are available: + +- **CurrentOneDriveVersion** The current version of OneDrive. +- **CurrentOSBuildBranch** The current branch of the operating system. +- **CurrentOSBuildNumber** The current build number of the operating system. +- **CurrentOSVersion** The current version of the operating system. +- **HResult** The HResult of the operation. +- **SourceOSBuildBranch** The source branch of the operating system. +- **SourceOSBuildNumber** The source build number of the operating system. +- **SourceOSVersion** The source version of the operating system. + + +### Microsoft.OneDrive.Sync.Setup.RegisterStandaloneUpdaterAPIOperation + +This event is related to registering or unregistering the OneDrive update task. + +The following fields are available: + +- **APIName** The name of the API. +- **IsSuccess** Was the operation successful? +- **RegisterNewTaskResult** The HResult of the RegisterNewTask operation. +- **ScenarioName** The name of the scenario. +- **UnregisterOldTaskResult** The HResult of the UnregisterOldTask operation. + + +### Microsoft.OneDrive.Sync.Updater.ComponentInstallState + +This event includes basic data about the installation state of dependent OneDrive components. + +The following fields are available: + +- **ComponentName** The name of the dependent component. +- **isInstalled** Is the dependent component installed? + + +### Microsoft.OneDrive.Sync.Updater.OverlayIconStatus + +This event indicates if the OneDrive overlay icon is working correctly. 0 = healthy; 1 = can be fixed; 2 = broken + +The following fields are available: + +- **32bit** The status of the OneDrive overlay icon on a 32-bit operating system. +- **64bit** The status of the OneDrive overlay icon on a 64-bit operating system. + + +### Microsoft.OneDrive.Sync.Updater.UpdateOverallResult + +This event sends information describing the result of the update. + +The following fields are available: + +- **br** No content is currently available. +- **hr** The HResult of the operation. +- **IsLoggingE~abled** No content is currently available. +- **IsLoggingEnabled** Indicates whether logging is enabled for the updater. +- **UpdaterVersion** The version of the updater. + + +### Microsoft.OneDrive.Sync.Updater.UpdateXmlDownloadHResult + +This event determines the status when downloading the OneDrive update configuration file. + +The following fields are available: + +- **hr** The HResult of the operation. + + +### Microsoft.OneDrive.Sync.Updater.WebConnectionStatus + +This event determines the error code that was returned when verifying Internet connectivity. + +The following fields are available: + +- **winInetError** The HResult of the operation. + + +## Privacy consent logging events + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted + +This event is used to determine whether the user successfully completed the privacy consent experience. + +The following fields are available: + +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience + + +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + +## Setup events + +### SetupPlatformTel.SetupPlatformTelActivityEvent + +This event sends basic metadata about the SetupPlatform update installation process, to help keep Windows up to date. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Value associated with the corresponding event name. For example, time-related events will include the system time + + +### SetupPlatformTel.SetupPlatformTelActivityStarted + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + +The following fields are available: + +- **Name** The name of the dynamic update type. Example: GDR driver + + +### SetupPlatformTel.SetupPlatformTelActivityStopped + +This event sends basic metadata about the update installation process generated by SetupPlatform to help keep Windows up to date. + + + +### SetupPlatformTel.SetupPlatformTelEvent + +This service retrieves events generated by SetupPlatform, the engine that drives the various deployment scenarios. + +The following fields are available: + +- **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. + + +## Software update events + +### SoftwareUpdateClientTelemetry.CheckForUpdates + +Scan process event on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. +- **AllowCachedResults** Indicates if the scan allowed using cached results. +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BranchReadinessLevel** The servicing branch configured on the device. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). +- **DeferredUpdates** Update IDs which are currently being deferred until a later time +- **DeviceModel** What is the device model. +- **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. +- **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. +- **DriverGxclusionPolicy** No content is currently available. +- **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExtendedMetadataCabUrl** Hostname that is used to download an update. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. +- **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. +- **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FeatureUpdatePause9-8iod** No content is currently available. +- **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **I#Version** No content is currently available. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6 +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBDualScaninabled** No content is currently available. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. +- **IsWUfBinabled** No content is currently available. +- **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MSIError** The last error that was encountered during a scan for updates. +- **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete +- **NumberOfApplicationsCategoryScanEval}ated** No content is currently available. +- **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked +- **NumberOfLoop** The number of round trips the scan required +- **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan +- **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. +- **Online** Indicates if this was an online scan. +- **PausedUpdates** A list of UpdateIds which that currently being paused. +- **PauseFeatureUpdatesEndTime** If feature OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseFeatureUpdatesStartTime** If feature OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PauseQualityUpdatesEndTime** If quality OS updates are paused on the device, this is the date and time for the end of the pause time window. +- **PauseQualityUpdatesStartTime** If quality OS updates are paused on the device, this is the date and time for the beginning of the pause time window. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting (pre-release builds) being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **QualityUpdatePause9-8iod** No content is currently available. +- **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **S}ncType** No content is currently available. +- **ScanDuratioInSeconds** No content is currently available. +- **ScanDurationInSeconds** The number of seconds a scan took +- **ScanEnqueueTime** The number of seconds it took to initialize a scan +- **ScanPrps** No content is currently available. +- **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). +- **ServiceUrl** The environment URL a device is configured to scan with +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **SyncType** Describes the type of scan the event was +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. +- **TotalNumMetadataSignatureM** No content is currently available. +- **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. +- **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Commit + +This event tracks the commit process post the update installation when software update client is trying to update the device. + +The following fields are available: + +- **BiosFamily** Device family as defined in the system BIOS +- **BiosName** Name of the system BIOS +- **BiosReleaseDate** Release date of the system BIOS +- **BiosSKUNumber** Device SKU as defined in the system BIOS +- **BIOSVendor** Vendor of the system BIOS +- **BiosVersion** Version of the system BIOS +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRevisionNumber** Identifies the revision number of the content bundle +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** Version number of the software distribution client +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** Device model as defined in the system bios +- **EventInstanceID** A globally unique identifier for event instance +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver". +- **FlightId** The specific id of the flight the device is getting +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.) +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **SystemBIOSMajorRelease** Major release version of the system bios +- **SystemBIOSMinorRelease** Minor release version of the system bios +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Download + +Download process event for target update on Windows Update client. See the EventScenario field for specifics (started/failed/succeeded). + +The following fields are available: + +- **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. +- **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. +- **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. +- **AppXDownloadScope** Indicates the scope of the download for application content. +- **AppXScope** Indicates the scope of the app download. +- **aundleBy1esDownl?aded** No content is currently available. +- **B1ndleRepeatFailCount** No content is currently available. +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. +- **BundleId** Identifier associated with the specific content bundle. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to download. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). +- **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. +- **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **Cbs5ethod** No content is currently available. +- **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. +- **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. +- **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. +- **CDNId** ID which defines which CDN the software distribution client downloaded the content from. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. +- **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **DeviceModel** The model of the device. +- **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenarao** No content is currently available. +- **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. +- **EventType** Identifies the type of the event (Child, Bundle, or Driver). +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **flightBuildNumber** No content is currently available. +- **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlightId** The specific ID of the flight (pre-release build) the device is getting. +- **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). +- **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **HostName** The hostname URL the content is downloading from. +- **IPVersion** Indicates whether the download took place over IPv4 or IPv6. +- **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update +- **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWVfBDualScanEnabled** No content is currently available. +- **IsWVfBEnabled** No content is currently available. +- **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. +- **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) +- **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." +- **PackageFullName** The package name of the content. +- **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. +- **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. +- **RegulationReason** The reason that the update is regulated +- **RegulationReóult** No content is currently available. +- **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. +- **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. +- **RelqtedCV** No content is currently available. +- **RepeatFailCount** Indicates whether this specific content has previously failed. +- **RepeatFailFlag** Indicates whether this specific content previously failed to download. +- **RevisionNumber** The revision number of the specified piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. +- **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. +- **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. +- **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. +- **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **TotalEx8ectedBydes** No content is currently available. +- **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. +- **UpdateId** An identifier associated with the specific piece of content. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **UsecDO** No content is currently available. +- **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. +- **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. +- **YsWUfBEnabled** No content is currently available. + + +### SoftwareUpdateClientTelemetry.DownloadCheckpoint + +This event provides a checkpoint between each of the Windows Update download phases for UUP content + +The following fields are available: + +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed +- **EventType** Possible values are "Child", "Bundle", "Relase" or "Driver" +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough +- **FileId** A hash that uniquely identifies a file +- **FileName** Name of the downloaded file +- **FlightId** The unique identifier for each flight +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RevisionNumber** Unique revision number of Update +- **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.) +- **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult) +- **UpdateId** Unique Update ID +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### SoftwareUpdateClientTelemetry.DownloadHeartbeat + +This event allows tracking of ongoing downloads and contains data to explain the current state of the download + +The following fields are available: + +- **BytesTotal** Total bytes to transfer for this content +- **BytesTransferred** Total bytes transferred for this content at the time of heartbeat +- **CallerApplicationName** Name provided by the caller who initiated API calls into the software distribution client +- **ClientVersion** The version number of the software distribution client +- **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat +- **CurrentError** Last (transient) error encountered by the active download +- **DownloadFlags** Flags indicating if power state is ignored +- **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) +- **EventType** Possible values are "Child", "Bundle", or "Driver" +- **FlightId** The unique identifier for each flight +- **IsNetworkMetered** Indicates whether Windows considered the current network to be ?metered" +- **MOAppDownloadLimit** Mobile operator cap on size of application downloads, if any +- **MOUpdateDownloadLimit** Mobile operator cap on size of operating system update downloads, if any +- **PowerState** Indicates the power state of the device at the time of heartbeart (DC, AC, Battery Saver, or Connected Standby) +- **RelatedCV** The previous correlation vector that was used by the client, before swapping with a new one +- **ResumeCount** Number of times this active download has resumed from a suspended state +- **RevisionNumber** Identifies the revision number of this specific piece of content +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc) +- **SuspendCount** Number of times this active download has entered a suspended state +- **SuspendReason** Last reason for why this active download entered a suspended state +- **UpdateId** Identifier associated with the specific piece of content +- **WUDeviceID** Unique device id controlled by the software distribution client + + +### SoftwareUpdateClientTelemetry.Install + +This event sends tracking data about the software distribution client installation of the content for that update, to help keep Windows up to date. + +The following fields are available: + +- **BiosFamily** The family of the BIOS (Basic Input Output System). +- **BiosName** The name of the device BIOS. +- **BiosReleaseDate** The release date of the device BIOS. +- **BiosSKUNumber** The sku number of the device BIOS. +- **BIOSVendor** The vendor of the BIOS. +- **BiosVersion** The version of the BIOS. +- **BundleId** Identifier associated with the specific content bundle; should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRepeatFailFlag** Indicates whether this particular update bundle previously failed to install. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **ClientVersion** The version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No value is currently reported in this field. Expected value for this field is 0. +- **CSIErrorType** The stage of CBS installation where it failed. +- **CurrentMobileOperator** The mobile operator to which the device is currently connected. +- **DeploymentProviderMode** The mode of operation of the update deployment provider. +- **DeviceModel** The device model. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **EventType** Possible values are Child, Bundle, or Driver. +- **ExtendedErrorCode** The extended error code. +- **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. +- **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **FlightRing** The ring that a device is on if participating in the Windows Insider Program. +- **HandlerType** Indicates what kind of content is being installed (for example, app, driver, Windows update). +- **HardwareId** If this install was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **HomeMobileOperator** The mobile operator that the device was originally intended to work with. +- **InstallProps** A bitmask for future flags associated with the install operation. No value is currently reported in this field. Expected value for this field is 0. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IsDependentSet** Indicates whether the driver is part of a larger System Hardware/Firmware update. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether this update is a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. +- **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. +- **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. +- **MsiAction** The stage of MSI installation where it failed. +- **MsiProductCode** The unique identifier of the MSI installer. +- **PackageFullName** The package name of the content being installed. +- **PhonePreviewEnabled** Indicates whether a phone was getting preview build, prior to flighting being introduced. +- **ProcessName** The process name of the caller who initiated API calls, in the event that CallerApplicationName was not provided. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RepeatFailFlag** Indicates whether this specific piece of content previously failed to install. +- **RevisionNumber** The revision number of this specific piece of content. +- **ServiceGuid** An ID which represents which service the software distribution client is installing content for (Windows Update, Microsoft Store, etc.). +- **Setup360Phase** If the install is for an operating system upgrade, indicates which phase of the upgrade is underway. +- **ShippingMobileOperator** The mobile operator that a device shipped on. +- **StatusCode** Indicates the result of an installation event (success, cancellation, failure code HResult). +- **SystemBIOSMajorRelease** Major version of the BIOS. +- **SystemBIOSMinorRelease** Minor version of the BIOS. +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **Targeti~gVersion** No content is currently available. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **TransactionCode** The ID that represents a given MSI installation. +- **UpdateId** Unique update ID. +- **UpdateID** An identifier associated with the specific piece of content. +- **UpdateImportance** Indicates whether a piece of content was marked as Important, Recommended, or Optional. +- **UsedSystemVolume** Indicates whether the content was downloaded and then installed from the device's main system storage drive, or an alternate storage drive. +- **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### SoftwareUpdateClientTelemetry.Revert + +Revert event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** Identifier associated with the specific content bundle. Should not be all zeros if the BundleId was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **CSIErrorType** Stage of CBS installation that failed. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **EventType** Event type (Child, Bundle, Release, or Driver). +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If this download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content has previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** The identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver, and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device's main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.TaskRun + +Start event for Server Initiated Healing client. See EventScenario field for specifics (for example, started/completed). + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CmdLineArgs** Command line arguments passed in by the caller. +- **EventInstanceID** A globally unique identifier for the event instance. +- **EventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **ServiceGuid** Identifier for the service to which the software distribution client is connecting (Windows Update, Microsoft Store, etc.). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.Uninstall + +Uninstall event for target update on Windows Update Client. See EventScenario field for specifics (for example, Started/Failed/Succeeded). + +The following fields are available: + +- **BundleId** The identifier associated with the specific content bundle. This should not be all zeros if the bundleID was found. +- **BundleRepeatFailCount** Indicates whether this particular update bundle previously failed. +- **BundleRevisionNumber** Identifies the revision number of the content bundle. +- **CallerApplicationName** Name of the application making the Windows Update request. Used to identify context of request. +- **ClientVersion** Version number of the software distribution client. +- **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. There is no value being reported in this field right now. Expected value for this field is 0. +- **DriverPingBack** Contains information about the previous driver and system state. +- **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers when a recovery is required. +- **EventInstanceID** A globally unique identifier for event instance. +- **EventScenario** Indicates the purpose of the event (a scan started, succeded, failed, etc.). +- **EventType** Indicates the event type. Possible values are "Child", "Bundle", "Release" or "Driver". +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode is not specific enough. +- **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. +- **FlightBuildNumber** Indicates the build number of the flight. +- **FlightId** The specific ID of the flight the device is getting. +- **HandlerType** Indicates the kind of content (app, driver, windows patch, etc.). +- **HardwareId** If the download was for a driver targeted to a particular device model, this ID indicates the model of the device. +- **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. +- **IsFirmware** Indicates whether an update was a firmware update. +- **IsSuccessFailurePostReboot** Indicates whether an initial success was then a failure after a reboot. +- **IsWUfBDualScanEnabled** Flag indicating whether WU-for-Business dual scan is enabled on the device. +- **IsWUfBEnabled** Flag indicating whether WU-for-Business is enabled on the device. +- **MergedUpdate** Indicates whether an OS update and a BSP update were merged for install. +- **ProcessName** Process name of the caller who initiated API calls into the software distribution client. +- **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. +- **RelatedCV** The previous correlation vector that was used by the client before swapping with a new one. +- **RepeatFailCount** Indicates whether this specific piece of content previously failed. +- **RevisionNumber** Identifies the revision number of this specific piece of content. +- **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. +- **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. +- **UpdateId** Identifier associated with the specific piece of content. +- **UpdateImportance** Indicates the importance of a driver and why it received that importance level (0-Unknown, 1-Optional, 2-Important-DNF, 3-Important-Generic, 4-Important-Other, 5-Recommended). +- **UsedSystemVolume** Indicates whether the device’s main system storage drive or an alternate storage drive was used. +- **WUDeviceID** Unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateDetected + +This event sends data about an AppX app that has been updated from the Microsoft Store, including what app needs an update and what version/architecture is required, in order to understand and address problems with apps getting required updates. + +The following fields are available: + +- **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. +- **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. +- **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **NumberOfA0plicableUpdates** No content is currently available. +- **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. +- **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. +- **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). +- **WUDeviceID** The unique device ID controlled by the software distribution client. + + +### SoftwareUpdateClientTelemetry.UpdateMetadataIntegrity + +Ensures Windows Updates are secure and complete. Event helps to identify whether update content has been tampered with and protects against man-in-the-middle attack. + +The following fields are available: + +- **CallerApplicationName** Name of application making the Windows Update request. Used to identify context of request. +- **EndpointUrl** URL of the endpoint where client obtains update metadata. Used to identify test vs staging vs production environments. +- **EventScenario** Indicates the purpose of the event - whether because scan started, succeded, failed, etc. +- **ExtendedStatusCode** Secondary status code for certain scenarios where StatusCode was not specific enough. +- **LeafCertId** The integral ID from the FragmentSigning data for the certificate that failed. +- **ListOfSHA256OfIntermediateCerData** A semicolon delimited list of base64 encoding of hashes for the Base64CerData in the FragmentSigning data of an intermediate certificate. +- **MetadataIntegrityMode** Mode of update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce +- **MetadataSignature** A base64-encoded string of the signature associated with the update metadata (specified by revision ID). +- **RawMode** The raw unparsed mode string from the SLS response. This field is null if not applicable. +- **RawValidityWindowInDays** The raw unparsed validity window string in days of the timestamp token. This field is null if not applicable. +- **RevisionId** The revision ID for a specific piece of content. +- **RevisionNumber** The revision number for a specific piece of content. +- **ServiceGuid** Identifies the service to which the software distribution client is connected, Example: Windows Update or Microsoft Store +- **SHA256OfLeafCerData** A base64 encoding of the hash for the Base64CerData in the FragmentSigning data of the leaf certificate. +- **SHA256OfLeafCertPublicKey** A base64 encoding of the hash of the Base64CertData in the FragmentSigning data of the leaf certificate. +- **SHA256OfTimestampToken** An encoded string of the timestamp token. +- **SignatureAlgorithm** The hash algorithm for the metadata signature. +- **SLSPrograms** A test program a machine may be opted in. Examples include "Canary" and "Insider Fast". +- **StatusCode** Result code of the event (success, cancellation, failure code HResult) +- **TimestampTokenCertThumbprint** The thumbprint of the encoded timestamp token. +- **TimestampTokenId** The time this was created. It is encoded in a timestamp blob and will be zero if the token is malformed. +- **UpdateId** The update ID for a specific piece of content. +- **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. + + +## System Resource Usage Monitor events + +### Microsoft.Windows.Srum.Sdp.CpuUsage + +This event provides information on CPU usage. + +The following fields are available: + +- **UsageMax** The maximum of hourly average CPU usage. +- **UsageMean** The mean of hourly average CPU usage. +- **UsageMedian** The median of hourly average CPU usage. +- **UsageTwoHourMaxMean** The mean of the maximum of every two hour of hourly average CPU usage. +- **UsageTwoHourMedianMean** The mean of the median of every two hour of hourly average CPU usage. + + +### Microsoft.Windows.Srum.Sdp.NetworkUsage + +This event provides information on network usage. + +The following fields are available: + +- **AdapterGuid** The unique ID of the adapter. +- **BytesTotalMax** The maximum of the hourly average bytes total. +- **BytesTotalMean** The mean of the hourly average bytes total. +- **BytesTotalMedian** The median of the hourly average bytes total. +- **BytesTotalTwoHourMaxMean** The mean of the maximum of every two hours of hourly average bytes total. +- **BytesTotalTwoHourMedianMean** The mean of the median of every two hour of hourly average bytes total. +- **LinkSpeed** The adapter link speed. + + +## Update events + +### Update360Telemetry.Revert + +This event sends data relating to the Revert phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the Revert phase. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RebootRequired** Indicates reboot is required. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **RevertResult** The result code returned for the Revert operation. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentCommit + +This event collects information regarding the commit phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentDownloadRequest + +This event sends data for the download request phase of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to PC and Mobile. + +The following fields are available: + +- **DeletedCorruptFiles** Boolean indicating whether corrupt payload was deleted. +- **DownloadRequests** Number of times a download was retried. +- **ErrorCode** The error code returned for the current download request phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique ID for each flight. +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. +- **PackageCCoegoriesSkipped** No content is currently available. +- **PackageCountOptional** Number of optional packages requested. +- **PackageCountRequired** Number of required packages requested. +- **PackageCountTotal** Total number of packages needed. +- **PackageCountTotalCanonical** Total number of canonical packages. +- **PackageCountTotalDiff** Total number of diff packages. +- **PackageCountTotalExpress** Total number of express packages. +- **PackageCountTotalPSFX** The total number of PSFX packages. +- **PackageExpressType** Type of express package. +- **PackageSizeCanonical** Size of canonical packages in bytes. +- **PackageSizeDiff** Size of diff packages in bytes. +- **PackageSizeExpress** Size of express packages in bytes. +- **PackageSizePSFX** The size of PSFX packages, in bytes. +- **RangeRequestSsCoe** No content is currently available. +- **RangeRequestState** Indicates the range request type used. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the download request phase of update. +- **SandboxTaggedForReserves** The sandbox for reserves. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt (same value for initialize, download, install commit phases). +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentExpand + +This event collects information regarding the expansion phase of the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ElapsedTickCount** Time taken for expand phase. +- **EndFreeSpace** Free space after expand phase. +- **EndSandboxSize** Sandbox size after expand phase. +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **StartFreeSpace** Free space before expand phase. +- **StartSandboxSize** Sandbox size after expand phase. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentFellBackToCanonical + +This event collects information when express could not be used and we fall back to canonical during the new Unified Update Platform (UUP) update scenario, which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **ObjectId** Unique value for each Update Agent mode. +- **PackageCount** Number of packages that feel back to canonical. +- **PackageList** PackageIds which fell back to canonical. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInitialize + +This event sends data for the initialize phase of updating Windows via the new Unified Update Platform (UUP) scenario, which is applicable to both PCs and Mobile. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **FlightId** Unique ID for each flight. +- **FlightMetadata** Contains the FlightId and the build being flighted. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** Outcome of the install phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionData** String containing instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentInstall + +This event sends data for the install phase of updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current install phase. +- **ExtensionName** Indicates whether the payload is related to Operating System content or a plugin. +- **FlightId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). +- **InternalFailureResult** Indicates a non-fatal error from a plugin. +- **ObjectId** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** The result for the current install phase. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMerge + +The UpdateAgentMerge event sends data on the merge phase when updating Windows. + +The following fields are available: + +- **ErrorCode** The error code returned for the current merge phase. +- **FlightId** Unique ID for each flight. +- **MergeId** The unique ID to join two update sessions being merged. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Related correlation vector value. +- **Result** Outcome of the merge phase of the update. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentMitigationResult + +This event sends data indicating the result of each update agent mitigation. + +The following fields are available: + +- **Applicable** Indicates whether the mitigation is applicable for the current update. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightId** Unique identifier for each flight. +- **Index** The mitigation index of this particular mitigation. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly name of the mitigation. +- **ObjectId** Unique value for each Update Agent mode. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **UpdateId** Unique ID for each Update. + + +### Update360Telemetry.UpdateAgentMitigationSummary + +This event sends a summary of all the update agent mitigations available for an this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **Failed** The count of mitigations that failed. +- **FlightId** Unique identifier for each flight. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** The HResult of this operation. +- **ScenarioId** The update agent scenario ID. +- **SessionId** Unique value for each update attempt. +- **TimeDiff** The amount of time spent performing all mitigations (in 100-nanosecond increments). +- **Total** Total number of mitigations that were available. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating Windows via the new Unified Update Platform (UUP) scenario. Applicable to both PCs and Mobile. + +The following fields are available: + +- **FlightId** Unique ID for each flight. +- **Mode** Indicates the mode that has started. +- **ObjectId** Unique value for each Update Agent mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **Version** Version of update + + +### Update360Telemetry.UpdateAgentOneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **Count** The count of applicable OneSettings for the device. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. +- **Values** The values sent back to the device, if applicable. + + +### Update360Telemetry.UpdateAgentPostRebootResult + +This event collects information for both Mobile and Desktop regarding the post reboot phase of the new Unified Update Platform (UUP) update scenario. + +The following fields are available: + +- **ErrorCode** The error code returned for the current post reboot phase. +- **FlightId** The specific ID of the Windows Insider build the device is getting. +- **ObjectId** Unique value for each Update Agent mode. +- **PostRebootResult** Indicates the Hresult. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **ScenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. + + +### Update360Telemetry.UpdateAgentReboot + +This event sends information indicating that a request has been sent to suspend an update. + +The following fields are available: + +- **ErrorCode** The error code returned for the current reboot. +- **FlightId** Unique ID for the flight (test instance version). +- **ObjectId** The unique value for each Update Agent mode. +- **RelatedCV** The correlation vector value generated from the latest USO (Update Service Orchestrator) scan. +- **Result** The HResult of the event. +- **ScenarioId** The ID of the update scenario. +- **SessionId** The ID of the update attempt. +- **UpdateId** The ID of the update. + + +### Update360Telemetry.UpdateAgentSetupBoxLaunch + +The UpdateAgent_SetupBoxLaunch event sends data for the launching of the setup box when updating Windows via the new Unified Update Platform (UUP) scenario. This event is only applicable to PCs. + +The following fields are available: + +- **ContainsExpressPackage** Indicates whether the download package is express. +- **FlightId** Unique ID for each flight. +- **FreeSpace** Free space on OS partition. +- **InstallCount** Number of install attempts using the same sandbox. +- **ObjectId** Unique value for each Update Agent mode. +- **Quiet** Indicates whether setup is running in quiet mode. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **SandboxSize** Size of the sandbox. +- **ScenarioId** Indicates the update scenario. +- **SessionId** Unique value for each update attempt. +- **SetupMode** Mode of setup to be launched. +- **UpdateId** Unique ID for each Update. +- **UserSession** Indicates whether install was invoked by user actions. + + +## Update notification events + +### Microsoft.Windows.UpdateNotificationPipeline.UNPCampaignManagerHeartbeat + +This event is sent at the start of the CampaignManager event and is intended to be used as a heartbeat. + +The following fields are available: + +- **CampaignConfigVersion** Configuration version for the current campaign. +- **CampaignID** Currently campaign that is running on Update Notification Pipeline (UNP). +- **ConfigCatalogVersion** Current catalog version of UNP. +- **ContentVersion** Content version for the current campaign on UNP. +- **CV** Correlation vector. +- **DetectorVersion** Most recently run detector version for the current campaign on UNP. +- **GlobalEventCounter** Client-side counter that indicates the event ordering sent by the user. +- **PackageVersion** Current UNP package version. + + +## Upgrade events + +### FacilitatorTelemetry.DCATDownload + +This event indicates whether devices received additional or critical supplemental content during an OS Upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **DownloadSize** Download size of payload. +- **ElapsedTime** Time taken to download payload. +- **MediaFallbackUsed** Used to determine if we used Media CompDBs to figure out package requirements for the upgrade. +- **ResultCode** Result returned by the Facilitator DCAT call. +- **Scenario** Dynamic update scenario (Image DU, or Setup DU). +- **Type** Type of package that was downloaded. +- **UpdateId** The ID of the update that was downloaded. + + +### FacilitatorTelemetry.DUDownload + +This event returns data about the download of supplemental packages critical to upgrading a device to the next version of Windows. + +The following fields are available: + +- **DownloadRequestAttributes** The attributes sent for download. +- **PackageCategoriesFailed** Lists the categories of packages that failed to download. +- **PackageCategoriesSkipped** Lists the categories of package downloads that were skipped. +- **ResultCode** The result of the event execution. +- **Scenario** Identifies the active Download scenario. +- **Url** The URL the download request was sent to. +- **Version** Identifies the version of Facilitator used. + + +### FacilitatorTelemetry.InitializeDU + +This event determines whether devices received additional or critical supplemental content during an OS upgrade. + +The following fields are available: + +- **DCATUrl** The Delivery Catalog (DCAT) URL we send the request to. +- **DownloadRequestAttributes** The attributes we send to DCAT. +- **ResultCode** The result returned from the initiation of Facilitator with the URL/attributes. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **Url** The Delivery Catalog (DCAT) URL we send the request to. +- **Version** Version of Facilitator. + + +### Setup360Telemetry.Downlevel + +This event sends data indicating that the device has started the downlevel phase of the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** If using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but it can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the downlevel OS. +- **HostOsSkuName** The operating system edition which is running Setup360 instance (downlevel OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** In the Windows Update scenario, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360 (for example, Predownload, Install, Finalize, Rollback). +- **Setup360Result** The result of Setup360 (HRESULT used to diagnose errors). +- **Setup360Scenario** The Setup360 flow type (for example, Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** Exit state of given Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** An ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. In the Windows Update scenario, this is the same as the clientId. + + +### Setup360Telemetry.Finalize + +This event sends data indicating that the device has started the phase of finalizing the upgrade, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** More detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.OsUninstall + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10. Specifically, it indicates the outcome of an OS uninstall. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase or action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** Exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PostRebootInstall + +This event sends data indicating that the device has invoked the post reboot install phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this is the Windows Update client ID that is passed to Setup. In Media setup, the default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Extension of result - more granular information about phase/action when the potential failure happened +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback +- **Setup360Result** The result of Setup360. This is an HRESULT error code that's used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as ClientId. + + +### Setup360Telemetry.PreDownloadQuiet + +This event sends data indicating that the device has invoked the predownload quiet phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** Using Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous operating system). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** Using Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, canceled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** This is the Windows Update Client ID. Using Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreDownloadUX + +This event sends data regarding OS Updates and Upgrades from Windows 7.X, Windows 8.X, Windows 10 and RS, to help keep Windows up-to-date and secure. Specifically, it indicates the outcome of the PredownloadUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **HostOSBuildNumber** The build number of the previous operating system. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous operating system). +- **InstanceId** Unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of the target OS). +- **State** The exit state of the Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** ID that uniquely identifies a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.PreInstallQuiet + +This event sends data indicating that the device has invoked the preinstall quiet phase of the upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used to diagnose errors. +- **Setup360Scenario** Setup360 flow type (Boot, Media, Update, MCT). +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +### Setup360Telemetry.PreInstallUX + +This event sends data regarding OS updates and upgrades from Windows 7, Windows 8, and Windows 10, to help keep Windows up-to-date. Specifically, it indicates the outcome of the PreinstallUX portion of the update process. + +The following fields are available: + +- **ClientId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running the Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe. +- **ReportId** For Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that is used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type, Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** Windows Update client ID. + + +### Setup360Telemetry.Setup360 + +This event sends data about OS deployment scenarios, to help keep Windows up-to-date. + +The following fields are available: + +- **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FieldName** Retrieves the data point. +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **ReportId** Retrieves the report ID. +- **ScenarioId** Retrieves the deployment scenario. +- **Value** Retrieves the value associated with the corresponding FieldName. + + +### Setup360Telemetry.Setup360DynamicUpdate + +This event helps determine whether the device received supplemental content during an operating system upgrade, to help keep Windows up-to-date. + +The following fields are available: + +- **FlightData** Specifies a unique identifier for each group of Windows Insider builds. +- **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **Operation** Facilitator’s last known operation (scan, download, etc.). +- **ReportId** ID for tying together events stream side. +- **ResultCode** Result returned for the entire setup operation. +- **Scenario** Dynamic Update scenario (Image DU, or Setup DU). +- **ScenarioId** Identifies the update scenario. +- **TargetBranch** Branch of the target OS. +- **TargetBuild** Build of the target OS. + + +### Setup360Telemetry.Setup360MitigationResult + +This event sends data indicating the result of each setup mitigation. + +The following fields are available: + +- **Applicable** TRUE if the mitigation is applicable for the current update. +- **ClientId** In the Windows Update scenario, this is the client ID passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **CommandCount** The number of command operations in the mitigation entry. +- **CustomCount** The number of custom operations in the mitigation entry. +- **FileCount** The number of file operations in the mitigation entry. +- **FlightData** The unique identifier for each flight (test release). +- **Index** The mitigation index of this particular mitigation. +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **Name** The friendly (descriptive) name of the mitigation. +- **OperationIndex** The mitigation operation index (in the event of a failure). +- **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). +- **RegistryCount** The number of registry operations in the mitigation entry. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). + + +### Setup360Telemetry.Setup360MitigationSummary + +This event sends a summary of all the setup mitigations available for this update. + +The following fields are available: + +- **Applicable** The count of mitigations that were applicable to the system and scenario. +- **ClientId** The Windows Update client ID passed to Setup. +- **Failed** The count of mitigations that failed. +- **FlightData** The unique identifier for each flight (test release). +- **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. +- **MitigationScenario** The update scenario in which the mitigations were attempted. +- **ReportId** In the Windows Update scenario, the Update ID that is passed to Setup. In media setup, this is the GUID for the INSTALL.WIM. +- **Result** HResult of this operation. +- **ScenarioId** Setup360 flow type. +- **TimeDiff** The amount of time spent performing the mitigation (in 100-nanosecond increments). +- **Total** The total number of mitigations that were available. + + +### Setup360Telemetry.Setup360OneSettings + +This event collects information regarding the post reboot phase of the new UUP (Unified Update Platform) update scenario; which is leveraged by both Mobile and Desktop. + +The following fields are available: + +- **ClientId** The Windows Update client ID passed to Setup. +- **Count** The count of applicable OneSettings for the device. +- **FlightData** The ID for the flight (test instance version). +- **InstanceId** The GUID (Globally-Unique ID) that identifies each instance of setuphost.exe. +- **Parameters** The set of name value pair parameters sent to OneSettings to determine if there are any applicable OneSettings. +- **ReportId** The Update ID passed to Setup. +- **Result** The HResult of the event error. +- **ScenarioId** The update scenario ID. +- **Values** Values sent back to the device, if applicable. + + +### Setup360Telemetry.UnexpectedEvent + +This event sends data indicating that the device has invoked the unexpected event phase of the upgrade, to help keep Windows up to date. + +The following fields are available: + +- **ClientId** With Windows Update, this will be the Windows Update client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FlightData** Unique value that identifies the flight. +- **HostOSBuildNumber** The build number of the previous OS. +- **HostOsSkuName** The OS edition which is running Setup360 instance (previous OS). +- **InstanceId** A unique GUID that identifies each instance of setuphost.exe +- **ReportId** With Windows Update, this is the updateID that is passed to Setup. In media setup, this is the GUID for the install.wim. +- **Setup360Extended** Detailed information about the phase/action when the potential failure occurred. +- **Setup360Mode** The phase of Setup360. Example: Predownload, Install, Finalize, Rollback. +- **Setup360Result** The result of Setup360. This is an HRESULT error code that can be used used to diagnose errors. +- **Setup360Scenario** The Setup360 flow type. Example: Boot, Media, Update, MCT. +- **SetupVersionBuildNumber** The build number of Setup360 (build number of target OS). +- **State** The exit state of a Setup360 run. Example: succeeded, failed, blocked, cancelled. +- **TestId** A string to uniquely identify a group of events. +- **WuId** This is the Windows Update Client ID. With Windows Update, this is the same as the clientId. + + +## Windows as a Service diagnostic events + +### Microsoft.Windows.WaaSMedic.SummaryEvent + +Result of the WaaSMedic operation. + +The following fields are available: + +- **callerApplication** The name of the calling application. +- **capsuleCount** The number of Sediment Pack capsules. +- **capsuleFailureCount** The number of capsule failures. +- **detectionSummary** Result of each applicable detection that was run. +- **featureAssessmentImpact** WaaS Assessment impact for feature updates. +- **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. +- **hrEngineResult** Error code from the engine operation. +- **hrLastSandboxError** The last error sent by the WaaSMedic sandbox. +- **initSummary** Summary data of the initialization method. +- **insufficientSessions** Device not eligible for diagnostics. +- **isInteractiveMode** The user started a run of WaaSMedic. +- **isManaged** Device is managed for updates. +- **isWUConnected** Device is connected to Windows Update. +- **noMoreActions** No more applicable diagnostics. +- **pluginFailureCount** The number of plugins that have failed. +- **pluginsCount** The number of plugins. +- **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. +- **usingBackupFeatureAssessment** Relying on backup feature assessment. +- **usingBackupQualityAssessment** Relying on backup quality assessment. +- **usingCachedFeatureAssessment** WaaS Medic run did not get OS build age from the network on the previous run. +- **usingCachedQualityAssessment** WaaS Medic run did not get OS revision age from the network on the previous run. +- **versionString** Version of the WaaSMedic engine. +- **waasMedicRunMode** Indicates whether this was a background regular run of the medic or whether it was triggered by a user launching Windows Update Troubleshooter. + + +## Windows Error Reporting events + +### Microsoft.Windows.WERVertical.OSCrash + +This event sends binary data from the collected dump file wheneveer a bug check occurs, to help keep Windows up to date. The is the OneCore version of this event. + +The following fields are available: + +- **BootId** Uint32 identifying the boot number for this device. +- **BugCheckCode** Uint64 "bugcheck code" that identifies a proximate cause of the bug check. +- **BugCheckParameter1** Uint64 parameter providing additional information. +- **BugCheckParameter2** Uint64 parameter providing additional information. +- **BugCheckParameter3** Uint64 parameter providing additional information. +- **BugCheckParameter4** Uint64 parameter providing additional information. +- **DumpFileAttributes** Codes that identify the type of data contained in the dump file +- **DumpFileSize** Size of the dump file +- **IsValidDumpFile** True if the dump file is valid for the debugger, false otherwise +- **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). + + +## Windows Error Reporting MTT events + +### Microsoft.Windows.WER.MTT.Denominator + +This event provides a denominator to calculate MTTF (mean-time-to-failure) for crashes and other errors, to help keep Windows up to date. + +The following fields are available: + +- **DPRange** Maximum mean value range. +- **DPValue** Randomized bit value (0 or 1) that can be reconstituted over a large population to estimate the mean. +- **Value** Standard UTC emitted DP value structure See [Value](#value). + + +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + +## Windows Store events + +### Microsoft.Windows.Store.StoreActivating + +This event sends tracking data about when the Store app activation via protocol URI is in progress, to help keep Windows up to date. + + + +### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation + +This event is sent when an installation or update is canceled by a user or the system and is used to help keep Windows Apps up to date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The Item Bundle ID. +- **CategoryId** The Item Category ID. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Was this a mandatory update? +- **IsRemediation** Was this a remediation install? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Flag indicating if this is an update. +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The product family name of the product being installed. +- **ProductId** The identity of the package or packages being installed. +- **SystemAttemptNumber** The total number of automatic attempts at installation before it was canceled. +- **UserAttemptNumber** The total number of user attempts at installation before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginGetInstalledContentIds + +This event is sent when an inventory of the apps installed is started to determine whether updates for those apps are available. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.BeginUpdateMetadataPrepare + +This event is sent when the Store Agent cache is refreshed with any available package updates. It's used to help keep Windows up-to-date and secure. + + + +### Microsoft.Windows.StoreAgent.Telemetry.CancelInstallation + +This event is sent when an app update or installation is canceled while in interactive mode. This can be canceled by the user or the system. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all package or packages to be downloaded and installed. +- **AttemptNumber** Total number of installation attempts. +- **BundleId** The identity of the Windows Insider build that is associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Was this requested by a user? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this an automatic restore of a previously acquired product? +- **IsUpdate** Is this a product update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of all packages to be downloaded and installed. +- **PreviousHResult** The previous HResult code. +- **PreviousInstallState** Previous installation state before it was canceled. +- **ProductId** The name of the package or packages requested for installation. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** Total number of automatic attempts to install before it was canceled. +- **UserAttemptNumber** Total number of user attempts to install before it was canceled. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.CompleteInstallOperationRequest + +This event is sent at the end of app installations or updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Product ID of the app being installed. +- **HResult** HResult code of the action being performed. +- **IsBundle** Is this a bundle? +- **PackageFamilyName** The name of the package being installed. +- **ProductId** The Store Product ID of the product being installed. +- **SkuId** Specific edition of the item being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndAcquireLicense + +This event is sent after the license is acquired when a product is being installed. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. +- **AttemptNumber** The total number of attempts to acquire this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** HResult code to show the result of the operation (success/failure). +- **IsBundle** Is this a bundle? +- **IsInteractive** Did the user initiate the installation? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this happening after a device restore? +- **IsUpdate** Is this an update? +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to acquire this product. +- **UserAttemptNumber** The number of attempts by the user to acquire this product +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndDownload + +This event is sent after an app is downloaded to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** Number of retry attempts before it was canceled. +- **BundleId** The identity of the Windows Insider build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **DownloadSize** The total size of the download. +- **ExtendedHResult** Any extended HResult error codes. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this initiated by the user? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this a restore of a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The parent bundle ID (if it's part of a bundle). +- **PFN** The Product Family Name of the app being download. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The number of attempts by the system to download. +- **UserAttemptNumber** The number of attempts by the user to download. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndFrameworkUpdate + +This event is sent when an app update requires an updated Framework package and the process starts to download it. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndGetInstalledContentIds + +This event is sent after sending the inventory of the products installed to determine whether updates for those products are available. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed before this operation. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndInstall + +This event is sent after a product has been installed to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **ExtendedHResult** The extended HResult error code. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this an interactive installation? +- **IsMandatory** Is this a mandatory installation? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this automatically restoring a previously acquired product? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** Product Family Name of the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndScanForUpdates + +This event is sent after a scan for product updates to determine if there are packages to install. It's used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AsOnline** No content is currently available. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsApplicability** Is this request to only check if there are any applicable packages to install? +- **IsInteractive** Is this user requested? +- **IsOnline** Is the request doing an online check? + + +### Microsoft.Windows.StoreAgent.Telemetry.EndSearchUpdatePackages + +This event is sent after searching for update packages to install. It is used to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndStageUserData + +This event is sent after restoring user data (if any) that needs to be restored following a product install. It is used to keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The name of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **ProductId** The Store Product ID for the product being installed. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of system attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.EndUpdateMetadataPrepare + +This event is sent after a scan for available app updates to help keep Windows up-to-date and secure. + +The following fields are available: + +- **HResult** The result code of the last action performed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentComplete + +This event is sent at the end of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FailedRetry** Indicates whether the installation or update retry was successful. +- **HResult** The HResult code of the operation. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.FulfillmentInitiate + +This event is sent at the beginning of an app install or update to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The name of the product catalog from which this app was chosen. +- **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. +- **PFN** The Package Family Name of the app that is being installed or updated. +- **PluginTelemetryData** Diagnostic information specific to the package-type plug-in. +- **ProductId** The product ID of the app that is being updated or installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.InstallOperationRequest + +This event is sent when a product install or update is initiated, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **BundleId** The identity of the build associated with this product. +- **CatalogId** If this product is from a private catalog, the Store Product ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specific edition ID being installed. +- **VolumePath** The disk path of the installation. + + +### Microsoft.Windows.StoreAgent.Telemetry.PauseInstallation + +This event is sent when a product install or update is paused (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The total number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The Product Full Name. +- **PreviousHResult** The result code of the last action performed before this operation. +- **PreviousInstallState** Previous state before the installation or update was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector of a previous performed action on this product. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeInstallation + +This event is sent when a product install or update is resumed (either by a user or the system), to help keep Windows up-to-date and secure. + +The following fields are available: + +- **AggregatedPackageFullNames** The names of all packages to be downloaded and installed. +- **AttemptNumber** The number of retry attempts before it was canceled. +- **BundleId** The identity of the build associated with this product. +- **CategoryId** The identity of the package or packages being installed. +- **ClientAppId** The identity of the app that initiated this operation. +- **HResult** The result code of the last action performed before this operation. +- **IsBundle** Is this a bundle? +- **IsInteractive** Is this user requested? +- **IsMandatory** Is this a mandatory update? +- **IsRemediation** Is this repairing a previous installation? +- **IsRestore** Is this restoring previously acquired content? +- **IsUpdate** Is this an update? +- **IsUserRetry** Did the user initiate the retry? +- **ParentBundleId** The product ID of the parent (if this product is part of a bundle). +- **PFN** The name of the package or packages requested for install. +- **PreviousHResult** The previous HResult error code. +- **PreviousInstallState** Previous state before the installation was paused. +- **ProductId** The Store Product ID for the product being installed. +- **RelatedCV** Correlation Vector for the original install before it was resumed. +- **ResumeClientId** The ID of the app that initiated the resume operation. +- **SystemAttemptNumber** The total number of system attempts. +- **UserAttemptNumber** The total number of user attempts. +- **WUContentId** The Windows Update content ID. + + +### Microsoft.Windows.StoreAgent.Telemetry.ResumeOperationRequest + +This event is sent when a product install or update is resumed by a user or on installation retries, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **ProductId** The Store Product ID for the product being installed. + + +### Microsoft.Windows.StoreAgent.Telemetry.SearchForUpdateOperationRequest + +This event is sent when searching for update packages to install, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **CatalogId** The Store Catalog ID for the product being installed. +- **ProductId** The Store Product ID for the product being installed. +- **SkuId** Specfic edition of the app being updated. + + +### Microsoft.Windows.StoreAgent.Telemetry.UpdateAppOperationRequest + +This event occurs when an update is requested for an app, to help keep Windows up-to-date and secure. + +The following fields are available: + +- **PFamN** The name of the app that is requested for update. + + +## Windows System Kit events + +### Microsoft.Windows.Kits.WSK.WskImageCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate “image” creation failures. + +The following fields are available: + +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskImageCustomization + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create/modify configuration files allowing the customization of a new OS image with Apps or Drivers. The data includes the version of the Windows System Kit, the state of the event, the customization type (drivers or apps) and the mode (new or updating) and is used to help investigate configuration file creation failures. + +The following fields are available: + +- **CustomizationMode** Indicates the mode of the customization (new or updating). +- **CustomizationType** Indicates the type of customization (drivers or apps). +- **Mode** The mode of update to image configuration files. Values are “New” or “Update”. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **Type** The type of update to image configuration files. Values are “Apps” or “Drivers”. +- **WskVersion** The version of the Windows System Kit being used. + + +### Microsoft.Windows.Kits.WSK.WskWorkspaceCreate + +This event sends simple Product and Service usage data when a user is using the Windows System Kit to create new workspace for generating OS “images”. The data includes the version of the Windows System Kit and the state of the event and is used to help investigate workspace creation failures. + +The following fields are available: + +- **Architecture** The OS architecture that the workspace will target. Values are one of: “AMD64”, “ARM64”, “x86”, or “ARM”. +- **OsEdition** The Operating System Edition that the workspace will target. +- **Phase** The image creation phase. Values are “Start” or “End”. +- **WorkspaceArchitecture** The operating system architecture that the workspace will target. +- **WorkspaceOsEdition** The operating system edition that the workspace will target. +- **WskVersion** The version of the Windows System Kit being used. + + +## Windows Update Delivery Optimization events + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCanceled + +This event describes when a download was canceled with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download being done in the background? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **isVpn** Indicates whether the device is connected to a VPN (Virtual Private Network). +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller. +- **reasonCode** Reason the action or event occurred. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the file download session. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadCompleted + +This event describes when a download has completed with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **bytesFromCacheServer** Bytes received from a cache host. +- **bytesFromCDN** The number of bytes received from a CDN source. +- **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. +- **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. +- **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocalCache** Bytes copied over from local (on disk) cache. +- **bytesFromPeers** The number of bytes received from a peer in the same LAN. +- **bytesRequested** The total number of bytes requested for download. +- **cacheServerBonnectionCount** No content is currently available. +- **cacheServerConnectionCount** Number of connections made to cache hosts. +- **cdnConnectionCount** The total number of connections made to the CDN. +- **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. +- **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. +- **cdnIp** The IP address of the source CDN. +- **cdnUrl** Url of the source Content Distribution Network (CDN). +- **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dnErrorCounts** No content is currently available. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downlinkBps** The maximum measured available download bandwidth (in bytes per second). +- **downlinkUsageBps** The download speed (in bytes per second). +- **downloadMode** The download mode used for this file download session. +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **expiresAt** The time when the content will expire from the Delivery Optimization Cache. +- **fileID** The ID of the file being downloaded. +- **fileSize** The size of the file being downloaded. +- **gCurMemoryStreamBytes** Current usage for memory streaming. +- **gdnConnectionCount** No content is currently available. +- **gMaxMemoryStreamBytes** Maximum usage for memory streaming. +- **groupConnectionCo** No content is currently available. +- **groupConnectionCount** The total number of connections made to peers in the same group. +- **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. +- **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **lanConnectionCount** The total number of connections made to peers in the same LAN. +- **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. +- **numPeers** The total number of peers used for this download. +- **numPeersLocal** The total number of local peers used for this download. +- **predefinedCallerName** The name of the API Caller. +- **restrictedU`load** No content is currently available. +- **restrictedUpload** Is the upload restricted? +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **totalTimeMs** Duration of the download (in seconds). +- **updateID** The ID of the update being downloaded. +- **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkUsageBps** The upload speed (in bytes per second). +- **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused + +This event represents a temporary suspension of a download with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **background** Is the download a background download? +- **cdnUrl** The URL of the source CDN (Content Delivery Network). +- **errorCode** The error code that was returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being paused. +- **isVpn** Is the device connected to a Virtual Private Network? +- **jobID** Identifier for the Windows Update job. +- **predefinedCallerName** The name of the API Caller object. +- **reasonCode** The reason for pausing the download. +- **routeToCacheServer** The cache server setting, source, and value. +- **sessionID** The ID of the download session. +- **updateID** The ID of the update being paused. + + +### Microsoft.OSG.DU.DeliveryOptClient.DownloadStarted + +This event sends data describing the start of a new download to enable Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **ActiveNetworkConnection** No content is currently available. +- **background** Indicates whether the download is happening in the background. +- **bytesRequested** Number of bytes requested for the download. +- **cdnUrl** The URL of the source Content Distribution Network (CDN). +- **costFlags** A set of flags representing network cost. +- **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). +- **diceRoll** Random number used for determining if a client will use peering. +- **doClientVersion** The version of the Delivery Optimization client. +- **doErrorCode** The Delivery Optimization error code that was returned. +- **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). +- **downloadModeReason** Reason for the download. +- **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). +- **errorCode** The error code that was returned. +- **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. +- **fileID** The ID of the file being downloaded. +- **filePath** The path to where the downloaded file will be written. +- **fileSize** Total file size of the file that was downloaded. +- **fileSizeCaller** Value for total file size provided by our caller. +- **groupID** ID for the group. +- **IsBootCritical** No content is currently available. +- **isEncrypted** Indicates whether the download is encrypted. +- **isVpn** Indicates whether the device is connected to a Virtual Private Network. +- **jobID** The ID of the Windows Update job. +- **peerID** The ID for this delivery optimization client. +- **predefinedCallerName** Name of the API caller. +- **routeToCacheServer** Cache server setting, source, and value. +- **SdbEntries** No content is currently available. +- **sessionID** The ID for the file download session. +- **setConfigs** A JSON representation of the configurations that have been set, and their sources. +- **updateID** The ID of the update being downloaded. +- **usedMemoryStream** Indicates whether the download used memory streaming. +- **WuDriverCoverage** No content is currently available. +- **WuDriverUpdateId** No content is currently available. +- **WuPopulatedFromId** No content is currently available. + + +### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication + +This event represents a failure to download from a CDN with Delivery Optimization. It's used to understand and address problems regarding downloads. + +The following fields are available: + +- **cdnHeaders** The HTTP headers returned by the CDN. +- **cdnIp** The IP address of the CDN. +- **cdnUrl** The URL of the CDN. +- **errorCode** The error code that was returned. +- **errorCount** The total number of times this error code was seen since the last FailureCdnCommunication event was encountered. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **httpStatusCode** The HTTP status code returned by the CDN. +- **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET +- **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). +- **requestOffset** The byte offset within the file in the sent request. +- **requestSize** The size of the range requested from the CDN. +- **responseSize** The size of the range response received from the CDN. +- **sessionID** The ID of the download session. + + +### Microsoft.OSG.DU.DeliveryOptClient.JobError + +This event represents a Windows Update job error. It allows for investigation of top errors. + +The following fields are available: + +- **cdnIp** The IP Address of the source CDN (Content Delivery Network). +- **doErrorCode** Error code returned for delivery optimization. +- **errorCode** The error code returned. +- **experimentId** When running a test, this is used to correlate with other events that are part of the same test. +- **fileID** The ID of the file being downloaded. +- **jobID** The Windows Update job ID. + + +## Windows Update events + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentAnalysisSummary + +This event collects information regarding the state of devices and drivers on the system following a reboot after the install phase of the new device manifest UUP (Unified Update Platform) update scenario which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **activated** Whether the entire device manifest update is considered activated and in use. +- **analysisErrorCount** The number of driver packages that could not be analyzed because errors occurred during analysis. +- **flightId** Unique ID for each flight. +- **missingDriverCount** The number of driver packages delivered by the device manifest that are missing from the system. +- **missingUpdateCount** The number of updates in the device manifest that are missing from the system. +- **objectId** Unique value for each diagnostics session. +- **publishedCount** The number of drivers packages delivered by the device manifest that are published and available to be used on devices. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **scenarioId** Indicates the update scenario. +- **sessionId** Unique value for each update session. +- **summary** A summary string that contains basic information about driver packages that are part of the device manifest and any devices on the system that those driver packages match. +- **summaryAppendError** A Boolean indicating if there was an error appending more information to the summary string. +- **truncatedDeviceCount** The number of devices missing from the summary string because there is not enough room in the string. +- **truncatedDriverCount** The number of driver packages missing from the summary string because there is not enough room in the string. +- **unpublishedCount** How many drivers packages that were delivered by the device manifest that are still unpublished and unavailable to be used on devices. +- **updateId** The unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentCommit + +This event collects information regarding the final commit phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** The unique GUID for each diagnostics session. +- **relatedCV** A correlation vector value generated from the latest USO scan. +- **result** Outcome of the initialization of the session. +- **scenarioId** Identifies the Update scenario. +- **sessionId** The unique value for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentDownloadRequest + +This event collects information regarding the download request phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **deletedCorruptFiles** Indicates if UpdateAgent found any corrupt payload files and whether the payload was deleted. +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **objectId** Unique value for each Update Agent mode. +- **packageCountOptional** Number of optional packages requested. +- **packageCountRequired** Number of required packages requested. +- **packageCountTotal** Total number of packages needed. +- **packageCountTotalCanonical** Total number of canonical packages. +- **packageCountTotalDiff** Total number of diff packages. +- **packageCountTotalExpress** Total number of express packages. +- **packageSizeCanonical** Size of canonical packages in bytes. +- **packageSizeDiff** Size of diff packages in bytes. +- **packageSizeExpress** Size of express packages in bytes. +- **rangeRequestState** Represents the state of the download range request. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the download request phase of update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInitialize + +This event sends data for initializing a new update session for the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current session initialization. +- **flightId** The unique identifier for each flight. +- **flightMetadata** Contains the FlightId and the build being flighted. +- **objectId** Unique value for each Update Agent mode. +- **relatedCV** Correlation vector value generated from the latest USO scan. +- **result** Result of the initialize phase of the update. 0 = Succeeded, 1 = Failed, 2 = Cancelled, 3 = Blocked, 4 = BlockCancelled. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionData** Contains instructions to update agent for processing FODs and DUICs (Null for other scenarios). +- **sessionId** Unique value for each Update Agent mode attempt. +- **updateId** Unique ID for each update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentInstall + +This event collects information regarding the install phase of the new device manifest UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **errorCode** The error code returned for the current install phase. +- **flightId** The unique identifier for each flight (pre-release builds). +- **objectId** The unique identifier for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **result** Outcome of the install phase of the update. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.DeviceUpdateAgent.UpdateAgentModeStart + +This event sends data for the start of each mode during the process of updating device manifest assets via the UUP (Unified Update Platform) update scenario, which is used to install a device manifest describing a set of driver packages. + +The following fields are available: + +- **flightId** The unique identifier for each flight (pre-release builds). +- **mode** Indicates the active Update Agent mode. +- **objectId** Unique value for each diagnostics session. +- **relatedCV** Correlation vector value generated from the latest scan. +- **scenarioId** The scenario ID. Example: MobileUpdate, DesktopLanguagePack, DesktopFeatureOnDemand, or DesktopDriverUpdate. +- **sessionId** The unique identifier for each update session. +- **updateId** The unique identifier for each Update. + + +### Microsoft.Windows.Update.NotificationUx.DialogNotificationToBeDisplayed + +This event indicates that a notification dialog box is about to be displayed to user. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before the RebootFailed dialog box is shown. +- **DaysSinceRebootRequired** Number of days since restart was required. +- **DeviceLocalTime** The local time on the device sending the event. +- **EngagedModeLimit** The number of days to switch between DTE dialog boxes. +- **EnterAutoModeLimit** The maximum number of days for a device to enter Auto Reboot mode. +- **ETag** OneSettings versioning value. +- **IsForcedEnabled** Indicates whether Forced Reboot mode is enabled for this device. +- **IsUltimateForcedEnabled** Indicates whether Ultimate Forced Reboot mode is enabled for this device. +- **NotificationUxState** Indicates which dialog box is shown. +- **NotificationUxStateString** Indicates which dialog box is shown. +- **RebootUxState** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootUxStateString** Indicates the state of the restart (Engaged, Auto, Forced, or UltimateForced). +- **RebootVersion** Version of DTE. +- **SkipToAutoModeLimit** The minimum length of time to pass in restart pending before a device can be put into auto mode. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UtcTime** The time the dialog box notification will be displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootAcceptAutoDialog + +This event indicates that the Enhanced Engaged restart "accept automatically" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose on this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootFirstReminderDialog + +This event indicates that the Enhanced Engaged restart "first reminder" dialog box was displayed.. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootFailedDialog + +This event indicates that the Enhanced Engaged restart "restart failed" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time of the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in this dialog box. +- **UtcTime** The time that the dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootRebootImminentDialog + +This event indicates that the Enhanced Engaged restart "restart imminent" dialog box was displayed. + +The following fields are available: + +- **DeviceLocalTime** Time the dialog box was shown on the local device. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the dialog box. +- **RebootVersion** Version of DTE. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that user chose in this dialog box. +- **UtcTime** The time that dialog box was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderDialog + +This event returns information relating to the Enhanced Engaged reboot reminder dialog that was displayed. + +The following fields are available: + +- **DeviceLocalTime** The time at which the reboot reminder dialog was shown (based on the local device time settings). +- **ETag** The OneSettings versioning value. +- **ExitCode** Indicates how users exited the reboot reminder dialog box. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. +- **UserResponseString** The option chosen by the user on the reboot dialog box. +- **UtcTime** The time at which the reboot reminder dialog was shown (in UTC). + + +### Microsoft.Windows.Update.NotificationUx.EnhancedEngagedRebootReminderToast + +This event indicates that the Enhanced Engaged restart reminder pop-up banner was displayed. + +The following fields are available: + +- **DeviceLocalTime** The local time on the device sending the event. +- **ETag** OneSettings versioning value. +- **ExitCode** Indicates how users exited the pop-up banner. +- **RebootVersion** The version of the reboot logic. +- **UpdateId** The ID of the update that is pending restart to finish installation. +- **UpdateRevision** The revision of the update that is pending restart to finish installation. +- **UserResponseString** The option that the user chose in the pop-up banner. +- **UtcTime** The time that the pop-up banner was displayed, in Coordinated Universal Time. + + +### Microsoft.Windows.Update.NotificationUx.RebootScheduled + +Indicates when a reboot is scheduled by the system or a user for a security, quality, or feature update. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether an Active Hours policy is present on the device. +- **IsEnhancedEngagedReboot** Indicates whether this is an Enhanced Engaged reboot. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** Indicates whether a restart is scheduled outside of active hours. +- **rebootScheduledByUser** Indicates whether the restart was scheduled by user (if not, it was scheduled automatically). +- **rebootState** The current state of the restart. +- **rebootUsingSmartScheduler** Indicates whether the reboot is scheduled by smart scheduler. +- **revisionNumber** Revision number of the update that is getting installed with this restart. +- **scheduledRebootTime** Time of the scheduled restart. +- **scheduledRebootTimeInUTC** Time of the scheduled restart in Coordinated Universal Time. +- **updateId** ID of the update that is getting installed with this restart. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.ActivityRestrictedByActiveHoursPolicy + +This event indicates a policy is present that may restrict update activity to outside of active hours. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByActiveHours + +This event indicates that update activity was blocked because it is within the active hours window. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.BlockedByBatteryLevel + +This event indicates that Windows Update activity was blocked due to low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** Device ID. + + +### Microsoft.Windows.Update.Orchestrator.DeferRestart + +This event indicates that a restart required for installing updates was postponed. + +The following fields are available: + +- **displayNeededReason** List of reasons for needing display. +- **eventScenario** Indicates the purpose of the event (scan started, succeeded, failed, etc.). +- **filteredDeferReason** Applicable filtered reasons why reboot was postponed (such as user active, or low battery). +- **gameModeReason** Name of the executable that caused the game mode state check to start. +- **ignoredReason** List of reasons that were intentionally ignored. +- **IgnoreReasonsForRestart** List of reasons why restart was deferred. +- **revisionNumber** Update ID revision number. +- **systemNeededReason** List of reasons why system is needed. +- **updateId** Update ID. +- **updateScenarioType** Update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Detection + +This event indicates that a scan for a Windows Update occurred. + +The following fields are available: + +- **deferReason** The reason why the device could not check for updates. +- **detectionBlockingPolicy** The Policy that blocked detection. +- **detectionBlockreason** The reason detection did not complete. +- **detectionRetryMode** Indicates whether we will try to scan again. +- **errorCode** The error code returned for the current process. +- **eventScenario** End-to-end update session ID, or indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. +- **flightID** The unique identifier for the flight (Windows Insider pre-release build) should be delivered to the device, if applicable. +- **interactive** Indicates whether the user initiated the session. +- **networkStatus** Indicates if the device is connected to the internet. +- **revisionNumber** The Update revision number. +- **scanTriggerSource** The source of the triggered scan. +- **updateId** The unique identifier of the Update. +- **updateScenarioType** Identifies the type of update session being performed. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DisplayNeeded + +This event indicates the reboot was postponed due to needing a display. + +The following fields are available: + +- **displayNeededReason** Reason the display is needed. +- **eventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue + + +### Microsoft.Windows.Update.Orchestrator.Download + +This event sends launch data for a Windows Update download to help keep Windows up to date. + +The following fields are available: + +- **deferReason** Reason for download not completing. +- **errorCode** An error code represented as a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the session is user initiated. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUCompletedWhenWuFlightPendingCommit + +This event indicates that DTU completed installation of the electronic software delivery (ESD), when Windows Update was already in Pending Commit phase of the feature update. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUEnabled + +This event indicates that Inbox DTU functionality was enabled. + +The following fields are available: + +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.DTUInitiated + +This event indicates that Inbox DTU functionality was intiated. + +The following fields are available: + +- **dtuErrorCode** Return code from creating the DTU Com Server. +- **isDtuApplicable** Determination of whether DTU is applicable to the machine it is running on. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.EscalationRiskLevels + +This event is sent during update scan, download, or install, and indicates that the device is at risk of being out-of-date. + +The following fields are available: + +- **configVersion** The escalation configuration version on the device. +- **downloadElapsedTime** Indicates how long since the download is required on device. +- **downloadRiskLevel** At-risk level of download phase. +- **installElapsedTime** Indicates how long since the install is required on device. +- **installRiskLevel** The at-risk level of install phase. +- **isSediment** Assessment of whether is device is at risk. +- **scanElapsedTime** Indicates how long since the scan is required on device. +- **scanRiskLevel** At-risk level of the scan phase. +- **wuDeviceid** Device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.FailedToAddTimeTriggerToScanTask + +This event indicated that USO failed to add a trigger time to a task. + +The following fields are available: + +- **errorCode** The Windows Update error code. +- **wuDeviceid** The Windows Update device ID. + + +### Microsoft.Windows.Update.Orchestrator.FlightInapplicable + +This event indicates that the update is no longer applicable to this device. + +The following fields are available: + +- **EventPublishedTime** Time when this event was generated. +- **flightID** The specific ID of the Windows Insider build. +- **inapplicableReason** The reason why the update is inapplicable. +- **revisionNumber** Update revision number. +- **updateId** Unique Windows Update ID. +- **updateScenarioType** Update session type. +- **UpdateStatus** Last status of update. +- **UUPFallBackConfigured** Indicates whether UUP fallback is configured. +- **wuDeviceid** Unique Device ID. + + +### Microsoft.Windows.Update.Orchestrator.InitiatingReboot + +This event sends data about an Orchestrator requesting a reboot from power management to help keep Windows up to date. + +The following fields are available: + +- **EventPublishedTime** Time of the event. +- **flightID** Unique update ID +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **rebootOutsideOfActiveHours** Indicates whether the reboot was to occur outside of active hours. +- **revisionNumber** Revision number of the update. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.Install + +This event sends launch data for a Windows Update install to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **errorCode** The error code reppresented by a hexadecimal value. +- **eventScenario** End-to-end update session ID. +- **flightID** The ID of the Windows Insider build the device is getting. +- **flightUpdate** Indicates whether the update is a Windows Insider build. +- **ForcedRebootReminderSet** A boolean value that indicates if a forced reboot will happen for updates. +- **IgnoreReasonsForRestart** The reason(s) a Postpone Restart command was ignored. +- **installCommitfailedtime** The time it took for a reboot to happen but the upgrade failed to progress. +- **installRebootinitiatetime** The time it took for a reboot to be attempted. +- **interactive** Identifies if session is user initiated. +- **minutesToCommit** The time it took to install updates. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.LowUptimes + +This event is sent if a device is identified as not having sufficient uptime to reliably process updates in order to keep secure. + +The following fields are available: + +- **availableHistoryMinutes** The number of minutes available from the local machine activity history. +- **isLowUptimeMachine** Is the machine considered low uptime or not. +- **lowUptimeMinHours** Current setting for the minimum number of hours needed to not be considered low uptime. +- **lowUptimeQueryDays** Current setting for the number of recent days to check for uptime. +- **uptimeMinutes** Number of minutes of uptime measured. +- **wuDeviceid** Unique device ID for Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.OneshotUpdateDetection + +This event returns data about scans initiated through settings UI, or background scans that are urgent; to help keep Windows up to date. + +The following fields are available: + +- **externalOneshotupdate** The last time a task-triggered scan was completed. +- **interactiveOneshotupdate** The last time an interactive scan was completed. +- **oldlastscanOneshotupdate** The last time a scan completed successfully. +- **wuDeviceid** The Windows Update Device GUID (Globally-Unique ID). + + +### Microsoft.Windows.Update.Orchestrator.PreShutdownStart + +This event is generated before the shutdown and commit operations. + +The following fields are available: + +- **wuDeviceid** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. + + +### Microsoft.Windows.Update.Orchestrator.RebootFailed + +This event sends information about whether an update required a reboot and reasons for failure, to help keep Windows up to date. + +The following fields are available: + +- **batteryLevel** Current battery capacity in mWh or percentage left. +- **deferReason** Reason for install not completing. +- **EventPublishedTime** The time that the reboot failure occurred. +- **flightID** Unique update ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot was scheduled outside of active hours. +- **RebootResults** Hex code indicating failure reason. Typically, we expect this to be a specific USO generated hex code. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RefreshSettings + +This event sends basic data about the version of upgrade settings applied to the system to help keep Windows up to date. + +The following fields are available: + +- **errorCode** Hex code for the error message, to allow lookup of the specific error. +- **settingsDownloadTime** Timestamp of the last attempt to acquire settings. +- **settingsETag** Version identifier for the settings. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.RestoreRebootTask + +This event sends data indicating that a reboot task is missing unexpectedly on a device and the task is restored because a reboot is still required, to help keep Windows up to date. + +The following fields are available: + +- **RebootTaskMissedTimeUTC** The time when the reboot task was scheduled to run, but did not. +- **RebootTaskNextTimeUTC** The time when the reboot task was rescheduled for. +- **RebootTaskRestoredTime** Time at which this reboot task was restored. +- **wuDeviceid** Device ID for the device on which the reboot is restored. + + +### Microsoft.Windows.Update.Orchestrator.ScanTriggered + +This event indicates that Update Orchestrator has started a scan operation. + +The following fields are available: + +- **errorCode** The error code returned for the current scan operation. +- **eventScenario** Indicates the purpose of sending this event. +- **interactive** Indicates whether the scan is interactive. +- **isDTUEnabled** Indicates whether DTU (internal abbreviation for Direct Feature Update) channel is enabled on the client system. +- **isScanPastSla** Indicates whether the SLA has elapsed for scanning. +- **isScanPastTriggerSla** Indicates whether the SLA has elapsed for triggering a scan. +- **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. +- **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. +- **scanTriggerSource** Indicates what caused the scan. +- **updateScenarioType** The update session type. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.StickUpdate + +This event is sent when the update service orchestrator (USO) indicates the update cannot be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.SystemNeeded + +This event sends data about why a device is unable to reboot, to help keep Windows up to date. + +The following fields are available: + +- **eventScenario** End-to-end update session ID. +- **rebootOutsideOfActiveHours** Indicates whether a reboot is scheduled outside of active hours. +- **revisionNumber** Update revision number. +- **systemNeededReason** List of apps or tasks that are preventing the system from restarting. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByActiveHours + +This event indicates that update activity was stopped due to active hours starting. + +The following fields are available: + +- **activeHoursEnd** The end of the active hours window. +- **activeHoursStart** The start of the active hours window. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.TerminatedByBatteryLevel + +This event is sent when update activity was stopped due to a low battery level. + +The following fields are available: + +- **batteryLevel** The current battery charge capacity. +- **batteryLevelThreshold** The battery capacity threshold to stop update activity. +- **updatePhase** The current state of the update process. +- **wuDeviceid** The device identifier. + + +### Microsoft.Windows.Update.Orchestrator.UnstickUpdate + +This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. + +The following fields are available: + +- **updateId** Identifier associated with the specific piece of content. +- **wuDeviceid** Unique device ID controlled by the software distribution client. + + +### Microsoft.Windows.Update.Orchestrator.UpdatePolicyCacheRefresh + +This event sends data on whether Update Management Policies were enabled on a device, to help keep Windows up to date. + +The following fields are available: + +- **configuredPoliciescount** Number of policies on the device. +- **configuredPoliciescsunt** No content is currently available. +- **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). +- **policyCacherefreshtime** Time when policy cache was refreshed. +- **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired + +This event sends data about whether an update required a reboot to help keep Windows up to date. + +The following fields are available: + +- **flightID** The specific ID of the Windows Insider build the device is getting. +- **interactive** Indicates whether the reboot initiation stage of the update process was entered as a result of user action. +- **revisionNumber** Update revision number. +- **updateId** Update ID. +- **updateScenarioType** The update session type. +- **uxRebootstate** Indicates the exact state of the user experience at the time the required reboot was initiated to ensure the correct update process and experience is provided to keep Windows up to date. +- **wuDeviceid** Unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed + +This event sends information about an update that encountered problems and was not able to complete. + +The following fields are available: + +- **errorCode** The error code encountered. +- **wuDeviceid** The ID of the device in which the error occurred. + + +### Microsoft.Windows.Update.Orchestrator.UsoSession + +This event represents the state of the USO service at start and completion. + +The following fields are available: + +- **activeSessionid** A unique session GUID. +- **eventScenario** The state of the update action. +- **interactive** Is the USO session interactive? +- **lastErrorcode** The last error that was encountered. +- **lastErrorstate** The state of the update when the last error was encountered. +- **sessionType** A GUID that refers to the update session type. +- **updateScenarioType** A descriptive update session type. +- **wuDeviceid** The Windows Update device GUID. + + +### Microsoft.Windows.Update.Ux.MusNotification.EnhancedEngagedRebootUxState + +This event sends information about the configuration of Enhanced Direct-to-Engaged (eDTE), which includes values for the timing of how eDTE will progress through each phase of the reboot. + +The following fields are available: + +- **AcceptAutoModeLimit** The maximum number of days for a device to automatically enter Auto Reboot mode. +- **AutoToAutoFailedLimit** The maximum number of days for Auto Reboot mode to fail before a Reboot Failed dialog will be shown. +- **DeviceLocalTime** The date and time (based on the device date/time settings) the reboot mode changed. +- **EngagedModeLimit** The number of days to switch between DTE (Direct-to-Engaged) dialogs. +- **EnterAutoModeLimit** The maximum number of days a device can enter Auto Reboot mode. +- **ETag** The Entity Tag that represents the OneSettings version. +- **IsForcedEnabled** Identifies whether Forced Reboot mode is enabled for the device. +- **IsUltimateForcedEnabled** Identifies whether Ultimate Forced Reboot mode is enabled for the device. +- **OldestUpdateLocalTime** The date and time (based on the device date/time settings) this update’s reboot began pending. +- **RebootUxState** Identifies the reboot state: Engaged, Auto, Forced, UltimateForced. +- **RebootVersion** The version of the DTE (Direct-to-Engaged). +- **SkipToAutoModeLimit** The maximum number of days to switch to start while in Auto Reboot mode. +- **UpdateId** The ID of the update that is waiting for reboot to finish installation. +- **UpdateRevision** The revision of the update that is waiting for reboot to finish installation. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootNoLongerNeeded + +This event is sent when a security update has successfully completed. + +The following fields are available: + +- **UtcTime** The Coordinated Universal Time that the restart was no longer needed. + + +### Microsoft.Windows.Update.Ux.MusNotification.RebootScheduled + +This event sends basic information about scheduling an update-related reboot, to get security updates and to help keep Windows up-to-date. + +The following fields are available: + +- **activeHoursApplicable** Indicates whether Active Hours applies on this device. +- **IsEnhancedEngagedReboot** Indicates whether Enhanced reboot was enabled. +- **rebootArgument** Argument for the reboot task. It also represents specific reboot related action. +- **rebootOutsideOfActiveHours** True, if a reboot is scheduled outside of active hours. False, otherwise. +- **rebootScheduledByUser** True, if a reboot is scheduled by user. False, if a reboot is scheduled automatically. +- **rebootState** Current state of the reboot. +- **rebootUsingSmartScheduler** Indicates that the reboot is scheduled by SmartScheduler. +- **revisionNumber** Revision number of the OS. +- **scheduledRebootTime** Time scheduled for the reboot. +- **scheduledRebootTimeInUTC** Time scheduled for the reboot, in UTC. +- **updateId** Identifies which update is being scheduled. +- **wuDeviceid** The unique device ID used by Windows Update. + + +### Microsoft.Windows.Update.Ux.MusNotification.UxBrokerScheduledTask + +This event is sent when MUSE broker schedules a task. + +The following fields are available: + +- **TaskArgument** The arguments with which the task is scheduled. +- **TaskName** Name of the task. + + +### Microsoft.Windows.Update.Ux.MusUpdateSettings.RebootScheduled + +This event sends basic information for scheduling a device restart to install security updates. It's used to help keep Windows up to date. + +The following fields are available: + +- **activeHoursApplicable** Is the restart respecting Active Hours? +- **IsEnhancedEngagedReboot** TRUE if the reboot path is Enhanced Engaged. Otherwise, FALSE. +- **rebootArgument** The arguments that are passed to the OS for the restarted. +- **rebootOutsideOfActiveHours** Was the restart scheduled outside of Active Hours? +- **rebootScheduledByUser** Was the restart scheduled by the user? If the value is false, the restart was scheduled by the device. +- **rebootState** The state of the restart. +- **rebootUsingSmartScheduler** TRUE if the reboot should be performed by the Smart Scheduler. Otherwise, FALSE. +- **revisionNumber** The revision number of the OS being updated. +- **scheduledRebootTime** Time of the scheduled reboot +- **scheduledRebootTimeInUTC** Time of the scheduled restart, in Coordinated Universal Time. +- **updateId** The Windows Update device GUID. +- **wuDeviceid** The Windows Update device GUID. + + +## Windows Update mitigation events + +### Mitigation360Telemetry.MitigationCustom.CleanupSafeOsImages + +This event sends data specific to the CleanupSafeOsImages mitigation used for OS Updates. + +The following fields are available: + +- **ClientId** The client ID used by Windows Update. +- **FlightId** The ID of each Windows Insider build the device received. +- **InstanceId** A unique device ID that identifies each update instance. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **MountedImageCount** The number of mounted images. +- **MountedImageMatches** The number of mounted image matches. +- **MountedImagesFailed** The number of mounted images that could not be removed. +- **MountedImagesRemoved** The number of mounted images that were successfully removed. +- **MountedImagesSkipped** The number of mounted images that were not found. +- **RelatedCV** The correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each Windows Update. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixAppXReparsePoints + +This event sends data specific to the FixAppXReparsePoints mitigation used for OS updates. + +The following fields are available: + +- **ClientId** Unique identifier for each flight. +- **FlightId** Unique GUID that identifies each instances of setuphost.exe. +- **InstanceId** The update scenario in which the mitigation was executed. +- **MitigationScenario** Correlation vector value generated from the latest USO scan. +- **RelatedCV** Number of reparse points that are corrupted but we failed to fix them. +- **ReparsePointsFailed** Number of reparse points that were corrupted and were fixed by this mitigation. +- **ReparsePointsFixed** Number of reparse points that are not corrupted and no action is required. +- **ReparsePointsSkipped** HResult of this operation. +- **Result** ID indicating the mitigation scenario. +- **ScenarioId** Indicates whether the scenario was supported. +- **ScenarioSupported** Unique value for each update attempt. +- **SessionId** Unique ID for each Update. +- **UpdateId** Unique ID for the Windows Update client. +- **WuId** Unique ID for the Windows Update client. + + +### Mitigation360Telemetry.MitigationCustom.FixupEditionId + +This event sends data specific to the FixupEditionId mitigation used for OS updates. + +The following fields are available: + +- **ClientId** In the WU scenario, this will be the WU client ID that is passed to Setup. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **EditionIdUpdated** Determine whether EditionId was changed. +- **FlightId** Unique identifier for each flight. +- **InstanceId** Unique GUID that identifies each instances of setuphost.exe. +- **MitigationScenario** The update scenario in which the mitigation was executed. +- **ProductEditionId** Expected EditionId value based on GetProductInfo. +- **ProductType** Value returned by GetProductInfo. +- **RegistryEditionId** EditionId value in the registry. +- **RelatedCV** Correlation vector value generated from the latest USO scan. +- **Result** HResult of this operation. +- **ScenarioId** ID indicating the mitigation scenario. +- **ScenarioSupported** Indicates whether the scenario was supported. +- **SessionId** Unique value for each update attempt. +- **UpdateId** Unique ID for each update. +- **WuId** Unique ID for the Windows Update client. + + +## Windows Update Reserve Manager events + +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + +The following fields are available: + +- **FinalAdjustment** Final adjustment for the hard reserve following the addition or removal of optional content. +- **InitialAdjustment** Initial intended adjustment for the hard reserve following the addition/removal of optional content. + + +### Microsoft.Windows.UpdateReserveManager.FunctionReturnedError + +This event is sent when the Update Reserve Manager returns an error from one of its internal functions. + +The following fields are available: + +- **FailedExpression** The failed expression that was returned. +- **FailedFile** The binary file that contained the failed function. +- **FailedFunction** The name of the function that originated the failure. +- **FailedLine** The line number of the failure. +- **ReturnCode** The return code of the function. + + +### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager + +This event returns data about the Update Reserve Manager, including whether it’s been initialized. + +The following fields are available: + +- **ClientId** The ID of the caller application. +- **Flags** The enumerated flags used to initialize the manager. +- **FlightId** The flight ID of the content the calling client is currently operating with. +- **Offline** Indicates whether or the reserve manager is called during offline operations. +- **PolicyPassed** Indicates whether the machine is able to use reserves. +- **ReturnCode** Return code of the operation. +- **Version** The version of the Update Reserve Manager. + + +### Microsoft.Windows.UpdateReserveManager.PrepareTIForReserveInitialization + +This event is sent when the Update Reserve Manager prepares the Trusted Installer to initialize reserves on the next boot. + +The following fields are available: + +- **Flags** The flags that are passed to the function to prepare the Trusted Installer for reserve initialization. + + +### Microsoft.Windows.UpdateReserveManager.RemovePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager removes a pending hard reserve adjustment. + + + +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + +The following fields are available: + +- **ChangeSize** The change in the hard reserve size based on the addition or removal of optional content. +- **Disposition** The parameter for the hard reserve adjustment function. +- **Flags** The flags passed to the hard reserve adjustment function. +- **PendingHardReserveAdjustment** The final change to the hard reserve size. +- **UpdateType** Indicates whether the change is an increase or decrease in the size of the hard reserve. + + +## Winlogon events + +### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon + +This event signals the completion of the setup process. It happens only once during the first logon. + + + +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + + From b1567238bc987713dde8b105a0b9b029cf03fb4f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 28 Mar 2019 08:21:14 -0700 Subject: [PATCH 090/737] new build 3/28/2019 8:21 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 6d5138182b..76c72b91b1 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/27/2019 +ms.date: 03/28/2019 --- From fe66322f4c0cf05d89c157dbb5faa784b805af3c Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 28 Mar 2019 08:21:21 -0700 Subject: [PATCH 091/737] new build 3/28/2019 8:21 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 74 +++++-------------- 4 files changed, 22 insertions(+), 58 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 1a4810d670..49791ce7a0 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/27/2019 +ms.date: 03/28/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 0ca537440b..d6a6f6eaad 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/27/2019 +ms.date: 03/28/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index a2d892faf3..12fd625a8a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/27/2019 +ms.date: 03/28/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 8540ded6cf..60f70721cc 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/27/2019 +ms.date: 03/28/2019 --- @@ -2172,9 +2172,7 @@ The following fields are available: - **DefaultAppLanguage** The current user Default App Language. - **DisplayLanguage** The current user preferred Windows Display Language. - **HomeLocation** The current user location, which is populated using GetUserGeoId() function. -- **KeyboardInputLaîguages** No content is currently available. - **KeyboardInputLanguages** The Keyboard input languages installed on the device. -- **SpeechInputLalguages** No content is currently available. - **SpeechInputLanguages** The Speech Input languages installed on the device. @@ -2188,9 +2186,7 @@ The following fields are available: - **ActivityHistoryCloudSync** Current state of the activity history cloud sync setting. - **ActivityHistoryCollection** Current state of the activity history collection setting. - **AdvertisingId** Current state of the advertising ID setting. -- **AppDiagnostacs** No content is currently available. - **AppDiagnostics** Current state of the app diagnostics setting. -- **Appiagnostics** No content is currently available. - **Appointments** Current state of the calendar setting. - **Bluetooth** Current state of the Bluetooth capability setting. - **BluetoothSync** Current state of the Bluetooth sync capability setting. @@ -2202,26 +2198,21 @@ The following fields are available: - **Email** Current state of the email setting. - **GazeInput** Current state of the gaze input setting. - **HumanInterfaceDevice** Current state of the human interface device setting. -- **InkT9peImprovement** No content is currently available. -- **InkT9pePersonalization** No content is currently available. - **InkTypeImprovement** Current state of the improve inking and typing setting. - **InkTypePersonalization** Current state of the inking and typing personalization setting. - **Location** Current state of the location setting. - **LocationHistory** Current state of the location history setting. - **LocationHistoryCloudSync** Current state of the location history cloud synchronization setting. - **LocationHistoryOnTimeline** Current state of the location history on timeline setting. -- **Microphona** No content is currently available. - **Microphone** Current state of the microphone setting. - **PhoneCall** Current state of the phone call setting. - **PhoneCallHistory** Current state of the call history setting. - **PicturesLibrary** Current state of the pictures library setting. - **Radios** Current state of the radios setting. -- **SensorsÃustom** No content is currently available. - **SensorsCustom** Current state of the custom sensor setting. - **SerialCommunication** Current state of the serial communication setting. - **Sms** Current state of the text messaging setting. - **SpeechPersonalization** Current state of the speech services setting. -- **UqerDataTasks** No content is currently available. - **USB** Current state of the USB setting. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. @@ -2753,9 +2744,6 @@ The following fields are available: - **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. - **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. - **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. -- **捔祦⽌䱩⽪昫橷瘴場漸䤫〫洯硈㍈㡮⽯** No content is currently available. -- **⽫甸㑪摭橷捔橗⭪晙晅晣穹椸樷** No content is currently available. -- **䉪䌯䱏杄䬷㝐灌䩚㠯⽉䝲伹㡈㕉佤** No content is currently available. ### TelClientSynthetic.HeartBeat_5 @@ -2773,12 +2761,10 @@ The following fields are available: - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **CriticalOvErflowEntersCounter** No content is currently available. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. - **DbDroppedCount** Number of events dropped due to DB fullness. - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. -- **DecndingDroppedCount** No content is currently available. - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. @@ -2792,21 +2778,16 @@ The following fields are available: - **EventsUploaded** Number of events uploaded. - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **FullTrigwerBufferDroppedCount** No content is currently available. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InvalidH4BFCodeCount** No content is currently available. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalidH4BFCode** No content is currently available. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsH4BFAttempts** No content is currently available. -- **SettingsH4BFFailures** No content is currently available. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. @@ -2814,16 +2795,10 @@ The following fields are available: - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexH4BFAttempts** No content is currently available. -- **VortexH4BFFailures4xx** No content is currently available. -- **VortexH4BFFailures5xx** No content is currently available. -- **VortexH4BFResponseFailures** No content is currently available. -- **VortexH4BFResponsesWithDroppedEvents** No content is currently available. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. -- **VortexHttpResponsesWi|hDroppedEvents** No content is currently available. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. @@ -3561,18 +3536,14 @@ The following fields are available: - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. -- **AsFatal** No content is currently available. -- **Exceptio** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). -- **ModTimestamp** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. -- **ode** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. @@ -3580,7 +3551,6 @@ The following fields are available: - **ProcessId** The ID of the process that has crashed. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. - **TargetAppId** The kernel reported AppId of the application being reported. -- **targetAppVer** No content is currently available. - **TargetAppVer** The specific version of the application being reported - **TargetAsId** The sequence number for the hanging process. @@ -3642,7 +3612,6 @@ The following fields are available: - **FileSigningInfo** A count of file signing objects in cache. - **Generic** A count of generic objects in cache. - **HwItem** A count of hwitem objects in cache. -- **IentoryMiscellaneousOfficeAddIn** No content is currently available. - **InventoryApplication** A count of application objects in cache. - **InventoryApplicationAppV** A count of application AppV objects in cache. - **InventoryApplicationDriver** A count of application driver objects in cache @@ -3656,7 +3625,6 @@ The following fields are available: - **InventoryDeviceUsbHubClass** A count of device usb objects in cache - **InventoryDriverBinary** A count of driver binary objects in cache. - **InventoryDriverPackage** A count of device objects in cache. -- **InventoryMiscellaneiscellaneousOfficeInsights** No content is currently available. - **InventoryMiscellaneousOfficeAddIn** A count of office add-in objects in cache - **InventoryMiscellaneousOfficeAddInUsage** A count of office add-in usage objects in cache. - **InventoryMiscellaneousOfficeIdentifiers** A count of office identifier objects in cache @@ -3705,16 +3673,13 @@ The following fields are available: - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 -- **InstallDateFromLincFile** No content is currently available. - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. - **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. - **InventoryVersion** The version of the inventory file generating the events. - **Language** The language code of the program. -- **MsipackageCode** No content is currently available. - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. -- **OSversionAtInstallTime** No content is currently available. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. - **PackageFullName** The package full name for a Store application. - **ProgramInstanceId** A hash of the file IDs in an app. @@ -3722,7 +3687,6 @@ The following fields are available: - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. -- **type** No content is currently available. - **Type** One of ("Application", "Hotfix", "BOE", "Service", "Unknown"). Application indicates Win32 or Appx app, Hotfix indicates app updates (KBs), BOE indicates it's an app with no ARP or MSI entry, Service indicates that it is a service. Application and BOE are the ones most likely seen. - **Version** The version number of the program. @@ -3928,55 +3892,41 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **]pperClassFilters** No content is currently available. -- **basedata** No content is currently available. See [basedata](#basedata). -- **BusReportedDescraption** No content is currently available. - **BusReportedDescription** The description of the device reported by the bux. -- **BusReptrtedDescription** No content is currently available. -- **Clas{Guid** No content is currently available. - **Class** The device setup class of the driver loaded for the device. - **ClassGuid** The device class unique identifier of the driver package loaded on the device. - **COMPID** The list of “Compatible IDs” for this device. -- **Con|ainerId** No content is currently available. - **ContainerId** The system-supplied unique identifier that specifies which group(s) the device(s) installed on the parent (main) device belong to. -- **Descriptaon** No content is currently available. - **Description** The description of the device. -- **DeviceDriverFlightId** No content is currently available. -- **DeviceExtDriversFlightIds** No content is currently available. +- **DeviceDriverFlightId** The test build (Flight) identifier of the device driver. +- **DeviceExtDriversFlightIds** The test build (Flight) identifier for all extended device drivers. - **DeviceInterfaceClasses** The device interfaces that this device implements. - **DeviceState** Identifies the current state of the parent (main) device. -- **DriverAd** No content is currently available. - **DriverId** The unique identifier for the installed driver. - **DriverName** The name of the driver image file. - **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverVer^ersion** No content is currently available. - **DriverVerDate** The date associated with the driver installed on the device. - **DriverVerVersion** The version number of the driver installed on the device. - **Enumerator** Identifies the bus that enumerated the device. - **ExtendedInfs** The extended INF file names. -- **FirstInstallDate** No content is currently available. -- **H_ID** No content is currently available. +- **FirstInstallDate** The first time this device was installed on the machine. - **HWID** A list of hardware IDs for the device. - **Inf** The name of the INF file (possibly renamed by the OS, such as oemXX.inf). -- **InstallDate** No content is currently available. +- **InstallDate** The date of the most recent installation of the device on the machine. - **InstallState** The device installation state. For a list of values, see: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx - **InventoryVersion** The version number of the inventory process generating the events. - **LowerClassFilters** The identifiers of the Lower Class filters installed for the device. - **LowerFilters** The identifiers of the Lower filters installed for the device. - **Manufacturer** The manufacturer of the device. -- **MatchangID** No content is currently available. - **MatchingID** The Hardware ID or Compatible ID that Windows uses to install a device instance. -- **Modeh** No content is currently available. - **Model** Identifies the model of the device. - **ParentId** The Device Instance ID of the parent of the device. - **ProblemCode** The error code currently returned by the device, if applicable. -- **ProblmmCode** No content is currently available. - **Provider** Identifies the device provider. - **Service** The name of the device service. - **STACKID** The list of hardware IDs for the stack. - **UpperClassFilters** The identifiers of the Upper Class filters installed for the device. - **UpperFilters** The identifiers of the Upper filters installed for the device. -- **UpxerClassFilters** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDevicePnpRemove @@ -4779,6 +4729,20 @@ The following fields are available: - **winInetError** The HResult of the operation. +## Other events + +### Microsoft.Windows.MigrationCore.MigObjectCountKFSys + +No content is currently available. + +The following fields are available: + +- **knownFolderLoc->DirName->CString** No content is currently available. +- **knownFoldersSys[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted From 39f90cf585d3cf0746fc039bc5a43dfb63d6f01b Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Thu, 28 Mar 2019 11:57:38 -0700 Subject: [PATCH 092/737] updates for my task 3180695 --- windows/configuration/kiosk-single-app.md | 2 +- .../mobile-devices/provisioning-configure-mobile.md | 2 +- .../provision-pcs-for-initial-deployment.md | 2 +- windows/deployment/vda-subscription-activation.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/configuration/kiosk-single-app.md b/windows/configuration/kiosk-single-app.md index 439acaa52b..7aba6dd11a 100644 --- a/windows/configuration/kiosk-single-app.md +++ b/windows/configuration/kiosk-single-app.md @@ -203,7 +203,7 @@ When you use the **Provision kiosk devices** wizard in Windows Configuration Des - + diff --git a/windows/configuration/mobile-devices/provisioning-configure-mobile.md b/windows/configuration/mobile-devices/provisioning-configure-mobile.md index 141db07726..ee0785c38d 100644 --- a/windows/configuration/mobile-devices/provisioning-configure-mobile.md +++ b/windows/configuration/mobile-devices/provisioning-configure-mobile.md @@ -44,7 +44,7 @@ The **Provision Windows mobile devices** wizard lets you configure common settin
![step one](images/one.png)![set up device](images/set-up-device.png)

Enable device setup if you want to configure settings on this page.

**If enabled:**

Enter a name for the device.

(Optional) Select a license file to upgrade Windows 10 to a different edition. [See the permitted upgrades.](https://technet.microsoft.com/itpro/windows/deploy/windows-10-edition-upgrades)

Toggle **Configure devices for shared use** off. This setting optimizes Windows 10 for shared use scenarios and isn't necessary for a kiosk scenario.

You can also select to remove pre-installed software from the device.
![device name, upgrade to enterprise, shared use, remove pre-installed software](images/set-up-device-details.png)
![step two](images/two.png) ![set up network](images/set-up-network.png)

Enable network setup if you want to configure settings on this page.

**If enabled:**

Toggle **On** or **Off** for wireless network connectivity. If you select **On**, enter the SSID, the network type (**Open** or **WPA2-Personal**), and (if **WPA2-Personal**) the password for the wireless network.
![Enter network SSID and type](images/set-up-network-details.png)
![step three](images/three.png) ![account management](images/account-management.png)

Enable account management if you want to configure settings on this page.

**If enabled:**

You can enroll the device in Active Directory, enroll in Azure Active Directory, or create a local administrator account on the device

To enroll the device in Active Directory, enter the credentials for a least-privileged user account to join the device to the domain.

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used. To enroll the device in Azure AD, select that option and enter a friendly name for the bulk token you will get using the wizard. Set an expiration date for the token (maximum is 30 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

**Warning:** You must run Windows Configuration Designer on Windows 10 to configure Azure Active Directory enrollment using any of the wizards.

To create a local administrator account, select that option and enter a user name and password.

**Important:** If you create a local account in the provisioning package, you must change the password using the **Settings** app every 42 days. If the password is not changed during that period, the account might be locked out and unable to sign in.
![join Active Directory, Azure AD, or create a local admin account](images/account-management-details.png)
![step three](images/three.png) ![account management](images/account-management.png)

Enable account management if you want to configure settings on this page.

**If enabled:**

You can enroll the device in Active Directory, enroll in Azure Active Directory, or create a local administrator account on the device

To enroll the device in Active Directory, enter the credentials for a least-privileged user account to join the device to the domain.

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used. To enroll the device in Azure AD, select that option and enter a friendly name for the bulk token you will get using the wizard. Set an expiration date for the token (maximum is 180 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

**Warning:** You must run Windows Configuration Designer on Windows 10 to configure Azure Active Directory enrollment using any of the wizards.

To create a local administrator account, select that option and enter a user name and password.

**Important:** If you create a local account in the provisioning package, you must change the password using the **Settings** app every 42 days. If the password is not changed during that period, the account might be locked out and unable to sign in.
![join Active Directory, Azure AD, or create a local admin account](images/account-management-details.png)
![step four](images/four.png) ![add applications](images/add-applications.png)

You can provision the kiosk app in the **Add applications** step. You can install multiple applications, both Windows desktop applications (Win32) and Universal Windows Platform (UWP) apps, in a provisioning package. The settings in this step vary according to the application that you select. For help with the settings, see [Provision PCs with apps](provisioning-packages/provision-pcs-with-apps.md)

**Warning:** If you click the plus button to add an application, you must specify an application for the provisioning package to validate. If you click the plus button in error, select any executable file in **Installer Path**, and then a **Cancel** button becomes available, allowing you to complete the provisioning package without an application.
![add an application](images/add-applications-details.png)
![step five](images/five.png) ![add certificates](images/add-certificates.png)

To provision the device with a certificate for the kiosk app, click **Add a certificate**. Enter a name for the certificate, and then browse to and select the certificate to be used.
![add a certificate](images/add-certificates-details.png)
![step six](images/six.png) ![Configure kiosk account and app](images/kiosk-account.png)

You can create a local standard user account that will be used to run the kiosk app. If you toggle **No**, make sure that you have an existing user account to run the kiosk app.

If you want to create an account, enter the user name and password, and then toggle **Yes** or **No** to automatically sign in the account when the device starts. (If you encounter issues with auto sign-in after you apply the provisioning package, check the Event Viewer logs for auto logon issues under **Applications and Services Logs\Microsoft\Windows\Authentication User Interface\Operational**.)

In **Configure the kiosk mode app**, enter the name of the user account that will run the kiosk mode app. Select the type of app to run in kiosk mode, and then enter the path or filename (for a Windows desktop application) or the AUMID (for a Universal Windows app). For a Windows desktop application, you can use the filename if the path to the file is in the PATH environment variable, otherwise the full path is required.
![Configure kiosk account and app](images/kiosk-account-details.png)
- +
![step one](../images/one.png)![set up device](../images/set-up-device-mobile.png)

Enter a device name.

Optionally, you can enter a product key to upgrade the device from Windows 10 Mobile to Windows 10 Mobile Enterprise.
![device name, upgrade license](../images/set-up-device-details-mobile.png)
![step two](../images/two.png) ![set up network](../images/set-up-network-mobile.png)

Toggle **On** or **Off** for wireless network connectivity.

If you select **On**, enter the SSID, network type (**Open** or **WPA2-Personal**), and (if **WPA2-Personal**) the password for the wireless network.
![Enter network SSID and type](../images/set-up-network-details-mobile.png)
![step three](../images/three.png) ![bulk enrollment in Azure Active Directory](../images/bulk-enroll-mobile.png)

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used.

Set an expiration date for the token (maximum is 30 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

**Warning:** You must run Windows Configuration Designer on Windows 10 to configure Azure Active Directory enrollment using any of the wizards.
![Enter expiration and get bulk token](../images/bulk-enroll-mobile-details.png)
![step three](../images/three.png) ![bulk enrollment in Azure Active Directory](../images/bulk-enroll-mobile.png)

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used.

Set an expiration date for the token (maximum is 180 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

**Warning:** You must run Windows Configuration Designer on Windows 10 to configure Azure Active Directory enrollment using any of the wizards.
![Enter expiration and get bulk token](../images/bulk-enroll-mobile-details.png)
![step four](../images/four.png) ![finish](../images/finish-mobile.png)

You can set a password to protect your provisioning package. You must enter this password when you apply the provisioning package to a device.
![Protect your package](../images/finish-details-mobile.png)
diff --git a/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md b/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md index 9979020ba7..13941c3e8f 100644 --- a/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md +++ b/windows/configuration/provisioning-packages/provision-pcs-for-initial-deployment.md @@ -81,7 +81,7 @@ Use the Windows Configuration Designer tool to create a provisioning package. [L - + diff --git a/windows/deployment/vda-subscription-activation.md b/windows/deployment/vda-subscription-activation.md index 52d00d7f17..bc7249bb71 100644 --- a/windows/deployment/vda-subscription-activation.md +++ b/windows/deployment/vda-subscription-activation.md @@ -88,7 +88,7 @@ For examples of activation issues, see [Troubleshoot the user experience](https: ## Azure Active Directory-joined VMs >[!IMPORTANT] ->Azure Active Directory (Azure AD) provisioning packages have a 30 day limit on bulk token usage. You will need to update the provisioning package and re-inject it into the image after 30 days. Existing virtual machines that are Azure AD-joined and deployed will not need to be recreated. +>Azure Active Directory (Azure AD) provisioning packages have a 180 day limit on bulk token usage. You will need to update the provisioning package and re-inject it into the image after 180 days. Existing virtual machines that are Azure AD-joined and deployed will not need to be recreated. For Azure AD-joined VMs, follow the same instructions (above) as for [Active Directory-joined VMs](#active-directory-joined-vms) with the following exceptions: - In step 9, during setup with Windows Configuration Designer, under **Name**, type a name for the project that indicates it is not for Active Directory joined VMs, such as **Desktop Bulk Enrollment Token Pro GVLK**. From d8006946d7a35a9a85b3fa33e5a22ddab662096e Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Fri, 29 Mar 2019 07:59:34 -0700 Subject: [PATCH 093/737] task 3180700 --- .../configuration/configure-windows-10-taskbar.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/windows/configuration/configure-windows-10-taskbar.md b/windows/configuration/configure-windows-10-taskbar.md index 6d89596e32..9439d40848 100644 --- a/windows/configuration/configure-windows-10-taskbar.md +++ b/windows/configuration/configure-windows-10-taskbar.md @@ -9,7 +9,7 @@ author: jdeckerms ms.author: jdecker ms.topic: article ms.localizationpriority: medium -ms.date: 01/18/2018 +ms.date: 05/21/2019 --- # Configure Windows 10 taskbar @@ -315,6 +315,16 @@ The resulting taskbar for computers in any other country region: + + + + + + + + + + ``` From cfac8ae6fcfba81d9c6004d129253f1558d4b200 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Fri, 29 Mar 2019 09:05:12 -0700 Subject: [PATCH 094/737] Revert "task 3180700" This reverts commit d8006946d7a35a9a85b3fa33e5a22ddab662096e. --- .../configuration/configure-windows-10-taskbar.md | 12 +----------- 1 file changed, 1 insertion(+), 11 deletions(-) diff --git a/windows/configuration/configure-windows-10-taskbar.md b/windows/configuration/configure-windows-10-taskbar.md index 9439d40848..6d89596e32 100644 --- a/windows/configuration/configure-windows-10-taskbar.md +++ b/windows/configuration/configure-windows-10-taskbar.md @@ -9,7 +9,7 @@ author: jdeckerms ms.author: jdecker ms.topic: article ms.localizationpriority: medium -ms.date: 05/21/2019 +ms.date: 01/18/2018 --- # Configure Windows 10 taskbar @@ -315,16 +315,6 @@ The resulting taskbar for computers in any other country region: - - - - - - - - - - ``` From 6d6481535f028c25e3d706ae7cebbed2a263c278 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 29 Mar 2019 13:15:15 -0700 Subject: [PATCH 095/737] new build 3/29/2019 1:15 PM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 76c72b91b1..f91d4a0548 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/28/2019 +ms.date: 03/29/2019 --- From 8c5178c35dc73447dbac3b204c0a75ec8a9207d8 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 29 Mar 2019 13:15:20 -0700 Subject: [PATCH 096/737] new build 3/29/2019 1:15 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 55 ++----------------- 4 files changed, 9 insertions(+), 52 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 49791ce7a0..b5c2cbf517 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/28/2019 +ms.date: 03/29/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index d6a6f6eaad..800377e966 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/28/2019 +ms.date: 03/29/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 12fd625a8a..e22d5344bb 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/28/2019 +ms.date: 03/29/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 60f70721cc..6c3abb47aa 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/28/2019 +ms.date: 03/29/2019 --- @@ -3983,7 +3983,6 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **DrivdrCompany** No content is currently available. - **DriverCheckSum** The checksum of the driver file. - **DriverCompany** The company name that developed the driver. - **DriverInBox** Is the driver included with the operating system? @@ -3995,15 +3994,12 @@ The following fields are available: - **DriverType** A bitfield of driver attributes: 1. define DRIVER_MAP_DRIVER_TYPE_PRINTER 0x0001. 2. define DRIVER_MAP_DRIVER_TYPE_KERNEL 0x0002. 3. define DRIVER_MAP_DRIVER_TYPE_USER 0x0004. 4. define DRIVER_MAP_DRIVER_IS_SIGNED 0x0008. 5. define DRIVER_MAP_DRIVER_IS_INBOX 0x0010. 6. define DRIVER_MAP_DRIVER_IS_WINQUAL 0x0040. 7. define DRIVER_MAP_DRIVER_IS_SELF_SIGNED 0x0020. 8. define DRIVER_MAP_DRIVER_IS_CI_SIGNED 0x0080. 9. define DRIVER_MAP_DRIVER_HAS_BOOT_SERVICE 0x0100. 10. define DRIVER_MAP_DRIVER_TYPE_I386 0x10000. 11. define DRIVER_MAP_DRIVER_TYPE_IA64 0x20000. 12. define DRIVER_MAP_DRIVER_TYPE_AMD64 0x40000. 13. define DRIVER_MAP_DRIVER_TYPE_ARM 0x100000. 14. define DRIVER_MAP_DRIVER_TYPE_THUMB 0x200000. 15. define DRIVER_MAP_DRIVER_TYPE_ARMNT 0x400000. 16. define DRIVER_MAP_DRIVER_IS_TIME_STAMPED 0x800000. - **DriverVersion** The version of the driver file. - **ImageSize** The size of the driver file. -- **ImageSmze** No content is currently available. - **Inf** The name of the INF file. - **InventoryVersion** The version of the inventory file generating the events. - **Product** The product name that is included in the driver file. - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. - **WdfVersion** The Windows Driver Framework version. -- **WdfVers-on** No content is currently available. -- **WdfVersÿon** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove @@ -4254,7 +4250,6 @@ The following fields are available: - **OfficeApplication** The name of the Office application. - **OfficeArchitecture** The bitness of the Office application. - **OfficeVersion** The version of the Office application. -- **Valóe** No content is currently available. - **Value** The insights collected about this entity. @@ -4521,8 +4516,6 @@ OS information collected during Boot, used to evaluate the success of the upgrad The following fields are available: -- **Boo|ApplicationId** No content is currently available. -- **BootApplicataonId** No content is currently available. - **BootApplicationId** This field tells us what the OS Loader Application Identifier is. - **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. - **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. @@ -4704,9 +4697,7 @@ This event sends information describing the result of the update. The following fields are available: -- **br** No content is currently available. - **hr** The HResult of the operation. -- **IsLoggingE~abled** No content is currently available. - **IsLoggingEnabled** Indicates whether logging is enabled for the updater. - **UpdaterVersion** The version of the updater. @@ -4733,14 +4724,13 @@ The following fields are available: ### Microsoft.Windows.MigrationCore.MigObjectCountKFSys -No content is currently available. +This event returns data about the count of the migration objects across various phases during feature update. The following fields are available: -- **knownFolderLoc->DirName->CString** No content is currently available. -- **knownFoldersSys[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. +- **knownFoldersSys[i]** The predefined folder path locations. +- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. +- **objectCount** The count of the number of objects that are being transferred. ## Privacy consent logging events @@ -4787,6 +4777,7 @@ The following fields are available: - **fileName** The file name where the failure occurred. - **function** The function where the failure occurred. - **hresult** The HResult of the overall activity. +- **hrutTyp** No content is currently available. - **lineNumber** The line number where the failure occurred. - **message** The message of the failure that occurred. - **module** The module where the failure occurred. @@ -4907,7 +4898,6 @@ The following fields are available: - **DeviceModel** What is the device model. - **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. - **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. -- **DriverGxclusionPolicy** No content is currently available. - **DriverSyncPassPerformed** Were drivers scanned this time? - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. @@ -4917,24 +4907,19 @@ The following fields are available: - **FailedUpdatesCount** The number of updates that failed to be evaluated during the scan. - **FeatureUpdateDeferral** The deferral period configured for feature OS updates on the device (in days). - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. -- **FeatureUpdatePause9-8iod** No content is currently available. - **FeatureUpdatePausePeriod** The pause duration configured for feature OS updates on the device (in days). - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. -- **I#Version** No content is currently available. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. -- **IsWUfBDualScaninabled** No content is currently available. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. -- **IsWUfBinabled** No content is currently available. - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete -- **NumberOfApplicationsCategoryScanEval}ated** No content is currently available. - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan @@ -4950,14 +4935,10 @@ The following fields are available: - **ProcessName** The process name of the caller who initiated API calls, in the event where CallerApplicationName was not provided. - **QualityUpdateDeferral** The deferral period configured for quality OS updates on the device (in days). - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. -- **QualityUpdatePause9-8iod** No content is currently available. - **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one -- **S}ncType** No content is currently available. -- **ScanDuratioInSeconds** No content is currently available. - **ScanDurationInSeconds** The number of seconds a scan took - **ScanEnqueueTime** The number of seconds it took to initialize a scan -- **ScanPrps** No content is currently available. - **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). - **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). - **ServiceUrl** The environment URL a device is configured to scan with @@ -4967,7 +4948,6 @@ The following fields are available: - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. -- **TotalNumMetadataSignatureM** No content is currently available. - **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. - **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5015,8 +4995,6 @@ The following fields are available: - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. -- **aundleBy1esDownl?aded** No content is currently available. -- **B1ndleRepeatFailCount** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5031,7 +5009,6 @@ The following fields are available: - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **Cbs5ethod** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. @@ -5045,13 +5022,11 @@ The following fields are available: - **DownloadProps** Information about the download operation properties in the form of a bitmask. - **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. - **EventInstanceID** A globally unique identifier for event instance. -- **EventScenarao** No content is currently available. - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. - **EventType** Identifies the type of the event (Child, Bundle, or Driver). - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **flightBuildNumber** No content is currently available. - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -5063,8 +5038,6 @@ The following fields are available: - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWVfBDualScanEnabled** No content is currently available. -- **IsWVfBEnabled** No content is currently available. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." @@ -5075,10 +5048,8 @@ The following fields are available: - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. - **RegulationReason** The reason that the update is regulated -- **RegulationReóult** No content is currently available. - **RegulationResult** The result code (HResult) of the last attempt to contact the regulation web service for download regulation of update content. - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. -- **RelqtedCV** No content is currently available. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. - **RevisionNumber** The revision number of the specified piece of content. @@ -5094,16 +5065,13 @@ The following fields are available: - **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. - **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. - **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalEx8ectedBydes** No content is currently available. - **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. - **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UsecDO** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. -- **YsWUfBEnabled** No content is currently available. ### SoftwareUpdateClientTelemetry.DownloadCheckpoint @@ -5223,7 +5191,6 @@ The following fields are available: - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. -- **Targeti~gVersion** No content is currently available. - **TargetingVersion** For drivers targeted to a specific device model, this is the version number of the drivers being distributed to the device. - **TransactionCode** The ID that represents a given MSI installation. - **UpdateId** Unique update ID. @@ -5347,7 +5314,6 @@ The following fields are available: - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **NumberOfA0plicableUpdates** No content is currently available. - **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. - **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). @@ -5465,7 +5431,6 @@ The following fields are available: - **InternalFailureResult** Indicates a non-fatal error from a plugin. - **ObjectId** Unique value for each Update Agent mode (same concept as InstanceId for Setup360). - **PackageCategoriesSkipped** Indicates package categories that were skipped, if applicable. -- **PackageCCoegoriesSkipped** No content is currently available. - **PackageCountOptional** Number of optional packages requested. - **PackageCountRequired** Number of required packages requested. - **PackageCountTotal** Total number of packages needed. @@ -5478,7 +5443,6 @@ The following fields are available: - **PackageSizeDiff** Size of diff packages in bytes. - **PackageSizeExpress** Size of express packages in bytes. - **PackageSizePSFX** The size of PSFX packages, in bytes. -- **RangeRequestSsCoe** No content is currently available. - **RangeRequestState** Indicates the range request type used. - **RelatedCV** Correlation vector value generated from the latest USO scan. - **Result** Outcome of the download request phase of update. @@ -6337,7 +6301,6 @@ This event is sent after a scan for product updates to determine if there are pa The following fields are available: -- **AsOnline** No content is currently available. - **ClientAppId** The identity of the app that initiated this operation. - **HResult** The result code of the last action performed. - **IsApplicability** Is this request to only check if there are any applicable packages to install? @@ -6624,7 +6587,6 @@ The following fields are available: - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. - **bytesRequested** The total number of bytes requested for download. -- **cacheServerBonnectionCount** No content is currently available. - **cacheServerConnectionCount** Number of connections made to cache hosts. - **cdnConnectionCount** The total number of connections made to the CDN. - **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. @@ -6632,7 +6594,6 @@ The following fields are available: - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dnErrorCounts** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). @@ -6644,9 +6605,7 @@ The following fields are available: - **fileID** The ID of the file being downloaded. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. -- **gdnConnectionCount** No content is currently available. - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. -- **groupConnectionCo** No content is currently available. - **groupConnectionCount** The total number of connections made to peers in the same group. - **internetConnectionCount** The total number of connections made to peers not in the same LAN or the same group. - **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. @@ -6657,7 +6616,6 @@ The following fields are available: - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. - **predefinedCallerName** The name of the API Caller. -- **restrictedU`load** No content is currently available. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. - **sessionID** The ID of the download session. @@ -7415,7 +7373,6 @@ This event sends data on whether Update Management Policies were enabled on a de The following fields are available: - **configuredPoliciescount** Number of policies on the device. -- **configuredPoliciescsunt** No content is currently available. - **policiesNamevaluesource** Policy name and source of policy (group policy, MDM or flight). - **policyCacherefreshtime** Time when policy cache was refreshed. - **updateInstalluxsetting** Indicates whether a user has set policies via a user experience option. From ce42be5de8a47a7fd35fe6b79beadfe982105351 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 1 Apr 2019 16:27:21 -0700 Subject: [PATCH 097/737] new build 4/1/2019 4:27 PM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index f91d4a0548..c9df4f0d71 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/29/2019 +ms.date: 04/01/2019 --- From 8bd56a341549d1dfc1dfb68f7417069c1e7fa366 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 1 Apr 2019 16:27:28 -0700 Subject: [PATCH 098/737] new build 4/1/2019 4:27 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 34 +++++++++++++++---- 4 files changed, 30 insertions(+), 10 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index b5c2cbf517..1d21304909 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/29/2019 +ms.date: 04/01/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 800377e966..e06f5187b6 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/29/2019 +ms.date: 04/01/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index e22d5344bb..0606766261 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/29/2019 +ms.date: 04/01/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 6c3abb47aa..25ff1cd99e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 03/29/2019 +ms.date: 04/01/2019 --- @@ -346,6 +346,7 @@ The following fields are available: - **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. +- **DataSourceMatchIngInfoBlock_19H1** No content is currently available. - **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. - **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. @@ -2760,13 +2761,20 @@ The following fields are available: - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. +- **CriticalDt2eDbDroppedCount** No content is currently available. +- **CriticalDt2eThrottleDroppedCount** No content is currently available. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. +- **CrrancalDataDbDroppedCount** No content is currently available. +- **CrrancalDataThrottleDroppedCount** No content is currently available. +- **CrrancalOverflowEntersCounter** No content is currently available. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. +- **DbCrrancalDroppedCount** No content is currently available. - **DbDroppedCount** Number of events dropped due to DB fullness. - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EnteringCrrancalOverflowDroppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2796,6 +2804,8 @@ The following fields are available: - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. +- **VortexHttpeReponseFailures** No content is currently available. +- **VortexHttpeReponsesWithDroppedEvents** No content is currently available. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. @@ -3409,6 +3419,7 @@ The following fields are available: - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). +- **DedicatedVidmoMemoryB** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. @@ -3435,6 +3446,7 @@ The following fields are available: - **IsRemovable** TRUE if the adapter supports being disabled or removed. - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? +- **KMDF** No content is currently available. - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. @@ -3445,6 +3457,7 @@ The following fields are available: - **SubVendorID** The GPU sub vendor ID. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TmlemetryEnabled** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. @@ -3552,6 +3565,7 @@ The following fields are available: - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported +- **TargetAppVr** No content is currently available. - **TargetAsId** The sequence number for the hanging process. @@ -4000,6 +4014,7 @@ The following fields are available: - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. - **WdfVersion** The Windows Driver Framework version. +- **YmageSize** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove @@ -4777,6 +4792,7 @@ The following fields are available: - **fileName** The file name where the failure occurred. - **function** The function where the failure occurred. - **hresult** The HResult of the overall activity. +- **hresult€threadId** No content is currently available. - **hrutTyp** No content is currently available. - **lineNumber** The line number where the failure occurred. - **message** The message of the failure that occurred. @@ -4938,6 +4954,8 @@ The following fields are available: - **QualityUpdatePausePeriod** The pause duration configured for quality OS updates on the device (in days). - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one - **ScanDurationInSeconds** The number of seconds a scan took +- **ScanDurationInSeuonds** No content is currently available. +- **ScanEnque}eTime** No content is currently available. - **ScanEnqueueTime** The number of seconds it took to initialize a scan - **ScanProps** This is a 32-bit integer containing Boolean properties for a given Windows Update scan. The following bits are used; all remaining bits are reserved and set to zero. Bit 0 (0x1): IsInteractive - is set to 1 if the scan is requested by a user, or 0 if the scan is requested by Automatic Updates. Bit 1 (0x2): IsSeeker - is set to 1 if the Windows Update client's Seeker functionality is enabled. Seeker functionality is enabled on certain interactive scans, and results in the scans returning certain updates that are in the initial stages of release (not yet released for full adoption via Automatic Updates). - **ServiceGuid** An ID which represents which service the software distribution client is checking for content (Windows Update, Microsoft Store, etc.). @@ -4995,6 +5013,7 @@ The following fields are available: - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. +- **AppXU3s8aHashFailures** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5028,6 +5047,7 @@ The following fields are available: - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. +- **FlighTBuildNumber** No content is currently available. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). - **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). @@ -5069,6 +5089,7 @@ The following fields are available: - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. - **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. +- **UpdatEImportance** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5132,6 +5153,7 @@ This event sends tracking data about the software distribution client installati The following fields are available: +- **2À@=2§3F'™+ck** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5152,11 +5174,13 @@ The following fields are available: - **DeviceModel** The device model. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. +- **DriverReuoveryIds** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. - **ExtendedErrorCode** The extended error code. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. +- **ExtendEdStatusCode** No content is currently available. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. - **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. @@ -6594,6 +6618,7 @@ The following fields are available: - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dataSourcEsTotal** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). @@ -6603,6 +6628,7 @@ The following fields are available: - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. - **expiresAt** The time when the content will expire from the Delivery Optimization Cache. - **fileID** The ID of the file being downloaded. +- **fileSaze** No content is currently available. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. @@ -6652,7 +6678,6 @@ This event sends data describing the start of a new download to enable Delivery The following fields are available: -- **ActiveNetworkConnection** No content is currently available. - **background** Indicates whether the download is happening in the background. - **bytesRequested** Number of bytes requested for the download. - **cdnUrl** The URL of the source Content Distribution Network (CDN). @@ -6671,21 +6696,16 @@ The following fields are available: - **fileSize** Total file size of the file that was downloaded. - **fileSizeCaller** Value for total file size provided by our caller. - **groupID** ID for the group. -- **IsBootCritical** No content is currently available. - **isEncrypted** Indicates whether the download is encrypted. - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. - **peerID** The ID for this delivery optimization client. - **predefinedCallerName** Name of the API caller. - **routeToCacheServer** Cache server setting, source, and value. -- **SdbEntries** No content is currently available. - **sessionID** The ID for the file download session. - **setConfigs** A JSON representation of the configurations that have been set, and their sources. - **updateID** The ID of the update being downloaded. - **usedMemoryStream** Indicates whether the download used memory streaming. -- **WuDriverCoverage** No content is currently available. -- **WuDriverUpdateId** No content is currently available. -- **WuPopulatedFromId** No content is currently available. ### Microsoft.OSG.DU.DeliveryOptClient.FailureCdnCommunication From bbf3529726f7e837cfefbf1f31d91297425677b2 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 2 Apr 2019 08:53:08 -0700 Subject: [PATCH 099/737] new build 4/2/2019 8:53 AM --- ...basic-level-windows-diagnostic-events-and-fields-1903.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index c9df4f0d71..b745b8fa81 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/01/2019 +ms.date: 04/02/2019 --- @@ -3130,8 +3130,8 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **Audio.CaptureDriver** No content is currently available. -- **Audio.RenderDriver** No content is currently available. +- **Audio.CaptureDriver** The capture driver endpoint for the audio device. +- **Audio.RenderDriver** The render driver for the audio device. - **Audio_CaptureDriver** The Audio device capture driver endpoint. - **Audio_RenderDriver** The Audio device render driver endpoint. - **InventoryVersion** The version of the inventory file generating the events. From a168f8af7f9af53e7dd874afa4e8fb05bde719cc Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 2 Apr 2019 08:53:13 -0700 Subject: [PATCH 100/737] new build 4/2/2019 8:53 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 125 +++++++++++++++++- 4 files changed, 125 insertions(+), 6 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 1d21304909..c7bbf928bd 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/01/2019 +ms.date: 04/02/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index e06f5187b6..72b3a95d4c 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/01/2019 +ms.date: 04/02/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 0606766261..48424772ba 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/01/2019 +ms.date: 04/02/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 25ff1cd99e..f86d9d6c9c 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/01/2019 +ms.date: 04/02/2019 --- @@ -1774,6 +1774,7 @@ The following fields are available: - **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. - **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. - **WmdrmPurchased** Indicates if the system has any files with permanent licenses. +- **聗mdrmNonPermanent** No content is currently available. ### Microsoft.Windows.Appraiser.General.WmdrmRemove @@ -1960,7 +1961,9 @@ The following fields are available: - **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. - **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. - **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. +- **Mobi�eOperatorNetwork1** No content is currently available. - **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. +- **MobileOperatorCommercia�ized** No content is currently available. - **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. - **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. - **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. @@ -2719,7 +2722,9 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: +- **CanAddMsagoMsTelemetry** No content is currently available. - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. +- **CanCollactAnyTelemetry** No content is currently available. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. @@ -2727,7 +2732,9 @@ The following fields are available: - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. +- **CanPerfotmDiagnosticEscalations** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. +- **Can䁃ollectCoreTelemetry** No content is currently available. - **PreviousPermissions** Bitmask of previous telemetry state. - **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. @@ -2742,6 +2749,7 @@ The following fields are available: - **CensusStartTime** Returns timestamp corresponding to last successful census run. - **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. - **LastConnectivityLossTime** Retrieves the last time the device lost free network. +- **LastGonnectivityLossTime** No content is currently available. - **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. - **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. - **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. @@ -2754,9 +2762,18 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **AggregationFlags** No content is currently available. +- **AggregationPeriodMS** No content is currently available. +- **AudioInMS** No content is currently available. +- **AudioOutMS** No content is currently available. +- **BackgroundMouseSec** No content is currently available. +- **BitPeriodMS** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. +- **CompositionDirtyGeneratedSec** No content is currently available. +- **CompositionDirtyPropagatedSec** No content is currently available. +- **CompositionRenderedSec** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. @@ -2773,43 +2790,72 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. +- **Decoding刁刁刁刁刁刁刁刁刁刁刁刁** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EnteringCrrancalOverflowDroppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. +- **EtwDroppedBuffertorFlags** No content is currently available. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. +- **Eve~tStoreResetSizeSum** No content is currently available. +- **EventSequence** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. - **EventStoreResetCounter** Number of times event DB was reset. - **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. +- **EventStOreResetSizeSum** No content is currently available. - **EventSubStoreResetCounter** Number of times event DB was reset. - **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. - **EventsUploaded** Number of events uploaded. - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. +- **FullTriggerBuvferDroppedCount** No content is currently available. +- **GameInputSec** No content is currently available. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. +- **InteractiveTimeoutPeriodMS** No content is currently available. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **InvalidHttpCodECount** No content is currently available. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. +- **MaxIn]seScenarioCounter** No content is currently available. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **MaxInUseScenarioCountev** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **Repe`tedUploadFailureDropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **SettingsHttpAtsempts** No content is currently available. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **SinceFirstInteractivityMS** No content is currently available. +- **SpeechRecognitionSec** No content is currently available. +- **SummaryRound** No content is currently available. +- **TargetAsId** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. +- **ViewFlags** No content is currently available. +- **VodtexFailuresTimeout** No content is currently available. +- **VodtexHttpAttempts** No content is currently available. +- **VodtexHttpFailures4xx** No content is currently available. +- **VodtexHttpFailures5xx** No content is currently available. +- **VodtexHttpResponseFailures** No content is currently available. +- **VodtexHttpResponsesWithDroppedEvents** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. +- **VortexHttpAtsempts** No content is currently available. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpeReponseFailures** No content is currently available. - **VortexHttpeReponsesWithDroppedEvents** No content is currently available. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. +- **VortexHttpFailures5xz** No content is currently available. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **VortexHttpResponsesWythDroppedEvents** No content is currently available. +- **WindowFlags** No content is currently available. +- **刁刁刁刁刁merDroppedCoᕵnt** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -3414,12 +3460,17 @@ The following fields are available: - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiSeqId** The event sequence ID. +- **bootAd** No content is currently available. - **bootId** The system boot ID. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **CompupePreemptionLevel** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **ComputePreeMptionLevel** No content is currently available. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedViddoMemoryB** No content is currently available. - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DedicatedVidmoMemoryB** No content is currently available. +- **DedicatedVifeoMemoryB** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. @@ -3432,6 +3483,7 @@ The following fields are available: - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPUVendorID** The GPU vendor ID. +- **IntarfaceId** No content is currently available. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. @@ -3440,6 +3492,7 @@ The following fields are available: - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMismat-hLDA** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? @@ -3448,6 +3501,7 @@ The following fields are available: - **IsSoftwareDevice** Is this a software implementation of the GPU? - **KMDF** No content is currently available. - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. +- **MeasureEnablad** No content is currently available. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. - **NumVidPnSources** The number of supported display output sources. @@ -3457,6 +3511,7 @@ The following fields are available: - **SubVendorID** The GPU sub vendor ID. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TelINvEvntTrigger** No content is currently available. - **TmlemetryEnabled** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. @@ -3546,27 +3601,39 @@ This event sends data about crashes for both native and managed applications, to The following fields are available: - **AppName** The name of the app that has crashed. +- **AppSassionGuid** No content is currently available. +- **AppSessionGqid** No content is currently available. - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. +- **AppTimestamp** No content is currently available. - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. +- **ExcaptionCode** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). +- **ModTimaStamp** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. +- **ModVarsion** No content is currently available. - **ModVersion** The version of the module that has crashed. +- **PackageFullNama** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. +- **ProcessArinetecture** No content is currently available. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **TargepAsId** No content is currently available. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported - **TargetAppVr** No content is currently available. - **TargetAsId** The sequence number for the hanging process. +- **TarSetAppId** No content is currently available. +- **TarSetAppVer** No content is currently available. +- **TarSetAsId** No content is currently available. ## Feature update events @@ -3684,6 +3751,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: +- **HiddenAr`** No content is currently available. - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 @@ -3692,12 +3760,15 @@ The following fields are available: - **InventoryVersion** The version of the inventory file generating the events. - **Language** The language code of the program. - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiPqckageCode** No content is currently available. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. +- **OSVersionAtI~stallTi}e** No content is currently available. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. - **PackageFullName** The package full name for a Store application. - **ProgramInstanceId** A hash of the file IDs in an app. - **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RootDibPath** No content is currently available. - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. @@ -3906,6 +3977,8 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: +- **** No content is currently available. +- **€** No content is currently available. - **BusReportedDescription** The description of the device reported by the bux. - **Class** The device setup class of the driver loaded for the device. - **ClassGuid** The device class unique identifier of the driver package loaded on the device. @@ -3919,6 +3992,8 @@ The following fields are available: - **DriverId** The unique identifier for the installed driver. - **DriverName** The name of the driver image file. - **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. +- **DriverPackageStrongName** No content is currently available. +- **DriverV** No content is currently available. - **DriverVerDate** The date associated with the driver installed on the device. - **DriverVerVersion** The version number of the driver installed on the device. - **Enumerator** Identifies the bus that enumerated the device. @@ -4538,12 +4613,15 @@ The following fields are available: - **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). - **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. - **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. +- **FirmwareresetReasonEmbeddedControllerAdditional** No content is currently available. - **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. - **FirmwareResetReasonPch** Reason for system reset provided by firmware. - **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. +- **FirmwareResetReasonPchADditional** No content is currently available. - **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. - **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). - **LastBootSucceeded** Flag indicating whether the last boot was successful. +- **LastBootSucceedEd** No content is currently available. - **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. - **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. - **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. @@ -4792,8 +4870,6 @@ The following fields are available: - **fileName** The file name where the failure occurred. - **function** The function where the failure occurred. - **hresult** The HResult of the overall activity. -- **hresult€threadId** No content is currently available. -- **hrutTyp** No content is currently available. - **lineNumber** The line number where the failure occurred. - **message** The message of the failure that occurred. - **module** The module where the failure occurred. @@ -4877,8 +4953,10 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: +- **CroupName** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **Valqe** No content is currently available. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -4890,6 +4968,8 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: +- **Ä7G§ Date: Wed, 3 Apr 2019 08:16:17 -0700 Subject: [PATCH 101/737] new build 4/3/2019 8:16 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 98 +++++++++---------- 1 file changed, 49 insertions(+), 49 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index b745b8fa81..e28e119c2b 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/02/2019 +ms.date: 04/03/2019 --- @@ -3780,7 +3780,7 @@ The following fields are available: - **ClassGuid** The unique ID for the device class. - **DeviceInstanceId** The unique ID for the device on the system. -- **DriverDate** The date the driver was installed. +- **DriverDate** The date of the driver. - **DriverFlightIds** The IDs for the driver flights. - **DriverInfName** Driver INF file name. - **DriverProvider** The driver manufacturer or provider. @@ -3969,7 +3969,7 @@ The following fields are available: ### Microsoft.Windows.DriverInstall.DeviceInstall -This critical event sends device instance properties for the driver installation that took place. +This critical event sends information about the driver installation that took place. The following fields are available: @@ -3981,59 +3981,59 @@ The following fields are available: - **DeviceConfigured** Indicates whether this device was configured through the kernel configuration. - **DeviceInstanceId** The unique identifier of the device in the system. - **DeviceStack** The device stack of the driver being installed. -- **DriverDate** No content is currently available. -- **DriverDescription** No content is currently available. -- **DriverInfName** No content is currently available. -- **DriverInfSectionName** No content is currently available. -- **DriverPackageId** No content is currently available. -- **DriverProvider** No content is currently available. -- **DriverUpdated** No content is currently available. -- **DriverVersion** No content is currently available. -- **EndTime** No content is currently available. -- **Error** No content is currently available. -- **ExtensionDrivers** No content is currently available. -- **FinishInstallAction** No content is currently available. -- **FinishInstallUI** No content is currently available. -- **FirmwareDate** No content is currently available. -- **FirmwareRevision** No content is currently available. -- **FirmwareVersion** No content is currently available. -- **FirstHardwareId** No content is currently available. -- **FlightIds** No content is currently available. -- **GenericDriver** No content is currently available. -- **Inbox** No content is currently available. -- **InstallDate** No content is currently available. -- **LastCompatibleId** No content is currently available. -- **LegacyInstallReasonError** No content is currently available. -- **LowerFilters** No content is currently available. -- **MatchingDeviceId** No content is currently available. -- **NeedReboot** No content is currently available. -- **OriginalDriverInfName** No content is currently available. -- **ParentDeviceInstanceId** No content is currently available. -- **PendedUntilReboot** No content is currently available. -- **Problem** No content is currently available. -- **ProblemStatus** No content is currently available. -- **SecondaryDevice** No content is currently available. -- **ServiceName** No content is currently available. -- **SetupMode** No content is currently available. -- **StartTime** No content is currently available. -- **SubmissionId** No content is currently available. -- **UpperFilters** No content is currently available. +- **DriverDate** The date of the driver. +- **DriverDescription** A description of the driver function. +- **DriverInfName** Name of the INF file (the setup information file) for the driver. +- **DriverInfSectionName** Name of the DDInstall section within the driver INF file. +- **DriverPackageId** The ID of the driver package that is staged to the driver store. +- **DriverProvider** The driver manufacturer or provider. +- **DriverUpdated** Indicates whether the driver is replacing an old driver. +- **DriverVersion** The version of the driver file. +- **EndTime** The time the installation completed. +- **Error** Provides the WIN32 error code for the installation. +- **ExtensionDrivers** List of extension drivers that complement this installation. +- **FinishInstallAction** Indicates whether the co-installer invoked the finish-install action. +- **FinishInstallUI** Indicates whether the installation process shows the user interface. +- **FirmwareDate** The firmware date that will be stored in the EFI System Resource Table (ESRT). +- **FirmwareRevision** The firmware revision that will be stored in the EFI System Resource Table (ESRT). +- **FirmwareVersion** The firmware version that will be stored in the EFI System Resource Table (ESRT). +- **FirstHardwareId** The ID in the hardware ID list that provides the most specific device description. +- **FlightIds** A list of the different Windows Insider builds on the device. +- **GenericDriver** Indicates whether the driver is a generic driver. +- **Inbox** Indicates whether the driver package is included with Windows. +- **InstallDate** The date the driver was installed. +- **LastCompatibleId** The ID in the hardware ID list that provides the least specific device description. +- **LegacyInstallReasonError** The error code for the legacy installation. +- **LowerFilters** The list of lower filter drivers. +- **MatchingDeviceId** The hardware ID or compatible ID that Windows used to install the device instance. +- **NeedReboot** Indicates whether the driver requires a reboot. +- **OriginalDriverInfName** The original name of the INF file before it was renamed. +- **ParentDeviceInstanceId** The device instance ID of the parent of the device. +- **PendedUntilReboot** Indicates whether the installation is pending until the device is rebooted. +- **Problem** Error code returned by the device after installation. +- **ProblemStatus** The status of the device after the driver installation. +- **SecondaryDevice** Indicates whether the device is a secondary device. +- **ServiceName** The service name of the driver. +- **SetupMode** Indicates whether the driver installation took place before the initial installation of the device was completed. +- **StartTime** The time when the installation started. +- **SubmissionId** The driver submission identifier assigned by the Windows Hardware Development Center. +- **UpperFilters** The list of upper filter drivers. ### Microsoft.Windows.DriverInstall.NewDevInstallDeviceEnd -No content is currently available. +This event sends data about the driver installation once it is completed. The following fields are available: -- **DeviceInstanceId** No content is currently available. -- **DriverUpdated** No content is currently available. -- **Error** No content is currently available. -- **FlightId** No content is currently available. -- **InstallDate** No content is currently available. -- **InstallFlags** No content is currently available. -- **RebootRequired** No content is currently available. -- **RollbackPossible** No content is currently available. +- **DeviceInstanceId** The unique identifier of the device in the system. +- **DriverUpdated** Indicates whether the driver was updated. +- **Error** The Win32 error code of the installation. +- **FlightId** The ID of the Windows Insider build the device received. +- **InstallDate** The date the driver was installed. +- **InstallFlags** The driver installation flags. +- **RebootRequired** Indicates whether a reboot is required after the installation. +- **RollbackPossible** Indicates whether this driver can be rolled back. - **WuTargetedHardwareId** No content is currently available. - **WuUntargetedHardwareId** No content is currently available. From c14180bb1ecd7810628c83071bb0ea541e4632fe Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 3 Apr 2019 08:16:25 -0700 Subject: [PATCH 102/737] new build 4/3/2019 8:16 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 102 +++++++----------- 4 files changed, 42 insertions(+), 66 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index c7bbf928bd..b1c005dbbe 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/02/2019 +ms.date: 04/03/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 72b3a95d4c..ab77c90805 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/02/2019 +ms.date: 04/03/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 48424772ba..db64dc298d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/02/2019 +ms.date: 04/03/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index f86d9d6c9c..f398e84056 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/02/2019 +ms.date: 04/03/2019 --- @@ -346,7 +346,6 @@ The following fields are available: - **DatasourceDriverPackage_TH2** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19ASetup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_19H1** The count of the number of this particular object type present on this device. -- **DataSourceMatchIngInfoBlock_19H1** No content is currently available. - **DataSourceMatchingInfoBlock_19H1Setup** The count of the number of this particular object type present on this device. - **DataSourceMatchingInfoBlock_RS1** The total DataSourceMatchingInfoBlock objects targeting Windows 10 version 1607 on this device. - **DataSourceMatchingInfoBlock_RS2** The count of the number of this particular object type present on this device. @@ -1742,6 +1741,8 @@ The following fields are available: - **PCFP** An ID for the system calculated by hashing hardware identifiers. - **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. - **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. +- **PerfBnDroff** No content is currently available. +- **PerfBnDroffInsurance** No content is currently available. - **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. - **RunDate** The date that the telemetry run was stated, expressed as a filetime. - **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. @@ -1807,6 +1808,7 @@ Provides information on IE and Census versions running on the device The following fields are available: +- **App�aiserRunEndTimeStamp** No content is currently available. - **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. - **AppraiserErrorCode** The error code of the last Appraiser run. - **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. @@ -1874,8 +1876,10 @@ This event sends data about the BIOS and startup embedded in the device, to help The following fields are available: +- **Firmware�anufacturer** No content is currently available. - **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). - **FirmwareReleaseDate** Represents the date the current firmware was released. +- **FirmwareRele�seDate** No content is currently available. - **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. - **FirmwareVersion** Represents the version of the current firmware. @@ -1888,6 +1892,7 @@ The following fields are available: - **DeviceSampleRate** The telemetry sample rate assigned to the device. - **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. +- **EnablePrevi�wBuilds** No content is currently available. - **FlightIds** A list of the different Windows Insider builds on this device. - **FlightingBranchName** The name of the Windows Insider branch currently used by the device. - **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. @@ -2251,6 +2256,7 @@ The following fields are available: - **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). - **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured - **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting +- **AppStoreAutoUpd�te** No content is currently available. - **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. - **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? - **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? @@ -2731,6 +2737,7 @@ The following fields are available: - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformiagnosticEscalations** No content is currently available. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. - **CanPerfotmDiagnosticEscalations** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. @@ -2776,56 +2783,43 @@ The following fields are available: - **CompositionRenderedSec** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. +- **CriticaDataThrottleDroppedCount** No content is currently available. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. -- **CriticalDt2eDbDroppedCount** No content is currently available. -- **CriticalDt2eThrottleDroppedCount** No content is currently available. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. -- **CrrancalDataDbDroppedCount** No content is currently available. -- **CrrancalDataThrottleDroppedCount** No content is currently available. -- **CrrancalOverflowEntersCounter** No content is currently available. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. -- **DbCrrancalDroppedCount** No content is currently available. - **DbDroppedCount** Number of events dropped due to DB fullness. - **DbDroppedFailureCount** Number of events dropped due to DB failures. - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. -- **Decoding刁刁刁刁刁刁刁刁刁刁刁刁** No content is currently available. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EnteringCrrancalOverflowDroppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedBuffertorFlags** No content is currently available. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **Eve~tStoreResetSizeSum** No content is currently available. - **EventSequence** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. +- **EventStoreLhfetimeResetCounter** No content is currently available. - **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. - **EventStoreResetCounter** Number of times event DB was reset. - **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. -- **EventStOreResetSizeSum** No content is currently available. - **EventSubStoreResetCounter** Number of times event DB was reset. - **EventSubStoreResetSizeSum** Total size of event DB across all resets reports in this instance. - **EventsUploaded** Number of events uploaded. - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **FullTriggerBuvferDroppedCount** No content is currently available. - **GameInputSec** No content is currently available. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InteractiveTimeoutPeriodMS** No content is currently available. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **InvalidHttpCodECount** No content is currently available. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. +- **LastInvalhdHttpCode** No content is currently available. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. -- **MaxIn]seScenarioCounter** No content is currently available. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **MaxInUseScenarioCountev** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **Repe`tedUploadFailureDropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **SettingsHttpAtsempts** No content is currently available. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. - **SinceFirstInteractivityMS** No content is currently available. @@ -2834,28 +2828,17 @@ The following fields are available: - **TargetAsId** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. +- **TopUploaderErross** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **ViewFlags** No content is currently available. -- **VodtexFailuresTimeout** No content is currently available. -- **VodtexHttpAttempts** No content is currently available. -- **VodtexHttpFailures4xx** No content is currently available. -- **VodtexHttpFailures5xx** No content is currently available. -- **VodtexHttpResponseFailures** No content is currently available. -- **VodtexHttpResponsesWithDroppedEvents** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. -- **VortexHttpAtsempts** No content is currently available. - **VortexHttpAttempts** Number of attempts to contact Vortex. -- **VortexHttpeReponseFailures** No content is currently available. -- **VortexHttpeReponsesWithDroppedEvents** No content is currently available. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. -- **VortexHttpFailures5xz** No content is currently available. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **VortexHttpResponsesWythDroppedEvents** No content is currently available. - **WindowFlags** No content is currently available. -- **刁刁刁刁刁merDroppedCoᕵnt** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -3460,21 +3443,19 @@ The following fields are available: - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiSeqId** The event sequence ID. -- **bootAd** No content is currently available. +- **B2ightnessVersionViaDDI** No content is currently available. - **bootId** The system boot ID. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **CompupePreemptionLevel** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **ComputePreeMptionLevel** No content is currently available. +- **Dedic`tedSystemMemoryB** No content is currently available. +- **DedicatedSystemMemorqB** No content is currently available. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedViddoMemoryB** No content is currently available. - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). -- **DedicatedVidmoMemoryB** No content is currently available. -- **DedicatedVifeoMemoryB** No content is currently available. - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. +- **DX10UM@FilePath** No content is currently available. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. @@ -3483,7 +3464,6 @@ The following fields are available: - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPUVendorID** The GPU vendor ID. -- **IntarfaceId** No content is currently available. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. @@ -3492,16 +3472,15 @@ The following fields are available: - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMismat-hLDA** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? - **IsRemovable** TRUE if the adapter supports being disabled or removed. +- **IsRenderDdvice** No content is currently available. - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? -- **KMDF** No content is currently available. - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeasureEnablad** No content is currently available. +- **MeastreEnabled** No content is currently available. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. - **NumVidPnSources** The number of supported display output sources. @@ -3511,8 +3490,7 @@ The following fields are available: - **SubVendorID** The GPU sub vendor ID. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **TelINvEvntTrigger** No content is currently available. -- **TmlemetryEnabled** No content is currently available. +- **Tel�nvEvntTrigger** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. @@ -3601,39 +3579,35 @@ This event sends data about crashes for both native and managed applications, to The following fields are available: - **AppName** The name of the app that has crashed. -- **AppSassionGuid** No content is currently available. - **AppSessionGqid** No content is currently available. +- **AppSessionGui`** No content is currently available. - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. -- **AppTimestamp** No content is currently available. - **AppTimeStamp** The date/time stamp of the app. +- **AppVarsion** No content is currently available. - **AppVersion** The version of the app that has crashed. -- **ExcaptionCode** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). -- **ModTimaStamp** No content is currently available. +- **ModPimeStamp** No content is currently available. +- **ModTimeSpamp** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. -- **ModVarsion** No content is currently available. - **ModVersion** The version of the module that has crashed. -- **PackageFullNama** No content is currently available. +- **PackaceRelativeAppId** No content is currently available. - **PackageFullName** Store application identity. +- **PackageRelativeAppHd** No content is currently available. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. -- **ProcessArinetecture** No content is currently available. - **ProcessCreateTime** The time of creation of the process that has crashed. +- **ProcessI`** No content is currently available. - **ProcessId** The ID of the process that has crashed. +- **ReportAd** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **TargepAsId** No content is currently available. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported -- **TargetAppVr** No content is currently available. - **TargetAsId** The sequence number for the hanging process. -- **TarSetAppId** No content is currently available. -- **TarSetAppVer** No content is currently available. -- **TarSetAsId** No content is currently available. ## Feature update events @@ -4089,7 +4063,6 @@ The following fields are available: - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. - **WdfVersion** The Windows Driver Framework version. -- **YmageSize** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDriverBinaryRemove @@ -4609,6 +4582,7 @@ The following fields are available: - **BootApplicationId** This field tells us what the OS Loader Application Identifier is. - **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. - **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. +- **BootSequenft** No content is currently available. - **BootStatusPolicy** Identifies the applicable Boot Status Policy. - **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). - **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. @@ -4968,8 +4942,9 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: -- **Ä7G§ Date: Thu, 4 Apr 2019 08:50:23 -0700 Subject: [PATCH 103/737] new build 4/4/2019 8:50 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 224 +++++++++--------- 1 file changed, 112 insertions(+), 112 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index e28e119c2b..a0330d713f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/03/2019 +ms.date: 04/04/2019 --- @@ -4040,24 +4040,24 @@ The following fields are available: ### Microsoft.Windows.DriverInstall.NewDevInstallDeviceStart -No content is currently available. +This event sends data about the driver that the new driver installation is replacing. The following fields are available: -- **DeviceInstanceId** No content is currently available. -- **FirstInstallDate** No content is currently available. -- **LastDriverDate** No content is currently available. -- **LastDriverInbox** No content is currently available. -- **LastDriverInfName** No content is currently available. -- **LastDriverVersion** No content is currently available. -- **LastFirmwareDate** No content is currently available. -- **LastFirmwareRevision** No content is currently available. -- **LastFirmwareVersion** No content is currently available. -- **LastInstallDate** No content is currently available. -- **LastMatchingDeviceId** No content is currently available. -- **LastProblem** No content is currently available. -- **LastProblemStatus** No content is currently available. -- **LastSubmissionId** No content is currently available. +- **DeviceInstanceId** The unique identifier of the device in the system. +- **FirstInstallDate** The first time a driver was installed on this device. +- **LastDriverDate** Date of the driver that is being replaced. +- **LastDriverInbox** Indicates whether the previous driver was included with Windows. +- **LastDriverInfName** Name of the INF file (the setup information file) of the driver being replaced. +- **LastDriverVersion** The version of the driver that is being replaced. +- **LastFirmwareDate** The date of the last firmware reported from the EFI System Resource Table (ESRT). +- **LastFirmwareRevision** The last firmware revision number reported from EFI System Resource Table (ESRT). +- **LastFirmwareVersion** The last firmware version reported from the EFI System Resource Table (ESRT). +- **LastInstallDate** The date a driver was last installed on this device. +- **LastMatchingDeviceId** The hardware ID or compatible ID that Windows last used to install the device instance. +- **LastProblem** The previous problem code that was set on the device. +- **LastProblemStatus** The previous problem code that was set on the device. +- **LastSubmissionId** The driver submission identifier of the driver that is being replaced. ### Microsoft.Windows.PBR.BitLockerWipeFinished @@ -4078,9 +4078,9 @@ This event sends data on the Windows Recovery Environment (WinRE) boot, which ca The following fields are available: -- **BsdSummaryInfo** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **BsdSummaryInfo** Summary of the last boot. +- **sessionID** The ID of the push-button reset session. +- **timestamp** The timestamp of the boot state. ### Microsoft.Windows.PBR.ClearTPMStarted @@ -4089,24 +4089,24 @@ This event sends basic data about the recovery operation on the device to allow The following fields are available: -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **sessionID** The ID for this push-button restart session. +- **timestamp** The time when the Trusted Platform Module will be erased. ### Microsoft.Windows.PBR.ClientInfo -No content is currently available. +This event indicates whether push-button reset (PBR) was initiated while the device was online or offline. The following fields are available: -- **name** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **name** Name of the user interface entry point. +- **sessionID** The ID of this push-button reset session. +- **timestamp** The time when this event occurred. ### Microsoft.Windows.PBR.Completed -No content is currently available. +This event sends data about the recovery operation on the device to allow for investigation. The following fields are available: @@ -4116,29 +4116,29 @@ The following fields are available: ### Microsoft.Windows.PBR.DataVolumeCount -No content is currently available. +This event provides the number of additional data volumes that the push-button reset operation has detected. The following fields are available: -- **count** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **count** The number of attached data drives. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Time the event occurred. ### Microsoft.Windows.PBR.DiskSpaceRequired -No content is currently available. +This event sends the peak disk usage required for the push-button reset operation. The following fields are available: -- **numBytes** No content is currently available. -- **sessionID** No content is currently available. -- **timestamp** No content is currently available. +- **numBytes** The number of bytes required for the reset operation. +- **sessionID** The ID of this push-button reset session. +- **timestamp** Time the event occurred. ### Microsoft.Windows.PBR.EnterAPI -No content is currently available. +This event is sent at the beginning of each push-button reset (PRB) operation. The following fields are available: @@ -4149,7 +4149,7 @@ The following fields are available: ### Microsoft.Windows.PBR.EnteredOOBE -No content is currently available. +This event is sent when the initial installation of the device starts after completion of the push-button reset operation. The following fields are available: @@ -4159,7 +4159,7 @@ The following fields are available: ### Microsoft.Windows.PBR.LeaveAPI -No content is currently available. +This event is sent when the push-button reset operation is complete. The following fields are available: @@ -4167,12 +4167,12 @@ The following fields are available: - **errorCode** Error code if an error occurred during the API call. - **sessionID** The ID of this push-button reset session. - **success** Indicates whether the API call was successful. -- **timestamp** No content is currently available. +- **timestamp** Timestamp of this push-button reset event. ### Microsoft.Windows.PBR.OEMExtensionFinished -No content is currently available. +This event is sent when the OEM extensibility scripts have completed. The following fields are available: @@ -4188,7 +4188,7 @@ The following fields are available: ### Microsoft.Windows.PBR.OEMExtensionStarted -No content is currently available. +This event is sent when the OEM extensibility scripts start to execute. The following fields are available: @@ -4201,7 +4201,7 @@ The following fields are available: ### Microsoft.Windows.PBR.OperationExecuteFinished -No content is currently available. +This event is sent at the end of a push-button reset (PBR) operation. The following fields are available: @@ -4216,7 +4216,7 @@ The following fields are available: ### Microsoft.Windows.PBR.OperationExecuteStarted -No content is currently available. +This event is sent at the beginning of a push-button reset operation. The following fields are available: @@ -4230,7 +4230,7 @@ The following fields are available: ### Microsoft.Windows.PBR.OperationQueueConstructFinished -No content is currently available. +This event is sent when construction of the operation queue for push-button reset is finished. The following fields are available: @@ -4242,7 +4242,7 @@ The following fields are available: ### Microsoft.Windows.PBR.OperationQueueConstructStarted -No content is currently available. +This event is sent when construction of the operation queue for push-button reset is started. The following fields are available: @@ -4252,7 +4252,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRClearRollBackEntry -No content is currently available. +This event is sent when the push-button reset operation clears the rollback entry. Push-button reset cannot rollback after this point. The following fields are available: @@ -4261,7 +4261,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRClearTPMFailed -No content is currently available. +This event is sent when there was a failure while clearing the Trusted Platform Module (TPM). The following fields are available: @@ -4270,7 +4270,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionFailed -No content is currently available. +This event is sent when the push-button reset operation fails to construct a new copy of the operating system. The following fields are available: @@ -4284,7 +4284,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRCreateNewSystemReconstructionSucceed -No content is currently available. +This event is sent when the push-button reset operation succeeds in constructing a new copy of the operating system. The following fields are available: @@ -4296,7 +4296,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRDriverInjectionFailed -No content is currently available. +This event is sent when the driver injection fails. The following fields are available: @@ -4305,7 +4305,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFailed -No content is currently available. +This event is sent when the push-button reset operation fails and rolls back to the previous state. The following fields are available: @@ -4316,7 +4316,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFinalizeNewSystemFailed -No content is currently available. +This event is sent when the push-button reset operation fails to finalize the new system. The following fields are available: @@ -4329,7 +4329,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFinalizeNewSystemSucceed -No content is currently available. +This event is sent when the push-button reset operation succeeds in finalizing the new system. The following fields are available: @@ -4338,7 +4338,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFinalUserSelection -No content is currently available. +This event is sent when the user makes the final selection in the user interface. The following fields are available: @@ -4352,7 +4352,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFormatOSVolumeFailed -No content is currently available. +This event is sent when the operation to format the operating system volume fails during push-button reset (PBR). The following fields are available: @@ -4362,17 +4362,17 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRFormatOSVolumeSucceed -No content is currently available. +This event is sent when the operation to format the operating system volume succeeds during push-button reset (PBR). The following fields are available: -- **JustDeleteFiles** No content is currently available. -- **SessionID** No content is currently available. +- **JustDeleteFiles** Indicates whether disk formatting was skipped. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRInstallWinREFailed -No content is currently available. +This event sends basic data about the recovery operation failure on the device to allow investigation. The following fields are available: @@ -4381,7 +4381,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRIOCTLErasureSucceed -No content is currently available. +This event is sent when the erasure operation succeeds during push-button reset (PBR). The following fields are available: @@ -4718,7 +4718,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SessionCreated -No content is currently available. +This event returns data when the PRB (Push Button Reset) session is created at the beginning of the UI (user interface) process. The following fields are available: @@ -4728,7 +4728,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SessionResumed -No content is currently available. +This event returns data when the PRB (Push Button Reset) session is resumed after reboots. The following fields are available: @@ -4738,7 +4738,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SessionSaved -No content is currently available. +This event returns data when the PRB (Push Button Reset) session is suspended between reboots. The following fields are available: @@ -4748,18 +4748,18 @@ The following fields are available: ### Microsoft.Windows.PBR.SetupExecuteFinished -No content is currently available. +This event returns data when the PBR (Push Button Reset) setup finishes. The following fields are available: -- **sessionID** No content is currently available. +- **sessionID** The ID of this push-button reset session. - **systemState** Information about the system state of the Setup Platform operation. - **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.SetupExecuteStarted -No content is currently available. +This event returns data when the PBR (Push Button Reset) setup starts. The following fields are available: @@ -4769,7 +4769,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SetupFinalizeStarted -No content is currently available. +This event returns data when the Finalize operation is completed by setup during PBR (Push Button Reset). The following fields are available: @@ -4779,7 +4779,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SetupOperationFailed -No content is currently available. +This event returns data when a PRB (Push Button Reset) setup operation fails. The following fields are available: @@ -4792,7 +4792,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SystemInfoField -No content is currently available. +This event returns data about the device when the user initiates the PBR UI (Push Button Reset User Interface), to ensure the appropriate reset options are shown to the user. The following fields are available: @@ -4804,7 +4804,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SystemInfoListItem -No content is currently available. +This event returns data about the device when the user initiates the PBR UI (Push Button Reset User Interface), to ensure the appropriate options can be shown to the user. The following fields are available: @@ -4817,7 +4817,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SystemInfoSenseFinished -No content is currently available. +This event returns data when System Info Sense is finished. The following fields are available: @@ -4829,7 +4829,7 @@ The following fields are available: ### Microsoft.Windows.PBR.SystemInfoSenseStarted -No content is currently available. +This event returns data when System Info Sense is started. The following fields are available: @@ -4839,7 +4839,7 @@ The following fields are available: ### Microsoft.Windows.PBR.UserAcknowledgeCleanupWarning -No content is currently available. +This event returns data when the user acknowledges the cleanup warning pop-up after PRB (Push Button Reset) is complete. The following fields are available: @@ -4849,7 +4849,7 @@ The following fields are available: ### Microsoft.Windows.PBR.UserCancel -No content is currently available. +This event returns data when the user confirms they wish to cancel PBR (Push Button Reset) from the user interface. The following fields are available: @@ -4860,7 +4860,7 @@ The following fields are available: ### Microsoft.Windows.PBR.UserConfirmStart -No content is currently available. +This event returns data when the user confirms they wish to reset their device and PBR (Push Button Reset) begins. The following fields are available: @@ -4870,7 +4870,7 @@ The following fields are available: ### Microsoft.Windows.PBR.WinREInstallFinished -No content is currently available. +This event returns data when WinRE (Windows Recovery) installation is complete. The following fields are available: @@ -4882,7 +4882,7 @@ The following fields are available: ### Microsoft.Windows.PBR.WinREInstallStarted -No content is currently available. +This event returns data when WinRE (Windows Recovery) installation starts. The following fields are available: @@ -4903,11 +4903,11 @@ The following fields are available: ### Microsoft.Windows.Security.WSC.GetCallerViaWdsp -No content is currently available. +This event returns data if the registering product EXE (executable file) does not allow COM (Component Object Model) impersonation. The following fields are available: -- **callerExe** No content is currently available. +- **callerExe** The registering product EXE that does not support COM impersonation. ### Microsoft.Windows.SysReset.FlightUninstallCancel @@ -4957,7 +4957,7 @@ This event is sent when users have actions that will block the uninstall of the ### Microsoft.Windows.SysReset.IndicateLCUWasUninstalled -No content is currently available. +This event is sent when the registry indicates that the latest cumulative Windows update package has finished uninstalling. The following fields are available: @@ -5049,30 +5049,30 @@ The following fields are available: ### Microsoft.Windows.UEFI.ESRT -No content is currently available. +This event sends basic data during boot about the firmware loaded or recently installed on the machine. This helps to keep Windows up to date. The following fields are available: -- **DriverFirmwareFilename** No content is currently available. -- **DriverFirmwarePolicy** No content is currently available. -- **DriverFirmwareStatus** No content is currently available. -- **DriverFirmwareVersion** No content is currently available. +- **DriverFirmwareFilename** The firmware file name reported by the device hardware key. +- **DriverFirmwarePolicy** The optional version update policy value. +- **DriverFirmwareStatus** The firmware status reported by the device hardware key. +- **DriverFirmwareVersion** The firmware version reported by the device hardware key. - **FirmareLastAttemptVersion** No content is currently available. -- **FirmwareId** No content is currently available. -- **FirmwareLastAttemptStatus** No content is currently available. -- **FirmwareLastAttemptVersion** No content is currently available. -- **FirmwareType** No content is currently available. -- **FirmwareVersion** No content is currently available. -- **InitiateUpdate** No content is currently available. -- **LastAttemptDate** No content is currently available. -- **LastAttemptStatus** No content is currently available. -- **LastAttemptVersion** No content is currently available. -- **LowestSupportedFirmwareVersion** No content is currently available. -- **MaxRetryCount** No content is currently available. -- **PartA_PrivTags** No content is currently available. -- **RetryCount** No content is currently available. -- **Status** No content is currently available. -- **UpdateAttempted** No content is currently available. +- **FirmwareId** The UEFI (Unified Extensible Firmware Interface) identifier. +- **FirmwareLastAttemptStatus** The reported status of the most recent firmware installation attempt, as reported by the EFI System Resource Table (ESRT). +- **FirmwareLastAttemptVersion** The version of the most recent attempted firmware installation, as reported by the EFI System Resource Table (ESRT). +- **FirmwareType** The UEFI (Unified Extensible Firmware Interface) type. +- **FirmwareVersion** The UEFI (Unified Extensible Firmware Interface) version as reported by the EFI System Resource Table (ESRT). +- **InitiateUpdate** Indicates whether the system is ready to initiate an update. +- **LastAttemptDate** The date of the most recent attempted firmware installation. +- **LastAttemptStatus** The result of the most recent attempted firmware installation. +- **LastAttemptVersion** The version of the most recent attempted firmware installation. +- **LowestSupportedFirmwareVersion** The oldest (lowest) version of firmware supported. +- **MaxRetryCount** The maximum number of retries, defined by the firmware class key. +- **PartA_PrivTags** The privacy tags associated with the firmware. +- **RetryCount** The number of attempted installations (retries), reported by the driver software key. +- **Status** The status returned to the PnP (Plug-and-Play) manager. +- **UpdateAttempted** Indicates if installation of the current update has been attempted before. ### Microsoft.Xbox.XamTelemetry.AppActivationError @@ -7197,22 +7197,22 @@ The following fields are available: ### Microsoft.Windows.Update.Orchestrator.DetectionActivity -No content is currently available. +This event returns data about detected updates, as well as the types of update (optional or recommended). This data helps keep Windows up to date. The following fields are available: -- **applicableUpdateIdList** No content is currently available. -- **applicableUpdateList** No content is currently available. -- **durationInSeconds** No content is currently available. -- **expeditedMode** No content is currently available. -- **networkCostPolicy** No content is currently available. -- **scanTriggerSource** No content is currently available. -- **scenario** No content is currently available. -- **scenarioReason** No content is currently available. -- **seekerUpdateIdList** No content is currently available. -- **seekerUpdateList** No content is currently available. -- **services** No content is currently available. -- **wilActivity** No content is currently available. See [wilActivity](#wilactivity). +- **applicableUpdateIdList** The list of update identifiers. +- **applicableUpdateList** The list of available updates. +- **durationInSeconds** The amount of time (in seconds) it took for the event to run. +- **expeditedMode** Indicates whether Expedited Mode is on. +- **networkCostPolicy** The network cost. +- **scanTriggerSource** Indicates whether the scan is Interactive or Background. +- **scenario** The result code of the event. +- **scenarioReason** The reason for the result code (scenario). +- **seekerUpdateIdList** The list of “seeker” update identifiers. +- **seekerUpdateList** The list of “seeker” updates. +- **services** The list of services that were called during update. +- **wilActivity** The activity results. See [wilActivity](#wilactivity). ### Microsoft.Windows.Update.Orchestrator.DisplayNeeded From 4da8a329980776d021f3e37abdaf4c16c2939a6c Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 4 Apr 2019 08:50:29 -0700 Subject: [PATCH 104/737] new build 4/4/2019 8:50 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 426 ++++++++++++++++-- 4 files changed, 401 insertions(+), 31 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index b1c005dbbe..c029cc311a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/03/2019 +ms.date: 04/04/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index ab77c90805..8fdeaa71a6 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/03/2019 +ms.date: 04/04/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index db64dc298d..f7b9ceb9f0 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/03/2019 +ms.date: 04/04/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index f398e84056..ee4dd734aa 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/03/2019 +ms.date: 04/04/2019 --- @@ -1775,7 +1775,6 @@ The following fields are available: - **WmdrmInUse** WmdrmIndicators AND dismissible block in setup was not dismissed. - **WmdrmNonPermanent** Indicates if the system has any files with non-permanent licenses. - **WmdrmPurchased** Indicates if the system has any files with permanent licenses. -- **聗mdrmNonPermanent** No content is currently available. ### Microsoft.Windows.Appraiser.General.WmdrmRemove @@ -1966,9 +1965,7 @@ The following fields are available: - **MEID** Represents the Mobile Equipment Identity (MEID). MEID is a worldwide unique phone ID assigned to CDMA phones. MEID replaces electronic serial number (ESN), and is equivalent to IMEI for GSM and WCDMA phones. Microsoft does not have access to mobile operator billing data so collecting this data does not expose or identify the user. - **MNC0** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. - **MNC1** Retrieves the Mobile Network Code (MNC). It used with the Mobile Country Code (MCC) to uniquely identify a mobile network operator. The two fields represent phone with dual sim coverage. -- **Mobi�eOperatorNetwork1** No content is currently available. - **MobileOperatorBilling** Represents the telephone company that provides services for mobile phone users. -- **MobileOperatorCommercia�ized** No content is currently available. - **MobileOperatorCommercialized** Represents which reseller and geography the phone is commercialized for. This is the set of values on the phone for who and where it was intended to be used. For example, the commercialized mobile operator code AT&T in the US would be ATT-US. - **MobileOperatorNetwork0** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. - **MobileOperatorNetwork1** Represents the operator of the current mobile network that the device is used on. (AT&T, T-Mobile, Vodafone). The two fields represent phone with dual sim coverage. @@ -2728,20 +2725,15 @@ Fired by UTC at startup to signal what data we are allowed to collect. The following fields are available: -- **CanAddMsagoMsTelemetry** No content is currently available. - **CanAddMsaToMsTelemetry** True if we can add MSA PUID and CID to telemetry, false otherwise. -- **CanCollactAnyTelemetry** No content is currently available. - **CanCollectAnyTelemetry** True if we are allowed to collect partner telemetry, false otherwise. - **CanCollectCoreTelemetry** True if we can collect CORE/Basic telemetry, false otherwise. - **CanCollectHeartbeats** True if we can collect heartbeat telemetry, false otherwise. - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformiagnosticEscalations** No content is currently available. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. -- **CanPerfotmDiagnosticEscalations** No content is currently available. - **CanReportScenarios** True if we can report scenario completions, false otherwise. -- **Can䁃ollectCoreTelemetry** No content is currently available. - **PreviousPermissions** Bitmask of previous telemetry state. - **TransitionFromEverythingOff** True if we are transitioning from all telemetry being disabled, false otherwise. @@ -2769,18 +2761,9 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **AggregationFlags** No content is currently available. -- **AggregationPeriodMS** No content is currently available. -- **AudioInMS** No content is currently available. -- **AudioOutMS** No content is currently available. -- **BackgroundMouseSec** No content is currently available. -- **BitPeriodMS** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. -- **CompositionDirtyGeneratedSec** No content is currently available. -- **CompositionDirtyPropagatedSec** No content is currently available. -- **CompositionRenderedSec** No content is currently available. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticaDataThrottleDroppedCount** No content is currently available. @@ -2794,9 +2777,7 @@ The following fields are available: - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. -- **EtwDroppedBuffertorFlags** No content is currently available. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. -- **EventSequence** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLhfetimeResetCounter** No content is currently available. - **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. @@ -2807,9 +2788,7 @@ The following fields are available: - **EventsUploaded** Number of events uploaded. - **Flags** Flags indicating device state such as network state, battery state, and opt-in state. - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. -- **GameInputSec** No content is currently available. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. -- **InteractiveTimeoutPeriodMS** No content is currently available. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. @@ -2822,23 +2801,17 @@ The following fields are available: - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **SinceFirstInteractivityMS** No content is currently available. -- **SpeechRecognitionSec** No content is currently available. -- **SummaryRound** No content is currently available. -- **TargetAsId** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. - **TopUploaderErross** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. -- **ViewFlags** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **WindowFlags** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -4800,6 +4773,403 @@ The following fields are available: - **objectCount** The count of the number of objects that are being transferred. +### Microsoft.Windows.Remediation.Applicable + +This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. + +The following fields are available: + +- **AllowAutoUpdateExists** No content is currently available. +- **AllowAutoUpdateProviderSetExists** No content is currently available. +- **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. +- **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. +- **AppraiserTaskRepairDisabled** No content is currently available. +- **AppraiserTaskValid** No content is currently available. +- **AUOptionsExists** No content is currently available. +- **CTACTargetingAttributesInvalid** No content is currently available. +- **CTACVersion** No content is currently available. +- **CV** Correlation vector +- **DataStoreSizeInBytes** No content is currently available. +- **DateTimeDifference** The difference between local and reference clock times. +- **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. +- **daysSinceInstallThreshold** No content is currently available. +- **daysSinceInstallValue** No content is currently available. +- **DaysSinceLastSIH** The number of days since the most recent SIH executed. +- **DaysToNextSIH** The number of days until the next scheduled SIH execution. +- **DetectConditionEnabled** No content is currently available. +- **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. +- **DetectionFailedReason** No content is currently available. +- **DiskFreeSpaceBeforeSedimentPackInMB** No content is currently available. +- **DiskSpaceBefore** No content is currently available. +- **EditionIdFixCorrupted** No content is currently available. +- **EscalationTimerResetFixResult** No content is currently available. +- **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. +- **FixedEditionId** No content is currently available. +- **FlightRebootTime** No content is currently available. +- **ForcedRebootToleranceDays** No content is currently available. +- **FreeSpaceRequirement** No content is currently available. +- **GlobalEventCounter** Client side counter that indicates ordering of events sent by the remediation system. +- **HResult** The HRESULT for detection or perform action phases of the plugin. +- **installDateValue** No content is currently available. +- **IsAppraiserLatestResult** The HRESULT from the appraiser task. +- **IsConfigurationCorrected** Indicates whether the configuration of SIH task was successfully corrected. +- **IsEscalationTimerResetFixNeeded** No content is currently available. +- **IsForcedModeEnabled** No content is currently available. +- **IsHomeSku** No content is currently available. +- **IsRebootForcedMode** No content is currently available. +- **IsServiceHardeningEnabled** No content is currently available. +- **IsServiceHardeningNeeded** No content is currently available. +- **isThreshold** No content is currently available. +- **IsUsoRebootPending** No content is currently available. +- **IsUsoRebootPendingInUpdateStore** No content is currently available. +- **IsUsoRebootTaskEnabled** No content is currently available. +- **IsUsoRebootTaskExists** No content is currently available. +- **IsUsoRebootTaskValid** No content is currently available. +- **LastHresult** The HRESULT for detection or perform action phases of the plugin. +- **LastRebootTaskRunResult** No content is currently available. +- **LastRebootTaskRunTime** No content is currently available. +- **LastRun** The date of the most recent SIH run. +- **LPCountBefore** No content is currently available. +- **NextCheck** No content is currently available. +- **NextRebootTaskRunTime** No content is currently available. +- **NextRun** Date of the next scheduled SIH run. +- **NoAutoUpdateExists** No content is currently available. +- **NumberOfDaysStuckInReboot** No content is currently available. +- **OriginalEditionId** No content is currently available. +- **PackageVersion** The version of the current remediation package. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **ProductType** No content is currently available. +- **QualityUpdateSedimentFunnelState** No content is currently available. +- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. +- **QualityUpdateSedimentLastRunSeconds** No content is currently available. +- **QualityUpdateSedimentLocalStartTime** No content is currently available. +- **QualityUpdateSedimentLocaltTime** No content is currently available. +- **QualityUpdateSedimentTargetedPlugins** No content is currently available. +- **QualityUpdateSedimentTargetedTriggers** No content is currently available. +- **RegkeysExist** No content is currently available. +- **Reload** True if SIH reload is required. +- **RemediationAutoUAAcLineStatus** No content is currently available. +- **RemediationAutoUAAutoStartCount** No content is currently available. +- **RemediationAutoUACalendarTaskEnabled** No content is currently available. +- **RemediationAutoUACalendarTaskExists** No content is currently available. +- **RemediationAutoUACalendarTaskTriggerEnabledCount** No content is currently available. +- **RemediationAutoUADaysSinceLastTaskRunTime** No content is currently available. +- **RemediationAutoUAGetCurrentSize** No content is currently available. +- **RemediationAutoUAIsInstalled** No content is currently available. +- **RemediationAutoUALastTaskRunResult** No content is currently available. +- **RemediationAutoUAMeteredNetwork** No content is currently available. +- **RemediationAutoUATaskEnabled** No content is currently available. +- **RemediationAutoUATaskExists** No content is currently available. +- **RemediationAutoUATasksStalled** No content is currently available. +- **RemediationAutoUATaskTriggerEnabledCount** No content is currently available. +- **RemediationAutoUAUAExitCode** No content is currently available. +- **RemediationAutoUAUAExitState** No content is currently available. +- **RemediationAutoUAUserLoggedIn** No content is currently available. +- **RemediationAutoUAUserLoggedInAdmin** No content is currently available. +- **RemediationCorruptionRepairBuildNumber** No content is currently available. +- **RemediationCorruptionRepairCorruptionsDetected** No content is currently available. +- **RemediationCorruptionRepairDetected** No content is currently available. +- **RemediationDeliverToastBuildNumber** No content is currently available. +- **RemediationDeliverToastDetected** No content is currently available. +- **RemediationDeliverToastDeviceExcludedNation** No content is currently available. +- **RemediationDeliverToastDeviceFreeSpaceInMB** No content is currently available. +- **RemediationDeliverToastDeviceHomeSku** No content is currently available. +- **RemediationDeliverToastDeviceIncludedNation** No content is currently available. +- **RemediationDeliverToastDeviceProSku** No content is currently available. +- **RemediationDeliverToastDeviceSystemDiskSizeInMB** No content is currently available. +- **RemediationDeliverToastGeoId** No content is currently available. +- **RemediationDeviceSkuId** No content is currently available. +- **RemediationGetCurrentFolderExist** No content is currently available. +- **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. +- **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. +- **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. +- **RemediationNoisyHammerCalendarTaskExists** Event that indicates an Update Assistant Calendar Task exists. +- **RemediationNoisyHammerCalendarTaskTriggerEnabledCount** Event that indicates calendar triggers are enabled in the task. +- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent hammer task ran. +- **RemediationNoisyHammerGetCurrentSize** Size in MB of the $GetCurrent folder. +- **RemediationNoisyHammerIsInstalled** TRUE if the noisy hammer is installed. +- **RemediationNoisyHammerLastTaskRunResult** The result of the last hammer task run. +- **RemediationNoisyHammerMeteredNetwork** TRUE if the machine is on a metered network. +- **RemediationNoisyHammerTaskEnabled** Indicates whether the Update Assistant Task (Noisy Hammer) is enabled. +- **RemediationNoisyHammerTaskExists** Indicates whether the Update Assistant Task (Noisy Hammer) exists. +- **RemediationNoisyHammerTasksStalled** No content is currently available. +- **RemediationNoisyHammerTaskTriggerEnabledCount** Indicates whether counting is enabled for the Update Assistant (Noisy Hammer) task trigger. +- **RemediationNoisyHammerUAExitCode** The exit code of the Update Assistant (Noisy Hammer) task. +- **RemediationNoisyHammerUAExitState** The code for the exit state of the Update Assistant (Noisy Hammer) task. +- **RemediationNoisyHammerUserLoggedIn** TRUE if there is a user logged in. +- **RemediationNoisyHammerUserLoggedInAdmin** TRUE if there is the user currently logged in is an Admin. +- **RemediationNotifyUserFixIssuesBoxStatusKey** No content is currently available. +- **RemediationNotifyUserFixIssuesBuildNumber** No content is currently available. +- **RemediationNotifyUserFixIssuesDetected** No content is currently available. +- **RemediationNotifyUserFixIssuesDiskSpace** No content is currently available. +- **RemediationNotifyUserFixIssuesFeatureUpdateBlocked** No content is currently available. +- **RemediationNotifyUserFixIssuesFeatureUpdateInProgress** No content is currently available. +- **RemediationNotifyUserFixIssuesIsUserAdmin** No content is currently available. +- **RemediationNotifyUserFixIssuesIsUserLoggedIn** No content is currently available. +- **RemediationProgramDataFolderSizeInMB** No content is currently available. +- **RemediationProgramFilesFolderSizeInMB** No content is currently available. +- **RemediationShellDeviceEducationSku** No content is currently available. +- **RemediationShellDeviceEnterpriseSku** No content is currently available. +- **RemediationShellDeviceFeatureUpdatesPaused** No content is currently available. +- **RemediationShellDeviceHomeSku** No content is currently available. +- **RemediationShellDeviceIsAllowedSku** No content is currently available. +- **RemediationShellDeviceManaged** TRUE if the device is WSUS managed or Windows Updated disabled. +- **RemediationShellDeviceNewOS** TRUE if the device has a recently installed OS. +- **RemediationShellDeviceProSku** No content is currently available. +- **RemediationShellDeviceQualityUpdatesPaused** No content is currently available. +- **RemediationShellDeviceSccm** TRUE if the device is managed by SCCM (Microsoft System Center Configuration Manager). +- **RemediationShellDeviceSetupMutexInUse** No content is currently available. +- **RemediationShellDeviceWuRegistryBlocked** No content is currently available. +- **RemediationShellDeviceZeroExhaust** TRUE if the device has opted out of Windows Updates completely. +- **RemediationTargetMachine** Indicates whether the device is a target of the specified fix. +- **RemediationTaskHealthAutochkProxy** True/False based on the health of the AutochkProxy task. +- **RemediationTaskHealthChkdskProactiveScan** True/False based on the health of the Check Disk task. +- **RemediationTaskHealthDiskCleanup_SilentCleanup** True/False based on the health of the Disk Cleanup task. +- **RemediationTaskHealthMaintenance_WinSAT** True/False based on the health of the Health Maintenance task. +- **RemediationTaskHealthServicing_ComponentCleanupTask** True/False based on the health of the Health Servicing Component task. +- **RemediationTaskHealthUSO_ScheduleScanTask** True/False based on the health of the USO (Update Session Orchestrator) Schedule task. +- **RemediationTaskHealthWindowsUpdate_ScheduledStartTask** True/False based on the health of the Windows Update Scheduled Start task. +- **RemediationTaskHealthWindowsUpdate_SihbootTask** True/False based on the health of the Sihboot task. +- **RemediationUHServiceDisabledBitMap** No content is currently available. +- **RemediationUHServiceNotExistBitMap** No content is currently available. +- **RemediationUsersFolderSizeInMB** No content is currently available. +- **RemediationWindows10UpgradeFolderExist** No content is currently available. +- **RemediationWindows10UpgradeFolderSizeInMB** No content is currently available. +- **RemediationWindowsAppsFolderSizeInMB** No content is currently available. +- **RemediationWindowsBtFolderSizeInMB** No content is currently available. +- **RemediationWindowsFolderSizeInMB** No content is currently available. +- **RemediationWindowsServiceProfilesFolderSizeInMB** No content is currently available. +- **Result** This is the HRESULT for Detection or Perform Action phases of the plugin. +- **RunTask** TRUE if SIH task should be run by the plug-in. +- **StorageSenseDiskCompresserEstimateInMB** No content is currently available. +- **StorageSenseHelloFaceRecognitionFodCleanupEstimateInByte** No content is currently available. +- **StorageSenseRestorePointCleanupEstimateInMB** No content is currently available. +- **StorageSenseUserDownloadFolderCleanupEstimateInByte** No content is currently available. +- **TimeServiceNTPServer** The URL for the NTP time server used by device. +- **TimeServiceStartType** The startup type for the NTP time service. +- **TimeServiceSyncDomainJoined** True if device domain joined and hence uses DC for clock. +- **TimeServiceSyncType** Type of sync behavior for Date & Time service on device. +- **uninstallActiveValue** No content is currently available. +- **UpdateApplicabilityFixerTriggerBitMap** No content is currently available. +- **UpdateRebootTime** No content is currently available. +- **usoScanHoursSinceLastScan** No content is currently available. +- **usoScanPastThreshold** No content is currently available. +- **WindowsHiberFilSysSizeInMegabytes** No content is currently available. +- **WindowsInstallerFolderSizeInMegabytes** No content is currently available. +- **WindowsPageFileSysSizeInMegabytes** No content is currently available. +- **WindowsSoftwareDistributionFolderSizeInMegabytes** No content is currently available. +- **WindowsSwapFileSysSizeInMegabytes** No content is currently available. +- **WindowsSxsFolderSizeInMegabytes** No content is currently available. + + +### Microsoft.Windows.Remediation.Completed + +This event enables completion tracking of a process that remediates issues preventing security and quality updates. + +The following fields are available: + +- **ActionName** Name of the action to be completed by the plug-in. +- **AppraiserTaskMissing** TRUE if the Appraiser task is missing. +- **branchReadinessLevel** Branch readiness level policy. +- **cloudControlState** Value indicating whether the shell is enabled on the cloud control settings. +- **CV** The Correlation Vector. +- **DiskFreeSpaceAfterSedimentPackInMB** No content is currently available. +- **DiskFreeSpaceBeforeSedimentPackInMB** No content is currently available. +- **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. +- **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. +- **hasRolledBack** Indicates whether the client machine has rolled back. +- **hasUninstalled** Indicates whether the client machine has uninstalled a later version of the OS. +- **hResult** The result of the event execution. +- **HResult** The result of the event execution. +- **installDate** The value of installDate registry key. Indicates the install date. +- **isNetworkMetered** Indicates whether the client machine has uninstalled a later version of the OS. +- **LatestState** The final state of the plug-in component. +- **MicrosoftCompatibilityAppraiser** The name of the component targeted by the Appraiser plug-in. +- **PackageVersion** The package version for the current Remediation. +- **PluginName** The name of the plug-in specified for each generic plug-in event. +- **QualityUpdateSedimentExecutedPlugins** No content is currently available. +- **QualityUpdateSedimentFunnelState** No content is currently available. +- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. +- **QualityUpdateSedimentLocalEndTime** No content is currently available. +- **QualityUpdateSedimentLocaltTime** No content is currently available. +- **QualityUpdateSedimentMatchedTriggers** No content is currently available. +- **QualityUpdateSedimentModelExecutionSeconds** No content is currently available. +- **recoveredFromTargetOS** No content is currently available. +- **RemediationBatteryPowerBatteryLevel** Indicates the battery level at which it is acceptable to continue operation. +- **RemediationBatteryPowerExitDueToLowBattery** True when we exit due to low battery power. +- **RemediationBatteryPowerOnBattery** True if we allow execution on battery. +- **RemediationConfigurationTroubleshooterIpconfigFix** TRUE if IPConfig Fix completed successfully. +- **RemediationConfigurationTroubleshooterNetShFix** TRUE if network card cache reset ran successfully. +- **RemediationCorruptionRepairCorruptionsDetected** No content is currently available. +- **RemediationCorruptionRepairCorruptionsFixed** No content is currently available. +- **RemediationCorruptionRepairPerformActionSuccessful** No content is currently available. +- **remediationExecution** Remediation shell is in "applying remediation" state. +- **RemediationHibernationMigrated** TRUE if hibernation was migrated. +- **RemediationHibernationMigrationSucceeded** TRUE if hibernation migration succeeded. +- **RemediationNGenDiskSpaceRestored** No content is currently available. +- **RemediationNGenMigrationSucceeded** No content is currently available. +- **RemediationShellHasUpgraded** TRUE if the device upgraded. +- **RemediationShellMinimumTimeBetweenShellRuns** Indicates the time between shell runs exceeded the minimum required to execute plugins. +- **RemediationShellRunFromService** TRUE if the shell driver was run from the service. +- **RemediationShellSessionIdentifier** Unique identifier tracking a shell session. +- **RemediationShellSessionTimeInSeconds** Indicates the time the shell session took in seconds. +- **RemediationShellTaskDeleted** Indicates that the shell task has been deleted so no additional sediment pack runs occur for this installation. +- **RemediationUpdateServiceHealthRemediationResult** The result of the Update Service Health plug-in. +- **RemediationUpdateTaskHealthRemediationResult** The result of the Update Task Health plug-in. +- **RemediationUpdateTaskHealthTaskList** A list of tasks fixed by the Update Task Health plug-in. +- **RemediationUSORebootRequred** No content is currently available. +- **Result** The HRESULT for Detection or Perform Action phases of the plug-in. +- **RunCount** No content is currently available. +- **RunResult** The HRESULT for Detection or Perform Action phases of the plug-in. +- **ServiceHardeningExitCode** The exit code returned by Windows Service Repair. +- **ServiceHealthEnabledBitMap** List of services updated by the plugin. +- **ServiceHealthInstalledBitMap** List of services installed by the plugin. +- **StorageSenseDiskCompresserTotalInMB** No content is currently available. +- **StorageSenseHelloFaceRecognitionFodCleanupTotalInByte** No content is currently available. +- **StorageSenseRestorePointCleanupTotalInMB** No content is currently available. +- **StorageSenseUserDownloadFolderCleanupTotalInByte** No content is currently available. +- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive in MBs. +- **systemUptimeInHours** Indicates the amount of time the system in hours has been on since the last boot. +- **uninstallActive** TRUE if previous uninstall has occurred for current OS +- **usoScanDaysSinceLastScan** The number of days since the last USO (Update Session Orchestrator) scan. +- **usoScanInProgress** TRUE if a USO (Update Session Orchestrator) scan is in progress, to prevent multiple simultaneous scans. +- **usoScanIsAllowAutoUpdateKeyPresent** TRUE if the AllowAutoUpdate registry key is set. +- **usoScanIsAllowAutoUpdateProviderSetKeyPresent** TRUE if AllowAutoUpdateProviderSet registry key is set. +- **usoScanIsAuOptionsPresent** TRUE if Auto Update Options registry key is set. +- **usoScanIsFeatureUpdateInProgress** TRUE if a USO (Update Session Orchestrator) scan is in progress, to prevent multiple simultaneous scans. +- **usoScanIsNetworkMetered** TRUE if the device is currently connected to a metered network. +- **usoScanIsNoAutoUpdateKeyPresent** TRUE if no Auto Update registry key is set/present. +- **usoScanIsUserLoggedOn** TRUE if the user is logged on. +- **usoScanPastThreshold** TRUE if the most recent USO (Update Session Orchestrator) scan is past the threshold (late). +- **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". +- **windows10UpgraderBlockWuUpdates** Event to report the value of Windows 10 Upgrader BlockWuUpdates Key. +- **windowsEditionId** Event to report the value of Windows Edition ID. +- **windowsUpgradeRecoveredFromRs4** Event to report the value of the Windows Upgrade Recovered key. + + +### Microsoft.Windows.Remediation.Started + +This event reports whether a plug-in started, to help ensure Windows is up to date. + +The following fields are available: + +- **CV** Correlation vector. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **QualityUpdateSedimentFunnelState** No content is currently available. +- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. +- **QualityUpdateSedimentLastRunSeconds** No content is currently available. +- **QualityUpdateSedimentLocaltTime** No content is currently available. +- **QualityUpdateSedimentMatchedTriggers** No content is currently available. +- **QualityUpdateSedimentSelectedPlugins** No content is currently available. +- **QualityUpdateSedimentTargetedPlugins** No content is currently available. +- **QualityUpdateSedimentTargetedTriggers** No content is currently available. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. +- **RunCount** The number of times the remediation event started (whether it completed successfully or not). + + +### Microsoft.Windows.SedimentLauncher.Applicable + +Indicates whether a given plugin is applicable. + +The following fields are available: + +- **CV** Correlation vector. +- **DetectedCondition** Boolean true if detect condition is true and perform action will be run. +- **FileVersion** No content is currently available. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **IsHashMismatch** No content is currently available. +- **IsSelfUpdateEnabledInOneSettings** True if self update enabled in Settings. +- **IsSelfUpdateNeeded** True if self update needed by device. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. + + +### Microsoft.Windows.SedimentLauncher.Completed + +Indicates whether a given plugin has completed its work. + +The following fields are available: + +- **CV** Correlation vector. +- **FailedReasons** Concatenated list of failure reasons. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. +- **SedLauncherExecutionResult** HRESULT for one execution of the Sediment Launcher. + + +### Microsoft.Windows.SedimentLauncher.Started + +This event indicates that a given plug-in has started. + +The following fields are available: + +- **CV** Correlation vector. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. + + +### Microsoft.Windows.SedimentService.Applicable + +This event indicates whether a given plug-in is applicable. + +The following fields are available: + +- **CV** Correlation vector. +- **DetectedCondition** Determine whether action needs to run based on device properties. +- **FileVersion** No content is currently available. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **IsHashMismatch** No content is currently available. +- **IsSelfUpdateEnabledInOneSettings** Indicates if self update is enabled in One Settings. +- **IsSelfUpdateNeeded** Indicates if self update is needed. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. + + +### Microsoft.Windows.SedimentService.Completed + +This event indicates whether a given plug-in has completed its work. + +The following fields are available: + +- **CV** Correlation vector. +- **FailedReasons** List of reasons when the plugin action failed. +- **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. +- **PackageVersion** Current package version of Remediation. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **Result** This is the HRESULT for detection or perform action phases of the plugin. +- **SedimentServiceCheckTaskFunctional** True/False if scheduled task check succeeded. +- **SedimentServiceCurrentBytes** Number of current private bytes of memory consumed by sedsvc.exe. +- **SedimentServiceKillService** True/False if service is marked for kill (Shell.KillService). +- **SedimentServiceMaximumBytes** Maximum bytes allowed for the service. +- **SedimentServiceRanShell** No content is currently available. +- **SedimentServiceRetrievedKillService** True/False if result of One Settings check for kill succeeded - we only send back one of these indicators (not for each call). +- **SedimentServiceShellRunHResult** No content is currently available. +- **SedimentServiceStopping** True/False indicating whether the service is stopping. +- **SedimentServiceTaskFunctional** True/False if scheduled task is functional. If task is not functional this indicates plugins will be run. +- **SedimentServiceTotalIterations** Number of 5 second iterations service will wait before running again. + + +### Microsoft.Windows.SedimentService.Started + +This event indicates a specified plug-in has started. This information helps ensure Windows is up to date. + +The following fields are available: + +- **CV** The Correlation Vector. +- **GlobalEventCounter** The client-side counter that indicates ordering of events. +- **PackageVersion** The version number of the current remediation package. +- **PluginName** Name of the plugin specified for each generic plugin event. +- **Result** This is the HRESULT for Detection or Perform Action phases of the plugin. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted From f8d890ccb8d8dd95d4fee53a1881a6f4e472d759 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 5 Apr 2019 09:51:05 -0700 Subject: [PATCH 105/737] new build 4/5/2019 9:51 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 96 +++++++++---------- 1 file changed, 48 insertions(+), 48 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index a0330d713f..44cb7ab443 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/04/2019 +ms.date: 04/05/2019 --- @@ -3943,28 +3943,28 @@ The following fields are available: - **ContainerId** An identifier that uniquely groups the functional devices associated with a single-function or multifunction device. - **DeviceInstanceId** The unique identifier for this instance of the device. - **EndpointDevnodeId** The IMMDevice identifier of the associated devnode. -- **endpointEffectClsid** No content is currently available. -- **endpointEffectModule** No content is currently available. +- **endpointEffectClsid** The COM Class Identifier (CLSID) for the endpoint effect audio processing object. +- **endpointEffectModule** Module name for the endpoint effect audio processing object. - **EndpointFormFactor** The enumeration value for the form factor of the endpoint device (for example speaker, microphone, remote network device). - **endpointID** The unique identifier for the audio endpoint. - **endpointInstanceId** The unique identifier for the software audio endpoint. Used for joining to other audio event. - **Flow** Indicates whether the endpoint is capture (1) or render (0). -- **globalEffectClsid** No content is currently available. -- **globalEffectModule** No content is currently available. +- **globalEffectClsid** COM Class Identifier (CLSID) for the legacy global effect audio processing object. +- **globalEffectModule** Module name for the legacy global effect audio processing object. - **HWID** The hardware identifier for the endpoint. - **IsBluetooth** Indicates whether the device is a Bluetooth device. -- **isFarField** No content is currently available. +- **isFarField** A flag indicating whether the microphone endpoint is capable of hearing far field audio. - **IsSideband** Indicates whether the device is a sideband device. - **IsUSB** Indicates whether the device is a USB device. - **JackSubType** A unique ID representing the KS node type of the endpoint. -- **localEffectClsid** No content is currently available. -- **localEffectModule** No content is currently available. +- **localEffectClsid** The COM Class Identifier (CLSID) for the legacy local effect audio processing object. +- **localEffectModule** Module name for the legacy local effect audio processing object. - **MicArrayGeometry** Describes the microphone array, including the microphone position, coordinates, type, and frequency range. See [MicArrayGeometry](#micarraygeometry). -- **modeEffectClsid** No content is currently available. -- **modeEffectModule** No content is currently available. +- **modeEffectClsid** The COM Class Identifier (CLSID) for the mode effect audio processing object. +- **modeEffectModule** Module name for the mode effect audio processing object. - **persistentId** A unique ID for this endpoint which is retained across migrations. -- **streamEffectClsid** No content is currently available. -- **streamEffectModule** No content is currently available. +- **streamEffectClsid** The COM Class Identifier (CLSID) for the stream effect audio processing object. +- **streamEffectModule** Module name for the stream effect audio processing object. ### Microsoft.Windows.DriverInstall.DeviceInstall @@ -4390,7 +4390,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRLayoutImageFailed -No content is currently available. +This event is sent when push-button reset fails to create a new image of Windows. The following fields are available: @@ -4399,7 +4399,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRLayoutImageSucceed -No content is currently available. +This event is sent when push-button reset succeeds in creating a new image of Windows. The following fields are available: @@ -4408,7 +4408,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBROEM1Failed -No content is currently available. +This event is sent when the first OEM extensibility operation is successfully completed. The following fields are available: @@ -4421,14 +4421,14 @@ The following fields are available: ### Microsoft.Windows.PBR.PBROEM2Failed -No content is currently available. +This event is sent when the second OEM extensibility operation is successfully completed. The following fields are available: -- **HRESULT** The result code for the error that occurred while running the OEM extensibility script. -- **Parameters** The parameters to the OEM extensibility script. +- **HRESULT** The result error code from the OEM extensibility script. +- **Parameters** The parameters that were passed to the OEM extensibility script. - **PBRType** The type of push-button reset. -- **ScriptName** The path to the push-button reset script. +- **ScriptName** The path to the OEM extensibility script. - **SessionID** The ID of the push-button reset session. @@ -4488,16 +4488,16 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRReachedOOBE -No content is currently available. +This event returns data when the PBR (Push Button Reset) process reaches the OOBE (Out of Box Experience). The following fields are available: -- **SessionID** No content is currently available. +- **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRReconstructionInitiated -No content is currently available. +This event returns data when a PBR (Push Button Reset) reconstruction operation begins. The following fields are available: @@ -4506,7 +4506,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRRequirementChecks -No content is currently available. +This event returns data when PBR (Push Button Reset) requirement checks begin. The following fields are available: @@ -4518,7 +4518,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRRequirementChecksFailed -No content is currently available. +This event returns data when PBR (Push Button Reset) requirement checks fail. The following fields are available: @@ -4527,28 +4527,28 @@ The following fields are available: - **ErrorType** The type of error that occurred during the requirement checks phase of the push-button reset operation. - **PBRImageVersion** The image version of the push-button reset tool. - **PBRRecoveryStrategy** The recovery strategy for this phase of push-button reset. -- **PBRStartedFrom** No content is currently available. -- **PBRType** No content is currently available. +- **PBRStartedFrom** Identifies the push-button reset entry point. +- **PBRType** The type of push-button reset specified by the user interface. - **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRRequirementChecksPassed -No content is currently available. +This event returns data when PBR (Push Button Reset) requirement checks are passed. The following fields are available: -- **OSVersion** No content is currently available. -- **PBRImageType** No content is currently available. +- **OSVersion** The OS version installed on the device. +- **PBRImageType** The push-button reset image type. - **PBRImageVersion** The version of the push-button reset image. -- **PBRRecoveryStrategy** No content is currently available. -- **PBRStartedFrom** No content is currently available. +- **PBRRecoveryStrategy** The push-button reset recovery strategy. +- **PBRStartedFrom** Identifies the push-button reset entry point. - **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRRestoreLicenseFailed -No content is currently available. +This event sends basic data about recovery operation failure on the device. This data allows investigation to help keep Windows and PBR (Push Button Reset) up to date. The following fields are available: @@ -4557,18 +4557,18 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRSucceed -No content is currently available. +This event returns data when PBR (Push Button Reset) succeeds. The following fields are available: -- **OSVersion** No content is currently available. +- **OSVersion** The OS version installed on the device. - **PBRType** The type of push-button reset. - **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRUserCancelled -No content is currently available. +This event returns data when the user cancels the PBR (Push Button Reset) from the UI (user interface). The following fields are available: @@ -4579,18 +4579,18 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRVersionsMistmatch -No content is currently available. +This event returns data when there is a version mismatch for WinRE (Windows Recovery) and the OS. The following fields are available: -- **OSVersion** No content is currently available. +- **OSVersion** The OS version installed on the device. - **REVersion** The version of Windows Recovery Environment (WinRE). - **SessionID** The ID of this push-button reset session. ### Microsoft.Windows.PBR.PBRWinREInstallationFailed -No content is currently available. +This event returns data when the WinRE (Windows Recovery) installation fails. The following fields are available: @@ -4599,7 +4599,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PhaseFinished -No content is currently available. +This event returns data when a phase of PBR (Push Button Reset) has completed. The following fields are available: @@ -4623,7 +4623,7 @@ The following fields are available: ### Microsoft.Windows.PBR.ReconstructionInfo -No content is currently available. +This event returns data about the PBR (Push Button Reset) reconstruction. The following fields are available: @@ -4631,13 +4631,13 @@ The following fields are available: - **numPackagesFailed** The number of packages that failed during the reconstruction operation of push-button reset. - **sessionID** The ID of this push-button reset session. - **slowMode** The mode of reconstruction. -- **targetVersion** No content is currently available. +- **targetVersion** The target version of the OS for the reconstruction. - **timestamp** The timestamp of this push-button reset event. ### Microsoft.Windows.PBR.ResetOptions -No content is currently available. +This event returns data about the PBR (Push Button Reset) reset options selected by the user. The following fields are available: @@ -4651,7 +4651,7 @@ The following fields are available: ### Microsoft.Windows.PBR.RetryQueued -No content is currently available. +This event returns data about the retry count when PBR (Push Button Reset) is restarted due to a reboot. The following fields are available: @@ -4662,7 +4662,7 @@ The following fields are available: ### Microsoft.Windows.PBR.ReturnedToOldOS -No content is currently available. +This event returns data after PBR (Push Button Reset) has completed the rollback. The following fields are available: @@ -4672,7 +4672,7 @@ The following fields are available: ### Microsoft.Windows.PBR.ReturnTaskSchedulingFailed -No content is currently available. +This event returns data when there is a failure scheduling a boot into WinRE (Windows Recovery). The following fields are available: @@ -4684,7 +4684,7 @@ The following fields are available: ### Microsoft.Windows.PBR.RollbackFinished -No content is currently available. +This event returns data when the PBR (Push Button Reset) rollback completes. The following fields are available: @@ -4696,7 +4696,7 @@ The following fields are available: ### Microsoft.Windows.PBR.RollbackStarted -No content is currently available. +This event returns data when the PBR (Push Button Reset) rollback begins. The following fields are available: @@ -4706,7 +4706,7 @@ The following fields are available: ### Microsoft.Windows.PBR.ScenarioNotSupported -No content is currently available. +This event returns data when the PBR (Push Button Reset) scenario selected is not supported on the device. The following fields are available: From 340015dd795a8e38b34239bae0222a23f7bb1a42 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 5 Apr 2019 09:51:11 -0700 Subject: [PATCH 106/737] new build 4/5/2019 9:51 AM --- .../basic-level-windows-diagnostic-events-and-fields-1703.md | 2 +- .../basic-level-windows-diagnostic-events-and-fields-1709.md | 2 +- .../basic-level-windows-diagnostic-events-and-fields-1803.md | 2 +- .../basic-level-windows-diagnostic-events-and-fields-1809.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index c029cc311a..b935c25c38 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/04/2019 +ms.date: 04/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 8fdeaa71a6..ded2f5807f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/04/2019 +ms.date: 04/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index f7b9ceb9f0..d65b1aae10 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/04/2019 +ms.date: 04/05/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index ee4dd734aa..21218c05f5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/04/2019 +ms.date: 04/05/2019 --- From 0d311c247214de1813c7d1c160d2569448faf660 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 10:51:49 -0700 Subject: [PATCH 107/737] 1903 --- .../windows-10-1903-removed-features.md | 50 +++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 windows/deployment/planning/windows-10-1903-removed-features.md diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md new file mode 100644 index 0000000000..1204493c7c --- /dev/null +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -0,0 +1,50 @@ +--- +title: Windows 10, version 1809 - Features that have been removed +description: Learn about features that will be removed or deprecated in Windows 10, version 1809, or a future release +ms.prod: w10 +ms.mktglfcycl: plan +ms.localizationpriority: medium +ms.sitesec: library +author: lizap +ms.author: elizapo +ms.date: 11/16/2018 +ms.topic: article +--- +# Features removed or planned for replacement starting with Windows 10, version 1809 + +> Applies to: Windows 10, version 1809 + +Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1809. + +> [!TIP] +> - You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes. +> - Have questions about other releases? Check out the information for [Windows 10, version 1803](windows-10-1803-removed-features.md), [Windows 10, version 1709](windows-10-fall-creators-deprecation.md), and [Windows 10, version 1703](windows-10-creators-update-deprecation.md). + +**The list is subject to change and might not include every affected feature or functionality.** + +## Features we removed in this release + +We're removing the following features and functionalities from the installed product image in Windows 10, version 1809. Applications or code that depend on these features won't function in this release unless you use an alternate method. + +|Feature |Instead you can use...| +|-----------|-------------------- +|Business Scanning, also called Distributed Scan Management (DSM)|We're removing this secure scanning and scanner management capability - there are no devices that support this feature.| +|[FontSmoothing setting](https://docs.microsoft.com/windows-hardware/customize/desktop/unattend/microsoft-windows-shell-setup-visualeffects-fontsmoothing) in unattend.xml|The FontSmoothing setting let you specify the font antialiasing strategy to use across the system. We've changed Windows 10 to use [ClearType](https://docs.microsoft.com/typography/cleartype/) by default, so we're removing this setting as it is no longer necessary. If you include this setting in the unattend.xml file, it'll be ignored.| +|Hologram app|We've replaced the Hologram app with the [Mixed Reality Viewer](https://support.microsoft.com/help/4041156/windows-10-mixed-reality-help). If you would like to create 3D word art, you can still do that in Paint 3D and view your art in VR or Hololens with the Mixed Reality Viewer.| +|limpet.exe|We're releasing the limpet.exe tool, used to access TPM for Azure connectivity, as open source.| +|Phone Companion|When you update to Windows 10, version 1809, the Phone Companion app will be removed from your PC. Use the **Phone** page in the Settings app to sync your mobile phone with your PC. It includes all the Phone Companion features.| +|Future updates through [Windows Embedded Developer Update](https://docs.microsoft.com/previous-versions/windows/embedded/ff770079\(v=winembedded.60\)) for Windows Embedded Standard 7-SP1 (WES7-SP1) and Windows Embedded Standard 8 (WES8)|We’re no longer publishing new updates to the WEDU server. Instead, you may secure any new updates from the [Microsoft Update Catalog](http://www.catalog.update.microsoft.com/Home.aspx). [Learn how](https://techcommunity.microsoft.com/t5/Windows-Embedded/Change-to-the-Windows-Embedded-Developer-Update/ba-p/285704) to get updates from the catalog.| + +## Features we’re no longer developing + +We're no longer actively developing these features and may remove them from a future update. Some features have been replaced with other features or functionality, while others are now available from different sources. + +If you have feedback about the proposed replacement of any of these features, you can use the [Feedback Hub app](https://support.microsoft.com/help/4021566/windows-10-send-feedback-to-microsoft-with-feedback-hub-app). + +|Feature |Instead you can use...| +|-----------|---------------------| +|Companion device dynamic lock APIS|The companion device framework (CDF) APIs enable wearables and other devices to unlock a PC. In Windows 10, version 1709, we introduced [Dynamic Lock](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-features#dynamic-lock), including an inbox method using Bluetooth to detect whether a user is present and lock or unlock the PC. Because of this, and because third party partners didn't adopt the CDF method, we're no longer developing CDF Dynamic Lock APIs.| +|OneSync service|The OneSync service synchronizes data for the Mail, Calendar, and People apps. We've added a sync engine to the Outlook app that provides the same synchronization.| +|Snipping Tool|The Snipping Tool is an application included in Windows 10 that is used to capture screenshots, either the full screen or a smaller, custom "snip" of the screen. In Windows 10, version 1809, we're [introducing a new universal app, Snip & Sketch](https://blogs.windows.com/windowsexperience/2018/05/03/announcing-windows-10-insider-preview-build-17661/#8xbvP8vMO0lF20AM.97), that provides the same screen snipping abilities, as well as additional features. You can launch Snip & Sketch directly and start a snip from there, or just press WIN + Shift + S. Snip & Sketch can also be launched from the “Screen snip” button in the Action Center. We're no longer developing the Snipping Tool as a separate app but are instead consolidating its functionality into Snip & Sketch.| + + From 48dc74dcae78953369130cb7bdf33eafde7a9456 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 11:14:02 -0700 Subject: [PATCH 108/737] draft 1903 --- .../windows-10-1903-removed-features.md | 39 +++++++++---------- 1 file changed, 19 insertions(+), 20 deletions(-) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 1204493c7c..9c64a28119 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -1,24 +1,22 @@ --- -title: Windows 10, version 1809 - Features that have been removed -description: Learn about features that will be removed or deprecated in Windows 10, version 1809, or a future release +title: Windows 10, version 1903 - Features that have been removed +description: Learn about features that will be removed or deprecated in Windows 10, version 1903, or a future release ms.prod: w10 ms.mktglfcycl: plan ms.localizationpriority: medium ms.sitesec: library -author: lizap -ms.author: elizapo -ms.date: 11/16/2018 +author: greg-lindsay +ms.author: greglin ms.topic: article --- -# Features removed or planned for replacement starting with Windows 10, version 1809 +# Features removed or planned for replacement starting with Windows 10, version 1903 -> Applies to: Windows 10, version 1809 +> Applies to: Windows 10, version 1903 -Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1809. +
![step one](../images/one.png)![set up device](../images/set-up-device.png)

Enter a name for the device.

(Optional) Select a license file to upgrade Windows 10 to a different edition. [See the permitted upgrades.](https://technet.microsoft.com/itpro/windows/deploy/windows-10-edition-upgrades)

Toggle **Yes** or **No** to **Configure devices for shared use**. This setting optimizes Windows 10 for shared use scenarios. [Learn more about shared PC configuration.](../set-up-shared-or-guest-pc.md)

You can also select to remove pre-installed software from the device.
![device name, upgrade to enterprise, shared use, remove pre-installed software](../images/set-up-device-details-desktop.png)
![step two](../images/two.png) ![set up network](../images/set-up-network.png)

Toggle **On** or **Off** for wireless network connectivity. If you select **On**, enter the SSID, the network type (**Open** or **WPA2-Personal**), and (if **WPA2-Personal**) the password for the wireless network.
![Enter network SSID and type](../images/set-up-network-details-desktop.png)
![step three](../images/three.png) ![account management](../images/account-management.png)

Enable account management if you want to configure settings on this page.

You can enroll the device in Active Directory, enroll in Azure Active Directory, or create a local administrator account on the device

To enroll the device in Active Directory, enter the credentials for a least-privileged user account to join the device to the domain.

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used. To enroll the device in Azure AD, select that option and enter a friendly name for the bulk token you will get using the wizard. Set an expiration date for the token (maximum is 30 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

To create a local administrator account, select that option and enter a user name and password.

**Important:** If you create a local account in the provisioning package, you must change the password using the **Settings** app every 42 days. If the password is not changed during that period, the account might be locked out and unable to sign in.
![join Active Directory, Azure AD, or create a local admin account](../images/account-management-details.png)
![step three](../images/three.png) ![account management](../images/account-management.png)

Enable account management if you want to configure settings on this page.

You can enroll the device in Active Directory, enroll in Azure Active Directory, or create a local administrator account on the device

To enroll the device in Active Directory, enter the credentials for a least-privileged user account to join the device to the domain.

Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, [set up Azure AD join in your organization](https://docs.microsoft.com/azure/active-directory/active-directory-azureadjoin-setup). The **maximum number of devices per user** setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used. To enroll the device in Azure AD, select that option and enter a friendly name for the bulk token you will get using the wizard. Set an expiration date for the token (maximum is 180 days from the date you get the token). Click **Get bulk token**. In the **Let's get you signed in** window, enter an account that has permissions to join a device to Azure AD, and then the password. Click **Accept** to give Windows Configuration Designer the necessary permissions.

To create a local administrator account, select that option and enter a user name and password.

**Important:** If you create a local account in the provisioning package, you must change the password using the **Settings** app every 42 days. If the password is not changed during that period, the account might be locked out and unable to sign in.
![join Active Directory, Azure AD, or create a local admin account](../images/account-management-details.png)
![step four](../images/four.png) ![add applications](../images/add-applications.png)

You can install multiple applications, both Windows desktop applications (Win32) and Universal Windows Platform (UWP) apps, in a provisioning package. The settings in this step vary according to the application that you select. For help with the settings, see [Provision PCs with apps](provision-pcs-with-apps.md).
![add an application](../images/add-applications-details.png)
![step five](../images/five.png) ![add certificates](../images/add-certificates.png)

To provision the device with a certificate, click **Add a certificate**. Enter a name for the certificate, and then browse to and select the certificate to be used.
![add a certificate](../images/add-certificates-details.png)
![finish](../images/finish.png)

You can set a password to protect your provisioning package. You must enter this password when you apply the provisioning package to a device.
![Protect your package](../images/finish-details.png)
+
Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes. +
-> [!TIP] -> - You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes. -> - Have questions about other releases? Check out the information for [Windows 10, version 1803](windows-10-1803-removed-features.md), [Windows 10, version 1709](windows-10-fall-creators-deprecation.md), and [Windows 10, version 1703](windows-10-creators-update-deprecation.md). **The list is subject to change and might not include every affected feature or functionality.** @@ -28,12 +26,11 @@ We're removing the following features and functionalities from the installed pro |Feature |Instead you can use...| |-----------|-------------------- -|Business Scanning, also called Distributed Scan Management (DSM)|We're removing this secure scanning and scanner management capability - there are no devices that support this feature.| -|[FontSmoothing setting](https://docs.microsoft.com/windows-hardware/customize/desktop/unattend/microsoft-windows-shell-setup-visualeffects-fontsmoothing) in unattend.xml|The FontSmoothing setting let you specify the font antialiasing strategy to use across the system. We've changed Windows 10 to use [ClearType](https://docs.microsoft.com/typography/cleartype/) by default, so we're removing this setting as it is no longer necessary. If you include this setting in the unattend.xml file, it'll be ignored.| -|Hologram app|We've replaced the Hologram app with the [Mixed Reality Viewer](https://support.microsoft.com/help/4041156/windows-10-mixed-reality-help). If you would like to create 3D word art, you can still do that in Paint 3D and view your art in VR or Hololens with the Mixed Reality Viewer.| -|limpet.exe|We're releasing the limpet.exe tool, used to access TPM for Azure connectivity, as open source.| -|Phone Companion|When you update to Windows 10, version 1809, the Phone Companion app will be removed from your PC. Use the **Phone** page in the Settings app to sync your mobile phone with your PC. It includes all the Phone Companion features.| -|Future updates through [Windows Embedded Developer Update](https://docs.microsoft.com/previous-versions/windows/embedded/ff770079\(v=winembedded.60\)) for Windows Embedded Standard 7-SP1 (WES7-SP1) and Windows Embedded Standard 8 (WES8)|We’re no longer publishing new updates to the WEDU server. Instead, you may secure any new updates from the [Microsoft Update Catalog](http://www.catalog.update.microsoft.com/Home.aspx). [Learn how](https://techcommunity.microsoft.com/t5/Windows-Embedded/Change-to-the-Windows-Embedded-Developer-Update/ba-p/285704) to get updates from the catalog.| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| ## Features we’re no longer developing @@ -43,8 +40,10 @@ If you have feedback about the proposed replacement of any of these features, yo |Feature |Instead you can use...| |-----------|---------------------| -|Companion device dynamic lock APIS|The companion device framework (CDF) APIs enable wearables and other devices to unlock a PC. In Windows 10, version 1709, we introduced [Dynamic Lock](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-features#dynamic-lock), including an inbox method using Bluetooth to detect whether a user is present and lock or unlock the PC. Because of this, and because third party partners didn't adopt the CDF method, we're no longer developing CDF Dynamic Lock APIs.| -|OneSync service|The OneSync service synchronizes data for the Mail, Calendar, and People apps. We've added a sync engine to the Outlook app that provides the same synchronization.| -|Snipping Tool|The Snipping Tool is an application included in Windows 10 that is used to capture screenshots, either the full screen or a smaller, custom "snip" of the screen. In Windows 10, version 1809, we're [introducing a new universal app, Snip & Sketch](https://blogs.windows.com/windowsexperience/2018/05/03/announcing-windows-10-insider-preview-build-17661/#8xbvP8vMO0lF20AM.97), that provides the same screen snipping abilities, as well as additional features. You can launch Snip & Sketch directly and start a snip from there, or just press WIN + Shift + S. Snip & Sketch can also be launched from the “Screen snip” button in the Action Center. We're no longer developing the Snipping Tool as a separate app but are instead consolidating its functionality into Snip & Sketch.| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| +|xxxxx|yyyyy| From 951414f2328339a2683823fc5d65b7f93e1e42f2 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 11:15:29 -0700 Subject: [PATCH 109/737] draft 1903 --- windows/deployment/planning/TOC.md | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/windows/deployment/planning/TOC.md b/windows/deployment/planning/TOC.md index cf1fef543a..0e2810b1b7 100644 --- a/windows/deployment/planning/TOC.md +++ b/windows/deployment/planning/TOC.md @@ -3,17 +3,13 @@ ## [Windows 10 deployment considerations](windows-10-deployment-considerations.md) ## [Windows 10 compatibility](windows-10-compatibility.md) ## [Windows 10 infrastructure requirements](windows-10-infrastructure-requirements.md) -## [Windows 10, version 1809 - Features removed or planned for replacement](windows-10-1809-removed-features.md) -## [Windows 10, version 1803 - Features removed or planned for replacement](windows-10-1803-removed-features.md) -## [Fall Creators update (version 1709) - deprecated features](windows-10-fall-creators-deprecation.md) -## [Creators update (version 1703) - deprecated features](windows-10-creators-update-deprecation.md) -## [Windows To Go: feature overview](windows-to-go-overview.md) -### [Best practice recommendations for Windows To Go](best-practice-recommendations-for-windows-to-go.md) -### [Deployment considerations for Windows To Go](deployment-considerations-for-windows-to-go.md) -### [Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md) -### [Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md) -### [Windows To Go: frequently asked questions](windows-to-go-frequently-asked-questions.md) +## Features removed or planned for replacement +### [Windows 10, version 1809](windows-10-1809-removed-features.md) +### [Windows 10, version 1803](windows-10-1803-removed-features.md) +### [Windows 10, version 1709](windows-10-fall-creators-deprecation.md) +### [Windows 10, version 1703](windows-10-creators-update-deprecation.md) + ## [Application Compatibility Toolkit (ACT) Technical Reference](act-technical-reference.md) ### [SUA User's Guide](sua-users-guide.md) #### [Using the SUA Wizard](using-the-sua-wizard.md) @@ -39,4 +35,10 @@ ##### [Testing Your Application Mitigation Packages](testing-your-application-mitigation-packages.md) #### [Using the Sdbinst.exe Command-Line Tool](using-the-sdbinstexe-command-line-tool.md) ### [Compatibility Fixes for Windows 10, Windows 8, Windows 7, and Windows Vista](compatibility-fixes-for-windows-8-windows-7-and-windows-vista.md) -## [Change history for Plan for Windows 10 deployment](change-history-for-plan-for-windows-10-deployment.md) \ No newline at end of file + +## [Windows To Go: feature overview](windows-to-go-overview.md) +### [Best practice recommendations for Windows To Go](best-practice-recommendations-for-windows-to-go.md) +### [Deployment considerations for Windows To Go](deployment-considerations-for-windows-to-go.md) +### [Prepare your organization for Windows To Go](prepare-your-organization-for-windows-to-go.md) +### [Security and data protection considerations for Windows To Go](security-and-data-protection-considerations-for-windows-to-go.md) +### [Windows To Go: frequently asked questions](windows-to-go-frequently-asked-questions.md) \ No newline at end of file From 50a5845de1e3d74ca21e0e74660456f84f6fa757 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 12:25:59 -0700 Subject: [PATCH 110/737] draft 1903-1 --- .openpublishing.redirection.json | 10 ++++++++++ windows/deployment/planning/TOC.md | 5 +++-- ...recation.md => windows-10-1703-removed-features.md} | 0 ...recation.md => windows-10-1709-removed-features.md} | 0 4 files changed, 13 insertions(+), 2 deletions(-) rename windows/deployment/planning/{windows-10-creators-update-deprecation.md => windows-10-1703-removed-features.md} (100%) rename windows/deployment/planning/{windows-10-fall-creators-deprecation.md => windows-10-1709-removed-features.md} (100%) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index ab677cc666..d559d7bc35 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -13944,5 +13944,15 @@ "redirect_url": "/windows/security/threat-protection/windows-defender-atp/threat-analytics", "redirect_document_id": true }, +{ +"source_path": "windows/deployment/planning/windows-10-fall-creators-deprecation.md", +"redirect_url": "/windows/deployment/planning/windows-10-1709-removed-features", +"redirect_document_id": true +}, +{ +"source_path": "windows/deployment/planning/windows-10-creators-update-deprecation.md", +"redirect_url": "/windows/deployment/planning/windows-10-1703-removed-features", +"redirect_document_id": true +} ] } diff --git a/windows/deployment/planning/TOC.md b/windows/deployment/planning/TOC.md index 0e2810b1b7..0496ee97d5 100644 --- a/windows/deployment/planning/TOC.md +++ b/windows/deployment/planning/TOC.md @@ -5,10 +5,11 @@ ## [Windows 10 infrastructure requirements](windows-10-infrastructure-requirements.md) ## Features removed or planned for replacement +### [Windows 10, version 1903](windows-10-1903-removed-features.md) ### [Windows 10, version 1809](windows-10-1809-removed-features.md) ### [Windows 10, version 1803](windows-10-1803-removed-features.md) -### [Windows 10, version 1709](windows-10-fall-creators-deprecation.md) -### [Windows 10, version 1703](windows-10-creators-update-deprecation.md) +### [Windows 10, version 1709](windows-10-1709-removed-features.md) +### [Windows 10, version 1703](windows-10-1703-removed-features.md) ## [Application Compatibility Toolkit (ACT) Technical Reference](act-technical-reference.md) ### [SUA User's Guide](sua-users-guide.md) diff --git a/windows/deployment/planning/windows-10-creators-update-deprecation.md b/windows/deployment/planning/windows-10-1703-removed-features.md similarity index 100% rename from windows/deployment/planning/windows-10-creators-update-deprecation.md rename to windows/deployment/planning/windows-10-1703-removed-features.md diff --git a/windows/deployment/planning/windows-10-fall-creators-deprecation.md b/windows/deployment/planning/windows-10-1709-removed-features.md similarity index 100% rename from windows/deployment/planning/windows-10-fall-creators-deprecation.md rename to windows/deployment/planning/windows-10-1709-removed-features.md From c9908489ea7c0e29a643ca73ca85a515308d755e Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 12:31:00 -0700 Subject: [PATCH 111/737] draft 1903-2 --- windows/deployment/planning/windows-10-1903-removed-features.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 9c64a28119..35b56b17dc 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -14,7 +14,7 @@ ms.topic: article > Applies to: Windows 10, version 1903 -
Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes. +
roadmapEach release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes.
From ef1ab22ea3b3a253a572313c8d5f6b3388002b2b Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 5 Apr 2019 13:31:12 -0700 Subject: [PATCH 112/737] new build 4/5/2019 1:31 PM --- ...ndows-diagnostic-events-and-fields-1903.md | 942 +++++++++--------- 1 file changed, 478 insertions(+), 464 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 44cb7ab443..451bee2d3f 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -1518,6 +1518,74 @@ The following fields are available: - **AppraiserVersion** The version of the Appraiser file that is generating the events. +## Audio endpoint events + +### MicArrayGeometry + +This event provides information about the layout of the individual microphone elements in the microphone array. + +The following fields are available: + +- **MicCoords** The location and orientation of the microphone element. +- **usFrequencyBandHi** The high end of the frequency range for the microphone. +- **usFrequencyBandLo** The low end of the frequency range for the microphone. +- **usMicArrayType** The type of the microphone array. +- **usNumberOfMicrophones** The number of microphones in the array. +- **usVersion** The version of the microphone array specification. +- **wHorizontalAngleBegin** The horizontal angle of the start of the working volume (reported as radians times 10,000). +- **wHorizontalAngleEnd** The horizontal angle of the end of the working volume (reported as radians times 10,000). +- **wVerticalAngleBegin** The vertical angle of the start of the working volume (reported as radians times 10,000). +- **wVerticalAngleEnd** The vertical angle of the end of the working volume (reported as radians times 10,000). + + +### MicCoords + +This event provides information about the location and orientation of the microphone element. + +The following fields are available: + +- **usType** The type of microphone. +- **wHorizontalAngle** The horizontal angle of the microphone (reported as radians times 10,000). +- **wVerticalAngle** The vertical angle of the microphone (reported as radians times 10,000). +- **wXCoord** The x-coordinate of the microphone. +- **wYCoord** The y-coordinate of the microphone. +- **wZCoord** The z-coordinate of the microphone. + + +### Microsoft.Windows.Audio.EndpointBuilder.DeviceInfo + +This event logs the successful enumeration of an audio endpoint (such as a microphone or speaker) and provides information about the audio endpoint. + +The following fields are available: + +- **BusEnumeratorName** The name of the bus enumerator (for example, HDAUDIO or USB). +- **ContainerId** An identifier that uniquely groups the functional devices associated with a single-function or multifunction device. +- **DeviceInstanceId** The unique identifier for this instance of the device. +- **EndpointDevnodeId** The IMMDevice identifier of the associated devnode. +- **endpointEffectClsid** The COM Class Identifier (CLSID) for the endpoint effect audio processing object. +- **endpointEffectModule** Module name for the endpoint effect audio processing object. +- **EndpointFormFactor** The enumeration value for the form factor of the endpoint device (for example speaker, microphone, remote network device). +- **endpointID** The unique identifier for the audio endpoint. +- **endpointInstanceId** The unique identifier for the software audio endpoint. Used for joining to other audio event. +- **Flow** Indicates whether the endpoint is capture (1) or render (0). +- **globalEffectClsid** COM Class Identifier (CLSID) for the legacy global effect audio processing object. +- **globalEffectModule** Module name for the legacy global effect audio processing object. +- **HWID** The hardware identifier for the endpoint. +- **IsBluetooth** Indicates whether the device is a Bluetooth device. +- **isFarField** A flag indicating whether the microphone endpoint is capable of hearing far field audio. +- **IsSideband** Indicates whether the device is a sideband device. +- **IsUSB** Indicates whether the device is a USB device. +- **JackSubType** A unique ID representing the KS node type of the endpoint. +- **localEffectClsid** The COM Class Identifier (CLSID) for the legacy local effect audio processing object. +- **localEffectModule** Module name for the legacy local effect audio processing object. +- **MicArrayGeometry** Describes the microphone array, including the microphone position, coordinates, type, and frequency range. See [MicArrayGeometry](#micarraygeometry). +- **modeEffectClsid** The COM Class Identifier (CLSID) for the mode effect audio processing object. +- **modeEffectModule** Module name for the mode effect audio processing object. +- **persistentId** A unique ID for this endpoint which is retained across migrations. +- **streamEffectClsid** The COM Class Identifier (CLSID) for the stream effect audio processing object. +- **streamEffectModule** Module name for the stream effect audio processing object. + + ## Census events ### Census.App @@ -2652,6 +2720,101 @@ This event is a low latency health alert that is part of the 4Nines device healt +## Driver installation events + +### Microsoft.Windows.DriverInstall.DeviceInstall + +This critical event sends information about the driver installation that took place. + +The following fields are available: + +- **ClassGuid** The unique ID for the device class. +- **ClassLowerFilters** The list of lower filter class drivers. +- **ClassUpperFilters** The list of upper filter class drivers. +- **CoInstallers** The list of coinstallers. +- **ConfigFlags** The device configuration flags. +- **DeviceConfigured** Indicates whether this device was configured through the kernel configuration. +- **DeviceInstanceId** The unique identifier of the device in the system. +- **DeviceStack** The device stack of the driver being installed. +- **DriverDate** The date of the driver. +- **DriverDescription** A description of the driver function. +- **DriverInfName** Name of the INF file (the setup information file) for the driver. +- **DriverInfSectionName** Name of the DDInstall section within the driver INF file. +- **DriverPackageId** The ID of the driver package that is staged to the driver store. +- **DriverProvider** The driver manufacturer or provider. +- **DriverUpdated** Indicates whether the driver is replacing an old driver. +- **DriverVersion** The version of the driver file. +- **EndTime** The time the installation completed. +- **Error** Provides the WIN32 error code for the installation. +- **ExtensionDrivers** List of extension drivers that complement this installation. +- **FinishInstallAction** Indicates whether the co-installer invoked the finish-install action. +- **FinishInstallUI** Indicates whether the installation process shows the user interface. +- **FirmwareDate** The firmware date that will be stored in the EFI System Resource Table (ESRT). +- **FirmwareRevision** The firmware revision that will be stored in the EFI System Resource Table (ESRT). +- **FirmwareVersion** The firmware version that will be stored in the EFI System Resource Table (ESRT). +- **FirstHardwareId** The ID in the hardware ID list that provides the most specific device description. +- **FlightIds** A list of the different Windows Insider builds on the device. +- **GenericDriver** Indicates whether the driver is a generic driver. +- **Inbox** Indicates whether the driver package is included with Windows. +- **InstallDate** The date the driver was installed. +- **LastCompatibleId** The ID in the hardware ID list that provides the least specific device description. +- **LegacyInstallReasonError** The error code for the legacy installation. +- **LowerFilters** The list of lower filter drivers. +- **MatchingDeviceId** The hardware ID or compatible ID that Windows used to install the device instance. +- **NeedReboot** Indicates whether the driver requires a reboot. +- **OriginalDriverInfName** The original name of the INF file before it was renamed. +- **ParentDeviceInstanceId** The device instance ID of the parent of the device. +- **PendedUntilReboot** Indicates whether the installation is pending until the device is rebooted. +- **Problem** Error code returned by the device after installation. +- **ProblemStatus** The status of the device after the driver installation. +- **SecondaryDevice** Indicates whether the device is a secondary device. +- **ServiceName** The service name of the driver. +- **SetupMode** Indicates whether the driver installation took place before the initial installation of the device was completed. +- **StartTime** The time when the installation started. +- **SubmissionId** The driver submission identifier assigned by the Windows Hardware Development Center. +- **UpperFilters** The list of upper filter drivers. + + +### Microsoft.Windows.DriverInstall.NewDevInstallDeviceEnd + +This event sends data about the driver installation once it is completed. + +The following fields are available: + +- **DeviceInstanceId** The unique identifier of the device in the system. +- **DriverUpdated** Indicates whether the driver was updated. +- **Error** The Win32 error code of the installation. +- **FlightId** The ID of the Windows Insider build the device received. +- **InstallDate** The date the driver was installed. +- **InstallFlags** The driver installation flags. +- **RebootRequired** Indicates whether a reboot is required after the installation. +- **RollbackPossible** Indicates whether this driver can be rolled back. +- **WuTargetedHardwareId** No content is currently available. +- **WuUntargetedHardwareId** No content is currently available. + + +### Microsoft.Windows.DriverInstall.NewDevInstallDeviceStart + +This event sends data about the driver that the new driver installation is replacing. + +The following fields are available: + +- **DeviceInstanceId** The unique identifier of the device in the system. +- **FirstInstallDate** The first time a driver was installed on this device. +- **LastDriverDate** Date of the driver that is being replaced. +- **LastDriverInbox** Indicates whether the previous driver was included with Windows. +- **LastDriverInfName** Name of the INF file (the setup information file) of the driver being replaced. +- **LastDriverVersion** The version of the driver that is being replaced. +- **LastFirmwareDate** The date of the last firmware reported from the EFI System Resource Table (ESRT). +- **LastFirmwareRevision** The last firmware revision number reported from EFI System Resource Table (ESRT). +- **LastFirmwareVersion** The last firmware version reported from the EFI System Resource Table (ESRT). +- **LastInstallDate** The date a driver was last installed on this device. +- **LastMatchingDeviceId** The hardware ID or compatible ID that Windows last used to install the device instance. +- **LastProblem** The previous problem code that was set on the device. +- **LastProblemStatus** The previous problem code that was set on the device. +- **LastSubmissionId** The driver submission identifier of the driver that is being replaced. + + ## DxgKernelTelemetry events ### DxgKrnlTelemetry.GPUAdapterInventoryV2 @@ -3899,166 +4062,35 @@ The following fields are available: - **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. -## Other events +## Privacy consent logging events -### MicArrayGeometry +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted -This event provides information about the layout of the individual microphone elements in the microphone array. +This event is used to determine whether the user successfully completed the privacy consent experience. The following fields are available: -- **MicCoords** The location and orientation of the microphone element. -- **usFrequencyBandHi** The high end of the frequency range for the microphone. -- **usFrequencyBandLo** The low end of the frequency range for the microphone. -- **usMicArrayType** The type of the microphone array. -- **usNumberOfMicrophones** The number of microphones in the array. -- **usVersion** The version of the microphone array specification. -- **wHorizontalAngleBegin** The horizontal angle of the start of the working volume (reported as radians times 10,000). -- **wHorizontalAngleEnd** The horizontal angle of the end of the working volume (reported as radians times 10,000). -- **wVerticalAngleBegin** The vertical angle of the start of the working volume (reported as radians times 10,000). -- **wVerticalAngleEnd** The vertical angle of the end of the working volume (reported as radians times 10,000). +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience -### MicCoords +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus -This event provides information about the location and orientation of the microphone element. +Event tells us effectiveness of new privacy experience. The following fields are available: -- **usType** The type of microphone. -- **wHorizontalAngle** The horizontal angle of the microphone (reported as radians times 10,000). -- **wVerticalAngle** The vertical angle of the microphone (reported as radians times 10,000). -- **wXCoord** The x-coordinate of the microphone. -- **wYCoord** The y-coordinate of the microphone. -- **wZCoord** The z-coordinate of the microphone. +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting -### Microsoft.Windows.Audio.EndpointBuilder.DeviceInfo - -This event logs the successful enumeration of an audio endpoint (such as a microphone or speaker) and provides information about the audio endpoint. - -The following fields are available: - -- **BusEnumeratorName** The name of the bus enumerator (for example, HDAUDIO or USB). -- **ContainerId** An identifier that uniquely groups the functional devices associated with a single-function or multifunction device. -- **DeviceInstanceId** The unique identifier for this instance of the device. -- **EndpointDevnodeId** The IMMDevice identifier of the associated devnode. -- **endpointEffectClsid** The COM Class Identifier (CLSID) for the endpoint effect audio processing object. -- **endpointEffectModule** Module name for the endpoint effect audio processing object. -- **EndpointFormFactor** The enumeration value for the form factor of the endpoint device (for example speaker, microphone, remote network device). -- **endpointID** The unique identifier for the audio endpoint. -- **endpointInstanceId** The unique identifier for the software audio endpoint. Used for joining to other audio event. -- **Flow** Indicates whether the endpoint is capture (1) or render (0). -- **globalEffectClsid** COM Class Identifier (CLSID) for the legacy global effect audio processing object. -- **globalEffectModule** Module name for the legacy global effect audio processing object. -- **HWID** The hardware identifier for the endpoint. -- **IsBluetooth** Indicates whether the device is a Bluetooth device. -- **isFarField** A flag indicating whether the microphone endpoint is capable of hearing far field audio. -- **IsSideband** Indicates whether the device is a sideband device. -- **IsUSB** Indicates whether the device is a USB device. -- **JackSubType** A unique ID representing the KS node type of the endpoint. -- **localEffectClsid** The COM Class Identifier (CLSID) for the legacy local effect audio processing object. -- **localEffectModule** Module name for the legacy local effect audio processing object. -- **MicArrayGeometry** Describes the microphone array, including the microphone position, coordinates, type, and frequency range. See [MicArrayGeometry](#micarraygeometry). -- **modeEffectClsid** The COM Class Identifier (CLSID) for the mode effect audio processing object. -- **modeEffectModule** Module name for the mode effect audio processing object. -- **persistentId** A unique ID for this endpoint which is retained across migrations. -- **streamEffectClsid** The COM Class Identifier (CLSID) for the stream effect audio processing object. -- **streamEffectModule** Module name for the stream effect audio processing object. - - -### Microsoft.Windows.DriverInstall.DeviceInstall - -This critical event sends information about the driver installation that took place. - -The following fields are available: - -- **ClassGuid** The unique ID for the device class. -- **ClassLowerFilters** The list of lower filter class drivers. -- **ClassUpperFilters** The list of upper filter class drivers. -- **CoInstallers** The list of coinstallers. -- **ConfigFlags** The device configuration flags. -- **DeviceConfigured** Indicates whether this device was configured through the kernel configuration. -- **DeviceInstanceId** The unique identifier of the device in the system. -- **DeviceStack** The device stack of the driver being installed. -- **DriverDate** The date of the driver. -- **DriverDescription** A description of the driver function. -- **DriverInfName** Name of the INF file (the setup information file) for the driver. -- **DriverInfSectionName** Name of the DDInstall section within the driver INF file. -- **DriverPackageId** The ID of the driver package that is staged to the driver store. -- **DriverProvider** The driver manufacturer or provider. -- **DriverUpdated** Indicates whether the driver is replacing an old driver. -- **DriverVersion** The version of the driver file. -- **EndTime** The time the installation completed. -- **Error** Provides the WIN32 error code for the installation. -- **ExtensionDrivers** List of extension drivers that complement this installation. -- **FinishInstallAction** Indicates whether the co-installer invoked the finish-install action. -- **FinishInstallUI** Indicates whether the installation process shows the user interface. -- **FirmwareDate** The firmware date that will be stored in the EFI System Resource Table (ESRT). -- **FirmwareRevision** The firmware revision that will be stored in the EFI System Resource Table (ESRT). -- **FirmwareVersion** The firmware version that will be stored in the EFI System Resource Table (ESRT). -- **FirstHardwareId** The ID in the hardware ID list that provides the most specific device description. -- **FlightIds** A list of the different Windows Insider builds on the device. -- **GenericDriver** Indicates whether the driver is a generic driver. -- **Inbox** Indicates whether the driver package is included with Windows. -- **InstallDate** The date the driver was installed. -- **LastCompatibleId** The ID in the hardware ID list that provides the least specific device description. -- **LegacyInstallReasonError** The error code for the legacy installation. -- **LowerFilters** The list of lower filter drivers. -- **MatchingDeviceId** The hardware ID or compatible ID that Windows used to install the device instance. -- **NeedReboot** Indicates whether the driver requires a reboot. -- **OriginalDriverInfName** The original name of the INF file before it was renamed. -- **ParentDeviceInstanceId** The device instance ID of the parent of the device. -- **PendedUntilReboot** Indicates whether the installation is pending until the device is rebooted. -- **Problem** Error code returned by the device after installation. -- **ProblemStatus** The status of the device after the driver installation. -- **SecondaryDevice** Indicates whether the device is a secondary device. -- **ServiceName** The service name of the driver. -- **SetupMode** Indicates whether the driver installation took place before the initial installation of the device was completed. -- **StartTime** The time when the installation started. -- **SubmissionId** The driver submission identifier assigned by the Windows Hardware Development Center. -- **UpperFilters** The list of upper filter drivers. - - -### Microsoft.Windows.DriverInstall.NewDevInstallDeviceEnd - -This event sends data about the driver installation once it is completed. - -The following fields are available: - -- **DeviceInstanceId** The unique identifier of the device in the system. -- **DriverUpdated** Indicates whether the driver was updated. -- **Error** The Win32 error code of the installation. -- **FlightId** The ID of the Windows Insider build the device received. -- **InstallDate** The date the driver was installed. -- **InstallFlags** The driver installation flags. -- **RebootRequired** Indicates whether a reboot is required after the installation. -- **RollbackPossible** Indicates whether this driver can be rolled back. -- **WuTargetedHardwareId** No content is currently available. -- **WuUntargetedHardwareId** No content is currently available. - - -### Microsoft.Windows.DriverInstall.NewDevInstallDeviceStart - -This event sends data about the driver that the new driver installation is replacing. - -The following fields are available: - -- **DeviceInstanceId** The unique identifier of the device in the system. -- **FirstInstallDate** The first time a driver was installed on this device. -- **LastDriverDate** Date of the driver that is being replaced. -- **LastDriverInbox** Indicates whether the previous driver was included with Windows. -- **LastDriverInfName** Name of the INF file (the setup information file) of the driver being replaced. -- **LastDriverVersion** The version of the driver that is being replaced. -- **LastFirmwareDate** The date of the last firmware reported from the EFI System Resource Table (ESRT). -- **LastFirmwareRevision** The last firmware revision number reported from EFI System Resource Table (ESRT). -- **LastFirmwareVersion** The last firmware version reported from the EFI System Resource Table (ESRT). -- **LastInstallDate** The date a driver was last installed on this device. -- **LastMatchingDeviceId** The hardware ID or compatible ID that Windows last used to install the device instance. -- **LastProblem** The previous problem code that was set on the device. -- **LastProblemStatus** The previous problem code that was set on the device. -- **LastSubmissionId** The driver submission identifier of the driver that is being replaced. - +## Push Button Reset events ### Microsoft.Windows.PBR.BitLockerWipeFinished @@ -4890,323 +4922,6 @@ The following fields are available: - **timestamp** The timestamp for this push-button reset event. -### Microsoft.Windows.Security.WSC.DatastoreMigratedVersion - -This event provides information about the datastore migration and whether it was successful. - -The following fields are available: - -- **datastoreisvtype** The product category of the datastore. -- **datastoremigrated** The version of the datastore that was migrated. -- **status** The result code of the migration. - - -### Microsoft.Windows.Security.WSC.GetCallerViaWdsp - -This event returns data if the registering product EXE (executable file) does not allow COM (Component Object Model) impersonation. - -The following fields are available: - -- **callerExe** The registering product EXE that does not support COM impersonation. - - -### Microsoft.Windows.SysReset.FlightUninstallCancel - -This event indicates the customer has cancelled uninstallation of Windows. - - - -### Microsoft.Windows.SysReset.FlightUninstallError - -This event sends an error code when the Windows uninstallation fails. - -The following fields are available: - -- **ErrorCode** Error code for uninstallation failure. - - -### Microsoft.Windows.SysReset.FlightUninstallReboot - -This event is sent to signal an upcoming reboot during uninstallation of Windows. - - - -### Microsoft.Windows.SysReset.FlightUninstallStart - -This event indicates that the Windows uninstallation has started. - - - -### Microsoft.Windows.SysReset.FlightUninstallUnavailable - -This event sends diagnostic data when the Windows uninstallation is not available. - -The following fields are available: - -- **AddedProfiles** Indicates that new user profiles have been created since the flight was installed. -- **MissingExternalStorage** Indicates that the external storage used to install the flight is not available. -- **MissingInfra** Indicates that uninstall resources are missing. -- **MovedProfiles** Indicates that the user profile has been moved since the flight was installed. - - -### Microsoft.Windows.SysReset.HasPendingActions - -This event is sent when users have actions that will block the uninstall of the latest quality update. - - - -### Microsoft.Windows.SysReset.IndicateLCUWasUninstalled - -This event is sent when the registry indicates that the latest cumulative Windows update package has finished uninstalling. - -The following fields are available: - -- **errorCode** The error code if there was a failure during uninstallation of the latest cumulative Windows update package. - - -### Microsoft.Windows.SysReset.LCUUninstall - -This event is sent when the latest cumulative Windows update was uninstalled on a device. - -The following fields are available: - -- **errorCode** An error that occurred while the Windows update package was being uninstalled. -- **packageName** The name of the Windows update package that is being uninstalled. -- **removalTime** The amount of time it took to uninstall the Windows update package. - - -### Microsoft.Windows.SysReset.PBRBlockedByPolicy - -This event is sent when a push-button reset operation is blocked by the System Administrator. - -The following fields are available: - -- **PBRBlocked** Reason the push-button reset operation was blocked. -- **PBRType** The type of push-button reset operation that was blocked. - - -### Microsoft.Windows.SysReset.PBREngineInitFailed - -This event signals a failed handoff between two recovery binaries. - -The following fields are available: - -- **Operation** Legacy customer scenario. - - -### Microsoft.Windows.SysReset.PBREngineInitSucceed - -This event signals successful handoff between two recovery binaries. - -The following fields are available: - -- **Operation** Legacy customer scenario. - - -### Microsoft.Windows.SysReset.PBRFailedOffline - -This event reports the error code when recovery fails. - -The following fields are available: - -- **HRESULT** Error code for the failure. -- **PBRType** The recovery scenario. -- **SessionID** The unique ID for the recovery session. - - -### Microsoft.Windows.SystemReset.EsimPresentCheck - -This event is sent when a device is checked to see whether it has an embedded SIM (eSIM). - -The following fields are available: - -- **errorCode** Any error that occurred while checking for the presence of an embedded SIM. -- **esimPresent** Indicates whether an embedded SIM is present on the device. -- **sessionID** The ID of this session. - - -### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption - -This event sends corruption repair diagnostic data when the PBRCorruptionRepairOption encounters a corruption error. - -The following fields are available: - -- **cbsSessionOption** The corruption repair configuration. -- **errorCode** The error code encountered. -- **meteredConnection** Indicates whether the device is connected to a metered network (wired or WiFi). -- **sessionID** The globally unique identifier (GUID) for the session. - - -### Microsoft.Windows.SystemReset.RepairNeeded - -This event provides information about whether a system reset needs repair. - -The following fields are available: - -- **repairNeeded** Indicates whether there was corruption in the system reset which needs repair. -- **sessionID** The ID of this push-button reset session. - - -### Microsoft.Windows.UEFI.ESRT - -This event sends basic data during boot about the firmware loaded or recently installed on the machine. This helps to keep Windows up to date. - -The following fields are available: - -- **DriverFirmwareFilename** The firmware file name reported by the device hardware key. -- **DriverFirmwarePolicy** The optional version update policy value. -- **DriverFirmwareStatus** The firmware status reported by the device hardware key. -- **DriverFirmwareVersion** The firmware version reported by the device hardware key. -- **FirmareLastAttemptVersion** No content is currently available. -- **FirmwareId** The UEFI (Unified Extensible Firmware Interface) identifier. -- **FirmwareLastAttemptStatus** The reported status of the most recent firmware installation attempt, as reported by the EFI System Resource Table (ESRT). -- **FirmwareLastAttemptVersion** The version of the most recent attempted firmware installation, as reported by the EFI System Resource Table (ESRT). -- **FirmwareType** The UEFI (Unified Extensible Firmware Interface) type. -- **FirmwareVersion** The UEFI (Unified Extensible Firmware Interface) version as reported by the EFI System Resource Table (ESRT). -- **InitiateUpdate** Indicates whether the system is ready to initiate an update. -- **LastAttemptDate** The date of the most recent attempted firmware installation. -- **LastAttemptStatus** The result of the most recent attempted firmware installation. -- **LastAttemptVersion** The version of the most recent attempted firmware installation. -- **LowestSupportedFirmwareVersion** The oldest (lowest) version of firmware supported. -- **MaxRetryCount** The maximum number of retries, defined by the firmware class key. -- **PartA_PrivTags** The privacy tags associated with the firmware. -- **RetryCount** The number of attempted installations (retries), reported by the driver software key. -- **Status** The status returned to the PnP (Plug-and-Play) manager. -- **UpdateAttempted** Indicates if installation of the current update has been attempted before. - - -### Microsoft.Xbox.XamTelemetry.AppActivationError - -This event indicates whether the system detected an activation error in the app. - -The following fields are available: - -- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. -- **AppId** The Xbox LIVE Title ID. -- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. -- **Result** The HResult error. -- **UserId** The Xbox LIVE User ID (XUID). - - -### Microsoft.Xbox.XamTelemetry.AppActivity - -This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. - -The following fields are available: - -- **AppActionId** The ID of the application action. -- **AppCurrentVisibilityState** The ID of the current application visibility state. -- **AppId** The Xbox LIVE Title ID of the app. -- **AppPackageFullName** The full name of the application package. -- **AppPreviousVisibilityState** The ID of the previous application visibility state. -- **AppSessionId** The application session ID. -- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). -- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. -- **DurationMs** The amount of time (in milliseconds) since the last application state transition. -- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. -- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). -- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. -- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. -- **UserId** The XUID (Xbox User ID) of the current user. - - -### Value - -This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. - -The following fields are available: - -- **Algorithm** The algorithm used to preserve privacy. -- **DPRange** The upper bound of the range being measured. -- **DPValue** The randomized response returned by the client. -- **Epsilon** The level of privacy to be applied. -- **HistType** The histogram type if the algorithm is a histogram algorithm. -- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. - - -### WheaProvider.WheaErrorRecord - -This event collects data about common platform hardware error recorded by the Windows Hardware Error Architecture (WHEA) mechanism. - -The following fields are available: - -- **creatorId** The unique identifier for the entity that created the error record. -- **CreatorId** The unique identifier for the entity that created the error record. -- **errorFlags** Any flags set on the error record. -- **ErrorFlags** Any flags set on the error record. -- **notifyType** The unique identifier for the notification mechanism which reported the error to the operating system. -- **NotifyType** The unique identifier for the notification mechanism which reported the error to the operating system. -- **partitionId** The unique identifier for the partition on which the hardware error occurred. -- **PartitionId** The unique identifier for the partition on which the hardware error occurred. -- **platformId** The unique identifier for the platform on which the hardware error occurred. -- **PlatformId** The unique identifier for the platform on which the hardware error occurred. -- **record** A collection of binary data containing the full error record. -- **Record** A collection of binary data containing the full error record. -- **recordId** The identifier of the error record. -- **RecordId** The identifier of the error record. -- **sectionFlags** The flags for each section recorded in the error record. -- **SectionFlags** The flags for each section recorded in the error record. -- **SectionSeverity** The severity of each individual section. -- **sectionTypes** The unique identifier that represents the type of sections contained in the error record. -- **SectionTypes** The unique identifier that represents the type of sections contained in the error record. -- **severityCount** The severity of each individual section. -- **timeStamp** The error time stamp as recorded in the error record. -- **TimeStamp** The error time stamp as recorded in the error record. - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - ## Sediment events ### Microsoft.Windows.Sediment.Info.DetailedState @@ -5754,6 +5469,175 @@ The following fields are available: - **ValidityWindowInDays** The validity window that's in effect when verifying the timestamp. +## System reset events + +### Microsoft.Windows.SysReset.FlightUninstallCancel + +This event indicates the customer has cancelled uninstallation of Windows. + + + +### Microsoft.Windows.SysReset.FlightUninstallError + +This event sends an error code when the Windows uninstallation fails. + +The following fields are available: + +- **ErrorCode** Error code for uninstallation failure. + + +### Microsoft.Windows.SysReset.FlightUninstallReboot + +This event is sent to signal an upcoming reboot during uninstallation of Windows. + + + +### Microsoft.Windows.SysReset.FlightUninstallStart + +This event indicates that the Windows uninstallation has started. + + + +### Microsoft.Windows.SysReset.FlightUninstallUnavailable + +This event sends diagnostic data when the Windows uninstallation is not available. + +The following fields are available: + +- **AddedProfiles** Indicates that new user profiles have been created since the flight was installed. +- **MissingExternalStorage** Indicates that the external storage used to install the flight is not available. +- **MissingInfra** Indicates that uninstall resources are missing. +- **MovedProfiles** Indicates that the user profile has been moved since the flight was installed. + + +### Microsoft.Windows.SysReset.HasPendingActions + +This event is sent when users have actions that will block the uninstall of the latest quality update. + + + +### Microsoft.Windows.SysReset.IndicateLCUWasUninstalled + +This event is sent when the registry indicates that the latest cumulative Windows update package has finished uninstalling. + +The following fields are available: + +- **errorCode** The error code if there was a failure during uninstallation of the latest cumulative Windows update package. + + +### Microsoft.Windows.SysReset.LCUUninstall + +This event is sent when the latest cumulative Windows update was uninstalled on a device. + +The following fields are available: + +- **errorCode** An error that occurred while the Windows update package was being uninstalled. +- **packageName** The name of the Windows update package that is being uninstalled. +- **removalTime** The amount of time it took to uninstall the Windows update package. + + +### Microsoft.Windows.SysReset.PBRBlockedByPolicy + +This event is sent when a push-button reset operation is blocked by the System Administrator. + +The following fields are available: + +- **PBRBlocked** Reason the push-button reset operation was blocked. +- **PBRType** The type of push-button reset operation that was blocked. + + +### Microsoft.Windows.SysReset.PBREngineInitFailed + +This event signals a failed handoff between two recovery binaries. + +The following fields are available: + +- **Operation** Legacy customer scenario. + + +### Microsoft.Windows.SysReset.PBREngineInitSucceed + +This event signals successful handoff between two recovery binaries. + +The following fields are available: + +- **Operation** Legacy customer scenario. + + +### Microsoft.Windows.SysReset.PBRFailedOffline + +This event reports the error code when recovery fails. + +The following fields are available: + +- **HRESULT** Error code for the failure. +- **PBRType** The recovery scenario. +- **SessionID** The unique ID for the recovery session. + + +### Microsoft.Windows.SystemReset.EsimPresentCheck + +This event is sent when a device is checked to see whether it has an embedded SIM (eSIM). + +The following fields are available: + +- **errorCode** Any error that occurred while checking for the presence of an embedded SIM. +- **esimPresent** Indicates whether an embedded SIM is present on the device. +- **sessionID** The ID of this session. + + +### Microsoft.Windows.SystemReset.PBRCorruptionRepairOption + +This event sends corruption repair diagnostic data when the PBRCorruptionRepairOption encounters a corruption error. + +The following fields are available: + +- **cbsSessionOption** The corruption repair configuration. +- **errorCode** The error code encountered. +- **meteredConnection** Indicates whether the device is connected to a metered network (wired or WiFi). +- **sessionID** The globally unique identifier (GUID) for the session. + + +### Microsoft.Windows.SystemReset.RepairNeeded + +This event provides information about whether a system reset needs repair. + +The following fields are available: + +- **repairNeeded** Indicates whether there was corruption in the system reset which needs repair. +- **sessionID** The ID of this push-button reset session. + + +## UEFI events + +### Microsoft.Windows.UEFI.ESRT + +This event sends basic data during boot about the firmware loaded or recently installed on the machine. This helps to keep Windows up to date. + +The following fields are available: + +- **DriverFirmwareFilename** The firmware file name reported by the device hardware key. +- **DriverFirmwarePolicy** The optional version update policy value. +- **DriverFirmwareStatus** The firmware status reported by the device hardware key. +- **DriverFirmwareVersion** The firmware version reported by the device hardware key. +- **FirmareLastAttemptVersion** No content is currently available. +- **FirmwareId** The UEFI (Unified Extensible Firmware Interface) identifier. +- **FirmwareLastAttemptStatus** The reported status of the most recent firmware installation attempt, as reported by the EFI System Resource Table (ESRT). +- **FirmwareLastAttemptVersion** The version of the most recent attempted firmware installation, as reported by the EFI System Resource Table (ESRT). +- **FirmwareType** The UEFI (Unified Extensible Firmware Interface) type. +- **FirmwareVersion** The UEFI (Unified Extensible Firmware Interface) version as reported by the EFI System Resource Table (ESRT). +- **InitiateUpdate** Indicates whether the system is ready to initiate an update. +- **LastAttemptDate** The date of the most recent attempted firmware installation. +- **LastAttemptStatus** The result of the most recent attempted firmware installation. +- **LastAttemptVersion** The version of the most recent attempted firmware installation. +- **LowestSupportedFirmwareVersion** The oldest (lowest) version of firmware supported. +- **MaxRetryCount** The maximum number of retries, defined by the firmware class key. +- **PartA_PrivTags** The privacy tags associated with the firmware. +- **RetryCount** The number of attempted installations (retries), reported by the driver software key. +- **Status** The status returned to the PnP (Plug-and-Play) manager. +- **UpdateAttempted** Indicates if installation of the current update has been attempted before. + + ## Update events ### Update360Telemetry.Revert @@ -6421,6 +6305,20 @@ The following fields are available: - **ReportId** WER Report Id associated with this bug check (used for finding the corresponding report archive in Watson). +### Value + +This event returns data about Mean Time to Failure (MTTF) for Windows devices. It is the primary means of estimating reliability problems in Basic Diagnostic reporting with very strong privacy guarantees. Since Basic Diagnostic reporting does not include system up-time, and since that information is important to ensuring the safe and stable operation of Windows, the data provided by this event provides that data in a manner which does not threaten a user’s privacy. + +The following fields are available: + +- **Algorithm** The algorithm used to preserve privacy. +- **DPRange** The upper bound of the range being measured. +- **DPValue** The randomized response returned by the client. +- **Epsilon** The level of privacy to be applied. +- **HistType** The histogram type if the algorithm is a histogram algorithm. +- **PertProb** The probability the entry will be Perturbed if the algorithm chosen is “heavy-hitters”. + + ## Windows Error Reporting MTT events ### Microsoft.Windows.WER.MTT.Denominator @@ -6432,6 +6330,60 @@ The following fields are available: - **Value** Standard UTC emitted DP value structure See [Value](#value). +## Windows Hardware Error Architecture events + +### WheaProvider.WheaErrorRecord + +This event collects data about common platform hardware error recorded by the Windows Hardware Error Architecture (WHEA) mechanism. + +The following fields are available: + +- **creatorId** The unique identifier for the entity that created the error record. +- **CreatorId** The unique identifier for the entity that created the error record. +- **errorFlags** Any flags set on the error record. +- **ErrorFlags** Any flags set on the error record. +- **notifyType** The unique identifier for the notification mechanism which reported the error to the operating system. +- **NotifyType** The unique identifier for the notification mechanism which reported the error to the operating system. +- **partitionId** The unique identifier for the partition on which the hardware error occurred. +- **PartitionId** The unique identifier for the partition on which the hardware error occurred. +- **platformId** The unique identifier for the platform on which the hardware error occurred. +- **PlatformId** The unique identifier for the platform on which the hardware error occurred. +- **record** A collection of binary data containing the full error record. +- **Record** A collection of binary data containing the full error record. +- **recordId** The identifier of the error record. +- **RecordId** The identifier of the error record. +- **sectionFlags** The flags for each section recorded in the error record. +- **SectionFlags** The flags for each section recorded in the error record. +- **SectionSeverity** The severity of each individual section. +- **sectionTypes** The unique identifier that represents the type of sections contained in the error record. +- **SectionTypes** The unique identifier that represents the type of sections contained in the error record. +- **severityCount** The severity of each individual section. +- **timeStamp** The error time stamp as recorded in the error record. +- **TimeStamp** The error time stamp as recorded in the error record. + + +## Windows Security Center events + +### Microsoft.Windows.Security.WSC.DatastoreMigratedVersion + +This event provides information about the datastore migration and whether it was successful. + +The following fields are available: + +- **datastoreisvtype** The product category of the datastore. +- **datastoremigrated** The version of the datastore that was migrated. +- **status** The result code of the migration. + + +### Microsoft.Windows.Security.WSC.GetCallerViaWdsp + +This event returns data if the registering product EXE (executable file) does not allow COM (Component Object Model) impersonation. + +The following fields are available: + +- **callerExe** The registering product EXE that does not support COM impersonation. + + ## Windows Store events ### Microsoft.Windows.StoreAgent.Telemetry.AbortedInstallation @@ -7591,6 +7543,31 @@ The following fields are available: - **wuDeviceid** The Windows Update device GUID. +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + ## Windows Update mitigation events ### Microsoft.Windows.Mitigation.AccountTraceLoggingProvider.General @@ -7845,4 +7822,41 @@ This event signals the completion of the setup process. It happens only once dur +## XBOX events + +### Microsoft.Xbox.XamTelemetry.AppActivationError + +This event indicates whether the system detected an activation error in the app. + +The following fields are available: + +- **ActivationUri** Activation URI (Uniform Resource Identifier) used in the attempt to activate the app. +- **AppId** The Xbox LIVE Title ID. +- **AppUserModelId** The AUMID (Application User Model ID) of the app to activate. +- **Result** The HResult error. +- **UserId** The Xbox LIVE User ID (XUID). + + +### Microsoft.Xbox.XamTelemetry.AppActivity + +This event is triggered whenever the current app state is changed by: launch, switch, terminate, snap, etc. + +The following fields are available: + +- **AppActionId** The ID of the application action. +- **AppCurrentVisibilityState** The ID of the current application visibility state. +- **AppId** The Xbox LIVE Title ID of the app. +- **AppPackageFullName** The full name of the application package. +- **AppPreviousVisibilityState** The ID of the previous application visibility state. +- **AppSessionId** The application session ID. +- **AppType** The type ID of the application (AppType_NotKnown, AppType_Era, AppType_Sra, AppType_Uwa). +- **BCACode** The BCA (Burst Cutting Area) mark code of the optical disc used to launch the application. +- **DurationMs** The amount of time (in milliseconds) since the last application state transition. +- **IsTrialLicense** This boolean value is TRUE if the application is on a trial license. +- **LicenseType** The type of licensed used to authorize the app (0 - Unknown, 1 - User, 2 - Subscription, 3 - Offline, 4 - Disc). +- **LicenseXuid** If the license type is 1 (User), this field contains the XUID (Xbox User ID) of the registered owner of the license. +- **ProductGuid** The Xbox product GUID (Globally-Unique ID) of the application. +- **UserId** The XUID (Xbox User ID) of the current user. + + From f3d14e5b74018749b57b5261419bb3642f7b0ecf Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 5 Apr 2019 13:31:18 -0700 Subject: [PATCH 113/737] new build 4/5/2019 1:31 PM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 34 +++++++++---------- 3 files changed, 19 insertions(+), 19 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index b935c25c38..68fa2f43f7 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -2954,7 +2954,7 @@ The following fields are available: - **winInetError** The HResult of the operation. -## Other events +## Privacy logging notification events ### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index ded2f5807f..535e3032d6 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -3142,7 +3142,7 @@ The following fields are available: - **winInetError** The HResult of the operation. -## Other events +## Privacy logging notification events ### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index d65b1aae10..880d63e219 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -4184,23 +4184,6 @@ The following fields are available: - **winInetError** The HResult of the operation. -## Other events - -### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted - -No content is currently available. - -The following fields are available: - -- **cleanupTask** No content is currently available. -- **cleanupTaskResult** No content is currently available. -- **deviceEvaluated** No content is currently available. -- **deviceImpacted** No content is currently available. -- **modalAction** No content is currently available. -- **modalResult** No content is currently available. -- **resetSettingsResult** No content is currently available. - - ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted @@ -4260,6 +4243,23 @@ The following fields are available: - **threadId** The ID of the thread the activity was run on. +## Privacy logging notification events + +### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted + +No content is currently available. + +The following fields are available: + +- **cleanupTask** No content is currently available. +- **cleanupTaskResult** No content is currently available. +- **deviceEvaluated** No content is currently available. +- **deviceImpacted** No content is currently available. +- **modalAction** No content is currently available. +- **modalResult** No content is currently available. +- **resetSettingsResult** No content is currently available. + + ## Remediation events ### Microsoft.Windows.Remediation.Applicable From 7e5f1d273a1ec897b234e43c65c63bedb5df4004 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 13:34:30 -0700 Subject: [PATCH 114/737] draft 1903-3 --- .../windows-10-1703-removed-features.md | 12 ++++++------ .../windows-10-1709-removed-features.md | 15 +++++++-------- .../windows-10-1903-removed-features.md | 17 ++++++++--------- 3 files changed, 21 insertions(+), 23 deletions(-) diff --git a/windows/deployment/planning/windows-10-1703-removed-features.md b/windows/deployment/planning/windows-10-1703-removed-features.md index 9a87eca2b0..45bac44358 100644 --- a/windows/deployment/planning/windows-10-1703-removed-features.md +++ b/windows/deployment/planning/windows-10-1703-removed-features.md @@ -1,6 +1,6 @@ --- -title: Windows 10 Creators Update Deprecated Features -description: Learn about features that were removed in Windows 10 Creators Update (version 1703) +title: Windows 10, version 1703 removed features +description: Learn about features that were removed in Windows 10, version 1703 ms.prod: w10 ms.mktglfcycl: plan ms.localizationpriority: medium @@ -9,15 +9,15 @@ author: lizap ms.date: 10/09/2017 ms.topic: article --- -# Features that are removed or deprecated in Windows 10 Creators Update +# Features that are removed or deprecated in Windows 10, version 1703 -> Applies to: Windows 10 +> Applies to: Windows 10, version 1703 -The following features and functionalities in the Windows 10 Creators Update edition (Windows 10, version 1703) have either been removed from the product in the current release (*Removed*) or are not in active development and are planned for potential removal in subsequent releases (*Deprecated*). +The following features and functionalities in the Windows 10 Creators Update edition (Windows 10, version 1703) have either been removed from the product in the current release (*Removed*) or are not in active development and are planned for potential removal in subsequent releases. This list is intended for IT professionals who are updating operating systems in a commercial environment. The plan and list are subject to change and may not include every deprecated feature or functionality. For more details about a listed feature or functionality and its replacement, see the documentation for that feature. -| Feature | Removed | Deprecated | +| Feature | Removed | Not actively developed | |------------|---------|------------| |Apndatabase.xml is being replaced by the COSA database. Therefore, some constructs will no longer function. This includes Hardware ID, incoming SMS messaging rules in mobile apps, a list of privileged apps in mobile apps, autoconnect order, APN parser, and CDMAProvider ID. | | X | |Apps Corner| | X | diff --git a/windows/deployment/planning/windows-10-1709-removed-features.md b/windows/deployment/planning/windows-10-1709-removed-features.md index cdb6eeb98d..d4796ebda4 100644 --- a/windows/deployment/planning/windows-10-1709-removed-features.md +++ b/windows/deployment/planning/windows-10-1709-removed-features.md @@ -1,25 +1,24 @@ --- -title: Windows 10 Fall Creators Update Deprecated Features -description: Learn about features that will be removed in Windows 10 Fall Creators Update (version 1709) +title: Windows 10, version 1709 removed features +description: Learn about features that will be removed in Windows 10, version 1709 ms.prod: w10 ms.mktglfcycl: plan ms.localizationpriority: medium ms.sitesec: library -author: lizap -ms.date: 10/30/2018 +author: greg-lindsay ms.topic: article --- -# Features that are removed or deprecated in Windows 10 Fall Creators Update +# Features that are removed or deprecated in Windows 10, version 1709 -> Applies to: Windows 10 +> Applies to: Windows 10, version 1709 -The following features and functionalities in the Windows 10 Fall Creators Update (Windows 10, version 1709) are either removed from the product in the current release (*Removed*) or are not in active development and might be removed in future releases (*Deprecated*). +The following features and functionalities in the Windows 10, version 1709 are either removed from the product in the current release (*Removed*) or are not in active development and might be removed in future releases. This list is intended to help customers consider these removals and deprecations for their own planning. The list is subject to change and may not include every deprecated feature or functionality. For more information about a listed feature or functionality and its replacement, see the documentation for that feature. You can also follow the provided links in this table to see additional resources.  -| Feature | Removed | Deprecated | +| Feature | Removed | Not actively developed | |----------|---------|------------| |**3D Builder app**
No longer installed by default. Consider using Print 3D and Paint 3D in its place. However, 3D Builder is still available for download from the Windows Store. | X | | |**Apndatabase.xml**
For more information about the replacement database, see the following Hardware Dev Center articles:
[MO Process to update COSA](/windows-hardware/drivers/mobilebroadband/planning-your-apn-database-submission)
[COSA FAQ](/windows-hardware/drivers/mobilebroadband/cosa---faq) | X | | diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 35b56b17dc..0aa2e0bfad 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -13,20 +13,19 @@ ms.topic: article > Applies to: Windows 10, version 1903 - -
roadmapEach release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. You can get early access to Windows 10 builds by joining the [Windows Insider program](https://insider.windows.com) - this is a great way to test feature changes. -
+Each release of Windows 10 adds new features and functionality; occasionally we also remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. +A great way to test feature changes is to join the [Windows Insider program](https://insider.windows.com), where you can get early access to new Windows 10 builds. **The list is subject to change and might not include every affected feature or functionality.** -## Features we removed in this release +## Features we removed or will remove soon -We're removing the following features and functionalities from the installed product image in Windows 10, version 1809. Applications or code that depend on these features won't function in this release unless you use an alternate method. +The following features and functionalities are removed from the installed product image for Windows 10, version 1903, or are planned for removal in an upcoming release. Applications or code that depend on these features won't function in this release unless you use another method. -|Feature |Instead you can use...| +|Feature |Removed or pending removal|Details| |-----------|-------------------- -|xxxxx|yyyyy| +|Cortana will be removed from Windows 10 in all non-English/US markets. Cortana will still be available for en-us markets. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| |xxxxx|yyyyy| |xxxxx|yyyyy| |xxxxx|yyyyy| @@ -38,9 +37,9 @@ We're no longer actively developing these features and may remove them from a fu If you have feedback about the proposed replacement of any of these features, you can use the [Feedback Hub app](https://support.microsoft.com/help/4021566/windows-10-send-feedback-to-microsoft-with-feedback-hub-app). -|Feature |Instead you can use...| +|Feature |Details| |-----------|---------------------| -|xxxxx|yyyyy| +|Windows To Go|Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEM vendors.| |xxxxx|yyyyy| |xxxxx|yyyyy| |xxxxx|yyyyy| From 0692dcca4f7fc51d6809f304a26b58378032dcf4 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 5 Apr 2019 16:16:49 -0700 Subject: [PATCH 115/737] draft 1903-4 --- .../windows-10-1903-removed-features.md | 27 ++++++++----------- 1 file changed, 11 insertions(+), 16 deletions(-) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 0aa2e0bfad..262f6dcd60 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -13,23 +13,23 @@ ms.topic: article > Applies to: Windows 10, version 1903 -Each release of Windows 10 adds new features and functionality; occasionally we also remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1903. +Each release of Windows 10 adds new features and functionality; occasionally we also remove features and functionality, usually because we've added a better option. Below are the details about the features and functionalities that we removed in Windows 10, version 1903. **The list below is subject to change and might not include every affected feature or functionality.** -A great way to test feature changes is to join the [Windows Insider program](https://insider.windows.com), where you can get early access to new Windows 10 builds. - -**The list is subject to change and might not include every affected feature or functionality.** +**Note**: Join the [Windows Insider program](https://insider.windows.com) to get early access to new Windows 10 builds and test these changes yourself. ## Features we removed or will remove soon The following features and functionalities are removed from the installed product image for Windows 10, version 1903, or are planned for removal in an upcoming release. Applications or code that depend on these features won't function in this release unless you use another method. -|Feature |Removed or pending removal|Details| -|-----------|-------------------- +|Feature |Status|Details| +|-----------|--------------------|--------- |Cortana will be removed from Windows 10 in all non-English/US markets. Cortana will still be available for en-us markets. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| -|xxxxx|yyyyy| -|xxxxx|yyyyy| -|xxxxx|yyyyy| -|xxxxx|yyyyy| +|XDDM-based Remote Desktop driver|Removed|The default driver for remote desktop was switched to the IDD for a single-user scenarios. We plan to use IDD as default for all use cases and anounce deprecation of XP Display Driver Model (XDDM) based RD fdriver| +|Desktop messaging app doesn't offer messages sync |Removed|The messaging app on Desktop has a sync feature that can be used to sync SMS text messages received from Windows Mobile and keep a copy of them on the Desktop. We will be removing the messaging app from Desktop devices in a future release. When sync is removed, you will only be able to access messages from the device that received the message.| +|Print 3D app|Removed|The Print 3D app will no longer be installed automatically in a future release of Windows. It will remain available for download from the Store. To 3D print objects on a new Windows devices, you must first install the app (1P or 3P app) from the Store.| +|My People / People|Pending removal|The **My People** experience will be removed in a future release.| +|UCS log collection tool|Pending removal|The UCS log collection tool is being replaced by the Feedback hub| +|Wi-Fi WEP and TKIP|Removed|Wi-Fi networks that are secured with passwords using older WEP and TKIP protocals are not as secure as those secured with new protocols such as WPA, WPA2, and soon WPA3. In this release, connecting to WEP or TKIP network will show a warning message that the network is not secure. In a future release any connection to a Wi-Fi network using these old protocols will be disallowed. | ## Features we’re no longer developing @@ -39,10 +39,5 @@ If you have feedback about the proposed replacement of any of these features, yo |Feature |Details| |-----------|---------------------| -|Windows To Go|Windows To Go is no longer being developed. The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEM vendors.| -|xxxxx|yyyyy| -|xxxxx|yyyyy| -|xxxxx|yyyyy| -|xxxxx|yyyyy| - +|Windows To Go|Windows To Go is no longer being developed.

The feature does not support feature updates and therefore does not enable you to stay current. It also requires a specific type of USB that is no longer supported by many OEMs.| From 9eab9e5e2868ede66accadbb88059bd3ffe9dc8f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 8 Apr 2019 08:27:05 -0700 Subject: [PATCH 116/737] new build 4/8/2019 8:27 AM --- ...l-windows-diagnostic-events-and-fields-1903.md | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 451bee2d3f..92e4aa33bf 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/05/2019 +ms.date: 04/07/2019 --- @@ -2769,7 +2769,7 @@ The following fields are available: - **ProblemStatus** The status of the device after the driver installation. - **SecondaryDevice** Indicates whether the device is a secondary device. - **ServiceName** The service name of the driver. -- **SetupMode** Indicates whether the driver installation took place before the initial installation of the device was completed. +- **SetupMode** Indicates whether the driver installation took place before the Out Of Box Experience (OOBE) was completed. - **StartTime** The time when the installation started. - **SubmissionId** The driver submission identifier assigned by the Windows Hardware Development Center. - **UpperFilters** The list of upper filter drivers. @@ -2789,8 +2789,8 @@ The following fields are available: - **InstallFlags** The driver installation flags. - **RebootRequired** Indicates whether a reboot is required after the installation. - **RollbackPossible** Indicates whether this driver can be rolled back. -- **WuTargetedHardwareId** No content is currently available. -- **WuUntargetedHardwareId** No content is currently available. +- **WuTargetedHardwareId** Indicates that the driver was installed because the device hardware ID was targeted by the Windows Update. +- **WuUntargetedHardwareId** Indicates that the driver was installed because Windows Update performed a generic driver update for all devices of that hardware class. ### Microsoft.Windows.DriverInstall.NewDevInstallDeviceStart @@ -3956,7 +3956,7 @@ The following fields are available: - **LastCompatibleId** The ID in the hardware ID list that provides the least specific device description. - **Legacy** Indicates whether the driver is a legacy driver. - **NeedReboot** Indicates whether the driver requires a reboot. -- **SetupMode** Indicates whether the device configuration occurred during the initial installation of the device. +- **SetupMode** Indicates whether the device configuration occurred during the Out Of Box Experience (OOBE). - **StatusCode** The NTSTATUS of device configuration operation. @@ -4181,7 +4181,7 @@ The following fields are available: ### Microsoft.Windows.PBR.EnteredOOBE -This event is sent when the initial installation of the device starts after completion of the push-button reset operation. +This event is sent when the push-button reset (PRB) process enters the Out Of Box Experience (OOBE). The following fields are available: @@ -4644,7 +4644,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PhaseStarted -No content is currently available. +This event is sent when a phase of the push-button reset (PBR) operation starts. The following fields are available: @@ -5620,7 +5620,6 @@ The following fields are available: - **DriverFirmwarePolicy** The optional version update policy value. - **DriverFirmwareStatus** The firmware status reported by the device hardware key. - **DriverFirmwareVersion** The firmware version reported by the device hardware key. -- **FirmareLastAttemptVersion** No content is currently available. - **FirmwareId** The UEFI (Unified Extensible Firmware Interface) identifier. - **FirmwareLastAttemptStatus** The reported status of the most recent firmware installation attempt, as reported by the EFI System Resource Table (ESRT). - **FirmwareLastAttemptVersion** The version of the most recent attempted firmware installation, as reported by the EFI System Resource Table (ESRT). From dd585ea017d4d5a4c42b374594b816babf4754ba Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 8 Apr 2019 08:27:15 -0700 Subject: [PATCH 117/737] new build 4/8/2019 8:27 AM --- .../basic-level-windows-diagnostic-events-and-fields-1703.md | 2 +- .../basic-level-windows-diagnostic-events-and-fields-1709.md | 2 +- .../basic-level-windows-diagnostic-events-and-fields-1803.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 68fa2f43f7..98a6fb916a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/05/2019 +ms.date: 04/07/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 535e3032d6..ccd32531ba 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/05/2019 +ms.date: 04/07/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 880d63e219..e0f05d671e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/05/2019 +ms.date: 04/07/2019 --- From cb62bd8a7f39966e10068a696fa0445cf1fe4792 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Mon, 8 Apr 2019 08:53:16 -0700 Subject: [PATCH 118/737] remove ms.date from new/updated topics for 19H1 --- windows/configuration/wcd/wcd-cellular.md | 1 - windows/configuration/wcd/wcd-changes.md | 1 - windows/configuration/wcd/wcd-deviceupdatecenter.md | 1 - windows/configuration/wcd/wcd-oobe.md | 1 - windows/configuration/wcd/wcd-policies.md | 1 - windows/configuration/wcd/wcd-privacy.md | 1 - windows/configuration/wcd/wcd-storaged3inmodernstandby.md | 1 - windows/configuration/wcd/wcd-time.md | 1 - windows/configuration/wcd/wcd-wlan.md | 1 - 9 files changed, 9 deletions(-) diff --git a/windows/configuration/wcd/wcd-cellular.md b/windows/configuration/wcd/wcd-cellular.md index 9c292c9e3d..fdee985945 100644 --- a/windows/configuration/wcd/wcd-cellular.md +++ b/windows/configuration/wcd/wcd-cellular.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # Cellular (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-changes.md b/windows/configuration/wcd/wcd-changes.md index 571f137000..684114268a 100644 --- a/windows/configuration/wcd/wcd-changes.md +++ b/windows/configuration/wcd/wcd-changes.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # Changes to settings in Windows Configuration Designer diff --git a/windows/configuration/wcd/wcd-deviceupdatecenter.md b/windows/configuration/wcd/wcd-deviceupdatecenter.md index 09f2af4d12..e8431b2555 100644 --- a/windows/configuration/wcd/wcd-deviceupdatecenter.md +++ b/windows/configuration/wcd/wcd-deviceupdatecenter.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # DeviceUpdateCenter (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-oobe.md b/windows/configuration/wcd/wcd-oobe.md index 31af250386..f36cfa5e0f 100644 --- a/windows/configuration/wcd/wcd-oobe.md +++ b/windows/configuration/wcd/wcd-oobe.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # OOBE (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-policies.md b/windows/configuration/wcd/wcd-policies.md index a2098f93b8..e1c039a10c 100644 --- a/windows/configuration/wcd/wcd-policies.md +++ b/windows/configuration/wcd/wcd-policies.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # Policies (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-privacy.md b/windows/configuration/wcd/wcd-privacy.md index ad2a699688..1e754ef32f 100644 --- a/windows/configuration/wcd/wcd-privacy.md +++ b/windows/configuration/wcd/wcd-privacy.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # Privacy (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-storaged3inmodernstandby.md b/windows/configuration/wcd/wcd-storaged3inmodernstandby.md index a866ee0dab..64f3ae3dc7 100644 --- a/windows/configuration/wcd/wcd-storaged3inmodernstandby.md +++ b/windows/configuration/wcd/wcd-storaged3inmodernstandby.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 09/06/2017 --- # StorageD3InModernStandby (Windows Configuration Designer reference) diff --git a/windows/configuration/wcd/wcd-time.md b/windows/configuration/wcd/wcd-time.md index b81a6d8f1c..c0ff2212ce 100644 --- a/windows/configuration/wcd/wcd-time.md +++ b/windows/configuration/wcd/wcd-time.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 05/21/2019 --- # Time diff --git a/windows/configuration/wcd/wcd-wlan.md b/windows/configuration/wcd/wcd-wlan.md index 1064831115..141a45bb7f 100644 --- a/windows/configuration/wcd/wcd-wlan.md +++ b/windows/configuration/wcd/wcd-wlan.md @@ -8,7 +8,6 @@ author: jdeckerMS ms.localizationpriority: medium ms.author: jdecker ms.topic: article -ms.date: 10/02/2018 --- # WLAN (reference) From c37e9090ec403646b1ff558804d6c60e436ca4de Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 9 Apr 2019 08:38:06 -0700 Subject: [PATCH 119/737] new build 4/9/2019 8:38 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 92e4aa33bf..34823fd12d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/07/2019 +ms.date: 04/09/2019 --- From 2c3b8fdf79507321990e18f920f6988faf0e1034 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 9 Apr 2019 08:38:15 -0700 Subject: [PATCH 120/737] new build 4/9/2019 8:38 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 263 +++++++----------- 4 files changed, 105 insertions(+), 164 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 98a6fb916a..f49cb11ad8 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/07/2019 +ms.date: 04/09/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index ccd32531ba..4481851e43 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/07/2019 +ms.date: 04/09/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index e0f05d671e..ff2f76bd70 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/07/2019 +ms.date: 04/09/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 21218c05f5..21821ed181 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/05/2019 +ms.date: 04/08/2019 --- @@ -1741,8 +1741,6 @@ The following fields are available: - **PCFP** An ID for the system calculated by hashing hardware identifiers. - **PerfBackoff** Indicates if the run was invoked with logic to stop running when a user is present. Helps to understand why a run may have a longer elapsed time than normal. - **PerfBackoffInsurance** Indicates if appraiser is running without performance backoff because it has run with perf backoff and failed to complete several times in a row. -- **PerfBnDroff** No content is currently available. -- **PerfBnDroffInsurance** No content is currently available. - **RunAppraiser** Indicates if Appraiser was set to run at all. If this if false, it is understood that data events will not be received from this device. - **RunDate** The date that the telemetry run was stated, expressed as a filetime. - **RunGeneralTel** Indicates if the generaltel.dll component was run. Generaltel collects additional telemetry on an infrequent schedule and only from machines at telemetry levels higher than Basic. @@ -1807,7 +1805,6 @@ Provides information on IE and Census versions running on the device The following fields are available: -- **App�aiserRunEndTimeStamp** No content is currently available. - **AppraiserEnterpriseErrorCode** The error code of the last Appraiser enterprise run. - **AppraiserErrorCode** The error code of the last Appraiser run. - **AppraiserRunEndTimeStamp** The end time of the last Appraiser run. @@ -1875,10 +1872,8 @@ This event sends data about the BIOS and startup embedded in the device, to help The following fields are available: -- **Firmware�anufacturer** No content is currently available. - **FirmwareManufacturer** Represents the manufacturer of the device's firmware (BIOS). - **FirmwareReleaseDate** Represents the date the current firmware was released. -- **FirmwareRele�seDate** No content is currently available. - **FirmwareType** Represents the firmware type. The various types can be unknown, BIOS, UEFI. - **FirmwareVersion** Represents the version of the current firmware. @@ -1891,7 +1886,6 @@ The following fields are available: - **DeviceSampleRate** The telemetry sample rate assigned to the device. - **EnablePreviewBuilds** Used to enable Windows Insider builds on a device. -- **EnablePrevi�wBuilds** No content is currently available. - **FlightIds** A list of the different Windows Insider builds on this device. - **FlightingBranchName** The name of the Windows Insider branch currently used by the device. - **IsFlightsDisabled** Represents if the device is participating in the Windows Insider program. @@ -2253,7 +2247,6 @@ The following fields are available: - **AppStoreAutoUpdate** Retrieves the Appstore settings for auto upgrade. (Enable/Disabled). - **AppStoreAutoUpdateMDM** Retrieves the App Auto Update value for MDM: 0 - Disallowed. 1 - Allowed. 2 - Not configured. Default: [2] Not configured - **AppStoreAutoUpdatePolicy** Retrieves the Microsoft Store App Auto Update group policy setting -- **AppStoreAutoUpd�te** No content is currently available. - **DelayUpgrade** Retrieves the Windows upgrade flag for delaying upgrades. - **OSAssessmentFeatureOutOfDate** How many days has it been since a the last feature update was released but the device did not install it? - **OSAssessmentForFeatureUpdate** Is the device is on the latest feature update? @@ -2748,7 +2741,6 @@ The following fields are available: - **CensusStartTime** Returns timestamp corresponding to last successful census run. - **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. - **LastConnectivityLossTime** Retrieves the last time the device lost free network. -- **LastGonnectivityLossTime** No content is currently available. - **NetworkState** Retrieves the network state: 0 = No network. 1 = Restricted network. 2 = Free network. - **NoNetworkTime** Retrieves the time spent with no network (since the last time) in seconds. - **RestrictedNetworkTime** Retrieves the time spent on a metered (cost restricted) network in seconds. @@ -2766,7 +2758,6 @@ The following fields are available: - **CensusTaskEnabled** True if Census is enabled, false otherwise. - **CompressedBytesUploaded** Number of compressed bytes uploaded. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. -- **CriticaDataThrottleDroppedCount** No content is currently available. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. @@ -2779,7 +2770,6 @@ The following fields are available: - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. -- **EventStoreLhfetimeResetCounter** No content is currently available. - **EventStoreLifetimeResetCounter** Number of times event DB was reset for the lifetime of UTC. - **EventStoreResetCounter** Number of times event DB was reset. - **EventStoreResetSizeSum** Total size of event DB across all resets reports in this instance. @@ -2792,7 +2782,6 @@ The following fields are available: - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. -- **LastInvalhdHttpCode** No content is currently available. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. @@ -2803,7 +2792,6 @@ The following fields are available: - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. -- **TopUploaderErross** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. @@ -3416,19 +3404,15 @@ The following fields are available: - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiSeqId** The event sequence ID. -- **B2ightnessVersionViaDDI** No content is currently available. - **bootId** The system boot ID. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **Dedic`tedSystemMemoryB** No content is currently available. -- **DedicatedSystemMemorqB** No content is currently available. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. -- **DX10UM@FilePath** No content is currently available. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. @@ -3449,11 +3433,9 @@ The following fields are available: - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? - **IsRemovable** TRUE if the adapter supports being disabled or removed. -- **IsRenderDdvice** No content is currently available. - **IsRenderDevice** Does the GPU have rendering capabilities? - **IsSoftwareDevice** Is this a software implementation of the GPU? - **KMDFilePath** The file path to the location of the Display Kernel Mode Driver in the Driver Store. -- **MeastreEnabled** No content is currently available. - **MeasureEnabled** Is the device listening to MICROSOFT_KEYWORD_MEASURES? - **MsHybridDiscrete** Indicates whether the adapter is a discrete adapter in a hybrid configuration. - **NumVidPnSources** The number of supported display output sources. @@ -3463,7 +3445,6 @@ The following fields are available: - **SubVendorID** The GPU sub vendor ID. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **Tel�nvEvntTrigger** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. @@ -3552,11 +3533,8 @@ This event sends data about crashes for both native and managed applications, to The following fields are available: - **AppName** The name of the app that has crashed. -- **AppSessionGqid** No content is currently available. -- **AppSessionGui`** No content is currently available. - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. - **AppTimeStamp** The date/time stamp of the app. -- **AppVarsion** No content is currently available. - **AppVersion** The version of the app that has crashed. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. @@ -3564,19 +3542,13 @@ The following fields are available: - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). -- **ModPimeStamp** No content is currently available. -- **ModTimeSpamp** No content is currently available. - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. -- **PackaceRelativeAppId** No content is currently available. - **PackageFullName** Store application identity. -- **PackageRelativeAppHd** No content is currently available. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. - **ProcessCreateTime** The time of creation of the process that has crashed. -- **ProcessI`** No content is currently available. - **ProcessId** The ID of the process that has crashed. -- **ReportAd** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported @@ -3698,7 +3670,6 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **HiddenAr`** No content is currently available. - **HiddenArp** Indicates whether a program hides itself from showing up in ARP. - **InstallDate** The date the application was installed (a best guess based on folder creation date heuristics). - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 @@ -3707,15 +3678,12 @@ The following fields are available: - **InventoryVersion** The version of the inventory file generating the events. - **Language** The language code of the program. - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiPqckageCode** No content is currently available. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. -- **OSVersionAtI~stallTi}e** No content is currently available. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. - **PackageFullName** The package full name for a Store application. - **ProgramInstanceId** A hash of the file IDs in an app. - **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RootDibPath** No content is currently available. - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. @@ -3924,8 +3892,6 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **** No content is currently available. -- **€** No content is currently available. - **BusReportedDescription** The description of the device reported by the bux. - **Class** The device setup class of the driver loaded for the device. - **ClassGuid** The device class unique identifier of the driver package loaded on the device. @@ -3939,8 +3905,6 @@ The following fields are available: - **DriverId** The unique identifier for the installed driver. - **DriverName** The name of the driver image file. - **DriverPackageStrongName** The immediate parent directory name in the Directory field of InventoryDriverPackage. -- **DriverPackageStrongName** No content is currently available. -- **DriverV** No content is currently available. - **DriverVerDate** The date associated with the driver installed on the device. - **DriverVerVersion** The version number of the driver installed on the device. - **Enumerator** Identifies the bus that enumerated the device. @@ -4581,6 +4545,19 @@ The following fields are available: - **UserInputTime** The amount of time the loader application spent waiting for user input. +## Migration events + +### Microsoft.Windows.MigrationCore.MigObjectCountKFSys + +This event returns data about the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **knownFoldersSys[i]** The predefined folder path locations. +- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. +- **objectCount** The count of the number of objects that are being transferred. + + ## Miracast events ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd @@ -4760,19 +4737,61 @@ The following fields are available: - **winInetError** The HResult of the operation. -## Other events +## Privacy consent logging events -### Microsoft.Windows.MigrationCore.MigObjectCountKFSys +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted -This event returns data about the count of the migration objects across various phases during feature update. +This event is used to determine whether the user successfully completed the privacy consent experience. The following fields are available: -- **knownFoldersSys[i]** The predefined folder path locations. -- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. -- **objectCount** The count of the number of objects that are being transferred. +- **presentationVersion** Which display version of the privacy consent experience the user completed +- **privacyConsentState** The current state of the privacy consent experience +- **settingsVersion** Which setting version of the privacy consent experience the user completed +- **userOobeExitReason** The exit reason of the privacy consent experience +### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus + +Event tells us effectiveness of new privacy experience. + +The following fields are available: + +- **isAdmin** whether the person who is logging in is an admin +- **isExistingUser** whether the account existed in a downlevel OS +- **isLaunching** Whether or not the privacy consent experience will be launched +- **isSilentElevation** whether the user has most restrictive UAC controls +- **privacyConsentState** whether the user has completed privacy experience +- **userRegionCode** The current user's region setting + + +### wilActivity + +This event provides a Windows Internal Library context used for Product and Service diagnostics. + +The following fields are available: + +- **callContext** The function where the failure occurred. +- **currentContextId** The ID of the current call context where the failure occurred. +- **currentContextMessage** The message of the current call context where the failure occurred. +- **currentContextName** The name of the current call context where the failure occurred. +- **failureCount** The number of failures for this failure ID. +- **failureId** The ID of the failure that occurred. +- **failureType** The type of the failure that occurred. +- **fileName** The file name where the failure occurred. +- **function** The function where the failure occurred. +- **hresult** The HResult of the overall activity. +- **lineNumber** The line number where the failure occurred. +- **message** The message of the failure that occurred. +- **module** The module where the failure occurred. +- **originatingContextId** The ID of the originating call context that resulted in the failure. +- **originatingContextMessage** The message of the originating call context that resulted in the failure. +- **originatingContextName** The name of the originating call context that resulted in the failure. +- **threadId** The ID of the thread on which the activity is executing. + + +## Remediation events + ### Microsoft.Windows.Remediation.Applicable This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. @@ -5069,6 +5088,46 @@ The following fields are available: - **RunCount** The number of times the remediation event started (whether it completed successfully or not). +## Sediment events + +### Microsoft.Windows.Sediment.Info.DetailedState + +This event is sent when detailed state information is needed from an update trial run. + +The following fields are available: + +- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. +- **Id** Identifies the trial being run, such as a disk related trial. +- **ReleaseVer** The version of the component. +- **State** The state of the reporting data from the trial, such as the top-level directory analysis. +- **Time** The time the event was fired. + + +### Microsoft.Windows.Sediment.Info.Error + +This event indicates an error in the updater payload. This information assists in keeping Windows up to date. + +The following fields are available: + +- **FailureType** The type of error encountered. +- **FileName** The code file in which the error occurred. +- **HResult** The failure error code. +- **LineNumber** The line number in the code file at which the error occurred. +- **ReleaseVer** The version information for the component in which the error occurred. +- **Time** The system time at which the error occurred. + + +### Microsoft.Windows.Sediment.Info.PhaseChange + +The event indicates progress made by the updater. This information assists in keeping Windows up to date. + +The following fields are available: + +- **NewPhase** The phase of progress made. +- **ReleaseVer** The version information for the component in which the change occurred. +- **Time** The system time at which the phase chance occurred. + + ### Microsoft.Windows.SedimentLauncher.Applicable Indicates whether a given plugin is applicable. @@ -5170,99 +5229,6 @@ The following fields are available: - **Result** This is the HRESULT for Detection or Perform Action phases of the plugin. -## Privacy consent logging events - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted - -This event is used to determine whether the user successfully completed the privacy consent experience. - -The following fields are available: - -- **presentationVersion** Which display version of the privacy consent experience the user completed -- **privacyConsentState** The current state of the privacy consent experience -- **settingsVersion** Which setting version of the privacy consent experience the user completed -- **userOobeExitReason** The exit reason of the privacy consent experience - - -### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentStatus - -Event tells us effectiveness of new privacy experience. - -The following fields are available: - -- **isAdmin** whether the person who is logging in is an admin -- **isExistingUser** whether the account existed in a downlevel OS -- **isLaunching** Whether or not the privacy consent experience will be launched -- **isSilentElevation** whether the user has most restrictive UAC controls -- **privacyConsentState** whether the user has completed privacy experience -- **userRegionCode** The current user's region setting - - -### wilActivity - -This event provides a Windows Internal Library context used for Product and Service diagnostics. - -The following fields are available: - -- **callContext** The function where the failure occurred. -- **currentContextId** The ID of the current call context where the failure occurred. -- **currentContextMessage** The message of the current call context where the failure occurred. -- **currentContextName** The name of the current call context where the failure occurred. -- **failureCount** The number of failures for this failure ID. -- **failureId** The ID of the failure that occurred. -- **failureType** The type of the failure that occurred. -- **fileName** The file name where the failure occurred. -- **function** The function where the failure occurred. -- **hresult** The HResult of the overall activity. -- **lineNumber** The line number where the failure occurred. -- **message** The message of the failure that occurred. -- **module** The module where the failure occurred. -- **originatingContextId** The ID of the originating call context that resulted in the failure. -- **originatingContextMessage** The message of the originating call context that resulted in the failure. -- **originatingContextName** The name of the originating call context that resulted in the failure. -- **threadId** The ID of the thread on which the activity is executing. - - -## Sediment events - -### Microsoft.Windows.Sediment.Info.DetailedState - -This event is sent when detailed state information is needed from an update trial run. - -The following fields are available: - -- **Data** Data relevant to the state, such as what percent of disk space the directory takes up. -- **Id** Identifies the trial being run, such as a disk related trial. -- **ReleaseVer** The version of the component. -- **State** The state of the reporting data from the trial, such as the top-level directory analysis. -- **Time** The time the event was fired. - - -### Microsoft.Windows.Sediment.Info.Error - -This event indicates an error in the updater payload. This information assists in keeping Windows up to date. - -The following fields are available: - -- **FailureType** The type of error encountered. -- **FileName** The code file in which the error occurred. -- **HResult** The failure error code. -- **LineNumber** The line number in the code file at which the error occurred. -- **ReleaseVer** The version information for the component in which the error occurred. -- **Time** The system time at which the error occurred. - - -### Microsoft.Windows.Sediment.Info.PhaseChange - -The event indicates progress made by the updater. This information assists in keeping Windows up to date. - -The following fields are available: - -- **NewPhase** The phase of progress made. -- **ReleaseVer** The version information for the component in which the change occurred. -- **Time** The system time at which the phase chance occurred. - - ## Setup events ### SetupPlatformTel.SetupPlatformTelActivityEvent @@ -6840,7 +6806,6 @@ This event is sent at the end of an app install or update to help keep Windows u The following fields are available: - **CatalogId** The name of the product catalog from which this app was chosen. -- **FailddRetry** No content is currently available. - **FailedRetry** Indicates whether the installation or update retry was successful. - **HResult** The HResult code of the operation. - **PFN** The Package Family Name of the app that is being installed or updated. @@ -7046,7 +7011,6 @@ The following fields are available: - **background** Is the download a background download? - **bytesFromCacheServer** Bytes received from a cache host. - **bytesFromCDN** The number of bytes received from a CDN source. -- **bytesFromG2oupPeers** No content is currently available. - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. - **bytesFromLinkLocalPeers** The number of bytes received from local peers. @@ -7055,7 +7019,6 @@ The following fields are available: - **bytesRequested** The total number of bytes requested for download. - **cacheServerConnectionCount** Number of connections made to cache hosts. - **cdnConnectionCount** The total number of connections made to the CDN. -- **cdnErrorCkdes** No content is currently available. - **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. - **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. - **cdnIp** The IP address of the source CDN. @@ -7063,20 +7026,14 @@ The following fields are available: - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. - **dataSourcEsTotal** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. -- **doErrorCohe** No content is currently available. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). - **downloadMode** The download mode used for this file download session. - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **downloadodel** No content is currently available. -- **downloadodelSrc** No content is currently available. -- **downlo�dMode** No content is currently available. -- **downlwadModeSvc** No content is currently available. - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. - **expiresAt** The time when the content will expire from the Delivery Optimization Cache. - **fileID** The ID of the file being downloaded. -- **fileSaze** No content is currently available. - **fileSize** The size of the file being downloaded. - **gCurMemoryStreamBytes** Current usage for memory streaming. - **gMaxMemoryStreamBytes** Maximum usage for memory streaming. @@ -7086,20 +7043,15 @@ The following fields are available: - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. - **lanConnectionCount** The total number of connections made to peers in the same LAN. -- **larConnectionCount** No content is currently available. - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. -- **nUrConnectionCount** No content is currently available. -- **nUrIp** No content is currently available. -- **precefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. - **sessionID** The ID of the download session. - **totalTimeMs** Duration of the download (in seconds). - **updateID** The ID of the update being downloaded. -- **uphinkUsag,Bps** No content is currently available. - **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). - **uplinkUsageBps** The upload speed (in bytes per second). - **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. @@ -7118,7 +7070,6 @@ The following fields are available: - **fileID** The ID of the file being paused. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. -- **precefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller object. - **reasonCode** The reason for pausing the download. - **routeToCacheServer** The cache server setting, source, and value. @@ -7133,7 +7084,6 @@ This event sends data describing the start of a new download to enable Delivery The following fields are available: - **background** Indicates whether the download is happening in the background. -- **bytesReqeested** No content is currently available. - **bytesRequested** Number of bytes requested for the download. - **cdnUrl** The URL of the source Content Distribution Network (CDN). - **costFlags** A set of flags representing network cost. @@ -7144,8 +7094,6 @@ The following fields are available: - **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). -- **downloadodel** No content is currently available. -- **downloadodelSrc** No content is currently available. - **errorCode** The error code that was returned. - **experimentId** ID used to correlate client/services calls that are part of the same test during A/B testing. - **fileID** The ID of the file being downloaded. @@ -7157,7 +7105,6 @@ The following fields are available: - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. - **peerID** The ID for this delivery optimization client. -- **precefinedCallerName** No content is currently available. - **predefinedCallerName** Name of the API caller. - **routeToCacheServer** Cache server setting, source, and value. - **sessionID** The ID for the file download session. @@ -7181,7 +7128,6 @@ The following fields are available: - **experimentId** When running a test, this is used to correlate with other events that are part of the same test. - **fileID** The ID of the file being downloaded. - **httpStatusCode** The HTTP status code returned by the CDN. -- **isHeadRepuest** No content is currently available. - **isHeadRequest** The type of HTTP request that was sent to the CDN. Example: HEAD or GET - **peerType** The type of peer (LAN, Group, Internet, CDN, Cache Host, etc.). - **requestOffset** The byte offset within the file in the sent request. @@ -7635,19 +7581,14 @@ This event indicates that the update is no longer applicable to this device. The following fields are available: -- **_]TlgCV__** No content is currently available. - **EventPublishedTime** Time when this event was generated. - **flightID** The specific ID of the Windows Insider build. -- **flkghtID** No content is currently available. - **inapplicableReason** The reason why the update is inapplicable. -- **qevisionLumber** No content is currently available. - **revisionNumber** Update revision number. - **updateId** Unique Windows Update ID. - **updateScenarioType** Update session type. - **UpdateStatus** Last status of update. -- **upgateId** No content is currently available. - **UUPFallBackConfigured** Indicates whether UUP fallback is configured. -- **UUPFallBackConfigused** No content is currently available. - **wuDeviceid** Unique Device ID. From d38f75054d7a8e7093602aa084ee616c3da3870d Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Tue, 9 Apr 2019 15:55:37 -0700 Subject: [PATCH 121/737] added new redirects --- .openpublishing.redirection.json | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index ab677cc666..ff7e5c472d 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -1047,7 +1047,12 @@ }, { "source_path": "windows/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-alerts", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-alerts", "redirect_document_id": true }, { From 2c847b994aa04b920b23aa258ab61f562a7f3f3c Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 10 Apr 2019 07:58:08 -0700 Subject: [PATCH 122/737] new build 4/10/2019 7:58 AM --- ...el-windows-diagnostic-events-and-fields-1903.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 34823fd12d..bd6c4e2161 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/09/2019 +ms.date: 04/10/2019 --- @@ -4466,7 +4466,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPostApplyFailed -No content is currently available. +This event returns data indicating the failure of the reset/recovery process after the operating system files are restored. The following fields are available: @@ -4475,7 +4475,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPostApplyFinished -No content is currently available. +This event returns data indicating the completion of the reset/recovery process after the operating system files are restored. The following fields are available: @@ -4484,7 +4484,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPostApplyStarted -No content is currently available. +This event returns data indicating the start of the reset/recovery process after the operating system files are restored. The following fields are available: @@ -4493,7 +4493,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPreApplyFailed -No content is currently available. +This event returns data indicating the failure of the reset/recovery process before the operating system files are restored. The following fields are available: @@ -4502,7 +4502,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPreApplyFinished -No content is currently available. +This event returns data indicating the completion of the reset/recovery process before the operating system files are restored. The following fields are available: @@ -4511,7 +4511,7 @@ The following fields are available: ### Microsoft.Windows.PBR.PBRPreApplyStarted -No content is currently available. +This event returns data indicating the start of the reset/recovery process before the operating system files are restored. The following fields are available: From e9d5f1efa1a143e25d58bde7338313248efd2cd1 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 10 Apr 2019 07:58:14 -0700 Subject: [PATCH 123/737] new build 4/10/2019 7:58 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 6 +- ...ndows-diagnostic-events-and-fields-1709.md | 6 +- ...ndows-diagnostic-events-and-fields-1803.md | 6 +- ...ndows-diagnostic-events-and-fields-1809.md | 63 ++++++------------- 4 files changed, 27 insertions(+), 54 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index f49cb11ad8..cc4a260492 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/09/2019 +ms.date: 04/10/2019 --- @@ -2975,7 +2975,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. +This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: @@ -3059,7 +3059,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event enables completion tracking of a process that remediates issues preventing security and quality updates. +This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 4481851e43..aef6875c51 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/09/2019 +ms.date: 04/10/2019 --- @@ -3163,7 +3163,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. +This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: @@ -3266,7 +3266,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event enables completion tracking of a process that remediates issues preventing security and quality updates. +This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index ff2f76bd70..1b2f1c8932 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/09/2019 +ms.date: 04/10/2019 --- @@ -4264,7 +4264,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. +This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: @@ -4368,7 +4368,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event enables completion tracking of a process that remediates issues preventing security and quality updates. +This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 21821ed181..a5e90b5538 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/08/2019 +ms.date: 04/10/2019 --- @@ -4794,7 +4794,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates a remedial plug-in is applicable if/when such a plug-in is detected. This is used to ensure Windows is up to date. +This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: @@ -4802,13 +4802,13 @@ The following fields are available: - **AllowAutoUpdateProviderSetExists** No content is currently available. - **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. -- **AppraiserTaskRepairDisabled** No content is currently available. -- **AppraiserTaskValid** No content is currently available. -- **AUOptionsExists** No content is currently available. +- **AppraiserTaskRepairDisabled** Task repair performed by the appraiser plugin is disabled. +- **AppraiserTaskValid** Indicates that the appraiser task is valid. +- **AUOptionsExists** Indicates whether the Automatic Update option exist. - **CTACTargetingAttributesInvalid** No content is currently available. - **CTACVersion** No content is currently available. - **CV** Correlation vector -- **DataStoreSizeInBytes** No content is currently available. +- **DataStoreSizeInBytes** Size of the data store, in bytes. - **DateTimeDifference** The difference between local and reference clock times. - **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. - **daysSinceInstallThreshold** No content is currently available. @@ -4983,7 +4983,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event enables completion tracking of a process that remediates issues preventing security and quality updates. +This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. The following fields are available: @@ -5019,9 +5019,9 @@ The following fields are available: - **RemediationBatteryPowerOnBattery** True if we allow execution on battery. - **RemediationConfigurationTroubleshooterIpconfigFix** TRUE if IPConfig Fix completed successfully. - **RemediationConfigurationTroubleshooterNetShFix** TRUE if network card cache reset ran successfully. -- **RemediationCorruptionRepairCorruptionsDetected** No content is currently available. -- **RemediationCorruptionRepairCorruptionsFixed** No content is currently available. -- **RemediationCorruptionRepairPerformActionSuccessful** No content is currently available. +- **RemediationCorruptionRepairCorruptionsDetected** Number of corruptions detected on the device. +- **RemediationCorruptionRepairCorruptionsFixed** Number of detected corruptions that were fixed on the device. +- **RemediationCorruptionRepairPerformActionSuccessful** Indicates whether corruption repair was successful on the device. - **remediationExecution** Remediation shell is in "applying remediation" state. - **RemediationHibernationMigrated** TRUE if hibernation was migrated. - **RemediationHibernationMigrationSucceeded** TRUE if hibernation migration succeeded. @@ -5036,9 +5036,9 @@ The following fields are available: - **RemediationUpdateServiceHealthRemediationResult** The result of the Update Service Health plug-in. - **RemediationUpdateTaskHealthRemediationResult** The result of the Update Task Health plug-in. - **RemediationUpdateTaskHealthTaskList** A list of tasks fixed by the Update Task Health plug-in. -- **RemediationUSORebootRequred** No content is currently available. +- **RemediationUSORebootRequred** Indicates whether a reboot is determined to be required by calling the Update Service Orchestrator (USO). - **Result** The HRESULT for Detection or Perform Action phases of the plug-in. -- **RunCount** No content is currently available. +- **RunCount** The number of times the plugin has executed. - **RunResult** The HRESULT for Detection or Perform Action phases of the plug-in. - **ServiceHardeningExitCode** The exit code returned by Windows Service Repair. - **ServiceHealthEnabledBitMap** List of services updated by the plugin. @@ -5136,9 +5136,9 @@ The following fields are available: - **CV** Correlation vector. - **DetectedCondition** Boolean true if detect condition is true and perform action will be run. -- **FileVersion** No content is currently available. +- **FileVersion** The version of the data-link library (DLL) that will be applied by the self-update process. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **IsHashMismatch** No content is currently available. +- **IsHashMismatch** Indicates whether the hash is a mismatch. - **IsSelfUpdateEnabledInOneSettings** True if self update enabled in Settings. - **IsSelfUpdateNeeded** True if self update needed by device. - **PackageVersion** Current package version of Remediation. @@ -5182,9 +5182,9 @@ The following fields are available: - **CV** Correlation vector. - **DetectedCondition** Determine whether action needs to run based on device properties. -- **FileVersion** No content is currently available. +- **FileVersion** The version of the dynamic-link library (DLL) that will be applied by the self-update process. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **IsHashMismatch** No content is currently available. +- **IsHashMismatch** Indicates whether the hash is a mismatch. - **IsSelfUpdateEnabledInOneSettings** Indicates if self update is enabled in One Settings. - **IsSelfUpdateNeeded** Indicates if self update is needed. - **PackageVersion** Current package version of Remediation. @@ -5208,9 +5208,9 @@ The following fields are available: - **SedimentServiceCurrentBytes** Number of current private bytes of memory consumed by sedsvc.exe. - **SedimentServiceKillService** True/False if service is marked for kill (Shell.KillService). - **SedimentServiceMaximumBytes** Maximum bytes allowed for the service. -- **SedimentServiceRanShell** No content is currently available. +- **SedimentServiceRanShell** Indicates whether the shell was run by the service. - **SedimentServiceRetrievedKillService** True/False if result of One Settings check for kill succeeded - we only send back one of these indicators (not for each call). -- **SedimentServiceShellRunHResult** No content is currently available. +- **SedimentServiceShellRunHResult** The HRESULT returned when the shell was run by the service. - **SedimentServiceStopping** True/False indicating whether the service is stopping. - **SedimentServiceTaskFunctional** True/False if scheduled task is functional. If task is not functional this indicates plugins will be run. - **SedimentServiceTotalIterations** Number of 5 second iterations service will wait before running again. @@ -5263,10 +5263,8 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: -- **CroupName** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **Valqe** No content is currently available. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -5278,9 +5276,6 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: -- **9ctivityMatchingId** No content is currently available. -- **9llowCachedResults** No content is currently available. -- **9pplicableUpdateInfo** No content is currently available. - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. - **AllowCachedResults** Indicates if the scan allowed using cached results. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable @@ -5320,18 +5315,15 @@ The following fields are available: - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 -- **IsWTfBEnabled** No content is currently available. - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. - **IsWUfBFederatedScanDisabled** Indicates if Windows Update for Business federated scan is disabled on the device. - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce -- **MetadataYntegrityMode** No content is currently available. - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required -- **NumberOfNewUpdatesFòomServiceSync** No content is currently available. - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan - **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan - **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. @@ -5360,7 +5352,6 @@ The following fields are available: - **TargetMetadataVersion** For self-initiated healing, this is the target version of the SIH engine to download (if needed). If not, the value is null. - **TotalNumMetadataSignatures** The total number of metadata signatures checks done for new metadata that was synced down. - **WebServiceRetryMethods** Web service method requests that needed to be retried to complete operation. -- **WEDeviceID** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5401,14 +5392,11 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: -- **ActimeDownloadTime** No content is currently available. -- **ActiveDown¬oadTime** No content is currently available. - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. - **AppXDownloadScope** Indicates the scope of the download for application content. - **AppXScope** Indicates the scope of the app download. -- **AppXU3s8aHashFailures** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5428,7 +5416,6 @@ The following fields are available: - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. -- **ClientVersion€WUDeviceID** No content is currently available. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. @@ -5440,11 +5427,9 @@ The following fields are available: - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. - **EventType** Identifies the type of the event (Child, Bundle, or Driver). - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. -- **FdightBuildNumber** No content is currently available. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. -- **FlighTBuildNumber** No content is currently available. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). - **HandlerType** Indicates what kind of content is being downloaded (app, driver, windows patch, etc.). @@ -5461,7 +5446,6 @@ The following fields are available: - **PackageFullName** The package name of the content. - **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. - **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. -- **ppXBlockHashFailures** No content is currently available. - **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. - **Reason** A 32-bit integer representing the reason the update is blocked from being downloaded in the background. @@ -5470,14 +5454,12 @@ The following fields are available: - **RelatedCV** The Correlation Vector that was used before the most recent change to a new Correlation Vector. - **RepeatFailCount** Indicates whether this specific content has previously failed. - **RepeatFailFlag** Indicates whether this specific content previously failed to download. -- **RevisionN´mber** No content is currently available. - **RevisionNumber** The revision number of the specified piece of content. - **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). -- **StatusCodeÀExtendedStatusCode** No content is currently available. - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. - **TargetGroupId** For drivers targeted to a specific device model, this ID indicates the distribution group of devices receiving that driver. @@ -5492,7 +5474,6 @@ The following fields are available: - **UpdatEImportance** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. -- **WUDeviceHD** No content is currently available. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5554,8 +5535,6 @@ This event sends tracking data about the software distribution client installati The following fields are available: -- **œßæ½ßüØÆÔîÐck** No content is currently available. -- **2À@=2§3F'™+ck** No content is currently available. - **BiosFamily** The family of the BIOS (Basic Input Output System). - **BiosName** The name of the device BIOS. - **BiosReleaseDate** The release date of the device BIOS. @@ -5582,7 +5561,6 @@ The following fields are available: - **EventType** Possible values are Child, Bundle, or Driver. - **ExtendedErrorCode** The extended error code. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode is not specific enough. -- **ExtendEdStatusCode** No content is currently available. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in the Windows Insider Program. - **FlightBuildNumber** If this installation was for a Windows Insider build, this is the build number of that build. @@ -5740,7 +5718,6 @@ The following fields are available: - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable. - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **ItentPFNs** No content is currently available. - **NumberOfApplicableUpdates** The number of updates ultimately deemed applicable to the system after the detection process is complete. - **RelatedCV** The previous Correlation Vector that was used before swapping with a new one. - **ServiceGuid** An ID that represents which service the software distribution client is connecting to (Windows Update, Microsoft Store, etc.). @@ -5866,7 +5843,6 @@ The following fields are available: - **PackageCountTotalExpress** Total number of express packages. - **PackageCountTotalPSFX** The total number of PSFX packages. - **PackageExpressType** Type of express package. -- **PackageSizeCanonicad** No content is currently available. - **PackageSizeCanonical** Size of canonical packages in bytes. - **PackageSizeDiff** Size of diff packages in bytes. - **PackageSizeExpress** Size of express packages in bytes. @@ -6632,7 +6608,6 @@ This event is sent after the license is acquired when a product is being install The following fields are available: -- **AcgregatedPackageFullNames** No content is currently available. - **AggregatedPackageFullNames** Includes a set of package full names for each app that is part of an atomic set. - **AttemptNumber** The total number of attempts to acquire this product. - **CategoryId** The identity of the package or packages being installed. @@ -6733,7 +6708,6 @@ The following fields are available: - **ClientAppId** The identity of the app that initiated this operation. - **HResult** The result code of the last action performed. - **IsApplicability** Is this request to only check if there are any applicable packages to install? -- **IsInteractime** No content is currently available. - **IsInteractive** Is this user requested? - **IsOnline** Is the request doing an online check? @@ -7024,7 +6998,6 @@ The following fields are available: - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dataSourcEsTotal** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). From 61224eba217beb356a32d829c296658cf3d49a95 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Wed, 10 Apr 2019 10:39:43 -0700 Subject: [PATCH 124/737] path update --- .openpublishing.redirection.json | 35 ++++++++++++++++--- ...ows-defender-advanced-threat-protection.md | 10 +++--- 2 files changed, 34 insertions(+), 11 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index ff7e5c472d..068c8c88fa 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -856,28 +856,53 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-features", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-features", +"redirect_document_id": false +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/alerts-queue", "redirect_document_id": true }, { "source_path": "windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/alerts-queue", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping", "redirect_document_id": true }, { "source_path": "windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access", "redirect_document_id": true }, { "source_path": "windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status", "redirect_document_id": true }, { "source_path": "windows/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status", "redirect_document_id": true }, { diff --git a/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md index 1ec412b1f3..9b89a258e4 100644 --- a/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md @@ -22,21 +22,19 @@ ms.date: 04/24/2018 **Applies to:** - - [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - - >Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-suppressionrules-abovefoldlink) -There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md#suppress-alerts). +There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md). You can view a list of all the suppression rules and manage them in one place. You can also turn an alert suppression rule on or off. ## Turn a suppression rule on or off + 1. In the navigation pane, select **Settings** > **Alert suppression**. The list of suppression rules that users in your organization have created is displayed. -2. Select a rule by clicking on the check-box beside the rule name. +2. Select a rule by clicking on the check-box beside the rule name. 3. Click **Turn rule on** or **Turn rule off**. @@ -47,5 +45,5 @@ You can view a list of all the suppression rules and manage them in one place. Y 2. Click on a rule name. Details of the rule is displayed. You'll see the rule details such as status, scope, action, number of matching alerts, created by, and date when the rule was created. You can also view associated alerts and the rule conditions. ## Related topics -- [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) \ No newline at end of file From 72bb5b050586e4c18ca48b69e00cbb99d6f0af77 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 13:49:48 -0700 Subject: [PATCH 125/737] change folder name to mdatp from wdatp --- .../TOC.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...lerts-queue-endpoint-detection-response.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../api-hello-world.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../apis-intro.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../configure-attack-surface-reduction.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../configure-microsoft-threat-experts.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../custom-detection-rules.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../deprecate.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../evaluate-atp.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../exposed-apis-create-app-nativeapp.md | 0 .../exposed-apis-create-app-webapp.md | 0 .../exposed-apis-full-sample-powershell.md | 0 .../exposed-apis-list.md | 0 .../exposed-apis-odata-samples.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 156 ++--- ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 152 ++--- ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 152 ++--- ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 166 ++--- ...defender-advanced-threat-protection-new.md | 0 .../get-started.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../images/1.png | Bin .../images/AH_icon.png | Bin .../images/AR_icon.png | Bin .../images/ASR_icon.png | Bin .../images/EDR_icon.jpg | Bin .../images/EDR_icon.png | Bin .../images/Failed.png | Bin .../images/MTE_icon.jpg | Bin .../images/MTE_icon.png | Bin .../images/NGP_icon.jpg | Bin .../images/NGP_icon.png | Bin .../images/No threats found.png | Bin .../images/Partially investigated.png | Bin .../images/Partially remediated.png | Bin .../images/Pending.png | Bin .../images/Remediated.png | Bin .../images/Running.png | Bin .../images/SS_icon.png | Bin .../images/TVM_icon.png | Bin .../images/Terminated by system.png | Bin .../images/WDATP-components.png | Bin .../images/active-alerts-tile.png | Bin .../images/active-threat-icon.png | Bin .../images/advanced-features.png | Bin .../images/advanced-hunting-query-example.PNG | Bin .../images/advanced-hunting-save-query.PNG | Bin .../images/alert-details.png | Bin .../images/alert-icon.png | Bin .../images/alerts-q-bulk.png | Bin .../images/alerts-queue-list.png | Bin .../images/alerts-queue-numbered.png | Bin .../images/analysis-results.png | Bin .../images/api-jwt-ms.png | Bin .../images/api-tenant-id.png | Bin .../atp-Application-Guard-events-icon.png | Bin .../images/atp-Device-Guard-events-icon.png | Bin .../images/atp-ETW-event-icon.png | Bin .../images/atp-Exploit-Guard-events-icon.png | Bin .../images/atp-File-path-icon.png | Bin .../images/atp-Firewall-events-icon.png | Bin .../images/atp-O365-admin-portal-customer.png | Bin .../images/atp-Other-events-icon.png | Bin .../images/atp-Smart-Screen-events-icon.png | Bin .../atp-access-token-modification-icon.png | Bin .../images/atp-action-block-file.png | Bin .../atp-action-center-app-restriction.png | Bin .../atp-action-center-package-collection.png | Bin .../images/atp-action-center-restrict-app.png | Bin .../images/atp-action-center-with-info.png | Bin .../images/atp-actions-action-center.png | Bin ...-actions-collect-investigation-package.png | Bin .../images/atp-actions-isolate-machine.png | Bin .../images/atp-actions-manage-tags.png | Bin .../atp-actions-release-from-isolation.png | Bin .../atp-actions-release-from-isoloation.png | Bin .../atp-actions-remove-app-restrictions.png | Bin .../atp-actions-restrict-app-execution.png | Bin .../images/atp-actions-run-av.png | Bin .../images/atp-active-investigations-tile.png | Bin .../images/atp-actor-alert.png | Bin .../images/atp-actor-report.png | Bin .../images/atp-actor.png | Bin .../images/atp-add-application-name.png | Bin .../images/atp-add-application.png | Bin .../images/atp-add-intune-policy.png | Bin .../images/atp-advanced-hunting-query.png | Bin .../atp-advanced-hunting-results-filter.PNG | Bin .../atp-advanced-hunting-results-set.png | Bin .../images/atp-advanced-hunting.png | Bin .../images/atp-alert-details.png | Bin .../images/atp-alert-mgt-pane.png | Bin .../images/atp-alert-page.png | Bin .../images/atp-alert-process-tree.png | Bin .../images/atp-alert-source.png | Bin .../images/atp-alert-status.png | Bin .../images/atp-alert-timeline-numbered.png | Bin .../images/atp-alert-timeline.png | Bin .../images/atp-alert-view.png | Bin .../images/atp-alerts-group.png | Bin .../images/atp-alerts-q.png | Bin .../images/atp-alerts-queue-user.png | Bin .../images/atp-alerts-queue.png | Bin .../images/atp-alerts-related-to-file.png | Bin .../images/atp-alerts-related-to-machine.PNG | Bin .../images/atp-alerts-selected.png | Bin .../images/atp-alerts-tile.png | Bin .../images/atp-alertsq1.png | Bin .../images/atp-alertsq2.png | Bin .../images/atp-analyze-auto-ir.png | Bin .../images/atp-app-restriction.png | Bin .../images/atp-application-information.png | Bin .../images/atp-approve-reject-action.png | Bin .../images/atp-appsource.png | Bin .../images/atp-auto-investigation-pending.png | Bin .../images/atp-auto-investigations-list.png | Bin ...tp-automated-investigations-statistics.png | Bin .../images/atp-av-scan-action-center.png | Bin .../images/atp-av-scan-notification.png | Bin .../images/atp-azure-api-access.png | Bin .../images/atp-azure-assign-role.png | Bin .../images/atp-azure-atp-app.png | Bin .../images/atp-azure-atp-machine-user.png | Bin .../images/atp-azure-atp-machine.png | Bin .../images/atp-azure-create.png | Bin .../images/atp-azure-intune-category.png | Bin .../images/atp-azure-intune-configure.png | Bin ...p-azure-intune-create-policy-configure.png | Bin .../atp-azure-intune-create-policy-name.png | Bin .../images/atp-azure-intune-create-policy.png | Bin .../atp-azure-intune-create-profile.png | Bin .../images/atp-azure-intune-create.png | Bin .../images/atp-azure-intune-device-config.png | Bin .../images/atp-azure-intune-save-policy.png | Bin .../images/atp-azure-intune-save.png | Bin .../images/atp-azure-intune-select-group.png | Bin .../atp-azure-intune-settings-configure.png | Bin .../images/atp-azure-intune.png | Bin .../images/atp-azure-license-icon.png | Bin .../images/atp-azure-new-app.png | Bin .../images/atp-azure-required-permissions.png | Bin .../images/atp-azure-select-permissions.png | Bin .../images/atp-azure-ui-user-access.png | Bin .../images/atp-billing-licenses.png | Bin .../images/atp-billing-subscriptions.png | Bin .../images/atp-block-file-confirm.png | Bin .../images/atp-block-file.png | Bin .../images/atp-blockfile.png | Bin .../atp-cloud-discovery-dashboard-menu.png | Bin .../atp-collect-investigation-package.png | Bin .../images/atp-command-line-icon.png | Bin .../images/atp-community-center.png | Bin .../atp-conditional-access-numbered.png | Bin .../images/atp-conditional-access.png | Bin .../images/atp-confirm-isolate.png | Bin .../images/atp-create-dashboard.png | Bin .../images/atp-create-suppression-rule.png | Bin .../images/atp-custom-oma-uri.png | Bin .../images/atp-custom-ti-mapping.png | Bin .../images/atp-daily-machines-reporting.png | Bin .../atp-dashboard-security-analytics-9.png | Bin .../atp-dashboard-security-analytics-full.png | Bin .../atp-dashboard-security-analytics.png | Bin .../images/atp-data-not-available.png | Bin .../images/atp-data-ready.png | Bin .../images/atp-data-retention-policy.png | Bin .../images/atp-delete-query.png | Bin .../images/atp-detailed-actor.png | Bin .../images/atp-disableantispyware-regkey.png | Bin .../images/atp-download-connector.png | Bin .../images/atp-enable-security-analytics.png | Bin .../images/atp-example-email-notification.png | Bin .../atp-export-machine-timeline-events.png | Bin .../images/atp-file-action.png | Bin .../images/atp-file-creation-icon.png | Bin .../images/atp-file-details.png | Bin .../images/atp-file-in-org.png | Bin .../images/atp-file-information.png | Bin .../images/atp-file-observed-icon.png | Bin .../images/atp-filter-advanced-hunting.png | Bin ...rd-endpoints-warning-before-atp-access.png | Bin .../images/atp-final-preference-setup.png | Bin .../images/atp-geographic-location-setup.png | Bin .../images/atp-get-data.png | Bin .../images/atp-gpo-proxy1.png | Bin .../images/atp-gpo-proxy2.png | Bin .../images/atp-image.png | Bin .../images/atp-improv-opps-9.png | Bin .../images/atp-improv-opps.png | Bin .../images/atp-improv-ops.png | Bin .../images/atp-incident-details-page.png | Bin .../images/atp-incident-details.png | Bin .../images/atp-incident-evidence-tab.png | Bin .../images/atp-incident-graph-details.png | Bin .../images/atp-incident-graph-tab.png | Bin .../images/atp-incident-graph.png | Bin .../atp-incident-investigations-tab.png | Bin .../images/atp-incident-machine-tab.png | Bin .../images/atp-incident-queue.png | Bin ...ncidents-alerts-incidentlinkedbyreason.png | Bin .../atp-incidents-alerts-linkedbytooltip.png | Bin .../images/atp-incidents-alerts-reason.png | Bin .../images/atp-incidents-alerts-tooltip.png | Bin .../images/atp-incidents-mgt-pane.png | Bin .../images/atp-industry-information.png | Bin .../images/atp-intune-add-oma.png | Bin .../images/atp-intune-add-policy.png | Bin .../images/atp-intune-assignments.png | Bin .../images/atp-intune-configure.png | Bin .../images/atp-intune-create-policy.png | Bin .../images/atp-intune-custom.png | Bin .../images/atp-intune-deploy-policy.png | Bin .../images/atp-intune-group.png | Bin .../images/atp-intune-manage-deployment.png | Bin .../images/atp-intune-new-policy.png | Bin .../images/atp-intune-oma-uri-setting.png | Bin .../images/atp-intune-policy-name.png | Bin .../images/atp-intune-save-deployment.png | Bin .../images/atp-intune-save-policy.png | Bin ...tp-investigation-package-action-center.png | Bin .../images/atp-isolate-machine.png | Bin .../images/atp-licensing-azure-portal.png | Bin .../images/atp-loading.png | Bin .../images/atp-logo-icon.png | Bin .../images/atp-machine-actions-undo.png | Bin .../images/atp-machine-actions.png | Bin .../images/atp-machine-details-view.png | Bin .../images/atp-machine-details-view2.png | Bin .../images/atp-machine-health-details.png | Bin .../images/atp-machine-health.png | Bin .../images/atp-machine-icon.png | Bin .../atp-machine-investigation-package.png | Bin .../images/atp-machine-isolation.png | Bin .../atp-machine-timeline-details-panel.png | Bin .../images/atp-machine-timeline-export.png | Bin .../images/atp-machine-timeline-filter.png | Bin .../images/atp-machine-timeline.png | Bin .../images/atp-machine-view-ata.png | Bin .../atp-machines-active-threats-tile.png | Bin .../images/atp-machines-at-risk.png | Bin .../atp-machines-list-misconfigured.png | Bin .../images/atp-machines-list-view.png | Bin .../images/atp-machines-list-view2.png | Bin .../images/atp-machines-timeline.png | Bin .../images/atp-machines-view-list.png | Bin .../images/atp-main-portal.png | Bin .../images/atp-manage-tags.png | Bin .../images/atp-mapping 3.png | Bin .../images/atp-mapping1.png | Bin .../images/atp-mapping2.png | Bin .../images/atp-mapping3.png | Bin .../images/atp-mapping4.png | Bin .../images/atp-mapping5.png | Bin .../images/atp-mapping6.png | Bin .../images/atp-mapping7.png | Bin .../images/atp-mcas-settings.png | Bin .../images/atp-mdm-onboarding-package.png | Bin .../images/atp-memory-allocation-icon.png | Bin .../images/atp-mma-properties.png | Bin .../images/atp-mma.png | Bin .../images/atp-module-load-icon.png | Bin .../images/atp-ms-secure-score-9.png | Bin .../images/atp-ms-secure-score.png | Bin .../atp-network-communications-icon.png | Bin .../images/atp-new-alerts-list.png | Bin .../images/atp-new-suppression-rule.png | Bin .../images/atp-no-network-connection.png | Bin .../images/atp-no-subscriptions-found.png | Bin .../atp-not-authorized-to-access-portal.png | Bin .../images/atp-notification-action.png | Bin .../atp-notification-collect-package.png | Bin .../images/atp-notification-file.png | Bin .../images/atp-notification-isolate.png | Bin .../images/atp-notification-restrict.png | Bin .../images/atp-notifications.png | Bin .../images/atp-observed-in-organization.png | Bin .../images/atp-observed-machines.png | Bin .../images/atp-oma-uri-values.png | Bin ...ard-endpoints-WDATP-portal-border-test.png | Bin .../atp-onboard-endpoints-WDATP-portal.png | Bin ...p-onboard-endpoints-run-detection-test.png | Bin .../images/atp-onboard-endpoints.png | Bin .../images/atp-onboard-mdm.png | Bin .../images/atp-org-score.png | Bin .../images/atp-org-sec-score.png | Bin .../images/atp-organization-size.png | Bin .../images/atp-pending-actions-auto-ir.png | Bin .../images/atp-pending-actions-file.png | Bin .../images/atp-pending-actions-list.png | Bin .../images/atp-pending-actions-multiple.png | Bin .../atp-pending-actions-notification.png | Bin .../images/atp-permissions-applications.png | Bin .../images/atp-portal-sensor.png | Bin .../images/atp-portal-welcome-screen.png | Bin .../images/atp-portal.png | Bin .../images/atp-powerbi-accept.png | Bin .../images/atp-powerbi-consent.png | Bin .../images/atp-powerbi-extension.png | Bin .../images/atp-powerbi-get-data.png | Bin .../images/atp-powerbi-importing.png | Bin .../images/atp-powerbi-navigator.png | Bin .../images/atp-powerbi-options.png | Bin .../images/atp-powerbi-preview.png | Bin .../atp-powershell-command-run-icon.png | Bin .../images/atp-preferences-setup.png | Bin .../images/atp-preview-experience.png | Bin .../images/atp-preview-features.png | Bin .../images/atp-process-event-icon.png | Bin .../images/atp-process-injection.png | Bin .../images/atp-process-tree.png | Bin .../images/atp-refresh-token.png | Bin .../images/atp-region-control-panel.png | Bin .../images/atp-registry-event-icon.png | Bin .../images/atp-remediated-alert.png | Bin .../images/atp-remove-blocked-file.png | Bin .../images/atp-rename-incident.png | Bin .../images/atp-respond-action-icon.png | Bin .../images/atp-restrict-app.png | Bin .../images/atp-run-av-scan.png | Bin .../images/atp-running-script.png | Bin .../images/atp-sample-custom-ti-alert.png | Bin .../images/atp-save-query.png | Bin .../images/atp-save-tag.png | Bin .../images/atp-sec-coverage.png | Bin .../images/atp-sec-ops-1.png | Bin .../images/atp-sec-ops-dashboard.png | Bin .../atp-security-analytics-dashboard.png | Bin .../atp-security-analytics-view-machines.png | Bin .../atp-security-analytics-view-machines2.png | Bin .../images/atp-security-controls-9.png | Bin .../images/atp-security-controls.png | Bin .../images/atp-security-coverage.png | Bin .../images/atp-security-improvements.png | Bin .../images/atp-security-score-over-time-9.png | Bin .../images/atp-security-score-over-time.png | Bin .../images/atp-sensor-filter.png | Bin .../atp-sensor-health-filter-resized.png | Bin .../images/atp-sensor-health-filter-tile.png | Bin .../images/atp-sensor-health-filter.png | Bin .../images/atp-sensor-health-nonav.png | Bin .../images/atp-sensor-health-tile.png | Bin .../atp-server-offboarding-workspaceid.png | Bin .../atp-server-onboarding-workspaceid.png | Bin .../images/atp-server-onboarding.png | Bin .../images/atp-services.png | Bin .../images/atp-settings-aip.png | Bin .../images/atp-settings-powerbi.png | Bin .../images/atp-setup-complete.png | Bin .../images/atp-setup-incomplete.png | Bin .../atp-setup-permissions-wdatp-portal.png | Bin .../images/atp-shared-queries.png | Bin .../images/atp-siem-integration.png | Bin .../images/atp-siem-mapping1.png | Bin .../images/atp-siem-mapping13.png | Bin .../images/atp-siem-mapping2.png | Bin .../images/atp-siem-mapping3.png | Bin .../images/atp-siem-mapping4.png | Bin .../images/atp-signer-icon.png | Bin .../images/atp-simulate-custom-ti.png | Bin .../images/atp-stop-quarantine-file.png | Bin .../images/atp-stop-quarantine.png | Bin .../images/atp-stopnquarantine-file.png | Bin .../images/atp-subscription-expired.png | Bin .../images/atp-suppression-rules.png | Bin .../images/atp-suspicious-activities-tile.png | Bin .../images/atp-tag-management.png | Bin .../images/atp-task-manager.png | Bin .../images/atp-threat-intel-api.png | Bin .../images/atp-threat-protection-reports.png | Bin .../images/atp-thunderbolt-icon.png | Bin .../images/atp-tile-sensor-health.png | Bin .../images/atp-time-zone.png | Bin .../images/atp-undo-isolation.png | Bin .../images/atp-unsigned-file-icon.png | Bin .../images/atp-user-details-pane.png | Bin .../images/atp-user-details-view-azureatp.png | Bin .../images/atp-user-details-view-tdp.png | Bin .../images/atp-user-details-view.png | Bin .../images/atp-user-details.png | Bin .../images/atp-user-view-ata.png | Bin .../images/atp-users-at-risk.png | Bin .../images/atp-verify-passive-mode.png | Bin .../atp-windows-cloud-instance-creation.png | Bin .../atp-windows-defender-av-events-icon.png | Bin .../images/atp.png | Bin .../images/azure-data-discovery.png | Bin .../images/cloud-apps.png | Bin .../images/cloud-discovery.png | Bin .../images/components.png | Bin .../images/creating-account.png | Bin .../images/dashboard.png | Bin .../images/detection-icon.png | Bin .../images/enable_siem.png | Bin .../images/filter-log.png | Bin .../images/io.png | Bin ...ws-defender-advanced-threat-protection.png | Bin .../images/machine-reports.png | Bin .../images/machines-active-threats-tile.png | Bin .../images/machines-at-risk-tile.png | Bin .../images/machines-at-risk.png | Bin .../images/machines-list.png | Bin .../images/machines-reporting-tile.png | Bin .../images/menu-icon.png | Bin .../images/ms-flow-choose-action.png | Bin .../images/ms-flow-define-action.png | Bin .../images/ms-flow-e2e.png | Bin .../images/ms-flow-insert-db.png | Bin .../images/ms-flow-parse-json.png | Bin .../images/ms-flow-read-db.png | Bin .../images/mss.png | Bin .../images/nativeapp-add-permission.png | Bin .../images/nativeapp-add-permissions-end.png | Bin .../images/nativeapp-create.png | Bin .../images/nativeapp-decoded-token.png | Bin .../images/nativeapp-get-appid.png | Bin .../images/nativeapp-select-permissions.png | Bin .../images/new-secure-score-dashboard.png | Bin .../images/new-ssot.png | Bin .../images/no-threats-found.png | Bin .../images/no_threats_found.png | Bin .../images/not-remediated-icon.png | Bin .../images/office-scc-label.png | Bin .../images/overview.png | Bin .../images/partially-investigated.png | Bin .../images/partially_investigated.png | Bin .../images/partially_remediated.png | Bin .../images/power-bi-create-advanced-query.png | Bin .../images/power-bi-create-blank-query.png | Bin .../images/power-bi-edit-credentials.png | Bin .../images/power-bi-edit-data-privacy.png | Bin .../images/power-bi-open-advanced-editor.png | Bin .../images/power-bi-query-results.png | Bin .../power-bi-set-credentials-anonymous.png | Bin ...bi-set-credentials-organizational-cont.png | Bin ...ower-bi-set-credentials-organizational.png | Bin .../images/power-bi-set-data-privacy.png | Bin .../images/remediated-icon.png | Bin .../images/rules-legend.png | Bin .../images/run-as-admin.png | Bin .../images/save-query.png | Bin .../images/sccm-deployment.png | Bin .../images/sec-ops-dashboard.png | Bin .../images/securescore.png | Bin .../images/settings.png | Bin .../images/setup-preferences.png | Bin .../images/setup-preferences2.png | Bin .../images/siem_details.png | Bin .../images/ss1.png | Bin .../images/ssot.png | Bin .../images/status-tile.png | Bin .../images/submit-file.png | Bin .../images/ta.png | Bin .../images/terminated-by-system.png | Bin .../images/terminated_by_system.png | Bin .../images/threat-analytics-report.png | Bin .../images/top-recommendations.png | Bin .../images/wdatp-pillars.png | Bin .../images/wdatp-pillars2.png | Bin .../images/wdsc.png | Bin .../images/webapp-add-permission-2.png | Bin .../images/webapp-add-permission-end.png | Bin .../webapp-add-permission-readalerts.png | Bin .../images/webapp-add-permission.png | Bin .../images/webapp-app-id1.png | Bin .../images/webapp-create-key.png | Bin .../images/webapp-create.png | Bin .../images/webapp-decoded-token.png | Bin .../images/webapp-edit-multitenant.png | Bin .../images/webapp-edit-settings.png | Bin .../images/webapp-get-appid.png | Bin .../images/webapp-grant-permissions.png | Bin .../images/webapp-select-permission.png | Bin .../images/webapp-validate-token.png | Bin .../images/welcome1.png | Bin .../images/win10-endpoint-users.png | Bin .../images/windefatp-sc-qc-diagtrack.png | Bin .../images/windefatp-sc-query-diagtrack.png | Bin .../images/windefatp-sc-query.png | Bin .../windefatp-utc-console-autostart.png | Bin ...ender-system-guard-boot-time-integrity.png | Bin ...system-guard-validate-system-integrity.png | Bin .../images/windows-defender-system-guard.png | Bin .../improverequestperformance-new.md | 0 .../incidents-queue.md | 0 ...nformation-protection-in-windows-config.md | 0 ...ormation-protection-in-windows-overview.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../machineactionsnote.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../manage-edr.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../management-apis.md | 0 .../microsoft-cloud-app-security-config.md | 0 ...icrosoft-cloud-app-security-integration.md | 0 .../microsoft-threat-experts.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../onboard.md | 0 .../overview-attack-surface-reduction.md | 0 .../overview-custom-detections.md | 0 .../overview-endpoint-detection-response.md | 0 .../overview-hardware-based-isolation.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../overview.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../prerelease.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../run-advanced-query-api.md | 0 .../run-advanced-query-sample-ms-flow.md | 0 ...dvanced-query-sample-power-bi-app-token.md | 0 ...vanced-query-sample-power-bi-user-token.md | 0 .../run-advanced-query-sample-powershell.md | 0 .../run-advanced-query-sample-python.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../threat-analytics.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../threat-protection-integration.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 624 +++++++++--------- ...ows-defender-advanced-threat-protection.md | 0 .../troubleshoot-wdatp.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../use-apis.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...ows-defender-advanced-threat-protection.md | 0 ...defender-advanced-threat-protection-new.md | 0 .../view-incidents-queue.md | 0 .../whats-new-in-windows-defender-atp.md | 0 ...ows-defender-advanced-threat-protection.md | 0 .../windows-defender-security-center-atp.md | 0 656 files changed, 625 insertions(+), 625 deletions(-) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/TOC.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/advanced-features-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/advanced-hunting-reference-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/advanced-hunting-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/alerts-queue-endpoint-detection-response.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/alerts-queue-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/api-hello-world.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/api-portal-mapping-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/apis-intro.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/assign-portal-access-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/attack-simulations-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/automated-investigations-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/basic-permissions-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/check-sensor-status-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/collect-investigation-package-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/community-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/conditional-access-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-arcsight-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-attack-surface-reduction.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-conditional-access-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-email-notifications-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-gp-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-script-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-endpoints-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-microsoft-threat-experts.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-mssp-support-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-proxy-internet-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-server-endpoints-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-siem-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/configure-splunk-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/custom-detection-rules.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/custom-ti-api-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/data-retention-settings-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/data-storage-privacy-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/defender-compatibility-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/deprecate.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/enable-custom-ti-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/enable-secure-score-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/enable-siem-integration-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/evaluate-atp.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/event-error-codes-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/experiment-custom-ti-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/exposed-apis-create-app-nativeapp.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/exposed-apis-create-app-webapp.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/exposed-apis-full-sample-powershell.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/exposed-apis-list.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/exposed-apis-odata-samples.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/files-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md (95%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-domain-statistics-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-file-information-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-file-related-machines-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-file-statistics-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-ip-statistics-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-kbinfo-collection-windows-defender-advanced-threat-protection.md (95%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machine-by-id-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machineaction-object-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machinegroups-collection-windows-defender-advanced-threat-protection.md (95%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machines-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md (96%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-started.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-user-information-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/get-user-related-machines-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/AH_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/AR_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ASR_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/EDR_icon.jpg (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/EDR_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Failed.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/MTE_icon.jpg (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/MTE_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/NGP_icon.jpg (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/NGP_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/No threats found.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Partially investigated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Partially remediated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Pending.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Remediated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Running.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/SS_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/TVM_icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/Terminated by system.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/WDATP-components.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/active-alerts-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/active-threat-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/advanced-features.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/advanced-hunting-query-example.PNG (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/advanced-hunting-save-query.PNG (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/alert-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/alert-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/alerts-q-bulk.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/alerts-queue-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/alerts-queue-numbered.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/analysis-results.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/api-jwt-ms.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/api-tenant-id.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Application-Guard-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Device-Guard-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-ETW-event-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Exploit-Guard-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-File-path-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Firewall-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-O365-admin-portal-customer.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Other-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-Smart-Screen-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-access-token-modification-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-action-block-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-action-center-app-restriction.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-action-center-package-collection.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-action-center-restrict-app.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-action-center-with-info.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-action-center.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-collect-investigation-package.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-isolate-machine.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-manage-tags.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-release-from-isolation.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-release-from-isoloation.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-remove-app-restrictions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-restrict-app-execution.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actions-run-av.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-active-investigations-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actor-alert.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actor-report.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-actor.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-add-application-name.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-add-application.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-add-intune-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-advanced-hunting-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-advanced-hunting-results-filter.PNG (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-advanced-hunting-results-set.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-advanced-hunting.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-mgt-pane.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-page.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-process-tree.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-source.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-status.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-timeline-numbered.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-timeline.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alert-view.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-group.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-q.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-queue-user.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-queue.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-related-to-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-related-to-machine.PNG (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-selected.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alerts-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alertsq1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-alertsq2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-analyze-auto-ir.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-app-restriction.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-application-information.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-approve-reject-action.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-appsource.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-auto-investigation-pending.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-auto-investigations-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-automated-investigations-statistics.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-av-scan-action-center.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-av-scan-notification.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-api-access.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-assign-role.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-atp-app.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-atp-machine-user.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-atp-machine.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-create.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-category.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-configure.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-create-policy-configure.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-create-policy-name.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-create-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-create-profile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-create.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-device-config.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-save-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-save.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-select-group.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune-settings-configure.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-intune.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-license-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-new-app.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-required-permissions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-select-permissions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-azure-ui-user-access.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-billing-licenses.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-billing-subscriptions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-block-file-confirm.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-block-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-blockfile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-cloud-discovery-dashboard-menu.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-collect-investigation-package.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-command-line-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-community-center.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-conditional-access-numbered.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-conditional-access.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-confirm-isolate.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-create-dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-create-suppression-rule.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-custom-oma-uri.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-custom-ti-mapping.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-daily-machines-reporting.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-dashboard-security-analytics-9.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-dashboard-security-analytics-full.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-dashboard-security-analytics.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-data-not-available.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-data-ready.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-data-retention-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-delete-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-detailed-actor.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-disableantispyware-regkey.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-download-connector.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-enable-security-analytics.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-example-email-notification.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-export-machine-timeline-events.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-action.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-creation-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-in-org.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-information.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-file-observed-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-filter-advanced-hunting.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-final-onboard-endpoints-warning-before-atp-access.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-final-preference-setup.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-geographic-location-setup.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-get-data.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-gpo-proxy1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-gpo-proxy2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-image.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-improv-opps-9.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-improv-opps.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-improv-ops.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-details-page.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-evidence-tab.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-graph-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-graph-tab.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-graph.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-investigations-tab.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-machine-tab.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incident-queue.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incidents-alerts-incidentlinkedbyreason.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incidents-alerts-linkedbytooltip.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incidents-alerts-reason.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incidents-alerts-tooltip.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-incidents-mgt-pane.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-industry-information.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-add-oma.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-add-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-assignments.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-configure.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-create-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-custom.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-deploy-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-group.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-manage-deployment.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-new-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-oma-uri-setting.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-policy-name.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-save-deployment.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-intune-save-policy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-investigation-package-action-center.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-isolate-machine.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-licensing-azure-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-loading.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-logo-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-actions-undo.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-actions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-details-view.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-details-view2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-health-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-health.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-investigation-package.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-isolation.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-timeline-details-panel.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-timeline-export.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-timeline-filter.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-timeline.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machine-view-ata.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-active-threats-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-at-risk.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-list-misconfigured.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-list-view.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-list-view2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-timeline.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-machines-view-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-main-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-manage-tags.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping 3.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping3.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping4.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping5.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping6.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mapping7.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mcas-settings.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mdm-onboarding-package.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-memory-allocation-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mma-properties.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-mma.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-module-load-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-ms-secure-score-9.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-ms-secure-score.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-network-communications-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-new-alerts-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-new-suppression-rule.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-no-network-connection.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-no-subscriptions-found.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-not-authorized-to-access-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notification-action.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notification-collect-package.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notification-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notification-isolate.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notification-restrict.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-notifications.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-observed-in-organization.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-observed-machines.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-oma-uri-values.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-onboard-endpoints-WDATP-portal-border-test.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-onboard-endpoints-WDATP-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-onboard-endpoints-run-detection-test.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-onboard-endpoints.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-onboard-mdm.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-org-score.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-org-sec-score.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-organization-size.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-pending-actions-auto-ir.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-pending-actions-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-pending-actions-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-pending-actions-multiple.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-pending-actions-notification.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-permissions-applications.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-portal-sensor.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-portal-welcome-screen.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-accept.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-consent.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-extension.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-get-data.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-importing.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-navigator.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-options.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powerbi-preview.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-powershell-command-run-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-preferences-setup.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-preview-experience.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-preview-features.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-process-event-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-process-injection.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-process-tree.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-refresh-token.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-region-control-panel.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-registry-event-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-remediated-alert.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-remove-blocked-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-rename-incident.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-respond-action-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-restrict-app.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-run-av-scan.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-running-script.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sample-custom-ti-alert.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-save-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-save-tag.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sec-coverage.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sec-ops-1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sec-ops-dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-analytics-dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-analytics-view-machines.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-analytics-view-machines2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-controls-9.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-controls.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-coverage.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-improvements.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-score-over-time-9.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-security-score-over-time.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-filter.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-health-filter-resized.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-health-filter-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-health-filter.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-health-nonav.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-sensor-health-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-server-offboarding-workspaceid.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-server-onboarding-workspaceid.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-server-onboarding.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-services.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-settings-aip.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-settings-powerbi.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-setup-complete.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-setup-incomplete.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-setup-permissions-wdatp-portal.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-shared-queries.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-integration.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-mapping1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-mapping13.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-mapping2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-mapping3.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-siem-mapping4.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-signer-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-simulate-custom-ti.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-stop-quarantine-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-stop-quarantine.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-stopnquarantine-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-subscription-expired.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-suppression-rules.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-suspicious-activities-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-tag-management.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-task-manager.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-threat-intel-api.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-threat-protection-reports.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-thunderbolt-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-tile-sensor-health.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-time-zone.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-undo-isolation.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-unsigned-file-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-details-pane.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-details-view-azureatp.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-details-view-tdp.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-details-view.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-user-view-ata.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-users-at-risk.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-verify-passive-mode.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-windows-cloud-instance-creation.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp-windows-defender-av-events-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/atp.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/azure-data-discovery.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/cloud-apps.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/cloud-discovery.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/components.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/creating-account.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/detection-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/enable_siem.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/filter-log.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/io.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/licensing-windows-defender-advanced-threat-protection.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machine-reports.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machines-active-threats-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machines-at-risk-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machines-at-risk.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machines-list.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/machines-reporting-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/menu-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-choose-action.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-define-action.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-e2e.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-insert-db.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-parse-json.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ms-flow-read-db.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/mss.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-add-permission.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-add-permissions-end.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-create.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-decoded-token.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-get-appid.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/nativeapp-select-permissions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/new-secure-score-dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/new-ssot.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/no-threats-found.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/no_threats_found.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/not-remediated-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/office-scc-label.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/overview.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/partially-investigated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/partially_investigated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/partially_remediated.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-create-advanced-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-create-blank-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-edit-credentials.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-edit-data-privacy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-open-advanced-editor.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-query-results.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-set-credentials-anonymous.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-set-credentials-organizational-cont.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-set-credentials-organizational.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/power-bi-set-data-privacy.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/remediated-icon.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/rules-legend.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/run-as-admin.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/save-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/sccm-deployment.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/sec-ops-dashboard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/securescore.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/settings.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/setup-preferences.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/setup-preferences2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/siem_details.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ss1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ssot.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/status-tile.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/submit-file.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/ta.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/terminated-by-system.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/terminated_by_system.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/threat-analytics-report.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/top-recommendations.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/wdatp-pillars.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/wdatp-pillars2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/wdsc.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-add-permission-2.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-add-permission-end.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-add-permission-readalerts.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-add-permission.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-app-id1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-create-key.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-create.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-decoded-token.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-edit-multitenant.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-edit-settings.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-get-appid.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-grant-permissions.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-select-permission.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/webapp-validate-token.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/welcome1.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/win10-endpoint-users.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windefatp-sc-qc-diagtrack.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windefatp-sc-query-diagtrack.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windefatp-sc-query.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windefatp-utc-console-autostart.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windows-defender-system-guard-boot-time-integrity.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windows-defender-system-guard-validate-system-integrity.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/images/windows-defender-system-guard.png (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/improverequestperformance-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/incidents-queue.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/information-protection-in-windows-config.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/information-protection-in-windows-overview.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-alerts-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-domain-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-files-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-incidents-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-ip-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-machines-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/investigate-user-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/isolate-machine-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/licensing-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machine-groups-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machine-reports-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machine-tags-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machine-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machineaction-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machineactionsnote.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/machines-view-overview-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-alerts-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-auto-investigation-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-edr.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-incidents-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/manage-suppression-rules-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/management-apis.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/microsoft-cloud-app-security-config.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/microsoft-cloud-app-security-integration.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/microsoft-threat-experts.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/minimum-requirements-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/mssp-support-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/offboard-machine-api-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/offboard-machines-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/onboard-configure-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/onboard-downlevel-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/onboard.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-attack-surface-reduction.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-custom-detections.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-endpoint-detection-response.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-hardware-based-isolation.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-hunting-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview-secure-score-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/overview.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/portal-overview-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/post-ti-indicator-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/powerbi-reports-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/powershell-example-code-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/preferences-setup-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/prerelease.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/preview-settings-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/preview-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/python-example-code-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/rbac-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/respond-file-alerts-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/respond-machine-alerts-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/response-actions-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/restrict-code-execution-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-api.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-sample-ms-flow.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-sample-power-bi-app-token.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-sample-power-bi-user-token.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-sample-powershell.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-advanced-query-sample-python.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-av-scan-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/run-detection-test-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/secure-score-dashboard-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/security-operations-dashboard-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/service-status-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/supported-response-apis-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/threat-analytics.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/threat-indicator-concepts-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/threat-protection-integration.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/threat-protection-reports-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/ti-indicator-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/time-settings-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md (98%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-siem-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-wdatp.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/troubleshoot-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/unisolate-machine-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/update-alert-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/use-apis.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/use-custom-ti-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/use-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/user-roles-windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/user-windows-defender-advanced-threat-protection-new.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/view-incidents-queue.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/whats-new-in-windows-defender-atp.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/windows-defender-advanced-threat-protection.md (100%) rename windows/security/threat-protection/{windows-defender-atp => microsoft-defender-atp}/windows-defender-security-center-atp.md (100%) diff --git a/windows/security/threat-protection/windows-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/TOC.md rename to windows/security/threat-protection/microsoft-defender-atp/TOC.md diff --git a/windows/security/threat-protection/windows-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/alerts-queue-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/alerts-queue-endpoint-detection-response.md rename to windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md diff --git a/windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/api-hello-world.md b/windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/api-hello-world.md rename to windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md diff --git a/windows/security/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/apis-intro.md b/windows/security/threat-protection/microsoft-defender-atp/apis-intro.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/apis-intro.md rename to windows/security/threat-protection/microsoft-defender-atp/apis-intro.md diff --git a/windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-attack-surface-reduction.md b/windows/security/threat-protection/microsoft-defender-atp/configure-attack-surface-reduction.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-attack-surface-reduction.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-attack-surface-reduction.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-microsoft-threat-experts.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/custom-detection-rules.md b/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/custom-detection-rules.md rename to windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md diff --git a/windows/security/threat-protection/windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/deprecate.md b/windows/security/threat-protection/microsoft-defender-atp/deprecate.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/deprecate.md rename to windows/security/threat-protection/microsoft-defender-atp/deprecate.md diff --git a/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/evaluate-atp.md b/windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/evaluate-atp.md rename to windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md diff --git a/windows/security/threat-protection/windows-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/exposed-apis-create-app-nativeapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/exposed-apis-create-app-nativeapp.md rename to windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md diff --git a/windows/security/threat-protection/windows-defender-atp/exposed-apis-create-app-webapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/exposed-apis-create-app-webapp.md rename to windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md diff --git a/windows/security/threat-protection/windows-defender-atp/exposed-apis-full-sample-powershell.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/exposed-apis-full-sample-powershell.md rename to windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md diff --git a/windows/security/threat-protection/windows-defender-atp/exposed-apis-list.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/exposed-apis-list.md rename to windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md diff --git a/windows/security/threat-protection/windows-defender-atp/exposed-apis-odata-samples.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/exposed-apis-odata-samples.md rename to windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md diff --git a/windows/security/threat-protection/windows-defender-atp/files-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/files-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md similarity index 95% rename from windows/security/threat-protection/windows-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md index 4251da56b9..e65b940689 100644 --- a/windows/security/threat-protection/windows-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md @@ -1,82 +1,82 @@ ---- -title: Get CVE-KB map API -description: Retrieves a map of CVE's to KB's. -keywords: apis, graph api, supported apis, get, cve, kb -search.product: eADQiWindows 10XVcnh -search.appverid: met150 -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: leonidzh -author: mjcaparas +--- +title: Get CVE-KB map API +description: Retrieves a map of CVE's to KB's. +keywords: apis, graph api, supported apis, get, cve, kb +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: leonidzh +author: mjcaparas ms.localizationpriority: medium manager: dansimp audience: ITPro ms.collection: M365-security-compliance -ms.topic: article -ms.date: 10/07/2018 ---- - -# Get CVE-KB map API - -**Applies to:** - -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - -Retrieves a map of CVE's to KB's and CVE details. - -## Permissions -User needs read permissions. - -## HTTP request -``` -GET /testwdatppreview/cvekbmap -``` - -## Request headers - -Header | Value -:---|:--- -Authorization | Bearer {token}. **Required**. -Content type | application/json - -## Request body -Empty - -## Response -If successful and map exists - 200 OK. - -## Example - -**Request** - -Here is an example of the request. - -``` -GET https://graph.microsoft.com/testwdatppreview/CveKbMap -Content-type: application/json -``` - -**Response** - -Here is an example of the response. - -``` -HTTP/1.1 200 OK -Content-type: application/json -{ - "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#CveKbMap", - "@odata.count": 4168, - "value": [ - { - "cveKbId": "CVE-2015-2482-3097617", - "cveId": "CVE-2015-2482", - "kbId":"3097617", - "title": "Cumulative Security Update for Internet Explorer", - "severity": "Critical" - }, - … -} - -``` +ms.topic: article +ms.date: 10/07/2018 +--- + +# Get CVE-KB map API + +**Applies to:** + +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + +Retrieves a map of CVE's to KB's and CVE details. + +## Permissions +User needs read permissions. + +## HTTP request +``` +GET /testwdatppreview/cvekbmap +``` + +## Request headers + +Header | Value +:---|:--- +Authorization | Bearer {token}. **Required**. +Content type | application/json + +## Request body +Empty + +## Response +If successful and map exists - 200 OK. + +## Example + +**Request** + +Here is an example of the request. + +``` +GET https://graph.microsoft.com/testwdatppreview/CveKbMap +Content-type: application/json +``` + +**Response** + +Here is an example of the response. + +``` +HTTP/1.1 200 OK +Content-type: application/json +{ + "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#CveKbMap", + "@odata.count": 4168, + "value": [ + { + "cveKbId": "CVE-2015-2482-3097617", + "cveId": "CVE-2015-2482", + "kbId":"3097617", + "title": "Cumulative Security Update for Internet Explorer", + "severity": "Critical" + }, + … +} + +``` diff --git a/windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md similarity index 95% rename from windows/security/threat-protection/windows-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md index 1752cd4d91..cfc710240a 100644 --- a/windows/security/threat-protection/windows-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md @@ -1,81 +1,81 @@ ---- -title: Get KB collection API -description: Retrieves a collection of KB's. -keywords: apis, graph api, supported apis, get, kb -search.product: eADQiWindows 10XVcnh -search.appverid: met150 -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: leonidzh -author: mjcaparas +--- +title: Get KB collection API +description: Retrieves a collection of KB's. +keywords: apis, graph api, supported apis, get, kb +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: leonidzh +author: mjcaparas ms.localizationpriority: medium manager: dansimp audience: ITPro ms.collection: M365-security-compliance -ms.topic: article -ms.date: 10/07/2018 ---- - -# Get KB collection API - -**Applies to:** - -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - -Retrieves a collection of KB's and KB details. - -## Permissions -User needs read permissions. - -## HTTP request -``` -GET /testwdatppreview/kbinfo -``` - -## Request headers - -Header | Value -:---|:--- -Authorization | Bearer {token}. **Required**. -Content type | application/json - -## Request body -Empty - -## Response -If successful - 200 OK. - -## Example - -**Request** - -Here is an example of the request. - -``` -GET https://graph.microsoft.com/testwdatppreview/KbInfo -Content-type: application/json -``` - -**Response** - -Here is an example of the response. - -``` -HTTP/1.1 200 OK -Content-type: application/json -{ - "@odata.context": "https://graph.microsoft.com/testwdatppreview/$metadata#KbInfo", - "@odata.count": 271, - "value":[ - { - "id": "KB3097617 (10240.16549) Amd64", - "release": "KB3097617 (10240.16549)", - "publishingDate": "2015-10-16T21:00:00Z", - "version": "10.0.10240.16549", - "architecture": "Amd64" - }, - … -} +ms.topic: article +ms.date: 10/07/2018 +--- + +# Get KB collection API + +**Applies to:** + +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + +Retrieves a collection of KB's and KB details. + +## Permissions +User needs read permissions. + +## HTTP request +``` +GET /testwdatppreview/kbinfo +``` + +## Request headers + +Header | Value +:---|:--- +Authorization | Bearer {token}. **Required**. +Content type | application/json + +## Request body +Empty + +## Response +If successful - 200 OK. + +## Example + +**Request** + +Here is an example of the request. + +``` +GET https://graph.microsoft.com/testwdatppreview/KbInfo +Content-type: application/json +``` + +**Response** + +Here is an example of the response. + +``` +HTTP/1.1 200 OK +Content-type: application/json +{ + "@odata.context": "https://graph.microsoft.com/testwdatppreview/$metadata#KbInfo", + "@odata.count": 271, + "value":[ + { + "id": "KB3097617 (10240.16549) Amd64", + "release": "KB3097617 (10240.16549)", + "publishingDate": "2015-10-16T21:00:00Z", + "version": "10.0.10240.16549", + "architecture": "Amd64" + }, + … +} ``` \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md similarity index 95% rename from windows/security/threat-protection/windows-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md index 412c1bd762..85bfd9945a 100644 --- a/windows/security/threat-protection/windows-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md @@ -1,81 +1,81 @@ ---- -title: Get RBAC machine groups collection API -description: Retrieves a collection of RBAC machine groups. -keywords: apis, graph api, supported apis, get, RBAC, group -search.product: eADQiWindows 10XVcnh -search.appverid: met150 -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: leonidzh -author: mjcaparas +--- +title: Get RBAC machine groups collection API +description: Retrieves a collection of RBAC machine groups. +keywords: apis, graph api, supported apis, get, RBAC, group +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: leonidzh +author: mjcaparas ms.localizationpriority: medium manager: dansimp audience: ITPro ms.collection: M365-security-compliance -ms.topic: article -ms.date: 10/07/2018 ---- - -# Get KB collection API - -**Applies to:** - -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - -Retrieves a collection of RBAC machine groups. - -## Permissions -User needs read permissions. - -## HTTP request -``` -GET /testwdatppreview/machinegroups -``` - -## Request headers - -Header | Value -:---|:--- -Authorization | Bearer {token}. **Required**. -Content type | application/json - -## Request body -Empty - -## Response -If successful - 200 OK. - -## Example - -**Request** - -Here is an example of the request. - -``` -GET https://graph.microsoft.com/testwdatppreview/machinegroups -Content-type: application/json -``` - -**Response** - -Here is an example of the response. -Field id contains machine group **id** and equal to field **rbacGroupId** in machines info. -Field **ungrouped** is true only for one group for all machines that have not been assigned to any group. This group as usual has name "UnassignedGroup". - -``` -HTTP/1.1 200 OK -Content-type: application/json -{ - "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#MachineGroups", - "@odata.count":7, - "value":[ - { - "id":86, - "name":"UnassignedGroup", - "description":"", - "ungrouped":true}, - … -} +ms.topic: article +ms.date: 10/07/2018 +--- + +# Get KB collection API + +**Applies to:** + +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + +Retrieves a collection of RBAC machine groups. + +## Permissions +User needs read permissions. + +## HTTP request +``` +GET /testwdatppreview/machinegroups +``` + +## Request headers + +Header | Value +:---|:--- +Authorization | Bearer {token}. **Required**. +Content type | application/json + +## Request body +Empty + +## Response +If successful - 200 OK. + +## Example + +**Request** + +Here is an example of the request. + +``` +GET https://graph.microsoft.com/testwdatppreview/machinegroups +Content-type: application/json +``` + +**Response** + +Here is an example of the response. +Field id contains machine group **id** and equal to field **rbacGroupId** in machines info. +Field **ungrouped** is true only for one group for all machines that have not been assigned to any group. This group as usual has name "UnassignedGroup". + +``` +HTTP/1.1 200 OK +Content-type: application/json +{ + "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#MachineGroups", + "@odata.count":7, + "value":[ + { + "id":86, + "name":"UnassignedGroup", + "description":"", + "ungrouped":true}, + … +} ``` \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md similarity index 96% rename from windows/security/threat-protection/windows-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md index 0de146e30c..55803636b8 100644 --- a/windows/security/threat-protection/windows-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md @@ -1,88 +1,88 @@ ---- -title: Get machines security states collection API -description: Retrieves a collection of machines security states. -keywords: apis, graph api, supported apis, get, machine, security, state -search.product: eADQiWindows 10XVcnh -search.appverid: met150 -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: leonidzh -author: mjcaparas +--- +title: Get machines security states collection API +description: Retrieves a collection of machines security states. +keywords: apis, graph api, supported apis, get, machine, security, state +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: leonidzh +author: mjcaparas ms.localizationpriority: medium manager: dansimp audience: ITPro ms.collection: M365-security-compliance -ms.topic: article -ms.date: 10/07/2018 ---- - -# Get Machines security states collection API - -**Applies to:** - -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - -Retrieves a collection of machines security states. - -## Permissions -User needs read permissions. - -## HTTP request -``` -GET /testwdatppreview/machinesecuritystates -``` - -## Request headers - -Header | Value -:---|:--- -Authorization | Bearer {token}. **Required**. -Content type | application/json - -## Request body -Empty - -## Response -If successful - 200 OK. - -## Example - -**Request** - -Here is an example of the request. - -``` -GET https://graph.microsoft.com/testwdatppreview/machinesecuritystates -Content-type: application/json -``` - -**Response** - -Here is an example of the response. -Field *id* contains machine id and equal to the field *id** in machines info. - -``` -HTTP/1.1 200 OK -Content-type: application/json -{ - "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#MachineSecurityStates", - "@odata.count":444, - "@odata.nextLink":"https://graph.microsoft.com/testwdatppreview/machinesecuritystates?$skiptoken=[continuation token]", - "value":[ - { - "id":"000050e1b4afeee3742489ede9ad7a3e16bbd9c4", - "build":14393, - "revision":2485, - "architecture":"Amd64", - "osVersion":"10.0.14393.2485.amd64fre.rs1_release.180827-1809", - "propertiesRequireAttention":[ - "AntivirusNotReporting", - "EdrImpairedCommunications" - ] - }, - … - ] -} +ms.topic: article +ms.date: 10/07/2018 +--- + +# Get Machines security states collection API + +**Applies to:** + +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + +Retrieves a collection of machines security states. + +## Permissions +User needs read permissions. + +## HTTP request +``` +GET /testwdatppreview/machinesecuritystates +``` + +## Request headers + +Header | Value +:---|:--- +Authorization | Bearer {token}. **Required**. +Content type | application/json + +## Request body +Empty + +## Response +If successful - 200 OK. + +## Example + +**Request** + +Here is an example of the request. + +``` +GET https://graph.microsoft.com/testwdatppreview/machinesecuritystates +Content-type: application/json +``` + +**Response** + +Here is an example of the response. +Field *id* contains machine id and equal to the field *id** in machines info. + +``` +HTTP/1.1 200 OK +Content-type: application/json +{ + "@odata.context":"https://graph.microsoft.com/testwdatppreview/$metadata#MachineSecurityStates", + "@odata.count":444, + "@odata.nextLink":"https://graph.microsoft.com/testwdatppreview/machinesecuritystates?$skiptoken=[continuation token]", + "value":[ + { + "id":"000050e1b4afeee3742489ede9ad7a3e16bbd9c4", + "build":14393, + "revision":2485, + "architecture":"Amd64", + "osVersion":"10.0.14393.2485.amd64fre.rs1_release.180827-1809", + "propertiesRequireAttention":[ + "AntivirusNotReporting", + "EdrImpairedCommunications" + ] + }, + … + ] +} ``` \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-started.md b/windows/security/threat-protection/microsoft-defender-atp/get-started.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-started.md rename to windows/security/threat-protection/microsoft-defender-atp/get-started.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/images/1.png b/windows/security/threat-protection/microsoft-defender-atp/images/1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/AH_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/AH_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/AH_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/AH_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/AR_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/AR_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/AR_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/AR_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ASR_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/ASR_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ASR_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ASR_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/EDR_icon.jpg b/windows/security/threat-protection/microsoft-defender-atp/images/EDR_icon.jpg similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/EDR_icon.jpg rename to windows/security/threat-protection/microsoft-defender-atp/images/EDR_icon.jpg diff --git a/windows/security/threat-protection/windows-defender-atp/images/EDR_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/EDR_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/EDR_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/EDR_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Failed.png b/windows/security/threat-protection/microsoft-defender-atp/images/Failed.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Failed.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Failed.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/MTE_icon.jpg b/windows/security/threat-protection/microsoft-defender-atp/images/MTE_icon.jpg similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/MTE_icon.jpg rename to windows/security/threat-protection/microsoft-defender-atp/images/MTE_icon.jpg diff --git a/windows/security/threat-protection/windows-defender-atp/images/MTE_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/MTE_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/MTE_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/MTE_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/NGP_icon.jpg b/windows/security/threat-protection/microsoft-defender-atp/images/NGP_icon.jpg similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/NGP_icon.jpg rename to windows/security/threat-protection/microsoft-defender-atp/images/NGP_icon.jpg diff --git a/windows/security/threat-protection/windows-defender-atp/images/NGP_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/NGP_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/NGP_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/NGP_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/No threats found.png b/windows/security/threat-protection/microsoft-defender-atp/images/No threats found.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/No threats found.png rename to windows/security/threat-protection/microsoft-defender-atp/images/No threats found.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Partially investigated.png b/windows/security/threat-protection/microsoft-defender-atp/images/Partially investigated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Partially investigated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Partially investigated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Partially remediated.png b/windows/security/threat-protection/microsoft-defender-atp/images/Partially remediated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Partially remediated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Partially remediated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Pending.png b/windows/security/threat-protection/microsoft-defender-atp/images/Pending.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Pending.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Pending.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Remediated.png b/windows/security/threat-protection/microsoft-defender-atp/images/Remediated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Remediated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Remediated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Running.png b/windows/security/threat-protection/microsoft-defender-atp/images/Running.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Running.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Running.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/SS_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/SS_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/SS_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/SS_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/TVM_icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/TVM_icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/TVM_icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/TVM_icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/Terminated by system.png b/windows/security/threat-protection/microsoft-defender-atp/images/Terminated by system.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/Terminated by system.png rename to windows/security/threat-protection/microsoft-defender-atp/images/Terminated by system.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/WDATP-components.png b/windows/security/threat-protection/microsoft-defender-atp/images/WDATP-components.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/WDATP-components.png rename to windows/security/threat-protection/microsoft-defender-atp/images/WDATP-components.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/active-alerts-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/active-alerts-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/active-alerts-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/active-alerts-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/active-threat-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/active-threat-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/active-threat-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/active-threat-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/advanced-features.png b/windows/security/threat-protection/microsoft-defender-atp/images/advanced-features.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/advanced-features.png rename to windows/security/threat-protection/microsoft-defender-atp/images/advanced-features.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-query-example.PNG b/windows/security/threat-protection/microsoft-defender-atp/images/advanced-hunting-query-example.PNG similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-query-example.PNG rename to windows/security/threat-protection/microsoft-defender-atp/images/advanced-hunting-query-example.PNG diff --git a/windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-save-query.PNG b/windows/security/threat-protection/microsoft-defender-atp/images/advanced-hunting-save-query.PNG similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-save-query.PNG rename to windows/security/threat-protection/microsoft-defender-atp/images/advanced-hunting-save-query.PNG diff --git a/windows/security/threat-protection/windows-defender-atp/images/alert-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/alert-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/alert-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/alert-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/alert-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/alert-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/alerts-q-bulk.png b/windows/security/threat-protection/microsoft-defender-atp/images/alerts-q-bulk.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/alerts-q-bulk.png rename to windows/security/threat-protection/microsoft-defender-atp/images/alerts-q-bulk.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/alerts-queue-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/alerts-queue-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/alerts-queue-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/alerts-queue-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/alerts-queue-numbered.png b/windows/security/threat-protection/microsoft-defender-atp/images/alerts-queue-numbered.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/alerts-queue-numbered.png rename to windows/security/threat-protection/microsoft-defender-atp/images/alerts-queue-numbered.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/analysis-results.png b/windows/security/threat-protection/microsoft-defender-atp/images/analysis-results.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/analysis-results.png rename to windows/security/threat-protection/microsoft-defender-atp/images/analysis-results.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/api-jwt-ms.png b/windows/security/threat-protection/microsoft-defender-atp/images/api-jwt-ms.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/api-jwt-ms.png rename to windows/security/threat-protection/microsoft-defender-atp/images/api-jwt-ms.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/api-tenant-id.png b/windows/security/threat-protection/microsoft-defender-atp/images/api-tenant-id.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/api-tenant-id.png rename to windows/security/threat-protection/microsoft-defender-atp/images/api-tenant-id.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Application-Guard-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Application-Guard-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Application-Guard-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Application-Guard-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Device-Guard-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Device-Guard-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Device-Guard-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Device-Guard-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-ETW-event-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-ETW-event-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-ETW-event-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-ETW-event-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Exploit-Guard-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Exploit-Guard-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Exploit-Guard-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Exploit-Guard-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-File-path-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-File-path-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-File-path-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-File-path-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Firewall-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Firewall-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Firewall-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Firewall-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-O365-admin-portal-customer.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-O365-admin-portal-customer.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-O365-admin-portal-customer.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-O365-admin-portal-customer.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Other-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Other-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Other-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Other-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-Smart-Screen-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-Smart-Screen-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-Smart-Screen-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-Smart-Screen-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-access-token-modification-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-access-token-modification-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-access-token-modification-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-access-token-modification-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-action-block-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-action-block-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-action-block-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-action-block-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-action-center-app-restriction.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-app-restriction.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-action-center-app-restriction.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-app-restriction.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-action-center-package-collection.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-package-collection.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-action-center-package-collection.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-package-collection.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-action-center-restrict-app.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-restrict-app.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-action-center-restrict-app.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-restrict-app.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-action-center-with-info.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-with-info.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-action-center-with-info.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-action-center-with-info.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-action-center.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-action-center.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-action-center.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-action-center.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-collect-investigation-package.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-collect-investigation-package.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-collect-investigation-package.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-collect-investigation-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-isolate-machine.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-isolate-machine.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-isolate-machine.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-isolate-machine.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-manage-tags.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-manage-tags.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-manage-tags.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-manage-tags.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-release-from-isolation.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-release-from-isolation.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-release-from-isolation.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-release-from-isolation.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-release-from-isoloation.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-release-from-isoloation.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-release-from-isoloation.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-release-from-isoloation.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-remove-app-restrictions.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-remove-app-restrictions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-remove-app-restrictions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-remove-app-restrictions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-restrict-app-execution.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-restrict-app-execution.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-restrict-app-execution.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-restrict-app-execution.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actions-run-av.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-run-av.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actions-run-av.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actions-run-av.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-active-investigations-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-active-investigations-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-active-investigations-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-active-investigations-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actor-alert.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actor-alert.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actor-alert.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actor-alert.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actor-report.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actor-report.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actor-report.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actor-report.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-actor.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-actor.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-actor.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-actor.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-add-application-name.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-add-application-name.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-add-application-name.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-add-application-name.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-add-application.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-add-application.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-add-application.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-add-application.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-add-intune-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-add-intune-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-add-intune-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-add-intune-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-results-filter.PNG b/windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-results-filter.PNG similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-results-filter.PNG rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-results-filter.PNG diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-results-set.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-results-set.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting-results-set.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting-results-set.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-advanced-hunting.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-advanced-hunting.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-mgt-pane.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-mgt-pane.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-mgt-pane.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-mgt-pane.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-page.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-page.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-page.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-page.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-process-tree.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-process-tree.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-process-tree.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-process-tree.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-source.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-source.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-source.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-source.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-status.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-status.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-status.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-status.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-timeline-numbered.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-timeline-numbered.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-timeline-numbered.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-timeline-numbered.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-timeline.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-timeline.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-timeline.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-timeline.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alert-view.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-view.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alert-view.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alert-view.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-group.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-group.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-group.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-group.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-q.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-q.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-q.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-q.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-queue-user.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-queue-user.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-queue-user.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-queue-user.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-queue.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-queue.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-queue.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-queue.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-related-to-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-related-to-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-related-to-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-related-to-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-related-to-machine.PNG b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-related-to-machine.PNG similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-related-to-machine.PNG rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-related-to-machine.PNG diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-selected.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-selected.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-selected.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-selected.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alerts-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alerts-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alerts-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alertsq1.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alertsq1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alertsq1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alertsq1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-alertsq2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-alertsq2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-alertsq2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-alertsq2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-analyze-auto-ir.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-analyze-auto-ir.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-analyze-auto-ir.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-analyze-auto-ir.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-app-restriction.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-app-restriction.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-app-restriction.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-app-restriction.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-application-information.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-application-information.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-application-information.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-application-information.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-approve-reject-action.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-approve-reject-action.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-approve-reject-action.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-approve-reject-action.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-appsource.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-appsource.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-appsource.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-appsource.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-auto-investigation-pending.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-auto-investigation-pending.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-auto-investigation-pending.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-auto-investigation-pending.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-auto-investigations-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-auto-investigations-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-auto-investigations-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-auto-investigations-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-automated-investigations-statistics.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-automated-investigations-statistics.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-automated-investigations-statistics.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-automated-investigations-statistics.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-av-scan-action-center.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-av-scan-action-center.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-av-scan-action-center.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-av-scan-action-center.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-av-scan-notification.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-av-scan-notification.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-av-scan-notification.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-av-scan-notification.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-api-access.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-api-access.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-api-access.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-api-access.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-assign-role.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-assign-role.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-assign-role.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-assign-role.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-app.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-app.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-app.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-app.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-machine-user.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-machine-user.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-machine-user.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-machine-user.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-machine.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-machine.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-atp-machine.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-atp-machine.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-create.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-create.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-create.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-create.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-category.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-category.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-category.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-category.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-configure.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-configure.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-configure.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-configure.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy-configure.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy-configure.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy-configure.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy-configure.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy-name.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy-name.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy-name.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy-name.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-profile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-profile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create-profile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create-profile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-create.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-create.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-device-config.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-device-config.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-device-config.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-device-config.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-save-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-save-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-save-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-save-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-save.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-save.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-save.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-save.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-select-group.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-select-group.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-select-group.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-select-group.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-settings-configure.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-settings-configure.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune-settings-configure.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune-settings-configure.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-intune.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-intune.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-license-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-license-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-license-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-license-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-new-app.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-new-app.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-new-app.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-new-app.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-required-permissions.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-required-permissions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-required-permissions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-required-permissions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-select-permissions.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-select-permissions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-select-permissions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-select-permissions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-azure-ui-user-access.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-ui-user-access.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-azure-ui-user-access.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-azure-ui-user-access.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-billing-licenses.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-billing-licenses.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-billing-licenses.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-billing-licenses.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-billing-subscriptions.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-billing-subscriptions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-billing-subscriptions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-billing-subscriptions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-block-file-confirm.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-block-file-confirm.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-block-file-confirm.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-block-file-confirm.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-block-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-block-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-block-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-block-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-blockfile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-blockfile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-blockfile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-blockfile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-cloud-discovery-dashboard-menu.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-cloud-discovery-dashboard-menu.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-cloud-discovery-dashboard-menu.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-cloud-discovery-dashboard-menu.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-collect-investigation-package.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-collect-investigation-package.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-collect-investigation-package.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-collect-investigation-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-command-line-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-command-line-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-command-line-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-command-line-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-community-center.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-community-center.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-community-center.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-community-center.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-conditional-access-numbered.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-conditional-access-numbered.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-conditional-access-numbered.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-conditional-access-numbered.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-conditional-access.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-conditional-access.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-conditional-access.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-conditional-access.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-confirm-isolate.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-confirm-isolate.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-confirm-isolate.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-confirm-isolate.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-create-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-create-dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-create-dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-create-dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-create-suppression-rule.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-create-suppression-rule.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-create-suppression-rule.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-create-suppression-rule.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-custom-oma-uri.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-custom-oma-uri.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-custom-oma-uri.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-custom-oma-uri.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-custom-ti-mapping.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-custom-ti-mapping.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-custom-ti-mapping.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-custom-ti-mapping.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-daily-machines-reporting.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-machines-reporting.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-daily-machines-reporting.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-machines-reporting.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics-9.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics-9.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics-9.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics-9.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics-full.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics-full.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics-full.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics-full.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-dashboard-security-analytics.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-dashboard-security-analytics.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-data-not-available.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-data-not-available.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-data-not-available.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-data-not-available.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-data-ready.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-data-ready.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-data-ready.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-data-ready.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-data-retention-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-data-retention-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-data-retention-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-data-retention-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-delete-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-delete-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-delete-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-delete-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-detailed-actor.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-detailed-actor.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-detailed-actor.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-detailed-actor.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-disableantispyware-regkey.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-disableantispyware-regkey.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-disableantispyware-regkey.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-disableantispyware-regkey.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-download-connector.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-download-connector.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-download-connector.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-download-connector.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-enable-security-analytics.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-enable-security-analytics.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-enable-security-analytics.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-enable-security-analytics.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-example-email-notification.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-example-email-notification.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-example-email-notification.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-example-email-notification.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-export-machine-timeline-events.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-export-machine-timeline-events.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-export-machine-timeline-events.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-export-machine-timeline-events.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-action.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-action.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-action.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-action.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-creation-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-creation-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-creation-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-creation-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-in-org.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-in-org.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-in-org.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-in-org.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-information.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-information.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-information.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-information.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-file-observed-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-file-observed-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-file-observed-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-file-observed-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-filter-advanced-hunting.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-filter-advanced-hunting.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-filter-advanced-hunting.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-filter-advanced-hunting.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-final-onboard-endpoints-warning-before-atp-access.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-final-onboard-endpoints-warning-before-atp-access.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-final-onboard-endpoints-warning-before-atp-access.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-final-onboard-endpoints-warning-before-atp-access.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-final-preference-setup.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-final-preference-setup.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-final-preference-setup.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-final-preference-setup.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-geographic-location-setup.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-geographic-location-setup.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-geographic-location-setup.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-geographic-location-setup.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-get-data.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-get-data.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-get-data.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-get-data.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-gpo-proxy1.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-gpo-proxy1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-gpo-proxy1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-gpo-proxy1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-gpo-proxy2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-gpo-proxy2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-gpo-proxy2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-gpo-proxy2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-image.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-image.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-image.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-image.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-improv-opps-9.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-opps-9.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-improv-opps-9.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-opps-9.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-improv-opps.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-opps.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-improv-opps.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-opps.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-improv-ops.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-ops.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-improv-ops.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-improv-ops.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-details-page.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-details-page.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-details-page.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-details-page.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-evidence-tab.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-evidence-tab.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-evidence-tab.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-evidence-tab.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph-tab.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph-tab.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph-tab.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph-tab.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-graph.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-graph.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-investigations-tab.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-investigations-tab.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-investigations-tab.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-investigations-tab.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-machine-tab.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-machine-tab.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-machine-tab.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-machine-tab.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incident-queue.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-queue.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incident-queue.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incident-queue.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-incidentlinkedbyreason.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-incidentlinkedbyreason.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-incidentlinkedbyreason.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-incidentlinkedbyreason.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-linkedbytooltip.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-linkedbytooltip.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-linkedbytooltip.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-linkedbytooltip.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-reason.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-reason.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-reason.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-reason.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-tooltip.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-tooltip.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incidents-alerts-tooltip.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-alerts-tooltip.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-incidents-mgt-pane.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-mgt-pane.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-incidents-mgt-pane.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-incidents-mgt-pane.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-industry-information.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-industry-information.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-industry-information.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-industry-information.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-add-oma.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-add-oma.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-add-oma.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-add-oma.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-add-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-add-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-add-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-add-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-assignments.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-assignments.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-assignments.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-assignments.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-configure.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-configure.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-configure.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-configure.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-create-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-create-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-create-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-create-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-custom.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-custom.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-custom.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-custom.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-deploy-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-deploy-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-deploy-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-deploy-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-group.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-group.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-group.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-group.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-manage-deployment.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-manage-deployment.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-manage-deployment.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-manage-deployment.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-new-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-new-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-new-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-new-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-oma-uri-setting.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-oma-uri-setting.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-oma-uri-setting.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-oma-uri-setting.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-policy-name.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-policy-name.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-policy-name.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-policy-name.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-save-deployment.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-save-deployment.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-save-deployment.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-save-deployment.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-intune-save-policy.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-save-policy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-intune-save-policy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-intune-save-policy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-investigation-package-action-center.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-investigation-package-action-center.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-investigation-package-action-center.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-investigation-package-action-center.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-isolate-machine.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-isolate-machine.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-isolate-machine.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-isolate-machine.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-licensing-azure-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-licensing-azure-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-licensing-azure-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-licensing-azure-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-loading.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-loading.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-loading.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-loading.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-logo-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-logo-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-logo-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-logo-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-actions-undo.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-actions-undo.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-actions-undo.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-actions-undo.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-actions.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-actions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-actions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-actions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-details-view.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-details-view.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-details-view.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-details-view.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-details-view2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-details-view2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-details-view2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-details-view2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-health-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-health-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-health-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-health-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-health.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-health.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-health.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-health.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-investigation-package.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-investigation-package.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-investigation-package.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-investigation-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-isolation.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-isolation.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-isolation.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-isolation.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-details-panel.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-details-panel.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-details-panel.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-details-panel.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-export.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-export.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-export.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-export.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-filter.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-filter.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline-filter.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline-filter.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-timeline.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-timeline.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machine-view-ata.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-view-ata.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machine-view-ata.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machine-view-ata.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-active-threats-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-active-threats-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-active-threats-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-active-threats-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-at-risk.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-at-risk.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-at-risk.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-at-risk.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-misconfigured.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-misconfigured.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-misconfigured.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-misconfigured.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-view.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-view.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-view.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-view.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-view2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-view2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-list-view2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-list-view2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-timeline.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-timeline.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-timeline.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-timeline.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-machines-view-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-view-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-machines-view-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-machines-view-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-main-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-main-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-main-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-main-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-manage-tags.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-manage-tags.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-manage-tags.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-manage-tags.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping 3.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping 3.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping 3.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping 3.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping1.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping3.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping3.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping3.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping3.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping4.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping4.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping4.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping4.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping5.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping5.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping5.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping5.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping6.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping6.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping6.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping6.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mapping7.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping7.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mapping7.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mapping7.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mcas-settings.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mcas-settings.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mcas-settings.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mcas-settings.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mdm-onboarding-package.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mdm-onboarding-package.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mdm-onboarding-package.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mdm-onboarding-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-memory-allocation-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-memory-allocation-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-memory-allocation-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-memory-allocation-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mma-properties.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mma-properties.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mma-properties.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mma-properties.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-mma.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-mma.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-mma.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-mma.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-module-load-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-module-load-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-module-load-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-module-load-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-ms-secure-score-9.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-ms-secure-score-9.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-ms-secure-score-9.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-ms-secure-score-9.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-ms-secure-score.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-ms-secure-score.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-ms-secure-score.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-ms-secure-score.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-network-communications-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-network-communications-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-network-communications-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-network-communications-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-new-alerts-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-new-alerts-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-new-alerts-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-new-alerts-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-new-suppression-rule.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-new-suppression-rule.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-new-suppression-rule.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-new-suppression-rule.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-no-network-connection.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-no-network-connection.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-no-network-connection.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-no-network-connection.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-no-subscriptions-found.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-no-subscriptions-found.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-no-subscriptions-found.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-no-subscriptions-found.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-not-authorized-to-access-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-not-authorized-to-access-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-not-authorized-to-access-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-not-authorized-to-access-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notification-action.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-action.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notification-action.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-action.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notification-collect-package.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-collect-package.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notification-collect-package.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-collect-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notification-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notification-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notification-isolate.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-isolate.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notification-isolate.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-isolate.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notification-restrict.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-restrict.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notification-restrict.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notification-restrict.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-notifications.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-notifications.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-notifications.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-notifications.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-observed-in-organization.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-observed-in-organization.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-observed-in-organization.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-observed-in-organization.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-observed-machines.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-observed-machines.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-observed-machines.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-observed-machines.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-oma-uri-values.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-oma-uri-values.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-oma-uri-values.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-oma-uri-values.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-WDATP-portal-border-test.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-WDATP-portal-border-test.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-WDATP-portal-border-test.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-WDATP-portal-border-test.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-WDATP-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-WDATP-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-WDATP-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-WDATP-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-run-detection-test.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-run-detection-test.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints-run-detection-test.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints-run-detection-test.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-onboard-endpoints.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-endpoints.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-onboard-mdm.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-mdm.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-onboard-mdm.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-onboard-mdm.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-org-score.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-org-score.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-org-score.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-org-score.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-org-sec-score.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-org-sec-score.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-org-sec-score.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-org-sec-score.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-organization-size.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-organization-size.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-organization-size.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-organization-size.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-auto-ir.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-auto-ir.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-auto-ir.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-auto-ir.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-multiple.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-multiple.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-multiple.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-multiple.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-notification.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-notification.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-pending-actions-notification.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-pending-actions-notification.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-permissions-applications.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-permissions-applications.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-permissions-applications.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-permissions-applications.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-portal-sensor.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-portal-sensor.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-portal-sensor.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-portal-sensor.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-portal-welcome-screen.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-portal-welcome-screen.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-portal-welcome-screen.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-portal-welcome-screen.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-accept.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-accept.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-accept.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-accept.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-consent.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-consent.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-consent.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-consent.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-extension.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-extension.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-extension.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-extension.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-get-data.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-get-data.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-get-data.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-get-data.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-importing.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-importing.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-importing.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-importing.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-navigator.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-navigator.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-navigator.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-navigator.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-options.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-options.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-options.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-options.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-preview.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-preview.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powerbi-preview.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powerbi-preview.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-powershell-command-run-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-powershell-command-run-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-powershell-command-run-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-powershell-command-run-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-preferences-setup.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-preferences-setup.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-preferences-setup.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-preferences-setup.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-preview-experience.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-experience.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-preview-experience.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-experience.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-preview-features.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-preview-features.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-process-event-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-process-event-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-process-event-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-process-event-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-process-injection.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-process-injection.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-process-injection.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-process-injection.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-process-tree.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-process-tree.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-process-tree.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-process-tree.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-refresh-token.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-refresh-token.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-refresh-token.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-refresh-token.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-region-control-panel.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-region-control-panel.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-region-control-panel.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-region-control-panel.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-registry-event-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-registry-event-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-registry-event-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-registry-event-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-remediated-alert.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-remediated-alert.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-remediated-alert.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-remediated-alert.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-remove-blocked-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-remove-blocked-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-remove-blocked-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-remove-blocked-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-rename-incident.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-rename-incident.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-rename-incident.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-rename-incident.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-respond-action-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-respond-action-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-respond-action-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-respond-action-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-restrict-app.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-restrict-app.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-restrict-app.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-restrict-app.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-run-av-scan.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-run-av-scan.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-run-av-scan.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-run-av-scan.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-running-script.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-running-script.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-running-script.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-running-script.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sample-custom-ti-alert.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sample-custom-ti-alert.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sample-custom-ti-alert.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sample-custom-ti-alert.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-save-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-save-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-save-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-save-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-save-tag.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-save-tag.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-save-tag.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-save-tag.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sec-coverage.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-coverage.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sec-coverage.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-coverage.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sec-ops-1.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-ops-1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sec-ops-1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-ops-1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sec-ops-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-ops-dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sec-ops-dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sec-ops-dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-view-machines.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-view-machines.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-view-machines.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-view-machines.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-view-machines2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-view-machines2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-analytics-view-machines2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-analytics-view-machines2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-controls-9.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-controls-9.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-controls-9.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-controls-9.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-controls.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-controls.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-controls.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-controls.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-coverage.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-coverage.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-coverage.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-coverage.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-improvements.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-improvements.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-improvements.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-improvements.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-score-over-time-9.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-score-over-time-9.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-score-over-time-9.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-score-over-time-9.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-security-score-over-time.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-security-score-over-time.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-security-score-over-time.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-security-score-over-time.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-filter.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-filter.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-filter.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-filter.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter-resized.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter-resized.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter-resized.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter-resized.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-filter.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-filter.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-nonav.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-nonav.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-nonav.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-nonav.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-sensor-health-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-sensor-health-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-server-offboarding-workspaceid.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-server-offboarding-workspaceid.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-server-offboarding-workspaceid.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-server-offboarding-workspaceid.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-server-onboarding-workspaceid.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-server-onboarding-workspaceid.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-server-onboarding-workspaceid.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-server-onboarding-workspaceid.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-server-onboarding.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-server-onboarding.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-server-onboarding.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-server-onboarding.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-services.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-services.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-services.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-services.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-settings-aip.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-settings-aip.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-settings-aip.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-settings-aip.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-settings-powerbi.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-settings-powerbi.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-settings-powerbi.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-settings-powerbi.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-setup-complete.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-complete.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-setup-complete.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-complete.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-setup-incomplete.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-incomplete.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-setup-incomplete.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-incomplete.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-setup-permissions-wdatp-portal.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-permissions-wdatp-portal.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-setup-permissions-wdatp-portal.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-setup-permissions-wdatp-portal.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-shared-queries.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-shared-queries.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-shared-queries.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-shared-queries.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-integration.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-integration.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-integration.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-integration.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping1.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping13.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping13.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping13.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping13.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping2.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping3.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping3.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping3.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping3.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping4.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping4.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-siem-mapping4.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-siem-mapping4.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-signer-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-signer-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-signer-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-signer-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-simulate-custom-ti.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-simulate-custom-ti.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-simulate-custom-ti.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-simulate-custom-ti.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-stop-quarantine-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-stop-quarantine-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-stop-quarantine-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-stop-quarantine-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-stop-quarantine.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-stop-quarantine.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-stop-quarantine.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-stop-quarantine.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-stopnquarantine-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-stopnquarantine-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-stopnquarantine-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-stopnquarantine-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-subscription-expired.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-subscription-expired.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-subscription-expired.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-subscription-expired.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-suppression-rules.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-suppression-rules.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-suppression-rules.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-suppression-rules.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-suspicious-activities-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-suspicious-activities-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-suspicious-activities-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-suspicious-activities-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-tag-management.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-tag-management.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-tag-management.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-tag-management.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-task-manager.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-task-manager.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-task-manager.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-task-manager.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-threat-intel-api.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-threat-intel-api.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-threat-intel-api.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-threat-intel-api.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-threat-protection-reports.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-threat-protection-reports.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-threat-protection-reports.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-threat-protection-reports.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-thunderbolt-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-thunderbolt-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-thunderbolt-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-thunderbolt-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-tile-sensor-health.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-tile-sensor-health.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-tile-sensor-health.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-tile-sensor-health.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-time-zone.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-time-zone.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-time-zone.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-time-zone.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-undo-isolation.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-undo-isolation.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-undo-isolation.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-undo-isolation.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-unsigned-file-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-unsigned-file-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-unsigned-file-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-unsigned-file-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-details-pane.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-pane.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-details-pane.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-pane.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view-azureatp.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view-azureatp.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view-azureatp.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view-azureatp.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view-tdp.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view-tdp.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view-tdp.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view-tdp.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-details-view.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details-view.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-user-view-ata.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-user-view-ata.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-user-view-ata.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-user-view-ata.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-users-at-risk.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-users-at-risk.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-users-at-risk.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-users-at-risk.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-verify-passive-mode.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-verify-passive-mode.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-verify-passive-mode.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-verify-passive-mode.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-windows-cloud-instance-creation.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-windows-cloud-instance-creation.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-windows-cloud-instance-creation.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-windows-cloud-instance-creation.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp-windows-defender-av-events-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-windows-defender-av-events-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp-windows-defender-av-events-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp-windows-defender-av-events-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/atp.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/atp.png rename to windows/security/threat-protection/microsoft-defender-atp/images/atp.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/azure-data-discovery.png b/windows/security/threat-protection/microsoft-defender-atp/images/azure-data-discovery.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/azure-data-discovery.png rename to windows/security/threat-protection/microsoft-defender-atp/images/azure-data-discovery.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/cloud-apps.png b/windows/security/threat-protection/microsoft-defender-atp/images/cloud-apps.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/cloud-apps.png rename to windows/security/threat-protection/microsoft-defender-atp/images/cloud-apps.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/cloud-discovery.png b/windows/security/threat-protection/microsoft-defender-atp/images/cloud-discovery.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/cloud-discovery.png rename to windows/security/threat-protection/microsoft-defender-atp/images/cloud-discovery.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/components.png b/windows/security/threat-protection/microsoft-defender-atp/images/components.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/components.png rename to windows/security/threat-protection/microsoft-defender-atp/images/components.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/creating-account.png b/windows/security/threat-protection/microsoft-defender-atp/images/creating-account.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/creating-account.png rename to windows/security/threat-protection/microsoft-defender-atp/images/creating-account.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/detection-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/detection-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/detection-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/detection-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/enable_siem.png b/windows/security/threat-protection/microsoft-defender-atp/images/enable_siem.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/enable_siem.png rename to windows/security/threat-protection/microsoft-defender-atp/images/enable_siem.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/filter-log.png b/windows/security/threat-protection/microsoft-defender-atp/images/filter-log.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/filter-log.png rename to windows/security/threat-protection/microsoft-defender-atp/images/filter-log.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/io.png b/windows/security/threat-protection/microsoft-defender-atp/images/io.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/io.png rename to windows/security/threat-protection/microsoft-defender-atp/images/io.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/licensing-windows-defender-advanced-threat-protection.png b/windows/security/threat-protection/microsoft-defender-atp/images/licensing-windows-defender-advanced-threat-protection.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/licensing-windows-defender-advanced-threat-protection.png rename to windows/security/threat-protection/microsoft-defender-atp/images/licensing-windows-defender-advanced-threat-protection.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machine-reports.png b/windows/security/threat-protection/microsoft-defender-atp/images/machine-reports.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machine-reports.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machine-reports.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machines-active-threats-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/machines-active-threats-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machines-active-threats-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machines-active-threats-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machines-at-risk-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/machines-at-risk-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machines-at-risk-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machines-at-risk-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machines-at-risk.png b/windows/security/threat-protection/microsoft-defender-atp/images/machines-at-risk.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machines-at-risk.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machines-at-risk.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machines-list.png b/windows/security/threat-protection/microsoft-defender-atp/images/machines-list.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machines-list.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machines-list.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/machines-reporting-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/machines-reporting-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/machines-reporting-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/machines-reporting-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/menu-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/menu-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/menu-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/menu-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-choose-action.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-choose-action.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-choose-action.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-choose-action.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-define-action.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-define-action.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-define-action.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-define-action.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-e2e.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-e2e.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-e2e.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-e2e.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-insert-db.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-insert-db.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-insert-db.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-insert-db.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-parse-json.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-parse-json.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-parse-json.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-parse-json.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ms-flow-read-db.png b/windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-read-db.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ms-flow-read-db.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ms-flow-read-db.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/mss.png b/windows/security/threat-protection/microsoft-defender-atp/images/mss.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/mss.png rename to windows/security/threat-protection/microsoft-defender-atp/images/mss.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-add-permission.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-add-permission.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-add-permission.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-add-permission.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-add-permissions-end.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-add-permissions-end.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-add-permissions-end.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-add-permissions-end.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-create.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-create.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-create.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-create.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-decoded-token.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-decoded-token.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-decoded-token.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-decoded-token.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-get-appid.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-get-appid.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-get-appid.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-get-appid.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/nativeapp-select-permissions.png b/windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-select-permissions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/nativeapp-select-permissions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/nativeapp-select-permissions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/new-secure-score-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/new-secure-score-dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/new-secure-score-dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/new-secure-score-dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/new-ssot.png b/windows/security/threat-protection/microsoft-defender-atp/images/new-ssot.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/new-ssot.png rename to windows/security/threat-protection/microsoft-defender-atp/images/new-ssot.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/no-threats-found.png b/windows/security/threat-protection/microsoft-defender-atp/images/no-threats-found.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/no-threats-found.png rename to windows/security/threat-protection/microsoft-defender-atp/images/no-threats-found.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/no_threats_found.png b/windows/security/threat-protection/microsoft-defender-atp/images/no_threats_found.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/no_threats_found.png rename to windows/security/threat-protection/microsoft-defender-atp/images/no_threats_found.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/not-remediated-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/not-remediated-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/not-remediated-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/not-remediated-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/office-scc-label.png b/windows/security/threat-protection/microsoft-defender-atp/images/office-scc-label.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/office-scc-label.png rename to windows/security/threat-protection/microsoft-defender-atp/images/office-scc-label.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/overview.png b/windows/security/threat-protection/microsoft-defender-atp/images/overview.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/overview.png rename to windows/security/threat-protection/microsoft-defender-atp/images/overview.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/partially-investigated.png b/windows/security/threat-protection/microsoft-defender-atp/images/partially-investigated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/partially-investigated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/partially-investigated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/partially_investigated.png b/windows/security/threat-protection/microsoft-defender-atp/images/partially_investigated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/partially_investigated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/partially_investigated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/partially_remediated.png b/windows/security/threat-protection/microsoft-defender-atp/images/partially_remediated.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/partially_remediated.png rename to windows/security/threat-protection/microsoft-defender-atp/images/partially_remediated.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-create-advanced-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-create-advanced-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-create-advanced-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-create-advanced-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-create-blank-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-create-blank-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-create-blank-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-create-blank-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-edit-credentials.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-edit-credentials.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-edit-credentials.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-edit-credentials.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-edit-data-privacy.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-edit-data-privacy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-edit-data-privacy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-edit-data-privacy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-open-advanced-editor.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-open-advanced-editor.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-open-advanced-editor.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-open-advanced-editor.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-query-results.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-query-results.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-query-results.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-query-results.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-anonymous.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-anonymous.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-anonymous.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-anonymous.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-organizational-cont.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-organizational-cont.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-organizational-cont.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-organizational-cont.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-organizational.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-organizational.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-set-credentials-organizational.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-credentials-organizational.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/power-bi-set-data-privacy.png b/windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-data-privacy.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/power-bi-set-data-privacy.png rename to windows/security/threat-protection/microsoft-defender-atp/images/power-bi-set-data-privacy.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/remediated-icon.png b/windows/security/threat-protection/microsoft-defender-atp/images/remediated-icon.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/remediated-icon.png rename to windows/security/threat-protection/microsoft-defender-atp/images/remediated-icon.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/rules-legend.png b/windows/security/threat-protection/microsoft-defender-atp/images/rules-legend.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/rules-legend.png rename to windows/security/threat-protection/microsoft-defender-atp/images/rules-legend.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/run-as-admin.png b/windows/security/threat-protection/microsoft-defender-atp/images/run-as-admin.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/run-as-admin.png rename to windows/security/threat-protection/microsoft-defender-atp/images/run-as-admin.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/save-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/save-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/save-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/save-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/sccm-deployment.png b/windows/security/threat-protection/microsoft-defender-atp/images/sccm-deployment.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/sccm-deployment.png rename to windows/security/threat-protection/microsoft-defender-atp/images/sccm-deployment.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/sec-ops-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/sec-ops-dashboard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/sec-ops-dashboard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/sec-ops-dashboard.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/securescore.png b/windows/security/threat-protection/microsoft-defender-atp/images/securescore.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/securescore.png rename to windows/security/threat-protection/microsoft-defender-atp/images/securescore.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/settings.png b/windows/security/threat-protection/microsoft-defender-atp/images/settings.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/settings.png rename to windows/security/threat-protection/microsoft-defender-atp/images/settings.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/setup-preferences.png b/windows/security/threat-protection/microsoft-defender-atp/images/setup-preferences.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/setup-preferences.png rename to windows/security/threat-protection/microsoft-defender-atp/images/setup-preferences.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/setup-preferences2.png b/windows/security/threat-protection/microsoft-defender-atp/images/setup-preferences2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/setup-preferences2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/setup-preferences2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/siem_details.png b/windows/security/threat-protection/microsoft-defender-atp/images/siem_details.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/siem_details.png rename to windows/security/threat-protection/microsoft-defender-atp/images/siem_details.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ss1.png b/windows/security/threat-protection/microsoft-defender-atp/images/ss1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ss1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ss1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ssot.png b/windows/security/threat-protection/microsoft-defender-atp/images/ssot.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ssot.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ssot.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/status-tile.png b/windows/security/threat-protection/microsoft-defender-atp/images/status-tile.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/status-tile.png rename to windows/security/threat-protection/microsoft-defender-atp/images/status-tile.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/submit-file.png b/windows/security/threat-protection/microsoft-defender-atp/images/submit-file.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/submit-file.png rename to windows/security/threat-protection/microsoft-defender-atp/images/submit-file.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/ta.png b/windows/security/threat-protection/microsoft-defender-atp/images/ta.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/ta.png rename to windows/security/threat-protection/microsoft-defender-atp/images/ta.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/terminated-by-system.png b/windows/security/threat-protection/microsoft-defender-atp/images/terminated-by-system.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/terminated-by-system.png rename to windows/security/threat-protection/microsoft-defender-atp/images/terminated-by-system.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/terminated_by_system.png b/windows/security/threat-protection/microsoft-defender-atp/images/terminated_by_system.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/terminated_by_system.png rename to windows/security/threat-protection/microsoft-defender-atp/images/terminated_by_system.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/threat-analytics-report.png b/windows/security/threat-protection/microsoft-defender-atp/images/threat-analytics-report.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/threat-analytics-report.png rename to windows/security/threat-protection/microsoft-defender-atp/images/threat-analytics-report.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/top-recommendations.png b/windows/security/threat-protection/microsoft-defender-atp/images/top-recommendations.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/top-recommendations.png rename to windows/security/threat-protection/microsoft-defender-atp/images/top-recommendations.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/wdatp-pillars.png b/windows/security/threat-protection/microsoft-defender-atp/images/wdatp-pillars.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/wdatp-pillars.png rename to windows/security/threat-protection/microsoft-defender-atp/images/wdatp-pillars.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/wdatp-pillars2.png b/windows/security/threat-protection/microsoft-defender-atp/images/wdatp-pillars2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/wdatp-pillars2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/wdatp-pillars2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/wdsc.png b/windows/security/threat-protection/microsoft-defender-atp/images/wdsc.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/wdsc.png rename to windows/security/threat-protection/microsoft-defender-atp/images/wdsc.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-2.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-2.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-2.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-2.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-end.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-end.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-end.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-end.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-readalerts.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-readalerts.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission-readalerts.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission-readalerts.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-add-permission.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-add-permission.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-app-id1.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-app-id1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-app-id1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-app-id1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-create-key.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-create-key.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-create-key.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-create-key.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-create.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-create.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-create.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-create.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-decoded-token.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-decoded-token.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-decoded-token.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-decoded-token.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-edit-multitenant.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-edit-multitenant.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-edit-multitenant.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-edit-multitenant.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-edit-settings.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-edit-settings.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-edit-settings.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-edit-settings.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-get-appid.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-get-appid.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-get-appid.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-get-appid.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-grant-permissions.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-grant-permissions.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-grant-permissions.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-grant-permissions.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-select-permission.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-select-permission.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-select-permission.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-select-permission.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/webapp-validate-token.png b/windows/security/threat-protection/microsoft-defender-atp/images/webapp-validate-token.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/webapp-validate-token.png rename to windows/security/threat-protection/microsoft-defender-atp/images/webapp-validate-token.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/welcome1.png b/windows/security/threat-protection/microsoft-defender-atp/images/welcome1.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/welcome1.png rename to windows/security/threat-protection/microsoft-defender-atp/images/welcome1.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/win10-endpoint-users.png b/windows/security/threat-protection/microsoft-defender-atp/images/win10-endpoint-users.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/win10-endpoint-users.png rename to windows/security/threat-protection/microsoft-defender-atp/images/win10-endpoint-users.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-qc-diagtrack.png b/windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-qc-diagtrack.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-qc-diagtrack.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-qc-diagtrack.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-query-diagtrack.png b/windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-query-diagtrack.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-query-diagtrack.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-query-diagtrack.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-query.png b/windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-query.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windefatp-sc-query.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windefatp-sc-query.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windefatp-utc-console-autostart.png b/windows/security/threat-protection/microsoft-defender-atp/images/windefatp-utc-console-autostart.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windefatp-utc-console-autostart.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windefatp-utc-console-autostart.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard-boot-time-integrity.png b/windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard-boot-time-integrity.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard-boot-time-integrity.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard-boot-time-integrity.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard-validate-system-integrity.png b/windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard-validate-system-integrity.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard-validate-system-integrity.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard-validate-system-integrity.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard.png b/windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard.png similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/images/windows-defender-system-guard.png rename to windows/security/threat-protection/microsoft-defender-atp/images/windows-defender-system-guard.png diff --git a/windows/security/threat-protection/windows-defender-atp/improverequestperformance-new.md b/windows/security/threat-protection/microsoft-defender-atp/improverequestperformance-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/improverequestperformance-new.md rename to windows/security/threat-protection/microsoft-defender-atp/improverequestperformance-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/incidents-queue.md rename to windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md diff --git a/windows/security/threat-protection/windows-defender-atp/information-protection-in-windows-config.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/information-protection-in-windows-config.md rename to windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md diff --git a/windows/security/threat-protection/windows-defender-atp/information-protection-in-windows-overview.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/information-protection-in-windows-overview.md rename to windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md diff --git a/windows/security/threat-protection/windows-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/licensing-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/licensing-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/machineactionsnote.md b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machineactionsnote.md rename to windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md diff --git a/windows/security/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-edr.md b/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-edr.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-edr.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/management-apis.md b/windows/security/threat-protection/microsoft-defender-atp/management-apis.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/management-apis.md rename to windows/security/threat-protection/microsoft-defender-atp/management-apis.md diff --git a/windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-config.md rename to windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md diff --git a/windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-integration.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-integration.md rename to windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md diff --git a/windows/security/threat-protection/windows-defender-atp/microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/microsoft-threat-experts.md rename to windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md diff --git a/windows/security/threat-protection/windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/onboard.md b/windows/security/threat-protection/microsoft-defender-atp/onboard.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/onboard.md rename to windows/security/threat-protection/microsoft-defender-atp/onboard.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction.md b/windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-attack-surface-reduction.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-custom-detections.md b/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-custom-detections.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-endpoint-detection-response.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-hardware-based-isolation.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-hardware-based-isolation.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/overview.md b/windows/security/threat-protection/microsoft-defender-atp/overview.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/overview.md rename to windows/security/threat-protection/microsoft-defender-atp/overview.md diff --git a/windows/security/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/prerelease.md b/windows/security/threat-protection/microsoft-defender-atp/prerelease.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/prerelease.md rename to windows/security/threat-protection/microsoft-defender-atp/prerelease.md diff --git a/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-api.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-api.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-ms-flow.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-ms-flow.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-power-bi-app-token.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-power-bi-app-token.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-power-bi-user-token.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-power-bi-user-token.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-powershell.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-powershell.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-python.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-advanced-query-sample-python.md rename to windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/service-status-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/service-status-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/threat-analytics.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/threat-analytics.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md diff --git a/windows/security/threat-protection/windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/threat-protection-integration.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/threat-protection-integration.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md diff --git a/windows/security/threat-protection/windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md similarity index 98% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md index 38a88cfe19..0f2789ceb5 100644 --- a/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md @@ -1,312 +1,312 @@ ---- -title: Troubleshoot Windows Defender ATP onboarding issues -description: Troubleshoot issues that might arise during the onboarding of machines or to the Windows Defender ATP service. -keywords: troubleshoot onboarding, onboarding issues, event viewer, data collection and preview builds, sensor data and diagnostics -search.product: eADQiWindows 10XVcnh -search.appverid: met150 -ms.prod: w10 -ms.mktglfcycl: deploy -ms.sitesec: library -ms.pagetype: security -ms.author: macapara -author: mjcaparas -ms.localizationpriority: medium -manager: dansimp -audience: ITPro -ms.collection: M365-security-compliance -ms.topic: troubleshooting ---- - -# Troubleshoot Windows Defender Advanced Threat Protection onboarding issues - -**Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -- Windows Server 2012 R2 -- Windows Server 2016 - - - -You might need to troubleshoot the Windows Defender ATP onboarding process if you encounter issues. -This page provides detailed steps to troubleshoot onboarding issues that might occur when deploying with one of the deployment tools and common errors that might occur on the machines. - -If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, it might indicate an onboarding or connectivity problem. - -## Troubleshoot onboarding when deploying with Group Policy -Deployment with Group Policy is done by running the onboarding script on the machines. The Group Policy console does not indicate if the deployment has succeeded or not. - -If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, you can check the output of the script on the machines. For more information, see [Troubleshoot onboarding when deploying with a script](#troubleshoot-onboarding-when-deploying-with-a-script). - -If the script completes successfully, see [Troubleshoot onboarding issues on the machines](#troubleshoot-onboarding-issues-on-the-machine) for additional errors that might occur. - -## Troubleshoot onboarding issues when deploying with System Center Configuration Manager -When onboarding machines using the following versions of System Center Configuration Manager: -- System Center 2012 Configuration Manager -- System Center 2012 R2 Configuration Manager -- System Center Configuration Manager (current branch) version 1511 -- System Center Configuration Manager (current branch) version 1602 - - -Deployment with the above-mentioned versions of System Center Configuration Manager is done by running the onboarding script on the machines. You can track the deployment in the Configuration Manager Console. - -If the deployment fails, you can check the output of the script on the machines. - -If the onboarding completed successfully but the machines are not showing up in the **Machines list** after an hour, see [Troubleshoot onboarding issues on the machine](#troubleshoot-onboarding-issues-on-the-machine) for additional errors that might occur. - -## Troubleshoot onboarding when deploying with a script - -**Check the result of the script on the machine**: -1. Click **Start**, type **Event Viewer**, and press **Enter**. - -2. Go to **Windows Logs** > **Application**. - -3. Look for an event from **WDATPOnboarding** event source. - -If the script fails and the event is an error, you can check the event ID in the following table to help you troubleshoot the issue. -> [!NOTE] -> The following event IDs are specific to the onboarding script only. - -Event ID | Error Type | Resolution steps -:---|:---|:--- -5 | Offboarding data was found but couldn't be deleted | Check the permissions on the registry, specifically ```HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```. -10 | Onboarding data couldn't be written to registry | Check the permissions on the registry, specifically
```HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat```.
Verify that the script was ran as an administrator. -15 | Failed to start SENSE service |Check the service health (```sc query sense``` command). Make sure it's not in an intermediate state (*'Pending_Stopped'*, *'Pending_Running'*) and try to run the script again (with administrator rights).

If the machine is running Windows 10, version 1607 and running the command `sc query sense` returns `START_PENDING`, reboot the machine. If rebooting the machine doesn't address the issue, upgrade to KB4015217 and try onboarding again. -15 | Failed to start SENSE service | If the message of the error is: System error 577 has occurred. You need to enable the Windows Defender Antivirus ELAM driver, see [Ensure that Windows Defender Antivirus is not disabled by a policy](#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy) for instructions. -30 | The script failed to wait for the service to start running | The service could have taken more time to start or has encountered errors while trying to start. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). -35 | The script failed to find needed onboarding status registry value | When the SENSE service starts for the first time, it writes onboarding status to the registry location
```HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status```.
The script failed to find it after several seconds. You can manually test it and check if it's there. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). -40 | SENSE service onboarding status is not set to **1** | The SENSE service has failed to onboard properly. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). -65 | Insufficient privileges| Run the script again with administrator privileges. - -## Troubleshoot onboarding issues using Microsoft Intune -You can use Microsoft Intune to check error codes and attempt to troubleshoot the cause of the issue. - -If you have configured policies in Intune and they are not propagated on machines, you might need to configure automatic MDM enrollment. - -Use the following tables to understand the possible causes of issues while onboarding: - -- Microsoft Intune error codes and OMA-URIs table -- Known issues with non-compliance table -- Mobile Device Management (MDM) event logs table - -If none of the event logs and troubleshooting steps work, download the Local script from the **Machine management** section of the portal, and run it in an elevated command prompt. - -**Microsoft Intune error codes and OMA-URIs**: - - -Error Code Hex | Error Code Dec | Error Description | OMA-URI | Possible cause and troubleshooting steps -:---|:---|:---|:---|:--- -0x87D1FDE8 | -2016281112 | Remediation failed | Onboarding
Offboarding | **Possible cause:** Onboarding or offboarding failed on a wrong blob: wrong signature or missing PreviousOrgIds fields.

**Troubleshooting steps:**
Check the event IDs in the [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) section.

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). - | | | | Onboarding
Offboarding
SampleSharing | **Possible cause:** Windows Defender ATP Policy registry key does not exist or the OMA DM client doesn't have permissions to write to it.

**Troubleshooting steps:** Ensure that the following registry key exists: ```HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```

If it doesn't exist, open an elevated command and add the key. - | | | | SenseIsRunning
OnboardingState
OrgId | **Possible cause:** An attempt to remediate by read-only property. Onboarding has failed.

**Troubleshooting steps:** Check the troubleshooting steps in [Troubleshoot onboarding issues on the machine](#troubleshoot-onboarding-issues-on-the-machine).

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). - || | | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional.
Server is not supported. - 0x87D101A9 | -2016345687 |Syncml(425): The requested command failed because the sender does not have adequate access control permissions (ACL) on the recipient. | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional. - -
-**Known issues with non-compliance** - -The following table provides information on issues with non-compliance and how you can address the issues. - -Case | Symptoms | Possible cause and troubleshooting steps -:---|:---|:--- -1 | Machine is compliant by SenseIsRunning OMA-URI. But is non-compliant by OrgId, Onboarding and OnboardingState OMA-URIs. | **Possible cause:** Check that user passed OOBE after Windows installation or upgrade. During OOBE onboarding couldn't be completed but SENSE is running already.

**Troubleshooting steps:** Wait for OOBE to complete. -2 | Machine is compliant by OrgId, Onboarding, and OnboardingState OMA-URIs, but is non-compliant by SenseIsRunning OMA-URI. | **Possible cause:** Sense service's startup type is set as "Delayed Start". Sometimes this causes the Microsoft Intune server to report the machine as non-compliant by SenseIsRunning when DM session occurs on system start.

**Troubleshooting steps:** The issue should automatically be fixed within 24 hours. -3 | Machine is non-compliant | **Troubleshooting steps:** Ensure that Onboarding and Offboarding policies are not deployed on the same machine at same time. - -
-**Mobile Device Management (MDM) event logs** - -View the MDM event logs to troubleshoot issues that might arise during onboarding: - -Log name: Microsoft\Windows\DeviceManagement-EnterpriseDiagnostics-Provider - -Channel name: Admin - -ID | Severity | Event description | Troubleshooting steps -:---|:---|:---|:--- -1819 | Error | Windows Defender Advanced Threat Protection CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3). | Download the [Cumulative Update for Windows 10, 1607](https://go.microsoft.com/fwlink/?linkid=829760). - -## Troubleshoot onboarding issues on the machine -If the deployment tools used does not indicate an error in the onboarding process, but machines are still not appearing in the machines list in an hour, go through the following verification topics to check if an error occurred with the Windows Defender ATP agent: -- [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) -- [Ensure the diagnostic data service is enabled](#ensure-the-diagnostics-service-is-enabled) -- [Ensure the service is set to start](#ensure-the-service-is-set-to-start) -- [Ensure the machine has an Internet connection](#ensure-the-machine-has-an-internet-connection) -- [Ensure that Windows Defender Antivirus is not disabled by a policy](#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy) - - -### View agent onboarding errors in the machine event log - -1. Click **Start**, type **Event Viewer**, and press **Enter**. - -2. In the **Event Viewer (Local)** pane, expand **Applications and Services Logs** > **Microsoft** > **Windows** > **SENSE**. - - > [!NOTE] - > SENSE is the internal name used to refer to the behavioral sensor that powers Windows Defender ATP. - -3. Select **Operational** to load the log. - -4. In the **Action** pane, click **Filter Current log**. - -5. On the **Filter** tab, under **Event level:** select **Critical**, **Warning**, and **Error**, and click **OK**. - - ![Image of Event Viewer log filter](images/filter-log.png) - -6. Events which can indicate issues will appear in the **Operational** pane. You can attempt to troubleshoot them based on the solutions in the following table: - -Event ID | Message | Resolution steps -:---|:---|:--- -5 | Windows Defender Advanced Threat Protection service failed to connect to the server at _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -6 | Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). -7 | Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection), then run the entire onboarding process again. -9 | Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the event happened during offboarding, contact support. -10 | Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the problem persists, contact support. -15 | Windows Defender Advanced Threat Protection cannot start command channel with URL: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -17 | Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). If the problem persists, contact support. -25 | Windows Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: _variable_ | Contact support. -27 | Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: variable | Contact support. -29 | Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3 | Ensure the machine has Internet access, then run the entire offboarding process again. -30 | Failed to disable $(build.sense.productDisplayName) mode in Windows Defender Advanced Threat Protection. Failure code: %1 | Contact support. -32 | $(build.sense.productDisplayName) service failed to request to stop itself after offboarding process. Failure code: %1 | Verify that the service start type is manual and reboot the machine. -55 | Failed to create the Secure ETW autologger. Failure code: %1 | Reboot the machine. -63 | Updating the start type of external service. Name: %1, actual start type: %2, expected start type: %3, exit code: %4 | Identify what is causing changes in start type of mentioned service. If the exit code is not 0, fix the start type manually to expected start type. -64 | Starting stopped external service. Name: %1, exit code: %2 | Contact support if the event keeps re-appearing. -68 | The start type of the service is unexpected. Service name: %1, actual start type: %2, expected start type: %3 | Identify what is causing changes in start type. Fix mentioned service start type. -69 | The service is stopped. Service name: %1 | Start the mentioned service. Contact support if persists. - -
-There are additional components on the machine that the Windows Defender ATP agent depends on to function properly. If there are no onboarding related errors in the Windows Defender ATP agent event log, proceed with the following steps to ensure that the additional components are configured correctly. - - -### Ensure the diagnostic data service is enabled -If the machines aren't reporting correctly, you might need to check that the Windows 10 diagnostic data service is set to automatically start and is running on the machine. The service might have been disabled by other programs or user configuration changes. - -First, you should check that the service is set to start automatically when Windows starts, then you should check that the service is currently running (and start it if it isn't). - -### Ensure the service is set to start - -**Use the command line to check the Windows 10 diagnostic data service startup type**: - -1. Open an elevated command-line prompt on the machine: - - a. Click **Start**, type **cmd**, and press **Enter**. - - b. Right-click **Command prompt** and select **Run as administrator**. - -2. Enter the following command, and press **Enter**: - - ```text - sc qc diagtrack - ``` - - If the service is enabled, then the result should look like the following screenshot: - - ![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png) - - If the `START_TYPE` is not set to `AUTO_START`, then you'll need to set the service to automatically start. - - -**Use the command line to set the Windows 10 diagnostic data service to automatically start:** - -1. Open an elevated command-line prompt on the machine: - - a. Click **Start**, type **cmd**, and press **Enter**. - - b. Right-click **Command prompt** and select **Run as administrator**. - -2. Enter the following command, and press **Enter**: - - ```text - sc config diagtrack start=auto - ``` - -3. A success message is displayed. Verify the change by entering the following command, and press **Enter**: - - ```text - sc qc diagtrack - ``` - -4. Start the service. - - a. In the command prompt, type the following command and press **Enter**: - - ```text - sc start diagtrack - ``` - -### Ensure the machine has an Internet connection - -The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. - -WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. - -To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. - -If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) topic. - -### Ensure that Windows Defender Antivirus is not disabled by a policy -**Problem**: The Windows Defender ATP service does not start after onboarding. - -**Symptom**: Onboarding successfully completes, but you see error 577 when trying to start the service. - -**Solution**: If your machines are running a third-party antimalware client, the Windows Defender ATP agent needs the Windows Defender Early Launch Antimalware (ELAM) driver to be enabled. You must ensure that it's not disabled in system policy. - -- Depending on the tool that you use to implement policies, you'll need to verify that the following Windows Defender policies are cleared: - - - DisableAntiSpyware - - DisableAntiVirus - - For example, in Group Policy there should be no entries such as the following values: - - - `````` - - `````` -- After clearing the policy, run the onboarding steps again. - -- You can also check the following registry key values to verify that the policy is disabled: - - 1. Open the registry ```key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender```. - 2. Ensure that the value ```DisableAntiSpyware``` is not present. - - ![Image of registry key for Windows Defender Antivirus](images/atp-disableantispyware-regkey.png) - - -## Troubleshoot onboarding issues on a server -If you encounter issues while onboarding a server, go through the following verification steps to address possible issues. - -- [Ensure Microsoft Monitoring Agent (MMA) is installed and configured to report sensor data to the service](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-mma) -- [Ensure that the server proxy and Internet connectivity settings are configured properly](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-proxy) - -You might also need to check the following: -- Check that there is a Windows Defender Advanced Threat Protection Service running in the **Processes** tab in **Task Manager**. For example: - - ![Image of process view with Windows Defender Advanced Threat Protection Service running](images/atp-task-manager.png) - -- Check **Event Viewer** > **Applications and Services Logs** > **Operation Manager** to see if there are any errors. - -- In **Services**, check if the **Microsoft Monitoring Agent** is running on the server. For example, - - ![Image of Services](images/atp-services.png) - -- In **Microsoft Monitoring Agent** > **Azure Log Analytics (OMS)**, check the Workspaces and verify that the status is running. - - ![Image of Microsoft Monitoring Agent Properties](images/atp-mma-properties.png) - -- Check to see that machines are reflected in the **Machines list** in the portal. - - -## Licensing requirements -Windows Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: - - - Windows 10 Enterprise E5 - - Windows 10 Education E5 - - Microsoft 365 Enterprise E5 which includes Windows 10 Enterprise E5 - -For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2). - - ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootonboarding-belowfoldlink) - - -## Related topics -- [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) -- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) -- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) - +--- +title: Troubleshoot Windows Defender ATP onboarding issues +description: Troubleshoot issues that might arise during the onboarding of machines or to the Windows Defender ATP service. +keywords: troubleshoot onboarding, onboarding issues, event viewer, data collection and preview builds, sensor data and diagnostics +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: macapara +author: mjcaparas +ms.localizationpriority: medium +manager: dansimp +audience: ITPro +ms.collection: M365-security-compliance +ms.topic: troubleshooting +--- + +# Troubleshoot Windows Defender Advanced Threat Protection onboarding issues + +**Applies to:** +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- Windows Server 2012 R2 +- Windows Server 2016 + + + +You might need to troubleshoot the Windows Defender ATP onboarding process if you encounter issues. +This page provides detailed steps to troubleshoot onboarding issues that might occur when deploying with one of the deployment tools and common errors that might occur on the machines. + +If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, it might indicate an onboarding or connectivity problem. + +## Troubleshoot onboarding when deploying with Group Policy +Deployment with Group Policy is done by running the onboarding script on the machines. The Group Policy console does not indicate if the deployment has succeeded or not. + +If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, you can check the output of the script on the machines. For more information, see [Troubleshoot onboarding when deploying with a script](#troubleshoot-onboarding-when-deploying-with-a-script). + +If the script completes successfully, see [Troubleshoot onboarding issues on the machines](#troubleshoot-onboarding-issues-on-the-machine) for additional errors that might occur. + +## Troubleshoot onboarding issues when deploying with System Center Configuration Manager +When onboarding machines using the following versions of System Center Configuration Manager: +- System Center 2012 Configuration Manager +- System Center 2012 R2 Configuration Manager +- System Center Configuration Manager (current branch) version 1511 +- System Center Configuration Manager (current branch) version 1602 + + +Deployment with the above-mentioned versions of System Center Configuration Manager is done by running the onboarding script on the machines. You can track the deployment in the Configuration Manager Console. + +If the deployment fails, you can check the output of the script on the machines. + +If the onboarding completed successfully but the machines are not showing up in the **Machines list** after an hour, see [Troubleshoot onboarding issues on the machine](#troubleshoot-onboarding-issues-on-the-machine) for additional errors that might occur. + +## Troubleshoot onboarding when deploying with a script + +**Check the result of the script on the machine**: +1. Click **Start**, type **Event Viewer**, and press **Enter**. + +2. Go to **Windows Logs** > **Application**. + +3. Look for an event from **WDATPOnboarding** event source. + +If the script fails and the event is an error, you can check the event ID in the following table to help you troubleshoot the issue. +> [!NOTE] +> The following event IDs are specific to the onboarding script only. + +Event ID | Error Type | Resolution steps +:---|:---|:--- +5 | Offboarding data was found but couldn't be deleted | Check the permissions on the registry, specifically ```HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```. +10 | Onboarding data couldn't be written to registry | Check the permissions on the registry, specifically
```HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat```.
Verify that the script was ran as an administrator. +15 | Failed to start SENSE service |Check the service health (```sc query sense``` command). Make sure it's not in an intermediate state (*'Pending_Stopped'*, *'Pending_Running'*) and try to run the script again (with administrator rights).

If the machine is running Windows 10, version 1607 and running the command `sc query sense` returns `START_PENDING`, reboot the machine. If rebooting the machine doesn't address the issue, upgrade to KB4015217 and try onboarding again. +15 | Failed to start SENSE service | If the message of the error is: System error 577 has occurred. You need to enable the Windows Defender Antivirus ELAM driver, see [Ensure that Windows Defender Antivirus is not disabled by a policy](#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy) for instructions. +30 | The script failed to wait for the service to start running | The service could have taken more time to start or has encountered errors while trying to start. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). +35 | The script failed to find needed onboarding status registry value | When the SENSE service starts for the first time, it writes onboarding status to the registry location
```HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status```.
The script failed to find it after several seconds. You can manually test it and check if it's there. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). +40 | SENSE service onboarding status is not set to **1** | The SENSE service has failed to onboard properly. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). +65 | Insufficient privileges| Run the script again with administrator privileges. + +## Troubleshoot onboarding issues using Microsoft Intune +You can use Microsoft Intune to check error codes and attempt to troubleshoot the cause of the issue. + +If you have configured policies in Intune and they are not propagated on machines, you might need to configure automatic MDM enrollment. + +Use the following tables to understand the possible causes of issues while onboarding: + +- Microsoft Intune error codes and OMA-URIs table +- Known issues with non-compliance table +- Mobile Device Management (MDM) event logs table + +If none of the event logs and troubleshooting steps work, download the Local script from the **Machine management** section of the portal, and run it in an elevated command prompt. + +**Microsoft Intune error codes and OMA-URIs**: + + +Error Code Hex | Error Code Dec | Error Description | OMA-URI | Possible cause and troubleshooting steps +:---|:---|:---|:---|:--- +0x87D1FDE8 | -2016281112 | Remediation failed | Onboarding
Offboarding | **Possible cause:** Onboarding or offboarding failed on a wrong blob: wrong signature or missing PreviousOrgIds fields.

**Troubleshooting steps:**
Check the event IDs in the [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) section.

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). + | | | | Onboarding
Offboarding
SampleSharing | **Possible cause:** Windows Defender ATP Policy registry key does not exist or the OMA DM client doesn't have permissions to write to it.

**Troubleshooting steps:** Ensure that the following registry key exists: ```HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```

If it doesn't exist, open an elevated command and add the key. + | | | | SenseIsRunning
OnboardingState
OrgId | **Possible cause:** An attempt to remediate by read-only property. Onboarding has failed.

**Troubleshooting steps:** Check the troubleshooting steps in [Troubleshoot onboarding issues on the machine](#troubleshoot-onboarding-issues-on-the-machine).

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). + || | | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional.
Server is not supported. + 0x87D101A9 | -2016345687 |Syncml(425): The requested command failed because the sender does not have adequate access control permissions (ACL) on the recipient. | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional. + +
+**Known issues with non-compliance** + +The following table provides information on issues with non-compliance and how you can address the issues. + +Case | Symptoms | Possible cause and troubleshooting steps +:---|:---|:--- +1 | Machine is compliant by SenseIsRunning OMA-URI. But is non-compliant by OrgId, Onboarding and OnboardingState OMA-URIs. | **Possible cause:** Check that user passed OOBE after Windows installation or upgrade. During OOBE onboarding couldn't be completed but SENSE is running already.

**Troubleshooting steps:** Wait for OOBE to complete. +2 | Machine is compliant by OrgId, Onboarding, and OnboardingState OMA-URIs, but is non-compliant by SenseIsRunning OMA-URI. | **Possible cause:** Sense service's startup type is set as "Delayed Start". Sometimes this causes the Microsoft Intune server to report the machine as non-compliant by SenseIsRunning when DM session occurs on system start.

**Troubleshooting steps:** The issue should automatically be fixed within 24 hours. +3 | Machine is non-compliant | **Troubleshooting steps:** Ensure that Onboarding and Offboarding policies are not deployed on the same machine at same time. + +
+**Mobile Device Management (MDM) event logs** + +View the MDM event logs to troubleshoot issues that might arise during onboarding: + +Log name: Microsoft\Windows\DeviceManagement-EnterpriseDiagnostics-Provider + +Channel name: Admin + +ID | Severity | Event description | Troubleshooting steps +:---|:---|:---|:--- +1819 | Error | Windows Defender Advanced Threat Protection CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3). | Download the [Cumulative Update for Windows 10, 1607](https://go.microsoft.com/fwlink/?linkid=829760). + +## Troubleshoot onboarding issues on the machine +If the deployment tools used does not indicate an error in the onboarding process, but machines are still not appearing in the machines list in an hour, go through the following verification topics to check if an error occurred with the Windows Defender ATP agent: +- [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) +- [Ensure the diagnostic data service is enabled](#ensure-the-diagnostics-service-is-enabled) +- [Ensure the service is set to start](#ensure-the-service-is-set-to-start) +- [Ensure the machine has an Internet connection](#ensure-the-machine-has-an-internet-connection) +- [Ensure that Windows Defender Antivirus is not disabled by a policy](#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy) + + +### View agent onboarding errors in the machine event log + +1. Click **Start**, type **Event Viewer**, and press **Enter**. + +2. In the **Event Viewer (Local)** pane, expand **Applications and Services Logs** > **Microsoft** > **Windows** > **SENSE**. + + > [!NOTE] + > SENSE is the internal name used to refer to the behavioral sensor that powers Windows Defender ATP. + +3. Select **Operational** to load the log. + +4. In the **Action** pane, click **Filter Current log**. + +5. On the **Filter** tab, under **Event level:** select **Critical**, **Warning**, and **Error**, and click **OK**. + + ![Image of Event Viewer log filter](images/filter-log.png) + +6. Events which can indicate issues will appear in the **Operational** pane. You can attempt to troubleshoot them based on the solutions in the following table: + +Event ID | Message | Resolution steps +:---|:---|:--- +5 | Windows Defender Advanced Threat Protection service failed to connect to the server at _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). +6 | Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). +7 | Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection), then run the entire onboarding process again. +9 | Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the event happened during offboarding, contact support. +10 | Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the problem persists, contact support. +15 | Windows Defender Advanced Threat Protection cannot start command channel with URL: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). +17 | Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). If the problem persists, contact support. +25 | Windows Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: _variable_ | Contact support. +27 | Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: variable | Contact support. +29 | Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3 | Ensure the machine has Internet access, then run the entire offboarding process again. +30 | Failed to disable $(build.sense.productDisplayName) mode in Windows Defender Advanced Threat Protection. Failure code: %1 | Contact support. +32 | $(build.sense.productDisplayName) service failed to request to stop itself after offboarding process. Failure code: %1 | Verify that the service start type is manual and reboot the machine. +55 | Failed to create the Secure ETW autologger. Failure code: %1 | Reboot the machine. +63 | Updating the start type of external service. Name: %1, actual start type: %2, expected start type: %3, exit code: %4 | Identify what is causing changes in start type of mentioned service. If the exit code is not 0, fix the start type manually to expected start type. +64 | Starting stopped external service. Name: %1, exit code: %2 | Contact support if the event keeps re-appearing. +68 | The start type of the service is unexpected. Service name: %1, actual start type: %2, expected start type: %3 | Identify what is causing changes in start type. Fix mentioned service start type. +69 | The service is stopped. Service name: %1 | Start the mentioned service. Contact support if persists. + +
+There are additional components on the machine that the Windows Defender ATP agent depends on to function properly. If there are no onboarding related errors in the Windows Defender ATP agent event log, proceed with the following steps to ensure that the additional components are configured correctly. + + +### Ensure the diagnostic data service is enabled +If the machines aren't reporting correctly, you might need to check that the Windows 10 diagnostic data service is set to automatically start and is running on the machine. The service might have been disabled by other programs or user configuration changes. + +First, you should check that the service is set to start automatically when Windows starts, then you should check that the service is currently running (and start it if it isn't). + +### Ensure the service is set to start + +**Use the command line to check the Windows 10 diagnostic data service startup type**: + +1. Open an elevated command-line prompt on the machine: + + a. Click **Start**, type **cmd**, and press **Enter**. + + b. Right-click **Command prompt** and select **Run as administrator**. + +2. Enter the following command, and press **Enter**: + + ```text + sc qc diagtrack + ``` + + If the service is enabled, then the result should look like the following screenshot: + + ![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png) + + If the `START_TYPE` is not set to `AUTO_START`, then you'll need to set the service to automatically start. + + +**Use the command line to set the Windows 10 diagnostic data service to automatically start:** + +1. Open an elevated command-line prompt on the machine: + + a. Click **Start**, type **cmd**, and press **Enter**. + + b. Right-click **Command prompt** and select **Run as administrator**. + +2. Enter the following command, and press **Enter**: + + ```text + sc config diagtrack start=auto + ``` + +3. A success message is displayed. Verify the change by entering the following command, and press **Enter**: + + ```text + sc qc diagtrack + ``` + +4. Start the service. + + a. In the command prompt, type the following command and press **Enter**: + + ```text + sc start diagtrack + ``` + +### Ensure the machine has an Internet connection + +The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. + +WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. + +To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. + +If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) topic. + +### Ensure that Windows Defender Antivirus is not disabled by a policy +**Problem**: The Windows Defender ATP service does not start after onboarding. + +**Symptom**: Onboarding successfully completes, but you see error 577 when trying to start the service. + +**Solution**: If your machines are running a third-party antimalware client, the Windows Defender ATP agent needs the Windows Defender Early Launch Antimalware (ELAM) driver to be enabled. You must ensure that it's not disabled in system policy. + +- Depending on the tool that you use to implement policies, you'll need to verify that the following Windows Defender policies are cleared: + + - DisableAntiSpyware + - DisableAntiVirus + + For example, in Group Policy there should be no entries such as the following values: + + - `````` + - `````` +- After clearing the policy, run the onboarding steps again. + +- You can also check the following registry key values to verify that the policy is disabled: + + 1. Open the registry ```key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender```. + 2. Ensure that the value ```DisableAntiSpyware``` is not present. + + ![Image of registry key for Windows Defender Antivirus](images/atp-disableantispyware-regkey.png) + + +## Troubleshoot onboarding issues on a server +If you encounter issues while onboarding a server, go through the following verification steps to address possible issues. + +- [Ensure Microsoft Monitoring Agent (MMA) is installed and configured to report sensor data to the service](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-mma) +- [Ensure that the server proxy and Internet connectivity settings are configured properly](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-proxy) + +You might also need to check the following: +- Check that there is a Windows Defender Advanced Threat Protection Service running in the **Processes** tab in **Task Manager**. For example: + + ![Image of process view with Windows Defender Advanced Threat Protection Service running](images/atp-task-manager.png) + +- Check **Event Viewer** > **Applications and Services Logs** > **Operation Manager** to see if there are any errors. + +- In **Services**, check if the **Microsoft Monitoring Agent** is running on the server. For example, + + ![Image of Services](images/atp-services.png) + +- In **Microsoft Monitoring Agent** > **Azure Log Analytics (OMS)**, check the Workspaces and verify that the status is running. + + ![Image of Microsoft Monitoring Agent Properties](images/atp-mma-properties.png) + +- Check to see that machines are reflected in the **Machines list** in the portal. + + +## Licensing requirements +Windows Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: + + - Windows 10 Enterprise E5 + - Windows 10 Education E5 + - Microsoft 365 Enterprise E5 which includes Windows 10 Enterprise E5 + +For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2). + + +>Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootonboarding-belowfoldlink) + + +## Related topics +- [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) +- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) +- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) + diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-wdatp.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-wdatp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-wdatp.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-wdatp.md diff --git a/windows/security/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/use-apis.md b/windows/security/threat-protection/microsoft-defender-atp/use-apis.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/use-apis.md rename to windows/security/threat-protection/microsoft-defender-atp/use-apis.md diff --git a/windows/security/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/use-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/use-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/use-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/use-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/user-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/user-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md diff --git a/windows/security/threat-protection/windows-defender-atp/view-incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/view-incidents-queue.md rename to windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md diff --git a/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-windows-defender-atp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp.md rename to windows/security/threat-protection/microsoft-defender-atp/whats-new-in-windows-defender-atp.md diff --git a/windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/windows-defender-advanced-threat-protection.md diff --git a/windows/security/threat-protection/windows-defender-atp/windows-defender-security-center-atp.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md similarity index 100% rename from windows/security/threat-protection/windows-defender-atp/windows-defender-security-center-atp.md rename to windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md From 16f21c04d15ecb6ac56b1af4caf6cd7ab0984a1a Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 13:51:55 -0700 Subject: [PATCH 126/737] in tp toc - change wdatp/ to mdatp --- windows/security/threat-protection/TOC.md | 426 +++++++++++----------- 1 file changed, 213 insertions(+), 213 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index caec919411..16acd664ab 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -1,10 +1,10 @@ # [Threat protection](index.md) -## [Windows Defender Advanced Threat Protection](windows-defender-atp/windows-defender-advanced-threat-protection.md) +## [Windows Defender Advanced Threat Protection](microsoft-defender-atp/windows-defender-advanced-threat-protection.md) -### [Overview](windows-defender-atp/overview.md) -#### [Attack surface reduction](windows-defender-atp/overview-attack-surface-reduction.md) -##### [Hardware-based isolation](windows-defender-atp/overview-hardware-based-isolation.md) +### [Overview](microsoft-defender-atp/overview.md) +#### [Attack surface reduction](microsoft-defender-atp/overview-attack-surface-reduction.md) +##### [Hardware-based isolation](microsoft-defender-atp/overview-hardware-based-isolation.md) ###### [Application isolation](windows-defender-application-guard/wd-app-guard-overview.md) ####### [System requirements](windows-defender-application-guard/reqs-wd-app-guard.md) ###### [System integrity](windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md) @@ -15,104 +15,104 @@ ##### [Attack surface reduction](windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md) ##### [Network firewall](windows-firewall/windows-firewall-with-advanced-security.md) #### [Next generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) -#### [Endpoint detection and response](windows-defender-atp/overview-endpoint-detection-response.md) -##### [Security operations dashboard](windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md) +#### [Endpoint detection and response](microsoft-defender-atp/overview-endpoint-detection-response.md) +##### [Security operations dashboard](microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md) -##### [Incidents queue](windows-defender-atp/incidents-queue.md) -###### [View and organize the Incidents queue](windows-defender-atp/view-incidents-queue.md) -###### [Manage incidents](windows-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md) -###### [Investigate incidents](windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md) +##### [Incidents queue](microsoft-defender-atp/incidents-queue.md) +###### [View and organize the Incidents queue](microsoft-defender-atp/view-incidents-queue.md) +###### [Manage incidents](microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md) +###### [Investigate incidents](microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md) ##### Alerts queue -###### [View and organize the Alerts queue](windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md) -###### [Manage alerts](windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md) -###### [Investigate alerts](windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md) -###### [Investigate files](windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md) -###### [Investigate machines](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md) -###### [Investigate an IP address](windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md) -###### [Investigate a domain](windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md) -###### [Investigate a user account](windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md) +###### [View and organize the Alerts queue](microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md) +###### [Manage alerts](microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md) +###### [Investigate alerts](microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md) +###### [Investigate files](microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md) +###### [Investigate machines](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md) +###### [Investigate an IP address](microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md) +###### [Investigate a domain](microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md) +###### [Investigate a user account](microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md) ##### Machines list -###### [View and organize the Machines list](windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md) -###### [Manage machine group and tags](windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) -###### [Alerts related to this machine](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine) -###### [Machine timeline](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline) -####### [Search for specific events](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events) -####### [Filter events from a specific date](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) -####### [Export machine timeline events](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) -####### [Navigate between pages](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) +###### [View and organize the Machines list](microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md) +###### [Manage machine group and tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) +###### [Alerts related to this machine](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine) +###### [Machine timeline](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline) +####### [Search for specific events](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events) +####### [Filter events from a specific date](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) +####### [Export machine timeline events](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) +####### [Navigate between pages](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) -##### [Take response actions](windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md) -###### [Take response actions on a machine](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md) -####### [Collect investigation package](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines) -####### [Run antivirus scan](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines) -####### [Restrict app execution](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution) -####### [Remove app restriction](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction) -####### [Isolate machines from the network](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) -####### [Release machine from isolation](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation) -####### [Check activity details in Action center](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +##### [Take response actions](microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md) +###### [Take response actions on a machine](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md) +####### [Collect investigation package](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines) +####### [Run antivirus scan](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines) +####### [Restrict app execution](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution) +####### [Remove app restriction](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction) +####### [Isolate machines from the network](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) +####### [Release machine from isolation](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation) +####### [Check activity details in Action center](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) -###### [Take response actions on a file](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md) -####### [Stop and quarantine files in your network](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) -####### [Remove file from quarantine](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) -####### [Block files in your network](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) -####### [Remove file from blocked list](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list) -####### [Check activity details in Action center](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) -####### [Deep analysis](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) -####### [Submit files for analysis](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) -####### [View deep analysis reports](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) -####### [Troubleshoot deep analysis](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) +###### [Take response actions on a file](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md) +####### [Stop and quarantine files in your network](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) +####### [Remove file from quarantine](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) +####### [Block files in your network](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) +####### [Remove file from blocked list](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list) +####### [Check activity details in Action center](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +####### [Deep analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) +####### [Submit files for analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) +####### [View deep analysis reports](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) +####### [Troubleshoot deep analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) -#### [Automated investigation and remediation](windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md) -##### [Learn about the automated investigation and remediation dashboard](windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md) +#### [Automated investigation and remediation](microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md) +##### [Learn about the automated investigation and remediation dashboard](microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md) -#### [Secure score](windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md) -#### [Threat analytics](windows-defender-atp/threat-analytics.md) +#### [Secure score](microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md) +#### [Threat analytics](microsoft-defender-atp/threat-analytics.md) -#### [Advanced hunting](windows-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md) -##### [Query data using Advanced hunting](windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md) -###### [Advanced hunting reference](windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md) -###### [Advanced hunting query language best practices](windows-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) -##### [Custom detections](windows-defender-atp/overview-custom-detections.md) -###### [Create custom detections rules](windows-defender-atp/custom-detection-rules.md) +#### [Advanced hunting](microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md) +##### [Query data using Advanced hunting](microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md) +###### [Advanced hunting reference](microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md) +###### [Advanced hunting query language best practices](microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) +##### [Custom detections](microsoft-defender-atp/overview-custom-detections.md) +###### [Create custom detections rules](microsoft-defender-atp/custom-detection-rules.md) -#### [Management and APIs](windows-defender-atp/management-apis.md) -##### [Understand threat intelligence concepts](windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -##### [Windows Defender ATP APIs](windows-defender-atp/apis-intro.md) -##### [Managed security service provider support](windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md) +#### [Management and APIs](microsoft-defender-atp/management-apis.md) +##### [Understand threat intelligence concepts](microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md) +##### [Windows Defender ATP APIs](microsoft-defender-atp/apis-intro.md) +##### [Managed security service provider support](microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md) -#### [Microsoft threat protection](windows-defender-atp/threat-protection-integration.md) -##### [Protect users, data, and devices with conditional access](windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md) -##### [Microsoft Cloud App Security integration overview](windows-defender-atp/microsoft-cloud-app-security-integration.md) -##### [Information protection in Windows overview](windows-defender-atp/information-protection-in-windows-overview.md) +#### [Microsoft threat protection](microsoft-defender-atp/threat-protection-integration.md) +##### [Protect users, data, and devices with conditional access](microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md) +##### [Microsoft Cloud App Security integration overview](microsoft-defender-atp/microsoft-cloud-app-security-integration.md) +##### [Information protection in Windows overview](microsoft-defender-atp/information-protection-in-windows-overview.md) -#### [Microsoft Threat Experts](windows-defender-atp/microsoft-threat-experts.md) +#### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md) -#### [Portal overview](windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md) +#### [Portal overview](microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md) -### [Get started](windows-defender-atp/get-started.md) -#### [What's new in Windows Defender ATP](windows-defender-atp/whats-new-in-windows-defender-atp.md) -#### [Minimum requirements](windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md) -#### [Validate licensing and complete setup](windows-defender-atp/licensing-windows-defender-advanced-threat-protection.md) -#### [Preview features](windows-defender-atp/preview-windows-defender-advanced-threat-protection.md) -#### [Data storage and privacy](windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md) -#### [Assign user access to the portal](windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md) +### [Get started](microsoft-defender-atp/get-started.md) +#### [What's new in Windows Defender ATP](microsoft-defender-atp/whats-new-in-windows-defender-atp.md) +#### [Minimum requirements](microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md) +#### [Validate licensing and complete setup](microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md) +#### [Preview features](microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md) +#### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md) +#### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md) -#### [Evaluate Windows Defender ATP](windows-defender-atp/evaluate-atp.md) +#### [Evaluate Windows Defender ATP](microsoft-defender-atp/evaluate-atp.md) #####Evaluate attack surface reduction ###### [Hardware-based isolation](windows-defender-application-guard/test-scenarios-wd-app-guard.md) ###### [Application control](windows-defender-application-control/audit-windows-defender-application-control-policies.md) @@ -123,10 +123,10 @@ ###### [Network firewall](windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) ##### [Evaluate next generation protection](windows-defender-antivirus/evaluate-windows-defender-antivirus.md) -#### [Access the Windows Defender Security Center Community Center](windows-defender-atp/community-windows-defender-advanced-threat-protection.md) +#### [Access the Windows Defender Security Center Community Center](microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md) -### [Configure and manage capabilities](windows-defender-atp/onboard.md) -#### [Configure attack surface reduction](windows-defender-atp/configure-attack-surface-reduction.md) +### [Configure and manage capabilities](microsoft-defender-atp/onboard.md) +#### [Configure attack surface reduction](microsoft-defender-atp/configure-attack-surface-reduction.md) #####Hardware-based isolation ###### [System isolation](windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md) ###### [Application isolation](windows-defender-application-guard/install-wd-app-guard.md) @@ -213,203 +213,203 @@ ###### [Use the mpcmdrun.exe command line tool to manage next generation protection](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) -#### [Configure Secure score dashboard security controls](windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md) +#### [Configure Secure score dashboard security controls](microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md) #### Management and API support -##### [Onboard machines](windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) -###### [Onboard previous versions of Windows](windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md) -###### [Onboard Windows 10 machines](windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using Group Policy](windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using System Center Configuration Manager](windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using Mobile Device Management tools](windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -######## [Onboard machines using Microsoft Intune](windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#onboard-machines-using-microsoft-intune) -####### [Onboard machines using a local script](windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md) -####### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -###### [Onboard servers](windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md) -###### [Onboard non-Windows machines](windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) -###### [Run a detection test on a newly onboarded machine](windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md) -###### [Run simulated attacks on machines](windows-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md) -###### [Configure proxy and Internet connectivity settings](windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot onboarding issues](windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) -####### [Troubleshoot subscription and portal access issues](windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) +##### [Onboard machines](microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) +###### [Onboard previous versions of Windows](microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md) +###### [Onboard Windows 10 machines](microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md) +####### [Onboard machines using Group Policy](microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md) +####### [Onboard machines using System Center Configuration Manager](microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) +####### [Onboard machines using Mobile Device Management tools](microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) +######## [Onboard machines using Microsoft Intune](microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#onboard-machines-using-microsoft-intune) +####### [Onboard machines using a local script](microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md) +####### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) +###### [Onboard servers](microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md) +###### [Onboard non-Windows machines](microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) +###### [Run a detection test on a newly onboarded machine](microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md) +###### [Run simulated attacks on machines](microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md) +###### [Configure proxy and Internet connectivity settings](microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md) +###### [Troubleshoot onboarding issues](microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +####### [Troubleshoot subscription and portal access issues](microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) -##### [Windows Defender ATP API](windows-defender-atp/use-apis.md) -###### [Get started with Windows Defender ATP APIs](windows-defender-atp/apis-intro.md) -####### [Hello World](windows-defender-atp/api-hello-world.md) -####### [Get access with application context](windows-defender-atp/exposed-apis-create-app-webapp.md) -####### [Get access with user context](windows-defender-atp/exposed-apis-create-app-nativeapp.md) -###### [APIs](windows-defender-atp/exposed-apis-list.md) +##### [Windows Defender ATP API](microsoft-defender-atp/use-apis.md) +###### [Get started with Windows Defender ATP APIs](microsoft-defender-atp/apis-intro.md) +####### [Hello World](microsoft-defender-atp/api-hello-world.md) +####### [Get access with application context](microsoft-defender-atp/exposed-apis-create-app-webapp.md) +####### [Get access with user context](microsoft-defender-atp/exposed-apis-create-app-nativeapp.md) +###### [APIs](microsoft-defender-atp/exposed-apis-list.md) -####### [Advanced Hunting](windows-defender-atp/run-advanced-query-api.md) +####### [Advanced Hunting](microsoft-defender-atp/run-advanced-query-api.md) -####### [Alert](windows-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md) -######## [List alerts](windows-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Create alert](windows-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md) -######## [Update Alert](windows-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md) -######## [Get alert information by ID](windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related domains information](windows-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related file information](windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related IPs information](windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related machine information](windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related user information](windows-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md) +####### [Alert](microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md) +######## [List alerts](microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Create alert](microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md) +######## [Update Alert](microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md) +######## [Get alert information by ID](microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md) +######## [Get alert related domains information](microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md) +######## [Get alert related file information](microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md) +######## [Get alert related IPs information](microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md) +######## [Get alert related machine information](microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md) +######## [Get alert related user information](microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md) -####### [Machine](windows-defender-atp/machine-windows-defender-advanced-threat-protection-new.md) -######## [List machines](windows-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get machine by ID](windows-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md) -######## [Get machine log on users](windows-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md) -######## [Get machine related alerts](windows-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Add or Remove machine tags](windows-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md) -######## [Find machines by IP](windows-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md) +####### [Machine](microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md) +######## [List machines](microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md) +######## [Get machine by ID](microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md) +######## [Get machine log on users](microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md) +######## [Get machine related alerts](microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Add or Remove machine tags](microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md) +######## [Find machines by IP](microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md) -####### [Machine Action](windows-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md) -######## [List Machine Actions](windows-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) -######## [Get Machine Action](windows-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md) -######## [Collect investigation package](windows-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md) -######## [Get investigation package SAS URI](windows-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md) -######## [Isolate machine](windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md) -######## [Release machine from isolation](windows-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md) -######## [Restrict app execution](windows-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md) -######## [Remove app restriction](windows-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) -######## [Run antivirus scan](windows-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md) -######## [Offboard machine](windows-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md) -######## [Stop and quarantine file](windows-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md) -######## [Initiate investigation (preview)](windows-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md) +####### [Machine Action](microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md) +######## [List Machine Actions](microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) +######## [Get Machine Action](microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md) +######## [Collect investigation package](microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md) +######## [Get investigation package SAS URI](microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md) +######## [Isolate machine](microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md) +######## [Release machine from isolation](microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md) +######## [Restrict app execution](microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md) +######## [Remove app restriction](microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) +######## [Run antivirus scan](microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md) +######## [Offboard machine](microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md) +######## [Stop and quarantine file](microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md) +######## [Initiate investigation (preview)](microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md) -####### [Indicators (preview)](windows-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md) -######## [Submit Indicator](windows-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md) -######## [List Indicators](windows-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md) -######## [Delete Indicator](windows-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md) +####### [Indicators (preview)](microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md) +######## [Submit Indicator](microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md) +######## [List Indicators](microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md) +######## [Delete Indicator](microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md) ####### Domain -######## [Get domain related alerts](windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get domain related machines](windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get domain statistics](windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md) -######## [Is domain seen in organization](windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md) +######## [Get domain related alerts](microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Get domain related machines](microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md) +######## [Get domain statistics](microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md) +######## [Is domain seen in organization](microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md) -####### [File](windows-defender-atp/files-windows-defender-advanced-threat-protection-new.md) -######## [Get file information](windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md) -######## [Get file related alerts](windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get file related machines](windows-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get file statistics](windows-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md) +####### [File](microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md) +######## [Get file information](microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md) +######## [Get file related alerts](microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Get file related machines](microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md) +######## [Get file statistics](microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md) ####### IP -######## [Get IP related alerts](windows-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get IP related machines](windows-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get IP statistics](windows-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md) -######## [Is IP seen in organization](windows-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md) +######## [Get IP related alerts](microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Get IP related machines](microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md) +######## [Get IP statistics](microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md) +######## [Is IP seen in organization](microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md) -####### [User](windows-defender-atp/user-windows-defender-advanced-threat-protection-new.md) -######## [Get user related alerts](windows-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get user related machines](windows-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md) +####### [User](microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md) +######## [Get user related alerts](microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md) +######## [Get user related machines](microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md) ###### How to use APIs - Samples ####### Advanced Hunting API -######## [Schedule advanced Hunting using Microsoft Flow](windows-defender-atp/run-advanced-query-sample-ms-flow.md) -######## [Advanced Hunting using PowerShell](windows-defender-atp/run-advanced-query-sample-powershell.md) -######## [Advanced Hunting using Python](windows-defender-atp/run-advanced-query-sample-python.md) -######## [Create custom Power BI reports](windows-defender-atp/run-advanced-query-sample-power-bi-app-token.md) +######## [Schedule advanced Hunting using Microsoft Flow](microsoft-defender-atp/run-advanced-query-sample-ms-flow.md) +######## [Advanced Hunting using PowerShell](microsoft-defender-atp/run-advanced-query-sample-powershell.md) +######## [Advanced Hunting using Python](microsoft-defender-atp/run-advanced-query-sample-python.md) +######## [Create custom Power BI reports](microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md) ####### Multiple APIs -######## [PowerShell](windows-defender-atp/exposed-apis-full-sample-powershell.md) -####### [Using OData Queries](windows-defender-atp/exposed-apis-odata-samples.md) +######## [PowerShell](microsoft-defender-atp/exposed-apis-full-sample-powershell.md) +####### [Using OData Queries](microsoft-defender-atp/exposed-apis-odata-samples.md) #####Windows updates (KB) info -###### [Get KbInfo collection](windows-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md) +###### [Get KbInfo collection](microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md) #####Common Vulnerabilities and Exposures (CVE) to KB map -###### [Get CVE-KB map](windows-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md) +###### [Get CVE-KB map](microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md) ##### API for custom alerts -###### [Enable the custom threat intelligence application](windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Use the threat intelligence API to create custom alerts](windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Create custom threat intelligence alerts](windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md) -###### [PowerShell code examples](windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md) -###### [Python code examples](windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md) -###### [Experiment with custom threat intelligence alerts](windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot custom threat intelligence issues](windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Enable the custom threat intelligence application](microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Use the threat intelligence API to create custom alerts](microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Create custom threat intelligence alerts](microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md) +###### [PowerShell code examples](microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md) +###### [Python code examples](microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md) +###### [Experiment with custom threat intelligence alerts](microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Troubleshoot custom threat intelligence issues](microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) -##### [Pull alerts to your SIEM tools](windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md) -###### [Enable SIEM integration](windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) -###### [Configure Splunk to pull alerts](windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md) -###### [Configure HP ArcSight to pull alerts](windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md) -###### [Windows Defender ATP SIEM alert API fields](windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md) -###### [Pull alerts using SIEM REST API](windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot SIEM tool integration issues](windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md) +##### [Pull alerts to your SIEM tools](microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md) +###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) +###### [Configure Splunk to pull alerts](microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md) +###### [Configure HP ArcSight to pull alerts](microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md) +###### [Windows Defender ATP SIEM alert API fields](microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md) +###### [Pull alerts using SIEM REST API](microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +###### [Troubleshoot SIEM tool integration issues](microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md) ##### Reporting -###### [Create and build Power BI reports using Windows Defender ATP data](windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) -###### [Threat protection reports](windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md) -###### [Machine health and compliance reports](windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md) +###### [Create and build Power BI reports using Windows Defender ATP data](microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) +###### [Threat protection reports](microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md) +###### [Machine health and compliance reports](microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md) ##### Role-based access control -###### [Manage portal access using RBAC](windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md) -####### [Create and manage roles](windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine groups](windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) -######## [Create and manage machine tags](windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) +###### [Manage portal access using RBAC](microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md) +####### [Create and manage roles](microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) +####### [Create and manage machine groups](microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) +######## [Create and manage machine tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) -##### [Configure managed security service provider (MSSP) support](windows-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md) +##### [Configure managed security service provider (MSSP) support](microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md) -#### [Configure and manage Microsoft Threat Experts capabilities](windows-defender-atp/configure-microsoft-threat-experts.md) +#### [Configure and manage Microsoft Threat Experts capabilities](microsoft-defender-atp/configure-microsoft-threat-experts.md) #### Configure Microsoft threat protection integration -##### [Configure conditional access](windows-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md) -##### [Configure Microsoft Cloud App Security integration](windows-defender-atp/microsoft-cloud-app-security-config.md) -##### [Configure information protection in Windows](windows-defender-atp/information-protection-in-windows-config.md) +##### [Configure conditional access](microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md) +##### [Configure Microsoft Cloud App Security integration](microsoft-defender-atp/microsoft-cloud-app-security-config.md) +##### [Configure information protection in Windows](microsoft-defender-atp/information-protection-in-windows-config.md) -#### [Configure Windows Defender Security Center settings](windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md) +#### [Configure Windows Defender Security Center settings](microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md) ##### General -###### [Update data retention settings](windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md) -###### [Configure alert notifications](windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md) -###### [Enable and create Power BI reports using Windows Defender Security center data](windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) -###### [Enable Secure score security controls](windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md) -###### [Configure advanced features](windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md) +###### [Update data retention settings](microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md) +###### [Configure alert notifications](microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md) +###### [Enable and create Power BI reports using Windows Defender Security center data](microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) +###### [Enable Secure score security controls](microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md) +###### [Configure advanced features](microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md) ##### Permissions -###### [Use basic permissions to access the portal](windows-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md) -###### [Manage portal access using RBAC](windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md) -####### [Create and manage roles](windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine groups](windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) -######## [Create and manage machine tags](windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) +###### [Use basic permissions to access the portal](microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md) +###### [Manage portal access using RBAC](microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md) +####### [Create and manage roles](microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) +####### [Create and manage machine groups](microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) +######## [Create and manage machine tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) ##### APIs -###### [Enable Threat intel](windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Enable SIEM integration](windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) +###### [Enable Threat intel](microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) #####Rules -###### [Manage suppression rules](windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md) -###### [Manage automation allowed/blocked lists](windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -###### [Manage allowed/blocked lists](windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -###### [Manage automation file uploads](windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) -###### [Manage automation folder exclusions](windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) +###### [Manage suppression rules](microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md) +###### [Manage automation allowed/blocked lists](microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) +###### [Manage allowed/blocked lists](microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md) +###### [Manage automation file uploads](microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) +###### [Manage automation folder exclusions](microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) #####Machine management -###### [Onboarding machines](windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) -###### [Offboarding machines](windows-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md) +###### [Onboarding machines](microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) +###### [Offboarding machines](microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md) -##### [Configure Windows Defender Security Center time zone settings](windows-defender-atp/time-settings-windows-defender-advanced-threat-protection.md) +##### [Configure Windows Defender Security Center time zone settings](microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md) -### [Troubleshoot Windows Defender ATP](windows-defender-atp/troubleshoot-wdatp.md) +### [Troubleshoot Windows Defender ATP](microsoft-defender-atp/troubleshoot-wdatp.md) ####Troubleshoot sensor state -##### [Check sensor state](windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md) -##### [Fix unhealthy sensors](windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) -##### [Inactive machines](windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) -##### [Misconfigured machines](windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) -##### [Review sensor events and errors on machines with Event Viewer](windows-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md) +##### [Check sensor state](microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md) +##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) +##### [Inactive machines](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) +##### [Misconfigured machines](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) +##### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md) -#### [Troubleshoot Windows Defender ATP service issues](windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md) -##### [Check service health](windows-defender-atp/service-status-windows-defender-advanced-threat-protection.md) +#### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md) +##### [Check service health](microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md) ####Troubleshoot attack surface reduction ##### [Network protection](windows-defender-exploit-guard/troubleshoot-np.md) From 7a6786be072fde8b79a97bac47fe715872ae6689 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 14:02:15 -0700 Subject: [PATCH 127/737] remove -windows-defender-advanced-threat-protection --- windows/security/threat-protection/TOC.md | 146 +++++++++--------- ...ft-defender-advanced-threat-protection.md} | 0 2 files changed, 73 insertions(+), 73 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{windows-defender-advanced-threat-protection.md => microsoft-defender-advanced-threat-protection.md} (100%) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 16acd664ab..316afb72b1 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -1,6 +1,6 @@ # [Threat protection](index.md) -## [Windows Defender Advanced Threat Protection](microsoft-defender-atp/windows-defender-advanced-threat-protection.md) +## [Windows Defender Advanced Threat Protection](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) ### [Overview](microsoft-defender-atp/overview.md) #### [Attack surface reduction](microsoft-defender-atp/overview-attack-surface-reduction.md) @@ -110,7 +110,7 @@ #### [Validate licensing and complete setup](microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md) #### [Preview features](microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md) #### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md) -#### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md) +#### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) #### [Evaluate Windows Defender ATP](microsoft-defender-atp/evaluate-atp.md) #####Evaluate attack surface reduction @@ -123,7 +123,7 @@ ###### [Network firewall](windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) ##### [Evaluate next generation protection](windows-defender-antivirus/evaluate-windows-defender-antivirus.md) -#### [Access the Windows Defender Security Center Community Center](microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md) +#### [Access the Windows Defender Security Center Community Center](microsoft-defender-atp/community.md) ### [Configure and manage capabilities](microsoft-defender-atp/onboard.md) #### [Configure attack surface reduction](microsoft-defender-atp/configure-attack-surface-reduction.md) @@ -213,26 +213,26 @@ ###### [Use the mpcmdrun.exe command line tool to manage next generation protection](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) -#### [Configure Secure score dashboard security controls](microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md) +#### [Configure Secure score dashboard security controls](microsoft-defender-atp/secure-score-dashboard.md) #### Management and API support -##### [Onboard machines](microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) -###### [Onboard previous versions of Windows](microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md) -###### [Onboard Windows 10 machines](microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using Group Policy](microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using System Center Configuration Manager](microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using Mobile Device Management tools](microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -######## [Onboard machines using Microsoft Intune](microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#onboard-machines-using-microsoft-intune) -####### [Onboard machines using a local script](microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md) -####### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -###### [Onboard servers](microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md) -###### [Onboard non-Windows machines](microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) -###### [Run a detection test on a newly onboarded machine](microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md) -###### [Run simulated attacks on machines](microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md) -###### [Configure proxy and Internet connectivity settings](microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot onboarding issues](microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) -####### [Troubleshoot subscription and portal access issues](microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) +##### [Onboard machines](microsoft-defender-atp/onboard-configure.md) +###### [Onboard previous versions of Windows](microsoft-defender-atp/onboard-downlevel.md) +###### [Onboard Windows 10 machines](microsoft-defender-atp/configure-endpoints.md) +####### [Onboard machines using Group Policy](microsoft-defender-atp/configure-endpoints-gp.md) +####### [Onboard machines using System Center Configuration Manager](microsoft-defender-atp/configure-endpoints-sccm.md) +####### [Onboard machines using Mobile Device Management tools](microsoft-defender-atp/configure-endpoints-mdm.md) +######## [Onboard machines using Microsoft Intune](microsoft-defender-atp/configure-endpoints-mdm.md#onboard-machines-using-microsoft-intune) +####### [Onboard machines using a local script](microsoft-defender-atp/configure-endpoints-script.md) +####### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](microsoft-defender-atp/configure-endpoints-vdi.md) +###### [Onboard servers](microsoft-defender-atp/configure-server-endpoints.md) +###### [Onboard non-Windows machines](microsoft-defender-atp/configure-endpoints-non-windows.md) +###### [Run a detection test on a newly onboarded machine](microsoft-defender-atp/run-detection-test.md) +###### [Run simulated attacks on machines](microsoft-defender-atp/attack-simulations.md) +###### [Configure proxy and Internet connectivity settings](microsoft-defender-atp/configure-proxy-internet.md) +###### [Troubleshoot onboarding issues](microsoft-defender-atp/troubleshoot-onboarding.md) +####### [Troubleshoot subscription and portal access issues](microsoft-defender-atp/troubleshoot-onboarding-error-messages.md) ##### [Windows Defender ATP API](microsoft-defender-atp/use-apis.md) ###### [Get started with Windows Defender ATP APIs](microsoft-defender-atp/apis-intro.md) @@ -316,43 +316,43 @@ #####Windows updates (KB) info -###### [Get KbInfo collection](microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md) +###### [Get KbInfo collection](microsoft-defender-atp/get-kbinfo-collection.md) #####Common Vulnerabilities and Exposures (CVE) to KB map -###### [Get CVE-KB map](microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md) +###### [Get CVE-KB map](microsoft-defender-atp/get-cvekbmap-collection.md) ##### API for custom alerts -###### [Enable the custom threat intelligence application](microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Use the threat intelligence API to create custom alerts](microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Create custom threat intelligence alerts](microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md) -###### [PowerShell code examples](microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md) -###### [Python code examples](microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md) -###### [Experiment with custom threat intelligence alerts](microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot custom threat intelligence issues](microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +###### [Enable the custom threat intelligence application](microsoft-defender-atp/enable-custom-ti.md) +###### [Use the threat intelligence API to create custom alerts](microsoft-defender-atp/use-custom-ti.md) +###### [Create custom threat intelligence alerts](microsoft-defender-atp/custom-ti-api.md) +###### [PowerShell code examples](microsoft-defender-atp/powershell-example-code.md) +###### [Python code examples](microsoft-defender-atp/python-example-code.md) +###### [Experiment with custom threat intelligence alerts](microsoft-defender-atp/experiment-custom-ti.md) +###### [Troubleshoot custom threat intelligence issues](microsoft-defender-atp/troubleshoot-custom-ti.md) -##### [Pull alerts to your SIEM tools](microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md) -###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) -###### [Configure Splunk to pull alerts](microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md) -###### [Configure HP ArcSight to pull alerts](microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md) -###### [Windows Defender ATP SIEM alert API fields](microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md) -###### [Pull alerts using SIEM REST API](microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot SIEM tool integration issues](microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md) +##### [Pull alerts to your SIEM tools](microsoft-defender-atp/configure-siem.md) +###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration.md) +###### [Configure Splunk to pull alerts](microsoft-defender-atp/configure-splunk.md) +###### [Configure HP ArcSight to pull alerts](microsoft-defender-atp/configure-arcsight.md) +###### [Windows Defender ATP SIEM alert API fields](microsoft-defender-atp/api-portal-mapping.md) +###### [Pull alerts using SIEM REST API](microsoft-defender-atp/pull-alerts-using-rest-api.md) +###### [Troubleshoot SIEM tool integration issues](microsoft-defender-atp/troubleshoot-siem.md) ##### Reporting -###### [Create and build Power BI reports using Windows Defender ATP data](microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) -###### [Threat protection reports](microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md) -###### [Machine health and compliance reports](microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md) +###### [Create and build Power BI reports using Windows Defender ATP data](microsoft-defender-atp/powerbi-reports.md) +###### [Threat protection reports](microsoft-defender-atp/threat-protection-reports.md) +###### [Machine health and compliance reports](microsoft-defender-atp/machine-reports.md) ##### Role-based access control -###### [Manage portal access using RBAC](microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md) -####### [Create and manage roles](microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine groups](microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) -######## [Create and manage machine tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) +###### [Manage portal access using RBAC](microsoft-defender-atp/rbac.md) +####### [Create and manage roles](microsoft-defender-atp/user-roles.md) +####### [Create and manage machine groups](microsoft-defender-atp/machine-groups.md) +######## [Create and manage machine tags](microsoft-defender-atp/machine-tags.md) -##### [Configure managed security service provider (MSSP) support](microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md) +##### [Configure managed security service provider (MSSP) support](microsoft-defender-atp/configure-mssp-support.md) #### [Configure and manage Microsoft Threat Experts capabilities](microsoft-defender-atp/configure-microsoft-threat-experts.md) @@ -360,56 +360,56 @@ #### Configure Microsoft threat protection integration -##### [Configure conditional access](microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md) +##### [Configure conditional access](microsoft-defender-atp/configure-conditional-access.md) ##### [Configure Microsoft Cloud App Security integration](microsoft-defender-atp/microsoft-cloud-app-security-config.md) ##### [Configure information protection in Windows](microsoft-defender-atp/information-protection-in-windows-config.md) -#### [Configure Windows Defender Security Center settings](microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md) +#### [Configure Windows Defender Security Center settings](microsoft-defender-atp/preferences-setup.md) ##### General -###### [Update data retention settings](microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md) -###### [Configure alert notifications](microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md) -###### [Enable and create Power BI reports using Windows Defender Security center data](microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) -###### [Enable Secure score security controls](microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md) -###### [Configure advanced features](microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md) +###### [Update data retention settings](microsoft-defender-atp/data-retention-settings.md) +###### [Configure alert notifications](microsoft-defender-atp/configure-email-notifications.md) +###### [Enable and create Power BI reports using Windows Defender Security center data](microsoft-defender-atp/powerbi-reports.md) +###### [Enable Secure score security controls](microsoft-defender-atp/enable-secure-score.md) +###### [Configure advanced features](microsoft-defender-atp/advanced-features.md) ##### Permissions -###### [Use basic permissions to access the portal](microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md) -###### [Manage portal access using RBAC](microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md) -####### [Create and manage roles](microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine groups](microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md) -######## [Create and manage machine tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) +###### [Use basic permissions to access the portal](microsoft-defender-atp/basic-permissions.md) +###### [Manage portal access using RBAC](microsoft-defender-atp/rbac.md) +####### [Create and manage roles](microsoft-defender-atp/user-roles.md) +####### [Create and manage machine groups](microsoft-defender-atp/machine-groups.md) +######## [Create and manage machine tags](microsoft-defender-atp/machine-tags.md) ##### APIs -###### [Enable Threat intel](microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md) +###### [Enable Threat intel](microsoft-defender-atp/enable-custom-ti.md) +###### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration.md) #####Rules -###### [Manage suppression rules](microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md) -###### [Manage automation allowed/blocked lists](microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -###### [Manage allowed/blocked lists](microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -###### [Manage automation file uploads](microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) -###### [Manage automation folder exclusions](microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) +###### [Manage suppression rules](microsoft-defender-atp/manage-suppression-rules.md) +###### [Manage automation allowed/blocked lists](microsoft-defender-atp/manage-automation-allowed-blocked-list.md) +###### [Manage allowed/blocked lists](microsoft-defender-atp/manage-allowed-blocked-list.md) +###### [Manage automation file uploads](microsoft-defender-atp/manage-automation-file-uploads.md) +###### [Manage automation folder exclusions](microsoft-defender-atp/manage-automation-folder-exclusions.md) #####Machine management -###### [Onboarding machines](microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) -###### [Offboarding machines](microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md) +###### [Onboarding machines](microsoft-defender-atp/onboard-configure.md) +###### [Offboarding machines](microsoft-defender-atp/offboard-machines.md) -##### [Configure Windows Defender Security Center time zone settings](microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md) +##### [Configure Windows Defender Security Center time zone settings](microsoft-defender-atp/time-settings.md) ### [Troubleshoot Windows Defender ATP](microsoft-defender-atp/troubleshoot-wdatp.md) ####Troubleshoot sensor state -##### [Check sensor state](microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md) -##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) -##### [Inactive machines](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) -##### [Misconfigured machines](microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) -##### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md) +##### [Check sensor state](microsoft-defender-atp/check-sensor-status.md) +##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealhty-sensors.md) +##### [Inactive machines](microsoft-defender-atp/fix-unhealhty-sensors.md#inactive-machines) +##### [Misconfigured machines](microsoft-defender-atp/fix-unhealhty-sensors.md#misconfigured-machines) +##### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes.md) -#### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md) -##### [Check service health](microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md) +#### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot.md) +##### [Check service health](microsoft-defender-atp/service-status.md) ####Troubleshoot attack surface reduction ##### [Network protection](windows-defender-exploit-guard/troubleshoot-np.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md From 552ea6dcb0d88a6b5aa31108077af251ca1c708e Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 14:34:39 -0700 Subject: [PATCH 128/737] remove -wdatp, update all file names --- windows/security/threat-protection/TOC.md | 210 +++++++++--------- ...n-new.md => add-or-remove-machine-tags.md} | 0 ...eat-protection.md => advanced-features.md} | 0 ....md => advanced-hunting-best-practices.md} | 0 ...ction.md => advanced-hunting-reference.md} | 0 ...reat-protection.md => advanced-hunting.md} | 0 ...d-threat-protection.md => alerts-queue.md} | 0 ...ced-threat-protection-new.md => alerts.md} | 0 ...at-protection.md => api-portal-mapping.md} | 0 ...-protection.md => assign-portal-access.md} | 0 ...at-protection.md => attack-simulations.md} | 0 ...tection.md => automated-investigations.md} | 0 ...eat-protection.md => basic-permissions.md} | 0 ...t-protection.md => check-sensor-status.md} | 0 ...ew.md => collect-investigation-package.md} | 0 ...nced-threat-protection.md => community.md} | 0 ...ed-threat-protection.md => conditional.md} | 0 ...at-protection.md => configure-arcsight.md} | 0 ...ion.md => configure-conditional-access.md} | 0 ...on.md => configure-email-notifications.md} | 0 ...rotection.md => configure-endpoints-gp.md} | 0 ...otection.md => configure-endpoints-mdm.md} | 0 ....md => configure-endpoints-non-windows.md} | 0 ...tection.md => configure-endpoints-sccm.md} | 0 ...ction.md => configure-endpoints-script.md} | 0 ...otection.md => configure-endpoints-vdi.md} | 0 ...t-protection.md => configure-endpoints.md} | 0 ...rotection.md => configure-mssp-support.md} | 0 ...tection.md => configure-proxy-internet.md} | 0 ...ction.md => configure-server-endpoints.md} | 0 ...threat-protection.md => configure-siem.md} | 0 ...reat-protection.md => configure-splunk.md} | 0 ...on-new.md => create-alert-by-reference.md} | 0 ...-threat-protection.md => custom-ti-api.md} | 0 ...otection.md => data-retention-settings.md} | 0 ...-protection.md => data-storage-privacy.md} | 0 ...rotection.md => defender-compatibility.md} | 0 ...on-new.md => delete-ti-indicator-by-id.md} | 0 ...reat-protection.md => enable-custom-ti.md} | 0 ...t-protection.md => enable-secure-score.md} | 0 ...otection.md => enable-siem-integration.md} | 0 ...eat-protection.md => event-error-codes.md} | 0 ...-protection.md => experiment-custom-ti.md} | 0 ...nced-threat-protection-new.md => files.md} | 0 ...tion-new.md => find-machine-info-by-ip.md} | 0 ...otection-new.md => find-machines-by-ip.md} | 0 ...protection.md => fix-unhealhty-sensors.md} | 0 ...tection-new.md => get-alert-info-by-id.md} | 0 ...ew.md => get-alert-related-domain-info.md} | 0 ...new.md => get-alert-related-files-info.md} | 0 ...on-new.md => get-alert-related-ip-info.md} | 0 ...w.md => get-alert-related-machine-info.md} | 0 ...-new.md => get-alert-related-user-info.md} | 0 ...threat-protection-new.md => get-alerts.md} | 0 ...otection.md => get-cvekbmap-collection.md} | 0 ...on-new.md => get-domain-related-alerts.md} | 0 ...-new.md => get-domain-related-machines.md} | 0 ...ection-new.md => get-domain-statistics.md} | 0 ...tection-new.md => get-file-information.md} | 0 ...tion-new.md => get-file-related-alerts.md} | 0 ...on-new.md => get-file-related-machines.md} | 0 ...otection-new.md => get-file-statistics.md} | 0 ...ection-new.md => get-ip-related-alerts.md} | 0 ...tion-new.md => get-ip-related-machines.md} | 0 ...protection-new.md => get-ip-statistics.md} | 0 ...protection.md => get-kbinfo-collection.md} | 0 ...protection-new.md => get-machine-by-id.md} | 0 ...ion-new.md => get-machine-log-on-users.md} | 0 ...n-new.md => get-machine-related-alerts.md} | 0 ...ion-new.md => get-machineaction-object.md} | 0 ...ew.md => get-machineactions-collection.md} | 0 ...ion.md => get-machinegroups-collection.md} | 0 ...reat-protection-new.md => get-machines.md} | 0 ...> get-machinesecuritystates-collection.md} | 0 ...otection-new.md => get-package-sas-uri.md} | 0 ...new.md => get-ti-indicators-collection.md} | 0 ...tection-new.md => get-user-information.md} | 0 ...tion-new.md => get-user-related-alerts.md} | 0 ...on-new.md => get-user-related-machines.md} | 0 ...ew.md => initiate-autoir-investigation.md} | 0 ...at-protection.md => investigate-alerts.md} | 0 ...at-protection.md => investigate-domain.md} | 0 ...eat-protection.md => investigate-files.md} | 0 ...protection.md => investigate-incidents.md} | 0 ...threat-protection.md => investigate-ip.md} | 0 ...-protection.md => investigate-machines.md} | 0 ...reat-protection.md => investigate-user.md} | 0 ...ection-new.md => is-domain-seen-in-org.md} | 0 ...at-protection-new.md => is-ip-seen-org.md} | 0 ...t-protection-new.md => isolate-machine.md} | 0 ...nced-threat-protection.md => licensing.md} | 0 ...threat-protection.md => machine-groups.md} | 0 ...hreat-protection.md => machine-reports.md} | 0 ...d-threat-protection.md => machine-tags.md} | 0 ...ed-threat-protection-new.md => machine.md} | 0 ...eat-protection-new.md => machineaction.md} | 0 ...rotection.md => machines-view-overview.md} | 0 ...-threat-protection.md => manage-alerts.md} | 0 ...tion.md => manage-allowed-blocked-list.md} | 0 ...ection.md => manage-auto-investigation.md} | 0 ...manage-automation-allowed-blocked-list.md} | 0 ...n.md => manage-automation-file-uploads.md} | 0 ...=> manage-automation-folder-exclusions.md} | 0 ...reat-protection.md => manage-incidents.md} | 0 ...tection.md => manage-suppression-rules.md} | 0 ...-protection.md => minimum-requirements.md} | 0 ...d-threat-protection.md => mssp-support.md} | 0 ...tection-new.md => offboard-machine-api.md} | 0 ...eat-protection.md => offboard-machines.md} | 0 ...eat-protection.md => onboard-configure.md} | 0 ...eat-protection.md => onboard-downlevel.md} | 0 ...reat-protection.md => overview-hunting.md} | 0 ...protection.md => overview-secure-score.md} | 0 ...hreat-protection.md => portal-overview.md} | 0 ...protection-new.md => post-ti-indicator.md} | 0 ...hreat-protection.md => powerbi-reports.md} | 0 ...otection.md => powershell-example-code.md} | 0 ...eat-protection.md => preferences-setup.md} | 0 ...reat-protection.md => preview-settings.md} | 0 ...vanced-threat-protection.md => preview.md} | 0 ...ction.md => pull-alerts-using-rest-api.md} | 0 ...t-protection.md => python-example-code.md} | 0 ...-advanced-threat-protection.md => rbac.md} | 0 ...t-protection.md => respond-file-alerts.md} | 0 ...rotection.md => respond-machine-alerts.md} | 0 ...reat-protection.md => response-actions.md} | 0 ...tion-new.md => restrict-code-execution.md} | 0 ...hreat-protection-new.md => run-av-scan.md} | 0 ...at-protection.md => run-detection-test.md} | 0 ...rotection.md => secure-score-dashboard.md} | 0 ...on.md => security-operations-dashboard.md} | 0 ...threat-protection.md => service-status.md} | 0 ...ion-new.md => stop-and-quarantine-file.md} | 0 ...otection.md => supported-response-apis.md} | 0 ...ection.md => threat-indicator-concepts.md} | 0 ...ection.md => threat-protection-reports.md} | 0 ...reat-protection-new.md => ti-indicator.md} | 0 ...-threat-protection.md => time-settings.md} | 0 ...rotection.md => troubleshoot-custom-ti.md} | 0 ...troubleshoot-onboarding-error-messages.md} | 0 ...otection.md => troubleshoot-onboarding.md} | 0 ...hoot-wdatp.md => troubleshoot-overview.md} | 0 ...eat-protection.md => troubleshoot-siem.md} | 0 ...d-threat-protection.md => troubleshoot.md} | 0 ...protection-new.md => unisolate-machine.md} | 0 ...on-new.md => unrestrict-code-execution.md} | 0 ...reat-protection-new.md => update-alert.md} | 0 ...-threat-protection.md => use-custom-ti.md} | 0 ...r-advanced-threat-protection.md => use.md} | 0 ...ced-threat-protection.md => user-roles.md} | 0 ...anced-threat-protection-new.md => user.md} | 0 ...=> whats-new-in-microsoft-defender-atp.md} | 0 152 files changed, 105 insertions(+), 105 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md => add-or-remove-machine-tags.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{advanced-features-windows-defender-advanced-threat-protection.md => advanced-features.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md => advanced-hunting-best-practices.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{advanced-hunting-reference-windows-defender-advanced-threat-protection.md => advanced-hunting-reference.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{advanced-hunting-windows-defender-advanced-threat-protection.md => advanced-hunting.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{alerts-queue-windows-defender-advanced-threat-protection.md => alerts-queue.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{alerts-windows-defender-advanced-threat-protection-new.md => alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{api-portal-mapping-windows-defender-advanced-threat-protection.md => api-portal-mapping.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{assign-portal-access-windows-defender-advanced-threat-protection.md => assign-portal-access.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{attack-simulations-windows-defender-advanced-threat-protection.md => attack-simulations.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{automated-investigations-windows-defender-advanced-threat-protection.md => automated-investigations.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{basic-permissions-windows-defender-advanced-threat-protection.md => basic-permissions.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{check-sensor-status-windows-defender-advanced-threat-protection.md => check-sensor-status.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{collect-investigation-package-windows-defender-advanced-threat-protection-new.md => collect-investigation-package.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{community-windows-defender-advanced-threat-protection.md => community.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{conditional-access-windows-defender-advanced-threat-protection.md => conditional.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-arcsight-windows-defender-advanced-threat-protection.md => configure-arcsight.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-conditional-access-windows-defender-advanced-threat-protection.md => configure-conditional-access.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-email-notifications-windows-defender-advanced-threat-protection.md => configure-email-notifications.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-gp-windows-defender-advanced-threat-protection.md => configure-endpoints-gp.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-mdm-windows-defender-advanced-threat-protection.md => configure-endpoints-mdm.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md => configure-endpoints-non-windows.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-sccm-windows-defender-advanced-threat-protection.md => configure-endpoints-sccm.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-script-windows-defender-advanced-threat-protection.md => configure-endpoints-script.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-vdi-windows-defender-advanced-threat-protection.md => configure-endpoints-vdi.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-endpoints-windows-defender-advanced-threat-protection.md => configure-endpoints.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-mssp-support-windows-defender-advanced-threat-protection.md => configure-mssp-support.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-proxy-internet-windows-defender-advanced-threat-protection.md => configure-proxy-internet.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-server-endpoints-windows-defender-advanced-threat-protection.md => configure-server-endpoints.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-siem-windows-defender-advanced-threat-protection.md => configure-siem.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{configure-splunk-windows-defender-advanced-threat-protection.md => configure-splunk.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{create-alert-by-reference-windows-defender-advanced-threat-protection-new.md => create-alert-by-reference.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{custom-ti-api-windows-defender-advanced-threat-protection.md => custom-ti-api.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{data-retention-settings-windows-defender-advanced-threat-protection.md => data-retention-settings.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{data-storage-privacy-windows-defender-advanced-threat-protection.md => data-storage-privacy.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{defender-compatibility-windows-defender-advanced-threat-protection.md => defender-compatibility.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md => delete-ti-indicator-by-id.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{enable-custom-ti-windows-defender-advanced-threat-protection.md => enable-custom-ti.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{enable-secure-score-windows-defender-advanced-threat-protection.md => enable-secure-score.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{enable-siem-integration-windows-defender-advanced-threat-protection.md => enable-siem-integration.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{event-error-codes-windows-defender-advanced-threat-protection.md => event-error-codes.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{experiment-custom-ti-windows-defender-advanced-threat-protection.md => experiment-custom-ti.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{files-windows-defender-advanced-threat-protection-new.md => files.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md => find-machine-info-by-ip.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{find-machines-by-ip-windows-defender-advanced-threat-protection-new.md => find-machines-by-ip.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md => fix-unhealhty-sensors.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md => get-alert-info-by-id.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md => get-alert-related-domain-info.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md => get-alert-related-files-info.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md => get-alert-related-ip-info.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md => get-alert-related-machine-info.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md => get-alert-related-user-info.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-alerts-windows-defender-advanced-threat-protection-new.md => get-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-cvekbmap-collection-windows-defender-advanced-threat-protection.md => get-cvekbmap-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md => get-domain-related-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-domain-related-machines-windows-defender-advanced-threat-protection-new.md => get-domain-related-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-domain-statistics-windows-defender-advanced-threat-protection-new.md => get-domain-statistics.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-file-information-windows-defender-advanced-threat-protection-new.md => get-file-information.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-file-related-alerts-windows-defender-advanced-threat-protection-new.md => get-file-related-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-file-related-machines-windows-defender-advanced-threat-protection-new.md => get-file-related-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-file-statistics-windows-defender-advanced-threat-protection-new.md => get-file-statistics.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md => get-ip-related-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-ip-related-machines-windows-defender-advanced-threat-protection-new.md => get-ip-related-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-ip-statistics-windows-defender-advanced-threat-protection-new.md => get-ip-statistics.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-kbinfo-collection-windows-defender-advanced-threat-protection.md => get-kbinfo-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machine-by-id-windows-defender-advanced-threat-protection-new.md => get-machine-by-id.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md => get-machine-log-on-users.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md => get-machine-related-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machineaction-object-windows-defender-advanced-threat-protection-new.md => get-machineaction-object.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machineactions-collection-windows-defender-advanced-threat-protection-new.md => get-machineactions-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machinegroups-collection-windows-defender-advanced-threat-protection.md => get-machinegroups-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machines-windows-defender-advanced-threat-protection-new.md => get-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md => get-machinesecuritystates-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-package-sas-uri-windows-defender-advanced-threat-protection-new.md => get-package-sas-uri.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md => get-ti-indicators-collection.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-user-information-windows-defender-advanced-threat-protection-new.md => get-user-information.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-user-related-alerts-windows-defender-advanced-threat-protection-new.md => get-user-related-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{get-user-related-machines-windows-defender-advanced-threat-protection-new.md => get-user-related-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md => initiate-autoir-investigation.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-alerts-windows-defender-advanced-threat-protection.md => investigate-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-domain-windows-defender-advanced-threat-protection.md => investigate-domain.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-files-windows-defender-advanced-threat-protection.md => investigate-files.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-incidents-windows-defender-advanced-threat-protection.md => investigate-incidents.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-ip-windows-defender-advanced-threat-protection.md => investigate-ip.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-machines-windows-defender-advanced-threat-protection.md => investigate-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{investigate-user-windows-defender-advanced-threat-protection.md => investigate-user.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md => is-domain-seen-in-org.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{is-ip-seen-org-windows-defender-advanced-threat-protection-new.md => is-ip-seen-org.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{isolate-machine-windows-defender-advanced-threat-protection-new.md => isolate-machine.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{licensing-windows-defender-advanced-threat-protection.md => licensing.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machine-groups-windows-defender-advanced-threat-protection.md => machine-groups.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machine-reports-windows-defender-advanced-threat-protection.md => machine-reports.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machine-tags-windows-defender-advanced-threat-protection.md => machine-tags.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machine-windows-defender-advanced-threat-protection-new.md => machine.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machineaction-windows-defender-advanced-threat-protection-new.md => machineaction.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{machines-view-overview-windows-defender-advanced-threat-protection.md => machines-view-overview.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-alerts-windows-defender-advanced-threat-protection.md => manage-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md => manage-allowed-blocked-list.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-auto-investigation-windows-defender-advanced-threat-protection.md => manage-auto-investigation.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md => manage-automation-allowed-blocked-list.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-automation-file-uploads-windows-defender-advanced-threat-protection.md => manage-automation-file-uploads.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md => manage-automation-folder-exclusions.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-incidents-windows-defender-advanced-threat-protection.md => manage-incidents.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{manage-suppression-rules-windows-defender-advanced-threat-protection.md => manage-suppression-rules.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{minimum-requirements-windows-defender-advanced-threat-protection.md => minimum-requirements.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{mssp-support-windows-defender-advanced-threat-protection.md => mssp-support.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{offboard-machine-api-windows-defender-advanced-threat-protection-new.md => offboard-machine-api.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{offboard-machines-windows-defender-advanced-threat-protection.md => offboard-machines.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{onboard-configure-windows-defender-advanced-threat-protection.md => onboard-configure.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{onboard-downlevel-windows-defender-advanced-threat-protection.md => onboard-downlevel.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{overview-hunting-windows-defender-advanced-threat-protection.md => overview-hunting.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{overview-secure-score-windows-defender-advanced-threat-protection.md => overview-secure-score.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{portal-overview-windows-defender-advanced-threat-protection.md => portal-overview.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{post-ti-indicator-windows-defender-advanced-threat-protection-new.md => post-ti-indicator.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{powerbi-reports-windows-defender-advanced-threat-protection.md => powerbi-reports.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{powershell-example-code-windows-defender-advanced-threat-protection.md => powershell-example-code.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{preferences-setup-windows-defender-advanced-threat-protection.md => preferences-setup.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{preview-settings-windows-defender-advanced-threat-protection.md => preview-settings.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{preview-windows-defender-advanced-threat-protection.md => preview.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md => pull-alerts-using-rest-api.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{python-example-code-windows-defender-advanced-threat-protection.md => python-example-code.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{rbac-windows-defender-advanced-threat-protection.md => rbac.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{respond-file-alerts-windows-defender-advanced-threat-protection.md => respond-file-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{respond-machine-alerts-windows-defender-advanced-threat-protection.md => respond-machine-alerts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{response-actions-windows-defender-advanced-threat-protection.md => response-actions.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{restrict-code-execution-windows-defender-advanced-threat-protection-new.md => restrict-code-execution.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{run-av-scan-windows-defender-advanced-threat-protection-new.md => run-av-scan.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{run-detection-test-windows-defender-advanced-threat-protection.md => run-detection-test.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{secure-score-dashboard-windows-defender-advanced-threat-protection.md => secure-score-dashboard.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{security-operations-dashboard-windows-defender-advanced-threat-protection.md => security-operations-dashboard.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{service-status-windows-defender-advanced-threat-protection.md => service-status.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md => stop-and-quarantine-file.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{supported-response-apis-windows-defender-advanced-threat-protection.md => supported-response-apis.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{threat-indicator-concepts-windows-defender-advanced-threat-protection.md => threat-indicator-concepts.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{threat-protection-reports-windows-defender-advanced-threat-protection.md => threat-protection-reports.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{ti-indicator-windows-defender-advanced-threat-protection-new.md => ti-indicator.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{time-settings-windows-defender-advanced-threat-protection.md => time-settings.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md => troubleshoot-custom-ti.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md => troubleshoot-onboarding-error-messages.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-onboarding-windows-defender-advanced-threat-protection.md => troubleshoot-onboarding.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-wdatp.md => troubleshoot-overview.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-siem-windows-defender-advanced-threat-protection.md => troubleshoot-siem.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot-windows-defender-advanced-threat-protection.md => troubleshoot.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{unisolate-machine-windows-defender-advanced-threat-protection-new.md => unisolate-machine.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md => unrestrict-code-execution.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{update-alert-windows-defender-advanced-threat-protection-new.md => update-alert.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{use-custom-ti-windows-defender-advanced-threat-protection.md => use-custom-ti.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{use-windows-defender-advanced-threat-protection.md => use.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{user-roles-windows-defender-advanced-threat-protection.md => user-roles.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{user-windows-defender-advanced-threat-protection-new.md => user.md} (100%) rename windows/security/threat-protection/microsoft-defender-atp/{whats-new-in-windows-defender-atp.md => whats-new-in-microsoft-defender-atp.md} (100%) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 316afb72b1..caca71920d 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -16,81 +16,81 @@ ##### [Network firewall](windows-firewall/windows-firewall-with-advanced-security.md) #### [Next generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) #### [Endpoint detection and response](microsoft-defender-atp/overview-endpoint-detection-response.md) -##### [Security operations dashboard](microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md) +##### [Security operations dashboard](microsoft-defender-atp/security-operations-dashboard.md) ##### [Incidents queue](microsoft-defender-atp/incidents-queue.md) ###### [View and organize the Incidents queue](microsoft-defender-atp/view-incidents-queue.md) -###### [Manage incidents](microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md) -###### [Investigate incidents](microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md) +###### [Manage incidents](microsoft-defender-atp/manage-incidents.md) +###### [Investigate incidents](microsoft-defender-atp/investigate-incidents.md) ##### Alerts queue -###### [View and organize the Alerts queue](microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md) -###### [Manage alerts](microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md) -###### [Investigate alerts](microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md) -###### [Investigate files](microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md) -###### [Investigate machines](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md) -###### [Investigate an IP address](microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md) -###### [Investigate a domain](microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md) -###### [Investigate a user account](microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md) +###### [View and organize the Alerts queue](microsoft-defender-atp/alerts-queue.md) +###### [Manage alerts](microsoft-defender-atp/manage-alerts.md) +###### [Investigate alerts](microsoft-defender-atp/investigate-alerts.md) +###### [Investigate files](microsoft-defender-atp/investigate-files.md) +###### [Investigate machines](microsoft-defender-atp/investigate-machines.md) +###### [Investigate an IP address](microsoft-defender-atp/investigate-ip.md) +###### [Investigate a domain](microsoft-defender-atp/investigate-domain.md) +###### [Investigate a user account](microsoft-defender-atp/investigate-user.md) ##### Machines list -###### [View and organize the Machines list](microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md) -###### [Manage machine group and tags](microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md) -###### [Alerts related to this machine](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine) -###### [Machine timeline](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline) -####### [Search for specific events](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events) -####### [Filter events from a specific date](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) -####### [Export machine timeline events](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) -####### [Navigate between pages](microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) +###### [View and organize the Machines list](microsoft-defender-atp/machines-view-overview.md) +###### [Manage machine group and tags](microsoft-defender-atp/machine-tags.md) +###### [Alerts related to this machine](microsoft-defender-atp/investigate-machines.md#alerts-related-to-this-machine) +###### [Machine timeline](microsoft-defender-atp/investigate-machines.md#machine-timeline) +####### [Search for specific events](microsoft-defender-atp/investigate-machines.md#search-for-specific-events) +####### [Filter events from a specific date](microsoft-defender-atp/investigate-machines.md#filter-events-from-a-specific-date) +####### [Export machine timeline events](microsoft-defender-atp/investigate-machines.md#export-machine-timeline-events) +####### [Navigate between pages](microsoft-defender-atp/investigate-machines.md#navigate-between-pages) -##### [Take response actions](microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md) -###### [Take response actions on a machine](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md) -####### [Collect investigation package](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines) -####### [Run antivirus scan](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines) -####### [Restrict app execution](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution) -####### [Remove app restriction](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction) -####### [Isolate machines from the network](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) -####### [Release machine from isolation](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation) -####### [Check activity details in Action center](microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +##### [Take response actions](microsoft-defender-atp/response-actions.md) +###### [Take response actions on a machine](microsoft-defender-atp/respond-machine-alerts.md) +####### [Collect investigation package](microsoft-defender-atp/respond-machine-alerts.md#collect-investigation-package-from-machines) +####### [Run antivirus scan](microsoft-defender-atp/respond-machine-alerts.md#run-windows-defender-antivirus-scan-on-machines) +####### [Restrict app execution](microsoft-defender-atp/respond-machine-alerts.md#restrict-app-execution) +####### [Remove app restriction](microsoft-defender-atp/respond-machine-alerts.md#remove-app-restriction) +####### [Isolate machines from the network](microsoft-defender-atp/respond-machine-alerts.md#isolate-machines-from-the-network) +####### [Release machine from isolation](microsoft-defender-atp/respond-machine-alerts.md#release-machine-from-isolation) +####### [Check activity details in Action center](microsoft-defender-atp/respond-machine-alerts.md#check-activity-details-in-action-center) -###### [Take response actions on a file](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md) -####### [Stop and quarantine files in your network](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) -####### [Remove file from quarantine](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) -####### [Block files in your network](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) -####### [Remove file from blocked list](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list) -####### [Check activity details in Action center](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) -####### [Deep analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) -####### [Submit files for analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) -####### [View deep analysis reports](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) -####### [Troubleshoot deep analysis](microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) +###### [Take response actions on a file](microsoft-defender-atp/respond-file-alerts.md) +####### [Stop and quarantine files in your network](microsoft-defender-atp/respond-file-alerts.md#stop-and-quarantine-files-in-your-network) +####### [Remove file from quarantine](microsoft-defender-atp/respond-file-alerts.md#remove-file-from-quarantine) +####### [Block files in your network](microsoft-defender-atp/respond-file-alerts.md#block-files-in-your-network) +####### [Remove file from blocked list](microsoft-defender-atp/respond-file-alerts.md#remove-file-from-blocked-list) +####### [Check activity details in Action center](microsoft-defender-atp/respond-file-alerts.md#check-activity-details-in-action-center) +####### [Deep analysis](microsoft-defender-atp/respond-file-alerts.md#deep-analysis) +####### [Submit files for analysis](microsoft-defender-atp/respond-file-alerts.md#submit-files-for-analysis) +####### [View deep analysis reports](microsoft-defender-atp/respond-file-alerts.md#view-deep-analysis-reports) +####### [Troubleshoot deep analysis](microsoft-defender-atp/respond-file-alerts.md#troubleshoot-deep-analysis) -#### [Automated investigation and remediation](microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md) -##### [Learn about the automated investigation and remediation dashboard](microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md) +#### [Automated investigation and remediation](microsoft-defender-atp/automated-investigations.md) +##### [Learn about the automated investigation and remediation dashboard](microsoft-defender-atp/manage-auto-investigation.md) -#### [Secure score](microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md) +#### [Secure score](microsoft-defender-atp/overview-secure-score.md) #### [Threat analytics](microsoft-defender-atp/threat-analytics.md) -#### [Advanced hunting](microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md) -##### [Query data using Advanced hunting](microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md) -###### [Advanced hunting reference](microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md) -###### [Advanced hunting query language best practices](microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) +#### [Advanced hunting](microsoft-defender-atp/overview-hunting.md) +##### [Query data using Advanced hunting](microsoft-defender-atp/advanced-hunting.md) +###### [Advanced hunting reference](microsoft-defender-atp/advanced-hunting-reference.md) +###### [Advanced hunting query language best practices](microsoft-defender-atp/advanced-hunting-best-practices.md) ##### [Custom detections](microsoft-defender-atp/overview-custom-detections.md) ###### [Create custom detections rules](microsoft-defender-atp/custom-detection-rules.md) #### [Management and APIs](microsoft-defender-atp/management-apis.md) -##### [Understand threat intelligence concepts](microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md) +##### [Understand threat intelligence concepts](microsoft-defender-atp/threat-indicator-concepts.md) ##### [Windows Defender ATP APIs](microsoft-defender-atp/apis-intro.md) -##### [Managed security service provider support](microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md) +##### [Managed security service provider support](microsoft-defender-atp/mssp-support.md) #### [Microsoft threat protection](microsoft-defender-atp/threat-protection-integration.md) -##### [Protect users, data, and devices with conditional access](microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md) +##### [Protect users, data, and devices with conditional access](microsoft-defender-atp/conditional-access.md) ##### [Microsoft Cloud App Security integration overview](microsoft-defender-atp/microsoft-cloud-app-security-integration.md) ##### [Information protection in Windows overview](microsoft-defender-atp/information-protection-in-windows-overview.md) @@ -100,16 +100,16 @@ -#### [Portal overview](microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md) +#### [Portal overview](microsoft-defender-atp/portal-overview.md) ### [Get started](microsoft-defender-atp/get-started.md) -#### [What's new in Windows Defender ATP](microsoft-defender-atp/whats-new-in-windows-defender-atp.md) -#### [Minimum requirements](microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md) -#### [Validate licensing and complete setup](microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md) -#### [Preview features](microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md) -#### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md) +#### [What's new in Windows Defender ATP](microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md) +#### [Minimum requirements](microsoft-defender-atp/minimum-requirements.md) +#### [Validate licensing and complete setup](microsoft-defender-atp/licensing.md) +#### [Preview features](microsoft-defender-atp/preview.md) +#### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy.md) #### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) #### [Evaluate Windows Defender ATP](microsoft-defender-atp/evaluate-atp.md) @@ -243,65 +243,65 @@ ####### [Advanced Hunting](microsoft-defender-atp/run-advanced-query-api.md) -####### [Alert](microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md) -######## [List alerts](microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Create alert](microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md) -######## [Update Alert](microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md) -######## [Get alert information by ID](microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related domains information](microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related file information](microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related IPs information](microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related machine information](microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md) -######## [Get alert related user information](microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md) +####### [Alert](microsoft-defender-atp/alerts.md) +######## [List alerts](microsoft-defender-atp/get-alerts.md) +######## [Create alert](microsoft-defender-atp/create-alert-by-reference.md) +######## [Update Alert](microsoft-defender-atp/update-alert.md) +######## [Get alert information by ID](microsoft-defender-atp/get-alert-info-by-id.md) +######## [Get alert related domains information](microsoft-defender-atp/get-alert-related-domain-info.md) +######## [Get alert related file information](microsoft-defender-atp/get-alert-related-files-info.md) +######## [Get alert related IPs information](microsoft-defender-atp/get-alert-related-ip-info.md) +######## [Get alert related machine information](microsoft-defender-atp/get-alert-related-machine-info.md) +######## [Get alert related user information](microsoft-defender-atp/get-alert-related-user-info.md) -####### [Machine](microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md) -######## [List machines](microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get machine by ID](microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md) -######## [Get machine log on users](microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md) -######## [Get machine related alerts](microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Add or Remove machine tags](microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md) -######## [Find machines by IP](microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md) +####### [Machine](microsoft-defender-atp/machine.md) +######## [List machines](microsoft-defender-atp/get-machines.md) +######## [Get machine by ID](microsoft-defender-atp/get-machine-by-id.md) +######## [Get machine log on users](microsoft-defender-atp/get-machine-log-on-users.md) +######## [Get machine related alerts](microsoft-defender-atp/get-machine-related-alerts.md) +######## [Add or Remove machine tags](microsoft-defender-atp/add-or-remove-machine-tags.md) +######## [Find machines by IP](microsoft-defender-atp/find-machines-by-ip.md) -####### [Machine Action](microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md) -######## [List Machine Actions](microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) -######## [Get Machine Action](microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md) -######## [Collect investigation package](microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md) -######## [Get investigation package SAS URI](microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md) -######## [Isolate machine](microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md) -######## [Release machine from isolation](microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md) -######## [Restrict app execution](microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md) -######## [Remove app restriction](microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) -######## [Run antivirus scan](microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md) -######## [Offboard machine](microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md) -######## [Stop and quarantine file](microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md) -######## [Initiate investigation (preview)](microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md) +####### [Machine Action](microsoft-defender-atp/machineaction.md) +######## [List Machine Actions](microsoft-defender-atp/get-machineactions-collection.md) +######## [Get Machine Action](microsoft-defender-atp/get-machineaction-object.md) +######## [Collect investigation package](microsoft-defender-atp/collect-investigation-package.md) +######## [Get investigation package SAS URI](microsoft-defender-atp/get-package-sas-uri.md) +######## [Isolate machine](microsoft-defender-atp/isolate-machine.md) +######## [Release machine from isolation](microsoft-defender-atp/unisolate-machine.md) +######## [Restrict app execution](microsoft-defender-atp/restrict-code-execution.md) +######## [Remove app restriction](microsoft-defender-atp/unrestrict-code-execution.md) +######## [Run antivirus scan](microsoft-defender-atp/run-av-scan.md) +######## [Offboard machine](microsoft-defender-atp/offboard-machine-api.md) +######## [Stop and quarantine file](microsoft-defender-atp/stop-and-quarantine-file.md) +######## [Initiate investigation (preview)](microsoft-defender-atp/initiate-autoir-investigation.md) -####### [Indicators (preview)](microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md) -######## [Submit Indicator](microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md) -######## [List Indicators](microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md) -######## [Delete Indicator](microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md) +####### [Indicators (preview)](microsoft-defender-atp/ti-indicator.md) +######## [Submit Indicator](microsoft-defender-atp/post-ti-indicator.md) +######## [List Indicators](microsoft-defender-atp/get-ti-indicators-collection.md) +######## [Delete Indicator](microsoft-defender-atp/delete-ti-indicator-by-id.md) ####### Domain -######## [Get domain related alerts](microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get domain related machines](microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get domain statistics](microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md) -######## [Is domain seen in organization](microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md) +######## [Get domain related alerts](microsoft-defender-atp/get-domain-related-alerts.md) +######## [Get domain related machines](microsoft-defender-atp/get-domain-related-machines.md) +######## [Get domain statistics](microsoft-defender-atp/get-domain-statistics.md) +######## [Is domain seen in organization](microsoft-defender-atp/is-domain-seen-in-org.md) -####### [File](microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md) -######## [Get file information](microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md) -######## [Get file related alerts](microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get file related machines](microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get file statistics](microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md) +####### [File](microsoft-defender-atp/files.md) +######## [Get file information](microsoft-defender-atp/get-file-information.md) +######## [Get file related alerts](microsoft-defender-atp/get-file-related-alerts.md) +######## [Get file related machines](microsoft-defender-atp/get-file-related-machines.md) +######## [Get file statistics](microsoft-defender-atp/get-file-statistics.md) ####### IP -######## [Get IP related alerts](microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get IP related machines](microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md) -######## [Get IP statistics](microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md) -######## [Is IP seen in organization](microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md) +######## [Get IP related alerts](microsoft-defender-atp/get-ip-related-alerts.md) +######## [Get IP related machines](microsoft-defender-atp/get-ip-related-machines.md) +######## [Get IP statistics](microsoft-defender-atp/get-ip-statistics.md) +######## [Is IP seen in organization](microsoft-defender-atp/is-ip-seen-org.md) -####### [User](microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md) -######## [Get user related alerts](microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md) -######## [Get user related machines](microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md) +####### [User](microsoft-defender-atp/user.md) +######## [Get user related alerts](microsoft-defender-atp/get-user-related-alerts.md) +######## [Get user related machines](microsoft-defender-atp/get-user-related-machines.md) ###### How to use APIs - Samples @@ -400,7 +400,7 @@ ##### [Configure Windows Defender Security Center time zone settings](microsoft-defender-atp/time-settings.md) -### [Troubleshoot Windows Defender ATP](microsoft-defender-atp/troubleshoot-wdatp.md) +### [Troubleshoot Windows Defender ATP](microsoft-defender-atp/troubleshoot-overview.md) ####Troubleshoot sensor state ##### [Check sensor state](microsoft-defender-atp/check-sensor-status.md) ##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealhty-sensors.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-features.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/community.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/community-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/community.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/conditional.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/conditional.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-siem.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/files.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/files-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/files.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-information.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-information.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-files.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/investigate-user.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/licensing.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/licensing-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/licensing.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-groups.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-reports.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machine-tags.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/machine.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/machine.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/machineaction.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/machineaction.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/mssp-support.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/portal-overview.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preview-settings.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/preview.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/preview-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/preview.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/python-example-code.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/rbac.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/rbac-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/rbac.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/response-actions.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/response-actions-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/response-actions.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/service-status.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/service-status-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/service-status.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/time-settings.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/time-settings-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/time-settings.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-wdatp.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-wdatp.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/update-alert.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/use.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/use-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/use.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/user-roles-windows-defender-advanced-threat-protection.md rename to windows/security/threat-protection/microsoft-defender-atp/user-roles.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md b/windows/security/threat-protection/microsoft-defender-atp/user.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/user-windows-defender-advanced-threat-protection-new.md rename to windows/security/threat-protection/microsoft-defender-atp/user.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-windows-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/whats-new-in-windows-defender-atp.md rename to windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md From 91bf200c2bbe2825c97642fd156a8ee1e6c98f6f Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 14:50:43 -0700 Subject: [PATCH 129/737] remove all instances of wdatp within topics --- .../microsoft-defender-atp/TOC.md | 360 +++++++++--------- .../add-or-remove-machine-tags.md | 4 +- .../advanced-features.md | 28 +- .../advanced-hunting-best-practices.md | 12 +- .../advanced-hunting-reference.md | 12 +- .../advanced-hunting.md | 14 +- .../microsoft-defender-atp/alerts-queue.md | 30 +- .../microsoft-defender-atp/alerts.md | 4 +- .../microsoft-defender-atp/api-hello-world.md | 14 +- .../api-portal-mapping.md | 26 +- .../microsoft-defender-atp/apis-intro.md | 30 +- .../assign-portal-access.md | 12 +- .../attack-simulations.md | 18 +- .../automated-investigations.md | 6 +- .../basic-permissions.md | 6 +- .../check-sensor-status.md | 24 +- .../collect-investigation-package.md | 4 +- .../microsoft-defender-atp/community.md | 14 +- .../microsoft-defender-atp/conditional.md | 12 +- .../configure-arcsight.md | 24 +- .../configure-conditional-access.md | 20 +- .../configure-email-notifications.md | 22 +- .../configure-endpoints-gp.md | 18 +- .../configure-endpoints-mdm.md | 18 +- .../configure-endpoints-non-windows.md | 18 +- .../configure-endpoints-sccm.md | 22 +- .../configure-endpoints-script.md | 16 +- .../configure-endpoints-vdi.md | 14 +- .../configure-endpoints.md | 10 +- .../configure-microsoft-threat-experts.md | 14 +- .../configure-mssp-support.md | 16 +- .../configure-proxy-internet.md | 40 +- .../configure-server-endpoints.md | 58 +-- .../microsoft-defender-atp/configure-siem.md | 34 +- .../configure-splunk.md | 22 +- .../create-alert-by-reference.md | 4 +- .../custom-detection-rules.md | 4 +- .../microsoft-defender-atp/custom-ti-api.md | 14 +- .../data-retention-settings.md | 14 +- .../data-storage-privacy.md | 30 +- .../defender-compatibility.md | 18 +- .../delete-ti-indicator-by-id.md | 2 +- .../microsoft-defender-atp/deprecate.md | 2 +- .../enable-custom-ti.md | 10 +- .../enable-secure-score.md | 12 +- .../enable-siem-integration.md | 20 +- .../microsoft-defender-atp/evaluate-atp.md | 12 +- .../event-error-codes.md | 96 ++--- .../experiment-custom-ti.md | 20 +- .../exposed-apis-create-app-nativeapp.md | 30 +- .../exposed-apis-create-app-webapp.md | 34 +- .../exposed-apis-full-sample-powershell.md | 12 +- .../exposed-apis-list.md | 12 +- .../exposed-apis-odata-samples.md | 12 +- .../microsoft-defender-atp/files.md | 6 +- .../find-machine-info-by-ip.md | 4 +- .../find-machines-by-ip.md | 4 +- .../fix-unhealhty-sensors.md | 28 +- .../get-alert-info-by-id.md | 4 +- .../get-alert-related-domain-info.md | 4 +- .../get-alert-related-files-info.md | 4 +- .../get-alert-related-ip-info.md | 4 +- .../get-alert-related-machine-info.md | 4 +- .../get-alert-related-user-info.md | 4 +- .../microsoft-defender-atp/get-alerts.md | 8 +- .../get-cvekbmap-collection.md | 2 +- .../get-domain-related-alerts.md | 4 +- .../get-domain-related-machines.md | 4 +- .../get-domain-statistics.md | 4 +- .../get-file-information.md | 4 +- .../get-file-related-alerts.md | 4 +- .../get-file-related-machines.md | 4 +- .../get-file-statistics.md | 4 +- .../get-ip-related-alerts.md | 4 +- .../get-ip-related-machines.md | 4 +- .../get-ip-statistics.md | 4 +- .../get-kbinfo-collection.md | 2 +- .../get-machine-by-id.md | 4 +- .../get-machine-log-on-users.md | 4 +- .../get-machine-related-alerts.md | 4 +- .../get-machineaction-object.md | 4 +- .../get-machineactions-collection.md | 8 +- .../get-machinegroups-collection.md | 2 +- .../microsoft-defender-atp/get-machines.md | 8 +- .../get-machinesecuritystates-collection.md | 2 +- .../get-package-sas-uri.md | 4 +- .../microsoft-defender-atp/get-started.md | 32 +- .../get-ti-indicators-collection.md | 2 +- .../get-user-information.md | 4 +- .../get-user-related-alerts.md | 4 +- .../get-user-related-machines.md | 4 +- .../microsoft-defender-atp/incidents-queue.md | 10 +- ...nformation-protection-in-windows-config.md | 12 +- ...ormation-protection-in-windows-overview.md | 30 +- .../initiate-autoir-investigation.md | 4 +- .../investigate-alerts.md | 22 +- .../investigate-domain.md | 22 +- .../investigate-files.md | 22 +- .../investigate-incidents.md | 10 +- .../microsoft-defender-atp/investigate-ip.md | 20 +- .../investigate-machines.md | 28 +- .../investigate-user.md | 24 +- .../is-domain-seen-in-org.md | 4 +- .../microsoft-defender-atp/is-ip-seen-org.md | 4 +- .../microsoft-defender-atp/isolate-machine.md | 4 +- .../microsoft-defender-atp/licensing.md | 30 +- .../microsoft-defender-atp/machine-groups.md | 8 +- .../microsoft-defender-atp/machine-reports.md | 6 +- .../microsoft-defender-atp/machine.md | 10 +- .../microsoft-defender-atp/machineaction.md | 4 +- .../machineactionsnote.md | 2 +- .../machines-view-overview.md | 10 +- .../microsoft-defender-atp/manage-alerts.md | 26 +- .../manage-allowed-blocked-list.md | 4 +- .../manage-auto-investigation.md | 2 +- .../manage-automation-allowed-blocked-list.md | 4 +- .../manage-automation-file-uploads.md | 4 +- .../manage-automation-folder-exclusions.md | 4 +- .../manage-incidents.md | 6 +- .../manage-suppression-rules.md | 6 +- .../microsoft-defender-atp/management-apis.md | 24 +- .../microsoft-cloud-app-security-config.md | 10 +- ...icrosoft-cloud-app-security-integration.md | 12 +- ...oft-defender-advanced-threat-protection.md | 46 +-- .../microsoft-threat-experts.md | 4 +- .../minimum-requirements.md | 16 +- .../microsoft-defender-atp/mssp-support.md | 10 +- .../offboard-machine-api.md | 6 +- .../offboard-machines.md | 10 +- .../onboard-configure.md | 46 +-- .../onboard-downlevel.md | 28 +- .../microsoft-defender-atp/onboard.md | 12 +- .../overview-attack-surface-reduction.md | 6 +- .../overview-custom-detections.md | 4 +- .../overview-endpoint-detection-response.md | 8 +- .../overview-hardware-based-isolation.md | 4 +- .../overview-hunting.md | 2 +- .../overview-secure-score.md | 2 +- .../microsoft-defender-atp/overview.md | 20 +- .../microsoft-defender-atp/portal-overview.md | 22 +- .../post-ti-indicator.md | 2 +- .../microsoft-defender-atp/powerbi-reports.md | 50 +-- .../powershell-example-code.md | 6 +- .../preferences-setup.md | 4 +- .../preview-settings.md | 20 +- .../microsoft-defender-atp/preview.md | 18 +- .../pull-alerts-using-rest-api.md | 40 +- .../python-example-code.md | 6 +- .../microsoft-defender-atp/rbac.md | 14 +- .../respond-file-alerts.md | 16 +- .../respond-machine-alerts.md | 10 +- .../response-actions.md | 8 +- .../restrict-code-execution.md | 4 +- .../run-advanced-query-api.md | 12 +- .../run-advanced-query-sample-ms-flow.md | 4 +- ...dvanced-query-sample-power-bi-app-token.md | 2 +- ...vanced-query-sample-power-bi-user-token.md | 4 +- .../run-advanced-query-sample-powershell.md | 6 +- .../run-advanced-query-sample-python.md | 6 +- .../microsoft-defender-atp/run-av-scan.md | 4 +- .../run-detection-test.md | 11 +- .../secure-score-dashboard.md | 24 +- .../security-operations-dashboard.md | 22 +- .../microsoft-defender-atp/service-status.md | 12 +- .../stop-and-quarantine-file.md | 4 +- .../supported-response-apis.md | 10 +- .../threat-analytics.md | 6 +- .../threat-indicator-concepts.md | 16 +- .../threat-protection-integration.md | 16 +- .../threat-protection-reports.md | 8 +- .../microsoft-defender-atp/ti-indicator.md | 2 +- .../microsoft-defender-atp/time-settings.md | 22 +- .../troubleshoot-custom-ti.md | 10 +- .../troubleshoot-onboarding-error-messages.md | 18 +- .../troubleshoot-onboarding.md | 62 +-- .../troubleshoot-overview.md | 10 +- .../troubleshoot-siem.md | 18 +- .../microsoft-defender-atp/troubleshoot.md | 20 +- .../unisolate-machine.md | 4 +- .../unrestrict-code-execution.md | 4 +- .../microsoft-defender-atp/update-alert.md | 4 +- .../microsoft-defender-atp/use-apis.md | 12 +- .../microsoft-defender-atp/use-custom-ti.md | 6 +- .../microsoft-defender-atp/use.md | 8 +- .../microsoft-defender-atp/user-roles.md | 6 +- .../view-incidents-queue.md | 4 +- .../whats-new-in-microsoft-defender-atp.md | 44 +-- .../windows-defender-security-center-atp.md | 8 +- 188 files changed, 1409 insertions(+), 1410 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index e8ea7a0740..0dc76f0fa0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -1,4 +1,4 @@ -# [Windows Defender Advanced Threat Protection](windows-defender-advanced-threat-protection.md) +# [Microsoft Defender Advanced Threat Protection](microsoft-defender-advanced-threat-protection.md) ## [Overview](overview.md) ### [Attack surface reduction](overview-attack-surface-reduction.md) @@ -14,82 +14,82 @@ #### [Network firewall](../windows-firewall/windows-firewall-with-advanced-security.md) ### [Next generation protection](../windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) ### [Endpoint detection and response](overview-endpoint-detection-response.md) -#### [Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) +#### [Security operations dashboard](security-operations-dashboard.md) #### [Incidents queue](incidents-queue.md) ##### [View and organize the Incidents queue](view-incidents-queue.md) -##### [Manage incidents](manage-incidents-windows-defender-advanced-threat-protection.md) -##### [Investigate incidents](investigate-incidents-windows-defender-advanced-threat-protection.md) +##### [Manage incidents](manage-incidents.md) +##### [Investigate incidents](investigate-incidents.md) #### Alerts queue -##### [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md) -##### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -##### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -##### [Investigate files](investigate-files-windows-defender-advanced-threat-protection.md) -##### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md) -##### [Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md) -##### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md) -##### [Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md) +##### [View and organize the Alerts queue](alerts-queue.md) +##### [Manage alerts](manage-alerts.md) +##### [Investigate alerts](investigate-alerts.md) +##### [Investigate files](investigate-files.md) +##### [Investigate machines](investigate-machines.md) +##### [Investigate an IP address](investigate-ip.md) +##### [Investigate a domain](investigate-domain.md) +##### [Investigate a user account](investigate-user.md) #### Machines list -##### [View and organize the Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md) -##### [Manage machine group and tags](machine-tags-windows-defender-advanced-threat-protection.md) -##### [Alerts related to this machine](investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine) -##### [Machine timeline](investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline) -###### [Search for specific events](investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events) -###### [Filter events from a specific date](investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) -###### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) -###### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) +##### [View and organize the Machines list](machines-view-overview.md) +##### [Manage machine group and tags](machine-tags.md) +##### [Alerts related to this machine](investigate-machines.md#alerts-related-to-this-machine) +##### [Machine timeline](investigate-machines.md#machine-timeline) +###### [Search for specific events](investigate-machines.md#search-for-specific-events) +###### [Filter events from a specific date](investigate-machines.md#filter-events-from-a-specific-date) +###### [Export machine timeline events](investigate-machines.md#export-machine-timeline-events) +###### [Navigate between pages](investigate-machines.md#navigate-between-pages) -#### [Take response actions](response-actions-windows-defender-advanced-threat-protection.md) -##### [Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) -###### [Collect investigation package](respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines) -###### [Run antivirus scan](respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines) -###### [Restrict app execution](respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution) -###### [Remove app restriction](respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction) -###### [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) -###### [Release machine from isolation](respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation) -###### [Check activity details in Action center](respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +#### [Take response actions](response-actions.md) +##### [Take response actions on a machine](respond-machine-alerts.md) +###### [Collect investigation package](respond-machine-alerts.md#collect-investigation-package-from-machines) +###### [Run antivirus scan](respond-machine-alerts.md#run-windows-defender-antivirus-scan-on-machines) +###### [Restrict app execution](respond-machine-alerts.md#restrict-app-execution) +###### [Remove app restriction](respond-machine-alerts.md#remove-app-restriction) +###### [Isolate machines from the network](respond-machine-alerts.md#isolate-machines-from-the-network) +###### [Release machine from isolation](respond-machine-alerts.md#release-machine-from-isolation) +###### [Check activity details in Action center](respond-machine-alerts.md#check-activity-details-in-action-center) -##### [Take response actions on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md) -###### [Stop and quarantine files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) -###### [Remove file from quarantine](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) -###### [Block files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) -###### [Remove file from blocked list](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list) -###### [Check activity details in Action center](respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) -###### [Deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) -###### [Submit files for analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) -###### [View deep analysis reports](respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) -###### [Troubleshoot deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) +##### [Take response actions on a file](respond-file-alerts.md) +###### [Stop and quarantine files in your network](respond-file-alerts.md#stop-and-quarantine-files-in-your-network) +###### [Remove file from quarantine](respond-file-alerts.md#remove-file-from-quarantine) +###### [Block files in your network](respond-file-alerts.md#block-files-in-your-network) +###### [Remove file from blocked list](respond-file-alerts.md#remove-file-from-blocked-list) +###### [Check activity details in Action center](respond-file-alerts.md#check-activity-details-in-action-center) +###### [Deep analysis](respond-file-alerts.md#deep-analysis) +###### [Submit files for analysis](respond-file-alerts.md#submit-files-for-analysis) +###### [View deep analysis reports](respond-file-alerts.md#view-deep-analysis-reports) +###### [Troubleshoot deep analysis](respond-file-alerts.md#troubleshoot-deep-analysis) -### [Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md) -#### [Learn about the automated investigation and remediation dashboard](manage-auto-investigation-windows-defender-advanced-threat-protection.md) +### [Automated investigation and remediation](automated-investigations.md) +#### [Learn about the automated investigation and remediation dashboard](manage-auto-investigation.md) -### [Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) +### [Secure score](overview-secure-score.md) ### [Threat analytics](threat-analytics.md) -### [Advanced hunting](overview-hunting-windows-defender-advanced-threat-protection.md) -#### [Query data using Advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md) -##### [Advanced hunting reference](advanced-hunting-reference-windows-defender-advanced-threat-protection.md) -##### [Advanced hunting query language best practices](advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) +### [Advanced hunting](overview-hunting.md) +#### [Query data using Advanced hunting](advanced-hunting.md) +##### [Advanced hunting reference](advanced-hunting-reference.md) +##### [Advanced hunting query language best practices](advanced-hunting-best-practices.md) #### [Custom detections](overview-custom-detections.md) #####[Create custom detections rules](custom-detection-rules.md) ### [Management and APIs](management-apis.md) -#### [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -#### [Windows Defender ATP APIs](apis-intro.md) -#### [Managed security service provider support](mssp-support-windows-defender-advanced-threat-protection.md) +#### [Understand threat intelligence concepts](threat-indicator-concepts.md) +#### [Microsoft Defender ATP APIs](apis-intro.md) +#### [Managed security service provider support](mssp-support.md) ### [Microsoft Threat Protection](threat-protection-integration.md) -#### [Protect users, data, and devices with conditional access](conditional-access-windows-defender-advanced-threat-protection.md) +#### [Protect users, data, and devices with conditional access](conditional-access.md) #### [Microsoft Cloud App Security in Windows overview](microsoft-cloud-app-security-integration.md) #### [Information protection in Windows overview](information-protection-in-windows-overview.md) @@ -98,18 +98,18 @@ ### [Microsoft Threat Experts](microsoft-threat-experts.md) -### [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) +### [Portal overview](portal-overview.md) ## [Get started](get-started.md) -### [What's new in Windows Defender ATP](whats-new-in-windows-defender-atp.md) -### [Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md) -### [Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md) -### [Preview features](preview-windows-defender-advanced-threat-protection.md) -### [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) -### [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md) +### [What's new in Microsoft Defender ATP](whats-new-in-microsoft-defender-atp.md) +### [Minimum requirements](minimum-requirements.md) +### [Validate licensing and complete setup](licensing.md) +### [Preview features](preview.md) +### [Data storage and privacy](data-storage-privacy.md) +### [Assign user access to the portal](assign-portal-access.md) -### [Evaluate Windows Defender ATP](evaluate-atp.md) +### [Evaluate Microsoft Defender ATP](evaluate-atp.md) ####Evaluate attack surface reduction ##### [Hardware-based isolation](../windows-defender-application-guard/test-scenarios-wd-app-guard.md) ##### [Application control](../windows-defender-application-control/audit-windows-defender-application-control-policies.md) @@ -120,7 +120,7 @@ ##### [Network firewall](../windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) #### [Evaluate next generation protection](../windows-defender-antivirus/evaluate-windows-defender-antivirus.md) -### [Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) +### [Access the Windows Defender Security Center Community Center](community.md) ## [Configure and manage capabilities](onboard.md) ### [Configure attack surface reduction](configure-attack-surface-reduction.md) @@ -210,29 +210,29 @@ ##### [Use the mpcmdrun.exe command line tool to manage next generation protection](../windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) -### [Configure Secure score dashboard security controls](secure-score-dashboard-windows-defender-advanced-threat-protection.md) +### [Configure Secure score dashboard security controls](secure-score-dashboard.md) ### Management and API support -#### [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) -##### [Onboard previous versions of Windows](onboard-downlevel-windows-defender-advanced-threat-protection.md) -##### [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -###### [Onboard machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -###### [Onboard machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -###### [Onboard machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -####### [Onboard machines using Microsoft Intune](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#onboard-machines-using-microsoft-intune) -###### [Onboard machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -###### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -##### [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) -##### [Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) -##### [Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md) -##### [Run simulated attacks on machines](attack-simulations-windows-defender-advanced-threat-protection.md) -##### [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -##### [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot subscription and portal access issues](troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) +#### [Onboard machines](onboard-configure.md) +##### [Onboard previous versions of Windows](onboard-downlevel.md) +##### [Onboard Windows 10 machines](configure-endpoints.md) +###### [Onboard machines using Group Policy](configure-endpoints-gp.md) +###### [Onboard machines using System Center Configuration Manager](configure-endpoints-sccm.md) +###### [Onboard machines using Mobile Device Management tools](configure-endpoints-mdm.md) +####### [Onboard machines using Microsoft Intune](configure-endpoints-mdm.md#onboard-machines-using-microsoft-intune) +###### [Onboard machines using a local script](configure-endpoints-script.md) +###### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) +##### [Onboard servers](configure-server-endpoints.md) +##### [Onboard non-Windows machines](configure-endpoints-non-windows.md) +##### [Run a detection test on a newly onboarded machine](run-detection-test.md) +##### [Run simulated attacks on machines](attack-simulations.md) +##### [Configure proxy and Internet connectivity settings](configure-proxy-internet.md) +##### [Troubleshoot onboarding issues](troubleshoot-onboarding.md) +###### [Troubleshoot subscription and portal access issues](troubleshoot-onboarding-error-messages.md) -#### [Windows Defender ATP API](use-apis.md) -##### [Get started with Windows Defender ATP APIs](apis-intro.md) +#### [Microsoft Defender ATP API](use-apis.md) +##### [Get started with Microsoft Defender ATP APIs](apis-intro.md) ###### [Hello World](api-hello-world.md) ###### [Get access with application context](exposed-apis-create-app-webapp.md) ###### [Get access with user context](exposed-apis-create-app-nativeapp.md) @@ -240,65 +240,65 @@ ###### [Advanced Hunting](run-advanced-query-api.md) -###### [Alert](alerts-windows-defender-advanced-threat-protection-new.md) -####### [List alerts](get-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Create alert](create-alert-by-reference-windows-defender-advanced-threat-protection-new.md) -####### [Update Alert](update-alert-windows-defender-advanced-threat-protection-new.md) -####### [Get alert information by ID](get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md) -####### [Get alert related domains information](get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md) -####### [Get alert related file information](get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md) -####### [Get alert related IPs information](get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md) -####### [Get alert related machine information](get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md) -####### [Get alert related user information](get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md) +###### [Alert](alerts.md) +####### [List alerts](get-alerts.md) +####### [Create alert](create-alert-by-reference.md) +####### [Update Alert](update-alert.md) +####### [Get alert information by ID](get-alert-info-by-id.md) +####### [Get alert related domains information](get-alert-related-domain-info.md) +####### [Get alert related file information](get-alert-related-files-info.md) +####### [Get alert related IPs information](get-alert-related-ip-info.md) +####### [Get alert related machine information](get-alert-related-machine-info.md) +####### [Get alert related user information](get-alert-related-user-info.md) -###### [Machine](machine-windows-defender-advanced-threat-protection-new.md) -####### [List machines](get-machines-windows-defender-advanced-threat-protection-new.md) -####### [Get machine by ID](get-machine-by-id-windows-defender-advanced-threat-protection-new.md) -####### [Get machine log on users](get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md) -####### [Get machine related alerts](get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Add or Remove machine tags](add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md) -####### [Find machines by IP](find-machines-by-ip-windows-defender-advanced-threat-protection-new.md) +###### [Machine](machine.md) +####### [List machines](get-machines.md) +####### [Get machine by ID](get-machine-by-id.md) +####### [Get machine log on users](get-machine-log-on-users.md) +####### [Get machine related alerts](get-machine-related-alerts.md) +####### [Add or Remove machine tags](add-or-remove-machine-tags.md) +####### [Find machines by IP](find-machines-by-ip.md) -###### [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) -####### [List Machine Actions](get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) -####### [Get Machine Action](get-machineaction-object-windows-defender-advanced-threat-protection-new.md) -####### [Collect investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md) -####### [Get investigation package SAS URI](get-package-sas-uri-windows-defender-advanced-threat-protection-new.md) -####### [Isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md) -####### [Release machine from isolation](unisolate-machine-windows-defender-advanced-threat-protection-new.md) -####### [Restrict app execution](restrict-code-execution-windows-defender-advanced-threat-protection-new.md) -####### [Remove app restriction](unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) -####### [Run antivirus scan](run-av-scan-windows-defender-advanced-threat-protection-new.md) -####### [Offboard machine](offboard-machine-api-windows-defender-advanced-threat-protection-new.md) -####### [Stop and quarantine file](stop-and-quarantine-file-windows-defender-advanced-threat-protection-new.md) -####### [Initiate investigation (preview)](initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md) +###### [Machine Action](machineaction.md) +####### [List Machine Actions](get-machineactions-collection.md) +####### [Get Machine Action](get-machineaction-object.md) +####### [Collect investigation package](collect-investigation-package.md) +####### [Get investigation package SAS URI](get-package-sas-uri.md) +####### [Isolate machine](isolate-machine.md) +####### [Release machine from isolation](unisolate-machine.md) +####### [Restrict app execution](restrict-code-execution.md) +####### [Remove app restriction](unrestrict-code-execution.md) +####### [Run antivirus scan](run-av-scan.md) +####### [Offboard machine](offboard-machine-api.md) +####### [Stop and quarantine file](stop-and-quarantine-file.md) +####### [Initiate investigation (preview)](initiate-autoir-investigation.md) -###### [Indicators (preview)](ti-indicator-windows-defender-advanced-threat-protection-new.md) -####### [Submit Indicator](post-ti-indicator-windows-defender-advanced-threat-protection-new.md) -####### [List Indicators](get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md) -####### [Delete Indicator](delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md) +###### [Indicators (preview)](ti-indicator.md) +####### [Submit Indicator](post-ti-indicator.md) +####### [List Indicators](get-ti-indicators-collection.md) +####### [Delete Indicator](delete-ti-indicator-by-id.md) ###### Domain -####### [Get domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Get domain related machines](get-domain-related-machines-windows-defender-advanced-threat-protection-new.md) -####### [Get domain statistics](get-domain-statistics-windows-defender-advanced-threat-protection-new.md) -####### [Is domain seen in organization](is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md) +####### [Get domain related alerts](get-domain-related-alerts.md) +####### [Get domain related machines](get-domain-related-machines.md) +####### [Get domain statistics](get-domain-statistics.md) +####### [Is domain seen in organization](is-domain-seen-in-org.md) -###### [File](files-windows-defender-advanced-threat-protection-new.md) -####### [Get file information](get-file-information-windows-defender-advanced-threat-protection-new.md) -####### [Get file related alerts](get-file-related-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Get file related machines](get-file-related-machines-windows-defender-advanced-threat-protection-new.md) -####### [Get file statistics](get-file-statistics-windows-defender-advanced-threat-protection-new.md) +###### [File](files.md) +####### [Get file information](get-file-information.md) +####### [Get file related alerts](get-file-related-alerts.md) +####### [Get file related machines](get-file-related-machines.md) +####### [Get file statistics](get-file-statistics.md) ###### IP -####### [Get IP related alerts](get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Get IP related machines](get-ip-related-machines-windows-defender-advanced-threat-protection-new.md) -####### [Get IP statistics](get-ip-statistics-windows-defender-advanced-threat-protection-new.md) -####### [Is IP seen in organization](is-ip-seen-org-windows-defender-advanced-threat-protection-new.md) +####### [Get IP related alerts](get-ip-related-alerts.md) +####### [Get IP related machines](get-ip-related-machines.md) +####### [Get IP statistics](get-ip-statistics.md) +####### [Is IP seen in organization](is-ip-seen-org.md) -###### [User](user-windows-defender-advanced-threat-protection-new.md) -####### [Get user related alerts](get-user-related-alerts-windows-defender-advanced-threat-protection-new.md) -####### [Get user related machines](get-user-related-machines-windows-defender-advanced-threat-protection-new.md) +###### [User](user.md) +####### [Get user related alerts](get-user-related-alerts.md) +####### [Get user related machines](get-user-related-machines.md) ##### How to use APIs - Samples ###### Advanced Hunting API @@ -312,36 +312,36 @@ #### API for custom alerts -##### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) -##### [Use the threat intelligence API to create custom alerts](use-custom-ti-windows-defender-advanced-threat-protection.md) -##### [Create custom threat intelligence alerts](custom-ti-api-windows-defender-advanced-threat-protection.md) -##### [PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md) -##### [Python code examples](python-example-code-windows-defender-advanced-threat-protection.md) -##### [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -##### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +##### [Enable the custom threat intelligence application](enable-custom-ti.md) +##### [Use the threat intelligence API to create custom alerts](use-custom-ti.md) +##### [Create custom threat intelligence alerts](custom-ti-api.md) +##### [PowerShell code examples](powershell-example-code.md) +##### [Python code examples](python-example-code.md) +##### [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +##### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) -#### [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md) -##### [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md) -##### [Configure Splunk to pull alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -##### [Configure HP ArcSight to pull alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -##### [Windows Defender ATP SIEM alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -##### [Pull alerts using SIEM REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -##### [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +#### [Pull alerts to your SIEM tools](configure-siem.md) +##### [Enable SIEM integration](enable-siem-integration.md) +##### [Configure Splunk to pull alerts](configure-splunk.md) +##### [Configure HP ArcSight to pull alerts](configure-arcsight.md) +##### [Microsoft Defender ATP SIEM alert API fields](api-portal-mapping.md) +##### [Pull alerts using SIEM REST API](pull-alerts-using-rest-api.md) +##### [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) #### Reporting -##### [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -##### [Threat protection reports](threat-protection-reports-windows-defender-advanced-threat-protection.md) -##### [Machine health and compliance reports](machine-reports-windows-defender-advanced-threat-protection.md) +##### [Create and build Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +##### [Threat protection reports](threat-protection-reports.md) +##### [Machine health and compliance reports](machine-reports.md) #### Role-based access control -##### [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md) -###### [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) -###### [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine tags](machine-tags-windows-defender-advanced-threat-protection.md) +##### [Manage portal access using RBAC](rbac.md) +###### [Create and manage roles](user-roles.md) +###### [Create and manage machine groups](machine-groups.md) +####### [Create and manage machine tags](machine-tags.md) -#### [Configure managed security service provider (MSSP) support](configure-mssp-support-windows-defender-advanced-threat-protection.md) +#### [Configure managed security service provider (MSSP) support](configure-mssp-support.md) @@ -349,56 +349,56 @@ ### [Configure and manage Microsoft Threat Experts capabilities](configure-microsoft-threat-experts.md) ### Configure Microsoft Threat Protection integration -#### [Configure conditional access](configure-conditional-access-windows-defender-advanced-threat-protection.md) +#### [Configure conditional access](configure-conditional-access.md) #### [Configure Microsoft Cloud App Security in Windows](microsoft-cloud-app-security-config.md) ####[Configure information protection in Windows](information-protection-in-windows-config.md) -### [Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) +### [Configure Windows Defender Security Center settings](preferences-setup.md) #### General -##### [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -##### [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) -##### [Enable and create Power BI reports using Windows Security app data](powerbi-reports-windows-defender-advanced-threat-protection.md) -##### [Enable Secure score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) -##### [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md) +##### [Update data retention settings](data-retention-settings.md) +##### [Configure alert notifications](configure-email-notifications.md) +##### [Enable and create Power BI reports using Windows Security app data](powerbi-reports.md) +##### [Enable Secure score security controls](enable-secure-score.md) +##### [Configure advanced features](advanced-features.md) #### Permissions -##### [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) -##### [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md) -###### [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) -###### [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) -####### [Create and manage machine tags](machine-tags-windows-defender-advanced-threat-protection.md) +##### [Use basic permissions to access the portal](basic-permissions.md) +##### [Manage portal access using RBAC](rbac.md) +###### [Create and manage roles](user-roles.md) +###### [Create and manage machine groups](machine-groups.md) +####### [Create and manage machine tags](machine-tags.md) #### APIs -##### [Enable Threat intel](enable-custom-ti-windows-defender-advanced-threat-protection.md) -##### [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md) +##### [Enable Threat intel](enable-custom-ti.md) +##### [Enable SIEM integration](enable-siem-integration.md) ####Rules -##### [Manage suppression rules](manage-suppression-rules-windows-defender-advanced-threat-protection.md) -##### [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -##### [Manage allowed/blocked lists](manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -##### [Manage automation file uploads](manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) -##### [Manage automation folder exclusions](manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) +##### [Manage suppression rules](manage-suppression-rules.md) +##### [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list.md) +##### [Manage allowed/blocked lists](manage-allowed-blocked-list.md) +##### [Manage automation file uploads](manage-automation-file-uploads.md) +##### [Manage automation folder exclusions](manage-automation-folder-exclusions.md) ####Machine management -##### [Onboarding machines](onboard-configure-windows-defender-advanced-threat-protection.md) -##### [Offboarding machines](offboard-machines-windows-defender-advanced-threat-protection.md) +##### [Onboarding machines](onboard-configure.md) +##### [Offboarding machines](offboard-machines.md) -#### [Configure Windows Security app time zone settings](time-settings-windows-defender-advanced-threat-protection.md) +#### [Configure Windows Security app time zone settings](time-settings.md) -## [Troubleshoot Windows Defender ATP](troubleshoot-wdatp.md) +## [Troubleshoot Microsoft Defender ATP](troubleshoot-overview.md) ###Troubleshoot sensor state -#### [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md) -#### [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) -#### [Inactive machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) -#### [Misconfigured machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) -#### [Review sensor events and errors on machines with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) +#### [Check sensor state](check-sensor-status.md) +#### [Fix unhealthy sensors](fix-unhealhty-sensors.md) +#### [Inactive machines](fix-unhealhty-sensors.md#inactive-machines) +#### [Misconfigured machines](fix-unhealhty-sensors.md#misconfigured-machines) +#### [Review sensor events and errors on machines with Event Viewer](event-error-codes.md) -### [Troubleshoot Windows Defender ATP service issues](troubleshoot-windows-defender-advanced-threat-protection.md) -#### [Check service health](service-status-windows-defender-advanced-threat-protection.md) +### [Troubleshoot Microsoft Defender ATP service issues](troubleshoot.md) +#### [Check service health](service-status.md) ###Troubleshoot attack surface reduction #### [Network protection](../windows-defender-exploit-guard/troubleshoot-np.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md index 5ab62122e6..106306a8c5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md +++ b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md @@ -20,14 +20,14 @@ ms.topic: article **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] - Adds or remove tag to a specific machine. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md index df2d4cbab8..98b6b36f1f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md @@ -1,6 +1,6 @@ --- -title: Configure advanced features in Windows Defender ATP -description: Turn on advanced features such as block file in Windows Defender Advanced Threat Protection. +title: Configure advanced features in Microsoft Defender ATP +description: Turn on advanced features such as block file in Microsoft Defender Advanced Threat Protection. keywords: advanced features, settings, block file, automated investigation, auto-resolve, skype, azure atp, office 365, azure information protection, intune search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -17,14 +17,14 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Configure advanced features in Windows Defender ATP +# Configure advanced features in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedfeats-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedfeats-abovefoldlink) -Depending on the Microsoft security products that you use, some advanced features might be available for you to integrate Windows Defender ATP with. +Depending on the Microsoft security products that you use, some advanced features might be available for you to integrate Microsoft Defender ATP with. Use the following advanced features to get better protected from potentially malicious files and gain better insight during security investigations: @@ -69,7 +69,7 @@ The integration with Azure Advanced Threat Protection allows you to pivot direct >[!NOTE] >You'll need to have the appropriate license to enable this feature. -### Enable the Windows Defender ATP integration from the Azure ATP portal +### Enable the Microsoft Defender ATP integration from the Azure ATP portal To receive contextual machine integration in Azure ATP, you'll also need to enable the feature in the Azure ATP portal. 1. Login to the [Azure portal](https://portal.atp.azure.com/) with a Global Administrator or Security Administrator role. @@ -88,10 +88,10 @@ When you enable this feature, you'll be able to incorporate data from Office 365 >[!NOTE] >You'll need to have the appropriate license to enable this feature. -To receive contextual machine integration in Office 365 Threat Intelligence, you'll need to enable the Windows Defender ATP settings in the Security & Compliance dashboard. For more information, see [Office 365 Threat Intelligence overview](https://support.office.com/en-us/article/Office-365-Threat-Intelligence-overview-32405DA5-BEE1-4A4B-82E5-8399DF94C512). +To receive contextual machine integration in Office 365 Threat Intelligence, you'll need to enable the Microsoft Defender ATP settings in the Security & Compliance dashboard. For more information, see [Office 365 Threat Intelligence overview](https://support.office.com/en-us/article/Office-365-Threat-Intelligence-overview-32405DA5-BEE1-4A4B-82E5-8399DF94C512). ## Microsoft Threat Experts -This feature is currently on public preview. When you enable this feature, you'll receive targeted attack notifications from Microsoft Threat Experts through your Windows Defender ATP portal's alerts dashboard and via email if you configure it. +This feature is currently on public preview. When you enable this feature, you'll receive targeted attack notifications from Microsoft Threat Experts through your Microsoft Defender ATP portal's alerts dashboard and via email if you configure it. >[!NOTE] >This feature will be available with an E5 license for [Enterprise Mobility + Security](https://www.microsoft.com/cloud-platform/enterprise-mobility-security) on machines running Windows 10 version 1809 or later. @@ -99,7 +99,7 @@ This feature is currently on public preview. When you enable this feature, you'l ## Microsoft Cloud App Security -Enabling this setting forwards Windows Defender ATP signals to Microsoft Cloud App Security to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Cloud App Security data. +Enabling this setting forwards Microsoft Defender ATP signals to Microsoft Cloud App Security to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Cloud App Security data. >[!NOTE] >This feature is available with an E5 license for [Enterprise Mobility + Security](https://www.microsoft.com/cloud-platform/enterprise-mobility-security) on machines running Windows 10 version 1809 or later. @@ -111,14 +111,14 @@ Turning this setting on forwards signals to Azure Information Protection, giving ## Microsoft Intune connection This feature is only available if you have an active Microsoft Intune (Intune) license. -When you enable this feature, you'll be able to share Windows Defender ATP device information to Intune and enhance policy enforcement. +When you enable this feature, you'll be able to share Microsoft Defender ATP device information to Intune and enhance policy enforcement. >[!NOTE] ->You'll need to enable the integration on both Intune and Windows Defender ATP to use this feature. +>You'll need to enable the integration on both Intune and Microsoft Defender ATP to use this feature. ## Preview features -Learn about new features in the Windows Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. +Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. You'll have access to upcoming features which you can provide feedback on to help improve the overall experience before features are generally available. @@ -130,5 +130,5 @@ You'll have access to upcoming features which you can provide feedback on to hel ## Related topics - [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) - [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) - [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md index 6c0c82d32d..34401ec9b1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices.md @@ -1,5 +1,5 @@ --- -title: Advanced hunting best practices in Windows Defender ATP +title: Advanced hunting best practices in Microsoft Defender ATP description: Learn about Advanced hunting best practices such as what filters and keywords to use to effectively query data. keywords: advanced hunting, best practices, keyword, filters, atp query, query atp data, intellisense, atp telemetry, events, events telemetry, azure log analytics search.product: eADQiWindows 10XVcnh @@ -18,16 +18,16 @@ ms.topic: conceptual ms.date: 04/24/2018 --- -# Advanced hunting query best practices Windows Defender ATP +# Advanced hunting query best practices Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-bestpractices-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-bestpractices-abovefoldlink) ## Performance best practices The following best practices serve as a guideline of query performance best practices and for you to get faster results and be able to run complex queries. @@ -42,7 +42,7 @@ The following best practices serve as a guideline of query performance best prac ### Unique Process IDs Process IDs are recycled in Windows and reused for new processes and therefore can't serve as a unique identifier for a specific process. -To address this issue, Windows Defender ATP created the time process. To get a unique identifier for a process on a specific machine, use the process ID together with the process creation time. +To address this issue, Microsoft Defender ATP created the time process. To get a unique identifier for a process on a specific machine, use the process ID together with the process creation time. So, when you join data based on a specific process or summarize data for each process, you'll need to use a machine identifier (either MachineId or ComputerName), a process ID (ProcessId or InitiatingProcessId) and the process creation time (ProcessCreationTime or InitiatingProcessCreationTime) @@ -92,7 +92,7 @@ ProcessCreationEvents | where CanonicalCommandLine contains "stop" and CanonicalCommandLine contains "MpsSvc" ``` ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-bestpractices-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-bestpractices-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md index 467af897d1..fe8f545929 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md @@ -1,5 +1,5 @@ --- -title: Advanced hunting reference in Windows Defender ATP +title: Advanced hunting reference in Microsoft Defender ATP description: Learn about Advanced hunting table reference such as column name, data type, and description keywords: advanced hunting, atp query, query atp data, intellisense, atp telemetry, events, events telemetry, azure log analytics, column name, data type, description search.product: eADQiWindows 10XVcnh @@ -18,16 +18,16 @@ ms.topic: article ms.date: 06/01/2018 --- -# Advanced hunting reference in Windows Defender ATP +# Advanced hunting reference in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink) ## Advanced hunting column reference @@ -99,7 +99,7 @@ To effectively build queries that span multiple tables, you need to understand t | ProcessIntegrityLevel | string | Integrity level of the newly created process. Windows assigns integrity levels to processes based on certain characteristics, such as if they were launched from an internet downloaded. These integrity levels influence permissions to resources. | | ProcessTokenElevation | string | Token type indicating the presence or absence of User Access Control (UAC) privilege elevation applied to the newly created process | | Protocol | string | IP protocol used, whether TCP or UDP | -| PublicIP | string | Public IP address used by the onboarded machine to connect to the Windows Defender ATP service. This could be the IP address of the machine itself, a NAT device, or a proxy. | +| PublicIP | string | Public IP address used by the onboarded machine to connect to the Microsoft Defender ATP service. This could be the IP address of the machine itself, a NAT device, or a proxy. | | RegistryKey | string | Registry key that the recorded action was applied to | | RegistryValueData | string | Data of the registry value that the recorded action was applied to | | RegistryValueName | string | Name of the registry value that the recorded action was applied to | @@ -115,7 +115,7 @@ To effectively build queries that span multiple tables, you need to understand t | Table | string | Table that contains the details of the event | | TunnelingType | string | Tunneling protocol, if the interface is used for this purpose, for example 6to4, Teredo, ISATAP, PPTP, SSTP, and SSH | ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-belowfoldlink) ## Related topic - [Query data using Advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md index 2665b31d0e..4d711a8fff 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md @@ -1,6 +1,6 @@ --- -title: Query data using Advanced hunting in Windows Defender ATP -description: Learn about Advanced hunting in Windows Defender ATP and how to query ATP data. +title: Query data using Advanced hunting in Microsoft Defender ATP +description: Learn about Advanced hunting in Microsoft Defender ATP and how to query ATP data. keywords: advanced hunting, atp query, query atp data, intellisense, atp telemetry, events, events telemetry, azure log analytics search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,9 +18,9 @@ ms.topic: article ms.date: 08/15/2018 --- -# Query data using Advanced hunting in Windows Defender ATP +# Query data using Advanced hunting in Microsoft Defender ATP ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-abovefoldlink) To get you started in querying your data, you can use the basic or Advanced query examples that have some preloaded queries for you to understand the basic query syntax. @@ -33,7 +33,7 @@ A typical query starts with a table name followed by a series of operators separ In the following example, we start with the table name **ProcessCreationEvents** and add piped elements as needed. -![Image of Windows Defender ATP Advanced hunting query](images/advanced-hunting-query-example.png) +![Image of Microsoft Defender ATP Advanced hunting query](images/advanced-hunting-query-example.png) First, we define a time filter to review only records from the previous seven days. @@ -127,7 +127,7 @@ The result set has several capabilities to provide you with effective investigat - Columns that return entity-related objects, such as Machine name, Machine ID, File name, SHA1, User, IP, and URL, are linked to their entity pages in Windows Defender Security Center. - You can right-click on a cell in the result set and add a filter to your written query. The current filtering options are **include**, **exclude** or **advanced filter**, which provides additional filtering options on the cell value. These cell values are part of the row set. -![Image of Windows Defender ATP Advanced hunting result set](images/atp-advanced-hunting-results-filter.png) +![Image of Microsoft Defender ATP Advanced hunting result set](images/atp-advanced-hunting-results-filter.png) ## Filter results in Advanced hunting In Advanced hunting, you can use the advanced filter on the output result set of the query. @@ -146,7 +146,7 @@ The filter selections will resolve as an additional query term and the results w Check out the [Advanced hunting repository](https://github.com/Microsoft/WindowsDefenderATP-Hunting-Queries). Contribute and use example queries shared by our customers. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-belowfoldlink) ## Related topic - [Advanced hunting reference](advanced-hunting-reference-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md index fb04442da2..86249293b6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md @@ -1,6 +1,6 @@ --- -title: View and organize the Windows Defender ATP Alerts queue -description: Learn about how the Windows Defender ATP alerts queues work, and how to sort and filter lists of alerts. +title: View and organize the Microsoft Defender ATP Alerts queue +description: Learn about how the Microsoft Defender ATP alerts queues work, and how to sort and filter lists of alerts. keywords: alerts, queues, alerts queue, sort, order, filter, manage alerts, new, in progress, resolved, newest, time in queue, severity, time period, microsoft threat experts alerts search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,14 +18,14 @@ ms.topic: article ms.date: 04/24/2018 --- -# View and organize the Windows Defender Advanced Threat Protection Alerts queue +# View and organize the Microsoft Defender Advanced Threat Protection Alerts queue **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-alertsq-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-alertsq-abovefoldlink) The **Alerts queue** shows a list of alerts that were flagged from machines in your network. By default, the queue displays alerts seen in the last 30 days in a grouped view, with the most recent alerts showing at the top of the list, helping you see the most recent alerts first. @@ -55,14 +55,14 @@ Informational
(Grey) | Informational alerts are those that might not be con #### Understanding alert severity -It is important to understand that the Windows Defender Antivirus (Windows Defender AV) and Windows Defender ATP alert severities are different because they represent different scopes. +It is important to understand that the Windows Defender Antivirus (Windows Defender AV) and Microsoft Defender ATP alert severities are different because they represent different scopes. The Windows Defender AV threat severity represents the absolute severity of the detected threat (malware), and is assigned based on the potential risk to the individual machine, if infected. -The Windows Defender ATP alert severity represents the severity of the detected behavior, the actual risk to the machine but more importantly the potential risk to the organization. +The Microsoft Defender ATP alert severity represents the severity of the detected behavior, the actual risk to the machine but more importantly the potential risk to the organization. So, for example: -- The severity of a Windows Defender ATP alert about a Windows Defender AV detected threat that was completely prevented and did not infect the machine is categorized as "Informational" because there was no actual damage incurred. +- The severity of a Microsoft Defender ATP alert about a Windows Defender AV detected threat that was completely prevented and did not infect the machine is categorized as "Informational" because there was no actual damage incurred. - An alert about a commercial malware was detected while executing, but blocked and remediated by Windows Defender AV, is categorized as "Low" because it may have caused some damage to the individual machine but poses no organizational threat. - An alert about malware detected while executing which can pose a threat not only to the individual machine but to the organization, regardless if it was eventually blocked, may be ranked as "Medium" or "High". - Suspicious behavioral alerts which were not blocked or remediated will be ranked "Low", "Medium" or "High" following the same organizational threat considerations. @@ -94,11 +94,11 @@ Use this filter to focus on alerts that are related to high profile threats. You ## Related topics -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts.md b/windows/security/threat-protection/microsoft-defender-atp/alerts.md index da5c717e31..d2fdf0726f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts.md @@ -18,11 +18,11 @@ ms.topic: article # Alert resource type **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] -Represents an alert entity in Windows Defender ATP. +Represents an alert entity in Microsoft Defender ATP. # Methods Method|Return Type |Description diff --git a/windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md b/windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md index 9ee1dafbb9..a1fdedb347 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md +++ b/windows/security/threat-protection/microsoft-defender-atp/api-hello-world.md @@ -16,12 +16,12 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Windows Defender ATP API - Hello World +# Microsoft Defender ATP API - Hello World **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) +> Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) ## Get Alerts using a simple PowerShell script @@ -50,7 +50,7 @@ For the App registration stage, you must have a Global administrator role in you ![Image of Create application window](images/webapp-create.png) -4. Allow your App to access Windows Defender ATP and assign it 'Read all alerts' permission: +4. Allow your App to access Microsoft Defender ATP and assign it 'Read all alerts' permission: - Click **Settings** > **Required permissions** > **Add**. @@ -184,6 +184,6 @@ You’re all done! You have just successfully: ## Related topic -- [Windows Defender ATP APIs](exposed-apis-list.md) -- [Access Windows Defender ATP with application context](exposed-apis-create-app-webapp.md) -- [Access Windows Defender ATP with user context](exposed-apis-create-app-nativeapp.md) \ No newline at end of file +- [Microsoft Defender ATP APIs](exposed-apis-list.md) +- [Access Microsoft Defender ATP with application context](exposed-apis-create-app-webapp.md) +- [Access Microsoft Defender ATP with user context](exposed-apis-create-app-nativeapp.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md index 4520b214d1..aeb28a277e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md +++ b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md @@ -1,5 +1,5 @@ --- -title: Windows Defender ATP alert API fields +title: Microsoft Defender ATP alert API fields description: Understand how the alert API fields map to the values in Windows Defender Security Center keywords: alerts, alert fields, fields, api, fields, pull alerts, rest api, request, response search.product: eADQiWindows 10XVcnh @@ -18,17 +18,17 @@ ms.topic: article ms.date: 10/16/2017 --- -# Windows Defender ATP SIEM alert API fields +# Microsoft Defender ATP SIEM alert API fields **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-apiportalmapping-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-apiportalmapping-abovefoldlink) Understand what data fields are exposed as part of the alerts API and how they map to Windows Defender Security Center. @@ -37,7 +37,7 @@ Understand what data fields are exposed as part of the alerts API and how they m The following table lists the available fields exposed in the alerts API payload. It shows examples for the populated values and a reference on how data is reflected on the portal. -The ArcSight field column contains the default mapping between the Windows Defender ATP fields and the built-in fields in ArcSight. You can download the mapping file from the portal when you enable the SIEM integration feature and you can modify it to match the needs of your organization. For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +The ArcSight field column contains the default mapping between the Microsoft Defender ATP fields and the built-in fields in ArcSight. You can download the mapping file from the portal when you enable the SIEM integration feature and you can modify it to match the needs of your organization. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). Field numbers match the numbers in the images below. @@ -47,12 +47,12 @@ Field numbers match the numbers in the images below. | 1 | AlertTitle | name | A dll was unexpectedly loaded into a high integrity process without a UAC prompt | Value available for every alert. | | 2 | Severity | deviceSeverity | Medium | Value available for every alert. | | 3 | Category | deviceEventCategory | Privilege Escalation | Value available for every alert. | -| 4 | Source | sourceServiceName | WindowsDefenderATP | Windows Defender Antivirus or Windows Defender ATP. Value available for every alert. | +| 4 | Source | sourceServiceName | WindowsDefenderATP | Windows Defender Antivirus or Microsoft Defender ATP. Value available for every alert. | | 5 | MachineName | sourceHostName | liz-bean | Value available for every alert. | | 6 | FileName | fileName | Robocopy.exe | Available for alerts associated with a file or process. | | 7 | FilePath | filePath | C:\Windows\System32\Robocopy.exe | Available for alerts associated with a file or process. | -| 8 | UserDomain | sourceNtDomain | contoso | The domain of the user context running the activity, available for Windows Defender ATP behavioral based alerts. | -| 9 | UserName | sourceUserName | liz-bean | The user context running the activity, available for Windows Defender ATP behavioral based alerts. | +| 8 | UserDomain | sourceNtDomain | contoso | The domain of the user context running the activity, available for Microsoft Defender ATP behavioral based alerts. | +| 9 | UserName | sourceUserName | liz-bean | The user context running the activity, available for Microsoft Defender ATP behavioral based alerts. | | 10 | Sha1 | fileHash | 5b4b3985339529be3151d331395f667e1d5b7f35 | Available for alerts associated with a file or process. | | 11 | Md5 | deviceCustomString5 | 55394b85cb5edddff551f6f3faa9d8eb | Available for Windows Defender AV alerts. | | 12 | Sha256 | deviceCustomString6 | 9987474deb9f457ece2a9533a08ec173a0986fa3aa6ac355eeba5b622e4a43f5 | Available for Windows Defender AV alerts. | @@ -72,7 +72,7 @@ Field numbers match the numbers in the images below. | | InternalIPv6List | No mapping | fd30:0000:0000:0001:ff4e:003e:0009:000e, FE80:CD00:0000:0CDE:1257:0000:211E:729C | List of IPV6 internal IPs for active network interfaces. | | Internal field | LastProcessedTimeUtc | No mapping | 2017-05-07T01:56:58.9936648Z | Time when event arrived at the backend. This field can be used when setting the request parameter for the range of time that alerts are retrieved. | | | Not part of the schema | deviceVendor | | Static value in the ArcSight mapping - 'Microsoft'. | -| | Not part of the schema | deviceProduct | | Static value in the ArcSight mapping - 'Windows Defender ATP'. | +| | Not part of the schema | deviceProduct | | Static value in the ArcSight mapping - 'Microsoft Defender ATP'. | | | Not part of the schema | deviceVersion | | Static value in the ArcSight mapping - '2.0', used to identify the mapping versions. @@ -92,8 +92,8 @@ Field numbers match the numbers in the images below. ## Related topics -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) - [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/apis-intro.md b/windows/security/threat-protection/microsoft-defender-atp/apis-intro.md index d05ecd0f1b..1b042e2d4c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/apis-intro.md +++ b/windows/security/threat-protection/microsoft-defender-atp/apis-intro.md @@ -1,6 +1,6 @@ --- -title: Windows Defender Advanced Threat Protection API overview -description: Learn how you can use APIs to automate workflows and innovate based on Windows Defender ATP capabilities +title: Microsoft Defender Advanced Threat Protection API overview +description: Learn how you can use APIs to automate workflows and innovate based on Microsoft Defender ATP capabilities keywords: apis, api, wdatp, open api, windows defender atp api, public api, supported apis, alerts, machine, user, domain, ip, file, advanced hunting, query search.product: eADQiWindows 10XVcnh ms.prod: w10 @@ -16,33 +16,33 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Windows Defender ATP API overview +# Microsoft Defender ATP API overview **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) +> Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) -Windows Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate workflows and innovate based on Windows Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). +Microsoft Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate workflows and innovate based on Microsoft Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). In general, you’ll need to take the following steps to use the APIs: - Create an AAD application - Get an access token using this application -- Use the token to access Windows Defender ATP API +- Use the token to access Microsoft Defender ATP API -You can access Windows Defender ATP API with **Application Context** or **User Context**. +You can access Microsoft Defender ATP API with **Application Context** or **User Context**. - **Application Context: (Recommended)**
Used by apps that run without a signed-in user present. for example, apps that run as background services or daemons. - Steps that need to be taken to access Windows Defender ATP API with application context: + Steps that need to be taken to access Microsoft Defender ATP API with application context: 1. Create an AAD Web-Application. 2. Assign the desired permission to the application, for example, 'Read Alerts', 'Isolate Machines'. 3. Create a key for this Application. 4. Get token using the application with its key. - 5. Use the token to access Windows Defender ATP API + 5. Use the token to access Microsoft Defender ATP API For more information, see [Get access with application context](exposed-apis-create-app-webapp.md). @@ -50,16 +50,16 @@ You can access Windows Defender ATP API with **Application Context** or **User C - **User Context:**
Used to perform actions in the API on behalf of a user. - Steps that needs to be taken to access Windows Defender ATP API with application context: + Steps that needs to be taken to access Microsoft Defender ATP API with application context: 1. Create AAD Native-Application. 2. Assign the desired permission to the application, e.g 'Read Alerts', 'Isolate Machines' etc. 3. Get token using the application with user credentials. - 4. Use the token to access Windows Defender ATP API + 4. Use the token to access Microsoft Defender ATP API For more information, see [Get access with user context](exposed-apis-create-app-nativeapp.md). ## Related topics -- [Windows Defender ATP APIs](exposed-apis-list.md) -- [Access Windows Defender ATP with application context](exposed-apis-create-app-webapp.md) -- [Access Windows Defender ATP with user context](exposed-apis-create-app-nativeapp.md) \ No newline at end of file +- [Microsoft Defender ATP APIs](exposed-apis-list.md) +- [Access Microsoft Defender ATP with application context](exposed-apis-create-app-webapp.md) +- [Access Microsoft Defender ATP with user context](exposed-apis-create-app-nativeapp.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md index bc87a4503f..227c780e28 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md +++ b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md @@ -1,6 +1,6 @@ --- title: Assign user access to Windows Defender Security Center -description: Assign read and write or read only access to the Windows Defender Advanced Threat Protection portal. +description: Assign read and write or read only access to the Microsoft Defender Advanced Threat Protection portal. keywords: assign user roles, assign read and write access, assign read only access, user, user roles, roles search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,11 +23,11 @@ ms.date: 11/28/2018 **Applies to:** - Azure Active Directory - Office 365 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-assignaccess-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-assignaccess-abovefoldlink) -Windows Defender ATP supports two ways to manage permissions: +Microsoft Defender ATP supports two ways to manage permissions: - **Basic permissions management**: Set permissions to either full access or read-only. - **Role-based access control (RBAC)**: Set granular permissions by defining roles, assigning Azure AD user groups to the roles, and granting the user groups access to machine groups. For more information on RBAC, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). @@ -35,13 +35,13 @@ Windows Defender ATP supports two ways to manage permissions: > [!NOTE] >If you have already assigned basic permissions, you may switch to RBAC anytime. Consider the following before making the switch: ->- Users with full access (users that are assigned the Global Administrator or Security Administrator directory role in Azure AD), are automatically assigned the default Windows Defender ATP administrator role, which also has full access. Additional Azure AD user groups can be assigned to the Windows Defender ATP administrator role after switching to RBAC. Only users assigned to the Windows Defender ATP administrator role can manage permissions using RBAC. +>- Users with full access (users that are assigned the Global Administrator or Security Administrator directory role in Azure AD), are automatically assigned the default Microsoft Defender ATP administrator role, which also has full access. Additional Azure AD user groups can be assigned to the Microsoft Defender ATP administrator role after switching to RBAC. Only users assigned to the Microsoft Defender ATP administrator role can manage permissions using RBAC. >- Users that have read-only access (Security Readers) will lose access to the portal until they are assigned a role. Note that only Azure AD user groups can be assigned a role under RBAC. >- After switching to RBAC, you will not be able to switch back to using basic permissions management. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portalaccess-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portalaccess-belowfoldlink) ## Related topic - [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md index a86ee0b027..9b4ee1c082 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md @@ -1,6 +1,6 @@ --- -title: Experience Windows Defender ATP through simulated attacks -description: Run the provided attack scenario simulations to experience how Windows Defender ATP can detect, investigate, and respond to breaches. +title: Experience Microsoft Defender ATP through simulated attacks +description: Run the provided attack scenario simulations to experience how Microsoft Defender ATP can detect, investigate, and respond to breaches. keywords: wdatp, test, scenario, attack, simulation, simulated, diy, windows defender advanced threat protection search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,23 +18,23 @@ ms.topic: article ms.date: 11/20/2018 --- -# Experience Windows Defender ATP through simulated attacks +# Experience Microsoft Defender ATP through simulated attacks **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-attacksimulations-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-attacksimulations-abovefoldlink) >[!TIP] ->- Learn about the latest enhancements in Windows Defender ATP: [What's new in Windows Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). ->- Windows Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). +>- Learn about the latest enhancements in Microsoft Defender ATP: [What's new in Microsoft Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). +>- Microsoft Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). -You might want to experience Windows Defender ATP before you onboard more than a few machines to the service. To do this, you can run controlled attack simulations on a few test machines. After running the simulated attacks, you can review how Windows Defender ATP surfaces malicious activity and explore how it enables an efficient response. +You might want to experience Microsoft Defender ATP before you onboard more than a few machines to the service. To do this, you can run controlled attack simulations on a few test machines. After running the simulated attacks, you can review how Microsoft Defender ATP surfaces malicious activity and explore how it enables an efficient response. ## Before you begin @@ -62,7 +62,7 @@ Read the walkthrough document provided with each attack scenario. Each document >Simulation files or scripts mimic attack activity but are actually benign and will not harm or compromise the test machine. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-attacksimulations-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-attacksimulations-belowfoldlink) ## Related topics diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index 8968b3b2cf..78375524ed 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -20,12 +20,12 @@ ms.date: 12/04/2018 # Overview of Automated investigations ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automated-investigations-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automated-investigations-abovefoldlink) -The Windows Defender ATP service has a wide breadth of visibility on multiple machines. With this kind of optics, the service generates a multitude of alerts. The volume of alerts generated can be challenging for a typical security operations team to individually address. +The Microsoft Defender ATP service has a wide breadth of visibility on multiple machines. With this kind of optics, the service generates a multitude of alerts. The volume of alerts generated can be challenging for a typical security operations team to individually address. -To address this challenge, Windows Defender ATP uses Automated investigations to significantly reduce the volume of alerts that need to be investigated individually. The Automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. +To address this challenge, Microsoft Defender ATP uses Automated investigations to significantly reduce the volume of alerts that need to be investigated individually. The Automated investigation feature leverages various inspection algorithms, and processes used by analysts (such as playbooks) to examine alerts and take immediate remediation action to resolve breaches. This significantly reduces alert volume, allowing security operations experts to focus on more sophisticated threats and other high value initiatives. The Automated investigations list shows all the investigations that have been initiated automatically and shows other details such as its status, detection source, and the date for when the investigation was initiated. diff --git a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md index 7dc172d03f..ebb98886d3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md @@ -1,6 +1,6 @@ --- title: Use basic permissions to access Windows Defender Security Center -description: Assign read and write or read only access to the Windows Defender Advanced Threat Protection portal. +description: Assign read and write or read only access to the Microsoft Defender Advanced Threat Protection portal. keywords: assign user roles, assign read and write access, assign read only access, user, user roles, roles search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,9 +21,9 @@ ms.topic: article **Applies to:** - Azure Active Directory -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-basicaccess-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-basicaccess-abovefoldlink) Refer to the instructions below to use basic permissions management. diff --git a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md index 007cfbede6..453a7575ed 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md +++ b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md @@ -1,5 +1,5 @@ --- -title: Check the health state of the sensor in Windows Defender ATP +title: Check the health state of the sensor in Microsoft Defender ATP description: Check the sensor health on machines to identify which ones are misconfigured, inactive, or are not reporting sensor data. keywords: sensor, sensor health, misconfigured, inactive, no sensor data, sensor data, impaired communications, communication search.product: eADQiWindows 10XVcnh @@ -18,21 +18,21 @@ ms.topic: article ms.date: 04/24/2018 --- -# Check sensor health state in Windows Defender ATP +# Check sensor health state in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-checksensor-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-checksensor-abovefoldlink) -The sensor health tile provides information on the individual machine’s ability to provide sensor data and communicate with the Windows Defender ATP service. It reports how many machines require attention and helps you identify problematic machines and take action to correct known issues. +The sensor health tile provides information on the individual machine’s ability to provide sensor data and communicate with the Microsoft Defender ATP service. It reports how many machines require attention and helps you identify problematic machines and take action to correct known issues. There are two status indicators on the tile that provide information on the number of machines that are not reporting properly to the service: -- **Misconfigured** - These machines might partially be reporting sensor data to the Windows Defender ATP service and might have configuration errors that need to be corrected. -- **Inactive** - Machines that have stopped reporting to the Windows Defender ATP service for more than seven days in the past month. +- **Misconfigured** - These machines might partially be reporting sensor data to the Microsoft Defender ATP service and might have configuration errors that need to be corrected. +- **Inactive** - Machines that have stopped reporting to the Microsoft Defender ATP service for more than seven days in the past month. Clicking any of the groups directs you to Machines list, filtered according to your choice. @@ -40,16 +40,16 @@ Clicking any of the groups directs you to Machines list, filtered according to y You can also download the entire list in CSV format using the **Export to CSV** feature. For more information on filters, see [View and organize the Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md). You can filter the health state list by the following status: -- **Active** - Machines that are actively reporting to the Windows Defender ATP service. -- **Misconfigured** - These machines might partially be reporting sensor data to the Windows Defender ATP service but have configuration errors that need to be corrected. Misconfigured machines can have either one or a combination of the following issues: +- **Active** - Machines that are actively reporting to the Microsoft Defender ATP service. +- **Misconfigured** - These machines might partially be reporting sensor data to the Microsoft Defender ATP service but have configuration errors that need to be corrected. Misconfigured machines can have either one or a combination of the following issues: - **No sensor data** - Machines has stopped sending sensor data. Limited alerts can be triggered from the machine. - **Impaired communications** - Ability to communicate with machine is impaired. Sending files for deep analysis, blocking files, isolating machine from network and other actions that require communication with the machine may not work. -- **Inactive** - Machines that have stopped reporting to the Windows Defender ATP service. +- **Inactive** - Machines that have stopped reporting to the Microsoft Defender ATP service. You can view the machine details when you click on a misconfigured or inactive machine. You’ll see more specific machine information when you click the information icon. -![Windows Defender ATP sensor filter](images/atp-machine-health-details.png) +![Microsoft Defender ATP sensor filter](images/atp-machine-health-details.png) In the **Machines list**, you can download a full list of all the machines in your organization in a CSV format. @@ -57,4 +57,4 @@ In the **Machines list**, you can download a full list of all the machines in yo >Export the list in CSV format to display the unfiltered data. The CSV file will include all machines in the organization, regardless of any filtering applied in the view itself and can take a significant amount of time to download, depending on how large your organization is. ## Related topic -- [Fix unhealthy sensors in Windows Defender ATP](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) +- [Fix unhealthy sensors in Microsoft Defender ATP](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md index 70fb7fe34a..133ce6e86c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md +++ b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Collect investigation package API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ Collect investigation package from a machine. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/community.md b/windows/security/threat-protection/microsoft-defender-atp/community.md index 35ed4d4458..a70adba5f5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/community.md +++ b/windows/security/threat-protection/microsoft-defender-atp/community.md @@ -1,6 +1,6 @@ --- -title: Access the Windows Defender ATP Community Center -description: Access the Windows Defender ATP Community Center to share experiences, engange, and learn about the product. +title: Access the Microsoft Defender ATP Community Center +description: Access the Microsoft Defender ATP Community Center to share experiences, engange, and learn about the product. keywords: community, community center, tech community, conversation, announcements search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -19,14 +19,14 @@ ms.date: 04/24/2018 --- -# Access the Windows Defender ATP Community Center +# Access the Microsoft Defender ATP Community Center **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -The Windows Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. +The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. There are several spaces you can explore to learn about specific information: - Announcements @@ -35,8 +35,8 @@ There are several spaces you can explore to learn about specific information: There are several ways you can access the Community Center: -- In the Windows Defender Security Center navigation pane, select **Community center**. A new browser tab opens and takes you to the Windows Defender ATP Tech Community page. -- Access the community through the [Windows Defender Advanced Threat Protection Tech Community](https://techcommunity.microsoft.com/t5/Windows-Defender-Advanced-Threat/ct-p/WindowsDefenderAdvanced) page +- In the Windows Defender Security Center navigation pane, select **Community center**. A new browser tab opens and takes you to the Microsoft Defender ATP Tech Community page. +- Access the community through the [Microsoft Defender Advanced Threat Protection Tech Community](https://techcommunity.microsoft.com/t5/Windows-Defender-Advanced-Threat/ct-p/WindowsDefenderAdvanced) page You can instantly view and read conversations that have been posted in the community. diff --git a/windows/security/threat-protection/microsoft-defender-atp/conditional.md b/windows/security/threat-protection/microsoft-defender-atp/conditional.md index d3dff32b11..eba91e7d07 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/conditional.md +++ b/windows/security/threat-protection/microsoft-defender-atp/conditional.md @@ -20,11 +20,11 @@ ms.topic: article # Enable conditional access to better protect users, devices, and data **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-conditionalaccess-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-conditionalaccess-abovefoldlink) Conditional access is a capability that helps you better protect your users and enterprise information by making sure that only secure devices have access to applications. @@ -32,7 +32,7 @@ With conditional access, you can control access to enterprise information based You can define security conditions under which devices and applications can run and access information from your network by enforcing policies to stop applications from running until a device returns to a compliant state. -The implementation of conditional access in Windows Defender ATP is based on Microsoft Intune (Intune) device compliance policies and Azure Active Directory (Azure AD) conditional access policies. +The implementation of conditional access in Microsoft Defender ATP is based on Microsoft Intune (Intune) device compliance policies and Azure Active Directory (Azure AD) conditional access policies. The compliance policy is used with conditional access to allow only devices that fulfill one or more device compliance policy rules to access applications. @@ -62,15 +62,15 @@ When the risk is removed either through manual or automated remediation, the dev The following example sequence of events explains conditional access in action: -1. A user opens a malicious file and Windows Defender ATP flags the device as high risk. +1. A user opens a malicious file and Microsoft Defender ATP flags the device as high risk. 2. The high risk assessment is passed along to Intune. In parallel, an automated investigation is initiated to remediate the identified threat. A manual remediation can also be done to remediate the identified threat. 3. Based on the policy created in Intune, the device is marked as not compliant. The assessment is then communicated to Azure AD by the Intune conditional access policy. In Azure AD, the corresponding policy is applied to block access to applications. -4. The manual or automated investigation and remediation is completed and the threat is removed. Windows Defender ATP sees that there is no risk on the device and Intune assesses the device to be in a compliant state. Azure AD applies the policy which allows access to applications. +4. The manual or automated investigation and remediation is completed and the threat is removed. Microsoft Defender ATP sees that there is no risk on the device and Intune assesses the device to be in a compliant state. Azure AD applies the policy which allows access to applications. 5. Users can now access applications. ## Related topic -- [Configure conditional access in Windows Defender ATP](configure-conditional-access-windows-defender-advanced-threat-protection.md) +- [Configure conditional access in Microsoft Defender ATP](configure-conditional-access-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md index d418764a45..2b787f64c8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md @@ -1,5 +1,5 @@ --- -title: Configure HP ArcSight to pull Windows Defender ATP alerts +title: Configure HP ArcSight to pull Microsoft Defender ATP alerts description: Configure HP ArcSight to receive and pull alerts from Windows Defender Security Center keywords: configure hp arcsight, security information and events management tools, arcsight search.product: eADQiWindows 10XVcnh @@ -18,25 +18,25 @@ ms.topic: article ms.date: 12/20/2018 --- -# Configure HP ArcSight to pull Windows Defender ATP alerts +# Configure HP ArcSight to pull Microsoft Defender ATP alerts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configurearcsight-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configurearcsight-abovefoldlink) -You'll need to install and configure some files and tools to use HP ArcSight so that it can pull Windows Defender ATP alerts. +You'll need to install and configure some files and tools to use HP ArcSight so that it can pull Microsoft Defender ATP alerts. ## Before you begin Configuring the HP ArcSight Connector tool requires several configuration files for it to pull and parse alerts from your Azure Active Directory (AAD) application. This section guides you in getting the necessary information to set and use the required configuration files correctly. -- Make sure you have enabled the SIEM integration feature from the **Settings** menu. For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +- Make sure you have enabled the SIEM integration feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). - Have the file you saved from enabling the SIEM integration feature ready. You'll need to get the following values: - OAuth 2.0 Token refresh URL @@ -107,7 +107,7 @@ The following steps assume that you have completed all the required steps in [Be Browse to the location of the *wdatp-connector.properties* file. The name must match the file provided in the .zip that you downloaded. Refresh Token - You can obtain a refresh token in two ways: by generating a refresh token from the **SIEM settings** page or using the restutil tool.

For more information on generating a refresh token from the **Preferences setup** , see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md).

**Get your refresh token using the restutil tool:**
a. Open a command prompt. Navigate to C:\\*folder_location*\current\bin where *folder_location* represents the location where you installed the tool.

b. Type: `arcsight restutil token -config` from the bin directory.For example: **arcsight restutil boxtoken -proxy proxy.location.hp.com:8080** A Web browser window will open.

c. Type in your credentials then click on the password field to let the page redirect. In the login prompt, enter your credentials.

d. A refresh token is shown in the command prompt.

e. Copy and paste it into the **Refresh Token** field. + You can obtain a refresh token in two ways: by generating a refresh token from the **SIEM settings** page or using the restutil tool.

For more information on generating a refresh token from the **Preferences setup** , see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md).

**Get your refresh token using the restutil tool:**
a. Open a command prompt. Navigate to C:\\*folder_location*\current\bin where *folder_location* represents the location where you installed the tool.

b. Type: `arcsight restutil token -config` from the bin directory.For example: **arcsight restutil boxtoken -proxy proxy.location.hp.com:8080** A Web browser window will open.

c. Type in your credentials then click on the password field to let the page redirect. In the login prompt, enter your credentials.

d. A refresh token is shown in the command prompt.

e. Copy and paste it into the **Refresh Token** field. @@ -160,11 +160,11 @@ If the `redirect_uri` is a https URL, you'll be redirected to a URL on the local 9. Navigate to **Active channel set** > **New Condition** > **Device** > **Device Product**. -10. Set **Device Product = Windows Defender ATP**. When you've verified that events are flowing to the tool, stop the process again and go to Windows Services and start the ArcSight FlexConnector REST. +10. Set **Device Product = Microsoft Defender ATP**. When you've verified that events are flowing to the tool, stop the process again and go to Windows Services and start the ArcSight FlexConnector REST. You can now run queries in the HP ArcSight console. -Windows Defender ATP alerts will appear as discrete events, with "Microsoft” as the vendor and “Windows Defender ATP” as the device name. +Microsoft Defender ATP alerts will appear as discrete events, with "Microsoft” as the vendor and “Windows Defender ATP” as the device name. ## Troubleshooting HP ArcSight connection @@ -187,7 +187,7 @@ Windows Defender ATP alerts will appear as discrete events, with "Microsoft” a > Verify that the connector is running by stopping the process again. Then start the connector again, and no browser window should appear. ## Related topics -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) - [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md index cd442ff5d6..e599ecf7be 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md @@ -1,5 +1,5 @@ --- -title: Configure conditional access in Windows Defender ATP +title: Configure conditional access in Microsoft Defender ATP description: keywords: search.product: eADQiWindows 10XVcnh @@ -18,9 +18,9 @@ ms.topic: article ms.date: 09/03/2018 --- -# Configure conditional access in Windows Defender ATP +# Configure conditional access in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This section guides you through all the steps you need to take to properly implement conditional access. @@ -45,7 +45,7 @@ There are steps you'll need to take in Windows Defender Security Center, the Int Take the following steps to enable conditional access: - Step 1: Turn on the Microsoft Intune connection from Windows Defender Security Center -- Step 2: Turn on the Windows Defender ATP integration in Intune +- Step 2: Turn on the Microsoft Defender ATP integration in Intune - Step 3: Create the compliance policy in Intune - Step 4: Assign the policy - Step 5: Create an Azure AD conditional access policy @@ -57,10 +57,10 @@ Take the following steps to enable conditional access: 3. Click **Save preferences**. -### Step 2: Turn on the Windows Defender ATP integration in Intune +### Step 2: Turn on the Microsoft Defender ATP integration in Intune 1. Sign in to the [Azure portal](https://portal.azure.com). -2. Select **Device compliance** > **Windows Defender ATP**. -3. Set **Connect Windows 10.0.15063+ devices to Windows Defender Advanced Threat Protection** to **On**. +2. Select **Device compliance** > **Microsoft Defender ATP**. +3. Set **Connect Windows 10.0.15063+ devices to Microsoft Defender Advanced Threat Protection** to **On**. 4. Click **Save**. @@ -80,7 +80,7 @@ Take the following steps to enable conditional access: ### Step 4: Assign the policy 1. In the [Azure portal](https://portal.azure.com), select **All services**, filter on **Intune**, and select **Microsoft Intune**. -2. Select **Device compliance** > **Policies**> select your Windows Defender ATP compliance policy. +2. Select **Device compliance** > **Policies**> select your Microsoft Defender ATP compliance policy. 3. Select **Assignments**. 4. Include or exclude your Azure AD groups to assign them the policy. 5. To deploy the policy to the groups, select **Save**. The user devices targeted by the policy are evaluated for compliance. @@ -96,6 +96,6 @@ Take the following steps to enable conditional access: 6. Select **Enable policy**, and then **Create** to save your changes. -For more information, see [Enable Windows Defender ATP with conditional access in Intune](https://docs.microsoft.com/intune/advanced-threat-protection). +For more information, see [Enable Microsoft Defender ATP with conditional access in Intune](https://docs.microsoft.com/intune/advanced-threat-protection). ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-conditionalaccess-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-conditionalaccess-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md index 2d843ca2bd..5352b16859 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md @@ -1,6 +1,6 @@ --- -title: Configure alert notifications in Windows Defender ATP -description: Send email notifications to specified recipients to receive new alerts based on severity with Windows Defender ATP on Windows 10 Enterprise, Pro, and Education editions. +title: Configure alert notifications in Microsoft Defender ATP +description: Send email notifications to specified recipients to receive new alerts based on severity with Microsoft Defender ATP on Windows 10 Enterprise, Pro, and Education editions. keywords: email notifications, configure alert notifications, windows defender atp notifications, windows defender atp alerts, windows 10 enterprise, windows 10 education search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,15 +18,15 @@ ms.topic: article ms.date: 10/08/2018 --- -# Configure alert notifications in Windows Defender ATP +# Configure alert notifications in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-emailconfig-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-emailconfig-abovefoldlink) -You can configure Windows Defender ATP to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity. +You can configure Microsoft Defender ATP to send email notifications to specified recipients for new alerts. This feature enables you to identify a group of individuals who will immediately be informed and can act on alerts based on their severity. > [!NOTE] > Only users with 'Manage security settings' permissions can configure email notifications. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications. @@ -55,7 +55,7 @@ You can create rules that determine the machines and alert severities to send em - **Include machine information** - Includes the machine name in the email alert body. >[!NOTE] - > This information might be processed by recipient mail servers that ar not in the geographic location you have selected for your Windows Defender ATP data. + > This information might be processed by recipient mail servers that ar not in the geographic location you have selected for your Microsoft Defender ATP data. - **Machines** - Choose whether to notify recipients for alerts on all machines (Global administrator role only) or on selected machine groups. For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). - **Alert severity** - Choose the alert severity level. @@ -94,12 +94,12 @@ This section lists various issues that you may encounter when using email notifi **Solution:** Make sure that the notifications are not blocked by email filters: -1. Check that the Windows Defender ATP email notifications are not sent to the Junk Email folder. Mark them as Not junk. -2. Check that your email security product is not blocking the email notifications from Windows Defender ATP. -3. Check your email application rules that might be catching and moving your Windows Defender ATP email notifications. +1. Check that the Microsoft Defender ATP email notifications are not sent to the Junk Email folder. Mark them as Not junk. +2. Check that your email security product is not blocking the email notifications from Microsoft Defender ATP. +3. Check your email application rules that might be catching and moving your Microsoft Defender ATP email notifications. ## Related topics - [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) - [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) - [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md index a2e8e2a9d2..24f3338a41 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md @@ -1,7 +1,7 @@ --- -title: Onboard Windows 10 machines using Group Policy to Windows Defender ATP +title: Onboard Windows 10 machines using Group Policy to Microsoft Defender ATP description: Use Group Policy to deploy the configuration package on Windows 10 machines so that they are onboarded to the service. -keywords: configure machines using group policy, machine management, configure Windows ATP machines, onboard Windows Defender Advanced Threat Protection machines, group policy +keywords: configure machines using group policy, machine management, configure Windows ATP machines, onboard Microsoft Defender Advanced Threat Protection machines, group policy search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -24,12 +24,12 @@ ms.date: 04/24/2018 - Group Policy -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsgp-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsgp-abovefoldlink) > [!NOTE] @@ -63,9 +63,9 @@ ms.date: 04/24/2018 9. Click **OK** and close any open GPMC windows. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that the machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that the machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). -## Additional Windows Defender ATP configuration settings +## Additional Microsoft Defender ATP configuration settings For each machine, you can state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. You can use Group Policy (GP) to configure settings, such as settings for the sample sharing used in the deep analysis feature. @@ -84,7 +84,7 @@ You can use Group Policy (GP) to configure settings, such as settings for the sa 4. Click **Policies**, then **Administrative templates**. -5. Click **Windows components** and then **Windows Defender ATP**. +5. Click **Windows components** and then **Microsoft Defender ATP**. 6. Choose to enable or disable sample sharing from your machines. @@ -145,5 +145,5 @@ With Group Policy there isn’t an option to monitor deployment of policies on t - [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) - [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Windows Defender ATP machines](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machines](run-detection-test-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md index 57ba954930..79a5287504 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md @@ -1,7 +1,7 @@ --- title: Onboard Windows 10 machines using Mobile Device Management tools description: Use Mobile Device Management tools to deploy the configuration package on machines so that they are onboarded to the service. -keywords: onboard machines using mdm, machine management, onboard Windows ATP machines, onboard Windows Defender Advanced Threat Protection machines, mdm +keywords: onboard machines using mdm, machine management, onboard Windows ATP machines, onboard Microsoft Defender Advanced Threat Protection machines, mdm search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -23,13 +23,13 @@ ms.date: 12/06/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsmdm-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsmdm-abovefoldlink) -You can use mobile device management (MDM) solutions to configure machines. Windows Defender ATP supports MDMs by providing OMA-URIs to create policies to manage machines. +You can use mobile device management (MDM) solutions to configure machines. Microsoft Defender ATP supports MDMs by providing OMA-URIs to create policies to manage machines. -For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx). +For more information on using Microsoft Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx). ## Before you begin If you're using Microsoft Intune, you must have the device MDM Enrolled. Otherwise, settings will not be applied successfully. @@ -40,7 +40,7 @@ For more information on enabling MDM with Microsoft Intune, see [Setup Windows D Follow the instructions from [Intune](https://docs.microsoft.com/intune/advanced-threat-protection). -For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx). +For more information on using Microsoft Defender ATP CSP see, [WindowsAdvancedThreatProtection CSP](https://msdn.microsoft.com/library/windows/hardware/mt723296(v=vs.85).aspx) and [WindowsAdvancedThreatProtection DDF file](https://msdn.microsoft.com/library/windows/hardware/mt723297(v=vs.85).aspx). > [!NOTE] @@ -49,7 +49,7 @@ For more information on using Windows Defender ATP CSP see, [WindowsAdvancedThre >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that a machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that a machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). ## Offboard and monitor machines using Mobile Device Management tools For security reasons, the package used to Offboard machines will expire 30 days after the date it was downloaded. Expired offboarding packages sent to a machine will be rejected. When downloading an offboarding package you will be notified of the packages expiry date and it will also be included in the package name. @@ -83,5 +83,5 @@ For security reasons, the package used to Offboard machines will expire 30 days - [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) - [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md index de556b2903..f431da0f01 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md @@ -1,7 +1,7 @@ --- -title: Onboard non-Windows machines to the Windows Defender ATP service -description: Configure non-Winodws machines so that they can send sensor data to the Windows Defender ATP service. -keywords: onboard non-Windows machines, macos, linux, machine management, configure Windows ATP machines, configure Windows Defender Advanced Threat Protection machines +title: Onboard non-Windows machines to the Microsoft Defender ATP service +description: Configure non-Winodws machines so that they can send sensor data to the Microsoft Defender ATP service. +keywords: onboard non-Windows machines, macos, linux, machine management, configure Windows ATP machines, configure Microsoft Defender Advanced Threat Protection machines search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -22,15 +22,15 @@ ms.topic: article - macOS - Linux -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-nonwindows-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-nonwindows-abovefoldlink) -Windows Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products’ sensor data. +Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products’ sensor data. -You'll need to know the exact Linux distros and macOS versions that are compatible with Windows Defender ATP for the integration to work. +You'll need to know the exact Linux distros and macOS versions that are compatible with Microsoft Defender ATP for the integration to work. You'll need to take the following steps to onboard non-Windows machines: 1. Turn on third-party integration @@ -55,7 +55,7 @@ You'll need to take the following steps to onboard non-Windows machines: ### Run detection test Create an EICAR test file by saving the string displayed on the portal in an empty text file. Then, introduce the test file to a machine running the third-party antivirus solution. -The file should trigger a detection and a corresponding alert on Windows Defender ATP. +The file should trigger a detection and a corresponding alert on Microsoft Defender ATP. ## Offboard non-Windows machines To effectively offboard the machine from the service, you'll need to disable the data push on the third-party portal first then switch the toggle to off in Windows Defender Security Center. The toggle in the portal only blocks the data inbound flow. @@ -74,4 +74,4 @@ To effectively offboard the machine from the service, you'll need to disable the - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) - [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) - [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Troubleshooting Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md index 4d6b519e13..8a91ad835d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md @@ -1,7 +1,7 @@ --- title: Onboard Windows 10 machines using System Center Configuration Manager description: Use System Center Configuration Manager to deploy the configuration package on machines so that they are onboarded to the service. -keywords: onboard machines using sccm, machine management, configure Windows ATP machines, configure Windows Defender Advanced Threat Protection machines, sccm +keywords: onboard machines using sccm, machine management, configure Windows ATP machines, configure Microsoft Defender Advanced Threat Protection machines, sccm search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -23,16 +23,16 @@ ms.date: 12/11/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - System Center 2012 Configuration Manager or later versions ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointssccm-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointssccm-abovefoldlink) ## Onboard Windows 10 machines using System Center Configuration Manager (current branch) version 1606 -System Center Configuration Manager (SCCM) (current branch) version 1606, has UI integrated support for configuring and managing Windows Defender ATP on machines. For more information, see [Support for Windows Defender Advanced Threat Protection service](https://go.microsoft.com/fwlink/p/?linkid=823682). +System Center Configuration Manager (SCCM) (current branch) version 1606, has UI integrated support for configuring and managing Microsoft Defender ATP on machines. For more information, see [Support for Microsoft Defender Advanced Threat Protection service](https://go.microsoft.com/fwlink/p/?linkid=823682). >[!NOTE] > If you’re using SCCM client version 1606 with server version 1610 or above, you must upgrade the client version to match the server version. @@ -66,10 +66,10 @@ You can use existing System Center Configuration Manager functionality to create a. Choose a predefined device collection to deploy the package to. > [!NOTE] -> Windows Defender ATP doesn't support onboarding during the [Out-Of-Box Experience (OOBE)](https://answers.microsoft.com/en-us/windows/wiki/windows_10/how-to-complete-the-windows-10-out-of-box/47e3f943-f000-45e3-8c5c-9d85a1a0cf87) phase. Make sure users complete OOBE after running Windows installation or upgrading. +> Microsoft Defender ATP doesn't support onboarding during the [Out-Of-Box Experience (OOBE)](https://answers.microsoft.com/en-us/windows/wiki/windows_10/how-to-complete-the-windows-10-out-of-box/47e3f943-f000-45e3-8c5c-9d85a1a0cf87) phase. Make sure users complete OOBE after running Windows installation or upgrading. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). ### Configure sample collection settings For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. @@ -128,7 +128,7 @@ Monitoring with SCCM consists of two parts: 1. Confirming the configuration package has been correctly deployed and is running (or has successfully run) on the machines in your network. -2. Checking that the machines are compliant with the Windows Defender ATP service (this ensures the machine can complete the onboarding process and can continue to report data to the service). +2. Checking that the machines are compliant with the Microsoft Defender ATP service (this ensures the machine can complete the onboarding process and can continue to report data to the service). **To confirm the configuration package has been correctly deployed:** @@ -140,11 +140,11 @@ Monitoring with SCCM consists of two parts: 4. Review the status indicators under **Completion Statistics** and **Content Status**. -If there are failed deployments (machines with **Error**, **Requirements Not Met**, or **Failed statuses**), you may need to troubleshoot the machines. For more information see, [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). +If there are failed deployments (machines with **Error**, **Requirements Not Met**, or **Failed statuses**), you may need to troubleshoot the machines. For more information see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). ![SCCM showing successful deployment with no errors](images/sccm-deployment.png) -**Check that the machines are compliant with the Windows Defender ATP service:**
+**Check that the machines are compliant with the Microsoft Defender ATP service:**
You can set a compliance rule for configuration item in System Center Configuration Manager to monitor your deployment. This rule should be a *non-remediating* compliance rule configuration item that monitors the value of a registry key on targeted machines. @@ -162,5 +162,5 @@ For more information about System Center Configuration Manager Compliance see [G - [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) - [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md index fee63e07dd..9b0d319050 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md @@ -1,7 +1,7 @@ --- title: Onboard Windows 10 machines using a local script description: Use a local script to deploy the configuration package on machines so that they are onboarded to the service. -keywords: configure machines using a local script, machine management, configure Windows ATP machines, configure Windows Defender Advanced Threat Protection machines +keywords: configure machines using a local script, machine management, configure Windows ATP machines, configure Microsoft Defender Advanced Threat Protection machines search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -22,14 +22,14 @@ ms.topic: article **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsscript-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsscript-abovefoldlink) -You can also manually onboard individual machines to Windows Defender ATP. You might want to do this first when testing the service before you commit to onboarding all machines in your network. +You can also manually onboard individual machines to Microsoft Defender ATP. You might want to do this first when testing the service before you commit to onboarding all machines in your network. > [!NOTE] > The script has been optimized to be used on a limited number of machines (1-10 machines). To deploy to scale, use other deployment options. For more information on using other deployment options, see [Onboard Window 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). @@ -60,11 +60,11 @@ You can also manually onboard individual machines to Windows Defender ATP. You m 5. Press the **Enter** key or click **OK**. -For information on how you can manually validate that the machine is compliant and correctly reports sensor data see, [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). +For information on how you can manually validate that the machine is compliant and correctly reports sensor data see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). ## Configure sample collection settings For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. @@ -139,5 +139,5 @@ Monitoring can also be done directly on the portal, or by using the different de - [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) - [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md index 8ee8615f84..be05604d0b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md @@ -1,7 +1,7 @@ --- title: Onboard non-persistent virtual desktop infrastructure (VDI) machines -description: Deploy the configuration package on virtual desktop infrastructure (VDI) machine so that they are onboarded to Windows Defender ATP the service. -keywords: configure virtual desktop infrastructure (VDI) machine, vdi, machine management, configure Windows ATP endpoints, configure Windows Defender Advanced Threat Protection endpoints +description: Deploy the configuration package on virtual desktop infrastructure (VDI) machine so that they are onboarded to Microsoft Defender ATP the service. +keywords: configure virtual desktop infrastructure (VDI) machine, vdi, machine management, configure Windows ATP endpoints, configure Microsoft Defender Advanced Threat Protection endpoints search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -25,15 +25,15 @@ ms.date: 04/24/2018 ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configvdi-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configvdi-abovefoldlink) ## Onboard non-persistent virtual desktop infrastructure (VDI) machines -Windows Defender ATP supports non-persistent VDI session onboarding. There might be associated challenges when onboarding VDIs. The following are typical challenges for this scenario: +Microsoft Defender ATP supports non-persistent VDI session onboarding. There might be associated challenges when onboarding VDIs. The following are typical challenges for this scenario: - Instant early onboarding of a short living session - - A session should be onboarded to Windows Defender ATP prior to the actual provisioning. + - A session should be onboarded to Microsoft Defender ATP prior to the actual provisioning. - Machine name persistence - The machine names are typically reused for new sessions. One may ask to have them as a single machine entry while others may prefer to have multiple entries per machine name. @@ -41,7 +41,7 @@ Windows Defender ATP supports non-persistent VDI session onboarding. There might You can onboard VDI machines using a single entry or multiple entries for each machine. The following steps will guide you through onboarding VDI machines and will highlight steps for single and multiple entries. >[!WARNING] -> For environments where there are low resource configurations, the VDI boot proceedure might slow the Windows Defender ATP sensor onboarding. +> For environments where there are low resource configurations, the VDI boot proceedure might slow the Microsoft Defender ATP sensor onboarding. 1. Open the VDI configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Windows Defender Security Center](https://securitycenter.windows.com/): @@ -95,6 +95,6 @@ You can onboard VDI machines using a single entry or multiple entries for each m - [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) - [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md index dc4a53e6ea..69ddf03031 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md @@ -1,6 +1,6 @@ --- -title: Onboard Windows 10 machines on Windows Defender ATP -description: Onboard Windows 10 machines so that they can send sensor data to the Windows Defender ATP sensor +title: Onboard Windows 10 machines on Microsoft Defender ATP +description: Onboard Windows 10 machines so that they can send sensor data to the Microsoft Defender ATP sensor keywords: Onboard Windows 10 machines, group policy, system center configuration manager, mobile device management, local script, gp, sccm, mdm, intune search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,11 +23,11 @@ ms.date: 07/12/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Machines in your organization must be configured so that the Windows Defender ATP service can get sensor data from them. There are various methods and deployment tools that you can use to configure the machines in your organization. +Machines in your organization must be configured so that the Microsoft Defender ATP service can get sensor data from them. There are various methods and deployment tools that you can use to configure the machines in your organization. The following deployment tools and methods are supported: @@ -46,4 +46,4 @@ Topic | Description [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) | Learn how to use the configuration package to configure VDI machines. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpoints-belowfoldlink) \ No newline at end of file +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpoints-belowfoldlink) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md index 8e6edc791b..0f0180a75a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md @@ -21,18 +21,18 @@ ms.date: 02/28/2019 # Configure and manage Microsoft Threat Experts capabilities **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease�information](prerelease.md)] ## Before you begin -To experience the full Microsoft Threat Experts preview capability in Windows Defender ATP, you need to have a valid Premier customer service and support account. However, Premier charges will not be incurred during the preview. +To experience the full Microsoft Threat Experts preview capability in Microsoft Defender ATP, you need to have a valid Premier customer service and support account. However, Premier charges will not be incurred during the preview. -You also need to ensure that you have Windows Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. +You also need to ensure that you have Microsoft Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. ## Register to Microsoft Threat Experts preview -If you're already a Windows Defender ATP customer, you can apply for preview through the Windows Defender ATP portal. +If you're already a Microsoft Defender ATP customer, you can apply for preview through the Microsoft Defender ATP portal. 1. From the navigation pane, go to **Settings > General > Advanced features > Threat Experts**. @@ -50,7 +50,7 @@ If you're already a Windows Defender ATP customer, you can apply for preview thr ## Receive targeted attack notification from Microsoft Threat Experts You can receive targeted attack notification from Microsoft Threat Experts through the following: -- The Windows Defender ATP portal's **Alerts** dashboard +- The Microsoft Defender ATP portal's **Alerts** dashboard - Your email, if you choose to configure it To receive targeted attack notifications through email, you need to create an email notification rule. @@ -83,13 +83,13 @@ You can partner with Microsoft Threat Experts who can be engaged directly from w **Step 2: Open a support ticket** >[!NOTE] - >To experience the full Microsoft Threat Experts preview capability in Windows Defender ATP, you need to have a Premier customer service and support account. However, you will not be charged for the Experts-on-demand service during the preview. + >To experience the full Microsoft Threat Experts preview capability in Microsoft Defender ATP, you need to have a Premier customer service and support account. However, you will not be charged for the Experts-on-demand service during the preview. a. In the **New support request** customer support page, select the following from the dropdown menu and then click **Next**:
**Select the product family**: **Security**
**Select a product**: **Microsoft Threat Experts**
- **Select a category that best describes the issue**: **Windows Defender ATP**
+ **Select a category that best describes the issue**: **Microsoft Defender ATP**
**Select a problem that best describes the issue**: Choose according to your inquiry category
b. Fill out the fields with the necessary information about the issue and use the auto-generated ID when you open a Customer Services and Support (CSS) ticket. Then, click **Next**.
diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md index 738c8f0548..3dd2f86f1f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md @@ -1,6 +1,6 @@ --- title: Configure managed security service provider support -description: Take the necessary steps to configure the MSSP integration with Windows Defender ATP +description: Take the necessary steps to configure the MSSP integration with Microsoft Defender ATP keywords: managed security service provider, mssp, configure, integration search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,9 +21,9 @@ ms.date: 09/03/2018 # Configure managed security service provider integration **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mssp-support-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mssp-support-abovefoldlink) [!include[Prerelease information](prerelease.md)] @@ -39,7 +39,7 @@ The integration will allow MSSPs to take the following actions: - Get email notifications, and - Fetch alerts through security information and event management (SIEM) tools -Before MSSPs can take these actions, the MSSP customer will need to grant access to their Windows Defender ATP tenant so that the MSSP can access the portal. +Before MSSPs can take these actions, the MSSP customer will need to grant access to their Microsoft Defender ATP tenant so that the MSSP can access the portal. Typically, MSSP customers take the initial configuration steps to grant MSSPs access to their Windows Defender Security Central tenant. After access is granted, other configuration steps can be done by either the MSSP customer or the MSSP. @@ -47,7 +47,7 @@ Typically, MSSP customers take the initial configuration steps to grant MSSPs ac In general, the following configuration steps need to be taken: - **Grant the MSSP access to Windows Defender Security Center**
-This action needs to be done by the MSSP customer. It grants the MSSP access to the MSSP customer's Windows Defender ATP tenant. +This action needs to be done by the MSSP customer. It grants the MSSP access to the MSSP customer's Microsoft Defender ATP tenant. - **Configure alert notifications sent to MSSPs**
This action can be taken by either the MSSP customer or MSSP. This lets the MSSPs know what alerts they need to address for the MSSP customer. @@ -85,7 +85,7 @@ Granting access to guest user is done the same way as granting access to a user If you're using basic permissions to access the portal, the guest user must be assigned a Security Administrator role in **your** tenant. For more information, see [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md). -If you're using role-based access control (RBAC), the guest user must be to added to the appropriate group or groups in **your** tenant. Fore more information on RBAC in Windows Defender ATP, see [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md). +If you're using role-based access control (RBAC), the guest user must be to added to the appropriate group or groups in **your** tenant. Fore more information on RBAC in Microsoft Defender ATP, see [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md). >[!NOTE] >There is no difference between the Member user and Guest user roles from RBAC perspective. @@ -147,7 +147,7 @@ Step 3: Whitelist your application on Windows Defender Security Center ### Step 1: Create an application in Azure Active Directory (Azure AD) -You'll need to create an application and grant it permissions to fetch alerts from your customer's Windows Defender ATP tenant. +You'll need to create an application and grant it permissions to fetch alerts from your customer's Microsoft Defender ATP tenant. 1. Sign in to the [Azure AD portal](https://aad.portal.azure.com/). @@ -272,7 +272,7 @@ You'll need to have **Manage portal system settings** permission to whitelist th 5. Click **Authorize application**. -You can now download the relevant configuration file for your SIEM and connect to the Windows Defender ATP API. For more information see, [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md). +You can now download the relevant configuration file for your SIEM and connect to the Microsoft Defender ATP API. For more information see, [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md). - In the ArcSight configuration file / Splunk Authentication Properties file – you will have to write your application key manually by settings the secret value. - Instead of acquiring a refresh token in the portal, use the script from the previous step to acquire a refresh token (or acquire it by other means). diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md index 595b8af148..bc9f3d4a50 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md @@ -1,6 +1,6 @@ --- title: Configure machine proxy and Internet connection settings -description: Configure the Windows Defender ATP proxy and internet settings to enable communication with the cloud service. +description: Configure the Microsoft Defender ATP proxy and internet settings to enable communication with the cloud service. keywords: configure, proxy, internet, internet connectivity, settings, proxy settings, netsh, winhttp, proxy server search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,15 +21,15 @@ ms.topic: article # Configure machine proxy and Internet connectivity settings **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsscript-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpointsscript-abovefoldlink) -The Windows Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. +The Microsoft Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -The embedded Windows Defender ATP sensor runs in system context using the LocalSystem account. The sensor uses Microsoft Windows HTTP Services (WinHTTP) to enable communication with the Windows Defender ATP cloud service. +The embedded Microsoft Defender ATP sensor runs in system context using the LocalSystem account. The sensor uses Microsoft Windows HTTP Services (WinHTTP) to enable communication with the Microsoft Defender ATP cloud service. The WinHTTP configuration setting is independent of the Windows Internet (WinINet) internet browsing proxy settings and can only discover a proxy server by using the following discovery methods: @@ -38,7 +38,7 @@ The WinHTTP configuration setting is independent of the Windows Internet (WinINe - Web Proxy Auto-discovery Protocol (WPAD) > [!NOTE] -> If you're using Transparent proxy or WPAD in your network topology, you don't need special configuration settings. For more information on Windows Defender ATP URL exclusions in the proxy, see [Enable access to Windows Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). +> If you're using Transparent proxy or WPAD in your network topology, you don't need special configuration settings. For more information on Microsoft Defender ATP URL exclusions in the proxy, see [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). - Manual static proxy configuration: @@ -46,7 +46,7 @@ The WinHTTP configuration setting is independent of the Windows Internet (WinINe - WinHTTP configured using netsh command – Suitable only for desktops in a stable topology (for example: a desktop in a corporate network behind the same proxy) ## Configure the proxy server manually using a registry-based static proxy -Configure a registry-based static proxy to allow only Windows Defender ATP sensor to report diagnostic data and communicate with Windows Defender ATP services if a computer is not be permitted to connect to the Internet. +Configure a registry-based static proxy to allow only Microsoft Defender ATP sensor to report diagnostic data and communicate with Microsoft Defender ATP services if a computer is not be permitted to connect to the Internet. The static proxy is configurable through Group Policy (GP). The group policy can be found under: - Administrative Templates > Windows Components > Data Collection and Preview Builds > Configure Authenticated Proxy usage for the Connected User Experience and Telemetry Service @@ -87,8 +87,8 @@ netsh winhttp set proxy : ``` For example: netsh winhttp set proxy 10.0.0.6:8080 -## Enable access to Windows Defender ATP service URLs in the proxy server -If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are not blocked by default. Do not disable security monitoring or inspection of these URLs, but allow them as you would other internet traffic. They permit communication with Windows Defender ATP service in port 80 and 443: +## Enable access to Microsoft Defender ATP service URLs in the proxy server +If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are not blocked by default. Do not disable security monitoring or inspection of these URLs, but allow them as you would other internet traffic. They permit communication with Microsoft Defender ATP service in port 80 and 443: >[!NOTE] > URLs that include v20 in them are only needed if you have Windows 10, version 1803 or later machines. For example, ```us-v20.events.data.microsoft.com``` is only needed if the machine is on Windows 10, version 1803 or later. @@ -102,12 +102,12 @@ United States | ```us.vortex-win.data.microsoft.com```
```us-v20.events.data -If a proxy or firewall is blocking anonymous traffic, as Windows Defender ATP sensor is connecting from system context, make sure anonymous traffic is permitted in the previously listed URLs. +If a proxy or firewall is blocking anonymous traffic, as Microsoft Defender ATP sensor is connecting from system context, make sure anonymous traffic is permitted in the previously listed URLs. -## Windows Defender ATP service backend IP range +## Microsoft Defender ATP service backend IP range If you network devices don't support the URLs white-listed in the prior section, you can use the following information. -Windows Defender ATP is built on Azure cloud, deployed in the following regions: +Microsoft Defender ATP is built on Azure cloud, deployed in the following regions: - \+\ - \+\ @@ -124,11 +124,11 @@ You can find the Azure IP range on [Microsoft Azure Datacenter IP Ranges](https: > As a cloud-based solution, the IP range can change. It's recommended you move to DNS resolving setting. -## Verify client connectivity to Windows Defender ATP service URLs +## Verify client connectivity to Microsoft Defender ATP service URLs -Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Windows Defender ATP service URLs. +Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. -1. Download the [connectivity verification tool](https://go.microsoft.com/fwlink/p/?linkid=823683) to the PC where Windows Defender ATP sensor is running on. +1. Download the [connectivity verification tool](https://go.microsoft.com/fwlink/p/?linkid=823683) to the PC where Microsoft Defender ATP sensor is running on. 2. Extract the contents of WDATPConnectivityAnalyzer on the machine. @@ -151,7 +151,7 @@ Verify the proxy configuration completed successfully, that WinHTTP can discover 5. Extract the *WDATPConnectivityAnalyzerResult.zip* file created by tool in the folder used in the *HardDrivePath*. 6. Open *WDATPConnectivityAnalyzer.txt* and verify that you have performed the proxy configuration steps to enable server discovery and access to the service URLs.

-The tool checks the connectivity of Windows Defender ATP service URLs that Windows Defender ATP client is configured to interact with. It then prints the results into the *WDATPConnectivityAnalyzer.txt* file for each URL that can potentially be used to communicate with the Windows Defender ATP services. For example: +The tool checks the connectivity of Microsoft Defender ATP service URLs that Microsoft Defender ATP client is configured to interact with. It then prints the results into the *WDATPConnectivityAnalyzer.txt* file for each URL that can potentially be used to communicate with the Microsoft Defender ATP services. For example: ```text Testing URL : https://xxx.microsoft.com/xxx 1 - Default proxy: Succeeded (200) @@ -161,13 +161,13 @@ The tool checks the connectivity of Windows Defender ATP service URLs that Windo 5 - Command line proxy: Doesn't exist ``` -If at least one of the connectivity options returns a (200) status, then the Windows Defender ATP client can communicate with the tested URL properly using this connectivity method.

+If at least one of the connectivity options returns a (200) status, then the Microsoft Defender ATP client can communicate with the tested URL properly using this connectivity method.

-However, if the connectivity check results indicate a failure, an HTTP error is displayed (see HTTP Status Codes). You can then use the URLs in the table shown in [Enable access to Windows Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). The URLs you'll use will depend on the region selected during the onboarding procedure. +However, if the connectivity check results indicate a failure, an HTTP error is displayed (see HTTP Status Codes). You can then use the URLs in the table shown in [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). The URLs you'll use will depend on the region selected during the onboarding procedure. > [!NOTE] -> When the TelemetryProxyServer is set, in Registry or via Group Policy, Windows Defender ATP will fall back to direct if it can't access the defined proxy. +> When the TelemetryProxyServer is set, in Registry or via Group Policy, Microsoft Defender ATP will fall back to direct if it can't access the defined proxy. ## Related topics - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md index 03df5ce551..b247126bb2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md @@ -1,7 +1,7 @@ --- -title: Onboard servers to the Windows Defender ATP service -description: Onboard servers so that they can send sensor data to the Windows Defender ATP sensor. -keywords: onboard server, server, 2012r2, 2016, 2019, server onboarding, machine management, configure Windows ATP servers, onboard Windows Defender Advanced Threat Protection servers +title: Onboard servers to the Microsoft Defender ATP service +description: Onboard servers so that they can send sensor data to the Microsoft Defender ATP sensor. +keywords: onboard server, server, 2012r2, 2016, 2019, server onboarding, machine management, configure Windows ATP servers, onboard Microsoft Defender Advanced Threat Protection servers search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -16,7 +16,7 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Onboard servers to the Windows Defender ATP service +# Onboard servers to the Microsoft Defender ATP service **Applies to:** @@ -24,14 +24,14 @@ ms.topic: article - Windows Server 2016 - Windows Server, version 1803 - Windows Server, 2019 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configserver-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configserver-abovefoldlink) -Windows Defender ATP extends support to also include the Windows Server operating system, providing advanced attack detection and investigation capabilities, seamlessly through the Windows Defender Security Center console. +Microsoft Defender ATP extends support to also include the Windows Server operating system, providing advanced attack detection and investigation capabilities, seamlessly through the Windows Defender Security Center console. The service supports the onboarding of the following servers: - Windows Server 2012 R2 @@ -40,11 +40,11 @@ The service supports the onboarding of the following servers: - Windows Server 2019 -For a practical guidance on what needs to be in place for licensing and infrastructure, see [Protecting Windows Servers with Windows Defender ATP](https://techcommunity.microsoft.com/t5/What-s-New/Protecting-Windows-Server-with-Windows-Defender-ATP/m-p/267114#M128). +For a practical guidance on what needs to be in place for licensing and infrastructure, see [Protecting Windows Servers with Microsoft Defender ATP](https://techcommunity.microsoft.com/t5/What-s-New/Protecting-Windows-Server-with-Windows-Defender-ATP/m-p/267114#M128). ## Windows Server 2012 R2 and Windows Server 2016 -There are two options to onboard Windows Server 2012 R2 and Windows Server 2016 to Windows Defender ATP: +There are two options to onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP: - **Option 1**: Onboard through Azure Security Center - **Option 2**: Onboard through Windows Defender Security Center @@ -56,7 +56,7 @@ There are two options to onboard Windows Server 2012 R2 and Windows Server 2016 3. Click **Onboard Servers in Azure Security Center**. -4. Follow the onboarding instructions in [Windows Defender Advanced Threat Protection with Azure Security Center](https://docs.microsoft.com/azure/security-center/security-center-wdatp). +4. Follow the onboarding instructions in [Microsoft Defender Advanced Threat Protection with Azure Security Center](https://docs.microsoft.com/azure/security-center/security-center-wdatp). ### Option 2: Onboard servers through Windows Defender Security Center You'll need to tak the following steps if you choose to onboard servers through Windows Defender Security Center. @@ -67,16 +67,16 @@ You'll need to tak the following steps if you choose to onboard servers through >This step is required only if your organization uses System Center Endpoint Protection (SCEP) and you're onboarding Windows Server 2012 R2. - Turn on server monitoring from Windows Defender Security Center. -- If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), simply attach the Microsoft Monitoring Agent (MMA) to report to your Windows Defender ATP workspace through Multi Homing support. Otherwise, install and configure MMA to report sensor data to Windows Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent). +- If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), simply attach the Microsoft Monitoring Agent (MMA) to report to your Microsoft Defender ATP workspace through Multi Homing support. Otherwise, install and configure MMA to report sensor data to Microsoft Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent). >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). ### Configure and update System Center Endpoint Protection clients >[!IMPORTANT] >This step is required only if your organization uses System Center Endpoint Protection (SCEP) and you're onboarding Windows Server 2012 R2. -Windows Defender ATP integrates with System Center Endpoint Protection to provide visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware. +Microsoft Defender ATP integrates with System Center Endpoint Protection to provide visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware. The following steps are required to enable this integration: - Install the [January 2017 anti-malware platform update for Endpoint Protection clients](https://support.microsoft.com/help/3209361/january-2017-anti-malware-platform-update-for-endpoint-protection-clie) @@ -92,7 +92,7 @@ The following steps are required to enable this integration: 3. Click **Turn on server monitoring** and confirm that you'd like to proceed with the environment set up. When the set up completes, the **Workspace ID** and **Workspace key** fields are populated with unique values. You'll need to use these values to configure the MMA agent. -### Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Windows Defender ATP +### Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP 1. Download the agent setup file: [Windows 64-bit agent](https://go.microsoft.com/fwlink/?LinkId=828603). @@ -109,7 +109,7 @@ Once completed, you should see onboarded servers in the portal within an hour. ### Configure server proxy and Internet connectivity settings - Each Windows server must be able to connect to the Internet using HTTPS. This connection can be direct, using a proxy, or through the [OMS Gateway](https://docs.microsoft.com/azure/log-analytics/log-analytics-oms-gateway). -- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are white-listed to permit communication with Windows Defender ATP service: +- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are white-listed to permit communication with Microsoft Defender ATP service: Agent Resource | Ports :---|:--- @@ -137,7 +137,7 @@ Supported tools include: For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). Support for Windows Server, version 1803 and Windows 2019 provides deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well. -1. Configure Windows Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). +1. Configure Microsoft Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). 2. If you’re running a third party antimalware solution, you'll need to apply the following Windows Defender AV passive mode settings and verify it was configured correctly: @@ -162,23 +162,23 @@ Supported tools include: ## Integration with Azure Security Center -Windows Defender ATP integrates with Azure Security Center to provide a comprehensive server protection solution. With this integration Azure Security Center can leverage the power of Windows Defender ATP to provide improved threat detection for Windows Servers. +Microsoft Defender ATP integrates with Azure Security Center to provide a comprehensive server protection solution. With this integration Azure Security Center can leverage the power of Microsoft Defender ATP to provide improved threat detection for Windows Servers. >[!NOTE] >You'll need to have the appropriate license to enable this feature. The following capabilities are included in this integration: -- Automated onboarding - Windows Defender ATP sensor is automatically enabled on Windows Servers that are onboarded to Azure Security Center. For more information on Azure Security Center onboarding, see [Onboarding to Azure Security Center Standard for enhanced security](https://docs.microsoft.com/azure/security-center/security-center-onboarding). +- Automated onboarding - Microsoft Defender ATP sensor is automatically enabled on Windows Servers that are onboarded to Azure Security Center. For more information on Azure Security Center onboarding, see [Onboarding to Azure Security Center Standard for enhanced security](https://docs.microsoft.com/azure/security-center/security-center-onboarding). >[!NOTE] > Automated onboarding is only applicable for Windows Server 2012 R2 and Windows Server 2016. -- Servers monitored by Azure Security Center will also be available in Windows Defender ATP - Azure Security Center seamlessly connects to the Windows Defender ATP tenant, providing a single view across clients and servers. In addition, Windows Defender ATP alerts will be available in the Azure Security Center console. +- Servers monitored by Azure Security Center will also be available in Microsoft Defender ATP - Azure Security Center seamlessly connects to the Microsoft Defender ATP tenant, providing a single view across clients and servers. In addition, Microsoft Defender ATP alerts will be available in the Azure Security Center console. - Server investigation - Azure Security Center customers can access Windows Defender Security Center to perform detailed investigation to uncover the scope of a potential breach >[!IMPORTANT] ->- When you use Azure Security Center to monitor servers, a Windows Defender ATP tenant is automatically created. The Windows Defender ATP data is stored in Europe by default. ->- If you use Windows Defender ATP before using Azure Security Center, your data will be stored in the location you specified when you created your tenant even if you integrate with Azure Security Center at a later time. +>- When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created. The Microsoft Defender ATP data is stored in Europe by default. +>- If you use Microsoft Defender ATP before using Azure Security Center, your data will be stored in the location you specified when you created your tenant even if you integrate with Azure Security Center at a later time. @@ -187,26 +187,26 @@ You can offboard Windows Server, version 1803 and Windows 2019 in the same metho For other server versions, you have two options to offboard servers from the service: - Uninstall the MMA agent -- Remove the Windows Defender ATP workspace configuration +- Remove the Microsoft Defender ATP workspace configuration >[!NOTE] >Offboarding causes the server to stop sending sensor data to the portal but data from the server, including reference to any alerts it has had will be retained for up to 6 months. ### Uninstall servers by uinstalling the MMA agent -To offboard the server, you can uninstall the MMA agent from the server or detach it from reporting to your Windows Defender ATP workspace. After offboarding the agent, the server will no longer send sensor data to Windows Defender ATP. +To offboard the server, you can uninstall the MMA agent from the server or detach it from reporting to your Microsoft Defender ATP workspace. After offboarding the agent, the server will no longer send sensor data to Microsoft Defender ATP. For more information, see [To disable an agent](https://docs.microsoft.com/azure/log-analytics/log-analytics-windows-agents#to-disable-an-agent). -### Remove the Windows Defender ATP workspace configuration +### Remove the Microsoft Defender ATP workspace configuration To offboard the server, you can use either of the following methods: -- Remove the Windows Defender ATP workspace configuration from the MMA agent +- Remove the Microsoft Defender ATP workspace configuration from the MMA agent - Run a PowerShell command to remove the configuration -#### Remove the Windows Defender ATP workspace configuration from the MMA agent +#### Remove the Microsoft Defender ATP workspace configuration from the MMA agent 1. In the **Microsoft Monitoring Agent Properties**, select the **Azure Log Analytics (OMS)** tab. -2. Select the Windows Defender ATP workspace, and click **Remove**. +2. Select the Microsoft Defender ATP workspace, and click **Remove**. ![Image of Microsoft Monitoring Agen Properties](images/atp-mma.png) @@ -234,5 +234,5 @@ To offboard the server, you can use either of the following methods: - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) - [Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) - [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Windows Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshooting Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) +- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md index 239c4d95db..9c544f5795 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md @@ -1,5 +1,5 @@ --- -title: Pull alerts to your SIEM tools from Windows Defender Advanced Threat Protection +title: Pull alerts to your SIEM tools from Microsoft Defender Advanced Threat Protection description: Learn how to use REST API and configure supported security information and events management tools to receive and pull alerts. keywords: configure siem, security information and events management tools, splunk, arcsight, custom indicators, rest api, alert definitions, indicators of compromise search.product: eADQiWindows 10XVcnh @@ -22,42 +22,42 @@ ms.date: 10/16/2017 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configuresiem-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configuresiem-abovefoldlink) ## Pull alerts using security information and events management (SIEM) tools -Windows Defender ATP supports (SIEM) tools to pull alerts. Windows Defender ATP exposes alerts through an HTTPS endpoint hosted in Azure. The endpoint can be configured to pull alerts from your enterprise tenant in Azure Active Directory (AAD) using the OAuth 2.0 authentication protocol for an AAD application that represents the specific SIEM connector installed in your environment. +Microsoft Defender ATP supports (SIEM) tools to pull alerts. Microsoft Defender ATP exposes alerts through an HTTPS endpoint hosted in Azure. The endpoint can be configured to pull alerts from your enterprise tenant in Azure Active Directory (AAD) using the OAuth 2.0 authentication protocol for an AAD application that represents the specific SIEM connector installed in your environment. -Windows Defender ATP currently supports the following SIEM tools: +Microsoft Defender ATP currently supports the following SIEM tools: - Splunk - HP ArcSight To use either of these supported SIEM tools you'll need to: -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) - Configure the supported SIEM tool: - - [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) - - [Configure HP ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) + - [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) + - [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -For more information on the list of fields exposed in the alerts API see, [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md). +For more information on the list of fields exposed in the alerts API see, [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md). -## Pull Windows Defender ATP alerts using REST API -Windows Defender ATP supports the OAuth 2.0 protocol to pull alerts using REST API. +## Pull Microsoft Defender ATP alerts using REST API +Microsoft Defender ATP supports the OAuth 2.0 protocol to pull alerts using REST API. -For more information, see [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md). +For more information, see [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md). ## In this section Topic | Description :---|:--- -[Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)| Learn about enabling the SIEM integration feature in the **Settings** page in the portal so that you can use and generate the required information to configure supported SIEM tools. -[Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md)| Learn about installing the REST API Modular Input app and other configuration settings to enable Splunk to pull Windows Defender ATP alerts. -[Configure HP ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)| Learn about installing the HP ArcSight REST FlexConnector package and the files you need to configure ArcSight to pull Windows Defender ATP alerts. -[Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) | Understand what data fields are exposed as part of the alerts API and how they map to Windows Defender Security Center. -[Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) | Use the Client credentials OAuth 2.0 flow to pull alerts from Windows Defender ATP using REST API. +[Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)| Learn about enabling the SIEM integration feature in the **Settings** page in the portal so that you can use and generate the required information to configure supported SIEM tools. +[Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md)| Learn about installing the REST API Modular Input app and other configuration settings to enable Splunk to pull Microsoft Defender ATP alerts. +[Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)| Learn about installing the HP ArcSight REST FlexConnector package and the files you need to configure ArcSight to pull Microsoft Defender ATP alerts. +[Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) | Understand what data fields are exposed as part of the alerts API and how they map to Windows Defender Security Center. +[Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) | Use the Client credentials OAuth 2.0 flow to pull alerts from Microsoft Defender ATP using REST API. [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) | Address issues you might encounter when using the SIEM integration feature. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md index baf0a25a95..bb3e6d4f5b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md @@ -1,5 +1,5 @@ --- -title: Configure Splunk to pull Windows Defender ATP alerts +title: Configure Splunk to pull Microsoft Defender ATP alerts description: Configure Splunk to receive and pull alerts from Windows Defender Security Center. keywords: configure splunk, security information and events management tools, splunk search.product: eADQiWindows 10XVcnh @@ -18,23 +18,23 @@ ms.topic: article ms.date: 10/16/2017 --- -# Configure Splunk to pull Windows Defender ATP alerts +# Configure Splunk to pull Microsoft Defender ATP alerts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configuresplunk-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configuresplunk-abovefoldlink) -You'll need to configure Splunk so that it can pull Windows Defender ATP alerts. +You'll need to configure Splunk so that it can pull Microsoft Defender ATP alerts. ## Before you begin - Install the [REST API Modular Input app](https://splunkbase.splunk.com/app/1546/) in Splunk. -- Make sure you have enabled the **SIEM integration** feature from the **Settings** menu. For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- Make sure you have enabled the **SIEM integration** feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) - Have the details file you saved from enabling the **SIEM integration** feature ready. You'll need to get the following values: - OAuth 2 Token refresh URL @@ -107,7 +107,7 @@ You'll need to configure Splunk so that it can pull Windows Defender ATP alerts. Polling Interval - Number of seconds that Splunk will ping the Windows Defender ATP machine. Accepted values are in seconds. + Number of seconds that Splunk will ping the Microsoft Defender ATP machine. Accepted values are in seconds. Set sourcetype @@ -146,8 +146,8 @@ Use the solution explorer to view alerts in Splunk. >```source="rest://windows atp alerts" | spath | dedup _raw | table *``` ## Related topics -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) - [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md index d20d381975..4d6bed28ef 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md +++ b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Create alert from event API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -29,7 +29,7 @@ ms.date: 12/08/2017 Enables using event data, as obtained from the [Advanced Hunting](run-advanced-query-api.md) for creating a new alert entity. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md b/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md index 4998ae8a80..bb24ba24f8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md +++ b/windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md @@ -1,5 +1,5 @@ --- -title: Create custom detection rules in Windows Defender ATP +title: Create custom detection rules in Microsoft Defender ATP description: Learn how to create custom detections rules based on advanced hunting queries keywords: create custom detections, detections, advanced hunting, hunt, detect, query search.product: eADQiWindows 10XVcnh @@ -20,7 +20,7 @@ ms.topic: article # Create custom detections rules **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) 1. In the navigation pane, select **Advanced hunting**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md index bc9982d2ae..552a856b66 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md @@ -1,6 +1,6 @@ --- title: Create custom alerts using the threat intelligence API -description: Create your custom alert definitions and indicators of compromise in Windows Defender ATP using the available APIs in Windows Enterprise, Education, and Pro editions. +description: Create your custom alert definitions and indicators of compromise in Microsoft Defender ATP using the available APIs in Windows Enterprise, Education, and Pro editions. keywords: alert definitions, indicators of compromise, threat intelligence, custom threat intelligence, rest api, api search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,11 +23,11 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-customti-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-customti-abovefoldlink) You can define custom alert definitions and indicators of compromise (IOC) using the threat intelligence API. Creating custom threat intelligence alerts allows you to generate specific alerts that are applicable to your organization. @@ -61,7 +61,7 @@ For this URL: Each tenant has a defined quota that limits the number of possible alert definitions, IOCs and another quota for IOCs of Action different than “equals” in the system. If you upload data beyond this quota, you'll encounter an HTTP error status code 507 (Insufficient Storage). ## Request an access token from the token issuing endpoint -Windows Defender ATP Threat Intelligence API uses OAuth 2.0. In the context of Windows Defender ATP, the alert definitions are a protected resource. To issue tokens for ad-hoc, non-automatic operations you can use the **Settings** page and click the **Generate Token** button. However, if you’d like to create an automated client, you need to use the “Client Credentials Grant” flow. For more information, see the [OAuth 2.0 authorization framework](https://tools.ietf.org/html/rfc6749#section-4.4). +Microsoft Defender ATP Threat Intelligence API uses OAuth 2.0. In the context of Microsoft Defender ATP, the alert definitions are a protected resource. To issue tokens for ad-hoc, non-automatic operations you can use the **Settings** page and click the **Generate Token** button. However, if you’d like to create an automated client, you need to use the “Client Credentials Grant” flow. For more information, see the [OAuth 2.0 authorization framework](https://tools.ietf.org/html/rfc6749#section-4.4). For more information about the authorization flow, see [OAuth 2.0 authorization flow](https://docs.microsoft.com/azure/active-directory/develop/active-directory-protocols-oauth-code#oauth-20-authorization-flow). @@ -387,8 +387,8 @@ Upon a successful request the response will be HTTP 204. > As with all OData actions, this action is sending an HTTP POST request not DELETE. -## Windows Defender ATP optional query parameters -The Windows Defender ATP threat intelligence API provides several optional query parameters that you can use to specify and control the amount of data returned in a response. The threat intelligence API supports the following query options: +## Microsoft Defender ATP optional query parameters +The Microsoft Defender ATP threat intelligence API provides several optional query parameters that you can use to specify and control the amount of data returned in a response. The threat intelligence API supports the following query options: Name | Value | Description :---|:---|:-- @@ -411,7 +411,7 @@ The following articles provide detailed code examples that demonstrate how to us ## Related topics - [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) - [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) - [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md index 8a393d5b81..76c3d3e1cb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md @@ -1,5 +1,5 @@ --- -title: Update data retention settings for Windows Defender Advanced Threat Protection +title: Update data retention settings for Microsoft Defender Advanced Threat Protection description: Update data retention settings by selecting between 30 days to 180 days. keywords: data, storage, settings, retention, update search.product: eADQiWindows 10XVcnh @@ -17,18 +17,18 @@ ms.collection: M365-security-compliance ms.topic: conceptual ms.date: 04/24/2018 --- -# Update data retention settings for Windows Defender ATP +# Update data retention settings for Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-gensettings-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-gensettings-abovefoldlink) -During the onboarding process, a wizard takes you through the general settings of Windows Defender ATP. After onboarding, you might want to update the data retention settings. +During the onboarding process, a wizard takes you through the general settings of Microsoft Defender ATP. After onboarding, you might want to update the data retention settings. 1. In the navigation pane, select **Settings** > **Data rention**. @@ -42,7 +42,7 @@ During the onboarding process, a wizard takes you through the general settings o ## Related topics - [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Configure alert notifications in Windows Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) - [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) - [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md b/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md index 67780a3f78..b320ac62c4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md +++ b/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy.md @@ -1,7 +1,7 @@ --- -title: Windows Defender ATP data storage and privacy -description: Learn about how Windows Defender ATP handles privacy and data that it collects. -keywords: Windows Defender ATP data storage and privacy, storage, privacy, licensing, geolocation, data retention, data +title: Microsoft Defender ATP data storage and privacy +description: Learn about how Microsoft Defender ATP handles privacy and data that it collects. +keywords: Microsoft Defender ATP data storage and privacy, storage, privacy, licensing, geolocation, data retention, data search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -17,20 +17,20 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Windows Defender ATP data storage and privacy +# Microsoft Defender ATP data storage and privacy **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) -This section covers some of the most frequently asked questions regarding privacy and data handling for Windows Defender ATP. +This section covers some of the most frequently asked questions regarding privacy and data handling for Microsoft Defender ATP. > [!NOTE] -> This document explains the data storage and privacy details related to Windows Defender ATP. For more information related to Windows Defender ATP and other products and services like Windows Defender Antivirus and Windows 10, see [Microsoft Privacy Statement](https://go.microsoft.com/fwlink/?linkid=827576). See also [Windows 10 privacy FAQ](https://go.microsoft.com/fwlink/?linkid=827577) for more information. +> This document explains the data storage and privacy details related to Microsoft Defender ATP. For more information related to Microsoft Defender ATP and other products and services like Windows Defender Antivirus and Windows 10, see [Microsoft Privacy Statement](https://go.microsoft.com/fwlink/?linkid=827576). See also [Windows 10 privacy FAQ](https://go.microsoft.com/fwlink/?linkid=827577) for more information. -## What data does Windows Defender ATP collect? +## What data does Microsoft Defender ATP collect? -Windows Defender ATP will collect and store information from your configured machines in a customer dedicated and segregated tenant specific to the service for administration, tracking, and reporting purposes. +Microsoft Defender ATP will collect and store information from your configured machines in a customer dedicated and segregated tenant specific to the service for administration, tracking, and reporting purposes. Information collected includes file data (such as file names, sizes, and hashes), process data (running processes, hashes), registry data, network connection data (host IPs and ports), and machine details (such as machine identifiers, names, and the operating system version). @@ -44,10 +44,10 @@ Microsoft uses this data to: Microsoft does not use your data for advertising or for any other purpose other than providing you the service. ## Data protection and encryption -The Windows Defender ATP service utilizes state of the art data protection technologies which are based on Microsoft Azure infrastructure. +The Microsoft Defender ATP service utilizes state of the art data protection technologies which are based on Microsoft Azure infrastructure. -There are various aspects relevant to data protection that our service takes care of. Encryption is one of the most critical and it includes data encryption at rest, encryption in flight, and key management with Key Vault. For more information on other technologies used by the Windows Defender ATP service, see [Azure encryption overview](https://docs.microsoft.com/azure/security/security-azure-encryption-overview). +There are various aspects relevant to data protection that our service takes care of. Encryption is one of the most critical and it includes data encryption at rest, encryption in flight, and key management with Key Vault. For more information on other technologies used by the Microsoft Defender ATP service, see [Azure encryption overview](https://docs.microsoft.com/azure/security/security-azure-encryption-overview). In all scenarios, data is encrypted using 256-bit [AES encyption](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard) at the minimum. @@ -84,12 +84,12 @@ Your data will be kept and will be available to you while the licence is under g ## Can Microsoft help us maintain regulatory compliance? -Microsoft provides customers with detailed information about Microsoft's security and compliance programs, including audit reports and compliance packages, to help customers assess Windows Defender ATP services against their own legal and regulatory requirements. Windows Defender ATP is ISO 27001 certified and has a roadmap for obtaining national, regional and industry-specific certifications. +Microsoft provides customers with detailed information about Microsoft's security and compliance programs, including audit reports and compliance packages, to help customers assess Microsoft Defender ATP services against their own legal and regulatory requirements. Microsoft Defender ATP is ISO 27001 certified and has a roadmap for obtaining national, regional and industry-specific certifications. -Windows Defender ATP for Government (soon to be in preview) is currently undergoing audit for achieving FedRAMP High accreditation as well as Provisional Authorization (PA) at Impact Levels 4 and 5. +Microsoft Defender ATP for Government (soon to be in preview) is currently undergoing audit for achieving FedRAMP High accreditation as well as Provisional Authorization (PA) at Impact Levels 4 and 5. By providing customers with compliant, independently-verified services, Microsoft makes it easier for customers to achieve compliance for the infrastructure and applications they run. -For more information on the Windows Defender ATP ISO certification reports, see [Microsoft Trust Center](https://www.microsoft.com/en-us/trustcenter/compliance/iso-iec-27001). +For more information on the Microsoft Defender ATP ISO certification reports, see [Microsoft Trust Center](https://www.microsoft.com/en-us/trustcenter/compliance/iso-iec-27001). ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-datastorage-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-datastorage-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md b/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md index 5050e3dcb1..4d9d0fa3ce 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md +++ b/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility.md @@ -1,6 +1,6 @@ --- -title: Windows Defender Antivirus compatibility with Windows Defender ATP -description: Learn about how Windows Defender works with Windows Defender ATP and how it functions when a third-party antimalware client is used. +title: Windows Defender Antivirus compatibility with Microsoft Defender ATP +description: Learn about how Windows Defender works with Microsoft Defender ATP and how it functions when a third-party antimalware client is used. keywords: windows defender compatibility, defender, windows defender atp search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,24 +18,24 @@ ms.topic: conceptual ms.date: 04/24/2018 --- -# Windows Defender Antivirus compatibility with Windows Defender ATP +# Windows Defender Antivirus compatibility with Microsoft Defender ATP **Applies to:** - Windows Defender -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-defendercompat-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-defendercompat-abovefoldlink) -The Windows Defender Advanced Threat Protection agent depends on Windows Defender Antivirus for some capabilities such as file scanning. +The Microsoft Defender Advanced Threat Protection agent depends on Windows Defender Antivirus for some capabilities such as file scanning. >[!IMPORTANT] ->Windows Defender ATP does not adhere to the Windows Defender Antivirus Exclusions settings. +>Microsoft Defender ATP does not adhere to the Windows Defender Antivirus Exclusions settings. -You must configure Security intelligence updates on the Windows Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). +You must configure Security intelligence updates on the Microsoft Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). If an onboarded machine is protected by a third-party antimalware client, Windows Defender Antivirus on that endpoint will enter into passive mode. @@ -43,4 +43,4 @@ Windows Defender Antivirus will continue to receive updates, and the *mspeng.exe The Windows Defender Antivirus interface will be disabled, and users on the machine will not be able to use Windows Defender Antivirus to perform on-demand scans or configure most options. -For more information, see the [Windows Defender Antivirus and Windows Defender ATP compatibility topic](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). +For more information, see the [Windows Defender Antivirus and Microsoft Defender ATP compatibility topic](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md index 6399e4f311..40d6df11a5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id.md @@ -19,7 +19,7 @@ ms.topic: article # Delete Indicator API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/deprecate.md b/windows/security/threat-protection/microsoft-defender-atp/deprecate.md index fe73a4d416..ac6fe24aed 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/deprecate.md +++ b/windows/security/threat-protection/microsoft-defender-atp/deprecate.md @@ -4,4 +4,4 @@ ms.date: 10/17/2018 >[!WARNING] -> This page documents a feature that will soon be deprecated. For the updated and supported version, see [Use the Windows Defender ATP APIs](use-apis.md). \ No newline at end of file +> This page documents a feature that will soon be deprecated. For the updated and supported version, see [Use the Microsoft Defender ATP APIs](use-apis.md). \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md index 49545c0428..c90107793c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md @@ -1,6 +1,6 @@ --- -title: Enable the custom threat intelligence API in Windows Defender ATP -description: Learn how to setup the custom threat intelligence application in Windows Defender ATP to create custom threat intelligence (TI). +title: Enable the custom threat intelligence API in Microsoft Defender ATP +description: Learn how to setup the custom threat intelligence application in Microsoft Defender ATP to create custom threat intelligence (TI). keywords: enable custom threat intelligence application, custom ti application, application name, client id, authorization url, resource, client secret, access tokens search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,16 +18,16 @@ ms.topic: article ms.date: 04/24/2018 --- -# Enable the custom threat intelligence API in Windows Defender ATP +# Enable the custom threat intelligence API in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablecustomti-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablecustomti-abovefoldlink) Before you can create custom threat intelligence (TI) using REST API, you'll need to set up the custom threat intelligence application through Windows Defender Security Center. diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md index c4590d0678..bf2bbbf003 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md @@ -1,5 +1,5 @@ --- -title: Enable Secure Score in Windows Defender ATP +title: Enable Secure Score in Microsoft Defender ATP description: Set the baselines for calculating the score of Windows Defender security controls on the Secure Score dashboard. keywords: enable secure score, baseline, calculation, analytics, score, secure score dashboard, dashboard search.product: eADQiWindows 10XVcnh @@ -23,7 +23,7 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -40,7 +40,7 @@ Set the baselines for calculating the score of Windows Defender security control ## Related topics - [View the Secure Score dashboard](secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [Update data retention settings for Windows Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Configure alert notifications in Windows Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Configure advanced features in Windows Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) +- [Update data retention settings for Microsoft Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) +- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Configure advanced features in Microsoft Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md index b3d89ea8d0..a5099be0b4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md @@ -1,5 +1,5 @@ --- -title: Enable SIEM integration in Windows Defender ATP +title: Enable SIEM integration in Microsoft Defender ATP description: Enable SIEM integration to receive alerts in your security information and event management (SIEM) solution. keywords: enable siem connector, siem, connector, security information and events search.product: eADQiWindows 10XVcnh @@ -18,13 +18,13 @@ ms.topic: article ms.date: 12/10/2018 --- -# Enable SIEM integration in Windows Defender ATP +# Enable SIEM integration in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablesiem-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablesiem-abovefoldlink) Enable security information and event management (SIEM) integration so you can pull alerts from Windows Defender Security Center using your SIEM solution or by connecting directly to the alerts REST API. @@ -66,12 +66,12 @@ Enable security information and event management (SIEM) integration so you can p You can now proceed with configuring your SIEM solution or connecting to the alerts REST API through programmatic access. You'll need to use the tokens when configuring your SIEM solution to allow it to receive alerts from Windows Defender Security Center. -## Integrate Windows Defender ATP with IBM QRadar -You can configure IBM QRadar to collect alerts from Windows Defender ATP. For more information, see [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_dsm_guide_MS_Win_Defender_ATP_overview.html?cp=SS42VS_7.3.1). +## Integrate Microsoft Defender ATP with IBM QRadar +You can configure IBM QRadar to collect alerts from Microsoft Defender ATP. For more information, see [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_dsm_guide_MS_Win_Defender_ATP_overview.html?cp=SS42VS_7.3.1). ## Related topics -- [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Configure HP ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +- [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) - [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md b/windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md index 6dd9971ceb..85aa0f8290 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/evaluate-atp.md @@ -1,5 +1,5 @@ --- -title: Evaluate Windows Defender Advanced Threat Protection +title: Evaluate Microsoft Defender Advanced Threat Protection description: keywords: search.product: eADQiWindows 10XVcnh @@ -18,12 +18,12 @@ ms.topic: conceptual ms.date: 08/10/2018 --- -# Evaluate Windows Defender ATP -[Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) is a unified platform for preventative protection, post-breach detection, automated investigation, and response. +# Evaluate Microsoft Defender ATP +[Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) is a unified platform for preventative protection, post-breach detection, automated investigation, and response. -You can evaluate Windows Defender Advanced Threat Protection in your organization by [starting your free trial](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp). +You can evaluate Microsoft Defender Advanced Threat Protection in your organization by [starting your free trial](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp). -You can also evaluate the different security capabilities in Windows Defender ATP by using the following instructions. +You can also evaluate the different security capabilities in Microsoft Defender ATP by using the following instructions. ## Evaluate attack surface reduction These capabilities help prevent attacks and exploitations from infecting your organization. @@ -40,4 +40,4 @@ Next gen protections help detect and block the latest threats. ## See Also -[Get started with Windows Defender Advanced Threat Protection](get-started.md) \ No newline at end of file +[Get started with Microsoft Defender Advanced Threat Protection](get-started.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md index f49caf3929..b6e868da21 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md +++ b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md @@ -1,7 +1,7 @@ --- title: Review events and errors using Event Viewer -description: Get descriptions and further troubleshooting steps (if required) for all events reported by the Windows Defender ATP service. -keywords: troubleshoot, event viewer, log summary, failure code, failed, Windows Defender Advanced Threat Protection service, cannot start, broken, can't start +description: Get descriptions and further troubleshooting steps (if required) for all events reported by the Microsoft Defender ATP service. +keywords: troubleshoot, event viewer, log summary, failure code, failed, Microsoft Defender Advanced Threat Protection service, cannot start, broken, can't start search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -25,7 +25,7 @@ ms.date: 05/21/2018 - Event Viewer -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -34,9 +34,9 @@ You can review event IDs in the [Event Viewer](https://msdn.microsoft.com/librar For example, if machines are not appearing in the **Machines list**, you might need to look for event IDs on the machines. You can then use this table to determine further troubleshooting steps. > [!NOTE] -> It can take several days for machines to begin reporting to the Windows Defender ATP service. +> It can take several days for machines to begin reporting to the Microsoft Defender ATP service. -**Open Event Viewer and find the Windows Defender ATP service event log:** +**Open Event Viewer and find the Microsoft Defender ATP service event log:** 1. Click **Start** on the Windows menu, type **Event Viewer**, and press **Enter**. @@ -46,7 +46,7 @@ For example, if machines are not appearing in the **Machines list**, you might n a. You can also access the log by expanding **Applications and Services Logs** > **Microsoft** > **Windows** > **SENSE** and click on **Operational**. > [!NOTE] - > SENSE is the internal name used to refer to the behavioral sensor that powers Windows Defender ATP. + > SENSE is the internal name used to refer to the behavioral sensor that powers Microsoft Defender ATP. 3. Events recorded by the service will appear in the log. See the following table for a list of events recorded by the service. @@ -60,39 +60,39 @@ For example, if machines are not appearing in the **Machines list**, you might n 1 -Windows Defender Advanced Threat Protection service started (Version ```variable```). +Microsoft Defender Advanced Threat Protection service started (Version ```variable```). Occurs during system start up, shut down, and during onbboarding. Normal operating notification; no action required. 2 -Windows Defender Advanced Threat Protection service shutdown. +Microsoft Defender Advanced Threat Protection service shutdown. Occurs when the machine is shut down or offboarded. Normal operating notification; no action required. 3 -Windows Defender Advanced Threat Protection service failed to start. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to start. Failure code: ```variable```. Service did not start. Review other messages to determine possible cause and troubleshooting steps. 4 -Windows Defender Advanced Threat Protection service contacted the server at ```variable```. -Variable = URL of the Windows Defender ATP processing servers.
+Microsoft Defender Advanced Threat Protection service contacted the server at ```variable```. +Variable = URL of the Microsoft Defender ATP processing servers.
This URL will match that seen in the Firewall or network activity. Normal operating notification; no action required. 5 -Windows Defender Advanced Threat Protection service failed to connect to the server at ```variable```. -Variable = URL of the Windows Defender ATP processing servers.
+Microsoft Defender Advanced Threat Protection service failed to connect to the server at ```variable```. +Variable = URL of the Microsoft Defender ATP processing servers.
The service could not contact the external processing servers at that URL. Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet-windows-defender-advanced-threat-protection.md). 6 -Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. +Microsoft Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. The machine did not onboard correctly and will not be reporting to the portal. Onboarding must be run before starting the service.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -100,14 +100,14 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 7 -Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: ```variable```. Variable = detailed error description. The machine did not onboard correctly and will not be reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). 8 -Windows Defender Advanced Threat Protection service failed to clean its configuration. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to clean its configuration. Failure code: ```variable```. **During onboarding:** The service failed to clean its configuration during the onboarding. The onboarding process continues.

**During offboarding:** The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running. **Onboarding:** No action required.

**Offboarding:** Reboot the system.
@@ -115,47 +115,47 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 9 -Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to change its start type. Failure code: ```variable```. **During onboarding:** The machine did not onboard correctly and will not be reporting to the portal.

**During offboarding:** Failed to change the service start type. The offboarding process continues. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). 10 -Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: ```variable```. The machine did not onboard correctly and will not be reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). 11 -Onboarding or re-onboarding of Windows Defender Advanced Threat Protection service completed. +Onboarding or re-onboarding of Microsoft Defender Advanced Threat Protection service completed. The machine onboarded correctly. Normal operating notification; no action required.
It may take several hours for the machine to appear in the portal. 12 -Windows Defender Advanced Threat Protection failed to apply the default configuration. +Microsoft Defender Advanced Threat Protection failed to apply the default configuration. Service was unable to apply the default configuration. This error should resolve after a short period of time. 13 -Windows Defender Advanced Threat Protection machine ID calculated: ```variable```. +Microsoft Defender Advanced Threat Protection machine ID calculated: ```variable```. Normal operating process. Normal operating notification; no action required. 15 -Windows Defender Advanced Threat Protection cannot start command channel with URL: ```variable```. -Variable = URL of the Windows Defender ATP processing servers.
+Microsoft Defender Advanced Threat Protection cannot start command channel with URL: ```variable```. +Variable = URL of the Microsoft Defender ATP processing servers.
The service could not contact the external processing servers at that URL. Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet-windows-defender-advanced-threat-protection.md). 17 -Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: ```variable```. An error occurred with the Windows telemetry service. [Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostics-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -182,7 +182,7 @@ If this error persists after a system restart, ensure all Windows updates have f 25 -Windows Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: ```variable```. The machine did not onboard correctly. It will report to the portal, however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -190,7 +190,7 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 26 -Windows Defender Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: ```variable```. The machine did not onboard correctly.
It will report to the portal, however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -198,15 +198,15 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 27 -Windows Defender Advanced Threat Protection service failed to enable SENSE aware mode in Windows Defender Antivirus. Onboarding process failed. Failure code: ```variable```. -Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Windows Defender ATP. +Microsoft Defender Advanced Threat Protection service failed to enable SENSE aware mode in Windows Defender Antivirus. Onboarding process failed. Failure code: ```variable```. +Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Microsoft Defender ATP. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
Ensure real-time antimalware protection is running properly. 28 -Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration failed. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration failed. Failure code: ```variable```. An error occurred with the Windows telemetry service. [Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -220,34 +220,34 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 30 -Windows Defender Advanced Threat Protection service failed to disable SENSE aware mode in Windows Defender Antivirus. Failure code: ```variable```. -Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Windows Defender ATP. +Microsoft Defender Advanced Threat Protection service failed to disable SENSE aware mode in Windows Defender Antivirus. Failure code: ```variable```. +Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Microsoft Defender ATP. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md)
Ensure real-time antimalware protection is running properly. 31 -Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: ```variable```. An error occurred with the Windows telemetry service during onboarding. The offboarding process continues. [Check for errors with the Windows telemetry service](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled). 32 -Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: %1 +Microsoft Defender Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: %1 An error occurred during offboarding. Reboot the machine. 33 -Windows Defender Advanced Threat Protection service failed to persist SENSE GUID. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to persist SENSE GUID. Failure code: ```variable```. A unique identifier is used to represent each machine that is reporting to the portal.
If the identifier does not persist, the same machine might appear twice in the portal. Check registry permissions on the machine to ensure the service can update the registry. 34 -Windows Defender Advanced Threat Protection service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: ```variable```. An error occurred with the Windows telemetry service. [Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -255,62 +255,62 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- 35 -Windows Defender Advanced Threat Protection service failed to remove itself as a dependency on the Connected User Experiences and Telemetry service. Failure code: ```variable```. +Microsoft Defender Advanced Threat Protection service failed to remove itself as a dependency on the Connected User Experiences and Telemetry service. Failure code: ```variable```. An error occurred with the Windows telemetry service during offboarding. The offboarding process continues. Check for errors with the Windows diagnostic data service. 36 -Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration succeeded. Completion code: ```variable```. -Registering Windows Defender Advanced Threat Protection with the Connected User Experiences and Telemetry service completed successfully. +Microsoft Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration succeeded. Completion code: ```variable```. +Registering Microsoft Defender Advanced Threat Protection with the Connected User Experiences and Telemetry service completed successfully. Normal operating notification; no action required. 37 -Windows Defender Advanced Threat Protection A module is about to exceed its quota. Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4. +Microsoft Defender Advanced Threat Protection A module is about to exceed its quota. Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4. The machine has almost used its allocated quota of the current 24-hour window. It’s about to be throttled. Normal operating notification; no action required. 38 -Network connection is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. +Network connection is identified as low. Microsoft Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. The machine is using a metered/paid network and will be contacting the server less frequently. Normal operating notification; no action required. 39 -Network connection is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. +Network connection is identified as normal. Microsoft Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. The machine is not using a metered/paid connection and will contact the server as usual. Normal operating notification; no action required. 40 -Battery state is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. +Battery state is identified as low. Microsoft Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. The machine has low battery level and will contact the server less frequently. Normal operating notification; no action required. 41 -Battery state is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. +Battery state is identified as normal. Microsoft Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. The machine doesn’t have low battery level and will contact the server as usual. Normal operating notification; no action required. 42 -Windows Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception message: %4 +Microsoft Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception message: %4 Internal error. The service failed to start. If this error persists, contact Support. 43 -Windows Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception Error: %4, Exception message: %5 +Microsoft Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception Error: %4, Exception message: %5 Internal error. The service failed to start. If this error persists, contact Support. 44 -Offboarding of Windows Defender Advanced Threat Protection service completed. +Offboarding of Microsoft Defender Advanced Threat Protection service completed. The service was offboarded. Normal operating notification; no action required. @@ -342,9 +342,9 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-eventerrorcodes-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-eventerrorcodes-belowfoldlink) ## Related topics - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) - [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Windows Defender ATP](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender ATP](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md index 3e8ba14f02..b89eeb886a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md @@ -1,6 +1,6 @@ --- title: Experiment with custom threat intelligence alerts -description: Use this end-to-end guide to start using the Windows Defender ATP threat intelligence API. +description: Use this end-to-end guide to start using the Microsoft Defender ATP threat intelligence API. keywords: alert definitions, indicators of compromise, threat intelligence, custom threat intelligence, rest api, api search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,13 +23,13 @@ ms.date: 11/09/2017 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-experimentcustomti-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-experimentcustomti-abovefoldlink) -With the Windows Defender ATP threat intelligence API, you can create custom threat intelligence alerts that can help you keep track of possible attack activities in your organization. +With the Microsoft Defender ATP threat intelligence API, you can create custom threat intelligence alerts that can help you keep track of possible attack activities in your organization. For more information about threat intelligence concepts, see [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md). @@ -47,7 +47,7 @@ This step will guide you in creating an alert definition and an IOC for a malici 1. Open a Windows PowerShell ISE. -2. Copy and paste the following PowerShell script. This script will upload a sample alert definition and IOC to Windows Defender ATP which you can use to generate an alert. +2. Copy and paste the following PowerShell script. This script will upload a sample alert definition and IOC to Microsoft Defender ATP which you can use to generate an alert. NOTE: Make sure you replace the authUrl, clientId, and clientSecret values with your details which you saved in when you enabled the threat intelligence application. @@ -80,7 +80,7 @@ This step will guide you in creating an alert definition and an IOC for a malici $alertDefinitionPayload = @{ "Name" = "Test Alert" "Severity" = "Medium" - "InternalDescription" = "A test alert used to demonstrate the Windows Defender ATP TI API feature" + "InternalDescription" = "A test alert used to demonstrate the Microsoft Defender ATP TI API feature" "Title" = "Test alert." "UxDescription" = "This is a test alert based on a sample custom alert definition. This alert was triggered manually using a provided test command. It indicates that the Threat Intelligence API has been properly enabled." "RecommendedAction" = "No recommended action for this test alert." @@ -130,9 +130,9 @@ This step will guide you in creating an alert definition and an IOC for a malici ~~~~ ## Step 3: Simulate a custom TI alert -This step will guide you in simulating an event in connection to a malicious IP that will trigger the Windows Defender ATP custom TI alert. +This step will guide you in simulating an event in connection to a malicious IP that will trigger the Microsoft Defender ATP custom TI alert. -1. Open a Windows PowerShell ISE in the machine you onboarded to Windows Defender ATP. +1. Open a Windows PowerShell ISE in the machine you onboarded to Microsoft Defender ATP. 2. Type `Invoke-WebRequest 52.184.197.12` in the editor and click **Run**. This call will generate a network communication event to a Microsoft's dedicated demo server that will raise an alert based on the custom alert definition. @@ -143,7 +143,7 @@ This step will guide you in exploring the custom alert in the portal. 1. Open [Windows Defender Security Center](http://securitycenter.windows.com/) on a browser. -2. Log in with your Windows Defender ATP credentials. +2. Log in with your Microsoft Defender ATP credentials. 3. The dashboard should display the custom TI alert for the victim machine resulting from the simulated attack. @@ -154,7 +154,7 @@ This step will guide you in exploring the custom alert in the portal. ## Related topics - [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) - [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) - [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md index 56c66b472e..f94e8cbf84 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md @@ -1,5 +1,5 @@ --- -title: Use Windows Defender Advanced Threat Protection APIs +title: Use Microsoft Defender Advanced Threat Protection APIs description: Use the exposed data and actions using a set of progammatic APIs that are part of the Microsoft Intelligence Security Graph. keywords: apis, graph api, supported apis, actor, alerts, machine, user, domain, ip, file, advanced hunting, query search.product: eADQiWindows 10XVcnh @@ -17,33 +17,33 @@ ms.topic: article ms.date: 09/03/2018 --- -# Use Windows Defender ATP APIs +# Use Microsoft Defender ATP APIs -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) -> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) +> Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) [!include[Prerelease information](prerelease.md)] -This page describes how to create an application to get programmatic access to Windows Defender ATP on behalf of a user. +This page describes how to create an application to get programmatic access to Microsoft Defender ATP on behalf of a user. -If you need programmatic access Windows Defender ATP without a user, refer to [Access Windows Defender ATP with application context](exposed-apis-create-app-webapp.md). +If you need programmatic access Microsoft Defender ATP without a user, refer to [Access Microsoft Defender ATP with application context](exposed-apis-create-app-webapp.md). If you are not sure which access you need, read the [Introduction page](apis-intro.md). -Windows Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate work flows and innovate based on Windows Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). +Microsoft Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will enable you to automate work flows and innovate based on Microsoft Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). In general, you’ll need to take the following steps to use the APIs: - Create an AAD application - Get an access token using this application -- Use the token to access Windows Defender ATP API +- Use the token to access Microsoft Defender ATP API -This page explains how to create an AAD application, get an access token to Windows Defender ATP and validate the token. +This page explains how to create an AAD application, get an access token to Microsoft Defender ATP and validate the token. >[!NOTE] -> When accessing Windows Defender ATP API on behalf of a user, you will need the correct App permission and user permission. -> If you are not familiar with user permissions on Windows Defender ATP, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). +> When accessing Microsoft Defender ATP API on behalf of a user, you will need the correct App permission and user permission. +> If you are not familiar with user permissions on Microsoft Defender ATP, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). >[!TIP] > If you have the permission to perform an action in the portal, you have the permission to perform the action in the API. @@ -162,9 +162,9 @@ Sanity check to make sure you got a correct token: ![Image of token validation](images/nativeapp-decoded-token.png) -## Use the token to access Windows Defender ATP API +## Use the token to access Microsoft Defender ATP API -- Choose the API you want to use - [Supported Windows Defender ATP APIs](exposed-apis-list.md) +- Choose the API you want to use - [Supported Microsoft Defender ATP APIs](exposed-apis-list.md) - Set the Authorization header in the HTTP request you send to "Bearer {token}" (Bearer is the Authorization scheme) - The Expiration time of the token is 1 hour (you can send more then one request with the same token) @@ -182,5 +182,5 @@ Sanity check to make sure you got a correct token: ``` ## Related topics -- [Windows Defender ATP APIs](exposed-apis-list.md) -- [Access Windows Defender ATP with application context](exposed-apis-create-app-webapp.md) \ No newline at end of file +- [Microsoft Defender ATP APIs](exposed-apis-list.md) +- [Access Microsoft Defender ATP with application context](exposed-apis-create-app-webapp.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md index 4d6b21364d..e0800f060b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md @@ -1,5 +1,5 @@ --- -title: Create an app to access Windows Defender ATP without a user +title: Create an app to access Microsoft Defender ATP without a user description: Use the exposed data and actions using a set of progammatic APIs that are part of the Microsoft Intelligence Security Graph. keywords: apis, graph api, supported apis, actor, alerts, machine, user, domain, ip, file, advanced hunting, query search.product: eADQiWindows 10XVcnh @@ -17,28 +17,28 @@ ms.topic: article ms.date: 09/03/2018 --- -# Create an app to access Windows Defender ATP without a user +# Create an app to access Microsoft Defender ATP without a user -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) -> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) +> Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) [!include[Prerelease information](prerelease.md)] -This page describes how to create an application to get programmatic access to Windows Defender ATP without a user. +This page describes how to create an application to get programmatic access to Microsoft Defender ATP without a user. -If you need programmatic access Windows Defender ATP on behalf of a user, see [Get access wtih user context](exposed-apis-create-app-nativeapp.md) +If you need programmatic access Microsoft Defender ATP on behalf of a user, see [Get access wtih user context](exposed-apis-create-app-nativeapp.md) If you are not sure which access you need, see [Get started](apis-intro.md). -Windows Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will help you automate workflows and innovate based on Windows Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). +Microsoft Defender ATP exposes much of its data and actions through a set of programmatic APIs. Those APIs will help you automate workflows and innovate based on Microsoft Defender ATP capabilities. The API access requires OAuth2.0 authentication. For more information, see [OAuth 2.0 Authorization Code Flow](https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols-oauth-code). In general, you’ll need to take the following steps to use the APIs: - Create an AAD application - Get an access token using this application -- Use the token to access Windows Defender ATP API +- Use the token to access Microsoft Defender ATP API -This page explains how to create an AAD application, get an access token to Windows Defender ATP and validate the token. +This page explains how to create an AAD application, get an access token to Microsoft Defender ATP and validate the token. ## Create an app @@ -101,7 +101,7 @@ This page explains how to create an AAD application, get an access token to Wind ![Image of created app id](images/webapp-app-id1.png) -11. **For Windows Defender ATP Partners only** - Set your application to be multi-tenanted +11. **For Microsoft Defender ATP Partners only** - Set your application to be multi-tenanted This is **required** for 3rd party apps (for example, if you create an application that is intended to run in multiple customers tenant). @@ -113,7 +113,7 @@ This page explains how to create an AAD application, get an access token to Wind - Application consent for your multi-tenant App: - You need your application to be approved in each tenant where you intend to use it. This is because your application interacts with Windows Defender ATP application on behalf of your customer. + You need your application to be approved in each tenant where you intend to use it. This is because your application interacts with Microsoft Defender ATP application on behalf of your customer. You (or your customer if you are writing a 3rd party application) need to click the consent link and approve your application. The consent should be done with a user who has admin privileges in the active directory. @@ -199,7 +199,7 @@ Refer to [Get token using Python](run-advanced-query-sample-python.md#get-token) - Open a command window - ​Set CLIENT_ID to your Azure application ID - Set CLIENT_SECRET to your Azure application secret -- Set TENANT_ID to the Azure tenant ID of the customer that wants to use your application to access Windows Defender ATP application +- Set TENANT_ID to the Azure tenant ID of the customer that wants to use your application to access Microsoft Defender ATP application - Run the below command: ``` @@ -217,13 +217,13 @@ You will get an answer of the form: Sanity check to make sure you got a correct token: - Copy/paste into [JWT](https://jwt.ms) the token you get in the previous step in order to decode it - Validate you get a 'roles' claim with the desired permissions -- In the screenshot below you can see a decoded token acquired from an app with permissions to all of Windows Defender ATP's roles: +- In the screenshot below you can see a decoded token acquired from an app with permissions to all of Microsoft Defender ATP's roles: ![Image of token validation](images/webapp-decoded-token.png) -## Use the token to access Windows Defender ATP API +## Use the token to access Microsoft Defender ATP API -- Choose the API you want to use, for more information, see [Supported Windows Defender ATP APIs](exposed-apis-list.md) +- Choose the API you want to use, for more information, see [Supported Microsoft Defender ATP APIs](exposed-apis-list.md) - Set the Authorization header in the Http request you send to "Bearer {token}" (Bearer is the Authorization scheme) - The Expiration time of the token is 1 hour (you can send more then one request with the same token) @@ -241,5 +241,5 @@ Sanity check to make sure you got a correct token: ``` ## Related topics -- [Supported Windows Defender ATP APIs](exposed-apis-list.md) -- [Access Windows Defender ATP on behalf of a user](exposed-apis-create-app-nativeapp.md) \ No newline at end of file +- [Supported Microsoft Defender ATP APIs](exposed-apis-list.md) +- [Access Microsoft Defender ATP on behalf of a user](exposed-apis-create-app-nativeapp.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md index 80c3f2dfdf..baa4e06aca 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-full-sample-powershell.md @@ -17,18 +17,18 @@ ms.topic: article ms.date: 09/24/2018 --- -# Windows Defender ATP APIs using PowerShell +# Microsoft Defender ATP APIs using PowerShell **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] -Full scenario using multiple APIs from Windows Defender ATP. +Full scenario using multiple APIs from Microsoft Defender ATP. In this section we share PowerShell samples to - Retrieve a token - - Use token to retrieve the latest alerts in Windows Defender ATP + - Use token to retrieve the latest alerts in Microsoft Defender ATP - For each alert, if the alert has medium or high priority and is still in progress, check how many times the machine has connected to suspicious URL. >**Prerequisite**: You first need to [create an app](apis-intro.md). @@ -48,7 +48,7 @@ Set-ExecutionPolicy -ExecutionPolicy Bypass - Run the below > - $tenantId: ID of the tenant on behalf of which you want to run the query (i.e., the query will be run on the data of this tenant) -> - $appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Windows Defender ATP) +> - $appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Microsoft Defender ATP) > - $appSecret: Secret of your AAD app > - $suspiciousUrl: The URL @@ -116,7 +116,7 @@ $response ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using Python](run-advanced-query-sample-python.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md index 2be8b96e04..a0676ff144 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-list.md @@ -1,6 +1,6 @@ --- -title: Supported Windows Defender Advanced Threat Protection query APIs -description: Learn about the specific supported Windows Defender Advanced Threat Protection entities where you can create API calls to. +title: Supported Microsoft Defender Advanced Threat Protection query APIs +description: Learn about the specific supported Microsoft Defender Advanced Threat Protection entities where you can create API calls to. keywords: apis, supported apis, actor, alerts, machine, user, domain, ip, file, advanced queries, advanced hunting search.product: eADQiWindows 10XVcnh ms.prod: w10 @@ -16,14 +16,14 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Supported Windows Defender ATP query APIs +# Supported Microsoft Defender ATP query APIs **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-supportedapis-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-supportedapis-abovefoldlink) ## End Point URI and Versioning @@ -58,4 +58,4 @@ Machines | Run API calls such as find machine information by IP, get machines, g User | Run API calls such as get alert related user information, user information, user related alerts, and user related machines. ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md index 8892195292..3eb6c6eb6b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md @@ -1,6 +1,6 @@ --- -title: OData queries with Windows Defender ATP -description: OData queries with Windows Defender ATP +title: OData queries with Microsoft Defender ATP +description: OData queries with Microsoft Defender ATP keywords: apis, supported apis, odata, query search.product: eADQiWindows 10XVcnh ms.prod: w10 @@ -17,9 +17,9 @@ ms.topic: article ms.date: 11/15/2018 --- -# OData queries with Windows Defender ATP +# OData queries with Microsoft Defender ATP **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -242,7 +242,7 @@ Content-type: application/json ### Example 6 -- Get all the Anti-Virus scans that the user Analyst@examples.onmicrosoft.com created using Windows Defender ATP +- Get all the Anti-Virus scans that the user Analyst@examples.onmicrosoft.com created using Microsoft Defender ATP ``` HTTP GET https://api.securitycenter.windows.com/api/machineactions?$filter=requestor eq 'Analyst@WcdTestPrd.onmicrosoft.com' and type eq 'RunAntiVirusScan' @@ -293,4 +293,4 @@ Content-type: application/json ``` ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/files.md b/windows/security/threat-protection/microsoft-defender-atp/files.md index 0491fe98c9..8a89db801c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/files.md @@ -18,11 +18,11 @@ ms.topic: article # File resource type **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] -Represent a file entity in Windows Defender ATP. +Represent a file entity in Microsoft Defender ATP. # Methods Method|Return Type |Description @@ -50,5 +50,5 @@ fileProductName | String | Product name. signer | String | File signer. issuer | String | File issuer. signerHash | String | Hash of the signing certificate. -isValidCertificate | Boolean | Was signing certificate successfully verified by Windows Defender ATP agent. +isValidCertificate | Boolean | Was signing certificate successfully verified by Microsoft Defender ATP agent. diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md index 5e8d10dd1e..da2a070318 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip.md @@ -23,7 +23,7 @@ ms.date: 07/25/2018 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) Find a machine by internal IP. @@ -32,7 +32,7 @@ Find a machine by internal IP. >The timestamp must be within the last 30 days. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index 687f9ab304..d46afc1621 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -21,7 +21,7 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -29,7 +29,7 @@ ms.date: 12/08/2017 - The given timestamp must be in the past 30 days. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md index f6ed806476..25198b66e2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md +++ b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md @@ -1,5 +1,5 @@ --- -title: Fix unhealthy sensors in Windows Defender ATP +title: Fix unhealthy sensors in Microsoft Defender ATP description: Fix machine sensors that are reporting as misconfigured or inactive so that the service receives data from the machine. keywords: misconfigured, inactive, fix sensor, sensor health, no sensor data, sensor data, impaired communications, communication search.product: eADQiWindows 10XVcnh @@ -18,16 +18,16 @@ ms.topic: article ms.date: 10/23/2017 --- -# Fix unhealthy sensors in Windows Defender ATP +# Fix unhealthy sensors in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-fixsensor-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-fixsensor-abovefoldlink) Machines that are categorized as misconfigured or inactive can be flagged due to varying causes. This section provides some explanations as to what might have caused a machine to be categorized as inactive or misconfigured. @@ -39,14 +39,14 @@ An inactive machine is not necessarily flagged due to an issue. The following ac If the machine has not been in use for more than 7 days for any reason, it will remain in an ‘Inactive’ status in the portal. **Machine was reinstalled or renamed**
-A reinstalled or renamed machine will generate a new machine entity in Windows Defender Security Center. The previous machine entity will remain with an ‘Inactive’ status in the portal. If you reinstalled a machine and deployed the Windows Defender ATP package, search for the new machine name to verify that the machine is reporting normally. +A reinstalled or renamed machine will generate a new machine entity in Windows Defender Security Center. The previous machine entity will remain with an ‘Inactive’ status in the portal. If you reinstalled a machine and deployed the Microsoft Defender ATP package, search for the new machine name to verify that the machine is reporting normally. **Machine was offboarded**
If the machine was offboarded it will still appear in machines list. After 7 days, the machine health state should change to inactive. **Machine is not sending signals** -If the machine is not sending any signals for more than 7 days to any of the Windows Defender ATP channels for any reason including conditions that fall under misconfigured machines classification, a machine can be considered inactive. +If the machine is not sending any signals for more than 7 days to any of the Microsoft Defender ATP channels for any reason including conditions that fall under misconfigured machines classification, a machine can be considered inactive. Do you expect a machine to be in ‘Active’ status? [Open a support ticket ticket](https://support.microsoft.com/getsupport?wf=0&tenant=ClassicCommercial&oaspworkflow=start_1.0.0.0&locale=en-us&supportregion=en-us&pesid=16055&ccsid=636206786382823561). @@ -62,10 +62,10 @@ This status indicates that there's limited communication between the machine and The following suggested actions can help fix issues related to a misconfigured machine with impaired communications: - [Ensure the machine has Internet connection](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#troubleshoot-onboarding-issues-on-the-machine)
- The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. + The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
- Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Windows Defender ATP service URLs. +- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+ Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. If you took corrective actions and the machine status is still misconfigured, [open a support ticket](https://go.microsoft.com/fwlink/?LinkID=761093&clcid=0x409). @@ -74,18 +74,18 @@ A misconfigured machine with status ‘No sensor data’ has communication with Follow theses actions to correct known issues related to a misconfigured machine with status ‘No sensor data’: - [Ensure the machine has Internet connection](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#troubleshoot-onboarding-issues-on-the-machine)
- The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. + The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
- Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Windows Defender ATP service URLs. +- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+ Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. - [Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostics-service-is-enabled)
If the machines aren't reporting correctly, you might need to check that the Windows 10 diagnostic data service is set to automatically start and is running on the endpoint. - [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy)
-If your machines are running a third-party antimalware client, the Windows Defender ATP agent needs the Windows Defender Antivirus Early Launch Antimalware (ELAM) driver to be enabled. +If your machines are running a third-party antimalware client, the Microsoft Defender ATP agent needs the Windows Defender Antivirus Early Launch Antimalware (ELAM) driver to be enabled. If you took corrective actions and the machine status is still misconfigured, [open a support ticket](https://go.microsoft.com/fwlink/?LinkID=761093&clcid=0x409). ## Related topic -- [Check sensor health state in Windows Defender ATP](check-sensor-status-windows-defender-advanced-threat-protection.md) +- [Check sensor health state in Microsoft Defender ATP](check-sensor-status-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md index 3cbd5cc31e..bbd89aa3a9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get alert information by ID API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves an alert by its ID. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md index 5e0a0256ae..1fca507328 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get alert related domain information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves all domains related to a specific alert. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md index a286bb19f9..9bbfea2471 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get alert related files information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves all files related to a specific alert. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md index af24309c36..097a942506 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Get alert related IP information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -27,7 +27,7 @@ ms.date: 12/08/2017 Retrieves all IPs related to a specific alert. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md index 55b0895b5f..67b08cb95f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md @@ -20,14 +20,14 @@ ms.date: 12/08/2017 # Get alert related machine information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] - Retrieves machine that is related to a specific alert. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md index a96ecfe588..13feffeb9e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Get alert related user information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -27,7 +27,7 @@ ms.date: 12/08/2017 Retrieves the user associated to a specific alert. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md index 45820ed888..f75ea370fe 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # List alerts API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,10 +28,10 @@ ms.date: 12/08/2017 - Retrieves a collection of Alerts. - Supports [OData V4 queries](https://www.odata.org/documentation/). - The OData's Filter query is supported on: "Id", "IncidentId", "AlertCreationTime", "Status", "Severity" and "Category". -- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- See examples at [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- @@ -136,4 +136,4 @@ Here is an example of the response. ``` ## Related topics -- [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md index e65b940689..0d1e9286c3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-cvekbmap-collection.md @@ -22,7 +22,7 @@ ms.date: 10/07/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Retrieves a map of CVE's to KB's and CVE details. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md index 2a44ef58e4..5ba64ec4c7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Get domain related alerts API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -31,7 +31,7 @@ ms.date: 12/08/2017 Retrieves a collection of alerts related to a given domain address. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md index c1136545a5..5d423ce391 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get domain related machines API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves a collection of machines that have communicated to or from a given domain address. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md index f4f669e5a2..ae79790f9a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Get domain statistics API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -27,7 +27,7 @@ ms.date: 12/08/2017 Retrieves the prevalence for the given domain. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md index 792f618d5f..35e9289aa3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Get file information API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ ms.date: 12/08/2017 Retrieves a file by identifier Sha1, Sha256, or MD5. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md index 46f6a80f2a..5df7bcbdb8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Get file related alerts API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -29,7 +29,7 @@ ms.date: 12/08/2017 Retrieves a collection of alerts related to a given file hash. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md index cf9e003f26..389c9e1c36 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md @@ -21,14 +21,14 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] - Retrieves a collection of machines related to a given file hash. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md index 17f1f3525d..674203724b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Get file statistics API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -31,7 +31,7 @@ ms.date: 12/08/2017 Retrieves the prevalence for the given file. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md index 08817b8e70..41683118e7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md @@ -20,14 +20,14 @@ ms.date: 12/08/2017 # Get IP related alerts API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves a collection of alerts related to a given IP address. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md index e17c0a1457..a1ab48a5a3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Get IP related machines API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -27,7 +27,7 @@ ms.date: 12/08/2017 Retrieves a collection of machines that communicated with or from a particular IP. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md index 3c2c965ffb..1a1062304c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Get IP statistics API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -29,7 +29,7 @@ ms.date: 12/08/2017 Retrieves the prevalence for the given IP. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md index cfc710240a..7617020547 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-kbinfo-collection.md @@ -22,7 +22,7 @@ ms.date: 10/07/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Retrieves a collection of KB's and KB details. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md index 5a6a77b908..57cb51ba8b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md @@ -21,14 +21,14 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] - Retrieves a machine entity by ID. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md index eb0edbe3e4..0315fbb35c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md @@ -23,11 +23,11 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) Retrieves a collection of logged on users. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md index df392f1ef1..19f9e99ebc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md @@ -23,11 +23,11 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) Retrieves a collection of alerts related to a given machine ID. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md index 19a78ab6d8..ac88ef7f97 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md @@ -21,14 +21,14 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] - Get action performed on a machine. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md index 4be4316a45..c91a221921 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md @@ -21,17 +21,17 @@ ms.date: 12/08/2017 **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] - Gets collection of actions done on machines. - Get MachineAction collection API supports [OData V4 queries](https://www.odata.org/documentation/). - The OData's Filter query is supported on: "Id", "Status", "MachineId", "Type", "Requestor" and "CreationDateTimeUtc". -- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- See examples at [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- @@ -175,4 +175,4 @@ Content-type: application/json ``` ## Related topics -- [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md index 85bfd9945a..9205fdc61c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machinegroups-collection.md @@ -22,7 +22,7 @@ ms.date: 10/07/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Retrieves a collection of RBAC machine groups. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md index 7e2ad2eaf1..d7104b407e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md @@ -19,14 +19,14 @@ ms.topic: article # List machines API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] -- Retrieves a collection of machines that have communicated with Windows Defender ATP cloud on the last 30 days. +- Retrieves a collection of machines that have communicated with Microsoft Defender ATP cloud on the last 30 days. - Get Machines collection API supports [OData V4 queries](https://www.odata.org/documentation/). - The OData's Filter query is supported on: "Id", "ComputerDnsName", "LastSeen", "LastIpAddress", "HealthStatus", "OsPlatform", "RiskScore", "MachineTags" and "RbacGroupId". -- See examples at [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- See examples at [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) ## Permissions @@ -127,4 +127,4 @@ Content-type: application/json ``` ## Related topics -- [OData queries with Windows Defender ATP](exposed-apis-odata-samples.md) +- [OData queries with Microsoft Defender ATP](exposed-apis-odata-samples.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md index 55803636b8..70fec0601d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machinesecuritystates-collection.md @@ -22,7 +22,7 @@ ms.date: 10/07/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Retrieves a collection of machines security states. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md index 32bc25c9bd..aad27c712c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get package SAS URI API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] Get a URI that allows downloading of an [investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md). ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-started.md b/windows/security/threat-protection/microsoft-defender-atp/get-started.md index 6086863cb6..f5a6fa236f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-started.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-started.md @@ -1,6 +1,6 @@ --- -title: Get started with Windows Defender Advanced Threat Protection -description: Learn about the minimum requirements and initial steps you need to take to get started with Windows Defender ATP. +title: Get started with Microsoft Defender Advanced Threat Protection +description: Learn about the minimum requirements and initial steps you need to take to get started with Microsoft Defender ATP. keywords: get started, minimum requirements, setup, subscription, features, data storage, privacy, user access search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,39 +18,39 @@ ms.topic: conceptual ms.date: 11/20/2018 --- -# Get started with Windows Defender Advanced Threat Protection +# Get started with Microsoft Defender Advanced Threat Protection **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) >[!TIP] ->- Learn about the latest enhancements in Windows Defender ATP: [What's new in Windows Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). ->- Windows Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). +>- Learn about the latest enhancements in Microsoft Defender ATP: [What's new in Microsoft Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). +>- Microsoft Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). -Learn about the minimum requirements and initial steps you need to take to get started with Windows Defender ATP. +Learn about the minimum requirements and initial steps you need to take to get started with Microsoft Defender ATP. -The following capabilities are available across multiple products that make up the Windows Defender ATP platform. +The following capabilities are available across multiple products that make up the Microsoft Defender ATP platform. **Attack surface reduction**
The attack surface reduction set of capabilities provide the first line of defense in the stack. By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. **Next generation protection**
-To further reinforce the security perimeter of your network, Windows Defender ATP uses next generation protection designed to catch all types of emerging threats. +To further reinforce the security perimeter of your network, Microsoft Defender ATP uses next generation protection designed to catch all types of emerging threats. **Endpoint detection and response**
Endpoint detection and response capabilities are put in place to detect, investigate, and respond to advanced threats that may have made it past the first two security pillars. **Auto investigation and remediation**
-In conjunction with being able to quickly respond to advanced attacks, Windows Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. +In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. **Secure score**
-Windows Defender ATP provides a security posture capability to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security state of your network. +Microsoft Defender ATP provides a security posture capability to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security state of your network. **Advanced hunting**
Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Windows Defender Security Center. **Management and APIs**
-Integrate Windows Defender Advanced Threat Protection into your existing workflows. +Integrate Microsoft Defender Advanced Threat Protection into your existing workflows. **Microsoft threat protection**
Bring the power of Microsoft Threat Protection to your organization. @@ -60,8 +60,8 @@ Topic | Description :---|:--- [Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md) | Learn about the requirements for onboarding machines to the platform. [Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md) | Get guidance on how to check that licenses have been provisioned to your organization and how to access the portal for the first time. -[Preview features](preview-windows-defender-advanced-threat-protection.md) | Learn about new features in the Windows Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. -[Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) | Explains the data storage and privacy details related to Windows Defender ATP. +[Preview features](preview-windows-defender-advanced-threat-protection.md) | Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. +[Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) | Explains the data storage and privacy details related to Microsoft Defender ATP. [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md) | Set permissions to manage who can access the portal. You can set basic permissions or set granular permissions using role-based access control (RBAC). -[Evaluate Windows Defender ATP](evaluate-atp.md) | Evaluate the various capabilities in Windows Defender ATP and test features out. -[Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Windows Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file +[Evaluate Microsoft Defender ATP](evaluate-atp.md) | Evaluate the various capabilities in Microsoft Defender ATP and test features out. +[Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md index 837155f677..6fe62b0834 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # List Indicators API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md index 75c9bc7f08..ee1b42726f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md @@ -18,14 +18,14 @@ ms.topic: article # Get user information API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] Retrieve a User entity by key (user name). ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md index 6044ca7009..ad8a4ad671 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md @@ -19,14 +19,14 @@ ms.date: 12/08/2017 # Get user related alerts API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves a collection of alerts related to a given user ID. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md index a3597ff7ac..ee24ebc6e3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md @@ -20,14 +20,14 @@ ms.date: 12/08/2017 # Get user related machines API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Retrieves a collection of machines related to a given user ID. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md index 1a769c409b..3ac978d6bd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md @@ -1,5 +1,5 @@ --- -title: Incidents queue in Windows Defender ATP +title: Incidents queue in Microsoft Defender ATP description: keywords: incidents, aggregate, investigations, queue, ttp search.product: eADQiWindows 10XVcnh @@ -17,14 +17,14 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Incidents in Windows Defender ATP +# Incidents in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -When a cybersecurity threat is emerging, or a potential attacker is deploying its tactics, techniques/tools, and procedures (TTPs) on the network, Windows Defender ATP will quickly trigger alerts and launch matching automatic investigations. +When a cybersecurity threat is emerging, or a potential attacker is deploying its tactics, techniques/tools, and procedures (TTPs) on the network, Microsoft Defender ATP will quickly trigger alerts and launch matching automatic investigations. -Windows Defender ATP applies correlation analytics and aggregates all related alerts and investigations into an incident. Doing so helps narrate a broader story of an attack, thus providing you with the right visuals (upgraded incident graph) and data representations to understand and deal with complex cross-entity threats to your organization's network. +Microsoft Defender ATP applies correlation analytics and aggregates all related alerts and investigations into an incident. Doing so helps narrate a broader story of an attack, thus providing you with the right visuals (upgraded incident graph) and data representations to understand and deal with complex cross-entity threats to your organization's network. ## In this section diff --git a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md index 9eedb8b8f5..e147c2ee32 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md +++ b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-config.md @@ -19,18 +19,18 @@ ms.date: 12/05/2018 # Configure information protection in Windows **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] -Learn how you can use Windows Defender ATP to expand the coverage of Windows Information Protection (WIP) to protect files based on their label, regardless of their origin. +Learn how you can use Microsoft Defender ATP to expand the coverage of Windows Information Protection (WIP) to protect files based on their label, regardless of their origin. >[!TIP] -> Read our blog post about how [Windows Defender ATP integrates with Microsoft Information Protection to discover, protect, and monitor sensitive data on Windows devices](https://cloudblogs.microsoft.com/microsoftsecure/2019/01/17/windows-defender-atp-integrates-with-microsoft-information-protection-to-discover-protect-and-monitor-sensitive-data-on-windows-devices/). +> Read our blog post about how [Microsoft Defender ATP integrates with Microsoft Information Protection to discover, protect, and monitor sensitive data on Windows devices](https://cloudblogs.microsoft.com/microsoftsecure/2019/01/17/windows-defender-atp-integrates-with-microsoft-information-protection-to-discover-protect-and-monitor-sensitive-data-on-windows-devices/). ## Prerequisites - Endpoints need to be on Windows 10, version 1809 or later -- You'll need the appropriate license to leverage the Windows Defender ATP and Azure Information Protection integration +- You'll need the appropriate license to leverage the Microsoft Defender ATP and Azure Information Protection integration - Your tenant needs to be onboarded to Azure Information Protection analytics, for more information see, [Configure a Log Analytics workspace for the reports](https://docs.microsoft.comazure/information-protection/reports-aip#configure-a-log-analytics-workspace-for-the-reports) @@ -46,10 +46,10 @@ Learn how you can use Windows Defender ATP to expand the coverage of Windows Inf 4. Repeat for every label that you want to get WIP applied to in Windows. -After completing these steps Windows Defender ATP will automatically identify labeled documents stored on the device and enable WIP on them. +After completing these steps Microsoft Defender ATP will automatically identify labeled documents stored on the device and enable WIP on them. >[!NOTE] ->- The Windows Defender ATP configuration is pulled every 15 minutes. Allow up to 30 minutes for the new policy to take effect and ensure that the endpoint is online. Otherwise, it will not receive the policy. +>- The Microsoft Defender ATP configuration is pulled every 15 minutes. Allow up to 30 minutes for the new policy to take effect and ensure that the endpoint is online. Otherwise, it will not receive the policy. >- Data forwarded to Azure Information Protection is stored in the same location as your other Azure Information Protection data. ## Related topic diff --git a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md index 976dfff7e4..f594da75a4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md @@ -19,56 +19,56 @@ ms.date: 12/05/2018 # Information protection in Windows overview **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] Information protection is an integral part of Microsoft 365 Enterprise suite, providing intelligent protection to keep sensitive data secure while enabling productivity in the workplace. -Windows Defender ATP is seamlessly integrated in Microsoft Threat Protection to provide a complete and comprehensive data loss prevention (DLP) solution for Windows devices. This solution is delivered and managed as part of the unified Microsoft 365 information protection suite. +Microsoft Defender ATP is seamlessly integrated in Microsoft Threat Protection to provide a complete and comprehensive data loss prevention (DLP) solution for Windows devices. This solution is delivered and managed as part of the unified Microsoft 365 information protection suite. >[!TIP] -> Read our blog post about how [Windows Defender ATP integrates with Microsoft Information Protection to discover, protect, and monitor sensitive data on Windows devices](https://cloudblogs.microsoft.com/microsoftsecure/2019/01/17/windows-defender-atp-integrates-with-microsoft-information-protection-to-discover-protect-and-monitor-sensitive-data-on-windows-devices/). +> Read our blog post about how [Microsoft Defender ATP integrates with Microsoft Information Protection to discover, protect, and monitor sensitive data on Windows devices](https://cloudblogs.microsoft.com/microsoftsecure/2019/01/17/windows-defender-atp-integrates-with-microsoft-information-protection-to-discover-protect-and-monitor-sensitive-data-on-windows-devices/). -Windows Defender ATP applies two methods to discover and protect data: +Microsoft Defender ATP applies two methods to discover and protect data: - **Data discovery** - Identify sensitive data on Windows devices at risk - **Data protection** - Windows Information Protection (WIP) as outcome of Azure Information Protection label ## Data discovery -Windows Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Windows Defender Security Center. For more information, see [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md#azure-information-protection). +Microsoft Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Windows Defender Security Center. For more information, see [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md#azure-information-protection). ![Image of settings page with Azure Information Protection](images/atp-settings-aip.png) -After enabling the Azure Information Protection integration, data discovery signals are immediately forwarded to Azure Information Protection from the device. When a labeled file is created or modified on a Windows device, Windows Defender ATP automatically reports the signal to Azure Information Protection. +After enabling the Azure Information Protection integration, data discovery signals are immediately forwarded to Azure Information Protection from the device. When a labeled file is created or modified on a Windows device, Microsoft Defender ATP automatically reports the signal to Azure Information Protection. The reported signals can be viewed on the Azure Information Protection - Data discovery dashboard. ### Azure Information Protection - Data discovery dashboard -This dashboard presents a summarized discovery information of data discovered by both Windows Defender ATP and Azure Information Protection. Data from Windows Defender ATP is marked with Location Type - Endpoint. +This dashboard presents a summarized discovery information of data discovered by both Microsoft Defender ATP and Azure Information Protection. Data from Microsoft Defender ATP is marked with Location Type - Endpoint. ![Image of Azure Information Protection - Data discovery](images/azure-data-discovery.png) -Notice the Device Risk column on the right, this device risk is derived directly from Windows Defender ATP, indicating the risk level of the security device where the file was discovered, based on the active security threats detected by Windows Defender ATP. +Notice the Device Risk column on the right, this device risk is derived directly from Microsoft Defender ATP, indicating the risk level of the security device where the file was discovered, based on the active security threats detected by Microsoft Defender ATP. -Clicking the device risk level will redirect you to the device page in Windows Defender ATP, where you can get a comprehensive view of the device security status and its active alerts. +Clicking the device risk level will redirect you to the device page in Microsoft Defender ATP, where you can get a comprehensive view of the device security status and its active alerts. >[!NOTE] ->Windows Defender ATP does not currently report the Information Types. +>Microsoft Defender ATP does not currently report the Information Types. ### Log Analytics -Data discovery based on Windows Defender ATP is also available in [Azure Log Analytics](https://docs.microsoft.com/azure/log-analytics/log-analytics-overview), where you can perform complex queries over the raw data. +Data discovery based on Microsoft Defender ATP is also available in [Azure Log Analytics](https://docs.microsoft.com/azure/log-analytics/log-analytics-overview), where you can perform complex queries over the raw data. For more information on Azure Information Protection analytics, see [Central reporting for Azure Information Protection](https://docs.microsoft.com/azure/information-protection/reports-aip). Open Azure Log Analytics in Azure Portal and open a query builder (standard or classic). -To view Windows Defender ATP data, perform a query that contains: +To view Microsoft Defender ATP data, perform a query that contains: ``` @@ -83,15 +83,15 @@ InformationProtectionLogs_CL ## Data protection -For data to be protected, they must first be identified through labels. Sensitivity labels are created in Office Security and Compliance (SCC). Windows Defender ATP then uses the labels to identify endpoints that need Windows Information Protection (WIP) applied on them. +For data to be protected, they must first be identified through labels. Sensitivity labels are created in Office Security and Compliance (SCC). Microsoft Defender ATP then uses the labels to identify endpoints that need Windows Information Protection (WIP) applied on them. -When you create sensitivity labels, you can set the information protection functionalities that will be applied on the file. The setting that applies to Windows Defender ATP is the Data loss prevention. You'll need to turn on the Data loss prevention and select Enable Windows end point protection (DLP for devices). +When you create sensitivity labels, you can set the information protection functionalities that will be applied on the file. The setting that applies to Microsoft Defender ATP is the Data loss prevention. You'll need to turn on the Data loss prevention and select Enable Windows end point protection (DLP for devices). ![Image of Office 365 Security and Compliance sensitivity label](images/office-scc-label.png) -Once, the policy is set and published, Windows Defender ATP automatically enables WIP for labeled files. When a labeled file is created or modified on a Windows device, Windows Defender ATP automatically detects it and enables WIP on that file if its label corresponds with Office Security and Compliance (SCC) policy. +Once, the policy is set and published, Microsoft Defender ATP automatically enables WIP for labeled files. When a labeled file is created or modified on a Windows device, Microsoft Defender ATP automatically detects it and enables WIP on that file if its label corresponds with Office Security and Compliance (SCC) policy. This functionality expands the coverage of WIP to protect files based on their label, regardless of their origin. diff --git a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md index 7e91cf5285..13ed50b836 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md @@ -18,7 +18,7 @@ ms.topic: article # Initiate machine investigation API (Preview) **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) > [!IMPORTANT] > Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. @@ -33,7 +33,7 @@ Initiate AutoIR investigation on a machine. 2. For Automated Investigation limitations, see [Automated Investigation](automated-investigations-windows-defender-advanced-threat-protection.md). ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md index 1c60dae5b7..fd445e7665 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md @@ -1,5 +1,5 @@ --- -title: Investigate Windows Defender Advanced Threat Protection alerts +title: Investigate Microsoft Defender Advanced Threat Protection alerts description: Use the investigation options to get details on alerts are affecting your network, what they mean, and how to resolve them. keywords: investigate, investigation, machines, machine, alerts queue, dashboard, IP address, file, submit, submissions, deep analysis, timeline, search, domain, URL, IP search.product: eADQiWindows 10XVcnh @@ -18,15 +18,15 @@ ms.topic: article ms.date: 04/24/2018 --- -# Investigate Windows Defender Advanced Threat Protection alerts +# Investigate Microsoft Defender Advanced Threat Protection alerts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatealerts-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatealerts-abovefoldlink) Investigate alerts that are affecting your network, understand what they mean, and how to resolve them. @@ -93,12 +93,12 @@ The **Artifact timeline** feature provides an addition view of the evidence that Selecting an alert detail brings up the **Details pane** where you'll be able to see more information about the alert such as file details, detections, instances of it observed worldwide, and in the organization. ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md index 010408840d..14ceae480d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md @@ -1,5 +1,5 @@ --- -title: Investigate Windows Defender Advanced Threat Protection domains +title: Investigate Microsoft Defender Advanced Threat Protection domains description: Use the investigation options to see if machines and servers have been communicating with malicious domains. keywords: investigate domain, domain, malicious domain, windows defender atp, alert, URL search.product: eADQiWindows 10XVcnh @@ -17,16 +17,16 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Investigate a domain associated with a Windows Defender ATP alert +# Investigate a domain associated with a Microsoft Defender ATP alert **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatedomain-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatedomain-abovefoldlink) Investigate a domain to see if machines and servers in your enterprise network have been communicating with a known malicious domain. @@ -60,10 +60,10 @@ The **Most recent observed machinew with URL** section provides a chronological 5. Clicking any of the machine names will take you to that machine's view, where you can continue investigate reported alerts, behaviors, and events. ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md index cf4b455f24..3f570b3926 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md @@ -1,5 +1,5 @@ --- -title: Investigate Windows Defender Advanced Threat Protection files +title: Investigate Microsoft Defender Advanced Threat Protection files description: Use the investigation options to get details on files associated with alerts, behaviours, or events. keywords: investigate, investigation, file, malicious activity, attack motivation, deep analysis, deep analysis report search.product: eADQiWindows 10XVcnh @@ -17,16 +17,16 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Investigate a file associated with a Windows Defender ATP alert +# Investigate a file associated with a Microsoft Defender ATP alert **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatefiles-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatefiles-abovefoldlink) Investigate the details of a file associated with a specific alert, behavior, or event to help determine if the file exhibits malicious activities, identify the attack motivation, and understand the potential scope of the breach. @@ -65,10 +65,10 @@ The **Most recent observed machines with the file** section allows you to specif This allows for greater accuracy in defining entities to display such as if and when an entity was observed in the organization. For example, if you’re trying to identify the origin of a network communication to a certain IP Address within a 10-minute period on a given date, you can specify that exact time interval, and see only files that communicated with that IP Address at that time, drastically reducing unnecessary scrolling and searching. ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md index 47c0edb764..cb3221071a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md @@ -1,5 +1,5 @@ --- -title: Investigate incidents in Windows Defender ATP +title: Investigate incidents in Microsoft Defender ATP description: See associated alerts, manage the incident, and see alert metadata to help you investigate an incident keywords: investigate, incident, alerts, metadata, risk, detection source, affected machines, patterns, correlation search.product: eADQiWindows 10XVcnh @@ -17,10 +17,10 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Investigate incidents in Windows Defender ATP +# Investigate incidents in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Investigate incidents that affect your network, understand what they mean, and collate evidence to resolve them. @@ -57,13 +57,13 @@ Select **Investigations** to see all the automatic investigations launched by th ![Image of investigations tab in incident details page](images/atp-incident-investigations-tab.png) ## Going through the evidence -Windows Defender Advanced Threat Protection automatically investigates all the incidents' supported events and suspicious entities in the alerts, providing you with auto-response and information about the important files, processes, services, and more. This helps quickly detect and block potential threats in the incident. +Microsoft Defender Advanced Threat Protection automatically investigates all the incidents' supported events and suspicious entities in the alerts, providing you with auto-response and information about the important files, processes, services, and more. This helps quickly detect and block potential threats in the incident. Each of the analyzed entities will be marked as infected, remediated, or suspicious. ![Image of evidence tab in incident details page](images/atp-incident-evidence-tab.png) ## Visualizing associated cybersecurity threats -Windows Defender Advanced Threat Protection aggregates the threat information into an incident so you can see the patterns and correlations coming in from various data points. You can view such correlation through the incident graph. +Microsoft Defender Advanced Threat Protection aggregates the threat information into an incident so you can see the patterns and correlations coming in from various data points. You can view such correlation through the incident graph. ### Incident graph The **Graph** tells the story of the cybersecurity attack. For example, it shows you what was the entry point, which indicator of compromise or activity was observed on which machine. etc. diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md index cf77b8afb9..0d5a09260c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md @@ -17,16 +17,16 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Investigate an IP address associated with a Windows Defender ATP alert +# Investigate an IP address associated with a Microsoft Defender ATP alert **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigateip-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigateip-abovefoldlink) Examine possible communication between your machines and external internet protocol (IP) addresses. @@ -67,10 +67,10 @@ Use the search filters to define the search criteria. You can also use the timel Clicking any of the machine names will take you to that machine's view, where you can continue investigate reported alerts, behaviors, and events. ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md index 2b9d2d90f5..8ca174ec64 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md @@ -1,5 +1,5 @@ --- -title: Investigate machines in the Windows Defender ATP Machines list +title: Investigate machines in the Microsoft Defender ATP Machines list description: Investigate affected machines by reviewing alerts, network connection information, adding machine tags and groups, and checking the service health. keywords: machines, tags, groups, endpoint, alerts queue, alerts, machine name, domain, last seen, internal IP, active alerts, threat category, filter, sort, review alerts, network, connection, type, password stealer, ransomware, exploit, threat, low severity, service heatlh search.product: eADQiWindows 10XVcnh @@ -18,12 +18,12 @@ ms.topic: article ms.date: 09/18/2018 --- -# Investigate machines in the Windows Defender ATP Machines list +# Investigate machines in the Microsoft Defender ATP Machines list **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatemachines-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatemachines-abovefoldlink) ## Investigate machines Investigate the details of an alert raised on a specific machine to identify other behaviors or events that might be related to the alert or the potential scope of breach. @@ -71,7 +71,7 @@ The Machine risk tile shows the overall risk assessment of a machine. A machine' If you have enabled the Azure ATP feature and there are alerts related to the machine, you can click on the link that will take you to the Azure ATP page where more information about the alerts are provided. >[!NOTE] ->You'll need to enable the integration on both Azure ATP and Windows Defender ATP to use this feature. In Windows Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). +>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). **Machine reporting**
Provides the last internal IP and external IP of the machine. It also shows when the machine was first and last seen reporting to the service. @@ -92,7 +92,7 @@ This feature also enables you to selectively drill down into events that occurre ![Image of machine timeline with events](images/atp-machines-timeline.png) -Windows Defender ATP monitors and captures suspicious or anomalous behavior on Windows 10 machines and displays the process tree flow in the **Machine timeline**. This gives you better context of the behavior which can contribute to understanding the correlation between events, files, and IP addresses in relation to the machine. +Microsoft Defender ATP monitors and captures suspicious or anomalous behavior on Windows 10 machines and displays the process tree flow in the **Machine timeline**. This gives you better context of the behavior which can contribute to understanding the correlation between events, files, and IP addresses in relation to the machine. ### Search for specific events @@ -114,7 +114,7 @@ Use the search bar to look for specific timeline events. Harness the power of us - Behaviors mode: displays "detections" and selected events of interest - Verbose mode: displays all raw events without aggregation or filtering -- **Event type** - Click the drop-down button to filter by events such as Windows - Windows Defender ATP alerts, Windows Defender Application Guard events, registry events, file events, and others. +- **Event type** - Click the drop-down button to filter by events such as Windows - Microsoft Defender ATP alerts, Windows Defender Application Guard events, registry events, file events, and others. Filtering by event type allows you to define precise queries so that you see events with a specific focus. For example, you can search for a file name, then filter the results to only see Process events matching the search criteria or to only view file events, or even better: to view only network events over a period of time to make sure no suspicious outbound communications go unnoticed. @@ -173,10 +173,10 @@ The details pane enriches the ‘in-context’ information across investigation ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md index 4260159191..886c34c0f8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md @@ -1,5 +1,5 @@ --- -title: Investigate a user account in Windows Defender ATP +title: Investigate a user account in Microsoft Defender ATP description: Investigate a user account for potential compromised credentials or pivot on the associated user account during an investigation. keywords: investigate, account, user, user entity, alert, windows defender atp search.product: eADQiWindows 10XVcnh @@ -17,15 +17,15 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Investigate a user account in Windows Defender ATP +# Investigate a user account in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatgeuser-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-investigatgeuser-abovefoldlink) ## Investigate user account entities Identify user accounts with the most active alerts (displayed on dashboard as "Users at risk") and investigate cases of potential compromised credentials, or pivot on the associated user account when investigating an alert or machine to identify possible lateral movement between machines with that user account. @@ -53,7 +53,7 @@ The user entity tile provides details about the user such as when the user was f If you have enabled the Azure ATP feature and there are alerts related to the user, you can click on the link that will take you to the Azure ATP page where more information about the alerts are provided. The Azure ATP tile also provides details such as the last AD site, total group memberships, and login failure associated with the user. >[!NOTE] ->You'll need to enable the integration on both Azure ATP and Windows Defender ATP to use this feature. In Windows Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). +>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). **Logged on machines**
You'll also see a list of the machines that the user logged on to, and can expand these to see details of the logon events on each machine. @@ -85,11 +85,11 @@ You can filter the results by the following time periods: - 6 months ## Related topics -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Windows Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md index 026174d5f5..6ff1bae6e0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md +++ b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md @@ -19,7 +19,7 @@ ms.date: 04/24/2018 # Was domain seen in org **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -27,7 +27,7 @@ ms.date: 04/24/2018 Answers whether a domain was seen in the organization. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md index 8cfb010fc6..08e8c07149 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md +++ b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Was IP seen in org **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ ms.date: 12/08/2017 Answers whether an IP was seen in the organization. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md index a09ded139b..1379df6c30 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Isolate machine API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -28,7 +28,7 @@ Isolates a machine from accessing external network. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/licensing.md b/windows/security/threat-protection/microsoft-defender-atp/licensing.md index 9dcb0b6f60..efbcf00dab 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/licensing.md +++ b/windows/security/threat-protection/microsoft-defender-atp/licensing.md @@ -1,6 +1,6 @@ --- -title: Validate licensing provisioning and complete Windows Defender ATP set up -description: Validating licensing provisioning, setting up initial preferences, and completing the user set up for Windows Defender Advanced Threat Protection portal. +title: Validate licensing provisioning and complete Microsoft Defender ATP set up +description: Validating licensing provisioning, setting up initial preferences, and completing the user set up for Microsoft Defender Advanced Threat Protection portal. keywords: license, licensing, account, set up, validating licensing, windows defender atp search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -16,16 +16,16 @@ audience: ITPro ms.collection: M365-security-compliance ms.topic: article --- -# Validate licensing provisioning and complete set up for Windows Defender ATP +# Validate licensing provisioning and complete set up for Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-validatelicense-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-validatelicense-abovefoldlink) ## Check license state @@ -53,11 +53,11 @@ To gain access into which licenses are provisioned to your company, and to check ## Access Windows Defender Security Center for the first time -When accessing [Windows Defender Security Center](https://SecurityCenter.Windows.com) for the first time there will be a setup wizard that will guide you through some initial steps. At the end of the setup wizard there will be a dedicated cloud instance of Windows Defender ATP created. +When accessing [Windows Defender Security Center](https://SecurityCenter.Windows.com) for the first time there will be a setup wizard that will guide you through some initial steps. At the end of the setup wizard there will be a dedicated cloud instance of Microsoft Defender ATP created. 1. Each time you access the portal you will need to validate that you are authorized to access the product. This **Set up your permissions** step will only be available if you are not currently authorized to access the product. - ![Image of Set up your permissions for Windows Defender ATP](images\atp-setup-permissions-wdatp-portal.png) + ![Image of Set up your permissions for Microsoft Defender ATP](images\atp-setup-permissions-wdatp-portal.png) Once the authorization step is completed, the **Welcome** screen will be displayed. @@ -74,9 +74,9 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows 1. **Select data storage location**
When onboarding the service for the first time, you can choose to store your data in the Microsoft Azure datacenters in the United States, the European Union, or the United Kingdom. Once configured, you cannot change the location where your data is stored. This provides a convenient way to minimize compliance risk by actively selecting the geographic locations where your data will reside. Microsoft will not transfer the data from the specified geolocation. > [!WARNING] - > This option cannot be changed without completely offboarding from Windows Defender ATP and completing a new enrollment process. + > This option cannot be changed without completely offboarding from Microsoft Defender ATP and completing a new enrollment process. - 2. **Select the data retention policy**
Windows Defender ATP will store data up to a period of 6 months in your cloud instance, however, you have the option to set the data retention period for a shorter timeframe during this step of the set up process. + 2. **Select the data retention policy**
Microsoft Defender ATP will store data up to a period of 6 months in your cloud instance, however, you have the option to set the data retention period for a shorter timeframe during this step of the set up process. > [!NOTE] > This option can be changed at a later time. @@ -86,7 +86,7 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows > [!NOTE] > The **organization size** question is not related to how many licenses were purchased for your organization. It is used by the service to optimize the creation of the data cluster for your organization. - 4. **Turn on preview features**
Learn about new features in the Windows Defender ATP preview release and be among the first to try upcoming features by turning on **Preview features**. + 4. **Turn on preview features**
Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on **Preview features**. You'll have access to upcoming features which you can provide feedback on to help improve the overall experience before features are generally available. @@ -104,9 +104,9 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows 5. A dedicated cloud instance of Windows Defender Security Center is being created at this time. This step will take an average of 5 minutes to complete. - ![Image of Windows Defender ATP cloud instance](images\creating-account.png) + ![Image of Microsoft Defender ATP cloud instance](images\creating-account.png) -6. You are almost done. Before you can start using Windows Defender ATP you'll need to: +6. You are almost done. Before you can start using Microsoft Defender ATP you'll need to: - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) @@ -115,13 +115,13 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows ![Image of Onboard machines and run detection test](images\atp-onboard-endpoints-run-detection-test.png) > [!IMPORTANT] - > If you click **Start using Windows Defender ATP** before onboarding machines you will receive the following notification: + > If you click **Start using Microsoft Defender ATP** before onboarding machines you will receive the following notification: >![Image of setup imcomplete](images\atp-setup-incomplete.png) -7. After onboarding machines you can click **Start using Windows Defender ATP**. You will now launch Windows Defender ATP for the first time. +7. After onboarding machines you can click **Start using Microsoft Defender ATP**. You will now launch Microsoft Defender ATP for the first time. ![Image of onboard machines](images\atp-onboard-endpoints-WDATP-portal.png) ## Related topics -- [Onboard machines to the Windows Defender Advanced Threat Protection service](onboard-configure-windows-defender-advanced-threat-protection.md) +- [Onboard machines to the Microsoft Defender Advanced Threat Protection service](onboard-configure-windows-defender-advanced-threat-protection.md) - [Troubleshoot onboarding process and portal access issues](troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md b/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md index d983539915..a932128539 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md @@ -1,5 +1,5 @@ --- -title: Create and manage machine groups in Windows Defender ATP +title: Create and manage machine groups in Microsoft Defender ATP description: Create machine groups and set automated remediation levels on them by confiring the rules that apply on the group keywords: machine groups, groups, remediation, level, rules, aad group, role, assign, rank search.product: eADQiWindows 10XVcnh @@ -17,19 +17,19 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Create and manage machine groups in Windows Defender ATP +# Create and manage machine groups in Microsoft Defender ATP **Applies to:** - Azure Active Directory - Office 365 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) In an enterprise scenario, security operation teams are typically assigned a set of machines. These machines are grouped together based on a set of attributes such as their domains, computer names, or designated tags. -In Windows Defender ATP, you can create machine groups and use them to: +In Microsoft Defender ATP, you can create machine groups and use them to: - Limit access to related alerts and data to specific Azure AD user groups with [assigned RBAC roles](rbac-windows-defender-advanced-threat-protection.md) - Configure different auto-remediation settings for different sets of machines diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md b/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md index 86bf166722..77885b5540 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md @@ -1,5 +1,5 @@ --- -title: Machine health and compliance report in Windows Defender ATP +title: Machine health and compliance report in Microsoft Defender ATP description: Track machine health state detections, antivirus status, OS platform, and Windows 10 versions using the machine health and compliance report keywords: health state, antivirus, os platform, windows 10 version, version, health, compliance, state search.product: eADQiWindows 10XVcnh @@ -17,10 +17,10 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Machine health and compliance report in Windows Defender ATP +# Machine health and compliance report in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) [!include[Prerelease information](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine.md b/windows/security/threat-protection/microsoft-defender-atp/machine.md index 40687ef4f7..c118700037 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine.md @@ -18,7 +18,7 @@ ms.topic: article # Machine resource type **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) # Methods @@ -36,17 +36,17 @@ Property | Type | Description :---|:---|:--- id | String | [machine](machine-windows-defender-advanced-threat-protection-new.md) identity. computerDnsName | String | [machine](machine-windows-defender-advanced-threat-protection-new.md) fully qualified name. -firstSeen | DateTimeOffset | First date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Windows Defender ATP. -lastSeen | DateTimeOffset | Last date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Windows Defender ATP. +firstSeen | DateTimeOffset | First date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Microsoft Defender ATP. +lastSeen | DateTimeOffset | Last date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Microsoft Defender ATP. osPlatform | String | OS platform. osVersion | String | OS Version. lastIpAddress | String | Last IP on local NIC on the [machine](machine-windows-defender-advanced-threat-protection-new.md). lastExternalIpAddress | String | Last IP through which the [machine](machine-windows-defender-advanced-threat-protection-new.md) accessed the internet. -agentVersion | String | Version of Windows Defender ATP agent. +agentVersion | String | Version of Microsoft Defender ATP agent. osBuild | Nullable long | OS build number. healthStatus | Enum | [machine](machine-windows-defender-advanced-threat-protection-new.md) health status. Possible values are: "Active", "Inactive", "ImpairedCommunication", "NoSensorData" and "NoSensorDataImpairedCommunication" rbacGroupId | Int | RBAC Group ID. rbacGroupName | String | RBAC Group Name. -riskScore | Nullable Enum | Risk score as evaluated by Windows Defender ATP. Possible values are: 'None', 'Low', 'Medium' and 'High'. +riskScore | Nullable Enum | Risk score as evaluated by Microsoft Defender ATP. Possible values are: 'None', 'Low', 'Medium' and 'High'. aadDeviceId | Nullable Guid | AAD Device ID (when [machine](machine-windows-defender-advanced-threat-protection-new.md) is Aad Joined). machineTags | String collection | Set of [machine](machine-windows-defender-advanced-threat-protection-new.md) tags. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineaction.md b/windows/security/threat-protection/microsoft-defender-atp/machineaction.md index c4f16727e0..66271b6633 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineaction.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineaction.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # MachineAction resource type **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] @@ -35,7 +35,7 @@ Method|Return Type |Description [Restrict app execution](restrict-code-execution-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Restrict application execution. [Remove app restriction](unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Remove application execution restriction. [Run antivirus scan](run-av-scan-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Run an AV scan using Windows Defender (when applicable). -[Offboard machine](offboard-machine-api-windows-defender-advanced-threat-protection-new.md)|[Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Offboard [machine](machine-windows-defender-advanced-threat-protection-new.md) from Windows Defender ATP. +[Offboard machine](offboard-machine-api-windows-defender-advanced-threat-protection-new.md)|[Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Offboard [machine](machine-windows-defender-advanced-threat-protection-new.md) from Microsoft Defender ATP. # Properties Property | Type | Description diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md index 3f4a20dcbc..ef5a31ec33 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md @@ -3,4 +3,4 @@ ms.date: 08/28/2017 author: zavidor --- >[!Note] -> This page focuses on performing a machine action via API. See [take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information about response actions functionality via Windows Defender ATP. +> This page focuses on performing a machine action via API. See [take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information about response actions functionality via Microsoft Defender ATP. diff --git a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md index c94234e9e1..73f5d50ed2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md @@ -1,5 +1,5 @@ --- -title: View and organize the Windows Defender ATP machines list +title: View and organize the Microsoft Defender ATP machines list description: Learn about the available features that you can use from the Machines list such as sorting, filtering, and exporting the list to enhance investigations. keywords: sort, filter, export, csv, machine name, domain, last seen, internal IP, health state, active alerts, active malware detections, threat category, review alerts, network, connection, malware, type, password stealer, ransomware, exploit, threat, general malware, unwanted software search.product: eADQiWindows 10XVcnh @@ -18,14 +18,14 @@ ms.topic: article ms.date: 09/03/2018 --- -# View and organize the Windows Defender ATP Machines list +# View and organize the Microsoft Defender ATP Machines list **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-machinesview-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-machinesview-abovefoldlink) The **Machines list** shows a list of the machines in your network where alerts were generated. By default, the queue displays machines with alerts seen in the last 30 days. @@ -92,6 +92,6 @@ You can filter the list based on the grouping and tagging that you've added to i ## Related topics -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md index fe70b2cba7..85be05b201 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md @@ -1,5 +1,5 @@ --- -title: Manage Windows Defender Advanced Threat Protection alerts +title: Manage Microsoft Defender Advanced Threat Protection alerts description: Change the status of alerts, create suppression rules to hide alerts, submit comments, and review change history for individual alerts with the Manage Alert menu. keywords: manage alerts, manage, alerts, status, new, in progress, resolved, resolve alerts, suppress, supression, rules, context, history, comments, changes search.product: eADQiWindows 10XVcnh @@ -18,14 +18,14 @@ ms.topic: article ms.date: 09/03/2018 --- -# Manage Windows Defender Advanced Threat Protection alerts +# Manage Microsoft Defender Advanced Threat Protection alerts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-managealerts-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-managealerts-abovefoldlink) -Windows Defender ATP notifies you of possible malicious events, attributes, and contextual information through alerts. A summary of new alerts is displayed in the **Security operations dashboard**, and you can access all alerts in the **Alerts queue**. +Microsoft Defender ATP notifies you of possible malicious events, attributes, and contextual information through alerts. A summary of new alerts is displayed in the **Security operations dashboard**, and you can access all alerts in the **Alerts queue**. You can manage alerts by selecting an alert in the **Alerts queue** or the **Alerts related to this machine** section of the machine details view. @@ -41,7 +41,7 @@ If an alert is no yet assigned, you can select **Assign to me** to assign the al ## Suppress alerts -There might be scenarios where you need to suppress alerts from appearing in Windows Defender Security Center. Windows Defender ATP lets you create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. +There might be scenarios where you need to suppress alerts from appearing in Windows Defender Security Center. Microsoft Defender ATP lets you create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. Suppression rules can be created from an existing alert. They can be disabled and reenabled if needed. @@ -118,10 +118,10 @@ Added comments instantly appear on the pane. ## Related topics - [Manage suppression rules](manage-suppression-rules-windows-defender-advanced-threat-protection.md) -- [View and organize the Windows Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Windows Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Windows Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Windows Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Windows Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Windows Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md index 150cd87e78..dc313000a3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md @@ -20,11 +20,11 @@ ms.topic: article # Manage allowed/blocked lists **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionlist-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionlist-abovefoldlink) Create indicators that define the detection, prevention, and exclusion of entities. You can define the action to be taken as well as the duration for when to apply the action as well as the scope of the machine group to apply it to. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md index 3b6362ab90..fa2c696f10 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md @@ -196,4 +196,4 @@ From the panel, you can click on the Open investigation page link to see the inv You also have the option of selecting multiple investigations to approve or reject actions on multiple investigations. ## Related topic -- [Investigate Windows Defender ATP alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender ATP alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md index 5afed1e6df..4960840dca 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md @@ -20,11 +20,11 @@ ms.topic: article # Manage automation allowed/blocked lists **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionlist-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionlist-abovefoldlink) Create a rule to control which entities are automatically incriminated or exonerated during Automated investigations. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md index 84706f7a5a..baf0ac27bb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md @@ -23,11 +23,11 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationefileuploads-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationefileuploads-abovefoldlink) Enable the content analysis capability so that certain files and email attachments can automatically be uploaded to the cloud for additional inspection in Automated investigation. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md index 23133475a4..e63a8c6207 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md @@ -23,11 +23,11 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionfolder-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-automationexclusionfolder-abovefoldlink) Automation folder exclusions allow you to specify folders that the Automated investigation will skip. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md index 8b8fa19749..d03aec8131 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md @@ -1,5 +1,5 @@ --- -title: Manage Windows Defender ATP incidents +title: Manage Microsoft Defender ATP incidents description: Manage incidents by assigning it, updating its status, or setting its classification. keywords: incidents, manage, assign, status, classification, true alert, false alert search.product: eADQiWindows 10XVcnh @@ -18,10 +18,10 @@ ms.topic: article ms.date: 010/08/2018 --- -# Manage Windows Defender ATP incidents +# Manage Microsoft Defender ATP incidents **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Managing incidents is an important part of every cybersecurity operation. You can manage incidents by selecting an incident from the **Incidents queue** or the **Incidents management pane**. You can assign incidents to yourself, change the status, classify, rename, or comment on them to keep track of their progress. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md index 9b89a258e4..2e6bbe1507 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md @@ -1,5 +1,5 @@ --- -title: Manage Windows Defender Advanced Threat Protection suppression rules +title: Manage Microsoft Defender Advanced Threat Protection suppression rules description: Manage suppression rules keywords: manage suppression, rules, rule name, scope, action, alerts, turn on, turn off search.product: eADQiWindows 10XVcnh @@ -22,9 +22,9 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-suppressionrules-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-suppressionrules-abovefoldlink) There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/management-apis.md b/windows/security/threat-protection/microsoft-defender-atp/management-apis.md index c0408e9e5f..fd37543f72 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/management-apis.md +++ b/windows/security/threat-protection/microsoft-defender-atp/management-apis.md @@ -21,38 +21,38 @@ ms.date: 09/03/2018 # Overview of management and APIs **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mgt-apis-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mgt-apis-abovefoldlink) -Windows Defender ATP supports a wide variety of options to ensure that customers can easily adopt the platform. +Microsoft Defender ATP supports a wide variety of options to ensure that customers can easily adopt the platform. -Acknowledging that customer environments and structures can vary, Windows Defender ATP was created with flexibility and granular control to fit varying customer requirements. +Acknowledging that customer environments and structures can vary, Microsoft Defender ATP was created with flexibility and granular control to fit varying customer requirements. -Machine onboarding is fully integrated into System Center Configuration Manager and Microsoft Intune for client machines and Azure Security Center for server machines, providing complete end-to-end experience of configuration, deployment, and monitoring. In addition, Windows Defender ATP supports Group Policy and other third-party tools used for machines management. +Machine onboarding is fully integrated into System Center Configuration Manager and Microsoft Intune for client machines and Azure Security Center for server machines, providing complete end-to-end experience of configuration, deployment, and monitoring. In addition, Microsoft Defender ATP supports Group Policy and other third-party tools used for machines management. -Windows Defender ATP provides fine-grained control over what users with access to the portal can see and do through the flexibility of role-based access control (RBAC). The RBAC model supports all flavors of security teams structure: +Microsoft Defender ATP provides fine-grained control over what users with access to the portal can see and do through the flexibility of role-based access control (RBAC). The RBAC model supports all flavors of security teams structure: - Globally distributed organizations and security teams - Tiered model security operations teams - Fully segregated devisions with single centralized global security operations teams -The Windows Defender ATP solution is built on top of an integration-ready platform: +The Microsoft Defender ATP solution is built on top of an integration-ready platform: - It supports integration with a number of security information and event management (SIEM) solutions and also exposes APIs to fully support pulling all the alerts and detection information into any SIEM solution. - It supports a rich set of application programming interface (APIs) providing flexibility for those who are already heavily invested in data enrichment and automation: - Enriching events coming from other security systems with foot print or prevalence information - Triggering file or machine level response actions through APIs - - Keeping systems in-sync such as importing machine tags from asset management systems into Windows Defender ATP, synchronize alerts and incidents status cross ticketing systems with Windows Defender ATP. + - Keeping systems in-sync such as importing machine tags from asset management systems into Microsoft Defender ATP, synchronize alerts and incidents status cross ticketing systems with Microsoft Defender ATP. An important aspect of machine management is the ability to analyze the environment from varying and broad perspectives. This often helps drive new insights and proper priority identification: - The Secure score dashboard provides metrics based method of prioritizing the most important proactive security measures. -- Windows Defender ATP includes a built-in PowerBI based reporting solution to quickly review trends and details related to Windows Defender ATP alerts and secure score of machines. The platform also supports full customization of the reports, including mashing of Windows Defender ATP data with your own data stream to produce business specific reports. +- Microsoft Defender ATP includes a built-in PowerBI based reporting solution to quickly review trends and details related to Microsoft Defender ATP alerts and secure score of machines. The platform also supports full customization of the reports, including mashing of Microsoft Defender ATP data with your own data stream to produce business specific reports. ## In this section Topic | Description :---|:--- Understand threat intelligence concepts | Learn about alert definitions, indicators of compromise, and other threat intelligence concepts. -Supported Windows Defender ATP APIs | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. +Supported Microsoft Defender ATP APIs | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. Managed security service provider | Get a quick overview on managed security service provider support. @@ -61,9 +61,9 @@ Managed security service provider | Get a quick overview on managed security ser ## Related topics - [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) - [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Windows Defender ATP Public API](use-apis.md) +- [Microsoft Defender ATP Public API](use-apis.md) - [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md) -- [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Create and build Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) - [Role-based access control](rbac-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md index 52627d87be..1256fa301c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-config.md @@ -1,6 +1,6 @@ --- title: Configure Microsoft Cloud App Security integration -description: Learn how to turn on the settings to enable the Windows Defender ATP integration with Microsoft Cloud App Security. +description: Learn how to turn on the settings to enable the Microsoft Defender ATP integration with Microsoft Cloud App Security. keywords: cloud, app, security, settings, integration, discovery, report search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,12 +21,12 @@ ms.date: 10/19/2018 # Configure Microsoft Cloud App Security in Windows **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease�information](prerelease.md)] -To benefit from Windows Defender Advanced Threat Protection (ATP) cloud app discovery signals, turn on Microsoft Cloud App Security integration. +To benefit from Microsoft Defender Advanced Threat Protection (ATP) cloud app discovery signals, turn on Microsoft Cloud App Security integration. >[!NOTE] @@ -40,7 +40,7 @@ To benefit from Windows Defender Advanced Threat Protection (ATP) cloud app disc ![Advanced features](images/atp-mcas-settings.png) -Once activated, Windows Defender ATP will immediately start forwarding discovery signals to Cloud App Security. +Once activated, Microsoft Defender ATP will immediately start forwarding discovery signals to Cloud App Security. ## View the data collected @@ -50,7 +50,7 @@ Once activated, Windows Defender ATP will immediately start forwarding discovery ![Image of menu to cloud discovery dashboard](images/atp-cloud-discovery-dashboard-menu.png) -3. Select **Win10 Endpoint Users report**, which contains the data coming from Windows Defender ATP. +3. Select **Win10 Endpoint Users report**, which contains the data coming from Microsoft Defender ATP. ![Win10 endpoint users](./images/win10-endpoint-users.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md index 6c2400b885..f8990f3871 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md @@ -1,6 +1,6 @@ --- title: Microsoft Cloud App Security integration overview -description: Windows Defender ATP integrates with Cloud App Security by collecting and forwarding all cloud app networking activities, providing unparalleled visibility to cloud app usage +description: Microsoft Defender ATP integrates with Cloud App Security by collecting and forwarding all cloud app networking activities, providing unparalleled visibility to cloud app usage keywords: cloud, app, networking, visibility, usage search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -20,7 +20,7 @@ ms.date: 10/18/2018 # Microsoft Cloud App Security in Windows overview **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease�information](prerelease.md)] @@ -29,17 +29,17 @@ Microsoft Cloud App Security (Cloud App Security) is a comprehensive solution th >[!NOTE] >This feature is available with an E5 license for [Enterprise Mobility + Security](https://www.microsoft.com/cloud-platform/enterprise-mobility-security) on machines running Windows 10 version 1809 or later. -## Windows Defender ATP and Cloud App Security integration +## Microsoft Defender ATP and Cloud App Security integration -Cloud App Security discovery relies on cloud traffic logs being forwarded to it from enterprise firewall and proxy servers. Windows Defender ATP integrates with Cloud App Security by collecting and forwarding all cloud app networking activities, providing unparalleled visibility to cloud app usage. The monitoring functionality is built into the device, providing complete coverage of network activity. +Cloud App Security discovery relies on cloud traffic logs being forwarded to it from enterprise firewall and proxy servers. Microsoft Defender ATP integrates with Cloud App Security by collecting and forwarding all cloud app networking activities, providing unparalleled visibility to cloud app usage. The monitoring functionality is built into the device, providing complete coverage of network activity. The integration provides the following major improvements to the existing Cloud App Security discovery: - Available everywhere - Since the network activity is collected directly from the endpoint, it's available wherever the device is, on or off corporate network, as it's no longer depended on traffic routed through the enterprise firewall or proxy servers. -- Works out of the box, no configuration required - Forwarding cloud traffic logs to Cloud App Security requires firewall and proxy server configuration. With the Windows Defender ATP and Cloud App Security integration, there's no configuration required. Just switch it on in Windows Defender Security Center settings and you're good to go. +- Works out of the box, no configuration required - Forwarding cloud traffic logs to Cloud App Security requires firewall and proxy server configuration. With the Microsoft Defender ATP and Cloud App Security integration, there's no configuration required. Just switch it on in Windows Defender Security Center settings and you're good to go. -- Device context - Cloud traffic logs lack device context. Windows Defender ATP network activity is reported with the device context (which device accessed the cloud app), so you are able to understand exactly where (device) the network activity took place, in addition to who (user) performed it. +- Device context - Cloud traffic logs lack device context. Microsoft Defender ATP network activity is reported with the device context (which device accessed the cloud app), so you are able to understand exactly where (device) the network activity took place, in addition to who (user) performed it. For more information about cloud discovery, see [Working with discovered apps](https://docs.microsoft.com/cloud-app-security/discovered-apps). diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md index 43bb2202f5..4b2be0215b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md @@ -1,7 +1,7 @@ --- -title: Windows Defender Advanced Threat Protection -description: Windows Defender Advanced Threat Protection is an enterprise security platform that helps secops to prevent, detect, investigate, and respond to possible cybersecurity threats related to advanced persistent threats. -keywords: introduction to Windows Defender Advanced Threat Protection, introduction to Windows Defender ATP, cybersecurity, advanced persistent threat, enterprise security, machine behavioral sensor, cloud security, analytics, threat intelligence, attack surface reduction, next generation protection, automated investigation and remediation, microsoft threat experts, secure score, advanced hunting, microsoft threat protection +title: Microsoft Defender Advanced Threat Protection +description: Microsoft Defender Advanced Threat Protection is an enterprise security platform that helps secops to prevent, detect, investigate, and respond to possible cybersecurity threats related to advanced persistent threats. +keywords: introduction to Microsoft Defender Advanced Threat Protection, introduction to Microsoft Defender ATP, cybersecurity, advanced persistent threat, enterprise security, machine behavioral sensor, cloud security, analytics, threat intelligence, attack surface reduction, next generation protection, automated investigation and remediation, microsoft threat experts, secure score, advanced hunting, microsoft threat protection search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -17,18 +17,18 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Windows Defender Advanced Threat Protection +# Microsoft Defender Advanced Threat Protection ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-main-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-main-abovefoldlink) > >For more info about Windows 10 Enterprise Edition features and functionality, see [Windows 10 Enterprise edition](https://www.microsoft.com/WindowsForBusiness/buy). -Windows Defender Advanced Threat Protection is a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. +Microsoft Defender Advanced Threat Protection is a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. -Windows Defender ATP uses the following combination of technology built into Windows 10 and Microsoft's robust cloud service: +Microsoft Defender ATP uses the following combination of technology built into Windows 10 and Microsoft's robust cloud service: - **Endpoint behavioral sensors**: Embedded in Windows 10, these sensors - collect and process behavioral signals from the operating system and sends this sensor data to your private, isolated, cloud instance of Windows Defender ATP. + collect and process behavioral signals from the operating system and sends this sensor data to your private, isolated, cloud instance of Microsoft Defender ATP. - **Cloud security analytics**: Leveraging big-data, machine-learning, and @@ -39,12 +39,12 @@ Windows Defender ATP uses the following combination of technology built into Win - **Threat intelligence**: Generated by Microsoft hunters, security teams, and augmented by threat intelligence provided by partners, threat - intelligence enables Windows Defender ATP to identify attacker + intelligence enables Microsoft Defender ATP to identify attacker tools, techniques, and procedures, and generate alerts when these are observed in collected sensor data. -

Windows Defender ATP

+

Microsoft Defender ATP

- @@ -187,7 +187,7 @@ Microsoft Defender ATP alerts will appear as discrete events, with "Microsoft” > Verify that the connector is running by stopping the process again. Then start the connector again, and no browser window should appear. ## Related topics -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -- [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) +- [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md index 5352b16859..460880caa2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications.md @@ -31,7 +31,7 @@ You can configure Microsoft Defender ATP to send email notifications to specifie > [!NOTE] > Only users with 'Manage security settings' permissions can configure email notifications. If you've chosen to use basic permissions management, users with Security Administrator or Global Administrator roles can configure email notifications. -You can set the alert severity levels that trigger notifications. You can also add or remove recipients of the email notification. New recipients get notified about alerts encountered after they are added. For more information about alerts, see [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md). +You can set the alert severity levels that trigger notifications. You can also add or remove recipients of the email notification. New recipients get notified about alerts encountered after they are added. For more information about alerts, see [View and organize the Alerts queue](alerts-queue.md). If you're using role-based access control (RBAC), recipients will only receive notifications based on the machine groups that were configured in the notification rule. Users with the proper permission can only create, edit, or delete notifications that are limited to their machine group management scope. @@ -57,7 +57,7 @@ You can create rules that determine the machines and alert severities to send em >[!NOTE] > This information might be processed by recipient mail servers that ar not in the geographic location you have selected for your Microsoft Defender ATP data. - - **Machines** - Choose whether to notify recipients for alerts on all machines (Global administrator role only) or on selected machine groups. For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). + - **Machines** - Choose whether to notify recipients for alerts on all machines (Global administrator role only) or on selected machine groups. For more information, see [Create and manage machine groups](machine-groups.md). - **Alert severity** - Choose the alert severity level. 4. Click **Next**. @@ -99,7 +99,7 @@ This section lists various issues that you may encounter when using email notifi 3. Check your email application rules that might be catching and moving your Microsoft Defender ATP email notifications. ## Related topics -- [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) -- [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Update data retention settings](data-retention-settings.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +- [Enable Secure Score security controls](enable-secure-score.md) +- [Configure advanced features](advanced-features.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md index 03ef4fb943..9a81c74448 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md @@ -63,7 +63,7 @@ ms.date: 04/24/2018 9. Click **OK** and close any open GPMC windows. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that the machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that the machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md). ## Additional Microsoft Defender ATP configuration settings For each machine, you can state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. @@ -141,9 +141,9 @@ With Group Policy there isn’t an option to monitor deployment of policies on t ## Related topics -- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Microsoft Defender ATP machines](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm.md) +- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm.md) +- [Onboard Windows 10 machines using a local script](configure-endpoints-script.md) +- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machines](run-detection-test.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md index b4aa4e7b94..01b6ee0ef8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md @@ -49,7 +49,7 @@ For more information on using Microsoft Defender ATP CSP see, [WindowsAdvancedTh >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that a machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that a machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md). ## Offboard and monitor machines using Mobile Device Management tools For security reasons, the package used to Offboard machines will expire 30 days after the date it was downloaded. Expired offboarding packages sent to a machine will be rejected. When downloading an offboarding package you will be notified of the packages expiry date and it will also be included in the package name. @@ -79,9 +79,9 @@ For security reasons, the package used to Offboard machines will expire 30 days > Offboarding causes the machine to stop sending sensor data to the portal but data from the machine, including reference to any alerts it has had will be retained for up to 6 months. ## Related topics -- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp.md) +- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm.md) +- [Onboard Windows 10 machines using a local script](configure-endpoints-script.md) +- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md index 11e887fd72..f3d4f3bdce 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md @@ -71,7 +71,7 @@ To effectively offboard the machine from the service, you'll need to disable the >If you decide to turn on the third-party integration again after disabling the integration, you'll need to regenerate the token and reapply it on machines. ## Related topics -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) -- [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Onboard Windows 10 machines](configure-endpoints.md) +- [Onboard servers](configure-server-endpoints.md) +- [Configure proxy and Internet connectivity settings](configure-proxy-internet.md) +- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md index 509661ca90..4790139b77 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md @@ -69,7 +69,7 @@ You can use existing System Center Configuration Manager functionality to create > Microsoft Defender ATP doesn't support onboarding during the [Out-Of-Box Experience (OOBE)](https://answers.microsoft.com/en-us/windows/wiki/windows_10/how-to-complete-the-windows-10-out-of-box/47e3f943-f000-45e3-8c5c-9d85a1a0cf87) phase. Make sure users complete OOBE after running Windows installation or upgrading. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md). ### Configure sample collection settings For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. @@ -140,7 +140,7 @@ Monitoring with SCCM consists of two parts: 4. Review the status indicators under **Completion Statistics** and **Content Status**. -If there are failed deployments (machines with **Error**, **Requirements Not Met**, or **Failed statuses**), you may need to troubleshoot the machines. For more information see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). +If there are failed deployments (machines with **Error**, **Requirements Not Met**, or **Failed statuses**), you may need to troubleshoot the machines. For more information see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md). ![SCCM showing successful deployment with no errors](images/sccm-deployment.png) @@ -158,9 +158,9 @@ Value: “1” For more information about System Center Configuration Manager Compliance see [Get started with compliance settings in System Center Configuration Manager](https://docs.microsoft.com/sccm/compliance/get-started/get-started-with-compliance-settings). ## Related topics -- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp.md) +- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm.md) +- [Onboard Windows 10 machines using a local script](configure-endpoints-script.md) +- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md index 88cd708b56..d18d805cd6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md @@ -32,7 +32,7 @@ ms.topic: article You can also manually onboard individual machines to Microsoft Defender ATP. You might want to do this first when testing the service before you commit to onboarding all machines in your network. > [!NOTE] -> The script has been optimized to be used on a limited number of machines (1-10 machines). To deploy to scale, use other deployment options. For more information on using other deployment options, see [Onboard Window 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). +> The script has been optimized to be used on a limited number of machines (1-10 machines). To deploy to scale, use other deployment options. For more information on using other deployment options, see [Onboard Window 10 machines](configure-endpoints.md). ## Onboard machines 1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): @@ -60,11 +60,11 @@ You can also manually onboard individual machines to Microsoft Defender ATP. You 5. Press the **Enter** key or click **OK**. -For information on how you can manually validate that the machine is compliant and correctly reports sensor data see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md). +For information on how you can manually validate that the machine is compliant and correctly reports sensor data see, [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md). >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test.md). ## Configure sample collection settings For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. @@ -122,7 +122,7 @@ For security reasons, the package used to Offboard machines will expire 30 days ## Monitor machine configuration -You can follow the different verification steps in the [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) to verify that the script completed successfully and the agent is running. +You can follow the different verification steps in the [Troubleshoot onboarding issues](troubleshoot-onboarding.md) to verify that the script completed successfully and the agent is running. Monitoring can also be done directly on the portal, or by using the different deployment tools. @@ -135,9 +135,9 @@ Monitoring can also be done directly on the portal, or by using the different de ## Related topics -- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp.md) +- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm.md) +- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm.md) +- [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md index 95c0a67fb9..9bcaf00305 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md @@ -91,10 +91,10 @@ You can onboard VDI machines using a single entry or multiple entries for each m 8. Use the search function by entering the machine name and select **Machine** as search type. ## Related topics -- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines using Group Policy](configure-endpoints-gp.md) +- [Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm.md) +- [Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm.md) +- [Onboard Windows 10 machines using a local script](configure-endpoints-script.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md index 69ddf03031..3507beb090 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints.md @@ -39,11 +39,11 @@ The following deployment tools and methods are supported: ## In this section Topic | Description :---|:--- -[Onboard Windows 10 machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md) | Use Group Policy to deploy the configuration package on machines. -[Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md) | You can use either use System Center Configuration Manager (current branch) version 1606 or System Center Configuration Manager(current branch) version 1602 or earlier to deploy the configuration package on machines. -[Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md) | Use Mobile Device Management tools or Microsoft Intune to deploy the configuration package on machine. -[Onboard Windows 10 machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md) | Learn how to use the local script to deploy the configuration package on endpoints. -[Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md) | Learn how to use the configuration package to configure VDI machines. +[Onboard Windows 10 machines using Group Policy](configure-endpoints-gp.md) | Use Group Policy to deploy the configuration package on machines. +[Onboard Windows 10 machines using System Center Configuration Manager](configure-endpoints-sccm.md) | You can use either use System Center Configuration Manager (current branch) version 1606 or System Center Configuration Manager(current branch) version 1602 or earlier to deploy the configuration package on machines. +[Onboard Windows 10 machines using Mobile Device Management tools](configure-endpoints-mdm.md) | Use Mobile Device Management tools or Microsoft Intune to deploy the configuration package on machine. +[Onboard Windows 10 machines using a local script](configure-endpoints-script.md) | Learn how to use the local script to deploy the configuration package on endpoints. +[Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi.md) | Learn how to use the configuration package to configure VDI machines. >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configureendpoints-belowfoldlink) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md index abe48eeec7..a5a9380158 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md @@ -83,9 +83,9 @@ Grant the guest user access and permissions to your Microsoft Defender Security Granting access to guest user is done the same way as granting access to a user who is a member of your tenant. -If you're using basic permissions to access the portal, the guest user must be assigned a Security Administrator role in **your** tenant. For more information, see [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md). +If you're using basic permissions to access the portal, the guest user must be assigned a Security Administrator role in **your** tenant. For more information, see [Use basic permissions to access the portal](basic-permissions.md). -If you're using role-based access control (RBAC), the guest user must be to added to the appropriate group or groups in **your** tenant. Fore more information on RBAC in Microsoft Defender ATP, see [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md). +If you're using role-based access control (RBAC), the guest user must be to added to the appropriate group or groups in **your** tenant. Fore more information on RBAC in Microsoft Defender ATP, see [Manage portal access using RBAC](rbac.md). >[!NOTE] >There is no difference between the Member user and Guest user roles from RBAC perspective. @@ -123,7 +123,7 @@ Use the following steps to obtain the MSSP customer tenant ID and then use the I After access the portal is granted, alert notification rules can to be created so that emails are sent to MSSPs when alerts associated with the tenant are created and set conditions are met. -For more information, see [Create rules for alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md#create-rules-for-alert-notifications). +For more information, see [Create rules for alert notifications](configure-email-notifications.md#create-rules-for-alert-notifications). These check boxes must be checked: - **Include organization name** - The customer name will be added to email notifications @@ -272,17 +272,17 @@ You'll need to have **Manage portal system settings** permission to whitelist th 5. Click **Authorize application**. -You can now download the relevant configuration file for your SIEM and connect to the Microsoft Defender ATP API. For more information see, [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md). +You can now download the relevant configuration file for your SIEM and connect to the Microsoft Defender ATP API. For more information see, [Pull alerts to your SIEM tools](configure-siem.md). - In the ArcSight configuration file / Splunk Authentication Properties file – you will have to write your application key manually by settings the secret value. - Instead of acquiring a refresh token in the portal, use the script from the previous step to acquire a refresh token (or acquire it by other means). ## Fetch alerts from MSSP customer's tenant using APIs -For information on how to fetch alerts using REST API, see [Pull alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md). +For information on how to fetch alerts using REST API, see [Pull alerts using REST API](pull-alerts-using-rest-api.md). ## Related topics -- [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) -- [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md) -- [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md) -- [Pull alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Use basic permissions to access the portal](basic-permissions.md) +- [Manage portal access using RBAC](rbac.md) +- [Pull alerts to your SIEM tools](configure-siem.md) +- [Pull alerts using REST API](pull-alerts-using-rest-api.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md index bc9f3d4a50..46c3f745a8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md @@ -169,5 +169,5 @@ However, if the connectivity check results indicate a failure, an HTTP error is > When the TelemetryProxyServer is set, in Registry or via Group Policy, Microsoft Defender ATP will fall back to direct if it can't access the defined proxy. ## Related topics -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines](configure-endpoints.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md index 5150173b16..bdd5095876 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md @@ -70,7 +70,7 @@ You'll need to tak the following steps if you choose to onboard servers through - If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), simply attach the Microsoft Monitoring Agent (MMA) to report to your Microsoft Defender ATP workspace through Multi Homing support. Otherwise, install and configure MMA to report sensor data to Microsoft Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent). >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test.md). ### Configure and update System Center Endpoint Protection clients >[!IMPORTANT] @@ -135,9 +135,9 @@ Supported tools include: - System Center Configuration Manager 2012 / 2012 R2 1511 / 1602 - VDI onboarding scripts for non-persistent machines - For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). Support for Windows Server, version 1803 and Windows 2019 provides deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well. + For more information, see [Onboard Windows 10 machines](configure-endpoints.md). Support for Windows Server, version 1803 and Windows 2019 provides deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well. -1. Configure Microsoft Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). +1. Configure Microsoft Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints.md). 2. If you’re running a third party antimalware solution, you'll need to apply the following Windows Defender AV passive mode settings and verify it was configured correctly: @@ -231,8 +231,8 @@ To offboard the server, you can use either of the following methods: ``` ## Related topics -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) -- [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md) -- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines](configure-endpoints.md) +- [Onboard non-Windows machines](configure-endpoints-non-windows.md) +- [Configure proxy and Internet connectivity settings](configure-proxy-internet.md) +- [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test.md) +- [Troubleshooting Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md index 1cc071a515..c5e8719018 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md @@ -37,27 +37,27 @@ Microsoft Defender ATP currently supports the following SIEM tools: To use either of these supported SIEM tools you'll need to: -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) - Configure the supported SIEM tool: - - [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) - - [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) + - [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) + - [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) -For more information on the list of fields exposed in the alerts API see, [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md). +For more information on the list of fields exposed in the alerts API see, [Microsoft Defender ATP alert API fields](api-portal-mapping.md). ## Pull Microsoft Defender ATP alerts using REST API Microsoft Defender ATP supports the OAuth 2.0 protocol to pull alerts using REST API. -For more information, see [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md). +For more information, see [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md). ## In this section Topic | Description :---|:--- -[Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)| Learn about enabling the SIEM integration feature in the **Settings** page in the portal so that you can use and generate the required information to configure supported SIEM tools. -[Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md)| Learn about installing the REST API Modular Input app and other configuration settings to enable Splunk to pull Microsoft Defender ATP alerts. -[Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)| Learn about installing the HP ArcSight REST FlexConnector package and the files you need to configure ArcSight to pull Microsoft Defender ATP alerts. -[Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) | Understand what data fields are exposed as part of the alerts API and how they map to Microsoft Defender Security Center. -[Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) | Use the Client credentials OAuth 2.0 flow to pull alerts from Microsoft Defender ATP using REST API. -[Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) | Address issues you might encounter when using the SIEM integration feature. +[Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md)| Learn about enabling the SIEM integration feature in the **Settings** page in the portal so that you can use and generate the required information to configure supported SIEM tools. +[Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md)| Learn about installing the REST API Modular Input app and other configuration settings to enable Splunk to pull Microsoft Defender ATP alerts. +[Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md)| Learn about installing the HP ArcSight REST FlexConnector package and the files you need to configure ArcSight to pull Microsoft Defender ATP alerts. +[Microsoft Defender ATP alert API fields](api-portal-mapping.md) | Understand what data fields are exposed as part of the alerts API and how they map to Microsoft Defender Security Center. +[Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) | Use the Client credentials OAuth 2.0 flow to pull alerts from Microsoft Defender ATP using REST API. +[Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) | Address issues you might encounter when using the SIEM integration feature. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md index a59e0fb017..6e5283c7f0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md @@ -34,7 +34,7 @@ You'll need to configure Splunk so that it can pull Microsoft Defender ATP alert ## Before you begin - Install the [REST API Modular Input app](https://splunkbase.splunk.com/app/1546/) in Splunk. -- Make sure you have enabled the **SIEM integration** feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- Make sure you have enabled the **SIEM integration** feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) - Have the details file you saved from enabling the **SIEM integration** feature ready. You'll need to get the following values: - OAuth 2 Token refresh URL @@ -146,8 +146,8 @@ Use the solution explorer to view alerts in Splunk. >```source="rest://windows atp alerts" | spath | dedup _raw | table *``` ## Related topics -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -- [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) +- [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md index 4d6bed28ef..f21867e552 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md +++ b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Alerts investigation' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Alerts investigation' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md index 8da5ea770d..daf80ba68b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md @@ -32,7 +32,7 @@ ms.date: 04/24/2018 You can define custom alert definitions and indicators of compromise (IOC) using the threat intelligence API. Creating custom threat intelligence alerts allows you to generate specific alerts that are applicable to your organization. ## Before you begin -Before creating custom alerts, you'll need to enable the threat intelligence application in Azure Active Directory and generate access tokens. For more information, see [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md). +Before creating custom alerts, you'll need to enable the threat intelligence application in Azure Active Directory and generate access tokens. For more information, see [Enable the custom threat intelligence application](enable-custom-ti.md). ### Use the threat intelligence REST API to create custom threat intelligence alerts You can call and specify the resource URLs using one of the following operations to access and manipulate a threat intelligence resource: @@ -71,7 +71,7 @@ Make an HTTP POST request to the token issuing endpoint with the following param > The authorization server URL is `https://login.windows.net//oauth2/token`. Replace `` with your Azure Active Directory tenant ID. >[!NOTE] -> The ``, ``, and the `` are all provided to you when enabling the custom threat intelligence application. For more information, see [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md). +> The ``, ``, and the `` are all provided to you when enabling the custom threat intelligence application. For more information, see [Enable the custom threat intelligence application](enable-custom-ti.md). ``` @@ -405,14 +405,14 @@ These parameters are compatible with the [OData V4 query language](http://docs.o ## Code examples The following articles provide detailed code examples that demonstrate how to use the custom threat intelligence API in several programming languages: -- [PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples](python-example-code-windows-defender-advanced-threat-protection.md) +- [PowerShell code examples](powershell-example-code.md) +- [Python code examples](python-example-code.md) ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md index 76c3d3e1cb..eac5c12814 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/data-retention-settings.md @@ -41,8 +41,8 @@ During the onboarding process, a wizard takes you through the general settings o ## Related topics -- [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) -- [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md) +- [Update data retention settings](data-retention-settings.md) +- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +- [Enable Secure Score security controls](enable-secure-score.md) +- [Configure advanced features](advanced-features.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md index d450893080..5f4decb253 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md @@ -41,16 +41,16 @@ Before you can create custom threat intelligence (TI) using REST API, you'll nee >[!WARNING] >The client secret is only displayed once. Make sure you keep a copy of it in a safe place.
- For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md#learn-how-to-get-a-new-client-secret). + For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti.md#learn-how-to-get-a-new-client-secret). 4. Select **Generate tokens** to get an access and refresh token. You’ll need to use the access token in the Authorization header when doing REST API calls. ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md index bf2bbbf003..7d87930ea5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-secure-score.md @@ -39,8 +39,8 @@ Set the baselines for calculating the score of Windows Defender security control 3. Click **Save preferences**. ## Related topics -- [View the Secure Score dashboard](secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [Update data retention settings for Microsoft Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Configure advanced features in Microsoft Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) +- [View the Secure Score dashboard](secure-score-dashboard.md) +- [Update data retention settings for Microsoft Defender ATP](data-retention-settings.md) +- [Configure alert notifications in Microsoft Defender ATP](configure-email-notifications.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +- [Configure advanced features in Microsoft Defender ATP](advanced-features.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md index 333a44a06f..14f0555964 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md @@ -44,7 +44,7 @@ Enable security information and event management (SIEM) integration so you can p > [!WARNING] >The client secret is only displayed once. Make sure you keep a copy of it in a safe place.
- For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md#learn-how-to-get-a-new-client-secret). + For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti.md#learn-how-to-get-a-new-client-secret). ![Image of SIEM integration from Settings menu](images/siem_details.png) @@ -70,8 +70,8 @@ You can now proceed with configuring your SIEM solution or connecting to the ale You can configure IBM QRadar to collect alerts from Microsoft Defender ATP. For more information, see [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_dsm_guide_MS_Win_Defender_ATP_overview.html?cp=SS42VS_7.3.1). ## Related topics -- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -- [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) +- [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) +- [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md index b6e868da21..cf3bab142d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md +++ b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md @@ -88,7 +88,7 @@ This URL will match that seen in the Firewall or network activity.
- + @@ -96,14 +96,14 @@ The service could not contact the external processing servers at that URL. +See [Onboard Windows 10 machines](configure-endpoints.md). +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -111,21 +111,21 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- +See [Onboard Windows 10 machines](configure-endpoints.md). +See [Onboard Windows 10 machines](configure-endpoints.md). +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -151,15 +151,15 @@ It may take several hours for the machine to appear in the portal. - + - +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -186,7 +186,7 @@ If this error persists after a system restart, ensure all Windows updates have f +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -194,23 +194,23 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- +See [Onboard Windows 10 machines](configure-endpoints.md). - +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -223,14 +223,14 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- - + @@ -249,9 +249,9 @@ If the identifier does not persist, the same machine might appear twice in the p - +See [Onboard Windows 10 machines](configure-endpoints.md). @@ -345,6 +345,6 @@ See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced- >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-eventerrorcodes-belowfoldlink) ## Related topics -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) -- [Troubleshoot Microsoft Defender ATP](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines](configure-endpoints.md) +- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) +- [Troubleshoot Microsoft Defender ATP](troubleshoot-onboarding.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md index b6eee8768f..46b9862de4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md @@ -31,14 +31,14 @@ ms.date: 11/09/2017 With the Microsoft Defender ATP threat intelligence API, you can create custom threat intelligence alerts that can help you keep track of possible attack activities in your organization. -For more information about threat intelligence concepts, see [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md). +For more information about threat intelligence concepts, see [Understand threat intelligence concepts](threat-indicator-concepts.md). This article demonstrates an end-to-end usage of the threat intelligence API to get you started in using the threat intelligence API. You'll be guided through sample steps so you can experience how the threat intelligence API feature works. Sample steps include creating alerts definitions and indicators of compromise (IOCs), and examples of how triggered custom TI alerts look like. ## Step 1: Enable the threat intelligence API and obtain authentication details -To use the threat intelligence API feature, you'll need to enable the feature. For more information, see [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md). +To use the threat intelligence API feature, you'll need to enable the feature. For more information, see [Enable the custom threat intelligence application](enable-custom-ti.md). This step is required to generate security credentials that you need to use while working with the API. @@ -153,9 +153,9 @@ This step will guide you in exploring the custom alert in the portal. > There is a latency time of approximately 20 minutes between the time a custom TI is introduced and when it becomes effective. ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md index f94e8cbf84..5d6e59a7c2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md @@ -43,7 +43,7 @@ This page explains how to create an AAD application, get an access token to Micr >[!NOTE] > When accessing Microsoft Defender ATP API on behalf of a user, you will need the correct App permission and user permission. -> If you are not familiar with user permissions on Microsoft Defender ATP, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). +> If you are not familiar with user permissions on Microsoft Defender ATP, see [Manage portal access using role-based access control](rbac.md). >[!TIP] > If you have the permission to perform an action in the portal, you have the permission to perform the action in the API. diff --git a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md index d46afc1621..04009c5fae 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip.md @@ -40,8 +40,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md index ba0614caa3..5c2458d459 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md +++ b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md @@ -61,10 +61,10 @@ This status indicates that there's limited communication between the machine and The following suggested actions can help fix issues related to a misconfigured machine with impaired communications: -- [Ensure the machine has Internet connection](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#troubleshoot-onboarding-issues-on-the-machine)
+- [Ensure the machine has Internet connection](troubleshoot-onboarding.md#troubleshoot-onboarding-issues-on-the-machine)
The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. If you took corrective actions and the machine status is still misconfigured, [open a support ticket](https://go.microsoft.com/fwlink/?LinkID=761093&clcid=0x409). @@ -73,19 +73,19 @@ If you took corrective actions and the machine status is still misconfigured, [o A misconfigured machine with status ‘No sensor data’ has communication with the service but can only report partial sensor data. Follow theses actions to correct known issues related to a misconfigured machine with status ‘No sensor data’: -- [Ensure the machine has Internet connection](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#troubleshoot-onboarding-issues-on-the-machine)
+- [Ensure the machine has Internet connection](troubleshoot-onboarding.md#troubleshoot-onboarding-issues-on-the-machine)
The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. -- [Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostics-service-is-enabled)
+- [Ensure the diagnostic data service is enabled](troubleshoot-onboarding.md#ensure-the-diagnostics-service-is-enabled)
If the machines aren't reporting correctly, you might need to check that the Windows 10 diagnostic data service is set to automatically start and is running on the endpoint. -- [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy)
+- [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy)
If your machines are running a third-party antimalware client, the Microsoft Defender ATP agent needs the Windows Defender Antivirus Early Launch Antimalware (ELAM) driver to be enabled. If you took corrective actions and the machine status is still misconfigured, [open a support ticket](https://go.microsoft.com/fwlink/?LinkID=761093&clcid=0x409). ## Related topic -- [Check sensor health state in Microsoft Defender ATP](check-sensor-status-windows-defender-advanced-threat-protection.md) +- [Check sensor health state in Microsoft Defender ATP](check-sensor-status.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md index bbd89aa3a9..270323aae6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md index 1fca507328..b61db5a4e3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info.md @@ -35,8 +35,8 @@ Delegated (work or school account) | URL.Read.All | 'Read URLs' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md index 9bbfea2471..de2acd3731 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info.md @@ -35,8 +35,8 @@ Delegated (work or school account) | File.Read.All | 'Read file profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md index 097a942506..17b8139faf 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info.md @@ -36,8 +36,8 @@ Delegated (work or school account) | Ip.Read.All | 'Read IP address profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md index 67b08cb95f..c706b3635e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md index 13feffeb9e..1402b61b4e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info.md @@ -36,8 +36,8 @@ Delegated (work or school account) | User.Read.All | 'Read user profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md index f75ea370fe..6fb1bbbf17 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md @@ -42,8 +42,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The response will include only alerts that are associated with machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- The response will include only alerts that are associated with machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md index 5ba64ec4c7..6e1478cb72 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md @@ -42,8 +42,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md index 5d423ce391..b6ee9ba801 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md index ae79790f9a..de9444bbd7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics.md @@ -36,7 +36,7 @@ Delegated (work or school account) | URL.Read.All | 'Read URLs' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md index 35e9289aa3..0315a79f79 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md @@ -37,7 +37,7 @@ Delegated (work or school account) | File.Read.All | 'Read all file profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md index 5df7bcbdb8..f3709ad133 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md @@ -40,8 +40,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md index 389c9e1c36..599b60b82e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md @@ -39,8 +39,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md index 674203724b..f828a524f3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics.md @@ -40,7 +40,7 @@ Delegated (work or school account) | File.Read.All | 'Read file profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md index 41683118e7..28b400897f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md index a1ab48a5a3..a8875b7324 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md index 1a1062304c..4fae9d2d61 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics.md @@ -38,7 +38,7 @@ Delegated (work or school account) | Ip.Read.All | 'Read IP address profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md index 57cb51ba8b..017460ba7e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md @@ -39,8 +39,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md index 0315fbb35c..a4233e222f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md @@ -36,8 +36,8 @@ Delegated (work or school account) | User.Read.All | 'Read user profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include users only if the machine is visible to the user, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include users only if the machine is visible to the user, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md index 19f9e99ebc..0250ee9a19 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md index ac88ef7f97..3cb8e46926 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md @@ -39,7 +39,7 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md index c91a221921..9bfc5cab5b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md @@ -42,7 +42,7 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md index d7104b407e..6d6a921754 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md @@ -39,8 +39,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines,that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md index aad27c712c..b4e18b9069 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md @@ -35,8 +35,8 @@ Delegated (work or school account) | Machine.CollectForensics | 'Collect forensi >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-started.md b/windows/security/threat-protection/microsoft-defender-atp/get-started.md index cc12829160..f2607a0544 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-started.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-started.md @@ -58,10 +58,10 @@ Bring the power of Microsoft Threat Protection to your organization. ## In this section Topic | Description :---|:--- -[Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md) | Learn about the requirements for onboarding machines to the platform. -[Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md) | Get guidance on how to check that licenses have been provisioned to your organization and how to access the portal for the first time. -[Preview features](preview-windows-defender-advanced-threat-protection.md) | Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. -[Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) | Explains the data storage and privacy details related to Microsoft Defender ATP. -[Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md) | Set permissions to manage who can access the portal. You can set basic permissions or set granular permissions using role-based access control (RBAC). +[Minimum requirements](minimum-requirements.md) | Learn about the requirements for onboarding machines to the platform. +[Validate licensing and complete setup](licensing.md) | Get guidance on how to check that licenses have been provisioned to your organization and how to access the portal for the first time. +[Preview features](preview.md) | Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. +[Data storage and privacy](data-storage-privacy.md) | Explains the data storage and privacy details related to Microsoft Defender ATP. +[Assign user access to the portal](assign-portal-access.md) | Set permissions to manage who can access the portal. You can set basic permissions or set granular permissions using role-based access control (RBAC). [Evaluate Microsoft Defender ATP](evaluate-atp.md) | Evaluate the various capabilities in Microsoft Defender ATP and test features out. -[Access the Microsoft Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file +[Access the Microsoft Defender Security Center Community Center](community.md) | The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md index ad8a4ad671..0761a2dfb9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only alerts, associated with machines, that the user have access to, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md index ee24ebc6e3..9562240757 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- Response will include only machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) +>- Response will include only machines that the user can access, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md index 3ac978d6bd..9ac051b1dd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/incidents-queue.md @@ -32,7 +32,7 @@ Microsoft Defender ATP applies correlation analytics and aggregates all related Topic | Description :---|:--- [View and organize the Incidents queue](view-incidents-queue.md)| See the list of incidents and learn how to apply filters to limit the list and get a more focused view. -[Manage incidents](manage-incidents-windows-defender-advanced-threat-protection.md) | Learn how to manage incidents by assigning it, updating its status, or setting its classification and other actions. -[Investigate incidents](investigate-incidents-windows-defender-advanced-threat-protection.md)| See associated alerts, manage the incident, see alert metadata, and visualizations to help you investigate an incident. +[Manage incidents](manage-incidents.md) | Learn how to manage incidents by assigning it, updating its status, or setting its classification and other actions. +[Investigate incidents](investigate-incidents.md)| See associated alerts, manage the incident, see alert metadata, and visualizations to help you investigate an incident. diff --git a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md index fad5873fe4..6a3739e714 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md @@ -38,7 +38,7 @@ Microsoft Defender ATP applies two methods to discover and protect data: ## Data discovery -Microsoft Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Microsoft Defender Security Center. For more information, see [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md#azure-information-protection). +Microsoft Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Microsoft Defender Security Center. For more information, see [Configure advanced features](advanced-features.md#azure-information-protection). ![Image of settings page with Azure Information Protection](images/atp-settings-aip.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md index 13ed50b836..dbf0d58497 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation.md @@ -26,11 +26,11 @@ ms.topic: article Initiate AutoIR investigation on a machine. >[!Note] -> This page focuses on performing an automated investigation on a machine. See [Automated Investigation](automated-investigations-windows-defender-advanced-threat-protection.md) for more information. +> This page focuses on performing an automated investigation on a machine. See [Automated Investigation](automated-investigations.md) for more information. ## Limitations 1. The number of executions is limited (up to 5 calls per hour). -2. For Automated Investigation limitations, see [Automated Investigation](automated-investigations-windows-defender-advanced-threat-protection.md). +2. For Automated Investigation limitations, see [Automated Investigation](automated-investigations.md). ## Permissions One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) @@ -42,8 +42,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md index fd445e7665..275fc11cea 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts.md @@ -32,14 +32,14 @@ Investigate alerts that are affecting your network, understand what they mean, a Click an alert to see the alert details view and the various tiles that provide information about the alert. -You can also manage an alert and see alert metadata along with other information that can help you make better decisions on how to approach them. You'll also see a status of the automated investigation on the upper right corner. Clicking on the link will take you to the Automated investigations view. For more information, see [Automated investigations](automated-investigations-windows-defender-advanced-threat-protection.md). +You can also manage an alert and see alert metadata along with other information that can help you make better decisions on how to approach them. You'll also see a status of the automated investigation on the upper right corner. Clicking on the link will take you to the Automated investigations view. For more information, see [Automated investigations](automated-investigations.md). ![Image of the alert page](images/atp-alert-view.png) The alert context tile shows the where, who, and when context of the alert. As with other pages, you can click on the icon beside the name or user account to bring up the machine or user details pane. The alert details view also has a status tile that shows the status of the alert in the queue. You'll also see a description and a set of recommended actions which you can expand. -For more information about managing alerts, see [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md). +For more information about managing alerts, see [Manage alerts](manage-alerts.md). The alert details page also shows the alert process tree, an incident graph, and an artifact timeline. @@ -93,12 +93,12 @@ The **Artifact timeline** feature provides an addition view of the evidence that Selecting an alert detail brings up the **Details pane** where you'll be able to see more information about the alert such as file details, detections, instances of it observed worldwide, and in the organization. ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md index 14ceae480d..283772ed84 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-domain.md @@ -60,10 +60,10 @@ The **Most recent observed machinew with URL** section provides a chronological 5. Clicking any of the machine names will take you to that machine's view, where you can continue investigate reported alerts, behaviors, and events. ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md index 3f570b3926..fc752990fc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-files.md @@ -41,9 +41,9 @@ You can get information from the following sections in the file view: - Most recent observed machines with file ## File worldwide and Deep analysis -The file details, malware detection, and prevalence worldwide sections display various attributes about the file. You’ll see actions you can take on the file. For more information on how to take action on a file, see [Take response action on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md). +The file details, malware detection, and prevalence worldwide sections display various attributes about the file. You’ll see actions you can take on the file. For more information on how to take action on a file, see [Take response action on a file](respond-file-alerts.md). -You'll see details such as the file’s MD5, the VirusTotal detection ratio and Windows Defender AV detection if available, and the file’s prevalence worldwide. You'll also be able to [submit a file for deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis). +You'll see details such as the file’s MD5, the VirusTotal detection ratio and Windows Defender AV detection if available, and the file’s prevalence worldwide. You'll also be able to [submit a file for deep analysis](respond-file-alerts.md#deep-analysis). ![Image of file information](images/atp-file-information.png) @@ -65,10 +65,10 @@ The **Most recent observed machines with the file** section allows you to specif This allows for greater accuracy in defining entities to display such as if and when an entity was observed in the organization. For example, if you’re trying to identify the origin of a network communication to a certain IP Address within a 10-minute period on a given date, you can specify that exact time interval, and see only files that communicated with that IP Address at that time, drastically reducing unnecessary scrolling and searching. ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md index cb3221071a..cddaa7e5f6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents.md @@ -44,10 +44,10 @@ Alerts are grouped into incidents based on the following reasons: ![Image of alerts tab with incident details page showing the reasons the alerts were linked together in that incident](images/atp-incidents-alerts-reason.png) -You can also manage an alert and see alert metadata along with other information. For more information, see [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md). +You can also manage an alert and see alert metadata along with other information. For more information, see [Investigate alerts](investigate-alerts.md). ### Machines -You can also investigate the machines that are part of, or related to, a given incident. For more information, see [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md). +You can also investigate the machines that are part of, or related to, a given incident. For more information, see [Investigate machines](investigate-machines.md). ![Image of machines tab in incident details page](images/atp-incident-machine-tab.png) @@ -77,6 +77,6 @@ You can click the circles on the incident graph to view the details of the malic ## Related topics - [Incidents queue](incidents-queue.md) - [View and organize the Incidents queue](view-incidents-queue.md) -- [Manage incidents](manage-incidents-windows-defender-advanced-threat-protection.md) +- [Manage incidents](manage-incidents.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md index 0d5a09260c..fda84c5cce 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-ip.md @@ -67,10 +67,10 @@ Use the search filters to define the search criteria. You can also use the timel Clicking any of the machine names will take you to that machine's view, where you can continue investigate reported alerts, behaviors, and events. ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md index 8ca174ec64..c8a7e86f97 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-machines.md @@ -30,9 +30,9 @@ Investigate the details of an alert raised on a specific machine to identify oth You can click on affected machines whenever you see them in the portal to open a detailed report about that machine. Affected machines are identified in the following areas: -- The [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- The [Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md) -- The [Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) +- The [Machines list](investigate-machines.md) +- The [Alerts queue](alerts-queue.md) +- The [Security operations dashboard](security-operations-dashboard.md) - Any individual alert - Any individual file details view - Any IP address or domain details view @@ -49,7 +49,7 @@ The machine details, logged on users, machine risk, and machine reporting sectio **Machine details**
The machine details tile provides information such as the domain and OS of the machine. If there's an investigation package available on the machine, you'll see a link that allows you to download the package. -For more information on how to take action on a machine, see [Take response action on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md). +For more information on how to take action on a machine, see [Take response action on a machine](respond-machine-alerts.md). **Logged on users**
@@ -62,7 +62,7 @@ Clicking on the logged on users in the Logged on users tile opens the Users Deta You'll also see details such as logon types for each user account, the user group, and when the account logon occurred. - For more information, see [Investigate user entities](investigate-user-windows-defender-advanced-threat-protection.md). + For more information, see [Investigate user entities](investigate-user.md). **Machine risk**
The Machine risk tile shows the overall risk assessment of a machine. A machine's risk level can be determined using the number of active alerts or by a combination of multiple risks that may increase the risk assessment and their severity levels. You can influence a machine's risk level by resolving associated alerts manually or automatically and also by suppressing an alert. It's also indicators of the active threats that machines could be exposed to. @@ -71,7 +71,7 @@ The Machine risk tile shows the overall risk assessment of a machine. A machine' If you have enabled the Azure ATP feature and there are alerts related to the machine, you can click on the link that will take you to the Azure ATP page where more information about the alerts are provided. >[!NOTE] ->You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). +>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features.md). **Machine reporting**
Provides the last internal IP and external IP of the machine. It also shows when the machine was first and last seen reporting to the service. @@ -81,7 +81,7 @@ The **Alerts related to this machine** section provides a list of alerts that ar ![Image of alerts related to machine](images/atp-alerts-related-to-machine.png) -This list is a filtered version of the [Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md), and shows the date when the alert's last activity was detected, a short description of the alert, the user account associated with the alert, the alert's severity, the alert's status in the queue, and who is addressing the alert. +This list is a filtered version of the [Alerts queue](alerts-queue.md), and shows the date when the alert's last activity was detected, a short description of the alert, the user account associated with the alert, the alert's severity, the alert's status in the queue, and who is addressing the alert. You can also choose to highlight an alert from the **Alerts related to this machine** or from the **Machine timeline** section to see the correlation between the alert and its related events on the machine by right-clicking on the alert and selecting **Select and mark events**. This highlights the alert and its related events and helps distinguish them from other alerts and events appearing in the timeline. Highlighted events are displayed in all information levels whether you choose to view the timeline by **Detections**, **Behaviors**, or **Verbose**. @@ -163,7 +163,7 @@ From the list of events that are displayed in the timeline, you can examine the ![Image of machine timeline details pane](images/atp-machine-timeline-details-panel.png) -You can also use the [Artifact timeline](investigate-alerts-windows-defender-advanced-threat-protection.md#artifact-timeline) feature to see the correlation between alerts and events on a specific machine. +You can also use the [Artifact timeline](investigate-alerts.md#artifact-timeline) feature to see the correlation between alerts and events on a specific machine. Expand an event to view associated processes related to the event. Click on the circle next to any process or IP address in the process tree to investigate additional details of the identified processes. This action brings up the **Details pane** which includes execution context of processes, network communications and a summary of meta data on the file or IP address. @@ -173,10 +173,10 @@ The details pane enriches the ‘in-context’ information across investigation ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md b/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md index 886c34c0f8..69493fe5ec 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md +++ b/windows/security/threat-protection/microsoft-defender-atp/investigate-user.md @@ -53,14 +53,14 @@ The user entity tile provides details about the user such as when the user was f If you have enabled the Azure ATP feature and there are alerts related to the user, you can click on the link that will take you to the Azure ATP page where more information about the alerts are provided. The Azure ATP tile also provides details such as the last AD site, total group memberships, and login failure associated with the user. >[!NOTE] ->You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features-windows-defender-advanced-threat-protection.md). +>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features.md). **Logged on machines**
You'll also see a list of the machines that the user logged on to, and can expand these to see details of the logon events on each machine. ## Alerts related to this user -This section provides a list of alerts that are associated with the user account. This list is a filtered view of the [Alert queue](alerts-queue-windows-defender-advanced-threat-protection.md), and shows alerts where the user context is the selected user account, the date when the last activity was detected, a short description of the alert, the machine associated with the alert, the alert's severity, the alert's status in the queue, and who is assigned the alert. +This section provides a list of alerts that are associated with the user account. This list is a filtered view of the [Alert queue](alerts-queue.md), and shows alerts where the user context is the selected user account, the date when the last activity was detected, a short description of the alert, the machine associated with the alert, the alert's severity, the alert's status in the queue, and who is assigned the alert. ## Observed in organization This section allows you to specify a date range to see a list of machines where this user was observed logged on to, and the most frequent and least frequent logged on user account on each of these machines. @@ -85,11 +85,11 @@ You can filter the results by the following time periods: - 6 months ## Related topics -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md index 6ff1bae6e0..47ad22f715 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md +++ b/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org.md @@ -36,7 +36,7 @@ Delegated (work or school account) | URL.Read.All | 'Read URLs' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md index 08e8c07149..34b518cee9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md +++ b/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org.md @@ -37,7 +37,7 @@ Delegated (work or school account) | Ip.Read.All | 'Read IP address profiles' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'View Data' (See [Create and manage roles](user-roles.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md index 1379df6c30..a83da49e7f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.Isolate | 'Isolate machine' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request @@ -63,7 +63,7 @@ IsolationType | String | Type of the isolation. Allowed values are: 'Full' or 'S **IsolationType** controls the type of isolation to perform and can be one of the following: - Full – Full isolation -- Selective – Restrict only limited set of applications from accessing the network (see [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) for more details) +- Selective – Restrict only limited set of applications from accessing the network (see [Isolate machines from the network](respond-machine-alerts.md#isolate-machines-from-the-network) for more details) ## Response diff --git a/windows/security/threat-protection/microsoft-defender-atp/licensing.md b/windows/security/threat-protection/microsoft-defender-atp/licensing.md index 1011ef2e74..c2fe9ab390 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/licensing.md +++ b/windows/security/threat-protection/microsoft-defender-atp/licensing.md @@ -108,7 +108,7 @@ When accessing [Microsoft Defender Security Center](https://SecurityCenter.Windo 6. You are almost done. Before you can start using Microsoft Defender ATP you'll need to: - - [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) + - [Onboard Windows 10 machines](configure-endpoints.md) - Run detection test (optional) @@ -123,5 +123,5 @@ When accessing [Microsoft Defender Security Center](https://SecurityCenter.Windo ![Image of onboard machines](images\atp-onboard-endpoints-WDATP-portal.png) ## Related topics -- [Onboard machines to the Microsoft Defender Advanced Threat Protection service](onboard-configure-windows-defender-advanced-threat-protection.md) -- [Troubleshoot onboarding process and portal access issues](troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md) +- [Onboard machines to the Microsoft Defender Advanced Threat Protection service](onboard-configure.md) +- [Troubleshoot onboarding process and portal access issues](troubleshoot-onboarding-error-messages.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md b/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md index a932128539..bdb50d0354 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-groups.md @@ -30,14 +30,14 @@ ms.topic: article In an enterprise scenario, security operation teams are typically assigned a set of machines. These machines are grouped together based on a set of attributes such as their domains, computer names, or designated tags. In Microsoft Defender ATP, you can create machine groups and use them to: -- Limit access to related alerts and data to specific Azure AD user groups with [assigned RBAC roles](rbac-windows-defender-advanced-threat-protection.md) +- Limit access to related alerts and data to specific Azure AD user groups with [assigned RBAC roles](rbac.md) - Configure different auto-remediation settings for different sets of machines >[!TIP] > For a comprehensive look into RBAC application, read: [Is your SOC running flat with RBAC](https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Is-your-SOC-running-flat-with-limited-RBAC/ba-p/320015). As part of the process of creating a machine group, you'll: -- Set the automated remediation level for that group. For more information on remediation levels, see [Use Automated investigation to investigate and remediate threats](automated-investigations-windows-defender-advanced-threat-protection.md). +- Set the automated remediation level for that group. For more information on remediation levels, see [Use Automated investigation to investigate and remediate threats](automated-investigations.md). - Specify the matching rule that determines which machine group belongs to the group based on the machine name, domain, tags, and OS platform. If a machine is also matched to other groups, it is added only to the highest ranked machine group. - Select the Azure AD user group that should have access to the machine group. - Rank the machine group relative to other groups after it is created. @@ -63,7 +63,7 @@ As part of the process of creating a machine group, you'll: - **Full - remediate threats automatically** >[!NOTE] - > For more information on automation levels, see [Understand the Automated investigation flow](automated-investigations-windows-defender-advanced-threat-protection.md#understand-the-automated-investigation-flow). + > For more information on automation levels, see [Understand the Automated investigation flow](automated-investigations.md#understand-the-automated-investigation-flow). - **Description** - **Members** @@ -96,5 +96,5 @@ Machines that are not matched to any groups are added to Ungrouped machines (def ## Related topic -- [Manage portal access using role-based based access control](rbac-windows-defender-advanced-threat-protection.md) -- [Get list of tenant machine groups using Graph API](get-machinegroups-collection-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Manage portal access using role-based based access control](rbac.md) +- [Get list of tenant machine groups using Graph API](get-machinegroups-collection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md b/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md index 77885b5540..911ac4adb9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-reports.md @@ -81,4 +81,4 @@ For example, to show data about Windows 10 machines with Active sensor health st ## Related topic -- [Threat protection report ](threat-protection-reports-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Threat protection report ](threat-protection-reports.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md b/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md index 61d6e8a22e..624d4c2542 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md @@ -20,9 +20,9 @@ ms.topic: article # Create and manage machine tags Add tags on machines to create a logical group affiliation. Machine group affiliation can represent geographic location, specific activity, importance level and others. -You can create machine groups in the context of role-based access (RBAC) to control who can take specific action or who can see information on a specific machine group or groups by assigning the machine group to a user group. For more information, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). +You can create machine groups in the context of role-based access (RBAC) to control who can take specific action or who can see information on a specific machine group or groups by assigning the machine group to a user group. For more information, see [Manage portal access using role-based access control](rbac.md). -You can also use machine groups to assign specific remediation levels to apply during automated investigations. For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). +You can also use machine groups to assign specific remediation levels to apply during automated investigations. For more information, see [Create and manage machine groups](machine-groups.md). In an investigation, you can filter the Machines list to just specific machine groups by using the Groups filter. diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md index ef5a31ec33..2e235e713e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineactionsnote.md @@ -3,4 +3,4 @@ ms.date: 08/28/2017 author: zavidor --- >[!Note] -> This page focuses on performing a machine action via API. See [take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information about response actions functionality via Microsoft Defender ATP. +> This page focuses on performing a machine action via API. See [take response actions on a machine](respond-machine-alerts.md) for more information about response actions functionality via Microsoft Defender ATP. diff --git a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md index 73f5d50ed2..657eac1d96 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md @@ -74,7 +74,7 @@ Filter the list to view specific machines grouped together by the following mach - No sensor data - Impaired communications - For more information on how to address issues on misconfigured machines see, [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + For more information on how to address issues on misconfigured machines see, [Fix unhealthy sensors](fix-unhealhty-sensors.md). - **Inactive** – Machines that have completely stopped sending signals for more than 7 days. @@ -85,13 +85,13 @@ Filter the list to view specific machines that are well configured or require at - **Well configured** - Machines have the Windows Defender security controls well configured. - **Requires attention** - Machines where improvements can be made to increase the overall security posture of your organization. -For more information, see [View the Secure Score dashboard](secure-score-dashboard-windows-defender-advanced-threat-protection.md). +For more information, see [View the Secure Score dashboard](secure-score-dashboard.md). ### Tags You can filter the list based on the grouping and tagging that you've added to individual machines. ## Related topics -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md index 6aafe49de3..4765a373dd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md @@ -92,7 +92,7 @@ Create custom rules to control when alerts are suppressed, or resolved. You can 2. The list of suppression rules shows all the rules that users in your organization have created. -For more information on managing suppression rules, see [Manage suppression rules](manage-suppression-rules-windows-defender-advanced-threat-protection.md) +For more information on managing suppression rules, see [Manage suppression rules](manage-suppression-rules.md) ## Change the status of an alert @@ -117,11 +117,11 @@ Added comments instantly appear on the pane. ## Related topics -- [Manage suppression rules](manage-suppression-rules-windows-defender-advanced-threat-protection.md) -- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [Manage suppression rules](manage-suppression-rules.md) +- [View and organize the Microsoft Defender Advanced Threat Protection Alerts queue ](alerts-queue.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md index dc313000a3..c852df752c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list.md @@ -76,7 +76,7 @@ Download the sample CSV to know the supported column attributes. ## Related topics -- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) +- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md index 92c91b1b6f..24817cb48c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md @@ -196,4 +196,4 @@ From the panel, you can click on the Open investigation page link to see the inv You also have the option of selecting multiple investigations to approve or reject actions on multiple investigations. ## Related topic -- [Investigate Microsoft Defender ATP alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +- [Investigate Microsoft Defender ATP alerts](investigate-alerts.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md index 4960840dca..357563de57 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list.md @@ -66,6 +66,6 @@ You can define the conditions for when entities are identified as malicious or s ## Related topics -- [Manage automation file uploads](manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) -- [Manage allowed/blocked lists](manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -- [Manage automation folder exclusions](manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) +- [Manage automation file uploads](manage-automation-file-uploads.md) +- [Manage allowed/blocked lists](manage-allowed-blocked-list.md) +- [Manage automation folder exclusions](manage-automation-folder-exclusions.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md index baf0ac27bb..3a6a4864dc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads.md @@ -46,5 +46,5 @@ For example, if you add *exe* and *bat* as file or attachment extension names, t ## Related topics -- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -- [Manage automation folder exclusions](manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list.md) +- [Manage automation folder exclusions](manage-automation-folder-exclusions.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md index e63a8c6207..e6b7c8bd5e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions.md @@ -76,5 +76,5 @@ You can specify the file names that you want to be excluded in a specific direct ## Related topics -- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md) -- [Manage automation file uploads](manage-automation-file-uploads-windows-defender-advanced-threat-protection.md) +- [Manage automation allowed/blocked lists](manage-automation-allowed-blocked-list.md) +- [Manage automation file uploads](manage-automation-file-uploads.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md b/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md index 84835dc6f5..916bbb2776 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md @@ -27,6 +27,6 @@ Manage the alerts queue, investigate machines in the machines list, take respons Topic | Description :---|:--- [Alerts queue](alerts-queue-endpoint-detection-response.md)| View the alerts surfaced in Microsoft Defender Security Center. -[Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md) | Learn how you can view and manage the machines list, manage machine groups, and investigate machine related alerts. -[Take response actions](response-actions-windows-defender-advanced-threat-protection.md)| Take response actions on machines and files to quickly respond to detected attacks and contain threats. -[Query data using advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md)| Proactively hunt for possible threats across your organization using a powerful search and query tool. \ No newline at end of file +[Machines list](machines-view-overview.md) | Learn how you can view and manage the machines list, manage machine groups, and investigate machine related alerts. +[Take response actions](response-actions.md)| Take response actions on machines and files to quickly respond to detected attacks and contain threats. +[Query data using advanced hunting](advanced-hunting.md)| Proactively hunt for possible threats across your organization using a powerful search and query tool. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md index d03aec8131..31fb4bb075 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-incidents.md @@ -60,4 +60,4 @@ Added comments instantly appear on the pane. ## Related topics - [Incidents queue](incidents-queue.md) - [View and organize the Incidents queue](view-incidents-queue.md) -- [Investigate incidents](investigate-incidents-windows-defender-advanced-threat-protection.md) +- [Investigate incidents](investigate-incidents.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md index 2e6bbe1507..c0d382b786 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules.md @@ -26,7 +26,7 @@ ms.date: 04/24/2018 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-suppressionrules-abovefoldlink) -There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts-windows-defender-advanced-threat-protection.md). +There might be scenarios where you need to suppress alerts from appearing in the portal. You can create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. For more information on how to suppress alerts, see [Suppress alerts](manage-alerts.md). You can view a list of all the suppression rules and manage them in one place. You can also turn an alert suppression rule on or off. @@ -46,4 +46,4 @@ You can view a list of all the suppression rules and manage them in one place. Y ## Related topics -- [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Manage alerts](manage-alerts.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/management-apis.md b/windows/security/threat-protection/microsoft-defender-atp/management-apis.md index fd37543f72..a4fe146a16 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/management-apis.md +++ b/windows/security/threat-protection/microsoft-defender-atp/management-apis.md @@ -59,11 +59,11 @@ Managed security service provider | Get a quick overview on managed security ser ## Related topics -- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Onboard machines](onboard-configure.md) +- [Enable the custom threat intelligence application](enable-custom-ti.md) - [Microsoft Defender ATP Public API](use-apis.md) -- [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md) -- [Create and build Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Role-based access control](rbac-windows-defender-advanced-threat-protection.md) +- [Pull alerts to your SIEM tools](configure-siem.md) +- [Create and build Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +- [Role-based access control](rbac.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md index 1e661e11f1..8efb9d7b22 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md @@ -90,12 +90,12 @@ You can also do advanced hunting to create custom threat intelligence and use a -**[Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md)**
+**[Automated investigation and remediation](automated-investigations.md)**
In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. -**[Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md)**
+**[Secure score](overview-secure-score.md)**
Microsoft Defender ATP includes a secure score to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security of your organization. diff --git a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md index 5a4a309e6f..b9112f5c8c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md +++ b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md @@ -46,5 +46,5 @@ For more information about licensing requirements for Microsoft Defender ATP pla ## Related topic -- [Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md) -- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) +- [Validate licensing and complete setup](licensing.md) +- [Onboard machines](onboard-configure.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md index 71bf5122da..07d8cb0e6e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md @@ -41,7 +41,7 @@ Microsoft Defender ATP adds support for this scenario and to allow MSSPs to take ## Related topic -- [Configure managed security service provider integration](configure-mssp-support-windows-defender-advanced-threat-protection.md) +- [Configure managed security service provider integration](configure-mssp-support.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md index d2eff9b682..738b4d31ee 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md @@ -37,7 +37,7 @@ Delegated (work or school account) | Machine.Offboard | 'Offboard machine' >[!Note] > When obtaining a token using user credentials: >- The user needs to 'Global Admin' AD role ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md index a22fafe295..68ca47d378 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md @@ -34,14 +34,14 @@ ms.date: 04/24/2018 Follow the corresponding instructions depending on your preferred deployment method. ## Offboard Windows 10 machines - - [Offboard machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md#offboard-machines-using-a-local-script) - - [Offboard machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md#offboard-machines-using-group-policy) - - [Offboard machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md#offboard-machines-using-system-center-configuration-manager) - - [Offboard machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#offboard-and-monitor-machines-using-mobile-device-management-tools) + - [Offboard machines using a local script](configure-endpoints-script.md#offboard-machines-using-a-local-script) + - [Offboard machines using Group Policy](configure-endpoints-gp.md#offboard-machines-using-group-policy) + - [Offboard machines using System Center Configuration Manager](configure-endpoints-sccm.md#offboard-machines-using-system-center-configuration-manager) + - [Offboard machines using Mobile Device Management tools](configure-endpoints-mdm.md#offboard-and-monitor-machines-using-mobile-device-management-tools) ## Offboard Servers - - [Offboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md#offboard-servers) + - [Offboard servers](configure-server-endpoints.md#offboard-servers) ## Offboard non-Windows machines - - [Offboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md#offboard-non-windows-machines) + - [Offboard non-Windows machines](configure-endpoints-non-windows.md#offboard-non-windows-machines) diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md index 61dc191dc5..7528d22790 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md @@ -78,7 +78,7 @@ When you run the onboarding wizard for the first time, you must choose where you > [!NOTE] > - You cannot change your data storage location after the first-time setup. -> - Review the [Microsoft Defender ATP data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) for more information on where and how Microsoft stores your data. +> - Review the [Microsoft Defender ATP data storage and privacy](data-storage-privacy.md) for more information on where and how Microsoft stores your data. ### Diagnostic data settings @@ -134,7 +134,7 @@ Internet connectivity on machines is required either directly or through proxy. The Microsoft Defender ATP sensor can utilize a daily average bandwidth of 5MB to communicate with the Microsoft Defender ATP cloud service and report cyber data. One-off activities such as file uploads and investigation package collection are not included in this daily average bandwidth. -For more information on additional proxy configuration settings see, [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) . +For more information on additional proxy configuration settings see, [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) . Before you onboard machines, the diagnostic data service must be enabled. The service is enabled by default in Windows 10. @@ -146,7 +146,7 @@ You must configure Security intelligence updates on the Microsoft Defender ATP m When Windows Defender Antivirus is not the active antimalware in your organization and you use the Microsoft Defender ATP service, Windows Defender Antivirus goes on passive mode. If your organization has disabled Windows Defender Antivirus through group policy or other methods, machines that are onboarded to Microsoft Defender ATP must be excluded from this group policy. -If you are onboarding servers and Windows Defender Antivirus is not the active antimalware on your servers, you shouldn't uninstall Windows Defender Antivirus. You'll need to configure it to run on passive mode. For more information, see [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md). +If you are onboarding servers and Windows Defender Antivirus is not the active antimalware on your servers, you shouldn't uninstall Windows Defender Antivirus. You'll need to configure it to run on passive mode. For more information, see [Onboard servers](configure-server-endpoints.md). For more information, see [Windows Defender Antivirus compatibility](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). @@ -154,18 +154,18 @@ For more information, see [Windows Defender Antivirus compatibility](../windows- ## Windows Defender Antivirus Early Launch Antimalware (ELAM) driver is enabled If you're running Windows Defender Antivirus as the primary antimalware product on your machines, the Microsoft Defender ATP agent will successfully onboard. -If you're running a third-party antimalware client and use Mobile Device Management solutions or System Center Configuration Manager (current branch) version 1606, you'll need to ensure that the Windows Defender Antivirus ELAM driver is enabled. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). +If you're running a third-party antimalware client and use Mobile Device Management solutions or System Center Configuration Manager (current branch) version 1606, you'll need to ensure that the Windows Defender Antivirus ELAM driver is enabled. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). ## In this section Topic | Description :---|:--- -[Onboard previous versions of Windows](onboard-downlevel-windows-defender-advanced-threat-protection.md)| Onboard Windows 7 and Windows 8.1 machines to Microsoft Defender ATP. -[Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) | You'll need to onboard machines for it to report to the Microsoft Defender ATP service. Learn about the tools and methods you can use to configure machines in your enterprise. -[Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) | Onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP -[Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) | Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Microsoft Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. -[Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md) | Run a script on a newly onboarded machine to verify that it is properly reporting to the Microsoft Defender ATP service. -[Configure proxy and Internet settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)| Enable communication with the Microsoft Defender ATP cloud service by configuring the proxy and Internet connectivity settings. -[Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) | Learn about resolving issues that might arise during onboarding. +[Onboard previous versions of Windows](onboard-downlevel.md)| Onboard Windows 7 and Windows 8.1 machines to Microsoft Defender ATP. +[Onboard Windows 10 machines](configure-endpoints.md) | You'll need to onboard machines for it to report to the Microsoft Defender ATP service. Learn about the tools and methods you can use to configure machines in your enterprise. +[Onboard servers](configure-server-endpoints.md) | Onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP +[Onboard non-Windows machines](configure-endpoints-non-windows.md) | Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Microsoft Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. +[Run a detection test on a newly onboarded machine](run-detection-test.md) | Run a script on a newly onboarded machine to verify that it is properly reporting to the Microsoft Defender ATP service. +[Configure proxy and Internet settings](configure-proxy-internet.md)| Enable communication with the Microsoft Defender ATP cloud service by configuring the proxy and Internet connectivity settings. +[Troubleshoot onboarding issues](troubleshoot-onboarding.md) | Learn about resolving issues that might arise during onboarding. >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md index 140c14d487..9e5d1c75b1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md @@ -33,14 +33,14 @@ ms.topic: article Microsoft Defender ATP extends support to include down-level operating systems, providing advanced attack detection and investigation capabilities on supported Windows versions. >[!IMPORTANT] ->This capability is currently in preview. You'll need to turn on the preview features to take advantage of this feature. For more information, see [Preview features](preview-windows-defender-advanced-threat-protection.md). +>This capability is currently in preview. You'll need to turn on the preview features to take advantage of this feature. For more information, see [Preview features](preview.md). To onboard down-level Windows client endpoints to Microsoft Defender ATP, you'll need to: - Configure and update System Center Endpoint Protection clients. - Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP as instructed below. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test.md). ## Configure and update System Center Endpoint Protection clients >[!IMPORTANT] diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard.md b/windows/security/threat-protection/microsoft-defender-atp/onboard.md index 582233db3c..f2cbb4cb17 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard.md @@ -31,10 +31,10 @@ Topic | Description :---|:--- [Configure attack surface reduction capabilities](configure-attack-surface-reduction.md) | By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. [Configure next generation protection](../windows-defender-antivirus/configure-windows-defender-antivirus-features.md) | Configure next generation protection to catch all types of emerging threats. -[Configure Secure score dashboard security controls](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | Configure the security controls in Secure score to increase the security posture of your organization. +[Configure Secure score dashboard security controls](secure-score-dashboard.md) | Configure the security controls in Secure score to increase the security posture of your organization. Configure Microsoft Threat Protection integration| Configure other solutions that integrate with Microsoft Defender ATP. Management and API support| Pull alerts to your SIEM or use APIs to create custom alerts. Create and build Power BI reports. -[Configure Microsoft Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. +[Configure Microsoft Defender Security Center settings](preferences-setup.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md index 0d954897a9..f529841ee6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md @@ -36,8 +36,8 @@ The response capabilities give you the power to promptly remediate threats by ac Topic | Description :---|:--- -[Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) | Explore a high level overview of detections, highlighting where response actions are needed. +[Security operations dashboard](security-operations-dashboard.md) | Explore a high level overview of detections, highlighting where response actions are needed. [Incidents queue](incidents-queue.md) | View and organize the incidents queue, and manage and investigate alerts. -[Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md) | View and organize the machine alerts queue, and manage and investigate alerts. -[Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md) | Investigate machines with generated alerts and search for specific events over time. -[Take response actions](response-actions-windows-defender-advanced-threat-protection.md) | Learn about the available response actions and apply them to machines and files. \ No newline at end of file +[Alerts queue](alerts-queue.md) | View and organize the machine alerts queue, and manage and investigate alerts. +[Machines list](machines-view-overview.md) | Investigate machines with generated alerts and search for specific events over time. +[Take response actions](response-actions.md) | Learn about the available response actions and apply them to machines and files. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md index b6d5d31b21..b3aad8c507 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md @@ -34,7 +34,7 @@ With advanced hunting, you can take advantage of the following capabilities: ## In this section Topic | Description :---|:--- -[Query data using Advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md) | Learn how to use the basic or advanced query examples to search for possible emerging threats in your organization. +[Query data using Advanced hunting](advanced-hunting.md) | Learn how to use the basic or advanced query examples to search for possible emerging threats in your organization. [Custom detections](overview-custom-detections.md)| With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index f1b31e4f2a..ec0b0550d8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -48,7 +48,7 @@ The Office 365 Secure Score looks at your settings and activities and compares t In the example image, the total points for the Windows security controls and Office 365 add up to 602 points. -You can set the baselines for calculating the score of Windows Defender security controls on the Secure score dashboard through the **Settings**. For more information, see [Enable Secure score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md). +You can set the baselines for calculating the score of Windows Defender security controls on the Secure score dashboard through the **Settings**. For more information, see [Enable Secure score security controls](enable-secure-score.md). ## Secure score over time You can track the progression of your organizational security posture over time using this tile. It displays the overall score in a historical trend line enabling you to see how taking the recommended actions increase your overall security posture. @@ -78,5 +78,5 @@ Within the tile, you can click on each control to see the recommended optimizati Clicking the link under the Misconfigured machines column opens up the **Machines list** with filters applied to show only the list of machines where the recommendation is applicable. You can export the list in Excel to create a target collection and apply relevant policies using a management solution of your choice. ## Related topic -- [Threat analytics](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) -- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) +- [Threat analytics](threat-analytics-dashboard.md) +- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview.md b/windows/security/threat-protection/microsoft-defender-atp/overview.md index 0bfb1b24c9..b9e251ae4d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview.md @@ -36,12 +36,12 @@ Topic | Description [Attack surface reduction](overview-attack-surface-reduction.md) | Leverage the attack surface reduction capabilities to protect the perimeter of your organization. [Next generation protection](../windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) | Learn about the antivirus capabilities in Microsoft Defender ATP so you can protect desktops, portable computers, and servers. [Endpoint detection and response](overview-endpoint-detection-response.md) | Understand how Microsoft Defender ATP continuously monitors your organization for possible attacks against systems, networks, or users in your organization and the features you can use to mitigate and remediate threats. -[Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md) | In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. -[Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) | Quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to better protect your organization - all in one place. -[Advanced hunting](overview-hunting-windows-defender-advanced-threat-protection.md) | Use a powerful search and query language to create custom queries and detection rules. +[Automated investigation and remediation](automated-investigations.md) | In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. +[Secure score](overview-secure-score.md) | Quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to better protect your organization - all in one place. +[Advanced hunting](overview-hunting.md) | Use a powerful search and query language to create custom queries and detection rules. [Management and APIs](management-apis.md) | Microsoft Defender ATP supports a wide variety of tools to help you manage and interact with the platform so that you can integrate the service into your existing workflows. [Microsoft Threat Protection](threat-protection-integration.md) | Microsoft security products work better together. Learn about other security capabilities in the Microsoft threat protection stack. -[Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) |Learn to navigate your way around Microsoft Defender Security Center. +[Portal overview](portal-overview.md) |Learn to navigate your way around Microsoft Defender Security Center. diff --git a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md index 2a989a87e4..349f685730 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md @@ -111,7 +111,7 @@ Icon | Description ## Related topics -- [Understand the Microsoft Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) -- [View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) -- [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Understand the Microsoft Defender Advanced Threat Protection portal](use.md) +- [View the Security operations dashboard](security-operations-dashboard.md) +- [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) +- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md index 6847252b33..08b7acca0e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md +++ b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md @@ -179,9 +179,9 @@ $ioc = ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md b/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md index 1e98001f5e..a651cb7907 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md @@ -36,9 +36,9 @@ Turn on the preview experience setting to be among the first to try upcoming fea 2. Toggle the setting between **On** and **Off** and select **Save preferences**. ## Related topics -- [Update general settings in Microsoft Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Turn on advanced features in Microsoft Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) -- [Configure email notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create and build Power BI reports](powerbi-reports-windows-defender-advanced-threat-protection.md) +- [Update general settings in Microsoft Defender ATP](data-retention-settings.md) +- [Turn on advanced features in Microsoft Defender ATP](advanced-features.md) +- [Configure email notifications in Microsoft Defender ATP](configure-email-notifications.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create and build Power BI reports](powerbi-reports.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md index 41c78cc6f9..35352f18b7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md @@ -48,7 +48,7 @@ Use the following method in the Microsoft Defender ATP API to pull alerts in JSO >Microsoft Defender Security Center merges similar alert detections into a single alert. This API pulls alert detections in its raw form based on the query parameters you set, enabling you to apply your own grouping and filtering. ## Before you begin -- Before calling the Microsoft Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +- Before calling the Microsoft Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md). - Take note of the following values in your Azure application registration. You need these values to configure the OAuth flow in your service or daemon app: - Application ID (unique to your application) @@ -202,8 +202,8 @@ HTTP error code | Description 500 | Error in the service. ## Related topics -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping.md) +- [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md b/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md index 09522e6ab2..4cf4e52899 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md +++ b/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md @@ -184,9 +184,9 @@ with requests.Session() as session: ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/rbac.md b/windows/security/threat-protection/microsoft-defender-atp/rbac.md index 1fa86fd35c..2df2a61b56 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/rbac.md +++ b/windows/security/threat-protection/microsoft-defender-atp/rbac.md @@ -43,7 +43,7 @@ Microsoft Defender ATP RBAC is designed to support your tier- or role-based mode - Create custom roles and control what Microsoft Defender ATP capabilities they can access with granularity. - **Control who can see information on specific machine group or groups** - - [Create machine groups](machine-groups-windows-defender-advanced-threat-protection.md) by specific criteria such as names, tags, domains, and others, then grant role access to them using a specific Azure Active Directory (Azure AD) user group. + - [Create machine groups](machine-groups.md) by specific criteria such as names, tags, domains, and others, then grant role access to them using a specific Azure Active Directory (Azure AD) user group. To implement role-based access, you'll need to define admin roles, assign corresponding permissions, and assign Azure AD user groups assigned to the roles. @@ -71,4 +71,4 @@ Someone with a Microsoft Defender ATP Global administrator role has unrestricted ## Related topic -- [Create and manage machine groups in Microsoft Defender ATP](machine-groups-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Create and manage machine groups in Microsoft Defender ATP](machine-groups.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md index e2a48992a8..bf1c957ebe 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md @@ -261,11 +261,11 @@ HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection Value = 0 – block sample collection Value = 1 – allow sample collection ``` -5. Change the organizational unit through the Group Policy. For more information, see [Configure with Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md). +5. Change the organizational unit through the Group Policy. For more information, see [Configure with Group Policy](configure-endpoints-gp.md). 6. If these steps do not resolve the issue, contact [winatp@microsoft.com](mailto:winatp@microsoft.com). > [!NOTE] > If the value *AllowSampleCollection* is not available, the client will allow sample collection by default. ## Related topic -- [Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md) +- [Take response actions on a machine](respond-machine-alerts.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md index 16b781e106..f90dd5dda3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md @@ -250,4 +250,4 @@ All other related details are also shown, for example, submission time, submitti ![Image of action center with information](images/atp-action-center-with-info.png) ## Related topic -- [Take response actions on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md) +- [Take response actions on a file](respond-file-alerts.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/response-actions.md b/windows/security/threat-protection/microsoft-defender-atp/response-actions.md index 643f72739e..51b90af80c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/response-actions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/response-actions.md @@ -36,5 +36,5 @@ You can take response actions on machines and files to quickly respond to detect ## In this section Topic | Description :---|:--- -[Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md)| Isolate machines or collect an investigation package. -[Take response actions on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md)| Stop and quarantine files or block a file from your network. +[Take response actions on a machine](respond-machine-alerts.md)| Isolate machines or collect an investigation package. +[Take response actions on a file](respond-file-alerts.md)| Stop and quarantine files or block a file from your network. diff --git a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md index 81b063e148..6443996f08 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md @@ -23,7 +23,7 @@ ms.date: 12/08/2017 [!include[Prereleaseinformation](prerelease.md)] -Restrict execution of all applications on the machine except a predefined set (see [Response machine alerts](respond-machine-alerts-windows-defender-advanced-threat-protection.md) for more information) +Restrict execution of all applications on the machine except a predefined set (see [Response machine alerts](respond-machine-alerts.md) for more information) [!include[Machine actions note](machineactionsnote.md)] @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.RestrictExecution | 'Restrict code >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md index d7b2db640d..af4e3a7870 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md @@ -43,7 +43,7 @@ Delegated (work or school account) | AdvancedQuery.Read | 'Run advanced queries' >[!Note] > When obtaining a token using user credentials: >- The user needs to have 'View Data' AD role ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` @@ -147,6 +147,6 @@ Content-Type: application/json​ ## Related topic - [Microsoft Defender ATP APIs](apis-intro.md) -- [Advanced Hunting from Portal](advanced-hunting-windows-defender-advanced-threat-protection.md) +- [Advanced Hunting from Portal](advanced-hunting.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md index 470cf1fc02..240efd12ca 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.Scan | 'Scan machine' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md index 7f80d83213..d9a36f6795 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md @@ -48,5 +48,5 @@ Run the following PowerShell script on a newly onboarded machine to verify that The Command Prompt window will close automatically. If successful, the detection test will be marked as completed and a new alert will appear in the portal for the onboarded machine in approximately 10 minutes. ## Related topics -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) -- [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) +- [Onboard Windows 10 machines](configure-endpoints.md) +- [Onboard servers](configure-server-endpoints.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md index 1ee8334e7a..61f17b701f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md @@ -40,7 +40,7 @@ You can take the following actions to increase the overall security score of you - Fix sensor data collection - Fix impaired communications -For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). +For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). ### Windows Defender Antivirus (Windows Defender AV) optimization For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AV is fulfilled. @@ -82,7 +82,7 @@ This tile shows you the exact number of machines that require the latest securit You can take the following actions to increase the overall security score of your organization: - Install the latest security updates - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). For more information, see [Windows Update Troubleshooter](https://support.microsoft.com/help/4027322/windows-windows-update-troubleshooter). @@ -229,7 +229,7 @@ You can take the following actions to increase the overall security score of you - Secure public profile - Verify secure configuration of third-party firewall - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). For more information, see [Windows Defender Firewall with Advanced Security](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/windows-firewall-with-advanced-security). @@ -251,7 +251,7 @@ You can take the following actions to increase the overall security score of you - Resume protection on all drives - Ensure drive compatibility - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). For more information, see [Bitlocker](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview). @@ -274,14 +274,14 @@ You can take the following actions to increase the overall security score of you - Ensure hardware and software prerequisites are met - Turn on Credential Guard - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). For more information, see [Manage Windows Defender Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-manage). >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-sadashboard-belowfoldlink) ## Related topics -- [Overview of Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) +- [Overview of Secure score](overview-secure-score.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md index 97e6cbec7e..ee063018af 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md @@ -55,9 +55,9 @@ You can view the overall number of active alerts from the last 30 days in your n Each group is further sub-categorized into their corresponding alert severity levels. Click the number of alerts inside each alert ring to see a sorted view of that category's queue (**New** or **In progress**). -For more information see, [Alerts overview](alerts-queue-windows-defender-advanced-threat-protection.md). +For more information see, [Alerts overview](alerts-queue.md). -Each row includes an alert severity category and a short description of the alert. You can click an alert to see its detailed view. For more information see, [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) and [Alerts overview](alerts-queue-windows-defender-advanced-threat-protection.md). +Each row includes an alert severity category and a short description of the alert. You can click an alert to see its detailed view. For more information see, [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) and [Alerts overview](alerts-queue.md). @@ -66,9 +66,9 @@ This tile shows you a list of machines with the highest number of active alerts. ![The Machines at risk tile shows a list of machines with the highest number of alerts, and a breakdown of the severity of the alerts](images/machines-at-risk-tile.png) -Click the name of the machine to see details about that machine. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). +Click the name of the machine to see details about that machine. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines.md). -You can also click **Machines list** at the top of the tile to go directly to the **Machines list**, sorted by the number of active alerts. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). +You can also click **Machines list** at the top of the tile to go directly to the **Machines list**, sorted by the number of active alerts. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines.md). ## Sensor health The **Sensor health** tile provides information on the individual machine’s ability to provide sensor data to the Microsoft Defender ATP service. It reports how many machines require attention and helps you identify problematic machines. @@ -80,14 +80,14 @@ There are two status indicators that provide information on the number of machin - **Inactive** - Machines that have stopped reporting to the Microsoft Defender ATP service for more than seven days in the past month. -When you click any of the groups, you’ll be directed to machines list, filtered according to your choice. For more information, see [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md) and [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md). +When you click any of the groups, you’ll be directed to machines list, filtered according to your choice. For more information, see [Check sensor state](check-sensor-status.md) and [Investigate machines](investigate-machines.md). ## Service health The **Service health** tile informs you if the service is active or if there are issues. ![The Service health tile shows an overall indicator of the service](images/status-tile.png) -For more information on the service health, see [Check the Microsoft Defender ATP service health](service-status-windows-defender-advanced-threat-protection.md). +For more information on the service health, see [Check the Microsoft Defender ATP service health](service-status.md). ## Daily machines reporting @@ -115,7 +115,7 @@ The tile shows you a list of user accounts with the most active alerts and the n ![User accounts at risk tile shows a list of user accounts with the highest number of alerts and a breakdown of the severity of the alerts](images/atp-users-at-risk.png) -Click the user account to see details about the user account. For more information see [Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md). +Click the user account to see details about the user account. For more information see [Investigate a user account](investigate-user.md). ## Suspicious activities This tile shows audit events based on detections from various security components. @@ -127,8 +127,8 @@ This tile shows audit events based on detections from various security component >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-secopsdashboard-belowfoldlink) ## Related topics -- [Understand the Microsoft Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) -- [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) -- [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) +- [Understand the Microsoft Defender Advanced Threat Protection portal](use.md) +- [Portal overview](portal-overview.md) +- [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) +- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/service-status.md b/windows/security/threat-protection/microsoft-defender-atp/service-status.md index 2a553f0551..31c8a5ee1a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/service-status.md +++ b/windows/security/threat-protection/microsoft-defender-atp/service-status.md @@ -57,4 +57,4 @@ When an issue is resolved, it gets recorded in the **Status history** tab. The **Status history** tab reflects all the historical issues that were seen and resolved. You'll see details of the resolved issues along with the other information that were included while it was being resolved. ### Related topic -- [View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) +- [View the Security operations dashboard](security-operations-dashboard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md index 745cdec188..9fde8c8592 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md +++ b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md @@ -38,8 +38,8 @@ Delegated (work or school account) | Machine.StopAndQuarantine | 'Stop And Quara >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md index 534c8fb1d3..f4b1020dc3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md @@ -65,5 +65,5 @@ The **Mitigation status** and **Mitigation status over time** shows the endpoint ## Related topics -- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) +- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md index 5274b81da4..7b758a94bc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md @@ -39,7 +39,7 @@ Alert definitions are contextual attributes that can be used collectively to ide IOCs are individually-known malicious events that indicate that a network or machine has already been breached. Unlike alert definitions, these indicators are considered as evidence of a breach. They are often seen after an attack has already been carried out and the objective has been reached, such as exfiltration. Keeping track of IOCs is also important during forensic investigations. Although it might not provide the ability to intervene with an attack chain, gathering these indicators can be useful in creating better defenses for possible future attacks. ## Relationship between alert definitions and IOCs -In the context of Microsoft Defender ATP, alert definitions are containers for IOCs and defines the alert, including the metadata that is raised in case of a specific IOC match. Various metadata is provided as part of the alert definitions. Metadata such as alert definition name of attack, severity, and description is provided along with other options. For more information on available metadata options, see [Threat Intelligence API metadata](custom-ti-api-windows-defender-advanced-threat-protection.md#threat-intelligence-api-metadata). +In the context of Microsoft Defender ATP, alert definitions are containers for IOCs and defines the alert, including the metadata that is raised in case of a specific IOC match. Various metadata is provided as part of the alert definitions. Metadata such as alert definition name of attack, severity, and description is provided along with other options. For more information on available metadata options, see [Threat Intelligence API metadata](custom-ti-api.md#threat-intelligence-api-metadata). Each IOC defines the concrete detection logic based on its type and value as well as its action, which determines how it is matched. It is bound to a specific alert definition that defines how a detection is displayed as an alert on the Microsoft Defender ATP console. @@ -51,9 +51,9 @@ Here is an example of an IOC: IOCs have a many-to-one relationship with alert definitions such that an alert definition can have many IOCs that correspond to it. ## Related topics -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) -- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) +- [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md index da34c747c5..a532cdc3b6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md @@ -57,7 +57,7 @@ The Skype for Business integration provides s a way for analysts to communicate ## Related topic -- [Protect users, data, and devices with conditional access](conditional-access-windows-defender-advanced-threat-protection.md) +- [Protect users, data, and devices with conditional access](conditional-access.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md index 37eb716bfc..200d9396de 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md @@ -79,4 +79,4 @@ For example, to show data about high-severity alerts only: 3. Select **Apply**. ## Related topic -- [Machine health and compliance report](machine-reports-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Machine health and compliance report](machine-reports.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md index c2d0bdf3c6..497987c490 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md @@ -56,9 +56,9 @@ If your client secret expires or if you've misplaced the copy provided when you ## Related topics -- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) -- [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) -- [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) -- [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) -- [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) +- [Understand threat intelligence concepts](threat-indicator-concepts.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti.md) +- [Create custom alerts using the threat intelligence API](custom-ti-api.md) +- [PowerShell code examples for the custom threat intelligence API](powershell-example-code.md) +- [Python code examples for the custom threat intelligence API](python-example-code.md) +- [Experiment with custom threat intelligence alerts](experiment-custom-ti.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md index 64c4946662..db5503aa11 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md @@ -91,4 +91,4 @@ crl.microsoft.com` ## Related topics -- [Validate licensing provisioning and complete setup for Microsoft Defender ATP](licensing-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Validate licensing provisioning and complete setup for Microsoft Defender ATP](licensing.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md index 5993a17f98..b46b9c95ac 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md @@ -29,12 +29,12 @@ ms.topic: troubleshooting You might need to troubleshoot the Microsoft Defender ATP onboarding process if you encounter issues. This page provides detailed steps to troubleshoot onboarding issues that might occur when deploying with one of the deployment tools and common errors that might occur on the machines. -If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, it might indicate an onboarding or connectivity problem. +If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines.md) after an hour, it might indicate an onboarding or connectivity problem. ## Troubleshoot onboarding when deploying with Group Policy Deployment with Group Policy is done by running the onboarding script on the machines. The Group Policy console does not indicate if the deployment has succeeded or not. -If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, you can check the output of the script on the machines. For more information, see [Troubleshoot onboarding when deploying with a script](#troubleshoot-onboarding-when-deploying-with-a-script). +If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines.md) after an hour, you can check the output of the script on the machines. For more information, see [Troubleshoot onboarding when deploying with a script](#troubleshoot-onboarding-when-deploying-with-a-script). If the script completes successfully, see [Troubleshoot onboarding issues on the machines](#troubleshoot-onboarding-issues-on-the-machine) for additional errors that might occur. @@ -71,9 +71,9 @@ Event ID | Error Type | Resolution steps 10 | Onboarding data couldn't be written to registry | Check the permissions on the registry, specifically
```HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat```.
Verify that the script was ran as an administrator. 15 | Failed to start SENSE service |Check the service health (```sc query sense``` command). Make sure it's not in an intermediate state (*'Pending_Stopped'*, *'Pending_Running'*) and try to run the script again (with administrator rights).

If the machine is running Windows 10, version 1607 and running the command `sc query sense` returns `START_PENDING`, reboot the machine. If rebooting the machine doesn't address the issue, upgrade to KB4015217 and try onboarding again. 15 | Failed to start SENSE service | If the message of the error is: System error 577 has occurred. You need to enable the Windows Defender Antivirus ELAM driver, see [Ensure that Windows Defender Antivirus is not disabled by a policy](#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy) for instructions. -30 | The script failed to wait for the service to start running | The service could have taken more time to start or has encountered errors while trying to start. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). -35 | The script failed to find needed onboarding status registry value | When the SENSE service starts for the first time, it writes onboarding status to the registry location
```HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status```.
The script failed to find it after several seconds. You can manually test it and check if it's there. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). -40 | SENSE service onboarding status is not set to **1** | The SENSE service has failed to onboard properly. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes-windows-defender-advanced-threat-protection.md). +30 | The script failed to wait for the service to start running | The service could have taken more time to start or has encountered errors while trying to start. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes.md). +35 | The script failed to find needed onboarding status registry value | When the SENSE service starts for the first time, it writes onboarding status to the registry location
```HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status```.
The script failed to find it after several seconds. You can manually test it and check if it's there. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes.md). +40 | SENSE service onboarding status is not set to **1** | The SENSE service has failed to onboard properly. For more information on events and errors related to SENSE, see [Review events and errors using Event viewer](event-error-codes.md). 65 | Insufficient privileges| Run the script again with administrator privileges. ## Troubleshoot onboarding issues using Microsoft Intune @@ -155,12 +155,12 @@ If the deployment tools used does not indicate an error in the onboarding proces Event ID | Message | Resolution steps :---|:---|:--- 5 | Microsoft Defender Advanced Threat Protection service failed to connect to the server at _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -6 | Microsoft Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). +6 | Microsoft Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script.md). 7 | Microsoft Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection), then run the entire onboarding process again. -9 | Microsoft Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the event happened during offboarding, contact support. -10 | Microsoft Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the problem persists, contact support. +9 | Microsoft Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script.md).

If the event happened during offboarding, contact support. +10 | Microsoft Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script.md).

If the problem persists, contact support. 15 | Microsoft Defender Advanced Threat Protection cannot start command channel with URL: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -17 | Microsoft Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). If the problem persists, contact support. +17 | Microsoft Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script.md). If the problem persists, contact support. 25 | Microsoft Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: _variable_ | Contact support. 27 | Failed to enable Microsoft Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: variable | Contact support. 29 | Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3 | Ensure the machine has Internet access, then run the entire offboarding process again. @@ -238,9 +238,9 @@ The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to repo WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. -To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. +To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. -If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) topic. +If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet.md) topic. ### Ensure that Windows Defender Antivirus is not disabled by a policy **Problem**: The Microsoft Defender ATP service does not start after onboarding. @@ -271,8 +271,8 @@ If the verification fails and your environment is using a proxy to connect to th ## Troubleshoot onboarding issues on a server If you encounter issues while onboarding a server, go through the following verification steps to address possible issues. -- [Ensure Microsoft Monitoring Agent (MMA) is installed and configured to report sensor data to the service](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-mma) -- [Ensure that the server proxy and Internet connectivity settings are configured properly](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-proxy) +- [Ensure Microsoft Monitoring Agent (MMA) is installed and configured to report sensor data to the service](configure-server-endpoints.md#server-mma) +- [Ensure that the server proxy and Internet connectivity settings are configured properly](configure-server-endpoints.md#server-proxy) You might also need to check the following: - Check that there is a Microsoft Defender Advanced Threat Protection Service running in the **Processes** tab in **Task Manager**. For example: @@ -306,7 +306,7 @@ For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us ## Related topics -- [Troubleshoot Microsoft Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) -- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) -- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender ATP](troubleshoot.md) +- [Onboard machines](onboard-configure.md) +- [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md index 7d2a7d86da..1ff99f3d60 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md @@ -80,8 +80,8 @@ If you encounter an error when trying to enable the SIEM connector application, >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootsiem-belowfoldlink) ## Related topics -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md index b5201a5814..84c7b19ed4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md @@ -37,13 +37,13 @@ Make sure that `*.securitycenter.windows.com` is included the proxy whitelist. ## Microsoft Defender ATP service shows event or error logs in the Event Viewer -See the topic [Review events and errors using Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) for a list of event IDs that are reported by the Microsoft Defender ATP service. The topic also contains troubleshooting steps for event errors. +See the topic [Review events and errors using Event Viewer](event-error-codes.md) for a list of event IDs that are reported by the Microsoft Defender ATP service. The topic also contains troubleshooting steps for event errors. ## Microsoft Defender ATP service fails to start after a reboot and shows error 577 If onboarding machines successfully completes but Microsoft Defender ATP does not start after a reboot and shows error 577, check that Windows Defender is not disabled by a policy. -For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). +For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). ## Known issues with regional formats @@ -73,5 +73,5 @@ When you use Azure Security Center to monitor servers, a Microsoft Defender ATP ## Related topics -- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) -- [Review events and errors using Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding.md) +- [Review events and errors using Event Viewer](event-error-codes.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md index 4320d58d31..c1bfd3a410 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.Isolate | 'Isolate machine' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md index 9531e39835..9680a57aec 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.RestrictExecution | 'Restrict code >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md index be7b420a9b..9752745d78 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md +++ b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md @@ -36,8 +36,8 @@ Delegated (work or school account) | Alert.ReadWrite | 'Read and write alerts' >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Alerts investigation' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Alerts investigation' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine associated with the alert, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md index 580beea62a..c8174671cd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md @@ -35,10 +35,10 @@ You can use the code examples to guide you in creating calls to the custom threa Topic | Description :---|:--- -[Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) | Understand the concepts around threat intelligence so that you can effectively create custom intelligence for your organization. -[Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) | Set up the custom threat intelligence application through Microsoft Defender Security Center so that you can create custom threat intelligence (TI) using REST API. -[Create custom threat intelligence alerts](custom-ti-api-windows-defender-advanced-threat-protection.md) | Create custom threat intelligence alerts so that you can generate specific alerts that are applicable to your organization. -[PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md) | Use the PowerShell code examples to guide you in using the custom threat intelligence API. -[Python code examples](python-example-code-windows-defender-advanced-threat-protection.md) | Use the Python code examples to guide you in using the custom threat intelligence API. -[Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) | This article demonstrates an end-to-end usage of the threat intelligence API to get you started in using the threat intelligence API. -[Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) | Learn how to address possible issues you might encounter while using the threat intelligence API. +[Understand threat intelligence concepts](threat-indicator-concepts.md) | Understand the concepts around threat intelligence so that you can effectively create custom intelligence for your organization. +[Enable the custom threat intelligence application](enable-custom-ti.md) | Set up the custom threat intelligence application through Microsoft Defender Security Center so that you can create custom threat intelligence (TI) using REST API. +[Create custom threat intelligence alerts](custom-ti-api.md) | Create custom threat intelligence alerts so that you can generate specific alerts that are applicable to your organization. +[PowerShell code examples](powershell-example-code.md) | Use the PowerShell code examples to guide you in using the custom threat intelligence API. +[Python code examples](python-example-code.md) | Use the Python code examples to guide you in using the custom threat intelligence API. +[Experiment with custom threat intelligence alerts](experiment-custom-ti.md) | This article demonstrates an end-to-end usage of the threat intelligence API to get you started in using the threat intelligence API. +[Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti.md) | Learn how to address possible issues you might encounter while using the threat intelligence API. diff --git a/windows/security/threat-protection/microsoft-defender-atp/use.md b/windows/security/threat-protection/microsoft-defender-atp/use.md index 2f1fff7f2e..df066b9b7e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use.md @@ -39,9 +39,9 @@ Use the **Threat analytics** dashboard to continually assess and control risk ex Topic | Description :---|:--- -[Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) | Understand the portal layout and area descriptions. -[View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. -[View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | The **Secure Score dashboard** expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. -[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. +[Portal overview](portal-overview.md) | Understand the portal layout and area descriptions. +[View the Security operations dashboard](security-operations-dashboard.md) | The Microsoft Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. +[View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) | The **Secure Score dashboard** expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. +[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. diff --git a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md index 2c305c28e0..fd2f77e7a0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md +++ b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md @@ -77,5 +77,5 @@ After creating roles, you'll need to create a machine group and provide access t ##Related topic -- [User basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) -- [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [User basic permissions to access the portal](basic-permissions.md) +- [Create and manage machine groups](machine-groups.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md index a7d944a061..060b92ef38 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md @@ -73,6 +73,6 @@ Use this filter to choose between focusing on incidents flagged as true or false ## Related topics - [Incidents queue](incidents-queue.md) -- [Manage incidents](manage-incidents-windows-defender-advanced-threat-protection.md) -- [Investigate incidents](investigate-incidents-windows-defender-advanced-threat-protection.md) +- [Manage incidents](manage-incidents.md) +- [Investigate incidents](investigate-incidents.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md index 93ec317ca9..d08d240b1c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md @@ -93,7 +93,7 @@ Microsoft Defender ATP is seamlessly integrated in Microsoft Threat Protection t - [Onboard Windows Server 2019](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#windows-server-version-1803-and-windows-server-2019)
Microsoft Defender ATP now adds support for Windows Server 2019. You'll be able to onboard Windows Server 2019 in the same method available for Windows 10 client machines. -- [Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
+- [Power BI reports using Microsoft Defender ATP data](powerbi-reports.md)
Microsoft Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md index af2106bf2b..89b74b62a0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md @@ -27,13 +27,13 @@ Microsoft Defender Security Center is the portal where you can access Microsoft Topic | Description :---|:--- Get started | Learn about the minimum requirements, validate licensing and complete setup, know about preview features, understand data storage and privacy, and how to assign user access to the portal. -[Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) | Learn about onboarding client, server, and non-Windows machines. Learn how to run a detection test, configure proxy and Internet connectivity settings, and how to troubleshoot potential onboarding issues. -[Understand the portal](use-windows-defender-advanced-threat-protection.md) | Understand the Security operations, Secure Score, and Threat analytics dashboards as well as how to navigate the portal. +[Onboard machines](onboard-configure.md) | Learn about onboarding client, server, and non-Windows machines. Learn how to run a detection test, configure proxy and Internet connectivity settings, and how to troubleshoot potential onboarding issues. +[Understand the portal](use.md) | Understand the Security operations, Secure Score, and Threat analytics dashboards as well as how to navigate the portal. Investigate and remediate threats | Investigate alerts, machines, and take response actions to remediate threats. API and SIEM support | Use the supported APIs to pull and create custom alerts, or automate workflows. Use the supported SIEM tools to pull alerts from Microsoft Defender Security Center. Reporting | Create and build Power BI reports using Microsoft Defender ATP data. Check service health and sensor state | Verify that the service is running and check the sensor state on machines. -[Configure Microsoft Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. -[Access the Microsoft Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md) | Access the Microsoft Defender ATP Community Center to learn, collaborate, and share experiences about the product. -[Troubleshoot service issues](troubleshoot-windows-defender-advanced-threat-protection.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. +[Configure Microsoft Defender Security Center settings](preferences-setup.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. +[Access the Microsoft Defender ATP Community Center](community.md) | Access the Microsoft Defender ATP Community Center to learn, collaborate, and share experiences about the product. +[Troubleshoot service issues](troubleshoot.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. From c8594e7e6f47e1e5716859e28d2bdb4ca262182f Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:12:26 -0700 Subject: [PATCH 132/737] fix index file --- .../change-history-for-threat-protection.md | 5 +- windows/security/threat-protection/index.md | 98 +++++++++---------- .../{conditional.md => conditional-access.md} | 0 3 files changed, 51 insertions(+), 52 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{conditional.md => conditional-access.md} (100%) diff --git a/windows/security/threat-protection/change-history-for-threat-protection.md b/windows/security/threat-protection/change-history-for-threat-protection.md index 1deaa652b8..76b8efdb9f 100644 --- a/windows/security/threat-protection/change-history-for-threat-protection.md +++ b/windows/security/threat-protection/change-history-for-threat-protection.md @@ -10,16 +10,15 @@ manager: dansimp audience: ITPro ms.collection: M365-security-compliance ms.topic: conceptual -ms.date: 08/11/2018 ms.localizationpriority: medium --- # Change history for threat protection -This topic lists new and updated topics in the [Windows Defender ATP](windows-defender-atp/windows-defender-advanced-threat-protection.md) documentation. +This topic lists new and updated topics in the [Microsoft Defender ATP](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) documentation. ## August 2018 New or changed topic | Description ---------------------|------------ -[Windows Defender Advanced Threat Protection](windows-defender-atp/windows-defender-advanced-threat-protection.md) | Reorganized Windows 10 security topics to reflect the Windows Defender ATP platform. +[Microsoft Defender Advanced Threat Protection](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) | Reorganized Windows 10 security topics to reflect the Windows Defender ATP platform. diff --git a/windows/security/threat-protection/index.md b/windows/security/threat-protection/index.md index 44c4ef2a2f..d657ec1311 100644 --- a/windows/security/threat-protection/index.md +++ b/windows/security/threat-protection/index.md @@ -1,7 +1,7 @@ --- title: Threat Protection (Windows 10) -description: Learn how Windows Defender ATP helps protect against threats. -keywords: threat protection, windows defender advanced threat protection, attack surface reduction, next generation protection, endpoint detection and response, automated investigation and response, microsoft threat experts, secure score, advanced hunting +description: Learn how Microsoft Defender ATP helps protect against threats. +keywords: threat protection, Microsoft Defender Advanced Threat Protection, attack surface reduction, next generation protection, endpoint detection and response, automated investigation and response, microsoft threat experts, secure score, advanced hunting search.product: eADQiWindows 10XVcnh ms.prod: w10 ms.mktglfcycl: deploy @@ -12,9 +12,9 @@ ms.localizationpriority: medium --- # Threat Protection -[Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) is a unified platform for preventative protection, post-breach detection, automated investigation, and response. Windows Defender ATP protects endpoints from cyber threats; detects advanced attacks and data breaches, automates security incidents and improves security posture. +[Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) is a unified platform for preventative protection, post-breach detection, automated investigation, and response. Microsoft Defender ATP protects endpoints from cyber threats; detects advanced attacks and data breaches, automates security incidents and improves security posture. -

Windows Defender ATP

+

Microsoft Defender ATP

@@ -71,8 +71,8 @@ Windows Defender ATP uses the following combination of technology built into Win >[!TIP] ->- Learn about the latest enhancements in Windows Defender ATP: [What's new in Windows Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). ->- Windows Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). +>- Learn about the latest enhancements in Microsoft Defender ATP: [What's new in Microsoft Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). +>- Microsoft Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). **[Attack surface reduction](overview-attack-surface-reduction.md)**
The attack surface reduction set of capabilities provide the first line of defense in the stack. By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. @@ -80,7 +80,7 @@ The attack surface reduction set of capabilities provide the first line of defen **[Next generation protection](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10)**
-To further reinforce the security perimeter of your network, Windows Defender ATP uses next generation protection designed to catch all types of emerging threats. +To further reinforce the security perimeter of your network, Microsoft Defender ATP uses next generation protection designed to catch all types of emerging threats. @@ -91,27 +91,27 @@ You can also do advanced hunting to create custom threat intelligence and use a **[Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md)**
-In conjunction with being able to quickly respond to advanced attacks, Windows Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. +In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. **[Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md)**
-Windows Defender ATP includes a secure score to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security of your organization. +Microsoft Defender ATP includes a secure score to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security of your organization. **[Microsoft Threat Experts](microsoft-threat-experts.md)**
-Windows Defender ATP's new managed threat hunting service provides proactive hunting, prioritization, and additional context and insights that further empower Security operation centers (SOCs) to identify and respond to threats quickly and accurately. +Microsoft Defender ATP's new managed threat hunting service provides proactive hunting, prioritization, and additional context and insights that further empower Security operation centers (SOCs) to identify and respond to threats quickly and accurately. **[Management and APIs](management-apis.md)**
-Integrate Windows Defender Advanced Threat Protection into your existing workflows. +Integrate Microsoft Defender Advanced Threat Protection into your existing workflows. **[Microsoft Threat Protection](threat-protection-integration.md)**
- Windows Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. Bring the power of Microsoft threat protection to your organization. + Microsoft Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. Bring the power of Microsoft threat protection to your organization. @@ -120,10 +120,10 @@ To help you maximize the effectiveness of the security platform, you can configu Topic | Description :---|:--- -[Overview](overview.md) | Understand the concepts behind the capabilities in Windows Defender ATP so you take full advantage of the complete threat protection platform. -[Get started](get-started.md) | Learn about the requirements of the platform and the initial steps you need to take to get started with Windows Defender ATP. -[Configure and manage capabilities](onboard.md)| Configure and manage the individual capabilities in Windows Defender ATP. -[Troubleshoot Windows Defender ATP](troubleshoot-wdatp.md) | Learn how to address issues that you might encounter while using the platform. +[Overview](overview.md) | Understand the concepts behind the capabilities in Microsoft Defender ATP so you take full advantage of the complete threat protection platform. +[Get started](get-started.md) | Learn about the requirements of the platform and the initial steps you need to take to get started with Microsoft Defender ATP. +[Configure and manage capabilities](onboard.md)| Configure and manage the individual capabilities in Microsoft Defender ATP. +[Troubleshoot Microsoft Defender ATP](troubleshoot-wdatp.md) | Learn how to address issues that you might encounter while using the platform. ## Related topic -[Windows Defender ATP helps detect sophisticated threats](https://www.microsoft.com/itshowcase/Article/Content/854/Windows-Defender-ATP-helps-detect-sophisticated-threats) +[Microsoft Defender ATP helps detect sophisticated threats](https://www.microsoft.com/itshowcase/Article/Content/854/Windows-Defender-ATP-helps-detect-sophisticated-threats) diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md index 380af8ef33..652eaf3652 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md @@ -1,6 +1,6 @@ --- title: Microsoft Threat Experts -description: Microsoft Threat Experts is the new managed threat hunting service in Windows Defender Advanced Threat Protection (Windows Defender ATP) that provides proactive hunting, prioritization, and additional context and insights that further empower security operations centers (SOCs) to identify and respond to threats quickly and accurately. It provides additional layer of expertise and optics that Microsoft customers can utilize to augment security operation capabilities as part of Microsoft 365. +description: Microsoft Threat Experts is the new managed threat hunting service in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) that provides proactive hunting, prioritization, and additional context and insights that further empower security operations centers (SOCs) to identify and respond to threats quickly and accurately. It provides additional layer of expertise and optics that Microsoft customers can utilize to augment security operation capabilities as part of Microsoft 365. keywords: managed threat hunting service, managed threat hunting, MTE, Microsoft Threat Experts search.product: Windows 10 search.appverid: met150 @@ -20,7 +20,7 @@ ms.date: 02/28/2019 # Microsoft Threat Experts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease�information](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md index afd1ba57b5..5a4a309e6f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md +++ b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md @@ -1,5 +1,5 @@ --- -title: Minimum requirements for Windows Defender ATP +title: Minimum requirements for Microsoft Defender ATP description: Understand the licensing requirements and requirements for onboarding machines to the sercvie keywords: minimum requirements, licensing, comparison table search.product: eADQiWindows 10XVcnh @@ -17,22 +17,22 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Minimum requirements for Windows Defender ATP +# Minimum requirements for Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) There are some minimum requirements for onboarding machines to the service. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-minreqs-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-minreqs-abovefoldlink) >[!TIP] ->- Learn about the latest enhancements in Windows Defender ATP: [What's new in Windows Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). ->- Windows Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). +>- Learn about the latest enhancements in Microsoft Defender ATP: [What's new in Microsoft Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). +>- Microsoft Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). ## Licensing requirements -Windows Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: +Microsoft Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: - Windows 10 Enterprise E5 - Windows 10 Education E5 @@ -42,7 +42,7 @@ For more information on the array of features in Windows 10 editions, see [Compa For a detailed comparison table of Windows 10 commercial edition comparison, see the [comparison PDF](https://go.microsoft.com/fwlink/p/?linkid=2069559). -For more information about licensing requirements for Windows Defender ATP platform on Windows Server, see [Protecting Windows Servers with Windows Defender ATP](https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Protecting-Windows-Server-with-Windows-Defender-ATP/ba-p/267114). +For more information about licensing requirements for Microsoft Defender ATP platform on Windows Server, see [Protecting Windows Servers with Microsoft Defender ATP](https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Protecting-Windows-Server-with-Windows-Defender-ATP/ba-p/267114). ## Related topic diff --git a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md index dfd40d8852..33e5a03df9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md @@ -1,6 +1,6 @@ --- title: Managed security service provider (MSSP) support -description: Understand how Windows Defender ATP integrates with managed security service providers (MSSP) +description: Understand how Microsoft Defender ATP integrates with managed security service providers (MSSP) keywords: mssp, integration, managed, security, service, provider search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,19 +21,19 @@ ms.date: 10/29/2018 # Managed security service provider support **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mssp-support-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-mssp-support-abovefoldlink) Security is recognized as a key component in running an enterprise, however some organizations might not have the capacity or expertise to have a dedicated security operations team to manage the security of their endpoints and network, others may want to have a second set of eyes to review alerts in their network. -To address this demand, managed security service providers (MSSP) offer to deliver managed detection and response (MDR) services on top of Windows Defender ATP. +To address this demand, managed security service providers (MSSP) offer to deliver managed detection and response (MDR) services on top of Microsoft Defender ATP. -Windows Defender ATP adds support for this scenario and to allow MSSPs to take the following actions: +Microsoft Defender ATP adds support for this scenario and to allow MSSPs to take the following actions: - Get access to MSSP customer's Windows Defender Security Center portal - Get email notifications, and diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md index 50855b0351..d2eff9b682 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md @@ -18,16 +18,16 @@ ms.topic: article # Offboard machine API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prereleaseinformation](prerelease.md)] -Offboard machine from Windows Defender ATP. +Offboard machine from Microsoft Defender ATP. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md index 273bfed16c..a22fafe295 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/offboard-machines.md @@ -1,6 +1,6 @@ --- -title: Offboard machines from the Windows Defender ATP service -description: Onboard Windows 10 machines, servers, non-Windows machines from the Windows Defender ATP service +title: Offboard machines from the Microsoft Defender ATP service +description: Onboard Windows 10 machines, servers, non-Windows machines from the Microsoft Defender ATP service keywords: offboarding, windows defender advanced threat protection offboarding, windows atp offboarding search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,18 +18,18 @@ ms.topic: conceptual ms.date: 04/24/2018 --- -# Offboard machines from the Windows Defender ATP service +# Offboard machines from the Microsoft Defender ATP service **Applies to:** - macOS - Linux - Windows Server 2012 R2 - Windows Server 2016 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-offboardmachines-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-offboardmachines-abovefoldlink) Follow the corresponding instructions depending on your preferred deployment method. diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md index a33cae087b..353ee5e12b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md @@ -1,5 +1,5 @@ --- -title: Onboard machines to the Windows Defender ATP service +title: Onboard machines to the Microsoft Defender ATP service description: Onboard Windows 10 machines, servers, non-Windows machines and learn how to run a detection test. keywords: onboarding, windows defender advanced threat protection onboarding, windows atp onboarding, sccm, group policy, mdm, local script, detection test search.product: eADQiWindows 10XVcnh @@ -18,21 +18,21 @@ ms.topic: conceptual ms.date: 11/19/2018 --- -# Onboard machines to the Windows Defender ATP service +# Onboard machines to the Microsoft Defender ATP service **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -You need to turn on the sensor to give visibility within Windows Defender ATP. +You need to turn on the sensor to give visibility within Microsoft Defender ATP. -For more information, see [Onboard your Windows 10 machines to Windows Defender ATP](https://www.youtube.com/watch?v=JT7VGYfeRlA&feature=youtu.be). +For more information, see [Onboard your Windows 10 machines to Microsoft Defender ATP](https://www.youtube.com/watch?v=JT7VGYfeRlA&feature=youtu.be). [!include[Prerelease information](prerelease.md)] ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-abovefoldlink) ## Licensing requirements -Windows Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: +Microsoft Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: - Windows 10 Enterprise E5 - Windows 10 Education E5 @@ -59,7 +59,7 @@ For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us Machines on your network must be running one of these editions. -The hardware requirements for Windows Defender ATP on machines is the same as those for the supported editions. +The hardware requirements for Microsoft Defender ATP on machines is the same as those for the supported editions. > [!NOTE] > Machines that are running mobile versions of Windows are not supported. @@ -70,15 +70,15 @@ The hardware requirements for Windows Defender ATP on machines is the same as th - Linux >[!NOTE] ->You'll need to know the exact Linux distros and macOS versions that are compatible with Windows Defender ATP for the integration to work. +>You'll need to know the exact Linux distros and macOS versions that are compatible with Microsoft Defender ATP for the integration to work. ### Network and data storage and configuration requirements -When you run the onboarding wizard for the first time, you must choose where your Windows Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter. +When you run the onboarding wizard for the first time, you must choose where your Microsoft Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter. > [!NOTE] > - You cannot change your data storage location after the first-time setup. -> - Review the [Windows Defender ATP data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) for more information on where and how Microsoft stores your data. +> - Review the [Microsoft Defender ATP data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) for more information on where and how Microsoft stores your data. ### Diagnostic data settings @@ -132,7 +132,7 @@ If the **START_TYPE** is not set to **AUTO_START**, then you'll need to set the #### Internet connectivity Internet connectivity on machines is required either directly or through proxy. -The Windows Defender ATP sensor can utilize a daily average bandwidth of 5MB to communicate with the Windows Defender ATP cloud service and report cyber data. One-off activities such as file uploads and investigation package collection are not included in this daily average bandwidth. +The Microsoft Defender ATP sensor can utilize a daily average bandwidth of 5MB to communicate with the Microsoft Defender ATP cloud service and report cyber data. One-off activities such as file uploads and investigation package collection are not included in this daily average bandwidth. For more information on additional proxy configuration settings see, [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) . @@ -140,11 +140,11 @@ Before you onboard machines, the diagnostic data service must be enabled. The se ## Windows Defender Antivirus configuration requirement -The Windows Defender ATP agent depends on the ability of Windows Defender Antivirus to scan files and provide information about them. +The Microsoft Defender ATP agent depends on the ability of Windows Defender Antivirus to scan files and provide information about them. -You must configure Security intelligence updates on the Windows Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). +You must configure Security intelligence updates on the Microsoft Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). -When Windows Defender Antivirus is not the active antimalware in your organization and you use the Windows Defender ATP service, Windows Defender Antivirus goes on passive mode. If your organization has disabled Windows Defender Antivirus through group policy or other methods, machines that are onboarded to Windows Defender ATP must be excluded from this group policy. +When Windows Defender Antivirus is not the active antimalware in your organization and you use the Microsoft Defender ATP service, Windows Defender Antivirus goes on passive mode. If your organization has disabled Windows Defender Antivirus through group policy or other methods, machines that are onboarded to Microsoft Defender ATP must be excluded from this group policy. If you are onboarding servers and Windows Defender Antivirus is not the active antimalware on your servers, you shouldn't uninstall Windows Defender Antivirus. You'll need to configure it to run on passive mode. For more information, see [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md). @@ -152,7 +152,7 @@ If you are onboarding servers and Windows Defender Antivirus is not the active a For more information, see [Windows Defender Antivirus compatibility](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). ## Windows Defender Antivirus Early Launch Antimalware (ELAM) driver is enabled -If you're running Windows Defender Antivirus as the primary antimalware product on your machines, the Windows Defender ATP agent will successfully onboard. +If you're running Windows Defender Antivirus as the primary antimalware product on your machines, the Microsoft Defender ATP agent will successfully onboard. If you're running a third-party antimalware client and use Mobile Device Management solutions or System Center Configuration Manager (current branch) version 1606, you'll need to ensure that the Windows Defender Antivirus ELAM driver is enabled. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). @@ -160,12 +160,12 @@ If you're running a third-party antimalware client and use Mobile Device Managem ## In this section Topic | Description :---|:--- -[Onboard previous versions of Windows](onboard-downlevel-windows-defender-advanced-threat-protection.md)| Onboard Windows 7 and Windows 8.1 machines to Windows Defender ATP. -[Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) | You'll need to onboard machines for it to report to the Windows Defender ATP service. Learn about the tools and methods you can use to configure machines in your enterprise. -[Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) | Onboard Windows Server 2012 R2 and Windows Server 2016 to Windows Defender ATP -[Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) | Windows Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. -[Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md) | Run a script on a newly onboarded machine to verify that it is properly reporting to the Windows Defender ATP service. -[Configure proxy and Internet settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)| Enable communication with the Windows Defender ATP cloud service by configuring the proxy and Internet connectivity settings. +[Onboard previous versions of Windows](onboard-downlevel-windows-defender-advanced-threat-protection.md)| Onboard Windows 7 and Windows 8.1 machines to Microsoft Defender ATP. +[Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) | You'll need to onboard machines for it to report to the Microsoft Defender ATP service. Learn about the tools and methods you can use to configure machines in your enterprise. +[Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) | Onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP +[Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) | Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. +[Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md) | Run a script on a newly onboarded machine to verify that it is properly reporting to the Microsoft Defender ATP service. +[Configure proxy and Internet settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)| Enable communication with the Microsoft Defender ATP cloud service by configuring the proxy and Internet connectivity settings. [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) | Learn about resolving issues that might arise during onboarding. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md index 700436d636..140c14d487 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel.md @@ -1,6 +1,6 @@ --- -title: Onboard previous versions of Windows on Windows Defender ATP -description: Onboard supported previous versions of Windows machines so that they can send sensor data to the Windows Defender ATP sensor +title: Onboard previous versions of Windows on Microsoft Defender ATP +description: Onboard supported previous versions of Windows machines so that they can send sensor data to the Microsoft Defender ATP sensor keywords: onboard, windows, 7, 81, oms, sp1, enterprise, pro, down level search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -25,35 +25,35 @@ ms.topic: article - Windows 7 SP1 Pro - Windows 8.1 Pro - Windows 8.1 Enterprise -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-downlevel-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-downlevel-abovefoldlink) -Windows Defender ATP extends support to include down-level operating systems, providing advanced attack detection and investigation capabilities on supported Windows versions. +Microsoft Defender ATP extends support to include down-level operating systems, providing advanced attack detection and investigation capabilities on supported Windows versions. >[!IMPORTANT] >This capability is currently in preview. You'll need to turn on the preview features to take advantage of this feature. For more information, see [Preview features](preview-windows-defender-advanced-threat-protection.md). -To onboard down-level Windows client endpoints to Windows Defender ATP, you'll need to: +To onboard down-level Windows client endpoints to Microsoft Defender ATP, you'll need to: - Configure and update System Center Endpoint Protection clients. -- Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Windows Defender ATP as instructed below. +- Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP as instructed below. >[!TIP] -> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Windows Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). +> After onboarding the machine, you can choose to run a detection test to verify that it is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). ## Configure and update System Center Endpoint Protection clients >[!IMPORTANT] >This step is required only if your organization uses System Center Endpoint Protection (SCEP). -Windows Defender ATP integrates with System Center Endpoint Protection to provide visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware. +Microsoft Defender ATP integrates with System Center Endpoint Protection to provide visibility to malware detections and to stop propagation of an attack in your organization by banning potentially malicious files or suspected malware. The following steps are required to enable this integration: - Install the [January 2017 anti-malware platform update for Endpoint Protection clients](https://support.microsoft.com/help/3209361/january-2017-anti-malware-platform-update-for-endpoint-protection-clie) - Configure the SCEP client Cloud Protection Service membership to the **Advanced** setting - Configure your network to allow connections to the Windows Defender Antivirus cloud. For more information, see [Allow connections to the Windows Defender Antivirus cloud](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-network-connections-windows-defender-antivirus#allow-connections-to-the-windows-defender-antivirus-cloud) -## Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Windows Defender ATP +## Install and configure Microsoft Monitoring Agent (MMA) to report sensor data to Microsoft Defender ATP ### Before you begin Review the following details to verify minimum system requirements: @@ -77,7 +77,7 @@ Review the following details to verify minimum system requirements: 1. Download the agent setup file: [Windows 64-bit agent](https://go.microsoft.com/fwlink/?LinkId=828603) or [Windows 32-bit agent](https://go.microsoft.com/fwlink/?LinkId=828604). 2. Obtain the workspace ID: - - In the Windows Defender ATP navigation pane, select **Settings > Machine management > Onboarding** + - In the Microsoft Defender ATP navigation pane, select **Settings > Machine management > Onboarding** - Select **Windows 7 SP1 and 8.1** as the operating system - Copy the workspace ID and workspace key @@ -93,7 +93,7 @@ Once completed, you should see onboarded endpoints in the portal within an hour. ### Configure proxy and Internet connectivity settings - Each Windows endpoint must be able to connect to the Internet using HTTPS. This connection can be direct, using a proxy, or through the [OMS Gateway](https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-oms-gateway). -- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are white-listed to permit communication with Windows Defender ATP service: +- If a proxy or firewall is blocking all traffic by default and allowing only specific domains through or HTTPS scanning (SSL inspection) is enabled, make sure that the following URLs are white-listed to permit communication with Microsoft Defender ATP service: Agent Resource | Ports :---|:--- @@ -110,9 +110,9 @@ Agent Resource | Ports ## Offboard client endpoints -To offboard, you can uninstall the MMA agent from the endpoint or detach it from reporting to your Windows Defender ATP workspace. After offboarding the agent, the endpoint will no longer send sensor data to Windows Defender ATP. +To offboard, you can uninstall the MMA agent from the endpoint or detach it from reporting to your Microsoft Defender ATP workspace. After offboarding the agent, the endpoint will no longer send sensor data to Microsoft Defender ATP. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-downlevele-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-downlevele-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard.md b/windows/security/threat-protection/microsoft-defender-atp/onboard.md index 319d254a8e..9bb3eaa985 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard.md @@ -1,6 +1,6 @@ --- -title: Configure and manage Windows Defender ATP capabilities -description: Configure and manage Windows Defender ATP capabilities such as attack surface reduction, next generation protection, and security controls +title: Configure and manage Microsoft Defender ATP capabilities +description: Configure and manage Microsoft Defender ATP capabilities such as attack surface reduction, next generation protection, and security controls keywords: configure, manage, capabilities, attack surface reduction, next generation protection, security controls, endpoint detection and response, auto investigation and remediation, security controls, controls search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,12 +18,12 @@ ms.topic: conceptual ms.date: 09/03/2018 --- -# Configure and manage Windows Defender ATP capabilities +# Configure and manage Microsoft Defender ATP capabilities **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Configure and manage all the Windows Defender ATP capabilities to get the best security protection for your organization. +Configure and manage all the Microsoft Defender ATP capabilities to get the best security protection for your organization. ## In this section @@ -32,7 +32,7 @@ Topic | Description [Configure attack surface reduction capabilities](configure-attack-surface-reduction.md) | By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. [Configure next generation protection](../windows-defender-antivirus/configure-windows-defender-antivirus-features.md) | Configure next generation protection to catch all types of emerging threats. [Configure Secure score dashboard security controls](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | Configure the security controls in Secure score to increase the security posture of your organization. -Configure Microsoft Threat Protection integration| Configure other solutions that integrate with Windows Defender ATP. +Configure Microsoft Threat Protection integration| Configure other solutions that integrate with Microsoft Defender ATP. Management and API support| Pull alerts to your SIEM or use APIs to create custom alerts. Create and build Power BI reports. [Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md b/windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md index c2617a285e..f5e0f9e489 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-attack-surface-reduction.md @@ -1,6 +1,6 @@ --- title: Overview of attack surface reduction -description: Learn about the attack surface reduction capability in Windows Defender ATP +description: Learn about the attack surface reduction capability in Microsoft Defender ATP keywords: search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,9 +21,9 @@ ms.date: 02/21/2019 # Overview of attack surface reduction **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Attack surface reduction capabilities in Windows Defender ATP helps protect the devices and applications in your organization from new and emerging threats. +Attack surface reduction capabilities in Microsoft Defender ATP helps protect the devices and applications in your organization from new and emerging threats. | Capability | Description | |------------|-------------| diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md b/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md index 13268d34ad..8101a199e5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md @@ -21,10 +21,10 @@ ms.date: 10/29/2018 # Custom detections overview **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Alerts in Windows Defender ATP are surfaced through the system based on signals gathered from endpoints. With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. +Alerts in Microsoft Defender ATP are surfaced through the system based on signals gathered from endpoints. With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. This can be done by leveraging the power of Advanced hunting through the creation of custom detection rules. Custom detections are queries that run periodically every 24 hours and can be configured so that when the query meets the criteria you set, alerts are created and are surfaced in Windows Defender Security Center. These alerts will be treated like any other alert in the system. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md index 1fb9eea8e2..0d954897a9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-endpoint-detection-response.md @@ -1,6 +1,6 @@ --- title: Overview of endpoint detection and response capabilities -description: Learn about the endpoint detection and response capabilities in Windows Defender ATP +description: Learn about the endpoint detection and response capabilities in Microsoft Defender ATP keywords: search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -22,13 +22,13 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Windows Defender ATP endpoint detection and response capabilities provide advanced attack detections that are near real-time and actionable. Security analysts can prioritize alerts effectively, gain visibility into the full scope of a breach, and take response actions to remediate threats. +Microsoft Defender ATP endpoint detection and response capabilities provide advanced attack detections that are near real-time and actionable. Security analysts can prioritize alerts effectively, gain visibility into the full scope of a breach, and take response actions to remediate threats. When a threat is detected, alerts are created in the system for an analyst to investigate. Alerts with the same attack techniques or attributed to the same attacker are aggregated into an entity called an _incident_. Aggregating alerts in this manner makes it easy for analysts to collectively investigate and respond to threats. -Inspired by the "assume breach" mindset, Windows Defender ATP continuously collects behavioral cyber telemetry. This includes process information, network activities, deep optics into the kernel and memory manager, user login activities, registry and file system changes, and others. The information is stored for six months, enabling an analyst to travel back in time to the start of an attack. The analyst can then pivot in various views and approach an investigation through multiple vectors. +Inspired by the "assume breach" mindset, Microsoft Defender ATP continuously collects behavioral cyber telemetry. This includes process information, network activities, deep optics into the kernel and memory manager, user login activities, registry and file system changes, and others. The information is stored for six months, enabling an analyst to travel back in time to the start of an attack. The analyst can then pivot in various views and approach an investigation through multiple vectors. The response capabilities give you the power to promptly remediate threats by acting on the affected entities. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md index b86fea8fb4..2c91a25599 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-hardware-based-isolation.md @@ -18,9 +18,9 @@ ms.date: 09/07/2018 # Hardware-based isolation in Windows 10 -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Hardware-based isolation helps protect system integrity in Windows 10 and is integrated with Windows Defender ATP. +Hardware-based isolation helps protect system integrity in Windows 10 and is integrated with Microsoft Defender ATP. | Feature | Description | |------------|-------------| diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md index 8d95c6f102..6742a95514 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md @@ -20,7 +20,7 @@ ms.date: 09/12/2018 # Overview of advanced hunting **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Windows Defender Security Center. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index 33671e8778..3d27aa1319 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -20,7 +20,7 @@ ms.date: 09/03/2018 # Overview of Secure score in Windows Defender Security Center **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) The Secure score dashboard expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. From there you can take action based on the recommended configuration baselines. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview.md b/windows/security/threat-protection/microsoft-defender-atp/overview.md index f9989d69f7..84d99f3816 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview.md @@ -1,5 +1,5 @@ --- -title: Overview of Windows Defender ATP +title: Overview of Microsoft Defender ATP description: keywords: search.product: eADQiWindows 10XVcnh @@ -18,28 +18,28 @@ ms.topic: conceptual ms.date: 11/20/2018 --- -# Overview of Windows Defender ATP capabilities +# Overview of Microsoft Defender ATP capabilities **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Understand the concepts behind the capabilities in Windows Defender ATP so you take full advantage of the complete threat protection platform. +Understand the concepts behind the capabilities in Microsoft Defender ATP so you take full advantage of the complete threat protection platform. >[!TIP] ->- Learn about the latest enhancements in Windows Defender ATP: [What's new in Windows Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). ->- Windows Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). +>- Learn about the latest enhancements in Microsoft Defender ATP: [What's new in Microsoft Defender ATP](https://cloudblogs.microsoft.com/microsoftsecure/2018/11/15/whats-new-in-windows-defender-atp/). +>- Microsoft Defender ATP demonstrated industry-leading optics and detection capabilities in the recent MITRE evaluation. Read: [Insights from the MITRE ATT&CK-based evaluation](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/insights-from-the-mitre-attack-based-evaluation-of-windows-defender-atp/). ## In this section Topic | Description :---|:--- [Attack surface reduction](overview-attack-surface-reduction.md) | Leverage the attack surface reduction capabilities to protect the perimeter of your organization. -[Next generation protection](../windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) | Learn about the antivirus capabilities in Windows Defender ATP so you can protect desktops, portable computers, and servers. -[Endpoint detection and response](overview-endpoint-detection-response.md) | Understand how Windows Defender ATP continuously monitors your organization for possible attacks against systems, networks, or users in your organization and the features you can use to mitigate and remediate threats. -[Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md) | In conjunction with being able to quickly respond to advanced attacks, Windows Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. +[Next generation protection](../windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) | Learn about the antivirus capabilities in Microsoft Defender ATP so you can protect desktops, portable computers, and servers. +[Endpoint detection and response](overview-endpoint-detection-response.md) | Understand how Microsoft Defender ATP continuously monitors your organization for possible attacks against systems, networks, or users in your organization and the features you can use to mitigate and remediate threats. +[Automated investigation and remediation](automated-investigations-windows-defender-advanced-threat-protection.md) | In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. [Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) | Quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to better protect your organization - all in one place. [Advanced hunting](overview-hunting-windows-defender-advanced-threat-protection.md) | Use a powerful search and query language to create custom queries and detection rules. -[Management and APIs](management-apis.md) | Windows Defender ATP supports a wide variety of tools to help you manage and interact with the platform so that you can integrate the service into your existing workflows. +[Management and APIs](management-apis.md) | Microsoft Defender ATP supports a wide variety of tools to help you manage and interact with the platform so that you can integrate the service into your existing workflows. [Microsoft Threat Protection](threat-protection-integration.md) | Microsoft security products work better together. Learn about other security capabilities in the Microsoft threat protection stack. [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) |Learn to navigate your way around Windows Defender Security Center. diff --git a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md index 352394a662..7a4701750d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md @@ -1,5 +1,5 @@ --- -title: Windows Defender Advanced Threat Protection portal overview +title: Microsoft Defender Advanced Threat Protection portal overview description: Use Windows Defender Security Center to monitor your enterprise network and assist in responding to alerts to potential advanced persistent threat (APT) activity or data breaches. keywords: Windows Defender Security Center, portal, cybersecurity threat intelligence, dashboard, alerts queue, machines list, settings, machine management, advanced attacks search.product: eADQiWindows 10XVcnh @@ -18,26 +18,26 @@ ms.topic: conceptual ms.date: 04/24/2018 --- -# Windows Defender Advanced Threat Protection portal overview +# Microsoft Defender Advanced Threat Protection portal overview **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portaloverview-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portaloverview-abovefoldlink) Enterprise security teams can use Windows Defender Security Center to monitor and assist in responding to alerts of potential advanced persistent threat (APT) activity or data breaches. You can use [Windows Defender Security Center](https://securitycenter.windows.com/) to: - View, sort, and triage alerts from your endpoints - Search for more information on observed indicators such as files and IP Addresses -- Change Windows Defender ATP settings, including time zone and review licensing information. +- Change Microsoft Defender ATP settings, including time zone and review licensing information. ## Windows Defender Security Center When you open the portal, you’ll see the main areas of the application: - ![Windows Defender Advanced Threat Protection portal](images/dashboard.png) + ![Microsoft Defender Advanced Threat Protection portal](images/dashboard.png) - (1) Navigation pane - (2) Main portal @@ -56,18 +56,18 @@ Area | Description **Alerts** | View alerts generated from machines in your organizations. **Automated investigations** | Displays a list of automated investigations that's been conducted in the network, the status of each investigation and other details such as when the investigation started and the duration of the investigation. **Advanced hunting** | Advanced hunting allows you to proactively hunt and investigate across your organization using a powerful search and query tool. -**Machines list** | Displays the list of machines that are onboarded to Windows Defender ATP, some information about them, and the corresponding number of alerts. +**Machines list** | Displays the list of machines that are onboarded to Microsoft Defender ATP, some information about them, and the corresponding number of alerts. **Service health** | Provides information on the current status of the Window Defender ATP service. You'll be able to verify that the service health is healthy or if there are current issues. **Settings** | Shows the settings you selected during onboarding and lets you update your industry preferences and retention policy period. You can also set other configuration settings such as email notifications, activate the preview experience, enable or turn off advanced features, SIEM integration, threat intel API, build Power BI reports, and set baselines for the Secure Score dashboard. **(2) Main portal** | Main area where you will see the different views such as the Dashboards, Alerts queue, and Machines list. -**(3) Community center, Time settings, Help and support, Feedback** | **Community center** -Access the Community center to learn, collaborate, and share experiences about the product.

**Time settings** - Gives you access to the configuration settings where you can set time zones and view license information.

**Help and support** - Gives you access to the Windows Defender ATP guide, Microsoft support, and Premier support.

**Feedback** - Access the feedback button to provide comments about the portal. +**(3) Community center, Time settings, Help and support, Feedback** | **Community center** -Access the Community center to learn, collaborate, and share experiences about the product.

**Time settings** - Gives you access to the configuration settings where you can set time zones and view license information.

**Help and support** - Gives you access to the Microsoft Defender ATP guide, Microsoft support, and Premier support.

**Feedback** - Access the feedback button to provide comments about the portal. -## Windows Defender ATP icons +## Microsoft Defender ATP icons The following table provides information on the icons used all throughout the portal: Icon | Description :---|:--- -![ATP logo icon](images\atp-logo-icon.png)| Windows Defender ATP logo +![ATP logo icon](images\atp-logo-icon.png)| Microsoft Defender ATP logo ![Alert icon](images\alert-icon.png)| Alert – Indication of an activity correlated with advanced attacks. ![Detection icon](images\detection-icon.png)| Detection – Indication of a malware threat detection. ![Active threat icon](images\active-threat-icon.png)| Active threat – Threats actively executing at the time of detection. @@ -111,7 +111,7 @@ Icon | Description ## Related topics -- [Understand the Windows Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) +- [Understand the Microsoft Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) - [View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) - [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) - [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md index 1116788ea1..cbeeeeb7ef 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md +++ b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Submit or Update Indicator API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md index faa5965b72..0d4640bbf3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md @@ -1,6 +1,6 @@ --- -title: Create and build Power BI reports using Windows Defender ATP data -description: Get security insights by creating and building Power BI dashboards using data from Windows Defender ATP and other data sources. +title: Create and build Power BI reports using Microsoft Defender ATP data +description: Get security insights by creating and building Power BI dashboards using data from Microsoft Defender ATP and other data sources. keywords: settings, power bi, power bi service, power bi desktop, reports, dashboards, connectors , security insights, mashup search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,10 +18,10 @@ ms.date: 11/26/2018 --- -# Create and build Power BI reports using Windows Defender ATP data +# Create and build Power BI reports using Microsoft Defender ATP data **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] @@ -29,11 +29,11 @@ ms.date: 11/26/2018 >[!TIP] >Go to **Advanced features** in the **Settings** page to turn on the preview features. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-powerbireports-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-powerbireports-abovefoldlink) -Understand the security status of your organization, including the status of machines, alerts, and investigations using the Windows Defender ATP reporting feature that integrates with Power BI. +Understand the security status of your organization, including the status of machines, alerts, and investigations using the Microsoft Defender ATP reporting feature that integrates with Power BI. -Windows Defender ATP supports the use of Power BI data connectors to enable you to connect and access Windows Defender ATP data using Microsoft Graph. +Microsoft Defender ATP supports the use of Power BI data connectors to enable you to connect and access Microsoft Defender ATP data using Microsoft Graph. Data connectors integrate seamlessly in Power BI, and make it easy for power users to query, shape and combine data to build reports and dashboards that meet the needs of your organization. @@ -43,8 +43,8 @@ You can easily get started by: You can access these options from Windows Defender Security Center. Both the Power BI service and Power BI Desktop are supported. -## Create a Windows Defender ATP dashboard on Power BI service -Windows Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. +## Create a Microsoft Defender ATP dashboard on Power BI service +Microsoft Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. 1. In the navigation pane, select **Settings** > **Power BI reports**. @@ -66,11 +66,11 @@ Windows Defender ATP makes it easy to create a Power BI dashboard by providing a ![Image of Power BI authentication method](images/atp-powerbi-extension.png) -4. Click **Sign in**. If this is the first time you’re using Power BI with Windows Defender ATP, you’ll need to sign in and give consent to Windows Defender ATP Power BI app. By providing consent, you’re allowing Windows Defender ATP Power BI to sign in and read your profile, access your data, and be used for report refresh. +4. Click **Sign in**. If this is the first time you’re using Power BI with Microsoft Defender ATP, you’ll need to sign in and give consent to Microsoft Defender ATP Power BI app. By providing consent, you’re allowing Microsoft Defender ATP Power BI to sign in and read your profile, access your data, and be used for report refresh. ![Consent image](images/atp-powerbi-accept.png) -5. Click **Accept**. Power BI service will start downloading your Windows Defender ATP data from Microsoft Graph. After a successful login, you'll see a notification that data is being imported: +5. Click **Accept**. Power BI service will start downloading your Microsoft Defender ATP data from Microsoft Graph. After a successful login, you'll see a notification that data is being imported: ![Image of importing data](images/atp-powerbi-importing.png) @@ -96,9 +96,9 @@ For more information, see [Create a Power BI dashboard from a report](https://po ![Image of Microsoft AppSource to get data](images/atp-get-data.png) -4. In the AppSource window, select **Apps** and search for Windows Defender Advanced Threat Protection. +4. In the AppSource window, select **Apps** and search for Microsoft Defender Advanced Threat Protection. - ![Image of AppSource to get Windows Defender ATP](images/atp-appsource.png) + ![Image of AppSource to get Microsoft Defender ATP](images/atp-appsource.png) 5. Click **Get it now**. @@ -109,11 +109,11 @@ For more information, see [Create a Power BI dashboard from a report](https://po ![Image of Power BI authentication method](images/atp-powerbi-extension.png) -7. Click **Sign in**. If this is the first time you’re using Power BI with Windows Defender ATP, you’ll need to sign in and give consent to Windows Defender ATP Power BI app. By providing consent, you’re allowing Windows Defender ATP Power BI to sign in and read your profile, access your data, and be used for report refresh. +7. Click **Sign in**. If this is the first time you’re using Power BI with Microsoft Defender ATP, you’ll need to sign in and give consent to Microsoft Defender ATP Power BI app. By providing consent, you’re allowing Microsoft Defender ATP Power BI to sign in and read your profile, access your data, and be used for report refresh. ![Consent image](images/atp-powerbi-accept.png) -8. Click **Accept**. Power BI service will start downloading your Windows Defender ATP data from Microsoft Graph. After a successful login, you'll see a notification that data is being imported: +8. Click **Accept**. Power BI service will start downloading your Microsoft Defender ATP data from Microsoft Graph. After a successful login, you'll see a notification that data is being imported: ![Image of importing data](images/atp-powerbi-importing.png) @@ -127,7 +127,7 @@ For more information, see [Create a Power BI dashboard from a report](https://po 9. Click **View dataset** to explore your data. -## Build a custom Windows Defender ATP dashboard in Power BI Desktop +## Build a custom Microsoft Defender ATP dashboard in Power BI Desktop You can create a custom dashboard in Power BI Desktop to create visualizations that cater to the specific views that your organization requires. ### Before you begin @@ -158,23 +158,23 @@ You can create a custom dashboard in Power BI Desktop to create visualizations t 9. Restart Power BI Desktop. -## Customize the Windows Defender ATP Power BI dashboard +## Customize the Microsoft Defender ATP Power BI dashboard After completing the steps in the Before you begin section, you can proceed with building your custom dashboard. 1. Open WDATPPowerBI.pbit from the zip with Power BI Desktop. -2. If this is the first time you’re using Power BI with Windows Defender ATP, you’ll need to sign in and give consent to Windows Defender ATP Power BI app. By providing consent, you’re allowing Windows Defender ATP Power BI to sign in and read your profile, and access your data. +2. If this is the first time you’re using Power BI with Microsoft Defender ATP, you’ll need to sign in and give consent to Microsoft Defender ATP Power BI app. By providing consent, you’re allowing Microsoft Defender ATP Power BI to sign in and read your profile, and access your data. ![Consent image](images/atp-powerbi-consent.png) -3. Click **Accept**. Power BI Desktop will start downloading your Windows Defender ATP data from Microsoft Graph. When all data has been downloaded, you can proceed to customize your reports. +3. Click **Accept**. Power BI Desktop will start downloading your Microsoft Defender ATP data from Microsoft Graph. When all data has been downloaded, you can proceed to customize your reports. -## Mashup Windows Defender ATP data with other data sources -You can use Power BI Desktop to analyse data from Windows Defender ATP and mash that data up with other data sources to gain better security perspective in your organization. +## Mashup Microsoft Defender ATP data with other data sources +You can use Power BI Desktop to analyse data from Microsoft Defender ATP and mash that data up with other data sources to gain better security perspective in your organization. -1. In Power BI Desktop, in the Home ribbon, click **Get data** and search for **Windows Defender Advanced Threat Protection**. +1. In Power BI Desktop, in the Home ribbon, click **Get data** and search for **Microsoft Defender Advanced Threat Protection**. ![Get data in Power BI](images/atp-powerbi-get-data.png) @@ -184,13 +184,13 @@ You can use Power BI Desktop to analyse data from Windows Defender ATP and mash ![Power BI preview connector](images/atp-powerbi-preview.png) -4. If this is the first time you’re using Power BI with Windows Defender ATP, you’ll need to sign in and give consent to Windows Defender ATP Power BI app. By providing consent, you’re allowing Windows Defender ATP Power BI to sign in and read your profile, and access your data. +4. If this is the first time you’re using Power BI with Microsoft Defender ATP, you’ll need to sign in and give consent to Microsoft Defender ATP Power BI app. By providing consent, you’re allowing Microsoft Defender ATP Power BI to sign in and read your profile, and access your data. ![Consent image](images/atp-powerbi-consent.png) -5. Click **Accept**. Power BI Desktop will start downloading your Windows Defender ATP data from Microsoft Graph. When all data has been downloaded, you can proceed to customize your reports. +5. Click **Accept**. Power BI Desktop will start downloading your Microsoft Defender ATP data from Microsoft Graph. When all data has been downloaded, you can proceed to customize your reports. -6. In the Navigator dialog box, select the Windows Defender ATP feeds you'd like to download and use in your reports and click Load. Data will start to be downloaded from the Microsoft Graph. +6. In the Navigator dialog box, select the Microsoft Defender ATP feeds you'd like to download and use in your reports and click Load. Data will start to be downloaded from the Microsoft Graph. ![Power BI navigator page](images/atp-powerbi-navigator.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md index 4a47170925..6847252b33 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md +++ b/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code.md @@ -21,7 +21,7 @@ ms.date: 04/24/2018 # PowerShell code examples for the custom threat intelligence API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -175,12 +175,12 @@ $ioc = ``` ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-psexample-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-psexample-belowfoldlink) ## Related topics - [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) - [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) - [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md index 91b8900c14..d9035a183b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md @@ -20,9 +20,9 @@ ms.date: 04/24/2018 # Configure Windows Defender Security Center settings **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-prefsettings-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-prefsettings-abovefoldlink) Use the **Settings** menu to modify general settings, advanced features, enable the preview experience, email notifications, and the custom threat intelligence feature. diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md b/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md index 66f745bb56..1e98001f5e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview-settings.md @@ -1,6 +1,6 @@ --- -title: Turn on the preview experience in Windows Defender ATP -description: Turn on the preview experience in Windows Defender Advanced Threat Protection to try upcoming features. +title: Turn on the preview experience in Microsoft Defender ATP +description: Turn on the preview experience in Microsoft Defender Advanced Threat Protection to try upcoming features. keywords: advanced features, settings, block file search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -17,14 +17,14 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Turn on the preview experience in Windows Defender ATP +# Turn on the preview experience in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-previewsettings-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-previewsettings-abovefoldlink) Turn on the preview experience setting to be among the first to try upcoming features. @@ -36,9 +36,9 @@ Turn on the preview experience setting to be among the first to try upcoming fea 2. Toggle the setting between **On** and **Off** and select **Save preferences**. ## Related topics -- [Update general settings in Windows Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Turn on advanced features in Windows Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) -- [Configure email notifications in Windows Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Update general settings in Microsoft Defender ATP](data-retention-settings-windows-defender-advanced-threat-protection.md) +- [Turn on advanced features in Microsoft Defender ATP](advanced-features-windows-defender-advanced-threat-protection.md) +- [Configure email notifications in Microsoft Defender ATP](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create and build Power BI reports](powerbi-reports-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview.md b/windows/security/threat-protection/microsoft-defender-atp/preview.md index 934fbed168..9e361a3d44 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview.md @@ -1,7 +1,7 @@ --- -title: Windows Defender ATP preview features -description: Learn how to access Windows Defender Advanced Threat Protection preview features. -keywords: preview, preview experience, Windows Defender Advanced Threat Protection, features, updates +title: Microsoft Defender ATP preview features +description: Learn how to access Microsoft Defender Advanced Threat Protection preview features. +keywords: preview, preview experience, Microsoft Defender Advanced Threat Protection, features, updates search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -17,19 +17,19 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Windows Defender ATP preview features +# Microsoft Defender ATP preview features **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -The Windows Defender ATP service is constantly being updated to include new feature enhancements and capabilities. +The Microsoft Defender ATP service is constantly being updated to include new feature enhancements and capabilities. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-preview-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/WindowsForBusiness/windows-atp?ocid=docs-wdatp-preview-abovefoldlink) -Learn about new features in the Windows Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. +Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. For more information on capabilities that are generally available or in preview, see [What's new in Windows Defender](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/whats-new-in-windows-defender-atp). ) @@ -44,5 +44,5 @@ Turn on the preview experience setting to be among the first to try upcoming fea 2. Toggle the setting between **On** and **Off** and select **Save preferences**. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-preview-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-preview-belowfoldlink) diff --git a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md index 22a8c2fd31..a91e2ea546 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md @@ -1,6 +1,6 @@ --- -title: Pull Windows Defender ATP alerts using REST API -description: Pull alerts from Windows Defender ATP REST API. +title: Pull Microsoft Defender ATP alerts using REST API +description: Pull alerts from Microsoft Defender ATP REST API. keywords: alerts, pull alerts, rest api, request, response search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -17,16 +17,16 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Pull Windows Defender ATP alerts using SIEM REST API +# Pull Microsoft Defender ATP alerts using SIEM REST API **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-pullalerts-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-pullalerts-abovefoldlink) -Windows Defender ATP supports the OAuth 2.0 protocol to pull alerts from the portal. +Microsoft Defender ATP supports the OAuth 2.0 protocol to pull alerts from the portal. In general, the OAuth 2.0 protocol supports four types of flows: - Authorization grant flow @@ -36,19 +36,19 @@ In general, the OAuth 2.0 protocol supports four types of flows: For more information about the OAuth specifications, see the [OAuth Website](http://www.oauth.net). -Windows Defender ATP supports the _Authorization grant flow_ and _Client credential flow_ to obtain access to generate alerts from the portal, with Azure Active Directory (AAD) as the authorization server. +Microsoft Defender ATP supports the _Authorization grant flow_ and _Client credential flow_ to obtain access to generate alerts from the portal, with Azure Active Directory (AAD) as the authorization server. The _Authorization grant flow_ uses user credentials to get an authorization code, which is then used to obtain an access token. -The _Client credential flow_ uses client credentials to authenticate against the Windows Defender ATP endpoint URL. This flow is suitable for scenarios when an OAuth client creates requests to an API that doesn't require user credentials. +The _Client credential flow_ uses client credentials to authenticate against the Microsoft Defender ATP endpoint URL. This flow is suitable for scenarios when an OAuth client creates requests to an API that doesn't require user credentials. -Use the following method in the Windows Defender ATP API to pull alerts in JSON format. +Use the following method in the Microsoft Defender ATP API to pull alerts in JSON format. >[!NOTE] >Windows Defender Security Center merges similar alert detections into a single alert. This API pulls alert detections in its raw form based on the query parameters you set, enabling you to apply your own grouping and filtering. ## Before you begin -- Before calling the Windows Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +- Before calling the Microsoft Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). - Take note of the following values in your Azure application registration. You need these values to configure the OAuth flow in your service or daemon app: - Application ID (unique to your application) @@ -59,7 +59,7 @@ Use the following method in the Windows Defender ATP API to pull alerts in JSON ## Get an access token Before creating calls to the endpoint, you'll need to get an access token. -You'll use the access token to access the protected resource, which are alerts in Windows Defender ATP. +You'll use the access token to access the protected resource, which are alerts in Microsoft Defender ATP. To get an access token, you'll need to do a POST request to the token issuing endpoint. Here is a sample request: @@ -84,10 +84,10 @@ The response will include an access token and expiry information. "access_token":"eyJ0eXaioJJOIneiowiouqSuzNiZ345FYOVkaJL0625TueyaJasjhIjEnbMlWqP..." } ``` -You can now use the value in the *access_token* field in a request to the Windows Defender ATP API. +You can now use the value in the *access_token* field in a request to the Microsoft Defender ATP API. ## Request -With an access token, your app can make authenticated requests to the Windows Defender ATP API. Your app must append the access token to the Authorization header of each request. +With an access token, your app can make authenticated requests to the Microsoft Defender ATP API. Your app must append the access token to the Authorization header of each request. ### Request syntax Method | Request URI @@ -161,7 +161,7 @@ Here is an example return value: "ThreatName":null, "RemediationAction":null, "RemediationIsSuccess":null, -"Source":"Windows Defender ATP", +"Source":"Microsoft Defender ATP", "Md5":null, "Sha256":null, "WasExecutingWhileDetected":null, @@ -171,7 +171,7 @@ Here is an example return value: ## Code examples ### Get access token -The following code example demonstrates how to obtain an access token and call the Windows Defender ATP API. +The following code example demonstrates how to obtain an access token and call the Microsoft Defender ATP API. ```syntax AuthenticationContext context = new AuthenticationContext(string.Format("https://login.windows.net/{0}/oauth2", tenantId)); @@ -193,7 +193,7 @@ Console.WriteLine("Got alert list: {0}", alertsJson); ## Error codes -The Windows Defender ATP REST API returns the following error codes caused by an invalid request. +The Microsoft Defender ATP REST API returns the following error codes caused by an invalid request. HTTP error code | Description :---|:--- @@ -202,8 +202,8 @@ HTTP error code | Description 500 | Error in the service. ## Related topics -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) - [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md b/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md index f4b63ae583..09522e6ab2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md +++ b/windows/security/threat-protection/microsoft-defender-atp/python-example-code.md @@ -23,7 +23,7 @@ ms.date: 04/24/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -180,12 +180,12 @@ with requests.Session() as session: ``` ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-pyexample-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-pyexample-belowfoldlink) ## Related topics - [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) - [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) - [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/rbac.md b/windows/security/threat-protection/microsoft-defender-atp/rbac.md index 8446e86a04..b5a8ca5ce4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/rbac.md +++ b/windows/security/threat-protection/microsoft-defender-atp/rbac.md @@ -22,9 +22,9 @@ ms.date: 05/08/2018 **Applies to:** - Azure Active Directory - Office 365 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-rbac-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-rbac-abovefoldlink) Using role-based access control (RBAC), you can create roles and groups within your security operations team to grant appropriate access to the portal. Based on the roles and groups you create, you have fine-grained control over what users with access to the portal can see and do. @@ -37,10 +37,10 @@ Tier 1 | **Local security operations team / IT team**
This team usually tri Tier 2 | **Regional security operations team**
This team can see all the machines for their region and perform remediation actions. Tier 3 | **Global security operations team**
This team consists of security experts and are authorized to see and perform all actions from the portal. -Windows Defender ATP RBAC is designed to support your tier- or role-based model of choice and gives you granular control over what roles can see, machines they can access, and actions they can take. The RBAC framework is centered around the following controls: +Microsoft Defender ATP RBAC is designed to support your tier- or role-based model of choice and gives you granular control over what roles can see, machines they can access, and actions they can take. The RBAC framework is centered around the following controls: - **Control who can take specific action** - - Create custom roles and control what Windows Defender ATP capabilities they can access with granularity. + - Create custom roles and control what Microsoft Defender ATP capabilities they can access with granularity. - **Control who can see information on specific machine group or groups** - [Create machine groups](machine-groups-windows-defender-advanced-threat-protection.md) by specific criteria such as names, tags, domains, and others, then grant role access to them using a specific Azure Active Directory (Azure AD) user group. @@ -57,18 +57,18 @@ Before using RBAC, it's important that you understand the roles that can grant p When you first log in to Windows Defender Security Center, you're granted either full access or read only access. Full access rights are granted to users with Security Administrator or Global Administrator roles in Azure AD. Read only access is granted to users with a Security Reader role in Azure AD. -Someone with a Windows Defender ATP Global administrator role has unrestricted access to all machines, regardless of their machine group association and the Azure AD user groups assignments +Someone with a Microsoft Defender ATP Global administrator role has unrestricted access to all machines, regardless of their machine group association and the Azure AD user groups assignments > [!WARNING] > Initially, only those with Azure AD Global Administrator or Security Administrator rights will be able to create and assign roles in Windows Defender Security Center, therefore, having the right groups ready in Azure AD is important. > > **Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role.** > ->Users with admin permissions are automatically assigned the default built-in Windows Defender ATP global administrator role with full permissions. After opting in to use RBAC, you can assign additional users that are not Azure AD Global or Security Administrators to the Windows Defender ATP global administrator role. +>Users with admin permissions are automatically assigned the default built-in Microsoft Defender ATP global administrator role with full permissions. After opting in to use RBAC, you can assign additional users that are not Azure AD Global or Security Administrators to the Microsoft Defender ATP global administrator role. > > After opting in to use RBAC, you cannot revert to the initial roles as when you first logged into the portal. ## Related topic -- [Create and manage machine groups in Windows Defender ATP](machine-groups-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Create and manage machine groups in Microsoft Defender ATP](machine-groups-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md index e5f643f908..e2a48992a8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts.md @@ -1,5 +1,5 @@ --- -title: Take response actions on a file in Windows Defender ATP +title: Take response actions on a file in Microsoft Defender ATP description: Take response actions on file related alerts by stopping and quarantining a file or blocking a file and checking activity details. keywords: respond, stop and quarantine, block file, deep analysis search.product: eADQiWindows 10XVcnh @@ -20,11 +20,11 @@ ms.topic: article # Take response actions on a file **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-responddile-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-responddile-abovefoldlink) Quickly respond to detected attacks by stopping and quarantining files or blocking a file. After taking action on files, you can check activity details on the Action center. @@ -102,7 +102,7 @@ You can roll back and remove a file from quarantine if you’ve determined that ``` > [!NOTE] -> Windows Defender ATP will restore all files that were quarantined on this machine in the last 30 days. +> Microsoft Defender ATP will restore all files that were quarantined on this machine in the last 30 days. ## Block files in your network You can prevent further propagation of an attack in your organization by banning potentially malicious files or suspected malware. If you know a potentially malicious portable executable (PE) file, you can block it. This operation will prevent it from being read, written, or executed on machines in your organization. @@ -199,7 +199,7 @@ Results of deep analysis are matched against threat intelligence and any matches Use the deep analysis feature to investigate the details of any file, usually during an investigation of an alert or for any other reason where you suspect malicious behavior. This feature is available in the context of the file view. -In the file's page, **Submit for deep analysis** is enabled when the file is available in the Windows Defender ATP backend sample collection or if it was observed on a Windows 10 machine that supports submitting to deep analysis. +In the file's page, **Submit for deep analysis** is enabled when the file is available in the Microsoft Defender ATP backend sample collection or if it was observed on a Windows 10 machine that supports submitting to deep analysis. > [!NOTE] > Only files from Windows 10 can be automatically collected. @@ -207,9 +207,9 @@ In the file's page, **Submit for deep analysis** is enabled when the file is ava You can also manually submit a sample through the [Malware Protection Center Portal](https://www.microsoft.com/security/portal/submission/submit.aspx) if the file was not observed on a Windows 10 machine, and wait for **Submit for deep analysis** button to become available. > [!NOTE] -> Due to backend processing flows in the Malware Protection Center Portal, there could be up to 10 minutes of latency between file submission and availability of the deep analysis feature in Windows Defender ATP. +> Due to backend processing flows in the Malware Protection Center Portal, there could be up to 10 minutes of latency between file submission and availability of the deep analysis feature in Microsoft Defender ATP. -When the sample is collected, Windows Defender ATP runs the file in is a secure environment and creates a detailed report of observed behaviors and associated artifacts, such as files dropped on machines, communication to IPs, and registry modifications. +When the sample is collected, Microsoft Defender ATP runs the file in is a secure environment and creates a detailed report of observed behaviors and associated artifacts, such as files dropped on machines, communication to IPs, and registry modifications. **Submit files for deep analysis:** @@ -230,7 +230,7 @@ A progress bar is displayed and provides information on the different stages of ### View deep analysis reports -View the deep analysis report that Windows Defender ATP provides to see the details of the deep analysis that was conducted on the file you submitted. This feature is available in the file view context. +View the deep analysis report that Microsoft Defender ATP provides to see the details of the deep analysis that was conducted on the file you submitted. This feature is available in the file view context. You can view the comprehensive report that provides details on the following sections: diff --git a/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md index 37e946eb11..16b781e106 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts.md @@ -1,5 +1,5 @@ --- -title: Take response actions on a machine in Windows Defender ATP +title: Take response actions on a machine in Microsoft Defender ATP description: Take response actions on a machine such as isolating machines, collecting an investigation package, managing tags, running av scan, and restricting app execution. keywords: respond, isolate, isolate machine, collect investigation package, action center, restrict, manage tags, av scan, restrict app search.product: eADQiWindows 10XVcnh @@ -21,10 +21,10 @@ ms.date: 11/28/2018 # Take response actions on a machine **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-respondmachine-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-respondmachine-abovefoldlink) Quickly respond to detected attacks by isolating machines or collecting an investigation package. After taking action on machines, you can check activity details on the Action center. @@ -185,7 +185,7 @@ Depending on the severity of the attack and the sensitivity of the machine, you >- Selective isolation is available for machines on Windows 10, version 1709 or later. -This machine isolation feature disconnects the compromised machine from the network while retaining connectivity to the Windows Defender ATP service, which continues to monitor the machine. +This machine isolation feature disconnects the compromised machine from the network while retaining connectivity to the Microsoft Defender ATP service, which continues to monitor the machine. On Windows 10, version 1709 or later, you'll have additional control over the network isolation level. You can also choose to enable Outlook and Skype for Business connectivity (a.k.a 'Selective Isolation'). @@ -210,7 +210,7 @@ On Windows 10, version 1709 or later, you'll have additional control over the ne 4. Type a comment and select **Yes, isolate machine** to take action on the machine. >[!NOTE] - >The machine will remain connected to the Windows Defender ATP service even if it is isolated from the network. If you've chosen to enable Outlook and Skype for Business communication, then you'll be able to communicate to the user while the machine is isolated. + >The machine will remain connected to the Microsoft Defender ATP service even if it is isolated from the network. If you've chosen to enable Outlook and Skype for Business communication, then you'll be able to communicate to the user while the machine is isolated. The Action center shows the submission information: ![Image of machine isolation](images/atp-machine-isolation.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/response-actions.md b/windows/security/threat-protection/microsoft-defender-atp/response-actions.md index bc0073bf43..643f72739e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/response-actions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/response-actions.md @@ -1,5 +1,5 @@ --- -title: Take response actions on files and machines in Windows Defender ATP +title: Take response actions on files and machines in Microsoft Defender ATP description: Take response actions on files and machines by stopping and quarantining files, blocking a file, isolating machines, or collecting an investigation package. keywords: respond, stop and quarantine, block file, deep analysis, isolate machine, collect investigation package, action center search.product: eADQiWindows 10XVcnh @@ -18,15 +18,15 @@ ms.topic: article ms.date: 11/12/2017 --- -# Take response actions in Windows Defender ATP +# Take response actions in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-responseactions-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-responseactions-abovefoldlink) You can take response actions on machines and files to quickly respond to detected attacks so that you can contain or reduce and prevent further damage caused by malicious attackers in your organization. diff --git a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md index 5cf3e7bd28..81b063e148 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Restrict app execution API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ Restrict execution of all applications on the machine except a predefined set (s [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md index 5077e43d6c..d7b2db640d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api.md @@ -19,11 +19,11 @@ ms.date: 09/03/2018 # Advanced hunting API -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) [!include[Prerelease information](prerelease.md)] -This API allows you to run programmatic queries that you are used to running from [Windows Defender ATP Portal](https://securitycenter.windows.com/hunting). +This API allows you to run programmatic queries that you are used to running from [Microsoft Defender ATP Portal](https://securitycenter.windows.com/hunting). ## Limitations @@ -33,7 +33,7 @@ This API allows you to run programmatic queries that you are used to running fro 4. The maximal execution time of a single request is 10 minutes. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- @@ -135,18 +135,18 @@ Content-Type: application/json​ - Error: (403) Forbidden / (401) Unauthorized - If you get this error when calling Windows Defender ATP API, your token might not include the necessary permission. + If you get this error when calling Microsoft Defender ATP API, your token might not include the necessary permission. Check [app permissions](exposed-apis-create-app-webapp.md#validate-the-token) or [delegated permissions](exposed-apis-create-app-nativeapp.md#validate-the-token) included in your token. If the 'roles' section in the token does not include the necessary permission: - - The necessary permission to your app might not have been granted. For more information, see [Access Windows Defender ATP without a user](exposed-apis-create-app-webapp.md#create-an-app) or [Access Windows Defender ATP on behalf of a user](exposed-apis-create-app-nativeapp.md#create-an-app) or, + - The necessary permission to your app might not have been granted. For more information, see [Access Microsoft Defender ATP without a user](exposed-apis-create-app-webapp.md#create-an-app) or [Access Microsoft Defender ATP on behalf of a user](exposed-apis-create-app-nativeapp.md#create-an-app) or, - The app was not authorized in the tenant, see [Application consent](exposed-apis-create-app-webapp.md#application-consent). ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting from Portal](advanced-hunting-windows-defender-advanced-threat-protection.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md index 90d62c40c1..9b6ba020c2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-ms-flow.md @@ -19,7 +19,7 @@ ms.date: 09/24/2018 # Schedule Advanced Hunting using Microsoft Flow **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -87,6 +87,6 @@ You can find below the full definition ![Image of E2E flow](images/ms-flow-e2e.png) ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md index 9282b0c321..55075237cb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-app-token.md @@ -131,7 +131,7 @@ If you want to use **user token** instead please refer to [this](run-advanced-qu ## Related topic - [Create custom Power BI reports with user authentication](run-advanced-query-sample-power-bi-user-token.md) -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md index 336ac77edb..bbec645b5a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-power-bi-user-token.md @@ -18,7 +18,7 @@ ms.topic: article # Create custom reports using Power BI (user authentication) **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -112,7 +112,7 @@ You first need to [create an app](exposed-apis-create-app-nativeapp.md). ## Related topic - [Create custom Power BI reports with app authentication](run-advanced-query-sample-power-bi-app-token.md) -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md index 547b531909..b510a94b78 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-powershell.md @@ -19,7 +19,7 @@ ms.date: 09/24/2018 # Advanced Hunting using PowerShell **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] @@ -65,7 +65,7 @@ $aadToken = $response.access_token where - $tenantId: ID of the tenant on behalf of which you want to run the query (i.e., the query will be run on the data of this tenant) -- $appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Windows Defender ATP) +- $appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Microsoft Defender ATP) - $appSecret: Secret of your AAD app ## Run query @@ -117,7 +117,7 @@ $results | ConvertTo-Json | Set-Content file1.json ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using Python](run-advanced-query-sample-python.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md index 07bb15a7cf..8bd9817c9f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-sample-python.md @@ -18,7 +18,7 @@ ms.topic: article # Advanced Hunting using Python **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -64,7 +64,7 @@ aadToken = jsonResponse["access_token"] where - tenantId: ID of the tenant on behalf of which you want to run the query (i.e., the query will be run on the data of this tenant) -- appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Windows Defender ATP) +- appId: ID of your AAD app (the app must have 'Run advanced queries' permission to Microsoft Defender ATP) - appSecret: Secret of your AAD app ## Run query @@ -143,7 +143,7 @@ outputFile.close() ## Related topic -- [Windows Defender ATP APIs](apis-intro.md) +- [Microsoft Defender ATP APIs](apis-intro.md) - [Advanced Hunting API](run-advanced-query-api.md) - [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md) - [Schedule Advanced Hunting](run-advanced-query-sample-ms-flow.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md index 4a58f9eedf..470cf1fc02 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-av-scan.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Run antivirus scan API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] @@ -28,7 +28,7 @@ Initiate Windows Defender Antivirus scan on a machine. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md index b5d51b9cf4..7f80d83213 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md +++ b/windows/security/threat-protection/microsoft-defender-atp/run-detection-test.md @@ -1,6 +1,6 @@ --- -title: Run a detection test on a newly onboarded Windows Defender ATP machine -description: Run the detection script on a newly onboarded machine to verify that it is properly onboarded to the Windows Defender ATP service. +title: Run a detection test on a newly onboarded Microsoft Defender ATP machine +description: Run the detection script on a newly onboarded machine to verify that it is properly onboarded to the Microsoft Defender ATP service. keywords: detection test, detection, powershell, script, verify, onboarding, windows defender advanced threat protection onboarding, clients, servers, test search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -15,10 +15,9 @@ manager: dansimp audience: ITPro ms.collection: M365-security-compliance ms.topic: article -ms.date: 09/07/2018 --- -# Run a detection test on a newly onboarded Windows Defender ATP machine +# Run a detection test on a newly onboarded Microsoft Defender ATP machine **Applies to:** - Supported Windows 10 versions @@ -26,10 +25,10 @@ ms.date: 09/07/2018 - Windows Server 2016 - Windows Server, version 1803 - Windows Server, 2019 -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Run the following PowerShell script on a newly onboarded machine to verify that it is properly reporting to the Windows Defender ATP service. +Run the following PowerShell script on a newly onboarded machine to verify that it is properly reporting to the Microsoft Defender ATP service. 1. Create a folder: 'C:\test-WDATP-test'. 2. Open an elevated command-line prompt on the machine and run the script: diff --git a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md index d501a0d824..1ee8334e7a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md @@ -19,7 +19,7 @@ ms.date: 10/26/2018 # Configure the security controls in Secure score **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Each security control lists recommendations that you can take to increase the security posture of your organization. @@ -30,9 +30,9 @@ For an machine to be considered "well configured", it must comply to a minimum b >This feature is available for machines on Windows 10, version 1607 or later. #### Minimum baseline configuration setting for EDR: -- Windows Defender ATP sensor is on +- Microsoft Defender ATP sensor is on - Data collection is working correctly -- Communication to Windows Defender ATP service is not impaired +- Communication to Microsoft Defender ATP service is not impaired ##### Recommended actions: You can take the following actions to increase the overall security score of your organization: @@ -82,13 +82,13 @@ This tile shows you the exact number of machines that require the latest securit You can take the following actions to increase the overall security score of your organization: - Install the latest security updates - Fix sensor data collection - - The Windows Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). For more information, see [Windows Update Troubleshooter](https://support.microsoft.com/help/4027322/windows-windows-update-troubleshooter). ### Windows Defender Exploit Guard (Windows Defender EG) optimization -For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on machines so that the minimum baseline configuration setting for Windows Defender EG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender EG events on the Windows Defender ATP Machine timeline. +For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on machines so that the minimum baseline configuration setting for Windows Defender EG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender EG events on the Microsoft Defender ATP Machine timeline. >[!IMPORTANT] @@ -137,7 +137,7 @@ Block Win32 imports from Macro code in Office | 92E97FA1-2EDF-4476-BDD6-9DD0B4DD The Controlled Folder Access setting must be configured to **Audit mode** or **Enabled**. >[!NOTE] -> Audit mode, allows you to see audit events in the Windows Defender ATP Machine timeline however it does not block suspicious applications. +> Audit mode, allows you to see audit events in the Microsoft Defender ATP Machine timeline however it does not block suspicious applications. >Consider enabling Controlled Folder Access for better protection. ##### Recommended actions: @@ -150,7 +150,7 @@ You can take the following actions to increase the overall security score of you For more information, see [Windows Defender Exploit Guard](../windows-defender-exploit-guard/windows-defender-exploit-guard.md). ### Windows Defender Application Guard (Windows Defender AG) optimization -For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender AG events on the Windows Defender ATP Machine timeline. +For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AG is fulfilled. When endpoints are configured according to the baseline you'll be able to see Windows Defender AG events on the Microsoft Defender ATP Machine timeline. >[!IMPORTANT] >This security control is only applicable for machines with Windows 10, version 1709 or later. @@ -180,7 +180,7 @@ For more information, see [Windows Defender Application Guard overview](../windo For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender SmartScreen is fulfilled. >[!WARNING] -> Data collected by Windows Defender SmartScreen might be stored and processed outside of the storage location you have selected for your Windows Defender ATP data. +> Data collected by Windows Defender SmartScreen might be stored and processed outside of the storage location you have selected for your Microsoft Defender ATP data. >[!IMPORTANT] @@ -229,7 +229,7 @@ You can take the following actions to increase the overall security score of you - Secure public profile - Verify secure configuration of third-party firewall - Fix sensor data collection - - The Windows Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). For more information, see [Windows Defender Firewall with Advanced Security](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/windows-firewall-with-advanced-security). @@ -251,7 +251,7 @@ You can take the following actions to increase the overall security score of you - Resume protection on all drives - Ensure drive compatibility - Fix sensor data collection - - The Windows Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). For more information, see [Bitlocker](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview). @@ -274,11 +274,11 @@ You can take the following actions to increase the overall security score of you - Ensure hardware and software prerequisites are met - Turn on Credential Guard - Fix sensor data collection - - The Windows Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md). For more information, see [Manage Windows Defender Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-manage). ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-sadashboard-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-sadashboard-belowfoldlink) ## Related topics - [Overview of Secure score](overview-secure-score-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md index 1c071364b8..eea36cb084 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md @@ -21,9 +21,9 @@ ms.date: 09/04/2018 # Windows Defender Security Center Security operations dashboard **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-secopsdashboard-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-secopsdashboard-abovefoldlink) The **Security operations dashboard** is where the endpoint detection and response capabilities are surfaced. It provides a high level overview of where detections were seen and highlights where response actions are needed. @@ -57,7 +57,7 @@ Each group is further sub-categorized into their corresponding alert severity le For more information see, [Alerts overview](alerts-queue-windows-defender-advanced-threat-protection.md). -Each row includes an alert severity category and a short description of the alert. You can click an alert to see its detailed view. For more information see, [Investigate Windows Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) and [Alerts overview](alerts-queue-windows-defender-advanced-threat-protection.md). +Each row includes an alert severity category and a short description of the alert. You can click an alert to see its detailed view. For more information see, [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) and [Alerts overview](alerts-queue-windows-defender-advanced-threat-protection.md). @@ -66,18 +66,18 @@ This tile shows you a list of machines with the highest number of active alerts. ![The Machines at risk tile shows a list of machines with the highest number of alerts, and a breakdown of the severity of the alerts](images/machines-at-risk-tile.png) -Click the name of the machine to see details about that machine. For more information see, [Investigate machines in the Windows Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). +Click the name of the machine to see details about that machine. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). -You can also click **Machines list** at the top of the tile to go directly to the **Machines list**, sorted by the number of active alerts. For more information see, [Investigate machines in the Windows Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). +You can also click **Machines list** at the top of the tile to go directly to the **Machines list**, sorted by the number of active alerts. For more information see, [Investigate machines in the Microsoft Defender Advanced Threat Protection Machines list](investigate-machines-windows-defender-advanced-threat-protection.md). ## Sensor health -The **Sensor health** tile provides information on the individual machine’s ability to provide sensor data to the Windows Defender ATP service. It reports how many machines require attention and helps you identify problematic machines. +The **Sensor health** tile provides information on the individual machine’s ability to provide sensor data to the Microsoft Defender ATP service. It reports how many machines require attention and helps you identify problematic machines. ![Sensor health tile](images/atp-tile-sensor-health.png) There are two status indicators that provide information on the number of machines that are not reporting properly to the service: -- **Misconfigured** – These machines might partially be reporting sensor data to the Windows Defender ATP service and might have configuration errors that need to be corrected. -- **Inactive** - Machines that have stopped reporting to the Windows Defender ATP service for more than seven days in the past month. +- **Misconfigured** – These machines might partially be reporting sensor data to the Microsoft Defender ATP service and might have configuration errors that need to be corrected. +- **Inactive** - Machines that have stopped reporting to the Microsoft Defender ATP service for more than seven days in the past month. When you click any of the groups, you’ll be directed to machines list, filtered according to your choice. For more information, see [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md) and [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md). @@ -87,7 +87,7 @@ The **Service health** tile informs you if the service is active or if there are ![The Service health tile shows an overall indicator of the service](images/status-tile.png) -For more information on the service health, see [Check the Windows Defender ATP service health](service-status-windows-defender-advanced-threat-protection.md). +For more information on the service health, see [Check the Microsoft Defender ATP service health](service-status-windows-defender-advanced-threat-protection.md). ## Daily machines reporting @@ -124,10 +124,10 @@ This tile shows audit events based on detections from various security component ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-secopsdashboard-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-secopsdashboard-belowfoldlink) ## Related topics -- [Understand the Windows Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) +- [Understand the Microsoft Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) - [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) - [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) - [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/service-status.md b/windows/security/threat-protection/microsoft-defender-atp/service-status.md index a0ace19060..2a553f0551 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/service-status.md +++ b/windows/security/threat-protection/microsoft-defender-atp/service-status.md @@ -1,6 +1,6 @@ --- -title: Check the Windows Defender ATP service health -description: Check Windows Defender ATP service health, see if the service is experiencing issues and review previous issues that have been resolved. +title: Check the Microsoft Defender ATP service health +description: Check Microsoft Defender ATP service health, see if the service is experiencing issues and review previous issues that have been resolved. keywords: dashboard, service, issues, service health, current status, status history, summary of impact, preliminary root cause, resolution, resolution time, expected resolution time search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,14 +18,14 @@ ms.topic: article ms.date: 04/24/2018 --- -# Check the Windows Defender Advanced Threat Protection service health +# Check the Microsoft Defender Advanced Threat Protection service health **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-servicestatus-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-servicestatus-abovefoldlink) The **Service health** provides information on the current status of the Window Defender ATP service. You'll be able to verify that the service health is healthy or if there are current issues. If there are issues, you'll see details related to the issue such as when the issue was detected, what the preliminary root cause is, and the expected resolution time. @@ -39,7 +39,7 @@ The **Service health** details page has the following tabs: - **Status history** ## Current status -The **Current status** tab shows the current state of the Windows Defender ATP service. When the service is running smoothly a healthy service health is shown. If there are issues seen, the following service details are shown to help you gain better insight about the issue: +The **Current status** tab shows the current state of the Microsoft Defender ATP service. When the service is running smoothly a healthy service health is shown. If there are issues seen, the following service details are shown to help you gain better insight about the issue: - Date and time for when the issue was detected - A short description of the issue diff --git a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md index 49687ff26c..745cdec188 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md +++ b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md @@ -20,7 +20,7 @@ ms.date: 12/08/2017 # Stop and quarantine file API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -29,7 +29,7 @@ ms.date: 12/08/2017 [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md b/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md index 14621034da..1e52dffbc2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md +++ b/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis.md @@ -1,6 +1,6 @@ --- -title: Supported Windows Defender Advanced Threat Protection response APIs -description: Learn about the specific response related Windows Defender Advanced Threat Protection API calls. +title: Supported Microsoft Defender Advanced Threat Protection response APIs +description: Learn about the specific response related Microsoft Defender Advanced Threat Protection API calls. keywords: response apis, graph api, supported apis, actor, alerts, machine, user, domain, ip, file search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,13 +18,13 @@ ms.topic: conceptual ms.date: 12/01/2017 --- -# Supported Windows Defender ATP query APIs +# Supported Microsoft Defender ATP query APIs **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-supported-response-apis-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-supported-response-apis-abovefoldlink) Learn about the supported response related API calls you can run and details such as the required request headers, and expected response from the calls. diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md index 9a145edebb..534c8fb1d3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md @@ -1,5 +1,5 @@ --- -title: Windows Defender Advanced Threat Protection Threat analytics +title: Microsoft Defender Advanced Threat Protection Threat analytics description: Get a tailored organizational risk evaluation and actionable steps you can take to minimize risks in your organization. keywords: threat analytics, risk evaluation, OS mitigation, microcode mitigation, mitigation status search.product: eADQiWindows 10XVcnh @@ -20,12 +20,12 @@ ms.date: 10/29/2018 # Threat analytics **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Cyberthreats are emerging more frequently and prevalently. It is critical for organizations to be able to quickly assess their security posture, including impact, and organizational resilience in the context of specific emerging threats. -Threat Analytics is a set of interactive reports published by the Windows Defender ATP research team as soon as emerging threats and outbreaks are identified. The reports help you the assess impact of threats in your environment and provides recommended actions to contain, increase organizational resilience, and prevent specific threats. +Threat Analytics is a set of interactive reports published by the Microsoft Defender ATP research team as soon as emerging threats and outbreaks are identified. The reports help you the assess impact of threats in your environment and provides recommended actions to contain, increase organizational resilience, and prevent specific threats. >[!NOTE] diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md index 005f30d3e8..5274b81da4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts.md @@ -1,6 +1,6 @@ --- -title: Understand threat intelligence concepts in Windows Defender ATP -description: Create custom threat alerts for your organization and learn the concepts around threat intelligence in Windows Defender Advanced Threat Protection. +title: Understand threat intelligence concepts in Microsoft Defender ATP +description: Create custom threat alerts for your organization and learn the concepts around threat intelligence in Microsoft Defender Advanced Threat Protection. keywords: threat intelligence, alert definitions, indicators of compromise, ioc search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -20,15 +20,15 @@ ms.topic: conceptual # Understand threat intelligence concepts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-threatindicator-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-threatindicator-abovefoldlink) Advanced cybersecurity attacks comprise of multiple complex malicious events, attributes, and contextual information. Identifying and deciding which of these activities qualify as suspicious can be a challenging task. Your knowledge of known attributes and abnormal activities specific to your industry is fundamental in knowing when to call an observed behavior as suspicious. -With Windows Defender ATP, you can create custom threat alerts that can help you keep track of possible attack activities in your organization. You can flag suspicious events to piece together clues and possibly stop an attack chain. These custom threat alerts will only appear in your organization and will flag events that you set it to track. +With Microsoft Defender ATP, you can create custom threat alerts that can help you keep track of possible attack activities in your organization. You can flag suspicious events to piece together clues and possibly stop an attack chain. These custom threat alerts will only appear in your organization and will flag events that you set it to track. Before creating custom threat alerts, it's important to know the concepts behind alert definitions and indicators of compromise (IOCs) and the relationship between them. @@ -39,9 +39,9 @@ Alert definitions are contextual attributes that can be used collectively to ide IOCs are individually-known malicious events that indicate that a network or machine has already been breached. Unlike alert definitions, these indicators are considered as evidence of a breach. They are often seen after an attack has already been carried out and the objective has been reached, such as exfiltration. Keeping track of IOCs is also important during forensic investigations. Although it might not provide the ability to intervene with an attack chain, gathering these indicators can be useful in creating better defenses for possible future attacks. ## Relationship between alert definitions and IOCs -In the context of Windows Defender ATP, alert definitions are containers for IOCs and defines the alert, including the metadata that is raised in case of a specific IOC match. Various metadata is provided as part of the alert definitions. Metadata such as alert definition name of attack, severity, and description is provided along with other options. For more information on available metadata options, see [Threat Intelligence API metadata](custom-ti-api-windows-defender-advanced-threat-protection.md#threat-intelligence-api-metadata). +In the context of Microsoft Defender ATP, alert definitions are containers for IOCs and defines the alert, including the metadata that is raised in case of a specific IOC match. Various metadata is provided as part of the alert definitions. Metadata such as alert definition name of attack, severity, and description is provided along with other options. For more information on available metadata options, see [Threat Intelligence API metadata](custom-ti-api-windows-defender-advanced-threat-protection.md#threat-intelligence-api-metadata). -Each IOC defines the concrete detection logic based on its type and value as well as its action, which determines how it is matched. It is bound to a specific alert definition that defines how a detection is displayed as an alert on the Windows Defender ATP console. +Each IOC defines the concrete detection logic based on its type and value as well as its action, which determines how it is matched. It is bound to a specific alert definition that defines how a detection is displayed as an alert on the Microsoft Defender ATP console. Here is an example of an IOC: - Type: Sha1 @@ -51,7 +51,7 @@ Here is an example of an IOC: IOCs have a many-to-one relationship with alert definitions such that an alert definition can have many IOCs that correspond to it. ## Related topics -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) - [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) - [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md index 026ac5e02d..da34c747c5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-integration.md @@ -1,5 +1,5 @@ --- -title: Windows Defender ATP in Microsoft Threat Protection +title: Microsoft Defender ATP in Microsoft Threat Protection description: Learn about the capabilities within the Microsoft Threat Protection keywords: microsoft threat protection, conditional access, office, advanced threat protection, azure atp, azure security center, microsoft cloud app security search.product: eADQiWindows 10XVcnh @@ -22,9 +22,9 @@ ms.date: 12/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Windows Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. +Microsoft Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. For more information on Microsoft Threat Protection, see [Announcing Microsoft Threat Protection](https://techcommunity.microsoft.com/t5/Security-Privacy-and-Compliance/Announcing-Microsoft-Threat-Protection/ba-p/262783). @@ -33,23 +33,23 @@ Microsoft's multiple layers of threat protection across data, applications, devi Each layer in the threat protection stack plays a critical role in protecting customers. The deep integration between these layers results in better protected customers. ## Azure Advanced Threat Protection (Azure ATP) - Suspicious activities are processes running under a user context. The integration between Windows Defender ATP and Azure ATP provides the flexibility of conducting cyber security investigation across activities and identities. + Suspicious activities are processes running under a user context. The integration between Microsoft Defender ATP and Azure ATP provides the flexibility of conducting cyber security investigation across activities and identities. ## Azure Security Center -Windows Defender ATP provides a comprehensive server protection solution, including endpoint detection and response (EDR) capabilities on Windows Servers. +Microsoft Defender ATP provides a comprehensive server protection solution, including endpoint detection and response (EDR) capabilities on Windows Servers. ## Azure Information Protection Keep sensitive data secure while enabling productivity in the workplace through data data discovery and data protection. ## Conditional access -Windows Defender ATP's dynamic machine risk score is integrated into the conditional access evaluation, ensuring that only secure devices have access to resources. +Microsoft Defender ATP's dynamic machine risk score is integrated into the conditional access evaluation, ensuring that only secure devices have access to resources. ## Microsoft Cloud App Security -Microsoft Cloud App Security leverages Windows Defender ATP endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Windows Defender ATP monitored machines. +Microsoft Cloud App Security leverages Microsoft Defender ATP endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Microsoft Defender ATP monitored machines. ## Office 365 Advanced Threat Protection (Office 365 ATP) -[Office 365 ATP](https://docs.microsoft.com/office365/securitycompliance/office-365-atp) helps protect your organization from malware in email messages or files through ATP Safe Links, ATP Safe Attachments, advanced Anti-Phishing, and spoof intelligence capabilities. The integration between Office 365 ATP and Windows Defender ATP enables security analysts to go upstream to investigate the entry point of an attack. Through threat intelligence sharing, attacks can be contained and blocked. +[Office 365 ATP](https://docs.microsoft.com/office365/securitycompliance/office-365-atp) helps protect your organization from malware in email messages or files through ATP Safe Links, ATP Safe Attachments, advanced Anti-Phishing, and spoof intelligence capabilities. The integration between Office 365 ATP and Microsoft Defender ATP enables security analysts to go upstream to investigate the entry point of an attack. Through threat intelligence sharing, attacks can be contained and blocked. ## Skype for Business The Skype for Business integration provides s a way for analysts to communicate with a potentially compromised user or device owner through ao simple button from the portal. diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md index c95bd47a62..37eb716bfc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports.md @@ -1,5 +1,5 @@ --- -title: Threat protection report in Windows Defender ATP +title: Threat protection report in Microsoft Defender ATP description: Track alert detections, categories, and severity using the threat protection report keywords: alert detection, source, alert by category, alert severity, alert classification, determination search.product: eADQiWindows 10XVcnh @@ -17,10 +17,10 @@ ms.collection: M365-security-compliance ms.topic: article --- -# Threat protection report in Windows Defender ATP +# Threat protection report in Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] @@ -52,7 +52,7 @@ While the alert trends shows trending alert information, the alert summary shows ## Alert attributes The report is made up of cards that display the following alert attributes: -- **Detection sources**: shows information about the sensors and detection technologies that provide the data used by Windows Defender ATP to trigger alerts. +- **Detection sources**: shows information about the sensors and detection technologies that provide the data used by Microsoft Defender ATP to trigger alerts. - **Threat categories**: shows the types of threat or attack activity that triggered alerts, indicating possible focus areas for your security operations. diff --git a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md index ae5f7b984d..944fdf6c3c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md +++ b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md @@ -18,7 +18,7 @@ ms.topic: article # Indicator resource type -**Applies to:** - Windows Defender Advanced Threat Protection (Windows Defender ATP) +**Applies to:** - Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prerelease information](prerelease.md)] diff --git a/windows/security/threat-protection/microsoft-defender-atp/time-settings.md b/windows/security/threat-protection/microsoft-defender-atp/time-settings.md index 0a8c046f35..a2617401bd 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/time-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/time-settings.md @@ -21,11 +21,11 @@ ms.date: 02/13/2018 # Windows Defender Security Center time zone settings **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-settings-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-settings-abovefoldlink) Use the **Time zone** menu ![Time zone settings icon](images/atp-time-zone.png) to configure the time zone and view license information. @@ -34,25 +34,25 @@ The aspect of time is important in the assessment and analysis of perceived and Cyberforensic investigations often rely on time stamps to piece together the sequence of events. It’s important that your system reflects the correct time zone settings. -Windows Defender ATP can display either Coordinated Universal Time (UTC) or local time. +Microsoft Defender ATP can display either Coordinated Universal Time (UTC) or local time. -Your current time zone setting is shown in the Windows Defender ATP menu. You can change the displayed time zone in the **Time zone** menu ![Time zone settings icon](images/atp-time-zone.png). +Your current time zone setting is shown in the Microsoft Defender ATP menu. You can change the displayed time zone in the **Time zone** menu ![Time zone settings icon](images/atp-time-zone.png). ### UTC time zone -Windows Defender ATP uses UTC time by default. +Microsoft Defender ATP uses UTC time by default. -Setting the Windows Defender ATP time zone to UTC will display all system timestamps (alerts, events, and others) in UTC for all users. This can help security analysts working in different locations across the globe to use the same time stamps while investigating events. +Setting the Microsoft Defender ATP time zone to UTC will display all system timestamps (alerts, events, and others) in UTC for all users. This can help security analysts working in different locations across the globe to use the same time stamps while investigating events. ### Local time zone -You can choose to have Windows Defender ATP use local time zone settings. All alerts and events will be displayed using your local time zone. +You can choose to have Microsoft Defender ATP use local time zone settings. All alerts and events will be displayed using your local time zone. -The local time zone is taken from your machine’s regional settings. If you change your regional settings, the Windows Defender ATP time zone will also change. Choosing this setting means that the timestamps displayed in Windows Defender ATP will be aligned to local time for all Windows Defender ATP users. Analysts located in different global locations will now see the Windows Defender ATP alerts according to their regional settings. +The local time zone is taken from your machine’s regional settings. If you change your regional settings, the Microsoft Defender ATP time zone will also change. Choosing this setting means that the timestamps displayed in Microsoft Defender ATP will be aligned to local time for all Microsoft Defender ATP users. Analysts located in different global locations will now see the Microsoft Defender ATP alerts according to their regional settings. Choosing to use local time can be useful if the analysts are located in a single location. In this case it might be easier to correlate events to local time, for example – when a local user clicked on a suspicious email link. ### Set the time zone -The Windows Defender ATP time zone is set by default to UTC. -Setting the time zone also changes the times for all Windows Defender ATP views. +The Microsoft Defender ATP time zone is set by default to UTC. +Setting the time zone also changes the times for all Microsoft Defender ATP views. To set the time zone: 1. Click the **Time zone** menu ![Time zone settings icon](images/atp-time-zone.png). @@ -60,7 +60,7 @@ To set the time zone: 3. Select **Timezone UTC** or your local time zone, for example -7:00. ### Regional settings -To apply different date formats for Windows Defender ATP, use regional settings for Internet Explorer (IE) and Microsoft Edge (Edge). If you're using another browser such as Google Chrome, follow the required steps to change the time and date settings for that browser. +To apply different date formats for Microsoft Defender ATP, use regional settings for Internet Explorer (IE) and Microsoft Edge (Edge). If you're using another browser such as Google Chrome, follow the required steps to change the time and date settings for that browser. **Internet Explorer (IE) and Microsoft Edge** diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md index 500048787b..c2d0bdf3c6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti.md @@ -1,6 +1,6 @@ --- -title: Troubleshoot custom threat intelligence issues in Windows Defender ATP -description: Troubleshoot issues that might arise when using the custom threat intelligence feature in Windows Defender ATP. +title: Troubleshoot custom threat intelligence issues in Microsoft Defender ATP +description: Troubleshoot issues that might arise when using the custom threat intelligence feature in Microsoft Defender ATP. keywords: troubleshoot, custom threat intelligence, custom ti, rest api, api, alert definitions, indicators of compromise search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,7 +23,7 @@ ms.date: 06/25/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -52,12 +52,12 @@ If your client secret expires or if you've misplaced the copy provided when you 7. Copy the value and save it in a safe place. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootcustomti-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootcustomti-belowfoldlink) ## Related topics - [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Enable the custom threat intelligence API in Windows Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence API in Microsoft Defender ATP](enable-custom-ti-windows-defender-advanced-threat-protection.md) - [Create custom alerts using the threat intelligence API](custom-ti-api-windows-defender-advanced-threat-protection.md) - [PowerShell code examples for the custom threat intelligence API](powershell-example-code-windows-defender-advanced-threat-protection.md) - [Python code examples for the custom threat intelligence API](python-example-code-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md index 3f520e22f4..01557d7ec5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md @@ -1,6 +1,6 @@ --- title: Troubleshoot onboarding issues and error messages -description: Troubleshoot onboarding issues and error message while completing setup of Windows Defender Advanced Threat Protection. +description: Troubleshoot onboarding issues and error message while completing setup of Microsoft Defender Advanced Threat Protection. keywords: troubleshoot, troubleshooting, Azure Active Directory, onboarding, error message, error messages, windows defender atp search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -23,19 +23,19 @@ ms.date: 08/01/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troublshootonboarding-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troublshootonboarding-abovefoldlink) -This page provides detailed steps to troubleshoot issues that might occur when setting up your Windows Defender ATP service. +This page provides detailed steps to troubleshoot issues that might occur when setting up your Microsoft Defender ATP service. If you receive an error message, Windows Defender Security Center will provide a detailed explanation on what the issue is and relevant links will be supplied. ## No subscriptions found -If while accessing Windows Defender Security Center you get a **No subscriptions found** message, it means the Azure Active Directory (AAD) used to login the user to the portal, does not have a Windows Defender ATP license. +If while accessing Windows Defender Security Center you get a **No subscriptions found** message, it means the Azure Active Directory (AAD) used to login the user to the portal, does not have a Microsoft Defender ATP license. Potential reasons: - The Windows E5 and Office E5 licenses are separate licenses. @@ -43,14 +43,14 @@ Potential reasons: - It could be a license provisioning issue. - It could be you inadvertently provisioned the license to a different Microsoft AAD than the one used for authentication into the service. -For both cases you should contact Microsoft support at [General Windows Defender ATP Support](https://support.microsoft.com/getsupport?wf=0&tenant=ClassicCommercial&oaspworkflow=start_1.0.0.0&locale=en-us&supportregion=en-us&pesid=16055&ccsid=636419533611396913) or +For both cases you should contact Microsoft support at [General Microsoft Defender ATP Support](https://support.microsoft.com/getsupport?wf=0&tenant=ClassicCommercial&oaspworkflow=start_1.0.0.0&locale=en-us&supportregion=en-us&pesid=16055&ccsid=636419533611396913) or [Volume license support](https://www.microsoft.com/licensing/servicecenter/Help/Contact.aspx). ![Image of no subscriptions found](images\atp-no-subscriptions-found.png) ## Your subscription has expired -If while accessing Windows Defender Security Center you get a **Your subscription has expired** message, your online service subscription has expired. Windows Defender ATP subscription, like any other online service subscription, has an expiration date. +If while accessing Windows Defender Security Center you get a **Your subscription has expired** message, your online service subscription has expired. Microsoft Defender ATP subscription, like any other online service subscription, has an expiration date. You can choose to renew or extend the license at any point in time. When accessing the portal after the expiration date a **Your subscription has expired** message will be presented with an option to download the machine offboarding package, should you choose to not renew the license. @@ -61,7 +61,7 @@ You can choose to renew or extend the license at any point in time. When accessi ## You are not authorized to access the portal -If you receive a **You are not authorized to access the portal**, be aware that Windows Defender ATP is a security monitoring, incident investigation and response product, and as such, access to it is restricted and controlled by the user. +If you receive a **You are not authorized to access the portal**, be aware that Microsoft Defender ATP is a security monitoring, incident investigation and response product, and as such, access to it is restricted and controlled by the user. For more information see, [**Assign user access to the portal**](https://docs.microsoft.com/windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection). ![Image of not authorized to access portal](images\atp-not-authorized-to-access-portal.png) @@ -91,4 +91,4 @@ crl.microsoft.com` ## Related topics -- [Validate licensing provisioning and complete setup for Windows Defender ATP](licensing-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Validate licensing provisioning and complete setup for Microsoft Defender ATP](licensing-windows-defender-advanced-threat-protection.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md index 0f2789ceb5..5993a17f98 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md @@ -1,6 +1,6 @@ --- -title: Troubleshoot Windows Defender ATP onboarding issues -description: Troubleshoot issues that might arise during the onboarding of machines or to the Windows Defender ATP service. +title: Troubleshoot Microsoft Defender ATP onboarding issues +description: Troubleshoot issues that might arise during the onboarding of machines or to the Microsoft Defender ATP service. keywords: troubleshoot onboarding, onboarding issues, event viewer, data collection and preview builds, sensor data and diagnostics search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -17,16 +17,16 @@ ms.collection: M365-security-compliance ms.topic: troubleshooting --- -# Troubleshoot Windows Defender Advanced Threat Protection onboarding issues +# Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - Windows Server 2012 R2 - Windows Server 2016 -You might need to troubleshoot the Windows Defender ATP onboarding process if you encounter issues. +You might need to troubleshoot the Microsoft Defender ATP onboarding process if you encounter issues. This page provides detailed steps to troubleshoot onboarding issues that might occur when deploying with one of the deployment tools and common errors that might occur on the machines. If you have completed the onboarding process and don't see machines in the [Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) after an hour, it might indicate an onboarding or connectivity problem. @@ -95,10 +95,10 @@ If none of the event logs and troubleshooting steps work, download the Local scr Error Code Hex | Error Code Dec | Error Description | OMA-URI | Possible cause and troubleshooting steps :---|:---|:---|:---|:--- 0x87D1FDE8 | -2016281112 | Remediation failed | Onboarding
Offboarding | **Possible cause:** Onboarding or offboarding failed on a wrong blob: wrong signature or missing PreviousOrgIds fields.

**Troubleshooting steps:**
Check the event IDs in the [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) section.

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). - | | | | Onboarding
Offboarding
SampleSharing | **Possible cause:** Windows Defender ATP Policy registry key does not exist or the OMA DM client doesn't have permissions to write to it.

**Troubleshooting steps:** Ensure that the following registry key exists: ```HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```

If it doesn't exist, open an elevated command and add the key. + | | | | Onboarding
Offboarding
SampleSharing | **Possible cause:** Microsoft Defender ATP Policy registry key does not exist or the OMA DM client doesn't have permissions to write to it.

**Troubleshooting steps:** Ensure that the following registry key exists: ```HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection```

If it doesn't exist, open an elevated command and add the key. | | | | SenseIsRunning
OnboardingState
OrgId | **Possible cause:** An attempt to remediate by read-only property. Onboarding has failed.

**Troubleshooting steps:** Check the troubleshooting steps in [Troubleshoot onboarding issues on the machine](#troubleshoot-onboarding-issues-on-the-machine).

Check the MDM event logs in the following table or follow the instructions in [Diagnose MDM failures in Windows 10](https://msdn.microsoft.com/library/windows/hardware/mt632120%28v=vs.85%29.aspx). - || | | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional.
Server is not supported. - 0x87D101A9 | -2016345687 |Syncml(425): The requested command failed because the sender does not have adequate access control permissions (ACL) on the recipient. | All | **Possible cause:** Attempt to deploy Windows Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional. + || | | All | **Possible cause:** Attempt to deploy Microsoft Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional.
Server is not supported. + 0x87D101A9 | -2016345687 |Syncml(425): The requested command failed because the sender does not have adequate access control permissions (ACL) on the recipient. | All | **Possible cause:** Attempt to deploy Microsoft Defender ATP on non-supported SKU/Platform, particularly Holographic SKU.

Currently is supported platforms: Enterprise, Education, and Professional.
**Known issues with non-compliance** @@ -122,10 +122,10 @@ Channel name: Admin ID | Severity | Event description | Troubleshooting steps :---|:---|:---|:--- -1819 | Error | Windows Defender Advanced Threat Protection CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3). | Download the [Cumulative Update for Windows 10, 1607](https://go.microsoft.com/fwlink/?linkid=829760). +1819 | Error | Microsoft Defender Advanced Threat Protection CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3). | Download the [Cumulative Update for Windows 10, 1607](https://go.microsoft.com/fwlink/?linkid=829760). ## Troubleshoot onboarding issues on the machine -If the deployment tools used does not indicate an error in the onboarding process, but machines are still not appearing in the machines list in an hour, go through the following verification topics to check if an error occurred with the Windows Defender ATP agent: +If the deployment tools used does not indicate an error in the onboarding process, but machines are still not appearing in the machines list in an hour, go through the following verification topics to check if an error occurred with the Microsoft Defender ATP agent: - [View agent onboarding errors in the machine event log](#view-agent-onboarding-errors-in-the-machine-event-log) - [Ensure the diagnostic data service is enabled](#ensure-the-diagnostics-service-is-enabled) - [Ensure the service is set to start](#ensure-the-service-is-set-to-start) @@ -140,7 +140,7 @@ If the deployment tools used does not indicate an error in the onboarding proces 2. In the **Event Viewer (Local)** pane, expand **Applications and Services Logs** > **Microsoft** > **Windows** > **SENSE**. > [!NOTE] - > SENSE is the internal name used to refer to the behavioral sensor that powers Windows Defender ATP. + > SENSE is the internal name used to refer to the behavioral sensor that powers Microsoft Defender ATP. 3. Select **Operational** to load the log. @@ -154,17 +154,17 @@ If the deployment tools used does not indicate an error in the onboarding proces Event ID | Message | Resolution steps :---|:---|:--- -5 | Windows Defender Advanced Threat Protection service failed to connect to the server at _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -6 | Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). -7 | Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection), then run the entire onboarding process again. -9 | Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the event happened during offboarding, contact support. -10 | Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the problem persists, contact support. -15 | Windows Defender Advanced Threat Protection cannot start command channel with URL: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). -17 | Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). If the problem persists, contact support. -25 | Windows Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: _variable_ | Contact support. -27 | Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: variable | Contact support. +5 | Microsoft Defender Advanced Threat Protection service failed to connect to the server at _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). +6 | Microsoft Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found. Failure code: _variable_ | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). +7 | Microsoft Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection), then run the entire onboarding process again. +9 | Microsoft Defender Advanced Threat Protection service failed to change its start type. Failure code: variable | If the event happened during onboarding, reboot and re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the event happened during offboarding, contact support. +10 | Microsoft Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: variable | If the event happened during onboarding, re-attempt running the onboarding script. For more information, see [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md).

If the problem persists, contact support. +15 | Microsoft Defender Advanced Threat Protection cannot start command channel with URL: _variable_ | [Ensure the machine has Internet access](#ensure-the-machine-has-an-internet-connection). +17 | Microsoft Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable | [Run the onboarding script again](configure-endpoints-script-windows-defender-advanced-threat-protection.md). If the problem persists, contact support. +25 | Microsoft Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: _variable_ | Contact support. +27 | Failed to enable Microsoft Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: variable | Contact support. 29 | Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3 | Ensure the machine has Internet access, then run the entire offboarding process again. -30 | Failed to disable $(build.sense.productDisplayName) mode in Windows Defender Advanced Threat Protection. Failure code: %1 | Contact support. +30 | Failed to disable $(build.sense.productDisplayName) mode in Microsoft Defender Advanced Threat Protection. Failure code: %1 | Contact support. 32 | $(build.sense.productDisplayName) service failed to request to stop itself after offboarding process. Failure code: %1 | Verify that the service start type is manual and reboot the machine. 55 | Failed to create the Secure ETW autologger. Failure code: %1 | Reboot the machine. 63 | Updating the start type of external service. Name: %1, actual start type: %2, expected start type: %3, exit code: %4 | Identify what is causing changes in start type of mentioned service. If the exit code is not 0, fix the start type manually to expected start type. @@ -173,7 +173,7 @@ Event ID | Message | Resolution steps 69 | The service is stopped. Service name: %1 | Start the mentioned service. Contact support if persists.
-There are additional components on the machine that the Windows Defender ATP agent depends on to function properly. If there are no onboarding related errors in the Windows Defender ATP agent event log, proceed with the following steps to ensure that the additional components are configured correctly. +There are additional components on the machine that the Microsoft Defender ATP agent depends on to function properly. If there are no onboarding related errors in the Microsoft Defender ATP agent event log, proceed with the following steps to ensure that the additional components are configured correctly. ### Ensure the diagnostic data service is enabled @@ -234,20 +234,20 @@ First, you should check that the service is set to start automatically when Wind ### Ensure the machine has an Internet connection -The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Windows Defender ATP service. +The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. -To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. +To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) topic. ### Ensure that Windows Defender Antivirus is not disabled by a policy -**Problem**: The Windows Defender ATP service does not start after onboarding. +**Problem**: The Microsoft Defender ATP service does not start after onboarding. **Symptom**: Onboarding successfully completes, but you see error 577 when trying to start the service. -**Solution**: If your machines are running a third-party antimalware client, the Windows Defender ATP agent needs the Windows Defender Early Launch Antimalware (ELAM) driver to be enabled. You must ensure that it's not disabled in system policy. +**Solution**: If your machines are running a third-party antimalware client, the Microsoft Defender ATP agent needs the Windows Defender Early Launch Antimalware (ELAM) driver to be enabled. You must ensure that it's not disabled in system policy. - Depending on the tool that you use to implement policies, you'll need to verify that the following Windows Defender policies are cleared: @@ -275,9 +275,9 @@ If you encounter issues while onboarding a server, go through the following veri - [Ensure that the server proxy and Internet connectivity settings are configured properly](configure-server-endpoints-windows-defender-advanced-threat-protection.md#server-proxy) You might also need to check the following: -- Check that there is a Windows Defender Advanced Threat Protection Service running in the **Processes** tab in **Task Manager**. For example: +- Check that there is a Microsoft Defender Advanced Threat Protection Service running in the **Processes** tab in **Task Manager**. For example: - ![Image of process view with Windows Defender Advanced Threat Protection Service running](images/atp-task-manager.png) + ![Image of process view with Microsoft Defender Advanced Threat Protection Service running](images/atp-task-manager.png) - Check **Event Viewer** > **Applications and Services Logs** > **Operation Manager** to see if there are any errors. @@ -293,7 +293,7 @@ You might also need to check the following: ## Licensing requirements -Windows Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: +Microsoft Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: - Windows 10 Enterprise E5 - Windows 10 Education E5 @@ -302,11 +302,11 @@ Windows Defender Advanced Threat Protection requires one of the following Micros For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2). ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootonboarding-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootonboarding-belowfoldlink) ## Related topics -- [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) - [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) - [Configure machine proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md index fccd8ca55a..c065888a3c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-overview.md @@ -1,6 +1,6 @@ --- -title: Troubleshoot Windows Defender Advanced Threat Protection capabilities -description: Find solutions to issues on sensor state, service issues, or other Windows Defender ATP capabilities +title: Troubleshoot Microsoft Defender Advanced Threat Protection capabilities +description: Find solutions to issues on sensor state, service issues, or other Microsoft Defender ATP capabilities keywords: troubleshoot, sensor, state, service, issues, attack surface reduction, next generation protection search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,14 +18,14 @@ ms.topic: troubleshooting ms.date: 09/03/2018 --- -# Troubleshoot Windows Defender Advanced Threat Protection +# Troubleshoot Microsoft Defender Advanced Threat Protection -Troubleshoot issues that might arise as you use Windows Defender ATP capabilities. +Troubleshoot issues that might arise as you use Microsoft Defender ATP capabilities. ## In this section Topic | Description :---|:--- -Troubleshoot sensor state | Find solutions for issues related to the Windows Defender ATP sensor +Troubleshoot sensor state | Find solutions for issues related to the Microsoft Defender ATP sensor Troubleshoot service issues | Fix issues related to the Windows Defender Advanced Threat service Troubleshoot attack surface reduction | Fix issues related to network protection and attack surface reduction rules Troubleshoot next generation protection | If you encounter a problem with antivirus, you can search the tables in this topic to find a matching issue and potential solution diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md index a3097cd460..7d2a7d86da 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem.md @@ -1,6 +1,6 @@ --- -title: Troubleshoot SIEM tool integration issues in Windows Defender ATP -description: Troubleshoot issues that might arise when using SIEM tools with Windows Defender ATP. +title: Troubleshoot SIEM tool integration issues in Microsoft Defender ATP +description: Troubleshoot issues that might arise when using SIEM tools with Microsoft Defender ATP. keywords: troubleshoot, siem, client secret, secret search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,7 +21,7 @@ ms.date: 11/08/2018 # Troubleshoot SIEM tool integration issues **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) @@ -77,11 +77,11 @@ If you encounter an error when trying to enable the SIEM connector application, ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootsiem-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshootsiem-belowfoldlink) ## Related topics -- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) -- [Pull Windows Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +- [Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md index ee883b6d7f..655895b298 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md @@ -1,7 +1,7 @@ --- -title: Troubleshoot Windows Defender Advanced Threat Protection service issues +title: Troubleshoot Microsoft Defender Advanced Threat Protection service issues description: Find solutions and work arounds to known issues such as server errors when trying to access the service. -keywords: troubleshoot Windows Defender Advanced Threat Protection, troubleshoot Windows ATP, server error, access denied, invalid credentials, no data, dashboard portal, whitelist, event viewer +keywords: troubleshoot Microsoft Defender Advanced Threat Protection, troubleshoot Windows ATP, server error, access denied, invalid credentials, no data, dashboard portal, whitelist, event viewer search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -35,13 +35,13 @@ Make sure that `*.securitycenter.windows.com` is included the proxy whitelist. > [!NOTE] > You must use the HTTPS protocol when adding the following endpoints. -## Windows Defender ATP service shows event or error logs in the Event Viewer +## Microsoft Defender ATP service shows event or error logs in the Event Viewer -See the topic [Review events and errors using Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) for a list of event IDs that are reported by the Windows Defender ATP service. The topic also contains troubleshooting steps for event errors. +See the topic [Review events and errors using Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) for a list of event IDs that are reported by the Microsoft Defender ATP service. The topic also contains troubleshooting steps for event errors. -## Windows Defender ATP service fails to start after a reboot and shows error 577 +## Microsoft Defender ATP service fails to start after a reboot and shows error 577 -If onboarding machines successfully completes but Windows Defender ATP does not start after a reboot and shows error 577, check that Windows Defender is not disabled by a policy. +If onboarding machines successfully completes but Microsoft Defender ATP does not start after a reboot and shows error 577, check that Windows Defender is not disabled by a policy. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). @@ -63,15 +63,15 @@ The following date and time formats are currently not supported: **Use of comma to indicate thousand**
Support of use of comma as a separator in numbers are not supported. Regions where a number is separated with a comma to indicate a thousand, will only see the use of a dot as a separator. For example, 15,5K is displayed as 15.5K. ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshoot-belowfoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-troubleshoot-belowfoldlink) -## Windows Defender ATP tenant was automatically created in Europe -When you use Azure Security Center to monitor servers, a Windows Defender ATP tenant is automatically created. The Windows Defender ATP data is stored in Europe by default. +## Microsoft Defender ATP tenant was automatically created in Europe +When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created. The Microsoft Defender ATP data is stored in Europe by default. ## Related topics -- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Microsoft Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) - [Review events and errors using Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md index 07203db964..4320d58d31 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Release machine from isolation API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ Undo isolation of a machine. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md index d6bd15719c..9531e39835 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md @@ -19,7 +19,7 @@ ms.date: 12/08/2017 # Remove app restriction API **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] @@ -28,7 +28,7 @@ Enable execution of any application on the machine. [!include[Machine actions note](machineactionsnote.md)] ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md index 8c700cf5fd..be7b420a9b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md +++ b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md @@ -20,14 +20,14 @@ ms.date: 12/08/2017 # Update alert **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) [!include[Prereleaseinformation](prerelease.md)] Update the properties of an alert entity. ## Permissions -One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Windows Defender ATP APIs](apis-intro.md) +One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) Permission type | Permission | Permission display name :---|:---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-apis.md b/windows/security/threat-protection/microsoft-defender-atp/use-apis.md index 9104f53a2b..a152053d8d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use-apis.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use-apis.md @@ -1,5 +1,5 @@ --- -title: Windows Defender ATP Public API +title: Microsoft Defender ATP Public API description: Use the exposed data and actions using a set of progammatic APIs that are part of the Microsoft Intelligence Security Graph. keywords: apis, api, wdatp, open api, windows defender atp api, public api, alerts, machine, user, domain, ip, file search.product: eADQiWindows 10XVcnh @@ -17,15 +17,15 @@ ms.topic: conceptual ms.date: 11/28/2018 --- -# Windows Defender ATP Public API +# Microsoft Defender ATP Public API -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf) -> Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) +> Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-exposedapis-abovefoldlink) ## In this section Topic | Description :---|:--- -[Windows Defender ATP API overview](apis-intro.md) | Learn how to access to Windows Defender ATP Public API and on which context. -[Supported Windows Defender ATP APIs](exposed-apis-list.md) | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. Examples include APIs for [alert resource type](alerts-windows-defender-advanced-threat-protection-new.md), [domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md), or even actions such as [isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md). +[Microsoft Defender ATP API overview](apis-intro.md) | Learn how to access to Microsoft Defender ATP Public API and on which context. +[Supported Microsoft Defender ATP APIs](exposed-apis-list.md) | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. Examples include APIs for [alert resource type](alerts-windows-defender-advanced-threat-protection-new.md), [domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md), or even actions such as [isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md). How to use APIs - Samples | Learn how to use Advanced hunting APIs and multiple APIs such as PowerShell. Other examples include [schedule advanced hunting using Microsoft Flow](run-advanced-query-sample-ms-flow.md) or [OData queries](exposed-apis-odata-samples.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md index a5bf6b10dc..f8109a93b6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md @@ -1,6 +1,6 @@ --- title: Use the custom threat intelligence API to create custom alerts -description: Use the threat intelligence API in Windows Defender Advanced Threat Protection to create custom alerts +description: Use the threat intelligence API in Microsoft Defender Advanced Threat Protection to create custom alerts keywords: threat intelligence, alert definitions, indicators of compromise search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -21,11 +21,11 @@ ms.date: 04/24/2018 # Use the threat intelligence API to create custom alerts **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-customti-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-customti-abovefoldlink) Understand threat intelligence concepts, then enable the custom threat intelligence application so that you can proceed to create custom threat intelligence alerts that are specific to your organization. diff --git a/windows/security/threat-protection/microsoft-defender-atp/use.md b/windows/security/threat-protection/microsoft-defender-atp/use.md index 07291b3a48..94b1666439 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use.md @@ -22,11 +22,11 @@ ms.date: 03/12/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-usewdatp-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-usewdatp-abovefoldlink) -Windows Defender Security Center is the portal where you can access Windows Defender Advanced Threat Protection capabilities. +Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. Use the **Security operations** dashboard to gain insight on the various alerts on machines and users in your network. @@ -40,7 +40,7 @@ Use the **Threat analytics** dashboard to continually assess and control risk ex Topic | Description :---|:--- [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) | Understand the portal layout and area descriptions. -[View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) | The Windows Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. +[View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | The **Secure Score dashboard** expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. diff --git a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md index ab60042a21..152c31812c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md +++ b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md @@ -20,10 +20,10 @@ ms.topic: article # Create and manage roles for role-based access control **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-roles-abovefoldlink) +>Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-roles-abovefoldlink) ## Create roles and assign the role to an Azure Active Directory group The following steps guide you on how to create roles in Windows Defender Security Center. It assumes that you have already created Azure Active Directory user groups. @@ -43,7 +43,7 @@ The following steps guide you on how to create roles in Windows Defender Securit - **Manage portal system settings** - Users can configure storage settings, SIEM and threat intel API settings (applies globally), advanced settings, automated file uploads, roles and machine groups. >[!NOTE] - >This setting is only available in the Windows Defender ATP administrator (default) role. + >This setting is only available in the Microsoft Defender ATP administrator (default) role. - **Manage security settings** - Users can configure alert suppression settings, manage allowed/blocked lists for automation, manage folder exclusions for automation, onboard and offboard machines, and manage email notifications. diff --git a/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md b/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md index 5f6903dad8..a7d944a061 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/view-incidents-queue.md @@ -18,9 +18,9 @@ ms.topic: article ms.date: 10/08/2018 --- -# View and organize the Windows Defender Advanced Threat Protection Incidents queue +# View and organize the Microsoft Defender Advanced Threat Protection Incidents queue **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) The **Incidents queue** shows a collection of incidents that were flagged from machines in your network. It helps you sort through incidents to prioritize and create an informed cybersecurity response decision. diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md index b73e7bc8b1..af06ab295c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md @@ -1,6 +1,6 @@ --- -title: What's new in Windows Defender ATP -description: Lists the new features and functionality in Windows Defender ATP +title: What's new in Microsoft Defender ATP +description: Lists the new features and functionality in Microsoft Defender ATP keywords: what's new in windows defender atp search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -17,11 +17,11 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# What's new in Windows Defender ATP +# What's new in Microsoft Defender ATP **Applies to:** -- Windows Defender Advanced Threat Protection (Windows Defender ATP) +- Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) -Here are the new features in the latest release of Windows Defender ATP as well as security features in Windows 10 and Windows Server. +Here are the new features in the latest release of Microsoft Defender ATP as well as security features in Windows 10 and Windows Server. ## March 2019 ### In preview @@ -32,16 +32,16 @@ The following capability are included in the February 2019 preview release. ## February 2019 The following capabilities are generally available (GA). -- [Incidents](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/incidents-queue)
Incident is a new entity in Windows Defender ATP that brings together all relevant alerts and related entities to narrate the broader attack story, giving analysts better perspective on the purview of complex threats. +- [Incidents](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/incidents-queue)
Incident is a new entity in Microsoft Defender ATP that brings together all relevant alerts and related entities to narrate the broader attack story, giving analysts better perspective on the purview of complex threats. -- [Onboard previous versions of Windows](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection)
Onboard supported versions of Windows machines so that they can send sensor data to the Windows Defender ATP sensor. +- [Onboard previous versions of Windows](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection)
Onboard supported versions of Windows machines so that they can send sensor data to the Microsoft Defender ATP sensor. ### In preview The following capability are included in the February 2019 preview release. - [Reports](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection)
The threat protection report provides high-level information about alerts generated in your organization. -- [Microsoft Threat Experts](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/microsoft-threat-experts)
Microsoft Threat Experts is the new managed threat hunting service in Windows Defender ATP that provides proactive hunting, prioritization, and additional context and insights that further empower security operations centers (SOCs) to identify and respond to threats quickly and accurately. It provides additional layer of expertise and optics that Microsoft customers can utilize to augment security operation capabilities as part of Microsoft 365. +- [Microsoft Threat Experts](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/microsoft-threat-experts)
Microsoft Threat Experts is the new managed threat hunting service in Microsoft Defender ATP that provides proactive hunting, prioritization, and additional context and insights that further empower security operations centers (SOCs) to identify and respond to threats quickly and accurately. It provides additional layer of expertise and optics that Microsoft customers can utilize to augment security operation capabilities as part of Microsoft 365. ## October 2018 @@ -53,16 +53,16 @@ The following capabilities are generally available (GA). - [Custom detection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/overview-custom-detections)
With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. This can be done by leveraging the power of Advanced hunting through the creation of custom detection rules. -- [Integration with Azure Security Center](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#integration-with-azure-security-center)
Windows Defender ATP integrates with Azure Security Center to provide a comprehensive server protection solution. With this integration Azure Security Center can leverage the power of Windows Defender ATP to provide improved threat detection for Windows Servers. +- [Integration with Azure Security Center](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#integration-with-azure-security-center)
Microsoft Defender ATP integrates with Azure Security Center to provide a comprehensive server protection solution. With this integration Azure Security Center can leverage the power of Microsoft Defender ATP to provide improved threat detection for Windows Servers. -- [Managed security service provider (MSSP) support](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection)
Windows Defender ATP adds support for this scenario by providing MSSP integration. The integration will allow MSSPs to take the following actions: Get access to MSSP customer's Windows Defender Security Center portal, fetch email notifications, and fetch alerts through security information and event management (SIEM) tools. +- [Managed security service provider (MSSP) support](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection)
Microsoft Defender ATP adds support for this scenario by providing MSSP integration. The integration will allow MSSPs to take the following actions: Get access to MSSP customer's Windows Defender Security Center portal, fetch email notifications, and fetch alerts through security information and event management (SIEM) tools. -- [Removable device control](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/19/windows-defender-atp-has-protections-for-usb-and-removable-devices/)
Windows Defender ATP provides multiple monitoring and control features to help prevent threats from removable devices, including new settings to allow or block specific hardware IDs. +- [Removable device control](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/19/windows-defender-atp-has-protections-for-usb-and-removable-devices/)
Microsoft Defender ATP provides multiple monitoring and control features to help prevent threats from removable devices, including new settings to allow or block specific hardware IDs. - [Support for iOS and Android devices](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection#turn-on-third-party-integration)
iOS and Android devices are now supported and can be onboarded to the service. - [Threat analytics](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/threat-analytics)
-Threat Analytics is a set of interactive reports published by the Windows Defender ATP research team as soon as emerging threats and outbreaks are identified. The reports help security operations teams assess impact on their environment and provides recommended actions to contain, increase organizational resilience, and prevent specific threats. +Threat Analytics is a set of interactive reports published by the Microsoft Defender ATP research team as soon as emerging threats and outbreaks are identified. The reports help security operations teams assess impact on their environment and provides recommended actions to contain, increase organizational resilience, and prevent specific threats. - New in Windows 10 version 1809, there are two new attack surface reduction rules: - Block Adobe Reader from creating child processes @@ -81,25 +81,25 @@ For more information on how to turn on preview features, see [Preview features]( - [Information protection](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/information-protection-in-windows-overview)
Information protection is an integral part of Microsoft 365 Enterprise suite, providing intelligent protection to keep sensitive data secure while enabling productivity in the workplace. -Windows Defender ATP is seamlessly integrated in Microsoft Threat Protection to provide a complete and comprehensive data loss prevention (DLP) solution for Windows devices. +Microsoft Defender ATP is seamlessly integrated in Microsoft Threat Protection to provide a complete and comprehensive data loss prevention (DLP) solution for Windows devices. >[!NOTE] >Partially available from Windows 10, version 1809. -- [Integration with Microsoft Cloud App Security](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-integration)
Microsoft Cloud App Security leverages Windows Defender ATP endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Windows Defender ATP monitored machines. +- [Integration with Microsoft Cloud App Security](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/microsoft-cloud-app-security-integration)
Microsoft Cloud App Security leverages Microsoft Defender ATP endpoint signals to allow direct visibility into cloud application usage including the use of unsupported cloud services (shadow IT) from all Microsoft Defender ATP monitored machines. >[!NOTE] >Available from Windows 10, version 1809 or later. -- [Onboard Windows Server 2019](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#windows-server-version-1803-and-windows-server-2019)
Windows Defender ATP now adds support for Windows Server 2019. You'll be able to onboard Windows Server 2019 in the same method available for Windows 10 client machines. +- [Onboard Windows Server 2019](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#windows-server-version-1803-and-windows-server-2019)
Microsoft Defender ATP now adds support for Windows Server 2019. You'll be able to onboard Windows Server 2019 in the same method available for Windows 10 client machines. -- [Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
-Windows Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. +- [Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
+Microsoft Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. ## March 2018 - [Advanced Hunting](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection)
-Query data using Advanced hunting in Windows Defender ATP. +Query data using Advanced hunting in Microsoft Defender ATP. - [Attack surface reduction rules](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard)
New attack surface reduction rules: @@ -116,21 +116,21 @@ Query data using Advanced hunting in Windows Defender ATP. - [Conditional access](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection)
Enable conditional access to better protect users, devices, and data. -- [Windows Defender ATP Community center](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection)
- The Windows Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. +- [Microsoft Defender ATP Community center](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection)
+ The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. - [Controlled folder access](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard)
You can now block untrusted processes from writing to disk sectors using Controlled Folder Access. - [Onboard non-Windows machines](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection)
- Windows Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. + Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. - [Role-based access control (RBAC)](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection)
Using role-based access control (RBAC), you can create roles and groups within your security operations team to grant appropriate access to the portal. - [Windows Defender Antivirus](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10)
-Windows Defender Antivirus now shares detection status between M365 services and interoperates with Windows Defender ATP. For more information, see [Use next-gen technologies in Windows Defender Antivirus through cloud-delivered protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus). +Windows Defender Antivirus now shares detection status between M365 services and interoperates with Microsoft Defender ATP. For more information, see [Use next-gen technologies in Windows Defender Antivirus through cloud-delivered protection](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus). Block at first sight can now block non-portable executable files (such as JS, VBS, or macros) as well as executable files. For more information, see [Enable block at first sight](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus). diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md index d85d398e43..468fcd0924 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md @@ -1,6 +1,6 @@ --- title: Windows Defender Security Center -description: Windows Defender Security Center is the portal where you can access Windows Defender Advanced Threat Protection. +description: Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection. keywords: windows, defender, security, center, defender, advanced, threat, protection search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -20,7 +20,7 @@ ms.date: 07/01/2018 # Windows Defender Security Center -Windows Defender Security Center is the portal where you can access Windows Defender Advanced Threat Protection capabilities. It gives enterprise security operations teams a single pane of glass experience to help secure networks. +Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. It gives enterprise security operations teams a single pane of glass experience to help secure networks. ## In this section @@ -31,9 +31,9 @@ Get started | Learn about the minimum requirements, validate licensing and com [Understand the portal](use-windows-defender-advanced-threat-protection.md) | Understand the Security operations, Secure Score, and Threat analytics dashboards as well as how to navigate the portal. Investigate and remediate threats | Investigate alerts, machines, and take response actions to remediate threats. API and SIEM support | Use the supported APIs to pull and create custom alerts, or automate workflows. Use the supported SIEM tools to pull alerts from Windows Defender Security Center. -Reporting | Create and build Power BI reports using Windows Defender ATP data. +Reporting | Create and build Power BI reports using Microsoft Defender ATP data. Check service health and sensor state | Verify that the service is running and check the sensor state on machines. [Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. -[Access the Windows Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md) | Access the Windows Defender ATP Community Center to learn, collaborate, and share experiences about the product. +[Access the Microsoft Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md) | Access the Microsoft Defender ATP Community Center to learn, collaborate, and share experiences about the product. [Troubleshoot service issues](troubleshoot-windows-defender-advanced-threat-protection.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. From dbb77d063b94fd08c177516b3210e1e7cde75744 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 14:58:31 -0700 Subject: [PATCH 130/737] update windows defender security center to microsoft defender security center --- .../microsoft-defender-atp/TOC.md | 4 ++-- .../advanced-features.md | 2 +- .../advanced-hunting.md | 4 ++-- ...lerts-queue-endpoint-detection-response.md | 6 ++--- .../api-portal-mapping.md | 4 ++-- .../assign-portal-access.md | 4 ++-- .../basic-permissions.md | 2 +- .../microsoft-defender-atp/community.md | 2 +- .../configure-arcsight.md | 2 +- .../configure-conditional-access.md | 4 ++-- .../configure-endpoints-gp.md | 8 +++---- .../configure-endpoints-mdm.md | 2 +- .../configure-endpoints-non-windows.md | 4 ++-- .../configure-endpoints-sccm.md | 6 ++--- .../configure-endpoints-script.md | 8 +++---- .../configure-endpoints-vdi.md | 6 ++--- .../configure-microsoft-threat-experts.md | 2 +- .../configure-mssp-support.md | 22 +++++++++---------- .../configure-server-endpoints.md | 14 ++++++------ .../microsoft-defender-atp/configure-siem.md | 2 +- .../configure-splunk.md | 2 +- .../microsoft-defender-atp/custom-ti-api.md | 2 +- .../enable-custom-ti.md | 2 +- .../enable-siem-integration.md | 4 ++-- .../experiment-custom-ti.md | 2 +- .../fix-unhealhty-sensors.md | 2 +- .../microsoft-defender-atp/get-started.md | 4 ++-- ...ormation-protection-in-windows-overview.md | 6 ++--- .../microsoft-defender-atp/licensing.md | 10 ++++----- .../microsoft-defender-atp/manage-alerts.md | 2 +- .../manage-auto-investigation.md | 2 +- .../microsoft-defender-atp/manage-edr.md | 2 +- ...icrosoft-cloud-app-security-integration.md | 2 +- ...oft-defender-advanced-threat-protection.md | 2 +- .../microsoft-threat-experts.md | 2 +- .../microsoft-defender-atp/mssp-support.md | 2 +- .../onboard-configure.md | 2 +- .../microsoft-defender-atp/onboard.md | 2 +- .../overview-custom-detections.md | 2 +- .../overview-hunting.md | 2 +- .../overview-secure-score.md | 4 ++-- .../microsoft-defender-atp/overview.md | 2 +- .../microsoft-defender-atp/portal-overview.md | 10 ++++----- .../microsoft-defender-atp/powerbi-reports.md | 4 ++-- .../preferences-setup.md | 4 ++-- .../pull-alerts-using-rest-api.md | 4 ++-- .../microsoft-defender-atp/rbac.md | 6 ++--- .../security-operations-dashboard.md | 4 ++-- .../microsoft-defender-atp/time-settings.md | 4 ++-- .../troubleshoot-onboarding-error-messages.md | 6 ++--- .../microsoft-defender-atp/troubleshoot.md | 2 +- .../microsoft-defender-atp/use-custom-ti.md | 2 +- .../microsoft-defender-atp/use.md | 8 +++---- .../microsoft-defender-atp/user-roles.md | 2 +- .../whats-new-in-microsoft-defender-atp.md | 4 ++-- .../windows-defender-security-center-atp.md | 12 +++++----- 56 files changed, 121 insertions(+), 121 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 0dc76f0fa0..297f7f6173 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -120,7 +120,7 @@ ##### [Network firewall](../windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) #### [Evaluate next generation protection](../windows-defender-antivirus/evaluate-windows-defender-antivirus.md) -### [Access the Windows Defender Security Center Community Center](community.md) +### [Access the Microsoft Defender Security Center Community Center](community.md) ## [Configure and manage capabilities](onboard.md) ### [Configure attack surface reduction](configure-attack-surface-reduction.md) @@ -354,7 +354,7 @@ ####[Configure information protection in Windows](information-protection-in-windows-config.md) -### [Configure Windows Defender Security Center settings](preferences-setup.md) +### [Configure Microsoft Defender Security Center settings](preferences-setup.md) #### General ##### [Update data retention settings](data-retention-settings.md) ##### [Configure alert notifications](configure-email-notifications.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md index 98b6b36f1f..dee0d64ec2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md @@ -83,7 +83,7 @@ When you complete the integration steps on both portals, you'll be able to see r ## Office 365 Threat Intelligence connection This feature is only available if you have an active Office 365 E5 or the Threat Intelligence add-on. For more information, see the Office 365 Enterprise E5 product page. -When you enable this feature, you'll be able to incorporate data from Office 365 Advanced Threat Protection into Windows Defender Security Center to conduct a holistic security investigation across Office 365 mailboxes and Windows machines. +When you enable this feature, you'll be able to incorporate data from Office 365 Advanced Threat Protection into Microsoft Defender Security Center to conduct a holistic security investigation across Office 365 mailboxes and Windows machines. >[!NOTE] >You'll need to have the appropriate license to enable this feature. diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md index 4d711a8fff..000918bc98 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md @@ -69,7 +69,7 @@ For more information on the query language and supported operators, see [Query The following tables are exposed as part of Advanced hunting: -- **AlertEvents** - Alerts on Windows Defender Security Center +- **AlertEvents** - Alerts on Microsoft Defender Security Center - **MachineInfo** - Machine information, including OS information - **MachineNetworkInfo** - Network properties of machines, including adapters, IP and MAC addresses, as well as connected networks and domains - **ProcessCreationEvents** - Process creation and related events @@ -124,7 +124,7 @@ These steps guide you on modifying and overwriting an existing query. The result set has several capabilities to provide you with effective investigation, including: -- Columns that return entity-related objects, such as Machine name, Machine ID, File name, SHA1, User, IP, and URL, are linked to their entity pages in Windows Defender Security Center. +- Columns that return entity-related objects, such as Machine name, Machine ID, File name, SHA1, User, IP, and URL, are linked to their entity pages in Microsoft Defender Security Center. - You can right-click on a cell in the result set and add a filter to your written query. The current filtering options are **include**, **exclude** or **advanced filter**, which provides additional filtering options on the cell value. These cell values are part of the row set. ![Image of Microsoft Defender ATP Advanced hunting result set](images/atp-advanced-hunting-results-filter.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md index cbe44720d3..525a4afacb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md @@ -1,6 +1,6 @@ --- -title: Alerts queue in Windows Defender Security Center -description: View and manage the alerts surfaced in Windows Defender Security Center +title: Alerts queue in Microsoft Defender Security Center +description: View and manage the alerts surfaced in Microsoft Defender Security Center keywords: search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,7 +18,7 @@ ms.topic: conceptual ms.date: 09/03/2018 --- -# Alerts queue in Windows Defender Security Center +# Alerts queue in Microsoft Defender Security Center Learn how you can view and manage the queue so that you can effectively investigate threats seen on entities such as machines, files, or user accounts. diff --git a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md index aeb28a277e..c85f9de2b6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md +++ b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md @@ -1,6 +1,6 @@ --- title: Microsoft Defender ATP alert API fields -description: Understand how the alert API fields map to the values in Windows Defender Security Center +description: Understand how the alert API fields map to the values in Microsoft Defender Security Center keywords: alerts, alert fields, fields, api, fields, pull alerts, rest api, request, response search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -30,7 +30,7 @@ ms.date: 10/16/2017 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-apiportalmapping-abovefoldlink) -Understand what data fields are exposed as part of the alerts API and how they map to Windows Defender Security Center. +Understand what data fields are exposed as part of the alerts API and how they map to Microsoft Defender Security Center. ## Alert API fields and portal mapping diff --git a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md index 227c780e28..b1cb1f4d55 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md +++ b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md @@ -1,5 +1,5 @@ --- -title: Assign user access to Windows Defender Security Center +title: Assign user access to Microsoft Defender Security Center description: Assign read and write or read only access to the Microsoft Defender Advanced Threat Protection portal. keywords: assign user roles, assign read and write access, assign read only access, user, user roles, roles search.product: eADQiWindows 10XVcnh @@ -18,7 +18,7 @@ ms.topic: article ms.date: 11/28/2018 --- -# Assign user access to Windows Defender Security Center +# Assign user access to Microsoft Defender Security Center **Applies to:** - Azure Active Directory diff --git a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md index ebb98886d3..c7f6f4517c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md @@ -1,5 +1,5 @@ --- -title: Use basic permissions to access Windows Defender Security Center +title: Use basic permissions to access Microsoft Defender Security Center description: Assign read and write or read only access to the Microsoft Defender Advanced Threat Protection portal. keywords: assign user roles, assign read and write access, assign read only access, user, user roles, roles search.product: eADQiWindows 10XVcnh diff --git a/windows/security/threat-protection/microsoft-defender-atp/community.md b/windows/security/threat-protection/microsoft-defender-atp/community.md index a70adba5f5..78f18ff20e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/community.md +++ b/windows/security/threat-protection/microsoft-defender-atp/community.md @@ -35,7 +35,7 @@ There are several spaces you can explore to learn about specific information: There are several ways you can access the Community Center: -- In the Windows Defender Security Center navigation pane, select **Community center**. A new browser tab opens and takes you to the Microsoft Defender ATP Tech Community page. +- In the Microsoft Defender Security Center navigation pane, select **Community center**. A new browser tab opens and takes you to the Microsoft Defender ATP Tech Community page. - Access the community through the [Microsoft Defender Advanced Threat Protection Tech Community](https://techcommunity.microsoft.com/t5/Windows-Defender-Advanced-Threat/ct-p/WindowsDefenderAdvanced) page diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md index 2b787f64c8..05c9269bca 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md @@ -1,6 +1,6 @@ --- title: Configure HP ArcSight to pull Microsoft Defender ATP alerts -description: Configure HP ArcSight to receive and pull alerts from Windows Defender Security Center +description: Configure HP ArcSight to receive and pull alerts from Microsoft Defender Security Center keywords: configure hp arcsight, security information and events management tools, arcsight search.product: eADQiWindows 10XVcnh search.appverid: met150 diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md index e599ecf7be..87e9fe515f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access.md @@ -38,13 +38,13 @@ You need to make sure that all your devices are enrolled in Intune. You can use -There are steps you'll need to take in Windows Defender Security Center, the Intune portal, and Azure AD portal. +There are steps you'll need to take in Microsoft Defender Security Center, the Intune portal, and Azure AD portal. > [!NOTE] > You'll need a Microsoft Intune environment, with Intune managed and Azure AD joined Windows 10 devices. Take the following steps to enable conditional access: -- Step 1: Turn on the Microsoft Intune connection from Windows Defender Security Center +- Step 1: Turn on the Microsoft Intune connection from Microsoft Defender Security Center - Step 2: Turn on the Microsoft Defender ATP integration in Intune - Step 3: Create the compliance policy in Intune - Step 4: Assign the policy diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md index 24f3338a41..03ef4fb943 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp.md @@ -36,7 +36,7 @@ ms.date: 04/24/2018 > To use Group Policy (GP) updates to deploy the package, you must be on Windows Server 2008 R2 or later. ## Onboard machines using Group Policy -1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Onboarding**. @@ -66,7 +66,7 @@ ms.date: 04/24/2018 > After onboarding the machine, you can choose to run a detection test to verify that the machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). ## Additional Microsoft Defender ATP configuration settings -For each machine, you can state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. +For each machine, you can state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. You can use Group Policy (GP) to configure settings, such as settings for the sample sharing used in the deep analysis feature. @@ -98,7 +98,7 @@ For security reasons, the package used to Offboard machines will expire 30 days > [!NOTE] > Onboarding and offboarding policies must not be deployed on the same machine at the same time, otherwise this will cause unpredictable collisions. -1. Get the offboarding package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Get the offboarding package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Offboarding**. @@ -132,7 +132,7 @@ For security reasons, the package used to Offboard machines will expire 30 days With Group Policy there isn’t an option to monitor deployment of policies on the machines. Monitoring can be done directly on the portal, or by using the different deployment tools. ## Monitor machines using the portal -1. Go to [Windows Defender Security Center](https://securitycenter.windows.com/). +1. Go to [Microsoft Defender Security Center](https://securitycenter.windows.com/). 2. Click **Machines list**. 3. Verify that machines are appearing. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md index 79a5287504..b4aa4e7b94 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm.md @@ -57,7 +57,7 @@ For security reasons, the package used to Offboard machines will expire 30 days > [!NOTE] > Onboarding and offboarding policies must not be deployed on the same machine at the same time, otherwise this will cause unpredictable collisions. -1. Get the offboarding package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Get the offboarding package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Offboarding**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md index f431da0f01..11e887fd72 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows.md @@ -28,7 +28,7 @@ ms.topic: article -Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products’ sensor data. +Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Microsoft Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products’ sensor data. You'll need to know the exact Linux distros and macOS versions that are compatible with Microsoft Defender ATP for the integration to work. @@ -58,7 +58,7 @@ Create an EICAR test file by saving the string displayed on the portal in an emp The file should trigger a detection and a corresponding alert on Microsoft Defender ATP. ## Offboard non-Windows machines -To effectively offboard the machine from the service, you'll need to disable the data push on the third-party portal first then switch the toggle to off in Windows Defender Security Center. The toggle in the portal only blocks the data inbound flow. +To effectively offboard the machine from the service, you'll need to disable the data push on the third-party portal first then switch the toggle to off in Microsoft Defender Security Center. The toggle in the portal only blocks the data inbound flow. 1. Follow the third-party documentation to opt-out on the third-party service side. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md index 8a91ad835d..509661ca90 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm.md @@ -49,7 +49,7 @@ You can use existing System Center Configuration Manager functionality to create ### Onboard machines using System Center Configuration Manager -1. Open the SCCM configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Open the SCCM configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Onboarding**. @@ -72,7 +72,7 @@ You can use existing System Center Configuration Manager functionality to create > After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP machine](run-detection-test-windows-defender-advanced-threat-protection.md). ### Configure sample collection settings -For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. +For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. You can set a compliance rule for configuration item in System Center Configuration Manager to change the sample share setting on a machine. This rule should be a *remediating* compliance rule configuration item that sets the value of a registry key on targeted machines to make sure they’re complaint. @@ -103,7 +103,7 @@ For security reasons, the package used to Offboard machines will expire 30 days > [!NOTE] > Onboarding and offboarding policies must not be deployed on the same machine at the same time, otherwise this will cause unpredictable collisions. -1. Get the offboarding package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Get the offboarding package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Offboarding**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md index 9b0d319050..88cd708b56 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script.md @@ -35,7 +35,7 @@ You can also manually onboard individual machines to Microsoft Defender ATP. You > The script has been optimized to be used on a limited number of machines (1-10 machines). To deploy to scale, use other deployment options. For more information on using other deployment options, see [Onboard Window 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). ## Onboard machines -1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Open the GP configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Onboarding**. @@ -67,7 +67,7 @@ For information on how you can manually validate that the machine is compliant a > After onboarding the machine, you can choose to run a detection test to verify that an machine is properly onboarded to the service. For more information, see [Run a detection test on a newly onboarded Microsoft Defender ATP endpoint](run-detection-test-windows-defender-advanced-threat-protection.md). ## Configure sample collection settings -For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Windows Defender Security Center to submit a file for deep analysis. +For each machine, you can set a configuration value to state whether samples can be collected from the machine when a request is made through Microsoft Defender Security Center to submit a file for deep analysis. You can manually configure the sample sharing setting on the machine by using *regedit* or creating and running a *.reg* file. @@ -93,7 +93,7 @@ For security reasons, the package used to Offboard machines will expire 30 days > [!NOTE] > Onboarding and offboarding policies must not be deployed on the same machine at the same time, otherwise this will cause unpredictable collisions. -1. Get the offboarding package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Get the offboarding package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Offboarding**. @@ -127,7 +127,7 @@ You can follow the different verification steps in the [Troubleshoot onboarding Monitoring can also be done directly on the portal, or by using the different deployment tools. ### Monitor machines using the portal -1. Go to Windows Defender Security Center. +1. Go to Microsoft Defender Security Center. 2. Click **Machines list**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md index be05604d0b..95c0a67fb9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi.md @@ -43,7 +43,7 @@ You can onboard VDI machines using a single entry or multiple entries for each m >[!WARNING] > For environments where there are low resource configurations, the VDI boot proceedure might slow the Microsoft Defender ATP sensor onboarding. -1. Open the VDI configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Windows Defender Security Center](https://securitycenter.windows.com/): +1. Open the VDI configuration package .zip file (*WindowsDefenderATPOnboardingPackage.zip*) that you downloaded from the service onboarding wizard. You can also get the package from [Microsoft Defender Security Center](https://securitycenter.windows.com/): a. In the navigation pane, select **Settings** > **Onboarding**. @@ -83,8 +83,8 @@ You can onboard VDI machines using a single entry or multiple entries for each m d. Logon to machine with another user. - e. **For single entry for each machine**: Check only one entry in Windows Defender Security Center.
- **For multiple entries for each machine**: Check multiple entries in Windows Defender Security Center. + e. **For single entry for each machine**: Check only one entry in Microsoft Defender Security Center.
+ **For multiple entries for each machine**: Check multiple entries in Microsoft Defender Security Center. 7. Click **Machines list** on the Navigation pane. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md index 0f0180a75a..cc7fc9a6ee 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md @@ -68,7 +68,7 @@ You'll start receiving targeted attack notification from Microsoft Threat Expert ## Ask a Microsoft threat expert about suspicious cybersecurity activities in your organization -You can partner with Microsoft Threat Experts who can be engaged directly from within the Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. +You can partner with Microsoft Threat Experts who can be engaged directly from within the Microsoft Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. 1. Navigate to the portal page with the relevant information that you'd like to investigate, for example, the **Incident** page. Ensure that the page for the relevant alert or machine is in view before raising an inquiry. 2. From the upper right-hand menu, click **?**, then select **Ask a threat expert**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md index 3dd2f86f1f..abe48eeec7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support.md @@ -35,7 +35,7 @@ You'll need to take the following configuration steps to enable the managed secu > - MSSP customers: Organizations that engage the services of MSSPs. The integration will allow MSSPs to take the following actions: -- Get access to MSSP customer's Windows Defender Security Center portal +- Get access to MSSP customer's Microsoft Defender Security Center portal - Get email notifications, and - Fetch alerts through security information and event management (SIEM) tools @@ -46,7 +46,7 @@ Typically, MSSP customers take the initial configuration steps to grant MSSPs ac In general, the following configuration steps need to be taken: -- **Grant the MSSP access to Windows Defender Security Center**
+- **Grant the MSSP access to Microsoft Defender Security Center**
This action needs to be done by the MSSP customer. It grants the MSSP access to the MSSP customer's Microsoft Defender ATP tenant. - **Configure alert notifications sent to MSSPs**
@@ -65,21 +65,21 @@ This action is taken by the MSSP. It allows MSSPs to fetch alerts using APIs. > These set of steps are directed towards the MSSP customer.
> Access to the portal can only be done by the MSSP customer. -As a MSSP customer, you'll need to take the following configuration steps to grant the MSSP access to Windows Defender Security Center. +As a MSSP customer, you'll need to take the following configuration steps to grant the MSSP access to Microsoft Defender Security Center. Authentication and authorization of the MSSP user is built on top of Azure Active Directory (Azure AD) B2B functionality. You'll need to take the following 2 steps: - Add MSSP user to your tenant as a guest user -- Grant MSSP user access to Windows Defender Security Center +- Grant MSSP user access to Microsoft Defender Security Center ### Add MSSP user to your tenant as a guest user Add a user who is a member of the MSSP tenant to your tenant as a guest user. To grant portal access to the MSSP, you must add the MSSP user to your Azure AD as a guest user. For more information, see [Add Azure Active Directory B2B collaboration users in the Azure portal](https://docs.microsoft.com/azure/active-directory/b2b/add-users-administrator). -### Grant MSSP user access to Windows Defender Security Center -Grant the guest user access and permissions to your Windows Defender Security Center tenant. +### Grant MSSP user access to Microsoft Defender Security Center +Grant the guest user access and permissions to your Microsoft Defender Security Center tenant. Granting access to guest user is done the same way as granting access to a user who is a member of your tenant. @@ -94,12 +94,12 @@ It is recommended that groups are created for MSSPs to make authorization access As a MSSP customer, you can always remove or modify the permissions granted to the MSSP by updating the Azure AD user groups. -## Access the Windows Defender Security Center MSSP customer portal +## Access the Microsoft Defender Security Center MSSP customer portal >[!NOTE] >These set of steps are directed towards the MSSP. -By default, MSSP customers access their Windows Defender Security Center tenant through the following URL: `https://securitycenter.windows.com`. +By default, MSSP customers access their Microsoft Defender Security Center tenant through the following URL: `https://securitycenter.windows.com`. MSSPs however, will need to use a tenant-specific URL in the following format: `https://securitycenter.windows.com?tid=customer_tenant_id` to access the MSSP customer portal. @@ -142,7 +142,7 @@ Step 1: Create a third-party application Step 2: Get access and refresh tokens from your customer's tenant -Step 3: Whitelist your application on Windows Defender Security Center +Step 3: Whitelist your application on Microsoft Defender Security Center @@ -257,8 +257,8 @@ After providing your credentials, you'll need to grant consent to the applicatio 8. In the PowerShell window, you'll receive an access token and a refresh token. Save the refresh token to configure your SIEM connector. -### Step 3: Whitelist your application on Windows Defender Security Center -You'll need to whitelist the application you created in Windows Defender Security Center. +### Step 3: Whitelist your application on Microsoft Defender Security Center +You'll need to whitelist the application you created in Microsoft Defender Security Center. You'll need to have **Manage portal system settings** permission to whitelist the application. Otherwise, you'll need to request your customer to whitelist the application for you. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md index b247126bb2..5150173b16 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints.md @@ -31,7 +31,7 @@ ms.topic: article >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-configserver-abovefoldlink) -Microsoft Defender ATP extends support to also include the Windows Server operating system, providing advanced attack detection and investigation capabilities, seamlessly through the Windows Defender Security Center console. +Microsoft Defender ATP extends support to also include the Windows Server operating system, providing advanced attack detection and investigation capabilities, seamlessly through the Microsoft Defender Security Center console. The service supports the onboarding of the following servers: - Windows Server 2012 R2 @@ -47,7 +47,7 @@ For a practical guidance on what needs to be in place for licensing and infrastr There are two options to onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP: - **Option 1**: Onboard through Azure Security Center -- **Option 2**: Onboard through Windows Defender Security Center +- **Option 2**: Onboard through Microsoft Defender Security Center ### Option 1: Onboard servers through Azure Security Center 1. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**. @@ -58,15 +58,15 @@ There are two options to onboard Windows Server 2012 R2 and Windows Server 2016 4. Follow the onboarding instructions in [Microsoft Defender Advanced Threat Protection with Azure Security Center](https://docs.microsoft.com/azure/security-center/security-center-wdatp). -### Option 2: Onboard servers through Windows Defender Security Center -You'll need to tak the following steps if you choose to onboard servers through Windows Defender Security Center. +### Option 2: Onboard servers through Microsoft Defender Security Center +You'll need to tak the following steps if you choose to onboard servers through Microsoft Defender Security Center. - For Windows Server 2012 R2: Configure and update System Center Endpoint Protection clients. >[!NOTE] >This step is required only if your organization uses System Center Endpoint Protection (SCEP) and you're onboarding Windows Server 2012 R2. -- Turn on server monitoring from Windows Defender Security Center. +- Turn on server monitoring from Microsoft Defender Security Center. - If you're already leveraging System Center Operations Manager (SCOM) or Azure Monitor (formerly known as Operations Management Suite (OMS)), simply attach the Microsoft Monitoring Agent (MMA) to report to your Microsoft Defender ATP workspace through Multi Homing support. Otherwise, install and configure MMA to report sensor data to Microsoft Defender ATP as instructed below. For more information, see [Collect log data with Azure Log Analytics agent](https://docs.microsoft.com/azure/azure-monitor/platform/log-analytics-agent). >[!TIP] @@ -83,7 +83,7 @@ The following steps are required to enable this integration: - Configure the SCEP client Cloud Protection Service membership to the **Advanced** setting -### Turn on Server monitoring from the Windows Defender Security Center portal +### Turn on Server monitoring from the Microsoft Defender Security Center portal 1. In the navigation pane, select **Settings** > **Machine management** > **Onboarding**. @@ -174,7 +174,7 @@ The following capabilities are included in this integration: > Automated onboarding is only applicable for Windows Server 2012 R2 and Windows Server 2016. - Servers monitored by Azure Security Center will also be available in Microsoft Defender ATP - Azure Security Center seamlessly connects to the Microsoft Defender ATP tenant, providing a single view across clients and servers. In addition, Microsoft Defender ATP alerts will be available in the Azure Security Center console. -- Server investigation - Azure Security Center customers can access Windows Defender Security Center to perform detailed investigation to uncover the scope of a potential breach +- Server investigation - Azure Security Center customers can access Microsoft Defender Security Center to perform detailed investigation to uncover the scope of a potential breach >[!IMPORTANT] >- When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created. The Microsoft Defender ATP data is stored in Europe by default. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md index 9c544f5795..1cc071a515 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-siem.md @@ -58,6 +58,6 @@ Topic | Description [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)| Learn about enabling the SIEM integration feature in the **Settings** page in the portal so that you can use and generate the required information to configure supported SIEM tools. [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md)| Learn about installing the REST API Modular Input app and other configuration settings to enable Splunk to pull Microsoft Defender ATP alerts. [Configure HP ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)| Learn about installing the HP ArcSight REST FlexConnector package and the files you need to configure ArcSight to pull Microsoft Defender ATP alerts. -[Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) | Understand what data fields are exposed as part of the alerts API and how they map to Windows Defender Security Center. +[Microsoft Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md) | Understand what data fields are exposed as part of the alerts API and how they map to Microsoft Defender Security Center. [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) | Use the Client credentials OAuth 2.0 flow to pull alerts from Microsoft Defender ATP using REST API. [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) | Address issues you might encounter when using the SIEM integration feature. diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md index bb3e6d4f5b..a59e0fb017 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-splunk.md @@ -1,6 +1,6 @@ --- title: Configure Splunk to pull Microsoft Defender ATP alerts -description: Configure Splunk to receive and pull alerts from Windows Defender Security Center. +description: Configure Splunk to receive and pull alerts from Microsoft Defender Security Center. keywords: configure splunk, security information and events management tools, splunk search.product: eADQiWindows 10XVcnh search.appverid: met150 diff --git a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md index 552a856b66..8da5ea770d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api.md @@ -137,7 +137,7 @@ Content-Type: application/json; } ``` -The following values correspond to the alert sections surfaced on Windows Defender Security Center: +The following values correspond to the alert sections surfaced on Microsoft Defender Security Center: ![Image of alert from the portal](images/atp-custom-ti-mapping.png) Highlighted section | JSON key name diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md index c90107793c..d450893080 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti.md @@ -29,7 +29,7 @@ ms.date: 04/24/2018 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablecustomti-abovefoldlink) -Before you can create custom threat intelligence (TI) using REST API, you'll need to set up the custom threat intelligence application through Windows Defender Security Center. +Before you can create custom threat intelligence (TI) using REST API, you'll need to set up the custom threat intelligence application through Microsoft Defender Security Center. 1. In the navigation pane, select **Settings** > **Threat intel**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md index a5099be0b4..333a44a06f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration.md @@ -26,7 +26,7 @@ ms.date: 12/10/2018 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-enablesiem-abovefoldlink) -Enable security information and event management (SIEM) integration so you can pull alerts from Windows Defender Security Center using your SIEM solution or by connecting directly to the alerts REST API. +Enable security information and event management (SIEM) integration so you can pull alerts from Microsoft Defender Security Center using your SIEM solution or by connecting directly to the alerts REST API. ## Prerequisites - The user who activates the setting must have permissions to create an app in Azure Active Directory (AAD). This is typically someone with a **Global administrator** role. @@ -64,7 +64,7 @@ Enable security information and event management (SIEM) integration so you can p > [!NOTE] > You'll need to generate a new Refresh token every 90 days. -You can now proceed with configuring your SIEM solution or connecting to the alerts REST API through programmatic access. You'll need to use the tokens when configuring your SIEM solution to allow it to receive alerts from Windows Defender Security Center. +You can now proceed with configuring your SIEM solution or connecting to the alerts REST API through programmatic access. You'll need to use the tokens when configuring your SIEM solution to allow it to receive alerts from Microsoft Defender Security Center. ## Integrate Microsoft Defender ATP with IBM QRadar You can configure IBM QRadar to collect alerts from Microsoft Defender ATP. For more information, see [IBM Knowledge Center](https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_dsm_guide_MS_Win_Defender_ATP_overview.html?cp=SS42VS_7.3.1). diff --git a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md index b89eeb886a..b6eee8768f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti.md @@ -141,7 +141,7 @@ This step will guide you in simulating an event in connection to a malicious IP ## Step 4: Explore the custom alert in the portal This step will guide you in exploring the custom alert in the portal. -1. Open [Windows Defender Security Center](http://securitycenter.windows.com/) on a browser. +1. Open [Microsoft Defender Security Center](http://securitycenter.windows.com/) on a browser. 2. Log in with your Microsoft Defender ATP credentials. diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md index 25198b66e2..ba0614caa3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md +++ b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md @@ -39,7 +39,7 @@ An inactive machine is not necessarily flagged due to an issue. The following ac If the machine has not been in use for more than 7 days for any reason, it will remain in an ‘Inactive’ status in the portal. **Machine was reinstalled or renamed**
-A reinstalled or renamed machine will generate a new machine entity in Windows Defender Security Center. The previous machine entity will remain with an ‘Inactive’ status in the portal. If you reinstalled a machine and deployed the Microsoft Defender ATP package, search for the new machine name to verify that the machine is reporting normally. +A reinstalled or renamed machine will generate a new machine entity in Microsoft Defender Security Center. The previous machine entity will remain with an ‘Inactive’ status in the portal. If you reinstalled a machine and deployed the Microsoft Defender ATP package, search for the new machine name to verify that the machine is reporting normally. **Machine was offboarded**
If the machine was offboarded it will still appear in machines list. After 7 days, the machine health state should change to inactive. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-started.md b/windows/security/threat-protection/microsoft-defender-atp/get-started.md index f5a6fa236f..cc12829160 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-started.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-started.md @@ -47,7 +47,7 @@ In conjunction with being able to quickly respond to advanced attacks, Microsoft Microsoft Defender ATP provides a security posture capability to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security state of your network. **Advanced hunting**
-Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Windows Defender Security Center. +Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Microsoft Defender Security Center. **Management and APIs**
Integrate Microsoft Defender Advanced Threat Protection into your existing workflows. @@ -64,4 +64,4 @@ Topic | Description [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) | Explains the data storage and privacy details related to Microsoft Defender ATP. [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md) | Set permissions to manage who can access the portal. You can set basic permissions or set granular permissions using role-based access control (RBAC). [Evaluate Microsoft Defender ATP](evaluate-atp.md) | Evaluate the various capabilities in Microsoft Defender ATP and test features out. -[Access the Windows Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file +[Access the Microsoft Defender Security Center Community Center](community-windows-defender-advanced-threat-protection.md) | The Microsoft Defender ATP Community Center is a place where community members can learn, collaborate, and share experiences about the product. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md index f594da75a4..fad5873fe4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/information-protection-in-windows-overview.md @@ -38,7 +38,7 @@ Microsoft Defender ATP applies two methods to discover and protect data: ## Data discovery -Microsoft Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Windows Defender Security Center. For more information, see [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md#azure-information-protection). +Microsoft Defender ATP automatically discovers files with sensitivity labels on Windows devices when the feature is enabled. You can enable the Azure Information Protection integration feature from Microsoft Defender Security Center. For more information, see [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md#azure-information-protection). ![Image of settings page with Azure Information Protection](images/atp-settings-aip.png) @@ -78,8 +78,8 @@ InformationProtectionLogs_CL **Prerequisites:** - Customers must have a subscription for Azure Information Protection. -- Enable Azure Information Protection integration in Windows Defender Security Center: - - Go to **Settings** in Windows Defender Security Center, click on **Advanced Settings** under **General**. +- Enable Azure Information Protection integration in Microsoft Defender Security Center: + - Go to **Settings** in Microsoft Defender Security Center, click on **Advanced Settings** under **General**. ## Data protection diff --git a/windows/security/threat-protection/microsoft-defender-atp/licensing.md b/windows/security/threat-protection/microsoft-defender-atp/licensing.md index efbcf00dab..1011ef2e74 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/licensing.md +++ b/windows/security/threat-protection/microsoft-defender-atp/licensing.md @@ -51,9 +51,9 @@ To gain access into which licenses are provisioned to your company, and to check ![Image of O365 admin portal](images\atp-O365-admin-portal-customer.png) -## Access Windows Defender Security Center for the first time +## Access Microsoft Defender Security Center for the first time -When accessing [Windows Defender Security Center](https://SecurityCenter.Windows.com) for the first time there will be a setup wizard that will guide you through some initial steps. At the end of the setup wizard there will be a dedicated cloud instance of Microsoft Defender ATP created. +When accessing [Microsoft Defender Security Center](https://SecurityCenter.Windows.com) for the first time there will be a setup wizard that will guide you through some initial steps. At the end of the setup wizard there will be a dedicated cloud instance of Microsoft Defender ATP created. 1. Each time you access the portal you will need to validate that you are authorized to access the product. This **Set up your permissions** step will only be available if you are not currently authorized to access the product. @@ -65,7 +65,7 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows ![Image of Welcome screen for portal set up](images\welcome1.png) - You will need to set up your preferences for Windows Defender Security Center. + You will need to set up your preferences for Microsoft Defender Security Center. 3. Set up preferences @@ -98,11 +98,11 @@ When accessing [Windows Defender Security Center](https://SecurityCenter.Windows 4. You will receive a warning notifying you that you won't be able to change some of your preferences once you click **Continue**. > [!NOTE] - > Some of these options can be changed at a later time in Windows Defender Security Center. + > Some of these options can be changed at a later time in Microsoft Defender Security Center. ![Image of final preference set up](images\setup-preferences2.png) -5. A dedicated cloud instance of Windows Defender Security Center is being created at this time. This step will take an average of 5 minutes to complete. +5. A dedicated cloud instance of Microsoft Defender Security Center is being created at this time. This step will take an average of 5 minutes to complete. ![Image of Microsoft Defender ATP cloud instance](images\creating-account.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md index 85be05b201..6aafe49de3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-alerts.md @@ -41,7 +41,7 @@ If an alert is no yet assigned, you can select **Assign to me** to assign the al ## Suppress alerts -There might be scenarios where you need to suppress alerts from appearing in Windows Defender Security Center. Microsoft Defender ATP lets you create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. +There might be scenarios where you need to suppress alerts from appearing in Microsoft Defender Security Center. Microsoft Defender ATP lets you create suppression rules for specific alerts that are known to be innocuous such as known tools or processes in your organization. Suppression rules can be created from an existing alert. They can be disabled and reenabled if needed. diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md index fa2c696f10..92c91b1b6f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation.md @@ -1,5 +1,5 @@ --- -title: Learn about the automated investigations dashboard in Windows Defender Security Center +title: Learn about the automated investigations dashboard in Microsoft Defender Security Center description: View the list of automated investigations, its status, detection source and other details. keywords: autoir, automated, investigation, detection, dashboard, source, threat types, id, tags, machines, duration, filter export search.product: eADQiWindows 10XVcnh diff --git a/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md b/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md index b430f21281..84835dc6f5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md +++ b/windows/security/threat-protection/microsoft-defender-atp/manage-edr.md @@ -26,7 +26,7 @@ Manage the alerts queue, investigate machines in the machines list, take respons ## In this section Topic | Description :---|:--- -[Alerts queue](alerts-queue-endpoint-detection-response.md)| View the alerts surfaced in Windows Defender Security Center. +[Alerts queue](alerts-queue-endpoint-detection-response.md)| View the alerts surfaced in Microsoft Defender Security Center. [Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md) | Learn how you can view and manage the machines list, manage machine groups, and investigate machine related alerts. [Take response actions](response-actions-windows-defender-advanced-threat-protection.md)| Take response actions on machines and files to quickly respond to detected attacks and contain threats. [Query data using advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md)| Proactively hunt for possible threats across your organization using a powerful search and query tool. \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md index f8990f3871..36122f938c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-cloud-app-security-integration.md @@ -37,7 +37,7 @@ The integration provides the following major improvements to the existing Cloud - Available everywhere - Since the network activity is collected directly from the endpoint, it's available wherever the device is, on or off corporate network, as it's no longer depended on traffic routed through the enterprise firewall or proxy servers. -- Works out of the box, no configuration required - Forwarding cloud traffic logs to Cloud App Security requires firewall and proxy server configuration. With the Microsoft Defender ATP and Cloud App Security integration, there's no configuration required. Just switch it on in Windows Defender Security Center settings and you're good to go. +- Works out of the box, no configuration required - Forwarding cloud traffic logs to Cloud App Security requires firewall and proxy server configuration. With the Microsoft Defender ATP and Cloud App Security integration, there's no configuration required. Just switch it on in Microsoft Defender Security Center settings and you're good to go. - Device context - Cloud traffic logs lack device context. Microsoft Defender ATP network activity is reported with the device context (which device accessed the cloud app), so you are able to understand exactly where (device) the network activity took place, in addition to who (user) performed it. diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md index 4b2be0215b..1e661e11f1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md @@ -116,7 +116,7 @@ Integrate Microsoft Defender Advanced Threat Protection into your existing workf ## In this section -To help you maximize the effectiveness of the security platform, you can configure individual capabilities that surface in Windows Defender Security Center. +To help you maximize the effectiveness of the security platform, you can configure individual capabilities that surface in Microsoft Defender Security Center. Topic | Description :---|:--- diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md index 652eaf3652..5541a2edb5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-threat-experts.md @@ -36,7 +36,7 @@ Microsoft Threat Experts provides proactive hunting for the most important threa - Scope of compromise and as much context as can be quickly delivered to enable fast SOC response. ## Collaborate with experts, on demand -Customers can engage our security experts directly from within Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand the complex threats affecting your organization, from alert inquiries, potentially compromised machines, root cause of a suspicious network connection, to additional threat intelligence regarding ongoing advanced persistent threat campaigns. With this capability, you can: +Customers can engage our security experts directly from within Microsoft Defender Security Center for timely and accurate response. Experts provide insights needed to better understand the complex threats affecting your organization, from alert inquiries, potentially compromised machines, root cause of a suspicious network connection, to additional threat intelligence regarding ongoing advanced persistent threat campaigns. With this capability, you can: - Get additional clarification on alerts including root cause or scope of the incident - Gain clarity into suspicious machine behavior and next steps if faced with an advanced attacker - Determine risk and protection regarding threat actors, campaigns, or emerging attacker techniques diff --git a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md index 33e5a03df9..71bf5122da 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mssp-support.md @@ -35,7 +35,7 @@ To address this demand, managed security service providers (MSSP) offer to deliv Microsoft Defender ATP adds support for this scenario and to allow MSSPs to take the following actions: -- Get access to MSSP customer's Windows Defender Security Center portal +- Get access to MSSP customer's Microsoft Defender Security Center portal - Get email notifications, and - Fetch alerts through security information and event management (SIEM) tools diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md index 353ee5e12b..61dc191dc5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md @@ -163,7 +163,7 @@ Topic | Description [Onboard previous versions of Windows](onboard-downlevel-windows-defender-advanced-threat-protection.md)| Onboard Windows 7 and Windows 8.1 machines to Microsoft Defender ATP. [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) | You'll need to onboard machines for it to report to the Microsoft Defender ATP service. Learn about the tools and methods you can use to configure machines in your enterprise. [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md) | Onboard Windows Server 2012 R2 and Windows Server 2016 to Microsoft Defender ATP -[Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) | Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. +[Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md) | Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Microsoft Defender Security Center and better protect your organization's network. This experience leverages on a third-party security products' sensor data. [Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md) | Run a script on a newly onboarded machine to verify that it is properly reporting to the Microsoft Defender ATP service. [Configure proxy and Internet settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)| Enable communication with the Microsoft Defender ATP cloud service by configuring the proxy and Internet connectivity settings. [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) | Learn about resolving issues that might arise during onboarding. diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard.md b/windows/security/threat-protection/microsoft-defender-atp/onboard.md index 9bb3eaa985..582233db3c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard.md @@ -34,7 +34,7 @@ Topic | Description [Configure Secure score dashboard security controls](secure-score-dashboard-windows-defender-advanced-threat-protection.md) | Configure the security controls in Secure score to increase the security posture of your organization. Configure Microsoft Threat Protection integration| Configure other solutions that integrate with Microsoft Defender ATP. Management and API support| Pull alerts to your SIEM or use APIs to create custom alerts. Create and build Power BI reports. -[Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. +[Configure Microsoft Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure portal related settings such as general settings, advanced features, enable the preview experience and others. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md b/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md index 8101a199e5..37f04e38cb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md @@ -27,7 +27,7 @@ ms.date: 10/29/2018 Alerts in Microsoft Defender ATP are surfaced through the system based on signals gathered from endpoints. With custom detections, you can create custom queries to monitor events for any kind of behavior such as suspicious or emerging threats. This can be done by leveraging the power of Advanced hunting through the creation of custom detection rules. -Custom detections are queries that run periodically every 24 hours and can be configured so that when the query meets the criteria you set, alerts are created and are surfaced in Windows Defender Security Center. These alerts will be treated like any other alert in the system. +Custom detections are queries that run periodically every 24 hours and can be configured so that when the query meets the criteria you set, alerts are created and are surfaced in Microsoft Defender Security Center. These alerts will be treated like any other alert in the system. This capability is particularly useful for scenarios when you want to pro-actively prevent threats and be notified quickly of emerging threats. diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md index 6742a95514..b6d5d31b21 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-hunting.md @@ -22,7 +22,7 @@ ms.date: 09/12/2018 **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Windows Defender Security Center. +Advanced hunting allows you to hunt for possible threats across your organization using a powerful search and query tool. You can also create custom detection rules based on the queries you created and surface alerts in Microsoft Defender Security Center. With advanced hunting, you can take advantage of the following capabilities: diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index 3d27aa1319..f1b31e4f2a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -1,5 +1,5 @@ --- -title: Overview of Secure score in Windows Defender Security Center +title: Overview of Secure score in Microsoft Defender Security Center description: Expand your visibility into the overall security posture of your organization keywords: secure score, security controls, improvement opportunities, security score over time, score, posture, baseline search.product: eADQiWindows 10XVcnh @@ -18,7 +18,7 @@ ms.topic: conceptual ms.date: 09/03/2018 --- -# Overview of Secure score in Windows Defender Security Center +# Overview of Secure score in Microsoft Defender Security Center **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview.md b/windows/security/threat-protection/microsoft-defender-atp/overview.md index 84d99f3816..0bfb1b24c9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview.md @@ -41,7 +41,7 @@ Topic | Description [Advanced hunting](overview-hunting-windows-defender-advanced-threat-protection.md) | Use a powerful search and query language to create custom queries and detection rules. [Management and APIs](management-apis.md) | Microsoft Defender ATP supports a wide variety of tools to help you manage and interact with the platform so that you can integrate the service into your existing workflows. [Microsoft Threat Protection](threat-protection-integration.md) | Microsoft security products work better together. Learn about other security capabilities in the Microsoft threat protection stack. -[Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) |Learn to navigate your way around Windows Defender Security Center. +[Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) |Learn to navigate your way around Microsoft Defender Security Center. diff --git a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md index 7a4701750d..2a989a87e4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md @@ -1,7 +1,7 @@ --- title: Microsoft Defender Advanced Threat Protection portal overview -description: Use Windows Defender Security Center to monitor your enterprise network and assist in responding to alerts to potential advanced persistent threat (APT) activity or data breaches. -keywords: Windows Defender Security Center, portal, cybersecurity threat intelligence, dashboard, alerts queue, machines list, settings, machine management, advanced attacks +description: Use Microsoft Defender Security Center to monitor your enterprise network and assist in responding to alerts to potential advanced persistent threat (APT) activity or data breaches. +keywords: Microsoft Defender Security Center, portal, cybersecurity threat intelligence, dashboard, alerts queue, machines list, settings, machine management, advanced attacks search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -27,14 +27,14 @@ ms.date: 04/24/2018 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portaloverview-abovefoldlink) -Enterprise security teams can use Windows Defender Security Center to monitor and assist in responding to alerts of potential advanced persistent threat (APT) activity or data breaches. +Enterprise security teams can use Microsoft Defender Security Center to monitor and assist in responding to alerts of potential advanced persistent threat (APT) activity or data breaches. -You can use [Windows Defender Security Center](https://securitycenter.windows.com/) to: +You can use [Microsoft Defender Security Center](https://securitycenter.windows.com/) to: - View, sort, and triage alerts from your endpoints - Search for more information on observed indicators such as files and IP Addresses - Change Microsoft Defender ATP settings, including time zone and review licensing information. -## Windows Defender Security Center +## Microsoft Defender Security Center When you open the portal, you’ll see the main areas of the application: ![Microsoft Defender Advanced Threat Protection portal](images/dashboard.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md index 0d4640bbf3..46ffbdcef5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md +++ b/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports.md @@ -41,7 +41,7 @@ You can easily get started by: - Creating a dashboard on the Power BI service - Building a custom dashboard on Power BI Desktop and tweaking it to fit the visual analytics and reporting requirements of your organization -You can access these options from Windows Defender Security Center. Both the Power BI service and Power BI Desktop are supported. +You can access these options from Microsoft Defender Security Center. Both the Power BI service and Power BI Desktop are supported. ## Create a Microsoft Defender ATP dashboard on Power BI service Microsoft Defender ATP makes it easy to create a Power BI dashboard by providing an option straight from the portal. @@ -133,7 +133,7 @@ You can create a custom dashboard in Power BI Desktop to create visualizations t ### Before you begin 1. Make sure you use Power BI Desktop June 2017 and above. [Download the latest version](https://powerbi.microsoft.com/en-us/desktop/). -2. In the Windows Defender Security Center navigation pane, select **Settings** > **Power BI reports**. +2. In the Microsoft Defender Security Center navigation pane, select **Settings** > **Power BI reports**. ![Image of settings Power BI reports](images/atp-settings-powerbi.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md index d9035a183b..72c0e3c1e6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preferences-setup.md @@ -1,5 +1,5 @@ --- -title: Configure Windows Defender Security Center settings +title: Configure Microsoft Defender Security Center settings description: Use the settings page to configure general settings, permissions, apis, and rules. keywords: settings, general settings, permissions, apis, rules search.product: eADQiWindows 10XVcnh @@ -17,7 +17,7 @@ ms.collection: M365-security-compliance ms.topic: article ms.date: 04/24/2018 --- -# Configure Windows Defender Security Center settings +# Configure Microsoft Defender Security Center settings **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) diff --git a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md index a91e2ea546..41c78cc6f9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api.md @@ -45,7 +45,7 @@ The _Client credential flow_ uses client credentials to authenticate against the Use the following method in the Microsoft Defender ATP API to pull alerts in JSON format. >[!NOTE] ->Windows Defender Security Center merges similar alert detections into a single alert. This API pulls alert detections in its raw form based on the query parameters you set, enabling you to apply your own grouping and filtering. +>Microsoft Defender Security Center merges similar alert detections into a single alert. This API pulls alert detections in its raw form based on the query parameters you set, enabling you to apply your own grouping and filtering. ## Before you begin - Before calling the Microsoft Defender ATP endpoint to pull alerts, you'll need to enable the SIEM integration application in Azure Active Directory (AAD). For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). @@ -111,7 +111,7 @@ string ago | string | Pulls alerts in the following time range: from `(current_t int?limit | int | Defines the number of alerts to be retrieved. Most recent alerts will be retrieved based on the number defined.

**NOTE**: When not specified, all alerts available in the time range will be retrieved. machinegroups | String | Specifies machine groups to pull alerts from.

**NOTE**: When not specified, alerts from all machine groups will be retrieved.

Example:

```https://wdatp-alertexporter-eu.securitycenter.windows.com/api/Alerts/?machinegroups=UKMachines&machinegroups=FranceMachines``` DeviceCreatedMachineTags | string | Single machine tag from the registry. -CloudCreatedMachineTags | string | Machine tags that were created in Windows Defender Security Center. +CloudCreatedMachineTags | string | Machine tags that were created in Microsoft Defender Security Center. ### Request example The following example demonstrates how to retrieve all the alerts in your organization. diff --git a/windows/security/threat-protection/microsoft-defender-atp/rbac.md b/windows/security/threat-protection/microsoft-defender-atp/rbac.md index b5a8ca5ce4..1fa86fd35c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/rbac.md +++ b/windows/security/threat-protection/microsoft-defender-atp/rbac.md @@ -1,5 +1,5 @@ --- -title: Use role-based access control to grant fine-grained access to Windows Defender Security Center +title: Use role-based access control to grant fine-grained access to Microsoft Defender Security Center description: Create roles and groups within your security operations to grant access to the portal. keywords: rbac, role, based, access, control, groups, control, tier, aad search.product: eADQiWindows 10XVcnh @@ -55,12 +55,12 @@ Before using RBAC, it's important that you understand the roles that can grant p > [!WARNING] > Before enabling the feature, it's important that you have a Global Administrator role or Security Administrator role in Azure AD and that you have your Azure AD groups ready to reduce the risk of being locked out of the portal. -When you first log in to Windows Defender Security Center, you're granted either full access or read only access. Full access rights are granted to users with Security Administrator or Global Administrator roles in Azure AD. Read only access is granted to users with a Security Reader role in Azure AD. +When you first log in to Microsoft Defender Security Center, you're granted either full access or read only access. Full access rights are granted to users with Security Administrator or Global Administrator roles in Azure AD. Read only access is granted to users with a Security Reader role in Azure AD. Someone with a Microsoft Defender ATP Global administrator role has unrestricted access to all machines, regardless of their machine group association and the Azure AD user groups assignments > [!WARNING] -> Initially, only those with Azure AD Global Administrator or Security Administrator rights will be able to create and assign roles in Windows Defender Security Center, therefore, having the right groups ready in Azure AD is important. +> Initially, only those with Azure AD Global Administrator or Security Administrator rights will be able to create and assign roles in Microsoft Defender Security Center, therefore, having the right groups ready in Azure AD is important. > > **Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role.** > diff --git a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md index eea36cb084..97e6cbec7e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md @@ -1,5 +1,5 @@ --- -title: Windows Defender Security Center Security operations dashboard +title: Microsoft Defender Security Center Security operations dashboard description: Use the dashboard to identify machines at risk, keep track of the status of the service, and see statistics and information about machines and alerts. keywords: dashboard, alerts, new, in progress, resolved, risk, machines at risk, infections, reporting, statistics, charts, graphs, health, active malware detections, threat category, categories, password stealer, ransomware, exploit, threat, low severity, active malware search.product: eADQiWindows 10XVcnh @@ -18,7 +18,7 @@ ms.topic: conceptual ms.date: 09/04/2018 --- -# Windows Defender Security Center Security operations dashboard +# Microsoft Defender Security Center Security operations dashboard **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) diff --git a/windows/security/threat-protection/microsoft-defender-atp/time-settings.md b/windows/security/threat-protection/microsoft-defender-atp/time-settings.md index a2617401bd..5dcfc7b1e4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/time-settings.md +++ b/windows/security/threat-protection/microsoft-defender-atp/time-settings.md @@ -1,5 +1,5 @@ --- -title: Windows Defender Security Center time zone settings +title: Microsoft Defender Security Center time zone settings description: Use the menu to configure the time zone and view license information. keywords: settings, Windows Defender, cybersecurity threat intelligence, advanced threat protection, time zone, utc, local time, license search.product: eADQiWindows 10XVcnh @@ -18,7 +18,7 @@ ms.topic: article ms.date: 02/13/2018 --- -# Windows Defender Security Center time zone settings +# Microsoft Defender Security Center time zone settings **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md index 01557d7ec5..64c4946662 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages.md @@ -31,11 +31,11 @@ ms.date: 08/01/2018 This page provides detailed steps to troubleshoot issues that might occur when setting up your Microsoft Defender ATP service. -If you receive an error message, Windows Defender Security Center will provide a detailed explanation on what the issue is and relevant links will be supplied. +If you receive an error message, Microsoft Defender Security Center will provide a detailed explanation on what the issue is and relevant links will be supplied. ## No subscriptions found -If while accessing Windows Defender Security Center you get a **No subscriptions found** message, it means the Azure Active Directory (AAD) used to login the user to the portal, does not have a Microsoft Defender ATP license. +If while accessing Microsoft Defender Security Center you get a **No subscriptions found** message, it means the Azure Active Directory (AAD) used to login the user to the portal, does not have a Microsoft Defender ATP license. Potential reasons: - The Windows E5 and Office E5 licenses are separate licenses. @@ -50,7 +50,7 @@ For both cases you should contact Microsoft support at [General Microsoft Defend ## Your subscription has expired -If while accessing Windows Defender Security Center you get a **Your subscription has expired** message, your online service subscription has expired. Microsoft Defender ATP subscription, like any other online service subscription, has an expiration date. +If while accessing Microsoft Defender Security Center you get a **Your subscription has expired** message, your online service subscription has expired. Microsoft Defender ATP subscription, like any other online service subscription, has an expiration date. You can choose to renew or extend the license at any point in time. When accessing the portal after the expiration date a **Your subscription has expired** message will be presented with an option to download the machine offboarding package, should you choose to not renew the license. diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md index 655895b298..b5201a5814 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md @@ -27,7 +27,7 @@ If you encounter a server error when trying to access the service, you’ll need Configure your browser to allow cookies. ## Elements or data missing on the portal -If some UI elements or data is missing on Windows Defender Security Center it’s possible that proxy settings are blocking it. +If some UI elements or data is missing on Microsoft Defender Security Center it’s possible that proxy settings are blocking it. Make sure that `*.securitycenter.windows.com` is included the proxy whitelist. diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md index f8109a93b6..580beea62a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti.md @@ -36,7 +36,7 @@ You can use the code examples to guide you in creating calls to the custom threa Topic | Description :---|:--- [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) | Understand the concepts around threat intelligence so that you can effectively create custom intelligence for your organization. -[Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) | Set up the custom threat intelligence application through Windows Defender Security Center so that you can create custom threat intelligence (TI) using REST API. +[Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) | Set up the custom threat intelligence application through Microsoft Defender Security Center so that you can create custom threat intelligence (TI) using REST API. [Create custom threat intelligence alerts](custom-ti-api-windows-defender-advanced-threat-protection.md) | Create custom threat intelligence alerts so that you can generate specific alerts that are applicable to your organization. [PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md) | Use the PowerShell code examples to guide you in using the custom threat intelligence API. [Python code examples](python-example-code-windows-defender-advanced-threat-protection.md) | Use the Python code examples to guide you in using the custom threat intelligence API. diff --git a/windows/security/threat-protection/microsoft-defender-atp/use.md b/windows/security/threat-protection/microsoft-defender-atp/use.md index 94b1666439..2f1fff7f2e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use.md @@ -1,6 +1,6 @@ --- -title: Overview of Windows Defender Security Center -description: Learn about the features on Windows Defender Security Center, including how alerts work, and suggestions on how to investigate possible breaches and attacks. +title: Overview of Microsoft Defender Security Center +description: Learn about the features on Microsoft Defender Security Center, including how alerts work, and suggestions on how to investigate possible breaches and attacks. keywords: dashboard, alerts queue, manage alerts, investigation, investigate alerts, investigate machines, submit files, deep analysis, high, medium, low, severity, ioc, ioa search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,7 +18,7 @@ ms.topic: conceptual ms.date: 03/12/2018 --- -# Overview of Windows Defender Security Center +# Overview of Microsoft Defender Security Center **Applies to:** @@ -26,7 +26,7 @@ ms.date: 03/12/2018 >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-usewdatp-abovefoldlink) -Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. +Microsoft Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. Use the **Security operations** dashboard to gain insight on the various alerts on machines and users in your network. diff --git a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md index 152c31812c..2c305c28e0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/user-roles.md +++ b/windows/security/threat-protection/microsoft-defender-atp/user-roles.md @@ -26,7 +26,7 @@ ms.topic: article >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-roles-abovefoldlink) ## Create roles and assign the role to an Azure Active Directory group -The following steps guide you on how to create roles in Windows Defender Security Center. It assumes that you have already created Azure Active Directory user groups. +The following steps guide you on how to create roles in Microsoft Defender Security Center. It assumes that you have already created Azure Active Directory user groups. 1. In the navigation pane, select **Settings > Roles**. diff --git a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md index af06ab295c..93ec317ca9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md @@ -55,7 +55,7 @@ The following capabilities are generally available (GA). - [Integration with Azure Security Center](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection#integration-with-azure-security-center)
Microsoft Defender ATP integrates with Azure Security Center to provide a comprehensive server protection solution. With this integration Azure Security Center can leverage the power of Microsoft Defender ATP to provide improved threat detection for Windows Servers. -- [Managed security service provider (MSSP) support](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection)
Microsoft Defender ATP adds support for this scenario by providing MSSP integration. The integration will allow MSSPs to take the following actions: Get access to MSSP customer's Windows Defender Security Center portal, fetch email notifications, and fetch alerts through security information and event management (SIEM) tools. +- [Managed security service provider (MSSP) support](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection)
Microsoft Defender ATP adds support for this scenario by providing MSSP integration. The integration will allow MSSPs to take the following actions: Get access to MSSP customer's Microsoft Defender Security Center portal, fetch email notifications, and fetch alerts through security information and event management (SIEM) tools. - [Removable device control](https://cloudblogs.microsoft.com/microsoftsecure/2018/12/19/windows-defender-atp-has-protections-for-usb-and-removable-devices/)
Microsoft Defender ATP provides multiple monitoring and control features to help prevent threats from removable devices, including new settings to allow or block specific hardware IDs. @@ -123,7 +123,7 @@ Query data using Advanced hunting in Microsoft Defender ATP. You can now block untrusted processes from writing to disk sectors using Controlled Folder Access. - [Onboard non-Windows machines](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection)
- Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Windows Defender Security Center and better protect your organization's network. + Microsoft Defender ATP provides a centralized security operations experience for Windows as well as non-Windows platforms. You'll be able to see alerts from various supported operating systems (OS) in Microsoft Defender Security Center and better protect your organization's network. - [Role-based access control (RBAC)](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection)
Using role-based access control (RBAC), you can create roles and groups within your security operations team to grant appropriate access to the portal. diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md index 468fcd0924..af2106bf2b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md @@ -1,6 +1,6 @@ --- -title: Windows Defender Security Center -description: Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection. +title: Microsoft Defender Security Center +description: Microsoft Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection. keywords: windows, defender, security, center, defender, advanced, threat, protection search.product: eADQiWindows 10XVcnh search.appverid: met150 @@ -18,9 +18,9 @@ ms.topic: conceptual ms.date: 07/01/2018 --- -# Windows Defender Security Center +# Microsoft Defender Security Center -Windows Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. It gives enterprise security operations teams a single pane of glass experience to help secure networks. +Microsoft Defender Security Center is the portal where you can access Microsoft Defender Advanced Threat Protection capabilities. It gives enterprise security operations teams a single pane of glass experience to help secure networks. ## In this section @@ -30,10 +30,10 @@ Get started | Learn about the minimum requirements, validate licensing and com [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) | Learn about onboarding client, server, and non-Windows machines. Learn how to run a detection test, configure proxy and Internet connectivity settings, and how to troubleshoot potential onboarding issues. [Understand the portal](use-windows-defender-advanced-threat-protection.md) | Understand the Security operations, Secure Score, and Threat analytics dashboards as well as how to navigate the portal. Investigate and remediate threats | Investigate alerts, machines, and take response actions to remediate threats. -API and SIEM support | Use the supported APIs to pull and create custom alerts, or automate workflows. Use the supported SIEM tools to pull alerts from Windows Defender Security Center. +API and SIEM support | Use the supported APIs to pull and create custom alerts, or automate workflows. Use the supported SIEM tools to pull alerts from Microsoft Defender Security Center. Reporting | Create and build Power BI reports using Microsoft Defender ATP data. Check service health and sensor state | Verify that the service is running and check the sensor state on machines. -[Configure Windows Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. +[Configure Microsoft Defender Security Center settings](preferences-setup-windows-defender-advanced-threat-protection.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. [Access the Microsoft Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md) | Access the Microsoft Defender ATP Community Center to learn, collaborate, and share experiences about the product. [Troubleshoot service issues](troubleshoot-windows-defender-advanced-threat-protection.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. From e52b3e7a87d8aac6cdf30d2503eb15b104106e10 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:04:55 -0700 Subject: [PATCH 131/737] remove -wdatp from within file links --- .../add-or-remove-machine-tags.md | 4 +- .../advanced-features.md | 12 +++--- .../advanced-hunting-reference.md | 4 +- .../advanced-hunting.md | 4 +- ...lerts-queue-endpoint-detection-response.md | 16 +++---- .../microsoft-defender-atp/alerts-queue.md | 16 +++---- .../api-portal-mapping.md | 12 +++--- .../assign-portal-access.md | 6 +-- .../attack-simulations.md | 6 +-- .../automated-investigations.md | 4 +- .../basic-permissions.md | 4 +- .../check-sensor-status.md | 4 +- .../collect-investigation-package.md | 4 +- .../microsoft-defender-atp/conditional.md | 4 +- .../configure-arcsight.md | 12 +++--- .../configure-email-notifications.md | 12 +++--- .../configure-endpoints-gp.md | 14 +++---- .../configure-endpoints-mdm.md | 14 +++---- .../configure-endpoints-non-windows.md | 8 ++-- .../configure-endpoints-sccm.md | 16 +++---- .../configure-endpoints-script.md | 20 ++++----- .../configure-endpoints-vdi.md | 10 ++--- .../configure-endpoints.md | 10 ++--- .../configure-mssp-support.md | 18 ++++---- .../configure-proxy-internet.md | 4 +- .../configure-server-endpoints.md | 16 +++---- .../microsoft-defender-atp/configure-siem.md | 22 +++++----- .../configure-splunk.md | 12 +++--- .../create-alert-by-reference.md | 4 +- .../microsoft-defender-atp/custom-ti-api.md | 20 ++++----- .../data-retention-settings.md | 10 ++--- .../enable-custom-ti.md | 14 +++---- .../enable-secure-score.md | 10 ++--- .../enable-siem-integration.md | 12 +++--- .../event-error-codes.md | 42 +++++++++---------- .../experiment-custom-ti.md | 16 +++---- .../exposed-apis-create-app-nativeapp.md | 2 +- .../find-machines-by-ip.md | 4 +- .../fix-unhealhty-sensors.md | 14 +++---- .../get-alert-info-by-id.md | 4 +- .../get-alert-related-domain-info.md | 4 +- .../get-alert-related-files-info.md | 4 +- .../get-alert-related-ip-info.md | 4 +- .../get-alert-related-machine-info.md | 4 +- .../get-alert-related-user-info.md | 4 +- .../microsoft-defender-atp/get-alerts.md | 4 +- .../get-domain-related-alerts.md | 4 +- .../get-domain-related-machines.md | 4 +- .../get-domain-statistics.md | 2 +- .../get-file-information.md | 2 +- .../get-file-related-alerts.md | 4 +- .../get-file-related-machines.md | 4 +- .../get-file-statistics.md | 2 +- .../get-ip-related-alerts.md | 4 +- .../get-ip-related-machines.md | 4 +- .../get-ip-statistics.md | 2 +- .../get-machine-by-id.md | 4 +- .../get-machine-log-on-users.md | 4 +- .../get-machine-related-alerts.md | 4 +- .../get-machineaction-object.md | 2 +- .../get-machineactions-collection.md | 2 +- .../microsoft-defender-atp/get-machines.md | 4 +- .../get-package-sas-uri.md | 4 +- .../microsoft-defender-atp/get-started.md | 12 +++--- .../get-user-related-alerts.md | 4 +- .../get-user-related-machines.md | 4 +- .../microsoft-defender-atp/incidents-queue.md | 4 +- ...ormation-protection-in-windows-overview.md | 2 +- .../initiate-autoir-investigation.md | 8 ++-- .../investigate-alerts.md | 18 ++++---- .../investigate-domain.md | 14 +++---- .../investigate-files.md | 18 ++++---- .../investigate-incidents.md | 6 +-- .../microsoft-defender-atp/investigate-ip.md | 14 +++---- .../investigate-machines.md | 30 ++++++------- .../investigate-user.md | 18 ++++---- .../is-domain-seen-in-org.md | 2 +- .../microsoft-defender-atp/is-ip-seen-org.md | 2 +- .../microsoft-defender-atp/isolate-machine.md | 6 +-- .../microsoft-defender-atp/licensing.md | 6 +-- .../microsoft-defender-atp/machine-groups.md | 10 ++--- .../microsoft-defender-atp/machine-reports.md | 2 +- .../microsoft-defender-atp/machine-tags.md | 4 +- .../machineactionsnote.md | 2 +- .../machines-view-overview.md | 6 +-- .../microsoft-defender-atp/manage-alerts.md | 18 ++++---- .../manage-allowed-blocked-list.md | 2 +- .../manage-auto-investigation.md | 2 +- .../manage-automation-allowed-blocked-list.md | 6 +-- .../manage-automation-file-uploads.md | 4 +- .../manage-automation-folder-exclusions.md | 4 +- .../microsoft-defender-atp/manage-edr.md | 6 +-- .../manage-incidents.md | 2 +- .../manage-suppression-rules.md | 4 +- .../microsoft-defender-atp/management-apis.md | 10 ++--- ...oft-defender-advanced-threat-protection.md | 4 +- .../minimum-requirements.md | 4 +- .../microsoft-defender-atp/mssp-support.md | 2 +- .../offboard-machine-api.md | 2 +- .../offboard-machines.md | 12 +++--- .../onboard-configure.md | 22 +++++----- .../onboard-downlevel.md | 4 +- .../microsoft-defender-atp/onboard.md | 4 +- .../overview-endpoint-detection-response.md | 8 ++-- .../overview-hunting.md | 2 +- .../overview-secure-score.md | 6 +-- .../microsoft-defender-atp/overview.md | 8 ++-- .../microsoft-defender-atp/portal-overview.md | 8 ++-- .../powershell-example-code.md | 12 +++--- .../preview-settings.md | 12 +++--- .../pull-alerts-using-rest-api.md | 12 +++--- .../python-example-code.md | 12 +++--- .../microsoft-defender-atp/rbac.md | 4 +- .../respond-file-alerts.md | 4 +- .../respond-machine-alerts.md | 2 +- .../response-actions.md | 4 +- .../restrict-code-execution.md | 6 +-- .../run-advanced-query-api.md | 4 +- .../microsoft-defender-atp/run-av-scan.md | 4 +- .../run-detection-test.md | 4 +- .../secure-score-dashboard.md | 12 +++--- .../security-operations-dashboard.md | 22 +++++----- .../microsoft-defender-atp/service-status.md | 2 +- .../stop-and-quarantine-file.md | 4 +- .../threat-analytics.md | 2 +- .../threat-indicator-concepts.md | 14 +++---- .../threat-protection-integration.md | 2 +- .../threat-protection-reports.md | 2 +- .../troubleshoot-custom-ti.md | 12 +++--- .../troubleshoot-onboarding-error-messages.md | 2 +- .../troubleshoot-onboarding.md | 32 +++++++------- .../troubleshoot-siem.md | 10 ++--- .../microsoft-defender-atp/troubleshoot.md | 8 ++-- .../unisolate-machine.md | 4 +- .../unrestrict-code-execution.md | 4 +- .../microsoft-defender-atp/update-alert.md | 4 +- .../microsoft-defender-atp/use-custom-ti.md | 14 +++---- .../microsoft-defender-atp/use.md | 8 ++-- .../microsoft-defender-atp/user-roles.md | 4 +- .../view-incidents-queue.md | 4 +- .../whats-new-in-microsoft-defender-atp.md | 2 +- .../windows-defender-security-center-atp.md | 10 ++--- 142 files changed, 557 insertions(+), 557 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md index 106306a8c5..045be04e37 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md +++ b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md @@ -36,8 +36,8 @@ Delegated (work or school account) | Machine.ReadWrite | 'Read and write machine >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Manage security setting' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Manage security setting' (See [Create and manage roles](user-roles.md) for more information) +>- User needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md index dee0d64ec2..a16aebe6e6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-features.md @@ -29,7 +29,7 @@ Depending on the Microsoft security products that you use, some advanced feature Use the following advanced features to get better protected from potentially malicious files and gain better insight during security investigations: ## Automated investigation -When you enable this feature, you'll be able to take advantage of the automated investigation and remediation features of the service. For more information, see [Automated investigations](automated-investigations-windows-defender-advanced-threat-protection.md). +When you enable this feature, you'll be able to take advantage of the automated investigation and remediation features of the service. For more information, see [Automated investigations](automated-investigations.md). ## Auto-resolve remediated alerts For tenants created on or after Windows 10, version 1809 the automated investigations capability is configured by default to resolve alerts where the automated analysis result status is "No threats found" or "Remediated". If you don’t want to have alerts auto-resolved, you’ll need to manually turn off the feature. @@ -53,7 +53,7 @@ When you enable this feature, you'll be able to see user details stored in Azure - Alert queue - Machine details page -For more information, see [Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md). +For more information, see [Investigate a user account](investigate-user.md). ## Skype for Business integration Enabling the Skype for Business integration gives you the ability to communicate with users using Skype for Business, email, or phone. This can be handy when you need to communicate with the user and mitigate risks. @@ -128,7 +128,7 @@ You'll have access to upcoming features which you can provide feedback on to hel 3. Click **Save preferences**. ## Related topics -- [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md) -- [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) -- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md) -- [Enable Secure Score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md) +- [Update data retention settings](data-retention-settings.md) +- [Configure alert notifications](configure-email-notifications.md) +- [Enable and create Power BI reports using Microsoft Defender ATP data](powerbi-reports.md) +- [Enable Secure Score security controls](enable-secure-score.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md index fe8f545929..e05cf85951 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference.md @@ -118,5 +118,5 @@ To effectively build queries that span multiple tables, you need to understand t >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-belowfoldlink) ## Related topic -- [Query data using Advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md) -- [Advanced hunting query language best practices](advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Query data using Advanced hunting](advanced-hunting.md) +- [Advanced hunting query language best practices](advanced-hunting-best-practices.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md index 000918bc98..44e20add28 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md +++ b/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting.md @@ -149,8 +149,8 @@ Check out the [Advanced hunting repository](https://github.com/Microsoft/Windows >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-belowfoldlink) ## Related topic -- [Advanced hunting reference](advanced-hunting-reference-windows-defender-advanced-threat-protection.md) -- [Advanced hunting query language best practices](advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md) +- [Advanced hunting reference](advanced-hunting-reference.md) +- [Advanced hunting query language best practices](advanced-hunting-best-practices.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md index 525a4afacb..1e817593bb 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue-endpoint-detection-response.md @@ -25,13 +25,13 @@ Learn how you can view and manage the queue so that you can effectively investig ## In this section Topic | Description :---|:--- -[View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md) | Shows a list of alerts that were flagged in your network. -[Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) | Learn about how you can manage alerts such as change its status, assign it to a security operations member, and see the history of an alert. -[Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md)| Investigate alerts that are affecting your network, understand what they mean, and how to resolve them. -[Investigate files](investigate-files-windows-defender-advanced-threat-protection.md)| Investigate the details of a file associated with a specific alert, behaviour, or event. -[Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md)| Investigate the details of a machine associated with a specific alert, behaviour, or event. -[Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md) | Examine possible communication between machines in your network and external internet protocol (IP) addresses. -[Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md) | Investigate a domain to see if machines and servers in your network have been communicating with a known malicious domain. -[Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md) | Identify user accounts with the most active alerts and investigate cases of potential compromised credentials. +[View and organize the Alerts queue](alerts-queue.md) | Shows a list of alerts that were flagged in your network. +[Manage alerts](manage-alerts.md) | Learn about how you can manage alerts such as change its status, assign it to a security operations member, and see the history of an alert. +[Investigate alerts](investigate-alerts.md)| Investigate alerts that are affecting your network, understand what they mean, and how to resolve them. +[Investigate files](investigate-files.md)| Investigate the details of a file associated with a specific alert, behaviour, or event. +[Investigate machines](investigate-machines.md)| Investigate the details of a machine associated with a specific alert, behaviour, or event. +[Investigate an IP address](investigate-ip.md) | Examine possible communication between machines in your network and external internet protocol (IP) addresses. +[Investigate a domain](investigate-domain.md) | Investigate a domain to see if machines and servers in your network have been communicating with a known malicious domain. +[Investigate a user account](investigate-user.md) | Identify user accounts with the most active alerts and investigate cases of potential compromised credentials. diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md index 86249293b6..fbe92937d8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md @@ -90,15 +90,15 @@ Limit the alerts queue view by selecting the OS platform that you're interested If you have specific machine groups that you're interested in checking the alerts on, you can select the groups to limit the alerts queue view to display just those machine groups. ### Associated threat -Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md). +Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics-dashboard.md). ## Related topics -- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files-windows-defender-advanced-threat-protection.md) -- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines-windows-defender-advanced-threat-protection.md) -- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip-windows-defender-advanced-threat-protection.md) -- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain-windows-defender-advanced-threat-protection.md) -- [Investigate a user account in Microsoft Defender ATP](investigate-user-windows-defender-advanced-threat-protection.md) +- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md) +- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md) +- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md) +- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md) +- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md) +- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md) +- [Investigate a user account in Microsoft Defender ATP](investigate-user.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md index c85f9de2b6..054edf688a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md +++ b/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping.md @@ -37,7 +37,7 @@ Understand what data fields are exposed as part of the alerts API and how they m The following table lists the available fields exposed in the alerts API payload. It shows examples for the populated values and a reference on how data is reflected on the portal. -The ArcSight field column contains the default mapping between the Microsoft Defender ATP fields and the built-in fields in ArcSight. You can download the mapping file from the portal when you enable the SIEM integration feature and you can modify it to match the needs of your organization. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +The ArcSight field column contains the default mapping between the Microsoft Defender ATP fields and the built-in fields in ArcSight. You can download the mapping file from the portal when you enable the SIEM integration feature and you can modify it to match the needs of your organization. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md). Field numbers match the numbers in the images below. @@ -92,8 +92,8 @@ Field numbers match the numbers in the images below. ## Related topics -- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md) -- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md) -- [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md) +- [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md) +- [Configure Splunk to pull Microsoft Defender ATP alerts](configure-splunk.md) +- [Configure ArcSight to pull Microsoft Defender ATP alerts](configure-arcsight.md) +- [Pull Microsoft Defender ATP alerts using REST API](pull-alerts-using-rest-api.md) +- [Troubleshoot SIEM tool integration issues](troubleshoot-siem.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md index b1cb1f4d55..484e346117 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md +++ b/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access.md @@ -30,7 +30,7 @@ ms.date: 11/28/2018 Microsoft Defender ATP supports two ways to manage permissions: - **Basic permissions management**: Set permissions to either full access or read-only. -- **Role-based access control (RBAC)**: Set granular permissions by defining roles, assigning Azure AD user groups to the roles, and granting the user groups access to machine groups. For more information on RBAC, see [Manage portal access using role-based access control](rbac-windows-defender-advanced-threat-protection.md). +- **Role-based access control (RBAC)**: Set granular permissions by defining roles, assigning Azure AD user groups to the roles, and granting the user groups access to machine groups. For more information on RBAC, see [Manage portal access using role-based access control](rbac.md). > [!NOTE] >If you have already assigned basic permissions, you may switch to RBAC anytime. Consider the following before making the switch: @@ -44,5 +44,5 @@ Microsoft Defender ATP supports two ways to manage permissions: >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-portalaccess-belowfoldlink) ## Related topic -- [Use basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) -- [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md) +- [Use basic permissions to access the portal](basic-permissions.md) +- [Manage portal access using RBAC](rbac.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md index 9b4ee1c082..f88df725ea 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/attack-simulations.md @@ -38,7 +38,7 @@ You might want to experience Microsoft Defender ATP before you onboard more than ## Before you begin -To run any of the provided simulations, you need at least [one onboarded machine](onboard-configure-windows-defender-advanced-threat-protection.md). +To run any of the provided simulations, you need at least [one onboarded machine](onboard-configure.md). Read the walkthrough document provided with each attack scenario. Each document includes OS and application requirements as well as detailed instructions that are specific to an attack scenario. @@ -66,5 +66,5 @@ Read the walkthrough document provided with each attack scenario. Each document ## Related topics -- [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md) -- [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Onboard machines](onboard-configure.md) +- [Onboard Windows 10 machines](configure-endpoints.md) \ No newline at end of file diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index 78375524ed..a413656b87 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -73,14 +73,14 @@ Semi - require approval for non-temp folders remediation | An approval is requir Semi - require approval for core folders remediation | An approval is required on files or executables that are in the operating system directories such as Windows folder and Program files folder.

Files or executables in all other folders will automatically be remediated if needed. Full - remediate threats automatically | All remediation actions will be performed automatically. -For more information on how to configure these automation levels, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). +For more information on how to configure these automation levels, see [Create and manage machine groups](machine-groups.md). The default machine group is configured for semi-automatic remediation. This means that any malicious entity that needs to be remediated requires an approval and the investigation is added to the **Pending actions** section, this can be changed to fully automatic so that no user approval is needed. When a pending action is approved, the entity is then remediated and this new state is reflected in the **Entities** tab of the investigation. ## Related topic -- [Learn about the automated investigations dashboard](manage-auto-investigation-windows-defender-advanced-threat-protection.md) +- [Learn about the automated investigations dashboard](manage-auto-investigation.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md index c7f6f4517c..294a775bb9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md +++ b/windows/security/threat-protection/microsoft-defender-atp/basic-permissions.md @@ -31,7 +31,7 @@ You can use either of the following: - Azure PowerShell - Azure Portal -For granular control over permissions, [switch to role-based access control](rbac-windows-defender-advanced-threat-protection.md). +For granular control over permissions, [switch to role-based access control](rbac.md). ## Assign user access using Azure PowerShell You can assign users with one of the following levels of permissions: @@ -73,4 +73,4 @@ For more information, see [Assign administrator and non-administrator roles to u ## Related topic -- [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md) +- [Manage portal access using RBAC](rbac.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md index 453a7575ed..4e675729c2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md +++ b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md @@ -37,7 +37,7 @@ There are two status indicators on the tile that provide information on the numb Clicking any of the groups directs you to Machines list, filtered according to your choice. -You can also download the entire list in CSV format using the **Export to CSV** feature. For more information on filters, see [View and organize the Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md). +You can also download the entire list in CSV format using the **Export to CSV** feature. For more information on filters, see [View and organize the Machines list](machines-view-overview.md). You can filter the health state list by the following status: - **Active** - Machines that are actively reporting to the Microsoft Defender ATP service. @@ -57,4 +57,4 @@ In the **Machines list**, you can download a full list of all the machines in yo >Export the list in CSV format to display the unfiltered data. The CSV file will include all machines in the organization, regardless of any filtering applied in the view itself and can take a significant amount of time to download, depending on how large your organization is. ## Related topic -- [Fix unhealthy sensors in Microsoft Defender ATP](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) +- [Fix unhealthy sensors in Microsoft Defender ATP](fix-unhealhty-sensors.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md index 133ce6e86c..c828e5a9b8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md +++ b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md @@ -37,8 +37,8 @@ Delegated (work or school account) | Machine.CollectForensics | 'Collect forensi >[!Note] > When obtaining a token using user credentials: ->- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles-windows-defender-advanced-threat-protection.md) for more information) ->- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) for more information) +>- The user needs to have at least the following role permission: 'Alerts Investigation' (See [Create and manage roles](user-roles.md) for more information) +>- The user needs to have access to the machine, based on machine group settings (See [Create and manage machine groups](machine-groups.md) for more information) ## HTTP request ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/conditional.md b/windows/security/threat-protection/microsoft-defender-atp/conditional.md index eba91e7d07..f4a0532ef7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/conditional.md +++ b/windows/security/threat-protection/microsoft-defender-atp/conditional.md @@ -56,7 +56,7 @@ There are three ways to address a risk: 2. Resolve active alerts on the machine. This will remove the risk from the machine. 3. You can remove the machine from the active policies and consequently, conditional access will not be applied on the machine. -Manual remediation requires a secops admin to investigate an alert and address the risk seen on the device. The automated remediation is configured through configuration settings provided in the following section, [Configure conditional access](configure-conditional-access-windows-defender-advanced-threat-protection.md). +Manual remediation requires a secops admin to investigate an alert and address the risk seen on the device. The automated remediation is configured through configuration settings provided in the following section, [Configure conditional access](configure-conditional-access.md). When the risk is removed either through manual or automated remediation, the device returns to a compliant state and access to applications is granted. @@ -70,7 +70,7 @@ The following example sequence of events explains conditional access in action: ## Related topic -- [Configure conditional access in Microsoft Defender ATP](configure-conditional-access-windows-defender-advanced-threat-protection.md) +- [Configure conditional access in Microsoft Defender ATP](configure-conditional-access.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md index 05c9269bca..862e906979 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight.md @@ -36,7 +36,7 @@ Configuring the HP ArcSight Connector tool requires several configuration files This section guides you in getting the necessary information to set and use the required configuration files correctly. -- Make sure you have enabled the SIEM integration feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md). +- Make sure you have enabled the SIEM integration feature from the **Settings** menu. For more information, see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md). - Have the file you saved from enabling the SIEM integration feature ready. You'll need to get the following values: - OAuth 2.0 Token refresh URL @@ -107,7 +107,7 @@ The following steps assume that you have completed all the required steps in [Be
Browse to the location of the *wdatp-connector.properties* file. The name must match the file provided in the .zip that you downloaded.
Refresh TokenYou can obtain a refresh token in two ways: by generating a refresh token from the **SIEM settings** page or using the restutil tool.

For more information on generating a refresh token from the **Preferences setup** , see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md).

**Get your refresh token using the restutil tool:**
a. Open a command prompt. Navigate to C:\\*folder_location*\current\bin where *folder_location* represents the location where you installed the tool.

b. Type: `arcsight restutil token -config` from the bin directory.For example: **arcsight restutil boxtoken -proxy proxy.location.hp.com:8080** A Web browser window will open.

c. Type in your credentials then click on the password field to let the page redirect. In the login prompt, enter your credentials.

d. A refresh token is shown in the command prompt.

e. Copy and paste it into the **Refresh Token** field. +
You can obtain a refresh token in two ways: by generating a refresh token from the **SIEM settings** page or using the restutil tool.

For more information on generating a refresh token from the **Preferences setup** , see [Enable SIEM integration in Microsoft Defender ATP](enable-siem-integration.md).

**Get your refresh token using the restutil tool:**
a. Open a command prompt. Navigate to C:\\*folder_location*\current\bin where *folder_location* represents the location where you installed the tool.

b. Type: `arcsight restutil token -config` from the bin directory.For example: **arcsight restutil boxtoken -proxy proxy.location.hp.com:8080** A Web browser window will open.

c. Type in your credentials then click on the password field to let the page redirect. In the login prompt, enter your credentials.

d. A refresh token is shown in the command prompt.

e. Copy and paste it into the **Refresh Token** field.
Microsoft Defender Advanced Threat Protection service failed to connect to the server at ```variable```. Variable = URL of the Microsoft Defender ATP processing servers.
The service could not contact the external processing servers at that URL.
Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet-windows-defender-advanced-threat-protection.md).Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet.md).
6 The machine did not onboard correctly and will not be reporting to the portal. Onboarding must be run before starting the service.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
7 Microsoft Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: ```variable```. Variable = detailed error description. The machine did not onboard correctly and will not be reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
8**During onboarding:** The service failed to clean its configuration during the onboarding. The onboarding process continues.

**During offboarding:** The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running.
**Onboarding:** No action required.

**Offboarding:** Reboot the system.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
9 Microsoft Defender Advanced Threat Protection service failed to change its start type. Failure code: ```variable```. **During onboarding:** The machine did not onboard correctly and will not be reporting to the portal.

**During offboarding:** Failed to change the service start type. The offboarding process continues.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
10 Microsoft Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: ```variable```. The machine did not onboard correctly and will not be reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
11 Microsoft Defender Advanced Threat Protection cannot start command channel with URL: ```variable```. Variable = URL of the Microsoft Defender ATP processing servers.
The service could not contact the external processing servers at that URL.
Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet-windows-defender-advanced-threat-protection.md).Check the connection to the URL. See [Configure proxy and Internet connectivity](configure-proxy-internet.md).
17 Microsoft Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: ```variable```. An error occurred with the Windows telemetry service.[Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostics-service-is-enabled).
+
[Ensure the diagnostic data service is enabled](troubleshoot-onboarding.md#ensure-the-diagnostics-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
18The machine did not onboard correctly. It will report to the portal, however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
26The machine did not onboard correctly.
It will report to the portal, however the service may not appear as registered in SCCM or the registry.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
27 Microsoft Defender Advanced Threat Protection service failed to enable SENSE aware mode in Windows Defender Antivirus. Onboarding process failed. Failure code: ```variable```. Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Microsoft Defender ATP. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
+See [Onboard Windows 10 machines](configure-endpoints.md).
Ensure real-time antimalware protection is running properly.
28 Microsoft Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration failed. Failure code: ```variable```. An error occurred with the Windows telemetry service.[Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled).
+
[Ensure the diagnostic data service is enabled](troubleshoot-onboarding.md#ensure-the-diagnostic-data-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
29Microsoft Defender Advanced Threat Protection service failed to disable SENSE aware mode in Windows Defender Antivirus. Failure code: ```variable```. Normally, Windows Defender Antivirus will enter a special passive state if another real-time antimalware product is running properly on the machine, and the machine is reporting to Microsoft Defender ATP. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md)
+See [Onboard Windows 10 machines](configure-endpoints.md)
Ensure real-time antimalware protection is running properly.
31 Microsoft Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: ```variable```. An error occurred with the Windows telemetry service during onboarding. The offboarding process continues.[Check for errors with the Windows telemetry service](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled).[Check for errors with the Windows telemetry service](troubleshoot-onboarding.md#ensure-the-diagnostic-data-service-is-enabled).
3234 Microsoft Defender Advanced Threat Protection service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: ```variable```. An error occurred with the Windows telemetry service.[Ensure the diagnostic data service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-the-diagnostic-data-service-is-enabled).
+
[Ensure the diagnostic data service is enabled](troubleshoot-onboarding.md#ensure-the-diagnostic-data-service-is-enabled).
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
35
@@ -37,10 +37,10 @@ ms.localizationpriority: medium -**[Attack surface reduction](windows-defender-atp/overview-attack-surface-reduction.md)**
+**[Attack surface reduction](microsoft-defender-atp/overview-attack-surface-reduction.md)**
The attack surface reduction set of capabilities provide the first line of defense in the stack. By ensuring configuration settings are properly set and exploit mitigation techniques are applied, these set of capabilities resist attacks and exploitations. -- [Hardware based isolation](windows-defender-atp/overview-hardware-based-isolation.md) +- [Hardware based isolation](microsoft-defender-atp/overview-hardware-based-isolation.md) - [Application control](windows-defender-application-control/windows-defender-application-control.md) - [Device control](device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md) - [Exploit protection](windows-defender-exploit-guard/exploit-protection-exploit-guard.md) @@ -52,7 +52,7 @@ The attack surface reduction set of capabilities provide the first line of defen **[Next generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md)**
-To further reinforce the security perimeter of your network, Windows Defender ATP uses next generation protection designed to catch all types of emerging threats. +To further reinforce the security perimeter of your network, Microsoft Defender ATP uses next generation protection designed to catch all types of emerging threats. - [Behavior monitoring](/windows/security/threat-protection/windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus) - [Cloud-based protection](/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus) @@ -62,67 +62,67 @@ To further reinforce the security perimeter of your network, Windows Defender AT -**[Endpoint detection and response](windows-defender-atp/overview-endpoint-detection-response.md)**
+**[Endpoint detection and response](microsoft-defender-atp/overview-endpoint-detection-response.md)**
Endpoint detection and response capabilities are put in place to detect, investigate, and respond to advanced threats that may have made it past the first two security pillars. -- [Alerts](windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md) -- [Historical endpoint data](windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline) -- [Response orchestration](windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md) -- [Forensic collection](windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines) -- [Threat intelligence](windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -- [Advanced detonation and analysis service](windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) -- [Advanced hunting](windows-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md) - - [Custom detection](windows-defender-atp/overview-custom-detections.md) - - [Realtime and historical hunting](windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md) +- [Alerts](microsoft-defender-atp/alerts-queue.md) +- [Historical endpoint data](microsoft-defender-atp/investigate-machines.md#machine-timeline) +- [Response orchestration](microsoft-defender-atp/response-actions.md) +- [Forensic collection](microsoft-defender-atp/respond-machine-alerts.md#collect-investigation-package-from-machines) +- [Threat intelligence](microsoft-defender-atp/threat-indicator-concepts.md) +- [Advanced detonation and analysis service](microsoft-defender-atp/respond-file-alerts.md#deep-analysis) +- [Advanced hunting](microsoft-defender-atp/overview-hunting.md) + - [Custom detection](microsoft-defender-atp/overview-custom-detections.md) + - [Realtime and historical hunting](microsoft-defender-atp/advanced-hunting.md) -**[Automated investigation and remediation](windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md)**
-In conjunction with being able to quickly respond to advanced attacks, Windows Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. +**[Automated investigation and remediation](microsoft-defender-atp/automated-investigations.md)**
+In conjunction with being able to quickly respond to advanced attacks, Microsoft Defender ATP offers automatic investigation and remediation capabilities that help reduce the volume of alerts in minutes at scale. -- [Automated investigation and remediation](windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md) -- [Threat remediation](windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md#how-threats-are-remediated) -- [Manage automated investigations](windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md) -- [Analyze automated investigation](windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md#analyze-automated-investigations) +- [Automated investigation and remediation](microsoft-defender-atp/automated-investigations.md) +- [Threat remediation](microsoft-defender-atp/automated-investigations.md#how-threats-are-remediated) +- [Manage automated investigations](microsoft-defender-atp/manage-auto-investigation.md) +- [Analyze automated investigation](microsoft-defender-atp/manage-auto-investigation.md#analyze-automated-investigations) -**[Secure score](windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md)**
-Windows Defender ATP includes a secure score to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security of your organization. -- [Asset inventory](windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [Recommended improvement actions](windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md) -- [Secure score](windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md) -- [Threat analytics](windows-defender-atp/threat-analytics-dashboard-windows-defender-advanced-threat-protection.md) +**[Secure score](microsoft-defender-atp/overview-secure-score.md)**
+Microsoft Defender ATP includes a secure score to help you dynamically assess the security state of your enterprise network, identify unprotected systems, and take recommended actions to improve the overall security of your organization. +- [Asset inventory](microsoft-defender-atp/secure-score-dashboard.md) +- [Recommended improvement actions](microsoft-defender-atp/secure-score-dashboard.md) +- [Secure score](microsoft-defender-atp/overview-secure-score.md) +- [Threat analytics](microsoft-defender-atp/threat-analytics.md) -**[Microsoft Threat Experts](windows-defender-atp/microsoft-threat-experts.md)**
-Windows Defender ATP's new managed threat hunting service provides proactive hunting, prioritization and additional context and insights that further empower Security Operation Centers (SOCs) to identify and respond to threats quickly and accurately. +**[Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md)**
+Microsoft Defender ATP's new managed threat hunting service provides proactive hunting, prioritization and additional context and insights that further empower Security Operation Centers (SOCs) to identify and respond to threats quickly and accurately. -- [Targeted attack notification](windows-defender-atp/microsoft-threat-experts.md) -- [Experts-on-demand](windows-defender-atp/microsoft-threat-experts.md) -- [Configure your Microsoft Threat Protection managed hunting service](windows-defender-atp/configure-microsoft-threat-experts.md) +- [Targeted attack notification](microsoft-defender-atp/microsoft-threat-experts.md) +- [Experts-on-demand](microsoft-defender-atp/microsoft-threat-experts.md) +- [Configure your Microsoft Threat Protection managed hunting service](microsoft-defender-atp/configure-microsoft-threat-experts.md) -**[Management and APIs](windows-defender-atp/management-apis.md)**
-Integrate Windows Defender Advanced Threat Protection into your existing workflows. -- [Onboarding](windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md) -- [API and SIEM integration](windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md) -- [Exposed APIs](windows-defender-atp/use-apis.md) -- [Role-based access control (RBAC)](windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md) -- [Reporting and trends](windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md) +**[Management and APIs](microsoft-defender-atp/management-apis.md)**
+Integrate Microsoft Defender Advanced Threat Protection into your existing workflows. +- [Onboarding](microsoft-defender-atp/onboard-configure.md) +- [API and SIEM integration](microsoft-defender-atp/configure-siem.md) +- [Exposed APIs](microsoft-defender-atp/use-apis.md) +- [Role-based access control (RBAC)](microsoft-defender-atp/rbac.md) +- [Reporting and trends](microsoft-defender-atp/powerbi-reports.md) -**[Microsoft Threat Protection](windows-defender-atp/threat-protection-integration.md)**
- Windows Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. Bring the power of Microsoft threat protection to your organization. -- [Conditional access](windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md) -- [O365 ATP](windows-defender-atp/threat-protection-integration.md) -- [Azure ATP](windows-defender-atp/threat-protection-integration.md) -- [Azure Security Center](windows-defender-atp/threat-protection-integration.md) -- [Skype for Business](windows-defender-atp/threat-protection-integration.md) -- [Microsoft Cloud App Security](windows-defender-atp/microsoft-cloud-app-security-integration.md) +**[Microsoft Threat Protection](microsoft-defender-atp/threat-protection-integration.md)**
+ Microsoft Defender ATP is part of the Microsoft Threat Protection solution that helps implement end-to-end security across possible attack surfaces in the modern workplace. Bring the power of Microsoft threat protection to your organization. +- [Conditional access](microsoft-defender-atp/conditional-access.md) +- [O365 ATP](microsoft-defender-atp/threat-protection-integration.md) +- [Azure ATP](microsoft-defender-atp/threat-protection-integration.md) +- [Azure Security Center](microsoft-defender-atp/threat-protection-integration.md) +- [Skype for Business](microsoft-defender-atp/threat-protection-integration.md) +- [Microsoft Cloud App Security](microsoft-defender-atp/microsoft-cloud-app-security-integration.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/conditional.md b/windows/security/threat-protection/microsoft-defender-atp/conditional-access.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/conditional.md rename to windows/security/threat-protection/microsoft-defender-atp/conditional-access.md From fd2e2b3287897bc4622292e6faea5130824c28ef Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:25:22 -0700 Subject: [PATCH 133/737] update author and product names in exploit guard folder --- .../attack-surface-reduction-exploit-guard.md | 10 +++++----- ...eduction-rules-in-windows-10-enterprise-e3.md | 6 +++--- .../audit-windows-defender-exploit-guard.md | 12 ++++++------ .../controlled-folders-exploit-guard.md | 14 +++++++------- .../customize-attack-surface-reduction.md | 6 +++--- ...customize-controlled-folders-exploit-guard.md | 6 +++--- .../customize-exploit-protection.md | 6 +++--- .../emet-exploit-protection-exploit-guard.md | 16 ++++++++-------- .../enable-attack-surface-reduction.md | 6 +++--- .../enable-controlled-folders-exploit-guard.md | 8 ++++---- .../enable-exploit-protection.md | 6 +++--- .../enable-network-protection.md | 6 +++--- ...ization-based-protection-of-code-integrity.md | 2 +- .../evaluate-attack-surface-reduction.md | 6 +++--- .../evaluate-controlled-folder-access.md | 8 ++++---- .../evaluate-exploit-protection.md | 6 +++--- .../evaluate-network-protection.md | 6 +++--- .../evaluate-windows-defender-exploit-guard.md | 4 ++-- .../event-views-exploit-guard.md | 8 ++++---- .../exploit-protection-exploit-guard.md | 14 +++++++------- .../import-export-exploit-protection-emet-xml.md | 6 +++--- .../memory-integrity.md | 2 +- .../network-protection-exploit-guard.md | 14 +++++++------- ...ization-based-protection-of-code-integrity.md | 2 +- .../troubleshoot-asr.md | 8 ++++---- ...roubleshoot-exploit-protection-mitigations.md | 6 +++--- .../troubleshoot-np.md | 8 ++++---- .../windows-defender-exploit-guard.md | 12 ++++++------ 28 files changed, 107 insertions(+), 107 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md index e16b905b59..93cfaddf25 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,11 +18,11 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent behaviors malware often uses to infect computers with malicious code. You can set attack surface reduction rules for computers running Windows 10, version 1709 or later, Windows Server 2016 1803 or later, or Windows Server 2019. -To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. +To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. Attack surface reduction rules target behaviors that malware and malicious apps typically use to infect computers, including: @@ -32,7 +32,7 @@ Attack surface reduction rules target behaviors that malware and malicious apps You can use [audit mode](audit-windows-defender-exploit-guard.md) to evaluate how attack surface reduction rules would impact your organization if they were enabled. It's best to run all rules in audit mode first so you can understand their impact on your line-of-business applications. Many line-of-business applications are written with limited security concerns, and they may perform tasks similar to malware. By monitoring audit data and [adding exclusions](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction#exclude-files-and-folders-from-asr-rules) for necessary applications, you can deploy attack surface reduction rules without impacting productivity. -Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Windows Defender Security Center and in the Microsoft 365 securty center. +Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Microsoft Defender Security Center and in the Microsoft 365 securty center. For information about configuring attack surface reduction rules, see [Enable attack surface reduction rules](enable-attack-surface-reduction.md). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md index 4cc8fbd9f5..60bdf42183 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 10/15/2018 --- @@ -20,7 +20,7 @@ ms.date: 10/15/2018 - Windows 10 Enterprise E3 -Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. +Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. A limited subset of basic attack surface reduction rules can technically be used with Windows 10 Enterprise E3. They can be used without the benefits of reporting, monitoring, and analytics, which provide the ease of deployment and management capabilities necessary for enterprises. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md index 5d82fb8254..0bc78c8573 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md @@ -1,6 +1,6 @@ --- -title: Test how Windows Defender ATP features work -description: Audit mode lets you use the event log to see how Windows Defender ATP would protect your devices if it were enabled +title: Test how Microsoft Defender ATP features work +description: Audit mode lets you use the event log to see how Microsoft Defender ATP would protect your devices if it were enabled keywords: exploit guard, audit, auditing, mode, enabled, disabled, test, demo, evaluate, lab search.product: eADQiWindows 10XVcnh ms.pagetype: security @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -19,7 +19,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can enable attack surface reduction rules, exploit protection, network protection, and controlled folder access in audit mode. This lets you see a record of what *would* have happened if you had enabled the feature. @@ -27,7 +27,7 @@ You might want to do this when testing how the features will work in your organi While the features will not block or prevent apps, scripts, or files from being modified, the Windows Event Log will record events as if the features were fully enabled. This means you can enable audit mode and then review the event log to see what impact the feature would have had were it enabled. -You can use Windows Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Windows Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +You can use Microsoft Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Microsoft Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). This topic provides links that describe how to enable the audit functionality for each feature and how to view events in the Windows Event Viewer. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md index 77098d4c10..fd33e84578 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 11/29/2018 --- @@ -18,10 +18,10 @@ ms.date: 11/29/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. -Controlled folder access works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Controlled folder access works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). All apps (any executable file, including .exe, .scr, .dll files and others) are assessed by Windows Defender Antivirus, which then determines if the app is malicious or safe. If the app is determined to be malicious or suspicious, then it will not be allowed to make changes to any files in any protected folder. @@ -39,11 +39,11 @@ Controlled folder access is supported on Windows 10, version 1709 and later and Controlled folder access requires enabling [Windows Defender Antivirus real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md). -## Review controlled folder access events in the Windows Defender ATP Security Center +## Review controlled folder access events in the Microsoft Defender ATP Security Center -Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). -You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. ## Review controlled folder access events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md index b772be4c4c..99f4b9d52c 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 12/19/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/19/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md index 05037553e3..88e1a4623b 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha --- # Customize controlled folder access **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md index c49eae7912..139a12bd0e 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/26/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques on both the operating system processes and on individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md index 843e0e7f4c..5a5dc12514 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/08/2018 --- @@ -18,22 +18,22 @@ ms.date: 08/08/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. > >You can [convert an existing EMET configuration file into Exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Windows Defender ATP. +This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Microsoft Defender ATP. -Exploit protection in Windows Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. +Exploit protection in Microsoft Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. EMET is a standalone product for earlier versions of Windows and provides some mitigation against older, known exploit techniques. After July 31, 2018, it will not be supported. -For more information about the individual features and mitigations available in Windows Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: +For more information about the individual features and mitigations available in Microsoft Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: - [Protect devices from exploits](exploit-protection-exploit-guard.md) - [Configure and audit exploit protection mitigations](customize-exploit-protection.md) @@ -59,7 +59,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md index c5d238cf59..5239e149c8 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha --- # Enable attack surface reduction rules [Attack surface reduction rules](attack-surface-reduction-exploit-guard.md) help prevent actions and apps that malware often uses to infect computers. You can set attack surface reduction rules for computers running Windows 10 or Windows Server 2019. -To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Windows Defender Advanced Threat Protection (Windows Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. +To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. ## Exclude files and folders from ASR rules diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md index 4cc8d86d0a..6c8a9ba1d5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) helps you protect valuable data from malicious apps and threats, such as ransomware. It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md). Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -103,4 +103,4 @@ Use `Disabled` to turn the feature off. - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) - [Customize controlled folder access](customize-controlled-folders-exploit-guard.md) -- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md index 86f640ad6f..da528e3360 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect against malware that uses exploits to infect devices and spread. It consists of a number of mitigations that can be applied to either the operating system or individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md index b1e858ebcb..291b023277 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/01/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/01/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. You can [audit network protection](evaluate-network-protection.md) in a test environment to see which apps would be blocked before you enable it. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md index 8648bcd508..08fe9b44f4 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 04/01/2019 **Applies to** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This topic covers different ways to enable Hypervisor-protected code integrity (HVCI) on Windows 10. Some applications, including device drivers, may be incompatible with HVCI. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md index 307b13fd20..83db94a6af 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md index 667c554a43..08847c82c5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 11/16/2018 --- @@ -18,7 +18,7 @@ ms.date: 11/16/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) is a feature that helps protect your documents and files from modification by suspicious or malicious apps. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -62,5 +62,5 @@ See [Protect important folders with controlled folder access](controlled-folders ## Related topics - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) -- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) - [Use audit mode](audit-windows-defender-exploit-guard.md) \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md index 6ae70924c7..64c227f6e5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect devices from malware that uses exploits to spread and infect other devices. It consists of a number of mitigations that can be applied to either the operating system or an individual app. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md index 74605b559a..a7de3f8d9d 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md index ee57054634..8015e81dde 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 05/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md index c15f7d5f95..443e9929ff 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md @@ -10,8 +10,8 @@ ms.sitesec: library ms.pagetype: security ms.date: 04/16/2018 ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/26/2019 --- @@ -19,7 +19,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can review attack surface reduction events in Event Viewer. This is useful so you can monitor what rules or settings are working, and determine if any settings are too "noisy" or impacting your day to day workflow. @@ -27,7 +27,7 @@ Reviewing the events is also handy when you are evaluating the features, as you This topic lists all the events, their associated feature or setting, and describes how to create custom views to filter to specific events. -You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). +You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md). ## Use custom views to review attack surface reduction capabilities diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md index 72869c7925..6cc021334d 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques to operating system processes and apps. @@ -27,7 +27,7 @@ It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Exploit protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Exploit protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). You can [enable exploit protection](enable-exploit-protection.md) on an individual machine, and then use [Group Policy](import-export-exploit-protection-emet-xml.md) to distribute the XML file to multiple devices at once. @@ -79,11 +79,11 @@ Win32K | 260 | Untrusted Font ## Comparison between Enhanced Mitigation Experience Toolkit and Windows Defender Exploit Guard >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. > >You can [convert an existing EMET configuration file into exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This section compares exploit protection in Windows Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. +This section compares exploit protection in Microsoft Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. The table in this section illustrates the differences between EMET and Windows Defender Exploit Guard.   | Windows Defender Exploit Guard | EMET @@ -102,7 +102,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md index 1be2ff6cb2..3246dc8164 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- @@ -18,7 +18,7 @@ ms.date: 04/30/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection applies helps protect devices from malware that use exploits to spread and infect. It consists of a number of mitigations that can be applied at either the operating system level, or at the individual app level. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md index aed6d58094..40ac8a84cd 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Memory integrity is a powerful system mitigation that leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode processes against the injection and execution of malicious or unverified code. Code integrity validation is performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor. Memory integrity helps block many types of malware from running on computers that run Windows 10 and Windows Server 2016. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md index 8ffcfaf3cd..8b883ee82b 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 02/14/2019 --- @@ -18,7 +18,7 @@ ms.date: 02/14/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Network protection helps reduce the attack surface of your devices from Internet-based events. It prevents employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. @@ -29,7 +29,7 @@ Network protection is supported on Windows 10, version 1709 and later and Window >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Network protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Network protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). When network protection blocks a connection, a notification will be displayed from the Action Center. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. You can also enable the rules individually to customize what techniques the feature monitors. @@ -43,11 +43,11 @@ Windows 10 version | Windows Defender Antivirus - | - Windows 10 version 1709 or later | [Windows Defender AV real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) and [cloud-delivered protection](../windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md) must be enabled -## Review network protection events in the Windows Defender ATP Security Center +## Review network protection events in the Microsoft Defender ATP Security Center -Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). -You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. ## Review network protection events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md index 514a74a4ea..bd01a47dbb 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 10/20/2017 **Applies to** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Computers must meet certain hardware, firmware, and software requirements in order to take adavantage of all of the virtualization-based security (VBS) features in [Windows Defender Device Guard](../device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md). Computers lacking these requirements can still be protected by Windows Defender Application Control (WDAC) policies—the difference is that those computers will not be as hardened against certain threats. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md index 0eea5319db..0ffe534d26 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you use [attack surface reduction rules](attack-surface-reduction-exploit-guard.md) you may encounter issues, such as: @@ -76,7 +76,7 @@ To add an exclusion, see [Customize Attack surface reduction](customize-attack-s ## Report a false positive or false negative -Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). +Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md index 7820eac52f..e8e2f3e46b 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you create a set of exploit protection mitigations (known as a configuration), you might find that the configuration export and import process does not remove all unwanted mitigations. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md index 708142ccf5..3feaedade3 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - IT administrators @@ -65,7 +65,7 @@ Set-MpPreference -EnableNetworkProtection Enabled ## Report a false positive or false negative -If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). +If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md index 32055b2546..b6733d5ed0 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Exploit Guard (Windows Defender EG) is a new set of host intrusion prevention capabilities for Windows 10, allowing you to manage and reduce the attack surface of apps used by your employees. @@ -43,9 +43,9 @@ You can also [enable audit mode](audit-windows-defender-exploit-guard.md) for th >[!TIP] >You can also visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the features are working and see how each of them work. -Windows Defender EG can be managed and reported on in the Windows Security app as part of the Windows Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. +Windows Defender EG can be managed and reported on in the Windows Security app as part of the Microsoft Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. -You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [sign up for a free trial of Windows Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. +You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). You can [sign up for a free trial of Microsoft Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. ## Requirements @@ -55,7 +55,7 @@ This section covers requirements for each feature in Windows Defender EG. |--------|---------| | ![not supported](./images/ball_empty.png) | Not supported | | ![supported](./images/ball_50.png) | Supported | -| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Windows Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| +| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Microsoft Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| | Feature | Windows 10 Home | Windows 10 Professional | Windows 10 E3 | Windows 10 E5 | | ----------------- | :------------------------------------: | :---------------------------: | :-------------------------: | :--------------------------------------: | From 4e53f9e8da68835d55732dfbfef7f569de391ab1 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:27:33 -0700 Subject: [PATCH 134/737] Revert "update author and product names in exploit guard folder" This reverts commit fd2e2b3287897bc4622292e6faea5130824c28ef. --- .../attack-surface-reduction-exploit-guard.md | 10 +++++----- ...eduction-rules-in-windows-10-enterprise-e3.md | 6 +++--- .../audit-windows-defender-exploit-guard.md | 12 ++++++------ .../controlled-folders-exploit-guard.md | 14 +++++++------- .../customize-attack-surface-reduction.md | 6 +++--- ...customize-controlled-folders-exploit-guard.md | 6 +++--- .../customize-exploit-protection.md | 6 +++--- .../emet-exploit-protection-exploit-guard.md | 16 ++++++++-------- .../enable-attack-surface-reduction.md | 6 +++--- .../enable-controlled-folders-exploit-guard.md | 8 ++++---- .../enable-exploit-protection.md | 6 +++--- .../enable-network-protection.md | 6 +++--- ...ization-based-protection-of-code-integrity.md | 2 +- .../evaluate-attack-surface-reduction.md | 6 +++--- .../evaluate-controlled-folder-access.md | 8 ++++---- .../evaluate-exploit-protection.md | 6 +++--- .../evaluate-network-protection.md | 6 +++--- .../evaluate-windows-defender-exploit-guard.md | 4 ++-- .../event-views-exploit-guard.md | 8 ++++---- .../exploit-protection-exploit-guard.md | 14 +++++++------- .../import-export-exploit-protection-emet-xml.md | 6 +++--- .../memory-integrity.md | 2 +- .../network-protection-exploit-guard.md | 14 +++++++------- ...ization-based-protection-of-code-integrity.md | 2 +- .../troubleshoot-asr.md | 8 ++++---- ...roubleshoot-exploit-protection-mitigations.md | 6 +++--- .../troubleshoot-np.md | 8 ++++---- .../windows-defender-exploit-guard.md | 12 ++++++------ 28 files changed, 107 insertions(+), 107 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md index 93cfaddf25..e16b905b59 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -18,11 +18,11 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent behaviors malware often uses to infect computers with malicious code. You can set attack surface reduction rules for computers running Windows 10, version 1709 or later, Windows Server 2016 1803 or later, or Windows Server 2019. -To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. +To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. Attack surface reduction rules target behaviors that malware and malicious apps typically use to infect computers, including: @@ -32,7 +32,7 @@ Attack surface reduction rules target behaviors that malware and malicious apps You can use [audit mode](audit-windows-defender-exploit-guard.md) to evaluate how attack surface reduction rules would impact your organization if they were enabled. It's best to run all rules in audit mode first so you can understand their impact on your line-of-business applications. Many line-of-business applications are written with limited security concerns, and they may perform tasks similar to malware. By monitoring audit data and [adding exclusions](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction#exclude-files-and-folders-from-asr-rules) for necessary applications, you can deploy attack surface reduction rules without impacting productivity. -Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Microsoft Defender Security Center and in the Microsoft 365 securty center. +Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Windows Defender Security Center and in the Microsoft 365 securty center. For information about configuring attack surface reduction rules, see [Enable attack surface reduction rules](enable-attack-surface-reduction.md). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md index 60bdf42183..4cc8fbd9f5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 10/15/2018 --- @@ -20,7 +20,7 @@ ms.date: 10/15/2018 - Windows 10 Enterprise E3 -Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. +Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. A limited subset of basic attack surface reduction rules can technically be used with Windows 10 Enterprise E3. They can be used without the benefits of reporting, monitoring, and analytics, which provide the ease of deployment and management capabilities necessary for enterprises. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md index 0bc78c8573..5d82fb8254 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md @@ -1,6 +1,6 @@ --- -title: Test how Microsoft Defender ATP features work -description: Audit mode lets you use the event log to see how Microsoft Defender ATP would protect your devices if it were enabled +title: Test how Windows Defender ATP features work +description: Audit mode lets you use the event log to see how Windows Defender ATP would protect your devices if it were enabled keywords: exploit guard, audit, auditing, mode, enabled, disabled, test, demo, evaluate, lab search.product: eADQiWindows 10XVcnh ms.pagetype: security @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -19,7 +19,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can enable attack surface reduction rules, exploit protection, network protection, and controlled folder access in audit mode. This lets you see a record of what *would* have happened if you had enabled the feature. @@ -27,7 +27,7 @@ You might want to do this when testing how the features will work in your organi While the features will not block or prevent apps, scripts, or files from being modified, the Windows Event Log will record events as if the features were fully enabled. This means you can enable audit mode and then review the event log to see what impact the feature would have had were it enabled. -You can use Microsoft Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Microsoft Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +You can use Windows Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Windows Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). This topic provides links that describe how to enable the audit functionality for each feature and how to view events in the Windows Event Viewer. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md index fd33e84578..77098d4c10 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 11/29/2018 --- @@ -18,10 +18,10 @@ ms.date: 11/29/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. -Controlled folder access works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +Controlled folder access works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). All apps (any executable file, including .exe, .scr, .dll files and others) are assessed by Windows Defender Antivirus, which then determines if the app is malicious or safe. If the app is determined to be malicious or suspicious, then it will not be allowed to make changes to any files in any protected folder. @@ -39,11 +39,11 @@ Controlled folder access is supported on Windows 10, version 1709 and later and Controlled folder access requires enabling [Windows Defender Antivirus real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md). -## Review controlled folder access events in the Microsoft Defender ATP Security Center +## Review controlled folder access events in the Windows Defender ATP Security Center -Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). -You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. +You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. ## Review controlled folder access events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md index 99f4b9d52c..b772be4c4c 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 12/19/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/19/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md index 88e1a4623b..05037553e3 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic --- # Customize controlled folder access **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md index 139a12bd0e..c49eae7912 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/26/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques on both the operating system processes and on individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md index 5a5dc12514..843e0e7f4c 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 08/08/2018 --- @@ -18,22 +18,22 @@ ms.date: 08/08/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. > >You can [convert an existing EMET configuration file into Exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Microsoft Defender ATP. +This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Windows Defender ATP. -Exploit protection in Microsoft Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. +Exploit protection in Windows Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. EMET is a standalone product for earlier versions of Windows and provides some mitigation against older, known exploit techniques. After July 31, 2018, it will not be supported. -For more information about the individual features and mitigations available in Microsoft Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: +For more information about the individual features and mitigations available in Windows Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: - [Protect devices from exploits](exploit-protection-exploit-guard.md) - [Configure and audit exploit protection mitigations](customize-exploit-protection.md) @@ -59,7 +59,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md index 5239e149c8..c5d238cf59 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic --- # Enable attack surface reduction rules [Attack surface reduction rules](attack-surface-reduction-exploit-guard.md) help prevent actions and apps that malware often uses to infect computers. You can set attack surface reduction rules for computers running Windows 10 or Windows Server 2019. -To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. +To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Windows Defender Advanced Threat Protection (Windows Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. ## Exclude files and folders from ASR rules diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md index 6c8a9ba1d5..4cc8d86d0a 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) helps you protect valuable data from malicious apps and threats, such as ransomware. It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md). Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -103,4 +103,4 @@ Use `Disabled` to turn the feature off. - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) - [Customize controlled folder access](customize-controlled-folders-exploit-guard.md) -- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md index da528e3360..86f640ad6f 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect against malware that uses exploits to infect devices and spread. It consists of a number of mitigations that can be applied to either the operating system or individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md index 291b023277..b1e858ebcb 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/01/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/01/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. You can [audit network protection](evaluate-network-protection.md) in a test environment to see which apps would be blocked before you enable it. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md index 08fe9b44f4..8648bcd508 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 04/01/2019 **Applies to** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This topic covers different ways to enable Hypervisor-protected code integrity (HVCI) on Windows 10. Some applications, including device drivers, may be incompatible with HVCI. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md index 83db94a6af..307b13fd20 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md index 08847c82c5..667c554a43 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 11/16/2018 --- @@ -18,7 +18,7 @@ ms.date: 11/16/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) is a feature that helps protect your documents and files from modification by suspicious or malicious apps. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -62,5 +62,5 @@ See [Protect important folders with controlled folder access](controlled-folders ## Related topics - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) -- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) - [Use audit mode](audit-windows-defender-exploit-guard.md) \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md index 64c227f6e5..6ae70924c7 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect devices from malware that uses exploits to spread and infect other devices. It consists of a number of mitigations that can be applied to either the operating system or an individual app. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md index a7de3f8d9d..74605b559a 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md index 8015e81dde..ee57054634 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 05/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md index 443e9929ff..c15f7d5f95 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md @@ -10,8 +10,8 @@ ms.sitesec: library ms.pagetype: security ms.date: 04/16/2018 ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/26/2019 --- @@ -19,7 +19,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can review attack surface reduction events in Event Viewer. This is useful so you can monitor what rules or settings are working, and determine if any settings are too "noisy" or impacting your day to day workflow. @@ -27,7 +27,7 @@ Reviewing the events is also handy when you are evaluating the features, as you This topic lists all the events, their associated feature or setting, and describes how to create custom views to filter to specific events. -You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md). +You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). ## Use custom views to review attack surface reduction capabilities diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md index 6cc021334d..72869c7925 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques to operating system processes and apps. @@ -27,7 +27,7 @@ It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Exploit protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +Exploit protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [enable exploit protection](enable-exploit-protection.md) on an individual machine, and then use [Group Policy](import-export-exploit-protection-emet-xml.md) to distribute the XML file to multiple devices at once. @@ -79,11 +79,11 @@ Win32K | 260 | Untrusted Font ## Comparison between Enhanced Mitigation Experience Toolkit and Windows Defender Exploit Guard >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. > >You can [convert an existing EMET configuration file into exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This section compares exploit protection in Microsoft Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. +This section compares exploit protection in Windows Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. The table in this section illustrates the differences between EMET and Windows Defender Exploit Guard.   | Windows Defender Exploit Guard | EMET @@ -102,7 +102,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md index 3246dc8164..1be2ff6cb2 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 04/30/2018 --- @@ -18,7 +18,7 @@ ms.date: 04/30/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection applies helps protect devices from malware that use exploits to spread and infect. It consists of a number of mitigations that can be applied at either the operating system level, or at the individual app level. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md index 40ac8a84cd..aed6d58094 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Memory integrity is a powerful system mitigation that leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode processes against the injection and execution of malicious or unverified code. Code integrity validation is performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor. Memory integrity helps block many types of malware from running on computers that run Windows 10 and Windows Server 2016. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md index 8b883ee82b..8ffcfaf3cd 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 02/14/2019 --- @@ -18,7 +18,7 @@ ms.date: 02/14/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Network protection helps reduce the attack surface of your devices from Internet-based events. It prevents employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. @@ -29,7 +29,7 @@ Network protection is supported on Windows 10, version 1709 and later and Window >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Network protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +Network protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). When network protection blocks a connection, a notification will be displayed from the Action Center. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. You can also enable the rules individually to customize what techniques the feature monitors. @@ -43,11 +43,11 @@ Windows 10 version | Windows Defender Antivirus - | - Windows 10 version 1709 or later | [Windows Defender AV real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) and [cloud-delivered protection](../windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md) must be enabled -## Review network protection events in the Microsoft Defender ATP Security Center +## Review network protection events in the Windows Defender ATP Security Center -Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). +Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). -You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. +You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. ## Review network protection events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md index bd01a47dbb..514a74a4ea 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 10/20/2017 **Applies to** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Computers must meet certain hardware, firmware, and software requirements in order to take adavantage of all of the virtualization-based security (VBS) features in [Windows Defender Device Guard](../device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md). Computers lacking these requirements can still be protected by Windows Defender Application Control (WDAC) policies—the difference is that those computers will not be as hardened against certain threats. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md index 0ffe534d26..0eea5319db 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you use [attack surface reduction rules](attack-surface-reduction-exploit-guard.md) you may encounter issues, such as: @@ -76,7 +76,7 @@ To add an exclusion, see [Customize Attack surface reduction](customize-attack-s ## Report a false positive or false negative -Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). +Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md index e8e2f3e46b..7820eac52f 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you create a set of exploit protection mitigations (known as a configuration), you might find that the configuration export and import process does not remove all unwanted mitigations. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md index 3feaedade3..708142ccf5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - IT administrators @@ -65,7 +65,7 @@ Set-MpPreference -EnableNetworkProtection Enabled ## Report a false positive or false negative -If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). +If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md index b6733d5ed0..32055b2546 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: justinha -ms.author: justinha +author: andreabichsel +ms.author: v-anbic ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Exploit Guard (Windows Defender EG) is a new set of host intrusion prevention capabilities for Windows 10, allowing you to manage and reduce the attack surface of apps used by your employees. @@ -43,9 +43,9 @@ You can also [enable audit mode](audit-windows-defender-exploit-guard.md) for th >[!TIP] >You can also visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the features are working and see how each of them work. -Windows Defender EG can be managed and reported on in the Windows Security app as part of the Microsoft Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. +Windows Defender EG can be managed and reported on in the Windows Security app as part of the Windows Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. -You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). You can [sign up for a free trial of Microsoft Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. +You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [sign up for a free trial of Windows Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. ## Requirements @@ -55,7 +55,7 @@ This section covers requirements for each feature in Windows Defender EG. |--------|---------| | ![not supported](./images/ball_empty.png) | Not supported | | ![supported](./images/ball_50.png) | Supported | -| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Microsoft Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| +| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Windows Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| | Feature | Windows 10 Home | Windows 10 Professional | Windows 10 E3 | Windows 10 E5 | | ----------------- | :------------------------------------: | :---------------------------: | :-------------------------: | :--------------------------------------: | From 6f2e3fea96fd6ed80be4144ba8290756318e5cf7 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:31:51 -0700 Subject: [PATCH 135/737] update product names and author in exploit guard folder --- .../attack-surface-reduction-exploit-guard.md | 10 +++++----- ...eduction-rules-in-windows-10-enterprise-e3.md | 6 +++--- .../audit-windows-defender-exploit-guard.md | 12 ++++++------ .../controlled-folders-exploit-guard.md | 14 +++++++------- .../customize-attack-surface-reduction.md | 6 +++--- ...customize-controlled-folders-exploit-guard.md | 6 +++--- .../customize-exploit-protection.md | 6 +++--- .../emet-exploit-protection-exploit-guard.md | 16 ++++++++-------- .../enable-attack-surface-reduction.md | 6 +++--- .../enable-controlled-folders-exploit-guard.md | 8 ++++---- .../enable-exploit-protection.md | 6 +++--- .../enable-network-protection.md | 6 +++--- ...ization-based-protection-of-code-integrity.md | 2 +- .../evaluate-attack-surface-reduction.md | 6 +++--- .../evaluate-controlled-folder-access.md | 8 ++++---- .../evaluate-exploit-protection.md | 6 +++--- .../evaluate-network-protection.md | 6 +++--- .../evaluate-windows-defender-exploit-guard.md | 4 ++-- .../event-views-exploit-guard.md | 8 ++++---- .../exploit-protection-exploit-guard.md | 14 +++++++------- .../import-export-exploit-protection-emet-xml.md | 6 +++--- .../memory-integrity.md | 2 +- .../network-protection-exploit-guard.md | 14 +++++++------- ...ization-based-protection-of-code-integrity.md | 2 +- .../troubleshoot-asr.md | 6 +++--- ...roubleshoot-exploit-protection-mitigations.md | 6 +++--- .../troubleshoot-np.md | 6 +++--- .../windows-defender-exploit-guard.md | 12 ++++++------ 28 files changed, 105 insertions(+), 105 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md index e16b905b59..51b3340555 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,11 +18,11 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent behaviors malware often uses to infect computers with malicious code. You can set attack surface reduction rules for computers running Windows 10, version 1709 or later, Windows Server 2016 1803 or later, or Windows Server 2019. -To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. +To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. Attack surface reduction rules target behaviors that malware and malicious apps typically use to infect computers, including: @@ -32,7 +32,7 @@ Attack surface reduction rules target behaviors that malware and malicious apps You can use [audit mode](audit-windows-defender-exploit-guard.md) to evaluate how attack surface reduction rules would impact your organization if they were enabled. It's best to run all rules in audit mode first so you can understand their impact on your line-of-business applications. Many line-of-business applications are written with limited security concerns, and they may perform tasks similar to malware. By monitoring audit data and [adding exclusions](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction#exclude-files-and-folders-from-asr-rules) for necessary applications, you can deploy attack surface reduction rules without impacting productivity. -Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Windows Defender Security Center and in the Microsoft 365 securty center. +Triggered rules display a notification on the device. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. The notification also displays in the Microsoft Defender Security Center and in the Microsoft 365 securty center. For information about configuring attack surface reduction rules, see [Enable attack surface reduction rules](enable-attack-surface-reduction.md). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md index 4cc8fbd9f5..9b29796bee 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 10/15/2018 --- @@ -20,7 +20,7 @@ ms.date: 10/15/2018 - Windows 10 Enterprise E3 -Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. +Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. A limited subset of basic attack surface reduction rules can technically be used with Windows 10 Enterprise E3. They can be used without the benefits of reporting, monitoring, and analytics, which provide the ease of deployment and management capabilities necessary for enterprises. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md index 5d82fb8254..672ab8575a 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md @@ -1,6 +1,6 @@ --- -title: Test how Windows Defender ATP features work -description: Audit mode lets you use the event log to see how Windows Defender ATP would protect your devices if it were enabled +title: Test how Microsoft Defender ATP features work +description: Audit mode lets you use the event log to see how Microsoft Defender ATP would protect your devices if it were enabled keywords: exploit guard, audit, auditing, mode, enabled, disabled, test, demo, evaluate, lab search.product: eADQiWindows 10XVcnh ms.pagetype: security @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -19,7 +19,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can enable attack surface reduction rules, exploit protection, network protection, and controlled folder access in audit mode. This lets you see a record of what *would* have happened if you had enabled the feature. @@ -27,7 +27,7 @@ You might want to do this when testing how the features will work in your organi While the features will not block or prevent apps, scripts, or files from being modified, the Windows Event Log will record events as if the features were fully enabled. This means you can enable audit mode and then review the event log to see what impact the feature would have had were it enabled. -You can use Windows Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Windows Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +You can use Microsoft Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Microsoft Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). This topic provides links that describe how to enable the audit functionality for each feature and how to view events in the Windows Event Viewer. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md index 77098d4c10..c137f791e5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 11/29/2018 --- @@ -18,10 +18,10 @@ ms.date: 11/29/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. -Controlled folder access works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Controlled folder access works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). All apps (any executable file, including .exe, .scr, .dll files and others) are assessed by Windows Defender Antivirus, which then determines if the app is malicious or safe. If the app is determined to be malicious or suspicious, then it will not be allowed to make changes to any files in any protected folder. @@ -39,11 +39,11 @@ Controlled folder access is supported on Windows 10, version 1709 and later and Controlled folder access requires enabling [Windows Defender Antivirus real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md). -## Review controlled folder access events in the Windows Defender ATP Security Center +## Review controlled folder access events in the Microsoft Defender ATP Security Center -Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). -You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. ## Review controlled folder access events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md index b772be4c4c..99f4b9d52c 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 12/19/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/19/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md index 05037553e3..88e1a4623b 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-controlled-folders-exploit-guard.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha --- # Customize controlled folder access **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md index c49eae7912..139a12bd0e 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/26/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques on both the operating system processes and on individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md index 843e0e7f4c..bc4ff6e8aa 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/08/2018 --- @@ -18,22 +18,22 @@ ms.date: 08/08/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. > >You can [convert an existing EMET configuration file into Exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Windows Defender ATP. +This topic describes the differences between the Enhance Mitigation Experience Toolkit (EMET) and exploit protection in Microsoft Defender ATP. -Exploit protection in Windows Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. +Exploit protection in Microsoft Defender ATP is our successor to EMET and provides stronger protection, more customization, an easier user interface, and better configuration and management options. EMET is a standalone product for earlier versions of Windows and provides some mitigation against older, known exploit techniques. After July 31, 2018, it will not be supported. -For more information about the individual features and mitigations available in Windows Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: +For more information about the individual features and mitigations available in Microsoft Defender ATP, as well as how to enable, configure, and deploy them to better protect your network, see the following topics: - [Protect devices from exploits](exploit-protection-exploit-guard.md) - [Configure and audit exploit protection mitigations](customize-exploit-protection.md) @@ -59,7 +59,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md index c5d238cf59..5239e149c8 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md @@ -9,15 +9,15 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha --- # Enable attack surface reduction rules [Attack surface reduction rules](attack-surface-reduction-exploit-guard.md) help prevent actions and apps that malware often uses to infect computers. You can set attack surface reduction rules for computers running Windows 10 or Windows Server 2019. -To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Windows Defender Advanced Threat Protection (Windows Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. +To use ASR rules, you need either a Windows 10 Enterprise E3 or E5 license. We recommend an E5 license so you can take advantage of the advanced monitoring and reporting capabilities available in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP). These advanced capabilities aren't available with an E3 license, but you can develop your own monitoring and reporting tools to use in conjuction with ASR rules. ## Exclude files and folders from ASR rules diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md index 4cc8d86d0a..6c8a9ba1d5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-controlled-folders-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) helps you protect valuable data from malicious apps and threats, such as ransomware. It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md). Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -103,4 +103,4 @@ Use `Disabled` to turn the feature off. - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) - [Customize controlled folder access](customize-controlled-folders-exploit-guard.md) -- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md index 86f640ad6f..da528e3360 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/29/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/29/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect against malware that uses exploits to infect devices and spread. It consists of a number of mitigations that can be applied to either the operating system or individual apps. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md index b1e858ebcb..291b023277 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/01/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/01/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps to prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. You can [audit network protection](evaluate-network-protection.md) in a test environment to see which apps would be blocked before you enable it. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md index 8648bcd508..08fe9b44f4 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 04/01/2019 **Applies to** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This topic covers different ways to enable Hypervisor-protected code integrity (HVCI) on Windows 10. Some applications, including device drivers, may be incompatible with HVCI. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md index 307b13fd20..83db94a6af 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. Attack surface reduction rules are supported on Windows Server 2019 as well as Windows 10 clients. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md index 667c554a43..08847c82c5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 11/16/2018 --- @@ -18,7 +18,7 @@ ms.date: 11/16/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Controlled folder access](controlled-folders-exploit-guard.md) is a feature that helps protect your documents and files from modification by suspicious or malicious apps. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. @@ -62,5 +62,5 @@ See [Protect important folders with controlled folder access](controlled-folders ## Related topics - [Protect important folders with controlled folder access](controlled-folders-exploit-guard.md) -- [Evaluate Windows Defender ATP](evaluate-windows-defender-exploit-guard.md) +- [Evaluate Microsoft Defender ATP](evaluate-windows-defender-exploit-guard.md) - [Use audit mode](audit-windows-defender-exploit-guard.md) \ No newline at end of file diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md index 6ae70924c7..64c227f6e5 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-exploit-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Exploit protection](exploit-protection-exploit-guard.md) helps protect devices from malware that uses exploits to spread and infect other devices. It consists of a number of mitigations that can be applied to either the operating system or an individual app. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md index 74605b559a..a7de3f8d9d 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [Network protection](network-protection-exploit-guard.md) helps prevent employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md index ee57054634..8015e81dde 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 05/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md index c15f7d5f95..58ecc61775 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md @@ -10,8 +10,8 @@ ms.sitesec: library ms.pagetype: security ms.date: 04/16/2018 ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/26/2019 --- @@ -19,7 +19,7 @@ ms.date: 03/26/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can review attack surface reduction events in Event Viewer. This is useful so you can monitor what rules or settings are working, and determine if any settings are too "noisy" or impacting your day to day workflow. @@ -27,7 +27,7 @@ Reviewing the events is also handy when you are evaluating the features, as you This topic lists all the events, their associated feature or setting, and describes how to create custom views to filter to specific events. -You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). +You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). ## Use custom views to review attack surface reduction capabilities diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md index 72869c7925..2f26612542 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/02/2019 --- @@ -18,7 +18,7 @@ ms.date: 04/02/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection automatically applies a number of exploit mitigation techniques to operating system processes and apps. @@ -27,7 +27,7 @@ It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Exploit protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Exploit protection works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [enable exploit protection](enable-exploit-protection.md) on an individual machine, and then use [Group Policy](import-export-exploit-protection-emet-xml.md) to distribute the XML file to multiple devices at once. @@ -79,11 +79,11 @@ Win32K | 260 | Untrusted Font ## Comparison between Enhanced Mitigation Experience Toolkit and Windows Defender Exploit Guard >[!IMPORTANT] ->If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Windows Defender ATP. +>If you are currently using EMET, you should be aware that [EMET reached end of life on July 31, 2018](https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/). You should consider replacing EMET with exploit protection in Microsoft Defender ATP. > >You can [convert an existing EMET configuration file into exploit protection](import-export-exploit-protection-emet-xml.md#convert-an-emet-configuration-file-to-an-exploit-protection-configuration-file) to make the migration easier and keep your existing settings. -This section compares exploit protection in Windows Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. +This section compares exploit protection in Microsoft Defender ATP with the Enhance Mitigation Experience Toolkit (EMET) for reference. The table in this section illustrates the differences between EMET and Windows Defender Exploit Guard.   | Windows Defender Exploit Guard | EMET @@ -102,7 +102,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Windows Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md index 1be2ff6cb2..3246dc8164 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/import-export-exploit-protection-emet-xml.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- @@ -18,7 +18,7 @@ ms.date: 04/30/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Exploit protection applies helps protect devices from malware that use exploits to spread and infect. It consists of a number of mitigations that can be applied at either the operating system level, or at the individual app level. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md index aed6d58094..40ac8a84cd 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/memory-integrity.md @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Memory integrity is a powerful system mitigation that leverages hardware virtualization and the Windows Hyper-V hypervisor to protect Windows kernel-mode processes against the injection and execution of malicious or unverified code. Code integrity validation is performed in a secure environment that is resistant to attack from malicious software, and page permissions for kernel mode are set and maintained by the Hyper-V hypervisor. Memory integrity helps block many types of malware from running on computers that run Windows 10 and Windows Server 2016. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md index 8ffcfaf3cd..e65dcc4777 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 02/14/2019 --- @@ -18,7 +18,7 @@ ms.date: 02/14/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Network protection helps reduce the attack surface of your devices from Internet-based events. It prevents employees from using any application to access dangerous domains that may host phishing scams, exploits, and other malicious content on the Internet. @@ -29,7 +29,7 @@ Network protection is supported on Windows 10, version 1709 and later and Window >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Network protection works best with [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Network protection works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). When network protection blocks a connection, a notification will be displayed from the Action Center. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. You can also enable the rules individually to customize what techniques the feature monitors. @@ -43,11 +43,11 @@ Windows 10 version | Windows Defender Antivirus - | - Windows 10 version 1709 or later | [Windows Defender AV real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) and [cloud-delivered protection](../windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md) must be enabled -## Review network protection events in the Windows Defender ATP Security Center +## Review network protection events in the Microsoft Defender ATP Security Center -Windows Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). -You can query Windows Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. ## Review network protection events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md index 514a74a4ea..bd01a47dbb 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md @@ -17,7 +17,7 @@ ms.date: 10/20/2017 **Applies to** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Computers must meet certain hardware, firmware, and software requirements in order to take adavantage of all of the virtualization-based security (VBS) features in [Windows Defender Device Guard](../device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md). Computers lacking these requirements can still be protected by Windows Defender Application Control (WDAC) policies—the difference is that those computers will not be as hardened against certain threats. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md index 0eea5319db..d1f516eacc 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you use [attack surface reduction rules](attack-surface-reduction-exploit-guard.md) you may encounter issues, such as: diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md index 7820eac52f..e8e2f3e46b 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-exploit-protection-mitigations.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you create a set of exploit protection mitigations (known as a configuration), you might find that the configuration export and import process does not remove all unwanted mitigations. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md index 708142ccf5..40c261016a 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 03/27/2019 --- @@ -18,7 +18,7 @@ ms.date: 03/27/2019 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) - IT administrators diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md index 32055b2546..cd2b47c9fe 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 08/09/2018 --- @@ -18,7 +18,7 @@ ms.date: 08/09/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Exploit Guard (Windows Defender EG) is a new set of host intrusion prevention capabilities for Windows 10, allowing you to manage and reduce the attack surface of apps used by your employees. @@ -43,9 +43,9 @@ You can also [enable audit mode](audit-windows-defender-exploit-guard.md) for th >[!TIP] >You can also visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the features are working and see how each of them work. -Windows Defender EG can be managed and reported on in the Windows Security app as part of the Windows Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. +Windows Defender EG can be managed and reported on in the Windows Security app as part of the Microsoft Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. -You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [sign up for a free trial of Windows Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. +You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [sign up for a free trial of Microsoft Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. ## Requirements @@ -55,7 +55,7 @@ This section covers requirements for each feature in Windows Defender EG. |--------|---------| | ![not supported](./images/ball_empty.png) | Not supported | | ![supported](./images/ball_50.png) | Supported | -| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Windows Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| +| ![supported, full reporting](./images/ball_full.png) | Recommended. Includes full, automated reporting into the Microsoft Defender ATP console. Provides additional cloud-powered capabilities, including the Network protection ability to block apps from accessing low-reputation websites and an attack surface reduction rule that blocks executable files that meet age or prevalence criteria.| | Feature | Windows 10 Home | Windows 10 Professional | Windows 10 E3 | Windows 10 E5 | | ----------------- | :------------------------------------: | :---------------------------: | :-------------------------: | :--------------------------------------: | From c75688a5863194392fdab581889545968bca9716 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:34:41 -0700 Subject: [PATCH 136/737] update all product names and author in av folder --- ...llect-diagnostic-data-update-compliance.md | 4 +-- ...ne-arguments-windows-defender-antivirus.md | 4 +-- ...nt-reference-windows-defender-antivirus.md | 4 +-- ...d-scan-types-windows-defender-antivirus.md | 4 +-- ...-first-sight-windows-defender-antivirus.md | 6 ++--- ...meout-period-windows-defender-antivirus.md | 4 +-- ...-interaction-windows-defender-antivirus.md | 4 +-- ...e-exclusions-windows-defender-antivirus.md | 4 +-- ...e-exclusions-windows-defender-antivirus.md | 4 +-- ...cy-overrides-windows-defender-antivirus.md | 4 +-- ...-connections-windows-defender-antivirus.md | 6 ++--- ...otifications-windows-defender-antivirus.md | 4 +-- ...e-exclusions-windows-defender-antivirus.md | 4 +-- ...ion-features-windows-defender-antivirus.md | 4 +-- ...e-protection-windows-defender-antivirus.md | 4 +-- ...-remediation-windows-defender-antivirus.md | 4 +-- ...r-exclusions-windows-defender-antivirus.md | 4 +-- ...ure-windows-defender-antivirus-features.md | 4 +-- ...ediate-scans-windows-defender-antivirus.md | 4 +-- ...anage-report-windows-defender-antivirus.md | 4 +-- .../deploy-windows-defender-antivirus.md | 4 +-- ...ployment-vdi-windows-defender-antivirus.md | 4 +-- ...nwanted-apps-windows-defender-antivirus.md | 6 ++--- ...d-protection-windows-defender-antivirus.md | 4 +-- .../evaluate-windows-defender-antivirus.md | 6 ++--- ...dic-scanning-windows-defender-antivirus.md | 4 +-- ...ased-updates-windows-defender-antivirus.md | 4 +-- ...ed-endpoints-windows-defender-antivirus.md | 4 +-- ...ate-schedule-windows-defender-antivirus.md | 4 +-- ...tion-updates-windows-defender-antivirus.md | 4 +-- ...es-baselines-windows-defender-antivirus.md | 4 +-- ...-devices-vms-windows-defender-antivirus.md | 4 +-- .../microsoft-defender-atp-mac.md | 26 +++++++++---------- .../windows-defender-antivirus/oldTOC.md | 2 +- ...-interaction-windows-defender-antivirus.md | 6 ++--- ...port-monitor-windows-defender-antivirus.md | 4 +-- ...ntined-files-windows-defender-antivirus.md | 4 +-- ...scan-results-windows-defender-antivirus.md | 4 +-- .../run-scan-windows-defender-antivirus.md | 4 +-- ...tch-up-scans-windows-defender-antivirus.md | 4 +-- ...ection-level-windows-defender-antivirus.md | 4 +-- .../troubleshoot-reporting.md | 4 +-- ...troubleshoot-windows-defender-antivirus.md | 6 ++--- ...group-policy-windows-defender-antivirus.md | 4 +-- ...nfig-manager-windows-defender-antivirus.md | 4 +-- ...hell-cmdlets-windows-defender-antivirus.md | 4 +-- .../use-wmi-windows-defender-antivirus.md | 4 +-- ...d-protection-windows-defender-antivirus.md | 4 +-- ...indows-defender-antivirus-compatibility.md | 16 ++++++------ ...indows-defender-antivirus-in-windows-10.md | 4 +-- ...fender-antivirus-on-windows-server-2016.md | 4 +-- .../windows-defender-offline.md | 4 +-- ...dows-defender-security-center-antivirus.md | 6 ++--- 53 files changed, 129 insertions(+), 129 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/collect-diagnostic-data-update-compliance.md b/windows/security/threat-protection/windows-defender-antivirus/collect-diagnostic-data-update-compliance.md index 61bd6e91de..d1d493ca47 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/collect-diagnostic-data-update-compliance.md +++ b/windows/security/threat-protection/windows-defender-antivirus/collect-diagnostic-data-update-compliance.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This topic describes how to collect diagnostic data that can be used by Microsoft support and engineering teams to help troubleshoot issues you may encounter when using the Windows Defender AV Assessment section in the Update Compliance add-in. diff --git a/windows/security/threat-protection/windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md index 2d08b48bfe..c27ea9d49d 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 12/10/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/10/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can perform various Windows Defender Antivirus functions with the dedicated command-line tool mpcmdrun.exe. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md index b2246f6bc2..901c6c4995 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can manage and configure Windows Defender Antivirus with the following tools: diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md index 5714563915..88526a1351 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 10/25/2018 @@ -19,7 +19,7 @@ ms.date: 10/25/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) **Use Microsoft Intune to configure scanning options** diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus.md index b5d15d6b55..de780c12e7 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Block at first sight is a feature of next gen protection that provides a way to detect and block new malware within seconds. @@ -32,7 +32,7 @@ You can also [customize the message displayed on users' desktops](https://docs.m > There is no specific individual setting in System Center Configuration Manager to enable or disable block at first sight. It is enabled by default when the pre-requisite settings are configured correctly. You must use Group Policy settings to enable or disable the feature. >[!TIP] ->You can also visit the Windows Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the features are working and see how they work. +>You can also visit the Microsoft Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the features are working and see how they work. ## How it works diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-cloud-block-timeout-period-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-cloud-block-timeout-period-windows-defender-antivirus.md index d7ffbcbafd..1db5465f6e 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-cloud-block-timeout-period-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-cloud-block-timeout-period-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When Windows Defender Antivirus finds a suspicious file, it can prevent the file from running while it queries the [Windows Defender Antivirus cloud service](utilize-microsoft-cloud-protection-windows-defender-antivirus.md). diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-end-user-interaction-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-end-user-interaction-windows-defender-antivirus.md index d72265f76a..bc655530db 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-end-user-interaction-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-end-user-interaction-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can configure how users of the endpoints on your network can interact with Windows Defender Antivirus. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md index 430acbec64..354dd5cf6b 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can exclude certain files, folders, processes, and process-opened files from Windows Defender Antivirus scans. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md index 78351fac00..7250b72a17 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 12/10/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/10/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can exclude certain files from Windows Defender Antivirus scans by modifying exclusion lists. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-local-policy-overrides-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-local-policy-overrides-windows-defender-antivirus.md index 9feb4b7840..3670b50c42 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-local-policy-overrides-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-local-policy-overrides-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) By default, Windows Defender Antivirus settings that are deployed via a Group Policy Object to the endpoints in your network will prevent users from locally changing the settings. You can change this in some instances. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md index 71db8e1517..b895c48fac 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 10/08/2018 --- @@ -18,7 +18,7 @@ ms.date: 10/08/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) To ensure Windows Defender Antivirus cloud-delivered protection works properly, you need to configure your network to allow connections between your endpoints and certain Microsoft servers. @@ -27,7 +27,7 @@ This topic lists the connections that must be allowed, such as by using firewall See the Enterprise Mobility and Security blog post [Important changes to Microsoft Active Protection Services endpoint](https://blogs.technet.microsoft.com/enterprisemobility/2016/05/31/important-changes-to-microsoft-active-protection-service-maps-endpoint/) for some details about network connectivity. >[!TIP] ->You can also visit the Windows Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working: +>You can also visit the Microsoft Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working: > >- Cloud-delivered protection >- Fast learning (including block at first sight) diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-notifications-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-notifications-windows-defender-antivirus.md index 9874e1fe22..4da87e4759 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-notifications-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-notifications-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) In Windows 10, application notifications about malware detection and remediation are more robust, consistent, and concise. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md index 15f82314e7..0d029074a7 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 12/10/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/10/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can exclude files that have been opened by specific processes from Windows Defender Antivirus scans. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-protection-features-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-protection-features-windows-defender-antivirus.md index de47e8d1a8..3c50b7b45c 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-protection-features-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-protection-features-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus uses several methods to provide threat protection: diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md index 84cef362eb..594dcb0971 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 11/13/2018 --- @@ -18,7 +18,7 @@ ms.date: 11/13/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Always-on protection consists of real-time protection, behavior monitoring, and heuristics to identify malware based on known suspicious and malicious activities. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md index d09e59a96a..7d76d8a3ca 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When Windows Defender Antivirus runs a scan, it will attempt to remediate or remove threats that it finds. You can configure how Windows Defender Antivirus should react to certain threats, whether it should create a restore point before remediating, and when it should remove remediated threats. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md index 64037f0090..c56a79193a 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic --- @@ -17,7 +17,7 @@ ms.author: v-anbic **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus on Windows Server 2016 computers automatically enrolls you in certain exclusions, as defined by your specified server role. See [the end of this topic](#list-of-automatic-exclusions) for a list of these exclusions. diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-windows-defender-antivirus-features.md b/windows/security/threat-protection/windows-defender-antivirus/configure-windows-defender-antivirus-features.md index 862b5513c4..168cab8841 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-windows-defender-antivirus-features.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-windows-defender-antivirus-features.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can configure Windows Defender Antivirus with a number of tools, including: diff --git a/windows/security/threat-protection/windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md index b719577c49..ee7a843321 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can use Group Policy, PowerShell, and Windows Management Instrumentation (WMI) to configure Windows Defender Antivirus scans. diff --git a/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md index 5d587e3b8d..3dee12bfa2 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can deploy, manage, and report on Windows Defender Antivirus in a number of ways. diff --git a/windows/security/threat-protection/windows-defender-antivirus/deploy-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/deploy-windows-defender-antivirus.md index df219115d7..dbdd57f33f 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/deploy-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/deploy-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Depending on the management tool you are using, you may need to specifically enable or configure Windows Defender Antivirus protection. diff --git a/windows/security/threat-protection/windows-defender-antivirus/deployment-vdi-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/deployment-vdi-windows-defender-antivirus.md index 1bf3ab9c2f..fe13cfa820 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/deployment-vdi-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/deployment-vdi-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) In addition to standard on-premises or hardware configurations, you can also use Windows Defender Antivirus in a remote desktop (RDS) or virtual desktop infrastructure (VDI) environment. diff --git a/windows/security/threat-protection/windows-defender-antivirus/detect-block-potentially-unwanted-apps-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/detect-block-potentially-unwanted-apps-windows-defender-antivirus.md index 37859694d9..3185d40ef9 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/detect-block-potentially-unwanted-apps-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/detect-block-potentially-unwanted-apps-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: detect ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 10/02/2018 --- @@ -18,7 +18,7 @@ ms.date: 10/02/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) The potentially unwanted application (PUA) protection feature in Windows Defender Antivirus can identify and block PUAs from downloading and installing on endpoints in your network. @@ -33,7 +33,7 @@ Typical PUA behavior includes: These applications can increase the risk of your network being infected with malware, cause malware infections to be harder to identify, and can waste IT resources in cleaning up the applications. >[!TIP] ->You can also visit the Windows Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. +>You can also visit the Microsoft Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. ## How it works diff --git a/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md index 787c9a85ad..a2f69a956b 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) >[!NOTE] >The Windows Defender Antivirus cloud service is a mechanism for delivering updated protection to your network and endpoints. Although it is called a cloud service, it is not simply protection for files stored in the cloud; rather, it uses distributed resources and machine learning to deliver protection to your endpoints at a rate that is far faster than traditional Security intelligence updates. diff --git a/windows/security/threat-protection/windows-defender-antivirus/evaluate-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/evaluate-windows-defender-antivirus.md index c937715d4a..05165e019c 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/evaluate-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/evaluate-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,12 +18,12 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Use this guide to determine how well Windows Defender Antivirus protects you from viruses, malware, and potentially unwanted applications. >[!TIP] ->You can also visit the Windows Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working and see how they work: +>You can also visit the Microsoft Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working and see how they work: >- Cloud-delivered protection >- Fast learning (including Block at first sight) >- Potentially unwanted application blocking diff --git a/windows/security/threat-protection/windows-defender-antivirus/limited-periodic-scanning-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/limited-periodic-scanning-windows-defender-antivirus.md index 93ef8703d6..36df0b6adf 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/limited-periodic-scanning-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/limited-periodic-scanning-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -20,7 +20,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Limited periodic scanning is a special type of threat detection and remediation that can be enabled when you have installed another antivirus product on a Windows 10 device. diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-event-based-updates-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-event-based-updates-windows-defender-antivirus.md index 4e04685c61..bb6efd9718 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-event-based-updates-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-event-based-updates-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus allows you to determine if updates should (or should not) occur after certain events, such as at startup or after receiving specific reports from the cloud-delivered protection service. diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-outdated-endpoints-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-outdated-endpoints-windows-defender-antivirus.md index 9a77e63d64..38ca9e9c62 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-outdated-endpoints-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-outdated-endpoints-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus lets you define how long an endpoint can avoid an update or how many scans it can miss before it is required to update and scan itself. This is especially useful in environments where devices are not often connected to a corporate or external network, or devices that are not used on a daily basis. diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-protection-update-schedule-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-protection-update-schedule-windows-defender-antivirus.md index 4f8774109a..29534e1b63 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-protection-update-schedule-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-protection-update-schedule-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus lets you determine when it should look for and download updates. diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-protection-updates-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-protection-updates-windows-defender-antivirus.md index f05c21e0b5..2b0abfb132 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-protection-updates-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-protection-updates-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md index 99e2c737d9..f9883aa6c4 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) There are two types of updates related to keeping Windows Defender Antivirus up to date: 1. Protection updates diff --git a/windows/security/threat-protection/windows-defender-antivirus/manage-updates-mobile-devices-vms-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/manage-updates-mobile-devices-vms-windows-defender-antivirus.md index 93a9e45f84..b6b70e86ce 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/manage-updates-mobile-devices-vms-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/manage-updates-mobile-devices-vms-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Mobile devices and VMs may require additional configuration to ensure performance is not impacted by updates. diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md index 15865ca9fa..d78140a765 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md @@ -28,7 +28,7 @@ Microsoft Defender ATP for Mac is not yet widely available, and this topic only ## Prerequisites You should have beginner-level experience in macOS and BASH scripting. You must have administrative privileges on the machine. -You should also have access to Windows Defender Security Center. +You should also have access to Microsoft Defender Security Center. ### System Requirements Microsoft Defender ATP for Mac system requirements: @@ -56,7 +56,7 @@ SIP is a built-in macOS security feature that prevents low-level tampering with ## Installation and configuration overview There are various methods and deployment tools that you can use to install and configure Microsoft Defender ATP for Mac. In general you'll need to take the following steps: - - [Register macOS devices](#register-macos-devices) with Windows Defender ATP + - [Register macOS devices](#register-macos-devices) with Microsoft Defender ATP - Deploy Microsoft Defender ATP for Mac using any of the following deployment methods and tools: - [Microsoft Intune based deployment](#microsoft-intune-based-deployment) - [JAMF based deployment](#jamf-based-deployment) @@ -68,14 +68,14 @@ Use any of the supported methods to deploy Microsoft Defender ATP for Mac ## Microsoft Intune based deployment ### Download installation and onboarding packages -Download the installation and onboarding packages from Windows Defender Security Center: -1. In Windows Defender Security Center, go to **Settings > Machine Management > Onboarding**. +Download the installation and onboarding packages from Microsoft Defender Security Center: +1. In Microsoft Defender Security Center, go to **Settings > Machine Management > Onboarding**. 2. In Section 1 of the page, set operating system to **Linux, macOS, iOS or Android** and Deployment method to **Mobile Device Management / Microsoft Intune**. 3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory. 4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory. 5. Download IntuneAppUtil from https://docs.microsoft.com/en-us/intune/lob-apps-macos. - ![Windows Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) + ![Microsoft Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) 6. From a command prompt, verify that you have the three files. Extract the contents of the .zip files: @@ -198,13 +198,13 @@ You need to be familiar with JAMF administration tasks, have a JAMF tenant, and ### Download installation and onboarding packages -Download the installation and onboarding packages from Windows Defender Security Center: -1. In Windows Defender Security Center, go to **Settings > Machine Management > Onboarding**. +Download the installation and onboarding packages from Microsoft Defender Security Center: +1. In Microsoft Defender Security Center, go to **Settings > Machine Management > Onboarding**. 2. In Section 1 of the page, set operating system to **Linux, macOS, iOS or Android** and Deployment method to **Mobile Device Management / Microsoft Intune**. 3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory. 4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory. - ![Windows Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) + ![Microsoft Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) 5. From a command prompt, verify that you have the two files. Extract the contents of the .zip files: @@ -377,18 +377,18 @@ You can check that machines are correctly onboarded by creating a script. For ex /Library/Extensions/wdavkext.kext/Contents/Resources/Tools/wdavconfig.py | grep -E 'orgid effective : [-a-zA-Z0-9]+' ``` -This script returns 0 if Microsoft Defender ATP is registered with the Windows Defender ATP service, and another exit code if it is not installed or registered. +This script returns 0 if Microsoft Defender ATP is registered with the Microsoft Defender ATP service, and another exit code if it is not installed or registered. ## Manual deployment ### Download installation and onboarding packages -Download the installation and onboarding packages from Windows Defender Security Center: -1. In Windows Defender Security Center, go to **Settings > Machine Management > Onboarding**. +Download the installation and onboarding packages from Microsoft Defender Security Center: +1. In Microsoft Defender Security Center, go to **Settings > Machine Management > Onboarding**. 2. In Section 1 of the page, set operating system to **Linux, macOS, iOS or Android** and Deployment method to **Local script**. 3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory. 4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory. - ![Windows Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) + ![Microsoft Defender Security Center screenshot](images/MDATP_2_IntuneAppUtil.png) 5. From a command prompt, verify that you have the two files. Extract the contents of the .zip files: @@ -471,7 +471,7 @@ Or, from a command line: - Microsoft Defender ATP is not yet optimized for performance or disk space. - Centrally managed uninstall using Intune is still in development. To uninstall (as a workaround) a manual uninstall action has to be completed on each client device). - Geo preference for telemetry traffic is not yet supported. Cloud traffic (definition updates) routed to US only. -- Full Windows Defender ATP integration is not yet available +- Full Microsoft Defender ATP integration is not yet available - Not localized yet - There might be accessibility issues diff --git a/windows/security/threat-protection/windows-defender-antivirus/oldTOC.md b/windows/security/threat-protection/windows-defender-antivirus/oldTOC.md index 8c12b9ff9d..f9457d3f21 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/oldTOC.md +++ b/windows/security/threat-protection/windows-defender-antivirus/oldTOC.md @@ -1,7 +1,7 @@ # [Windows Defender Antivirus in Windows 10](windows-defender-antivirus-in-windows-10.md) -## [Windows Defender AV in the Windows Defender Security Center app](windows-defender-security-center-antivirus.md) +## [Windows Defender AV in the Microsoft Defender Security Center app](windows-defender-security-center-antivirus.md) ## [Windows Defender AV on Windows Server 2016](windows-defender-antivirus-on-windows-server-2016.md) diff --git a/windows/security/threat-protection/windows-defender-antivirus/prevent-end-user-interaction-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/prevent-end-user-interaction-windows-defender-antivirus.md index a156c5b1dd..2de691deb9 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/prevent-end-user-interaction-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/prevent-end-user-interaction-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can use Group Policy to prevent users on endpoints from seeing the Windows Defender Antivirus interface. You can also prevent them from pausing scans. @@ -35,7 +35,7 @@ With the setting set to **Disabled** or not configured: ![Scheenshot of Windows Security showing the shield icon and virus and threat protection section](images/defender/wdav-headless-mode-off-1703.png) >[!NOTE] ->Hiding the interface will also prevent Windows Defender Antivirus notifications from appearing on the endpoint. Windows Defender Advanced Threat Protection notifications will still appear. You can also individually [Configure the notifications that appear on endpoints](configure-notifications-windows-defender-antivirus.md) +>Hiding the interface will also prevent Windows Defender Antivirus notifications from appearing on the endpoint. Microsoft Defender Advanced Threat Protection notifications will still appear. You can also individually [Configure the notifications that appear on endpoints](configure-notifications-windows-defender-antivirus.md) In earlier versions of Windows 10, the setting will hide the Windows Defender client interface. If the user attempts to open it, they will receive a warning "Your system administrator has restricted access to this app.": diff --git a/windows/security/threat-protection/windows-defender-antivirus/report-monitor-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/report-monitor-windows-defender-antivirus.md index 6e22b89713..ed1703b544 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/report-monitor-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/report-monitor-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) There are a number of ways you can review protection status and alerts, depending on the management tool you are using for Windows Defender Antivirus. diff --git a/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md index 1718727ee2..4de3b92e99 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 11/16/2018 --- @@ -18,7 +18,7 @@ ms.date: 11/16/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) If Windows Defender Antivirus is configured to detect and remediate threats on your device, Windows Defender Antivirus quarantines suspicious files. If you are certain these files do not present a threat, you can restore them. diff --git a/windows/security/threat-protection/windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md index ae3a67efe6..8be9dc4db1 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) After an Windows Defender Antivirus scan completes, whether it is an [on-demand](run-scan-windows-defender-antivirus.md) or [scheduled scan](scheduled-catch-up-scans-windows-defender-antivirus.md), the results are recorded and you can view the results. diff --git a/windows/security/threat-protection/windows-defender-antivirus/run-scan-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/run-scan-windows-defender-antivirus.md index 15a9be7d17..d3cdab176e 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/run-scan-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/run-scan-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can run an on-demand scan on individual endpoints. These scans will start immediately, and you can define parameters for the scan, such as the location or type. diff --git a/windows/security/threat-protection/windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md index 9a451f585c..42310786b4 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 12/10/2018 --- @@ -18,7 +18,7 @@ ms.date: 12/10/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) > [!NOTE] > By default, Windows Defender Antivirus checks for an update 15 minutes before the time of any scheduled scans. You can [Manage the schedule for when protection updates should be downloaded and applied](manage-protection-update-schedule-windows-defender-antivirus.md) to override this default. diff --git a/windows/security/threat-protection/windows-defender-antivirus/specify-cloud-protection-level-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/specify-cloud-protection-level-windows-defender-antivirus.md index 089226de14..0f59883e27 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/specify-cloud-protection-level-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/specify-cloud-protection-level-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can specify the level of cloud-protection offered by Windows Defender Antivirus with Group Policy and System Center Configuration Manager. diff --git a/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-reporting.md b/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-reporting.md index 85b5650e9c..935339fb99 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-reporting.md +++ b/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-reporting.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) When you use [Windows Analytics Update Compliance to obtain reporting into the protection status of machines or endpoints](/windows/deployment/update/update-compliance-using#wdav-assessment) in your network that are using Windows Defender Antivirus, you may encounter problems or issues. diff --git a/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md index 0bdced17c6..1fcbeccd26 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/11/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/11/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) If you encounter a problem with Windows Defender Antivirus, you can search the tables in this topic to find a matching issue and potential solution. @@ -29,7 +29,7 @@ The tables list: - [Internal Windows Defender Antivirus client error codes (used by Microsoft during development and testing)](#internal-error-codes) >[!TIP] ->You can also visit the Windows Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working: +>You can also visit the Microsoft Defender ATP demo website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the following features are working: >- Cloud-delivered protection >- Fast learning (including Block at first sight) diff --git a/windows/security/threat-protection/windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md index dcb8f76069..1d000caef1 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can use [Group Policy](https://msdn.microsoft.com/library/ee663280(v=vs.85).aspx) to configure and manage Windows Defender Antivirus on your endpoints. diff --git a/windows/security/threat-protection/windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md index 566898708b..b8eff33e4a 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) If you are using System Center Configuration Manager or Microsoft Intune to manage the endpoints on your network, you can also use them to manage Windows Defender Antivirus scans. diff --git a/windows/security/threat-protection/windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md index 8e45003982..9fc1d12db3 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) You can use PowerShell to perform various functions in Windows Defender. Similar to the command prompt or command line, PowerShell is a task-based command-line shell and scripting language designed especially for system administration, and you can read more about it at the [PowerShell hub on MSDN](https://msdn.microsoft.com/powershell/mt173057.aspx). diff --git a/windows/security/threat-protection/windows-defender-antivirus/use-wmi-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/use-wmi-windows-defender-antivirus.md index c4f3239b0c..ef249aaa42 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/use-wmi-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/use-wmi-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Management Instrumentation (WMI) is a scripting interface that allows you to retrieve, modify, and update settings. diff --git a/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md index 59ec895413..6dbff069e4 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Microsoft next-gen technologies in Windows Defender Antivirus provide near-instant, automated protection against new and emerging threats. To dynamically identify new threats, these technologies work with large sets of interconnected data in the Microsoft Intelligent Security Graph and powerful artificial intelligence (AI) systems driven by advanced machine learning models. diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md index 449d118890..34ee455d8a 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,17 +18,17 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus is automatically enabled and installed on endpoints and devices that are running Windows 10. However, on endpoints and devices that are protected with a non-Microsoft antivirus or antimalware app, Windows Defender Antivirus will automatically disable itself. You can then choose to enable an optional, limited protection feature, called [limited periodic scanning](limited-periodic-scanning-windows-defender-antivirus.md). -If you are also using Windows Defender Advanced Threat Protection, then Windows Defender AV will enter a passive mode. +If you are also using Microsoft Defender Advanced Threat Protection, then Windows Defender AV will enter a passive mode. -The following matrix illustrates the states that Windows Defender AV will enter when third-party antivirus products or Windows Defender ATP are also used. +The following matrix illustrates the states that Windows Defender AV will enter when third-party antivirus products or Microsoft Defender ATP are also used. -Windows version | Antimalware protection offered by | Organization enrolled in Windows Defender ATP | Windows Defender AV state +Windows version | Antimalware protection offered by | Organization enrolled in Microsoft Defender ATP | Windows Defender AV state -|-|-|- Windows 10 | A third-party product that is not offered or developed by Microsoft | Yes | Passive mode Windows 10 | A third-party product that is not offered or developed by Microsoft | No | Automatic disabled mode @@ -59,11 +59,11 @@ This table indicates the functionality and features that are available in each s State | Description | [Real-time protection](configure-real-time-protection-windows-defender-antivirus.md) and [cloud-delivered protection](enable-cloud-protection-windows-defender-antivirus.md) | [Limited periodic scanning availability](limited-periodic-scanning-windows-defender-antivirus.md) | [File scanning and detection information](customize-run-review-remediate-scans-windows-defender-antivirus.md) | [Threat remediation](configure-remediation-windows-defender-antivirus.md) | [Security intelligence updates](manage-updates-baselines-windows-defender-antivirus.md) :-|:-|:-:|:-:|:-:|:-:|:-: -Passive mode | Windows Defender AV will not be used as the antivirus app, and threats will not be remediated by Windows Defender AV. Files will be scanned and reports will be provided for threat detections which are shared with the Windows Defender ATP service. | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] +Passive mode | Windows Defender AV will not be used as the antivirus app, and threats will not be remediated by Windows Defender AV. Files will be scanned and reports will be provided for threat detections which are shared with the Microsoft Defender ATP service. | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] Automatic disabled mode | Windows Defender AV will not be used as the antivirus app. Files will not be scanned and threats will not be remediated. | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] Active mode | Windows Defender AV is used as the antivirus app on the machine. All configuration made with Configuration Manager, Group Policy, Intune, or other management products will apply. Files will be scanned and threats remediated, and detection information will be reported in your configuration tool (such as Configuration Manager or the Windows Defender AV app on the machine itself). | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] -If you are enrolled in Windows Defender ATP and you are using a third party antimalware product then passive mode is enabled because [the service requires common information sharing from the Windows Defender AV service](../windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md) in order to properly monitor your devices and network for intrusion attempts and attacks. +If you are enrolled in Microsoft Defender ATP and you are using a third party antimalware product then passive mode is enabled because [the service requires common information sharing from the Windows Defender AV service](../windows-defender-atp/defender-compatibility.md) in order to properly monitor your devices and network for intrusion attempts and attacks. Automatic disabled mode is enabled so that if the protection offered by a third-party antivirus product expires or otherwise stops providing real-time protection from viruses, malware or other threats, Windows Defender AV will automatically enable itself to ensure antivirus protection is maintained on the endpoint. It also allows you to enable [limited periodic scanning](limited-periodic-scanning-windows-defender-antivirus.md), which uses the Windows Defender AV engine to periodically check for threats in addition to your main antivirus app. @@ -72,7 +72,7 @@ In passive and automatic disabled mode, you can still [manage updates for Window If you uninstall the other product, and choose to use Windows Defender AV to provide protection to your endpoints, Windows Defender AV will automatically return to its normal active mode. >[!WARNING] ->You should not attempt to disable, stop, or modify any of the associated services used by Windows Defender AV, Windows Defender ATP, or the Windows Security app. +>You should not attempt to disable, stop, or modify any of the associated services used by Windows Defender AV, Microsoft Defender ATP, or the Windows Security app. > >This includes the *wscsvc*, *SecurityHealthService*, *MsSense*, *Sense*, *WinDefend*, or *MsMpEng* services and process. Manually modifying these services can cause severe instability on your endpoints and open your network to infections and attacks. > diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md index de41958e5e..1e9f3e028e 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus is a built-in antimalware solution that provides next generation protection for desktops, portable computers, and servers. diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016.md index f38d0b3823..b272703ba3 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Antivirus is available on Windows Server 2016. In some instances it is referred to as Endpoint Protection - however, the protection engine is the same. diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-offline.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-offline.md index e860e58f69..f8279e4b09 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-offline.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-offline.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Offline is an antimalware scanning tool that lets you boot and run a scan from a trusted environment. The scan runs from outside the normal Windows kernel so it can target malware that attempts to bypass the Windows shell, such as viruses and rootkits that infect or overwrite the master boot record (MBR). diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md index 4b78bafccb..739439af03 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md @@ -9,7 +9,7 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel +author: justinha ms.author: v-anbic ms.date: 09/03/2018 --- @@ -18,7 +18,7 @@ ms.date: 09/03/2018 **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) In Windows 10, version 1703 and later, the Windows Defender app is part of the Windows Security. @@ -36,7 +36,7 @@ Settings that were previously part of the Windows Defender client and main Windo See the [Windows Security topic](/windows/threat-protection/windows-defender-security-center/windows-defender-security-center) for more information on other Windows security features that can be monitored in the app. >[!NOTE] ->The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Windows Defender Security Center web portal that is used to review and manage [Windows Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). +>The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal that is used to review and manage [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). **Review virus and threat protection settings in the Windows Security app:** From 86160de735f398daaf15c681e17e8e49e8b9d8a4 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:37:59 -0700 Subject: [PATCH 137/737] update product name in ac --- ...ation-control-events-centrally-using-advanced-hunting.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/querying-application-control-events-centrally-using-advanced-hunting.md b/windows/security/threat-protection/windows-defender-application-control/querying-application-control-events-centrally-using-advanced-hunting.md index b1018f5e79..af40ccb8a4 100644 --- a/windows/security/threat-protection/windows-defender-application-control/querying-application-control-events-centrally-using-advanced-hunting.md +++ b/windows/security/threat-protection/windows-defender-application-control/querying-application-control-events-centrally-using-advanced-hunting.md @@ -16,12 +16,12 @@ ms.date: 12/06/2018 A Windows Defender Application Control (WDAC) policy logs events locally in Windows Event Viewer in either enforced or audit mode. While Event Viewer helps to see the impact on a single system, IT Pros want to gauge the impact across many systems. -In November 2018, we added functionality in Windows Defender Advanced Threat Protection (Windows Defender ATP) that makes it easy to view WDAC events centrally from all systems that are connected to Windows Defender ATP. +In November 2018, we added functionality in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) that makes it easy to view WDAC events centrally from all systems that are connected to Microsoft Defender ATP. -Advanced hunting in Windows Defender ATP allows customers to query data using a rich set of capabilities. WDAC events can be queried with using an ActionType that starts with “AppControl”. +Advanced hunting in Microsoft Defender ATP allows customers to query data using a rich set of capabilities. WDAC events can be queried with using an ActionType that starts with “AppControl”. This capability is supported beginning with Windows version 1607. -Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP: +Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Microsoft Defender ATP: ``` MiscEvents From e415425c97c022173af243931e9e4ba0420a5ce1 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:39:39 -0700 Subject: [PATCH 138/737] update ag product names --- .../configure-wd-app-guard.md | 2 +- .../windows-defender-application-guard/faq-wd-app-guard.md | 2 +- .../windows-defender-application-guard/install-wd-app-guard.md | 2 +- .../windows-defender-application-guard/reqs-wd-app-guard.md | 2 +- .../test-scenarios-wd-app-guard.md | 2 +- .../windows-defender-application-guard/wd-app-guard-overview.md | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md index 80dbb5a03b..062d1ab9f3 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md @@ -13,7 +13,7 @@ ms.date: 10/17/2017 # Configure Windows Defender Application Guard policy settings -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Application Guard (Application Guard) works with Group Policy to help you manage your organization's computer settings. By using Group Policy, you can configure a setting once, and then copy it onto many computers. For example, you can set up multiple security settings in a GPO, which is linked to a domain, and then apply all those settings to every computer in the domain. diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 8be213c70e..2bd4f7732a 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -14,7 +14,7 @@ ms.date: 03/28/2019 # Frequently asked questions - Windows Defender Application Guard -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Answering frequently asked questions about Windows Defender Application Guard (Application Guard) features, integration with the Windows operating system, and general configuration. diff --git a/windows/security/threat-protection/windows-defender-application-guard/install-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/install-wd-app-guard.md index 7bbb3edc4c..b340cb1da4 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/install-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/install-wd-app-guard.md @@ -14,7 +14,7 @@ ms.date: 02/19/2019 # Prepare to install Windows Defender Application Guard **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ## Review system requirements diff --git a/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md index fc2f274410..7ae28017bf 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/reqs-wd-app-guard.md @@ -13,7 +13,7 @@ ms.date: 11/09/2017 # System requirements for Windows Defender Application Guard -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) The threat landscape is continually evolving. While hackers are busy developing new techniques to breach enterprise networks by compromising workstations, phishing schemes remain one of the top ways to lure employees into social engineering attacks. Windows Defender Application Guard is designed to help prevent old, and newly emerging attacks, to help keep employees productive. diff --git a/windows/security/threat-protection/windows-defender-application-guard/test-scenarios-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/test-scenarios-wd-app-guard.md index 092d966221..e372ec40e6 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/test-scenarios-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/test-scenarios-wd-app-guard.md @@ -14,7 +14,7 @@ ms.date: 03/15/2019 # Application Guard testing scenarios -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) We've come up with a list of scenarios that you can use to test hardware-based isolation in your organization. diff --git a/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview.md b/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview.md index 41cf3d2bd0..e8dd4b2672 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview.md +++ b/windows/security/threat-protection/windows-defender-application-guard/wd-app-guard-overview.md @@ -13,7 +13,7 @@ ms.date: 03/28/2019 # Windows Defender Application Guard overview -**Applies to:** [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +**Applies to:** [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Windows Defender Application Guard (Application Guard) is designed to help prevent old and newly emerging attacks to help keep employees productive. Using our unique hardware isolation approach, our goal is to destroy the playbook that attackers use by making current attack methods obsolete. From f7f39d937e9fe0e669b5c319b9b39fab276ccaa0 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:41:49 -0700 Subject: [PATCH 139/737] update wdsc folder with product name and author --- .../windows-defender-security-center/oldTOC.md | 8 ++++---- .../wdsc-account-protection.md | 4 ++-- .../wdsc-app-browser-control.md | 4 ++-- .../wdsc-customize-contact-information.md | 4 ++-- .../wdsc-device-performance-health.md | 4 ++-- .../wdsc-device-security.md | 4 ++-- .../wdsc-family-options.md | 4 ++-- .../wdsc-firewall-network-protection.md | 4 ++-- .../wdsc-hide-notifications.md | 4 ++-- .../wdsc-virus-threat-protection.md | 4 ++-- .../wdsc-windows-10-in-s-mode.md | 4 ++-- .../windows-defender-security-center.md | 6 +++--- 12 files changed, 27 insertions(+), 27 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-security-center/oldTOC.md b/windows/security/threat-protection/windows-defender-security-center/oldTOC.md index 92d6f70f01..4ca95e5608 100644 --- a/windows/security/threat-protection/windows-defender-security-center/oldTOC.md +++ b/windows/security/threat-protection/windows-defender-security-center/oldTOC.md @@ -1,9 +1,9 @@ -# [The Windows Defender Security Center app](windows-defender-security-center.md) +# [The Microsoft Defender Security Center app](windows-defender-security-center.md) -## [Customize the Windows Defender Security Center app for your organization](wdsc-customize-contact-information.md) -## [Hide Windows Defender Security Center app notifications](wdsc-hide-notifications.md) -## [Manage Windows Defender Security Center in Windows 10 in S mode](wdsc-windows-10-in-s-mode.md) +## [Customize the Microsoft Defender Security Center app for your organization](wdsc-customize-contact-information.md) +## [Hide Microsoft Defender Security Center app notifications](wdsc-hide-notifications.md) +## [Manage Microsoft Defender Security Center in Windows 10 in S mode](wdsc-windows-10-in-s-mode.md) ## [Virus and threat protection](wdsc-virus-threat-protection.md) ## [Account protection](wdsc-account-protection.md) ## [Firewall and network protection](wdsc-firewall-network-protection.md) diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-account-protection.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-account-protection.md index eb6433dadd..f0717a9b1f 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-account-protection.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-account-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md index f8a95593d9..4b44cd3f09 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-app-browser-control.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-customize-contact-information.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-customize-contact-information.md index 30cc2c355d..f8ac757f91 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-customize-contact-information.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-customize-contact-information.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md index 83258123af..4abfa20ff5 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-performance-health.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md index 5df35a849e..6b828b0347 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-device-security.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 10/02/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md index cc7706945e..84f4c82eae 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-family-options.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md index 1aea2d2d26..29be0d4d92 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-firewall-network-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md index b936dc1dcb..98abf1ab59 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-hide-notifications.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md index f4ee73535b..db876c5abf 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-virus-threat-protection.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md index f13658dab4..b17f381379 100644 --- a/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md +++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 04/30/2018 --- diff --git a/windows/security/threat-protection/windows-defender-security-center/windows-defender-security-center.md b/windows/security/threat-protection/windows-defender-security-center/windows-defender-security-center.md index 60a0d3278b..938c532c3d 100644 --- a/windows/security/threat-protection/windows-defender-security-center/windows-defender-security-center.md +++ b/windows/security/threat-protection/windows-defender-security-center/windows-defender-security-center.md @@ -9,8 +9,8 @@ ms.mktglfcycl: manage ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium -author: andreabichsel -ms.author: v-anbic +author: justinha +ms.author: justinha ms.date: 10/02/2018 --- @@ -37,7 +37,7 @@ In Windows 10, version 1803, the app has two new areas, **Account protection** a ![Screen shot of the Windows Security app showing that the device is protected and five icons for each of the features](images/security-center-home.png) >[!NOTE] ->The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Windows Defender Security Center web portal console that is used to review and manage [Windows Defender Advanced Threat Protection](https://docs.microsoft.com/windows/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection). +>The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal console that is used to review and manage [Microsoft Defender Advanced Threat Protection](https://docs.microsoft.com/windows/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection). You can't uninstall the Windows Security app, but you can do one of the following: From 0c3ad2be39a454727316522f1366bfe1625d7cb3 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Wed, 10 Apr 2019 15:42:04 -0700 Subject: [PATCH 140/737] updeate redirects --- .openpublishing.redirection.json | 171 +++++++++++++++++++++++-------- 1 file changed, 128 insertions(+), 43 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 068c8c88fa..fc7f418de0 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -856,14 +856,19 @@ "redirect_document_id": true }, { +"source_path": "windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-features", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-features", -"redirect_document_id": false +"source_path": "windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection", +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", @@ -871,8 +876,8 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/alerts-queue", +"source_path": "windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { @@ -881,8 +886,8 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/api-portal-mapping-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/api-portal-mapping", +"source_path": "windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { @@ -891,8 +896,8 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access", +"source_path": "windows/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { @@ -901,53 +906,33 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status", -"redirect_document_id": true -}, -{ "source_path": "windows/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/community-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/community", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-arcsight", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-email-notifications", "redirect_document_id": true }, { @@ -956,33 +941,118 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-gp-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-gp", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-mdm-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-mdm", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-non-windows", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-sccm-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-sccm", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-script-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-script", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-endpoints-vdi-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-endpoints-vdi", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-server-endpoints-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-siem-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-siem", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-splunk-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-splunk", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/dashboard-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/dashboard-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/custom-ti-api-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/custom-ti-api", "redirect_document_id": true }, { @@ -991,16 +1061,31 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/data-storage-privacy", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/defender-compatibility-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/defender-compatibility", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/enable-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/enable-custom-ti", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection", "redirect_document_id": true From 50e74994efceb3b662077ed34aa53e2ea7d6d00c Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:48:58 -0700 Subject: [PATCH 141/737] remove wdatp in links --- .../microsoft-defender-atp/alerts.md | 18 +++++------ .../collect-investigation-package.md | 2 +- .../create-alert-by-reference.md | 2 +- .../exposed-apis-create-app-nativeapp.md | 2 +- .../exposed-apis-create-app-webapp.md | 2 +- .../exposed-apis-odata-samples.md | 6 ++-- .../microsoft-defender-atp/files.md | 8 ++--- .../get-alert-info-by-id.md | 2 +- .../microsoft-defender-atp/get-alerts.md | 2 +- .../get-domain-related-alerts.md | 2 +- .../get-domain-related-machines.md | 2 +- .../get-file-information.md | 2 +- .../get-file-related-alerts.md | 2 +- .../get-file-related-machines.md | 2 +- .../get-ip-related-alerts.md | 2 +- .../get-ip-related-machines.md | 2 +- .../get-machine-by-id.md | 2 +- .../get-machine-log-on-users.md | 2 +- .../get-machine-related-alerts.md | 2 +- .../get-machineaction-object.md | 2 +- .../get-machineactions-collection.md | 2 +- .../microsoft-defender-atp/get-machines.md | 2 +- .../get-package-sas-uri.md | 2 +- .../get-ti-indicators-collection.md | 2 +- .../get-user-information.md | 2 +- .../get-user-related-machines.md | 2 +- .../microsoft-defender-atp/isolate-machine.md | 4 +-- .../microsoft-defender-atp/machine-tags.md | 2 +- .../microsoft-defender-atp/machine.md | 30 +++++++++---------- .../microsoft-defender-atp/machineaction.md | 22 +++++++------- .../offboard-machine-api.md | 2 +- .../post-ti-indicator.md | 6 ++-- .../restrict-code-execution.md | 4 +-- .../stop-and-quarantine-file.md | 2 +- .../microsoft-defender-atp/ti-indicator.md | 8 ++--- .../unisolate-machine.md | 4 +-- .../unrestrict-code-execution.md | 4 +-- .../microsoft-defender-atp/update-alert.md | 2 +- .../microsoft-defender-atp/use-apis.md | 2 +- .../microsoft-defender-atp/user.md | 4 +-- 40 files changed, 87 insertions(+), 87 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts.md b/windows/security/threat-protection/microsoft-defender-atp/alerts.md index d2fdf0726f..761f24b3f0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts.md @@ -27,14 +27,14 @@ Represents an alert entity in Microsoft Defender ATP. # Methods Method|Return Type |Description :---|:---|:--- -[Get alert](get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md) | [Alert](alerts-windows-defender-advanced-threat-protection-new.md) | Get a single [alert](alerts-windows-defender-advanced-threat-protection-new.md) object. -[List alerts](get-alerts-windows-defender-advanced-threat-protection-new.md) | [Alert](alerts-windows-defender-advanced-threat-protection-new.md) collection | List [alert](alerts-windows-defender-advanced-threat-protection-new.md) collection. -[Create alert](create-alert-by-reference-windows-defender-advanced-threat-protection-new.md)|[Alert](alerts-windows-defender-advanced-threat-protection-new.md)|Create an alert based on event data obtained from [Advanced Hunting](run-advanced-query-api.md). -[List related domains](get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md)|Domain collection| List URLs associated with the alert. -[List related files](get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md) | [File](files-windows-defender-advanced-threat-protection-new.md) collection | List the [file](files-windows-defender-advanced-threat-protection-new.md) entities that are associated with the [alert](alerts-windows-defender-advanced-threat-protection-new.md). -[List related IPs](get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md) | IP collection | List IPs that are associated with the alert. -[Get related machines](get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md) | [Machine](machine-windows-defender-advanced-threat-protection-new.md) | The [machine](machine-windows-defender-advanced-threat-protection-new.md) that is associated with the [alert](alerts-windows-defender-advanced-threat-protection-new.md). -[Get related users](get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md) | [User](user-windows-defender-advanced-threat-protection-new.md) | The [user](user-windows-defender-advanced-threat-protection-new.md) that is associated with the [alert](alerts-windows-defender-advanced-threat-protection-new.md). +[Get alert](get-alert-info-by-id.md) | [Alert](alerts.md) | Get a single [alert](alerts.md) object. +[List alerts](get-alerts.md) | [Alert](alerts.md) collection | List [alert](alerts.md) collection. +[Create alert](create-alert-by-reference.md)|[Alert](alerts.md)|Create an alert based on event data obtained from [Advanced Hunting](run-advanced-query-api.md). +[List related domains](get-alert-related-domain-info.md)|Domain collection| List URLs associated with the alert. +[List related files](get-alert-related-files-info.md) | [File](files.md) collection | List the [file](files.md) entities that are associated with the [alert](alerts.md). +[List related IPs](get-alert-related-ip-info.md) | IP collection | List IPs that are associated with the alert. +[Get related machines](get-alert-related-machine-info.md) | [Machine](machine.md) | The [machine](machine.md) that is associated with the [alert](alerts.md). +[Get related users](get-alert-related-user-info.md) | [User](user.md) | The [user](user.md) that is associated with the [alert](alerts.md). # Properties @@ -57,7 +57,7 @@ alertCreationTime | DateTimeOffset | The date and time (in UTC) the alert was cr lastEventTime | DateTimeOffset | The last occurance of the event that triggered the alert on the same machine. firstEventTime | DateTimeOffset | The first occurance of the event that triggered the alert on that machine. resolvedTime | DateTimeOffset | The date and time in which the status of the alert was changed to 'Resolved'. -machineId | String | ID of a [machine](machine-windows-defender-advanced-threat-protection-new.md) entity that is associated with the alert. +machineId | String | ID of a [machine](machine.md) entity that is associated with the alert. # JSON representation ``` diff --git a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md index c828e5a9b8..49aa2a3832 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md +++ b/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package.md @@ -60,7 +60,7 @@ Parameter | Type | Description Comment | String | Comment to associate with the action. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md index f21867e552..67376f8415 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md +++ b/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference.md @@ -69,7 +69,7 @@ category| String | Category of the alert. The property values are: 'None', 'Susp ## Response -If successful, this method returns 200 OK, and a new [alert](alerts-windows-defender-advanced-threat-protection-new.md) object in the response body. If event with the specified properties (_reportId_, _eventTime_ and _machineId_) was not found - 404 Not Found. +If successful, this method returns 200 OK, and a new [alert](alerts.md) object in the response body. If event with the specified properties (_reportId_, _eventTime_ and _machineId_) was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md index 5d6e59a7c2..4d8dbed5a8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-nativeapp.md @@ -82,7 +82,7 @@ This page explains how to create an AAD application, get an access token to Micr For instance, - To [run advanced queries](run-advanced-query-api.md), select 'Run advanced queries' permission - - To [isolate a machine](isolate-machine-windows-defender-advanced-threat-protection-new.md), select 'Isolate machine' permission + - To [isolate a machine](isolate-machine.md), select 'Isolate machine' permission To determine which permission you need, look at the **Permissions** section in the API you are interested to call. diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md index e0800f060b..9d46f63fe7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-create-app-webapp.md @@ -74,7 +74,7 @@ This page explains how to create an AAD application, get an access token to Micr For instance, - To [run advanced queries](run-advanced-query-api.md), select 'Run advanced queries' permission - - To [isolate a machine](isolate-machine-windows-defender-advanced-threat-protection-new.md), select 'Isolate machine' permission + - To [isolate a machine](isolate-machine.md), select 'Isolate machine' permission - To determine which permission you need, please look at the **Permissions** section in the API you are interested to call. ![Image of select permissions](images/webapp-select-permission.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md index 3eb6c6eb6b..393903a87e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md +++ b/windows/security/threat-protection/microsoft-defender-atp/exposed-apis-odata-samples.md @@ -29,9 +29,9 @@ ms.date: 11/15/2018 ### Properties that supports $filter: -- [Alert](alerts-windows-defender-advanced-threat-protection-new.md): Id, IncidentId, AlertCreationTime, Status, Severity and Category. -- [Machine](machine-windows-defender-advanced-threat-protection-new.md): Id, ComputerDnsName, LastSeen, LastIpAddress, HealthStatus, OsPlatform, RiskScore, MachineTags and RbacGroupId. -- [MachineAction](machineaction-windows-defender-advanced-threat-protection-new.md): Id, Status, MachineId, Type, Requestor and CreationDateTimeUtc. +- [Alert](alerts.md): Id, IncidentId, AlertCreationTime, Status, Severity and Category. +- [Machine](machine.md): Id, ComputerDnsName, LastSeen, LastIpAddress, HealthStatus, OsPlatform, RiskScore, MachineTags and RbacGroupId. +- [MachineAction](machineaction.md): Id, Status, MachineId, Type, Requestor and CreationDateTimeUtc. ### Example 1 diff --git a/windows/security/threat-protection/microsoft-defender-atp/files.md b/windows/security/threat-protection/microsoft-defender-atp/files.md index 8a89db801c..85db198384 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/files.md +++ b/windows/security/threat-protection/microsoft-defender-atp/files.md @@ -27,10 +27,10 @@ Represent a file entity in Microsoft Defender ATP. # Methods Method|Return Type |Description :---|:---|:--- -[Get file](get-file-information-windows-defender-advanced-threat-protection-new.md) | [file](files-windows-defender-advanced-threat-protection-new.md) | Get a single file -[List file related alerts](get-file-related-alerts-windows-defender-advanced-threat-protection-new.md) | [alert](alerts-windows-defender-advanced-threat-protection-new.md) collection | Get the [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities that are associated with the file. -[List file related machines](get-file-related-machines-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) collection | Get the [machine](machine-windows-defender-advanced-threat-protection-new.md) entities associated with the alert. -[file statistics](get-file-statistics-windows-defender-advanced-threat-protection-new.md) | Statistics summary | Retrieves the prevalence for the given file. +[Get file](get-file-information.md) | [file](files.md) | Get a single file +[List file related alerts](get-file-related-alerts.md) | [alert](alerts.md) collection | Get the [alert](alerts.md) entities that are associated with the file. +[List file related machines](get-file-related-machines.md) | [machine](machine.md) collection | Get the [machine](machine.md) entities associated with the alert. +[file statistics](get-file-statistics.md) | Statistics summary | Retrieves the prevalence for the given file. # Properties diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md index 270323aae6..f8eea40763 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id.md @@ -56,7 +56,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful, this method returns 200 OK, and the [alert](alerts-windows-defender-advanced-threat-protection-new.md) entity in the response body. If alert with the specified id was not found - 404 Not Found. +If successful, this method returns 200 OK, and the [alert](alerts.md) entity in the response body. If alert with the specified id was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md index 6fb1bbbf17..46726fec58 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-alerts.md @@ -64,7 +64,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful, this method returns 200 OK, and a list of [alert](alerts-windows-defender-advanced-threat-protection-new.md) objects in the response body. +If successful, this method returns 200 OK, and a list of [alert](alerts.md) objects in the response body. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md index 6e1478cb72..4201cbf4d8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts.md @@ -61,7 +61,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and domain exists - 200 OK with list of [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities. If domain does not exist - 404 Not Found. +If successful and domain exists - 200 OK with list of [alert](alerts.md) entities. If domain does not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md index b6ee9ba801..9168ffdd7e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines.md @@ -56,7 +56,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and domain exists - 200 OK with list of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities. If domain do not exist - 404 Not Found. +If successful and domain exists - 200 OK with list of [machine](machine.md) entities. If domain do not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md index 0315a79f79..474e98f273 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-information.md @@ -56,7 +56,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and file exists - 200 OK with the [file](files-windows-defender-advanced-threat-protection-new.md) entity in the body. If file does not exist - 404 Not Found. +If successful and file exists - 200 OK with the [file](files.md) entity in the body. If file does not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md index f3709ad133..d28d08c520 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts.md @@ -59,7 +59,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and file exists - 200 OK with list of [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities in the body. If file do not exist - 404 Not Found. +If successful and file exists - 200 OK with list of [alert](alerts.md) entities in the body. If file do not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md index 599b60b82e..88d1a2e8ea 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines.md @@ -58,7 +58,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and file exists - 200 OK with list of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities in the body. If file do not exist - 404 Not Found. +If successful and file exists - 200 OK with list of [machine](machine.md) entities in the body. If file do not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md index 28b400897f..711a6def63 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts.md @@ -57,7 +57,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and IP exists - 200 OK with list of [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities in the body. If IP do not exist - 404 Not Found. +If successful and IP exists - 200 OK with list of [alert](alerts.md) entities in the body. If IP do not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md index a8875b7324..9cf6c3784a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines.md @@ -57,7 +57,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and IP exists - 200 OK with list of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities in the body. If IP do not exist - 404 Not Found. +If successful and IP exists - 200 OK with list of [machine](machine.md) entities in the body. If IP do not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md index 017460ba7e..93cc44b4f7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id.md @@ -59,7 +59,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and machine exists - 200 OK with the [machine](machine-windows-defender-advanced-threat-protection-new.md) entity in the body. +If successful and machine exists - 200 OK with the [machine](machine.md) entity in the body. If machine with the specified id was not found - 404 Not Found. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md index a4233e222f..4c87962798 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users.md @@ -55,7 +55,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and machine exist - 200 OK with list of [user](user-windows-defender-advanced-threat-protection-new.md) entities in the body. If machine was not found - 404 Not Found. +If successful and machine exist - 200 OK with list of [user](user.md) entities in the body. If machine was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md index 0250ee9a19..97d706a373 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts.md @@ -57,7 +57,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and machine exists - 200 OK with list of [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities in the body. If machine was not found - 404 Not Found. +If successful and machine exists - 200 OK with list of [alert](alerts.md) entities in the body. If machine was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md index 3cb8e46926..3740226c86 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineaction-object.md @@ -57,7 +57,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful, this method returns 200, Ok response code with a [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entity. If machine action entity with the specified id was not found - 404 Not Found. +If successful, this method returns 200, Ok response code with a [Machine Action](machineaction.md) entity. If machine action entity with the specified id was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md index 9bfc5cab5b..6dc52d9c42 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machineactions-collection.md @@ -60,7 +60,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful, this method returns 200, Ok response code with a collection of [machineAction](machineaction-windows-defender-advanced-threat-protection-new.md) entities. +If successful, this method returns 200, Ok response code with a collection of [machineAction](machineaction.md) entities. ## Example 1 diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md index 6d6a921754..db7af73a74 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-machines.md @@ -58,7 +58,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and machines exists - 200 OK with list of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities in the body. If no recent machines - 404 Not Found. +If successful and machines exists - 200 OK with list of [machine](machine.md) entities in the body. If no recent machines - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md index b4e18b9069..8b8827362c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri.md @@ -23,7 +23,7 @@ ms.date: 12/08/2017 [!include[Prerelease information](prerelease.md)] -Get a URI that allows downloading of an [investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md). +Get a URI that allows downloading of an [investigation package](collect-investigation-package.md). ## Permissions One of the following permissions is required to call this API. To learn more, including how to choose permissions, see [Use Microsoft Defender ATP APIs](apis-intro.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md index 6fe62b0834..69018dc935 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection.md @@ -58,7 +58,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful, this method returns 200, Ok response code with a collection of [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entities. +If successful, this method returns 200, Ok response code with a collection of [Indicator](ti-indicator.md) entities. >[!Note] > If the Application has 'Ti.ReadWrite.All' permission, it will be exposed to all Indicators. Otherwise, it will be exposed only to the Indicators it created. diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md index ee1b42726f..276869768f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-information.md @@ -47,7 +47,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and user exists - 200 OK with [user](user-windows-defender-advanced-threat-protection-new.md) entity in the body. If user does not exist - 404 Not Found. +If successful and user exists - 200 OK with [user](user.md) entity in the body. If user does not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md index 9562240757..f4304056b4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md +++ b/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines.md @@ -60,7 +60,7 @@ Authorization | String | Bearer {token}. **Required**. Empty ## Response -If successful and user exists - 200 OK with list of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities in the body. If user does not exist - 404 Not Found. +If successful and user exists - 200 OK with list of [machine](machine.md) entities in the body. If user does not exist - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md index a83da49e7f..d8aec274af 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/isolate-machine.md @@ -67,7 +67,7 @@ IsolationType | String | Type of the isolation. Allowed values are: 'Full' or 'S ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example @@ -109,4 +109,4 @@ Content-type: application/json ``` -To unisolate a machine, see [Release machine from isolation](unisolate-machine-windows-defender-advanced-threat-protection-new.md). +To unisolate a machine, see [Release machine from isolation](unisolate-machine.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md b/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md index 624d4c2542..899c910e78 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine-tags.md @@ -83,7 +83,7 @@ You can manage tags from the Actions button or by selecting a machine from the M ![Image of adding tags on a machine](images/atp-tag-management.png) ## Add machine tags using APIs -For more information, see [Add or remove machine tags API](add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md). +For more information, see [Add or remove machine tags API](add-or-remove-machine-tags.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/machine.md b/windows/security/threat-protection/microsoft-defender-atp/machine.md index c118700037..c7a7c7bf2b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machine.md @@ -24,29 +24,29 @@ ms.topic: article # Methods Method|Return Type |Description :---|:---|:--- -[List machines](get-machines-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) collection | List set of [machine](machine-windows-defender-advanced-threat-protection-new.md) entities in the org. -[Get machine](get-machine-by-id-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) | Get a [machine](machine-windows-defender-advanced-threat-protection-new.md) by its identity. -[Get logged on users](get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md) | [user](user-windows-defender-advanced-threat-protection-new.md) collection | Get the set of [User](user-windows-defender-advanced-threat-protection-new.md) that logged on to the [machine](machine-windows-defender-advanced-threat-protection-new.md). -[Get related alerts](get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md) | [alert](alerts-windows-defender-advanced-threat-protection-new.md) collection | Get the set of [alert](alerts-windows-defender-advanced-threat-protection-new.md) entities that were raised on the [machine](machine-windows-defender-advanced-threat-protection-new.md). -[Add or Remove machine tags](add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) | Add or Remove tag to a specific machine. -[Find machines by IP](find-machines-by-ip-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) collection | Find machines seen with IP. +[List machines](get-machines.md) | [machine](machine.md) collection | List set of [machine](machine.md) entities in the org. +[Get machine](get-machine-by-id.md) | [machine](machine.md) | Get a [machine](machine.md) by its identity. +[Get logged on users](get-machine-log-on-users.md) | [user](user.md) collection | Get the set of [User](user.md) that logged on to the [machine](machine.md). +[Get related alerts](get-machine-related-alerts.md) | [alert](alerts.md) collection | Get the set of [alert](alerts.md) entities that were raised on the [machine](machine.md). +[Add or Remove machine tags](add-or-remove-machine-tags.md) | [machine](machine.md) | Add or Remove tag to a specific machine. +[Find machines by IP](find-machines-by-ip.md) | [machine](machine.md) collection | Find machines seen with IP. # Properties Property | Type | Description :---|:---|:--- -id | String | [machine](machine-windows-defender-advanced-threat-protection-new.md) identity. -computerDnsName | String | [machine](machine-windows-defender-advanced-threat-protection-new.md) fully qualified name. -firstSeen | DateTimeOffset | First date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Microsoft Defender ATP. -lastSeen | DateTimeOffset | Last date and time where the [machine](machine-windows-defender-advanced-threat-protection-new.md) was observed by Microsoft Defender ATP. +id | String | [machine](machine.md) identity. +computerDnsName | String | [machine](machine.md) fully qualified name. +firstSeen | DateTimeOffset | First date and time where the [machine](machine.md) was observed by Microsoft Defender ATP. +lastSeen | DateTimeOffset | Last date and time where the [machine](machine.md) was observed by Microsoft Defender ATP. osPlatform | String | OS platform. osVersion | String | OS Version. -lastIpAddress | String | Last IP on local NIC on the [machine](machine-windows-defender-advanced-threat-protection-new.md). -lastExternalIpAddress | String | Last IP through which the [machine](machine-windows-defender-advanced-threat-protection-new.md) accessed the internet. +lastIpAddress | String | Last IP on local NIC on the [machine](machine.md). +lastExternalIpAddress | String | Last IP through which the [machine](machine.md) accessed the internet. agentVersion | String | Version of Microsoft Defender ATP agent. osBuild | Nullable long | OS build number. -healthStatus | Enum | [machine](machine-windows-defender-advanced-threat-protection-new.md) health status. Possible values are: "Active", "Inactive", "ImpairedCommunication", "NoSensorData" and "NoSensorDataImpairedCommunication" +healthStatus | Enum | [machine](machine.md) health status. Possible values are: "Active", "Inactive", "ImpairedCommunication", "NoSensorData" and "NoSensorDataImpairedCommunication" rbacGroupId | Int | RBAC Group ID. rbacGroupName | String | RBAC Group Name. riskScore | Nullable Enum | Risk score as evaluated by Microsoft Defender ATP. Possible values are: 'None', 'Low', 'Medium' and 'High'. -aadDeviceId | Nullable Guid | AAD Device ID (when [machine](machine-windows-defender-advanced-threat-protection-new.md) is Aad Joined). -machineTags | String collection | Set of [machine](machine-windows-defender-advanced-threat-protection-new.md) tags. \ No newline at end of file +aadDeviceId | Nullable Guid | AAD Device ID (when [machine](machine.md) is Aad Joined). +machineTags | String collection | Set of [machine](machine.md) tags. diff --git a/windows/security/threat-protection/microsoft-defender-atp/machineaction.md b/windows/security/threat-protection/microsoft-defender-atp/machineaction.md index 66271b6633..6bf2a9b4b6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machineaction.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machineaction.md @@ -26,21 +26,21 @@ ms.date: 12/08/2017 Method|Return Type |Description :---|:---|:--- -[List MachineActions](get-machineactions-collection-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | List [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entities. -[Get MachineAction](get-machineaction-object-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Get a single [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entity. -[Collect investigation package](collect-investigation-package-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Collect investigation package from a [machine](machine-windows-defender-advanced-threat-protection-new.md). -[Get investigation package SAS URI](get-package-sas-uri-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Get URI for downloading the investigation package. -[Isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Isolate [machine](machine-windows-defender-advanced-threat-protection-new.md) from network. -[Release machine from isolation](unisolate-machine-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Release [machine](machine-windows-defender-advanced-threat-protection-new.md) from Isolation. -[Restrict app execution](restrict-code-execution-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Restrict application execution. -[Remove app restriction](unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Remove application execution restriction. -[Run antivirus scan](run-av-scan-windows-defender-advanced-threat-protection-new.md) | [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Run an AV scan using Windows Defender (when applicable). -[Offboard machine](offboard-machine-api-windows-defender-advanced-threat-protection-new.md)|[Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) | Offboard [machine](machine-windows-defender-advanced-threat-protection-new.md) from Microsoft Defender ATP. +[List MachineActions](get-machineactions-collection.md) | [Machine Action](machineaction.md) | List [Machine Action](machineaction.md) entities. +[Get MachineAction](get-machineaction-object.md) | [Machine Action](machineaction.md) | Get a single [Machine Action](machineaction.md) entity. +[Collect investigation package](collect-investigation-package.md) | [Machine Action](machineaction.md) | Collect investigation package from a [machine](machine.md). +[Get investigation package SAS URI](get-package-sas-uri.md) | [Machine Action](machineaction.md) | Get URI for downloading the investigation package. +[Isolate machine](isolate-machine.md) | [Machine Action](machineaction.md) | Isolate [machine](machine.md) from network. +[Release machine from isolation](unisolate-machine.md) | [Machine Action](machineaction.md) | Release [machine](machine.md) from Isolation. +[Restrict app execution](restrict-code-execution.md) | [Machine Action](machineaction.md) | Restrict application execution. +[Remove app restriction](unrestrict-code-execution.md) | [Machine Action](machineaction.md) | Remove application execution restriction. +[Run antivirus scan](run-av-scan.md) | [Machine Action](machineaction.md) | Run an AV scan using Windows Defender (when applicable). +[Offboard machine](offboard-machine-api.md)|[Machine Action](machineaction.md) | Offboard [machine](machine.md) from Microsoft Defender ATP. # Properties Property | Type | Description :---|:---|:--- -id | Guid | Identity of the [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) entity. +id | Guid | Identity of the [Machine Action](machineaction.md) entity. type | Enum | Type of the action. Possible values are: "RunAntiVirusScan", "Offboard", "CollectInvestigationPackage", "Isolate", "Unisolate", "StopAndQuarantineFile", "RestrictCodeExecution" and "UnrestrictCodeExecution" requestor | String | Identity of the person that executed the action. requestorComment | String | Comment that was written when issuing the action. diff --git a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md index 738b4d31ee..89ba1d35f3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md +++ b/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api.md @@ -59,7 +59,7 @@ Parameter | Type | Description Comment | String | Comment to associate with the action. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md index cbeeeeb7ef..a9b58bd743 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md +++ b/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator.md @@ -28,7 +28,7 @@ ms.date: 12/08/2017 > Currently this API is supported only for AppOnly context requests. (See [Get access with application context](exposed-apis-create-app-webapp.md) for more information) -- Submits or Updates new [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity. +- Submits or Updates new [Indicator](ti-indicator.md) entity. ## Permissions @@ -60,7 +60,7 @@ In the request body, supply a JSON object with the following parameters: Parameter | Type | Description :---|:---|:--- -indicatorValue | String | Identity of the [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity. **Required** +indicatorValue | String | Identity of the [Indicator](ti-indicator.md) entity. **Required** indicatorType | Enum | Type of the indicator. Possible values are: "FileSha1", "FileSha256", "IpAddress", "DomainName" and "Url". **Required** action | Enum | The action that will be taken if the indicator will be discovered in the organization. Possible values are: "Alert", "AlertAndBlock", and "Allowed". **Required** title | String | Indicator alert title. **Optional** @@ -71,7 +71,7 @@ recommendedActions | String | TI indicator alert recommended actions. **Optional ## Response -- If successful, this method returns 200 - OK response code and the created / updated [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity in the response body. +- If successful, this method returns 200 - OK response code and the created / updated [Indicator](ti-indicator.md) entity in the response body. - If not successful: this method return 400 - Bad Request / 409 - Conflict with the failure reason. Bad request usually indicates incorrect body and Conflict can happen if you try to submit an Indicator that conflicts with an existing Indicator type or Action. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md index 6443996f08..be5f7fdb33 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution.md @@ -60,7 +60,7 @@ Parameter | Type | Description Comment | String | Comment to associate with the action. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example @@ -101,5 +101,5 @@ Content-type: application/json ``` -To remove code execution restriction from a machine, see [Remove app restriction](unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md). +To remove code execution restriction from a machine, see [Remove app restriction](unrestrict-code-execution.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md index 9fde8c8592..c6f058274c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md +++ b/windows/security/threat-protection/microsoft-defender-atp/stop-and-quarantine-file.md @@ -62,7 +62,7 @@ Comment | String | Comment to associate with the action. **Required**. Sha1 | String | Sha1 of the file to stop and quarantine on the machine. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md index 944fdf6c3c..7c15c26dd6 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md +++ b/windows/security/threat-protection/microsoft-defender-atp/ti-indicator.md @@ -24,16 +24,16 @@ ms.topic: article Method|Return Type |Description :---|:---|:--- -[List Indicators](get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md) | [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) Collection | List [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entities. -[Submit Indicator](post-ti-indicator-windows-defender-advanced-threat-protection-new.md) | [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) | Submits [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity. -[Delete Indicator](delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md) | No Content | Deletes [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity. +[List Indicators](get-ti-indicators-collection.md) | [Indicator](ti-indicator.md) Collection | List [Indicator](ti-indicator.md) entities. +[Submit Indicator](post-ti-indicator.md) | [Indicator](ti-indicator.md) | Submits [Indicator](ti-indicator.md) entity. +[Delete Indicator](delete-ti-indicator-by-id.md) | No Content | Deletes [Indicator](ti-indicator.md) entity. - See the corresponding [page](https://securitycenter.windows.com/preferences2/custom_ti_indicators/files) in the portal: # Properties Property | Type | Description :---|:---|:--- -indicatorValue | String | Identity of the [Indicator](ti-indicator-windows-defender-advanced-threat-protection-new.md) entity. +indicatorValue | String | Identity of the [Indicator](ti-indicator.md) entity. indicatorType | Enum | Type of the indicator. Possible values are: "FileSha1", "FileSha256", "IpAddress", "DomainName" and "Url" title | String | Indicator alert title. creationTimeDateTimeUtc | DateTimeOffset | The date and time when the indicator was created. diff --git a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md index c1bfd3a410..51d270d828 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine.md @@ -61,7 +61,7 @@ Parameter | Type | Description Comment | String | Comment to associate with the action. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example @@ -105,5 +105,5 @@ Content-type: application/json ``` -To isolate a machine, see [Isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md). +To isolate a machine, see [Isolate machine](isolate-machine.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md index 9680a57aec..3df0690019 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md +++ b/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution.md @@ -59,7 +59,7 @@ Parameter | Type | Description Comment | String | Comment to associate with the action. **Required**. ## Response -If successful, this method returns 201 - Created response code and [Machine Action](machineaction-windows-defender-advanced-threat-protection-new.md) in the response body. +If successful, this method returns 201 - Created response code and [Machine Action](machineaction.md) in the response body. ## Example @@ -101,4 +101,4 @@ Content-type: application/json ``` -To restrict code execution on a machine, see [Restrict app execution](restrict-code-execution-windows-defender-advanced-threat-protection-new.md). \ No newline at end of file +To restrict code execution on a machine, see [Restrict app execution](restrict-code-execution.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md index 9752745d78..1a81370b13 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/update-alert.md +++ b/windows/security/threat-protection/microsoft-defender-atp/update-alert.md @@ -64,7 +64,7 @@ determination | String | Specifies the determination of the alert. The property ## Response -If successful, this method returns 200 OK, and the [alert](alerts-windows-defender-advanced-threat-protection-new.md) entity in the response body with the updated properties. If alert with the specified id was not found - 404 Not Found. +If successful, this method returns 200 OK, and the [alert](alerts.md) entity in the response body with the updated properties. If alert with the specified id was not found - 404 Not Found. ## Example diff --git a/windows/security/threat-protection/microsoft-defender-atp/use-apis.md b/windows/security/threat-protection/microsoft-defender-atp/use-apis.md index a152053d8d..5f3f6b0f0a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use-apis.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use-apis.md @@ -27,5 +27,5 @@ ms.date: 11/28/2018 Topic | Description :---|:--- [Microsoft Defender ATP API overview](apis-intro.md) | Learn how to access to Microsoft Defender ATP Public API and on which context. -[Supported Microsoft Defender ATP APIs](exposed-apis-list.md) | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. Examples include APIs for [alert resource type](alerts-windows-defender-advanced-threat-protection-new.md), [domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md), or even actions such as [isolate machine](isolate-machine-windows-defender-advanced-threat-protection-new.md). +[Supported Microsoft Defender ATP APIs](exposed-apis-list.md) | Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses. Examples include APIs for [alert resource type](alerts.md), [domain related alerts](get-domain-related-alerts.md), or even actions such as [isolate machine](isolate-machine.md). How to use APIs - Samples | Learn how to use Advanced hunting APIs and multiple APIs such as PowerShell. Other examples include [schedule advanced hunting using Microsoft Flow](run-advanced-query-sample-ms-flow.md) or [OData queries](exposed-apis-odata-samples.md). diff --git a/windows/security/threat-protection/microsoft-defender-atp/user.md b/windows/security/threat-protection/microsoft-defender-atp/user.md index 12ad0a75b8..3f001924f1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/user.md +++ b/windows/security/threat-protection/microsoft-defender-atp/user.md @@ -21,7 +21,7 @@ ms.date: 12/08/2017 Method|Return Type |Description :---|:---|:--- -[List User related alerts](get-user-related-alerts-windows-defender-advanced-threat-protection-new.md) | [alert](alerts-windows-defender-advanced-threat-protection-new.md) collection | List all the alerts that are associated with a [user](user-windows-defender-advanced-threat-protection-new.md). -[List User related machines](get-user-related-machines-windows-defender-advanced-threat-protection-new.md) | [machine](machine-windows-defender-advanced-threat-protection-new.md) collection | List all the machines that were logged on by a [user](user-windows-defender-advanced-threat-protection-new.md). +[List User related alerts](get-user-related-alerts.md) | [alert](alerts.md) collection | List all the alerts that are associated with a [user](user.md). +[List User related machines](get-user-related-machines.md) | [machine](machine.md) collection | List all the machines that were logged on by a [user](user.md). From 83e0716c221c998fdbd189e1e5ecd01129717cf7 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:54:47 -0700 Subject: [PATCH 142/737] fix broken link --- .../threat-protection/microsoft-defender-atp/alerts-queue.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md index fbe92937d8..f2aaa2d6aa 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md @@ -90,7 +90,7 @@ Limit the alerts queue view by selecting the OS platform that you're interested If you have specific machine groups that you're interested in checking the alerts on, you can select the groups to limit the alerts queue view to display just those machine groups. ### Associated threat -Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics-dashboard.md). +Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics.md). ## Related topics From 7330fb3e0f9f74669f473e5302b9fe228b65587a Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 15:57:08 -0700 Subject: [PATCH 143/737] fix file name typo unhealhty to unhealthy --- .../threat-protection/microsoft-defender-atp/TOC.md | 6 +++--- .../microsoft-defender-atp/check-sensor-status.md | 2 +- ...x-unhealhty-sensors.md => fix-unhealthy-sensors.md} | 0 .../microsoft-defender-atp/machines-view-overview.md | 2 +- .../microsoft-defender-atp/secure-score-dashboard.md | 10 +++++----- 5 files changed, 10 insertions(+), 10 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{fix-unhealhty-sensors.md => fix-unhealthy-sensors.md} (100%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 297f7f6173..0a5682ebc9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -392,9 +392,9 @@ ## [Troubleshoot Microsoft Defender ATP](troubleshoot-overview.md) ###Troubleshoot sensor state #### [Check sensor state](check-sensor-status.md) -#### [Fix unhealthy sensors](fix-unhealhty-sensors.md) -#### [Inactive machines](fix-unhealhty-sensors.md#inactive-machines) -#### [Misconfigured machines](fix-unhealhty-sensors.md#misconfigured-machines) +#### [Fix unhealthy sensors](fix-unhealthy-sensors.md) +#### [Inactive machines](fix-unhealthy-sensors.md#inactive-machines) +#### [Misconfigured machines](fix-unhealthy-sensors.md#misconfigured-machines) #### [Review sensor events and errors on machines with Event Viewer](event-error-codes.md) ### [Troubleshoot Microsoft Defender ATP service issues](troubleshoot.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md index 4e675729c2..d5c18cff52 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md +++ b/windows/security/threat-protection/microsoft-defender-atp/check-sensor-status.md @@ -57,4 +57,4 @@ In the **Machines list**, you can download a full list of all the machines in yo >Export the list in CSV format to display the unfiltered data. The CSV file will include all machines in the organization, regardless of any filtering applied in the view itself and can take a significant amount of time to download, depending on how large your organization is. ## Related topic -- [Fix unhealthy sensors in Microsoft Defender ATP](fix-unhealhty-sensors.md) +- [Fix unhealthy sensors in Microsoft Defender ATP](fix-unhealthy-sensors.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md rename to windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md diff --git a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md index 657eac1d96..79720ee3a3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview.md @@ -74,7 +74,7 @@ Filter the list to view specific machines grouped together by the following mach - No sensor data - Impaired communications - For more information on how to address issues on misconfigured machines see, [Fix unhealthy sensors](fix-unhealhty-sensors.md). + For more information on how to address issues on misconfigured machines see, [Fix unhealthy sensors](fix-unhealthy-sensors.md). - **Inactive** – Machines that have completely stopped sending signals for more than 7 days. diff --git a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md index 61f17b701f..ebf3512bf7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard.md @@ -40,7 +40,7 @@ You can take the following actions to increase the overall security score of you - Fix sensor data collection - Fix impaired communications -For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). +For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). ### Windows Defender Antivirus (Windows Defender AV) optimization For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for Windows Defender AV is fulfilled. @@ -82,7 +82,7 @@ This tile shows you the exact number of machines that require the latest securit You can take the following actions to increase the overall security score of your organization: - Install the latest security updates - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). For more information, see [Windows Update Troubleshooter](https://support.microsoft.com/help/4027322/windows-windows-update-troubleshooter). @@ -229,7 +229,7 @@ You can take the following actions to increase the overall security score of you - Secure public profile - Verify secure configuration of third-party firewall - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). For more information, see [Windows Defender Firewall with Advanced Security](https://docs.microsoft.com/windows/security/identity-protection/windows-firewall/windows-firewall-with-advanced-security). @@ -251,7 +251,7 @@ You can take the following actions to increase the overall security score of you - Resume protection on all drives - Ensure drive compatibility - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). For more information, see [Bitlocker](https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-overview). @@ -274,7 +274,7 @@ You can take the following actions to increase the overall security score of you - Ensure hardware and software prerequisites are met - Turn on Credential Guard - Fix sensor data collection - - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealhty-sensors.md). + - The Microsoft Defender ATP service relies on sensor data collection to determine the security state of a machine. The service will not be able to determine the security state of machines that are not reporting sensor data properly. Therefore, it's important to ensure that sensor data collection is working properly. For more information, see [Fix unhealthy sensors](fix-unhealthy-sensors.md). For more information, see [Manage Windows Defender Credential Guard](https://docs.microsoft.com/windows/security/identity-protection/credential-guard/credential-guard-manage). From fa3be69c2ea5de103ac17c14e2a2269dee9353fb Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:00:21 -0700 Subject: [PATCH 144/737] fix anchor links --- .../microsoft-defender-atp/configure-proxy-internet.md | 4 ++-- .../microsoft-defender-atp/fix-unhealthy-sensors.md | 4 ++-- .../microsoft-defender-atp/troubleshoot-onboarding.md | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md index 46c3f745a8..07cedb408e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet.md @@ -38,7 +38,7 @@ The WinHTTP configuration setting is independent of the Windows Internet (WinINe - Web Proxy Auto-discovery Protocol (WPAD) > [!NOTE] -> If you're using Transparent proxy or WPAD in your network topology, you don't need special configuration settings. For more information on Microsoft Defender ATP URL exclusions in the proxy, see [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). +> If you're using Transparent proxy or WPAD in your network topology, you don't need special configuration settings. For more information on Microsoft Defender ATP URL exclusions in the proxy, see [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server). - Manual static proxy configuration: @@ -163,7 +163,7 @@ The tool checks the connectivity of Microsoft Defender ATP service URLs that Mic If at least one of the connectivity options returns a (200) status, then the Microsoft Defender ATP client can communicate with the tested URL properly using this connectivity method.

-However, if the connectivity check results indicate a failure, an HTTP error is displayed (see HTTP Status Codes). You can then use the URLs in the table shown in [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-windows-defender-atp-service-urls-in-the-proxy-server). The URLs you'll use will depend on the region selected during the onboarding procedure. +However, if the connectivity check results indicate a failure, an HTTP error is displayed (see HTTP Status Codes). You can then use the URLs in the table shown in [Enable access to Microsoft Defender ATP service URLs in the proxy server](#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server). The URLs you'll use will depend on the region selected during the onboarding procedure. > [!NOTE] > When the TelemetryProxyServer is set, in Registry or via Group Policy, Microsoft Defender ATP will fall back to direct if it can't access the defined proxy. diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md index 5c2458d459..d874f34507 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md +++ b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md @@ -64,7 +64,7 @@ The following suggested actions can help fix issues related to a misconfigured m - [Ensure the machine has Internet connection](troubleshoot-onboarding.md#troubleshoot-onboarding-issues-on-the-machine)
The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-microsoft-defender-atp-service-urls)
Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. If you took corrective actions and the machine status is still misconfigured, [open a support ticket](https://go.microsoft.com/fwlink/?LinkID=761093&clcid=0x409). @@ -76,7 +76,7 @@ Follow theses actions to correct known issues related to a misconfigured machine - [Ensure the machine has Internet connection](troubleshoot-onboarding.md#troubleshoot-onboarding-issues-on-the-machine)
The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to report sensor data and communicate with the Microsoft Defender ATP service. -- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls)
+- [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-microsoft-defender-atp-service-urls)
Verify the proxy configuration completed successfully, that WinHTTP can discover and communicate through the proxy server in your environment, and that the proxy server allows traffic to the Microsoft Defender ATP service URLs. - [Ensure the diagnostic data service is enabled](troubleshoot-onboarding.md#ensure-the-diagnostics-service-is-enabled)
diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md index b46b9c95ac..69c3b620ca 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md @@ -238,7 +238,7 @@ The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to repo WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. -To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-windows-defender-atp-service-urls) topic. +To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Microsoft Defender ATP service URLs](configure-proxy-internet.md#verify-client-connectivity-to-microsoft-defender-atp-service-urls) topic. If the verification fails and your environment is using a proxy to connect to the Internet, then follow the steps described in [Configure proxy and Internet connectivity settings](configure-proxy-internet.md) topic. From d33361fe9b7259bf758294bc45ed08691227c41d Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Wed, 10 Apr 2019 16:03:15 -0700 Subject: [PATCH 145/737] redirects --- .openpublishing.redirection.json | 57 +++++++++++++++++-- .../microsoft-defender-atp/TOC.md | 6 +- ...ty-sensors.md => fix-unhealthy-sensors.md} | 0 3 files changed, 54 insertions(+), 9 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{fix-unhealhty-sensors.md => fix-unhealthy-sensors.md} (100%) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 9f59abb6d7..7b46d8e423 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -1101,13 +1101,13 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection", +"source_path": "windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration", "redirect_document_id": true }, { @@ -1116,18 +1116,28 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/event-error-codes-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/event-error-codes", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/experiment-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/experiment-custom-ti", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/general-settings-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/general-settings-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/fix-unhealthy-sensors", "redirect_document_id": true }, { @@ -1136,36 +1146,71 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-domain-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-domain", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-files-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-files", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-ip", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-machines-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-machines", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-user-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-user", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/licensing-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/licensing-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/licensing-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/licensing", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection", "redirect_document_id": true diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 297f7f6173..0a5682ebc9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -392,9 +392,9 @@ ## [Troubleshoot Microsoft Defender ATP](troubleshoot-overview.md) ###Troubleshoot sensor state #### [Check sensor state](check-sensor-status.md) -#### [Fix unhealthy sensors](fix-unhealhty-sensors.md) -#### [Inactive machines](fix-unhealhty-sensors.md#inactive-machines) -#### [Misconfigured machines](fix-unhealhty-sensors.md#misconfigured-machines) +#### [Fix unhealthy sensors](fix-unhealthy-sensors.md) +#### [Inactive machines](fix-unhealthy-sensors.md#inactive-machines) +#### [Misconfigured machines](fix-unhealthy-sensors.md#misconfigured-machines) #### [Review sensor events and errors on machines with Event Viewer](event-error-codes.md) ### [Troubleshoot Microsoft Defender ATP service issues](troubleshoot.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md b/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/fix-unhealhty-sensors.md rename to windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors.md From e4003c516e9d1bdf45757da7fa3b4473e0a429a2 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:03:17 -0700 Subject: [PATCH 146/737] threat-analytics-dashboard filename --- .../security/threat-protection/microsoft-defender-atp/TOC.md | 2 +- .../threat-protection/microsoft-defender-atp/alerts-queue.md | 2 +- .../{threat-analytics.md => threat-analytics-dashboard.md} | 0 3 files changed, 2 insertions(+), 2 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{threat-analytics.md => threat-analytics-dashboard.md} (100%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 0a5682ebc9..3c6dda9da7 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -70,7 +70,7 @@ ### [Secure score](overview-secure-score.md) -### [Threat analytics](threat-analytics.md) +### [Threat analytics](threat-analytics-dashboard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md index f2aaa2d6aa..fbe92937d8 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md @@ -90,7 +90,7 @@ Limit the alerts queue view by selecting the OS platform that you're interested If you have specific machine groups that you're interested in checking the alerts on, you can select the groups to limit the alerts queue view to display just those machine groups. ### Associated threat -Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics.md). +Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics-dashboard.md). ## Related topics diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md From cded9b9c19b8b743a1026539e52b847858c23a51 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:04:22 -0700 Subject: [PATCH 147/737] ta --- .../security/threat-protection/microsoft-defender-atp/TOC.md | 2 +- .../threat-protection/microsoft-defender-atp/alerts-queue.md | 2 +- .../microsoft-defender-atp/overview-secure-score.md | 4 ++-- .../microsoft-defender-atp/portal-overview.md | 2 +- .../microsoft-defender-atp/security-operations-dashboard.md | 2 +- .../microsoft-defender-atp/threat-analytics-dashboard.md | 2 +- .../security/threat-protection/microsoft-defender-atp/use.md | 2 +- 7 files changed, 8 insertions(+), 8 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 3c6dda9da7..0a5682ebc9 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -70,7 +70,7 @@ ### [Secure score](overview-secure-score.md) -### [Threat analytics](threat-analytics-dashboard.md) +### [Threat analytics](threat-analytics.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md index fbe92937d8..f2aaa2d6aa 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md +++ b/windows/security/threat-protection/microsoft-defender-atp/alerts-queue.md @@ -90,7 +90,7 @@ Limit the alerts queue view by selecting the OS platform that you're interested If you have specific machine groups that you're interested in checking the alerts on, you can select the groups to limit the alerts queue view to display just those machine groups. ### Associated threat -Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics-dashboard.md). +Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics.md). ## Related topics diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index ec0b0550d8..7aad2ad004 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -78,5 +78,5 @@ Within the tile, you can click on each control to see the recommended optimizati Clicking the link under the Misconfigured machines column opens up the **Machines list** with filters applied to show only the list of machines where the recommendation is applicable. You can export the list in Excel to create a target collection and apply relevant policies using a management solution of your choice. ## Related topic -- [Threat analytics](threat-analytics-dashboard.md) -- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard.md) +- [Threat analytics](threat-analytics.md) +- [Threat analytics for Spectre and Meltdown](threat-analytics.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md index 349f685730..07ac3f1831 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/portal-overview.md @@ -114,4 +114,4 @@ Icon | Description - [Understand the Microsoft Defender Advanced Threat Protection portal](use.md) - [View the Security operations dashboard](security-operations-dashboard.md) - [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) -- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) \ No newline at end of file +- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md index ee063018af..9d6eced4c4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard.md @@ -130,5 +130,5 @@ This tile shows audit events based on detections from various security component - [Understand the Microsoft Defender Advanced Threat Protection portal](use.md) - [Portal overview](portal-overview.md) - [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) -- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) +- [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md index f4b1020dc3..c4b5ae9d96 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md @@ -65,5 +65,5 @@ The **Mitigation status** and **Mitigation status over time** shows the endpoint ## Related topics -- [Threat analytics for Spectre and Meltdown](threat-analytics-dashboard.md) +- [Threat analytics for Spectre and Meltdown](threat-analytics.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/use.md b/windows/security/threat-protection/microsoft-defender-atp/use.md index df066b9b7e..501f6f9019 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use.md @@ -42,6 +42,6 @@ Topic | Description [Portal overview](portal-overview.md) | Understand the portal layout and area descriptions. [View the Security operations dashboard](security-operations-dashboard.md) | The Microsoft Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) | The **Secure Score dashboard** expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. -[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. +[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. From 554538ed0198797c6435eb5675953ecf09b7188e Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:05:01 -0700 Subject: [PATCH 148/737] file name --- .../{threat-analytics-dashboard.md => threat-analytics.md} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{threat-analytics-dashboard.md => threat-analytics.md} (100%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/threat-analytics-dashboard.md rename to windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md From a7ccceaaf30ac88f326c4f5818ccf165ff5e2514 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:08:43 -0700 Subject: [PATCH 149/737] troubleshoot file name --- .../microsoft-defender-advanced-threat-protection.md | 2 +- .../{troubleshoot.md => troubleshoot-mdatp.md} | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename windows/security/threat-protection/microsoft-defender-atp/{troubleshoot.md => troubleshoot-mdatp.md} (100%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md index 8efb9d7b22..d9cd1f742a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md @@ -123,7 +123,7 @@ Topic | Description [Overview](overview.md) | Understand the concepts behind the capabilities in Microsoft Defender ATP so you take full advantage of the complete threat protection platform. [Get started](get-started.md) | Learn about the requirements of the platform and the initial steps you need to take to get started with Microsoft Defender ATP. [Configure and manage capabilities](onboard.md)| Configure and manage the individual capabilities in Microsoft Defender ATP. -[Troubleshoot Microsoft Defender ATP](troubleshoot-wdatp.md) | Learn how to address issues that you might encounter while using the platform. +[Troubleshoot Microsoft Defender ATP](troubleshoot-mdatp.md) | Learn how to address issues that you might encounter while using the platform. ## Related topic [Microsoft Defender ATP helps detect sophisticated threats](https://www.microsoft.com/itshowcase/Article/Content/854/Windows-Defender-ATP-helps-detect-sophisticated-threats) diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-mdatp.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/troubleshoot.md rename to windows/security/threat-protection/microsoft-defender-atp/troubleshoot-mdatp.md From c3fc41a124a8b9c2bb8eadac0df46004ad483b0b Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:12:18 -0700 Subject: [PATCH 150/737] update overview topic --- .../overview-of-threat-mitigations-in-windows-10.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md index bb4bb74070..c3738fd5f6 100644 --- a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md +++ b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md @@ -103,7 +103,7 @@ Windows Defender Antivirus in Windows 10 uses a multi-pronged approach to improv For more information, see [Windows Defender in Windows 10](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) and [Windows Defender Overview for Windows Server](https://technet.microsoft.com/windows-server-docs/security/windows-defender/windows-defender-overview-windows-server). -For information about Windows Defender Advanced Threat Protection, a service that helps enterprises to detect, investigate, and respond to advanced and targeted attacks on their networks, see [Windows Defender Advanced Threat Protection (ATP)](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) (resources) and [Windows Defender Advanced Threat Protection (ATP)](https://technet.microsoft.com/itpro/windows/keep-secure/windows-defender-advanced-threat-protection) (documentation). +For information about Microsoft Defender Advanced Threat Protection, a service that helps enterprises to detect, investigate, and respond to advanced and targeted attacks on their networks, see [Microsoft Defender Advanced Threat Protection (ATP)](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) (resources) and [Microsoft Defender Advanced Threat Protection (ATP)](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection) (documentation). ### Data Execution Prevention @@ -442,13 +442,13 @@ Examples: #### EMET-related products -Microsoft Consulting Services (MCS) and Microsoft Support/Premier Field Engineering (PFE) offer a range of options for EMET, support for EMET, and EMET-related reporting and auditing products such as the EMET Enterprise Reporting Service (ERS). For any enterprise customers who use such products today or who are interested in similar capabilities, we recommend evaluating [Windows Defender Advanced Threat Protection](windows-defender-atp/windows-defender-advanced-threat-protection.md) (ATP). +Microsoft Consulting Services (MCS) and Microsoft Support/Premier Field Engineering (PFE) offer a range of options for EMET, support for EMET, and EMET-related reporting and auditing products such as the EMET Enterprise Reporting Service (ERS). For any enterprise customers who use such products today or who are interested in similar capabilities, we recommend evaluating [Microsoft Defender Advanced Threat Protection](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) (ATP). ## Related topics - [Security and Assurance in Windows Server 2016](https://technet.microsoft.com/windows-server-docs/security/security-and-assurance) -- [Windows Defender Advanced Threat Protection (ATP) - resources](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) -- [Windows Defender Advanced Threat Protection (ATP) - documentation](windows-defender-atp/windows-defender-advanced-threat-protection.md) +- [Microsoft Defender Advanced Threat Protection (ATP) - resources](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) +- [Microsoft Defender Advanced Threat Protection (ATP) - documentation](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) - [Exchange Online Advanced Threat Protection Service Description](https://technet.microsoft.com/library/exchange-online-advanced-threat-protection-service-description.aspx) - [Office 365 Advanced Threat Protection](https://products.office.com/en-us/exchange/online-email-threat-protection) - [Microsoft Malware Protection Center](https://www.microsoft.com/en-us/security/portal/mmpc/default.aspx) From eab433bf3c27688c26c95404fe0676e6a8884386 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:20:27 -0700 Subject: [PATCH 151/737] update url --- ...curity-center-atp.md => windows-defender-security-center.md} | 1 - .../overview-of-threat-mitigations-in-windows-10.md | 2 +- .../windows-defender-antivirus-compatibility.md | 2 +- 3 files changed, 2 insertions(+), 3 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{windows-defender-security-center-atp.md => windows-defender-security-center.md} (99%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md similarity index 99% rename from windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md rename to windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md index 89b74b62a0..7c7ef2d01e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center-atp.md +++ b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md @@ -15,7 +15,6 @@ manager: dansimp audience: ITPro ms.collection: M365-security-compliance ms.topic: conceptual -ms.date: 07/01/2018 --- # Microsoft Defender Security Center diff --git a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md index c3738fd5f6..12f446cb26 100644 --- a/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md +++ b/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10.md @@ -448,7 +448,7 @@ Microsoft Consulting Services (MCS) and Microsoft Support/Premier Field Engineer - [Security and Assurance in Windows Server 2016](https://technet.microsoft.com/windows-server-docs/security/security-and-assurance) - [Microsoft Defender Advanced Threat Protection (ATP) - resources](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) -- [Microsoft Defender Advanced Threat Protection (ATP) - documentation](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) +- [Microsoft Defender Advanced Threat Protection (ATP) - documentation](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection) - [Exchange Online Advanced Threat Protection Service Description](https://technet.microsoft.com/library/exchange-online-advanced-threat-protection-service-description.aspx) - [Office 365 Advanced Threat Protection](https://products.office.com/en-us/exchange/online-email-threat-protection) - [Microsoft Malware Protection Center](https://www.microsoft.com/en-us/security/portal/mmpc/default.aspx) diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md index 34ee455d8a..4b8cc048a4 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility.md @@ -63,7 +63,7 @@ Passive mode | Windows Defender AV will not be used as the antivirus app, and th Automatic disabled mode | Windows Defender AV will not be used as the antivirus app. Files will not be scanned and threats will not be remediated. | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark no](images/svg/check-no.svg)] Active mode | Windows Defender AV is used as the antivirus app on the machine. All configuration made with Configuration Manager, Group Policy, Intune, or other management products will apply. Files will be scanned and threats remediated, and detection information will be reported in your configuration tool (such as Configuration Manager or the Windows Defender AV app on the machine itself). | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark no](images/svg/check-no.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] | [!include[Check mark yes](images/svg/check-yes.svg)] -If you are enrolled in Microsoft Defender ATP and you are using a third party antimalware product then passive mode is enabled because [the service requires common information sharing from the Windows Defender AV service](../windows-defender-atp/defender-compatibility.md) in order to properly monitor your devices and network for intrusion attempts and attacks. +If you are enrolled in Microsoft Defender ATP and you are using a third party antimalware product then passive mode is enabled because [the service requires common information sharing from the Windows Defender AV service](../microsoft-defender-atp/defender-compatibility.md) in order to properly monitor your devices and network for intrusion attempts and attacks. Automatic disabled mode is enabled so that if the protection offered by a third-party antivirus product expires or otherwise stops providing real-time protection from viruses, malware or other threats, Windows Defender AV will automatically enable itself to ensure antivirus protection is maintained on the endpoint. It also allows you to enable [limited periodic scanning](limited-periodic-scanning-windows-defender-antivirus.md), which uses the Windows Defender AV engine to periodically check for threats in addition to your main antivirus app. From 440345de4d1bcfffeee6fe44a21f042152cb1893 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:24:04 -0700 Subject: [PATCH 152/737] fix eg file names --- .../attack-surface-reduction-exploit-guard.md | 2 +- ...k-surface-reduction-rules-in-windows-10-enterprise-e3.md | 2 +- .../audit-windows-defender-exploit-guard.md | 2 +- .../controlled-folders-exploit-guard.md | 6 +++--- .../emet-exploit-protection-exploit-guard.md | 2 +- .../event-views-exploit-guard.md | 2 +- .../exploit-protection-exploit-guard.md | 4 ++-- .../network-protection-exploit-guard.md | 6 +++--- .../windows-defender-exploit-guard/troubleshoot-asr.md | 2 +- .../windows-defender-exploit-guard/troubleshoot-np.md | 2 +- .../windows-defender-exploit-guard.md | 2 +- 11 files changed, 16 insertions(+), 16 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md index 51b3340555..93cfaddf25 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-exploit-guard.md @@ -22,7 +22,7 @@ ms.date: 04/02/2019 Attack surface reduction rules help prevent behaviors malware often uses to infect computers with malicious code. You can set attack surface reduction rules for computers running Windows 10, version 1709 or later, Windows Server 2016 1803 or later, or Windows Server 2019. -To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. +To use attack surface reduction rules, you need a Windows 10 Enterprise E3 license or higher. A Windows E5 license gives you the advanced management capabilities to power them. These include monitoring, analytics, and workflows available in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), as well as reporting and configuration capabilities in the M365 Security Center. These advanced capabilities aren't available with an E3 license, but you can use attack surface reduction rule events in Event Viewer to help facilitate deployment. Attack surface reduction rules target behaviors that malware and malicious apps typically use to infect computers, including: diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md index 9b29796bee..60bdf42183 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/attack-surface-reduction-rules-in-windows-10-enterprise-e3.md @@ -20,7 +20,7 @@ ms.date: 10/15/2018 - Windows 10 Enterprise E3 -Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. +Attack surface reduction rules help prevent actions and apps that are typically used by exploit-seeking malware to infect machines. This feature area includes the rules, monitoring, reporting, and analytics necessary for deployment that are included in [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), and require the Windows 10 Enterprise E5 license. A limited subset of basic attack surface reduction rules can technically be used with Windows 10 Enterprise E3. They can be used without the benefits of reporting, monitoring, and analytics, which provide the ease of deployment and management capabilities necessary for enterprises. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md index 672ab8575a..0bc78c8573 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/audit-windows-defender-exploit-guard.md @@ -27,7 +27,7 @@ You might want to do this when testing how the features will work in your organi While the features will not block or prevent apps, scripts, or files from being modified, the Windows Event Log will record events as if the features were fully enabled. This means you can enable audit mode and then review the event log to see what impact the feature would have had were it enabled. -You can use Microsoft Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Microsoft Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +You can use Microsoft Defender Advanced Threat Protection to get greater deatils for each event, especially for investigating attack surface reduction rules. Using the Microsoft Defender ATP console lets you [investigate issues as part of the alert timeline and investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). This topic provides links that describe how to enable the audit functionality for each feature and how to view events in the Windows Event Viewer. diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md index c137f791e5..fc8c602805 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/controlled-folders-exploit-guard.md @@ -21,7 +21,7 @@ ms.date: 11/29/2018 - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Controlled folder access helps you protect valuable data from malicious apps and threats, such as ransomware. Controlled folder access is supported on Windows Server 2019 as well as Windows 10 clients. -Controlled folder access works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Controlled folder access works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), which gives you detailed reporting into controlled folder access events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). All apps (any executable file, including .exe, .scr, .dll files and others) are assessed by Windows Defender Antivirus, which then determines if the app is malicious or safe. If the app is determined to be malicious or suspicious, then it will not be allowed to make changes to any files in any protected folder. @@ -41,9 +41,9 @@ Controlled folder access requires enabling [Windows Defender Antivirus real-time ## Review controlled folder access events in the Microsoft Defender ATP Security Center -Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). -You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how controlled folder access settings would affect your environment if they were enabled. ## Review controlled folder access events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md index bc4ff6e8aa..5a5dc12514 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md @@ -59,7 +59,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md index 58ecc61775..13fcbf3167 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard.md @@ -27,7 +27,7 @@ Reviewing the events is also handy when you are evaluating the features, as you This topic lists all the events, their associated feature or setting, and describes how to create custom views to filter to specific events. -You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). +You can also get detailed reporting into events and blocks as part of Windows Security, which you access if you have an E5 subscription and use [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md). ## Use custom views to review attack surface reduction capabilities diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md index 2f26612542..fa1dae1039 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md @@ -27,7 +27,7 @@ It is part of [Windows Defender Exploit Guard](windows-defender-exploit-guard.md >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Exploit protection works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Exploit protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) - which gives you detailed reporting into exploit protection events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). You can [enable exploit protection](enable-exploit-protection.md) on an individual machine, and then use [Group Policy](import-export-exploit-protection-emet-xml.md) to distribute the XML file to multiple devices at once. @@ -102,7 +102,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md index e65dcc4777..d259d88575 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard.md @@ -29,7 +29,7 @@ Network protection is supported on Windows 10, version 1709 and later and Window >[!TIP] >You can visit the Windows Defender Testground website at [demo.wd.microsoft.com](https://demo.wd.microsoft.com?ocid=cx-wddocs-testground) to confirm the feature is working and see how it works. -Network protection works best with [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Network protection works best with [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md), which gives you detailed reporting into Windows Defender EG events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). When network protection blocks a connection, a notification will be displayed from the Action Center. You can [customize the notification](customize-attack-surface-reduction.md#customize-the-notification) with your company details and contact information. You can also enable the rules individually to customize what techniques the feature monitors. @@ -45,9 +45,9 @@ Windows 10 version 1709 or later | [Windows Defender AV real-time protection](.. ## Review network protection events in the Microsoft Defender ATP Security Center -Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). +Microsoft Defender ATP provides detailed reporting into events and blocks as part of its [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). -You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. +You can query Microsoft Defender ATP data by using [Advanced hunting](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection). If you're using [audit mode](audit-windows-defender-exploit-guard.md), you can use Advanced hunting to see how network protection settings would affect your environment if they were enabled. ## Review network protection events in Windows Event Viewer diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md index d1f516eacc..0ffe534d26 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-asr.md @@ -76,7 +76,7 @@ To add an exclusion, see [Customize Attack surface reduction](customize-attack-s ## Report a false positive or false negative -Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). +Use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md index 40c261016a..3feaedade3 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/troubleshoot-np.md @@ -65,7 +65,7 @@ Set-MpPreference -EnableNetworkProtection Enabled ## Report a false positive or false negative -If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md). +If you've tested the feature with the demo site and with audit mode, and network protection is working on pre-configured scenarios, but is not working as expected for a specific connection, use the [Windows Defender Security Intelligence web-based submission form](https://www.microsoft.com/en-us/wdsi/filesubmission) to report a false negative or false positive for network protection. With an E5 subscription, you can also [provide a link to any associated alert](../microsoft-defender-atp/alerts-queue.md). ## Collect diagnostic data for file submissions diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md index cd2b47c9fe..b6733d5ed0 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md @@ -45,7 +45,7 @@ You can also [enable audit mode](audit-windows-defender-exploit-guard.md) for th Windows Defender EG can be managed and reported on in the Windows Security app as part of the Microsoft Defender Advanced Threat Protection suite of threat mitigation, preventing, protection, and analysis technologies. -You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md). You can [sign up for a free trial of Microsoft Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. +You can use the Windows Security app to obtain detailed reporting into events and blocks as part of the usual [alert investigation scenarios](../microsoft-defender-atp/investigate-alerts.md). You can [sign up for a free trial of Microsoft Defender ATP](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=cx-docs-msa4053440) to see how it works. ## Requirements From ffc85728257c22cf40a7f359dae996d36ad89077 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:28:44 -0700 Subject: [PATCH 153/737] remove link --- .../microsoft-defender-atp/threat-analytics.md | 3 --- 1 file changed, 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md index c4b5ae9d96..91fc9e3b31 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md +++ b/windows/security/threat-protection/microsoft-defender-atp/threat-analytics.md @@ -64,6 +64,3 @@ The **Mitigation status** and **Mitigation status over time** shows the endpoint >The Unavailable category indicates that there is no data available from the specific machine yet. -## Related topics -- [Threat analytics for Spectre and Meltdown](threat-analytics.md) - From 02863694656b97cc750a4fb11e16feb4ba1d17d4 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:31:06 -0700 Subject: [PATCH 154/737] update toc typo file --- windows/security/threat-protection/TOC.md | 6 +++--- .../threat-protection/microsoft-defender-atp/TOC.md | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index caca71920d..749db9c96b 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -403,9 +403,9 @@ ### [Troubleshoot Windows Defender ATP](microsoft-defender-atp/troubleshoot-overview.md) ####Troubleshoot sensor state ##### [Check sensor state](microsoft-defender-atp/check-sensor-status.md) -##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealhty-sensors.md) -##### [Inactive machines](microsoft-defender-atp/fix-unhealhty-sensors.md#inactive-machines) -##### [Misconfigured machines](microsoft-defender-atp/fix-unhealhty-sensors.md#misconfigured-machines) +##### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealthy-sensors.md) +##### [Inactive machines](microsoft-defender-atp/fix-unhealthy-sensors.md#inactive-machines) +##### [Misconfigured machines](microsoft-defender-atp/fix-unhealthy-sensors.md#misconfigured-machines) ##### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes.md) #### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 0a5682ebc9..69977fe4cc 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -397,7 +397,7 @@ #### [Misconfigured machines](fix-unhealthy-sensors.md#misconfigured-machines) #### [Review sensor events and errors on machines with Event Viewer](event-error-codes.md) -### [Troubleshoot Microsoft Defender ATP service issues](troubleshoot.md) +### [Troubleshoot Microsoft Defender ATP service issues](troubleshoot-mdatp.md) #### [Check service health](service-status.md) ###Troubleshoot attack surface reduction From f3a2c4e16b5d54a8e78451fee9430e538ad811df Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:37:44 -0700 Subject: [PATCH 155/737] fix troubleshoot file name --- windows/security/threat-protection/TOC.md | 2 +- .../microsoft-defender-atp/troubleshoot-onboarding.md | 2 +- .../microsoft-defender-atp/windows-defender-security-center.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 749db9c96b..29c713479e 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -408,7 +408,7 @@ ##### [Misconfigured machines](microsoft-defender-atp/fix-unhealthy-sensors.md#misconfigured-machines) ##### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes.md) -#### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot.md) +#### [Troubleshoot Windows Defender ATP service issues](microsoft-defender-atp/troubleshoot-mdatp.md) ##### [Check service health](microsoft-defender-atp/service-status.md) ####Troubleshoot attack surface reduction diff --git a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md index 69c3b620ca..36fe7db04c 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md +++ b/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding.md @@ -306,7 +306,7 @@ For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us ## Related topics -- [Troubleshoot Microsoft Defender ATP](troubleshoot.md) +- [Troubleshoot Microsoft Defender ATP](troubleshoot-mdatp.md) - [Onboard machines](onboard-configure.md) - [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md index 7c7ef2d01e..b0ce4f4679 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md +++ b/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md @@ -34,5 +34,5 @@ Reporting | Create and build Power BI reports using Microsoft Defender ATP data. Check service health and sensor state | Verify that the service is running and check the sensor state on machines. [Configure Microsoft Defender Security Center settings](preferences-setup.md) | Configure general settings, turn on the preview experience, notifications, and enable other features. [Access the Microsoft Defender ATP Community Center](community.md) | Access the Microsoft Defender ATP Community Center to learn, collaborate, and share experiences about the product. -[Troubleshoot service issues](troubleshoot.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. +[Troubleshoot service issues](troubleshoot-mdatp.md) | This section addresses issues that might arise as you use the Windows Defender Advanced Threat service. From cfea3c446cfa77fccf6bfa38229a471a713f53d9 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 16:58:57 -0700 Subject: [PATCH 156/737] fix warnings --- ...security-center.md => microsoft-defender-security-center.md} | 0 .../windows-defender-security-center-antivirus.md | 2 +- .../emet-exploit-protection-exploit-guard.md | 2 +- .../exploit-protection-exploit-guard.md | 2 +- 4 files changed, 3 insertions(+), 3 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{windows-defender-security-center.md => microsoft-defender-security-center.md} (100%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md b/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-security-center.md similarity index 100% rename from windows/security/threat-protection/microsoft-defender-atp/windows-defender-security-center.md rename to windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-security-center.md diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md index 739439af03..b8b4f4cb60 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md @@ -36,7 +36,7 @@ Settings that were previously part of the Windows Defender client and main Windo See the [Windows Security topic](/windows/threat-protection/windows-defender-security-center/windows-defender-security-center) for more information on other Windows security features that can be monitored in the app. >[!NOTE] ->The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal that is used to review and manage [Microsoft Defender Advanced Threat Protection](../windows-defender-atp/windows-defender-advanced-threat-protection.md). +>The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal that is used to review and manage [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md). **Review virus and threat protection settings in the Windows Security app:** diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md index 5a5dc12514..013ea04010 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/emet-exploit-protection-exploit-guard.md @@ -59,7 +59,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/secure-score-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md index fa1dae1039..f00aadcdbf 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard.md @@ -102,7 +102,7 @@ Configuration with Group Policy | [!include[Check mark yes](images/svg/check-yes Configuration with shell tools | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use PowerShell to customize and manage configurations](customize-exploit-protection.md#powershell-reference) | [!include[Check mark yes](images/svg/check-yes.svg)]
Requires use of EMET tool (EMET_CONF) System Center Configuration Manager | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Configuration Manager to customize, deploy, and manage configurations](https://docs.microsoft.com/sccm/protect/deploy-use/create-deploy-exploit-guard-policy) | [!include[Check mark no](images/svg/check-no.svg)]
Not available Microsoft Intune | [!include[Check mark yes](images/svg/check-yes.svg)]
[Use Intune to customize, deploy, and manage configurations](https://docs.microsoft.com/intune/whats-new#window-defender-exploit-guard-is-a-new-set-of-intrusion-prevention-capabilities-for-windows-10----1063615---) | [!include[Check mark no](images/svg/check-no.svg)]
Not available -Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/security-analytics-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring +Reporting | [!include[Check mark yes](images/svg/check-yes.svg)]
With [Windows event logs](event-views-exploit-guard.md) and [full audit mode reporting](audit-windows-defender-exploit-guard.md)
[Full integration with Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/secure-score-dashboard.md) | [!include[Check mark yes](images/svg/check-yes.svg)]
Limited Windows event log monitoring Audit mode | [!include[Check mark yes](images/svg/check-yes.svg)]
[Full audit mode with Windows event reporting](audit-windows-defender-exploit-guard.md) | [!include[Check mark no](images/svg/check-no.svg)]
Limited to EAF, EAF+, and anti-ROP mitigations ([1](#ref1)) Requires an enterprise subscription with Azure Active Directory or a [Software Assurance ID](https://www.microsoft.com/en-us/licensing/licensing-programs/software-assurance-default.aspx). From f041fcb7884a55fc53e0c73f1a1259a1b7d90754 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 10 Apr 2019 17:08:01 -0700 Subject: [PATCH 157/737] remove link --- .../microsoft-defender-atp/overview-secure-score.md | 2 +- .../security/threat-protection/microsoft-defender-atp/use.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index 7aad2ad004..dd41c155c3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -79,4 +79,4 @@ Clicking the link under the Misconfigured machines column opens up the **Machine ## Related topic - [Threat analytics](threat-analytics.md) -- [Threat analytics for Spectre and Meltdown](threat-analytics.md) + diff --git a/windows/security/threat-protection/microsoft-defender-atp/use.md b/windows/security/threat-protection/microsoft-defender-atp/use.md index 501f6f9019..1220885f55 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/use.md +++ b/windows/security/threat-protection/microsoft-defender-atp/use.md @@ -42,6 +42,6 @@ Topic | Description [Portal overview](portal-overview.md) | Understand the portal layout and area descriptions. [View the Security operations dashboard](security-operations-dashboard.md) | The Microsoft Defender ATP **Security operations dashboard** provides a snapshot of your network. You can view aggregates of alerts, the overall status of the service of the machines on your network, investigate machines, files, and URLs, and see snapshots of threats seen on machines. [View the Secure Score dashboard and improve your secure score](secure-score-dashboard.md) | The **Secure Score dashboard** expands your visibility into the overall security posture of your organization. From this dashboard, you'll be able to quickly assess the security posture of your organization, see machines that require attention, as well as recommendations for actions to further reduce the attack surface in your organization - all in one place. -[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to Spectre and Meltdown. Use the charts to quickly identify machines for the presence or absence of mitigations. +[View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics.md) | The **Threat analytics** dashboard helps you continually assess and control risk exposure to threats. Use the charts to quickly identify machines for the presence or absence of mitigations. From 1e1cdb1790be67543d928e81af2fa1220d148d82 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 11 Apr 2019 08:13:38 -0700 Subject: [PATCH 158/737] new build 4/11/2019 8:13 AM --- ...basic-level-windows-diagnostic-events-and-fields-1903.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index bd6c4e2161..7cc546dd61 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/10/2019 +ms.date: 04/11/2019 --- @@ -3336,6 +3336,8 @@ The following fields are available: - **COMPID** The device setup class guid of the driver loaded for the device. - **ContainerId** The list of compat ids for the device. - **Description** System-supplied GUID that uniquely groups the functional devices associated with a single-function or multifunction device installed in the computer. +- **DeviceDriverFlightId** The test build (Flight) identifier of the device driver. +- **DeviceExtDriversFlightIds** The test build (Flight) identifier for all extended device drivers. - **DeviceInterfaceClasses** The device interfaces that this device implements. - **DeviceState** The device description. - **DriverId** DeviceState is a bitmask of the following: DEVICE_IS_CONNECTED 0x0001 (currently only for container). DEVICE_IS_NETWORK_DEVICE 0x0002 (currently only for container). DEVICE_IS_PAIRED 0x0004 (currently only for container). DEVICE_IS_ACTIVE 0x0008 (currently never set). DEVICE_IS_MACHINE 0x0010 (currently only for container). DEVICE_IS_PRESENT 0x0020 (currently always set). DEVICE_IS_HIDDEN 0x0040. DEVICE_IS_PRINTER 0x0080 (currently only for container). DEVICE_IS_WIRELESS 0x0100. DEVICE_IS_WIRELESS_FAT 0x0200. The most common values are therefore: 32 (0x20)= device is present. 96 (0x60)= device is present but hidden. 288 (0x120)= device is a wireless device that is present @@ -3345,8 +3347,10 @@ The following fields are available: - **DriverVerVersion** The immediate parent directory name in the Directory field of InventoryDriverPackage. - **Enumerator** The date of the driver loaded for the device. - **ExtendedInfs** The extended INF file names. +- **FirstInstallDate** The first time this device was installed on the machine. - **HWID** The version of the driver loaded for the device. - **Inf** The bus that enumerated the device. +- **InstallDate** The date of the most recent installation of the device on the machine. - **InstallState** The device installation state. One of these values: https://msdn.microsoft.com/en-us/library/windows/hardware/ff543130.aspx - **InventoryVersion** List of hardware ids for the device. - **LowerClassFilters** Lower filter class drivers IDs installed for the device From 5aa38071f3fe3e488d9ee670a4474ac3f3c9689e Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 11 Apr 2019 08:13:47 -0700 Subject: [PATCH 159/737] new build 4/11/2019 8:13 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 4 +- ...ndows-diagnostic-events-and-fields-1709.md | 4 +- ...ndows-diagnostic-events-and-fields-1803.md | 4 +- ...ndows-diagnostic-events-and-fields-1809.md | 456 +++++++++++++----- 4 files changed, 334 insertions(+), 134 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index cc4a260492..bf54d09ae5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/10/2019 +ms.date: 04/11/2019 --- @@ -3075,7 +3075,7 @@ The following fields are available: - **CV** The Correlation Vector. - **DateTimeDifference** The difference between the local and reference clocks. - **DaysSinceOsInstallation** The number of days since the installation of the Operating System. -- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in Megabytes. +- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in megabytes. - **DiskMbFreeAfterCleanup** The amount of free hard disk space after cleanup, measured in Megabytes. - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index aef6875c51..e82222b6ab 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/10/2019 +ms.date: 04/11/2019 --- @@ -3284,7 +3284,7 @@ The following fields are available: - **CV** The Correlation Vector. - **DateTimeDifference** The difference between the local and reference clocks. - **DaysSinceOsInstallation** The number of days since the installation of the Operating System. -- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in Megabytes. +- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in megabytes. - **DiskMbFreeAfterCleanup** The amount of free hard disk space after cleanup, measured in Megabytes. - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 1b2f1c8932..5339268f09 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/10/2019 +ms.date: 04/11/2019 --- @@ -4386,7 +4386,7 @@ The following fields are available: - **CV** The Correlation Vector. - **DateTimeDifference** The difference between the local and reference clocks. - **DaysSinceOsInstallation** The number of days since the installation of the Operating System. -- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in Megabytes. +- **DiskMbCleaned** The amount of space cleaned on the hard disk, measured in megabytes. - **DiskMbFreeAfterCleanup** The amount of free hard disk space after cleanup, measured in Megabytes. - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index a5e90b5538..9c1f8ed87b 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/10/2019 +ms.date: 04/11/2019 --- @@ -550,10 +550,12 @@ The following fields are available: - **AppraiserVersion** The version of the appraiser file that is generating the events. - **AvDisplayName** If the app is an anti-virus app, this is its display name. +- **CompateClasIndex** No content is currently available. - **CompatModelIndex** The compatibility prediction for this file. - **HasCitData** Indicates whether the file is present in CIT data. - **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. - **IsAv** Is the file an anti-virus reporting EXE? +- **ResolveAd85mpted** No content is currently available. - **ResolveAttempted** This will always be an empty string when sending telemetry. - **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. @@ -589,6 +591,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: - **ActiveNetworkConnection** Indicates whether the device is an active network device. +- **ActiveNetworkCoompction** No content is currently available. - **AppraiserVersion** The version of the appraiser file generating the events. - **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. - **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. @@ -2005,6 +2008,7 @@ The following fields are available: - **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. - **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. - **ServiceProductKeyID** Retrieves the License key of the KMS +- **SharedpCMode** No content is currently available. - **SharedPCMode** Returns Boolean for education devices used as shared cart - **Signature** Retrieves if it is a signature machine sold by Microsoft store. - **SLICStatus** Whether a SLIC table exists on the device. @@ -2049,6 +2053,7 @@ The following fields are available: - **Sms** Current state of the text messaging setting. - **SpeechPersonalization** Current state of the speech services setting. - **USB** Current state of the USB setting. +- **UserAccotntInformation** No content is currently available. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. - **UserNotificationListener** Current state of the notifications setting. @@ -2456,8 +2461,10 @@ Describes the installation state for all hardware and software components availa The following fields are available: +- **** No content is currently available. - **action** The change that was invoked on a device inventory object. - **inventoryId** Device ID used for Compatibility testing +- **objectIn** No content is currently available. - **objectInstanceId** Object identity which is unique within the device scope. - **objectType** Indicates the object type that the event applies to. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. @@ -2507,6 +2514,7 @@ This event provides information about the results of installing or uninstalling The following fields are available: +- **`ighestState** No content is currently available. - **capabilities** The names of the optional content packages that were installed. - **clientId** The name of the application requesting the optional content. - **currentID** The ID of the current install session. @@ -2725,6 +2733,7 @@ The following fields are available: - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. +- **CanPerformDyagnosticEscalations** No content is currently available. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. - **CanReportScenarios** True if we can report scenario completions, false otherwise. - **PreviousPermissions** Bitmask of previous telemetry state. @@ -2737,7 +2746,9 @@ This event sends data about the connectivity status of the Connected User Experi The following fields are available: +- **CensõsTaskEnabled** No content is currently available. - **CensusExitCode** Returns last execution codes from census client run. +- **CensusExitCodeoaderCensusStartTime** No content is currently available. - **CensusStartTime** Returns timestamp corresponding to last successful census run. - **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. - **LastConnectivityLossTime** Retrieves the last time the device lost free network. @@ -2752,13 +2763,18 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: +- **ꭤ↑롥戅ꔠ촉꤆䳨㢳桜ꀽ㴂颭ྞ䚿ꆁ억ﱎ콧ꓘ먗** No content is currently available. +- **AgentConneCouonErrorsCount** No content is currently available. - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. +- **CensõsTaskEnabled** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. - **CompressedBytesUploaded** Number of compressed bytes uploaded. +- **ConsumerDrop0edCount** No content is currently available. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. +- **CriticalDatasbDroppedCount** No content is currently available. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. @@ -2767,6 +2783,7 @@ The following fields are available: - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EnteringCriticalOverflowDrOppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2780,26 +2797,55 @@ The following fields are available: - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **LastAgentConneCouonError** No content is currently available. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **MaxACouveAgentConneCouonCount** No content is currently available. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. +- **ᴗ㜛ﭮ紀⁻嬝藱唬穉聮쁪カ鳄髈** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailur$Dropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. +- **RepeatedUpѬoadFailureDropped** No content is currently available. +- **sbCriticalDroppedCount** No content is currently available. +- **sbDroppedCount** No content is currently available. +- **sbDroppedFailureCount** No content is currently available. +- **sbDroppedFullCount** No content is currently available. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **sorBdingDroppedCount** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. +- **ThrottlgdDroppedCount** No content is currently available. - **TopUploaderErrors** List of top errors received from the upload endpoint. +- **TopUploaeerErrors** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. +- **ǔ໦岋ࣉ䫕꧓ꏖ훭늓겲均効座⺽ඕ��嘩璽춒** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. +- **ჯ⌷脻㍛䮥肑鍼Ⅵ䄪ꬃ鳃抍⓯钑볨䨎ᖪ먩諢涇͙켦榩偊撏嫄艸** No content is currently available. +- **반쐍⾋ꯈ��玱䁕��龓ⴶ샴賷헖쉺分╅㾚흦დ** No content is currently available. +- **빛䨮哆茠뢶☲偍矉繡귴틐⤺॓酠ꐜ⇫ꈚᑋ勰叙湧ㆧ噟ܝ㸇朤ಳ** No content is currently available. +- **쩤খ䠸퇫秂窇벘货齳��ꕢ顦ᜃⲎ耡��옥䦏��淨㖘⃵┵ᘵ鳝톈如癶첛ᲃ絍** No content is currently available. +- **퓙쏴撑⋇뭟혦꩑戙厀뎓燼㼿渺** No content is currently available. +- **훾電쇔䕅碎霶퍕◲⫒븩ὴ앏艐堗详鲝‶ᜧ** No content is currently available. +- **军伽礋圿萦꒎㲮꿨휒慢䷳橱瘒糜劷墹鎗ꭖ潨ᓔ** No content is currently available. +- **唹켴亰铳ᮍ㭨狣N洹滓ꦲ횴䝃怭픱烰彧魋阭刏⅄ꙹ꯬襖** No content is currently available. +- **櫠䰩遗ᆖᑒ��噊썻ࣆ鮷��㑡Ḯ偬ƚ㣸☂灚Ἇ汆磚䐯槴** No content is currently available. +- **蔇İᏘ࢔谼��ﰊ庸涝芦ᅳ蔭隷嵨̐ꊰ** No content is currently available. +- **裎墴_郐堩��ᴰ뵾핝㳊愨鳘鯡廭顩圧由꽆餢俗䡄ﳻ捳褮ꨞ㵙钫욯홏Ը໤ꖠ䬞悺俽** No content is currently available. +- **趬ᛉ뛀䲮憎** No content is currently available. +- **铽ჟᔛ}䘅��讀랃帷덉侙쩠뙆档玳꼱** No content is currently available. +- **㝫��粆疺⃩��렩榽ႚൾ滑햓ꎢ** No content is currently available. +- **㮆퍈栵ᥳⷣ뤏䳬HttpAttempts** No content is currently available. +- **䱪��໿��雔僽땧觪⊝쵥虚䧁嶟轶** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -2816,6 +2862,7 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to database failures. - **DbDroppedFullCount** Number of events dropped due to database being full. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. +- **EnteringCriticalOverflowDrOppedCounter** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times the event store has been reset. - **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. @@ -2823,14 +2870,18 @@ The following fields are available: - **EventsUploaded** Number of events uploaded. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. +- **InvalidHttpCsdeCount** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. +- **LastInvalidHttpCsde** No content is currently available. - **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. +- **RepeatedUploadFailur$Dropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** Number of failures from contacting OneSettings service. - **TopUploaderErrors** List of top errors received from the upload endpoint. +- **TopUploaeerErrors** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** Number of time out failures received from Vortex. @@ -3405,30 +3456,43 @@ The following fields are available: - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiSeqId** The event sequence ID. - **bootId** The system boot ID. +- **BraghtnessVersionViaDDI** No content is currently available. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. +- **BrightnessVersionVyaDDI** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. +- **DedDcatedSystemMemoryB** No content is currently available. +- **DedDcatedVideoMemoryB** No content is currently available. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DisplayAdapterLuid** The display adapter LUID. +- **DisplayAdapTerLuid** No content is currently available. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. +- **DX11EMDFilePath** No content is currently available. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. +- **FX9UMDFilePath** No content is currently available. +- **GPQPreemptionLevel** No content is currently available. - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPUVendorID** The GPU vendor ID. +- **I3SoftwareDevice** No content is currently available. - **InterfaceId** The GPU interface ID. +- **InturfaceId** No content is currently available. +- **Is@ybridDiscrete** No content is currently available. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? +- **IsHyrridDiscrete** No content is currently available. - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? +- **IsMismaTchLDA** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? @@ -3443,10 +3507,17 @@ The following fields are available: - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). - **SubSystemID** The subsystem ID. - **SubVendorID** The GPU sub vendor ID. +- **Tele}etryEnabled** No content is currently available. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? +- **TelInv2YntTrigger** No content is currently available. - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) +- **TX10UMDFilePath** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. +- **WPUPreemptionLevel** No content is currently available. +- **YsDisplayDevice** No content is currently available. +- **YsLDA** No content is currently available. +- **YsRenderDevice** No content is currently available. ## Failover Clustering events @@ -3532,24 +3603,42 @@ This event sends data about crashes for both native and managed applications, to The following fields are available: +- **.xceptionCode** No content is currently available. +- **.xceptionOffset** No content is currently available. +- **ags** No content is currently available. - **AppName** The name of the app that has crashed. - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. +- **argetAsId** No content is currently available. +- **argetAsppId** No content is currently available. +- **argetAsppVer** No content is currently available. +- **d** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. +- **Modame** No content is currently available. - **ModName** Exception module name (e.g. bar.dll). - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. +- **nCode** No content is currently available. +- **Pack9OeFullName** No content is currently available. +- **Pack9OeRelativeAppId** No content is currently available. +- **PackageFullame** No content is currently available. +- **PackageFullFame** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. +- **ProcessArchite2kure** No content is currently available. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. +- **pSessionGuid** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. +- **RepoztId** No content is currently available. +- **TargetAId** No content is currently available. +- **TargetAppI4StartTime** No content is currently available. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported - **TargetAsId** The sequence number for the hanging process. @@ -3675,15 +3764,19 @@ The following fields are available: - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. - **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. +- **InstallDatgArpLastModified** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. - **Language** The language code of the program. - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. +- **MsiPackageColm** No content is currently available. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. +- **OSVersionAtInstallTioe** No content is currently available. - **PackageFullName** The package full name for a Store application. - **ProgramInstanceId** A hash of the file IDs in an app. - **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. +- **RackageFullName** No content is currently available. - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. @@ -3781,6 +3874,7 @@ The following fields are available: - **ModelId** A unique model ID. - **ModelName** The model name. - **ModelNumber** The model number for the device container. +- **primaryCategory** No content is currently available. - **PrimaryCategory** The primary category for the device container. @@ -3937,7 +4031,9 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: +- **inventoryId** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. +- **syncId** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync @@ -3996,9 +4092,11 @@ The following fields are available: - **ImageSize** The size of the driver file. - **Inf** The name of the INF file. - **InventoryVersion** The version of the inventory file generating the events. +- **LriverName** No content is currently available. - **Product** The product name that is included in the driver file. - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. +- **TriverSigned** No content is currently available. - **WdfVersion** The Windows Driver Framework version. @@ -4070,12 +4168,19 @@ The following fields are available: This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the beginning of the event download, and that tracing should begin. +The following fields are available: + +- **key** No content is currently available. +- **UniqueKey** No content is currently available. ### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace This event collects traces of all other Core events, not used in typical customer scenarios. This event signals the end of the event download, and that tracing should end. +The following fields are available: + +- **key** No content is currently available. ### Microsoft.Windows.Inventory.General.AppHealthStaticAdd @@ -4516,6 +4621,7 @@ OS information collected during Boot, used to evaluate the success of the upgrad The following fields are available: +- **BootApplicatio~Id** No content is currently available. - **BootApplicationId** This field tells us what the OS Loader Application Identifier is. - **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. - **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. @@ -4798,107 +4904,107 @@ This event indicates whether a remediation plug-in is applicable, to help keep W The following fields are available: -- **AllowAutoUpdateExists** No content is currently available. +- **AllowAutoUpdateExists** Indicates whether the Automatic Update feature is turned on. - **AllowAutoUpdateProviderSetExists** No content is currently available. - **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. - **AppraiserTaskRepairDisabled** Task repair performed by the appraiser plugin is disabled. - **AppraiserTaskValid** Indicates that the appraiser task is valid. - **AUOptionsExists** Indicates whether the Automatic Update option exist. -- **CTACTargetingAttributesInvalid** No content is currently available. -- **CTACVersion** No content is currently available. +- **CTACTargetingAttributesInvalid** Indicates whether the Common Targeting Attribute Client (CTAC) attributes are valid. CTAC is a Windows Runtime client library. +- **CTACVersion** The Common Targeting Attribute Client (CTAT) version on the device. CTAT is a Windows Runtime client library. - **CV** Correlation vector - **DataStoreSizeInBytes** Size of the data store, in bytes. - **DateTimeDifference** The difference between local and reference clock times. - **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. -- **daysSinceInstallThreshold** No content is currently available. -- **daysSinceInstallValue** No content is currently available. +- **daysSinceInstallThreshold** The maximum number of days since the operating system was installed before we check to see if remediation is needed. +- **daysSinceInstallValue** Number of days since the operating system was installed. - **DaysSinceLastSIH** The number of days since the most recent SIH executed. - **DaysToNextSIH** The number of days until the next scheduled SIH execution. -- **DetectConditionEnabled** No content is currently available. +- **DetectConditionEnabled** Indicates whether a condition that the remediation tool can repair was detected. - **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. -- **DetectionFailedReason** No content is currently available. -- **DiskFreeSpaceBeforeSedimentPackInMB** No content is currently available. -- **DiskSpaceBefore** No content is currently available. -- **EditionIdFixCorrupted** No content is currently available. -- **EscalationTimerResetFixResult** No content is currently available. +- **DetectionFailedReason** Indicates why a given remediation failed to fix a problem that was detected. +- **DiskFreeSpaceBeforeSedimentPackInMB** Number of megabytes of disk space available on the device before running the Sediment Pack. +- **DiskSpaceBefore** The amount of free disk space available before a remediation was run. +- **EditionIdFixCorrupted** Indicates whether the Edition ID is corrupted. +- **EscalationTimerResetFixResult** The result of fixing the escalation timer. - **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. -- **FixedEditionId** No content is currently available. -- **FlightRebootTime** No content is currently available. -- **ForcedRebootToleranceDays** No content is currently available. -- **FreeSpaceRequirement** No content is currently available. +- **FixedEditionId** Indicates whether we fixed Edition ID. +- **FlightRebootTime** The amount of time before the system is rebooted. +- **ForcedRebootToleranceDays** The maximum number of days before a system reboot is forced on the devie. +- **FreeSpaceRequirement** The amount of free space required. - **GlobalEventCounter** Client side counter that indicates ordering of events sent by the remediation system. - **HResult** The HRESULT for detection or perform action phases of the plugin. -- **installDateValue** No content is currently available. +- **installDateValue** The date of the installation. - **IsAppraiserLatestResult** The HRESULT from the appraiser task. - **IsConfigurationCorrected** Indicates whether the configuration of SIH task was successfully corrected. -- **IsEscalationTimerResetFixNeeded** No content is currently available. -- **IsForcedModeEnabled** No content is currently available. -- **IsHomeSku** No content is currently available. -- **IsRebootForcedMode** No content is currently available. -- **IsServiceHardeningEnabled** No content is currently available. -- **IsServiceHardeningNeeded** No content is currently available. -- **isThreshold** No content is currently available. -- **IsUsoRebootPending** No content is currently available. -- **IsUsoRebootPendingInUpdateStore** No content is currently available. -- **IsUsoRebootTaskEnabled** No content is currently available. -- **IsUsoRebootTaskExists** No content is currently available. -- **IsUsoRebootTaskValid** No content is currently available. +- **IsEscalationTimerResetFixNeeded** Determines whether a fix is applicable. +- **IsForcedModeEnabled** Indicates whether forced reboot mode is enabled. +- **IsHomeSku** Indicates whether the device is running the Windows 10 Home edition. +- **IsRebootForcedMode** Indicates whether the forced reboot mode is turned on. +- **IsServiceHardeningEnabled** Indicates whether the Windows Service Hardening feature was turned on for the device. +- **IsServiceHardeningNeeded** Indicates whether Windows Service Hardening was needed for the device (multiple instances of service tampering were detected.) +- **isThreshold** Indicates whether the value meets our threshold. +- **IsUsoRebootPending** Indicates whether a system reboot is pending. +- **IsUsoRebootPendingInUpdateStore** Indicates whether a reboot is pending. +- **IsUsoRebootTaskEnabled** Indicates whether the Update Service Orchestrator (USO) reboot task is enabled +- **IsUsoRebootTaskExists** Indicates whether the Update Service Orchestrator (USO) reboot task exists. +- **IsUsoRebootTaskValid** Indicates whether the Update Service Orchestrator (USO) reboot task is valid. - **LastHresult** The HRESULT for detection or perform action phases of the plugin. -- **LastRebootTaskRunResult** No content is currently available. -- **LastRebootTaskRunTime** No content is currently available. +- **LastRebootTaskRunResult** Indicates the result of the last reboot task. +- **LastRebootTaskRunTime** The length of time the last reboot task took to run. - **LastRun** The date of the most recent SIH run. -- **LPCountBefore** No content is currently available. -- **NextCheck** No content is currently available. -- **NextRebootTaskRunTime** No content is currently available. +- **LPCountBefore** The number of language packs on the device before remediation started. +- **NextCheck** Indicates when remediation will next be attempted. +- **NextRebootTaskRunTime** Indicates when the next system reboot task will run. - **NextRun** Date of the next scheduled SIH run. -- **NoAutoUpdateExists** No content is currently available. -- **NumberOfDaysStuckInReboot** No content is currently available. -- **OriginalEditionId** No content is currently available. +- **NoAutoUpdateExists** Indicates whether the Automatic Updates feature is turned off. +- **NumberOfDaysStuckInReboot** The number of days tht the device has been unable to successfully reboot. +- **OriginalEditionId** The Windows edition ID before remediation started. - **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. -- **ProductType** No content is currently available. -- **QualityUpdateSedimentFunnelState** No content is currently available. +- **ProductType** The product type of Windows 10. +- **QualityUpdateSedimentFunnelState** Provides information about whether Windows Quality Updates are missing on the device. - **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. -- **QualityUpdateSedimentLastRunSeconds** No content is currently available. -- **QualityUpdateSedimentLocalStartTime** No content is currently available. +- **QualityUpdateSedimentLastRunSeconds** The number of seconds since the Quality Update Sediment Pack ran. +- **QualityUpdateSedimentLocalStartTime** Provides information about when Quality Updates were run. - **QualityUpdateSedimentLocaltTime** No content is currently available. -- **QualityUpdateSedimentTargetedPlugins** No content is currently available. -- **QualityUpdateSedimentTargetedTriggers** No content is currently available. -- **RegkeysExist** No content is currently available. +- **QualityUpdateSedimentTargetedPlugins** Provides the list of remediation plug-ins that are applicable to enable Quality Updates on the device. +- **QualityUpdateSedimentTargetedTriggers** Provides information about remediations that are applicable to enable Quality Updates on the device. +- **RegkeysExist** Indicates whether specified registry keys exist. - **Reload** True if SIH reload is required. -- **RemediationAutoUAAcLineStatus** No content is currently available. -- **RemediationAutoUAAutoStartCount** No content is currently available. -- **RemediationAutoUACalendarTaskEnabled** No content is currently available. -- **RemediationAutoUACalendarTaskExists** No content is currently available. -- **RemediationAutoUACalendarTaskTriggerEnabledCount** No content is currently available. -- **RemediationAutoUADaysSinceLastTaskRunTime** No content is currently available. -- **RemediationAutoUAGetCurrentSize** No content is currently available. -- **RemediationAutoUAIsInstalled** No content is currently available. -- **RemediationAutoUALastTaskRunResult** No content is currently available. -- **RemediationAutoUAMeteredNetwork** No content is currently available. -- **RemediationAutoUATaskEnabled** No content is currently available. -- **RemediationAutoUATaskExists** No content is currently available. -- **RemediationAutoUATasksStalled** No content is currently available. -- **RemediationAutoUATaskTriggerEnabledCount** No content is currently available. -- **RemediationAutoUAUAExitCode** No content is currently available. -- **RemediationAutoUAUAExitState** No content is currently available. -- **RemediationAutoUAUserLoggedIn** No content is currently available. -- **RemediationAutoUAUserLoggedInAdmin** No content is currently available. -- **RemediationCorruptionRepairBuildNumber** No content is currently available. -- **RemediationCorruptionRepairCorruptionsDetected** No content is currently available. -- **RemediationCorruptionRepairDetected** No content is currently available. -- **RemediationDeliverToastBuildNumber** No content is currently available. -- **RemediationDeliverToastDetected** No content is currently available. -- **RemediationDeliverToastDeviceExcludedNation** No content is currently available. -- **RemediationDeliverToastDeviceFreeSpaceInMB** No content is currently available. -- **RemediationDeliverToastDeviceHomeSku** No content is currently available. -- **RemediationDeliverToastDeviceIncludedNation** No content is currently available. -- **RemediationDeliverToastDeviceProSku** No content is currently available. -- **RemediationDeliverToastDeviceSystemDiskSizeInMB** No content is currently available. -- **RemediationDeliverToastGeoId** No content is currently available. -- **RemediationDeviceSkuId** No content is currently available. -- **RemediationGetCurrentFolderExist** No content is currently available. +- **RemediationAutoUAAcLineStatus** Indicates the power status returned by the Automatic Update Assistant tool. +- **RemediationAutoUAAutoStartCount** Indicates the number of times the Automatic Update Assistant tool has automatically started. +- **RemediationAutoUACalendarTaskEnabled** Indicates whether an Automatic Update Assistant tool task is enabled. +- **RemediationAutoUACalendarTaskExists** Indicates whether an Automatic Update Assistant tool task exists. +- **RemediationAutoUACalendarTaskTriggerEnabledCount** Indicates the number of times an Automatic Update Assistant tool task has been triggered. +- **RemediationAutoUADaysSinceLastTaskRunTime** Indicates the last run time of an Automatic Update Assistant tool task. +- **RemediationAutoUAGetCurrentSize** Indicates the current size of the Automatic Update Assistant tool. +- **RemediationAutoUAIsInstalled** Indicates whether the Automatic Update Assistant tool is installed. +- **RemediationAutoUALastTaskRunResult** Indicates the result from the last time the Automatic Update Assistant tool was run. +- **RemediationAutoUAMeteredNetwork** Indicates whether the Automatic Update Assistant tool is running on a metered network. +- **RemediationAutoUATaskEnabled** Indicates whether the Automatic Update Assistant tool task is enabled. +- **RemediationAutoUATaskExists** Indicates whether an Automatic Update Assistant tool task exists. +- **RemediationAutoUATasksStalled** Indicates whether an Automatic Update Assistant tool task is stalled. +- **RemediationAutoUATaskTriggerEnabledCount** Indicates how many times an Automatic Update Assistant tool task has been triggered. +- **RemediationAutoUAUAExitCode** Indicates any exit code provided by the Automatic Update Assistant tool. +- **RemediationAutoUAUAExitState** Indicates the exit state of the Automatic Update Assistant tool. +- **RemediationAutoUAUserLoggedIn** Indicates whether a user is logged in. +- **RemediationAutoUAUserLoggedInAdmin** Indicates whether an Administrator user is logged in. +- **RemediationCorruptionRepairBuildNumber** The build number to use to repair corruption. +- **RemediationCorruptionRepairCorruptionsDetected** Indicates whether corruption was detected. +- **RemediationCorruptionRepairDetected** Indicates whether an attempt was made to repair the corruption. +- **RemediationDeliverToastBuildNumber** Indicates a build number that should be applicable to this device. +- **RemediationDeliverToastDetected** Indicates that a plugin has been detected. +- **RemediationDeliverToastDeviceExcludedNation** Indicates the geographic identity (GEO ID) that is not applicable for a given plug-in. +- **RemediationDeliverToastDeviceFreeSpaceInMB** Indicates the amount of free space, in megabytes. +- **RemediationDeliverToastDeviceHomeSku** Indicates whether the plug-in is applicable for the Windows 10 Home edition. +- **RemediationDeliverToastDeviceIncludedNation** Indicates the geographic identifier (GEO ID) that is applicable for a given plug-in. +- **RemediationDeliverToastDeviceProSku** Indicates whether the plug-in is applicable for the Windows 10 Professional edition. +- **RemediationDeliverToastDeviceSystemDiskSizeInMB** Indicates the size of a system disk, in megabytes. +- **RemediationDeliverToastGeoId** Indicates the geographic identifier (GEO ID) that is applicable for a given plug-in. +- **RemediationDeviceSkuId** The Windows 10 edition ID that maps to the version of Windows 10 on the device. +- **RemediationGetCurrentFolderExist** Indicates whether the GetCurrent folder exists. - **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. - **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. - **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. @@ -4911,35 +5017,40 @@ The following fields are available: - **RemediationNoisyHammerMeteredNetwork** TRUE if the machine is on a metered network. - **RemediationNoisyHammerTaskEnabled** Indicates whether the Update Assistant Task (Noisy Hammer) is enabled. - **RemediationNoisyHammerTaskExists** Indicates whether the Update Assistant Task (Noisy Hammer) exists. -- **RemediationNoisyHammerTasksStalled** No content is currently available. +- **RemediationNoisyHammerTasksStalled** Indicates whether a task (Noisy Hammer) is stalled. - **RemediationNoisyHammerTaskTriggerEnabledCount** Indicates whether counting is enabled for the Update Assistant (Noisy Hammer) task trigger. - **RemediationNoisyHammerUAExitCode** The exit code of the Update Assistant (Noisy Hammer) task. - **RemediationNoisyHammerUAExitState** The code for the exit state of the Update Assistant (Noisy Hammer) task. - **RemediationNoisyHammerUserLoggedIn** TRUE if there is a user logged in. - **RemediationNoisyHammerUserLoggedInAdmin** TRUE if there is the user currently logged in is an Admin. -- **RemediationNotifyUserFixIssuesBoxStatusKey** No content is currently available. -- **RemediationNotifyUserFixIssuesBuildNumber** No content is currently available. -- **RemediationNotifyUserFixIssuesDetected** No content is currently available. -- **RemediationNotifyUserFixIssuesDiskSpace** No content is currently available. -- **RemediationNotifyUserFixIssuesFeatureUpdateBlocked** No content is currently available. -- **RemediationNotifyUserFixIssuesFeatureUpdateInProgress** No content is currently available. -- **RemediationNotifyUserFixIssuesIsUserAdmin** No content is currently available. -- **RemediationNotifyUserFixIssuesIsUserLoggedIn** No content is currently available. -- **RemediationProgramDataFolderSizeInMB** No content is currently available. -- **RemediationProgramFilesFolderSizeInMB** No content is currently available. -- **RemediationShellDeviceEducationSku** No content is currently available. -- **RemediationShellDeviceEnterpriseSku** No content is currently available. -- **RemediationShellDeviceFeatureUpdatesPaused** No content is currently available. -- **RemediationShellDeviceHomeSku** No content is currently available. -- **RemediationShellDeviceIsAllowedSku** No content is currently available. +- **RemediationNotifyUserFixIssuesBoxStatusKey** Status of the remediation plug-in. +- **RemediationNotifyUserFixIssuesBuildNumber** The build number of the remediation plug-in. +- **RemediationNotifyUserFixIssuesDetected** Indicates whether the remediation is necessary. +- **RemediationNotifyUserFixIssuesDiskSpace** Indicates whether the remediation is necessary due to low disk space. +- **RemediationNotifyUserFixIssuesFeatureUpdateBlocked** Indicates whether the remediation is necessary due to Feature Updates being blocked. +- **RemediationNotifyUserFixIssuesFeatureUpdateInProgress** Indicates whether the remediation is necessary due to Feature Updates in progress. +- **RemediationNotifyUserFixIssuesIsUserAdmin** Indicates whether the remediation requires that an Administrator is logged in. +- **RemediationNotifyUserFixIssuesIsUserLoggedIn** Indicates whether the remediation can take place when a non-Administrator is logged in. +- **RemediationProgramDataFolderSizeInMB** The size (in megabytes) of the Program Data folder on the device. +- **RemediationProgramFilesFolderSizeInMB** The size (in megabytes) of the Program Files folder on the device. +- **RemediationShellDeviceApplicabilityFailedReason** No content is currently available. +- **RemediationShellDeviceEducationSku** Indicates whether a Windows 10 Education edition is detected on the device. +- **RemediationShellDeviceEnterpriseSku** Indicates whether a Windows 10 Enterprise edition is detected on the device. +- **RemediationShellDeviceFeatureUpdatesPaused** Indicates whether Feature Updates are paused on the device. +- **RemediationShellDeviceHomeSku** Indicates whether a Windows 10 Home edition is detected on the device. +- **RemediationShellDeviceIsAllowedSku** Indicates whether the Windows 10 edition is applicable to the device. - **RemediationShellDeviceManaged** TRUE if the device is WSUS managed or Windows Updated disabled. - **RemediationShellDeviceNewOS** TRUE if the device has a recently installed OS. -- **RemediationShellDeviceProSku** No content is currently available. -- **RemediationShellDeviceQualityUpdatesPaused** No content is currently available. +- **RemediationShellDeviceProSku** Indicates whether a Windows 10 Professional edition is detected. +- **RemediationShellDeviceQualityUpdatesPaused** Indicates whether Quality Updates are paused on the device. - **RemediationShellDeviceSccm** TRUE if the device is managed by SCCM (Microsoft System Center Configuration Manager). -- **RemediationShellDeviceSetupMutexInUse** No content is currently available. -- **RemediationShellDeviceWuRegistryBlocked** No content is currently available. +- **RemediationShellDeviceSedimentMutexInUse** No content is currently available. +- **RemediationShellDeviceSetupMutexInUse** Indicates whether device setup is in progress. +- **RemediationShellDeviceWuRegistryBlocked** Indicates whether the Windows Update is blocked on the device via the registry. - **RemediationShellDeviceZeroExhaust** TRUE if the device has opted out of Windows Updates completely. +- **RemediationShellHasExpired** No content is currently available. +- **RemediationShellHasUpgraded** No content is currently available. +- **RemediationShellIsDeviceApplicable** No content is currently available. - **RemediationTargetMachine** Indicates whether the device is a target of the specified fix. - **RemediationTaskHealthAutochkProxy** True/False based on the health of the AutochkProxy task. - **RemediationTaskHealthChkdskProactiveScan** True/False based on the health of the Check Disk task. @@ -4949,26 +5060,26 @@ The following fields are available: - **RemediationTaskHealthUSO_ScheduleScanTask** True/False based on the health of the USO (Update Session Orchestrator) Schedule task. - **RemediationTaskHealthWindowsUpdate_ScheduledStartTask** True/False based on the health of the Windows Update Scheduled Start task. - **RemediationTaskHealthWindowsUpdate_SihbootTask** True/False based on the health of the Sihboot task. -- **RemediationUHServiceDisabledBitMap** No content is currently available. -- **RemediationUHServiceNotExistBitMap** No content is currently available. -- **RemediationUsersFolderSizeInMB** No content is currently available. -- **RemediationWindows10UpgradeFolderExist** No content is currently available. -- **RemediationWindows10UpgradeFolderSizeInMB** No content is currently available. -- **RemediationWindowsAppsFolderSizeInMB** No content is currently available. -- **RemediationWindowsBtFolderSizeInMB** No content is currently available. -- **RemediationWindowsFolderSizeInMB** No content is currently available. -- **RemediationWindowsServiceProfilesFolderSizeInMB** No content is currently available. +- **RemediationUHServiceDisabledBitMap** A bitmap indicating which services were disabled. +- **RemediationUHServiceNotExistBitMap** A bitmap indicating which services were deleted. +- **RemediationUsersFolderSizeInMB** The size (in megabytes) of the Users folder on the device. +- **RemediationWindows10UpgradeFolderExist** Indicates whether the Windows 10 Upgrade folder exists. +- **RemediationWindows10UpgradeFolderSizeInMB** The size (in megabytes) of Windows 10 Upgrade folder on the device. +- **RemediationWindowsAppsFolderSizeInMB** The size (in megabytes) of the Windows Applications folder on the device. +- **RemediationWindowsBtFolderSizeInMB** The size (in megabytes) of the Windows BT folder on the device. +- **RemediationWindowsFolderSizeInMB** The size (in megabytes) of the Windows folder on the device. +- **RemediationWindowsServiceProfilesFolderSizeInMB** The size (in megabytes) of the Windows service profile on the device. - **Result** This is the HRESULT for Detection or Perform Action phases of the plugin. - **RunTask** TRUE if SIH task should be run by the plug-in. -- **StorageSenseDiskCompresserEstimateInMB** No content is currently available. -- **StorageSenseHelloFaceRecognitionFodCleanupEstimateInByte** No content is currently available. -- **StorageSenseRestorePointCleanupEstimateInMB** No content is currently available. -- **StorageSenseUserDownloadFolderCleanupEstimateInByte** No content is currently available. +- **StorageSenseDiskCompresserEstimateInMB** The estimated amount of free space that can be cleaned up by running Storage Sense. +- **StorageSenseHelloFaceRecognitionFodCleanupEstimateInByte** The estimated amount of space that can be cleaned up by running Storage Sense and removing Windows Hello facial recognition. +- **StorageSenseRestorePointCleanupEstimateInMB** The estimated amount of free space (in megabytes) that can be cleaned up by running Storage Sense. +- **StorageSenseUserDownloadFolderCleanupEstimateInByte** The estimated amount of space that can be cleaned up by running Storage Sense to clean up the User Download folder. - **TimeServiceNTPServer** The URL for the NTP time server used by device. - **TimeServiceStartType** The startup type for the NTP time service. - **TimeServiceSyncDomainJoined** True if device domain joined and hence uses DC for clock. - **TimeServiceSyncType** Type of sync behavior for Date & Time service on device. -- **uninstallActiveValue** No content is currently available. +- **uninstallActiveValue** Indicates whether an uninstall is in progress. - **UpdateApplicabilityFixerTriggerBitMap** No content is currently available. - **UpdateRebootTime** No content is currently available. - **usoScanHoursSinceLastScan** No content is currently available. @@ -4992,10 +5103,16 @@ The following fields are available: - **branchReadinessLevel** Branch readiness level policy. - **cloudControlState** Value indicating whether the shell is enabled on the cloud control settings. - **CV** The Correlation Vector. -- **DiskFreeSpaceAfterSedimentPackInMB** No content is currently available. -- **DiskFreeSpaceBeforeSedimentPackInMB** No content is currently available. +- **DiskFreeSpaceAfterSedimentPackInMB** The amount of free disk space (in megabytes) after executing the Sediment Pack. +- **DiskFreeSpaceBeforeSedimentPackInMB** The amount of free disk space (in megabytes) before executing the Sediment Pack. +- **DiskMbFreeAfterCleanup** The amount of free hard disk space after cleanup, measured in Megabytes. +- **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. +- **DiskSpaceCleanedByComponentCleanup** No content is currently available. +- **DiskSpaceCleanedByNGenRemoval** No content is currently available. +- **DiskSpaceCleanedByRestorePointRemoval** No content is currently available. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. +- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. - **hasRolledBack** Indicates whether the client machine has rolled back. - **hasUninstalled** Indicates whether the client machine has uninstalled a later version of the OS. - **hResult** The result of the event execution. @@ -5006,47 +5123,69 @@ The following fields are available: - **MicrosoftCompatibilityAppraiser** The name of the component targeted by the Appraiser plug-in. - **PackageVersion** The package version for the current Remediation. - **PluginName** The name of the plug-in specified for each generic plug-in event. -- **QualityUpdateSedimentExecutedPlugins** No content is currently available. -- **QualityUpdateSedimentFunnelState** No content is currently available. +- **QualityUpdateSedimentExecutedPlugins** The number of plug-ins executed by the Windows Quality Update remediation. +- **QualityUpdateSedimentFunnelState** The state of the Windows Quality Update remediation funnel for the device. - **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. -- **QualityUpdateSedimentLocalEndTime** No content is currently available. +- **QualityUpdateSedimentLocalEndTime** The local time on the device when the Windows Quality Update remediation executed. - **QualityUpdateSedimentLocaltTime** No content is currently available. -- **QualityUpdateSedimentMatchedTriggers** No content is currently available. -- **QualityUpdateSedimentModelExecutionSeconds** No content is currently available. +- **QualityUpdateSedimentMatchedTriggers** The list of triggers that were matched by the Windows Quality Update remediation. +- **QualityUpdateSedimentModelExecutionSeconds** The number of seconds needed to execute the Windows Quality Update remediation. - **recoveredFromTargetOS** No content is currently available. - **RemediationBatteryPowerBatteryLevel** Indicates the battery level at which it is acceptable to continue operation. - **RemediationBatteryPowerExitDueToLowBattery** True when we exit due to low battery power. - **RemediationBatteryPowerOnBattery** True if we allow execution on battery. +- **RemediationCbsTempDiskSpaceCleanedInMB** No content is currently available. +- **RemediationCbsTempEstimateInMB** No content is currently available. +- **RemediationComponentCleanupEstimateInMB** No content is currently available. - **RemediationConfigurationTroubleshooterIpconfigFix** TRUE if IPConfig Fix completed successfully. - **RemediationConfigurationTroubleshooterNetShFix** TRUE if network card cache reset ran successfully. - **RemediationCorruptionRepairCorruptionsDetected** Number of corruptions detected on the device. - **RemediationCorruptionRepairCorruptionsFixed** Number of detected corruptions that were fixed on the device. - **RemediationCorruptionRepairPerformActionSuccessful** Indicates whether corruption repair was successful on the device. +- **RemediationDiskCleanupSearchFileSizeInMB** No content is currently available. +- **RemediationDiskSpaceSavedByCompressionInMB** No content is currently available. +- **RemediationDiskSpaceSavedByUserProfileCompressionInMB** No content is currently available. - **remediationExecution** Remediation shell is in "applying remediation" state. +- **RemediationHandlerCleanupEstimateInMB** No content is currently available. - **RemediationHibernationMigrated** TRUE if hibernation was migrated. - **RemediationHibernationMigrationSucceeded** TRUE if hibernation migration succeeded. -- **RemediationNGenDiskSpaceRestored** No content is currently available. -- **RemediationNGenMigrationSucceeded** No content is currently available. +- **RemediationNGenDiskSpaceRestored** The amount of disk space (in megabytes) that was restored after re-running the Native Image Generator (NGEN). +- **RemediationNGenEstimateInMB** No content is currently available. +- **RemediationNGenMigrationSucceeded** Indicates whether the Native Image Generator (NGEN) migration succeeded. +- **RemediationRestorePointEstimateInMB** No content is currently available. +- **RemediationSearchFileSizeEstimateInMB** No content is currently available. - **RemediationShellHasUpgraded** TRUE if the device upgraded. - **RemediationShellMinimumTimeBetweenShellRuns** Indicates the time between shell runs exceeded the minimum required to execute plugins. - **RemediationShellRunFromService** TRUE if the shell driver was run from the service. - **RemediationShellSessionIdentifier** Unique identifier tracking a shell session. - **RemediationShellSessionTimeInSeconds** Indicates the time the shell session took in seconds. - **RemediationShellTaskDeleted** Indicates that the shell task has been deleted so no additional sediment pack runs occur for this installation. +- **RemediationSoftwareDistributionCleanedInMB** No content is currently available. +- **RemediationSoftwareDistributionEstimateInMB** No content is currently available. +- **RemediationTotalDiskSpaceCleanedInMB** No content is currently available. - **RemediationUpdateServiceHealthRemediationResult** The result of the Update Service Health plug-in. - **RemediationUpdateTaskHealthRemediationResult** The result of the Update Task Health plug-in. - **RemediationUpdateTaskHealthTaskList** A list of tasks fixed by the Update Task Health plug-in. +- **RemediationUserFolderCompressionEstimateInMB** No content is currently available. +- **RemediationUserProfileCompressionEstimateInMB** No content is currently available. - **RemediationUSORebootRequred** Indicates whether a reboot is determined to be required by calling the Update Service Orchestrator (USO). +- **RemediationWindowsCompactedEstimateInMB** No content is currently available. +- **RemediationWindowsLogSpaceEstimateInMB** No content is currently available. +- **RemediationWindowsLogSpaceFreed** The amount of disk space freed by deleting the Windows log files, measured in Megabytes. +- **RemediationWindowsOldSpaceEstimateInMB** No content is currently available. +- **RemediationWindowsSpaceCompactedInMB** No content is currently available. +- **RemediationWindowsStoreSpaceCleanedInMB** No content is currently available. +- **RemediationWindowsStoreSpaceEstimateInMB** No content is currently available. - **Result** The HRESULT for Detection or Perform Action phases of the plug-in. - **RunCount** The number of times the plugin has executed. - **RunResult** The HRESULT for Detection or Perform Action phases of the plug-in. - **ServiceHardeningExitCode** The exit code returned by Windows Service Repair. - **ServiceHealthEnabledBitMap** List of services updated by the plugin. - **ServiceHealthInstalledBitMap** List of services installed by the plugin. -- **StorageSenseDiskCompresserTotalInMB** No content is currently available. -- **StorageSenseHelloFaceRecognitionFodCleanupTotalInByte** No content is currently available. -- **StorageSenseRestorePointCleanupTotalInMB** No content is currently available. -- **StorageSenseUserDownloadFolderCleanupTotalInByte** No content is currently available. +- **StorageSenseDiskCompresserTotalInMB** The total number of megabytes that Storage Sense cleaned up in the User Download folder. +- **StorageSenseHelloFaceRecognitionFodCleanupTotalInByte** The amount of space that Storage Sense was able to clean up in the User Download folder by removing Windows Hello facial recognition. +- **StorageSenseRestorePointCleanupTotalInMB** The total number of megabytes that Storage Sense cleaned up in the User Download folder. +- **StorageSenseUserDownloadFolderCleanupTotalInByte** The total number of bytes that Storage Sense cleaned up in the User Download folder. - **systemDriveFreeDiskSpace** Indicates the free disk space on system drive in MBs. - **systemUptimeInHours** Indicates the amount of time the system in hours has been on since the last boot. - **uninstallActive** TRUE if previous uninstall has occurred for current OS @@ -5063,6 +5202,7 @@ The following fields are available: - **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". - **windows10UpgraderBlockWuUpdates** Event to report the value of Windows 10 Upgrader BlockWuUpdates Key. - **windowsEditionId** Event to report the value of Windows Edition ID. +- **WindowsOldSpaceCleanedInMB** The amount of disk space freed by removing the Windows.OLD folder, measured in Megabytes. - **windowsUpgradeRecoveredFromRs4** Event to report the value of the Windows Upgrade Recovered key. @@ -5076,16 +5216,32 @@ The following fields are available: - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. - **PackageVersion** Current package version of Remediation. - **PluginName** Name of the plugin specified for each generic plugin event. -- **QualityUpdateSedimentFunnelState** No content is currently available. +- **QualityUpdateSedimentFunnelState** Provides information about whether quality updates are missing on the device. +- **QualityUpdateSedimentFunnelType** No content is currently available. - **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. -- **QualityUpdateSedimentLastRunSeconds** No content is currently available. +- **QualityUpdateSedimentLastRunSeconds** The number of seconds since Quality Updates were run. - **QualityUpdateSedimentLocaltTime** No content is currently available. - **QualityUpdateSedimentMatchedTriggers** No content is currently available. - **QualityUpdateSedimentSelectedPlugins** No content is currently available. - **QualityUpdateSedimentTargetedPlugins** No content is currently available. -- **QualityUpdateSedimentTargetedTriggers** No content is currently available. +- **QualityUpdateSedimentTargetedTriggers** The list of triggers targeted by the current quality update sediment remediation run. +- **RemediationProgramDataFolderSizeInMB** No content is currently available. +- **RemediationProgramFilesFolderSizeInMB** No content is currently available. +- **RemediationUsersFolderSizeInMB** No content is currently available. +- **RemediationWindowsAppsFolderSizeInMB** No content is currently available. +- **RemediationWindowsBtFolderSizeInMB** No content is currently available. +- **RemediationWindowsFolderSizeInMB** No content is currently available. +- **RemediationWindowsServiceProfilesFolderSizeInMB** No content is currently available. +- **RemediationWindowsTotalSystemDiskSize** No content is currently available. - **Result** This is the HRESULT for detection or perform action phases of the plugin. - **RunCount** The number of times the remediation event started (whether it completed successfully or not). +- **WindowsHiberFilSysSizeInMegabytes** No content is currently available. +- **WindowsInstallerFolderSizeInMegabytes** No content is currently available. +- **WindowsOldFolderSizeInMegabytes** No content is currently available. +- **WindowsPageFileSysSizeInMegabytes** No content is currently available. +- **WindowsSoftwareDistributionFolderSizeInMegabytes** No content is currently available. +- **WindowsSwapFileSysSizeInMegabytes** No content is currently available. +- **WindowsSxsFolderSizeInMegabytes** No content is currently available. ## Sediment events @@ -5263,8 +5419,15 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: +- **FaeldName** No content is currently available. +- **FieddName** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. +- **FieldNime** No content is currently available. +- **Gro}pName** No content is currently available. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. +- **GzoupName** No content is currently available. +- **OroupName** No content is currently available. +- **Vadue** No content is currently available. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -5276,6 +5439,7 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: +- **__TlgCV_W** No content is currently available. - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. - **AllowCachedResults** Indicates if the scan allowed using cached results. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable @@ -5287,12 +5451,15 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BranchReadinessLevel** The servicing branch configured on the device. - **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. +- **CallerApplacationN!me** No content is currently available. - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - **ClientVersion** The version number of the software distribution client. +- **ClientWersion** No content is currently available. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. +- **ComvonProps** No content is currently available. - **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). @@ -5301,8 +5468,11 @@ The following fields are available: - **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. - **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. - **DriverSyncPassPerformed** Were drivers scanned this time? +- **EventIfstanceI** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **ExsendedMetadataCabUrl** No content is currently available. +- **ExsendedStatusCode** No content is currently available. - **ExtendedMetadataCabUrl** Hostname that is used to download an update. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. @@ -5314,6 +5484,7 @@ The following fields are available: - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. +- **IntentPINs** No content is currently available. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. @@ -5321,10 +5492,12 @@ The following fields are available: - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **NumberOfApplicableUpdatds** No content is currently available. - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan +- **NumberOfNewUpdatesFrvFServiceSync** No content is currently available. - **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan - **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. - **Online** Indicates if this was an online scan. @@ -5346,6 +5519,7 @@ The following fields are available: - **ServiceUrl** The environment URL a device is configured to scan with - **ShippingMobileOperator** The mobile operator that a device shipped on. - **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). +- **Statusode** No content is currently available. - **SyncType** Describes the type of scan the event was - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. @@ -5411,17 +5585,19 @@ The following fields are available: - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. +- **CaLlerApplicationName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. +- **ComvonProps** No content is currently available. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** The model of the device. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation properties in the form of a bitmask. +- **DownloadProps** Information about the download operation. - **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. @@ -5429,6 +5605,7 @@ The following fields are available: - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBuildN�mber** No content is currently available. - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -5471,7 +5648,6 @@ The following fields are available: - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. - **UpdateImportance** Indicates whether the content was marked as Important, Recommended, or Optional. -- **UpdatEImportance** No content is currently available. - **UsedDO** Indicates whether the download used the Delivery Optimization (DO) service. - **UsedSystemVolume** Indicates whether the content was downloaded to the device's main system storage drive, or an alternate storage drive. - **WUDeviceID** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. @@ -5575,6 +5751,7 @@ The following fields are available: - **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. - **IsFirmware** Indicates whether this update is a firmware update. - **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. +- **IsWufBDualScanEnabled** No content is currently available. - **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. - **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. @@ -6324,10 +6501,15 @@ This event sends data about OS deployment scenarios, to help keep Windows up-to- The following fields are available: +- **^alue** No content is currently available. - **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. +- **FdightData** No content is currently available. - **FieldName** Retrieves the data point. +- **FimldName** No content is currently available. - **FlightData** Specifies a unique identifier for each group of Windows Insider builds. - **InstanceId** Retrieves a unique identifier for each instance of a setup session. +- **InstanceIl** No content is currently available. +- **InstancmId** No content is currently available. - **ReportId** Retrieves the report ID. - **ScenarioId** Retrieves the deployment scenario. - **Value** Retrieves the value associated with the corresponding FieldName. @@ -6366,6 +6548,7 @@ The following fields are available: - **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. - **MitigationScenario** The update scenario in which the mitigation was executed. - **Name** The friendly (descriptive) name of the mitigation. +- **OperatignName** No content is currently available. - **OperationIndex** The mitigation operation index (in the event of a failure). - **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). - **RegistryCount** The number of registry operations in the mitigation entry. @@ -6444,6 +6627,7 @@ The following fields are available: - **callerApplication** The name of the calling application. - **capsuleCount** The number of Sediment Pack capsules. - **capsuleFailureCount** The number of capsule failures. +- **detecd1drSummary** No content is currently available. - **detectionSummary** Result of each applicable detection that was run. - **featureAssessmentImpact** WaaS Assessment impact for feature updates. - **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. @@ -6454,10 +6638,12 @@ The following fields are available: - **isInteractiveMode** The user started a run of WaaSMedic. - **isManaged** Device is managed for updates. - **isWUConnected** Device is connected to Windows Update. +- **noMoreAcd1drs** No content is currently available. - **noMoreActions** No more applicable diagnostics. - **pluginFailureCount** The number of plugins that have failed. - **pluginsCount** The number of plugins. - **qualityAssessmentImpact** WaaS Assessment impact for quality updates. +- **remediad1drSummary** No content is currently available. - **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. - **usingBackupFeatureAssessment** Relying on backup feature assessment. - **usingBackupQualityAssessment** Relying on backup quality assessment. @@ -6643,6 +6829,7 @@ The following fields are available: - **IsBundle** Is this a bundle? - **IsInteractive** Is this initiated by the user? - **IsMandatory** Is this a mandatory installation? +- **IsRemedi-0000** No content is currently available. - **IsRemediation** Is this repairing a previous installation? - **IsRestore** Is this a restore of a previously acquired product? - **IsUpdate** Is this an update? @@ -6792,6 +6979,7 @@ This event is sent at the beginning of an app install or update to help keep Win The following fields are available: +- **__lgCV__** No content is currently available. - **CatalogId** The name of the product catalog from which this app was chosen. - **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. - **PFN** The Package Family Name of the app that is being installed or updated. @@ -6988,15 +7176,18 @@ The following fields are available: - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. - **bytesFromLinkLocalPeers** The number of bytes received from local peers. +- **bytesFromLocadCache** No content is currently available. - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. - **bytesRequested** The total number of bytes requested for download. +- **byvesFromCacheServer** No content is currently available. - **cacheServerConnectionCount** Number of connections made to cache hosts. - **cdnConnectionCount** The total number of connections made to the CDN. - **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. - **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). +- **cfileSize** No content is currently available. - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). @@ -7015,11 +7206,14 @@ The following fields are available: - **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. +- **lanConnectionCoujt** No content is currently available. - **lanConnectionCount** The total number of connections made to peers in the same LAN. - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. - **predefinedCallerName** The name of the API Caller. +- **restrictederRepo** No content is currently available. +- **restrictedloaded** No content is currently available. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. - **sessionID** The ID of the download session. @@ -7028,6 +7222,7 @@ The following fields are available: - **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). - **uplinkUsageBps** The upload speed (in bytes per second). - **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. +- **ytesRequested** No content is currently available. ### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused @@ -7043,6 +7238,7 @@ The following fields are available: - **fileID** The ID of the file being paused. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. +- **pagaefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller object. - **reasonCode** The reason for pausing the download. - **routeToCacheServer** The cache server setting, source, and value. @@ -7063,6 +7259,7 @@ The following fields are available: - **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). - **diceRoll** Random number used for determining if a client will use peering. - **doClientVersion** The version of the Delivery Optimization client. +- **doEr2orCode** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). - **downloadModeReason** Reason for the download. @@ -7078,8 +7275,10 @@ The following fields are available: - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. - **peerID** The ID for this delivery optimization client. +- **pgerID** No content is currently available. - **predefinedCallerName** Name of the API caller. - **routeToCacheServer** Cache server setting, source, and value. +- **sessionId** No content is currently available. - **sessionID** The ID for the file download session. - **setConbigs** No content is currently available. - **setConfigs** A JSON representation of the configurations that have been set, and their sources. @@ -7701,6 +7900,7 @@ The following fields are available: - **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. - **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. - **scanTriggerSource** Indicates what caused the scan. +- **scanTriggerSouRce** No content is currently available. - **updateScenarioType** The update session type. - **wuDeviceid** Unique device ID used by Windows Update. From 419edba10b52a37d6f534609782ae5de35cea607 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Thu, 11 Apr 2019 10:03:34 -0700 Subject: [PATCH 160/737] source paths --- .openpublishing.redirection.json | 172 ++++++++++++++++++++++++++----- 1 file changed, 146 insertions(+), 26 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 7b46d8e423..1e2d95073b 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -1216,8 +1216,13 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machines-view-overview", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-alerts", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", "redirect_document_id": true }, { @@ -1231,38 +1236,68 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/onboard-configure", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/portal-overview", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/powerbi-reports", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/powershell-example-code-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/powershell-example-code", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/preferences-setup-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/preferences-setup", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/prerelease.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/prerelease", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/prerelease.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/prerelease", "redirect_document_id": true }, { @@ -1271,38 +1306,78 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/preview-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/preview", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/preview-settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/preview-settings", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/pull-alerts-using-rest-api", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/python-example-code-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/python-example-code", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/respond-file-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/respond-machine-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/response-actions-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/response-actions-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/response-actions", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/run-detection-test-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/run-detection-test", "redirect_document_id": true }, { @@ -1311,8 +1386,8 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/service-status-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/service-status", "redirect_document_id": true }, { @@ -1321,28 +1396,18 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/supported-response-apis-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/supported-response-apis", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/threat-indicator-concepts-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/threat-indicator-concepts", "redirect_document_id": true }, { @@ -1351,8 +1416,48 @@ "redirect_document_id": true }, { -"source_path": "windows/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection", +"source_path": "windows/security/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/troubleshoot", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-custom-ti", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding-error-messages", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/troubleshoot-siem-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-siem", "redirect_document_id": true }, { @@ -1361,6 +1466,21 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/use-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/use", +"redirect_document_id": true +}, +{ +"source_path": "windows/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/use-custom-ti-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/use-custom-ti", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection", "redirect_document_id": true From f8c21a798f4377016fd44696b30bc8f5a289fd44 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Thu, 11 Apr 2019 10:52:44 -0700 Subject: [PATCH 161/737] redirects --- .openpublishing.redirection.json | 170 +++++++++++++++++++++++-------- 1 file changed, 125 insertions(+), 45 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 1e2d95073b..7cad091704 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -871,6 +871,11 @@ "redirect_document_id": true }, { +"source_path": "windows/keep-secure/advanced-features-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -881,6 +886,21 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-best-practices", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/advanced-hunting-reference-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/advanced-hunting-reference", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -901,6 +921,11 @@ "redirect_document_id": true }, { +"source_path": "windows/keep-secure/assign-portal-access-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -911,6 +936,21 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/attack-simulations-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/attack-simulations", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/automated-investigations", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/basic-permissions-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/basic-permissions", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/check-sensor-status-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -931,6 +971,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/conditional-access-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/conditional-access", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-arcsight-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -941,6 +986,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-conditional-access-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-conditional-access", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-email-notifications-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -951,6 +1001,21 @@ "redirect_document_id": true }, { +"source_path": "windows/keep-secure/additional-configuration-windows-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/keep-secure/monitor-onboarding-windows-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", +"redirect_document_id": false +}, +{ +"source_path": "windows/keep-secure/configure-endpoints-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1021,6 +1086,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/configure-mssp-support-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/configure-mssp-support", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1071,6 +1141,16 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/general-settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/data-retention-settings", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/data-storage-privacy-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1101,6 +1181,26 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-secure-score", +"redirect_document_id": true +}, +{ +"source_path": "windows/keep-secure/configure-aad-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/keep-secure/enable-siem-integration-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1141,6 +1241,26 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-cvekbmap-collection-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/get-cvekbmap-collection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-kbinfo-collection-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/get-kbinfo-collection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machinegroups-collection-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/get-machinegroups-collection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machinesecuritystates-collection-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/get-machinesecuritystates-collection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-alerts-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1486,6 +1606,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md", "redirect_url": "/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard", "redirect_document_id": true @@ -5491,11 +5616,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/configure-aad-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/manage/cortana-at-work-scenario-7.md", "redirect_url": "/windows/configuration/cortana-at-work/cortana-at-work-scenario-7", "redirect_document_id": true @@ -6006,11 +6126,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/additional-configuration-windows-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/keep-secure/ad-ds-schema-extensions-to-support-tpm-backup.md", "redirect_url": "https://technet.microsoft.com/library/jj635854.aspx", "redirect_document_id": true @@ -6061,11 +6176,6 @@ "redirect_document_id": false }, { -"source_path": "windows/keep-secure/monitor-onboarding-windows-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", -"redirect_document_id": false -}, -{ "source_path": "windows/keep-secure/passport-event-300.md", "redirect_url": "/windows/access-protection/hello-for-business/hello-event-300", "redirect_document_id": true @@ -8046,11 +8156,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/advanced-features-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/advanced-features-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/keep-secure/advanced-security-audit-policy-settings.md", "redirect_url": "/windows/device-security/auditing/advanced-security-audit-policy-settings", "redirect_document_id": true @@ -8151,11 +8256,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/assign-portal-access-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/keep-secure/assign-security-group-filters-to-the-gpo.md", "redirect_url": "/windows/access-protection/windows-firewall/assign-security-group-filters-to-the-gpo", "redirect_document_id": true @@ -8816,11 +8916,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/configure-endpoints-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/configure-endpoints-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/keep-secure/configure-exceptions-for-an-applocker-rule.md", "redirect_url": "/windows/device-security/applocker/configure-exceptions-for-an-applocker-rule", "redirect_document_id": true @@ -9456,11 +9551,6 @@ "redirect_document_id": true }, { -"source_path": "windows/keep-secure/enable-siem-integration-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/threat-protection/windows-defender-atp/enable-siem-integration-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/keep-secure/enable-the-dll-rule-collection.md", "redirect_url": "/windows/device-security/applocker/enable-the-dll-rule-collection", "redirect_document_id": true @@ -13896,16 +13986,6 @@ "redirect_document_id": true }, { -"source_path": "windows/security/threat-protection/windows-defender-atp/general-settings-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/data-retention-settings-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/security/threat-protection/windows-defender-atp/enable-security-analytics-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/enable-secure-score-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/security/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection", "redirect_document_id": true From 2b80aa42e36d19e3d6571d097d9121d93f0484ad Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Thu, 11 Apr 2019 14:22:50 -0700 Subject: [PATCH 162/737] redirects --- .openpublishing.redirection.json | 145 +++++++++++++++++++++++++++---- 1 file changed, 130 insertions(+), 15 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 7cad091704..0871ecbeb5 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -1291,6 +1291,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/investigate-incidents", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/investigate-ip-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1331,6 +1336,16 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/machine-groups-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machine-groups", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machine-reports", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/machines-view-overview-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1341,6 +1356,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/machine-tags-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machine-tags", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/manage-alerts-windows-defender-advanced-threat-protection.md", "redirect_document_id": true @@ -1351,6 +1371,41 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-automation-allowed-blocked-list", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-automation-file-uploads-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-automation-file-uploads", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-automation-folder-exclusions", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-incidents-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-incidents", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/manage-suppression-rules-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-suppression-rules", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/minimum-requirements-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1361,6 +1416,16 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/mssp-support-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/mssp-support", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/offboard-machines-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/offboard-machines", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/onboard-configure-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1371,6 +1436,21 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/onboard-downlevel-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/onboard-downlevel", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/overview-hunting-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/overview-hunting", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/overview-secure-score-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1461,6 +1541,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/rbac", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/respond-file-alerts-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1501,6 +1586,26 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/secure-score-dashboard", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/dashboard-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/security-operations-dashboard", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/service-status-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/service-status-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1531,6 +1636,21 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/threat-protection-reports", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/time-settings", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/troubleshoot-windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1601,6 +1721,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/user-roles", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection", "redirect_document_id": true @@ -1611,6 +1736,11 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/windows-defender-security-center-atp.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-security-center", +"redirect_document_id": true +}, +{ "source_path": "windows/threat-protection/windows-defender-application-guard/configure-wd-app-guard.md", "redirect_url": "/windows/security/threat-protection/windows-defender-application-guard/configure-wd-app-guard", "redirect_document_id": true @@ -13971,26 +14101,11 @@ "redirect_document_id": true }, { -"source_path": "windows/security/threat-protection/windows-defender-atp/security-analytics-dashboard-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/secure-score-dashboard-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ -"source_path": "windows/security/threat-protection/windows-defender-atp/dashboard-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/security-operations-dashboard-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/security/threat-protection/windows-defender-atp/threat-analytics-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/threat-analytics-dashboard-windows-defender-advanced-threat-protection", "redirect_document_id": true }, { -"source_path": "windows/security/threat-protection/windows-defender-atp/settings-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/time-settings-windows-defender-advanced-threat-protection", -"redirect_document_id": true -}, -{ "source_path": "windows/privacy/basic-level-windows-diagnostic-events-and-fields.md", "redirect_url": "/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809", "redirect_document_id": true From 9362faa749dda8b810888ccccf8a77ae5bf02b81 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Thu, 11 Apr 2019 16:22:17 -0700 Subject: [PATCH 163/737] redirects --- .openpublishing.redirection.json | 67 ++++++++++++++++++++++++++++++-- 1 file changed, 64 insertions(+), 3 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 0871ecbeb5..e287ccb9e0 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -14211,11 +14211,21 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alerts", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-actor-info-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14226,33 +14236,63 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { -"source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", +"source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines", +"redirect_document_id": false +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics", "redirect_document_id": false }, { @@ -14261,6 +14301,11 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/block-file-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14269,7 +14314,13 @@ "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false -},{ +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-file-information", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14320,11 +14371,21 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/collect-investigation-package", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip", +"redirect_document_id": false +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-filemachineaction-object-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false From 4577041a35c33988074ad3fcc499af040c685b13 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Fri, 12 Apr 2019 11:38:52 -0700 Subject: [PATCH 164/737] redirects --- .openpublishing.redirection.json | 117 ++++++++++++++++++++++++++++--- 1 file changed, 106 insertions(+), 11 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index e287ccb9e0..8d85371c03 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -14223,7 +14223,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-info-by-id-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-info-by-id", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-actor-info-windows-defender-advanced-threat-protection.md", @@ -14238,7 +14238,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-domain-info-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-domain-info", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection.md", @@ -14248,7 +14248,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-files-info-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-files-info", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection.md", @@ -14258,7 +14258,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-ip-info-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-ip-info", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection.md", @@ -14268,7 +14268,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-machine-info-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-machine-info", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection.md", @@ -14278,7 +14278,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-alerts-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-alerts", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection.md", @@ -14288,12 +14288,12 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-related-machines-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-related-machines", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-domain-statistics-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-domain-statistics", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection.md", @@ -14303,7 +14303,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/is-domain-seen-in-org-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/is-domain-seen-in-org", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/block-file-windows-defender-advanced-threat-protection.md", @@ -14318,7 +14318,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-information-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-file-information", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection.md", @@ -14326,16 +14326,31 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-file-related-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-file-related-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-file-related-machines-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-file-related-machines", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-file-statistics-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-file-statistics", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-fileactions-collection-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14351,16 +14366,31 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-ip-related-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-ip-related-machines-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-ip-related-machines", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-ip-statistics-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-ip-statistics", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14383,7 +14413,7 @@ { "source_path": "windows/security/threat-protection/windows-defender-atp/find-machine-info-by-ip-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/find-machine-info-by-ip", -"redirect_document_id": false +"redirect_document_id": true }, { "source_path": "windows/security/threat-protection/windows-defender-atp/get-filemachineaction-object-windows-defender-advanced-threat-protection.md", @@ -14391,26 +14421,51 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-filemachineaction-object-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-filemachineaction-object", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-filemachineactions-collection-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-filemachineactions-collection-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-filemachineactions-collection", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-by-id-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-machine-by-id", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-log-on-users-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-machine-log-on-users", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machine-related-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-machine-related-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-machineaction-object-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14426,11 +14481,21 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-machines-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-machines", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-package-sas-uri-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-package-sas-uri", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14471,21 +14536,51 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-alert-related-user-info", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/get-ti-indicators-collection-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-ti-indicators-collection", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-user-information-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-user-information-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-user-information", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-user-related-alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-user-related-alerts", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/get-user-related-machines-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/get-user-related-machines", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/initiate-autoir-investigation-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/initiate-autoir-investigation", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-ti-indicator-by-id-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false From 843b9988a4ec0b69aeecb5579772ef240bfe1e14 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Fri, 12 Apr 2019 12:07:14 -0700 Subject: [PATCH 165/737] redirects --- .openpublishing.redirection.json | 100 +++++++++++++++++++++++++++++++ 1 file changed, 100 insertions(+) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 8d85371c03..79df2e526c 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -14396,6 +14396,11 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/is-ip-seen-org-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/is-ip-seen-org", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/collect-investigation-package-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14496,21 +14501,41 @@ "redirect_document_id": true }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/machine-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machine", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/isolate-machine-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/isolate-machine", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/unisolate-machine-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/unisolate-machine", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/unrestrict-code-execution-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/unrestrict-code-execution", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/request-sample-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14521,16 +14546,31 @@ "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/restrict-code-execution-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/restrict-code-execution", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/run-av-scan-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/run-av-scan-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/run-av-scan", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/stop-quarantine-file-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false }, { +"source_path": "windows/security/threat-protection/windows-defender-atp/stop-quarantine-file-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/stop-quarantine-file", +"redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/get-alert-related-user-info-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/use-apis", "redirect_document_id": false @@ -14590,5 +14630,65 @@ "redirect_url": "/windows/security/threat-protection/windows-defender-atp/threat-analytics", "redirect_document_id": true }, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/add-or-remove-machine-tags-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/alerts-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/alerts", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/create-alert-by-reference-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/create-alert-by-reference", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/delete-ti-indicator-by-id-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/delete-ti-indicator-by-id", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/files-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/files", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/find-machines-by-ip-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/find-machines-by-ip", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/machineaction-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/machineaction", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/offboard-machine-api-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/offboard-machine-api", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/post-ti-indicator-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/post-ti-indicator", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/ti-indicator-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/ti-indicator", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/update-alert-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/update-alert", +"redirect_document_id": true +}, +{ +"source_path": "windows/security/threat-protection/windows-defender-atp/user-alert-windows-defender-advanced-threat-protection-new.md", +"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/user", +"redirect_document_id": true +} ] } From 46d34c80780e5d09db9ab693efb2137935b8ab29 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 15 Apr 2019 08:39:56 -0700 Subject: [PATCH 166/737] new build 4/15/2019 8:39 AM --- .../basic-level-windows-diagnostic-events-and-fields-1903.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 7cc546dd61..a32ec507e3 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/11/2019 +ms.date: 04/15/2019 --- @@ -2388,6 +2388,7 @@ This event sends data about boot IDs for which a normal clean shutdown was not o The following fields are available: - **AbnormalShutdownBootId** BootId of the abnormal shutdown being reported by this event. +- **AbsCausedbyAutoChk** No content is currently available. - **AcDcStateAtLastShutdown** Identifies if the device was on battery or plugged in. - **BatteryLevelAtLastShutdown** The last recorded battery level. - **BatteryPercentageAtLastShutdown** The battery percentage at the last shutdown. @@ -2402,6 +2403,7 @@ The following fields are available: - **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. - **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. - **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. +- **InvalidBootStat** No content is currently available. - **LastBugCheckBootId** bootId of the last captured crash. - **LastBugCheckCode** Code that indicates the type of error. - **LastBugCheckContextFlags** Additional crash dump settings. From 064240b87cbf2d34a0ca9add89caacc8a5d5d2fa Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 15 Apr 2019 08:40:04 -0700 Subject: [PATCH 167/737] new build 4/15/2019 8:39 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 26 +- ...ndows-diagnostic-events-and-fields-1709.md | 38 ++- ...ndows-diagnostic-events-and-fields-1803.md | 26 +- ...ndows-diagnostic-events-and-fields-1809.md | 313 +++++------------- 4 files changed, 142 insertions(+), 261 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index bf54d09ae5..a9d6322d66 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/11/2019 +ms.date: 04/15/2019 --- @@ -2958,24 +2958,24 @@ The following fields are available: ### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted -No content is currently available. +This event returns data to report the efficacy of a single-use tool to inform users impacted by a known issue and to take corrective action to address the issue. The following fields are available: -- **cleanupTask** No content is currently available. -- **cleanupTaskResult** No content is currently available. -- **deviceEvaluated** No content is currently available. -- **deviceImpacted** No content is currently available. -- **modalAction** No content is currently available. -- **modalResult** No content is currently available. -- **resetSettingsResult** No content is currently available. +- **cleanupTask** Indicates whether the task that launched the dialog should be cleaned up. +- **cleanupTaskResult** The return code of the attempt to clean up the task used to show the dialog. +- **deviceEvaluated** Indicates whether the device was eligible for evaluation of a known issue. +- **deviceImpacted** Indicates whether the device was impacted by a known issue. +- **modalAction** The action the user took on the dialog that was presented to them. +- **modalResult** The return code of the attempt to show a dialog to the user explaining the issue. +- **resetSettingsResult** The return code of the action to correct the known issue. ## Remediation events ### Microsoft.Windows.Remediation.Applicable -This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +deny The following fields are available: @@ -3059,7 +3059,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: @@ -3264,13 +3264,13 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event reports whether a plug-in started, to help ensure Windows is up to date. +deny The following fields are available: - **CV** Correlation vector. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **PackageVersion** Current package version of Remediation. +- **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Result** This is the HRESULT for detection or perform action phases of the plugin. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index e82222b6ab..8c42efe77e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/11/2019 +ms.date: 04/15/2019 --- @@ -3146,24 +3146,24 @@ The following fields are available: ### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted -No content is currently available. +This event returns data to report the efficacy of a single-use tool to inform users impacted by a known issue and to take corrective action to address the issue. The following fields are available: -- **cleanupTask** No content is currently available. -- **cleanupTaskResult** No content is currently available. -- **deviceEvaluated** No content is currently available. -- **deviceImpacted** No content is currently available. -- **modalAction** No content is currently available. -- **modalResult** No content is currently available. -- **resetSettingsResult** No content is currently available. +- **cleanupTask** Indicates whether the task that launched the dialog should be cleaned up. +- **cleanupTaskResult** The return code of the attempt to clean up the task used to show the dialog. +- **deviceEvaluated** Indicates whether the device was eligible for evaluation of a known issue. +- **deviceImpacted** Indicates whether the device was impacted by a known issue. +- **modalAction** The action the user took on the dialog that was presented to them. +- **modalResult** The return code of the attempt to show a dialog to the user explaining the issue. +- **resetSettingsResult** The return code of the action to correct the known issue. ## Remediation events ### Microsoft.Windows.Remediation.Applicable -This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +deny The following fields are available: @@ -3266,7 +3266,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: @@ -3399,13 +3399,13 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event reports whether a plug-in started, to help ensure Windows is up to date. +This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: - **CV** Correlation vector. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **PackageVersion** Current package version of Remediation. +- **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Result** This is the HRESULT for detection or perform action phases of the plugin. @@ -6566,6 +6566,12 @@ The following fields are available: ## Windows Update Reserve Manager events +### Microsoft.Windows.UpdateReserveManager.CommitPendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager commits a hard reserve adjustment that was pending. + + + ### Microsoft.Windows.UpdateReserveManager.InitializeUpdateReserveManager This event returns data about the Update Reserve Manager, including whether it’s been initialized. @@ -6578,6 +6584,12 @@ This event is sent when the Update Reserve Manager removes a pending hard reserv +### Microsoft.Windows.UpdateReserveManager.UpdatePendingHardReserveAdjustment + +This event is sent when the Update Reserve Manager needs to adjust the size of the hard reserve after the option content is installed. + + + ## Winlogon events ### Microsoft.Windows.Security.Winlogon.SetupCompleteLogon diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 5339268f09..38e274be19 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/11/2019 +ms.date: 04/15/2019 --- @@ -4247,24 +4247,24 @@ The following fields are available: ### Microsoft.Windows.Shell.PrivacyNotifierLogging.PrivacyNotifierCompleted -No content is currently available. +This event returns data to report the efficacy of a single-use tool to inform users impacted by a known issue and to take corrective action to address the issue. The following fields are available: -- **cleanupTask** No content is currently available. -- **cleanupTaskResult** No content is currently available. -- **deviceEvaluated** No content is currently available. -- **deviceImpacted** No content is currently available. -- **modalAction** No content is currently available. -- **modalResult** No content is currently available. -- **resetSettingsResult** No content is currently available. +- **cleanupTask** Indicates whether the task that launched the dialog should be cleaned up. +- **cleanupTaskResult** The return code of the attempt to clean up the task used to show the dialog. +- **deviceEvaluated** Indicates whether the device was eligible for evaluation of a known issue. +- **deviceImpacted** Indicates whether the device was impacted by a known issue. +- **modalAction** The action the user took on the dialog that was presented to them. +- **modalResult** The return code of the attempt to show a dialog to the user explaining the issue. +- **resetSettingsResult** The return code of the action to correct the known issue. ## Remediation events ### Microsoft.Windows.Remediation.Applicable -This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +deny The following fields are available: @@ -4368,7 +4368,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: @@ -4505,13 +4505,13 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event reports whether a plug-in started, to help ensure Windows is up to date. +This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: - **CV** Correlation vector. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **PackageVersion** Current package version of Remediation. +- **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Result** This is the HRESULT for detection or perform action phases of the plugin. - **RunCount** The number of times the remediation event started (whether it completed successfully or not). diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 9c1f8ed87b..f359c36a0c 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/11/2019 +ms.date: 04/15/2019 --- @@ -550,12 +550,10 @@ The following fields are available: - **AppraiserVersion** The version of the appraiser file that is generating the events. - **AvDisplayName** If the app is an anti-virus app, this is its display name. -- **CompateClasIndex** No content is currently available. - **CompatModelIndex** The compatibility prediction for this file. - **HasCitData** Indicates whether the file is present in CIT data. - **HasUpgradeExe** Indicates whether the anti-virus app has an upgrade.exe file. - **IsAv** Is the file an anti-virus reporting EXE? -- **ResolveAd85mpted** No content is currently available. - **ResolveAttempted** This will always be an empty string when sending telemetry. - **SdbEntries** An array of fields that indicates the SDB entries that apply to this file. @@ -591,7 +589,6 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: - **ActiveNetworkConnection** Indicates whether the device is an active network device. -- **ActiveNetworkCoompction** No content is currently available. - **AppraiserVersion** The version of the appraiser file generating the events. - **CosDeviceRating** An enumeration that indicates if there is a driver on the target operating system. - **CosDeviceSolution** An enumeration that indicates how a driver on the target operating system is available. @@ -2008,7 +2005,6 @@ The following fields are available: - **ServiceMachineIP** Retrieves the IP address of the KMS host used for anti-piracy. - **ServiceMachinePort** Retrieves the port of the KMS host used for anti-piracy. - **ServiceProductKeyID** Retrieves the License key of the KMS -- **SharedpCMode** No content is currently available. - **SharedPCMode** Returns Boolean for education devices used as shared cart - **Signature** Retrieves if it is a signature machine sold by Microsoft store. - **SLICStatus** Whether a SLIC table exists on the device. @@ -2053,7 +2049,6 @@ The following fields are available: - **Sms** Current state of the text messaging setting. - **SpeechPersonalization** Current state of the speech services setting. - **USB** Current state of the USB setting. -- **UserAccotntInformation** No content is currently available. - **UserAccountInformation** Current state of the account information setting. - **UserDataTasks** Current state of the tasks setting. - **UserNotificationListener** Current state of the notifications setting. @@ -2461,10 +2456,8 @@ Describes the installation state for all hardware and software components availa The following fields are available: -- **** No content is currently available. - **action** The change that was invoked on a device inventory object. - **inventoryId** Device ID used for Compatibility testing -- **objectIn** No content is currently available. - **objectInstanceId** Object identity which is unique within the device scope. - **objectType** Indicates the object type that the event applies to. - **syncId** A string used to group StartSync, EndSync, Add, and Remove operations that belong together. This field is unique by Sync period and is used to disambiguate in situations where multiple agents perform overlapping inventories for the same object. @@ -2514,7 +2507,6 @@ This event provides information about the results of installing or uninstalling The following fields are available: -- **`ighestState** No content is currently available. - **capabilities** The names of the optional content packages that were installed. - **clientId** The name of the application requesting the optional content. - **currentID** The ID of the current install session. @@ -2733,7 +2725,6 @@ The following fields are available: - **CanCollectOsTelemetry** True if we can collect diagnostic data telemetry, false otherwise. - **CanCollectWindowsAnalyticsEvents** True if we can collect Windows Analytics data, false otherwise. - **CanPerformDiagnosticEscalations** True if we can perform diagnostic escalation collection, false otherwise. -- **CanPerformDyagnosticEscalations** No content is currently available. - **CanPerformTraceEscalations** True if we can perform trace escalation collection, false otherwise. - **CanReportScenarios** True if we can report scenario completions, false otherwise. - **PreviousPermissions** Bitmask of previous telemetry state. @@ -2746,9 +2737,7 @@ This event sends data about the connectivity status of the Connected User Experi The following fields are available: -- **CensõsTaskEnabled** No content is currently available. - **CensusExitCode** Returns last execution codes from census client run. -- **CensusExitCodeoaderCensusStartTime** No content is currently available. - **CensusStartTime** Returns timestamp corresponding to last successful census run. - **CensusTaskEnabled** Returns Boolean value for the census task (Enable/Disable) on client machine. - **LastConnectivityLossTime** Retrieves the last time the device lost free network. @@ -2763,18 +2752,13 @@ This event sends data about the health and quality of the diagnostic data from t The following fields are available: -- **ꭤ↑롥戅ꔠ촉꤆䳨㢳桜ꀽ㴂颭ྞ䚿ꆁ억ﱎ콧ꓘ먗** No content is currently available. -- **AgentConneCouonErrorsCount** No content is currently available. - **AgentConnectionErrorsCount** Number of non-timeout errors associated with the host/agent channel. -- **CensõsTaskEnabled** No content is currently available. - **CensusExitCode** The last exit code of the Census task. - **CensusStartTime** Time of last Census run. - **CensusTaskEnabled** True if Census is enabled, false otherwise. - **CompressedBytesUploaded** Number of compressed bytes uploaded. -- **ConsumerDrop0edCount** No content is currently available. - **ConsumerDroppedCount** Number of events dropped at consumer layer of telemetry client. - **CriticalDataDbDroppedCount** Number of critical data sampled events dropped at the database layer. -- **CriticalDatasbDroppedCount** No content is currently available. - **CriticalDataThrottleDroppedCount** The number of critical data sampled events that were dropped because of throttling. - **CriticalOverflowEntersCounter** Number of times critical overflow mode was entered in event DB. - **DbCriticalDroppedCount** Total number of dropped critical events in event DB. @@ -2783,7 +2767,6 @@ The following fields are available: - **DbDroppedFullCount** Number of events dropped due to DB fullness. - **DecodingDroppedCount** Number of events dropped due to decoding failures. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EnteringCriticalOverflowDrOppedCounter** No content is currently available. - **EtwDroppedBufferCount** Number of buffers dropped in the UTC ETW session. - **EtwDroppedCount** Number of events dropped at ETW layer of telemetry client. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. @@ -2797,55 +2780,26 @@ The following fields are available: - **FullTriggerBufferDroppedCount** Number of events dropped due to trigger buffer being full. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **LastAgentConneCouonError** No content is currently available. - **LastAgentConnectionError** Last non-timeout error encountered in the host/agent channel. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **MaxACouveAgentConneCouonCount** No content is currently available. - **MaxActiveAgentConnectionCount** The maximum number of active agents during this heartbeat timeframe. - **MaxInUseScenarioCounter** Soft maximum number of scenarios loaded by UTC. -- **ᴗ㜛ﭮ紀⁻嬝藱唬穉聮쁪カ鳄髈** No content is currently available. - **PreviousHeartBeatTime** Time of last heartbeat event (allows chaining of events). - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailur$Dropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. -- **RepeatedUpѬoadFailureDropped** No content is currently available. -- **sbCriticalDroppedCount** No content is currently available. -- **sbDroppedCount** No content is currently available. -- **sbDroppedFailureCount** No content is currently available. -- **sbDroppedFullCount** No content is currently available. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **sorBdingDroppedCount** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. -- **ThrottlgdDroppedCount** No content is currently available. - **TopUploaderErrors** List of top errors received from the upload endpoint. -- **TopUploaeerErrors** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. -- **ǔ໦岋ࣉ䫕꧓ꏖ훭늓겲均効座⺽ඕ��嘩璽춒** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. - **VortexHttpFailures5xx** Number of 500-599 error codes received from Vortex. - **VortexHttpResponseFailures** Number of Vortex responses that are not 2XX or 400. - **VortexHttpResponsesWithDroppedEvents** Number of Vortex responses containing at least 1 dropped event. -- **ჯ⌷脻㍛䮥肑鍼Ⅵ䄪ꬃ鳃抍⓯钑볨䨎ᖪ먩諢涇͙켦榩偊撏嫄艸** No content is currently available. -- **반쐍⾋ꯈ��玱䁕��龓ⴶ샴賷헖쉺分╅㾚흦დ** No content is currently available. -- **빛䨮哆茠뢶☲偍矉繡귴틐⤺॓酠ꐜ⇫ꈚᑋ勰叙湧ㆧ噟ܝ㸇朤ಳ** No content is currently available. -- **쩤খ䠸퇫秂窇벘货齳��ꕢ顦ᜃⲎ耡��옥䦏��淨㖘⃵┵ᘵ鳝톈如癶첛ᲃ絍** No content is currently available. -- **퓙쏴撑⋇뭟혦꩑戙厀뎓燼㼿渺** No content is currently available. -- **훾電쇔䕅碎霶퍕◲⫒븩ὴ앏艐堗详鲝‶ᜧ** No content is currently available. -- **军伽礋圿萦꒎㲮꿨휒慢䷳橱瘒糜劷墹鎗ꭖ潨ᓔ** No content is currently available. -- **唹켴亰铳ᮍ㭨狣N洹滓ꦲ횴䝃怭픱烰彧魋阭刏⅄ꙹ꯬襖** No content is currently available. -- **櫠䰩遗ᆖᑒ��噊썻ࣆ鮷��㑡Ḯ偬ƚ㣸☂灚Ἇ汆磚䐯槴** No content is currently available. -- **蔇İᏘ࢔谼��ﰊ庸涝芦ᅳ蔭隷嵨̐ꊰ** No content is currently available. -- **裎墴_郐堩��ᴰ뵾핝㳊愨鳘鯡廭顩圧由꽆餢俗䡄ﳻ捳褮ꨞ㵙钫욯홏Ը໤ꖠ䬞悺俽** No content is currently available. -- **趬ᛉ뛀䲮憎** No content is currently available. -- **铽ჟᔛ}䘅��讀랃帷덉侙쩠뙆档玳꼱** No content is currently available. -- **㝫��粆疺⃩��렩榽ႚൾ滑햓ꎢ** No content is currently available. -- **㮆퍈栵ᥳⷣ뤏䳬HttpAttempts** No content is currently available. -- **䱪��໿��雔僽땧觪⊝쵥虚䧁嶟轶** No content is currently available. ### TelClientSynthetic.HeartBeat_Aria_5 @@ -2862,7 +2816,6 @@ The following fields are available: - **DbDroppedFailureCount** Number of events dropped due to database failures. - **DbDroppedFullCount** Number of events dropped due to database being full. - **EnteringCriticalOverflowDroppedCounter** Number of events dropped due to critical overflow mode being initiated. -- **EnteringCriticalOverflowDrOppedCounter** No content is currently available. - **EventsPersistedCount** Number of events that reached the PersistEvent stage. - **EventStoreLifetimeResetCounter** Number of times the event store has been reset. - **EventStoreResetCounter** Number of times the event store has been reset during this heartbeat. @@ -2870,18 +2823,14 @@ The following fields are available: - **EventsUploaded** Number of events uploaded. - **HeartBeatSequenceNumber** The sequence number of this heartbeat. - **InvalidHttpCodeCount** Number of invalid HTTP codes received from contacting Vortex. -- **InvalidHttpCsdeCount** No content is currently available. - **LastEventSizeOffender** Event name of last event which exceeded max event size. - **LastInvalidHttpCode** Last invalid HTTP code received from Vortex. -- **LastInvalidHttpCsde** No content is currently available. - **PreviousHeartBeatTime** The FILETIME of the previous heartbeat fire. - **PrivacyBlockedCount** The number of events blocked due to privacy settings or tags. -- **RepeatedUploadFailur$Dropped** No content is currently available. - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** Number of failures from contacting OneSettings service. - **TopUploaderErrors** List of top errors received from the upload endpoint. -- **TopUploaeerErrors** No content is currently available. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. - **VortexFailuresTimeout** Number of time out failures received from Vortex. @@ -3456,43 +3405,30 @@ The following fields are available: - **AdapterTypeValue** The numeric value indicating the type of Graphics adapter. - **aiSeqId** The event sequence ID. - **bootId** The system boot ID. -- **BraghtnessVersionViaDDI** No content is currently available. - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. -- **BrightnessVersionVyaDDI** No content is currently available. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. -- **DedDcatedSystemMemoryB** No content is currently available. -- **DedDcatedVideoMemoryB** No content is currently available. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DisplayAdapterLuid** The display adapter LUID. -- **DisplayAdapTerLuid** No content is currently available. - **DriverDate** The date of the display driver. - **DriverRank** The rank of the display driver. - **DriverVersion** The display driver version. - **DX10UMDFilePath** The file path to the location of the DirectX 10 Display User Mode Driver in the Driver Store. -- **DX11EMDFilePath** No content is currently available. - **DX11UMDFilePath** The file path to the location of the DirectX 11 Display User Mode Driver in the Driver Store. - **DX12UMDFilePath** The file path to the location of the DirectX 12 Display User Mode Driver in the Driver Store. - **DX9UMDFilePath** The file path to the location of the DirectX 9 Display User Mode Driver in the Driver Store. -- **FX9UMDFilePath** No content is currently available. -- **GPQPreemptionLevel** No content is currently available. - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. - **GPUVendorID** The GPU vendor ID. -- **I3SoftwareDevice** No content is currently available. - **InterfaceId** The GPU interface ID. -- **InturfaceId** No content is currently available. -- **Is@ybridDiscrete** No content is currently available. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? -- **IsHyrridDiscrete** No content is currently available. - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? - **IsMismatchLDA** Is at least one device in the Linked Display Adapters chain from a different vendor? -- **IsMismaTchLDA** No content is currently available. - **IsMPOSupported** Does the GPU support Multi-Plane Overlays? - **IsMsMiracastSupported** Are the GPU Miracast capabilities driven by a Microsoft solution? - **IsPostAdapter** Is this GPU the POST GPU in the device? @@ -3507,17 +3443,10 @@ The following fields are available: - **SharedSystemMemoryB** The amount of system memory shared by GPU and CPU (in bytes). - **SubSystemID** The subsystem ID. - **SubVendorID** The GPU sub vendor ID. -- **Tele}etryEnabled** No content is currently available. - **TelemetryEnabled** Is the device listening to MICROSOFT_KEYWORD_TELEMETRY? -- **TelInv2YntTrigger** No content is currently available. - **TelInvEvntTrigger** What triggered this event to be logged? Example: 0 (GPU enumeration) or 1 (DxgKrnlTelemetry provider toggling) -- **TX10UMDFilePath** No content is currently available. - **version** The event version. - **WDDMVersion** The Windows Display Driver Model version. -- **WPUPreemptionLevel** No content is currently available. -- **YsDisplayDevice** No content is currently available. -- **YsLDA** No content is currently available. -- **YsRenderDevice** No content is currently available. ## Failover Clustering events @@ -3603,42 +3532,24 @@ This event sends data about crashes for both native and managed applications, to The following fields are available: -- **.xceptionCode** No content is currently available. -- **.xceptionOffset** No content is currently available. -- **ags** No content is currently available. - **AppName** The name of the app that has crashed. - **AppSessionGuid** GUID made up of process ID and is used as a correlation vector for process instances in the telemetry backend. - **AppTimeStamp** The date/time stamp of the app. - **AppVersion** The version of the app that has crashed. -- **argetAsId** No content is currently available. -- **argetAsppId** No content is currently available. -- **argetAsppVer** No content is currently available. -- **d** No content is currently available. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. - **IsFatal** True/False to indicate whether the crash resulted in process termination. -- **Modame** No content is currently available. - **ModName** Exception module name (e.g. bar.dll). - **ModTimeStamp** The date/time stamp of the module. - **ModVersion** The version of the module that has crashed. -- **nCode** No content is currently available. -- **Pack9OeFullName** No content is currently available. -- **Pack9OeRelativeAppId** No content is currently available. -- **PackageFullame** No content is currently available. -- **PackageFullFame** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. -- **ProcessArchite2kure** No content is currently available. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. - **ProcessCreateTime** The time of creation of the process that has crashed. - **ProcessId** The ID of the process that has crashed. -- **pSessionGuid** No content is currently available. - **ReportId** A GUID used to identify the report. This can used to track the report across Watson. -- **RepoztId** No content is currently available. -- **TargetAId** No content is currently available. -- **TargetAppI4StartTime** No content is currently available. - **TargetAppId** The kernel reported AppId of the application being reported. - **TargetAppVer** The specific version of the application being reported - **TargetAsId** The sequence number for the hanging process. @@ -3764,19 +3675,15 @@ The following fields are available: - **InstallDateArpLastModified** The date of the registry ARP key for a given application. Hints at install date but not always accurate. Passed as an array. Example: 4/11/2015 00:00:00 - **InstallDateFromLinkFile** The estimated date of install based on the links to the files. Passed as an array. - **InstallDateMsi** The install date if the application was installed via Microsoft Installer (MSI). Passed as an array. -- **InstallDatgArpLastModified** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. - **Language** The language code of the program. - **MsiPackageCode** A GUID that describes the MSI Package. Multiple 'Products' (apps) can make up an MsiPackage. -- **MsiPackageColm** No content is currently available. - **MsiProductCode** A GUID that describe the MSI Product. - **Name** The name of the application. - **OSVersionAtInstallTime** The four octets from the OS version at the time of the application's install. -- **OSVersionAtInstallTioe** No content is currently available. - **PackageFullName** The package full name for a Store application. - **ProgramInstanceId** A hash of the file IDs in an app. - **Publisher** The Publisher of the application. Location pulled from depends on the 'Source' field. -- **RackageFullName** No content is currently available. - **RootDirPath** The path to the root directory where the program was installed. - **Source** How the program was installed (for example, ARP, MSI, Appx). - **StoreAppType** A sub-classification for the type of Microsoft Store app, such as UWP or Win8StoreApp. @@ -3874,7 +3781,6 @@ The following fields are available: - **ModelId** A unique model ID. - **ModelName** The model name. - **ModelNumber** The model number for the device container. -- **primaryCategory** No content is currently available. - **PrimaryCategory** The primary category for the device container. @@ -4031,9 +3937,7 @@ This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedevic The following fields are available: -- **inventoryId** No content is currently available. - **InventoryVersion** The version of the inventory file generating the events. -- **syncId** No content is currently available. ### Microsoft.Windows.Inventory.Core.InventoryDevicePnpStartSync @@ -4092,11 +3996,9 @@ The following fields are available: - **ImageSize** The size of the driver file. - **Inf** The name of the INF file. - **InventoryVersion** The version of the inventory file generating the events. -- **LriverName** No content is currently available. - **Product** The product name that is included in the driver file. - **ProductVersion** The product version that is included in the driver file. - **Service** The name of the service that is installed for the device. -- **TriverSigned** No content is currently available. - **WdfVersion** The Windows Driver Framework version. @@ -4170,8 +4072,7 @@ This event collects traces of all other Core events, not used in typical custome The following fields are available: -- **key** No content is currently available. -- **UniqueKey** No content is currently available. +- **key** The globally unique identifier (GUID) used to identify the specific Json Trace logging session. ### Microsoft.Windows.Inventory.Core.StopUtcJsonTrace @@ -4180,7 +4081,7 @@ This event collects traces of all other Core events, not used in typical custome The following fields are available: -- **key** No content is currently available. +- **key** The globally unique identifier (GUID) used to identify the specific Json Trace logging session. ### Microsoft.Windows.Inventory.General.AppHealthStaticAdd @@ -4621,24 +4522,19 @@ OS information collected during Boot, used to evaluate the success of the upgrad The following fields are available: -- **BootApplicatio~Id** No content is currently available. - **BootApplicationId** This field tells us what the OS Loader Application Identifier is. - **BootAttemptCount** The number of consecutive times the boot manager has attempted to boot into this operating system. - **BootSequence** The current Boot ID, used to correlate events related to a particular boot session. -- **BootSequenft** No content is currently available. - **BootStatusPolicy** Identifies the applicable Boot Status Policy. - **BootType** Identifies the type of boot (e.g.: "Cold", "Hiber", "Resume"). - **EventTimestamp** Seconds elapsed since an arbitrary time point. This can be used to identify the time difference in successive boot attempts being made. - **FirmwareResetReasonEmbeddedController** Reason for system reset provided by firmware. -- **FirmwareresetReasonEmbeddedControllerAdditional** No content is currently available. - **FirmwareResetReasonEmbeddedControllerAdditional** Additional information on system reset reason provided by firmware if needed. - **FirmwareResetReasonPch** Reason for system reset provided by firmware. - **FirmwareResetReasonPchAdditional** Additional information on system reset reason provided by firmware if needed. -- **FirmwareResetReasonPchADditional** No content is currently available. - **FirmwareResetReasonSupplied** Flag indicating that a reason for system reset was provided by firmware. - **IO** Amount of data written to and read from the disk by the OS Loader during boot. See [IO](#io). - **LastBootSucceeded** Flag indicating whether the last boot was successful. -- **LastBootSucceedEd** No content is currently available. - **LastShutdownSucceeded** Flag indicating whether the last shutdown was successful. - **MaxAbove4GbFreeRange** This field describes the largest memory range available above 4Gb. - **MaxBelow4GbFreeRange** This field describes the largest memory range available below 4Gb. @@ -4664,6 +4560,19 @@ The following fields are available: - **objectCount** The count of the number of objects that are being transferred. +### Microsoft.Windows.MigrationCore.MigObjectCountKFUsr + +No content is currently available. + +The following fields are available: + +- **currentSid** No content is currently available. +- **knownFolderLoc->DirName->CString** No content is currently available. +- **knownFoldersUsr[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + ## Miracast events ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd @@ -4900,17 +4809,17 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates whether a remediation plug-in is applicable, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +This event indicates whether Windows Update Sediment Remediations need to be applied to a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: - **AllowAutoUpdateExists** Indicates whether the Automatic Update feature is turned on. -- **AllowAutoUpdateProviderSetExists** No content is currently available. +- **AllowAutoUpdateProviderSetExists** Indicates whether the Allow Automatic Update provider exists. - **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. - **AppraiserTaskRepairDisabled** Task repair performed by the appraiser plugin is disabled. - **AppraiserTaskValid** Indicates that the appraiser task is valid. -- **AUOptionsExists** Indicates whether the Automatic Update option exist. +- **AUOptionsExists** Indicates whether automatic update options exist. - **CTACTargetingAttributesInvalid** Indicates whether the Common Targeting Attribute Client (CTAC) attributes are valid. CTAC is a Windows Runtime client library. - **CTACVersion** The Common Targeting Attribute Client (CTAT) version on the device. CTAT is a Windows Runtime client library. - **CV** Correlation vector @@ -4965,10 +4874,10 @@ The following fields are available: - **PluginName** Name of the plugin specified for each generic plugin event. - **ProductType** The product type of Windows 10. - **QualityUpdateSedimentFunnelState** Provides information about whether Windows Quality Updates are missing on the device. -- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. -- **QualityUpdateSedimentLastRunSeconds** The number of seconds since the Quality Update Sediment Pack ran. +- **QualityUpdateSedimentJsonSchemaVersion** The schema version of the Quality Update Sediment Remediation. +- **QualityUpdateSedimentLastRunSeconds** The number of seconds since the Quality Updates were run - **QualityUpdateSedimentLocalStartTime** Provides information about when Quality Updates were run. -- **QualityUpdateSedimentLocaltTime** No content is currently available. +- **QualityUpdateSedimentLocaltTime** The local time of the device running the Quality Update Sediment Remediation. - **QualityUpdateSedimentTargetedPlugins** Provides the list of remediation plug-ins that are applicable to enable Quality Updates on the device. - **QualityUpdateSedimentTargetedTriggers** Provides information about remediations that are applicable to enable Quality Updates on the device. - **RegkeysExist** Indicates whether specified registry keys exist. @@ -5033,7 +4942,7 @@ The following fields are available: - **RemediationNotifyUserFixIssuesIsUserLoggedIn** Indicates whether the remediation can take place when a non-Administrator is logged in. - **RemediationProgramDataFolderSizeInMB** The size (in megabytes) of the Program Data folder on the device. - **RemediationProgramFilesFolderSizeInMB** The size (in megabytes) of the Program Files folder on the device. -- **RemediationShellDeviceApplicabilityFailedReason** No content is currently available. +- **RemediationShellDeviceApplicabilityFailedReason** The reason the Remediation is not applicable to the device (expressed as a bitmap). - **RemediationShellDeviceEducationSku** Indicates whether a Windows 10 Education edition is detected on the device. - **RemediationShellDeviceEnterpriseSku** Indicates whether a Windows 10 Enterprise edition is detected on the device. - **RemediationShellDeviceFeatureUpdatesPaused** Indicates whether Feature Updates are paused on the device. @@ -5044,13 +4953,13 @@ The following fields are available: - **RemediationShellDeviceProSku** Indicates whether a Windows 10 Professional edition is detected. - **RemediationShellDeviceQualityUpdatesPaused** Indicates whether Quality Updates are paused on the device. - **RemediationShellDeviceSccm** TRUE if the device is managed by SCCM (Microsoft System Center Configuration Manager). -- **RemediationShellDeviceSedimentMutexInUse** No content is currently available. +- **RemediationShellDeviceSedimentMutexInUse** Indicates whether the Sediment Pack mutual exclusion object (mutex) is in use. - **RemediationShellDeviceSetupMutexInUse** Indicates whether device setup is in progress. - **RemediationShellDeviceWuRegistryBlocked** Indicates whether the Windows Update is blocked on the device via the registry. - **RemediationShellDeviceZeroExhaust** TRUE if the device has opted out of Windows Updates completely. -- **RemediationShellHasExpired** No content is currently available. -- **RemediationShellHasUpgraded** No content is currently available. -- **RemediationShellIsDeviceApplicable** No content is currently available. +- **RemediationShellHasExpired** Indicates whether the Remediation iterations have ended. +- **RemediationShellHasUpgraded** Indicates whether the device upgraded. +- **RemediationShellIsDeviceApplicable** Indicates whether the Remediation is applicable to the device. - **RemediationTargetMachine** Indicates whether the device is a target of the specified fix. - **RemediationTaskHealthAutochkProxy** True/False based on the health of the AutochkProxy task. - **RemediationTaskHealthChkdskProactiveScan** True/False based on the health of the Check Disk task. @@ -5080,21 +4989,21 @@ The following fields are available: - **TimeServiceSyncDomainJoined** True if device domain joined and hence uses DC for clock. - **TimeServiceSyncType** Type of sync behavior for Date & Time service on device. - **uninstallActiveValue** Indicates whether an uninstall is in progress. -- **UpdateApplicabilityFixerTriggerBitMap** No content is currently available. -- **UpdateRebootTime** No content is currently available. -- **usoScanHoursSinceLastScan** No content is currently available. -- **usoScanPastThreshold** No content is currently available. -- **WindowsHiberFilSysSizeInMegabytes** No content is currently available. -- **WindowsInstallerFolderSizeInMegabytes** No content is currently available. -- **WindowsPageFileSysSizeInMegabytes** No content is currently available. -- **WindowsSoftwareDistributionFolderSizeInMegabytes** No content is currently available. -- **WindowsSwapFileSysSizeInMegabytes** No content is currently available. -- **WindowsSxsFolderSizeInMegabytes** No content is currently available. +- **UpdateApplicabilityFixerTriggerBitMap** A bitmap containing the reason(s) why the Update Applicability Fixer Plugin was executed. +- **UpdateRebootTime** The amount of time it took to reboot to install the updates. +- **usoScanHoursSinceLastScan** The number of hours since the last scan by the Update Service Orchestrator (USO). +- **usoScanPastThreshold** Indicates whether the Update Service Orchestrator (USO) scan is overdue. +- **WindowsHiberFilSysSizeInMegabytes** The size of the Windows Hibernation file, in megabytes. +- **WindowsInstallerFolderSizeInMegabytes** The size of the Windows Installer folder, in megabytes. +- **WindowsPageFileSysSizeInMegabytes** The size of the Windows Page file, in megabytes. +- **WindowsSoftwareDistributionFolderSizeInMegabytes** The size of the Software Distribution folder, in megabytes. +- **WindowsSwapFileSysSizeInMegabytes** The size of the Windows Swap file, in megabytes. +- **WindowsSxsFolderSizeInMegabytes** The size of the WinSxS (Windows Side-by-Side) folder, in megabytes. ### Microsoft.Windows.Remediation.Completed -This event is sent when a remediation plug-in has completed, to help keep Windows up to date. A remediation plug-in addresses issues on the system that prevent the device from receiving security and quality updates. +This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: @@ -5107,9 +5016,9 @@ The following fields are available: - **DiskFreeSpaceBeforeSedimentPackInMB** The amount of free disk space (in megabytes) before executing the Sediment Pack. - **DiskMbFreeAfterCleanup** The amount of free hard disk space after cleanup, measured in Megabytes. - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. -- **DiskSpaceCleanedByComponentCleanup** No content is currently available. -- **DiskSpaceCleanedByNGenRemoval** No content is currently available. -- **DiskSpaceCleanedByRestorePointRemoval** No content is currently available. +- **DiskSpaceCleanedByComponentCleanup** The amount of disk space (in megabytes) in the component store that was cleaned up by the plug-in. +- **DiskSpaceCleanedByNGenRemoval** The amount of diskspace (megabytes) in the Native Image Generator (NGEN) cache that was cleaned up by the plug-in. +- **DiskSpaceCleanedByRestorePointRemoval** The amount of disk space (megabytes) in restore points that was cleaned up by the plug-in. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. - **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. @@ -5125,57 +5034,57 @@ The following fields are available: - **PluginName** The name of the plug-in specified for each generic plug-in event. - **QualityUpdateSedimentExecutedPlugins** The number of plug-ins executed by the Windows Quality Update remediation. - **QualityUpdateSedimentFunnelState** The state of the Windows Quality Update remediation funnel for the device. -- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. +- **QualityUpdateSedimentJsonSchemaVersion** The schema version of the Quality Update Sediment Remediation. - **QualityUpdateSedimentLocalEndTime** The local time on the device when the Windows Quality Update remediation executed. -- **QualityUpdateSedimentLocaltTime** No content is currently available. +- **QualityUpdateSedimentLocaltTime** The local time of the device running the Quality Update Sediment Remediation. - **QualityUpdateSedimentMatchedTriggers** The list of triggers that were matched by the Windows Quality Update remediation. - **QualityUpdateSedimentModelExecutionSeconds** The number of seconds needed to execute the Windows Quality Update remediation. -- **recoveredFromTargetOS** No content is currently available. +- **recoveredFromTargetOS** Indicates whether the device recovered from the target operating system (OS). - **RemediationBatteryPowerBatteryLevel** Indicates the battery level at which it is acceptable to continue operation. - **RemediationBatteryPowerExitDueToLowBattery** True when we exit due to low battery power. - **RemediationBatteryPowerOnBattery** True if we allow execution on battery. -- **RemediationCbsTempDiskSpaceCleanedInMB** No content is currently available. -- **RemediationCbsTempEstimateInMB** No content is currently available. -- **RemediationComponentCleanupEstimateInMB** No content is currently available. +- **RemediationCbsTempDiskSpaceCleanedInMB** The amount of space (in megabytes) that the plug-in cleaned up in the CbsTemp folder. +- **RemediationCbsTempEstimateInMB** The amount of space (megabytes) in the CbsTemp folder that is available for cleanup by the plug-in. +- **RemediationComponentCleanupEstimateInMB** The amount of space (megabytes) in the WinSxS (Windows Side-by-Side) folder that is available for cleanup by the plug-in. - **RemediationConfigurationTroubleshooterIpconfigFix** TRUE if IPConfig Fix completed successfully. - **RemediationConfigurationTroubleshooterNetShFix** TRUE if network card cache reset ran successfully. - **RemediationCorruptionRepairCorruptionsDetected** Number of corruptions detected on the device. - **RemediationCorruptionRepairCorruptionsFixed** Number of detected corruptions that were fixed on the device. - **RemediationCorruptionRepairPerformActionSuccessful** Indicates whether corruption repair was successful on the device. -- **RemediationDiskCleanupSearchFileSizeInMB** No content is currently available. -- **RemediationDiskSpaceSavedByCompressionInMB** No content is currently available. -- **RemediationDiskSpaceSavedByUserProfileCompressionInMB** No content is currently available. +- **RemediationDiskCleanupSearchFileSizeInMB** The size of the Cleanup Search index file, measured in megabytes. +- **RemediationDiskSpaceSavedByCompressionInMB** The amount of disk space (megabytes) that was compressed by the plug-in. +- **RemediationDiskSpaceSavedByUserProfileCompressionInMB** The amount of User disk space (in megabytes) that was compressed by the plug-in. - **remediationExecution** Remediation shell is in "applying remediation" state. -- **RemediationHandlerCleanupEstimateInMB** No content is currently available. +- **RemediationHandlerCleanupEstimateInMB** The estimated amount of disk space (in megabytes) to be cleaned up by running Storage Sense. - **RemediationHibernationMigrated** TRUE if hibernation was migrated. - **RemediationHibernationMigrationSucceeded** TRUE if hibernation migration succeeded. - **RemediationNGenDiskSpaceRestored** The amount of disk space (in megabytes) that was restored after re-running the Native Image Generator (NGEN). -- **RemediationNGenEstimateInMB** No content is currently available. +- **RemediationNGenEstimateInMB** The amount of disk space (in megabytes) estimated to be in the Native Image Generator (NGEN) cache by the plug-in. - **RemediationNGenMigrationSucceeded** Indicates whether the Native Image Generator (NGEN) migration succeeded. -- **RemediationRestorePointEstimateInMB** No content is currently available. -- **RemediationSearchFileSizeEstimateInMB** No content is currently available. +- **RemediationRestorePointEstimateInMB** The amount of disk space (in megabytes) estimated to be used by storage points found by the plug-in. +- **RemediationSearchFileSizeEstimateInMB** The amount of disk space (megabytes) estimated to be used by the Cleanup Search index file found by the plug-in. - **RemediationShellHasUpgraded** TRUE if the device upgraded. - **RemediationShellMinimumTimeBetweenShellRuns** Indicates the time between shell runs exceeded the minimum required to execute plugins. - **RemediationShellRunFromService** TRUE if the shell driver was run from the service. - **RemediationShellSessionIdentifier** Unique identifier tracking a shell session. - **RemediationShellSessionTimeInSeconds** Indicates the time the shell session took in seconds. - **RemediationShellTaskDeleted** Indicates that the shell task has been deleted so no additional sediment pack runs occur for this installation. -- **RemediationSoftwareDistributionCleanedInMB** No content is currently available. -- **RemediationSoftwareDistributionEstimateInMB** No content is currently available. -- **RemediationTotalDiskSpaceCleanedInMB** No content is currently available. +- **RemediationSoftwareDistributionCleanedInMB** The amount of disk space (megabytes) in the Software Distribution folder that was cleaned up by the plug-in. +- **RemediationSoftwareDistributionEstimateInMB** The amount of disk space (megabytes) in the Software Distribution folder that is available for clean up by the plug-in. +- **RemediationTotalDiskSpaceCleanedInMB** The total disk space (in megabytes) that was cleaned up by the plug-in. - **RemediationUpdateServiceHealthRemediationResult** The result of the Update Service Health plug-in. - **RemediationUpdateTaskHealthRemediationResult** The result of the Update Task Health plug-in. - **RemediationUpdateTaskHealthTaskList** A list of tasks fixed by the Update Task Health plug-in. -- **RemediationUserFolderCompressionEstimateInMB** No content is currently available. -- **RemediationUserProfileCompressionEstimateInMB** No content is currently available. +- **RemediationUserFolderCompressionEstimateInMB** The amount of disk space (in megabytes) estimated to be compressible in User folders by the plug-in. +- **RemediationUserProfileCompressionEstimateInMB** The amount of disk space (megabytes) estimated to be compressible in User Profile folders by the plug-in. - **RemediationUSORebootRequred** Indicates whether a reboot is determined to be required by calling the Update Service Orchestrator (USO). -- **RemediationWindowsCompactedEstimateInMB** No content is currently available. -- **RemediationWindowsLogSpaceEstimateInMB** No content is currently available. +- **RemediationWindowsCompactedEstimateInMB** The amount of disk space (megabytes) estimated to be available by compacting the operating system using the plug-in. +- **RemediationWindowsLogSpaceEstimateInMB** The amount of disk space (in megabytes) available in Windows logs that can be cleaned by the plug-in. - **RemediationWindowsLogSpaceFreed** The amount of disk space freed by deleting the Windows log files, measured in Megabytes. -- **RemediationWindowsOldSpaceEstimateInMB** No content is currently available. -- **RemediationWindowsSpaceCompactedInMB** No content is currently available. -- **RemediationWindowsStoreSpaceCleanedInMB** No content is currently available. -- **RemediationWindowsStoreSpaceEstimateInMB** No content is currently available. +- **RemediationWindowsOldSpaceEstimateInMB** The amount of disk space (megabytes) in the Windows.OLD folder that can be cleaned up by the plug-in. +- **RemediationWindowsSpaceCompactedInMB** The amount of disk space (megabytes) that can be cleaned up by the plug-in. +- **RemediationWindowsStoreSpaceCleanedInMB** The amount of disk space (megabytes) from the Windows Store cache that was cleaned up by the plug-in. +- **RemediationWindowsStoreSpaceEstimateInMB** The amount of disk space (megabytes) in the Windows store cache that is estimated to be cleanable by the plug-in. - **Result** The HRESULT for Detection or Perform Action phases of the plug-in. - **RunCount** The number of times the plugin has executed. - **RunResult** The HRESULT for Detection or Perform Action phases of the plug-in. @@ -5208,40 +5117,40 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event reports whether a plug-in started, to help ensure Windows is up to date. +This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. The following fields are available: - **CV** Correlation vector. - **GlobalEventCounter** Client side counter which indicates ordering of events sent by this user. -- **PackageVersion** Current package version of Remediation. +- **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **QualityUpdateSedimentFunnelState** Provides information about whether quality updates are missing on the device. -- **QualityUpdateSedimentFunnelType** No content is currently available. -- **QualityUpdateSedimentJsonSchemaVersion** No content is currently available. +- **QualityUpdateSedimentFunnelType** Indicates whether the Remediation is for Quality Updates or Feature Updates. +- **QualityUpdateSedimentJsonSchemaVersion** The schema version of the Quality Update Sediment Remediation. - **QualityUpdateSedimentLastRunSeconds** The number of seconds since Quality Updates were run. -- **QualityUpdateSedimentLocaltTime** No content is currently available. -- **QualityUpdateSedimentMatchedTriggers** No content is currently available. -- **QualityUpdateSedimentSelectedPlugins** No content is currently available. -- **QualityUpdateSedimentTargetedPlugins** No content is currently available. -- **QualityUpdateSedimentTargetedTriggers** The list of triggers targeted by the current quality update sediment remediation run. -- **RemediationProgramDataFolderSizeInMB** No content is currently available. -- **RemediationProgramFilesFolderSizeInMB** No content is currently available. -- **RemediationUsersFolderSizeInMB** No content is currently available. -- **RemediationWindowsAppsFolderSizeInMB** No content is currently available. -- **RemediationWindowsBtFolderSizeInMB** No content is currently available. -- **RemediationWindowsFolderSizeInMB** No content is currently available. -- **RemediationWindowsServiceProfilesFolderSizeInMB** No content is currently available. -- **RemediationWindowsTotalSystemDiskSize** No content is currently available. +- **QualityUpdateSedimentLocaltTime** The local time of the device running the Quality Update Sediment Remediation. +- **QualityUpdateSedimentMatchedTriggers** The list of triggers that were matched by the Windows Quality Update Remediation. +- **QualityUpdateSedimentSelectedPlugins** The number of plugins that were selected for execution in the Quality Update Sediment Remediation. +- **QualityUpdateSedimentTargetedPlugins** The list of plug-ins targeted by the current Quality Update Sediment Remediation. +- **QualityUpdateSedimentTargetedTriggers** The list of triggers targeted by the current Quality Update Sediment Remediation. +- **RemediationProgramDataFolderSizeInMB** The size (in megabytes) of the Program Data folder on the device. +- **RemediationProgramFilesFolderSizeInMB** The size (in megabytes) of the Program Files folder on the device. +- **RemediationUsersFolderSizeInMB** The size (in megabytes) of the Users folder on the device. +- **RemediationWindowsAppsFolderSizeInMB** The size (in megabytes) of the Windows Applications folder on the device. +- **RemediationWindowsBtFolderSizeInMB** The size (in megabytes) of the Windows BT folder on the device. +- **RemediationWindowsFolderSizeInMB** The size (in megabytes) of the Windows folder on the device. +- **RemediationWindowsServiceProfilesFolderSizeInMB** The size (in megabytes) of the Windows Service Profiles folder on the device. +- **RemediationWindowsTotalSystemDiskSize** The total storage capacity of the System disk drive, measured in megabytes. - **Result** This is the HRESULT for detection or perform action phases of the plugin. - **RunCount** The number of times the remediation event started (whether it completed successfully or not). -- **WindowsHiberFilSysSizeInMegabytes** No content is currently available. -- **WindowsInstallerFolderSizeInMegabytes** No content is currently available. -- **WindowsOldFolderSizeInMegabytes** No content is currently available. -- **WindowsPageFileSysSizeInMegabytes** No content is currently available. -- **WindowsSoftwareDistributionFolderSizeInMegabytes** No content is currently available. -- **WindowsSwapFileSysSizeInMegabytes** No content is currently available. -- **WindowsSxsFolderSizeInMegabytes** No content is currently available. +- **WindowsHiberFilSysSizeInMegabytes** The size of the Windows Hibernation file, measured in megabytes. +- **WindowsInstallerFolderSizeInMegabytes** The size of the Windows Installer folder, measured in megabytes. +- **WindowsOldFolderSizeInMegabytes** The size of the Windows.OLD folder, measured in megabytes. +- **WindowsPageFileSysSizeInMegabytes** The size of the Windows Page file, measured in megabytes. +- **WindowsSoftwareDistributionFolderSizeInMegabytes** The size of the Software Distribution folder, measured in megabytes. +- **WindowsSwapFileSysSizeInMegabytes** The size of the Windows Swap file, measured in megabytes. +- **WindowsSxsFolderSizeInMegabytes** The size of the WinSxS (Windows Side-by-Side) folder, measured in megabytes. ## Sediment events @@ -5419,15 +5328,8 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: -- **FaeldName** No content is currently available. -- **FieddName** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. -- **FieldNime** No content is currently available. -- **Gro}pName** No content is currently available. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. -- **GzoupName** No content is currently available. -- **OroupName** No content is currently available. -- **Vadue** No content is currently available. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -5439,7 +5341,6 @@ Scan process event on Windows Update client. See the EventScenario field for spe The following fields are available: -- **__TlgCV_W** No content is currently available. - **ActivityMatchingId** Contains a unique ID identifying a single CheckForUpdates session from initialization to completion. - **AllowCachedResults** Indicates if the scan allowed using cached results. - **ApplicableUpdateInfo** Metadata for the updates which were detected as applicable @@ -5451,15 +5352,12 @@ The following fields are available: - **BiosVersion** The version of the BIOS. - **BranchReadinessLevel** The servicing branch configured on the device. - **CachedEngineVersion** For self-initiated healing, the version of the SIH engine that is cached on the device. If the SIH engine does not exist, the value is null. -- **CallerApplacationN!me** No content is currently available. - **CallerApplicationName** The name provided by the caller who initiated API calls into the software distribution client. - **CapabilityDetectoidGuid** The GUID for a hardware applicability detectoid that could not be evaluated. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** The unique identifier of a specific device, used to identify how many devices are encountering success or a particular issue. - **ClientVersion** The version number of the software distribution client. -- **ClientWersion** No content is currently available. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. -- **ComvonProps** No content is currently available. - **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). @@ -5468,11 +5366,8 @@ The following fields are available: - **DriverError** The error code hit during a driver scan. This is 0 if no error was encountered. - **DriverExclusionPolicy** Indicates if the policy for not including drivers with Windows Update is enabled. - **DriverSyncPassPerformed** Were drivers scanned this time? -- **EventIfstanceI** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. -- **ExsendedMetadataCabUrl** No content is currently available. -- **ExsendedStatusCode** No content is currently available. - **ExtendedMetadataCabUrl** Hostname that is used to download an update. - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FailedUpdateGuids** The GUIDs for the updates that failed to be evaluated during the scan. @@ -5484,7 +5379,6 @@ The following fields are available: - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). - **HomeMobileOperator** The mobile operator that the device was originally intended to work with. - **IntentPFNs** Intended application-set metadata for atomic update scenarios. -- **IntentPINs** No content is currently available. - **IPVersion** Indicates whether the download took place over IPv4 or IPv6 - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. @@ -5492,12 +5386,10 @@ The following fields are available: - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **NumberOfApplicableUpdatds** No content is currently available. - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required - **NumberOfNewUpdatesFromServiceSync** The number of updates which were seen for the first time in this scan -- **NumberOfNewUpdatesFrvFServiceSync** No content is currently available. - **NumberOfUpdatesEvaluated** The total number of updates which were evaluated as a part of the scan - **NumFailedMetadataSignatures** The number of metadata signatures checks which failed for new metadata synced down. - **Online** Indicates if this was an online scan. @@ -5519,7 +5411,6 @@ The following fields are available: - **ServiceUrl** The environment URL a device is configured to scan with - **ShippingMobileOperator** The mobile operator that a device shipped on. - **StatusCode** Indicates the result of a CheckForUpdates event (success, cancellation, failure code HResult). -- **Statusode** No content is currently available. - **SyncType** Describes the type of scan the event was - **SystemBIOSMajorRelease** Major version of the BIOS. - **SystemBIOSMinorRelease** Minor version of the BIOS. @@ -5577,6 +5468,7 @@ The following fields are available: - **BiosSKUNumber** The sku number of the device BIOS. - **BIOSVendor** The vendor of the BIOS. - **BiosVersion** The version of the BIOS. +- **Bundle02,UsedDO** No content is currently available. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle. - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. @@ -5585,7 +5477,6 @@ The following fields are available: - **BytesDownloaded** Number of bytes that were downloaded for an individual piece of content (not the entire bundle). - **CachedEngineVersion** The version of the “Self-Initiated Healing” (SIH) engine that is cached on the device, if applicable. - **CallerApplicationName** The name provided by the application that initiated API calls into the software distribution client. -- **CaLlerApplicationName** No content is currently available. - **CbsDownloadMethod** Indicates whether the download was a full- or a partial-file download. - **CbsMethod** The method used for downloading the update content related to the Component Based Servicing (CBS) technology. - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. @@ -5597,7 +5488,7 @@ The following fields are available: - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** The model of the device. - **DownloadPriority** Indicates whether a download happened at background, normal, or foreground priority. -- **DownloadProps** Information about the download operation. +- **DownloadProps** Information about the download operation properties in the form of a bitmask. - **DownloadType** Differentiates the download type of “Self-Initiated Healing” (SIH) downloads between Metadata and Payload downloads. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose for sending this event: whether because the software distribution just started downloading content; or whether it was cancelled, succeeded, or failed. @@ -5605,7 +5496,6 @@ The following fields are available: - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBuildN�mber** No content is currently available. - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -5751,7 +5641,6 @@ The following fields are available: - **IsFinalOutcomeEvent** Indicates whether this event signals the end of the update/upgrade process. - **IsFirmware** Indicates whether this update is a firmware update. - **IsSuccessFailurePostReboot** Indicates whether the update succeeded and then failed after a restart. -- **IsWufBDualScanEnabled** No content is currently available. - **IsWUfBDualScanEnabled** Indicates whether Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates whether Windows Update for Business is enabled on the device. - **MergedUpdate** Indicates whether the OS update and a BSP update merged for installation. @@ -6501,15 +6390,11 @@ This event sends data about OS deployment scenarios, to help keep Windows up-to- The following fields are available: -- **^alue** No content is currently available. - **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. -- **FdightData** No content is currently available. - **FieldName** Retrieves the data point. - **FimldName** No content is currently available. - **FlightData** Specifies a unique identifier for each group of Windows Insider builds. - **InstanceId** Retrieves a unique identifier for each instance of a setup session. -- **InstanceIl** No content is currently available. -- **InstancmId** No content is currently available. - **ReportId** Retrieves the report ID. - **ScenarioId** Retrieves the deployment scenario. - **Value** Retrieves the value associated with the corresponding FieldName. @@ -6548,7 +6433,6 @@ The following fields are available: - **InstanceId** The GUID (Globally Unique ID) that identifies each instance of SetupHost.EXE. - **MitigationScenario** The update scenario in which the mitigation was executed. - **Name** The friendly (descriptive) name of the mitigation. -- **OperatignName** No content is currently available. - **OperationIndex** The mitigation operation index (in the event of a failure). - **OperationName** The friendly (descriptive) name of the mitigation operation (in the event of failure). - **RegistryCount** The number of registry operations in the mitigation entry. @@ -6627,7 +6511,6 @@ The following fields are available: - **callerApplication** The name of the calling application. - **capsuleCount** The number of Sediment Pack capsules. - **capsuleFailureCount** The number of capsule failures. -- **detecd1drSummary** No content is currently available. - **detectionSummary** Result of each applicable detection that was run. - **featureAssessmentImpact** WaaS Assessment impact for feature updates. - **hrEngineBlockReason** Indicates the reason for stopping WaaSMedic. @@ -6638,12 +6521,10 @@ The following fields are available: - **isInteractiveMode** The user started a run of WaaSMedic. - **isManaged** Device is managed for updates. - **isWUConnected** Device is connected to Windows Update. -- **noMoreAcd1drs** No content is currently available. - **noMoreActions** No more applicable diagnostics. - **pluginFailureCount** The number of plugins that have failed. - **pluginsCount** The number of plugins. - **qualityAssessmentImpact** WaaS Assessment impact for quality updates. -- **remediad1drSummary** No content is currently available. - **remediationSummary** Result of each operation performed on a device to fix an invalid state or configuration that's preventing the device from getting updates. For example, if Windows Update service is turned off, the fix is to turn the it back on. - **usingBackupFeatureAssessment** Relying on backup feature assessment. - **usingBackupQualityAssessment** Relying on backup quality assessment. @@ -6829,7 +6710,6 @@ The following fields are available: - **IsBundle** Is this a bundle? - **IsInteractive** Is this initiated by the user? - **IsMandatory** Is this a mandatory installation? -- **IsRemedi-0000** No content is currently available. - **IsRemediation** Is this repairing a previous installation? - **IsRestore** Is this a restore of a previously acquired product? - **IsUpdate** Is this an update? @@ -6979,7 +6859,6 @@ This event is sent at the beginning of an app install or update to help keep Win The following fields are available: -- **__lgCV__** No content is currently available. - **CatalogId** The name of the product catalog from which this app was chosen. - **FulfillmentPluginId** The ID of the plugin needed to install the package type of the product. - **PFN** The Package Family Name of the app that is being installed or updated. @@ -7176,18 +7055,15 @@ The following fields are available: - **bytesFromGroupPeers** The number of bytes received from a peer in the same domain group. - **bytesFromIntPeers** The number of bytes received from peers not in the same LAN or in the same domain group. - **bytesFromLinkLocalPeers** The number of bytes received from local peers. -- **bytesFromLocadCache** No content is currently available. - **bytesFromLocalCache** Bytes copied over from local (on disk) cache. - **bytesFromPeers** The number of bytes received from a peer in the same LAN. - **bytesRequested** The total number of bytes requested for download. -- **byvesFromCacheServer** No content is currently available. - **cacheServerConnectionCount** Number of connections made to cache hosts. - **cdnConnectionCount** The total number of connections made to the CDN. - **cdnErrorCodes** A list of CDN connection errors since the last FailureCDNCommunication event. - **cdnErrorCounts** The number of times each error in cdnErrorCodes was encountered. - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). -- **cfileSize** No content is currently available. - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). @@ -7206,7 +7082,6 @@ The following fields are available: - **isEncrypted** TRUE if the file is encrypted and will be decrypted after download. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. -- **lanConnectionCoujt** No content is currently available. - **lanConnectionCount** The total number of connections made to peers in the same LAN. - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. @@ -7222,7 +7097,6 @@ The following fields are available: - **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). - **uplinkUsageBps** The upload speed (in bytes per second). - **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. -- **ytesRequested** No content is currently available. ### Microsoft.OSG.DU.DeliveryOptClient.DownloadPaused @@ -7238,7 +7112,6 @@ The following fields are available: - **fileID** The ID of the file being paused. - **isVpn** Is the device connected to a Virtual Private Network? - **jobID** Identifier for the Windows Update job. -- **pagaefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller object. - **reasonCode** The reason for pausing the download. - **routeToCacheServer** The cache server setting, source, and value. @@ -7259,7 +7132,6 @@ The following fields are available: - **deviceProfile** Identifies the usage or form factor (such as Desktop, Xbox, or VM). - **diceRoll** Random number used for determining if a client will use peering. - **doClientVersion** The version of the Delivery Optimization client. -- **doEr2orCode** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downloadMode** The download mode used for this file download session (CdnOnly = 0, Lan = 1, Group = 2, Internet = 3, Simple = 99, Bypass = 100). - **downloadModeReason** Reason for the download. @@ -7275,10 +7147,8 @@ The following fields are available: - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. - **peerID** The ID for this delivery optimization client. -- **pgerID** No content is currently available. - **predefinedCallerName** Name of the API caller. - **routeToCacheServer** Cache server setting, source, and value. -- **sessionId** No content is currently available. - **sessionID** The ID for the file download session. - **setConbigs** No content is currently available. - **setConfigs** A JSON representation of the configurations that have been set, and their sources. @@ -7900,7 +7770,6 @@ The following fields are available: - **minutesOverScanSla** Indicates how many minutes the scan exceeded the scan SLA. - **minutesOverScanTriggerSla** Indicates how many minutes the scan exceeded the scan trigger SLA. - **scanTriggerSource** Indicates what caused the scan. -- **scanTriggerSouRce** No content is currently available. - **updateScenarioType** The update session type. - **wuDeviceid** Unique device ID used by Windows Update. From 51ae9eb3760a7fa2149060542d8e17a56119ebdd Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Mon, 15 Apr 2019 10:23:27 -0700 Subject: [PATCH 168/737] updating 1903 links --- windows/privacy/windows-diagnostic-data.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/windows/privacy/windows-diagnostic-data.md b/windows/privacy/windows-diagnostic-data.md index 4a50f70b53..d3587cfb5a 100644 --- a/windows/privacy/windows-diagnostic-data.md +++ b/windows/privacy/windows-diagnostic-data.md @@ -12,17 +12,18 @@ ms.author: daniha manager: dansimp ms.collection: M365-security-compliance ms.topic: article -ms.date: 03/13/2018 +ms.date: 04/15/2019 --- # Windows 10, version 1709 and newer diagnostic data for the Full level Applies to: +- Windows 10, version 1903 - Windows 10, version 1809 - Windows 10, version 1803 - Windows 10, version 1709 -Microsoft uses Windows diagnostic data to keep Windows secure and up-to-date, troubleshoot problems, and make product improvements. For users who have turned on "Tailored experiences", it can also be used to offer you personalized tips, ads, and recommendations to enhance Microsoft products and services for your needs. This article describes all types of diagnostic data collected by Windows at the Full level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1809 Basic level diagnostic events and fields](https://docs.microsoft.com/windows/configuration/basic-level-windows-diagnostic-events-and-fields). +Microsoft uses Windows diagnostic data to keep Windows secure and up-to-date, troubleshoot problems, and make product improvements. For users who have turned on "Tailored experiences", it can also be used to offer you personalized tips, ads, and recommendations to enhance Microsoft products and services for your needs. This article describes all types of diagnostic data collected by Windows at the Full level (inclusive of data collected at Basic), with comprehensive examples of data we collect per each type. For additional, detailed technical descriptions of Basic data items, see [Windows 10, version 1903 Basic level diagnostic events and fields](https://docs.microsoft.com/windows/configuration/basic-level-windows-diagnostic-events-and-fields). In addition, this article provides references to equivalent definitions for the data types and examples from [ISO/IEC 19944:2017 Information technology -- Cloud computing -- Cloud services and devices: Data flow, data categories and data use](https://www.iso.org/standard/66674.html). Each data type also has a Data Use statement, for diagnostics and for Tailored experiences on the device, using the terms as defined by the standard. These Data Use statements define the purposes for which Microsoft processes each type of Windows diagnostic data, using a uniform set of definitions referenced at the end of this document and based on the ISO standard. Reference to the ISO standard provides additional clarity about the information collected, and allows easy comparison with other services or guidance that also references the standard. From 6edf2539bbdaf2f09370eea1ff001442267b8c2d Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 16 Apr 2019 05:57:55 -0700 Subject: [PATCH 169/737] add 1903 download for 19H1 --- windows/application-management/manage-windows-mixed-reality.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/windows/application-management/manage-windows-mixed-reality.md b/windows/application-management/manage-windows-mixed-reality.md index 20b71d39e8..333dbab4b5 100644 --- a/windows/application-management/manage-windows-mixed-reality.md +++ b/windows/application-management/manage-windows-mixed-reality.md @@ -9,7 +9,6 @@ ms.localizationpriority: medium author: jdeckerms ms.author: jdecker ms.topic: article -ms.date: 10/02/2018 --- # Enable or block Windows Mixed Reality apps in the enterprise @@ -34,7 +33,7 @@ Organizations that use Windows Server Update Services (WSUS) must take action to 2. Windows Mixed Reality Feature on Demand (FOD) is downloaded from Windows Update. If access to Windows Update is blocked, you must manually install the Windows Mixed Reality FOD. - a. Download the FOD .cab file for [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), or [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab). + a. Download the FOD .cab file for [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), or [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab), or [Windows 10, version 1903](https://software-download.microsoft.com/download/pr/Microsoft-Windows-Holographic-Desktop-FOD-Package-31bf3856ad364e35-amd64.cab). >[!NOTE] >You must download the FOD .cab file that matches your operating system version. From 245662323a5347bc2c11d72cd8936736f0cff134 Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 16 Apr 2019 06:29:24 -0700 Subject: [PATCH 170/737] remove extra or --- windows/application-management/manage-windows-mixed-reality.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/application-management/manage-windows-mixed-reality.md b/windows/application-management/manage-windows-mixed-reality.md index 333dbab4b5..789eabab79 100644 --- a/windows/application-management/manage-windows-mixed-reality.md +++ b/windows/application-management/manage-windows-mixed-reality.md @@ -33,7 +33,7 @@ Organizations that use Windows Server Update Services (WSUS) must take action to 2. Windows Mixed Reality Feature on Demand (FOD) is downloaded from Windows Update. If access to Windows Update is blocked, you must manually install the Windows Mixed Reality FOD. - a. Download the FOD .cab file for [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), or [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab), or [Windows 10, version 1903](https://software-download.microsoft.com/download/pr/Microsoft-Windows-Holographic-Desktop-FOD-Package-31bf3856ad364e35-amd64.cab). + a. Download the FOD .cab file for [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab), or [Windows 10, version 1903](https://software-download.microsoft.com/download/pr/Microsoft-Windows-Holographic-Desktop-FOD-Package-31bf3856ad364e35-amd64.cab). >[!NOTE] >You must download the FOD .cab file that matches your operating system version. From d1a9f02529e5314f2abc2f18a6067279bc9b8fcd Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 16 Apr 2019 08:35:57 -0700 Subject: [PATCH 171/737] new build 4/16/2019 8:35 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 174 ++++++++++++++++-- 1 file changed, 163 insertions(+), 11 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index a32ec507e3..04b2280580 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -1,6 +1,6 @@ --- description: Use this article to learn more about what Windows diagnostic data is gathered at the basic level. -title: Windows 10, version 19H1 basic diagnostic events and fields (Windows 10) +title: Windows 10, version 1903 basic diagnostic events and fields (Windows 10) keywords: privacy, telemetry ms.prod: w10 ms.mktglfcycl: manage @@ -13,11 +13,11 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/15/2019 +ms.date: 04/16/2019 --- -# Windows 10, version 19H1 basic level Windows diagnostic events and fields +# Windows 10, version 1903 basic level Windows diagnostic events and fields > [!IMPORTANT] @@ -26,7 +26,7 @@ ms.date: 04/15/2019 **Applies to** -- Windows 10, version 19H1 +- Windows 10, version 1903 The Basic level gathers a limited set of information that is critical for understanding the device and its configuration including: basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information. @@ -2088,6 +2088,18 @@ The following fields are available: - **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. +### Common Data Extensions.cloud + +Describes the service-related fields populated by the cloud service. + +The following fields are available: + +- **role** The role of the service. +- **roleInstance** The instance id of the deployed role instance generating the event. +- **roleVer** The build version of the role. +- **ver** No content is currently available. + + ### Common Data Extensions.container Describes the properties of the container for events logged within a container. @@ -2101,13 +2113,18 @@ The following fields are available: - **type** The container type. Examples: Process or VMHost -### Common Data Extensions.cs +### Common Data Extensions.cs1 -Describes properties related to the schema of the event. +No content is currently available. The following fields are available: -- **sig** A common schema signature that identifies new and modified event schemas. +- **dblp** A bitfield that is set to a non-zero value if the event in the newer schema has an equivalent event from the 1.0 schema. +- **esc** The event sequence clock. +- **ev** The version of the event. +- **locale** The client language locale on the device. +- **scid** The Service Config ID of the running title that sent the event. +- **users** A comma-separated list of all users logged into the device when the event was created. The user ID is encoded. Example: x:12345678 ### Common Data Extensions.device @@ -2116,10 +2133,15 @@ Describes the device-related fields. The following fields are available: +- **authId** The ID of the device associated with this event. For Microsoft Account tickets, this is expected to be the MSA Global ID. +- **authSecId** The secondary ID of the device associated with this event. For Microsoft Account tickets, this is expected to be the MSA Hardware ID. - **deviceClass** The device classification. For example, Desktop, Server, or Mobile. +- **id** A unique device ID. - **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId - **make** Device manufacturer. - **model** Device model. +- **orgAuthId** ID used to authenticate the orgId. +- **orgId** Organization ID associated with the event. ### Common Data Extensions.Envelope @@ -2128,26 +2150,91 @@ Represents an envelope that contains all of the common data extensions. The following fields are available: -- **cV** Represents the Correlation Vector: A single field for tracking partial order of related telemetry events across component boundaries. - **data** Represents the optional unique diagnostic data for a particular event schema. - **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). +- **ext_cloud** Describes the service-related fields populated by the cloud service. See [Common Data Extensions.cloud](#common-data-extensionscloud). - **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). +- **ext_cs1** If the field doesn't exist in the newer schema, this contains the fields from an earlier schema. See [Common Data Extensions.cs1](#common-data-extensionscs1). - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). +- **ext_ingest** Describes the fields added dynamically by the service. See [Common Data Extensions.ingest](#common-data-extensionsingest). +- **ext_intService** No content is currently available. See [Common Data Extensions.intService](#common-data-extensionsintservice). +- **ext_intWeb** No content is currently available. See [Common Data Extensions.intWeb](#common-data-extensionsintweb). +- **ext_loc** Describes the location from which the event was logged. See [Common Data Extensions.loc](#common-data-extensionsloc). +- **ext_mscv** No content is currently available. See [Common Data Extensions.mscv](#common-data-extensionsmscv). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). - **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). - **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). - **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). - **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). +- **ext_web** No content is currently available. See [Common Data Extensions.web](#common-data-extensionsweb). - **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). -- **flags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. - **iKey** Represents an ID for applications or other logical groupings of events. - **name** Represents the uniquely qualified name for the event. -- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. - **time** Represents the event date time in Coordinated Universal Time (UTC) when the event was generated on the client. This should be in ISO 8601 format. - **ver** Represents the major and minor version of the extension. +### Common Data Extensions.ingest + +Describes the fields that are added by the ingestion service. + +The following fields are available: + +- **auth** Used to assess the trustworthiness of the data. +- **client** The client name. +- **clientIp** The IP address seen by the service. This is not necessarily the client IP address, but could be a router or some other device. +- **processedIngest** If the event already had an ingest extension and the client was authenticated as a first party, the ingest extension will be inserted as processedIngest. +- **quality** A bitfield added by the service to all events coming from a client device. +- **time** The time that the event was received by the service. +- **userAgent** For events that are not using the CUET component, this is the user agent of the browser. + + +### Common Data Extensions.intService + +No content is currently available. + +The following fields are available: + +- **deploymentUnit** No content is currently available. +- **environment** No content is currently available. +- **fullEnvName** No content is currently available. +- **location** No content is currently available. +- **name** No content is currently available. + + +### Common Data Extensions.intWeb + +No content is currently available. + +The following fields are available: + +- **anid** No content is currently available. +- **mc1Id** No content is currently available. +- **mscom** No content is currently available. +- **msfpc** No content is currently available. +- **serviceName** No content is currently available. + + +### Common Data Extensions.loc + +Describes the location from which the event was logged. + +The following fields are available: + +- **country** 2 letter country code using the codes from the ISO 3166-1 alpha-2 standard. +- **id** Location ID based on the client's IP address. +- **tz** The time zone of the device. + + +### Common Data Extensions.mscv + +No content is currently available. + +The following fields are available: + +- **cV** No content is currently available. + + ### Common Data Extensions.os Describes some properties of the operating system. @@ -2167,6 +2254,8 @@ Represents various time information as provided by the client and helps for debu The following fields are available: +- **flags** No content is currently available. +- **originalName** No content is currently available. - **originalTime** The original event time. - **uploadTime** The time the event was uploaded. @@ -2181,6 +2270,7 @@ The following fields are available: - **installId** An ID that's created during the initialization of the SDK for the first time. - **libVer** The SDK version. - **seq** An ID that is incremented for each event. +- **ver** No content is currently available. ### Common Data Extensions.user @@ -2190,6 +2280,7 @@ Describes the fields related to a user. The following fields are available: - **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. +- **id** Unique user Id. Example: x:12345678. - **locale** The language and region. - **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. @@ -2205,12 +2296,36 @@ The following fields are available: - **cat** Represents a bitmask of the ETW Keywords associated with the event. - **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. - **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **eventFlags** No content is currently available. - **flags** Represents the bitmap that captures various Windows specific flags. +- **loggingBinary** No content is currently available. - **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence - **op** Represents the ETW Op Code. +- **pgName** No content is currently available. +- **popSample** No content is currently available. +- **providerGuid** No content is currently available. - **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. - **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. +- **sqmId** No content is currently available. - **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. +- **wcmp** No content is currently available. +- **wPId** No content is currently available. +- **wsId** No content is currently available. + + +### Common Data Extensions.web + +No content is currently available. + +The following fields are available: + +- **browser** No content is currently available. +- **browserLang** No content is currently available. +- **browserVer** No content is currently available. +- **domain** No content is currently available. +- **isManual** No content is currently available. +- **screenRes** No content is currently available. +- **userConsent** No content is currently available. ### Common Data Extensions.xbl @@ -4068,6 +4183,43 @@ The following fields are available: - **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. +## Other events + +### Microsoft.Windows.MigrationCore.MigObjectCountDLUsr + +No content is currently available. + +The following fields are available: + +- **currentSid** No content is currently available. +- **knownFoldersUsr[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + +### Microsoft.Windows.MigrationCore.MigObjectCountKFSys + +This event returns data about the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **knownFoldersSys[i]** The predefined folder path locations. +- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. +- **objectCount** The count of the number of objects that are being transferred. + + +### Microsoft.Windows.MigrationCore.MigObjectCountKFUsr + +This event returns data to track the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **currentSid** Indicates the user SID for which the migration is being performed. +- **knownFoldersUsr[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted From 6766d38b9ded0a209bd4971d2e2a517ce1f50d7d Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 16 Apr 2019 08:36:06 -0700 Subject: [PATCH 172/737] new build 4/16/2019 8:35 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 30 +++--- ...ndows-diagnostic-events-and-fields-1709.md | 34 +++---- ...ndows-diagnostic-events-and-fields-1803.md | 34 +++---- ...ndows-diagnostic-events-and-fields-1809.md | 99 ++++++++++--------- 4 files changed, 101 insertions(+), 96 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index a9d6322d66..187e5b5800 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/15/2019 +ms.date: 04/16/2019 --- @@ -2980,17 +2980,17 @@ deny The following fields are available: - **ActionName** The name of the action to be taken by the plug-in. -- **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. +- **AppraiserBinariesValidResult** Indicates whether the plug-in was appraised as valid. - **AppraiserDetectCondition** Indicates whether the plug-in passed the appraiser's check. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. - **AppraiserTaskDisabled** Indicates the appraiser task is disabled. - **AppraiserTaskValidFailed** Indicates the Appraiser task did not function and requires intervention. - **CV** Correlation vector - **DateTimeDifference** The difference between local and reference clock times. -- **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. +- **DateTimeSyncEnabled** Indicates whether the Datetime Sync plug-in is enabled. - **DaysSinceLastSIH** The number of days since the most recent SIH executed. - **DaysToNextSIH** The number of days until the next scheduled SIH execution. -- **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. +- **DetectedCondition** Indicates whether detected condition is true and the perform action will be run. - **EvalAndReportAppraiserBinariesFailed** Indicates the EvalAndReportAppraiserBinaries event failed. - **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. - **EvalAndReportAppraiserRegEntriesFailed** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. @@ -3004,12 +3004,12 @@ The following fields are available: - **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Reload** True if SIH reload is required. -- **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. +- **RemediationNoisyHammerAcLineStatus** Indicates the AC Line Status of the device. - **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. - **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. - **RemediationNoisyHammerCalendarTaskExists** Event that indicates an Update Assistant Calendar Task exists. - **RemediationNoisyHammerCalendarTaskTriggerEnabledCount** Event that indicates calendar triggers are enabled in the task. -- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent hammer task ran. +- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent Noisy Hammer task ran. - **RemediationNoisyHammerGetCurrentSize** Size in MB of the $GetCurrent folder. - **RemediationNoisyHammerIsInstalled** TRUE if the noisy hammer is installed. - **RemediationNoisyHammerLastTaskRunResult** The result of the last hammer task run. @@ -3059,7 +3059,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have completed on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -3080,7 +3080,7 @@ The following fields are available: - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. -- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. +- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in megabytes. - **HResult** The result of the event execution. - **LatestState** The final state of the plug-in component. - **PackageVersion** The package version for the current Remediation. @@ -3135,7 +3135,7 @@ The following fields are available: - **usoScanIsNetworkMetered** TRUE if the device is currently connected to a metered network. - **usoScanIsNoAutoUpdateKeyPresent** TRUE if no Auto Update registry key is set/present. - **usoScanIsUserLoggedOn** TRUE if the user is logged on. -- **usoScanPastThreshold** TRUE if the most recent USO (Update Session Orchestrator) scan is past the threshold (late). +- **usoScanPastThreshold** TRUE if the most recent Update Session Orchestrator (USO) scan is past the threshold (late). - **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". - **WindowsHyberFilSysSizeInMegabytes** The size of the Windows Hibernation file, measured in Megabytes. - **WindowsInstallerFolderSizeInMegabytes** The size of the Windows Installer folder, measured in Megabytes. @@ -3679,7 +3679,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Applicable -Indicates whether a given plugin is applicable. +This event is sent when the Windows Update sediment remediations launcher finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3695,7 +3695,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Completed -Indicates whether a given plugin has completed its work. +This event is sent when the Windows Update sediment remediations launcher finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3741,7 +3741,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Started -This event indicates that a given plug-in has started. +This event is sent when the Windows Update sediment remediations launcher starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3779,7 +3779,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Applicable -This event indicates whether a given plug-in is applicable. +This event is sent when the Windows Update sediment remediations service finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3795,7 +3795,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Completed -This event indicates whether a given plug-in has completed its work. +This event is sent when the Windows Update sediment remediations service finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3848,7 +3848,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Started -This event indicates a specified plug-in has started. This information helps ensure Windows is up to date. +This event is sent when the Windows Update sediment remediations service starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 8c42efe77e..8aed3dab5e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/15/2019 +ms.date: 04/16/2019 --- @@ -3168,16 +3168,16 @@ deny The following fields are available: - **ActionName** The name of the action to be taken by the plug-in. -- **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. +- **AppraiserBinariesValidResult** Indicates whether the plug-in was appraised as valid. - **AppraiserDetectCondition** Indicates whether the plug-in passed the appraiser's check. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. - **AppraiserTaskDisabled** Indicates the appraiser task is disabled. - **CV** Correlation vector - **DateTimeDifference** The difference between local and reference clock times. -- **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. +- **DateTimeSyncEnabled** Indicates whether the Datetime Sync plug-in is enabled. - **DaysSinceLastSIH** The number of days since the most recent SIH executed. - **DaysToNextSIH** The number of days until the next scheduled SIH execution. -- **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. +- **DetectedCondition** Indicates whether detected condition is true and the perform action will be run. - **EvalAndReportAppraiserBinariesFailed** Indicates the EvalAndReportAppraiserBinaries event failed. - **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. - **EvalAndReportAppraiserRegEntriesFailed** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. @@ -3191,12 +3191,12 @@ The following fields are available: - **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Reload** True if SIH reload is required. -- **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. +- **RemediationNoisyHammerAcLineStatus** Indicates the AC Line Status of the device. - **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. - **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. - **RemediationNoisyHammerCalendarTaskExists** Event that indicates an Update Assistant Calendar Task exists. - **RemediationNoisyHammerCalendarTaskTriggerEnabledCount** Event that indicates calendar triggers are enabled in the task. -- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent hammer task ran. +- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent Noisy Hammer task ran. - **RemediationNoisyHammerGetCurrentSize** Size in MB of the $GetCurrent folder. - **RemediationNoisyHammerIsInstalled** TRUE if the noisy hammer is installed. - **RemediationNoisyHammerLastTaskRunResult** The result of the last hammer task run. @@ -3266,7 +3266,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have completed on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -3289,7 +3289,7 @@ The following fields are available: - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. -- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. +- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in megabytes. - **hasRolledBack** Indicates whether the client machine has rolled back. - **hasUninstalled** Indicates whether the client machine has uninstalled a later version of the OS. - **hResult** The result of the event execution. @@ -3350,7 +3350,7 @@ The following fields are available: - **RunResult** The HRESULT for Detection or Perform Action phases of the plug-in. - **ServiceHealthPlugin** The nae of the Service Health plug-in. - **StartComponentCleanupTask** TRUE if the Component Cleanup task started successfully. -- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive in MBs. +- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive, in megabytes. - **systemUptimeInHours** Indicates the amount of time the system in hours has been on since the last boot. - **TotalSizeofOrphanedInstallerFilesInMegabytes** The size of any orphaned Windows Installer files, measured in Megabytes. - **TotalSizeofStoreCacheAfterCleanupInMegabytes** The size of the Microsoft Store cache after cleanup, measured in Megabytes. @@ -3365,7 +3365,7 @@ The following fields are available: - **usoScanIsNetworkMetered** TRUE if the device is currently connected to a metered network. - **usoScanIsNoAutoUpdateKeyPresent** TRUE if no Auto Update registry key is set/present. - **usoScanIsUserLoggedOn** TRUE if the user is logged on. -- **usoScanPastThreshold** TRUE if the most recent USO (Update Session Orchestrator) scan is past the threshold (late). +- **usoScanPastThreshold** TRUE if the most recent Update Session Orchestrator (USO) scan is past the threshold (late). - **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". - **windows10UpgraderBlockWuUpdates** Event to report the value of Windows 10 Upgrader BlockWuUpdates Key. - **windowsEditionId** Event to report the value of Windows Edition ID. @@ -3399,7 +3399,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have started on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -3667,7 +3667,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Applicable -Indicates whether a given plugin is applicable. +This event is sent when the Windows Update sediment remediations launcher finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3683,7 +3683,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Completed -Indicates whether a given plugin has completed its work. +This event is sent when the Windows Update sediment remediations launcher finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3730,7 +3730,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Started -This event indicates that a given plug-in has started. +This event is sent when the Windows Update sediment remediations launcher starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3768,7 +3768,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Applicable -This event indicates whether a given plug-in is applicable. +This event is sent when the Windows Update sediment remediations service finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3784,7 +3784,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Completed -This event indicates whether a given plug-in has completed its work. +This event is sent when the Windows Update sediment remediations service finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -3838,7 +3838,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Started -This event indicates a specified plug-in has started. This information helps ensure Windows is up to date. +This event is sent when the Windows Update sediment remediations service starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 38e274be19..d26544c92c 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/15/2019 +ms.date: 04/16/2019 --- @@ -4269,17 +4269,17 @@ deny The following fields are available: - **ActionName** The name of the action to be taken by the plug-in. -- **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. +- **AppraiserBinariesValidResult** Indicates whether the plug-in was appraised as valid. - **AppraiserDetectCondition** Indicates whether the plug-in passed the appraiser's check. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. - **AppraiserTaskDisabled** Indicates the appraiser task is disabled. - **AppraiserTaskValidFailed** Indicates the Appraiser task did not function and requires intervention. - **CV** Correlation vector - **DateTimeDifference** The difference between local and reference clock times. -- **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. +- **DateTimeSyncEnabled** Indicates whether the Datetime Sync plug-in is enabled. - **DaysSinceLastSIH** The number of days since the most recent SIH executed. - **DaysToNextSIH** The number of days until the next scheduled SIH execution. -- **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. +- **DetectedCondition** Indicates whether detected condition is true and the perform action will be run. - **EvalAndReportAppraiserBinariesFailed** Indicates the EvalAndReportAppraiserBinaries event failed. - **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. - **EvalAndReportAppraiserRegEntriesFailed** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. @@ -4293,12 +4293,12 @@ The following fields are available: - **PackageVersion** The version of the current remediation package. - **PluginName** Name of the plugin specified for each generic plugin event. - **Reload** True if SIH reload is required. -- **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. +- **RemediationNoisyHammerAcLineStatus** Indicates the AC Line Status of the device. - **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. - **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. - **RemediationNoisyHammerCalendarTaskExists** Event that indicates an Update Assistant Calendar Task exists. - **RemediationNoisyHammerCalendarTaskTriggerEnabledCount** Event that indicates calendar triggers are enabled in the task. -- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent hammer task ran. +- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent Noisy Hammer task ran. - **RemediationNoisyHammerGetCurrentSize** Size in MB of the $GetCurrent folder. - **RemediationNoisyHammerIsInstalled** TRUE if the noisy hammer is installed. - **RemediationNoisyHammerLastTaskRunResult** The result of the last hammer task run. @@ -4368,7 +4368,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have completed on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -4391,7 +4391,7 @@ The following fields are available: - **DiskMbFreeBeforeCleanup** The amount of free hard disk space before cleanup, measured in Megabytes. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. -- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. +- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in megabytes. - **hasRolledBack** Indicates whether the client machine has rolled back. - **hasUninstalled** Indicates whether the client machine has uninstalled a later version of the OS. - **hResult** The result of the event execution. @@ -4456,7 +4456,7 @@ The following fields are available: - **ServiceHealthInstalledBitMap** List of services installed by the plugin. - **ServiceHealthPlugin** The nae of the Service Health plug-in. - **StartComponentCleanupTask** TRUE if the Component Cleanup task started successfully. -- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive in MBs. +- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive, in megabytes. - **systemUptimeInHours** Indicates the amount of time the system in hours has been on since the last boot. - **TotalSizeofOrphanedInstallerFilesInMegabytes** The size of any orphaned Windows Installer files, measured in Megabytes. - **TotalSizeofStoreCacheAfterCleanupInMegabytes** The size of the Microsoft Store cache after cleanup, measured in Megabytes. @@ -4471,7 +4471,7 @@ The following fields are available: - **usoScanIsNetworkMetered** TRUE if the device is currently connected to a metered network. - **usoScanIsNoAutoUpdateKeyPresent** TRUE if no Auto Update registry key is set/present. - **usoScanIsUserLoggedOn** TRUE if the user is logged on. -- **usoScanPastThreshold** TRUE if the most recent USO (Update Session Orchestrator) scan is past the threshold (late). +- **usoScanPastThreshold** TRUE if the most recent Update Session Orchestrator (USO) scan is past the threshold (late). - **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". - **windows10UpgraderBlockWuUpdates** Event to report the value of Windows 10 Upgrader BlockWuUpdates Key. - **windowsEditionId** Event to report the value of Windows Edition ID. @@ -4505,7 +4505,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have started on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -4738,7 +4738,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Applicable -Indicates whether a given plugin is applicable. +This event is sent when the Windows Update sediment remediations launcher finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -4754,7 +4754,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Completed -Indicates whether a given plugin has completed its work. +This event is sent when the Windows Update sediment remediations launcher finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -4769,7 +4769,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Started -This event indicates that a given plug-in has started. +This event is sent when the Windows Update sediment remediations launcher starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -4782,7 +4782,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Applicable -This event indicates whether a given plug-in is applicable. +This event is sent when the Windows Update sediment remediations service finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -4798,7 +4798,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Completed -This event indicates whether a given plug-in has completed its work. +This event is sent when the Windows Update sediment remediations service finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -4820,7 +4820,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Started -This event indicates a specified plug-in has started. This information helps ensure Windows is up to date. +This event is sent when the Windows Update sediment remediations service starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index f359c36a0c..26bb7bab6a 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/15/2019 +ms.date: 04/16/2019 --- @@ -4549,6 +4549,19 @@ The following fields are available: ## Migration events +### Microsoft.Windows.MigrationCore.MigObjectCountDLUsr + +No content is currently available. + +The following fields are available: + +- **currentSid** No content is currently available. +- **defaultLoc->DirName->CString** No content is currently available. +- **knownFoldersUsr[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + ### Microsoft.Windows.MigrationCore.MigObjectCountKFSys This event returns data about the count of the migration objects across various phases during feature update. @@ -4562,15 +4575,14 @@ The following fields are available: ### Microsoft.Windows.MigrationCore.MigObjectCountKFUsr -No content is currently available. +This event returns data to track the count of the migration objects across various phases during feature update. The following fields are available: -- **currentSid** No content is currently available. -- **knownFolderLoc->DirName->CString** No content is currently available. -- **knownFoldersUsr[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. +- **currentSid** Indicates the user SID for which the migration is being performed. +- **knownFoldersUsr[i]** Predefined folder path locations. +- **migDiagSession->CString** The phase of the upgrade where migration occurs. (E.g.: Validate tracked content) +- **objectCount** The count for the number of objects that are being transferred. ## Miracast events @@ -4809,36 +4821,36 @@ The following fields are available: ### Microsoft.Windows.Remediation.Applicable -This event indicates whether Windows Update Sediment Remediations need to be applied to a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event indicates whether Windows Update sediment remediations need to be applied to the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: - **AllowAutoUpdateExists** Indicates whether the Automatic Update feature is turned on. - **AllowAutoUpdateProviderSetExists** Indicates whether the Allow Automatic Update provider exists. -- **AppraiserBinariesValidResult** Indicates whether plug-in was appraised as valid. +- **AppraiserBinariesValidResult** Indicates whether the plug-in was appraised as valid. - **AppraiserRegistryValidResult** Indicates whether the registry entry checks out as valid. -- **AppraiserTaskRepairDisabled** Task repair performed by the appraiser plugin is disabled. -- **AppraiserTaskValid** Indicates that the appraiser task is valid. -- **AUOptionsExists** Indicates whether automatic update options exist. +- **AppraiserTaskRepairDisabled** Task repair performed by the Appraiser plug-in is disabled. +- **AppraiserTaskValid** Indicates that the Appraiser task is valid. +- **AUOptionsExists** Indicates whether the Automatic Update options exist. - **CTACTargetingAttributesInvalid** Indicates whether the Common Targeting Attribute Client (CTAC) attributes are valid. CTAC is a Windows Runtime client library. - **CTACVersion** The Common Targeting Attribute Client (CTAT) version on the device. CTAT is a Windows Runtime client library. - **CV** Correlation vector - **DataStoreSizeInBytes** Size of the data store, in bytes. - **DateTimeDifference** The difference between local and reference clock times. -- **DateTimeSyncEnabled** Indicates whether the datetime sync plug-in is enabled. -- **daysSinceInstallThreshold** The maximum number of days since the operating system was installed before we check to see if remediation is needed. +- **DateTimeSyncEnabled** Indicates whether the Datetime Sync plug-in is enabled. +- **daysSinceInstallThreshold** The maximum number of days since the operating system was installed before the device is checked to see if remediation is needed. - **daysSinceInstallValue** Number of days since the operating system was installed. - **DaysSinceLastSIH** The number of days since the most recent SIH executed. - **DaysToNextSIH** The number of days until the next scheduled SIH execution. - **DetectConditionEnabled** Indicates whether a condition that the remediation tool can repair was detected. -- **DetectedCondition** Indicates whether detect condition is true and the perform action will be run. +- **DetectedCondition** Indicates whether detected condition is true and the perform action will be run. - **DetectionFailedReason** Indicates why a given remediation failed to fix a problem that was detected. - **DiskFreeSpaceBeforeSedimentPackInMB** Number of megabytes of disk space available on the device before running the Sediment Pack. - **DiskSpaceBefore** The amount of free disk space available before a remediation was run. - **EditionIdFixCorrupted** Indicates whether the Edition ID is corrupted. - **EscalationTimerResetFixResult** The result of fixing the escalation timer. - **EvalAndReportAppraiserRegEntries** Indicates the EvalAndReportAppraiserRegEntriesFailed event failed. -- **FixedEditionId** Indicates whether we fixed Edition ID. +- **FixedEditionId** Indicates whether we fixed the edition ID. - **FlightRebootTime** The amount of time before the system is rebooted. - **ForcedRebootToleranceDays** The maximum number of days before a system reboot is forced on the devie. - **FreeSpaceRequirement** The amount of free space required. @@ -4875,7 +4887,7 @@ The following fields are available: - **ProductType** The product type of Windows 10. - **QualityUpdateSedimentFunnelState** Provides information about whether Windows Quality Updates are missing on the device. - **QualityUpdateSedimentJsonSchemaVersion** The schema version of the Quality Update Sediment Remediation. -- **QualityUpdateSedimentLastRunSeconds** The number of seconds since the Quality Updates were run +- **QualityUpdateSedimentLastRunSeconds** The number of seconds since the Quality Updates were run. - **QualityUpdateSedimentLocalStartTime** Provides information about when Quality Updates were run. - **QualityUpdateSedimentLocaltTime** The local time of the device running the Quality Update Sediment Remediation. - **QualityUpdateSedimentTargetedPlugins** Provides the list of remediation plug-ins that are applicable to enable Quality Updates on the device. @@ -4887,7 +4899,7 @@ The following fields are available: - **RemediationAutoUACalendarTaskEnabled** Indicates whether an Automatic Update Assistant tool task is enabled. - **RemediationAutoUACalendarTaskExists** Indicates whether an Automatic Update Assistant tool task exists. - **RemediationAutoUACalendarTaskTriggerEnabledCount** Indicates the number of times an Automatic Update Assistant tool task has been triggered. -- **RemediationAutoUADaysSinceLastTaskRunTime** Indicates the last run time of an Automatic Update Assistant tool task. +- **RemediationAutoUADaysSinceLastTaskRunTime** Indicates the last run time an Automatic Update Assistant tool task was run. - **RemediationAutoUAGetCurrentSize** Indicates the current size of the Automatic Update Assistant tool. - **RemediationAutoUAIsInstalled** Indicates whether the Automatic Update Assistant tool is installed. - **RemediationAutoUALastTaskRunResult** Indicates the result from the last time the Automatic Update Assistant tool was run. @@ -4895,16 +4907,16 @@ The following fields are available: - **RemediationAutoUATaskEnabled** Indicates whether the Automatic Update Assistant tool task is enabled. - **RemediationAutoUATaskExists** Indicates whether an Automatic Update Assistant tool task exists. - **RemediationAutoUATasksStalled** Indicates whether an Automatic Update Assistant tool task is stalled. -- **RemediationAutoUATaskTriggerEnabledCount** Indicates how many times an Automatic Update Assistant tool task has been triggered. +- **RemediationAutoUATaskTriggerEnabledCount** Indicates how many times an Automatic Update Assistant tool task was triggered. - **RemediationAutoUAUAExitCode** Indicates any exit code provided by the Automatic Update Assistant tool. - **RemediationAutoUAUAExitState** Indicates the exit state of the Automatic Update Assistant tool. - **RemediationAutoUAUserLoggedIn** Indicates whether a user is logged in. -- **RemediationAutoUAUserLoggedInAdmin** Indicates whether an Administrator user is logged in. +- **RemediationAutoUAUserLoggedInAdmin** Indicates whether a user is logged in as an Administrator. - **RemediationCorruptionRepairBuildNumber** The build number to use to repair corruption. - **RemediationCorruptionRepairCorruptionsDetected** Indicates whether corruption was detected. - **RemediationCorruptionRepairDetected** Indicates whether an attempt was made to repair the corruption. - **RemediationDeliverToastBuildNumber** Indicates a build number that should be applicable to this device. -- **RemediationDeliverToastDetected** Indicates that a plugin has been detected. +- **RemediationDeliverToastDetected** Indicates that a plug-in has been detected. - **RemediationDeliverToastDeviceExcludedNation** Indicates the geographic identity (GEO ID) that is not applicable for a given plug-in. - **RemediationDeliverToastDeviceFreeSpaceInMB** Indicates the amount of free space, in megabytes. - **RemediationDeliverToastDeviceHomeSku** Indicates whether the plug-in is applicable for the Windows 10 Home edition. @@ -4914,12 +4926,12 @@ The following fields are available: - **RemediationDeliverToastGeoId** Indicates the geographic identifier (GEO ID) that is applicable for a given plug-in. - **RemediationDeviceSkuId** The Windows 10 edition ID that maps to the version of Windows 10 on the device. - **RemediationGetCurrentFolderExist** Indicates whether the GetCurrent folder exists. -- **RemediationNoisyHammerAcLineStatus** Event that indicates the AC Line Status of the machine. +- **RemediationNoisyHammerAcLineStatus** Indicates the AC Line Status of the device. - **RemediationNoisyHammerAutoStartCount** The number of times hammer auto-started. - **RemediationNoisyHammerCalendarTaskEnabled** Event that indicates Update Assistant Calendar Task is enabled. - **RemediationNoisyHammerCalendarTaskExists** Event that indicates an Update Assistant Calendar Task exists. - **RemediationNoisyHammerCalendarTaskTriggerEnabledCount** Event that indicates calendar triggers are enabled in the task. -- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent hammer task ran. +- **RemediationNoisyHammerDaysSinceLastTaskRunTime** The number of days since the most recent Noisy Hammer task ran. - **RemediationNoisyHammerGetCurrentSize** Size in MB of the $GetCurrent folder. - **RemediationNoisyHammerIsInstalled** TRUE if the noisy hammer is installed. - **RemediationNoisyHammerLastTaskRunResult** The result of the last hammer task run. @@ -4943,10 +4955,10 @@ The following fields are available: - **RemediationProgramDataFolderSizeInMB** The size (in megabytes) of the Program Data folder on the device. - **RemediationProgramFilesFolderSizeInMB** The size (in megabytes) of the Program Files folder on the device. - **RemediationShellDeviceApplicabilityFailedReason** The reason the Remediation is not applicable to the device (expressed as a bitmap). -- **RemediationShellDeviceEducationSku** Indicates whether a Windows 10 Education edition is detected on the device. -- **RemediationShellDeviceEnterpriseSku** Indicates whether a Windows 10 Enterprise edition is detected on the device. +- **RemediationShellDeviceEducationSku** Indicates whether the Windows 10 Education edition is detected on the device. +- **RemediationShellDeviceEnterpriseSku** Indicates whether the Windows 10 Enterprise edition is detected on the device. - **RemediationShellDeviceFeatureUpdatesPaused** Indicates whether Feature Updates are paused on the device. -- **RemediationShellDeviceHomeSku** Indicates whether a Windows 10 Home edition is detected on the device. +- **RemediationShellDeviceHomeSku** Indicates whether the Windows 10 Home edition is detected on the device. - **RemediationShellDeviceIsAllowedSku** Indicates whether the Windows 10 edition is applicable to the device. - **RemediationShellDeviceManaged** TRUE if the device is WSUS managed or Windows Updated disabled. - **RemediationShellDeviceNewOS** TRUE if the device has a recently installed OS. @@ -4957,9 +4969,9 @@ The following fields are available: - **RemediationShellDeviceSetupMutexInUse** Indicates whether device setup is in progress. - **RemediationShellDeviceWuRegistryBlocked** Indicates whether the Windows Update is blocked on the device via the registry. - **RemediationShellDeviceZeroExhaust** TRUE if the device has opted out of Windows Updates completely. -- **RemediationShellHasExpired** Indicates whether the Remediation iterations have ended. +- **RemediationShellHasExpired** Indicates whether the remediation iterations have ended. - **RemediationShellHasUpgraded** Indicates whether the device upgraded. -- **RemediationShellIsDeviceApplicable** Indicates whether the Remediation is applicable to the device. +- **RemediationShellIsDeviceApplicable** Indicates whether the remediation is applicable to the device. - **RemediationTargetMachine** Indicates whether the device is a target of the specified fix. - **RemediationTaskHealthAutochkProxy** True/False based on the health of the AutochkProxy task. - **RemediationTaskHealthChkdskProactiveScan** True/False based on the health of the Check Disk task. @@ -4973,7 +4985,7 @@ The following fields are available: - **RemediationUHServiceNotExistBitMap** A bitmap indicating which services were deleted. - **RemediationUsersFolderSizeInMB** The size (in megabytes) of the Users folder on the device. - **RemediationWindows10UpgradeFolderExist** Indicates whether the Windows 10 Upgrade folder exists. -- **RemediationWindows10UpgradeFolderSizeInMB** The size (in megabytes) of Windows 10 Upgrade folder on the device. +- **RemediationWindows10UpgradeFolderSizeInMB** The size (in megabytes) of the Windows 10 Upgrade folder on the device. - **RemediationWindowsAppsFolderSizeInMB** The size (in megabytes) of the Windows Applications folder on the device. - **RemediationWindowsBtFolderSizeInMB** The size (in megabytes) of the Windows BT folder on the device. - **RemediationWindowsFolderSizeInMB** The size (in megabytes) of the Windows folder on the device. @@ -5003,7 +5015,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Completed -This event is sent when Windows Update Sediment Remediations have completed on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have completed on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -5021,7 +5033,7 @@ The following fields are available: - **DiskSpaceCleanedByRestorePointRemoval** The amount of disk space (megabytes) in restore points that was cleaned up by the plug-in. - **ForcedAppraiserTaskTriggered** TRUE if Appraiser task ran from the plug-in. - **GlobalEventCounter** Client-side counter that indicates ordering of events sent by the active user. -- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in Megabytes. +- **HandlerCleanupFreeDiskInMegabytes** The amount of hard disk space cleaned by the storage sense handlers, measured in megabytes. - **hasRolledBack** Indicates whether the client machine has rolled back. - **hasUninstalled** Indicates whether the client machine has uninstalled a later version of the OS. - **hResult** The result of the event execution. @@ -5095,7 +5107,7 @@ The following fields are available: - **StorageSenseHelloFaceRecognitionFodCleanupTotalInByte** The amount of space that Storage Sense was able to clean up in the User Download folder by removing Windows Hello facial recognition. - **StorageSenseRestorePointCleanupTotalInMB** The total number of megabytes that Storage Sense cleaned up in the User Download folder. - **StorageSenseUserDownloadFolderCleanupTotalInByte** The total number of bytes that Storage Sense cleaned up in the User Download folder. -- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive in MBs. +- **systemDriveFreeDiskSpace** Indicates the free disk space on system drive, in megabytes. - **systemUptimeInHours** Indicates the amount of time the system in hours has been on since the last boot. - **uninstallActive** TRUE if previous uninstall has occurred for current OS - **usoScanDaysSinceLastScan** The number of days since the last USO (Update Session Orchestrator) scan. @@ -5107,7 +5119,7 @@ The following fields are available: - **usoScanIsNetworkMetered** TRUE if the device is currently connected to a metered network. - **usoScanIsNoAutoUpdateKeyPresent** TRUE if no Auto Update registry key is set/present. - **usoScanIsUserLoggedOn** TRUE if the user is logged on. -- **usoScanPastThreshold** TRUE if the most recent USO (Update Session Orchestrator) scan is past the threshold (late). +- **usoScanPastThreshold** TRUE if the most recent Update Session Orchestrator (USO) scan is past the threshold (late). - **usoScanType** The type of USO (Update Session Orchestrator) scan: "Interactive" or "Background". - **windows10UpgraderBlockWuUpdates** Event to report the value of Windows 10 Upgrader BlockWuUpdates Key. - **windowsEditionId** Event to report the value of Windows Edition ID. @@ -5117,7 +5129,7 @@ The following fields are available: ### Microsoft.Windows.Remediation.Started -This event is sent when Windows Update Sediment Remediations have started on a device to keep Windows up to date. The remediations address issues on the system that prevent sediment devices from receiving OS updates. “Sediment” refers to devices that have been on a previous OS version for an extended period. +This event is sent when Windows Update sediment remediations have started on the sediment device to keep Windows up to date. A sediment device is one that has been on a previous OS version for an extended period. The remediations address issues on the system that prevent the device from receiving OS updates. The following fields are available: @@ -5195,7 +5207,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Applicable -Indicates whether a given plugin is applicable. +This event is sent when the Windows Update sediment remediations launcher finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5213,7 +5225,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Completed -Indicates whether a given plugin has completed its work. +This event is sent when the Windows Update sediment remediations launcher finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5228,7 +5240,7 @@ The following fields are available: ### Microsoft.Windows.SedimentLauncher.Started -This event indicates that a given plug-in has started. +This event is sent when the Windows Update sediment remediations launcher starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5241,7 +5253,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Applicable -This event indicates whether a given plug-in is applicable. +This event is sent when the Windows Update sediment remediations service finds that an applicable plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5259,7 +5271,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Completed -This event indicates whether a given plug-in has completed its work. +This event is sent when the Windows Update sediment remediations service finishes running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5283,7 +5295,7 @@ The following fields are available: ### Microsoft.Windows.SedimentService.Started -This event indicates a specified plug-in has started. This information helps ensure Windows is up to date. +This event is sent when the Windows Update sediment remediations service starts running a plug-in to address issues that may be preventing the sediment device from receiving OS updates. A sediment device is one that has been on a previous OS version for an extended period. The following fields are available: @@ -5468,7 +5480,6 @@ The following fields are available: - **BiosSKUNumber** The sku number of the device BIOS. - **BIOSVendor** The vendor of the BIOS. - **BiosVersion** The version of the BIOS. -- **Bundle02,UsedDO** No content is currently available. - **BundleBytesDownloaded** Number of bytes downloaded for the specific content bundle. - **BundleId** Identifier associated with the specific content bundle. - **BundleRepeatFailCount** Indicates whether this particular update bundle has previously failed. @@ -5483,7 +5494,6 @@ The following fields are available: - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. -- **ComvonProps** No content is currently available. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. - **DeviceModel** The model of the device. @@ -5621,7 +5631,6 @@ The following fields are available: - **DeviceModel** The device model. - **DriverPingBack** Contains information about the previous driver and system state. - **DriverRecoveryIds** The list of identifiers that could be used for uninstalling the drivers if a recovery is required. -- **DriverReuoveryIds** No content is currently available. - **EventInstanceID** A globally unique identifier for event instance. - **EventScenario** Indicates the purpose of sending this event - whether because the software distribution just started installing content, or whether it was cancelled, succeeded, or failed. - **EventType** Possible values are Child, Bundle, or Driver. @@ -6392,7 +6401,6 @@ The following fields are available: - **ClientId** Retrieves the upgrade ID. In the Windows Update scenario, this will be the Windows Update client ID. In Media setup, default value is Media360, but can be overwritten by the caller to a unique value. - **FieldName** Retrieves the data point. -- **FimldName** No content is currently available. - **FlightData** Specifies a unique identifier for each group of Windows Insider builds. - **InstanceId** Retrieves a unique identifier for each instance of a setup session. - **ReportId** Retrieves the report ID. @@ -7087,8 +7095,6 @@ The following fields are available: - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. - **predefinedCallerName** The name of the API Caller. -- **restrictederRepo** No content is currently available. -- **restrictedloaded** No content is currently available. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. - **sessionID** The ID of the download session. @@ -7150,7 +7156,6 @@ The following fields are available: - **predefinedCallerName** Name of the API caller. - **routeToCacheServer** Cache server setting, source, and value. - **sessionID** The ID for the file download session. -- **setConbigs** No content is currently available. - **setConfigs** A JSON representation of the configurations that have been set, and their sources. - **updateID** The ID of the update being downloaded. - **usedMemoryStream** Indicates whether the download used memory streaming. From 27b525e366e7221874e89b7bf3fbb59fe7d420af Mon Sep 17 00:00:00 2001 From: Jeanie Decker Date: Tue, 16 Apr 2019 12:39:03 -0700 Subject: [PATCH 173/737] fix order --- windows/application-management/manage-windows-mixed-reality.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/application-management/manage-windows-mixed-reality.md b/windows/application-management/manage-windows-mixed-reality.md index 789eabab79..5f7378bd96 100644 --- a/windows/application-management/manage-windows-mixed-reality.md +++ b/windows/application-management/manage-windows-mixed-reality.md @@ -33,7 +33,7 @@ Organizations that use Windows Server Update Services (WSUS) must take action to 2. Windows Mixed Reality Feature on Demand (FOD) is downloaded from Windows Update. If access to Windows Update is blocked, you must manually install the Windows Mixed Reality FOD. - a. Download the FOD .cab file for [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab), or [Windows 10, version 1903](https://software-download.microsoft.com/download/pr/Microsoft-Windows-Holographic-Desktop-FOD-Package-31bf3856ad364e35-amd64.cab). + a. Download the FOD .cab file for [Windows 10, version 1903](https://software-download.microsoft.com/download/pr/Microsoft-Windows-Holographic-Desktop-FOD-Package-31bf3856ad364e35-amd64.cab), [Windows 10, version 1809](https://software-download.microsoft.com/download/pr/microsoft-windows-holographic-desktop-fod-package31bf3856ad364e35amd64_1.cab), [Windows 10, version 1803](https://download.microsoft.com/download/9/9/3/9934B163-FA01-4108-A38A-851B4ACD1244/Microsoft-Windows-Holographic-Desktop-FOD-Package~31bf3856ad364e35~amd64~~.cab), or [Windows 10, version 1709](http://download.microsoft.com/download/6/F/8/6F816172-AC7D-4F45-B967-D573FB450CB7/Microsoft-Windows-Holographic-Desktop-FOD-Package.cab). >[!NOTE] >You must download the FOD .cab file that matches your operating system version. From 85337ba37717c4193472115297020fa2c67368d2 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 17 Apr 2019 08:32:51 -0700 Subject: [PATCH 174/737] new build 4/17/2019 8:32 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 76 +++++++++---------- 1 file changed, 38 insertions(+), 38 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 04b2280580..c229f9a624 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/16/2019 +ms.date: 04/17/2019 --- @@ -4109,6 +4109,43 @@ The following fields are available: - **ServiceName** The driver or service name that is attached to the device. +## Migration events + +### Microsoft.Windows.MigrationCore.MigObjectCountDLUsr + +This event returns data to track the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **currentSid** Indicates the user SID for which the migration is being performed. +- **knownFoldersUsr[i]** Predefined folder path locations. +- **migDiagSession->CString** The phase of the upgrade where migration occurs. (E.g.: Validate tracked content) +- **objectCount** The count for the number of objects that are being transferred. + + +### Microsoft.Windows.MigrationCore.MigObjectCountKFSys + +This event returns data about the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **knownFoldersSys[i]** The predefined folder path locations. +- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. +- **objectCount** The count of the number of objects that are being transferred. + + +### Microsoft.Windows.MigrationCore.MigObjectCountKFUsr + +This event returns data to track the count of the migration objects across various phases during feature update. + +The following fields are available: + +- **currentSid** Indicates the user SID for which the migration is being performed. +- **knownFoldersUsr[i]** No content is currently available. +- **migDiagSession->CString** No content is currently available. +- **objectCount** No content is currently available. + + ## Miracast events ### Microsoft.Windows.Cast.Miracast.MiracastSessionEnd @@ -4183,43 +4220,6 @@ The following fields are available: - **WFD2Supported** Indicates if the Miracast receiver supports WFD2 protocol. -## Other events - -### Microsoft.Windows.MigrationCore.MigObjectCountDLUsr - -No content is currently available. - -The following fields are available: - -- **currentSid** No content is currently available. -- **knownFoldersUsr[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. - - -### Microsoft.Windows.MigrationCore.MigObjectCountKFSys - -This event returns data about the count of the migration objects across various phases during feature update. - -The following fields are available: - -- **knownFoldersSys[i]** The predefined folder path locations. -- **migDiagSession->CString** Identifies the phase of the upgrade where migration happens. -- **objectCount** The count of the number of objects that are being transferred. - - -### Microsoft.Windows.MigrationCore.MigObjectCountKFUsr - -This event returns data to track the count of the migration objects across various phases during feature update. - -The following fields are available: - -- **currentSid** Indicates the user SID for which the migration is being performed. -- **knownFoldersUsr[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. - - ## Privacy consent logging events ### Microsoft.Windows.Shell.PrivacyConsentLogging.PrivacyConsentCompleted From cc14178c1f01b831c446a70f458b9be01be273db Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Wed, 17 Apr 2019 08:32:59 -0700 Subject: [PATCH 175/737] new build 4/17/2019 8:32 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 2 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 40 +++++++++++++++---- 4 files changed, 36 insertions(+), 10 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 187e5b5800..7d66c1ca89 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/16/2019 +ms.date: 04/17/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 8aed3dab5e..add7ca9310 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/16/2019 +ms.date: 04/17/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index d26544c92c..d43561bf66 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/16/2019 +ms.date: 04/17/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 26bb7bab6a..3826050602 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/16/2019 +ms.date: 04/17/2019 --- @@ -2790,10 +2790,12 @@ The following fields are available: - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. +- **T`rottledDroppedCount** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. +- **UreviousHeartBeatTime** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. @@ -3408,6 +3410,7 @@ The following fields are available: - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). +- **DedicatedVideoMemmryB** No content is currently available. - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. @@ -3420,11 +3423,14 @@ The following fields are available: - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. +- **GPUVefdorID** No content is currently available. - **GPUVendorID** The GPU vendor ID. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. +- **IsHy`ridIntegrated** No content is currently available. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? +- **IsHybridDiscRete** No content is currently available. - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? @@ -3538,12 +3544,16 @@ The following fields are available: - **AppVersion** The version of the app that has crashed. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. +- **EzceptionCode** No content is currently available. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. +- **FriendlyArpName** No content is currently available. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). - **ModTimeStamp** The date/time stamp of the module. +- **ModVdrsion** No content is currently available. - **ModVersion** The version of the module that has crashed. +- **PackageFullNale** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. @@ -4551,15 +4561,14 @@ The following fields are available: ### Microsoft.Windows.MigrationCore.MigObjectCountDLUsr -No content is currently available. +This event returns data to track the count of the migration objects across various phases during feature update. The following fields are available: -- **currentSid** No content is currently available. -- **defaultLoc->DirName->CString** No content is currently available. -- **knownFoldersUsr[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. +- **currentSid** Indicates the user SID for which the migration is being performed. +- **knownFoldersUsr[i]** Predefined folder path locations. +- **migDiagSession->CString** The phase of the upgrade where migration occurs. (E.g.: Validate tracked content) +- **objectCount** The count for the number of objects that are being transferred. ### Microsoft.Windows.MigrationCore.MigObjectCountKFSys @@ -5340,6 +5349,7 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: +- **Fie** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. @@ -5372,6 +5382,7 @@ The following fields are available: - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. - **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown - **CurrentMobileOperator** The mobile operator the device is currently connected to. +- **Deferral@olicySources** No content is currently available. - **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). - **DeferredUpdates** Update IDs which are currently being deferred until a later time - **DeviceModel** What is the device model. @@ -5398,6 +5409,7 @@ The following fields are available: - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 +- **Num`erOfNewUpdatesFromServiceSync** No content is currently available. - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required @@ -5469,6 +5481,7 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: +- **ActiveDownload4ime** No content is currently available. - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. @@ -5493,6 +5506,7 @@ The following fields are available: - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. +- **Co,76dB4ime** No content is currently available. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. @@ -5506,6 +5520,7 @@ The following fields are available: - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). +- **FlightBu9ldNumber** No content is currently available. - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -5517,11 +5532,13 @@ The following fields are available: - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. +- **IsWUfBEncbled** No content is currently available. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." - **PackageFullName** The package name of the content. - **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. +- **PostDnld4ime** No content is currently available. - **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. - **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. @@ -5535,6 +5552,7 @@ The following fields are available: - **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. +- **SizeCalc4ime** No content is currently available. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). - **SystemBIOSMajorRelease** Major version of the BIOS. @@ -5544,6 +5562,7 @@ The following fields are available: - **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. - **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. - **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. +- **TotalExp6dBedBytes** No content is currently available. - **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. @@ -5587,6 +5606,7 @@ The following fields are available: - **ClientVersion** The version number of the software distribution client - **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat - **CurrentError** Last (transient) error encountered by the active download +- **CurrentMrror** No content is currently available. - **DownloadFlags** Flags indicating if power state is ignored - **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) - **EventType** Possible values are "Child", "Bundle", or "Driver" @@ -7073,9 +7093,11 @@ The following fields are available: - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. +- **dileID** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). +- **downlinkUsageFps** No content is currently available. - **downloadMode** The download mode used for this file download session. - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). @@ -7094,6 +7116,7 @@ The following fields are available: - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. +- **ppedefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. @@ -7101,7 +7124,9 @@ The following fields are available: - **totalTimeMs** Duration of the download (in seconds). - **updateID** The ID of the update being downloaded. - **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). +- **uplinkFps** No content is currently available. - **uplinkUsageBps** The upload speed (in bytes per second). +- **uplinkUsageFps** No content is currently available. - **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. @@ -7149,6 +7174,7 @@ The following fields are available: - **fileSize** Total file size of the file that was downloaded. - **fileSizeCaller** Value for total file size provided by our caller. - **groupID** ID for the group. +- **grOupID** No content is currently available. - **isEncrypted** Indicates whether the download is encrypted. - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. From e5cdb04fa0a52924ae2cadf5291a35a7c5672243 Mon Sep 17 00:00:00 2001 From: Wael Jendli <33766257+wjendli@users.noreply.github.com> Date: Wed, 17 Apr 2019 11:42:37 -0700 Subject: [PATCH 176/737] Add LTE attach purpose guid --- windows/client-management/mdm/cm-cellularentries-csp.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/client-management/mdm/cm-cellularentries-csp.md b/windows/client-management/mdm/cm-cellularentries-csp.md index adffb8bef0..32ca9ee217 100644 --- a/windows/client-management/mdm/cm-cellularentries-csp.md +++ b/windows/client-management/mdm/cm-cellularentries-csp.md @@ -183,6 +183,7 @@ The following diagram shows the CM\_CellularEntries configuration service provid

Required. Type: String. Specifies the purposes of the connection by a comma-separated list of GUIDs representing purpose values. The following purpose values are available: - Internet - 3E5545D2-1137-4DC8-A198-33F1C657515F +- LTE attach - 11A6FE68-5B47-4859-9CB6-1EAC96A8F0BD - MMS - 53E2C5D3-D13C-4068-AA38-9C48FF2E55A8 - IMS - 474D66ED-0E4B-476B-A455-19BB1239ED13 - SUPL - 6D42669F-52A9-408E-9493-1071DCC437BD From 4ae7c10b9aa1a308e235ac234c6dae8f87b5bef7 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Wed, 17 Apr 2019 15:25:44 -0700 Subject: [PATCH 177/737] updated names --- windows/security/threat-protection/index.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/security/threat-protection/index.md b/windows/security/threat-protection/index.md index 8747fb3827..bface3f851 100644 --- a/windows/security/threat-protection/index.md +++ b/windows/security/threat-protection/index.md @@ -37,12 +37,12 @@ ms.localizationpriority: medium -**[Threat & Vulnerability Management](windows-defender-atp/next-gen-threat-and-vuln-mgt.md)**
+**[Threat & Vulnerability Management](microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md)**
This built-in capability uses a game-changing risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. -- [Risk-based Threat & Vulnerability Management](windows-defender-atp/next-gen-threat-and-vuln-mgt.md) -- [What's in the dashboard and what it means for my organization](windows-defender-atp/tvm-dashboard-insights.md) -- [Configuration score](windows-defender-atp/configuration-score.md) -- [Scenarios](windows-defender-atp/threat-and-vuln-mgt-scenarios.md) +- [Risk-based Threat & Vulnerability Management](microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md) +- [What's in the dashboard and what it means for my organization](microsoft-defender-atp/tvm-dashboard-insights.md) +- [Configuration score](microsoft-defender-atp/configuration-score.md) +- [Scenarios](microsoft-defender-atp/threat-and-vuln-mgt-scenarios.md) From 0e10de048c051784558a0868a2183724aa115a19 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Wed, 17 Apr 2019 15:35:11 -0700 Subject: [PATCH 178/737] search product --- .../microsoft-defender-atp/configuration-score.md | 2 +- .../microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md | 2 +- .../microsoft-defender-atp/tvm-dashboard-insights.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configuration-score.md b/windows/security/threat-protection/microsoft-defender-atp/configuration-score.md index 746d31cc8f..bb6764a9a3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configuration-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configuration-score.md @@ -2,7 +2,7 @@ title: Overview of Configuration score in Microsoft Defender Security Center description: Expand your visibility into the overall security configuration posture of your organization keywords: configuration score, mdatp configuration score, secure score, security controls, improvement opportunities, security configuration score over time, security posture, baseline -search.product: Windows 10 +search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 ms.mktglfcycl: deploy diff --git a/windows/security/threat-protection/microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md b/windows/security/threat-protection/microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md index d83dc2575a..cefa8aada0 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md +++ b/windows/security/threat-protection/microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md @@ -2,7 +2,7 @@ title: Next-generation Threat & Vulnerability Management description: This new capability uses a game-changing risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. keywords: threat and vulnerability management, MDATP-TVM, vulnerability management, threat and vulnerability scanning -search.product: Windows 10 +search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 ms.mktglfcycl: deploy diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md index 9613ef139d..c0236a5f88 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights.md @@ -2,7 +2,7 @@ title: What's in the dashboard and what it means for my organization's security posture description: keywords: -search.product: Windows 10 +search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 ms.mktglfcycl: deploy From 021bc3707ea97df8a7f3b03163782c49de022c33 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 18 Apr 2019 10:01:12 -0700 Subject: [PATCH 179/737] new build 4/18/2019 10:01 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 121 +++--------------- 1 file changed, 18 insertions(+), 103 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index c229f9a624..161e810b9e 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/17/2019 +ms.date: 04/18/2019 --- @@ -1606,6 +1606,17 @@ The following fields are available: - **IEVersion** The version of Internet Explorer that is running on the device. +### Census.Azure + +No content is currently available. + +The following fields are available: + +- **CloudCoreBuildEx** No content is currently available. +- **CloudCoreSupportBuildEx** No content is currently available. +- **NodeID** No content is currently available. + + ### Census.Battery This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. @@ -2088,18 +2099,6 @@ The following fields are available: - **ver** Represents the version number of the application. Used to understand errors by Version, Usage by Version across an app. -### Common Data Extensions.cloud - -Describes the service-related fields populated by the cloud service. - -The following fields are available: - -- **role** The role of the service. -- **roleInstance** The instance id of the deployed role instance generating the event. -- **roleVer** The build version of the role. -- **ver** No content is currently available. - - ### Common Data Extensions.container Describes the properties of the container for events logged within a container. @@ -2113,35 +2112,16 @@ The following fields are available: - **type** The container type. Examples: Process or VMHost -### Common Data Extensions.cs1 - -No content is currently available. - -The following fields are available: - -- **dblp** A bitfield that is set to a non-zero value if the event in the newer schema has an equivalent event from the 1.0 schema. -- **esc** The event sequence clock. -- **ev** The version of the event. -- **locale** The client language locale on the device. -- **scid** The Service Config ID of the running title that sent the event. -- **users** A comma-separated list of all users logged into the device when the event was created. The user ID is encoded. Example: x:12345678 - - ### Common Data Extensions.device Describes the device-related fields. The following fields are available: -- **authId** The ID of the device associated with this event. For Microsoft Account tickets, this is expected to be the MSA Global ID. -- **authSecId** The secondary ID of the device associated with this event. For Microsoft Account tickets, this is expected to be the MSA Hardware ID. - **deviceClass** The device classification. For example, Desktop, Server, or Mobile. -- **id** A unique device ID. - **localId** A locally-defined unique ID for the device. This is not the human-readable device name. Most likely equal to the value stored at HKLM\Software\Microsoft\SQMClient\MachineId - **make** Device manufacturer. - **model** Device model. -- **orgAuthId** ID used to authenticate the orgId. -- **orgId** Organization ID associated with the event. ### Common Data Extensions.Envelope @@ -2152,14 +2132,8 @@ The following fields are available: - **data** Represents the optional unique diagnostic data for a particular event schema. - **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). -- **ext_cloud** Describes the service-related fields populated by the cloud service. See [Common Data Extensions.cloud](#common-data-extensionscloud). - **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). -- **ext_cs1** If the field doesn't exist in the newer schema, this contains the fields from an earlier schema. See [Common Data Extensions.cs1](#common-data-extensionscs1). - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_ingest** Describes the fields added dynamically by the service. See [Common Data Extensions.ingest](#common-data-extensionsingest). -- **ext_intService** No content is currently available. See [Common Data Extensions.intService](#common-data-extensionsintservice). -- **ext_intWeb** No content is currently available. See [Common Data Extensions.intWeb](#common-data-extensionsintweb). -- **ext_loc** Describes the location from which the event was logged. See [Common Data Extensions.loc](#common-data-extensionsloc). - **ext_mscv** No content is currently available. See [Common Data Extensions.mscv](#common-data-extensionsmscv). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). - **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). @@ -2174,65 +2148,13 @@ The following fields are available: - **ver** Represents the major and minor version of the extension. -### Common Data Extensions.ingest - -Describes the fields that are added by the ingestion service. - -The following fields are available: - -- **auth** Used to assess the trustworthiness of the data. -- **client** The client name. -- **clientIp** The IP address seen by the service. This is not necessarily the client IP address, but could be a router or some other device. -- **processedIngest** If the event already had an ingest extension and the client was authenticated as a first party, the ingest extension will be inserted as processedIngest. -- **quality** A bitfield added by the service to all events coming from a client device. -- **time** The time that the event was received by the service. -- **userAgent** For events that are not using the CUET component, this is the user agent of the browser. - - -### Common Data Extensions.intService - -No content is currently available. - -The following fields are available: - -- **deploymentUnit** No content is currently available. -- **environment** No content is currently available. -- **fullEnvName** No content is currently available. -- **location** No content is currently available. -- **name** No content is currently available. - - -### Common Data Extensions.intWeb - -No content is currently available. - -The following fields are available: - -- **anid** No content is currently available. -- **mc1Id** No content is currently available. -- **mscom** No content is currently available. -- **msfpc** No content is currently available. -- **serviceName** No content is currently available. - - -### Common Data Extensions.loc - -Describes the location from which the event was logged. - -The following fields are available: - -- **country** 2 letter country code using the codes from the ISO 3166-1 alpha-2 standard. -- **id** Location ID based on the client's IP address. -- **tz** The time zone of the device. - - ### Common Data Extensions.mscv -No content is currently available. +Describes the correlation vector-related fields. The following fields are available: -- **cV** No content is currently available. +- **cV** Represents the Correlation Vector: A single field for tracking partial order of related events across component boundaries. ### Common Data Extensions.os @@ -2280,7 +2202,6 @@ Describes the fields related to a user. The following fields are available: - **authId** This is an ID of the user associated with this event that is deduced from a token such as a Microsoft Account ticket or an XBOX token. -- **id** Unique user Id. Example: x:12345678. - **locale** The language and region. - **localId** Represents a unique user identity that is created locally and added by the client. This is not the user's account ID. @@ -2296,7 +2217,7 @@ The following fields are available: - **cat** Represents a bitmask of the ETW Keywords associated with the event. - **cpId** The composer ID, such as Reference, Desktop, Phone, Holographic, Hub, IoT Composer. - **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **eventFlags** No content is currently available. +- **eventFlags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. - **flags** Represents the bitmap that captures various Windows specific flags. - **loggingBinary** No content is currently available. - **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence @@ -2319,13 +2240,7 @@ No content is currently available. The following fields are available: -- **browser** No content is currently available. -- **browserLang** No content is currently available. - **browserVer** No content is currently available. -- **domain** No content is currently available. -- **isManual** No content is currently available. -- **screenRes** No content is currently available. -- **userConsent** No content is currently available. ### Common Data Extensions.xbl @@ -4141,9 +4056,9 @@ This event returns data to track the count of the migration objects across vario The following fields are available: - **currentSid** Indicates the user SID for which the migration is being performed. -- **knownFoldersUsr[i]** No content is currently available. -- **migDiagSession->CString** No content is currently available. -- **objectCount** No content is currently available. +- **knownFoldersUsr[i]** Predefined folder path locations. +- **migDiagSession->CString** The phase of the upgrade where the migration occurs. (For example, Validate tracked content.) +- **objectCount** The number of objects that are being transferred. ## Miracast events From 57ddb2d7104103e6b85a6b84a7c937f7ed4a69b3 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 18 Apr 2019 10:01:20 -0700 Subject: [PATCH 180/737] new build 4/18/2019 10:01 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 4 +- ...ndows-diagnostic-events-and-fields-1709.md | 2 +- ...ndows-diagnostic-events-and-fields-1803.md | 2 +- ...ndows-diagnostic-events-and-fields-1809.md | 70 +++++++++++-------- 4 files changed, 44 insertions(+), 34 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 7d66c1ca89..086a835957 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/17/2019 +ms.date: 04/18/2019 --- @@ -4004,7 +4004,7 @@ The following fields are available: ### SIHEngineTelemetry.EvalApplicability -This event is sent when targeting logic is evaluated to determine if a device is eligible a given action. +This event is sent when targeting logic is evaluated to determine if a device is eligible for a given action. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index add7ca9310..8dedfc835b 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/17/2019 +ms.date: 04/18/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index d43561bf66..452ecb0c6d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/17/2019 +ms.date: 04/18/2019 --- diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 3826050602..122c0460b9 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/17/2019 +ms.date: 04/18/2019 --- @@ -1817,6 +1817,17 @@ The following fields are available: - **IEVersion** The version of Internet Explorer that is running on the device. +### Census.Azure + +No content is currently available. + +The following fields are available: + +- **CloudCoreBuildEx** No content is currently available. +- **CloudCoreSupportBuildEx** No content is currently available. +- **NodeID** No content is currently available. + + ### Census.Battery This event sends type and capacity data about the battery on the device, as well as the number of connected standby devices in use, type to help keep Windows up to date. @@ -2790,12 +2801,10 @@ The following fields are available: - **RepeatedUploadFailureDropped** Number of events lost due to repeated upload failures for a single buffer. - **SettingsHttpAttempts** Number of attempts to contact OneSettings service. - **SettingsHttpFailures** The number of failures from contacting the OneSettings service. -- **T`rottledDroppedCount** No content is currently available. - **ThrottledDroppedCount** Number of events dropped due to throttling of noisy providers. - **TopUploaderErrors** List of top errors received from the upload endpoint. - **UploaderDroppedCount** Number of events dropped at the uploader layer of telemetry client. - **UploaderErrorCount** Number of errors received from the upload endpoint. -- **UreviousHeartBeatTime** No content is currently available. - **VortexFailuresTimeout** The number of timeout failures received from Vortex. - **VortexHttpAttempts** Number of attempts to contact Vortex. - **VortexHttpFailures4xx** Number of 400-499 error codes received from Vortex. @@ -3410,7 +3419,6 @@ The following fields are available: - **BrightnessVersionViaDDI** The version of the Display Brightness Interface. - **ComputePreemptionLevel** The maximum preemption level supported by GPU for compute payload. - **DedicatedSystemMemoryB** The amount of system memory dedicated for GPU use (in bytes). -- **DedicatedVideoMemmryB** No content is currently available. - **DedicatedVideoMemoryB** The amount of dedicated VRAM of the GPU (in bytes). - **DisplayAdapterLuid** The display adapter LUID. - **DriverDate** The date of the display driver. @@ -3423,14 +3431,11 @@ The following fields are available: - **GPUDeviceID** The GPU device ID. - **GPUPreemptionLevel** The maximum preemption level supported by GPU for graphics payload. - **GPURevisionID** The GPU revision ID. -- **GPUVefdorID** No content is currently available. - **GPUVendorID** The GPU vendor ID. - **InterfaceId** The GPU interface ID. - **IsDisplayDevice** Does the GPU have displaying capabilities? - **IsHwSchSupported** Indicates whether the adapter supports hardware scheduling. -- **IsHy`ridIntegrated** No content is currently available. - **IsHybridDiscrete** Does the GPU have discrete GPU capabilities in a hybrid device? -- **IsHybridDiscRete** No content is currently available. - **IsHybridIntegrated** Does the GPU have integrated GPU capabilities in a hybrid device? - **IsLDA** Is the GPU comprised of Linked Display Adapters? - **IsMiracastSupported** Does the GPU support Miracast? @@ -3544,16 +3549,12 @@ The following fields are available: - **AppVersion** The version of the app that has crashed. - **ExceptionCode** The exception code returned by the process that has crashed. - **ExceptionOffset** The address where the exception had occurred. -- **EzceptionCode** No content is currently available. - **Flags** Flags indicating how reporting is done. For example, queue the report, do not offer JIT debugging, or do not terminate the process after reporting. - **FriendlyAppName** The description of the app that has crashed, if different from the AppName. Otherwise, the process name. -- **FriendlyArpName** No content is currently available. - **IsFatal** True/False to indicate whether the crash resulted in process termination. - **ModName** Exception module name (e.g. bar.dll). - **ModTimeStamp** The date/time stamp of the module. -- **ModVdrsion** No content is currently available. - **ModVersion** The version of the module that has crashed. -- **PackageFullNale** No content is currently available. - **PackageFullName** Store application identity. - **PackageRelativeAppId** Store application identity. - **ProcessArchitecture** Architecture of the crashing process, as one of the PROCESSOR_ARCHITECTURE_* constants: 0: PROCESSOR_ARCHITECTURE_INTEL. 5: PROCESSOR_ARCHITECTURE_ARM. 9: PROCESSOR_ARCHITECTURE_AMD64. 12: PROCESSOR_ARCHITECTURE_ARM64. @@ -4590,8 +4591,8 @@ The following fields are available: - **currentSid** Indicates the user SID for which the migration is being performed. - **knownFoldersUsr[i]** Predefined folder path locations. -- **migDiagSession->CString** The phase of the upgrade where migration occurs. (E.g.: Validate tracked content) -- **objectCount** The count for the number of objects that are being transferred. +- **migDiagSession->CString** The phase of the upgrade where the migration occurs. (For example, Validate tracked content.) +- **objectCount** The number of objects that are being transferred. ## Miracast events @@ -5349,12 +5350,37 @@ This service retrieves events generated by SetupPlatform, the engine that drives The following fields are available: -- **Fie** No content is currently available. - **FieldName** Retrieves the event name/data point. Examples: InstallStartTime, InstallEndtime, OverallResult etc. - **GroupName** Retrieves the groupname the event belongs to. Example: Install Information, DU Information, Disk Space Information etc. - **Value** Retrieves the value associated with the corresponding event name (Field Name). For example: For time related events this will include the system time. +## SIH events + +### SIHEngineTelemetry.EvalApplicability + +This event is sent when targeting logic is evaluated to determine if a device is eligible for a given action. + +The following fields are available: + +- **ActionReasons** If an action has been assessed as inapplicable, the additional logic prevented it. +- **AdditionalReasons** If an action has been assessed as inapplicable, the additional logic prevented it. +- **CachedEngineVersion** The engine DLL version that is being used. +- **EventInstanceID** A unique identifier for event instance. +- **EventScenario** Indicates the purpose of sending this event – whether because the software distribution just started checking for content, or whether it was cancelled, succeeded, or failed. +- **HandlerReasons** If an action has been assessed as inapplicable, the installer technology-specific logic prevented it. +- **IsExecutingAction** If the action is presently being executed. +- **ServiceGuid** A unique identifier that represents which service the software distribution client is connecting to (SIH, Windows Update, Microsoft Store, etc.) +- **SihclientVersion** The client version that is being used. +- **StandardReasons** If an action has been assessed as inapplicable, the standard logic the prevented it. +- **StatusCode** Result code of the event (success, cancellation, failure code HResult). +- **UpdateID** A unique identifier for the action being acted upon. +- **WuapiVersion** The Windows Update API version that is currently installed. +- **WuaucltVersion** The Windows Update client version that is currently installed. +- **WuauengVersion** The Windows Update engine version that is currently installed. +- **WUDeviceID** The unique identifier controlled by the software distribution client. + + ## Software update events ### SoftwareUpdateClientTelemetry.CheckForUpdates @@ -5382,7 +5408,6 @@ The following fields are available: - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. No data is currently reported in this field. Expected value for this field is 0. - **Context** Gives context on where the error has occurred. Example: AutoEnable, GetSLSData, AddService, Misc, or Unknown - **CurrentMobileOperator** The mobile operator the device is currently connected to. -- **Deferral@olicySources** No content is currently available. - **DeferralPolicySources** Sources for any update deferral policies defined (GPO = 0x10, MDM = 0x100, Flight = 0x1000, UX = 0x10000). - **DeferredUpdates** Update IDs which are currently being deferred until a later time - **DeviceModel** What is the device model. @@ -5409,7 +5434,6 @@ The following fields are available: - **MetadataIntegrityMode** The mode of the update transport metadata integrity check. 0-Unknown, 1-Ignoe, 2-Audit, 3-Enforce - **MSIError** The last error that was encountered during a scan for updates. - **NetworkConnectivityDetected** Indicates the type of network connectivity that was detected. 0 - IPv4, 1 - IPv6 -- **Num`erOfNewUpdatesFromServiceSync** No content is currently available. - **NumberOfApplicableUpdates** The number of updates which were ultimately deemed applicable to the system after the detection process is complete - **NumberOfApplicationsCategoryScanEvaluated** The number of categories (apps) for which an app update scan checked - **NumberOfLoop** The number of round trips the scan required @@ -5481,7 +5505,6 @@ Download process event for target update on Windows Update client. See the Event The following fields are available: -- **ActiveDownload4ime** No content is currently available. - **ActiveDownloadTime** How long the download took, in seconds, excluding time where the update wasn't actively being downloaded. - **AppXBlockHashFailures** Indicates the number of blocks that failed hash validation during download of the app payload. - **AppXBlockHashValidationFailureCount** A count of the number of blocks that have failed validation after being downloaded. @@ -5506,7 +5529,6 @@ The following fields are available: - **CDNCountryCode** Two letter country abbreviation for the Content Distribution Network (CDN) location. - **CDNId** ID which defines which CDN the software distribution client downloaded the content from. - **ClientVersion** The version number of the software distribution client. -- **Co,76dB4ime** No content is currently available. - **CommonProps** A bitmask for future flags associated with the Windows Update client behavior. - **ConnectTime** Indicates the cumulative amount of time (in seconds) it took to establish the connection for all updates in an update bundle. - **CurrentMobileOperator** The mobile operator the device is currently connected to. @@ -5520,7 +5542,6 @@ The following fields are available: - **ExtendedStatusCode** Secondary error code for certain scenarios where StatusCode wasn't specific enough. - **FeatureUpdatePause** Indicates whether feature OS updates are paused on the device. - **FlightBranch** The branch that a device is on if participating in flighting (pre-release builds). -- **FlightBu9ldNumber** No content is currently available. - **FlightBuildNumber** If this download was for a flight (pre-release build), this indicates the build number of that flight. - **FlightId** The specific ID of the flight (pre-release build) the device is getting. - **FlightRing** The ring (speed of getting builds) that a device is on if participating in flighting (pre-release builds). @@ -5532,13 +5553,11 @@ The following fields are available: - **IsDependentSet** Indicates whether a driver is a part of a larger System Hardware/Firmware Update - **IsWUfBDualScanEnabled** Indicates if Windows Update for Business dual scan is enabled on the device. - **IsWUfBEnabled** Indicates if Windows Update for Business is enabled on the device. -- **IsWUfBEncbled** No content is currently available. - **NetworkCost** A flag indicating the cost of the network (congested, fixed, variable, over data limit, roaming, etc.) used for downloading the update content. - **NetworkCostBitMask** Indicates what kind of network the device is connected to (roaming, metered, over data cap, etc.) - **NetworkRestrictionStatus** More general version of NetworkCostBitMask, specifying whether Windows considered the current network to be "metered." - **PackageFullName** The package name of the content. - **PhonePreviewEnabled** Indicates whether a phone was opted-in to getting preview builds, prior to flighting (pre-release builds) being introduced. -- **PostDnld4ime** No content is currently available. - **PostDnldTime** Time (in seconds) taken to signal download completion after the last job completed downloading the payload. - **ProcessName** The process name of the application that initiated API calls, in the event where CallerApplicationName was not provided. - **QualityUpdatePause** Indicates whether quality OS updates are paused on the device. @@ -5552,7 +5571,6 @@ The following fields are available: - **ServiceGuid** A unique identifier for the service that the software distribution client is installing content for (Windows Update, Microsoft Store, etc). - **Setup360Phase** Identifies the active phase of the upgrade download if the current download is for an Operating System upgrade. - **ShippingMobileOperator** The mobile operator linked to the device when the device shipped. -- **SizeCalc4ime** No content is currently available. - **SizeCalcTime** Time (in seconds) taken to calculate the total download size of the payload. - **StatusCode** Indicates the result of a Download event (success, cancellation, failure code HResult). - **SystemBIOSMajorRelease** Major version of the BIOS. @@ -5562,7 +5580,6 @@ The following fields are available: - **TargetMetadataVersion** The version of the currently downloading (or most recently downloaded) package. - **ThrottlingServiceHResult** Result code (success/failure) while contacting a web service to determine whether this device should download content yet. - **TimeToEstablishConnection** Time (in milliseconds) it took to establish the connection prior to beginning downloaded. -- **TotalExp6dBedBytes** No content is currently available. - **TotalExpectedBytes** The total size (in Bytes) expected to be downloaded. - **UpdateId** An identifier associated with the specific piece of content. - **UpdateID** An identifier associated with the specific piece of content. @@ -5606,7 +5623,6 @@ The following fields are available: - **ClientVersion** The version number of the software distribution client - **ConnectionStatus** Indicates the connectivity state of the device at the time of heartbeat - **CurrentError** Last (transient) error encountered by the active download -- **CurrentMrror** No content is currently available. - **DownloadFlags** Flags indicating if power state is ignored - **DownloadState** Current state of the active download for this content (queued, suspended, or progressing) - **EventType** Possible values are "Child", "Bundle", or "Driver" @@ -7093,11 +7109,9 @@ The following fields are available: - **cdnIp** The IP address of the source CDN. - **cdnUrl** Url of the source Content Distribution Network (CDN). - **dataSourcesTotal** Bytes received per source type, accumulated for the whole session. -- **dileID** No content is currently available. - **doErrorCode** The Delivery Optimization error code that was returned. - **downlinkBps** The maximum measured available download bandwidth (in bytes per second). - **downlinkUsageBps** The download speed (in bytes per second). -- **downlinkUsageFps** No content is currently available. - **downloadMode** The download mode used for this file download session. - **downloadModeReason** Reason for the download. - **downloadModeSrc** Source of the DownloadMode setting (KvsProvider = 0, GeoProvider = 1, GeoVerProvider = 2, CpProvider = 3, DiscoveryProvider = 4, RegistryProvider = 5, GroupPolicyProvider = 6, MdmProvider = 7, SettingsProvider = 8, InvalidProviderType = 9). @@ -7116,7 +7130,6 @@ The following fields are available: - **linkLocalConnectionCount** The number of connections made to peers in the same Link-local network. - **numPeers** The total number of peers used for this download. - **numPeersLocal** The total number of local peers used for this download. -- **ppedefinedCallerName** No content is currently available. - **predefinedCallerName** The name of the API Caller. - **restrictedUpload** Is the upload restricted? - **routeToCacheServer** The cache server setting, source, and value. @@ -7124,9 +7137,7 @@ The following fields are available: - **totalTimeMs** Duration of the download (in seconds). - **updateID** The ID of the update being downloaded. - **uplinkBps** The maximum measured available upload bandwidth (in bytes per second). -- **uplinkFps** No content is currently available. - **uplinkUsageBps** The upload speed (in bytes per second). -- **uplinkUsageFps** No content is currently available. - **usedMemoryStream** TRUE if the download is using memory streaming for App downloads. @@ -7174,7 +7185,6 @@ The following fields are available: - **fileSize** Total file size of the file that was downloaded. - **fileSizeCaller** Value for total file size provided by our caller. - **groupID** ID for the group. -- **grOupID** No content is currently available. - **isEncrypted** Indicates whether the download is encrypted. - **isVpn** Indicates whether the device is connected to a Virtual Private Network. - **jobID** The ID of the Windows Update job. From 9b7198fbc27033affb7ca0f899119a2d86b68033 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Thu, 18 Apr 2019 15:09:13 -0700 Subject: [PATCH 181/737] new build 4/18/2019 3:09 PM --- ...ndows-diagnostic-events-and-fields-1903.md | 58 +++++++++++++------ 1 file changed, 41 insertions(+), 17 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 161e810b9e..a8a6106419 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -2134,13 +2134,12 @@ The following fields are available: - **ext_app** Describes the properties of the running application. This extension could be populated by either a client app or a web app. See [Common Data Extensions.app](#common-data-extensionsapp). - **ext_container** Describes the properties of the container for events logged within a container. See [Common Data Extensions.container](#common-data-extensionscontainer). - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). -- **ext_mscv** No content is currently available. See [Common Data Extensions.mscv](#common-data-extensionsmscv). +- **ext_mscv** Describes the correlation vector-related fields. See [Common Data Extensions.mscv](#common-data-extensionsmscv). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). - **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). - **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). - **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). - **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). -- **ext_web** No content is currently available. See [Common Data Extensions.web](#common-data-extensionsweb). - **ext_xbl** Describes the fields related to XBOX Live. See [Common Data Extensions.xbl](#common-data-extensionsxbl). - **iKey** Represents an ID for applications or other logical groupings of events. - **name** Represents the uniquely qualified name for the event. @@ -2219,28 +2218,19 @@ The following fields are available: - **epoch** Represents the epoch and seqNum fields, which help track how many events were fired and how many events were uploaded, and enables identification of data lost during upload and de-duplication of events on the ingress server. - **eventFlags** Represents a collection of bits that describe how the event should be processed by the Connected User Experience and Telemetry component pipeline. The lowest-order byte is the event persistence. The next byte is the event latency. - **flags** Represents the bitmap that captures various Windows specific flags. -- **loggingBinary** No content is currently available. +- **loggingBinary** The binary (executable, library, driver, etc.) that fired the event. - **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence - **op** Represents the ETW Op Code. -- **pgName** No content is currently available. +- **pgName** The short form of the provider group name associated with the event. - **popSample** No content is currently available. -- **providerGuid** No content is currently available. +- **providerGuid** The ETW provider ID associated with the provider name. - **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. - **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. - **sqmId** No content is currently available. - **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. -- **wcmp** No content is currently available. -- **wPId** No content is currently available. -- **wsId** No content is currently available. - - -### Common Data Extensions.web - -No content is currently available. - -The following fields are available: - -- **browserVer** No content is currently available. +- **wcmp** The Windows Shell Composer ID. +- **wPId** The Windows Core OS product ID. +- **wsId** The Windows Core OS session ID. ### Common Data Extensions.xbl @@ -7480,6 +7470,17 @@ The following fields are available: - **wuDeviceid** Unique device ID used by Windows Update. +### Microsoft.Windows.Update.Orchestrator.UniversalOrchestratorInvalidSignature + +No content is currently available. + +The following fields are available: + +- **updaterCmdLine** No content is currently available. +- **updaterId** No content is currently available. +- **wuDeviceid** No content is currently available. + + ### Microsoft.Windows.Update.Orchestrator.UnstickUpdate This event is sent when the update service orchestrator (USO) indicates that the update can be superseded by a newer update. @@ -7503,6 +7504,18 @@ The following fields are available: - **wuDeviceid** Unique device ID used by Windows Update. +### Microsoft.Windows.Update.Orchestrator.UpdaterCallbackFailed + +No content is currently available. + +The following fields are available: + +- **updaterArgument** No content is currently available. +- **updaterCmdLine** No content is currently available. +- **updaterId** No content is currently available. +- **wuDeviceid** No content is currently available. + + ### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired This event sends data about whether an update required a reboot to help keep Windows up to date. @@ -7518,6 +7531,17 @@ The following fields are available: - **wuDeviceid** Unique device ID used by Windows Update. +### Microsoft.Windows.Update.Orchestrator.UpdaterMalformedData + +No content is currently available. + +The following fields are available: + +- **malformedRegValue** No content is currently available. +- **updaterId** No content is currently available. +- **wuDeviceid** No content is currently available. + + ### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed This event sends information about an update that encountered problems and was not able to complete. From 1115f64c67d3d2e99d082fcdfdc3f3f6b14cf308 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 19 Apr 2019 08:31:12 -0700 Subject: [PATCH 182/737] new build 4/19/2019 8:31 AM --- ...ndows-diagnostic-events-and-fields-1903.md | 61 ++++++++----------- 1 file changed, 24 insertions(+), 37 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index a8a6106419..97b84fbcf7 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/18/2019 +ms.date: 04/19/2019 --- @@ -1590,7 +1590,7 @@ The following fields are available: ### Census.App -Provides information on IE and Census versions running on the device +This event sends version data about the Apps running on this device, to help keep Windows up to date. The following fields are available: @@ -1608,13 +1608,13 @@ The following fields are available: ### Census.Azure -No content is currently available. +This event returns data from Microsoft-internal Azure server machines (only from Microsoft-internal machines with Server SKUs). All other machines (those outside Microsoft and/or machines that are not part of the “Azure fleet”) return empty data sets. The following fields are available: -- **CloudCoreBuildEx** No content is currently available. -- **CloudCoreSupportBuildEx** No content is currently available. -- **NodeID** No content is currently available. +- **CloudCoreBuildEx** The Azure CloudCore build number. +- **CloudCoreSupportBuildEx** The Azure CloudCore support build number. +- **NodeID** The node identifier on the device that indicates whether the device is part of the Azure fleet. ### Census.Battery @@ -1865,7 +1865,7 @@ The following fields are available: ### Census.Processor -Provides information on several important data points about Processor settings +This event sends data about the processor to help keep Windows up to date. The following fields are available: @@ -2136,7 +2136,6 @@ The following fields are available: - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). - **ext_mscv** Describes the correlation vector-related fields. See [Common Data Extensions.mscv](#common-data-extensionsmscv). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). - **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). - **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). - **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). @@ -2169,18 +2168,6 @@ The following fields are available: - **ver** Represents the major and minor version of the extension. -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **flags** No content is currently available. -- **originalName** No content is currently available. -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - ### Common Data Extensions.sdk Used by platform specific libraries to record fields that are required for a specific SDK. @@ -2191,7 +2178,7 @@ The following fields are available: - **installId** An ID that's created during the initialization of the SDK for the first time. - **libVer** The SDK version. - **seq** An ID that is incremented for each event. -- **ver** No content is currently available. +- **ver** The version of the logging SDK. ### Common Data Extensions.user @@ -2222,7 +2209,7 @@ The following fields are available: - **mon** Combined monitor and event sequence numbers in the format: monitor sequence : event sequence - **op** Represents the ETW Op Code. - **pgName** The short form of the provider group name associated with the event. -- **popSample** No content is currently available. +- **popSample** Represents the effective sample rate for this event at the time it was generated by a client. - **providerGuid** The ETW provider ID associated with the provider name. - **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. - **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. @@ -2408,7 +2395,7 @@ This event sends data about boot IDs for which a normal clean shutdown was not o The following fields are available: - **AbnormalShutdownBootId** BootId of the abnormal shutdown being reported by this event. -- **AbsCausedbyAutoChk** No content is currently available. +- **AbsCausedbyAutoChk** This flag is set when AutoCheck forces a device restart to indicate that the shutdown was not an abnormal shutdown. - **AcDcStateAtLastShutdown** Identifies if the device was on battery or plugged in. - **BatteryLevelAtLastShutdown** The last recorded battery level. - **BatteryPercentageAtLastShutdown** The battery percentage at the last shutdown. @@ -2423,7 +2410,7 @@ The following fields are available: - **FirmwareType** ID of the FirmwareType as enumerated in DimFirmwareType. - **HardwareWatchdogTimerGeneratedLastReset** Indicates whether the hardware watchdog timer caused the last reset. - **HardwareWatchdogTimerPresent** Indicates whether hardware watchdog timer was present or not. -- **InvalidBootStat** No content is currently available. +- **InvalidBootStat** This is a sanity check flag that ensures the validity of the bootstat file. - **LastBugCheckBootId** bootId of the last captured crash. - **LastBugCheckCode** Code that indicates the type of error. - **LastBugCheckContextFlags** Additional crash dump settings. @@ -7472,13 +7459,13 @@ The following fields are available: ### Microsoft.Windows.Update.Orchestrator.UniversalOrchestratorInvalidSignature -No content is currently available. +This event is sent when an updater has attempted to register a binary that is not signed by Microsoft. The following fields are available: -- **updaterCmdLine** No content is currently available. -- **updaterId** No content is currently available. -- **wuDeviceid** No content is currently available. +- **updaterCmdLine** The callback executable for the updater. +- **updaterId** The ID of the updater. +- **wuDeviceid** Unique device ID used by Windows Update. ### Microsoft.Windows.Update.Orchestrator.UnstickUpdate @@ -7506,14 +7493,14 @@ The following fields are available: ### Microsoft.Windows.Update.Orchestrator.UpdaterCallbackFailed -No content is currently available. +This event is sent when an updater failed to execute the registered callback. The following fields are available: -- **updaterArgument** No content is currently available. -- **updaterCmdLine** No content is currently available. -- **updaterId** No content is currently available. -- **wuDeviceid** No content is currently available. +- **updaterArgument** The argument to pass to the updater callback. +- **updaterCmdLine** The callback executable for the updater. +- **updaterId** The ID of the updater. +- **wuDeviceid** Unique device ID used by Windows Update. ### Microsoft.Windows.Update.Orchestrator.UpdateRebootRequired @@ -7533,13 +7520,13 @@ The following fields are available: ### Microsoft.Windows.Update.Orchestrator.UpdaterMalformedData -No content is currently available. +This event is sent when a registered updater has missing or corrupted information, to help keep Windows up to date. The following fields are available: -- **malformedRegValue** No content is currently available. -- **updaterId** No content is currently available. -- **wuDeviceid** No content is currently available. +- **malformedRegValue** The registry value that contains the malformed or missing entry. +- **updaterId** The ID of the updater. +- **wuDeviceid** Unique device ID used by Windows Update. ### Microsoft.Windows.Update.Orchestrator.updateSettingsFlushFailed From b7f16d21b4f76cf232f3250a00e43b6ba64b861b Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 19 Apr 2019 08:31:23 -0700 Subject: [PATCH 183/737] new build 4/19/2019 8:31 AM --- ...ndows-diagnostic-events-and-fields-1703.md | 4 +- ...ndows-diagnostic-events-and-fields-1709.md | 6 +-- ...ndows-diagnostic-events-and-fields-1803.md | 17 ++------ ...ndows-diagnostic-events-and-fields-1809.md | 39 ++++--------------- 4 files changed, 15 insertions(+), 51 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md index 086a835957..ab24b15b13 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1703.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/18/2019 +ms.date: 04/19/2019 --- @@ -1464,7 +1464,7 @@ The following fields are available: ### Census.Processor -This event sends data about the processor (architecture, speed, number of cores, manufacturer, and model number), to help keep Windows up to date. +This event sends data about the processor to help keep Windows up to date. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md index 8dedfc835b..a4a2c28bc5 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1709.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/18/2019 +ms.date: 04/19/2019 --- @@ -1329,7 +1329,7 @@ The following fields are available: ### Census.App -Provides information on IE and Census versions running on the device +This event sends version data about the Apps running on this device, to help keep Windows up to date. The following fields are available: @@ -1538,7 +1538,7 @@ The following fields are available: ### Census.Processor -Provides information on several important data points about Processor settings +This event sends data about the processor to help keep Windows up to date. The following fields are available: diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md index 452ecb0c6d..e199627613 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1803.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/18/2019 +ms.date: 04/19/2019 --- @@ -1374,7 +1374,7 @@ The following fields are available: ### Census.App -Provides information on IE and Census versions running on the device. +This event sends version data about the Apps running on this device, to help keep Windows up to date. The following fields are available: @@ -1628,7 +1628,7 @@ The following fields are available: ### Census.Processor -Provides information on several important data points about Processor settings. +This event sends data about the processor to help keep Windows up to date. The following fields are available: @@ -1907,7 +1907,6 @@ The following fields are available: - **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). - **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). - **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). - **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). @@ -1933,16 +1932,6 @@ The following fields are available: - **ver** Represents the major and minor version of the extension. -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - ### Common Data Extensions.sdk Used by platform specific libraries to record fields that are required for a specific SDK. diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 122c0460b9..19d1f81064 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -13,7 +13,7 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/18/2019 +ms.date: 04/19/2019 --- @@ -1801,7 +1801,7 @@ The following fields are available: ### Census.App -Provides information on IE and Census versions running on the device +This event sends version data about the Apps running on this device, to help keep Windows up to date. The following fields are available: @@ -1819,13 +1819,13 @@ The following fields are available: ### Census.Azure -No content is currently available. +This event returns data from Microsoft-internal Azure server machines (only from Microsoft-internal machines with Server SKUs). All other machines (those outside Microsoft and/or machines that are not part of the “Azure fleet”) return empty data sets. The following fields are available: -- **CloudCoreBuildEx** No content is currently available. -- **CloudCoreSupportBuildEx** No content is currently available. -- **NodeID** No content is currently available. +- **CloudCoreBuildEx** The Azure CloudCore build number. +- **CloudCoreSupportBuildEx** The Azure CloudCore support build number. +- **NodeID** The node identifier on the device that indicates whether the device is part of the Azure fleet. ### Census.Battery @@ -2070,7 +2070,7 @@ The following fields are available: ### Census.Processor -Provides information on several important data points about Processor settings +This event sends data about the processor to help keep Windows up to date. The following fields are available: @@ -2357,7 +2357,6 @@ The following fields are available: - **ext_cs** Describes properties related to the schema of the event. See [Common Data Extensions.cs](#common-data-extensionscs). - **ext_device** Describes the device-related fields. See [Common Data Extensions.device](#common-data-extensionsdevice). - **ext_os** Describes the operating system properties that would be populated by the client. See [Common Data Extensions.os](#common-data-extensionsos). -- **ext_receipts** Describes the fields related to time as provided by the client for debugging purposes. See [Common Data Extensions.receipts](#common-data-extensionsreceipts). - **ext_sdk** Describes the fields related to a platform library required for a specific SDK. See [Common Data Extensions.sdk](#common-data-extensionssdk). - **ext_user** Describes the fields related to a user. See [Common Data Extensions.user](#common-data-extensionsuser). - **ext_utc** Describes the fields that might be populated by a logging library on Windows. See [Common Data Extensions.utc](#common-data-extensionsutc). @@ -2383,16 +2382,6 @@ The following fields are available: - **ver** Represents the major and minor version of the extension. -### Common Data Extensions.receipts - -Represents various time information as provided by the client and helps for debugging purposes. - -The following fields are available: - -- **originalTime** The original event time. -- **uploadTime** The time the event was uploaded. - - ### Common Data Extensions.sdk Used by platform specific libraries to record fields that are required for a specific SDK. @@ -4509,22 +4498,8 @@ This event indicates the number of bytes read from or read by the OS and written The following fields are available: -- **BootAttemptCount** No content is currently available. -- **BootStatusPolicy** No content is currently available. -- **BootType** No content is currently available. - **BytesRead** The total number of bytes read from or read by the OS upon system startup. - **BytesWritten** The total number of bytes written to or written by the OS upon system startup. -- **FirmwareResetReasonEmbeddedController** No content is currently available. -- **FirmwareResetReasonEmbeddedControllerAdditional** No content is currently available. -- **FirmwareResetReasonPch** No content is currently available. -- **FirmwareResetReasonPchAdditional** No content is currently available. -- **FirmwareResetReasonSupplied** No content is currently available. -- **LastBootSucceeded** No content is currently available. -- **LastShutdownSucceeded** No content is currently available. -- **MeasuredLaunchResume** No content is currently available. -- **MenuPolicy** No content is currently available. -- **RecoveryEnabled** No content is currently available. -- **UserInputTime** No content is currently available. ### Microsoft.Windows.Kernel.BootEnvironment.OsLaunch From 2e9e683afabb7f8381c3270f5d5b890a7cdabc5f Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Fri, 19 Apr 2019 13:13:02 -0700 Subject: [PATCH 184/737] fixing typo --- .../basic-level-windows-diagnostic-events-and-fields-1809.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md index 19d1f81064..b312c42c9d 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1809.md @@ -3877,7 +3877,7 @@ The following fields are available: This event indicates that a new set of InventoryDeviceMediaClassSAdd events will be sent. -This event includes fields from [Ms.Device.De~iceInventoryChange](#msdevicede~iceinventorychange). +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: @@ -3968,7 +3968,7 @@ The following fields are available: This event indicates that a new set of InventoryDeviceUsbHubClassAdd events will be sent. -This event includes fields from [Ms.De~ice.DeviceInventoryChange](#msde~icedeviceinventorychange). +This event includes fields from [Ms.Device.DeviceInventoryChange](#msdevicedeviceinventorychange). The following fields are available: From 3d577dc32ce2b9b140b1deb9d2e2107a1dbff248 Mon Sep 17 00:00:00 2001 From: Brian Lich Date: Tue, 23 Apr 2019 10:06:39 -0700 Subject: [PATCH 185/737] final build 04232019 --- ...-level-windows-diagnostic-events-and-fields-1903.md | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md index 97b84fbcf7..9f8a2900c9 100644 --- a/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md +++ b/windows/privacy/basic-level-windows-diagnostic-events-and-fields-1903.md @@ -13,17 +13,12 @@ manager: dansimp ms.collection: M365-security-compliance ms.topic: article audience: ITPro -ms.date: 04/19/2019 +ms.date: 04/23/2019 --- # Windows 10, version 1903 basic level Windows diagnostic events and fields - -> [!IMPORTANT] -> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. - - **Applies to** - Windows 10, version 1903 @@ -46,8 +41,6 @@ You can learn more about Windows functional and diagnostic data through these ar - [Configure Windows diagnostic data in your organization](configure-windows-diagnostic-data-in-your-organization.md) - - ## AppLocker events ### Microsoft.Windows.Security.AppLockerCSP.AddParams @@ -2213,7 +2206,6 @@ The following fields are available: - **providerGuid** The ETW provider ID associated with the provider name. - **raId** Represents the ETW Related ActivityId. Logged via TraceLogging or directly via ETW. - **seq** Represents the sequence field used to track absolute order of uploaded events. It is an incrementing identifier for each event added to the upload queue. The Sequence helps track how many events were fired and how many events were uploaded and enables identification of data lost during upload and de-duplication of events on the ingress server. -- **sqmId** No content is currently available. - **stId** Represents the Scenario Entry Point ID. This is a unique GUID for each event in a diagnostic scenario. This used to be Scenario Trigger ID. - **wcmp** The Windows Shell Composer ID. - **wPId** The Windows Core OS product ID. From dc90e8ddde7012f009025936fdc54465b2d1a484 Mon Sep 17 00:00:00 2001 From: karthigb Date: Tue, 23 Apr 2019 11:45:44 -0700 Subject: [PATCH 186/737] Update configure-windows-defender-smartscreen-shortdesc.md --- .../configure-windows-defender-smartscreen-shortdesc.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/browsers/edge/shortdesc/configure-windows-defender-smartscreen-shortdesc.md b/browsers/edge/shortdesc/configure-windows-defender-smartscreen-shortdesc.md index 58dfd6be9a..ce0f753466 100644 --- a/browsers/edge/shortdesc/configure-windows-defender-smartscreen-shortdesc.md +++ b/browsers/edge/shortdesc/configure-windows-defender-smartscreen-shortdesc.md @@ -6,4 +6,4 @@ ms.prod: edge ms:topic: include --- -Microsoft Edge uses Windows Defender SmartScreen (turned on) to protect users from potential phishing scams and malicious software by default. Also, by default, users cannot disable (turn off) Windows Defender SmartScreen. Enabling this policy turns off Windows Defender SmartScreen and prevent users from turning it on. Don’t configure this policy to let users choose to turn Windows defender SmartScreen on or off. \ No newline at end of file +Microsoft Edge uses Windows Defender SmartScreen (turned on) to protect users from potential phishing scams and malicious software by default. Also, by default, users cannot disable (turn off) Windows Defender SmartScreen. Enabling this policy turns on Windows Defender SmartScreen and prevent users from turning it off. Don’t configure this policy to let users choose to turn Windows defender SmartScreen on or off. From 5f0d4b97e71cfa2263f32f7c58215f631f2e6619 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Tue, 23 Apr 2019 14:23:30 -0700 Subject: [PATCH 187/737] fix error --- .openpublishing.redirection.json | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 22d6eeea52..974018c147 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -14674,10 +14674,11 @@ "source_path": "windows/security/threat-protection/windows-defender-atp/user-alert-windows-defender-advanced-threat-protection-new.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/user", "redirect_document_id": true -} +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/manage-indicators", "redirect_document_id": true -}, +} ] } From 54c0c02c2dd5a160a781e8cab345d7d305124639 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Tue, 23 Apr 2019 14:57:28 -0700 Subject: [PATCH 188/737] update links --- .openpublishing.redirection.json | 5 ----- 1 file changed, 5 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 974018c147..4b84e0c62b 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -1356,11 +1356,6 @@ "redirect_document_id": true }, { -"source_path": "windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md", -"redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-allowed-blocked-list", -"redirect_document_id": true -}, -{ "source_path": "windows/security/threat-protection/windows-defender-atp/manage-auto-investigation-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/microsoft-defender-atp/manage-auto-investigation", "redirect_document_id": true From 783fc36d3e55d39c1a9a7e4dcdc873a504476bbc Mon Sep 17 00:00:00 2001 From: ImranHabib <47118050+joinimran@users.noreply.github.com> Date: Wed, 1 May 2019 19:08:57 +0500 Subject: [PATCH 189/737] cloud experience host information Cloud experience host related information was missing in the document. Required information has been added. Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3276 --- .../hello-how-it-works-technology.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index d12e00c028..401dcdc382 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -39,6 +39,7 @@ ms.date: 10/08/2018 - [Storage Root Key](#storage-root-key) - [Trust Type](#trust-type) - [Trusted Platform Module](#trusted-platform-module) +- [Cloud Experience Host](#cloud-experience-host)


## Attestation Identity Keys @@ -304,7 +305,16 @@ In a simplified manner, the TPM is a passive component with limited resources. I [Return to Top](hello-how-it-works-technology.md) +## Cloud Experience Host +In Windows 10 Enterprise edition, cloud experience host is a component that helps you join the workplace environment or Azure AD using your company provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you(including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. +### Related topics +[Windows Hello for Business](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) + +### More information +- [Windows Hello for Business and Device Registration](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) + +[Return to Top](hello-how-it-works-technology.md) From 522bb702bb2177779c7b30dc037ee2df0e1f9cf7 Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Wed, 1 May 2019 22:21:50 +0500 Subject: [PATCH 190/737] Update windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md Co-Authored-By: joinimran <47118050+joinimran@users.noreply.github.com> --- .../hello-for-business/hello-how-it-works-technology.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index 401dcdc382..6fb3df408c 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -312,7 +312,7 @@ In Windows 10 Enterprise edition, cloud experience host is a component that help [Windows Hello for Business](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) ### More information -- [Windows Hello for Business and Device Registration](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) +- [Windows Hello for Business and Device Registration](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) [Return to Top](hello-how-it-works-technology.md) From 0ceb9f2a5e6fa6c0d1d8f7a5bfb8b5592c34dc44 Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Wed, 1 May 2019 22:22:06 +0500 Subject: [PATCH 191/737] Update windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md Co-Authored-By: joinimran <47118050+joinimran@users.noreply.github.com> --- .../hello-for-business/hello-how-it-works-technology.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index 6fb3df408c..23acc75c13 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -306,7 +306,7 @@ In a simplified manner, the TPM is a passive component with limited resources. I [Return to Top](hello-how-it-works-technology.md) ## Cloud Experience Host -In Windows 10 Enterprise edition, cloud experience host is a component that helps you join the workplace environment or Azure AD using your company provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you(including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. +In Windows 10 Enterprise edition, Cloud Experience Host is an application that helps you join the workplace environment or Azure AD using your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. ### Related topics [Windows Hello for Business](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) From 53e037095bc9b0837f79c9d7c882b2dfc5883d4c Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Wed, 1 May 2019 22:22:25 +0500 Subject: [PATCH 192/737] Update windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md Co-Authored-By: joinimran <47118050+joinimran@users.noreply.github.com> --- .../hello-for-business/hello-how-it-works-technology.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index 23acc75c13..5f740c9437 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -309,7 +309,7 @@ In a simplified manner, the TPM is a passive component with limited resources. I In Windows 10 Enterprise edition, Cloud Experience Host is an application that helps you join the workplace environment or Azure AD using your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. ### Related topics -[Windows Hello for Business](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) +[Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) ### More information - [Windows Hello for Business and Device Registration](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) From 24efe934039130e2c78fcc911d0470adb413b0fa Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Wed, 1 May 2019 12:53:52 -0700 Subject: [PATCH 193/737] Updates per task 3309387 --- .../mdm/policy-csp-deliveryoptimization.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/client-management/mdm/policy-csp-deliveryoptimization.md b/windows/client-management/mdm/policy-csp-deliveryoptimization.md index 95e6d74539..47a3305652 100644 --- a/windows/client-management/mdm/policy-csp-deliveryoptimization.md +++ b/windows/client-management/mdm/policy-csp-deliveryoptimization.md @@ -6,13 +6,13 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 07/06/2018 +ms.date: 05/01/2019 --- # Policy CSP - DeliveryOptimization > [!WARNING] -> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. +> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here.
@@ -985,7 +985,7 @@ ADMX Info: > This policy is only enforced in Windows 10 Pro, Business, Enterprise, and Education editions and not supported in Windows 10 Mobile. -Added in Windows 10, version 1703. Specifies the required minimum disk size (capacity in GB) for the device to use Peer Caching. The value 0 means "not-limited" which means the cloud service set default value will be used. Recommended values: 64 GB to 256 GB. +Added in Windows 10, version 1703. Specifies the required minimum disk size (capacity in GB) for the device to use Peer Caching. Recommended values: 64 GB to 256 GB. > [!NOTE] > If the DOMofidyCacheDrive policy is set, the disk size check will apply to the new working directory specified by this policy. @@ -1046,7 +1046,7 @@ ADMX Info: > This policy is only enforced in Windows 10 Pro, Business, Enterprise, and Education editions and not supported in Windows 10 Mobile. -Added in Windows 10, version 1703. Specifies the minimum content file size in MB enabled to use Peer Caching. The value 0 means "unlimited" which means the cloud service set default value will be used. Recommended values: 1 MB to 100,000 MB. +Added in Windows 10, version 1703. Specifies the minimum content file size in MB enabled to use Peer Caching. Recommended values: 1 MB to 100,000 MB. The default value is 100 MB. @@ -1104,7 +1104,7 @@ ADMX Info: > This policy is only enforced in Windows 10 Pro, Business, Enterprise, and Education editions and not supported in Windows 10 Mobile. -Added in Windows 10, version 1703. Specifies the minimum RAM size in GB required to use Peer Caching. The value 0 means "not-limited" which means the cloud service set default value will be used. For example if the minimum set is 1 GB, then devices with 1 GB or higher available RAM will be allowed to use Peer caching. Recommended values: 1 GB to 4 GB. +Added in Windows 10, version 1703. Specifies the minimum RAM size in GB required to use Peer Caching. For example, if the minimum set is 1 GB, then devices with 1 GB or higher available RAM will be allowed to use Peer caching. Recommended values: 1 GB to 4 GB. The default value is 4 GB. From c68e5f808b4324e0d7b8c465732ae4d405fe761b Mon Sep 17 00:00:00 2001 From: ImranHabib <47118050+joinimran@users.noreply.github.com> Date: Thu, 2 May 2019 12:52:36 +0500 Subject: [PATCH 194/737] Changes applied Changes applied as suggested by copy/edit review. --- .../hello-how-it-works-technology.md | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index 5f740c9437..015c33f72a 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -24,6 +24,7 @@ ms.date: 10/08/2018 - [Azure AD Registered](#azure-ad-registered) - [Certificate Trust](#certificate-trust) - [Cloud Deployment](#cloud-deployment) +- [Cloud Experience Host](#cloud-experience-host) - [Deployment Type](#deployment-type) - [Endorsement Key](#endorsement-key) - [Federated Environment](#federated-environment) @@ -39,7 +40,6 @@ ms.date: 10/08/2018 - [Storage Root Key](#storage-root-key) - [Trust Type](#trust-type) - [Trusted Platform Module](#trusted-platform-module) -- [Cloud Experience Host](#cloud-experience-host)
## Attestation Identity Keys @@ -100,6 +100,17 @@ The Windows Hello for Business Cloud deployment is exclusively for organizations [Azure AD Joined](#azure-ad-joined), [Azure AD Registered](#azure-ad-registered), [Deployment Type](#deployment-type), [Join Type](#join-type) [Return to Top](hello-how-it-works-technology.md) +## Cloud Experience Host +In Windows 10 Enterprise edition, Cloud Experience Host is an application that helps you join the workplace environment or Azure AD using your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. + +### Related topics +[Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) + +### More information +- [Windows Hello for Business and Device Registration](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) + +[Return to Top](hello-how-it-works-technology.md) + ## Deployment Type Windows Hello for Business has three deployment models to accommodate the needs of different organizations. The three deployment models include: - Cloud @@ -305,17 +316,6 @@ In a simplified manner, the TPM is a passive component with limited resources. I [Return to Top](hello-how-it-works-technology.md) -## Cloud Experience Host -In Windows 10 Enterprise edition, Cloud Experience Host is an application that helps you join the workplace environment or Azure AD using your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. - -### Related topics -[Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) - -### More information -- [Windows Hello for Business and Device Registration](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-how-it-works-device-registration) - -[Return to Top](hello-how-it-works-technology.md) - From 69b54b8d9640c97fc9fedf589dff4c622c995178 Mon Sep 17 00:00:00 2001 From: Jie RONG Date: Fri, 3 May 2019 14:32:52 +0800 Subject: [PATCH 195/737] Update set-up-enterprise-mode-portal.md In previous doc: Step 3, following 10 of To create the website will change the connectionstring to like following: But for Model first connection string, it should be like following as displayed in Web.config in the project folder. This will introduce data access error, throwing "Keyword not supported: 'server'." 2. The fix is in step 1 - 6, just update server name and database name, then remove the manual setting steps in Step 2. --- .../set-up-enterprise-mode-portal.md | 18 +++++------------- 1 file changed, 5 insertions(+), 13 deletions(-) diff --git a/browsers/internet-explorer/ie11-deploy-guide/set-up-enterprise-mode-portal.md b/browsers/internet-explorer/ie11-deploy-guide/set-up-enterprise-mode-portal.md index 47c4caf92b..c6c5cf099e 100644 --- a/browsers/internet-explorer/ie11-deploy-guide/set-up-enterprise-mode-portal.md +++ b/browsers/internet-explorer/ie11-deploy-guide/set-up-enterprise-mode-portal.md @@ -43,7 +43,10 @@ You must download the deployment folder (**EMIEWebPortal/**), which includes all Installs the npm package manager and bulk adds all the third-party libraries back into your codebase. -6. Go back up a directory, open the solution file **EMIEWebPortal.sln** in Visual Studio, and then build the entire solution. +6. Go back up a directory, open the solution file **EMIEWebPortal.sln** in Visual Studio, open **Web.config** from **EMIEWebPortal/** folder, and replace MSIT-LOB-COMPAT with your server name hosting your database, replace LOBMerged with your database name, and build the entire solution. + + >[!Note] + >Step 3 of this topic provides the steps to create your database. 7. Copy the contents of the **EMIEWebPortal/** folder to a dedicated folder on your file system. For example, _D:\EMIEWebApp_. In a later step, you'll designate this folder as your website in the IIS Manager. @@ -105,17 +108,6 @@ Create a new Application Pool and the website, by using the IIS Manager. >[!Note] >You must also make sure that **Anonymous Authentication** is marked as **Enabled**. -10. Return to the **<website_name> Home** pane, and double-click the **Connection Strings** icon. - -11. Open the **LOBMergedEntities Connection String** to edit: - - - **Data source.** Type the name of your local computer. - - - **Initial catalog.** The name of your database. - - >[!Note] - >Step 3 of this topic provides the steps to create your database. - ## Step 3 - Create and prep your database Create a SQL Server database and run our custom query to create the Enterprise Mode Site List tables. @@ -229,4 +221,4 @@ Register the EMIEScheduler tool and service for production site list changes. - [Enterprise Mode and the Enterprise Mode Site List](what-is-enterprise-mode.md) -- [Use the Enterprise Mode Site List Manager tool or page](use-the-enterprise-mode-site-list-manager.md) \ No newline at end of file +- [Use the Enterprise Mode Site List Manager tool or page](use-the-enterprise-mode-site-list-manager.md) From 2a6248937c504561c5e34d29e9e2074e03dcd851 Mon Sep 17 00:00:00 2001 From: Rona Song <38082753+qrscharmed@users.noreply.github.com> Date: Fri, 3 May 2019 11:27:51 -0700 Subject: [PATCH 196/737] Update faq-wd-app-guard.md --- .../windows-defender-application-guard/faq-wd-app-guard.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md index 8be213c70e..2e9c8a2adc 100644 --- a/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md +++ b/windows/security/threat-protection/windows-defender-application-guard/faq-wd-app-guard.md @@ -70,3 +70,9 @@ Answering frequently asked questions about Windows Defender Application Guard (A |**Q:** |What is the WDAGUtilityAccount local account?| |**A:** |This account is part of Application Guard beginning with Windows 10 version 1709 (Fall Creators Update). This account remains disabled until Application Guard is enabled on your device. This item is integrated to the OS and is not considered as a threat/virus/malware.|
+ +| | | +|---|----------------------------| +|**Q:** |How do I trust a subdomain in my site list?| +|**A:** |To trust a subdomain, you must precede your domain with two dots, for example: ..contoso.com.| +
From a0b726daf0c03797d10980a0d1defa849ac055bb Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 3 May 2019 23:38:14 -0700 Subject: [PATCH 197/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...system-components-to-microsoft-services.md | 155 ++++++------------ 1 file changed, 53 insertions(+), 102 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 923bfedcb3..1616b648c6 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -48,55 +48,6 @@ Note that **Get Help** and **Give us Feedback** links no longer work after the W We are always striving to improve our documentation and welcome your feedback. You can provide feedback by contacting telmhelp@microsoft.com. -## What's new in Windows 10, version 1809 Enterprise edition - -Here's a list of changes that were made to this article for Windows 10, version 1809: - -- Added a policy to disable Windows Defender SmartScreen - -## What's new in Windows 10, version 1803 Enterprise edition - -Here's a list of changes that were made to this article for Windows 10, version 1803: - -- Added a policy to turn off notifications network usage -- Added a policy for Microsoft Edge to turn off configuration updates for the Books Library -- Added a policy for Microsoft Edge to turn off Address Bar drop-down list suggestions - -## What's new in Windows 10, version 1709 Enterprise edition - -Here's a list of changes that were made to this article for Windows 10, version 1709: - -- Added the Phone calls section -- Added the Storage Health section -- Added discussion of apps for websites in the Microsoft Store section - -## What's new in Windows 10, version 1703 Enterprise edition - -Here's a list of changes that were made to this article for Windows 10, version 1703: - -- Added an MDM policy for Font streaming -- Added an MDM policy for Network Connection Status Indicator -- Added an MDM policy for the Micosoft Account Sign-In Assistant -- Added instructions for removing the Sticky Notes app -- Added registry paths for some Group Policies -- Added the Find My Device section -- Added the Tasks section -- Added the App Diagnostics section - -- Added the following Group Policies: - - - Prevent managing SmartScreen Filter - - Turn off Compatibility View - - Turn off Automatic Download and Install of updates - - Do not connect to any Windows Update locations - - Turn off access to all Windows Update features - - Specify Intranet Microsoft update service location - - Enable Windows NTP client - - Turn off Automatic download of the ActiveX VersionList - - Allow Automatic Update of Speech Data - - Accounts: Block Microsoft Accounts - - Do not use diagnostic data for tailored experiences - ## Management options for each setting The following sections list the components that make network connections to Microsoft services by default. You can configure these settings to control the data that is sent to Microsoft. To prevent Windows from sending any data to Microsoft, configure diagnostic data at the Security level, turn off Windows Defender diagnostic data and MSRT reporting, and turn off all of these connections. @@ -108,59 +59,59 @@ The following table lists management options for each setting, beginning with Wi >[!NOTE] >For some settings, MDM policies only partly cover capabilities available through Group Policy. See each setting’s section for more details. -| Setting | UI | Group Policy | MDM policy | Registry | Command line | -| - | :-: | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [9. License Manager](#bkmk-licmgr) | | | | ![Check mark](images/checkmark.png) | | -| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | ![Check mark](images/checkmark.png) | -| [18. Settings > Privacy](#bkmk-settingssection) | | | | | | -|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | | -|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | -|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | | -| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | | -| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | +| Setting | UI | Group Policy | MDM policy | Registry | +| - | :-: | :-: | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [9. License Manager](#bkmk-licmgr) | | | | ![Check mark](images/checkmark.png) | +| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | +| [18. Settings > Privacy](#bkmk-settingssection) | | | | | +|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | +|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | +| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ### Settings for Windows Server 2016 with Desktop Experience From 903400c4d1b9e698b50eeb5aff849015b3e4569c Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 3 May 2019 23:55:14 -0700 Subject: [PATCH 198/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...system-components-to-microsoft-services.md | 178 +++++++++--------- 1 file changed, 89 insertions(+), 89 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 1616b648c6..99e29bee27 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -118,110 +118,110 @@ The following table lists management options for each setting, beginning with Wi See the following table for a summary of the management settings for Windows Server 2016 with Desktop Experience. -| Setting | UI | Group Policy | Registry | Command line | -| - | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | | -| [18. Settings > Privacy](#bkmk-settingssection) | | | | | -|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [20. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | | -| [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| Setting | UI | Group Policy | Registry | +| - | :-: | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | +| [18. Settings > Privacy](#bkmk-settingssection) | | | | +|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [20. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +| [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2016 Server Core See the following table for a summary of the management settings for Windows Server 2016 Server Core. -| Setting | Group Policy | Registry | Command line | -| - | :-: | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [6. Font streaming](#font-streaming) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | ![Check mark](images/checkmark.png) | | | -| [19. Software Protection Platform](#bkmk-spp) | ![Check mark](images/checkmark.png) | | | -| [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [24. Windows Defender](#bkmk-defender) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| Setting | Group Policy | Registry | +| - | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | ![Check mark](images/checkmark.png) | | +| [19. Software Protection Platform](#bkmk-spp) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | | +| [24. Windows Defender](#bkmk-defender) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2016 Nano Server See the following table for a summary of the management settings for Windows Server 2016 Nano Server. -| Setting | Registry | Command line | -| - | :-: | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | | -| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | | +| Setting | Registry | +| - | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2019 See the following table for a summary of the management settings for Windows Server 2019. -| Setting | UI | Group Policy | MDM policy | Registry | Command line | -| - | :-: | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | ![Check mark](images/checkmark.png) | -| [18. Settings > Privacy](#bkmk-settingssection) | | | | | | -|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | | -|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | -|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | | -| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | | -| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | +| Setting | UI | Group Policy | MDM policy | Registry | +| - | :-: | :-: | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | +| [18. Settings > Privacy](#bkmk-settingssection) | | | | | +|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | +|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | +| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ## How to configure each setting From ccf0f2ea9ab2b074c63d6860648d7a374edf96f4 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Fri, 3 May 2019 23:58:37 -0700 Subject: [PATCH 199/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 99e29bee27..a3902d9ea0 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -160,7 +160,7 @@ See the following table for a summary of the management settings for Windows Ser See the following table for a summary of the management settings for Windows Server 2016 Nano Server. | Setting | Registry | -| - | :-: | :-: | +| - | :-: | | [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | | [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | | From bc561e1fe8930093b0ceeca03ca548c70f65e3ff Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:07:13 -0700 Subject: [PATCH 200/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...system-components-to-microsoft-services.md | 100 +++++++++--------- 1 file changed, 50 insertions(+), 50 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index a3902d9ea0..53d253142c 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -59,59 +59,59 @@ The following table lists management options for each setting, beginning with Wi >[!NOTE] >For some settings, MDM policies only partly cover capabilities available through Group Policy. See each setting’s section for more details. -| Setting | UI | Group Policy | MDM policy | Registry | -| - | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [9. License Manager](#bkmk-licmgr) | | | | ![Check mark](images/checkmark.png) | -| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | -| [18. Settings > Privacy](#bkmk-settingssection) | | | | | -|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | -|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| Setting | UI | Group Policy | Registry | +| - | :-: | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [9. License Manager](#bkmk-licmgr) | | | ![Check mark](images/checkmark.png) | +| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | +| [18. Settings > Privacy](#bkmk-settingssection) | | | | +|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| +|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | -| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | -| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ### Settings for Windows Server 2016 with Desktop Experience From 79db69e04c022b5e2529c3914165a208813953be Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:19:24 -0700 Subject: [PATCH 201/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...system-components-to-microsoft-services.md | 102 +++++++++--------- 1 file changed, 51 insertions(+), 51 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 53d253142c..1b00182dc9 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -170,58 +170,58 @@ See the following table for a summary of the management settings for Windows Ser See the following table for a summary of the management settings for Windows Server 2019. -| Setting | UI | Group Policy | MDM policy | Registry | -| - | :-: | :-: | :-: | :-: | -| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| Setting | UI | Group Policy | Registry | +| - | :-: | :-: | :-: | +| [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [2. Cortana and Search](#bkmk-cortana) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | | -| [18. Settings > Privacy](#bkmk-settingssection) | | | | | -|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| ![Check mark](images/checkmark.png) | -|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | -|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | -| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | -| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [4. Device metadata retrieval](#bkmk-devinst) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [5. Find My Device](#find-my-device) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [6. Font streaming](#font-streaming) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [7. Insider Preview builds](#bkmk-previewbuilds) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [8. Internet Explorer](#bkmk-ie) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [11. Mail synchronization](#bkmk-mailsync) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [13. Microsoft Edge](#bkmk-edge) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [15. Offline maps](#bkmk-offlinemaps) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [17. Preinstalled apps](#bkmk-preinstalledapps) | ![Check mark](images/checkmark.png) | | | +| [18. Settings > Privacy](#bkmk-settingssection) | | | | +|     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.2 Location](#bkmk-priv-location) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.3 Camera](#bkmk-priv-camera) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.4 Microphone](#bkmk-priv-microphone) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.5 Notifications](#bkmk-priv-notifications) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png)| +|     [18.6 Speech](#bkmk-priv-speech) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.7 Account info](#bkmk-priv-accounts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.8 Contacts](#bkmk-priv-contacts) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.9 Calendar](#bkmk-priv-calendar) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.10 Call history](#bkmk-priv-callhistory) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.11 Email](#bkmk-priv-email) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.12 Messaging](#bkmk-priv-messaging) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.13 Phone calls](#bkmk-priv-phone-calls) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +|     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | +| [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | | +| [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | ## How to configure each setting From 9d88227d5998fa30f911f3dfeda3a962f8291f1b Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:21:54 -0700 Subject: [PATCH 202/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ndows-operating-system-components-to-microsoft-services.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 1b00182dc9..77904998e6 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -109,7 +109,7 @@ The following table lists management options for each setting, beginning with Wi |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | @@ -219,7 +219,7 @@ See the following table for a summary of the management settings for Windows Ser |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | From 974f967c4580d243267ca923492f1361725dd740 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:25:48 -0700 Subject: [PATCH 203/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ndows-operating-system-components-to-microsoft-services.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 77904998e6..53e0bf5f70 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -137,7 +137,7 @@ See the following table for a summary of the management settings for Windows Ser | [20. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [27.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | | [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2016 Server Core @@ -221,7 +221,7 @@ See the following table for a summary of the management settings for Windows Ser | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [26.1 Apps for websites](#bkmk-apps-for-websites) | | | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ## How to configure each setting From bcd69a998272ade26e8d20e1447c40171e9f0803 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:27:24 -0700 Subject: [PATCH 204/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 53e0bf5f70..37c46d6aaf 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -446,7 +446,7 @@ To turn off Insider Preview builds for Windows 10: ### 8. Internet Explorer > [!NOTE] -> The following Group Policies and Registry Keys are for user interactive scenarios rather then the typical idle traffic scenario. Find the Internet Explorer Group Policy objects under **Computer Configuration > Administrative Templates > Windows Components > Internet Explorer** and make these settings: +> The following Group Policies and Registry Keys are for user interactive scenarios rather then the typical idle traffic scenario. Find the Internet Explorer Group Policy objects under **Computer Configuration > Administrative Templates > Windows Components > Internet Explorer** and make these settings: | Policy | Description | |------------------------------------------------------|-----------------------------------------------------------------------------------------------------| From 81600f747eb272afa1dcc50a2e1e77e9ae1def95 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Sat, 4 May 2019 00:41:15 -0700 Subject: [PATCH 205/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...system-components-to-microsoft-services.md | 290 +----------------- 1 file changed, 1 insertion(+), 289 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 37c46d6aaf..72bb0cefbe 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -325,14 +325,6 @@ You can also apply the Group Policies using the following registry keys: If your organization tests network traffic, do not use a network proxy as Windows Firewall does not block proxy traffic. Instead, use a network traffic analyzer. Based on your needs, there are many network traffic analyzers available at no cost. -### 2.2 Cortana and Search MDM policies - -For Windows 10 only, the following Cortana MDM policies are available in the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx). - -| Policy | Description | -|------------------------------------------------------|-----------------------------------------------------------------------------------------------------| -| Experience/AllowCortana | Choose whether to let Cortana install and run on the device. | -| Search/AllowSearchToUseLocation | Choose whether Cortana and Search can provide location-aware search results.
Default: Allowed| ### 3. Date & Time @@ -363,9 +355,6 @@ To prevent Windows from retrieving device metadata from the Internet: - Create a new REG_DWORD registry setting named **PreventDeviceMetadataFromNetwork** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Device Metadata** and set it to 1 (one). - -or - - -- Apply the DeviceInstallation/PreventDeviceMetadataFromNetwork MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-deviceinstallation#deviceinstallation-preventdevicemetadatafromnetwork). ### 5. Find My Device @@ -393,13 +382,6 @@ If you're running Windows 10, version 1607, Windows Server 2016, or later: - Create a new REG_DWORD registry setting **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\EnableFontProviders** to **0 (zero)**. - -or- - -- In Windows 10, version 1703, you can apply the System/AllowFontProviders MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) where: - - - **False**. Font streaming is Disabled. - - - **True**. Font streaming is Enabled. > [!NOTE] > After you apply this policy, you must restart the device for it to take effect. @@ -433,15 +415,6 @@ To turn off Insider Preview builds for Windows 10: - Create a new REG_DWORD registry setting named **AllowBuildPreview** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\PreviewBuilds** with a **value of 0 (zero)** - -or- - -- Apply the System/AllowBuildPreview MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) where: - - - **0**. Users cannot make their devices available for downloading and installing preview software. - - - **1**. Users can make their devices available for downloading and installing preview software. - - - **2**. (default) Not configured. Users can make their devices available for download and installing preview software. ### 8. Internet Explorer @@ -562,9 +535,6 @@ To turn off mail synchronization for Microsoft Accounts that are configured on a - Remove any Microsoft Accounts from the Mail app. - -or- - -- Apply the Accounts/AllowMicrosoftAccountConnection MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) where 0 is not allowed and 1 is allowed. This does not apply to Microsoft Accounts that have already been configured on the device. To turn off the Windows Mail app: @@ -583,8 +553,6 @@ To prevent communication to the Microsoft Account cloud authentication service. To disable the Microsoft Account Sign-In Assistant: -- Apply the Accounts/AllowMicrosoftAccountSignInAssistant MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) where 0 is turned off and 1 is turned on. - - Change the **Start** REG_DWORD registry setting in **HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\wlidsvc** to a value of **4**. @@ -627,21 +595,6 @@ Alternatively, you can configure the these Registry keys as described: | Choose whether employees can configure Compatibility View. | HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\MicrosoftEdge\\BrowserEmulation
REG_DWORD: MSCompatibilityMode
Value: **0**| -### 13.2 Microsoft Edge MDM policies - -The following Microsoft Edge MDM policies are available in the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx). - -| Policy | Description | -|------------------------------------------------------|-----------------------------------------------------------------------------------------------------| -| Browser/AllowAutoFill | Choose whether employees can use autofill on websites.
**Set to: Not Allowed** | -| Browser/AllowDoNotTrack | Choose whether employees can send Do Not Track headers.
**Set to: Allowed** | -| Browser/AllowMicrosoftCompatbilityList | Specify the Microsoft compatibility list in Microsoft Edge.
**Set to: Not Allowed** | -| Browser/AllowPasswordManager | Choose whether employees can save passwords locally on their devices.
**Set to: Not Allowed** | -| Browser/AllowSearchSuggestionsinAddressBar | Choose whether the Address Bar shows search suggestions..
**Set to: Not Allowed** | -| Browser/AllowSmartScreen | Choose whether SmartScreen is turned on or off.
**Set to: Not Allowed** | -| Browser/FirstRunURL | Choose the home page for Microsoft Edge on Windows Mobile 10.
**Set to:** blank | - - For a complete list of the Microsoft Edge policies, see [Available policies for Microsoft Edge](https://docs.microsoft.com/microsoft-edge/deploy/available-policies). ### 14. Network Connection Status Indicator @@ -654,7 +607,6 @@ You can turn off NCSI by doing one of the following: - **Enable** the Group Policy: **Computer Configuration** > **Administrative Templates** > **System** > **Internet Communication Management** > **Internet Communication Settings** > **Turn off Windows Network Connectivity Status Indicator active tests** -- In Windows 10, version 1703 and later, apply the Connectivity/DisallowNetworkConnectivityActiveTests MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-connectivity#connectivity-disallownetworkconnectivityactivetests) with a value of 1. > [!NOTE] > After you apply this policy, you must restart the device for the policy setting to take effect. @@ -673,10 +625,6 @@ You can turn off the ability to download and update offline maps. - Create a REG_DWORD registry setting named **AutoDownloadAndUpdateMapData** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Maps** with a **value of 0 (zero)**. - -or- - -- In Windows 10, version 1607 and later, apply the Maps/EnableOfflineMapsAutoUpdate MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-maps#maps-enableofflinemapsautoupdate) with a **value of 0**. - -and- - In Windows 10, version 1607 and later, **Enable** the Group Policy: **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Maps** > **Turn off unsolicited network traffic on the Offline Maps settings page** @@ -703,10 +651,6 @@ To turn off OneDrive in your organization: - Create a REG_DWORD registry setting named **PreventNetworkTrafficPreUserSignIn** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OneDrive** with a **value of 1 (one)** --or- - -- Set the System/DisableOneDriveFileSync MDM policy from the [Policy CSP](https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-system#system-disableonedrivefilesync) to True (value 1) to disable OneDrive File Sync. - ### 17. Preinstalled apps @@ -951,14 +895,6 @@ To turn off **Send Microsoft info about how I write to help us improve typing an - Turn off the feature in the UI. - -or- - -- Apply the TextInput/AllowLinguisticDataCollection MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) where: - - - **0**. Not allowed - - - **1**. Allowed (default) - To turn off **Let websites provide locally relevant content by accessing my language list**: - Turn off the feature in the UI. @@ -999,18 +935,6 @@ To turn off **Location for this device**: - Create a REG_DWORD registry setting named **LetAppsAccessLocation** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. - -or- - -- Apply the System/AllowLocation MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx), where: - - - **0**. Turned off and the employee can't turn it back on. - - - **1**. Turned on, but lets the employee choose whether to use it. (default) - - - **2**. Turned on and the employee can't turn it off. - - > [!NOTE] - > You can also set this MDM policy in System Center Configuration Manager using the [WMI Bridge Provider](https://msdn.microsoft.com/library/dn905224.aspx). To turn off **Location**: @@ -1053,17 +977,6 @@ To turn off **Let apps use my camera**: - Create a REG_DWORD registry setting named **LetAppsAccessCamera** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). - -or- - -- Apply the Camera/AllowCamera MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx), where: - - - **0**. Apps can't use the camera. - - - **1**. Apps can use the camera. - - > [!NOTE] - > You can also set this MDM policy in System Center Configuration Manager using the [WMI Bridge Provider](https://msdn.microsoft.com/library/dn905224.aspx). - To turn off **Choose apps that can use your camera**: @@ -1085,14 +998,6 @@ To turn off **Let apps use my microphone**: -or- -- Apply the Privacy/LetAppsAccessMicrophone MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessmicrophone), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessMicrophone** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two) To turn off **Choose apps that can use your microphone**: @@ -1101,9 +1006,6 @@ To turn off **Choose apps that can use your microphone**: ### 18.5 Notifications ->[!IMPORTANT] ->Disabling notifications will also disable the ability to manage the device through MDM. If you are using an MDM solution, make sure cloud notifications are enabled through one of the options below. - To turn off notifications network usage: - Apply the Group Policy: **Computer Configuration** > **Administrative Templates** > **Start Menu and Taskbar** > **Notifications** > **Turn off Notifications network usage** @@ -1114,13 +1016,6 @@ To turn off notifications network usage: - Create a REG_DWORD registry setting named **NoCloudApplicationNotification** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\PushNotifications** with a value of 1 (one) - -or- - - -- Apply the Notifications/DisallowCloudNotification MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-notifications#notifications-disallowcloudnotification), where: - - - **0**. WNS notifications allowed - - **1**. No WNS notifications allowed In the **Notifications** area, you can also choose which apps have access to notifications. @@ -1136,14 +1031,6 @@ To turn off **Let apps access my notifications**: -or- -- Apply the Privacy/LetAppsAccessNotifications MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessnotifications), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessNotifications** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two) ### 18.6 Speech @@ -1160,10 +1047,6 @@ To turn off streaming audio to Microsoft Speech services, -or- -- Set the Privacy\AllowInputPersonalization MDM Policy from the Policy CSP to **0 - Not allowed** - - -or- - - Create a REG_DWORD registry setting named **HasAccepted** in **HKEY_CURRENT_USER\\Software\\Microsoft\\Speech_OneCore\\Settings\\OnlineSpeechPrivacy** with a **value of 0 (zero)** ### 18.7 Account info @@ -1182,14 +1065,6 @@ To turn off **Let apps access my name, picture, and other account info**: -or- -- Apply the Privacy/LetAppsAccessAccountInfo MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessaccountinfo), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessAccountInfo** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). @@ -1214,14 +1089,6 @@ To turn off **Choose apps that can access contacts**: -or- -- Apply the Privacy/LetAppsAccessContacts MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccesscontacts), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessContacts** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). ### 18.9 Calendar @@ -1240,14 +1107,6 @@ To turn off **Let apps access my calendar**: -or- -- Apply the Privacy/LetAppsAccessCalendar MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccesscalendar), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessCalendar** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). To turn off **Choose apps that can access calendar**: @@ -1270,14 +1129,6 @@ To turn off **Let apps access my call history**: -or- - - Apply the Privacy/LetAppsAccessCallHistory MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccesscallhistory), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessCallHistory** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). ### 18.11 Email @@ -1296,14 +1147,6 @@ To turn off **Let apps access and send email**: -or- - - Apply the Privacy/LetAppsAccessEmail MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessemail), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessEmail** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). ### 18.12 Messaging @@ -1322,14 +1165,6 @@ To turn off **Let apps read or send messages (text or MMS)**: -or- -- Apply the Privacy/LetAppsAccessMessaging MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessmessaging), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessMessaging** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). To turn off **Choose apps that can read or send messages**: @@ -1362,14 +1197,6 @@ To turn off **Let apps make phone calls**: -or- -- Apply the Privacy/LetAppsAccessPhone MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-privacy#privacy-letappsaccessphone), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessPhone** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). @@ -1393,14 +1220,6 @@ To turn off **Let apps control radios**: -or- -- Apply the Privacy/LetAppsAccessRadios MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessradios), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsAccessRadios** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a value of 2 (two). @@ -1422,10 +1241,6 @@ To turn off **Let apps automatically share and sync info with wireless devices t -or- -- Set the Privacy/LetAppsSyncWithDevices MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappssyncwithdevices) to **2**. Force deny - - -or- - - Create a REG_DWORD registry setting named **LetAppsSyncWithDevices** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. To turn off **Let your apps use your trusted devices (hardware you've already connected, or comes with your PC, tablet, or phone)**: @@ -1440,14 +1255,6 @@ To turn off **Let your apps use your trusted devices (hardware you've already co - Create a REG_DWORD registry setting named **LetAppsAccessTrustedDevices** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. - -or- - -- Apply the **Privacy/LetAppsAccessTrustedDevices** MDM policy from the [Policy CSP](/windows/client-management/mdm/policy-csp-privacy.md#privacy-letappsaccesstrusteddevices -), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny ### 18.16 Feedback & diagnostics @@ -1502,19 +1309,7 @@ To change the level of diagnostic and usage data sent when you **Send your devic > [!NOTE] > If the **Security** option is configured by using Group Policy or the Registry, the value will not be reflected in the UI. The **Security** option is only available in Windows 10 Enterprise edition. - - -or- - -- Apply the System/AllowTelemetry MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx), where: - - - **0**. Maps to the **Security** level. - - - **1**. Maps to the **Basic** level. - - - **2**. Maps to the **Enhanced** level. - - - **3**. Maps to the **Full** level. - + To turn off tailored experiences with relevant tips and recommendations by using your diagnostics data: @@ -1557,9 +1352,6 @@ To turn off **Let apps run in the background**: - Create a REG_DWORD registry setting named **LetAppsRunInBackground** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)** - -or- - -- Set the Privacy/LetAppsRunInBackground MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessruninbackground) to **2 Force Deny**. > [!NOTE] > Some apps, including Cortana and Search, might not function as expected if you set **Let apps run in the background** to **Force Deny**. @@ -1580,14 +1372,6 @@ To turn off **Let Windows and your apps use your motion data and collect motion - Create a REG_DWORD registry setting named **LetAppsAccessMotion** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. - -or- - -- Apply the Privacy/LetAppsAccessMotion MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccessmotion), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny - ### 18.19 Tasks @@ -1605,13 +1389,6 @@ To turn this off: - Create a REG_DWORD registry setting named **LetAppsAccessTasks** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. - -or- - -- Apply the Privacy/LetAppsAccessTasks MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsaccesstasks), where: - - - **0**. User in control - - **1**. Force allow - - **2**. Force deny ### 18.20 App Diagnostics @@ -1629,10 +1406,6 @@ To turn this off: - Create a REG_DWORD registry setting named **LetAppsGetDiagnosticInfo** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\AppPrivacy** with a **value of 2 (two)**. - -or- - -- Set the Privacy/LetAppsGetDiagnosticInfo MDM policy from the [Policy CSP](https://msdn.microsoft.com/windows/hardware/commercialize/customize/mdm/policy-configuration-service-provider#privacy-letappsgetdiagnosticinfo) to **2**. Force deny - ### 18.21 Inking & Typing @@ -1646,11 +1419,6 @@ To turn off Inking & Typing data collection (note: there is no Group Policy for - Set **RestrictImplicitTextCollection** registry REG_DWORD setting in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\InputPersonalization** to a **value of 1 (one)** - -or- - - - Set the Privacy\AllowInputPersonalization MDM Policy from the Policy CSP. - [TextInput/AllowLinguisticDataCollection](https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-textinput#textinput-allowlinguisticdatacollection) to **0** (not allowed). This policy setting controls the ability to send inking and typing data to Microsoft to improve the language recognition and suggestion capabilities of apps and services running on Windows. - If you're running at least Windows 10, version 1703, you can turn off updates to the speech recognition and speech synthesis models: @@ -1660,10 +1428,6 @@ If you're running at least Windows 10, version 1703, you can turn off updates to - Create a REG_DWORD registry setting named **AllowSpeechModelUpdate** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Speech** with a **value of 0 (zero)** - -or- - - - Set the Speech/AllowSpeechModelUpdate MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962(v=vs.85).aspx#Speech_AllowSpeechModelUpdate) to **0** - > [!NOTE] > Releases 1803 and earlier support **Speech, Inking, & Typing** as a combined settings area. For customizing those setting please follow the below instructions. For 1809 and above **Speech** and **Inking & Typing** are separate settings pages, please see the specific section (18.6 Speech or 18.21 Inking and Typing) above for those areas. @@ -1702,10 +1466,6 @@ In the **Speech, Inking, & Typing** area, you can let Windows and Cortana better -or- - - Apply the Licensing/DisallowKMSClientOnlineAVSValidation MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) and **set the value to 1 (Enabled)**. - - -or- - - Create a REG_DWORD registry setting named **NoGenTicket** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\CurrentVersion\\Software Protection Platform** with a **value of 1 (one)**. **For Windows Server 2019 or later:** @@ -1749,11 +1509,6 @@ You can control if your settings are synchronized: - Create a REG_DWORD registry setting named **DisableSettingSync** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\SettingSync** with a value of 2 (two) and another named **DisableSettingSyncUserOverride** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\SettingSync** with a value of 1 (one). - -or- - -- Apply the Experience/AllowSyncMySettings MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) and **set the value to 0 (not allowed)**. - - To turn off Messaging cloud sync: - Note: There is no Group Policy corresponding to this registry key. @@ -1812,10 +1567,6 @@ You can disconnect from the Microsoft Antimalware Protection Service. - Delete the registry setting **named** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Updates**. --OR- - -- For Windows 10 only, apply the Defender/AllowClouldProtection MDM policy from the [Defender CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx). - You can stop sending file samples back to Microsoft. @@ -1823,10 +1574,6 @@ You can stop sending file samples back to Microsoft. -or- -- For Windows 10 only, apply the Defender/SubmitSamplesConsent MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-defender) to **2 (two) for Never Send**. - - -or- - - Use the registry to set the REG_DWORD value **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows Defender\\Spynet\\SubmitSamplesConsent** to **2 (two) for Never Send**. @@ -1893,10 +1640,6 @@ To disable Windows Defender Smartscreen: - Create a SZ registry setting named **ConfigureAppInstallControl** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\SmartScreen** with a value of **Anywhere**. --OR- - -- Set the Browser/AllowSmartScreen MDM policy from the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx) to **0 (turned Off)**. - ### 25. Windows Spotlight @@ -1911,10 +1654,6 @@ If you're running Windows 10, version 1607 or later, you need to: -or- -- For Windows 10 only, apply the Experience/AllowWindowsSpotlight MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-experience), with a value of 0 (zero). - - -or- - - Create a new REG_DWORD registry setting named **DisableWindowsSpotlightFeatures** in **HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Windows\\CloudContent** with a value of 1 (one). @@ -2056,18 +1795,6 @@ You can find the Delivery Optimization Group Policy objects under **Computer Con - Create a new REG_DWORD registry setting named **DODownloadMode** in **HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\DeliveryOptimization** to a value of **100 (one hundred)**. -### 27.4 Delivery Optimization MDM policies - -The following Delivery Optimization MDM policies are available in the [Policy CSP](https://msdn.microsoft.com/library/windows/hardware/dn904962.aspx). - -| MDM Policy | Description | -|---------------------------|-----------------------------------------------------------------------------------------------------| -| DeliveryOptimization/DODownloadMode | Lets you choose where Delivery Optimization gets or sends updates and apps, including
  • 0. Turns off Delivery Optimization.

  • 1. Gets or sends updates and apps to PCs on the same NAT only.

  • 2. Gets or sends updates and apps to PCs on the same local network domain.

  • 3. Gets or sends updates and apps to PCs on the Internet.

  • 99. Simple download mode with no peering.

  • 100. Use BITS instead of Windows Update Delivery Optimization.

| -| DeliveryOptimization/DOGroupID | Lets you provide a Group ID that limits which PCs can share apps and updates.
**Note** This ID must be a GUID.| -| DeliveryOptimization/DOMaxCacheAge | Lets you specify the maximum time (in seconds) that a file is held in the Delivery Optimization cache.
The default value is 259200 seconds (3 days).| -| DeliveryOptimization/DOMaxCacheSize | Lets you specify the maximum cache size as a percentage of disk size.
The default value is 20, which represents 20% of the disk.| -| DeliveryOptimization/DOMaxUploadBandwidth | Lets you specify the maximum upload bandwidth (in KB/second) that a device uses across all concurrent upload activity.
The default value is 0, which means unlimited possible bandwidth.| - For more info about Delivery Optimization in general, see [Windows Update Delivery Optimization: FAQ](https://go.microsoft.com/fwlink/p/?LinkId=730684). @@ -2118,21 +1845,6 @@ You can turn off automatic updates by doing one of the following. This is not re - Add a REG_DWORD value named **AutoDownload** to **HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\WindowsStore\\WindowsUpdate** and set the value to 5. - -or- - -- For Windows 10 only, apply the Update/AllowAutoUpdate MDM policy from the [Policy CSP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-update), where: - - - **0**. Notify the user before downloading the update. - - - **1**. Auto install the update and then notify the user to schedule a device restart. - - - **2** (default). Auto install and restart. - - - **3**. Auto install and restart at a specified time. - - - **4**. Auto install and restart without end-user control. - - - **5**. Turn off automatic updates. For China releases of Windows 10 there is one additional Regkey to be set to prevent traffic: From 79cc2eea39f66affaf700d8efa707b82b5d8eff7 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Sat, 4 May 2019 17:21:18 +0500 Subject: [PATCH 206/737] update start-layout-troubleshoot.md --- windows/configuration/start-layout-troubleshoot.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/start-layout-troubleshoot.md b/windows/configuration/start-layout-troubleshoot.md index c29f399bba..bab10f57b6 100644 --- a/windows/configuration/start-layout-troubleshoot.md +++ b/windows/configuration/start-layout-troubleshoot.md @@ -280,7 +280,7 @@ Additionally, users may see blank tiles if logon was attempted without network c ### Symptom: Start Menu issues with Tile Data Layer corruption -**Cause**: Windows 10, version 1507 through the release of version 1607 uses a database for the Tile image information. This is called the Tile Data Layer database. +**Cause**: Windows 10, version 1507 through the release of version 1607 uses a database for the Tile image information. This is called the Tile Data Layer database (The feature was deprecated in [Windows 10 1703](https://support.microsoft.com/help/4014193/features-that-are-removed-or-deprecated-in-windows-10-creators-update)). **Resolution** There are steps you can take to fix the icons, first is to confirm that is the issue that needs to be addressed. From a37a05a2f0c48d518a7e5708b3f4f798f823b1b0 Mon Sep 17 00:00:00 2001 From: VLG17 <41186174+VLG17@users.noreply.github.com> Date: Mon, 6 May 2019 12:21:36 +0300 Subject: [PATCH 207/737] updated info about NDES server name https://github.com/MicrosoftDocs/windows-itpro-docs/issues/2450 --- .../hello-for-business/hello-hybrid-aadj-sso-cert.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md index b571ee817f..a5d222346e 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md @@ -425,7 +425,7 @@ Sign-in a workstation with access equivalent to a _domain user_. 3. Under **MANAGE**, click **Application proxy**. 4. Click **Configure an app**. 5. Under **Basic Settings** next to **Name**, type **WHFB NDES 01**. Choose a name that correlates this Azure AD Application Proxy setting with the on-premises NDES server. Each NDES server must have its own Azure AD Application Proxy as two NDES servers cannot share the same internal URL. -6. Next to **Internal Url**, type the internal fully qualified DNS name of the NDES server associated with this Azure AD Application Proxy. For example, https://ndes.corp.mstepdemo.net). This must match the internal DNS name of the NDES server and ensure you prefix the Url with **https**. +6. Next to **Internal Url**, type the internal fully qualified DNS name of the NDES server associated with this Azure AD Application Proxy. For example, https://ndes.corp.mstepdemo.net). This must match the primary hostname (AD Computer Account name) of the NDES server and ensure you prefix the Url with **https**. 7. Under **Internal Url**, select **https://** from the first list. In the text box next to **https://**, type the hostname you want to use as your external hostname for the Azure AD Application Proxy. In the list next to the hostname you typed, select a DNS suffix you want to use externally for the Azure AD Application Proxy. It is recommended to use the default, -[tenantName].msapproxy.net where **[tenantName]** is your current Azure Active Directory tenant name (-mstephendemo.msappproxy.net). ![Azure NDES Application Proxy Configuration](images/aadjcert/azureconsole-appproxyconfig.png) 8. Select **Passthrough** from the **Pre Authentication** list. From 3d6346be58ff3183923271ae7c7646c34e539fda Mon Sep 17 00:00:00 2001 From: VLG17 <41186174+VLG17@users.noreply.github.com> Date: Mon, 6 May 2019 12:49:49 +0300 Subject: [PATCH 208/737] removed obsolete information https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3085 --- ...policy-csp-localpoliciessecurityoptions.md | 131 ------------------ 1 file changed, 131 deletions(-) diff --git a/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions.md b/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions.md index b1594d5d38..dc9a2c4e0c 100644 --- a/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions.md +++ b/windows/client-management/mdm/policy-csp-localpoliciessecurityoptions.md @@ -24,12 +24,6 @@ ms.date: 06/26/2018
LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
-
- LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus -
-
- LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus -
LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
@@ -255,131 +249,6 @@ The following list shows the supported values:
- -**LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus** - - -

Attack surface reduction
- - - - - - - - - - - - - - - - - - -
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark3check mark3check mark3check mark3cross markcross mark
- - - -[Scope](./policy-configuration-service-provider.md#policy-scope): - -> [!div class = "checklist"] -> * Device - -
- - - -This security setting determines whether the local Administrator account is enabled or disabled. - -If you try to reenable the Administrator account after it has been disabled, and if the current Administrator password does not meet the password requirements, you cannot reenable the account. In this case, an alternative member of the Administrators group must reset the password on the Administrator account. For information about how to reset a password, see To reset a password. -Disabling the Administrator account can become a maintenance issue under certain circumstances. - -Under Safe Mode boot, the disabled Administrator account will only be enabled if the machine is non-domain joined and there are no other local active administrator accounts. If the computer is domain joined the disabled administrator will not be enabled. - -Default: Disabled. - -Value type is integer. Supported operations are Add, Get, Replace, and Delete. - - - -GP Info: -- GP English name: *Accounts: Administrator account status* -- GP path: *Windows Settings/Security Settings/Local Policies/Security Options* - - - -Valid values: -- 0 - local Administrator account is disabled -- 1 - local Administrator account is enabled - - - - -
- - -**LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus** - - - - - - - - - - - - - - - - - - - - - -
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark3check mark3check mark3check mark3cross markcross mark
- - - -[Scope](./policy-configuration-service-provider.md#policy-scope): - -> [!div class = "checklist"] -> * Device - -
- - - -This security setting determines if the Guest account is enabled or disabled. - -Default: Disabled. - -Note: If the Guest account is disabled and the security option Network Access: Sharing and Security Model for local accounts is set to Guest Only, network logons, such as those performed by the Microsoft Network Server (SMB Service), will fail. - -Value type is integer. Supported operations are Add, Get, Replace, and Delete. - - - -GP Info: -- GP English name: *Accounts: Guest account status* -- GP path: *Windows Settings/Security Settings/Local Policies/Security Options* - - - -Valid values: -- 0 - local Guest account is disabled -- 1 - local Guest account is enabled - - - - -
- **LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly** From a214762af7e9a4335c0dd463fa450c40666d625a Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 11:24:29 -0700 Subject: [PATCH 209/737] added new topic --- .../TOC.md | 1 + ...win32-apps-on-windows-10-s-mode-devices.md | 47 +++++++++++++++++++ 2 files changed, 48 insertions(+) create mode 100644 windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md diff --git a/windows/security/threat-protection/windows-defender-application-control/TOC.md b/windows/security/threat-protection/windows-defender-application-control/TOC.md index 8b71416a15..ee04e5c824 100644 --- a/windows/security/threat-protection/windows-defender-application-control/TOC.md +++ b/windows/security/threat-protection/windows-defender-application-control/TOC.md @@ -31,6 +31,7 @@ ### [Use a Windows Defender Application Control policy to control specific plug-ins, add-ins, and modules](use-windows-defender-application-control-policy-to-control-specific-plug-ins-add-ins-and-modules.md) ### [Use signed policies to protect Windows Defender Application Control against tampering](use-signed-policies-to-protect-windows-defender-application-control-against-tampering.md) #### [Signing WDAC policies with SignTool.exe](signing-policies-with-signtool.md) +### [Sideload Win32 apps on S mode](sideloading-win32-apps-on-windows-10-s-mode-devices.md) ### [Disable WDAC policies](disable-windows-defender-application-control-policies.md) ### [Device Guard and AppLocker](windows-defender-device-guard-and-applocker.md) diff --git a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md new file mode 100644 index 0000000000..c9842bdb33 --- /dev/null +++ b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md @@ -0,0 +1,47 @@ +--- +title: Sideloading Win32 apps on Windows 10 S mode devices (Windows 10) +description: Windows Defender Application Control restricts which applications users are allowed to run and the code that runs in the system core. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.localizationpriority: medium +author: jsuther1974 +ms.date: 05/06/2018 +--- + +# Sideloading Win32 apps on Windows 10 S mode devices + +**Applies to:** + +- Windows 10 +- Windows Server 2016 + +Windows 10 S mode is a locked-down system that only runs Store apps. +Although it provides tight security and thereby promises reduced management, its application control restrictions make it difficult for some to adopt it widely. +Sideloading makes S mode a more viable proposition for enterprise and education workloads by allowing critical Desktop apps in addition to Store apps. + +## Process Overview + +To allow Win32 apps to run on a Windows 10 device in S mode, admins must ‘unlock’ the device so exceptions can be made to S mode policy, and then upload a corresponding signed catalog for each app to Intune. Here are the steps: + +1. Unlock S mode devices through Intune + - Admin uses the Device Guard Signing Service (DGSS) in the Microsoft Store for Business to generate a root certificate for the organization and upload it to Intune + - Intune will ensure this certificate is included in a device’s unlock token from OCDUS, and any app catalogs which are signed with it will be able to run on the unlocked device +2. Create a supplemental policy to allow Win32 apps + - Admin uses Windows Defender Application Control tools to create a supplemental policy + - Admin uses DGSS to sign their supplemental policy + - Admin uploads signed supplemental policy to Intune +3. Allow Win32 app catalogs through Intune + - Admin creates catalog files (1 for every app) and signs them using DGSS or other certificate infrastructure + - Admin submits the signed catalog to Intune + - Intune applies the signed catalog to unlocked S mode device using Sidecar + +## [Admin] Setting up Business Store to use DGSS + +1. In the Azure portal, create a new resource of type Azure Active Directory, then create an associated global admin user. +2. Log in to the Microsoft Store for Business as the global admin then go to Organization > Private Store and accept +• This will automatically generate a root certificate for the organization +3. To download a root cert or upload policies/catalogs to sign, navigate to Manage > Settings > Devices +• Note: you can only upload .bin and .cat files +[Admin] Creating and Signing a Supplemental Policy From a66303016109175aa7f35a1394aa7175ca8b0b9a Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 11:48:20 -0700 Subject: [PATCH 210/737] added new topic --- ...win32-apps-on-windows-10-s-mode-devices.md | 54 ++++++++++++++++--- 1 file changed, 48 insertions(+), 6 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md index c9842bdb33..60b8c97f46 100644 --- a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md @@ -37,11 +37,53 @@ To allow Win32 apps to run on a Windows 10 device in S mode, admins must ‘unlo - Admin submits the signed catalog to Intune - Intune applies the signed catalog to unlocked S mode device using Sidecar -## [Admin] Setting up Business Store to use DGSS +## Setting up Business Store to use DGSS 1. In the Azure portal, create a new resource of type Azure Active Directory, then create an associated global admin user. -2. Log in to the Microsoft Store for Business as the global admin then go to Organization > Private Store and accept -• This will automatically generate a root certificate for the organization -3. To download a root cert or upload policies/catalogs to sign, navigate to Manage > Settings > Devices -• Note: you can only upload .bin and .cat files -[Admin] Creating and Signing a Supplemental Policy +2. Log in to the Microsoft Store for Business as the global admin then go to **Organization** > **Private Store** and accept. + This will automatically generate a root certificate for the organization. +3. To download a root cert or upload policies/catalogs to sign, navigate to **Manage** > **Settings** > **Devices**. + Note: you can only upload .bin and .cat files. + +## Creating and Signing a Supplemental Policy + +1. Create new base policy using [New-CIPolicy](https://docs.microsoft.com/powershell/module/configci/new-cipolicy?view=win10-ps) + ```powershell + New-CIPolicy -Level PcaCertificate -UserPEs -ScanPath -MultiplePolicyFormat 3> -FilePath + ``` +2. Change it to a supplemental policy using [Set-CIPolicyIdInfo](https://docs.microsoft.com/powershell/module/configci/set-cipolicyidinfo?view=win10-ps) + ```powershell + Set-CIPolicyIdInfo -BasePolicyToSupplementPath -SupplementsBasePolicyID 5951A96A-E0B5-4D3D-8FB8-3E5B61030784 -FilePath + ``` + Note: ‘5951A96A-E0B5-4D3D-8FB8-3E5B61030784' is the S-mode Base Policy ID. +3. Put policy in enforce mode using [Set-RuleOption](https://docs.microsoft.com/powershell/module/configci/set-ruleoption?view=win10-ps) + ```powershell + Set-RuleOption -FilePath -Option 3 –Delete + ``` + This deletes the ‘audit mode’ qualifier. +4. Convert to .bin using [ConvertFrom-CIPolicy](https://docs.microsoft.com/powershell/module/configci/convertfrom-cipolicy?view=win10-ps) + ```powershell + ConvertFrom-CIPolicy -XmlFilePath -BinaryFilePath + ``` + Note: PolicyID can be found by inspecting the Supplemental Policy XML. Convert to .bin to sign with DGSS (recommended) or .cip to sign locally. +5. To sign using the recommended DGSS option through the Microsoft Store for Business, click **Manage** > **Settings** > **Devices** > **Upload** > **Sign**. + To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md) + +## Creating and Signing an App Catalog +An admin must generate an app catalog for every deployed app: +1. Use Package Inspector to [create a catalog](https://docs.microsoft.com/microsoft-store/add-unsigned-app-to-code-integrity-policy#a-href-idcreate-catalog-filesacreate-catalog-files-for-your-unsigned-app) + - Start Package Inspector to scan the installer: + ```console + PackageInspector.exe start C: -path + ``` + - Open app installer + - Stop Package Inspector: + ```console + PackageInspector.exe stop C: -Name -cdfpath + ``` +2. To sign using the recommended DGSS option through the Microsoft Store for Business, click **Manage** > **Settings** > **Devices** > **Upload** > **Sign**. + To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md) + +## User experience + +Users will either have apps pushed directly to their devices by their admins, or they can download apps that their admins have made available through Company Portal From 23ac84be9b08141ee17b575da3bc986f7c47a65f Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 11:50:30 -0700 Subject: [PATCH 211/737] edits --- ...sideloading-win32-apps-on-windows-10-s-mode-devices.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md index 60b8c97f46..249ce3ddce 100644 --- a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md @@ -67,7 +67,7 @@ To allow Win32 apps to run on a Windows 10 device in S mode, admins must ‘unlo ``` Note: PolicyID can be found by inspecting the Supplemental Policy XML. Convert to .bin to sign with DGSS (recommended) or .cip to sign locally. 5. To sign using the recommended DGSS option through the Microsoft Store for Business, click **Manage** > **Settings** > **Devices** > **Upload** > **Sign**. - To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md) + To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md). ## Creating and Signing an App Catalog An admin must generate an app catalog for every deployed app: @@ -76,14 +76,14 @@ An admin must generate an app catalog for every deployed app: ```console PackageInspector.exe start C: -path ``` - - Open app installer + - Open the app installer. - Stop Package Inspector: ```console PackageInspector.exe stop C: -Name -cdfpath ``` 2. To sign using the recommended DGSS option through the Microsoft Store for Business, click **Manage** > **Settings** > **Devices** > **Upload** > **Sign**. - To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md) + To sign locally using signtool, see [Signing policies with signtool](signing-policies-with-signtool.md). ## User experience -Users will either have apps pushed directly to their devices by their admins, or they can download apps that their admins have made available through Company Portal +Users will either have apps pushed directly to their devices by their admins, or they can download apps that their admins have made available through the Company Portal. From ec802e324eb6f1d8caf26495f7a7c1d1e9be267a Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 12:08:33 -0700 Subject: [PATCH 212/737] adding path-based rules --- .../select-types-of-rules-to-create.md | 33 +++++++++++++++++-- 1 file changed, 30 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 1a987c35e7..22294479af 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -23,8 +23,6 @@ Windows Defender Application Control (WDAC) provides control over a computer run A common system imaging practice in today’s IT organization is to establish a “golden” image as a reference for what an ideal system should look like, and then use that image to clone additional company assets. WDAC policies follow a similar methodology, that begins with the establishment of a golden computer. As with imaging, you can have multiple golden computers based on model, department, application set, and so on. Although the thought process around the creation of WDAC policies is similar to imaging, these policies should be maintained independently. Assess the necessity of additional WDAC policies based on what should be allowed to be installed and run and for whom. For more details on doing this assessment, see the [WDAC Design Guide](windows-defender-application-control-design-guide.md). -> **Note**  Each computer can have only **one** WDAC policy at a time. Whichever way you deploy this policy, it is renamed to SIPolicy.p7b and copied to **C:\\Windows\\System32\\CodeIntegrity** and, for UEFI computers, **<EFI System Partition>\\Microsoft\\Boot**. Keep this in mind when you create your WDAC policies. - Optionally, WDAC can align with your software catalog as well as any IT department–approved applications. One straightforward method to implement WDAC is to use existing images to create one master WDAC policy. You do so by creating a WDAC policy from each image, and then by merging the policies. This way, what is installed on all of those images will be allowed to run, if the applications are installed on a computer based on a different image. Alternatively, you may choose to create a base applications policy and add policies based on the computer’s role or department. Organizations have a choice of how their policies are created, merged or serviced, and managed. If you plan to use an internal CA to sign catalog files or WDAC policies, see the steps in [Optional: Create a code signing certificate for Windows Defender Application Control](create-code-signing-cert-for-windows-defender-application-control.md). @@ -103,4 +101,33 @@ To create the WDAC policy, they build a reference server on their standard hardw As part of normal operations, they will eventually install software updates, or perhaps add software from the same software providers. Because the "Publisher" remains the same on those updates and software, they will not need to update their WDAC policy. If they come to a time when the internally-written, unsigned application must be updated, they must also update the WDAC policy so that the hash in the policy matches the hash of the updated internal application. -They could also choose to create a catalog that captures information about the unsigned internal application, then sign and distribute the catalog. Then the internal application could be handled by WDAC policies in the same way as any other signed application. An update to the internal application would only require that the catalog be regenerated, signed, and distributed (no restarts would be required). \ No newline at end of file +They could also choose to create a catalog that captures information about the unsigned internal application, then sign and distribute the catalog. Then the internal application could be handled by WDAC policies in the same way as any other signed application. An update to the internal application would only require that the catalog be regenerated, signed, and distributed (no restarts would be required). + +## Path-based rules + +Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. + +- New-CIPolicy parameters +o FilePath: create path rules under path for anything not user-writeable (at the individual file level) +New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u + Optionally, add -UserWriteablePaths to ignore user writeability +o FilePathRule: create a rule where filepath string is directly set to value of +New-CIPolicyRule -FilePathRule +• Useful for wildcards like C:\foo\* +• Usage: same flow as per-app rules +$rules = New-CIPolicyRule … +$rules += New-CIPolicyRule … +… +New-CIPolicy -Rules $rules -f .\mypolicy.xml -u +• Wildcards supported: +o Suffix (ex. C:\foo\*) OR Prefix (ex. *\foo\bar.exe) + One or the other, not both at the same time + Does not support wildcard in the middle (ex. C:\*\foo.exe) +o Examples: + %WINDIR%\... + %SYSTEM32%\... + %OSDRIVE%\... +• Disable default FilePath rule protection of enforcing user-writeability +Set-RuleOption -o 18 .\policy.xml +o Adds “Disabled:Runtime FilePath Rule Protection” to the policy + From 44bb04a93af5d51764df038568758bab57e09d8e Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 12:24:44 -0700 Subject: [PATCH 213/737] new section --- .../select-types-of-rules-to-create.md | 60 ++++++++++++------- 1 file changed, 38 insertions(+), 22 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 22294479af..14ae09388f 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -108,26 +108,42 @@ They could also choose to create a catalog that captures information about the u Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. - New-CIPolicy parameters -o FilePath: create path rules under path for anything not user-writeable (at the individual file level) -New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u - Optionally, add -UserWriteablePaths to ignore user writeability -o FilePathRule: create a rule where filepath string is directly set to value of -New-CIPolicyRule -FilePathRule -• Useful for wildcards like C:\foo\* -• Usage: same flow as per-app rules -$rules = New-CIPolicyRule … -$rules += New-CIPolicyRule … -… -New-CIPolicy -Rules $rules -f .\mypolicy.xml -u -• Wildcards supported: -o Suffix (ex. C:\foo\*) OR Prefix (ex. *\foo\bar.exe) - One or the other, not both at the same time - Does not support wildcard in the middle (ex. C:\*\foo.exe) -o Examples: - %WINDIR%\... - %SYSTEM32%\... - %OSDRIVE%\... -• Disable default FilePath rule protection of enforcing user-writeability -Set-RuleOption -o 18 .\policy.xml -o Adds “Disabled:Runtime FilePath Rule Protection” to the policy + - FilePath: create path rules under path for anything not user-writeable (at the individual file level) + ```console + New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u + ``` + Optionally, add -UserWriteablePaths to ignore user writeability + + - FilePathRule: create a rule where filepath string is directly set to value of + ```console + New-CIPolicyRule -FilePathRule + ``` + Useful for wildcards like C:\foo\\* + +- Usage: same flow as per-app rules + ```xml + $rules = New-CIPolicyRule … + $rules += New-CIPolicyRule … + … + ``` + + ```console + New-CIPolicyRule -f .\mypolicy.xml -u + ``` + +- Wildcards supported: + Suffix (ex. C:\foo\\*) OR Prefix (ex. *\foo\bar.exe) + - One or the other, not both at the same time + - Does not support wildcard in the middle (ex. C:\\*\foo.exe) + - Examples: + - %WINDIR%\\... + - %SYSTEM32%\\... + - %OSDRIVE%\\... + +- Disable default FilePath rule protection of enforcing user-writeability + For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: + ```console + Set-RuleOption -o 18 .\policy.xml + ``` + From 5b121e06fda2b52493fb9818c21f4441d71459ea Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 12:29:36 -0700 Subject: [PATCH 214/737] escaped ex --- .../select-types-of-rules-to-create.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 14ae09388f..9dca57a76c 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -108,13 +108,13 @@ They could also choose to create a catalog that captures information about the u Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. - New-CIPolicy parameters - - FilePath: create path rules under path for anything not user-writeable (at the individual file level) + - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) ```console New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u ``` Optionally, add -UserWriteablePaths to ignore user writeability - - FilePathRule: create a rule where filepath string is directly set to value of + - FilePathRule: create a rule where filepath string is directly set to value of \ ```console New-CIPolicyRule -FilePathRule ``` From cab27d69904f9b3ab8c26581297700979e1d8af6 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 12:43:42 -0700 Subject: [PATCH 215/737] added new toc entry --- .../TOC.md | 1 + .../select-types-of-rules-to-create.md | 44 ------------ ...improvements-in-windows-10-version-1903.md | 67 +++++++++++++++++++ 3 files changed, 68 insertions(+), 44 deletions(-) create mode 100644 windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md diff --git a/windows/security/threat-protection/windows-defender-application-control/TOC.md b/windows/security/threat-protection/windows-defender-application-control/TOC.md index ee04e5c824..89a1b3bafb 100644 --- a/windows/security/threat-protection/windows-defender-application-control/TOC.md +++ b/windows/security/threat-protection/windows-defender-application-control/TOC.md @@ -34,6 +34,7 @@ ### [Sideload Win32 apps on S mode](sideloading-win32-apps-on-windows-10-s-mode-devices.md) ### [Disable WDAC policies](disable-windows-defender-application-control-policies.md) ### [Device Guard and AppLocker](windows-defender-device-guard-and-applocker.md) +### [Windows Defender Application Control improvements in Windows 10 version 1903](windows-defender-application-control-improvements-in-windows-10-version-1903.md) ## [AppLocker](applocker\applocker-overview.md) ### [Administer AppLocker](applocker\administer-applocker.md) diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index 9dca57a76c..85b9f016f2 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -103,47 +103,3 @@ As part of normal operations, they will eventually install software updates, or They could also choose to create a catalog that captures information about the unsigned internal application, then sign and distribute the catalog. Then the internal application could be handled by WDAC policies in the same way as any other signed application. An update to the internal application would only require that the catalog be regenerated, signed, and distributed (no restarts would be required). -## Path-based rules - -Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. - -- New-CIPolicy parameters - - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) - ```console - New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u - ``` - Optionally, add -UserWriteablePaths to ignore user writeability - - - FilePathRule: create a rule where filepath string is directly set to value of \ - ```console - New-CIPolicyRule -FilePathRule - ``` - Useful for wildcards like C:\foo\\* - -- Usage: same flow as per-app rules - ```xml - $rules = New-CIPolicyRule … - $rules += New-CIPolicyRule … - … - ``` - - ```console - New-CIPolicyRule -f .\mypolicy.xml -u - ``` - -- Wildcards supported: - Suffix (ex. C:\foo\\*) OR Prefix (ex. *\foo\bar.exe) - - One or the other, not both at the same time - - Does not support wildcard in the middle (ex. C:\\*\foo.exe) - - Examples: - - %WINDIR%\\... - - %SYSTEM32%\\... - - %OSDRIVE%\\... - -- Disable default FilePath rule protection of enforcing user-writeability - For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: - ```console - Set-RuleOption -o 18 .\policy.xml - ``` - - diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md new file mode 100644 index 0000000000..69413bcaca --- /dev/null +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -0,0 +1,67 @@ +--- +title: Windows Defender Application Control improvements in Windows 10 version 1903 (Windows 10) +description: Windows Defender Application Control restricts which applications users are allowed to run and the code that runs in the system core. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.localizationpriority: medium +author: jsuther1974 +ms.date: 05/06/2018 +--- + +# Windows Defender Application Control improvements in Windows 10 version 1903 + +**Applies to:** + +- Windows 10 +- Windows Server 2016 + +## Path-based rules + +Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. + +- New-CIPolicy parameters + - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) + ```console + New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u + ``` + Optionally, add -UserWriteablePaths to ignore user writeability + + - FilePathRule: create a rule where filepath string is directly set to value of \ + ```console + New-CIPolicyRule -FilePathRule + ``` + Useful for wildcards like C:\foo\\* + +- Usage: same flow as per-app rules + ```xml + $rules = New-CIPolicyRule … + $rules += New-CIPolicyRule … + … + ``` + + ```console + New-CIPolicyRule -f .\mypolicy.xml -u + ``` + +- Wildcards supported: + Suffix (ex. C:\foo\\*) OR Prefix (ex. *\foo\bar.exe) + - One or the other, not both at the same time + - Does not support wildcard in the middle (ex. C:\\*\foo.exe) + - Examples: + - %WINDIR%\\... + - %SYSTEM32%\\... + - %OSDRIVE%\\... + +- Disable default FilePath rule protection of enforcing user-writeability + For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: + ```console + Set-RuleOption -o 18 .\policy.xml + ``` + +## Multiple Policies + +Beginning with Windows 10 vesion 1903, WDAC supportd multiple code integrity policies for one device. + + From db7c319f3b849c3f30bd30b317083e59c33ed170 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 14:28:02 -0700 Subject: [PATCH 216/737] added preview text --- ...win32-apps-on-windows-10-s-mode-devices.md | 3 +++ ...improvements-in-windows-10-version-1903.md | 27 ++++++++++--------- 2 files changed, 17 insertions(+), 13 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md index 249ce3ddce..5bbde4033e 100644 --- a/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md +++ b/windows/security/threat-protection/windows-defender-application-control/sideloading-win32-apps-on-windows-10-s-mode-devices.md @@ -17,6 +17,9 @@ ms.date: 05/06/2018 - Windows 10 - Windows Server 2016 +>[!IMPORTANT] +>Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. + Windows 10 S mode is a locked-down system that only runs Store apps. Although it provides tight security and thereby promises reduced management, its application control restrictions make it difficult for some to adopt it widely. Sideloading makes S mode a more viable proposition for enterprise and education workloads by allowing critical Desktop apps in addition to Store apps. diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index 69413bcaca..d3c5ebd625 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -17,9 +17,14 @@ ms.date: 05/06/2018 - Windows 10 - Windows Server 2016 +>[!IMPORTANT] +>Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. + +This topic covers improvements introduced in Windows 10, version 1903. + ## Path-based rules -Beginning with Windows 10 version 1903, WDAC policies can contain path-based rules. +Beginning with Windows 10 version 1903, Windows Defender Application Control (WDAC) policies can contain path-based rules. - New-CIPolicy parameters - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) @@ -34,29 +39,25 @@ Beginning with Windows 10 version 1903, WDAC policies can contain path-based rul ``` Useful for wildcards like C:\foo\\* -- Usage: same flow as per-app rules - ```xml +- Usage follows the same flow as per-app rules: + ```powershell $rules = New-CIPolicyRule … $rules += New-CIPolicyRule … … - ``` - - ```console New-CIPolicyRule -f .\mypolicy.xml -u ``` -- Wildcards supported: - Suffix (ex. C:\foo\\*) OR Prefix (ex. *\foo\bar.exe) - - One or the other, not both at the same time - - Does not support wildcard in the middle (ex. C:\\*\foo.exe) +- Wildcards supported + - Suffix (ex. C:\foo\\*) OR Prefix (ex. *\foo\bar.exe) + - One or the other, not both at the same time + - Does not support wildcard in the middle (ex. C:\\*\foo.exe) - Examples: - %WINDIR%\\... - %SYSTEM32%\\... - %OSDRIVE%\\... -- Disable default FilePath rule protection of enforcing user-writeability - For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: - ```console +- Disable default FilePath rule protection of enforcing user-writeability. For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: + ```powershell Set-RuleOption -o 18 .\policy.xml ``` From a878d791762b0a5706f03e78be9aa0689303c967 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 14:29:59 -0700 Subject: [PATCH 217/737] Update windows-defender-application-control-improvements-in-windows-10-version-1903.md --- ...ication-control-improvements-in-windows-10-version-1903.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index d3c5ebd625..1cf88aa97e 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -28,13 +28,13 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD - New-CIPolicy parameters - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) - ```console + ```powershell New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u ``` Optionally, add -UserWriteablePaths to ignore user writeability - FilePathRule: create a rule where filepath string is directly set to value of \ - ```console + ```powershell New-CIPolicyRule -FilePathRule ``` Useful for wildcards like C:\foo\\* From 43571b22c515a289d7749145e97fe99fd6d97cbc Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 14:31:41 -0700 Subject: [PATCH 218/737] edits --- ...ation-control-improvements-in-windows-10-version-1903.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index 1cf88aa97e..7aa79f9097 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -66,3 +66,9 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD Beginning with Windows 10 vesion 1903, WDAC supportd multiple code integrity policies for one device. +WDAC – Composable (stacked) code integrity policies for supporting multiple code integrity policies +### Precedence +- Multiple base policies: intersection + - Only applications allowed by both policies run without generating block events +- Base + supplemental policy: union + - Files that are allowed by the base policy or the supplemental policy are not blocked From 44f3ed827f23c238f17516e6ec695175f5560453 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 6 May 2019 16:01:58 -0700 Subject: [PATCH 219/737] commit --- .openpublishing.redirection.json | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index fdaff1c87b..442f0b1ee5 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -13953,14 +13953,16 @@ "source_path": "windows/deployment/planning/windows-10-creators-update-deprecation.md", "redirect_url": "/windows/deployment/planning/windows-10-1703-removed-features", "redirect_document_id": true +}, +{ "source_path": "windows/security/threat-protection/windows-defender-atp/manage-allowed-blocked-list-windows-defender-advanced-threat-protection.md", "redirect_url": "/windows/security/threat-protection/windows-defender-atp/manage-indicators", "redirect_document_id": true }, { - "source_path": "windows/hub/release-information.md", - "redirect_url": "/windows/release-information", - "redirect_document_id": true +"source_path": "windows/hub/release-information.md", +"redirect_url": "/windows/release-information", +"redirect_document_id": true } ] } From fc8eff7139bd482802f06d98ef4c8a9262cfafbf Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 17:16:22 -0700 Subject: [PATCH 220/737] added PS examples --- ...improvements-in-windows-10-version-1903.md | 170 +++++++++++++++++- 1 file changed, 167 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index 7aa79f9097..86738f84e8 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -63,12 +63,176 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD ## Multiple Policies -Beginning with Windows 10 vesion 1903, WDAC supportd multiple code integrity policies for one device. +Beginning with Windows 10 version 1903, WDAC supports multiple code integrity policies for one device. - -WDAC – Composable (stacked) code integrity policies for supporting multiple code integrity policies ### Precedence + - Multiple base policies: intersection - Only applications allowed by both policies run without generating block events - Base + supplemental policy: union - Files that are allowed by the base policy or the supplemental policy are not blocked + +### Newly Supported Scenarios + +WDAC brings you the ability to support multiple CI policies. Three scenarios are now supported: + +1. Enforce and Audit Side-by-Side (Intersection) + - To validate policy changes before deploying in enforcement mode, deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy +2. Multiple Base Policies (Intersection) + - Enforce two or more base policies simultaneously to allow simpler policy targeting for policies with different scope/intent + - Ex. Base1 is a corporate standard policy that is relatively loose to accommodate all organizations while forcing minimum corp standards (e.g. Windows works + Managed Installer + path rules). Base2 is a team-specific policy that further restricts what is allowed to run (e.g. Windows works + Managed Installer + corporate signed apps only) +3. Supplemental Policies (Union) + - Deploy a supplemental policy (or policies) to expand a base policy + - Ex. The Azure host base policy restricts tightly to just allow Windows and hardware drivers. Can add a supplemental policy to allow just the additional signer rules needed to support signed code from the Exchange team. + +## COM Whitelisting + +• https://docs.microsoft.com/en-us/windows/desktop/com/the-component-object-model + +Get GUID of application to allow by either: +- Finding block event in Event Viewer (Application and Service Logs > Microsoft > Windows > AppLocker > MSI and Script) and extracting GUID +- Creating audit policy (using New-CIPolicy –Audit), potentially with specific provider, and use info from block events to get GUID + +### Author setting + +Three elements: +- Provider: platform on which code is running (values are Powershell, WSH, IE, VBA, MSI, or a wildcard “AllHostIds”) +- Key: GUID for the program you with to run, in the format Key="{33333333-4444-4444-1616-161616161616}" +- ValueName: needs to be set to "EnterpriseDefinedClsId" +One attribute: +- Value: needs to be “true” for allow and “false” for deny + Note: without quotation marks + Note: deny only works in base policies +- The setting needs to be placed in the order of ASCII values, first by Provider, then Key, then ValueName + +### Examples + +```xml + + + true + + + + + false + + + + + true + + +``` + +## New PowerShell parameters + +New-CIPolicy +- MultiplePolicyFormat: allows for multiple policies + +```powershell +New-CIPolicy [-FilePath] -Level {None | Hash | FileName | SignedVersion | Publisher | FilePublisher | LeafCertificate | PcaCertificate | RootCertificate | WHQL | WHQLPublisher | WHQLFilePublisher | PFN | FilePath} + [-DriverFiles ] [-Fallback {None | Hash | FileName | SignedVersion | Publisher | FilePublisher | LeafCertificate | PcaCertificate | RootCertificate | WHQL | WHQLPublisher | WHQLFilePublisher | PFN | FilePath}] + [-Audit] [-ScanPath ] [-ScriptFileNames] [-AllowFileNameFallbacks] [-SpecificFileNameLevel {None | OriginalFileName | InternalName | FileDescription | ProductName | PackageFamilyName | FilePath}] [-UserPEs] [-NoScript] + [-Deny] [-NoShadowCopy] [-MultiplePolicyFormat] [-OmitPaths ] [-PathToCatroot ] [] – to generate new policy format(base policy and policy type and policy guid) +``` + +Set-CIPolicyIdInfo +- **SupplementsBasePolicyID**: guid of new supplemental policy +- **BasePolicyToSupplementPath**: base policy that the supplemental policy applies to +- **ResetPolicyID**: reset the policy guids back to a random guid + +```powershell +Set-CIPolicyIdInfo [-FilePath] [-PolicyName ] [-SupplementsBasePolicyID ] [-BasePolicyToSupplementPath ] [-ResetPolicyID] [-PolicyId ] [] +``` + +Add-SignerRule +- **Supplemental**: provides supplemental signers + +```powershell +Add-SignerRule -FilePath -CertificatePath [-Kernel] [-User] [-Update] [-Supplemental] [-Deny] [] +``` + +Set-RuleOption +- **Enabled:Allow Supplemental Policies**: makes base policy able to be supplemented + +### Examples + +**Scenario #1: Creating a new base policy** + +```powershell +New-CiPolicy -MulitplePolicyFormat -foo –bar +``` + +- **MultiplePolicyFormat** switch results in 1) random GUIDs being generated for the policy ID and 2) the policy type being specified as base. + Can optionally choose to make it supplementable: + - Set-RuleOption has a new option **Enabled:Allow Supplemental Policies** to set for base policy +- For signed policies that are being made supplementable, need to ensure that supplemental signers are defined. Use “Add-SignerRule” to provide supplemental signers. + ```powershell + Add-SignerRule -FilePath -CertificatePath [-Kernel] [-User] [-Update] [-Supplemental] [-Deny] [] + ``` + +**Scenario #2: Creating a new supplemental policy** + +1. Scan using `New-CiPolicy –MuliplePolicyFormat` to generate a base policy: + ```powershell + New-CIPolicy -Level PcaCertificate -UserPEs -ScanPath -MultiplePolicyFormat 3> -FilePath + ``` +2. Change this new base policy to a supplemental policy + - Provide path of base in `Set-CIPolicyIdInfo –BasePolicytoSupplementPath` + - Provide GUID of base in `Set-CIPolicyIdInfo –SupplementsBasePolicyID` + ```powershell + Set-CIPolicyIdInfo -BasePolicyToSupplementPath -SupplementsBasePolicyID -FilePath + ``` + - Can revert the policy back to being a base policy using `-ResetPolicyID` + +**Scenario #3: Merging policies** + +- When merging, the policy type and ID of the leftmost/first policy specified is used + - If the leftmost is a base policy with ID , then regardless of what the GUIDS and types are for any subsequent policies, the merged policy will be a base policy with ID + +## Packaged App Rules + +`New-CIPolicyRule -Package $Package -Deny` to block apps is your best use case, so something like: + +1. Get the info about an installed package. + ```powershell + $package = Get-AppxPackage -name + ``` + Dependencies field in output is full Package object, can be accessed and passed directly to New-CIPolicyRule. +2. Make a rule. + ```powershell + $Rule = New-CIPolicyRule -Package $package -deny + ``` +3. Repeat for other packages you want to block using $rule +=…. +4. Make a policy for just the blocks you created for packages. + ```powershell + New-CIpolicy -rules $rule -f .\policy.xml -u + ``` +5. Merge with allow windows policy, or you could also use examplepolicies\AllowAll.xml. + ```powershell + Merge-CIPolicy -PolicyPaths .\policy.xml,C:\windows\Schemas\codeintegrity\examplepolicies\DefaultWindows_Audit.xml -o allowWindowsDenyPackages.xml + ``` +6. Disable audit mode. + ```powershell + Set-RuleOption -o 3 -Delete .\allowWindowsDenyPackages.xml + ``` +7. Enable invalidate EAs on reboot. + ```powershell + Set-RuleOption -o 15 .\allowWindowsDenyPackages.xml + ``` +8. Compile the policy + ```powershell + ConvertFrom-CIPolicy .\AllowWindowsDenyPackages.xml C:\compiledpolicy.bin + ``` +9. Install the policy withwout restarting. + ```powershell + Invoke-CimMethod -Namespace root\Microsoft\Windows\CI -ClassName PS_UpdateAndCompareCIPolicy -MethodName Update -Arguments @{FilePath = "C:\compiledpolicy.bin"} + ``` + +After doing this on the next build of Dev3, for the apps that you blocked, already installed apps should fail to launch, and should you put this policy on another machine that hasn’t yet installed the apps, store should block them from being purchased/installed. +If you wanted to make a rule for an app that isn’t already installed, first make a rule for an app that is. Then for the app you want to actually block take the store URL (from store page click … then share, then copy link to get something like: https://www.microsoft.com/store/productId/9WZDNCRFJ3TJ) and grab the hash code at the end (in bold) then replace the bolded bit below: +https://bspmts.mp.microsoft.com/v1/public/catalog/Retail/Products/9wzdncrfj3tj/applockerdata +then grab packagefamilyname and replace the one in the xml you got in step 4 with the PFN from the link above, then run through 5-9 again. + + From 7bb830d8e386dde5fa961af312871748c931c9fa Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 17:17:56 -0700 Subject: [PATCH 221/737] added faq --- ...improvements-in-windows-10-version-1903.md | 70 +++++++++++++++++++ 1 file changed, 70 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index 86738f84e8..3bee320959 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -235,4 +235,74 @@ If you wanted to make a rule for an app that isn’t already installed, first ma https://bspmts.mp.microsoft.com/v1/public/catalog/Retail/Products/9wzdncrfj3tj/applockerdata then grab packagefamilyname and replace the one in the xml you got in step 4 with the PFN from the link above, then run through 5-9 again. +## FAQs + +Misc +a. Questions: +• What uniquely identifies a “file”? SHA1, SHA256, either, both? +o What is the “Flat hash” vs. normal? +Either hash works as a unique identifier, would recommend sha256 though just because lower collision chance. +“Authenticode Hash” is the hash we use, it is calculated in a way that does not change even if the file is embed signed, whereas “flat hash” is just a direct hash on the bytes of the file and changes with signature. +For Scripts/MSIs an embedded hash would use the SIP of the particular script type, while a catalog hash would use the flat hash (since catalogs are only aware of a few select SIPs, particularly the PE exe/dll one), so the 8028/8029 events log the “CatalogHash” as well, in case it differs from the hash used to evaluate against an embedded sig + +• What property of a file is used to map out to a publisher? +Files are tied to publishers via their signature (either embed signed or catalog signed via a signed catalog containing that files hash), correlate 3089 events in order to get publisher data + +• Can you give a description/enumeration of values for “signing level”? + +Base signing levels are: +#define SE_SIGNING_LEVEL_UNCHECKED 0x00000000 +#define SE_SIGNING_LEVEL_UNSIGNED 0x00000001 +#define SE_SIGNING_LEVEL_ENTERPRISE 0x00000002 +#define SE_SIGNING_LEVEL_CUSTOM_1 0x00000003 +#define SE_SIGNING_LEVEL_DEVELOPER SE_SIGNING_LEVEL_CUSTOM_1 +#define SE_SIGNING_LEVEL_AUTHENTICODE 0x00000004 +#define SE_SIGNING_LEVEL_CUSTOM_2 0x00000005 +#define SE_SIGNING_LEVEL_STORE 0x00000006 +#define SE_SIGNING_LEVEL_CUSTOM_3 0x00000007 +#define SE_SIGNING_LEVEL_ANTIMALWARE SE_SIGNING_LEVEL_CUSTOM_3 +#define SE_SIGNING_LEVEL_MICROSOFT 0x00000008 +#define SE_SIGNING_LEVEL_CUSTOM_4 0x00000009 +#define SE_SIGNING_LEVEL_CUSTOM_5 0x0000000A +#define SE_SIGNING_LEVEL_DYNAMIC_CODEGEN 0x0000000B +#define SE_SIGNING_LEVEL_WINDOWS 0x0000000C +#define SE_SIGNING_LEVEL_CUSTOM_7 0x0000000D +#define SE_SIGNING_LEVEL_WINDOWS_TCB 0x0000000E +#define SE_SIGNING_LEVEL_CUSTOM_6 0x0000000F + +The TL;DR on signing levels is we have collections of certificates+EKUs that we use to define broad “security levels” based on signer, for example SE_SIGNING_LEVEL_WINDOWS generally maps to “signed as part of a production windows build) +Some also inherit from others (e.g. signing level windows is a subset of microsoft) + +See minkernel\published\base\ntseapi_x.w and ntseapi.w, and/or poke around in onecore\base\ci\dll\cipolicy.c searching for references to se_signing_level* for more on signing levels and how they are used with CIPolicy + +• What is the “SI Signing Scenario”? +Pretty sure this one maps to either kernel or user mode (0 or 1 respectively), CIPolicy lets you configure whitelists for each separately, e.g. you probably wouldn’t want some random user mode app, say notepad++ to run as a kernel driver 😊 + +• Can you also provide the “description” for the events? I know audit/block are each one of two values next to each other, but do they audit/block a specific file type only? Script? Exe? +3076 Audit for exe/dll generated by CI in the createprocess stack +3077 enforced version +3089 Signing information event correlated with either a 3076/3077 event, contains # of signatures and an index as to which signature it is, one 3089 is generated for each signature of a file (so many 3089 map to one 3076/77). Unsigned files will generate a single 3089 with TotalSignatureCount 0 +8028 Audit for scripts/msis generated by WLDP being called by the scripthosts themselves (scripthosts opt in to enforcement, so we don’t enforce on 3rd party scripthosts like python/ruby) +8029 Enforce for scripts +We don’t currently have signer information in the script events + +• I don’t understand what the “Policy” fields are. +Code Integrity Policy is at its core an enterprise whitelisting solution. For these events to be generated, customers would have had to generate a policy xml, compile it, and deploy it. PolicyName/PolicyID fields are optional fields customers can add to the policy to get propagated into the events, policy hash is literally the hash of the policy (and policy hash matching guarantees that two events were blocked by the same policy). Since you can have multiple concurrent policies on one system supplementing each other, knowing what policy actually blocked the binary from running is useful + +• Is this purely file based or do I need to worry about the “PackageName” grouping? +o Eg… do I need the packagename to get back to a publisher or are individual files from the package all mapped up directly? +An event is generated for each individual binary that failed policy. The PackageFamilyName is put in the process token of all binaries loading under an appx and is can be used in rules in policy to attempt to allow an entire package to run rather than whitelisting each individual binary, but we will still generate an individual event for each binary that fails +I can’t currently remember if the PackageFamilyName field is even calculated or just zeroed out if there aren’t PFN rules in a policy + +• What field in 3089 am I able to join on to map from File to Publisher? +CorrelationID is actually not in the event templates I sent you and is actually an optional field in the metadata of every eventviewer event. In the XML of the event the correlationID’s path is: + +For comparison, the rest of the fields look like: +valuevalue2… + +• 3076/77 don’t seem to include ‘File Path’. Can this be deduced from ‘File Name’? +• 8028/8029 don’t seem to include ‘File Name’. Can this be deduced from ‘File Path’? +“File Name” in 3076/77 is actually the path in NT form (\Device\HarddiskVolume3\Windows\System32\myfile.dll), and the “originalfilename” field maps to what would be “File Name” in a file rule in policy XML +For 8028/8029 File Path is the C:\ path to the file and you’ll notice a trend where we didn’t bother to include all the same fields we do for the PE files so there is no “originalFileName” + From fd96a3d538cf448adb87c3cb857d242e986a5f09 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Mon, 6 May 2019 17:32:02 -0700 Subject: [PATCH 222/737] added Q&A --- ...improvements-in-windows-10-version-1903.md | 82 +++++++++++-------- 1 file changed, 49 insertions(+), 33 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index 3bee320959..b563a2c54f 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -237,20 +237,23 @@ then grab packagefamilyname and replace the one in the xml you got in step 4 wit ## FAQs -Misc -a. Questions: -• What uniquely identifies a “file”? SHA1, SHA256, either, both? -o What is the “Flat hash” vs. normal? -Either hash works as a unique identifier, would recommend sha256 though just because lower collision chance. +**Q:** What uniquely identifies a “file”? SHA1, SHA256, either, both? What is the “Flat hash” vs. normal? + +**A:** Either hash works as a unique identifier, would recommend sha256 though just because lower collision chance. + “Authenticode Hash” is the hash we use, it is calculated in a way that does not change even if the file is embed signed, whereas “flat hash” is just a direct hash on the bytes of the file and changes with signature. + For Scripts/MSIs an embedded hash would use the SIP of the particular script type, while a catalog hash would use the flat hash (since catalogs are only aware of a few select SIPs, particularly the PE exe/dll one), so the 8028/8029 events log the “CatalogHash” as well, in case it differs from the hash used to evaluate against an embedded sig -• What property of a file is used to map out to a publisher? -Files are tied to publishers via their signature (either embed signed or catalog signed via a signed catalog containing that files hash), correlate 3089 events in order to get publisher data +**Q:** What property of a file is used to map out to a publisher? + +**A:** Files are tied to publishers via their signature (either embed signed or catalog signed via a signed catalog containing that files hash), correlate 3089 events in order to get publisher data -• Can you give a description/enumeration of values for “signing level”? +**Q:** Can you give a description/enumeration of values for “signing level”? -Base signing levels are: +**A:** Base signing levels are: + +```xml #define SE_SIGNING_LEVEL_UNCHECKED 0x00000000 #define SE_SIGNING_LEVEL_UNSIGNED 0x00000001 #define SE_SIGNING_LEVEL_ENTERPRISE 0x00000002 @@ -269,40 +272,53 @@ Base signing levels are: #define SE_SIGNING_LEVEL_CUSTOM_7 0x0000000D #define SE_SIGNING_LEVEL_WINDOWS_TCB 0x0000000E #define SE_SIGNING_LEVEL_CUSTOM_6 0x0000000F +``` -The TL;DR on signing levels is we have collections of certificates+EKUs that we use to define broad “security levels” based on signer, for example SE_SIGNING_LEVEL_WINDOWS generally maps to “signed as part of a production windows build) -Some also inherit from others (e.g. signing level windows is a subset of microsoft) +The TL;DR on signing levels is we have collections of certificates+EKUs that we use to define broad “security levels” based on signer, for example SE_SIGNING_LEVEL_WINDOWS generally maps to “signed as part of a production Windows build) +Some also inherit from others (e.g. signing level Windows is a subset of Microsoft) -See minkernel\published\base\ntseapi_x.w and ntseapi.w, and/or poke around in onecore\base\ci\dll\cipolicy.c searching for references to se_signing_level* for more on signing levels and how they are used with CIPolicy +**Q:** What is the “SI Signing Scenario”? +This maps to either kernel or user mode (0 or 1 respectively). CIPolicy lets you configure whitelists for each separately. -• What is the “SI Signing Scenario”? -Pretty sure this one maps to either kernel or user mode (0 or 1 respectively), CIPolicy lets you configure whitelists for each separately, e.g. you probably wouldn’t want some random user mode app, say notepad++ to run as a kernel driver 😊 - -• Can you also provide the “description” for the events? I know audit/block are each one of two values next to each other, but do they audit/block a specific file type only? Script? Exe? -3076 Audit for exe/dll generated by CI in the createprocess stack -3077 enforced version -3089 Signing information event correlated with either a 3076/3077 event, contains # of signatures and an index as to which signature it is, one 3089 is generated for each signature of a file (so many 3089 map to one 3076/77). Unsigned files will generate a single 3089 with TotalSignatureCount 0 -8028 Audit for scripts/msis generated by WLDP being called by the scripthosts themselves (scripthosts opt in to enforcement, so we don’t enforce on 3rd party scripthosts like python/ruby) -8029 Enforce for scripts +**Q:** Can you also provide the “description” for the events? + +I know audit/block are each one of two values next to each other, but do they audit/block a specific file type only? Script? Exe? + +|-------|--------------------------| +|Event ID| Description | +|3076 |Audit for exe/dll generated by CI in the createprocess stack| +|3077 |Enforced version | +|3089 |Signing information event correlated with either a 3076/3077 event, contains # of signatures and an index as to which signature it is, one 3089 is generated for each signature of a file (so many 3089 map to one 3076/77). Unsigned files will generate a single 3089 with TotalSignatureCount 0 | +|8028 |Audit for scripts/msis generated by WLDP being called by the scripthosts themselves (scripthosts opt in to enforcement, so we don’t enforce on 3rd party scripthosts like python/ruby)| +|8029 |Enforce for scripts| + We don’t currently have signer information in the script events -• I don’t understand what the “Policy” fields are. -Code Integrity Policy is at its core an enterprise whitelisting solution. For these events to be generated, customers would have had to generate a policy xml, compile it, and deploy it. PolicyName/PolicyID fields are optional fields customers can add to the policy to get propagated into the events, policy hash is literally the hash of the policy (and policy hash matching guarantees that two events were blocked by the same policy). Since you can have multiple concurrent policies on one system supplementing each other, knowing what policy actually blocked the binary from running is useful +**Q:** I don’t understand what the “Policy” fields are. + +**A:** Code Integrity Policy is at its core an enterprise whitelisting solution. For these events to be generated, customers would have had to generate a policy xml, compile it, and deploy it. PolicyName/PolicyID fields are optional fields customers can add to the policy to get propagated into the events, policy hash is literally the hash of the policy (and policy hash matching guarantees that two events were blocked by the same policy). Since you can have multiple concurrent policies on one system supplementing each other, knowing what policy actually blocked the binary from running is useful -• Is this purely file based or do I need to worry about the “PackageName” grouping? -o Eg… do I need the packagename to get back to a publisher or are individual files from the package all mapped up directly? -An event is generated for each individual binary that failed policy. The PackageFamilyName is put in the process token of all binaries loading under an appx and is can be used in rules in policy to attempt to allow an entire package to run rather than whitelisting each individual binary, but we will still generate an individual event for each binary that fails -I can’t currently remember if the PackageFamilyName field is even calculated or just zeroed out if there aren’t PFN rules in a policy +**Q:** Is this purely file based or do I need to worry about the “PackageName” grouping? For example, do I need the packagename to get back to a publisher or are individual files from the package all mapped up directly? + +**A:** An event is generated for each individual binary that failed policy. The PackageFamilyName is put in the process token of all binaries loading under an appx and is can be used in rules in policy to attempt to allow an entire package to run rather than whitelisting each individual binary, but we will still generate an individual event for each binary that fails. + -• What field in 3089 am I able to join on to map from File to Publisher? -CorrelationID is actually not in the event templates I sent you and is actually an optional field in the metadata of every eventviewer event. In the XML of the event the correlationID’s path is: +**Q:** What field in 3089 am I able to join on to map from File to Publisher? + +**A:** CorrelationID is actually not in the event templates I sent you and is actually an optional field in the metadata of every eventviewer event. In the XML of the event the correlationID’s path is: + +```xml +``` For comparison, the rest of the fields look like: +```xml valuevalue2… +``` + -• 3076/77 don’t seem to include ‘File Path’. Can this be deduced from ‘File Name’? -• 8028/8029 don’t seem to include ‘File Name’. Can this be deduced from ‘File Path’? -“File Name” in 3076/77 is actually the path in NT form (\Device\HarddiskVolume3\Windows\System32\myfile.dll), and the “originalfilename” field maps to what would be “File Name” in a file rule in policy XML -For 8028/8029 File Path is the C:\ path to the file and you’ll notice a trend where we didn’t bother to include all the same fields we do for the PE files so there is no “originalFileName” +**Q:** 3076/77 don’t seem to include ‘File Path’. Can this be deduced from ‘File Name’? 8028/8029 don’t seem to include ‘File Name’. Can this be deduced from ‘File Path’? + +**A:** “File Name” in 3076/77 is actually the path in NT form (\Device\HarddiskVolume3\Windows\System32\myfile.dll), and the “originalfilename” field maps to what would be “File Name” in a file rule in policy XML. +For 8028/8029, File Path is the C:\ path to the file and you’ll notice a trend where we didn’t bother to include all the same fields we do for the PE files so there is no “originalFileName”. From 39a69c639722cab6c188230f9d80ab67f1c30cf9 Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Tue, 7 May 2019 10:19:06 +0300 Subject: [PATCH 223/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md Co-Authored-By: VLG17 <41186174+VLG17@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-aadj-sso-cert.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md index a5d222346e..f3c76726c8 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert.md @@ -425,7 +425,7 @@ Sign-in a workstation with access equivalent to a _domain user_. 3. Under **MANAGE**, click **Application proxy**. 4. Click **Configure an app**. 5. Under **Basic Settings** next to **Name**, type **WHFB NDES 01**. Choose a name that correlates this Azure AD Application Proxy setting with the on-premises NDES server. Each NDES server must have its own Azure AD Application Proxy as two NDES servers cannot share the same internal URL. -6. Next to **Internal Url**, type the internal fully qualified DNS name of the NDES server associated with this Azure AD Application Proxy. For example, https://ndes.corp.mstepdemo.net). This must match the primary hostname (AD Computer Account name) of the NDES server and ensure you prefix the Url with **https**. +6. Next to **Internal Url**, type the internal, fully qualified DNS name of the NDES server associated with this Azure AD Application Proxy. For example, https://ndes.corp.mstepdemo.net). You need to match the primary host name (AD Computer Account name) of the NDES server, and prefix the URL with **https**. 7. Under **Internal Url**, select **https://** from the first list. In the text box next to **https://**, type the hostname you want to use as your external hostname for the Azure AD Application Proxy. In the list next to the hostname you typed, select a DNS suffix you want to use externally for the Azure AD Application Proxy. It is recommended to use the default, -[tenantName].msapproxy.net where **[tenantName]** is your current Azure Active Directory tenant name (-mstephendemo.msappproxy.net). ![Azure NDES Application Proxy Configuration](images/aadjcert/azureconsole-appproxyconfig.png) 8. Select **Passthrough** from the **Pre Authentication** list. From 2a7799ee70852037f9ca761a8bef08fb60b89db1 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Tue, 7 May 2019 12:19:40 -0700 Subject: [PATCH 224/737] Added 19H1 policies --- .../policy-configuration-service-provider.md | 60 +- .../mdm/policy-csp-internetexplorer.md | 601 +++++++++++++++++- 2 files changed, 653 insertions(+), 8 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index a27926a537..05d54e0bec 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -1323,6 +1323,9 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/AllowEnhancedProtectedMode
+
+ InternetExplorer/AllowEnhancedSuggestionsInAddressBar +
InternetExplorer/AllowEnterpriseModeFromToolsMenu
@@ -1389,6 +1392,9 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/ConsistentMimeHandlingInternetExplorerProcesses
+
+ InternetExplorer/DisableActiveXVersionListAutoDownload +
InternetExplorer/DisableAdobeFlash
@@ -1398,6 +1404,9 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/DisableBypassOfSmartScreenWarningsAboutUncommonFiles
+
+ InternetExplorer/DisableCompatView +
InternetExplorer/DisableConfiguringHistory
@@ -1416,12 +1425,18 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/DisableEncryptionSupport
+
+ InternetExplorer/DisableFeedsBackgroundSync +
InternetExplorer/DisableFirstRunWizard
InternetExplorer/DisableFlipAheadFeature
+
+ InternetExplorer/DisableGeolocation +
InternetExplorer/DisableHomePageChange
@@ -1449,6 +1464,9 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/DisableUpdateCheck
+
+ InternetExplorer/DisableWebAddressAutoComplete +
InternetExplorer/DoNotAllowActiveXControlsInProtectedMode
@@ -1842,6 +1860,9 @@ The following diagram shows the Policy configuration service provider in tree fo
InternetExplorer/MimeSniffingSafetyFeatureInternetExplorerProcesses
+
+ InternetExplorer/NewTabDefaultPage +
InternetExplorer/NotificationBarInternetExplorerProcesses
@@ -3812,6 +3833,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/AllowCertificateAddressMismatchWarning](./policy-csp-internetexplorer.md#internetexplorer-allowcertificateaddressmismatchwarning) - [InternetExplorer/AllowDeletingBrowsingHistoryOnExit](./policy-csp-internetexplorer.md#internetexplorer-allowdeletingbrowsinghistoryonexit) - [InternetExplorer/AllowEnhancedProtectedMode](./policy-csp-internetexplorer.md#internetexplorer-allowenhancedprotectedmode) +- [InternetExplorer/AllowEnhancedSuggestionsInAddressBar](./policy-csp-internetexplorer.md#internetexplorer-allowenhancedsuggestionsinaddressbar) - [InternetExplorer/AllowEnterpriseModeFromToolsMenu](./policy-csp-internetexplorer.md#internetexplorer-allowenterprisemodefromtoolsmenu) - [InternetExplorer/AllowEnterpriseModeSiteList](./policy-csp-internetexplorer.md#internetexplorer-allowenterprisemodesitelist) - [InternetExplorer/AllowFallbackToSSL3](./policy-csp-internetexplorer.md#internetexplorer-allowfallbacktossl3) @@ -3834,17 +3856,21 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/CheckServerCertificateRevocation](./policy-csp-internetexplorer.md#internetexplorer-checkservercertificaterevocation) - [InternetExplorer/CheckSignaturesOnDownloadedPrograms](./policy-csp-internetexplorer.md#internetexplorer-checksignaturesondownloadedprograms) - [InternetExplorer/ConsistentMimeHandlingInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-consistentmimehandlinginternetexplorerprocesses) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](./policy-csp-internetexplorer.md#internetexplorer-disableactivexversionlistautodownload) - [InternetExplorer/DisableAdobeFlash](./policy-csp-internetexplorer.md#internetexplorer-disableadobeflash) - [InternetExplorer/DisableBypassOfSmartScreenWarnings](./policy-csp-internetexplorer.md#internetexplorer-disablebypassofsmartscreenwarnings) - [InternetExplorer/DisableBypassOfSmartScreenWarningsAboutUncommonFiles](./policy-csp-internetexplorer.md#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles) +- [InternetExplorer/DisableCompatView](./policy-csp-internetexplorer.md#internetexplorer-disablecompatview) - [InternetExplorer/DisableConfiguringHistory](./policy-csp-internetexplorer.md#internetexplorer-disableconfiguringhistory) - [InternetExplorer/DisableCrashDetection](./policy-csp-internetexplorer.md#internetexplorer-disablecrashdetection) - [InternetExplorer/DisableCustomerExperienceImprovementProgramParticipation](./policy-csp-internetexplorer.md#internetexplorer-disablecustomerexperienceimprovementprogramparticipation) - [InternetExplorer/DisableDeletingUserVisitedWebsites](./policy-csp-internetexplorer.md#internetexplorer-disabledeletinguservisitedwebsites) - [InternetExplorer/DisableEnclosureDownloading](./policy-csp-internetexplorer.md#internetexplorer-disableenclosuredownloading) - [InternetExplorer/DisableEncryptionSupport](./policy-csp-internetexplorer.md#internetexplorer-disableencryptionsupport) +- [InternetExplorer/DisableFeedsBackgroundSync](./policy-csp-internetexplorer.md#internetexplorer-disablefeedsbackgroundsync) - [InternetExplorer/DisableFirstRunWizard](./policy-csp-internetexplorer.md#internetexplorer-disablefirstrunwizard) - [InternetExplorer/DisableFlipAheadFeature](./policy-csp-internetexplorer.md#internetexplorer-disableflipaheadfeature) +- [InternetExplorer/DisableGeolocation](./policy-csp-internetexplorer.md#internetexplorer-disablegeolocation) - [InternetExplorer/DisableHomePageChange](./policy-csp-internetexplorer.md#internetexplorer-disablehomepagechange) - [InternetExplorer/DisableIgnoringCertificateErrors](./policy-csp-internetexplorer.md#internetexplorer-disableignoringcertificateerrors) - [InternetExplorer/DisableInPrivateBrowsing](./policy-csp-internetexplorer.md#internetexplorer-disableinprivatebrowsing) @@ -3854,6 +3880,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/DisableSecondaryHomePageChange](./policy-csp-internetexplorer.md#internetexplorer-disablesecondaryhomepagechange) - [InternetExplorer/DisableSecuritySettingsCheck](./policy-csp-internetexplorer.md#internetexplorer-disablesecuritysettingscheck) - [InternetExplorer/DisableUpdateCheck](./policy-csp-internetexplorer.md#internetexplorer-disableupdatecheck) +- [InternetExplorer/DisableWebAddressAutoComplete](./policy-csp-internetexplorer.md#internetexplorer-disablewebaddressautocomplete) - [InternetExplorer/DoNotAllowActiveXControlsInProtectedMode](./policy-csp-internetexplorer.md#internetexplorer-donotallowactivexcontrolsinprotectedmode) - [InternetExplorer/DoNotAllowUsersToAddSites](./policy-csp-internetexplorer.md#internetexplorer-donotallowuserstoaddsites) - [InternetExplorer/DoNotAllowUsersToChangePolicies](./policy-csp-internetexplorer.md#internetexplorer-donotallowuserstochangepolicies) @@ -3984,6 +4011,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/LockedDownTrustedSitesZoneNavigateWindowsAndFrames](./policy-csp-internetexplorer.md#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes) - [InternetExplorer/MKProtocolSecurityRestrictionInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses) - [InternetExplorer/MimeSniffingSafetyFeatureInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-mimesniffingsafetyfeatureinternetexplorerprocesses) +- [InternetExplorer/NewTabDefaultPage](./policy-csp-internetexplorer.md#internetexplorer-newtabdefaultpage) - [InternetExplorer/NotificationBarInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-notificationbarinternetexplorerprocesses) - [InternetExplorer/PreventManagingSmartScreenFilter](./policy-csp-internetexplorer.md#internetexplorer-preventmanagingsmartscreenfilter) - [InternetExplorer/PreventPerUserInstallationOfActiveXControls](./policy-csp-internetexplorer.md#internetexplorer-preventperuserinstallationofactivexcontrols) @@ -4373,6 +4401,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/AllowCertificateAddressMismatchWarning](./policy-csp-internetexplorer.md#internetexplorer-allowcertificateaddressmismatchwarning) - [InternetExplorer/AllowDeletingBrowsingHistoryOnExit](./policy-csp-internetexplorer.md#internetexplorer-allowdeletingbrowsinghistoryonexit) - [InternetExplorer/AllowEnhancedProtectedMode](./policy-csp-internetexplorer.md#internetexplorer-allowenhancedprotectedmode) +- [InternetExplorer/AllowEnhancedSuggestionsInAddressBar](./policy-csp-internetexplorer.md#internetexplorer-allowenhancedsuggestionsinaddressbar) - [InternetExplorer/AllowEnterpriseModeFromToolsMenu](./policy-csp-internetexplorer.md#internetexplorer-allowenterprisemodefromtoolsmenu) - [InternetExplorer/AllowEnterpriseModeSiteList](./policy-csp-internetexplorer.md#internetexplorer-allowenterprisemodesitelist) - [InternetExplorer/AllowFallbackToSSL3](./policy-csp-internetexplorer.md#internetexplorer-allowfallbacktossl3) @@ -4395,17 +4424,21 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/CheckServerCertificateRevocation](./policy-csp-internetexplorer.md#internetexplorer-checkservercertificaterevocation) - [InternetExplorer/CheckSignaturesOnDownloadedPrograms](./policy-csp-internetexplorer.md#internetexplorer-checksignaturesondownloadedprograms) - [InternetExplorer/ConsistentMimeHandlingInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-consistentmimehandlinginternetexplorerprocesses) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](./policy-csp-internetexplorer.md#internetexplorer-disableactivexversionlistautodownload) - [InternetExplorer/DisableAdobeFlash](./policy-csp-internetexplorer.md#internetexplorer-disableadobeflash) - [InternetExplorer/DisableBypassOfSmartScreenWarnings](./policy-csp-internetexplorer.md#internetexplorer-disablebypassofsmartscreenwarnings) - [InternetExplorer/DisableBypassOfSmartScreenWarningsAboutUncommonFiles](./policy-csp-internetexplorer.md#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles) +- [InternetExplorer/DisableCompatView](./policy-csp-internetexplorer.md#internetexplorer-disablecompatview) - [InternetExplorer/DisableConfiguringHistory](./policy-csp-internetexplorer.md#internetexplorer-disableconfiguringhistory) - [InternetExplorer/DisableCrashDetection](./policy-csp-internetexplorer.md#internetexplorer-disablecrashdetection) - [InternetExplorer/DisableCustomerExperienceImprovementProgramParticipation](./policy-csp-internetexplorer.md#internetexplorer-disablecustomerexperienceimprovementprogramparticipation) - [InternetExplorer/DisableDeletingUserVisitedWebsites](./policy-csp-internetexplorer.md#internetexplorer-disabledeletinguservisitedwebsites) - [InternetExplorer/DisableEnclosureDownloading](./policy-csp-internetexplorer.md#internetexplorer-disableenclosuredownloading) - [InternetExplorer/DisableEncryptionSupport](./policy-csp-internetexplorer.md#internetexplorer-disableencryptionsupport) +- [InternetExplorer/DisableFeedsBackgroundSync](./policy-csp-internetexplorer.md#internetexplorer-disablefeedsbackgroundsync) - [InternetExplorer/DisableFirstRunWizard](./policy-csp-internetexplorer.md#internetexplorer-disablefirstrunwizard) - [InternetExplorer/DisableFlipAheadFeature](./policy-csp-internetexplorer.md#internetexplorer-disableflipaheadfeature) +- [InternetExplorer/DisableGeolocation](./policy-csp-internetexplorer.md#internetexplorer-disablegeolocation) - [InternetExplorer/DisableHomePageChange](./policy-csp-internetexplorer.md#internetexplorer-disablehomepagechange) - [InternetExplorer/DisableIgnoringCertificateErrors](./policy-csp-internetexplorer.md#internetexplorer-disableignoringcertificateerrors) - [InternetExplorer/DisableInPrivateBrowsing](./policy-csp-internetexplorer.md#internetexplorer-disableinprivatebrowsing) @@ -4415,6 +4448,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/DisableSecondaryHomePageChange](./policy-csp-internetexplorer.md#internetexplorer-disablesecondaryhomepagechange) - [InternetExplorer/DisableSecuritySettingsCheck](./policy-csp-internetexplorer.md#internetexplorer-disablesecuritysettingscheck) - [InternetExplorer/DisableUpdateCheck](./policy-csp-internetexplorer.md#internetexplorer-disableupdatecheck) +- [InternetExplorer/DisableWebAddressAutoComplete](./policy-csp-internetexplorer.md#internetexplorer-disablewebaddressautocomplete) - [InternetExplorer/DoNotAllowActiveXControlsInProtectedMode](./policy-csp-internetexplorer.md#internetexplorer-donotallowactivexcontrolsinprotectedmode) - [InternetExplorer/DoNotAllowUsersToAddSites](./policy-csp-internetexplorer.md#internetexplorer-donotallowuserstoaddsites) - [InternetExplorer/DoNotAllowUsersToChangePolicies](./policy-csp-internetexplorer.md#internetexplorer-donotallowuserstochangepolicies) @@ -4545,6 +4579,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [InternetExplorer/LockedDownTrustedSitesZoneNavigateWindowsAndFrames](./policy-csp-internetexplorer.md#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes) - [InternetExplorer/MKProtocolSecurityRestrictionInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses) - [InternetExplorer/MimeSniffingSafetyFeatureInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-mimesniffingsafetyfeatureinternetexplorerprocesses) +- [InternetExplorer/NewTabDefaultPage](./policy-csp-internetexplorer.md#internetexplorer-newtabdefaultpage) - [InternetExplorer/NotificationBarInternetExplorerProcesses](./policy-csp-internetexplorer.md#internetexplorer-notificationbarinternetexplorerprocesses) - [InternetExplorer/PreventManagingSmartScreenFilter](./policy-csp-internetexplorer.md#internetexplorer-preventmanagingsmartscreenfilter) - [InternetExplorer/PreventPerUserInstallationOfActiveXControls](./policy-csp-internetexplorer.md#internetexplorer-preventperuserinstallationofactivexcontrols) @@ -4989,7 +5024,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [Accounts/AllowMicrosoftAccountConnection](#accounts-allowmicrosoftaccountconnection) - [ApplicationManagement/AllowAllTrustedApps](#applicationmanagement-allowalltrustedapps) -- [ApplicationManagement/AllowAppStoreAutoUpdate](#applicationmanagement-allowappstoreautoupdate) +- [ApplicationManagement/AllowAppStoreAutoUpdate](#applicationmanagement-allowappstoreautoupdate) - [ApplicationManagement/AllowDeveloperUnlock](#applicationmanagement-allowdeveloperunlock) - [Authentication/AllowFastReconnect](#authentication-allowfastreconnect) - [Authentication/PreferredAadTenantDomainName](#authentication-preferredaadtenantdomainname) @@ -5014,7 +5049,10 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/MaxInactivityTimeDeviceLock](#devicelock-maxinactivitytimedevicelock) - [DeviceLock/MinDevicePasswordComplexCharacters](#devicelock-mindevicepasswordcomplexcharacters) - [DeviceLock/MinDevicePasswordLength](#devicelock-mindevicepasswordlength) -- [Experience/AllowCortana](#experience-allowcortana) +- [Experience/AllowCortana](#experience-allowcortana) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) - [Privacy/AllowInputPersonalization](#privacy-allowinputpersonalization) - [Search/AllowSearchToUseLocation](#search-allowsearchtouselocation) - [Security/RequireDeviceEncryption](#security-requiredeviceencryption) @@ -5062,6 +5100,9 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/DevicePasswordEnabled](#devicelock-devicepasswordenabled) - [Experience/AllowCortana](#experience-allowcortana) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) - [Privacy/AllowInputPersonalization](#privacy-allowinputpersonalization) - [Search/AllowSearchToUseLocation](#search-allowsearchtouselocation) - [Security/RequireDeviceEncryption](#security-requiredeviceencryption) @@ -5152,12 +5193,27 @@ The following diagram shows the Policy configuration service provider in tree fo - [CredentialProviders/AllowPINLogon](#credentialproviders-allowpinlogon) - [CredentialProviders/BlockPicturePassword](#credentialproviders-blockpicturepassword) - [DataProtection/AllowDirectMemoryAccess](#dataprotection-allowdirectmemoryaccess) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) - [Wifi/AllowAutoConnectToWiFiSenseHotspots](#wifi-allowautoconnecttowifisensehotspots) - [Wifi/AllowInternetSharing](#wifi-allowinternetsharing) - [Wifi/AllowWiFi](#wifi-allowwifi) - [Wifi/WLANScanMode](#wifi-wlanscanmode) + +## Policies supported by Windows 10 IoT Enterprise + +- [InternetExplorer/AllowEnhancedSuggestionsInAddressBar](#internetexplorer-allowenhancedsuggestionsinaddressbar) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableFeedsBackgroundSync](#internetexplorer-disablefeedsbackgroundsync) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) +- [InternetExplorer/DisableWebAddressAutoComplete](#internetexplorer-disablewebaddressautocomplete) +- [InternetExplorer/NewTabDefaultPage](#internetexplorer-newtabdefaultpage) + + ## Policies that can be set using Exchange Active Sync (EAS) diff --git a/windows/client-management/mdm/policy-csp-internetexplorer.md b/windows/client-management/mdm/policy-csp-internetexplorer.md index 823af29f0b..28f3b3a7da 100644 --- a/windows/client-management/mdm/policy-csp-internetexplorer.md +++ b/windows/client-management/mdm/policy-csp-internetexplorer.md @@ -6,12 +6,13 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 05/14/2018 +ms.date: 05/06/2019 --- # Policy CSP - InternetExplorer - +> [!WARNING] +> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here.
@@ -40,6 +41,9 @@ ms.date: 05/14/2018
InternetExplorer/AllowEnhancedProtectedMode
+
+ InternetExplorer/AllowEnhancedSuggestionsInAddressBar +
InternetExplorer/AllowEnterpriseModeFromToolsMenu
@@ -106,6 +110,9 @@ ms.date: 05/14/2018
InternetExplorer/ConsistentMimeHandlingInternetExplorerProcesses
+
+ InternetExplorer/DisableActiveXVersionListAutoDownload +
InternetExplorer/DisableAdobeFlash
@@ -115,6 +122,9 @@ ms.date: 05/14/2018
InternetExplorer/DisableBypassOfSmartScreenWarningsAboutUncommonFiles
+
+ InternetExplorer/DisableCompatView +
InternetExplorer/DisableConfiguringHistory
@@ -133,12 +143,18 @@ ms.date: 05/14/2018
InternetExplorer/DisableEncryptionSupport
+
+ InternetExplorer/DisableFeedsBackgroundSync +
InternetExplorer/DisableFirstRunWizard
InternetExplorer/DisableFlipAheadFeature
+
+ InternetExplorer/DisableGeolocation +
InternetExplorer/DisableHomePageChange
@@ -166,6 +182,9 @@ ms.date: 05/14/2018
InternetExplorer/DisableUpdateCheck
+
+ InternetExplorer/DisableWebAddressAutoComplete +
InternetExplorer/DoNotAllowActiveXControlsInProtectedMode
@@ -559,6 +578,9 @@ ms.date: 05/14/2018
InternetExplorer/MimeSniffingSafetyFeatureInternetExplorerProcesses
+
+ InternetExplorer/NewTabDefaultPage +
InternetExplorer/NotificationBarInternetExplorerProcesses
@@ -1216,6 +1238,82 @@ ADMX Info:
+ +**InternetExplorer/AllowEnhancedSuggestionsInAddressBar** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services. + +If you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users cannot change the Suggestions setting on the Settings charm. + +If you disable this policy setting, users do not receive enhanced suggestions while typing in the Address bar. In addition, users cannot change the Suggestions setting on the Settings charm. + +If you do not configure this policy setting, users can change the Suggestions setting on the Settings charm. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar* +- GP name: *AllowServicePoweredQSA* +- GP path: *Windows Components/Internet Explorer* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- 0 - Disabled +- 1 - Enabled (Default) + + + + + + + + + +
+ **InternetExplorer/AllowEnterpriseModeFromToolsMenu** @@ -2713,6 +2811,81 @@ ADMX Info:
+ +**InternetExplorer/DisableActiveXVersionListAutoDownload** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This setting determines whether IE automatically downloads updated versions of Microsoft’s VersionList.XML. IE uses this file to determine whether an ActiveX control should be stopped from loading. + +> [!Caution] +> If you enable this setting, IE stops downloading updated versions of VersionList.XML. Turning off this automatic download breaks the [out-of-date ActiveX control blocking feature](https://docs.microsoft.com/en-us/internet-explorer/ie11-deploy-guide/out-of-date-activex-control-blocking) by not letting the version list update with newly outdated controls, potentially compromising the security of your computer. + +If you disable or do not configure this setting, IE continues to download updated versions of VersionList.XML. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Turn off automatic download of the ActiveX VersionList* +- GP name: *VersionListAutomaticDownloadDisable* +- GP path: *Windows Components/Internet Explorer/Security Features/Add-on Management* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- 0 - Enabled +- 1 - Disabled (Default) + + + + + + + + + +
+ **InternetExplorer/DisableAdobeFlash** @@ -2904,6 +3077,80 @@ ADMX Info:
+ +**InternetExplorer/DisableCompatView** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This policy setting controls the Compatibility View feature, which allows users to fix website display problems that they may encounter while browsing. + +If you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list. + +If you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Turn off Compatibility View* +- GP name: *CompatView_DisableList* +- GP path: *Windows Components/Internet Explorer/Compatibility View* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- 0 - Disabled (Default) +- 1 - Enabled + + + + + + + + + +
+ **InternetExplorer/DisableConfiguringHistory** @@ -3290,6 +3537,80 @@ ADMX Info:
+ +**InternetExplorer/DisableFeedsBackgroundSync** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This policy setting allows you to choose whether or not to have background synchronization for feeds and Web Slices. + +If you enable this policy setting, the ability to synchronize feeds and Web Slices in the background is turned off. + +If you disable or do not configure this policy setting, the user can synchronize feeds and Web Slices in the background. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Turn off background synchronization for feeds and Web Slices* +- GP name: *Disable_Background_Syncing* +- GP path: *Windows Components/RSS Feeds* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- 0 - Enabled (Default) +- 1 - Disabled + + + + + + + + + +
+ **InternetExplorer/DisableFirstRunWizard** @@ -3424,6 +3745,82 @@ ADMX Info:
+ +**InternetExplorer/DisableGeolocation** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This policy setting allows you to disable browser geolocation support. This prevents websites from requesting location data about the user. + +If you enable this policy setting, browser geolocation support is turned off. + +If you disable this policy setting, browser geolocation support is turned on. + +If you do not configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Turn off browser geolocation* +- GP name: *GeolocationDisable* +- GP path: *Windows Components/Internet Explorer* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- 0 - Disabled (Default) +- 1 - Enabled + + + + + + + + + +
+ **InternetExplorer/DisableHomePageChange** @@ -4001,6 +4398,82 @@ ADMX Info:
+ +**InternetExplorer/DisableWebAddressAutoComplete** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This AutoComplete feature suggests possible matches when users are entering Web addresses in the browser address bar. + +If you enable this policy setting, users are not suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting. + +If you disable this policy setting, users are suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting. + +If you do not configure this policy setting, users can choose to turn the auto-complete setting for web-addresses on or off. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Turn off the auto-complete feature for web addresses* +- GP name: *RestrictWebAddressSuggest* +- GP path: *Windows Components/Internet Explorer* +- GP ADMX file name: *inetres.admx* + + + +Supported values: +- yes - Disabled (Default) +- no - Enabled + + + + + + + + + +
+ **InternetExplorer/DoNotAllowActiveXControlsInProtectedMode** @@ -12568,6 +13041,83 @@ ADMX Info:
+ +**InternetExplorer/NewTabDefaultPage** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * User +> * Device + +
+ + + +This policy setting allows you to specify what is displayed when the user opens a new tab. + +If you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed. + +If you disable or do not configure this policy setting, users can select their preference for this behavior. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Specify default behavior for a new tab* +- GP name: *NewTabAction* +- GP path: *Windows Components/Internet Explorer* +- GP ADMX file name: *inetres.admx* + + + + +Supported values: +- 0 - NewTab_AboutBlank (about:blank) +- 1 - NewTab_Homepage (Home page) +- 2 - NewTab_AboutTabs (New tab page) +- 3 - NewTab_AboutNewsFeed (New tab page with my news feed) (Default) + + + + + + + + + +
+ **InternetExplorer/NotificationBarInternetExplorerProcesses** @@ -16878,14 +17428,53 @@ ADMX Info: + + + + +## InternetExplorer policies supported by Windows Holographic + +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) + + + +## InternetExplorer policies supported by Windows Holographic for Business + +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) + + + +## InternetExplorer policies supported by IoT Core + +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) + + + +## InternetExplorer policies supported by IoT Enterprise + +- [InternetExplorer/AllowEnhancedSuggestionsInAddressBar](#internetexplorer-allowenhancedsuggestionsinaddressbar) +- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) +- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) +- [InternetExplorer/DisableFeedsBackgroundSync](#internetexplorer-disablefeedsbackgroundsync) +- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) +- [InternetExplorer/DisableWebAddressAutoComplete](#internetexplorer-disablewebaddressautocomplete) +- [InternetExplorer/NewTabDefaultPage](#internetexplorer-newtabdefaultpage) + + +
-Footnote: +Footnotes: - 1 - Added in Windows 10, version 1607. - 2 - Added in Windows 10, version 1703. - 3 - Added in Windows 10, version 1709. - 4 - Added in Windows 10, version 1803. - - - +- 5 - Added in Windows 10, version 1809. +- 6 - Added in Windows 10, version 1903. \ No newline at end of file From 73219b51a0fdfb2e5279ae1f7509dae2c33dd91e Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 8 May 2019 14:07:29 -0700 Subject: [PATCH 225/737] draft --- windows/deployment/images/after.png | Bin 0 -> 51574 bytes windows/deployment/images/before.png | Bin 0 -> 48588 bytes windows/deployment/images/ent.png | Bin 0 -> 77540 bytes ...s-10-enterprise-subscription-activation.md | 64 ++++++++++++++---- 4 files changed, 51 insertions(+), 13 deletions(-) create mode 100644 windows/deployment/images/after.png create mode 100644 windows/deployment/images/before.png create mode 100644 windows/deployment/images/ent.png diff --git a/windows/deployment/images/after.png b/windows/deployment/images/after.png new file mode 100644 index 0000000000000000000000000000000000000000..567b29463626db095b588608f06699d6d25291f3 GIT binary patch literal 51574 zcmeFZcT`i|_AX2S1*D5oq@w~#liouWRJte_x4XjfN=Ycv zNkVU-_Zr$4-uHLzxZgeJyyN@p`|Iv8VC-b?tn#e6=A7%9bFKIKx|-D2Ze1fHBBFl$ zNc|}h5h)iD5#W^kD&ZR<{>cQwe}MZ_O;w`eUbbbz2U0r~9Tg&?vX7LfFRu_jQ@A_= zxf2mx_qhB6Oxkk#5D|4zK2}$G=3}vb=HDPW48ldWGv~gq^@)x_q1G1;t_#1vbLSV= zd*t`q2?%8G9Yi-o!8&q?t=g05#g?FSN%w! zHioo+qYsUp+(0NH^3NRmGH_=js0y)>7ka}*vUbBJ?!EhGb0;7Nxagaqg8cS^?>OT= z=Kad%UGMW=_5ZnSv~O_z>((RVAhP)=l7as3E2eCWj_Z6d2(QQUKUY{T5%>Sx=KlYC zTX8`A3kN)`?K+t}Y|>FUnhvu^Pf&UJ&BtgCG=S~mvBDK)seM&vX6owmD24N*xmZ2u zilKc5Oi(13obDqKzce30#*sAczu8Dlt90t(9^$jp#W%QP-5N+MJO4>%Jn&?lP$E)t z)U4uVs(7D*`%af$pqNl~RFNANEakOZi^z`QZ2N`ql8%t z#}C%$;qn_vX@U4<(-(L7yreT7PL4OGCpH7U<#e@bIxGT@7h+e7>x*k~#oy_MaWAl) z8PD-U5iZ{6$2e&-&*A5>Sf~0QzK@DmSJcdwQ_w!#`-|uPjI#xPAdlwU_Bc`>;TnS%Pwjp>HN{aQa(ZaoTvv8{Ar)-+ z+uaYXG_z7zqKiVP9M{3?H|hk0Qez;T2Epp29KQ20sT+}YX|C-FatPMb$T_&YQ?3pu z`4*e!uegdnp#R`DsTpg{zPqkC!`b!aO!TNnOI`1(ifevi~Ui{DcCcR z`QGh=T<4lb!8^(>v$fj^>+P$+P?JDQHPR=r&EG9eZBc+$1H0hvKkw; zxC|X%mD)3}R;&lMNU$rBDB^Bt+) zyGBX1HKGvvg`2(j37vVkoZ+KYbLnK7ZY9qMY*+&}rg^XJFFy0ole{?6jO2nFi4&eMVPcdKwyT{Tdxhkxz z%|MlO{}W_1ocNc@qe7KG-%wW~)m2?e?w|1Q-IS|mQ_4V9K%V&MmQ)w!J6B{WSkq>P zxty(=hyeJK?F3F!>Y^pl2f>^V>sNQi=gKD1y(iH}258UB-Ot152yRTT_#^X#6WTt0 z>8Sws!E>n);{Mx(4DF?l_tez=FdcYCb?ZNgTmD$mB+s<#)sEeFmH&j4Gqk6*7t4N| zcP$&!jeiPw<;kBemW0dJl`?GRo>sLupM1=^IkHRWBNbi+Es`bNMj|znJ<8#7f2Dxg zs=@g%2fX_S_rmU_2~=ThXEDK!DZ}%{P?f;1#E5C(m=a;7K4uGVK&T|e6HR8#+VgbC zs0OcccSV9alP4>;z-W68c9bwRgN`FETq1j3X1tD_-l*T49MTNIofbJ#JAYk;gaP}e z_mkRN?%sMJP(NWa`-qi*!6(DS9>>Ver!Zg90N10?aQsGk?mceN^a)Q+88{f}EJrgl}_ zVr7|={1&J-oy&dJHSWYB!sX|x{Z*MoNRHjv_|@IwnX1>=Y6VE7Dxz8N+AG1- zy_@s&`>S|cP_?S9oiKohGDal^iQJI*pB~VCH^RhD$q0dOZN*19o|G8`kC}G}P3%F5 z1iLs|jk1+`+>6WwpK^+*uQ-7JFbbO`rgki@3M!W#C@&N3rdDr(Z*kqX!P@aF?-gz~ zoBJ&%Ky1t0br_#0LDSK6CjEKNIfnHNzm7oYu1 zI~o6^EhY|8`dx2{k56sSft2LFu7!gah~K{Rt0O!4fm;8f!xgz^XQF3h6#h~ekP{dj zp6(YZ7u`fmnk_}8-U?%k{_~U3EGxO18YaFQ{#(okM4#YC-e@jyhulBPx0tbPPFL2J zzbNgtqryn5_*go=tjDW+%8qkCHB#Sw_0L>(o_Y_)*m#(}1F_&*tg2+$0kkNm>5%@& zkUlZxquh=35?zJ9H1O}cgu;ZgBSUetQt{8o!XiuC>V0J{i6Q5i_kmm`jJ!!=`p#3~ z#OlrXl_iE3>cLz&-`DaVK-gh^3fJwQoreq4ht-~Y`WDxN(A?9YcXlI9eLpI%#C&a{ z-SeCUv6cu+ugiTHv~U*xs8sqIyIN2Wq|_Smyv;TQ_8Q>*DQ<3_NKZE>mPphRkb+mQ zYP`2Zd4juY_BmeQCD$-^i0RuJ;KvQFnm=IoVg0ol*a5U=77!lkINI=36^S29j*wH$ zDG*3a{1qV3nuVk!4=YAI6dY?4eNZ#ks*>IhFJ6C=7oXYz-#;$=7=Ms(tiMs=j1`wL z=09;X++e7YaT9#&uH!CIhY41Lho-EDNjMsfO5fP0ZccmC!lMA@aAEUghbDb35q4|J zPj|q-NS``PqO(G-%P{tu&+jUYN*DV>3dINQYUu6G!1?%Nr=_`7kAQtOd7FhdG9zxR zc*A*5cGFQPw>7_iTSEt?oo*kzJHhQ9w<5OIEG!=Fd6SF$P$b>*7pxPN_wtleF_Zl! z7k*f}k|^e(j_vM_*2>8pk?9pC9&;WIcACEZuMK=;3!c>FtH#DGm`@Kq2G4S%GxP9u7fqXE3Onm&y>C+xT<*iQ!nfz?g zO}%~^Qz53IyN1qcCZIgX&#h0t9#-}i&eY^V85oBvAsqHP#x>WG4pPnEso_Ehh`equ z1=EBat-m*fXe^yIE+qk)7dQ7IU}fQ!exiL?c@=rx#96?^$x$80 zRD-U^nN`qYvYpf4AZFXV_HPrrM)zp~C8qgJIG1P}{3gHl{DuuXy8*76VChSmOo&1s zl9Csc+*IfTF9hQj$^~2REPDoRUKd?q@-322j2A#Ddz~SXTjMD|z{YBUT?ng}eXV<(w{u;5CvfW8QVRuXiDL z#Bv2YC{coqI=`kDG(a?B^mHq3Xh}W+ag_V2U=zLPD0UQF?%*~|Ay zdL{!^RSrT60>aVusWu%z8;|$%E^s?WF0RN>a&r6Pcft01%cqj)FlggcQCLoA`^8(! z?W>Vwx^d!@H|%Dgq>38~R5_x8)sx%q@$5xO=M=n^;RPwieQSG7;`kU^`O*E?^oK1e zxX?-`Ja!#9CG(p8TSy}ofl5owUVHKVgPDhq3*{R!u{`IvI92^A1WEQYkiSdA@f}ua znO^z>hH1<;!_atMf5++K=MPG(9`GsWVfXPQ4ywQ)@!9=9kCw9vo9;j!`?gY-v zu&KM_d~n3#TZhP5O}EJEFZ)R6N4IzWmSz=Tzd|HN|9@YHjhYtS{DXRQ8XO&EYK*W{$xrP_dT$J=y9uUiGv7kHLW*!0qQN zIOz@F@y!Z3n-@zY?i6$$HHd0{08@?$-RoRuoJf}(q_KGoAZXR=B~=n7-GGk!fEQw7 zuM-};dEVAk{^*0_6(^1*jAO)l8Pmzf$~Boem1IhdW1~beEz-}3_3{vn%Wc{oRcS24FU z61M6F6RRxm*>#NInjYjea?6hZE2HB<1fR-Fr?cJ7+!n*!OMpG};ax3UHN@|sBK2Hz zGk(~<_Oo{IQkx*n5i_wmCnoRF9)y-M$o8P6H&R21$be$MDty}_aZXM@Va~)5eu1w` zK4w?YO8~pjt%|9DXnaPJjIP2~kQq09b-OJ1x2`q|r}lSzL}$WeA$`9j_q~p+K()S0 zt6^Y6W3hU&Bn8N{h7p8uXK1}LzdP|426G}wJiS-xIQxtrug)$YW6tvG%sL5j@t9CIS z?92b{Hm}PcF|zOBfd(VLCCec7qJIhW#Dnk?x&Cpj+6~)7bJEaqM{Jo+y-1Y3Gr@tU zg;;+rS;y;-w)vzRT|!#`iC?#i?_^Xe%C{ulm!Pu3YZyuC2g{J#OM0>>2P`pw1`_?A z+#-gU=LPZ>Z#GvwN`}JA7=iW0@?hCcwwXGrIQkEg=+O7(3tIRiQM9-#mNG5HRC0k1qq*atn zyr9`MDi@7YjomMC3zW2hbWSG4PtOw;D2**Txp4jI+3`j4xd-v!?80WMVdF4SQu4JI z2{UHyw~J6JXUg%7{mYcC)*vREnXeBtlq?T{O|0!Mi|T{MPcR&d!H?2Sl)K^7c@s?S zmC`mHmNwUc5(`nYa;|Q1HgO^ABTF1lWQFO{O)uyk6<*1yVf`3j7MnwPT zefiec&uhd0>^)^0T6LBNo$u8`oUJvmZ7ZWhm9q8S(yLW|($0^bd!h*|srKRV{7q6P)#!P=@D;n=3(T`@>cV zyAy|IyUNcJQE&U!w74KKJS<}=sW;$kw6;<2>Y5O&OU!@Sd?)5MN6QguN*HbObUeFh z=1FVPLHODW`%wv>tskpz3Pl8@soOow^$uif>bezhf#iTthi+==@dwNovzDik9!i5& z*OV21%o2QddlRXGd#t_fj^=x?Zar9mf`Y_Y?=I;OSU>*V`A4j47_OoSbn zoKgVg(IP8Yz0lIoomqVj`dCGq{6V4T8!u_OpkDJ=%aMifwZaxbsU@slHoP6_^vE+a z?O>}xOjws&r+Qg3V<$hcJDA%t zhJP2KZ0==CARzl{jgI)2|J2E(j;A0}?_y6c|0G!haWo^L$sF=30U`!?B`vHf8;$Uk z4$lgtFtE^iv)%kdiNV|`L7+sait|Cwwg^h~K-(lSSqj3uQYMQa5*6YRDyTNy%P<_s zU%xx6G_pH6!SRlV}^NSA52KUt!%62Ms{gs(d9>=p_@};!yvm%if%03Lv zT&SH2ufQbZ;MeYEZ^~5+`Y3s?<v%b#mZE*v#VU7+(RL({=N8c#6EvO0SJV!Mtr%ImU*Y@|uR4W#c7h>=Yb{r5 zbZ5-sz$Z^FBSW+Q@~bAq!qH7dB4N@}GQZduTGgPOKf2%$4D_X=znWJO_`HbfxuxPe z%5n!aAyr!gj=_R=PuVJp%$QI-%H1c6&3Pzaqu?WW->j01t20Aa)D~F zx4c6Di&uE>o}qXiQOpnaQNC8e`UF~89V-sbA`#CoGKallK_JJcl#ZVslA<0&2`eij z`~um_W%O{Iroo+uZe)Xp3zwPsZ{WRZ5xDT|7wg3CX+OsC`GM3* z?b&|L<6R8+HSVszdo{V|68aNV@)8(KZHCFy-sSuWumv_O=uGNre+a~0%UsG~%8P<- zb+W@7#cX?04(vqsv?_E+AsSyUS+nOfIbLJsQ8Ds@oeg6TkCB~XVw)H$NF}sZ1&~t@ z90@8wA)xPUEPR{_PlRYJ8#!+EHA5)lDgu?y0;2v9fo~mR9Zx=&D{K|X>LsU$ULkjU zp154GNEfQxI8kIdv6`cY#eEIrC~OWa7nJ&zYnQz)tIHUHTkgLC!_SiL|Gw)VHny;) zcEHkIS7AeIHP~85Jn58xb)^E;Qek>u@$I{k(8|SiwMJlCNAg5B)ja+e8b8b*Xu*um zG@_&}!RHNLoEYEbij^(FA*oyCB?KX{GLj!14d3xIY;NqH92%lk`{QYix^aqN9sTpS zUT3+~>tvu>P!eve9U)BxEs7lJ5Vh;qbuB6G8VS75^gLDL;AyyBR?%9yp$PBe8zgXd zOC)6G(q&r?yunqsifR&Ut+fjIQ*_!e6iK@?l0^PZEPDAN8lkd2y^E+n03i48V)#*Q z_sQw>McmN59tqQ*60sid6?Pva5XA_srRua;TurqR!PwRoqZ}P0iCS1MF!Uu;A8ej5 z((Z$kZwZ_1OF>Cti04nWmVWJ%P>|daz+TbS`f-pz`+XnC>|tJbj`-g(0rc8|!oP{p zzZn+~vR$%wG0K&lr4-=CJcp)@oA4@B4Nj zvK%iLtDBr2^h9s+y+`)R-T+9%@?onpri+#Vpd8e)y4C^V!2j~im)WwDst_P#QBOqD$*Y_GK*=d>3uC=01Zgm?Dp7s*vkuT|BP)*+82D zt;W*GkKo)fX=6>0K1TXAhNo#zV5LPA#G;;dxnYQ&_kjbmiDD3gei%yZZ=XQ%W4dbq za;LJ2rozd;!qi#5r?w#XepU&QsQO?2)J6wcq)b1g+uzX|!x|18@m}_xZ~ZU z)c2NgN&G@4a{LRmT2s%saCsG(E%ixX+TukD`O@Y3O0A}gG@U#Dm5ZgoiLmuoud#f^ zprO8#am&?Jd(Ms$L0WVLI8#iLpdgd=hV}>e{lzoQjhV8Yv34Pe*88X*h)%SqqgZ4n z5>+W)C{oGw%MJ`?CanHz^yywb9BQp(hzgCLm|m^s0l}o5%_<`4PQEaVE@Xcs0#s&7 zH-pi^WN-aM*)UI)xLoMh{T@-Q=$cz}!*&YD_-UmEIS$BQ-p49!hS^T7w^v&0Q%dfo zYTu*ABiLiU1itvfZcbU~%3WC90w_WCI2>lDF$t%5%AdR~9=0i@8|D7=zu;T7r;n<~ z*Y)R>jyk`V*+7u-z?%hGD=Fx#_jWxu=1K_&s>v@r*er{-cV@=FI2q~igt@-g|3vZq z=Zj5-=s$=Jnm#E=-$QlC$f*A7)RnUC>9y;#mU4CGk&h5DI_y@8VRdPjGyxs!3WV-% zc*=*C#_xf}0v(E@?}2d6h4S?fyG6&;6gSovHvz;aLxv!(`i-q|QD=3GU^kC47o#>- zX><&4(&1WpOrW6O;uI|ubQrvs2SGR33}ivREaA0RU@|IZ>N2j5eI(@4-W)D9{kG1} zLn4h278^MBezwW(?{GcjQ#Ek#cL^qNqtgYha~%{dF}Y4Rs@DMA^{-vi=3P&zI_22X zLlP+N?qeuGOY~N>@O0T{Lpt)Vi?a}c4o1)JlPt7%z34i#jliGJ?W5!ciPj=lGC^?J z`WoW(`Ro+;-=;#(hW#v9T*3s`*}E?hPsB$9J-)R=Dixm%F>P?;-#kDaXN>lKJ?hww zYp!4X<~A7V2KL1;f|ta{>V%mtA>ZHiT%T*H??_0yiq63izj+)qy+@XrR1QWsUgii^d?)@T zxc99@I5q|%J#Q>pPW~;cWY9>jmVfz#%FsDc(ei*`{t!d}102GXvwmF_l%sy9Tq8TLchB;w{9mX3f&$7y=W?m~@)S0o8dpl! z!(-deeiR#qTfYRnGFsA3+bfzZ+VwPuc&x?=$XT6DZV6M%%i88LPW&xJr8^|U@pC1B zO^m|~>Bmg<)p{s#XU1ugtfvVJUJ%p#P6;p5dOzR#8Djht0ZFjdVEHkn(5H$$N*dkR zXHFUQ?NYrsQD3mJF_e|z11JA4WYKb>Dx;>Fc>B~gWj|;evRyTmNYqHlaumo>bg~WB z^)PZ`TvU`|MiIQ#RY4aswGpxgsKAwWAQz*p=l<7K-`D7_v~gdxGjZ2!ucVt?J7O#W zx2oW}A=zvD=ZDQo>wQ}xv;kZbd5ejG%ZUT)-0r;ME9+u2IRs0Jha6SjO9G5GxXCa1 zEkgVJCo8_5N=)t-d+VI<>0L&{QYx?9t%9Hc zu2_$;+BOCb5r7-kRKM%I&725MhrUc3g=W)^Gpx?Nxas2Jfb+^A$X_P@1_3>Y&B3iV z_cadI==atK(Nz>at{t9y*u1<+sYs_K!#rDg9a{oeJ(Zl^zR)>qO> zfJ~=EW%&*tbkGRjkIB1IJ%C>-3oZT_+0<%kH5m~!o6SIZIdqyQW4{qm9ZFzPKR4n0 zE#%dVf-L>#9#!q%EM|Xu^;I>9l$^OfvqX#2*_!>Mi2n;D!C~W>%d>fO>EKuVbnP+Z zv`!$?=5X=lO_rR^riRN#c6M7`ocK4*m>Y@Vye5~K0IR?u&jk9L*XVqcg~d{7ByWZV zrtPm6IkJM-$C)b1S@scyyvn3UJdnOWKi!8EM%O_}U)L1|tB!R6ha`Df-pBgpR4*Bd zHya!`<_e#NL*aL~I*kan=84az#dW}pq(ZV!uNH3E#l7_=qh!3TF6ht+f%OI>7-BXVWx;4iC0cS zUSEML8{eHVu84kb`GHk{DNW#-uF`bPoSD#$i{=+9Tu5E8-|AAb??>5bw!w~?rLC<_ z;47f15zu;4YRk51+%_Xp0{W$h#8&n^%6BELs>D`XekwA}q5Y@u(lW(?suQ zKGKgfi4*lwvfKv(qdnz-2$9vWqH#gN0dKMJQUWU?N69u?v>(6F5$d(A{cHcz>J_P3 zzZSeq_e+ak2RtbCgCb=UBSdr&98{dUk3ehn0>N)qy!I7~*Fd)g5?iXmm^c(PT_=8K z&fa>eL>u+H2$J7uHn^4PIZ+a;8%wIb#?OaD?bwXS2B(b{SB@!OxNiC&bBEhzeYDed4>G%3P7Y+$d`XJ=qZTS z9!~m8Z!hJ3%mY9CySg|3DnQ-FOkB(wppJ8P>KGEl2eJyv{c@n{3WBk9-)X@{r}V;sOUGRvfZBXiEo z)9%C5k@=Ltjq!aevb7L%G5_~bzc+)Hm9&M=fAz#dn-6=t1~+Q;X@Z4HDG*(bylrK1 z#H7x9H#u!d{8=and2Qv%YZ>Tw2J~|-7fNT|vEGdVK`XFLuTsi`t~FjU3C^RosT75i z$xW?vm)g=YYAK{6Ut1}mjKOQ=5yZ<^>%j+XVU8Ds8M_*4K;PEF8u&ZHsq|wEotRX^ zgmFL;jg;8+R|*MFg9}Cjd{CMkdZ=};QZ0MFwS;)qFt_H*-$fbFN47|WbuTCMSmk#I z@~E}k2ndDl$9uYZldl zN}t=Rf!MCVZrc6pCFz&X)PuzAOx?sz-cvnXe61y)ObvFu!DW<|UjDq%lAbRRIyyOA6#v~D96_uC-&g{v3RXg`pkTD;^n9?sjq5%V?&3@jhIyAr&_Sdp{* z%0)8r;6lI4w!6{g@<_$XVm`;B^=$aX_)IZfj{K3iL}jyUaX(hhJ`e`qDC&cLaMHWW ze#OY52Xz0BhN@%GJqGm2xk9o8K?vt@FaMf;+3Ra`0=>HE?~^42`Ps9se)#Yon<2(p zfA>C*d*xleOF(RN5tXrMeMU{dtKaB*ro$&U3B5fA;R;~g{RwIRwIPc*Q>W9pE>qx6 zZC43!@7Mgc((%XTM(^kUh>?w#Mc}F(-^KK#h&J#%A}D3jc{Jo7>%o`x_S3NZV~;&5 zSaaCL#5DgkdN%(ydh}?dQ>0gC=RXbKJZf#^bwt!ZHO8jex>8M-ARW54N-^1;X^!@M z71@Gt;$I&s3=!WC1qjo_R1}k)`j2HuzpPXX`lrUmOa%ASRQ#iu6bWd^3u^phL!6k` zA5i@#*x-ok^z`=mO?tX*uOnvu<7idJ!(fl(_o3y~x$Nz?|C6Bf8xh2Ledw_3dM-O6 z;y?9Q)AT(IR%tlJ*YY}I{qBD+xlG!sAR42crbP~=!7y>2_Kr%rW^C0=Fe*Z zg8l{B{wG-3Aa@CEMQQ&hv~qu38o%WK3Ia?}{J%mN1Lpm&y(;hij}s8{giu{V@_&NM z4g}es;k@wivnEVGkVcI&_)r{_);;;}szR{vM|tXZf~pXUo#?Z16*K)0(pZE*I(`4E z*Ir7ozq=g&gSsfkAXC4=U`51}CGGi@Wgh>gk_h!A9NXf5G3aRn_rK}sWCZMVNmvrp z94#uK*@Wo{tCsY?>7a7Vhtwt0!$$9&JcdBQo{MoDP`dW)0LzzoI?p#4uydISytqlo z0L8+t65_Wt1lNo&g3ayGZB?6N6lq7$6!h?`@75nRTFJ1Z#Z>1FK_)Bbm2RKY?T$f+ z5e3|O>0B(j`RGpsZ*0CIWM`Dg?9*b~6vvWt97P@SYTR*ZVv~m!-m-CyU57o$w~g9# zC)6*9;M#g=FBzuA%5T)%?h$$K&^qBg)p##m?os`AJ8Np7Zl=ht7W3fRDsmB z-)Ex#m^E{teL&~mG(!<$mKSf{VKK6@wEI(QvVQ7pL&#T#dEVe^#N1j%Uk24OTS+KU z$ZePH-%QS9+yZS$cR5eeJV!u17lZAtV~W-s{t7#tx3$0>qIi^qD*w-A)Q;7>3c64PI;_~2x9OGho9;8^JnOm35=44~+pq>(xVQ;S7jLCHaqkd;VHfUR( zG_-iPpI54kdKm%*ESc`Yw8nUQbtp#DJ2?CWCv46Cx$j{j_~gY9DR)NU=F^?_Ec0^7$AxlzsjRTLer#Elkg9uLin^i}>DXfX%fR1g)qJ--m4LRT>&U|ex#Z$n~ zy{vs=kVgsT!P7^Zb*sgTL6~IOBV!BSh50o1Ui4?Uc?lu$TWC3i_*dy$HRMHwOz0pf z`AShPZEFFYZJxvx4;p(c&xxppI^E9WyiOa^qy+<+?3Dz%$e@J>q zM|#w(BhhJ9k7%NYX6uSP%tMHk!iZY-b99^c2DDP$MH7e`qLxmh_3W*edH+vi4>B_S z9lh6`JM~9lKEYXFZe7tG?m(7Md(tpL#h0RxbC;)Cdk(^HDD&zXF+I_K>t_Y^xuRG- zStP@?-aswBw7TNvbNu4^edjChRjstup+nH$H;o}R;Pv*(@z2LeP>yl;bDZ*}nZ?ax1a=YE)sTYrLf2{76NpmD= za4lA=v*t9AYMs8FerBZ!e}|Wi_^KuWIpH7eIEP}eSK*fA#9$9q^Wr?ARzTefw_@5P zLeAD+v;9Z)BqmL7?Omtmdex}YhdW$6ApvXA5Lu49go&Zrv`*&m59S3_vwoCE%gqP*|)g(=+! zvirbP_)}*X&&tQz(uB89rnc!s|o~^mu(f8D*>jA)$Unq_7h5 zG*~c9CrzA`r#L%p7iJN;lO}?g!8{2}?Id0Mc&4j`yQKr&Q|Y~V2qWY0vAP|!sDuTV7xyA|pKy4_>ndSqzU-EA^u7_yV%Z&OOOAxtzN=g?=u&RSWIX59$EW0+PBW~N7Huri@>0_+#B`Ec?BJn7}+_rP+NDqM=ihUVDB zGjPh;2|_y8>rr+O`irAX1f-Y0^8K|>6bwU>I%Y6Aaa`3MyvFhpz&W?fK>hAJs|P|) z0Z#y-u8$O9x4!D3C0vj@cTAn|XB?&hZMC_^1ns&Fyz6o_a!Gw|~3`6Vax=bMj7 zwcAsl0e4h`e~x(8-f{$G@Zs4J)FCmYcrhggF1iR8jrV@ad%3g;&K0-i@^4&+IsR0+ zn{s#HO+li2H)20u$)Po{YIllPCjOT!@-6v5h5b!PtGcP8q@%o!%j_xltf)os1pw<7 zSW1gffeChKkdtnA)4>CU_H5%+)lB6M$$Ld{RX47NiDI5lmXrs8(*BE=ao;&l=IS@2Urga7sqj~$c;0(VhR7#K-AqrCkmWxawlU!c`bmWIvf zyhBAJZ8~UYE}Hw5)-v17k;bnpzEy1s)QG|>u-ESCG-^66Nw!m2j+!tnNF4mGr|aaZ zJDMMPz^y#a-CEhf2Jotm5v5#9a%N48nw?uRyxn8%WP zo23p>nI?CTS(ye>Yw&{KN3?*?XYtPEWxk0M-0G+$Z`f^hv7rV0o+ldw?vOHe!{7?U zgF^n(Ly;lFH&2jt4tW$DbZ2)_l*|HS(ap+VjB9&U$7-n&*=)E%xW;P|(+)55WpZ6J zvLykS?pJ0xje6wC^8}GdL(Gf1e_OUE3>z)0 zcGQX_pcO<)bKb|p`bv@PAdCccp)NeM5L}H@AleO5=b-x$qQ=;J%h}d;~$}bQ1O6SejG$v-#d{gWQ_6PM~lWxcRaC$d2zT{ zoX|VYgOH>f&UGj{-(CYKw3GjKEJnThwVmSEFX3mN(JV{l=A*R~1V*$MWMnt`EV95Z zWx79~77-mEyvlZ99gsN3qfGwQY|8!Wnn^S{WKmK}CJesuA!)r-OTxDzLhrl0Av!YD)jaMG?Fxmw5ec= zgHPiN0XtT=nq8mLT}6rolc>vb7#;TjQNK~dZ2BAls4^80TM(SD6`__i9m334>y@E3 zrU#8OS8w!`%c0gaOKuPJ%|%yv0X*Y7GWtiGer~#{D8qjUtSKfTKKh+|%f!;#4^%-D zIEF4wQ;KkeMA|Qc2zs)x4Rpt(FM5PmB+C}5aCY46_#_%OXN=X zFoq`rb*;&v+;`T4p41dwx!o=_8o%a4e4rEbZItca@^w>lD4`L%-XuLu*tG(D^4oG>2EgafA|Oj zt5s9uR`iu~OsE2VwDm*q+#z0e$padbby@n&tZKLH`q=F;viYVNcuZSeta)*#`wBp`C(qehBd*_%Zt(=Z9}mi9yqFd)Mto54!q;kU?1P^|QBL+%6Nujg(;Kj5-Pe=A4CD)NX& z`)!NJePtqC;+{!VQMv}+fhF)`#giL1=S1=--@=qR-+NV1+b_gj&zp;L2zj8}iA!45 zQ%G<*C*)Bwydpj$HXVfr%_oN5#PKkYuec{097H$<#pqciTMSBtKY8V+Rn$+C7WQ<$ zs1L+6PKG@HNt|D#sCtp3_{DVtdER>dTJ7F->dE4jz`Jd`;#0e(scV9=f3tjRCym~D zaD?L(Q!s(013dxE9xCnH#S%Ezj&HF-vSXA4B66Gp$$GzePT(pULma%T8>k57_J6eD z2K;tAaL#Hg>&dMJG}(ijZz~5vTIpNqRnmTbTMR;u%wV?<5N7-gKK|N%%bnr7zr(~l zXC=0SGHZ7MSUY0UEoEI`NB9KLcp7A!bDjI0MBU5ZMBgrFF?_>^7*h#v{f=v28dqTF@#ssm{egbl>56rpRTcKIz->@c-lNnk)^(} z-fK}TC!M7%6SR(E)qGSjj?TK7kg9pR4aqcOZ9A}W3rEb za-JvfsFRIdWd$Q*U%q$)P&G>2X-`>*v{}<2gc`gU2|prpK1#NoPN5@fp&4uIBttv- z)c4&W8GU;sHb$JveEa}-jZW+uI@-wQ)|BTOIQBM;qFfIHJxl6ZATNPJY9qwuaz81K zz1N=GVLDrz&tWLh*(F3Wc1Yf5Mzj7ykz)^?!wu!pB5!r?*`b?WZa)n!Wkis~R zqD6Ew4mcPS|mA%${@&Y_333qFMKwCax3-Q zoM7A5hVi-I8}FEu#)}=~kbT08&!ls+WL4wdWot4o8u^}Tg4$>J0&!Z)zL()eP+ZUs zEyp8vJC<;4(4OUGm9={_mfGpIEO1Ir{PNJjz(+z;124pb66BC#G@KW0N;-XEmqD7G z(~StFWVv23s>6V-nV}6HNu`U`=D<6DS4v)E(>(Y9LBf=E1I#zCI=>o6*!@??=RNM)G2g|PIsVj0-3EO` z5GZcXG%z#AadoE7y71Fo5v7X@r?mO}i(P4mE8)S$d3V@f_}nMNNsDg7u8vv;o!Rtd zC`NC&^hl0s6OIEo)VX9|x+WX_Q!B|h#{+id=0BvUvb;)CST$=k0 zZgrcxM^)bSbPLR-KkaOtW29&#Ltfp zbpy9)gT$+9_b$U?Hp(2(z5XuO4tD9wz0m^!TzJ4sKnVB18vt=Zqz4Z_(t}V8eav(9 zzh16M;JJ0li`fVMl%rKw{k5qb>~ndb!2j!|7Yd*ES<4%)=iGX6nEMRF2mm`#W-|KU*pNv#d3b;q+`&eFHUk$=0)6R5&I!5 zAv{Asm#}-6hlj+i>u#b1rM9i_-GGePrSPL@qL8DXb#&T&T$>}N&J&fAABxeDZ^)-Zp4^lc|rcSkBw{{jg3Cpg6d?OoT(g$C| z{5S%(T7-NrtKlhpdpXYJrB_K~D7n?S9y~}7)pKZ16nWB#DsEGMyd@ch5@`<5A{-sT zIhy8`52MnS8p+$P^cTJnL*Lns6})U^6xFN0j-!y!Qy+=!_PrkSyR#i5A=dF&oso~# zxuSG{_*dogMO?@O9M-uRI-BE6s8>uNdG`)aWK49Gy$w7TCa5blY5S6p?nB^ibCajW zd2cCf{Up%=MizsQ52u1I@&Xp0GK{1N?I6h4!u0JIUF?nvi3HX%{WoguIo|#dsh$69 z8(8a(B8+r6w|j=Vjc9q9RCKp1p)Fm6Ryw8GhJjmG8Wq5i%&dNr_{^ zVHmG>PkQAy)6%>!_F?jUg@VdfsSYKLh~oy%j!*HIXHVQ7x2lg6X{rHz3nCDwVU)6j z_SeUB`+n|en2R&z!*K=;&tLKiDM}(t8C$nw4L|yT4TBPz@1OpObkZHv3OtI#4(xf} zWpx_CyQG_U6)H<$Z@mnWUCM$DTZY^(Oy0 zP9ShMv`ad$V>=ety#L!CsIa-?oEk9ap!*tWd)(K2RM{n+;Xd2G=`4F(&{fUh`oiJZ zH`@Y}vhag=Z0ziR4T_zkJqVLY#xYbIT+DyNokE?#DN!9iJ8XdW`x{{UrFLHRcu=`xJbl$<;`=K5q zP5grdfv}Mh!`Tn}4pJzMDDX9$*HnK!&ga}u;l22(nI5|s3pYIT);o(|JiN)*9JEt6 z7x;SaP`~Iqk;)zNSKY1=nd6n5%28No3xLc=>%3!9=6EER#u@)xJm_4~bjS5OnlWE?Amij9Q7T6r{6f9$< z#v}b&$*Y@`+_BHsXGSzauW6$vUrP0N^_slfPAda^>?V);<(x3R0!z{`kUx}ZZ%DRF zC*L_XT^y7e*lawUjFvdp6okbupr(fO(zQjWSx+Iah_Ta^hHwZ-K3gl;>WpHgajhJ6 z%c<#jQ7CgTcU^kIV=zwwCMoy^r!-*QuZ5w5)LojP>IpAwcMJtV@-j)fN5ZY9)b&dH zN1W%5btdm=HoP*#GZO%7sien5 ze+r8}ZWeY&KPI!}X*?L?9FODRQO~qzExgnle?jG55&&}VZC-4zsGf)J_p#p~p=W`; zeT@q0mA7oV>-^ftAlL`5*;G$YU)nF7R$p=%D}YHwuz4-b7drdxYhc8IdvzM8FYC+K zf9AM-g%$`J_^2&CqB=1oM5KCteQrfad z%yu%y_)6y*l81LXNxUb_c|CFe>R1HAApAG$w^S*ELro=oztH|jqH6tW%ae`YI7VshM5tGU1VA8F3@hTW)i=H|FtB?8H1uBh$_q z{fQPY`QCvtx@*ZLJrZ--2%gFRUZ6iz$SWthlRwxg?e_Xeq{SPTz2(C8YjU|vzLne? znNPOt<4@fs=1Z(v|0oe-=e=JD9A135vInE9ZYs6Uh)AsOdmaaI*r6j$-trJNwTus; z#bUKC6GmT#P``VtweX($bP`=aV$|#En?HT%gTeN^@CY1r?^!m{$saRyikE=i)}|vi zoU^5bs8^-s5crm?dhPpFwAfhr+n=%w=C?o3 zVviOr;EAR@>fWNsz8!088r`WUMgEE$RuWlK;6&l7xYvpWBPokHakGSy-@<-t%>vC+o86 zEmTXS?0&lT_LcYvkmCQI?U1^jE02)LEA|J8&+6>5`PLZ}Qzxd5CIA?T!9_X=gedyd z74qdUtxMTLdR_-wK`g3awq5NLE`x?@`@P;9L7{tUfh0X-+;z$l(M+cDo)-hfcP{L2 zz95I8eWRLbUI<9gg9>zTJXRNb2i6IJ2Cr+CX`Q#`#orTiOSd_ZJV(YYqPDN!47hn- zU2-~1Z6DQ)YPGoZ{Pyj^D~H~ueRkPansojolXWp&Pss{-A|w|JX&ZJ^_EH~sjKGQH zxTG~Dvr+tpeoyuK{9U+|(Oi@6^~B7M6)j3B0DSNgW-83uY5U1^0Droj>7YypQng9TMs# z;9x8?>09$sRIfRyH15ZoMeU$T3v3zxs6TO7cVEVB(83;#@TWUPLX<-mVcPL=C3ZTsg-P!_V@(^INB7gjt=T992>l%~lolcg_udW{D2#Ck8nK&Qq@lK* zo8sNhM$_LV)^{s6$3Ti@ph8+Vw8YYI_fG{xdcM%kRrD=>J^-=BgDXy{1EeHpQm-`Bx8yAd8<$QB_dt#!AVk^L z>y@Kc5v;RdS8{;M$(-D=L(KE zlE+9#AtfSsXnnHOAjr9z1r}X=FlQvk#bsD!r#L|1hg3#vL<6B*)o#`PA`_arKY8ec}cpYeD<%R z6QP@DVW|DsxAKv`Uf;I+m+!`!!(oN<#HK`AP#fHkS>#RkmH3?||D^4VSZSsOVuxT` zGtpbdU^TRf3O(O5j-{uyXjQ)ow)M1f6Z!Zd3&}b3pP3jwntx021_gsd;W99P>1s+4 zgP@hqM_B6AdFh;IL=iW&xwUjb1X|xccazPO6@5X{L77AmEz2Ji;EaA=WQgJI|GdG* zdNldm`vIFBEf{6;Jj&N{p2s44`?ZY+!hxm8M2s#&o+GDcXI5GkZYGs7q_$h~kR7OT zqX4?AKd==FezZt!aWOY#Ioyir545~=3TQm7vqwA~q-f!&?s!pF3a$Hc=I*!pkyv0B zY!%$dWr*|(9+0}+Ja_AE&&6VCMtxRfYLT@L3HqIU;RpO^bVd74@`!Vgk)_mb=Wxwf zUwoHXH=)axZf-A71}i}fdLjD@6H_i-o3 zovz!3@qyAYqL00%}Bd3KMh(}>#@D_SFBkDkluH`PX*x?msIO|BF zypeM>IZQfb`%WCeVQfo5gt?jRrMV#^MbmatyCb>toGH7O-(A1v+<(;^?6%&2iTp|; zfz}BnC`6vo4CkVkONz0Yo1sph>p#oNAZyOT93Au{QrDW$;mXJ#-f^)YdN`;BF+K~w zuBATrRt zGD(l?*_$GAl6Pdl+D(m?n2c2vL^GDwv4&+8e<1QH?v~?am0rJz(cLRNvyk=_xQcB@ z+u8UvYmD^$7HLph-0Yz<%+~h`#)-G((M0=mu7o{Q7{S=k?du1K zZK(<4#@O2LBv#Z5#qYAu0_dGggoj0 zy$ez#!9eyGNZ_Q=FGH0A9c_bN00hxa_Z^bn78|AmlWv}z9l}QMk1T&nizMe4-@A3zno3EA^W}v5?A2l z>di)UrqXfcId^Mf;R+E+glsaV zD$RezKM!_Yp0#c7cCf{WidCNR z%Jpy|LRQ*|ccYgUi@j~lzTvNL+6${c2&NT!c9M5aI7(m$77{rLvRTdhu9_GTf*UqU zQ6y^=*j9MHin+=8&`wWCnlt_V8>O$RJR(c$^UIeYkhvT|5q1)C+A{8-(6EK3l2B-k zP^Vqy>Rtg<>w=4@F{OL`VvCKkv2f9b&^a+yX##cH44I^v=Y6-lk2Nnwse6m74%Dhl zv%FKC@r!FE8ZfWBpL3p4S4YA#otVWx|4sqtmC+|6ww|Jb9*xW`&2p}ZT{ZA4xoIJm zOKCd=$@Pt>ZAx`x~fut$xX8Mh#UM|;uL#*)!>^cIQeCSB_ssV z&$x*0AXApnDdnRVvFT^QQkjC`6F^GF8s~6MsY&dk7Kdp9^6WK_DnxV8{I#XHbHZKt?|7!zbqTG-jWS|Kf`utKZ z-DEO;S6y9bhlWH1REV4@%j?Kzz#oA`$_6hCcw(&14CgS13L&8zgdx>kA?~CQX~Bmz zN)BW3nU^qMCX3@CWN!!vH?D*~@N12%c3?|+=s!>YB9~~V$FpKnT9Q>Et5_p~@qUIu z?u&<^j#tkf$|R?!$f2dBA(xKAOE8nUwKatir;DYkZ`3xsDCboUQ@O;D%?<*Jg^Y-( z$#4#$^SBwem5Ev(ZSTZjPV|KQ4=d_o7@{=?Fcfko~lhR*tiN zwy#y8?Ow2I84*Og0Ar!8s{73`>|fgmpbBg)O$igJF$JbSMrxK#bNUG{m;3d5%!R5 z_z9p6EQ}x|C7)Dt!Yz(VtWvGu;P%EIvF)u(XFA}*emDB}*63`P>lP`Azi1kt(WF~U zWPrg!BP$V!DY4y=vLeJ}LlI3lAp1Jvp06}PU3!lA9PBDg@gbWQ5owoJk~i zHr7LP{JHp1UeSso?TULs(8M=#7p=rUPA3NjG>+;qp*y<6ngiVS%VLEOP=;A8a@MGu z7N6W;&3e-mqN7^DN*K;Yx$Cx#T+anZ)IMS2konFJ;D+sx5GzfceP2o&<8on42v$@A zk~Hb8EyTGCL?oK!d`oFUP=ix|u z_EAK;s#1cyFX!TnxEV1?&{LLil6i~k9Hza-6?V)bf=`IoEGfpuTmxh-U6jR`X(%MHC) zFp`GZEXmEKXGhJXx-{G+o?}WdsL7+RitX~xM}M$MH;rf{PqZ$4k6W<);ks?n8gjKY znFFpD_N(Vu1rXpekCYU0F{mg8yWZW%x+u<%U2jdY@@{E#Lr{du)dtWQ-s^Odud(62~<3EC&f*XU(Xrig6F1H93%Z|Nq zI*-!IvZQnz$_5i^9L0*z@O7fK_$9FG7|9EBGOE#w^y+85l{FY)4H1Krf_8N8$~kRE zS>N0|#zBGnPMM%D%AHN5KO7AjFQ)FyBS4UM|8hRTG_p$y7eb)56UocTaO`(NwM}p+ zD~`##2&_q~q*WNt!6jV$aq?zlz^!VGfAX~^$@T&5NYneb4ye3*1(FA?>^chVY@Ik$ za2Pj8`>J(oezzApFTwGj+&WZVAKo&{ggG=5A?vQQf8-6~5rJ;sjJzIf%QoV>DJQW_ z^XYt7pCBPoq2B>aYT2>=>*|sUUjJkX&icRIMUDXaYmZ;CXprVK?ds3^x&oxSWKn_} z>@UiVkLJ@w5K>I9GE+y=!vvE#+6Nc=KjUVBzAmVDMpv6sG0^cSGD4$qRJ5Mtd+JZ7F^n%b}uA*dJl5*f>TzwU+NY<;Fr#8#6;a~{J#zF$x>_|8e zkyK097@L54&st5?>$T@HQ6b>o^jA(~n_+PD%3CQNelGrc8(z$ICB;I&PB&_4RtV1h zl^>h~`F0qM`MEkGdOp;|?!M*r0k>4Z*@wTi=4>g$oL2;n3lQn6kiL>NwLXJhCwSJV z6Zg4rmg3sEN%>E$ZyDRmN|Y=;PN4VMsA=7t6qul(9U0&kZ+WC`5qj(8hnrHSVU|Ez zaA$~hd6(t9z4u77DaFF|=Py{QX^_6lcJHpq;UL$ahPeX1tg*#@@e2_R)*|{}yDxcj z)L*92f@4n22`vQU(F`eTVbH-Y3$JB;gC^j`O4czzZJr1N$NwUZYu zBA6<`2U!iZRzQpPYb(kklFQUd2Z@s>xcR_wFZXkB0%c4nsTh~EJtJFM;fp!4V${J< zY~dd{PSyFO7y_244Z6V}*GIm^W4&L_b%Xom&{or5w+OV+Q@>ott(^TSvE{F;R;LMz zQ!5$LN2(Ivr7V3(UvZS|AhR3KddV^&J;b}rtjU{fpM1UjWfz=ZhjAe z`Q)O2ge`L^hDw`@RW#fBP-)E!SF`#)QODP$vUlTrG>a4G0sscv&{29+4=8vBv9tQq zUO>__BuCOSTj<#spM~kwz8`H9ks&d^-%x}Y4DTiU&@ILvAu`yP9rNXybb%q)fhHO7 z^JRZYQuO^%JO*q|ftXqO&zU(?!si}Eq-olly-R~GOH)sTnBcf}%=`4wZ}A7-rJR2| z#AD6$(ZOtBHwEJ3Gc}*|?wyf{@IHoJiYA>M>~fudsP1GmBTPwQH^iyJzW_f{nLOUe?B#_w+oRF6M7(-LavFuo`}6gtz) zWv+Vrffi7Ah`kNiyj6S6hfUUz2}UkU|Bj8ebw>Pl>gEN1q^W%DedGSmpR&bU6b$DI zORuZ>=GsywH&#gXFH{7IW|NbHMnuN0PcFZ0>U7FaV06d@cf6; zWa4H9xGkj1K)VA1VA=|}YdP;I#y-^a@4l69`-e3Ylk;(E;%Ix80_Ry2x^}#Z^T4t} zk2+^laqB+Wqe@~f99Qo7lC=meB%LUF?`NM&*wy!T&j4Dsnft;fwWw5-sQCJH!g^f1 z zJnUC9>`#OrCVs9#F`*C$V-(fU&4JIz6x*fT_%g3RU*FYS;t;rHwzu}gw`Qd^Yn&v| zU0d?AA)2`JKZKMBalCxGv>M>nms*wTGXA7ix1U}OLf-7EKb$oSC_|dE^lNdn2&s7zAaEnu;Eooee5KR` zZqZ&s)jsG#0;h;6&HTW@*6bFi(@+{+czfp%`>JKXtyz~LnYfGG#i2%oEP3K1Z~siR z(~Iz8FqA|7c_`Oy`Vut}%KEwu;x=oAal|+_*{GA{$Rmr2l-cvc$`-r6fFJgi+iomj zKC6A{c0L(PN9Whww?JeuRzD%Jt;0@-z;(^r#qn*%0LciLA+F5E8$FvG#_kL5R;kWoNt(Oyc}zM3?S2ujM3+dB+;|C24$m*49YW{G)Od7d^noD?xA*o{o_xO4Pg|>+FB-sOtrf94)?PfZxf)}46fvWX_X{ox zEfcl4wcZa=Pd(}G(%7`{{$Jm=O>bHLn8{^t!n%CX< zmV;3n5s^4!hJCbJfh$^dVkq2N**xVB^GlrD#y<6JASq1ikoj)0UK?l)l0K-tTi5vE zyr7Sfy2SL$@Z9LRwgY^Fo11x-ZuLJB zJ>w;uesOr>lay_O*6Z~-nZlLjt?<<1bQs)YGbK-0W$PZpS&F)Vn*fB({w@-Ymd1-u z-s~G5t#g&XS@b0!)H71nVJ!BI!e-_i-+Lv@*YCca_aw{xiX3C3=&4=^)CFi2&7yvn zs_KhTI@25Kn%hBj46|AfF+P|O9(X>9u94 zv}s?}rJgQ|d2B=bSlpredD1GSlymp&O^=C+siU+f-$#=iv*g}gso&9}voQ8pfvQJ{ ztTbguNQ5wnxG!og*t|Nc^)u3nDt7Kk%I-Y1PgQ8i>r^?Yh>c@AJpbW9X+mi#C)5sg z(%y!5R)abAbpN@xt9GJfOF>c_xL+%Bs2Rm@(Sz_gtOh2uJvSGc5y{cGMmv!pr9 zeX95IA_$L6ghgv+m)+BE8)_$UR+P*hX4(^YQAA!q>wu;AWU`ut(9V1s7GqJvzQ0*8`cY+N)P`2i4U_ zHhbHW)b|RT{iOCWH(ohoxt_Guq&-|}C?q=x>Gkv3@5#4Dcnn~qrT2Escpo-Bo1v6) z2kzkG>YpE(AN9gTOkXL@rr@2Khtj&QnU*q*(0)%+58hTUr*|HmX^&PA>D@oZd+=Fr zZ;1qt{T7f^;xjr}%X)USDXOLVEUK_i9AV8ky1hmh!wc%lCW_Wt+jNfRN!31C0dbUM z(J@dQ4b3i(dp^?c7Ou6iE2h6}DqAg;d_7S0>t2b@~%EX~$|&96=%EE|=x>%2GeT7cK6Q&lRuY zC3q68UEoP#U0BtbxEGH z#By~iE%-F~(=j>iHOKR0f75<;uIF(?HMh=B;$MZ}_Zu5DARH_hNCGh!bMvmg$EJ4) zGgQwRIc&Ly2N-9|<6qzoQWt3uyQrG<`b3A(>HenJ&h87g?(sVxzI0>=O}oj$7PU3F zq+zRd&d->i_H-t-$8Aacr}rq5Z4Y1(H@e)E7fnJ4Ho~CQkNb8|qgnCV7lAi1`%zSv zAVz=@!;0jqNroR@3kpYKQ}<8SzQ0fuYxNj#$sf5>_CEEtuUoV2f{+E=tljZSF#_L0 zzbY>WfpIG-S7`Ht4sqoGf|H~Km$S`yaRQIK=ZBaof%j^_jU41?i=oOE4Ag`jnyH0W zM6|L|rFR9)K&49aB5{DZcNV5vDsAwZN45ClRu+ShEwNYRec@9p7}56_-26*w^J6Zz zVuxyy9{`(=q>oacl~wJ8=sNjTB{aYqWClL4uNBCZqXp}9aNn(8t)_a+b<`M?WrBJ? z>`i?{W-TSYxnNw(1$}Tjtnp{1X|7-x@_<`b&-;Tms5@RpIidzG4`REX@;@h#aVCrq zJ?t=%id`Nt)?q4mc$t+1*R2iJzNyPW#NzKs8_%7S^53l-t_N;4^`JvcWa8fCK=^Sb zs_Py_fBeQb;pz&m4jiBO6h>{7Y__!YN(Q~@rO#isLD+0(nd;1IrU6&ZT9`n`e+p8(gycDCRz$LQzqQcI6nS4rf@!_; z+4cfXi>%%M>iO_h8e~GR%u{ZnVfn$6Rx`p@Zs_u~ z>t4(MZWt=0@7A8DB?iv@IFaWeULCtEhp$636;fBlFYm0yr9e4jpFc9PBkjMIejxVg zm;k3W-`6r1GmxzB*YIz0Dg_;}4P%u?*bgYbl``JnGWL-JHDBiFSEZ)RmC`5n@4hb} z!4_c&oEsQSNdBiOu~!rS8Cm!|ZvrsuAml*iT-gts9}58|0|ip>u~IJWpN-QN6Fz;Y?tvrwKc7O7$XzLWfzqlFh(SzjvC0p1EQY}9=vZ{A{kSORbXZK&n;$$w7X}lb z6Mm4^9X4?#oWNlyy;BfV6yEJUcr9tGhzI;Yb;51H1FE1dh^4 zVV#n^mbf+(gl-QgR)Px{8MYrzc*6+PI!?*13@p+m@VN&UkQqkVe6i1Uu*x0mx2B|- z7P;qJ1CXOBXykxMvgl9q{^(AYdiQnr6Pr4ImcZzAj6;)QF>vd=BM;0 z8&TkLM9mg5$&nksbpvw5amWQUZ!G+bns>{|ttnqGBwCZsWx%3xsSTSOIg@S(c3?(@ zbH$lg`XcZK0>25uM;lzkfNksC83zJF|60A874cu)+JH}~6K5`WL=rV&|L3C=2u;D3`&3dL$4rWu!>g*n+3JV|t&7o+6mg&Q zBYSo5OTiB`{1#?c!2RhOKEWNfX1AKJbM0Kj(H}a7r5m{Yg|yl?s>(WvlB0uoeSZuP zUAsDh6ox{hilVY-Tu4u24PL15T4BeJe?HOZlGy#8JqDsF?y}uQ8^%@w;cC(rUYwpO zi4Pa}T^I&P%&Q&hG^CEV1bvuX0Wtz)^JB;7EOP>)8LfcH^~nIJkVTi|;R<`NpL5e0 z5d7K8%INn1D7zV^@#`M=v=$Xo0S(W-98^N^6VMuSoJ#mbwTRF}O?DAeAmHKANsCsF zxP>W0_Dz^y9j??j>Sd$=kkRV*ogoQ4{8`C2mYN5nGj!I9Df7Xdgl~lbW}}zl7I8Ej zEsY+>OH8xFH^ijfkY_X0IZR15veogS6W}xaIL^q|#47;gK+M@s+h%CbJ2Pki5-JfK zX$TTTc)d&U-3&*`T&}-pncS20GDC(33FKu(lLyQBb_0>p-&>bVEBn;N-s|NMUMGn5 zeVXy}6)0I0eq)b$V+vpdhFj$Vxq{A&$lXDIQVTs@=fV4OpHtzJo(xnRO?XsbH&GLw zcLp`4sx^rN>UvAZVT*WMn->3YaS3Xe4Go3uG0rH3z4Q-O5Sdx2%ay5<`^kot=b?Sohig zgW^{kN3TA}1MJh4X}c*D=pHbLf$`C%?=TXp{8`$!fNeU_M~8v?-&Br;t0^k2R7KUe((z zP5KN3AoMDt0bX6JBy?QD)wE#8@))e>D&+R{jCC*^+Q z?7|6E?$-z+^8Qi&?LaQJ4GYTOO=MvKn&{V`;d;>jAD)O`i~iq21OGqxU30~~@629S zSU|Sgo6QzJ{>>izzLj0c;9(N~#fa4mOXh=JY}1$8*o=wsUQ3C|8FQNYKqh7aU3oFA zGA{>Wy}+j|#b;aU_^{2xXqzFAt!A{IcZj1nsg?c+%Y3{uyX?L2q8~o7YC^XXGpzRD z7h@4!c42(|nxu1pS6E=ws;}_TGw7HJGaE}V@IahC@2e)y8&pau5TY;CI6{vHT{YcgKJWwKt^nBwf}6l_|%wAN{plK3H=3v zQ~pJLOQZm>M`=8f&RKinno8I+UCDp_#wh<)Q;km;{aed#s00ySc}0k{>J?MckljPkNK8dOu)a^;|thK%lvCS9xQyTJsNHcuRVOz z#=+!t_RPONZ)>JC?Qm;0%aS?w{sX@fX3MFo3`4U zBk3>yY3>Xu0~#kS=;QY*pB4+-=AKAM?&qYrnPPMB#95C&J^v;N{$(=oGw$zS@i`4h zoqU<~!c9Mq2|3x*=sV2)8&CS*)962gZDBnL%)3cD*y=h*3`e+Y!t;Nt*6{nPC1#%o z*cf~PKF5jxNqOtv#?T5oEq{h#qrZm-)S&eX4`e*-I1_izhS1fhy=I6Em z1+g&Me=FhLwUCo9W-%S!GaGGE`{ke~Vx&6Oo(ufV!TiTr__zuikd|VA6EjXedaIbG zx)vlL{!e4@H69jOk+=4;Z*L&&WTtI*4Ri#Hg(Kl)Fz^lx)vGxG)N?TQ_r zIGLWs-7jg3_}ydX|HtUS+tI9~10y|b0|RrCK@n~sWyHP-K`wgcrQ!`(r{=YsY+U0*W_?UOp|7&ZTr~I!*m~|QbPeb7s2$bWW zX7{Q6Zx#Jtn+81)nl!$ppI6M2^l4G;Ne!o6y=Rd_WT%^t7gBpM8X(Z~39oX>V-d*dmf)|#{%~!i!IMpk4ijypa7#W1yU$=e zzcxDN=e_qMz4hT4q$~bj0+nqmcmva6^A`IcaSp6M+{EMgan$4MH#&VwDchY&^zYlA zU%5XUutHKbW%ETDx6=ch zz1dIWp?3ixb7D4>BUP!RlXyE7;3Z=!*Njd`lbL*uHrfK9k_q#qi0%@BdT`<&2H;91 zhBX?qEjqohAI5q{6mzH$z41n+wR9 zBT+9$DPq-);`qSYHB)Rx)Ks(U^E5{LI4*LfhOANY_ok#=dmZ_teq${e;n>O&enWF% z#yslD{#?9W+l-7GIJK*d<1v7-l>jkX9-BnRRF=01SOglI@j=IjyBg}?BA_|F3+qtO z1tO{EbqSIR)$R&m%(@c>n>%JdhV>X{Z!C}<>;ff!(ov_1@vC`a_fyEI&vwKU)svmN z!v00PzF&=TcFx)ym&OsJ>!CxAT)N=c(L5neT_wX-i&*bjGBM{^fqwbhkB%OM`M zGr7-3Gg#zTVcXR#=vAV11UgCyD$P{7l*)3e^&kS~aem3IZ$_^jjkrg2cz z{0OCGvP1K1GlSiC7ot@B>AbZI-!6DOID5;z1HUl=kDoN+t%mOHd^e$`iNs!`w&ge7 zQPeI>{-o~W$eHih`C{H;NC&U?0$N!OK`DZ@nmc7|UzFH$w6v#U$)RfFik>mm|7lXPvT-Li;M#|e8C?43U^>QL+szCIr`H8|{=iH|m_44+zjtrMAr5<>WNBfq-v$ zhT*$o2Tu&187iWa$Y0fUx+Px`2V2sk6U!5uQy98S(G@a}`{iF!#pK1mtd4HlhHGms z7`qNzsEI=BwzvG;R79R@^PdB)GMT$EzY~*oWNuADqE6hR8T@wUbqa|44~J>R@mxF@ zs$>;(J%`FdMH#A_s-eQ)WZo0#WC^de9gP`Wcz@_B?PJzX?UN`Q{W6_-W{;{z`yA}% z6e=EmVbI9KmQ7kU=~n&63?4lr=3AChClBTx!CqI8upOw=7E1fDMmi0bdFdM`Dhx$i z%O-jQ2CVR+SB}ej;?uMSV%-ts|AVD-d4vB6@C{F(Xy-;<#>Y3$#0WnQRG9#`aY<#L zW$NHlK1}`&_8qGog5&nsyD{Ziwk+dSV;%qsF&6s?T)5p!v1cXArQ-;~S|kYD8Ih~; zb`Z1Rn2&!b3co3=#U{Y0@L11mqop4JL@sdjsk5E~i==i%DcI=ekb%5ik~`r7EsReL zoND%JtL~ccCCipIDr^geJ2LN%Ju%jfD-n?BBJ)4%^`=B6Z8g(|`B1~!j$tYaE7fHh zAEPIr=9@4d<@%CvDOJb!btK@BbcT=Rf0}>w;7jaIUD;5A<9+=VodGRbpUm@cu_57W zjc#({ncoEo{hd@(R+1)4LcEoj^Ew9jA7e^du?N1@jq}ONHU8A2CEMY=*F$Ylk%kt* zw8(^Jc~Mr&tRAu-=QOj42SN54uRv=Si}nqj2Fc=O!Nu*Hq1I5d7Y-^uUs#iZAH@?j z?QBjx@$!rrv(WY4PpM5BF}yr8t?@mXw}i8CJvhYsYH6j7g(Ao}87|p(cIhSyu-&AG z-1@U}FyVR-Vv+8iz%$5Rr^garo?5lau_BCh3kc=(V{2GjVG-$dP)o?yWs+rUO)@5uT+ImD!W zJ*mR}LoQG@%O?@kJ6LuZ3}xF=J^`@qcX(yIvX7@@cI(|jTdgdANrQbu&+DwAW9rk1CJrM z7`99K`d82C2iy7yf6IEg6YiyHX%(rIGv2H9Iq$N>h=}bW>K8jz=vD|#1)>v4;_q1b z;&wl09^>uSrO*SFqJu~FlW-#YgC8x?01|LR>GJv7Oz8FC!*}H}dIu2KoDDh_jOf88nKE#rU=1zQt(z2*iK)xE6?Phmh2 z`>3_!Kz0nebWEn@qpUx1HLvBYJth6_5G6y)%>o)DvjZK2OcB0hsS|}nA^J!?kzPOC zqQ_Ru4?7u%3BPmYtrnh+_^EwB?e|l2jlcitSP^FdC`(}~%qO4w9pdhPTu)C^U**-G zO4KBjozJd?x&L)Inv3Bpxn70e%pQ7txHTkw<=SIqaI;v*1vlY=GWO<|g zjEgtB>nC~0p4A>o{%3nmrr3>arkYGe)LdM?G{V#et5C2 z(KRGM17BEpAv}Bt4V!AsdECqu;gtO3flCJXlr8nP27 z(Zi@gJ@2pVSEa|G+2lGh{mRB)umONrd2^*hB-nnX(AX=rkmL9=2~pXb)Rm6QHw~-> zWRM@^HjCyv)Sgoh1-=Tf1M*G#_@jT{}Z;hdIG9sEa4xP$2a zpGAOOq=&&OC}j~q{l&LhM(42UQNnQ>UomoZ0rs=sC@m82)_T3~xUI9V$q)s|&6`Q( z85TbtlTXW`(4L>zNW$HQKBw2aL&=ydF$bm|ffw54n`A#dG-n=qg0j1Ua?pF~X_)0) zacc>{f~}2nff%`UKR>J+?$%O!fI=UzDP)tbE+~0F)Ez@>DI&^|P+b! z8#zh1&D;%92QVJYhPUv)Ia)6^ z4vi0>rxs+R1u8ky3X%btv$Qj?Kug3Sz42}dvn++qQSO?vt5@dS3YtPAszv}8w4>J@ z*;xaDvqI+fI~mqj(&?32l;?c1^$HlBx*Q%4MK~`_-A}-|Ya7&7TZ*xY+53y^*e4&< zU5};o_Wk%Glzl~PL-Yz|SFZ+_m2VSLa?bE~G%^icu%sNt`tY2T$P5=nBKb|7PAq-ql5Cn8ysmne z*Sl_!okZFn-E)5K+PfoA9sJ|D)#3S&nsDCxWTpqITqY%@F~2A-;Z70unEDZmjwP7eSF0RB@F9+SWir&6p23A=A7aQ% z$IIACN`jm=X(LzNUq3#_^C6G%$T!5AseRd*Rj3{E;+3Sj9+0W7UL&PjNg1wsFd~V0 z#no3xr$yfLWId zVIi%6Dl7j!z})1YXBB-P4w#@H-az~;E}2Dp>zspu++$08gN_#~47ZQ*2_VYSv`8`4 z!ahPSu@;Eb-Iz4x?#6_EsB@tG4F8SVk4D#}5N@nzrzxI9NnGA_kp%K?L(yB}E7Mg` z>h8U=1bHdrx`wsRCMe1Vf04LehYa=P8PNkIZO(c7fx}=@V(8aIg8J({LL*F8C zA_PRlGmdLRs0x$s?!KncWhvNt;+!wZOj3a&F=G;eDt2Z$nBeR8(Iw zdWo|`b3&Zb3c_UAHD4m?E8I22K43{+aAihl05K&jl%(TJfbdRk9ofiFQ5dkThZF&C5|$yc7EATM41!2gzn$ATvVt5^_X5&5I$!>VC-&w`bx~ z8M|_Q;BbU)D0rsXXobNNuE=VmJ{n3p^--lBj4_nZ0otZp@)lXK9m8p)%P)MY3J3gt zx~oxJK4X&=rB!@@iZ_HcHh-B#idy*5o-ApZf^NoI@y|15(y(W(5S!=WAUB`v)-_VW z+!Tef8ALDT2}hb!klekq)XCSHiB_`>lC{xIoN|>Sv`ep5!yMWNSQW`#-*^9^j1e13 znJ7iU_TQL%-nV)ivs&5phYf?*pX0`}mR@;Tw&!0?PMYC9mYE1Qvy_Dk0H!CApRcW- zgF*`AoI$*tFJ=?%y%Omfr@a}BhkAm$^ypQ~JA~5y4BN3?WLvgo%!j*HcFOEb{jusMKF1Hvxe1^1DJwx)ovB8?^-z!tpxrni$Mnja|8!%=kX68eYCDE*(I z)|_U^n{}myVS>5c!-7AA`|I7OJ?$eF&3d{~8p(7YK0BlqZJ^96iw;2s9gGd%_j1Mm z3m@5-uqVy2>D$M@`hG>UcRs590G^@1bE~y$3U3|E7cTzc>#MROMqwtlH!fBiHR5CA z`8vjZC>&U&#UGmk_wF(WW@C(^=IZcew07O7AYfSzhdK*DD{m43;wRlDPL;I#tgL1)#=7wyB2WBsS41WT`rYC;&2taXJY@mRQz}*RJ8+h8 zvwbfwIvh?gUxne}efOACUAu!=1^9<`t>sR=Xy)j@B7D65ibgB_mB&wj^{==EN%JlM z@>38R82K%O0f@X)7T`VRzkY1{%cB;i1XM3~Pmy$s&+YNLSS-k!BIJJ9#;mky;nD^w z0De)14I4F%&*p2;@menhY`Eh$G5JU9%YB}DhJYv(46a97{l)iZW5C^1jfdlAr?AF{ znuDeJhNs;UyIB?>1B4VlBaJW~gvbtbEB5#9q6Y%LxZiUbcW#KhnWlY`PB)f3KeHa= z1K3m9`!kI(f|^ki*(ehnl|dF5z7_fkhlRzdIY1}R#rm>-dMmWjh1%#07rraf)C z*5_HqCKc#+P2C$eyOn8l;}eiV;;Z@xEpptU{e4Vv#Qu0&dI(|wA;&Ill8=`~i=3=$ zb6Bo=E(iJs~T>Gt)%yLN~U4%m7 za~K_)qM2(ElKEUd|4(~o9#2*G{(Z-IP@F@N`8di@hC&?k!9l|@S4g7Fna3i-F~pIO zh%!WGw|S1tWDFTHmN8^XnKFCU)_vdK@9%j%e?5Qy`lJ5IUfbGhuYIlS`dshN$W=-E z^L6%Srg`+xHN8GK+`YIn$U|qtJ}$^L<>$5iG~!LtJeOla(pHhAeLLHWo2OB%eshJ& zd?K=QKih|Ve}~3F*Ij;kvTosKt3&Y&B;3<|1JGIf|32oqKsXgHNVV4wY zO#)_qcr~fobM=GzDI7Zhk9t8uL^9keBc?*iTvgDrTFY@4#(xf2QC;en2jjc1Fn$vW232WjPL1hC`uuS`o=P z8>K)oqeF|6g>9aoePO8{w5{m4 zcsET6_tzb~qUBZNa`#$S(2(qQd>!$s-aTD842xy$cHfa%oVJr6`=zi@^vJw^`ej<{ zZFqF6l%=+6pAC%kSHJ={W+7VTjEP}KOe7h14DP-E(6YBpRJS|Or__0>gfXaUH+Y>(a-u;MvBbi1b zwXL4?0GvE+$~LwxRhY@ZOy&?E;Ar%#Uu@{p`mJH+1v{>I3Sm(`7v;VgYRE5|e0A`4 zDiJadktaGI-_5+yp`E&?P(Gpz>q@1~*;P(;*h-1dwqklJTNq)GdI^MbqvPc*syrI9 zZghh$ZF9?t21tRA8SsML95gg+il2Y-8IZ1y_UBGo030i%G7JkVt~Rk63u#k?M1_(m z4W&`yOjRdfWv9+`l#=X~sLRP& zB>w$5fd)6+;;0lj*(!;nPVm@OVNtA?DB}l<2)mPh5*OjQLcJ!L;d<)d!4*2ho|yIT zo}vO{zZE#TaaOft@Pl@+qLD?@R)1R5}eC|lJblITx+gk=8iy}G497<<=HRl{0mfGMaVG}{AI8Lb z_YrhL2~hDpzonK$&W%Min(ZuMB?fno`C0H2+zb~f{3b4`r!X-g(A(;1*n!BGp%Y!C zp(;{XD=Vf#uSH3127uHNr+(CZld7%{An=LQ(Y`IgcPp|5wWvI1cTa^q*TTD*$Si(y ziQQNEPPB{P;PUWTkN-|yK6cjmqauK^+~)9R;K$lpXu(MRU^9@@m-XT1knzN~^(~Rk zx~!M&tKGQSY(SKl>E?F@wo8-r_1i?8pe$UxjH0v;}W7Tq$LNMzw9OeSO|fUt45wB=#0;I-5USRH$CnOOdDZco%O; z2G$I!5t6G0oJpynt23=$-=&j!Mm{enm;431GH6%i0exGtIpH?Jq=TaS#I*8jP7Q=V z?zJ#_9T}=68iwwqfA!--nUGH`Db65h!@Bnrx;PHB!c-CJ2|VombVU8ER3;*CJ@vdV zyJ^CfCo4eO{lTkc!~gKrW>afeO6%^_UqZ7XIMGRM^oN#tPY^IGJ-IS+zo7CWIVJqS zC0ej+C|wScnE zb%dc4zKveued@Q-RtM@t607^-~;cAYRz6L`Zo+%;!_12z8n-R08 z;MHNL?j4)xY8uroej<>9{B*ggQ-||=!gp#MtUOGB)!Uj8WyLeCS<^ypVwn*>umCZb zk6&IK-nw2fV*){;J?DT!c>OHv@Vp7h$wC%!;~plK}&p-O!v=N61D!?d6!_rud{jFcA@q|2})+vv|s#X zc!%qt8!FM!oas&u7qB{Px7@oDdYR{yyVlX1pL_;dYvQw>agDhrtS;mf>Mwt1NWTn4 z38;vQml(3>d%hTo+4!rrDxNjFa?{w6aYFeEjXhwPV@113wioZF_)!8j-AF5v01Cn^ z@qPY~9(=?hh7Vm5@F^I$+At60BTgaDz8iGpm=a5vmAFH@xWv_bBimY68fUf%y?yA6 zn?F_Hhl5EOCjfNKX|&TzA5aS=`%e~M<|r;O`9#+-v_g(!=uit(CS>`y`9IPUt}-Z~ zLM9=*h!jHaQ$$1o<`SW|xFDF@s_1!ewfCP@3SGH*NN7=0H|SzREbn&cpGS&Y-z!w^ zKfbp33P!8eo)7gxt9GA(67?6V7{wVKYTx3C;AUu^e#w#xpdpTCY<2)nc45;s#v-zd zY{84J3=ddfMT0Gqq~!FIBg&F>rVl7JoLAuMSP+m5z(`?yCoJFZs~cffi0qi(18Sb$ zCqM~KZcwRS(PWo&1y#d@LQ4ni3WPqdFHf7Q4z350;J{vJaqa`-3|*1XZb0Cm%8hC` z%nook3dZ!tO2A09gB*W|3QfKn=IvyR+`-xsZ4k|kFYffb+Py)W3f|Bmjb@#EZMQeX zTnP}^YZR8l=ng}fV}R9#A&Th8&TQo=HK4)FQR2f;O5A-&X~*sM3lzk; zr888c*Wx9-@68YbG{q@ewF-t1dnRo1nFe#0jhiqBuY~@uLE)@jPVB=+ElRJbwpuTt zUVPjw3%dz+BD)j9SQ0u%%$I#$Pr^hlYtO3w*`jBt$%c3ph8an4w>a5oC5lZRtH62~ zjz_EfaGKKYXHS~VQ%=3Q?{@|pj~0Ckh#Oh31lKhLJuq-su{OpRWQDB#3h73n zWfnEvbeP?AB(;L-Muw!T0J51tq{YPy)B7T|L?bQ#Ii7y4-^uJj(V6XdZTj#3%^M_s z5DC#Sc}j7g#O|rcO~98$TqZk)K5nBTuVG?bq0aO{1%moQPL z4|eH+-qY9tm;?LF!;f9vOl~ubF;FKWoIJW`&^wuKtz(ms=#GVl?5=`zhs6=M*Rer@ zG#y2qX&3EyG`a5qo5K>#JkgId@&S zx3mErG>xM)cz5TTYWdwJ@sz{za^yk1G~05pceFNY2{h;)Z^V=uGXG;ZhjQNstSSfp zj3+z)msp(J8N?YP3Gu)}L!p-x&!xzIuY&>%mO^RuxMbo%*OOs2@8#un8~g2W-f2IH z%SpWIgEp^J2PU?pG*h_rEdve;BSdM;5<#YjEftR7=D$c4H-S4n=^A^Va98sY3^gVQfPhc>- zSM^HBiey74* ztj=FS7!^IRN4wYq0|4l@?SC?A(7Yb=V{A;tVbgIobos=O1LTK;+O&c{uSg?F;K!@FATy}8WFaY zqTyqAAFq^Izm@=pDRTP2$lISxR%n;MNXRLJ)M3j%UK&tP{wJ5mmP(B%`l0OQ@zy=s zzy`+05&U`|BHtom{%|s%ShVtUA*J?c>b{O10_CNzDNNei>e9OSEU`Yo$=-!dS91fe{9uo=l?OsaU>06-t0ExEwQ@H*Iu2+%7;5`nFj$P z=whlpn%S{71aR!GlhcnXkLVDRYw)SbU6@tdi06chN~e@}Sh@+>rv{pCJk?)Cqeuf> z7X|yR`BvWA6Rn2}v3^Ot98f75E9e9j-25(!m+5l!JL z)-+VYag+)jz9WJc{9dy(EzFJ@id#t({mRaFtP!mIc#LCCqT{APP7Zh<^wMt*(BKHg z_9<8>IVm*V0$B)PWkcL4aQYvsx}kS!Ey?_y)bVxyL9LU9nnji07k9X- zY(=TWLM;GW|12TsvvQ2$$qUm4Rb}5}K7s~6D7yUNBbb5&!|_^MQg%1`lMZI1K@=kl zsQ%U`f;4e=)W>d*)*A0M06viIGUSCEPFRa&S;B2|H@V;Qwk>tuP z9t=%D7&^O8X<9jbbadrA4Vio(>k)R~x_r{0 z77(St-eSb)&IUEQ@)`fm(1rf*g!7uV`i`K3_4Y6uNTp2?gT##~p=}n*Zhsv61=Zl9 z5&?h-bh4985mbth$OlB*w({(^%f)cSs_dp7--Ju!5b$d8 z<}aXle>#w?g$J#4GV*MPayVLFKK9lDR`^@$K zWFiHdt2sn?3_rRc^|PW1o)n(3j1kG{`gEXz8;s{()jI}IgdtFeKeFpy%>9PJrjLzC z>?Cn^jGFu=5M?fftJ^+@@IvH+xIwLUm!k@f6lRsVX^mf>U zlh>{aeXV$7rrOvpbJBwvpibn44(BdY?~V@l`kmJa0oM{oEDd9+0~zG$J2MSSyxxHW zIxp0pxbE@UCcn~RF;=~;^#{u)pQ&EtrQPc-#^a7nW^1LH>H9mndvgwnt?q6{m$ik* zPN`M-Egf_TJ&&Qnd?D^)7|2g0OxqY zI$Jf$a*>Ew7iVDHQ}AJ%Gt`4CItT^2fx&7N6^Ftj524{a@T5Qey{zEUU&Is~HN?I< z(JXl-kgPc-EL9`m_SL^yc(1{N&&t1)CI=Eg$J}S{bv2|OF@jhC!5$9!Tw5x!M9j=H zF-WawG0%5@X1GUYwYnWNDprOBbNOJtX3!?o0xfCgzvy3KJ}y4SOfjEevTL3O`GM7S za*jR_P0Tulf=&R9i>dgU;Iq4+epCh7TkR7LuSxOurz(g^Aepzr>a~2!U;Qew?0KV_ zJh|H_Rkt(OWqk47LPk9A{tc>!`_75-|%Q8E3d zU(a<@J#xV^>ySqTGU;&TD!`Z zbl?lw0xf6$}y-yuLcZ{}WuFS3yyv4o-Rz)c64_J)3gdZHv4R<&f$;}%3 zei@5%hN>iDWvRmN0qW$>QZ{FT`BSjJZv3fUAnmgTIWMeLch=>-UenTSNM^4SLr%V4 zJ?iFNWvS59J$sD0IXn>KGd}t%5?4LBValpFQ>j;L%ae5AwKDNoB}zkHM7I6t=|r_j z>WR%hiST*09;u?8gM^&!;p4kIIs7}Kdf()$h)q{@ey^jr-LlM^_Aca~`hVal1LXcCJ>LbX5 zUI#`x=6Is|Qn+}6L-~@kXpp=+dv`uO%q=~FB+`$Jl~kG1gIfz2!gkoXv+j~b(rz^6 zTd_BbCX2)@lsN`wVOdf*&|&hL2Ot;GlTmzmqZ1Esy<9MKfXioh&Igy?{tX$1G_Vs_ zOuz6*qm|B37rp%V6~HWPj0hG4UOo*$Y1-c?N7&*>6P$3MQqSa`_6Ag`q7*(2gkZG> zVUQ!0`Z(m=!4vj96tboQjz?T*wGrV(1z=ed)gR&6^=-Mv!5#-+>ujT4#9~n#_Xrcw zVP1g@ebbVkZgp^aw%t=VBAy4$_rMNGwsH+*J4@wOrnjy6%#FRi8FU>kdOif~fi_n%Av06*w$<{TMT@%BFh+ysv87 zAJ6sFS@5hZaP9n1{eA?U?DJNy`@BhzA9Yq zyXgeKGFyJl*67^P+AttaXRcHa>?I3YyGb9dw^WroO{@f1{|h3X`U1MOYs12jWs9b* z!oy;HJ9Rnq{l+Xq$oA(i74gaR3^nx=x%hgIRJ=f`%7%u4aDXV$!{9EnDIAd&JMaCT z0*=xNaZS-g=jBWc4PDx$8tN&=W4SuWGs~BFhoU`NX9NLwxSIZ&G6)9%w-kk-eSn}$ zVW;~Ij&&fj7WK&T(yPbQge%Fb&I=Ay3x{TVFXWlW;?4mfDQ;;+- zu1@5Y{#r7=_m>4?4aMRi>!r%t?Yx3V$>UhVMa?^@y04f%ZYb3a>modB&9T_wZzRJ^szc-7!gR5+smEriq{suVWszV3xHWWh0?5sqBA-wW zS0)HE&j;I>K8vX8PF7#$mdmHDe`MwzG0ZnGS?l_OEqY6;%%!(OSQix7QFgO@e_Gq z6Q-XnGpS%8#i>R&6wOKYGj!PbWmA3Yx`4%f^?I8kEE5)1HGY(6*zXBPTym3@5ypCf za*JM}TqJ|$k!5_Qq1R?lO@=@#pL*xU*K0t9pzjGIotJs^i;Sw@aj`--&?Je-Wp3#I zUjCrYEoLv@_rO=&y7$LzD}82|zha28o^&q;Q_Vf=JN_otVXdhFPzM4epO3y3>~{=z z!XZc><#Z_9>>xfi3DXzA$*ZlKLZBj(B&U6Luyb{~@|DSkSHZXY9_jPN5z3=lwq_*= z>!HaF^4HX8gI`H4fRb2?vgla924{4pkiQ-Soly+u9zXS1X^p{&;1@3SM~ViuK;(UH z>@yNE{KDn&)DvcjaPoPAyN>aKc#FKFs?<=z!$qPiV7V1t*n4XA+EF|MxCuwcTO89X z0cp}%T8zq_36_#3)R+?F(k>O|@=U0)k~WxLW-Y#`Ax;oSd2gvIAGLd7%VK$;SN)P3 zaUHRDejTaOMz+hZbXV@c-_DARlxznmyG;%}c{h!+c=2D*U13e{CoRcM&4Yb--^Ta|biGPJ`%Q6jro?E)i$V zsK!y74PC?J*M7ct2`|MCa-@C>FO%Kr#<6OD7Mv0UYe=*+jei|Ue}6VJJmg{8aA>6& zqt|zn&JPA7wfETQO!-g+06YN#bog&m%OA!bbD~(%rnYBXf3jH;C(4u!GNxQ{tc6w_ z3mDyfIyHt%Zv|UfsezktT{ab;_!djx`f0m!i^+HHM69$m_0m{gE>}#Ll%yY%#RJqb zSOJOM@=oxj4WM-Ht&Quu`bT)HMIh4#%<0qSX;+q0efC%uHqk-Lj73zLse*vJ$$oUK zzEz)NS6X?uCbKrmextr9_elT(CEDS9c|a@=j}K_WG3`o)%N(ish7jLaM<4hVDH@r} zBdHS@59!s4Khn>$e4oM3@VA~rlX?*8zD-q&(tT&!^sq?K4U%uXOk6=wWlH7DN?j0m zlDzw+R7IX-^YgqsIWaC@o91D^THhzetB>^>gEYwbkIB+n_Z_0ajOk zcus!KxV#o&7)mB--KBNE0R7nGv=d8MvmJoO@BjCQet}reYS4s#$se$;toQPl{;B|& z3JHMelDMToAVJgY!bz1Ocom#Jn)?M$-{4h3J#um?Hu&1O&h*bIex2~(>pp47nRpt9&HX*?KCwswW09<hJ&@T}l4A28r3j(eJv#8IjGaZVV_#&NDp``E<=_Hrb0n7yPsiqgHwv_C&IfTj%Fsh1cVrOPA(ZsR(vb-3EB3u_YlI6Fa)owkh@~)mDPl${op7qPh3D>Y5lbj@Pt^EG};P?gY zk|iZ?HeBxG4lAw72a%MuhU?0im}YS*Tll_lcf)GR4|?L`sh{giZ`KhSj+htP5&^}} z^0HF%d>u8eCb`$8(7#0AZvhuU34YcVG%&lK=3>9JVZE`y$c=TZ`JnOo%vJgM^Gm;x zJEy?+`A&`Z$%7EPl8xddCwXMVcPcpYSy8dKaz%~^q=@H=8g&{C1I`%w$&sREBqW!f zq=1yUh-qQH>1)bgZlMVHeeV#@J%+(I$@qf>4fexgVR(^$ojGuE3IqthhOC})Z{3(D zk~0;gI0Z;3vv#}C5E!C(eOB1b&%g_jkR*+sE%?tRy$t- z6(qbQntk|tR`cO-_FJ4jGm_os{mJMXxW!SbT3jhK4lkD~*6IT!7uYSm_l*YVjIe3& zNM<)_`hB97M)!4Mgp@M&fO^PPfWlXM216-ij5FAnD8mu#@jB zw2=UvZG=P+Phx_HPsrTYT#kF0m%T^k&*R2@>fU4W;x<|}QJ)IGDAs<7`yID%IC7j` zq(-#H>$^=(5$CXG_sQx?)+;zbN;;5aUI0xq`u(vFVad}%FF$EHMsxQ1C}Zr&6wGG!L-%bbSyA_0??sJbn-$ZL z28!ZjM7Ps$}MF7Ce`Ej5gkuPS4| ziacDB_F_ygDduMplk!TlWKyxLmI$dz+T~vAV2;r=z+x)(BL-aIDfVC6=Zb{)R4zUX z`+Ja4ggAP48Y>qWOAY^Zntt#xf4`}x>g#-x-UvvgqeDtQ4NHM7@kfU$s2U6g^LGZj zM8LH(G&^(N-cc2jFtff~HmP;gt$z;YFByUHsjiGzpi#tKnS>8&XwPYF0kQm@tbzp1 z6GbtKn46e$xRV2$ziz$U=(E0WNKT!wuVaOMMf4cly#MIjz=zr;i85^&SH-}DSUZcl zY6C%q5DVFDJ@DXhxpcj=RMF%_Zo!+ zMdU&b4f`0XsW!{|EC(_P^@TF-d7b712dCAd#9L@hvzLE+vtKQrk3-()a;RCD*?cvL z$-2OF{$sLmzM_%MiQl} zfWKpo9@_uskwXYho`j=keIvZP1d20P=T}1>-~9ro7d#PSdY2YK1Tju|1(KcrI!g-r zepj%L_%C?-EM#O>I3v27^HgTTSUb!PJYQu(#vC+tm_! z_tU?^Y5K`e{P#C^YTq)tTcVc=2~L~L2|jop*}{uw!##jhi(H(v;a;$Wxq$MGW|w^F z?QC-dXG>u8dPCRgpqjXc@=oG3=?p`LikLJ67Cb z{)P6Osw~e(8XsZ+fR5yLh9#Z3@w^zCk?07j>t$SySSO_`^qDl7@JvcIs@7*K);tbI z0)|1m&g`-m*XQz2u}+^fIoP73irqYs6(#X0=284uFm%?TWS3b~X;!RPM0{tEw4!R& zFjy3#4o)xd=5AaBeI>Nj3oU-|c-z1S#F(dHHE}$>tqZZyQzDJmJZ$X%ZCx}z zI9ZG4>OiDQITn}+uXG-sp1xVL8V62qci0xl(raEXHXcQ1_h>R}b0M$YQI-Nk^;bd^ z#I=M%g%%H%dlDcJ*O@3NkLt4?%|oFO*3Y$lIY_w)uJVQ<>k%{R()}D+nS!)9t-`q` zAa5=d@SPQ?8_3PXa+m{k&keFjD*UF&gkF+ot12gmxqu`~7#EP0^X5(O)(6^AuFbls z?F;=tPE=0+ejsW7%fH7ue*!j5ko4BK1-jYHi)3rZS-GU) zZ;US?o_Cig&49Kluv@&0@Tk8*zjbiB&Z9wg*0IMcQLP)(V4t7LB4YPW}4$KPq| z$;qY4XArg|?a~i{FxvHANBK&VFlgfWs`2L#nBuxUmaxGepZ<`V)SKgR2cD5BS+jE3 z66cs3PvXbe)5L4$^3ci5Lo08hjiFK9v(f?=GZ@p|B&;DtpNkQdZJV~$4qww2W@qZq zVv2`&~31f>)mIXvNfGe<(1wVO*qsTj|e zSg5y?xD`(;Q@C8Xa%rgR;r-yXJc}`TC2VrI;~76d*z7CwP8@GN^d1FKAx;%eiFxjJ zmt%pT^=VEkh$IpjZih)X7#IKEiP^u$wTo~U=5Spm$`#pE+OZk}noHQ(t*pNco6}Wx;}s&R+@4oW<9vtgjG*&gA^4jqXLk?BY~x{iOZxWtlFS9(jzuhjVjA zJ5)Y=dTDpR+OgZ_UUr!E%3MNB<7aoj`cHf`<}CH9%5RS3-JEY%!@RfZ7{N`MJ#2CX5(a(C zDy0qcGDZExIBA~F4;teI*D|jj|6))%2rYU7Qc&el5Q)OyZwJ2MCrTFtIRn#-Uz?$V z3Zp&fc(=Q@L#MfmqK>av5>F0C8qm3ec>3Rxnuib~@*WU%ve^h>v3TQT{0@soZJHuE zu3Y`(m}RJzQl-1{t?+{qk+p4w&=wQzE`H?!Ra>^!4-=m8=G;pJbU$%btyM`CjUKz| zuD}K&J5ZK|lI+Dc{(qV;^dG}WiJVy5owQF^#U3<0KlA2ve35poCV#FTRDs|a0V(+3w5IcxjD^~4@ z?Ls9sp;kT7>;66C{$BU}9M5t5{(Sy$M3PU=@p_N*eZJ23`3^VG)1<$8<0=^$89hMj z(Q`5~N-i=oa;__vNuRvZZc-z?TylS|`H&1Tz_mttLuva!_W>DMMGWof8!FO!8i*Fq zos5jd8ClaCz@rB*z0Eex0;cbSK|jtK`~neYFP(Uqu04Aed{sk|nf{wr zmK?pp3mNX7)Tl{ioEn%ih- zYB1jjY?x>YIz0VJ7bqUHSBI8%7+18-Sba@6J>3b+SWQ(}Nlvli8TW5??8OE_55K>idVY}kUCIA6Xv(oR9k;`fJ-xRuKx_30C`nY6K0$I zMt1i){CQ6%yAbX((239B+TsXt^iK<1I;4%Jf5vMrBgy0urg1%Wz;kwda}_4&geWdU zqZHQ5+o!f>tzuMa>Njd|!)|F&X^ci7=qo?g`7v%%>^8OUS0tUVDxrHlFkN{ zwj6nUf8wQxXsE#+Ku^*GkJs$6k1P8y=oCcruj7@vrD&xNDXLPOk4Zz83nSdj*WNch>1VXc z;k0`iMy#RaYydRgF%k>ifPsqXzQjD5u`kRRM{T#!rg=3HKpRvJpa~}EOrP4_iLedh zaaa78!h+@NGiqj#2P4WWk{?dh^!;A%HJk0{uJ9rnkwGU99(2kOC+y}*2E;nZ zmnGjth@o!X!+qR^a?8znTfLTz*X32AS$pOEb0MtkWK-qW&n3n$R+Y@{Tt0urQNwTF zeIXzr;^Q_95GgguYB>tqO7NLu&je$`mp*Z0WtXKs)a{m34y4{L;;qz8K3|5L&kBD= zq9$XKV|G>}X{cq%&8wCNq$$mR0t5Ce+H!c=K+qG2fi0M=UrPMMW-%XF%POy6v&{DW zw}5f&N2^&u-JY2tlxidQaCx$oB@W%2e>&x>iZOk0Pn9hpSo{LktC~_LLPZIZD!Oes z`{#knMl}z73~h~TLfX%vBf3uSvUG7DJ+tXoGnm+iXD9nYG&}!Mt60vbiWAcB-^?*0;NgeTtSp zg0a_{YW4kbG|_NhtZ^;wELYV$0clSjKC1Xds^@lLy3|zORZif6^nkoTMge2fITH2M zs+MLBfRzbIK38T@!dQF_Y0tNA4;RUtO!u1g+2DRD7O9}FaH(VIx-i#u+7!(i5v=BW zUY@v~-hLC0h^P&jziv7|OA2`AN|$sJ7=3TB4z1r-3tV6uM!|&^)S0ppv#vYI z++J((9UDp9;5wdaC@Z8Gu^FM0)NTvjYTuP_8T!lKJiDtpNLDx8I6D&&_*WXd&)uJO zV(2Wea@I@TppVE|@uDfR+R>M(xMCXWgAlN5;B>Cbi5f$0U9ZtLTxGHnRhm$M0?|u# z45*blmfrvwi)Sk6Uxw+gdssZLlbphj(AAa5S7=nD&jV_(URw{XQ) z%JWXwd1sr@p^*07TOTC)+?WfA_;qEGvE4nxnjO!XSrP)}ya^{%cq!BM;cI&^P4ZCG z1g-q6+zFLMB|8!^lKhgFEoJ)t^3+EMZnL(jiHs!LVRXJ3C@{&&JCT(E6f6?{QIu%~ zL;*Y!eb91>L~2BWc#mQ9kyaT3;Vo9Iq7;|Z2Iy?>KI9?<83ctmwI_OIs zn1|7uHl#lFuLaXU-yfqy!x;vSpuoO7T`l=^pOus*fEWvt>qwJKf1ZD_<<}4jj&#)b zf}^&XK8h(42og-3MrWt|gLSUy@OJrUF=J5Y*TP&i6TZdf0Xq>TrhM-PHrpVFB6pj$ z3P2M8o6?xWJTB5ukm?rm~>En2liE-=6;#hn4w^ zUaQTqxxqC6LS52B8J~y(u9>L zUBzaXtQ$%%lq=J9bUv;vN2(m@#6D-BXts>gRde}!N^?UI70*2%RMDM`h!Uo31&FQ` z`Km^t2t+-!9ysOSAj}ne=B6Rre^Z1@E7m$#nIOAQ75n39OJoYu&n(-lfNmKOp$SVv zZ4FuyY3d3lBq5cXUm65vdMLXVqC^=tU)q9eA5wl7d~RI(Q(@o-+Wc$b;Owfb}$aH+!Mj^D;y^WvtZ6(j8h;&Hzcv=@*0YEmSq)=nR zO1M&xvH-YMswF>kw^;eQ#F`2NQIhw8^A~aZ*2-h3&%g!{D+y8QfbI-ASS5YTe|iRz zma$ts^MTd_R`H7VAApw8QDS~G?k?RCd;}EWk5O<9Qnv+a1%j(^3C{x)QQuLUlyu)t zkJ|2mm!GbW5@m=q0u6k3SsBtjkgF}-Nv;n$eI>t9(auPpWYT^<8ISc`xf#8wIhv@l z*IudPp>T)MhT$FR-r}-c2?h0Qu8vU-%y&7E{d1DED`o?UC}iWZcfuYQYMrCz8W37= zdzD7-WeF{)P?+j^07jim??5Vzy4|i4g{~+MTt4m96!Ff{RbVL51a&cutQT`)XX9(` zpBSqI{!omA+%B{NO?paZo+~uF&JuhpB~R$g|HS@6zB)Pboa{2PKf}}7SuejWaZsQ? zc@ar4sYP#n>@(ho0!~z8*oojlm;mi-yi{Mam~=Qz*kEE|p}L`S94iC1fmyiJE2{*( z4o)pjhIIRy*$j@s@mrS8_%S))G3+|@&~xC;@?qeu!Hn*KxB#$mXo-&zjSlU4{ zIeeKCuXy6^*$tD{rhMveEruAz6jzwV2Z|>~f+yUwtI>!D)+&{@a8$Xoq|<~iQdj=c z_>$cgdM$SrKxA~%)I(Ig0NU1^3Ezf0{XoKhS}ygM6Foq74Zc}-h}C`p4^kGi#f!c2 z@X&k=BvRnY?XEXd&Y;SFAqw@p$?K+v36xDB{<$-XQOFh>`G|xLyH_6Wy_)MXf}YvX zrxGI8S@q->=IhW3s^JX7V&F)(lVZ6>>F69byA-nic zzJhd#M7Q~8pHS1HG?#b=iwc4HAr$yM=7~t40z}s=NeJ7seVmNfemyEj?IQ;=M2LP^ z=SoRjn3DIK14V(;3%szg#^D_RkWF`)-jG9SrgNVcIX&>ek>lsLKT)Rl8V2sT^oc%9 z8$F>ou`qNV(@liTljjqhS4w6yLf1c4J5m>md!WSXLMeNKX;F&C40JI{k2D|;`|u0c zTzhg(5}E-MzBWzIm_+&!zp>OGiC&j3u^mluY6kRzIZ^Auv|Y!G{zZ0WuWRV0Y0_87 z1J=b}0hvI9d1h!StrY9=0H^@YZ@6X!)1=DK5MBLz9G9mfVH4aZX#E{S`>B6=&?tb{ ze3_UgWVg~#ms!vV*_`qc4iFFVsgk>Xe<60JzxRC-Dv~CQc5C#RD^lk7&ToPHBd&K#y2Wq;N4A1+nxl({O19f)IDly zpyYc#l#gpyJRNtimLVe;?_3dFldqZ-X<8y0|a4fuhn* z57pZax?wM@Y!wJr@d3pH*_Gmn;Mh`gCxH|ElbXX=C*31A(=R=Ry&_e&0t>9i%t{^fUR@2yK8$pv?Q zjiGHpWv(kVh_#;*q~aY5LnxYV)M3ojWYv*5celS?sB~6a$%M~!Xhso6CylAwSI#;- zviucI7`KvVi4xCHB4trbM%`wapX$4mQK81hv;=l3 zhlk-E9-)ou3%c=>3 zR=AIWk5N++WhI4=4niHp=2278HHA&dL3EgLX;Q@MjcKSc)q*jtrHUzCS;a=@CdZg0Xx(NolM)p1U`TNLF1p(~-O zwgEr`ReMlq_w14ZoFkPfdqS(mNm$4Sc^o#Wb@R%;V$q;&`U|{Ux69EmHd7G;qFRe>R^29!+8{zt_&wT#hq53~Sh}rJs1KzjAI(cRCyS}A zNQ@%i##=aAJO+j1?d^UDaX+O*s#Z^1UquExlv)$v+PY5fp9ghCl zMEj27m%e-}`4_dXWV65$+HDI#O+Oy5(K0(=5+Jv_2H$Em0Xag)@KSu(A)8l{ zHWi|N#?A?tL+J#}fP%Uv!Uxw^nF-c!=juyE!$h}BG1=?O#uzimq!C(1(6ATL(BOP^ z3?D+j`lV!AG_=#l)C)Z4GOc{KxmHV+_$_;xe!kx>e*HweJkoIqy*0C8xe`J#seo+Y z7edAcxa`mNg;0RnM5q9iw9xA?=q*h7?6NoA(NWU#nh(1*>m`m^2wH8VFYqW<7f$82 z=h!6?qfSS3Ic70tQ20@KR_w2O11n|i)$x?Fnkb{u>?r)jj}MZ&e$}5Qwio#WXWltw z)UM3JP-O)Sb?S#d2Qd)8>3Yh6Z?QyyLER`fOP-UXuUkvF1@?jWHV28%Cq7>L5&lAi zt`gdwzxC0lMh*$(&LtT4;4!_rZS}c`FwZi~7+9FQJ>}RxwcnPbZ>s$gWlJL?e=(ad zSEvwIs0E6@Nuow-A-3tomtQy4<5n2J-?2hvCZ-f(x-Kov#;D zO9EvQ9coJ)owQ04K)A7rXKVu+%O0RsqG&<*9$xeOsp*8LN~h7CvUrkiA|3vs+i}|$ zo{pAHfLw7LDk(O&tz=x0LKC)5eye>Z*LP|+H-hylnEY9;Aa>yi}JO8D^;t8CM=$$W}DUA6~M#8yDVh$GXz$#`UFNr`lI6I`VnbE$SGXCMrPdDV#a>CTt5;huMVb;xukr z6BPc6c9I2g_jx38R&qZJiqk=T;zX_kIZzgf;Nx<7jD0F)46t>&ZgtbJsRi+VpC_ID~8LWVT zQ{2pz!dxiw#Md<+#s`VRn4HbUR{}?{erc0mIT%CCcqPHvz~1hpuYp_AlP`1~EEN!Q zFp6|CIT%Q;26ZwR#-2s;w*S0IcrH$jbZ<>2sc->(f&J=nz*T?#u^CQ6O|RI^7N0*Y zaz&M128dm?+FC6}$GE_)lGiZDQq%YN$!s#TWJc%msvT!Y5nNwGQ(UQoLf~twF(WnD z$MtCg5$;MeuK3aLXYcb%OtZk+@*$$zt2=-4FJI?hh%McFl0>`zu!tb|vkasA^vbq# zWJ%vpe!C%Q>no9PVtvFDcKqbhYO33mI>abRfab;$-peSl86STeb5n_z?)HnNOll4ua7HNOiaAiWBUf z)%XYJv8YVQ6>GstrT4@=MCJM?l0b%LK4;btKF3=39{WPywR~>$OW*LXRAtR7U5#~8 ztO}6LNwm5SIu5@*>?vy8o9RT9pxuiDO#`^>NNJJ!2d3 z+O+)5wGyV-9|H#a|7+#P(SiA94d}_N~~_nM69c)Rr~y4Il*u zlon#|y$D!%xoG|5dQ_i@5gVW0orFApPZ9g^4GDrTLx!{TlW6=xE-6wZ52q|*9fGtX6{dguuIL5V$z>IJt!VJ;FcKn zgcIo{t`pD1NAnz>u}|PL$$-pHm8;5L*~WVnxJJzohut#I%gR~-qS;)XUcRycUql%Z zwzjulq}jFw*L=m$`G_;qr2C@mgM7*cW5HRk0{V^46?<~405cS9pou?=-y%p<$)n(7 z^}$W11FFOBz$D}>1WPrMFZMFH0lw@}qG2f3j@(;}^=)eXNDoFL6hWX4;S^%7&kv8Z z@6lG&mff=|61rYR$I)zFHN88PH7Ap;y|Ho!dU?)y{}(>>Im&aRULutZg2azB$7pNh zy3Yi>d-Ct)c$wYi7^!N#Tp)=-^*1z09-y47RL2zv{eR4jRj<$JF4Oi3_c*sf=o1n_ z9yrN`cO}%VB~4t&8ouqpUcGpxZl00(@7Gv_fj*AVwo60|dHr1-@nSdj7(wtzsABf2 zvnRK0!dBRi=Sf{sf?Nj83CO!XuWyox7p`gJ`z*~!3o5u7YlVv#62|s7*rSyUTTNLR zroWd_Y#k#slO8YLM2o&yqI|9|Ex0g54E@eR@*|hp22v9@G-99IzQ)jw`0{X(1-SHW zND&_I4XyocVdSkgz)(%|TsVLi_JkN{GWRjHdZvrc5E(IXeE9POQUTh^^I%5c>`DUe z>x^6;sgcH*xp+l?Q*?cpa(u>6R5>K-04hjOk*xyKP?!AP=uj7k6EqB+Z&V_1$~aDv zu|2^rDSbsNg`%MYW?~Bceq4A93XJb}1&22Nh7+_74Yk=j;KWCJv!PExb-TS)nF!f* z5{YQ_2h@khwx`#UnT4S-7NsmJUxR-W|NdCToR9{SA-@1B37ZOyNtQD?qHl zTwN~Q*3j8-@2ULg>iK#T$T&o{$5+5MW*>nhvBK78VW$3+V*7;4E0{*n_?c(xN_N;3 zJgq7nKpyfS;Vi`Xwvt3>`XebKch+vlb1z({sLOd4vCZwb3K0*|_jL$E;6bxvx%>#o zfqNzqGh*X(DET1~MNLz%vHMDmlSZlnoKkTxCeeS8`8k8eqjy)-Va5qX7;sYA$hXMd zydRuH6DIk;wjt$l+4Yzbg6!Zy=OjVVAwbmRAo{kL@k!>!0LxwWT}PL3>3A^vp5CHO zs?b6#6&ABU+#O4`$CtfDc+7-6lARSca z7ptr2_Hd=%HyY$kNM$5pf*<^rVPv) z7V^NL**FyZMf{3<4iS_P;!Ay3Uvz)5i1E6ZwJ>PHSa2av^EO` zl#Eq=JZxX~hp!96ge+*{@qTZ~U=I69TcEUVJcRFOf3JXF&O)vTS1fUqjOGttC8o&{ z&iBX?HB5_gr63u*>VW_wR$HuLrSb|5HJY)~p=&i34`E$mZ>2WJ;4B6@}75qDp&<&3G=C;pu`Rc)~+^-qc#RxY!| z0?#lvwfUGrSnHBdA9P(E~ugr>qXW6lcAJg z3Y8Y&D)<%(rm!a3C_T(V;iN+axsLU$ImG@zu3u9!2PM@ksOJ!_vzZdT$tA>I_WDjr zV$|)5b}gO9X)!q?;ALdX7e>M)oa!&W!GgPq7}?iZV>3I@|6)Es`+ydeh{06muG!%CSPF>@ZX#BO?9sU2n+WfkVEopHgpx&5m zL^*;ATYaN|ymfo8g#QTRQ%D}W|8kBvgzRQv82Ry3)`EkD!Q!Yg>nQzlaG;S=f{m{H z5azuZ8?mYi0CaxF!r&5gf*Y~Ayye}cG;II2`Da9PvR(`z*uJO`!*Y!j$lx1h;(2g% z=|-5fAurI`id^$i>~4JHPLzwI=hke-crEjYsNXne_TY=GArNjsN=ovAxz z=AJs>-za`0k)#DGL8HcH75Ka^L9ZcsF^po^qI}umNB*CBB@{*ibLKJZm2}22Z)a@Xpa>EXGjuDQS&E(`dw`t)EgmUv_iG6nq&Qv1wupP59#U zgpnFzmbS9OCzolX!lozHkDS;T37d5o@h^+Q3Rn6cLNW%3V8c02iC1mG&LbW){N|w4HY;a@n7HI}R`SBak6z*EGE6BTrY`{_OHizw5vKB|%r~{upR%bG zYiB0~-E@-eq<9zdu>YV5(GXaLMS=R*g=5d4&pyw?zYjAxqg!aE<*js+Rx z1^hh~tT_#S@526J5DGsn zWgU(cg|d(VWb&N_gT=O#1_}@Gg5?MCK+iwWeKcC$NkVDPEHGBn@=DWngY_bR06duX z+fK8b=V_~E(PU-f^p|CHri3Fko}4(|WMu{XQLKen~`;yx8{U)tW!#oEL@a!~PJvfN-vSN*3wPS6*O zVrY7V)ZXkMJb*XLI&nOPv{{TzOzV7dkkQBfFDIaDVh#*6GZsUH%k#RSv!mqAw*xsd z8E3U{+BjWLmA3K{M|erJ{lFNp3L7;-3KEEJ^q{hJU*Ws(h0_k*KM-T`a?F*knP1Bk zR=`tWTOS1%mOR&hN0FUUm8T_|XDSjA6;mO;bt}tLa7~|ZsxL99pV5(riq<2}awKP2 zr2?@mVrAHr{+;Lq(2*~K|DDG)Ec(Ck{|OC7mC8-_@5DZ~oP~!sa|Ta=I~awkAW$%`>Gh_ zacTkGR3B8aHMAQVO5hCFaW8{$Si&2mXt|-7gPOf4(4f>A$obY&m@8@2u=jOTsK)R~)j2k{ZEpZhuS~}F5(NS6jZFMKJfZPl29P>)=fC$*d4eid9c$ceVw7$6 zUDfEHYNsCFngu6PjrWq&F-nN`>)1V#00u(ZVgG_2R&Y4&z-#yG>|R4EW01f3aX`b> z|Avu7@pKx0{C{ch*ePt5F6F<7!J}wn{J%G$YTIyN(`_C6FHygL`#(fIgH7Xy|K~vr zdxBj;1OE%sP9g_3>|(SfiI^$<8`{@j7MuLLvbD_8jbQ$>EbU)m)81J97oc9>C-tED z53=m7feC&wIa5&xZ{q0ur#T=?1p#=&AbrmYx%Sh40>SYv0EQZyix={fc8vZ9pc9;g z0MBcW{a6lcCQbhVgxk2Muzcs8Gdq{i(tncV?*Vvr+$VX%^A^NPe1ndZW8#142X-C! zALa;%5d8;y!6u~q<;O|?Ai9fQhj0E9e|1(%KuH(u2+{L#h(F46Fdkgh{8<$Pqz^2xY1t}1x{EVD`*+81@2$zbUHIxnG;)zq?QpO;lNJpZ zbmEOT4XD1;D{I*N@2-l}r@wvR+%p$@G+|9GH9Ba!l{$@pXh77TY&MMSL^hC;rl*<< z)7_q?33m7PFD98d+w+i;uxkKej;A-@oVhd+$33_<8}|l6tqxNi5Nr3?>|F4DC8edG zM?_i2t=7-Lu;!q{hO`yQ82evq*UGfImV(rf&Ci7Q6X_F#~E3f+tRX%GL~12kKHb0_2Ug$$t}=-8``zyVeBXmM8^>9V_sy4*7p z-X$)9ie`8L_7E#pC4y7om&%k7w0$b8#*pY)*e zBmA-RqYt1e4>U-3l{2r&`|#ax*HemwTqcv=mRb+i`zXyl-LBq2s{*i$ruT(##0uyzu4YjvB(#8 zn6^&)HX`8Cx=E#Ayj|L)tk8hc;f$BLV*gjE$+Tu<)R_3cFF(08*UVGZewJjt6}PCI zpC`@4=>s+Svac!S@ZqfA7XMOb`45_~7y2sIAT%jaIPWZtl+g9Ur1qZII}T4$zJBRl zlRrb+jR~{W{x|^T2g(4A52sfiVp^(3uRW5=N=7)4sO@hy5h3jrT|BtUCqRyEZ&q-$ zBEASpLtU_{=kG5Z_h>OV|G|;gD81bD&_LlYp1g@iM=2=r#_cv}dqJzGRYQkocdxaL zE|Vnv2{}zTno`qz2Bak)>li*L$gy~;KAa=kfTufHDRZ)8-vX=Lf!Mw40y&pnB2wIAgt2wVs2dW4CI$D(z$@1UjZ?~TyCG4-q zF0_WU*WDyrKDQ@t2GCIBOZ*;Z(9(d1%2Rqy>PG9D>n+HwM~L8ib!h3`PL-S!<^Wq^)rC@gD99zh z;ys#k_jZeFr+f`J)D}!mLtSI*A5FO!d&pR>SCOT6mxU~@J4JYC>nTIdbl6kk!M)mm zFAm25JP$+g!R7k+TWjd4t(x$@#eD_vasUa;+bo<*&W zCu6|nazS9uV)K8Gut;A2=c4iw2fT`{Y?+q6ULyZQ=A5-8;gTgK<7pI<`0-}@6|*Zm z_42}#;j=8ufjaM=Dy+2TQJW6Az3E-ueV;lH^C{Qa@?TZLJ-QP7$KVHP#@^VM7O7G{ zgdil=J^GDBCgtj>KKZ*rk0Toe8b_KRy}JQL&1m)2Tt!X>vGNnKl9U3|!@k%9@XYNl ziSf8|j_Xc6`#PMh{7xp9DJnqrjO4m3oI0F)!m)hYg?jkx;sBuL-2U>h{@e2$OxhO; zgMF$beirg&kIx7)BpQ>^&-*OM-cJ3g#gn!e&%fleRqQyYZowE_BZpV2#JiqO&}s`T zw8&J6L*YHN2{aTi`T!d0UZgTtp=6{l#}l{kv$V6|H$d|DR;g!yx`|4UjDk_4H1F(I z0pZ+Js@ilpWzoLoxtXG^t>tbej6mVhuBUw1rw`-vd3%IvIB56>avb-5WL#gyn(4IH zC+>g%LK12#O7`-rc6cjZYm*&r*OQG}UM{r*H;(mwb8IL6e+1RfaCgx1=0SaBHEc)A z-vqr%mlWQLQPK!oakbL2!CXaD8gALJUwTSO432o&VJjw);>A4=xzxMQ?BOmF74ho* zAd>6So#iWr9GW0-?4SqbvT3>|Hw zVC-NH7?+^fPc?0M2p3W}CCQx%nz)1wU58V`vqe}=5S6yBx5LTnIjkQ_ zijfkapdiE(lO$aDS#(WQ$jzC*Fgw7uU~8sUk)|73yA_N{Ud4Hbx+(J6tK^q%H@&hn zj`GEJ>X@AWVS8_?jNzbxMd$P66X0U-0@jKJ6#fa}`&LKkc5BChfPL2v`7dgc$I1z? z<7A0hu3)AKuCw{ng4SEN>Fszp0YM8)b~;W-F|)5!m@Xf_k~QNrs;M~s_Z`*i(V9EW z$~2UVZ7~hHrlU`cY>X}Rrmd-slcwPDDlLK7bZD5S3)so}qF4GWM9i#@OONxFi} zO%o$Lc-MPQ*&!(KGi%3HGxo2i9CXY-p2S@39J{nDsAD9;Wtl=)U?;@=3E1H5UH)YK z94-}`FIMAsHc8%|2XYYf&y7Z}VTfA}=k`gp*Du+@0Zk0*^@`qoF!oQ`)!Nsq#&1oq zm9S)M4(8oB@v3s*QiDFf)gJf+Yv%{m=C)qW=*S;Ty#QrR@1 z5P_`K2&c6hk6R1#T)4bk*+I^>2$cGWSfd;#ZcE54NPG#%fF>$OiU(uGG5 zy2#-DiHG4k5$$s9=so^xMAW5pYv3T(f)VP*PqO0_bu2=#GqwSny@@8B&Q;sZ-EjJ& z)g-077&CTD11t5tU0I9gTgEyPql7C`RkQBR)C2))j0cXH<8JH`lx&73JOgmT)+&ON zHo%O47`;a-@hn^#2dxMzAxLK4nLHY^bTjs6{`8R34AQP&X`-5SBPkJgl?WFBrPc50O8}`4 z_r>_$3BOxiL~_AFe;iV!nSScDeb2&j3CzK?Z4e#tLRETj7i<;$E}nK~cQRWvSe3v! zQ!c>VN+t2Ym0J{^tltzJkUQ%u54iEZ#*KY%IT}3IKwVT!TFizHsIo9@KP#LAW+vP7 zeMSdeG`HDR0LKM`p<$@AFfo@>ak8jv$n!E%_U$FR>veipr3C8w$VVjv4TPBfO6DIb z?uv8#)PZ}#%CH}4!QQ2`cQ*#k|G-l4;HGQUQe}9r;)4!XjE@lMdSWBi9PbsHaLhvX zX_gUNXK-lqX(Mh-;dXF`2MNu1d`rHS5DzHZR901obuxbRs~`8Hm{P=1ta3ruE5UY> z*%A*EJOABiFL)?h!{DmW91`I*eF0iesP{8YaYIqe6N86RxtnpZpg+7ox1`g37p225 zslwGhXu;kcNhp&S{Ma!NepuHnBrnAGXP26Ki#AK%=D^@CQ)802`Ckmq3NDZemHnIS zqDD!O>{(x~2QQ3T*l#YV4|N^GEmgv5#Jx>(8t?LKb=}%}%{nUCNO$FAEheyavcD37D zLatBv^ey=hsHScPRtTZ0U1S!>YQ)%r0#-vxI`jJXSG?Tq7`SoPOl>Vx^zP21fo8cMC%w-+(U+_H{Fw7{uSFV-YJdX zG9xI4KHaH%+Gs`X_(AFm(4|tsd1>(ZJA@YS93-; z=JW$rPbR7>-TvnGqK}6NBQ3APa!W7RFA{IL4L{s+x!_knKd5%AV%tcnUNyYctbWAR zEEU_tNk&PCEaTPe7W?z$y)ORKAmtyX$x@NKeH6-5t>sb{H@Eq>`8Xah^`9q{HduAd zV0XVI&2LJyV_NRNzb6*?C7v(*JWTn7Cs|cn{v9o(v(j1c#t@r4KMO-j^5D?Hy)aVb zMe)Abju!ukXyY$PYl%YmNTlyELm#@XN5o~#WXYgA(buZ=oB<59+ zxxN3^(GFvogYB|i;RS<`e)Qd8c>e!}`8%&^G%mkgy^3`sv3kkyHVJN>?ZJ=M6J=CP z5)x>%l77qc*>8A~?2R~LR2``i_Ywp)OJQ5jDc$I7Z%j3%7dY^MnI3TqLcAMu z&1%tL(J)4*a{xxkg)%(;{Z#)$@k=nJDypEo3H2X}fl>)Mj!kEFbL*xChY!h4gh&vk zFR!JF@6F54KZ{sbxnm(uG!Vv>$!eT=e=}TD43$dPP`Hj2!P_HA0G)-`6r$yA4MZ@k zV68u%2_Lkwn{hhSRFzm7S`$+#e9cHw@i-~F-o=F%=t9&=57 zs_7;1%O-Up6m?dER^&t_?)_U+9}j@}ne;iQEd8C@q%-kppMlQOua9Zes}-)_uFuyz z3aD0aJ|Q+stqlcx<^&);<2w(cW18pkH5jKtWqYUeI4fgmsPC2SM#ylAgKMnX9t@A~ zp1j?IP-k^r_AhMDv!kAB&!nGnoNii;yEM19tx!efWH}gmB)O3N3~XL9EGX`SSLkQu zJ^affU9jKeAV3%ZlO&%cy|h|$pcbrNyHZER((1RbrfF3WjAUR zmcQJ3X!!R}oJUw0)V9+a(z+T`;1AwPryrSRF(zCT4sb&2>dPxHr&15M81L=8a%obV zxhNmN`3=KZnJI9ii*yF^!M;KJzL|e=(;v^4e2y~IQfiuxoqXFC*5@V@FL$QKj08EI zxvXi!1f!Nk%zr7_XP3B|9-q!>;Xq%xcfwW+A0RvTUh)1!S8a^BT#Vx+C+v4;tj*0L ze|JXAIzQX^{kubfpyZl{mr5syEd3AGQLFn(b4mZ|PJC-F>!Q00)*8i48oMn1!&bc# zeZu|dw4gOa)y(Iq!Pz~WeQe3jX@_~UoRc3BM`8*FrWUNOrM0p>d1|sWZsOu3R{s}l zB~p68PEUEKV}(>9z+Qerb$>`BEJ0=4piNtzV6ECkPF4aMV)3;auFsAOWPJ42H~r_ZNHj--QhxwSQwXpT4NE z&|klriQ{tZVBRQK+B7}~6DPY=YZTV<<5Twr)tc{ljXu+?Zr4*ivW{nfCAF1-@DT#5 z!EA0e8~30-ZPe!RmwTt==jJ3xrxP$4*hS$4-RrT|Me$T#a{*rNZ8Rb>T|9n{l{E+T z@cJi5Kl?o3AWxvuDT;tlk~bys&x1;;zkaPm1Z_piSd6cu=MT{hM@KQ|dQ&T@eWU^s zQS&6;$SGQRw|j-e6l!;Un57qF(Yn=9uDC#kx0F{A>|G$~#ITeksr-b%yy;Wee5T(f zpo@BTL|s4ZXSxvAX2TZRqmCq#DjibMis38XSb;6`?#{#?)h$Xqi|!f5^WR|mu=xze zivkf03~Wzj)$Me0;xZX8$b__|7&Y|SwTR(plF#*2=U%KfR`$Km5HZEJymANgPHsNSt@rkt{3DYr65qM8x1h=?1{jt{S^$PS ztx019W((RcA(xy!)r)Y6HJ|Rv#%>+!9?^<7mUHWqrAMvS+jh>8j^#I2FD~~h986ki zGA6+l7SwU3B!X#UaHE0&m_oY9Ruz6@YLmq1I?m+>buep2X4b_C+AER9U+UHReL}WS zWut9{*me3=G0?D3?To%(Qr|z&BuF+8*oX&CxDe}TZ4Ep%n`*hh}sf_x!fUsZv7P``U;vC45eIqCia zghV>lhF@m6B9abym>#6nHn)PHKOxzpyFG%YWxI=QUBEa&hbu*8Sl>Qf4 z+kGqd2Y=OjC9;dktKavT! zn!sr*-mK{JIIEyig|$yx_Ba^Pe|Raz&TKnj1h)V@dIkF}ykX=CTl3zZE9TAH_Wedd zb8`7hJFiv)U+k5cpYGQ<%Kj=IRIWLi5K&v2UoG=Hh))eV?CA1J%DP5GmSF3^>VE!2 z?A)Y(zZZ8#O!HdR%3X7JQ{4FZL0XJmZ4aC2A+l=yYY#~~WS6-aPXFL)g{Yiflw#3O zFU$(`J(2U399?SgRg1I-vN8z1{V}7Ci}SbO#!Fq4a+yN!`&!6vA#R0f!}8axTS-Gj z6rS7pWo$cXqJ_DGrsK_~qk{(G_4K-=)A^2}U8he^jv8&7n|!cwWr{z2L@}w5>_X}u zxIotSy5~_`;>n6gQwQm(q^aMvNq|CC- zBlXLxIq%3z-}hmIx&QY;^v~EG%I`Ybv0Uxw-ReR6cqVYYq^MKdLY!>A?PZL@ zROZGuQQzm`-u*duowVeis5}N2^shDj>FfUod+!<5g!1(ZD+B>S>QO)-v`|!}sq`u! zM3ACK0qH_0M|vkTDN>|_UZez30Tt=eI|xEVs`QSbL+C9)?!vqzr62V9A+=auSiSIC*?%eq(FiiM!uZiq3j}By)?n`d&_>R`Hr%KfGq*}`XoWi9PG7U^j+qu9E z38;TR*L>BDfRT9`$E?FD{>p&W+I3&6i9T)LshZiH;sQ!?D5-fhe4@Ag#56@}F%30! z8@c=_z-e+*U7FgP+9Hi;MGUgbFE(tSI671wr5L$`5gQJzp%2dD{>%og{f9+fr>?Xt z5)}wdN#7}-#`*_Wd+!le65ozBf^-b5+k%5owGdh4-`8wzy19|^r4yQa15=pukEH56 z123u38Ph224L&lYKa5Wm=-8n+hhquvIH$vZVeS?#eCA*+EfmTK6Z0~9p(vlLTK6cZ z6h=$Y=4}@|T_e1Dshk#bkHw@yeNvFoecEl{LD-;S<4L?Nvq_Q6&b%|j8S3Cho0zDq zVKTf1AV3vxUHM_b9oI)Lj7kD(CCw{>pGkt|_+>YW#hZ0#2n}zi`b}IjHh-m52K4wZ zB(1i4l656eub=8PV9Wr*5X(_(ts0H^IR2prgZ4OU_K5T-z=&k*7ft&pufE!UfJf8G6PK`p55Ltv@}IMJC7oQVk%M>Wym|aCEk_`V_Wi5RD2*}Ov_{5v^bz8 z^ZC+>g)IC6i4Vy>b7)}*>A*I{y~KIZ^Pwq$`$We@!y_V`z}(lGQ^2%!Mj20v?Lj;Y zRm@aV&B-HcJf~#fugcTaryS@W9&(SGe4sxekl;NLqQ=vOn0uc(aHe9N>|}Ptd}ZC} z?IhgIavu0j5n!$^dO?C#!@X#gvwai-ogfX6Q>+)mC2IaHx>jPax$Z;pO#ditTid5a zbp7^jYW^yz(m|yx_Og8sWtZqpB_Gf$ZgNGIhGB266BRJVg$i%0y}pv2)xq9{z4ZN7 z*Dcxw4vY#a_AL!Q_k*d~Xp)necjN3PBP|Qf6jt%B0Bhy-QVaWdL7k_UA$6uc-xFwA z&b~}<{#r2g8^6VI$(LgkC6B8dQt(h>2(rbPn>x>K+2_o~_Mjj`rf2PoU-q_QNTBTB zNNl0P*|I2R9fb%wl; z=;b4HjV=GsEXM!jC`|JfrM*5sTf-7Ne`Tv}x{GAP?oDBvj;%^)<$a<Hk!V?RiV)yWk9wXRO+h3OWVR$i5jnIJ=gpTXf%2Pz;+27&>?m1L|_(9(S_Tjo;-f zEM`B_^hJ2j?u%^C^TOZXWidlLBMz}N?V?4@3ZFo$8!c_Y*eO`7gntZ?x_Rn z)AZAZppsf%YG!+Rvqim-$II4SDuYuV`elY4(&In3wc5@|!AO_V>JZ~FZz**-VBs$oj1NPjgOM394KRp(-B~#Nkpk#@j7{d^yVkSC7CftL<+Ft zJ_;<7llX-WchasztEt*BB}c$6)XS@9h@73g4RD^kod9IY++Ky0w4t?}f1>J9@F1Rj z@l((Y+HY=WddHqTtnWSA9I^~zGXi2pL$OCBH`<(2fM2S3V@Eekg0KyknfT}_epRpb zl)D#EE@&(E7@r0ly|Pv~W>5_}arAN-9|$50CpFFvdaz+Bf5D-}va+w5#1dC`9J2y` z)nG|FFXbW(x*)2x4k+qHXGZx-T(#Fbt*Ot7V!_zL6hwGMJs=Ojd763c$3z8phQoAA z|K2nW$;~NJag`Hl9+b9Iib8t_6*rHw4*!+AdM#WGOz)*re;_qOykI#Q91$-Hw|7ml zeRm(8Bcz~S^wtI~^LRhx(-UCA*@UZ{?|fw^7uv-@Q$X8lljq`<9qrYjEbee+^v5+K zvZ0|TH;GK+Q&8;@WN$02DeF1a#_rBhTb{2ctD73_`LllfthcuO-pp;FC9>G99veo8 zZp_qqP16RMAaC7$8MOaav-ylDWv;bRnv>+-x8aJ`Qq#8Z0}hoQvg8!3wO8UBlh8Qz zYYEq6#hOdMzU3~*FxOL;hLFOkLgUP?g^@2{DmvRgzalzCnRdOeDMm*v9%unl!;Pw2 zQQ4VI83&SyoiBqur>Bu~&E^34oygOvlg#5}?R7Lo5>Nd-Owq@9v`4;1m;5M^UsQ*D zRhI9r92QSIXM7p<@YzU;$$pSH%UyPa81GmxaxN~RhWzevd^cr&o|fe1S)_*vVT*S) zG`PZ=Eg}&)as7AfaC5e)_RR7b(8=`Fc)9{S*-WuskRl2bk-BhbXU@;Db` zoLK&9+MiHCVO&&r&(^nlb-&`bWXF_9f_|y)ikVe+sa%*p;-%>lk(;-M%UV*Bi$tZ^ z47Dn;?wGu?n-DC`d_=^Y_@N)%ph|v1MoCu4%bm?1zIdxqy4f1Zx+#UE*gPadul`ch zYk9LFcOFUC>&h*!uv5HPpn*)J`1T=BQ_^V>y^K-0$N5Id+dubKXkYpp>L~*cq|Igu z2+b)%J8HgSt{U($K(Te!alCBYB?)pSB#boGYs{vX!GR)m^IwUdA|+SQiwFtEG37(c zz#jYdjW@a*OHJXMHoayoA;Y`e0+=uI_~$H$7Oq^}FcCvp6qlECpS}aA;?zz{;6veS+P{&tf4qOI@uLnOX^xum zE?qc8@e~?d7@~aYPchhh8>c?A$b}K(@(Clw1uk7jA$@nl!(kT{q~NsCOUq3>EY$pP zT_Gm;m6d0w@T(^?W&SHORkmRBOzw6TZ*QR(;AzLY$&ZOwk;IPu>vQj4LiQjBTdpbV zwM_CdS)QWB(`{7T@avoTN>Q{R@aW*`63Y)>4o2DkDaS|Ro=h3G^s;HX)F}Ia1Sm%| z^F4-HvxnF+I5kqdm>MgVU=sm>*f-1Y=YR4$Z}}7d?CPMiI&D}_#dA~IFt3!hk6pyz z_RegRv4{AD^HKq;=vPsuWiy%NC()j4#0H2LA>`=!xG;u@*c#}@*?+P z(c~Oln`VKd6f3|*(|TM$i&ak` zeCLrT+C^cd)N&ARN+lc#5|%g*j!k&ad+Axl>OxNzAWL~qvK1fzoNIUw>}qQ06l+OL zpG9z!{K~V*6?f}~DE?(SOxj+-QUWiVVkYQC0@e0m^UK5#5L;6JYL5Qm#**5m>4jC( z%|bPctI%4>RKdeF8JhbBEpJZPRzgUH&7+Qn5xV?rd`T$unjl9~_TpXGV`lA#FQ?eI z3L){=K)tLd~8Ja&c@kevH^sozP!oD~PBR^Y|u#@#Lo1 zSr|_jlR;2Z=og@2Hjr2b!|Q<*C!uE3`%~+v57MjNp&pFYt(;1#(+}-|=g+7~v#iv4FK>u{4Gn zuW84$ay^e0>#;g^Hpqw&+Y|l4gUsMxdSLyGPoiD*&uc&pDC@6Mw7jiUp1cv5!Y7t- zz`ZGfuWkn|9*18*CBq`x42|ppQKCl@{~N`l<4FoxsM5I}3Rmc~Q;wp4f>^EX63T9{b-pCFu;b=$H~tVh{z<@uq4O;%eX6Txqu{_k-C>1w z1)RLg$`fz>K+;k;SJ3Zt09^$D&R_K!^DBKJ+lZdP)XIU^grAwM4B-tU6QmcS;? z3I$9WFB?VG+$0yovi$OZNCD3JPabBjzE;9}+W`N|Y~--vQfEVRC|-k)fd-VJ$lr)Q zNE6Jb4{vv)ciK-PN2ohk&Wp3+ukgubeXS0&bV+ln0vxJi%OmKc$L#y?A7KKdh%VzK6^4QygP{-Hm>yBbQ|hh!%4vv@{hy_`(WGo&9VoB^_V5 z%CC19+xlSanJkP{l0dYVv?)o3XFPwWSyIVIO5PuOi)5n=?TxM38UgnfH8!tuE~qyJ zrM}V^t<0&vAf$l0Vu^yA4TUKC7LvNe-ZlgA$V{G? zcNhd?n0yI#Pk%`4TCe=|?RWg;js8k4*(bIdL%`Sy=Lj;=rxk^FaQZL5Up^EvURA^Q zKF@*v5cct1ch;7&Jp4PMaA)>h(DitTaiEaW_4(DvZ%t0^9bYX@tN&m!#)=4;ElV}Y zT&C!~rrh*XkG3&eX)e$-ZiY8rbDHVh)}yRZ_7i;xp^uo^@98keo@P21Vh!EFr7aC~ld&Yyz$FvqxJ$RvqfY}>&ULsC zd%rxD-roY`Ddq}!KT14qNw&cWI72ao+}4%QtKEqS2D=tFz_g zty0>9^A)wCLOJ)rb?g2d6QjC#Vk1;{PD^&4va3w(B4F&1JTOq0On%Qqf?f7g#P!+Rh-f04pQSk9MzB?xbec06q73VN-;hJnaVe%N55nq2yo!p(B!Z-a(k8jAn6q* zE3N({P>)QNfRhge*BFrJe!vvH{%4mj**~wyzzj6wsj!kk#x&n3_*S5F z6MeAR76Rm|jK`Y3L<8GBhH$@>HZ8sFR}j+qYaQjlgXZ$XRZ2s%Gi5%A#;7T(4<=%p zzxv6ULXEF+ptzcz8GlHbI+qZ1>e3)+eWiEco`HxeF0If+i5avH_BRw*462^{Mxc(| z0+Hj@#8zb~TBNm3%(+rFt=bZ~!z2BQ(ei;XPN7aCRj505G`g5hyIuybxycsEx+by269fZ zCCSh8|IvrPyaLYS9}Ulw^nJ>v>1w^lK*Q+_t~9oay$?u;(Ur;08v42EM`o;&FeUW; zH{`Wg7}uyG3klxE2nNw#aFN955A}$3Z>K8jwVW?dljE3L6EviInIO{ z!NA>SadD4ISOF&im3yL7=mR+$9OskIIy|g6Gcft3E(gLg>^li%8FZdPiLvLIc0h>* z8KPsHj*sp3#}O_b3xf;ZkT}RCBiOdDC`zwQGU#cSnuMRweab=$U#Td+WSPue3NC?J z`jG9pWD`Ni9ROFn(R_)}p`n36JY!*2i*1n+%10kpd0ESze?G|?teApaX+lfSS^r7d zE6^&EoFJ`#R_e=<8;!^hvzB8?6-JT&Y*mKv_)&r#*6`5{t?}xC5IQ`fOp#KvW%c@p zjT_H6cFep-$n%2{uVx{CY#lxvq_>y0JQk1uMPNZk`yt>>RcJ$>vJ+3fN*Wv&`i<`U zfWwy8W%#+F`n9+}I;CO^Dijc_`!{rx?eDVNH6CZ4-yM0z>f}ocmn=3ykVG%1lJ5ms z6tBj};gzOKJ<@n*dk+qklmECH@09&L)>C)?uS&uZa9u ztOd34VszmYY|n`S`8{k_Hs-7MOKkL(h48S>KR)3n=z|{glzZ4T>D9g?!Kz&p;&OcK z8ZkvNI!~gh97G~&{JrwVxkXWG5TnwD79yyOccQ)BZr*5o)?CZJqViRzuVS=n^P{!# zKw-x_cYR)BUd!9As6dUxlw_?T<&W(f42d5CXl`w0g>0wrt@H$1p5Gfp@rq<@!?^Wh zK)@}savgI4TAj^*ZlL!Tk3XEJ)unRhf&b+oZ?@76R5>L^J%@V*g&xbevhz6rx|^-G zpxhFMrsSRKOm=+yzg1)Yr8q=TH0FhT5Cznh>szEVpfGXkSjZ`*=CojD`Uv5n?{zvz zqUzbUR+w+8tz+$C_X!dV?NI#-B8sT4+T@j-qmdfW4b7s_4UIHQj^-2$EtyD+oT7`m z5v&(4h@cIH=YOi>Bp(>Yu+DMUL7_PhC`zxfc6n3Vn+{@__EK7N{4g?~N-}mWBfQ(3 z79J=*l-E)*OmW|RV7eikFcz@1J!A!!q?7d^i#3=tdmW-|t6r?h8mpLZn!&pI!&F`k zL=#1y$aSxci9yrDktCj<0ib5&$E zF)C4*WkU=$ONVoKhHv+(u&onqLMx}uGp{RjYU6{g%Huy;pvPjtY0#=Gmw?XWK=ay|0bMuj`<9B-?GqmmW0jzsWj|tE3*ceb^HC zi)1futpM|~B;|SjHvT%R!sq`gt9jdLT-EldyJX&?^!B>v{UA4?T}m467ZEbi6O(hd zm^$f~oa5N`2G3hk^XTXJ%4O6XqMeQ2SsBk$zPqM2qa=04@2rzTS}#0Dl1hbLif%49 zYI3FTE|&DKV&?08wamk%#PG5y&tw6fW8Y=&C&!jEtSTp~BGS*~cFA^HM~LG*FB&dF zZnM3w?N}gZLQRg*FaQ!Cd?DP%7^c4uQ--7&G^Jibg|x=jj=kp^ zC_#CA=D_Q~lIOf``Uvd3v0I~+^>1DDq7Iv7yVd9V(t@|bI@IsQJK7HCL8ZAD(yONu z$a{P1!)rGR^p0$_tj3@;+4Z`#s5TY3jAQ;ir*G70LNU%Uq{TQ_XjDbSFJsvFeLJ)| z-DXNfPt4b=1MO~pt#CI{+~Lc((luG&=>CtA?4sDDyjnE_Yr279PCa8bxbhk9 zwBwbO>^*aT`lg?)Wt_1u3hF)?MVeVYY%za`4|O@pxoOMPHPp2?<2o!`I&0=tesp`l z^KYT?f(HGX!fZES{!?3w$UoUUU+`gZTEKP%IiC`bol$zGBR__J?&gb^}Z{k{u~kK zDzt}7^etqp>dlx<_}H3`B&MiZ&*(cBy#~S+zd%@_y58T(TzQPzMtUa#+Z8--)I&3u2Qm zGZN%r+J$_G)93tVZnDJyCmAixQuKq=VR?8GbWE=tx-f~ysCS6U3sK1qrTHtEN@pcU+L={c7naMG5!6^o{m=o=Xr<@|wcW=70>+O~9)->+jrlq;r(FrDID z%N>yrj7x?@*Ne)jjTuQRLv5t2B{ASgfP(Has6i#hih2Zsf7zjB@Y8gNNY&DoDz;f_jl5 zohCdm)cg=#@Sy3X-0I!fuVVdF!C15#o0>?=wyU%0E0tb=5oIEji_Y7yl8`b;n=!9G zxEr=^$R~BYpp+h0#YM-}*CdSt6x;%F5ZZ1lC0nX%?WYm zU{dsmR3`V5&)0ftboHtojQM!kR>aB2i>EkN?2U6`;1R({-!)f1JSm`N@tWlue{Jzn zJcoT*PK8yKWlTb*T`c4I=mj>%U45SB?^0jZW_37FC4?kYc67aw^3Q2KR*=+>7v}>g zf@>&y_&hPMUE$X<+of=tw}5RNF4&pmI1EUam^ka{?nWQtmT#{-!6oiqn7LbWW5kMJ z;p@#$C0l8DCZ;l6%nW6!3_N16VHj}=)ZlC}HtI_9oTs>}e<3KP)XspZYNx$?kBXIY zh{fc>hs5_<@l1p8nZ){~5?c3UT)9Bs6Qept{gMggm0Y2f?`^)hwx%SPNT`Q|Nyx|U zOg(RQ%KhN;#jTr%;X*mPI~^xO-Js_jK3Oyr0PwglhLJPEjOWe83k$={jg_wL4Gx4= zC1l-H)ALIk$t{qG2$MFT>*#u?c9{gRdYTjh#oJ0zuL*BOUN(a|Q#0h3P8u}0yl&bz z_Xee?hCLr$Npbxv@lRk2`3dgniFW4#{U>ulei#;W-#v)CE3x%{V$mu^-#D*fOih+1 z+x%!1!{WV|B$r0v9&bDJ8uMz4xLLXm(|Edl(|+{MT|e2<2c`3NYuKwfXANWd|AWh& zEu#$MAS4iep3$E1FE?#YS1oe%FDJ5EF|Iol#fg4O(;+P^QtUrtXV)3u(<6G9&iIFF_NHnFYNj5O}g0s#t&-NbL4 zU?O33+CFma%PEn1*|YdVb~`8Po0Ls8Y{q1)@n&C>GwTd3!toT;VJ@!SK{fI}$5 zVnRqkzPt)qRTEwE=r8=J7Jw;5ny=wL3F?n&nc&wv%asmv!~7n(wj`MPhugj8A{J%4 zJGD>G+$M6WW|p3hTapHpZM`=B`@T2+Q?FrPYJKaFST*ya44XcUSwA8}4 z_Gnu|wo(q-xS3+|ItKl9v2k&HO!|WiYthe?|4g3YzDjVM+xNZYs($^|;`>B@y2d>1pebns{X0m8w{Rh^i)2huyBi=S+C+SP zdkEf}ezYg(XdZf98q>!`CrfvhX|98^-ki@3ynOnTD}wg?%8WF!+|4rVKfD(nuSZ@% zJC8_|56I0rhusmDpTpB!z~@1a#wyra>2X13$N7<^!hS2X;@aLPx5lJtd?seQU9;S_ zYt&e~j`7@A<1?zbdaB1tVfMPR*pc zL}H`~-BejaF$%v*UIHzsXb5oc(zR#bH9F1l%&05;-h3nna_?Uo<&Rj_eTSocei4NI zRwLGT2X~4Z*3-I)$Pmpvwq5n={rW2)Ke$6I%2#N0eZH|X>Oze(3|kkJnF z9tbGEG=e^D1JuS*c@qX|rz(a_fwG4jh^Dg%{>Fk!zq~t0DT5uoyKapAYKznM+HY=C z{fw=#dY%itVr@S}wlijrl;^j5eI2kB|)gmAzA{b7+`;PxqNx^kM022&!kFApb7~g zr3(gWmcmkuRM&E}HqPy#!o#A&CzLwf=+nk(~qls$Rpj_q13P$3_6nX4CEdJaOw>3cnD701=*(-saK*Hl+CMK0#yK4Zc{bWj?m~vC zg*hI8($MA-S*v%!8#WpwrHGLKDEERMpV-|fd=3Chan0+~wEHb1g!T0*K4po`Zj#}o z-`~{OelMu^+Uh@B)CySrOgKB8I6lO}Y<)mEblq}H?Rvuji=(_Hn*zGC%0(a4Q9OAP zaUKF&;dfydp83}?<`nX@_YGu2!}8>2Q!C`pI38+)w0R$8Jf$EN>Osco_Z!0xg8%zY zn1AEBy!*$uc2U2h5fv~Z$u33>^@8hsN)_@1%XFQq4cqhm= zh)L280KAc$qS=oVvF~9nemkqIBf@n*A>U9 zG&^e}w`xkka!F8{n_duvSA-=sM-9!m0TFaUc7MFvijU1pC3tqLzg^yM$AV4R?t44^ z+AY*}+^Ys;P5V|p1xC9x=vONd?J48?uLbb3HEkYBb*sy7igm4#B?8_FcYsgy5Gw+} zk-IZ}!7j|)FNy;8-iX6=dk;)5oF${J0ptgA0kMRoYYiiu!X`jueaYK;iDLhas~U3v^K5Fx znnbz)kv0j7Z)%Z3bp-;xaG4a0$ZzY^1qU+Sv;u_5Xbk|21n~*SbAc4_g2l8L#>P3i^5@pk7DLUV@u_eBcYe# znkfEltRq5{Qv@XJTew!R&LP`~gp)SQajMxkXX-_4q-;ggqE{bJDD0wFK_G+_XE38D zo*#^E6bxv00W6!s5mAV<${xSJYJGi$0s{YKo4^~3_Buq(gY?7LYuYdjN0`OPnCi1w z>8jcu0B<_e9; z+xeIwUSTo6f0@|LyDC$UdwILI96}0BO|y;my-4LQP&Cc^UF7wDFn7a*Fd;6g)Du!l zt|Zf7?T^TL;T`LhEwoaA+5edk{Z@V`412sSA&-kipTGIw>3_T|cn7jv$)Nb%*Lz|w zLWuF+81ipWqV3jJLelQtZ|%0CmcLW)0O~F-K$ToR0+@#yh+rV9#PY-6pMPf)fTOtp zu8mjHDZ{=JBUOL{zk>e#`8TElkw*Age zssFw0|4&Hy75P~wT>XJKt=z7Tv_n2Qhi`E;5n@gtVo?@WJ{8Ho)BI5MJ$AX42&eBJ z8yjox8Qd#D`Ps1#Nwn`ARg60rN?ZbLDdQ9V_;q_ftkZ7>w<}-o^0QHtqlkSAuWl5o zchIWN_|Lv%f}Rk{0eJGCF`t8n9JO6Lc~fqOark@5_)+saD;dv*FlyQSkX|kDn0TLJ zGL``V?CUOQB4Xc#dnIRr*aJeN0RE76h@UuBe~$iANGn*|@P&yEc26T||0{-Z0F*WO zDE)b1b*?c=Y*vS-*$Mor9HAw>{H}tZv=uHSB1gC-7@80(H5bl9!^Z0&D8QX~wwqBZn&uj_|Q4X$KO! z6xg5eQLcn2>3Jh*jQo$V>v#@zD@%9LNg^pogLU8x`rWxbmB}xlMbUA>S2!C{iwQAn~8~ODo1&03NBvV${oRCjV`W^x@JuC2ui(Q>rJI?!cM)I;A3y!5K9U|N+Xi%x3X9nd?Wggd{Vohjcp-? zPI8jx3>QSBn&dW?1|H28x6(Wh-VlT9oK5Rx5qR|T$j?*KF>qmbA;()I9dw}J2^}^& z+d2YNK2nmj#Tkgw_ia8LE1qhx#hY;#e^2n_>9>&9H0!LNHbod>a)T-D+ z2~9IQ8|<;*rRGm-l0+)@)&?^@DP_Z!!vv3~c>n%NbvG>m$bgBvNob2gWt8#7FH&K5 zL5xUN$5m#nO>G=R<($cx!UtLSrFPM20aI=5;vOFMZ^_kvfYM5;V=`Md8zueVz@`8t z>P4Hd_3u}0%WbagzmNN^m$u&j_aC_Zzd|7hR`-AJ$=&~dMSpMh|LIxc|1UDCd8s9N zf<48j-|>ZLVz(oJi!O(^5Hpuc{zA^vWSv@HWl|Hj|C^~Q8InKb(uEYWILTm7O5SQvXF@5sgzBU~+ys3A9u9qW`+2UVB z_Oj!zp1%_O7aA6RHhw8PimrufVZiLpfR)gNNMUxmg1cXLs0X!~+HaQYHb(C=Wx?RD znE)r@48Y_n=`eWkdB>u~ypzb2w)d&=M(xO|(tjVL3%<4oNFgPGm#_Y8_X#-# zm>sVYSt)N5=?xujjDO6kguy>`nb5|=9`pcm!0|4?%XkyeSDF=p$SqV9thS=`^NP0y zV5|H+xdU(QETS)o+&C3?YB;F6K>iYN}-RwRUKHDxoZ2^r1YOJ-#*GKci*R**)bZ*wh;=n0^LopShQqg&%JBIe3Y5Uq8 zTPhzW_dMUP+v(^>R;Gtdxf|>>!A;{U2OzamCzIW0jYl?5i(ogo|D`6@(?(n5wdpbnUxZJg##hMi-4_q3$ZI{ruFjU|p8Q4LI2HG$v)m&M zY!d8Wn`G~)U3J{BKpv1VMNKQ=lTt3BY)k0CIe3`Lo0M{`d3T`1$@hglxvj3AJSA@& zi~I7mz@vUyCjFEHKj7vcUoPa~}ovK9Q zct_-R^MobL4t^>m{_uIc=6#T~j6~V4y9;Z9GaT9U@AJGF1g?xbpwqgx+TtbhmgWB0 zRDc6i7C&kmE0ZhdNQhgw<-?(sVs5}L>6ATs`h!Db*i)0%9~al%io++lvA}HU!3&x$ zhNDmR>UiN#AEWRe@ULC{T|Xc71nfKQY@VI?IA30`$A(%hj;iG~Z=`w}toaET zhaz0f2xt3WQ%8|8%gwjYR;5b)E&tN$^1reO8nm}l2xl7$D4g-B=OwpMe4weLN0zJR z)!i7|gC65S--TJZWidf2laNj-(Xu_(f#4!v-^>2e)bXJ)0Yr1~@ zQTG9EWVCKko8zzjf|*(tt1S_D7>A_zCI60cytV1H@4}l&Fr2i>i_S=qvc0PVKX5+x zz;FR~j4!~S-UfotAaZFo9@my)C>w#`l4;i*&TLo@td`0SNOATaXEPG-ls3VaTw8rj z>f`YqQ=Ct;=2tbkL&cQ0dMh{6n*FEjNi9x`xVryx2VivoFZ=l5j`jM;s1YHL_D=1= zSh{(9ePiR>QSS|j+~&>H{c?EN7dMtGG@YT91oaxI1#+{%TAY?Jyt;#keMg4)m$~1n zBl5SB*0ac)JBHe>p9W9ccx2%p*y_mU$_*Qhu#ME;G7eRBo|%dGm?>)3(u1LCJCBBys@sy#ferN0>_Sr^`2b?% zFLLPEWP>ZW;fAQ(;c3rbK#7XpV>scFL|)l4B7Ldne`61gvc-LtaCq218??|gM!GC! zmnK&`=J~)9BLgI)P&S21S+#UGkrk3>D z)M$etw_$_my6j@A6^`6rjyNCpf6X`6Fz)b|N5jJ5Z7(sb^t%1+_PQMvavvz9#^+FRV`hJSJ+w+4;l&d91G&gh6 z-=gf`!1EW7sz%p8Qtjs+#lM-h9WwE`d-YG0?eOCw2O3$C#pmcuv;)Wdw*`gVFRqOr zM)Bm0al*l{o1(y~5~Booq}6oT^l-sx@6Nysm=7*JL5Of;5npS@zn)ZZH<6we-5SX8 zaXjtz1;@LS7Omy&zS$F0TymG!Yfn$R$Bw4sFN}h(n^5%Ee!%gR z8;g}{4<%B^a)))`ZD%O!0N9VmW?(;Vx)>suTtHQ(W=-Zn*{CNTC;ptNj`LClIC}g& z_WRQZTW&15swhgNmgNr1zz;ozywQW^>HFZQJb6jLSVbWsE4@)bKS8&&^p;l%;+^x4qMHHNgu7h2dz@Ke4z5_!0)CPoR_^V=j?m>LH z;K`5IMScOku4Nw0CkZsQg@=JwguF9x<4`!w#KBfYp2`zkDslI%rtKw&iu|el@4tS! z8(C@SQ2qW0urnmbB*5&2BhNCwT--nH#NBzWaME&{f@1FhbcV#`i54L)N~1_M8f zr!u(e?grXZj~eRu@>fJJpz3f#XzVvm(`0+l^>yt=&5fI`>tBY&B_?7`Cqz#`#=`;h z{l_dUy+t`V)HzS2T$kG~LD?5p&AoD);I2MeNKe-guD{JrK9=kuO*q+Mjal@;WuD9l z4#_ART4Pf>>-JONp!ER%XeYJf-TWr8Q6WYcyo*gFX|=5;GP;h>5_Vtdv55(Z6lUlh z){Z-9V0s3K8H^26$$reN0C;dwRUJY93e^mQJoZ zzscgr7rw!&UX^U$oHZYCacIEA|-D6BQ2@-)%L#>ZTlE$3MAl=Nmmm}FVd3gb0g4f_6Q3AkQ=I*Y+W>ZLUN_$EatmjEP&vm_7^J{B>vupM={O~#(f|FNBb)3UWK~qCr)eS;_ zb0vbs+4m|@!OnIJ)& zQi^7&Nu6{skIAE~KVIC6e|w|3FR5VU;u;5FJS_L?6p4p)a0K|)27tz_n#D_U%mR=2 zYVuQlvC6U5AQff+6|rsbs@((~{e(8_udBb_K53Z#20?VQ{{$vS=4%dv`a& zvtUHx-rCO<<2=@UY~sTWGV;AZ9;&uZ^0~$-=$~r@l?Gvs!#2}Oc!XVz=x1Q|()~F6 zO^JtbLIxG`Fh^y%*A~D*zy}%b8w>dO1k$#)|1+NNerXUSTi_ z;zqXXcG;S}>a8hF9!9Ep5->NHJ9ycCcbAymtcEm|2XY{4<4F=odK<*_%K=#&WFsR% z6VtUR0HIWmN35a!nuP*I5nUlLlwpQjKYX zWDrk{g_>WTM&J=K3rn7NKJbr-1Q+H`k}d}3tu*VmX#s)<3O8}zbf zSpCCqBHC!N2}&|TuyZ+YPY;LBTFH7Hc>QnYeFph>7>p9HELArF9n{@WR?bD00=(_F zZ4a(Ql>y{<22vsrbDw3mGTfU*Z<3ubHx?$LJVb`M@%y_C<+6Lv7ACl1rd@q=Xz8uy=%a6EqS z{5Kd~(Dt}VLmsNeeb|8CkVzGJ7LdNIlIM`0V^J+|6-=h9HeARoK@*^<cs{~uk^wu?v8{cES2fKS&N zKBjd=eD>VN$WE%_sTR51D?k@@<+HW2fbbNBSXUtdvTmfpP{+{gQlfu>%Sh2BFN;tX zImg^icAe>?TeX$xLQZ)D2HyX|EKxD^Xj`6A=x$mAbqyRTVv5wGD_}I!Rbcuc$j|gy z&|2ye(}J^-QG-qN%yprxG~s4xPm2#J*#blM;ebE@9%JXFN2mL7xL*97-*QPy4L$5$ zHbr}hUAYwCjFl-6-b)g8iSq7!vc{^3DR!BHl=$+gbDEiXK^hWr7lpCRMEtIxW6H6R zM6=DV;*xS&VeP!JyCwWpA%q-zUpbj_jj5bzJahi#ezu=2NQ<{xS5V?P?Z@`E^>jkl zRdQa`thSx&&|>qk6JGhjK*JWiMg>WR2|SY=PqJlJn-mm=^R9g2C^D0hJTuU4FZ0J9 z${PfQ^&~LJ#L<0YP+l4f-Sh8FGJAEbVc_@WSpP#e~jQ$38gzj-dS z`iwP>9*UO87wAbH4~s5&GFH`@`qT8K zW_FQK*TARA^ICcaF;stsma+N9bTD>#zc71QTe&qSb#{;YJj4v50GUHHeXVg0{7x`t z8c}u!J!dDBhbyy2c4b0FcA(W`{+6h}4L-+2zJdp_VwUOg_VXM7r9SgA5El^))qb7T z=$kcorko;?zFJBogm_9_YrVTS20Jc}$IriTy@QuuRA4AyW5n_} zm&-+rc2tJc~dmaF7{myAUCVN z2K4^0dNZ7e zsMG&gqYq*DV<;lbmb6#EbT}dHkAir`x1U!IK6A#*juagQJiNzDb`of_jKfd^va&n~jd%wSS_h0Svm%#7l%8Dzt@KprZl{J_MncK7kx?UfD zd0IG;YrclPdz6_JJ$$l`AD|U~?&xKEwM{rOlPP0l?Q~wP$1xtpNb~yb_FS|gN-@)t z#FL?#LJ%k5>I^^EO#pr8r20bK*LtQK%)@2gh-TEL8!ORcK~1>&SdJmkp(+s@U}D!n zn9#*?r&2wGN^t7%*u2`tzPyE1_l;F~BYS=$wzlOB%@Y45RK+zPuE8$%p5J{G&HHaP zQv{fH!m|YTHjz^^zF#FPT6>rIe^dU_9nufFcjjJ0G|#^~SB?RMviTC9WQw(&GOXrT zJg@|H2CbGe-Ko!fI#F5Vkl^nL_FapDvpVy>El1q@GCz1V87aG)D)KhGn3R}?g8g_{ znMymZ+)qHV(;Yr4)Y7+XZQ2)HEqZWY#J#)dkMTrH+VvkLf1)KM9Rw00cECB~s#gKk z^tn@NI|ZbX(^^VISV;;M*7J$DNxH=}`qaE^M@88%U)6#g@eGq^ZZAmde*0kBQ5x5{OO7cWFNxZ-2BYyBQnqiiGk_QU7_|6~U!FX|a4I~@j2PfW@#bk|WoOrQOJuyMb# zRrV*7BSa9!2ps-7X{216_FR(ZXldkJAr)4dlaF)G_0(#cqJY~BbWN1^sn)8rB7~7ql>}$9+5iNI%?0ateI@Ylyl4TgOW-C#5l8}9kOwABc7!zX& zVa5`MFy?#SKA-RB^Z)Pn@3()tuC8V-&Uv5nKIip(z8+7_y=6mPm8=jWbnZWWcJ4S3 z*>?;fLLCXTaRjT)QI&ckCwZ>kQm%L3V%c8lZS{A%ywhy}=o#J4@g%*Lov2L|xhgvH zWv&a=v+He}_ZPF2@VU|=Ek6&$bEV6UqRB7!+Dx5g%r%*KEHb@&!G^e}V{YR`GBfy6 zWp_}k*5sh(1?zZDKw_DPw=>EqzIYxEGuur=0X{GNj^$T7l|-lF<&?&-Mg}97P;BOO zT)_7In9!@=LdtBJdv#MjnaXxw3noa_eCN=Z2gB#90c-u{ljh0{s|`M1Vaw0;e)2C2 z$A*x$ICnQFy~Ae5xOYot0%pD;%WT1!hs*U%zb?K%;-}V>^3_Ij0B`*8#5UQdH|$W6 zs0`X{8YF%CRcb8ZXci04%_f)r2;SZt%GdK~K1<4(^J&DBDofn9&&#|VO1}p#ce{7j+u@H8VdH0EFBIDwo=o1gN#EC0wB#Mf z{>n-a2O+B`7p>Djs?2n$rz4Y<45($b(!>9r6hD%ksPCx4VT0NShtpoKBLnKjT<^g{ zCTbIU2%T@vok~3~T1lU%nGUreycdLJ+aAl& z*OvZy>>_{s&~E2n%-PWlKQdg6nk}y0dZDOwP5iElLFp-$Y0sELjF=2w83h6?;(NVq zKx=0N+Z*=z2B#Knqpml6dgZgblKe14eOHT#9hoz#cq^TG;~9 zuF3hd(_&DOb=1D=BaSgIU$r0F6t;{0q6IfgBGAzA4x)aPsVR*{9rUiPA;4zg2J`#& z=Aq$}K4FhO?)B^*Rtr86_Svh zQ{0w?C+f}y51gw>W$I&cH(qhqQk@q@>2vxx40VKvCl6MsQi^@D0K1mO`OfHT`^M^} zx*20)r(gKut8>RD{~)u~Ti>!7>LYX%JJHjkUy9g^x&(;GB&muvu<6N<5AHRb4f)x` zjV}`Jv@lm>iN8vHS+=62j$sVpajtX2UV`C%0JM8<1v*?1iqBN@757HlAu%d5d+6U2c{5izlV|nu z-);bKNe7{3t&aV~ffy%vTiA%)zu>c*I$j%;{S*V=P};bsCy!%YRr}1dfer(jV@njK z+}OwSozY8h=FLjfhT6}iggWT?ewTp=*XBm@gnsy+Rt0vsZQ_?t_7gveYCR+Dc*Nu> zgbhgP^oJms4CwlSs8z)Pc@$c~@K2+mDF{rtd%? z6=(|9fU1roY+67({hee-Ko*?AceEM|SNU8UcB0JYf-~k`S+Ew6MUR{$o-fGsmpX-Z ze%gAMxl(<`1Up|5VsevZ5C!*vMIKZh(`YfVRupq zO3BU=WbA?e;hDY)psEW8n}dFU*7|+nfkgU$L9)KBlp){dT>A*mAb>Fy4qkpysSef7 z045MAa_uIjA%zAPRIpBUH6C{xHo}~QaH>Ippf1>eNQ44fE=$=0Fz3M6TMm-|Hvtlc zAXn4vTgAP-nPwsc4uHj~llAt37ns9YokHo;%D zM8|BH4OByq=Q!8~p~rI{dOQ^o5K{Fiu@&jJ&+>i)D@r;ndDM-NF8U(HClc|aj2e{V z-v!vLk2rG6Z@i@s`uUAch5aq?U9sTpSd3TQjznikbrReM2@Rktgsde-#+k{~Zp=Wg zCL4vR&qDxHfb5Y4IaVM15qC`YSNHtuLN^+pb<>{QiJVL+Y)3|k*@+@1K3Qn~)g*|3 zEmX19!%uB=?6kkW42P-_OS@cXyIz;yL*B)0e!c;ylOLYKF!ldXN!v5-V}iNo2wb50 zs0xx2SG@1Mi_>@;)QAQTs6rKgNqe&}NbrsU2~UkBkR7c7|8pF;MV&qreKf`5mwnsM z$7FI(HhL~XMz8Qi9nzBE`m@Y{!)e`jzuTyaAY4Xp65~3qA!|2;#8pvTCXA6)0I7|{6?Mi$3(l_$D@#NMIjbSTPeRJ;`hg8P~kYAquqr<~$?9WY9Hn*0}NjPw4CPKlfP42+~bWmZP# zz7oidmh@gnI4nVIzrR&HkF#gBS$a^3mt{ybR(;yJ*tG{Vb z-oogZgCF}?0KT07)ROM=$nllcZl*rlu#wF;Hm?@0+_|~%yQm8aiKfnCtE0Ikihy>l z9?*SXr-!9{1$#nfu*kG;vwsWPPjXTeK84g+8pa$IKxObMeRMZ;YM4~3_vV;Z!_aH3# zka9^g1703ArsEIyB#>J-N8QKV!M11c^0I;}-hVnPW|DlEyk=D?IAV$6h}m*DQji*7 zurl`+Z8ZsU#{0L3Y#Ou+u|(l@4nZbYfKCPUW;Wr%sUfR;T?_) z0O|tsy#wvrivgT{pWC$(Kc@iGe4OD{)v=F^7~TzjxRH!m;8PH>@uuy~>IS3M>cgKe zh2~W_05_|YQs;QGUSh-*-FmS=c=6Fjzk zHTpYe!P^u|%X^#3ncm~1Om7xu{a+dbtBu7)mOzMOvmYY2(~w8MOT!Xik&TKPsl}-? zXdq7L2T7whzVWAeT58TD+>H7YI2dDFRy+FbjQZZ+*G@j6&pVwvZy2dm%{~gsG1fL$ zrQ2n3_JYuhL-2Ms-splPkMw-uiuLO-Bx5p9-v}?fZ}16l-gg-fmkFJ57S2}}R0J=s ztN$%U;;{8A(jA>z>&cy#xn-f#*JFre)QXm;p36k|VWV24!NDP|JbGXZ*;g0Wq(3Tr48W-{lSi@6{Vh>)i1|jCW}zySQY4{+`QI{)~_u!|@apd=ARflveAjWJ21zTLtogb6ryLEDf zFgW%I&|GQHFH{NYo!%8xbb;p^{)~71tz8O-yzwRMaYDHjE^#4t-1l|n#_m{)J(mV&s@0I`FD9Oq^n@4MX3gZ9tWR2^9o$=2N;Xk+O3G`H>|kOZT3=M0HqE4*aFhT{4sKH2^lNe=RaNa zt}&p>?uCzd#c!u$O>bAWRDrRPn{e$pAzfia&HIsTh)(e4SO1$%E4dr$u)Q4I@xQ7t ztMTxoYZ{1CMFuvQ!RVwc;Z`kH@qc2%{ z`bM0`B22leMmA&VtkWxjarT^FZqTPtRW?Ojr3#7H4bYg3p%0@TJfn49!d(%yw!xjtx{lX%!W{+GQjqMfDZQ!E=fsT|zcgQTIKmw}& za+CYotC3FN$~*%S2nNz%egN=4gBQO>1VOM}sz^_dcFC06(whz>KuL7*D)HdfW`|uiDy;V`g zCPzEH{20`ypn{l)_va?)^c@$`$cw@cHcCHL^^-dHCzi|CnG;- zqI{AZPC7@9&RqiiTn7SI>^SFeG@an0pbNJm#c?%hD*Kx_XbGzqr#(K9hoh|O^`h4fa`;TACZ{|()cf`tsMaaIXD-q*3?1|&q$E!zN7 zZQrYal`c=Qswobg@LUSxVS*s?tqPjtnw|p4_aJZc@aNmT$~#E{Jhr|$;S|NUEFusr zFJOK*ufpQY7jdq%=||JGuXXvXFyexZgz;ORF&KTqZkK-0_e`?}z;kfX#D4#5CK~Nu zq6-pQ3xS0B_hh};bN#ip%?W^EfIC|!mK;kDkVL6B$=ymxFjiOiLJ=O>k_^XDP7|A7 z>&lEYqTTKeMihBUqfY(;q;OFwBv{M=ji(W_D3&7FINU11y3V4$?OvKr7s<*~0 zB#q3AjC>M3=v$Z}tsU}*9vQCGGy-O*A!fo;kAc#hl)9K6Wy?N>6l#8nSQj#4L+ao+ zTpT-63jD>cXoGeVqPm#O$|X(c`0tZp%4Kv630)6Y-jk}LO4*HItZ6*R$8|rW6#yY# zeJL}I_y-8E{rlf^x*}bGJd=qu@qP=ERxQZpCYcGY^a^j#b*Lj7@7y4U=rh9yEI({c3`=O$6Jx=k=4ygcEFc&(Cv2@>=7CD382B+ zclI5{t79<_x+!bIcbmW+mMFq*%SZC>IknO^88(;ZnV~Foq`BXR*^i(6E0|Y07SutR zT&j#|O(#AUWm#%_PS#B1L2F z8aRE>CA^PFmc$4!jT4&m0n)AJGG1FlV&=-u?T1XMqSo6}HaMr0#eg~>?wVaAC`-JO{2ueTcUPzO?#c|vd0 zvi-5_7m8%o1i;ufDYaiH`C2GDR(7tmQh(yPy+gX^=&QA6iua_s@q`9$sE6^uVH8oD zP|mXwHE@1RDDYM@B$-FYeFw>vp{W!jVK*XYzCMn_6QnBH6rKkSgm;iw&X6k)LE#_A z1^1YfauStPs;vBNJZ4#Enmt8C$s1j5R?fA*0wvPub7VhCPGBI$MZfuWlb;$?kvzC{ z=oBM|cOByq;ou3(MH28ujJIk6R)6fAD z9JC$kkN_LBX^7)swfl}cTo^SyzA(di5CM5N9^?S;#zO;|AKI4d03Fh?l|%m=)kBFP zwQWw(C5qhbm*-{LxBU(Wrvl|RGaG5qL8E4Ln;>j8eXu10zjT}AEtJRXh6|T}*yKO= zK9dQ?6s4Trb)U_d(L_OJNx;t1yp#v+LysXdccX%yqc~; z9;rV|!K%xy$i7E)ZFwij<+{fB8 z;#lOGlW?5%eznQ99L+qbnJWeLim}_z(g5IhQHC1C^LJE*&#(SB1M2gdPBv!Fis_O( z#_S%%wed{k(n8b)0-}d-vp=gvQzTylI5!6J@aIqQa?q%UGclf_9eaf%Vqq4MsD&gV zQoR+7KEcpI;L5M977_n@KP@+^5E@8!#NWGn4w)9B79z22DcG z1Py4--_35WN{asKoN!8YA=J&g3%RY#IDr5zvAc`2%6;7RLEH$j!TaJcaIp%7OR&Iy z*)nI$E5*N484^>Pzi@ul^7^eJ^7NBJ!-OS?9}A4_3e53R%M#(#NR?T~eKu8ez( zHx__VqW9!o&ItZDuXBibKIXIc13tTx=jxqube})kKfW)s#xIM-9)2VNlLp1|9oom7 zr~DhqIijOgb9LP8S3i9_<-&`kfVgePmOzIOChy8_GVjkfb@cL%d_CftQS5Tgz1JUW z6g_LMIg}W15Llg-aD`xVpB5WhzQa&5ciUOVQrqLyWuUpNz)s|bpxbRnWIF3=H;9D) zdT)UrCahhfHp`3S9|CXN#wPAf za(l1~7)Lt4KXGB<$arz#Qvf=P|NldbOdoaP_q@`yeVmmRcc?hY&+5 zmQbEDz}@&2h;VSbx-+<($#w?d@BZ?o<zXQcngheO8zA z(o@J@Dds;)`0a`faVs(pkk$q!3S4W={5sh;g6SQ+TI#YWUh@d==L5EvmWq{syg)f| zWNT7>ao2^0n>uwig1bg>GoM;ov>ccp5i`w~Jf*+E_~CiuxtS}ox97s1RQ^`t*RoU* zTJZBA?&6lI;pF}82jw?%tw}Q(m$B*t5Jv4-g^N8w6HqHQWr*>v?A_sy8x0kYPn1oq zA=Zb|v%y7I*(L0_mr;uB=w@4|t|5R15gjeN0^L8h&Z82&DhPGlg0onBJ|K$ik# z9uCKj>~l$9@nBRFj+e0NUOd+O-Z{Js(PcRVvm;0}844SQo-($*i}h~_%0&klwKzo!-qjlan01x zmMOS?a45QAO7w@o;6{(IkBCiKbyMW!eU%c>x66_vf#7P-s-@j)k!b$x_CXh7dw)C; z@d}{X1}s9IEm4&IC6{iDwn+K{(ROGL8-j z8MN5L>b-A9DfXqMR| zC7;E}j_Ik^M_*MG-IRVHLwcF9RA9!AHv8++XW>@4vGf1&2?$bVuAD4@pKM|L0HUn2 zD(3i}3geJyru3_QriP7~3CFRgv1jx+cWqFMT!uNDOFURU&q`QLX z>zV=0lE4GgSuf~er4>CJRNFV8Rt`)QT3X%vrcD0TJl5E`ngNDYXuPoz^qcrujK#3G z0+pqXK4>r&2^6#e99-y0C1X#_*6YL7>2+`iuzlb(ee3MSKQbOXk2x#em-#>@$>X`s zb!k|w(_6XluEiS&&0f3f@iVo|#$p-YpQU~tIh*Lg;Hu6ZP$t~-)Ha+sE#=#uwQq!s z|7V*{HI5R0L6_xxeNdEK^#;PRbi{nj(vHdE!iaM^e@Y9ah z8h-{(su~kv8`t^(Y0f-DFc8=qEM9J}^7F1a8cw9<)T3L=0Cg~LK-23btQF* z>zWqqbGKaxcsMs!W>cmSS!D7Awfs+{*jE65t5ru&oti&1%qO=C@nJL__X7Wgf1A~$ zm}>^>6}(f%{>q@w-Cow=xbXNKo|ZtBX6;?)yD5qenGOE;Y?x&Rk8fA3S=^gUn;sM5 z(5=@gTEr1LUlTUdMK2SbBt|XNFWzA^FYo-6?varks=p#VRRRI*; zXvXcpE55COSl~Z9s~V|aqGOl(lJvI>p{@P0ahR<|(JzvwjzVgY`E)6NpuA)_BpkER&PFa|Cd$ez6-em5_;65}>MTjVBiO#`2wocrtY zNJl?<>Ks#*n;+Y(3UAG}QQE0-8WnR=zpXY;NujP}MjETe7WtN=}K?=nK zm5qFr{#>7IACfWv-;#CAOH^+TI}HwYmeGDs@)kL_))nWzqiBz5z^jd-wupr^DM7e= z@}tNkW1oB;4&AA%27TSZ@S8ZNXFp!Nkz-}{#QZ4GQ|q#G-&UpH5%wPY@uGBo8ae8^ zPhWUCP^}Sz6ky`)eyzT~a>{y=h#-#4*yte&5B*mv zAh7lt(PaM2Ns#fO4#rycq-YE{>qrX0OfV~JO)7_6{intxxY_63SmT=42x`9bwlx5q5V z?^}*U_zcg~t|9Kt@ffgvv@&)N`JoD$i%DN}{byknJ}_WYe&|keI7Dc-gC;AVBL8C{ zy@Q_d<%YM`OOioXqlZIt-dOpzqxJKYpY!!w5x2j%9F$X#YG^7=Zp$ZJoGf=wGYWw+gto*2_>yM6B z(3Le0H1tat4$k&XY{8(=c!}jxW6G~*8X7yD>nUSzXR1Z%>Fy<9NX$V(F{nhlhdS)1;g4qR>o9o{0|#uHhg1GsM)FVK+c_H1w13SQ93fEje}fG@ lV*khe_=r7!Q%4Ht0xntlD!qn2F`hsKp{{Zbyg?s=2 literal 0 HcmV?d00001 diff --git a/windows/deployment/images/ent.png b/windows/deployment/images/ent.png new file mode 100644 index 0000000000000000000000000000000000000000..befa6abcc460d2cef2c421d9fa0da3d86bbe2d2c GIT binary patch literal 77540 zcmeFYcT|&G_brSCks?@tP(o4kh=4TdEffJ2Y0_&bQlu*c1PqZ9KoJm?-a%^URe}&H zg3^(MUPPsZra}k=621r2bKdj*?j7U1|K4#K!{LBDWv{*0UVE-NXP)TkXr7|uprfLq zI(75L^*dBl)HGC7N8u+=0Dp<(Yv%#}JK}vuQ;a-Mp@1_|STVY~jtUnNxP8eCEfLcKcp1Z71c(%=MB~ z+VWJcN|E8~Zt}h*D3QMs_K1q=>uiI21ilaEb1lq$Pu?1J9;vtDR(K`n0;r;*BJzl zRXG|Xh9LRG%8JS5(FuvgW5+s7dUz0=77)S=x1=j$OmdM#8nZoIu!kp<;KmR7dMkCu zyJBr>vkV!!|I?{@cJmec1i`JP`RVU5jXux-^+7?5Dd!yDV>GOpv^7um(b8C$a{6*v zoS}WqE$Na=(nt+ryrqkBD7M5qGrfx_vd->wBzYo4$Jp0dL(U;H{LaiuH(>f}XKgaa zDt@Gi8BEQ`zg;TDSUI9S*}d&XxHIuF=O&7E_L9 z)~T-}F@XSi#G;Evl{}5I?Bgx87(?WL)hZ)l2oCo7p3pY)H??mU|Q` z0{7X2urGfQ&Y^;!UVEBu?`WNDRCRcd(diRNlzsj5Jwnl$81n!V^ zH+E+z9eWhS(!!@m%sFV@#P$q=pV~^26jA=7^!AEaEU6n|LFd{CB_zxhlQP8vGoCgX z>(wq}WrxVojhDY<_EdA~j&3anmWxYdSVVk8&uk`FTI5~94|-LU_op>}axxzE^_kEi zVf|uL=HMT#yH>Xf&1@%#X=C3Jj>KdTW5#I0=F2DN?(Og7?hJWz_RzX3R6`;t=a=?B zD!u$k-09q3;;vpmjd_*&Od8BvHb5Gy{#sBQ_q@d_GO|w5o_Ip2{urZCzLD zV{Np#FR*a-cj>MR8$@o5Fp*Z;G?+zq&TD@B1po0VB7yl7&1!({<1^-T63ksaQ=V6z zKb!Ghm(GiWQw$f0ZeV-kZ`y6-kvofynkK#eWG2V=mEYb!RldS{L)Jdn`96Z^N$0PV zbVcO3kn6Gz@%&z>|0Of09v<2TKjh9(n!Ql`driJ^sUCK#gs+|mryyyk#(T~RHI7@s zSN2m@1h43pFj_rlp{Kz~xe93fBzGuGWGmOzke^EF6jYc@tBJ{jCF)=JGHK8zklZTY zVHM*7bmX@kx&6jHV@khs3mCXIRFTZ??M!;}uI{sBKQQkf^rrp2)h*f=TX!tZY?77E zKKQWDuYG^@VIA{RW;&W7y?cFiszb_$b#Z$fHLffZ&~xprN#-etlJ_Cxe%{vo=+3IpE$)Q%OgI`xx8 z-+rXdk5Wp-v+pwEs;P@;^}X~RHQDw+tkA@$ds}l+_Nn>)pvAjwEn)V8^D!wkd_;<){NI5%90cO68tui5Tkp=k z;eXr)h{D+`f$K9C%-FU6qhOQUix!QTEZcjZ%_c;|b1rkZUmJqV0#G?5dS$TsI|g zxJ0$`?<4T49dIs0ALqkB^JK1YxwAGh*`AvH{6rTuwJRh)kYpmWxW}`vkIsbN2`_3Y zf2A2Hc~>UMdA-RGsARboTbVn-Mue|ktXJ)qC^2$F^quvU7T%6>M_{?DgyUd@?^O0Qap2ckic#&<_ycY7I@J_Tw9 z%-RGwTX6V~8_wF8kFfAb^NoMqIyPy!e2$T#G1Tn|OEr1xFvhBA{TtP}*#T#@r-sZ1 z4`)BS_gt84_U?&rVx1r}Bl=9_#{hrb$G!9tpPq{o@4cTMGDmDoddi| z@HVt+wJ5Y(Fe7Q@Xh~%#1>N17k!`B{%A^^RB3bbARCHak)2bB3P_|XP!m#<2b%(bCepDdm8c3 zTU&F_YU!GwK*qDQnyJdW@+^GR2z%=>SJwg85zXG8R+oDW?;zmpx`Hvowg6C}w7G4) zB{~-|t{$_0@pWu*dY$|G7arou%k2KE6_#~6FG&{JQhWW7R7f75qZS#~l{Qg3sgSZZ zRJT6uUFX^FksJP1{daOYN&?9_A9jsHn3?=b>sB)QL7xv|vCcwq zV7nKCv6I@2PQIcjq&Ar%ZV%_|5!|Un&|H{`TvQ3fPa{+_<>7qW!I> z_q3)BG?rHUr9sv6+jVQ|VY3Iz$gLQKzsdzrjC(xq5Aij{kkBw__Wk zuX!sXaem94Gt4CIm?XEz?=w{@cM$m-;6z4_k~Bbn+N2A1%bZq!e-a6R{_}r-RM-6f zZaSQdIy8ntLa6|$)!v|^tGf`eF|U11QqpMl+qb(&X^%<%Kr#t-O-#(T$#*pc_UO@M z00D2bJUVJR)}1I~A!3ETD{TGNxyfrbgq@vT46?s>?clLrLN0+1vb9H)^&~00#b(fJ zfI8Gx=HXmdytAl`oSgX?2DH~{*4T^;?u`))1-D5c=xc26j8CKW$=hSTF(nQRz(`=f)?(aURKvKcN9e?OXuTX%AF zTv;Da#0QEE$dW0$>mViJ`(N5=tKG)LHwHC%#)u++6)#-1s7pGcLaTDtD?7`$66_aH3J6gV?5@PC10Mn7id|GDF~g z^j)RVZ3+!rGLK@Kk*EcXP8I`oBC#eF@~AN3e=Z;5GT&V>&r z^e+n9PSJe!OR-eEuRmzX)rj809tPs52;77(0so!9pWo*+>gCT9>S-YJ6 z*tzb+iT*4{q}S=sYv<^xHW+>!d!tduJ)70qyt|IUeA%#qxSFwTE%|}y=*XxU&MVA5 zrx_0x!I6#rc=|^A9ZMgqjkV}Q%AS8~i@JvGdm5fcHcFK3uai`Z?}Crbr+PMvK_C54 zSAWM${|UQ=GAuOq_QqqcY~WGlDFvB9<6xynqs{rvX!x%0Mk~F@ ztC@n&+VJ<96DIxy^mO^4JKibAWkS|_{+a($Ug8S>jiM1)-0Qe|q@6fTZZTb@o!4al z-W16#MKSCGOF}Uebe@$F2_sB;_a}Q|$io?ljOi~k;akay7}c64(a)R9n)uNZCr-G~ z(ZJmBAW}UF)m@jYv5s`!`To5^_QAJEe==dDx4K`+HRItI+KrusOq1jO0*x^$nV@1P z>Q656@#RfTO?K@L&xQ(gQ;E}o{ln^#Kw>%VhRFxvkTGqVojG#)Q_fuRbG0MZg7pr@ z$}6ODJ`|+!tC9ci?(V7*c7z+TcYn89!=Cc9Tcj?-j!^7gxc=Vy*kd=lBQ_c5*BWo- zHV$~{&}d+Zd!c~rr|E!*2y}pmzl^2ue$>7;c$49^lM2po>7N1lR`k|SJ~3m z3soR&7r|}}%)(dN2WsrdoScepymsiPPi8YqYQ!#pltS4MADC7${omp6L`#~pa1VY|4sD>>Y?*_7(>vrbFrT9CiG`1Q;k_=@E z^vi<~L%tH`!|}R{8w1EHGq`g1W(qK!yR%t*ZismO-1CH;#ayMylev;dQsPXhlALa^ zwMrJ#pQ2&eoQoz6EekVXF_ap6vhFGAbkp!$CJ<-qVQq@EWn(LjGJ%5VdpmEpYclj zPB+t>f$Mx9mvN2&LG>Hl^e8e9!&mRGsksEHv@MHUI(-*zjA2!!2cZR(>BGV@YQWB5K2mS(g7lz?pSzNr~8 zsQ?hw)4z`w-}AFsdIKh_8KIQru+RexrR{bYf;<$$#?aPsAs2|k)Ex^%10*01k|ju{ z(ASSIk@?Z~P#8`V*n$WFH`Yo~^<|S(#**Fh#TewG==32$ z3+aAtUe?DU;7_s!?&g)K%ecmn)=_8i=aj076$qVseFLc0y& zOhl`3)8+84c@18?x9X55f&FX_C2#5Dcu?u$Lmx{yCF-DYostzL^);4cNwi*PvAu6Q zsk-nI*bu6>TP(6TE9`GTrsB=~SM|aFsIfc1K)+Y&Ak0^2(|BAybH5)pYfWDhC^KQR zSp&z;N^l51dV?h008&pWx2V8{C{)$T9G%g{Ar?=(=rF5$v(!NzsAsjY>zMuNm;e;( z4O$>Pl0Z}!bIvNBZI9+Le+iwMjJuj`mi&qI4Kt?rLGfrxx4iJGNhddbMc7us>28sT z7?pL}Wed29gZGdFK{i`IqcS3I@rYE=Nh^A~@0-@~+L;D)Pp6cs2dF)3PmB3NRY#^N zJ1=mVuCz2(fvyNT?gaxTD!mK8%1R?pR!-3%Tbo6Bu?x8wO5hlQi-+*c&CWhJtDK%X zz0ziYiDp^WMX!YyNXT;l71Xi6-3eLwAVuJdIEa-W-Pm}5TO4*n)rizSARaT@ry(3y zP58e?NZ|!J?&k+xs!7xwWuGj+lW5iqc@L zKkDb3xOg#U(_*)>wg;>YGh}E9e}yr#ySvpXxGm!!SYc;jbgML zR@M~QU>eVY0Kl~5dEcj5P{P|F4VQp^Zm73}-$jC~lQu5ef)a|rlplE74)y$VsHs{J zt|0?mMTd+>KW|QGltE<;bv0waS9ma6+073Z2eP03EYxPk7L}9<(NSu6BA~GWR53C7 zop|Dmd8-P%toYPq^IpV~Gls5VBgBlV@IR&$8CrVs*EHG)G5e6Rvo=FpfP0Xfm0lGe z3RPNF9?xsEm|A~cj6^z!Mrjng)LfzxdiM8@4GSIng{J~Kj;hS$%-T$oPq-%E0Z+T? zwPdMMH)D@Vh=hgGYv!`S%3DSam8c4%f8C3gj1r|kd~uEwP|telX~_Da>TA-b-LLEr zSl(G)Wp4mbc==?ui(vMuz63p`5``SXJln-#p;n<^r7!~k`t{B-Nz!>TB48nLm*-xm zvl`BW(;#T3oVD~Knh%TDSg2SJqrJ#5m7<;mKzHC6AH2qTQf~Q&=!?-;UrKgQb#PzL zQMP^fFiE5qP#g6?|Kl}9z-y!#PAs!9h7&mrMfuzG0UiOkluFO@B+UVXVgPJj&p|KI zW!sAs;H(7u7(7KGLxllMc^tUvae#`u!EOEH?V_@L) zEH7{w6_)xJ!or&JE~c_DgwNWzVLv}=YXL@i?y}Bl#-qSB%2vFG_2PCk0AC4=G_DOZ zS&+OWuhRz)z*GNPNf%&3t(;{{H*GI+NG7o`y4?El<7+1^%@N?5Ea6}4m4C2a$gogg z--P|TdyVDSq#i`;zcJt2$ie718kBTI^g^{ zc)@26dve-eD9+|3ty; z(qb zt^|b&15ddjbMoN+=;Qx9oz(LAQLBoy3s7-c7##m&!5V4*xk%VpW-$cV2M0I5;rugs zswxY15dfET1He)mzn%;WK1?n#Nme?!bw`;(o8R%U9{aPb{EKfbX0tdYe-9<<$Ukp6 z`)lZes{hR0ulX8y`X8@UZEZoBln+aS!E9{22f6ha{T*myNA5;8zm&-Ry`St{fQ>wj z^7_6qR(<#kul`8t$Nu4A*%s9&t4}k2d0`0hM=z3=3Nm}vrW$)^+ah`apq;x6kOiN_ z7>>h%JQrX~)0KG$^y`Ol7s^*siS|Di^>JmjWo>NG^i5vu#(6NJX;ia_F;}>u{`p7#eCLbC3rv2106(~>$&-$%RiUDVsM86_2 z?Vzi6Lm=@zJv~Y5&AWXH8$H+Nqot=SGMRuRQ~m=!japmWPSVidk{NxA4-sZKk&fnd z_4KS~`fCuGvd>|cf!9JS$2NsW_PVm2B%Ngp(bd(B^*?A3F-75|;8xz+ya8gH-?V=x zu$Y~cX*aN90QM2EbW$rn^}pvSSscerBwV#{)7#n{(oMab`RLQzt#Q|_G_OSk(?(x+ zlEp^umNh1*>6FPjOR*E&n7`df5!K8C^wAqYyEUFHVQW@H87{Txr5AZ?GXlpK74(3h zk8B|mcFyG0iTcEm5hW}WIDp(loUWc2T<(iiB7Ml9@m~b*c0(z5ekie@K%xD%&*>_N zIVoNhX>IUc=mAKKd)>mdrNB$X;JDF#&!#d2d~>Wk09*PbtZ$t-gP5VfBeUlMrr?ZJ z5@!!G>onxC>s_+V^L73B(~PW!2nIYmBc5pmXcJe|#C%uB9oB;jR+qam6tDK_ToJqR zvbrJ>tw7>h?YdD#9&u;)lX`fd74&)xSk{iX&sZs4G2_AU4rO^TA}(0fZ`QGP4M zKB5dPZUlhh_1W-3MaiT3JPMTrP)--xbSML6ixN>HU0@A_Un!%7f!a}t; zsX++xGE^H1g`zKV!XXb=Dm%NfA0K6>zJ|Ztd&9yab?mLbH)%o$3MUw4e^$%R8OHfx zC+a;5w6tcQ@UY#pFfTVUZFrEkDovz=&%dRRmg^WLqhKX*Ad5@GROMgnd@6EHQ@#VDk-MN(<9_gz@_AUdPtML zg)0E15QMgSPsjNh{n&^c?{zvQ{@{d-MfS8aLkxJCHDl4jm*&AJyky$b5_A-9 zL)A!r@z~X^@hRiZZzPQsLS7+>d6w61xv0NEh%mOUCG)06pZAcYJ8|6B`AaV4$7}>o zO8s;I%0cxAwHVNk;}Tg&-*Bk|b>>&VSg{$DmmXOscYG64TCE{~-<|5@LAbRoD{MC8 z4X# zNpO}|Lh$c=Tt34nu+q3s*qJ|=w9bz(N~wXof0o+?Oc z)-}2$X4!)}biA(ldi(gSM=^N`m>rJkKwLR+L|W*Aj(1=|a!?S%t=5*jh>$2IrR{g& zf)r}i$dD+Y#q0>D4dOoy@PrWKQgb6Q$vZP`VZ*pU>}6{p5#`DHGdp3VGDxj~0NWkR z&%rGt>!vcIh(%pbkTlG2B8HTgU*N+08oP|X@n9&F$N$?Ic|}u5xmk5b^X2g7moDZH zj0<0HXiVVhYP8+^rzZ3kUL5617o@X)Pl2zSI=WF}2)go55 zYGVNQYf-^>dsmMWvb$1UCxq_L=_(=VO)ZhdCp9CRU0oHm<8ZI6$t$`jT#YfVdLpB% z-2P{M@(4w2lgl*Q(z+o`$^eO82tbBc$48-PcAaH^L|3y9$=8AlahIieCicsmt7 za#e@|`Nv4&Ijhfa97w8#B24JWA0sdqE9w|hE_-0p8KdNNpv)LK6`#X!R~uRsPx(}` zHRm&3#)vG2s=60GKs}<1GzyA0=*HHOsD}E-G0PStlg`)8*(0x;h44|e6Lr`+!ufoW zi|B!Y{Y%5XHBfgoP@2aK{&G+gwa$XcbnX)k&*k$ zM+f7Lpmwmh`SP!IMc$^FM?9>g(=FjDe2=Dnnpzd>>=BC_X#_3d429sAP1xA zg*WR}_d8VC2v@W_4I7c!%502y&$Oc#YMazl!crNFVJsbwfUbr`C1DHYjx><3<(g{K zh2JRb$CCx3)W~h_X)=~ZD50o zU1`^UxD;|D-2{C(L*C=+NF{%d&$2TQ`ts|o*;WzUlU6BrsBO+feS+XNZf4u1Ff;6Y z0$%xi0ngiesc7k00Ct$InV7BesIBX>qoO0vnVSUPpC<2Y%H{>F;BPy_aS^C$A;Uxt zE7ZC{?HviQ;Vz!TRjF_lg)Edifea-vjF4Q`M@cSxtt!sOhYf-7BUc}?jhE6)F7v+# zQuy$jrFL;J{LSd$*~QG9vKaLkapZX(Wgr5mr(KI72-+%QE(UqIC9Pug5J` z*F@CX-C%2uMH?SR;5u6ALpngt1k(#+JtgRbd|S%E7-Yy&9y%0f^orP7RIA|W}Y*Fc@H`HKMuQWc5 z$DtO&q~t&>#Y=nLs^#~_ONLp-I{{``W+6v=AzNdsNa@jLplKf)a5nZcQn%Ws(s4zo zN}7b1Y{h1O)q9id*Q1mw<^EKs+lYPBEEhfK6c;-@VsjEs4BVMZ?9Sz8=_rQCZ<60P zl|{U8ZqIF1K%@&j4G*0O+I9Ee4@im(QGmGhs?F(*f~NfjG|4IxhTA3Yq);pWkuD^q zAqL@#V63d=-wbjEHI4^a^6pAL<#D)5nq2NtPS{DrRFb&~R|oagJG0LyN!!ai9a~E% zcT)K>lw2kfHH&VptdhtIj1x3I`^|XGbzZ`AVK9rw>5zkgVdBTQUA??KBJp5qvP8x zNctmW8*TE<;LLGd@+A?lp@pke(`EWn6z|Q62hNC;aB#R0BS90%jSnR4W)V@bNPrmE zkM+`9G~MJzT9Y_gPrL-u1dK%{2u7*#ag#sy7MM2}GS=qRUEM6l-&&~D9e$AB%>iGi z*M24nuvF=O{kM8==y_eXTg^mvEzR(ibJzyr8=r(oQTvljsta11iwH0Ufy}^O?S@_s zv&)&A!WuS0hbgokv{w47dVfNtvW<(k;`@;!YE5|Mwn4JpP^*em>n^{7t6=f+Hxt2!Vlns9{Tl1wPjlcBK981AyKBI zU!JWFNlyYo>pEa46KboHNI^Rffl3eyg)vcKp#qrZSKs1wm+^`eaVs!h zbqG3-rHSRa>oPUEW#4VYebo!w+hk@MEPfVQE27 zwf0A_42PnAqr-yF!&nS)_DO*hYi0I()TCSY)6>*m)rR$|Er+Wl*P-;p7`njY^kZ1i2D0_7QyfbIuaScFSCU}DMbk!(JV>{-pa?ORhq68^Xwe~N zk!Y8pCR!GTdlMI2d1{532ITJQqkgp*uSflAZe220hp zx?5XcKOu4keR>0mG7;s64f;v9sua=RjE6!M_I&+ZtT3fD?$jD)4ui-N9tEUIQuT)i zt9*iBtYIMh$Od$%pM$n2V8s7i@!CT-{PEzI)s;Zf-n$O^Y4nS)_da5#&N2j_H^h!R*@sI;IV!hY#bG?sFi&wMu}3 z3NeQCG#jcHvSA<&MmmD`6rZUbq{-;A4_ zRt>t_Xd0;`=nfGzJoDZO&{;-0YB+99b`hf^Ga7=A4Q?)3oEcrtuFTQ_(bP_Q>)A#M zYfM%JM1$?RIEh(fsCtowJO> z?ya9y$;u##i%D&A2rc1CHsu8fz%vQ?gzzC3c#Q`e<2|y=P_X1vEx73Q@+(yOm|~bb zz-Tesrgy}cE!+``G#Gt-#>2lbT0+s>{afzWp&L@}7I#;3hv&|lcQUp6Sev98PYw?| zB4Tjr+;kg0OdW5PE^YefE_D^BDj0fDw=+(;>KR1ZJCA$S(u7GokSQc?FQCRpGV@FO zXTRT^QC*1O7JkW6wG7*zPN0guen2W*pK(fQ0TeAd!b9^PXH5_ctU$GPB4WN8ix5LM2S$e&Cmx)c*Ed&F%2%0k~MOT%?BT%9jvobtA|6WiozuAkl8dOqF2t29LDNY+4}fJkW!Hji1xIsZ$uxwi_QORf zX1bDg2k}95xuf+w9CB*iZ*gFMz>vMV^)e)@$U)vu5Nt@^8A922mU!QE&`&2V20m>y zOYbyWY$|q2FHj;W<P* z44d%TB0#ygQb%2*vxMJGVozJWU24_JrEzEqRVk7) zP;^AvWs_Rj6V&Dmy%J5aCc)0EtXnLE3!^Oy=TQV^QiJ#H)jSxX9FsBQIavi1qas30(268N zULd0DoV*Cowe+Shn@tE+S#}m=L5wd)np(p19g4hhCJX5XnJ*7eo{G>Ly+GHlY>k2< zh%6Qgh>qD6D!DOOO)zOU3^*r@i^RhFJK_?59UVrY4_W0yWfJj@3W;f$!E>|x4 zUN@F06zyPAuO9F_PO#s<@_sy)dpk>MeIS5x@^-fO71s8mo|F)j*Dw^ikem^-Oks3A z{+cIgDQ!pzt2AEsyNKzqwHIkigcxKVV~jV@B^xzZ1>%6hh?_YOdo;I~wz-P^aG14? z!hwD!RE=dzj@mMQSDo!RUQr-(d=gg=oXJ5AI0PBK>_mN+B4@@-OH->0&p^8`LE*;5 zI&E?A^8w|}L%W?Q2fSKYe%Zo+sBawjhxC5u2yi6(4D^?zdscH z4#0tpA}}M%A9mLo%S%F3h!F2bCuuD7$YQ{`!%vvgY>99Fy!=H41UA=2C=ighpr$nn zk7lM$(&WiYkq19fKWjYsseimchaJ5ro^DFZGlqln_3u&Aa z_W6{^ReyW=J;^g}4hUuyC33G}pBu{cvMWm@pYot-BpQ#(C#8=|O8wL+FR~`1jd!qr z&HCqf_d@flu8bP)?ESOJ>FaahCrLPoB`i5v*_1VB)r;L->0n0629o|SaRM{O#2GJk!bGJ z)@#&v{pW^>4yzWsIJp3-XCBqx%3mV8&IX!S`Yn=QBX+O$^>&mWAP#(^giUe38oAzfSKmx4m7rE#|D@~w#?n+1roa!x{4nF zc_U{wQR2{Wl*Z~6+8zgTwF=u==C!M<)Eg-3mpGuo4w$e58OHgq|7gg6k;WJ7+KSJd zM4yfUsPu=@&yXQHzphmOx0W~h9It8#!p!pDzTVz=?~ri^L^Wl>LtIF!R_}Pm@jUo? zd$=K}+n-56<@#GrfCv_ubS3X}W5eC~iYyzXRiJz)13eZB^0h*Ae$QvcQ3krmn50sjg> zuGy>~AJ{VLuh}3H{)Yhsto1X_Cf9!bv&=f=C6)iMt zBlS;qFVO&oU9Wq&?-t7uWYp5~vR2~Vp|P=h+<_~V52*5NTn@a*FaOJnEFgW?o8J(N zro(&8G^Yz+rH0YzaE&Jnr!vW{Q+E0h-9Rw2kykwt*947AlCFjH zX_CLTF+pmEETWD(^*#=10gxWPo38gKUR&sZ2qFR|9N>GTwSbgJ_4w95ujd0Bj{5DB zi4zzHMgYp$juy;V@$+w%2YJ5M8~EEfK%GufT{x6TY&L;GCB;H0Z@wHo|LtGCVJep2 zdVoX0xEyhH!U^iFl1yqpz&{0FxPKXj8~-*86AvW7pt;;t)Y|~7b!eSia)Zy(9g+)S zwGfKu4&|V}LO=_@nB4rV$?e~+!!+E##*GjQ2n<|(1(mLqzP=D$hjPD{I-Y^>R7=+_ zHkjJb>-@2|(LdoXSF>J_5zuA*4i9ZY5b(II8O+|C$o!8^o_ffE{%;=sey#mTx4Ytf370z?LfygmNfW z{|P0e`K>-8Us1?RfGHfQbB{!#tWS;R|V%kekwZjd#O=m}Zg;eD;| z_M0}X;6J2I2N!5;asdCehoBUlF4NZm#VzK&BFI%}^JKy$jRS)H07;nfQMT5mQe{JQ zfIdGe>*vaJlRUZfeya*s?wTxnPCu36z+Y0N<5a)(^ur+nRzr%lAt#|=Wba=4vtPb6 zRr~BL1L)!-TADaxq-?7F!Dio_||M;FS~ z$oj!qqzu3mNXFZruXWP|XfS3u)+WvD0?65cY^O0izeSL?(|eA@{R z9rqQYDluN5q9VTd+g^0w!8M}{s4>mOZ1MdX(2@TfkW3*Z>q;Y~Pzmvyohm)h;wfqB zLeD?>vIumvUd{#(sRsnFhF+fn)CGYII?H8WJPV`Tf%UwAeOW2Q!zTxzNc1Z5y&cIU zLY*~iy#+9U*-g)Wo&w7j67TVd9eA(xS*d>G`Lp3((RkH16>WOQZ-@0eiW4}Bes50N zV|?1(My7e6yO8%he1b_@wO)EE`rMVuwHu&&9H@jq z6Q<3^R>bpYdp4rZ3g<|Xuq7nE1 z-gt)b>4o!Yt!;osQi<%&IyJIx4R8xuWc?V`)l!;)H}3alQo2g}Lr<5YL=AKQIzq*o z`p@D3UhzL}O;%~Z^K*1ugv3=d@_G7F&Jzx*wq_48 zYMRq8Um+o-wF#?}rGWo=LAN}Ht9px5>9gA09nrw@R+aRjb-;CyHlVvo{1PRSP@e~P z4a=VafdjUm@$ep_68h_qR{}Ll{^O|hlTd`qfQ@bde!udbxw31kdteI z`#PdI7sz=49V`SkWZR2H?6oPqRh!}A!U1bRAr4!3j!}(e?;b@*#hU8<#r*7E11XB< zsDRCIVXao8@YqbP74;qAJ%i_~hmCI7a_o7ula0_x`ax$|I0+bztv_FN~$2 z6V95k+_iK1SptT}>3l9xfh>&0j4ZG5k9<0_NPEB}xQ*?3>0t!lV1LL0(p7CT(Z_}A zap28EyusQonX}fI?A^Q=I149EnHaZZLF|Cz1K`={IjI2rDurI`zjHop9dLGbk!IML z7jM9iyz;o4ox!>s%WvrQS>v35(7+AVrPzyxGG8>#hUcCH{KSc-GW^UWZW%9La_RLr zFFk(IA@#7pTWg2*N!n6QdKx4t{iwKNQd<)d_#Q;rNeW_jb!wB?y5$>3(#AwS6=D6u&@j=j2wHi3V3hhEK`X8xz3e zD_i#Xdr?7#H~?ZwPWc)IVXSIBn{>O4V#{<0$G?6z1=8{5VLA#$x?TrtOLYK7roMDw zjBh&kw7qyjSrf~{~99D z0;$TF4&$Xo?)S018Q`1D6ZkCta{TLC-PPij-lE${^?}`5v zdCk1n_l}A&F8c8ob4|d&u8hIUn2%03oh~tJm>{UioYYGHuhG{cLzg03@*Cg%1r7@Y z+*_r9H*(VIzow&45UgOh_p`~TCG%}3dtiCG&SL4yQO*+M<_cX+;XbPZ=8o-&q*IP> zv;LYiiL<{+WKXzqO^DECDlTp$A=H^RU{}{u4O^tXtiGim*v5z7MHoAGF8$tRQTHzP_WTlI@K$&|1XS};o&Rm%18gjGhyW=5<@Sp0t`ncl) zP*V@rk1C7hJXpxNbm*xTXy(0eg4Qw#^yA)1z5Bss4)GvT9{pAq{FU&E-(}EhoF4Bf z!97ux2`=G%>+$uqZ)BF;m}Zd>kdNVu@au8z#^LHsES=)SZOc)K`ZBlVwt@V2N>Af( z+yYv57r}=9^Vmds1A#7f`TV=fagRIB%I1$r#cm=O#Szet6ejhpms+nCjd)l(~6TTz>(rYHHU+FB}RI>&pPAS<9ehe1k0VA_2<7>^?5E#-xZantB(C&^fS2gPGh zB-}J&KNqvvwv%o_6|MPSc{I**~^P!*$+s^hXCvwy2${|0}nKxfv7qtv(3)L_%*nLGOZSAAI_LnIYb;Mdg&OJ=^if zo>kJ_6HMNrm9pn=D*IBM<@WYXMy=+u`LBxBQ>?gp%rLk3&uxYF1jVs4c1+|~aWB-h z?R_ZQI4cX2D&TP}PsP#Lb#LsF-QW&HRM@jB2Og)ip1O0kkPmnf*>BuxAJT$M$Vpvu zx-)^qgG9Ob??hPyOvB>$Zs_}~q=!rT`cKMctN6=jOur8_7L5b(_TCB9Gf;7)Vx`af z^t@G0`YwOGbmvbor^JSFCAv7y>AMl3-gq0G?}j%`G08^^PWwLTft{NVlL^}Y_)z!E ztqJY=bK#o8hF#e5i1A%ZH-AU2DT`aX3y1Eg6~mslCVi^=rj8#B`4W%lt_>`l6=(_X$qJ zDtZZ%LGeQxgI}LjJ)E^^(2m;d3@fo0xH{wRyDU>ojab@R^>tCKr{Z|^U&Vz$OS51- zx)9F7{e$o{BGfEc_0qwgnjx3LKCiPA13fE$K0OM2iEdO=>}MS`pj3~|;L>rriBjf) z>oE{Pa8Dtsgz}lc$uFA^^J(j9Vs^OHM>A;@Q+t9Fx0BwwKe>3*+}bLvll^jiUt5q~ z9<)7@M@>V~c#1Mbe5JdlV?%YQQENxGm(}SX#O_iX z<;}%Uh)_SOgtN*_tCGv*Z2h$y1WpUgy%NJP3e;Pb&LqZ)Y&^6&oxt%;!0^MhU^s>4@<7=f7=g#JkR&<bVqz;R zg3E8v+FvDu{l&%Wp&^`Y`Sq3=pQILe82e6fIL4M&S>{HBe658UG?e)C*j8k(?#z7< z_Qt`lZ?Rwc|JZxauqKl?jMvpg6c8*ZAWg-BpcLsKARtZYy(1!>08*s{RHQ5jh)VCh z_Z~V(5$S{$N$CLnJY5<9J>U!fJyr4M{d!j z>i=sKHXu|!rtAN1X?i!N?bQQL?)`R*jUgG=noL7Wi%5M+K#>2HyV0{lm5Jx)q!&f? z-R6%fBYQR%1N@^lD0j?il5}+?xGvo+fW;afjJ7B9fB4o%kapYmdU(^4&&H}Jo7JobqyuPq**4hPirKvb`=ZFcj7U|CyWO-ZG21P5iBlSfAo)*)^IYdD zsjcMv?Mp}YPlxzFE2BRPHd4uam|yv4@s&%5R{e*|n?OU<3OYczpTRbhl#Nk)cJ3StJmfBKASWk`Aihe$JIj_&o+cio&z3TNYDU&#vfiV_ z6Bv{*yeoRM-W%dmLgp*AHI7IJlV@`Qn|Kh8H^$qd+!_x+$y{C{1`_gY-oEfQ;O~dj zb#`@)T|VxhgC{SmT=-pnKVq@y2zs+(Ph8E?LwICnqknx4zq?0yvz6_+;4d>5(i$9 zKIIpehZZAN`lhBSL}Og8Gqad`?>;ri)cgu7n0+>Xih$3Ekg$~$!p_Y7v!VFc%o`$8 zj)uj4C3SvsjRl5P*(~6ak8@dlfc~@HhLEQl0McBwcDGB-(V*Q_-{Ldjb7Yl0>*Qp- zu1qO@`*oNtN~z@!JyD#P6(M55o%6C5mzWYm5so)sfxui2jHkp6Zo>i|64&+odSD|? zO{WeW+j-0sx^JblR-u@dwlD85<7enbg|9yaK7Fc$FR2~5@%VqWBmbJtUBKr>e56LQ zQNUm@`|sMf3pEIJp%zsc*-o|;$#B=ZVO(0ZTMO@0;}3QY_Dwx)%iBuzf-@wtP|$d; z92`GHS1L({t}~uxEt_CV${Xt3wz|L->+<2{OL`oIn)}*>nVVT5nlG@QjjT-6GEa0I zE=`w+n%)DyGJV5??Xuhc$tdHIx|#PMKw^G2JRPh4IqhaN27{?Ct{6Lqv#qf0(t8gC zMG13SujcPxLKpX+ef=y&5Lt1Wa@y(Fl5~e&xs@XaMf3IDC<({y=AoAJZzvn%2L1ps zQjXC^Q%SBu=basR_4$h@acBJU8?;hfEVwnepq8u8W(e9eb9L$4Iz+tY_nF&d@NE38 zXA6%o&4^@xL^A#0-|ae`&i=b`%n~#Ww4@2@td28sB1X;UnqkM zT8AP+bv3>`I*Y5V9NzIxGvmWAjSe1C$7y}GaZ18f8hxcN;1Z1HZFbTFvfmA>?aSyq zG+wl2D<|}lnjARLgS=pp%#n-`vZcf-59=V zDkQ2ZS#ZGqS7&(IJTkvMKN_{04pS4a zAM8(JyG$`o@=!9`iqLi!NStS{O_g3Y(%X=xbKcLrKN{obcL!p+!@cD%8$glInDnW* z*sUx#FVuHXy+n}H>$U6&LX_%SZ6#}f?!H9jsjxPRjj3#BG!Z|Z)}jRLjOX*_4UR4~ zls;%J>AB=eMNuPw(SppYC9O{27z*qpgI?BwR!dR3az#%TkKJg#c6Aezs40Bk!Bo_w zsvsPRj4<&as#;)WZk<^lf!t`=Nqeb}lWK;J>VV{fdo2{*pe6nUcPwbT0)SUUhy~I3 z?FiWtPFnX8%F%?Q+C)`8`Jt_X3tCHuy|kkH_LCZi?!dE@UoNWe%=GGWQs6h`fN`7d zINH?rF^ zcDJX6lo~VsDs)n?TIUS12v$i4`2g$6(;zLJwhaX_?sPWt$1CYZt?y;%R?QT$-1{lX z-6D&FXxU%)OGEF|ZE`(v%59)H8WOEbH;?v*b<@bBYt_V<0%!x7Vc$JU>@uU|_St*C zj_1kIBWx19y8oawc!jnAtdPYaQwh;#etaJpqv-NpYG;`*5x+u!!Y}wTa?qrdlhk1GR%4S{R5nAP!BC*KqgY)vBF}n^y-TA-Ho=MG*O*P z0Hu;oBl&7*pTFwPg`Qll_RmUY8FCb&ZODM?EEkPWINuq%jX!QA=UVecU3M=tSZbpr z8bt^e;OGnHb_(8H>ALoKYEYCS%Dn6HsN^*N))lwJ^GY3R`mU_^YDz%CFdg`OAFF+a zC1`N_{M)*(+#dj3!{qVe@cs<+zB$Lr7#`N~JmGqZY~kxUV3wdf0OrT8DpehCx;)dU zYhybXG>~|E_2;?jRd^=tse<*rJ81FZCg|g-Pcm+q>a+T8S?0RTw8UGE7C)6gE`BC> z+fB+5`-#bhz_my0Yscxo+oAe5cES>FvmzPIE85Ky68OKiu|3tB=~V zZ0}bhk1agDzqo(l;x{b_bDB*uMd;phSzE92>;Tv$V6Rs*4s4C%7Z zLkk6Gst~?RWp@Gz@KsOZk_jNa<~cIg?=QbZKk(bZ?y|T2`90J@;s21KYx6yE1>O&m0{GCQ ziU+ti4S9iEvWptAOL9IoJ$cz}or9HgwyNiDpQT0{!PzSc&jjXs1O#0vF{!+DA+gSz z3f)Knt&|L^X7s-I0zK+jab*syN%j(5vGVjEzSEwv029F~F&l|?;fY9hGrHQ~oO^5Q zWWlTcIopvCB4NFwCu_i(Ox-i%J}zEzMkrK|p&hz}W5mdJ&CBgsR(V9?wG%qCSq5sF z+`!K=??(ir6L|u|O;=YWVn!uWMzcq=_qosi`k1wHyGBAtL2<)raNPP+uL(6ZR{(4_Ucwcrw`W91icAb{8Ya;t(2FHkESqt8LLukf1*!s%JxO6fnk_i%6b?xoRzhR zh(0P)LjzD;RnyD``1)o^V&T^g(;Jjgl2jNU*Zw>suHYf)uB$0;k|}kRzSJm?A$CMA z`_Gn~aXrUPk&;-J&J|FSuwq47#{t zo!PcGV;%Jt)fg%p03&UGZSd)<<$F4HSV@XmuhpUuK@9?Cx~_sLxW1|0YJi0xa@kd4 zW!eQ(;wE4)ut8(?X1QM`Nps&b8(QEzKQLX|YGPPO{a14yn=E>c#x%|UXp==F$tZ2%l60Xfe(&Az~ z?J!l{cNe7dwpl#AF17ms?(Y<(R+SZ%F~GwFtBL87M4gZ}G7lPw8NUJ6#$4aR!Inm@ zt)4Gxv8j=&>*63y*^m^!Le5NW{M-?E9~+8$N_9-dO+bJc-#bS>tHh zAAy`d&3Vc8+k3ut)*`PC(H zHTey&8?hUS)jBKUA}2&nbH;=}?3zO;fC5d}bwy3KdEBbA2I*^9#wuw)?oO*=%Shpi z+qraM!6rd;1D-PN4r0`T%hNvweo&zSNd1}3QKZ558L4jD479j~ppkLCg|Hlx@ukfc z)rz)d^Nu-8FTdddo|?bX%ZG&=X$#~M1(Nx1M^ZSq3=rXzvuv^wCb_hd4v0nR0(m% z$f+l$q$(dw=+pdId49oU{Ovybr&L9%b^c>c`U?~A*EhK_cL~Tw|G)k0{|cbt#@r<^ zRR7P8RZ%xE85zC1j8_?c{TB!2|Aq(rZ+{~oF#TygBWZ?*Ej5yp`O-g}T0eYWA!xHNz`nff6~%%hj2u)7S1TbX#Fu1%SOm%{UBALtOj@XK59PXIzI$;URO z0q_zd4O{(UmIKM++dG!?D?=GeK*ty0|MSqssMe@SAr5k{wS%dtNK0AV1+-SAa<7YZyj#TZ=)L{m?}IBwtKQ*<0~ zHe{9PAVG?Joi`UqZzZc&Y=CEC+e(>cjNgpd0L+MlWZMsIQq74Pi&PP^7Na6x0kd(+ zE!hiwQ>FKJVYb2eEdzT?677dP3^VAQ z3IcCpjijA%K%}W3u?pitjnSRL1DhIVp9#@#SJG%nc%zmwO3=O#gwKi&O`kgB;j)m5 zmU3GPa$4?Bs&JdidrUd#`oNI-M7BF3>qu;r}ITGi_jgbk zJ2&;TpcF+Vk$%O~(p@<)>X=olFoc%)AGSEMBZCiqPCe2oubF%lbS?z^F7mSd$9EJ4 z>V-e!otNMLE8aQef{2zOXr^X;ubc&TuDqo zKVQ`!-pxI=-a8J23J~U0eyCF)(ttmD#9H9*N*dTGk-7iG6w?1~zWUZKg(Fv%!pY-) z5(#g{_OM+Dx2dNXF|wvh|I-TQ72E@?V7+|_LYO=1tM2O{e3Ig3de5VzRV{1~`>E)N z>drYWv6b4&e#wJfRc~;XcQs2<9a_{Ujms~mUqBm9>7fIPMiD# zB1pM2l5>aWN5Qne&yNW_Oj?qI{#@{4TfP7Y zT2q>oxP`OJD6jTWCX-@qwuiAcgbFFv)=1o*sy?)Wou@`K4Ph-X+%%(4?Zt18H~y}T zOb0b(dkN`fJnWbJ<$VkAx?4mKR{63HQlkWrKuPXEGhud7F)_@F)Qq1R8-nT3vxt9_ zeXT(9$y|`N#KkiD*^R+SK;}yu3gMzEIE-zPH3kcLQ1U$52M zQ}Rr(fu#EHUuF1N$(|U@j*aP@iO!=zy|@^|WnA8DSMPPPobmv!OC(&qFcaQQLEa43 z%Mi876LU}VUY9g($Iq0=EUJH9mJ>vq_*48gGm_+{5(W)nX<`-t)4{7@!A>-vpW#MzF?S-*gE;35368v+>|MNP z67b}IMqkK+Ng4zciKwz0$=dx8zB*m!veYMpR?dt8x~4s$zGrz*BpqtQ9HqNB zCXywn4h;p{OwaGl~yEI)IWdM5nz7$)hQ2th~#nl`Ca}t(EMU~|Nnp0 zVXENIu_{fKA5gs{nAycW%R|@Yn4QCaB_(Ud7jf) zV0#Rbeo4}me9xp?0MR%MQcq8+jRDKOQqu2R2c7$j*ANxxDy(z+?S^_D7Rw;b<_Qe> zeWW_ubfiweG@M1;R)UBfA%mDV-I4?Nj6gb*XRZ5&oUi;leW?qObxq$%k{(C|WbV~Z zSJ}lF*9-x|WcZ4sv;fva&aAGV&*L>Io3Kj~hnHm=ZyFTurf%aw^~c#$)Livvs6-X^ z`_jXozSSQhJpYBBOM)*+QwY}%GVebMS!1{g&~>93SXotLdebfZ2vf+O-%=y+ZD5Dg zrKTP&wk3ECf%pi0I%-ctoc$IQ;Ab$NysQWW;==8(2Cto*+5=BjOZF|t7LZvL-7D(K z-C6=#{sX^)`%^YR`d+-{oV>bm2rWBsTiJk<;s7K?o)D*{8WL?Mu|n?}z6&%&vB1E< zHKdLn{m+N+pV-K0FXIC?C8Dn1{6CTOkEG1gs2;PCpnqzTKU}Fywg=!3O<;F+avoX^ z-61m~G3HlyL8E5T;qw0BWvyH#*u)PB^+?}+QEWwYfLV&K zM_TG&GrloW8bDP4@d4ZJ4UUsMsI6Ij01k+ug`HMDHw{a~c*O0yFQTo{9+Q$va~`x55~;2=E%J zew=A;t}luu0MH&%;jv*-FJ1!)oBfnw5S)Dny7}=&c0mEBv4(V4sr_X6rmyRo!$NjH z&5Ze1a44%lyNw3*^F{8M%t>EP3IbOi)U4hG6V*M$nI0C=cFCAKz7ocX9upa~0m8?D_jBfBgwy<_|6apZaa-y=uko)6} z@#^!=tRxM;7=m)?!YM0jgAB3c*($8rXcoG?C`Xh=zCznhOdUfX`UNjVnvwL@f5#!2TW@$0%ZvUr&)(J_9j+v8X(jHzS+u^dzt0pTA0Q#t@TtO`XSvA^E90_D#b?|AOjC!SBo?O>J&DsaC+dDn`XNZT0~--$W)O_R}>aLrYe53Q&#nL%;* zG`RLj)YqfeAp7$II42egb2ZAZqVy`m)eQ5K>j5Bg1Hih&wcYe-A*vfLbg5kIu7sz# zR0fU!H@CRf--vhlnZI zxB}6|(uaO-OQ$cJA8zJILAoOX!*Q!6&BZGTvILn((F+_oe#usmAg!c_mAv)JM7K_x z1qzOyVgWn&5zq92^Ucb#g+_?vqkew%Tn$?>c`W=F$B+Y9Y-Q1nxuZ%4ZfDjjx~-B2 zy+aar9tIq?4oH4ho2m$zxp)UGH~(fIt6NUBPVO8zGsSOvp?1XLK~-Y6{M0B};cBQp zTchh-#+x2v_JR%6mvQb48R&%a!}Aw0E95uP1r!vt*7z4G;UA;)OM>R^2~_%mu*#yx zNQoO2M?1LcVnp|0E{p4n3u7sMRI>OMjJ?gm^$>@pVdZAt2DJxquTQ-yF1|o8pwwRjxL(>!y)O z6WY`y!RVC-PNvnyLqIML2Zxl`%rO!Xqk-$fK;74%BxnrnpJppG2Y`H@y}jX8n6B;j zy7U3^B083u!R0U$7oys$MUBSXBy$Up=wPpj=$YF=(E~VAWAlnt@~q}UgDJ;h5&9S6 zzUgn7x0Ea_;7)KD;0zzRM;s)xjE0p0_s#EN_n)#kzVh{;8@GL^oZ&)u;^LVFxoHts zGp0bp{cR@n4T=YqMS9&UgRA?MUwCRysDIBGl97fgujbQG28djQW})JWUn81WFQ8AR z#c!_2*`Jr1%D)C!g)3i7mmdXJF9u2CCl4A|ysMfE2UXdEji9!~34hC1enxWyA6F%V zfdBz~U9`Ht^b2EpMBc`(g^R^kd4K#Xx2!Wh`&tg80qCn2%D=yQ5mv2VL_myXFTVlu01bKm*4YUsweDkM?nb$VaIZnt;j-*fdWfB{Kj2W1wYiyWW( ze3s|$?OKM8Odoa_aHhECI#;lt>OLl$SI-)cf5~-shAf+vNt9NYeZ}cjv)EqfV~8qU zG5XzQuNfM^67smrB(tciz=kymh~xTB00xt_RkY*!YzR7H-C%t$2 zHs!%l)75&yiB5PfuRQ(n^UxABCnxQuKRI!Y{IbOU(>$&NQqI#mvtzq}z?R?is+o8t zw|{gQenA2eD3^+IOS@y;$g}no4CVlXvZo7#aesYqIab-A{&D!FXP6wQL%tcCHm-?NHS6TLLmlxH8$tNFr^1`~hCwTT zQ*N_5tjpNbhd6y=BYaswr+c-VGh-^JM+3{pJ*E?$j+^??QF$z7#0CS`28_I95UKs} z%Ow2T-lArFl>iv928xh02D+(FO5=IX466+OJ4gLLuBV7=y%T-FZ_)1 zn;Qmua>hPERMZ&BHY zVCSyjG&3=_z#zDQ^FI{Q*_|8Gt(im9iE*3g`))Mn9%voux)znz+0|+UVgKph~n^Tf!;lZe%$;?Lh;p1 zVu5dXs5tN@qq>oA?m>#w)y%%8BF`TsbY;KsDF>2E!kcLW=p&A;v)9?o?LUP2xF)@a8@n~at{Xu991EU)5mF6k|xXD zO}rEk?GSR2`)ZXx-k#f_fw$~0aRcjlCcS!SIaI<5tUc4qQ7re~1#N5Irt0U&XdW<- z*eXXnp#Ar7Nt>C{pUyW$q1xwi0SEiSFUJKLItP7pdIxFX5NbPLhh^>7+H`*F2A2_u zEwenm0*3DR>5FqYIV1TS!tfy1GyC8!gT^oE?jT1Vcnhsdjnfo=-bOR`%6Clmo8%d0DB~$@r{xSvU)}4Cx@_d_YB#T5pyr^}IvC?cnFN`MgM8uC;3r9wB=h)}sPO_c zHRk_62@%o;LQHh98xyx%j|2c%`Sk3&`1C$wh7;MXsnS?NIsM?G9UL_+H^ zqwOffXRIHL?_fPq2-94nVkJBwPkm&rh_cNkcZD=XgQkoq4mV8FB4q&Rd+gJI98Bop zpr?`)BAa{k>lr*PH1L+&w=WNcPe?GCI>R z4Ysqv9rtWHsBvro)a$dZKv;NrYSTzzE`!pY?2IT^(00L_>prl;Hb%0Pb(Uvl&ri#A z?Zhy%op6u@QILZmTp1_f;m^d^@Pgic5RdI|9Xlz(pOZ zBURtbinAa#x`KW$w|gDBGl{ayCAS+4zu|dtZo|Wlrvj-q{7X^(b)vVE;EHpkK?iM? zq92g)zg_IVyb(V$8UIGD|9|~6eWopOE&X8_Y$YuRkg6Nm? z_0RqhsV&(0vQwJjgB*#&pX&QF&iNxl`OD55Ogir#^8F7pm;Y(lka}8&8O{GSc>mvg zq0+jzxOkrV@#}rPNv^*gxyA9{5t;R_VP+9HW>pe5zkK6tiO_rUa8q6gIrsffP$9^B zC#R*(R}8EvJR<^uMkC{059jpo^%j;0CFBD?2lebO)wtQDg1&t10>BDICaahx&?zP< z8!_;))A#*`Xp}@-KfbngHm7Y$AqxO!QE9$ z-Hi_Gx{d6xGt}918wI{R;>$NiEXZn~j=4G-S?FLc^2~ElC0^teH+*Y>^oZ9SH{jo_ z6?yD6MN3gEloWKl_mOE0N>p^f$;q-UQGD1&(9eW|!OGZ5H2ih!$3l(>!AXzneUrphe>Y2FnpLLSrMoVW30L29$j&9`G0O$~jN>Zm6VXz>yqSB4 zs(-sC`?^j0JhP>nvl0ZVcwjR*l=JG(i$R=(ew^Q0y&VZd4=wF|5YtUF&vaX@ zw`UAFBb6CBnT#yP_V3zXr!a1gd3lQQH0U!?Qf;W8E~QtBz{aw^ou7UB#NPcw3}%?m z^2^?HlE%Bk&m>e0FU(d_x}&z@*azGe`cwHeD_ zZ=NxOMNlVHWMo(_ETp0&2W`CipUr*leI+tlH&$rS*p6jl=J)S{f(IIUE)p}4#Y9~^ zYwzyi8sDE{5j1J`DXz9@go;jl$@7l*u$`ct=@hB0^`7Q zoC2f9QQ?csizJMtAfi|l8W3gVPPV|u5#RR#G6-X3QhmAS1EQbJkz0hcEF5Zbc8SO)r^2)>D1()OeXqx{$V>Y(i zGb~r8aSQ3Modzd^=N^rQen;{0mGT)2QIWgRG&XUKjPl(TVu$gWUzZD1-q=^Em=9Wj z+98zWbt4#rMGRmyv+!Vs38aNrctrdkoK}7JRC7=hBW5t_r1+WW>Zea9u=S8a14sA0 zX$U^(9puByJi~XE*k>gu^n}@1k;)imNBkzDnyO2h@heUA4j+)& zEPP+Wn6wne%e(+1O#gO^a-E2+*W1lvuDix}RUCw4o2n67&>L_zbe zcd%K>M{?Q2veFQ5-xlmux9M#RI+I#V*#lY1;D)mz$d}tca)0#&yC^kML`+QJITxck zX){`FT4=`y-hC@1qqAMx>s-@HM?us4M#MW`-uKvg1=e^Ke0p`g_m*viAc`)D9N(As zDT-$9X1U61=UsoVc;vQa?{_DS612#QY^Q%7`}_?i_2(^ZNwP%332Mimk4br zpq*P1VejD<;PUMc6Cxu>;=9Q@&m{dSFMpe<-FLf-D>wPP>h3TxiFm@9zS{&%Vlh@r z#2rbYRo`g`-*pC_cB=<-pIf-=`yy7Gg;tyP1{-i=hJUIwbU#Fuue0^Uud*&*)?U@g z3hPx5u_z438BLU^a#ahl_WG)IEYvx84>a}}i)YUh7QRf=kUNGYyfFS)&dMQkn@`*! zaL2KlZgXs7syAF2HL&_HW8S_yGp~|ys+VT}n5fY`ce}Pk^fzgxnSy@o+K12B ztur@&QkRId&WkIPsvs0-yR82v@>FBzqLH0w(8C>y#5xgmFK4HPn;p@471`cIjtU3l zB-zXeml%^0+M?F=pnc|8#m=L|COw$s=k@tW?~Ai>f^6cFvD!%Yc(a|sc(Heu_kVj^ zR8f@;8Mm)r7dAjR6jGr>(Io}G-_5F7_e$$3l^oE?=lc7n>3JJ3D#sOX$rx%xW0$L# z{b#YO3ll0ac$kS{Gqh&10fya*VJuKZC*JFKP3#0~iYhjqx@S)5nj(|n zW;VNCBh~u9nW1)OTuKN;%p<|vJj?0pQb&g6Kn-VKPt>($WLekR_g3P5 zBZ`ShK*+a?2CtFyfPAMF99NgTSM{2OWob}!oqh3Ed-189HO~n zOk=C;Bm@9|CE0CeUB+?+%ivP!(zyE-+)MN4JxZQ?pG@&Z>sI@H`*d$%Uz>YLpuXc9 zfZyN(DRe6B!=|wE5-*;w?Wc6`nXViw5$*lltv`~XZUC?;+~0T8Tn1lzW^`COgeO$A z=k)587gPGJ$?iw5Z;ph!rPQGe6&WJdN=u5SMof2IjlzzK4V$&6RVA5N^G)k}on15A z$ZP%x%V(xKgO+$X8t9Nh! z84pZ#{d@dQL$7m2LQ0Gj`kRyemp%k&2n%~Hl}>Ks$Srr56M6^aRpPf$m0v1uc=h$W zZNzyXjUm-LRJ=v>pw3&Tz^e?s4!jGbD}j^X5-QTE=5u3=lT-02I%<<-E~KiO>U>gT zFZUcv;J5Y{6_%Tw3TaMGc<1I*zGF9QKgEW#Tei3MWsg&`yn-rc5UTs2_kv_;Iwwj_ zw~;Y%DNH3o9h=0~YpvwJ1Spwu1?W_;eMhrWBO2q@oX-NSSRss~G+?Me@oT z`N&hJ7Ah82o>qY&^u z-Zz>c0=5XUks6HV*2fyjxU^3UJ4{UV*2n$!`+*5DCL8lvk?-uZ%h!e0q@`64qyT5N zYr>0nhg*T#YXiBC0B}1PJ;{0TWZ^ToUGGQfc8w{~t{sr5YR6Zug~d)yh%cMb=WO46 zK4m6z-=*T7aPFm*RJkV|ZIustetS>1^qxKJx zVTp`c=RL1DF^Kit)VDH@5pkR0%Jma|Ml3`j$Ms=W23_mJ3U_y*@*Ry|?1>)PBbnp6 z;kPP4oSq_{<7HZ$4IfH!W@jvuft5i}T&%frYDnhg-q2h9_fv8s6=GK`h(19m5xyxw zfe0q0W5c7~$M2-%gTO#E;%-a0voiXVI9ztl_TnY^WAh6*P2<(xd;#VxXXTvb7joZZ zH=r?UPm-9HUNadDZclqMovb%DJxKF*2DH(3@#(lpTO&rP`7B>4Iaf^kIKT;)o=4Ss`c}> ztR~KxU9RgIwYqi1l;pG#8U}7rl^yl1LpDNag#T#&)WOR}Mp^8%wba5~=2#WEbtGy!$4x z>K%eg@ZcPxXU6-tu)Gu3H>8BE<4#$B(u8~(38_H0R+;x}*#?a#YmX~;Q<2}!D$n;d zzNh6P%x-zTZ{?8}jZ7Y4CMgB#hnag+$~sPmYk4P*TIq^S61S{1YR>vv!3O0hMiT5cKdXr0Z<2QDaK2npvYZ4p=3zc43 z2NO&Uwvl>})Jj9X_li?B|a~*n9QIWb1I> zWx6F1;zrH)&T{REqe$u0nY)wY8c&j*Pj8MlG$!urW|nxb7@-yVv$P>IOImN>bz6l@ z)H?O1Pll=8u@Jpta12b1Y>Y?ym|s7|pqtR2R(K}(^0)a$zNf=$ME9&+e9mPTjEYk4u6G-TCig<4qinuIM(Od=Ku;*>Jo-8~fwIgLnUW3<6i2;Bf1}eSPjZRa!HM05a zWJ=4CR?2Owy36`a5>Ks=xgrA2?Y+~*&K(UWPE&KZZnjHlQm^VjR(X$!dqEpf67w_1 zHXNp1crH@Ih7=2yBwAX`zqr~YtpyqUK9V(~P~MPNHG&dd^sbtzcXINoq%Gau8Q~ml zH(;FTpY&(euWg#B{Nh|s%V}5TG$_u12xCgDTaycrJ$jpt-tQe~6j?usgT7IQ4Uh%- zFPf`t#EGzCPqWO_J8CXsrzk*0{?^b}eh#yUl^h?(eU9d^ID78K$c^Lj>)%jq_dJqe zH%Kav%Wm3Xs&4n`pxJAJT2$164#fQsunv1WXbw)+TDkCFuKTS^(C zvgYupDyWP?%C*|1z{RvbhPB{mOA4MluKz=FD`&RHNY+YC`yCz>%kWom)SrCj?ekuHznxda_q}Xy{hiG4;#{q- z>7GpspQgFxldCghMT&e3V`0#HVaeGE5~y4)cX|OVM?sERbifZ z0uD%qBTwz&Ms?0ZRG67Z65l`bRoEQ-A)?9&T;l}6{b5NhYVrsS(q6)QRlKcLHWS$Q z!1C9&9eVmU0VFQ$r#eVmh!VIImADINE~Tqup_UZn+{Umc8&!EIoCKNxJkNXsceh?2 zhA+U?R+wF_Q&k^L_c!SX5=f!hXYI4|6*?pw1~s$j`~5LtCcyDMWZI|PIC8|3$GH^t z%WFBmJsXfX*QmhPpGr6`<~Z9Ju9qla??7y!D%ool`y;}ap!SoNm#-VUrz5z zSdVCuEUu}2ue4x_D*0iAmDliVQwh7{+c)Wz&;>5Fo2^U~_K@y(aLwiC3=FEPkDd&= zqHHP@8T+F-^>?geP@;)U;})ZJM@KT1ZV;5a!8z@ zREE07#U)}*~ z)qDwVMmHTTr!od81_w<0b#PsKVqW9BCgGIOi^@521sfjrtNg?p@_irr zGF7iGvNEriNsY&FmEI~g=KHG;xMvPuGeXRxt?-J^E*-H@rZDZ zq&OuB#%aNK11U#$nz4T*IntFN%T;exXOM%*Z&)AHyZdR}{)BMSdqvGLKc(oB>DqzB z27`EwLr1LOmE$}px$Cf$vdpj#!uL!di!Fdy0>dJ18YV_ z&ClgRz;8s{S`8L4_SaZg**w|_bRUKJ$;(-<6vf1(oPFIuL z*u|Iyjr<-4p{BPj7K5AkuTqX1kMpXrcmtmvmP zUX)OOl5}?oT&j*R@fBt#wL4-?omhs|apu|4Jy|tk1Z>+-&T%_F;~?)|>WyT72jaK1 zVvT$BwO*jFp`IJ7UhF(YNMV!xBhj&|(_u1n-SFJ9GIHI~{+@6b>rUK!%=J&Lk1U0S zpSCg~w)3E;|InnlI`sZa%3BG)U9>hMb$D1h8byX_79xDeBm$8J}pAapLz&ZG{tOO1x%Yuaw(h(bu83MOiF zgJFeb7%8DfoJn(ez(%E-C>+W4M}-#2>YYwn-nJM-a?hXuZ_BR(c?}TK0ipL{3_t6S zLu##)2Qy1mngM5NWqT_FpNLlv6;09|^T^etxYdlMwGM^vKunNRrB0aRGwIG$n^P)Z zd$NYg|LEJ~~u{^+t+}lS6)y zH+#uW4%8&<%P2S?`Nz4Ed1d4Yz+FpRdSp6GJ`gskUP%GX5A@g6v_#`$MLfO)qr^)G zT-|Z8GSIHK^RUM`A{?|J_a>(l7M{p2?@bfiKQpB?Rh-f{yHK(4x#gn>=y9l^H$JqO zfmvs{vp(Y<;uM^H(hi;~*OCW?f~x~n!g-!MH}7n3Bh=j-Y}Y`xYWX#-Cdsg@n!-#^ z9~|g^@sFI%S~t^Yb7W$Wv49wkoR`*N54P0xn}9_hTXWVx{&He=4=`d+tXwr$N>CF3)2}-uQOrE*V4!MNCigzyxCxKuBuu7W(kce)gx45MJJ>SG)He@bR^XDf(d) zhgM%Du*Tr(f;{=(a%dJd^h3Kkdsjvq3I>wAldwI8W8Pzuv!I|2+5Sb3gYr*LhyYd7Q`cJ-%OaFeISixH??qq;QvB^JVGtKK8L_A58ep zY+>fXCcyrW)%{Ro(zvw?+_tulH|?j)8#OjL1wCbWHHbQZeQBB3)SVzm)FCAt zKwnzhGj+-$TS?`#@$r@uvpgh4Y55wSrA|)6Qx7<794F%u_LhFuy}L*;5Ah&SZzA@(XaD&Cz?v z!kxYc3QQStL|MOLn|$`{`*vt*9hP z^TEeErPno%bG2uk=j9`POH2ld$3D3$IHTX!kKwg$$S5=YgVjxkL_i~K!`FH5H|XTc@N}&3IRhJfZ>Rf5PBO-?MZ(B{7sOGb zuDn91Gs?`)Ps0I7wt;|iehh5-K7`=11Z%NktM|KbUpng@hYLzHFBD>?>E70 z5vS_qF3XmhS%AKtHtDsVD}6m#=yCmP8<)Vz%LMms4%mIBG8ondKrXfmIGxg5Igf0H0l{4D!ZK)cs`{%(xO?@fgIn2D4@4U5ZgD;NzOr?J&^Mkh4{1?} z$?dOm&ZB)!LpPFDm*cVXJkGh75aKhP(w1=99g*anGj>;Vt(t+9lZbTemR#?XZu#UZ z2*oP&$1G>MBEcT))+iH!9v!I7p+Rk-rfgNLxl1D^o z9=*O#Lq-+RJ{s6PmNoi;lQ;aCEVDy7?!P@_aD+`gY%Q}v6i=?NMQ7C&n)H`#7mm3E z4EAX_YIWt|_P}boeDjvS0}B)&8yEvazs{btMS1s1X?2lVRectZpejB~#ZoPWFxg4L zO*tlvwOT&z1OdIG0DazNU-xrp2ewhZqT9Lk$J76l9EWV-=&kzFCg-llYQp0zD@170U<1yrt7lHNH}V zDWZOaZ5)8PFm3?Mcz!8ff?mnsP|<xTY$A}~7<$3%VlD=WPZjirn@^KkIsx!&5d$w13(EQ(q7m)QDn z-K-kZBa2-;G?bq7ZE7kr-NkGpk$zR6E&oJbEXP)CyZBA!k-{mpIA?WPZck5UVPT;G zfQP0H?!V#!9iK~_xjXrpJm7N7OSr9Ri#ksz0CjH(VF0A5PCP5G+0PMAoVusUlbC!! z)KT+9)jG8|-D_+)0m$#BrdbH<baPFh8hPzk^mbZ7MXi6_rNd8mHxqaDCu zu5qnMh7AKrhmT*SW95o2H`IT$k@W0M5EgoB)7imGUz6ymUM2c7S42$oxk||R=cFpT zMgy97KB0{8pxUvmv4UfZc9Kf`#Dtepy9mVNI7bHtB6+g!_o)eNDnnVG)lH|+(9ql} ztl4~vuSXy)O2ClM_zoRRuSf=Gfyen0s@H5ZkO*p#!93xzGvwM(-s<@D#G>%lT>Qy#AyNaYGszCsN#=%sp{l zyyNg$>$nH<{8IEI;jCV7!jRzDWw&vUjiK1Fh0WcPWpNQ3(GUZ^YIk0}%S%WGnmai2 zf>;u5+fgh-7a=~oSip1g9*LHmex*m`El%)C?rFB4_brlN_kP8PhWg-Em!0j`k&pj;F(9~2FYvY{bGf$k~EL_c#D72QK#rW(KK+*O8Yg-OWWK`1b8XavAfF3 z-2m_xiFnGqIT~!#S+qsj%g5Wa=i{9d&thI6TfUfk(Qzt}Yq{DI(42sGBR(aCm(T)# zzu}rk&&ssviqT*ZQd;lPDuzAjaAK%@F#&Vxpci-Uq!)vBZl5>2E#|>1*IsiGNIG&h z-IZ_FIwa%0f-)$gdI%V_G3PnL!ZTWAzRBrJMUPq99<^= zg-(r?`w8@RSWGm`4u8a4IB8;9Ifl@Ii8_oZ4bhOkZ6C_$43VLBT!#%$!derm>{y`k z*8gTEz?Gj&o5_)3=)~)H=y3FLOy&a7pLNp28cTVSuWk0c{dF)AL9=yN9TJ7!&gP%- z8ToCE>X%59=qtmp>BhCs*2`ZyejSgA1G%P`fcAASfEX=^MfxKogRA23R|V=1l=u(Q z_4%cBP~g=ECN^w2 z9q!O;+3~Z~Ia7{y`s=bD-StI*&+ka=<;KQTnHI2xTwiw$VZ%yD3Yz-K+r-p6Qo7)h zX0em zCFqZ6)qrHw)=q49+{tI5$3vWf>XUrh%=kCqgU-W$;cM_e1pITgpfxF}QEA$;v1z>r zUY)W(SZt_6&D>w4f6QdG8k{C4d+v**M=~`8_Z+2uTSmLx#tu?!;rp(#<8FV&h~swn zb1|o0iAo)o)pY5`{6I0%P(A9cX*NZWNf2aFm-8}!!Y_apWIJYL;;!G}PpVTp^&76( zV{nY&I653oOUz7*a@Um)TkVV2hhxB#zbw;KykP3+6>}P(mlS(?wp%F%=WXJ0&Mt3U zhY3tHrbvtnMu)h>gw*G@cK4a3104sak2~E|4fp|n@MppEI{*bAJ8$%5LDY6gp&k%x!>@?HLC1qX3;s}%xIsbNO)@*W%)P0+Y)bU+m>HhV6BHTuhdt=hu z+Mg#TImAGaP{rVOZRS^`jCvKga2aZ;qxVZp!B^7}j#yA~6%O8ws(e{7QGyPMS#}Cc z6^D{Bg6Vz;6Wk{;dez?D^s?nXRc2Wzb{zHvU` zE-q-KwtC1Qrrs7dtjP-6G?J?n>J@)tRgHH-B z@+fzS(Hk6s<3A!~iBSy(_~!^b{#t3g!t^U}Z`5BiI(}|ZW>^JI4dDj^s5(lSw>0KX zu$J@C3nG!&&e*ptRI0Ie2xn4LV?-UV5+N)hl0kY6^^b-}>Rfx?`St}c+==e!edYnl zi4gNYqO@9Lc$;8?Xgnl4RW#lH_f+3&3bd}r|V5Xby^pl^c;w*0Z5>O@|lJo1B#x2XJxp&9jaHR(=eT&^k z%Sk@j(Yz2I4^xMXYxMo66hNsudx$q#u!VF@pxR~i)|jhv{B$na0~D6}Q*z>=f5!?}#L#vN|YewO+1v_%N8#jLGHV=Uzyrcb3$FLpBZhL^c;QyWE(O zR@+El>m&wk5xCPoVlx_Qz-JTKJ(pc@H7nN{ck|)&la`;k%j?CLh-or;=mjMAre_MN zJE!N+OC>WRkI4wzr>+zv3iywf$0M%z!C)btmWLn(W}#7msl2JX3!nBcM=@07R?HKDQ?#F5fpYoAkH>+fPskjRBhX0%%@qsQE9Rsmmc_}S?vGkc9= zojW^e3-~Jn{PCao{k>THy*VS=1gCx!JP@wvf$~>_y}V`1-W`Jr>vd%QWVinQihVh< z?}LG_y9a5E$s*4vxgT{m!yQ6VkB%Sr=8mkWzJHIgFSXYjem<5w*s|tj7rj`|(-6jG zvNHRD^De7G{;DDAELVBs?#Ne#qt}EoZPIgzvDyGi2K6Z%C1ui;C)jRUIGP0E57?v3UTVc zy7EW9aHFlMWUulteB@U5b>bC6U-y(i#uwqu(&*mRV+NR!dv*n0z)?wM9wthuaxOe? z29N8x`EM*p_yM}3nhLK`yr38vB*E1#6R7+p#ePQfbQq^%EnJSK{r}8F{ik%?Q3kwj zDlF{m_|>5LAomIg1$f>mM>5bQ3sMT%jNGV;&}fzILw>*eBWPBrGb7z|g=L=SV+itF ztG%NMCwBPvZvQn7_3y-w_>rktId$}CpE#N)WP*Pd#8lb^%JIFqLY>WALY<#}#xFP+ zFQc=+u$Zu2-hAF>PWdTw@0_2^hL=sHsfS+ z_1)*B$&8^7#Rh|NR8eV zj42)OEtu6fj*5L&3whrK5vEjPtW=)^;7`B74W4VuYYwjl1=zsQY}zQT`k}eyee@ zF#h0KyuXTp0OVA3XGkNp^*`mM=#L`~OKFXmfmG*TERn_HuvKXIc3m7zvNXFY2#pwqHb= z|2EOb|CW|KlhA=9K|?LG*ITwi1Ui;bXV-`?_jDP?m9U(a;Xn6tDcfqHCy=XmXe*}T zXYPd`q7h$i@Y6pi>$~%^x#T)lWA{3I$O0aq@6HobE6+P-;-K+it0FNk?V?5tQyltM zMA*;xUQuiIzm2b{cdzK*nx7`=47kM&GP)nbj6k)=48TMe6lvJ_}aTyb4(J&at4Lgau~nFCgX$2OXm`J6cJE zfcP><3iJiV=0zq91^C<4P0tV5n}O(+=`oHkq+-rzko8zXhXfT0NLJc%lH({T}c8lO9#_FKeZh&{G6AU6-;UzD(dgYlWA|*&%kI6&v zu&QH4%A<2ly?Kwq*H)6D@|mA}fqXJi-tyNtzP#rRr6KhF{j+J;TaW=#zD~Ejly?fD zyOxr)#4mZT(&v#C{Wx7T;5*m^MngeunWS`V%oc8~6)(sFrh&&sM;CCD&2oz$q#;a+ zaG+&_zPsAL*bKOMY}@B5pxCk_O(8tZ%;J4<^?20wb~=23X&@JNQ##ocB@uFMX=?{C z%9R|7ZoA>Y2E+k+=^-x_UO|i)UbE;>h5uwx_i3E+qkF>>6Nx;x1r63$S8pcsiiR}$ zlZ~b5!&Xv6{>4LN2+k=E+liMaO^s@PIU6jrx^iw9B~rLfj8~Kl)rlJ?0{b z%0+#Mg)*qx_LH4uo4zUx#A#MbMgg1iFfbRLi)tTyYg~&0eZ7NZZ_;1F?DrB0`F=*- zw{|IPtZ%+XMS2bz1p~yX8Rg|dkdq;KTY4#CAPD${R1aL{kHb;OAmc*Z{1 zLL9VQprA1g$MG!mbn8+1K`|4)Z=??qXt{G|7=GQ?GoFo7!L59%P?eyXlET-YDRIjlknC&$^3$O`X)rXCI8?6 zFK`RBU`WN~s=#)q39*2r2cd@@5-Bt5jB}{u5AGd!Ei-0NWGw5JsBP%>>2BvhX<*sj zHA0BCc(`i<*hhj+Q9k`OAErQb8vgh>;t;hHNfys4U}TcYQg&hzKoOV1NzUb_qEHgb zEtI9FPhfQM3fA$+crZhcG&&SDP@CfoB0qaVl&7{EK9#uh=@tTbypnlWpY_Y<>@O8q z9Fh)nV^AwxlZCTdDOC>hZ6c}#al2VcUcy;OuA6;36MU)ey|*zZ0uWN`69AJdZkXDAib1|K<^EXLIYKZYU)?l1eT)_+a~8_!$nrg|W=z zo{OCuDuKf5O2tvOwHeMn5;D#;Jlmbp)^V3Dvh!WmC#_*!h)~XWgdTd(5&IbOyyP>+ zkE=RFb$w{DSU-bc53pdDV1G`*_IK^8ZC<`B=qjm+va_pOd`LA~2PgAK7@*}k;t%q0 z7EB;BSB$=wb|l4)Keky+M|8sfH)`z1rL-;~`Wgx6b`>lV6y(mn(zOsRDw`6&WmZ7t zN%2M4_4)U@P`iz_hr$6B!qQeVJW0j~={69`-WQJ4VfKC#W65FB>swuYuaJ$Xr#o&i z^I)OJrKDEpbAN9ydF?keu{VLWJWE1DiUw4dg&3z!Iqfm9czLx+`cb4t+TQq?un@E@ z3>#l7uN#11$x|GNkY?l_a$8ob%n1(oj;RuMJn^>2{xJ!m*5fn0UQjWoqU<534rx@% zXD$P6=D;_P;T_DQMnJPV@rK3El?Pa2>^*K2Pss(zEJ{TCxoYX{%5;p@l~UEg$eQ$CQZJ;sM!x&v8v zUGxr7WpTx!Gy#=Jg@I(QYJvn*6vB6C_jz*hZO;x4Dtt+k%dTUk9YM#bv6}E2sFePq z;YLUUd2fw>F$&|^VEQ<^Jm!9Ezr(|aS0zQG=twQAX$3%8-)+Sgl;J_X=&IWw)znO` zM+sSdmQ5l8YQR0srEg9gUemYE+EB7i^5s!G00cmf-zhyZxxD6 zjZf%2pgFxHPW$PT1TxK0N-B~GJr7ONlA!qQ9U={f&k(%{KW@4NCZDtA83 zdsP}|C3sz>%B71`u%1RdGIeITD^p^`kQ<_Ffwj35r)r25-qxcbMHJsZQNqMZg1o+Z zs%Ku9- z5oiuj1N{@n=_C1_;;Miiom@EhZu^y}s9_VPtLI@LaX_ojWodaM0 z_-EPb@9n&5mQBKm-_E6L%JtjoM!icV!xkKXbmxZO(;hX&iz&&C=v>>S1GBX{>(m4B zd1D``S7p(cD|}K_cMT)C&lh-J!f>ooh#E=;Y!RbpIjRhv`pMl|ex7sAM1bNEdSq*b z$0gxu>^5FBXZM6^p7s4nd(rK<4Do90cDA^dnX;@F{AVCCGs>NMTCfB*pz&DJ0sXAs z!>MB+pfm!mTAOj}(W26MD5GUb;uL9-OK9oS0EChAa)`2Xp2tbcxB2l4Twg{Nm_J%Y z$MC#rw>JG2Dq%Bwz+yMY%6s_48IfKW%9YeMF6-Q+-K6`Gx&_c9`wNuNL42jZe!2##P?C##sKKGqx4iG#o^z;F^?Aw4)ht zGHYHgJ7RC&jatqzV}Ebaa(;IOKzNYusNv&GE!Oo}$sK3t>#d8XKmV_7K|LRUFb?d@ z9&d>YZ(}_G!oSaR$r&W1*F_pRRl?qJ%Jg>oPglEjpT5(1@FNwQ*PL zXQdu_7i2UK!T)g!^GfwGmKw6gl-8!UeTO;M#uBoYhQwmONyFeyg^Eyi>8&G%Vf5C$oMTNQckN0Y?=kUIMpb?Km^;vrJ#{q6{4zmnd&$z0M>6r-vJ75^+7qW1H!t zeDAC(12%)}*Jd!C^*iD}t0?K+uB;(3_f*lHVDbojM~o`G(2JUEX34E^Pna!MryqFuYTD^(n&?}5=dOVSG3+h0EEZNQw=3GXeHx6Sxy0FB38$Kv>zCGNA+=@yR=;+U^16?vxSF!(6&g8eDX;h5 zum+y~7@Ync>4ph;<_imBJaAKe&WWp7VWwE?YN|s&^ zf;G2RR9bX)?Selmaptz=3HH06XQ>e9W;MIh$VR3xmn%?mqASh z(rb$JC-Yw$SmzQo&o#_9dRD5~J3lQ!C4L>ax@zF+ykK;o3n7g5igdF4e4{vnaw;uM9%gyF0@st)~c9UlU{Mj`p1ibw%MK)My2t;zZPi zYd`?IYof;W~+f-C3I_Pg0l@?;ma(Z@ql5YS5$J6-8gj1kuGh2!7Aw6wtm6$5@dImm8R$*5 z5n$!g^Xip(32$v?2P;RvSw{adbPfll-DlkBUJTBg+gq~Cs17KN}GZb!2%mA z`%D{+(fLi+e!chJXDB21Ocl!Ke#l)V&k`XKaNp=&mUS&SSZ~_fn-g51gm+i{EOuH__T)BE{Jtt2FCn~`*fi+U{QS`K0yC7CLJuxC(-(iRPq z{`DP=AN9OB>OXQ)9G%in`h}|+c0GGQGRuvO zFhsSwarRDY{#T(>b5C3Y0x6|)7_-=K->{Ivi{{+B97z06jgQaweC?CUzgHhS|3vJj zQEsJ)x!FX0QIO4M;lTAeYySVYZ<6z^KGJF^LO+y^@GwT2lE%JL*T6Bn2~>#vlK#+PV~#1;VdJL5XS?^_iF0qq&_e=3`jSqFiNaRYip_Le_!v2k zlsWgcB}K#=s=2G6fJ>lBKKG=)DP2kT(WkMurA#s=)Dx9pYPa_);ZVGrE1#`pJI43$ z$!sx+jZ?t_RRP2mmV_GWMRruz$6DDGcyV;Av`oUURO(_!vH$zAE+RVcq=#)8VXt+U z?zkKOTr+`HvcMq@eZ`8)Vss=&pIc$1*d$}`{;F>!Te)lhWc7?!tbt3hw)S0-in+&H zJ#r+)vgpOqXEN~|gtmiqJ6bZ*_gp%L{#m(&oF!?s1Zc4+;T zL0Di`j@@j+c5xw`Fl66(IVV0*U*-Of*sZO#o@~Ve+h=V!!$UXw8v?AqOip3MvEyv! zAn!&z#VxLHQVu5n#~-QsvP$|6;zZ~bZ|~n_;Lr#@agn=j=+GfUd__XX?W|;fm97eC z8ui35Q}l!ZR1z`tMCiMP}l)m;YtG zz% zzDDJ#@UnJ6CFw;$F7p%u=gEUp=lY;FCZr!^YyP|$sR)Oe40gq5&6*2N9MHZ->({;u z=7YF8Y8MKb&a?>##jLsJLLqSaylBPDOed&BF|5;LWjX(zK%jyYiNi&_G2{?Ae0~B( z1#aHRr8h9lt}KReSBSS9K1`RrB6akl%f6nDHf#*F(T@(@Y;0~^Bi^zpg*a%`6V;$$ z`ZnL-m9ZK7o3fLox$Tp8{i6hJxg`27B~W*Jq+ODyo+y&Ep8N4ethxph`)Q929Ryv_ zanvU%KHz9vg+j{d^NLG;46H0^p)(T;qO`{+zq-3~*=bodLA2^UiWKPWYQYtL4 zuN3lfk6%p?V`D$V{p|=2kag|%8P0Q1+qz)M|KrE7YKS z=U1bz=ORYiE_9F7uyDv+rwkKPu!eAU-BH>w3_UFvvm#K=kBX0$2Z-^lMf}n~hC9x-U-7&A|s= zpY~#xPqs`7zziENy!Y0QwoTCAhzaa`nYbhUWL75@H_^ERqa%OK{T((89ya7Lfcama zeCw2g*+SHNZ#sJLMq8bl#f4o!&8gUTB!oneudvJcLPIWFxE(X3^J`oEfag|AIJOTq zET1^CyzOEZ;XPDXUFlw_Sw`nz+KRNvvt^lk@(gzP*Ea1xbvQYcvM8*P@%Idps zb(H<0H#q35T(D?Bwbff~Y1`IZ7V3y)b44^X#C1dMZ-21SPQ2jPFQYbi zS9pH-jhM@)g|33ISGrh4t3;q&e8kUTV;LW_wt7*=XsQXJ zK6XA&2I~f=u(f+m&%$c1Z#k6KA)hJu(f4}|!-J87*+YG;Q*p`brT5TTkh|nz9uwbG zTq~J7g2?~JUAQy$)=lr{SNwkNJJ^gUa}V(DXuu-X4s{*RCS8!5y4>1!VO?C*?}2zR;r|fTVvtXOH6Hw?USCbq*Qn+v*$~(cKHW0GtJFkImFwAU^lCS zrp;GOaa)CSlJS*=sC|cn(KvJzRrExi3HJhhjY}s(&Ja4U+(=PzXuL>3)n~2tUUY@T z;=<0?Cd242=n|5QxsLzkJUSfgcG|ws9U#N2zf{avmI@Yh*--onIp#V=bbRl*W8b}R zMweOshyUtuP%{T_EGdMZXaTeCWCK-L<$Vw=s-+T9jFPo5umEW$sn`l#f=6B%r_tg~zyoROCX2To0 z_zHuzO=iMs8Ks1aZ|Hp<-&9@=dRr6x?Gy2#`j3(S5jS{>Z)dJZ-bRKb)~{f3_Pnd8YsZ~FWAn2+F}h2t=kIsLp8Da99&*IiPi z*YL3_!IQ1y`}E=?zpI4ABMJ8wuM*;s6a=65#+`>C)@=7-5!=Qo#77sE-+R8(A`iYT zoUS4uV?Bx{|H(K`AO8wWiEhZe_x5?Al0tGb*|C^BYzTM0a&O)#p8L3n56ToHi-h1TOWByr|M?X(eKu~Q+aUY~k$Fo1>KbM8iE#{sG z9$k@Fq}zZYGRIRMxtePZg%O@BJjypK1kYYzKYmT!ESM*lMN`;zEKKv-Zy@2VF!I`C zgM5*|Pi3V~VLSo;VGVRF6^*QKiXJ2ZJqR?IF{=WKFRZPgbGOLowL6`DzOPS6;;ZMg zXHEDKwbq~R#Q_6-W@%e}X`vDbM)#%E^hr&Bd}9m?Kg7b*4clLJ74z2ZejKayaIJdg zh$mNxI534GCq34k0Xp0{EiKKei$t`}>tN3u-3>eF!{OFps+d`zOB1%wLoj^P_~b2K z=G)}jU#}7t|A+mQXIJ`Cim`;-CW_eiLV!ykWj|>G4iuH8P%FQz_2^0#Od&@>$LZP| zR>c8xXn*v;lt=ylBiewA}#QEFqtVXq9S~U$i4`sIRYg3Umar8I@zzuC|*V_bnt@KRI_S zyPo>T>>@se3Jk2^%g}e&_~-R08<2rpeKftD1l<{#gW~*Od+{!>`vBG|7Tq17aFL!o z>UkVQ_8T`?3Y5jI@f5gct|wOrK$(*=NvA683w|QW0j7XSkQ5f zNcKpyt=s#`0GI)4(UTquM*6(*+_hikQc{7?eK(#rfMU6%A*BG%9YDIj$BZUWB< z7IwnsK+5amplg({Z+J1M@ggonT{6Y+X>kBPUu(K=aHa2p2*-%)n00yn9xf}n^yUYs zyY(X=I$6sTaf$ywUe!LY<6zAU3l9!}Q!PubE|^7+)kO|pzx2k-^EQamq_R4vfDm#z zXkt=a*IP*28Ep2Mu(2r87Z@l*Z~qdtCn_OA$bHXlaWucpGEjw4jab(i zDOKU_3&_66U_=pNVq(&|qL;sL_Uzel(8f;6Q^f9r|7A}G>g;jX34KRj0MU@(Fgr}% z&dBE>%e2g7FVV^~{cU+J2SAe`d^5{{GkHfcuMpKAK?Ki4E|nQZDEYNz;(Cy+n1oT) zWOWhA-5=f-*ky5Ru3YQlxs(mIm`QE;z}`bt7N%&dH>e~YML0p57nV>JtUESPsh-@o zh!W4&Zc!VKE?pn2L(bhv=lt|gkg6dBqXQv$arTdo z5RLSvWyn&86;+>hQmF(Aei5(>3ilGL&nITG5*Eu{u{q9pfirl|2O{WK1&*}~Q5jy2 z#U8FrvQJo!W7y69H@VKnXEdBr6D~utK^sqe>7a&-`Kl{gQ~a#n`;{0^dz0OhbHha@>TaKA zf1rkpR6`hQGjaX&)_QQYiR^b2j?=DC&CL9{6p1ZR*sKZ+44f;K$aSD|&lklDOVOTG z&pIDhu7))>?Xl<0UY?S!nson;c8bURoNb|78A7x6mPka7^`NyvtF%Vt7a5T8h(38! zTLDgfRSPH+Eqa zsZ-+%JUBSWDk16>m403Vy6JQ_k%KN%URdO_y7Ifm-xcR?iDa3`P;h+ErpOS)D4D8X z$xAxVpcpPz)Jx}wD2W8rqg_V8RIsU= zzU`=Dxkqu|F0Vv-V+>v`%FB z`95BB(y~8!a?6&*Z0-rZGGz|}|0LKgP0fK9`51gx z0(yL$g4@M%T6 zPSAK*qxu3TkrQO|t==v@sf&SG>^dQF5VjJE$Sqdd{pz1^qO^!G3}`neWm01o5)J%epZt zb1CnatOOQQ4ka8ugG%F{)%2WkeEi<~M_O5LbM2_mePkZt#TYw2{=%61nyX?6E((ch zS0A~pz3}rrLi|s7s~;5Ei_K7@BzeylQ5`EKTk3MUwr5NV|)1KhbC32 z6j#xCyW*pwbBrgK2iODYFT9t0Fx5(bb(xM5fRhAHWRUyjveeGUy&{d^{UZIRCRxF( ze*M?`VXWp}AX46*5Du532oN+@DyKt;h4a=q5uFKS{<#algsiw`HKPHdg1c8zy)p@} z&4~wV@jZNVAA4=PWZrtLEI(FN88->n`R@5{dOWD;OYXaHQGiU^k0YmUnCzo`rWNhi zmZ$%|wDTqi)kfDr(BW_hv`K7fYCnOlX7EPoQ|Lc%ZcXR3s;MFq`AxmN@+2n}wfHQF zyslCPYt?!6S{m7=$iX!ICTMnyd?wy-O;Pjzy(jpF&{OD%7lMBR2z=vbZW7=kX~SsF z!(hb!>3KKumW+qU95x1JKjsf)ag^51g^fPsoBfYwj>J(jXB@UeKm?tNCQZHiQ$6|T zBB|%^PEKnhAdY2)UY3Vyt!Oa`;9D&prgr9mB#27X6~qt-{FNvB0`7%rxwPKSS8P!X zXyZwJHm2@`EeZ*{+kciKDk_T46^Q|zL;NaPm5*0$Utk1Zb6Fc-W`u65qnjvIS#i_^1n&OF#h~dn zT7049?`23+g`41UwiLMWAkRY_T4AsepHu@7HnIRx9mTWE;FJeF*jrrA)hbzSy`HQT z(h?uo#RaZ`8V>+8o?r>RI|B+P%&vfKy$V!JBt=}E;z32GnL)&X6*>ULS7qkt7q&ne zTGcIqy$N;R>Jib|)N{_M(qfo`9pcsw57rOE-FZ)G7aBVMRb%Ph`vK|}iU>t@qwy+d zt4-{6mn1BZv>dl8tc~gy*k(NTO%0I(-|9ii@@MmBf}}v_&~J3pm)h{bN0&8O5Uh&1 ztm>d$h3FWJ!mA|0`9-^I%2xZ`<|DNY722NlTM7u>y7eOoC<@=NbD}IA0pd*GwI}3J zi1nbJ%KR~``sqaPWRJB5noX@5-)6H9KOStUMY0WXR1Bc75Ewg`xEe zSo}3yKPWu1;uoVp39Q}dJm)v5Tj0Kk9)FAl>F9My^tIdMY9CbUsz;jUewd|hJ>($t zO%Ic+P-t)guihEu4I(?zbHq=AUFaAYRia;oIU87|Z{TYr59&=?LMpY5paNlW7zXNG zlcfv)dN*c5HmprGvTSahPe#&8mjk;!nhq3p-68BZEdDaU<9f0*ZXv&X^5LkmHEVB* zsRV+sD(3Up)=d|yv{79sBGGj+&`?M5$1e3UyYq`A$>2G4NlJtXDDaq>&{ZjG;c_ph z65V>9p>9~UJ5+@)$Ib0LMY*MV<%pbhUP+zs%EAHYQ83^4teafz_+rO+8zS^u-+?83 z04=cjV64a7r>syE2goVI*K_JLheqp~nn36=$}t40ZM|8iWLEHV5Om3VL-2!viq3)2 z`ztj-hd#V}*fa1kdud=QxhEFAt|})tah)*N$?3x8!;{ zze7BfhJ5I!=XM@NsE}1xSC_72+1JA8k@tRBBi<~K3%XDJ?5e96!N zoWQSXQJE&9_gj7-%cqj|tsb02=mO4Q@E>~Y}fIvVw?U!Do- zN^TXcU3+`3vBqEQP)<|fuN`x;g1g7 zwUXn;x~A&dSamHoA6ZD2GB8E9MtkeQpT!Q^w)-Gtu}ked1KxF@{4vFj%-2Ty2ZwTFx!~ z*iKZQjaqWqpKS>hD$7JYD0q(Zf?7clQ|_wCpn3@5NBk}H|> zB4-6({w%T{h?FDAwFPxI7^bePyG&_u6%=E{M?wyviQT9XJEnX9(Pj{-m^5J{!Dq;+ zqC?{W81cmjPzCe)bCNu7S0usHSTUP&xMgU>Ys?TFxeF-HEXGyxeA38-=sZn$D`=?%FBFqpL#_keKQbXczVMnIb*PVXwtM)i9)}2C>3K_m zYY&r$nq!GCrQ%+&0km}>H5^om8{Jj0H#Nz^A=Bn9U%yiHBBDj^j|H_#4a7bRF_Iru z873Ufc1?BO{iu?~tLWmpboUb;ZLJ)9H8P+hEs|a{Req z>-7ms^P675!tz}r?`jx*lSUpSAMTrXeq%*tf4p{2(x2}>PVuDl3UMIu=l5!-m&5>s zdbUAc`rgO3Xpp}S7_ohn4l~~6lgH+gTsIP=rLCP0y30~#F!tR6Zg5*u#VDW|A!qtX zUk8$tC)jZ3{@6gBWwP&}ZCa1#=4eZgM=E`PmN>D65i5x`08k@;0jT|^B%N)(*Wm%w zV6PJA7`Rf^IuT@}>yL5z^Q6s@aw0i(`(ZF$oH`lL&y}{8sqVa;ZoPu*qSzJG(EN~F zKwX+MEuC}T|5e_bM??L-|Kr+7ilmY~dl6EW#+sdEE7_T{M3}L!St>grgzS5EB4Z6N z$(nu7Sdx7h3PXl5-+O3#^?83k=kxoW^ZlLkJKuBqZ#45v26EkLx?KCs1Mh zeWCkFh3#M+2AS1;ME=_`gSh@6`T@5o;QM2+4!F}lPV^IOpdW+v=>n@tpjxrwK34IX zg`=Lez)N+>ejfic3-uIB1#;IJ2qD4`|Ib=%yn4ndpiaMaqY@%i()8pBxEHv4-XSEE18 zE#7^c*HL}$9cKsk9$^@{CRLEZHx)1$3MDGG!XmW7SS*4?GzUuA^ z2;NGQikV!sbLS4F0dg;=TYA73Cu5Wwj3mRUa-jr z02qbnv;_#D@QwlsFJ=d6A=fM7Z-2l{Bk)H7sq&0x;T-+Oq{3gz`yz=AY~vr2&h6Km z6dF5L@4XNu;qoPmLhU1fcgZIGe)afx*a9>&Kw2ut8&RDE30FUwGpTg(!|^8R?}nIR zt%?dD4rbkkC^rYH`UcGDhK!$}pJ=8*cE7oO=7C$qxt;aqrcwDBbavVn$d3r?c9>Zy z+cQG8LuPfSV&@@&fSXW=EhwL^P|>Ps8NDh?U~hIT9g*1QYS)JYuC{};)_B=LN!lBn z?sRf?zkB%Obh?z=(jUB^xN;>EVjYEuB-pHk%#eNSz3!Rz6qDQQ2}&2{#6L)7R2#4R zEDD)=>ti8jPoe6ooxU&hW-LZ-9+!K9HH@((CEODORipvxBQsaFZ-AkgS=)u)ps(tN z{*i!S46yy;+?o+Df3rKf_Z~)z%kJcO3Qo~k(M43G_)jd!l9%6IWho~YC%qw5I;eo` zHAoQgp54E{9|YsgeS)zrn$Ze)?Rj(BfBg_d)n<3$$Gy5$hRb!6>N@qW*b{(JdG6pL z{+CgNd^(Wtb9COP_9G^1eM8%BsZjG{=igfI7a8Rd+m|HP4R^u)nHC*(T?pkmg!Pz87!-2bd9+Xqu)a%rtI}(Fk;oQoIjVc^OaFhv<7Ko?TSK{) zls>8%tsCthRWn7@#4Of|Y2ra-j+VhGvEISerLR|_2C;HlHD?VOS4{r9H9=>uuDAmG zRGLK@B!!oRp8RnVQgHkXS_f#&B^C^&(s@Jz?;gQ2Y+={8+Cp8DGLqH(=6jQH@fb0p ze;8k-uI^ATrm268SnfMkT~~~e+@6V2g0^wz|G8ph%zBRqSwjiM4ao1+7Y?0H2hS^x zmH8o33!<6)W<_&8(kQPO=xMnio5p5$;_f-4WhzxuY;p1vUbODT1pH;7rl(37*>ApK zYDs0l)j|MnaQ7(IUM!Ghg?GuJ>dP5I+Xt@6e6azZzHN`)FFg;8)}NOPwJgI}JU#<| zkkV=C!qflQEoT`#u{6+y(^8eIuv>Zu`^|ek3*qo6joD|I>uHpQr6ukIG}5HnL*I>G z)MpHVmi@14!0-y_a_uux_dA@vXNn5;QJmj@vCsMZck6$DJw_59GU%ic5&h`Y|G;$q zRXY+$U)?>{Zyo8|-%Vx=cdW|5nS=n~ogrpO1xpDP5UgFvij!&Xs8R1yX~j{z_uas~{* zxxI&*jfIW@gT_9!s!SV+{qO*bb)NYg3-yZIz^nEOg_MVc)fVbkaI|n+pA_NT2QeXM ziP~j;rW2DbIDkQGKrERZ#(m$8zt zZwzdS${`6nl&EPg3N!#Yb|z&5SxAJ*2hpOd?|kTwUZVMRU*nNJB;@qA`sLQTR6HTy zmfv=BtOCV$ZCjPv{{$D9Cty7U4eQLj5gP}IA9j%-$B-DmoWM?!;*Pq!1uC@JFvc>R z$6{72piUmQKb`tJ#5l^3-`X5^M#9=A&HTNFO4TIt9vz^1VVEi8b39&FV4wwv*kIXTbm7-p~id0{3N>UOcZ3Fe9K-D=d z-0ht3+U>c7P?#8gcU=i@={K}!)2Qy23@{b>Dr5U>t^BH|PY-QR2UIA7E zvH>ZSG5cngk0{*Ktw_>$8&JSNUiyYLySDwk!j=AG}#3J93&88Z8gK9gp8#M_a zyGaH>A##KHvXb0`#^-m%-l;}c4F<|1`IHn$%P)w?Bf>={JSe#~lJ=|WT=xOcW*UlUNAFpD*lAM;ER=!r%Vz$TKn=B{N!%jg9%_ ztl901tlYb&yL??b9RP+C4#3i(&5F`W-%}Mi=o0z{PjnOV>ug)pB)|11Md2F>lSfZw zk`Ac?6Z}sQv$v_>fPwIZP}5iWAtU|VZaC- zFT2D^f#mbV6EMTD+S8#1nq@2MX9x;f+Q)w{ihsJoFI{QT#le9|26;QM&;^Z?=E#mqfM zy=;7$vD~Ca3WjvHD~v&uHiJn<6CR~2jqI71F@Apu+?xc#o3?3~eDw8TlG05kh73y? zhA1utO2~!s0Que~c=(_lGH;^MnNKeTUFM>-ZTyj)0b#K8qNo3obUnlKH)DAe&{wn% zASSR=LE$Or+<=MKZUHb5d$S z_zGG8y|*>95VhL}1*!+UZfrdRK!lyw$qM_+nWZwf*V$g}_Ij|q6vaNrnxBL|4AQBR zyM4jWUVXu}*T4@zIBxdJc9grgK09DEQ`Zq4_!b#@FHD_0Pu$7F(l@Ct-))Q0_4Cta z5xIf_>5m>toCCzwmo%Ar$2{~>=Dxm#fi>$qDw^+67?Ur~R`Rxdoq(Rtb7_>p{<^#U zI&(fq{Kx5Vj3BnbNzIc$T&-9iy{6RQw@W9HSP;_1JFBD(M_$^ackl;mF^KQ=NhNBi ze3R^RY>>R0-x5zS2!k>^*+~7yDk7PxDE3#rd~an7##lI>mk#AaaQ^=OXG&fp4Q1SD z&aA}BriOO(mvC$3n`q?F*U=B`a1C>&ctq02YSq0FFKy2=bMNkHRNVOIwBcDxy3yD- z;~_)Y5_ijL-wu7UtZIKPQRJY_9b69kPD|7-_49~R0q;q10}=1gg8R+CM zxokWMRli7E*KtPfSY&IIskB+-6U_YM=aeh4C~awVSgO6%*>qB&=th78R?KaaMHp-h z$KBHc$+9%^?v5`yfAbClQYd7|TogTi>#+Zb{b0x(*~WZgN4f>Fd6bq&DCK8IBOX*> znT%@O9E7wo*YyWHv|v1GY^)CCe6$uTBGA)*ifi8;-Yg2~kjjw0zq0WpXoTK2Qg^T1 zm_;6^T@lGB?k-^1$EassDXEtY&%zATv@?uL6b?@vm#7^YbK>~MPCizN1M1;u1Ny1%Vjc(wf1qW|J%_1rCNm@sgYyaIqSc2Tr+oVl6`yrX#*}Uu# z#o^O~B;XKs`IQ5KFn6M@4ge800^*)G=Z#uU)UXcn`TzN7Rke{g}1a0*bi z=c%t);MqQU0ZZh}chdM<$$4QLx*0h)&%}T1O{vguDhh}g5h^q6L=N8yYuZ#szjoV` zUd*!peozZbSRkdHQuX5+H!rb}+%swu6VDp$`BsEp^4L%GPqa z%2e=E*W{2|^YZ8v$yHV&Yl&Y+-@jy>ti-2&Y@nYNU^s6)55Ne>f~ZN!F>zN06xi+! zz#}<8Aa-%|k~S2`Nja`Wn2%Ef0QC-Wa3Hn?UaKA2@+921FWe>ObKe%itFtqkAi_*@ z!XmE@)K|ceLzN4pX5l?Pd~BoE_%aoxtI-22vnJE*U&Yvy9e0=L1>9iFV%C?WU?fy??9Io&OI-~d`M0|NhJJh?b3qC0SMi{ z>o>zOLWMVzf%L-ln)T2Oa1vRc{q^|%-RAkrJ1#28W{x&x`^50?1v zFP*vgPw0Y94{S(?Gpz?!;@)1&_~r{=z>syL>>8dOB6@4(+T)qV6~l@oLiRlX?8Dm8)$X$2Afbys&mukeg+&i7JVd;3ym zG8v7)1A|cb6Z$J)qHhjk$-1XeD)v`L_Mq_(YGCo(UoMq6cwfko_}S+@5F(reS5J|^ zM-DkI|F16du_Hu8gGV68ng7F|&s_BV4?pn2=k#9!O;A5$ZjwtY{$KLN_hyP}RxG)h zu?d;fM+lnQzaQaW<>mjW&kZVV(>R~ecMt=KDdElk`C@*cCJ<38Vb^drU|lu@%`?xI)??_g42Fp_nY*;zktAs@RjZX2)zf}VI$WmKk0d5 z#1@b%B$TD7<6VK<+W5+NP1JC0^N%ik5_`*DIgwavPzFUPq0gMSgvlo`fFa!%(3?D-Tif#~E(B|`$1@QML#D$;hKt!EoLWN( zekcNcTs1vKlzpgMSee{8gQBbvOfCBoMh}Us)01l{#@2haNUiQe)dU5=KGWdMeXv{I zFOo2S036R&sjm^ozauC2=E4}o<9XX2u1?ghfRf9qRSJ`RH(Qk*mqz^w(7rU`N_8U= z=jB@Z0+_sB9nUjjaLY2$&A229XzrP?^`53h84B@%bC4W#-Fla()d%$&PvuEZ(3>BH zS2zbnV?d8PPqr@I0iOKK&dhW=``lgd$E?C-fzf}~$ea$H@ zGxh0@DAg);oRB&HV3qQ|fCBx)7U+E!Roy%eas8SK+|#-vd+qAf14)T7euPu3voML! z-=63<$1q@g2%Yi$vl8tgja!*d@pcBOgX{ETzS@mDec>KuUeVgCOFOiM*>&b+dg0i# zxeEiA6y;WzSQf$SQuL|=opaiXY|FETl#U7M>C>{v;PLo;CtbHITzLGBH@+JOs`fVX z(hr$~3B7rY2tL|lIj|f?O}xn7dQZvjm_s*vMZ&F{X8hvfNgFglTu}1!JT*ZyNze&k zpJ#gX3!zM2_G#yC;3^%WmYL51EZ=z+CENThZ`=}83Fr3#yGo!Gj+LHBnjhHQWEiZ$ z`tk*dl5=9IO(0do?PYmbA9OL=5rm z=j}TAgOS}AU_ka}U+mwO$=yV&eb<1#M1WoocGVKH*Is9P-b6);XQkeao7_ zK~ze)Rt5~S0kWm~7%E5HUZruvTnfr}9{k4ZNN**OQ63%8)&LX>nWtdh($@I*SZ+OMs>}YQ z*R5nSlAL>7)@M>Dv}+d(OcnK%t}KZ?EJM}nnhjR7?d)Rm@t$CDw;8w()nV&KRnSvp zXf2C+wmAf&D5J^YY74r+5%WQz(RzS~mD}wuK-+HMNS6&_AL&3DtU`=};>)KA zA%S{Cvky)jl+ z7ddpT)_i6#L*Bt}!BunT;b1~f$rVVBx5}R1!UOIzj9B4<`gF5l7kD}Sb6_|XVnCOr zm5Fa|&vVuiZ8lB9`pTDl@_SoXjQkFJX|C~JKgb)*6OV)2y4r5}p#d+35GOyHNvE%xad1$5ip+hCOIu}%a?k~ zJ3w5d+hTRzy?X}m?mRcPs+H2->;=adPJTKLx$s!8g!dti(uCPdH+W-GM_0z~{Fjic zo=~$=2_0V@{RR5`x&jIG-Lg}%%Wv~2#B(@50G$*zF6;=johI*ky_g*KX2fP2%d*3i z)zomWdl&nea%Oj^8Tl5OP}pxyI5>_z{)8gFo>$b>sS=waUsd({ydn;_bsY#zqIbw> z^nt6HY(EgTb7RK=*JsnG^uDJJM@;wGPOetdAEgj)*?c7r-=c02l9pculNAe<*9T{( zpik)Zig{Dt`UaI3UK?>90LUN;#M@igoZc1ppU;StPCQ4h#Wx%!z0}K3E#tj}tw^BN zMUpS^c<_|r32KnYZKQ|P!(OqFJ@hMPkr);76N91NkITY5F%%4wEC&nBga5AV$=oDC z7M?LqDz%b2nslU^AZmHNTT%_B@?9uikbULl|~K-D=SXxVrZ7Y zoNjg8_iI<5^IGl_8rhCg`61de6@81&a!cIRMCHB5P$Y#j_mkNu_l{MjVagqtc?T2( z!{Zp?_bH?-T*MDHq@^Ef=_v_grPPZBspHjXVXgB)A-3cKtX9YewSL8N`8XTDFf%AQ z>PF1T0e-%+;ys^RgpjtWo_Us1rZ5nr!Za8J-_gVmxV3pvW6du2d7GHQFoYH;wqR6% zN0+dcVy?8LuXK$yq;l#s!-B*q>o;3zw6o=K~uGYh`k((*VLE#yW^=#`!UQ9?$ z6F1P!KA6rjRiQQ+lQ>1haK{o-DK_18lA`*l=MlQdhN=8NbbRKmuv*PY*le#XefLF3k2?PNb2(~30{362I(4uq zKh1ea@dhGoREfIPc|x7Aog*(6&JFjOdtSb{v8`3{_0fQiYe;_2_d06g<HqntABoRLYGH_l54fs?y!)4)!`wmFem*?2w0L3Ljz2m`p=-F_(;>%D zVwza6^xHp=%!gg*8rrk^;q~R$9h*C0?*fiKIgt@UoaJF}JE20KlQJ)mVlBJu#M+jK zAmKpiqn?lMW{O&`PZEE+?$NBmS1{-%oY+X#))1eNa3it60sp+w;v-p>Kvyc{k#vYupT1ND60>O%g}Bb@ zudzBWED-BO?V0X_LMF3Rk&07eX4qvy&M1g}c`uw+B@Tfv>?xsdmqKK1@@o}8z@6i% zshbXY$zq&yuB2{}D(ay~tT;%NLrc#t)|Zr`9*>sush&dM2$Isu)~?avE2WGlO%&a? zos7WdF7RqB=YMZcjW*YXUD%vt@k~|RIs3?*lEC@^he+@MowXQY6`#fw8z}-5Q*qPp znfg4}57epPzEJdb(2TStK5mnDYOZ@(jklabq;`$_LvVt)_$#B+mfSiYJ68k~H{;Y(J(;zKULJYoHN+y*@UAh1+qz?|9WUY=Yr&l9wUh z6ZuR`!Q>neb+QVF@5e4JGC4;%s7SdsLf*Zgx84i;*B%}3Q7d@v9tnE4Pkz#X znCPB@cP2NM^@j5bg~R%SIAlcFql*VSj~Y!EmE>B~#wT4BLWgdWbxq0Ha2FL;HgT`R zbKR0km={=hxT{;g?X#+m!2tJ|H<^M_>=h^(aj8J0$*Gono0r8JE)Y7}dkwss9Y9LT zTsU-i(=fDp4X}9uoJ8SYTJUKjgH`YS2=6Q`-p7*GR7b-ym6f(U7(I+_+UU_bd93qN6SVX!h2d9&9)F- z+KR)5NU+-FO*)laLpbnW*0Xt2@=IH@7(-t`u>ARS`=RP);rd}X=1b}7OtYZ@tmoXJ5SKjUzpEooM<=>{L%8qH00go48y@IGB70$$6h_`jny;B?tA+aF_ z&=U9;)Ygzs-7?-V^>$^AW#16#50AV9km7Az0sb(2nva)CKxD?k+x~&D#P!wJYABZC z?$AVNN79WtXQ!bgQE`-i0I>nIHW5ccUK0^Tweo%gA}nD)!oWCo7phjf>v;rzsY(Sl z!jSUHNtvvFWuy0ju>Hek9-hwXpy@{V_YbCXyFQ322e_loBxWvGFV5vIl?et`3^(ci z{DyAFWVDl-CgRTIWbUN=*w=4C3uD0uzje$SMNMxT1dL>Mtg71`c_3V=O%X%m*x1rM zUZpI>Fvu4<&zoqMp+Ia{zv+3uHT1b!b(|djE~fkT&=SmaEU8{>^hc+de6YbXg7V=dE$1rUt`9~*sPpzLb7O-e$3K* z*R=U-gWZ?f4$5!m#}}y@;kMzZ%01DCrX4D`yN9~7Ggex^Ds7qLVjJ9NKd<#Y6Ls0p z-dc)y3wJ)W?_f5|c|h7eKugbeJS=t9syIhc)t0~bEZrdKw!HPpr16od5yZ9wT!%W2 zM2j;PS|yO&5i#Oo+SjRozTe5C8eY=?U7GBbGZ25gS$sko_s+&~fI-olJVV1bWY5n6 z)~3P``x!ai{F=2wO_*0?XZ&04;FcBHUAVQkL(*g7JEXd5lOW3|zvlo=aES_7O2I>M z>4K$7kFS3GN2w;XXl@QKR_ETJr-t9dHszxqBs?S#~@ zE#5g)qo9^m-aT+#fPd98GS(#C=FUg#*gsDnj;~0H*U0OXpL%whi`d?lb@o1POc;`w z=uKSf(0wX}?-B_$AH7;vP@9`78SVUgtecbCy1_`jHeMHjb(owALg4K*@mfCW;;A}Pih~>eRA#JHYyMA#xbbznv&x`O^iKN z_C~dZ;ou(V-7>@1Uf*1tF{F_`=5tznBQfUVkHpQ^hna<^RHSVR43cdFqC)y`@a0_( z2LbR%V0*?mX$wot`)=NgjmY3evX9Ym-%R06Id7^((DGYD6@pjGxz@Di#y&hSl-;bE znlv{s8GVnnr*iNy*E?S3Jo~w?jE*kH+iUAh!n?6bF;)4ZM96i7NW46COSTp#lIe!f z;zL+%^$VN{Mp`JM@J!Iev67j|p4`PjTxI#p95sqM_w6QIPd~g_zk7GUR}^PHDxZ{! zW<8$9^3sTW^9!sgp6=_~b5U>08w^dtsMqg$yXlxooOtQ!i&NCllKQCnfG)OqEFxn> z@R+|Bbb0jpG6%1q+UGWl=EnRxCEWIJCQ{grb1I;aA|AlQNnxK(=5_!{{WLgyTh&oR z+E!kR38`eMs13HlkSQyb9HGM4*j&VrRR*PDorePdiBAxH%T-PLz9)yL+JUv2h|bo; znarA4ZuY*6{APINx)r=0W^}tK>{Y&?(JD=0u>)Em3i(t4yR`I4yLkQ`hs|Ab4p#1^ zS&U6SS*~I3>fLMDYimd6u$x+bbE%@NRSSlvtu$}Da&Pnvpd=>Lx5kf39Y1#nG9nJC z@wX@<;6OaI&>~fbJ&}HQSufxJZt{)j%Sv`BWu;brra6HsA>+9C0&D8`saKD z_H3_f@B5sos~!M`2Mo9S4c0>3*B6gS4vBr^_t6|R4dmP=Pi=&qH5C9TXyD+ilMqFb>F{L8jZ0`5&>Fx zs;qB23dqo;FU3~z!Fwz1QsOUUpV_*`A|V1(yj{%uc15Wkz>VkOdM;FKknfp*%iU`M zceEm6(B+@%OvAEAFlxg+$Hr~)9gt{Aw~5YPDh&`q&U-K;eqJLuh)+0W$& zC4ZRsHa5GTawC6zO2`{;`aDl{c-RS&LlW5mbv6%Qb`%Zpa_PrRM(lGLi7rurL-sNW zHyr-O7Hb>ZT%U4zT+(Z{{+nSDna=~d zCvJS<$z*_xT)@PRx#tTaE#7;%>`G&A#zb#ynhcJsi&V46ux3n*J)sO2JWV0@9eqIx*~1M{mbTjts&yiCyd+ep`7e`#Yi_Z0yPo&j$HgEwrkgP-nz{7W z+dG_wlm4v@?o0{w*OvBfyz9r=e|^4Vb^gE*bM_GER+y!grz-U)sFj6gdE0`cv2@Dv zDvclW_JHsWl&ae8%Al*+;Wao~{`8QV4W*Br+h40i?bQW_3b&8J7^NSd4tlfwIK*Q6COiv4Pml!=ao5d(kdhdD5y|U zG(_0V5mWwUP{SuWVSd}L=i@OQ z>+gw*b2gE!)?pLKR}hlB)@;*t{4RTAd6i?{maietO8KR2(1l&Feq*?F4N+)&!%IDp zZ@41y{0s`1?8hG2rvZUw%p{>%j>dbLUBRAN7dVJRI{Zl0rMdV>iiaa7DP!VY5+@2G zeAc5D6Y~CB3jho8?~`y(?+p2cy6u0Ve-SMNX|ZT5)u6p17r7 zUt_(pZs8$^yp}=;T4I?)__JM88jqr+Z#>wQoE!#42N0sRogy?XwnrH97k>HBUMxA z$eE6(YxuRHJCo@Ra-sCRBvxg;0W|^RReo3reNXb|)ww!HmWKYxjoT2K@c?#_)eAB2 zJ>Ldx2XKrTnAQ&;Gd|6Ab9VMVxv(5LN)ondCAu@dsQDQN-jmoTqxr7Z`B>hts;5}2 z@bXhOg|2F4u@{61Pi*S+EQxHeB!wfQ;f#=gm3Dw;T- z!2A3`#x|DivbNk%d)8ntU3Ds5+$;OH>&kF5x8BaqM3-y@;_Nmt9ugC+fFXoi>b9Ng2>r1ABTwwymu(f2|1LN+Wy^y4trEnNSaKk`x*x-jnO{ zyEL0G=L~TH~KXI?Gw4Xa5Illz3 zS%dY7VQTI9)+N~$p4-*ThKYlGVRJQ?>>};awAMzgW@#aHjsnp2m`~VaqXVwf>2@&e z*jEUhM&*}>-36+qHoZK}A#NF(MV&RIp{>ZlRr#(Kd5)n9FQ?HYi88L^Hm!Tp@Gp0o zVSN&##qOW9Y}PmX=ZPsO3abh$o!M(`$t8E{9|%tkPa@=mqi?;V>l0pR?&>TIu53PL z=P{FNcr##WLDX@y^Xv#B#$qQ>D(CoYw9i}kt~bWS1^ zD#C*x4l!qM#*Tf2r@M|4Y%c*{z{PHt_5S30ZL z%{j+`ZERwJp&`%uV#zdoqXJu(vyxu1H8kv2Ro6AyGX5;dd#tAC*~<{Go_C@b2~Q)d!zi=&DV}g(pciLK=IC6 zsy>Icc#=CR$u9k|bMVAFQe(E{!)`XCN%dF96FG$;3Mnr0+2(YtGl!O|pf@@zZwsU+JJHR{9_C_{)mnenZ zvSc8Yu1!gzSSuFd`SX1wkv|yrnIKh|d+i|3Ab3q+QKa5c-+o>oUX@k$w8$Hy(?04_ zz>%Bk8A-6?b-}P{L?-JgmlXyl>R9+$A3u=yO0y7qi@Wnu`h;emV?9Vc4!-aD^*L;$ zhEGKA>7`U5Co$bgFxu|exojcHDftr}EysJ5L1HVdooo0Jo22L9U>*>a%d+S4h0g_1 z?geqh^j#KqTu!VhT@Ww4aB%*y6T0=n37;mh<3)xo6#aPjHUn?1z}TFgcs^wb)$N3T~BRk8^m#c(4vP z4uf=}s_IHr8;Bb(k5Cy_W{v1LM!5&JrnO;54-wr2U^ctf*z&3slRbh1Pv>m@FlG!9 z_`|dNz_WF3E;9ICQHQXF^#_qdMDBFJ3rGQGC**dqJ?`5y-1U1UoigL7z_6>uU)H-n zds_d0Ad#rctyC`+m7htkS90gycbEL%kSBh*PyV0zyw#74+8y951jn+!pWhD#389_n z^B)Kv|8R*g{@W&j3fLsX{%RZj`%BYKZvggficA1`6}6FTT2GY}8b@I2qd5m8jXb`| zRXpBWnQhg z?mOMiD+NI0oCJ1UE`%D#@IZz~WoLF9c=SI#LNW$?a)x9-8ZStaVDZ_>+U z%ubd4QNGEzP_@0y!=b=>u%iB*#GWIbkE<%D`T6{a!VoMCdcy z4Us9HBv_&5{kn};@K&j|IwZV?XIsC6Fh{OkqE_hgrHx{vSfvxRU{6sxQz{*2&fJ<# z8Ae9??71r?Y`^^U>61L$?rrSl{{H@;-Rp-eyi>7fdXC<|eK;&Uye5iM zt-80jcg9(D7P#`YHmJzke+A+L2SCi9izoAa;X^_}u$AcW1ZoSb54yKAbL-#X_jXny z6c`_w;`eZEkFf=H8GGM=NU#PF8b(5&KWAHA+}!|;vl^hnd-tt2*2w+xB2+@JzCC{n zg98K!iN#p?d`ynFWtddxGfm)`76~j00%qoc@SsH;xFoi9r+`_AYe^UQAvvD?7VSXg zZ@R-Z`9oU}wdIuT1ttTI0anWlfe$m|2~%i!HmLIaO|m|$rKOlp4s&kkGN6?0^W485 zF6saTP)o;DpmSb*cN)iI3yAr}+X*+%sMm9zit^FTI4Mjx9to6{tIQvO8-y_{G0$_r zT4|FCz26UO!U_wytK+5!h73nn38tVvnQPE|3dIk(g`s+dF&lJg-M8eu{wtk;;CGQZ zc^o4L8m{~UBnX4EhT$WDKu=JFy0w1QvfeL@BD8X&qHq=H0uU;mlJYvQ(~%mF7aZ!u z2EXM9t;HT9(tP@BzkpUvP~AHXZ}&;l)IE%i=pOJ~rLCaio?2+^B*g1K0sz6p1sJ5Y zNg=A_%bGG@$!|V7nuL`~rXLX5ctR0s@liTuP*E5|k^*c3*_ZAxouZ+ma{yExqdq7n z2gg``ab2~1-ZtTCk3({*pTnT*fe@8^u3jkdewuA7-ZZNdj1Y}h-icB z&%Pmc+!pN8xv)(c@`=MguV8-+Mng-i512w!x)hFDS3oY}#2`6Np4+prZQZ&bGG7jH z2buNp$|ALBtVL16?t$%qfckPnBV!z6?MvT*g;!1{wKuRJd%NS2J#(}tGa}NxaNxH^ ze*bo~Pc_f02%ieqAAA&oRGgp*1l$QI`HAtE9Uv4E#0Hzjhw`dRTCkJg^vzAaueJBM zBO~0UJvG81ZYy2%u|D^k+2{ANm{cUr2AlZX^*+gq1W9N)eJfrV;g7Dr)#%>voD)x?l|V9 z2Kg-`RON;SZYhmr&ppIip(P8RG30fGXzavqz#T|MP~XbF=!^YWXvQp8!2pc!zCaz2 zcAi!|XPZQjA`N&c=7lemn;KS{PJQHN3e`C|FDkH>oOwk+Ph*F9R9EfOOlsyV!7GIx zDv<|leAiQ~hV)HEMZ(x+5R*hi6^Hk`XZzj+?NZF2r~wjd_&S>+Amc=Y&$*xUK0@RB zfUc!-n>^1DG_SllGrD#iBX_0)Mu2mK&%EoafTpzH99YxD^meZ2`~FV!DP9h-rIsB(lvY#J=7%83#_t zi#7RYbqN=aY9Uyp)e%^T*~&JVV1WQlLnJIGadYMYgTonL_ZO{`fZZiqhPrWL7}@3Q zxSN{@gj=?ywLsc%4YH!C2F8D|?4#%4Gy@NHThtP)*q>YX;JgGB;{P%~W}n}Cz??f6 z9PyWd_W$Rf9}KSeW9uE@SNn4z{&o8QBt-u@j(^%o?aO2jh|7Q8*#EOHcE7QOKh$*_ VhbzXnV+kd`lANk+k@Wp%{|iiQX0HGM literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-10-enterprise-subscription-activation.md b/windows/deployment/windows-10-enterprise-subscription-activation.md index e57c8a14cc..4d7e530d66 100644 --- a/windows/deployment/windows-10-enterprise-subscription-activation.md +++ b/windows/deployment/windows-10-enterprise-subscription-activation.md @@ -1,6 +1,6 @@ --- title: Windows 10 Subscription Activation -description: How to enable Windows 10 Enterprise E3 and E5 subscriptions +description: How to dynamically enable Windows 10 Enterprise or Educations subscriptions keywords: upgrade, update, task sequence, deploy ms.prod: w10 ms.mktglfcycl: deploy @@ -16,7 +16,15 @@ ms.topic: article # Windows 10 Subscription Activation -With Windows 10 version 1703 (also known as the Creator’s Update), both Windows 10 Enterprise E3 and Windows 10 Enterprise E5 are available as online services via subscription. Deploying [Windows 10 Enterprise](planning/windows-10-enterprise-faq-itpro.md) in your organization can now be accomplished with no keys and no reboots. +Starting with Windows 10, version 1703, Windows 10 Pro supports the Subscription Activation feature, enabling users to “step-up” from Windows 10 Pro to **Windows 10 Enterprise** automatically if they are subscribed to Windows 10 Enterprise E3 or E5 via the CSP program. + +With Windows 10, version 1903, the Subscription Activation feature also supports the ability to step-up from Windows 10 Pro for Education to the Enterprise grade edition for educational institutions – **Windows 10 Education**. + +The Subscription Activation feature eliminates the need to manually deploy Windows 10 Enterprise or Education images on each target device, then later standing up on-prem key management services such as KMS or MAK based activation, entering GVLKs, and subsequently rebooting client devices. + +## Subscription Activation for Windows 10 Enterprise + +With Windows 10 version 1703, both Windows 10 Enterprise E3 and Windows 10 Enterprise E5 are available as online services via subscription. Deploying [Windows 10 Enterprise](planning/windows-10-enterprise-faq-itpro.md) in your organization can now be accomplished with no keys and no reboots. If you are running Windows 10 version 1703 or later: @@ -25,11 +33,16 @@ With Windows 10 version 1703 (also known as the Creator’s Update), both Window Organizations that have an Enterprise agreement can also benefit from the new service, using traditional Active Directory-joined devices. In this scenario, the Active Directory user that signs in on their device must be synchronized with Azure AD using [Azure AD Connect Sync](https://docs.microsoft.com/azure/active-directory/connect/active-directory-aadconnectsync-whatis). -See the following topics in this article: +## Subscription Activation for Windows 10 Education + +Subscription Activation for Education works the same as the Enterprise version, but in order to use Subscription Activation for Education, you must have a device running Windows 10 Pro for Education, version 1903 or later. For more information, see the [requirements](#windows-10-education-requirements) section. + +## In this article + - [Inherited Activation](#inherited-activation): Description of a new feature available in Windows 10, version 1803 and later. - [The evolution of Windows 10 deployment](#the-evolution-of-deployment): A short history of Windows deployment. -- [Requirements](#requirements): Prerequisites to use the Windows 10 Enterprise subscription model. -- [Benefits](#benefits): Advantages of Windows 10 Enterprise + subscription-based licensing. +- [Requirements](#requirements): Prerequisites to use the Windows 10 Subscription Activation model. +- [Benefits](#benefits): Advantages of Windows 10 subscription-based licensing. - [How it works](#how-it-works): A summary of the subscription-based licensing option. - [Virtual Desktop Access (VDA)](#virtual-desktop-access-vda): Enable Windows 10 Subscription Activation for VMs in the cloud. @@ -56,11 +69,14 @@ The following figure illustrates how deploying Windows 10 has evolved with each - **Windows 10 1507** added the ability to install a new product key using a provisioning package or using MDM to change the SKU.  This required a reboot, which would install the new OS components, and took several minutes to complete. However, it was a lot quicker than in-place upgrade.
- **Windows 10 1607** made a big leap forward. Now you can just change the product key and the SKU instantly changes from Windows 10 Pro to Windows 10 Enterprise.  In addition to provisioning packages and MDM, you can just inject a key using SLMGR.VBS (which injects the key into WMI), so it became trivial to do this using a command line.
- **Windows 10 1703** made this “step-up” from Windows 10 Pro to Windows 10 Enterprise automatic for those that subscribed to Windows 10 Enterprise E3 or E5 via the CSP program.
-- **Windows 10 1709** adds support for Windows 10 Subscription Activation, very similar to the CSP support but for large enterprises, enabling the use of Azure AD for assigning licenses to users. When those users sign in on an AD or Azure AD-joined machine, it automatically steps up from Windows 10 Pro to Windows 10 Enterprise. -- **Windows 10 1803** updates Windows 10 Subscription Activation to enable pulling activation keys directly from firmware for devices that support firmware-embedded keys. It is no longer necessary to run a script to perform the activation step on Windows 10 Pro prior to activating Enterprise. For virtual machines and hosts running Windows 10, version 1803 [Inherited Activation](#inherited-activation) is also enabled. +- **Windows 10 1709** adds support for Windows 10 Subscription Activation, very similar to the CSP support but for large enterprises, enabling the use of Azure AD for assigning licenses to users. When those users sign in on an AD or Azure AD-joined machine, it automatically steps up from Windows 10 Pro to Windows 10 Enterprise.
+- **Windows 10 1803** updates Windows 10 Subscription Activation to enable pulling activation keys directly from firmware for devices that support firmware-embedded keys. It is no longer necessary to run a script to perform the activation step on Windows 10 Pro prior to activating Enterprise. For virtual machines and hosts running Windows 10, version 1803 [Inherited Activation](#inherited-activation) is also enabled.
+- **Windows 10 1903** updates Windows 10 Subscription Activation to enable step up from Windows 10 Pro to Windows 10 Education. ## Requirements +### Windows 10 Enterprise requirements + For Microsoft customers with Enterprise Agreements (EA) or Microsoft Products & Services Agreements (MPSA), you must have the following: - Windows 10 (Pro or Enterprise) version 1703 or later installed on the devices to be upgraded. @@ -74,25 +90,47 @@ For Microsoft customers that do not have EA or MPSA, you can obtain Windows 10 E If devices are running Windows 7 or Windows 8.1, see [New Windows 10 upgrade benefits for Windows Cloud Subscriptions in CSP](https://blogs.windows.com/business/2017/01/19/new-windows-10-upgrade-benefits-windows-cloud-subscriptions-csp/) +### Windows 10 Education requirements + +1. A device with Windows 10 Pro for Education edition, version 1903 or later with a Pro for Education product key in firmware. Note: If the device comes pre-installed with Pro for Education from an OEM, it will have the correct key in firmware. +2. The Education tenant must have an active subscription to Microsoft 365 or a traditional Windows 10 Enterprise subscription. +3. Devices must be Azure AD-joined or Hybrid Azure AD joined. Workgroup-joined or Azure AD registered devices are not supported. + +>If Windows Pro is converted to Windows 10 Pro for Education [using benefits available in Store for Education](https://docs.microsoft.com/education/windows/change-to-pro-education#change-using-microsoft-store-for-education), then the feature will not work. You will need to re-image the device using a Windows 10 Pro for Education edition. + + ## Benefits -With Windows 10 Enterprise, businesses can benefit from enterprise-level security and control. Previously, only organizations with a Microsoft Volume Licensing Agreement could deploy Windows 10 Enterprise E3 or E5 to their users. Now, with Windows 10 Enterprise E3 and E5 being available as a true online service, it is available in every channel thus allowing all organizations to take advantage of enterprise grade Windows 10 features. To compare Windows 10 editions and review pricing, see the following: +With Windows 10 Enterprise or Windows 10 Education, businesses can benefit from enterprise-level security and control. Previously, only organizations with a Microsoft Volume Licensing Agreement could deploy Windows 10 Education or Windows 10 Enterprise E3 or E5 to their users. Now, with Windows 10 Enterprise E3 and E5 being available as a true online service, it is available in every channel thus allowing all organizations to take advantage of enterprise grade Windows 10 features. To compare Windows 10 editions and review pricing, see the following: - [Compare Windows 10 editions](https://www.microsoft.com/en-us/windowsforbusiness/compare) - [Enterprise Mobility + Security Pricing Options](https://www.microsoft.com/en-us/cloud-platform/enterprise-mobility-security-pricing) You can benefit by moving to Windows as an online service in the following ways: -1. Licenses for Windows 10 Enterprise are checked based on Azure Active Directory (Azure AD) credentials, so now businesses have a systematic way to assign licenses to end users and groups in their organization. +1. Licenses for Windows 10 Enterprise and Education are checked based on Azure Active Directory (Azure AD) credentials, so now businesses have a systematic way to assign licenses to end users and groups in their organization. 2. User logon triggers a silent edition upgrade, with no reboot required 3. Support for mobile worker/BYOD activation; transition away from on-prem KMS and MAK keys. -4. Compliance support via seat assignment. +4. Compliance support via seat assignment. +5. Licenses can be updated to different users dynamically, enabling you to optimize your licensing investment against changing needs. ## How it works -When a licensed user signs in to a device that meets requirements using the Azure AD credentials associated with a Windows 10 Enterprise E3 or E5 license, the operating system turns from Windows 10 Pro to Windows 10 Enterprise and all the appropriate Windows 10 Enterprise features are unlocked. When a user’s subscription expires or is transferred to another user, the Windows 10 Enterprise device reverts seamlessly to Windows 10 Pro edition, after a grace period of up to 90 days. +The device is AAD joined from Settings > Accounts > Access work or school. -Devices currently running Windows 10 Pro, version 1703 or later can get Windows 10 Enterprise Semi-Annual Channel on up to five devices for each user covered by the license. This benefit does not include Long Term Servicing Channel. +The IT administrator assigns Windows 10 Enterprise to a user. See the following figure. + +![Windows 10 Enterprise](images/ent.png) + +When a licensed user signs in to a device that meets requirements using their Azure AD credentials, the operating system turns from Windows 10 Pro to Windows 10 Enterprise and all the appropriate Windows 10 Enterprise/Education features are unlocked. When a user’s subscription expires or is transferred to another user, the device reverts seamlessly to Windows 10 Pro edition, after a grace period of up to 90 days. + +Devices running Windows 10 Pro, version 1703 (Enterprise) or version 1903 (Education) or later can get Windows 10 Enterprise/Education Semi-Annual Channel on up to five devices for each user covered by the license. This benefit does not include Long Term Servicing Channel. + +The following figures summarize how the Subscription Activation model works: + +![1703](images/before.png) + +![1903](images/after.png) ### Scenarios @@ -126,7 +164,7 @@ The following policies apply to acquisition and renewal of licenses on devices: - If five devices are already on the list and a subscribed user signs in on a sixth device, then this new device is added to the end of the list and the first device is removed. - Devices that are removed from the list will cease trying to acquire a license and revert to Windows 10 Pro when the grace period expires. -Licenses can also be reallocated from one user to another user, allowing you to optimize your licensing investment against changing needs. +Licenses can be reallocated from one user to another user, allowing you to optimize your licensing investment against changing needs. When you have the required Azure AD subscription, group-based licensing is the preferred method to assign Enterprise E3 and E5 licenses to users. For more information, see [Group-based licensing basics in Azure AD](https://docs.microsoft.com/azure/active-directory/active-directory-licensing-whatis-azure-portal). From 5707a133aefb9336a584e9582c92e0e1458735a6 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 8 May 2019 14:15:06 -0700 Subject: [PATCH 226/737] draft2 --- .openpublishing.redirection.json | 11 ++++++++--- ...ation.md => windows-10-subscription-activation.md} | 0 2 files changed, 8 insertions(+), 3 deletions(-) rename windows/deployment/{windows-10-enterprise-subscription-activation.md => windows-10-subscription-activation.md} (100%) diff --git a/.openpublishing.redirection.json b/.openpublishing.redirection.json index 7a179df68a..d414deb585 100644 --- a/.openpublishing.redirection.json +++ b/.openpublishing.redirection.json @@ -13950,9 +13950,14 @@ "redirect_document_id": true }, { - "source_path": "windows/hub/release-information.md", - "redirect_url": "/windows/release-information", - "redirect_document_id": true +"source_path": "windows/windows/deployment/windows-10-enterprise-subscription-activation.md", +"redirect_url": "/windows/windows/deployment/windows-10-subscription-activation", +"redirect_document_id": true +}, +{ +"source_path": "windows/hub/release-information.md", +"redirect_url": "/windows/release-information", +"redirect_document_id": true } ] } diff --git a/windows/deployment/windows-10-enterprise-subscription-activation.md b/windows/deployment/windows-10-subscription-activation.md similarity index 100% rename from windows/deployment/windows-10-enterprise-subscription-activation.md rename to windows/deployment/windows-10-subscription-activation.md From cbc377b5477ab593779069bee6599d7b170bbc1f Mon Sep 17 00:00:00 2001 From: Max Velitchko Date: Wed, 8 May 2019 15:22:55 -0700 Subject: [PATCH 227/737] wdavconfig.py => mdatp --health --- ...osoft-defender-atp-mac-install-manually.md | 9 +++----- ...soft-defender-atp-mac-install-with-jamf.md | 21 +++++++++++-------- 2 files changed, 15 insertions(+), 15 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-manually.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-manually.md index 82e53c1ff4..1d6f73f280 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-manually.md +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-manually.md @@ -90,9 +90,7 @@ The installation will proceed. The client machine is not associated with orgId. Note that the orgid is blank. ```bash - mavel-mojave:wdavconfig testuser$ sudo /Library/Extensions/wdavkext.kext/Contents/Resources/Tools/wdavconfig.py - uuid : 69EDB575-22E1-53E1-83B8-2E1AB1E410A6 - orgid : + mavel-mojave:wdavconfig testuser$ mdatp --health orgId ``` 2. Install the configuration file on a client machine: @@ -105,9 +103,8 @@ The installation will proceed. 3. Verify that the machine is now associated with orgId: ```bash - mavel-mojave:wdavconfig testuser$ sudo /Library/Extensions/wdavkext.kext/Contents/Resources/Tools/wdavconfig.py - uuid : 69EDB575-22E1-53E1-83B8-2E1AB1E410A6 - orgid : E6875323-A6C0-4C60-87AD-114BBE7439B8 + mavel-mojave:wdavconfig testuser$ mdatp --health orgId + E6875323-A6C0-4C60-87AD-114BBE7439B8 ``` After installation, you'll see the Microsoft Defender icon in the macOS status bar in the top-right corner. diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-jamf.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-jamf.md index b2df2ab85f..516c62e45a 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-jamf.md +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-jamf.md @@ -178,26 +178,29 @@ Thu Feb 21 11:17:23 mavel-mojave jamf[8051]: No patch policies were found. You can also check the onboarding status: ```bash -mavel-mojave:~ testuser$ sudo /Library/Extensions/wdavkext.kext/Contents/Resources/Tools/wdavconfig.py -uuid : 69EDB575-22E1-53E1-83B8-2E1AB1E410A6 -orgid : 79109c9d-83bb-4f3e-9152-8d75ee59ae22 -orgid managed : 79109c9d-83bb-4f3e-9152-8d75ee59ae22 -orgid effective : 79109c9d-83bb-4f3e-9152-8d75ee59ae22 +mavel-mojave:~ testuser$ mdatp --health +... +licensed : true +orgId : "4751b7d4-ea75-4e8f-a1f5-6d640c65bc45" +... ``` -- **orgid/orgid managed**: This is the Microsoft Defender ATP org id specified in the configuration profile. If this value is blank, then the Configuration Profile was not properly set. +- **licensed**: This is a confirmation that the machine is licensed for ATP. -- **orgid effective**: This is the Microsoft Defender ATP org id currently in use. If it does not match the value in the Configuration Profile, then the configuration has not been refreshed. +- **orgid**: Your ATP org id, it will be the same for your organization. ## Check onboarding status You can check that machines are correctly onboarded by creating a script. For example, the following script checks that enrolled machines are onboarded: ```bash -sudo /Library/Extensions/wdavkext.kext/Contents/Resources/Tools/wdavconfig.py | grep -E 'orgid effective : [-a-zA-Z0-9]+' +mdatp --health healthy ``` -This script returns 0 if Microsoft Defender ATP is registered with the Windows Defender ATP service, and another exit code if it is not installed or registered. +This script returns: +- 0 if Microsoft Defender ATP is registered with the Windows Defender ATP service +- 1 if the machine is not onboarded +- 3 if the connection to the daemon cannot be established (daemon is not running) ## Test alert From b5b1054f90012af983fd4bdc2c2f2ac56a70351b Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 8 May 2019 15:59:45 -0700 Subject: [PATCH 228/737] draft --- windows/deployment/planning/windows-10-1903-removed-features.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 262f6dcd60..c7352cabdb 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -24,6 +24,7 @@ The following features and functionalities are removed from the installed produc |Feature |Status|Details| |-----------|--------------------|--------- |Cortana will be removed from Windows 10 in all non-English/US markets. Cortana will still be available for en-us markets. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| +|Cortana on Android is removing all Cortana cross-device functionality from it's application in November. |Removed |This will remove all of the mirrored notifications and Cortana natural language skills for texting or calling a mobile device and finding their phone. The **Your Phone** applicaiton on PC is offering a partial replacement for text notifications from Android phones but not the full spectrum of features. | |XDDM-based Remote Desktop driver|Removed|The default driver for remote desktop was switched to the IDD for a single-user scenarios. We plan to use IDD as default for all use cases and anounce deprecation of XP Display Driver Model (XDDM) based RD fdriver| |Desktop messaging app doesn't offer messages sync |Removed|The messaging app on Desktop has a sync feature that can be used to sync SMS text messages received from Windows Mobile and keep a copy of them on the Desktop. We will be removing the messaging app from Desktop devices in a future release. When sync is removed, you will only be able to access messages from the device that received the message.| |Print 3D app|Removed|The Print 3D app will no longer be installed automatically in a future release of Windows. It will remain available for download from the Store. To 3D print objects on a new Windows devices, you must first install the app (1P or 3P app) from the Store.| From 02cf000a1873bffabe092ddabdbc4e3d240fb579 Mon Sep 17 00:00:00 2001 From: Max Velitchko Date: Wed, 8 May 2019 16:59:26 -0700 Subject: [PATCH 229/737] Adding page for other MDM solutions --- ...defender-atp-mac-install-with-other-mdm.md | 82 +++++++++++++++++++ .../microsoft-defender-atp-mac.md | 1 + 2 files changed, 83 insertions(+) create mode 100644 windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-other-mdm.md diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-other-mdm.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-other-mdm.md new file mode 100644 index 0000000000..ec7b8d74f1 --- /dev/null +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-install-with-other-mdm.md @@ -0,0 +1,82 @@ +--- +title: Installing Microsoft Defender ATP for Mac with different MDM product +description: Describes how to install Microsoft Defender ATP for Mac, using an unsupported MDM solution. +keywords: microsoft, defender, atp, mac, installation, deploy, macos, mojave, high sierra, sierra +search.product: eADQiWindows 10XVcnh +search.appverid: #met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: mavel +author: maximvelichko +ms.localizationpriority: #medium +manager: dansimp +audience: ITPro +ms.collection: M365-security-compliance +ms.topic: #conceptual +--- + +# Deployment with a different MDM system + +**Applies to:** + +[Windows Defender Advanced Threat Protection (Windows Defender ATP) for Mac](https://go.microsoft.com/fwlink/p/?linkid=???To-Add???) + +>[!IMPORTANT] +>Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. + +This topic describes how to install Microsoft Defender ATP for Mac. It supports the preview program and the information here is subject to change. +Microsoft Defender ATP for Mac is not yet widely available, and this topic only applies to enterprise customers who have been accepted into the preview program. + +## Prerequisites and system requirements + +Before you get started, please see [the main Microsoft Defender ATP for Mac page]((microsoft-defender-atp.md)) for a description of prerequisites and system requirements for the current software version. + +## Approach + +Your organization may use one of existing MDM solutions that we do not officially support. +It does not mean that Defender will not work with it. +It means that provide support for deployment/management with this MDM solution. + +However, Defender does not depend on any vendor-specific features, and can be used with any MDM solution that supports the following features (practically any modern MDM solution would support them): + +- Deployment a macOS .pkg to managed machines. +- Deployment macOS system configuration profiles to managed machines. +- Running an arbitrary admin-configured tool/script on managed machines. + +You can deploy Defender without the last requirement, however: + +- You won't be able to collect status in a centralized way +- If you decide to uninstall Defender, you'll need to logon to the client machine locally as an administrator + +## Deployment + +Most of MDM solution use the same model for managing macOS machines, with similar terminology. +Use [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf.md) as a template. + +### Package + +Configure deployment of a [required application package](microsoft-defender-atp-mac-install-with-jamf.md#package), +using Installation package (wdav.pkg) downloaded from [ATP](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages). + +Your MDM solution can allow you uploading an arbitrary application package, or require you to wrap it into a custom package first. + +### License settings + +Setup [a system configuration profile](microsoft-defender-atp-mac-install-with-jamf.md#configuration-profile). +Your MDM product may call it something like "Custom Settings Profile" (as Defender is not a part of macOS). + +Use jamf/WindowsDefenderATPOnboarding.plist extracted from an onboarding package downloaded from [ATP](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages). +Your system may support an arbitrary Plist in XML format (you can just upload the jamf/WindowsDefenderATPOnboarding.plist file as-is in this case), or require you to convert to a different format first. + +Note that your custom profile would have an id, name or domain attribute. You must use exactly "com.microsoft.wdav.atp". +MDM will use it to deploy the settings file as **/Library/Managed Preferences/com.microsoft.wdav.atp.plist** on a client machine, and Defender will use this file for loading onboarding info. + +### KEXT + +Setup a KEXT or kernel extension policy. Use team identifier **UBF8T346G9** to whitelist kernel extensions provided by Microsoft. + +## Was it successful? + +Run [mdatp](microsoft-defender-atp-mac-install-with-jamf.md#check-onboarding-status) on a client machine. diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md index af6205c2ca..130835c66e 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac.md @@ -46,6 +46,7 @@ In general you'll need to take the following steps: - Deploy Microsoft Defender ATP for Mac using one of the following deployment methods: - [Microsoft Intune-based deployment](microsoft-defender-atp-mac-install-with-intune) - [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf) + - [Other MDM products](microsoft-defender-atp-mac-install-with-other-mdm.md) - [Manual deployment](microsoft-defender-atp-mac-install-manually) ### Prerequisites From 26f085eeddcb189d96fcbca07c5ae82b33c15645 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 9 May 2019 09:40:06 -0700 Subject: [PATCH 230/737] Added 19H1 policies --- .../policy-configuration-service-provider.md | 6 + .../mdm/policy-csp-system.md | 152 +++++++++++++++++- 2 files changed, 155 insertions(+), 3 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index a27926a537..f566cfd699 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -3111,6 +3111,9 @@ The following diagram shows the Policy configuration service provider in tree fo
+
+ System/AllowCommercialDataPipeline +
System/AllowDeviceNameInDiagnosticData
@@ -3171,6 +3174,9 @@ The following diagram shows the Policy configuration service provider in tree fo
System/TelemetryProxy
+
+ System/TurnOffFileHistory +
### SystemServices policies diff --git a/windows/client-management/mdm/policy-csp-system.md b/windows/client-management/mdm/policy-csp-system.md index 77c58a2714..92fd30f9bb 100644 --- a/windows/client-management/mdm/policy-csp-system.md +++ b/windows/client-management/mdm/policy-csp-system.md @@ -6,7 +6,7 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 05/01/2019 +ms.date: 05/09/2019 --- # Policy CSP - System @@ -24,6 +24,9 @@ ms.date: 05/01/2019
System/AllowBuildPreview
+
+ System/AllowCommercialDataPipeline +
System/AllowDeviceNameInDiagnosticData
@@ -84,6 +87,9 @@ ms.date: 05/01/2019
System/TelemetryProxy
+
+ System/TurnOffFileHistory +
@@ -128,7 +134,6 @@ ms.date: 05/01/2019 > [!NOTE] > This policy setting applies only to devices running Windows 10 Pro, Windows 10 Enterprise, and Windows 10 Education, Windows 10 Mobile, and Windows 10 Mobile Enterprise. - This policy setting determines whether users can access the Insider build controls in the Advanced Options for Windows Update. These controls are located under "Get Insider builds," and enable users to make their devices available for downloading and installing Windows preview software. If you enable or do not configure this policy setting, users can download and install Windows preview software on their devices. If you disable this policy setting, the item "Get Insider builds" will be unavailable. @@ -154,6 +159,80 @@ The following list shows the supported values:
+ +**System/AllowCommercialDataPipeline** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
+ + + +> [!NOTE] +> This policy setting applies only to the Windows operating system and apps included with Windows, it does not apply to third-party apps or services running on Windows 10. + +This policy setting opts the device into the Windows enterprise data pipeline. + +If you enable this setting, data collected from the device is opted into the Windows enterprise data pipeline. + +If you disable or do not configure this setting, all data from the device is collected and processed in accordance with the policies for the Windows standard data pipeline. + +Configuring this setting does not change the telemetry collection level or the ability of the user to change the level. + + + +ADMX Info: +- GP English name: *Allow commercial data pipeline* +- GP name: *AllowCommercialDataPipeline* +- GP element: *AllowCommercialDataPipeline* +- GP path: *Data Collection and Preview Builds* +- GP ADMX file name: *DataCollection.admx* + + + +The following list shows the supported values: + +- 0 (default) - Do not use the Windows Commercial Data Pipeline +- 1 - Use the Windows Commercial Data Pipeline + + + + + + + + + + +
+ **System/AllowDeviceNameInDiagnosticData** @@ -1434,6 +1513,73 @@ ADMX Info: +
+ + +**System/TurnOffFileHistory** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcheck mark6check mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
+ + + +This policy setting allows you to turn off File History. + +If you enable this policy setting, File History cannot be activated to create regular, automatic backups. + +If you disable or do not configure this policy setting, File History can be activated to create regular, automatic backups. + + + +ADMX Info: +- GP English name: *Turn off File History* +- GP name: *DisableFileHistory* +- GP path: *Windows Components/File History* +- GP ADMX file name: *FileHistory.admx* + + + +The following list shows the supported values: + +- false (default) - allow File History +- true - turn off File History + + + + + + + + + @@ -1459,4 +1605,4 @@ Footnotes: - 3 - Added in Windows 10, version 1709. - 4 - Added in Windows 10, version 1803. - 5 - Added in Windows 10, version 1809. -- 6 - Added in the next major release of Windows 10. \ No newline at end of file +- 6 - Added in Windows 10, version 1903. \ No newline at end of file From 4117641823258d8fc785aa0bbe3c6041ee69b51b Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 9 May 2019 11:21:14 -0700 Subject: [PATCH 231/737] draft --- .../whats-new-windows-10-version-1903.md | 37 +++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 windows/whats-new/whats-new-windows-10-version-1903.md diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md new file mode 100644 index 0000000000..55b1f54d90 --- /dev/null +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -0,0 +1,37 @@ +--- +title: What's new in Windows 10, version 1903 +description: New and updated IT Pro content about new features in Windows 10, version 1903 (also known as the Windows 10 May 2019 Update). +keywords: ["What's new in Windows 10", "Windows 10", "May 2019 Update"] +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: greg-lindsay +ms.localizationpriority: high +ms.topic: article +--- + +# What's new in Windows 10, version 1903 IT Pro content + +**Applies to** +- Windows 10, version 1903 + +This article lists new and updated features and content that are of interest to IT Pros for Windows 10 version 1903, also known as the Windows 10 May 2019 Update. This update also contains all features and fixes included in previous cumulative updates to Windows 10, version 1809. + +>If you are not an IT Pro, see the following topics for information about what's new in Windows 10 in [hardware](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows), for [developers](https://blogs.windows.com/buildingapps/2019/04/18/start-developing-on-windows-10-may-2019-update-today/#2Lp8FUFQ3Jm8KVcq.97), and for [consumers](https://blogs.windows.com/windowsexperience/2018/04/30/whats-new-in-the-windows-10-april-2018-update). + + +## Deployment + +## Configuration + +## Security + +## Microsoft Edge + +https://blogs.windows.com/msedgedev/2019/05/06/edge-chromium-build-2019-pwa-ie-mode-devtools/#2QJF4u970WjQ2Sv7.97 + +## See Also + +[Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features.
+[What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10.
+[What's new in Windows 10, version 1809](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware.
From ba046cc060498140ddec69490a6c8a2020520465 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 11:57:29 -0700 Subject: [PATCH 232/737] Create windows-endpoints-1903-non-enterprise-editions.md --- ...-endpoints-1903-non-enterprise-editions.md | 271 ++++++++++++++++++ 1 file changed, 271 insertions(+) create mode 100644 windows/privacy/windows-endpoints-1903-non-enterprise-editions.md diff --git a/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md b/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md new file mode 100644 index 0000000000..44fadd939e --- /dev/null +++ b/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md @@ -0,0 +1,271 @@ +--- +title: Windows 10, version 1809, connection endpoints for non-Enterprise editions +description: Explains what Windows 10 endpoints are used in non-Enterprise editions. +keywords: privacy, manage connections to Microsoft, Windows 10, Windows Server 2016 +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.localizationpriority: high +audience: ITPro +author: danihalfin +ms.author: daniha +manager: dansimp +ms.collection: M365-security-compliance +ms.topic: article +ms.date: 6/26/2018 +--- +# Windows 10, version 1809, connection endpoints for non-Enterprise editions + + **Applies to** + +- Windows 10 Home, version 1809 +- Windows 10 Professional, version 1809 +- Windows 10 Education, version 1809 + +In addition to the endpoints listed for [Windows 10 Enterprise](manage-windows-1809-endpoints.md), the following endpoints are available on other editions of Windows 10, version 1809. + +We used the following methodology to derive these network endpoints: + +1. Set up the latest version of Windows 10 on a test virtual machine using the default settings. +2. Leave the devices running idle for a week (that is, a user is not interacting with the system/device). +3. Use globally accepted network protocol analyzer/capturing tools and log all background egress traffic. +4. Compile reports on traffic going to public IP addresses. +5. The test virtual machine was logged in using a local account and was not joined to a domain or Azure Active Directory. +6. All traffic was captured in our lab using a IPV4 network. Therefore no IPV6 traffic is reported here. + +> [!NOTE] +> Microsoft uses global load balancers that can appear in network trace-routes. For example, an endpoint for *.akadns.net might be used to load balance requests to an Azure datacenter, which can change over time. + +## Windows 10 Family + +| **Destination** | **Protocol** | **Description** | +| --- | --- | --- | +|\*.aria.microsoft.com*|HTTPS|Microsoft Office Telemetry +|\*.b.akamai*.net|HTTPS|Used to check for updates to Maps that have been downloaded for offline use +|\*.c-msedge.net|HTTP|Microsoft Office +|\*.dl.delivery.mp.microsoft.com*|HTTP|Enables connections to Windows Update +|\*.download.windowsupdate.com*|HTTP|Used to download operating system patches and updates +|\*.g.akamai*.net|HTTPS|Used to check for updates to Maps that have been downloaded for offline use +|\*.login.msa.*.net|HTTPS|Microsoft Account related +|\*.msn.com*|TLSv1.2/HTTPS|Windows Spotlight +|\*.skype.com|HTTP/HTTPS|Skype +|\*.smartscreen.microsoft.com*|HTTPS|Windows Defender Smartscreen +|\*.telecommand.telemetry.microsoft.com*|HTTPS|Used by Windows Error Reporting +|*cdn.onenote.net*|HTTP|OneNote +|*displaycatalog.*mp.microsoft.com*|HTTPS|Used to communicate with Microsoft Store +|*emdl.ws.microsoft.com*|HTTP|Windows Update +|*geo-prod.do.dsp.mp.microsoft.com*|TLSv1.2/HTTPS|Enables connections to Windows Update +|*hwcdn.net*|HTTP|Highwinds Content Delivery Network / Windows updates +|*img-prod-cms-rt-microsoft-com*|HTTPS|Microsoft Store or Inbox MSN Apps image download +|*licensing.*mp.microsoft.com*|HTTPS|Licensing +|*maps.windows.com*|HTTPS|Related to Maps application +|*msedge.net*|HTTPS|Used by Microsoft OfficeHub to get the metadata of Microsoft Office apps +|*nexusrules.officeapps.live.com*|HTTPS|Microsoft Office Telemetry +|*photos.microsoft.com*|HTTPS|Photos App +|*prod.do.dsp.mp.microsoft.com*|TLSv1.2/HTTPS|Used for Windows Update downloads of apps and OS updates +|*purchase.md.mp.microsoft.com.akadns.net|HTTPS|Used to communicate with Microsoft Store +|*settings.data.microsoft.com.akadns.net|HTTPS|Used for Windows apps to dynamically update their configuration +|*wac.phicdn.net*|HTTP|Windows Update +|*windowsupdate.com*|HTTP|Windows Update +|*wns.*windows.com*|TLSv1.2/HTTPS|Used for the Windows Push Notification Services (WNS) +|*wpc.v0cdn.net*|HTTP|Windows Telemetry +|arc.msn.com|HTTPS|Spotlight +|auth.gfx.ms*|HTTPS|MSA related +|cdn.onenote.net|HTTPS|OneNote Live Tile +|dmd.metaservices.microsoft.com*|HTTP|Device Authentication +|e-0009.e-msedge.net|HTTPS|Microsoft Office +|e10198.b.akamaiedge.net|HTTPS|Maps application +|evoke-windowsservices-tas.msedge*|HTTPS|Photos app +|fe2.update.microsoft.com*|TLSv1.2/HTTPS|Enables connections to Windows Update, Microsoft Update, and the online services of Microsoft Store +|fe3.*.mp.microsoft.com.*|TLSv1.2/HTTPS|Windows Update, Microsoft Update, and Microsoft Store services +|g.live.com*|HTTPS|OneDrive +|go.microsoft.com|HTTP|Windows Defender +|iriscoremetadataprod.blob.core.windows.net|HTTPS|Windows Telemetry +|login.live.com|HTTPS|Device Authentication +|msagfx.live.com|HTTP|OneDrive +|ocsp.digicert.com*|HTTP|CRL and OCSP checks to the issuing certificate authorities +|officeclient.microsoft.com|HTTPS|Microsoft Office +|oneclient.sfx.ms*|HTTPS|Used by OneDrive for Business to download and verify app updates +|onecollector.cloudapp.aria.akadns.net|HTTPS|Microsoft Office +|ow1.res.office365.com|HTTP|Microsoft Office +|pti.store.microsoft.com|HTTPS|Microsoft Store +|purchase.mp.microsoft.com*|HTTPS|Used to communicate with Microsoft Store +|query.prod.cms.rt.microsoft.com*|HTTPS|Used to retrieve Windows Spotlight metadata +|ris.api.iris.microsoft.com*|TLSv1.2/HTTPS|Used to retrieve Windows Spotlight metadata +|ris-prod-atm.trafficmanager.net|HTTPS|Azure traffic manager +|s-0001.s-msedge.net|HTTPS|Microsoft Office +|self.events.data.microsoft.com|HTTPS|Microsoft Office +|settings.data.microsoft.com*|HTTPS|Used for Windows apps to dynamically update their configuration +|settings-win.data.microsoft.com*|HTTPS|Used for Windows apps to dynamically update their configuration +|share.microsoft.com|HTTPS|Microsoft Store +|skypeecs-prod-usw-0.cloudapp.net|HTTPS|Microsoft Store +|sls.update.microsoft.com*|TLSv1.2/HTTPS|Enables connections to Windows Update +|slscr.update.microsoft.com*|HTTPS|Enables connections to Windows Update +|store*.dsx.mp.microsoft.com*|HTTPS|Used to communicate with Microsoft Store +|storecatalogrevocation.storequality.microsoft.com|HTTPS|Microsoft Store +|storecatalogrevocation.storequality.microsoft.com*|HTTPS|Used to revoke licenses for malicious apps on the Microsoft Store +|store-images.*microsoft.com*|HTTP|Used to get images that are used for Microsoft Store suggestions +|storesdk.dsx.mp.microsoft.com|HTTP|Microsoft Store +|tile-service.weather.microsoft.com*|HTTP|Used to download updates to the Weather app Live Tile +|time.windows.com|HTTP|Microsoft Windows Time related +|tsfe.trafficshaping.dsp.mp.microsoft.com*|TLSv1.2/HTTPS|Used for content regulation +|v10.events.data.microsoft.com|HTTPS|Diagnostic Data +|watson.telemetry.microsoft.com|HTTPS|Diagnostic Data +|wdcp.microsoft.*|TLSv1.2, HTTPS|Used for Windows Defender when Cloud-based Protection is enabled +|wd-prod-cp-us-west-1-fe.westus.cloudapp.azure.com|HTTPS|Windows Defender +|wusofficehome.msocdn.com|HTTPS|Microsoft Office +|www.bing.com*|HTTP|Used for updates for Cortana, apps, and Live Tiles +|www.msftconnecttest.com|HTTP|Network Connection (NCSI) +|www.office.com|HTTPS|Microsoft Office + + +## Windows 10 Pro + +| **Destination** | **Protocol** | **Description** | +| --- | --- | --- | +|\*.cloudapp.azure.com|HTTPS|Azure +|\*.delivery.dsp.mp.microsoft.com.nsatc.net|HTTPS|Windows Update, Microsoft Update, and Microsoft Store services +|\*.displaycatalog.md.mp.microsoft.com.akadns.net|HTTPS|Microsoft Store +|\*.dl.delivery.mp.microsoft.com*|HTTP|Enables connections to Windows Update +|\*.e-msedge.net|HTTPS|Used by OfficeHub to get the metadata of Office apps +|\*.g.akamaiedge.net|HTTPS|Used to check for updates to maps that have been downloaded for offline use +|\*.s-msedge.net|HTTPS|Used by OfficeHub to get the metadata of Office apps +|\*.windowsupdate.com*|HTTP|Enables connections to Windows Update +|\*.wns.notify.windows.com.akadns.net|HTTPS|Used for the Windows Push Notification Services (WNS) +|\*dsp.mp.microsoft.com.nsatc.net|HTTPS|Enables connections to Windows Update +|\*c-msedge.net|HTTP|Office +|a1158.g.akamai.net|HTTP|Maps application +|arc.msn.com*|HTTP / HTTPS|Used to retrieve Windows Spotlight metadata +|blob.mwh01prdstr06a.store.core.windows.net|HTTPS|Microsoft Store +|browser.pipe.aria.microsoft.com|HTTPS|Microsoft Office +|bubblewitch3mobile.king.com|HTTPS|Bubble Witch application +|candycrush.king.com|HTTPS|Candy Crush application +|cdn.onenote.net|HTTP|Microsoft OneNote +|cds.p9u4n2q3.hwcdn.net|HTTP|Highwinds Content Delivery Network traffic for Windows updates +|client.wns.windows.com|HTTPS|Winddows Notification System +|co4.telecommand.telemetry.microsoft.com.akadns.net|HTTPS|Windows Error Reporting +|config.edge.skype.com|HTTPS|Microsoft Skype +|cs11.wpc.v0cdn.net|HTTP|Windows Telemetry +|cs9.wac.phicdn.net|HTTP|Windows Update +|cy2.licensing.md.mp.microsoft.com.akadns.net|HTTPS|Used to communicate with Microsoft Store +|cy2.purchase.md.mp.microsoft.com.akadns.net|HTTPS|Used to communicate with Microsoft Store +|cy2.settings.data.microsoft.com.akadns.net|HTTPS|Used to communicate with Microsoft Store +|dmd.metaservices.microsoft.com.akadns.net|HTTP|Device Authentication +|e-0009.e-msedge.net|HTTPS|Microsoft Office +|e10198.b.akamaiedge.net|HTTPS|Maps application +|fe3.update.microsoft.com|HTTPS|Windows Update +|g.live.com|HTTPS|Microsoft OneDrive +|g.msn.com.nsatc.net|HTTPS|Used to retrieve Windows Spotlight metadata +|geo-prod.do.dsp.mp.microsoft.com|HTTPS|Windows Update +|go.microsoft.com|HTTP|Windows Defender +|iecvlist.microsoft.com|HTTPS|Microsoft Edge +|img-prod-cms-rt-microsoft-com.akamaized.net|HTTP / HTTPS|Microsoft Store +|ipv4.login.msa.akadns6.net|HTTPS|Used for Microsoft accounts to sign in +|licensing.mp.microsoft.com|HTTP|Licensing +|location-inference-westus.cloudapp.net|HTTPS|Used for location data +|login.live.com|HTTP|Device Authentication +|maps.windows.com|HTTP|Maps application +|modern.watson.data.microsoft.com.akadns.net|HTTPS|Used by Windows Error Reporting +|msagfx.live.com|HTTP|OneDrive +|nav.smartscreen.microsoft.com|HTTPS|Windows Defender +|ocsp.digicert.com*|HTTP|CRL and OCSP checks to the issuing certificate authorities +|oneclient.sfx.ms|HTTP|OneDrive +|pti.store.microsoft.com|HTTPS|Microsoft Store +|ris.api.iris.microsoft.com.akadns.net|HTTPS|Used to retrieve Windows Spotlight metadata +|ris-prod-atm.trafficmanager.net|HTTPS|Azure +|s2s.config.skype.com|HTTP|Microsoft Skype +|settings-win.data.microsoft.com|HTTPS|Application settings +|share.microsoft.com|HTTPS|Microsoft Store +|skypeecs-prod-usw-0.cloudapp.net|HTTPS|Microsoft Skype +|slscr.update.microsoft.com|HTTPS|Windows Update +|storecatalogrevocation.storequality.microsoft.com|HTTPS|Microsoft Store +|store-images.microsoft.com|HTTPS|Microsoft Store +|tile-service.weather.microsoft.com/*|HTTP|Used to download updates to the Weather app Live Tile +|time.windows.com|HTTP|Windows time +|tsfe.trafficshaping.dsp.mp.microsoft.com|HTTPS|Used for content regulation +|v10.events.data.microsoft.com*|HTTPS|Microsoft Office +|vip5.afdorigin-prod-am02.afdogw.com|HTTPS|Used to serve office 365 experimentation traffic +|watson.telemetry.microsoft.com|HTTPS|Telemetry +|wdcp.microsoft.com|HTTPS|Windows Defender +|wusofficehome.msocdn.com|HTTPS|Microsoft Office +|www.bing.com|HTTPS|Cortana and Search +|www.microsoft.com|HTTP|Diagnostic +|www.msftconnecttest.com|HTTP|Network connection +|www.office.com|HTTPS|Microsoft Office + + + +## Windows 10 Education + +| **Destination** | **Protocol** | **Description** | +| --- | --- | --- | +|\*.b.akamaiedge.net|HTTPS|Used to check for updates to maps that have been downloaded for offline use +|\*.c-msedge.net|HTTP|Used by OfficeHub to get the metadata of Office apps +|\*.dl.delivery.mp.microsoft.com*|HTTP|Windows Update +|\*.e-msedge.net|HTTPS|Used by OfficeHub to get the metadata of Office apps +|\*.g.akamaiedge.net|HTTPS|Used to check for updates to Maps that have been downloaded for offline use +|\*.licensing.md.mp.microsoft.com.akadns.net|HTTPS|Microsoft Store +|\*.settings.data.microsoft.com.akadns.net|HTTPS|Microsoft Store +|\*.skype.com*|HTTPS|Used to retrieve Skype configuration values +|\*.smartscreen*.microsoft.com|HTTPS|Windows Defender +|\*.s-msedge.net|HTTPS|Used by OfficeHub to get the metadata of Office apps +|\*.telecommand.telemetry.microsoft.com*|HTTPS|Used by Windows Error Reporting +|\*.wac.phicdn.net|HTTP|Windows Update +|\*.windowsupdate.com*|HTTP|Windows Update +|\*.wns.windows.com|HTTPS|Windows Notifications Service +|\*.wpc.*.net|HTTP|Diagnostic Data +|\*displaycatalog.md.mp.microsoft.com.akadns.net|HTTPS|Microsoft Store +|\*dsp.mp.microsoft.com|HTTPS|Windows Update +|a1158.g.akamai.net|HTTP|Maps +|a122.dscg3.akamai.net|HTTP|Maps +|a767.dscg3.akamai.net|HTTP|Maps +|au.download.windowsupdate.com*|HTTP|Windows Update +|bing.com/*|HTTPS|Used for updates for Cortana, apps, and Live Tiles +|blob.dz5prdstr01a.store.core.windows.net|HTTPS|Microsoft Store +|browser.pipe.aria.microsoft.com|HTTP|Used by OfficeHub to get the metadata of Office apps +|cdn.onenote.net/livetile/*|HTTPS|Used for OneNote Live Tile +|cds.p9u4n2q3.hwcdn.net|HTTP|Used by the Highwinds Content Delivery Network to perform Windows updates +|client-office365-tas.msedge.net/*|HTTPS|Office 365 porta and Office Online +|ctldl.windowsupdate.com*|HTTP|Used to download certificates that are publicly known to be fraudulent +|displaycatalog.mp.microsoft.com/*|HTTPS|Microsoft Store +|dmd.metaservices.microsoft.com*|HTTP|Device Authentication +|download.windowsupdate.com*|HTTPS|Windows Update +|emdl.ws.microsoft.com/*|HTTP|Used to download apps from the Microsoft Store +|evoke-windowsservices-tas.msedge.net|HTTPS|Photo app +|fe2.update.microsoft.com*|HTTPS|Windows Update, Microsoft Update, Microsoft Store services +|fe3.delivery.dsp.mp.microsoft.com.nsatc.net|HTTPS|Windows Update, Microsoft Update, Microsoft Store services +|fe3.delivery.mp.microsoft.com*|HTTPS|Windows Update, Microsoft Update, Microsoft Store services +|g.live.com*|HTTPS|Used by OneDrive for Business to download and verify app updates +|g.msn.com.nsatc.net|HTTPS|Used to retrieve Windows Spotlight metadata +|go.microsoft.com|HTTP|Windows Defender +|iecvlist.microsoft.com|HTTPS|Microsoft Edge browser +|ipv4.login.msa.akadns6.net|HTTPS|Used for Microsoft accounts to sign in +|licensing.mp.microsoft.com*|HTTPS|Used for online activation and some app licensing +|login.live.com|HTTPS|Device Authentication +|maps.windows.com/windows-app-web-link|HTTPS|Maps application +|modern.watson.data.microsoft.com.akadns.net|HTTPS|Used by Windows Error Reporting +|msagfx.live.com|HTTPS|OneDrive +|ocos-office365-s2s.msedge.net/*|HTTPS|Used to connect to the Office 365 portal's shared infrastructure +|ocsp.digicert.com*|HTTP|CRL and OCSP checks to the issuing certificate authorities +|oneclient.sfx.ms/*|HTTPS|Used by OneDrive for Business to download and verify app updates +|onecollector.cloudapp.aria.akadns.net|HTTPS|Microsoft Office +|pti.store.microsoft.com|HTTPS|Microsoft Store +|settings-win.data.microsoft.com/settings/*|HTTPS|Used as a way for apps to dynamically update their configuration +|share.microsoft.com|HTTPS|Microsoft Store +|skypeecs-prod-usw-0.cloudapp.net|HTTPS|Skype +|sls.update.microsoft.com*|HTTPS|Windows Update +|storecatalogrevocation.storequality.microsoft.com*|HTTPS|Used to revoke licenses for malicious apps on the Microsoft Store +|tile-service.weather.microsoft.com*|HTTP|Used to download updates to the Weather app Live Tile +|tsfe.trafficshaping.dsp.mp.microsoft.com|HTTPS|Windows Update +|v10.events.data.microsoft.com*|HTTPS|Diagnostic Data +|vip5.afdorigin-prod-ch02.afdogw.com|HTTPS|Used to serve Office 365 experimentation traffic +|watson.telemetry.microsoft.com*|HTTPS|Used by Windows Error Reporting +|wdcp.microsoft.com|HTTPS|Windows Defender +|wd-prod-cp-us-east-1-fe.eastus.cloudapp.azure.com|HTTPS|Azure +|wusofficehome.msocdn.com|HTTPS|Microsoft Office +|www.bing.com|HTTPS|Cortana and Search +|www.microsoft.com|HTTP|Diagnostic Data +|www.microsoft.com/pkiops/certs/*|HTTP|CRL and OCSP checks to the issuing certificate authorities +|www.msftconnecttest.com|HTTP|Network Connection +|www.office.com|HTTPS|Microsoft Office + From 22f42b2e9b3504d4b4e914bddd077a9aa2f2936d Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 9 May 2019 12:12:43 -0700 Subject: [PATCH 233/737] draft --- windows/deployment/upgrade/setupdiag.md | 24 ++++++++++++++++++++---- 1 file changed, 20 insertions(+), 4 deletions(-) diff --git a/windows/deployment/upgrade/setupdiag.md b/windows/deployment/upgrade/setupdiag.md index 9b97b16be8..a8dc80f2ef 100644 --- a/windows/deployment/upgrade/setupdiag.md +++ b/windows/deployment/upgrade/setupdiag.md @@ -7,7 +7,6 @@ ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: deploy author: greg-lindsay -ms.date: 12/18/2018 ms.localizationpriority: medium ms.topic: article --- @@ -25,7 +24,7 @@ ms.topic: article ## About SetupDiag -Current version of SetupDiag: 1.4.0.0 +Current version of SetupDiag: 1.4.1.0 SetupDiag is a standalone diagnostic tool that can be used to obtain details about why a Windows 10 upgrade was unsuccessful. @@ -64,8 +63,9 @@ The [Release notes](#release-notes) section at the bottom of this topic has info | /Output:\ |
  • This optional parameter enables you to specify the output file for results. This is where you will find what SetupDiag was able to determine. Only text format output is supported. UNC paths will work, provided the context under which SetupDiag runs has access to the UNC path. If the path has a space in it, you must enclose the entire path in double quotes (see the example section below).
  • Default: If not specified, SetupDiag will create the file **SetupDiagResults.log** in the same directory where SetupDiag.exe is run.
| | /LogsPath:\ |
  • This optional parameter tells SetupDiag.exe where to find the log files for an offline analysis. These log files can be in a flat folder format, or containing multiple subdirectories. SetupDiag will recursively search all child directories.
| | /ZipLogs:\ |
  • This optional parameter tells SetupDiag.exe to create a zip file containing the results and all the log files it parsed. The zip file is created in the same directory where SetupDiag.exe is run.
  • Default: If not specified, a value of 'true' is used.
| -| /Verbose |
  • This optional parameter will output much more data to a log file. By default, SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce an additional log file with debugging details. These details can be useful when reporting a problem with SetupDiag.
| | /Format:\ |
  • This optional parameter can be used to output log files in xml or JSON format. If this parameter is not specified, text format is used by default.
| +| /Scenario:\[Recovery\] | This optional parameter instructs SetupDiag.exe to look for and process reset and recovery logs and ignore setup/upgrade logs.| +| /Verbose |
  • This optional parameter will output much more data to a log file. By default, SetupDiag will only produce a log file entry for serious errors. Using **/Verbose** will cause SetupDiag to always produce an additional log file with debugging details. These details can be useful when reporting a problem with SetupDiag.
| | /NoTel |
  • This optional parameter tells SetupDiag.exe not to send diagnostic telemetry to Microsoft.
| Note: The **/Mode** parameter is deprecated in version 1.4.0.0 of SetupDiag. @@ -97,6 +97,19 @@ The following example specifies that SetupDiag is to run in offline mode, and to SetupDiag.exe /Output:C:\SetupDiag\Results.log /LogsPath:D:\Temp\Logs\LogSet1 ``` +The following example sets recovery scenario in offline mode. In the example, SetupDiag will search for reset/recovery logs in the specified LogsPath location and output the resuts to the directory specified by the /Output parameter. + +``` +SetupDiag.exe /Output:C:\SetupDiag\RecoveryResults.log /LogsPath:D:\Temp\Cabs\PBR_Log /Scenario:Recovery +``` + +The following example sets recovery scenario in online mode. In the example, SetupDiag will search for reset/recovery logs on the current system and output results in XML format. + +``` +SetupDiag.exe /Scenario:Recovery /Format:xml +``` + + ## Log files [Windows Setup Log Files and Event Logs](https://docs.microsoft.com/windows-hardware/manufacture/desktop/windows-setup-log-files-and-event-logs) has information about where logs are created during Windows Setup. For offline processing, you should run SetupDiag against the contents of the entire folder. For example, depending on when the upgrade failed, copy one of the following folders to your offline location: @@ -141,7 +154,7 @@ The output also provides an error code 0xC1900208 - 0x4000C which corresponds to ``` C:\SetupDiag>SetupDiag.exe /Output:C:\SetupDiag\Results.log /LogsPath:C:\Temp\BobMacNeill -SetupDiag v1.4.0.0 +SetupDiag v1.4.1.0 Copyright (c) Microsoft Corporation. All rights reserved. Searching for setup logs, this can take a minute or more depending on the number and size of the logs...please wait. @@ -397,6 +410,9 @@ Each rule name and its associated unique rule identifier are listed with a descr ## Release notes +05/10/2019 - SetupDiag v1.4.1.0 is released with 53 rules, as a standalone tool available from the Download Center. + - This release dds the ability to find and diagnose reset and recovery failures (Push Button Reset). + 12/18/2018 - SetupDiag v1.4.0.0 is released with 53 rules, as a standalone tool available from the Download Center. - This release includes major improvements in rule processing performance: ~3x faster rule processing performance! - The FindDownlevelFailure rule is up to 10x faster. From e936adc1bb432d397f45c9e3aac764d712c1240e Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 12:35:53 -0700 Subject: [PATCH 234/737] Update windows-endpoints-1903-non-enterprise-editions.md --- ...-endpoints-1903-non-enterprise-editions.md | 20 +++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md b/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md index 44fadd939e..2c3885c711 100644 --- a/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md +++ b/windows/privacy/windows-endpoints-1903-non-enterprise-editions.md @@ -1,5 +1,5 @@ --- -title: Windows 10, version 1809, connection endpoints for non-Enterprise editions +title: Windows 10, version 1903, connection endpoints for non-Enterprise editions description: Explains what Windows 10 endpoints are used in non-Enterprise editions. keywords: privacy, manage connections to Microsoft, Windows 10, Windows Server 2016 ms.prod: w10 @@ -7,22 +7,22 @@ ms.mktglfcycl: manage ms.sitesec: library ms.localizationpriority: high audience: ITPro -author: danihalfin -ms.author: daniha -manager: dansimp +author: mikeedgar +ms.author: v-medgar +manager: sanashar ms.collection: M365-security-compliance ms.topic: article -ms.date: 6/26/2018 +ms.date: 5/9/2019 --- -# Windows 10, version 1809, connection endpoints for non-Enterprise editions +# Windows 10, version 1903, connection endpoints for non-Enterprise editions **Applies to** -- Windows 10 Home, version 1809 -- Windows 10 Professional, version 1809 -- Windows 10 Education, version 1809 +- Windows 10 Home, version 1903 +- Windows 10 Professional, version 1903 +- Windows 10 Education, version 1903 -In addition to the endpoints listed for [Windows 10 Enterprise](manage-windows-1809-endpoints.md), the following endpoints are available on other editions of Windows 10, version 1809. +In addition to the endpoints listed for [Windows 10 Enterprise](manage-windows-1903-endpoints.md), the following endpoints are available on other editions of Windows 10, version 1903. We used the following methodology to derive these network endpoints: From 455b7236ea01925b0814ebb968321986a6e2f357 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 16:57:41 -0700 Subject: [PATCH 235/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ating-system-components-to-microsoft-services.md | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 72bb0cefbe..1cd88e5243 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -39,9 +39,6 @@ However, some of the settings reduce the functionality and security configuratio Make sure you've chosen the right settings configuration for your environment before applying. You should not extract this package to the windows\\system32 folder because it will not apply correctly. ->[!IMPORTANT] -> As part of the [Windows Restricted Traffic Limited Functionality Baseline](https://go.microsoft.com/fwlink/?linkid=828887), MDM functionallity is disabled. If you manage devices through MDM, make sure [cloud notifications are enabled](#bkmk-priv-notifications). - Applying the Windows Restricted Traffic Limited Functionality Baseline is the same as applying each setting covered in this article. It is recommended that you restart a device after making configuration changes to it. Note that **Get Help** and **Give us Feedback** links no longer work after the Windows Restricted Traffic Limited Functionality Baseline is applied. @@ -56,8 +53,6 @@ The following sections list the components that make network connections to Micr The following table lists management options for each setting, beginning with Windows 10 Enterprise version 1607. ->[!NOTE] ->For some settings, MDM policies only partly cover capabilities available through Group Policy. See each setting’s section for more details. | Setting | UI | Group Policy | Registry | | - | :-: | :-: | :-: | @@ -268,7 +263,7 @@ On Windows Server 2016 Nano Server: ### 2. Cortana and Search -Use either Group Policy or MDM policies to manage settings for Cortana. For more info, see [Cortana, Search, and privacy: FAQ](https://go.microsoft.com/fwlink/p/?LinkId=730683). +Use Group Policies to manage settings for Cortana. For more info, see [Cortana, Search, and privacy: FAQ](https://go.microsoft.com/fwlink/p/?LinkId=730683). ### 2.1 Cortana and Search Group Policies @@ -558,7 +553,7 @@ To disable the Microsoft Account Sign-In Assistant: ### 13. Microsoft Edge -Use either Group Policy or MDM policies to manage settings for Microsoft Edge. For more info, see [Microsoft Edge and privacy: FAQ](https://go.microsoft.com/fwlink/p/?LinkId=730682). +Use Group Policies to manage settings for Microsoft Edge. For more info, see [Microsoft Edge and privacy: FAQ](https://go.microsoft.com/fwlink/p/?LinkId=730682). ### 13.1 Microsoft Edge Group Policies @@ -1643,7 +1638,7 @@ To disable Windows Defender Smartscreen: ### 25. Windows Spotlight -Windows Spotlight provides features such as different background images and text on the lock screen, suggested apps, Microsoft account notifications, and Windows tips. You can control it by using the user interface, MDM policy, or through Group Policy. +Windows Spotlight provides features such as different background images and text on the lock screen, suggested apps, Microsoft account notifications, and Windows tips. You can control it by using the user interface or Group Policy. If you're running Windows 10, version 1607 or later, you need to: @@ -1765,7 +1760,7 @@ Windows Update Delivery Optimization lets you get Windows updates and Microsoft By default, PCs running Windows 10 Enterprise and Windows 10 Education will only use Delivery Optimization to get and receive updates for PCs and apps on your local network. -Use the UI, Group Policy, MDM policies, or Windows Provisioning to set up Delivery Optimization. +Use the UI, Group Policy, or Registry Keys to set up Delivery Optimization. In Windows 10 version 1607 and above you can stop network traffic related to Windows Update Delivery Optimization by setting **Download Mode** to **Bypass** (100), as described below. From 3c8fc7a4ed6263938d394c3edb28ce1e49d77d37 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:08:30 -0700 Subject: [PATCH 236/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ows-operating-system-components-to-microsoft-services.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 1cd88e5243..e86b33a16f 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -96,7 +96,7 @@ The following table lists management options for each setting, beginning with Wi |     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | @@ -129,7 +129,7 @@ See the following table for a summary of the management settings for Windows Ser | [18. Settings > Privacy](#bkmk-settingssection) | | | | |     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [20. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | @@ -1488,7 +1488,7 @@ For Windows 10: -or- -- Create a REG_DWORD registry setting named **AllowDiskHealthModelUpdates** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\StorageHealth** with a value of 0. +- Create a REG_DWORD registry setting named **AllowDiskHealthModelUpdates** in **HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\StorageHealth** with a **value of 0**. ### 21. Sync your settings From bb3fc68af11c27d207e9b245ab56a43affc54c69 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:15:11 -0700 Subject: [PATCH 237/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...perating-system-components-to-microsoft-services.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index e86b33a16f..5964599ef4 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -96,9 +96,9 @@ The following table lists management options for each setting, beginning with Wi |     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | +| [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | | [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | @@ -146,7 +146,7 @@ See the following table for a summary of the management settings for Windows Ser | [6. Font streaming](#font-streaming) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [14. Network Connection Status Indicator](#bkmk-ncsi) | ![Check mark](images/checkmark.png) | | | [19. Software Protection Platform](#bkmk-spp) | ![Check mark](images/checkmark.png) | -| [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | | +| [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | @@ -158,7 +158,7 @@ See the following table for a summary of the management settings for Windows Ser | - | :-: | | [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | | [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | -| [22. Teredo](#bkmk-teredo) | | +| [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2019 @@ -206,7 +206,7 @@ See the following table for a summary of the management settings for Windows Ser |     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | | +| [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From 1000661358f37cf87af06bcba38828acb560e92c Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:19:05 -0700 Subject: [PATCH 238/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 5964599ef4..ef98f3c09d 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -99,7 +99,7 @@ The following table lists management options for each setting, beginning with Wi | [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [23. Wi-Fi Sense](#bkmk-wifisense) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From 5d4ef5882af406a1993bf5d8aa1175265df89e02 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:22:58 -0700 Subject: [PATCH 239/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ows-operating-system-components-to-microsoft-services.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index ef98f3c09d..af7aace6a4 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -104,7 +104,7 @@ The following table lists management options for each setting, beginning with Wi |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | @@ -132,7 +132,7 @@ See the following table for a summary of the management settings for Windows Ser | [22. Teredo](#bkmk-teredo) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2016 Server Core @@ -214,7 +214,7 @@ See the following table for a summary of the management settings for Windows Ser |     [24.1 Windows Defender Smartscreen](#bkmk-defender-smartscreen) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [25. Windows Spotlight](#bkmk-spotlight) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | | +|     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) |![Check mark](images/checkmark.png) | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From b6bc7577d870a0007cf4dd4117f29f3f27f4316d Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:25:53 -0700 Subject: [PATCH 240/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index af7aace6a4..94c2c9f4dd 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -106,7 +106,7 @@ The following table lists management options for each setting, beginning with Wi | [26. Microsoft Store](#bkmk-windowsstore) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [26.1 Apps for websites](#bkmk-apps-for-websites) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [27. Windows Update Delivery Optimization](#bkmk-updates) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +| [28. Windows Update](#bkmk-wu) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ### Settings for Windows Server 2016 with Desktop Experience From 4b445fe8cf340293684880184d40d5fb096a738e Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:36:36 -0700 Subject: [PATCH 241/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 94c2c9f4dd..91ea2a2d0a 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -125,7 +125,7 @@ See the following table for a summary of the management settings for Windows Ser | [10. Live Tiles](#live-tiles) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [12. Microsoft Account](#bkmk-microsoft-account) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [14. Network Connection Status Indicator](#bkmk-ncsi) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | | +| [16. OneDrive](#bkmk-onedrive) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [18. Settings > Privacy](#bkmk-settingssection) | | | | |     [18.1 General](#bkmk-general) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From 2e7a4cf02e2b44f53b2e9bbdbbe64642ad437c6d Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:38:28 -0700 Subject: [PATCH 242/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ndows-operating-system-components-to-microsoft-services.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 91ea2a2d0a..4f37cf4f5a 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -144,8 +144,8 @@ See the following table for a summary of the management settings for Windows Ser | [1. Automatic Root Certificates Update](#automatic-root-certificates-update) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [3. Date & Time](#bkmk-datetime) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [6. Font streaming](#font-streaming) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -| [14. Network Connection Status Indicator](#bkmk-ncsi) | ![Check mark](images/checkmark.png) | | -| [19. Software Protection Platform](#bkmk-spp) | ![Check mark](images/checkmark.png) | +| [14. Network Connection Status Indicator](#bkmk-ncsi) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | +| [19. Software Protection Platform](#bkmk-spp) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [22. Teredo](#bkmk-teredo) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [24. Windows Defender](#bkmk-defender) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [28. Windows Update](#bkmk-wu) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From cbac0ad6f2f8e9a057a565e7239504376228330c Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:40:59 -0700 Subject: [PATCH 243/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 4f37cf4f5a..01593aa1b1 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -200,7 +200,7 @@ See the following table for a summary of the management settings for Windows Ser |     [18.14 Radios](#bkmk-priv-radios) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.15 Other devices](#bkmk-priv-other-devices) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.16 Feedback & diagnostics](#bkmk-priv-feedback) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | +|     [18.17 Background apps](#bkmk-priv-background) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From 36d3fb430d2bd55ce4cc1c1c15cf37b35fd07822 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Thu, 9 May 2019 19:42:23 -0700 Subject: [PATCH 244/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 01593aa1b1..5a69fa7d6e 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -204,7 +204,7 @@ See the following table for a summary of the management settings for Windows Ser |     [18.18 Motion](#bkmk-priv-motion) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.19 Tasks](#bkmk-priv-tasks) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | |     [18.20 App Diagnostics](#bkmk-priv-diag) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | -|     [18.21 Inking & Typing](#bkmk-priv-ink) | | | ![Check mark](images/checkmark.png) | +|     [18.21 Inking & Typing](#bkmk-priv-ink) | ![Check mark](images/checkmark.png) | | ![Check mark](images/checkmark.png) | | [19. Software Protection Platform](#bkmk-spp) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [20. Storage Health](#bkmk-storage-health) | | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | | [21. Sync your settings](#bkmk-syncsettings) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | ![Check mark](images/checkmark.png) | From 6c67c066f897fc0875bf60fbaf1e7a3e68e0dfca Mon Sep 17 00:00:00 2001 From: ImranHabib <47118050+joinimran@users.noreply.github.com> Date: Fri, 10 May 2019 10:15:30 +0500 Subject: [PATCH 245/737] Changed applied Changed applied as suggested by @mapalko. --- .../hello-for-business/hello-how-it-works-technology.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md index 015c33f72a..99026497a4 100644 --- a/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md +++ b/windows/security/identity-protection/hello-for-business/hello-how-it-works-technology.md @@ -101,7 +101,7 @@ The Windows Hello for Business Cloud deployment is exclusively for organizations [Return to Top](hello-how-it-works-technology.md) ## Cloud Experience Host -In Windows 10 Enterprise edition, Cloud Experience Host is an application that helps you join the workplace environment or Azure AD using your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. +In Windows 10, Cloud Experience Host is an application used while joining the workplace environment or Azure AD for rendering the experience when collecting your company-provided credentials. Once you enroll your device to your workplace environment or Azure AD, your organization will be able to manage your PC and collect information about you (including your location). It might add or remove apps or content, change settings, disable features, prevent you from removing your company account, or reset your PC. ### Related topics [Windows Hello for Business](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-identity-verification), [Managed Windows Hello in Organization](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-manage-in-organization) From 9178e4ce729b15b09e800c8c4e43e737fe806cc6 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Fri, 10 May 2019 09:52:59 -0700 Subject: [PATCH 246/737] Added 19H1 new policy doc and policy --- .../policy-configuration-service-provider.md | 9 ++ .../mdm/policy-csp-servicecontrolmanager.md | 115 ++++++++++++++++++ 2 files changed, 124 insertions(+) create mode 100644 windows/client-management/mdm/policy-csp-servicecontrolmanager.md diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index a27926a537..58bba60460 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -2927,6 +2927,13 @@ The following diagram shows the Policy configuration service provider in tree fo +### ServiceControlManager policies +
+
+ ServiceControlManager/SvchostProcessMitigation +
+
+ ### Settings policies
@@ -4112,6 +4119,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [RemoteShell/SpecifyMaxProcesses](./policy-csp-remoteshell.md#remoteshell-specifymaxprocesses) - [RemoteShell/SpecifyMaxRemoteShells](./policy-csp-remoteshell.md#remoteshell-specifymaxremoteshells) - [RemoteShell/SpecifyShellTimeout](./policy-csp-remoteshell.md#remoteshell-specifyshelltimeout) +- [ServiceControlManager/SvchostProcessMitigation](./policy-csp-servicecontrolmanager.md#servicecontrolmanager-svchostprocessmitigation) - [Storage/EnhancedStorageDevices](./policy-csp-storage.md#storage-enhancedstoragedevices) - [System/BootStartDriverInitialization](./policy-csp-system.md#system-bootstartdriverinitialization) - [System/DisableSystemRestore](./policy-csp-system.md#system-disablesystemrestore) @@ -4833,6 +4841,7 @@ The following diagram shows the Policy configuration service provider in tree fo - [Search/PreventIndexingLowDiskSpaceMB](./policy-csp-search.md#search-preventindexinglowdiskspacemb) - [Search/PreventRemoteQueries](./policy-csp-search.md#search-preventremotequeries) - [Security/ClearTPMIfNotReady](./policy-csp-security.md#security-cleartpmifnotready) +- [ServiceControlManager/SvchostProcessMitigation](./policy-csp-servicecontrolmanager.md#servicecontrolmanager-svchostprocessmitigation) - [Settings/AllowOnlineTips](./policy-csp-settings.md#settings-allowonlinetips) - [Settings/ConfigureTaskbarCalendar](./policy-csp-settings.md#settings-configuretaskbarcalendar) - [Settings/PageVisibilityList](./policy-csp-settings.md#settings-pagevisibilitylist) diff --git a/windows/client-management/mdm/policy-csp-servicecontrolmanager.md b/windows/client-management/mdm/policy-csp-servicecontrolmanager.md new file mode 100644 index 0000000000..a2558d44fc --- /dev/null +++ b/windows/client-management/mdm/policy-csp-servicecontrolmanager.md @@ -0,0 +1,115 @@ +--- +title: Policy CSP - ServiceControlManager +description: Policy CSP - ServiceControlManager +ms.author: Heidi.Lohr +ms.topic: article +ms.prod: w10 +ms.technology: windows +author: Heidilohr +ms.date: 05/10/2019 +--- + +# Policy CSP - ServiceControlManager + +> [!WARNING] +> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here. + + +
+ + +## ServiceControlManager policies + +
+
+ ServiceControlManager/SvchostProcessMitigation +
+
+ +
+ + +**ServiceControlManager/SvchostProcessMitigation** + + + + + + + + + + + + + + + + + + + + + +
HomeProBusinessEnterpriseEducationMobileMobile Enterprise
cross markcross markcheck mark6check mark6check mark6
+ + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
+ + + +This policy setting enables process mitigation options on svchost.exe processes. + +If you enable this policy setting, built-in system services hosted in svchost.exe processes will have stricter security policies enabled on them. + +This includes Microsoft to sign a policy requiring all binaries loaded on SVCHOST processes and a policy disallowing dynamically generated code. + +If you disable or do not configure this policy setting, the stricter security settings will not be applied. + + +> [!TIP] +> This is an ADMX-backed policy and requires a special SyncML format to enable or disable. For details, see [Understanding ADMX-backed policies](./understanding-admx-backed-policies.md). + +> You must specify the data type in the SyncML as <Format>chr</Format>. For an example SyncML, refer to [Enabling a policy](./understanding-admx-backed-policies.md#enabling-a-policy). + +> The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see [CDATA Sections](http://www.w3.org/TR/REC-xml/#sec-cdata-sect). + + +ADMX Info: +- GP English name: *Enable svchost.exe mitigation options* +- GP name: *SvchostProcessMitigationEnable* +- GP path: *System/Service Control Manager Settings/Security Settings* +- GP ADMX file name: *ServiceControlManager.admx* + + + +Supported values: +- disabled - Do not add ACG/CIG enforcement and other process mitigation/code integrity policies to SVCHOST processes. +- enabled - Add ACG/CIG enforcement and other process mitigation/code integrity policies to SVCHOST processes. + + + + + + + + + + + +
+ +Footnotes: + +- 1 - Added in Windows 10, version 1607. +- 2 - Added in Windows 10, version 1703. +- 3 - Added in Windows 10, version 1709. +- 4 - Added in Windows 10, version 1803. +- 5 - Added in Windows 10, version 1809. +- 6 - Added in Windows 10, version 1903. \ No newline at end of file From 0698551ddba4bd99d3d06c7550a103103680f912 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Fri, 10 May 2019 12:52:08 -0500 Subject: [PATCH 247/737] Update hello-hybrid-key-trust-prereqs.md --- .../hello-hybrid-key-trust-prereqs.md | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 1993139da7..73a2919976 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -58,7 +58,20 @@ The Windows Hello for Business deployment depends on an enterprise public key in Key trust deployments do not need client issued certificates for on-premises authentication. Active Directory user accounts are automatically configured for public key mapping by Azure AD Connect synchronizing the public key of the registered Windows Hello for Business credential to an attribute on the user's Active Directory object. -The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012. +The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012, but you can use a 3rd Party enterprise certification authority too. The detailed requieriments for the Domain Controller certificate are shown below. + +* The certificate must have a CRL distribution-point extension that points to a valid certificate revocation list (CRL). +* Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name) +* The certificate Key Usage section must contain: +Digital Signature, Key Encipherment +* Optionally, the certificate Basic Constraints section should contain: +[Subject Type=End Entity, Path Length Constraint=None] +* The certificate Enhanced Key Usage section must contain: Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1) +* The certificate Subject Alternative Name section must contain the Domain Name System (DNS) name. +* The certificate template must have an extension that has the BMP data value "DomainController." +* The domain controller certificate must be installed in the local computer's certificate store + + > [!IMPORTANT] > For Azure AD joined device to authenticate to and use on-premises resources, ensure you: From 5dc0ff8e942f0d59708af9683da3bd914bf8f5e2 Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Fri, 10 May 2019 13:19:46 -0700 Subject: [PATCH 248/737] Latest changes for 1809 issues --- .../status-windows-10-1507.yml | 22 ------------ ...indows-10-1607-and-windows-server-2016.yml | 26 ++++++-------- .../status-windows-10-1703.yml | 24 ++++++------- .../status-windows-10-1709.yml | 26 ++++++-------- .../status-windows-10-1803.yml | 28 ++++++--------- ...indows-10-1809-and-windows-server-2019.yml | 18 ++-------- ...ndows-7-and-windows-server-2008-r2-sp1.yml | 34 ++++++------------- ...windows-8.1-and-windows-server-2012-r2.yml | 26 ++++++-------- .../status-windows-server-2008-sp2.yml | 12 ------- .../status-windows-server-2012.yml | 24 ++++++------- 10 files changed, 72 insertions(+), 168 deletions(-) diff --git a/windows/release-information/status-windows-10-1507.yml b/windows/release-information/status-windows-10-1507.yml index 3cab3fb9e9..16bf511276 100644 --- a/windows/release-information/status-windows-10-1507.yml +++ b/windows/release-information/status-windows-10-1507.yml @@ -61,9 +61,6 @@ sections: text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

- - -
SummaryOriginating updateStatusLast updated
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

See details >
OS Build 10240.18094

January 08, 2019
KB4480962
Mitigated
April 25, 2019
02:00 PM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 10240.18094

January 08, 2019
KB4480962
Resolved
KB4493475
April 09, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 10240.18158

March 12, 2019
KB4489872
Resolved
KB4493475
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 10240.18132

February 12, 2019
KB4487018
Resolved
KB4493475
April 09, 2019
10:00 AM PT
" @@ -74,30 +71,11 @@ sections:
" -- title: March 2019 -- items: - - type: markdown - text: " - - -
DetailsOriginating updateStatusHistory
Custom URI schemes may not start corresponding application
After installing KB4489872, Custom URI Schemes for Application Protocol handlers may not start the corresponding application for local intranet and trusted sites on Internet Explorer.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1
Resolution: This issue was resolved in KB4493475.

Back to top
OS Build 10240.18158

March 12, 2019
KB4489872
Resolved
KB4493475
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493475

Back to top
OS Build 10240.18132

February 12, 2019
KB4487018
Resolved
KB4493475
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
- " - - title: January 2019 - items: - type: markdown text: " -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following: 
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership. 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 10240.18094

January 08, 2019
KB4480962
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480962, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue was resolved in KB4493475.

Back to top
OS Build 10240.18094

January 08, 2019
KB4480962
Resolved
KB4493475
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml b/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml index b22aced938..d444c69dac 100644 --- a/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml +++ b/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml @@ -61,16 +61,13 @@ sections: text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - - -
SummaryOriginating updateStatusLast updated
Zone transfers over TCP may fail
Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

See details >
OS Build 14393.2941

April 25, 2019
KB4493473
Investigating
April 25, 2019
02:00 PM PT
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
OS Build 14393.2931

April 25, 2019
KB4492241
Mitigated
May 10, 2019
10:35 AM PT
Cluster service may fail if the minimum password length is set to greater than 14
The cluster service may fail to start with the error “2245 (NERR_PasswordTooShort)” if the Group Policy “Minimum Password Length” is configured with greater than 14 characters.

See details >
OS Build 14393.2639

November 27, 2018
KB4467684
Mitigated
April 25, 2019
02:00 PM PT
Issue using PXE to start a device from WDS
There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

See details >
OS Build 14393.2848

March 12, 2019
KB4489882
Mitigated
April 25, 2019
02:00 PM PT
SCVMM cannot enumerate and manage logical switches deployed on the host
For hosts managed by System Center Virtual Machine Manager (VMM), VMM cannot enumerate and manage logical switches deployed on the host.

See details >
OS Build 14393.2639

November 27, 2018
KB4467684
Mitigated
April 25, 2019
02:00 PM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

See details >
OS Build 14393.2724

January 08, 2019
KB4480961
Mitigated
April 25, 2019
02:00 PM PT
Windows may not start on certain Lenovo and Fujitsu laptops with less than 8GB of RAM
Windows may fail to start on certain Lenovo and Fujitsu laptops that have less than 8 GB of RAM.

See details >
OS Build 14393.2608

November 13, 2018
KB4467691
Mitigated
February 19, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 14393.2848

March 12, 2019
KB4489882
Resolved
KB4493473
April 25, 2019
02:00 PM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system will stop working and a blue screen may appear at startup.

See details >
OS Build 14393.2879

March 19, 2019
KB4489889
Resolved
KB4493470
April 09, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

See details >
OS Build 14393.2724

January 08, 2019
KB4480961
Resolved
KB4493470
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 14393.2724

January 08, 2019
KB4480961
Resolved
KB4493470
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 14393.2791

February 12, 2019
KB4487026
Resolved
KB4493470
April 09, 2019
10:00 AM PT
" @@ -81,6 +78,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
OS Build 14393.2931

April 25, 2019
KB4492241
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -98,16 +104,6 @@ sections:
Issue using PXE to start a device from WDS
After installing KB4489882, there may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. This may cause the connection to the WDS server to terminate prematurely while downloading the image. This issue does not affect clients or devices that are not using Variable Window Extension.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: To mitigate the issue, disable the Variable Window Extension on WDS server using one of the following options:

Option 1:
Open an Administrator Command prompt and type the following:
Wdsutil /Set-TransportServer /EnableTftpVariableWindowExtension:No
 

Option 2:
Use the Windows Deployment Services UI to make the following adjustment:
  1. Open Windows Deployment Services from Windows Administrative Tools.
  2. Expand Servers and right-click a WDS server.
  3. Open its properties and clear the Enable Variable Window Extension box on the TFTP tab.
Option 3:
Set the following registry value to 0:
HKLM\\System\\CurrentControlSet\\Services\\WDSServer\\Providers\\WDSTFTP\\EnableVariableWindowExtension

Restart the WDSServer service after disabling the Variable Window Extension.

Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to topOS Build 14393.2848

March 12, 2019
KB4489882Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
After installing KB4489882, Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites security zones on Internet Explorer.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493473

Back to topOS Build 14393.2848

March 12, 2019
KB4489882Resolved
KB4493473Resolved:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT -
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system will stop working and a blue screen may appear at startup. This is not a common setting in non-Asian regions.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016
Resolution: This issue was resolved in KB4493470.

Back to topOS Build 14393.2879

March 19, 2019
KB4489889Resolved
KB4493470Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 19, 2019
10:00 AM PT - - " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493470

Back to top
OS Build 14393.2791

February 12, 2019
KB4487026
Resolved
KB4493470
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" @@ -117,8 +113,6 @@ sections: text: " - -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege. 

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507;  Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership.
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 14393.2724

January 08, 2019
KB4480961
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
After installing KB4480961, Internet Explorer 11 and other applications that use WININET.DLL may have authentication issues. This occurs when two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine, including Remote Desktop Protocol (RDP) and Terminal Server logons. Symptoms reported by customers include, but may not be limited to:
  • Cache size and location show zero or empty.
  • Keyboard shortcuts may not work properly.
  • Webpages may intermittently fail to load or render correctly.
  • Issues with credential prompts.
  • Issues when downloading files.
Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1
Resolution: This issue was resolved in KB4493470.

Back to top
OS Build 14393.2724

January 08, 2019
KB4480961
Resolved
KB4493470
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480961, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue was resolved in KB4493470.

Back to top
OS Build 14393.2724

January 08, 2019
KB4480961
Resolved
KB4493470
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-10-1703.yml b/windows/release-information/status-windows-10-1703.yml index 10d69d6cc5..c0cfa4ac36 100644 --- a/windows/release-information/status-windows-10-1703.yml +++ b/windows/release-information/status-windows-10-1703.yml @@ -60,11 +60,9 @@ sections: - type: markdown text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - -
SummaryOriginating updateStatusLast updated
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
OS Build 15063.1771

April 25, 2019
KB4492242
Mitigated
May 10, 2019
10:35 AM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

See details >
OS Build 15063.1563

January 08, 2019
KB4480973
Mitigated
April 25, 2019
02:00 PM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 15063.1689

March 12, 2019
KB4489871
Resolved
KB4493436
April 25, 2019
02:00 PM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

See details >
OS Build 15063.1716

March 19, 2019
KB4489888
Resolved
KB4493474
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 15063.1563

January 08, 2019
KB4480973
Resolved
KB4493474
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 15063.1631

February 12, 2019
KB4487020
Resolved
KB4493474
April 09, 2019
10:00 AM PT
" @@ -75,22 +73,21 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
OS Build 15063.1771

April 25, 2019
KB4492242
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: March 2019 - items: - type: markdown text: " - -
DetailsOriginating updateStatusHistory
Custom URI schemes may not start corresponding application
After installing KB4489871, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites security zones on Internet Explorer.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493436

Back to top
OS Build 15063.1689

March 12, 2019
KB4489871
Resolved
KB4493436
Resolved:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup. This is not a common setting in non-Asian regions.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016
Resolution: This issue was resolved in KB4493474.

Back to top
OS Build 15063.1716

March 19, 2019
KB4489888
Resolved
KB4493474
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 19, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493474

Back to top
OS Build 15063.1631

February 12, 2019
KB4487020
Resolved
KB4493474
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" @@ -100,6 +97,5 @@ sections: text: " -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege. 

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following: 
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership. 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 15063.1563

January 08, 2019
KB4480973
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480973, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue was resolved in KB4493474.

Back to top
OS Build 15063.1563

January 08, 2019
KB4480973
Resolved
KB4493474
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-10-1709.yml b/windows/release-information/status-windows-10-1709.yml index abdaf311b0..2618d42ebf 100644 --- a/windows/release-information/status-windows-10-1709.yml +++ b/windows/release-information/status-windows-10-1709.yml @@ -61,12 +61,9 @@ sections: text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - - -
SummaryOriginating updateStatusLast updated
Zone transfers over TCP may fail
Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

See details >
OS Build 16299.1127

April 25, 2019
KB4493440
Investigating
April 25, 2019
02:00 PM PT
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
OS Build 16299.1111

April 25, 2019
KB4492243
Mitigated
May 10, 2019
10:35 AM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

See details >
OS Build 16299.904

January 08, 2019
KB4480978
Mitigated
April 25, 2019
02:00 PM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 16299.1029

March 12, 2019
KB4489886
Resolved
KB4493440
April 25, 2019
02:00 PM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

See details >
OS Build 16299.1059

March 19, 2019
KB4489890
Resolved
KB4493441
April 09, 2019
10:00 AM PT
MSXML6 causes applications to stop responding if an exception was thrown
MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 16299.904

January 08, 2019
KB4480978
Resolved
KB4493441
April 09, 2019
10:00 AM PT
Stop error when attempting to start SSH from WSL
A stop error occurs when attempting to start Secure Shell from Windows Subsystem for Linux with agent forwarding using a command line switch (ssh –A) or a configuration setting.

See details >
OS Build 16299.1029

March 12, 2019
KB4489886
Resolved
KB4493441
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 16299.967

February 12, 2019
KB4486996
Resolved
KB4493441
April 09, 2019
10:00 AM PT
" @@ -77,6 +74,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
OS Build 16299.1111

April 25, 2019
KB4492243
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -92,17 +98,6 @@ sections: text: " - - -
DetailsOriginating updateStatusHistory
Custom URI schemes may not start corresponding application
After installing KB4489886, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites security zones on Internet Explorer.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493440

Back to top
OS Build 16299.1029

March 12, 2019
KB4489886
Resolved
KB4493440
Resolved:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup. This is not a common setting in non-Asian regions.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016
Resolution: This issue is resolved in KB4493441.

Back to top
OS Build 16299.1059

March 19, 2019
KB4489890
Resolved
KB4493441
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 19, 2019
10:00 AM PT
Stop error when attempting to start SSH from WSL
After applying KB4489886, a stop error occurs when attempting to start the Secure Shell (SSH) client program from Windows Subsystem for Linux (WSL) with agent forwarding enabled using a command line switch (ssh –A) or a configuration setting.

Affected platforms:
  • Client: Windows 10, version 1803; Windows 10, version 1709
  • Server: Windows Server, version 1803; Windows Server, version 1709
Resolution: This issue is resolved in KB4493441.

Back to top
OS Build 16299.1029

March 12, 2019
KB4489886
Resolved
KB4493441
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493441

Back to top
OS Build 16299.967

February 12, 2019
KB4486996
Resolved
KB4493441
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" @@ -112,6 +107,5 @@ sections: text: " -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege. 

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership. 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 16299.904

January 08, 2019
KB4480978
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 causes applications to stop responding if an exception was thrown
After installing KB4480978, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue is resolved in KB4493441.

Back to top
OS Build 16299.904

January 08, 2019
KB4480978
Resolved
KB4493441
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-10-1803.yml b/windows/release-information/status-windows-10-1803.yml index 3e58d9c048..9fea9cbeb3 100644 --- a/windows/release-information/status-windows-10-1803.yml +++ b/windows/release-information/status-windows-10-1803.yml @@ -61,14 +61,10 @@ sections: text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - - - -
SummaryOriginating updateStatusLast updated
Zone transfers over TCP may fail
Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

See details >
OS Build 17134.753

April 25, 2019
KB4493437
Investigating
April 25, 2019
02:00 PM PT
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
OS Build 17134.730

April 25, 2019
KB4492245
Mitigated
May 10, 2019
10:35 AM PT
Issue using PXE to start a device from WDS
Using PXE to start a device from a WDS server configured to use Variable Window Extension may cause the connection to the WDS server to terminate prematurely.

See details >
OS Build 17134.648

March 12, 2019
KB4489868
Mitigated
April 25, 2019
02:00 PM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

See details >
OS Build 17134.523

January 08, 2019
KB4480966
Mitigated
April 25, 2019
02:00 PM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 17134.648

March 12, 2019
KB4489868
Resolved
KB4493437
April 25, 2019
02:00 PM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

See details >
OS Build 17134.677

March 19, 2019
KB4489894
Resolved
KB4493464
April 09, 2019
10:00 AM PT
First character of the Japanese era name not recognized
The first character of the Japanese era name is not recognized as an abbreviation and may cause date parsing issues.

See details >
OS Build 17134.556

January 15, 2019
KB4480976
Resolved
KB4487029
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 17134.523

January 08, 2019
KB4480966
Resolved
KB4493464
April 09, 2019
10:00 AM PT
Stop error when attempting to start SSH from WSL
A stop error occurs when attempting to start Secure Shell from Windows Subsystem for Linux with agent forwarding using a command line switch (ssh –A) or a configuration setting.

See details >
OS Build 17134.648

March 12, 2019
KB4489868
Resolved
KB4493464
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 17134.590

February 12, 2019
KB4487017
Resolved
KB4493464
April 09, 2019
10:00 AM PT
" @@ -79,6 +75,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
OS Build 17134.730

April 25, 2019
KB4492245
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -96,17 +101,6 @@ sections:
Issue using PXE to start a device from WDS
After installing KB4489868, there may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. This may cause the connection to the WDS server to terminate prematurely while downloading the image. This issue does not affect clients or devices that are not using Variable Window Extension. 

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: To mitigate the issue, disable the Variable Window Extension on WDS server using one of the following options:

Option 1: 
Open an Administrator Command prompt and type the following:  
Wdsutil /Set-TransportServer /EnableTftpVariableWindowExtension:No
 

 Option 2: 
Use the Windows Deployment Services UI to make the following adjustment:  
  1. Open Windows Deployment Services from Windows Administrative Tools. 
  2. Expand Servers and right-click a WDS server. 
  3. Open its properties and clear the Enable Variable Window Extension box on the TFTP tab.  
Option 3: 
Set the following registry value to 0:
HKLM\\System\\CurrentControlSet\\Services\\WDSServer\\Providers\\WDSTFTP\\EnableVariableWindowExtension  

Restart the WDSServer service after disabling the Variable Window Extension. 
 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release. 

Back to topOS Build 17134.648

March 12, 2019
KB4489868Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
After installing KB4489868, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites security zones on Internet Explorer. 

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493437

Back to topOS Build 17134.648

March 12, 2019
KB4489868Resolved
KB4493437Resolved:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT -
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup. This is not a common setting in non-Asian regions. 

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016
Resolution: This issue was resolved in KB4493464

Back to topOS Build 17134.677

March 19, 2019
KB4489894Resolved
KB4493464Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 19, 2019
10:00 AM PT -
Stop error when attempting to start SSH from WSL
After applying KB4489868, a stop error occurs when attempting to start the Secure Shell (SSH) client program from Windows Subsystem for Linux (WSL) with agent forwarding enabled using a command line switch (ssh -A) or a configuration setting.

Affected platforms:
  • Client: Windows 10, version 1803; Windows 10, version 1709
  • Server: Windows Server, version 1803; Windows Server, version 1709
Resolution: This issue was resolved in KB4493464.

Back to topOS Build 17134.648

March 12, 2019
KB4489868Resolved
KB4493464Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT - - " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493464

Back to top
OS Build 17134.590

February 12, 2019
KB4487017
Resolved
KB4493464
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" @@ -116,7 +110,5 @@ sections: text: " - -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership. 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 17134.523

January 08, 2019
KB4480966
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
First character of the Japanese era name not recognized
After installing KB4480976, the first character of the Japanese era name is not recognized as an abbreviation and may cause date parsing issues.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Resolution: This issue is resolved in KB4487029

Back to top
OS Build 17134.556

January 15, 2019
KB4480976
Resolved
KB4487029
Resolved:
February 19, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480966, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue was resolved in KB4493464

Back to top
OS Build 17134.523

January 08, 2019
KB4480966
Resolved
KB4493464
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml b/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml index 2b50998415..afb53b80c9 100644 --- a/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml +++ b/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml @@ -65,6 +65,7 @@ sections: - type: markdown text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ @@ -73,10 +74,6 @@ sections: - - - -
SummaryOriginating updateStatusLast updated
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
OS Build 17763.475

May 03, 2019
KB4495667
Mitigated
May 10, 2019
10:35 AM PT
Devices with some Asian language packs installed may receive an error
After installing the KB4493509 devices with some Asian language packs installed may receive the error, \"0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_F

See details >
OS Build 17763.437

April 09, 2019
KB4493509
Mitigated
May 03, 2019
10:59 AM PT
Printing from Microsoft Edge or other UWP apps, you may receive the error 0x80070007
Attempting to print from Microsoft Edge or other Universal Windows Platform (UWP) applications, you may receive an error.

See details >
OS Build 17763.379

March 12, 2019
KB4489899
Mitigated
May 02, 2019
04:47 PM PT
Issue using PXE to start a device from WDS
Using PXE to start a device from a WDS server configured to use Variable Window Extension may cause the connection to the WDS server to terminate prematurely.

See details >
OS Build 17763.379

March 12, 2019
KB4489899
Mitigated
April 09, 2019
10:00 AM PT
Latest cumulative update (KB 4495667) installs automatically
Reports that the optional cumulative update (KB 4495667) installs automatically.

See details >
OS Build 17763.475

May 03, 2019
KB4495667
Resolved
May 08, 2019
03:37 PM PT
System may be unresponsive after restart if ArcaBit antivirus software installed
After further investigation ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809

See details >
OS Build 17763.437

April 09, 2019
KB4493509
Resolved
May 08, 2019
03:30 PM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
OS Build 17763.379

March 12, 2019
KB4489899
Resolved
KB4495667
May 03, 2019
12:40 PM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

See details >
OS Build 17763.404

April 02, 2019
KB4490481
Resolved
KB4493509
April 09, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

See details >
OS Build 17763.253

January 08, 2019
KB4480116
Resolved
KB4493509
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
OS Build 17763.253

January 08, 2019
KB4480116
Resolved
KB4493509
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
OS Build 17763.316

February 12, 2019
KB4487044
Resolved
KB4493509
April 09, 2019
10:00 AM PT
" @@ -92,6 +89,7 @@ sections: - type: markdown text: " + @@ -104,7 +102,6 @@ sections: text: "
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
OS Build 17763.475

May 03, 2019
KB4495667
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
Devices with some Asian language packs installed may receive an error
After installing the April 2019 Cumulative Update (KB4493509), devices with some Asian language packs installed may receive the error, \"0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_FOUND.\"

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
  • Server: Windows Server, version 1809; Windows Server 2019
Workaround:
  1. Uninstall and reinstall any recently added language packs. For instructions, see \"Manage the input and display language settings in Windows 10\".
  2. Click Check for Updates and install the April 2019 Cumulative Update. For instructions, see \"Update Windows 10\".
Note: If reinstalling the language pack does not mitigate the issue, reset your PC as follows:
  1. Go to Settings app -> Recovery.
  2. Click on Get Started under \"Reset this PC\" recovery option.
  3. Select \"Keep my Files\".
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 17763.437

April 09, 2019
KB4493509
Mitigated
Last updated:
May 03, 2019
10:59 AM PT

Opened:
May 02, 2019
04:36 PM PT
Printing from Microsoft Edge or other UWP apps, you may receive the error 0x80070007
When attempting to print from Microsoft Edge or other Universal Windows Platform (UWP) applications you may receive the error, \"Your printer has experienced an unexpected configuration problem. 0x80070007e.\"
 
Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
  • Server: Windows Server, version 1809; Windows Server 2019
Workaround: You can use another browser, such as Internet Explorer to print your documents.
 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 17763.379

March 12, 2019
KB4489899
Mitigated
Last updated:
May 02, 2019
04:47 PM PT

Opened:
May 02, 2019
04:47 PM PT
Latest cumulative update (KB 4495667) installs automatically
Due to a servicing side issue some users were offered KB4495667 (optional update) automatically and rebooted devices. This issue has been mitigated.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
  • Server: Windows Server, version 1809; Windows Server 2019
Resolution:: This issue has been mitigated on the servicing side to prevent auto installing of this update. Customers do not need to take any action.

Back to top
OS Build 17763.475

May 03, 2019
KB4495667
Resolved
Resolved:
May 08, 2019
03:37 PM PT

Opened:
May 05, 2019
12:01 PM PT
-
DetailsOriginating updateStatusHistory
System may be unresponsive after restart if ArcaBit antivirus software installed
ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809 (client or server).

Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart.

Affected platforms:
  • Client: Windows 8.1; Windows 7 SP1
  • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
Workaround: ArcaBit has released an update to address this issue for affected platforms. For more information, see the ArcaBit support article.

Resolution: This issue has been resolved. ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809 (client or server).

Back to top
OS Build 17763.437

April 09, 2019
KB4493509
Resolved
Resolved:
May 08, 2019
03:30 PM PT

Opened:
April 09, 2019
10:00 AM PT
End-user-defined characters (EUDC) may cause blue screen at startup
If you enable per font end-user-defined characters (EUDC), the system will stop working and a blue screen may appear at startup. This is not a common setting in non-Asian regions.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016
Resolution: This issue was resolved in KB4493509.

Back to top
OS Build 17763.404

April 02, 2019
KB4490481
Resolved
KB4493509
Resolved:
April 09, 2019
10:00 AM PT

Opened:
April 02, 2019
10:00 AM PT
" @@ -119,23 +116,12 @@ sections: " -- title: February 2019 -- items: - - type: markdown - text: " - - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1  
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2  
Resolution: This issue is resolved in KB4493509.  

Back to top
OS Build 17763.316

February 12, 2019
KB4487044
Resolved
KB4493509
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
- " - - title: January 2019 - items: - type: markdown text: " - -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege. 

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:  
  • Perform the operation from a process that has administrator privilege. 
  • Perform the operation from a node that doesn’t have CSV ownership. 
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
OS Build 17763.253

January 08, 2019
KB4480116
Mitigated
Last updated:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
After installing KB4480116, Internet Explorer 11 and other applications that use WININET.DLL may have authentication issues. This occurs when two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine, including Remote Desktop Protocol (RDP) and Terminal Server logons. Symptoms reported by customers include, but may not be limited to: 
  • Cache size and location show zero or empty. 
  • Keyboard shortcuts may not work properly. 
  • Webpages may intermittently fail to load or render correctly. 
  • Issues with credential prompts. 
  • Issues when downloading files. 
Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1
Resolution: This issue was resolved in KB4493509

Back to top
OS Build 17763.253

January 08, 2019
KB4480116
Resolved
KB4493509
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480116, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().
 
The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings. 

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue was resolved in KB4493509

Back to top
OS Build 17763.253

January 08, 2019
KB4480116
Resolved
KB4493509
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml index ef1b22e4bf..0ce3cb79c0 100644 --- a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml +++ b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml @@ -60,16 +60,13 @@ sections: - type: markdown text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - - -
SummaryOriginating updateStatusLast updated
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
April 25, 2019
KB4493453
Mitigated
May 10, 2019
10:35 AM PT
System may be unresponsive after restart if ArcaBit antivirus software installed
Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

See details >
April 09, 2019
KB4493472
Mitigated
May 08, 2019
03:29 PM PT
System may be unresponsive after restart if Avira antivirus software installed
Devices with Avira antivirus software installed may become unresponsive upon restart.

See details >
April 09, 2019
KB4493472
Mitigated
May 03, 2019
08:50 AM PT
Authentication may fail for services after the Kerberos ticket expires
Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

See details >
March 12, 2019
KB4489878
Mitigated
April 25, 2019
02:00 PM PT
System unresponsive after restart if Sophos Endpoint Protection installed
Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

See details >
April 09, 2019
KB4493472
Mitigated
April 25, 2019
02:00 PM PT
System may be unresponsive after restart with certain McAfee antivirus products
Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup.

See details >
April 09, 2019
KB4493472
Mitigated
April 25, 2019
02:00 PM PT
Devices may not respond at login or Welcome screen if running certain Avast software
Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

See details >
April 09, 2019
KB4493472
Resolved
April 25, 2019
02:00 PM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

See details >
January 08, 2019
KB4480970
Resolved
KB4493472
April 09, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
March 12, 2019
KB4489878
Resolved
KB4493472
April 09, 2019
10:00 AM PT
NETDOM.EXE fails to run
NETDOM.EXE fails to run and the error, “The command failed to complete successfully.” appears on screen.

See details >
March 12, 2019
KB4489878
Resolved
KB4493472
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
February 12, 2019
KB4486563
Resolved
KB4493472
April 09, 2019
10:00 AM PT
" @@ -80,6 +77,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
April 25, 2019
KB4493453
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -99,25 +105,5 @@ sections: text: " - - -
DetailsOriginating updateStatusHistory
Authentication may fail for services after the Kerberos ticket expires
After installing KB4489878, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

Affected platforms: 
  • Client: Windows 7 SP1
  • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Workaround: To mitigate this issue, use one of the following options:
  • Option 1: Purge the Kerberos tickets on the application server. After the Kerberos ticket expires, the issue will occur again, and you must purge the tickets again.
  • Option 2: If purging does not mitigate the issue, restart the application; for example, restart the Internet Information Services (IIS) app pool associated with the SQL server.
  • Option 3: Use constrained delegation.
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
March 12, 2019
KB4489878
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
After installing KB4489878, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites on Internet Explorer.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1 
Resolution: This issue is resolved in KB4493472.

Back to top
March 12, 2019
KB4489878
Resolved
KB4493472
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
NETDOM.EXE fails to run
After installing KB4489878, NETDOM.EXE fails to run, and the on-screen error, “The command failed to complete successfully.” appears.

Affected platforms: 
  • Client: Windows 7 SP1
  • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Resolution: This issue is resolved in KB4493472.

Back to top
March 12, 2019
KB4489878
Resolved
KB4493472
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly. 
 
For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color. 
 
Affected platforms:  
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493472

Back to top
February 12, 2019
KB4486563
Resolved
KB4493472
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
- " - -- title: January 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Internet Explorer 11 authentication issue with multiple concurrent logons
After installing KB4480970, Internet Explorer 11 and other applications that use WININET.DLL may have authentication issues. This occurs when two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine, including Remote Desktop Protocol (RDP) and Terminal Server logons. Symptoms reported by customers include, but may not be limited to:
  • Cache size and location show zero or empty.
  • Keyboard shortcuts may not work properly.
  • Webpages may intermittently fail to load or render correctly.
  • Issues with credential prompts.
  • Issues when downloading files.
Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493472.

Back to top
January 08, 2019
KB4480970
Resolved
KB4493472
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml index e159932ae6..a16b0e0d20 100644 --- a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml +++ b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml @@ -60,6 +60,7 @@ sections: - type: markdown text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ @@ -67,10 +68,6 @@ sections: - - - -
SummaryOriginating updateStatusLast updated
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
April 25, 2019
KB4493443
Mitigated
May 10, 2019
10:35 AM PT
System may be unresponsive after restart if ArcaBit antivirus software installed
Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

See details >
April 09, 2019
KB4493446
Mitigated
May 08, 2019
03:29 PM PT
System may be unresponsive after restart if Avira antivirus software installed
Devices with Avira antivirus software installed may become unresponsive upon restart.

See details >
April 09, 2019
KB4493446
Mitigated
May 03, 2019
08:50 AM PT
Issue using PXE to start a device from WDS
There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

See details >
March 12, 2019
KB4489881
Mitigated
April 25, 2019
02:00 PM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

See details >
January 08, 2019
KB4480963
Mitigated
April 25, 2019
02:00 PM PT
System may be unresponsive after restart with certain McAfee antivirus products
Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup.

See details >
April 09, 2019
KB4493446
Mitigated
April 18, 2019
05:00 PM PT
Devices may not respond at login or Welcome screen if running certain Avast software
Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

See details >
April 09, 2019
KB4493446
Resolved
April 25, 2019
02:00 PM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

See details >
January 08, 2019
KB4480963
Resolved
KB4493446
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding.
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
January 08, 2019
KB4480963
Resolved
KB4493446
April 09, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

See details >
March 12, 2019
KB4489881
Resolved
KB4493446
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
February 12, 2019
KB4487000
Resolved
KB4493446
April 09, 2019
10:00 AM PT
" @@ -81,6 +78,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
April 25, 2019
KB4493443
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -101,16 +107,6 @@ sections: - -
DetailsOriginating updateStatusHistory
Issue using PXE to start a device from WDS
After installing KB4489881, there may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. This may cause the connection to the WDS server to terminate prematurely while downloading the image. This issue does not affect clients or devices that are not using Variable Window Extension.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 
Workaround: To mitigate the issue, disable the Variable Window Extension on WDS server using one of the following options:

Option 1:
Open an Administrator Command prompt and type the following:
Wdsutil /Set-TransportServer /EnableTftpVariableWindowExtension:No
 

Option 2:
Use the Windows Deployment Services UI to make the following adjustment:
  1. Open Windows Deployment Services from Windows Administrative Tools.
  2. Expand Servers and right-click a WDS server.
  3. Open its properties and clear the Enable Variable Window Extension box on the TFTP tab.
Option 3:
Set the following registry value to 0:
HKLM\\System\\CurrentControlSet\\Services\\WDSServer\\Providers\\WDSTFTP\\EnableVariableWindowExtension

Restart the WDSServer service after disabling the Variable Window Extension.

Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
March 12, 2019
KB4489881
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
Custom URI schemes may not start corresponding application
After installing KB4489881, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites security zones on Internet Explorer.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1 
Resolution: This issue is resolved in KB4493446.

Back to top
March 12, 2019
KB4489881
Resolved
KB4493446
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color.

Affected platforms 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493446.

Back to top
February 12, 2019
KB4487000
Resolved
KB4493446
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" @@ -120,7 +116,5 @@ sections: text: " - -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:
  • Perform the operation from a process that has administrator privilege.
  • Perform the operation from a node that doesn’t have CSV ownership.
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
January 08, 2019
KB4480963
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
After installing KB4480963, Internet Explorer 11 and other applications that use WININET.DLL may have authentication issues. This occurs when two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine, including Remote Desktop Protocol (RDP) and Terminal Server logons. Symptoms reported by customers include, but may not be limited to:
  • Cache size and location show zero or empty.
  • Keyboard shortcuts may not work properly.
  • Webpages may intermittently fail to load or render correctly.
  • Issues with credential prompts.
  • Issues when downloading files.
Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493446.

Back to top
January 08, 2019
KB4480963
Resolved
KB4493446
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding.
After installing KB4480963, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue is resolved in KB4493446.

Back to top
January 08, 2019
KB4480963
Resolved
KB4493446
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-server-2008-sp2.yml b/windows/release-information/status-windows-server-2008-sp2.yml index 102f665769..689abfde38 100644 --- a/windows/release-information/status-windows-server-2008-sp2.yml +++ b/windows/release-information/status-windows-server-2008-sp2.yml @@ -63,8 +63,6 @@ sections:
System may be unresponsive after restart if Avira antivirus software installed
Devices with Avira antivirus software installed may become unresponsive upon restart.

See details >April 09, 2019
KB4493471Mitigated
May 03, 2019
08:51 AM PT
System unresponsive after restart if Sophos Endpoint Protection installed
Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

See details >April 09, 2019
KB4493471Mitigated
April 25, 2019
02:00 PM PT
Authentication may fail for services after the Kerberos ticket expires
Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

See details >March 12, 2019
KB4489880Mitigated
April 25, 2019
02:00 PM PT -
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >February 12, 2019
KB4487023Resolved
KB4493471April 09, 2019
10:00 AM PT -
NETDOM.EXE fails to run
NETDOM.EXE fails to run and the error, “The command failed to complete successfully.” appears on screen.

See details >March 12, 2019
KB4489880Resolved
KB4493471April 09, 2019
10:00 AM PT " @@ -91,15 +89,5 @@ sections: text: " - -
DetailsOriginating updateStatusHistory
Authentication may fail for services after the Kerberos ticket expires
After installing KB4489880, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

Affected platforms: 
  • Client: Windows 7 SP1
  • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Workaround: To mitigate this issue, use one of the following options:
  • Option 1: Purge the Kerberos tickets on the application server. After the Kerberos ticket expires, the issue will occur again, and you must purge the tickets again.
  • Option 2: If purging does not mitigate the issue, restart the application; for example, restart the Internet Information Services (IIS) app pool associated with the SQL server.
  • Option 3: Use constrained delegation.
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
March 12, 2019
KB4489880
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
March 12, 2019
10:00 AM PT
NETDOM.EXE fails to run
After installing KB4489880, NETDOM.EXE fails to run, and the on-screen error, “The command failed to complete successfully.” appears.

Affected platforms: 
  • Client: Windows 7 SP1
  • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Resolution: This issue is resolved in KB4493471.

Back to top
March 12, 2019
KB4489880
Resolved
KB4493471
Resolved:
April 09, 2019
10:00 AM PT

Opened:
March 12, 2019
10:00 AM PT
- " - -- title: February 2019 -- items: - - type: markdown - text: " - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color.

Affected platforms 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
Resolution: This issue is resolved in KB4493471.

Back to top
February 12, 2019
KB4487023
Resolved
KB4493471
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
" diff --git a/windows/release-information/status-windows-server-2012.yml b/windows/release-information/status-windows-server-2012.yml index 831a726f86..be5f206c02 100644 --- a/windows/release-information/status-windows-server-2012.yml +++ b/windows/release-information/status-windows-server-2012.yml @@ -60,13 +60,11 @@ sections: - type: markdown text: "
This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

+ - - -
SummaryOriginating updateStatusLast updated
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

See details >
April 25, 2019
KB4493462
Mitigated
May 10, 2019
10:35 AM PT
System may be unresponsive after restart if Avira antivirus software installed
Devices with Avira antivirus software installed may become unresponsive upon restart.

See details >
April 09, 2019
KB4493451
Mitigated
May 03, 2019
08:51 AM PT
Issue using PXE to start a device from WDS
There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

See details >
March 12, 2019
KB4489891
Mitigated
April 25, 2019
02:00 PM PT
System unresponsive after restart if Sophos Endpoint Protection installed
Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

See details >
April 09, 2019
KB4493451
Mitigated
April 25, 2019
02:00 PM PT
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

See details >
January 08, 2019
KB4480975
Mitigated
April 25, 2019
02:00 PM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

See details >
January 08, 2019
KB4480975
Resolved
KB4493451
April 09, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

See details >
January 08, 2019
KB4480975
Resolved
KB4493451
April 09, 2019
10:00 AM PT
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

See details >
February 12, 2019
KB4487025
Resolved
KB4493451
April 09, 2019
10:00 AM PT
" @@ -77,6 +75,15 @@ sections:
" +- title: May 2019 +- items: + - type: markdown + text: " + + +
DetailsOriginating updateStatusHistory
Layout and cell size of Excel sheets may change when using MS UI Gothic
When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

Back to top
April 25, 2019
KB4493462
Mitigated
Last updated:
May 10, 2019
10:35 AM PT

Opened:
May 10, 2019
10:35 AM PT
+ " + - title: April 2019 - items: - type: markdown @@ -97,22 +104,11 @@ sections: " -- title: February 2019 -- items: - - type: markdown - text: " - - -
DetailsOriginating updateStatusHistory
Embedded objects may display incorrectly
Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

For example, if you paste a Microsoft Excel worksheet object into a Microsoft Word document, the cells may render with a different background color.

Affected platforms 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
Resolution: This issue is resolved in KB4493451.

Back to top
February 12, 2019
KB4487025
Resolved
KB4493451
Resolved:
April 09, 2019
10:00 AM PT

Opened:
February 12, 2019
10:00 AM PT
- " - - title: January 2019 - items: - type: markdown text: " - -
DetailsOriginating updateStatusHistory
Certain operations performed on a Cluster Shared Volume may fail
Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\". This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Workaround: Do one of the following:
  • Perform the operation from a process that has administrator privilege.
  • Perform the operation from a node that doesn’t have CSV ownership.
Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

Back to top
January 08, 2019
KB4480975
Mitigated
Last updated:
April 25, 2019
02:00 PM PT

Opened:
January 08, 2019
10:00 AM PT
Internet Explorer 11 authentication issue with multiple concurrent logons
After installing KB4480975, Internet Explorer 11 and other applications that use WININET.DLL may have authentication issues. This occurs when two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine, including Remote Desktop Protocol (RDP) and Terminal Server logons. Symptoms reported by customers include, but may not be limited to:
  • Cache size and location show zero or empty.
  • Keyboard shortcuts may not work properly.
  • Webpages may intermittently fail to load or render correctly.
  • Issues with credential prompts.
  • Issues when downloading files.
Affected platforms: 
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 8.1; Windows 7 SP1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1
Resolution: This issue is resolved in KB4493451.

Back to top
January 08, 2019
KB4480975
Resolved
KB4493451
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
MSXML6 may cause applications to stop responding
After installing KB4480975, MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

The Group Policy editor may stop responding when editing a Group Policy Object (GPO) that contains Group Policy Preferences (GPP) for Internet Explorer 10 settings.

Affected platforms:
  • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
  • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
Resolution: This issue is resolved in KB4493451.

Back to top
January 08, 2019
KB4480975
Resolved
KB4493451
Resolved:
April 09, 2019
10:00 AM PT

Opened:
January 08, 2019
10:00 AM PT
" From def5857f0ea3c60546ae1a6b093000ef1ebb653c Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 10 May 2019 13:29:51 -0700 Subject: [PATCH 249/737] draft3 --- .../whats-new-windows-10-version-1903.md | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index 55b1f54d90..673f46f242 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -19,9 +19,23 @@ This article lists new and updated features and content that are of interest to >If you are not an IT Pro, see the following topics for information about what's new in Windows 10 in [hardware](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows), for [developers](https://blogs.windows.com/buildingapps/2019/04/18/start-developing-on-windows-10-may-2019-update-today/#2Lp8FUFQ3Jm8KVcq.97), and for [consumers](https://blogs.windows.com/windowsexperience/2018/04/30/whats-new-in-the-windows-10-april-2018-update). - ## Deployment +### Windows Autopilot + +The following Windows Autopilot features are available in Windows 10, version 1903 and later: + +- White glove: Windows Autopilot white glove enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. +- ESP enhancements: The Intune enrollment status page (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. +- Cortana voiceover: Cortana voiceover is disabled by default for Windows 10 Pro and above. +- Self-updating Autopilot: You can enable new Windows Autopilot functionality without updating Windows.​ + +### SetupDiag + +[SetupDiag](https://docs.microsoft.com/windows/deployment/upgrade/setupdiag) version 1.4.1 is available. + +SetupDiag is a command-line tool that can help diagnose why a Windows 10 update failed. SetupDiag works by searching Windows Setup log files. When searching log files, SetupDiag uses a set of rules to match known issues. In the current version of SetupDiag there are 53 rules contained in the rules.xml file, which is extracted when SetupDiag is run. The rules.xml file will be updated as new versions of SetupDiag are made available. + ## Configuration ## Security From ac3bb9b597ae2a230cb762bd95cf8bb28a10ea7c Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Fri, 10 May 2019 13:49:57 -0700 Subject: [PATCH 250/737] New Announcement Added --- windows/release-information/windows-message-center.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index 2a4ba41456..fb66108a56 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -50,6 +50,16 @@ sections: text: " + - + - + - +
MessageDate
Reminder: Windows 10 update servicing cadence
This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
+
    +
  • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
  • +
  • May 1, 2019 was a Windows 10, version 1809 out of band update (OOB) released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
  • +
  • May 3, 2019 was the Windows 10, version 1809 \"C\" release for April. This update contained important Japan era packages for commercial customers to preview. It was delayed due to a blocking issue requiring investigation, causing it to be released later than expected. The update was then mistakenly published as \"required\" (instead of \"optional\"), which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the classification and mitigated the issue.
  • +
+For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
+ + +
May 10, 2019
10:00 AM PT
Take action: Install servicing stack update for Windows Server 2008 SP2 for SHA-2 code sign support
A standalone update, KB4493730, that introduce SHA-2 code sign support for the servicing stack (SSU) was released today as a security update.
April 19, 2019
10:00 AM PT
The benefits of Windows 10 Dynamic Update
Dynamic Update can help organizations and end users alike ensure that their Windows 10 devices have the latest feature update content (as part of an in-place upgrade)—and preserve precious features on demand (FODs) and language packs (LPs) that may have been previously installed.

From 0b80b692f94db3055b589de8d153ccb5e7334b4b Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Fri, 10 May 2019 14:07:02 -0700 Subject: [PATCH 251/737] Latest Change for announcement --- .../windows-message-center.yml | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index fb66108a56..5990f3d920 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -50,16 +50,13 @@ sections: text: " - + From cdecc3168902b9c4de822b9696641cd71f8873e7 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Fri, 10 May 2019 15:25:55 -0700 Subject: [PATCH 253/737] new topic for multiple policies --- .../TOC.md | 1 + ...s-defender-application-control-policies.md | 43 +++++++++++++++++++ ...improvements-in-windows-10-version-1903.md | 25 +---------- 3 files changed, 45 insertions(+), 24 deletions(-) create mode 100644 windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md diff --git a/windows/security/threat-protection/windows-defender-application-control/TOC.md b/windows/security/threat-protection/windows-defender-application-control/TOC.md index 89a1b3bafb..bdaf9c0a68 100644 --- a/windows/security/threat-protection/windows-defender-application-control/TOC.md +++ b/windows/security/threat-protection/windows-defender-application-control/TOC.md @@ -16,6 +16,7 @@ #### [Microsoft recommended block rules](microsoft-recommended-block-rules.md) ### [Audit WDAC policies](audit-windows-defender-application-control-policies.md) ### [Merge WDAC policies](merge-windows-defender-application-control-policies.md) +### [Deploy multiple WDAC policies](deploy-multiple-windows-defender-application-control-policies.md) ### [Enforce WDAC policies](enforce-windows-defender-application-control-policies.md) ### [Deploy WDAC with a managed installer](use-windows-defender-application-control-with-managed-installer.md) ### [Deploy WDAC with Intelligent Security Graph (ISG)](use-windows-defender-application-control-with-intelligent-security-graph.md) diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md new file mode 100644 index 0000000000..a542e82236 --- /dev/null +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md @@ -0,0 +1,43 @@ +--- +title: Deploy multiple Windows Defender Application Control Policies (Windows 10) +description: Windows Defender Application Control supports multiple code integrity policies for one device. +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.localizationpriority: medium +author: jsuther1974 +ms.date: 05/10/2019 +--- + +# Deploy multiple Windows Defender Application Control Policies + +**Applies to:** + +- Windows 10 +- Windows Server 2016 + +>[!IMPORTANT] +>Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. + +Beginning with Windows 10 version 1903, WDAC supports multiple code integrity policies for one device. + +## Precedence + +- Multiple base policies: intersection + - Only applications allowed by both policies run without generating block events +- Base + supplemental policy: union + - Files that are allowed by the base policy or the supplemental policy are not blocked + +## Newly Supported Scenarios + +WDAC brings you the ability to support multiple CI policies. Three scenarios are now supported: + +1. Enforce and Audit Side-by-Side (Intersection) + - To validate policy changes before deploying in enforcement mode, deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy +2. Multiple Base Policies (Intersection) + - Enforce two or more base policies simultaneously to allow simpler policy targeting for policies with different scope/intent + - Ex. Base1 is a corporate standard policy that is relatively loose to accommodate all organizations while forcing minimum corp standards (e.g. Windows works + Managed Installer + path rules). Base2 is a team-specific policy that further restricts what is allowed to run (e.g. Windows works + Managed Installer + corporate signed apps only) +3. Supplemental Policies (Union) + - Deploy a supplemental policy (or policies) to expand a base policy + - Ex. The Azure host base policy restricts tightly to just allow Windows and hardware drivers. Can add a supplemental policy to allow just the additional signer rules needed to support signed code from the Exchange team. diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md index b563a2c54f..95d58415d4 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-improvements-in-windows-10-version-1903.md @@ -7,7 +7,7 @@ ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium author: jsuther1974 -ms.date: 05/06/2018 +ms.date: 05/06/2019 --- # Windows Defender Application Control improvements in Windows 10 version 1903 @@ -61,29 +61,6 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD Set-RuleOption -o 18 .\policy.xml ``` -## Multiple Policies - -Beginning with Windows 10 version 1903, WDAC supports multiple code integrity policies for one device. - -### Precedence - -- Multiple base policies: intersection - - Only applications allowed by both policies run without generating block events -- Base + supplemental policy: union - - Files that are allowed by the base policy or the supplemental policy are not blocked - -### Newly Supported Scenarios - -WDAC brings you the ability to support multiple CI policies. Three scenarios are now supported: - -1. Enforce and Audit Side-by-Side (Intersection) - - To validate policy changes before deploying in enforcement mode, deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy -2. Multiple Base Policies (Intersection) - - Enforce two or more base policies simultaneously to allow simpler policy targeting for policies with different scope/intent - - Ex. Base1 is a corporate standard policy that is relatively loose to accommodate all organizations while forcing minimum corp standards (e.g. Windows works + Managed Installer + path rules). Base2 is a team-specific policy that further restricts what is allowed to run (e.g. Windows works + Managed Installer + corporate signed apps only) -3. Supplemental Policies (Union) - - Deploy a supplemental policy (or policies) to expand a base policy - - Ex. The Azure host base policy restricts tightly to just allow Windows and hardware drivers. Can add a supplemental policy to allow just the additional signer rules needed to support signed code from the Exchange team. ## COM Whitelisting From 4a6b92476cd5d6d6b3e81b89bfafe7f0e8ffddbb Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Fri, 10 May 2019 15:47:51 -0700 Subject: [PATCH 254/737] draft --- windows/deployment/windows-autopilot/TOC.md | 1 + .../windows-autopilot/pre-provisioning.md | 22 +++++++++++++++++++ 2 files changed, 23 insertions(+) create mode 100644 windows/deployment/windows-autopilot/pre-provisioning.md diff --git a/windows/deployment/windows-autopilot/TOC.md b/windows/deployment/windows-autopilot/TOC.md index 35cd9c6cba..3b57a30541 100644 --- a/windows/deployment/windows-autopilot/TOC.md +++ b/windows/deployment/windows-autopilot/TOC.md @@ -5,6 +5,7 @@ ### [Network requirements](windows-autopilot-requirements-network.md) ### [Licensing requirements](windows-autopilot-requirements-licensing.md) ## [Scenarios and Capabilities](windows-autopilot-scenarios.md) +### [Pre-provisioning](pre-provisioning.md) ### [Support for existing devices](existing-devices.md) ### [User-driven mode](user-driven.md) #### [Azure Active Directory joined](user-driven-aad.md) diff --git a/windows/deployment/windows-autopilot/pre-provisioning.md b/windows/deployment/windows-autopilot/pre-provisioning.md new file mode 100644 index 0000000000..91a2f06219 --- /dev/null +++ b/windows/deployment/windows-autopilot/pre-provisioning.md @@ -0,0 +1,22 @@ +--- +title: Windows Autopilot pre-provisioning +description: Windows Autopilot pre-provisioning +keywords: mdm, setup, windows, windows 10, oobe, manage, deploy, autopilot, ztd, zero-touch, partner, msfb, intune +ms.prod: w10 +ms.mktglfcycl: deploy +ms.localizationpriority: low +ms.sitesec: library +ms.pagetype: deploy +author: greg-lindsay +ms.author: greg-lindsay +ms.collection: M365-modern-desktop +ms.topic: article +--- + +# Windows Autopilot pre-provisoning + +**Applies to: Windows 10, version 1903** + +With Windows 10, version 1903 and later, Windows Autopilot provides a "white glove" service enabling partners or IT staff to pre-provision a Windows 10 PC to be fully configured and business-ready for the organization or user​. + +## Prerequisites From 3f8aed8f7b7117226619b32b71b2f35501014996 Mon Sep 17 00:00:00 2001 From: Jose Ortega Date: Sat, 11 May 2019 03:22:18 -0500 Subject: [PATCH 255/737] added note for #874 --- ...ndows-operating-system-components-to-microsoft-services.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 58d06760a9..c669ded36f 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -768,7 +768,9 @@ To remove the News app: - Right-click the app in Start, and then click **Uninstall**. -or- - +>[!IMPORTANT] +> If you have any issue with this commands, go ahead a do a system reboot,and try the scripts again. +> - Remove the app for new user accounts. From an elevated command prompt, run the following Windows PowerShell command: **Get-AppxProvisionedPackage -Online | Where-Object {$\_.PackageName -Like "Microsoft.BingNews"} | ForEach-Object { Remove-AppxProvisionedPackage -Online -PackageName $\_.PackageName}** -and- From d51bdc2327b1e520721a2e53b33a06aadaa75113 Mon Sep 17 00:00:00 2001 From: illfated Date: Fri, 19 Apr 2019 16:45:28 +0200 Subject: [PATCH 256/737] Surface Hub: note for creating accounts using EAC According to user feedback, using the Exchange Admin Center to create Surface Hub device user accounts requires on-premises Active Directory to synchronize from, for that method to work. Closes #3295 --- devices/surface-hub/create-a-device-account-using-office-365.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/devices/surface-hub/create-a-device-account-using-office-365.md b/devices/surface-hub/create-a-device-account-using-office-365.md index 2d52e698c0..7166019087 100644 --- a/devices/surface-hub/create-a-device-account-using-office-365.md +++ b/devices/surface-hub/create-a-device-account-using-office-365.md @@ -217,6 +217,8 @@ In order to enable Skype for Business, your environment will need to meet the fo ## Create a device account using the Exchange Admin Center +>[!NOTE] +>This method will only work if you have an on-premises Active Directory that you are syncing from. You can use the Exchange Admin Center to create a device account: From 08adcc05c8efc4971f6ce37ca17df24e1263de0b Mon Sep 17 00:00:00 2001 From: illfated Date: Sun, 21 Apr 2019 08:09:45 +0200 Subject: [PATCH 257/737] Mobile Device Management: duplicate entry in XSD Remove duplicate entry in the XSD for the ProfileXML node in VPNv2 CSP. XSD XML lines can contain the elements - name - minOccurs - maxOccurs These elements can alter between having the values 0, 1 or unbound, but can only appear once in each XSD XML element line. Closes #1950 --- windows/client-management/mdm/vpnv2-profile-xsd.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/client-management/mdm/vpnv2-profile-xsd.md b/windows/client-management/mdm/vpnv2-profile-xsd.md index 87b64762f7..330c7fc340 100644 --- a/windows/client-management/mdm/vpnv2-profile-xsd.md +++ b/windows/client-management/mdm/vpnv2-profile-xsd.md @@ -132,7 +132,7 @@ Here's the XSD for the ProfileXML node in VPNv2 CSP for Windows 10 and some pro - + From 7c2b0b98bdea9032629c8f45266e5f5bb13a4fe9 Mon Sep 17 00:00:00 2001 From: illfated Date: Sat, 27 Apr 2019 06:45:36 +0200 Subject: [PATCH 258/737] USMT ScanState Syntax: hidden unescaped characters Asterisks, backslashes or combinations of asterisk and backslash need to be escaped for the character to migrate properly to the docs.microsoft.com site as visible text in HTML. Github shows the characters well enough, but the migration process does not seem to keep the special characters through the MarkDown-to-HTML conversion. In this PR, I have made a "best effort" attempt to resolve the missing or malformed command examples in the "USMT ScanState Syntax" page. Closes #2388 --- .../deployment/usmt/usmt-scanstate-syntax.md | 34 +++++++++---------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/windows/deployment/usmt/usmt-scanstate-syntax.md b/windows/deployment/usmt/usmt-scanstate-syntax.md index 3090160049..67c879d27a 100644 --- a/windows/deployment/usmt/usmt-scanstate-syntax.md +++ b/windows/deployment/usmt/usmt-scanstate-syntax.md @@ -455,9 +455,9 @@ By default, all users are migrated. The only way to specify which users to inclu

USMT migrates all user accounts on the computer, unless you specifically exclude an account with either the /ue or /uel options. For this reason, you do not need to specify this option on the command line. However, if you choose to specify the /all option, you cannot also use the /ui, /ue or /uel options.

- +

/ui:<ComputerName>\\<LocalUserName>

@@ -500,17 +500,17 @@ By default, all users are migrated. The only way to specify which users to inclu
  • /uel:2002/1/15 migrates users who have logged on or been modified January 15, 2002 or afterwards.

  • For example:

    -

    scanstate /i:migapp.xml /i:migdocs.xml \\server\share\migration\mystore /uel:0

    +

    scanstate /i:migapp.xml /i:migdocs.xml \\\server\share\migration\mystore /uel:0

    - +

    /ue:<ComputerName>\\<LocalUserName>

    +

    scanstate /i:migdocs.xml /i:migapp.xml \\\server\share\migration\mystore /ue:contoso\user1

    MessageDate
    Reminder: Windows 10 update servicing cadence
    This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
    -
      -
    • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
    • -
    • May 1, 2019 was a Windows 10, version 1809 out of band update (OOB) released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • -
    • May 3, 2019 was the Windows 10, version 1809 \"C\" release for April. This update contained important Japan era packages for commercial customers to preview. It was delayed due to a blocking issue requiring investigation, causing it to be released later than expected. The update was then mistakenly published as \"required\" (instead of \"optional\"), which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the classification and mitigated the issue.
    • -
    -For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
    - - -
    May 10, 2019
    10:00 AM PT
    Reminder: Windows 10 update servicing cadence
    This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
    +
      +
    • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
    • +
    • May 1, 2019 was an \"optional\" out of band update (OOB), non-security update for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • +
    • May 3, 2019 was the \"optional\" Windows 10, version 1809 \"C\" release for April. This update contained important Japanese era packages for commercial customers to preview. It was released later than expected and mistakenly targeted as \"required\" (instead of \"optional\") for consumers, which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the targeting logic and mitigated the issue.
    • +
    + For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
    May 10, 2019
    10:00 AM PT
    Take action: Install servicing stack update for Windows Server 2008 SP2 for SHA-2 code sign support
    A standalone update, KB4493730, that introduce SHA-2 code sign support for the servicing stack (SSU) was released today as a security update.
    April 19, 2019
    10:00 AM PT
    The benefits of Windows 10 Dynamic Update
    Dynamic Update can help organizations and end users alike ensure that their Windows 10 devices have the latest feature update content (as part of an in-place upgrade)—and preserve precious features on demand (FODs) and language packs (LPs) that may have been previously installed.

    From 9928a0c615f9ec727ca9b389f9b6786aa7797dc9 Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Fri, 10 May 2019 14:41:55 -0700 Subject: [PATCH 252/737] Updated link for japanese era content --- windows/release-information/windows-message-center.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index 5990f3d920..64f62b302e 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -54,7 +54,7 @@ sections:
    • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
    • May 1, 2019 was an \"optional\" out of band update (OOB), non-security update for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • -
    • May 3, 2019 was the \"optional\" Windows 10, version 1809 \"C\" release for April. This update contained important Japanese era packages for commercial customers to preview. It was released later than expected and mistakenly targeted as \"required\" (instead of \"optional\") for consumers, which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the targeting logic and mitigated the issue.
    • +
    • May 3, 2019 was the \"optional\" Windows 10, version 1809 \"C\" release for April. This update contained important Japanese era packages for commercial customers to preview. It was released later than expected and mistakenly targeted as \"required\" (instead of \"optional\") for consumers, which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the targeting logic and mitigated the issue.
    For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
    May 10, 2019
    10:00 AM PT
    Take action: Install servicing stack update for Windows Server 2008 SP2 for SHA-2 code sign support
    A standalone update, KB4493730, that introduce SHA-2 code sign support for the servicing stack (SSU) was released today as a security update.
    April 19, 2019
    10:00 AM PT

    /ui:<DomainName>\<UserName>

    +

    /ui:<DomainName>\\<UserName>

    or

    -

    /ui:<ComputerName>\<LocalUserName>

    (User include)

    Migrates the specified users. By default, all users are included in the migration. Therefore, this option is helpful only when used with the /ue or /uel options. You can specify multiple /ui options, but you cannot use the /ui option with the /all option. DomainName and UserName can contain the asterisk (*) wildcard character. When you specify a user name that contains spaces, you will need to surround it with quotation marks.

    @@ -469,10 +469,10 @@ By default, all users are migrated. The only way to specify which users to inclu

    For example:

      -
    • To include only User2 from the Fabrikam domain, type:

      -

      /ue:*\* /ui:fabrikam\user2

    • -
    • To migrate all users from the Fabrikam domain, and only the user accounts from other domains that have been active or otherwise modified in the last 30 days, type:

      -

      /uel:30 /ui:fabrikam\*

      +

      To include only User2 from the Fabrikam domain, type:

      +

      /ue:\*\\\* /ui:fabrikam\user2

      +

      To migrate all users from the Fabrikam domain, and only the user accounts from other domains that have been active or otherwise modified in the last 30 days, type:

      +

      /uel:30 /ui:fabrikam\\\*

      In this example, a user account from the Contoso domain that was last modified 2 months ago will not be migrated.

    For more examples, see the descriptions of the /ue and /ui options in this table.

    /ue:<DomainName>\<UserName>

    +

    /ue:<DomainName>\\<UserName>

    -or-

    -

    /ue:<ComputerName>\<LocalUserName>

    (User exclude)

    Excludes the specified users from the migration. You can specify multiple /ue options. You cannot use this option with the /all option. <DomainName> and <UserName> can contain the asterisk (*) wildcard character. When you specify a user name that contains spaces, you need to surround it with quotation marks.

    For example:

    -

    scanstate /i:migdocs.xml /i:migapp.xml \\server\share\migration\mystore /ue:contoso\user1

    @@ -548,15 +548,15 @@ The following examples apply to both the /**ui** and /**ue** options. You can re

    Exclude all domain users.

    /ue:Domain\*

    /ue:Domain\\\*

    Exclude all local users.

    /ue:%computername%\*

    /ue:%computername%\\\*

    Exclude users in all domains named User1, User2, and so on.

    /ue:*\user*

    /ue:\*\user\*

    @@ -586,23 +586,23 @@ The /**uel** option takes precedence over the /**ue** option. If a user has logg

    Include only User2 from the Fabrikam domain and exclude all other users.

    -

    /ue:*\* /ui:fabrikam\user2

    +

    /ue:\*\\\* /ui:fabrikam\user2

    Include only the local user named User1 and exclude all other users.

    -

    /ue:*\* /ui:user1

    +

    /ue:\*\\\* /ui:user1

    Include only the domain users from Contoso, except Contoso\User1.

    This behavior cannot be completed using a single command. Instead, to migrate this set of users, you will need to specify the following:

      -
    • On the ScanState command line, type: /ue:*\* /ui:contoso\*

    • +
    • On the ScanState command line, type: /ue:\*\\\* /ui:contoso\*

    • On the LoadState command line, type: /ue:contoso\user1

    Include only local (non-domain) users.

    -

    /ue:*\* /ui:%computername%\*

    +

    /ue:\*\\\* /ui:%computername%\\\*

    From 0c29aa345115c4123bf56a0990cc79c8ea108645 Mon Sep 17 00:00:00 2001 From: illfated Date: Sat, 27 Apr 2019 07:39:02 +0200 Subject: [PATCH 259/737] Use ASCII character codes instead of backslash - change from using backslashes as escape character to use \ as the direct character for backslash - replace asterisks with * where needed --- .../deployment/usmt/usmt-scanstate-syntax.md | 30 +++++++++---------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/windows/deployment/usmt/usmt-scanstate-syntax.md b/windows/deployment/usmt/usmt-scanstate-syntax.md index 67c879d27a..15e9ea1b2d 100644 --- a/windows/deployment/usmt/usmt-scanstate-syntax.md +++ b/windows/deployment/usmt/usmt-scanstate-syntax.md @@ -455,9 +455,9 @@ By default, all users are migrated. The only way to specify which users to inclu

    USMT migrates all user accounts on the computer, unless you specifically exclude an account with either the /ue or /uel options. For this reason, you do not need to specify this option on the command line. However, if you choose to specify the /all option, you cannot also use the /ui, /ue or /uel options.

    -

    /ui:<DomainName>\\<UserName>

    +

    /ui:<DomainName>\<UserName>

    or

    -

    /ui:<ComputerName>\\<LocalUserName>

    +

    /ui:<ComputerName>\<LocalUserName>

    (User include)

    Migrates the specified users. By default, all users are included in the migration. Therefore, this option is helpful only when used with the /ue or /uel options. You can specify multiple /ui options, but you cannot use the /ui option with the /all option. DomainName and UserName can contain the asterisk (*) wildcard character. When you specify a user name that contains spaces, you will need to surround it with quotation marks.

    @@ -470,9 +470,9 @@ By default, all users are migrated. The only way to specify which users to inclu

    For example:

      To include only User2 from the Fabrikam domain, type:

      -

      /ue:\*\\\* /ui:fabrikam\user2

      +

      /ue:*\* /ui:fabrikam\user2

      To migrate all users from the Fabrikam domain, and only the user accounts from other domains that have been active or otherwise modified in the last 30 days, type:

      -

      /uel:30 /ui:fabrikam\\\*

      +

      /uel:30 /ui:fabrikam\*

      In this example, a user account from the Contoso domain that was last modified 2 months ago will not be migrated.

    For more examples, see the descriptions of the /ue and /ui options in this table.

    @@ -500,17 +500,17 @@ By default, all users are migrated. The only way to specify which users to inclu
  • /uel:2002/1/15 migrates users who have logged on or been modified January 15, 2002 or afterwards.

  • For example:

    -

    scanstate /i:migapp.xml /i:migdocs.xml \\\server\share\migration\mystore /uel:0

    +

    scanstate /i:migapp.xml /i:migdocs.xml \\server\share\migration\mystore /uel:0

    -

    /ue:<DomainName>\\<UserName>

    +

    /ue:<DomainName>\<UserName>

    -or-

    -

    /ue:<ComputerName>\\<LocalUserName>

    +

    /ue:<ComputerName>\<LocalUserName>

    (User exclude)

    Excludes the specified users from the migration. You can specify multiple /ue options. You cannot use this option with the /all option. <DomainName> and <UserName> can contain the asterisk (*) wildcard character. When you specify a user name that contains spaces, you need to surround it with quotation marks.

    For example:

    -

    scanstate /i:migdocs.xml /i:migapp.xml \\\server\share\migration\mystore /ue:contoso\user1

    +

    scanstate /i:migdocs.xml /i:migapp.xml \\server\share\migration\mystore /ue:contoso\user1

    @@ -548,15 +548,15 @@ The following examples apply to both the /**ui** and /**ue** options. You can re

    Exclude all domain users.

    -

    /ue:Domain\\\*

    +

    /ue:Domain\*

    Exclude all local users.

    -

    /ue:%computername%\\\*

    +

    /ue:%computername%\*

    Exclude users in all domains named User1, User2, and so on.

    -

    /ue:\*\user\*

    +

    /ue:*\user*

    @@ -586,23 +586,23 @@ The /**uel** option takes precedence over the /**ue** option. If a user has logg

    Include only User2 from the Fabrikam domain and exclude all other users.

    -

    /ue:\*\\\* /ui:fabrikam\user2

    +

    /ue:*\* /ui:fabrikam\user2

    Include only the local user named User1 and exclude all other users.

    -

    /ue:\*\\\* /ui:user1

    +

    /ue:*\* /ui:user1

    Include only the domain users from Contoso, except Contoso\User1.

    This behavior cannot be completed using a single command. Instead, to migrate this set of users, you will need to specify the following:

      -
    • On the ScanState command line, type: /ue:\*\\\* /ui:contoso\*

    • +
    • On the ScanState command line, type: /ue:*\* /ui:contoso\*

    • On the LoadState command line, type: /ue:contoso\user1

    Include only local (non-domain) users.

    -

    /ue:\*\\\* /ui:%computername%\\\*

    +

    /ue:*\* /ui:%computername%\*

    From 4841ee484624fccc9d8d0145a51e48ab0e9046d0 Mon Sep 17 00:00:00 2001 From: illfated Date: Fri, 10 May 2019 23:38:20 +0200 Subject: [PATCH 260/737] Microsoft Accounts: small typo correction Change proposed: change the typo "a mean of identifying a user" to `a means of identifying a user` Closes #3601 --- .../identity-protection/access-control/microsoft-accounts.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/access-control/microsoft-accounts.md b/windows/security/identity-protection/access-control/microsoft-accounts.md index 38c26d9546..18d956384e 100644 --- a/windows/security/identity-protection/access-control/microsoft-accounts.md +++ b/windows/security/identity-protection/access-control/microsoft-accounts.md @@ -22,7 +22,7 @@ ms.date: 10/13/2017 This topic for the IT professional explains how a Microsoft account works to enhance security and privacy for users, and how you can manage this consumer account type in your organization. -Microsoft sites, services, and properties, as well as computers running Windows 10, can use a Microsoft account as a mean of identifying a user. Microsoft account was previously called Windows Live ID. It has user-defined secrets, and consists of a unique email address and a password. +Microsoft sites, services, and properties, as well as computers running Windows 10, can use a Microsoft account as a means of identifying a user. Microsoft account was previously called Windows Live ID. It has user-defined secrets, and consists of a unique email address and a password. When a user signs in with a Microsoft account, the device is connected to cloud services. Many of the user's settings, preferences, and apps can be shared across devices. From 5b409467b1ef06aeeaaa6c6d221931236db7c141 Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Sat, 11 May 2019 14:21:14 +0200 Subject: [PATCH 261/737] Update advanced-security-audit-policy-settings.md Typo line 93 fixes https://github.com/MicrosoftDocs/windows-itpro-docs/issues/3587 --- .../auditing/advanced-security-audit-policy-settings.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md b/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md index 842cb0b7bb..6ce2b1bc64 100644 --- a/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md +++ b/windows/security/threat-protection/auditing/advanced-security-audit-policy-settings.md @@ -90,7 +90,7 @@ Logon/Logoff security policy settings and audit events allow you to track attemp ## Object Access -Object Access policy settings and audit events allow you to track attempts to access specific objects or types of objects on a network or computer. To audit attempts to access a file, directory, registry key, or any other object, you must enable the appropriate object Aaccess auditing subcategory for success and/or failure events. For example, the file system subcategory needs to be enabled to audit file operations, and the Registry subcategory needs to be enabled to audit registry accesses. +Object Access policy settings and audit events allow you to track attempts to access specific objects or types of objects on a network or computer. To audit attempts to access a file, directory, registry key, or any other object, you must enable the appropriate Object Access auditing subcategory for success and/or failure events. For example, the file system subcategory needs to be enabled to audit file operations, and the Registry subcategory needs to be enabled to audit registry accesses. Proving that these audit policies are in effect to an external auditor is more difficult. There is no easy way to verify that the proper SACLs are set on all inherited objects. To address this issue, see [Global Object Access Auditing](#global-object-access-auditing). From 4ff728b4c6f1025ad8413725522693400c7fcea9 Mon Sep 17 00:00:00 2001 From: Jose Ortega Date: Sat, 11 May 2019 12:09:40 -0500 Subject: [PATCH 262/737] @Illfated corrections --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index c669ded36f..2c21af8eba 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -769,7 +769,7 @@ To remove the News app: -or- >[!IMPORTANT] -> If you have any issue with this commands, go ahead a do a system reboot,and try the scripts again. +> If you have any issue with these commands, go ahead a do a system reboot, and try the scripts again. > - Remove the app for new user accounts. From an elevated command prompt, run the following Windows PowerShell command: **Get-AppxProvisionedPackage -Online | Where-Object {$\_.PackageName -Like "Microsoft.BingNews"} | ForEach-Object { Remove-AppxProvisionedPackage -Online -PackageName $\_.PackageName}** From ffd29448058dc6c7a1525031b726a6ec6af15b45 Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Sat, 11 May 2019 11:13:14 -0700 Subject: [PATCH 263/737] Made some change in Announcement. --- windows/release-information/windows-message-center.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index 64f62b302e..bcea3b01d7 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -53,7 +53,7 @@ sections: Reminder: Windows 10 update servicing cadence
    This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
    • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
    • -
    • May 1, 2019 was an \"optional\" out of band update (OOB), non-security update for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • +
    • May 1, 2019 was an \"optional,\" out of band non-security update (OOB) for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • May 3, 2019 was the \"optional\" Windows 10, version 1809 \"C\" release for April. This update contained important Japanese era packages for commercial customers to preview. It was released later than expected and mistakenly targeted as \"required\" (instead of \"optional\") for consumers, which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the targeting logic and mitigated the issue.
    For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
    May 10, 2019
    10:00 AM PT From a7bcfabadcbf92e5d4bbd3f63c6d8ec9c4837779 Mon Sep 17 00:00:00 2001 From: DocsPreview <49669258+DocsPreview@users.noreply.github.com> Date: Sat, 11 May 2019 12:19:38 -0700 Subject: [PATCH 264/737] Release info preview (#164) (#165) * Latest changes for 1809 issues * New Announcement Added * Latest Change for announcement * Updated link for japanese era content * Made some change in Announcement. --- windows/release-information/windows-message-center.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index 64f62b302e..bcea3b01d7 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -53,7 +53,7 @@ sections: Reminder: Windows 10 update servicing cadence
    This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
    • April 9, 2019 was the regular Update Tuesday release for all versions of Windows.
    • -
    • May 1, 2019 was an \"optional\" out of band update (OOB), non-security update for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • +
    • May 1, 2019 was an \"optional,\" out of band non-security update (OOB) for Windows 10, version 1809. It was released to Microsoft Catalog and WSUS, providing a critical fix for our OEM partners.
    • May 3, 2019 was the \"optional\" Windows 10, version 1809 \"C\" release for April. This update contained important Japanese era packages for commercial customers to preview. It was released later than expected and mistakenly targeted as \"required\" (instead of \"optional\") for consumers, which pushed the update out to customers and required a reboot. Within 24 hours of receiving customer reports, we corrected the targeting logic and mitigated the issue.
    For more information about the Windows 10 update servicing cadence, please see the Window IT Pro blog.
    May 10, 2019
    10:00 AM PT From 7c787e3a2c8fe1754a18470c91cc3d0669dbb033 Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Sat, 11 May 2019 14:47:53 -0500 Subject: [PATCH 265/737] More Illfated corrections :) thank you Co-Authored-By: Trond B. Krokli <38162891+illfated@users.noreply.github.com> --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 2c21af8eba..67e8c2419e 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -769,7 +769,7 @@ To remove the News app: -or- >[!IMPORTANT] -> If you have any issue with these commands, go ahead a do a system reboot, and try the scripts again. +> If you have any issues with these commands, do a system reboot and try the scripts again. > - Remove the app for new user accounts. From an elevated command prompt, run the following Windows PowerShell command: **Get-AppxProvisionedPackage -Online | Where-Object {$\_.PackageName -Like "Microsoft.BingNews"} | ForEach-Object { Remove-AppxProvisionedPackage -Online -PackageName $\_.PackageName}** From 36ad8a02943d2ffd1f48afacc1edc1ff613d3d50 Mon Sep 17 00:00:00 2001 From: sccmentor Date: Sun, 12 May 2019 11:18:47 +0100 Subject: [PATCH 266/737] Update waas-manage-updates-wufb.md --- windows/deployment/update/waas-manage-updates-wufb.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/deployment/update/waas-manage-updates-wufb.md b/windows/deployment/update/waas-manage-updates-wufb.md index be96b68e59..19a38e1f89 100644 --- a/windows/deployment/update/waas-manage-updates-wufb.md +++ b/windows/deployment/update/waas-manage-updates-wufb.md @@ -85,13 +85,13 @@ Starting with Windows 10, version 1709, the Windows Update for Business settings | Manage Windows Insider Preview builds | System/AllowBuildPreview | Update/ManagePreviewBuilds | | Manage when updates are received | Select when Feature Updates are received | Select when Preview Builds and Feature Updates are received (Update/BranchReadinessLevel) | -## Managing Windows Update for Business with Software Center Configuration Manager +## Managing Windows Update for Business with System Center Configuration Manager -Starting with Windows 10, version 1709, you can assign a collection of devices to have dual scan enabled and manage that collection with Windows Update for Business policies. Starting with Windows 10, version 1809, you can set a collection of devices to receive the Windows Insider Preview Feature Updates from Windows Update from within Software Center Configuration Manager. +Starting with Windows 10, version 1709, you can assign a collection of devices to have dual scan enabled and manage that collection with Windows Update for Business policies. Starting with Windows 10, version 1809, you can set a collection of devices to receive the Windows Insider Preview Feature Updates from Windows Update from within System Center Configuration Manager. | Action | Windows 10 versions between 1709 and 1809 | Windows 10 versions after 1809 | | --- | --- | --- | -| Manage Windows Update for Business in Configuration Manager | Manage Feature or Quality Updates with Windows Update for Business via Dual Scan | Manage Insider pre-release builds with Windows Update for Business within Software Center Configuration Manager | +| Manage Windows Update for Business in Configuration Manager | Manage Feature or Quality Updates with Windows Update for Business via Dual Scan | Manage Insider pre-release builds with Windows Update for Business within System Center Configuration Manager | ## Managing Windows Update for Business with Windows Settings options Windows Settings includes options to control certain Windows Update for Business features: From 12147107edb489af66f821a83bf816fdfafa1258 Mon Sep 17 00:00:00 2001 From: Lindsay <45809756+lindspea@users.noreply.github.com> Date: Mon, 13 May 2019 07:18:18 +0200 Subject: [PATCH 267/737] Update appv-creating-and-managing-virtualized-applications.md Updated extensions. --- ...reating-and-managing-virtualized-applications.md | 13 ++----------- 1 file changed, 2 insertions(+), 11 deletions(-) diff --git a/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md b/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md index dca1b3b048..a2e9327cb3 100644 --- a/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md +++ b/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md @@ -93,20 +93,11 @@ The following table lists the supported shell extensions: Copy on write (CoW) file extensions allow App-V to dynamically write to specific locations contained in the virtual package while it is being used. -The following table displays the file types that can exist in a virtual package under the VFS directory, but cannot be updated on the computer running the App-V client. All other files and directories can be modified. +The following table displays the file types that can exist in a virtual package under the VFS directory, since App-V 5.1, but cannot be updated on the computer running the App-V client. All other files and directories can be modified. | File Type|||||| |---|---|---|---|---|---| -| .acm | .asa | .asp | .aspx | .ax | .bat | -| .cer | .chm | .clb | .cmd | .cnt | .cnv | -| .com | .cpl | .cpx | .crt | .dll | .drv | -| .esc | .exe | .fon | .grp | .hlp | .hta | -| .ime | .inf | .ins | .isp | .its | .js | -| .jse | .lnk | .msc | .msi | .msp | .mst | -| .mui | .nls | .ocx | .pal | .pcd | .pif | -| .reg | .scf | .scr | .sct | .shb | .shs | -| .sys | .tlb | .tsp | .url | .vb | .vbe | -| .vbs | .vsmacros | .ws | .wsf | .wsh | | +| .com | .exe | .dll | .ocx | | ## Modifying an existing virtual application package From 412888018f32607672f3e3a839a30e579cee5b26 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Mon, 13 May 2019 17:08:19 +0500 Subject: [PATCH 268/737] update microsoft-store-for-business-overview.md --- store-for-business/microsoft-store-for-business-overview.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/store-for-business/microsoft-store-for-business-overview.md b/store-for-business/microsoft-store-for-business-overview.md index 0bf1fdc2d4..f6afc25250 100644 --- a/store-for-business/microsoft-store-for-business-overview.md +++ b/store-for-business/microsoft-store-for-business-overview.md @@ -28,8 +28,8 @@ Organizations or schools of any size can benefit from using Microsoft Store for - **Scales to fit the size of your business** - For smaller businesses, with Azure AD accounts or Office 365 accounts and Windows 10 devices, you can quickly have an end-to-end process for acquiring and distributing content using the Store for Business. For larger businesses, all the capabilities of the Store for Business are available to you, or you can integrate Microsoft Store for Business with management tools, for greater control over access to apps and app updates. You can use existing work or school accounts. - **Bulk app acquisition** - Acquire apps in volume from Microsoft Store for Business. - **Centralized management** – Microsoft Store provides centralized management for inventory, billing, permissions, and order history. You can use Microsoft Store to view, manage and distribute items purchased from: - - **Microsoft Store for Business** – Apps and subscriptions - - **Microsoft Store for Education** – Apps and subscriptions + - **Microsoft Store for Business** – Apps acquired from Microsoft Store for Business + - **Microsoft Store for Education** – Apps acquired from Microsoft Store for Education - **Office 365** – Subscriptions - **Volume licensing** - Apps purchased with volume licensing - **Private store** - Create a private store for your business that’s easily available from any Windows 10 device. Your private store is available from Microsoft Store on Windows 10, or with a browser on the Web. People in your organization can download apps from your organization's private store on Windows 10 devices. From bc4f9a20eb45721386f3bfb236894d72c009c331 Mon Sep 17 00:00:00 2001 From: Lindsay <45809756+lindspea@users.noreply.github.com> Date: Mon, 13 May 2019 18:09:47 +0200 Subject: [PATCH 269/737] Update windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com> --- .../appv-creating-and-managing-virtualized-applications.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md b/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md index a2e9327cb3..9a68fb9338 100644 --- a/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md +++ b/windows/application-management/app-v/appv-creating-and-managing-virtualized-applications.md @@ -93,7 +93,7 @@ The following table lists the supported shell extensions: Copy on write (CoW) file extensions allow App-V to dynamically write to specific locations contained in the virtual package while it is being used. -The following table displays the file types that can exist in a virtual package under the VFS directory, since App-V 5.1, but cannot be updated on the computer running the App-V client. All other files and directories can be modified. +The following table displays the file types that can exist in a virtual package under the VFS directory, since App-V 5.1, but which cannot be updated on the computer running the App-V client. All other files and directories can be modified. | File Type|||||| |---|---|---|---|---|---| From d42a7b0c3b97ca0c8f40495219e917f95e764845 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 11:57:49 -0500 Subject: [PATCH 270/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 73a2919976..2e9bd1375c 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -58,7 +58,7 @@ The Windows Hello for Business deployment depends on an enterprise public key in Key trust deployments do not need client issued certificates for on-premises authentication. Active Directory user accounts are automatically configured for public key mapping by Azure AD Connect synchronizing the public key of the registered Windows Hello for Business credential to an attribute on the user's Active Directory object. -The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012, but you can use a 3rd Party enterprise certification authority too. The detailed requieriments for the Domain Controller certificate are shown below. +The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012, but you can also use a third-party enterprise certification authority. The detailed requirements for the Domain Controller certificate are shown below. * The certificate must have a CRL distribution-point extension that points to a valid certificate revocation list (CRL). * Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name) From 250089d828d765c881cb41693a911bf249907ea8 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 11:58:41 -0500 Subject: [PATCH 271/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 2e9bd1375c..cfa4d2724c 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -60,7 +60,7 @@ Key trust deployments do not need client issued certificates for on-premises aut The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012, but you can also use a third-party enterprise certification authority. The detailed requirements for the Domain Controller certificate are shown below. -* The certificate must have a CRL distribution-point extension that points to a valid certificate revocation list (CRL). +* The certificate must have a Certificate Revocation List (CRL) distribution point extension that points to a valid CRL. * Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name) * The certificate Key Usage section must contain: Digital Signature, Key Encipherment From 70f35d9b556ca77586782b3fa234d89b59e7ebee Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 11:59:11 -0500 Subject: [PATCH 272/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index cfa4d2724c..8e2a006a40 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -61,7 +61,7 @@ Key trust deployments do not need client issued certificates for on-premises aut The minimum required enterprise certificate authority that can be used with Windows Hello for Business is Windows Server 2012, but you can also use a third-party enterprise certification authority. The detailed requirements for the Domain Controller certificate are shown below. * The certificate must have a Certificate Revocation List (CRL) distribution point extension that points to a valid CRL. -* Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name) +* Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name). * The certificate Key Usage section must contain: Digital Signature, Key Encipherment * Optionally, the certificate Basic Constraints section should contain: From 6f1af988debf6ac45f39b9d2dd82f20f68fad894 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 11:59:46 -0500 Subject: [PATCH 273/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 8e2a006a40..fa127fbc9c 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -63,7 +63,6 @@ The minimum required enterprise certificate authority that can be used with Wind * The certificate must have a Certificate Revocation List (CRL) distribution point extension that points to a valid CRL. * Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name). * The certificate Key Usage section must contain: -Digital Signature, Key Encipherment * Optionally, the certificate Basic Constraints section should contain: [Subject Type=End Entity, Path Length Constraint=None] * The certificate Enhanced Key Usage section must contain: Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1) From 479a1ff8734f6d075d3ef75328f6d9013145d24b Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 12:00:13 -0500 Subject: [PATCH 274/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index fa127fbc9c..5255ad8eec 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -62,7 +62,7 @@ The minimum required enterprise certificate authority that can be used with Wind * The certificate must have a Certificate Revocation List (CRL) distribution point extension that points to a valid CRL. * Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name). -* The certificate Key Usage section must contain: +* The certificate Key Usage section must contain Digital Signature and Key Encipherment. * Optionally, the certificate Basic Constraints section should contain: [Subject Type=End Entity, Path Length Constraint=None] * The certificate Enhanced Key Usage section must contain: Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1) From 72371c8e34b8d360a8036c9f662f20da9f9debe2 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 12:00:31 -0500 Subject: [PATCH 275/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 5255ad8eec..dfe1bdb31d 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -65,7 +65,7 @@ The minimum required enterprise certificate authority that can be used with Wind * The certificate Key Usage section must contain Digital Signature and Key Encipherment. * Optionally, the certificate Basic Constraints section should contain: [Subject Type=End Entity, Path Length Constraint=None] -* The certificate Enhanced Key Usage section must contain: Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1) +* The certificate Enhanced Key Usage section must contain Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1). * The certificate Subject Alternative Name section must contain the Domain Name System (DNS) name. * The certificate template must have an extension that has the BMP data value "DomainController." * The domain controller certificate must be installed in the local computer's certificate store From 6f42299166ef7a8eb90d449098abd5fd088c077a Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 12:00:54 -0500 Subject: [PATCH 276/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index dfe1bdb31d..c6ad8bf880 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -64,7 +64,6 @@ The minimum required enterprise certificate authority that can be used with Wind * Optionally, the certificate Subject section should contain the directory path of the server object (the distinguished name). * The certificate Key Usage section must contain Digital Signature and Key Encipherment. * Optionally, the certificate Basic Constraints section should contain: -[Subject Type=End Entity, Path Length Constraint=None] * The certificate Enhanced Key Usage section must contain Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1). * The certificate Subject Alternative Name section must contain the Domain Name System (DNS) name. * The certificate template must have an extension that has the BMP data value "DomainController." From dca438d5b4f8cbf5c36ad1d1d5085956a2a00dd4 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 12:01:09 -0500 Subject: [PATCH 277/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index c6ad8bf880..86afa736bf 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -66,7 +66,7 @@ The minimum required enterprise certificate authority that can be used with Wind * Optionally, the certificate Basic Constraints section should contain: * The certificate Enhanced Key Usage section must contain Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1). * The certificate Subject Alternative Name section must contain the Domain Name System (DNS) name. -* The certificate template must have an extension that has the BMP data value "DomainController." +* The certificate template must have an extension that has the BMP data value "DomainController". * The domain controller certificate must be installed in the local computer's certificate store From 3aa10bc1504fdadd15316df6265672b3d99120bb Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Mon, 13 May 2019 12:01:35 -0500 Subject: [PATCH 278/737] Update windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index 86afa736bf..9b3432c015 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -67,7 +67,7 @@ The minimum required enterprise certificate authority that can be used with Wind * The certificate Enhanced Key Usage section must contain Client Authentication (1.3.6.1.5.5.7.3.2) and Server Authentication (1.3.6.1.5.5.7.3.1). * The certificate Subject Alternative Name section must contain the Domain Name System (DNS) name. * The certificate template must have an extension that has the BMP data value "DomainController". -* The domain controller certificate must be installed in the local computer's certificate store +* The domain controller certificate must be installed in the local computer's certificate store. From 30fc0eb470c713b6033ea489012349cee8376656 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Mon, 13 May 2019 11:31:03 -0700 Subject: [PATCH 279/737] Update TOC.md --- windows/privacy/TOC.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/privacy/TOC.md b/windows/privacy/TOC.md index 35561d07af..b687b5bc1b 100644 --- a/windows/privacy/TOC.md +++ b/windows/privacy/TOC.md @@ -20,7 +20,9 @@ ### [Connection endpoints for Windows 10, version 1709](manage-windows-1709-endpoints.md) ### [Connection endpoints for Windows 10, version 1803](manage-windows-1803-endpoints.md) ### [Connection endpoints for Windows 10, version 1809](manage-windows-1809-endpoints.md) +### [Connection endpoints for Windows 10, version 1903](manage-windows-1903-endpoints.md) ### [Windows 10, version 1709, connection endpoints for non-Enterprise editions](windows-endpoints-1709-non-enterprise-editions.md) ### [Windows 10, version 1803, connection endpoints for non-Enterprise editions](windows-endpoints-1803-non-enterprise-editions.md) ### [Windows 10, version 1809, connection endpoints for non-Enterprise editions](windows-endpoints-1809-non-enterprise-editions.md) +### [Windows 10, version 1903, connection endpoints for non-Enterprise editions](windows-endpoints-1903-non-enterprise-editions.md) ## [Manage connections from Windows operating system components to Microsoft services](manage-connections-from-windows-operating-system-components-to-microsoft-services.md) From 6e854b67b7b882ededbccf85c148659f104fec7e Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Mon, 13 May 2019 12:06:47 -0700 Subject: [PATCH 280/737] Added enrollmentstatustracking CSP --- windows/client-management/mdm/TOC.md | 1 + ...onfiguration-service-provider-reference.md | 65 ++++--- .../mdm/enrollmentstatustracking-csp.md | 182 ++++++++++++++++++ ...visioning-csp-enrollmentstatustracking.png | Bin 0 -> 50786 bytes 4 files changed, 222 insertions(+), 26 deletions(-) create mode 100644 windows/client-management/mdm/enrollmentstatustracking-csp.md create mode 100644 windows/client-management/mdm/images/provisioning-csp-enrollmentstatustracking.png diff --git a/windows/client-management/mdm/TOC.md b/windows/client-management/mdm/TOC.md index 07e2cb8f96..3689c9b175 100644 --- a/windows/client-management/mdm/TOC.md +++ b/windows/client-management/mdm/TOC.md @@ -126,6 +126,7 @@ ### [DynamicManagement CSP](dynamicmanagement-csp.md) #### [DynamicManagement DDF file](dynamicmanagement-ddf.md) ### [EMAIL2 CSP](email2-csp.md) +### [EnrollmentStatusTracking CSP](enrollmentstatustracking-csp.md) #### [EMAIL2 DDF file](email2-ddf-file.md) ### [EnterpriseAPN CSP](enterpriseapn-csp.md) #### [EnterpriseAPN DDF](enterpriseapn-ddf.md) diff --git a/windows/client-management/mdm/configuration-service-provider-reference.md b/windows/client-management/mdm/configuration-service-provider-reference.md index 8f8ef0ecd3..640eec77bc 100644 --- a/windows/client-management/mdm/configuration-service-provider-reference.md +++ b/windows/client-management/mdm/configuration-service-provider-reference.md @@ -7,7 +7,7 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 08/27/2018 +ms.date: 05/13/2019 --- # Configuration service provider reference @@ -23,14 +23,6 @@ Additional lists: - [List of CSPs supported in Microsoft Surface Hub ](#surfacehubcspsupport) - [List of CSPs supported in Windows 10 IoT Core](#iotcoresupport) -The following tables show the configuration service providers support in Windows 10. -Footnotes: -- 1 - Added in Windows 10, version 1607 -- 2 - Added in Windows 10, version 1703 -- 3 - Added in Windows 10, version 1709 -- 4 - Added in Windows 10, version 1803 -- 5 - Added in Windows 10, version 1809 -
    @@ -932,6 +924,34 @@ Footnotes: + +[EnrollmentStatusTracking CSP](enrollmentstatustracking-csp.md) + + + + + + + + + + + + + + + + + + + + + +
    HomeProBusinessEnterpriseEducationMobileMobile Enterprise
    check mark6check mark6check mark6check mark6cross markcross mark
    + + + + [EnterpriseAPN CSP](enterpriseapn-csp.md) @@ -2646,14 +2666,6 @@ Footnotes:
    - - Footnotes: -- 1 - Added in Windows 10, version 1607 -- 2 - Added in Windows 10, version 1703 -- 3 - Added in Windows 10, version 1709 -- 4 - Added in Windows 10, version 1803 -- 5 - Added in Windows 10, version 1809 - ## CSP DDF files download You can download the DDF files for various CSPs from the links below: @@ -2696,13 +2708,7 @@ The following list shows the configuration service providers supported in Window | [WiFi CSP](wifi-csp.md) | ![cross mark](images/crossmark.png) | ![check mark](images/checkmark.png) | | [WindowsLicensing CSP](windowslicensing-csp.md) | ![check mark](images/checkmark.png) | ![check mark](images/checkmark.png) | - Footnotes: -- 1 - Added in Windows 10, version 1607 -- 2 - Added in Windows 10, version 1703 -- 3 - Added in Windows 10, version 1709 -- 4 - Added in Windows 10, version 1803 -- 5 - Added in Windows 10, version 1809 - +  ## CSPs supported in Microsoft Surface Hub - [AccountManagement CSP](accountmanagement-csp.md) @@ -2750,12 +2756,19 @@ The following list shows the configuration service providers supported in Window - [Policy CSP](policy-configuration-service-provider.md) - [Provisioning CSP (Provisioning only)](provisioning-csp.md) - [Reboot CSP](reboot-csp.md) -- [RemoteWipe CSP](remotewipe-csp.md) 1 +- [RemoteWipe CSP](remotewipe-csp.md)5 - [RootCATrustedCertificates CSP](rootcacertificates-csp.md) - [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) - [Update CSP](update-csp.md) - [VPNv2 CSP](vpnv2-csp.md) - [WiFi CSP](wifi-csp.md) +
    +  Footnotes: -- 1 - Added in Windows 10, version 1809 +- 1 - Added in Windows 10, version 1607. +- 2 - Added in Windows 10, version 1703. +- 3 - Added in Windows 10, version 1709. +- 4 - Added in Windows 10, version 1803. +- 5 - Added in Windows 10, version 1809. +- 6 - Added in Windows 10, version 1903. diff --git a/windows/client-management/mdm/enrollmentstatustracking-csp.md b/windows/client-management/mdm/enrollmentstatustracking-csp.md new file mode 100644 index 0000000000..975a1a8c3b --- /dev/null +++ b/windows/client-management/mdm/enrollmentstatustracking-csp.md @@ -0,0 +1,182 @@ +--- +title: EnrollmentStatusTracking CSP +description: EnrollmentStatusTracking CSP +ms.author: v-madhi@microsoft.com +ms.topic: article +ms.prod: w10 +ms.technology: windows +author: ManikaDhiman +ms.date: 04/25/2019 +--- + +# EnrollmentStatusTracking CSP + +> [!WARNING] +> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here. + +During Autopilot deployment, you can configure the Enrollment Status Page (ESP) to block the device use until the required apps are installed. You can select the apps that must be installed before using the device. The EnrollmentStatusTracking configuration service provider (CSP) is used by Intune's agents, such as SideCar to configure ESP for blocking the device use until the required Win32 apps are installed. It tracks the installation status of the required policy providers and the apps they install and sends it to ESP, which displays the installation progress message to the user. For more information on ESP, see [Windows Autopilot Enrollment Status page](https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/enrollment-status). + +ESP uses the EnrollmentStatusTracking CSP along with the DMClient CSP to track the installation of different apps. The EnrollmentStatusTracking CSP tracks Win32 apps installations and DMClient CSP tracks MSI and Universal Windows Platform apps installations. In DMClient CSP, the **FirstSyncStatus/ExpectedMSIAppPackages** and **FirstSyncStatus/ExpectedModernAppPackages** nodes list the apps to track their installation. See [DMClient CSP](dmclient-csp.md) for more information. + +The EnrollmentStatusTracking CSP was added in Windows 10, version 1903. + + +The following diagram shows the EnrollmentStatusTracking CSP in tree format. + +![tree diagram for enrollmentstatustracking csp](images/provisioning-csp-enrollmentstatustracking.png) + +**./Vendor/MSFT** +For device context, use **./Device/Vendor/MSFT** path and for user context, use **./User/Vendor/MSFT** path. + +**EnrollmentStatusTracking** +Required. Root node for the CSP. This node is supported in both user context and device context. +Provides the settings to communicate what policies the ESP must block on. Using these settings, policy providers register themselves and the set of policies that must be tracked. The ESP includes the counts of these policy settings in the status message that is displayed to the user. It also blocks ESP until all the policies are provisioned. The policy provider is expected to drive the status updates by updating the appropriate node values, which is then reflected in the ESP status message. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/Setup** +Required. This node is supported in both user context and device context. +Provides the settings that ESP reads during the account setup phase in the user context and device setup phase in the device context. Policy providers use this node to communicate progress status back to the ESP, which is then displayed to the user through progress messages. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/Setup/Apps** +Required. This node is supported in both user context and device context. +Provides the settings to communicate to the ESP which app installations it should block on and provide progress in the status message to the user. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/Setup/Apps/PolicyProviders** +Required. This node is supported in both user context and device context. +Specifies the app policy providers for this CSP. These are the policy providers the ESP should wait on before showing the tracking message with the status to the user. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/Setup/Apps/PolicyProviders**/***ProviderName*** +Optional. This node is supported in both user context and device context. +Represents an app policy provider for the ESP. Existence of this node indicates to the ESP that it should not show the tracking status message until the TrackingPoliciesCreated node has been set to true. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +**EnrollmentStatusTracking/Setup/Apps/PolicyProviders/*ProviderName*/TrackingPoliciesCreated** +Required. This node is supported in both user context and device context. +Indicates if the provider has created the required policies for the ESP to use for tracking app installation progress. The policy provider itself is expected to set the value of this node, not the MDM server. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is boolean. The expected values are as follows: +- true - Indicates that the provider has created the required policies. +- false - Indicates that the provider has not created the required policies. This is the default. + +**EnrollmentStatusTracking/Setup/Apps/Tracking** +Required. This node is supported in both user context and device context. +Root node for the app installations being tracked by the ESP. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*** +Optional. This node is supported in both user context and device context. +Indicates the provider name responsible for installing the apps and providing status back to ESP. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*/*AppName*** +Optional. This node is supported in both user context and device context. +Represents a unique name for the app whose progress should be tracked by the ESP. The policy provider can define any arbitrary app name as ESP does not use the app name directly. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*/*AppName*/InstallationState** +Optional. This node is supported in both user context and device context. +Represents the installation state for the app. The policy providers (not the MDM server) must update this node for the ESP to track the installation progress and update the status message. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is integer. Expected values are as follows: +- 1 - NotInstalled +- 2 - InProgress +- 3 - Completed +- 4 - Error + +**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*/*AppName*/RebootRequired** +Optional. This node is supported in both user context and device context. +Indicates if the app installation requires ESP to issue a reboot. The policy providers installing the app (not the MDM server) must set this node. If the policy providers do not set this node, the ESP will not reboot the device for the app installation. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is integer. Expected values are as follows: +- 1 - NotRequired +- 2 - SoftReboot +- 3 - HardReboot + +**EnrollmentStatusTracking/Setup/HasProvisioningCompleted** +Required. This node is supported in both user context and device context. +ESP sets this node when it completes. Providers can query this node to determine if the ESP is showing, which allows them to determine if they still need to provide status updates for the ESP through this CSP. + +Scope is permanent. Supported operation is Get. + +Value type is boolean. Expected values are as follows: +- false - Indicates that ESP is complete. This is the default. +- true - Indicates that ESP is displayed, and provisioning is still going. + +**EnrollmentStatusTracking/DevicePreparation** +Required. This node is supported only in device context. +Specifies the settings that ESP reads during the device preparation phase. These setting are used to orchestrate any setup activities prior to provisioning the device in the device setup phase of the ESP. + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders** +Required. This node is supported only in device context. +Indicates to the ESP that it should wait in the device preparation phase until all the policy providers have their InstallationState node set as 2 (NotRequired) or 3 (Completed). + +Scope is permanent. Supported operation is Get. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*** +Optional. This node is supported only in device context. +Represents a policy provider for the ESP. The node should be given a unique name for the policy provider. Registration of a policy provider indicates to ESP that it should block in the device preparation phase until the provider sets its InstallationState node to 2 (NotRequired) or 3 (Completed). Once all the registered policy providers are marked as Completed or NotRequired, the ESP progresses to the device setup phase. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*/InstallationState** +Required. This node is supported only in device context. +Communicates the policy provider installation state back to ESP. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is integer. Expected values are as follows: +- 1 - NotInstalled +- 2 - NotRequired +- 3 - Completed +- 4 - Error + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*/LastError** +Required. This node is supported only in device context. +Represents the last error code during the application installation process. If a policy provider fails to install, it can optionally set an HRESULT error code that the ESP can display in an error message to the user. ESP reads this node only when the provider's InstallationState node is set to 4 (Error). This node must be set only by the policy provider, and not by the MDM server. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is integer. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*/Timeout** +Optional. This node is supported only in device context. +Represents the amount of time, in minutes, that the provider installation process can run before the ESP shows an error. Provider installation is complete when the InstallationState node is set to 2 (NotRequired) or 3 (Completed). If no timeout value is specified, ESP selects the default timeout value of 15 minutes. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is integer. The default is 15 minutes. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*/TrackedResourceTypes** +Required. This node is supported only in device context. +This node's children register which resource types the policy provider supports for provisioning. Only registered providers for a particular resource type will have their policies incorporated with ESP tracking message. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*/TrackedResourceTypes/Apps** +Required. This node is supported only in device context. +This node specifies if the policy provider is registered for app provisioning. + +Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. + +Value type is boolean. Expected values are as follows: +- false - Indicates that the policy provider is not registered for app provisioning. This is the default. +- true - Indicates that the policy provider is registered for app provisioning. \ No newline at end of file diff --git a/windows/client-management/mdm/images/provisioning-csp-enrollmentstatustracking.png b/windows/client-management/mdm/images/provisioning-csp-enrollmentstatustracking.png new file mode 100644 index 0000000000000000000000000000000000000000..813656e9af8ce2b266dbaaf60bf0f78f0299674a GIT binary patch literal 50786 zcmeFZ2T)Yo_b%9qihvP81QbM3kSLNR3N%@;ksL*mk_E}34S>=}kSG}%5s(Z5k{UsB z&N&F!WXVm2e*1uOz5oBKshOIYdNcKYx9XOqea_i&t^KWUeQSF^P>?!JOhpWX!A{Fa zODMr$$9Q0{<8~*Hf`55J+-Cv)IAW_LB?ilAzB~>7a?Ir3{d+K2wm->^{&DbkB5P?4 zTNv!(4e0+PGD`G|Fj&>PjKn=bu!zwC`ZQL+D zwJy(2ttWEHv3rdW`)uslL}WVOo#Jjz1$bWr!3SzAAE0n zAjkA``MaEKY=_&K7xNuMq688NOO}GPIHs^J^HqwhBT*F8r+11OK(}D6yvdBvpIax% zp>B%O#-pLXPF??{5-jCUGgO8w(@Y=UU2E1h@(Ora-=w9N@>)+rOKV_gh}$2Uj^`?A zsO81c?*k4Pwk9&Ri!IR~To-yPXUq8T-+P*A=ndnR*9yZr%QFMnV{V1`^jJ1#rlqy2 zfH#X$;c)P!$Y}Oh_9*Ac!M5uLglD2%QRmPr6C3euDdSb)(}{`jl@~`~ux~MN)!^vp z=)!t=jN?QXXN$&lPBCer&qe;)TSiaw7pK~;ul#_Xqw!D+_Vx80qfpZoaA~FTJufC^ z`+RP?MRvR^aiLNCBxpC9IEArHuMnBS74N0pef8bBcKSC`>%O|e?kj6{E23aUMWyCY zIr;ga>@kSftY#bVlioq=>_07sbZ(!8Chbd$8X`YGKci9Gd8yOgtP}hm%c&;mUS=~Q zm<)bz{UizR8yaHOV=b}S(l9H5pM1&;T5waPnw)Wh!Co|TG1a%XkJTpXX}(UMGk)@T zw{D!lbF_q8=sV>%9R=3UGcCHT;cqU2Pxb3F)i*aQ=&voq+*V}V4L9q8YJB)zoKbC& zUxWj5KRGbFeQgMD-dL?kO-cB1 zzyHpyQ<24AG>*=aQYw4|y?S1)9NaFiAAk|mJsa0$U8s6$6;Bwn8h+X;P$$eJj2hqR z-RlryLx<++w8ZG9vs`5Iv1~G1r5!odfO(gU8hajD9o)Z6{V<~7rc9x_U=8^#@X=p3 zOsKs$eY58w*s1pg{I-wxk{2j-dC@J|t5g14-l}9HY^firm6oD4v&Un^5H~6@7sM2V zu(lTz@{)HuEG62ejfm!){IGiXU!?+D?@xfK_z;CcOCn5JjC?chTozi+D05)mD%BNo z4GWVEd~IhIMonIk!4}h*Z_+#ev`JQnRhf)IswRf5>Ei13)1XHj{NzUVn4OvM$+R{V z;|rHB%-$+rdR{rjuSS!?mGLQA^`Z@ia!`w(V9V7Ky>=$KX4X@*g_25_@$0PJ#hkQ@ z?dEoQSU#(_#IE#e2EKWxZHE<&T7Kx+l!{4o-yRxNK1&oM+fI?}m~>1G&JoV0Gdw)p zeHOSCSmh{~U-Qwa-j428rc@%A1=WqGFSjlU@wMF|Z|1&~=Xah_a3*Qqe^8EFzI?Ik zMZeM1Fy-I|;cQ+PKgsh+uH4Q1`U1%={Z6FY&{cCV%xiN=>BhHvlDP_>c%U9vU?G$L zWy36+V(6Qi6S)|4;uF!v@B$f6?HNkN$d(e*=O={xi@$7{uPry78_8WP(Tzrq;`#)& zB1sA@EPO`^c3XAU=AsJ=k%~ikQ<|jx`d+gPZwJw&>Y2KjTQa_>b&o3;tJS{kX#VkDDz!G1%$SZr?@)D-#$8$IFRD(_f zix_V!BmwhsUc}oDmY2LGRhzA&KZIzV9gG+g9@eO-sx~Iy1#lf*v8XsAE9t&fR z4`&2t(P%!W@wt_ip2ud&M4fo5~@$U86j3~3g7h*rY2&_ z-ZmG}WfXAM2lrRcc2lQzgiZ8VVg)!zG1U{rmsRQHujf#ZD* zhZz>Q`MW=q$&51Ytn~N2?uN-(H}<^iBy3t@yPk5oCbA`*nPMkl?Wj zSqR;Tnh)RcZ$q`;9u4UZp(o$@Dr`_iF4#Qr%$ny43iv$k{>(ignNJIgN4YVfw%IbL zm&x>4&w}mC_7I_}rdE?Al3%UfC$n)?xC6N8`P`C7BrdYJ05?to7HTORg>GyP(-T^W z;%=;$Ty=W!&2Cbo88&aD=lKvawJT=I(4kbPG)(o>=-L*mBFFIa;OJ97*w)qfJi*3m z&6b2C=H0iO-caC&sm#xd_1CAG#DIfwS>ro+J$gxn4BL=7u{YmQmhGkO5%7Wkj{PI& z&;my=70;V97>kRGv8l&3iRrHV1U@6Iev+4mr|~-xc=cBN?uVoD`c^t?zM;nLVao#AZ4ycLlDp&@@g6^#GN| zSpWUaS(D6A1--o~tYS=dwV}s3auo$Xle+-32{y-lAn<;^j| z*wQMQkj@o7_vr1Fvm-8}yxZy1AH(?XuB{48`o*wEF*T8u?as3?D1t_clI`GaJiNSN zp`pf^p};y0IE*wtQ~x_>t|s2G4P5Z2|1jU z2|_S;{8874_R&wc6#TshzX#V&7T&6FyzjAYOl+snLhPO;J?ua|b>gh#wkl$FZ3xn3n=2vxz^GOzV zb}I{ua6)h_!-_uJLHMW?iQn776+SM!eb;UWAV#ZLm+8D*LYajXk!C@BEIws})?a0B zpspv4_WkhBrX}$iy2Z9hkz%D779?V4e%obWU|=F1S}n^b2n29zD9#Rsn@Go(tFra-zOAy_jTz z4s53v3ZBZr3lt0Y$wUz1Y-Z;qPd<$?pwPuHrxp$k>8z-OUW#tdp_bneGEWjSq`#z~ zqc`3g-Dxx9ooG5R)D;!TMaU(3e^1y>LxA7i734A7yJJEtanQ?=ROCi3E-udY%MdDX z^f}jVxm?9*W@a`K4}m^=04c%X$|8|nR8P-~-K_=299^n;=PWB2z?bjJWRqmFPO^(y zCCk?v6k`N+8@VIJ?ga6b4emT>j%Xic)(qv3QNa5Tf1l|1*4z?!e#OhP9kf~n** z5>k8P(Upo%^jj}Pma+Sx#{2_N6)vR*O$7I)CaNijnE7TrW{`wGBMffF5p51i{L+#4 z?;*iFvo(l$j}kCcOVC}oV{61+YOl3!dU}Mq?v;V6nQSG`2hX3j#)+meRRL}J#rB-9 zsg~3LP;`1c_ha$#?u74@CK^d*w<{S$eYcK~?Qu%_m%h`u?YJ~L45nts=zISX7LNBz z^%$z(PFNgyx@zna#7r?`MQ=NNT&-*XCtEs@Iq`fV#lnkQ+&~WPFB%kIeQH>JU1d)D zmZGJF#WW!`7{iz~lkC$^)`oL0xWAyHd&!O3u1I`d+I<|a$|HyzT5n3IPQw^Q6o?ga ze&u!8)2rfCI{QvToG=Ar(Moblo@HwGVwAVBsQKxRrv4@zk28teN@edolQg{%fl>;e z>z}TMn-za&AARC1?m*kMYUfadOib^2a=I8NG%=Lf?-d@IiX}{yUR1?x%wKF-_%dzW z^DtE%Q#`a&jgy@n&>K*gwKm-vIIELV$S7^4o_>XY#bIaqIEBw7jga$4T61Xkd{1Xg z4CKx*WpGwD(PI-qu%BgeE=eBSq%LtgBIy?M<5ABkQMaV~HaKr*6gT~81){zaD`%L= zTPRQE3amZqDNqr2UNxtnAF24BaogK{pv!ukeO&>Oz3?)bI+UaV*FAbOtG$-`L_X`+ zq@`i{i#GTTB-zf>*`^GO(W1<)&+SH*iD7Azyk<*QNe*7sg3ZA<%dQGl+1{=!CX6t4 z-5T%eQrUe33`X=a-qOr$R@SMVN-gig${Q1AOabfk5j3|#-pz=6hP8c{iqCo|6nK3s zzokELuKQYJ<nR%iOifu0K4b9J6rf7euR{2FgPhC29Bpaje_TrMT zzwA%ZzIEP(A5H1E;u{>KW-vTPtlep)dy*;6gO(kS$9Dy$KH}m;CQF%aPQb9*7<#4Xd%EIHXUl{Z%2yCkw`bQET% z?KR=q-!Od241tPvzlD-*2Pk>ddE<#CX^B(RJ<~Z9Y0O3H5gB+JM{#%WY%+CzNxq8} zIo!f~eb5hg{`g(}g5}*>jFz&drG4t_dKM=MynWh8oQYTe(eDM7d&f7CIHqSvz55kv z31CZnX-HwjvZL6M%kQ8~t(qVc!bebf^LyW0eYBM*<$jBUsCLr;Digx!O4{WampoyU zjnlZ|_)aFOrt;yyx7^hkjCr*DwBN9U^k0*W3y4d#*0TC=ToXMG$|VkCeOja&$EW)` ztwvl5T_0@^5XVjd*V@XKgx1zeF5%uIFna=g&btrVaPK0Pd;X8jI$rY@eDYu`vx9qU z7K=QyZ)qRucM^sBbyfnY>a!o1}{rse~>K3Y!>z3VhZhI z4*bLho!JL?ZJb1`5=l(mGsSeS;Z6#62%!sc=9QLO(C9$kG93YZk}c%s-O_8G=cb>H ztYb0hscVv%{lyDnBh}qp*TdWkzkGQ@qY0jVB9(w<1Z?9ClVeAcbyIfW_Al#jF4MZ;4+3}J(;9Ov2^6;1dQ3qx8UEK)Qw2X|1 zH&BGU_DKWY2Avrw*=+3x;@Jh&$VDh5Wb|FVgWMZ+L9Uh8>P2rnG`l;kq0EZ#f8{TX z?+aNr1i?vtJ<18<>f)$1)yOPNOr%a%Ww0wxFmc}a__NZJJq8LmvCwibvHPnAglJ`|L#%1e`#pK$OvWZyA`r-8XHP80IE2D6+D(?YIm@KB)heo%&4#Cq2`q%Yl|b7}EOT8m|lD%t+UJMjeA`)d^HnoJQn92dlnVZpnO zS*5?fL8sFQNDJMrN4AYeU@u-uz~9pkp_T#NfLxy*Q74cUD}v&nGCPOz%l0tXqs0dZ zdYNqWAf|Y+yed{*TtZiSx$n8r1 zk&rTW&(Y4V>+)Oh^CR%{v>TkV^C6@7cb_gSgCfmgWD`)i0?1zD$%YAa&=kRI(9{BR zy{N8dVCs}j&H<6FqNB`YWR^cc8KJIL@LAy};4?}Opm+H9^Dx+{6TlagW-=Bmxb8L= zCUhrr4AilHjW*=y`S79TesYl*T;@8h+g>gfYh=rJ6!xNA6#o9>I(Z_O7T?{qFWjb$ z&!6W#S&x#rtsFe>;WKdrc1aYF4bIvKdwY8n_7%5bqpKH1G%Ba0b!;q1+v($2C?#)K zy%?L?_Iuq|)q>f z+iu!1oJ=oy#w5c~lIv5F@TI(~A(lD}*I72l!t?UDS1ti#*l%~C1-*k^3?p#7m>8oi ztj5li=b#=Q^T35rO=#XbOfm($n{Djl7A;?0p#iv>6Q==HlL42xk;kmKDv%}*CsM2+ zhg;RfsgPv=%I8rl*de1AN|jK1ccg}RuNA$y(u{u2;EJXI&AkP~^k+uhaUAg>rLuy1 zf4x|xAOR=Jf8XjoN?sN9jWXE`v7rk!at`d|VYT3w+xAXfr@KimVEn0hV!OMN&uz)S zRpA_Do@-(tDfWJH2a`WepPA&LLPp-g;EcW29rF>iUbf3NmI-$4Z$2FahbSX#&6z6y6yuE~e3!xEvwCc|t-Uo=))qc`f zsh2#g(*cXI-*d2;LCo;Xc&oPeh}n-1*q^o+e2S<$i#;YAWK8QqNE+q`G8zSEK`P44 z`|aem3UQ1VCs)aX?R+T}k*Lf>2gQ%anCl-m^VcY4$}}_0kWjuYah@pb+sxs=cm($C z8|2!yQHPdiPha;*7m+qi5V|z&ucoHf^ztN_mlI%Kl$q+U#z@NuDU-1U6T%+702CXr zSVjT|xawOW8e|C*l{c3k|iB?ee>P60i(_=)svr`>I;y;TxU zqQt+9>= zTq`b4?5i-mg)cX;Dz#sWtB(&-Jl`$|h1hqMhxr|z1ES+`p|x9lPGR9wKPDI~@ZSD5 zki#nnCni=^%wfl4ccGL+H!L_{1G1C!C0h9qcK6+;reD7-Y(aja)#7)H;!um>(d-~$ zkA0s_&}|(Q;J31}f)oI8On$zxA1C020lpw2hlh4D*H>3dF8MHL#yB-o>5=BFL#GzT z@l(-iG=D!}`)T&^wnlq8BOpLQy2HtYLWV0L%ztF>SI@);0$7~fK2>iBkcPR1g-&?k z>R8Hd_lv-QjLFKM#Ut#)oKhfbFm$k|b0%|*wS3Qsa96# zG5|r6Iq1M)Lb0SM2ls8>p&bp;N)~osmPk~}M@o>^1ANnA1f|uB0N#Lx4^E9YXK6ul zB&XW%by&Q&T~aKcM&ogJ*+60j004(TTfh|MfHVIkpjT!)pUiE2`Rh-q&}bW_WIoo! z+vdB$^r1jYA$FB(CRC?qO<)JDrQy7H~6mz%RLC1!0dC4km2+ z8GKaCiFZp!cfKyjrrasBXG^-7_cec0PRZ?`jU`VqG@W)nYTin{^{a9GCdh(!j;O7D zEGqestHvwMABx;9SfBrJofNR)zzxNtYum>GabEtqBTOX6>m31wj$Gpn#-a>mhUGn{ z=ez1Gd<%rOvha8%W;#m-Zy|q_ZghD31C2~CF7&;6YLnR5GGP-4r`&}f4A`H!etCIW zDi+^Jb?1!cAg=@WU2pe}uuSFTDIXQ(5)(oBzGR(ZQj?fuVy} z4JQ;td4M=NigJR9 zs)17ljAA)~bELaLyk&W(Y%h`9^m5!+6aJk^`81_b$sYf2ljmm}W}BME8xz_c6V%wG z5YHYmJ-c`umZkQ)Rok{G_-5n<2Y1&s-FBzVpXp_rVTy#CEU4+Tv-3uDIFPwg@Rrr-%iht>yIG%H zE|}1awEzhY8!Kys!FkvVA%I?hWhJhY!wZ*ic}PBFCzSxHUNR%m&)VLXV~wlx^BMf- zj=*{e4xEot3M0rrbzoDVe9d|Kryi(4Q7D-^b?xx?`XQ^b&Bd`1;1JqRk|z#4%Mc4^ zwkAFfYXwRZkU-1PVEMmJ@5noLuMH(ofE0~9`Z%j;2XSH4Y%lD}7qkmg9z`anK zamh&ca3Xeomeb-N`2l2C^zy)MkO96VFHdD>tlrGztR@tBg#aZ(3q=bHn_3eGAxt#v zU^@p|!lBPiWP~8Om#&)`%G3_8)K8maHfn2XX>m${^udt$fx*p???;4A+gnv*{0d0{ zmRK+ofP)5hrHwoalRkOi)^;Btz5uCM(*ery#s8>!xSf8UfsO+Tra%%)Eh=1BLxZCR z=$VLqPco7T1q4*~Zt+SHxBL{5uI6KQDv)3+pmSx+yA1DN!$kO|CVg7s3hU=^`7pMY z=CFm4vX(a_1h7EKgT9ri1Q&I6b(!XUo~Z}Yw9b_t{7%T8n@-eb#a7!3DdM>I6V&#(+lB)V-sYYFG3k-w^#pZ zc>h5BUpdth%E8=MD-xvq8xcog%LiKovj4Np^=oTu_4V~QPuZvW4{WeLCMSuSfC0D# z1eY;>Hkc@XO(-BBFd=;u_VjQMw5yRD85kJsZ4Ex3UY_b)0z{-WP#uah#9pIUfUMT8 z5u{8I+1g+24cs9jM+J73@Nm0recXpBddVQ1u!?dUrgA22w;aAK!li=Q!13}H6cknv zzW_1=$Yp^2H~j_@C)yiLw1Xfa>qLad+zk;Cd_hOhd!)Q5k8{a7K41FMb<Wca&~^! zjl=OLCg0c$BaN>=&?)I~tJuLKM6XGOn_syY!0V?LeP5&Gj3rS5b|H9sd zt$Gi%mRj$QG0PVIV9UC#9h;N%-0Go#LZc9=F2e8K6~<*9&lkHK9`7}}E=uUMM4zt=-R8KmG$kgI|4*A{@05a0y%1(>7I zurQIW9TPxBg;!o#pRB(gV&_(0QMc?|jyXxMj;N58%NTTg-93&oHKI$ZUfMFOU9Jdl zP%tqbS-liFlhGC~l9{iX`M6R58C3c<@AN3Q`4h+ZAMy@LI;t*Ys)#|ANZjYXRlgo& zziUJK02}+3Riu1%l8CO34!0CNZ1uw7&H!A~AZ7&z67qm-G9eVPoa6Mgat1u9RtkE37A;O{U{nw@ z0$8@(He`v<=k)%9af}^zpN*}r`>$)4^N3xpU#J7xqr5MbsYEZ_0V%m3yTU`A;kO1i z^>~r%Rx%7CE7-{KH)(VRcZew0BbT1LUDn25O4T%YHbLZ`uVTGnd7q;vV!KDBo3@U8 z&7D;UY4DPRMx1s#a36__eByPKBcValQg+655a1FSkgFuHS z7}R@BPQ2XIvNE-ZTS(=&`)p0j>h*f5F6%m?KWS)Y|J)dlHaihH=ujI$|C=lCV^30Gf^79(XF;`8kS zE4NJCPz-CIyewYJl$2(>6pCSW~ zO2603%-)bVyJ|4+nR4O%z$5lDUyv{c89a-R>o%J|2+8S#3R+5^uXL*ciV(I7mJn=f z=(HBXXzQLn-34o-x^puqbbRkE!g0L?y}@*^H!@*O3GsLVzG9ITMq7sF8hRE|%eqc4 z!j;xi`bArl*T#GdXPRdUqKdy(1q3~X>q7-)5gPy@%ipw!8GIt)Un11;`n5Se_$}7) z;mD2nc1$0?Ei&ZmyrUky)<4yU4sCi}9&~D$w<14VOi+>v* zjj*dD#=0Kr>7{XZTULo)6MZMC#qxXkNR*RY2(mSndD7LVYm#fwe?Bks-iQ|5yO;te znLV{rJM8siIboh~p)xBkxl_2Q@&3=yNv1sq`zj{Ep<2URW!c&K|7{?U>^zhN^1KPv z$4CtZ^{6kVc48vL@f~>kgdbN2Vje4KBva2|r{YVjzUa`7yeSELYDIoyLO1!toeOIT z0a#x9dYw-h`tub+(I2x-ao0_L&6^Lq`48HZ_T*8|*d6az=z;X~?dIi|{r-!SI!u%Q z_#g^Im*gV_6#`ej+nx|*;Hy1D-RgpQt8+S!fVNJBcInN#igitdvgU$kkoHd=5B4&5 z@3*;)DBH2BArgGkFBO4FNx`Hi5#~-n(xc&Sh0)xLww1CP+3dgkZ_l`m`V-n%U-np? z^OgT7;}}Nq!ucV(`j(FXd2X{G0baR3DgEh>vJGV<0n26hd;z^Abf`e zgg|xJy~r`Z5!NYH_Rxnu8lZcSRt3O5F7}^eFa(7j+}P?Di4rkAeJz*TjZT&wv-(;B z#6L*n`hZpA5+Tg(A8`3pB^bz*m%A!{ln(iP4C1ZP`|51b4S37e%tO$E*6 zH^aC2Bey`A^H$Tv&ZX~Rv9NOo>=5Jtc2yBG0Aqa4m?a4*tUrY)+^I_2Gup*2+5uiP zDzX5hR8!a9PTF+r#q-12m>xjAx{4EMFJr-JaR$L)lm|4*J|;(91pz=U&*4G!0C5a} ze9`>FNe37Js*lO>J@i4!WcNUn5b&Gb+K&oOf=J+n`Mz)zL;-*+g`Wdx-;nyy9V9cp z0-?m!fy3DsgP->R;X>cxb_Ij`PgnkbH!IV42%zPi;KG42B-^jBlYd2j@PNHEM$<~C z^#OszKCu*KK&LcPw1AQ$plaxh2U_M#c4Z)41p#^E`(q%9cCa4-a=W*c4rNk8jfqVw zH+@z_1c7E6qGw4VTwTh&_ZljYvKgI7&jfy>5pn#~zqapm>^}3>ZmthdvH!a(Sza+7 zUm~I7G*NJ~X=oq{apdn^_>qE9?`_A;kHt>BcvHZ@LLAHkf)k{F?_m&E z{KX$w%SfxCofnihD_)E2m0!00_TzvKJ+Od)=gg=X25eyk#7TSyoWuvfNyIX`i^-LL zJA~I@%;35DF0))Kzp_WC8HuKymF2>j^nP5?yCi>T!13slfsf&Zb`GPxo;~UD^mIg6 zz&uy6XISF|p={f4zzd8F&?>(*`zPLe&_~3&Z?)%9uYmM1lzjTvV?bxF%fFk({pxbu z&o?&RWX#wKP%ITn;WamHXcf+ag>>|YllwW{{a6)*U&lZ^^3jR-1{8;QQ|-Da>F74* zF`m+CT0|EQS4D9TMGlIoG(EgE&>7WTb6nfH?bb6@}{g^NmU{6KL2(y4!qNEQw_ z@iNGh&-EsJHDRF1q+s&7tHSB3M?0+{*OnePO&JI%U~WabYgYFc7@fnSk5MG6DPLN< z-{=U6?S!0HYcKnJgZ*pA0RlNaJ)IdVW7gT5JC%E3&p9CV>-7!yyFqchDFRL9bIZ=w zH7bMTxU3kQ_;6XkHqcT7rtJjm@7V!#+h7?IU-{FeJ2_j8NJQZL_!mj5gpr7@=!pjd zSexEEI8+1%%i{8fY5kvkpiwUtQe*FbKu92-a49dBaXxt{g?SU`XNRcDC+j_pgoeBq z?uIUsNT*@Ww-W=YF>$km!%OnKnJhD`Ew+D+PcBupeou_Nun)IFPlscfiwex+DAabV z!#PpS*57BjD`(A{VxKu-i~Dt|v^J^AZyZv?uCV>ON_4z_ z$FV^t(^;Hdd~#E_%j6!?dgW+OeNEqo{-TSkyA$CL$w?i^x0Gm0-|x9xuLgZM$Whx$ z9M#ybDfn&IS8=Fi3R+h;8_PsON?{Qf$LF!!hI5F)?7So!uDzdnv@((Y14<8%n!piW>nn*bZ0p{I#@yAQ2Q?UQqjrImXUe`gYJ8L(G%a)3f+dW3#C{24N zQlceKo{11|`KBInozGwBSWiQy@5Zm@xN#(}=9Key3hJCb=P)zh+D6rFlU<=l^CIKs z?}A$Gru!g5-1lAHb)kAd(3?AHSe&_i?r#rc=rXyax3|K&ACs&s1$75xGo<*YQ>U;2 zwtHpR;aVSq&`g_3B|bl~`uRv)8AseYMc}tnMIyZot7oyloR-C#t8O=o%`mHY_nW&A z%uI4bA-87lMfpCvke`vYrO$eM*l(4Q)^)ABoiuar64_ryR%^3Rj?W+V33=k~?7Ww$ zxI+kbK#=+_9ZNiN+JTgXI=*8U-zm2eb8YdyxB91n%ckN^LW;NdQX8-H3S>1nD>$Ia zI4k=u@#@bKr}OSDU$l~P4*4y`Jpwbl@|V>-xt7;}yz&GWcw&as|{g5%3s z_sXm`;~Tido$ya7-JTWJ*Glm7n&+Ji0h=ju5=pJ%MiLo=Z_DPXzTaE4WQEJcI-F~Yqzq$3d$8!As!ZTb;L+k6n8&o{tUTu=z z^Ei`dC)Ui+Dg2AcT)j;FB<0dTLxEaY$4JIhvA()()`dc_69~HC>>c+L#E$WP+WW;g zocAW9!SuRi%Y#VaUk>W{eL?5dsmDuE+@|uv@5db#BTgsato4jE zkkfB+zhoVcC~)WZo;u-+?FsGMFg-sxtJ+D{VqGTezkQ#@xyuyga6N%Xz$OeAevTog zgDTIviRY%Pj=mKG$;FCG0__PUZu5x%0^WIZ{Wk2c9eB_7skR^Kc;<$_xP?{J1(HwU zeBu_9kv#+}ovLK^MK=vMahZ3N@5kLn*kh=5n+%3{3V!HhcD#?`pXHRWv|nYLjXXA- z+2w3d(M@iCoyl@EdjR2cWm@Go(@}HnzqGcF!LRkimKmJBOf-G(fK*zTp9iUiOF+T( zo5_nu$MJKEDu0*YR{!GV??E5^yNdYo+i#El^61A|!GFKSOhD^ov(?v^dc*eQQAnWl zJ0w;n`|_o@SU^BeezN0Do#@2k6b6($`_l;Bd2{vl?Z2ntGDL^vJ}epXS-oixCQ^dL zJ52l_IPni-l+5^c8mQG`L#p)z^G2xdleQ0)An6=t=U?&9y*P4^8rVlE#A7atH6kG0 zTe4Hf+5I6fz|v@Sc`33WGm_xUCBeT3$qHaZRUxy;?&=LF-#`OJkgiMecGCj3$wvtO ziIl)7%uGxsLD6HK(w=W_i&la>C}jcJVjy4D*m~@2VbOHi5Xema@Nz(o5Dik^AIgN2 zQ1$H1_^e4i5%!yS94~$^a}U>&<}EP^CIZkSpu(txkF)g4ms&Nhqr`t1Y%ht5^1QoC z5|14L;+Z1WDxz^=%-Lk zO-%s*F$q@7mUW%YD5$oIl(A0HMEhNgAUbzQJ^|`K;GAv=?28XrwU%Xw$pt|M(P$Nk zXfarzMHcphS^dvL|Cy)%N4H7_W+JBZ_Cmc1MnJ{@rP4^n z;B@qD4-f%&4*2V2Mp3b3Mh|)_CSoNJChtcT$3f=NGeANdey{!@BLdk`Ji52epGCxJ z*^$FUas8%9aPFs7l~={B^C#9f&#Z~BMwbY;FZ-eY)uB}lIFNB7m(_iD(77eI$-b(n zb>yIfN#;Yzyway#?q`hk-RC{b7pOxYW5|1L`rYP&kBZ5_^KOBma(BQBDD9i_e(xb^ zuli~IuG+53cSb@FKZn>Lm4h!CbnqlFqp0#Im@H?C^=@g|=F2{TdzY2h%{{V=|LhN>^B??AnBnqg`|NEOJYQBp zm4&V7{BNxxXSj_Qt67*V;dLQhY%U{QDp~B4CkHAX89W`Qu^!JT;K5&L+0hr#(Ouo) znh>a=S~vXR&~N%n0gYVv?t`P|A^j>hD?+TbQ5QdYeEqhyiMlH1l#4g&)gA!PznABzvqKb=jU~~$7)bwK@&~#O{ zDg0QeexBuzMiKqtZ8A;7YGpNgM(z0rIaN~vvk@Xx7V8%#DeCnXk^RnYE4=R9c`hmW zDk=+B_cK#*lb1Kmfpu^`FWaMpis<$x`p9wc?C zi;d-tX;;V1VfNUckZ0e zkC<49NA2q7Z3#WyRnSTsx<5POQYl%j^);7qM97>tsWe6Z-`3ZuSK=K0x@?cO`!<^( z-FGRx{|>>{;uOCSfu#$~G*P%r16~=Ij}hH%QB5#)NW{RWIlh>1HWCH($8MS-o7V@K zOdEbp$7}VL3q6P=6-FB5&#RJcL(8}~jqBy~uriGDoOPPZ6?LXzBHp6?$2Z{3R`B3h z)cs^ee#6uwf|kmDWMKT}uwKV32XmJiw}+0>W2pRS5Yr|DU#fI*dmB{CTA*i(H?7cV5cPN@h@)FqaiDCSkK}BrzJ;0iSp_8UNtB1} z@{jDecQ^~E+H5W^mlm|dT~1+~LLT~R^C>4dM{M)YXwFsttwI~N z)s-|c<9yXCm>a6_HoUp2$e40)wUnGwb>GB=(*C}R{P`mc zxv0#sf-EjsX;a4yc#QNE+^PSf{-vWP?XK;&egsPKQQBLsiRD<-ZX0gfT%SmXi>a9HH5;KAJ38$E~ z`6D6K&NvGHPPQFuD|A80UNrrD)S6ZL-ig~nCMt<*E&bJRMuHR~GKOTLMqJ!z9ImTq z-09F_8+37)9=MCoG*-Rv?^%#8LMQ*E8aXh2qyntHFTa~X?vdc{h9YQT-j)vST2 zBU#2L_gC{-7UeO46r_tmx(-+YCXAJ*!wKwg%=pdji}`kE`LcUv2MchidV(Wq3+911 z8lDU5fm>VV&9ZLPwAs4R#%4X7l^dllrhyB&{hDlpdfA;7fq=9hk=axM${kH%;&mBha_y#24k_B4Se!c@(SZ{hqMtJTjs z?B~a$#U!5p%Vwxg!<%WhZNmcO>Gb4(PJ5UF$hFHaPp1MdCns5c}a_dKQf@28R( z4O_+jKA-zU;dHOTaQ->OYfmr{Q-1l^Nzd~DQ5)xZ2nV2w8V3ip(ly5Qg^|poZJn*! zR~YtVn&vpAb#eDCBn^P;0Y~bTm(b30k%XeEhlEe!2ouWm=2;rSub2n7LP#1D^r(t1M^LeyYI#E~;^fOB!&R@=pm)d~a`8TBDge3||0~iq?HP?}oR? z7IfQMma+l@r^PAZ*(hPUrWGJ71+s6MDRaKRt1~m7`72p@ps9_~%PXi2QR6*%?41AGM#=x>3ofz;Cj+{W!O#ln8-xMf$@mo&!T*AQ&MprCL1 z4$#W3vLE&fqBDPM51_ZHbko=}K~?$<-&g(6J#TPGQmN}TXw^Ti7b;Xn_#1uBvL zNGS9WvYei2ZgL5hB;ZnkXTwwQqkl+G^6pCNy0hXvB6Os&68_y6D{z6`KeCmC3Jse9?%aHYk~kSZ}F9ko}VRW5l^3|TII{2Ur*+`*d? zOf6^GdBXNti3w3Wz#<>1O53$T#Vk)+w_nsILm;N;lNvwIl5?Kse-U{A@%EdlZH7tJ zz~;g6as_mu+evVX4u4j6iPEogTtV9{gic7AS!}sRy6bpDa|GvWk6qf!ykx;!6J{B3}H2O1EJwdXsEdg&# zexsTJujz}nC$5U(B>DuQnmD*RsH6YFbLV!OPKp(x=!=A<*S8XW_o;qgrxj4r>3+zt zg`V|U$1S9qP*$SGZqZm8I8FO&`RzhS}CwYAYgGKho)xaGMT+~ zU&E?KmaXO{W@l*{-#~Q-rN}^@h`lkr6%jDi!ERi4eM^pB9CIrt0aZa=3cCvb<7HYa zAL+8urZG<3-LPxHGOk4}HKX}fB1r~+UAWQ>9qJj3#yqn&o8Q)a&V)4(Olke~qWhHf zqqnrGB1dhjOE1EAk&ELcX_T+vYTHC0Q#rW@kDHFIjto4R2>7IH;Zd4nk zw$%7k*s`IlSDT+=*;_ZB(*az%Bx0aF$j(YVt zgX?aER`*qf|1t;Fq?}F{5!phMD#QeIMs`cXS z+urpOOF@Llo!9((usHTV$>w|Vf9kD)Do*C79^39t!N?HDzeIL#pE@`=%xi8g2=7w= z77HxmJlUJ{f$#uC*ZZU(@z?+;@cfw$_uB!* z0w6Jkq4LA8^oHz^YXjMf1&Ym!WU$AF%S8xMYI3=rBl5cj-5AH1kLOh!q>}u=MTH>M z6n^~_jQ$T{`O0s1-oYm^yaJTAE<_2)su4AT8te}I^6a2q?8e#d=V)|<_gxzx0Qfwg zk(Tx$ff)Al@LeHI9i39QNwY4Mj9`W?>xWptNk~k#;Ge1reT~6e*GC9vL9&3=dv|n- z(xA`q*&Y>T`{U)OLV>sC9#sBpty8>P>TbQ;B{ISlbYi%@Jy2L0+5pc8V2}UI^AXaV z985Z`_8UpdNEz6RLskT$F8<2NLuA8Wng4yx;;*DWM1A}v9e~J+zf=Jb=kZs*by4W#xR zpD%C#W!^w1L-|cfw-ehP~8;M0K`gp41s)o#V-WK;cpPkC{v; zCI)a*-c7kpy(s)BxcT5Lxb!q2A5=ZYn&y7aAT#*{WURNCUi>+h07nOqB)I$(sA^RB zp?mhag7m=d(3fwi!GZe zT9m^uoNuUZ2mJFWsALq}7^ekQVDGIou05!j z3ef%Y(4|_CMo6FV)TKWrC@Q9uwy(I&eYk&AKxncTdv;+2AI-n<;@)3l0%cdgiP>W| zp!+p}t0Thx&yyA~BAL{~n$rDZ@Bf|vAr1%tHKqHttKGxUU(c<&2YK+KMedoNaKSm1>?9L-u^pl zw%-FFPe@wV_#SVw&9GGVLSaP%okDN83DNw` zuK6z43`}%9#pajZ_c4Z_U7tZ3`S+sT|M+SE{sSjG8CA6w71Gu(7SJeP#NnvtLzsN; z>es&;kQd7^AfjF(yxEUS$d~6u#32T-dpeA!xwzp%Jndk~x4h+N zJfHG2j=PmPO(=U->Ud&0rK~>Uhu>yj7n0e(#k1+(Z7XFmwqTGeH6{zVt5)yaH+vZN zUjM(Ew*Q@6=J+eQe3cG|YH!$?9A`+UGq4)lr7qhpK3{0+BaVOd)H@aa zS1Y~Z)}=fBZ$|)SvFDKBnZfItO&6K&P}u#p(L4{?JwhnHsg0<-x^gP{O>ky4zPdtcT>g(}KYJxgZ+c6w?@T zK*^xUs&(X2>o$qZqZ324b4FWlme&L~=_VgvGNHqTe3r1tFFk@=xzsGOi@Vxf{gp^d zO?@}(;w6wn4~A}IS7BV^L{&V{y?tqKr@`nFE* zA!ibu6whybl3?kuIFlD&62ou_uQKsI@=C9fP?A8^2<4dhyT~j%&u(g@lTX3*()#HJ zS|P{9Z-THFX@_puP|`H4LCSAjh{&(@{UhQG=I4PO5omy`L=T_4{g;0Z_=YsNMAFPtx%`Jxf7C zcir7(b8W_EYk=I1_mtTg`)j;f3pQ~@Q$|HkmEZoT?ku}fRlL?}r(sd)TSz+-P2UW} z6QJx@e$xldfBEH+!)ou^cYl;bA6%~iT>}@jK4-7}tjSY-5-zJ<8`A&5-g`$? zm2G>2$4DU}0s;yGq9_Ool0}jQqF?}yB*{^bEI9{7q9RC?EC-OBL~>F|N|u~aaz-*7 z!s)pIDR1|9-{>CSeLY6^yZ%w5s@!LXwbx#At~r0S;gJ?O&R@{CF@FPiJ~3k zpzWX7epak8J9SF+P>oeQ*Spjp)w4dj{E0t@%q=nvgS1u`--8yYE#fw$}LD~5O5Em#nO_JBX?nnAF zxkW|xiz~~333?bSj_`q07mT;tKq=kEnd0a^G3VSOln|uCuD;siY2OU+vswgM8OX_08b-H5fGw)MGiQA zP&gP(Ja}{;5v%?VL4xe&Q4f;&cIkQiyIm1rtc$ zMerUd-hZG&K>ju$&&t~aYHVw^BqmJm`)x4HdGn0 zbwQUSf>yR>WvT8C_3=r+Yj}A3Wr~BSyK`#Ay(v;Gimt7k(iwyTiFhN=Rnd>ADM8t( zg`m9D%az1Z?5QY%$lt|l!5i9o*#SgAdz|oB-WP$Gmw)FBMv1`|<5*o&{V;iNPO3*b zvpl-(u_OIh_;p6K$BP@+>gb-A{)T`aK?U}g*+7ihkqQ@na25NpN;7?4sQq}~t0WQ9 z$E(FYZMT=cMQHQ9bB;ZMZ>j!P*F1I)A#_o+O39e8go4#2kVC7oTB2|W%)VYl3pp5W)>+YIHH>pA;U}nz*$i{_r&F} z=uxHy#fU4cqt6+1%|_l}k0S+Uvk$s{inpmxPyV`wcMQ9~OrxaiHV0v1?obdPw0M`1 zzsCssD zTzeh~C+-P)6_fOIy4*4r=1<+%d`OAk^S9zH0rP*5`$AaP>gPTxO+lpR@j~Ae@dqP z)SDx{Za~Z)-_MzvRpi`oeewGD%1?!|Gtt`yBQpnwLaU9r+U=J4x6LofZ8Z_(^*6WU zk&XPWz2EzXR*QOPILE*JlBl%3(L6%Pn2S6*8aA)x0JYK^Rwv}2{8z)A2Zj+;nqd*{cF?+I5hgVak(X*a7UkD87qNzU_x z+S&facU7yTwpQk4mDlUc<)adPiQ`o5Avz5ut=?ULZlzco&a%LqIBse4_Rx_(Mmi3| zDeW*X;|>^haP0 z#_3i%jT0xt{+Ue8gAVB(bu!67Y?SC+9=95-6A8OReRNX&M|Lp)v&5imgXkJuR#a3x zTd;J`;A6L>SFv41!1YBxa@8>j0u4$%GcRtnQq!yV1}XEH*4?=Q7o@PVsxzPy2I z)lfh2*Vo@#2uD!OIoa9LP@_U<(dBaN=g?(#|JRTb2lC1Wc2<)JgU?moe?3tR8^kIo zkLSXB>fAn(6E%*f@26O*xHgfHwq}Hz{7t-H4@WHp!5@gh8A8q;82@jHYAHwrW*aykePDlvyc?LFo$ZIxQS<$u zz=X@V_~9(nv_p+iW!xEdH;8X{2=NfNE)R*Zs=kywV#hQ zfM3+b9sl`oZJ&4s!W`ef6_9PQ$8A^NKltLGABq92?4JQa#d&%kEZBc%sE4;ipDFL( zDC#l>^G{tJ<#Gy*K8Iw@JD@z&P47fTKLo~#fNhTL^s&C~cZpDb=b4TT|HkOT-Tc3G zSxmpoPWv^@flWS?E{-|0j5{wU=a2hB4uE%yvmF^ioT=iN*NZKjz|ZE72N6g?9Ac}p{qabdSCiM)yl`rl3QFSvs09c~f{$gS-E z;Dt<}vZ$pCgPVrE-Cgl?z%2R(^tHtNtW3_%F%Iq^ARUSM#D5SzTTnvSxqZxmbVd=< zDg98$k+=kI7fPYex2H4LV8x(MzSNf(thVFQgos;?V2@J|FxcmF@WJP`f5Ak?Em^ex zedEtF^!+n+W0z!90KAU(&*L4xFZ$hJDT)IhFg-9XuxOxA59xC-`DyC58ee&dr0mO^ zhn9t(dPXq&%Jjw*gikJLvRE%9{j9_W-lo)Ab@=g|&>#z-P%RfZmF#czn66@S!)FhA zl!Tv}>u;K})LFcrnlQ8xS4nuN?0L=eMdn1@$Lv4GU(8BW;Yz-%&T7puj_0d5x&dX! z^f2+ybwjG7KaYpi8%4V1Q|P>U`?qt~Rs2~-ezUB4=DR7#r5=g0nKUIgDpSqcV_nTt z)>dy{oF-X+Jr|(EV`x~sPBz}P;*^xIae0)L>%vE%*q$N*hG4xR5EP#b%x*ZiENhsmMhe-n(t33lLrnNYVLM^xP?X& zg+uk7UWttDv_msq)Utu<&vQP9kwkpH`}Mdf^W9dLejb&9)Y`|8}ys* zKdETVOg>WoF@+svO5ue54cR!GnRVx_dj{{$@DY<$(u@{n+v1J*@Ys!*tz;HWJmnYS zoGx|#_8?prU03n`9yCkO^E`~MzD5yTQOv{tZNz*TGgxo~xyq8eo#s}b+H!uLPiN-a zKPLPe(1;&AUgO9>=pY|@hp^g%Qa-|dNJajoH;EQL+8~dDtaDz`!6Zk&3^V@LjWc*) z-my6q^TNZM{mJh+R^uSbW-8=YLw&ZxSDcJwl|D4>9V|Yc0?8-RYr_UNbc-+EA{;nm?ylCL zVLV$#UYX|*WGowa-TqW5A2HQ{+aFVm5j;)g=bfEBxin8u-Nf_g9wkk5nEKE@yLS@T zjkaOZl1Y2Yv3{w=REkTR6xHE`i>+^AF8%7u%FPZ|?pj?}|Cd*KCWEmdZE|4r=j&vF z@{#VK)1xnME&VDK{9f|4X#TNVsilI!DvqO_dl3%Q=i{`O;Qbq48SvZXTT!%u_8TGjv^U|gomy>Z{ea7sCDb+%vloB1w z-|=PAG!(sDPOnw8SJzTx{ruo-cll~9uh9p?FfZ?JVw{4f)vOQJ-L0RFiMpSGm`5gy zr@x?JRa=7L&ll_GE$qqqzp>KMk-(z(dzJdPF0yD7rkcq~ef;rcDBb-oTEWV_{2qf6 z|DO{U|B1%&Ld>8i&;Z5_KzY$kXO9K-tzee}u|(T|gDV6#p7!=&TSHW6OE@Ahq(h^4 zQ$Fw>PKHow5GM;6g6+hGMHj=SO@6-WFZ@7kKJ=!;th zA>KDq2R>kU$R5KVi^=?D#tU&nz#fp9i{HsA<3SX_E-~frPAI}60;y4d{Y94%;Us4X z8Q4ckz0m68e)uw{euq*3$RWN#pb{_8-FB|d?%25(HlS(bLa76L>OAQ058<7By&s4{ zN79>8FDQfD2|IDG-8K3oNf5}X@(A!DH0?#kgY>ccLHT0ePQP?*kexyDFFhXUTsp{6 zIs?1uZ8ga`@_&N$iI({`LlBgX!A9|zuUSkp!8yr+Zkh(~vjO5aU(IZ;D z^_Pf&QH}YL(l%mYLS@kjkAx6G$!6A@S!*d^Yfmq$yUmpoR!Vi9yn zX!45PvwoQniaYL$?S|s-m7jJ{nIv?F74*>;J`Hj(*36nL79LMs-Ap$=gC-Llfsz;0 z&3Js-Zl0neySPR^o>-WRyJ^UMus9_iNNm|+2dCkr&-Q~{QeYY{=}RZo*Xwaz?R7JkzPXK&Cu3jBD#(p!muxrEtNC?5V9@f6 z!5@2@Bw;btRuW0^eUEBgefpetqIa`ThvzA#yRF&Mw8g)U1dOMIpV+@DG#b3OL>WOM zs`Nzc53p6l|`vXmni8Vwmpos9wOPV~+O| z(C(efRMeC;F#03S*mv;)OlwrTH1NXTW9GE+R}(&ZV=(S&`X_a0^jyw@<)V>hxG#1) zosoJrFjWeD6gV^pY;dpKRc&h_94%n^#VL@Maz*)PX0d8!l!p1p8*e4vUKo1wsDy+j z%XMb&jkw(6Ymnbxsm6IYTd((9vvKu*Pr-a6rDM#;NMTC}%hY)GzlmF6Cx z%P6*sUtZ>Rn$*c?Opnc3GCB7yV})dE170ny2Af0Ebnw% zzeS49F989!^m~%2S8oZSS;BO0tO^wQtQ#;?N1o{&;lpJNrtv&ur~px$sE}}zOfK_U z!e70~xdd&$_>#H9w~l>ZkkhfQ%XqgErK7uzzZx%J_ONjIlYNTc$Nmt%2hEG8E|FUh zn_UVs`m5JunX0fhBdxYbqg~*~`&`*ko}qN@{wgK)C*!|^b)C?vt}(`Q9)bbwyWY&wp4`fm(z=!j#iWX5^jQCNgW4s1eUu% zw`j8H$F%ydpuBoQg7CDy-NXZ0&jPhSeHReH(y164Vvb?UsG6Dagwu`YPYTo>nF4J` z*(J@<2?bO5w(q&`B?`R^Wthzzxb{g`5LmtlXvw+lOody*Qai0GkACNGu21C4f2y#g;tBh zSGQ`#l;8X#;B8d(MsYHUa()zv!+~RhXRHj$Z|rR^E^w4}lx3)nvffe6q?sg667aoM zwQ=gK=bRo3SP5Y|9&eMhtZCi zHqWeM1Vp83b8^Cu5%-EQXRTZ`3=l31E+Hh|AnE0vqVeoz8ZdlQ_8}PF)LPZyLY zB$`H-h6mj!q0)0%K=LI+mVj(vXGSr#;iEgdb9bcQ6_=(;wv>^|!@Kr(Ono+Ei~#-M zo%I-v)wo4+4|89o!5B> zn0^-hFcz=!s`b0%AtgG$XLvsA0D7ay(EzmQAJ z)7o=#Lv(4ck$H&9Z)hpRIaBqL|5sn<#gRMFGbNbT?N=j$iHAalD{V2J>sL-KI}AEX zyyWnWBH_}_vtrU*Zx85HWxD%gc5>9+^3=|5fitVPcoUrWkZ%$H_#hSjcH)Fvx3L37 zTNed2w}SlDH&to9x!xu3!G!rUQkrKizwOa+`M}+(Af0f||T{EUs&c|3JVK}40 zFawfgZ?Iat?K|I&O=GYGCMvQpM|wW0!as@er{3?m1oZe>(vqcL@&ZGgRrBaZgIPT1 zf=12$gtSXj$?=t>kAHOuUHi4n|MwK(O60>Q2FMNeyZn;P-+&vuRgu;@3F5o<#*bCG zl!}=udP15Wbc=|3S(9JXPT}_oOBgY_pwonmZ=mGTbLAdBUlXXmlGKOfrSyRynUGmY zBd=)`qoyE%C`-*^1i3Daz(xHA;~AL>{`P=J=gH!!sM^sxn~|o9(a}+vbQ8RU$;W942<7H{-VPlyzPZM9kV>nbd`fOq zUP{kl*1UpmL^!u4OXPSy-AkGS!_i#|6Ao znA7~K-d(mSM`dVqzmD*)fg{!fJx*?!#__nWr4y+$ZY`?Qb9D35Aa{x1M{gYk#GVo( zM`x`*^k>`N;Tj)O>u0XX!NGYx-7c9*qK^wLZ0+rP`0G$>7ayXZKR#DQD%z_{ClJ5R zp%G!*dyAjX(j?*e;tPJSi8fo+BoQIyT01PEAXP_84&f9CXF?g~$t<*)olLhq+C>D; z$23OWSn*vFlMz@gkZ<5B{gky*tP_Q2Fc3Dl{dIMz6&{Gw7Grq4)F5PbLiR9DKR%j8 z#CcfBDTVNa;r-N|$5DAePO~UCf~|fRdYzVN21oxS@5bbSjFEd)LMsn<&T{DsV}JVr zFjUhonLXI&7Ebu9#Kz-lS(Yp|7uZ9-1e6&8yy8uh4i` zpbb!G^qg(_ll5CM(W();Lb`SkHHvkYuP-L|dU@*n6L^vhX$Qd=tuO^Z%bg9<7=RJHG z6QuEXC49cuOUJ0Xaoyii{^~Vggf)tS;^mWE7X{8D8Gb6(5TTgW$a1lM<+R79^bp2 zNDQg*!ilF&JJ1#{-kP*0S#e_tOL(KXZo`*g;*EvTbS?3@E zjQ6`zJI5MjQN+CmQf!GBR6QE~5WvHZz-YSO>Y412^9yvA)2jK2&#rDL@z3E~rQ@Xq zdSIt2FDsFafM_yEFn4!%v->imi2u3TeSKxi$196S&DukNj$Q(UK3g*0j1nI?M@i;p z!L#$so+bcC1>I;cI<2xBCKV1FgR`{}41*U1e=v$uRFtl7r-F5?8&Qaciu>pq!On(= ztZh;@Z)_9)B<=pWo^-$#5u}(BSe;L8D2?HtX#(+m92CP7_~n0KN#B8Vb@Og=@{R-A zB#e%1Y3^#pb1(hWf$U?$gPUBcYb}{88(AzuU>9Q6JG=YmualmIP&x&bF{)mcjDig! zh&z;7t(^05JFX+cfUYj90XhtqLQROyv4P$a_+vzK71jOs{(Y|?9*d9=0nR>@g` zE(bWJrQl~kqyd`{*tCv&Qa%W~L*7I-(mXnP38_^7$J!UTE&uT`-sy0FUB~~YOq;h9 zkc~eg_75E^<;U+irLP>Q2O-25GshUjQ31h{od!`<1e6YTFNj&BeGcHKY&923z%L%W zJbr-a@{XI>12d4kvPAqV5g!Jo;K;&-Uq406#o*UarbpO~Re{M7uOz6Q5zHOD8Jhz}jA`TFAkakI7yEyW~f(^p9(}zHu(|pvw*oT3^M@rqM{@|VV zHSpRP2Ct0{iqc+KZ}HBeP^ZP9jszfb=q$$;dTODR1&%ADHxGmB(w>D_LxV(&1K`^Q4W>_Duye?$T5|Jlu*(r_ z%0LX2=dRlEmk2huZEMYaSt#t^W&mO7gz@7Ku5ZXjW+uy@x7M@&c?*^^S5V4949TE? z2QKViDX&+(q#00hcBQ3My(TL9g;7YG!c1qQg+H%p2Gq^Bzk&h#=;(Xiv*4kG$O!?2 z+6+K=Cec&VuEoO4-lQBglFN;Y^CbNrdJi}TgF=L*=q>|ty#|gzZLI4H@AdU1nIvR$Zq!6n1rJl&pX&Y5X}er!p1t^oZ(8+^Cw8Gl7bSa@M1Z&E z?W)(>p~k(Gu|b=75-nvMnbshE?`UWsczxyc}a;f`%HimXAG1r@ys!j2s{Jloto z+d7&m%c|D4G>0BOTHOE!F7amH&%OcEr)%&%Cdmil<_hKzaE5<_{D45dOpTIARi~aD zx=uY$aI-B|Lrvgx^O0EYO+tGP|I#QWR{CpE=_)fbJt(g8t3GAnY3PgE6m`KJCW#?h ztTl_VqbZ344&TkKDzS`dW}mUA**5y6y}Dmr&-1a14N=u`Y{1IdhUge2-|eJvOZ(_^ zs@4sbhkxABfF*eew^}A6p>jjdhe9g>M3%>o8gGhdJCe?MQ4FM|&Revy8+c_`VL|Ev z_H}wE=brSx`YK|@(ay9aG-KB?X%_OSfxGKC-{+pH6h`!Ff`EX9uP{T^3HiE1sB6%l z@s~;VO(lQx#A!2}RR}vBojR{MU6H}4b4%6aU{3yGYjw^FV{e&*{V+A#G`CmY?d)Tc z&j+S7GxDOWteBpf3(T&ru#NeXtUgfiakDWYD>!2uHoz?>>QyW>GkLo7;;cZIp6DKI zry5prgx;XhU$#&L4Y-c*&FRgVZ0UqFxF%-`<2GIXnR<@|wsfxSP@zuyfsuGk-&f&j z0xOi^tQ8Nmc|7yHJ;OJuxB8hU1m^pbzv+A|PU~tNCA+wgo+;reYWOXRsU~P)7%7Cq zm0SP_{dXMjf|3?Q4T?|mJ*Zm6-dScdtvJbhTJkEsvol&tyVoI=&)A z8(rFFsoo^9a$FlGeDx}vm7||>^&xsN?fm9wA<=k`yQS-ow6LoQZAMzMfr)+d#>wHo zu1*wVcI^DzC6^AO)H9{fP51W{4qH#NY7E)0^4)0lY^OOn)pFq(o#D`-e0{bS%+lUN8 z?NVAxzCQ}fNizPD7q{rW01mrj8I8X!508ZvY|KOgohgP({}qKmsr;dq$q%o$69PWb zP8-B(lPwa`w99s^5jOIaS!c40r$Qf?xF}evhx+uH2Fu}81B1){3Tj}k+1uKlxU=hJ_(aFZ z=&BmOmJj7nyd0VzePP*aL8|q7+vhzyFU1legQRTG^bX0{wY zIKVRC;A5Z0$aGZ>U1ke@G7JsY1#8U84cQd4B)x=->6~^PiUaKrW~PJh&V>Ic57wJ| zjk_lw@xnxWjBIab3R>7ZAAeKbAO3n`g#mJex}O&JoOOVFin!k$x!PNXE6S>+Rn)rE z94Unk)Ax-x)1ZLHZJ)D*>=S-om;f^2_n)U=;c6i7Z) z?|N~K!UaJY7J`zu_w!uYkkW7#$r8ucJdST>Zv_Q_Em+(&bK4!gHaHD<;Wc^9%*-Hd zriW1uW4+%2pRRO4LRb?q^@W&YY^O8X1M+xaUrksib0A)k42nS-YB$w)5iqk{}X-u2GY#X8!oy4&E zEu^v7TIBKC7g^ACi?SbZEGjOp>xhDnT?&M(E|-NVH~l|2Lr7r9tJ-8n?ZL=qb=2K>5)F10%3B8A&ITLlcR|kOm?+ zFak`B1~Jh!Md*=$F&1K5?+;ptW6C34 z*39f?y@=%TU*I7JGTm@w3?|W38+6!#Z;p_^wH^rHXh6Kln4DKOf;L94!+|Ntfl#Oi zoSO6q!Hz$DDcDA$<5z)ni0~u7A4T013*Kk&|G^y>s$-447wwlxa6zs1?f)GQ6`4J{%(-3nxpSAH#kOZ;N_dvklV&v~%W0>> zcgp2%S6H?zwA4CoPl5-^Yf^LHVfnz{wh!RKt4@TBuALgX6_v%HMwjtlTc?0UU>1K# zQIP=>55P0-fIlR>(BX!vk2+jc?7uKhkpUt)yt&^_W9Kdlq%*>b5fHy)&|zA=Rj?rT zSS9+y(+|*$V?Bs37ns@X4}xg#b_LOrOp682AntgPEumdJ0#)w|4J<|*Q_|W}PR}iP#WQQK~XtZ;6x%X`^wIJ!RddQ=-pZGPE4cJzzGKTl;dm=TZPd1@1GM`|X|w zUqe2I9~?XZptxgELcKcW)rODzrBbPk_mGNZqe11c$K12aKAR3o9QtfC=4?!D7al_Mf_UP zt>lf@Fw|oj)uK7TuLTu}fmsMi?3>Vmfz7_Mi;>J~j<`k&XAQzLi2KaItAwecAK2=BUdTwWauhRi z|4R2k;2qKNfh}pp6FF%C^zA}Z()?LGT!vKl2WQ;+NDqQliI8TN9k(=ki9g3Wgp0&# zn?bvFia}q7r*_2dkqqL+6NGp-?>!Oswlm+H+Ikn86R%Tl z85b}>8w&JsN16-Y?6t}FoB~~5jkn3yrhK$DizOCVSh-Jh;=`8o`QV`kj#|CAq-c#y z=gG)%$)%e@v#Oi}?w=OQDN=M(`naoJ^YoZ87fRTJ#v&N-x^olpj;}E4a~Pko1A*t z;5%*f7mLuO(=UnRN-yuuwAA(9GPXr*2IW(~wD?3o`4CEhznvY=@$F$P5Qm#rrp`u> zQXg*UpV*Sb_4vTR+I#apjxkOQiS<}0{ch#xK)ay&9(D~? z0)kZw|ElCR--w)|Y}-` z-;Q}l=HeDMeqEHsbJyw210`cGJKLoAe!Wp%CU*YH=#W7s8o#W1{hO$<$lAhGi0Ad% z)awkYy(PZ}dR24GjVsK(-+v1pGbfE2SshIofwD*Mv_lu@nxLi+!0UYtY170)E9^1b zJJ}W|x~M|M0uX9mb2A1pT?RM8V}6&RX1Zm(Eo(6ScDX_zMZ~`rY8#+P1?U^|-%GG` z1nFfCX|RYl@j1tF)?D0ii7!Wt$ZWLc>zsVP6b-708nPdQ*#TT1u=Uf3wXI@VZ%tH& zIQb?1vIMy6EG!CVEPy?z_F(htj#VKdO(nor0HsoZg%TgxPaD;DrSb zT+KO&GYj#l+4U(rsNDj^5iOUU~20^^b2d55*ny!?1Fcdd8gtP+oX4e>z+8c-h zZ;F~GJIuQ__TS*1$ASb=DO9Y#^YSnBbIkRvWjhyYKA;^29U(Dl2BtBB1dtO0JCe3G zS#y3k&uKW%Q@G=h;Nax8Nib?{1fp4k8g5ZO8I!2I<5Ku(6nLYS5lCd@yaPs2-(rD} zIMnpjNChp|zU~eGr}-9q<#>>4A`XK8`M3YwF}M>gkH~0ny+d$m<`pOxZOGl9LfQ!$ z(re&>0KS%Yvy{Ig_8k22W@zfG*^49b@$m>Jm;QhY$bG`WvIq$7YCSn*IN(T!2pjE~ zatHx_YZhio7?YaJ)(YaQop=z%3qbK7;{iLqLIpK-kf9=tR73@is?DU4LL%vcHwP06 zfl9l?(lXrzG9PGm@A!!$+HbAIT(aBKL_~6Rrbki00y~I$4cc01MFe1UObd80A6EP> z`&LuS^rs6u`anB|e#cPPp~MPb4=utz1~0#&^^ki)Wm`QNhy^HU1HoCKd^%G^K&!mz z#T7G zip7V#->cWIP7>XTOx{axYYqr(lutuz<8f%{xfpv+9GtEE4s z*t8n1DTr65 zXY5Z|8_p!1^$}X{xYIm3l-nBk=?rS|!hnUN;(IIo^Z5=2?l+keS*3B(m9G{Ac-W+i zrwCIS&9eJ=>-!ZR*PZgO;*Iz7`3?z|J-$MS!iRt=g*TsWS9QJVAKtSSgYfh&8ut00 z&I zxN!q5YTKW8q;WmwS$$taD}jB5Ue5Wid*f=@$iua_$1QL|%gx0Je>p%3IKl1FEv4E> z`U=Oi2(}W_AEH_!2j`BP?wC~wPx+J;SN6P79RcKTU-5F#o`o>qI>I z5_ZfLxGqI}H7#bScmHmepYb8JY^hv9vGZWPQdz_;3)iXzgIYs}9M45dW_@qne6{H6 ztxM!3`dpPoZ_we?1-01wo}`U>KHU{MRHUWpnRx+62sB<%PoN<)Qwh8JwtR18Y<^QU z!pOGmP0QW7QpKC49_Gc-YE^10a81%kR3pJaI9LtGB+_>H80q7&qMvR2?MCJV{mVC~ zzlCNCiVW-Anfp*G{$ooqjpve~%4crOAURDDbxtR|aEdW!8*sH6-Ic&R;9~LH)#E9B z9M7J2((hFHvyzK z5M0ELkwxMqem*s%A-R8qiGe}Nb?cEGA-x?hy+yAw*{xg48s>EeZqh8*F6ODzT4d#-nG+1HQkwY+Nig%o$T98X=em^F3e>5jo|mX@ACy|T&_S! z8E1uT6cTku$VLH6XODDS-vx{pKV6WF!gZ8=yyR~O&ml!ElsucP<<&@W^xO%U?bz?g zgj`qv^~6agP~{^Mw4VY=ytpV=+EY=sb5${FYMJkeY-Fy2P8nDaD?h$XEfh$K5=OKs zGm_E)#-ID~ql{>MPR~G!6J|jk=g@Nh`Mow0%a2X>QDS!>sr)M&RPdNu&myXKM^NXGXbVPo2T>>8;UC~#2j>vk)v-gNUO+N~ z_~xNdU-p#m{^y=PVcTE*u@4k^;(*?`D zm$zfekOZ?Bc`+ybp;sqHz55P#{SzklUbkb&PWt6bVg3`>tA*rj$HcFLc=X;$&BnFU zF*iO1e906LhzC+Yja&7%*@>oKnr&T*J36%sQtDC9fM@voQuNYj_e?x$S26nG3 zVlcN-RpbMg-)Kw3jTfP>mMJP+ks(hhOq8ivJ_D4um8ZHZV5j)|-X6O!-Sz)=H9xYV zD002`MKZGtG7x(cEe2z80ZL2emp(&9)dH!_!%P!q^6ohXwrvrMs2rXv0;;TsJ-$NS zu97;eD2au2)Qlk-1b-#<;@GSj@mM-D$$LIvI8}tRbMAbkwr15YnqYa_StLF`OIV_+ z%iUOE2e+iyd+ir<;+5-V&#{slpz-*7C`c606(9Z>NFwFV)9Mjt=*YsO=xUOxq=B{GwZ> zz-a6uq@pr$I%1bw!IC=xAKdPh-pip&v8?54(Gg1GHyCt+eIuDmV5vyeP)-Kdrv~*7 z0cH%t(e#`r+q1Er(ZK|@QN+1-J1?HyKCdAkc>12FqJ1W&RcNTT=;oAbnPwlAg!|Ok zqh1WjI6ja&A6Qq*i@7f;P|WECw}Oqv?lhRxMcai6ZKzjJR>g;TdTVa6^+$E0Me#2^ zqDsB|`Aq7Ix|4aBTZH3|Ez4<&y;PT0deR+qWniqnn4B)1r(3;U17hTRGcWL~wD^uoB&RV~Io0I5wHUhmXWiZwXqWA!5{q+v{Aby&ym&lwVT|Jc4 z``Og-G_~Mao@mLO*@C6>`78$Bxah3lld?yrd1G&st2Sa{?I0}L@duX@*<{+Q@6 zwe!E1W4q&tv+lHgwp5UIz`e?Qk@(YIz2R3aZ(aRX2WBleqdCo+MA!F=HG}5R2Fvd^ z?C#wRZEe}j0a{I;x8+BhKF8#)A7&aTOwHNYK4XH9E?@oO#I=4a0~=LUz|+b<<%W-| zoYyJm=XwuBO9$)JnbeE&D~^JXCijO&Ca{6o+dKuEXPY0Z-}tn^>Z1Gld18U$bV&== z1!D(=7!#HD?k(J_oEM%s9>XCWXf%a2FPRiF8(NR@tLlg!BiA3eHhv=2V{ulq1PGBdop0Ok zJth6H@@vaXBK%6Y4hCaY;Y^N+w2v*-h_Uv(>#-_cK`1-zV{JSu5E|h0&zJwNtJ1FP z%TAE`?_L1^xKs;t4HzX;{-&ZkxV^{#mh6 zE~>DL`%moq_v8)G_yBPQmaA7~!LTSN=P?cHCgo0;0xSF0M`=<~g52{rcHd2M{98Pf zANUBMZoUPi5~!_&JX&DkmXFR7xnQWJEy`p->nZf8bay#Rxrv4|*bnc6jY05Wd zR9J+F$4MFrd%v{U73$qBZMjr{t-ukuea><+Lr-%GO=B|85G^YZF6jb3$n zka%}@@3S^4$ZEjY42%cWcFAfJh1B+_B(5)geIF;e!C52Os)+|#{9bI{zMV1VytQ0E zu%*CB1)^!gvq8X7VppTWRiVg(R)%TjOx9LUK`) zn?DpG8zMWRx0lr|T{Dsmq%&8IXRBz0U?QL?>*hJywB_AAO5+Q(39n!it*Hd8}LfKm^>Gy!ql+DlglieeO!BJ>O{2PfHnB>Y}}o+MFmdBNvG6 zX>P3=kDu_-TfEZb0w{QRt=qVnz8T-M)*5)fgjiW^Tq_7MX@;>2xxbEpiR<3ewo_MbBhG~EgDeYkdnf#EsilW1kHsR_p7gQ72E6J$|MqA1Kq!75gEQeTw~_@TL0y3yZEtS zY+R3pnh}>rLrUaPcFp*fUQYI0EgAi`alKcjVN@-vQXz6Ofs9PYLZ#8Dzd#zDy#uUC zBt#FKyT;`GRXG;p$4hp^$v{yKe$qgF>K@R;E5)^EY8i% zn#`zu54j0~bjAlfCjI;_?7V`45~W*yN08frgHf4cu&h0U6yN*7&fOlnnU%zdIt*Db zBlqqtqbh;O4x@AAUFYt7qfUi;AH1n9bIL_?_h}DG8UFwIBrtdk3=AFV9U1Kzo`DQ^ z?%eq%g!=j%83S@RwPQ3I4VHdG(?5N*Z;4k-drXN^Xea1%tM6-?ov`yn8li z^w)@;w-{Kdqi36tW!))W6l@W~IhhmXZI(~c?G>2s%GKU3U0X{<=2o{mCBCswG28#W z;>U(YH~;hdE3ufsbNd(ce_SOKxE3FIcaBymFDX^N-HLL4M8ldWrPh@6QAR6Y$E%s+ z>mTnL#dEytqMhssBG&4T?k!wN-TE0>(Gg|IeOaQB<;t9e-1i41?Hu`me_V#cK(s3< zmz)t)yFTyC}#-)4I1aT|HiZhXIDvw38jpX`;&1ir%M*u^Og0ZR<~T7YH%)7_61ZmJW%zw^j!#+P+!QM}<{ zRY9EDa)H}#z9so?H=JahZuPaG@@m2TEU!M!B9E3J+Z)eI(6O1PbztW5Vb;@0V@$F; zY3Uv%&6rj}7GH9Wx23ssIyoS*hklA$fe9;gSCkhV4%rjnOMELKx;|XCjm6S#^Ut*o zthaQj$w`~%FX*7j9^3dYS9Q1(+TPa2Uh(lZOa6Ux#vzUD1j&p;1g_bPi~p=Z+Mxvi zz*r4k(y4emeEh!kdQ+M#`V#PX%y+-%4|SW&cg-fX)X9Pr8ygQ)Yq@V@B?qoea1*jnT=Vj zRn|()s1k0ys3*^aK~3%JMdVEkCu64P=1f!zHtXW&9G5p4XazR>#2OaY3Ove|7t5TJ ztS0hI`tr@kBo+kRBOplrbzg$1CQT_%Kf^HH7`p4(w0G+diY`RYr8`fU8O3I8NG!Oy z^Y0u;!&I|@+v>kP<5t}$5D~WGbvUpw)k%F>UN?OpKiDCS4mfqFg8{ap>lu-G9o&tM zvkbKNAFSOHuCs10U8Bt?b1*aWcPOL7+d0fg)OK!bi=Zt#NjyrdX&u`rxY11|ACPf< z*aca|*;5%IEU_A=IqEDQN;(rIHg1a@6za7x;9JLtwC|ijRL)x70 zjpnfM^0fWj9D|zm*FfYXAArx|I8|lcQ5G21=5^|ln$3zxxI9bIWjB7PfBkj;5?Q?E zvG`o#PZw1o4y?`sbs{cgKzGnrKshNc_+HkBg~2@d4*XdKv|)#F?pml!;DkiXPW!|F>0WAw&1JRXDeW??8~<9kf@E6 z*89e0RdsT)A&Pm7sTr+9_gqiN`xk86S^ShTzzo#%Ygmq3ls%kMePp?si5^I&H#n2Z zSpO!C%`qIEl+)33x3MSS%2ks)bKa_b2BkNQM7>Pv#N-3TQ|=LU_DoQnETN2!)_eSw znl(p%Dqe<-s&|yl!?BL;fofzXfw=qGM7hDmd#*h379rNTX|~6$Z}9PLp3mCgk0Q-R z7uig;rw#WIDIo8zZV<}BL6a0wTT=RzJiHflQX)fEto$iY*1w7^aJp)D&p_P5^$t6$ zWaCp9$um61n|CUboa4P&c@B6fAZyh*?d@@GYx zB{zFPT6{rOlzfkg33d8-+xScppQ=tWqpOGGCS9Zs#f>w{6Zs0FUM>*@x({v z7ZNk5`de_nUwwPrSfg0G(7TzE_i1OWn-Z?8n!X#CGH!3J1?S5dq+9a8 zoe@x?=KbuGUHVa3NlyjSQqY~iXV!d}Q$f#xr}l^Am2ZJO1&0&EpIl9QKs~=MvT`w< zF*3zVk=CBaajdSQO|;zK{7AiTvW$DNBq7CbQ%hvR2V)oyo#9ZTW}`K# z|9fachpF$)p%D3ae}{#;>>&>#kLxv>dL-l|T^OB$yD7OSl3o^8T-ac5Z#*~KPbg%j z+oDT9n}T^I6xT8<>`#Z69A0XEF3E_d)F_GFD!SUd+lF&zZ>9dcn>pM!+WtD1Pk01d zb{p~Hcbj894)?4jLTPw0!WPZcw2j5m6h|J|Z6qELS$X_aC;I+7d%N!yZOaT;uIwk8 z)Mbx{dnla9A7fQc^GgX#bTuqpR4UIi8dnIErft+SH(mTvAI=kCBBTv4AQyZj@?;3$ zo**+(ODCnJF$nMW`-I%2rPq=Y21|}VUgY^wUei`{k96?t=;SaQoIFa};k$PALO%^{ zV$_HT(ejTk&s@*wZr*OlB@oGr3vc-Q<+j#BZv5(!pzl~71)J-)61(1Ln*9aPRNjv-iH|-u*lKch23)loR^TsIVRbJuz_7km7vI^G|Mn9zpu8e6g9S0ikPyK`;<2D=1(-&Vd{wX4B9F>YTQBkmDj z6>1|P+Eyf^l5O>ApJ3yW+Dp&eKc@NjCKX=M;Zs)_{YHK(e<+JtsxS1(3=uO-S}*IW z4oz!&Ni=IyJa`NI&Q_cs0Q0Qd=Cl>|AV5@ZPkw(DqH%SLeU6mBK%OoLU`Dl2YFk$$ zMnobhj?P^ASmUc`Id_hN#mwxgKQnHgJ6XvQm(O$|cJ~{`$+6gQJIxJd!2b92l8JMQ z#MB)D^@5q#TUDc&Wgf1kudn$96Y}5;pJG4PUsS-x014NtY-_<?AqMju%n)5Zw9t1aU>m_82v?FIEW2VSz5LuJmY1xl0Ou_pmpo^@G6G7XSH^W|_zJ z-Tab+_0cB*ZRyD|yEUZrFbog2=S04*$&RnyfB^S)PH9wc2h2kU7K%BfVhkVKQ_ws? z^w{L2v(Dcu61aK_2e=8ZUZ;4`vV_I@J`3=nCx9wck+^DzeUOE4;E7rcUb`DuGJjv# zduOdo%S3CvK9RlMrxT+X!}9C^j5fWE>VnOyxUFl6*RKwUY_shkbpegtx2`S?8Xa!1 zrlux?!O&T$Br1uOkE2?jd~SZ$7st=#aqF(x^t(Gye6=^KYipI2D=tFHOf^mJ#AI1F z$JnaO|F|FlY4So3fpGIB@X0hLXyqm}uu2GI%w|6zjZ$}E6YN2?(!yn~>PZI3de7y|zG$LqadNrid zUI+Wdp*q{_%`W1}wb2v3f@6w`QGCX;`LjF3l6Ob$6+LuAb`-clf}eE=qRh z2|@ebyW%n;iaFoG@7a@9Ji6-E!1_*l5@3apZMZ#`c_S?U!nV8R6v0xW6$7X>HgVnf z@`mlAFzXnNqoQIk<3OW#S=&BEfwEccIDXbj-Y&ZR%>dj%d`9S={u;^tPz?g)hJq7H z`k(vC?sRmckP2jAYPdNm%>HJGN5qfe-u9MY96yb4H6|a?jT%vk=z|-}!t?zyKlO7X zEiT*X71qWr&zd(*(jpm;`8gG8m5x)c()DWB zM8EMV=vq^=MLyS{nC*6R*0yR|{DkJ!SNGrzgL$c#v3I5CryjI9_?ug}ieEEdA%m^h z&&PiKFmXxRt<0fOX0N2y_))m z*6vMg_Dg6inRW(cy+KB Date: Mon, 13 May 2019 12:07:31 -0700 Subject: [PATCH 281/737] Update configuration-service-provider-reference.md --- .../mdm/configuration-service-provider-reference.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/client-management/mdm/configuration-service-provider-reference.md b/windows/client-management/mdm/configuration-service-provider-reference.md index 640eec77bc..e90f12b931 100644 --- a/windows/client-management/mdm/configuration-service-provider-reference.md +++ b/windows/client-management/mdm/configuration-service-provider-reference.md @@ -12,6 +12,8 @@ ms.date: 05/13/2019 # Configuration service provider reference +> [!WARNING] +> Some information relates to prereleased products, which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, concerning the information provided here. A configuration service provider (CSP) is an interface to read, set, modify, or delete configuration settings on the device. These settings map to registry keys or files. Some configuration service providers support the WAP format, some support SyncML, and some support both. SyncML is only used over–the–air for Open Mobile Alliance Device Management (OMA DM), whereas WAP can be used over–the–air for OMA Client Provisioning, or it can be included in the phone image as a .provxml file that is installed during boot. From 56a87a2622afb53586e1b69269a579bd504ef7fa Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 13 May 2019 12:55:37 -0700 Subject: [PATCH 282/737] draft2 --- windows/deployment/windows-autopilot/TOC.md | 2 +- .../windows-autopilot/images/wg01.png | Bin 0 -> 2436 bytes .../windows-autopilot/images/wg02.png | Bin 0 -> 4129 bytes .../windows-autopilot/images/wg03.png | Bin 0 -> 89020 bytes .../windows-autopilot/images/wg04.png | Bin 0 -> 158281 bytes .../windows-autopilot/images/wg05.png | Bin 0 -> 264215 bytes .../windows-autopilot/images/wg06.png | Bin 0 -> 124860 bytes .../windows-autopilot/images/wg07.png | Bin 0 -> 193713 bytes .../windows-autopilot/pre-provisioning.md | 22 --- .../windows-autopilot/white-glove.md | 146 ++++++++++++++++++ 10 files changed, 147 insertions(+), 23 deletions(-) create mode 100644 windows/deployment/windows-autopilot/images/wg01.png create mode 100644 windows/deployment/windows-autopilot/images/wg02.png create mode 100644 windows/deployment/windows-autopilot/images/wg03.png create mode 100644 windows/deployment/windows-autopilot/images/wg04.png create mode 100644 windows/deployment/windows-autopilot/images/wg05.png create mode 100644 windows/deployment/windows-autopilot/images/wg06.png create mode 100644 windows/deployment/windows-autopilot/images/wg07.png delete mode 100644 windows/deployment/windows-autopilot/pre-provisioning.md create mode 100644 windows/deployment/windows-autopilot/white-glove.md diff --git a/windows/deployment/windows-autopilot/TOC.md b/windows/deployment/windows-autopilot/TOC.md index 3b57a30541..e497301f56 100644 --- a/windows/deployment/windows-autopilot/TOC.md +++ b/windows/deployment/windows-autopilot/TOC.md @@ -5,7 +5,7 @@ ### [Network requirements](windows-autopilot-requirements-network.md) ### [Licensing requirements](windows-autopilot-requirements-licensing.md) ## [Scenarios and Capabilities](windows-autopilot-scenarios.md) -### [Pre-provisioning](pre-provisioning.md) +### [White glove](white-glove.md) ### [Support for existing devices](existing-devices.md) ### [User-driven mode](user-driven.md) #### [Azure Active Directory joined](user-driven-aad.md) diff --git a/windows/deployment/windows-autopilot/images/wg01.png b/windows/deployment/windows-autopilot/images/wg01.png new file mode 100644 index 0000000000000000000000000000000000000000..fa08be3f484d7234479a4143c0290f21f4de0835 GIT binary patch literal 2436 zcmcJR`9Bog9>>R)Z7`vXrRfDHs()j%t#Ni^Gi%-xKWVqD89#?BomqFR3|Yseq&{p~4R+J2 zWloPuL{wJIG;Oc7ndm#I=AN5ArqoAi=jL1-`kldW76A6dAoiDcobi#kZwtdw3T^YV z7EcUsvwXKLP91$+vDc!s%|3tv{rLa4ITp9|O`lQi*SO``?%Dlr#;w89rTS!C8ax8| zj5iq!$AG3fzn4-O3OH6>ZmuLEO#IKxqy4?6=%uKbAC2f;S3Q>0T}E0!&wV@N3X1mm zzE`&?wAF(5Yqh=i3tD?6);W0*AKN0=zWHP?MQ&EVww*W+S^$=+^B z-&_8f0k-gDpyM{M2&0u|n_k5I;A&yxK63!Qs9(`ovYfMTc?e98pxnZqk@PP+AWp>8 zDZN#gYK$CZy0oO(S>{70F)Y)gw-K`51s82YD5tKMHa?sp1g-5aX~p**?)D7FKr3kV zP@CN*@8PJSXU?xjpdr#aT-A0IP#}+iEWeN7J5T=#ezk4!C;cH>3?Ra(BXaGmq*48i zWdps4-FcFyA79HJd~VhkS$y}1rEvX`!6qpxq0h zVqzlmBGe-~dd3CP?WvoOdrB@eh+fXV8o)+9c76{#W$w`{%-x~*-g;BIeU`*PbdV70(@1C z#}Qe*nYL(7gdV%SlXv&Pz(9p_ot-Q{a1(&w^v#44h1uJwJO3lp=; z2>lJ8$c!kzAI~3yNApeLOuDPYnKI8R;lcEpEvnfqo0u)1Bx$3m*RNmGqeEpNkS877 zESRDniY!sm+U@@CL*Jr3)ju;)46U)WNt_KlK$5Ccqo?GQG~%CY`IwdGW?(dH^o^@E zGc`LsrPan-h&7APJBL`=j(x&}tqE6Q2KNn&MkR(guHfr4#JiR&>l1u`4eoZh7*Z7F zI0;$~6kdK74`Ts)xSgXUVy!4TF&0E0uw61&4@2G!;rHji;Bq0>%HWf zW}tP6$#A-U%;Xk{&ZZUq!yIopmkp= zC#4rWvg5-i2183CsNj!zC9QOXwp;P(F&+8`p}kf2Nj@E$)dyagUZjC}H_~Yypyk!Z zd|Iyu7b}le|I+kTeP^m|7x6{@zlFrAlI6^9T8#uS5*5pA3SYEk$aj@83n0eUA3Kc~ z2MOIET0Kk-m>##eKAX++U@XeW}EzTBW!87XBTzYVjT(YvOWiXLy$Kpvco` zDb*5c1o%~$$Rp=FOkioYvXqfhrk4igg(Cajr%I{im_hWyHg;C*@p`;JAIcI9YP$0q zHh~u`YPbkgr15ef^wfj95C7EpVf|)z_%cFZ8D7%{8i)wq&7BmztX{$-bf?XcK|yLI zq3XBzIuONoW6DloRwtV|0_ll1->P+}sN=VZQnn9P2W^6#?1B6var8-0)|GU*EX@_3 z#VKz$%_qI@Au5P$0qdDG=w~XUy(v|r3!QtYd|ZIcx$wh&2frhu>yDyBkmo1~k>ynL zM(YmN1lXfo>A=D7@j&?H(vVJ2gF{461M1p!hMhzKp_>~6J}r$8KzG!L#sd8oUe1^< z!QZ>1F3v2AM7VGU>7YrvOyo3VXrdCj(+~Ebxnq)n!*a)?^b+$6T!B61&Z;$61f_5U z0#d*H!d|pR=4c#!6qJEZw{TuqKPdMdTdht}g6$J5*;^C=A zlKszfVuO#(#XwExObGWc>OF*(^ZX2KPUB-I{jG|YRLkuj$kV}dDScX>9m&PR30z~v(W76sL;jV0=6HQ$cjL>b0zUjV5i;)f(??LiJ>zB& e;4B{Z&ERS4cc(6^1|#;*34k^>M^+kPWB&tJjbJ_i literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopilot/images/wg02.png b/windows/deployment/windows-autopilot/images/wg02.png new file mode 100644 index 0000000000000000000000000000000000000000..5de01d68032b1fd57b1613fdde47453ed4a30a26 GIT binary patch literal 4129 zcmd5<`9G9z_n!|EvMUUOKE_g!hOuOcgfT)PWC>*$GPVf`!yqLegHX*3jbiL;GWNA- zhRj$)ktNGmqC)niXL|Mh{_;G}AMpHe-}gD^b*}3==XGD_ecmU*>WV2Jj|2|@0N^u& z8`}T?e^s&MATBo6nP~HPtWGNh8hL(l^KxN9Y{aZ&^I(H!4F$e(Q zZ~y)LMGGkO000DP%#00f@42p!dK0DWL}?Kv=8{?sl2(D~CViHgLi97nK$oJI9UKy) z25lcDpAz3ZNX!j2j73AIV6T1MPjaasg$Nu+AD-llhAJ4afF@xu$ z0lhzC|+u`XWd?lSD;A_6w*(z5j) zcxGKQJv6lmRBgqvrc{mDO2IB^rq|@O?r$dE6)Nt|oQ&!^+Yn!Ec+(CdMi8QqrJppQ z<-d>0ZWJ=TQC&;ftBs8>er;iYu{ONpNO`{bTFK6+POV|F*4V$Vs*0Beyjt8#cdvte%>DQ6*PY>aj# z3sZR;7RxAUjY*&vvJ>iKIZHaS@}E0a0~hOXyN^Jf&x&$67R*pRJx7qf+4U&#eIf0~ zXYc7nw0ko?)wki!_8B@(#@*N~hSA2-)S8wWcE5>WuFu z7i3b|0i_RD>76dNbBfMIzF-K#{3c&(Out(}A8PO*uohTE4+U;7ux@QB=@6NFhgNX= zFk%NOW_Y&rm}JbSQ&3@FqX}UVAG2rql+7sP9tH=X^ggnuM-80a8ng5DsS>vFmCRyF zqyFcynbV{0FFp>!WSvmF_I@xx!@hn8EKcgg zDeJSGS+xc88ZNj^5b|K%0@hZ1ypzsxK*OH@EWiI+lmEr&Y-(yMrgCE&N?>e!9hvj? z6Kwr;xYzi-MX5rNg8p?FsqK)-mKLc}8!*X4RGR?T_Sbu{0?5F{0eKx)%qz`=Os#+{ z{YWQQIq$&DO&>%ADIm)uenmKrnlLG!t65}4h^0?FGj zxrn2|)LYb+Hk>CLRFsQO0MH#2Ac&YY9QXg0>7qVTPe*5WsiY$JwYm{u^`=+JbjM-u zz(;Pzg7%$p4|nQO0qM_mXrnXc_dULIA}vnJKnIB7tSk+77r;g5Xb_|=!_qYDLRSYa zI3p{3sVMtU#t**ff0N4bS`ADpD!E?4FH4JIY|qXgh}dRVR9nh%2hF!_1tsjdT=3P5 z4A3*@B4etYzr^v*=J`IQqQo8VoL*A}lk(T+dj(`o1@h-2ckDGlA4+PlT&yEcaHfLOnk5OUF}w`8@;RF7CQc4ELD9}l zeCoiR23rAbpDRzvF1GmF$DiyNOQ^_TzFiq9Y3UU4{qdlSf$LbiWBfXl9jfrS0GJ>@ zcm5Ty%gok)Y+c)L(KT&Fln*s|np4E)4d3GcJ0nD|gDUujEHES0!6uoNGm~IF8B<@1 zCpOxIGAF!itHj=_)JyxE``Z~R+}(*5hwk!`jIID(zypH(*{G79!p4V%F7fDyG3B@F zjcD5;$wYPKVyYp&nSWg!T!{lk5c{PZv|X${jqRUo1eO027D0uKyY1S13&TBYmW96D z6uzSgu6zZGhs^k7AM0~&%?otl-HrRRHbI+HG#a9x@kDqPzp zX7VNX$favfsEcF&wqT23B~7rXx3mpOzwnf5$6ldig1t3@+M2kQv+ShshUK6Z-~n0@8Z-))`uhJir9JTU1zR z=yg%3vI6ZLqp)i_x!&I5?dl<^7w-3}Y;c=BJtQ^`#}xkHUP5sIeS#`hpukH|1T!O5 zwq9eqAg@q`;3rFIJNR0$T1+d7r471mrM*{i{XzJ@s7;@F6LCPvInHp!Km9{HA9En+7fQD?H#rtP%shqOi{BM1hv$>V$7x=j(1vYXP|E{xnbj zH9gV2(-XE5Uq)>5a~B#D6;fX(@_^3I+I21fRN|pA;Gtq0kG+*sgq{O5QNqN zqmJ56I755DfO}`v%wC7fzflN5G%@jJ>Pdo^c5DdBWtw-6)N0?@J{9}RzWHR8yW~1! z0kL%MxS56RrclU`_s%PKJD#O<84L0U_hYw$$AmSYOSFh&N!V!x!aL5p>~AgHd|Ehq zZRv2iE+OPHQWzC$<@7PI*U z=eQ3`1`x229wT9(TYhC2KSg*9OgOv~2W%w%^IKSsNNBJ*`E&;6;S1S;{Q_Zf)JE#Wkzm|;1Q*d*pk=+{-}`d6Xy~w88+7TW)r7=c!$!?kD$}2TWA;;`t@n zy6XdPESOUggC{O+)@7(aJdNfhswoaCc>P|Px;)MTZHo`Mjy!XG%l7oKBK3vz0lD<4 zlpk+k=6(?{(e#Cc$0~ez2T;cG-C`SuQ89tyDNy%MooU$Vkg|`|;|%z7?I0#i2K(eP z`yVtD(U>9WhPq-8Hrm^binJDp15Gjr{Eigf6f{V~*`222`IA5*%*!_hr<|7uxeuiy z&%%cmM%Fk?8=U-p_~v_4>t&8V{u5X~E~pxwn@gFzYvK%z=dnKabR@Ps_qc=)g(Ji$ zuky?T>lS&xUUAhbu=^e4a!?SkYl1P#@D@(Uei$|Kb&2>KxaXbvJ0oE0;&eJ$V?5N% zyn9A$-;TPS#*4O6FWc$d_!_hOQy;JT( z?AOPEGb+}M!N6h-my)=-Ys!i`H-O~|Nw+S8?t^jd8FcX)PS@z4HX5e0f$$WJ0M>B9 zD`WNU(nr?f{jg$IY!>>Q$Zk10VK<^<)JbGt5#!eiNaU98_h$4wV&Mj@YM{05=F zspdV-*GTq>W70R&M^$0W+6(b%-m(`RB#57a4k!j>n!v)SbiJUV@74Kxy^cZzGQEo!z@5alLb43$| z2xvEdWiunYP5A=tmBiE@2o*2!OL3@2+&ncKXt1|jz0$)UYt2d;;ah|Yw<<`0Nt0xzXid=7u z+O7O8iKG~PKCXCiJ+Y_IM@-TI2PCc%y|RGDi5!231cnax@(BnC5IiePCZermBVa?S zEWY#e?!CG9CyJE${@?4oG7IpD1hm7S+Wg;QdjHNq;l9+B6~6}li%MR-S>v`)X@jU6 zES~#=MFstHfvL+j7paSB%Rq-HiPgaVNL7 literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopilot/images/wg03.png b/windows/deployment/windows-autopilot/images/wg03.png new file mode 100644 index 0000000000000000000000000000000000000000..f312437f55f7b4b49ede100cd069623b8585c816 GIT binary patch literal 89020 zcmeFZXH=8zwl$nUXcC%$L=Y*`6eWZbrGs?of}+v_C_RAEdsBMnL3-~hO?n3@qI8H5 zKzc8s_maHf+0WkR?DL*|zVn^&zCXS(z8`@R#<+8>`@XKMHRoJ&5u&NCNO6tv8UO&G zP*#$A3IGs&1^@^=NeS?O@o}^IivI<4c&hjqP||;E4gUsYE~6#`0F+0OUl!Z zy>tKoZjN5PfRLe|7ytm5rz|I<<7&8hNscPfeK|wka!__`du+>ewDqugsC;sW_;VHd z6AyES1!l|Ek^j^42U;SicVNGG(7RV6(%qIzpxgYxq_5ampMwGjLOFah-^bq}<6r}F zC_N(LVB?_UsVeqvImb>7`1Bn&XRNqISr;E0Y@9`in3bHil(_Y|4Xk)ipC<_poR`GM zJ4ii!vl8Dx^@jtGOW)5R-TwUFb?-(oydF}O@6I0Z78tg?+hg&{;|Vo^Wn6BW4@luI z!uaY}hgG0Wn_qiMYUe`}8W%aC-n(Hw%jVw8E8bfxg_b6oxXl6Vec@2_`wZM^MnMw9 zg7C|;;E-U7;9Yiq_#+awF0EGnIDj$Aj5q-H)Ee>;%$S+51+w_e&4%s;rB)jZg96kZ z^9!>FUaK-j&|0mzyNSaLerO;Ar^np{Z#liQa-k7qpbnwHfG2zJ!G9H16`4}Er;g~v zfHX~cP2#TESedtJg{xK^yR>Piy|Nz?Vl^IeDykG5%FBM>P8*Vic3)wPy?_CxlE+k- z+TSV~3$-OwrRgytisujL%7HLLxk2J>J~pnJ3}Y_8##?ZTE~R4Q7XlW(hV`_W#p&-6 zg0%J%&dRi4IN9nGZ!5ur{{ED?!Z_`Qu*5oFB^wKKwAu6WBK2Z5<^afYYCe9K81-mU zbP(EN4#7ld+J0qKy z20JVfPL8jy*B@NbaIEA^|p_v>(Upo`h_S#J3SFhe!TW{ z&E9VpiiXr|o=~^n9@|YT89vw#42HFKGtIpCBemB9U1@6-WYwUtX*+5gk%9(tJBGm! zzJcrtOr;OU-H{eg3+$jSft7p#`<{8@k?O@;RTkPC^zx!l>ZKF%GRSz=g;i7PDTtA# z3Varai)36NLLq@C|M6OvQJ!F(|h!+G{8VUT=i8L0SRO=Mu(ED*&Djz0c9l<)OlABvtuj%7ujq zGaz8Yw^G)x`tedwXmsm->_Lpub@yq$B1Y^tm9DMAA^d44*YfORU(4y1K#vaC?tOs zB+8h=8Kth+grP2$>;!k2qE%@0h8Y@u0U6r7&M4^(RvGb0Y%M$GZdMd{1@TVa%E7E7 zf{!^HIC^^VDZ7vW?bxy7koaUXOzN>xjt~NdPO_s?1(zfzMnoU7#GEwXM!LX7ixdEgmN^~%0!p2L9 zVdPwFkRAr;^bID~-X97Tg|S_$vS3Qp$z))s#3&!X64js35tDI(ON^Y2J7}MtUwFGJy z@aqS^Kr4izmH)ODgIfG5YS@rK7})jwqh#)#`9Z@pipfJZu+EpZIwCp~x~hnqPO8v| zj+((Yj%=f58?u36*B#}-(lFNSHk1?Yzg%VmtAW2k1qKsjwdCts9vR&Z039JaqpHEN zPuY0B)tG)+9IZ}ADk=$HJ)5^ifAcr@#@W2^i>58yU(12U$hs--t3*lhn0s3+h3hpK z`MFJ>KTmhS{1o(d`RlOfuw1UbG*5Hds#`I19FkA>)qmSbFHZ0K9WX!$woabiC-ziF zEVkuXAUT|DTIre2ZX57xykY4Ty2+y~my*nP??~9K@wMjAWanYhWElh%Edqd3t0p*8 zhKAJ_nhvV8Blxcq=7rgwDX0?5TkHSGp{O;Hoyj3L(=XemDRZ2tx3E$XySWa@$FL_G z-a}Eo?)%*xW&87!mWEZEl7*^qt3GgtQN!}9s9UAo<_NMwZ%PxfFF&R$R#ReTvhNIRR%GbKf2Hej zu+6;380k?b+%dKu7qk(P0KVtmP+O1lAhr~)*JnwYFeFgxbZwBNP*;$Ut?{C_tY<`s zBNm8|@`GEC&55gw;Tu@p^3op*oB^TJd?n3{mNq0UkiycA4=yPBKq-!$0k_F#d#NSJH3VZK6@vlHDFxR%=jNWhh7s zGIs`1vljw@U8~3p>3aWh0cv5>q5+EMo5UM!&ZJ-~IxAR8qTom-SFBk|7G^jvJwiSL zsVZQh&BRsZ=-#GeWuxy-t1xwFS)$(giYWF;Ltkbw(5u@oQsxa^YYz%uCmkpD5z3yk z_<@ky%(qG4SqkEM3XEFKLc7f1*=Duwqzz%?Ya4KKD2l8V@yGjdqWNbeNY)mZ32oX5 zoc?}!QCf&=-h{$a^P85UH&dd)$m;~*L)Pij4v0OIYOow8JBcEP)8yd`s%lw;W{zgq zct>gyv2cvgBp8{%cW86}|73g?cCQ+w8`m=_79T3uWYf;%`*Xsp1ZhfjCY9Fj-%;Z> zrH#!}d+ZBy?;G);R5k4V=vQbURAF2x_g_8C2o<|;g$rC2nQK1Yib*-`P43!jo5uo`%B1`XrEcy6em}zSdtDV~ z1`q!j>_qT2=VzmoZ~Zzs>!lRXK>^3hKhWa6lzaR|{2arp;W6@8>NIefaynZpXes;d zL$e&pTe8!`DqhGM1p+5e(VBG~jE_i~ZSoLj@^YCASU>`G0~qb|MpF>+G01nOAfgFG zqrS>#3#R24CIHbx)k%VbvP{%Fh3p zLiLXb8aj)B-P?_MvM!DuRm5msS-JOGjWA@cf+3}WA?aY4Xj8B0h^xaV?E;Z+;@b9F zBSg1Q;*kWzg_9lBHYuy94!Lr2Ic_eyr~AHMWc&f_a0|`JG|{O}dX?8H`Z0h~rI-uK ztf$9Pe~)UAdCIUDc=VH+#+c4dm8nSUSgQK(7v*jF;DcFqe^yE1a32OpbB}hnIqHY4 zM%tE+0zBRX2lIzM%#T17p0nuDFbNf6)YG=!p{8+HkNAlP!90UB*LM~y1!_wdaa6i_ z+8$5qZMRfpcgtBsUW;zOcE4XtL*fus(J#7jRi1XfkwfbiV=pRdPq|2mtEi+{uFsmb zuLKP)&Kdiv&C&!v9$C>msJjLMYxzH6X}E_DsTwbQTXZl-ayz1zB#m$PX_zy^6q8%Y zWstvq zq}6T^L;z9!Www&i$3ZMSTUA|ZVnWd8Okkinh4X?qjk4i6fk_3%7C94>Ub$9iZKWv& zOIcfeUHNt`&pESpz7J%w%6XslRluoynx*t)j}nEoK2ls*Z9&-Hl2lYU8_fX-FstW@ zEsJ8@5~XWJe1eP3*l@uLfu&Vm^t7}V)wHYr>)7q~!V1bHJj_o)x>%n_9^|Si8fXVh zgp8{ya_2;-K&uEl>Fv0vWueBvA;wv>p@P+m1*?T3OU6<^71_ZenocetL})}l z=Dionek=<>tX(yJY9<&WL*ZJC`J9+2U6Cfu;8^=7*wcD*_E0m0mKsNvxMi0){q@~? z1aE=<73wY)-zetA?LG`LP}idC6c-1MH@IxOt)#gO$unRkYqr1k@HJfQ^+g^dn~#x#yKvJ?myzT=Ogj}w>A5mK85$kq5Pf_%|BJ=evD|?ZX7k7{>Fs=B zmB}C$(&#U-XgTiYEnHi&fq=y^88Ot zSbQaocfhmfrv|R;uN=ng@_V;&MWR#!SXa4nMSViv$>W${;!Lheg9qcY6&)nX{DF*D zwb@l}$t?#%8=P;_Xplk7Vzz#>9`ji#uCmDiLQ}TuU(Igek|h{0!Jnf4HSiyhKrL4B zog+n~*H6Dyex=VtPJi5ICT8!dyg>lzE~0!&)#sf*b!$G)%+Wxom~-k}y`AW>81O*# zi_2{Y!ITm|pzO}|QMjM)7k&s!z(lWqUvER3nS*xa7Rh$z_%f*Up}{N7&CgS#jI|SU zI=R0_IyB44ka0=;55eC=XL?&zUIbGHR5BXm{%GI}(X4TDKC z$V9ag1KG)PP-i}E{*5L`Fl6KvDT1{?R7pbUJjvN1IAP*kX6n^&)3%U4YbCApK!^K^ zAKPFAh!7ygZj7WQ?Yw6s|Hm^IlPDpV1>`e&(}r;YXm zcHjXn78|dPwOA4v`y#&JqKj?c`0Hyfd5}ew=DuEJp8B?n-00-n{(#hs6w&KnQz_Je&XkJOg4dumf@$07u0$~C_qAySfo%{+kczTn2_**IE9{T9l z^D+LX&_K9wALw{*kQ_`Mlw-SJCb^rP$gKu8dAia0vBR`rRLMxoE}&CHuFYPbejQZX zAL`cRK46cT&Abx;0NgpM^ zD>XqTP(rl7dt{;f(zhb(`y7OR|5;c=zq3@(MsJ<8(?&0ovtqCH;yK^DJrCXVeG*;` zpZ%ZO-d=wZkN}p8*}Da)@0Rhn7|#K{DHdaIM@dbz1U(U?BFkVwVa$n|;6SJ_d!h80 z+tJ`xbq0ero14KCD<$Lnuh^Xf4iRD?V&Q95iE6z`mYTH66@7!wYflHdvb(zS9vY+S z3p)!+olUIP?AO#FPGbdiqV(4EO7}4EfNJ6cHWE?dcr5@_dvcLLZRrS9Ct zUZbw$JP4tF5fEQ+dGs^RNNn?6Xg1IC+eu_in&;k+f(-97k(Ja1DUyW@g1SnaN8#Y5 z4C;0U1?p0ErIps=fUa%UEv^hgmVYO(DjRX0$v7eS;XAi-*_)k1L&v>Et!qj22Xko= ziI(BrLa{%U6gOp`FTrkuAsa@S~+w0l0`TX&3>q?^I4DpN+@O9D!>+1|X#3hGP^D+Kom&ZwnWU z%I-;4>K-=MvnF*`$g(stIQn|SMj6b(RNq&RD}Sb7To;y!u}IsZArgaT7osj%VqQ7E zq$PVPYGX~&*3Tn^`P^eT>i;0b@3m~rOFYW{$#dU@rjogML?RopB2O1z{2Ryg2F_o^T^5FRt|-PO$*T_qXEBaoC^QGnIRbW8lAJPWO#skE6|9 z(Bc)2p2f>+cpU9@eq`Xe+v!cgp+N&4v|yn}Nyd4aaQY_a3-^hK+H{qb4jw2kk0>z& zM)8Kf2mWL?ph2ZU_;2b@xW8SiBCqOO)$T=Hsc_|NIfaBK!zQM_#D-Q)M^*W5bbQRY zQ0LEteE#PL%=hXCg&z|r4a+~&e#~;SzilxTwcHzABHj2mS=lttlK2U0Im5q{agD!yIi8@exIxZdm6JStR-QK5jFqIE57w=Y}# zXro)iNy7slt@o^g7W?BX%(z*nb`|m55la&thjV>1&~WB+?YQQ7`oX$!LdBH$MSQ8} zT2>Iti2&|Fs0qWqAC>29-GJAYWkH(r=u7jaSt96;hTlmTzr8$;YQ9?dWM`*bE-qP- zRBh*FHc#N8M$+6Vck#6MBTdx@;IU;@X>f+#z1XWV)?K0YAIexPqi&|2L_H5 zcMeS~v`19!p;S$+fVYp<;ZYf(2ib`QNdG2j1`dn`sg}<7d^5U+lzXBuVs5vYZRx#L zv}Lt}0*X@Mu}!<`XMg0qPTOv?Y8eT31%=#EQZAh_TbL9&j0?6l95o_CtCh2bTV+&O z?;Om}PntEn?d}Jhw?`q<>v6@x_F5!|!H}CVukIvj8Z>lXAfU+|xhhiXBx-UI^|%~s zND+f1hubO;5hVG?MJlK|qXsiF}B&knAyY9&h24P1)@_B=yHlUc&A zcCL#PF$f#X1{;amzyM{Y)Y1(4p^PRj9je#gzP|r1NiZpm7|z$QDtwzr;8x*kc8JP> z$)nI}wN~l!(rRG{z%nwN|EWc6t^s>N2YU|U4r9)c3uEB^2Y~#b^K%H48-8MHFYV^T{76??1W*$+V@FEkkB&)6#bGQKv!nm=L$ipg=Rt4q^(c2JM0d z*8z^JaD8=i(fvOGt&uX)=kr# zn27P>u`fP@hka&qR_x`VQS4$*5Q!VNL@ay_GhEPOZTAc1ORklJ2Ig2yg1~r`t``7| zUhXEn^MOlwg7e*z`vTYC*)T@00^>(Uq?#b4`4WegYN8G!Sw5GBe-1a9Q}Ufy2N0iC zy>FaQRE{rj9S#Fca)}DVv^EKbLfBe>XeKe>Y1}zZFZrS8`UVfQ1>45+(dT5|Lvnx6 zrvMSIuW`{g;Ds5$aWj|yc{0DQf?gl80NtjYc)6Qgmg>ez{-Vpe-s`$S2K`67c~B|O z5$-K1944doAX%#ET+ryOm!ajtKFy!5vt(&G#jf8)`eFqkj;+nb86@J_bgu(73;nFD zKR4(=Bbt(hiJHda&6}klpOYXxX!QVp!{---Kh6t*|D>054#1O(`bL8sVNETB1~i14 z;9v{>stow`J4oWL!}d7#wrmDRnT{-plw1T0g$jvQq5LEQ!;|I#2dO%x#PSD6S|k!* z8~bb<(R0_*;?GM!U+I5B-Deo{9RpDwE#M@IfeeE6&Ml zm+?z_gAg$!2MFo9vz}daJ&o~zK$e>=dpGmX1)I(o%MDoYF$Xx1^K|f7F$u0G8Zw61 zWvQIM%7yE(40j%2DgUAI-zRr6c}!0nWa|nC~|~m96&w#}<;% zm*J~f{f_i0H|ze-SlVbk-TqY{A}$}|!z&86|A1HOGDFvUPdCt@AHLg3!qR-y554HH z-a4D+l{&FLm%3zn=)HW1e>ogW3Dt%mr|kw z+)rvT)syPtyB!1GM-{Rjci+>fCS*0;wQW8%i(M3Bg}M)gU6>Z$_CK+k-`fPHQ_s_W zGw+I3gsPm`;V>#XA?I0Pj3-bh7RgzcD5L2`wX zoaSCJ;JAm!@%HR;lyB;KhRh{iDxE3c>zy$;U7LAv8lsEuXJcmfjoeosurzLyc%MeL zoM)$`AJj)RF7!iFPXePPPpe#}c6OnXl~YE9#>Y$fLbp6N%ehnSzu_eynB3+&=h+yU zQ8x?d?6k-Bn`OB@MvCDQ3Egk26nM3h zG81$UryNHdt_q~Ywi~|9vRt>4?lFzm_I$9Xw|#uSv!HbK-x6sMWl*EVRb0I@eFwlS za9{s0F7my0sf%`=)5PpCCHlBZDh{PGjr&RoXyVUkor2N)NSSad)T;CQe^@I#FvLtr zX4~8TIob<*->Qn0W4X{VhK%(#CYmfCR2cqCzr_ULUGfbu0BI$5)IWDvC6Y{LJi1CF zTu&)zaUD^n##)?%et4!&1PbN#g0;Z14KSErZMyyCyrum|0AC6O z6|{>jZFw(R;JKWI!&XV*GDa#=0*uVQvwT*UevYGw-eU1TUBLek*`<1(zPlWc+c}HR za9t|v8E2%DxQN&Ap6k&yz$I;8exSOHs3^fzGt3;VUuL-VkVxSSq>i%`4cvReN-r19 zn``@w2zNp6r%v7qqVuygx8LKmTG&b&_kIdT(K{1NQ8t^O!X<;WF=X9*Z?>nK^t-JM zE7mhqCptFdiN_XC7NS^k`(hm;mV#I}z~z z-Y>!KL(!o~da^UiHfI{Zn2m2cRj{V}@-SvT#5*JgiDMCB?-z!3lt)B0em+0 zJQ|CT4`5@iI*ha$GGojUUEm_N5v7F?q4SO%5rn`{Sgw;FJQ_5~CO{G|RP2HpHa2~v zSs$QgU!4T51diTQSEga2UXTYNcjA($@t6Q_`d~S?VGNIX)n4{`5YXhvEv+X()@H^v zTZxI~g4kRijK4sct)`_tY}ev0aAtrx0AtXD{bhY$Oz`fU6h;W+5MvBNPV8xb+W9x0 zR=%bJLMBqpaJFLdN;d7sy|;9REBhZ;nLMqUf`KbOf_NFhYlX!wI$_m4A0pIg zPPL8uI=o!ZCYjs$t(D8N+oB^U+!d=V8uZZ+%0IRcw5dogLZok1sP@wi;tp3D8K!lt z2LJ!yHrV?pGJHMppkpQDH*Q8@N$}E0Ds5vAntq*s_>!^PBAD|7!abs6X{p!+$KXz+ z(0I8&^I|}%t$|QoTC(v3l#2^Oq@Qo$v(I#zulUlKuJ?Qb9-7=Z*^{N3xlDpKolIz8 z_Y-~}jU5}}x*4WVHfJtY`;LG6oL2d`_qsj2v@@UCDK+vwXZgK*O2RVHU+P!ecNTxox`MG%Ii?B?rCSe~#hWuA~oac#Q2pZLAj7Nv(v z9!@S`nsmJYUY*Yhyg^J`U1X_pL|yEBvjQ(OG8kTAbVJvmW3~QZlsD_vjW5397ZN#IDbrx@!{DD?I;#`OH8F6D{N}VDHM(7gY?g z&QU3_Z8X#zQd09=*=SRE4;hXmmCJ{J-JXgO!E1+!>ckU>w}D#x!FbZ=+n7J$brLPL z@A9v;&d>R5Ld6t>NUQpkK0sDdW#o0Jf*kCABE{F|Yw{9|D$J-NEq0Sf(JuK<8hw%1 z#j?@4w%VQDtBenVBd_Z|zuwSf_~$(YEMzm4GUy0BrNzfyM#C0Zd50jTC}PvY<#j*0 zNH{;v5B?(6m=0_*Vad%}TI9?kxj1ma?D(46*ElyD-lVgc&gVO&{*1xNk=wVJoPY0= zCFy@6vyz(ye0k=s71i~W#L4Q9UU0Xd>Z`{l{6Y;|)+omc;Uz=*d46aqRfLC+$W7GJmKW`i;*m?#Oq;qSo_Gj@%->&=%>R>)!t@Jsrco3d_kk_ z61O32^BufLmda;4wl7^CrJ%J~ZX|M?D8g=d4Rt}q@RghluppR?^G4%G^Ex4 zBBEvYAr?D>JD1fAFa~}&sTD8=J6UadYHDsS*C5t}q{W_q{i~FnqCb{w3$6OvjzF5I z?ZVN@!`Zx<)GP^sv}H-j{POf3Et#hxO}wQZndIic)QNj%d4q?V zJ2H_B)~sMLOJNQZ+YmHLsEvm9H)XC#sc%AaU{YIRhu-(R$7Loabiy5w@aj8G?#7UX zK_^^5iSJ`ieMa?GGplcO&o7(If{jzx>+hPN4yn45F5#a*W-#t z$lD=7CFd-TM0E2D!}bJlZQA@o6KD!GQviPo3ce7!%2Av%snt86BDii59tRXWxn_dz z#ibcSx*i>D)#DysxJVm%Uj{(*q(CCCxmhs@k{7fbfA9ol@&ohBBk{*c>SKoQZ@lU4 zctBm++vgEb1e<_|)@G-R47WXhh~W-!&8y2T@0KZe&Gm6UX)Yt_54|`0HKcaB^dvnt zo2fE2vFpkGrGVUIdt0 z_e!jxj~1wE=K`5tq{eATp5kG`qm@(#!-H%F1AH3x2IgLBv!;6;M8(bxEydkAA=M(G zd!BPygV_A_-MR1tl>Hp9kgPqfsOsbbW736SN+&GXb{_;+l*jLdvOcPO0R=+c8B5n| z?iagM*fuG|T~q`JDS)63QA_jXt1O`K)d~-E9QvG~Uhd>4T9`O^QT$II*9%22lW4O| zpe7Y5j3G(s5V8qZ7-=i~iwmV;yyus!8~V<@AZbEql_8y!rPja6iE9P0ppg$UM)Cj9 zKNqv5p?powS=BeaLT`qDFH2yr{?}3`BUoMC2?N1PpP%Xe4D9uzc!+-*pOBuO&9}iV zW!m-&f221*eYRSY7m7MCW-TNpGlC%iVAJltGW)FP+{pC*BWsun`j9#4QOZ#EkdZD; z9eX<6yN&wV$IUvh4_ZvSB-6+f-g69?Ae+Ja_|vd*!cDpISv-;E|cE?q8qi|uNc zDqMV)RaP1g7jTm=(=1MB2Abw(F4u$XPCG6q51|WR&rL>RDIDx;lG5PtvQremz{Yp# z^63a?igEQ%ObyfT-LJJ)?v zg_9M@Qx0PfQh#;i3ma=e>E_Eeip)QKK(`wiQL~xw5sA2kB%QQLtKE8eIASXeu1(5r;=SED*&@T)l!M8*#ev75qKM)D8P>7yL|>Txpv9nL#)%Q*dRZQ&Y$;>u-9 z5-s)5Q7V~gSAy7)h_RWYG9Rl&YagtXVgcAeLs}u*GAVYSjmbpp;c%>x*c->fw$2G6 zQrm(obZk}&?pcOO@kJ-Qd(%=$=|wxQWOE5^blh~qUaCt;>W&Am#yKXQ+oTZ_v7D!@{9c89pK+U`&^V81*gioeU{7+4F2-68vJ_KKv8le|^Sv9m z?J(QA9gNSJxzR+rRLIY+c7xTyEo1WyTfrcL4uIb1&_jWDm9R>WugKdI75uHjN|!ua zeiczp?E`$G3*RgTw%@NQp;tFsyR%@XD2as8t$oEXgtS-?X2O!(6c|V@{L0h5U$vFU zk}yAEfw7u=(nK6~Mb90djd{*}gm#L?wOUMMKN1@KR_SrPg-pp=s3;yxcke)V{VngN zpZ1!k!H}oFWAovd=o$LJB#;udx#%H z9ulhW-e=lBEj3uMIe43hTUwSgN0XdS>?sqN(Y5F>`&MpVyAmYx{xH4FR7l%d0^b?k zzw{}G+2+5O6i5yDL0{CDL}TFRS~Q8Ug54$@0$59Zl-Jb(+K8G|vS9y3d*}@9CzGu9 z15qH82B3)leGlc&YkKo4i2q4@C<6F@?n03!+(S2l$K&&CN*+JU(ghf&0>E?{w|LS6 zDhsH(zN~;ce)vvJ*10{nQiI2BI=6j(6_iO(WRZK_)n``Ic*?^=%-w2;l~m`_=ry|N zH1gaGn}MiH@0n{-rTU&|%tfk8PowZu%y^%h)#zkcw&m@JdCTcnJ(jo2*m%Jb9Iv?{ z?m>djYy$2?``8oPX4JGbf}7d5>)#DpD$Q`ZTrfOpJN8^8pWNe&9$L<5+WMtygu(r= zdpIqmc&%2-oJFjX37tI89KXUoW$T`>+y{d1D+boqrJATVS*7Z(l@tSQTkJsFQ zWEGa&zVw5VkZ6|5n~shTFo*TuFkhqiR(@ikCgFw&Hx`P5oCnT~9&O62lw&#gldE|s zBdT^(STJ?;8`apY4YnXwl7$n(k{0Zlx#WHlKB-<8^TAPepRQzV8$E7Xj8(xO<*zE| zJ~Rrh;wN%Hv`G|*2dG%MzqC_b4pMOn7zz%8kSsfru3$jM2VwxRF%No_$19R8B$Q9i z;T6-)h}7kXYSCp1YrV~N-&i}JGJ<6q8$vo$rHyMmIg7-(>5LtVxvmU$i)X5h>(Qht@t?CZ zxqr>hoXlwizop~v<(OT0EEv!RDH7h>9s0M~qd}Ck5OMfWyt@^3T#}1+5(N!3RBh0C zJk1xVdF=E5N`CO!Xx5&>wObW(-~R9G2{l_{$brk2Q+yJBPAMaP7vh%i$Iz-BhDtzO zRjch}V!dV8xEJ5s^eerLf(HVU7k3fghSPn;cOOaxU2b_aGeSS`C4qsMH=-2R6?TK) z|B%ZXY)TVfdf?)<1jWun(~n072E>4MPD_p&(j`XtHU}OUROv|pPp`BCyfleLJ#)D% zHK!oC<+DNbP<&39rFkwLI_)qMz<|YaW243yWRt(*wwqVGMoO`98o2RQ6dt-(#&B#otte!hGek(Zv`lq9vY?cEwY*hGUvXSrcX6$SJ3y3kmc|S4G-{#biqd0(shLG&7c1knY=&uVrBh7&mTGUhm4T9WMg8Z3> z71j#r=?mP3iIPb*P`BhqE587H1)>D2i$PNDI@Rr@%nw@a? z5uB?P@qT_)@n}UTaXn(;X+qIsNYzd0hCGT@(F22OM||cyU?b&&)P1D$FW_d)S&U5F zwhmX99+a5qW)R{L%904lgnV2kG&*PbL+JQ&?$UL|@ar3tmpj3H(a+V4+|wW^_T(yW zHZGL}adWe>h(owpsiZFAqh^ltdP*=@!1|s3)n>q+?m#1!#puj0!)uIN$^$1$g>M5N z|Gxa-gR^GArmWzXEWvG${^FppUAi7WX?DybdKrCJp`Ydm{u?DO;%bK}(6 zFZi5cwdo4gz^nLBETTDUpED?;~` z!Q8OWeHMzeu&;P_US8$|4CK8bYw?PScmn14Fa`Kn&~mK85w+UI^Z2v5K)ui~C{VB2 zG3m9Ex7C>mBqtcz%QNh5o2y1|b8hwdKk4sJ40!S^Tc#kOgG9<=jF0Jll^5OY+{zDC z4{uYRJ{F4>7j;g?q|#Ic#86N2TM!P9rQW0~qo)}BrDmN!cA3##k258ace1fkC~qjr zrZu&XJ-(#mh>A=z6El~?AUHbU;0fOYVRK?48+k%Ur;+3}Cmi?JEgV`#i#a7(Yt#1A zY6m2B(W`~hf;F$h^XMF5=Dt1n3gs5b;Kn5r~8o5K@)XM$nxDz-NcL9E!} zpGrngNz>DP!<%Pd*O8GH8tgng$X7k9r0wD&FXpl*>|!*V@sQO05=qs9w;&7;ZCEvE zXh@U7^OvCRCAdXh{HN{Zj@fL17Q?6{4@Rk`j&Y3_N4PiJJ2mRKV+XsFn$r4x36|3e z=&{f0K^VTX!|dXXox%Q0!}V-3v42!deS0}0v7NutIG5w%y{@8n5mvbMAYmJwH6t70 zlCm*F2n~^Q!Pzm`a0znGn6z?*Pnh-mWXTX=(CGcporMdp z(`D=x5i*;3Q$|kMNj&!cJ=}O}$ztHm)=#LL$gOgT#ut@zOi#YPW|TF(d(-PDb-D1w z0@bFL1L=f7x^F5z-{BKtGF|~2vv&)DuHoo{@!!?~S#OfXD^rW|=a!|cCi8*YqjPVg zJW|;gCs`hZ$13V}Q?J8i>A(b@fpH5S1lBte;k^*|X0VYp$+ z`n}-~M;!E-)|r#ND|OFv)uHm;(xYr8nURTn548A65w-7&uAEwH!{a(xT=%a*0C$)j z@t!%gPdq00IoWuikU_cYukt&emi_y+FXjv z8+5@YP-z(r+U2fpB@{n01!$3NeQeNxh@dWQ!vysp-dO|)R~9+R_{%V4PJTHzGLX0N zZ_5|(#gidM9)at^s*`4bu?# zIXLpZ4)(uYu%qRTv)crL(6}hapInqO3I$;68~zVn2)=>%c}iO_b4R)c_j4*g4*g!0 z7i=NjziK04*j+KwP!mYET`dQ~oj@Qt@v7*4*b6&nL3fjNGvTk^8*DeK+s6~0eHSUL zi;-iF4=@+UTkx=D^;qidHpA^({>^*w=eJ!~AKGCzU2qp9xb>vZlrq?}X{P3l70Htc zCdrCUJnb0`d+?;;d%8-^Sn4Kxs-$$~nDqwc<7BCL*+^v5drsQ)hMe0Jn2bk5hE$FR z9ydmQ*fD;sa_D9cZ>AyuhkkBC*Cog*rf4hde#J7Bytz720xpc9vZk;D_V71s-W}B! zbsy_im`N6>U*oWsSWXmP&X4#dcKqAnZ|dc-k?V6ef?=!Ke9Igud2ycgt}s>p_T5*kbCepF5zp! zz#-a^yp51-V}_k?WYW1IG4-9ks|P>7%gG4@8x9iD1RdE-_@{Xgj|{ zt)2UraF6E=Nj`4bAT!=7^ zajPEBORCpsqoLwEgDH|bb+{R*=V~dYFRSYiH@{-%u@SVjPtH1gncut8?AVD{KhY|- zZgLI;{+B+@tN8_&U5d8niyyIXeshvsd(hE3m^i0Ub7^$hwk^E4{rv08JQ3#3q5Vk; zY$=xW-0g*cvEofeLAr`#XA_5GOqgq*zfbv_k!XrQ1uE-RYSd{pdF`oPP`ZamjuDmR z&CZ@PqgoowQyZQizb$*cn(`Bi4L+7FLwSmS#KuJ;r9j3qcsQpab$QU_ah&cl?RNSA zf=74+!8`AFcDcm4i9ZLKQ&B~2!G5)$os`budq1qL$sArMJ7~g#m^r~8e{(oWHvQc@ z=)=4$*1RB=-*Pd$!gO}+%IBE*3Ge*nvkD%|uYOeWtW4vW zuwtw>*qSBk*X}>d8XvhQ2c3X8NLXrouuPa4P*S?Brb5fCV1(AqOQ&D5_{zD1&t@Bf zRH;YHQMfdQ-+#zPv|Re9q@SHdd0sR_DP#n1d#=t=dCp@cS`NzKG^UJxkI$dF9}EsYZ%1pQ^mGw+l6gb zdPDPicqG5g80+qIn} zXhNG$Ol}6LM$G)mq~zjjlAD>fNBVf(7dyp0mikhkcBMaZ0*T#UUs*#t1gDU z);8V+ou5w@nKq1mA3v0dzE#g~!>*f@D(`0ek zMUxQl!R!y$p&}=DYR7}yTq;LAjBV@|N>fHN4s8FJg zx?J~jM;F9ExUZHyIjc{0%21eZ{l2;=V*mqT?`&9b%#WOaYJ)F+{F}MIqJz1FR8x|< z9+~)0`sr-a?+lOe3qs;tH)?fApR0yv2SNgdoKe!ock}Brzc2k#HVdA6VpTJxWuXv) zw|y|6VI~ZsN%yGRLHu-_%!EKLPylAqx$>sG-jH?3W5H^m$@kxn1193gX*{Z)*n|%~ z8wuylzBwU|!aQ5Z?w`kZoLph8;O1aRlDOzUJ|KEH}=w748Qy*ocr<@4pT_mQx26T%i zrE*0jdhCf8MsUzK>S{? zV2KZkljTHX8`m2^)pz>%`z4j6BPPx03V90RUWYH)wd{0pHyv$J+0I$BZdp!B9O(!9 zWev6FM^4@4tKPz^kepEs^Fwz7Jq&Q>SiJX3BXP#vcW4Y2&c+>Ryv*`jg}e9pEe651 z6y_7hZOjekR5HTTskjb=pbzxBTO^-(n4_u2jS;uVlCZlG9h?d698I^L+x%GS5jA=g zk5`ELIrv=|9gIq844D~(D{G>h(rs-P*zmX#Z)F$pI!e&Id;n=7oHu&BbeF)Jp6i%@fQjeKypkOG89mpknTO6lox83P@0+K;9|3vhh14 z@U^Yo)+*bdQ_y+A8H?zd-Dp}}WHXCSeksE;JszCY6|8!vDBQ6_^7XUZ3vIqyiGm>n zcf^`3Vz1>CQ&ii=|I0~%$=Q^M&wu+z5Ho)pV@PAr(pkqwDLttF67v2&b9Gf9!kjMo z=+_&lb=$`d>8}*cT{_j4T#5D4k_imk!DCB^$eyk`Pd8kf>r_WhY~XD`R} zu%qO*C*?*>`}nRUznp6AHWrFoR?BeP9GE#9JE9EY`lIEYnTze-{&w^6e##{yX^KX* z21?cgh_CN2C_D`6J%Rz7-j;k5fUA~c$ZN&Ebo*cn#K?vMBdOW(~ z<-O3j{z52XZ9|xVc{|YC+A=NGbv|T6e5{*|)PUGh8{c*CA?Ly|mIUDqOpDg6;;%f_ zeFs9;;_`hsoT%hKc5nNhglmE5t{T?PHOffAl3>Zay)R#@a}rxF3x|4SubRS(rhXbG zgwm6IqtX!PVJjtk7CtB^k^Vsq_lrcn`(NC>1yq#nxA%{LAcBN+gQOze4bsvUqBKau z&@pr)9ZL5gh#(=|-Q5F2cX#J|kNP~n=Q-zh@_*iS*85*emom)EeP3~3*R}Wl?$0*+ z7m?`oFbjCV`v!>M{HK;a6VYH9!lQ~Bfldte1M30t2MBlxstZ!tV|N`wpnghO_gmQR zU`WZei+Q3o>RgtQTSzw&(c$PL-X~uiN~3`)D8^+3)tWyu$7nKt0c-{t#ie1EGVC4% z48H^6l0YDwTV>;h^8eC@M1zX~UB$_X`5g0&5B=6TB-3d~yg@eGNx;(#tWa2k?dqf~ zCRAJjh>nQXZ%i>*YPqtf<9$%+M$TtY^#n4sJ$A?IZa<$|ZXqw_B=X-mhXRMkbwQE+ zp4ltet{l(}bhO-kN50r&`eZ(U(tT|{z+~pMAyyQS8i6jCu6OG$`)`H;;p$?&!|JS% z(OH20)7#An-mA^nS?k__`hlC{h~%~?Hz!px0?X>{GF)XL>tyXsst}zjjBUlpT~E07 zA6WK;fynk`J(5i)U98i|9iha=)qsACRDuzaG7CiZIkbEJER?cDBO*7|X%o1zJ_7uu z)q(No2YJu`B5K62ReCA)P%QL&pyHFloa9k4_91$EO8YcIXwNEzi)z27zz>tPA0Nft z3|KW0SN?rk6H3Hzi4MX~c_L;(LGPf#y<+L`uY>k+;?W2`7KkR~t#yN|PjuKM(Vn<% zeVePv8Z2!Etkp?CBf(Qj?qW23ORhv=H_?&?s2~0vSk+&}lU28ZNkTvGuVd#nG}+T! z5JDZcvp{)=e+>vj03F{ybGxkUu`iZ>-pVR$ck6@Yw$Web+MZ3})IaTUlE~|}^95K0 zlFDZeDLt-tC|z3v>K2VGFHs4n56ZQznzhxh!<&Q_LN;#;2&a#dW-mHqLK@2qK`B*J>Aoc6F6js4 z+aaV11pWcb;H>bTz$iQ!G={?-;Mr`LUgDw8m<@4l4M|2Mhs-%kG^<90H-gYqO4Rgp zs_aHEzCZhWKHS`Wcv7LD(RxVcuS~~(o;c{yvUa5-Az?|FmPM_NecY5?tNlm~{u zN=)jL^~fHPjfhUy!OLk>oU{W_$w)GYhxv0=0EN9cnwpKWZS5ylZc9(JQFaYfo*9tqeNd12CE64KZiUsXr9 zgxr@!Z@e;xEIEzM#3*gj^i_!O?s1eVvJ5PREeCfnI?p$JB-SZV7^RPEF~pF>oy7as z_h>Vm_1D}+xn;(6zx4b-#blzr=cS>UeH=q}96Z#-leEZ0ka3~f)rO^3c*3X@C#kf2 zi)A5&c|b#&bUH!tM}E!+rjJa@h$mSzHzwYWKr4>uL#j51HIjo$@6&#ENECmMbP<6> z?$gES8JlBa<3;cIR9jNI6CG8l2jEJ4<7uSj(Wgon$kM6)2DKih3NO)t}6_*B^v=90yZgq{O=KReS7= z?Os&EC=QDcyY)S8d_?U>H9f3WR|7Nz!+~iVKP$Phx&J0@$(oGYVAxT1|)<+;Q3? z@hBy=AtQxtqirvTxwIgg11_yPfdD2B#cuIC1x`uMHdJu)hH{IgiZ{?C5%N(rnp*Av zd`zAE|B-t0CgZ|%y;7SA_AkK2af5us~V9EoN&BoCQ&0* zRvdN;&6n84_n}5fdrvwLS`L={DccsxJiSFx68lEBWCK+aqX3`H_lxc=i(X&(P+m{@ zP~IFNm3wS>!FIpg3<-2=0(z|CQxE5k(!;N~5gE{Wk6X@^eGCuuEI{I9gJ`3!>~ht( z*qD76MOi$Bl4yf{?_i~?-k+5GmGoK{gz;p}8Xw60Z|wZK%071TI&(rq@-8W>F_X6g zp#bOC2gU0Qo-?x(VP76Lqvfi=roo*<6H-6P0ppQHcAk2}XfK1cFeF1vn335cUXo{0 zBwQ<0^S8+Nu2mVoldn2W_DA=1KwOJ|yDP+o{1+dWx-OdtN@@Jv#CS)a-jyulX{;IX z;$Ac@P*q79RIM7w)+=q!kkUyzxVVL3qv6W5PI2YqcYrHzz}(h*JduT&@nqD} z?19F%)svx(eZ9GiH|c#CIX}?_{sJgk)v|U(nWJluKI^yAhm+$kZeMWm5g%hr1Kk_{ znTz7@$cpNJAS?c$SSi^@fQ?T$w^y)POHX~ON;6$%O)A8U89Y-y9`_+hq>-Zi;UkN{ zM_JTYNmMV4cjkqfTLz6?&yoK#-(d|=#n;zgIVDUDo2J+T)5E;RSss$Z(HgSLZ;Lwh zW&Xro>5rgw^gRyPMy3_2QTM+QjQY9hA=wPcF(g~J5d$ZXW8@_uiFa?;a|@uR9Hb<9 zF5v*k1U9agY;z^CtsxQp!dBE#Mrj)5r*JyKW2r_e`a>Y`yEx;Go&RLSx!_s{6+*MD zlm$2kDy)eI3ma>bmkyzhkHe0i?5J}@1rBCoR`i-G;b79IeQftp*tbh?tvX^b3t>4M z8DTrfKoCe;ME;+Oe*YV61sz(BQko!5D*uw)JCa$J*~m+v_R_JA7RlOwsC})H@j07k zZ0DYl{hKP}jT^NV9z#46Vcwyv`(TOem$Q;zLUy^C1 zAH4+h)_3(}t4YKRHXNRd-8g8Ng(@hFzU)ODe+E&tw5uvIMMwwaH9QW+Co1ItYdRz5 zef~TA+a<$&B9~hLnW}%*+XV1FP~Ypv5UCTRc<8-@%ZT+Z(K&y~gjU2Q4_D$Hexj#5 zz~!u2QX`{7M$D6e@(w7tCeXhcL=Obh{OYg_MRU!g=PwH~p4UA55`+1REJU^xE=c1; zWf3~GN)+{V?HN~g>79zgWA9#C;$O)#5>f3D zV|OR#T*)5Us>lsb;ulwwZzHxDuYG3J0<`Um+cUpNM}NSF5cj`B`+5Pr$zm?rG=||} z2w^L|v7qp(A;QQt2#8dJ>4L@s^@g3QPrZ=1@L_RPw;$8X;++!3T$##jivh9BndviL zp9!HwsUoyVrT$7{1p8Z3!w`S1j|%{rifd-aZ4N=Pm1l(t2!bL0uzjBFi6>>PV(fw5 z1{hE7{dI1aEOloKC#>lQnfnu-ipc>1l7mzg7AuYV(UYiAW$`c~^BRBELxf?o&Nu4V-~Ainw6v>cEcrkFyDoJ@(fV z6jH2z+Dl+S5ZR2gf*+w>e$AH)MI^Gnb^Hh}sa~70Y8^5+`Y`=~M?Pvi7i%4lL5Ju# z>nB-@|HC2!m2xh8HjcI7MhLr{B)MO#p9@j}4BNWdJ0{9vPD*<<=>(}{(@2>f<_d$K z8C1+uSbp!&ND9*oG13=LhK`z%iT(~3qWoH0Ura8qVlJR-3Me=Nb*DE*FuW*!oiPS0 z?JWN9oGh|Grt9IFzksOViVX|+=VSle4J&&78Efe8*vaA@4|sIy&z*PkhEP+((0}-k zoxa4jd%!|lDnVUt@y=flQUF!sZ!{$P+h7(J&SsP7_OPECm&wWxYh?wGdh;^(JwpjM z;0reV%Pd5Ftj#+Yv69 z3mP4+Ebi9bDk>8hiNFj29&QM9`qkh^cD~L_cho4EcBSHE&I|{(hkB%j@9@oEK6a4c zDSohl!_M)jRGKZl$|3l?5#fPU2#*%%$MNJqrqZm|4u**)O7U~06hlFQQtVtAd2W*);V_804BOb)9&siiOzP$hl-d$BJcl>sjv6j z)Zgx6tV>(?uk$nEq@^}=@Q^ zTLh!LUj(BXP2yIm2Cf?UuL~M2PLa3_HuwVtmL?JxP z11(>MTEFx33^)wpZ<%?P2FJ|5d!%>oU!ze8j}((Ur!<%6K2=v0hvy%)QyQHDf8D+U z(!_?Yb>4y`hsCa(OSP2Kx*O!BgbB2cT(y+F;NM)?bLKd}s9($jD3!Z4hb%RF&whCZ z0c9W%lt4A0U=v|zkO>S@{=|cD*Er)JX2YDV{4dkyB(eaCqVmhIK?KzIe<8B9I@y0D zWZxId1j71)ZHaRt%Y#4c1~yFezCw``0cQ`gq_RS6K0}bdW&=6{LL|NP1_4sWaPXJ4 zpM>BwehNJt88o9Ja)vQr7v0?DYfL2#<_e?=?t zOT6%sQttG&%Yd>jjKlSHde=!z^_#vjII{f)o$4nkJpD7LXoXE1>KmnM=j9PnwUl}f zILdI#xxecpfGIEo;y|}<@RLPR2wVe4-0#$uBJ83B=Z5x+z&swDULE$=|3-(xkw;_E zAn!fjIo-wRY8S5W?t3b^I{JH5>{0a6lrzpbqrz_ov&NW$>^|9fv2<@a=X@P!v)JGv zD*4!0s77k|1gUCGy+%tD$4fq#$>G8@twhoE^O|OA%GifJ)oMGQ#w?%bHJxbCptPaM zEQ>^%yEM;h#^%JvJ_1nKHO+ttvjFkl&7lB0A|#@@)^7}Xr(_6zPGbLjmOrKgfVm*8xk-1mp%{{<8~2sp}&Wxn|sMh$@2t8Og>zP2PLd49k59KA(=Gs087`9`1oB>_2sKA;Y}wA~WiKNTC@DmYU;7%~ zep;t6-+z(#n@}i(Nv*F68Qy}RfV>C)f+$=?`q%D==%f*`;@&a9Y2aqI?rWHcTQg&4 zB3@MB@ZN0BG~i|A8)aOHR(fcrbUHm1Sg*=XSe0uFQH$?RAQ$_Kaw6s-I`l9 z`pZ3&PLR$?5p6CMnX+ft03=K^pmhLgI&XkRL5;wyrN2Dg zJr$&aClyZ^rMdyggxWPJ)~do)Aa`Ttw`aS+>kJ!_k~D%o{DB#MQGC^xQ^zyLp)iWO z*yQ8$#(G3R(inVVK0JzXkHAEFb+Jb+BApu$=o$JjaWXCh$hR~j%6f>?Tvz4&lT!~N zX8{Y|X_+nsCM;3IhnEsCfL#4ql_)jo;qR!U@P$}b)00T#_bA%CQVdw^J|jK%FZTMR zd$^WL|7L#wwON8W>po@va zj{W_0i{VBLAS3yA1C{nWDEev2oITW!P%=t`pbFDNmx5$!f?zx`0HE;CsA*Mw(>fSO zCjR`AEn+2aa1wLggFONkO=ZFn0~70hj>PdNEMD006WHsWt@?{Wpc2Ga(VMty;*nMD z`h%L&f~2clVr=N|P-ykn z_!iA%@)%;-6qyu>wYC^l5LhmEgBJ0lMwKEr2e8l;4T-nlNz(-7SXrPW4rl6#}Am4 zFG}I3F+F}DXW+E5|9IBBQ#5cBt)q^j9_3kYu@{3P1qCysNPtt&*8xecl${_QZPN~) z-c?HQL2!_?>4Km(7SE%W2nR_jj?zfC-LM{F!O}K6fV>dQX^u1$0x&?B1A!UM4o{{> zFqHZpM|_fkM7Z#8f;c196#p(`Ca2R13DhI1VhIn}|8dqvI>D!7z)VMZZ(v1Th@Fai5U;mda%g|GS3dhTpu5;&01@x;GW zKvDC)jG%6#SJr54DThnMyM;;>zsP>~3KsY()6x+*Lel8FG0D7wio}J-KIv53Ic6pi zE#T%-$(d07@3<6a&yb04Rcye>wXfe+qC&*#FIR8@~n(i_^_4A)8C7 zm{<&#^+tN*&}o@jQEf^hq9`8aH*b|Tr->Zw+vS}-Ckd-i2^X-rPI7E=hH6Rg6(>QgR;-r+O-G6^+g9S>#GhH z>)C!2LZ|J=g%^Q?TOYs=f-`1DUMdS8_HgzCjyA#?fP=WTkL^1-8+eDpp77M^=`&94 zhl34YzIV%-r^}IpFa%6tC9(HQk<>X+5A@@n_!B?-)A4`u(D)~^*otF=7(7yLu`!BJ zZ8kDwl3DObQ4J{s)x0L{`@KocwVpJdo~&}q-Cgs4$$&m+y8GV`rVRS=Xnkf`H%E-3 zCF*OOb4UjYZoE)$XR{z2Jo=q7TfRWiTZk{dX`+QyYe&;&3`!bj8o6U6BA>;05xDca9 z4Nytzc=pl>7>n7;gCsM+(t*SF)j{iFqBo1A0G4v{bE@ldSNQeSZ#4Mj%xPV=@U}@m zc&zw}qywJW)CTN__G9WPK4)$bfD3f@isCk&XusdD1Hd2}_i{?#4W!JY(C>i^MPcw{ z1J#Xe^C~BPa)Qe{UuTZ?@&{$|cVR>1r!$+zMhyonn@!i#;6Jo+-zVkP&wOn0jR+E_ zI8X;VP4S7 zMw{y1S*;wc4F_VGXgU8#mQEeppxQ~c_Jl-ccu5S0L=CBT(@7B71PBIu)rjH~a}7wL zDyMY9P*xCo&;&AsGzy^nmTF0xX!D`=lIaM9j*()^G|NSWgTG9m7(B%Qp!k#Uq7sP~ z2I%L2`){qKJV&Q;dIePQiq*b41ky>{EE{W3$lnV1Ui5o=35rPbP^%U5AAPs%Q>E=y z^(WHYpvULQSA~8hrcpF`*-F%E?mhSb&h3523MpYt@-f6@OP1bz5D1y4?Ubn?`2AVPV#@NcT65BGhe&+X0*lw9pf>HKReie-o>AP+G&w(Fh%!-cUDMaC}iF{Tm^nZ4vft% zC4byja-)?jn?B#OHR3*ef+U{~D?WC8zH%s{LheA5k~YTv7zgyWH(vB?rX(t zEnm|n018I@`U4aH`Qn$qw4)5D2l6!i@kbot*+;uWX7*nfs@+9=EWW6P}Iq zS{J^Zip4i?d^pZXvJH7kl4R( z?0RQ^x9s8brR9ln~P4K-R%mL^? zHL`Z#D6)bVY5;}?(VnT!Zyd!&D zv&;;d|LnF%I?GprgOa|cHBDirb6Us^*Mbl{kH1=)=S(BNf6$4Pq(0^H!~N`KKb}-C?b>Vbq4kprB&~n^Tbv?c0lS&O^Y+ zH!|j}IcxoCl@35BfFL!s&d&FP4YhiK@>>{k^#sq=`FbM<7CMc;vvqOCL;{g8iQ7O{2yL!z=+SQ9W<_yJVo zS}x42y#U&dt;A*Q94iZ3VwSuAIVMeTn5Y5o?+yU~`Wf2x>N}bYoAFB*luNDzNiKN} z!wC#W1AM+u!3c-$t3jC8x3p8mM*X;{XD#VPmK(@R*lee7bYU^q)Teulp7f4`38{kP zw~?bm6DV35r{V-)9>n2 zhg-*`@wF&rkY0IlG6R*&_I|+Dl|;m1IAAdAhs}Q=nI!d1jjE{-JVe$#2Yy#25phh$ z^3-TN*%Mo0X~6ic(dl+;__(cT+>gXo?u*+e0iM0&2EYtyG#vas6try;=u}>C9`7#W zmPw%rwBNN)>tHY*Yix%A^Sasz7JvDz5~h9lB`H|uNmlaAGn$IvheD^T;hgal1U09% zyQQqh0=)d)yD{9^$+*~We{i_ZH^KBH=$~FVSFf1nb-vN62yGGrl5g3zpN=FH+%z_G zlaU162eHM^6g3{Q?nX!)KJWdo18WqF1{?2gQI6N_A4+(>evQ}GRc#Uxv>pF_DeD?zg&<<8w6--w!@gH72S8R-UH}UNA^ER`L2wV**N83E(d0nK{d!Y770XowER%-yMnVJ|+R|}5gB-HH z>&tmZG!SX=K>c~LqZ!P6fAM(DV=|bsg7djc-Ch(>t2ME1J<+%c{+M97tx2@`qEa|{ z#=%Pvwqe%*mYcHc0==+RzUMPP*52$d zW|e`w25+-YQre~br&4PK*Z3rldalWOVjhEtcjwnYu)z133+JiYqoxcEX~js&LmNZN#za5-T9_$H7}0SRk61zwD|b{TZP!)Bj?H!4obQOad?iKMqdtgYm1A!;CQ zaG-l!=v+n@Dj^vjFZ0NWnV5aT+&_|!*Sy3(V7Z-}W{CFIZf(w#Q-BAe1G?_(e~rDO zs1(w6gzwmA&@i*MEI6-GppYs!rwFZc3xY&j@ZHH-49BTic9^3M^gyyVHYadzi!>On zmnq&hKRT0e=%(%fV-m&`4=agzz7Lea>laP&4s@wXlNjK}wl-PK`FKy{6 zIXnBvHS-TZY!s|u8}K8~?}TGQchos0MCYCeeWT)>2~F{gAeOMRKBqTV3kP>n-;14P zSi^i;g;u*nXOJ~ko&LpAo39{w^6?-#`zn>zZs6ees6;EA^Q{h;7kz58N(FNzY4$F9 zoICbW-7-Bb2299+Xi9kIWT1|_<{b8F?y7T4Da{S_E)9&=Pl8iIb6CrL%b|rRs!pQ% zwq#>1-+vgTwvE%5UCc9I1JS=0!+3Sk8=Lc*pURBBQH%j$kVxldq>p)FDwWjM8jpnx z_FZJ!UU9xj92T~{fi@k>pgv-KpIx$yRsH8oQA=qhCVNnGUjv8tBRb#LT-`=pW3D_S z?uOXUvfAWYZYXpQjr-i@*|2kpYP~pBj2#ce-p**)*@+z4d_=zM--i5X->@`Z3x=HC zr59BuKay8D-ti<|hcx1nfJ0cX<`&KNHLRLMV(V__)8sY?uV95zlb zx*%8F*Q<%qn8qH7R`V^?P`b21ra3I`pq@lemDft!t~xBHs{5q(&^r{ZZLT$?dQP5Y z7A>40hE0-aQaCJ%m_Ua4{q)1tGoR}v>-UBXN$Gp}72xigjn@T}CIM7WSqnx6piebO z3XTctWq)V_;My*x0SK7IDpf<$^n zM&uw8GOwbu!#*&e^&rwoM)Ms{$wabNS38qNCpDm=G)p?ZZPEGukoNFZDpDbkPnA#xb)(Jy7#tJ61r(!9 zqz=`f1B9Bo@E@tkQTqesDlGftEy zENVD8owJthz7P4qBDl)amc1txtB&z~&7s8wZW=lHT{o`nn->IicgJd6wa^i5a1n!$ zO4Ym&B_Mo36B}q90MuHQf$HU1#THt}s>o?2_3nHdJ_Si)tA`>mjXamm^lcCKpXo4A z{@mPHQar6L_usz5lB57is+@Ep4`T_7C0MHNVp*)YjzYZ}ERso89rLZT<@B+& zWNir*R_I5+n(?~G&_{$0-#(Xh?`*Q*7u-7$k|Ov(r0bu=@st>h1HoWEw~@>$XRMb4 zW&;YO#J|)CyNPkzL@HRjD^5`OEf-~6^@v8WVq@^V?F)T~!fNr-8x#AT2C39SSifzP zQR$mhckCoR1^>P11v^Qj#8>XFN$v!8vwT%wE7dmW&InTKlGA%a$+(7yhIyRm{;?E7lnBk}mA%l`KaLwjsr_bs6^sYh4r?ip|*sk}>n; z*-mbYu`C*^xSSV{ynYRezp43bpD%s;t}2#Fy9*e8Jw959NIU&(1Xl~$%FhP?bnik_~QmQG_R&mHqkA-u zLdIg^Y%rN5&Ek!EbtH~1awF5PbP9uLmXxgCo3y=+@qNFOgh$k=HEoD~F%^2vAhQ3F z7ubXBS~iQ&mppYkKLW>qbSco~aBocf{^gfzHwuuZMPAk)MLbca|6=#WB4^~CD zXBKEz>k_sfvO5!zM3chK)=8Z|k&%|H4xuOj#}1O(DSu`Ubiq*7cAVj3?N7wgp!is`6x?|kP=26oCH z4;ZLa0;qJ2C_EY>PaVYoI~H@*c6$RCyA>zUr@9>%yJfJmBTP>?0Ns}Vo06Enbh9zv zOjOMPqfm!4R~cpD%7R2m@@uR2@;B+z#Y?W~(>m3usV-SM{#X93QvlP9yu-<9iH7o{ zV}FV;q$s9GWvmB#rO!h3Ms+WPt%VLl`~hGVMs=%mIa^_N$AZs=0;Kzo-t5O{DeZ{u zo(yi&N}DRrinxLo4S7(Ku_E0adK8XK%R^o;r&_pZ2G8I@G)vl9AygQ9#!|4D-N>W;&onNM>A!}y>-ZDtCCJcv&v2= z35&{o+n*4A5HRQ~)64d5uW|yrQo5r*+60PuZoMs>)UECdS$Z>jku0hi(NOEfH1Rgz zW+Hv*RQoL!z%(aDR(NrWVc2J@01L}0_HnVw&};>YCac= zSAY1_#Y?3a@_4(2Ky!WV;iMw^a4>TiHy6EIk+=&B#EDu|Pw+W}kTSr}9HegtMwEO8Bw*p=?f;?Ko{1 zp%hgR6|C*ixvoS#xlG4kra7#Db>;6TB+eh?y6@}TLfTMdI$!h6FPn+eA ztYYrs5y&C-W5>-$#JmhQ!$OYrIJ?u&cR)XRkz8*)-SD``6FPG{`J=M?bTV1AI}E+~ z75yqjqG0?2qXA$o&oPQ3&oh_nhl|dI3GU2&ndkz!?p;L9`{F7QO$s8o$FP5?WT3)X zrEmb8rQJ9Vh#VJ^Lrn@!j0?SoHpn0?#4~KR64IKW!9L^|^N#CWT+7yLR281mU6(^<_U z4@;?CKCU4rk#Kd@7mSuF$jMpbD~aWJFf&k+&1r4>?49PeW&4fBCjEe};h(iq=!FxbWf8q_3)H-YWCf(IlEO`}x3{`fZ}#j?G6o zR~%>iw-Wa8TKXx|Rg=ACkfnq1;+5emj)X$p;q!0;SJg7rQ&ngm@Br%HCA{Oq)fhL} zUD7J(F<9l*%>UYhuf!HMwY(ZL+@XreBf+
    OY=?g!x8u^OT9-r8Hl+V9sgzi@ne z#^1qI4Y{%W`Vy$=ha)qJ)^W6M7A15p{gj{bj%Yzi|5<}A$@tN*59x}G(v8()MajbT z8Npc*dGj4Z*`9fa*;JEhjdmnIx?a8|?a=wASq?tnGMF|HXv4 zW84DjSf)+NcD_A}eEx{M@vIMuV5b8T5+gBu$ZYe$U3O3Bt^+%i57tSC9WOF`xBI;w z(8UWrC~%}@X)J*pqxB$z+`XB>+>L4j*B|+!r_h*bX@B(Akg){JozTJHqt^Jr@sX~I zi^gdBVDZ}O_JvwAJ(6OyZzb#06!)to&4yPp(T?gX6a*#MND}(oTCb|jl38x1NI}9N z-E7|JhvmS^c?}Ax?8fhCI7(VI{+Km>ug2BRT6~TBYqXlFu$c(2Xb8PI)Yz@UboME+ zwQAW_OELd_+dSY{JL&Z`;Ka1TpkGhg%@(c40N3#*!yebJMuQ|*I05=~QGj*!GDa<0 zy|h>=ecgBb9I23RVPXXro9{lBxRc=a)gqP^tiH0qYYOn#v>)A0^$*Mt@8O0r!3VPX z8rk5&^;ysAq~|>$99X!q$oymxky{~{Y(yD^!3Ey2k#86<-dh(uh4_#f>No<`Z7j=R z)1}%DahJ*^WtZEPFdK17axT8-iNlcl9p|ma^0y60SZug^Bl^O`LNDVe?)$EPan_7L zSGW7ImwxxQgn1%^t&^wWoXz-hcX#fXFib~)^6lyi)&vINoYPu>Q z}U;(e2Z8#dn3oPyfwxmUJ%f#kOBVUK?YS5sL3FnX&GovZzf|x` zGC#nZe~;{S0M%8`Bz`;P!mPyf+U5c}xQD%ctE8T^tDl1f2;fO?&ER6EzNldd9A==r z4^A;<6pPL#=Vqat=YnMm-WN!1xW|U2IP<+ir3$ZD`AZ+}pkZ(%grTHDcSi}2;t~qF z$O3_N!?jYik=&}1)Z?Pr6DujVisSs+DaKSqLAKHi&@x5O7) zr5LkRmXNj*T|7w1%!=h1FuRvf<0iXoWNEo*XYDiC7vPBee1^p0?PcGi#9b2lEteK` zI>YnNBtl?qY#|aU>4g%I$dQXlUFq&84`Fk6+lEcV#ZbTn}(ZSCG&zbToS8NZP?V6rc zDvWu(GVBgCJbc!IFqhAXBJHzcbC2Hk(zYTQVKKu1(cmR6~7feaFyYM_vWQ{l3gfb4a2e?M|WK#3v-2ecIn8<~`fv1S0}GD67{ zYgY(|JuqHm(F=o(>rM0n&i9+<-4jmXC!^0Ws$ecU5=zC>(apet8GHQ=B^1h3cfAdA zbis0(xJsmMM};s8%LN96R0~P4n6empO3B$!2P+XEgIIcpqg~UH;*cKk2RLBSWTDGH zSGfEfp~wpC<0mHmo0>Mcd6c5H`#W8e%u zHc^z^xt4;w!ildrnqG9ax-G3H0mWJVkX&~(OlUdS^HH+jJ4B~ts>+|;QZNFH&YrhA zRsEslZ0=!i?QLwmpC3_6OGIz%<2m~SJIYLorXOIt)Vjw6%xZ;~#(Z&F5Vn?AcAo~9 zS+x(P&R3PX8jv z&v*C=QGy%c(=rt>l{K%az(dg{QSBu|pAYz3)$58_!-Qg{p2!f%^nWH03|JNg1#6;G zmOv>En+=Q!Q3EclHStIn07gm!4&Y*w4;S?vUxo*2?csr1XA@)0F#qez)63lsir=;1 z(stN{wmL*znSj6o*}@t!GGLPTTr=1>k|c^~>`D40Mq@>8dUXig*-wnNz2yzOEjJiM ztq{1wKl#=smrR#TSgopduh?7aeGBHq{TbVS;bz|zc4TtQnA;j=2f`Gi(XuOS718`) zJqfZYTx_diVaM>=-1+^hvhvzcAl&mTzwTl~KU_GbmsDtlJ-m~@2_E49R?M$7J4@qX z69WB@A-EBh1JiNIomp6fLU$$@WzNxLJ$C!gXG&+kY8>3j2ZBR91k+DsD1a`pWHoOs^)<{?uak8tnzD5CIOJ# zMJ*b;UP&%$qk189=xj zlkS(qq1maT(A}Z+9})00KpLSJ@Pi4H@PGT&7Xj%1&~5w@bNr9$HiZ77Z7K8nDFW%* zqhS6+tio94^FN?|`9oL`^dF07-uQdqm;a#~06w?S@z>@C0dgDl^UFVb1o)4Pz+coT zs(7uD%J58wKXfQk)=Mvc4gT*}$j*PynBVV_5&7TvcoEA@t3KsrvFKq``Bh(H?yH;^ zU!H${^7rtsr=^~U-5^0!4xlh_N%dG zhcUCxhimKae|-z^uH}JPwVMMb|9+#^wqF7zJqzjZ8Q>DXzarqvl>O><^J=l);;$Yl z;(^G3;P>$B4b89r{@MQNKY#TkAQvOGKPdE9&$dp6q*VX$sVA>7)rdt>@kxJ+q)Lf} z9skn0d=6I;CLX2VH_Zv&dGklZU-4^vICFhtp7d+FjTs(IegEAjuX1cEy7tb^jSk`B zk3xrszeX&tcdha-?X~(me>j1;vLEho)r=+TdVM^OwM{PZZ(ga)$N30Cc|DKiamIRk z!0I?j4S%?R{xQ!9z<5})Y#3oik>00yUm`8>^xR>f5^Su?y)7K zecYuM^5`FJe)@g51}b>|2atQ?FAYpb>o_7|M_$#LQ<>fKeag$hY@u^G z(9Jfl+fu$DzNpoqV(d=!*=60Sb-()+!&(-hTPd2_pA#yt7#J!CB*ATL1DRA$4aaHwJiMC2~{^tkJapA`Bd_W^4d|Ok0CXPv3W&(SsLfY{V}a6|IZEGG84 zN#2?8sw-EEf9PkobP03=qZwNW0gB;t0oet!=SsXMd&dPHZYqTEdUP1+!akFS*&Y|! zL5{O-r&Q#Rr-0(@S_xKPfHF!N_M@*Q+Ul?5w|?F*2V`|ex?A33$H?QV-Q8{nDA~|k ze@*WoNm+586@rB8l#DKLCmw^id|N2<dCOr#-&w*B6`lBpbCv5wPLkD$7I^P}jANWSiqR72OWHMapsq3KAB~tc8zIvx7+!UQzPmVKSB`<4R ztE^53oSAv&*J1LfnpcaWClDHINb4;7c_SsCCB!3cF5+|V^|bGk*A6=TX1l~wJ*3yy zKQ5#S;m`a87=Aq-hbHQdM&UcoK;yXyELvx;R(MGxw4I27>sCV1St@iQ49%C3X+3!8 z&a)Yw0#8z+{?XL5iu3iR)}_zpS#v6UZhvPmciv}xnt!fFWLbS2gWm5Ec}tTZKGC5V zPAhAFAlKh2kKw0tVm`6Ok1e;hCQ?X#q^5QJynYqbe&P|8t8>-3dz+F?jZw66E5+d1 zq3tpKdVTZ;9}qmYb4hEnr5C6@r#3&zMO7H}JxRVXK{<|GbA4E|KAL9!;h-BmN4A2I zGbip_!LHpKhek2pmG7Wy&5iZCX|q#q&60BMIz-k>zgWYRVY8{O`zlUS9T8V}S?zud z4Xkv|`bJL|vXMex;H-Bk%nCxD*%+pjM-fkwI^iuoR2+U79UDR-$lk5J3GXrf1NeGH zXamI($J{}aJy|010dZ4APPv^<^E1Ia46fGVzPcE%PoZV>DPRoJGy6G9ZbHN9Jdj%s zzNyveZO-1&m04mj?v%z+>bngA5~*00~0jAdZ%hIwYI~nX^qTFmR_v*+U1c!#qrpC+kn@xD7D5IAQBTguUV%8cou~(q>FF);r#~ z&E8*0)je`c869wdb-}+&W~VAzxRcvs?~=yt6@2}I9e@@tZc8S<_X;EHX0J+zDaKwZ znBLYq_EAk0Q~y}+x;1dfPRMfM;W1h3l$bu@en{iOUvApMhRPAa+>Q;or4xB#`7&pH zlZ>n{_ygvIvY{T7qGHbe@tU`zU3?Gi%U&gp*qkU&Jh18z(AmJGGb1oEHe?B~wsn}} z_aof-97W)#=c$+_9zp}=SDpLU{N*L5Z!Mn`OwxUs%aGH>1laQ|OePq5q!JVsc0rAd z$g8FK@HLF46u$H`2kc`nrKNhdq*yvmU_ma0@9K-iJ_RfZ*31o4xwqBS$`8eO)9_`S zys@Fptd#O&@oeq)X(s(h1}V6ndZ~t-_R!U9aaEDMn@aOh??2!by51%Ga8$+g zLLX#(H>qchnN46wkDlu>gs`bjA2;A`8!>7!?~;m(!=s&8H37Jz{K5{x}#__Sz& z9nKGOfW)RRBnIfJ()juIi1X`Zf=agE;JF`zdw%Z;jwyzj(Z>baLwmnRSB>V@p}n7$ zCl)m(UJz?ZHZF1N9zUdP5bxPuEv**aJWog(>+m_|)O*>7chl6qGaVtfqB56E7?;ng zwJbeC$yi4b)Q@PLbn8mj{8}OF%Wrm^KrJu8vtjI&Dl0wCXk3uGzP`D_G;K-XM5dHf z1rZBxP9XJ>uh(pT5FzGk$I>v_GD+N+S2T%4W75g1XxyaYL2KEexJKpL=HSUfJ6Ju; z_}bln@n;j5KUt%FFZ02P$kzd&>yMyd{u0=1;8G|udEyDN=mbR!)P>K{coV{;7UyV}D~ zuvUb!6BLE|qvSgyOr(+6e2i~D&SmwAjee6;!sJaIcXrR;B6DB9O`sAC(;EbP62+AO zaS;Fp1`;9igX9u)@(-0BK{JzG5>xynIs)lGizBaFj@OHfP&nVH$jV2)8%h}O@YKdW zf*`QdUa&|0^hV6IRjGK+oed*A{><-?cWrNGHscmK=vT!H|E{lOb+vp?-rM_G?~n?= zp{*zp@(R-c&V2zILqeKy*2q&f$y|qTIR(3=p7&O+%Aa6S6`PS>&fwVX7ky+3j!Wh@ ziQaT7X=UAR-6%%M<3daYAzfLMq&8vf_8G7r?gX6-xWbiN4g`LkfP*m5$WgRfVVG<; z2~kZmi4kLSl}vTTlTHt_{KXd@?Xg~&_UOYfO(O%XluQ*~3cF4in5?O1*OQ)Q>Sfw_yRQEme(RRl6(zgbU{lH=``#Q6nUlp%c628j&W(M81$`p^B zw=7`0q`kMlrvRcV?jKr-S7eSN)_LlO#GS_xQfPyi7-DQD7Y&{1ew#(rdK^y34^&^D z(*&C}HGj+SOSe`+8a4rg zka@@EoUvF(AWOR@$P_Xn3YX>f+TjC-`>R^hAIVI5A$inpcz~(8lZg@(06cyU#%1@j zy6h`i4p+e^6T$E^z!P{?b5z^jYryB&w^hmBT4m+9IAdo_bGv#quO;UW!tSB)>Y`}h zK5kT5f|OT)O+uZ;zH32w>jR*BXqm}Bi!kgILP;qp2PHI2nj7gS2dY30;ucq+@>nQ5 z99GE5b$%xPvD_vBs_aW$By~eJzuDaOR!fGKpUv(Id9`6!DPF0=Kx>o4QyU67#Qb{a z^z;voo}IBQe_mnHc+mZllRxw1Pt(F=rJbB@0be+xegjv$#UT8Z4OA{MDq zr@H`sAX{xOaU+1j0+!y{eXo{Jl&1j}dye}<%uH)opiB$7FVBT|y#-r@r6ekMX0!d( zNpXLk^hoAfoE6pRo1z0n%wBoGpVYH>OW=o}v`#omknAoL+Ms(?vhO z`<$VI_LgD(y;aMz?$h()4)$b}*x=F{wMr1nU2xY@#|RViG1VeHzn95uJXUB^^K{BV zVY$WmJ6duZszaN_h+0!!`?zHK8>sBzRHUDgaVgDemJHgEC-uX$X2)A994)Wpi}=|u zbOYi{Fx#AWe!E9GxgJQf)9e4{S^bcoc!@}yI=7V4j2JZMR{mmwUsT+?kjEP+lyP{t zcQ#np-M1qmt@Ik7bC=`!!iHBHQtpEys!c^Z__~*>Y#=WBTn#RO#%_gSa^%Cgoh~~d z)9nb{%#mTUyGD)$!RPU(V_8kMfo4|S(Ju;&4byDWQA0RH0-MTGDRYT4lZTs~vsZJf zZf%|G2WL)KeZ624nEs?Aibbi3pId6CCMT-stZIqZ$#6^X@kBu)91NfFYBEo^)lKN) zcf^gxhMiS$zkCX=+jC3%yg>PuCEnl!=xt$XY!!tN8#RJPmV6N7NHe6-`H5i?k>qu2 z=1!4@|GL^(1TF%Bmd?(kKG(0kKU`8#S(_;QAIygH)bf~|U!@c<>+)CEH4v$qz!50!%nrmqv_$aP(sAY{x1lIbi!3YWhFP;0qVoCGGKrk`%3#Wh+i z!Iu~FTAm+%+Nz09v+ax2K%gs~Z z@NxEdT^W~}KxL_iVSmdz>5x1bKb9$@b+=&?&B%o$!EKb!z4X#{*1DxY_U93Gx`hcx zBc3NGr^h72?IWTE7p<02T$2}3qHHAh*i;s_L6sYY%AwSN+Is^?gLx$q&`L!)gxTFf zZY0C6y5P11n$Y)3X#m?bMlyWfzBJzsueGDmrHLIfLDKx&1J?z6;31NNcjNY+lj(C< zgkX7ep(36qAKGm*RGj639QY$?I6gxFkY^Do|3qL+_4)45ASUz44sP?Xb36FWU|u&& z|8TLNq6x!ou=stlx{ed{B*Q0^-0iG|{-vm+@c|wMp#^c=3I!$1)=`)0cj%I?w){`A9!P#9LmP$+Bf=u)+5Bgsl4h+|NaYsrIeT)X?&clug9q zlz2K1NB7$(A2N)Q*XihWFk7DONiGHTKJbQi&a>h5&@qGDOp>kQG%hVo)vyAFVD8q;pj=`HBX)eXp(wZ%ok8u;cJ9#oQo*X8&*R zk{YGqB#4XXb0*QA>o?RNi_&y-EyyyTm!?_YSK(Y=PAI;a?68>i{>u-Pq6hpyy{-}N zCx21*SFfJ&rW$Zb&TXHjPG5NcI+= z^at)R2IDYdGH@WQs@l#6#Uf4N3vr@xJpk~h+ZSv)}CE-)MkhMZlOZL;>H zsl0%Oc9In}U>N-DpNxg`6HNnny9Xd)ddeuXXOfBe1x?a~VUlX!uu5Jq3b32n83lx` zL_J@1VQaVZ3!u3IY8H5@mBX)VDUG{PI=mdyorg4*#YH|Ex;OiFCRH&h!(XVacJ~eO zLGuG58TY4_{nE0m(?F_CI1`2=huap(9Q)U{WXX)5?tjJ7IOF6}hi8J(gMukw{s0Z% z_UFNY-E_=Al9b5yWhyQ`l?%4e=BeY3Qvzd*k|B3D{ed>N1pZt$C={Wk&(hN$uQeg2Jl;@_R0JS|86=a*V;{GM0+9tRD4dv$zwe*Fh+eb(Y}v-^S- z%zKN#rGfvA{{OE$#rz^W6k{FSf00Fv>mH zknDF?@w}-6y2^ftx4+%Czcs(DMW2A!6(|Gnju?`!e10KklDQ+o%LmC>9sEC2N?y5f5 zQxPwd^!NSqxU(U88`=~KfU{A+I>eUx`7+y=Zc9fa)4wyHaM}-fGwUA$9c^^NOS!{M zWca`5fv%ZSdKp>&KZqjwbFk6xUQp2CRc)+jOu{x>0hn_+6bbnSAU_}D81X^giv1ml z>AkKwCs=(Noppq(y?$9_sZD*k03`S6=#NjY&WryE*(^%BzhV)9*7A8}oSGRhW%V*^ z1+bshI|cP;(qV^JPWJyElsUuSC4@Kv^qPg%74Kz7G|L9B_MUM2FQE%~p>I|H{nhad zf3^_f18y)8KP1v8*?V0I9?1)uM6piI^pEsI z2P#UAV*R~R8=^9Kq3x^yV18Fj@Q?wDK%pGqkn;@!&!9Iu{>x~fjYXOvRAKBys1PzR z>(`zE401HSy1gn&kPY5~!QV%oHzxoLvqu7FmbpXx^3~?rJ80-&QM6~wew_a}N1zlt zaI$&MF$n{&i(Uw?XHG@D@iO_-e@qS}tmTQuSZTSw2QQK~ofdeB?6W9%QT2HksI@eq zG%)FRW)gk#O$W%edez~4aunG9@aLFdfj8P!A9&jBw(@k{NCX6`pSM>Z(sT8|3

    x z?^niqBf>N8FFU7AXFvoJR{?sTkNkei_#7|!Fa;~I#cZ*B8!z}=W8isT9FlX?y#}5k z1;Pl{KYS9-exUlE z0=3|IfE;FB?t(3^{d{5;UWNv&o6VD;V0lH@yU0J*OdM04L) zVqzj*AN}ED3bcbok>sz(`HioC2AlmCP5KkS$?OU~`zqf;u9KP{uNUjG{f12l1CZ@X znS*nVfXBI&M(=@#M#>!S_5q6^c=v zvv^CJ-Fp4C1Zr1M+z0U{n1 z6G`@?AUM_&=uJA_0E>=wjOb76u)wk+ah^vkI&N>>*YY|xFbwdf=<6(-(4)C`?7Dn! z39{e49B#j^KJaRq@9LYvW5w!SMQ%F`xaX?fGmxMPyn5z+{e1`g&K)SQH8yA0Kb(Wa zTGW>0h@n5vW`doZJL}AC6af{3@%#GPtg#Q>ye@y??_&JES1A z+lujNhSBdFU7;n@(~@)Pc7W0E;+s3;xm^@R_jm8vW+IZq#93co%M-pC50Z$RErX{m za5)Zp?~QjM*XFmCCwB~PLsdRUA49Hl*MW{$;w^eNRr*YoiTVuUYoPp@pEAWmRwM%2j3dO<4A+ z400z&I#NJY2*ed2fvm~;o_qO(SJY`eCaCBJ_jqorURW;pO9!|x0uO7btVca)(JVKf zGx4V37=(ps5t2xt3tmt++9lr9G?S>YUE7%i6;p{$@OKK54P&GUXok1Op|B2~&Zt~Qx*P#yC|?Pazj&Y=y(qJW;S7uz ztGBk=-~ctnUv&36Vt>8@Jz}t!Mf^vu*>bq^)#!kz6NZQuBN~~S+p+Dr{wW5rK>vC} z`bH>)c`l$;3)Yy4+GV^ql+9WEwdN$7xik1lo+nU$>1h%4xG3rs(DdAPf7}{!t?c_a z>z8ThmTSYs2()eoI_iuQ(ELO@Gk88AdRimOdoVAXqw(Vc7zgbC`{UAITOD>oe^6!Mx#|eUHy$G{@WkQ^j!543`}Az3Vz? z24w_IBQ2PDx}5f4=2`?2=Y#K#yKhKZHHmRBvpkD?5QF1#lk@@(_0XHp%GE}cID0=#lN@)30Q)&A2%?u`uS(kX!xbh}R-G3frDAChE1 z{&%3k?J!x^gVBC2{}2C3gFoEqxI3V;i-q$lhC66Tbla!>R*)seit|n~&4PJ8-yV)& z;j2sWTQ4sGo_b*16W_HyVMYLw7@6~bac~+=4(qkh1V2tNKE7!Pp#&E}X84f^aT>mG13N7T3sp5mv2QMs?<&LqxNDWkE z0egFtL!i4SzuQXp_6yKsv2ZPi788q@*Qpz@aAGi|y`D=R zX#54b8jg-^;ffE0*{-(S{p!?+f)}Wb8d+)(gIl1Vi?_tB=d8 zwv!p10_x&f7a2Rm4a&_OrRh*6(aaTbqq zQt}oRalryS-@V5C?W!DqJ(Vn!!1a99HSq-->MJY2pr6ED{+KorL{89o0(GiHuJSx3QwB~ z;MBhE5Y*OkC!56vIpOULZfD&VG(=0F6gy(U5m%K0(bv{X%c%WU7m)#_VMj#=pgtVo z5IoJiG@hJJ;dsJ19NnVUM|E}bnF^g^{Kxu&D49y)ekY#71_7Hy_;wfBAlr4%kw z_k1BBAPo7Y@X@NMxrE_zjgk58c7ehKi;H&mS)=n!XCu_bLcJ)VcYDwR%g=+LyG_=+ zy$PD~E`!y_UWJmcU_VRD zHx0eY5QwV&EC9Ox&O~E%zOU;X72KaOhYGu*T4degB4qw3(G0Zve%=H~MrUw47)vIp zt8Vog78Xm0mcez;yTN`{Uvcu)IaSstkvY>Az8YFA#BuIZZ33KrAwyvkt_Z;>0l=_R!7-vPP0ATyqK*w9mmj zuW5ZT+8u2s&5Ke)bGvexOTDKcc&9i)^=_T<%{`Zmv~9!w*htrFmh4_s1b|?PiaY*> zUx)+orcI!ro*zb^+uV+91$O!bS4!}=?lbrb@zIo6g`;F-(Of6sy^EgJ#LvN0i)t;{ z#^k$+Xml;lp2R+iee%2zro(EqxmRm}RpZ)=7^N|o`0=}}J1LtpLrq;HbpUPaIbG0e zhDgQ@-v~;t)=sJ~Ei%fLRM7LVIuW7lcSwImN@g16#sp;Q)w^{7>(Oa)SknNSWH+vO z4w&`>&3)+jH#Z7nq1SB1f;9{JCgme#6oIrg*uY1`02jo z*;$J|s!W$SL2Ngk?8ifk<>RIJf-sHs4L+c6S6zSsa%SRi%?5x*IJ&L z=9}#f=f|lUvsVxhLTbPLi35L@70Ja&|MnNd?xZ*fPGHmdVe%wmj*9xUZp*6ZZMEV+ zL4f93;w?yYu(U`=vh!G#?1NgYcl#wu^j~^o zuZ6Jndr#B_5}bI$;H*OOh?CG@^qaijOX1}g+dRxRDzXL!*{L+WDQ0LR2FS$<*_93I zn|e^Wrk-+XKew$+n#(btbai=t2pj`_P$oWzqKfwo!Yfc=OrtX>MQ3)P3^&i!Tg7ih z?3POLilxp;dH^+s7e0eNOh;!X`<70zKte#|&>F)+lLV%X0gM7h<62xl`iubg4wEhF z)t!PXqNhjD{h#Nj)yGzhr;}X?TxX%FHjJBL`l`n=g(qb}J)YkqeNnPHY$eJBno(*` z3;ZGPtsZ`87z`c=^W6*!mbz@?WH*|wIF#l**xP%t$`+MrUC7u88V+38eWH*Jen=Nw zEE`y?xw=052&yT_MOX{{b1zFqya@pZ7~BHU9^-c#F$y#Tuh3vj>w zfS!Hmoc8clC7Z1X>nL)cVs-giQ$$4Pdy-@C}?Xr z^cD7Y$rpz(Pc~$%RCWyCu`Yoe2QeQ__4z`KDbcAhhBxd;^jJR7gY|@Y&ae;={$~MD zU(iZ{qFC2+081&{pZc9~3*HVyC+@|^h7-j2?IAr~Cgu8Ft^NU6V3qU2ufve%7;%)Y zj|Jp5TBX|_*e?3ac9dtKR={I@6UzuH*-%(HE%l|fa-9mmds@>lP>=F0?Qq%Iu-E#A zyhGcdt}fF6d{dm}1FzQ7=2 zrh%tln!ZW)yWLapE6u1*G|DaaZMg)#1612A#J_U5-AXQ_W3PW;$uIE>>Y+Wy3gmI= z-QpS8_{zD$1S@Qru%JDhdEorOm-v%yRQM`N4u z6XS2hMvz_7XV?fH{M9HwHvOi(g-i6L8zV`(7N~`S3{swc9L9@D(mKtH&(G;@4 zM6Vm@P@RO0&_!=NJ30o!b;gt%R#3CWVbsSDS~4D%4LIl?$`9n%>><4RW>vr% z#4`C&8Qx@swadKZZk+04$yBR2sSmPdhfKkkX?dbdblz>j#dJj_Y%4^dfTG^#z0q-6 zF^d9eTGm=|fD}1z9E8wBY*jS4h=ETK5KP>ikiu}^<$6*2yx!$5(1`6!DErgH;4EcDAqN+f)=K*hyCD8OO>|1e&I zwSa9GB%opeX@G|Uli<1Gdr;~`fR5fh_;XZ5ADV|U^g@D9}X@!nw-+$zr`!WE!9Elj0AM&KCamNalgH1vhcBfp0S%o$2;)YUK~=O2fRd zRO?c^LwuJa3gk>XqaR;jj+csL#~IUxV1O}8P+r(+N)M$U==JF&%BRb&ulm-Df^~_A2X(|SpUs`3Co2regYC+4pRJSEB|o}68@x` z`qN<1s!iVKE=N7bh_HqhOkJy3I-ENJ@Bn~+2^PeC1X!`$q6iiYo+b4ZZATeKL$v>_zzQHhhgC}|ES!P|#UL+Cuj z97Mb`G);I{mUikt%9AdO$CO1R^9yF<_3_#33sB1C#ddf1p!JTaV^8v<-(OtFy|W#x zLF}I4c&He6oS>%kp8tB%Q+V;%%4~t_mfkTpwUlUvyf&)>%K+9RlsNG-kn?S~$7^dw znYq5lM7<*(SNk9H2I=Fr9d1t7s4+-3r?F6^aP8RLpJj043YDJsG&%8ArHNWXsC$ri zHk_Ot65mYGx-gSY*)CXy9{Pt;$Gxw7Ur$_V4X>O25Yqu6H_R?i`PL3<0IB+s=RioB zm!n)n20p+!y)z|H&PJ^}f_~BfF+GsT<%e2q2RUgOX^Vgw$)y&+fL0Zx4-V#Op~kQU zn@HWL{I(r|S+T*+&G{unbc4>e!18kzQ!`NdEA?7k>_Sk9R;rDBQUrn104`y^^R;G1 z<_D%(G6`X5=fJu5z>0U7v5ORWpy#47vj~g8=5`9fo5--E8->aXB6-e2Ii!{o%fYJDpsy|vkq$j;wyTDVe?Gssq_y2P7kmFn`ii>G%G!b{7o zN?jR5cU^bF=%O*R`v_PIf9Xzg7oj`*4lODUHnyqjRy{zS(5eGQi-Fvl_7y4_Pw&dw z^8j5Z;zlF2=Co!dvGC^%)PX5!+}m-KX|3rSiJP>nA$qyFC3P~szRNJpj@39r>24?O50-BW1Y2cY5GsWo zd_0pS%WS!`syjfN344M#dhtf5Rnen3L9>2Mk)^~ln6$zENfZ28;Y2XY^}Q{rD;k}ai=W- z9Ne%cB(1>|?&Muf+tnm*(!5me*e%3-4s&iSm7kNl79g}nw#j7oK5Do-Ep-ShjmB(! zxVn279w$Dl8GF9);!pF9!*X2kR(-;$D5L%k+AOi=>8WVs9lRdAz5Hz%=>;vlo$)6B z2<4I7r-wu$yGgiKWQ&zuB-Wkx-h#g0x|Q0Xw&d^uo=x#qJ@n7;xQ%q~II9AZY=|EG zh9Q|T3L>|CpWO4;CTfw15eo7jWar;#Vsx)th%aNS(&eeQRd5;fAq;gdTBsJts=dR- zRU~jmaIq;w81gAXL0X+zEy$N8NDo7shmBR8Oe^V#dfZj|E>%jF#wBbZEbbe}Q>`pr z_np!RW^1=|)@llJe1EUAn)Fv+%e1MgfhCtwVO+3^l_*^p&xiO$Nce6hg4QL^E}pgL z_>dnCJZ(rm&@iqHoFt6FY~FKPzXfi1!a3+AA2p*C6H-uw`JbLw#4UFN16{jz+2S2` zcV&mrIR2EaK`p2L;1|nfT~`<@#CTs^7)a!KS2xtn4p%vPs+(shaIy4AmG$=aBYU~( zjSO4cFoG{**Ch3$*qZp(W7>HHDnLLzNx*aC&gbRT zCUGT1PEH~<%1ktVq83zXfDX^*wC~^@=JX>$DwzDy*5&GqA$u{x*ZmOXKoxYg5l@+J zw2N6%A>y73mHk$lHS*Q{kDdnVsB1N0HpefeRRu-+be482L^Xq=qM~a9o|8T9>H2K( z75*nnrB-p;pNA=a@%C-2zi~}y8G@v7KxTpOZf1HwgctqJ)Pfjbl&ls_C$lUNk0Xj# znRDvbthPxDGkHx?qL@>{le!(0?S^Y8NxlA^ht&SWU$XdjY0*eMl94kAZw`u>s^;XvOCtV zzQyO2`pIgq1VveS0}ZhK?n*bPwvXOrZ+sO5vs!{I2W*e=JyQ%r481V!jtq88h~xJG z{E#o{AKw$BhRE|0W9QLTqq0&s&GnkjGJakQJELSVa=gtcTP+UGfaNJV%k5`>@#?LmHXnlaoSO2iqHx z3vW!_A9>x-^rg!OlA_oski;b)B>}DvL8Ci6Ld0?CEZfO)P%~<+_Gj0$Jo9!c0*F~S zq28;DUu+G{sAGmHbFaO^A?#-lYOF`B>3T8`o8`oTy{X&c64Ilwr(}0_2Yu*sPsP+M z>JB`x*ZAn`RhayM5^9BgK0JmBO8l7qseZ&Kdci|2WGpK>gMfwWkP?vv$QsMl)%O@% zJL310y$@-L`(O}g)P$pkM=m30M5d4D+o?-iIrSjhJkMNBrm8e7`H|Tiw?zD(TJ>KQ zPow?Z;g6(YfGJl#JG%IBuw5!VKrQNp}pt3u5mQ2 z)hq%wC_Q)QE$jpD`Y?HT$a-sl&;#Dp01tV;_U26E)Xl*1Q~*qTH%M z=2Kd1VamL%Gb@rL^H8_lz!^~uMG*U0gvxe2*i;;w)$+r;YMdK}4ma`B>wKY}Oh-(; z$)bF(~f&U36V;;P@eDcIC8Q$}n2v+7;y7_he|~fhEVMy951+aadp|%lehhdA~b;%KE2~Frf{RGR=r`O>=x8N*b3h#3V>z zaLn8L@|`bq7YlOowDH3>9P{>9rZues0t}EH_C-jxZxg16h9NUdvX&T^G%L;nOwtn@ zYpbnYa2I1yMS+%xHa6WAXm+NUGmbz`p+m~h%Nc(_Q;MZxcb|M9nEg=?}V1@97n=y0(m%2yA;P9bpa}RH8dsjR1CJg!(j__z-?f- zW|y7upg;*_5l`4N%Pdi|ouD}fggmXK3liN(w{)(DQtyqbl#jF1F5QC+jvNf;OM=9c25=lACt6^L0vG;Zq4uvWxav3 zk?PYNjHY=JWA}2Tw#b1ymA(&&Nl%)OJDR_B#4!!b(btse_86-#8O8M*<%Sh+=;Su; z=t-U!sQmP-JUi-hpTJ1nyHp#L&{v-_6T7ZhM!V`MLRoB2L>=L5qle*+P-&LO4k5A= zhIy1i3C*Ku>Rc~bhu=>o(uPvk4Z{add`LqzrVNVXVQ|KY+|&u0$Vfb~$lCGO)bPkQ zaR!vX-154A;39TlS3%pDs!?JidDobplEDI}QdIP7tc@Tn?=fm!b^gltTmFG0^{Cf; zx%V;6y~H-h0oGUXR(AzdZ}E7rk0ovtRm4~siIsjAHe${>tUrnePO7m*500`c$hAXo_@!_H_G2eJ5eb{iOfyx`|a1{Szjd=an&NF zIrT$T#m{q~1Ra(qvs=uq4ET;4A2zV1nk>nvK>^7okIF zvemw_=0vf~B0EPRG2DQ+2sBuXH1e#N#vYQL-@lR>H)kb5dv94UhLSN-z;Gefu-JbbFE3AU>K@f&CJ)07ci%2cil-P(9WYPI6XN z?}w%(rBS2E<1U6$$oE3OT@w0oIc4#+FD3o^h=Ao)>KX`ju{?UA)Off!#^l>uI=T2r z2645Ki;V}^QbO^kv@JGMpx0{b$#!FqO7^}k_B|z{8u&4@wiv8zx&fPS zrbkZ~(4J-|4F){uUesi;^sfK#JD-TsFZN6uo2Ig0b??Y36n$d@C3G&wF}GkHa4lt%)BMO&_<`tcB_mEd=k{#${F zW;>(+38$Ko@!U$3yt^r11gIYpU1?Lx|6>eRi$z@2Ypl}d+SdeVy^WPQgc=#&|B%RG zs@^xL-r|i^rLn-{2D|=}a`9D?e0q>WEwCId~cxb}mQ=w<@Al$|ja}%##{5*|}F)zAD`y z^A_aXDzl(dp3smQLV}yFxz*gX&x*)aE>aa1OPxreDuGg~u2ZpEV6KVBQkRrIU^*%d zoOX$tsc?GGRHwSQY}Yfss8{+~7gsU~+~GqN`!}CkxuU6~ly?b(jL;E|bf^89DxI~i znraiENGEFY9L(T(BECTATtw$hGBL>ID{I(evNJl+vAN`5he(=W4KKkRkq7lKaMJOi zEawd?{79r|Di1Rr9+D^#@f4L5yA%%8R}(uce&1D=*IC+6evZdRr=h6e*ogdVOcP^i znj#ND+f*YahJzH4Aj5NJZUVIUbqkn9>{P_w0fb!9kgjtdmZ`iTL?2Z~OjY|8??w?j zgWTusbovKuyscWZA!{^#O8FM~8sg&?Tj+)-5ga za`yUdL`fKZ>}xgqN(q&@;rxN!IiBckl|z3x(1%o_46L^dAC1TNEMr}*?cV%If{!%W}Yc-U@ebWE|REZO`zlA9l9Xkni-2SrHcNrHKyq_P{ zZGqBkb*m_H0n)9TT{h;V`GL?11HTV#JiG^$O zD7ZRY7qqt+Mo|Q1oCG&0wmKoq=6qE=95HtTZQsOFXA)0MJj(sH4m4ra)9QJ{o!T;u z?zxb%Qz-!q3<@6kXjDFNx+lA7b@+|Ez`~lb-diJ`=qh_Evyvh+gcE2hJf53DjgGwR z{TVE(xmyWQ@KS^{z%dZ(^p;*oC7Z(yi-^XHS0-4uH-ZGJA>2Ib*+wvk&A%+rX|Fhh z@ycxaut)EMyPO_m6Y4*|H?XBQpkBR`#tFjqSF1D0-H=TewOmLQUu&UwEtLsH`raz= zQBt%lH_q+7_xEZAvi%u6ZNa;5CW&_!->v3qa_>^9UU2AT#J|ulY*?`xM@u#8Pbl$( zFvCU;S(Vt^yIkRO`FG}T13M(7Fta}fE3xb^Rrd={LZVy0X*eHnDI3EN3pHP-aS+O@ zOu$G*?@&m$-EK0HhPThhhQaA>2ye z-a=dD5h9tjtb4vMnC)>{3Isg1Z|ChWihR0ayJUfZ1i^Me?i75Le>}_O^>;`QRZM3t zo%;a{@a;Z;PrZJb0P3F!a-Dc^qh8tct_Xa(E_fFVj6aXvAZ{$1H;!x%8QBM^)How; z30dN+S)4N599AtV2=v|^p9o?nJLkbM$`zK_<2{mkclvNN;MX%KYdw?)}^OvadtU@YD;rH$Y zyCaYqkclbPhqp!N_;#i3sbklNNQiEa%~Z%h2eL9FcK@j&^(z z8G&*x8(!j<8$6C?eUM&On>JTtMD@lk&jj?I7UAIDdJiMa+FH!uN3awx@t_h0R$~22 zP$j4Jukb|Xi9a>&^@?zyh?%G>sW(PM3vxt@kJ6{Z8m5)_sP4&QAt|2zKR1;whTPl2 zbD`>{n)05O$Z7S?C4PY6@)Txi)SlZFSuPDD@X8yI+$n3Q%<1SyJ=(#Zxg0H zh{s5D6Jq}OV}ZYyg8%nlgFiw1&w@V^yaX|mjIGClKI@Z8lp-bW|Ad7k7V%@6XUm^^ zGM}0J9x+&VGT;5z2u6J$B=f!KUBHRpZEiZ@PiWy1&Y-_zN)qqzV_2)6Yvze2-hT9Z z0)AhaO1z_srX~s}=lM^3gn1mLUyE~P=LmK0@!)lBwE@Mt(%Z9SX{wT zLW~{%;fK?`*hiAbWF5jQ6scd(&A%^{=mN*cvHvkg7@Pj43q;DB{;I}b4p%|XKzKx_ z{Vt7qwch96Epgu>AsQ|1lOqligb-B@2yPi2(7y%dr1&v>_Z!iE)vUFGvP2J;;Uyu# zflyx*8^Lxh2cr{+iTM-eZlUxKqh>#atgaAx5Eb3JABMJ}R-L5~1G?Td0vwRzfdmKM zcG0yD{4wW<;@S~76^eD;Or~_C*Zhg6=)s}2U1;zZb0jTup_Fa>q%Q3INS*jeGtUc8 zBz%&ToKgA#7_lN3mynPUA3xIb6q!+{LAFp`1vUbkLG_#O-EeMh?o+xw%HjtADiXCt zB@!q{m;teil_Y~nJ_Zktp$J8f(ZZU_-ism_1f>^K%Ekcr0)R%+T%4|T^C-stVd1dR zJUP%5RRd;eur{~Y-7y^UtNbKkCUP>( z%P=l6Kkf9+P(tT1R<_~HB!bg4C-Bi$#}XP7MN_+?Dva(1h?BA#HDGe}(EyebqVflG zGQS9b;`!b66bqg=GlqmmqE>y;So=`d(PFjDjU&dhmv157ZD#F9=Ke!$K#CR*AnV3( zni)P?x&k2=@qas-QmWiEbKjfG{+m-;Uo1P(#&)rNK;sf-r3JSd{BS^{je%EU$mhMoyXvtDG`aKw{qY(Vd~Vy~yP8rN zL|<&Mt;=8m5@2eNa6nI;6Fbk-engS=Kn{W)vcKEK6e0-zYMb|@M#PrCX*TZ;utCWuJ#v`tMJ*TdrL-P;)9W9Kq9I#|pp!Wg%x(OTSP%7op15KXUed!}?cokF$3T z1`l^#>A`LA=Ns9eBWu7}Bd?zUBBi;nz*>||`14~f)R0wZrL&O8{l;Mx2ya>aw;UQ) z^Lu}I;pFu&x@$kfy$fWk>(b;V_Sb)B4P+kr%ii8Zqls8{ZFYEmh_UdaF6O=$bxDSL zvp^&>+mVGrkZ4j^x?KxF8E6Z-`L5^n^#igV4#b%8i%S5kRs=3}Nkai1Xc_uPE|sNs zk;op%GftR<2Ew;|&p)LWo^H-YSEE**ja>z*>u=d1Enn%y%r4)XV;G~t{hd<)n0!Zg z2>+z<-Ns))Ls2fX!Gu$vMmmkkNGH6)2>h5tL7v?sR0=H4J1_k<`1NO^4*KW}Z=hn6 z0`F0M1Vc-IVfq%}+iy!#WflNQRCakNKyK8P2Ru+oqXxeOS}$bvaW6J_3jR8zQd5tx z#Z#}v9C{oU;}F4jQ(g&tpGmb#6;T-+CP{S#(y@>Dx^1!F7beLmq>< z#y8*|k>mb%{=>#v8+0;+e`R5_eY&+=41<$UQl-zb_t*ZX>e&wJxXbGhl);DD78qX< z*kFn>WEiY8Utm(_FekCkt2f`;x`W3&X~j-DAzGcp{m+_5edNV~Ud-BnkpOHOw0F5~qayde#Kx2l zuu`%pKQC+ert-{|4Dn9{lxO3AmW0eC(|C7;;xo(Zq z)*#SK&Igci=e;*BMNsE}99II#RuQiCF9ih-~0##AHjFzlcjOKX@!YAH-uE?T$bsc)u>!+ZP5b`QkyJ0EdJpx z#&7gNQEKxj6VdI}qoj}Dg#s%v)Iu9R&+*V1So-84O1IMpKIjGtbet~S1NXLd zKdleG+qg?-QYciE%p&AaecqsAKbu^p{wldTBv;LRF{qbi(ClT^{f7>I-F2f|A^?#)641 ziRWa}Wi$_3njvloJPn!*X%cKD=9Rwncp}n>aurfHeVU~h9}DYLI!<(9)rD^;)UtV) z-m6sT7AjrRP=id{mJxVns-j}4Z5^ht`BVC88{At>!SA?BPqsV=AAm@xTWj)PQTxSKA|Kn*32 zgI2z9g1F?qWS^2t+6el#r5H)Pq*3ArajuwNy)=Ir3nPrNw?RL@vSaSgm~Dy0?d#h5 z6i~ev%qaF$Z=-rZ!v={51Zz@_liq&|?*0Y~I7E!CYLh)|#&ZEaXyc(X9QJq^LR4JD z>OVr}eKWhwYUWm|ED}`Z?nAr3l3$YqCo7)yX*21j4XbZ7+YQO)7tU5FDqGs+ejiW$ zhxsYnq0YMy8Trop$#fd+mVq>uC<0zxJMkBJa}XkBIf`cH^km!j`Go0|fI&a1_@-&3P*N%CT#qz@`sYQ89IH9`w;WES zZkO_mOSbnemp}C1yq{%{?2jbBC@Sq#zV!{Vm7Zj;_flJJ<>MBjTTU%yG7u)^}MbsWAJ%nm6!uFmPcWGYt~1~pJuyt*hbl5 zT2)1LRv*HjCpLT$;N7X)0qHv^fg2@vf`xrnbsO2Rwz(&pt&t>ON~cy-&Kg8PByWT#hsG09+Rv|A`$DqmL#46$)RoD=O;Cd$9*5l{ zCqC3jO)ue^#@8RG8{Hd|SCh==l)~Fcbil&W!%m-kwJfSb6y?Vp`(idNyoExHRzxp0 zNwx;P{foy|f5@jL&Mm(9Dm#`On#dAG-m2SChM*!37h#_Z7O?J}Hk^ih&;mkOzjGI2 zzEO*o)`j>^2TSg^gyFMeXHg0rvDKY+6;1owqup>Z)T; z+2CbbDex9R#pcjQWWt)lv$^Sd=RM2n*;P6Db#-nTF1puG*%^_!d&(`RIUJ2l@CKfy zD%c1L8JDkC;!sZ_zqBiVm0zdBM`duKV#7HCiRRq5H10pz}ffM2PgsHl@cvnbuA z8?5j@Aah`HX~9MU-m3?UGA?v+^Xthd+j;< zkPrpP2FwW^XHT(yof>9}JRrimSlt{i0FKSW$G2T}4|s?2>sN@ogr7C7YDLq|JA(1) zp=$$4J!T+?({B%4J=Mq^$5zu?K)p{m<1}r_Q@A_o>QJNu9jHt5NZS%(;$c zuJ~BW)R&GJ3<83fKfPV(R3o#&xzO%=8CL~SmWeZg-i&7|oW!myEInuC!lK(a2Qsw8 zP>)EnJ9mo{dL_d@BsK_8d|J9_p0gHXwxgo7lsouKK8)$Y9cCF%LmQc7bNFoaOwX~! z3`bgJ(kx`ddosu1E?+Fcc1jd1_$u-4=yn>~uf?9a)Yru1RX=YLMoMj>6x9jSmcB$$ zachZu!_AB8Z_Da^Q*D%;_THftxgbK|TSI%b5y2?@Fd`^tUH`mQmGe8q0EK3?TgCOT zWg~sn>ay?wrx^6 z2TsX8gv0K8Ry7NL;q0H7bviiGa^?C*58>nCklL1r@AT3#)GspLN0&S7Y|Y(%Nkp;6 z+p9JudiwbsdF^DFb9Tx{gH#B6yV>%Db!I3Tmn6%cPKlbb|HA$alCrx=e^ea&_H zrzcebT|u&=+?Qwy#->Rkh8>PVH&l>E-OpDkLM3I8l%FPi_;ayn1~<42e&NAWvrX!i z)JqZ{t)jlTV>(m!_p)V)88dLVVXL5&=NtT()`%7`@lBPzfpRCD>fAxZ;mwcyr(6zV ztDUcnYuLuMtM&WLDlY4=f!F2cj28cO^2-PyEq^eCb|zTYK_-qs9h3WI%BC1IQX2<5 z)-)oBhpwi+H)WeIf?Ksu6X+g&*u50ix=_^0P*dY9sHb3EsO4}$;* zoMvV3q%8-3ChRr59Vw$_ts{3Ju!05@)7CdQ4vX0~)jhOl zflRQpW|bDxH2i%C1C>RR)88A_AvekCBjuQ`9K%X|;B2Tk_tUQEt7pK5^sxNJ+_T1# zHi)nT*rg=%YpX@mWhic$2`1iKo6g3Uq*aJSx$Aw=JfN&!pLa+<^20ePc^Cl|S{Y$}e$i8f~s1%<%|hV}HdV60b1 z=Lb$yjWFc}R{4niOurUL>x(zRh@but#cH7zP&PLG6wtRmCXHxBlX^IuS9ijnYofPM z5VhLw$kENz6SyB1>sUY(IVSj2+V7XMLfahtIsEqtJPGl;{!n2dR471F*}veRO`}kx zrLdG~+1u=+Kpk!ylk~N9mP*d>B5n=BT-DML{raE>$#}-o4?|<_(FHVheY@Esl15p z@b&uOhkb-RMSpV6*tFv3;WKal5j;eQjNme^6Xs@^XBof$#*?0zF&#SGD$CdOF|dvP z+i7s$B`F?79k=MK{(g#wr2}Lo_5>WeJbsp#NbVTun@SYqLN{z3}r*@U-9 zHMUzt)vw`zN`w5-j)VEcdoP+V4z=BZ7wx5?Bs}#nqZ%r|%-I;Rq;L?F%;!cT7um`_ z8NSScV1-W1LwPQdE3_7POtjS`#fW7ttI75Z=!qC2dP+1EjPd9}ToqL(5*Siv<^J$j zbv7Gy3WD8Alv>k%3kpNh`&)KwhGDuncvrF?Khj9FzPXwr#(sM&dSYxdnT$Mb^4PM! z=J_{@@Ja0?7iVEZr>$YcG4kz~>xNNrCj5rGY4QWHUcO*Y*naW=kE-0&a91SPtL~LA zjYt9Mc4TKmKN1N#!Doy+L&VYJ!EMw#oLLA4B8dod=JRf5gzX2yIQh^LdmjhOlp6hJ znrS7kwD0Q`TUCGN$`OO`j{{GeLE=^`^7K?_hB+mghjI>{xz7k$1_MaYIJ~!K>(!7R z{)}1z*Z101z?1h>Ox{*aTa{-%c1q}wB;!pzkAC|0NfeEVG^9mhnt3CM(a&7_&E3dT zm0mLbIv!;&2lJLkF?>)YU1<;-Z+C})-xPtzzj?-elL*`5e z!8wm3m?|hiP21Jz(zBYeVZTL&bGE|mWHT*|G=?2*1T6r$@sAH%w_L#&Xu|{dkI+1_ zp#`5Pf)}mWeb%2oOS`Y?Kh3m;r6$tv%1RnNjb0bcEj$2Qtm9b_uB3x-@B>G(>G|*SM zf?VIe$_~v)Jk}2Fizkg6Wg3&T9Dgr`G&vD|&)`060^#BX!!q@|M#EzqdFf!xClh52QW6`FL;YG0wKH#^17cQM(c2e5vuXHW;VXmeoglNW?;t+ znJ9L&W{9PSd?i2;{X+aS9`&g8Pg~XZ6JYG!o16wAnppk#9w zkVeYV_~68vb*9Ydlg6XVT6)*y0*Lt5OgM+gDuM57>iJ7Et;bK`*%1FV zoL~f&gH!(+umLav&Kza?gU|tppD9@Iu=Z({L{-7TW3@l$GjuSXQ8KLZtfYtM^y$Z) z*{)C5mPa4t(Y+Erx>AMprsC#9W4c=Y=&6txi=s4+U>nn{X%;T}<@#@t6Y~4NNeVlZ zsVZS>sXiEkzQm+|cWKe00+0L+rY`!EnHpWT5uDP82K23YJCLoixZr1HFkMlOE`8~z zOv^wVB7ot&f2oq<5z!>-x6zr+2rv#R5o6Y$S=dWvvmZ$uR)h^WSf*~l7#i?gz!rh} zW=)7g>wEeU>bs-qVH@PMV%2J163Yrmo1vXxpL|!tQZ~YmIKI@(pF13Is6H@!pGi-7 z$J=AWow#me;ps*sqbDaG8tK^hrW4X~wr|xWu|5ko30&i&f0?mALVo%l3~BlWrR%l; zLg&yVAsNka;4DRcHOH%lwP$cly!j}0uM-dxX|H~1vS9R(_k)ZNXaV?ok*M|BDyysf zCG`%ZI&-Im|MPbUNQMnl&Cq7b2DcM-1ut^m5~}hH1unc2cc3_dM;`~n69%LD-=IN?vK zteOA=hV;`A5)d471FFj4>U8H;HV(l4v>Q?~n=&$mE&Ka6HJ{qhoq_nFDa7p)rS1jK zdh>-bBpNO9Q9+yq7wcPJzoCi@9>9E!v9W0uMC|s+Nnfa19SF_{MW&^%F|X}cw$^_B)Lp0ZMc1w**lW&>ual9izdNK#(#hrVBzw`CV&N)ag4!BVWG?#-?y` zZhg_k3$F|gUm(bIHAxOT=XUf9`N&UVy7-$}TxS$=2AmO7-Z%I>GoXzCE&{Yg^??@E zqUzrY;iIzOAW&P^WQGE<1;r?TZrb6_E!L|}R}Oy}y1rV_x1m2_kLcO6Ap(nVz55C3 z%e9j>=1+{{4`mV4CjLngr8yH~Sc^@DpfmIF6{Z8)Qj}k-$|CLpB|mj!e-0D8;&muB zQrnBhzHs>$!?v$EKF^9|bYFD_m|D@4b-GgFj)ziKxgO2-9Q#S-_FW=ZD#KPm(k~A` zM&<_$GVjr&C?XDqo7*VtoArZDn4<_-N2H5l_a!aC@pKj3!YR&wlna zsP;-OlG^7yT6Y4kduJLhtWpf{1%3BOH+!7I&S7P)KxmLQt#2IYw$FWAoVb7bl%3h6 zEmWT<81h)kF&B(fp?`c>gWX{i`0}S9JD^+xv@89!Kla@mv$;ysZ%BS%J>s zq55NNn*Vc7fbNFGSKjrX|Mhou$A5U(zx2C*x#9o8tHGJ|r^@%QQiR{Z8eq7aTK7nO zF%I1-jR0T_$_V~?8ir7AL*kp^d%r6ee*YYxa-_=I1I4EBzkTSh!TDm)Fq)`Uz`;(s z^~ZmGxDawwOgZiAKUd+OJP_#N(9`<^oBlT!jrc2814S1YLMtoVflq%E?|+RJ5S@p1 zPNFEkj~DnqrO7Z0ao4Bc|34ot)i+SCkm7Y|7DELOJM@l`|2-H3PzN|gAr*ZM+O8S7 zVj}*c$^UC;LKDSr-p=_$Z0>*f-(DOhx9k?l30OZ^na974)kQkGM`iZzfBh>_pHYPl zL|A;}P4xTw96>XN_c}yPyQSY%`D&o!t&C9jHGJq*3q%YXOo<(L{qy!%qRv?Cf4=I? znm6C+6okIkdarZOZ57jb@8fZ|OtZ3rGBK$yO=LOkCbesdlr8%|=0^#XI1XG*9`|;g zOS}bd5x0CSl=}oc{pUtbigvBtO6;jW%q-TPTbc|C=>ISqOyk;Il8phHpAg)b}-OB4NH&H>YMP@L_c zqN0^FdtGB+;dz=YzezDW?ew>DQ@`8|`JPcs*_iCI`|}Di^ult!l#xaVIauevyfJ&g zS+J?`2zAd&KE};xV94SD+mag9(Mm; zqG{cvXS7Ig7ZpA5+(xH+gSQdQu_sq|^gS`R)6fKW?f1E_#vTZnKFI~2@M#w}C@55( zbJwN6No@W$XI`vWJQttHoqe;4^v5iN^URfeB=P1A@wyVB`>~h{!DfC*i9(atW#X3g zn?38Si~SAz4ARI947Gtd9ev3T?`fP7#)|mESyXp@2~+0S zzU_Un_p=&Dx9G?8z($0316SF!xB_b91Q;voVdtNEn=(_(&=;p6lZ76^Z@V+Ck`U5m zBQyN+$>LTPlCTnN9Nx|2xe5Y!C%}^ z&^90(4i7@PY1%<19mg{RPwn++v+OFRvSe5v$#A7=EyJpJD`fd;>=1HSqzbDu$tYXx zRT^QMr!MD!Z#_3`Y3z|-aW#nQqjiBv%`p$Neo~8FrPB%tR_SbsnVMlEp8vSa8M{9D zDAI-{IwP&MoC%-e*c4;)<)0g>1NF5XJe#Bx!DsZ8GqXK!55ol=k*uU8??P?Q;AmYS zDi;v%>``bM+#o4Foa zflWaO9w_iVylR%L;W6cmiJoyM7~qn3?t`3E4}cR%Pbc#D~hN62TP-{vS~B!2w9(CWX#2TJ-OEJ+VFN!BAbfQ!)NfwtEF)jK?`uJ%2Yd^ zL}O)a;ngy43<7HVQoaUIsYAt~d17s%H(I6XK2nSdO10M1l~K`<1gkT35>aO>gd?pP|#&Sa;%)1c8<}*sB`n zgilw!JdshX?i znM2cct4LeHT_V0Gj+41_DGl6NT<6t1b4#E5SeWF<>!6v-P2qeMi5Lp~`>G*Dm%0m>{&vld+Nh$NEXD$-Ko zgRutI!J&;Gn1bL`%UVLkpYX@d1W@%!11J%NLWBJRHfhaPKSf#1c{r=*gEm)#Al)rr z0C&b|R@msND=BKOXrjm2mv@_DVLv#@FjRkOvLiJvd^y(g(446MXjFL-ZJLmNdPm`KW2b+^C-E+6twcL(4Z= zA{!vJtdvbR@B6(%#i+0!q_8}PJ7ozS$<`zcJ#(cSms!>K&7gEDJb zK9PCmoARcrEow|#ofeN1^25_G4Y3Pr`#BmVkt=0E3AF^|d}TrDiugeh>c$`kKflX9 z@yV6}-}!Y~sMlKQmlon;cf0Rf&B1l%va7ZYcL<(g#HF5{0`=1rqr|1ERqoGeDphG7 zvW{!kFlT;+XGU+ol-r|F$liZdUqBI`7DCqB(SVMxd~@X?GiQt+&xL$a`0q)6g0%b| z=gn@bcf{Qyt-?lI1M2reBmi@=Oc@UQBItMYoPIqV!nkEFm{ksVju_vi1O(81) z^$aKGcc7JyCSHwII|K(>F+#B81UHHU!FU**62E_(F*M*<5cwqae|%RY?ZkzI?!;z_ zNERTfMdo}A2iifQo=;J=K8$QDv*H zz`^Y43jukf_{BtzG$!wjsSHNE1n7M7oPWQCH|P7_Vb|z8UZwamA_oJ=1&JH_diAjq$3MnD zX1a4^kWVS=BZyWZ3-Qzbdpl}_k8|D4@nqWnhQjz!^2Jy9(gfa?{>N3_&+QQ7ZGcQR zCT*-7BCU#LB)LGfQG`o*M0q^AW?Hr2n^CL5VyD?~ID^{DIo~#6=;Fd>8r+|9~!hWX+b1V{zP_T6?37^Xr5Fg2T4NdpFVswoUUJLjZ|agsi?-N3Z%wwoR`z zeME?HWVJ08+uEI>*g67G78Mrj?=b9SEjau|J*v1=n=A&KUJI-g_3-zWFKFZdFy^wg z4y7FFIJZTUD^9Bhuai()K{&SnAcLJOr*G*r@nvakfxIrlxNw@!KxP{?LWzchJv3~p*FBFzef>adj>HHgj{%P>I{Rnm0(vI=f zHqc!OqE;GEKP!`(;9{}ax^Ew%aqBJRgpzdDdw*yH7POkJ_T61~ro_AU6#kxjj{IEz zdq4WgT-}Mc7x3nY&063U(9^!@C4cymX_@gXABtZb(%R_?#ue_0ahWI3Dw}C)1+M-}An{ zZNFosu>>l|)0YQD#8on_i`M|R#?~OzQ)0EYhajqzv>f_^E}W#+ftozhBzJVreg z2C}!kS2Ob}`paLJwiuE})!g5$L{cl69QSK@tudn2miZ1(o(@H9F$mD-aX5B-#5sj< zzow=xA+r(c*uH5D!y&G_72>RZ{h`@ye|=_zwR!*2Uz@Yr~be z)#_+Sv(4=86tVe2cVd;t+qyxXj`;R=g7 zqplGpi1^{0S&toCHCuIGqkQN2wAeMUWkOq*=yZLpQvJdRr!T)fsFT6-r|H*N#5gId z?G%24iTmI4CUy!2@;`i68l2Nb_jI|Su52()rXj3eu9~_xb9VOr^yk2n#=S-r_UzN7 z$_9?=Od;Kr29LpX-BtXnnCY+OS7(UBS84ug$Hp|nA690;^iWRj^Ci>u7ictj{ zmGAYE?_1)jy5q@Z`1GDDiyi6fmI(=NlKVMZ+uppKNhJ^2XB0y`?}-yND6?n(SbK~8 zj%W^v?hfOdb>tCN$e)t$~@59A2A#-)oX;}Z=ZXmtIAKf;vKZzaO!($%BgFpo7FN{ z7og|~Ic$IZN%SnJ$&35}%T_&CB;t=3TFuj0Z?e8NU>Ld0yB57$jH=w%+G6?4Ahy2^qwRJJ|cMe29mN1~!N}(A#@r>I>*TGj2 z4P0xBXH;?#Ccl-+Za& z;1V)ZE>XHOY-$%t4(+)}(DHg>NaVaDD}|dE`{UgnQwQC+`=U32^GO8m~25i zDza|kB-tm1gX#x1V(xmRHIOhoj)TkcSCnCx#4+)r6N1#vFAQ)a@HCEiH}S^mk=tQ& zcPUrj_h2#=Ww)QxwPKqY8cIF(VEf*K3$gL%#GsyL8gBH~H|-;m((1 z5e;9Dw^0`iID^)#lZpi0jdmQppFdz}MZL!!-uIO~V3fk0_{V6<%sSK7;;rR->kq<@ zEV+1Ng}dIzcyZTSI#o37c8c4Skz>TK=O`feB=1r7=O9^UZ1Ow-|Z4Sf|9>Ko9p?svPof9%)f zNSREBy^Mvl-G$MHPkBfv+)Mb8?Q8iXDvW&#@jdm8o^%>dJ$d=cE6cZVF~|)2Ske3` z_jq_;hHw-CSH9}^SF23$s7ach-CaJNSBw>FeiK0$caOf8?bvsQ915|-6HqjNDb8G` z#zDhYxQs!80|e)98OdLJ!7DV0W8#yO<)@T)2Yc4^T|q<cp)Key<=p*zIEpAM=gEixiO_5f*GsnyTm};wxj`IKt+cz}Gl)48 zkiRi*@+EgEH+vEwm*ly$TbHB8CE3xUG0vA|9QH#v+|?m>RsSS6qGh!IHd8Y3YZwC3 z=A{(T5OdvKy2urthQSNhVUCE;6IzKBs+FG)L1w7?PxKmuPBP-$B>7igvnr?YvI!wj z*E=zpz0r+o9LM~l6S>2>r-ZR-RFJK3%k~msw_=W~|DmaO!6z=M# z-Rd<>Q(;IkXEI4s)z>d^YGUHRN{j~I!;Hj{Zm#g+Lrwy_@3SjJHi@ByL+%snH2M=} z!;qW9I@UK`XZZL@^%z!h2!#4^`;D^6$Tv z6r7;zzry=>e^Ws{OJJ-3-Cx&+0ajRlk{$Qp39{u0?1nCCYNWx}H2;i1~OZ;J^ z!JmVAX*%)`4Eh%v`=>p8DTDvdZNC5d zc^tywKv(@B!R3i_iq}n#zs~h_)mm28bh4()UO8m)$gcn%jtT9z!H{L}YIV5bx{!X& zl?)})^2fC5l4tA!K+Xn83}88LNgFU1(!Y42A<|!l%I;q9ZeTs!wUlcnawAT=A+>}a zd?|SN_d@}>$@}|<`;+fue0ehyQ53f4~v`ZUeHZjYM7s339CWe|{yLzt5bz z^}U1>(sJ7};?uIt{&vEYvRDkTYi7VRO$otl##`A4fuv0v?TC;%_bm5W(d21P5?y5HWtEw1gz>Xca_T=W*)g4x-j27v`^ zDz`_Ml5WIeYJa4*HoJLsHdfxyclJ?u4H%r)()XG~od^VV5PYUKDRloaPM1Cj2U}tm zzm}uY3to~lw5HpP*^;c22%Sfbw;lKcN67NX2a-aj@082n4S{Uy(%l^N*$o`Y*dYp> zi~5m^kWRVDG%NYC{_st@5;HW-t`*c+)ZK%f3E*-5$qims2JqIw3=ajxwXZKaZdZ=v z(Ds%{yao)H+hsoC+qXQy167(DBnHn&Jl?@20T>oW5E&vFj-NK7aPZ-7v=HyQ*v9Cx&>QQzXK|J-Y@dbfRIQjKDLkJn(&iwTD{pl@;vjE%c z)RC5l5MnqU9|VFCl;5*kTw^11x3X+`STLN6pxAN`w-;^!6LH;QYQx*(+MsjrYW=}4 zF+XVN16(u!Qx$U3eAg^@yS0L#X5rQmN1QQp@F`7l7pl?VQhFQv8Z_dSiqQpi9p>!( zu38d0I`bBcz&M_P;G+ruOJG}_$=yAZ{u%6=s^Z8mwDSKV; z6=;;|^nTzw=NQJ@i9&^JRKkUNMYHqIScKxqVUWi%t=Tsp7(GbyG{w29-$fmpVnK>G zb8B^;t0AQF!1jTp4G^qvq`WbOP9iY!FGMKV3R2?w6REouY9?BQzgQrmm{DNOMqn`z zTQ&*O^9kZ>cy968oZ%c1o+sXkhlEpm_-qN^i?K%p`6Q&S3m$;42=7Z`Z7-JkfiOgO{a+>b1d*&Lds0D9Ho-jv5G$xNFwC#3NEw7H%$J}j5ODp(2IgLsDF zadFk-a1Ld6c=s+X2ir={CBBH8X?aW$&jli|d~|Vb{o$%TS)tLpH*=srQ4bZHbGwNX zx7Go<>xuz4iBvS5t#}63YmzW{mX+(HL1%Gsm>-w|KWK2cyE|PaYsNQv?&~HFdZuOW zpd0K~J4s($w~ngu)orW|avx>zTnVe|5_6;6r{Yo@Vrbbx59}NN2reIZ@BB?YyTn52 zN#H5HxG7if@vgT@?-5E%w}`r0m?wtpxLb&ue70RnDXh(^`6nDkr;TCEjjb&uV|CW@ zRux(qBu1h9W4A_bHwR8I9tjcM<=u`{`zw9Kkw%UjuoGJVF~FJsNrWz221 z-JmJXX)|av+S*LNz>kcBfFNgXvH~Ys`%>x3*-CP@E8M`R?I^D9*awLA;bvjYM`CvG z=KJ8y+Jl(@QDL`+^96e6rK8vCmjOlGnq*Ncae~4V3wTU^XS+c2G%^ExMl@(OB-K2jdIAX|KVxpkPpK66miSk`-G5F zaNU#L{mJKU%OZ#VY7DC4pk5z4xBi%F^F^UCSP6+ZbDAj}<9)muL0?`IZHW_)56AGS zvz0w#K}88Rl_GUWO|wk3K^y+)!opkV7#TWV`fAEnV(tli5Haiw@#iM_vHSIzTn<6R zA39k)mb)i%#^7pqw65gR{f$z(rbK!L9y(kKzqG9%7SiZL|yc5@MmuktJhG`VYe zsCNs{WO~+PYVuyJXyrVq9QDRayn=`|Z{$4<<#q36_G%xDO=-t6gy&YXCsRMAN_eIX zBBigEOa}R&tr>&$#^ZXbLaW9P$sSfkKpM=yc~Gi~14w#A+uIe9fmza!VEMz@L{6}x zF1+vf!!Q2H@$DEpNTmZAM18mF<;F6mF(UQ>vTYGR((LG1Bff+X`eP*ueC2}0)eg}J zcH}pA2aDG-;##h(Y$r71eF;`&Ewf9;gA85@uUblJkwQ)% zZv8XFKp08nm64?CH%{)IF(}T7s^Z+weJ>GmTA3?CFHP~9(iV5z%?Ud?YLChx?=N#B zMILKjp`iDKx~y%JQFe8%gerN9(m>%y`L)~#!q3iPb8l{kP-vl5ceP&;y2~M6cN5|z z?lo>mBF7YaCa*eo#IP(99_x1Ar}7)z9_70S6ih5=hb`_~qciaJ5fr2MkPD)|5t;IM zUOHG?P9nAt^}TqQ(nq5Vi5GTwp6uYC-Y2;_-mUrk&&`Jp$xzp*!xG)Z`k7t3%;zhu zappXG`X_j$49~-DejHq1%B}0v;VrasiseBE_g+j~LEq5uMx>#d)W7pK>m1aXYi6z` z2k7FD`}Q-fqWVbWd)=7^EGOHjsJlzuiK{_T2*owjz_k>gN@T;o11XYc#SFYgCM!vYVhuQjx{?(E&C;!ZI(CMTgPnY+m;lbnk)2E5UpcSho3wk-}zuYOT zQg52GC1x0J6;H%Tn0c60)$*PmdNd|K-}nT5qRC(8d7X6pUX(4u)YLm);@#-x1{IQ_ z;oEC-MdspE&a2YrN^%Xy>u;6)p(lM+TZ8>mSdab70E4~LPQHuU*jmCD?&&YFI`=_r zajj>7+#oC`xtY3A6oi$Q-&3kDU&cswxiWQ@t`T_(A9QIl?$#WQV6s|-<4O^mn$iv? zk4e35tC{(tg+#vPm#}W%#UThwH$y+xpsX$t^Ugs|GJ?EHH)3s@NU|s4nW5kM?iFMc z=;V9!_VpfgcO`$O(^;>f2U-m05|Xh6*nV{RLWdnmr0#G5Ck48~zUGSPa+TqT7Vt%) zzNCba&|>=O17eG5tALG@JrnHwr>n7=Y0@!7?R@WYEe#1`bv~o*70K<9sk5+H_2D5G zWc`Tw`Q*WHp~XGW!(m)4WTG=Pi=bS$#Z~OZ;wxvWp2AG_pv~B$=Oa>xOkS|S3!tQi zuOBTvpenb@?D8t;OGApzE_&bP(d{ItC}+lh_;nu}dl#Z^=W zvbaGpv%V%5lAGio*DuPW$vthI*)?$>i*#(=6WR8x>;Q0=_h-Jp5KwK4R<`BUvUJ@@lYehhYiKr9Kw^41p7fB%# z!puV%xLdwRxo&#_DgB9wa_jPq_-+{dyS872Zf`^Qw$KOTohRZ<5-;Yb2n5}(3^uCP zZkOjw?iO!72OG7jk;p3`uQ$P-M@TiNYHF$enei#3_V(ue$2CHiZ^LmiGWRk-SX-xZ zU&qiZkRPgiqnVA?vikJ&N- zEh;a$zZ2~A>OIv;DayEeilJ{aGg9M+BGnaCqv5yFPxrLcLrO4kpRW*p z4j4+v9fA*gjwvG2KN=_??n|i%Dqk!-)0}XEeh{bBxQ8C&ob64Q->pbrWsIW*OjcW` zv{=|9K5CzQSd}63P>8hd!=li)+K|x%@koP%1}{JUT;XyAw$Cdf9X`%fbQ_?boyU#C zMjN8Sh!}IIV9w{_r)fO#U;1B~rXDY|>uDmXlq&{j-4;cORooW2j--n@JSW{i3l68< zfMBV}W2P+ujmq!i5ww`=hg`AHPB0?NmFEvOv7b8)#?N(g?%HO-Yd9YnqH6JY6(38N z%|zmLX9(`jhHd#8@?}zZG`x~lJ(1e7%BQ9rg~y#2wnZWMEQCV-{Z}?9KzaFwX;@QN z=tjlS+7~nzXpqrm#|h@a>!~K_4tjLNb-2m71}+;R$>z%;W1MGU^*=qdXG$l+0R2AC z>vgM|_Oq)Y(o(lhdl0@e{i)knI3zJ?4Gu)OppUSWK7-(Mpw9h>$M10jl$XCr zDLGq>{a{>aoef&&FVNpWE8vfq{f;A`=m_E-hTZv7Eel`6A2gz8m3+`G3$-n(V2{W+ zF_|MLbs-;6DCx6|4?2p$&2|DM14w9aaEY}cO$%q~JuN~WgD0X1v2Iv>!w(yx+lrVJQ8Ep`UU zu7q3Qsoz^ZctDJH5AGMftrfEB0PU@)9Gt(1xR7C*2cGqTM9?CN?C% ztUTJCz-S{M1YkA$75~P78ElrJDZ%(y#{vg7Kso6W4%BNV8UGP4QEO1`0lFG25IP%g^mGrOZdI51QSt?2Aa{C;^) z5cgMhyW+h(n`+xq$(u0wM|f#Q=Kfq*snF@+g4H;h#JI`gGcPO6yY`%Zswp(PW6@d- zcb352cV?5!AGz%Y(+lH_n(C^_4Y){fpLT^8)o;!BXf~4pur75gRvxJh@?f0E&3w<} z0deT-iwJpPq&CebSMSBWVjJcc2$AOB??3g6*`o>GBi-?qn49`igxk+e@_18cTq`~K zIPUqFLJNFc;iQ554VjSWDys~9D(SCNVbyzCAmjN_R)N8gZeKEXKf{kHXO1jUoM zG1lt>6QV}X@oUWTA`FPE0f)55o4Sq$GMzAt!v8{&MoARGnE-#4vj{XoGs(7obRarcgv=lEB|^R_YGFE_ z1>A6xFaIGQFwvq3s)+Rv`L$oY-e4eQysW(-i_S_sQ>FDm_I@pv24G5zF52IE!o@oh zi|)QBFZ-hy-I&%{u%~%3Ymv3v7!b|hvs2I)--HzYSQW^i*s`ne*FuJOJ zxBM(5b|Cw%Vf=(K1$Pv_+fyNgOh5;0x5Z$){X8mr<7_Q(Sie<#<865((MuHmdOVm3 zIc)$3ltupre+k#T8#r0M9IE3;WyelAPvrADH=L^yNQ5?=EQau^^+TFYbw827^#`Sz z(EW&i%nO)OL+Q{oJ0$V~?Nebn8i5Fp)3Ny@(vaPwF18%mMrH#@M^`fbs8rNeG}iv1 zUpZ^F&sZ!6j3*nsra3vB18Cxs_3lTjdfaJHCaNI2i3JNqLO$9HGF-OZoy2^)9i(C% z0V#6>a8u;8ZW@?A;uk{BGYIdx*GPu09lzznl}(rdr6ce>akd`2pZeoq8-NYf=R>tm znRK959p2Q8>265mN3)!r40ZNjRu9HFmLPpB6XT+`>LG+zzd+%ZGO`)P(Iy z^{%XZds-2&&fo94a%rPn6k?KN6^gpWV|N=J3%^fDCk?L^Bic&ejK0Bl77V2OT;UIc zf}OE%&6OebP$=t+SZG)CD16X$V0of!7vPfQ4K87+UDV za6+Dc!1i>qMTr9rf^GY|x3vaMMeLur;4FJ&x;^&IPr%h{!Vtb{8!N}6eC~+C@~)Lh zDdM2rZnKV1)7#;!jxL{~m{azZ2DT;d3XIve z-x(sN2G>$6$!T4TB51(7gTv|!pdy<4Gar=;9u8zSAh1~O7HM>dzV~V?T`QhWa_p3O z|7cI!S$l~=LJ3Xc^ofx`2T&%!RF5#3EqL9Z`*;~bIMema)3bolC(=o_Q|o1;%QRNv)O9La?c zImPk)aRer%cys>Tw8Q=7bFn!*kK@xV^G3v^vE+Q7wRZ)Vd;MNK>k6-zyvLq#?;j_9 zf5Wu4UdWci4R|qK;-DpI^S2i;?0eM3Q7){A-l#0xfT4}5wPZ{H>jcwb$*p$xR6L@y zw(1>N0U7pk{qqAlC||bgriuGp^gdHgvA@^%17}ln2t4|KfjuW`*z{ zP668kVb=YVMF6ER|Dl%t<_!Ke|38U=f3Pb+&@uOyVC6py6dYXR@2`Tk;tU~-WdXVB!)t6&s)(U4VKeY;IjAT z*#_4maO*1O8U1}YxCbx-$dh!*`!C%PUQFMB={=ai{9s`IItuQu&x1*6hH4C*#6bNb zXj|wDq9-w(u3t7LgE>?OML8>IH3L@vuLI~(r~}@oW3t|9w<6E8mzZyH1YD^Dvzw_F z3vb2)n3eHhVRZ)MGFZG~MB2;-J(1L~QVt^ro_5T+X=wgK1i+W@S`FO)4vGPy^whGv zk)rEV{iX(LU1pb%#Iz1XMrDyQ+Z2NcTs&sm?Jtd`D<8fX(5YOhee&rM96wMA{Vy*I zaS#MW7p9wIwe}{?!S`7@d@+#>JGKYu@Qu2!BSPb%5f6TyC8TQf{^Z+`g;1?gBb>x& zk+ad&xw@P;loHd=+^M~)w6=IGC+@4A0OGc38k`K;-2hp1x6XqjLHS?pl(gWoqJiOBWhLD0HY#KN|5x2thDEjhYY(E1G>V`oBPk_HcOxk! zEe%Rbcc+K}BdH7sNVlLg2y8$>kZzAlYRs;+UZCw_VV z?mL{Y*YwzD4Kd`oWIAJ?ghYBYhy)z@2rN=3AtR1xVU0H$a(+0UY3F?sNTe3+YI zeSaTcbA0h<4+-02d3#eS?P1WLu)06Ep6=WYw{B_IHQH4o z9NPFClw$O1>}Hyan4Q-95Glk65rd7}VJOyZcab3kk)%4elGfg{PqcQ_^9kJ?H_dKP zQNtH^TNP*>T=Cr>y!3p?XC+fUMu0(1=QPZl@{bz>d_DtX@ID?2*%;MO?@_|2>5q-- z3|MfPFYSAXy~VpGoXuAYj-jBo9nw%RvWECR_-@m#9Nqvzm^b3@@1{fp$z{x1{p9tN z+xJlh1KmClg)JSPR#XvuV2Bo_1IVteVUE16tt;Q#8IWSz{UaqselrU-_lzbScluef z{pm;IO@`?inyUlS+8=RS&a&LuE zUcPj|T=D`A^Zsw!$Y~LhZs?4yns@+sl1~I610H#8Zv4ipx0)C7frRahmjoRjH)2k6_s&s?s1i68c}}c zQ>a#{gr|_+m?XCguBY1(5J*tB+ZMr@Do3NL;O*%Uvi|ABZw;0Rw&bP@R z_C^*QQGal?nd-ct*8Av5-gPZx7PsZAfsD$bE4l+qtyFA{rBkE#=TX1q~HTg#I<>{u^X%SvWVWW4?3sTaPuqEkT z(zX25)2d9rn8YX(o8oA1wRWwaa?LE)a-~>2KcJ?FX_uUZ_f7(-T3JS0kL!EKsJ;tY zEPW3n3T(Dx?>*DER811XG=B>!hryDUz#NrP>HR@|G<8wk)_9DVuXjJUR1U5=Qa0ff zrfILH9#bQZ?Gqm_wLY0VKFL52q|le)43nyk=0~B|TJ`mVUp?uM649jhtbOW}u4rhM zL@vkVpz<_@mCM;=xlp`wR7TCeaU>PH?xO#aiG2*@(`PvAna}T7Zl|zm9A5688pl2i zm_vT~^~R;5y*!>B&wYdy^Awzlc)3*5k({s6=2|Y==ime;XWfU-WB~qjhy-4m`h%5B zzaaF!?y?`jfGHGifQ8%yBGum0%@NR^f_&@5S!4^)wCbC=7>6bZ;FqVS?xY-QWWC-C zB|=llQu%hHxpu93PPepD>{>25;`}y={=9Yewn8(+UiOExf6FH zRgB~fuFl@SIof>m+)`QCeX;kG|e$AtrN-h^4l;c_i2 zPKxe#71=;&YqzNO&L@?Cv+?;ViK(g-*pI&BJ?dj{kYOfD2C>GxU{grp8N;fVYqO`r z-BhvbV+k&i4LzUtyJN7IlH)HEYFNJZGzIF0-#-iSBj4J6ah!Pcb*BT0U%W_Sn1!ci zWD(p%$h11uP#I6fG9-DkO72e zfgTONLpQ`0gC^iK(T0#t|Cg8#Vi^a|M_x4dj+n$50fZ(hwvcYC@1wgn{u~J^mEt;Y zrWo@sU){}bEC6&YtXxSv%eT43k46&2ytTpmC=1g7B)%p`xgTbSnVMFU=KlyAp*d<( zDMTb{-oPX?OV{||Ew^x6uF1T7P8NccSM4_NXIG;CBk1`VzJhAdlYlNo7opkrSJR2P zLve$vvjg>(~@}~RcrP7P(|Ur zH*NAZ&r4v%psW^(iGS|!zXR}-l}rOP{ebMg{cu6|6Up|IJ2#vph^fU^`280CDhTUN zzDqVMZ6S9XG&J~K0paL`Wt8o?**%o}A|8Fe3>2yZlJ6=YWt|nC#!@xr4e%}VHcF_? z?%O0)2CzU12*}rSi3@xwn8>$tlxVY>lk39ABJWT|w%1-xE#vfuGw=v2&6VtBl<9#F z>WaDrbP-UtxRQpfVCUb|01|va*F5HZ3$$-_psS@9{?F8+v>m6)>XSl=SbwR7{}!8@ zb6Z}$T3FrahB%xdb{~;PH4C&+C`%HMeYc)w96BbZNxgQ2jZ{q;GaA!1mpBqC-<6%>UMZ{YkI^EuSEj6D6Bz=MZ}HE<^Y=1W?XC{ zsSXvo^qymO3cw^2l%3|egOL%dK^^{3isn5nAB&~MA2#rq#uLrjyvz}xDm+Y@Y9ECm zsCEJXn0F!IH-V6>7j=TKdVVKP4-f-?-XV0J+p?1|h2gtT`GZmUw6>l;*=NF>Jk^_p z!K~CGp54fS!u%*w?Y^Msw=h^We0Np%R~8INDdf4uy$9jq+xxbLrF5lyDpf1Zm5n(o z+ZDawp6&wkKG7^ngF>m3os1ZEI|rWi*3NTG?ZMP_M07P!+UEE_J zAOY0QJCcNlCRwJj1d~6&`>p<^QAc)OEcD|#pWH&=o?8ElqBrGlFT<)&|Km;80xy0} zMo(=wJlB>chtvzWyQ<#o{7AR#IB3RFQ~ABN8AU{b+?B%x(vu(|xiR@dy%{HJr6FhP zxe4i#dsY3LtJ#3}95L$t;?wg>`ccK|UleQxP?vz_`Z(x-AfSctg`4Xk*K`5t5P0o5 zr$;XgZla}?qs7JsNoI4LzvA?KWzFrZ^?M-L=s^rK4EnuGjQu!IcLLkNtEhzn1N7!F z=J=4+=W?uj_~c0r*(fZ{`d;sP`4bO`cCsFP{odl% z>=fHmu%z&Ryvb)U`7{`&a`YqL!f)E&At3&6)JSOpXG1XSsT0t97TDONGnRWvk6UhUVB$f=n*3bua@#MJgj>aK0)dERyNjvz1E!idskfp} z4tFQcJJCz-WY1QI)_s_x_2dwd2x0elLpoQ|gG<`9cJ5D@UD{RJaTIDUYq!kntJ`Ub zH;z%k7AVFlEPp{byPcs)(L&~26t!sn1t_kJat@H>R~Ztd!358zehm`!yM3=$n8t<7 zK}y^&G$)_gS{n7h{XTgw2~U|&9u;FBdlXLK+a^CBZGiKG$~0sLRFRzKK$m7^ZwYca zXqJ@Y1WjR;iQ?x#Oa|VDJu@x<2s+MjBW&4aJuwRE%Q?9B71kur0a8N6EFTKBEW{<( z`y`gD`2oaF#*^uNZ;#4H*Xf>xRTKYSKi3>wx}^6@4((tMq444jWNi8(h@Z?^3)1;6 zfgYX0vG%1|ePr?LO=5XTCV#Gp@nOybDat7X>7?D>n8x?%H|n)Noub3#P_-&lQ~O zjlwi=Ipg#jJYKx-G`fSdV1f1xzn27L#z4D6@x%hC!#{@Ot+8L$?f{Q~GsDY$1t_Oi zdHtBn$!||iZ|4*~Z<+)QR$|=1M$GxVEV>$m?1Bj}S*B-T3;4e`4#M7Ed3EyH`^576 z->HY5HQ;dUJ5DA;*zRAIH7f&XGl_}iZ>(daiIH`ZXJL#)=+P1g7XGVt7jg1h4LFqI z;L;NTfi2yV<`t5O!&4kAPJjHZ&wHHp^!Ml5QMNFg_}EH^E(p>6tGvf^3op8hVKWk^dHwr2-I<-P4^k<=_PBi~_MY6jRy8Ki>lfXYN&Htazaea@=#l__eHZb{i z7;)9w6TYcGyyt5bcZmtFdBi86l0pj@FoQ8jE3!YW+akbSRMcZvIekal%HOHnKlW1-h zN-YT>Rt4Ri|2$4sA-G&?>^k0SO$218Q*XsVR`x#+3E3(nuEnTC`lwnBy3)|`|L4I| z0w`pYfOrl`(j}pv*WuqQ$KeFwkbNC?gI-M>WQR1-ix0bWTOKVA)@HL;iP$^=l%s!q zOcHvmz+a z${*DPb5uh*CFG!#N#!vH0H&ino(#F~etexa2omsVx*I)mOUQ-`^f9C#A|ip@7f#cQ z6w$4Z-J^UVOplK?(0=s?U*O3kt0aAU%8@}qI7C2F;Nq;ub3M*uJQs;_hsk8$MmH;i zq}Vx9t(T4x)tVX_0pGO}8~BrbSAA+oAkrt}v15aaYVy-OlEl>R z$DBTZ@KH@o$LjSD<5I_|Z{NOwWFY#{!Bk7BFyPs6%TK?V}w2RA`K6kGm+O%@TEptc#7zc)nLFWQu zTm(}jHFJ+~)l+}@^UuQcYqFCnQD`r;&RbTP!~oi8>kYMd;l^; zp$U*F+>^Z1-1QBp!m*aocm*tZQL34&t*(pj+Q**6aXmOJm1ml_LPQ-Z^I$NoX=rI5AR;v! z*s4>({QO%zN6T=~IfaJHoJiD?+}mHz>Kjwx*{JFs1P&0u^Jfv>>K#ahYm!`GJp4xy zW-+LjSZUDg%8LKYUwvg^^#_*qD#BSi--h5u?w`PAAtD#1$;OHwj{}k$k{v4F9#_!K<5HH9cQ;W=iZ7NuqpSmM^w6qsT(_CU1fKv|bo~xYi_{DVB|l@D-}Q6y(|D zcs_ZdcX_dzmy1%a3|(QoKFZzo#e!VaQkq*c>zOa$__Ug=F8k5OZLXA;D|A3P>w{{& zUlPre$syPoYIonfF}YCwc4EVMH+zi%Qf*z4gU|Fr6m`f}G2sr{wiG4E0d!`J;WjFo z!rr+3IxY}oy)iqm-#*0a6IStR%rtb1zmAw*!qc$qB7PmG1fS^yEs15MC^TIjsfBpX ziHPK^hNf|o-6DFbPQfH(K;GA0f1thQBo7ahJDQq}8}%2QM-A0gW4;NSs$~HJ5vOmf zmLvsLyNkzrCAHKqf+NH$-3@sRg4i6l)$*^CV-N7HQHyWh3`Iw2e9Qdn-u{8LLVnf} z_;U%p-foHuVRKUb(#(naJO-{ta~JnY_(G4KoAphQ+d8gWUOG4x)hwc$ z|4oilzoBT#lcKyTZbLMzNx|aPqihF_fw9;{oxk$7hw8sHuOu?NM4z|=LlBX-3vYig z64<<|Q$+W+YVHaa?+_|GxQc$tgmJV&L1Uj9(2JnFM=5-!51CTG)S0b;;RKkI+xo9g zcb#vg{epuM;_V9*m^v8O_8@F_mS|q6LmP5|1~?3+sRVcvseKo(rgm&BM|n^O9F;(8 z1KiVoum15x3hY3a4QIv^Dqz0?uq5mO)`0Nh%wJOhALP)odNyg@{D(#U1ks8@G<5ih zg?iqv9?7cBP?^iJ3LaaL$msD^Fn7M_RGiN@@LIaiVOx0|(_>K!FacZVtZ!G-y6)m}3tuEYx~LrS z1&0MKR#5c~v$HY;O{O`mZO<3_b1VX#*u1ndkA{K~HH=XJh9BdP>2e4o{w%Y*TDy|X zK1@glpV>&Qh}$1rPd0w>VY8_r#Iz@@3**XTkh~Hw-9+Q1c7)5W1n!gmS++Mf7XveV z%4tSg+SUAHDRXBIxm$?hDCe`gz8szkK=ZwPF;nRORitf2M6>j+wG6qfd4J*c!s9s# zz7o@%_SX4rwh?V&asGUiyD86tqa%H|pzfKv(V55-YtxT&e$-fm%AXgt<+ck=^~plp z7}x^&T>#F9Xea>9gZVIxhNUrPW+8%}GOH>1s;ax-20G%^P}0<<48W|94XAp1Trco- z^--V&!#AJC!+5hh>+X-b2=X5R65c&9pBi=a?ft_KeYAe7^F>D{T@7+Zeu^Qh`vb-1 z$rWCzK!WU>qFiix$|6(hQ3bj2i?eMptGefK)nY#Fqju@dnwKaTZVVD}XXZE?@tRYR zY7uKWA5j=)|6B*A0!5o^JaPno!raQ+G|>o^5wh~4IV-`V z38@1_LJ}`d`taiYOyAukJ`%|J{{ZIJcR%XYmU5XzOE)@Xtupu|m3aX&1!zbod`jn< zuE&OTI>}iCgmx*wzKb^(3b!@<&IR~P_M5+w%_1)((CZS*kB>7-4uRqPM2=vQE;S!B z08+bEe(MHQIr(~wYO{B*&!_O)=d=rmmrOZ2 z5didrF->%eC^ch^W9@VtOLPPG-Ovw@Qwxv-yLW`H z0a-)4lpe0EqWo5-Ux65xDbG?Mm5AqEl%Jnp>tweENJuHmw4A{ZXPs+D0`FUz2BH2g zP+4eC64q(Svz0jr*A%zrm%+*r;h3B{F&??ZPt-<9obAWcB|9f$@6lNI(Uwvn6Uby= zBGj7G*3T3=Nyrk&?%3vtw>|;`PW+)i4+)?pq$7`~sUbN!AY*}Nuwrh%U(giqWA4;Z z^Gpmuu6CXYAdzQYW@;-n8HRUxZIp-Zs##Fx-dN^P76`!hJ2?d=QO;Yc45Mp$=+)P}OEabxnLo3{_p+WgE#pc;eI5&HaXg-D`mh~OKTEsGmY|;f_InoctN5t*Z_|2| z6H2NCr)KE&O+^Ss$J#C$5L(3SoAC_XEf1CJEAg^8V2M#W33n;rGv(t&a+8Y2{vT`G zSfwXT)XM5Bj|Fx3h})w92_H!2Wfjcz)WI2X1Vupi0vpyOFh0d~Q*Kz6WHQ8UcxWiw z2Fx6lC~d!K|GfD*@dB*$q*w#EFIKQqd2Tg*yZ%%F98vd}stO>VBvF@gM(^P#rVAL6b$Razq(LY&x&kK^~J)-vD$u-p$N)B;KSnwFukg zC3N9Gt;NO*<*3lU5K(esw)FVxr>;Jq;qS@GCN7*xgMCW zs%9$nO@VL)sRxhn4a)@(XO~xNg&3K z%_swKV&zBfH# z)Zu$Rij&s5@bLw1`SkpRo1xJt%hgPqLFoa)<&Ru_i2|CEGDrQ*RmI8$;WIvinp(Ot zgC%+UkJWhwh zySGcsvgED!X4A|0s?-%Xp4EZUG{K4=n;~hAB5T>Oe!Nfg&ZQ6F%5|yT5P#I@MlN%e z+V<$m_~XvRVm;lm_N)B1Yk)IN%8!_k@S*^3^i9nt38VOC#A*{bQEhCt={FvzBL)EK zq5pKRsGLTGSxUNW_$JfO$YhoH3BN#d0mro~&JrKNIY~b3G2j-KYLaqe6ORFu+^UM+ z{R3NzeOmqCp7lD0or5V|hC-O?7912GAS+I1Z|dMdO!zpMsUENNKXlFRMAvUDJiHJ6 z{a24g+#_Ec*qaNCjW|(r2Jcx339tDseh#WA2h0SG4Wrc5-ok8loktQmw@Yb9KeH?QamX}L_EDG-ZBbonZXQKrs zK%;J-W(AI8MQ{>hEh*$cS$svnJ^+L*|4==hB$U2Z380Mw^{axrDP*$cxOB2cz6%Eg zs$v#;g=S0PWb;K|(;iFO9jA>Uog|Qi_SNWMK{-{gube_t%V^&N*jf+{Eax?zvqZ)V z|07oF%WTzaBY@I)b8!9IA~;P=`Xzr5%WiTarhFgQwNY$1G&;sj`R9Q!_4 zIu85TVM|nQ6JHat5___`cDI-M(p_NBZSVAyNWp%2G=MdEes28SE}tRjI4Ll8;zUW2 zNgph?7*_#?++y)=vuHaQo`Xih)=9zvR6OuCpW@zEWnEofRvabT@gyd%a;0F^N?NZR zE@z$&JoiI;6WxImNCBnI7MoyKNP62^o;obW9pA|CoXwY9C*&*WOZ}>oRzP5BWVMY)^K*84C0M4p?VI$mq zc!Fr4CkTxAAmgT=xd33y<0s8pb;UjDslVa_?kcLtZPZfAs@4aEBk3R_P>7y};!Q;<=S Jek)}X{9lE;_^z`2XU6g*?l}f}cc;4T^vV`1%|0gHV90m{CNYA*(9X5* zAvD<$+wv>RFvYCMOz!R87-e~8B2ow<|7#Xur2Hb+^ye2vR^`t_^is&JdiLjAU8Z`G z=UEHIeR*Vbn6mtG_qDXhYvb*S&b-nhMq~P=tq<*Sq_<0|?e{wp~!Qro_3f6L*DFNIrPO-2X^lg^FD3#r=sa{KEA9M=@+T zxAiSM$YLJgCTV6+a8aFQ4yj#Dx<%4$-uLh6*_I)Y?xf zK<=}J>}D>apek(U<#YYOtt9dAmub1&4qmHKYdcY*^X_O#&*#hXMlOm1vM$^`KeWrF zc|j&s)*-iMiJN)BUG8YAMNbQjWrMr|!Wk3s>>A0He$jMHgvs}6GU_zw4YIUQr&?Vb zO(MUEVgs0>88wo! z#e$aLTT%+dt-sCMP@mfBuP>y)Vb>-uQ>e<;b~95^;QQD?p!IR=3;dZ6zO3khM>k7} zWO+11X1un_TA;96T0u-!oeJ9JubI&NzEd;hzU(~`o&G3zNTqrdsHnm`s>qUApdWXp zl2^swA{eBWr0F8hUuhlBYLQzn9?$MaL9$7*^^8i#6_t7`AXu6M0Tm=$40TWh>v-6S zg$`sl%=HyXXg!3Dkr}$Eal3NF>#lsYP9y_RNdDig2?+ zr*#6c+H|4*^k*&vQXW?o;@B(80{^tf@IU?kUG#6>MShNAjT4RI=)P)>WhO&<&+N3Y zDkeJ2-qJAX?YTXk5%6R)a7jq*w^0DI>N;F>&i&_P*|dGrb>+0(^7Cdx7XDkN|3zH&zBB)|9@l_Z(Ui|JQ3$;-PB~Fk2=S&MUSGnCC{FppdFxzPTh)*s+fJ;gc;U$P`B4Rh z!X$!)P}v-(&T*GqSyZ+)Hs7-_3R&eL!`6fHH)NfMntc@|54Z#yjP2l~F>Cu*DgRlm zmfX=HN#kF**mJ9T!;uEVQt7@r)Kmo)zxnY%;(8biN0J~RF@@0TC_xPni-J9I?;wdh z{h*BCNUcat+tI5UsFqrC=b`;33O3ePzZS^g4c>BFf_NE*hq(s26+0C6ROS)nBLKH7--B${e`Nxy=gP0o{-+(qj z`G$!~B{BnRBJCfR1@aM?JyCW};QcU&^m3?%4JAEx{P%pQON@SA$8Mu5nBI(7QMjnXHPPOo~hzdiazABh-G%_}aO;64l_f{o9 zM@5NcTe3JOgkGvAu%QVJ9#z$e(1vJi#jpK1#&uD^mmMP05{i~_g)S4I$byWV6~RT! zOR=RDk%metj5%=$YJP}W-8NhltM&U#hlWi>RXY`!KF7s}K5elExE~X{anzNHv_Nsz zrZn|lA2#>bq&6EmzWf+Zh2+am<7$X<2?`7Bjc5?k2dSmS1)VeASu>RMNwsHy|zm~%6>wmjbN0v2G`@ELZzXYEqc-d?7<@9^U z#uD!rjtg1aZiPlC{_R`4CiQF7xmch4fy?!*jpLr<#jnJm zA;@UTm9%Jmg*lZ_#k4jDSuXmc2#d9#ZON3_pgV9N^30#y+S5(SH2ZRXv0_cc67Un; z47M=XWTdRJ)(ZZ{K6JxH{$X<6kzyaV0&7lRG?waOrkk+P7R1XGyGp|@M3-;V0?86# z8!?Y9Ti{wFt9Ro=FC^1D40w4D5F5!*av7~&mx{i>CV5l=os3IPDD>%pDn`Cm5tAE4t zdGO?~a+clEUO-ok9Ow36Qx*Llo&FcglSuca@?uEmrqKN;@+%Vl%}VIDhp+mo38cWR zusE-|Ki~4lRFU%LEa(E9${oc6@hImb&`SB?jz;`+buUzZST^-5>Q2n=|Fm)~80STh z9a>PC4iU{t&v{u2D{#Zwz;h^+Ex}*uuVsVV<^lnD*~DVO9l3Vv!|jE0rr%%Y_TpJq zZ|i8Nngy;f!EE1tBWO+slnA=+8^^)>SWSf-^63}?u5~@y!ITuaYsFs z@@l4&DL33y*H1V+fExBVR$K#&Ahpl41Ro~RoF!WK z;7H7TxgvYa&P4BEPW!V*?}7h)_4{NDFSr-x5boQBR(IXI9qGjqn?hnppnmHLn&**$_j1&xR#zZ zH=!Ec);4Y9IwczI`H(xRCLCStnT8^?SaC`Ikp;O%nXSgXq|u0j7O-e;ONq@GrC6IV z_K<%rWXCvYq9j@GO~Q@fC~k6dztQ0Fn^A=lQCMqR(ATis{7jiiut?*G; z4{&Dc2uqFc7US~Mkgy=wIzR=a#k|Z2S7yAv30C!?{RyonbQ&%kUwPuT*w#d1YH4($ z2wd@TrS;NAc<557HG1XY_Q@m6RM2TN28RScGA-m+tFKAlaiJVmX%7vjHdYPbV(dj_ zP(#fc392l@E>4d$<^(^x?=NoXTHxNxO?L7papRSN>viMd%_QR1eMaakkd2VR@sbIv z-Kb3JtPO}w?$FB@Du;o!nG6hN3pZs+5=)g5QOl)S%_6BA8iD%U6DobSY_3AN%oLks ze;IEgBK)cGLC87bJUMPyWxK=zAD9K$7)Anx%86kb!xA4VD~5W%ARSco%vmebom{yU zsiL$FB;@$Ov!91<<@eq2R=>LnVc0S7L4J%OC8-u9e)YU4x0xlE1xX@I<*>_L|7xs) zw*Hw|plxrb_;{Vnb>8rMe~W6Q`9oE!5?H8)dn5^vG4C z)W*g{jF$-7V5RX!7jE;;wb>XV4`&Ggf?lP@@oUM{6d#+b#S=*c$MWx*dm+8mZYNBPOX>vt!$Z*pqSWuz(~}O;^>9 zLsI=fEP|m|W>f9%Xt}#O{l|q}UuxpN`ThGmaO~N+c*b~M7`%+0JnQMM#!y;brg3*t zU;4N@E;gB7ElB45bw_kR8dBnKx;nTYOu``Uw9-LmUw^)qVqdd*)3-*|$A@12r~$v* z>+7wkgSBr@2;C(wUhPv+y)K3bzv1*(J+-@2S0)jztdcV=I+y$tFD+g-M1F22?Tk=e zV)|Az0ZmMb4l#F!n4A=t3%5Uaf!%#ecg9b|Z0G(fGnMv=O1kZ|A2cb7YDIw?9qJ<+ z7AvtI$&ER4bj$t8iY6g&R)@ximUNk~e#GA5LdZnxHU-AOGbx}!T)6mF29z|D#v?kx z5N4aPim`Y}0v1T2q8HUNf$|n^vXvBORR3QSy>@~wwXrOkbVzgry7~Et8mM;w4voKCP&c;J;+Ll*7>aJ z@*!5cA6NdP84+1{^SOMQt>09Rj#;+uHC+3eT$S8k15TNHi#gj$>)8{x2bv6oexDE{ zdWJh}f%y5f+lVj@=3=@Rx%*dcbb_ZWl4aRu2Giju14m&GvT_jeF6OybE<#SKdLewV z+J)a`kq8?w3MyurUrzk6&P6pWwlG7v&{SRp_ALbYl@cpZm^bvs&ypVn_rYY9)>GEK zX@O*5L{>xSK6bV%R=;pM#*TIE-ZOyZP=8rBG?$cKW>rz4inQw!4!2X(=;j^@(pJ4o zhhG-TD=Q3HCvvR>TPJ9QL~9>Ys2rOC;Dt$9xd z%e1c07fko7u**z3xjK{~={)V4*pz91OwvhuZ$_hITBiLxx_$MOkMDY6iMZ*r`)u7! z%)<5`ySuxX&)z}{t5O8LwCB-enR(Tm=ay~N?Ap0ln;TYi6$E-VAWPXO1krIZT&WBk zTvG<&8YF^BjdPp%lo^PWxeA0$_u?x!t-aASYX`c z8z;Eg`y8&Bp$NYhcVXBm8*^3)I@RoTU+?;jf2vn#CU-#c!bi>?-2XOR8E;=?7B<_r>~kg_RNb$|qq%dZJPExy3Vx44 zdnQd%^|1donl$$oM-twahJST96d1G8uBCrd8G#f2bQWFfeV_+rUM8xkQ}p`rDr8 zh_=63X}uyrPHk#vzNa=alq;W0@~J(UO>rfgZW+$d?{!vuE-vnDqpSYqm~yn?`LCck zS+ansxd2iFixS<6A^Vc#v`t>~l7Lc2RGm_f1sOHQDex)EFfE&8xN)R1SU2Pz>84`z z$(*n;b3UEyV27upIe|->ES8^Ao1Tszi`%UYQWlBF&EGu?ZE8dn%uVb4D+aJl>OY6;@pea`WdIG}heK9IYTS>jh@-j;ux!!jcLS7aVgTXoymi%P|r z;}}Z}!K{ycU|~#-645C!hPmC05i!}gnSy!RC}@wehuSNh7d1joj89-hYk0u5F> z*?)pWJzvyTO4uK&&kATg3SySm%W7_xw{wk=P`=cdX4GcCkjkf1nDQEN@z1maNz-k$ zhqHfkg%E=np@t8@Z)cun$^>pa16!`!maWcFhQHp&9hRVQZ?GzmEz>v23e+~%P|%g; zg11wS#-@D|#jn&eBrlu{*mx2n(n_B7IW<*Wu&_@N^w;| zPN~j& z>{^XXa5Jk}5m$4Rq9VO?bSgqDZQA(+1}z-Y15pkj$&(&Z%7XELP8vksmyN7S+;wdG~6+kboehSLYw4idMr*b zt3KoOT0h)Hr#1;oDNJP^PV<%?FEpzTT+I%m8Ek?X4fa_XZ3!d%r+M@fHYy0CDOAjN z4n}c=@e^3b#h1^k{*{9C4_X2I=C&1huNI-!wqXadBarPlEXAJ?a;BY-cz{?q=^0~} zD3)J=4=2`1xq^wmt|DCr+|eumry1$(0cb+>_8iNM5eZCmr@zRM5AE!`ruArQYMHCu zoAa2`{|Ev1TJZQAj)r+k>kl@IN>742?RWN`)uYQ(vpsyztXalo6d&EiX;dcjCw$RA zYd$94a3>D(3k8-w`xlsIb(SFS* z5C-Z%LOC}=xtn?7rWFA6)lQG~Z-ZBvQ^_B~<@9yICIvHmW_GMxYqw3`VFW_CQQ%nt6$>n8I3(uEFRX{;yYT zw#B8NXQm6LVK1dvA^*lp7w+HF*W9VA!}o2mWHq>p`+UKVZsdu6r8ObF8EwFZtPc3J zNl~qc?Kz%J67QxGI{%DTBzWT97Eu{ROkaV{QrOgLs_p zR2wH9(DHDa&*5RiKSF0eTSfR}KDBV>=x=b+T&bj3@j~1wJq;jKA`Z8K|DG{JlMI;kSwbUjS=@&bfJrKf4 zs%`s5gr8SQxDbD&E!4!`!PUbhPKtYW*e~(Rg6%gaF@)KPY-#l93w~(g+esef&O=iu z7GS-wA$YAg^QM(5WS}o}&R_R0N*9tgZ24Tt@rTF@@lugnQ$>xu+?_4_}mvX{?G z|4t&?l`U+u{*CaO3{Kp!f0b43LRUer5tk_a?IqjYDK+d|mJ`C^{VV;p=BPD3L-`Eo z>4Jj-N~j#=#*8q#OA+LQkHQ6La4n-+Vgr&q)jr0JyD_xe?2uo53b55Y|GR!QBpJnB zmK-84gRS)j(6TuBW^s9gb=WOPk7!lGPsshPkPQJx9zJL{7cq3kAjCqgex=DGcsY`f zgqO5)y4xL-#*O~EujXT3wyS@W8hzPLicV=iy*_dQ0l;Qw%hY%6`+7Q>7UTBh$pU@H z_31q3t!VvXC{Kx)%f>fAUEC^VI2A4O17zg1D*5o{(@^`{+NM<5&7#4mZ{sFhz4}@C zp4ZNA%ur8iB!u3QnObqf4nvOQH(w5(rqY%C;YI;s365y(!t4M_tvhzcE+HC4Wa81n zYkZonah zoZTO5Y?W#N?^X1YikfMjKhTtP%*HJf8TrnXJ-YH3qFj*?+%5lEXcZg1ReStXS)v%PgpT4#HMZyVl+rQGtg_ko)hLx zy%VjP=zBlbGp_HCTm&iqcpd3$o_l!QFLTD)xDrMiyv$=-1TbwHRHU7kySg=I=R}?J zd%f=_8oc)3>^`c$Fa@T5U1+KF=?q8HS)Uiv^+8_a+1Pr={#kQ#O<1J&3TvtF^%lUw zIROZ`dhu;aZx6=i)%vQk#ioC_@S|tn-gjUrpYnYdQ-~< zZ+f(V$D)KcB8GfB0GS44e<~* z3^6&XBH_5Err=2oGgB;BNk&f{J5zEeoT`82$sY4QQkMYNd8x-t9Qo$9f?^zW%@7X)VH79c~m`W`>HV}a<>UsdiZa1lcz5uCM zvL$k5-zcc+;&ptlwSe?wYp^mHAcb&3YU-TcbCUFNs`SCv+UTY4BULQB`e=Ujp53r` z2}C$QMIL*GG7ZTQ%F8Ulxc1WF&y27T#jpNr;nDtBHw;=}xwRS01FdAWc#jnNjOb2E z`YEyyYg1Opg!4>1(<~%5<`bbKRSlP4<|L0OgqZn97`9MQEX(oD8g{!og!EdG*`g16 z&*eZ0%x?O2>){Asfk&Z_<}!fB#C3O!+4t?NOU6na9wqfekmx5eRvrTytCDt zcmRB2<`4j*S4LJ+jPQ9|EPZUH5_DGxb=3z53hevW4(wlFwb_t6Dpqof3%#GkO^xBz zJI?aEji-A%TAN&tr35C5Lq_Sfs+b98ON)Mz8+9jp4p!CnK+&IdGx{jkN?Zm%6Mto= z=K)GgAd5|qB8kHJ=myJgX)HpPzmw-G>(zwcGVKVV4mvKdbk0h@4fn*-7V&128yXM) z%7h0Es;9bE!*ENL%XU<;{DPn4GnK$6BN89L2DM!L*|fSRi(x8f_HqH^~@C5ATZM{bd4t8fo3vls;y9KX>?j z{{DFgg=zTGMAiKM*{@05$Xq^LG>>k#N4GEy;aiT1(VL!6Z8~@#^3yl{eDm(ze3N_Y zEHHgv?vu_np4G{SGx%*Yrk_taGokx*CYsiTs_IXx7%#7cGB7<8>2!E2SXk?~cj|T< zuU5_$TZ2oR(4Lwd_B%~RzdUxw$eAkqz3auT4-JMA-j;sIy>_$xLj8t9y~V~k8-2lm zdM|83MunR6$L6(cfTkTY!DxjVsm<~5YycZWArFP&qv}VbuzjS2zw5Pg9L(Y=)guU? z_1CC?eYs{N$bvXml2^41JZi8XjXhAXVU|FN5D-oj*=4W9vpKnv1`X|z@Jcka>0dd;_3OblR5T?nzGJZn%9LwtE)gbktn0V zkAlWAfNo!qq42*~cBPW+FV=^0DODc+1W-|J0g@Q5H2Ry|zEv~@R}FiJQQAiE9ksx0B{E-*_h$jT_)Pw#B{8RK~i5d0|@1IN=o0idl3BfAe#Qs101U0;E?g5-|mWkVu z!#%z1&4qT{W>`beFDehc4OZZP=fWW4Gtzuwpfu*iw~$1j8z>a=UBu`i`*Eo7>C@tb zLW^Um92VI~Y}q4L0~jJi16vQQX3325dGeQcb9nb_gG^=7Eq^bfhkKko$9=RT>>*77 z@fVNT03Swj-UQtrmI}BXkzhJAp;p)3-mHoPCxTCfDWQ|HE^u3N%8Z-h(J_WGU1K3W zoaK}n{Llp@73x5u35tJVi;&i|!vDq!Cc8$)DGZ!X8#-Npg-JYkQ z@jo`SU~41d^y^#d1D$}JRa6@7PLqRDN4s_v%Dp7T4*sxLrYy&^C@ z-*k49xmayF9FO!pO<}w$SkAco?j?h%1U~I~>1jP!k{vkIMh$4u~X*xa;%QFqB z%bk(s=L&e<+NNT^U>CKq%Mf+rUJ%#(%}IfgJF9s?mpgTlEa%<(TP1Y^zVAm4_W|Qq zyQw6JI};K;o;XJ~T_0DIGk@7IzePka%GbYHcd3V4o0vfQS~z}XWz6#V2AtUUW5Si z$wdld1)k#(SZx5{73ITzUBF%=Nv#DYjR2Sj_K@s`@Bal5Mk4~A0%1sdhV%V zc74%Zrqw&G^QTRiHGb)f)pv9IAppQ;YFZyL^>|g~>wX2uN$L8y>lwc2AZnAdF4jo( z2xoe)Jz?=vkDjV#3Qeh&0mlQH2gBlCVm?=Aj+Mmj70p&m5zdrVD+{ z=IQJC)3hURdMuH?3iV;D#a1Tt-j*rmqL;7kXAi)sttG#V06b;a#}i(6NTg^u=6+d@ z7`;83Jw(seK%9-dY@D$dy;;{QVyb9tb3~r%>+4%`ePWBuyo<>Q^|25qGknJRFGIH2 zfB2JYCQ2S#4x8AoZNODcs%N^QvYQoa+2Yk%+7cFu-)T_BD&K9pIUA!o3kZ`npJ+MY zWqK3j(dR6n*?j+`2pn3!)EDOb8X2WOY&a&vHlXaqPYJYdBtHO~8@JDGyrjycffMM~ zy1lRQ$!#vIi@OgD4yHkwC<@!3?fX}v)gDi}DSw$SGvS3Sl^gN8n}EpL6*MNs68fb! z9@$3<-cTg&bGiKuv;wE|0ss`T9pj@rL4Yfilr!2I$y>`FS4*MB?ez4n2GXp!gdKKx zA5^P_CB#4^3=$veFrgpxeUpOst1sc&M&O_v+LkH@&k5Grj?na<8w>QUW)IYQc>rHCFUi-g#P$_bN5{i zY0qgYn>=l7S7@qs?{6}^x~}3y4>To`G!NVuymxv$k3N_{kA)2So<_J+5uWt1HE7UcL=itS%-#k!?-thZzDb^}Y1fJ)vwdJlWwdyV&} zH5_&uPEFhwgA$BiefP)0D`_~H0*If>_sdl-znm54{mb>F?)O3S#PuBBS!8mQ_|P=E zrNwF#ZV?MA-j7}YdxyM4tuSUZG2sQ3P+{f$3L1sJ&}2EC@ER>dU;Y%ykOie6k2S7UtYMl0%jv5Y7QWb5PY7phMSkT~EX7kUf&>w8 zW;}odqv4<*Wf%u6x0`Tr=qF(m6e@%Yhd;6APo%N=5r-?*oOugoP0%G*8JH-Y&vtiB z5h0jmEeTK2YWtW^ldWavdNXKd8Yj5=;gmm@L)G^i`9KoHPGXU$5rC+J^<&1fT?^;Bi?8FX8S6(ygQVKx4SC4hUW-7ExV+Pnkc>;{lG;Qn2Ko)=fm^}IVj ziI}#l3$KFkht#7j?W5~uKyJ%%rQSLA$w)HO!}|9EMcIT4BxTU{*hfl1&sAPw)jd=Fyj?y8lZ5SFqciHO$d;i+83yAk!vRQM$Amv)Jv*>TMYS@xv-Vs1 z6CD(&U>9i7MNwF}CF9B^mzBhDv!TA-6eC_S$$2McsK$^_p#_sS>f+F02dae(=ge)B z;ASgQ<0dm^&zVtiZ!r12_RX$C$A&oEG4QM6aj+6L3#tU);kV77v&7$pq_jTQ(md?{ z%An}KP%s_Al2K4Uop=7d>D>T6E>c55+?e~%@>qA?Z_sQ-TUm|lSu0v>tBzXL!YHJ? z;ev3KR~+Ax4Xlv3Tsspn&bZhc%%v zVNaE>Ouk=bfJYAvMApKZlk&^mM4t`r!MistWbYEW-NFgTvy*)5oqJ%Hv1W<+LyUAO znEbOCnUM^SqWuCEkA9VBMV3vo#a$o|BeeA&k=;SmBFn#w`b$9BVQoR)cM#e*4#AU1 zGu4k-@}Fz7Awvl5p0vP;EmunDLJO%8wQ&<76QtrYA< zz*2g9<|!q9dhPbDgQT9i*U1_GG}A50+nQX?dK7mBK9!a$7iIAg7+fKo6*wALHTpkb z1LN9woA6j98TCQ8t_oE%gBfcmS6KvM_ht+sTwjIDjohSkLJRJPC*xr3@^3Pbs;4J^ zELL+&6*a+wN_DQUxici%=fxw=k4QSd-wNc{$L{nwE=W53=<|Be@ZRO#`=&u$i;LP) zPqB1UF%yzb{!@pm32OVZxc10;%l%e2zDA6%=~bF2u#Durv&^`>$jW$qG3Dla!9RNt zZ7=Po_&G4fz>Sb=Aebw=ewSD-l0iM5|*Q_SaRL(6wvY~i_s7Y4!27=7Qbl(>eUR0p=8@O9RGmB*Az^CNb7s@82e zVMInw@rSU_+)L_&8<5i1+b_R&^qQg%Vu$&t3*Lh4x-!m%eAlKMx2J#8@vj8o_^N&v zfT!V~rdg}nTuv{ItN2N&;#-Jk4Gb4=J$O&@?ZNRQoPxK3mdZgnziuWMeUglPpw-T& zLq^hKp(^}<3zZ_QSfwR4FGDUjoZs0G;y5Fa-&DG>Qh5t3;@+VOZ<8WlgljK^3Qh#+ z{v^yFF6t-nToTRA4tOlcs1WiEt0271MeeBj$Q|wfuS>{?v>5-RfQ~~=b!vE|TI4#@ zBf^J!d2EhYxgnF3h@W?G7RhXK;UlrIS`~8_x}d}J7Z%~3GdCOpGME7#_)Q_X==|!Yozzm!!B%RzCv=ix^rz3fFI)G$ZrWdcJ8-y?Q4e0G zzA6RuxgSeaO;=+~*Q@gv_K|a^93}OZjtgzR&MU2#bLZVkGN(t9G6zA2k+YFsCo-hm zmoT24*D~iVgVNVuj4v1Wi%B}ioRbOgHqm0v8m<}cO9XJ=Z0gje9sT%qo7j@8qA)T2 z37pBLr$2w*7!8NgtUl_Cp*bp*j(_fDGfec94v&;^g*(?kX%@g6I!{Fx9>p`;-Ayts zD@pfE7&jT%REml}+pRy;aB<&R*SIJ4>AG0#N7NUlevym`kv+F^2bR9zPvg2`LLa5E z=a1hzIt)smIym#yti)j9kr=%`9-An)fYZMdO(6;XP8>MgNuY(WBhyO`^yK@Ai1K|*U9DSeKTe1Yf# zei_XU%#!KVyBR{)G}!@cd<`+dw-(#^xB`dDaA*5Q*U&H6qyC{-X{I55c|jFUPYHAD zS-INIAv@j+oN%3@*}LDFzo&mASkYymQ4sRsn*Z>kE@Tq?U=`%e1I@2kd z|42RoTTmdorZ@hZWt;RZ|Fu5dgkar@nTZ%V3jz~vfl|hANfZAal zONk}fV7sInxBDbe14yN60Zoj*(?L9!!o(oNKG zA1m&59yx5milx{nF@S4Vnb5J(Pm)QDaA?%p?SY7LC5H<{9D$EpU1^e92&kqBAHNb@ zu)N~>s^GbZz>5_)-6!Ub|HdwN(nSDflV?=_NsgBQq(7;E zj}+Q(yrbP_0NIpf?=1+#cQ;Vxq0W8MBN-!~%D*sx7a=eFWy<(Ham+SBnydy@0Jx-> zIbTb;msrR z1~mdWI&;yKOWt6&dk&OK1=nv<>zwYP1Lz|Tj~hFi%DB_VN{#Q)H}$pdo9+ZJV_xl_ z`mEgmM4XFF=Utx-HO#V%$G7+Uzcz`|tJcWIWmZ%7pNE4+*Cm>mgy7_j318QKY0P}a z)uhtB!%^qDBYtPb=_QAmH(m5!zqX{g&2fR_(}CGasu)tSl6q9%-}HH=^_ytJj|UsK zJ{ea_rKB@dUQmq0CgMsB7N^^Y;eEc5N2DMG-x&PyiR+2^V_L(Lj6=uM<_b@R_*XdU z&Y5&3(vc_k%7v%n)q`yLJL!n{Ha-<*@C;+6R<@GbT^g3XXF1N=fBVMvUa4*KBj(fk z#<^gjmYz2X&;MCu5{s1->Y!#A2 zg#&kTvKxdye%`@QqLk@pots=&2%A_lkjIj6jFC|HawPe08}_jUn@8eqep9@CdS6u- zpomaoi3p3CMNe$Pe2c>6b4`gi&U$iy%5>`&Me!wwE{$0@lgGmSH{}W~VBqJ#iv)}M zs#}lo|H64?xZtjT3?PrbDUj~V%wbI=Dk1kmR{vKsUu1E!KvYBY%=MBSgSViZnaKqa z>oPxX3_QjGgqbH&7}@^F^#T2816H)sa7&D4D2)Tu==Q%j$FK5v7U#m{`Eu?Ejy z_BWm5`3g(=nRtoaqhRQbpCKI~+nT%8>+R8Ku|8|`kr(7V`_@b$9-Ut09q+YjU-)6G zB+~bK+8%Qh0mMT-n5E;U`s%%TexHqbKJ;9ZfzciXuqhQR*Q__9%Lb*L_Xm9s22Ea< zaxD0w_oQWx$|I!@zFYb%Q<$D_VYcqiJFNygiJ^J*)6eW9eO5Y7uf}(!$|W&(*2`Rj zmo=sK1M#B8`8%)%0AAz!pyT?eSC6Cl?LHC3dNbK8%{dv5X0)&i0wuUdu8 zQW$u)Qe)UHwreUpv8Cz=Xg3*OZIS7Hy6NYhWg*H`Z7H%qT<~_Rcb{>b&hP`%Ai%X% zd+KXmwAlLcyb{CitK_B3TY2X2v*iumONmQUy#efFS*d5#njI~_hWOM(<4KGf-}fe8 z%!m8IzZem~jfe(P_e5u1-Z$y}eu%-Z9NebsS0++lC$NU7ai8Tb_&e~J92e@#f!OC| z8^f6aFGS+$`@@iIMX!)%;WiVwO|PNV+j8FBuQ8{-GM66by`~Xn2!`}m$G{%werIPe ztWI!2p?e$kY)pLM=P|+SXK%bMBIHmp2xLG^IK2Otw}NW*_N;`m4d^+KF*LtU@YA6o z_3Qs^@%&4I?B5y;hGfbV0C$)JEz9v>P{U^}7)0Ciy#xnJO8E=%RDA{gP(G~I?JFB^ zRrYsVGV`eX6)hG*)yHZ=Q4jxYNC4y@l5C6avkl!K(kiH3T zK?MH?HVrHM|5pn;0#Xxn?g1jejls?>@R3HNMUhuW_|j8hQ^x3tH&)V;;`DAp%_p^@ zrK@B17?c%N(>iZPkk>;Eq6TkA*KEemhe0TD+`20q{_j%hGU#O)^oqWZuLS*IQ%8-X z7&^M0ipfNr9&`Rm3|*y(ak%Ool)5ZuLVxvj+fr&;?OA?@#er^%<3JzSo?;H?&wefg zOazC_Sq9V!o7_X zsx364o9L3i*CMu{GqXr335|4du`OraUGAM1w%vSd$x&&x{j|s|;<>G|Cc6#|+vU9;I+*S0^1&Q=8OI*USLl|Os#+>ZCWyuK%}^buJ7-x- z$G*c0jobCFIl9izzKhY|acHEvZ@)D4+Ha?35_4#t7xw{Z=u1+kIq$>%U#S#8%GT1Z zF1Vh~`};}|wngB?TYK7_Rvy#y9x)wP2v^kQPTn&(cH?h%LHHt+)zF;5#J51izDP^1Przu;kU8~%I$b9JMa*Tn-7x%bFmwLCe3b4$I+rv4USyaCZZbUC1%b?-W^ z>9X`5I*;^$?ELmt)gfV9fpA?X0|+Ueo*Ojh|?1IO^3X zT`ikho}qZE_@LWv!9$GRa**28d!I_*$nkhg|MDfmu6|$9E;e|%YW9_(*=w$y`6djo z#nc=PtNp-nP-%XBwzG@2Q|8^CuHwf|L%5GTv-niFGNwS##Z&mbLup%XocdgmTmls+(qr7DX3G zl)mo$myg`G9xgz`V?X1GXHt@QDhchbj6IeL2u@U`i%HLxk+Kj>U5EO&ww@4?8;AEk7Wa*pOG8=M=O=k~9FvoBa`qX6Y7bRTQ&QBWq47`tm(;S*K~@b53cW-bOsCAW>d|xmRD~Xyu6X_x!zfO4#PQ)O6Ip!`DNo;;`vc#`Z{!TO6}z3c%!G- zj=!WcYVUa4&HEw}a~8RKapueuyiA%N-nze@etD7CbktYuR^=OfXh>24ocZz|2$z~> zoG>yMar5Y}I)nGFzpVRgm+@nYGcG1G8a!W#`7CKN)UMZ|yYI_jqWRO$oBDo0*U#58 zFrg7deANpN0M2^zDG#FnyPA8oxa2-%`sRSo;jw{b$~4FHXR5@^d18tOJVwt|;}dyj zEo_OUJ0qD+AD-2tcQx&tk8T^G%(hP;(gz$Dr5@d7rFqRYk9JkkMCwxCqmPdI_{T%P zQXRI~I`h1`hiy|H&h`DK&qn$D{8HqkW;YEh$8uZLtTdC1<5Js}$!YDC0hOntfCBVTplXiHk?>6B=DDCYpw!FuHVlAGI*^|{`(0E2Q%|OKv zxprgsHC<~~>-%wO)*h@hW+S@%w?`5}?;wDNre$a3IM;1;qp4D_KuCHXDd)8pE}p%i&PLMW+k1Yf`STPv3em2>*>SbrL={4xqi@9Xa9R;>Rs#O4g-O zW7m6TKH$zs)%n+YPqBNK1$#*^B<@RRuMy=$9KU>3yPcX^{W>`5<3^1@ zS81&YQK}Ax{AH=I!&>ZZU&z$Wn}m3C6u8L&UlLeN-+giONr`Nw+NwFxt6GYE`frICdCx*1@dmMOF2}RlAskNoCba*bnFafHIAGQhFJx(2A1+TcsY|KA6pZ5TIMrH^!rUKCcl*LYH|p*PHpiC}}kcuB&oU{}toZ=3+-Q zI*Hi5e&d*PIc7B72$xf_K$~k`+l_rQ=K@)R%;<1Q30pY4e3D7?b^_y>Z7q^e?)A*o zmc}#Q$pyG3_{kQ$w+R#=O`z79TaFa-GbQK?QJxP)YMX3%QKptb&((lB2kVyW+!8KQ7_I8!#6@=(L` z*70!KMv1KmQd@$!)5TU$;ZyD0d27IhU!i6(GvU~uwdTDL)gIo|a)ZXb@rz5D3+baN z8nsJmwG|K7(0OaqQNNp0PoGNs;s7<#wwTM11un~3cPcUA%Zk6*EGvO<;v8HzDnrY;dm(+81Jr1rjq++nzR=ew*- z-%7iFs{@7XicQb&q=65|)`p)T^=`at^gmR1^A9FVsg-=P$B!PQF)~y|sf1LrSB`pN zqJ#zJXQDI#oC4(lk;J3(8;x9ak#~vNc*L{J!I+%-q^q>vTrl;VQte);q^!6DQx=82 zwp}Ia4>#xLu`h4ImEh)!lm3RHSN*T5KM7PAa5}D_i2V)_w=CHlk7arApU!2aoE#j%_o0Z*fVv%nu4={OFvxB_ z7{?Yb~$Pt@uA zgs4XeVjH>;+WBWSYmSB0`_s?&)+eCf4gRwOxi0)`VIk-BXzC993d6nlq&%M6K=lqj zXgmNl`b#e^EbcCbV1F`6uS+FG`bp{rl^NB!l@MSXmYs{-6?U_rg@ z>I?grCWQ(>c7-AD-!b8l!`ML;UHr`>99?3h0Y)zr<2OPa5NR#!U~0rlg`olYl|E&N zsUii3x;C0jT+rPgFuGc*^T>0L?-e6ZCHl0CSHKZQgFzQM59g)mP3FG-Zr;Eab`bhrqJ_<+Q=+<*_M(3)9MU$Mc~1Vi``78m+}Pr&)Sux6{N z^wx=LH<7NFb-Sg7J2uC;umS=1{UQY2JdltyhtwiTD%GpJitkT|?DQ`*I!lf-cYPEfUQRjC&LwYsD)%^s8X*Nuy0EXIT$%SUI@#1A*ApRH3J@;eeiExFU#*0dh z^hX+^FL8#MQH2lhF!lsxvPc-=k6s#+yc1L*WksEM4_AllYgKr#E~=Vq>Fqm;$M2(6 zZ?L^jVDo%-8J0aFx+ZYQv|0y05E>E=nH~$tuu8T*URLq`-n~@*z5*M8ta( zUvzI{H}f=8(#q5UVt*bT-y*KCPw7sxcl~tLZ~{6CUh!lEDrDOS?&Pu%+1r244q!dU z-#|bV*_no3$u8-Imt0It)Z;xo`>&6diAk+maydS!d|MKC!roN)U@nMj8m-zB6yp^_ zl;HRnhC)E;#T?9od5H>}XGEJ)KCO+cHikKUio!4Cso%BIE949-xib7lPJQVt5)OBh z#PT%cgW?jRB!yM!>v22-!!2m2e{RTYOp$26Hld!S!Y2|q7b96m@Fug2AI&|>=+`!E z>W<#Yks3^I#R8p`^+uHLrKJZeygO&{Vlabo^j z--bi)QZTAHq%s;9HXG{>vDPhA8R&JmIpM3d7g0=}H7@*fu`23|AARun=8B0y{22(lv~*HW>OsDgK95r+E#LTSyr{{@98bopOV(o6xvzT<~-mo#}Et zuDa+_A5BWNjx`#MJpb^;BDmR#-aCX^-un6!djrTdy*g7~VwTWO_czG}^3E&HS@Ioc zdX{x5WPi1B+R^Oq)t*!U3scQ7tgh2qs=eFQiQMAaZga*}-9wJW8SxdJb4Aje0fJ?n zbI++gZCJI(f~oOQ&C82-w_Y{CW>PcV_llZ)*L8(x_iWsOL-Z&XL6-$K>M2xvw6n7q z=-~8jf{@OdqW=69Aa^ZaKV)+bWD%py8!DfWWW{Gsdc27b=&PdWn_lUt~RxRtl%MMF}I0V7`9Y)@M|pLWyBg%m0g>tkY!- zoo4i#mbvT$FMpee!k8xy2>ro<@D*Zz#w!Zp+E{!t=Y(M4!{+TAX z%-a{U{NcB`REl)NJ@76#!zT)Aj3i=e%lD;ZL`zn?w_0ixt5h!`MAw@+Y^VEln;B)3 z%HvdV)h4l!8$t^y$8SAw1?oqsb31(58*|-3_NLdRX3IJ}=lS&m-5SbW#K1nEW_(|lM#zdv>w~`ii)9R?u$8v zwI@v}hyvQ9g>st2uHJ(~5{SB#Oyv1Yxv-B~7*);)vUiyJH)icdrcRcS!=} zM;AY5#iY;7vZvWTP#eQc@=&(GnVTkoTKU8VIAjwpc|G7e`rzren zE|ES_h*7o()#;{opvQC`a{E#dk{qP+&F+!rGP&Tvq=GA()6H`hr6GOY=9mt-S=;6| zPJz!ks-6T$jo+rtdK{^6o+eb^uALG5bXzSwovoM$=!yA&)~90o!zeX0fpw5bpWU}h z>#|l6klXmJnb`M{vY@gAVtFt!uzdhi+0^l2Rycc?`mfXR|xQ+CKa>#iwo!aV!RhrEyIFY8xmRGonQEP zLmAdMvKgglY~k=><~uo1xv(EoPkRdKKbQ*JECN4~y#5py=_mOol~wgEq{<3{9MF(z zCRzrdW+IN>JnnvmEsTmA!Xo|T+@BOs+Gh$VcO(8E`x>v6ZJXn* z?$asYaeoXS->tW&!If%{4Vb)SETB(ArSd@d&iLv1t@CdDYqq<f<0nOQTWiLu#PEU#{Fawwsx=#*=%!z z?9Lq~eAuHXyPZmX$>k1k?-1xX^hgLEKeVxkGmZb&d)LzrfNVG+E*q158v44>`Tb75 ziIrmh$x=M`(pj~K+aXrC8z=;=^f6Do#R5;;U&qIAGU5CpUmw6Q#TodnE*IMS8uv?H&{DF_l><2;nez1tA`i&~aOiyH;$3OJ7%Et$V@TG4-FhBM#l=O#~Z^ z#lx6Q@npjveX_v4w9L9IsSiWxq?395xi+EWKrZd0KPc$TfsLwNYDg`AG6Iv2;ClRB zum!;SM@A2@kZ6nHGpU)gv+icZGviO1hfM}4am_-kJ z&X*)j<%shz+q11U!%4K@$Q1(OgSo41a5yV>1=ab9XdqJxylKh z+Sh_mA%;OUW-6!9V~vecKVARn*CFIgYy#?vVeY$&`fe-E1;>HEocCWMdXJD|H=F?7pnL;fpUb8Nsl&B!C%sf1TY`VX-gTIlKqbQ5ijEnc&)bUqXJ3)8N_Jw&>n@C zo5oZrEVFNtv57uCxcL%Y9&y6Y@Kcj$So(ROzh-)m4!9!<049@@z=aWi|CbwhTl{ni zaBa6UZ{sNw6|?uFI^$py`79oGWmoSm z+(=3dm8_JhqFV~Kc_aiVJpa>h*2nX@;)$`HLgf2jI1g-B zWQra;l~|rfi%>TNIikG~;I|7D;k)x9o8{0YL+FgY&^N@f3Bd{EwA~lc1UX&MKWZg# zpNBj^?C3&vCnrucXb~+^DT&6b!Y`UOy}g0O8d#(7sRbO)N~K5%HYoU4uai^M=Hz0%U5x6o%mTLO^!l^d)MuhL^5}?rEv$7qRSbojV^i>fXZThhdDEFE3x8 zV3i%h4CE<0hpV5%22sF@9pK=Ro-vcHZmCGB)GE2rc=n?3XQw&QOyX0wF+2K40u($wi5S(XGj#9Cv-IZElZeDdVjOPHTZiuFb{(R7(Up-d7L z_mLX3QDYv81u9&$aT>ps5Q7WI5w~QR`{q=|`&9hzGvpGMh%q23 zmqN{ixn+UB5D|6Qeh?ACRsSA4_?-;TGQbg09V5!+*d+dt%m-U51P%RsWuNpC-KwCa z+r5_yTd%E1P1ognF?^~}w=MF>`C>!|aDG(V?E<_{2~(pm5|heXV%$`Cc3UX#Ez3>r zWM-hX=sg9<7{}XWN;|6b(SfYZE8%SlgOuk8xcqY28NOpKnFnxx!Cd|T(EksxB-OAP zQ*pTjubv?r#V))td;VRw!S$iEG2SrkXR7}H03ej?Zcz5!4*Vb_hjW8aEPI&Ydo;ld zyL_9kgV{ev6MR)z`W?Gpr}{VA>Yvf7solO+|ChTRfCcF7yEfpr`pzqmt00n_`Kf3x zZ7{WR*6mM&xr0i`XyPW($Xs?D{2cGRx}jvi_=sGgRpx-GTr0mI1^+PWRf4fEmEb=ac~?Yp_KDKhM@Jb-T`?TQb=Z8W`g5oZG&} z2J=puv*@5d!J8u>jPVk)pnvt=8u!~Z^gzJwDIgZQp7q(OXw(F$rCi$`O~9-_f72MH z;Tf97I(lXXYHD9#IB#~ETb5;9Bl{3p0qVPF1B7O17feJ^cv={jy@`FVWXH}B9@Cap>? z-^Y_AD^JJ93e4#mz9U3LKPbMZpnc0<`-4#><|m5xTN8NElj`24&pIxYZOfoj8M&O9 zy4PCIY~_;cm&#a;RW1LCf^sR3x|xK?N8VxmotjEThFpv}O8!HDa{u4U|J&BrTR2Mr z^e?pK7rAl6Mm@Y~69@^Wk?Re+*+95@##te*hG0JmugzTS^^x5N!9kuvstaTM-m1l} zmtc=@nY9=rl^@qlThP@TBsPqD@tmgPs}|!D=1ck+kc62=>>YTy@^LzZ*+!#_u>0qARsC| zH(P&FA&&Ir@pEBP$ z5fuq847>9AaUQSDWAolC0L|_K?8=9h>%SwWqn@(%*IovyV~G5x-@Pip>0#-5Rb7I# zkf=o!zWV*fLApc06ACy>y?#p--wbQROcu^Ce$0^^Sqo{~Sh8C$3gGO@hc)L0PTxw6 zTPm-mWC~|h?{+!eB$S`w!`O#u?iuSax*YS|8ELRf$w`evs~oWhb$OT5(!~f(GNl?x zQk9c3=b3ZLElW?|BqKnk26-K_P*Gp6b?2m%^|WhqSupfF^05yZ9u*tTiOJuy=f`=0 zP{OA&^C?q2@kl~$&3IrRdRA^oTXknHQOn=%F$k5YiJ0%Y3v=I4OAY7Sv+H>!aHpls z@50lFF#*}X-G1OO28l8;;Hq38{QQpjW>NJ68Sx*<0N78X2|Mg0pDJZ8mAtzZt)woI zD2=N7nonLpl&{Z_ES-Y5i_k@=%kRZ}3aAi~0`M`E@(aE7nnI1C^m4%qz|#(Q*Bkpx z%J(`1{QJL1BZwhZLIK09<^6z~O2N%g#{BA=Wi2sc-<~?ks(_dXP*%G0+kWYf-&#bJ`7&e#&4hRW0$u@A4b;4N@cT}@8ui@r5`dzUqwp_WR~L+z1N%C zR=;M(LWBWW$`hE5Z3)#R>zbdd*bKETZeLB&DCcRxdvYZih%`XBCa^4n`qi87@0Ohl zf1UM2-O173ymKhX``bC4brGhTe_0O;WOjc_=v^2N*6wqp$>q<_mU0>q0z!{m$)r#0 zF+cqd4el|p>pJrjxBP_~)7x{dztHJT$E*H;SdZvqkD&PP;F!k|D+OM<7eXKN3&cD& z{yze&15FuH>hfdp?Jk69B>w;Yf87KL6paJO72zd*wl>93eb0kA4SkPN$n9Th33Ug? z&?$be{Q#N?E-wx2#63Tmah|1SE!-8f7%vi(jDIO8O)ylO3{}3$aMuen+!BR}5C$C; z_%mq|Gl(JmF#qQ$LT=~w&M0IQGh>VfmG#^6BR)0VN>1P2bVF+m0EDR_(Wsmd>(zK)uH1dgphV1nUsrF+{q>zx>>N+n&nc1} zx^`RXj*h8^E~nDVC4P~3SO1ZUI8@DBP^Oq&%ZV~u%Fjq5^{UP5s+z_FQD1Q)e;W-%S+-wX&lvWg2PC857|dV-*?3j1~1t#zy{Z{7hHHuT-HY} z(NHHloDC>H=4r6?IGBr_XF3CZy7G4&2|{kK$ud~uKU@-QS{T7ka>hw#U=XigRKA)@ zD4{1?AI};c$S=L@H~d+WbAX|dMJps^&^0FK>TdyCax7PSjWg;^0baLX8V!ViNfmz& z0mFK!_Nf}y@KZ^*BWgky?~mD0e~nhpLA&tIrP?f(rRcnJE1I$lYiD^p|C=&R+?76q z?aarO!GVPTeyzFbms+#!V=~D7srNjCFY{la1;jn06ZoWBUklq9R_is}h@2u+mUwg_ z{P5H8&$VW1j7ApJ7FATt2Q|8-A4vx>atu*f7+-!JkxRU(uo zMn;rN&CC0uwZ`gA45vFwnxZn&83(*1OkXa_de>6C7=L$NgNTUX-_Iq}{GLlDQjj-| z#rp3CrXeBfajf;C&&y#>@o3d_j@Rij(m%T=1d*6MeKleB&i0}I3^`WHEFNuQ_o z4QG~D+&yZjpO+VU-t<(1T!w7lhfu+x#fZ8VG7u^RsjFB)Ke0Kk1v!E#ddI6!UTQDA z3l}criFxLK_@$6M+ZF-T;yo!;aG=*huFhup*A?_Hy{;7%xF5(`!)^TR^ltq4nt=B& zGF9I~o;PRNA$yAG!F{6NQ%$@$9{rTK(o@KxEb)SN@}0PNIagoYQCsYXeDv=rESch@ z49^xe-`P?tT`fc5q(Wz4xmtWz%%Q4+%yQH&ppmuc9D~Av-3Z#6@H^cWY#pB8fh~Vc z8x3*8{*56i>$1F3f8~y<;=d=Vy%svJ4`8*0N_TTOvKVrcNmC!;$^|itU+9@Joe@aA zXMw86k14Kv?~(tr1&5G%hyp1x0`&Y(^}wjRs&d{eME-&Fu0nsKqm2h^z(1zs{H?C| zRx*NLiHAgAxf}6l?zPiM;UZRI>%f|)hr8`deUQPt1mQ(O071Mth=k;~K}-i9U5uTm zcA431$)MF-IVuIPDcu^Y0|L9#{Iij^h*}|$fAiHqjWN*E#DckAO+(ia?7;U0TY*8~ zeS&q}0Wwv}X?DK#DceTwM#h?X8k~i~y)?U?zDCy}@@`eFTF_E*<;Ng(e})hS_Sf=S zbuwi6W>F-t%Wa#YE4jQzG;pALb<= z=u~CgA@D-sR2MGO8$!YLOv5!)%OjT7{c;cY=KUU4Hp%GM0nG0S;ta`rI3}aNwB-7P z#NkM5TgHPg0)9(Vnr?W`^I%nOl6o?4nYqyXMLBPA={{_owo6Q2;i=`%=1j2Y!6|TN zewkblYY!lz{lge%eGo>LDgJVS@E@lu7n;J@RZ?XfkkQsN2Yil75oX3{6%6-tMvHGH zv4k_{P&turedQMuACLrw|}zV`5a(B#TeNiug{u693DVnFpkC%@YR@a`XY>vAG`z^yHV5on=^otgiNjgPzn&; zrsF*3$mcZb&?}E5n$N{(e`}hlOA&>>;ki2J|L}*_T3ZIG-g3~5z2g5QT*cq(s~-NH z!iDENPwp@7w$m!_&@p(W`H}1xk;$S~i6_X22iC@*on;YZf0QVs6csABN@Dqh&Kxf@ zD-dM!GCl-S-Henx1EpCB1eRkHdkKwPC10Z_-q$4ZLxE^HUuc|VN4TX?w1UP;jJ*9e zIv#g|U=W(IkZ$@5pD)=%nlFDOPL$et(|l@`a|^`2^K1OUnGg(E6ia*JkYYIkrEEak zV^Gq(Ieo6uF<<93);3o!4Z~f+U(>h$l{8J4jeG&sqvKsbAfb3#@D2GqpxXYIV!442 z7_OqU+^h5q=Kvr;j)V;e$sKkDqKWe!LD_{%0qY z0`f)ieJp}vo>K8T$I++h$ccr388{C(-aX7Bhc2i5nq~2Zz@rU-l-~2zZPt6EBll52 zzZr7E7v>8XxpP4N{FVLY(ZObol8g4$7K31{$XIzjc5&}WB_Gz+1qHgUz#AB4vR{HY z(lukF{sP~TZW^Y)joSPEUQp&t|9>-C1iK>6F(**OaF~Fl2k;aAThSj#gv#GjQ3R3^ z>D>G#WB_9hYFg<3fTSyJV$*d7{Xdfdm2I?qD>~{4DO`N*v^sDF98bCnk3z#_4!k!P zP2NL3gW%R+w@hfr*5^IW-IEU>Fj=Q&jr<~HKNJK}0NOd&`VP_nGdR)>hm8565pn^} zXj&2X!HL^z*6Qs9VI)s2H;6yDfiXsdl#_r=pZ?HP;~WUT;G~&^5eaYk|7%8JUpUWI z-ALSK+hsX=m!&d80}YT1R;0np(JWzd4qZGeHIajCq!(?{5f&5JGlnus>@}+rg{_>% zOULwijR((%$55A1?Vk7>Jl!ycY*$`G=}6KdoutcR_dwo^NQ7P>jf4xgWpWg~EoPua zWIW59LSy+bB|t4ExYnBeBMx6pcks}|LJOV1zlRmZNa6nl8*ssu^iE&NW!cDdueqg; zOLyP4(;>q*wwW6fOt%s*1aXTRMRmvl5?@{4_{JpG;Fo1JbTVm%Q}t!9D?Wru8t3>) z9Cz2Atz1rK)*8EzZ9IjaCc5#(vUSo!y#wFv@yuNv2gw_v4y+#*m5YBD6?RXgRLIWj zOEw-zA{UhRrR&txkR~HmdLlNEhMk+-sTp|{D6Jak+$fqkD;{ z3<*ZYGL=yq`Mb}sAoZDgg%tk;o`|_#^2lkBjgox&?+KH05$JygI{y73)`s!05R=&S z1;U}L+$sQ{XkE%Dw2#WWY6POGHM_FX3UE)c#)%0%9m}J!X&~vpanwSZN z97niZQpif0^oA-3$&-jK5GDoNRjFDip7$Eaf50H=jBX=~5~;`@Mn!ka4Bd`lRiT&e z9(TW*GH@*qf7)U8$u;4QxhjqNu`iy>&*)d{S72` zjp(UoC2mA4-Z@be>j+#4!mj6jfe>7(2-V`w2kJo}OeHXF_D9GG9Za$TJn!x&A{|$+s`A3mCP>YgbCi;DD%fBf0cy4v_iOq_`?nX#PT>O-| zorEF*8=h@8!?Y73tj_IJqIl)DSZ>C`F!@;-x3ISHpRH{%3{XHuQy4y|m;hI4CI_o> zryPpLIo6kgWtrR<#EfcJZ0HRWQSJthQ^cfDBUOiwG94{tf)-cpuKeT0s$$1)%@7I9 zt_fAy_ik~c>JVkCt_{BGBE1)_8dC57!WIpi#noKX(+Meu4EniRB$NzQAt%c*zUIY- z_VNR@c5ggdP-HGqML3rN3cZ9i-p6kIyY4t5i06y*(S^qg+m4f`j{3Bh^-T_z>smbP zL}~^>jv{W|nwE~|qs{jOJG7S&J1vaxG9+!9a%~MnL#?$COjPcBr|2G!rRW@YLqvY` z3M|Ne!$8f~TW2XS)hlm5f+!dyIeZBm;~*K()X8BaCuD41<&*N%$#GF%r9Lu7&&D`3 zVz6-a5mL-$I^_`Rwzbj35!k8*lKhCM)L|QyrBg$uj#gaWxh}k%pQDCTqr(TK-Na)U85E2 zm)!}b>7R2&!6Mq9QL<9KB33l_XMut%pV#k#LjS6co%Z|oK}Mg}Qi?*nR50u$=&bu0 z>CL#QyCFY^zk)*OLsPC3x3JY^@gogdJ`ay4?!x-|v^qNP2e1xJ`Ssz&6|)0JiqGNJ zo6q$1YEElcHIEyiaF;RNRik6t8pBNwNXfqbY0EV9uy_&0!T@}zMK-(%jz1Bcd;(+! z0jLWyO&tgnKonHC)a)tgLBtiQf_1OaB0u;moly`8B&i2sML{$RZ1YQHFp$V;Jk%(y z>>oBI0)h7%0y+|^WAWTfixzk9QR+%Iu=nA7GoviWf7kPvH1Tr>udG;PumG#k*V}ks z!fa+Y}=EbkAV6>mdW_rtrJ@DBuqshxb3$FYw+^@?-nG5^N z%tgY5TgxvWF!qn|kH}r?aEQRkgcZStb<9`a1zHy4yHFP}+7)r-yK)O-37+ zX;DO~eo><5?lv{p6}1E3_~7x&!-mQyyC~}AN-)%Ei`x-XB?aky;iYsGX0bIOx;{?b z1Y>IlTgBnnk#sP5;9y54pLp3a(efIJaaG&7UbR6r%Yss;2hC-gST*<>L~71oJER2? z2tP~4D%r?zk6g!-W?jk-kDuqc;YL>}8bF!w!Nv&afI_yZ3F*^vo|dI7M&TtWM< zSCiziP18Oy^Jm0c#yq=9=BV1%VNVe!9Io@aDMVc>!_(&PnzWE0pFOirtKqw5mKvjM z-qEvG8P@DdX_CE8eH9mU&=;$o|j0|EUPdzbQlO?({L5`gRFs6DC;Dd{w7 zlp~KfsKN!qdTGDHb7WNEz!a+iSJG=x9{Y<=jnNJKRxGd=|Il6$t`%htdr2Y6>R6p2(uhS|Rz~Au|J2GcVbQ{0l_lCB|VI5f2|Ka1(-b7Ne zxNi}A_T+Y{j@47@*8ltn^}cO1TL_4ZFrGauVJvuG*80((zcW@yh$|tq+X?6F`E)l} z?<^j9{?y*z|2WA=@aIdLfblc&-u}Z=yRk9t6`<6+ImB_MmRz~LpD*Guv96X#l0fx` z8@c3STi=xZ$2-|$?Fy2||6^CJ;h%i?<#!FJII-tOHs5^hPj{|IwQ<-J(ueB|hu6$-Wayy?ZBmEw_u?|I|?ASVAve{jr@2rxOQff9@w|e}0Zm zBPri%QtgNA*hTY`<%ioIa1C1p3%ftI>*UImFYWQ9iO5zw%k7W<__9q1tQX@VOD+(k zo%I$iAu1>!SO6Xo+H^ErbK{GOV(rn``Za}vN?#;O|9Piqycq_FsL<}-QCtNCeI%SB zI??y6fBoe{MCL=oi!qqxGrfBoogL-cwVr){rc)Nwp-2$k#6i+TrRH@cG(h3=a|{B= z@do513$Z=#xi;Tbxn(Qz+>qLn$D9E0jv!WxfV(Xu71mbiwh9S-O{y z_^uuaav~3_tl{{Fo2K6QLdr&QMSD6r`Y@z@neXy791vzelxUUqqGM}8TBTlc94U*-RL9AU4 z7qcqePP=Te7ghPqHzKo;Q7SiQxFi_%5&0>HbU@xEN~ZQClERWf>X) z6HPaIzX&Vjq!*IZI!?k@`P#4XtQl&ZhLsDy$lj~MbLh|L?rE~s+q0nDnDWsDsacR~ zqf}Na(bjmU_G9aNZ}Qhh1Sbv@@W@7;o~3L{CrqU)e%u}DQb2Z9h0hlQ?LQ1WT!mUI zy7DOym@L|i=BwLCxRV!+E@{UlbaR(=c0!5ju`XGM?tM)TJ&vY~5xdlePC%5-I^Tc5 z&zER@FpnTGIP1rtU+=z+-7GgaJrp`w*}Ggnaj~)9bh}{sl>Fn=J}{D3$Pze;-pgv# zLLWGPHWRE-g~E*#-?xlIXyKDS=eq>gg+wx0AQBtSOd_MTPb+Fpz{@+|)p~+lGAN#( zADyazY9~bcP?xQ92tCzuGv4e4-7$JeKPZKE1107C+-sfvcPZNy zCW=XA9R*)xQIJS^-c~m2HOSS_)dK{_xMSYQ7a?qsMXAb*$z_60J4CO%vzWh@B2H|X zV6BqtP{h&d*pG%>RcPjQeox!GyBU{GX0bCd5;YzYH7zGnp@MPVn?=jVa$YiNyBFfN zL8H*Vg+Y6x_^=uCRPl-keRnrg=|yumwfoH=6;F=i`KocTQqWc+2GYvw0h} zLEpQf;8=hZaThPsUBedfe9q?hF{j&*vwN#^8@$N8Bs zp>NnJUBFD8b^K+@Z-^jy9b;wINGDNye#R39mK$0Aw)~#gDrQ0j_s<_hlWvT4dg_Iz z7|kzI2h6w;n$wcey6NF&ZUE27l2XfqmE)25bp9=+61E-UeLcEy(0ik*E{E;Wa_wS& z{n1=qvoBsAJzW{(QbZ|76b93*rDJ_Cx2_P>aL#@xj`7E{h>wS^VW0AHN=n@%?%DJxg}gXS6O#Yk(^S^qt(eK zt(H}|xdM)fh}kN%z+^96w%%7{ZXT_MTkv>&@ND5Cd-<5`5?C&dH42VzhAv_)4m8kG zLIC>27@K8URWE=WQOl;o8Hb#wOaP=#;XV3kV;Ns}t1x*Tc&D?D-)$hHdw{(-C9>8# zDdoj;`vvz=^13C?#5v=nitvT!~^jvrouzgMua>7G{ z@W=IvCx4GzMCFWndlN@Ey>C2$&b*=z7=v+3vj;`dgr+$79J1OdkC};xed1>2joBL0 zLbMuLp`{|=)-UEPT|Yw`nl5&{L)k@u)rLuK(qVp={Ie%lBopxpLFeBbm0v5bUkT8* zS8ebUN^y7YIPKDhd-&|t?bRN{Y+lwAR=3Z?q7Bs*#J#~jaYwaS-oI0`R(Y>}4-Hn- zoNo0j>%ne+#%fZ2i&{~)MdoV7D3PjhJO}keT{~@q{TcTX$zC>w71_9@b=$U-JiO7zuRJQ zb^YnrZi|ifo~hY*?3$RoIMd7qIUVzau_p3e$Nzq^z8<56D+I?Lf;@~oQo4(_oh&Y6i5YUR$ zykuu8Q%7x*?h~%WJfMA$lWLL~&~h+g(V!kM&>+pUjltKTVu8pm?sKP-D4h06C->aOXZ^m@SC&{!62ouhppb!CN6&r*cj52%Tj(69g{M6@_PoK@m zIqx`VTp(IZ`sVp+W@#L+94~Ll1VO+8A1 z9H=!o;eGb+4`*j7Dpv{jxY4UKW&;@GaRn>p;|XduMibp_=#EmpF)rNg4vsfwb-!S? zp4)j)84&t-UZt{Wov2=Ia`SeNa6RsuZp+Dh+f>B{?Z~;~)r66oO-4&`>1bipC}P)oY5S+?AwA#^L6d=-3sHF8U0R&T2e>DQgFLvNFBG+*@hE=h4n#v=_N zpfx5?`P}UY;Itmlz%{Qz&RHRhSqw0_}o(+kKsEf)dJ|I;>|f|^!c)* zU}h{)!BnJWsA9Wu)GrzzGA%8cGl90~FQ?qP^b(EJo7%PJ77T6vh})N2%vIigszmnu zwwuQCxE+pKN6S|T=gF&ngfj{tc>z-Npa_W~uJwb^cDYK?-pdv2s`l9?4dVoCJgR49Uf4mCMg?$qr4A8iJ9aCVop@*Nk}wM=`pId0 zGQ1!SA#7dUWP4f$ld{-})t{U&YKUHEU4vxdx1vI^_A0#K)C1_@mR_B-{Aso@cw-7? zh29Nh%|iij@gt;YE(grOTs{KH$8-JTX`Vg*XU;BQAa$Pb;7i%jk z@XJ)LIyuE3Mhi6@!m$y71kCIdsu}F8H=XJ}k-;T2fqJ7_PFJPzK&M#*+;;~CqI||n zqrBY;$RqjYmPWp$sH+c@?fSXuBM=H7tXDUhcaf{Ir37Ob4mUqN6o1foG5x`yjcB{;6`)~g?(np@u*c*L5`;NyyzVul?JeO1a4 zP@Gf`;M^%(YfO=RQFrKksPuG~&+~kXo1Q*lti$DVHw0I*ZJKUF{H=E;ypsq}ODxY@@5>3X)EG@ib1HTk&lf#%qBuWz zp>WhIpg1!;0M1 zNgfb1%+y)iZ<6_*R|d|Xv!T;}Zl+m#FrGTp+MrNTzY6ysNJi-@az!N7?5=gzvDE0o z6ioWNyCj`4mTo;dPq3ucA(E3cYALWAPQ0P^htBxDrdq<& z{3JHD24^)kec0QC$wCIVje*>n>6V?S8IWWp1h&VZ8s*b>BJ{283NtsI!W=#+g{etf z{PC3x6S7~1FoITR&q0se)8HfvyWQ9r(2M-edQpGb6`!FAw}ur?h2zyWhrUWOFa$15 z_at<)3 z^j&3A)yyxf&;RO1U&&z!oBzm@T3C0jFUyF#zY9mldA?jAXK=}mup#<7mzydL^w^dL z5)SuHI6U`Zi|X)Qp)ig_H@fxF%7F=XNQe7Y!o&(yxQX6ln03g|Y+oAcjvR?OoJ9v4 zGFosr)-abgn~ttmn7VsyN7bC2$LQ7I60z4rzLsqQ0{=V3{)Us95X-1?t3Qc_#5tnDNl{B+2@ybi^O);)#}d(D)fT`>dLPV+)_xo=C2PZ;Em9Kdo0~OMv>^` zN~in&diJ-=ExPV%wNwYwVTWcer!8YD$wrH?cs&Mry+)a-kk!)`>sbpM_UEy(8Pvh# z6S2&0m1Fs*; z_8krgQ9|r!J=k?agi>6@!!paghvn_qKQvkC(%4dNwa8L!D<1n1BJF^&1a(G15r~C)Q0hNiu-#F`dN%WQBJ=3*Fqp4O zVmKXtDdyy}Fo#1O@pOsp&3-ARs4%J3_!qK!!uIaHnexfqSFi$RtU9u}EDCJ-3*KMn zv1U6}Cz#l~(xWovqA6_@&|99a_oQ?|gYE<^<#bK=!`{$ixN|&-VhC-&`I30I>F!c? zIgiyY_GSe2qF(%G^h)>w!ttGBf1cJ*@lwa9XVmnpN!oq;TJyP9W_ec}WGu3URWiC3 zRps@B0uE!VPKBCekCr(wGPLF{pWjbYV{r5Nq$V&C=Iomp6OL+#R>@-W5x`f{S)v4C|A zs|ZGSnagFBmSz1KY!=Jl2~ss-M~^Q|$r0*(?46%V?6=KUCM|^Vm(!X{p3J^7nUNau zE9qmdp3F$gQJQDooR==vu0E;gXG_KC;cPf(6X4mxb-iz`X{i;`q&J=5`}ygQ zH|VP@K!%sX*UZ!c$veA)>CyvH}DDoRbGPb-$GmI$v4gyQ@bw;1}-<8BK1U}e#;z~dL_8|A! zOZxvq-J3@xxxW3Qw)^hfWoqqA%ZbX$%G69v#i_EiG&M8C5i%{OoN^wJ%F5Ez%G7c! zO-(>?OjD6^A~Qz>)Kn6307n!RLEt>J_j`Wp{hjx(v(7ndooD$6>k*#kzVGY0ukmwV zmw4QWY}~kIJk(>z>fnO*T=qAg!XCG-yr#_VG-y)z@x)ALL|fNILEO_;Sj-*9MOcM2lr|I5esG@oKz}{bun8B5_d`zC{>xOfYEKYlp==Cha9xjeiJsihUI+ zn-|3QgDFx6&&_k48{}_M%6x0s33;AlI(u>-)l8($UK>7FR-?6CA^Dgdm*Cgpti0xm zIy(1mP#Z(>OdBMdOC4;u>f7)4Ucg1k>D&<$3pEjPi{T3&{eKi=FA5w>FQMIAzce-S zesf2zVoDOSL<1M)nmlryYsIhc+pv7n+tI22kUl`)h%{8CSNRZ+;&eQs9zKD=lY;~s z(+R6*-olG?iUxv=&SXsed`K_VkRVjU9qhB7BLB2R>RK|gp-PGC7ZZCANtCq-ZJn}6 z-0c+R+sRKM)4oxIz1#}g{Z00~4n-E!MMwv0zcM#}{$->jbPW=_?KXom{PenYYp>6C zHOVD9K50Kfr^Cuk*H+ikv6Sbqn}6r&;#pi+(jv^xgW+O_N284wULts$xS=`3>m&VA zXK^{-9-o+^6ftvrSTdnBCdRGlxTN=hnbk+^G)4*MeBCI6BV#EXEqYg_VlID}Z*Z#M zoMp*7KgTy7vK3YdM)Cr)zNqnlsRW-{W(uYtC!{h5UXKe4q> zhNWZTb(huW7)5(DmVdez6|({p2fA)4w`mr@l-$hfTv&>9VMI(?{Ph((8bj}HcM{#@ zjC+Jyk7?siNa3wUud$I$LYN)Hhr8Dn-)KL)S({UC&M^HhZ*H)-EFZt>dA=|{BKh4_4$u=@5*-#JC@=_ z&HQlIpZ&0RwM&+|ce||!nRi+iGTcD9wRk7mZnSxlDXS?fY^8E!4WKy52fRg7Ftdai zK$k#{E4N#$|0S7cMS5u58M#G0J1RcmE2s9D@@}!dcbl^=Ts8mxsu4oKWkz!E3#8er z3X}3Y=C7dGA0Pc2PBO6L+~k;r(NFHTW*m&dBxdQB(`pAz6jbT5DOS=`bS?$P1JV;0 zB183314n8YORdtTfI?`Aj_K311FN*Ku9PIu+u@%FUvE2GY~HVF$_QK({vjOP_Emo%MydXEWAiv)oObV&LM*6~oGwQg4?KVQDc4inxP{%kPs zR-cI_xY+*AQ=!z?f$=Y2&UIf~ zM5(+~sVo5=^RWX-l$lnMgfUT3D7zNRRhNs(=&|alx+1DU5&jNutUTfd_wjnnHCiK> zw|3mz%_OHS@W|rJ|R2hrclJ*@|Kk$Zd ze6OBQ5F-AAvEgyI4>cE+4r6xOf%0S4ke=;HivjIP)US0F@cKC&qUUgYiK)i>FCwY2 zH)2iuJoZ|iUSq$doJ}B`L^VFMnj79SKOuF-C|X3JQ>#eL+owH z2BnUpHt)#MyRdzh&MdW&BJkBdA{WDZeoE{mZu1}T-84qTGGdRkdC@(MT7wy-v97{I z<`d7+&B`1Vgxlr=F zRG3#xV#_JlesII*pyLTo@gGYkKkqWT|7g0@99ukE&9Tbj2#>E4;YY2rbm}_l&Y+Kk zqJ}Hn&EWII6QlD?G}b{p!YXi7!}?A)G9niohWZFjN)?)xSu0;n2pU%sD*ZIknon-5 zZ>>=A4#@i`PdaF?a2j-hFrbm=PcGR9wz@KaYm|C5*04|(e2lfTz0s2(-&IteRU+Ts z6*hjNARL!~%h@)$U#PsW{=V5)Q!{C8NA3=)iTt9Q*AAPWz^tLvNk#ZRd)-R)duMx59RnXr25gpWExw={eH2h zgTPyqpz6VY_|)mY+R1a~%`m^w1Z)8-e<$=B-KlPcxkd57Xn@Plg2r zojUq4?Wpy)Lr{BAt>H#`XPT;?Zn9qyp!ZhULjKp$cS1*>$#3a4aTi_m?hO6hO~Y@c z?ZlzZ4Z>-`v#GmmQLikXqt4NudJ?~S`x)tq&oc5eb;Wgk0UM%FrNb@sGD#KpB6d)u z5Nq9AHpo$EogVy$*+zOLK{+YV4%bWkc{!14!rX;dVrP&S7Sa%E#+ys60)O}*&J&W0S8-HV?wcfSQ6B>Q4W6`r2+jlR^57; zrD&aS> zBdN~!+zQ)jk7lXi1;EZ{UU7tyGOglyWf1TRH=*x=&6hNpd6(GCKg7UUNW==Z#^V=t z*AYxAx@rhz;zmCuqq@~9Ax1Z5sQEa z2+ap9fz4UCFxuN+yXT9pt@;JkoS+Bt)j_Vw?jgyx))EWEyv;J@=0%GZ_qy>MX+3k} z?F2qGJ#)P9S4{rO$qX&_2g{KLIsV$LW5Qp|XV{HdMB<$3a!bx0Nvq@B9~STr$HZ@d&g z4H0ck%Q`BezV;%4I9>UlVfwEoBAZ(5{e=4w-qs)NvPVnyLwhNQMU!=!sMk+WPlg+2 z#f9+5b`a{7|@QgP=5y?^T)FW1~L-*gg@B@;^3eiFb^93r;F(7LARS z7;m^3$5K-twz6I@SwT%}V-TQb-Utd3B!Iht9qM>tLTY2Xp zTggXsNcjB7DnLo}51^dRdHXkJpcG!l(%iwKi_MF$+*U5fVAsX4tNJNt*1xKx#!hMH zv&P8bgLW2(O*#m_Hsbd~Xe*z6#(!Ybs=d?ipw8Z!AJa*&;7oYoY#*ycXD>6Z1pElnG-zaf9}sj*?d1A zd&cH3!u^l*z||#$^gs96Myj_(cKSp5*&nRBXil^EKlh{a_EZBN+#Y}k^BfnYe{P;V z0dV@mAVqJ(iJ1Sob?Bd4|9nBLFXS)6mVZARCj=?}-@JX)=+A$Dc{UZ8;lH2RIopN1 z|NVSV*-T&R-_J7!0IUCV-OKxb^!B|or~OB29!bcV0HDkt00hdd@KFLN&M|pJ2E66- zYY~@=uD9w}fbFm{)y-&7@7JA`DTlo??{bLW5l9V<@%+iS9`@g z&H)eoFr8D~%bn0xfJeJ4T(pw`{zxr{Ko)YM_sqNuRso5h@)d3V=;n>&m};OmYK ztJN}c_*1OUyy|}&fqJoZcKCsTfV1%voR&ut#;5Pef&oC=DxU)=Ne#D#>k^Q?(tfS#w*y1kJWR56E|_%rD$sFt)ztm2qnlz1DCE1AlfM4K zM1ABh*#RG$>@(^Jg;>E#eromrK1+1cU8N!SW4vqR#3R;~+6n|OTr;WsS-IH^#cgx? zIr|9t?%LLOasr*xe&mz64B)ue90YmV%hj5}2YIlj{a}byh&tA(x0cGocR;@$@l+WI!uDuWtt^(t(9fo%?%zzPoySet@Eiv?4pr?W220tr+PD;ww@ z3upYv8f(lMDCw|sX zYjZi>$5kA0poF-@?%&VytUl%nEmk^e)Vx_hK`J!bMi{wWSoFtXz_|nKQR$ov@1+DY z@#Bami6KjRX)d4IpGL_$S}4EYmtrasGl(Z3@4WT}TFijy`lsHg+7pWF2S@Z2DcfZh z>%_$rZvwnr_<;aLOc#PSmJGb|!xoJrgfj`f^{i452FLuSHZE*lkMr$d4^_|3wn^u` z{U%?!@F8Zg*-CT4$?HnjNMmhreoT2Yl7fvn?T3XoSdPrD1e zIfB0RHJ(%;`JvJhk%}l<2u$R#ij(Xh?N9$`D0q z0d_?*zN*80woAy9N64LYYC876W-b+cC3TXnM^et(ZNQlw4jN6B-G7E}1PCH&SBywR z)-jn3>+&?W`k)D5!)^8eHE3dn9M0L39@Zvt{hTC5&_p-_zW~mxfLT+#A{30adOh2e zESC#--&wz5{G7l3AEkLf$5Qr_UW{|cYA5OwKF$Sf9Lo2VarTRqy4K|0Ox$=ZJccMD zv`D|Jqfx!YZVUqA-rSiI%UCqwzL3s5N-vLD{KVrg#w^;KI%e0V7AU*2K0mEht@B*f z%l~w2cKBt(YDQ7kcVI=*YwfQS(wiyl+s!xDzGDzW0~#ZCjb8I2K^PB+f3iXJ2@rm% zMPjj;7m!=p69Me2e5|o`y;p0no4DIU^Fw$FEXLZ)SVP{3R==YDIS&0}VXRRhN{Ju9 zGBcnR8nk@udB6AvZbx!XBXwR$X@}o(H0eU%y*{10ae_$7rucsZhra_gBvv<0j~r&< z^MkB16X@4Wi@I;p`kV`usKAiCGmV{&m=A#)b^XX9vCe9BS)J;0a7*jw8y^@?)L=A< zi*+31rQf-*S_m=;p^4kp&u3&;uVH!&c$nZ%QKP+4eH5S)*95@Bn*dF-hDsh4z44B& z8?VywEBTOuK9U4r&oqreg1&q|0_Fvve|?);@V#J5+evzhHlf{}H5NftBF|9LQpnw3jxT-I5QxI$Ypb!@n?JZ=San4K3>+m<$TFOcQa@bMHOLua@@i+(YuiYI#iUu zT|&&`1>f>a!Lq&mW1QM1Ab2=47A85mDK(pYFZY;6wp;=|i2dpt+Us5X;S5H^(9znd z?E4puoSqaM^PLk>&nJaZ6q^&|8oC4gqN9)r=QE*9Q=oQrP5VB^Tfj0)!A8Cq|2r$2 z8<`g-xc&1j#xLMdd0>pSBjZY(6EPOP7>nE{loWSdM{hwtrDD9&(lkta@~dH- zLrLI)IG~6GE^B$~H$xM}b)QQR%UQKUdF2l!-PH5$#6}fVKBTjD&j)X^SGV1({2F&e z!EP+Pt6TNV(gtwwBP2p)jG1XV6F8)5f(16{v}w$zKsf1~a7tTlFVR;r?91Gn5tPY^ zu)Mg1Pg>&a`#Mj;Lod8m4(+5}j0<`gaV4-UEJ+sN?R)Wem2M8j1d`4f2jXt|jH>ZZ znbi_nedLGz86y-g)U~=fC)q5NIJ>!>aJJFdj~#n++72#Bay$yh>%7{Ak#{olLB%1G zs+TpKuQu{VkwOI5`B^ApAoaDqW44nW=kURDM3nLyMMDI zg>X$syI=KgkO(d2;L_5!QNGjbURqqDes%)E3uqP0J@C^A(%m_GVQulTL}v32p~>u7 zTv}@C5k*R~94yjZZd8A+I>2bMH&5-<4uB|Rl0>VLv&k^Z)80i_uRrF-M9ZVN6w6#i zd^SLxR-_4I#&oMEl`%EfI20hzJaH1y$n1Vg!G&h_(1NOZywo~)@ARr)H?t5Lu!h>Iqa36tQ9@fN6L~(;mI@0_K4eA4Q&(i zNc+uqD{ZqzL8G;i{i`1MkXU|$s?u{(=dRl0Q=yeTV0~d&iwkC7gZlpHw->HtcpP?a z!0IvjoB=sxphlb?}8d!5bK; z>6#KYWx@BlzrW{lYli8vmU^;moh%lAqN7%ePTt>M=1ZZ>Aqtj{^CpSkYja>{A-QUA zGY^jjNEl|Qy*+_IqX(*=Xx=*0D-GJz%1+)1aV{#sCSt2j;Cd=)E?*(smm5_S zWZCh=f`%&5zP1N~pB~!@jU9j~97awqA*DRC@LyjTQ*W9j8(?Q@rL4`0ZE{hc7;^*1 zMz{O08qdzBI5hGUE^HQ_g%(4Qz5C>f>SB1gn(cb=`v0MjX>bd6LBto(#T;)@A2fH| zGf>gr)wEv3LddukJRjTtfK$Azb3ncLhXbh`K^mt8xhAAO^&iT3vcFv8jojfo=%@7e zD<6SyjhmcSOk23o5B)0a+i2fEoUQZS%6F5?T;$B6!utH|xwKmZAe855r?Qm`IX>Xc z^3*nY(ThY+5UY7N2d&yoN{!=u z=TXQ|7;_NR+>8XcDIi6l@HYlKGk<0lwwCHAxjgn zRas`w~b@~al~pb)FMK+8* z<6BAvf@WebiIz<_jD!%cfo7hs)do=jnJt&%6LOiqF3Iu%0YcI^9jOcIB?>h5fetvA#!DxkK90hsXg36nW(K@> z&VH5+bHG=w>f%^b_Xyee#1P2*Ua}wbit3^0RvBJI8prIdj>*CS0a-&Zy*pZ=1bgQN zSO$KR|D?~`y-3?2C$^gV=ET&X;rtmtGUoMuCVKHu#L(-G)E=9ph67aWE+dr zt#=aWceS>!f_B74RP&zbIgL`PpXprx?r2}>l11t`ceqipNKwNgI*JMEl2`1*TG~aw zJI%;`E2Y%VS0WImNuDJtkdO*aMD~z6OveiA@9q2Zf!|PHXa$WeR#O77!V5BB7p^k! z0yIXetR${tt!FzeJW&Y5okPg+%>{x)U zd%THNnfy|1o-S2#ymTP#Zeci!+2q_&_RR)}LfX5f+ZgzFf(P+`m{_hgG}^&yjXKnR zc6w6(7=|0_>?uQ4$+hr&|6uqsuC@nOI_4o6buYhljr>vrrA`j)B+Vq*lT@Y9)y!ePS>x?}4u8if zyk}H2l!nM-B8oWk)IWvlkA%xwFij`9hjgW~rxP58S^nQ|9yL{t9k0%8cTrEFo5%*f z$N(w}I%S8x0vykXv4$`%(?knx9jGqnRU7Qs53};SS$|UNKt`l$J=i;<|35W3Hl?gB zUfo$myJ;95_tetB!*09O+pfAGnvUZ(8WO|TVFIi8wl1E?+oKlcnVqnKh)d?0E2Lz? zme}t@R|h{}85frhh>bY?Hg^F--uSuySV#m}d6tL-8Yc0-CL|!(mh{QSmmbYi&TcWT z=69lk+P4Bm&fpjL&gN>zzDXtGoe>{5*(yWJ9(f`doiSp_eKu(rRNYadXpSCmbeL@Y z6bwjtT`$R(Hs1|VMD;AbCt6!j+(1Cf3%S z$;}AE@{Z;9r;C!(>23)e^J^shAI$xRvtVz>b?8Rbv&kLaI`e3~5b}aq+ZO&f@nBV5 z23{h^gaSGNOTJ0ka7ZlNkeAgAi|#|2RH9&hi3J}t%0*sA_;)RW{`Ce%adu*zZTNle zMC9h)@rYCh7Oc^5O-rIsieO!W$E~rSf=8B)`kBIyND}k{#}%pDk0;QbdND=3nRaHD zr|V|jb5^uC*X1bY=W_t7RSuyZ)F@E}b?xWX_jl3CWO;3eorQ9LFVa(zFKVIpuCD8x zEbe&uu?sUIj&jaHL5YJyH)%!#TZ&FZWazKV1#VweFXONO^|FJ@0wk^XiNed=mrOsE zw3E5+cV5jsAY@*loJwYR#O!2msj2?G*+g;9Xuj2O41)d^|-Cwj|jt%46RmYClDR*I827F&IKJ@WokU;!fx!qWaATqy1E=x$ScHcB%V8QCbaXt&C2+YbgjwLjc1E%+biO(GDkm z`f#Kx2@-cuu?1D#P)dU}OSR+QwvlQSW96(G-ydB3fV~%SCE@PIAPogyU}rUkws9Vu z(ZB8xx6*d*=7xL+k=3=EYE`M2!n@gEn;ZBXMae2ShDuTc0wx|x#QDzpLEtpj2e&QKd#%PoAIO(+&g>i8yX14b(BOq_ z$*%wg13jv)TpoI?*Hr0*TEww9wJ05bYbc%U2==Sx-E>&JY_(Mu{(tVS9+|Ce0oEO> zE^B}z&(~+D=0&#b_R><6qne^k+>PI<(aV5XTZA|BEdB44h#fduqhDe~)$9%#xcBNX zAUfr%d!ko3MT?_Wb_uQ2^2;6V$cerrWir9sRKajvdt1ZVkk;T}8NpOvA=$%Kd8-pP z5n8q{g<;B*kEkU-;jmv3=AIqR_ZO6bTXF~u# z#kp_q*Qv$X=go~Z&S5D5eQwMT8J9PNz6uQ}GW%5d8bLT=d`=HV ztGmYdc_JTc&qJ9w?fqY5kqW&cJ*vH6cv&SED{lpO+4slxu0J+38wKJB7VsjN1i=b! znS?xPC$63Z8|}{4gW{UUrm$FQ3TV0M|C~df#Rj#TIHtE~y9gq*}J+f~385Dod2vBOj7Z(1MpQMd_ z*|828D74V3M{fKS&vPUlw(@fH8VSw;CsMYYZS0IY;#X1S*>q%*)9ao?@49(te__MT zQz+{m#=s_^X~OYkmdRjO#qPaOC2KO?s;xD}|x}p7F*Z97ttBG)H243Q-vSwjsMTcWKMRo9;N_G{p*4N++%GUy%KJg|SWmNEH@c$8j7F5Gu& zs=fVceb0Ba=NCjNEd)ojNG_4~c=}sdnQKI{Jhy~C2ULprw@!|Q>GFhG+B1>s%ns>w z15ETQERi=%9N(8=@YF;r3RCSY0DS58?^@wOf0vM|dtOgH)3+WSJf|M4n_+LHG#Ik< zQ)^IdtjoY7w~uIlqMH{R&I)SyLtg!8DqKLNcn{TgdhOPR+d`6qQ303pEhnB|r=u?x z^@r}@qB=rb3L62lt_dciq|>9VrgWYkrjG^tknRsal6QIC^_w?ys(#u|!VD5ECZRC30HfW6EXhP59yZI>e z`+@JIb7`TV+{SPgMkjg5disN`|8f`+7Dp+ir9VR$z0!Q8`N&zPa>zcJxgUG*zl=W% z#tToQyG*4tEGoz~=KvwdpV?Q~L3FV+yl(r5PUG=c!Azy{YH|`RdLjC0b>NmV)C!PN z87-eZbEjtH>89Irfzk)V85hWOQMJUZnQ-F?tPRB@&?69YZ!>=!j9JGmD7|M))W5e~ zS~}0gNY`C*#2$Z4ue@0Jspxtx=HnNOhdinE0{yD`TQXZ6CVQ@VO%;_ZMW5|PW1CS) z_A-SlY)7uUQoI1AU6$qfj7Qv0e)Dnar**q(9gtuKbWkh#piKv4UCOxfAR37Dod4c) z-G*D0==AB^mYXNbZg14u<8^)}6>V)-@-U!cM!Hr?_nanQ?hVry$N03z8W`?|$d_c; zKzPLzRODsd{i^A8%9}np0Qh7a+|U^_1eRtm?W|6OI>ze{b)T@g64HmtOq!&q;a*lY z6`shu$XELbJ)@SqSmyER4;0O>Bx7z+(TtFJIzv9}Da}{KEZre|hqHR~n=o@$L;JuR zlo#J*;p#u(4Voytp-4~+xe`kbO1)s3oIt0UD%4kRrJ?e2i-6!Nm4$0GmpC)Wm^Ew( z6bm^oPc;}jEMOhLL`dKsfHiTxj8X%T9PU-LG{^R6bizz_OYbYFkcQMOD05dT3p&=q zdY$hqdnAE8(ZY(Pe7auLa7`6$ZSi&CH5v7T3Z&-nC02MJ56m2Cx1=}ZQ+3-LIncP< ziSf+bxSw7pidPtarXur?NwUjAEpjg!@wc_I*oQnR;%CJHX$F8aP4-8qJ2lNb7}oYk z2?xT(Cc@#aq=QqUQ0dxb5B+p5LCj6UIZRA$4~{EcU%$T47#oAJl+Y?ck93{$C%?|v z^BvW+_~l(A9imDO@Jbm*r|ctM&c*f~S@>YN4iWDzV>|mehV@;|i`VR_n4Uy6$d~t9 zkINliJDHKNTC)o2^1W=xIT9`o0c-hROOjGD^eWPZBn+&O4#dHImTI)}JfaU|+GrnL z9kx1^q4sm&ue{V|Ung~C_3$M?_Gi75C)!_?G`#M!0d6drhDWcCsyD-&HS)5YZ|1XO z!iRoaY%U^;&5V8Hw1&zK0oWa zD$eyl2v|GTG(%9k6;4q`rNP9hG39IH8{3ETq%P`f2pny? z&O8E06nq&}$p?TkqWqk^C7c3;GPcsdPG#>^ys<^PS`r!i8vPWzhZ8F51G#Tsc8J%2 zCnBG{yx1zrW|j)LWSFL;&VMu%?bYiNC; zG=qfSrW07$W5p zkNgwJOZXW~DqL*TRLlp`&wKtf(RF)R0c*4!J?Cx?J-TynVly!zT^^@Z75E=KBzhua zLX-@R4sJZHD3|NJsbSOoTFXqceB`33WKE8--$gV4dv0bV|MGrnCX+%nWdG--j?FK{EZ6_QFs72X7k2Id8-c}YKtqf%h z0MQ`h;vYo=t?k)uD)S1`S!)>Nm(^;l{`Kq8yTxj<0VM#wc-lr68&Ed(A#V&hX5YT| zEs&qNK0)>JUwjR-?(lb?e|KorpW5tZ49rh+QbvE=Z8qU~sI?UA*PbhTY^m^*qU5}_ zt|0!L<2kS8A1-XEz)eE#xUx-0BS+y~ykbF+t0{F1_C0A#!yQ))B*T(7=c;=c4B6|Y8}Am!-cg+n{Ib!=?syooGk;10iI`xm{HY6lj3+^i_}7Fdq^s+Es>(V zH}DQ6m<}8-foXML;Cp;5uO{x*z{dv9ed;?(Oarxm|JSfM3W2qp{|$q%-$L$ zal6+@ElM$5S{8Z_h|OR7C%tCV;m;f_1>&a@)94L*y_mxQMGAXE-RC>IfLSekn@)J0 zpS~MziI4+wm1F_>vixITgQTwhr)>VhA{>_`AeWmhisKd*FrYt;d1h5*&q9D)+ zEfI{<&3lG!t=aZ)eC(1}i62Q~q8{dl*J^unW2i5AGgGWT;y&!E>d!dU82fpIaX0dC zA9FB1|KokB$*(T#ZyDylQrh_iXlYw}pWle4=>MLXcT&i9u!>OtY-ij2eGW5Y$+4e2 zBa&qsbQSe*YU~2N37+6*_)M{!cmLad}%)lE3@b^NRs8t*j4?tt?m}1(05g}d_wmsrWz-6gx~BrkZQN4bbDInQL$-E{*gX+M>Hm_&{eScRW&YBe zWPs1b#BPY7LSoE~l0~E@ul-->1ejer^LVxu-zz5eSp+c>8w}|g_PT|C{Tpp^(JrAG zD9LLoEi?h}FCsvY*r{j2&3w}e;751>a{|PPfqeu3PPmz`1;(<1Tie9MI;4R`{pWf+ zEqdiYSG3gs_qTf&GXCDe_1QTa8&JQd8XOUZ~( z=J#A)%weZoUepJWd~qv!$Q2>tU+9r{)pq3bhxEN0`nwG-+RZe|Z2mvf zJDVoCC#CVp*W-!u)EyI?K%v9@6iY|Z^m%IFzc8sRjBHBk0g&pUl4HI=rw-u#cKn`m z6ZK7WrP^#l-5>uv$2$CgVsC&l_8YB znEaduQA`Q^cZsu3KBSX2I7^}t4qlr58RXjHK>*6k{R;ro8GdNWiKhy~OyYv{7vvMa zZvO@hwhkEV;^x{HTZiovoTUGni#4ZJM-ls#;IaFay^O9#*w0eBxUvy!CqeobUGv}h zSUX4%(qfxlJjnr4XwOy~37aKbw``o7;M^yq@U#u;{vDNQLYhC##e;gRJHGq^7mQXwMFf^dd&_CaJ+bOk!khBpA;e+*noVt7z ze|%ASrBUG6Vq@$DL9{*%V132R=c&9(y5T<$x_8uYR|@DW z0exuM@zI?mV9bNMGAYxx4nX(8J^y^gyJ}Yobduf zCwNo26;%odjNziGtP-{6SisRePg;ISH9Og>gDsl{AG@=l1(fY!%QY`O0>GwUpk_6( zKKEVYD~1LOznpE*EaJI{F6tMA6A#`ofGjL0oyV zTBH=k6!2wne9>S5ycn-d)#M%49r684!05hKas+PH%{imc_xLB-^Che`Ks3%e0zdoF zSqmh=ITH!9Y#<$K=9}qtJ}2nTCk`!X?3yKi%$jdTj9lucCmk_KbO!X*qrOtJ@2|D! z0EAUqO*H6xAFuCEfkKos?PW+StAs@)6+n~%6~hB86|lH9q-k?>*vLyVXcM4ZbG{Kw zHU&SfTnxwi)85$5`ZZ=JIhqOmXKqAvi9zHPS3V2eRuBIToBUj# zy;N?>HG^c_0}?B`j>t{Hx-q*iUetky(!3_^98S-~$Cf#hjRcW%84!MuEAM0ce!Zqs zEKD-6q(%a{`(eI=N7pyfde_nI*|dootGSg$FToPg3Q3ciV#%4F zuGnnEdPk%d1{AHZCu&GzDFSw?QQVMgAw<{Lo^;h2(%8&=V$zVJ@R7fq2}Q04_r>OY~IsirZr7sW+goW&l`(& z8`Qp2&N`|-qrq_qoit^#h*eu(XbRI=sb|>jba{a z|E;#}^&1>h)O5)30u)|5H_bFosFG^bNxf^)D$}z(aWGP1No`b zO^}7So6~_g>t^YOuNLCSnegl4^Lq_Hn8Z-J7F3kikfY1JmD%RRD*4)7U=kAw#f8t;TOW5POI{15BGx5;s4j1YU0tO- zNZEI0=LW+Ti3$%R-gVul$(jM+Wbmt+1j>0ROk&Eq88|TR;06i{x=}W!>%abDL|NR% z8jd)EC>`4eCbdbFzoU6G(%BD5-Gsf#x1Al3ngsVTLf4tOgPZ4PWOPytpDpT&w#_}* znJfB$&Vo22mjQ{!?zb2R&WNbe12%bhyp8($IB#|68U*PGz}5}`L^<+9H4oHHFKXb)$EyGsZaUNTeJ2S_w0OE?=S)>)UB+Yc!o8+60g1gXqHHH{tr> z3l3!hPCj+Xx1*5HbLs`KoW6E3j{D_*^~yEvBPYZ%?n4LGz#%L5AjDmZ=*|)}UW;!r ztdVzlPS!^XlAv4~wKA0(F&^bdDVLm04*m(aC#sKE8*c8}PfidC+;Cq8B=xumtn4x; z8X4*Jf&ed|2){YM|58}*68_}Fmvf1z@RRA`8hN?w)m0o&0e7kDBMP5MxOfJVJK|qA zR;*H-3>?85x!JrdQWDKdhOnWL@jW_K&_XMXPlx^2J$1yfBWboKrRHw?u?@D2i^u$- zg%8uWNlm1Y+M2eDwC$TI=3`xDqOabp1azW@5XAW%=9OcYg+R)BQK*z*h9c+m?IFyZlfM3-uQJn z^BBy!)XfDq7m$?-wfBOrr-h#Fk2Q(ty(d+Mi<>Pd8_5b^YSW3rn)_a#u6X$Y{NhD4 zP^=KB#n}X`9ZI=E?v^N_ss~jn7~dugs4yCsA4+2NcK&&V!~H zicX|VLO)QQBxd2$^yo`pfYYp9T&j;lE*tVNx@v(he+1&))VWNEx?W_i!mmOvE|

    }RRhPq=AQ`t`T6ZFW8=HAy0xy+Ur5TmBjU+&httE8 z{^7Hk+_$&f?hlxWmQbw2yQPu3YJoag2N+o>xSx=b50uO0>SFHx;^igrIQu>5MJ!wyJt<*>~ zF(Pgu91YHic$!;HdS#)Z;T8KfDS+qHfExIvTR)YfR1kU-4(Dable96amb}zKz@m%= z3Z`}En<9ZA{<~6lKA+zs+ZtU9K|7EbjL{GvKkr=5Gzc6wsudYbzIMV2lb3}+74b+& zk3RibzvQ)F-;I^Zq@?#6#y~O$(Q&VzPBBPe`_u5`>wJO9C_oVOpZ(th@%*(&eRP9N z?Sv|D+%ZZXutMUY=;&gVm`|2Q4YD=P(f-5$JO9O?nQhYV)PBZHhq1yA4U>K^*|Up( z5jsVT=fl4-KO#cn)s2Pw-PxGZTeMFa@vwsIZ3#Abo+=Di2Z z>*1W0qnfM>SgWL- z_iTiC-uJK?KsJAZuhw9tfv9S8Vn@&>s430mGYGluny2IQvLyGZmz`IOFV?hkoAg0|hQ6#uXZS4qH_M%+|K7ETWH4y)L6DJE zf@U+~EZQbV#iF-J1rxU>*F&b0QLVZF;QVYYVIy+sbyG>t1`nB{vN@ct>1$x!ab*5L z(H`Pg-#g~|CTpIqw|jC74sJI?H!XitV}=72pMe@A8%{@HIXu%oUGjlel+N##S6_z=$IU)Ca4xTnPl6RAesMDCZ7THq)Mj=%QfW*2`Q zX|L{^s@~2mG~J9B)u9$SwzxTwYgrp($XV3m-=V=b9RVdtQ!pLkD`<0TArb+>(|*dE zpP=(*@DZ5q1B{?wVFbLfEZ5{5rXO~dXKJ+O+~7PnHKy52-;2!);oA~PgUI?D=%b6b zQa?_51xAqu4;tSjwT)VP?FPj3T6=HiT40-~5;@?J0qF{^9G-L0TRvUg<)gltD?Se4 zjXD*z?74a}eC02%oZ!b$j{~zLZ^7mUfYYlm87vS0fx<6^o=v*Sp`r1wh0bq*gM`jk zVp_T5IKUjemei}Ja8AA5@3d@tp&SG!Yx7z6M@3#xGswZ0m_f6PWk)`$&2#_`mrjtb zg&oDL(GHUUEmvvgxp|F@zwmqYw(U*<+;_74MU(MQ6P%2ET#>9Q9bO;d0n29F)1{2p!Kqke);w`SC}Fhee*kxYY|v~#Lzo~5~JJQmkV$q zChPSNB#$;tyfd~nV+}-(JVKwkRENddN;q-qqgR>xys(ay=f{rP<~7~wlC68fHGG<~ z`#rGbzk|^&tdj-)o5x_MKsv?al2X?!$8uVkGF6do**eohj#pwx=Q8b*Un)BfUTZq) zVP_QmLeq*>pOrmze0aeojYzqKE|@L0m#~gm2ZUIz@0EmAmt(WVlLjGE57U7Ny7f_@ z^1*K%_Ac#P`KMIJO@-fj?1s$m9gz^dEN)s4aFAfmR(SX$0AAH2?SodMKq-rU(#R;{ z=QiQmD3XKrPc!8e%+{H%Ja8V3?2gAij?;A!7fkB)Pz$V?g-WJNb*BBxa93efGhmwP zJP6-h$`m-Mb5R0RpwUJ{9XF^ltNcKG;jD6p!gd!tk2}5?q8e`u=OvpB4 zEMqr`!O)alxUZqk`JC_f{^x!?e)r>k-2Tfs-tX&uU9anUy{_l$`Fg%a#XwQahWL-q zLUX-oB|01Z%jxLGfGF9$YC}xJXU%G$4-~MI8n|s+Ve_0KmUE3Xzpen!AakoFWvRUn zw)s$6^Zqt+X{-h-SUZ1>s<>?+|2=1qRwNO*C0ud6knXwzBm$FZjWnfxSyJ7j>Nco4 zC3|xIP6(^WGNB;1WP!N&4p(GU6{;@MIQ2f6zfQn=*x0LOp-^pMO0P2#c2>Y>SMFmh zj*BcsusPhpS0DiJ^1q?hUSRkL)S9LaQf8QKb2QC=dZM}L=>9ng&PMW=MZw%XQg6L8 zm~IJQxFFejd3aiQL@r=cb^qsPR1i^ZruCxGEXLWmfN9daN(CLs?x#YK4Dk{p6?B9- z$O)^b#G%ReLTS+QL$^t(p%yMI@74F^oE8U*+~#^B&z9Z;dJg>=@{(T5r=?*OfjY&v zn4zKES>EMBaEdXsxYYdUkwkPX*fBZK`CU-sRmWZTiN|%81`p)c*fO9?W-_xl-sChS zDS-NSeTr@RuD+@q6fe#}3Wam$Ikq)HykqHCTWWF}VI@l@=6Gp8&CmwpocEr@!zUEB^oezYC5{Z|1x0 zlZa+pV#s`kUD*+?@C@Iqe+ znBa7@wERYuOP_^$Q-p0X&)EY40s!l_VSAyV%3+j#J6+s8gh9Zxu%O6}wRrFONngIz z@H~?e_4%rx{Ui~)mapv0qV^|77cfxsFi=7fdyyNm_2*hUwTb3!f%lV)wU7LT4(>%v zw+~DNdA^klJeowerD{kqqf>BjaQWlzQ+hQmfd3@7Qda0g5dbnWiRIRyl{|ftIjK+` z$_hkP@|#~Yi6MNxzMWQ4OMJI7*mtn1w?q!V0&x-UG+J4d_%{BOBwl=4xrU1?dIH4Y(Tt77D&qMQg z2&R#;Ex@V5nua?A24D-u#iLhjtX1w!o=NNs2{4=nRh#ROyXB{f5KbdyR?~%{_fn+* zeBWk5qR`{ z>s+#iBv^R@`dhzp6`Vrz)zN}Mo@VyF2i^a*IiEyRj!AGHT%Yz%f^Jl7oad{(3E7DJ zAnNn|OS==5dimE?TV@ZLT)~Nq;-lGUn&jldKqx;r+h~&gHs7*O|2%nEjt!DDlntb< z_?!S%jXk`;_Q%JXofdK&k6!4H{9UU@cj-En%D=j&NW6EgH}VHl;=l;cW$_hdqMg$K zxhe3&$US}u-kT^BfJ5pCfcp-#Yj>xj-gPz{t1ivCsH~~2iUc}N6b-IxjxEnuqggo0 z97ZdFv&k`E%uHhh?`{{~&uzFy$i(@(s zIqQ8f_6!I;BL8xV%-g$NuuH^%4I;~=jz)QYj6z3hRD#E;bab<@n3wY@GyjW8d%af^L-rm;9NVNx6cr<)O#9VwJM!yE*F*Fw3yfCB-&(Z z8+JuQVDYOmD}a4Cc7vzLtV}IVf(* z(`Pvg&t=EYv*z6t^SPi9-7fGrf_S@vNo!m?-Y<0URJvB=x=L*0t5CkjeFhIwI<9=$ zM#wWaiDcho7y-`Q%=ld~A@1XqYRfl_$Ge5vm25`rjz5{u+3(BQ;vg0iRWl zudo~XKHG&^2Mc2b7AwKjRT)2A?+Qs1d2r!k0azqqn$v0=nn`xnTnwq12nAP(TdYy(>@ z-R`IL?M&UT+f3D?LX=RQRHJITNWkTthex@q;F%1={6-IwL=uL2Aq2AqvH}A0;lr&i zwlshuYp#LuyHJ_m^!PGupM(W_8`OAqf};$h%}>o~am3m>)#tH)Xz+36qm9B{vD;PM zw6wH2J3VTwH0f%@#&crCGwJ!Fy}UF8 zE*JDfN)hGjKAMYUt0jxlB=6Og(<=l#TfUs+AgWvh6QJWsGV)Aol&F?=(6-gDKzCiN zBfe;yHM3~%St}`rUC@hxr7bKwOVJQeuS4uI;#U<`gp086@7RsFU^fLK?ia+|E-258 zlX)nurW9e3gGtR!;Guz795+#vcu0J{$kSuYAYQ09$x;$AMPHI+lvK3f|Fi0v(vc(k ztIBt8YkQ1ihSV|j&~eqWYX%rv4qub9XhPgecWJDckB!=dZT5=4iH}npqo6f+;vVPq z^S;_CsuFNBcV^-njGM;cf#sg&LXFly>^M=pplw!9&71=*8WAP-KucgdsI2v3S5+j? zk-Kguz?W9WLYYQwM+tv7kCZK{1QD=5u z2}6c(*k?YmUkTra<-U0 zsnm!1B`&Jv+2@Nn5H(qTaa>KAfhL&f@?ZtGSjBfABOsIVZCR$ma!zrZl^T<^YfVFU za?gemI1mqfm)9oO4?;k7F-Ju@bP2+6x;{{@?37NrpA9^7!R> z@oxPH@fC1bun5}Z#grZuX!;Wv8t5o%*PmyW z;Qj@vrR4Pr*rwQJ+T=!$h^oBYgXu}n|HDOv=GW#!6#KQfpc`%54Rig!+x}VTs++7( z%pcb8kvce2C@SqP2=Vf*11CL7bM~*=Knx;o?yZ^(kH@uj+b@3x@aqIwyeJi zZItia0!pbdH2Q#9#f0Wjt|*mQJ}O?YT+1h7|G@$HDCNo0olu7m|I!z4^&ef0A|7fB07E+c2rmoBRc+ z(Gt_IzDj|5r&Znza{=37(eFc6!_k~10x_GfHM|uD6nG|T-}c#Fo!*?!8JHS9kbLPQ z8gA)dsG~Dhpp8)4C=i>- zJ6e+*N?KXjcsr=^bX?ZX{@b5~^B+KGLk#nKgpA$m;h1=;jidTV-|Z_O-|Bh%*m@lK zULk;D!tfJlEc)3-oOEA}%Dso#FoB9NR;sWlt>iQCTy(hCJ%(&7ts0e4jjPqRKkTJY znv_qO5tF~a;_m4Ij73~%x<^*Djc?)VNkWpw&mG0>b1#_rghdP_rtNQfoUR)JHmmTp z9J+NzZ$*EtxL8BFRi?E;@J?>@b3$hF17y$dm8|84Y-ovui(N>de64$ZUH*Daf_!82 zRzXEnHE8>&B%7gSgd0|Z7O&$U*0@ii-20?Oh@^?0Hx+vJ*W)FW28TbLtabNZ~Z;L@6Iv9SlNQt`*4~hW#QSX}#^=qD0r_i;l30hQ6(FG@azP&fzgx|XA@z5OeOsa-yawjN;h zYXJLCK_;f3J56L8PTVFU*?JLN1mp}{J)D5-%-=?yofumBXl90OR|tJT)xpFp-i&hR zWQmq+8bro3`xJ)XSdNSTTDT7Vfpi{|(`kTb*2QSo>Eu2q5Y;Mfg4mhnVpC2xHv*ka^EEboXj^0Q!2?`3b?_Wrj_M1U= zC0GqRk8vmNDqkL)KUiHL$ClNRM7f7WfIFek7jOlF=Nk;qO=)`pY}VGW$b^eddg)Ht zJ-6W_{PsL|Ynept^Bg)c4Pc(y9%>3Vct@4`=Hx$O8Z0o0?frh2#26dE_k8fnN!E;$ zSuRKgrKsZkP@2~Mdl++h!u-YlCsh2qNg}nSsac}g40n^q%uo=+u&mhVM-Q1q2cG9p zu2l`33pSP|2QgxXBXO|ZYoM^KDue5t-e2SL0e4oWCzz9h=JnPY-XUESBse{6emWd5 zd**FSF2d717p|+jn)wp5c|YKCK={ZIG_&~aZt=*yilw<)Z=51%1>1+h%FuRWd8Xo5?`#=c z4m%qM@4O>Ekx&_Pp#)7;3-6qb!?(QSO63fYMk*X(ETLIsGaCv0VO?-ejN-J+-9}ij z^57C~>&=8!s91FVO0RlUg_L+aM<-m_J%GkkxqqxhhH5UotzKjo8}b!mc;4Jd%?4KH z-cq}i?g5Ql5~&^HWDz$FYNDx!T%2qj+1<-H3tK^$tt2;IBRg=lG4SYYBN#R6d!QUi z4TAy zqqpk(>~>w4(jM%llAR9%BK|&y>1w;J?^Yl#q;;Sifq=53(rQ&W75?!0Ce;fU?|z7d}qjg$vEY&y7*aG{Nt+MM_WwmAc-&T9wpqRVtO z$OYH~9VOeIVZFL4cYsb96heyfrKu&y+jgsT{3T}eTU`22V=XSS2}wht)!yVsBxbpG z*#-@amjx~&F0_9QeSuWql(#z0yh330OgWw_ zT>Hz_p7*e(AV0}^VWEUuQP)BVlnFiJ&UOgh0MR%}iYOoWS^dxd!CyV2e@@8l*{#YA znw`u;y>SkDz2Y%);lOi;pN*&XXhm8BCvWrT{Q--9xnAjf|A$1E4%LEvq*;P09?8dea1 zZkC>plX?pbNI2E8?uY)eFk5`_1M&)$LfDeK zlQec5^AItli~_q;wrHaRv7El_vxEb= zOaXfb(kB)?TB=#Hy?Ki%clA0aZ1w)RsEa=S6+oD0!fA{ zUYv@MuuJfsA=7WVe;)}Tvvy(vGKVL*trmz1F9F$G81+}so__$Y6sUdnib)C|4n^kg zp)~O+r?Ir@TIJv`WKKVtNUF3ku*hLaX_t7$;1GGzHCobdMAKG=7c3(xFhg-|#b9Utu5>p+BE?7ZM>5^-3f{@DGTN4Mb zyxPr!FMS6hNeW`W0Agr0kD|nh@ENpsarz$?ifsa*wAVvYBDOjskJ|)pyET$7e zkU1uh8=OVbojap5T@83;hU&pfGi?Jf&+!5D?plSrb3V=1qH{gUT1uBJp(Np^b~zbH zor0gg*Y^sfX?aS~L(xFEFrGJ3N0t724&R8bHCle;L{59@)M(_ zhM$<2G5e_3yAb0%7Fp}q_=KjB{^0rVu!rdl*uL{vjk6$k1HVsw^^e&{j0nz}9#e~@ zWPVj!W24S~2eNZ2=nBbww+BAc(9+pAHDaL0@?M*mj_u;KeO;tRTbSu?$Cd1$LI79n z^?|4U-37&!3Vl%eq=VPos`{0M*_+dUcThNx(GM1aebLLegOk>3~X{rlk~>?o%(6GTNsLN|8|ZN{v( z0qQ!5t?r`6)x~^{c3PRcf)LQ+qd({P{<(vfAE`ZZnCw}nL-&@PXq=s4UxiXG+jKbbkR8ag|c>J!~A-&uk+_?@C3gpi&t8ac3>_ZNJ zUwiIgC_sr7bx{_cvykI`xXf{f%X}7|S>!x=$m*AV@jF9<|F|WhL+5tj6^@v^`u*#} zkNba|xG4~s-aMILy3<%L8wcP^oFqtO9X#sEAnZ0&W^KXBI*9N#iqA-F3nf&hc0qnk z>2Foe3R(~7vZe7_y5vxkSI7A;gbTRjfBsw|3#4Go_HtrfaM!D(*CseMAfG_a#d0t* zBd=KCFr9Yf2x>5$8olq|&mnk858?cS4gxQLOWHjie4CNCTnzGY<%i#OE0!hP+5dZ5 z>T6CwnyewFJ%R>aX50TFKVk|*QC$8RQW7g1$crI)A#4f$KeH1|@l8Sd&yML?lZrtE zYg^Fx7zl^4Y|p&EaiouS)v3AkK&`eR7u4+Q+>{}uMjG5)mRQzGu;O@?2NnUTMe%|7 zKMoQfPfQ0t9*p7JbdY{r+e~rPcm;bzn?)oi8#g33PaXK9BQ{irF4Wfm_%?}->IFHk z;@+EN)Px%`!ya{P?jfQPs!^7qqHC&0V8$Eou;D59tO(Mgn+;*t<^@t$PPm)hQ<>?&vq3ml7>DuDKIw8&Q`n3G)T)J^S=LR^I=f zxDoGA0u5NfPqzc0IoQc_Kw1(u`8)*^So6Clc{%?JYP3i^5rFYF8{MW zkmVD4^2fxIbM~yW|HFs3sO1CcRZgQ3#^^t#_^ik9ZQvaQcrlXs1MZsXI=n6SbzQ>( ztylO$2uJ}x@jTR^eU}hv1l3Qb2Jv%ye>L*b8ci> zWidNiN|)29TP1mYX@oF~NsW9?NYwzjWl-Jv--af-$M%Vs^fQ;+@~w9v-FS@*^+zmI zzngX$tk-!gZQ9_Yg-)I+|9?-L0d))c(1vVT%ACjOXq*--bcCzpYvfWg!vFRCl3-uH zHJe-|OQ!u4F!Pz;6qsOHP^CkGaDpxMZD2-D7u%;A*V$7ga0y7S%y2Bo#{iq|qdm-> zu9nF$!8Pi3h=rr?gM9B4w7A5rEKQ(nwUVOD4sJt_2zjk8ky9Ffm^AtuEWN`t8c@rx z8G;RZOY$&q>g)2AfXI>tv;g=%Pz};RvX|gJQF^N*9!V|o<&iK zkqVj(Aa44v_ovdLO}Y{U+#d1)tQ9D;YOQO&&6X5pgck@WwY%Tt$6L*IUTm|jxv#Bp zkz%RA>nG7c+t{>)NmY$kBY=6i1quzqZc~EDcg4l0Kq__JmU*-r38+QvHn3}Go7$^A`Be0!1o+sM7Z2*&z5c_pB*2t2bB~`!#+yG zPlDSl$3nZ&7B?NgQ0^V`H@hjbk+E zpQW^r)0sfb5IDG*q&Fe5v_=)zi$)7xqO0R{Y})lS z`34w?3<5X7vH~4^%600HUh!%s}%Oa1TwOtHILR zR#XGnQsa44a$ ztBQ>~P=1f)GXhNGSnYZz{Yx2y?HN_7S;GH%)NHPrj?A87(5j+&gCKaKfJv?UU9qU9 zz3s&U-J(;HbSFn|jG5JG)NeXRrD7h+$Slmg^4lnNEu~ai#KI@83miDdTUCdNbjq|@ z{IqogjNiSlPJ3U0SofJhyDd<8#I`qV5f!p_9IPoTpM(A|``OUqzK2lCD&){{4t=NS z4XZWkfe&}ufT@h5uCK4s5Cbz_gkp3_i)wsg_Tbf)#!`3muWy2{EGk+YD%pV9Zc|9f zz`AlpKR;DvkxUk_#{>Ghk%L)NXNKG7J)S>64Tp_@+4Id9TlU6f)_95!cxUuCiRa1t zeUx&niytWSYJFgVmx8cG{N;X(yBturyP$L)DGd}%Cj-amAQ>O|5(&I5Gi)HIdchG` zP1A7~$Ku;%4Tke**}eBU+BZ_$=DlB+K6uCTu1L_4Kc}~GDk->l6r@gpIjp-EczSu0 zXd5eMiVSgFq>S6BLY8r?ks2RBi&l>HLk5=X@bZ~H`g~}H{v8k;zOy^Lwj6kwO5oc#=AzWIx^fMO0@mAFx1JIwO&zif;w}>4JPgeb`uUem6*M?E62%)wh?w)QF_&-ku10{;%q$OO`xI5aoykDKu=Z3c&(Qy^evF6 zWDVM?7$qNgO&Qh8j-ws6T6IFz+KVprLaI=5^l(3somROoO}7fwSTk<&(j_iu;ASox z@`;A;pP>}!9_b7Cb-!_e%KY_LsbxnD;Q6{XKRZ@6U}L} z2ZduVxjc8*hQcnsqj^Qn?XI>Nb@nG>vVlC-l3VFttInqWiMmB zypYa7k@rri#jD5cE|%GB92Sx_1Fn5ex_=JQ{%JH5SPL>Hb$Sz&=lq~JHHS!_ zFVTuEJ#sCf?H^wlhryfY!M1|Ldhz82%aMfH*UlFZXnGnm#dD@v%T=g>JK!XUhWn36 zhQ{5*BdHf>A5r$xV~y|Yc*RFKPb)@SRW3FBN&ZtLXRqn|Xa#p7Lo2!TW){qn5?elT zJmj?@d0NS!xX=MCQ>~d;sls`&sA^#eBZLQaoN{#1S&mWC>xo9F{N^UA`5U&V_ht~ad*}OZ zSG+d$e|SM*7yB4eVGZ3QuSz=;>>nF*soOS|eT|La@E8Q?1*s|VJu zb%In4OwI1X19t4r%CZ3Uw)JD5}?N0V;yQud(u6CfPIn~2{ ztXlJY1hHvFfz59Uo+?tCCQ68KmWm4{(8`t5J?GukZXb4YAf@v#UA1RiNTb2riOiiK z#6;Bv>5C`sXT07cnGdgy)a4l&_spz(61eL-TJ4=+-s-t&x_&<6nny*H<08neQ{@LMQ^V^eqg3fD7xr(4lNZ^)eK<;Ib5lOs z#|zdlNQ$k{wmKMbXiJ1s6j7p(R32Om}`Y>JX3@|S_ezB@Q<#A_zR zSKq~KYQ{5*ISwE_qh9)W^7#6HsZx9)>8l?`%d}q12R%jA_b z`6K~9CKp`~DczlipA)|(b6u7wMz5wL9-)064;Zwlh>%j%bb<>w8|GLTqx*MJm&_bk z;gtBzOg3>eLV*b$re0Bvoq^2@zGeuu5PT5iUsHWef^44|xf9_b&kgQgQV z1WVUL)~LUXi@5rBuLTJkuG?kltngEL^82N2I$dSDO+B*g;!BBdnGQkE+O;0C1RbPm zC1`&~HJ*;GFw1T5AQIm0@=VNes3TBl%cIV-9J^&y^KiG5Q%N zMD4F;M1W2N>^8G~_qk@ZwOQJ$)bX8sHb56P%$@FL2J)f4TApu02olAn(W@D8d(-Tu z`T;sYH0Q*`2j~$_pf&{U1T;rjcuYCz7RMt5D9L>ZmP7EX*#GM$a7y`Rsja>tb+DGs zL{i~6-QHU~Ru%JVc*Ki-6Lelg3^Yng)}`-+CzU>k2oO;^-I(n@taQGQpLil8R>wl; zhKcW7g<)tUQf+)dyl`OtR(73rO_0KFM4jaTdmYn^R-jGwT>B9ng$?Xu|22E)MAsvk zi79NWg^WywC8Y*?{=}~p5r8BB_qG^sJ5*n&SNzq({)@a-6&F^{2$0_1K!n-~kP6PW__l~;4Rwq? zHIJlRl|TRtUfkF9D=-B6K9;=s=?!J?Qoi01oZ6ccf9-+z&Z?I%O)#=1O9Ma!0ZE$NQj&PC8f91@mTr4!>o?Y%_}DD;p-+LXN*m82|W(`@P}O@Yr3< z<|v?v1=$}_$R($Vb|1EndYABPe}Rj!rN6PU)_GlgsFSUL8mY<5ugu5q`1U-MW)Ee1 zgA!;SInrQ1)b$$3s-kSY}~!mb$SwrltYSPYsPa`W%rhHwKwRNlkj0OImuBcBHivfE49>7QB%q<|onDVHf`AGh3XcsC_8->TFj6X{1~cr0?->9GNV@A`Rpn z0F%?X6wM|OXP6G|PFF8tRQX+GWZ-B20$(0kiy}v~ivGB6p6b7hr?Qk0qs+!LvKg!?nUdvGgAwTB1_vf6qLv z2{dp9!{$G;$Q(vlEe7;U5&r4w&U80pkNu}lp91=Jv0+80xa+o!>l_j0MP=RTQsAXm z*SNm1k(=(ey_M$pvcJBz?W#0&jQu>jHTAupI5|mx?0j0z@w&sl$I1oRPhVV3bQfeu{3Bt<26ue`39z;h;E8Wt7jacXek_GnlBGWdv+d*#{ zpC}zon$c#m%hJ19FagyfJW=sh-C$bvGDX|yi&Q*gt6`wB+tv>^CIz%M^6H%`lX`A@ z;PZ1qxnyuzAcNPhd49*TnHGFl9OZkjB#ZzaVbZGm$d^>Z?oTpvLw%11T}~^epwXw{hew$}rfntL^*KpW5_l zGBRbxZdfi^3F88TefvkC z(3O$%Vl`!R#c$L<2b~5e0-jQ+^sf|Af|IW}-`seD)OP}koReEwK>nC5tHi8BIg#M! z?UtsiW9NZwwOJ#pft7F3l97qf$Z{PZo)|G+?{{yG#o5}tp_A>?2tYb?_^dD0N-Ei3 zMh=ty6e?db4^+zlD4Wn+rfjWs=|el5(cC7|7mSsobn|dC6fZ zw>9yjy6Z&?8CaC?3$LEyvyW8$KdWxnUm(r&NwKz(1EkJ+d=vi2heW=t8K-k~X(Oxd zX#LMM4w>Hk@ZkwPuMCfI*NEB(H7sf?9@si1Syv)mp)szl`s!sx;X2r}$Y8eC3|yj% z-Di{=uZT(|a$LGGDx1D2N4&aI(aYKci`=&H03@XMQAd60vR@Ma3}}SC3P5t@@J#(t z5z*e^36gZQR{u&wfFn|a=JaWM&@dgaSQFRW^T)+2RyQ^%nGATU#l6A+i~8kT;te}~ zcR~1$sw=lu93|d=FPx<1?S*x9@sA`Jw7D>yM(Z?2OaD- z{0@WOe=YI<&94Xy@E}K`AA|G+a9Y+)@htF+JovwIJ|op3pejl;@?UTKCn5ZI3h@8@ zue6iH2(sH-0s=-qFk>PDCac5LbA{f^$RPY)SJ3#Pnwj?uH%w!3zaG_2BMX!O=p>g)0Z|LU&nw^pGg9T0CiVwoNJ8>&2l<;?;052GpKGc& zZ|(hB=tEBOkd5r9z5sHH5q0}kKc)n%rOG%}+jY#V&f=?G2*1QskoUx?GYc@Jm*=_T zACJsT`GKg~aBtbG$*6Wmsg-=tK5lo1!fSol{0ykvkiu9z_07yCS-i&1iXLICd2K27 zJ5~HE8bY*^8+K^5layE7REzS3A^VF?vOz?Gz~lGT1)?8pAOO<@6QbYX>!B~J4_Y6( zpjmR)5t3e^YafAD0g4D@ql)z^{4vVhKH^ETL5+BDCJL4{fudPlBN#(zsy|bb@=p`eA}t^$mcup!vCZrT;f_+;htKcCj34GO{*GBaY0)gO zUT@1T9;cs+jk`NeThp{v#@m|_c*E0Z0bg+XR2w@tA3M*jPAR(t(@QQe+l8&1;hS`B zr8&=Z0u9!{6F{BoYimWO4Th4-qgB0iy(!{a9Jyk?JM3SXL_M*$af*>`&OfUOaKG6& zJxnT0YW9uRm?9O0r>^Uj$A&n{sH;?#{QJcIZ8y`^3mCN7PcT0WW>UT*_QFQ`ljZ*fiQkzr3BFb-Smw_xaJy!<%KV~j zWHWZ|<)Sk_V7T=U8{_{yCu-B1uM{gSrLo@=O*jBWkv98(8+vjJ`3EZ(D2p~`?{Itu z(rp`q&o4gI_GSR%U%mV*O$ULemCw{*T%mz&=Vfc`yH#xiW}5d3tqobrLB8WC-`SWY zE}H`9F}7)=PPT8%+ZREiR6SLyrle$rn43nc_TdDvJG1Kbgc32h1x!od+TpFR!VTJJ zNw{S@zTV1$_jTHzLi8@*<5`T4LoWfy=awp%$UlIT$tXZCTUCzYZ$O$rDdeskmk=PT z3jui*plvhu-a^s#?lK)`{HoBoCujSU(JNOP5C@`yzQ6cFz-BeWWG#dWk3hBW#7L)% zI@URWEIy?_7GcYqIg|jbRch%W?5xAW;$kuoE175s766+v_ugAqV5*M8rR>5LpBnMq zE9S=>@)txf$%;~x`B6KpF zQy?0mWN;O~fGU@X8aM0VF?H~kxkH01g;%0%`mZ#ER7+EC?Eh4vGcm+0!3-`>c*{)e zO?wN2uGN0)_HzUvkfC7Xz)dFdo3l7{lz_5$@K^u%3t|4NBNtUNza9TU26~W`&!rUu zt!>GD1EMF;lF!V5!vp{SVf8# zm9Z`&;UwMdr)iq+%XjJm))sITV;;|{!mDy%e!}i|oz`5(IQgp^J{c9XzZ&cAiu{ZQ z{b$w%)?XzT4mXeSIjU`7T)|M$44LnE8QNPU1EZ0tE=)g#vG8)<|YeTvxj-kGbCK-ESn}N zU9pA5oj$1-EJTAZfQ7uxK@ul@vRSI(7&ZO#wVTAa{;8x7pcY~*V_c-QA>_$0cOJIi z<9-mLPOtSVe$Al4x8m!iuUeT*VzY}5e4m0!38FAJ~DSaQ0ycs69B_O`quN}FqWLy?~y;i1f1GE$8= zhOuubESj$W}yi;ChrJWIgMxv%=QB{yhX{1fE(&4(?= zC@f!!lPZK1f;xKOr1O)rG`-(*K1P6|)vpHDh`8A{qbf&_8J{s1bekGpz5pgg%!(a* zB)B>N1$Fw)1W@k|qJD5MCF$g==y6Jq1=Gne8pd+K>^z0M9kPykJt&a#H4R+Y1_sjV z+j6pk>(U_4N1ufUxxtIC=y~<0J{ri?^h4lwH!04cM*>CrvZLBFilMy6CNSOO6cb;7 zE$W@l%8b$XOz#%}Nv!5%kqtP~KsCgZ*9>&{T0+_JH;9}S-Ugrz17Rh0GvOsvuD^~m zAPju?JDPv8)|4aSqy%V$;t?x6$y@oc@CRbW-`YlHQ}hb~F3C@=0o>!)dXb6F2DdqN zbY^Q#N;VOx!=gTraS2wi{X8cLuSC@{nAm{_l}7c~sj(ZR(K$&h_FIFtuT}UDgEGsP zRXGGnNW!C=#g013S?*{ov#V|57mo2x)MLDc%Fr#H*2x&Tz!+V23M9V&=Y`Re{TI~s0F80Q9Reu zTa3HT%rx@RB7h+3L{P6Im;AALr7t9?g}?j7`lHwIwueevh0Fn2|kt4`>yD zEbEAnIT&SM&%ZXz_@4;S`{j&KByR-Ydn3WCYdIjeX|VbV^j?Zwn0i7)#7YLwMgf_* z>VQXU<+-YI`c)TV16&eQCye+S(LT4wqh?Uh-X+KRJnv4&>uL+TTNxh3QJJJwt2Jtq zZA(V1?n}Mauy5QU^i~LIZ%>y82K(1c<4a{)HeOCV4usVA*tLaUT)1_Yk_SKgzel!n zaw_I=oul&k-baI%wr;Jp*=~w1fI<-83OJHO)YWuC5E1mA6Z29sOf78}2%C|-%+vofBVD{wMx+C z0!80Jdp`jK{!BE$o>Aie+HhjG!GS`NRjRe>B|~3pv8H&_m-k!?O%2nDpd&l?K8iQg z_PEQ&zw^5HmDjzf2lmQa2BYMT8+*acrEG1s9>uSSoPD}#l7&@@P#Kq*kKgcbULq7F zytV6jSyfsDJ1yz_EPaDa0wX+XJ|L#whC9u_Y~>1Y ze`q<1DlQ%|a` znjUvqiUXAvb{eCgGcQU_wV3mPT7OXAZ1_bUcX~scFPTuj9wC`H&e{H}Y72|c32P-$ zOcW&{T1vV~O-{i5-nvj*!L;1x6mg-#ArbiW=8FmLZ2xhUG#s#=C!&IYSnUT|qVNCk z2@3d0rO|`e;ZBoUOF4_-AGr*0Q;MPu#Yc?)2_njs0*dFc803IMuXH<*Zap7yhVr9X zyi!EFQ^d;?d$*mJ0#|rZ`3RJ z393cPRG3e41G#4{RjGjfF@N|7kun#QjsSbjBMIP|^D$yibW{b<>E2NAT1vFXWz*_h zZ}X_zJd8yYpf|iikz+zM%Btl(1Hi}a=D%EiETg-AJt9Lc!L!FV)nm}WHceP*bl3y#6o!RztyR3_! zXZgYQ2Av6;38w?!`Vc#&K-ivQ2Qluihszgeuv0shfMJjw;BIw?QeTM5cA-V@ucl~# zaUaF*ON`=WrZ=A*quO)X$EXUl(eo9^lip_sAe)+k0M30-T93$(sGGZ?AQ_YQ75tzF5?ad8^uilz2aQw58jROy}h%qUL{Hal>E&pum!Txzkfd;pE0 zgyJ9-ZdHzfGxY_migblk=x}GSNI#o*Zd)22W0%g%*wjqZ34WuZH3j%i^I879YWlGP z4T5Grw8OSF96O4mijfLD0XWRhZ7>(F81B~1$HbfZV{Lu8a#%pZ{@j*HmLuq{y8V&C zMA1F7-6cX#E3#h0eY{MjmI>%IP`u7L0t62DMH~AGZxd3!hb+o^H_xtY^>RNp+F$D3 zTeV=@nSTKr=!KX8{;Rsv!-tpcynyG|w)JKv)xczX7psh%+#ylL+pk{>61LkR`T9n zAYv3GA~psrjey|#1stBjT04kQz$Kw)A_-TZx3RXS#<=A`IG}kQx!Zjb&CQlj1!<80 zJYe@nfp`ib9aZnYRfY>y3d1RB1aV^c>+ zBKD#55EX`?>m|hH8@Yg#_Km`%)FCV9(yis=pB5Utdjt4#k5ASN-ix zP89r5%;-#{8#HjqZ{NE!gnF{>%gc?Q-Fk58=>hviw9I;c6B9crhUTVy_WSSI3C0<- z!hd@4G5SCQ0Wc0#SzcK&0~r`FaBwY({n`)kDXgwYagoacLS{f7fs5h7OXSHyQH=NM zqG*w`Gh^AEOHdd6~`V!kpQ8Vk4pjeXE-q;4ePm9QG$(*%OFVq4*c9tTk z9Sw#p9_LvI(JMD9S3C=sbTf;~nwGfx6Qw~1{p+tYQ3ajt1C53_{{g-pMe2$E0)Fdl z!KI$|es=!{ZIUx4GWV0Z>=L9!Qca1Irx#KrLFw(LYc zT%(92bp-gpo&4)ZL*`!9{a?g=Wk6Ni);1hO5TrywN)QwTq`N^%q*NrNQ#v*+sWbu` z0g(m)rMsnj(;(forE}BGH#d6D^`86w|2&>w!dh#NIp&ySJkN+~dh=J`r0J*oHf$|& z^9v=5<>}(PyR%>8Q)V+9Iabj)=tKZ0{?(ML!i(-JH1$uwgX|LTXZ%@MopbNxL(sTe zdpIwaeW60+v{;0~)W~}<^Jx2HPEFmx{g@T`8HEqhx1rf?;^m-A>({~}>FjV{IG7m7 zWmyWdm^zG0UvcE-N%*1yAI@?6#DG|it%HpzyE4CZYRJoF^I$-Oz z71uz~kj~?0Y&THUocsFt(fC4rA$C9E;Qhh*08O3mK}bp}bMC0N=2Yk8;9|?olrLoRhESnV8afR z2gb~zc#A0eQ0GuS%#qejk*w&kLpVmIyx>}1+{MG>Wb;K3R6{9mASRKWc#wq> z(z4bF$I4t`_2-oPgGK847+hvtw1cmYA&nyKG0@n zW_e2oP|UBGM^xA$DsB%|uU6Zf#Zd}u<40<-_$a%s4V~)+@cKp$gVTx$-r3ASWL;3&47HQ*~>U!?iEfH87fzKBeeftW9?dcpi_+ zRy{MH4e`V|Z+&Ae&om(@+G%-@3P1@lpaB80liZrTT^sJJ1<>aqkyXzNv;akBEe;D$=cV0OYvfz*f`%gFY65;F!soDYg`WjZQUEg zVGR6HLUYjPM*##G0-F`72{b#PTmR{XwdW}k#u$cqD;%i$k|o7Kz7Ux90`bngJlF*F zl%QYT$#6J$jmCvpS@9ppF0u$Ilc9AUP)w$!p1i_{d394gld+9Z%NvS}MHoq*`|Edl z69AxFr}p+siH(A#*n*qj9$6&#q#p1+jXpO3Ju*5mb8(<#2E56gvho_s`Q|`S9kYJ2 zza~C%ufXI-3ZQa)Bg=k(BxVqMA)7cA^j`;z+6(DF1Z9r&Yi}#pf&Bc-(A`AalJiYT zGS98b^cuIpnOxA>Z+|EoJLzl%4`XI;N5}K@t>wCIHxLvf+rU*7R(`q}N8XYT4E|l3SEl*b#V_pw1rLHz+lKgP=zRD*4(%pehCA z!MoVluyRsZ0AF_1rj^9lXa8r@eIsj-R2Tl&}CeH9rVBk3snM@+;5pmk|K+^j)E$$^#@6oO4_2|R<~Go=$g zM{~|A@j(& z7X{jj07+T`bQnmlUmdzTn5R=W{leC*taZA^6(lRMF&D& zbsW|6&zu0L7^U;;{WyZD<& z^`+9fa>0`ws3^f0@=pWVKcna!`}PM58_TTzw1vN*no=;7>N4h3@e(qvlvUe%F1ldE zrQ!>Z626#^N<7P4&96H@i=3I+Tp$UxAaUTW1qunq!5~+sSJN2&PgRb(2mPq#Q?0dP)8 zE($2Q#uPYgDK)?n=u5G@?#Q&F?^Zf5RSmwN@HBr!@rnW}d}6X8Y}`X`4J!1$lL}3Y zqhL5IIa0l@^QgH#VuE;VU&Q}8Pn6WnoaINU%jv|7M*})>MjT$2mFcRwr+&XPuLszd z<=9gP#F@hvaL`X2UIe8jw^yV)-OhccmbuUp8(MihZ%&+>MywN(qGkWRIwyNce(X7a zCGOYMHDze3sbQ&!3WAz9Ss1{t_Cy|+8F4drSHQ$cvmg5i-~KxT&5dQNE#8es}QV__OP+(<7r8cKt$^qJ$3v7 za1p>rQb3vs#wZSj$M&?}iD0-LNxnUT22sSG;!mTIO*VKn$(k zwx_mwfq^J8VF%9sQw#*J;Is} zD}p+qEi*!=H+jhM&_V*oUhkJJbrBlIHcS zoE8iGujoL&_GJ}glHgofcUJ0!RYFInSq>J=`g{&biCddlxrZPgnqMfK1Pl6cm+eFYFRBDCUnjVfKOPCE3b|_{x5)+QH;KFn&bjVAP-{i(^RJ ztX(@F(Da!?!Zi{gpX88U=RFc#+K<(n;YReCx>;WVTi>Tx#177qHVOZ5X?`7J#QXSt zrVJsH)CL>Dv^<3y#c=`d-rE3YZgQdSq&5QVH>f+SoAV4^)l-j zVG&fCszTKb;E{nt4FlMAskIxXGrt$?CZl)}8ea!X>t+h$7kSfYMr|l3l$7g@nzgPz z7(UCk#a+i-*;5+&@vL;H6i+_{&FppcuGQ;a_taElPBY@#D5#5E)8pZ zPAc6AxW5B4sg3b0VRdG0!cK)ro+)#c{OX+#Ztr|uH zKY=MafB(VSbz)+VJ>Is1K1#>q`xdhk28mXO>FL2n9FKKkYwzYdbi;orF)bIa4fuP2 z5ZZG87J%vZQJ5QKo=)%c!62{MV6?WSq5iiKK_wTi>QoGt4^dCun>&j@F&ikd%Krg4 z?K4dWhXA`W{h&c9EO8^_ScDIc#psuXti-WE>&XfPz;}k5Ps}J=Kt@xN)X#gYRez;O z-C*>!a-fZ&(6W9-p-!wsyaeiRkB0I+hTI9>{_m<6=bUGjJht;B$&{tfrz$<279zCs zcGV(TgpLOyd+V|)cTOj)N4GgxLLZXPAd^HYdov3pgNQOGfW5Acedwn$Zt|Ll4_MM% zs+_ou)1(YIZ%PU7Nwz<~3R5%~0K+x*{_N4}k?Ci8 zJT+2&X;SGBwvfNK{0He-DB7TObxw>4pT|Ykis8`RC5sj!KGwdz=fEAU?XBF)XMxVv z#A`)l^aQR^ulWuSAK}OK|6bjqcskz0P{1l?%C}&otyME;xF4CVXjA+dL;p>dQL4Cw z??5R8KHOLYE({=4cYv687~^2CCA}Sfkyd0ym>x=xmD{j>`w--5K1P-%DTna8NNE5nG&dJHLk2gC$lW145lZDTTAsEfY}JJe zn2jg-uZN23na0zhJG`vPz)iqQ(59xZjRiv)OGMBI{T=P|%HNkehJZju3?yab zpSN_qua&thT1;w0f@Ub3Adwl_>mLL>cvVNI{#s`elJ1wjNp*Klh6MMEb>fS6zGt26 zIVIwqOEG%%&jP|;Au9&-om3fe?x0Wq+Fk)<36uvpm8LZ6AOV_#6n>>a_D?0q-Hs02w+ z?pSPOObLoEMJd89oeT1MMggsm%Yy0p=IX3`Z6;-h9}=p(+IBw*?V+)rqngp_C&u}y zq^0pauLtFeb2m=7ah9d>UHJNQ^c8Wk7c3H6%=O0t%~e)jXK2}N(`HuwwMhxCR(G&+XReSs@g={~9tg<(lP5o!l>9RF zYN}*94!I|wN~rE&<_*rC{P?lI=gG-8)!LI}yOOh@wrmoAX z4Ty5Vv+bs2dNE{?HOd#PUnigk8&=18f6#Jk{Bqbl`N#EP3X{4^1HIDoBS;sJnTQht zkoRs)a|aEv$(rnnrq-)TPVNy@xE1=*w4yxU45Of~UjvlaUqBCDddX78KLjc^R<8cgTp&(*X|5?4S5R)umU`&woA?OFQ5EW$Y zvDV;ulkxPhPWUkEvMMwAyAk5B1(ec(5l1c3u^?5LZ(CyfzRv0R$ePP;m8ztEZkeey(g-;< z!&9XPcM_QB<$gF-Zol%<6398IM7hXDFfUfUD0*VbExTgCjxSvoa7vpe!zT+ zD5Mj*090kzw#)%cj$0ZM23_qy8S3qI`au)%|0I}S zQK(ipFfhUj0&H=->ZxFt#hN6s)+ZryLD?n{IfFT`;CE2$vHrD^azFSE@Vm1R;Ec7E zfm!w6iJ3JsS_^&PDGNc&m2G&ofkn#5-~26eWFMJd`9Cdl6>eZk=&MtZyf~1{*1|1f zBpG6G6PEvdku-N2%vsi(j0Kn_4H>f7PgLXnRU?Ies7HGz-dY0~bY&pjT&Z%1zRdA> z99TIp&@IE;iPC^~8q_oxFlkmir!hw^!@h@a>1*%R`0qZef926k5kNf;ij#zZhJ#$e z&rBL=@+-qYmoz~q24J#O;Xnb-z!Imym|k@#n^T#Y*$?21$royX&cEcZb?U%5c;k&+ zq6yExB)a)4Rae*kU$6Y9#OuFuMgBYM_@9;jcjETng!kW&WDe-n_L}l|YCz%a962Xr z`l{pDpZt}%Ja6st2br1b3!Y*rFz_b*|9ZrM_2ubE?d7Fm2WlJ7!GsS}S2 zkCXS*@{+1z@`1}p)pY5><|fW+!|GiXv{(KtHlP3yAH03{(O z9q(--=|2V;<}c5dY zja%m0z!w)kjfrR{#~AKW=p*mtj3<32_;Qj9_Co?+--`mE>u0g5OwzBnCe()#N6E?>H=1TQ z;iJQgQm>^(uW@(pr@dwp>>w&vOsiVtr5S_Y^rN)!A4Q*3f_8oSIv>^rx$o0P0XHOm zN6iLf|w{f@8-X}TRiHU($J(7l&;wx%-8**%HU+g1IrDgC~ItjavKh) zbrVTXE>@V5lQEaN@4ww`?nc-c$uQh#CntUqFv+Iii28`Zt~zTi==XCUSn5Vb@!>ku zE~#$d!oM$jikv8Jt)F;SQx|@kB2V9!ql_^P7}ahj>AGDg-}~L~E(UMy{Y74zq_;52y=N5FPDs>H-2mU*B zs=l15xtuxgIrUf)+B)9=gZK_6tm;ZPhKDt}s$OH>mv{$u?H%&7kXq1O`66wR_mg{2 z?|B3tU%mGe@(}^P z|9V*PV#QJnkpkuPMZTco^q0)S$c-$ac$aSzmI5_|&N6wN+uwG^ z!rdk(I@Bk^)F{Vr%a8LiyD>3Odx8h5%NBWI*86=V0{(h2ym%DYdtuj0Sne{Hse=gL{p^q;WH-5)c}vFG zII@kOd-=GhjCaGjm)w7yW2#Jjt_xCi*E$UO@E2DPFAmE0*qmH&O{>GhNvb_6T_PG_ zZ}Y`RZ{;0B7hSBtq_NYyTFvc%9WI!_%x-obnFlxaDN2-XO8+6Ny!#jP81>KlKy*4@02au>J62eI!F@lsVPhvTBH-zlw z7N>qyPT0oyj1_^Zd`fuSy>aKa}&F*=^R+ayjOT zp!30(F^FIPi^@*ZCybBzN`0{;Vq)ReuATYFqkgubb0#aydXK0sn8-5B_lR8mAgW%79#k6iA~ZCrL>yR3o_rtZdm z7GCl~*>>@0Am;E@vasi7kqpzb{*^tD#=1RFA{()=u+W$w=@s>8>*ZZ^IdM!3q&*5T zgu=!Bt9)dsla}W((n*A!28bv5#13Tj{EO-T*?D#@*h86cLCb17Sm;Il%jckM)g)fbw zC5%Qox;5?h`F}xW2$cI=u+WkFECkqKX|n^y2kvEv>2P zX<;s|NPm`yFT1X2^mpvs3=IuI9k95#cv=Ek<}0i%kB?P+iHDT3>;!^*C!H7yk_cVo z7ov7S+_1ps*+k@IWtmx8wn*dIJ38)+K6r?+xVpT|8ba2csg%B*jY?N*)cJXOT04Gg zbE*n5ZxS1i3?9OD|SDkm>*M><76g|NhSKjTs_;O}UFCsp1u){{a{$&1fcIM{l>RN=&%rK%@fjs=5D*3Du z5YyAsuNaI{e6R6fO$N!q{hknfCq9oY z)j$n7_wh$woSAX(rluz6na$~%iIU>*T1Nw`Eg7?eakTkGR_Kblx;p#5`XqC>5UM;+ z!y1m=@yjr>;yF>AUbMvoDW+?4Q^-WLXHOLxV9Y0q$;q}@$lWXDdYfkUl*7R51?}qW z!<>~7L!Il{Y|C$?K1=p37QBKkRtVt#R1 zP^)Zap{0;80pwx)W(6G?8X6iIiIY+xA|e7!RX$c1$txQf85qEijw(*Ae#+|t6>@ft zHU&QhP*?8s($YI(Ki_?k`c`8wO96e6(ax*l`+gI4O_DW1zP_Qk*=I##V`F()*IHg) zUQrQ`$f7cJmU+&=z#uJwyNUdayB}s;X)%ogm^lP0`|Wa^mvf zi!=D@y}go^Abl&VJi4PNf^nC?O_yRuBfL)-L5*{)Owq1pSw%XyXGkA2@ee*@pZ ziq&0k+`>74dB$E1<#o!7AiNJ{tY-{1bVS_*xmedA$;>*n!G`1pubx|ksQOE)q~&MK zLd?w>t3;2oQa&A873Sl1P@}>y@a{>Fk6;;x6y6P(Tkg1Mc}INBIYp# zu6A|?Rs~>EZ}ol9#8$3#m5zAJ(0+_u!UjVZIHh;J0%k3{u1!O?A@KC3O=kr%3b9j? zIl@iuL{@J%9f;afZ zX!m}(reRdek}XwilaR0_XRAVjb;ZTKO$F$T#!*eEF^kCb zDtJo*Zwzbd=!CvV#2cENT-RpP#K^&dxCYjD7>>NzxuvYC3Qw=O?TEEj^;VVaTBM4F zl?E2Z9&9SV%^=qF+9I*d$VwuqyNwf3JyjmxG>R3w+U^kQ-L)~xgWUOA!*{ATn{vM^ z8siWgP6e2IeOdBz#U}iYyzjs+@QRp&Fv^Y6@9?29GFQ~1XdLhaZM1U=DtXz^v_rOr zrIO6dc208qazEb7YJY+6r-!VKmjcb_Un8JU+^##&h;4RuJ&w1Y1s+26Y-x)L?l^ z8NidQ+}hg8Iw{Q7Z8rQg#O*l&xPYk@QhmfH6L@S<+v_Wj)wn-I*AB(%5#LA;w*4h&q-10Sdzxh+S?<1x5Z9KOcjS}g zmu=F0Tv^d?NW}(ROD27VqXe*Z@g+$6HjQr7@uSH1TER6Q?!2}Z_BHEv=Qr1;9q~TY zODo3bLpn0gaTlFGV{{ReZymRp&3zHL)~9zU9N1hM=kModv($j|vn`C~2&FO!a}rVA zOVRG(IL%%(`)2+ih>YGCrYL7AQoL#QZwY-fhl)Fnd`hY-bL-tZtkHfXW>;)(M2H(8TL$LbS-QzrNoTs3cN9)){0%JsaF|`2)2Pb;4*p~f$ z2{0d<{Jp4{dHNAPbVJ{zfQDMb8J_-r_443?Fzj7-tH!!bpZu9ZGhD!4!3_9~#ARs59ch+|f z|=xataG*1~J5!uicQ^8=>TU`r{@s|tPk_h#;J#GNJvPM+nq1Y-b%fT zg1=|}xjWkV^~THZCtA>Z!;Bzl0WY?sZG@8tly7%+qk@J!KB|Sexj0S7Ipytb)w+59 zyE`PkZ4tHu)D1foyEi}AfX1CU$@%%A6Igb)lMp4sVY1GaCVvg6J+#G{9wnDe#`N0M zuP)&*?y(pvLSOP4DNIi{wzBFeZR49vK=&~Z*VLxKzeo1A*2m7l-o7A)-p;}z2N-bU z_bVoQoz%T(zpt+)Z zvDVlRjk4R*6oX%kTox81gqw87iX!O^jZ>^ zcR3qZ3k!=qqIa~@8)2?tXoreQXP>^$M98pjNGcrpqjr(q!<=k!#$FWq92x>Y&`%ke z#{bJ&^LGsR^xkh*%E68t%bLqdnaYm5q_p(DNli<8y9{R&6t4obmZ@BSQ>0xwRppc# z(@Eq1AoAHh`iwuxu`^93E^CM~DJdyy2Pb>{Z5wxG>tbBuE~^3RxxxEG&h;( zf?nTbpHYJ*KN#b(-aFE8=Tw6BN-|UANl8ihnVAi)*1+K;6D1&rGr4TfilqVn6g14_ z;4rB4zBY-q?N{Q-Hc!X1Gq7~Vu6oVc++`;Y32lZx*J?imI&0Ot53=2?thNpn z^t=%C+WgoS@mF4c2kbsuRFyAgJ>T_~qOtrOxUh5}wPqPbOHJ9-lqpL8^6e^fal+_U zhA^T6C+)cbP5RpmzSNkNX^~NjHP_DmQq=g|R8vRoV}9$}h?@gS?6eLpEgc=gwxqn= zHAoDs6GQ9Z{&^cCp`VUh<(t@TRwRZ7_B~$MJ=XOtya`(VQ26#yAUrFJ!4*$J!P1h+ zHX0>*R+ztAG4F8kCWe53zzd8+#oNipPz|=aX_TbDh+wF(d8Hw5q@^)jA@9=8n{J8H zQmfq}Jeqsb&2<@E0xI9)(Zg#pAw{$_N18Myq^S108#KGu_%L^z|JSaylj}qjG(0d?t^t80Jbz+7@eus|S?*#?* zvFkYE10+fqkt#bYKd4OD*^_R|lbDMjP~XPiUL74HBO`mw6qNrAwsdj2RgMNpu6_Z6 z;s8!g&M#^5sds!iovut=hwtWN_P5>lrtQ|CKaY)-GQqkZR_e< z)h))V8S!&x6-8p3p_tTzz3n^w6tumTWp}rdx!R4LN6!^TuWlar*{rDj& zN)qXaBStj8EQ{zh2rU)i(6D{$jp4;Rhpp5mmn_s?N}~88@&fPZTHujS{*Ek>ND^@L zsAJ&fx46}07$UQ9%0{ANWA!6Eo;hqMgn+y%ICp8=jjgH;6>%2Zk7J{w0WW|j%`2La zJmgOTd9I}7ZMF_#b7||*zCx-QX76LQyEsY_Va0s+wBt0oi}N(0lp;_rU8<;%xeT~a zmPNjrmKFsA7;DeX#WnU@jK~|}t*@fpx94tl@v106&EM_q?RC4=zOTJSFd)2kZw%YW zhj(V9fgs>{!MAVd9P?hR0a4x)zPld~jef+0Z;kp&&^PKq<>LU8EfSQ|HHd~&zux9U zPy2<3O4$Ai?ZdhdTqLBVU}!@`X_l6hlvE$^BQ3_WL&>QzZP07Bw628>ee~`EdB%3S z8X9B_8dbZ%e-9|Y=F`&B3MgPC%m^Ke3GH~)f|Vw)E5p_eE?gWgwq}*i+F)S*T%0Pqk9)j4 z%P~hvbe#`WF{lE9{HTyKPy)4GTSR~AQ|I4gevGx_aILL<=kQJ#QYVn$Y4E>n%F};P zdvM|Zf!6&Bw;mu7DqGmUkxERY9k(PWF@7lAD{^@Th-(2Jol7K#N)21VwBr~eA+|%lD}D#@D7PZ5ws6z$mcE4!*iMe z#D)K)xp7kHieLHVbznlo|9KK_aA>FqqM0xagaerO^?!@@m)ug~kue$ag&pdG;Ad)3 zhbgZ-y~5etOUqe2?k~dk^oWLhN@%!ha@8T`;!b?xtgc0 zV8a0PtrTAXX8-$b&#ns^$Fm+q=DSJ$(zEaWL_iCFeSCl|0EZvQyzSs+d?CRPzt#Y# zOt%$Top2aIr0u zIX`^%cq!?!KdN>Q!*d%0PiXHW@(F5$|9ZmC;!!uH(4^bQ^cgr8;m@A7zW)B%{q(@d zsTH;E<1UC2&Lc#Q36aYyq(yG~e?%7Zvm23yx96(Gmo>M@(@7rn^;S4gVR1W6SLF6X zqpOUO#`Frm_IYHC1Ykd<2N&O>L_UlF`@cV=t1=dj!&67HT^@VCqIhc{i(X&wSG4g+lq3`Gh&!1ufBpW5-JCXsw= zy-<07x(Eerz#JWxjw);%^hHeqFH@Rub7ukz=SX{grQ z;?WYodS+CYl=v*p&(EjhQ51>iu$oy};od-5i;2E_cVe4K5 z&lE?O4^md)HPdqXV{4qS(0f9aB_*5!0+wf?2z|%?G?@S(4c6F4UkNi+5J- zjk;tkJR_L?Igz}%r|ZQLU}rI@aoQapMvr%g{o3;X!)m3(zZS70H*=f8Ae(V_J-}(M znU?56fOni`@Zv5%tLowMqnbaS1>WGS@O7wxL=HM01WRK5*_UmvhkvePHt{v4jriyP zsL}8cd9P&1R_#=2BOx1%CTZ4DYio@MrbQW_f^Hp0URqN%A@#*|vzAOuNRT-)W7&S` z{nb9SL}8;@wf%8+P`eNUPCS!mi`7F%n-ed7${)JpqFauw&Dc%e$+dal8n(s;8JE>C3Jbb`E_4Z2n^!2*dzc%2!{^KA|lPf;s@!ScF6jI~%;p;hx0g4})5&ZpD z60)`moFaEHZ$;$txK{);{qo%9@!X98GZ^}k#lhH;OFEI`b}*g-zE}+IX6pJ$p@_c; zCj68xnI7`G<8B_$^%o;kwH~={4og*58hoSpi%0YG)cuXYAwtWzpT52fV^f`1`UyIS z+m9>ryWiRI>csSAk5bhKM3CU(W(?;)3pY~GU*sJGD~=QHqs$d>s>(Zz+ax(4R2gy` z(O#T9yD~!~IBvFr?3fFB&>2T_GUyb^LsPW2XhsCRt=$=pt77Fz^I)j(Znv!V_C^x_ zX(MC4Yr~A^wiiA4{y<=(Wv&zgdGKE>J}`wE6FA)}H>AH1Qsimpu4Tyj&^CEBa)>5-g9F@#BW`n%u^tNuqhYLEbbC`e9 zc^41M+XkL>q2sI9mV2(|{9muliQwB5;`7+0OWM9g3J!L2+}3#K*3S~eJ}0b6*qQZY zRmf?^(!030_+~2?jE=VTN3}B|Wi1qb1lsMD(aU^$2;Te8?eyn{&{yzH+w8`H=edHX z7xeJ%BTq6|*chidbON(f7<~Lv1Mo~0<9XTG*m|f!tnKeZ;VmsKL8zGEUH3`X%El)r z$>~aOguhZ}U;NK)$zl2*gB1TH25AqEfmSlF2l_kg!tPmu!vtjI(L3cdu&=GIZd-Rh zB9RvkmQX%5zStdJ#fO{BZjAaU$V=PnLF7lEe8AEgDex!M+Aef-s3urFws~34IgH@s z`?0fAWEvC_@ZFU*1bH}+_mM=5lBiwvO3xHu7GkQLP9Iq7l0@X!eV8QAuQ}AnJE44g zFjp*s@NzipuHNog)80-v6tR5v0F|Pbm8>33$az~=QnKaZoY6CV^6Bi?ccwXT(|e%D zM`h&+Xd=&MSxCU<)cf^s2Eyl&-LPpdf=klQtp($9G!>ZL?YI*W++1>?>EJGY761F) zbw%-xrSY|~3a1T>4e)wx8@?aLK8IT~ip8Zn>gpOA@=`q@Ok6O^$x}-lyhlPZR$@BP z*Z0xX`u34aj8uaHACMo+_K|@SpxbB zd4mGcS!Rc0bHb3NiFwG0f3!5lY3WE99we^68Bbw#UUYuHyt1+as6Ct)-2ZxDi#}9b z-f1(9?w$(#RCxKJY`A@sQ5VuQ_oBzb11&llUb4fm#j3Rzxf|`^Lr8gu0F7tz09z zY7PWOZd??Fh7U(3ED4|qA}uEO}XT=61Rv`x`_ge*8dvN5=Y+P~Lo?iK2J zlt^`@JI#J#znmUmBF6469sEo;HSvQNWgi4;Hr3f0hAmlE8m%KYgQyjJH_Pdmy(tS(Pzv+e?L1H z*Fr4SBk21!*c!mL{o&pic;iQVdwX47av+5Er)fwa9aRz~{Q!?Xeea`)lm4!d7yWZ% z`18p<^x-a0V&>}N0w|7;?*ak&#@cLetPAc>@sAef^N$;i%NJjdt_4%&b8t*dOtAGa z1#s$;l4y%*+r1J;A8a5=#;tmeH9{$$n3mvGgCbV{+PMp7c>^m(s&Q!hmhNhsQs)lQ zUuCyPg0E?+4bTk(|3)r0g$str!!|f+J^@3e>Od|vm-Y8we&VM`zr9k;K*g{)IAgE3 zKnmZcRF-UIlognBl!J-3Fs zx)qpz5NB0s3N+N+-MzH56chL6P1Yq4qJiK%H#Zma;NW2XZdY$_Dr17e;ojaW6&3x* zUU#biPWCkf3blPKY9s{&!i`Qf(28);t6W@sO)~u+%b`8}GP#p+oz$2p(G_SDY z=pvklSP2xmYqA0)64gJK9?zB@#?qp3GQQR9@xy=%h#%&eCMh82|D&PRkR`p zb#FX(fuPThBC1aBd7g31T-2~6SRPr=EN_vDV7Sl!4As_BsFz7DtprtN#StwGiN!ZS z=zSLzS-f#Gkx=p5OWG23tm8BaAhrNq&>+iHr{=?bupdCFhwancHG#5nmQ%r_0~Q~P zHG(Wh{Bk^ZJMEj+R#s^=ih?6Yvkl%RxO`T;&*mhYgIjcE)S^RB9vEOMG?b*)8$sw6 zA{+GOehJlhPTMCej35}?m24ZOU65)Ux1;fzMdmYEKOS_3_0htn5^#{+ZSc8ah0YSy zozRW|DvzIS1X8wc*mEanPI_ute7DwsTS_ZW5DN#*q9#F)z~NjCgiJ%ecauLJ_%q|W zRTCr3>w7&Zifp0tcOKm@&Uk_T_kA28au$=FRC{)E=&_S!dGCCBH?-$MLzw9zU0T{C zV8(TCz;k;Pa!(vj=cs+Z3SOcjwos}T8rMThoo9Z-aeefCMHSNx*|GO1;#t|*z|6|K z-l;5felhyhy{kq*^DZ8lR76BXfCfj@?(pECGvl770e6j%;$u#P)@AIMoHcvtqMdr< zg4f&?whPZ>3rd4lI*%W(J2-~C=^q^QVJ3sI&9ZGP><(rsnfS4!`Io=BiOAWu@nN+0 z=2d#kYoTY58NkEISr7x)z=YlPQZA&o!bG}BEpMO$BwL%Cj$5icM8fq}q`#v&9DgJd zzViv`WmURDRnODYFFI8>(>QR?^T%eY*AOfN_%r+$UBig21J8vZ&!f@3Erl+js-rCW zD3%hHt81i1Sd^knB5VlFrCx?-X3{%7-Y{5;)VP}z9nETq(Y(<# z7(e2=P2$W*PDYk$5HuDgu0tv#ecJy`_Dx{6vx3vzPq8sE4RKiMf#~pO)H4*}@Ymb? zJlxzxD~*H@dBb{x*#ugxi|v+@K0=t}C@2aAP~c}(fK1)zWhFtK3pi8|rQoC?zKJi* z!eR@xzAyYNRC!Lh9*gAmS};;Ezzqy6b4^Xn)YO!nogM8bl4^e;IT*wDYnBlhK3ebO zW8s3=t)heq3P$u(k}HDRZCEK#xf{{yEBrU+QFY0q4;W}yb@^2a2@d|sm$_@tcJ;5= zuD=4;M-2Ztj{RJ)%l4$ue114iXjg6Ih4aYKcRYo}lg1T|1Iju)dHzKt`v-)WC`PjA z(gl%XP_0WDXxg;#nx7U8r^m&|5X8;*@qvSOS`F1DZPL=x`Mg!IYx`Y?ihgf;>D1 z-IGGCas1>6m1v^|6v$qpusbO%hP@^-iO=p0==r6l=CG|C4)0ujhrl;?5OQ6Tkt=`0pa;)0@n#ycH1uo*csGc%#Pw(^EKsCNo> zz-Tkf^c!-pQp0EB^b*fM?-xEf^kn$!DJb{Hu=tCG=Ghnrx}fv`W*cNIIw-E63PZM0 z!V3BedXV(GQs>(>k%Eu3?5Yv@wMV04JRWmlSkc8O z+-LUyCApwuBM`sxbph`QmP!f2_BTfNqY2;W>Y}7R@0-H*?c@%L@1-7axGqSr<~DbC z`>u0(d%k2yJT7qR{AR28rKO}MT=pS65Xw;-|H=|2K*jD4p9z(RLWDZ9q{*ROT*W?_LM(6Iyv;<+DNs*@}EQ$uCl}F=>AHB ztFwR8L*+eKt-9b6BuWJkpiB#4h~$E;!g&O(N^VctyMEbsSQ+}?j!kHsTPe@eIY zb+XW|vmOjO?4hM;>*2Qi4;*kwH|IgLlz)lRg0WfWO(^NtEwHXal^23Y@0ebZ#O|Rm zAisIehKTE~93`Afqm%sQ!2H!J4OrdU2^_E6qhK_V+-XYgv?X}%oJ~{uP77P#2?bFr z1_s8IA-SE#2DnJ2*b}^n@mwo5FX+G-<838tl@;d@?DM*xDBuRD;A`(qmyluv7x^?i z$%I->Ny%W`JO)0gjx>)N+&X{tfSDlmR3sD>l6|g$1c>;PZ2@FL5J7LvU)7ii2?-X9 zM?^bB!M!;XjKdheHB?BEn-JIs$+W|_*R065EXmKRqiG47} zA(VJmb)B4M9``3R8|dFrVXA{IoVe_eR7R^E&uqurO~Z~8w6e7YTN**SQx%T^m+ zz$Jf?uGmY;=(N^{zm&uX5}pcPIfAq_;T>$gFuyz0@3EyGoGC=d$4jV-i=!Q47}GMd zQ&&VEyf`GEd2*KWO2Zf#Fj-wXQ~lbDmz=P2Bj@^fzsFmuM}YEl9ZU<~ll;eE^St=mcix-Q^>!luxH^}M)UZk}( zOwHr;VJvW&Xz9%!HV5J1;0z587T~J91j#}CARllYomcAGevG%0E|lwS(-+!XHXTpj z$j3j9vShav#@1eHZIyZ@O7RMH_@=dVt*B6y%4lc{sjUQwG@qbQPIJ>(y0hE`N(Xm_br zMsQT{AEvzgYS9yUxe7!ii1qd1AdV(%0)r>Jh)z6uuz+h1t7yR;x2 zxU3h3X6f@{jK&@L_b+G3e**mbrBrABR-Nft507#YY++5Q%X)WdJ%!3~$?o|CV|%SE zs!Q63C@9S9@D%m7sxqdGXen)D?;qR}yHvICLZ^o0=6kv?M~NF78{s~IE-gP?O+)3< zk{uGnEGdRUnRq+c*>%=&TAwKMkC*1chkS+0(enX5tg~ZzCoMTwzdq}St@y<#AFlj4 zhtF&XZ#0oj##MV-IPg$X5PM#&y#(K<7?LT2k3QW$8uakbM-LLd4#EMsJi%Gol}RvHnPlpIg^_uhdHCCr8!40gAO2pz2fMdI`W~TG&nU0 zYe$YblY?rx0CJ?|F^1Fs*7T9)=VOP%$J%^3h1sH&T+r~Qho|n?W5(I{3w8-W=$^lo z!hsSmvr&{KtB)CS&)U0xFu<+Dx-THt$j&ZZ~ZD~|?O z|I>w_q#35|d;9x6Ccm7ZwZ4)z>!zG07BxKkz%%GHWxqWvKzpExv6c7F#f0DB z!=FrHOcSo_tI39RTI3u8Rj}FE{Zn#@=+QxPqcqMV`4G+9&ACn#cq2TuY=ut}YeTd5 ziS?s@?Os=V5z0wvI|B)7YaUY@k|&$Yy=t0!SJwMw>~qkrtL8z?Zi^v-vjM;{$tH{Z zJhC1S4i2W4vB)^gYIY66E!vfx31=3sMOh6zoFos6iMiaey^;Y}HQZ`4#HVbzNa@}i z7JwYfOR3ZyIVVW#DsVzeH@WqqNDF-7OEFST&qGM-y3UrL$2_$*yqidF2V2BRgtY5X zQYxu=_$N~j^GkaU^6DOI&zJ_hdS63m_mdjJ0jYL2QCs?`?P>5)tmHEsN4iW7F3F%a z;+F*YimkQ_-@haT#8%ySZwfRbh~ZU1PI`jO<~h8;_SspB7c^#No>$=BLW{fSj6o2{ zOsF1y8=M7l`0mxL;UK{3FdVsu84jgmKk6^B>N{Ech)_g76&^9%{vQ0#>gFl072@#) zyo36UsUKqE|m| z|0Hvuo(|N*gu(*+bF3{0;`Nq6hV#&ZrR^bv?;MwQ?Ko3X4zUEX;|#1KQFzqTv$OZ` z-P>RDVQ55q)zaQL!R0BUhG&qq*iko^f^=Lx&*>Vbw03N4?AfPFp3u3kxsXHeqfeSs zWZlcBrk?yRCo=BMIoWe|5X}p-`>cR<>T+DWDE^|xzs~Mjgn-?86y?_n1w;Okz zsD*Z+pi}YEX-Pc2zostl>GhrJ;Pd{)Rsr4_L${@URieJH?L_sVP;->SEUw-zC@idW z`MS?zW!(5RyKw+8jyT0Z!Cci4kFmgO2JuL6lM;=4Gv1M500|Q6Vx?+JWseBdccE&B z)(_|xKM`C;U?+Yq>feU#7b1|@Q$Sx@dUYb))IBY6yPyfCkmxmsT-*J>T)glXeE0W} z|4H51{8g^~McpYJ`-|`t{`bfJ|K^V^9-?+uSE-8Tnq|I8+a4v>2Fm#a=YK)-cPwqT za;SDYSuh^PSkNZlcP4$#8REB(gzs~Xe;>H9R^vjq^pKkr}9+4c$1JQQ$i5qskO2oAXY`zP3+SF$frQ+gPerga?|w@Gh-ZT64L zUE|FOX7d+(2|#uqBR4CuW2`LgeJ6Hf0sFfBRqO7sWa!So0=WiPfC#@w(Q6QqlxAlygDu`^ zfhjdVAH_G_>P_i{eqXx}eg9-7znGcXxH>tZqLm^qzj@8)7x}YBdh?R|CF=NOK)=ZL zws-UH$Vhc8diDi_hqUx=E0xE}op#2g)P5Ej^blcU9xycw0`&Cy+f(;2EN7iX9lg>H zEDgO)KPbTX9Hsr{cTUBx5z(w~jI}EmA0LO?Dy}7JtJ2Hu%{8^#w-J)|4cQ{+sCuhy z_tzqu-&0S}qeY=7(v)_5Y&@*TupZmX2?7lXJC(HkOAY7=iESK<*<=kYjEmNZxGBwD zaI)s-=f}$hIWMfxG@_#_Y$&Ce9}WY5yYw_U(qcNKQ}-Vuszb=wPpj{-C7X(ycU$P| zCu2a2my!Yq#hIChwhv7-iNP_k4~_>028MjdyD$;CgmhSBIcA8e0WBD^wIITe+iwXRwu7!$rXH`tWZR z-Pl|1*sX5J&?+yPAs1$DABWB2ZL|fnJjh zjw3reJE^AVt;_rM1zYB`bW};A2qy6icFlcwBXz;XYaTm3Hg?^^#bNE{!~JnEB%vsK zfl%CDVEQN)K1}-iTH@xlk#gBqPd358&%DJB#sXVMOZ>^ z{p*9}tqg0ij(v7DjN?7K8}C`Z9LU{S-?5b5m5J3p2Lp-A+gUfy&51)gOvOY;S1$l_ zZGlhMz)}v(sq2PN(rRab+;mTFH&oXRowLV_vfo$svBv)RSQ=sXEg7R zIZgT}C-NJoiqf4l8FPgT1)rXfT9xWf*WEPTC%JSgTpWa@p!aUt;c?LE=95iNbe z4fqF8;X_RW3c9ixiCz4gSc`=f4XJ@0ustDhIuXkGXj%4gSY-v1Fpa;%y*KL!-9&n5YIV7x7+`* zuPEhMs@!e_DesiZWEQ^c8N@h2`3FZQq!1nZ3!sDQ5 zx8ZgH+mfxW%Vm+dCJPTaQJUSbR0r_l7l z1M2XY7%|3n%JWKaiDb8@o!{7Ss>(;L12u8ug~*_kp(2Qr9pyPl+a>fA;EXLS|3}Uu{(#BQ~EEtL;5F zsJE6J85z0oLTi5olRSfYtHHAUcIsj2V%K7B%*;lYgGR~HR_ykCf=-^6$Bz|y7aB)! zq`p^!|0`@; zhX@Aj%^MCeEr;2D>b&FSF;ct86&}d;+w~;zYa_aOJOz%`)KsxRM8g6kc5nzwOE)#< zeX6MNR5Yl7*%ofuiL+teX+R5$iRFO3P8tt$N7F;<3xc>d!|H{tL;2v1nVA_l=k85@ zfaLa$?1+eC4H#B3;r(LuiIsc4WS=oNE5m8_2}NIKtWeU9v!{_#e-soP3)cN4y;Wb{(n5^^#+!ph z_vghC&b$kAj7Kxa@UtTyYg9{pg`VfPsBwI` zRy^Ul!5Q)?D&fEbw{O$O`M*os)a2+IP z*_rp28ELUOeQ0NpWk=7&MY2s`>O4s>5_bblFv8@fx)YtaQiVvunmbI{4_-cji$YjX zczg4GQ>zlEm_^`His8$vTk< z5MX`Ov8cT%pl7r;qeq{g;%8nUOC!C~Jawec*=QKIy>g$n*@6x>MZJ~h`{Q& zIg?v@24^1&pp*4^@)P)qatVW(9hOtMwY3!?CRE#ua44;8<#<6V4M#p>vn)@Dbvv#0 zZmL!xHQIrSN&u$AVpkefBR&s~jdC2JKeD$yyfKsSLwK`qqay~u=`+~grZLFVQ6R^2@K0!Mwy zj;-TDv~XGGQ$f<1D?xMUkLKeRyqCMA^M-p%H@)ZbR&u4+@|(lUL3l>}6MZ4Dc*g9W zy#d}fdV2cV*yELALi3);oO_}qE{y?C8ubew!dc6Ch>9vpzNH)F^o~btq+H2-@}@}B zWDtXQjK#6AqtfIVh01AKRIw!`q=y+lwGl$7*w5p_?RG7k@dnpnWx;pf8{<{4*0~8 zGO+K1)#@=Jp`wEX?r^Eo6`zMwnI{Td*@sA8w+7N0dY<{%Y06>Gj%e|8fP(K`MuyNu zL1qra2M@l3!T{mtWSLp#ewa=hpPEazSIDDpjazt_m?VVz zh)^yB>$M+Vsd@rR++3o57vEvfrN*;`DUj1QG&ZuWYo=$AM(Yc3O%KYp$&Xtp7#gn$ zr&#OAL@t{jNSbdu*l8mL*Bz}L1@c4zDyimU6(0+ZZbjo|aRi3qH`Zq5$R6`%4NNC_ zJSbNh{E*+}LA#UQQl9X$lz;?wMy=!kQAz5>SKmoL@x^fK{qr&-W+N4H6?9K3d)Gne z7(M@i`*U(i%2~G`+45wyl?Y*lvGtz*qSEivr0;iw+gWY1O}pWElz?^ zg5cA-FYZ`6bRdlR0v=^c)%!uha6w^V&nvKpIXldBd695c_}Y-XI?oHCK9%u!X<^a+ zYKOw7tA*Gt+F_F}+`k@DLlh5kIp$Fu)meAFsVaf!cuTFV&IX%pxDIkGHw4MlXw_@byKHG#n%xKOWd9r)WCa)Y#Z-v(~%pn$j3iUFp?wP2)(5I+aGVYDSwS z$5EpsbxqBSp=)`f?LnO=yF?-bx>j}v{6X4&TfYMjVvuNde_yHv*?e7O+PM+B{K(5E{`^Mru?40Ob) zWF47C*DNj5wk_nZf&JTA(STmS$Kav@#{l3?r)o3X%;nOvvS`oORJJNADRr%|(h_9I zB8-KwLWJRVcQNf%UlKUKoiQ}X4F=!xEKmlT`q?fP*BZKoNy zGqu#Goi23wqn0uBs+KG3*-e8LCi(rBqS;aE;c@9)!i8(s>dVT?zJC3>xLD^P#(9k= zq<|YI*sp&2yH+ym_!x5J$8gId%k4@J_wU};H3@;7(qgl-E?I-WlzyOVGpB^kO(2_k zbFCyjUH7IJH4`(u_`jiN#?cM9xFM}iFe){OpaS7&ezjAgTetYni)cRJ?%ON@nY(K}ZsIc6K%Ov~6-V}SI9>{4$SVmqf!dg0 zMj%AvR3PL9WT3sTduElIm>W364fL$nJF43VE$&ndaaxlJlr!<~*#&+ZtkzyO(kOhI z$^GIzh8z|UM78MLxdZVjGshb1>+9p=`nnc%{bbB788Mv+4*KIS09DApirG zNJ~AdwN=0!z|O<0pr`#wE2Nr{H#wVi)$e-k`~x^FmFdFIVL%mcTmg9nod^WT4!{en z`0Q!|+yddsoPWj%YOljR-X-Uu!Z0!#h2Z{$@X&qu~b#NT6DPiwyme%OsZiQ38FcLn(`wqF=)qo-&S)wf(#MTiO4 zgegbw)%(p5O4=(~k{_&;LvHg_pFAfpumHJ)Xjd??r!yYZx>763-H1*%Zayw*5*&oV zXhY+&Bl*0=BeIA42)kKN4^^mKyO?>Kij5ma}bX;XBvBmYoZ|D9fF_Tn3Jl!zX4 z=LYaEKtVy_H42HWy>|pUR_Eh>B|Iuhl=*-U-tnZH+z61Y89KK_HpeL|D@U&0eGN)O zmZu&6`%fs~ej;Yy2KvVz67UF*!E@h}Yv|+@PUCNEPDRul78Dee3+9s2GFq)N(Nyi; zOe6A$zQ=v1Y9oL?o?t$DbUrbiRBG%|LTYMLG~Dj~bMD=89$UYVr4{7vpweu3V`yw0 zn(t&*CR_`Jm<2iGo^5u;mT%uw?%e5YZM7M#qc?;gjIF51$fe_4Nr4zqI+nY={ymHV(FqkRF>-5)7$>9KbDQ^YV#$9e{2=MXrHT1h+JDcyJF}L?_sL?To?;^ z5Mo;OisHRbh+qRvxXJy(_Oy=y-IuWbo}MCz08b~tkWElTjy)t$GzbBsWkWqb-5ey0 zm<}Bc2Ct^b0VAlFrpbc9X-ZP~?6JgZ_jxbs{Qq27AfwrZ49c90GLaWAai{2!-w&x@ z6c0DZ#S#*#)d#{!EghjgZ}?0iUbm_l{C-6cIw=wRP)9!{@tVe6@%4~qSqu@VB0zSN6>2^n{ z?eH{?`AcB`4b{3lwjS}80K)F}*wKu^Q^}~~_BHKvixBTzy88Xf^V?5;A3sn`0!L7xnc9Bb+uJ+WqL=5VxZNl4D*OtS z<*r)Woc2yROM<}8CHu}1hL|7pX}4#)`g+~K+~?0Au((a$dOowiVhU0Ofu*0{9k>E~oSIJU@L%zt~rPXme1B|L5epp-R_+@aWcX zp9ytebLh_;3Nj8++!-_84Oin~0IsO}=EJopWCWK|lodz5j~bTzNNM_*)Xrg6`Hg?T z+bEl;?wGtVjH!^@hp_t(NmKOSoOgA0K1Plc#P;y7byU3epH#0t=ya~*Cy927hYV68 zR|gk*a#frl2XhiujI*8f=av@tDCOhQj&B|9igXvqO~HMb68SqS{6!esIw|VzHVu&; zre#3rgABt8q%f_;b@?{q)KJ|U9V3I%F2fW?P$?uRg`jCr@W?xr z&&6F2MnI&ZGf2qu-HAiU-f;_yb_loRyR`y%v|e zDlS0#`+@>Mj|FLkM+#@3H^F?pzUcruR??x#P_x*1aYX(i2peE}hTDUvDH5_J2*v?HNJ@flw3`dSk1T;4^2o4EJNtt2r1*t2A z{1jCy=QzZCjWJmp(8oGmo{~j+n$nOtxk~HccwM&OzRsd5Q2%TL`o5yamP9oAfxdo} zvEA~-XB<)N9G5q?{^g^pB!RX`!B!!Ak-{RQV6WDqC_x;vhGlq`6@lPKQ9 z1hd5M_~I^0|K0Bj1W5A88u>@jqSH^~lVcG7{8}drF>}3z48?7=IeF-eKC_9+LWhV!_Fu2sEKfi@8l&7csWnz3pl-z!_#3c+& z-rJHomRUO-G2F(TBY_@z5||aSdGzClD^or6Tq`~1OhJW5$r{fzqB&nrc6HLR6qh!dmLru zOfBrR1vcYKTW?UV>w=B87^2{vj~X)m<$rpMd=48yQ9R+5DuRkzuSjNLZYR`M(`UYTMy(HOtKE?ZvxX+o|r$i;GQw&vVjaFho+-mSUQFf{)* zeCR%YcQ%>8!A9KNA~(X^ij}tYF+g!{JuA#+!>t0ke3bi%X!{T)9j~GRYu%D3o_s(- zlj1Iu00<*{$FGI*gW7jil}9vlf%mD_@xdWtO2oNmHR3+YX?I%32J%Wv`D_}==o=jVIKwx`2{xhiO|dq>iq%iU>qPkQx?&aK!Lv39o4AdZ3sgeh^ZsWuWXEt8~@MOM+OoBcwsk#oodi!MW9Vf5h6Zu&}tViu4za5cQ|8jqE*9|IYiY zUrz*1E|8;BY5JQgSoRitI|--JLnfcX{xaNd#F_`X$}QRRlO+S|Vwa}O>A(Hw|bm)uNlP7E7-1+Wy zdZeXgCjpNs?o5CoQ=C6Vg}dnUUS`=alW3iWQN{86Z-e=-p|STo>x+5>CZ04?;HfO9 z*)}n5_wxAB!X|p7QA>))=3|>@^Jl~wp9`jLk?Vj7$3M<=F&kG?I&Uf#vED~(ik8Qg zS61Tc?P@+{7+_}$=cLDM9UO)o$ad~{B85Q{J9KIhw?1VH;>~?`JT!?*+G^S9m+JZc?WR580|N!0H4r@si5%z zMA}7Y^0~J_UiOWj$6l}|sbJt6Jtrr|4_9?Iw_ScpX>rQ3z1eQm1cQWOOyU z9+API$=^{~4KN=40qCnI7Dpk618!LzY+O-gqR$_CJb~aexSNYv_DO+^yGyo*P?5u*4|zu`iWkLN8psaxF!z3%Te*Y22cygAwaA(Kc7zOJCF$j4!eAKU=dU(;ZLcn zpZs3`X7%lF0@|o;4*`!AmQRe$TCVSlUUT+Z?VmCRXppk_`T4cAwbj+t0o-ZsZeDH# zHeL+{4$|usXB02^=tCaP-xCLLvPN^ujgRymnoW*~g@i@Vzx?DuFe)n;TStewu`w4V zWZM}@Af_=R0F&#ml3ER*CZ}av6bZENayC>Qc#jKex_lUi} z%?0Pk;b$vY94ai2n+2U$;2ogmM`Q};KJ895$0qXypkn^au)X#ED-8D1rAx}nL6bJ; z5Uh+0IpE_057z}jYQ=Vw(HEavTU#MAn3xt8LacxWJ*8joVA_Z8H{qQbRd!) za0Kih;9I^<{SA!VfX^cRScye)a&rwNM!vSU$Jc_6$1g9)omgaRvD`dOxaJMM1E(CV zU@R73JVdpwW3>8V_B^EKV~4h*7*_1T6;)jZfiBoqItcCcPI-#bUA%L9sVU;yGbss) zF7T6ziVD?T8?LZYG~+Hhm#FNc@{j4mqzefGkj_rA{pkoyo|`6n+%PPLOpofx958n8 z?b}q^>dut|FBB`4OPmZZm9Bo`>R)}|S;ew(*6#alcq8xyBZ1Nar_o^A=pnNXzt5jP z?>Vkh?^Zcuh3ASlyK=!RC;Pp|GJO=NR18#)9Jb5Mp?-NeScbti7_|y^7 zv=^)5uW|t^9kGN+N)y1pfYu>-bIkL6F?|QU7lu!^`h{H?! z=fI-jTgKfxo6|0G%3qE+toWwMY;O5qOT2yt~ZkMplFZRitcsVlWyM zaQv`Qq=lNKr4qIuu@TZ2SXp03a^Qp>t#*~c!`i3V{uAfL-Juq}Wo%YjLv?ohl(j!L zvXsn!k9D0aETze;=B~0tZ8he9ZB|T~;)qsi^*%FGb}ND zcP(iTGb|TW%3tTum+-ts_KE;-SZ{@P*YSYF46?^!fk}uvu@;3NE6|6gS;R=1yLLu( zcXzh$4-G$55n{i{`THmQMKRp^;)2<2d|yAg{B6fKKNsO#msRUA-15Rh)ZLzcWeM_V zYj%1;-BBCt_bgPAc(uZdJdyb!NqSE5C_v^u8oaNh=K#l#`Co{lvV7$5?&OE&K93(*1|4^E z^yG?GP;C6A9VYLXt?g3DC2u%~^N zS>{m1Q&;tYI~g&}Q-|q%-s$=(=%(`!G`y!Qp?`tp@9R2ueL6J!{p~*>F4pdTaI3VK z+krl-A$qpSflbs6;%{&;1!O`+4ZBmVZQ8-KAW#u$Wruvfkwmb56c=~h8PISjb_FJ; zBL-LrAlMvzje`9J|MS~?9|I#bY9cLGTU|*f`r5YZ+~=j(={pyk7TX!OCdUG9H$vFBRp`j;%3 zgwruEQBB1uASdjWb=3Jz0*k}XZ=M$06IT7>>#|d&PLVuE34|_W$E%048m>T~B3szD zyzwjnZBw~0wS)Ok2&wRT6I?v<=q5gDRN;x94P_)ev&Ft;(G1G9NPFOZ@jRhui^-h& ztfAiGeuE1)lY+;PaADa}ZGM%!+3mCVpD4aq07~g}(PCGB^d^kd2Y2SdYQ&{VyBI%) zGY(FD;0ju`SM;Ejg@PpBCCFI0UM0=180!E{t3UpMR^aH9UPQC4mA8Qx${xkC8vOX!=YzRZ_XPw5hRHaNieZbL7(uv; zxmBcAEPBMY^ejC@Z>TObpwmbO{!qB^&x7k1iHED56eVM=R|e%`&Tge#%gKivquc|Z z7Ed_va_w!ZySKCv(ZNni>H5x0z2cfhBNd^!wr(5|koT7mFvLXq{v z86Y#^>=NubT^sm$#-Izx%e3U=W$XEa13R2;ClB_~!6|>r$Xh{CF)lYNtJRiRGU|1* zqHYVX?EN7F6)`7W-G}5>jp$ifj9mfISsPd2BHPK9y3$&zl#_8utVA;xe&EGJ%Fs~w zFfc*ZI+6@vjsDMD^%RH^geOL(*Zx30K zwOW<2Z@4|@^XY`B2bzpRe>}c`;}Y#{pFcl3$x;sVAXwz#!iXkuANmUHZ?9ryVL^eQ zC9u1Pr%S$T(|A_H5nX+r`_TDBQ%q1m04wneb}WB`2=;(d_~zqyN?~Y7AV|1^jyTD| zs$P2xIzP2gH~D{%W!5g>ODjC3@%w$`_s=@*x`~x3G#Kh>OCDQ~XK??qXgZcZywySX zZ1lz~q;s+kCPrH5xBf^6ZX8F9Gq^*?bSL`cW=RyvH=~?05^m0#SQM>-SfDA&eGBO) z2xbeU*&O?qo}LB-r!I-P{@SGDYQ$w-m2Nim(@NNG!-K}gq9IqYjkw6R@1iUiCAw z3D2|TZ9=9NV6?=;?QP(fHx}3X3=WU6b^^!#o`;ff)0l$E=L%hGtgN0%YSK86ybAVK zi|Kzi#Ytr&mDfpx}V}3}@{A&A&=P@xcAWdyObN|WROZeG^aA(|^k8ml74KthdEZ~{B8 zC`mY1lNc!rBM#S631BI% znsS}Du~~wUs8?xB^sEFO|6GFz8O`7!im=)@d6aZkcp!+7%IE zA9C+9yn0|_avpQ~{tw|a&e9uIGem=gRB3ldriMntCLSO*)E^{j57nHuz@N9yJd{fl z37Nvzg1iRJ%LrR(p1BxxM;iI;RllcB|6MHbli9%8IW`WhK#&3m$3Uic3)Bf}YU0w; z76k-7Y~_jly#Iq$Ar7=(2svwby0^xDv=^BV<@#qZ#p~o*9iY`CtATH)94%3u$`>zK z54Ydxu`#HP;1{OxC#pTo1t?FRJgJ~VhjfTyZhx3nCR8fb>85p^C2QVufUC_c?Wn5P z>p~?-!TM7b?>R#KvIeZWy>8hH2qadT2CCJKWy1mf!CTGmd?8O+DuUO*e5<|+E*vzP z>gws1q+3-M|JM8Hvhr8HnCue3ZRaxLm z%g6*F#fketO7OV${UKKs48FoSw8A4oC8z;?ZbBvUHcm-dxf!J5Q`z_dve8fu-zFJD zK-&cahBj3V4O1>zqPGhknV*EovRG+(jS=IX2p8t3-rl`gW4n2kse(}LCyLLg4u2|0 zgPoLqYI^!&YeA(ty=N` zdV6mRrIYy=MqClPG{tbkj8)UpGCvjv0(NK@eA&>|HA+(M1)QvrHH6LIh@jv&C*_Y) z0wp`-aox->81A z)%m!^1B#uJ*HA(OS`m6_&nJ50`@hblpBnkR6Qnj#7AAAwPk!a^dCg&#^!)#l$#*N} z=9+bS8Yb&OIarHkKpgkF*ZY08@AzuQ56Ci+F4NZ1I*UYxeQId5-7ZFo>!m?AG7F2b zg!t-dZ3@v|UaHKXI`^|qZRMzq4z@wYM+}FWpF0?7Y7|{YGHZT2G9D?jhwxqGX8-Hx z`z5LX+kX>RD6ThB_ahBM!(87-49jMX28<2pHA$(n!r?iyuUJvfuO{@YJZUdAZRfw( zqm@-jP8swDWqRz+`B4a$I}}t@!79Z(m@_8U2QU!4Zw7xw>XNJX3)GGqvQ!T%2oO4O zHSavMcf346R5{g9C|urc?J!^b9{CZbN!Yvn4}a$0K0LIYJRn|685tsnLA-zW4kAEA zXP!V{RK>jvtuiPy5BCVz5l)zcm8s|BowF554}A(_=6_Vu#C$9qu%evlg{Y{=Rh~g2 zYEA7l&l4e6L0MeTfB$OU<9w}ynBEV#=5ExsX_t{)o9|$hjASKuZ9uu0t%hzE(qwTg zPe;W#7%^;#97N65bMEPauaf_DbpN7q5<41jjo6?RfGIeOQ3N^R&-}BSWv4eHhGDw! z)w9;U!G)w8B?JekI-U!N6mfTOYSG@wW!V3DE)<%%yvBEk&uN*==|`C;ny+^GM3WF_ z4`{WYk-|00pi#h*fCNth=D+vA_wf684~7Cd=%20#^%y3#<_Xt2gg&y7qiJR49QeUn zUVKbj33>Q2vK{TT(fP|-i6CD025W%SxctVEM&cJ>5moD4RVFWLRN~uV*!bj;;q8thWf0kKEt5pf6AJblk+NG5OG0jmyR~W0akec zE0&)M`!2`;kskU)Zov=DTE<<-6w1+Wug7Si#)*`4IrA(Cya$gaufIsDA+#OrC_a|= z(Dn4Q8b%w0kqzFf!PPgE2Q$fukIrf<6Bf50d-52Xx7bshq$?Fxtu2yf;B&u{2>e=pQe3h=E1XU?TNp`??LGn;*>ZQVv>Hqj&rW_RSD`zh|p zUVr9Z|6QZ?q6p+%KezcbCh9zqH1+(I~FXRv3& zp}DEax%hwm|F3JUZT)~3`6ShaYX3WIrEMdh+{`iKgDE)JljGnZK;-zp{5wqtdsIhr zG`g+yd(2%yN`Zv{@&eN9pd~+yM~T^s2Y+HvXj~6Q--hY|$Q}2kq83_T!J??l~hS92-S2}gJemFTyX|xK9LK8d~_P%+qTgs@lMW{ z+dHI!AcW>Te!(+cb6Z3QqKc+mnJG>sE?M!B+1+vW` zw5nRO$nmq*Te~+iOT*fVyq2R1mF&fyTau4*mB4oSm~ecEr;r5uf{xoND><HvjpiFNgPzGxg>yu z*0*j5raD7cktT!G2mIMy;$Hky4_$^Thovw^7`WgO7W)tIyjW;N`rD`-;p5&^d0r>? zUrRkJu3@2D)d9IMq=bnZ|1Rc8PiBdm0MZi}ReWK{F8lpPontu4O_A!=s&7$On zp$xvK-QlS(Lo~rrcXe$Z@&6h(ER(%yPe9B2DwoT)*M;@X)UZeK&_gN@={MvXIcEGr z@r~hOHmi3@HNL=Sd;eM?8|5xaU@?Zv%Reqkxt_l9BW$?S_>sDy*m_Be;4HzM`XQDl z#Nb!gjJ*A4-gW77rNXO8X|mc@jB(e;7OyIhusz5A&dGrfuk_KIO8;0rP}Q{LW0;BU#{S?E>7cviFCt*`>F4%_a#5gNrqP(@obxh(o3 zwXwk2(JMjSs^{<{VpJ4|nY8%4A{Yp$vu%WkWk8f+d1T90B;&Y}pC<{psXRl>@hP8` zWlW5soOxf?UH#7~e!c;{sh-W?a7IW76V=&y2f+narlVKV7+cQUYZ)jg#xu5@po&}{ zBn$RO9djINI3JBud8uLuMN{HuNEzyy4r`NQXyPtWUT5UZRrWU^Ya+@_zRtt4Kk+Yd zs^Kfd-&fbxuK7c?BuvHdvfBHWe-Ic<o+am~G6WtXE_+I5vnJAJk! z96V3G{(B=#E!*cdGT=uC0QoS zZ63Q@=Vr&&tsj~|M!b5fdcubfrVuCx8Fh(T2*9&dRaLuG7G@s#BtQcr)YRBXh95l9 zD4WEb9D7||-LuTQZ~no9|I*86r(D&9`#3=BygWPr2Pj@43{8lSuM~Zb7n%$H1W~^* zC>KCiu(q-izWN8MFXt*iMv01%^D*Tox&$p2YimiG?mu`?mtBA8cgX=4TyUCp=cjg8 zc1Yr;QeC!KZRZ|^@NX>-Q7@YRy5TISLyy(`H*ekm2MPIyklJS!8%6QB9@jY$)B&%L zJ&3qW184}KG%v0uD7bt>hzCC0*w}y)h!EG+P&R?8>7AJj{_pe$Y;S;j8SSf)9r@tF z;PIf=mXMT0TY(R>b&z^mxHyyLibS+FWyvv`fwC-`POsOI2aB?=g!vM1E_E=Es#a$B zN<1+pL|VP*G=fHYs`qHs;u8|Qu-Xii>MR2fwUF~|Wk_Abx9cy8%Vw-!_-c@02MO&5 z%c2>Gr|r(;yPP-V4uzMe8;k=SX7DZo#Exq)M>x|@g(P>!PsM5lPzYlZCu`>m@Ww=1 z&)R34Ie<|Void%F*L#MAuZxTiG+Z0U{H}|D8`)1J)r`|-YZu|T7~8uxvb!>_ta_y8 zm)T~o*J1yr5`C>Z1Kf*(cNFw4ri0o@mS*kqobFQ{i6U*I zfJ;QPS1>1arGvm{jPfg=m&o9}Xob!@IF~GhIFF(Do>IoIoef5%4ASX}>x3q!d@|pS zMW6Y==45LNElx>I?(4q{t??R+=(y?l2#~nEqAN@G_r^672OqvJuGn0glcSYcxI5pB zXMgLMCNbZa5}Ou(HDX>lhLf_Ki%#YxuYtubN5A?&w^38J!QS6}frW@>S&7Bc;I?3( zE-QQD4W)mq{lD-V+{zEx=2gn2Z$t~MKP~3+n6LQ4bTHQJnEPTQ2k(!M(6TB=x$)^% z<1^O6<9$PjPfAB_$(+rX0$cCgzZg z+p0CE6s~U4D?S_nSnoKFjHUB`(k{QrRNoEMz#prq+vhI@A zmk@6G?5U@Cuk9_P`F4`_b?rNHm#PN_SW^X+4wyvInXKL%=7}>&JETJ?X~(H<2n)<4 zxgsC9#zHo#NKtIYaZM*}#$*;W-@!ELwxFzZ({qV#q zungo>7(O&&#ZQ-|y&GL!vU`9y^U9t7Y0E2J+Q~}YvHl^aBUw6exo_cpmieyRYH>W5 ziGSgbs`gm7o$3>}PLbkvCLSK>9N0MxIH*Wb3Zds~sOo|i4kOe6RJbR>tU#C&atN{} z6}zXY_=rVrgJuOtpRnr#T3<@-$C=5@Oij_kKoZtyFkNOl?T_jM9w~7uw~09H^0PTg zuJaTg(Yg@%Z~KX~DS}F%kjM$gwKlJQOd3`t02=v9<&;s^2j23JA0r=kUo%%6gf)4en;@ z?mj!0*Bw+`8?44%&-9q-ZC)sOJ0Z8bo7F}>q#BL2X zYi=)(wwJEGP%~fh7AX3`rSoIf@`)LmY(az4!-jvw=GN4YD@m=(dWw?sFL^!Xf*=i^ z@X-|8Vd;DR{tYLY8z7fa?6fV9!*qvU*NtQatCT?Ui4T9u9TXV8F_EP6RB1W57~x|F zM;{a`UeRosg7*~YGfAQ~Jc{RxP2Ff>1YGc-`7vcwrZgA}yoQf<$e2;beB7=-Kw;{N zNawkn`PhiHzvT6+knpJ9FUF9OXb<*3*x>EYMv)5y2I3)x&pr(Sj0no-D`OXH&vO^O zo@HM+d9me{U(wah{-d)(;O8$FULR+PSUjYEq`eL+bl8eNQR|=WL4GY?`8m{%coKh7 ztJ)^lSfBL-cQgBL;05KK&+DC_2JzVGI=1OBPQntoQe-BP4#7o&xc%7F`LOf*Hot_& zC?TQpMDigpVIq39KePkIHG z2tnvE;)FTA+}3;Mh3+3AyIf@zXAOIZb0Lk(1Hb$M4dUog!L%Np9-2PqmcG#P#cSt# z9qx^&)a}&hDwe!J4}r+&RBdT%2XQ4$K+lDfn=IC1|AVw-Y~AC>_pG(porUU99Su!q zxAx)j`@y?4aa3XY+KC@NwN+IdvB4NF0g2m=f56t&ij3h*Y&zyujdGLYw*$CCJFhklkoPvS~j%ZLz6oiS7mw~ce_28RZ zYb?<$H==;GXGlIcjUm8l0v%<0*Uwt&DB;q`$P!NV%6#Sce-U%BQlpZCNcW=|GMyjq zrgiq}BI6J5Sgw9;wp{{-N<+=2ueHlTjrWBYK!oH|XVN_a@V~lPo(XWO%L~1YAd=WJ zS5dj-^(@}u+z9iPMtvh^A{LaHUKHAPp@Ca6vs5 zYue<}m?dMaFK&*R0Goos3=s~P#@3q_Kg*FMMR*GBkm+sBQgz--LnPStYABh5j84*m z^@UeFN6{&tKYz~43l}ff=DeH-5|=Ik+9l2QbW61`37{)*T6SyxGqe2%hJ>_GFROej zosexP#4BWof~UHx>%AGlr-uMK@U{ZEotn!bTX+`rEToL`Fn&g)jgt4E?Cpix(?}8Mq?@SSQnQ=k66NA|!W3`uir@ zGb;vbZ8x_Dg?2OZ1Z1?%&qrzQ@U65aLjH%l|3?8Id;R5KbZ_kT2li4cMeO|;a6cb9 zceCls5P(8HEY8_0h!Z#`FE1a-u063WI57=a`(A)4-HhvSj}s`_)+dh_gTt$^kZ(m##LX|Av3?6U?(cIYcc?z@S42zwPTs)QKYGkbZ%Vieqyv{;+XkrJ20zPEyMJ!L-G?3p0ErR2<<%2;lGfne|IEbohZ2x1t9>ws2Wf}#ajfTkSpj(P}?TK9fu{uBJ5lY zacGtfE+OU%(QE@FBM5fv==>r?@t-)f8Ji=}B1GUEKlfV1r2KwHEv3;g6S)0jxdoJe zE)Xnka_e@stDU!7!htwDX2+i6(5rjxOG?V^vNI2hdIur}&VdvF4BnM8pr-(C4*+Hi zD8Xg%jC68AnV=nHZ7oCN$w1Pwvd!;$id^A@NNHTm>+S7joUoz__Wi{&H2`jh?UO3C zphdeR0+e3fsDQRvfkHJfoCU|t!<>B!XDPzVXm$!}f~0$AqqCr*pfd-NdkZPM*S3W( zV7x?z5NrTPLe<4ClvzyBE4>@$QJ~N&$>a6RKa#y{UDkg9=zYgEF@{6qPsrAs9Ibff zVS2>Sf|X;wDvj-7*&X#@8~551`iTWbz*0+Z zpf@au^)kT21EpM$T85Yr#0k6DEssh3VV-u5e$Pk;c%A`vvNF;p|@FBRj==GYr zt|aO=>CuVje_M`u>x=Zq3y3%Nnt3tk5S^XbrtIBV)gJ~b_dm##w8cTaeSqo2n-;2C zt`%u4Pa9zO*bf%w=hs;@2<+|bC=9(H@qyE>1Yyq6aE|dV znu|wHznGTjQwDI$`K6`G?GZQm{kd*mUtgdeeZzTY1&C?u4}Dy*pYO>8g`N?bDj+}2 z`Q>*bIjg&W$!}uOV^h5!$l`au7c^)CF{JghyhvR>m-&Xbyp=uPwbu`vmq~ntL)a*~iC46dG}@VQabAtA8>`Ou<(I73o$VNPC1o6xbMrf=sZp0f!y`ExIVo>^8|# zDNsb_pBrKQoeg{Uv`Fzw^QSjx1^?XEb>Bpf9{Fcps)t~6g*3SHsv!N9wpc3ja*dYN z{5*IOes#Rwd=zhyJ-I%JB;YPIyiCnTuo4es{;)_Iv&gF_K%N(f&YytoX}zOl4zNzG zlLjPc*hRbZFzdSxhYP>6fEbAXc=@*ad#ImXWLQk;ZgfKVK_f|S-6LT6mIg)4g5LO0 z_Qy$TZi8FK<_cI6jU1ctjL6~6h*yYCY6)%+Y1^rB=%-cW~`ES*3-9U zs=*Xr#pns*S@;0=9`hQ?6K3mFw5kzt}wy!SliF06Yj_Ndhh? zXuM&GRDyWz^A!X@ab{-b1ss0dgLA>Nx&S_EC*7;7!wgtD+B1`wpbPNk6|X3KLl^d$njjasvl{*! zB%|jZa{q?4G6H_Se}Nsbjyf0jY;$@wSj%e>fH=C)`@{?Ir@?uCSC^l~XXOM>)@rF{ zvjR9)V^@%rS8m7Oas?z{*JQ9|md9}*pWa+=nZOF1^a0@dYq|T+5Cuu#6E31Sv5%Ak z)we(R?0-$-Yj!qAYCayKUyAw~viu6LpOVG^GosR(OK~j;G}o?4lY0`e z=x}VyKDLhzh-}rl#4aFQaGH69{#nt(mX}X4JyPZfZ(z+r-2%=@zSpL2I_?yD@?+VL zURlqAZUjWtvxFvTu?_`};k1CQSz4KiZ*J3K%;Ya`StPo0*$)F|Zb&c*CVw?|O&k!TRn$q^Ni ze%5D}y-vGs_BCfzxy z22(&izTTuk5gV%a@dNKX@H_*25&WN@z{<5VWSWVgOSkRXjcJIY(a}N9VNX&N;)UPbI9Z8Ss$mtPHq=fan%Usl%1ZUT zxlmes={2wVJntLYAKiqvUllvzT=s@j=y75_VjvYb@>>`#at^va8ob*LkP}SOjog0| zdj~WFQeb@td=v_SLB|%U+eX zh7tA|l8vv*4!yB^mf3sL>K+&Fk4!^YFc1_e15=c9<$xQ9NPv-Pl8amc7-WrK8~Gq~ zl9xz4_*aw&5}-tWkjv?o?W4XYa-wXn{+bv0T5jSo#(tOUb#W3yXKv7~r3WP$J?0er zSE9!%?(4M(=GSNw)0(~}Yz=5>I6v~hJihXDh4!CjKIbzc-2XEBp7szR7s!avh3Ig^ zEFmV(wn!{MTNyx(XwZ2}cndgdnfDMZ)wKH>9#9x{+JO!9!xq0UDC5#q2ix0?#sxaz z#o}5zT1Lx_rmnB$7+<9r+5<9r2+@)LE5ge^P1r9PmpY6vpAIzFpCHgbkudLlpg_+H zm_Zb=RV~(W5KoG2v`d=#V}r5yw!V>I4)#&-yhk4BH}wU6x*h}OU5`Al<;ODbrRT#% zH?>AF_ZoaxudG18s`v@_As20^-h&aFBG)~x<=nN#OrX}t`7=b0P{|?y77ps}ySAcj{u?O~01J-Qleuj_u z&FjG^9O!{nGa%2}obN(0_s)=Ipa09lzf+GV&$#56qbfSKOzM8Hih@$xw>ttgfD)(x z@6DC4TtaGZL#7`e32*!IRPq!@C2O9-do%tmA^}%Ez-rwDL6tYyyaX)CnhJo70ld&9 zU^_$IS7M)HeoJ%4{7jh`5n@=G*(+e4!=DkS&J1-%?q#~j(GEHY27?*0XPifkD6ck= zRs=AHli&RG(~t|i<2azu8(ZUsroX*V>U=4)1+AoRzP`KLmS{P$>dqQf%{jhVLt`$D!o zmJBDeq{Q@ZugHaxQWgel2;3faTC4`}4S&!5jsGpmfKuC}|L#PS8pyl=bG~qCX$fHT z!b2~bc&VM|4?WpB%$nzo5y*M%WefQ6e#P}}tY@)kJDH2^oP3M?l^so_V;MCtneF>K z5fv1Cjfn(ewHk@R`77)uoQ}=nye0E((L+pKD4E^kU0KHe1V+0 zW@L@lddrp8%I!FIX@4kICf>)Uy{{jAt30iQ$Po8!`Jtutrt7UoEZ6?GzbkcZB~Wr# zD&~{WjzJri8S)V_&-dGFn1=D7M!SX_P;{DNYoQ?v0|n{RlJsjCi}kS4qhvQfP$07mFGGzQC@NxHJ`(TTyrYA9%76T+a9vV&PHo!py`da*8` ze}dY8ug&k33}E7LB$RMuH@~FNH^ck7wxAW?2{e(d!yoyYP9B7iYieJn?U~_Kqe*tYxo~}I>MNpQzYTVM2maJ zR}~?YJ&+WegJf8F>}rJe)2I9l$lWjgi!kdEPt@{pWSi$MvHcyEXZCTn{C0zxmNFsN zlFR_Np9i>>FUle?;0<8LxZ`J=y*|lTQJx@ZQbPnhOT`;BZ;}c?WG5t-Qq96kTCp-E zq&a%o*O>|`m?=cJANJc52m}J8i%`$E_SnOrMH_xXm);-p#2jy+PnV(@>*zog@$d8)f6)m=e+RcjZ*EDc&Ua~!UAg;Qb zo*lO#Y@0sMdAeP^FdZGreFWP>`T>3dBD$o_Mx1&47Oe(%C!#*ew-FYu`DuFhu|D(` z5ROYEtDF%gRj^fM5~F**+WKY4o@UiNiv?vrZF6(*EDP|lf4)dL>{K7^1Ryf};w zZ;y6-E((3ozC2S^3jn8<>{bU%<8JKbEqPB`#T9ZSe2phw*|k1yuS_7E zp3~Bj-++HV`oN&RHe5McS{#~nzFMpGV=d5+XC&qdpRbmxTJ0!+Prm!FfcnE#+2?p| z6lmbmbq_v8KI&N4i4G?c>PZGLG|q>=+DHZ~DP?T)EWm5qQ4<-n6jNGEF5+iu2wxh1 zly+C)%XIFyp*9hfWSD#|45zAbhrQU?fx@K&j~)9 zv(2!EO~&^Y0%W}?!{S>rQ2(;%*e#H6jM;R;J^-LWlvAe&s52!9hUb_BonOBBq?b0M zunIS!J+cU1BkBICWvtsz1XbiO4pg3B!eGe z6&%R9H3)A|U@1j^M0*2~J2miK>PEyB$V`5 z$5f;ZP-Pkf(Ku$L5^}|uQ3v0(xMz1tWiYj5xZfM!7#c`tPG{QtI60lzf+o=4@&#pz z_yYSm-pssaIzz?wEr}~syL!b`9HBzzd9R*5*&O~?Y+F2zp5Zxz>sG6m`p;y2c9>uQ zF{#@|hv1141(E&1HhsC`uj8-Xx05|5rAB~oO4>AhNvc^77>yKLV^@*(j z7HN^g0rfn0ZBzLxN`#-^)V_V=0?gq?0Q(0CdAT1Y3k)TNIV2>{_^(PX+~wGV?BqF`;_r84w{@f^$F%NIBUZzSoG#zRkv&h*5@tb8NL+8je&zZo z_e2uyEpRxPo{0jW23@4F(ZK6AQzb3h+tLMQXoJDTn7oVw@P;H1Bv%1 zHdj~{QV(VQ#x2y*;XZ)O01du+rX%e+zPvFK%F`5La+~AWD-0xlA4Z+mWklD=4+v_t zVZ)o)G`M%4wy3hVpy6shW=Gd!YH|^FP${20vY7=t#Wz&w+<68>YP@`(IuYxzoM3ow z=_9P&RwSn05?O7$NuxjH%3YslBM>{PQ$g-d*rSZIXKtqLlP?2 z^NyD#Q{d}Ai8VPY95&vVj=V-|iX9?Hc2>EUi;pv|#_{~AvmznU^ph6_sH~s}exj`M z=p88^WaSzK{ne}B`0s3Qe`iK~0}smrRnpUB?qU!q_EJzDb^#B1Fu%;w@Z(1Ozy=G@;{rt}LOG`|8fnIFOxqGPIaX8QK zk+|`!=noT`5^{dA5D@)hCR=RhU?ck@LPgea75i}NHYu>{sA|_~S&gZS6vn0JWYm$h zmp;uJXL%bTB1^HmIBeMdz`dzD1g?)^!&(OMCseHOry->VxW$eFvvp@4oLz-}Q)2f9iIEhht0Jne1oxP+KFI~OM=8US<_ z(1j-eENm`1QYRU^=l3l9w68ebm`TRvV6#9BzD}-q{6SEM8X+&!?%Po5v45`#=(AiB z_@He?7nVe$&(Sd?2l-^i#r5he=?~ivccSV)$s1Cy*1N8AS<$515VHEay%tJiwm(@$ zh0xahJ^=3$5)||rZeZ1X{=8h1S=1P;$%lpjyZI{NiaD1A#<`D`9sfltK_<7|A~OTSaEdz{UE?9@$QUDamZvKm3S5n(#=Aw%p`-)5zWDdI7p%Z?YR z{=2-5?`Jf(h)D3L{-5eL3G-E;|4N!~a`ApYP*T&so^l5C3;|EEkQ%vo@BHR3tmlI< z$KAU*Fo4k#clgY72`8{qc5Mjc9S`K{y_6P#`Bi8N&^jvDiOLrFv{<$imqkLND!}3QGC5gVhS2rNbQ70-%K30T_T37V4E@-tO)n$a$^; zPi)}g!`yUd#Z2lB$E9r&O?rX=V0v=zx6w|V@TJz-+0;FDJP3D`hYvZ{b2dJ(zmDBQ zKn_3b<`ni$nR2sv)sjpnRqK0QLdMXp5!fUO?$e{^NO#`G@2=t=9PIhFQb)!|3&Mal z1Yex)mG2cl_pto`n(QPXlfVa@t%ObeuM><>%Ym>7sFZ*w?>P}A9-cpU9S!*SJ;1(> zF*7^c8URrVw>CC3vioVOE$~S55oA>y5*cSza!5_jE({~#Vx?B4vrJtw>YAFgp2mDU zJT`C9s1U|J5W->{-s2<`e2w%;5Raw;9pD!XhKX1~wMzsq44is*Fz2^{z6$$YZ!?~n zn&doUQ_uzlP}3SOPW&odY735n3Z{l1l(Bey#vJ%hF0Gf=W{QdO@%aU~g|3!$$3{RqmAR{GZ7wQYSa-X9rr7d4Ff!Doib-d10EaEXIp0u>I zKzqKVRq^1DU}6-gAQ({JzoQu(4b~B#*O`&}{?kJ+v9F%I%qTx?O-S_xYT8BO7N{%0V=3hazs7$sYS7zqbb#g1*JrCx(b!m8d&(JH! z$Hf_e$~kolqYNU)O#EV3Pfw{d3u3kG+W=?h>~+SOQYoO=O~wrvzT6-!2CW3dm+J{( zPV>b;ABJ;# z0nw04=f^bm?+RxVnf#Cv1u_KQuP}gK8ccgO)z7`$J=tUPC73FP@&<@+(~~9(AQ!=E z4fYEKNrSj2wtXD9R)0c=k3#P(6z3Nf#w?B12ef6Foo#PgnwilHkA2!tn{jLVHVUgS z^=KIBR&uYiV)-@J-#Xy+Zx*i)LPLk?k=INiCkGZN!u>7|-~&DCE~!Jt9ujS=EQF%G ztjFYZwUgWT2O^}bQoRH`YzFs1nDE=FqYgP|oE7LGD39*WKZB%2CJ0kgT_>!0x(NV@ z^=u2)({&*#{oR?6$5SSv0Zr|@mM|(Ns{NC zp6$TAR#$ELN+hfaC}{Mta4IZjN`K54-!Dc1r<~35d}F$ zhrG2I4II%{u-%KBTtc$kqHl6BpIlNND24u{M?U%I0QJP9kEcZx+?OV;MV+>SfyGRU zPFb$N`j9_8aOMUXQ-Ihy8tFV$Fm1`f&^hh7U%<){Ezyg+sMOYk7)qca*YnUIZeiTt z;igLfW!wX>P&g;Z#guE2Fanv= z4fu=!?8{v>o|n9;coN5gma+&h_k8WHGoKLgJ@0&{M*Z3+rqYG=9X;m04%}nX)U2$n zYpV3beD7hfr{nP~p%GG7v6><(q`D1eH0j0Sp7kyZ6Ll4_5xqbB9YBHxFl0Mb6PGyw z*Z51mE_wnh;`b^HzDyjYv4m)^&N)_69z^D^^f} z9e@bk1Mf6Dk9Oy}>;zWQ;>U!pn!eYuP%cd9^jWDGE^%CyYFhmA*WgU!gHn`NHjIx9 z0bC5&GVbkz1>bY~r1{vIyhn7kr2elI3X!}7dP(@4NCmrjVOPubta@%Z%RYQ(lWCwoWs17@9E{ihGg5k z&<6axPlw++?U;9WBfTPqhdWlo3eIY#qLp`coe=jupncr#SQOQCB4jB_O z$?p8eyCuCqzzybPj#oct+rT64lW?~!J^-oFXbq>gKLW{r#}r~C6AC)Lg%=Nw$J0zzeSpF^#tJ3V)Wf2A;QiVD@HDLYOr}_ z1xM8J<(lPZ4RIIbe1g5yM-qwa(J0wSmx%=8Q|D!6ks|l|FX&zhn^Fdc?5Cz-4al+$ z!Bg( ziq%sqdrwbK;O-bCmtvMNC^q17=8=)&X{waydn9la>VDWN(16xG@&zS;-x}q2i0sSV z79_e`Q!=o?=zy-#?Ol%MgF%#+M?HLP-I{T+LsoYmlLvp*aM-zQx%Xq#eql3Q$I*mw zdlPfi1wu%2#Yu?m2>V@}& z%)ek9>Fo5rUMly3x5a)Ah#i4gsUgx%_U>N_zP z2e!v$zn7N>ska|;b+1pi0g(fsVmE$8jPs?5iJ$g|y}dnBdPTXIpJ+{{vZ3^M8|pD zSL}FQ4EZlx9~>2+oRZ*qH2t*gXi`nOa&u@FmEgG#t|fzkvTa%wF-M+r*0u*fxV3M? zZE!10Rvc?liHl!`^nu>tyDByT9E7-vN+&@1?hxMeoY*Guaxf&KqYnalWZ%sMFzn1u z)C-0n7Xu9$d42pf)r72u3IwlX97TynR=F% zJ`GSNQoQH>=Q>lBl-H!6?r3j+^~qyN$X)*7WKxy#?C>DLAo(;s%T6yTP$Wzqd#3rK zfDCvx%AIK6VO1p5l=|A}5Vf#hHWzmR4O$$MFa^%EAtDzs&S7yp*Tuy;%L)4dK*N3= zfCDLm-LSs?<~L1NC8mF#tMR_nk(K*DxR-YtxvkxR8}sV~q9tytar+)1mXb{8)n?Th zbnXQ4=I&=ZTIm6jZvff`@DwMJr-GtaG}Y9)0n(1=-~mm{_+hm+qkx5oq2(3d?@@$~ z_wFPoPrW~J<1sr*O#kxbOmx17cJDsOy8^%x0dJ)z5a{1x`*r;8J0OhVFBeY}14^1b zEd=9K6xfJbebvmm-@f|Wy*ePwCZ}v-4;fRo7|8#rbN()cY@JOxgo&|F5x;iWzuHCo zo%H}NPYb8p2V~%>f>`p`mercqZCv+APJ6cx>?pgD2d7wvlN-kzM&Og!5jYxsZR)F& zae5Cn1%Pi01vV|^W5u(%$HS8kxET)PrneYe`U>{temCH>_Pj9k%B7sF_7Vm5E zA;@iu+Rk0^y|dtuYIv#L7xQ>iJ{FjpaMGC@xX4`xgQ#`R(~jgJVaoX3i{FW*#d#`J z0<~_8UF-~~8Ccc83B<|jH#+N+{RVq&ub`B(KhAlrK#BObgvsY2Vq!NE`6sTX9|t4gVmn)wt?lxY$BLN>H#sy~E<`<&d)&0! z`ueP1_HInfG2Cq#&sfbdWnbC3m2Nx89u=x?>JSpT)(B)yFJrFF0Lux zu}u^BonZGM!GZ5EI`1p%=sO9zT@0ah^e$ zGU+mdUVz$A_7=Ryfvb0*Y-=DxyDMw&u%3TQ!@l*{J)>k>Cu6hQXo);@lWZ(2-o+bg zRd&M#h?`ju+{_Bc!TxlQxexC~f+%rA^>bWF*hgGL#5Vo;5dn`HM4$mh_gM~6i1qV=BT4xkqdlrdm{NR2)j3R3Lf;&?m~D_=)JWC+!mO|y&$>>)VU zFP%Q$$$z&;Zqy3Fn{9m*eeE!hoq#O?4%hhq_do9(ZC+(R`GPC$eIJo-7iQ@7{(OE? zoOeX9&F0u66T}(pFIDMPiJaRY`^)GO;57J@xnksxIZ^bu*k5@i?)_gMVtD!?IC0ef z`~VV+0QRqOF4+Cw{%@}p0$(P`DxUbFk`xmb z=r6W5X2=RFdS*ImeP=2}_Ppn)nz~Hzb)UTyutw>cZE;@76{nky=>0Z6*HhkNcDn5^ zk8B(=*;l}d67r8eED9`St|)R}8x*qc^qgG+HOc$UD%^QqUcAvYI@uhtfc<8pnv-1t!M-fcIj9;Z zN?mv>qo}T8X~eF5^O=TN<&tl2xpsVGD>bQf3xm&I#J@lMZMglx{HSK$>e%;&tNgx4 z&Mdc|z^u$gD(zsg4AYhaZAUDGo2F3vTS8H29GvLCu6*$)t(ctzoqc`Y(#%a~qrg}z z_?mBFcuFSv-K7*E|VYj%tn%d z(xes?jDL%>g*D~ECLF#Wol2~l+>@pK%{~8bE$;uS9G$a@PV=%2SJ8oh&zApV3?`117C>Xn>LDEdOao+i# zUm$}rQn({L9E%~yyC+$wXkz@!N;*5v#k+jgXL3f!$*_EzyZ)W zY20A_A$`oIZ)#ZwP{DCsCkvFWzXwsKbXUk z!Zr-}aPT57$U*aZLpSX9xYB*-DZ5`vtrHlumOgzqsFW2@gg<5^TNJGV_8c8QpXcoh z?<}5egST@i2jhn%kOe>aB!N@&W7yYDzUA1SKCfK~6*b&*2<~*!`t`8TYWSPVN|I-4 zV}7U7R}z5|Sji%{6>Fy@&QCTi9@@fWozy!Y?KHkEEhrF6q(o~?X3cqCs+^kL&qu;oSKDybNVvLwf}fNu=UF2_qA(@p2RI}n83b; zWtEP4Pu1#b(mAS2n9RD`_lNyrFt?ABdLb!mlHu={?JI>Saan4-FwbPnS6cJ7f96}3 zGCAM1=m9>}kG?ey7SV!q#xGYs@bsr1JYGqq`&oY}X83c)mlqN|RE_zbnTHJ|+maIA zihm2X-z*Wxy`@0%)8-H}tV9MO+|Y8eP3C(So`EQ4E)YDJ;9lLlq+0M%cyYqDZ`iZr zZKE#q+SMOnyTgE4un7&jTFp?x{U$SWYxnX8hoWx1m!3E6Q>A2NWVreshwrAGr%mbm zPXE$KQU?9r;-M#FWCKK@pinZJ?3#Q)H<#G3G)2ozn&$smjEK{!{Wq!K9x0*A2JWGM z#`{>aCVlM~-q6sor7jrMBk-mGqy7EdnztdM&sT_@BF2aw+r+{Sv(VlWL;J zt0-Rf;h7vIqD=t~jhj}U4!O2XMTYatG)T&&Ylg~lS1w1RKinP1r1LmRytn>P+A^6o zK|KCTFZ_RY-f8z)k*yKncE!O~2M0z>Xhr5`vH8A5d8f8qlM}@0Gwv2`d^pWgNU3bZ zXwuEbqQwU_qxC!}sN+?~$vZHzL{ti?TB5J2OQ2Tm`jPYJ#Y7Fc?+Az7#%-rUwpG$d zN159O;h%ck?=#OQU8&rzuU~#~&^S9YquBIFlb(bHyOMY<5wJ(vB6cny`KmiTK~58A z)j+!th|9ZJ=u!2Z1g?<%t=qabmbW!PoU5bk+}0dm%Uzr_qZ?$O6jVej!O~vdJ%~5r ztf_eF%8NRjn33pC#5jLHEDQW8J+sf2KfI`$V!(OJ@1*fh`|REZyd z;6t^nJ)vNyQm1a@4AjcjC#SK%PTfnOJG$QcF=WYYGhIG==x{;ycx7EZUbOv}uQ(}A zH|pOXb%aby{~T;5HV&LwOJZA3i**~piD?2NblG^?`7_Pz$W=^;%y3fUfo=s8CwFhQ z1N*qZ;GUH=!@S0hGDlts|At1}RQi{dGoPI-_Wkw~RU@u^3$Av0s+9LDnVCjYpyq|l z+QULpk%CBrTn}xY?-}&;`6rLt1sOfA*9`QuTOp1mixRCYl z2e^@wOazBZxxznisM!{qeRL5Zf4WRKq!g9#UlTTome?)y(MqbInd%4vPk~T27BcXU zwesg`8U*qp2>XscHRb4VV zE{`)P*dM$Nd6K4^XF9dSXYLBye`JrqE=g=Q^48}uTgh>s<~rXZ86%@dPPvGhg|Wl; zq@luFMMbSG@|S;AGGn&FqBuQVi!B3HS9J;7tKNa#qY{YO2`3Pg zFx865-TK(1>TG)kr-2TnroW$KsYKtlZ9-F^>>iWVr~`)8<)VDI=>}FUi6y9QDfjtx zY~oR8M4Z65&G#O^kIU3PPLr4!ZjMW=_(Ve%S~Fx?Vbzx-j@zh|`#?ABDoSEi@bb6B zudYO_F>UNXQ@X3Tln`|%f)7Qn^*vEh$as7GD^wJOeKEh4_a3iklsXd9{ESwg&dDS) z=&!$9pgs-N1uqa{eM2;Y=wAsNPDKee;K)_0`b(o1ag69Q>t|#R~*`-WMBhO_V%mi87 zDpn(Z$+sY@+!69jUl4zEEoip0LYqCz@ib&%2feq5p0s5ZIkIBl{C&V_r#Nt4a)f=1 z0_WZ*+rQjNLp6gL>+rJGZ%jdi3!C~gIcRK@~}`xd(UEEa1cca*z^fac&}auf;-0V zSA?#!-EPGVqmam$ZDeAyY!n)-&BCQ%kY?5-(nO;IU^bw2>OD7xj7evfv zA=9r4a-4p9dzW~ihK)d5F>44gG9>*j{7RQikO%I_eRv?L^~U|*HKjyluQjliehBjS z`IawVdn#69g7v_jK*lyMDpY<#gLLL_7)D<<&IrF&5d8(*UIby-;0oqGaQSd9bsHtN zxwG!nz1M|y+Xm^o)Z}9`aJM^0^}qWr@j0g0VKdIx7gnM;QAuhb@rar0Z1b zkWX+9V71F{J+jboCUmky^9hCe1?d}kui|8nuc zT2pVvGxXcGI5Tr|&HNX?qBspzc?^C8079V|;46-3^q0Hj(UfCi%qa_ahJ*&tNH#tDC{n2m!12vL0p! z824qDU}Av#3cE&*-qu1t=qIXTKvSDd+G4a)yWoAcviY&4^t2^WE1>@4);FIZx64V zqxV{N<5POe#%!nBSGbVYQ{7O(cu~e~$g=wSNp+*$)X1Zlnf{L&3&=wv`H=3-k4J@v zcVTUnJf>4~)AUh@yK+cxVh{H&uHmfR>{ zR3M?N>5kz}P^x@3I1yu>rIeeQ*%C%>Qtg&Kgr!(~OQoaJlPAM+#&jxij!chnyKWyNE8< z2sILc3c70e^Co~(KYf)ve28a47I>LWxiXr=L{rzkh4*RQrC=klj2wME>Oqeqk$x~= zKZusUwcy&A<_HMUmeaW}yIH0Tr*PhTV?z*F%r$Wa!B9C@bl+|DY#mF!?^E;Vzkqu& zhH`5rJ{PQ)W0Ch$-|R$q9i_?cw_JzW4zO%B(mp?b zDIV?Gy()Hu7MtTOkqmqyv%3dtPikWll+kY~{n7v6bo%a9HDJR_6q@k!`R>IG)d%w6 zK+KJ}o zp>oWNcHI=Qiz_-_O)@DryM^DKW%&7qU=m8AB##uR#2x3V0> zH4qVhNl)WkoB)r{UDa%R$Y}7$aJE-Ho8X}bR82bMLe?B1 zzOx$8@m7{S8AWJ_*io_UZS2Vkepdb`It)XOf0SP4Mjaa;Z4y}TlVy9L#gKcO$L=eL z;}s6w;&JzA^hB5}yHaji+Rr57sH%0FYN{{jtNRwPSMC_x3U3V^ zb-nfGaLn`t4(|PviYiGo+Jt@Iu_q1V>~J-j&oYL~(lDHm`v=uM(^d%alUvYun{k(i zJgkW`f^@-VBFcYazovY84LS--osHq(abgHL`Lmf@2|_eqwVhanOz*1%_-W zx(ZK~WkDlD6Ue+}S%K>K5sYgSSacc1UdS&higl|5TU(cf&uZueu7SM^W(Ta*5zl?g z(SYZQvn~9i7DpY;dLQCl!=bDNnR_xwO~5F|Vcy%tv|ky5U=C)aB5lMUGLL81$(5&O-!dC+wCiJF^$Q4=UbqzNfpl zSMwKuw*pssOR++;84c(c>EPT~Kf`Zx=vEF{Zyh#sw`nBb65*p*{+!+jw8Mx=zB=gh z@bO7=z8rc>nL+MnNC;28grkhj(bGUX8HkZ>&ULe#KXzmWBd^jZ3}#Dq`_s9_Pa3ae zl72bAReQ7qjTa`@7m82c15sM}j08ASRHjeXz22+P&GAI{KkD*nX7&f!@k7%stINFZ zM!JXZ5mx&x}WBQosi}8U|lruBX{MeMqQ>qj<{Z)ib7+91{cU0 z<_1`D%sQEn+Yev9%2EE@v2t4^LM21q*zef+PV}4yKQC`ugLHbbmKFKiXmnODULEG& zABW2Rph;8br8DOKSESbQfo{gI;q(37bokNi=*Pq1l;gc|8JGfH;g%m_(#)RU}PkBQT7r$XEc-YJn2j}qYZwW5hxn}HPW@m$Ozgz1GeA?!^H;oS{Z=Zbb15jwd`#nkd zYa3ryC}R4-i*g*ea6?A7<|JL(3L_v<3PCiGK0M_V5f9k0q+RbD7TGz3Cy+;vlpPuAUUB zduV#u@8UP2|L4cCksLZV;U_RBeNG5SSH0frak&v*-0;}3Wz}~1xN0B6wqLbo>UeMb zt(dDvleLhkJE}}D!KtYpzPdQN*A73H#77>dD^wl_lKFO%OB_D?TcO>dEC}pF@N-Y` z`=AAON+zGlszer5dM4)iTs!Pvwckc*|298rJg5rpqY(u@W|y9L7R}+@RU65O?GY}S z>gBTOvJa4VrAq@p>F`bD60T9*P__SC;rz>>@oAIj)$6yvkM;AI(sH%k?27)~mob86 zrRE}sf#K6LA+VybQ0z=9v)K#V)hF2~M6?Fiwm^zV)XK}nmS6@yzXDQwai?G`2`%4) z&}rG}VaRByV>;83J-s+m7uP88pgC-QvoTKyM0nMbh3$(oa{J*A0fPRoLG_nuzPA8W0ydDV>dxunO^cww)C1Iya1Zk*~G8BHO3Xqa9F;Kp)mgBoNh4FN3{Ws_9OS0eV{RnZhZTmrfx5n<(70}B1Mv)<2VKG zw--{0z0zRi?OpgiQWmH-L-<+C(^;kJBaf%L*A8vfZxc_6X&K$(2X{NL1ou0lV9l#O z3n(ajCjur@@HOMexe`-s*W3&)dFlN>Fn8TrVugAaET&jB@+lQVZ>bqMm8?8*fOVS2 zqFIy?G0NIf-(<}B)>a?Yp?M{j2u&4jSZ^fg%a zxo$>_HskR;3GU&al2yvY)+YaFC@bxz8o_|&W>w|r*IEH9X43?Zo(QVjYqMFUb1ddJ z9^gtyU1sdc9Z=_B0ovjlfd9uBVgYz{0E@$-{Hn&PY>{uOICsLwufR`rMpzoxwIHe^ zL#JZTkJc*Zd8CeOTG;q?)_bT;>!NR|iL%t~sza{xnS4}J3T|Ot^}PNxB_F+*RDRmf zG({%@g(-7qYHf#5sx)3l)ymITD}K@3S5-I6S(4cJY*&Z>7)kDD=Og-%TF3cw6N`7p zdME#jzWLtlUZTCWs>PzwrN+1Kcu=wmhS8&q7c0zJNXk}TREZs}hTN8mdiQ+pm!`FL zu>)C!=S?tat<+Aji%TV)0m9~K;EqzajEw2ps=3UX=nfy6;64dfcHAh-gw<{M>StzM z*V&(=Z!WCDRCjFuPjlz}$oAg<{f^T`aXP3P%{f(76h&1-(b_v!?7g=dLCp@TR#ff1 zcTpo&jFyrjLG7)C*wm^W_d9LR>2p?>m3MC!f!IzQ*JAe05YvN!|2~>$yuT zrpedhyEc={bT-_IGHU-y#F&D$%M{>1wbS&gkR(SiWc0U>6 z{XObJ^8Idi51>p3^Gsh{SQwL%1*zUyW20~r`(!kaw;p4FOx_^+#rJ6AFVn>Z{oo63 zjozWwaiKTQjk@cRp57QJDj6(Lrr&j;dhqor>UU$|^(HD2TW(MUq0$bL+h{yeP|c$c zu93G{F=Ah);yBlpcJ9(m%VYPh(POh>^oI)qY3TatG}AW9s1oKi^s$2yiGDHl%ycQ8_vlL>^mU6Y2@7W~PGL-I+eNb2YqWNH{*} z)SkL|uu1VvgCZ#=RJ?faJ-YO|xPgGO2VMKF`pY?d4nOCDsHM5j0UiQ6Ia{W`$-1!j z`j%vs%QGk8i(nRK|29%kYK;sr>GC~d3CO%4jz772Agh!(X_Bqc>M&DPxK3P%AXx>< zpMm`%U9++vvPrto-30N1<9*d>oMCR)#$CzH!hyfqlf&M?r%A1!JJ6mR)M{&^(`R402IN}$W~Ij& z!sMM>u^uT7My(>}b3fcMz)Z5H9>4hyldVSY+E;@6$CFeK?wEdhO-559$spijxjFZF z@q9O z?xqKGu7?XKNtkJ?nDSxx+{-RA9ckwfkYs~i<6zTq>RoH53yT#%tnKPf^tBDgAQwVAjqgoRqU z^!i~Y>pEABCqVzQw1Q{r0hEl^m*7)64zp%eZ%@p4{rmnhc0MSZu=iZXt@O>z?BK_| zEiy?4+;sKq&J2I&Z9-UphXwgM2UDt6g0NRDh=Z-697KbSB(sf<|>O-4??=GFoGr^TAu{dxDRc5ZT$N$bA`mTAM zaPnr(UD4Tb8+qy7(Ct0*C|-&DBHE*uG$!rQ9At7tM+q^C32zEbhf28{w`N1Tq`}@P z1@cJ`F+_#D5aW%WMIBwmht?s&-C0MMjl>ZV_}fCEGU*OxpBDNGK(KmA51HLabPgOJ zGQMPH>38X-eAPmJL3(8dHVpVy?{^#jGL|{uwn&2~ogYN(?<-}CjE}iVez$Iu300fG z(%f7KLvws`t1Z}QHQI03*U6*LSNjqoXRhgal3#@zQqALhpk}1=*dRXtjxctUI+&u> zGzY)U!P;B!k)Z)tqZM^Bkq&6T0J+a{pTzV&Cc4;nrB^!iW!arX?l%SyG@L!x@943m+qbUy_e z4kZPYpg#|8Pyx{?VOpMNhFGplSD)Y8TFi)j#S;@6JmS!xx4aXzBx!n9+ko!n&B^q} z=uvPp7%hy?1t||y9B9Fp?#kUUYV^}Lc@Rfesageuob&`9K~+sFtg3eSql}4plC;BB zveC58PzUi>@hahRrYs1bC0+-IlABVhnXBRK>|Hib$C<_|tZc_pdTRtEhQBOxpff5J zeA;%qsm-~YENd{h>e>_~G@pou z+UpcwW*W8061TYrBm-F+V?4CTaUWoT`fkgneLTUs;`G(2@g#>%wFk7oj^jm-z=&hf zF~nJ9Q=vn$Yc-%pNK~$5Wjo3qIbz>%Wov2d0qR}&w%@r+x@$uWY?_^9?@m>>09_zX zjsuUh1#Kp41!$HXPt<||cMNC!istfJ#>>uKSeC8&LKH)C$Gb**`nK|?uhzkQeCp-J zwrwuza}fG<9K1U{$4yMC@;_zwv1=5m)!VJSWy?~KS12`3Z;**hJ!s*}f7xjNIecJ= z)gq|(RZUkp+Ql*1ed-*FW?8XlAs#Y=cA4}Z2xd?y{J_AJ*9FHmK?Dp$$J!_t^BY zI*5N}Y#^2)o+m6J;GL9#%=jO+%hvW8t{w5TPjfIgSC}vd)jmy0{|%nGP^T3bmE})p2?Bp95=vu<$`2CoX$5A+uT`5+Almz!in-+eW(>LrriGTQKus4ID&v(s9R3aYUs29 z>1&PC$CUU;xeFJxE{M5(% zc1`6pPY=B&q@7eFeq17(&S+eUcY=c<%7~i7SHp-Ye9k5MwpRMF$!-gi(`K{=CnzMV z#Gle_?+PgK#HZ)^*TwRAa*pw;L1-#oi*Gm(ZPzzdS#unnqgzC{eo}t-)Jl!y)ooaDe>VZJ5HQ*=jR21qV5fh9dK_g zByIO|CMY))W~V~r&a~aZM4*E;3*Qo|;+lbQ)!K0x|23oRuQJZ>57!@aja+)5+pm`! zGsFNJ(-~zKAh%Iay&OlBW#dg0@DH3;8!^2J!>Bb1NTI%`za>eIrF|ph%u{O;Af7QY z1G0E_I07)6aAbFrJy)P+FDYXRy=j`r&|1QvbZZTDPswIN~(_`m=;OG9fVW?k%cQ?5_TAqKiMA6{J+g3mcq~l`MGY zc7=v-;&Bs2wAza_ja!X0*Ri*Hr={>NFBU&gm10|#DX8NULBFB>g$vEu(v}^1m;4cH z9y%G4qn|t;SNj)E!zFMFWxZWphAkeO*M_Vu#ZovI8|l#kNxk!I_d?sw)AQfe<}bab z`{-Gt6(T}Fgzmtua*U9_m3m=s+>=77%p+{+exq=AklIt+!*vlz?x9n?i~5+fqKWiE zC6NAkf0Wi-|1xjFCR{t8dr?n)fCxL)TA7jfAJ>y1a^h&UxM9!SBD14Wz5Hme46pny z4}F`7cf`0?h0xhKxE`Mo-`{qbkFCBm^{ zFvalGSBK~B#Z4MEuE|+HI-Yfu{?uBU6mI2+$A|L@F9zE0-XPvTrbbNyPR2L~%Axl5 zPI`2cE8`@qd)G$Q)0I_gVxug;yqE=7dhurb;b1CAU;mic{#1RA2@`6LBj66*8k7DA z+@~lA=PKU;cHNY~Z&)YpRBih{lo?UYa>jqblt$W<8=5M=VrW^Vbz#c*HZHn1!?SU6J?&-vG-)m7h4_Wq_7`WT$w zt*Eb!6h&ur3iN&Of94m(0`tE)>tv9E@X9I+rrZ`=QCk z6S7IA>jT9G4v-s0{(P8oxCZ*lCcoAy) zK3X1;5bNb(zM#)qbAy%H;p|eF^o$IqM1~0J`G*q3O*k`8eU!;~P1l{vA-uvrkd5_#Phdpr)jW6`O{C~{gxCE{09(LW9>Qri1$oHupI~+d`a3%1Yh1V{Xwqv(AFWGQhA98=wYh;mh{gej5JbEJ`#p9AU z9ynEhHjhWHpVN8Q=_Mxif;l45zs+^P9MWLjY7<7(~KIyYv1wMU2I zS%u$}zRd^n{3HX#2<}cPYfyUq1KbFP|G>H%8ABv|O~{Gj-I~x@7;s6z_id0wYyd0R zjglMzT4~Ql)vn8k@EfOr_1TEj7Arw zrG}hW`rqw%@0Wi^)f*X#(}nr*+hKNI1Eh#So7ACHEdEvmh)E}Db7LYps>-KxxK^Lk z?fc3d5SH;H+F_j|RTF}wQ3m*11`D_2=A3d2Ty;~xhrKT%lf7+}HfGhBui9>pUx4oUJBVC<+~MFX`4q zG;U!7;5jsZ*h0=xy!GqJVVm^O=k;yM`&#wt_6_4B-GC*0wp+t8JiyUFmAdN!h49V)3H(?d7K>2BD%9;i@PNH#6 zoWAB6B4Yf_r+Tze)E+1WT0XqaGjKo;by>5^}vM%mZprFN}r4h?C7}paX8GpX-_5RvtQNJ^;_~F z(I2JZHFkqKL<`l}!e>Y^0&H`4YhEky=;Z7BSTF&-J`0}VK`9T7>d?=x-4#uc%+SPV zf#J8oF?(cScT4Uh9Iv}6QdD<3R{_P~dO6vAGfB4NVX;9CPfp2zgPC-%g!sG)Y<>C1 z)&2O|udJgv(s%bvG3BAS+%4>yb6?Kl(U)kdqeqc}dkJ?i$~Q^bt;11;_wBU->-SvhEet*=KsJ3 ziCdcP%U|eUh|s@u%u}blKcA^n!qT_KbYuedSrp-Nq@S*QDxW;87j_S+V($?Qa{i6$^O0iM?3` zj410R=Yzye3ym^!hO}p-*lJEn0$ybJsK%{j^=OFQQ(v%TaW28eBhk?TnKH+X$=a`A z^q6{x>EWsarIs42?h8rq>DiSqHv}RS0Bhg}3b;#396?wL;6^THLL{)ZpZ&?@VrfRO z++fEAXlRy5pfV4@cIjeP&Z&k0#E?$ds|rc#&n5v>NZJ^9%|nJ6xQ#z5@Q;jzd%{S!Ugz$`Konn23Z0& zU{^uL?qJoO9RRO{ZwZC$4`OWBSriiodwZv^d(15@>7uNo1h%;IFXGaga~0@g6;SKT z94pBgjU(2Y)PJq@|B@cH*Bj5D?allR&=+Tun12o$FrVfWz7D{yjencMz9>FStzPys z%Z>+p-vCT#dwt>_>1q}fyv)6x$+1Kxy%OPpGuUEgU0mIfh6bmUl zNq$GQ4=L1)b*$q9d$TU}J#XiOj04c7h%Xll(5M0&=tIe9Lo0K{F9XG2=|{=kAThSG z;M3;1&jB??3taq6H}hH!ug}5GDRP>*5SP~vn0PUO2NQ9cmOiy}Nh3S^)2XdkJPCab zKk=4Np~*S?Z=`V_QQSlas2kNVuuP8VNd=IP99l^c&#;mFE2l(;WqU#5MZsLA0)>+A8dp;$yW6x^I#0-ssW6xCIBe- z80mL_i9hvL58a;?jEAv2kV-34CBz!ax$t5#q#4nh;k!4(Pt*q+?>+cZkt&?{ik<+}isJWZp3O-29sGzlFg95>uYtus%zL?>?pPs%)GuD z!gbL4s97^1Y7MkPIWI%obH%``gr|u^@B#R8Fby!yVD;L^f!6>V7d~Mpm%QauZSZW# z=ySS68`rW_jEK+7*%)cDECH?sI8A5s)hm}+6d8C-rGaP|uPV7^G}a37=(u@>V)BEbEKjBEA78=w`Nh>z zg#Scwa7=k(fxhX9s5N@eiUVFT~@==>| zL=Z72K}q0ulKQV)KjNGaYJa-Zz>B?L8_BUTpC)`@fM9>vJpXwQtngN^lzr#S{s#8)Kn<009D|!fU_!3u8f|ZKH&USryd3V>diRbc-RbR<%-@M8qA+w9;rmT zq)3M=S!kPE6E!)tZZ5^VUS`YO;c{$L^5^ik(p7x-k~Sp>;usA@?c5R^}hJM z?f{(eQizLdz94k4NJz?A7Yt*;A@E9GCV>E%UwdoDvvZ7op3Q?0sEe!m*i7RWQfVSs zlZR~#A|T-he!E70u}}YPQaPM;6Yq~feam=1fa-(ofrcmen1GlSp;E62n`K$TN=PvH zGs>$xHxOZ$n|z)-0gnwFUEk0#9(s}QY3wU2E5Y?qTJ+9cE6&;rctri8#e^!-l?`tI zRb6mz;=!)K*M=K$vb*?7)3n(Y)vqD6+@eDHF<@r57eeUCNYHd~ z=UgO1>9QD_=X6~pT?N8Vr4&O~Fa$xk1jX%gyq)1a_vW*Vxk2olwuSate}8f|fC|5V z?rXsxpx1x9jOdCKXC&#+{Gy+FdtpQmyxo;`Nc!_IgzV%Cw#} z-cI$p`=@}ah#Dd-Txvhc#t_i!%HhqHqLCqz1q{^8N5@j1u}<*QG7F6@Ckw^3Dk7eL zuHX$)&JI(?e}>SiS?6RgaFU-s^S$B;!!XeBgSk|qAn~79ywYcCKm9~5pM!Jo2mK4e z(bqRIVlyitCy$ALuU3ZqAm5IqlIkqq|Gn5HagO1e7{`|5sZ{?e{P9nswzmk%2}B4E z8VQHKC9Yw9yp+ehNfkl=sNMYa%xoMGP^te}(EWW5{=X-1|DWQ&|Cc|P0Ifc@K$nzY zgM*RcQMZYFIF%esWGiyhAxyaD;MtiQ)U1ExKmUDU_8*)liD4l9_#OesI^Plr+xg;q zGbRU2R`%=c*e=$ji%_iHmIAU0BsaD=uRe4*nr zixz1xU3QMi3+g)@zQmzi1_*1Ccl56cPd{EXO*_(a`qPX2Sp3m^&&1(UL;aiw5Gae0 zQWrTqh^a>{w@JV#HY%!Qpl^bRhZ-sH!Musuq8*c*@p_BH4@dWW75;M=z{dL_$dOAk za}Bzls!iB=4egXoIUKkG1oL7S*}iN=aLJncdm@uOJQttg4aU57@*S4w(7ETF8Pa?> z|F;(f5=r_HBB8i`Gvmd!gV&6Xh@I!&u1Pl+GEui7N6cd`$By(ke1SISQ9zQ(6}~4F z(#{8<{ZafTv)oGPdO;fCK6AP1BzMow{BuP5?)~tej_pCcO_40rdtdVMu?#8P-h2Ip z0OHYE-UK?6ecjz}tR>mYKvP)Il6T+}gPu9o@kh1ke}Mg`p(ooId>=Ol0cLdmE$GBb zdHK$&&KaXY#DJo@;^Zb?8l)7`pWY$XCg1^OLI;l=DgY4-)IaF+(?1VJ@G#7GR3(Q@ zyua)XNw`GDf2hW(?k1DBa;)z-&JnH*%2YLskQvthU?cxJ1x%u1}v1C@fRYM5JjjO8L^xp;%j6td93fYv!Ns z3rD4@NJ#QBoIZ;P-{Sf$7xF_p?e98^zr?xr8W|w{UsYML;iM@Ir@zKp0DRcxE?s2r z;0|N6c#FLX!P0ZPAB`1G)zBL#J5iUBVPbQf(bAScxgU*4&8%*P8mPwD8nMSKljN zCaZ=f(DN4Xo1iq zJHFH4qg4Xs1gL9E{Fss^Cu5Xsn?_z^`hheJVQl1<7V@p^bYsFchp4k|_@vVE<@BJo zHS(6a^uD1DLI+$^N-ChUg!@%4A8&C}&pawm^;Dzdp6ctn_nJKi^m%$F!iE&tmXsBu zcIZ#%Q~%e4@sT1Z2cYuZ&{)9Bi3sGLtkdpTWbrLK>`EYQ8iRNP_c`&&R5NGq;aif-jUC-b|UfnP5BVI)D7uAEk{E(7e*J4H{X__2vLA zm15!4@;B&L?s4qPLQ^0uKWsiKdWH>E@A9QUx|Ja*i33LixPP|3yg2`56WQ~E43ba< ztHkJxU0Zv5%5B4v?4ZfcUUU7qyG<0DN(%qjzqmiRF=(=?kI>f|f|B)x-z8lhnr${y zIr)4uFi?Y4%3YnA6KPt8E z!@$rstS_Q%KkQVJv44!J^~JLb>~x1wBK5!x3+KRqwh_ThEC^j@XI&n#{)0I{Lo90g zW!q&wk?fn-#YK7>de+b!lz#VKUg z_WTsNuCBy1D6$8|gP^(%0;CP9kCy+GS)urD*{TKeS^&}KE9br>AHVm#MoC6OQM^dh H@cI7%+3xD3 literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopilot/images/wg05.png b/windows/deployment/windows-autopilot/images/wg05.png new file mode 100644 index 0000000000000000000000000000000000000000..eeb5a9beb872a64d5c7a4ed78240c14b752ba560 GIT binary patch literal 264215 zcmce-Ra6{d(>00(NpJ}6?(Xg~zyO20ySs&;!5s#78wL#lf+P^!-Q8V-2MEbOuYKqJ z*ID1ixj7fJW_7P#-Ss?OwY#eJu2>DABF0;iw{UQ97|Kd=AUHVGX*jqyxu^)RGe7d+}l?=S#;4u6C@q-_7tFnfJ`&*$b zC#~&odj9J0Szyg)E1KLe?P9qRi4kxRAyKsrxCyJ(rcK(sLi;P2q&*GZj1kZo2n-mM`@^SD#l+ItZio9(Z0?{>xknx4-Qcb}Ur>|-2x7%D&v+tYrt!Ed3-yR>J>cOX}jILrI_a4$)ecdiN{Rq$2P-uFBW~CoVyux}6%Us~tBy@FZ*)v%2=Mk~krdm6b2ii(P*QFe z#5q;83R`iGpoo~buFMV9&p>=8t_aRVG-jI&{ubY_f}4~@vav^_2MyC1KE8kxGfhdK z<2{!}lCQ8eWFbyOk3qaFF3E658ZsP8luf|*mW}wzEOEw({MX-$p%GBJzl4IBtWL-Z zMEw5tj8=yFglMDt+&lQgSF!b4ra0Mib%L{ro1fn8o9CQQXhn5NlUR$8_bI7hP})zMRb=4m+mB-#=}hdb~c^*N3+fc>L3PU3n4nu<-MmUbdO$jJGI&OkS^q7v40dWvTZ zcyW|o4`dXc+sRM&anHe?pb3)Us3zB7|8Vvr(YHc&_($j$76JavB~h8xUxkFkg&XxR zOlXLtnze~J`5}x-Ku*hDozR+Q(iTScp2K~lkIOGn-;kuvk>yA=k=c`%Z)GmNq!Dza zt~$jTf09nb`jN!ITEB$;?#H+K)6SfX(g{?vZwu_pgy(r)u9P#qQ0tCdeq|i4edB9T zf;1}fOw6@m9A~7&8okI$gkiAmYTvK~$|;~%emh$QNz`ahTJTh;tf%f_dQ~_#g|^35 z3k5sF&jfo7q~mn%Iv1&oc^mQ?D5%RET(@QNYJFDf$X|K%!!?#x02>h)bT3MeQj z38i)t8f}qUnx^@MmDZyhKI^q1QF8IQg#u!a?YS@du};QGiO$K7MAuY*<=$&hS&;F*m0q2Uf*Z>Ab@=z`C#*|{ zPo>4#pTDLVDrLy<-suUHNE9>z(rAj?xoy#9W=E*5Q-8@c$94)BWsb74vsZ_mu}0fd z)*swIaiaWh_cbp1+qh&q1`4RCkmq*~KES@{Yx!O0_lNc#00y`RV=F2e;SZuv)0Cx- zDC{qOh&oZ^OHCVBjeMTb7g~t@7c{tkDWCmudC>j2TcK6yJKc^ybVi)xrm;qsn=Oge4R!pP6g4L=*lA?*i4+pcgO&IgLc(@_C zmCkedj?eXb1wRmye7n3ly|x^W)*gLLgRG7?B}K%wyZ#M=jxPgdzXy^f?vDGC#h>~o z)&zYY-7eUD3C}hrh1nMsZSyjthl1k4WN4~9Q_{+lq+$l~+YKzK z^pcS|*gVZt!L#@o^2LqPT$NZ7>$N@9sLzu!VJn|Z)o+RR@B=xkx>ccrj2aRSmWGG2 zI_y1nG1UR%aua$2cI^#_hN;thX+b{*PH)AuGy!}nkvZBS`O*(a_PI9U9v>Z2101U} z+R9P+1eCtxQaVJ=R|;b^XALQY(|_{t@=fDy?+iMyic~P?|#5`Fz zIXyl%m;X7*#jh#^!^B5DMig+8h*@o;uy|E9fL~1*a&TgL-6XCADTr&BbmJ8G7O&<0 zjaRn7_taVI8o-&O6P|6s(@DpM;K)2_z;p+;qPt*#rVe8#UP?d|5|JJ5##_F@B}Qe6Mz+j#a6Se4SCCdn~Oeq zYYzZY+=rj;DZDJDURIir=C7J4&6m`hDW7jek?xHPf8dbd2XlnT6py~wNkUOR#t)l% zO%`QDs{Mj0O=3}hVAsCsK1*&9YU7aNu7$9G*DFv$-9-7-KI-UmJBH3CqRm=aw6@D_ zk~_#so1KgslbL||2SQmSHPQ-N9*86e(=33z+vmsH2|h3}XF?Ze_x-pN$-2t=fK6Qu zlOuN1aUCe40eKaU|Au9fT&3v3-S0i9y$GtO_T4@Mxd|DfK!s-358VS_IwV%ODQP3Yzio5dt)h2SCic*sX~b_|)J1EOA0Xr?#6^M`ToN%CBH zro2D;y5f-TZnS$1&8G`PNX(Qf%2?j(AjMj#%mHyRKfPX1m+QweA?rr~d364a&@dt+ z4|i;s&l^-R*il?}kk4;DXgLD>UzZ*!mj0el%rE_|mf2IoYY^c*YQpa|87#Fe^zY59 zOiB-0s%{-6xK>j?k0NRRERcx}wz>ezdGp0FF(P~~q6ywbjyB&m@!=~&{azQ8E)P{f zSKxFmt-Zby^>oxk5FQSNb9R1XZ;KsDJUc99rBp80B$v`p1w;N9(dmPRwZ zOmz+TP>uu2JLH=-r65Ji{5eB!Y{gHoKzlHZ?RG9H5z{E0M&HV7Emd3~`GN%SQnrqow9nbIk*lQa+WvF7cR$B@YGh>&~NW=`N zJlcMDlZtuzoH}nrC>bU!_-W{K>BH#;+pMVcib5TkDiM8+vhc$Okz@6CX%kac`5<8r zH_J+&Ba=CHNNO6ZD3}$a%w>xdJCmr87po)j922m3w(Xl$H6vK>m89RxV^|V&>NpM- z>Q^Xm)F#r)9q0$qXpAs~VuP)d7j#6fgzVlAitaYIiF7dC2^p;gvcrQg_2;J*r(rE}=p z5jZ{8dt=www1aKxxApBT@CzEMDBFM_dmMY`6n}b&SyZT+7l}P*a$+Pe_9h2m5VwM^ zm8Li-3B4yuA~}#;8ogErjd7lc(z<)bKBp8}?=&@>C61&YJ)pq-d9)wwls7Iwe)ZwV z!Y0o#VD6&8E%?I`=j-{M##7+8e}Z-O1zypwe#MZ79Tdud-;EI0jb-t+_SUwRAM1IZ zz&RR7Xr7u)9!rzw@Wd1!D5XEm;e9LskC7oIG?pF@sLW#^R~<{CxYIN+I>8qW186dD zk!YIoCLx`8zH2KI<$8Fzs{KO7U4%-ZIz5LvThD!aXB;R-zN-*sIE4u6!dllgZ&V_4 z3=*#&??Xx;zK#hym!#|sBsuUR*!~lnn)-H1&d9yBYi^b`ZudC~VLUe9BF(}aaf~ry zOmQ}|m2KiAp$o7R;KZL!t7sLkLJ<)W5u7(_JU^F?;F zM?M3EW=2lE?td%_w|_^Q@2E$xYJqBN9pyWw&gJd}b=1C5XN*=P%@Pa~zVPfOybC8G5eV1N+t4Z40~*-WTwuP&!GjL=UHejgF6AXr`X2iI}XSHh0O& zZ&U$NZrcQE_W8a72%q(K2Kkac>pwproPUbksQ;j3Ftd6w3n7hr#^0b0+P=qC$dke4k#Z7x2?< z6K`m|Fk=jqL3kEDog{wPD<61WEjE{dQ2haPkpHu0AJpK&Gok&(GXMUkw(T$yu8`=D z2spBg-4>d6V}_^w#HAR=TO9T2gxg5BxDx@p)X2dg^}#|JAJJnkT#bW@p!$y8=PeR9 zyTwHva<2RgSM;+*rM!Vg{&7~CD9Fx!x7(-OUHz~^( zXLY7@pTHvbkI?DY?0-X~_`kS!PnN@!u*=Iuix(hCq~i{IjfL6m>%ivfKs8gYi{`9EtO8dOV@gB_o5|vbK^bs%2!xawx|u$ z$Y#>(`#ji;bM>Sf;nsgx9TfoD;yGpF{d2Q~(^qlRJcCA-?DkUfRxopnYmD7^dwmvYwHYJ%Q-9#2zT;FvA0aZ8Q8ltf`G&;=ZLQJ`uMfi92S?^h< z_!`_hg55jJ8kS_W+&XUu{220C+~!qsyAwMnE^m^4FMj@vW;y9#x>nw`2@&ko)=#6%TQNUDB}8p3Y!20NbWo#wclYR_5V z0-d5dJaO;uDCuT!LD0%fFy1BP_WgDFjrwp$M;+GFL>~Q(u*8l3B;5hCWYy72!HYCB z?539TQc>~+D3n7euu%3Yydx)A&6qub7Iiv1)7(2^-;z#_5&mVC6EV%DckK0m#%Sph zSU3MBt80E3n+iCxsOl-_+~K5E9a{(}g*q+eGwp&LaC(WNwesE-01_3=Ilt2MQ!KMS zTMaQGpCku270rDr_3ccyNU9bPD;MD9B9h6EyxQ`dffYD`5yWZB7iv8@qMH7e|ay%2wUE9&yG z@iST)zq(d6R8PnSs4~)h^wWa*$}%jyeB={Gu1K5O>HZFfu3c}2_06pK`5aseBRoz%@|{Vs^Y`Fry~U<0H9r(+{#*hS{LpcRY3V^%CJ_TdWIs@H zNjM=F@Ed8gVmVQFu9B%-%=_}Vs~JM9FilaK1!#+La~@%1~#dfb4W#xOcS9Hg^C# zqon_N?rhw^GTck?&GYXc5`PzBycP18=vf-3{<0HE2gR7O?9g;I64yA(S2d1i(^^Vl zUtr`7XQAOHlxUbz_W$P^8M7nO93RvpQl*l?YL5;Y%WXM%nrSy2J0WDfSUy`rYo1Dm zq%v-heFF&52Bhe?OG=-FJw6X1@N{1Iy5zs33M{SCb ztjaNKK9ON@Z{IgN#xS=7g@WJg3OA`4Y~Edb6Ww~)pA?jAyCvL|{I9}SR8sQq$z$+O zS}d_;w}rLfo5jtGh=t3ZYC>W5FbBwqTAA@{=Zc#Yoh2{FN_?+hVl+pVw$p6=zkOG1~wVrYhKA)n~k z8=%(b5pfA~3XR0c*1t*#ywRcd#ikYFBkMC!)7G{llwtq5ZvY>6XvA1xJQO3DqQVxJ z4_JJlyFx#*EN(sc*-4#93{7eyT#32t zAFZzT7kij5yRsVm=^IbM!3(+}gRz*Z!jJ_6`W%rX@6VS@XYAE~_ufKY2O3%PS*G^$ z?ugPqwicGP8j@2|xDbr>^*w5%H*^;lzCLD&%Ns`OIURT;pvY=xU9C3J@V#r))vtXQoXD7KD1PYg4SA~r z%jfxsR^3-?e>5C^$HC>Osu(`t?(!*cHgn|HRgX+v<`(7jAQaQR8Ev4?I7)P<*-dDCSX8IKAsaN4Sxx4^ehI;|Ytq~r2g6|mIl(s7P2j{&}1 z1pdvWu!V*&O~t#yaRE&uWUkRyZbm#{ChNugmPPd)$O^#!%a*tCj*Wb_~uSUOfQLy1NTEFfYr&^>53x3C^#SClTahs+sCwJR8DP}0dCnBHf z$l!8i2A0T~7X1wy;GP#c)MTi9cDJILb7?EiEDb96DAlZKd_KFCe4uq-S;eXNw}EF7 zs9%4nNXG1`_65Y;V#MOUq8gj7%c3hG41zc_lo(Y0-_fc#rHrWI$RNF!p>9=ko@RYc zF$*Cul5bOkgDr1ZCw-YEsbr8lnTLBJniMa`weL*}eghuREX;q>8PEUK@kkW&G&peU z;n$>~_~+ZBkG6qTA39Ckme%fl7kqtv9}0^C{-Q|Sbjv1-U-wU#xHn}9Ug)kmwEr;9 zb5BF`0)mxK>D9odry>4My2@XSbr#-^J&^(>C{+QPHpE(<&5qHh6=Id;2n}_Q<7%7Xz;!DPescwvb&eAnosjw)Rq)t|U_Oms zmR-=myH=K0uOsu<=BqhYbYh0#iKjC)t4U>gk|wpfS~|QhU7O8fKUxHX`=ELn3pbTU zFN}O9Rcv~7E~{pR9E(S=N_13gL4=V*O{-U#tTx+J_LsvF>wV?pN!_peYcElQx?eaY zViFP(CUr@wkJ+#SS4?<^$vt(~-Q8suOI{9-Zd)B5O|mzT#6%_Gv`1X>7hZz!+^?7G z%gFSp>%IlqNrBg#{B(fONZsj2d_w$%JV%5y=7s&U`y@wtJly%a z0w&n#?VjV^W6gN(l&#zLpHY;ThffL|NWstoMD?AMq&_M|KwJO9LHvX8!V74Mlb%q- zf;}ZU&;}L68$Z|5h;cf*`iifu-`uwj7g-Rgjnx_FNnVAC-Bf;D<7vaD!Gi$LVkr~j zAnT|=f26M<3rgdSlN4f}ZxmU*i&7VY@A?+|=9Ubvl0b-n=BCpYm@gjIEpxxSd)GE?DJ{Vx-h zq-t;6Xc)V6SlDR}dJVz3F3N7He4`kAf|pc}2Y0-WD@>i7ia9KI!|vpL?2fA6Hs_d= zys)ShcS{*c1`TPd8g<8*%3{TpDEHy4j6aS|h9K)7{L;_(_AZcGt47b|jxbI>pbmar{tKmQi=cNG5sUEmqDx5UELps+EXO`%0>RazPUAp5%Fym>!&75q1v z^4Btqrg+|;V063KXzMJ}J9VjZ54Zc29-l)Mx`MSXJpILs1z%0k0I6p5JvjxNUcDpk zh;Uty1s)HSp(b>tAi^}W`BFPEO_Fk64`c^Kh%JwyLYSOTrw1X1nR0f&s;f+-=!3{; z6F88UaG{OJw;Xzy(7@$a{0?(Odz{PQ);O11PUFuIrRZE7WXD>O-KdS((xwiaVB<>S z&{<`;iGVRmoQjPaj+QKdXsop_DvuM=r0#-{U%5k^(!CMKgPKbDphuQ-fHKWOXk=P4 z&OUCtyfSuE zhd?vol0CyC>t2Tdf5!)#kl3!x@}swmziy6e350bBsy6|C z8q8IO`*fL#ewe30Ks67aPTv$_nc)7d$Sg~2USv@qBPN`y3 zs4ApZ)Bj8g++)2D&4Kjof}^XnktA7w^1#oNyz>juUM)Q{2aI|`r-WHL)x~`I9K)jm zI*m69kXP$1$P?I9s5icePPlxO@d;_G)Ot+i%ZZMfZC<4q-iEkwRus^u9u=hK_Yu*w zJdYL?H78C{5v-kKGaT6BDY$WsAsI=5q1gRi#k+{2MXTg7s>JHZAyO(G*)u*<6{XD5|zp zXfuMfK3?C6lL4CeXQ4^TLTSSUVS97mX9fA9*PSPyHI}Yx;UR&WB4e@*jy0Bj`UjGb zaJEX8s_TPs2gHLFW;=}&ukbf~Ww?lNCH9_7b@?+(3Y;IS^YPl|lo^`mvZ z{uZB6y7TQA?^Y2sDygcMcPx!F>aRTBQ>yLE-v8h~*iA$eQv0H>cb_yeu!R;i(CdwO z@Z50lX-S_9!=5#96~*R~3Y#R3n8g3ly;`Rso~lcrmnQK1B}+R<@Kxk;BGr4ArrTo- z_k@;FYDWA^6~^pqA}*p!E&rtcdm?rW>Vg^~3?3RlUVHiG11o9>>eRTAD&X1Qwv|=)=;!U)Z*%lfzRdYc+0xSu9woqtms>J2@edk+^mK|U? zbv3QU@uC)pUEc4E*Mf@&Jfj|w+mHBDsKr0SOgT)@P^%8{YI{QCgF}qBF>u>4N+fBw zov+q}O4!aoeBY5Y{qWvPF$(fh=yqKby!--Squyy8($|oC;DwF~FwbzQ%f)73OPd`9 z-1a9u#d&sYnH7p8d=DR=i?=_|lSge?m1KGI1IEp`NqoKjUy6$l`56`l*)0X5l@U1~uQ3)r=LtJ((Mq2p141$B}h_4zj?v z`p39AaP|G7IYP<=>&wLMt@NC>5eQ(g<`dMU>x2wC1ZyiZ5DKs-PqMCQm*WDDU%=jw zZ)12%01>Zqf0pGeZwHxNw%*q;C6kpCDZWl|A` z^=C1-I2#w3eiPGlWN8C3#|a=l4qk6qQVKQYZ~%N&mVosR)u&e&DxRVMh2Fq;szEtj z0CbKmy5Nl`=jg90LP?!QUoGXP;SR3$y#?|hK&PIrzbPjM=g0c!BD}lz8?-y^L;d!1P zOL&>j>SH4b^;?erH6PBYaN7(q({Qs!tqLh z-T6i>Fb@y?bReL4g&DGHyy?AowdnN;kEmhXD<9Eji9%>L(@p0&q#UTKyi}Vh>svy$0jJCZilI!*AQU3|J%-0Pn>6fo#=?CN@f?qd0yzNB@_FCKK*v19En;YM<7(N z3wdw`Hz^DUR1*gBvtIv1OEAXWHhOkzR-fY{|L=G_b}?y4h3lM^%P=1^&6@#v2LI{P z`q%XX_fJLHa58l-@0tbAi44@%`Qzzv^Xy?Sx>L>GoQ!>kh={s{gvm$o&!KpXDto@1 zbl_zqt!aAm;z~?Q3i~CxVxB!No>Y|$gV%})?^@h{!gZ~~lomd)B9^Hqvr{0;3s~ACLYU=#Gz%U9LVns{i;KLHTD{7EAnL-%5QW@aFI` zaqXq`fuQvP(|E@_C}hXzeq1caoo6Hxor%YZdrDh=T*PA+1kpLrWC?4|CFH7$Zat;% zwEn7GK_^T>!$jZxJB8A{lp4GU8kj)ut;4a;S=;|(2{tTGal%>|RU(#7OhZN6HTpIC z*7Niz|6^HDLKGmFxPDN(+{)h~3Lcm2zE3Oe{uk8wv;?>6iKg}8YYEF#HN#NhS4U!Z zrz!DG((mlEd?XC;EOixt#0Nu}q!%;6y>M^j6}X#bJ4#9z+H`y@N zv+gZBMujgLSOc`Kpl5C{VpX6OE6_xeFTmH`-_B3-q=H!(Rs?Uj4VJMu zl;?GR9&y%URdHkIDURux5a-pow-iUXY`9#nt^ksnL6^!qb_Dak^u~T9Fay;(&tTfkk7>^v^-Hu%xu)1r#t8sM(j|kEo=`iaxzZZDG9OQp^&w+RX`pJs91vG9 zneDiM6=}HIfUdQz5hT3_(Ol|?S`xgXMgM`d8*=8xYcS;$bT)UPpKat~P@X z=^B0&jxNtbA<=F#U`Cra7O-^_9)hX(&QivYNXe_ku*jFS0nqB)ZveERK=Ms_Q%8Uh zGqlm|V2zkM=F&0asB?r{;VZ^ps5Q<}wgW8hhG|)%iQ05m6aQ*cRL=nyK30H3(Ws^1 z=r?V_sOuMclMY^n%uII)jSn7?{x*kq_9Fp0Lv6`}&Y=}hY7wPyCyNnl6rN_)>2^UK*M-R`h z6^krI6n6*jKZky8yBf@T@@jZs&&G6E>5Q}A)!=rg=h%Hvh~&sY%4=^wXs?^txqvGZ zGW}R#UoHQ({Q=u~a94LIMNSF(g==*gej?>B!;z#HchcOGq#xCwKt}a^B_j2rB|)(^ z!rr@k?>_G2tjsdn|9KY(od63QL?xKE1Fb3tzy~Lz$8K2ThKj3EGq3j#E0V~k*@jHE zjvMAf$Hf1!*}k>^j}1X=mTdd0vSf|;ts+r$GU5CF1B00MQR718jJnW9p$^vjjaf!# zvbqk{6yI@6vWtZLYN9obYET|#q<*|XCr=K`Cxkr78{ej^&d) zIu%S)Lsx9eG6RQd(qdoNMXe-N2QmYfH5Lo`N;Q%B1(*E*A#yy@X?U$HHeZ;73tpt8=)lxu2*gippnF>{6g zHr#slJ*j9h@$8Q?C_udyWaZ(lw@BA?H;1I!3HY#QzhD#IY(+3vMED2W>Qq0bCHoB% zcw3mlvR`FP$n+oR>+TQ$3(pQWla)%Crn)QG?Wm>Ix9dK(;KyB)Xvj{m=--7kNc8AG zT9B|#q@IhSqM}>S(6`OoO{@>Utgv88L%d`$kG@ElSOU}a^787Q^*-e(K?@fc{uDXK zyi+EAhayCw&4PL<+jswaP;8#Vlc$Cbp6Hx2Q*~V772kc5YebU)ipZ3E9&58*mn2#w zA0xkS&vlsoU5g4n1YpDfA?WX0fITtad2b%ymQAk3^c3sGqc%0&GAkTt` z(7Z^)o8WoJyYLy0$Sy1H2ZA$1Aith1N~{zs*_=$sLM$-_Ab0H-JPdK=YB4oI`CHX~ z{<_MQ3${PDAbLgKh6SMq)W4lW+M%4n?O#uhfvN8wj$UedH-8gDHh@C#KX&HJO|zD+ z<|6VpO@S)8p=c1{Ms1}+Sl!+%&}*r4;pTc-pgkVgXln7p3&c6cgK-v ze{e$nT$AoOpA1bY@fTPN)fXLSh-Vj`WL1WwSL_%cNB=UX<1+`3HdZlw@0d-QBju_r zpaQ#yobxLiCoefYONG$c5+=AWkFbXql@^iK719Pqo1Efj8-YYHQ#v@jJXo#(F>o>n zahGoiC3p#`&>+MMxt^r?N7@s`N==y7aY`JqjK0st&$}nPW`z2zSq@QlRwU=hfv-ePr&>_RZXt$Q?%IzUV~#RCGZlo@~`< z5Wp}V{IZ}DjXl)VvM%OOWh%rr2wawkrx_z(Q_D}%BK*Y&zUNp-W~-6t1s|ho&=9<+ zfYzhhuV1mw(%HLL5ig5Wi-0`y#sTKwvI#k#8<(W4Ga}{hmd%R(?r5V0(7?SQDOGCC9)ikOzcFaDWhX69r`0U^Ca23+9+gbD3|n& zO2d$pzQ2GxQD?MnmQ~EO<9DTK%x{m2{=N}p_h;#u*l02v^yZu+x^x?C#CQc#E63t* z@{U8H(&#eh>W)LDx$f1GVmP6}5p?01r%ve6n@PFo8Q;={VmWcWnghbHxG&$LDh%N~ zCk-q^?4|e@!_Ok;^zgrC3Qm~0jo!c@&d)UD^KHilOwh9av^eC~bz&tN@~2ZYNZe!Z;rsB(_QRju!;9C5KY??XJvYTo zYWJ3%I>C(&+(-E=C0`_JThzcz9ZoA+(?VYti#G4jU|SFr9sxe+m3TnCU{K zn1pcN7qub6y+eEd@7lKd+nSSQhS5gm8b!I3akSDT2HnDfv&IIc4cYU$tI8VZQ$jOE zXec#SUO)gI5FB`NK6ZM%-g-)2JEMIA-Gu0!6$J*&c{cUKeW}LBbf=!V4BsVhQXAeF zunh^ebMv`;x%ACyA#s=#(4lek(+Q{~4T9y5eqPU^c-C{s1vz z)G~$YIUxS2-2J`tdp~@jeJLf+cl$S0B-ZsAGrv4gc-0BS91gHB*-xKV%_$7nNc*f? zVQT~;qpVj~PdY34lkbbGbKW1S{N`JvSnX>&YB;`tw$w_dZREJHf%VW?ugI0BiPIsh z(=kV(B~T%&`$vIZbBLxpR8swDW1tHpL>SrS9@R(c?nhJd&~TD zR$mw)vCG#d12=GtXpM5H^48C|v;-W4b9R3OKn%^i{=P% z2PP1x!N6EP8#$NZOOh$LP+Go{%|Pe*0p=Dnp-L7}P+U>caadY>Xa_cOToEckJUTjR zIfugBgN{(3pkS%yR-1=K+#ej^`6-<%8i^~9?I<1N1YUkcu{MDj#J|DTM)f$N%lO_- zMKtp!?o4t3Ets_9Y)eAx9cpQ_&&*QDpR@a-&`pAPT4Cw|T~)*V`mnpqojSVDdJBuj zq|7DNd2K&iqKyLMf72YAZup$3r(QmFzvFeHpSL7PKrWN`9H-#`1d@^KRO&XEpBv>; z1nYpjSK@79J`fme(Q1S*dRS8MHwn2|g&x(BKz#!~hr{r0J%j zb@rfBqJ1YMuI^O^Kf4G&z|G(uvd05+mK#k#6-k~JtwL}dHa~%td1~RbAgb*mplX1P z2ty&*{C&x6e!h@MwQ8Md&vGlD_;Yo6cIv!Di^B5kkSCo|;+x;kRBvm#_NA>IxhIto zM0O(ODCi%`(spk{VyKfFVH}`ph2?exNsadZwUy_N8KIUPxrTIF(sYdWCr1>9^s$5_ zT)uF@BDO9GGfq$s=hA*>HUxB@UIIl>i|nKOR$xpC$l)w>_aE%g+ee^~O+fn9T+oD; z=+-lg77F%0ntC0d40+o7Z`@sQytk6PPV#%550bo_Nf!S(T?VW2`|$)_CI8IVL0m63 z*EdkUp{Ohgw9lWI`=C0W%r-DlvM6)U!A{K)lWCv>1oSDlgKuq)*InHT_0g9$mV&>n{8k)1{u{}ZDa;nTvRO`}@B73G3)9$%TOm)eiQCiW75nU^O*p)q z3iukd=RMb6=6;FlacTdaCot&XH?F12;TK$KO=wOgV14ebyfn9k3w=up(AF{!gRF$gGY|D<(9zRPTWd$CTjvKety}=Qz&Ok z1vg|@Fuzi4E*~b+v9E{e1KA%>4%7vo@T-sKZ!-WNf?SHbnPVPd#NWJEF5c_;?74- zIMip@#E;= zLM4Q2r6D>?_d>yZEMro@xHKBUB%Ac4HbG)>7;EcL-W91GTq~#2y7HaV8^Gz5YP^*~ zuv3;u($?j9pLVhP~JQX6Pf9jWfQ4pzF# zrUO92lIyxaq9WHS7VP?rrbLdf2hj!gm;oO@7TTwX`dwzs$yMfqDh`gu(@DQ7X{o_l zB0TEvziEK&ju=wJMDpewpjtL*zr0$#fT3%ue`6rp>Bil{0bFo=yiAQbY~l?vfKMNPJtIZB~nOHabr zP?K1{bWDAcb{%eAEF6*;*Lt=gq1&>Qldosw!ULBI7cD%GPBi)Ebyp3Yb73oO=mzHk(rFflb{ zkjqy#u%4lzHsX?Ay=iGh3--U4hMFgvRUnjB={zX?pE%)233LqZ(*7!8C$I`UZds!um<&l>$ zC7g*GVe&O0j|M3gnR)u`P1}wGl=zFx!JA+|yNFu;j0ch-lTtm#rKWAwz-!dpa}3au z7m~Zkm=ZznF?j>%{LtsH)vU#s&vMkfN~V2y=b|L2R1%=*jNW*t%3+`(IV$?g+UAh*8bA%f2fbzQ{=@er2o}(tJ`n%rXBa z_wPOG{6XzQhNMo-iU6JWo2oJIH{XU^y4el$ER*3!0jFH6%m|iqm?6z~ztm!Bo?v9L zCr0G5s0})mv5Zxv%Fd;!&rna*h?DN;Fu4Xd%0|+!3POR zcsjPMxZj^KIBo@DR}wfyivMYmUjNyE?OmnCKkP}Rv6RS_i98CxYWXfdI$s25(_gN zv=(RoI}P&$uTFKWdH;EfT2lGf%2eZeeBiH3&2*WQ7q%|_eYzdGopXeIYWtt}`d%Q7 z^CFpzl2eazJIx$5nB=GBXOQvVv#5a;yxFC{xh$cccXU^nRm7dmt;>Qj%raX^@v=-` z(=1yyFD%Wb-mE&$c3+gVoRpJcn~_@Jh(A~{r35vTj}^@4`S5jjjojx(dHCi$T7FTF z=R^Ml{l-&nSpIX8vdkjFpUK+6qzpLLjqOSFgqX| zmf>Q~>HmK)D}k|&<6+wHz5{jFi56DAe?))N3q^>HFs&fjE*!m=`45jj^cn8Iqyyx9 zWzq_A4qn$fvGYQFgnUNt>&;Rh{X#)S^%T@eiG^N?1iof4bM_qZ$z_xV8 zLT``5?4PYn;hl`flZmmsuK&Z_TSdk7wAMP2-XP!KHDx zMuS_Rao1qM-932lZ{@$=z0bSPKIdG27u+xggIcSrs;lNR=kM|L+^y#Wq`AKZb3Q+> z-SJlMU6odgf8TI*S^O?5#GayW9)P3fpY^|mb7XSghY5N|(a)|ogT#&5KkDB&oU(^7 zXLRIY(;PZ~(V*3o6qJpp(U7AzVJfT3(on`5E@^d@` zgH3mos`o2To?7YTb=E1>74-T#8T&r|g?^J^R8RR_9MDCy&gz<5rQrN0($X8N6NHe# zoKF-52BrIHzXi(7k|+KomXd>Jf=lJOMi)~cSy$Aoqlq+gdM>cXdeJ@j((0sFWhQFJvP zP?92tj!8I$aay@>pr>KbR@4tT2byc+x4ji0ilEETeq5%*0Syq6&_$|Ud!_>>qL0hJ zxj-@p%(7+q7mt3`St!s)t@dyS_aDN7$oFMaTK*k_y;9zf3b3cIQ-mo-<&EEU4vyIl z5fmHoq4NC4GsBl4M^=zBzZR#pU$)V1>WF}0xl>JpJj~wF-yNEu1o3!1_!?TW58_vz zFA`X<;}_0efzH~dqbEgTi|l$1z07@AVQ=%!En+6lx_5|?H=3Z&=s|;lbNj`C?0~fg z3dAOe1oXLRY81((>vsS2cbG=0jc?E?7x+~%uVC-Tw*i05#nOg_jWirejLY$@$E**| z2IXl-(-7p3Rl2p5hZse#FIJ+B(7XyW6KCLcDCMsTYj_ksjv=L(VtK6U38lOR4MaHa zESt%BbsFlbM0Tmb zQNAZG#mmuNvV01JpauWB%YU!rJj6qAd>S-mL+{1dLQ1o?uxRNH}$d=4uA8iz4CZ2(QMVK^$EYEwt8GXp94)CGz5Si?gl8d z0>LD%!vt7phzM!XsYJFD2w^zE)6pEX_Jb>GEI+wrPIL1=l?Tm|dNdH)N)g=7#Y7J^ z$uh1rhsO}ni#c)p%A-f;RV&gV8c-`D)|cbMR#4QR{uG)2ckUj^b0>dpWmqUvvneOx zQKR~zrNAQb75#hSD=)p=;z}(rV?I_jTzC;}Z`*^)9YdUcTz+*Js`}evS;Azj3GsIX zp0ZK(dvNB$B>Eh*`>j7;?2(P?zMNG|ujZw(#3CStILD}WxMIqV0%t~Ab=|@qZ1cS} zh429A+i!Pzg~^;mSj4ebdg`sB&+BIPa${8Q1erF;3Ild2qSM$9Z~c8SfnN_O3WR~) zA-0m6PUmCqlIhp)rG~cdg%SiXZ4vz2qx5~yNTiOzm+|INh=SzPDHQDCcz^p!n`7M+ z{XhR<`5=?O=okV4Xf;-?;ggLfVZrOxfRHKMmFN9rQhnuzhW=QmAG#}Uy2I%w;Ov#C zyMU>G(l0;)2D%EIBTur)n2i6ih{Fu)Nl8c^2GaeH=vS|@Zv1{rk^8N6#)v%Z<*Tgt zlmi0h%ILDMhH{7J;Vl|q3xu%mXW-lrm`{T4krlUVjN2?H3%OLL&Wqy8g)V3q$UMfv zp9^d_=#v0X^*9c5rkUO$85k0fPSv4Q(_ZXfz}A?=WIK^Bp%?kY8JQy@%?@!gVZQ9o zdLf$wmK%9U zBK5hJ?_pES$_^lXt_7HSp-t(yDt4Aq>^5OJP z7ad@J=wvpYEK5`6Jl@2_sZv)i%4Abl4o%nF;-=5=DO^d6|By{~*>VLgnHp^BDtYJM zJs5&BXPg-^CXku-w~p=L-(6yqKU+C1wX!5u;>bTEbn}jZrg}^9qKacMq(EClp%f_6 zEIBkQW+dS{9_RM}k>p!#5ggD=HHhDRXWx8Y0J>0bv;xG4X9hdt&q^8(luL@nggF2a zQ#;b!GUXR=c+A(Eo3@6I%?8}Pbou4{v^HY>i$sM6pGY<4o1(F;Y`jx^7}!IsTlQ8? zQY!Xyn{gCR^scZf5EhFpbB)5GyJqcV%*+oPMRf(WX^rFlB(S7ONevX==>-pXNPj4y zTYJ@XD)&G@0`Hj;AHUn9$AlPNG0aWZX?-cdo_tm7%rrRk3w%#qZMDGp`0hAj&1%~ z!{qy`aE+U~Fy@SMBKhq?3aG*Fd-`GDD)b$i`>l1Bydtk<{slY1%2w%{`B&}zSJ~Hx z;RFHWv(FxmCLd0GpOS?v;p=OCfh#oI3pbSseznP^S3)lit~opzhit68NHBFHNwA31 z#zba?7*(ZIT*Tfoc(XfIW(Mu$MS*!vUdHFC8y8$tPw1$Yck|tJGQDcEG5vH5yJX65 zG@}rDSzb7#XBdl@-;PRcg)#Aeo5h`LOmTfm5z*o{asNuq6{?8k$2cbPOA3eCG?d1A zbo{}K!YLF60&}_ZF3m?)96-`?lF&X+dPj5Oy~V<$5x)I&S*MP?S_!-QecT>117I8f z&-fm7HO7C$^4t*BBmPO#LWmeD$Njl^GgTLgb%HDZ*E2luxjgl&!+2+r)#T5BTJ-bN z@n?`cltf8wIx-

    %pKxhY-d^@=mm;3fKYM|9u0%TAhp3YM`3dwHU#Q%!;Rw8zcbM z=f9qeeVy{XJeSSitgS2P!+N6LD-KFIArqg7-}tdkchA0r4Ha~Li)PI0Zgm%#u3aTH z%8#NVVr!Sle&pD*u4|8&Oq90i7wecr342aJ(Bn}A_xqmLB_1ek?9Fp@A`LHCgG)V3LO zhrtc)E_tg415)_ac>1lK)RaZJ^7w+LJreb{70qVCDdERG)gTG(4HF~pkfq9K=f<`H z$D(@C7jvC>(r`O0iRkI6g#(wBYXG6Z4mOCPe9d$40rivqoe zT<3A?(JtZ0FPaX0Kkhuq(IhvNJmsU*ZysCmsr+LXGN0b2XmL!bM%b*~4b3Rl)!|V! zGW8u$N+Nu89pH%8@VA{Huw;RUsk?jCeehgBQDQbp6M{#Fm*S4bzNkVqdxf3OD_YvW zcYKJI*sq(F=jtFn!Qb^3^kHU8kp8E!`vwC}hN&;ix?1$ZO@D?GKdTMg)SzjU;&w(6 z-#!rUk5}pD%SgJ?f-)|ecMWPudk^15YOp&Bu2!lDX5OPgfzvQF&Y)X!INd`B2+3Z^ zL-Rx@>bQ^Hl5UQcmlo{+6_PdaQ64I?ahe^u>Qt&C@7|Ahs25|=Wv#bfCk*^~u5n4D zm_KZ=PJ`9`K+Cl3tyrq)QvJd%jV=(9;dlP1S7DOD2C?Fph3BJvC-3KyA*V~Ov+&VX z-EmIi!}v`Jl_@m3!`iyIA~F8IM5U!Wy%CytCwPb}7139z()~J(moJRD8%%LR4Ox^u z$!NAs7fM{&>tjy5b0)dfZ>rNi$XG3s!99>EcU@b&HVKbJocUJQl0= z@P!5GZ3J+yWN<)V1X+%k(tQ@(4w1%o5MyLj}uU^5RBzHTI zFKPM`D6913R4J5sMVQiXjFr^ zqWg-H-fJEEpxyk)JoINiWJ#-h1`1+pCl%)3mSiL;52cF_#qe)8I^7b|9HYg#x+e`9 zb=y3|8LM>y?-(daOTP`Unjw^C-@g1hW}@1=q;A{vbu2&e=X$laECfJsEf|!LlW&$r z;&Su#MM}sC64Hob8;9}!H=-7>Nc7&s>Ay9*!pse<64)Zx?H%#o@#xgX$yXO4k!Suv z%mlXM2L0x@!4VPetsd_q%q;|mf7*{(Qe~QA&>9f;O^mGzTjJ!+0pGsbM1V1v;@}fc zA{B1kJ;eN<O%&r_0X~L7N98%I$mG+PlrIgd@%tzzP?#q zj7)l$ATH>(FCOK=AW~w0UjS<}WOpc(;Qt|EW^8JXkFEw}5prT={(us48g($mR_QB8 zDqJ~jC48Ov&}N9<+dd!orau#wi(QQ~_?@TvTRS5v zl#)ICsdU)ytbB~{N81Yd0pd68+71EACS2>&K<#At0S?-JS)JMb`zcfGF+s@qnHngb zB)i{t)sAO9Pwt9>FZYGoFK;a?H9&x2=Q{oK;^N|cE_w5_z1Z#dZ15_wm`T_E1U;GG z(O`d8>pt_9!!c>fU$vjj*6~hmks0-6#gV^K(~nZBvh6ju#rmnq;nZ2 z7GT9=iEBHzS;nML83eUGzB?=k&HQ!vnQq7r^B0Cb+9c6P6_!)P(iO+RvLRbue~||i zErZqyrN85q){MsMPZ>&>5boTgufH?bggKK+zLfQJfJ#Yr^NC*A(h{smLKMP(k`}7p zv$|9=nbEnpZ-)7nHy%`AsQ8qv4DMw3dNz^Z$aYi0YtQ_-ti#YfykuUY3dotz*=(}H ztc(T1DrfLOqA2E-V)8p7Az=Z&Me`kNcdrA>40LUX4}94WlNJ!e37h|5k^U}QC zj+bdOLUzMwH z)hqvlW#|K(KBp!oK7A0YNC1njt~$XRxbbUVU2Jl1LI+k&9uZz(kHvuXmaJd+9pDB} zjTX_kp8C}|w#j}!FJI}>c@v|#fRYPWr5yyv#`bC9GUBSwPJ=dkPi8muXxwnCSVNUm z7)`lFgq|{1*0n)i)-%=PPd;)Ne-50L(#(rjYw-m|i*=o)Us8W5UkI(xPEY<%#dHh>`G8`HNeGBw$D>;bs z#)?+P+%qOX!}*Q=J+|tXo|pXk@1iS!t0Rv#iWf`VdyV`Eql2i*K7BELFeL2l!vFs53m>;kh;cwYbtZ8%3f zKS#8vL@c8NB}b$9TWow2`Y1EzuaoLgTJU6w1ryVIdCA~S+kbb7_ZfPP0bcm;*a$ar z+jGol0rl9ZeZkCFKk}96>j?*8rID!v9ta=^+b^3Kqyho^04<_7wv-L=OyA6WD0JY_ zHr!JY^@+YA5{3@2aST`;74XJ;!C^=z9>iS_f$}&^B;`#bX+V+rDwyWq^yNla|Gus{ z`Txy8zE`;NhloH{kss;3oPFYg)h7rq5?@U(>p#!C)p#u7R2nb4W6xsBBzfX$YOW38~jqUFo!-yNNuaj-t*Xz8i45l^W zr2w1YcEU~w4qujht>Du9{O9AtHbYS}`v&XLkfK_J-yAcD7~EXzbt(8rq$7^0!OYAp zQ{jYvQ}7OX^0;b|++4WCXwzjOFOJPh@D&PTLQSb7*VxEa`-;2=RHrvfvtFBU#msS6 zs)x^;PqhfR)GC99!@|{3oI+Gm=v+5@9MXdL#eO4I_UX4thx;M2y-`|8QO7lg z{}SK>I1u$m3|0e(08oh;4uC#ziQ1m%d4bM$$XdiJ3{Fgw|2e&d;=7v>D=#D=INSJ$85j(j;B}pb6f$b2l({#P%N6lQZuEE}Of^heCdG zCF&BxwU2rxZs_}`0$K;JmeTx>=L5sGCb~E zl-rb4)XAL$=a!Z#?Qkk$R-Gh+K%!T}FLp8bS!bbi8F=*rB}OHUy63hF=3j7v8(7fV zbBrc6&oP@%{;D<5F-*IroD_s&nr@b6GH1UOkK#HFv9?{75@S1N%D1puOelT5dOAezp`$rKCyLco_m#B0zUfK+x_6@M{*9l_fJPEq@rFP@~ls9IrE~ zh&?|lr#5LAl-SFP{+t#;)v8Z%kQh*+_?cLIFM@a8+LhIS6_$2}6F6HK$>rbn0z41o zzcOs8{dXx2e`vzWmg4^+A~tO6+*lq9bht_?`NBakt<_gAiiP_k-^jcysm=|PI(68u z4hZ~=T=q8FHIeLFoy^v4Ku*R&VU#3k_mhgFZ;qg{Y?HuXLAhY`C&@-^Vu*`<1Bv3) zKCK>WIvWUPP3+_cwy9`S02!j%jH+25Sb!~|#JN$QEW(v(i%Z`Zme6fw3V8|+a?f)! z&1mjte$!#hk%Xo(HBYloam@fK!ZTdqmmB>nB~r>xP2t{hRYM_I+3QQJj7h}|nk5Lo z$iW$v*|>dP41d3J?f#Z^6hIM9nYE1g>y8%%qU0mrep|Nl)dbNyWsi*D7TqhlqE+Gk zj-EHFz~K9oneCe|O9Yj4SJ~6LGjrUHCak>_jU+(%`99uCF3~XK1iGRG3#F3yAzNwl z&a&{jV_`0sA%A`&I`^bR2A-;4otBqrd%;eiPZ9ebtLd@>^pQFW@1NyGW5RMJ8UCP< z{XDW2Ma}H8pusK3VWWj}p4jBc z!rQ_r(^DuM2i8|3tG%!7B_&_hh(Nq%{i*bCgpM;^X(Co$qGBBs`3~KKFW7@s6#tji z=hZM!QKJ}N?Jb8fq>UBLjy<>QB{Ao04-YIl=aGCRrK|Nm>7qp^309dKxlQSOZL=!@ zMX7&7cy#EAPoadVdz;uFNhD6#Irq!nO#csthcI3ofg*f_2dA)>+Cu1FHwtiAPgikr z*(jGfDM!eAUji4~18g3f6q)HouWQ~PB?aC|dsMe#@ z-(>X7MXN7ZF;0D^WIdlAygi?$RgNCc{P{&R z{Zbo@Zy#zgNPO>Nmi^CV+q`dMvhKb#F5hj%tln+0`|hNc+=1^m@Uy`OB|5MJEg@JZ z{jt^}0)}wF=&axIEC_I=k}Z1r-*|GVI{Iu9L(d)e?W=WtHu?NE*`GGpLEF1a@45++ zOCItXmY0{w|E!bWRyVd^h=^T00T%tgk& z1^%o441;w<^gquN9P!pYd6VyCovM!j{n_Y3k7X@~O9f&ixR<=2>U6N1(65hZMO}i3 z(J1bakU5n8NiuxvM7KT@GGRzNsmj!d`aUYB_&x2UX%ZhHTH*B(=W>;| zq;jr((=eyslG~X~-y3{7FKMYyd~j0s3Y9ySOQna5bC;qp%z!{HnXtZxN=VWZr~#(#UHp`=w;2Ixp>vKV6PMM1Ab0Ht@-!+rd#V5Z{G{d4hAW5%il9e2m`uBR5jhzdE@HrJ{lJ49ZW}LFj-G$J0Bz;UA?9UqNGO0-0M4{SSJ*tT$Jne11O^#b}<_( zC@y2d_8lkZbw)+IHqcfTN4ihx9Zwr`jR!MSP} zs|q_aAWM_&O4Fk7a|u}T>)a!oU>V8d|4gMPUrqnWq%6{NYQf$#9&_azt%7AeK`R@3 z(D~3rzJc)A^n!aXfK5AoKhdaM$FgpEklsAE<>Ty^-Vd*}Dr~*Zzr-FLIn$jk+OBH~RV2a3tK@o7)5{@lgQILnfNW;t zilRk5Th3-+^Mlxf@e%8?=gBUYjrt+C_bS%|j~*=PGr%ob&kUhd;Iw9<`a&cjMa;&I zxa|TC`QY41;rh|EKu|)1*rCs*d~_+Lbe<~b$5;w49Of~zf==qP+NnSh66j)pfq7<1 zfd2T3r&|L_FN-AIsZ?p=0gYaVNBN`BdI2!W>NMaN2z7X{_Q!5BhlrX7N*aM})QY-Q7LrdpF4&Ya0sqb;Sc;pCXf|r!P(w-Kb7nK}$zIMDr)FZZzYR$?Zp1Rx)J4AjRq z|C6$`A(Qc3Em0Z+OJfy93h%SRqnv(f5D6RO&iF33Gl--?J+FCueRhyyC7zK++Ig# z^rHf_UQ{n;c|VkiU^^j6=ao~7#ss9XIyh0wA{eQ6p|tL0;27EIYqcLcYjy3nU5y!y=0-1Y&8%G>PuTMfs>TQf0kVEYwlQ1LxUy^hBmyV60ir#pE>;9~$`Uz1WPe*JQr?|rD> zmh7tD>9qIhJ>X`=5c|E>PX@l6pl4dY{G-9=xU|v&YcFOOI3@++`E4qWp8g*g3!e-$ z3gf_q(L|6kcZ)23n@aEH#``~&waO5Ay)ow05&8;@n0O!cqSq-NdMTJ`u3|2x?*T5c z%Z4v;f=R9Mhw3-~!Yp%PyujQ39yh5wjLSoCCHF&3C2of#eo~XfbJZg?UY9^o^&pQu zelW}%xhZ+G>!E-ye*~#1t}&3LBmzgsF5?#BJPLu{DmYxHBC2Y}BvMNaMKHvI=N9%8 z9E#0WcqZzWhc6Vx$zzFZ|BZgk0xp}56scB-GSDSf3>&KUNOxNZr*ui=Ou=6B>g#~3 z^O`Th7&SjKn95@-p^Bc&SJlEDCZMfQ$?@_Use9W+*$q2a3Z>t@x+*d{Hvd}ki}&iB z&J`pN6xsHEr9a*cXwYT=gsifuJElq0)ep%b8tqz+wT>xH)P3pxjD*3tqC?Td|8U%X6LBp zIFs+4`L--%$`6`0!V4U_gNFoi%Yh1C%N0R!H<36XS)crc@sjdXlKh9VNdF^YVDgrnDZlf&J#L^>J}n(1FUa8&*1NR=(m{>jvME+5IeqVFhfub5WC z(7$ZkM&U6jD*9K}@B31{KWJ%KF?3{-C0crIy{;h z>$&3Z&Cv)T>uuIR1@-5Y?~H@hTGWv($u+h73O<( z;EwO_GrD8)VkDN=Fc7$Py^m%I{SH5~DT<1D1rWX0&4u!(ZBt@h%;WqJvMlolDYp_y zY<_Nz$;`Z_FTeG_i0HwNJv2DYti+@hqlECQ z2PmHuF4Yv=uy8qk&QVd6SL_i#LWpvz736bvYRPHQZ*;bM`h!Mf8H*|JeB9aJZy~U2Mm0$`A$G z0@UdK@=5OI{vmTl0UlRZz~gHC^kkKTyZh$^L2#S%|3hUZ6E#fz;oT5vF~nF z<>#pl+3dS5@8s;enCH+L|I5bfmCKHQBo3B{jFXnrwjs{Z&vXsuSrp@$W1pjsXDa=! z%8af`OMcflc>MXi)BPO>kh-^7tqXR?1VmJ7cWak_xF34^{|;R}Z)j}aTo!wL!tlKe zCV$jzS3fNQPQUPco;RIQi{6cb>of-I=HUJB!Wx#+Bdn=TV0-$E7YZie!6o$?g^mmj zZWpJH=feuH2HhYFdH^(K8dPY%qoi^+wo0*%dCVxuP%8b6plq6;N6q0liR5ZYi25)U z>y8ZV2Vy7%9MW<%<9*?vscT#!(X39wL_3`ls+^q<9O7Me{xWqrQ8dO2ciA#r3v-9bpYHg<1jpTh z%5L2v`zrB;lFc`Y2|g?*U=OgLhys9b%hlj)Bg-sg-cOrNSD6Ml71mn0_)3;8D2g@f5DWb}{|e=$4OUcPOIk z2cG(=p?7fuDuUkTc&3Wcci@~A5=qCk8TvFwUBv0E5o0^fMd@mFUAn4HBhWOuFcw>n+*kPd6-a5Iw88;vvEds@(-9+}ugU7Y@9fLb zvM7Unt!bd=!W*;J|J)^pOl;}|gX`$AFXVHQIMzj7zatfqPhY;%)W%NdvEa{bj&@fF zsZ!{^{;e_!7qN^ykZ2j7c!YxrAr`gs^{BIi29>5FJ-GcG7>2saWg*FpP8Wo2xe1Di z&~nQZ&{Lkf8SxYr$?ZlBl|yzi0wUsz3gsV;=Y3!N2t^oVkbTS)sxJ*E0073**;PH0gEBwvpS?^FqGD9}2!M_|C*2{m?B`M}Sb4kn*_1vgIm~PZt!Ah(`^D5G_aHZ5{?&L3&yL>)pKH zNsm1`v#9lvgS2Y# z$KNhG18+e5j|=U8W<5nO#v6YRT0U*VO8=H6zcHaUT(Y?=*lY*{a2V+i?e^XCK64q( zTRA_L_+O{p_=AU!INRW{LH$6eOQinduQ@{z;HJ&ey`*31YK=;`n?VneI6MG zVzz(xc@Q*hkGnyd@^ArP4?WoWz^=#lijk-3pQ zRS8U3t8CZkuzdGKeizsHFsIV`Xn1;?3aB8!{y!fha=9lJBmA_tsUq?;9YycB;u1Gi z0Sk_ALB1cpdNQr|uQDhv+E!j7rA59NzEom&2De|=SL(ax$rLiuify`ixnh<#Cq)i5dGCc>$wH0S_J z1jF6%#h9iH@NY;&?qM`V4XQC|kgkx(?24(zb zAS$CsyAqJ{^0eEdJP`V0Z}{yc(dzRh%tc^>LFEz7#hkoP&!y*8MfeoZ=4+Dt zE)PkB10C+JF$PRG|2-f!it zs!~xjle33Bz?7!wiQ|lm*cPEB*%IWTJ9sHx=Ce`{7 zSLo)RnY#WutzPz<}$K(?GI27onm!}>z6sx2|L#=v; zNv)NN-g$v6^bS`Y|0wV{Z+2zDD&9%mlpG|c590w|pp|C`gNgUYA0l$U8Qt+1o= z_8D%{vi{KE8Uh6E=?N8BKTK!B1usZ?~%r|5!Kj3pYlPre3hUkzb0 zg>d2I(FQJTkgrwJ9c?s#ve(gg!1{~cuS32(CdE9PS^{S3(A(T7!FE>xW<4YZ?3G#0 znW`4)c%cxFQW;P;^OeDRopH9CpetaduJ90Saj)V4`ZQ@S{LzM`-$OsAl0EdT>}a>k zj|(Tr(+#Y=PG_QWy!m@kS-%p6+2pwxwjfqM;J{>zE2mpv<0_S_h;wh!+2}Lym=hnk z4|>6J#w9ukO*^Qo<=*yFAN_yq?^z*em*u;&{^9tnit^&8HR)IZ)dSL6UY7ht*&h9$ z_>GG4ReQpvFBSCnRtMI12DBwx-CCa+A<4i6Mv0$vYI}@euxudOJ$7NRENJ$7gYZ$o zw~m+AX``f`{)azCKxbzAS4v2qpvrYL$01|`91(~qoh{V8v=%?}3(LhCThm5KKFoIb z^^kMX$h-)DUm2k1!^0&>=xI3_Y6J6xdT*?0VHc|_AX+OkHb+*qb1@-IXz|z~euR2+ zzryYs5GNtOS;(vZ;rIu~)9Opp5kx;*JE4`~+&|h7AH+wTmogCUSM~}ne){z+)6D!# z2vsqtE+5HaDwXnEyaHw?aZ#E9Ko!CU(Z$xS{+$A=6|-81#Ua?1hP0o5%ylZ5{@SOU zhS=vR4HDP^eE31lW~vC%B0mloj^)hiIs{xhYHloBJB}Cl72yk9km;~s<^gw^lvqVa zuvhr6n-$=mfKLtUy}ZgU6*LQMjQ_FVJ$jRo?YQduXh}cD5Y)C=cj{(ao6G3Jhg`Dw zEeFqd)J}$&rarDjeToCBYNM$j?a;}~n(fVlWgqM0*`HT0=#uc4n?)T%hiE2{`zoTY z*srWOf~KA-i4nfFZ>)gnq?i%Ud)l!8!6 zq)|TsMgMIK*!~FhU63p$Cz&br3qx!YF0U>H^}-QGETG$m9Y>#;l+ESq;$9stYAYOX zi_&QV9A!IA1@$@`Hxd}d!rbN6Ek^n4pEPMQCde%BO^ei{jPPbc=Dsg&SmjTGnDS>i zkmS%ulk#~zkO(@dUp0$9%d&^@@;>SxJ*YUL)ioBkiiZ8`Ib1Ng4xMT^K$01u4E-f? zEE!0xC}X@oOoaINI?{g>XPaHpZX|Q4OEYRi`_^ zh7#I(nK9+4+huJqxwV@w&fN}|gW$ILnI>a|SH!bxe`m}#D+32ao`DUjylVrrnuuk; zld0@yA@Y0r_EX1`C;iIy<_l83r$*qU&ewkNu!k>tKL#`Q*(Sc32v~JqjjHsUdcqJp zdz1axHQX>TsIx2Lxw8YQ^r7Vq4GqORg&au?@}4_;XWeG0_-x?(tzlkBilqTMj&Wwu zyq&LY`oT$c6bgM%i;!I*lD$@JU?tlP@t?va=ChRJL*XXRQQ5LL~9W ze!OK=p6Fw3eKW)#H%rj%;d;YVUGO|`U*L0Gd1xbl2zB&3TwFOj$$kRv3wu(JXi!-) z@ACXlBflMbcu1yVI6x}9Lx?yE*x6^zNH6`DA@R|<5s z3UWL^vN0+=W9GMqP&P4qL_ScY!bQJn;Csw$S5$fWGwTa$6g);Nj0#~YKvbG9s=Q5; zB`@pkt&U9oK#OpYuGbko73B^nQ3c=`ABVE{sHPEp6H2lcRPSD5@f@dfS_Z8Kp6$;t*OmkQ|?Cqd|MXTcCQiAeT<-BQV~j)7r`O>80HS}-RM)T z;1xG86K+X}zD+Fv&0hc$o?n8IQ&rdS2u|y&1TwoXt0U*%?p6RaTro`hs)EkA+_J00 zD6LV@^9xREgr`Tc6`V(tj>@!Hz*%n-{mT|beI$Co zU0pd|12khMsNpzX_FQAe%1Cz2d{tUG-x!S}i9-;PKlBdE1&HzAIwdbZDumP(@wdMj zv-DHI6%w~pRjA~=qtVkw^~88l^@|&$AaBMW3ZXJWfUViV5f|c9(HQ(^UTKbdSvAP5 zB^3G-rHS!4ghle1c#mD~Dio_UBcy*yRqorL#6`D^h*0i#MWrq}*vN$AHHT3@bg|$nWqisQ6eSh!*+aIk zNkkMAGESxddHUciR^nZN(`$G8WzJUWoRSPx`i$0i6-x@st{EU-Jxii=Fb3aBE}$i@ zziXa7h^IJCIG3dVPLfXzX(e5=%bxEB{XU0Ni@@6-&Zhhz1wV-b35M^v9RJgjn`VX0 zRqQxg+4FO3ddYP>u35W90#l9=Z7(;JPP$`L(s_$xZn7Aaqb-1#oIrtCo`om4z*}m&hBh zYl9?z6Owe6hi582+NZ}eyX)WDV1jr|2`&kV_|x~Pyyk6gACp;h7@R~MpB+_9k0?W6 zUwDZTS-j~{qn-N8>9T^9o#~KQUIq-&!bti=5XwG$r%eQ@Ues_TtD^kgJ@)Rk1*uDQ z6#TQOQC$mW$tbNp5-fxuE5|u$vT$Ej_$V9=m@rN6oa21)=k7Q2oc#k^A^#fW|VGxmOZ8aVm(#QsloCGAH*iGEKKn3Y;L5pbT8*5qdG=9mW zTo@`A?&!%}h8CtLGB%g(X`u>`%3Ve}Ni<-;vun&mrDom0u4E;kJf<>s>OwiM*~)l| zqRHq8CV!q89%5%U0@^(^raIl}(r2u|F6dXz0eW~g;B`4QemwU-7h@aceH^=YcrboC z=~Ov++}KITzW;tB@_6cJ$=KWetmF9P@At>+l-z%3-qQGM29E#Z>7`Cu(YZ*&>C?$+ zAIp5AxhTsgsX;n_Ge=xyrYe!_Q&!&%oa}e20j;NP_rGiYeA8*AN~PS$;d?$i&}si+ zW*p~C*tn%L(z)j@z`1y_9}xT=nWd(L@=3GJM$vram2IDuZTrukd=YjwHJ<1~vT*E@ zxt^X4t#e_7z8-L?sH#Xk!l}gINJ{ItV?~ejij2iKBCOa``N5m!6Z&9_-KaiZt?^2a z%aFnEA~)9E11d*__WJvU6&vQ4@r~(xj(+1e&p%_@w)w zTqS;+sr+SmB=9+kx!dvyKsnYCTc=X^Id(OBXFkH5fIdK#`)@&IpgM8%!_USdRmuwC zgnv3+w&Up}j-O1!S4MDZI5}Jek*QdMf^WS+a#wQX^GZW4uAsd*O^GhZPONy1@{*et zQ~k7}DTxiO+-72D>+DR~t#3e4bk!E#8*F52HSb6cSK0H}#6gl;K4|3LVcUun9RA$e zOl?%B3)PfQSIhm}4`~r>PXPrw#2#F3XdUIJSdbKid%X@@wNATGUGWNg^e9)xo~k0M z`fp+0K2KihMQ#JV_~OaGoCdI9SHitaVS%sIa8t3@txQ;3V}k+LW3WU$1sDEeJRrDz^=~0bnRPP`d3yPIqjrc%w;ypTD~16LLN%1YsdjB-&JnV39@U0$Al>{zydnj z{NdZ*j1BT@R3Cz(?-AaAN1d=mFmq4MY|I#LQW-G&H@*gh-#~>mFByEpfV8(|2^2?B>mP5&%;bY*>gzl@M zui~`oY2?@FI0&XbMw;ph){Cy!UI{QQ5ue__n%kl0f%^J zpl!7NYT0nH#R@^npJM*CvZe3DMsJAV#Z7ktL z>|K}7&!RIzo}j$6eG)EG$>+m^V7y_XL>8@5w>Rj9ERzDnW?DIY)|DQTj{IAASa=f0 zTRtc2Z*rsdNx}9e3eXxs4c=lJEKQpaw|QtEIlgCTjEwE#A2Omro=SsViOBH909>^t_qIma?B`Yw>3wtFaTeMf6#`j-V|sl<6gDOdq+j2Ax2 zUPg-bM3l2AY>BFi>Zf5InY9#C|IUBlP2%nis34s{uBr zk%l}?^4dL(mY0_e-~W>Lt*I2MEGkE>7zfv@hDhPOWWu?lWsajt$Wk}(B3%hJDV^bX zZGb3xVvKxaYbuZE9T85awJx_ydPDDj(dR{`-)t#@1_cUH(6+8g%<)y3>JuX| zIATv;5ePk-VuRKScQcGkyBG%x$c=>$E%W^T)_W@o#vmwA*20hb@sE^5L)DHUv~9w3 zLzLCEKdL?odq{0J74D1ONr{c?-X=-5u6UpKu0A(r`xyZ)na}3C>7or62N*{Wsh+0~ z;e4m92i|`L9v|;(K;U`q+HKo5+kg7;m+A{d1A+eRQPrG5rDg32b(BlYL~OAYrlJw}EO%b9uEfZK=Jikq|{ z$sSd*Vm=e~OSGMte}kai6u&8+Yy&G-!|s&*H#;+(sWP9pENL9mP4ky20>jZXN89#? zWoGOa#0g52>}Cz&$2+6x&ujO7zegP(&l=kgMZ_N4F#OiKF?=pNWdZ+BIKatJ#sL9k zXh*>LL&nnUx0|HIp9=K!nsn>3t`{}kGrIZV82X}g$j^O`ir!T*-hDTFL?HL$)1$osii5Y@ouxxEs=^cjYuvr}_Nd^EuIR($ya46VcJ^ zleSV+Ma?h%zUiDqxhchE{Vf>)#Szq$_`9=y+#?ou$z9I;-){DZbFC<6- zg?o@fgIjQSmq2hRY)+o{?VkR6W_qojKLFTOi*wFCzkT1=_2s8hp;@u{>Y;3BTs>V3 zFi(o;qGXDOfGzDmO}j@+Dy8m`TYeekcex>sIA>p{VIKqDC4dup7p=qe`zQ_nZky_g z#tGVWu6Ir$nykC_?PtQUw34Z_57|Q@=SgC%Pt|B-FQoTRq7m^(8zYfpVe^C%%1AcobNjE!wt}*QPG>CYCjS6Vp zI?W9$wz~bzEtmx6HEcph-+u(S2m%tjDFTb3p)C#J+2|zA{j_!VN?Ir-(!yA}>LCZ; zy%Sz*uB+?dUxhKt@7h48eYxgF@y|8tbZvM);tn#T5%j| zLDl!C2NV-C%9$#S38F<`wO}Kds-kMrm3%Gg#VZc48BJUe6fn|qH@ra1SqnhqH+f6e zdsa4S!m;)TFI2SeEy`A<^OZTLlRt53b6ClPT{ppV=v|Ve4^A>cGC@gsMcsqk#dg8j zaM}H@Qx}U*x+ygy!%XQ|639%7npcID!x}nZN2c?sfg(mht-9!;s?8yFJqw3-1_xym z1Wgyj?w0$<8IAlM0<^OQKG(_tUoJGI;adKeIdMpUoDf@{jpN*%X7wd0)C>Vyr zRkzNhId2up*p#_Kkste85Gv zEY>TQM^}Ua`Z*4HyI_}Zh}EVLq2M3C5G!RQehR;*_`f&*?|uutYu0}3hYD1wF3 zDKT&V$NXxW|Hr5B!`&6laA)KZL;lRc%WYA=<~5*PO= zNmxap7yC=LvybT-M9HfQqmq0@_)8`zZD#jExIj}XkAhb~{n|VQ;cXxAFdO)Auk$#caQ#naSo;7z#E&Fa%^%K%UK>SY%1;~&uvB7X4w)V81d zt|9A#4$OV;ccgo*1xW0bgVphCb|EL=FOj9QG$D{MlU5QWneL>=K>cgB14>%W_}Ij=j+~{ zElA74eD>}L782=;iY|7XjY-EAlZS@S`;0dk1Ja}6 z>ALzCA3={eC-2Uji6=dux2!3F`mELR>y^Hjp?IbjXi| zbJ9;*@cbBxWRI=sr65w-$tZTIdfyShu#t<$ba~ariW9|Bq?>&G8q8T4U=NNXLkmzK z;~vFVArFuRr#$46d=wpJ&0EF9zAiHVhTSlP5KwK+C>5nu^6UaRMk-v%CtN$YN51Jh z=hv%PN1BIUtrxOC)U@7oS5q-d_nbIV$Nuowma)*C)|}l)Z^_K33FEV0>DD4MeWcqb z!(u=J66mW7dwGaNfwryBE`H5CE2{84x9A(9oIpf%T`L3`cb_O$q>Ce1%26Xn|JL*Q zAk0|)rnEZ!D+cmZvhRm+eYZ=GE+yH_DuUN4F`acq{&7X8@yu+v`b-}=qdlGcX_yIJ zYu`#_;=RBU{1q9umgUO$vHJZ%rGPlpfh;D5Y4WrDZu*olw)HeVwrN9nt)pS{R8zss zo+JL+Qjcs_2FJQ)h6WT;fGhAV&0sLjwA`_|Wd@um%|8crC&YO8$o=JQPwitAezCm< zK;_Xn{{DU-R9n8<`{R}BcO(MfoF z>?lMOPA*h+PE>WXR|;lK+_@Nz@2b)$_5N!n$T-lR%3m!pZvvO}f0>1vtSkwRE=L%_ zM0zht^4c0RJjpr*ErEFRc$TnZ2Nc(@%P*}FfV|Q_ z;UhC#vt*Lbe1ql73HdAQA(HkC$0TYfS3Ft&XRxsI^0sp7kay=^mM%t|(iTr!G1)nY zqn;s{3{aF58r~bsOw#bV*dBM5L9E1YQrvlvWJpWZOv!+Y-PsPYC!^~2tIQz~|Ekk0 z30CM&lOZWB`(kDsSf@mRAS6vAyU>RemS?Rc5q*p^l0?EvUf5`>$P%S8cBy}&!RP6~jp03lpU7&U%>3|Xc$=CUl< zQ{qCnu0CIb(Hq@g8a-V)`K}fL&zLtyel6%lK&JIdiXKe8#?VLs>8arE37CbhJHge|prpINYama5_FqUY2b4aA&Q=0I@Zmr?xm8_E+D~wqRK$TGfV^ z8`8?w*W385`d=$=du!x8>aVcUcN-2~kphsN6^de=gNL7jD-VFcWlrZn_@aL^7MM%@ zt%rFWUID?_wVmU~kwu^$HU#TA$gN>J^lCjf08U5rR?lWATAm&o5q@kv@~Vca!<#Gb z;833-J;mFd#df&9ynub<}Iy4mQBzs-a z$~CP?ZlH7~miW!gi((KPgYD6>`szaulXxf@Fr?%ps$0BmVh;`tZd|mebmqv7nNRg0 zm{!eQ>$1l$_QShA3FGku)wXR<%4ejlIjoQdW{|U!hy`V+f1G?4HQq7w0?X}7%OguD zvR1j--zeGp?PFl>55o^xFkRs3a@ zKTTvaRD2tF^|-VxvWZVDp{wE(5-rwO0i0ViUP^**%Er9xg4Jo$uOeslF0W=)t-eeq z1wt=XliiSbuXtEJIH+W2I87fLN2r6Gjd8hCL&RNM?6_9h+`({z( zr^E2WaQdv7R*?_F0|UDmdwkkXCU2F6Aw|Noq}wimd}joeGhz%A?`Am}$9U-LFnHIc z+?|_)D_Q~x_N^}=k@r24s!;3EpZ!NPowKFMr+cKx5_bS<(V9Dc46rR0lO!VJBv~hB_-BR>!=}JKZzC&p`s}iyfQ|{a`ny%1LE! zkLlajbt^?*Ly<>pPu05v^4i=2UfO=g@6BS;VB6|fVEMkUnc&d%w!&7R-K{85N^2z0 zqo)SdUgZrIKaI+qYlatr#daR?*<`KTOG3+gqfHTKk62`noQ)4$3#k6M7akZcwQF>p zm-F~Fm0M@}rSVNwZv36CY)l@hr-aD+E#AxVr_w1c;y&N6aIaJO*J(P3&=5(Su2Jp9 zSd9aJB;%~+E$Mv_0BizCPBI5A`|>4h(KFFCnHBN-j-NQA>vZ-D6zn!lae_poERGOe z%D&_h{rObrsc6PPP5d*c)B1gLlmgcu290EqehawcsC?5|Ix7jH}|urjQ_vn3tR|3uq4f3U}A-QMYQMZ z|0sDuV)yp1jnLvKI12^m0*SnG%FzbX0_8LDd%#SPsveF?Zegy^VhaJz#F@;nk7$Da zS-*C)MvRguxYWFv!<38IK!%p&Q<6$!+EDfG`^Jg%BjSGJyb|Ar=}$@iNgzgad{v&Q=L4`Benn-4 z8_Fi1N_G8dO8nu zzd!Mx)$ZEwJ%NvA2JQvw!|YB{tI|zj#lKz2w}JN*3ga`%+c0~Ed5DA)L87ZO=hTel zG_0#;pF7}Wx28J7Whh|3Z5p4~jb67c_hl8VIaPRh$YP20+F_|-$!NYZyXBs#X?M@? zYkHV^K&3LN*X~(RRDS1`P>X|lwnHhp=WdNM&mwF#X|J}T|LGLZQ~*&>LS~mL==J`?y6C+ur1}&3 zV&>}o%xBu`{7o&kPe_oAILpkSCMp^?Bm|=o8~Rc;g)5?=>Xb|u<|1wog2hUCk>bV4 zr`eVw`$>G&^Qe+TRQG+e^Kspx;?si2{ zq50>NiT+dflr7eD>la(0y;~wnI$_2*%K0RU4g1!xW;t#Th43q;=wI^?!vS+QjRqS9 zZku^!B|-kim%L+BVUsKJOO?&W$*4OU^bsC#P!DTE^EWvpbay*$CMIR^tUsF>c89j3 z*bWRJ?B-J{1`>~LsTuCCt6js$$p`Cl0s52N5il^iYqOANLwFv^n|k@cr8kjoIgGCR zr8JXhErW3di+%c%2L#2-yl9l)NYFTx`?YL;X}xr^NdCp)H+|LG8jb}@PfOI@a-We> z`(8#z>Plk;p)W!W*?2v8t0d+FNBowOTxe5qLQq7wsLW5s7g75dG?_KZmd=X=@cb`- zez#{weM^@<8W#OVN5d}pz}pOfM}*p@nq}F;>pwwas7flqlXYtcWCP!4l}NF*`K)5- zRadnRgRYuBHVX0g**1T?DEY#2(Gw_8(yEsFvEqs0kZ{BVP9 zp!13Z#2})ZcX-#~v8lL7U3r?TjkUHti(lWwQQDw^Mn-sv^iuy)`(kMjq&HET%zP%3 zKILfD78a!WR@9#@`DuKK3LqB{;Pe&;+k~P;D2&u;Ze(jSU__wXF_(OiV&swxw7@?I z92yRc`){nZucz|wNH(LSb9JC%U5?!BOw--*b$Kn{^ZH~qQDXCX#=AAh?(D(1fDF$X zVyP%Uo@S$20YWZ4N`nJM;S}K1`%~`!L}{~aNFs<%m-(w!8H_1;iV%LfmeMX z+4IbXo?Q)nf)#IduGsvke!fOCCgsn#43@r8lTUccjKr39&j;b3^~%_y@H7(RzBsbB zEilJh&DbR-fR6ago=EK#d9I%cdXdYz%AXBal{Q2t#V4|k8`mxyfF+tTu`$C#7l4q# zUN$#K{F>gI#nV=w`q?8emAa2*%l7}X*&dO9$K7nC!e>%8^5enBi8tU_$LK@XKIw6w z3wjYicHlhGdpLV~@ST0S^5-3)dAJL_+zGsrl*P_@oMaQyOD{0GUE-wRhff7wVaEa( z&4$-zWHQC-^{Ze$JCVX(#&~0>>3l>0R;w`f%}Cp#xhnvOT;;_Y^@b*4(al};&bfi{qEI>07Yhv)uIrb*TyfQ=*|o2bX)iT7*RQvj+;ZgUO=P&l zW0|?8*E6t3>%{B0bd!DZ)OoiG-~0>HoaF_JoOK{$3&Vd=$BNzqnOKq2DL~8v01*OU z@?#4Qfj-R{!`p8hAz^&mh#!tC4_M=ZSZYqTL;f3gt42)_3tQ6;bvRka1zJe zVOX5B?idYvrc$QZzE!4o1s&wh2W^CXR}A3DA?{_x@LenX{^BzKzI;BreIl;5_nkj9 z&UrVBM2eaPDH`h)k*7i>JAse__c$pce^^Ly=!=MPWGl_rIN^fF{ZYt;A}Jl;YZdA` zxn9Xch{$Ms$R!f{EF#T~|9#&zG@r2pJ9ZyiAp(ahvj=Xjz}+-zWAK3@tEnHo41VbY zYd|M;ZZ6)aYelc&6I#`COp)~h2J3d=S30|St5Dff7IgaLp1UufTI$30HJ89fC8^-V z%26OW8x6ykPpYs2q}Uan2}=Te^Q9Lcn39v1I)4$YYv9qfcJc2ih}NUM;TBi9+rcZ9 zNZ{1z;*w4t78*yPVwDMqFiu-rON=sm)5omcQrtwGvoC6`0)pMH3eS}AAk&GEoHYvE zLW+yKpf>WuREzG^S&y3Cq(RmU6E$j<5T3RV0P5JfE1arkQZX3>ZS$np)y80g)8s`A zdq3OE^v+Nd?j!2!3WH^PHOZ4=`vR6WM)fIQ=UEK;q!PS*L{M%C&16~U3MPJ%ok-x1 z5BADNGqy)XQt`6_m-(O#T6Q0C_SDH6g^&q%`ch6<=+NU>v0s8+W(SvR)N`F!x-+P0 z(aszCB+3jFm~_TB5d|7U6jO~JnH-Q*b0^dJBr`a~HmLd7F+!XR2UA6G@#ja`Qdcy- z#S2iYVIfKhXCg>Y;@5fLgljK@H~<6|F5M_ZD$tV2U>n3wIno z1jli8JZh*DX32NWgyJv8nKyqbCBOQ$QiLHx{D>;^Oz1<%2Fr`gTKE)xhQK$6ndb#D zEM7Qj*D)d{?<*$DDxV0}^-C+8fo9#1;7icOWxI-|-(g6OpuMUNR8A}ZOi8)*kyN&$ zr3r)Y`N`<;G8#i(>KH6TE>1W4e9I!VQ(O=4s-gwjXmDp4I8`*L8+jCPp-#0~$UzeM z7s(DM|2kkH1$<0v$0*E3LgAnrN|t&vC3yihE(ATe=KRk&M=s#Ndrr;8Wh8=U<2PC~}g(y_HU^0%bkPQwji8R{`gQz9)65;82xQFni}y zBz6s;GkJ#1cRrFyO&K8ycXtY>NEl^)>aKE>kA4?IY;Dhg#lX=r$^3l}K}g|U@&ZGj z8cwpaIJ?gu2@2CRRf#S{gFL1;$OIGt7p7T>YkSCc|M8KI+DX2j0SL}H$H)7pn!@L7 zRJ(P_Q@05nH$AlAJp`2dn~nKXn71i&+1vrCA;Gye%;=8j$%hQ(Itz=<-n#!%kNpSO zdEp@K)5!o)=e5w~JW+zP&u*k5pYZt+QEb4vTjf)FQQ*nykL}q^;9!C`V0Crrft2FD zFX!fBmp-2@;51eAZWuuNoIb&?Q-S7!*ETp{)}Qxj^U35kB{S!~D96{5!(Tn~&?b8` zT_lr7{(WopByy^OT8;9T6$X)~qz?b<<*yIPl~FCNctiUAZeD_m+Gl1<`i16y=SFTG zKiW55Ro*1L7Ni!|Z3Chr%r$&QA*?NIowVy8L7ORfXf05uV?`4@(-QOACk&G|H_ zb8w4DzgqPCin+bUvs1Zz{QDduLqX3p{2NvN^}?)wOT9HlY4Y=f6JE%#bT z)pHc2$}oPnwI97yy|O*hE6g}DUv*jBrpmybn*@SX99XuSBV($J^X88VL*kmlByQ@T2D;F>|%N1ra1ogm}!(^c`uBK*0z21&)<4-x`wt;2zMtJxiY*F!0|2Z;CqFy2Ue5& z3(?}y?Fo~oTP;Wpopi-o7wfh&nRErfy+k~W%6#EH84KqR+u`U%tsv~C#-$&vfA!}T zfPsE-3!`WdKD_D-GI|X`{zMD5RR#sl+4OV1x(`c~his+mZzTbgp&{TjyZ|z*J`M0% zDZpvY(Am99qM|D(J$)Ofa>m}HVW1BGgHn0}GoA`}5at4|XnJCI@A!Dw3tZ74B(u>R z5coaV;Ig2}kc$4ms+UpfcT}@Py$vnx&eyvxzm9RRAxUAVrQe2=dNkkm{We$tdNFaj zzCeXCGSJ$9K3oE^5e61xy~V%`<81F^^RMD>?qmHC`&(xxUL&N~WQP%;#2R8gW4-_J zC+k{}T>ElPY0$cX@4Iz$JnB7R%XWfsPu00w+B)u^E(X~d+%?__5{n9O!dz^}m&kHU zg2-I(^%o3;>O{;;#a4u$K$aK}Z(9$>{cikCh52(2h2YO9+kV4E%Z*Sf?K;~!H_3V} z)51i4Vw*mmFTcJ8yB z6)f-IP7DKrs6oS|(|Kv15}Nw^KEm6RfdTJ!$+0|dy2c5w6%2V!tKD6VY)YJEOZlyZVu z66uzOehu8~zbuo+HIlw}+5F+yqAI6XsfS6=AF3yLj(|1Zx{LR-pWtnIiA;Qxot*Yz z!hTvuA%yHI(353zVZ??_pv+et;2$=W7z_y~IeyZqcXBNhV-znDiP7Gl7UZ5U9se(? z$d0}~#uyYEb3`waTvsl!1%X_?UX)`eeHj39E24m|W#(r4vse{3uh$ea&N_}*ih>lG z4lQmEY01SO3y)vo^WNzovT~9XPIV)O)awz#F@9ta@b64w4FOe*q?onRR8s`M_-!l0 zK4D!w4&-Cyka|IEN%KTEdoiF8kUv@Z#87`pbagazN-UFsoiq~RGcXY%elH#*MYI-k zXcyOyOCl9J3m}CQVQQ8}Yx#l-=n9uEbqZ|MMLfMcP!O`izqFBUe!GG8D1e(%SITK? zs&`HXI7k1NpA!-J_$M--BD#2t2Eom_-#7KZCJn)EQ5?Q|EpR@1$R4v!+q$>Cux#_5 zOhjC@+24zIL7U4piHangwd2j~EM+`3*Ee#uu#goIpbqWvcrDsIc#dJL$762Dlu_Lv zIW2lJBU~?MoR64MUHXS8#rX_bj!kiNpOtnd`$f6Wv8A@)1Az1d zZ_Lc5H7uPZJ2y{NkBoYS?*j0Mr$`k(e|YU!tKC!Tqtnymf!9hZ*+lfy)(P86BitgD zw`tn$I$+-|@XqXMEBWd7iVhY!{ms)303_mc5;VA9vdZ>HF9rXd@@E-txmTJ8F{ZQM zn&?u!$X-%bHy zFC8he_3TC7(F4h1mzd^%l1oxPSK(wS)F-en=W zTZTi{`H~>f%9OPI1Wn&ldsV_PvTTt&j86JXpzg>d_ax+aAyH|L7XJj+&<`bMM1BQpe&r@^+8SheuVhE{atvf2JGh<|A#0sTo zsZj?Q#5sau=xN##$V589ELhRFrWCH@Ts;#6J71KaeM;edGs-qusyRtQWO-o4YD0pr z^1KvZbj@AO$Tb5`Whnn#y8VMw`zrM7lAfuzHd|%s7vhRmXKC}ajClDB6J^0NmGT~;%LF%%z7GetJdK_;+`Gox7G09kC)kTG3j^aHQG zOGnP?dD^u0`kb_(ty#HftdQA2B&BOXuu;+<K2bxCvnWv7EhmOb%>$vfxT z{#%WVHlNwmInH+X2U*t~*dhF+C#QdI^F!m>4q@b4B&wHVi*+*te5Z%I{n*PtHq$Zd z%&}UR{#*G6r9iRz3F&bCA*mnsongwS9Rj3h0i2#r-(q&^C!8_Oio7u_@;kW>SUb|ya7RgyPo#pCZboPL(eNvC1;Ax}TS#K>)5aJ4w?iAkQ>_D0 zh-M%EDN{%zT`D7sP9k$sW0>0*;qR{cjJlTHEKizl%q3{ILntj=wnnJXm zk!AHy*w2B!FQ0Jbwz8?epLTi?|Csscz`ch5l664g%E6v} zWrP*b1^~FASoCfx4olE7$g{j8`g>a$D8NlB zrgEw_Gdo=mU9e85WI01+h%!GvT2C6jvw=1qSbV|HT0P|52l&sCuLON}Fp3_YiSh>Y z--CEMfPu}c_8*(u39Bzeb2hsH@fYsdhOpcH(vIwt$Lo#R9`vxV)y3g>g3d5Ea{K`A zEUdYU&jH_JZv-DS&@+7mR{2H-@rIj)Dd4jjk1A4WhI#k{{NMS1v#8lXs~N|VxRn@n zlZWy3UHc1DOMkb1ZD3epLvU%Q@mxf~Me*Wt^&~vNNsn^LwJo#7j>wnQeZ~NKRoHtl z^n+wKL&ocnQ4~cvD1kXMRj_lqvcjV~=UczC2|G!XLPcqQnCXuPBF~yf#!y(HZCLmK z!HCjapgMIh`O000lDR}7)1b;Kn4#qxBD}_V(S4^Rf!W|o8P0q7vNt8#%jBGNA|CO* zLd#_EcbQahX?EP6$5A4FQk&}LneDy=?dFfJ{g)XBy{EVHHYvPs89h;L2i5B<;GDq= z=d}R&Q|V)2(<>hP+5&mea4oJywc=@7LHfNhFR#r+T@`V(e&KbEHA7h6i@jo(Bk2=vypHPNmwvz8qh!Hs*h-pWDks|K>pXFU7y{OZTZ;`pEL1u^O^fFBY|*#3>r*Ena|v=k`XBWN5AhKpU}mMdkyCM zXHlJ>(d2i5N$3A^O~esH|LZk5Pg)UtsJ}lTb^_ESal;g# zP+bw4$PBOwZYrq){Z8#KQZ-~_5cIfoAgTJyDaoL<>-PP9(wv+6-Bf3vn?f2u`0~X{ z^vB~A1^jNP5+37|PX5n10L4S&o#@#Xz39{MtD$6(^II!&KKRAo1B9p1WePX=veS=C zET?%EqXjB@9;58uE8sbFX6LJjgr03K!;?g^*?$GJ;JUW37R|>qKcYmf-t+<^dAy1x zrJOZW^VTC&*HUax<6%RgKFhPul%dKwZ<*-xSF%-~SIxU}ABZE+YEbjXy<$haTyiz&m1*Xyf zSQE&yHaF~Va02&4g@lqC#>4K1&$K_6CR{!CFp6f|t~|~LRmvfayR>618FJT-p;6<=}Ehh?94At$$OCxKhleeCaZ2&iT`a9J~5W~2Pk z81BMqU-M^ylOAx2)Rk%IK$|`*TyDLSluJ{0ZH6dAM|{Q!H1EwU!w?&tiyT#UT3e{~ zM3;{~GjRU`#Y}|-fa)3y;xu1gdW__bPjM#U} zJ|p`=JU@(Rz=Vg12@m^_OWb_r7O!EUPQhvSmuFZ-x{I1Qj!KR`^;R1 z!I0X)gI#5@OsYdoovPtauBOI)>AmUm((kP-AS?u)-am|D&+hhxYHCFa`N`WBQTR(S z#c^>!28{eLRaKiVdClqGv}6;Y-kui{SOPOC9E0kCA6P=&cp zNre+=Gs1+4wC3dIHQzE)dfW*)Q9T-kDL}i)T8qE^KQ!C(wChr1*It%`{q+EV6`57w4xWt^# z+Y^=jl(91|z|TZ>MTGfBo% zjQjqXnHC8+ls>RaHXO8;vKPxMoT1wqm(4%p-M_^K`KFsy7JN%RjwfN3RsPqH{8_xB zw8ZNoc*Z{}BbG#B%_wWTdC|LouE`A^H;8L`D@R4y2$At7Kwwo(*#OL}R&+p2@}{%r zLu59eum?D4KN;0EX}_0nB06+pg0NnmY`25yZbH{EKV3L{hvPqVthRuKas>H)(9;^Z`jUEp~pLE(0 z(Tj=#Z_igRS7M*C+dU7x{CBZVDemhtpH?YE1mIuBR0vZWj2?%HRs!x41NTlS?nmz+ zWUp?XYOgEDQw*m4*>rhr!r$afl9dz|_Q(%8>=vKypKYTW1-@4i_(Xqv0f|N#8^q~$NS;)o|-Weu%>fXFPRC;Htbo+RB61!gA z>PFN)K;s;lOfTo8(Hr6pM;j*ab@~Xw)U!TG!tM3!RHIJHw@r;tgC$$#xE$*sv-yli zHl)c!fbo?DCK~{4S$6EI9=-~;@XelC8xT?Xo*(agrgur0q65&A0ZxBa+l17|1f~4@ z$%y^p9W45-%jh#L-$S%R+UYG{6{xO&$;F}a;pN?hX8gJ>mIQhe{kN~-CPs|;&2i3o zTRw#0WWV8RkqEfOUCI=JzVgqh#WJOwm*S|)Bs9NB;2$?bwg;VGcvG#XQ+`FnWZp~*cZoe|afg=9cAp@1+afjSTP4;TUJ2RaSbEDJ$ zcCLQ>15&2T3J=xz)tKd1JN?161-p-QA^|? zy^n?6vD1g1HHE%`&=9I5C-GHqkD(~jCFLd=kbi41Fx_`ozGX-YK{NAqD{$9uldNo2 zcXds~dnI!=z=gMyfWirrE;m_;MT0;~2#XmQuz-Z^t_`#rb9t++x zCIV`UblHz2qnoTM(V8fj+p}r5VI}oL6Vt^J9vFhlJ_)jG;Ia0>`>}SsNcv`1I&*!p zaIKic0+z*KGjsE)kG}mlIcLGPTa*sO`Ao=W2%1$)7I*K7bc(mgsn!b)tPLb&76-7f z@P2k-NF|44#n`$qZ>MwqsMde>L9O1a1LV~N>hpste4H9znIloY|3LWa>jFg~3p!Y% zsJXJSG`q)&U`yZM1*6bBa1_i4bi|1=_b?G>W-}EQ8>pvES;GtQn$06@i43&rK_Zt^ z8dqel1B%nX9>aiavBH$w?&u;mkA`f%kj7hb9)91e)0H z3ztJRsx?y%RhGZZaSyU;j-8{$)n5EK4{Z9`F@D?LuWwRXn0aSbh;~(4wg9(wuS+p$G~rWASzg-+gYywvqd2MK%waT} z@FLa8qx50%cQHvN7b1FSK%~B05sx~^>e|05NNH$(EuQnIF^cJ3?@v4tl2;P-P>156 z!sWN!tktr~wTbK!C_11fhnQ#FEb4Y*rMXz$#kE&)Z$&UE$;|&*qr25&!*|;cI6mS9 z!1B1Fn4XbHOf$Gl7WZgFbtS5dET(5<^YiO5Td=x=ISA=V4mOQ*ahJZKH9avK4?MIJ zNgd$-l;|!7<-XO7#^a6FwJ(IyqTFd|JNR=6=nhpaz9(ZabIJQI@)9*HvmORr`UX|s zfT%~7Yu1Mvw+}+qUo|qX1lL{DB>gUbp_P;x@J*dMNfe>H(QSK&V%PPg&o&8doF-&5 zmdu2@25JGTXI7Q~z5p0|zRdsd1$351>f=>o`{i$^{Kr(Q#|^u{v)$76rxE(m`+X;hyU#iI{R1byzfa}(I#0Yu zP6HnwNBUGAX0K9n@O-i3oewU4CYyM8TuKA?c|s%IE-b4Iclh7iJT=8rmZ~4TZA|#j zFJxe@G>89ugBKh#n)A&*QFN`Yrmac0R+ctcvsO8&ZKc3A3_ZhHfRk0T$*Y%WxB4bg2Jg(-=wUtIR2aHFe-4pKUjs) zA4R)z!*Hlche5ejr@K$P$J>2C$I&Y zJN0o)&4bvkC`t4C0gj_dqk^I!UTGbJqFp_w;Le_{TEh?r0nJbzEsEW{QpqOt^J8t_ zvA(dGUSTps+g5YDtf*h%4h@ae3KpB`VuGL1(yD^@3KSm+keB9L0ms%CSp zZ#5pIJL~ESPHuw_ocN+wOqf_0a}w70jRFhzk2Y+*2f`1`!pDU!2E8Qdnk~PdP-8B%P!!s(|Wn)v{x}v!?oj`w%1w3fST{H^tCa|mCs?s17%$i+K|;mQ7f3^8%YkimdP!j=2%4o*4?j-IaAi( zK_A0v@S>n87;$zf-QA!GJdZhPlape6uj67XzSlF-VywU&-kpGHD!pxv+cu@hJdGH| zb)W?-;(v8Czo8i{#@iD?s>P=d21PK*xo=HCj&lYvBeQ-jVVim6lzkjKe!~cT59(5R zr>vS?`Vn%zJ^g)yp+sFcu)))cqLZr~Nn_0=(}Ee7tSiVFi`COZ)9u5b7) zQ{4Rv$z!G%XG-FAs!AWu?8Q|=1dG-t`kNXH;c-vkvj;gaYoRDmOOr2jEn2z@@gEAMKkAZZqme8w zREI>}y!~KTg3OLp3fnc4v@^pNKaNJ>RXj4$tO}Rv5x3Hk``}ycFxRJ>J4*5@L^o`- z>FMj|dXjkb>E5qRPmLlxbvyuSXDvUO32FQ2=xNr$h1yYZ zPUN-vjUzCC*}bBX%Xx3~<^5UXN=sCo?rsG0{_W0hWE z;hS(R-K4_$_3+&4@;A)=-^M~1{_AQtD{bO^sa@t|UQl;!(}F$8V62YzaAXx7;q?om zRrnQ!|2f;^8Y$5?c(mx<4DZvup3&1}``kU8^Eq&*EFyfoSymN#SYQjd418MV6om(0 zKHUlGJXN;0UOZHaKJsSdxP&~V8iAjDo%CpHjFSFroByD?*p{q)d_wOz}Wy|b)4%qt*92@!^2^lE5c*YrfXZJ|wmzrCDy3iC8 zsknaqb1u*UW%VKkiALn;r@RK-1v=Drobu7-=UEto7XG$wHlyBE|&sy|{ep4MM=6S<9QbA(}OUp`fOAN3Ty^Jk}kxW7K*D{;3i$7k_{NVlaD^q%3 zxR5aGRLVosh55De0i`0tgGbB`222}6-8L9kp(#4IEVm4*wk@$kY=LG`Ps&Zc-Xt|e zRm(Bw@wqtZ($jCs*8Q$f*G>^<8s|NUTKzdqz&-)>a`n5t=6)?{$SdLO>t)C^9GZw; z6rH%MJ?p~P0#aOcgT98GnZ}_PO-H*0cpt1dhs4{SF<)+A6|qipDezVM&?+_>lFwE;fd#w|j%57DY?3?$K7!Da zcaRloO!8ajG*#ru%#I?CjQzB~M@T05*VhO|@;a&I%-)$(w2!s~)Mwey80kcqgXF2F zXVZq6)TuOHmC!xY!!7?=VuG7Dh4jX!Kg&v9<(HzoAS1!dcY%1^`Xr_y96n`g?PzXB zMjRsxrjybcU30g$)1|rQymPQa#Ex8s!}|#R4`0{j+gSLrsXOh&i}7v=WZmbH>Zcjl zrlCY+(7dQ1-RNQiLMT}M&}N>qoNz1S3!{8Zh6z(*&|uWtGkj2eRQaQWRJ@IzXL?2q z)Zs88$qz4t!{W8F*7v)#nrvDM*Ml0vE`R=K<2JlxATyjzS(J1=vE-kQKh{ zxt%IWpvbem;8b}tKX0ptyg*2miG2Xl$gdp#9PhW0Q#6`WM8jc`Dk5NjuRgW$v7LF$ z94~nWnWaCeAHX+IFiV7k+%?p+4({!`!tt7Ipu;nWFV}^TidH>eP?g4n##rzgOTJ$| zfao@WyrPS}8Cf%qd6K~3!wT-(`?2r^X7wga?=KR$=)2xjNtF4KWxZNQALb0^MVVWG zT{P9&z_bZLfjTT{R)v3RuxHsMscKs8^~?W@w)c!`>g)DKEub`!B3(dAD4{96OAQh_ zB$QC33WQ#jq9|3Q2_!+flt2;)Jt!zDRS1goUIgh)ML?QxxBusq=e*(=bFDVse-Th%Hst#k)$adrn|h|AauoBHp}KJJ#*oYTACDFoav(Nmz&ke;pR*> zwBWw^msdeu@>KLk)?RsyV2_5?r-KnJC43EZB{RCVDJbPTB|Y}xXG4f^dhaqzx9Cf+ zq!jpDI^tvK4KLevn!<@!>WnZn9#*6ab%_TYfLNowR2 z4S5d9>`HbrT}YgSc;vF%nLzVPnzX9XS}25Lthuj%h?qzPn4+BspD-knDX#e5_0Cm%h&6T%ID7+K07_;kp0LJ5T14*sNI2=b?|WqGgcjw0Uo zAaGE`Wid`-N24sNA&sPwF9)U|(dAEBb(IRB>FZxL#`%ZeG!MoR{a*^?TC~01^6>KrW=A;s zI4nd6jGG%w3ut}(@S^s?Wqb^LOAT8&bXb9)5%2$2gY!hgFnrxxJG8~(E zH~&@LPt@(whPR>b-VQcA@^xBDhSQ3<8!3+5&xN*mI_;hOT-r|BgJ}Kc4#xnj%?LBE z6@eB(v}o^?af$a3`I0Y?j>KHv{6L2<9q;Dc^#fNcjNtc}jDerX-w^=}A$ReYP3q$J zZ1;>qZ!g2lX}y`Y-iz$i(l1yXe8(9N9h$n>nzSIv{rG-;Sy0NA^asgP`=i@e0C}O8dCpC#2s#7;ljXp zu#1e6ray&>R)%~s)!;#B>`Y!d@?iLyiKsz6_;LN-p3sO4D8?cZ>JocIV3zpe%*(+7 zon|x(_#lD&GOEfjb2B=~{S9vrL5c!R)oHFhKoE?h>otal4rKUidD!e2VBh|LX8NpE zEJi}r*MRo??1*)bWZFU#r6 zQ~H?NaoH2Ys-TvxS3pv|UqEbymt%;w6P4Xd8Ld_3p#=YpzVU6X0BG9K1GNN~xBfoO zcW_p$zUMs%3qcVkZ^PT&}D2@B@>Lf-zu}qJvbW8+$7|&+ZXFDTrg|ln=2s zAzunUS*vY{2P?|K5`VV2RyY!|^bOL{`vqxNh)Wl^N%D!{X>slt2xaaa*!5t`xL6X~ zRQ$tA%JoV!KAhX?CW16jiPWnQZVP#PRx1y2MzfAIHer1t_Nln85IJd3^oDYr%It20 zwu#hYFw*55pLLQgLkURs-EiMcyI&qy_o?TE(LyG8RGbHYNc`Vwy1nM(C~$O?UdEC1 zVe|La*k!@vI>iew>%qxezEd^-z18h2InHS`>*} zEb8Z2E?_(V;YA)9;SN8|mIK7KmiA#Z>GP#4@b{3_4m9BWo&u`!diUr=8-H05FGIdIp6 z!dLF_X{&H94vQim2{1JNN7w;$#I%e3Dbk~S|Fx169EdmgvK>v&;eJAqhRyBv5W}m`VHKFFAmm@|;Ip(Q zu|O$ut~L4p8lD&lff(QIC{ju8mi_+D#H5PtTbPVtU|0$_``Hd<@S}=Z&Oo!?thJEa z-(VI-_DV-kwK-S9?d9OU*rCCr!?+O{TCq5}6<8)@iLy*`et0n(x|29KmMgxJWh`|F z8D6E`y%yQCR{UvbCvMIkFqN?xbV>I|OsVn$0P4H2zE7E%5))+uR_nwu-XO%3h@BKT z;Y;=oF??@Eh}jq<*G3*w69_cs;>wMTX9r=R8JGC8+y^&r!&5&VQPfpx;bnenPc->f z>TyzM`gcS`5+PWObgNzcwBDLw%ejgY>lsx zJi!lbip$yR*zDsnG{6yTZdAjTXY{LXwP59;&JT~u?!}WMtu>dHxm8lSX|Uz-AU~it zrmyH!s(C9l(D(u7cP8@gy(nmVMkRQTpg@)hsa7r;AlJ~Kmhy#|HRK#dXvhZv>_spu zv^mFDrwn|rRCcJcZG8XX@crByT*as1Ll$x=FdImCRr1m1p^W<%myhQaD9Fu=SS9cn zrEzbDPn`X$qsDJAmgj6CEHNflwczcP17kan$nNTr2}$UKGrGlE9?b$Xc3uZs7XWWWeA-;{_BS} zo-rFJCYn<3LxOZ{IE$oFv6EuM{!4glUG?)s7wr@?uZov313dPxeB_G5r_SxAAp~|e zF?^=$W#sAhR{J(^3W5HGIikYsm4j%&OMwJV$Wu=36a+aOEe6Nk(yF*t%)&ZOe=dUV z)1-e_Re9e$Gh`aUvcMo#IZ1g5xObiV%~gY7{w4w1Qq= z?JoMy?f6GCBDo(N=MhKQc<}?z#rpr)jIoTbEaMbAXet^nVADa;0%_Zb%g~4foR8sZ zWQo3kcq81`fRZq|-OxSCL!yG2#j8Q?^xR?Rx}c8YGxf^!V5cXld9W01in%U~o4O27 zf>#|I^u~N_Q*gBzYEc4u@HbzZ<1{#CL{}gv%cgl4I?<(l-Ev!FG9u&UE6`+mJG+7m zr`c2j`#`J_El@hm%-o@0sUoaBwZ;3ht3@<1)ccmysl(s--?mI)yEh;Pq7Pm)ZKpD; zRf)%8cgu|bkBhR5X;pcY-~Ms=c_Vx)@&^6V$Qi_kk{tS=J2{W(UYlp=gBd2{Cw_ix z_QxGOxPIP7r72m&G1-7$O>hv&DJmfO&^(r?~lt_~{*|J&( za4$)yB9R#2njgQhHfR_HY9WoN#MY41AVI-p)SDNMs!sJq5i z=eeVa3`V?W;A>5Qy!Q~ei6BbYoKstt`HhcBMg$Z{(g)y|-kQ&mQU3D2DnG-2A4MdzM4VB2+lC1(F9(sRBvu;wLpR)i@vHQ6--(v2P0U!1)R3d2Tc-N^_0-U zs)hbOM+Ib$3I>obYEbAV#agEtyN_rIoBm1TU4uCG7sIp4272tQ6p@oo2^ULfT$1|< z?Cw)f|ym+N5XFoAl?D5PX}%e@tRYSvXy)lHn`I%XLu^pZ%QjH2Lp+9H;`T5NY2&_q>EfYx``z+T_bnAOIGz zx=w+;tonx#6mAu5HgB{ZKs?j_UgSj8rQ}A`*7F-bryfbLI6In0Y>0C^Su_0bOyH)k zs_&Ym;v)tMfV(Ri7@L-!PGt;mQ$3uA__%9+5Z*QyX?Hqc(B=pnHFaC;v~EuoXVVgm z-Q>Q8oL024T?!P^>Td-@arGDdaa5z>Z`gr{df3RsAcxE7aw4bG76{4MCKA%_@DLF( z#t>*ibVO_6o@WONa3U3B8Di)l?@_*4hKir*tE1XP)9-BRAE3j3N1iw^8{dsQFc8WM ze?K4W?1_!co}G+eg8s2ola!$$_jj0^jU{=Hgnur%@xlR7PB>fxItp>{8k!vUV%Zhf z_@3VYoFM9r$|{s}&3zrOTlX24)*Qf72_|zEQR9(4F)Fp0{zITf0R@;KqGA z!$w@U!}3qqk5s|r0BwdP(+?lth3?mOv^PYJS9JxE+!BDMA_E1y6gHWOVl=K zHdx0Eyuc`%#(7J?Qf{bS&b7vxT~49uvr^uu=|IZ-vHs9}t<%T=hpBo|^!7YfCna~_ zhXO*;U=xSId38v&Sd3uvQQxiz8$`A1=lD;mhRnte-8|TaX9ijK?l}GLPcjLRmtL}NGZ~R77 z-bF$N$sJ5sDJ4FE58FQFOGEuSV_Ju5!Vp^~mkKv_x7doMgfjLOj$ekTWuO(^g5D`H zx~>O9$66d(wq!2Z?#YwKHi`-qvJo+m#lVC5>*Bh{~+x;T_Q&})c8@KeHPZ;5(7Hs|a( z0C7gRZFPf3XzAq&yYwwJrH$Dy(rdCdo%~=9k~F=6Hz=>;8WVV~U19ry zz?xkbs_R8za*U(Gaf-Sr)_=;|N(#!7Tpu(hkM5I4eJ9UxJfXdO7HGbgN2m6&Ef9vm zqwc5K#WbtBts}1U$o?^fbPop3vUirlKG4IH+TLkr*2Pwa*WO@%n;d^*q$*(1!oREx zrKLV|63i@;{ep%7y?nBx2Udyavb)T5=<4qC_ZBQvMF&m9 zsg79n#{P=(G*7`+j^*$RJh0Hb9=p9`->b#B(8UNd7~Vd)d$Dos{Hu3e4d?#60W204LXcjF;Yie;5J+6PC%h8*O-bXBUEQgn ziOxNRY^m$I}F9fZeIw?t%06srKG#V*FO1Q*^%s814;)qqNWS`UT$bd3ckFRB7Kr z1cP^dKSl`qJ=kOnd{vfwQRlqs}c+y9;-~?C%y?iaSgq~CT z>EviJ9e0{N`}6cS7g8q@O^>?Fxt>XDjV$NCucvqC=;Pd?9gSyO{F_H*=23S9t7szI z|FYALd%m2^uJA@4%zxzhEw)F`qr~Z_c$hIXxPG)i=Cs3CE1)R`5n+Y+Qq+32LV$^5 zU(a=FkhInVR&-rij<~{)$~7z+Ehj+$UR$l88lk)cTr}Mu=avUO_{9)NSP4&4>E7^< ztLQo-M*ZZ`c*gSzKrCotF&w9htDnVX3sSO`*EEM+*>ZyXueYK2GlQ%bgS{q@ze|$Xl2yIRqEvJDZ!L z7p#$N$)_il>;0#zff#r2sw>nRL;NuOLLk$vGfzs)lC`lZ{h3>^D5~XQ@IdfmZ?^C4 z{*S5lrn1RU1gBE8M*#lTzOUgMz2`u|{LAoB;Vc43ZWPLG=Cl6NE7$xK_2+zcK;_O# zVUGZ9?ULA@<>;4#c#A{dmH{qfe^1h4$Yksgx$AJp7W(cDS!_m zRTy_KmtgwN@Jk-E_(a)}!|=|L#d3C}5m}YFEpbUk*IM-UHwrdO^8Jl$e?qkai<8sg z@F3Z9&L8Y2cZ+cuuuV+FkHlKo7k-ujGPhi+dZR(nUHllpn0U3`lW}8SfPyQ>hi`&! zLSNnlgSsGXOCq4|6*v;XyRFL6U;f}lXcD|Zf%<2#k|yjVufS>@lrJ|ZnyM`4n&Az5 zDy@%lzpinUNDODruBvopk7^yVeb504YXi)m3~!tpx-()ICI?0EfhMoutBk^Z_~hiYVNAN9Oc)CV1GTUlx5iHn zP&QO%nqYb4Q?nCco&1-_vm48@WsLZAiC_c^Sy$>Mg%}D*+`Qd8VT{AX=#m)x$_?k{5UP>=F z>$k66%tq#x=jqJk8r3DGq6zR(&J@Ig*Cu7GPdld3XXMA#k;jP25f2}BM*qzDO0x;D zZQOODcc9O9RNF@)_5VnCAqnqmmZ^NHVmv%!JZfo5Zb^i^q?thAI5orn&#cnH-Vlpi zd#2mqabeG_#xlNB$@#zIXgd3*jpsZiFr1B!r+y9;`TA`%_Evo3D34iDU3-wX@`vfO zkRiQR1PANNQ(bseZi0-?$oP@n+@He1Stkm;8X6a0o$GBJ#YpdmjdhGI_c>=G7*;N{ zJo!0_1@)=Po$$S(lm@kU)v`{e7a$l`t$=sH5&|Ad0tcyBEv}oo<{sGabbX+64uXz2 zu>DsM+V>Ib9=DrklK?2laJcz2*J4(E1!Z zw0V=+I8kST@Im1(gbvI{trezMJzXr)*6X!e=T>>t7CV%PMdu(VW0RH=a@V~K<^G~6 zpDPcD;rA>V06&&gEJnR1$(z~jx4H%ChDAkgRHko6kMyknv$ym*8gj?ZJxe|wV|O_I z>5gx``k|{`g=*9-1Lti$HCO3!u1>0PC=~PQ7yZR=Oj`Z$Y^2-%8Eu3OHpeHr(+3qq zU<(Xic~@jdsIaRuLUq(CwfNUoXZcreOjn`jf;dSn{wZU{NC0)3rP$r%6s?W0V85TB z_N0!!#G=KmbP?0gGC=1p%mO!4$=RfAMNCJtOBDUYhQ^z1KgzKTZ@hx1iLx9_{7BP* z;Jd@tiVg@c4bY%6p-AzznVD2Eqd4=Wy6ojMMRuYtip)0WV8U!)&NEcc_TRajH>&XE z;9U_z&WmdDygt<~S&vL+1klbZa^KKUA zAcK&ctH1won^laHtyQkMIaxoHQX&5E6X>OGXn!l zU4*$`fNaE<=B!(-qks1M^~mSjSgUtZWkG2O0E%Wi<@gXf=}8hAw;WaEG08?gQ^6)~h1F3@;yNW+Mu?$wU@5HP0Z8f;DN}BZtGq zQ0g^1zQvlFhP-vYK60gO7Bv*W8ApU@%*6Bxmb|HzR8V>+1ukn12U$z_A+V<~Wj7rM z+(vk`Zj(xm+KjSK?E&A=^$`b{&!hNyUf$e^DG#_rC}W-djTh7W9!7j2750P*M4%W8 zSzHmMj=klD7%~8PTF7XFS}mf!^k^sp#3uB9tjw0HO}z%l^1vd8v$*sEUNG_|s{uZ> zff;nhbo=BRs2rdzNYMipzEGjnh3}tBD%VP*5fc-d*)qsKLM?X`i-30)ecVdlZTKtQ zA|q>+Wuuju2xB{{=1E%Wax-6iWY@jRB89Jd51U{kDK^sja1l1fYJsER-9Xd*XMx2$ zd1t+usODoA@if78fX?Yr{`R2F-tQbFP*m*m&DQM`le7|E|Aid4PvJk!i9S;ALKU^3 z_)2@0$&iL;1dpm|hH?~-PLCyg!g8npO;6zS+if1o`A7;0OlWzsjN8VybHOFM zn8$?wcWg-U`1kGFf+I0g?2TG46hZMutZ+2s!g?7at&Ss(Fgn?YZfCmCM~)3NCrm~V zjII@1#=GO5TW&cPgLA}Q(OYX#W#0gJV|mB7-L}uHZvY4Hcp9513M=v9P#6%v^(nE) z>yLd=R(@w6Gq?s!`8Lx0<>dJlcxHeN8iw;HqNjZ5la}3%^%T49u6SdvuRG0mx|UT}rRthTg*m zhWv^Ij=6tP8gEs(@E$-`U^!ZdK-_*0tH3nRg@XM=(G=!~(k%dP0}!?Lgx=eJp#!7{ zdY+S>P8#(_!Set^wWlFq7SKQ7064zTSGoRmAox*x4{&_uY>`V%%J7fw29X;3m;yA= zW4WUneu}znYm4~$4X!1%^3MYsMxffZve?Z_pmtLWrA@x+=wG}lhj(69;(1S!$N}5h zk=Au0a_JT}6+IKC}RSEWB!eiF%xT5NF6OSFhsk<=9I&&Kwj_mPAt;K zdc{?+kI82tRc@-uPwMEZxde4Zw+76g#Fqz1icQwW5<=gw*U8S8@T}mB zMdu0>QH}teJYDtQOAvKH8jIn%7kV* zNOgXSrs)2uLakuSXslx%Qw>vgZi2jbEi*IPKs)a&KryIFuo&Xh0%GsntP;w&^_<5Tem-Yy|dv{F~-iE`y#=O%97GHVU(wV{Lzp=?x-#5!ja(pNpJR7n|&%6 zN2V^}qJ}w(++Wc>F;^IA2{?;UyL8V-(PhkHaf5McrG(W@1 zX?^kK&_XF2EKWZiBydkZoqo`uAk&S)O+9+*)MLy*nuf;3m{?T~;?^Y?u>S&YN3Sw$ zvbf=#c8#UtIZ3EpWBiOcT+fSG1}e=VGM@N%F;+Nz|2PC zwtDcOYeu%PFZXk!TF0VId_NtO5ot-i@8C@n!EQA=`mIw4>br7q7j0lw8usa@DRS7E z=T2dbKmr+SEIWpodYC4f?pnkh(YXtHV7sm2OIMoPlr?U z-2XJo3BKH7GhFpD_u^2rYBO3KLdId~kXHq?cJE9C$-fL;!gM7JJeOAPobyz+Acvy0 zh(l7C8iDRc=*rOE6&aXs=X&F7hH1C=HH^7amiTnVx?_Rg+j_Ykslqb>2?^<6W7`7z z?&mgt9}?ToaL6D7SPY50t*TtdSl59tU1wEgxJ1#lcvVJE>ucO;}>BgQID zdxlG%%*OuMLqV;o~lcFUYfXVLNnhOy%l4Z;ejUs;Y$_`SFMZ-qxW@$`*9a z4l0I;*nlD-!;e}OX+rqu)dfa{&)CA>nsy4~bLh=QY`Dv8>p;mKs1woc&B{0&wo<7S z%!(U@>DI<_YX-w5IU}SaWZv8ovuV$Q`!E?#s`ZF%JT`q$cU+}9Y8yB?b|JkeG-Y(X z%y2@v!h9j-!%}-)FMkaW9Vst6V3i4RCnS*WU1<)vVO>y^qo^rmP+&-0TH7s?E$I(p zYD-m)YBAX~Pw_B$p`@Vb5XWlp6F)!w5gEE{=xL!TT%3x1>6-2l*I%>v5NYa0&dBC7 zhHJlcH4#C6zRlQ@T-^XZPAlj%{tlN!_K4>{BAohL96Gnuy9=h6Y7XlNp6Mbrz5e}EZ4-6Cgb6PmDncb#0tzsTAI zCSrY4GUAG9n#6Cip%Bi&2}QffJ{9wag!hL7+%F=nd_5!CuZWfmjm}LzEi*$)Pa^f6`=I+OGh+07BFcw( zE>qUgQ<)1~ag%-0HBdExm_do!y2GK74BjKn9MFW(IYdPpl}lkc*fl1hJh{;{VKs?~ zG?P`+aZc<1Vps*ow~=q8oD$E+()h5zZ?^3>d!$UJi>`Gp$J3~&E9?F6z?qDve{B4m z@-&>JP^`eCa=>s=>68c6!&Qzgm}K$L^|Y24D1q$9Hp`$8WZF{JFX`!s@ZC#;ifpQS z3XYR5R{oE7TxC%M6r6ey zLV5QRvi+fgOjeXadE18vEr37h!@`KKMF~7JcW3>TO@ZTX>`>dzdfN_paD8%tyuLH3 zY-b}OTS$R!nnl$uTS2utb%p`UtOSD(X@9fBfr*Y=acPqZjXCsRjc>$4>P{gO* z8wX!6wMJguzjJ1~?(Oq>@87AefjFwlm^DzDH$8Qc%ZmQ^j^ilPpx>jC!-1-QX`qvgprw~LA{4z&U#TKHhA+e2edBR)u zBhG)|d)PqZ+u30N2%TI$#EuMYl>dcBQr^L<-!8)5sY%T`DW}!cX@-S1En>)A#_VjC zeZ#@9!$WM2A)o<9*hPS6{Rutg+n{pCuo1ivrdak6_D;Y05te83PyEmzIIu@P+aEkv zW7XCE78>7kKldfTPrB>pY?~($R+i%f&}3ev+JwNWZn1N7jQ@W^+7GR70h!uOZ0phlA_DqaHM{( zclY_0m_r~qF?!u{*^-$$&s@|bJBaX2wMk!WUtSA6X)1dDEHG5keK8&UJR66Z%{57{ z_;&8*6CJN`3ka?isgAGoSur)<+dKD_?n@v>C^^feo_z1|^CD?kF$P#?Y7{lxEjQNg z)Uc>5$8lJzk*9om$EJcyBWxk9R+2@)HI**2{rMf(Pm@IIwFbi?ga}uWBFga66?XQ~ zIu#Vj&t{A+ZNV`tK9dRlncmX+$%e| zYO)A{pVc0gy`>+?@9~ld%&Xei{(e~aOM;fHKi*roa^_r`=rdu<_}cwOp!IcqtKKRD zLwb?x>!fo9uIK3dcAW~gky4<0Y8lN2Kr{rV_nalH3#O?rj^M|D@X13gmTJk|{|fi# zB%yIBrnhb81PHvpQQ7)vn&#NrJ%x&CLJ~Nc{r@G+Z}5a@&ft%EV{q}02OblcCg3AQ z#4Dr_e{%O<2(A5m(e`P6uF>@((xeZ6Vs+Zz`^H5RZ^)9YNW*YB=e6CxLXxjkrw82T zTd91QE20}mS_gHLwh{4+n*39g7qIk$9)mA#(Lq(srhw05HuUj9vR11k^QY#t$);o< z3O7nOc$_0}Y~!kcXTNOS>YYJ5Ourm_vgTO9P9Ttq{=Xud@$^}sB98bn>qkB;1&5wY zncj3IIChvlR_yOsLfYcBZ220T_5vQvPtX9$0c(~9B0WYD5j-ZH{J$(xG`*Ta?DSKV zm5V^Q0?RAj+02*b$dA^32G3$h0Yh4ULl?P!pTrU!Dgha~Ab<+w(zMaEfzMyyn8(pM zwak7qtGLZ9`}$$P?RZ0}S+xG;vKXQ>&~S+7ya2gKfVx_dln zxL?GI=YPl~E)%*RY`uheCSePlXL-Et+&ojW}$&-CGUI72$2@gIy6~3w#_T$Hs_J4F(%2CeS z9Sc7@m%b$#(DsV4F&U%8mXh|wzisTDtO;f6cbdzH;l}sG`;3;OfuqLnjkT_(L1rT zk?e!lfKTPK{vokF3EU0O3=@!WJ0ijNWPL1)*Ul-tRt?J1_6d>fIx>8Ae9j{h+Aa46 zzL66B+ez1wc;$^P2YEj{&2Z{9wFkFI3bmQnC#ue^-ZF(GjKs#d*X<&_g9u(ICBdKS z&A$#;#hmmgYmoq|hy(VU(HfMw8fA~YZDVedn&W3=u|ro?dOOV>2UZ7Lf4riJza_4g zZHkglLqI*sTg^K$V3(H`)8n!rFXvNFpNp5p0cw)TVf+x31=`fQzqKP7`0&@};Cj!< z4zu2)%-QUvjJUQ3;UT{OGkmLAAA*z;&=r-K$RDZqFDi{BSBpqss%yk<4>#0=FL&&C z4w)HvtpEgE_!}kRIpnjkT>klBpj^(otGs1kyo>?X-NFcAsOWUNHW=x2C|f$WBV#NF zl-iMX%X#Yxo9L6Fo}CPfzhsD(^iSY?2b*t-3*GC$oOzd$%K318^#By`yP2Ew4Q9z8 zi?*K{J!MNT#4D9()bstVFZE6k)e{_>#E(C5Wkvp_7@Uem&V))B>z8)VotKaLK~9L~f`(YXIYYhC=~E z(6H;A#PteePJ`K!HiW6WP58}B*tZF%&x>-><-a-KBv(}|u~#Y;1)jRk3gmzWag|r2 zS$hFa&8dWE8;g#@X=27!4}|A1Z=Wt1wqidT<0!{-B~jBSo7P3WC$;s&=9;?Tn0F?K zB@X_oxh(J*B~uT9Gx_0F>}#9ezI$zn>F8DtUy7Uw_PnY&q801FzBT0TOE#pKX#rkI zIPsI|kAzMK3ro1<1e8lFc?CI25IFOzQz!s`zcRwK;;6_~FLC%@sK7W^zYRiN^K_I4 z{AXYg#taf)&mL^@EldBzGa}0rBQjO|+~VzAxmBj2qUq>gZ5!X%l2qC`@-h#4rcq3* z_Uk9oxPA1W4)JRps}sk9!au@+DR=APUGXJ=FzW$;r>SW)MJI=guACsWB(H=Dhls62 zNh({vmJK@mP$=0j{1~LQg=if#qvU{7JIt7th}$PiT2m5EK(H zW%6W65gavc7V_mi1gK%?r7tIXZ%r=Ql4gD`Luj{x3yFfz@^UwL={$Wr?xlo$ z4y{D(@%E3887aWy6v_cpoPuPGa%?`}Y?e??ylFmbdVHJpPmln?Ss`#ZzCIs0tXX(- zVU)m-Fbmlg>X^Dp-e;u@FE9XfUpFxiR-dDybHpYrfk_4kO8$#-|{W`95HeE8nqd9HV5zh$@kUDoyS-^CyI z|9px$J_Sa5ug$ssWh5E4pPZb`d_Vh~7P)y}{b%;E`dMef`-AQ*o`{nVS%sjvwFESg1n0sz#BWff{B>M6DC(2RAO$z0S09u)9 z)?@M{XIGAo)^pA=gMu=D(*7IEyCKrQV$;Rk1Y-@)ZiwXe)k4AFVjL?*KbtByoQ@(` zAgghsgy$thty|^`cE2E~%8Sw1(+n!q(subQ>g$KC$3~_;(t#xc%&?j9&3uF^tyJW- zP03%=2-M^N_qpM!+AeX0>y{G+8jgZBwi>Yd)Ia5b-JvPU>E7FLMg&w?7O5tBKA$ zB}>%mlq0ArIxi<}?CIrxlCddnL(4Tv&*bly=aSzT34ig;1KB1RS(-Doa9~z$f(s@ zKI&N;-dSIsR8D~FE4HR&6soi|lM^WgFrPmIEXC(R#ytZyZZ=V|(A2Ig^b-5L6sbK3 z2%SHDCTkjf#Y1^@X)&sBp{-SV+_sX>;z_!O6wma@0geZu)Q@@f7Q(JsdodD z|FBtiS;;d*rfT`2UC;PB+Xh+`9k!5cAS`05m1&5%rwG-ecE6tE&0Gf|hmT6?mu09e zEOs>|fh6*?R*q1UMslKeZxk9RIgrD?Ypp-cjAiu_HM@nt(inU&Q>QK=$(i(Xu+${H zymi7?ZsX;pMTiuN1^L=bgi<^;7nj?DS?l#pKfl#%UbJ9E0(#M?0~Rj{7FS#BFOELl zkSv+cJ=XbY6)6^5<>#`QB6=>u7c^~{#p4=l$)^oo;=pp$yOXWfm8i(;kE7U_(Syn9 zpFKyHvW>HNgTO{)TT|?%b$y$*R7i39*_T2oB|&E0tqNmM94r&6Me4n+n}MfUE=0nb ziQgZj)EO;j;v~Mk_3`SN&Wuub4aP=GZuJDZ|l670^jVW;c1cSqb zS&F9wHq?^T_o`d@#+{UZoqpdyya3Y|?|iuEPt6+m#yt^kM3fhiMj&tLnAgp~Lk}}g z&1hOX)!{MPHA}yj$f#_yHGdDzU=U1*t3gy^bx0Nlu<`3|Gtc-zm+w>-Ch?Dg_VI7T5U*-~< z+~cTT-bZr^A2i%CBF){tArLkABYm zS#*E&{q!-RIV zk#>(@b{IjFbvQ!+pUqNLneL82IFQJK&-&s@V3{U-4&Oc3R$ps z`SN72Xq0jPEIQdz*|xF6*>K^&jay7zOfHuDvQ|Oyf!Bw6$Hm-|bc=!G!+#=T> z;UK0|PL>hla(~tw=Icp%w+@^02Uv*!1iMaa2wDMTqW(@3mF8iGJ$XaX--XREI>Qs+ zddnZaT3e_ykZwK14xPTp3@dXy4j&36N`wg&OB5tm4~zN95eurs{Zu5_db4*LE%l`U zOg$H4sd&?bh`DynAUGV`qeLXu4o@Ei4W*IIdX&mtbLHiY(ROrP(J_6Wn5SaYo)~pa zl$Wy6^g8ua4dQ6jC(425YTezXOs);Dy$LmB02U@GRg~=Dt^6>s{whhN?Y z>YlJn2(DoEn;`FS(RlVQ#4{vA0Cg*nNo*x`XO$OW`$`)h?L=o_B6JP=xdg)$$VhFH zasVp_dZA8zV&L>+O?uyRkX~_bd^y0Px{$s8yR|{1}1U=gPeRw{S<%o z#pza0X7m|*%vemurs$T4uBV+@w2j%tfm>K`C~OfYXCH%@MrL@T+zI;&7W?Mc4LLcW z3;x^Qzn3Cv-ny5X3YZ_IX6TejU?I^z(>w*CoK(ZVmNvdiK2{ff13_J}k>!+OJ;nM2 zRD}tU%`PM+>1Tx!^lNwQL0tvz%AS<;cAZ`!Cuav-vZRXJUslm8nXqYwh`s;)6fvW;Ko!cQwNKt#p7DhTp zPfWaq`&?)OCuu&}-Xy>MU+8F2i`Bqwz(K`eF_7M?i}gQ>$NvRBN&q&%c>yZe|ES2U zY5u*$bSZpdWN)`SB;-xf3`~~@P{7H z;8VJzyS6UB;-AH8e22XJ2lM$0ZhalC`WNyv5uubqyohbl9+nr94T{O1c@m^)AU?eu zaFOGD3G9X=aJ>8nTKl)t9|I<$4{0Xi!ew;c{Xgr}CC+08ffHgh=kF_nJlb7WEud{3lqsU#D{iTWKTJ z!^aESSEJT?(;hVm<`t+uIQW|G0%)pJzvNp#2GXCgxP(+yrDW^UNGFzM&LkR?(qNgX zzgMvzEw*P=CSn_(MqQ3RD#+vzn)5Li=_2iQE}>bN?JIP3t;MR%(SGef>a-RAgRx7u z;icS^XgbyBZfH2=YuI;W59znaHZNT51g{z92PzC9MY|@E*&JvgthmzK^^0SW3DMrR z?Y_s7 zc3eyW8Fh413+9DYe-4IIx~U1Y^`}IP{_x{MKz`jMBjCP7J7%kkv=tqd>29_g$X(yk zHsO<|!=2Hf?&cS4aatdo(~j87BWhmjM~atQj*csP&zU1_?1d+7qCO;=ALR!!g?XZd zNaAEG}Of#A&*P75gnCQM}DJEK&mv?4|L9=U~rCQ402e zWbY3tdn8Lm`+7U78fJEDBfJ?V4{)|d?+z%(h`Lzbqak*>4z90*-CctW&gnf#Zn+14 zI(A;p97;tN*YEiQb4g22YIBP5%y->DsTxmEe2V`$+L0zrZ(0I0p>o7LILP)DM=P`s zvS{@!EZz4L%y({yi5n(e63Sb@T=R^VB!?vSu`#QQhNep7$|7SE7vh3eJ)u z8NFnoefxH9&(|94PP>-3hLN;7$nc5J(`nyEN|FxVwj7fuJF{HEzK*KyYc?-GfWQU1aYg zd!O^F?tA}U6%<7;SX0NG->`2WgsQsGh3UH{w#7C~Blo{0lqYTz)U!z}RcXMWdeFe~ z(dKD60!KvWhH%%TOlZRT$op99y(MZ3uMi;yju!R8X$Ef~e(1oYBa~aD0a6$L`*3hK9eNj2J~sZw$-lx5B7-Q0 ztYaiz0V9d{eAQk(E$3%E{}Vzz<=7S`b$vZ~;zlpY(wh%MEXgkvOB`E2#6zyjeuqQL z{ee@aAcR|#E0z*O93Gvx2x^kBeF;~W>at3GTuqQ|Q$zbBYvTtH5Anrbw`#sH1+X+O z+(d`@apbJt)PNrR|2Qe|`;`FY<(~2%{`~Z5jTnjopdr>kJcZAx)r`pi_@@TgBL znKe3$wW7-Ds*NAn;;7v_E4hMY5fGP)HFBpJrYlXdd>l7)X{bSkW`f1l%1ar0n%R8m zUI*GIZD*{bw6vm^gU9HIPiydcK`bpE@OX`TT0#YB0dXq`@66?vWe6Qu<@P;aF`K)F zXv;l&A$K~}uc9UwoMtDJFe{a`0TiD*>#L`o>|R^N8Gn?#%q+0_**yVjKr#m*$gR+? zi_F!JaO*P4nN@qq8=+yYm1mC&1vdd%GYZ_*uW^tGc2zU%zv}DuQK5^{%}nQud8>Q5 z;8xxyy`yuj71sgs9zE|CTGSX)71_(FbGWMkxBI;`S9Z3M@U|oWPmb*J^7r}OQy20@ zI}p|^fd;38+h00UiYdi?3_vWYMM``Y^c7t9Qa7Xev1#@93%An4Iv4A!k@LQvn=xd7 zFG*ilz|Ys&&+GVdl?L{Dp``_zQ^gB%avo_YkvB zGIafM^)rL7tx?k(3@%g}m{`Zx#{K6swFJ>!i|?pH-RYY(+qFO9%IVI*@Nm5UhR&+X z6u}tqLfPU2BUwxOAm8U&Y2<`?*WP9gB%WRkC2y18xoOfoWZzL4Sr zB@*zEvd@-k@WscgUiqzGxjAJYxHQ|60ay(k-GgM#m+9`*%kX@i)G{flU^f4`=Jvjj z+f-ChOa4f!^g391uGN>)-BQ54=IBLf*cZAn^|bVAH-4{QujF-pvAf@}htvU0C_Ygo&!PXL8pv(Bt2=f_bjMI z7`^xiPuM`9W$1-wgwu)QW@cF#wMbIJ=mAtE2Bz&*7mbttEJ`Zf^xnad=hvZD^u4go zP@p)Txh_CDGQmMNiX~GoYjX&_{}%m;e%uFR69{0*t7(-H;vkmaGOMtu+QiX_k&)9# zLkyyC*2~9%5MITD^22+nY-TpgTx5}W3Gvw7Qsw=y_!$)!NnjIR;k17^Mto z#Kj_{mhVa#t>IjsB8HM%uFPnys)3+CzOPt9Kzz9)$+A!KBHpRVcQJ|F@8uE1gG=Tb zmf?Oc+v~&Q)^H^x_>gna;w*G*n`6iY=7dBdaa?{MLE{wgI87Hm>N@sxe=R4g*X6On zZiL9%CqR#vH8u7)!lt57hT;Nn$-@gu>)l(4=8y3z+@`F4SsSH^9N@iU;DE^c$8KBv zVs^^+k1)J2Rl9MRQuS)vCm6W--M!SFMlpXg8S-HG>$aUpq~+AI9dat>=e-(m`;I;n z@X@%D3xSVBP9Ne{?~i>>eotEloL(3`c84SgKNfJD25kIbz@qg3HJ4B7 zg&1rC2m4PB)@*HEU427=YDgWViM;&o)0vzthrFy)xPK~j)C_zPhve&&=6GJstt*|Ow(d^9WPpQocTW9eq@J_3PK8(d$$OkvgF}pc8d4R*pU}&V z{I#coi0B$$amz?Cz1sjvBNj~8Hn6?oz6o{JCdC?|iyf6G zAthY+uhdrijbxqv&n2biPy-sXvhu5VW(1uGUAg5_%b(Jz`^kEIW_s_ZQEWL>T4NzC z?T}v0La+4=Zm=o$J1{(}rvq!H9V=^<8heEUP!D6Fq<{d8PB0JMa zU#Pmy+0=T9N=7gq;)_RUQu4}uhbU1g&eO%g1mwSN_LJG3Ql#DCcnR)0=}iP+Wjx!9 zN*W+kln8C^o6=yzl2x*6_%?H1FeRJdIKq)F2sXvf0Cxxbn)&;k^oC~|^?K!7d>IK% zS^t@(EvCYHc!6%qK&V57RUo;wiB2v($U1$$fmf8_UaK$+1X(3=Rla29s6rHIO;Nvz zB#&dUV+DW9K)z;^|Dn>xRWq#{`|d4c$uH*5$dY_FQY6f5sMXaCXo)Yo=|yLN87v!? zC$;^pN|cAh$7^MEaJ-Xm+UQl>LS0h7S+F*xj6{@c|OPAB*lENGa zF?3bbXgc#RjZY3u8%lP6L6`I`gl8bX^GD97nfjp)-f~Hlr}6Uvb(8Myp;9iUR>lI6|K_c6IIOi+eW%rf2%XkmR*&HiFO|;lNaY(h? zOZ7oc6w2qkWulVY^EU6}!;Kwt{Tjm;Fokj2Ou9|8KIq?cN|p*_3?APUT53RHn1}zsWjZ z{z@Q;fC_XB>HSD?bc%E~53lc8M3c3nB?Vy^<9VYd2`z?1gGjfPe2JxWBv+#-T2EK! ztd3wegnDfXONd%psZ$mC=(Ev5#N-+!M)srOv54y#P6u4OB z4R|tSIf@q&n~yPQ3q*19-ju4IEZ$_8boT(vWbHO=UNcQCr$pOBjAL~?_xpwS4pZ_8 zM-R;*%QySKsj!b9#sHw);peh?5#Y1h(cJ1&ocZn*-lo$LwA!QNl+XVmJK^^UgXq=% zbAD!rvVZ^n#6bJ^rzrRYG3T`(AwXchsQ2F9QeyKR?ZD2CA}je9F;S1l-t(}&JACwu z0S=n}Zv2?HqAH>I=<;u~#Bd4CV*5Hs<#odFr#D`Iy&m;6UGMGQ=-$99sDaC5pl)Mj zSEDSd3ZvVOc~{50mz!I?>u4`MRV?R~XOEBBps`Lan&_yfuj`DcJY1ts?NIQ3K!p@L zfGix*(g9bIHI?3Tf!rj|;ybA+D@j)vU8x++$1)*I=X`Y(RRSOY6$uDHRi*WKwSB*O5l?ZT{QQ&-&Asw=Ui_162uWw;e(|icKQUPCm zb|0aDHKk&E+vsqwx5%Ca*XWebe82zfhN_=}Fp^ttrpBpy`Uc&q6KJBtt5;BF83||(nMZOC5X&{g?K17Ay_}K=&)0Fi zbatxfq{&=6W7?)E8<1nKWCgyeKM#h<(;X}PFd5FPYpUxNg|}^K&5V-qazu!dYi_Ag zRoxyQo@rInIxm|^MRSQWz%#Kdo_WasPCrXM=#LLp(5rI}h+ z@0$HeATn7zvW=igZ}>h%(puM5?Va!VxAGLb&>BQt)5Mn-Cesw-zmdhR-|M7VeaJ?^9{JSw<~R?CvL5r`l%*|?)h*VxQV7-}XR zP?YJ$pVTikb!0;`JV8&4Qra4FQR&QU{pg;SpfZ>BPk+oy1L=RdO1{T>V_v07^=s6# zs=Jye=#n)|tF;C@I2&m4Cd+8e=>FdXq|W{R!;ty!?jr1e~_5@v(S>* z*Z&RgUV73v=J|IoEwFOq@vJ@gG`XgYQ4{5Dus2UjkwX%HV`o9iyy_SnHcTN4J(0?K z6XXOS+~AcQs|25v+(s@=Qq}%8h2|JCFWs`YB%~kz8ANN}3@T^Qnf7ikb#{^|ZUmpd zLvBV<;6ajk|KWWKA+)dLzsErTr>DAq?M=7$=0e=-tpTCv-ALFSBZ6cdJRvKZ9nXcj>Mu2rB#kI%6Ljuxm#Pp!zy8d)hJW(kf{(G zWFmEs+_#%6V#6J5j~$3eesb9iz=2=}0DK%jny3116RPqvK|S(evRYW=2BJ;~CU>0^GYnX46#O;6w${xf@3+?Jbe7_c zS-bN<(uRVbZreYkVusXJzA{q@%NukGp9Wo&W7zhY)H~e{J_-+WH#%)G4(xQ3vw&kaW8f{F<25Lpvn$5fyDiMA z)>d&75Xf%UbF{VnvZ^wUnJP7VWR%B(&|fmn z!wk#IKhwM^$KEDHzRpUCwY7g^rqIq-S;~W`V3T@r z$5-mrX^SwybHhPeq21mpWpni>a1@~26d7+jjmVI+3S~VY`MCx??896#sk1Q!5cE1L zZ~4+jhpLdbrc6>D(fk<2aNAw80Zl_khH)4NqYOK^VnG){em3G3B^<2_rE4~?9=YOI zwyefH6EvFJ#-6~9b0PmZ^GRI`{$Gjhq?VOhP;J!RJCpx2?XWK#{V&nvr4^@jy1VpmrefwpM{FstCouu1O=DEPYTrr>)hP68TEMqE@;MvJ;bYuh z+yItnZ{SkHOs#}U3W-QT1!J3$s{Q^yc<{{RrcY|0_S&&%)X-DnKrBFh=3@M3AAYyS zFa^Kgy5e&#(3zzw&PxhPUJG zIbOMDU;f-Eojzbwt=^o9Hk}%El>Nuiy)~F<6fm~jasGu0uzmRN0`XP*f7zt{PtbFo zHbSt4Z_h#!d{ISzLDQ&~pKd`3Vt3F@C11eZ7I60i9*8!$?F|Zf=y>eKSEBU&wf53; zZQR6cC?q05*lP_(+V3$6zAvxzth1{pnRqxxjg}Vco*Zz|iL>Rr!Wx}6O+!Yb3izan zj7>@NPK#2|cMBD6!|9Aua+s6m-4=XAyw$g93DZUbvq$d(nJ5MuvOIfJClMxhtOy!% zVc)ZH+#!G)FpRegIhBB=Dv?6KZOclf>@~V%6l*#YodR_>cg7S>L{GgycOGq))cCQ> z?O-)y0(n;1^(0}QIdL2|!2dlVp*l$+?DE2AAD2>qS8K>7FB&gkdZ84hjUH;dwei14 zMQ_T?|4g27&>;LduxJ=Q;9q?;Bn3Qt~U=qfhu$L38-&LDR#Y=mf(N4_6SlU zUwqmkfBY4+nIOV-15LU}$fNxHG>H$yh9J-#I1kCTmkT0OtpsdM45-A!KBZAIbo5-+h|-5WVP z2gP>uvkzA1JDu!JcpVkrl8dh}%B_QtSSgZR zB9v0-h@riFQQyTzA~h`z!xDsg4j262G6n?JWaiBI-xhw0V*X|_mh@?RCOF!ae@|-P zvpe#?sP&o6+qAey0f}5NsGE6L62g-6A4J1KA1w4sJvC^cup zqpo2qg$bJvt3g*&Rw|`OW^=ffoQSLZMl~E>vUO^q7gx88f>~ebjqco%~^RImUe`_8T1HrFaFNqy0hAeC}=&k-gx5jnzG(mjnh*;`EYa`*#S$eN* zY8SGWn^50xT^5`lUiqG>?IKDjGu5QrgDDKKvj77%bGJi`D|u@vYz>tO#Ol1=th`35im~xF1&yH0VU*q zrjz<#o;1*($OdI;UtCN-%x&D)UfJCDA*yK9aH5y&P`il{m_ZH(thA+unq3+tRq_iYjw zRYJwOK?FuNXM25~X03Y*T5fqPN4Wej1MuY8Qtr^$)n-nn&ZA5wHKdVccVh{C60IKu zu2(Gu`nm^%e84n07`r8m0X>g>?s;$Q*H(Y}|LkV3gG}11^bA+-;}-%9<2#w1$(i_^ z1E3*fH>TW}*Gjp=MD|1m$oKU;Yow)$;vxsPw^yH^$%&uM!WFAPOnZLR-p9-Vu77%Y}I zYXJ`}=y`3p^3Q(F8^{Aq{L3GbQHpXMQsw~p(nWd`?A|6990@S?E?|D##KGAKdFhkqUH z5#}vt>Hiq*ez~a@#=q^~YQD9e;*)b7n#9js&-?VVis#)?WkGGU0oUNa_Oy2;5Ig_> z7ag7HnaG#zxUR2qAJPc_+virChnv&YrKO`}kszY>v#^Kjc*wTZojT@3yQ`NpfP~|xhV<^4vzc^z+0(ScNuTr3enjriu61$Zi zHe&Q@VMA#3ZZroYu)3`Bwyfj6%+Ys~%wQQM;My`^R>R2A_t@6R6|?GRoil?tLC*qY*Ds%DY|nT0KNlSL_-%N#?ve5GyQLF?Hbp!?-AXMZ$vpy{d{KsM01|B zB?A=9o{HH5Me-XqKv=ME!~3KDOf|cVMaK>b5)-@b_f9CsEyu+3^!*q(;QfD0{W5#| zuav6qdv7^RiGDji9e21Fp86A!po49Mroh#-|0d^6rJw6Vr_^XaD{(izxXl;4&#$k4 zlhZ=&`}@%7X|}O_W=6y6R8shA+UWO;k-Kvha`w~XZfzh;-fIJeCRX5_TSi)ig+a-( z)-rke^Bd#Ote&Gg&9U0Ho2{FR&CR6wvR){Z!rBHI@t%`f2;~KY7yD1 z#aCdhQR^ma@1pRR;JI15S_NJ3>3@s^DzJJM&gVAN*Qsb zbpNuqz7G&m0fg+E@4N2arbuV=WB%8G;A}PBb|M4ijqqBLdt6Bu&*OlN)D?m()E3+t zoZx?%4|Vom3qlsOrE$&=rVYNJyaiskkPgP?Z&^K$_i$o$mG&s?)qp9IBTSb!D>A}A zQ;B!w{|&b_ngJCtj1hPP!g52wJ|q3&ZaA!0g;L6{GO* z4q?&=JqSMG@%@T-JKDFJhy3Ru;OW$IG&Ap@>gm2pNDW>OG5lv0Nw(JxiRRdg8n z{l#ugq-Gy{#hVo$4qB=Qfw+WneQ6={hD6jN+d#0E*HQHVbWsKN;m29mysX&$MDbS> zONAp!JG%AWk{M(@_3D&)mX_$=k&t6Dr5u4VZ0vQy6ATaljoEsA1rpo~QBjl-*jjJ) z83s7;O}5B~7yXBJf{!L6V&^clvYkw`8vP&PM0=gDk&Y&*@fBNf?Y6;hi8KCf=|xpD}xglPblr#8V74OXWQObt?+V!EzbmST7L27=(SiBb-QX?0^i~cEc&U1>qZ>i@35XkAJlCWa zo&rF+`W#Gk*)1d%8{~@z>gbDK@F(9U4KhFS_upRA&Of~U@TEx( zIwWws))msG5U~B(Eqn>|yitcxpB8eA!^q;@Enr|^-G@R5JdnmF?&VEEg7cje)*ED9QD?ouEVg{@Yq~;fj_m3{kmdzF96+)3; z9NW{Cx_o_4R#aNxZWWvnjwDYRQ*Y$D_vtviP|NBJg8~;c^xtqAjf;pbYMfQ%Hlu~E zNG;3{RJ1-_(f12n-+^Df0j!4Ux@M!+f?)1-w;o`^k9IR1T8|r8-oJ63HQpTE3F<8_ zGy~Q_=$~`lT`AA+rMAL^*#PymTwj%p_e1Jxd!sS;M~y}3jQ5vJx>L)7l?Q>SgvhwB z7ik*2SbhIW%~g*H*_qms!_x<$2k4N@cha0WmHHOCOjoWj9JFd)WN`Y_LWteTK9q-$B zmbEV!jVC*EU&I}^V3SBWeAm$%`O$NdPE&P^Ku6l$`$%KFQ97dnUhGZ3uNQ@W|1t?B z8EJE*`+La#c)pgG0TsiI&T~L$rHdg{(YkZur)TAGPI=7@P%r^$;)J<}=bMka@95I~ zIs|jeHO@Aq!mhXMJj#2L#3i9?yUhZd)|=QthmVfWGs~arKj+G{J@c~PkR~i3)ub7D z^xX)Y+YpL2yREDKkII_k@Y>ii=PpwA>B~)`wT{gml%pS*d?8LON*y+9|1x310yo!G z@k>l|{9pE5L-f%=Ls_ET+M6%zwyl;W&Txr=dY46K&zGjpx-GeH+kU*z$v6ot0Z2;( zOY2XT&j=BqB3PjQMKMY1dJ^Y$vyP5EPz|NP(b_+iG@9y7h@fnB=4{)!6ui zS|l$sE{c#ntr)F@bA-#hv^V-Nah;H@jS%a93Tx6V)wWd?yMSPs0n`69NSom1p4Ks4 zJ&4kx5?)R8y)W6|Eu`l`XBs{);u?Pr^mA^YHs?k(!v(TNjumRZNMq}0f?&Q3cdWuB zj8t9g=<~6m%0_`|QG2}ib0C40YaNelpB0=te9u z;$tu2NE|ymH|=d~x4u)Oq$9Fby|`g;>P@uGDVpCsN-h=GY{h3$ZifCPa7Fcoo-Dub zT?&5GAo1oRC^M@f)HTm;5vvu(2)NFBU?HYGTZeS(%05o-+H|O=h_1ogddaDqU>_t4 z0+#WUbyz}JHz3{I57p-=*}^zW6!!QY2h#S4Ixx#_?4xXDXOfWQoq$d-cWpGK}1 zgJMnu!X|-J?R#;V_g;(3q?I40r6E-TUrU<}CDbLfnzcvs7DIL=TgvIg{!$)kVkNlQ zLp5Zbp4b#9-%d5OLT}{=lDmvC31xHeRwhe%W0w|u5^g&~)_*Bt5@Vcs9RD+Lzfa%jNvMY$-%z?NiyrmxU3^+HQLODTF%ocY616^?gMK z0XU$;tHnix^_{o1y*8DI$tL8jci}y`9E;cDi%@WQbfxQ@B3Q0gIv&y( zNE5t=|64|H2IhJN9Q9ib@c+9tmCKv7Qe5q`bzf3rH6b(1^f;+XK|j_^aad}tB0Z81 zM2stTz}>zlbi0o?^-6n{xuN#>q8A>gL&Fgb#r?RWEa(qWLoMI0{maM0Z3l4QAzBuTumrg?XJDN?{gLMKh2PkLq&<%kHfGY-5c zy;KM)F(RfJfl(c7a7lQQLGm)i6ov?|rB>RNq7%r#ax+e}+`*9OeKLrF$Pm*_?w?mo zo`3fAnxj5gADgqex2|Uj6-a$0=zk|9uu55Y#N4Ut@y-{zT?avb8FD)~w~#0zz95p` zgN!Z&@!`%cKK~HPPkfcZ>LOeezzkr~o z9;|?atrwEtU>k|397BN|%x}~UrX*<5AZrJsTOvf+sLed%=Q}7}QmQ$+yM{>Fq(;7$@XM()uye#9BA-j@6*NR0b)K8X}ZtVziDE z$+j{Y+}?74yF>#`r!YyUw|SWEp%gM-%Hs(=1Zi8Cjeub>gO%*OXZRTpKCG~JHp2(2>Ds0w1cptRLInqqj^mb6dWl7k zb?xa;z=61oKAdo@Z9lmvs@<|y$c-?1B)pFTq1!gMTz;7Os98)xe#1pm!^`*$!O*0* z_j3qlTQDhIvL2mn6tJ`fxG>C4V$KXv8l>zG<`f+ca$27zq3p)Wz``yc~qFWL3vZt26);Nh5Fe z_6GgQQpNq<@_L+{M1Ikom71E`qzALvl{9QJNZBE*^5j{NaX3{;$=AXScELn=_il1w zhdtD&c(uk`23IJR6%X+BO+irYK;2ftYUv(7>dqSF?V}fUvU(cp{QJ`cxom3j^y)#! z256gWHjVtj^=qFbKIda{wS4OI3Yz8DhrYCvoZr`5nQ4q*%2{J4^8bYR7o5@? z+ELR~L@BMsZj>)lUji@MAIHK>eSiA%kp4o0ADxPJ%&sBooOAGfzNyRz;s@_iv9`PI z4Y}7iv6FWAwgyB`(VXaCqGQ-wrwM}b_sX|3wGA880d4R@g$IJ6Y%lJp*Z0@(b0R|f12X;Tw);{5SJJ}>AX1rL9QU<)iTL7GEo}(b-8r68;C~rRiZ;4 zf*>Nnu~RLuths73#Lwc)MIz&d*1+9B`IyTuT!UbMUu#d6fFk6_V}XS4fHKaIo zp?SfJi+70swe%unPo@Wa<#h4d%Z{6Mw9exb*B_^=g%povz)G=GTHUK0CSv18u|N-9 ztUNAIlgZU^q;mb;vu7sJ+KrVERTuNYh*TrUA-D0(F->^sf?`gX{oHJ#lEkjodf=iv z3@Hg)kF5}C<#$GjFA!cw4+72-wxo&*^v}AjsN#++#3Z01Z1IFxk~(L7=x17qkBilq z*l3(bR;s5xx5Yg(i$hRvD<8MKg}~0wtZ!=abdlA^nSQd*>1_r6iCx+aqzPX>TsZIj zO5)pOil&D_GenIPL7B?5=!YVB@W$CsTu6wo4V}1?J9BUxCHxCEL7l819CJT^R=>@M zReaOVq;YnO53lZzyR6!-sKB}#Sl~}k*YK|8;EhiM9OIK%AeOQqF_*;$;D)Z&Y%4&~ z|8>%RYkVJ1>Tpc=W4pkk;jJZUy**n?{W+{NC--MXDmHn?qDjn4&8o)1d$%FR*V97d zD2t>6;9X@vbP?s2EZTV;6Xaxs$ay2*!c0$o+YM}^fXILAb5(TY z1aGAtC{)<9nATnkVk)C+M}RFM=;P0`Q;s=GtPYC_B3d@Z;UsS$w#|go%BM&m z%Z*K`=3P>vPz{(n2|LQ*N*^lOWTBDO?X8Qpdr1<8ncT0X) zr-1WYrquydE6P#gSUAAfkdD}VxAP^!!!e2G(m1rKF?;gr)g?{c8d73){e1oVb4^&V6SbPlJBb4lRF}#t)x<_r62w+lMe(S3Su7(C#k2S;7;~!nO z_C>|HYW)SwKI3BaG~TtgU62wNEw|z}H3{Pw2?XZ7WLyY_mOt7;0e*bma#kq(UUIaF zQIC}=KZiQ!Z#SDV`4d#P=-n4}5ybXg$y0ED+!hw^Nr5|-=g&IS+tOV^>S1}~99>&V zc+rGET)wg&r|!T$G0!}POp%Wh?8k0vmnJ+E4oS26>ivVly_`&lQfB-Fbx<1+*I5Kl z76PABClKngcNyOjVXhi;?CeP$D{HFuN*+A1A^&HT!?ABieBm#>W0)H7yjX@E5|Tz; z0vDW+k_g9>ye`eP$A$b2cCF%t$qms9IT3q88Zp^|?{%Hz>{l*>kCgwFztczUU!nO+GW^9B^v2oR32)S8S-cdLc z9dfybN)s3s&cpETQG2z#>#qf#{Ik=7H{8Ct+=66lsBPU z;jHM;(NmSoqsMvR2xWj5<3qxD_ri69i>faJ-o>Q-=i0oN*XtEU*NV-=piP7$k3)Hi z($72;vB3THxvuPXI(NAdzNbfG_{>YfQ3=VnaJ!a;Fk|XXJxpVzx7&w$!dyLo9+Es< z*68%&X?B3n38Rf)3I|pxp8kFt1a{;E_O1+ZyjS@b{I2FH7IF;?Vy{UxJR;3`2hj3cWh9exGNs z`WfC_j*{2wqmnzdx`}U|IUQp12jaR7ZL!6-8IS-06U%#{?g5cgf4&td9`*EE>T>g+`1RXW?VG2 zO#hRJR=Hsvio8Kw68(7)G`7`NIRK7E1hC@V5-**#3wtV&7Yh+qYraQjg#0noG^JOQ z=7yfYD$Va+2TK`U(A=d1#>Z1}!KUpcm(I*ORx>8?_eN#X2+L1kTwP;?q0z4%-{FtB z(2>TLbb6rp+8?lYwKY6az(mJviJR6O8mx*(7;Pn23#E!;dK)kcx1EXu?EXFku4f}$ zNaLn465@`~pz3}mr#Gg*yT)nA7ojGO6#l-8I&OI$FNRw=*IzyI_+9+u!+!GQ5huWE zx)OCeMfuFJN15}Jm!AQG!nf=;byj@`D3ixh!~1*REn(U*rY&s2%ZCcNe24)d{U7k? z7RzohNSbi_MheAf(d7mgai`tA!jS%EHRh&8QhZ2KTv|IL0?{U>$?b1j1xYFx%-MH!kYUA?Psrw

    yvi3--)XgXFh7KRrg`KkLd~ho!ixSDH~~SQzCNAf?1O z>rba4+L~D@L`Mj}kkf9-c30*rOOeDyPy}IuZWv)Vinfa;KZ|UHNyeT?2kKLnzc`P^ z^MAD|GJ6N-Jp*0X4?ADCf$bMi`sS&`y$RJDZk50F9>&Qk0Z4e;f(Yk!%pXVjSFeRT zw^etp-csN&l^OyN5;o_a+3(b7=hf!LdRi{d*8bWJ&KI2Q1LK;qa)OGF+)FKt^87;2 zR^XuBS@Yx?<^UntW3~ohw(X{8;~*x0^#`;yV1#uPxeB*gN*b6!v9_bPEPkp@^b1z? z8S{Ml{ulyi!wwj+U3&`j`z!$X?(}Z7p-xsWc|in;IAIqAqqFg6H1uhuSih3;qdf-S zY-|FLIB|z?azuL8Q=(sr&z9oU301Q`QnKIR!}(N17QkK7Phm-!3)z9z2)K#t@ii?u z4%clE4~W)lqUf>G!WStB(;-zQTPeVDAKS;TG5xDkd*a3-WFb+8HCG=?t7jT2{T?;BSl{Qz19Wt?-qRiS*e4g%9ql~=-@pt{($jRhWb^>Pw; zX+dwrbjz|_a3;5ckE^!?X^w*M2dfE18`8Kcc1N;%a6NK$PtQvOlHm#ex5F2{lrv|k zm)?%HuPvVv!t%uRY%ZunC-!Ws%e0A%^V3QqBC%AY!aEk%L;7CW!VNUZ3Rzt&S~YZ?zAz_wwR zOa{>4GeI?TCdI<7=2@Q2xI5^xTaU)<;}Oip|JVa+4(Qlz6etP=?<(DUS!-z8YN$j_ z-MsjR<7-BNrPk8;r6pId2&%5dbE<8+ZLoB{USLR;5_AOW=eU5ytA`O1F&J_Y%>_XB za+XD0s%N%&+td<*Ql@Ex()|~JxTcG{OIXKu^Cced-v+6nZb~|sN7_cjUWo-uZ(VW& zfkTgNK$9_2_ZvypJU7Oe%3#qOmSZopVMueTjT|M5RXaJvTYP9kjT#17=J+2J zUuq-pkw|0Dp5FfXRvhIj1Pmw);6)fvj3-mXS-3&r0ibF1Z3JAD^tG^qSnjcHwL02$# zI~tj1vpcKC>;8U4L7hP6V@?-cw{N1bl49+m=!}^Pd!BS8HlKVPT!cAvOZg~wfrIBftIKnza&c0=9Hf_|r1BH9J+ z3+jv`+$FuvDi~nkfjkj?ee#Qkm8NP%ca2fPwoa&oh|nPOjy|tB8i=?h_(HJ*WW#c( zkpYry#2aMVUe9q6|EA}5-{K;>Dy{t?P)2*=zd-`V8IR_z!^GBv^F{C!Q*{wSsEc0YoU#3~ zf?Q%7Tpg***pP*jdh~iIO#&6oHYlmAE~fqN>uqX(>J1G>)f))gHvi zO7Xd~(KJ{;)GX)+)fiACkxVYZ-=Qw6bsN-A@F>W=aC8v71dnh_IRXv*mAoh&$z;K) zVyW%0?Q6nDPsaq12YF%9c{Xb!RAz>Q_t5sIy<75MVF_7Ah0%1bxLK zV+N7SH4JisN^>Ps8`|9Omd}V9K#0Z(wG)C6)yuB@@4X{I7$+Mg02O(8ymqwh#GQ`U zGJAI()fp!e*RkrH*%y{SfKF~Mz@VyT+-_pB)?#bzBiv5(=$YITK1YC;S$M_;so?#n z+C6o&PLTqw_!yDdFO^(G!R3iSdxbu!;@ z-ES??G?0+Nok|}*#ml)*;M+t+78&k3G;E|AUu`^puNbQJ4BmJKL2RTpQ9qm9GAAf9 z!`XWmmblnR+f~^~?OYq{nxnDf;(iJuN1n?l6@rJ-8(WJ5;A8^27?48x5UiaPcN(4X z|FH7uzdAvoHPz~%o2*B)u6a$hwr`K7fTjY*U1BKAX1kVqf}5Ud-wc}nhV2KJujk8ZE<A(%i<&^E3G9Z8+J_9|4C%bABdvfsC8|iy6hk8q{z0*}!2}HhcT3uMz zV9CTaZVbiE(XWya20z>K&Z`L!kD9w3R;~ z!YEj_+HZkLW@kk682$SnAFq0H$F1%G!nm3Z-KtF$H>Ir#1CJ}qv&mHLJ2E7sz+qAQ z#zep%rR*pF9-iLOtc{9#^Jru5``GcVJo|6oHmREQzTT+#Sq02)4j{sm5%<~kQ=V(- z90%`APFYXgQ!QQ214@(V*CkDXU-2l#XNzPVbpnkYru!9Jo4NG3Z-Y&*5RHMb{|I8b zu|ml(UKMUuJPT1AQR3jv#&$V-;(?YFumup@khy1H$P8R;Wx z@d0k~G2LpvNW$xC#H+U`iCE@k z6&Dtv46R`6U>uj1C*`TOa=Jc@zi-sfFOzrlE`qyF)oM+T#kv4fX>Hp1u()W^fN$qh zS5gVMLDKfj%<}iH4_q^`f0Pa zW~^j$i8-jbngBG%8&?3h!+t}WB8DF;DaYwdn@{;*(*TM&8yO|EneR6*lWErn&r(fK zTv+wV(%f6Ui&?cZQBm{*L9Bu=Ma8-=aJbjJ_%l?$;F8jpYO#uCLURSWl7Ll#FG9>* zny!Wg0b7BxqseB?!8Mf0+d>RElvv7Z>p2OJW?pw^A&?e;80!z}a|=r-90 z>2C|@8A7s1-Jf_bbK{UYfBywD|2L<{fu31TaYy3HERuyXY>5tZSX;w=oD;JU5%$3R4}kFq9b@2(Fd1%qV8 zjCAUlkzrh@x4C(tSpS;@rSJX=k(NYED~4X3GV--p%!g;6Rftxf#eXE7-i6!tQHZ7T zn@*i4`->;bNaTW&NR4Ly6F?Y>0_NXA#ler|7ccK_lk8{vldHbnBc!Pj6lP@K9~L`w zQ!Ib$QGh1C)SwQ#38L5SRxj#W@ap!~i@+f;D^TMe>Xo93%kq^MHt$o$GX}W;@!C|5 z3Qg)3OD+*yGv;TJ8?3earFcY_z|)2cq& zAI(Pee4nDp_4H{6jP({6fms^mZUV?!hM0iV#tb5weQ;W$9BnTt0oRq9#E`&SBPaX& z(jqI&*6U3MA3u&qvCl9bNV{A=BT4P{ouZk+9A<7X+N|2~Yv8~Pg4PmpkN_Uk_MnXZ zo=iqRoPUfE9YyT4SNmU?`_8s{(G^dMIK)ybTvyM|;PL+Q%>0hK3%>{pGeWf+tnE!4 zZjR}(awbA}PsHqF)l3UAR5_cCPcuSWsD$_(MuU+Ahw{B_FPy$A8T7BB>O|=J@wp?o zWk-H9`VX~1qZv4b@3?W>OLoXl&q$?Ycm;)QKz;e|ZpV`otIi)F5ItQ0GDGO%@FBR% zoxdy}9GF*4svI`>Lss$CE_ot9+3vUU3hi`_>ZKK7GO9sMBh-FXj}7r4LeHH)4-{f( zC$B)`F{44SZ*$&>-^;u5Nf&s)?sYh}458IW(TjjkNf9SC$DmKQr^L#;2Rx<`Cts|N zL_a+ec(ef=5W`_R{SEpzV98Rr`g_>z$4$k{RmVHePnct%IPj%PGgoawNq*?Mqn<@q z+U#h4vOOmAU`d&CI{tAJ{(Ez;iObM&qbLP^8ly_^1t+cSaTtYK-ELwAK)R|jy;-7mk7NHMSoyOg!k`X|cPR;*4?xWK$)J<6Ec zL70_YA1=(ZXj1w-^(d}c=_J4{`Ug2eJ$zGv%GyH-Id&qZNw*zVlU(RBVRL9>&qK|= zJZcnI+zz%wU)wziO&DzLeOK(wbX_LSaA$&Z?KbZZXZkP5oPB<@@LOFi#qo2+^^5`2 zxoQzhU(9*>!90AJ`m#kY zA{@j{I3(O*a`f{u20@NwYE+PZNub0=bqUamZB|c8+`w(>e49t%Zon$aHC|eC$a|5Y z1BYRz>z)|7dFjZb$=9V64i?Czata7;TQw@RMfIlMgAc%B#tcwk^gHGbOCvMpu*zi@ z(-mfu%eGpj1C;5=3udRPwAkC|XU;U0%R#SyOxD|F>{2{mjhV`afd#o@OO+NsR+xg( zd?jPn3(_Tl85_*1ssV5M*PM`-(r5zf=q^tx=M>#t5Tic+;_OxoZsqRB)ZB0W{i?_y~la z3P`UxESe^HR8m)oOJS1f!25edUoCJ^$0UvwrszAS*b;EenGG zYOc+;iup{IfqhD#Kxkcl=d9k1A_Oqebnd5GKSoS5&RKMJfS_y{%m?9j#wS#gpU#!2 z@}-MLATFV11(V$u^*%y&S5zQ?6UQF8He(0Qg3Qg((1&$i{Z_D2-exZ!M+B8>v?}qf z9oM{4w3?^i9nm2p&0nllcnYEeR29=%N*b{Vb%?emZ8bhaZ}$Jo(%Nd9pPS-6g;>56 z^B+I1-#ZBoCVi{o!>~bn2NWZQIlTbH1GIBqXh2J{SfV;5K&w2Sa4^~LwqgHWj@{~I zYncqB=i3f4;G)X``4=(|XK@~YOr!D}>LjpN?3?;^5Rb^|vO((U8OkVYf3@$>Ks+Df zAc&BI^72%@e@Zp=6~pvV0xCvEuZqGUqR`dJ)jSdB)swJ z;a}^oq6CYI`fei<=jE@XD3VHELmA~!5fQww$LiAvVXR13Kk!sIgqN>>yp%A{2_1qW z)n*IdZJD63KW+{$U<%%ho(y+0@qn&@O9`lT<~jT>Kc5jyMYciDEWO~^{8cdJu-KaE=0p0n4HrX?EzCUP5i#j#C8c^c&0}djzr>Tj z7ytH&7wCXN#=EM{18IyK5BZ%S3EvG0jY(p~HYXm%8alb%lP(amM!%GgVvzRTn2rrp zqAX7qPni?c!Kh{8zBI_SmM5P%w-tQs5E~gN$zp;V1{plYrnH2UfXk)n((_sE7LDU3 zBE#eJI?K>qZ&nWtscSvraiuQdoSYvxaUi8}9@UJNhqQu7c+-i~vxx3(3^G9keJ2^j zr=qhLjS{Hrx-ij2;`tn!y*8Nj9&smMBDWbLgO1s}$!kr%z@~BD5ABALr#R=!Hhxm!s| zFOT5=ai&w8Y%g-ZLWF{A3YvX90iOuA_MM@P?g?!#7ZPc{3>djCE6%kF$#~h%d3i!~ z!|^KS(ocrK4z>vdI(m zd`-nhR4SH_=0EdxyhV@?F+zg$v~=kD7PuV%7p%2Ow1^zQNGUETlV{w5#%wN1>jS8s zKH6N?ytp`=gfTRB>q%{kR49HLNFgJ7pgC~F_q$5~Rp$t(`+6DXB!C;?uV!NW*6#x- z-%nBQo5C_L3P!JQ%^!p|WY~IYTamy;pq*GSdZy7s4ES#2^Qqo;r{v=*u%=L~)r_4h z?;TxzF#U{Af~4W+<+*-;57^wk&w86PMbrSz`|zh?Y<8*#q$m4(2gLRH+RDf0R@h># zT_`rAEzZ@SeO6N_YN?=d5!SDlq-<{fPS+eoj3|6z^Qb91F9)%HJgc_+VuXrHfA|x? zAvX|(nzQz-0 z>sdH)Vd!4(bI@2hNlR=U6>=CaH{$^I{t29nd^v2S;LS^QSpWgg7AzA-nUxrzqSw0! zSa`1G$p2ORFK|3%?JvFck*imyHR4Qy8RugX3jIgJC z>ix3W)9k*UB_IQ?AcGg5-xz?aQ#7v91S8;NVm3CCT(ab+u~fbHd7bPbRACz6cSi#^ zVu6eA^C^3|NOLOOrMw{PO<^1KX(#R5ZTd8Csr>5K8EY*La1^@3?;+G}Lc6rqsX;Q$wnUnA zp8i7dh(w|=Pq9e+IgU(eEu$ogFm93;f*tMqx=x_05MNXuwEr*fJb>3vfa1-=+h^iC zBnE*j!Vyu+@s(nsOxWt_aBC|-H7gw?rEa~U*Q9iVV~nJ}yiNDd(8Ku1n)3*_lXr8S zfr*^-zEw69k|HOr@avgANb~@3Zexmdn&Gg3vsEaYT*1lTV$rU0n)V>a z#xn@b6=f`T8g6n|*Ydwsie)u|!M8`HEoC?0jt#Lg==a1;%6aaT;r61b#p zf>j$ZH-04D=4iF(PHbpxiU=PrU`N01Q?-!(%-I*^FMt^2fi4Q^LO>wN^=Zt`a;{=E zd8eLa!9GQY{IkGo)f?G-8Ptzp;wgbpBgR#@Px#a7kUE{{ktGevhvuP0f;i#;XV_%} zDO5#Pb6n4$PJ4Ap^E;24t%(V+Tz46l*X^A$AU+NJCbXgzak0U|9I?Al$BkW7<7JhE zqm67SO;yQH(y>M9cNn!M3bg|#z=3n8yx3(U|DhAprG2m1{ZaR>%_4{iA~Tw+epe)J zM@MyR>1Eg>mNKhSGBMzb9g5hU&X2Tb?6JclLQ>g=)`N5m4z%_~gV7m^OyW{p_2zE2 zuNn=;Gw;|ZvM}Ot8=zMMeYjia>BC9yz&~D5r12{3=K;PGi&O6j(r9js=t23}4LQxE z#mQ$pDj*+16wIy$W=JGJ4jJJ`oSB3CXQ99Ed@|7NRZ2uFepj;#5%4FT#C3@D`|&z08XmS1x0;RntY!pl>P9q?P8^(hj6#wuKW z?dp=UA1H^GKwVGqC)Mn}l2Wu2U5asW=mf;Nju6%!9fvuUv!fsP2r!*<07o5D3jahj z;r|4u6rjM$ZYXu|b03#D>~W;5SBS$RoD*?Eyv7dMYJqZCuE+~M()jP=dW8LN56m9Y z5JiAv#xZ6ODRLj(=t2d*hq-92FqG2v7%P)=@16uY-zsntvsk!MPLXTIceFtEzpA{^ zd!SY$#iwC7tBb#MoP1|y7HHn{TQx->y_zb71yNM+reM|27jI55pRr+GS^IP*^kIcl z6f}cUQdQ!&wc5M?)O%y|TY}^l4W~T-u?2C_>5PiVHHI=5&L(h!K0(MJZ4?~!=Y%S8 zSCON!{M9b7!1PlIY?<1&7?AG!L%-QvibaOK2UigEZM*$ewK^xsc_j~?4GpO(*%ycF z4+jrWFZwCf`ee7&az=f4*2*K7SubLt&IHMGek9lL#05j>>4ITC1#CYZ*Czrn3~;1o zEq>I=H1nGQ^UW^I+ln|b^eVJ5I6=sSdCSi=XBh#`6$w-6*M%70I!{=)>CZ&TTtL(s z{60gQAf8*OH*v|b?KgA5Z?%oIi(y!7<<-N>SYDyReL=_$ThIkbI_61d~r zQAWf!K5*C8wjTY=9A)fr2G9&Tpk)KTPpPLr08Nqw=g$;D!$M=fC}Xdq;_wQj+rEoB z&E=_DBVhAxV}V7QW(pxfh=T)S=Fs0D>7UZu?9iM?tuvv00RCz%aA>Ea?^Vh$KpMCR z^_&G%<-mq-E}vhVXoD<5G_<`DzaHX0$;oV&V>q3&+cu(5Y$u1>6d6pli*Dqq(6PmW!oG2)!r?kKqdFhcPVQwLzn<%Y|eNMP7D z)m_@cQ-o*hSc5ActEc9^=UqV~Buk{iWR*_5LJm}#`Bzo}YVrfZ;X@4KwgNtmj-Zal zDYnBIXeG<0tnC$(O0r4m~Tktiv2VD)cc^M?Qks=jay6!rY-eX1ZWa7kf&9|`E)gcBw&Lcslo((&vt|3D^3O* zo9`MyY_ao>#lUS-FrQ>&%Uk^SZJmwn2TtTLFOJ5TMBEKGL%4wLz*k4!u(5q~N0+?c z0qa;J@#)!8So8qyv$37~`eY%tpPLbz7O5X}rpv|(9`1rG{$P9h@AMF8k8KB!$7%R+7K#F<1m1NL6+NYDnG^RsYT3me<+n18PT+1Tt})@h2WN=jseU}VJq z`ifYDg}3__VQWhh>?+_Mf871bR+o(}-+hdaGXwrimspkbmzyO1>CZeu@VH}7&eBUQ z)c1nVB-`D4Um1=AUw#-NIl@hNh=qb*Zt~(!Hz7mU|2aI##gqeZhbLdDN!ae5(X;Tp zjU>Xy;2&??_$mcqyK93S*n*G&;2{98o@XM)&JurhWylu2Ac{jr!U&=;N(5O;yYv3^ zAT6LnR7*c^R*tCJkHQsjpi{ozVVMUK!Q#j{XKX)<1GSKp?cv-HF&coBDbSB24%yYP ztY96onlcuDl`uja7ZH0tBJxN6^A_OSub+6|$gH4xorW0Q5s$-VM?QbOu3zwoS8ezm zdpK1J2RRi%(5ZFW0hj&xBIwj7+F1I{fp|3tB$GoSa1C3+*RM5M2PscXy=D0fHWagt z90zd*xhmz)_e$dT9sq3u6mQuA@%R-e8pHvjVqvPP!=En6EhxKCXrcy;AD2kKSBM%B zh--SUn(#-O@NW(^B{pf1f8|P1JJLkBhy_2|vwzp z?Sll;y-(-g*E{VV_;C0A$Dgf;0neFtLozGEGs!t~dV1}})9JaW{eF5Z=El|NsT^$3 zbhho`3}bYG*JLfbJm+!raA*Z{a~{u6LMG>j?=z=Q_X`q!!q};OgS-*^$M?_A{uzUR z*1xgD(N$pKsxxZ{eSB;h%5epL*e+n(3dq@t@lHAN=4S z4CVjLobY38Slvw*AdY*S-HPgDB}F6^x#`F_6YACb-<{=^wI0cIB*y%oAD-Db!pZit z!G4|9XO4%gpJ_^+*}*n>txj*br~2=IEti!!X$7(ov$JYFszq8cSCu;8Y@rvzq_KHA z>A!FN=f8J#4E^N=3bZf!i>TrDp}^3KZ{6H zTY6Og6Y?P4w+?}+{*A*qnRC(bWF&#FpDZ|*=63JUo^lFxB5NX9|Pb0`xo#r zB`2GqeS(ec9j<06s_y3I`4en+oe%xZCBLX&(b~;+!)fo=<7Ro<$3%Pw+aJ?h_7Y)$ zMLS%6o)dp7T`)Qz?fgDum?;%J;T^I|0J$sjDCG$gpsm62r#A_h$8Nu==2{{0KZP<6 zv;D5hgh@0B90MTQGh?BuA`Q^;JS9s^H<|pG^AMc)c>9uHdb$Ij?O}Vt_|q+}M{C8v zNa(#zEZ2l*@x+|d6K}erb!PontMA$FVh`!N&(B6wKi$K|Hdne}N$OSok2mpwaaQ$Z zWBW|r-;Cl8Uu?L;##XNN)yw|dCDKQgkFwn@J^3GV;#Bo5%&F$1zxI`peB=W|?N&3WvX zsbV8`D)t#?UFAmxi{obPpR*YELxcMFJHo6EDQfPM*>fAvau08{@20a zocWv8iL6Liy|k;dvk^-5@V2pkdfP8k^@otII!OTLzg+XHIXBq9J=JW6!SFHt1c8OV z@6R6yolIWiMOKbEJAW@S|9^gyEc*Z1KG~XUb5&J~vP+~(5Tx(Mzzn}N|Ay_)t3*fI%YxvuQ#qkjggzaGN~&Ic zde3AiPP<-Q=~?yRcf#cUr$;kucg}Z{cHE_e_%z)-&qVf0*{}CX4T!O4DIABadnJ?; ztW8+O;SB|c&t%!Q!LfAIkhR`A<9?Nyhdtao!$@^_>cH8OR zGTIR)(Y&(qF}r2IaBx&Rk)LF#rBCaSvs~r3woSXaaL(p@K zZp@T(Zn0ojQDf0Jhpcau>cs4@yZkqaL5rpk!BbWlb|AwDxbeXCzX@EzWpr9SrO{`P za)NIdY~F>(&Jx%}ME-|d0naN)Xwiw$in-VG+n1>=GJK3ef@Z|m;po2?nlJld>tk=P z_@&BKj*UjBM&sB$P^qbj#}qt<95iQJm^W{ca1?*b8=eaTEgv@LVEwq_1;-6}NM)X#Z=*CqDq`Iy793hFDu{=*t8C>@hmbh&3hzc*B2;DB zyM`j`YF1h%8&_rb>}Ewp^!vZHcx1QnJaDVwM36$cM{Durp|&yI-HdV`jkzORC){(w~&QWk2#NSl4LOb8k=X|kp-@M#inx(cQ&Y4-2 z5wnKm!z97K$Z)zz+-5QT>;1CW2)&7h;)IloM>KWY`(X+`>z4L@{2?~F`cs-(y9fUY zM|+9i=y1xL@Cp9>`E+6(@>5%ur=)y}h3e4whu+rJ;#Dt?1-Fwg2HclsxSEM zbOx$q#I{4#!xKIJ;c$qOBT+D{t$t;)-c^D}aQ}*e&qj(ve&ktnMyZ~>Aw(yE#N?(Y z{Rvzs(S`M*B-&S<)N;h+* zo|zgeN+?MwNl0i1)s+nWZrtz%>{gpkN0SJ-o8?r%j@BF z{%*$J`LlnMpKNE(X1{3Jkbex9h^mrN`WF*(C84TRv2W?1A#}{ ziImc`mU>Q3&0toRTjn+TqZ2PR<74#RFv2Yn-Z%5{SZko2l8@Xqftl;Zdz*I}*Cbr0;H6@B`c8i5tGk39alLE&ZK=!!_6Eq-0uC*mp+k z7v!Z?uPom0vrke^NLe>1WQvam;e4lgUY_k=pL}`dbk4Q?=~kgUl{b0(p12=7fWBL| zZ(iVU#zdIliBmpo?W|#uBK)(OMFqJJy|GS78FU-3w+ou9SXfMO-1k{>D}gU4%%>h} zPNEUeo9n2pm(vR|9=XFZ#3EIjsKk-1dR$FV|1p2}R+Ho#d>CV`v zIkm{xsEH>2Hbv_4eAT&gsTQR-%Ux90Vn2%=wm!3`pvCK7HZEv|0IvpoSNnX$+W10# zVYKS$VBrZ=wEvR;)D71XZ1Qzcu3y9LTUakU7CMuU^FP+_{ym4&M9hLiHpZRt2knY{ zN4NOp@15EB6_2C!s4PCdH=*XH7!hHX2ef_{qQ`>@1>`r zSXL<8GGi6!SEZ? zpNXyHAs&Nl=ycqy^UT!m0ZQVNtDW|&{q{7{t!Xe2+`^0H^2WD`)1P5 zPB$WF(|KLWoJ^~*!eA;kPx$$|He3(#%6-&q(ZX_W*TmkcSH9RK>r!b@_9;@AAe?4(x|yb)>-kkFo&oV*s0BxDX*m=fd0hKgwJ9 zV0THekg^`m7&yK@IH*#qsd`)HG_m+4Hm#$mQCm;$?UX}0g>lJZYw2)D+8L{cJ?=j5 zRFxCl&xl#9)r^!eV%iLYW}m#4c{;P_kWDjP#FU>w=A_4HGD7g}vlW}D3BtECl;@55 zoYSo9zFENkFXp1HYinRTBz&js#(5qPvyYTLStpIxJyoyesfki83w%}3;cRL_?vHl3 zQIhx4QGs#kZSpxUtHCIriMfR_3f6y!_=c){!QX1e$KB`m_+Q|ArpLS75>N6%;bTm8 zO^nAD+;TSiymwhSL3@9?0iLEy%OP(CpDL4fOk*#yW!SyFu1}vCb9zRrXa7SaOHfB+ zXroc5!@_s-VWL@>pj`_sV-bINM4C`T1$HLfvkJ=5wqM39yb-{X1rq1 zXa5Hy)ux4l%fqg;SfR(}jwP{rQ$Duh90!BuW>!}V?4%PDs!&bj!~)-*DpG9FRIbACp_K8W-)UKYCF<@E6_>R-&lzjk3=<5Fov>t#B0-{I?a9>**dRoW^=rUNRRZqh`V`= z?RJIR3ZmJ4(+p}|^|H5r@$jBZEE_&J3 zEh2lo(}mV1bKXT8xz_Mg>)|hhE=F82?!NBM7vA)KM17Fcf?Vdd;Qh|x>^hH_K}^C4 z(x-(dLDJ8rIFt`#xK#|F2@|B`8wE6^FIIA7MLopCNp`aurVD;u;!P0E71Y7ubk*lJ zFns>ya|c^THQZ@@(mpp$%yTcUPAF8PbxLAC{U{YE&9C@u>PP7cjcdk_vo{a(=I7}w zM+;jGiFGXOF?{tuqYij^$U#kXwZ;cBRF-l2$rnD|3J$TG3Ld7mlu7bnZkHHox21(k z$fH(K%!PFW4OI2~aFXqnsHm358sxSulD|$&+1qSil~JawMAuZA+%L}D)%`mHHfCFd zlsLE_G!2wZrMot`E6Jr?TrVqCON$jPns|xb>`1$?)R1o=!S~|k8`otU)*nq*l0NH7 zqf2`AQY%yO4nvV+qZ&cj+Nbh6kCv&Yr}6n3D^Q+66#mU(#C9V-RH9GM+ab%*_DA!k zGvYq&NX+$i!d6_?n=2p=;IrorT34{Bn1cbUJzec|i#e2}(j6xoPoZV*>(|Elr2CW- z-fh+mJSgE#S@u~rIdk}6b+4;IfgJA!a~ZYO5M3=_W&PQnl`u2m()L($0^8n_+fUaX zKQ2vtocE(o`?!H)aWPNT@$i7NJ0$)m#HQk2T1zGDtch>0B=+rtH501|6FRgRDKwRbrAsroeLk^W9C!qtqtx zWJRs5^jbGj7mpE5r^yK2*eeRa$Mlr)8^-J(S$0U@XFT<=$62 zt{Pt(HQ4?^wQMYrjr(Nf(?fp`>8(3INh;Bg*=Mw#rq&c9ifEXZg}IxH ztgiZ#kw3q@Tz>%fW}D~9V&@NvX9*=tQf9-)^5}n+^lk1nR!k?Jkx2MOjaFk;3ch?mW*FpR&kiQ_S%lTVA!ghK)fcIUywlLGM#k%b$~^($#Sb@ z#w*!xCbn67%lVtk{#0ERD7BdvW7Fqxs>~y``F@g^lR~F#XJxabynIU8d5_=9V&5d< zBRvwit=$XUlO7HH#uok^`M1B^P!XI>+oxGQ%qLS&GHYUHtNp-ZbTVb-mY9#&fl6K< z>w(uQzb474Qz|=9u5;@K6#q#Ka{)8qy?)zkRFt1JcgWhE@vSt)FWczNXW<6h8pUfz zmHg2pz9M6#^c3DbE}=JuJd?7QZAN)7N%sZnK*c3ZwF#8>>&>O@7?$a35q7 zEm^q2bI3Yz&RJ#xxu-*#t}N%k`iE@l-3rNz-c<#xmF0rX1`MlHH1 zwPMkdacNP)DE5;Kfb1e>cTOSj@L!bjRfdo8Pv^f6lUSb9*UG$!S2!PQu`kov784vU zp+fIFF-&`^$U(C#qbn!G4Ni_Gij`G&_BOSY3cH(}=^6YIN~XnEsog;ro>9+B-=-lS37!wwwp`y52qM-k3+g89!ry7Z24|4JPaBz#V z?vbiByIPOc+^0>h@k<-Z6#pFjd?yt?gw3U=K9ben`}!D+XEd5|mMuGKo_;Y>!-)8M zd}P*{$ND~!oTMyAPP{VVHX;;-l3txz`j9>F%UOD+piVN8mQpVNZRm!C)5A>(-r1BE zN8T3~mP0Yp7F$2!%Cy}UW>Ft}8u?m?!`zgz>$5V4l$5&c$`X~Uhv|X7be>2eA@8b0 zse{LACU;bv)31jcG>+dc)G~Nta!f$zR^D`)nlr~U`A`c7n)W#6My*@NFV3$hN`+PZ z7E}Ii5y)@?12$hL};?@)nlgC>vY-dlS;Sk-7+is~l^sn5h{+soHKs%)Lw3ct0lSj={ zt~fZ}n*ZpEOLPfB*f_(R^B&?)ady?4;79p9TP}Sz-e>=6=wcLh zVz*fW)q&)y_ncwD+x{3&%uVo5tQ%C>py|61J~61*Y2T&Ioa~db_lB3g_V=i+Wtt|u zx7S<2;3xYi;=WOd9@fATT*rnZr=>eQ zb+X3ytPd|difU6l&VSViss>YzYOQNY!h{(9b3Wyn&W^c*bXyYpM5KD~U~>Xer_>qt zC@0*>em?x6!4{Q-Vy^9rE6z((dvj-kkj=$8%DM)qf(P1~whPWYQ%5(MQxFbXf z=fvjiLX^ck{jttrbv5q|7)zX;<y43YTK*S%|~vr(Z1bDs>DCWDcY zoaC0&^qX$>)TwLpFEwl^$^BEgvbC&A01Zfr6Vj;0b>SS(pDy#@DmTcN#|#3PUPr5A z=HW=oOZgc0%HJD_hrPC1?|F>r44~Jmf;Fdv#0i@;{CqNhOSOJoP0MGZG$!yqmrj3I zVRD+nRYf>~ zV)4tK&t!w{ToBu6fnZ;N|9xwypnZ1pa8U00Mase)mRcsleXv?Tx0uLc%=CBZz6)|{ zz*}KhS*QSJtcQFX@whN6miThqqBTV`nPB1I!81r)Q^bvou0~}|Tp>DIrcIrSp^{d# zut#(Qr6(xq1WvE>I7ziuW(FdaNBtB@uYFqbcX)OS_bSL*7}cxim9L*?y`O5(GV zCnM;$6T3El7>QLqcA9+Y_WP_#pOI|StFLa`*djR9hMtGMzt(tjwHa&R&KCOD_G zyna;SUE+-U4ChYv&9ZXQ2pV3BIDJi+gjQ{iHm#0PO)oKsIg2t5I+a5`9BYxEBbIT= zM{cnAkwxnU(|eEZ8>apbjnQ@I7lM-WWNvF4TaE5nHK_vI zWmji(>@|B%^Xh8t(_N?H`3FBOHO^~mWv(=~@}5w~Fz)9+ty~I`*2%wi8G*z%%o3)5 z4PS|IAKT1IXLL)U8iT_mf|Izs`~^yvV|-ARwoSmcP<^`14+vI6+0+BwJf|=#5 z_`d4f*cOXUcEw**p^l5>@lo2KMVtwI)~_lsVwONid|Nd4I8c`?Z2vx*_$BWu@#A2Z zMZeAVW9`C*y)%~bvU11}?y8KDl=oa|+}Krsi%{{F@^#6UdNc6uCO@jsTF`jrwODZW zJ&J7Qz>a~#WX-U;zk)yIp*xciAbUL~p|3x!#l;^F=Qa4wKhN&SHr{o^&wji!b`c*q zulT8`s$;o(NL0YZG_jH|GmkyEgW*u>=+&dk8V?o%Mkh=hA%Azphx&;8 z9e1VBG;K8T7~0!vtha$vLGoNGD%zl${s3Rr6EaXn_C~D{f;(g5E?(@n9Gp9Ba_qSY zLELWaajf>S=N?v;gTg~8`)^#V@elvYyye>5Tl4!g(JTU+=-Ata#O;bSUrLBjsJqkO zB}B)F5PaFCkF?{n*uME+{|0CLKiF%C#`Tz&I^NF5EBUZ_+E+qZ68OuiVG_cV@;nl` z6U2*a_9Q;Gxwr-WSAR=iDACjkIS2}KtJ2x#u;{GFdLKJ=Et|1`MLVy-*V@jGfpYkr zf0%KR!~QZwM=-B@w6lbd|MJK12|aAiNgiaN50flU!b7~WU9MwKsMlU3tZVj>_I$?f zW4xl#u57p5uYJ{WH#^(%jS%5y#vyCNFiuLD4BpCsl_m2lN_=MBj};eXQzV^G6T6Jb zt{8+K)4+1$%SRpp?SZR<73rAv{;ki#@gBh$H!WEO-n}G_&tiYaJMsNl`KTQx?SSgy z(9pVS=Jj`;)|;>aw6o?so8s=}LK7#o1#6*Apyu->@mRE7hx3+C?Zl01bifj78nG2~ zN%B9L$|42hCHvYnl?#4#yE$3A>J`Q2YVg1JK9PyCJS(J}uuD?jW1+OltD3x9If14d zCc$p&cWbTViZI&_qB@WT^5g#lS)79gfBaHzV~7v#U~*Wtaj20zzaHMxr1hd+&rj10+C5 zLP$t{H@4s3`}lm@zQ^(Y`5upda+u`vx$bpc=XIXveJ4MPmj4f(Q>?XTNO0Rqrb8$@ zwlx@*Vteo-yVqCwQ){?6@w^2hsV{Ia~nOQHMBZsgYL_T)qa=b(JvsCQ%VPIIEx z%32H@W(-EChA6_G|FbXFWc7l_S6R%?Hy> z8BVskZG1xyw6x7muP07S3Pv7qBP74%M&#c*Y}KlbWPl9&9wt8s#s@u!=-8NNUAUt4 z!OIB#4JoMaUsfP*e17l|tEB$tUmdy=SoF_iDvQiVwn#Nc7YO)>Ns=4xIemBCrP>J) zVRZfpRhtyU&AHaujtg+5dN;4NP{L+PqOy!ZH@hXs#c!LyMiDio-hbW-+~)CuZY|N# zEhihR=UZ0_OdBinwzpJkiWJ5~KRU-ot)@>ZlioB?gxAI+SRcC8TE{0{c$y|nf+Zzy8W%hRrS2tD z0ax@TEy-)f&f~{m=2!nF)r;85b_XGXSrix>I~&wE75l5N8k$st&HcE_kcCjj;2EP2 zwK5--drp<`OoHx^5I!t{(zLsk>Fe1l2+5B3hG~m;3{8emA9SpU=})V|ovYYgyE7j? z4ff+Le*(M#lO(I}{$>KdeID-P!;Fj26$pmOoYJbml!;ZcTr6aUs+|gS9yLTtpVUT1 zdFP%18@}6Px$*-nrZ@Xpd%_Wsw=xsD;ER>Ck;i|~d@~vL-Tz|teP(%NCuJrGr)BU| zo*2fVFIXd|(|UJH6~~{8TLo$(1E=AnsC!#vlRQbS;Zm{6w6U<5;{{?z)$U$kHYlMt z)cOrR6Cc3ud^Ow4{}1@ukivS0)YIyI@Vzi?WV~UZWXENGlcX3^qfgzE&=_xrb7CD* zporo87Gd{SGu!?gt*X|p*xJUzxx30q_ZW*ckc(EG)W@p5kB#B$qNmhQe zmOBSd9Q?n|UNJsD=T+JQcr9Q)eDhEX_1F19xW#dpu5}=6#7?i^y0LRk`fq2&I<7aC z2ENGcsu1sZ^V>f(Soqm^^CWRMu$U92k3F)J_y2znJ~0l)U)|qt53gbWBuLQp=urhr_1p>(y%K$8$C>0q#&2 z8&Em`jmCfe_M!r~8)sNrRymSce-j7D4rtX&7ZLT&y{AId!k0t2vs(dw;vga34T)H0 zVD2tiUP=LZjajfqPYx!=xA*X5OG)L-DgWM4M)t`Q(n4KMi_PD046<1+I!)QA^qpDlt1UBgR_o`?Rlj%N;VzXLvKqRfav|7DDpEL@ z&TqfDi$M_^m{Z9`6X};%zeV9!NLnLvU8Cyo8E~WmO2x-Q(nF~1u^W0=Oo@Oe?d>wtQP9tunyndiU+Z-a7DG{=|hl3o#9ru>$+gp;ie zJFHT#b*e9})JRA98>5VR4MYO()Jm+kgjJ65^lrERJ>_z4lD9~a-DYjje#q=S8&qD~ zbPD?Jv!)NZ=Q;&cZ$ecLCKL8z?+oeVLPz1Bzz4-;18_-9!%IoW7-Xp%&|j#VpM zMh}u~JeX>WrlR~MU?TYqJ`ERH6Tv1$g8y&0F>O~g<0M^B(T5rEk02BDV_T4Q5%BLU zEWnKxwDP=R71pKCCE^Ko*iCp@0IAZ&pW|e(t}rOQTnomt#R@-T?aUG!ZLZCp5U@Se z-_^UuT<92M?w^-IlyA4B_;-bi2)=Lycc1(`>vZ0b?ffl#7e=( z2E$caCk{TPc{aIFm@Gxeh#NKXuJE(RuMkWTkTNh>t@rj~U#J zIx>~5*aS}_Ft=n~_j_fsT!XxnBQp*PTrb5mzhw!FB)5x61v)bDoY0G|Cr5qXI^_L~ zp_IM;n?d`N{oU{Z+*bIVEwXtfpYP}ed>KBs%h5iK-m?ID_dQRj*(WtLZ||eZ^u*WM zX82PBpSdIHv6Z!2XgRyR(h5Qv_waX>(#tId{N82-+J#2FY^Nzmv^y^(-C9y>efJZE z&S(riCtvuvm0e6jxz<)Z#k&16?zXxu_tWxn0)4M-n9agiW?Txa3hmD+*VmcF>!Q|r z78Vw^=tt$$t!(eSOnPL1TDMtsnZo>NV6(Jzi7bzcT3zj^{M~L*jsJ*WTwK;h-Yg{z zG$O0MukxS2^MVH(Rz+1+%69Cbj1?407}50ut)jH~U@3d+OR#uyz~Vb+(PlGcJF8dr zGM#mV6gfyG`Owsxj;_=S(VwYLfn4t>J`>B+b(`e9a6NS z5E0&vF&dF6#fe*+CX)wIc3Fsrtj^??Yz&3PG+JUh>235N}ekW3E7bC#~rmefr&jwQ=SicBo7WFpgH4&u{{>VM%470oc%$u>-K9r?#rh(L; z0iaavPRv2%f){roowk!v&GcE{L&Nzw0vbJ2afJnPh_WD!)En0=6AP@2mt5?B9?J4$ z2{}8whA*T@lLTZSXyYI70jUrFi6t8AXW<-XQ0t@%I?T8Xj4DLR(02Oy^f%7<1lf#Y z!>xFmUHzp3PYs8;d4Jx~%!Tcbs@Sr0XUH9LQs`n)b#r$N#&#>{dkv$^GD8(39^r&S zUNy@kWRt>)4Kd@}l8(tdE|5GcDqpcsRCzz-X#R3|z$d>^p|7y~Qx zktJO%0gVf`svnCUgtO**J7hof813KjWsoEqd=3gJSJ;gp!pHdfrd(arP)b5E*H6cI zmd{6)2<8oey3gy99cvAAX0HyaERk%!HHrl542m&U=4b>bq1LW0eD!y8kQ-<;R7~78 z)Q3vr9d~rcj6}!i@8X|HCZmVW*#+vIgu;;Go8vioB(0|+JZp9*)I*w-M(sMD$I9tp zzFpSY*{SZ|YtkFp-@P3u0DsL+7*Ahv;$L{7a`6W(a5LG3@G>f?w{gy3N~40jZ?H6x zx|dQhyTa-yjY=QQO_fzuSsa2MMy^%*MlMX!X-@-XGt|sOnMam`u5dM#F7|XS#u|Mj z-N{#e>|cFcv*2TP9Dhxb*}vkyPmz>elw61o?~o0k51)j?K`o#g%-Hn3^xGpf$tdZ` z^M%VSainnQX-ta`32`Q41~&$MZ#=!-UD=*)Swk3|dCwnI8;{M`@)krQeg}uzXdGss zmA*j>Lu^Mgc`J-w;;PT|KsYp7PTPz^8aV`>$k@TL7{9kdIopF-L5u{x5n{*iHa40}E1$ylr1-L8FP zwldO@wNW^YxyYV(=Cwp=8#^O=%U)5x&3^)QuY0SrWSXEMgrDd!v*^fe8}%VE0DNN) zuiYyC39uyhrjc3|3%UB@dJW%_!tbth-*e5*OPdH4)J$(u(jB4Mav3%5dwB>nh3|L@ zmtktU&0kq=Lv$%~KJdVeh&x7$F-fwwMYCr)bfPo>7&k6)>%ZfEGZ($l{MM1y|W3Y$+Yg2Fxtop=E0_@WD)d~)L5Pm=tG3-A&m?Ac`8e|-bpP-gIKvv zL=bv#j2X52ah$g~67VN_riXgWYLm7olf63@oG0S=(u)Z6_T-XTc&B)W)YfU6cc9I` zjF7gIIxBVVwyHcok0Lr?Z5SKwR9G8rIEs4QpW^Hzjw~rz_0xrgLj}sDbbhowT&?4J zH>^a@ztv)?*&0&{qZ$YzYGB_K2K9zK8MUK*WZ$pKsXwc~-=k~4Vvyj?98WGsGlrTH z%m^>Wc?LNX_Lh9I;-)@~L~9J`ik~8Sm@+K;Y}Hxj#d$^jS2g2?RE>_h7+r6wU2@kx zz}vc~+T7KABLh^!byE@CsCBVh01=sy`464dpT&C?aljdHqw<&he>HIDtRBysrSWR3 z=_ph)bGuTf@qu2f9|>8;YROT_G95cRQF$?hpSg+ykCkPx1MsC*!_C)cJ%jXO*KOR$ zsU(Xtv#Fvoh>P__hJiJ5Q2U~dzPszRz`^?ABRBExrzrkiDYA&oTgQMOue zyAr&$3n|)o9LV^Tr6izLT``kOJ^2RAOljbat!u|pY^=z;e4vkL`1wCr%Ow19SiMa+ zXyQ|z5puX`rBsv+fmmrD=4x8-nXOWd<@EOS0 z%=U0&KzA-;Z$(GjX>Ktwu|8QKuac8j4Q&Xz1n@2!&28@hlQ*j6Xa zC}=}g`VZ>N+UbEA4vWaVbfTb~-=^Gcm0Z_}{kAd;!`jQ%VowcXK}ELU%HCX9=|;A1 z9@A})qhZyL_0Z>ve;E%>;3g4IaIZo16TX+tJvT^&be!g?Xy>wRs**Vs*09%dq!^n8 zHFUHum3d1rGsb2cA2!P77L`Z5uGaIoSJuq@H8;)g2Cekn1_=sn7ji)1AmnR>yKUkuuuTm_&669|7=mf6T%6`TQ?uwG z;^(1h{>PySjCWbpMiMe?8nfC`X`10d1xlSZQih)?DciGrP0>oRatGB;qy>kloMO@u zG#E>8km4>XAd$CxlJfargdX?IkBPsdZ{i5NXNIu@1nd&ZeLI?Xu&I;fKU9uFyGreD z*?Jbd7dR}<1Nv8+x2R4%Q>>8P?G%Jpeesn_|LW7dWtoGPxA!5Ec1dpP7$t7#3-)TW zVBVi4<@h{D*2xoET4s{13cB8n7NW2CYoD2H;O9r8boB}@gq4@3bj?lQ=DYjUz;1=G z>ZL4=N<3n1duRCmRfuG~LTDls`S@}R2QQ_e1ELGdDe@F8Am!6X)v(8V@TVx%4RO=O zRZc{k6P96m1q(miR;?_sY1+0M z6PX3<9I9qefFIoAslKzQch8e}8(JA;B~S=GoNnI#c70(t~Drca$v;fJRPl48SWi;LTC=|M`P@|*Id=6+6Z z>>Ji`Rp!Eugo4@YuKf~rt~@vF$0d&+Bu#&Ojq$B+{Z-=J3qrhMa%QAE$1S{|7Zpa$5+}0>HWqpR5Ul?rm1dBrRulG!MdXh*cs&A zQTZFi-)t;G8!0oo3aE5IF%m)SmK;P+wG73TQjR{ZE+U>kYJrRl?#*q zqGoq?e}yC$MQ&2B+fJZd9SXb4-@APya>H9Bk~z?pjNs%13F?U5!|R^%_>bwLV?bxCou(rC!(Zo2X;fuRn zOxuYxd_{x>cY7mi2oUA;K_aiox}sKuB{UV%eHfkCxx1ic|)>29=pF zj8}(d3_Bih%n2iUT&SqGJE1t3-9w`c&b99ifKVeaT|$5#Ttiz|caw%|XzS78@HR{5 zDxC73NVWnwV&GbS)HLlN*lYfG)%2@T!{3;16zFeEoWc)XPK+!te{=el%5i&_{Ei!X z!^(*j9hbjFU0t;BqqQ@c-cR;$c(5+9th|rfP|nc&i8uh-@1GN{HNefyOP3JVxNTMH@C@9L6n_<-8XXoX3&;6V%SzD$ z2ZUM8GyKISS>2{CzHRZm*Oik^M-s$&D81E|a6gzQk=+CcCRA^;*z68G!!wXSo7p+^ zrnemIz}@qWliEnx>`Nz(^nWJIjr|JiO}m|9lVmlZy-O_f-AgyRYN2xr-Z;&^0aJOQ zWLKBAi+2PRv!QyqwyCjcR~CHLM;sCQ+RuKWmQ`fYRF%tLzo#I|ksw8mm4x7>({ z{%TUU+UN&cPf3d(UrX`IEAL4_(ArUr9cyaAab~Olyh%fPo+f5;K00W)UTzc`<}GfE zYzSrQRkEtLI(ECB{N5o5zZ(|dC|FWy3JCfKJ92W|{d`UY<{uPuD86Bxm1md4ReaT;HN1Bs?81}OcZrM7V^PN1tHlH~1obW7ZIatyJAE;wiom7N7;FM3d z+X{DsHuCoRgnCbdUD9fJk({aZsFZsf_DOEnbD8F-TE(K2l3acT@>SWLW|(3K?Nd_8 zABOTK!qr5b#9NV#qj08ke7&svMN42+~PlK%V& zh$4x}JBxNS!k+uqW2m$=2<6wKn*@Px^p5`x4zEir30=!4NX;}E=$y|bru7_$Q6p>U z2qUO;$Mx8kPJBMUD-XReNzZ2ZLi0-FD-x4}bHq%nzR3w8C$W*TkyE z(B~`1b!O+~`z!c1x|4|!bEbBg(E%rWKcN&|L4;Lw2_W1`ms5kMV@4+_q*HV3_mve{up&J;0b=wCLE|J2)> zy;9{0@u^&hd2N>CuZ`s8?d{396t?XTO%UxmfJ0#S8{y|35r{`xXU~vEP>IHn`woPU zH6o;*sVZXB`v;?>V=i1rXJs;FJBC<;Y;a^{hWxB%f&pwgZrlqoKG6aRldRZALx2%A zuV)U-CqxDiXWRUPS3(K%O`cxDiJ>Yr#4gi5HsHL6LIe@_o(Ma*DTxg!Yv{{O!q->cwlzw zI6#_s7P2RZ9MFcaqMZ-!XB_5KUaQJt&~>C$rYJ*b_!S(t4BXL9jP(F)63K+JUcEuH!CTx<;=1M%CFlZ7aQ|&Y=UKA>+6_KeryU<^VRa&;Ypbk*;3GU zz;odNgLCmkXTs(}tv|;FAG{W;O6-sbf+QUL=*E)F?u|Aad14nA=^c4Ny>_t=G|P$_jK=W-lx|{*i8nmEYUFzO);iByBCKGUF=$Xm2UdcEf|bvOa>!&5bqGGrj8+ z26wIv@H%C+txlAaZO($mnYz4`$A$ngIP-+esR)YaqHS)O*x=0ga9Q;H8Tmy2glB4^ zVBHCN%>VVufH;CYsoJ7NA0h)0=UXA`dwvmkIsXwuE%I zX-M@z1i^&$+d5B;oc*xrUaq+@ib*7;W zVzyng8tTEnc1m|hF$83+K;C+@Iosl|Nf$sG`(7&aw7Xdy7hv@QkoltTt1TstarO&L zTGvfGY~+Hj7eOL@Jm=oEHK6f;S?~z}Vev>OlHR4ysobWdQC&&>1lDWCVnWt(k2yP* zdMT0RtBP|ow3kzHD3w4gX#~-$QSZ!&9<@T(3Xbnp!VYEh7 z1>Te19R->fj5$q6JIPZJ0=&d&{+W{NQRz3g#XwDk@PGLpuCH>yMs62OZAP@)+Bw+I(C9jFK%E#6 zI^QyqC1W zo4qEOb;^rzflsQV%WAIDgRC%BlB;hOdNjAQtt#82< zX8&llsOWv-GVA>M?W)Vh&W8JxTVeN29=L#Ket^N5My}=R-z<|%ggkbP@ex11hKclq zEDcEP@8wJ8O%|&yRgtf10gXPRLe^pRTc3o~tR;Hqq+QW;bAiSNw$v+R-iK9?~-Pq(KO++LDd-})vxV)d;S&aP7x({wX2cE^p$E-yZv$ z8f3E-oBKVEYa?0f&J_}|UI`&yo$=WFgLd8Nu)Sukw;3Z}Uv~VPkN(NxQ11&><$UwR zCu9F-8{MO_k$J?C6q|>Vb3jqEWHf((6`lVL#`#YUGO7kT_m1BMSz@#Sgb#-(jF0s_ zcZ$H(K*Fg2gjIU^5T6fg|F4Dnf28?+Zr}+X1_wQf=2`{2PGGIfJMFp%fX-{GAbxT| zVe38}k37Vuz&>K4`&VXB$-spKa4y5I=-h)%0<~&wv!7h0at&OxKG0sK8Ab>t?93MV z@&JXzMp47zcXCm+C;lP32%VAXGrsc+$rBq=iI`bfX5S6Q8(?i|8;(FZ^)N+$t0(GS zaBAOx?~gJw)%|)c2Sir3i6FsyqK}3Ks(cCA%Xi(G<8gtsuPkdeKbvX&r}54o&Qdro zRZgi_HKn)h!<+*a!q~|E3V`exbUza8K+6YFTPRzknpW+)-$oC$4AM%JD59_Sp%Cg2U(VkcVx4Cmyvu*x z#Xh^d{nuUW5C2f$jrCu5vHvj={r6z}zZq)%y|vGO-NpXL&+z}c0RBC}^A97q|Ie0) z6e^X~3T3uN((o30A~|v}C;hKx6 zdAw=N-&#i|{iR=F%V^kwu+zs z{WmV)&h!7yjsG9S;J34H!Xp?dXO`K^hy=tG&WN?l@c@EhJP6$CJ-8q15HaiD9WxJ^ z*G_R@C)qv2$gAZU&6_#BAA()i<->0@qx5YBL-wmVL}EyvmxwR_7w)KURVmEj&fZ4K zR+~wse_*P+vsMTNy^_TpvHFgqwng?KE{nc9RPGXn9X^Ure5JlUQoVUU#g9N)F}IAz z4F^)j&IAS@e6eNPm(PQY%O>ncPWLSYyg-$84s905Y6I2z(&|wIMEKs`A|@NlEQ-#B z+F$9_ppGo+CCVo%f1CbBorXNo)Hu($yJ%?aTy4ePcWl!s z6fN`yCHRs{>V84fpDuqOB$gFlK0vGvd~+BNZt%;?za!u@_aTdsH{HELpB<0!ZCeu8 z=Mi3I6Xu)xN$2OnA<-@57oCf#EY~uXc z#Ht$>#^zOCLafOE>}Y8a#McekJ2WmzAhz)HPJO>zm^66?!qyBf$?YO+kNOC8GCeMA zvC3c+@}KsBzkpD6e&NLXPNSB%wE>BL5?}55=~w~iV8@wj$3?@Nl;y{5rKYl8cy85I zI;I|}ji7O?<#Je2{N(pq#~*0Lk)Bqr4q4VMN8G4k+2SMJ{YulyuVJ&;^vc3!qa}If zh>;xDk0#ckP#!wD=xZ*4RC&8Nm4q}e&t9(+=;?{zVV^#*{~KQ9=Wq77m<_|6mSnhQ zzTHds0o-l}`+|ZpleI_3+9KNn?`$J6n%hgn4PMRLwT4~8^9f30NQe164nIXCnk|N< zy(dwzD!2&QLZG@(r20%h7IqKp42Bj5raam%O{IQf9Xho9^5*p`rfGhfAr$0_rsA}E zmYYr2I@^AiUdW~mcXcX+uPb+pW$_M$q)Fq~X_KjTjgl4=D6z>JQsb5^`(UeYr1aWikBvQH zLJh_AH$7V~sEtHiim0dZ1$ag0>g%o5e&5sNI4vxsN*zm`gYbL&X^;tSd3fve1$PSv zNf7>2dd%cSz0&3gNd$ft0~t@{iFms49w$7$M;ll3oKnq@e&2N}bP?TEYSzTdW{$lZ zX38l!wu!`%YC60kfbCSflI$Lnau4vWNtWU6vY5#0 z!KlUMMJX;51#6YVGJl45M9-!xqN=t6zs z#3d7zb9gx4U<4b69yf^d#3zq8yl&-`EE(BHIoJH!vHtAXD!nzT!wrdiBYjmKvoA6i z-b1HM>3g~DmewnV6BV_QM=H*^?)DuWH&FSx9YCYV9z=K9vs$!1T=y-GQnb#EnE z{RKEtr-2#2ym%a{0_)K!ikbY)lF8Ea-m|xEs?WK>e| z<3K#FQjEu^7%_shqHj}gk86YpWG=6B{ivK`ZM4ZgUHOy2R&ym;D`Ekf6}mQ09xW_f zhFia=4}`BQ&{*Zlv{;I8*sM=bwmKZ^sl z)W^U){A|=}fB!R9Eo)a9(NIogp+}4pOY4+0!;5RujOQ5<8wE$=4-q_ZI!$wNXK{R&qtQS94K*R-J zmyDuHija0gf% zyi{%+%*-#3Od=Y0^}M~=lN8~JYAwi*?TbrO2Hk~@4@h3!GP)*3{I5hI5#l{yr;dm= zBAxtBxu;iS*<7Ru+U>AbrjI>6mG1UT8%degQZe=Lb@C5)ogQ(HJyOb`zKe-jAF)R2 z+u`@R<2H`L!dR2(q$eX;E_pai0JHmb`t$IGM_#44agT`XuJ3vk-9`{>%fV%{p63>P zp-cG_LDrRRaFft>zezv*I>V4^Q87`%^9I<;q1&eFTaa$n;@R&`{dFl<~oibr23>cG+y7XS{txp01kF3dER@}%rq^^Li^N>M?vFE8zH*Bu`jTH22|>ZRZ0t8?`1>`+}97XiX>`MmsX$k zM@XNxFruT_d_C=gE#u1Bw5ivbCCkuVga@J|A9puC?)x4QGkd?y9o%~b0okJ@9qwkP z9>PG=2l6y*Ndfrmz~Ly9X1Urv{C0anat_(hJdmodxR;3T=L6<*c ziefHewlb-bL*Vl+g}Db>OnrRJFA>9x|B-xdg1xwt1A|6KLVppXW3I> zlzZ#%)hoO#y!Rix&aS$MeW{HHel#7&WS4$C4inx3ISb-t2;(Cw75ck*9T`@I7N^>fS`z5k_f}=ekvg_6vMCP z<>Q0R^xfkxu3UKe0K~aB{?z1lUN(Cf>wd`ynkX6ZF!H|YSuCd>tSGracy9#38u5Tk z2{6Zl`9nBqH@v4bMm5{@wR*wHMp+&YG^rr(Xic$h?z)v<0w;8!QP4%e)$hC4r7L}< zm&PIQ;dYFJ7J&-#C>#D!dgu0017{sz+9x1ku-r4B?@^)s*xZ9)O3P1EZNRDuX$CR- zyCN$_eK*FXhvcm4*R6%PN1n7351Wnhe`jsfW%1^+@ltB!xO?01e4yG_-IKd3_ty7w z&t3G>fz<12g;dY#F}o@Y-J=S3yPev>?{tW@&K~9tni3CpT`ODPCs-H~E(2>)Ur98Z zpTDB@cjoDv{q3H08Yb1 zD9qPutWK^$PxfRCthnX@r-n8Ec}Efqn&`@?Ik5Z$UOO1(?fom7JLy_Zl6q(ae!KVL zguoj@jxEDK^7=uF``hs^E)luB?9{*&RRme?Y*25c(%EFl)+zEeNG-I76-^y?XnWkb z@zzA@i5Cj8khhG&Fz6!5v=1tX$ol%r*At81YotzA6Pht17I0Qm=`eBu_#vWM*Gqf1 zMmaRU)soCNHa=K!&TFX)JrO|yyDW>!$=6T37>olS(sPA2#^<%TGa#v_Q_|7BSsA#S zC#G4v)zBhg``Mwj?4sii6=dA_(R4bUx7XQaME2Bc$RnpBKgmNv4BFn*4ezgFLasau zEfrmoOo1l3xv(=s>6yjb(Mf6(M}(4!an-8fn}x`9;JZzqdymfaUK$LLEU94D3k9Bm zEyl`G)YeTGdn{)^WH~D*3p+%t011FcVM6r~8Ek;SH+T4b)bM(|}K27rpcHpjl zO`=K1#+J}Db0m8o-4y(UGpc8%;E$C?H#JvrPGMA;Q<(kyM12U5~R3C$25B#>b~W zM#X3YqsyMsrSs3_6;s!H$!m5W{EpuP6IU&^apv)LwD@uh_BB4q>xfhQtBGc0_MI}y z1^3LDE_zH^A_dZ8=jPjl7Zws`+WFuKx*P4XkO4b^Hx+~b6F(uoiS;-1yv6t$7=JOH zZ0%rNu&-r1u>Gbi#JFIQ?nyqWSi*YK$CWzGCtX`)MZG{s{pc2WJ{%LeV*23X1+`Gh zyqDJAmAt@oV9-h}wtUGuMEJ>_%1RmC>2|p%SvV}~3@AJ6y*`MY0Ln7OFV%HW*&kFB ze3Jj(l=!U&oNJcO`H4ZFD}j774!->Mvujt~(2E@!iIY)hrHr3iITyg?G}VOE5FSDA zpSV7I@R)}WW^Kf~yl{TL(xg9jO++EvuSe4`@CLU2!&TTGHYiL|PuFQ=)y?62cTJ!#*cboH0ZDJ?4lqO?AhDlF7O=wTJ38NcH!ULf7$J=GnjkXio86$jaFa} zZUi2?pW+hO8Y?H=>yj>7Ij)DjDr-|!XI$_@qJ|(hb-;S&=WrHvSZG<)<9LRCfljp2 zeywYFazVlf;nSKT_My4I@%h>T{k7#64cF5#$b)rg`33e8@BtjtQYPPveUBKTyeY!u!wGr)O5Q{2=R0!Mc;e>(a#OP=+Rlc zP4K!shl6yuMef$xcPtn%=JjqjMY(DJ+%RlfS!QGqE4~b+4zrqfsR%Ll+dZ8UlToC# z{@90w)uYKvx`W5X!$g?g?DUqz!C5#czCwbGZIR3wcdbCZ)78T%mT>SEU)_SAc^d|n zLvWS!qy!`wrkr2}l%#&)DvA>yBuW;oni{}@)V$JNYv)cKK=pB1JYO>~N42b@zHh>) z__ISdPA!0P{-9p=NTi&}Z7j5_ksRFVuW0C3jA-dv1vVU=8}$cdg8zWze>2?eT0enSu1=I47Z=Fd%=iO2UOw-q z*L(~>hxJiUlkpEdY$gBDsI3(H)24rttAFC6u)V$3)*CXUr z#`>wfx?nr`{y9DvU;kn~DMvZsp<2pOegX4FvBVPW^{h}gFWDk#O#l{z^*49mQGUPsB{qQ<@RQ_0~7>>XA=Nlb?J)!U`rM8HRkY zZSvMZN;k?kvAY5p7vBt#P{sb`ldM(s|u;I z+0Sn^cLfN-FN3SGyy3vf){lK7Nrp7f4eh8m8~MB;nCpKrUnMt?{JpS($3D=o@_oX) z<}eW!z5HH@Ji7V1W>k^KVV`~0?D@_Xshc|4{f|Ep%jF=idjgbfrW_5O2f~~yRQabI zf|KL_i00f*xdmGVdVOqn+(H&s@Ot?t18p`X>%n+^_l6(?3jf7jeuueH5?-nC=p!sP zuGcy3Mq5ue3UvW=9_ZDf?u%KohldqUJOWU6c=mJX_uN7elzTV)2iBlX8R#dIwqWPP z7{?9=yH^;A+WmI6*v974TQA!U{_Hx^GcPrn<$`X0nT}(qjXmcF11)D5e&-5fxDG>q z*KsAaH2BMIePA?f%R(_?CIYLDF4=pN%;~U|Y^Z9gZDAqN3<3*0ker+m z1$STju54uU!pyUK%ZMGa7Q2Czs=kBQm;`M!m?&P*N5e!GTQuHxF9=>zSRvM9vmM*F zpyMH)KR89(!z?54*!fS3bfG8b3;8A<1IT^RuA%wE*0u_1dh7klnpP=J)Y?5iX;NN< zmzy|dy9Z&^2%Rcx{E&Rm0kYBQ9R8NGc3F6Xx`5`5_Y!ZyEOMZkTc$*#W168_GLNO3 z#7wYbH_(Z}%uh_H$cmbVTpISisNuTX4q;v8MflUn)JKNi=?$NHxz~#t{2kHrjT&k+ z7Z(6!WNRUN!B!n&dah9eqhW`74Lny%@|;Aiu?R_NrlZ6ZDwbFh9>``n!W>D1V`2sz+5Au&#mq^uMLL|YrpE>T0}E-kNYDvEK9`|elQqI9q<#$=HZ747?|palY%SV?iH=XB@o@ns%VXXP35(D zC~CLi+PHK~M-f!wd~M`#gn(CelA651KtxHZB|M>+*RESObwD3Jnj9hSGJlj*tG*IM43NOP%r5e>qz>HbE>-w zI0vokH`?fEH@?-8HYhn>&b-S*w7fH;fP3_20~q=HLF>}=zbQ@o$WZ78MtFm&wQa!* ze9G1<;#yUKYf&RE70;V3r)h%g>opTVt6cohxTC?NX<#H>1*9^u$G_-m={_##lI6Xg zZX(t0FF1{T27U9(s|$f1J9{5yRzW_~-Y*zObCl4J81m-I$?t8{U82_iD^I1KJ1t=ysA{TaYmb!AQ(hp*DX5}+PTQ6tOOV|dg1}>C`*$Z_$tfa|E zs-4!@=AMm%@zU5CX}kB$*Aw+30UYui*5rEao_q_2MI3Zy$-h z7zO}^mf;Gw!ZP$D-GjD2F3@ulC*eEWg%forw$Ht2Z%Ut2OIoZ&xmWa?{n4a3llp(y zd(XHgvuzKU8OLEp6wX*cMPM98L1_vCN{bC~q>F&msPr0o5K_irkU>OLngIa;1?jzn zkVHX1X`#0SBE5#tLJ~rfcZYNC{SD{d`+j-9ydRDq^ONV<&)#dTz1DyI*IFbf(UQ!X z-)v_w$^hD{+si4^_cls`9(DaVsHs5Y+~$g#{O2`~exs{R=5K)c-Kx zO@pMf9`s@2EPw72(4kddstjcuNhDc#zqQ3?iqy?#gVvoUw`+8lz}7Cz~l_}LJ4xFk^% z)hcbYx_KR|`7odjj_#WK)}48V31}jw1k@TU@yi0v>}aX5aQZgCf(b7RPKJ-ob>x`_ z+WTuvEG0d6H5s~EM~-;W{@Ytm*;fW>H)M^kB#w-Z-trJ$%v1eYb^f~cVR_924IQ|l z@4*|-Q`6)>IA6ung-} z@xs+pMWrN}U-fi@GgGIfJOnxwtM|*XDEAnL@=)v!BMB?PECZp-mm1#xYi9DmuV9jF zTByu3&z$DRC<^WIF{KMKN4lG&eAy=GdW8>terR%FNYWj$>l^mv3{knqLSDY7MxPOH zI!J`w8{XIA)PdsN={+FGm|@QS*Mwtr(8JVghFn5K5&F9?RU}sI;n1NU)0OeUdWt8C zR5e2iLwF{L3ajOCRA^yWB1Rff)i|)1R;k~unoe)oq}!3l#7YC6 zs6NWt@A5F{p1k$BqSspgpn|9Tp13djUvrdg!5rn%O;5KYO;IvR&YKPMV$vf+L7b#8 zs&0V7_Fbh!Q%x0IY7Z0d1dWsdSo@1K2kCFCrZe%`61G9kR^cxXm)_oa#qmz^aebG-N;9+IqakT%Vs|eXnnt zhCS??LJH7m_~uro{2}?)(qFhO5+xYSyvQUNTlb8&*1;?Y5q*l#K~)^Ay5?3w3-1~8 z03YUc=IO$z;T^WG@wY;k=QRjxl;Ko!JJ-BROc>Kqw5Bj8HSONWnPsCuAG+zJ#~U&D1*@_B{pk+ytkha9gES5i{KSb(v-i5m-BLll<*)Yh|~V(f+?uuUx7i zuAASA`aY2V0lCDbYK*?|g6OJ?FXyCSKU$~yK4;FoP#aIGdWx>+^NuV#?aBe&#gSgP06|4$TV|0&MYg`!B zyG{Agb-A5K>poDoHuu47`D9RqnlZ^#v}EQ!0D6Rkrgll;-EcgK7wQ+Fb=YXlrgK0M zPnX6XK@}#o=B6g&^Ngr77Hk85&gV`-4!N=~ME3Q3%q(jAZZaJ3b%cc8fH~=c8T6H4 z2K_x_#wdTH3#5U&6u!6s`#_jYu2E=jezZ6qC84TLK|_0ev}$3@p*yVZNc&?ze^X5~ z2<7XhiQ+y$yoMifnI$Xo@`A^HT|D)7+5M2h-drrnfcConMt>xxFs>&KOw&@4GESAL z3(>K-lHxxS^6?p>!Vc*^A~yEMCMeIh+3)8M6xr?XKh?-Vc3W%-6h*MjKmtQ>Ru{d|((5kmUABw?Tn4|DiTmk+$ZLIpeRirJEu zt`(=>RtZc`OG2kyBli|N)c#J|+=hQLo!ph{{P2PotqNx@@( zzqxy9eVpYNcA2+sw>2FSyPlCjquXuP!swr<_w=g~xkUC#_B%E8 zkO^(cY@97-P|Q(`Y176Cr0&>lAg)(;Elhng`%reK$!$ZIxzY5w?-i=Xqs8=6UL9cK zoLzJDMmVkcVyJy#AzH3G)5%qj;Z=^H=Pah= zV}DO)4qR-oF0tZJE{7gN=$8VZN*J7`1;t=83J?z$#>aB#0S1CB>g8Lz^r{f6T?(eI z$da~4VPjOaP~IG-9jgl?aN&H`hON)NUb7MDO9e>>zNDyGV{NeKz&w&MG>)nms2d8d zFtVt}_7K#7>X4*fUl43)?plP9Do)Y}m=ziWw+;(83VOze(CsA3vlc#Q&SudA-2Rs( zBz$E=FjgNZ4U#~El#f|TXohKc#sY-7%Ib?utM{e$mjwYvGmXdj5RO6fy=#SemWVG7dOUY)SY1>96;BXn5=eN^MpLmC9XrhwQy%P>GPMnty5?z zI>0}y;yDnifw=7Vs zemw0l?un{bbGM;Soa4w!Bc3FR@F%E_EbDHyoo)4g_!T3zdBD^pZJA}SL0DmpWgbe- zfsBl96zM;6v^5Z5Fh8H#rJ=W8P@C_eP_EnSphh#D_)vQpb~wPG?S!sr`f(b|-PM=N z-kxJexRuQKs%vfx49uaH^G&XmryGFbkUW*+{7p1!t1+4A>J%`LS9rY#Ra+o`Z5X9@ zfzTJe0mfy|FJmu+oY5XDmT%O`6690P{P_2q#q1e@kV%f&^LlzpG}t99T}Q+IM`FM+ z!KF^%eZ%bmFUmM^tTlapYeY1vL`nbHz&Ai554-gIZ_i4CzAiAOBqd_YoM2Ttr=5x@ z%x%A*iQCCoRaRJ#HQdhnS~+JES_o4J3?5`o(i^05!K&WK_X5Nk#Mb|FYXtT$M)q}1 z`xqf)eq#JlHY6NSV#AyV32lMni;SmuJ~=1cPL|JEh3G3`hP^oHh^-O=e}pu4OiM@W zAFEsXltJuljCHOH+0t8soa@4Lc9ct`YK(tCN+cY{dH`j zW8jf;lymIxEQV{BN)Um+%G$s9dzO*N6IBnv%&XrMc6kr-=JZrPZK|u2TECeg9o;7X zf~Xf1>_1ZRJVr(LIQ1UQ8|iUjJH@s+jvI`K$QsM#_x8f*CyugVB*oRk%a2_oT=v;9 zJ~{kJ;6Qc!Cwd-ex)-lO_;~-ey7U&F&+NTo$c1pu$fy2B`V#V<6Qb?NkVbuI?)u~& zqTP1uV;KT|w!L2@(JU(k%a|3Jl+_0Ft*@;Ls~N|CRT85~9m9r%XBMe*a+$W?7L}ll zHC*&roY9?}g~Z|o7^XI8^Hkzz=)6H z!3=-y#|=8)6*it^IM$yvt&6Lhd9?Ldj#ml`4ank^<|tUm%Ej>-o!abwigmo2I;DNy zSRXS|1z%f;OpT$>JXl?(1lpz8!i{g?+&Rls)W%o$NtZKvZ;QcbC%x+C^C5<5=>xUb zCAIGbKdhoutR`kKGPIF-JwujWu3--*7P=on5V#Iu)^U7wENSY+HIh0K-W`Z*=8INriG}2g1ok@=oS2x&YP3|0~+z12UM?;O3r?m zJL->q!!k6VE0Xc2p<|DT3^Fo*G3Z^u{q1c69%mg;>O}9QqKc}=Dc8B{ZmWACx~wa> zcV&+=vZ`bXc~b2tMtcw=dWqdJLH*bdvL3v-r=JQ4Tbd8(bfWoow#A_Ry9G{jl32ck zUx-+L^49iB*TAMsX9tWLz#mYtorD7tL94{Bt4wN+eE#6fi7IUi3MT~}%VEO5Tv~mS?(h%%Qy=PI!>KaM_MNGOwJam5 zCKEk8(}aiw?o>U-nUOkQ4A^>Nj5V z1uoHTFt+uQDwKS~JYeJIVk{1TT%1GQa~}_H_((e1r(#ccfR0gGg^{gaB}vM|!=3}{ z@r^RZmFUq)v2lGQ72#A_W^I=++$zJA7zo~6t}z6yJbGeC+%a5I7Y4XK1uE+8sR=J^31+8_2XP_H-jJE017>nr(a#`EJ ztQ!>EC>iAMWo>USRUwU|?kXAjhE^|*Kk^c(sKK^&EWwRk$ys;Q0w2DA*qM@HtQR`x zc>%BR^o}M&Z02;WT8-~BMEQzc=WB@6W}i(vW#~ikb|2Pl*4<@Q8$=5uVqu)ephL+* z>(|BML9!T}vp}jzYHkZZP2TT{(Z?j};q)w!p48-a9*Kar{TApU;j=nj zMB87+T0;de0){N^`z~=apMlQ9kZNJhqKvJCsm@Ss#^;#utER5Lb4AT3y$tP@@VJoJ zX~)iCa&k+Hm)J}@JFX>HT*9GOteD}&$v$-76f+EX=1G=TLiwkl?>*o1fBHhb)|S<- z!pmrKgKwA)HrS@~7vh^r6t#x#R#Hv$u~02k;e79D zkYIJBji4YgDvXv%O-Y$=`wcEqsP)*keEvWQ8wY?M`0jWBN6*b&<2UoCBn{&v!yTou zhzeEz?0gOTOGuAZK7W0>H_8@v^Z8&n%b8_ab=XAqmXW4DhNgXEVZGb^)7acEPo?u> zGjpSa$9N!!ly_U-s!*Kf@pEu#v3z@}gU|#xpL&kM4!G)ZUvDqVZ`=a}gFq zFGeOW>PNLEBFFc~JO-W=v0}AkDqH%7)q>~iyu*vgnoY8o#|gAWe|1Th`;YeF^rji) znQEPtb~K_S^s7nkLSufqgYl$GJ9V%6pkCzbZ)#8OGnO<$z!XYHb*O3?E zysbBej@#uQR?h!p>FU|)S}ib9R(5tL-i$FIU)a#&((tkdd|iHoOMUgQflb@YgP|{Z z0bZ-wh5c*`#@1xJA9_;C!zSTN5O4X9P$eVOmP({W(mt<~#28bF_z|W^G!gecHOpwam9b!_ zp}S$Sn(!_*eDi{>jZ*Pc`VE&rV6;}-de(<{NcL^(-czIUs#eNNPkD$t{U&B%xt4AD z5hH3Tn7W{qDwcd!dW)!=ZthInM@#gRO&`7fyRXns9h*lkMPG{*`(SHjm4HdrK^Mh?n?tKU zf%Ol-DIGfA@w7otye;tnDIbGHY-tD~_PPxEkL;y$Qv?@#l?y49>7vOhk=5w3f!R6b?*dD2elo# z9iYOPH3e?R89?{FqZaP(cHu7vKl*an*4x^76mV)hD)s5I84h<5 zm2R6Y@Kjx9Lyea8eNb$3<-U@=4Esuf*gJ}?J6_5}(q_6CxqfENoxi#wYe>&J?6Ai& zw&fuRxB4l1>>CBb!=d6GO8w10IVr(^$(u)RVhgv1gMNeQ9U=7l#wt=X;hoaH4^d{8 zld|rftnen-k>b}!5KlBVA9?X}FA-(Uqewj=j=E|?GaLAY+>Yw;m0KD`EzL)6cl51{ z*V;-<@jhKRa?F}tL-b?Bkcd;}_Um5DC{}XEMG-Y)Z+tMq)ukv+_TjXOFb)sfb z!C4H)xz;jbC1b^3+Na{g(VXa(b!+g+5!D&q7(Jy}Ag`tw@P72dMh9~tT=Z~F=2?1{ z&ugDPp1CChNx%CZc_Hzf6>q5gTdUNHsPdOr?Cafug+)1oD@kMVl+}n=YT93e8%qnO zhyYUjc)nL1xsVgO`VR5XS1Cr7rtnI^US#;}T$W_r&)O(2SKzH2{LQkuz^u1zC{!8# zR=#)qiUyDO>_jIqZrG)F^&YN+>8%xz!%J4Gds|_syVYx!)Vv(Dnp#_D+D-AjRwVX* z-!d6}9&x%5#9rnkNk-FoRH6Sbj>e$dmgi*F;~TPP$4+}Dq8I5K0#olLw+o{gO-jYJ zlSr?1`+_2}GBR3e16^8^1|dr4(~ykyt&uVdS8a zM*C;SCpoRwK#8)2{JplZR(81;yx`Vet4jeYPPqfNntK=_NtOv7AhCs%0!mY{9+yPX z{C{t8o$4Dk^92#a&!eH{o06&3pFP8?oFP5fWHYld;j7h+w-BVv-)y{4eIn<( zM_q}^TXT0Cv)V^WBAZQP`PA?y!i$v~WPGv&Y-}wk-)KNO2HLD`pWrdZ$USK{+N5D> zh4C2^&2?Wi%sg-y+7mk)I&GhdyfrXTyyyOpO)5Qh{;~C``4wwr zUwd`w_1hhtH%8?~wA=-I%-Y%G)4TTAVc^w9UwI$oCzStS=tZ>i$(j~k5P)>@RazSE zd7P{m+zgRE?y`p-8FYNU$Sd}RC9d7b_=GRK{;EdNl3$pKh9Lp50Lz9QabE9Um5PlH zcXA&&yLwMWGTlL^T!GIJFW0*1|9J3KMishp*vIzuN{^z#og?&f+KP%=_IYQu4e}li zkiq2_{tvt#$RLUy2J0w9j z{}jo~%evw2s8d^=afh`v-nlEQzJJ-1O=gxTq41odr?(J3fx6KX!U6IJ6!lnJTW3Q! z3)TVkfcBgc)o$a-e-F1IPm=1a)zCgkk zgsODt`np4Zu6u}!GXA3@T!nR8W1G8AGg4~LJ3ut@*oSKUBM&oI zJx_AHj^ck9Cf76&8Se;fLPBOayUmo1#t(Te(b)#6Z|ohtV#Qrg3&IC+7KR4tc62czAz_%fv@V@~~Tl_p`f* zsnPb+71SO}?fedvy4mhWnN3$lmm;A@HnqQKq(;XP^A=XV3s2WkPaz^eAL;X9zO$Qd zY}2(Q zZ$-6T{P?zVu=*_7HqWp8_RwYyA=-o+*#SuoL%*MgSA|Q62Lo5) zM9?~Y<#L0em7}M_&W-9OYu`@zl5TiE7+z!3{YOZ0P(Km}$tbLm_r&BqeSK_X>r>L4 zYg-p*2~w}78bAx-rFq`kMpy?=J0EF&r(tj7VxBWwh9*B;TbQetA&@-)r?|TE7^n z4r8ngdz;41Vtt2c&O8`->lSyjL%ZWnFzSyg%=G+X;`U03#zkT+y-7S669TU~O)8!W zxNMmZCNL0--z`-+kh6@kqb-MSpDK7&sZ-(VQ=Fv#4qvT~7o@@Xl)cApor^6}Uoa3+ z*ZPhT_i=`%`Cqcn_R8F1&Qazin_M8_oS0sjPw4L?TQLoQq{4`+HFVEl^$-~=CB`Z+9l~|WaV%Zib0?lx*v<);E#SR z5hnzJ430Q_tmBY<{VkHjmTF+K2|ktfy7K*~L(!KC1>y<6T!6zOyQ_J@O6r~md_Y58 zq_@~+6g$}0Iu(Ek-m6YUO?o#hy#lKg&ocL%Kz3&4##d7#gQ3{+#V-`jOWhH>L6atx0575)B_g*NH@lV$DvSlN zS8BB(Mq013V3KX6kG;0)8Fh4%$c0n+gA=EHeE8p$EVO>HvT4b1C~e3xBDG}e}*%o4g@w_JD@U212flv%Z=;=9#xg}Z(M_YH9!7M(A_6RAdOtR8#*Va0mrI$xSKE# z-=H3UfD~ZoQkg)@I1dS!!*16Ald)NEF7phkvwE)=E^9-7+vIvAmg_WQz>%<3WQbmA zn}p>jsZks%kz_wS)e;dmvSX&#+P*m@;nE5mmv2JW&p`BT#$}c77k+eVE9RH_n{(kE z2k?p7dlhp>`+Gv4JJ>5-8J78hLAyU=5JyS%$v9+rZ9(pW62eRXS%s>*wp6P_(x<>6 z#IW=e`LI~=*2^LbZYEX3n(n^=1C6_zAjkyAK$X(n2Cr`34&vI3;Jm2QE7ne~wL~24 z##YFmUS-@QLwuC!t-Q>vyas zJto&CA#dN<_B2MjJxBmSL+2=(@afG5oPo$DmuH-`}8UJ z8~F-0fh*CdSgKm>6K##MJl z#~=f)CtgY2JCB_;U_3(hX17)@Do{A_&>B>^rA=aHZQhL?m(Ln?>E7U@(gRluCIiHa z^5reY^ixx1YVfm!DBX!eZhNK$-xmJv!eHeIT5 zd>yqpLXg8LYN%h>{9!)G+sa8YaWgzL!7>3mD>1tu^>owVTb~6;dcSju@;rZ9j_7Nb z)p7RlX!`LaWIc(`9~&Oq7@d1j=wqH!=3o;ANT`7OV6qaxlYGd61)6!aK6Yn-AzP=tShUXmzAyMoyN`E2?8%9m2R8@d%W#G}$9 zb<^|J>xsXPMrXC_;&GzR5oG{iB6{R2KEa?3hC}N z{=IG-4H8;L81GuD!W)}n+lHO*e;8gkW?6zyL+Aggak&75iXn$DuCIP>_&{hfgY*`c zfL_kMhq9HP2`wT+4Dg)?ee%1Pi#@HlV5Y0EVm|$c+sNN#qwGw7vj&raSF^b6ysa`Y z<1an~!o2Qpogb^R-S)-y3v6b~njveRa`relx`n`vRz54#{}pxq&^>kQHeI|aI-EWi z%~xPXxS)UTBOi2xF0VNTd_oxmGt*eP~ImRBzxLBq^t?s4cNqtj0GX z2@F+Dum=#}CKVbggru?{Ca=@-dBLyJ^C8W1FUK@=Kqz1z1KE&do_JrQthL;IyUV@c zPVo{ux#1Rd<&$tkeBgRTuf;g=!o)0YL}9l3S_C_iJy8+q*2md^Y(i5C9e*7p=9e_N za5XPGwWQ>g9ipDuP8$XM7LrOwC+SX3BOL}NS+fjvwY84ojr%2L=VZKKy;sj>K>8~+ zD%|kp0B`3Au%@)byYO}-dF`^#5}9$e>UmIL%; z_)w$-7#4Fj{7+*$cqOhtzW@>9lCClBxSxZ&sy0CB!m{u;(npL zyJ(HAX0b?Uz{@JXNG>8kN$`Aka2XX?A83diT-~4G0&J#m;8stDM27iB#3}U87q%4o zD~Gf4{8FoN28v)N(>5`!ee4UiH8DoSbbLaBzit*1p*nbV;0z`$<%eW5pCk4K#4x3r z#i5PmsCdS{tLkdK5(^p6`wdXM8`X7odQ@ao1>9$IQz8a7JjZxs9ith3|JQJj0<^BF z3WYs?bv>s(%cuye{wi28AA>1|+Dee3`Ypq4LMpLuD>NU}sU{-l)WuyHJY}&e4}RrZ zwv#MFrVwwOEMD?_NjF6@oJbta_}UM>#H8`+ts?W>>Qu2T#|yj*eHy8kDE%U1zjDOh z+LlYO;|r1{3ci3qd)b#Mt^Pz+E^dG14eLptR_KSAxKjO71*_4OSwI}Ncc8~z;_&m2 zlBinv?3Z@P2xA-~0e6k4hA!*^}NQ(31nx;H+}J==84?qe_x^fN=>6Q0vR*w+gAxIHK-hO@NQ zdl~{ywCSi&s5oJktZkM3Vmr7NRM1$05uob{dh<7iE~G2wZA zs+t>C1rbpTNd#L|04w{Mm@8nvHA8OC2wx3ZF;g!h-D!m(dhRp-dN&r?@L0~$`{PJk&+^Mo!r0mVWS2SNHXX$!LRyBSC-<(af$*lcJ6|r;xcD_E9g?h4cI2Q2 zc7Ay;?0z^kFSUps?iv7Pq>~8-u~|lp^YG9=)hwWdz8O;^9?ec*sL?xydKaJJa{02o zx$6}lct%8a{Gnk8B|W2n0tk~bkRg7^`ZvF{9U%cb#P#QcH1rlkIRld}NLjaZJgR$b zJhL%Mbb0rFRRWrzG<-&lBzk)8Y@tWZb*PjihbeuOt@KAJM~U16oQxo(O$i z0;wJu6EXtqs@p zFKP!nc}^Kc9a_A_xg5&w4MV=`z}&KoC0Ft{7H1rWSgnC_C5}IsW^S?MOt&*)t@HY- zO8x5ZF=UH-hO|A$&uZy(P3Yug5n$fzYyKYA)@Cl_ZjjLJsHVvePc(E^KaQ{FZ6*C$ zQ{u2S5h-3WmK3%5%sB&JB^B{lIH0W*3{mVz5=I41%(42a{5B^Vgaf|6n z&e`YvRs`0oJnWchx*m2dLc&V{9~RjMU5K=Ha`(CzSVRGT-)t?e{Iayhf~J&O8&=7u zZBaiS0TXue(LX=4Qh7{?(RujbtJwJAx64mdt4i)zn=#_gF}LiGLWuM#tJy#Ln|89$ z|3vQ7e)_vL6&i?GZe|N1(ipU(KcW?_hI*W)Q^53qSs38RLG5;tXYT2q)7f+H42&RQ z@;tx3Ms`aa3~vXNio{*?Nuk9@8r6if zM(TW6n-kC{7}EF4u|&gR0Wsy?^scb%L)g90?=OcVnZ)zr&m2-R038IlS!No7vi!T) zUAR!G^wIQh5NSTzy1`*9bCVEMUGBUch>&^MUW?xGl26-xete{HO(sGx3bHide|{ZH ztBtp>on&NcWY1-_v$NF!xujnA5W&1{qsc;y*$iou%KSgR<@b^bK68F}#qEuQD-7+w z23a0_iS_!wzGsCoz>HOb(T|;w!MwM}sY~#FZ6}#ppOt8C5d*O;&0s49^{4i4f~q_# z<-enq0wSM~(5YQ|xbxHH-*)ZV&TnSB`CB``CH(rI$Nh~q{-3=Q?7)8nUj4wB+Vw-8QNLK~im4(APOqwa#d7(Cm)LyX6 zcUCnwcfd~s(}^MY`%_~`r%}=tfI8r9>n5Q7D?8{6@i(tYX3Mq-!r+k_;2_Q3K4>cQFR0qBO+L)@@S}d}y}AeT{7-BZkBW z)ONlLADaza`@~ape-tRd!OHdMKJ|#sGLjV(gTY26_!oT&YqE^SSMN+-5R_*88@;x+ zKv4WMx724ZFI3qIXm6iB2*>d)>|^Ge9~05jJBOhlrJ0Yx`vHH69*fr4>mcDG4yr*i z!mM*Jr#MAe9Hroy8>0B3 zAh|pi4b7R@Gz$F%aCD)d$MH^c3JLwXtGMe!%CN3@{@$2l%W*KXUN~Pe!?b#&2Nb%@wZx5nRC5W- z;I4jnHxM^fAxmBIspE$A8JoMV<2fpi?G&e2%dGFC1v9$=WBj+>65igUk0HR8iRX?G z(%QVI( z3d`Va!c0z_NPAuTP&@p91j=vw9-mh&xvn?~Ka%d0TKJ}|2hQKju8MN_F?^q;%m?;( zW|66P9OWr9szLx}&uqx0R$r{oMZ~+L zfpGP`0B&FoKYG!de0JDN8z4v{v0r*43}pD@4HaJ1JJja_-sd}^#{&~nMM|2Ja>KLi z1hr75h~0Z<)RNVX#MxCk=ctGxKiLo=qklM(E5G)eDn(ffTsHZ<-cp#inH1mh@_GxWo&r#vzhW0{-pGErF?Ud zos?NF$T5%lI^KOCVZ{w!2G!dI|Eqf`X6UbEt(1Ss(Zbtcb0& zh`Odmsh1QizZ;a3^uAETT7#O4p@{ASgns42TAP_>3OdTIUkN|H$U5Xe^(zxCr-HW-T|TR$VvGc^KU>M$pkig?@EsFor=z(nexr zW9B}fpMso0`Z8rI@AJ2w+ZhsCdjuEJJA^hJ&b1|zO5S3S@e_8Za z!PFC?#2lh=sudDY&)}6VEi?JnJId&X8}016)fdt86N`Gt?O3-eOPku^<=H7UdB5pYd}(~I3Xyh-fon@WqTLOH%6 z0zRswOu%6Tf9Phdu{vANpj+T(`Q+!-+z1mx+(jUBTsk=sjiB?ZS7rA`Muj2ZlXg;J8eqGX)Bg%N=Lt<14*r>0n1ys7 zX=T24g`m%F`JN_bmF#zE(GX}usp7wB!<_^y&ysijm1mBL)Lb;mSqjJOCrOh3P;}<% z@~)bnUVP@w;tZy1>n76WtMs1bnhDRVNpIDy*?b4q?-}iHi z_ZEQ8RwX1++VlKsWZG4QcWsBONoP*PC!qge2PT6m@+WYL2S`If_XI|ixI*b~XJaYr zi>g?)w}Sn=o3zWJ^E!RD^?DwHcPEos%JcCV`Du2GkYP}R#n}QsYD1TTuJY6B`A}S2 z-^1p5rZp&lyBSnyx|=8E`8Wll=7iY?Lan$sE3hdSpKEXDt@Gr4VpK=H#}DPQ%%GHB z_x;oR&VyBfTFZQoca=)5+Z%V56KR`UiuH#_Pmg>R1}pmAcXt|EEv@w*fo_{}0du#< za%A0}=ss`tL-T51r34c-jou(HieB3gPOf*Wi7V5Z_xQ`;Hz@@+r>pNWkb5qH_= zW;+V7!RELiKRR!kPTy(nBUF0(-;NVxAZHKg43y>IHBU3QfmEfwD_Mchl3&77suVFi3;)>sF6NA}8U~emhpD*y>Gi11>20 zkDJr$x#ekw8hFOo^wn?P`2fc=&EgojIuFIsSKv4Vuj0CHlEFudr@ee2D9+!$!5dbm zvNvT;;F8GC-d!7klu9)=?ZM|`khNls zG8P_s^FOLcXc9eAF?rE&$FUUt8G(`|?P{?g1K#E*m7l2gIv z2{v7vjT)#Vs8PQ3BHTJBUu6lC>6Y>Eqz>*bRkM2gJ{1Fq%0_N`a|CG8-B1NG|FB>K zMt3oTE^982qR%J%Ag+d5DoOR-!B+mUD+zPi8WooBH`28$>LO+ZDJz4j=vTksQa)PtCD!5N} zy3+^=z1XDzK^~JI7+o)HKC?d1vvyiZ2wmS5ZFju`1Q(1^-;PgOgp}4SkP} z=!$Ep?qCHwUtzY(f&1O}pFzA(+y9rJmAQ<}g3Mnkp10=h>D~cygnrp|P0#g!z95;h z70*{6QUA4@f9-OE-x!*vrHO#OdU_&E`G5b8hrWZM?>{R#`>yo=Yp=?7@73&wsG6&w z)5_o`@4~+xu?yA_a$wKrm6?Iv{6EjsmxALz051W-EmU(<&@V{n=Uu1%<}m0&lbcH& zQw!ZL8_R*6%7c+t>;=nO8%i~<**SpSQgGM8jz7qq)srULU>ug>DSG7KmQNS+G+N$bO;Uw!mAcSydaI7q3X{n?8H1sw+X*(>x~9_F+UlAB zFEORlZ3l}~cg*CQe*;DAgSL9M6EkDM@;^s#>Zg7`MZa$DO1l{5@ep`e z3avtIWv9`WAZtFo>xM9UoSv4Qc&^5wor2+#0Va44Tv-+4KPu*^QqZuVRNR@=XV9IN zD5>;$BnB`q*vD@t zd_xF9JOF5l!$1CRj^6yLtNnN};??s?6FwHiM7a%n#4uXH_tK<(iSMY>QV#_t(|`5G z`ue1H*d#sYp7D(^2MQqU4L;A>zfv`M2pG}jKXwV^yJ0{F2szsHr;!Xb?ejNA?AW{F zfnJD~oSf8A7qG-hE6v!mAHv8#|7jB`5Wdef4UQ0}@2pyGy)p1ydy_ zyE_%v6U%%SeZ7(ZAR=7c@n_3%Rd5%4WVtS0(O6s<`hEDk4mPwv)Ih}t;quSM3)Zd@ zuuFh@0#I)ORj8y?23oIA4(j#3+nII&e%e!|O=1>iWU7LC=(^RwV(St;Q16YcHp4mC+>G9(N+Fm{s(70E!fU;*!l}=nXHIHI)E`7#XT{ ziT`hebt&wvN}u;bZx_9e-80^QLWbqQjqwVI zRIz=qGzt*A?yXBORrD zb*dKj6gcb`Yl4j3Rg68=)f~YcU$0f&@U?bh7j1vrwg?(AK$f%v84Vp|hDhd?{n=Rq z5{<1w^yQq(Z>w1Ok=VyMShDr6o*ffM)UDYWd}%5nd&i6MLpW!xGF`^w^x+vF`eo1) zG~KGjOLm{D+RC>kIgTP3NlE}Db>mjeraF9K5Z!6X=r*syb-BAWvCX1rYO0kPE$z4m z;_LuVSwI=K9{5_~$yhI~ty?r*`NZeN_wz385&FF(b(iFyA`^Tr?su$cx0ep99eul? zyeMD^vc`*Bt|f~HTO`acO70WBx8tsFkLD9#g!5sUdeKjJ5(`OAea|5MzPuViF9rn~ z%6)4BD|6U!Rz2@0#aWXlY0(0{SFp$v0Ih_xc-0ast&SvL;PriY_hsvXM(adDP2YC# z!#El)0vZX6mEkN>2Ax1KTM=3@EJ6&can%#KZ=@IUfAo@a7G~GJ$jID_eUU`5E ze33)*)3R9<_C65)NA-d;g#I-aM+wb9)>1)KjfR;j~sMGNdgkRsxgN83c z(^bIgt1a?g1;U|rb*Bw2cQ(>L!RzCyC0jjmO&eG{^+rn#?6v~%4OY1FS zA^Eg%>Inc;pb+nzBLCs7jUFHIl{Sjo*U7mi7gJ(lQz^Db$lvDozIFn0197au?lw%f ztAeGa24HJkxq{0cIRW4%?LG$`)(=h;88K$(x;n1|WrNTwkT8-plImxG`62yS)7#`E zH@M4kU{cp&u}+E;urxhxHOh$vAYn%veD)?$fS#yjt+u=>W!%0fv;HjRwo7}3+qx&K}Zmcx=Mc)COLi;*hZzV=F3o9YvMt+Cyeg*w4 z1ZpSwr++}D19D5b-%J0isZnMKKmA#;e_yaSQp~n(fqp=xm17 zmQLX4kKbE_xi+{VhYg^J@|$gzBzM`$qzBS2i)LC7bQj~TsCF{6)=ZeKsyYE-cvl0+ zZ(H^Dy5DB$^-tQl6BRG&(KBIg*K^%`YC$4ONpa13lfs6u`+BcsKTd>%xTvg5row&*PXXb zIDww819j})sDw<+LfOlsQIgVyPF>De-_%y}YK~Nsvj|97+Wz4IvH>I{?i#!JIbr0X z#&P{J<|qDZquL5Geq~|$EuaH3X15RF*#vE|!Kz3Y-+n1DYA$C=e}$88=?9S; z8d~F`-0F{>5HB;3GCbzyGV6(=Q6u=YfYX7mslTI0u>F|f^StYNi!=MxUTFCR>y z%ls!v_7#UtI2(~`#ELyPl#PTefup``heJ%#%2~G|NEE#@0F^mgF$y~54?9+jnAJ`} zUn}#Le2<{h^xF?WL#h0nS-c*){T0 z6XizLuh&a6U7brCUsP2%k7$_ANXu#jHNJyCPVo-JJgW}T3rt_=KOq&p!PgZb^|d*A zBDSK(5LZ>56SA#IY8x-2eyzY72UYyzkYf(L{NA}W6*dL00Ml;f`#Yu<&vH8qoB&zA z_pEqSL`Wnwy#sSolM|1`iiUk)rO+{;_MdNvrR&{;L-Jh?J95QVr4}u!1ER%rX{w2N zUT#>F;iad?7X32DukHl2TIOu+PvrKQ>`GAcC2uG8?Cuy*t@54YSNdrFJiO1OH*{3# z2?p+St8MJksjIW2_m5=wL{zi`tWRhs`Q;I4AeIqfUluIW0L|;;i>^5>#2g_0=637>#saSjy8TE6m{PfX5xkLHV-&&4%Y zUv-`^;Ks6B0*WjB(xQ_Ro%as+WbXAeM)(0{he!>&rMy8ov%oB*s$itX0;tcP4GF!Q z+X2O>MQKG>K$ey*5xZW7kWCE4+mVb-_Lk(dm6duH!d(JjKM2d9b$rjMQ0^aKdGWC`W{TtTL!HKt zA$Jcwq(rT$II>5BU4Pwc0_YBcR|Pugu^?)Ka&2MA2hUCDS0{>hlu0GC27r zf2*UC;CI269536PU04=>*aP`;s>JszPh;dS6?TAz;(#;abX9ygh?<**9gi%Y)N-e# zZiR%GneREyBwR4K`s#`GK%KD>!|WITG+~$TrTuX91lbF%1&Wk1Hb6=f*Le)_nw{k2 zZ-_z-3u!|)Rij`I$!*{2xPbfl2fI-#uZyLpomd01`FW6fdPaE7IDe_*U|=;Gx(B7H zBiduXJ+}+bpQ>1iZt|%M4qsLP7~X(#y3I{z)h!QFY&cUWDSq%LjHc_v*?he(l1Xw- zq;f}gba-0#k6FY+mEojYVaZxqoD+~k_RwESTjiA)UNw~3!e5Cofoyp6t%%?DR<+r! z%mgA$Uo)>=EWD-L14xXhby^t{Av$W`4(@OIL|Nw|vY+rH>OjnJDCaw52wD zyIyT|BjAylv8{%NfW|RE>6hoOq2Kh|Iv?0t`OiytjRh9WPde2WzO<^10i9Rv^cb|! zT4%&Pd9)EqXy-XK%V^`m?P;NFl4<8r6Y8ZyQ)~e99`jhu~6V_G}d!g z6KwcPL4#rRSWql*-}%Y1&NBlM~afLB54tf&w zLhFVsblL3nc5m_||4~?>F>@cR{kefOvF7SP|xU$yyW3AfAXyaj1Y0TP4j z5B_J?u1}k6P7XN(gO#Yw^Z)~@FXMAnL2{6fw1V93n>DK7R(ckt{AhB>Bdfb+{M&p` zP;@zEzM?u|@oA?4^7P^g*I1L70IR@yjHkU@sIsI6R*^E=FpDSdDi$>zll`28akf;3 zjTtYu3S7P~ybOqnI&x##)10bGS(zdqnc>0uZOKbs|7^t zhjE8Pvsy6z)eDZ-UhPJW8k{s5S|#kR`pWG$W}W5Xg&Z0yOx83^Se9IF|ky0C6`~QoXPAQt1gdy{~I;WXg{VUeI+`<9FZR z&4^`z3MdgOXYh-ys@r@4N@Kcw-SGa6*oDE{{HSs~0x)Wo-%-@~^-foY^9XcYdBhV` zf)$eK{l240zHAjo$*9_rg0jz7@~Is?vpx;x7FiDj=c3mw_+?l8yxhY>M30PylQpje zx5m_2C&uX3@i6R<%z%rtcsfZx;#iU9qx)dbPRfR!TpshD^!Im59YX*T*}bTcl`X%Q zof?qbcMtQwd7A^;Zssf-Cft++8-m zU~2Kt(%jx;FhAEkL&2$rjTP7(I$r>~aTbtV2vtckvN9o$LGkwejPQe|9O4U-Foxdl%v-1V09A$c1K(ILydX_zO7I*4sWO zerO6~3<8e4rsbxVpzp%sb(U&dJ`49-x)S>Xde^6z*e___{xV+PRNhHS;#wMri9^RS ze2fmcmX1_kExPXgv^&H_;_e^zyS2k-KDc#RMxE%<$!#6D7=;PEoDPq+*=MPfBZgSs zTiDewA75k~=2>MKJAH2Lle$~n;^&T*+{K_|$@h&m%G+Ti$pUy)4#8{v>zpUh`63Pc zC^iDlf?A*~$I}jj+&M@JuJ=phqx@@hVpbM4pS6DLY2|cBF5n_aFdPpY(2Zfg${~kf zJKQobX7{NtPf(HiSVgO>%Y-8eYK=~)e^)Esi_1mMK9YT<$`}!T+My1IJ10FHC z1%!DtHOLpEc8gXAGM;n+3Q~e(y!XD(<{TuXZi zm20=nT*sDQVR<Tja*bu)&m~tMBV6^v676FlACMgdz~PkJ#zI@ zl^yhgk`Wn{u_xB9By|Fc8Ja(Favk(5Bm&qnzRGJ}Zt@wmQVB?Iz4y>2C#`G%lwv!hnA=|DtT*ZSzHb{Z?T8 z98ZWl=Pev(K?!Jpz|LUbPZWaU>ET#^9J=?*s$()c(=5yF_gbpw@Yu@5Q}r$5iU)H~ zs+v6{eoypBKZgu!j=gycn_fK0nt=}&=-0n+8XH74^@{u`vUw_ zI}M~Sj&De}JwLy8k_$HpkzHw6vIf2R^j2@jLGl%7TIR^`8j>|S<+Y8?UWdACRyg>) zqoqx{kD+@!A2~4^AE-_M(tO9n?Y)1B@$w$ebJ3=yRXFD~pM9R*m`nDEB+#b)>vrPF zQG%f?5NZQA(Ir*<21q(wd#XF%#}#xz^z^aUtQK3_A+(?9WmMfinU^jW9yTE5qW76i z_zjdP@_xyEG12P`Scu7IK`y4ZsveXr+t6IkotTA9J*nC3?s)*Fxb7wF z^GuyrfHAAS9^{|ufoBh&BP&#V2qjHiMib)+t)Afqpumz$2eUk$ZAfW8uNdTVp;2Mq zne4g206gWojevZ^;pT4x!s>U;;V(hyg1P>6DY4R^`lTBwX>xf0^yiv3WOr|sVqsY7 z?@tbvo_-hcZ=dWfL(-$E^1|@JxC~9x=HilgldG36dhNl`?W!m)#wwN%p@Bu2KCul4 zlgsgPEg%mA+j*y7{=j{%I@=_7Odz)1TmFe6ah@Jm#b zetGoHQbLP!5>CWKsnZ_$R<5m=?727rG(KyJ72YqJjhPJ0R#qMzs?_c+y9hYAAG$dt z7gcT@kVWEKo36Tie_)SiRlf!20UU!p;Lr@|_tSn}P7|Na+L{pD{Sagz6ESe(;DgO( z3Y_R)BEz_|>v(>C)X_1~8Y*@cIB+vC z@4S`b{+@tq7$E}Cg&q3FURfT3lu}e}+%h=YOLD@=DNCibAnLG{!L()v#*B2>j_08h zGYu-q4nWsn@$C-K3tp?! z4_aSY8b8`$oX`~$!O%RJvsbZyD?!OPX6gb{6VNRQo>=RzQ)?y`)`1d)^s$#W?Y$NB z;nfewc^=VoIa5u56*>oPLn4uEF1Jj>1y9O_pTn`xAM>vCJ~8bD^&XP#bWKODr10{c zn}A1*;!i)H9IJv$=HZUHp?X8odt#RvmYH-3h?iHWIYk(S=6y(0Wj3k%5^NN(0_Q6- zoB`ex8B`;!2LPzk`Nb!dlkMvmn)nLf1!RT$)C+&t9N^rwa{x1FkNbJ?2U^P?J5-&v zq8!$KzF?k%yV=+Z!2`C;kz}`Dxpx<0_&?QocdjkJAS(oP;UA5yI@-!6-_Es;?{rJ+1PMjz3=0erkdidGYFK)Nw0$=1g66?Mil+;5$58vCAemu}K$XmP^Ad7cu~WIy*le&r$22ma=B2O6wla1clinEfRM@OB5EkGdFWQB1}yA3lD@_|AR@> z*Cf76qFnt+WKL|XT$MW#^XzWWr#r@zsx*8hkomZ9Ga=<=r&)J*lvbXVv?(ZJf8 zBPYPx=+ep@|I)8 z#s+GmUVXb|3x9kA7V_JF@Nn_8W->u2&3!rkjo*}o=XY6ehxNexn_A4sJ!3kzIcjbN z6t)1KZo^;@-S7%{fxvpNAFO985_Xg~{ zvDc?lc|z2 zd(3k}?6sdbxP@l(wukC$8#rT;f6c3BHX`-vg*JcZ$N})uvi(#yU7=JqFHI%J=2SYI=P~ky3V?CPn_Jes~^2IDA7C+vt>oI8Gtq76=VPBytZ>X z&)e?y9j;b94+%nE=9!5|fg?Y>S$nOK1<{fY?gJC8{frwx!r#pKc~BAGuH()+PeV-5 zzG2%gbUP91RQpP+~Nm%VCsEn<$<9#$2$3JQbonxoUg%*D<{K4-o=32 z&aYzm08RLVW8sjt;`=IJFf8zXThbS`yr~vG|D_b`tXewQ3r1ln=0?`_{lw|BwY`Mt zN--zZ#X_c!p+Msb?-Ff5NYX((4z1tTST%Vcx}+R*GH0GR_@*OY_OJ6d8r1=oxnc|w z18^a8wS4K5Qq()IrtqQIn^Ozzt|~v)zn_{gi}iQ%$sdm8z9uWB<<@-fDyT4Bihex-%2 zd1tf+EBXP=+4F_Cx_c>)iQ2?VVZyFrf=CnL2imu)H*ChX+$;(;n6-6tNS%-T2~ZYn zfhla*CU1FrUI6BCfGIimsvlY;hZ;WxjVu4g#Qpsw2-RP8ol%^thB*JZ@^YK?cEPtB z$znm}!uPN{Pr8!NCup0sI_D#CAHKD?fl_w;Tc{P#7}8x-sED2fg<_d_Q1km@YC{b+3Y-E0vQ z(V&BW|FDk#<6*6i5SP^CNWRB_7E;L5>szU1{S6g2pe`hp@cK!Yj9&fx5g?2M4O?2! z%JlVyo{gm$-~g!iIlJ-3*N>gsP=vL91dMLmuwQ$B?Dzc}?{59z=IJ(N_wfL`&4se5 z6+i-;7G=|Xemo8Gy;<1w6`Q_d(^q^nBXv_N)+Mm%D>i+_rmwK7x|n*_tPf1h{_xq< zicPK9)QU~5`0p&|_hw-emf6IhHu1ZUCY=9orWJ2xG^%9VqHFqgDQ|~D3C zPw%vx`mP>3tg2RE&fZeOB_GGus%wru981NSqN=Jhw|~9z?BB;PNNuj|*k^w9%D3P7 z{`e4bLwQ+Y+m5mwznuE5BqI$JH(P}0G2$U}phjnVESZZj1S&f-DLVvh z{u5nj)=<#^fA+L&;n9gW-FZ1ZP{i>5bIHzub1us~W9@FnpW(&f?@OZ#y7R1sE!OK4 z8|$A(sh4s6vlk8`uOEEhXbV8#bHoxi-;hHo_@gNwzO&`j0nf{r8l%*+u*YZrIQ09& zsuIU>72;E!uKj-;x^VXDkY=E~XTPG?mwz1EysZy{*p$`>Ic%=2KNMqA6F&%I(?Dz* zh)w6S>8d|y!Da;UK@OYo)(1IkMyG$sVbeft8i>se*=ErEK?^p6<_~h%+*N;&!~Ze6 z>fcVEB*eUC12;x-*F|Ie}#8!N&HF;sq}ZK%ID|jR@;1@ zF3)xT{x|gN)b3wgbx*0^wS;Z^J93rz&C@tAAPNKwQZ1L@hG8)vX2o?wu`Pl9-}ELre#ak|PVf3AA6>8RXBo1>L3 zCKFsECX>gL+zVH6VetD(;hm#V(~vR5 z^m~hK<{9y5vl+69%#%z-SL95QX7kgZX>G7o-1__;;mc3`+gMOzMib`&ei5QHSD$z5 z(7@E6!Z;6vfut@cH{~kJQVS$V6A>%w8XJYbfkccodqeq*9L>6&=c5u<#~W^h2nM_n zSmk}+ZM;a$fSRF>TgOrp=ViCIOZ6HJCwr3Qm@95IKrT45oNMOUnrb13^j`n@YIB}j z6?UpfhFnQ3O~-@Vx$1haIIiIHPfg8S@08kgu(K)i8CkcB6b_hMo5^R7^x)*Ubu`(hKyaH@z?a zyc@943ggS5GVgr&!D{$&F2)P@P-*JIy%Dz!c6#Yz5rXw|*t9pqYM5a-?c%6A5c2U| zs2Q*j71`-asMR>-=?MEQO{sWYvcfiX%^BFq0o7chKmvXs<_QzM8i!e z?mhn0F=vRDj#@LlZrD*fmiwv{v}5_hXm3Q6B{IR?Qf8_kMzp{Ii=u2i`ekaOwB`D4 zsn)c-Na5&>rFIeKKQzA(a)qLW8wb-wRmSTFNt{^|_#2%sG-J5Q&EYq%(X7aBIb3*h z#TOg2Bc?wL#eKo=Zhsi2lY=-H`O;c7Y?zo_HmBTVlhK7&c9in#?-yz8miMIc4QySx zDV3NSa?DsuYYL3KvuSPwieFO%lW>sn|4~Ard z&+kolU3Dop#6%AV>fM=La#+l~CS5h9&fAeTgtZpVpI41I40KTD~nFG#njd(B^%T}Wp}0c-Wf|6q-`h?xvCowS@gydgxWQtXzbv&pO<(x68VHPD`xTjRr~MKqgs zl|lrIJ!pnuY7}QYE>6}SnB2VDaYlha&%9iuH5NQGox|db9f#Bn>Ps@{O-Twn40BHS1@8GOg`n zUtDN~z!FqoOXFdF{NX$$nK<7y3)^#_raHt;`hGVx)pM!W@Dh}uXU2J*$`uK;0_R^oj=MYDj>p95!i{-J zNsDRnia7r$azW>>5V4ae!bG+cTh2c%4k(PsMGevdn)4X?IV=SGZVJm^G?Rj`>)#*C z7*B7b-S(oSK~1&r*M4gEH#j1@CTEfw-fGDoQ^ub}9K{Q71a+ zot8HjDx?&wPk2lA1xC1N21*IK_FKKwk0wn$P!4$!$0SrLR+Gk#2E*NZb48EZsVL~!Ng3Kq?T-8PC93r)aJtzf;BbSZgVa;TF6 za{m!NdwaXvz^(D%!6BUlB(kG1{k)myl4W6EY8pFMG(<*~0De%7xiw=@!e- zLwei>tCZNMgY}g%lnwWuap>I*ao|{d5Ap_;uk~h-1=?yYQA;M?M`*EZ+cwnXyF!!H zD5)!h=Ets>amN@v_YiD#hp{3tncGpTEOM;Jxe(cmxDt|4jIY-ITC{89f|+MBW>#-p zTS?rFH?em&_%0?WlN*w5k)V1vG`G5I>AYu2gom%-vI@~!u-)*9c}68vV4bxDMOXZ5 zqYt}isI)`lNZi{JtkxL*xx_JS6uYc34GBBm6sOB-E@Bv9kw{|*jMoZoq_U1w@IQ^a zi`x=vt!Z&O!rRZw;Jf@bc~4^~^i5t@-n$Eh{u_3$9l4=>)=c- zyyA|Hk=*=91+rMu<_Qe0VNejF`{jE*pdGy_g}TICLY!_j&q$()`PGCGaQT?G&6SXO zzIB1p20`p&MF#vn;bV>ZMmI;1#exWS#iXP35&mDMOA)d+r3Plg0P=`32sRmUSCB;n zmmOhJKFqW_;$3GBN@M>XgeL|6Ks|Bm9TQpD6sKcn89~^( zs+=3M)UboLs}1AFgpEr%OL3qF^su7kfUBH@o1gD}HU}!5g)o%_!L$$^2!$KAx>0PV zi-`sS^O5!$ob5q)6lDh_lR5S7nSz$dbkEQXwLsE8BeGQ);Z{whZtw9Yv}RDuGj7gR z&k7=PPDt(Tjbb}W1EH%+EYIm3_Rz7$@C>JfNI@Y@#^-OhCD$d{*a0ukW|;kqqN zFc2&3@6!|tE!+ePOg$6)BgqA?f&LtI+T&TLxdxNE^pV#PLKHnj9WbZ^D;^*+p5JK2 z)xw9G(pXAO;zPq6*J%1H0;f_(jUpwc5F(fED&$ro=;e#!Ojqql;k^~egg}uV?l#)x zD)#0@NLR;9Q+J^8HPRP>P_f`Fr0J>T(^s=@F)dHhW$kWJ4Y!KZK}> zJ&nHHcUa1A%W~6}=@>RUA80(Yag*R1q9_wUS*j+|&-PZ#H%Tp#2C}E@MR%U|`tG4F zKjpw;I4ZjD6+u?KNLwpj-?tW8LBriuqDu5x3Qd>899F^ zl*XjO(x2S8)lmM|zZ-OsL%9o%2Haf)-DdyJY!;Wb zPcSxVpXG{f@HH1jz#?7>X;+#-(3_5G^+2y2my6SNhg=K2_BP!Srb-~&0Sg@lqv68d zIh&)lI@h5GZw1s$J{=;c2t`U0)tCvQHGd_aU@XkikjbfV??q)1o?j>JW@wxX&DvaaIv=q-&Wye8HPD1Ws+8t#0Pqy6q#9TcXRvG6->}5ra$@9|h-p!noiyN8rsu zaqt$=oHg-}-Q2q`!Imb^%79iG25T7n8ZN8A<1jnPBO`+D9T0epbg*`7e%xX6kAvbG zZ}I2eH|fk|+u&AR@Nk%>TkQkxs5iJ61N>1j92G#$#U#pFGUId=1DbDykZFBXWL8~` zlnwiu-+F2hilV)k+A|>L3+*8kz3_nJV#QJD@{a;J6(Q#9iDRo)g`#WUH=f$COg#80 z_sp=fC?txAO;h5f;N=vl9DjGH;R^eag_f9JL=AVM7pV^!rYZ%mrk`(&8EL5;v91Yv zD-$*KKr&(&JFMz*?0%`=r(d-TB*cGOLzQwIFNyG8BT z*p>b57Uf*|Ba#K-9jQQpt7y0uvkg+u%h&<^Y2>pFmOY_yj)N8t`&zm2#XK+x3n314 z3W{l#2_b=m<(@E>h%2lOU3NCBdh0A(ktp6(Og3DQ#DgvHKrd>E?`>7CT)$!ocFL723I1tPa?14L zpGuEiSNd_VffYT9iEZ?@r%_#}EtOxvwW@tPOL-^Prda2LzZ;mH@`j3gE8@u1f6TnV zOH9Idovgbq8cRWD_ddI7l&VxEE$@t|7&|7E8pQB$HGw>VV-ga(n%DJwmxk$4F&Zj# zG!VBP_0Ju3V*V;Gowmg@`_VbLXx?sxU|F;03?;m!{W-{Tu9R7F6k8IhpStRjcQEpaIeUQUu71akhY*tbIA&39J215Pp z!~K8$d7AqsFX6xc0)L7AE>8Ea|K5Lg;l2v-r;iR4YXl$KJi(?6{@1L7)Fv#7zj`-< z(ljN#6Gk(Q=#s5XxOdwAxm>{l9lT?d`rylmr7?E8s@TG-c~683m${n%(Gumj$a}7p zF4|&5^!9sAi_NQ_s$NIk98*>2=|rHyUY>U1b7soZsWAg%GjRw0I`cxU3USVHPy&WJ8!Zn5Pdp1bbZQ4wXC_j!*B2feU{9NMlUX%#|by!H4w7kIXYND0r3r z_>WHNcTL{&Qt`BGdAFmsGv{>(VYJenm-(Rc>p0!&9CM|=uD-)~rDTY_O)GwAk5Ou0 zK!g}Ztq-PHNnR;5^bue6gR(FfeGmQ?`l^{Skft#ubknA$lN0hg z!R9MyCK1hlHQi}ox&BBSevS)s>)09A3w|ErfHyScPZ2|AQ+0k?e~xaukn;rOtK~e9 zVM)}~G4<__OEb?H>-osGJk<^qpYys&t|l=8B$zu|@j5QG?(ZzaF*&S2&r2F{y2exI zPZm$Kb{QdGR()DziyWn2@Tv>>$k-Gs`x72sMGoE9gY88dq8M*1GuEIDFNzcV-d(V; z9KA1>yF|lHa($WZZU5um!|rNkxPdSE1t3HFPj0E?j4<;e-x+v zjFY4rGF$&ew(iF!)Qvog2`sBS&Fz`Rp|0woXp{f zDUn`R24T1$p#(@Y&bc8)X=3@&Zla_7@O6N2%s6;eee4XP15K*TGu)Gmu1m+yI+8Rd zq}Gd;Zeng6(edfkj=Ti<>JWT&E$347EO(yeF&lepCK;maD~VT!pRSg8&&Va4hKkx_ zW8Qg&oQFLxK~z?w1L2ac3qhU-!PWn})cgI(57dYWgtM>41*&qBeK~92;&$H&?FGuZ zZ2Ze2Za2mWSI)`3lDG0I-KdC$zy6LL8d=~$CrJ7>JAe`s{HK9F-+qb}A$eWTD$02Ia^5n(~NYCO1ZEiQ@5 zyYdkKv5Vq1JoMd@*Gjv96fw34Mtkxu&hiuUCW^^QNV?j)bF;s6 zvXrH*$rMy~le6q3s$4T;B?*A-<&;yX_ z!#AS%F?amw5l2!;f}Y`Gl!YUHpL90es1BOG<7Rp-GyvJCyH zQ!z|`$)y-gCT=lJPWn1d_pj3$zfM}aF#8K8zz2u!dV3F(eE~m6R3<*NllKgLY$Kg@ zw9Jm9)VzOM7XP(P1ja}5;wuV|6IEoA_LqqY{Y-T%uj@X0gc*eN<}GxZP@i7!5!aSK z3Y9H%b~-*Cd%vvu;?o=*avbrx%86=nJzR;6y|LIl1B>R(%#242q}C`+C(+_O+RS71ahn`oY1xp^?8tGM$7){UjL_qYhy{p$wd zLsj9i?Ut>ovH1$^W61Q(gL~vXrEjZDoMg>6#-Q3RNAs+pqtSiG+ErqDw0KF)L9K5Z zy53=RA&(>IZ?N9ni|0RDbX`#qrhA3+b;Ac6Bo1B+<{2HvKv|{3od!B4wTQEs>n?9O zD@3sHz&1W+CQr`TOpCc}yu$T%O746~$4_22I0LDlWe$Je>1bxUTBtMKu9dPj6CAWQ zOwtaLuyNRIc2Y=CV@#%V2Cv6?TsZrZ_T(>>dssO4y3`@gIl~;}m~TnPADmfZ4yBV? zzH|Bw8YEC;hwq3An!$#Do9_pTs9%b=$GZNtS!QV59O;fUJEoGliWJGGD5y~)Xs+< z2bXa~POEt9Zl5owQyZJZI)i1a2iQHCFDtv|@~qn#otLn>DflaYy)XIv73Ylp)3l3T zJw}=^6&1v-g6_%^V8yD3@1tYpT5ks?qXat1Ixxe?kn@e9Gu2HI@Onw8Z9_)H()L-3 zk?^7w&`nX&UAcp-euX+Wv!V9yZK5^p%?f?Tc6ld=tN&W~s;6@R-Y%OfnABfAOSQJx z6LKj3>cU`?L82LDTWsa5KML7@`aCR2)~W0mIAJ7IH-R*)5>nwl+f+?>1K2dp^kQYC z<72&`E5kxM1}0@b&`H<>_e?USr^PtS>iN}hEuFvg`l)&e!@=udoUR>3h3GSEEJbN6 z6A(r>uRWI)6gg@&FX6Q^6!yHe!Buf1$bcpkHM?VuWQCl?;WtbAmU zD>0#37Fz69@JuqArKBe|U+t3cbYQxyd{n55VD+bV>8vbfnxalq6-sTqO;Y|6*M5CH zaNepXZP2!x~q2PorNyy}F>#g9|_H9M5dVhOGvZ9)8N!k-nH4 z>bzA13!#sS+9t5##rV!rMd~dc&K(Am&e#%OW&9){ zns>(Ef(a}FTC2!(WaJe6BlG@nFdMl3`7GuIFMf5JHWbImPfHTz>*+KEt>g*8)A5 z&eBAay$rM)#$9}mS)<#-KPtKk>|6|1u*M9zg01I`6qyPW_ literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopilot/images/wg07.png b/windows/deployment/windows-autopilot/images/wg07.png new file mode 100644 index 0000000000000000000000000000000000000000..bc5a81bb3fbe0721264e1a00d2aa6aa755fddeb6 GIT binary patch literal 193713 zcmeFZcUaSB8$XJrLM;NV15}pQ0g8aKS3pV?1sTfTMhwW7Jwg%{fhr;@OE$`g?8sgr z3Mvwo5J=b&nSrn&frKQ#C$@c0d*1i_d(L&8tG%dYSn_9wea+aaf4Wz7lI~x3CCzXfRhoOI7(XUj22#9G~eO2EU;2 zsNgvn!pP&o+zFFtfW0L(FET+|AFV2m3R^=co4I?35gD!KV6+ z{+RaXd1YOHzI-@8?2>n8bKl4;XAwRkwKKAsnC1F-WHFs$`q#@|_vM3u&-3mpzsG9C-#!|Yz8&=IdPls>X3Vo0eI_o1=WG&pFx-zShO5~n@X49W zk;3>0kFI0WF8D)<&;Iz~iNaHV{?A1&X0D4b+k_gpf0z4_H=z3Gk37KOCxe-G3_I#N zdGJOGLRc)MGtpfdU9D7L3UM9%9iqDZahC90N7m7Y`hYI4x(=SdqC;>9nW=z22^oM} zr1$KQ7$d@me_r~OxW|P)28+~Lx-zDw@aH33=N$evpdb5kA{Cv--KmfJ?jHuP=*qCW zn7vJ`X^l@Cu6)%~AW=Uu43rnHTTbUu>qGK`gI#}3a6js=Ia|r; zoF$2c2Ode#2)~@YF28Jy*`eJz+xA$?>$k!;2Bs+AP}gBSv9?%b*uphJUv_uKd4&J= z&Ep?UUMN-vw)64Bnwuzk396%b0=;J;Wr5F zZSi9v>%N;oXH&C?qd{9w1(}Cm6&~_E+(=02BOymV^5^R%ox4Cl@$SV(fCZk`O;>eA z?^^QkjUzYxxd*PW-2U1jLinrcico5EV+qGOXm3t`4ehfFyv&uMCx%vF)r^Zt)Q*t) zQuqovdZ`NDx~C+JU57u(ok9CC%2(4<{@PNU|D1%|Q(z|)rDNNA(MvT&%qxir zWv3-euogH*&Sy8L1?ib)O2^DKV+jx59KWQX)45XS6 zQtM~HOKcz!eNR;gDf6Yz{>KZH>7_nW61OZZR*&j!Zxh$N#S|oN_1xK)`>ve*?buFC zp0du!cc1BWH&_zsUR9pU>3pM4GI91OVfZ-xb?Dhj-zwU{JWYNWL)>C$D~AGcPFM9< zP(YVQ%{MVhdQdJ2$6Ux-5`9&Xs%06L6koF$&&D_-XI-z6WLJB>=Knq%cIvM>hxOwZ zx36;y0w|7(TYr?YskuOXrAyw9=ZpHtIh|-E##!@p|3;*mcUVA~X~yn=X(o!-Z}F(r;Y z&>Kf^|NV@7;-CPisSZwmaWOHGb?wejuJZqB+Gr&HbT<0-nqE4`dYanq#`erTW?+)8 z5ine}_Pg=GfG@=3WB(hbPd!m|vI!4rm7Qc+p?Le@J7xtQzqoyzdNxA$t0oWL`ZUO@ zz04uK|L+Is*OCcXt2%9IoXH-axM654R_#4-t`n`ZnHncN59#mhJWP;|*YbMrE2agt z>+$NUdS*}UpA|Rx5GR=+uYB`8bn+B^{8rZ+DBqF9cE%d`^hqYxF#2yeZ_} zN8kV68sjgY-Ag+kM13lV%aFe|9l3}dCmDFZ_7Vscz+T`W9n{4-?R?){V>ZViA+;?p?l~ zTQevBtkLtj|H9yJ-TYrV@CT~-|7IS{w}?q6u1GAa0bJF%5pncSh*e%y>=f0Nb9KUK z1VGLC8}4d_C)|VNAX0yzH}_51#Ug8{l8pIQUyaO_=bARd#%HeBIU4ow|8a)wScZ-B zmVx-B?l)MKDQ$Et>62j8(ZP}%EAuO$S$9Hhgn4+XjD{`CTU^ZwR-(N3@!VxogEzKug>&^OPJ#kF zIWF>b6ImM%Eat0Zmwyo8VQerx1tGUS9yH2!&XUw&ERVn?Mdby+Z@Ku--*PB%R}LKf zk%k%j*$uKfYDBr`f+0!-|5~Tc!}D3h-5UF2x?XCFXw4NK9)^n<-`yps8Q<;xHWa5`*Vw5Ogjt~5KQ!g_8mof*P5X@u`w@#D8bD<`4@!fgtJanaSLR zWmIn$J-;nB&8mq#gN@h0-fpifZ=zjdTt6MD$iwqA;V%tJVB`eP)I5uPxMF#asIbOT z%b0W~S+<0NNrJ1f*V_1(!>GIU(VZG!-q*LHrJ=^C<~IwyBjU&zQgGIxW)tLI`~_5V zRoBl$eAg+h3rk`|9;^;#W}M?&>w?so>EtjzJXkT74fc?uDx`8VNtX!`>UqsxFdyJ_sW(ujs??<_$qz;j5T|e zPUnn&E;Q(A(6RqKo6{LX9GXQ1>joG1qEWE6)rt7Kdezflaxp(%{!1al7=L$RJbXN% z)azu{Hd|KfiD}4JHQYA3R7e;#ybE^-<z(*h>zCCmFFX^&Hbq`M%bKra>LG0J*WF4G#3FXBH zqb#G4R~v_B&>uI(@j2 zAaZ@|)8Ukuq)0`X$~5M1_kPpns^yfZFy*g_9W4?$GA7s^+D5s}{8CJ|hmYZ@05IR*J!JP!iLLymK&*ELV_KdU(Cg%p8GUA5PT1-&8Fir z5`F3%ApAF8Lr$2QrgS-rTlEElEnu3`?VMQiX#Qh1!q{eyg%HImc&R$%k6{fnRvMTl z>hy*UVci=>SqQ)JOktDEfOX7i(ZxGcL-uhxh=gZoAN8HQYzf5x=JD=vMBg?u>(1&k zH%COf99@^)8B0-QDKn~yTgGyJ(y9G0w_$3t)W)ABPVD!ktalKqEkgQ6xBnj=Nb|-} zhio61=-})?qzz$Lbz6Z+=7SnJ+sZlw537y(wi#Xz%x<}u zDwKyFKg(Cv$b426Wf9W3t@hyCJckdjVF=j~OZgk+ytSpx`WkaY7nhb{X~6z zzN(=C5|2GvlD7!zO(~+lDMR&PGvggnI(k$2Wh=k-aqBkcQ1fB!q7hIHTe(}=c5G*< zHs)$(KmdcjR6L|MT1ok2PUd7Do4DV#Oz1p{o_>!>Pad8d2cQ0}Oy3pSn(y8ZCi-BMN*MFYaBH8Sb=Ai9G}IQUQ!$RD zSao0-jC4>WXA~Z}IX48dUtyxP4<+8S6P82hc<;+!3jNZ);hf)%Lqcs#SvpnSI$CkM z(#&Kh+{&{Rg9D`H(t0{5)|oX={bwCXoyj-N3QRqhf_7}zm+;NUCKfKzrL-i2m|vyC z*`=Q8f#aKTlDY**d-3pLLWh&8jQMXUMkH@v{N;KDc7&G=;c0vsj^omE)`(=e)ZgJN z+;QXJ3SC!goROGfkMg8Q_t>;6fmp z-op8k5o_DLCK>5$^k@ueOwHkuo_D}js_0mRGed|yqedF@Hgio{Ya^364`O}7rmNK| zP@~ksTT_oaTJLKfPAuGT(-lYVM5#fTUu7vHZ#;nMzV$YNKrSkHSXss_mXZ=D>cb(|`rmhWU5SOt#Pw|f&a<2BXJ-oDuA#LL4| zeE087F!0h~b%F||X`waEAv0vGC9rj1QHQdFQIxK3ljGo=jfFhCtp5XyG?R1NYtr%7+x1}v|rD{`s@B!vWQRI0YLeas5_K%ack{PT3n{jWut zWlNNga7h-ouf)FWTcKDIibcs0D4WlZaLO+~oSCP<6wuxU{R$sz1I!9i$kV(2Il_;i zSLD@Z;vt|~fV16KN(|igj%~$fG;Pd#QciV5?G8K^srXY~+{@7;aCY#QWl#|fInEyM z^o?W{eucE;bgJ;d=3@0y4U6YdCA2X1aHhZeMRgLlRbkL{AvMt}`SRG0n z@*CBF?&7&%|966u`5zgr_>omNss?QxUAbM#b>(d?`az9H;xsoOfl+kV&38*Y(bi&_)|>kJU#_zdD^;RC2vnNBlpSno zqaUIu!;8%Vji>5lVj8G$Nhn6X_mj&gGas5D-9rAxjfn&IxIOvLX>m7meSbP7AE$p& zS7&7kvzPB6AFP5L4z@5+pu;-PyC6~TFwarxe-yX8m519Ux!v`uCGL$(N%*NTn?lH` zuClSp3c^-EOaAcOi*?`2YUWGMwOWcLFSWorNpdQgZ`_q+QV=Ig>Y)?4lpZ|d&LR{l z$V%0mo!M}d4WjG_Wu`s7c^=GC5{QL?a$$nH_lTy0G_m2^tfP##_4Sw)ek(pa9&+%Z zoV`4s_xy8E!;YoG3SIOngX&p010Xh6XH?h+F$%}XF>oD`l;TltkQIJx>}oycZW+vs zFFYfHvQu?9(XMK02y=9QO-c!P1R>A4o;{*t&zn8-XU09uqIC`>7FOZ+;zu_>_ic#E zq(G*kRm{-avB`N-xz~rx18jKu!&j3?eX8boFra^Of^QKcCR;RxAQy}kjcfG5gjXnvi8l+Fv%m*w+)b3Q=&gwf#e8(7T#hg1w z!G7S(oU9#{`g74-%w|&d_ZZQeM?rI9&M}xVFf;VIkm}htq7T4kN^w$=;pGYZ_3w~P zlUlJIOJJH#2aBgny2k?`eWxMydRqoczlRhf9s*@tujh;%&$^T+SAlbExaTh>q(=z<`n+&IpLNQvO~%50A!`zjKTjZxzPI2HU)T z#{|Cdt~w@vM5gxLE&`nWI(Qa8s5HCjgo*PIc3f{(q5bGNX9qe+0IS6SOxb(^TuMM7 z+*@<4zv}hqgMe}Y&pAS1q+40fMi~f{zvCnUqbDqZiraatI#sUiB%s; zJeN(>%;u@Zq84llch|CWMy1t`*w*I+aj*-$l%kGB#7+jL;3sx??#~N*wV;EEu_kF+ zoSg;H?#A_ZU>7??th0tVl7J(FX0g@fZ1SV1Z9O33Eugb~Y92Aj2-`fJGNwu=UL>6j z-Rj$p|< zG@j`#z{U5%G_6&obcrMKmVw9J9I{mJ`lD#A6Hw!PYI*`OX#tWb%B#NJS0iHsM?s!jCv8Ubi-*C5vDRftoQb`ICC*aYL*|gn&D60cvhSXSXGQO0Rh7}PM zrJfn${lr=F^P=5&4k@}t-+445H8*s@6+r*3%JLz%`441r$S`-uIh+xW*ImEK2s>jr zrA`Ia?IzN4xPK1>-+V|CubW$kpCj_fRmVTnilBWQ|8 znXp@c72isS(jIe4$Kv;R4*$|POpOLaw*9>=308id%XFyjjLxtSn5q0wLU(+0cKhdS4nXKckV%KO|Mzn=nG$R=8ays^APjelpi0N@@+x2n{ z;g{Cqn`=#JSD#@!KOqIWk-t_r&->OduTo!rd0f2IiFB>7K02iELCV$_cjq+EoXJ0G ze$((|rb9yfVUnt+wUpi{8gU?U^_KcAj3)SM9}N!Il0 zp*!oSH7gI_vhCRO3vS(wo+EE~v4X=Bda3c==OQYvDVf$&YpBtE#>8F#RVv6;MqK1@ z$GgiGh1)Nz?zc4F*0a4iB@n(d5Y@+SkZA@=oUuvYB;$JAOC8r`;W4S-l4d!OU4nWG>cv&u z6p`CbSknu0pwf%!AeO8{vVJNnjcZ<6e!ECy=3-83nuNtZtQ+0JE)h z)$_NTw_l_1Hf)MO&0uwbZCzkmso&`sDt~L=fE=AV6Yu zh_(FfvBlWz%hrxX6!WJMu9f-(%S0xpbfnXufU5%qZeQo6uCN*M`+G`tBu!b42$Ft% z^9QR1sao-XZWV!fa-3-RT73#btIxCzK*i-jfJ?G{3Wg*R;kLmsttx6BV^Hb5V%d-> z+xpHourmgx$a91CoyI>Xh52GxCN}3@SJSgJXA9tjX)y)(El-y7t!YMgdAt!S)gSs5 zW7=~TezH_Pg|2t1Mc15WBPudA0Sdv@T5Av5jr9xejzW-?-^8-?E4_8$8z!Vduc4j@ z6R8%Rz?me9s-axOR3YZ54Uld~W30<|W1&j&jiuP^GB#b}Bf3~#RHVPqB~o!HISY|M z=u#e$qeIxOEPKtIer`D|lZ|0}7<6oe_|%;2Y2I3B zuYY`cC!#YIycl+yI0DrxH}#JA)LU6*x^RR#k+0wtHu%M~08s>yx+%8ci`nELRWwRv zL`AAPBokaoy2Cajow7d5zE94S%A~Ne4vFmb82(_{_6v5W<^xnu5;PFU2JCfi+XCl5 zaND0H_|6vq8%^D#tJRs((H%qz0M-7~)b%XH`DU{cTrb*j6L5cBhsB(V5#yAem#rp^ zihpdZNG=G@QVu~9a0lpB)aipmv1K#k-iHQ(1z^z-=MRQXB?{|oSKJX=(6k2y4X0T^ zu6+O9Tf>yUD>g~Lh>xllFG{`2R7B4Qd`#(Do*e5um$m{JXY}sU*AnmBm#*8GqfLbH z-}EBQ@^(5)R%^R&TguKY$5gha12n`dYD0EF%h~`^v#LWFKOc^$ItzZ!F>CMo8tIygRaTMJThGVlC6# zu;$VVeOHIxvcu)y0U>1L%i(GRP51m*-)0VHkvKJ^X$5NeFv(6=D=&X`X^E>A9h6kH zKMSApWWGDP0I&|I-hGcm8rGihS1ezto6##Ric|zT&vY_V(v&oAhmZ_D$+E3KCBziv zgK-b)*-!e?{IHK|YYlX+pyLp6L&_##*=sT_WHyqrR=W9Bwp@jw=#nIrxXsL#&L{+S@<| zFEZK;bBGy}wv5xerGiyJ6St20%Y;|{x{#~dFTCiI&Iqk*6K1gD(=`7>ok6) z@pEm5iBrS3SuB$#=0tX(d>uFlQ8`xsn$sEz4Y! z;0+Rwd?gt+9~Iucz6qp)2}bNMBS-@Ir9&pK45wzSF7Tdzq$DTzBJ|wXDWlmKu&}$q z&H)XT!M|C-&!M`ptJUT;FaAo*Ul*-jJzWiE3u-QJD9d*i9%VM0@N11f7Euso@BZsC zP^a7m7{aXy5Gk(o?P-Y!NETGL-;Z zXjfH@2k?}Jvbr=mN&Jw9ck(Sm&1UGNBjHoF*64-O-25Jea@5|F@TmID7fLO1s@|XV zQpvV1<--YQh_ucM>tt-xFRY%s2;bWYI3eB($iK@OnCtzLcaWbQ9}8~dpRA6(*6F#; zj<q|-&5SS;W>ZLC4FzR&LoU@#0Ye1+h#gQL6Z*33a1CXeQ z*2s$Gb%l@F>5is$b_Ae_lN+0{G_jQniogWAL3oBn2F>n4HMYMNE`yZJ{=(huR2>e% zD#llFt)G%I%IFtRKo1No>MlMXw{Q0~bB%*YyO9S2u?Q7FG~id$u(WY=PEg}^-9sNY<5bGj-zR~%>1IfuQ$3KkDBX^5!L{FuETw7jgeD~UR4 zeFffHw30w95DnQ8-m?!C&Mq^tB&t|5P+O45j`KL{^ShE+cM;(U`W2``Knpeixv}cs ztAu6G*kfa3VSwP6pkn+1YdTg!FXKAqJG+#S zL>mCr;Z|++z#O4cx}2)42MGdu><{MeBeA9NmvJGgc zDE;-?aZV`B{=)LbK5O8WZEmoyWwzv8MdBtc=D|%)l({0;qh6kzy@gXoxR7!y(HN;E zT^5i+79e9bnV_-DPEp^L&i=wmV*QfJ(yX6xYI9SNt1vF0R}Ag%0tRm;q;l__#5#oO z+~k}d!p@Q(R>A*3Y&lHX(cKw_3jcB?1&JcN4_(@LnEg1^dHdvNDTD&{dq%q+S{yiR z)#W3y3+pn*#)m@9PQk;7WZWhIKe+X4v#z2&k`I76qHMtcP^(K)yAn6-CpuaOtPOYf zpyei}4?)WEyMN|9ZosZAJ6RkMsk+IvA!X%)IuP+OyRj{e#R8IcM?{q6s9H^+&9vNS z1l=$z=sBHQIWxA2!ljKiy7F-85ZmNlAgDsEUx^Zmx%1@O+Kw58agPnkCMuvt3~rUZ z+{WeqS-Uj^@m|O|cghjZG;QWbL7^9H1G49r5=&0Q*fX4_YcPsgRIB^yo~b?UHN?|q zB!n*l9E(0n>;742cA5wq=H>_wvH6T<7u>3dNd&g5;@KqvKS`1nyE;1_jvAowwxqqP zo4i*vc27`ZQ<|B2Ra92Zj~E0s7K=hHfdhX;Wa?$FUaA*C^6fwfB(dzZ1#L@QWbfHg zVovZ8so9C}4t73q#BG@Wh=$}KcURCb+kM3d)P*qM_(gAWCwpdDRpOvYb#l<+{g@Dd zf^pmKj`lt?z*R+1sbYOmo*sTy1s(h_57QJPLAD(G48j=5O1X1`yN@SeHoilxm-X9@ zeJVS%^V)hCuw_a(kotKAY6q^suRe-@>a81Pma+vFc_U=-<;8ei<|MDF&)n`sQ6wM< zg`dfTT?*1!qC_?5U2t^AZ~wNK*lA4HshLG|KXx3(N=J*9=dK zcrfj&?%6|cFY#yY^C>nkiBx16w}T*oy-QDqHRm3WE}(hAAE zmCnan^BEhWx|$dqZ(Kj>PR`1KpC0heNCdDqq3?M3wt_c5xtpCDxx`?8`i&OblN^)j zq*1H(nwsAqY>+WPt{1H|K3n43!V{^8FlpBYj`UFLOm+!poIi*U0~~#Zw&Kzw61g+T zMvCW1(m$Z#G+s;c^0HH6aloluNodT_F6nMTfp7^RC{?|7u-Ad^^w>*fm6eSK8z`fE z3Y!2qY}}qZCyx2@GGBKTH-Wh9yt6&1Gix#ocPc&JO`ZJGr+{VH5ey*Py(awV8?bl7U z)-=^0+2?hfx}einV2K1n?b7Oy$DJ;(Vuw>1szYsV;8)mIy#f@rEUIH|msl*#R4B zeK6Yjdmff+z>Br+3!Hjr^09ss}hq!zsV;X9l`2XA_sd zBrrpR=Q@c$@&x_oY8D8dyv1LKUyrYeFgv|o7&rOu3>y)%3Naz}^@Y6ZS8HH;*8m1KV{m+9{jKSX$cexCnM2f|M>AB`z- z=UTdsF7=ok(^hnkadC&EChFRb+QDK=FIB*|a{E}O z6(}TWau`ubZpXd*cS(OFiP;VrrC>@lq7Efe0t{!K@Mn4X@uOx8T1|g!`$W|!_hDrF zmkQ%=31MxPFy%2Y)$!X`wq6U7LV5 zp^4HpyK)@=0ctDyv&N^#4YGwi)AkG9#({_yRPU$p*AT2kc8^fw9x2q!2TabfdN5(T zp8bq=unK!N)8Fk;HGNg4S~{S8xP01FnEs=bnGTS?MzmxqmoWSL4q66Mb}kA^_~Im? z@o-b;p*Li|H+GyVOYIZa^$qqP9^_`@8v4?PgG9D5`U`2hg=2PC>okUG-^I5WWO*=k zjqg2RT{YI$A!Xe>i<^i)C!+-GHvVIV+TDd6dZw)AGCV~dz~sU?A<-EqM1)8v*R-Fl zz*Hc?+CPA#cx%uN2nJsJqD` zrF~dMVSp8>h^nJuhPUgf`F4ba-`@dYZDplTv~M#R@5GDdoJnEDwdC_1%<{2|=qoob zi&W$W$53OKaPoHT;>Ud1qTBITDqAZ=GR+aH4~%9N3^|rXNkGK)4K>^P zK8(oK4_EJ=WN9qjFS_!qt5A}OX5HtK!e@VB8;DU!@mT4XykPD)*g0( zLZ(!5bw{UcQI=nYeEl>VQ-DMW;i;OdO&gs2U~$sao-GDp_WWC-_xxRcM|By(EY;OM z8s^FR5HC~$d1<-O#v=m=X~A(*z{G<^E0Pwwdb zm}FI!gSnOr&`hHhP@9|J1t#U9VwD$xeu)P9K&5^fnRl$1$q#FJj3maHX(R;8B(vqQI736HD9%8dCvhyURDrnLSVDlx$xivNweA4yq`> z1%vQn3-}Xm*hrkHe5UDw2kE74cvT2!EXV@S(zOO1-xPGX}=WA?W9XVt!XD6yF2L7p6E|L!34 zQX6IxVP9Hn#Rv0cS-UvJ;(`3fAXVeTEMi#a$H3hh>x~qhn;8j z_#)T8B=p35Fn%4efJ29mXO=fv+ggvZFW6x03R!-vgw1q~w)d&)ONJ>5q-02NH6V|G z5*!klI!4kOikHhR{uv$nf=HYmCX(74=@Fv zJz}Q1-RaQc`@_yMr+R$WY;%ImX7cKnAx~iOub>E75436clg+_b@<4k6c&pDck*mP# zl5-$#w@WSH*|MHry&@+lHvpdm;>#yrvjYD-9dz$XmR@RbrhR>%G*S`3Ch~m!I)rO( zLydD=j=7Hb%g;D@gOx<^wP)FL6nk9qcWy>#Yj%84Q`4Y3Xvvs|NjAi!G=IjQUc7JW zyU+9^HuOrd?uq|f@Ym*HvrVNgb2OP8FzRJ75OxyeSPX5<78Hxdl16Igj)X`>rg7s5$BXsU^mVxB zl0$TG+_skQcLosf=#vG%mR>mII_m{s0xoxfHCe3%D6$8f=Z-R0btkjAV4 zzJV-35Bina7?tAqVLy=6MV=@rG+*q$K~p+Rth)F@@)Mk$YXEAbH|I5D!mZQD+Odqn z^4?@7Yzl`~%v`qfqz#Zb!p6h^=0?7?VIb(=rb!%ml{jb^(<*WHy=N9c7 z)gq8(=VTJ-Th{RzKwkrFeq1lX&s#IirIcF`WoPxo2ImN6^Yt7o!gsD8Q*bOPx7M}` za(4smSiZ|+wzGl_)SA|c8m(g26>NQg6aXj|#4@E7+7XS(wZMVt3TNNeBRq3W|2V!5 z<=AVR?igU8NT0oJF&M!0fPu$UW(#r&7Ygl{QQBv3f5HwB_P9BZ&5IR=3FDhUGLZA4 zHN78h{KVH374j(&Qy^KrEH@6q8JGerH$zQHF7osN^`*`38e*7P(%ocA&vceb@hKl2 zwHJ+2;k}%4I)oeex_{~cuQ~#e@^B*ZOR1FA8LAuzyS|Hmwlcjq`4GzvTWD=f8)yTm zsC-b$t=QN4EG-h-a=WPWAgSKH{643XGJsz61n;f`*DYcLWZLFY2^K3;{r3;1LYgPX zoa(7e5n})Gz4)f4uUH8?z~|El8r1OqC3PGKzd*Zk8a#l2Aa9bQKz|>gP`&Ch%6kZe zp8^x6?G78u&*fZI*PjFSo`}eSZ~HVAR-T8msRz_uGI@G}Di0)xR_$qqtyo*V^ zR8yJT-4e$qnF#%c0e|C+wo=;5l3EdG)&5-CmaOwg*i9QHOxcmdJ&`cmO)0OEpcHbA z`j|%{@QDtI^q1#EDo%vLzr{n$9EKL!H)_v>^lOl!Rknw4Gjj;zz4{w!G703Rfjj%E zh&?-lpfFUs{n|cxB2o_}eZ%AHWof9{3|F%Qwb$KjCTiM!?q$7mSHpXNf;M;L!aY`_ z2(jfBpf6CLg8YN6+u$Bb%d{qD_vUcZjKjcCF3d*hH2~6S>7FG9>eWk=J<6Qtygb7v z|ADDUbb4m;c&&`ue7|f<8Y4>h3T~BaYoR>ISP#b78?HGH3MV)AfGM~Jp!8XI*hS- zE+;XdodEQoo)|yQd>cQSqp%5FB&#yteydzlQ)`Q&tb}q{%XtgCCgCVrRGQM)YIV+P zk_5Po;py9S5U9IN3q^deQ{DK5-?Wojj(foQVZ&S3HiskaxY!im1O+Ke$@5cL-Az%4bNI6( zbV#|7f$*KwqL&E?3f`d&`2aVRFZT_4Ij~yPDU}Mu%?22cBNx)Hp#@U#PJ3_RzC2I~ zdz~5B>2cF+2GD6f7&o7XIVucfw~Yver5?Qx|LXe6Gx!rKJUWAU0 zR$B1A2B1H%)cR5kS@bdkx>MdY=#8756zizn2rk&Cd^fFwy%K}$Z0OpW&rU8OqH_T# z^k^va2jLVu8^SA$m{&`E=ApzrxpIpViSCmI1D>YAl~?RTIQ=dluTwB0Z#nzDeLmQ- z+*%HWnY2igtbu4IRR%d*a`*xrj8#%$kz6AtN}Q70+uPk(+1_6I3s^>QrJ@fZr?&oR zq&4mSFmMSrtk0-T)zPvIU2YsVsXsdwT+h`lOAgy)M=GXt`+liPin9wSpCoi8dT!|O zk7>vxu%_I~UlF2=xY`xwlyvp%Tsv4$*ZGWe@J*GFBkwLn**>KS;R9WZ)OAOmKxA3Q zcmTrFvhU47@Fu2XmuBtgNkrEchJoo8Hu))=psNI4ZScZiPc3pEq|6{2*Kf9}T+=O&}-npjKQ<`C? z|JA2RD5Eo9D<6ldCy~8cd!3_Av(tg72QpHEo^}U54u8AP@ifMKO*~Pf5&^1Sj#d5A zQ*c$rgm@`_kPNOFX?R2Q2Htw0RmFyThED<)VN5$~-)f84NYi)Wxrl-kPWj zwlRSSMgxVL%ceND1FDa+mEY}B)$UNQ;D}T^>{~lPpO43w>!I{=8)xlbf z9gw5eJo}F#ItKLN6i`HKyCwv)S2fL~jq_>0rPIGik1x|0K>mizKrfgEAG-Cho0UuKT%{ECPiM zRWv7h!PQYZ%xl-IWIy3n2V@H3Km!5>K((0{U@WfL&5(@H0P* z4SYKSLM~({$~*LhBgI47;#6h`!iI2oNZ+r4Ki{Vb{U#x@9~@gChlgcfI75Z|_*V@#;8+y@SR@z*U6(AW+q-O%jiR*Ga|I5NxycZ3cOAh?8t&Z-l z*Eq{_SLpBInYV^?a8V))EFx)Cnj%~@o=cvC_Mv>cu!NHxDsM(kjmB6zqm<6xHbDY5 zp;ql#gj}|FDGwnd)Ij`MP;A@6NBvWnEPC3b8xe0QVVVyt4{$%kFy(9t%RE{o^Jf#e z4Pd7OL$ZH~G3;`kml-XK02me&YHqFvuPX?Ds8jQ91+QC5=&dYzBEXGNw%p&P&Aqm9 zGvBHwXn{$|9y;NyCt+$r@D`s;7NAizoW?V?wi@#M~-gnX{h;3U< zdN|-V>ETlz2A0ypl=m4VAWG$8)xcb+;STU3U7`)*#ljgA+Idv(bC6}iWrR9`$kEEN{smE;eIk3$G+u7F zQy7deR0kc_N+;AB4VOe{f)!kRqAq*((1k%+4K5J6-xOtDtgI;$V7HkX?bBS|9#U&h z=f>zmUX7;IN{JFTq%(}Y#xsp2qhuaKSRm3`wnJEHt#AKiF3YJhnRqtEK@PmVGS>qx zDmB>D3wcR6PJ@e?DeRePJ8gnhzVqXFH@kXzFS<3&>cJQ%^Kjyx<)&J7nf;R9Mj7|DOA$I{09w~5~+77-78FE7em*KboS0c+Ng)Bd(a zATRo3geO?7PHxgUHpvcfP0UeWPE(L}3k>v+w(jO*j&&Ape8v?dB?`^3+Rv;28+lZ= zBhu6gyXLz@ijnL&yD+Yo$~BVZt>(d<)G+7nnEE3ZrdRbUk7(|@v-nM0j#lxmrLP76 zHrueY6iuGkb(i*co&SOw_udm&xq8kJYY^jl19ZS=l;_jjjg zSF=ZgvT^`bbqcTE-!_`XbwFr_11RlnU0crGz*PTCUH$i4^SoJVAg}^Basikf0KQu9 zn}h?QwT~sU37pI5-7F361ti!X_YjOBXUKP(xo&H=&ox9^>8ap*sAkt?7jRy<8C-cQ zpQX|`iKL=A+6!eZR#%5$wvJkfyB$p_p{(kas-!228&R{iD*|sSOpq@dR<;vQ+#~Jp zF?ahU2rwxLslV~&6vT0_IC6b>pn3n`$!De|L-;%hvwtx3qy)Fsdkb$_%b&n8 z+@38>*G=-E+pK_V4)oJWEO{xBeg!Y}Z>RNCUTjiB@Vi#1p7b|-f=u+7JCp&)if%jV zhOD@C(8+GU?=Hmuo%#hvat6;gyZ6n#(FdV#Cs5O8gvPEhkM+kHC}YHyxthPItSE4} z(R!)e`y;?_Q#We^8pDqQj7pIHAi(egIHL+jT6XXi07wM|@e$l$ovcJ8Ra24~8(^gJA8Va>eB$^6mww6NNyrw`c`9;V*Y7pkTw|pMqOz zfi{1?EYk2k-4~lVj+F^&<28-m&D%JY%p{yN;%0U*IVMoG@jap{D-Q?n3~mp*xPDtk zF%cc$^B<$Kx|)pudHiOprCyhvo^+mwI1d)k3ta99eB;l}1z`#jTHLOSX`YM#c!t6G z86M@bzOh~UgPS}vULyWSkV&37$89nHhrRcViZa`}h4FaI3azLpQCnM35ELXQZADs1 zA~{QwlqfkAp_OC=l_ar{oI!F%K}E9UObJLRr~(A43Mi`TTN~eZeBGzd{e8zBqx*+r zD0GEq@4fa~bImyyte~&cEty5%J}wrSx7GxuV*_<|;)1lm77LajQu z^S#{hf9O5p`C$_oSKjJE0pS6( zS2NpTMaDlLh5lgP}n+bUEq|4&?*KzaX&zsXi+Cr;w5wE+9n9hYJ)HAduwSI#%jtA|QN+ zZ2dhIb}5dJKazw>U(*$oO?>KZ5htb!AAKtlJ&8^tBI| zgcpo@CIHVIQY5b&J$mV+a$?>pm)Uqz<(uSs(6UC5?ycS5@HcsuPZ3}l1r*w+8}<^q zT?J+f)YFY$!eKO6z{m(3)4a0Fg4-``PR1RvsdR5in3~W5jHrLeOx+Otp5wgbqL3yJ zkQwwD5myw!VUVy$=#Sb#FyH+YWG7B%8uWR>_pr{Oc+ufQWDm!;YdrOJN`8qOTPX(y zp$MH|Q`jFo*cY{6KT31bf?J&B=9a*Jwm_abzT~3Q>|;amDocYTdL#W-dXJp`UFr%yF9p!^g1A5 zhJ+?YqU{PRvs{Jstu(q{-~E3RWI`M+Zmn0vo%R~?0<4!cE@m?p+lTp*29#(W2%z*J zqm9GNJ*%NK9&_p-o5_u*H+{@&y!_f5+%dpnWZuW_bdz-TrbRIJVm{s9=*UNK5V`4B z<3x-x*+X{^HS0d0dARQqugpFd2u#Za4rnA;Lm9q>WDOPWS^#2XS8s&%M9MuPspgGF zx6xUOB5Wx`A%cMI-4}V!&#{C=lyvj}rcQThNNm**(j>|`SOouWKoG5%yKtICZgA<^ zudsH7*fAIP79STHts&<3JsSR75>yvm;*u8vVC7A*E>@Py^=4*I>#m^_C$Z-%Ei^yQ z`FV*PA1kxe0PLizmYN3+m)hJ)i_kb+qE6;mfT~Xz{2mH-J+~0jiRZ|!K*jleRuU%3 z0GgQ2Q#a+Wr z-wFm`1X%3&CpV2e8@EGiLa_S#7%Z2WYTY@&3V_lTFBz>4y-*+zz?ZKE)D#w3yBR-V z0K2OyL#H`2`CKnIAJqh@V2{5;q6;?u-Y>>;J6O)Euuou4GB1mQdS1tDmdurVI89J@FH{cp}u0J$_G#M2eUi*TgBiWITI(5_VG$| zrn9}Oj^^A4H^PJ1y1O?jD{m8hez&ggcMA#j%uy{QMzh5P1VzQD0dl@%{c>UHV{bAXoXc+;b zv_1a9l)PtGqJQbgyA8)`KwW&So3bvx(zlV=S{`wckJYkmSd^~_xT%nDZ-CcB;mj(P z$M4K&EV+c5GHr6(a@eRc@;2OVtj3Iy^{336(p+5%X(Y~Y|(F%_Ff*(ktS8!IaHwfqC2s*_^A%G zTA}d@+2kq`zOeC8fHuk5=W?0fU)Yq*_317t>rp_hcQxD38dQR750sjyOSju*vyiDqKAEef?#67PH^&nQdLmh)ADO zb$h|2RQ6{e7()R*0t^TMT~xpVr65tB-v|0bgD(U%>=A`sl#2|EL{<0Hkwst3Z_soA z?E0A`Eej5moy_mobu|Ql=XPf!Hau&kLRx++X~_$3N%+zbLx&h!Ds%O~x&6(^BL{jO zm3FtzaQd82zuI>o3wlDQIx3~M3OtMY5w|KJr3d2*61O8I08|zQAJ<>cMAdnLL65mm zG?GBsHZ;|q#IxKaUcBd4-nkJNHsRWV+S;0SSNLh>wb6=L{^%v0hF!E%M}sAFTXUS7FlC0Zx1FYB(8^>uj-9^lYEKeCR?U+;~03xr0xr6U%Md2 zV^n87k14G6Q2^d$6f7e>>IUy0e0%o3K>07Bsv%FE7Cb{J|-7m)x+e+yCk0kQUCVMXouK+C-&ZkO0mbAUZ1pubF)C7$S(jyk8Q1U-^RxSNA3&>u4VEbLmJ_9(bs|(c~>MKI@gN z%C*TA%MA;4BJ9rxFYk~X)@7asl;jeGy5tH%__y{jBV z0Nsw9aCeXS&1r8>s^gDV0FOiHbS}_p?rYAOJd=kTy}BQlGvol42P9arMx@PCip+BU zlC{jVpG3G{xsey#HFw)&$Z~1BssJR4#g#ok+2%T0%tyT^1B?^=5ET#9Df5>49s9;n zUX3%Ia$U`tZ>X`>BzM2g%LbgnqOdC7K3@~nZ>$Y)QaO)anu89aw2@8)mb>~@sJ=QT z1ChpMf1J7inm0zJ_JY7{$4wrfENIhaa#^6(%OPtT4ra##5CIVpC_@u1IIYqm7R5Ao4+aawuSrg*O@71DKA7CO-e7#|c=p`Hr==d%$s963O~h zD7|9S0~K@(d^k8}bMnXa<`Hm^^MH0)eXC7mcODKI%0a& zbok|o<3^7b;9l`-jPMo4DZf^e0@oM-6TwE~59Pn49XE;ZIks>UmDGaC8Q^E^-50Zx zZDyHnBS0DuX{mqsmHbgHB^6q{qJU>E?|g;NRBb_u>2 ziV!o${U4JS)!LePd>pV_`~GRA;<0@mrt41%6163id$uZfYs5B(B}>E}IAGAY(!#MO zZv7is#M6>wCADR><42nGZ`e^ah#>LGdHxddF)!(nx7Ssw)*@YuQl&)rM1VEEm9p`% zs;YKwBq~q$_T!XwbmnHv*khmDRMoBHKX1K#cA*mFu=kE4D)^5>H@)b0)a19#8C69H zmZd;i?t(m}le9~|+aeW?p7~e~{Yta->f)GIefiwG8C}9N_b~u&V{gauc*zI1>n7l*}@nd3X-a2T{&{0edAnge!feKWy@G z1O{^#zrx!VUk4^@v~KM-H9KRlo50TjAjO=hKW-ZVSDiE1T&1^!OVupQ&^AY?v)%Zy zaCYGFLZJ*k2$#?NCC8rvR(t%|J3gcxsgJpdaP?e%S4*FC((#@xUEC+9?bX;d9eFtk zuor;)4Vp0FaP5Io|0q=8`^8`?yAVaP15!6J(kZG zPG^kD)Pdr;;LHHXh40?XrGy z@SNUbBxk9_@mHaQWWnI7YWdw?07(LI#E+GOr^V5AB*MBSQTbTEjm56p20d~G{eHK? z?2m=7f01$=xsOQwqBK1`bi30dY#ozrMmw0Jqan}VqJkXLbcEb(_Hv(8gX(UZy{9?% z+FNi5r}QJs7s%sCei%qHw^V}YtIE{aMzDuhfK8N3^ld9cSF0aE@|m0+`cU^LMqDtd zL!x}$(WjmSM%|FL$Pa4-mmYH5v7_R=`(G9>zYVzGJ_5%IoNwlO;s$pffnW?7tn6ok zT;|wSx8r|1Tq5ub@9WWz*GtN5d({|LO+!ix~-JS@i`CN(^9+2+eZBGK$4PASN;tGAkuD| zUKu8W9v%Pb9MWXeQHdu_E%*z0-@Ejt>Ps#fNXTna00-cy25A;ObECeKG$(H!1#UE- z|6+?V98jiV0`&KSL>=M{PL#Qrs&t=;GjLUX4uTlweO~dmeSQm~r5hdku{Z?3hKDkc z7Omvx+uWK?o^R}^%?~&7%7wQovoGR-fYMM~f{}^UqE%&JP?F#>etUbJ2@ms~7j_zO zV(TUEf?5TF#ym@{^riFXK%hJaY_M3GM;$b@@TJ*R0P9PyJQz(wjwCK7E%BG!>5DmU zb#~>vwHldeE{%NNL*z3Wu*%Ow-ZzJx9;@Z88b~E!*z8@)t z(6kI+5k#|8gLCeX`F(Rt9`8}Y@W}HDWZ?YO-0+Zk`Dj^jhwr?FajDs083Z#OCgH!N zcw!|~`??Yg&cR|qVj-?LNfRUgrW{-gx=E4qivc%HJG!GvC4UyUYlMoZ_0J9-!Da0} zO{kp)l27C)2@ZVYD+>S{a>`~~^KKj|lm7|QE=1#j7@)F05@o%W_baxA#1=x7>`J;QQq-a~Ra# zZ@?!SFTbLfODJUtrYyEba{;de&W$M{?YzJ6s8}8w`7+Ce-3I)GH`NOZiU2ocjIL11 zVxR4`+31G#aF^fI1e9dED(ANscRV?Ce3a8{j>>?%DXZLH7^);~u8IrUbgL$NR5~_oK24dbgbwyrJw@#n-7iTXp9GsuFWnb=94Lr; zXL`lp+a>5(FqftQkh*VfENZhWJ0F0h%A8Y+io4K)5i2E@Qj`F5cC|EVVIs?v&aFH; zKupRD7c{X4i&0RwS!%^See-5zw>P*yL0fYxd74G7PFTe4oR~8XAh56iyR~jw#w@)N z+jI|i`6(S-RMV?;7c$w{rk=MtXR3K|;hqaDc$wFTUNi{DS73PF2ss7s(i+*6z8Rq_SA@cAEv7 z>c^vAz^MQQT@`f9pl$2}iYn79p-Yc@!IzZ03&$muym8G|wpX6B??#F9xn$LvpL3eD zhzEe>71+q0f_!e5nuh*A;fi@-RsIDHf1Iw?EYtBf=Gr8E0(G8Rd(6}PHngM%N zN~XW})c%-DE{rNuC|yf3-dstQ3D~}Dk$<%Q;gvwvV~EjedPN*yK-O+r-mJWv%sB!6 z0OV*$|JRh0tntT0eaU_`l%GEh+Dh<*1WXPdy_7P%(*glTfOpbrGFm#&l?X&3ShiC6 zBx|Pm+Qt~{LM{&3UBSLG0$Ur9q!%O_A)m@|@l`_;<2*>(T|`pJ(O!Bsy)6v$VN`{QIDLP=&Oq-%Q6(Y4H}` zbA$!SO@Tm(w50gC<{$jvuzJUO_8}jR(j1iH3(WojzLvjwl9MsW;*+5$byVvwIiLr#-{0~;t6og3=2Dwc90d|zXyy#X-nHc2!b4qYC2K{$H? zsq~X=pr^1jQTJxMqUibkh>!@kS*9#&pBhWT!M<-qY^jvYkCm*yIt%i(!$-f3&sA~X zgk?nPh8yZdbeXd4{Jx0XF4j!M{0box3}lsmgv_u#>2uN(t=WKIZFwmBhF3!O3+!Y5 zUTWPUE`;Sa#vSYn(8weBc(0_NUhFXGjf?rFG^|M^GV?xa%G&G}0~q6fXq-@7kg$h- z;cSwhM>kSV6Bv+a#jn@G!YNBUqFkJzINnNX&yej)IY@4dQ zdB;IGx+UdNZ@Eim9HB)vo#C9P0su6uTJ(kCPF&`G>9701eRAPi1!S5RfoMnEt?x@+ z-&jTd0OE#u9l^C*&@MW=MmZy&PD#~NRq7D0^ve~3Ue30*)VViNxtrw#zY@{xjy8Ff zE%Hb`RLd!Kmoo{Xmvz5f^m)lST z&=0Lyyn3L?Nj!ev7g#sYpv3sDXG4S1m652tcAy5oUANB+sQN&jD+6OC;Hr*NbSZ$) zG&~fenSD7r?xM3RPC{JZ*dKpO5v2oJRC^cpdRY$g<2!Epfagua!&2Q_wCElaE|Ds* zk-kL>!fUyIBWd4(j06bhkHe0`75CI3k78yu?r~D@Id?>gf?w_X2l${CQDB8k09#Qh za;{ZfaATF`lb#AqedI-rE~NW0SFOlz88Ex(Ns^i{@}AhWEBV$ z_bt5se1r}3IlW1b$Dp!dZ9nM&#zz4=xDe#p9naT0d(ss8(?f-nGT$xA*tipqAx0Ov zIZ%K#1t=~)E@GGHx{i4+>ue01AbW$6)|@ereZ3Ggu}wT8Mj$MaRW(Z*d>c%!jMZmq7R7*JqU


    5Adb86EmPj;Tw0U`m8iDEg#G9q>TM zyyuB7Z*Nn}mKLm7#kdd3FOGpes?@9lh**?G>1P1$n1RWCmn>iJ#OL;LD^23pYSdSJ zFV%}3v0Df?N4i;~TFql&dxNj*R$y~;M4`pdCClHhwQJ9Bl+2_EQA-y~()Zz_IeBS= z)FIiQY!)IG4M*iPgjCBk^C0~w;K+x|0_Dq~6GbQvFyE|9YEF#$-+mrK0Nz`VyxZW> z@s#~KBVz-!#aCCN!-R6BuwN%TTqcTzefCzJj^!9!&o=>LH)6<{UZD(6FJ--bmLMj- zT3nDr?dAS?7DO8|k6_EcE$)07e}S(EIVfM@h7=!~OS|{6cLjn{FV52y5>pT(lbtHT zjLgtA>q8D)Zq_W#5fsT3Hwj^Gm#h|`c(IgL0&5A0pLy;!SzFwiP7s8iYmEo7(@lDd zn@LF=;ql3TfIIOwtYS2id|$9DbVkA8$>xVH6%CmjxfqcVO~H;gen z&X96|3puK~Rwgg4p6$wB@PMpK)0b7FB|hsUk;sPBXb~Pj zJN_+sOpDPh8z@RzyWIBv9&*!z6SURCQJMmJj^uJq7VQzrsKJ&d)kfe4|DAcQ=aVDj z_hjA&SzO_s)OdIHA=&OHL;a_phX^CC716#wLO4vlYFxZbM3mrU@ExVaCk?@U8tg$S z8?g?ktZyh3q=?Hu4?eDY*2=^S$BsDX-tmJtmRyk0N-Y3VQHA8kB z7l4scwOBjcEEyW3K^?E_!||BFQ^8l>M854{J_`buRQbE(`%O@R4_DFX`q!`sKd&)Y zE!;qmYR;E!CC(fM+-_dFMTG&|&CF@{8F*6_-oP??ksG_8s;)*Tf%h~V$h>r+^?{uY z-EEqvpS0H(3bzbzSxuSbb=sA>-8wVhA13WWPMs7izc^~1 zc_v|Br8zWJ3=c?q<%7rwO3cAgRdJI!@aziM;kx(KV}N?`&c^pGi2t_x2#QQ&b4yox zrX(gyrOapnFgdQi{m@DS#0j9K>Y*VuCm>gC_J*>kvhllv#wJj7J=5o3&DQp}rjaQ^ zl#uImbyfXCv1aZ(KqqRtUz2;L0P^Z^*>Xhg792Mdku3p0h*`SF4nkxYuil{c@xE`l zZe*{gJFV;v{0$eJ9|6Bl2g`5-lY7qJ(jo9W}uvyLS~I^COGau-&VI zPI7xy9&7N+W3JZV8#`4ddV!BM?PZ~A`D`R`+hI_|mCB|kF$0qNRoiXBO$7uD`*`R! zEr0X?h8UTbr#aR6xVD6P5qt&oJ(HnwdD>MHJ|}D62F=uO&!3omlL56~4I7>t{LpSz z`lVKWdo5nVv*Aa49^qa1>aCS_d=tM-=PRp*7_WfFx$A0Woi7kQ&^|2*7#;PL@efM& z2lmC3g8rd9B667iD66Ry%B!ZCZo4S!iI>$NRz@CQ0xb=YaePBlF2wcDaemF>HWKCw z+cR^u)!IJTvD?}`+KNL{S0f$R+9ad41h)EzNwdzOizzF4EG?CWWdHC5uL{t79|f%d z=i`Dm;{(%b1J1E?L6B5I>y->d`fDF!Mb=OS>Nx#EozVCmi(YPP-I=~`_19M z<@qHje6LzwuVBet84eRb;3No@LL}uI8+MxeYWfr}fg$Uvw`}!z?0j$~lxg_Zb?y4G zHkfE}0_+hbes19a`@9*B{VX=iONhP`o0IYQN^~n?$iv+Y6Al=J;P^HE)d5873Tnv} z{kB$+wrAYh1T&dCW~PbAesucS(@Un{fC}q5wD73NtF{)r13=Fq>ct$@zI)dw@}o3; zfAe7bVps&_>TDuX!gU*E&LSpJ%TBNtb}T2h49^tu@Uezi_h|r5GG0`lE-uG(@sF+Y z$KYHQ0~tO6s4~dn2c%!d+evjGaDuY8shP@Y5PiWvf)w~k?P<3xoCWD&DevWy3vyKO z$R$@-+SJS29pRDnr3{1pV^TSZp7pXXp_D5&f%IeoX_Tvs=Tdb{=D%IBD2x(^Z)lOP zRUdN&^0aB=HBo4A7E8Pviib}WVW2(r_Sco}nQ`;N7!K&_NVP29iUQX~wdTlPID^S9eEIW{3eVP3P=ZIi-m~$R7N;t-DKat`4x7s_86l}wy z1jo?;yaosR9V*M_>~gAEqzz%{%Y@=C@Seu^W`*)<8>bKv8OO2AKK?pZnwW}X@6X;b zjE8Bp>R?D9;7R@nE$%Y4X30I$1w}tp>fF%P2#c1HUa%d8IUJ@cs&p%gS+`20&BT%n z7+b5$T+{9r5$7Kjw+{L6MFZpBH+_D8l$GnW09N*>+-=v(kG9H4q>z-U^F{%cK79_@ zS$fsqDqIj%Tt)2LBnLM#EyRBUNoW1n?pV%Of+h=(L^ymaZim`6CPdgLRwCi@*I2VL=hfVc{lO_Jh|C!t0pgQnbxU!Gg6d&Vn4s_ z*w@T?8(DDQ1NV{Oa=*KH%wp(_*9bMu=U(ioE*gInWh~Lld#1lJ6{C@-)UIDL|6!$z z>l~$Tco7tsyUoJ;M@LKF78utReKMx3x=KXnpy28~mP?W6K3Y5hwsA4C-l^GwQL<5i z7M>EcX6Y_sgh6`do40gmlD5}+UC|x6zQT6?2KcnYP#+eXxlXOEGg;^~F=pe5%L6Fv` zmN?i^EzQ9lK1c~z`?LYz!75B@`6;sGBX~I!JMnaw9noOdQ(*yuXV_QhU~UArG4E>` z$|m2DA&wfmv73~bFoFU@Elu_-e*9dE1+R^IFeF#%*P6q*A45h0HyIjp1B3kQtye&x zye5gKM>Nwbs>TCOfN!i{<<%*2bWF=d9d;7pt+;0-oe4RrjTs3ihTgSQ#50}iFw&Cz z7|{!;8FG98(oaM`@19t)AU3i*9 zw_k*f*R3?N#7jHBe`U$EEct}WhS9S%DL`k4H3lbA9=-f%6Md@2`b{A!mk4GW9ul(S z0Ixq$Bc)8|yn8eI?P1^u@+GUkVpr7HvHm!poT8+{)AZ?Y_iP*8vE?G3_RMK~dol;- zi(SBwKmth}} z$kCDZX(Pye#_M+hnE*?jBXXOgBM+>17Qj4!6chrea5CnBn4m0iPPY&5DR&zwKJk{# zB~vLfgYq|lGDa;ch$>d%6h0NgN(z^)H)nA)b#&j`{Y?)HV!eHfgc%jx>ZX^>L1ayz zPCwO9CW$|c4~5<9r?NUohPywQ6YNzd|XG}o-!ti8a&vTuZn8u_3p z1U7>8WOiorb_3) ztyDguCKZ%R_lB6t0=W*sfC4t7;%>4Vh-G6JP8~eihP4n@)qn)>OkOHT1vp?H>gg{ z3snS+)D;jn(7?@_yf-~*{vKk;TeR(IWcu7p6_Ag==yH<>SDXOzw8pn=@^Eg52@U+E zL_81GZ^WrJR+M)T4VBW57RyHFlW|5?VEE8zbl*(3?*;Uxm!F7XcYp?C&0sJax+5oz zVE^tK<`~dGt5%x5a0sUyIi`(>A*^ei(|E_Kyk3L-`v6DqaV^!S4K_m7S6C6G-BeHnW!n2FW2mnYHc>H2MbWkx-7U zZcJf26|x8=N?KBZWokC%8C*ZplzLZM1| z2UUK2WFCC*TxZ}I^kn+P&CZ|^hae6h7>7eTA6U7B-#6m7!4f@lAT5 z*%>W2FdH3~cIlb~iS`OI|1{vH*jmUtVuK@^QS`&?WYd3HvtJIzQ{vhAo4K*EW1AQt zTId+hgJTMXlFJVMwWAH7s8~-_KC|hAk1I+pkpboyQAA4yU$P^4!NXv`vZ80ZU?g*^=`#Gw0AL>P>HER&{9APnT)QDm2@b_n*z+9 zTGlxtu1tN*H1e7PAsw$A8V^}{P6`wYCS$b+809ccGE-Ix-$s$`Th$|a{k^ke;-!?F zHb(g@b!ybw6^*vgjST*kr8&Ue!$9VGJ(@(SqiN*aNJ80wp;HS+ksp7yD!2wWRth;y zt+#4^M?nL)Sh8QScA*Qxj4Qvh4dG&jd!OP{BJd zg+Dj*Bh9p?evp#hT7k#8-}PWx*hP(Bd&l~HB_44ZBXbXjSv9IrN@=YYxl~|gb;W1T z=Ety~*q7`ei&*N<+eLlhS}asbZHe*%`v9KdJ02Za2qx$f#-MgXHa}^I!-0molg_^Z zhN2x%2dquJLlaS4w)fVoHQT5x-loNilBHl=sRPWcmTY z-V#aBUR?tFtMu%Q4ASJk%_{+K)4<$GNPyKS#fPRdz^Y2dOB<*7@6C^ExCEi(=k%QBwe)#U@V132xP3x2Kq9{D93%p~!K%^S8+jwZK{Lg%3No{}>!B?iw7JOLC|6g# z$hK#&rBoiZF-+27v_yVKKewGEO$GHL<~K<;s&dDmoeQl!VR`(_JwA+WM=gix_e9jF z4Q?$@aw{OD@2Yd3XlZu#w=97wvtqNNZm=obsd9%p{E27U=po>B5rAQssikd!l0uORIBlqm9Ho+x7XrRX3y z8lDNO*))Jm1MEsI>S&_0e}l1_Wgqu%XXYnj7a6Ge^YJ;%9{P_qN1dE}h&PaJ0xUdZ zjcVMp(vJh1FLLV57r-<44(4K&zZG<6xkZu5pl9Wlo!{7!1N3iz<1_)r%Q`#cO7-7X zgMlRT?)=xamZ8(*4JOe< zU+C3?#d(wqJ8QOlGt#(Gh2WDgc+v(Y6l@KY$v-N18}Dz!(n41$QuK$eIAm1yh{m{B zh>pq+D~TjPn31V%U<8=02*0(mod6-r9=}T&gk4`DHqBSizd-sD2RteeufVvBow%1v zGaQ`d;3Aj~bVQ;jpBKB+NZ|O-ZO6fh6;oV+46%4Li@|1gFtv8Q%PWaep84op;Nmjaga@ zPlB_PWKJt8hP_M_Rx9*eV+qXts#1NCvL2SPMDU8D!ER;tGAsu3?hZ6%89Z%xV2X#c zeI+H@!pEUn59s9Pg^H7MY6oATiBee6#k@8a+4Go-tb$tn81-;jK8sFrLHu|x?lr1F4crIz)Rlp~|IZO)Fv4>%)P?-i9MnV5nO}o>u$ZVL zF7PxKJRJsY(j68hKP!DfT7MWj$&oftRM^iuXr?pOOoq=d7|Sz*Ei@^Fkr*tir2Oa_ zZFqc~s{*dz`D%{*3q0NBUgy0{BZ$-BD%9wBDU2)oWNfo2>k7$NPc8FerqLwnZ)n;= z8R}kEu^%DAfN4{`v5k@EtCQQQ0|&a@0=dKYV9z?h!7A$Lk&{aw7>2C?;c?8Yz0MTC zYg?J$Kf$G43xqWbw&NhsMLPm}icPk+wk5h7IK(hrs}@2`H;LS>AykcK`XCl1i2quB zH^n5rmifH|fS`F{1_mkg`z}kPX>H@zSC&RkYIG5`wg~VR=Mj9?t))|p#@iL9kt9WX zhk-;S<2+_GSmpzsa1Jn+76vugK`=)eS%QfvJ?WQmk>(oIK`D=jNF^uFskCajTqnLf zkGxC@(o`AcQ?KddcFP*_CxfEA8ccmfKgizP(Rixko^t?ap+qoLYGw#rzk6p))eD0| zgf_ixr&PXOvW3biu$GaKs`FVuEy&sZe`Rul(v z01ybtfsK5TUksr_g1U}_39l5{ld^Gr+|9of69@rj;WW(dkcMp3(rykt@zk*wb47830 zS6X1^DVmqG`TM4WcpRb8Y5GVR%VtU>?ZdP?cP0JIT^@|(AW&;$==HHkY(bX5+MR`F z-Vqqssz}bw9<`FWjCxd<(@nnBLST$Zn32J#yMX<7kzXRgF{f_w9Z7E081j%7WpHklAEoB^oy9)V^S8XrSYmD&lxi6e?v%BFYinX)S(WBDd@fk zChRb-tU*p-PoTB1j?_wxGcM14B4k_4<(UR|Cdf{kck~Q4v@@_Zm~BPb=LnySN=nmu zJC54f9bCsW{IUDtL+$E^Pj;5PE#AGR*QsrP>>xT*u_C!XU5f*`o!N0u@9H~U*Wr#lax!oU zLbX$^Hommv;WP{R+Gz(H16A^*#%jv;QllrrQ`C-g%}fP8fvH|M#GVK@@y3KPU0ADG zH8WvhXq}3>PIuL`sUb`zH#pDSriJb>_ywQT8Yq6mKC3Gt(UI?`!#tiY^R+^xy1BtNxGv|@aLYEbo!=ZHnZV8Qt(!h(VWp}?vz5bGO4aHBieV7(qEgTj8%)<==No7`^5Chr_cu8S^uZqEpZH_)%J)l!E6 z20F^Shq>IG+cisMQb(*;vJY%u4RmqX<;<4W^u*g^@8r? ziv~irUK*CJ0?&8ari$};wwE`FE-d%i7AAjqz-vFBpIDFOTI*eEb{Zs#SSd8@4E^4H zG(e}~>>%aP^Lx!VfCg>5cp7UZ=F&?IuD3e}N)Y-wPfu0NZ*Au3pYQHd@f>Va#5x;2 ze=2rBfHjTbJMVB$z0UzY?KJg-txD}igF$keea&guQ*N|YJ^Aya2h879EQcH)+?kwy zH*7XI&Ns{uew$aVE(@pBY^PF)?S{=ag5z0koAoRk+b4IwYZf~))@wBR%4qxN;`LB( zLY*(C?8m;RPlP!tE0ebo?|(jPR=;9*^HSp3dq*rb%;l@-ZocwSTyx@sEO!*WsWEq3 zeCVtGyn$C@yM|672blMy| zRiv`ctjnkL%FU-Tb(B2@8*OyVH*Ec3_vrX78w?uzbc}4H$M*E9xfshjTGmWGaHF=m z?-f_H(Fi3*Vx|LmXH~N48Xn(hCKYRnWh&Y3;;D0+8)G32YE{BRU)|i7Q_F(-%g$2d zzD$Iu+i-c!sWt3t`-QzbM`v^8EW>%yA;H+h)pXsdPi}qH-A^oYqF#Z>-)wHY+?j9D z!7XMKZIIqhtxGpKBJ0frZ>@)`bo%|H(dn!(t^gq(Mip7*!Oo|`K5~@N`JGE@*+r+8 z(6-5H*?$ckLOA?_oAi!FI_*_sy@+V^E^eb}mC8Q4(&}~dndB!N0`~1A3N4KJ!lNUa zccq)%dI&NDS^HWAJj_3)mZ`SM)%5$!4R^AZjD!Sxi(sbQqXb?1?j(53MH2?7i!jyL zu2id3Nqw3%mDL1xz}ce~8{YVbu{*W@Rkc#PtB8j?DR+w2_WnC*PT%)=c5RUx=>VY_ z?`_$zF0M*vFf+7^OWJ}iLkzasQx*U1i*6x@Y{%^a3se{Y! z;_sTL*}pJ%idZIX%XNCks9KAgUob2;w^(zyQ?mT6dp^BYZ?$HA(YyaUgH_i1#lZI$ z4!-18oBZ|OnwI{Y;k8EjpnfC%K}>YTQm05>%v!CG(P6uQ+;C#5VuBA19vaa-x5f;g zHGgIlEqyKZDcdy;)1NlJ?um+nz>%yJuAo=_d)onb9HXf_-)oGj_KdrhNF+xW$@z^P z7?g{w$!d!-_3-lPhlO#duo`p3)s0Uv4Zo~QW*`^^IZlCf@7M6J0v!m1`K;yN~= zk^g$Boy?;iix!+Z<9DCz8kW}PmohPSTS-T5tk1Xgrvhr74~1bgP&8M%@wj~{v-gJB z*C>&r2_E0iV|*9l?w%SRIGO%z9n0YtMm)W)FmHQEC8pQ0ucXd*{^E?nWEi|%?TZUjF+7Qsd%ex*F|lbgbIR0>KT)G-M<9oy-y zY_c}B&-eQfW0+w_cU$jY3v_f*#j?e&>q;LXn99$Le%JSj{?nI;qvZkjI*goYmJiOhkTPPicVWX=! zA-GehQGKIvc~kV|M8?L9gP~(n8%03BHf@84Nv7xxKh<^mp<~^8V?J%IL%xUXlRRpo zr!qWsV_RZEfu>N?b@emr*PIVA-Ff8sewXSHY?#`qS!Wih^+G@Cc`GcPEPASr9!BxO zCygtnlre7p3Wj{uQUZYK2VMO>$FRpj& zD;mYKrqfp$3BJ9L@{P$XjkFWP@$~7heeQ<`#1a^ER(Gk@VxLf&uiJfzX^a_zmNQRZ z=g{F?VhFY~b9H{c^2_j)@%rQLBzfC1!VPzbAA^S_JXWWIeO8)Tyr*8(glrg-@ph9D zrP~f$EF06B94xxY4WRU_2_)R#Aa^iMNWZYGx^n56wcp13F#3Xt>gXh{V~o+lX3^Mi zRrPonEtJ4$qhFwA-(5QK{Z**1U6dcKeILuF_3F%3EwZW!BOll9Yx|i@_FMmS1iRi| zGWh*GHLVcKQ+RgiQ-^OE7e&+hG1v8wcGa9k8M>bworE<{A7Y7LZ7Ab*9%~Pdw^v`O zAauyPEHm8K$_h`pxfQmPpM=u-LyN*XV?$-q2j|~k>woJpk!h8*&F&TL*4vJ^GZsQr zbWBFv^IOu)-I&|jx@;@k>ftV#Po;VDS=+4LiO+)a-DJihQGg8R^R!@gZ0oAUv5?In&`Lp zZ(L$xVk&+9=l#RPv{OXkIMdGQE`#)-FhvJnkCvXh@LRSVrkTdCo+l|UKb}4ff8THU zM3`xRYinRA`mGR1RR7Pf^;LmKPBKnX%mQoH@$?fD)4S4xf4VN=?|0JR4rQudS!3+6 z3K_GVoeS9s|0>4%-+n93>tn$E>Djh$$)`#18km;%G3Jw3qUoIOF5sJGYHnqvYyY-SB|GD_+C9jw; zzOUUc9SG;e8Z!V8I(}d~EWf~iS^n#r{T2)k)gu*~^T%}*(c2FHmlynP^gN|?82<&G z*f(t6UsEo!rUkED6SS}VH`BWl|7G=FRMu`^V~niD_Iocso6RpBGYFA$AKFyhNcb5` zU`c)n3sv)97Ai%M^F7A-eL1drMqcRI&i$?MzfmBT2M~`Id3=n4!)JVn8@6cF-?!)= zJ%Oh@1ov_4IS#2U4y-uOTsy__9jd6+1V(j%vBH@au5JLmS?#L3S(%tF@&El%oNyiG z5D)VAILksaC5hHmQsfykY3`iv^n!!QNxR7F@;tPSZ29$EID?(XbyTV$m*6jroPr?y zn41~)iP7Kp$>q5P%o5A^i7^u?>|nvSwXO`os~qwdd#ZvOa!WX${H~GPy_*nfE>`?oDJnm?K?#&I!E<+jJT#^cI2$#vZ8xX!SD{r6{o!Mu7p%qq@zO32Dp z;6USQZhKcmDAuLvywJu{Qzz>-rgw>l{=Qo;tPaA4F|?13(6VfEA58z7m2UM7%x4a zM#>ldPAu%5_pST(7I)sme4=%ieKnQNZ;$n*KMzx@UF~!C`~DD}(YvSMF?{}W-3liY z{<|Fe*GKcuzimC1f1b-fdt+-O{Bu73i4p(A#D8L9*pEl>&%FT8;h&iJ&olTZCjJu> z|A~pH|M$;6_~#k?vk!js!v8r7|D1*YSI@%LuA-lR{`r+=l7=MO#`}-|35S38;&9){ zwQJW-zr2?2gnoKV_)i%3A1BY|R6Kt4=(nFAt4^VxUNHYNsCMC#>|s=|EBOg9i`ZINh1aiGCXN>`y4;o!|D_*rPA}+yBik zY`g1JUD4uCNklP6SEm=a1+=C2(AiE1h|Z8$7wu5V^JympYyvkHl(ut<+Kg_D zHK_Mj${Vgtsi$u9A6-(Cj&vo}K3Hgn`R{yFl`NNRdQP%x=inDc8C8AH81(4WZ3c?! zLBzy1c;B|q+4;sJgYK^c%*Q`?oMtN4`0Mk=c_{qPCQ0;6rbt`W_jX6R%a_6E2cBTgZw7<$l-D>TfS67MokX-6T|Di|2X)>(F-fERP^tFMmW5=>; zC7jgp^%sE7aD0|`o5 z;>iEst#QfpLj|_RwKKWGNjct@U|2C*9oB1MeN1xw`_f5LD)ps?lG)CZiC=xmMru__ zmv#naWk&{Z$(s`gSe495gOXbNjyVp!H)9K&H?mL`q1*nL@ld<-NWoJceKt94f{Uz- z=S7l%GZ1; zrv|o=q9Z*o&P_$;&eQ8^<{tT%MVZz4t^K0Wc;36Z=#tau<{tmKq_aI29j~u_@-iD`E|pb?w*25;_%w;HK}@^) zvDVb4YyFNy;$I`yrau4wMjhHQM;ceBzPbC%=3|}3pAHP0gH`%-6YdC$zK-%{SH+$3 z^KJz-XPYmb5^Q$KH6UMG!^*0Mn{q%y?9PQfe~D#FHo5=1=`^3}{9J{trgqWwg-!`p zE{&5+y-lQeq)e~fJLdn?ReE6Tutm(@qIc7o!?S z&HCdZ5qVtgAIE{!rP|W{rIfdx{OU-`xphXYr8~+^*Dm53K278^&-l$J*jZ)WGbfA4 z`y8ioMm|yAE%tQPPu7!96m`v@gJMdo2130}R?u#2dshNni22h6e8{V!IO2wXItje#zV1l$c;g@N#G! zwv_9W;FWa=s9EXnY*c8Z=`4%QD#V~`kJTQoqP{kmR?~lLzRof)iS9|8k4i)3>dMo5 z1)CcUjCrB+HuacS%4t*@vQON z&vU9mnHAHLTR+RN3CB8aH6}9z3$nY@J5VjBw%@%m(~zy2eI?h>(vyi&kE1p}V$P;< z2B3~)+W&sgU%1GPx4F@{HoNM;kYMhQF~tM#U1m3)NiLvQZ^?|keUwX(d&(NzK5)sV zbD~1t{fed6HGu%pf#%ZJ#IAtgl!4|8TMRl}m}N0ThpYGma&>MEXN>m|7Q4X;+=;Zd zwmfo_T*JG(7tq>!tiv8v@7bM~oKxl08^K~mDu@(ZC|zrD^kenA*V$q`;`y(txB1B) zt?eerJ~3FkgI~;}Kik(ZU2hj5S65c$XwmgbURC0KpR?@m>IqxZGlCvzEm@NR$#Pht zV!W}lPURk1XOrB_$m**6O%~hnfu^A1(mFWxX-{gL_I&9C*6& zCLvtDc4yPqZ}LDGYU-+wRnuVWysg}`i219=-s@v+H4hAX1*0$@pVCpvehKpH@!BL;^SDfqj-*yVw4HG+S?1w_xk5aR8MhI%V8dT z4^gQKv!1j%CrB#!+*N(6rL%S3S5HF1L+;>67R?H^p3w&U@d8kd+cEw-Z+4xq3O}j$H)TPv^fY_p( zHVm8re0;7bGC#OtZ9#Q@zkG%5HsKWQ#XJ!_#| zW)GXqTV63jb11i9rsuK6*3{xFxhvCowIx$Re3ivD8)|lesR=B4edVmD(Z;Q~s`M8zp8xuk_Z5XXgl+qST3+;)#M9JXUXYtLcDTB|{anVbdw^r~Rn@?S z1%E2OUcj+7SHD1rst^-`Zj~M@_Q-r5Q)mkvY$yh2?%lm4pgJ8Q*3>8X^bLC&&<5Q} z)j4B~Nnili+brI$qPr@X#=_D&ItnA!4U^X2-s5Y!k<}g1IU=?2MxVh{aN}(Nx%i`& z&z_eHX9nYf1h@{Y%no@5zr2u5(kG-k$vgeBd5g90aGR{D$$IpLwri}BF{f>!mdIEV z16K~t!LGdbxgeWIH0H&8nvrHEw!go!jWb?OajpLtl#zN*>LmpROW$$G7tj;9Ck&rF z7TH;}_~N96zr(}NuzU}Ze?B|8?5jkoXfW<;KPMuy_i(#>txVqy%p$w>`aX94CPwVq zD^?m;4{UjHdB2*CQ9L>?{e3WfU{TSv_wF+!l;%Ix7AV4f?v-692{tjxm~GX}Rb}!_ zKJ%Kg?|S1JZfM1srGh68(7ZOPlwyvU*7wd|Af4(p-IrjL%ET&|Ndz_Zv0+I2*lI=~Y4y(C;r7&+WRMicY*>f(wyH409WAP_a5^*_NePjH^PQmn7io_6`b+(N1G<@uHMtpWdm(X@7^@1ux;y}&tEfQ zvp#@DA6;Z(lhAT(&$2Hp!wBrNzw~-Os=?w~{GiMUiy-uk%DLL6vY4EI6)4BC4R}_* zp*`%bK8>52?W!8hPf_LZWxGF}63V7<%K5oUO469U=L5wkR}EdA4H4)eSAO?>PgU+K za^hRJMgR5r0Cp~y<;!*BSIKiJ0g@a^g(zHyYr37IX6jXJ+BEK5)pT^Ur+%NQb^Ll9D6TCify$eNpqQD z5zDJRo^DLN6XA=})(JbIkWCbcZ;x0mk`|J4O`DVZ+~;w6GP>_6FwL7+dlmAn=2GLf zJxki6y2*`^xX(A`*N=>QDm-pU_LVH1>rnTJ-&}YcpO6@>FnTl7h;gp$j9GgL-tohC zC3vgEun3i3B^a;6?qYTDl-j7_Xt(4zx z6x|X6i3*y(;L70psS%?IAjS<({@xF2v3^3klCFx29@RzUvK=%RkRuPFJDj zRwSg%oK9^KIO}=O@SH;RC1nzDrdD^a_i2uMJ>KpRkoy9GJM1Ifx&26SVa;N9j57nz zBx$rGA-c4nSKM4eD9T|yLQi&VxG))WxvU?R#j*ApijECd{eIK*M6(s`X%c^d;onzl zcc>?#`Y2vCcr4pOqOBsMv=fbaA?H^yER((buzRlHP8W|%>@|v6py%GY1RbaB+=!!Q z{s~&-H<{Kr{ks!oo_1wi_;j&jQ^A@VwA3jM-K((`uGs>mHpStJQ8V+N#gs-%)8x>) z8Jf^DVL50&BVM*g&OgCKqr8_k+DW}P)#Pcj+0)x^+J~cN3$kZ;%A~cOv6x;A*DfFG zcv2yJ*r!O@M=@$6J)Yw^mz3R_rDlwYU#O21W_j=Cs`;{G|EB@%NAqRj?aJsmZ^Fk_ zjcD10jq3NObFj%9QP~DR;Fm4>Uqzx%8WGYw2bdj7oKCs)gi!H0v5wZ+ru6ixVE;LB zLASX?x4}1Ooy9$Bvb8)W+g)-_xi)Tg1WQ8DBSE+{4i!#`s}kAvC7-&(jlUtQ6*y?Q z)=lwGDbMlaAy%4Q3_eNOG<8%cntUl{MQpZ4`|`?vR7zX1;FSJ}%KDALnXj3-u*09s z9A)2Vu^D!5`2mKty zv8{qd8 zgZ_onWj4u+;cl<wHBR*Elw`owvnrqW>I)|fMHsraqgNMn1#h3Su?Jqi~e2%7u=UW+D|6BXz>5lbV zDkD!*w3|ZZ=ohC(Zj@6xH$#Q92GnO)>!Jc`E_?pKF=U__#>c59%^e<$I#b8&(mH&3 zY!A~wd6L@bd_d005H@suvQuD0>BXg%&cfyc)1{MnRxSB;dzc9MDfO2%qEfvc=8R=z zd*L#0nM!dY758nkOH3of1CFZtKx@W(`KwI63<*6x{u@^kus>)l&#G7~N$an4zb_VS zs+1|W)owMo+IxSCnX`@SqSf}5j?>jTz0sKgl8RQh6oP}(^{l*WI)dHTnPt8?{};=M zX#eMY^})rmVlmzeDbc2Bu8)7J%5YD3A@8RiABwKDp*#GmL(yqWCueLZ!`1acoE`t! zjj-Ol7@?*s0R=|Et+rd4dfisDN^hsO}xB3Z45$4vv$E4qsA-yU7HX-#Xr zg*w}06Kk&%=%M8F>gkHdy#(#)X_SwuYPRM=BJRa&x9@euXj@|snpED`F;BY8YLTrA zwWp>?gOhAixvEF1KEm5pwl1EOdVbW%M~R+vzRtD7KS|B$RJsn!vpC7rr8eth<69*< zicvLvDDUk^&E%;G;{M~r63vH+SCf| zW-^QQWxVt}BzpO3v#ecq(KNY^MONzQ)8mE~ZqNisaFWsN27?s}FvlM1Y zwRl74zu7@Hpj^B$=h-7G!s%u)iVNv+)!mzT=`T_~@DJ1PVR??*>%0qc4}4>}{Y9No zX-O1G9f_Z=VMVb1J$U}v!`oXlZ>%(_dp<2FrpRqBNjx(_7hU`*f7NW-QL~8Q&Dt8gt)|?OH~jm2ahEr7_Y5Wy zl5~T4t3Q^DrI&V(wA(7I$UsYofezHL`|Lze#%hExCdtt#-{ojkz|Es(Nvb#3MwS*= zYG^AeNdcPcxL<7vm`MXAox$iNHHD(^Unlc(Hcs?b_88^P87nTcBwd^UEXOSLqF#ge1NWL5#mY&z4sYVTj?7!cEzsDx1abWbE}-73Y|@ za~Twy<|MUz>Wyk)ExFbrRRM*BF|q;i2l+ZzePXdn-3T}biD&*I@K5smVRSf)7hf>? zN&nvhxW%+mQPlQT_Q329-v(xdEZ$!cZV)tN5oYaEG1D}^1p{7_r0G)^G-J%{Y`3q| zqF=MmSlYVBwEY7)gD)^h!Y&k3#u{Hy?Y{mPhL@FJ4T; z^;xjlUh9s`Sr1@qlk#4(EXrNA?|*E$nW};=my|7jJKpKomg|mAO5NR)YIR&kFlAw$!Q?b?l>v{zW0sX`uG z8LP?F))9em)+qHisB)_TZSr7*V$_(UI7Yk(gZss%rFHYFuKhJuEM8i?;V$tFO3`X< zgYhEEKM$-T!^08Pw)9HQi^^{oj|+yd!fA8vo(jcZmJ^!$4E8Z@8Jv-G?9OtYG<)mu zEYeC}dxZCFu#Rvu6V^%@qnNpJ^@rrcQF*u3_gas6XRKES<_zh0eGC)|u+^eEz?s2- zlhzXFC9L0&qpq^u&gA(;F(q*W#gw+BqQCkxyno!XpnGOd zrT3b|MqkK1v%AvSKd9^+ne^Hr+^PGg(7t26?d6hLM)_WImHSX=pXrQg!(t-%;@|epC6l~wKSqbUd`uA`E{c|`SXhpcp8*=^i-`%*N=EilZDD0@TTnp zmRGRtLo?+@b$-L`Ki^jFi5!a7h-ELq>xd$|8RIYlWo^#j}$gU^!oHy<{9g`GYM`&bLkMkj~k!JG|3E7hgC+rs^ zx#jiKCJXIb$7Wgm-m95bXsg$?zus=R>Af$I^}DTko%6+FZpC12( z7T5nti+vG~x+NCpBp9t_YE&3BDk<2W>+B*Jt6Pb=Xll)~oYXd$&r`qG!M`u>*-dFI z*zFquXW3CLSOI$EWYkz1B^txcoPhnM!jlXMOr@(M#RZ{R>yzp{SGowmpz zepK|9H|}cR0)IpjIVz8z>Tb7XFz+yb=A_M6Yqsv;eC4@K9$m^ik+?k8+;$x68m9B9rB|@(_eb~?ep-qQ`^GuBMqDm!%TWz|ozsXR2yt3bSmsn>F9|yrJ9a!-o@_J!vOV$(A+?|2BR$aGzYa z{2+Fo_%YXn73Fj&Q)ON{DAQfhNu93uc@00p5QT zCEg#r z@_N6iFZ&M@s~h9N7JF+x)rSP4t2~_Dy!fnpvogxw6POFJhaRa6l-iHiGAkHj`UVot z>c5={_Mw^{N2$5Gx>hO4t$aMa&Z+Z)iCyBc`uSKw8K?JJ$I^zrUbUBd74z%D!o2g5 z?OgOFzZFVT2+gFR44-cz&ynbV6YUG2Ir(K0O<6uzYyzau-tUsfKkTNWc03<;TgfRi7sky%3jPIl3vzoE#_~!Le|umq)d6(m1&sd zTLCXu*()l8zg`-poIQQdX(Y#rZwoRAE2@KW%yHL!SY@}W$DHLAqo$v{x)C<8nMw^_ zW}hDZbS34-{w+4Wjqm5eoU5x6@25Y0;TV$VC<_fM|dnYoK;t` zBdz5*i&A&3{Y5)26|B6Info}qS;AFf^+ZdP`^~rF>lqSTQm5{>ZcyJX>X=p^XZk30 zyQz|@mzrSJ%&nvr9lmX+YJk~)cUBwa^J-sU{QY_Uo4WDd=8Y#}ghREnFVL)MZpDgD zmhWcnCi3q6`Xt9?tqt)Un)}QvKjXC|wyMwjgg3grUFGpv;bGyq#z=e}My?`y4?GY# zA4y;)mQBZtq$>`X2FqE=_q_|bH#d_Ud^kpE@;3&dyQH#$<>ae@hk}JCWAIe-Rwi>F zxB3$nk1wTU8J0Qtak#kQR^!>O+NqGzIb4UA8+j5K$Nk;cI+W1VF*b$m&35Kw$upka z)@aHg6T3fyIny0Fb#tILX7FL*^q@t8cg?u?}Mbe`x$2o|{ z-vyjvY&0gZVK?fQB#MzS);B5GDi6P!2kK+Q`HW?}(BZp?M3M~i7hUe*la7ql zv~PGDT})RbDcHBkRwQo>8LkOki!w-G5KhoD<&d*t{D5wXsujR(lpLF&XE)YcqSk1e zv$etL==Z1G`v@Y{JROq;E5)h2t2}<{v6>h5$DxX6#SY>lLLOv@eT>|Cy2z=T|P_qM=j#PsOfQ^d@n!W4OO%uS zn5_!J5!cRXg}dKg`H=MBJuaadUWD zo=w82X>&S(YrlAC=rw6R+3GMmuW@)i0bg32i#{xsrf>oDN=W2m`#S0Zo_?A)lh8>y(;VML*ZAxvT7KS#D z_Peyu&W_)xU&=~3^pDk+JM%9dZ$0c*hkXgo zVIzN<&|N4Z_9dw+)*#G}yP3?x9;wEuZOxRLUlhtIo@3?Mu+P^y&O~YCJjT7d?HNir zI5uA4RaSz%(OcgkqOmq%AZ&+JryIgcCr$?%V$+;B0^C>~CwfrA&#)2tI*-OibmtVD z6;wOwk~ByjH(Rjti7$N5O%kmkeH^}h-X}4EbVTyGLHEGwRE6~PwQ3VLdhYR4Pi|EkzeeqrIWz;uhDo1NvB&3eFDqW7#5A?Bgn*L0 zxdw^V?9FEV8zT>Lw?{HoUW%-=75Or!A{K*TRs7rfv9rs#VKG6+Z5xK9c`eGSn& zcP4b<2kT?)o1K~+2XA*@OWw88Dvm(lzH>N6Bzxo3d_-9M?Fq9;`TnSFLIr0`+_t~c zHRG77ywK|Fru9rRR#w%6JyMh@L7yT2w8PPmr+2H7TPb$kN~OuNt~!8 z*6)rU)SE$f9kEKou*UIosju0`f$8V@K2Z&ZI6dUwA1$3??wV<$DJxd!}*Q6%HAnbN& zD9ADLn@u)_Z%=Pi6GU=eqAJH&LFBVl%_y1}o*Ur9#ITx?0Qn%2Z$iTY&iZgI&9KdP z2jsusA6_5`mnK$wy7g+wFF(_OrTVs#SKIzX@FlIVO$v6Ka_?qXV>R+QE=SD{%Pzfx z?;f(6;Yh_Lz70Gtg}p`@M(^2#B4lq*GO0S}Dk}Bi4QkhFeSjzrwUI5&HOxw6UIr4K zd2Vx+kYn!iJNfH$$caszH)H&>d8%xz?YtwIkwToV^KtkJ=eF01!LB4*pAl2*RqK{z zE%l)Q(d26{jqbjcEwtL~b|3J}vY=;pTeqNN%XnpzgxO_KLR<>VZA2plN9x{8kG}r+ z1rM8hlbKDi7!!Meb{9K0C(U-2k&3m(#?d#-a$5%eoX#I7#%?=CEHYW6)~X_h$wgA) z!j&DrX;6MUr^+zz#la%<5i;C0pZJ@?a^8OmMMUt3jNSX5J_~J!xl+A>$ND8Xc2C0a z#9r*jBPHs5#wV<4ESag0!k~0Fb9tw_UUkY5JoQPH_;Y!-Rz!|PJV6d86kqXk3qGeI zp@~Z{0Ns=t+1E3$d=bx1vfJHxPGcGjcqL8u35v$~2`hB?Pr+s($y zs65+eF7a8C+GU<$$f|_nH&siN-#8bKtaND-IVlrQaCh(TW-&U@BX z_(n1V|K@$0?^-_y1_xOKICXtF2dwQSyYYxG6ur^vn9a9Y<| z<##opbYEgojCyjd)R$JqGugh>GM?Hu(-fv9%^7roOxUbDq)*F2%U4VZ{cv!~~aT?*>b ztAvT^60;)|cUV{*iqy-$0-?@<+B5NuL=+54G)Bx1t2_Gy67 zS={m4kX1LPWp}J6ND^Db=CWcZ75wXAEJ@Y3+Nhm0J^xu_3CU`Ku47-4e3x^1Lr;(< zmB~ki*gH(ME^{=1wbCwYs~?xDPY!iOV;1xFs>`N)@6R@^}=TJYa3nHC0(s>8yQO5(Cx<{6OSK>1}uh>BZry=A~ZDez(^lr z3wRT`DBc%)T#jFCD=|M{j;`Aix!AUuQXzT|`WlFQT+i-SE&tMm0jU_WUw~0o-5u88W|`IMea`J?B-96XQsbHX?W zVmtyRxzWt z#ht0{R#)fQ&8xjFvD9XD^)Qci_7mW2YzD3kyWAP*tec*WPtP~MoX|mu6Dx8>4LDS! z*gVQaodv*)fXWxcRolii?+;Al$DB#B&Zz0(M#=6<(%zxI-_JI!HM!6$>RSZ})OMF_ zH0?uqe8mwX&FKpR(QHvjF;YdnuzsP$*_|39sNHF$)z#zbo;oUcS}QfowKiSoaig5Ad$880uRVnR2PbQo}ke$r2T)I^#{kw=t0z~0BLUV zg1kdWwX8B;rRw#UMio%ROGRyvrpxrgq9pF=AMZ{g6f_H&bO|nOr=#17 zD=U1aV@RQ~NcaCe?++lq3uyv~#Ovr;iEKf38f`+J7@_bD$kle77SB zA6ang{cjfW?%cA~QC=IhT%euM9LDxS0|DC=SW3lGR_g>y!p4W>VEL2AH-!S&gypAW z9bE=3)0VysoD9$Pn$)w1V>PzsQ`mUVT(HOFt`KnFabGrLgc56pxoO@R%Mqnh`KxU*ey_^z_*`(F>lR6;NzEiavRd>XkddZujKi?P)49*8 zqNTkymX^LPyHn9+nHF~pru0mtVaS3$+~Gi~F;sc^sz-*^(18U(EgOWh5~ zikFu+QB0f*jGU+&%b-NzpQhU4Viu^QlM=Bus4Tb%3kAwRw9I{y_S$+MdV8ss*^ezw zRic^S>M}4j8**Ea!|1_c?EBEaz-YOhPH1lm zZlzDG=lam<1HE0}2X_S}skx~a{cyEg<+!GR$p;B#w?O zKIj7)2$dG^Vb$-%=glU0=rX&i1ZJSXOc=8qP|NKP>-Ma1}QGw}-@!vhQ6~NdFQlpGjK! zO$F+li*ZYt5fgS5YXq@?tAS4&VC3HY&h~Y6ufm5Cg&xJIYVnT?@vwvVMe~x>6m!a^ zqVr~trR2gJ!?lgVG9tml$j6C$9uw5RVTbY>nKv#0w%q=nF>7a)J!vT6#Z#vwYg1Jl z>HM&j1#V^?hwf!VtmuszwkP)4zdCE08>EiyH*psr)O};rZ@!4-sM%oLEB!EV?>65-h-8zr(%G+}nF`@j zTr5wZ39f*cYKORO<$uqH+Vjf0%iZqYkiT=djM|71ob|9FeRN}h(OZiBi#%7TF9B)? zobKfFq?YTjXm%OiNe!r?*UE#!X1iYDgw>1}9kp=xpUZy!+T8RBw)26^An2&$iczn2 z<1X@l@o+}r^{tw>iz2?6ojp>nE9#!XPdSkrX#eT!3<*8ii;~RC0!1e8d7Buaa(ZI- z|CT|9{K$0rn#@K>1_YA@-I20#vA*b8TpsC}GY9k8(yfqYSFIPwO-Tv=<)#w<`KI6w z{(f+xgaq9Qo2tk-c20bfAv|)FQ>GGRNsB5D^6J+*REw*UVv4 zo(`53m917BfOHzNx+*G2tr8JJMkn_d@!ENG#nhyh0R0$@`={d?B_s>D2w<;yTdb6$ zK_rEU-G0Us|DAzw%A{fxA`C&yQEXEnXxM?*fLW&Cx8*Cd3=7CHRr7hXTAXg5A4YS1 ze8eoj0n$=Z);hoe)`|jksdn_BL!*4HS#yLh+m2yU2*7OGSg%0pHyvF@5UoJYs?W&P zdz>AAT)tPmQ67hwhU@b6@VEsU7i_9t5(WSi`<^sJhA`>o-MZwKko_x3Pi}J}bX2^E zcfi1!B#`-QamE?dh{x)YhycyRZe>P?o{71V7VDq_Hg)FB>^GZZg$jn?HbdMhKHEfX z#Zz0KpAegBjbSq$NWCLdALoiIYvA;}L%Hvk856Q_1JG!`7T}GPzQSVGc=#j-2ghiU zL{wb>TOZ}IfJ@yyy|6}{K7$6!0L24rNZ6_X5HOuzckV)t*!0q2TZ>t=#fqdmpOCaQ z?Dyak6mA-JY?lL*$IiXkpe9kvyfvB?B=dYu#gj`z;^?i;$QlOz$>(Bi-#vvziGS3pF7f1ho# z4>Mc=0)G{v>o2@oT)t;;%#45K4XVnj_6ZY28Ci(`!fx*wYD#ZTwAx`D`<+5JKPt)p zAfef`v5bVUVlz#s@AA+FUUJI*!x4x=yiLf$y;$*ejMsIv_JMF0C6h=QxnTjHlByQ< z!~XD<-jZr@M*b8CCquRszVLYP^s$(&S(tnPiYO72U);uynf-p$j1Cr>AfO$Xv9>U4 z{-T@6-fj1q68oQ@xwGRZ#6Bmre6x7D8(a);@(3FzRvj@k5D!dZB*|-xCE>dmAv3tC zYqHB9ARd7UG2lKO*O!atlF(FBQc|)G5cOOrLLpB-qoi;Wp8iL^CW!d(Iz%|lfE%KCCr;`Y#2a_eu z;Eg4CpKY3qj7%+yWNeCRWc8$=9g@_jc_MLU2>jQL_nyQmNm*C;FmqvHu#ESxnHkgO zP<<3*W5g>4(tdR3`J==vo&Z-PZ6$cjWx$$*2;I!e?s)1ePJT5#Usq*hl_9=N;4}gjuzy*d1FdtbBp^5P^mNd7 zk5tM))d18Xel#RRU<~+kdd^vOr^Ay2USm(bGc(;E0oJ^TtTo?&@yY$+qOhgaB}b0J zUR07_d9lMHTPkqtIq+R$D39MI!KTFuBB#U%{S;&q;r3w?Z%hDz)_3y?fN>eHZ{V0W zl1QD5lC(1h8*)%HEaM}B>q{Gds1{_E{r$Klvh(T-Eoc>@W?a7ly{c2cCr_KzfW=K+ z@>5`Zq_Rn!RzPwB{z)w}9m#-^{QjcIisJO4E{o)}x_^FnAby)V?Z+cz4v~!ssOx>r zsd{!h#u(no#7BoAS&FPT2y^fw<#JxfmU9h{Ed+i$F|4c-V|5 zsnr=p@qdw7|Kor#cMvM#iY7ESgnoNpA6JAE znTTZp@B&sE_b#RZ{Jw>j&d6{7cK`wG`r3j!^S{su0mc>BzJFR!;Nbla==*|V|8Y;i z!9s53zu~H^WPoT_ng$Z;aw-;2a-y4PWIPwFpuD6OMK+_OAeSLV`vGBsee42jb9)`V z4FMMx2_g#VYh4LvBBUT3cs$tcdv9p=&CT3CyFcp9qU8(8}kdUz%e4<{W zz*;c|@q-N(0RnEL%Yq0AZvf_1YHxbHZwfZ;kFbsr1N?aRovY7}ACc%#TdZ7d`+r?~ z3Df49Q^-b#Fh;J>N>z^`b!%(*Hbm~g9w4@zAOMa#98r=7S&KX&ljLw75?XmaP6G6e zmtbiNutR`w(MTm&COhuPfkKM}P{}(q@TNm!{A5yq5M){*B(HWxRy#osRLs2PyY_tN zM)^$wdqxQsN!P!d0d_PIuayqrz?y+&gkfWZx%XJO@Ls~sKE z4e}3^!xqF60RF5n9juM@X!ptRLi5%`290NA;1#bWLS9y|{CC(tvT*)(Lb+tea>@9$ zId|zC4C6b8UOfvWj&&+S7xC8Du;W$;rQ<>D5;osy4Ew`IY$;Y#lzH{DX+scGupM^- zWq7(~Tor*zK!6|x`UZ?T5ksy3#sD~9d8aj6++-e6@x^9On7KGXmO(H%{3yCbuw?iL zSPqcUCO>Y7)UwY%0eHjmPe-(OXu~FuYBtaVP=webH607-zb1r}1CSzRi7x)AFiR2O zn2f^dQHBurAmKQH2R?<|-{;>L0CuZ^w1Zy+SwuXNRpfB#H(3}gg8O5H_XE_?!V7Z2 zGy0N7j8?8QdbbGNNhBS%-+%6G#vmio=}Q-TYtF2ZkJ-*`K9^n&Y}1J@SiWF2_)Hn@aQj&>;L6HUq};Z!2f{V z*Pb{+Rd;FQj=cMWxrOW!+jlPAUnd-PvGGqm37QaLZu&n!6J7Y~5Bh_p6xqzfY4`0l zCh5)q-kS&i7vea-#H_G6agFq5+t49MmA}BJC-rfR6 zCIyP^|A?9SzfCzJ6M5p@ZX2quuEO&$`)phWMYC6+X&3-Ya`^sbx8Ld=#sejD^a{bo zL(u-Fv(tHlFTkTLC1f;>#fe=NJu$J#bNK|G{IY0b8 zgjiLeO@wUP7#sGxgpt%?uhrH_G-fjZDo#XlM(?C;cqm2z4GTIYB}$2{4ZwvxIxL-@ z^!qX}S--v;E!icwEzpy~vewy%y#f>o=Q4C}RH|6IWY|HK6b?Hc#vJiJn>;Ne2t)Xt zYLS@6HW{L!V>^K5>(FaW@-0jLj*Y3Sgn`0Z2Jpa8VVl@(@-_}bSpa!kHk%rQAr&Uj znz2+>ck)M46tnlt<@F#t8A4vIbDt3k_fR0jn=jJPp%EFfyk}260dhU? zl{oUp>icTNnX@DF6k)NkGz!G1Y@3eM8Nedg+x$X_^Tf_jr~bTKaD#+_l}KzQ&P*2J zFIZ|bmT~;#H5dO}cuE@42jb`oe6TbqGejvs4FjS*g+89ktE4U1F~y<3&XT%mm@Q_>o*OTIl@zcbG^gI020BB+F?Mu zYS|1Z87x0eI8O=nU%kh6NViAiaz9K7C>T*FuzYNQ0PRL>`VGUj zw4Y(fy;fuJjKRWYFb7C65In^y8B}##T$~9DQ(AJeDM-r0^6-}0XXc_9>c-N>v9Ad7 z-{)pmlmWE@P($Dngd^fLAyav=;=h5~e`wPexrhk6U8mvin-ea!D=oiRSm!}Gf+pRO zuM55Z4b}d`_~5dLUIb9yA&7(7{|%7;!^+^Y$gP1W-GTf6HdUbf5H)4;iPVM=_@!tS z#GOLQYk(Rt%Pt{Fgm&0C06Q6XdAx|8cm`l_pt}(%_8pXh!CD1n>fUN?%(7n`QlJqN zNXc0Hpc>5iEP+5p$OvEnf~Qcd2-FIZ3<~sdg(vFgL&2fRnEB4OnF>_lurNfj9kjmt z?CatPz;+}tAq?pVdD-t)UIcqhObYwByQw28ts0!qQ}^HP0sd0CO(Q0Nj(}Tct6uW8 zxd;l=Pk!yyIn(-KK!K8;CLV>&MrO>?BaoR~8}AMvgaD+@>F3R6pl}BS810h72>Fm` z$gTZkSfK6=fjDFHP@#e>_*ejWNSzom7GQNC5uKE7KVDBGZqx1D%wmw0l|Um{9N=)e z4wQ^s$cMfD#y>5rfnmGZ57pse| zSeYS~8jDEPVgd795k~$q6l%-}D;}&NBZwrB7(h@Ez<*v2RUFytm1E_sp2z?@7rj z2@Q~SHH~4L$AX(64&`#p;49LRATT{>hou!LA1N+~3yC|;@8bEt=7;+kq8E?3@@T}L z0yqNM&xcq_#;ZHH!#{~Y2#Bgu0d2*`ai}K*xw(m;&Yz5oZ>WH`ux{>Ua;Q%?hpEDcny}k)-HDvhXiPTWWO+tJc(3Cv_O*`4?>wHK_84Q2C=OXggJO1`f z+p6_mk({t#Z-VLW%=v8iA)BoXoNZVeu-aKGZr2_5g46)4K18X&uPJdj-+&A43iTDP z?Padrztz4b1xxx21?p!JKavynA$$iC+x{CU)j$fpGjOa8f$VJc;VZDGVPB=(K7iZZ zKD)ej$Jt_35!nGn_Mw07Mzzq66ua4veLxb%kq4(pLv}kQ?mP%rUqwuVn#Tus5*aDT z&Hz41+*4PHm0TA}3_)A+S95)xIJkD72m+`aj{@z>m-A4F>+Aw5J6<@Vd{ zf_4%Tns-!hN7)@NI!yR^%g)zGad<7d$VvxdE>iTbkk!wcrXF*1HT}Ydc9lT!>3{4Y zR=^76E%j$sGV0B*K)Zg9G;+}cb7w~qb<>fEv4ZkhN3G|SFZY`U`(C;%1R(Sf=1c6? z9Y3gVPz|BPssLVlVJK36My#CLaci@Qk1qgeN=94^j{o}+-~af0czSb$jDj72@N>i+ z1lj^5-|KiclJ;5khmuL8SUrZ<9Q;~gkB)$v(pTZrw}5lT34*In8nn&@61r1_QK|(< ziGF-Z^yNRdYcn{a7?r(i)FJE~cl~^}bhyyelx%|I+)-MiG1sxZoH5is0CX|KDzVf`jO$q^l(~>58Qo9q(2{>=RDB zn*3&?1|lF5s1rP(fEnpYEl4@Ev#YD0`q9-dQyj{ze#ovs(S2wLcT7S~R}AC?Vwiw; z0<|*qHI41_5YrH8z_q>6AdR6c5$>ctY(TyXp<) zK$=4dS<96bQNS3ewHETLQ6Q+N+7q^eTq{pA3YtSYq6%EJ+EOiqM^-M}vtxh?1=1Ci zp?#elW;I4eH3~8d2yKkc{WqnSpa>?d+1A?Z4oAG{fMBM_H4Wz#NuO0o;Kr01mh%xd zRG|vO54-vXmd*$wR>9JvFCms5kY~Vrq;eK&SX?7q;|a_Pz-ZNCFPx)%sIe$g_p-H4)!M{fvtT)r8+;HuZtf<}P&XpG!JflF4Urk~=gNe7 zQ7CaiFd4GUKM-P!Os;3|803b##Z295Fduj@q^4dj z{kC&<1d)t?&s`K-W40-H=376NCB-dO;AujPZ^A)J_}Zr+1y$faD%X`0zi?beLXO%_ zZpVuP#51EbqxFlYhzJI#B3qeFOE_#`r-;x8P}iKE1fa@@Y!=~dMa~^mhMGGp6hUIX zgcpDn655hr0YC~^uiR-i&!o17TmQw5{_9F%EPW~NLg>$XrX|1C5&Yzmph}&1760PD zBGgmh`E35Rll6w$mKugZ?*Fmp{#2-lZHUzT!hbB0b2R@n7CZUXolGcX4_1(02Hy^8 zSt;wM-onKdd5x}Y`3>X0PPfqr*$h)TZsmm)cBqm5&582mX}c3pGUG_1^>xH-<6{$^ z8w`+t$DNJUJ^9V~yK6!X@r7MaXP8YW7fekqGcJjAF7r2S^QiN7eLi;S1`6xEr%RzAAuWG&X!pzZxnd2%w6xPmbb7xjtl+C{gi;yznY*v zMnZ-uTUXwButmGQ%qH^1a&1ZPPP57QH#{Q(K3+DKEsovd(R)HLMr9q2SdTtSxXJyG$uXFsLArn?DM+*qDa|( z0!>$D zjZ1EKq*%nqd{ih!g_(#52>#-ljov9@3YgB(_0h2N{aNUHSqaL!nqx=Jw4eZ7RRL1< zBkY_8Z$Gbv8uUHp#niORSJ)4-rkrb6w-7#ie%+&BYEC%fiMY*lOoU&nO&b)DiMv%~ zVxZVb!X?K@p5D|v=vb0CPt;|LH+MXyUYU5_CX+EDNsXGH%i($365b)J{I&c;?=P`N zstb{_8Ax~`MGyOXn!xQm33M3bw+P@Aa-a#!s|0TnkmWK+t$^*d0`9WBY&8wBrLpvR zER=8}l@d@7gMVAhyZUY~Gk}sP)GNZqoNMd-+zufHIbc^iZV={gv`k%XXNKZYumEr7 z7!C|3wO9j=0aWcb3@ckKpGVFhee#n(3ROp}2UTijn%VR@rx~8MV4AcuZ4AXi9?(5bjdJM+57DB=?QV3uPu;2SwOpwekiPiqbjt^e4w__>v0!=qr?XuOm>8V9^A?}kPC#nxCI%S zx4hKUbVovowXKNfNAW(x(5mjda6=4b2+s*8y>?DV!cSdCYs$BOS^yeCgSrZq;*jQ+ zC^0Ogx}LCgCm{|OxTn>taYRPD)O-R|hYbX@%TFws7fTN)o%h~a3xpS)MH;jqRhr0Y zHpES??UMYRpt=bjMMK{D?Skp(om2v!hWzH8R-%9^NvC>Rj(9LZKfvMrKDIk{va**< z8(lX1n~&N7T2eGpYOZ^IAO zWGW=Vz8JH;zmk?QKxY^d^u^!^$a@%giPhq$pKK z({S43SPteH=c#nPV6vA!Y}+^)%k7O$27l2Eh=OJpcmAAG>x;I%Waik<*EKEQ;dott z`@@R;BU)u~_7&IHgRy&1XOdzzY*hMcL)pvYx*qt8%FQlT5>o^8T~AaF(q3&fEbTdY zRxxVtH3YAdp;vI(ukB5W7A3dK_k802y3_|FJdy(gK!AiBY!=7qHYP|FAvIk#RbkAa z_+TKBx^S2P&&4teP|ELwBphk$eSQ#kfr&7lO-sOd^gB^jKV4?_wYbL(e$9N%xIrXj zh@pB;5ta~!MPfvaf6-ODqcQz%?TrbfAOm#Djw7TW7OEjH1t$y_Jq!ev!0~Wk9u4E{AK=En{)buoGeNdl|L^c_a2l#A=@W1RB1Zx2e06XxKlB{?b*J zAQ-4PYv@paWZA742ZwQn9NN$;{lwbsrcU>Uf#uIvy*viBP4*7t`l)g@k91pZ`UV=- zq~XiNpjAw~OLNNq!`xekRhf3}!{ex^AYc#*0*b^&N&03dls#kjhj|y$3AN4{yty zkW?W0vqP|M02>^UC#3MLr9qYeAU+Q%wk>_R2#mnxo{7+OUzS7JGN|whb6m~r?YH;? zHxPjd$e0MR%oZz4QuG#0~0!2Gz0JWI}l^P zEt~>P_u7yca`pk&=`WW{btVrFqRK??Ql#z0Kl7!V+MG7qq;Ko{r#)NA1M>+X()`yB zE_T3aR=7}m4G6XEpQmJl+3^wR0q)HV4qzbFkg5TcSql&85CV6dIn6t{an3wSrQc>WWs*~d6~dxPlQsMDOy-c` zp*eqx@S*12M->^9!?G}rO22k6$EoJsgw!zP2a1zQD5W=HBZ2CL7&`uzU$tazxh4@(puT~q5Nog5e~n&ulHrmew;#aFDLc>yPaMQ;(>CT!9K%J{1l5$lhgW$53%$7knJp+EjH72 zW^UKz(bt``pMN#lcv1Mf+pWkXMP#?6oWU2PQ#ve2zhek*uF(#f*>=rmB9La-c9mG9 zb`1ZH?i6Xr1dia|z^nM78;^9CELNuYw_}mET(E!|p3X+xhsi>t9nA~&$fWltN<2-J zy#!ja5e4{@=4sk)hcta&|ENNjr4WvO^ny2=bxIRY+Wu#goc>ol2j4Zgxs)xO(t1Pl z9&T;shR(lneh@Pnt<3yt{;5DzgyY~?BEXxmz>i@oN{>e`p>p`F!ls8nYV3+j3i3C&&n7rk5^ z+j!|Y^tc_nS^bBt2Zfu4O+5qHiS+Z(md3BHt1b?0#^_|1d=+kKHE4@xydMzldMC2_ zqD7kfG;Mm#p&UdYc+N_udVo4VPA5 zV#Yf;xgPGvvoFVRt6P*Y%a61_&OUF|GtQ||nJLA8^T@BqKMw&#BiHnghjE{J=Qt8S zU~58BQLEq@6TPn3BO4+$n0YTP73})(=y?+FwWv7^g)ryZ8#>qw1dq)1f?|I?O}Asn zP&%r>Mr)XS$eC*>?_<*oGF!8Pm5$wGj{^6bS!~^2)Z^XnrSG*V>+RXnvm>g^*muMG zaQCmSq>Ie9{hWu(vk!6{*zUheI}VdGS+lFc;queE5QGzsp+)B12jlOBCWZkNt8qPO zY)fF7Ncsp?ibHbt3R<%?S}@B#{+O!>#cjLRgvh?*wryxrbE8)&CCw_X`ca=~LDJyY zbiKh>^8Nt3k!@4^0AiO*O3v;8W~yDL+IY+cd!NocO6S78KXB9B(r_<_+Bqd~J!ee> zGkcg{ePS$bN9pY?pR6U5bJ#=%yfYi^mvQOng9kZRjO26{yxOwSq|>9em?7y87d!c1 zA-=iIp`&)qc3=tknC5lK*21Sy#DS6?Lv%YCEYC-VV-)O*7p2e%I{f%^>MAK$m4=qU z>sWkA{E_WO4GETf5NE8zVzgmQl)b_d32l<#?E3_oCe&P;#%uO9@iRM;s)YORImj+H z&+e>{fOSlUL}mp2Of`JWDCRrX%g8qL<38NT=JOhHKeUT(zrlX>#vr>nZ$+xq zrwN>*M_5?*bRx{*L4Pk}>m_E@r_bJ$|9;PG%LgYk+$htR6|uw3bSBa+*4w^zJ%Skn zxn**5INHJkjen)^K+0WJVdqQm!LjQ(Tk(y^r~&z@+CXqzHaX}x_4k*(X=`3i;~n1! zJPcIw!htb73YSP#1#((M(R`K{fQgXrvlgZ(?Xsbo@LDP6?8q)j`>BEqOa{$T+k{#$G6pTd=SrFR-Xy~PgTr0WqH!NX=zX9!ymt$-nr;2Q7Q)>oID0S#|)!y zRc*6%&)+_~vmC^!)Q_)L<+7e^TgVu1TP`Rao}ajEI)JzdcbbtB=)YLo2w->pt<{di z!Nk)R;}arJr)5$T9dN)@UJCT{i#>s3Z-Rrqt$+5>9Q zEK9Fd#@GtbD1}TNz1q%R4q_}JuP%ieKWB!Sv{fDOEy7MpH?SOE9eB!CnOWE6($T7B zD(N!&`3~vSU_r3(^M~%#?p73cuP5Fgk-xo_W7L!6YZaqDku=S6{03&XURPn#^Zx2& zxR>-xtlOEJ#w(%3H?$p7hs%F^g<#p)3gIb`LgUc+EFd_x(_tOT; zMa5`F(0M>R&{hpc<#`Z9CW4fH5p92|01dbb>7=?;pamr^!IodZNsxvxqQPX6T>jF{ z8`_PtGjm~VU_Ly&g+>eri_3oCN5rT(*;N?JYm#Vg)+Kk{+bAP!0PkX+wWmrAMFTSi z3fqIyuaZVtTU0MGldcVYerP$I&!b${C<%VM*th|spL8qa%X^E7$CV?ZNe<=*bO?#U zxxjT-BW_L`ZDX`fGWkN|V7v`I=R-<<#w1&7)>&t!?e&xLKuzQ9PO|fbPaqw4u^Gtf z4YiuupkWHrsPJoQqgx6v(`9sQT6T2hmfm<#>!dT&Aw2Serj&q)Z=>{~Tg&@K50jOg z_?2A#=lqMe4m#2!BZYi$9DK>ciHgc|t>@F7or{WGmL|*9P3y-vh$HBEeHzAbYWX$Q zr~31x)%uF_R|iNlHU#UUb1Mw(nCjOuvbXA!Id(o=99eW;={O#_&tu(B7|EoWTL}Dr zn0Gd+9S=&=E|yOBb^RM?)|QtpI@8)NRxCt@?RA@gV_(^m<|MR#nN#2L=$aQsfu?VX zXne8bVjEEAG4EK4zXnZ*Dc;c|>|R_9Q?5*wKaON72LdCH-|v3vH zj=_VLRc3QT>u3`9&vQQ#I+FA49&yXS4zOJzS}XLjHXLb_n4aPb{^j=16VIX5+QO=z zt%YZ$anV@6ufS+y*d0p3h!htPd^tjRD3dfpa=kGv zsu<+!^7I=H8%;qO^+)?GXlG}6yOCTOwnv_EXF8IPBO79qfJAh?o&rjF3MtZ2urD08 zvEkt z!-4AhY@x2LnlR^P)z{Nthw{6O9;U`2BJ5W2ZLxyxc4MU|_bly_ACd*5N}9W~Vp9S6 z)*G{F_Ra~TDe7fPvLnOg8=NbjgtrKX*I2W;i#KzLEu!VO4Tr0%=c0ijjeTMg_f}QtJWI+n>JgzF$72s{NX=qR^0i6>qV$w`=5}FFy@wLmvX4 zo*r%%*o3s2ceawzIP|^=b|k!Om7~1M#!SC(DB|^$#WyN9f6>*6wrRmcC(8k1>@HpY1ZN?u*KQE1xCwG84Y`#yUoyk+P#beNl4jJkx?&5RN1 zKHm%J#3*fV$`fzcb#g`PfDCZUiKXbTSlexO4U7`LXKyY^-y~@2*?Qq(OUvg^uqdoF zc=`->N>v-(^7G!(buky}==ftq`aV(J^`KpNy3%y3T;|vJgnvu0DMKGX6=Y{FUk0S`e9)TxLaKoOc)4lgtoBA3DCQ;( zeZb7+K>yOd+)%@yQ8XuWuqyMpi?kVVe&n zh~;c1m7Ha6I8c&#duC%b>IY|X>`(3I^Y7$?Weo@i(ya$=yFKAMVW0Wzf)EM^I8hKr z!p=deeI60ehX8-bzDg%U&3|u$tfzyRMpnQ5JaOYwS+6`6vv!sE#qh!>^~ zwR#G-{D2fN!8uP_UBQD@OGu#GW%v~zefi?>|2t0z^sgSM_N|k!ZGpMcjTVeMGB7BDll_D*|RWzTd9WI{PwC@%~VP!kXmn_OJanWn+$<-QuUM{R;Y2}PxC~Vrc-}c;c$5pIM zdzgE^?ZZXF>_UY{yI_RuA7puq+Tu4b=2|3q01G@O#|pnN4rA&f7Ck3qt<@C6C9V=R z4JP%E6q3{p=Xu{daK2le3Cw+Y-3zOyx8Uvm8?b?7&?Tyxt<1)9&k*a_wkMmwl=m)u7ku z&<*^KO~kfn0sie7{;z_MgT-3=vvARj!ZMUXShsEW;C0X0r=9$(gbQk{i^;peilgz8 z)9DYIj2<&}e3g_-p5c*qIhG`UZz-L2!dI7|>}qv}x9Q$}Ef@bayg@IiaAJ|wWQXtO z_m&KvRjah6I6Pm>QCF!TmudPeG18vFm1^Ds#>d~}XU7=Xjb`3akn(#FFh6K_mrLe} zz0V_KviOv?naL&3k}!FhA&}0EdChKlbV|Xx``1{bzjgrpFwuMlB^W5d6+Jqv#{J%E z6a@7+MbgJ|$t6z3<|A(-_tQ(R6|larLwd~M0CA;Ql@TCNp62_ zys}GDw=@^V3Rt@bcOQ^r0m3-#O%^Auk1nKE|WUXcj5bqB*c=&;)2$33^Uk5 z3YocUJA9tRvU~vq%(aBWJ*ht&iTHhpTso@rbq59QSxC|l*ev|RQcTJg4e`aw!xc1gBSjm5_e!IPrIBLsiw1WmxkZc@@kG(;y@zfX& zA)$ktT=pI>K2eL2NLzL$rhmIYPjr=Js5vzs$0D{WsrQo-hq#HbCt+-=b)ZFRhw%df zqVRb7QByh9h4lOZ)it+-?%~JS6cYR<^^vB<@sf_mn3>bF2u=~JT$~-MN-nY3;8w#{ z@kY5ntfn<{l}jdMeXDE&{^I?oYWPB`(v@|}y0Z{Q0%lT~$h=mbC6&@$ys_W_NkZO4 z4pw|zsVtEeAwyY&%2GmhyTI9P?h?WUF=AWu8|iPdHd9G?NQtW6A}3q%^-O!Uh|y|k z<00Q0sMmhj$r=PsqOH`9R#@OOtJ#sVFZDK^fLT;I$5^4FQfq6*Qfj}XvxQHMhoPe% zO=`rqW=}J}$fL2TJyVqy618!xC;or)Ac2T4Hx}Dx!P+|cel)-^fi64Zwn9*vx@%gG zbUqH+Q!2R22YW*w#c*oUna7`bb9It`I5SrmY`iUZI^3(OWzt5@#>GocaHu+%tl7U9 zt<)-($rt07=&sHxtVAgcxFz)Z5><)oBoR2&t)$*LEpnTwvv%ip;55kc&=`?6_T0gpXrKn4QCSDvqX)Qd zU0@`dYuoo^Msp<7=1jJTLQVt7@Fi^)Nb981d^o&}?*KR9%ih^>IWfjHFGfL7cHsDI zQ|1h-(c170%rB-g|BH=2Th%2ixTGUZoHI4-GqHsgisg(r+!1yEu#3=A&P-R+!{)eK zueC(&p8K@#Ko;=_-pOhk{#9Fhg6%1Zi%GR>`S8T9+j{PcqOKO>$DOpYe>@rj;+@&S zn@Qh%?k{J3K^%3-zdnNbOWfqzDwPG2GF>?fmu$a;e9U@mahr9GzVAuREoDS6w zjDu9R*`SJ8=&m-;(O_6vUXqr)zT&nn1~fQ9c-N+?G#VNZF%NGO`sLc=%eyDwWrzf5w`!Vg;CLVmjv%|^T@o3eZ0uU zN^oWV3`BYuX;m-qUj!DxYdwt`@hw%a7w6tP;=HPS@lid9jwn6;**y=7ti%0Vw2~F7 ze(R!9;iy|r-5O(jp0GaugH^Yw0XFlI2-__KDT^}lNVMZdzu~9!A1SGn3uR z`+_25i1*%ol`JEY&a`|Le+&wek$0}U4<~ICSEX41<8QLjLLyqx9R)tlX@!qu7%7(jBR>zWsISjjSG0sZ`g9-$qD+y#xdBcHvHN?Oau_(o~&`P-sC zEEGFEwVzCGOceE-BMqNOLnXW^Xb8+dG-yEn%X&H~6x!*K#$$ky;6fw~bvaPX1Ot;^k1&dN##vMaEl1CMQ~tOZaRgraH=b?b4s2PbTIs*zzwUkJfY+cIk(Q8V17< zCa-+Wk|%M-?au+9*yQ-g--PUqjDBPhhN2~koxHEG>uX=?3C!NQ7=O%@)=cmye*50A zU)#3U5DK06ZfMDSG@^5Y$tqZX%rApoDb^=6)#&@WOzwVHb7aR?%{p#)t@or1_6CVV zhlG8hoWe{Bk-rHFv09gg6HZdBvERTD3~8-DwX@51ix{)zXMgwHf3+2V|2Z5LKXVRf_NHN`G8$2=yqYJ~K z7qby*+mw!EpNG;Rj)kp4o{R-7l(qF@vv<(%kvh2_GS3Qb1_$7OQ2v7Xdgxq31dBeH zoUp2uJkbSKVCVLYY+T5fz_u!av~hnoGr#$$)i)oQh=>@Gb+6vm>wuKO*&<^jHA!OS zAT9lkFLUK4_%FF`N?IeNU>+}RMVGwxk7vYsF`Zz?JbBYeA&`g#K%Ag@|{Ij>gG(K#O?TXD;feBYWiFL+cl2v7kpZkS4=uKDKVzxr(mzYwX}3xl%H1f}&^;R+PiqcVBNlQRYKw z_PMJ3@ zv`AH>b8Mi2M&j+$K6g5C-ul6s&-YHA!CV1C%o|IIsszNN6QXB9bi*Wk%@P{7#k#Q+ zE}YV5Z~;!BZRo>=AUcU?w{4@|I3FKs#C_)q9ZRZOelo#jRX&M%Jv}{9Vk|JD52Ew{ zLuT=}PpMIX1Fl630+(?>YoAcyPt%ul<^23MJ|>ZW|FcZSAVrm@2`g8m`-ORzA=!A6 z@`c#OBF6kv_H4#MWD&3I7b;5U^t2v!P+;CK%uYq&SM=zsPc>3Ek4cv(&r3eq<=hpn zb$qXP2ZKT-4C7K;459p!^fUO{sRTS&*156NY?;5MMMbQJPn9J^v)>FUa3zn(t!`?^ zvRl!f?pSab36@+Y#6wBR(mW4;Inw`aHaL52$IO#+Y@0L2vZ#G^iq(1`i8Dd7cu~H~ zbYiPl)wC*yjDyf>pj{Ma)-+-_H|e5`ggQ5VYEG%Fo|n@g>(qEDg=b*Z_{o-EguV-e zi;!{YEtKK+Mu^35^3Prv&`DoSDU*E0VwO^3#WHD~DOsqIRgzzERbEX zEY5ksqhWr_kS0vQJSRt`U!*n9*bp1*F2o4LT`2=q}y8A-q)YT+hSL_XA zoUsg~Rnr-{&H9zY_-}p01eUj$^)IU!*laXjwBcF|K9dmI>@MQ2g@Yk5Gui&imt8nc zGuS7kIaXQvs&s{#;TAjD*uL+|Cw>|{8;hjJTI>yIWwg=g&KZi5u?h*P^$Ke4#VOt0 zLiFc6Y|N#Pv5XB3%66j2r>9`M*zf7_$O5;t z?<*Qq5u>DM%;S$}e}U^WQ};~UsrXC(;^u=!DA&F-0XB$cdM z0h{DnNqn99=Yv}LP~w#q;%`HQM7@Y7OWkg-XGLW(aK$`Ix*095EH6uguAVJkjbP!S zZE?u7&}|OG57^qYa^Ky?;Fnfmp$4`FnV1```Nzv1G(FicwCWr5@M31IDcyQ;AxJ<- z=ow3^SFGfC>m(KBLxy0TF?oD}%ec>2lHe~<=YrCHI~TMBeo=Snw7d(z}ZRrKa! zep8j#P?4F!euP?nKI@Cuj%)e1_Gp-*-{c$2*Nl=_FVz&@4y%$Q3Mtxn@9@lOKb^46 zj<|HJDfoRr$R+f8{)4d>)tq_3Nn6_!$?Ob)EbMZ9Z8>Ml*s@B*|K&g!;K7e%8 zA#Xl}0I$b<8tyv6+bQ}{dr$ENstY$`MFueVL&aZuZuwxVOikiZD6K|gG`mKB^=xn| z8GTItxx`_Vz`o5{vuN!2*LT&_xD~&ZO+C}WUUpk-kY0lsCCzfj#HRX z(83b9%osO1RY@mojDMkT?E&4M0V_4XeVXcg|I7V?JNB|Q%${5Ar)V!Pn{c*n)d|OJ zU0bW?G|pT3QFuaTs}A#B=F?|E_qOIo`I!7dAWo-OE)?1qlD+Nk_(%y zlMkyzhT@lSdGk*5gb?AiuY2V0age&Af%A8*<>Mzf;Pp>au8N-q|(^Fvj!cbgf8t+sh z4Jtv>iKdJr>wys~5BKdW6}RsyC*O1*{bkY1rS!fWWyL*q?Q7{L!t&c{Kj6eyB|MS0 zp&)A^eK^lTEpWM|B|BgtOg>#9YCE>EVFiY0W}bH6kfM{9cy6lE^~jkr5%ZvX#m9vg zd77-W7DHOiFk3bJKJ8>|Ck+#GbLdd?_kR zvwbeeo2T!ckdR-}vWe!*HB^FtZ1U>4pfe|*u@Ihn#F5xFtR!CZ`>5lOh5g3vgYH7IX za;u>C2mLkMZy7@kxjp zO6-gGKdf>laFl&h%yYeUuqtBJ#W7^-9SLsX@fC`$82WLGZ(BuQ5_*J3CWj}b91C9g zuL>GJV=?&6w7)DfME#Y~atc?cz-8Wn=?z$`GiKHzwg*)rgFB^GEPOHLikU-QOLtQ4 z3S73Oai8s;#nlO&J5ffSpY$V!f~9{(w-;}1+km#hWv)a^=ggyk*t3+B7lOR`PUutm zv(uhG|0r#jBotQW<8wiDyeIVUJ&lz-`8?Lo{WRw4L+?HhmdNE5l^h*b6FcQ9Z3?C0 zgRRP9ve&b>6NkU(`*vIOtet)LsmY{!in+PI`4ZQ7StL*B5N{|Jx7L>2WY7fn4qc-H zH@oF0-XcPU7zw|Av+WvQ!TjXO$*iHm1dZhb*`2i4=tWEKF}xQGNqqCUILZ2CLA}{r zJx{|gYMv_JLu;drXTH$2RE(l4zgsi*s>mkSNvq&BMikECGWI>K=4AD=edrsF<3KiJ z8+DV5gIOlzT4!WfC@*)uFWWc52jK%ofm7K#C~KSMh|brwjA;p~5#@ItefzK?9>JXb zD)}}_L63#?R@UD47-b?d^^Y~S{J5gaOVp1GH(l$Sw4BEiX|d}3hu3rovN74lm!|M2*eE~ZZBjT?+O(W} z72h%v@1JZm^TY{j6D2JtD}rxLkRn(>ViCyINr#8|ZtuC|J{&~Jd*Pb;o4O6_P#^S@ zpxFiXY(sT550;ap9GS|G+}w(`=g?nvoQ1Ehm47->kDr#G&imX_s;Wpts+~{E2kY}| zL&h}Da;MJcme=ivXw#nG5|hO`|34sLLRu87!;c4PIA@-*NMl$~h%*H;lA*0U5;CF} zv3@eAF^YEq%1mbDR0c4eJ&g&vjzH1tkKgtreLX@Z#=zJBE zJBKW|+pnHLkS1Q=8m`PFe&BF;APNb68I)5?_o}=1CuXZEOD30)Mf%&alrp;LQr^Yy zcZ;pfbTWggRZUyZz`(%JP@)?PjFV(f%Fl=t8iOZqp>d}k>3*tuVLJ7)yudRSK`%Vs zk>?ln{P*HsXGle|BdJ0D*xjg96>Z0fFBfHkm30dd?>RH(+7MNrO8da65Ug$WrayAyf7?S6Bt@bZ45v)Oesw$ZNaUn*NDUooG~4 zES~s`i#3=#X}RyMwGH_K2Xr^;R+^n`x!wG6d>&a54+JDauah&LGuvWYTU(+D0v4yc zb7Hn1(m2oE#oe5Wao6@a>$I^j-z)xV<~13&)9W^2U!p-kuX#CG;JaA|U~#fB{Ca27 zb$WUeXd{KHr~m4L2s+!Yb5}7_E}=TZ zDk1yiO#5BCK43m~UAnWHqEgcmX@X4qpK=L9u`9-u4Z)!uJ<_)c%5A18h4r5S82xgZ zWH44T^nlUIMNK`lQ=a+5IckW{$WM8K@a*b2{hv-lmF|v5XE3Vo2TW;z z#T%lslVGYHur2^C;oOPnk02MI6Bcj))3hX4QJBEQA{TI-m)8~84f!cjHi9IyK=2Kv z3n%prs4Gj~dV(dXQlGOWctDG3oeRLhsG5^LihFiKf5>4B*T~`rw3LXxeL68I0-Xnm z1ea}QI>Z2NJM65q@Fy{ybpsj`6dEc{8&Y7hlH__W01rdu1^L(&;~Qe#*WPN%COdB| zv<=0An~}UC&ErrjA-`BTTudUGr{(QHPXKRxx$dP`AN%|IY2=hR0^xNDO=3b{ zRBs&2L^#1Eb)+jv^m)}n_r-PeDP4Fm@PTlJkV??bdpvt&CCAdC*0#=A-UhpBz zJOL-d_p1w&b=UoO!9*spnZuWeQQU^qA7~V6Y)oS`uZGVv*&J|HcpJ|mP#$#s;fYrdWs?Qb3*js8I1bb~7PD#8abM6QKnH#X z$byrcUNZc2nq-(9o!2$AC-iTh#@xAv8oT(6h2(_(x!j6ZlCqPYYLOs}WwYH+PjWY9 zdb7u9FsKs6{kZy45&R1B1TF0qLuRh!{R9DWveUd`{Q$1T90I8^IG-R&!HFgCWtp8z zAlxx8(41W#Zz0@(;8D+i4H}0R;&KnRTC5*j72hGUz&hX1k2E!NZ$JJP)85nZ|iC z*8N}~lvj)3T7V*b606-G*fPU0{a7FEh4@$)0KtiE8GD*wI z?usVF^!1*v;Fzk@66XN6ILLs(wsHY4JTff2D=1K}vz<2SNWC_XOTuBEnH*=@F93H2 z{_9jb#y4%g%d&Or9mnH4*j*_y>lg3Ff{(7;nj~$BOVyt1FU}#je3qQ2C%+S%7Jq;l zBkrY}ch`G9#tL|JB))NFy8{t!XLb6~YmPO6L=qwbg1Q%j<5N=^a-aiO|5Y} zHK$_P=gJGX&_|A`QlU&*iFL7~r}Sq!(yj}SSWX11h%cs1!Lb~Yg%xKv-v=8f?KFn! zDK9GU1hiT=H#7te4USJvCMP9{MMd6FN`Jn?kiwD-4bfIqSo)WPa(QYNUXYr`x`)t&?tppu{!+C8vYad?~ZaOBKc8s}#^zVC|!Vk&D1+)Qx-d(OAkV3HO=TqtX;MCPuW}9K!BV}%$-BBtxh7@-s zZVxf^cs&I66)GaTP+19zvik}__#_TdowCOd2mu*IZN46WW%t0_As~x{iZ}=yqhC+` zqRdQV&;8EN?=0Jlp1;H^u2iI&3Cw3(IjMwfvV4;G%(=#o36ls~jed-xsZCePfN;#) z`x|K?J|`!qJn;#*52*hr#JtLTsuW5+@U`FbBv?u`%0-FXbYsGdtSnU@ydyVhHLBcxy38G?S5S>EeY)9bRx7Re- z{yYf*Y^(UVTr~eBNeJQV5%(Zn-8h@`Sm68-kd5Ai6`90z8qP?yc$(O`H%OQU{uaz0 zeG52#+9F}bzA7`<%KpSTd6OYdL`<5918sxP!%OeLF}JPoBXiX*rLZsZ> z_0JF#azsNc9fcAF?Q=n5Y(K$%sz$2g?czI2^#NJ_&W&pMSrk0RI!HEdpMuCZ(iE>~sVM2UBa{ z)&aPq)4HVTy4ERAZ~;1%L$VcGh;>|GCHCNYus{_u#1;1*B(;gIqKT9!Yw&{;+p*Fg zs&LE`#PYzx4S*E^$fRxP8^9nqZlQDcz7OWay!`9`Ts-MNLUfuT`08zdhA~P&b`7jl zJs9qhz=yZP@vWStUO%}PXSbZ1@H!yd;|Jun5JSo>NGsO5G+@3(02vFiLm*RuK}z@5 zdnlkTvIE{zttm1Ty^N=3ssWoR6N;wsci^cuS9n%bR6q|qY&){HxA=;P)pSa8;#}_W zwTD%1dqt+bl<0D`Vsov>7+OjWE4)dgcV2vYjhuH|G0`0YWTSzW4$u z(bR`enSy*lJhfbb<(P=Ajeu7z zWSNdoTW=^|xQljZU@S)F5m-@~zrHhiy5(4A^A_|q-{2;Au6ROU+jUK;1-}ut{sxqN zA;@M|ZqLMa|7x2JXFAn9E>h}i$<3namS9E`tOlloYBZgL^PWd*!hL7AkaT4V_uX8A z;4=u5^83#%_J1Ie8#f@u3n-NJfG-TVzPj@jJoSXj*x|VbUJ0@J1cwbu_*gFl@?905 z+<}@gn6)%q;h5i18qRH>O>i>KX>F#B?<#_w6McP<=~#L?xG-))h;I2IXbs*RSSbMS zLB?$tw2n1%UtaG$=t8K>&23el z7wG%}S|jf)MwOhUEnAD5EG#>NXD2i$(%t{*D}51J%j zD5B;omD`y?8UsaG=wQrm8@jtE>T?#>rET3cFVQFq#QJr2*Jb*Xl(e+;1%Yr9He=D9 zt3j5s$zVtfffNiAV8a1R6bLNC$P3a$*SWu3e(pbxctXNI@INxov)Aw2L5}gniy~o018BK(y>JYCox!%Z}gpY^V@7(5r1+V5?`blMmfc_JQMSnZd29DYDrM-yoe>2k4-`<{}|SzrQ#!H;*x%>#xu=-elF zOgswYGu=4{;Lz7V&MnJ*Fkd_@?(6~iqKb~I5~NJo<`qjK(|uP2r^=G`4Yhq5)~YL2~J#dlado>+}82cn{b@wl@};wVapWc|xavR@++-$O4I6@y|2^ zvy&kbwL0n#(NZy6Q>~Ab2j;pNlVFza$kt}O=KAU_pX%WXQEB{}2V`5fO?$pt_hbmL znGf7CvVgzPgu!UhWa+No`wC6e)gulcrk_()$9|aL0y3@*P+pSBac5Z(G#lD!E#UQT z9G@x?vo-^oG&RP_?M6B=Od(+w#yXC5_Q&pth1P^xK ^gaT@Sr?3IRi_l~qc0#6~pCgbl1ypq8r0SM+Q=ITxr9Y(Day5Nlni5HwO zML<7LFFc_2Cbgm>N%F2SycLqd0&H0ix8&=uP#;2~A=L0M1c_~@3RdAuA#};?8wjxN z87j;`l%y-s)7`N6mu*+d0$o^C%Ek&1B6+Y4fy@w9NcKN`%YaeHS}tF$EnblLhk&I z{yeyky@XF0kfX7I6h;B!9$d8B{qS*7Cceibpr{JS7DSd4tWElPTrkQv|9^1Rhpd<6 z^idR}gU|tSY4iSn4`xV`2Ygo$`B6ZUKMXN`?*I0H{(t{f`d5N-85Xpirjz9LegKMw z>;UZ6d5kDd*xpM-3jk39D--;{Ghpepr}z^%zWweB4^9s{{NN-(f|2ksWSmT*@6}z{ zLjPHOpH`>alU(l}MMTmal+<%-RD13tB(p?fnQ7+(09Yef`hc)$v`F>z^~K~I{7Bfu zo$$TOY-b^=T7sRKc(*nci4O=rV1@`Y5E!?L0{`XA38se|Dh1|zf1~OE{qP6agYZF^ zfKg}_*4!Ma;=?IcfdaND-!U~C7jSPm{b=Fy9!x&0FrEl z5T=}qYx>hur=?!Qm^B`~P9-pFPc%8MboCSkviqU70tqLFw%e9|?=;yieD6Fc7USzA zAQQK;w&rcojbu0LFqe2seEIU_=rMr)K67vi{#xYJL1Gjf8(1zYRH|Ue&|s?l7Epi1 z1skLAfWXYvD~Z@W_0|sv($23r*wTq1?oIW512>wbE9*XB5`X*q`{LL#r%`WOo();t z>Nr6!4BlnnSz$id0#cwr-;pJIK~9?Yub~eidMv&}CLPT546?A}MmpI8AYBBcPT{s0 zM{pT2@P>fqctfF_>CgiN5sDrJko$k&;^CMvWPC=iNM!q7vOtmW-l6kJf(Y?KUnPFqJzE*q?;lATB;>5ge1we z)M}-PqXF;o>U_V7&sikjhWZ1n65z}jJXq*evXNPDNzF~j2!QF>Mx<=9qjyuU?i?NV zCq#7zg%3;+U7PJWmFsk&ynKTe}y84S>^9s z8xom8=0HR6@4@wVG>TlN_)!HRF81fs_tBC#uMqK{HCf;|0m(v&{5wmBC{dt#a^~c} zfYNLPw*#!B*E$g=;DOavsVN30WtpuB9n1G2bUCbB;2h)$5LS&7N~wvd6=!%+V1IVq zh~fgEgAhm)ff^HY_8>Jc5rDGg`Wzj?$DWsiG{hK%!SnorL{cqMm{oMw=hpxzv>`}+ z=mCuDkk@-sbJrzQ`3!zQ+6KfnpN9HLRS6);@&4H-)qpKBQj zRhuWIzz6$#fPcZXA0h1JPeI030Xjr|9S>P}aI@VxDin7n6=%N2eTKBT7;NF|7q%xM z7gVu$x>ad2-?s)ejG*}6AW$K&?TUr*DIR}`B`90K$T*EY($(*+pI446pi3N<9@4SM zDu}%j=`G^#Am>|YWc6N`ZMr_)cUMc`0&X<|*rmgNCV6E42NoDk9wZJYHh*iAU=F7A zfNll}xl(z+EWOt}sGhN`x0{#t`aPWO%39W`OuGsQ4k;7anBBCUQKVyeKd>tZ71o;N z@rdy-PU~bFv)FYV2udI*@+E;rPpa|pOX z;vUBtwI@S0o$AFXWaqS6q(2clXNCXCi_6ytgadV%#`=DM@d1L}6tj`qtQ}O%xG}1t z3tQqulw?7{48)eG&5Tp=mHsikfTgui?D z&W9qXbS6CmiFRWi#y5a=e&E=lVudgyZH52#98c)~Nuwj&7sA5h{$+#ygRX(7^HVh- zi1_d$L0*awx)(Uze0itE+7nk_ez43 ziC>l;wIPgEI_b`oNPm%85;~H~?y4}NKxh*P2R27SZiaIrNI@?{;50941(HC}nE+v5 z{IBGWd<&e%(XQ*gKq{5xldg>-7HvW}L-(&(3Z=~R=*MaYF%9ql`3C>^14IGq;_0>| zU&ZpJfj99WR_X2Sg_02@qvo}*$&zq@Q9I00?|p*cyVju)ecvD96%vWbP=z^7Z|xLg3B(ji+~Oa15t-lYu@NSBw*=d^0W%+WK<-_jb#yc zV_@si6QZAD{XAF@5IluaVg{ZC5@Pj2nm(N(qdn#c(z*|fVqum75OTc?*SKPRF`1@yAB_Yjbe7C`jZCqKI3U`y0} zz6ZQ1u&@NI%X6 z`^{9PjF1A3Fr>KYSqrAfi5pin!Q~o`S+L{*Y8k#ty~vaf(3Z>vsDlCJK?tA?CN?Ib z))=(PR)0H=_Xam5O!S0)<-xu)9KsNi;Sh#{5`-in>jLk2t}?W)1kX`9RR%;MByXRW z5WJg}<>f?sj?&UnBO@dEsYpn8h=_>9iOmBVPWPojxP-ZS02GfDVsLX6K#71N#xEvE z4-uXG!FtvF5BK#SdN>kzfZ%i`*;! zlvzN=djyye_4S_u4WUd?yY!*$;IW9u%nQwxp}F#WXMDprFsQpw1L=scYo|9X`ksg` z;qJE?;My{f{}Mp#_p6YQqXJOWOFuTX6)gc!dXedM?@`iA%~(C2L4Ew zA0J0|M{{T+L-cvSVo*Jdh|nqw`)?;hRc+G$yN@U*JuJF1%*Uz6d}$|pIK@l11C3-uSu@0}5~ z(=Eck5!i1261=dQ5RS#j;-;hsqGk+Z{6xJadU|DiaFt87Ta`>ou!ugr?1PL12TIJsqv&JqcM!NZHEckZP4e++UIC#6}6CcvDPQoQCSc>}WOk{q%qIh59vU zwW8Yic+5fQ0WMeKMI+zfIE#jJ=!*A87%ekgYHis2hy%&QZAK>H@o44gc|+j{o`urW zATAhZL<=UlPkL26V64zQbZGjU_I!kB!3*-v>AnY$NCCSQAkUGG+#6HBT|xv8$V=p> zYT9m`0VnlaZ0zjjHv3|0O!uJ4C?&-iuNshVGGviZ6a)j-Q)C~oZSfGv3Muqro%_*549RPmOC)RsxvkKB%4kR*DeML`1zZq zT;dFemW9xYuU}Fbm?K@-*mc%3UVchCDDO?}B}4X2N&jOk{US4Z)msT^%9Fa`r}QH# zZ6tE&K3jKqoqriEBdF1`NSL`85JsP73n?*eM1|dNS zMf(U6k%<^MIK;P)v#!QUTFFFl1CmH`bqxHDCxWc&g!ON~k(t(C=@8CfxZlnt6H!?C z{gz8)7juIHI%BUB>TsK~O*F;7R zt!JcrBwLwowb-T5jQ_UiL7v#!w*|wX;IZVMAZ7sCo)c+~)4VfZ(2g`U@#=l~1Rbuh zQVLAErGasG7&!^4JKR;4#?9y)0DINLKrm?H*SXUIOf@qy}2g%0=nlAN*6u4mS zHiMB4)LlF-5%XWJoQ)J78lZm7T|DlW6Hole6A{Y8Znu{;=r8)DL;>EXS|R$fHUEdX zHxI`$Z{vrbnI@)%Hlu7Q$r4c{*^){~*^^z#QrWVHFi|NIMM`!evSr_yHd&IfWv8-5 zmh4G*Ki^w3)Al^`d;fUf<2T3gJjc}3?Y^)3y3X%;e$LP0a@@;JiAsV{1piCf1=H~# zf+2P?l%@Cfk#5KQAUyiW?P8-WI=VK)!(62d`l>wk zpl(;Fk#8ej>Fbr+sPktr#24gBKn`Rjy>6M9ZD}j7&8e2GPtT8^I(*=;ePUtv)h#3E zX*I6>{bOGGgr}CTGHVlXe$X9x;TNL^hyKR_^21MJ^`Pv*2$Rtkumv2?4b#py#64a% z#(Z?%PIGG}hsJqwVRBmDE-mkJnfPSVAv%Bj*omQvq^lfkQVhJRWMGf|;ZgWCyA%7b z_)8JX4VEVgoa{?3mg%@%8!1=q4f)?__vWYJkM(VZ9I!k@7~Os44o357!=@hemVLnlgYuggX_6=c=0Yyu@kSJHLJ4g-RAsFT4QZ{ zP0R8D3FX1E*uzhsUJP#F)8BdSSVw0TtL_qS;bfyybAL%bSC^UUO6_!~XQ}4pRTbDO zx3#h8n6J5Q?=auK#wPvfu(%-6F;oiX+YJU9(=pk{HP}6RAEFx!)!Ok>7WS5>w96x| zc61+_lGDCbt<2A5KNECR=1zFFjas~a@os)+SM_3HXD!;DvmZil-fE62-3HS~lcpE!t(0$F zSu&L&cQ$BcaFJEjpNa9gj$-`LEh&$t&aN-l7t(-rb+3J5QD znog_kbUm3IbG@K==h<8r#X8M4E4tIdbsImOX*=9fEFVzkJCz*~wL9Ix<)I(HxJwNS z&6?)BEt1*cL7~H=ll<$v1*s-edL6Y|E#@sc=aMs>>fc7z1pc?;`qws<^kI0Mu!W_N zJPvg5Nmv`M=k^NASNoLrZl~b2hBX>=QW}Levt`R{4kyc1-7@JOl$Aak#h>tDY59)6 z$?=Q}ZS;wnjgd#*M_lcVf7j%ct2$LB%Q6*s(>ys>^VvuZwA~uPCW${5ng(lQmq^;BnOAVus4AtK#?{ISzPqRtl+~ z@y|{8iOpcTKPcu;_ur?BciW`rAGu!SE+C{|RnEQfW}5$_knOBFX#yqB5;-64cAlNc zojv`wJ%~-d;2cjzg{G%*=gYveKf6;KiSA%ZO}n5UysW`^`E8?NnHl=J#JiUIi$yxu z^muaIJa@Zg=@_T$K+sL@=_i4obeFAK<^K&mlhl1cuV4n<3=7jMdj+sha{SMIF)nAB zF%jH1X}aXG2!z-Q{^I8q722mB7(Df=3})fsu|Q`6d3myav7VFF1MGLO1%{wq^mG%a zup8VN2|^E|EW#D*UCXJMZtj=KOuOy;|y=>K7M?60vtggyNDSmBBwq?qJ z&;U^--FU*{AV4biV){;25ii0v*F_!ZMAHR9!PXX#whxVO48(f_RS54gy8TW13sHH> z!S7^xw@&!<6sW?uXF>Fd)8vSmQ<^}=ghz(3M!tPgFH@mKTORU7ovvkfDGkT=A6AHa zh&HoVM3Xn}iX)Upn;9)nKPq1pNZB8_IKAe2w%NJ!ktd6!wWP}_`JN3`#Y)1Kb*bjH zACIglIeZopTxr@$W(l`?FCXnzQ)`y>VXyTJxJ#?TLYwk)%1qV>#C98}wCSwe#Z?;_ zWO~F{>|*fIt{#Qkg=hD^xD#4s%Ee{tn$5kDOHkNE(<=Y)w5f5ttMS_5;9w(FzB*B5 z#^W38j1TzUs1-OK|8D)3>89w3dfpUX11rXkxf~Qo^8d zvV2LpoBo>|?zSu+QWM{9iWR{JrT# z;HS)|oc1#lska|(eZj)Fkt^M}Y2b}%M8i}Fi`n{)mVz3F;~OSe%(Oo9l!vLNZqPo?k>whLo(=dkPyt zsRD0z_!wAZ-Fht8(Efyg2Esn#w*X6tpId;S!((G(M%m0ru2e7N(-!)G_3)AKn*2o* z*U0|KYdIcC!1fI`y+=H;+c*p6=z#jVMC7Fd!vYf(09lGou8JKGQ{#D2&%j0{094F( zgUKylSfOGVp>VNZednuSY_;?eUfIuHv6DHjHtghj?n}!V(!gu$dwRZ^I+HU^QA&xE zy?V~m`5nts43onm2dA*eC1a(H(rQs9&X;);nh}i`u@5mE zTKy?SU50`nr2(SpevvDfEjUBYJiur0r@W6}?JkmiYm$UD!PsoM{Xbe!&gev>Kn7TL*6_0}oaYX3g?y3?`o9{3j_BLJ3hgswiMOqXkDakM-%h*-* zp?tO$2Pl2sQhJ|+Hy`6~PmZkarEV>M9;xS6)Ee2|b}ci5Bbq~u|Is^oi6J}5n;H4} zr*vNo~8v6!YYNEvHkyE$MPHd|X$ErJqLQ&Cs*XCYm9W z<7S!yMd8t&Q9nCyel$PT%Dpmkg=z8N#HDo4j9{v9LCbJeJ}HJN2AT@0$Nwju8DU=T$^S)$S9i6z|d`d@I@^A-CR z^n0&gnU%)XrS`z8O>t4;isyUxC*J0GZfNUhd~M9@nDI~YXh)_8w5N%JA~0|8AR!2sfGL zG{c&eQw~YJL(JWs`SfgT95LU68#oP09$jS+yz6pyIqPm6C*hNg53tj|x?Vzya<_Ng z25H=u~_b66thu^4fUmb$29FC*1wyDxb zguiU+p>0`s#LN9X2v%4};wgZ}gTjR^I_DVH=_>G|m+#7osxz@vM_vBZ;#bOhywp+O z?&UIZ+mtk3rup-FetS$IOikoUVe+H9#o)F?*Fed5EaRshm7qY6ra*~Dvz(*Cz7@6? z&X4x^jFzvko9>9x)&FBu&~vc)H83`@d1kkkycALAr1wD%q1?A3oK;7A^eQtU zmfu(;Yhb!=c??g*O~L#5WA~f_WefWxO;54!e{%LznPIEAL6o3bsztkQ@^b@lqqlej zit=Au%p*`q-EMx=ZQ$BuSwY)-cLCq4Z%6WaYu&OEba~Qc#F94+b=u8xT_0-G6HEwN z_yjI)yX|%wJBDeD+3!XP7tcQ}602=SHJVx8~;rPMuzq=MOR7W!iZel1W1oi@~|caIW>~n=tlk$rKi1MXx#GH zaeLcwce;yD2m{^J12S28<&^;GE822Z&XYwuYu-_@(Vn)LwI}5mtDZjaWV))cS+ZTh zee;^^Bu*pwY5Uc@j6qr+0?9KSISqC@bep_ycnE~~9#P3td_jC?-1>KKHT{?yPMunt z@zb@#A|3A8^r8**It+}5kG9?oaTjQAzvFv-wC1h-VuT&nK6PP-hQW^NqR zK0p2IM%6)f_RDd1v^wY!q{ekstPIr+4g%8GCf)DX`~JHvYrz0WpSNM8cT1r zNs?c7+RSbLBZ*{_rMFL4aJKABdeJxQ^)7dBShKr8sL57;R=Vr2&OFKI5V2v|{EJbm zul1SJnzpw5s!6x2&o=nB=4EA?3RT>swMtSB%Ik=>UQ(W88J<2nEu*O`YVJ0tyjM40 zcbmxtNa>_N}^te$+|;STKD8=;EMUUVXK$oG4w~2&0QHq z|D4d-sAz6kPOUGpFEcE%D>QFW4&LulHj@5O5f}@c)$9}ty>wzPW-XQI$4`)%{DS=D{++8y0x0h;@v#Id7nj#o~3Qs z3D>5~JKb{$Rx_hFoF&q908QUJk>SZpm&)x{8DO<3CBN)l;hEXYJU5+tj|%1I*3VqL zyzZ2I!QM(eAVXNW#NYmlL$W!3RwPG%)a0Cz?Zo?ep}wXQ zQbkis)sN4GT-lT|e!0T-Lha%2T83ptb7XW%()M@h`KETb$J~7y3_p({)@h^O z(}B)ctSS?Y^PP4kt&|FyH?5mEf5r6qA9eO#76Ri{`E6DVQ*x6&5N6K^RO#-0()g}( z=@FYf$(sgJjmmDn3Gfi&TElL3pSRCzrIr#$(%4-Q$Dx)Ijcq&C#wHR&ewn@#rQKvV zXk4OR)9f1_cFenFSg!WjCcYDns;!b~cq>nYv&V61mpAZ>c?b-J$(P>C^Cp1RrElpp z|NBxj+8hPE2deZ=Fz`i zX(jw;!*BOZeVJwIqR-S*o7a24^p^G$yT~P<$991(;FQqmw3#_RxOb%W@~@Y$c$5%M zlN$pzN?ToI*MMy8?v%sYp&M>%=h!wsxT95=CYNm=?P}9*U-d9h$eVL8N3M!?tEJbB z%;whn_wEX315i3RMVU;~zG2B@*Azw+W7bhpP|y4ST28Fga5iAAvZ;^>d}JlBM%%z&3z7@Ry4tC0* z=DPvg?_}mnQg=NBiqVII&a=s`=!%t6kNYw{KaU+`A&>qW3wg4)g&qP(1oSVE-rb5? z=r?tz`lUBy9hz$#_3T-2G08Z>vy;)yCv^Uups?vvgXY67tSsHrY8MZ$=@@>KI1V!s zfst8VNdY@arwvf_ph*oom%6q0mbX^1t8rP8bx2}ip~RVsJGMr>Z!oc+Fw;8kF7Pxq zo1xLX)zW*+C&B)8^La7t%&>s1DfFoZYXNHyFHd! zbLyTf)+osQGe|amov&X1pBrmOEa|3s1oNC*|5IXO-!*>+5ZxcoxhsSjnp#60TDO~x zw%QfOUVSn9xZqBAC4=%)%|0{(&oT8#6oJB#$fThNI5GHH9Es260*Ito+ zCk@C=*%0HzQ1w5BaQ7oxvYUFq5TJO@Gp=OhwtE0QN(F-E9z3S?uc?Vt2xa5pk-yeK zi2cR$bNOa155b~o$B<0`08#4*J+qFYLU0)YJ&oQfjuQmGk|>+Qorgpq-7F{&uL{iu zw6Ro(N@3UQ3!AR(+Piajkx)Cx`1(qIuL7T32@bm}=0EIjT&CehcqsSa<73zm;;r9bxT*Tz)@2{8Qog_YA=x8BNCN0D zZbf#4O|5%>*?yK2)Z`*Du`|dD-g;j%*!I083i8A}Xq6^cFN_Z&rgS(4v z>b}0Qc0h5+^kYeMXJG!YTxZd*&FyqkM=!R@(b&(*W|to`QQ&|%)Zgzl*=SbpXw83Z zB*BvYDD(5^SewJ`iDzWN5)Jb+$lV~ya9U5baZq&AZvq`k{ux0 z2$lhqA4yB^?pR)@Trt8#Cuz7pYw#E#Dfkr6$1jC6KQQsqW=fW9+|PZFDmlig0?)n2 z#yG*k2!1c^iE9*g9iJZUKK-dQYjy+#m~v3H7%T&S5=Wa#?(WG(AJKLwFID;p^8$bs zeH~Zmj#D=v|9}!o$vo!Pwg>Eu;EBnNSKo_m4-v7M1T}5pjv-C}{et`3?`~6Ky@x3T zFaZ|5z0=!Gp9#dRp2&K(-WduziL@h&DtaBQSzY7^eYm=(V(evU9XFd>$x)~CLna-0 zyQ^LQqLIy&Yx$Q%mNl{&eI`qyuw83@OAae6b@9>uadjlPnuc{whB)}U?0^Mi+#4$M&HSij-S zckPmyx*pj7Uk1sxE2hc02h3>S3wl6jS-nJ&v8xRL6wk!9-WMRxns5QSya;XOH zt6m)tk9{FsOc+r$s`G3kvb;6#Tmv6wRi5amSt@QOQhhVtu4m`{jQ%^j=4$#f7uVdq zj2-{lVpp4nJ6GnN#9UqttLQ&zKJPp5@w(j=S@|)uAc@AYl&buqZHnF_F;L4<dkq zHWr*=O*GBBm6r7z-@EGaIOQxxA<_LJuh zm0cF%e;#|X#nDR4aqNJm=m^<557|@wS}y*{&79MS^W$t;j>gHKDnAXd_B-llWmLQk zd@hyj$!^iW60pQoJCjXUrhmFoX6ta2%l5ZgwPSgj17n)kW{L*ST~NApCuy~$PFmjz z!MjD5H=k&4pV;&+_zmp~3!YMjVaL>j>5Z{fzZm{bjFbU1k18 z`h}Nmm0~Gw2@_9*xcvS7RYyDoj_TUo98m2C2Z?OXrQ>@MVeDy^`7?PuwnvhMrt2LG zoevMxU-fxwz7XQ??N}+yl5Jo4=DAFZZS#?W#~JyYyXM2rHYAyf8uOKDhgHAxv6V?} zysK^5tFM;tP*t@5?$%N4ExBz@vNmwsnd~e4WA@}dHWfTMflIQ@E3|Jk4Oygg$HiK< z3hr>O4p=qRFwwKvv3Sb0)$T?uYxuUd*)s`j0Q55sRb@TO?64p1`Bjo)ZaE~Qz}33U zl9j(HL$numbdLLD@6dj1pU&D9E^0LvSC-te%R+N^uP0BiX!Fpv!Pp|*lG&ZzVzaAO zz<%}Apv-(m+FKEW#Y_#eJ0eV0uW;VGpVwp&c6hyAw=+wQSc>&LebcjQOQp`JR)Ti=cUg!Ej9)xH;FIjimBgzFgA*?C?aM6-9#t3Y~9>sqm@cV=Gh z0wuR%KHX$U_MTG^3!N&zP%YnUT2)^YytYSCap=E2!LUpKRq8LJLu;(2pY8{n%YZFm zxmLeU;ro%+7=z5#l4O%5gBk)&H;S#B-de5En>BlGe{XqsadTn+7#26f8kQ}oCkc9% zcq*tcrtG%s8k@Db{;WKlENH-;o=%QL(FeKUQF0#Ii0q|x>WU&*i^aM+{?Y4qIqOii%+kA-DRAzb?G^-rRuyv z#?E&xv1UHo!fkJHvdN&Scq>nXh+^{k0B%=1p!uqt3Qa)34G(GeFq)TyhXuRsDNZ^w z=GEG|%VNpgZ9aVxSZtqeIKInbB&{<+0k(nGX@Zvy`je4aw_m|E zG1%djpquKW;F{O38A{fiS|*%wq=Pyu+%J>KyCY(&d{4Ki?=ERFVvR~&+RnbSJ0(a+ zn>M#&f3F@xgZl8WmYZP}KO?)U&HVeBAFrcYhkl`$75!xyD6&^6)*y;JsONQ^x=It9 zuBG(y{gyCGGXiAAu_)~Kt@0%<4|qlmKG|h*_H=q3)L|Pfk3C7(b9Fi*NaENk6{Q1x znQw3Z$F~P&#`0%4e-EWgWN4gTbo3H;5c=37?eq0T;i!ia$28BjKz7$Tab`2?vmB2a zDx<5)CiZYjs-|HMP(EyYR)?XGpB|v^hx&rdE5g!iBc5388$4i3`^jz6Y4L$jI+x6| zBCppjni3LSH7&2#IB|hvR?njS_DIC)4!RUGuaa0J!8>+*k>O|D1rCno`YajA$+|T5 z|MDVKw`8g6h%kg#>26WC46Z%y>=lC%T`Fwub}%3(z`8ybC&l?5R;^b4IHuZjdjD8Gyx>f9V8zWyI^EFv*ZcR~zx?3x zaypi$i}FqPJp-am?$ocB@qV6E3eOE#=H#DEimP=@`Q*3V zyy?xvv}1mt&eE}$#Bj2|Az|3+K)ZBMyYaDXtETk8-V}TB(&MVGbN$^FmwXwm+YYx^ zSnj@cc`ijR+l{u;TAY3F;PX40Yup-}1|JLVTswbEES{#EuBj{cozr24uyo@I*3klX z>4zmW3H5r1D+WSe(GBhx9GWZS4uHPbTlYVay?sb2_U$ze{Zp&_R`b#KtGaYe^5l0~$@llC z6Ng91*4kKqyC32U)V%B^G2ah>i~ z32@?2oU{u!_948wnK~QnU(3{K&{mN3FEC;t0NBv^@tr%dqFh$lF`bFZ2-Nh=+DU&9 zd%h=6^1>xEjnxGU|3lclhmr&ugJfRJ+)vm0{qkk5uYF3UGj~kT(bLZnCVzoOo^3qc z;^S}`grXA`8?X#Z<@IDF+)d(3_;OF-95(Nzm&iML=s}&Lk-9f)kjd^O_R`2R!}3xQREV&yUsdQ(bjvvdzm};phXVKKHh!R?nVI|j9w5B zv5HvVZI)v=U_p!U4(K$s^0u9$OoPcJlJ1HZ?vj@!=_F9 zCJG*UZ`EEc?%&85&;<2`QNo;(XEg0WmOHlQO0W&doL3n9S=;%NaDN z>SGTF-!1j|s01gA<0tH4lvK>=4y1T>iZA8iIj&kdoQc>zQ3?Wp|r}O{fN`rK+uwu^3FtGG9a?_ zLMb3+{oAUQ7NlJIuG2AF{AveR9C0HakIo*Dvy+G6h&IGqYA)fsUDUKi93b+*H#tAq z#!b;^8?f;+rV zWp@{Vx1ayy>*KkPJr~PE;=tQ?0a7|mFLx|!h#G&=00_4At zUl(U6N?`u9fv2e_Q$VUA!XAR|3Tgu$_`(Q5m`KSW>(}-wXCmUS{Fq^v8|kOV<2Ghz zyfysv_VxS%{E}i7W0=)l`N6A~ZzCIsLYS+h8DV4SVPP@N0LOhRS&bF_t-=$HS${c5!+QwQZ-K1I!0yzhSfS z#}R8#;$%RvhFbIz}pP9J)poHL!RDXG(>X6lWXTvz1tEb*r0hMiem zDbF1Ttx`;6pf(x$mT9Yf8eUPv?`1*zLEOiQ-sA$#I`wU2BD(ClW^I*LSn)^S%4^h& zbUjH``XTvW^`>k&gWXOH}$Jo(S} zDfzPS&$=IYN>cMq=5zrr#y6VP}k|#TlHP8t+9D zZ-_^LHq9eMU8Mpj?tA)>7_PXCD{~8+Y{^P8;mKrz^p?nz00UZqicp`V?SLF5@3s7a z*O&=F1o!3)!?GKYl^lszkrr(}?^Fz5K@Es3)P6Cl>r>gJKiPQRX}fa9-s7l&!yWT@ z!fyffem#zmuC3KvnTA4mtRb|kwCSyF4Nuc)o9g<1{&2`0juMGMK%Ox#5Y zjgIK(jIuvP9;m~SlzaR!RbLyHT+zF?#w-&){SibwrDi5#nu3!tp=xDQfk*T;(bIqY z{!>_Ir8}b+K}~v<)cCbZw9!%l1_QON1)kHtf8+(zvd)SHuzi{~ZJp!E+E|}nllcBK z_-HjnhrSkk&PmXI=~)cPl*#co5zoN{N>x0wdLnjL=T*TvdST~Cy=-wgL&C3XcZt>l zkI5k{SQT!7Oe@d?f#Vcq0E?3=v|Cr*pF_fxYTH2>h@972?pO&z#yvp$wzuPMepE&? z?9Qfcjp+!H@tEVdWM-nq5l#?Y6at@9){EbXx7GWx+_vWZMYT zd(%)rCoDD0#)?9Wq76mmh0HJuWXY}CS*2mq(Gh=)a4i?cZ$m*ENA=(|PvI`SV=qir z$0N-earlo^8h2%U+*j`lZcFA(y;hB|hqs7$Ip{=gm3maR#%vtqGxw9m-|Q)b(ZLFO zVSc8sG_v1YIFYA)?>*Pqk7-BvlXH6*TFh<4-@knZh@SU5~dg~cG6qxGC^)>4DlvhhhcPxucmGq zw)Ji#97mT}Nr8Xr^Y3chfA;)1JU}Y{?D_DwjPM82aU2Mr|I|NPXkyj1Q2Oxyk>AV~ z3m%C771>gUOq$$H4vAbS1UudnJL7!Mh@Gub~;2)xIQeQJg5^MNprs+}2t+XJ$hW-ZR z;d^x#r7SEgqJGjz(h}lc>W-VU%53v9;$&G!y>OdK#ccqnuT+3O?rz*Sh3V_#kvL?! zLjQ($fQBqnYaMy#xYY|16&XXE`r~1rcW3xwvkzf=W!}7Yuo7gmDX5Vvq!>xBD3u*U zyS2JG7n13+ii%*E<}u&%*eoANwno<{sbIK%26BJQNp;>(WnX}+Fnk`aXdSt)h6e@D zhlDl@3L=cA6Pp#APEcb^)P8X6At3Lr4Q*InN5PM(($e?LFt6Z!y;EN4Kqya@c|3zv zow5wY3z{+=?^917hHb|b{?u79hauj<4i_uMKhPi1X4KQNE2@2!Z;QEq5!-r|9aR=gB`Cb6ehb?Pxj)&C~0p1 z2a5gE%)IBA|-X+Xm+ zYr_l*U)?Ph76wbofrCs$zp-^En*7uc#)9OYXe@S{-=BocaODg+e$0F;M=VPS3l-oL5PqIHQdUSL&i`7#BkKM?kM|YbmC-n-i zFBR^$t5E#|>ofFr5w7EeD6y6bU6x%`R-la#R&Mp`FLLmD@M(<01{MASOV)6hb;MHR zJOp!D?Y!9^c*oF}-lW)~ljD6cX)L^nUjdHYoK&4(7l?R&o9}(+ruwS@hWWvY(DN|c zdtj@qOzdP*^d-?|>N>P-9;9hMH+C4U8fXA?3?66*9NlM1oQ#r zwN1|{%j{Q!@@P(j0@%A@^(Ri|2FvjXJl0Q+Trp0o9u6yKXPY2tNrDK{+*Ifte(*01R!}1zxEXc4A zQ*4ZSFp~IBQmxfFa~?cs7BO{rV4{t|S3`+`T(|2?1f?s3vvw93Q8SZ+U?}59z#{G> zj7-RH69h$f9oqir-4b_~5pC~+R%I6jZldg431v1e7ZH|$k;G%`;Po#ZW~{%-&>#ly zW^k{w-_uhSE(y30CwqvQ5{!F6g^*GgDukia%%h9TVm7(KbmbkiIRR}#rDbKx$j{kR zcw6UDH11f?t8aETNmUMBUANtUI1T?q-G7-lz==HCfS#=npb1i04DYeTtp)IDN9hF! z?p$_eu500HTdn{#dKZ&!!@*49+C#%t}GHm$cB*q7nLJJXs!BMSr z4!$Qw`lP$XWBJ^si`}!opD5#P&GEDnT@Xri9;J}M#X^33RqDCvQIxc{PY+bW)lQcV z!j!xw-x6K!0A|j#+-pE*P(mrLka_YP*~dt=q5pZQGf0$1?r`@aA}h zWo2nADvjX<3`PTvE_yQWO3r=Qmv<%|Qz`+3`&;AWKY$G z0iSg5t;Y-S;_n*CVLtpE|FZV@gR>)VFusw{8~iqLGg96|ntR!yo&%V%E)vJCX6i2! z07SIDA?+Ch1A$u9T<^oGQUi+|AL3q$u* z=B?iu+UBmlB34dR?@q!bFHglvCWr`M$Y&IH2q4SGgNh0Yv{*f!k@?0P>3d7ve>{r- zZV`BBq0#@_y!!|K>m&r>b8r8D;om{C&UGc?`NDZdvB!9Q{K^I$3f1jBw0|UP6u}!c zcBI><80vDdBZWk{PxM!!g=gc(NY?`95e)b+Ji>{516MRL)LMA0nL2ye-Gnu=MNrWtBOg+e8i49TO zv$SD_I5(_(@&$AePj^ z&$PFbofBy)P-)a`CgG95x&l2@-_ zS9PT^tX`h%54yAtc_xH6huh}dQOR6`D|`UiI!mV03lcv3xnKYW!zD)N1sJR z1uh3nl?|iRbSM^=Byp~thOhXOHI9zuPhtJ0h`+($Ww*M+3?|T5FB0L-|G|gFIR>qe zrKa+s?TCoEmE=U`S*D$6(B&UbiJ>&fvW?2-^+JAONT>SdA=Ni|d7&b2d zx074QMZ?CDtZ>FH{>-sD0iobf{xDiRB5aA;a41Y1?*gG+(AAjVbqV^)%<%_L+ULqT zAQiOVmj*3@6>;Qt_5jI^%mt?`Ve}}8H?|NU{8_&67kKbvN2SmCnhOXwv9KIL(9GY> z-1oMB#9s)zf`8C^q$7}Yu780~{(t!~+;A-+HBx)x(G3O4d0I-D2BQ4XxRiL*~fhORq6AWJTyjFb6U@0CrNlDB5>#AP$`L1&%K0&1M zm?$84E4qB-Kf^u?^CJu7^}QJXXE2FzIBz$7$qW4$f*necQl&x-SmtDV!F2q+uq`cT zln|h>e_5A3PV=}mZyf93(p7{_t+<08%cx+L_@+Ucy4*W3Knf6rTS^bghKq=A(x z?4ItzO1^XzS;7UiwzlF=r(=RfXQs5N_l{{Y*%c7?AD_H8F7{FFycH4U<>e}pHys)t zV#GMI51!}f2e6W^ll7CZkD#)rY$JfYioChJiE+nC2+EbT`(7pmQ-D1i6dB;CPDoO+ z9*U3U-QxY1Tg`Zqs40x zmpD4&lw7t7hc-#>&<)@r7UgiB>beVeF&ntHm#bG$)_k8K#2>Ct5E6{dJVG9jr9j6( zDO`pN$NgE7v;{Y1FfJ+IHfk^U?EX=HIrDQfG4H&}hZq7Fwi{ePzz7(~$Qe`u&64a{ zqc)&~kTJwoIa%Y44(zf{II8P1{L3)*PmD1ctN?rxgBWXEgNlFu6bm-G*v@^%G(UT{ z{SBSQf3pZ9NFT-dgEV~$#+aWc&M*46A3>+Yt@r=R9}@*o8*y)`KQn|jez z1GB@f*-Z{Mn4*X10_1jt9Q0uH0$=(!9(5ck&q;;}?mXdobg4{Xui(tie~uNzQqL2A_Yo*8^B7 z&Td6U67dP!X&<4N3sYI@n&2<(^58K7wQEHjSTu3G|cP=A7jjG-$uR#SZ0yv7>51Gt7FDhA`ZIJ zR20}~@xvP`ryG)C2ae$puE|l@N1-S$#3h_y^)kA$xyHn?NW~h-gc^A}2~P>$qU3C) zyMUKD`tN<3A{Zv*`tmKbWmJf22!%h`LJyB&p{6KmwDE**86ti#R}wS(zBXbV4l21D z@?JnR3E*-(@f!Bd*d~*VD>jhH7+KG~2kJs`RHwUu;|o+7^qBhzgvKzj2@e@gwv3D& zeG)|3L7}CT2jlD4pDa6u7zq@0m?mREM%GEv#BP-Y>tMU~-OBX)&BXUkMd)|_HksUR z{e4^hZT#l~5##Sg&jE#R*baBJv4bMY-i1F%5@{BaNdIaoo|JNbO>g@$hU>GU70OLi z-@nV~I+6cUM!!f~U8wbxbXIU_R&BcX9Z)x6XktHA@JeCu)P*r-(xUzKrzuv7u=o$P?5*L7@9!tK!cFRXaW*4{dv-F!zBSaI&=7HO*BfTCguhe4?e->FyNM~_vOn_ZOtlaSQ zoW&dpw2|->@Hlku0(>Sp-L-~W0R3w8r6@)_jJKCou(rcKLt?5`6;Ck+#qyy%Ws|-~ z%lN^KLVOF2nq7(E7%l0csAw4Bjz`p%y``xU{VT)D zCnmXf@mCNn9f2(pHszOKhLdw9vR6cn{{^w)Sq@;Sx9K2DHNx`jVD&^2La#X19v0rb zy&d$D4>*1ZLt||R9{BxJO^^mg*WC-5?z^Y=3EL!qnwWafXSbpQ+v3^3C-hu}t{xW7 zWrQ7tn7E5nAA-Mzd9~+7d6E=>ZP#{^AxKgnZw3VK05)l~L^#HIL*_ZaL*Z^nXEoskA79tRfS ziS#l*V*yJNX`||Dv&^-dPRl~6h+0H!t%w6qXfTXr<6%u}%i>2YW^t?zn65+$%L&k> zNcbM2edI%U5SR>z8`K4?s=?18+#)Q+8UKJOW>^zYu%J4IflCw_RrxAL3deGJxplyn zf01!<0qRA z#4GC}s9q+ImL!YfSY?KFsabv*dZaq8Zo6l4$hldB=}Ho~Ls_W%#8Xob!kt4_nmq;`{hyf^=u z1N?zc%dN{aKG39ED5lc?3VZ58^n8HWxTrgQ5uJD!lS&wimeK^?$prKIerEgOc3lO{ zmAgN^e@qT+^lDTEo4vCDl*R2+I-zpkA!7Fv3naUd5V$sBypWPf&8KlyRu`P;vOBC- zNA{x@=`cF8xqSKN0P1bf#Hq%MXLJa1=_ zs{95HcwM<;qy>f4v#TKB>kyIe4|amL8M@T$ap{69EO1L88k=$d< ze_;@mt`L9!JK|huSws=E4EiU7*dl7$02&hLO$Z!OeuRe%aB(5n76b(nP1I`b4Q!UA z92PzVj?XDAMIy5BG6)IW#m}$kw8DdM&-3^!@$rZjvSv3sT!ME13kE;eZ;}!k%JxGB z-*-qlC6)B{+oBEF?+}vs=TY>c%z*=!#@DX~l^_yLJ#bA&P}GbPq)wu1#5-vds(CwaBUluS;AC9{*q>=J&xV1sExy`jCibb{AN=DW{uro=iODcz zz%|aft6?rP(3px(aU=iUQS=D-+!)NkNm(%87yjS-J=l7Xqy(T^#NC6klpvnq|9fLe z3@<*@V@X;l@>$5X^XsUU9}G+jD+GXHB$SWj$6)X9O%%*`HjAm3S53NsFfbW1`k&A*c+oGW9}23Aba90#tS*%a3cvx_tuhqmzH0rVWN6!)j6Z`=vg7M^)XU#@VKEOT~kxS$$)-(y-979WJI+IA?8+r|) z@i;aT3-L}QQmHqq&YLI)=omBFwVT z2;a&LJ!X=Xz+X6iW5ACzXuzMH>`zLC`e1WXZqulEds`&1bLdSl*p6e#;sbaLg-;LD zc`5pA@P(4W$_4kR{CW<^fy|VjB-QY7d@m;6BbFh|z8=ID5aVo%wM|C_YgSi7yC-RN$$4z+%~-A?^^FEhOdzebh4+2Vk;bZxH|v#Ckmz zgoc3wK^o>ru0fh>FwDaQhZO3A4X+7`kAoFvU|17@G-17OJNzY@nU*u|kR^+T$H?~Z zXQtSvn;(;#hQ+yM;{&PwRygz7FCh8%kGQ%P)#YktoV*S%)WBYz&Cf`us!K{Q!AsaY z0NG1Z!WY<)bpH2{^`op~;Ozvk9rU0;bCeGZbYrjA@&nhH$&Nna`G*n2Wki7LiBW`@ z&ZE7{w$ul=5uY7q;FOqN!t(l(_JN&5IwouESSXy2H0l0F$FTOUu{(>m2uv{*`~oIn z_-2#ct%Y)Jv6~ynGyomIc){O|c17d~c7LV~$u~uXvHlZ-p9a={Fq02O47R_2I%#Kh zb4iR=(>*_8+-7SIS^+`5K?sb+WA#Pv_TS@?(XWA@LCPv(rM_An{OD3qcpzkUMKxW> z*ZOL8a47Rf?Kla$?#K@pS>AUCip!P)^8f~?!5rFOvxZP`+gusXT`DLIoSY1o+vsqn1;Tn>xT)P};f9qcp|KNdAf2&!0LDQIzx`|#T z`4&*2udzz%9hCR^X!rpIth->H8ZpaPQhSzvx_(R3y$vKP?~3vGMo(rork%Jo5J#2l zx+TARPvOa22Q?IASnE8u;nGsF>_+21;8=>zP&GW}{{T0{mWepxQ>J^Meel~$L*^g6 zOt7}#u;o4Oj_aYe5b=O@W?OzXkUxZ{p)T4EwQ72m-^4Gp?74o$4jU~1VGL)iC?#An z-F2u+WuO#rh)~p+G(aM2F~@Veo45452<7R08UcnRdJdFYO?;#qn{rX)Rjc=sW4-Vp z4jmrpe?>h>mPU%63ua$LS=>;d1PPRGC?R_pM17O}2Pj+n%;779u;?ZDw=J?t2Xx;E zTekDgbOjT}+{^~{Pz8z;;WDx_MJNg0Hd%|XHM+`g6yc{LwLj`T8J5S_lW@CJ?FG4r z^65TrOJLe>*zVsaKz|Nji5&-PMT(^R87!i7pMMX*iMPLT?gP^e%N0t$D5Lvk35Ac& zM9EtHXViZBJ$>kNgbcSt|7u0bINV4!zh4~9Jh9*9AAfdnJJhFq>nz1k{RtJNc>j$D zYHa_Wm-CtVe$Y4X$(jI+_8dDGn%uunM6Xld*u}kUrEm@mMXFyx;7AY*>;>=gvGWyu zFhHw`3r@N$l*+&h&LkF)?BvA}V}&#}W}D~R<$f^&PYr}2KiF8I!{?OVX!TOlM6MzJ z*^Q<&oKP8-9eVgr9s;CkYWH}L$6jv6PpRQ&3^>B=XQMG3Av->%@JmkI57yXWcn%dp zc8!>LpmrS!-;L%Cl9PD7!jEW_T#RMOK}gMF>$l)o=0q!6{S2_w& zxa&tb;$Ni$jv5^UuYOT$`pt{zdq|{(JqeDQ#)<51As^}k$~Q@U0>=y)^OsXkJiC8= z1IyqZpKP$}HZMg8*1ME`8gpz(3i8F2_`^WTfbfaDBhB>KX4a;3mFT>*kapkQA4{2I z?CWe@2}!w73SuvDlW@^OOu~uG1*C24x-R2n4`1uS27NbOm}$ZZjmT17T@`$h1B`%# zGrg#U$dMmfDik?Fd->1Fn!8s%j{A!WLxcs)&IYwoOUS(0c0mXtKwA!8PW+P1mIaH1 zp4P?t(J+Mo$=gVKOd7e;=w%T5IN`V%^~q(W5wPIn>&^iy4Lh;NCnHLK7Gv`n6UXug95m$`V(b8Zw##U~qtcv(Wbeqb;whx+N+s zB7$v01l1Xeh$I#~A9}vRah0YsxvR-0_lwr&2Wk-M&8Rt<{%QGCft**!qK#xmiWw3Y zRA?)pC3t|hi*wi>m~PEQOWe-I7zhroJ-%`x;yLI=hMw+!qFqCW4CI3hzu;`)Yl8_E zk>r405EfQsKd7~EZZBFPjw6H_k~o~XMKeP@b{6;5lNcf8z^fZQ?k*>43^BS3goFGw zZIA0aaAM1rzlgYm=z*u1l#G8P)p{*}bPz-SBY_F}7xr#a)Za{8LJvV9#5DbHG~t9e z%6fvxLqF$lVQ&97`tCO$350q)giz+_7CH(8~U7}hnFd7l&o{LNcqNtgqqL||fYy?_Mgq1TJ2nhVI3nz8u zCg_vt_=&LU?E6<>A15V~Y;ls0D}PJR_T5YK$$_St>ym1-WZWI3ELuW57iln%w=S8dsGOapG{5ciFVC7&IZ5x-ImX_AF?dKbzp-Fe-Wx6kjJ|+qm(XH0* z_Gd8tCfJC%&7Fg)QpogW-1QBGANJMr>lJ7;lgSI#=0`a-f$o*`;+b|EE#s_Em;oQ= z1!;@1Qz)ElPJq&e@RE^Zw{{M;ZiI?kDMt7#M2sWb3Jyl7P5HI_1G&Z-piy{B}+@gGcQDX zq5K2qX!kb%W##*S{@=l&t4NS}8a<;Qf>23(GS1M+jjNoLVhK`g_$P(ubQWM9kVcF* zqC|v41H~Rf3gM7(Dn}{^*JpFy^s^y3G{)U^>nLH&D!%CU0F7fA*B5gO>4CV#MXFVU zcnN}XaOrwk;d39(^tItQWDv7Y#L;ijD&#n7_*rxI)u0*j-30h6rIdWmNdCP3yvz76 zpYkh7_(JU8zg3dY%7%Z&Qmjh-PycWDT^bIy|B&HOBC(wKw=(CwL5|vpYQ=h9-CxdA z>Qw#`B3}(*^Z;<)*PNLEb2_5S#)|*VQ|}61EW3TM;s47OPE z$^&2PdB0sw(@T*wThqv&rm-c6@g{8jAfRR#_H(5k4K$?#e}J=LU+j^(zT;yZQNxx&5mBqnRHzXouD}FCbS=>gpxuh+^>_xC#vU2n#vp=K&Qz9543IZwEX&7VmQlBax?*SHD zA8@ienB72wL(RpL-gSWyM{vAayb4BB!~ci8cY&%gfB%N(HwGhynUQh|F;qxXA?*r9 zBH6WtbRJ44WOR^{8i&RxDulM$NvT~rNhPH+!=!`V`J|*!whl-qv`AnuJ^yzf3fDL!@ckOzP{J>IbC<4;e}fU!h$xPFe&0JkrL?@@ht>kYz&C|38?{>mY_JSnTAuE9tpkaVaW!mtjrP(nA z<)8`52aHq{Am!>?d2f}ALIf7|orPA~!QxgJ+Q|96BQC<#wz7j3zxa%lyujbLBDU_- zL{%YR$Hh=5rWE^^95)n7wAd?d*Qs;Q1{Z&B;i)~YnA*@@3)Hftqhnuc4nHv3 z1iM!rC(?>W?3dUN`kAmepT9}UXg<7|;zH&T&;f`Hk{#^QTjfvg(;Deb?n{FS-ow2j zn|lDbe+`YdWLsf0l8pI90M#C7KM*+4ItJBBtt z+M`Tfy6Q+GJ)v1+qzV+}jikk&H;U2@ajgPschrg_;{h-fXmrd{b&&CDSmQ)Omhv>( z!bG|F2!L1u)Cldwa<=?PY*#%sDe5P(vlbQ}kLa3(t^-#_V-wsihzP)q!-4G zh_ryBcCUY?G#KcX*Y*h)iCBd83{eByPyK#zwD{k-9D3{g0tG<8^aBJpvqVW8D?{D+ zY}^l88%$!BtD6k?ke2CBuW=$1>mITbADk3KE27W0|3-q4avvJV1n2W#U@hR8W(jvZ zzUvI|UMc9Zumo~9gi}#lhd`jDv~u<8J6Co_R`&5B1;%Payq~lhL;GP->A7WF&h7`L zF~olAH@&g*{^6(jg1)HmWL8!dz?{@;e_;!TB{usSADnM6wGvYhyY?A1SLmN$9R!1S zpR{+8e}QaMv${E|*8BiCWN7F07j_`ofqY*H6Uimb(vglL`^6%-_R-ip7`_GjI)b1Q zxuxnFZjo9q2kOQcRyVNQU}A?spm*UVVm$Nk>~8j-+#8*RFb7zu4{f`xLbZ%+0+W7y zhP9z@q3b%fw|6r*K46K-+Zz4?y3GP2CTJL1!EH{AyW~FHL4R)RoRK#UApz@7+vB@X zwT1yu3nxJIdDYT2rX`BM-gT{sb&hKInmW~pGi4;6j@gc!52MV56w;%S?h1)v%zvio z*oAwYr*i=?mSc8rHSSI6WYr6+R;*Y753kF88yqSmgmX`<45qE_KMqYnQLV2xt1^3{ zzjKKi>+Dy+0f7qz0FL~#+b|g;ydjr)a<7;c);nwH#13_R-r&(L-@8x2wtgR@@6??) zpA3{oLhnenNnigy=&*WS=z|)ZRf`Fo|R9BjW|cCsGzJvw^fDXI}66* zpYq7h(jK@7q)`+eu${T%(0Ae&E2XrhZB@U#d(#I29d@tcphfz9`3SP-;!zDN>_IJG zc}x=0(v$C<;@4cY8Hw2V$`^h!c>+34%`3^w*hdjQv$cazmYb zX%_(X5@50@nS!?e@3rdukkSNG6(Hq}#WEwH5OgKwMTg^T zqr}kDr)6Ao3JMBFsK}o1YBs zk}m36{QOfY1=`=w%V_@5-ZBwJBRycf6kPT4{-GTWS;nBCz=y(RM&S$Pu1gcIz4O2j zfrvg160RUUI-W3*7ovjmI_Kqsk%D>3>hQEIEXcw^^z4STch18{k2)yR=V}OWji1rt z!bT7L7bDXegPW_+93m>GavYjmNZHW!I6TKB<#g8f6JYa8k}8s%LEAtE?;Xw+cuk;B zHo;_%EWMwrbaijsJ7wzV4u2?mvZgWnpB2cQt&BG|d|q%5`WCyY3n#bzIkhdk@*JWT zT(v6gkF6c<@Mx+>i*yNxnBKgjlVl#%QNbIn{_Ibn*pyD>q#o5o7PV}5ERDMY@yb-J zRaPBEHn3h~wp@NfJ_Kwt$(ej!6F7~Aj=x9bRo8ZY-->JSCjn+V`Q7kMm>k2@VvE-U z&<=s-6xlt+7Vt%=HwL|X`+5oZIwUt-NZ3||xhVtC9W>EoFfG1;n#XO}{~+5bg1HU_ z=XGzp4D#rX!18usTh-FHD~T3yT}V5o36kLFv$!n)j_zFCbin0)2wGc@T`{|I_P%~D zaHTb3;yg7*FKrBkX;e-?BaExr0r8IWqovtbJo{kC8ozK`u4v3}i)s)A*#~eF;L#b;|P*cu#jzx;y%)jnz%^8^hcp znSY>UO;K_Z_?k7*L>**OXj5FQ?SsD$U#j};$ixM@*o=&b0EADY1w%I5t!#$im=tIL zrz`xZq4(tSJdAMXEa#XI6N}gF)b1i-wo4~%%c}X5>R~{(hOwWyAaD>Z9Z2DR9^y;(Tn`(|@_J2k%qdWbT<1y?+1Rn>|)nZdp&ww6di$^MYiZ^LO%={XSMY zC;BHVB_HP_d56~peSb`Pxz93d2WF%%f0gr@;qS*}UvTwa{KDd?YkGCV>lF2~HBGN9 z67Sk3?76-5$=<~F?spB7zWVB`Rd=o!>c6`ge&mJmi=VzafBbp9?^b|p)w9kUqB}{G z%{epQJ|ZQr5+tcho2(SlY8VZ2)&_j6RV|y&MF`49ztHR4vARLB=id891`1Ny?O9z< z5bEYp**ucnBbJ17mf=%@Vi>Q@OdeBs1f-;2C{&Np+N{~L4iF4gGo6dCnkNIrB-zIQ!M7=C+YGex^{~ot>h?nnuoFEO;u6ctm-1IJ;h`)kXoWO-C{B^KdX60fcn~iiBWjt zQ@7QwwH;wSCD-%TrNu{$EZlRm4lx?+p-#ynfhA&g+LoKvK+nDNNm|XW)^hCtseChK zK(BSEt_`I;$fx36Rco-ej*JirGfZi=bwAt7`zmB6w6G`J4F{?!466&u*{CYL0h1*cVMrEWEudzuR7QB3)6oX>Ya0h_7PLYot%#{^n(8U6soP zvy4j;+O2T!)^z^x8ZvAbF)kSi{X&6&#cQ(|5Q@5Z25Al3q9xXMkqshctzW3tVm0aW zB%IAtO9R>GcWHeow+3>kDJZ=aau4hP1ToSo0JfNy-n$;GXq76PLuy;j-B$Ful@YSJ zcm~VC)8SFVUEpdnb2k|vuJ|}M&;Cbhsv*v*(pV0BCFwxS6K?UcvQ3&(@tioYf*_RT zHZ{c|j*xNH@bLkqzLSmNJR~xNH*p|hJEvVc+m1Ky@Su-1dJHQ~)0+F<^UjA8{?s(% zIl7xxaVGf2>ginU6vfYh94x6RGN>_J@5R%*u33ipIUN+{qs?+aR-wO}*wi4o80_JZ zN5%;Ek4S(=+pzVBvBw7Og}j}?ti!4Y+#1|qkil!U(lluK;SfdIkY_k7|k(SCZ|n+nQv5 ztOAuhPEfc>E@Bdtu>bdN+;S+|SlBGV_ulSstO9^&TE0CVor(zAnToO%5S`&A$)6EW zIh_k%mzG~BzCsoAq-&e3kJ+E23Wcxp7Y?7}JJ9$8WAoJE0-1aYkS-HleG*~|yS)#X z!$Co(MJE%`)_dv>Q@&}d&v3?0^t8AM$v}lE-IKwZ*3H{-^~q%rHEryn4rLL!e;*#( z8yZ1{$9-andiRmAozuFTry{nJ`uCDWf$rLFcU_IROit>21GpUM=W93wkz1J{0;gZ|pTI4%+?FZ>9nsqK)~kvLgG^`yM%^UU_d z3gu$eZvGPRO2#|Hx^ow9ud~i>;9X5d9cbIfAqda;ZTsAPlp4*0A4bymg!@FkQZP^?rqYQ2V!tSBTPlwdfE(Y0~`2L_^WK* zCL0>?J=!q~YaTF$iur0^^_3dam-^bya&05DTT>T~@4%_0v_U?~>s z_!q{pOXT~|RK{~wa4G%8FCysg;XfS=YHTzTlY1^mWVbt30f{=Af%_FB zhVE@!q3M%E!%A-q%OrWTwx+Xu?)hb-RhO46*bGx#m0akn7ad93Ou`3H;UPq->||Xq zN(w{ynh-Q%2d17^NxTPAL2@mug%VvxYDucz|@0-w7`?HU+ z7arNue*PsJG>x?Kr=C|H*Asa}bAs?frrFnBklBG+^E!Udk6*1_wa2l5lKmu8^E|=u zAM9|j-Hthckz?=*d|>aNisNtxAdgSWj|Bp1(oC0Fn1qjxe)=89tF7X>myq|-p0VOF zL}2A|p(IR}ccSn;hFT?eqI7v%fc?<6~^i_<-y0lr$Kj6m$O2SK6TAsRIzv0tv?s$OaggL{u zIN>Vs$9_fG6IP=NH}>B=as2_;oELs%+yNz3d=vcf*Z80U#bI0G#|QmK_!E3(K0kt+ zh1GfT$09xcfYOHkcRcsR<+g%5tK4usf8ifL_y2OjAMo3Q zRRf-<@j=O(4QAyD|G;+_{c@sf?mVC1(Y0{cmaLLYng2{XnfmCIr}P0O5T7*>vg5kK zc>pGHx2k|?au~YO6(b<^MgbJIt`sdL@0;}FOx>1iN~_z$DWbU7Y(_P#zntr_`ezrL zG`sK=^Xynb=u%<@PhBC5gW<7Pb`Rfj-L`|mZ=^b`-=WbUTu=8+SEiB6w(&jU1Mee{qFVV*8&wiYc<{(%QqK#}H6m}cb=Xa~N_t*# zejhF6fsWF_ewuS70`X4v7Ld6HqR5&^25dT9=+YRg9ofCe6G`=VoBi&9Qq=0x3wNBh z&~pUr(gp~%%-I#j)dq+m&!wv=cS}*Y;ibi)eT)5}6X*V_)R;zgu+>BE!ovuEc;%d( zcuiYtQ@9y5J*i()PNcNVs0o6O?>$WAt*B`*JR{OEk7}As;iw5pKebovewy)!rdj%I z3+9%V^LXh>H>b|!uS2W+@bVqUxZ%a|W*JWW`}KFKJ-G;NO*Cq;c03ioWOb1{B83$- zE}qC}-~||Rrt4DHSzlP2;@4~iCgfLsp^%`T?DbGyGS2(`*~T)wOE=A?kaVD7f4!1h zJKB3ruWf8bIRyCcTPr{9K93$%>uuigk4i@krP7k4)LMn>;hjc{h?zGgMW&I?oEXJk za4s#CwX<7>{Nk9|I!kJ56g<&dd1~X{YqBZ-C19csUfFNA%E_`An z$CA*-q&2HKpbl_>s-WWY;Jt~_t}XPam2^?qwhiNg8P4|NDLVYR;-(o6v>{HaW4=SB zti00&fVC32M)~@={~0n2y;^>r_(LO1|?tNlM1o3We|VZp!XeP$Kw*1c?U@fWnt;bi-!{|tp+`F8$UN|Rrbw0>t?3uiV!&nfY z$qu}>-Zn=L?_JBeLk=uY4j@3ZD3F0fYcr*%GEQ2e3#~wAqsD~_fC%B*pWdMX^8t#} ztQX^hM%)b7d#Wfq_K2X1{Cn_vNj>K*RGEyta6MEf)XcG~`^(v?iVYg>lMW~~*xo(y zRiJJi#uXGW{Mw@K6a|xh*xddK`-S5XHC01ci}#Ew{6_f0lK&1LC9G$G^S@AG{~umN z$qP+3?nB$-0u`?}yEPpC1`r?qzHlz?YKUXzsyv-mdXqbu$g?^mv1LPPMZ;~(DQKP& z41Y4iJOUQGA~uB%xco&m(1E1p$6|iN{Ed?dfu8IALcumomUp5E(==JrnYuxx-diL( zuz@JxQZl7vVUDLe3b8WRza0D`w~6`~@Q_^X&h>i3wt$2@XP9TCxg@CnWH}x^pp56* z3c_l~AmA^O<$=izkqe19S`&^|Q2x50hl;Gsa(8x)Fa9xKy%0$0wkfOtjwyd!FPuh6 zrE<7nWSPUc9acW1`ILJda8}D|l{SnokFhQxEU*HH1MK{ooSCHrenCKkNr&mdWJAE$ z27Hp-&b{M9FfO5LT7=~FO294wi?s$fbPq~aQ5;@fn%ySt$U4^hwbz5gG8fjxMi{E0 zwz}HvJ2gzH@e&#-<@R)5R`R&n>q9RrPV6e!oeqP=$5Y#d_T0KC7Ag; z)V(h1oteMN)@?RVsNH_M&%S}ty_bzF9;Q?jw4gR`*;W=#jX8VM@(&Nv_857htS!8| zY$Ebo{M{H&uQZ`!K~8N|C-ZWbamH6)^_*O_Tyvf9h~+@Q3QP#Ez_WnrZ(A`$)I{3E zg_qdd-OWt%4=BfilBgyQR3Ga~cduEA%cnsm;w5I2=%3#^tpTQynoo5uE52swORiWp z5Lb_NR33ONM#Bv}HC<0pldEbuV$KG$I!bD1#{{1BrQk~m)xlme-x7guKGu~*?HUTS zm-k6~;GFnXuPyNzdnqHNQKqoj2(tqk&rGoY7=36b40#&4`P&dP*EzcI;QJq<-rzUo zLt$Lnsn`o-w7rrEM@5W;>O%xt=t!yUq8qkYun4qe_n6h24fyy+HNxMvdB>rLM)^~} zz51r>*5IGGu<4?1OIR7GQlShD6P5(ouzzXmsGs{-Lr}0pHN-&O{xckG=2SsbM%6}C z52^7&b13`?;k(PfP}k7*{j+k?{Qd7;m!Po}{pM6aMVBM|f-m)T=&2Ox@T@>oTv~oB zK~)jk9;yfudoj==n8uzJgfVTnREM|{=lgQl@gkczH15jl=1`Daz?oWY$8503D28~ zw!(}YJaA;0mUo(nlv)YZaVIp{P7v`DXSIT$b+vANWQj1R6)^_gDl*}iW?{tml;YWkQwCo90QZC7YuZOXCGho8` zI~vs6U(|W-1lv|MUB;QE0W-8mhmvzgVG)u^-=(Lz5#n7LI@06j%Nj;3AMw`c zvg1|xvuAez5Ki|GSc?T$r{t%JO8Ik1cjgr(!Q1z!8whT5C?o34K&?@L$h zHI6SBB=H`AN&}1tT>6s4mbmaZ|NnBK7)zTwYc_Vx!+n5braYoK4piWj1)^FlZF(I_ z*P4jw2_WG-w3s+Y10_`P@p}WDtH?aqKSt7hKd9#+sv!S^G4lW0U$6$8!kxoR3`%oxW|P)% z%;O$VC3dVXDVI`Bk4jmfX8J_AtbPdxYemGO!q*{HP&jBvbIAYc%k(D<$9*QH=Y zz!yaA7ASTZ4Y5G-fY%9UTR%5Utva>0x2OBO^_##SlI8y0%Ft@q-_>!OdGK%WSu3W>OgA(UBr)BIB ztvaAk9hvR(UaVQzSO@{Ei9&;1u5cA_hHmdXYktG6NqgXmAgdsb8BCy)VUmFVC1wi7 z+Z64R1?r ziTUByt4*WspB?$5pbe90rlS!&+p6{llqilX^2Hbiitjk{Ne_q)`(wmLK&uD_0V+>D zK+NxESKJ*srZ8xZkt1XiCa0ZI0Gf?3K}q|(nfo11fSdKYCgO(puLluzr6Sew@oXIV z`5^P44yZ`lhzXX`QetnxNs4ioXdt2>ia}#==4VswEOrBaYpzn0CYU@L5X=ShCX(G}++3 zTLrg3P|RhcQPxTE>WU_q$aWfug88tn{g`;U?-+80s--T{xX?H@UACKnj?U!p; z*p_UoF?Z8=eDMZvtL2qn@849}!gw`tU>XjcZP1^zOR7X*dCFFVp5JcSkIK{aBfE*B({e zW2=&K&7;P5&s8{e#Mcjf`=?pDBL|}=N~G4j+`usvgS~Fs!I}G6Z3kqEDpu^T_H<)i zfoCVWX!8uGs8hqBb*}<98~3DC_6bzmsJUfBz5(A@iQ%DldSogRm4T|Z+7DH-oNH(O zcV&ug2@U~fKz0?|C@Aly_ik`vwDGfdv(v4tW{7CT=W_zVj6(GzInOL+__x*#cg`(4 z)YfZz8PnkVCp)~A8ztqxOGUCFaah9pbnV@%t<_uqG|MDQvwM|?%|70Xc1W-ml<1(R zKfM9#F>o@Yfm3Q{@i`Pm>Hb7;t1>ax*2Eh}M(w+vRE|tq>ulW{Nh;mH8t+JkbCY(% zmb{wJlf;SXm9iAy%FxGbAz&4p*LUj=DW|*R;(0H$lYXMp<~g#Mzz+n!FxF=r;@z3l zwNHg_YhQiqrgcLgJWSx&d*Jd6nfe<<2ch!TbscCSN<8GwxG7lwJg0d$ALc3$ak#*=y*jfze@l{^j1nYnKgQLAC*vDU{|^n=SlR~(TtX9;6X^%A*+j* zy{uEw_0IO8@32d8-|$q~XkyH_)hcl`=voO*X&M;?*4h-8g{7xxN)fSrzRAh~vNnb* z;qvaCxsv!+{TN+x>1VU->p8B-uXeDiXr(TBIv4ai>KgJ!mvfmpPw!rBr^`WeEV>+g z){v^Ui?gZO_X|ZtWr8*nZ$(AKHlqBMI6otF2u&{Nr@s0~YLt%&J9kzaY&HG?v0(XH zDoJyJPFWhH*PC~@4ZHxPW&!6xgN@d~A}=o}<0KR{bQd6}!kpU=gl#_e84&i|2<-P} zw8H=i=^PTljlwqJEA5p7ZkqT3rCj{G&4)jQB|i{2fuD8WcP!u{1Csk7Q4D{j1M|I^HU7-15%;&`9$U&b!OrA3rE+`209daOyIc1fO4Wyd^{>2 z)Ipya{%9hJC2l)jed6*w^!3)!g|uSAFBEYuQQA!04cxNLO0pH1u3I^Ev6yAhZvaO^ zrVv>d(&jx9b2o^Fw$9@hE{rzdYG{Cm00Xv}%Gk)tt8P00CIG42dhFwA@xuVTBM00E z#-$yOp7Pjq#`V9ApccT5S2z5sWa){Ti%o(N!@s361IWQatuhwze+(bP{9*2>-~9FM zs;X?;L~SNA4p(6M>j`~eciMbc*{wg0yN^aM!)5+phvU-=M{2K`6(S*w@huxcRh-NF zmRxM88rS&Yyj3!sb@0DstA)(A%<)7EGko;qD~OUX-xQ*x(uKO>Bs_`nYz56VR%$;v z_ISo^YOD>_G|&~h*Z;tGn$3zh2n2v{IdWnUj0H>_DiIdGXwVQ#v!U@P?lWX2S$erw zpY`Q4JAi_MRi)f-eEQKT)~E7r2e#sXH_qCf4AO@^^)LluxR3C-x0LTkEJ;}0pdTWJ zY&ef;w7B|r8FaC~V((E)%Ki!O_=^c7;Zz5oOu+)KZ*Q zqx&Kk;x`53(3rJLgS(X9N(LsAX6vv93^~22mot&P>w;xj3Nv(}vRaS_PMqhg+;I}G z?v}mNDj+LE3u9Qi;jN{!fen;P9&Sp?ZiOhY>G3ro_95FZm&J0>{6T2uV;s&sX?kDs zWFI%i?Qh?4bFleg13r5VE^oHDIvsv?4HnKUcDfNapAK}ur`VuW{A%=2r2r>1*AA@9 zVy|ND8fJD^Ec1)7ZkUHr06wx{+X%@CQSnK0)VmEk5oq_bTPh6_$9v5<{cpJM=kK6t z7maz+YVGdppuFKQa-co1=4j|5^7teGScIEX=cLI-Lk zp-2U=!(=GST3(Va$(cw#*0IZI_m#F3wy16aZatQC>P=FD_SxS}sZm#cb{j1@)!;V2 z&Rg>CoX*jYyvP?`57KAhj#cmb3V)Twuk7%vsNwMMiTQ{W$PTC| z1wyb?8}zh@qM<^!@sig`QO%0|ynvqa6hM=P>psGzr>KCn8>tG5XyC-p%hvxpKSUA? z3p|IeZ7&&E5a9Zpjss=LrGOY=>t#$6rxse^Fi#cjQb4cjo=bMVI2XE(!5;;0r;ai)404G9a zZqB}TmMR1#Y3E7mRwp?LKbL6>K5wdzD`4XD+zVB511LG(`=Vq3sF5&qGh98*UCOl4 zzgJm(qg1k;+RX}A!p?ErA;RWe{2x+Kw8KqUQz4cLaKO^JXaRtJKp$|IFXQIRr+5($ z*Z>xqiRUb2ikd;L?>G|XWNVQk1z|l)0H30wwXwGsdTxR14grj%nV}(z_j;hl5%#Om zx`wUt9FohDS1Ty3l7BV+^!=b0;XJVY=)bizRyeYavXOoRc@jvIVvqlXyncwDz}F+Y zh@+NnQ*_27k;#8j=uvV;rW64X)KH?poKUf>advG(vJ1Lg6e{$d_7KoXr1VISL;U$Z_N4M zKRd-uyYO96Jhr3efh;onAu4d^zARIKu*G5QJ}xj4rhW~T5F*a3gLb`&L{JDq;F%hYU1(YUL;-C#T%nNY(naA`W7j) z6JyfuJNCEIMHHyHWergqO6K$Lg*N=sQ!*dGo62khp{%ae+!B-)c1LYlK*?F{! zI9V`Ug9t;PBao%|rqUW3ec5QB(1N#g%Sj#SB|k4CE=<5KSzQ1&u9XSmp!Z-X{*ei$ zzrnSX%_FDc;~3K-?nLu>g)32nfvpDvNjlLK2}9`|z`RG#Rvk;r8oovB)gBe}EVfw( zl+dq<^^H2Ye|EDb8$tq-i+O{(CgqTv-L1D zaCbqs^MV#z2tRIN8Db1xcZodzghdk7c;R#Z+xagMTmS5fiKIdwE9!T@Kr4UV>WU~d zQ472B%z#%*r~vqcI}>UN2GNaSB(&$2#bOrE^%k;+6|UG%0{C4Dz#JZAB0*y#dq^H4 zJg^D3Vg-?Q4AUoO5BO*1HE6PN>e54lhwqOcW{?2+ZI2=%wloE8^!_RBAfxIKVAFGc2rl<2aGsh@mI(?q z#4u*i0&?sO!ENi~&EUmVXY#Nl%yyotMnXM)n`&s$x4#?y+n$qWcs>_itFd_zl8pq*UbaNv{ZWP{Ixlr?le-bk1;rhoDt)s^g!M#;5|S~sV^@MGvz;g42dMb zqS8GiRq2NCXD>{S9wz&E4^u(*gHc4VU3`t{N}IRvk-20MNXqY;f(UVRRK3qa&L9>9 zDhV{7HVul|d-w6uSm1;>(`hi_gOUqHRI`QtwC>T8^CyX0U|e8%|8j;WW$h)=if(S$ z7O+td_RssJ`^0C5@4F>k>i^KS;lSHyz7#c&m?$)Zh_<~ez4^UDkHTRR@k4Q7Bhe-4 zPLL7i)7qi$fiyuyAfKNRcsSx{1-f{i*sDmR`#38o3d?3+@sxbeWHiz?`@q#fW_V}! z?n>Uc2t#WLr-z8#aK^dw9i*e|9UJiDpm1wl9IARQqv73dqf6GKE9I1w-;*07*vQAZ_d}t-_F6W;mRp@Yk;wH!z zsJfxU9I`d!$y9bSQF;%W{i$--<%GY&VBQe-+dx88o|>)L-t?_j^+Nw?;>=}-Mps4N zB+!HAb#;tXU|4nOg3$Q-Ul073&t1suiR$U9`2v0EpxyYC zk7`utBYqSD^P2~0he8g0RF^`TvRo)m9c)J60|9|9_QSzbCdBej4dTIYzfC21$%JIM z^DVi*GFs1{NR{owa5$ii6||)>lF*Wk39W_Pel`47uBt{+x)A=a z!z+RO@lxUAgVf!&m$IZg%~OL0&)uXM`?-wdeLv221Aub%ZS_}n@@-vD{_zAj8ydkv zFfOyy*a~6Tu8#h^vV18SLO}FhUS>5L8gtNuq@<`QOaSWQGb-s|Dz5g75w~VSein<~ zJJp0K(@GKgLc|+sH)K>DGL7&ifZXoOvFt7r@y>oR1!yeE@MuWE*Vz631q1 zvI-f#`XGxZ!KNRbCz#vw<|+wpHtVb8TI=V0^6UQ8X zXj_!cWsq_Z@1rS#>*{p8z7-BJQgOLvoyf2S=BO`Ulz`)@T_}Jfr&UB)skPU=Z7D?y z0ecfDf#&O4^-!fl^X*Fid~?xB;Q~eyFFfDSJC%4Wkf_AjS_AGadlYq$`xDEvl$Xo~ zy>OCbqld*_eJ_PW`G~5mrjb214s~78ElS&-_zh=fAQY)3DiF=JC!}Apn8MGXU9gxp zKH`=y_nr;&1nJ-JUUR<x{ck}YezRi$t3E0n^+lahhvT&Kz9BYGU zyv?ZL8;ZxJ`b=$r(M`Ym4}7vbNfoanhl<0D^Q}0&0Zg|ai@T188(~Y zSM3{j4L5=y&nU;j$qP1JKL}{5A&a5mX@hYLE&%>U&dii&Kb*w_TW_1A*sTw4Fy7zo z6(%g}M7@AS3#)Z|v^S*G@5m3Wc_2ylTL2~}8}uGf21P&NDBW`|(Ehh7(V~!8mtybc=1ROF+=le@wOAbK*K@ulfU3?+sl}otaM#vlRxmbg9 z*NNqHWn;dH3tznxbg?NUz16uaTo>A-3)-C|*d>xhfH?PoTn81^^zxT#0X$kzBap&= z#N_5Kd|G+p+NU15YiqGSCVJsQQecX8kKKY`p-An5nh5QY8W*Twlcgp?mikRV)%&Bz zV!R2;8{WNJQ4p>#@8kd$gS2*IxBaz$C@ugDRz)Tcv-0}Vsg7|#`nd5;Ii?GO@?U0B*>EpL(J6BWP0PK1FU^aas+Cfog9Hr4n3L$^kFdshQS@D{R2n@ zgh~O8W!_}xBY3aC20;#o{vO8IvPd0t8XnId<2*)I{nzqc7oTaeQIGA-ZLVSE%FgjY z(4-}j)cfTaq%DQE+HwmseTw7xcU1K24AYymxn&IqevtFRv|vjS+<#?nJ)g7JvK z>wbj92y@v_024ssfQo8bZENRMYmQiafIC&~qpU5u01>ic*Up5BgSj3ZI;W0$9bic_ z+LhyxRki7m)I!gf&ydu@D%obpH&q7%MHT8XyNIn!S@@Ki$V`pJ*)bXB0qPSodHCr( zwIoAp8|H2(aWnNx#Jx_Q!GA>fj8FXO%_|W$-;IPYPH&;2C8eMg9gQX$v}jV4j_d3e z5HVV_)L%V+veglms%g%uklvd3MUZ3y;bN`HxNLxFa5T;Le)ncS(~e9Z_~y|1sUhZs zL>|jSl#D7VvPCFKfl%GKRC736CX#!S?Oru>?_}m~_!px3CPZ{NhNIbfU!>B=^LQ8> zH{ZHBck&iYRN)0DWS~d>i|j<TNffGnhXZQYHkGU>2-mhh+JM&WQAW4{_U556Om2@hoZ>k1-b7BeapcC zr9x;W6Zs*UKQF6a0O|p6^N=o%Ix=I$kwY!a2#-e3HOqa&cFt=8mR{|7lB+p&Xh8w;CQA~GHwddAsj|u z*Hv*K%~Ws!6yhiJ?JM~3v3x&3)YR;^SFqLyH&5!nFkhI1vYjYfsChaK!N6w0l}No!BIcN5L%+_}{?9JHKd&+!{T zQZpc5NLjqWi=EzrNp)e8xx%b;^dAeLZUwT39KbU}DdB(xqnb7PUWnYF#-{OM|GZpk zr_tFUR1DJRxQ2EfZw$z|-!ejZxg?!UxU~&;dkWSk+T|hGNHGjg6ekW}!SI2b_`AHX1`)hGrx_EjnurFT@#27^qp8y2JX?A5=5D=sN z)e<@dj%~o?g$pMb;Fuv!P_$$(pWTPr5)YYCdnj4gOFq=;{FO8%gL~-_Qm^e zP0UyUjT=U~>c|zbT0UafG>VZtL}Sk`pdD%R{CQ)rw?LPe>rT>!kH`=wqd&gaCa>Fi zD`^o@Sm6IaOiPkt817v?J?U@wI53%_i`pQPHh>T8dT|n;Aoz8mumJ_sFvVsKCMSX9 zw?i;AI(2P^YBa!z{Qba!$?p*xDgJJFEA9xf`r1q~^}}Tekv#1|)c@!z`9i%p+aVN( z)mo96-(pN5?Po%I$nY(Q5Ryu8Mwz<}lTDmdy+PSSR1}_Qew9q9JGKI8g+;aAtia@qsm)vH`W8c-NCWsi zbf88WTv^n_hHPV)&=j4TS9V*p_Ugo>R%*aleCX>v$JXQd%AZ;0#O`MSeFdv+k#sOzM{Uj9{fb{nK$);Q# z94qCSJS-3ydugwQ0fvi%Za62}#F@130G`q26h_XgwmGO7UQ;KH-IEJ+0PywDz1#Fw zdKV#EHb7$onHTUDE2+TVCDwO4IIw>z{(>}tSZ7d0Z;0#1X^Ce~`s}ib6kC1#f_Nm^ z=nzrpG^Ym9qx%3UZdjv$91;Pns7*JWaLk>F%SOI?7H~cO<*35BkQ%l-JxxM;3=bWq z8;BUx$Yr3(hS62WFQQ*UZ1ANfFsx)|C{Jd9+mPF zgXXrq0$`9jD&dR%)c}3jXC6>fq1TE!BvH3E0CIyZ|Ns1DPz=M9JHRM1rzLfybHj{p-OYS~ie8&i6$_U(@fD!y!Ono} z1Qe&w^*`QMcCIM}2Z}<1vmg;6zZC;9UcA6at%<5mU`0RTl>__iMqr_hpvN1S$ZXn> zpZ8-k@VFBQEaRo5Y{{Xxb_$g6cv=4nmNKp9n-QdOo1UyO-?u=16#Vn1{b45z!FCXM z)f3?TCK7CvfJ&nUNI>$UY(q^c9)wOKLp2U|WI%LA{QccMFeP7F+($|HSa^YoNh@tt zxu^Je<~go^4V9$$Q5tHdc%jeoKo(#L{GVjbG|86ho^ob*olVI09$hCmc4*}r_?QN` z_|Y{j_nQuhjx&a*E!i98OOwCH;*}Z7i=eZ zS+uC_fc2n5gcPs=0=95N>r;(+;^=jC^VI0vGZD8W3cdEk4xG3i>pl*t^UFSyovt>* zdc(5nEtiQCOYmFkWqO^Yu>Nir;L<{&2HZyKoJuB{>8Eok8Ne^J?(%lX;QKK-N3?}7 zS|MOdZvBOz>fB?JLa@KH08TdwV*;N1k%OPk#Tn?p(o3_iSOM}usHdI1E+!BZZe^?? z0gh{<3UM~4&U*yABaCc2q9k%_pgKH{$O2H9Jux490Q-o~bf~8i`wJsscK#SMT~Heb zA*NOv2{W5SEfW$vRxvQ94nnF#QCJCzBhWZta8z`El7bIx5Jgh?M;#dEUz%f&104Aj zg8W?D)r$U8;N)6}a9CvD zd3FXa8(juF>NSwcG9Dwp{%-uw_b8Z;psWeq$H5Spqrr0z!bfe1d=;eH%{9+l2faKF zf)0pk@OiWERKM9>_ChYO@6<^JOACFKXxiV?J;Oww5!mPM=yjoegz8?%g!w}ekJ2qa zdP33&NV4n^MdzH&4l)0vnH%Uk)vh}@Vr*(f%R0=3$dkeOu*Md~xjQ^*Z%ccm1|hwJ z49ox@6PhBMdqEITIy*jJ7vF=oUOU@iprY+Akj0bPzW*>>-3eg=PDMZyUF`&8#B$yt z0Zagm=&kHCkHTX!>o8Njb2*fglN2`}oRW6sIcOIsF8aOk14R7^D_`Ri9{I{jg7!|~ z^#|k-o1)W-zPk#ML=c;Th|kxNLcu^U=7K{F5|t=d0~;XMJ_}_HL0%$J0>81=yQQ~j zKtV2t_sQ0nNPpZ7YA^gkeG7o9$*k7ELo7rx0lwhEgW$x%Pcbi%>(jEi?7IqcX}R-Y zL;10O-d8kn;YFpfPBd{1fCa~4J`_RsqO>CvD4_cPD((5d@COh=&Wtp~X^!+w0uo3E z?Ahr9=`1ix+DD4ggFUo}K@%C@kU0+H8(2j=7hW^IMZ?jJjUKMPp>sgnBXgsjHA4cm z2RfZdZRR1VUBMEnd-0CaGbyWVU;dN4QyW(B!QPSo?R6+kE#;jEEcK)Va zH|W*`Rfyc9z}XqA!-1YZ#eVEkKNkp#qoHOpKAY9|01wV~3r^SuM|Q_bATF4P(Mon8 zt)l{s8H@a+NE%12hyfD}%p}s{_X;$HyszbpZQtIXycUI-;nG47dp8F1a|jI>6Rh`Rfw%VRmb05gF7 zi*`m3k@T(BN+H85*0)Cm17>hKVmc9<6s29@hR_mn|KM|^HFJ0roALtiDAG1E7*A2O z11Z*raz3QrHcfqx#FOOr>!WXzx2MO9a|(qwT5ke^A#vVegvA7ba{;#!T;Mv!d?$Prfv%okS(rk@N!_^ALgT!C;gw2Ou9 zA7%U_B{cYe5{>JfB(dg`E4x#8qCYSJV2!oxy2#OSWn)HyY%b2a;5baP_&7*kHeFz= z7m>l6Q7dymeo)pH^9cdFz#fo7LUKt&Z2mV_kVw>i!mhtl5;aVNO{wURM0y($;7@;u zs_6i~u_!a-r-=e1z6kLDFHWXKXMZy-Y+da0q^322)}tsU~vsVQMeI7 zP)95X(rpE*p>JNHu|V)hTvMbArdWX?d-b$#*|9Rr%E(!b*jt2gv<|x$vo%$%CC*|w z39?2?JPO7I^+oqQy?ZC?J*57jpklGKC>lwK7>ePNj6?CtxICP~cL~QPQGd1HYzW(7 z7xpmLAHVix)OeC^Kx25xB1)P)@?~_0V|na}Bv2QWW!$iz$J=61nzwm76cJR6AjmoW zV1jMvG5GA4Ot1iux1Tv4!XhNcbEYdhXZwtL;xmSpc6xzmpbXF<&d_i&w1bebN#PhK z9a__ze~{>jRgZ>tO($D-4N)_lFh6{-t_=v;@ueC75zx{+ow>~&a}b~AZ7E06r9fmF zEdXHk{`Ix@6%0 z@%axmzk|oCZyYov!QPg!!Toi5AT&I#2KZ|%=0^X3+t_{-0X~w>bC?OURPS%k2F4uuZtX8_;?U=zlZ)QnUmd>mAqk;*%$ai6g`$zp{^~O@ z;%H7{KNe_sP$>O-Frgo_8xSkG!E6$O2Np_43gmlJlfn13i<8dND(pOlE5O1y4e`X# zN*-YH7;tLQ$izGfa)#*z!}S5QA6O$uO&K~6Q(Ju_9IdqPnEU)9o_cI?u)w?mlL-KN zIA7q@8Znh|1RapTT|;33!ZP}$3xU4+&8;P`WoXW%S`A^)`NBD`42jiccxZAXHiXgLR1p?m>I`2Tw;o+v|wTiMk<8An+JBk zwIjAIuUI}skghB6=NRkn22w@Qd}!wipaAaSIkf<1e+SJS}F%C6n1kc=Wv%UDXhBUFs#Fbwd7sr7=dDoC>vNTq4k4IRzM$S8HOy}j#dYv zH{&#ilhqIFVKsuKg3MnKY9K3{q!h(d4ABH%L3&~rH%Ca-eK?DPGasHZb!iLEL;@Z@ z04Uoxp(6%NgrQQQ#mbkgP!L=|9tbj%==A!Xd95#H_hN!)ERH7qm!Zx_W?}#_7MTzO zfTK>%^@Fc3R;WB85{HbFxEc!Sz}29aLTVA1*H~@Zo?&{)`Y^5r>QO}b%W$Uqqb^Or zQV;)tB!PEC7{Xd7*L;Hw2Q0n@7bL(!f-^gBPIAQs!50Q=I$aP*`cDFewrl`!1-N*t zdGQ*MMtOM@WhujPIS$4g?R!*{)$D6atOm(HE876?G!QF_azq)K1a6m-z?NBb-qHNN@UO$ebt8=`?)!E(spejN+q(nh`vhH z<_%!#j$V#{S$gcHj!89q9EbgaUo@ z=oc3u=d^xy?=O#;)Y%|#EDK!=QW7wl-WEC5)m_|yI14ZVcv)&uj(H*P)33c<)5u+e=e>iR+2~hXeR&jU zh|P>C7DM>lHN@>>?}R2ByI!WZ58YO5Gi9|PWt|e;F5#c7-6lx*@9%ED5V%F4WgW98 zg}6O{ISbt&-GzD(@1(T3Q^8Ee;yzM{!L_?GPsbhxAE*|C6fC`j;xg!wFE@JaNw^g+ zl;Q|r1hBW6z>|>PmYAaEW9Cc#HVIW9JsFItCoJ)ejm%w7N~pTx%oF^wBU*81K%~W3xZ1c zgdOyJa2-w$p^kuP@R!ZVq&ol}-5oai+3R(=`SD2kASNV}2i@b^Qb7*%$XDY7gp(=e zvJY6yU7VBA;50F12tpueg9&N+a8*!``Gq3czy>l|Izfim0(H?tFdATCRmgsXHw+o2 zW`3cVND*f%O0pd^GpYGAO{xeP7uA;YhreJ}BXIs7DhNz{qT*7%e1PSvU(N8P(4v7H zfY3_)QN1hrn`nj{$bt0B(gY$4uu!V zdrY{QMpvM!(a)g=6yh8>V8qTSV@t;hO(<0^tOsfeNhT065Q&r{UrUFxKRo7w$xs$e z7(nqg++ElY;3IfODNY;GU95|NUmZ`RawCK(1S@Mq6Ig&w+ss$G=>UQL!i0PZ44WE7 zP5thVB+$Si8pcsQj2cMZX2i$9C%i2`e>G|X;IKtF>;YQ$Js<_RHWNTfiAN>s91)oi z9@P|816BE%hS?(dZdt=ZJU9|PGW5z=XXOo1{ z>(IW@5Mk?vbHAWtEw!T9a9_7?uv*=4FbWv45BzNXzG-Kmz~V%3?`&y>P_+->hIg zs|jM$%7|c!F2);)B@y7uC}0x=Ff^mN=TXmEGi>HGTUilQwF23O`=zKP*g@Jv7i@P)SUbe zpeSPb{!jl1g@gl2;I+>RbK~r*~seQ`-c> zgWiJ?g!jQ|E4JOh1}ltA*2xNJ{l}y}#-W&ih89f%N*rkL{#N}902(wzv~6eWTh^0c z+VKoi%o5IB63pG2cQqcEt;cU`*pEDczWPsA#m*y&IZRm^r-I^&XMPF(A4lBL!fFU5 z5v~R(a$TCkdJdAt3h*3rB~+1x^UL3V{J_|Qr79>ivD%6Y+@970`p#K|pjZqUC{$2F zB&2*ZQEk^_O2r}|B;>R+M!K`^_XX10pk*j+-uMqds$PckkU+t^(Yk!!EM_QBs%6-- zfJqNYAZ2cDamrk=2~B|QRPlV*kGyUD)Ca-QZ=k>OP&DPZt7!dhMDoOLLoG~neh%;( zdnB^N+~c7V1|U>J_Xgn;r|X3s6RdcOOTM{e5y4;UNkF0J-(*RRZ&Y&Li`R4A82Ye} zxZ5jQ{23i+pMeHMVxC!Wugu8|alj!KoVx$^xeHf9k$6$~i3`&11Y4yDEqalxDA>;7 zme~^Fm)fFGfg!K!`c~q6b@SchhU-`e^?_S}7paK|vazETav@?a|BO zJb}vuM3Fw;0Q>;F0Y_CDVzd^v(ng@n~3IWkadv{HGPTP|a zy^~c3R0NPU&J3QLvETHY;d&S8gsEf-G(frQUO#_=!;Bski)<5wabVm+jVJGBCrd0t z{00(UscU8ATp=cqHjNporC|r1pV*)wI24@;xaAQK=I%VKq_7c^7`U(YNbi8K`+f8w zjEQkrltLmeKi)QUUZ5ZSPYna5_yVdhPrM!i9!O=zp<=k$@So}@zk_UNyLt(~VRzF} z^g$Z~+Q5z*pcfo=Bp%eOne@QeIV*oBAQ%15{34Xmz%Dk>s*@xzL5Ot?u4x@YG>0y8lh~ z5y~g;hDO8sZJ8Tdh(l(+w1uO3wc>er6w)aZY_TqXqehJ^mLJS)f4Ir3P94ji_`_e{ zv>o>t6ITaC#0_do7xcbeak#XsM6gFgVKfwif`CLo%FwT^;n9HcknKLVJL>xr;vw_f`DtA zWSgDs&^InYUB{^D>UkM6=?FRNdA1}j7LP({*CQG(YuFZs+f(poqGfe0lEyy{rUDYq z00qgY^KcO_S5QhpU;+(ZFyw4ZegL-^Lfk%sr$f82DUPbP7>&6Ca>g+K?DY|SbABO@ z$8=Idw|*M8H%9&0Z{V=W*(z@uosw53T0#dqgrEl$@IAJ~P{P4r!QBO;Q4%b76j&i- z^583mWfQ1Cn#4HQK?Fz8Zqn=hk>2{S`$JR@{>_?0?GZ{7{Q=yYLPvyOFfhT76sS~V zL>rIr2T9YRUi~*jDP1%rqMsrIBehkiI-l$V_>zwHf8!#^2#Y~TPv#&Al%>ulB1QEP zY`pE-HVfgH0oZG2P9Y@l1i;m6o~O1x(F~*hEWO}x?H?dg=kM@-9fGHGiaG|5(Ez1k zBLm9CV?pu^}9mp?lrCT87WYY-{hVnYbAU!?%jWwOl-j>oDmrjdY}QY@p%Y>l@g~c4s?G9 z9YehP1&{K52+n|>$s4gN7*24E^B*n69>-p69v%7yx%<}HzZESQ+r?HvLenqRer*so zENtAXap8pfBY`cONv?fBWjL()Z3~i^Ny?>IeAxx_Ng}w0cBK%+l4N+*w-;t<3yu-( zR!Fj~ymHv5qutcgc`EI&K^Gx6R4oDtAtZFgoM+UFRlz-GBme8MLABz4vG<-)O=fG@ zFf)!aiokJDkv=o1pa>{cX^~+R6)B2}f)JHnBQ?}SMMb5lH0dA$(uDw_2V?;0(g_ek zuSuv$Aoblr&l#O_&YU0L`rftPwfyDsSqXWb{p@|$>%Okw*Xy9%0rDUs257)?gf|pc z!JFVHSn*GJg8=|w&NxK6VTLt;&lE7jTmhsnK=MiM7C<}*z5_g>90JZQJjS^~b{0om z?Kdrz8Bi|cAcZk4y?_x?w&hyC#IfznV(cJiYR_1g)7u0{C6J4PM%z}&_&rmZgP#Ho z^}aNdMThu3r_rCpkj^;wNXff+i{dhapv;23)pkJy;Hf29TlwAW}{l9_(iDFuv<^py2jp z`RLQAWELn!ntfvZ0d+Qzpl5l;0%1)~=ECV7fxUb)98~d*r2tZA{IN*!TciJxyl~R7 zKXC$_DCYd%(g6J{1p91-IFZ=Pj=y6c`_xH${jY`^r(%BaZ?(<-6@~rNVu4)q{Qsba z;v}Mff(1B4Q4t=0XQ??dR$Bwq{+zlA&{_q7)vK6{$utg550HWa6(fMCEl#tSFWUTy;V>s%{##?G&Kp^1?Cl2}# zn#TV&5zm<%X#>b>c|dyKI=Ki8jwl$P>mXeL$P^IKEOwFwD_J0kCIs zJ?{grt-%?SHOT~3QU+%~-}pXOwM9d7t5cO_UP-xXVxErrfunWOuGc}^t>X*OUQl2& zL9{=2-`!>W{i7NCvZX%2590$CZ;Lde;xp7mFY^NdShRA`!vR$rf1{blA}-zloJ797 z4a`3>qs?4S;Eg%`wKHoo@!PjXb2!>{)|#n4!ASsC@K#C*K!A=ergJ1Cn1F<-ZxPNZ z{*bwlD|J~prx_b4ODg`pb+MI1QnA;7g%bND(w6_X;RFa5@j%40F< zi$K^HP)Y#v!^kQCITYBoAYghk33``e<{vL@2b4#cpiSo046qbC?K=T&B!_wXg}-fr z>tpf3c~BMNR4ozfoGC}dk(n;eegG)|7;NMKnlK;!&WVBqt5C^{a2?P^{Hb@jMZpXF z!lz;=2;tCH%|C%Q5~qGHy2JWC9pp1$GC;uKB&S9RYUSW`fc`3HDha864D*}TrNeJH zJjokd(}SSJ${CpE;A6SHe1U-kI|zXCA8`tqfM5Vn23s86;D2ZiTI;4)djChP$*Do* z{cBkH>-6#8E6tpz`y=I_lSH49>L7ah9L@bFMNLjx_k}9)XT<5JFZ}%PDxv_h3M|z> zCy)MBng0xO`pw5xGiiorKVJEpF@G#CD`51_MbBM zUuodP`WcZNY9SC&ZSc3W0mjRePcnqTcaDNJ0|1`0z-5CD(t>v;D1(AXhciMn8No55 zpLF9mg(X0X&k@N1-C3~J0YvU9U<}=gT?Rk1VSF0u0@at;Ej-~Bu$ciYrC8eR(Ww>t zzhj>RNemcPSO#*G@S_VHO?E)^_UUOD;P6&}psK)&qX*os2OxIT(L|u!^jcLK&4Fn@9?|^;6m~!qPzfS25YM$$f8>x+Z%w*^!I-Xu z{wi7D5dBy)0!WC>0TjUC1xKOQk5H%!63T;XavU0`@CCp(;qU%FS2egiO{dYQZI})a z-VXLDoN_(LUN}9q(MP92OBV<7YoLz>7QP(RrBOg(-FFf2I|Eb@cmtqqSLwN!0fxpA zS7xXctAFdw!CiY_LWnRv$$;+Kl)O+VxO!VL#=FDZ@3XbJ*R3Ul#aLNq}S)6cITR zm_UP=Q!xO=5##JDNAmQ_0EY#5y;H!*aJr0AdyP5dJO*MMOe#?Hy9AEKr{PHu-1k>( z!Kpbr@>1eseu?}uD}8{G7F7PG3KTeXdqm)kUy=dm8%LCK^6%s0e+?~O+ynBuzZ!)9 zTCoCYUB-`}QoH|EQ2JLK_8Hj3$@M_e`FA6apF_RRz^Tt8(f_L^2Ig}<1G7F8=X_3S z|3fbZFq=54cXe`j`%HdH=O{dX4uvEAIj%iT4Uj{D&S;YF!VwTvb98F~^%>v~10Dm+ zKmihnS3t&a{~;*or2&3u(6WC5>WY9m%H!FuM9$2Nz_ToHZcTvRBq&yaV~}4>F$EP= z;7|b#=@20A5R^52<9SLIP!@n;FtA%eH;q?J?Mm=O4u>MM()dHjC;psE9O+bmE8(=U zL8@8qZVOH#x5W z{*4(q`}^;|Ct3Y>M->WgK;v)72SvaQ_`Lk@<7BGf_g4>o!IAaX0X6XZQ|G@ez<*~U z|F#3Z9fAMi9x0UDO`nGMjxV{}&F0OCZhKuW)spR^9 z(@EX?wfFV}Ohkkd$22_cO2!^HFI7|T8j=@aX5b z!HvbgxMQP-fQa@FOL*ALQW_e6O+ImGTwyVp^?(DdPMqa?g|@@N09W=Lj%6?lz2tqN zR6-4brQ!SYHtlbPzwE%A{b@350`3ql-g7ON>CAkFg(Uc8uN5?y-L5KZ_pMQdCn7YQ zp5a|y>|I=x05>qW>ubON1fyp2?YFPuAggc7T?sX|A;*mdf3j4ky7f5UHGi_UDpx^QMI`u8p9WdO7 zxvQkkE+s?)G{I|Ab{_+^1LRXo;i1Zl=7lTkIX0RB%E`--5?kQz=cZpT-G^rDWL}F> zpT&vr{=6Gi9u4pDc@}x{u`B@lp$!Yf=9x2_D)%t#gi5@+I;s1rY)gHNY$h{Tf5tw93EPIBwIW7W?dm z(Q+T>smHuhrjmO>CvkDJZU$ao?1f#{P9B1tL+Q%I>f$dEdP>L1qZKq|j z2R1qah69G=k4K{JOxQ*dlo2wowPV`@`Hn~shgN;g2%z1Jc4z~5{EpKnx`>(qr2c1y z;%L^+c;;2aCb%^&xvyUkBTE+Pa2q$lFJ7u^#k!+Lc~#A20!`{~GyO*|skjCu z=$sTC3sG5QvjgT*+Rlc1zAD=^_S;Xc>Y|wd8tDjW(D|za1G#$P{QI35g|$DP`*G_9 zEf1uBK@Y>lbr0e`I~h@uS9qsQ7r7E%2UEGblEDwZ0hx?XvQFHdzYQ8+crl1kN(kZ~ zQ9T}{9XrgzZ^wrWm(8K^XKP}!A@AO&Tzm~$fIC3x{aDDosR!_#;E9mtU+;qr#dvmH zEo_peF$HSE&D#STooL>#_C;V$exwb2kMkj=v`;GE(BeOwsU2Gj|HUH~3H~I|Lu|ff zwBz2RJU?0BJyjBTOvRfVWk=b8hS}^TsBA=j&hAxrlHb`N! zjPok`=Eds7z7zGcdDklz< z24)q$C1Dn*lgs*T_CQNC)1MmZ*90*r;>6-WXn`x4a9e7-Ap4hA^-Vf?g#Ols($c=Og+Bujg<@Op6XX_VspP$$nlYAB*F+ z$dAI3Do5}UPe{4+K{$r}ZpfpZV>pL;cN#7}no^RESacs=y>!*FW+8IZuylYvpV<%x ztC)K~%&2BX?5VIZhq0Z0d*gU=hDs?B5-~(g%Q;dA#N=4I+U(k}Z5hg?X}o^cS;L?C ztV?2eQ4(Jsj~~S!=Jy`j97vHBT<+~uTL>oc6f;&(O5Sh=>m`!CqRz-LQ%G)0PFmpi zVcm2yV9`~5ryiV&N4#evvf}+HVc#PpAM&c5WLqI7*AuIzb0NGFIT*QmO_5O|3?(}FLX~hr{5$>wa$yV2D$5ZpgD(o%n8l=M2*|f}|@Wh<@n1GL3lgVyEkw>uB z*;+4ca0%?2x7dy@Bn?)3Ry^j#jh3QVIPeexh@q;`m~?V*MrgSfA<>^e(_Y(e%|6U1 z^(Fn_PDlp5Of90P%vo}w7yY;C6VmR$jqqE%^AVBLTf7z`v2M_T43ha70NQH@GHk0Z zQ51LjNwsgsEyXr{AB?_ZG*i^M!*(Pyp8B5cZ$- zRExG>dos9+2*1wWOVoTiRsHH#5x43{-fLWY%G+6K>d>X(}80(Z5H~ z{ebX~0SZ|Di(}R8BgtCJu{(`oXAR zvaxtqk(lkspMyxGAoh-8%yy)j^gCrpi~_!KlHMjaCQ|J?aZenJsF+ccHeQW}o!z(m zGN%22>GDVC55_cSViC3z=VrSK6oW>i-v%nI1T5{U+O80->BSstvun1)x+TWWjs3qOq1RtWt8IqCF*swxb&!l1*~M)iYs zlQ^o>37%(hl00w6#+1U7)NipeI(1IuK?}X>p1AhZC?1x5g>uDw7~;cLMXU@r^1E$V zu9V$~h;hMwysqwOS3mX(hKDeX!A@2~S>7FvCX37Gh8Ky6FHFx5MczLW>_oHAOcy)V9UGv88r?) z*h11Qso7QVowY!}*ReG6-_4e#g z=;-RWbiSzSA-^LG-J(t%E%t3FYB#}Uv?7=x_bq?pw*D1@mX&w!>s99w|GCUP zq$Yli8&k8nh*VIz3t~{k2h^1rSZMj<7-xp)kF&KvzPgsRULKzxT^mjb}16Fi}gb*y`$Q7;|jC&b&~3ink4(Rk=N(#HdxFs%xR z8TJZRidK!9ewz16%ezPQNUCChkUgKUfnq1CC{8231a9G^4D}%HLqo4}UabrtdgK&Z3vL1wVA| ztTYfVyWV7tFW)paONuW+3#v%>5W0B$43kRjFC3=lcP8_=Xy(T&Qd)Zm7^iO1TfxWS zG?&xM!F5YRAlgzx?tU*?G`;PYBCW#5+x9ylK4t|fV)h^zv8i>z4@|B^uLRe+U)Nkg zsVcH|{E=md)9~mCHdUpTzfI=fTRKpA0&< zZ{QhPTq|_C|9CnEZ+xh8iM3vPKc2OId2AR>8Yr-6XGH98ukea3nm=+Z);ns=e6T3d zp8q%J(&-k_Q!`Z8(30Q`2y-kA18K?PPr}iIq}(@q^zPrtw^n?N{!nI0${lu{$T)JJ zJV|qkb*Lb6hX(9rpxa7A9y@JrQ$_j*IF3db-M^Gt5=`^-Kf3m`L_LqX?sLDL-~^~G zG|~Juw4TCL*|al4ilV82Ai~kRVMCkZywQaAUWH3=^Is%XYLs5YyH?P{hxVUp3!g z4_DHEE^ndNQW^CUG^s4N@`YF$uB<)#mH(A;p=+qjjdS7jD6Yjy!u=c(b#-IVYsQh--p%xN$5KzMYL z+x#m=7Y$y-GCo-f*V#P6i>cD2!ckbB8C%1WE~%@mi1hV=rz?V|;^Nsz?gy@W2JJPTtmrwn zb7CQ_3G9y<@51saY-V6sYMpbnjuyxf8gRH4ym z5nlVe!25yyv>6k5T(6Un%?4SL8=-mK{bYhy`pAbm^Udn~u=b6X=!K3YBV>@^Q8im) z1U9qZpOr>Z+9|1yh{Rvfntj1q(ASsvh0c#{ZI~1+nf*veI8mbCL=$lG$Y5IF)T2X* zGvR#;Q$l3p?erKG$o4baO0;8Nj9a$j(+Mu^NoR@9qVpJP_FVr?-j>Luvun3=_XjGJ z9KvoK`;n|@NS1nBJ`=nAyxky8!H*ab1-sIHb}En$xp=T3KT6+L8YwfbdURUB?^TejGsF1)}j5<|{c?yJ9wl5F0I5*&FaDe8OykdPQVD8Tg2$3w1F zY+_4peqTPY+7i7ZXuZPlcJAZMM>&AqjI?nH@jPc;s+Av}>*RYbi+Q`yvu{J^kKP^D zMSTOSR&HeD(v=&xE0(plan&Atl;?XWUORRwxc?v**ToNJa(){t+e*wQ+;|Ny|72B( zsh5X|Q=vNyyF)5-L=O2SeK42KL>OgkV);f3k1__BY24@pWm3OQhK6*H2c(knfmft5 zw>E6JAhg4&t31brW_{qSz4v#I9vAThE76w9-Q#d5FZ-9#F=cTlkbab>XTTfQ9o)R$ zvzbj$J3>sFJ?TtcD2g~;j0+|*l6*>dG5b3)BnS2Of{G~fGFxx@(43ZlaHM^SI~E}4 z>3dBRhot;s7TEi+mSGy@xpk$kDn-we#bOuyx^EKOBv!^u4De0KKL(Y!1}YePyOivV z!mSC5Ru(-HO?J!JOu4AyWmHppfs|qM%n#;H@5z(@#f08{R(GR9_rOR^X>*rTi;SvB zr$dow5u|s*xI<|e*QtdaNKQ6pukDZH+jViXFRFL6aYQI-mE`kI&F z{%vi*tg`b5_KGK;Ui9cGFSk;g%%(F zj_cM0ZM6FCWTV|po8_ppY#-NB?D4`y(UO%Y+1r9gMt{#DPKT>wFD4G%d%w||p`<*m z9ZRu|v>#a>i!Nzh6O@j9;x0ZcEdF-<%s+%%NwZ$i9=pj z5R5xr&thaCTC^TmFI(d!)0c^<79dhMFYEVN1^YKDzWWSaO0K9%_sl^m3pTnQzw0oq zsU;X6Knp+$wPO>*mGQn#YSIzrQMp}7cKW5WrbxF3Lnp7WjvcW!!Tq%3?hc6rD0?ld zMoPa=YyENBQO_Az0pF7|P0zD5&`$8Gu8LNK^(}hSnyRu`WOI_$tdznLQnhRr(GYEx zSJIUOHNV7O8Zu(&vh z7Kd$3?NHcS>XeEDW^k-CF>7~=Rm@vI=XPZ>1op;@t4$)~KOU|A5h^ZPBIcAz*)M7W zEJ2kZv8OwUnKRYXBO>h9C@OPNQ)IviNA69!zYQavZO#Jk%^uMm?2D2Z+DlT-(vDpb zaT3eYM9&@Fft4H}Hmz4P->bvkn$KnTk;8||CQZhFp$ zZb~ZAKV*jkTA-#PsKj+<)LcgY5V6nN&pyvaH@j%bC*C&R1n55^T!RQ&@-SBGTt)(6 znh=|e-=Fv~rL9aRwb!wtEL-Fm8G3I=k!=yRFuf$%R#I?MH5?T%J@>t;F~TrzfuRFa zaZ)XrjV6YLONjU`g;PvigdsW~opjLk-(@6Bj1Ipf5S@`n3!Kz7Fd8UbyTXqZMQ$ir z%3P(%YUr%YHYo4e$|9sE!}fQ4LOV9uw8>(qh!v4nU~;{ikXo_25U16dKzQ@>Ha2I?rdwQVWI#5_}$z2K8+Sy96KYU!;m@Z#s1~XEQB4Yno z`ymvd8)*jS&y%99 z#171As6(~8Du0MJB<=L@Qb{Yqj{!Aebo!gVR-_`NGK{1$O|P0Rk|-EK+)Yv0+w+#h z*J1@(vKqA874+g|w1g7yESCqfO^N_hca5F?_guBT)zb^Il{xYE%Gn)S!_Vz1&f|^n zSvd=jVZTWR266L?4zhdu%^i~l1xi0o288jU8SzfqCDBaX9>!KoOH^r(LPxCKmp*Y@l< zK3=6)w;XfcQN1ow#sp3to07l;>dy7Iw9gc~S@L4fL^dYdXS^Zz#8;15QkVRH5oU^t zkF0*k-Z815FP^PlkdNYjy@|>Bw3c=Z?%yeuMD|SsU!xiQ4T4(5a3sl{XsaTcn>Z}* z;WRc72n5Z|F`i8=tZn1A02k@8Zqh0^c8g320cuObWz)Si04ikvI%&>iGU5G@7~Za--5(UtY={S+w24|-Z#!rh)11_X0pxR zpVnq!hLWEw{Ctl1=69^!xxl7`Rln|w&V|LA=Gv&ve4b9($~i+7l`G8i5ik>AJ_z2* z_kSsWKRSFOk!Toh@5MDgwxoFp|0 zMFt(_?@KgM?bE)$pSzRK=I0B-?43#GzFE^t(dj3p*K818VmRkjYV*wC*AAnOl zeWx?hbLy9rv;qMQzhu68gpspk9?m-30V5t@Mb$W9Ak({|YI}#{D@}$L#sYGP_h#h8 zdkw$_FS(!E0jWut01#t;#?yuL2;n4~G=aXgrVtYDy13w51dUhzuHrQHO_tL;7>HQX z;#VD#z1OjxljYWyI^)b-xp5n*A_o;EBfpp9=ET#kOU~y@Avl+$W9qJY8U;Pgd~oVD z7mCt*`_OEdK|Rl{(0QkAHKT3Tl{uM)trAb-G_ROg;I43Ue4+ZQ`_lFr(h==9XA0E& zPg64M{|Gu@T1CmKkv${}WyNn`Jw4Fp@lt-jv}a!J@Xe*|^n@E_P^k5MtUJ${(^6_l zaEiDv7>ZB%@pg_yvyIW=&DYAHBZGTEJU_*n#1Ynyr)`TjL9+|q>J`ZrXZRh*BKskT zM;23uG4JAVX3O-oZ($!*y{YcFg+>y2}KaR)fA=j!iz_L53y2|0m)tO zyr@p;Rf*);TM2}hW}EGkL$;tRqEO$Dm%Z0r3mJ``7GBWlOZBta>1Au(`BsJFu!@MzE`IQ1AfPg zSH5(Ir_~{*l{xISWV`ZCHNW|mn4EfRz7>N7D@JXAvGm87xW+;p1L!9@{~&%#TA?`;KSo3`4YDL}>P&Jrq`5 zu_}`YcySqjgdIQek@5ZY%=XxoC>CzqWyQdsnDCEw2(8 z#*o-%rmodpdBNbe(ZjEb zBVI@SAWeJ(Y>8XLGwf_fJ6??%Fi?PGoK{&n&g$Jh&@r5p_{iFhE=jFk(jlXx*Q*0a z_2DpNc7^37I_w3v7mQ&?>ToxNuH*zXoekm+datDqY!@Tt;(0`xi}x*j+&-Dtg36Nw zGf4SFtSlx!^!{#46;n~4azPyzp2b^m@$PH}B4mDWoL45gN^^81j$SiNLpw7r;S3k3 z6=x~Vej9D5wD6L3nNC9PsO7EU@J8YU((w!lN^3_?xg^qS)Zrna-J*W7@dt&eFU-}E zx}Ncvl^(h3Vi|VTI@xbJ#^iShYzg>`8|r7d;TpXg4%eLVXnq`{Q-tptW<)@<#}Kql z%CWh1Cf7#2+*ygo=pP4Iqz>CsLfigJVB{!?FVCe)Ssf&qJu{qwiKo62qcjqvD{C?? zc(=J1>aUYctZm(~<&#p=wi;Cd&ONd5M{1;G{q5aVs+9egO;m42Lq-DTW^z<{Behn> zbqcQH`&>V57~4{Eme{nhUI<9_v8BF%+Llq5JsuGoFdZx7<-!14_!z0WostZf2?kr427T>PDD$?#lS52I9v{ni+vcJ2(4S-=>CQI*kJ4y(@MdV0PbZ?&z z9?&aILP9N*WcTsF&|l0vwtvG`-?TCCs8e!U#XK37q) zHsEq#7@Di1vEH4e85KU3rMYce6k2`sV};jfY26U_316q5>AgjruSaU-CDfINh%)gj zQSI1+`dQ-x{7c?)G;*p`3~qQqQk~5W(Hz{cFThv8O^A!Cv7IZ`5dTAdUOJdjcJH7i z3A=~L4EMvoN4pXN)HSZtckLz@RCvDkvk~KK38{`SbSg-0_hp`=C|!Wf=mmv87VP#O zhE3~Wm&Da+zfB9m`}uP{ZX0E+JI@dMpQJjUGV;-Da>A+}sIkmr?F(2djlnN~0%|gB zF=vfqj8d0!J+Ws!vtHDh)bnHoOaxZW;szH`i|^gzt0~Q^7{_JuYVLKVGcN`lj56vJ zay4UR>0wtaF0BWjsYaJD=fz~|ufd5#S>}!B0p~C9IzfkTaaW_nNGHtA%KHieHcVBj zx%yw(7|NT?laZ9Duv;awCrBd)@}Tp3p}5{1+n)h)m6h%yv?Ivq*31yIX7(#XnY7YK zkL6W-WM_U_r9MlGJdkosOd=auWUJ@BY+{m|&AOAO$0}jhqsi_fRFjq%6z0GbpQL1E zav8ik=*3|P4`OFsSC@&2|1b1Y|CS&mMma80J>!%#-od8dZ`X&5+Tzuat%I=#;wY;# zm|PrW$fLkj%2Q%bz=(w#WL@rA0bJe!9XIG!n`+0> zcc2TLy^cgTc3|Ms`Lw#2vT~t zg(lN`P_XK0!S?9B!bFic(W`31<9rpxZg@T5T|*T!VZELAdJh#3-v zJ|v#8@t&(K;CI3Hg0$sq%tq9vm!}O1m5EqX}iLPJ= z4Km3Xgj34;jMInwj-F=SYXL*ptYanK@&9PNK8^~exkZ?fTz033&4?8*qV@s^;temEZ$}*f!Fh+X^foS1#x#<9d_Kh;cV$JMVPQe>_cY?%jXM{tzEwa0uBqA``#+q!+z9 zl$uHBR9k5TN1?FYi)MLq9bRRNp0}ry)&~2RbDTlFe_}qAje>#Rhvkx0;NpoWPs#AY`BJ4bq4E+{@Lo6Ea}r{L5wQpSr2A-`NIh%RmNXBiz;f9U%vx3uiEU8! zlQAWjm)rV+DTr0Dt;fXD1*h0$_Nd&WYJST$62*G*-*Fw^_f_n^H)9E>=QY)#rl_&} zanSzC>&oxeD?kk>HL+$>{k=)nv=cxr)~+1-vV3swxAu)cvKfyKa$<;+3BugB;*Lw} zz^yWqg#GU#JOnsjkooEh6Xx_-U5hM>t2Vjg_XA{LRbC@FF5gIPp^Aw(+xJ(;!iY%& z<75=*-iB@a>h`#djs+@s)PXjVM4o^6W8~%s^$9b8)(V6E`^PR`#aAwknro^Ke>B8& zsgn4>pKB`kGA85Vl8)9E8j3|*-)enKPG&Ho6dQ3$lY~R6PC^HE;ZwWr6CG{CDgm&u zcIDWY55UFs%-ZO&*Nihi{zcb#>Nai)q{MT8b^=h&XsL<19B{N-nnBq#VR*Q>?k4bj zSs&!OcSk5PH4%w*JLZ2r&XX|56EE(KJ_6$UpSAz}5sC+>lya&p{+(^p{W=q<#7^j| zuCCO&x)=)K28vRn*hvzh%7DkR|M9Ee09UwDe*XH;ajxzCs_MhJ!gcS#!!NryTi1-9 zf4xYYi@Sa*U5Ii5@HTnVh^-F+l%w`ndG^*->2qHuC!apJedo8E`?hkQ+D%(K;@h74 zb|AhTh;Ii1baTFW2(SX*eCrp0gl`@KtiZRB>07Y*PlV351M%%ZeDe_BJj6c%FkANE zn}_&Tj`$ab^P7kG|KcI$w#T?^p9|uRfe zNqfa;m;dqCy}16sPF^TQ>P%40-hZpERsTGsw`1=7x1amco_$-)Z(HS`=pk^H|L>i< z#LfQl@DRD-{r=9)=tkUq{By;c&HINc<&YkBuG2m95Z^UsI7YUjb7fMI3C%$SM?0%~ zkZc=qTdaro&IkVo`|z9X?iSJTQCfp-O+`7S{D<&$c3qjDxcp}_|GiQ}dXH7>OHoOp zY9|%c{MYB6siQ+HJ%6j%Fj_C3`xx`!&+7Xd13WB%RKqWib;VZHiKvR_go>?8RBze_ zn&e?U>t54YbGhY{2uILwiCE*-?=#BFQ;3lh?`(_DOTwzuPF7hC)IO+8PTs@3_EY|;kC2}%TIN_fOQ9}_&*ilC zR?Dibr~mwC`{PJFy%IW)A=rA>pJ*5Dl>D(lK{}$x#VEsOB~2aTeH*&IhQ0-U+ zFqQ_y-)b04^W+??-&JOMpP%v{V7s3}6ia~VZP(Ts)uU8l9CEIDCGYgrzdW1S zrgl)5wFn%!oVJPj@Ej15W`ZFl0fWlf_q^DE3XP7>qLcTo7ss@%q@@8eW<_yCwOc_~ zm*iR_Zr2Zgxn2Fl%@671n1*>Ic_diBxfnnVGf~>HBk?vyHlNj-?@j#f*DMNA0}|Lc zXOFpPNAPE^{Qi|$omyY-IK%Czv%^@NesV=pkLA>*$S(F8YfP4?meiQ}K!iwCIkYQE zB=t<08Vr!~{l4!z5xiv&;f^Lq@~>mwubDoTqj5JpQQ4{4Z9URa7g zHhOY{TvFM=9D0e5Qzo%2XIO}NlYY@E*U7>brXIUOWT5&Zg9TJUD%7NVsOs+GT2wk6 zlN5kd;m2*vu?%Hzu2kCoPHltSvc#^RPYZYI&y%R~V`E%|E9V9$Lgf*2RfHFT0uWka z57-@yE=hFI`65d+%V})2asV@HDT@iR9bqIb(jg|M-}e<5d+sEhq|&Tmc^KPzFayd1 zI?qkh;ny(L=`j$>RmMyR4f+G;K&Ir`$;VDMJ><52Y~qiitog`4OeSGha|)CF=Qlec zo>l`!n`-)!FpbsI#H6dkqc!VMQJ4cm$|n_0US_p}eq^epJP}glMkJw;M=I9(1#0{@ zqV5)?>A}R|j@6EQ>p|Qa6^#Dn`i=QeMaxlAPN^vNgpr>@y{;}_m0IykR(0k~^2Onx zqw!-oIl|PjVIZkk7ewL5_!hf0(tl@$fePJR!G}F0po!JpX z$84+>mIv9$m8;OAPAO_tBMjD{<&(2?R%zX)C(zXOP?C0^u?#4ohsc>0s@2pF-fGF_ zLA>OR2|@Xc8AGc}Ni1WL$k>wgk)TBgm9f*@M)ssNwr&PGV+qC3xyxU~q%2WqmKeU1 z1ukb;?ch$_Cmw|>(^W=k^-YL^mBIa-SHKneY4eIkmLu=Jb3-%IW84J9p+nUZx2)eu zu1{eGNH-KF8^K~$oe*_#`ndceHA)8F%Wl~jL%OkMTISgl(K!oi@oAdWiK^sX(p(N( z;5Rcs6E@nSQv>^4qg{CmswClTilS-04CO$Lm z27i0ja0tedJTzk|?L3uvD6YbjJmmfUXNdG#T`+yN54!89ipNS-jvGe&CcOz>ZK@fh zZ`_sAW>&!LYtLhuTl40hu?EL9P&*dbak42c;IUkVhB!oRWujd_BW;1#+|5}qg?AgaYXJ6v)As}Y?DpB&bzo>)I5Kh;^dGPIo?$;OSOv^nzhhcm;~5r{E& zz5dP`1P5<~;$bxq(@ zI&v~|fBwm=^@L9PjNg7zSvJCI{DthMz&IdOvR9N=bgVm~XHj0_71VWxs=1e6FEKHB z4_0G2To1v}wM=dZMXr~y6mh#<<&~n=p+Wm^Zlw;*|yhUW6L@nCw@8_ zLXoi;q_O99>se#g;}7N2>Vv{Z z-g(eND!7mMw93-^t!&eTge-0#MSvl2(ZhE` z%4nN&%^{kbet@Kcb-@t0(~Q-HmLhJ*#?WB7)eeey8`OFp8?L3S^bgWc$R9+ZU&k$O zYAw83N@WU{W?8qIQyaob8ccVSFv$EFrI&6!=F}=XPpzv$;3TTHPeDVob|$uck?i8gmUQLQiU|SmhVga<}m@n#ofo=7~HKs<2`` zU{Fs%US3s2ktOzHOqqE!`=qKH0p+@_Aj~SC948`gvV&L1sb}TNy%>*bx9pkS!L1n2 z1?cRA`blV95nDZ==GLHGZidn&mx21|WFf&fwyI9ird=sB!%oJL91SY zzC`+FxOB{y@W?x_uk_(<>nYSJSmGQ2^NI0OXFGqo;ySS1bJCcHRFT=09=5P#9FJWX zI~5`TRLvRUGouMzi_vnSOIwR}TBplGp()%3$VC%2HeuCMHchifrs`Q?I_!J$Ef&8Fk>9=(!9fQ2eKT^nw3=&i;P{( zk;$qKmDE8iiK`6xzJFFfzHm9Mpc76`pS<>$piLJCW;yfv4rr53i89+vM8e8*YwV1@ zk{M1dK880f=;W>fIn(QvSy>}a`u>mO+hW7X*5M=UoE`^N5TnlDGMXXF<2ENDjB}IU zWx!?q^1M3jo@CD?@u*sbQx@<@1^D70K-}>_6SkCE5Px%aP7~gjzpeyZdELT~r-U-G z{340ZGF|{cd&JUs_nJf=&KA2+GD-ThHj-Ow<7AZKDcPi=p~3p;jHiIOE+5i=ByS&B zk;hbV@1`=dwWLaG=yXk*dXj$)Wlf&wcTA(PP#ND&x*4VaoS=RHjPuS%bH;fGU}Yz2 z{&88ST|AqoAfM$dO8se}YSpUDxbmqeBJkgiG;k=fc-GBhVsrF7_G}}B)>47xp+m?_ z^O!u5s+C#YMLF9ZUn84NZjt0@n=U*g0Vkz;`R)Wm6WbX>#(12K7=K(vD~x{;j9NU= z&~NclbG1}wHd?;jm=nqZAK7Ic&!0pOcTa;Js~m?7^pm376GI~WI@6x!?*!~{rzZ7W z2B*i{*|$f;j=HfcoZO}#NXZpc)?AZSi6)YzK4=Uo%?I2lx z%J@<&w-%2A=G8!2Z9_21@7l!A zOjYB6HrT%zk}vc~Zo}AHUBNt@7uHEiQ-qC{;n)T{M_4 z;K-kNwC4G_3E2T_zh&8uyzW?`WY$V~4*w`fjPHe(2uEU>_i6D9N+NCrU#s+aUlI6vm{=B8s% zXAaxPt0*=tFkn*d96)Tgb7BoglPF=oO?iT*KOM*05og>rm0Gd30Me0WmN`%rxBN>+ zBX&koQop0P>%Jq~8(Y^v=8sY=@^;77{%*o;ZD4kT`avvg&y>7RPih6~6~}dJNE^FS z__fwhgp94kYK%}}*3_F^nrYnSr`4q$Ya?-kq~4!8g2`Wk*CZtKW}o_Gpymh)TU>kq zu_(X^nt-oHXfCJDW$;}DNi}LE%qh}}ol2c?87kMfdFzPk%a`WA+cRQqE|@~9g;Yu9 z0Rzip=gJJzQ|nTra?H%FvYUZAuSKGE?C74qB-58k?^Rn%dCfgGt@3NuJ79zYOj-9t zGLb#38wo*phA1GaO5fH zj;Dgu&Ya4_U9ailzK$e5>dmrLFUKG-kn7WF9*7N4Q)WR`Iq8=v8={qf8M%%H#y0sT zMCP9x{^Zt%SA`kP3@)gr#S7beosHE)*RZo%vMkSX1M^6$pLH2BD<^e#O{4osvGZ13 z){Rv-6X#P!j&D~_MvV?qTLTo=;Et-&is>e{Mj7ybOC^VSELwtUBA+?KpuS@(_nmIego+uGaxpp) zK?@x@iqbvme=%@zapb_x-o~4aBNe{RtON;S?-CU@$V!^)FBGfvTiXV zubSb&d%Znc;Gkm}?^T0*FJKwU34MYV%Lq9agW7jP~C4d{MUsd&za?cLd$l^CU# zoc2Vg07m%=`dX*NTBD_7W5(stl?|h53A%(Ba`uFPP-NENiKRyi>91A+d1lZ;%YS;z zA>T!PzqHmrMrgO#MImru>nQK)K)=e1Q8hmQVobGK`=}S$*Htb1>^_`DMJV<7-obhfe55RQ5hpcq>L$Q z2oOS$fRORK8#@qs`|Cc>y}!(pKVQCl!(Mw0d%bI~wUUI_xx=5k%@;T-<a(ESi8t+c#o8LP-q$<{j7FsQ)UPdj6$t zn|%m-Chrn6n1y|u_vq20h+jscc4_56lhdbploz;@Zg|jHYKxWr$Ug`(Pn%dYtK`zC zCL7Q@+~5yRTx}%sUQ%hjZb%<8p?zG)lg!lgl(Gf7A+|GhsT@@D^cxlH+BdFD-U)g8 zmx7Q2+CAXMV)VO_3Go`}7l$+YZ1o`S46QJbnEDxGM?u|Lp7E3~^m@(kWE@F1S9Msp zZ%&aB!h2<$YJwRO7y28_6S&HZ6na$FiNLC;s%26t=^1-1(Lvg&UV;pt8U2ujA7bel z^2DLdXb+)$U^|w_RXwu)kew@6h4-#bY2*L@1OIw6}#0Nkbl`slBhp?qT@Y z_?0kE@gAnAz<(vvdKi>)_?lk#HvO-+$W8p+MvE13@p(TR>Zlzd;3r;Wq*$pgEIjX# z(!#a3G)kh=&4ozCw}wJ!PGZ#}lB^^rbX3C#4hQvW&-sK>g3Z>T09nOo`Wmj+Obe{P zw82l4x>olPD#Wi!8eiw3l}LCQTQW62e2BjAJ?Y7 za1qbuWLFq3CJGhy%YuCWdeKjsk@3`r(c^P9W72xbyn-PdBDWl)APM*JFLF0$@|q9l zS{oNApA{&`Pj^5UAVE$gEm@gNygUIsJaTQ#fZ(~F-tLdOlBun+4QB>!5rgUob1-n$ z5S(5XRO_7zS~&;w4_SHrSN-$XqigWmMEV+3H~;ZZsOH;!3zG&`d&l+MuQ%~?k|VcW zwa)6hW#DINLv?FUesa1Yk>2t}FZ~ z#ryng7rJV8YvGPJ)hx3}R0K=LOV4x_PA99sD zwhEdqx_tPre9c{duo-BtyJx4^`qrnYMy3ZWFJJDeHV{5(YI(V^yKVAG$?jk_zy4yM zc5fNViZkcE=raek zL3995j8A-tbQoD0L>$Q1fCu6^m~i$XmCVIAjkwsYPaBUR-GYH^qj0=r2^SkK{%%=c z2~~GPot5v?_l|~G+aB{#rugA;SP}UKsKxthl2s7SSt$*Wtw5sphpS?V#K{lI+K^@Z zoUlS)7pXBY4$2(s(t@E(WF+H*9Y|Sg2sfkt{%(?Pqx9VdtRb{7 zdv=k47ahOtqOG@mtxL+pp$5#)7Sh)wM*yDeB-~np0rUi9SRA;hf!=k{a{nRX*df+)}bl1uZ;FoM;tsGR_Z4*zQkg5Hw|?0}H-aqN@4Cldk0REsDArxk=K{GfK* zI3Z^0@F0P zcOM+oB8%B7d;R?Uhq2#ou-y|sf-IzPPw3ID1Gr4RotvG_Wh{4ySXb=*Rn zfHzUh_C0EWw=JAjGS^Fd%zE9cuEPLa^0Mw@dpMMAcU1Ydvsd%G!zI)s| zVyeaK-m%L6PVU|%YOTk7f8imJmG>@-Y`v=HTNV5+M__&b!7sM#UFPEdNm`|WbJnN7 zeTyS*9@hQsVC`4;w5^@T*3W+$5pdSaQSI1y;FA=D`f=V4UDD0p@As*5|NW;$>1xMW zcaLsHs~=nLLzujKg?Cg~W1>H$f~iRL>Wm+}MW8yMRWD41QQ(T!%IsE*8k<^bT9_CZ zjycnU8p@UFZdC`m*fO0-Kg0FETsn<#ewF6^ z7w{-b(hwA|teA|B-o3|R(HjC4z29(n+oLLhr@irVMGh^?lpDuLm^!M}bjVKeVv|nK zR^)$J)Wf>ivRnaPJ`9SvPJU^t*YINLss^Cuc(0l|D1Lc=gw(yD62$A7K{avt?UX9q zgGE>>EqMAq!ptZIkrzWR)SLP$tdMbzdpkBy>&+TX)%C}oOs;3gg@!kSy;fLa<$7;6vjb>LrhCm+vk z+g%;^7b7eZJl2~|kT-U|7V-6y5sK2pKVHfnHg6P^m4+PgL6jKP`{O%X>6s+4sP)hfU)2ZNOuO7Y!RUFB zsS@jShSRL;u*X3^ZxY5nuraiaJ8A4q0n~7gU%tAfP;@>f1yOQmHk5(L*!WU`pt-#K zhi@k}GS0L7@w2UTEehruhqFI+a=-|E;@D=i<#203_X2}wW2h)bWrJEP=#zJkt51e9 zEPte^+m@FI=&?J>p0+3wbg~y;XgTa6e1bIuWId~+TqQ3apJ~J}3$t^VA7~UNl=s)` z!01KRt6d8zbb?Ie$!5kda|L??bO_&zDH>gDpU%qe26ZDO>p93hoIB#Yt1$Tc(Z5&E zJ9|#MZS@}A+IcR<{dAIeFw$xcPSb{!A6!L93NXk(YwF4TZQ@g5r|y}nn<@gsJ=trD zYIVU(Y@#olDVfyZ7kE3i1M`**+bY(?u>PeeLca`08+~SIVberxdqB@2I*~WN$n$Rx z=Nd8NmY((>u`sz~RVMS#y%u!D^kcbO2Py3;$_SK$l9!A37T_j`NNWXSU9q@ZryyKF zU5g}1d3UGVSulIjpTb>?EWzHGY!4e#1$>=NXT4E7Ntb2}n{$B%dnKDgdD{7&S7u%7 znWxJ5uo1V8f|zBkCwi-88Z}VbA`*@tA-Pq7GQ)$|MSY0lsgxig$yj5oE41=LqFO}i z-deZLmSuMxOk$U>8k}KjBAfR!bMbwdArUIu{$eni4qy8l7g3g9GukeDU%n^jP~et^ zK9S`q2;*j`RhUz)2$eEt17jh3CQ9aK-nl-uh%4?`ueZ$SK>L+lN(;0*ON+n^WgT#k za!IlGB8N`^Bsd8Q$27*fOLg*=+Qh-}H$v5;wuc=AGqU%h@C}--4WRMDr zpp7&Wnr&+Qkj*f2dsf*fXR$BsFOwSf;zO69sPtpJ%#bPzlJ?kM`N;3GYUk zMJ@Vj-59rbb%$>U@iS(PIUJJY`SSdm&IS1?P*M*uUf`@V9!KO8BF$bRGQ!cSDb_=n zReYSO@%qq`1cobi+n3XneCjK}p;IY{3>)<1fKz8YF_h~+>Et~Gv_prLWLA@0(Y~g& z8Y|k}t9{tYAZfI9lLWUd&Rv!-6z|Kd!wWwoXSWPq4cxVa2_2grhwAPtI4iukJ~^Dl zpV+}b=(D1ZN*}+Wm##Beu@N;%boJcHFtAVr^U13FM{+_N7xmM3Ik&+`&3wZH9knp5 z(Cgu3Yaz}S1`2|f6a@9gol6xPbZymFYa|0<_lyGs(U-xN51($JVjOPB6;3v1h*f zZ}l_cs8vEDiLb(-WU5Yo^oXy$yW8?!%YEVKa(ZRiwqdm!7njq>i3Gu|Md&=()i=!Y zYik5r=$zYIwc#Tg{8r1(i<*^d9s5rob8bjpVlQ(jS^UWv#KokQb})III=hCXVXRKv z{=Gh+D0xqdWj;9~A$)zN@{T<4&-EI$0IdUnNk~l%!T-=(`$1PxI_r5^h-xOyX$2!= z5)=GZ56i;}3GJIW`VNXYCg&1K*p$6C^A(hUfLN%xO9y^_Y&+4f1;^+zJy1a2LWu~# z4m6U9IloJ3u_=j0jv&sI)LwiwKy`C`Kg`P!HCu^`_sxuQ3Ykb4LQ*HfmiQ7-=(I>>tu#@78EplXUX?SWJMgN+1qa>X7x%wlfgMsLP{DJ~2oJ7jKJK zV*yiNE7(9sQTho`17h&O#4`IN*C@o%DK)d{e)4$vZgX3Rs7PG?$ie~=R)Ur>k@HDE zmr>=JgYyYX{AFk)s?t%@Mq1-Q9KX%y1uEMXFLbTebr~ziHFhi<|S zl-+T-Jbr!gl`H6H(~Fc+O30z#bD=orhR5D0FfT3{QxU(@?^EYluo1lU-xJs=bbQrl ziy#_%+DMP2>rh7&_-KtOI-prQ#8FES?xTtoX*DN3c1V6ssi2@%${<3_>ZOuw)c}N( zG?N2CEN;>HjG7BoJOP%6*Dp*FsaO@-3NJ|``l#qW4#`TZ8tDa*i`%R>Bzp0F+H63~ zijsemLhjnJPtngiK@awD5Xc@fB##x*%kh+}ICwBYtQ_X}L8Ceo7&kSaZLk8YAF^ta zKFD>fYH-+1P82vZTB1i+2s@*`3uMfW4kceuU~|<+3aY6d>i~uA!sY^8{b)Y%WhL2= zJTVq?N;VFm>@&Kx{D>IoZJ`5n6ME&QK9pdN+F}pf@tyCt<_5f@!v7N$HaAPC5OO9U XdB4qP&yv Date: Mon, 13 May 2019 13:12:33 -0700 Subject: [PATCH 283/737] draft3 --- .../windows-autopilot/images/wg03.png | Bin 89020 -> 88067 bytes .../windows-autopilot/images/wg04.png | Bin 158281 -> 137992 bytes .../windows-autopilot/images/wg05.png | Bin 264215 -> 133517 bytes .../windows-autopilot/white-glove.md | 45 +++++++++--------- 4 files changed, 22 insertions(+), 23 deletions(-) diff --git a/windows/deployment/windows-autopilot/images/wg03.png b/windows/deployment/windows-autopilot/images/wg03.png index f312437f55f7b4b49ede100cd069623b8585c816..89ac12747c8e62d6b5a3d0ca64d77586f42322d7 100644 GIT binary patch literal 88067 zcmagFc{r5u_y1p{M3%A@V<}1Yl$aPq*<-SgJzLhnSjJ8&J7X+zu#P!Yp$8O?t8|4pVv9(b)JuB>{C4rCI)VXGiS~)X=y$- zICF*;dgjd8SM=wBcediij)AAMJ_Z`9XDS9ji@=L>PAa-8XU<@f7>{k~fY%qjG|ha@ zoMFcO`#X#G{Nixt%-;g7$0|kv*2~!!KA5Og?KaFzwfOrm`=>SjE{l1v@PSrKP3>F) zJ^f2X{k@H z(n<5w!V?a}|N9Uz`2cCC|G$s)hyQ=CwIAoSp6psg<7U0UAZFlc|L5nMsTq*Yi(y;+ za{u1=@B15hFE_KvH??xa&CJ`vTFR`NOj=J5-OQ?=>wY!037!9+qk*S4oa@|RW>}qv z)h|Wud~YqiO{0QNutu>o_RQF;LB<~;2}Ulm+9fi)qQ>02DLIdv`XT33AZ87k zQj_vjxtS0{kLC^ah7~MnZkOblp|D#2NFKSI$>l#C=(K76!Qw&tPvcB%;+s|*mx2)^{J1W|aQD2!ba-$1X*!AO4q8IN-Lq!(#yd`7 zT%;08QjvuAoJL; zM7NZ_=_oVhN_ZDx;!C!l7}<-bFlIO&w-xC!2}9dj-iPQ3a!6(9_L>Ys&j#~Y56Rd+ zORK7DOr7YE4>pF8z>`s(raT_FGX5X85KRTkWeTGO?GH=ZR*a{L_d60-+%pNCE*+ug^c!1m9}Ep#n1HT~SQ$9C#FoluVcVmMNjI>ululWy zX?A0|-VUamP~`5O8Oan6hbwf%P(oUSnW(~fFIo4qZjxN*94U<7j z~!I$ujm6Bi}R!~Zf1j(5?c(s;ttPXqZSWL z!LL+#v@fTUU8VyftrX zr8Oz7eT7qy8QRd`Y7?QCEibfE)&`!M>q&F$O1KvBSi-7NrtFdL1<~50nzMoJXIQUm zF@qi?r`&2NKsjtb9IYXz4`xxkk74$7@@XHFOebkU#vtgITH)HH5%G$CS@Vm>M%m*Ruq*0_lvU(ES{m3XaDBF8_va{ z$H082Av?F8*y6StB32aWW{Z8lqW;VwI#WEnKjM^2Av)( z6d)*FLxs9opQnUTYtk;FzC**M?Rxne_p!By?BwrX=*J`blv;r)yDVP_XW}sCVbA_G$g1j~jaL zbt4?)meI%LohayM5nfhp>c&Na5d(^W^ySybkuy}#?jE4!$0zt;c3^thl*n~v;sXp;WoAPbG5%r z8ZT{xADM?r!W3#HVh5=ACET2*8oE*r%d^~i%ftL$88rs=7wAN+6L0AidCs)nb^h`3 z;m7Cw?}g&Iq}~!rO{4qsM}D^4415VM(0VDzBm@m|K(E*HHRPex79#p^_V8=nZTNUD1S z0*_?KQrAK=95XD{VS{ud@u&OmX>2)5q;x~={U`Ay&~fu{cQ?3!Ekpkxbp*ZPb6~i; zTf!)JT;K5fWtU;yjzy@FRd4oM$yZO?9Smt=&KtkG`<{_|W}=g#i8Cq+DmAQ2EL|L5 zCzdb5@|Vk%uo%ZD<7O7|M5R_L@p@=er4cNA83i}ag*s8*%mJslyhMQSAOhU&arRB@ z21pYpT-nTSxTq!0VAjMY6~TUFpOuOd{CHrNeFIfwFI-W2W7i^7^gDHhFwwPYISYga z90mgJ;P$8|yuS5lwP~|QIJZ0IvS9n_@Jl+zIMnJJiNHolK}O|s#WG?NRfq0g4lJ88 z20#UtH0EY`D>}A4*gbr~pkOp!F9(FO`)cahh+GjJv-Hv3Cr|gw%`|^oWy9}1bXBck z;jwZidihy=9IK}$p`~T`8MAWy@UpwE!y;OijK0c+hlS5p{-r~NWqIihtZ_C|UqMnz zpCpoW_lvbkW>jg5Uny^B86*G7n$Z-whU|7}o4asv0!+m|4HZROew7^^-!4;#Vu~OB zS!wx{hex=edRG=wP#0EOXX;n9EkX>2`4#V*aN)4Jq7{vXlEIia3T&*OJc?b2 zSA%oZ1V`~*C#_q0L^4&6vC{`r66NMzu_z^9e-!n4FE?N>ww7LaL;Fe2zLCxQo9w@e zo&BCUO>~SoUDP!EhB0@m zu(2y7H>F5RITI3k;Ap<)b$s>f>zxrpXb-{EMnZ1V>rud(mVYjpMdQxmd=|)$23xr+ z;tZNZK;kWBF*bgPM$4V+PAA+Ijh11hrs>9^_B>3(rM2-VB_!fui2_%p{v1_I?f6-p z0K_!dEXxSCT-WW$PnugQwTv0ojGWc04F%z&%oMv#Wp%~WD_Vc7gT;{xTcvvFjrxO6 zly0hl$50YJwRW7HLZ9BDWHXJiwxw8D^}1;22cn}W*k@CLm?DXT22u|8_;Om97%Osc+w)1CKZLGZ=`W|pt zzZFO#Z+@D|d~IMW^6Y3X4chz0)cTr|>A+7#diEwLasjwM%lTK2C>KdetN}4*B=V#P zuZMz)m;siWgfom8?vSmB_j7Bp<00f7ecG94AXlB`;ltO;@8AV=EszARj3`1u``Mk* zMtq<%i0AnyM&4R|fA>AK_v>2 zM3Z4$x#oC@&C$~n&JqfDh9dI<_X00z;!fnQv~7o}1=CnSanQJIwe5RU6e5viIyLHf znbf%hoU!i59XI@aAS`%F2Th}l%rO>lpcwX!0{2|40+An7o3!*XhzB24oEuPlhwi|c zf1y_}in>C4+M=t0tDgvQ&rEc(-Kp0aehb~P_(WzqAxx#HO_f*2N7LiR(CC$n%1(RDncJHe8-3~(Ec0Ct@&JiGj z;NnXDgiHuW*zM0fti?mlFN_*C?TZcm!i&A9hk0~!1hmDfQ6ZrnTtlbIhK|IM$SMaj z^^aGuLXnbH4~C10AjZ|yuafl#?l)h(x1p8QIOxt8H1r(1U8HL1uy6bf!ZQ!@}2FI3Zo0COm&QBv}}l zlMX3B=8`Wyok}h{*_*L3uk+wlvgd|o0#%4pR-B`PO)duR-5}u(s({Sd@kG`p@<&mz zrrl9yZ2n9=_467)ppE+VtG&UUmM{)VC2>db8MhU0L}!wk{V zE@R>yrn*(4x*x_GS4NsJ3ojewz`tz#lGsS#Z=&pDr(_^l%xQ=%)fCpolr%LOCFWSQ z^Ylx0B!Ps~9LFyb8{O)u?(!HCwXB68RyG}F;oqyYyPyh^Lz3Kjr`w}CS6G|M2b7MC zi?CFaHmV)zD!TQM`ujSxI-@*|Ehkgt? zaHJsIhkCc#yigrEy6IOHuyc5<0R5BY@HijrtrkG}&TOH!)m`{wHR&3LBq_GE*RCDc z>{odjN9&|_@X9ega!@_TZ`5q_ za0wlac~>PRmdtNs{@{0}eS5pY0E_osk4f-@+1G4yK%%&~*B`n!CCtPvLw^%3GnZGU zVm1?Y1RwXG37v1=8ek+1x+^~N*nGoCe$4AST4uJL>d-5BeuFP$U8UHt2=)ELgRS6m zaavBlzD9U=U32O_T5GfU+?w~{7Y5Il)+g0wXiCJ&9l|H~OB}0rsVF}T5I832RhZKbCn5lZS6%X485y-El&_Rm+L~l| zTR1}^2}R3f?=I|Ud6-+Nyh50JKx^>NiOxfq(+O~Ea4R1yac4G&>l(Pm$=YfVGl+4kC)`naSV(-?*k`N#=8#_EH5na)A^bkq`I z!raQ;ZEE*@U%#>KNyBovuC~+B*NL;GP%A?ZH~T3O3pcJK9ano`CpbWb!+O_qHu=Br#ixCb5`{%C*!zJWWr@Un?MO`!sA5 z8a8)dzo9#Ae*EWXKU@OegC;$pA2SL#8`v8&yc5YEPe144te$gT>y4Yz8_|sL+s4$E z>&63t%_DOc$=jXnjuCfGX1fOGzT>;P@0~dH*qE~bsqei&yzJ&aALCS?WRrOEYc87* z{hR>u#RtdhxcPQQsY~Y~BBd4di5SK_M%S+MVb8d5L|dpO@(z6x*YJDJugtu!47X;r zuLkw*94zEUBVuzAF2ln$-8#cG_4kuf#YgQ~!>J?1o63K;lsD_zP9)O56+Q|R?=Cee zzOgqQ>{*XF6IA=HxpOkY{7j|+uE9OTZrquYOKqupu zsRH96M|(36-#wn;M;41f+kQLPJ%a{u{W%klY&xT4{WDq`wTAO7eB#160d|?0+S=ln zvq?&a&I0+zpDZUVl2$NV`R97|Vs;q>pb9HBX_LOgy0!+!Es?c&_=&6~&W>lu(P5ByQ0!B7X4y>6g?|VzO!WNzg)L!39s;2O4=zAD-Kms_E0M` z{L6Apg9;26d^+R(sCosLAHnTNM9(d~MGo#lNkz+cq=2%HS!&(vSD;m2aq^=AB{x2On(E!)qw=5A;8O_}#2WVEBQZTe6xY&- zD(%%QSxP1}_0O-z3Lo6Cdm+x6E=vGr+9 zMe>VZ;(z@McSXVP{f*GVinsALr#D!0rq7Lr#Q)aUuYiEC=UUg**6pVxaq)bb+Z+{b}16;RLC( z&mBs;Z*B2s&Tsu3G2RSkRcilX81|j0%34IH^R{P4 zQMhL?izRtx2K=;<>Ai%mb>BqA&!WxnYY|i>cT`C2*IMeH zku zrQS1MX-WzlEx~(|=HD~ewQ~fnT;LD!0*jts#MoW{c|D}Jm;SD}H5<(zWp%suQ}bj@ zN6X*Sqemnln8lA*ZqU=g&xqtHx;P!z2shp95ayjo-2GhcqC?i_+8)Wy%H1AM#PQvD z6uts%zr2aI(UAekg^IhxM|wbH-+54($GIk|f8ILXVIhS@#xi81lZW*i`C;Jr)XRq| z%{{aR8sVxR{^)FqUqsL}bQ_Yea5*s6DQR{5;#0JC&c1oBBG$=P82T`4V*8A&tQF%> z3pq}#otbOiLA=BYl$)(M;or1^O#|i#Vdy8^!mV8%@%$xHaA1P~berU8!vwI0d;AQw z%nEegI}w;|7F2gTCMgUEIu-$2iAgM6(-2pd2n_1lyNts{!+O!HME>acA+r|i;v}ZA zI|K^q@)F#VN1gkiE0qclSRRUJEl*@8qg=+}yfTxjIGM?}5*!{lvKIju z_>{No6m4@$IhF=lpzCuD{7n2MfkJXSak{X`lr;moBl4_i9JQir)+`(1g5H~Z;nX~OPcn*ABMgfv{!_hhTP zSCGBKbT)fOh9q&1w;r_#BTrFNYrUGI#`bf`(S_035}IQsbQcW+%Ds8v$Uv16=CFW9_l)_S>Vz|VC&VWY_729q=ko5o>>u>tmf}4UXXbDCG85_% zkjtoA+s~UeU*_Z#Ek%EN@H@fiejoMy4XEi}AF$!R7DyE_9tf*3nsYH8MI;x@Ox?MY zTu_~RRq*82Kt{{joLJa35x3*w58K_&@07w_1k8(NydxsPbH)03>YrvJQiV|-8)AQD zN$!G9If2h%ut(YgcR&{@V?LE6kEX~hzFFQk;U`Nr22IG7^;Bhz2AC1^)jI;>T{FPA zlQkn!ka7DF^Ml8?bl>0f`TaeGmId+@rF> zqsJ*7Ewgc!&C!|(luO%JNhcRDUcV_hd+FHd#OLhYuL|T~r9E(J4{9?m*wco~mwP z?cF03!Fpq=$)ClqD2$bMvZFxxIy6~GCueukXRvuLHn_#4+5|teG=rXy~znKlnGLS~1X!bU6-L7{8Ry@on-iHFvwvoma?$inipFcXw+u7N-YBlUd!G_7UG=xc z(9u=B@O0cZ)pFb?=eq?)uWP_YaPX3qzj0g5bJWw z($Mq$huV!v2Y2TJ=a;tHrN2hpGmW;73pq#mo^WP0Bc(EI*d*FJ1mgE*JEz7VjPyLj z#Pnpy`g$NkuE=1wAua(z2(>EtKq%+{mY8}}VF>0iD)5dDT3`74h+&OmPd3Y9=bZro>kjp(|;5uUisx#=rU16m3TI8NtZ8KKykMVRyV7i6Sh-o)6<iOM^eu_qOojlKx|*mU29qwR^gvX_ec#ve zd&sUYg7&|F`p4|yW&zTSmw&WT9+?2!X`_mbp+{+p@jq|p{K|Ty;p>h#q`59^%K73%FOZbvh2|MVo4iN zC1%Gsv^QHy99h&}W{p04W>|Mgdl-qRH-(XOEDGb{TPg?kvSaKc zCQBT9MSd1-gyQMLa!Hgu9D%3M{|QKdbL>;XM%)+M@dI;2|$y zEx38E#0^K(x0EF|t`MR~^&%a>#@Y{$Ea{`GjinIl>%+UjRkE0JK!sVcvskJNT0(8< zywSgmH|_|FCt9DBRNHcnc2Vv8A)E$_#geTPjlWev6`^s{gp0@bDlfQ*)=6hu78WNQgA%ys;>Ugx`*Bf-1|1AKs-S(B;p~R!F>~Kk8iHyO=qoE z7WJ!}9Uhn06#LDwdKJNLVFH@V4>61#7jEx<@4j+#Ax83^14*Hhv) zpM}5ZYejFZeS5{vU^dg|tAhoknEBbI7eqo}ASxvF@~7My5EnAHJ=nzTfq7e9<=4~q z(%ut>_Z-Qe(er4t27y;-l=bzxu==NA)2=U%1qG9n@j>XSqvya5dP3}w2fCIK2T^(X z*70>7uE}sd{JrDN#R=&Amka8>9SKibAOWc30^_%7kga%Sz=AV3WB7S!oyXM6Tzh0=*4JNl(t~=mbFt_w7w`u0 zqOH?wbel>Uc(il%T*oUbj&2S{j~I@{>StrV*Dr%kZg>ho6@zy#xv01kTgWgj7yU3~ z7TBYEm7|GIs_ocY0EFCNmTr%ll0r_w{@80+z<9ccrNR$%t|=hh>5HcS9N@~AZzICj zTd&ITex8fn97g?VNRrV7MtM(047E5`Iwh|?)+eP|fhQt&kGF@Rv=Oh3suYv*vPz(H z?uf?CxL2vdQ-LoN=59a}OuIzvlX(ppCs3IFdfO0~BE@JXawxXuCR@dhz2`~IwR5h~ zyhwV-LaVbBHgX3Hf9p*}zXi^&3H*HmrT|10aW{I@G(`tccjimcH<+ts>p4ugn(TRa zJoHm5fem+w&N$}SqQJws#4f8RSyx-@;Z_>7WXcoCWZKqZ&cpL|$Sjzb z<)ABtYLsMy+xpf8EOb)gCoCuTbDX_@#d`X{p?$i{)HW%ve@n_*Oj!B8SjS(DBdxoEKPT3sk^T+A zuKW8PuOn^x{sg+s9nAL8zKamJ9~|7e-L0v&&uwGE*Ugrz9erto?(5lW<3}#)nby~8 zAS6c+_~dU=i-%@`;M%_dt*4};__Z57ti{Po_hkTSLa3o zwS~9rN=-J=hlX`7#)%nqMjdwi?-E=z3>eQHy=$Ab6BjJ_x4{~+{}7QTXhU> z9J4vC8$aVR<)%$9wul#mjZ}S|kAJ>z_PYAa^U6Et0|sAP(NA9Dn|88G0eZq?kksG{bO7JbI-)s@4HN4hNV_83`%PN*kkM`cC2*q8O;a%c5~6|{ zS9|qmT}X4<-f%OY?IwPUTh0U2eNp4-_=9-{mvNvA#ihtkJi?s`BQM@$@Vzo$a(WeG z-IGC6m9Mc+lopftL6@<>ibY_bk z3jhXbN>`f4K5bFmG7Rs%h2l9f{x_~_W~Wag^>k@<)*%^|q!JT<^O8jELLsOhGV<856%7pVduj-r82&9Lak;cX6}YYtg%*0)O)$T$d5~7TFYNMVDy z*yepr8X$YK@cjC%cwLbuCRsWEwbi{%wfz{{CTmbqb-X`SONoJ6X!|u)xSO}VJwx!> zvZzXHy|TgF#VXaNjZ@D2C}jR>dSV`OB(3U7F2x(<`RaD@Q)Txrf_|TDSm{an8oV66 zYW0d(eByuy1OKoO*&awt)-x|8PzF3Bsq{C@s=TUbYtcOTy?--bcCug%Lxo^4=9%#gc*IF!B9vuho zayP}(Iu6SiK5YsK^TUU^xlN5q@+rp|S?+L+wUsPz?;+ehr$pM+L@!yDKoCt`fclK4 zqE3J>t39!60fcFyQx>6Al8(n?s$s&+mNK{LiM0=2ZhiP{n)`2oQFs_qKnRpXk`~kn z0nyl9L9IK^QD#z@en1!*Sy<5 zwjXBl9k{!Ihw2C`X>&H$DuO~QjvI~NdRFu6<$#0sHueuT*Rn2fHA@lx7&cJf#8$Z< zFqplId{ohDzEhBpRSVM#0r!=9?Ops#$Uo}1vZjQ|oHzC6tQXIR!=B{)kbVIR*;F}; z^xYTYCwEk^Yyz!BpYrKOQswZsml;XyAVkOI*(G0bGUgR4hSaHd_VMepy&jAXF2{6#GUC{HO4sbcaq*oN z)wfrJgN&pc*_M`Hbx`f=4!0J`7h)&eOAfniO+4Y{3dT0^>3aH>5Q2q5Y5Yn<7t3Zk zNtNPO?^kLwWs=c1J@J&2sm>$b2vQ1w7(IUd~}%?}op3)nTC&E)I2VD~B)J-ZUJm%eTrHzfcKk+dA{?jAN)T<94# zvyS-c_)IRr|IN$4jTmpEjKxooW+@J2Pu0Hvt`$h>;ZG;3=)vG?sriG;eUHrl22=Le z5%eg=(eM?<15=X)7n~kvebtwhwe1=C;+mNlk`xb)Xr_Nl}8sNlX8;#rvD_S5}lT$&v1r zN32q=X8XHKV{5@{w9=B`-(BdXke6B6*QaJ*fV?gxTG4YRfSRfln28(uv>p(pXAckm zjK7PxQ^}Uc7+fK~-Sg@Wid{7`;6m)3UKOR}2kx-1dC_xTA&EQ@EZTokz!KqFU;Epm zuY>Kr*o;5I2WvJ8zRJZ?Zc)0(K9uG5%QjlH4#_-e-j(qkc;PScLOvs}toX|>G$Cu) z{30%GUT}6n0}?^q7x#|q63dGhHg7@OWAFn4O&;cYo6k*?Wu4@@u@@dEDBaAVYSZ?r zwml8&AB-}TjFD3CG1ueCp>a7Q1Z90p&#C|odG^>pM*zApSL9J~SgRPrHD8Uygi2b0 zD#9v66oLyp&v+=zQcM+=OaU2I@3L||1yH1i{&*LByPrX_CbUTJ^gHs{7|K^POj>d@ z9CHgZkI|(7+#)8lwKDaO7uUi<$$XW3t#QXJCXrW%+rt(I@RC-oG6o)i>iZQN4yrgc z3J?_^#oKZ=wA+)2l32oKh6AYcG`%TbezNm`z`Haei^YVw8IDrAZ|Dgli`U-y7|lLRJAvq>j=(DunHu7uG8qtF$~c0(%@_fa_`C27Wj0I+WoQJIodTwrBE^CH}kRO;5-C zFIyV-@?G|{3{H9m=YIr8_et_bMYZj0FPPBMo_bLpHtaWG?mFrBC|M1t^5(Z+rA_{v zo|DahRPmKAn~Tk6<6KG*Y+q4TM8)&)zDnEQpvkEx-u2qR%f9FQQ4{lMf?LWOPy;#y znRs%y-9w$_HY0y{6TE54(oI%X@&34`4|a{_Yt=od8xL=}f-ESXzCO6~}}7$0J+hZYD54R9Pjj%nD7N$2_utdCBYbc4ALS-+yl8*Nrs8~gA0n3K_g!-&zDD6??M z(6aay;5@)C&JPig5C9S>Q+}hqd>*0Du}bcWoq$ah3PZ06+zDyV8jPV;`uuf6euwMV zk$kP7q)Yyg>M7=j6}zrV1;#h%RFkvu_dxR9ChR3~fbtS|%=_YpZ2Nlsyu8qKj<+@UQCz2Pa=1AVgej?JK$7<_b*J@&t=;%Ncfem}9Xg04?(^ z0Yl~@a;I!bJiO+_V3u?AmIuFDh3|-`ALn~(Pz9W!%mQa$x3j>bQPRhujI!Su9f-m= z0-LeAAl3|0lo@~l%wh(p_8qpx;07}O5MUYUX0z--1?{!v^kay0sWqcx7+QXZf*M9q zz9;}`&jc-RF%51_Ed3~sO_2TG^)0HjR=E#s zAu2fnk9Tbge`py9Kc0Tjp1t%f+8Sr%iQBT0_%ZGkZ#hf-UGk%n-GHSPT+t}@DAd>! z$AP#;xlkX~=~0WZ73n}wz$Q*RvQMUVU2$jUv3@_r41_u#~4I+$VYlGa18i|sTU{7LK)LhrAo-9`yM=QJc4@o36h&Ds8gQQ`sefRo{j1esiCTEPEDUH3jZlzxeIu$E~pwq?^b^DC*6d6$uaV+ce_4 zEfOd?I}_*)#u~vk)8(;FGl5lX#j3(M;-GPavdyF=!rRK;3dm&RUABk@vM(77)HIEg zHwCR{6t>@6OMVG$jSh1;rlN2Szk}9E0p`EK->H;Rnl?auY;X;pud0QoRAEec_ynWJ!PnAL}*#=aZjJUP9>j$BJV ziv}?(?ECk_nV{EEX$(MmB7%$M^Wxzna0;ou;UfaDP`Dia@f`d+LMOUztydlvu!wk*lKwEjb0&w zOHRv+B7&M+R^XfSw7sTyYq3TWh*x%b&6kS0Z|^~&))8r+;V1lvVgItm{I5O|nFa4P{XpX{pP#+B8DU7I)h-cK46;^X`%VA0{~QyylzIL+v-`*RgmG$sZU0!j`hc zTGc?$r_A{QUI@4-KajOR6IE6nXs!@RDAsi^3JWGwb;x1{y0pe&z)FIY>59S`dGM+@ zcX)CZ)khcaOV+7@_$_=nWkFw1ZY50O!1`QyvtKN;&7A?PmlidkT*>G%Rh#Ns z_DDWk^+3CTp5tMj5T;XcCg|MJQcRP+8{R`{Lf18 z2Qh?UV2Lj1t&Y>>CGT+&_sqibAf|W#?T)g@CwF2GhD_QBVlhrQ!^Jrq(w(#`pk`j>Pmzm@dF@?Tyo1>HL7nE$(<-nt^y`eW<>BP zFDbu5db6_*VISTb<>rn)VT&%d#*LJRmHxZrt40t;x3pfKZ1@s*QWaiSj#4f)Y-yx~ z814dds1dlW-+?=PihWdX3IXBqK#KrrdZ=`U8t+33Zvyj@3Z?BVO5;D-ViFU1NFBCu zKx!sfkcj0-WJsrd_|q37Ntbjy^`>1A=3Kj=l}dS%H1lIX6hJ#L)@VJ{h$p?J~RZoJBN6YaNL z?7$vuKK8_Uk@g$N5#XFgL&w^n+Wriv=nC0adUKpu^`icJvHYBlRDofrrDp{u)RM2X z`YA9WNxZ7;0QwXU2Nw8N1N=DMDkL#Qv^27-&ncr6pOQyqi(^rM1> zBKvH}1JHwybBhrd_>$wLT45CcWclzTzz1H|Gy)uS?UL+|ON zRW7Tdk&s)ZAKu#nP~kIj63h)l1}!b3Wi!7YnNc&INq%mS z+Og8c_+fyh0`~1i)H3X2l@-_0ix z)WdA5EZh>Un~HAp{^uci1c+4aO?u0B5JsO2i}bwLTK0PX!JOF&{>(3)i2#h|x3%lc zeU2A4BO|~PrDBpE3F)C)!#z%1(epY|HdkYYs~XAVF3oYzC-Mvc6xPZ#+-wIpkOr*n zI}XXq_2yZ`Y$?cm(#DTRERm%Xor~j@U`tA2yTNIQ=6I*Pu2ezY>D6LzNs?c~v!#-a z&4O#uW-T{>Cj0;}m6cS_BHB9t!DS*uUowKdsoVzry;FAbhN-1miL#x)ByU)}B~sch zxHQR6NTp(1=E*-FkTltAr*z;@!T>80Tx#fFp#%(6@_jk;v!rxO>&Dp0^_}B|+i^zb zAHR1Go0hivrav%wo}FSXE)PPjedV|Q?HS$qaP7aYPJNTx_cqhbfBe@V`tLn_65T(q z$fZj`|HmLI$o~QI02=^!p)CKQS&W?G|2=kgU*GQZ_@JP@IdDrm!RR&w(HQujw}ZvFOdf&u2th1esc|6u|%#=DaNjMnc3;O*A7-_TtGlpubLPvV!d$D`iFvI+Noe|Jxger%vjbLHZovi0^37>Q>0)Ae>_%&)c{dHhqIL@yN| zU7w4UJ^hoHly8a#22+I|@5vqi`xA8LlNnTUy1k|v{cQC^zn;DDx=qtECqExtNjzQ0 zvCP+wS*LZzb7i=hT^9sU2^1*cS40&6n)VeJ<(QA~*DL{ev(&-|AJm7C%^m=wu7Ac~ zgn97LOaPxP@0VJRozTWk2Q5AP_-AkP)>9sx9O8V_TI*51(_l`-L&d{Cc|&;`N$o#U z~Rklo^sqM4aaVZZycgrQ0Y4w)ov z!S8b4AMLi@*1OGkfcU#%Ke9Yt?St~~eI?PpaFQE9j`jN9)Ev19n0!tD<)%Br877&3 z0|5Jg99+g};KPq3lS*N}tqUvP-pGDN$Fr?+Dd-vf81C9o)NM?^ZaRVWEUQ$HSztmg z|199VCX}L;b}O9+QK5=r(X2o-Fw5}Ci9!Kx0BdM(92T&lY!?8 zE>rz(Ea@mXubtB!6D<)>1>6zJ;xAzz3*5!HZ!6rEqEWM+3+xps>IP7gD~Gf+>-&_X za5N}A?SgfldSbrERO6?9_{_O&PciZ2SwaQ;#&y$R}v$!F? z+B!L~IhEtvbsU^}3DHBEN}D4^Q2xaqpB@d+G0y*9dtCf97qE8(q(KDm3D*SoX2SoT zcVXdIIu35EV*Sm@DJc~A<8C2#CM+0mc7}a=-p4Vq@{jGuYZCr;@p!(zm~#OPF9`~( zv~!XdO27jwT4blX%WMAUni+wZ{Pq)nJg@)jgEF_V3fmmJ3<&4%T9Rj*;&&l>`)sH4 zfp6Tdkt{s-jxL*H`}mA6U{O0iRQ@u@i7^z{REt@sor2d*arUw@K92Tw zQIWf?qCs=1&odHla zK%+^fy*lYW&AF2N_WF;|Kv}QDD||kr7yJ38{29gex(658c{>~~1`c^A`&U>A@p*{H5JT;5jDwn>>9I=2HiA`(dP<%=mx3~Nqv=Fi2jTyPc}VX;%_@0LdO*9n#+cZ5%27hgFb3#fF`&5 z_=1-&-@28>?1JAA83y=WqngqyjP^fv*%nixUfyx933U%EiJuBmt1N0wm&kQ)-N?Ld zwJodrxUc=qX0dY^_Jinml}XRzs<`A`pFu^gF0MJ#q&HW9#J9%e!*yj(Isc8?gEpg5 zR+N>fjjuV&P_6xyPt1rDR6k0b@?g+#G<1A=o!>&QoGXk+ z$|h7M5muQ($}o4k&y zWO)4n0<*+Z9(V3C{d(8g)KtR}#xaSo5!lYH#d)p->^{7iDRsHsSuTv83=VWHa}AM5 zi<58@|FawracJYt`sG~>kkp$5V zLG(6^-b+jvAxbcMNFsWK5Te)U2}TP>jXJs@-*!Lu^L+1dyzl(Q%r<*(d++O7*IK{x zT+TAk^)J6G1un#XkSb|-?TJcvVfZ|lzLS9kg-t98KdqC(m#=#%0!t%m5=5mB@S?dE zy9TFV7=4)-6kB9P$v_-c$~vJp)z6Hh`$}%(d&H*{D_PgihILjA(NFRR41a%g`~jNX(jqZs#k~~oz^{=V z(3Ia7V3%&=x_2I76-`K?+Uz^=)@^{a9_PF!!qzl`Kq{KQL9KT=kuwBRpHL@@9TxM-vnA@hYf}nH{fZ@Y(dZrwh*r&BC zt-oFnCV7TYC|#eetY$%zNk(HK(1USZ5eom6JcTvCnlsZdVt_Nn7bpFFBCub;EK3>3@eLMg*U3*YYZEmZYi90Ryx+)uWh; z2In!=%BHouEGGhUfdrwEuoV@< z{6joFAl6n@Fwfnp>d--zbE+~)OxgBUMxF?)-Xm97Vje7Hdu=rFS+IcENv|fM;gtN4 zXLYo=QgD=U5aH7NTOHoCI4uNbbHHNy+dn3$3=A-+X}-ZDBqt92zWg$tnG9A*d`c*F zD_EgbE0kB>yOGVAjW$eH!;pEam@Ir(NYSTjIUPv;Tkh(kAMH(9s>(8245=KwUdZ9E zr}n+IgweNo&kG;7Iei>RY5dl*4Qn!z1t}~J&th}N+bT-Z?_f|m!ntw{=nJGPbYiu0 zGcy+V>>bSUY-Q{LpE4e6l&OYo$32&qkYcpKXa|q)PUfc^B6&__{39yfBk2#aM_lB4 z$X&+h(N37osJr6O*dqp>5SYl^IRiH1m|2}* z3)Tt(;@aRq1{0|@#*VYt9K~oOWmPIPuR4mCD2aLNJ6;0l{YF)0J!sXoFaq^u4Ar<( zg`rA#bKjLvI`mKT;+615Uz)d0=y`V@5z9*MDM)*Q)N##9iLR8H#_mAba(o(y3sh$x z(y`Xp4<}HU1V>4Ic#Ede8*G!L=Qh_l}fSjOoV(EuEcM(IwyU zP_55uzD2!=CAk-i#r}H6yi^v-D6NC4F7-GffksIln_8i>4$48{SinRDK4zcP-~d*; z(n{)%iUVU_CKHhQKZ_hzOO$)MEDp$VjI8Nmr#S^RWGj2FbeqcAR^GH085 zj-M^qF7-gPngpqp_tP3~lU`HaRckxng=Ti9X|T=*&sO6a~AHT;)GLBC~8H zXW)p|!dwX6M`dI}nd)qHBM&89`O$XK`OfD>N=J5^i`44^OQh^Y-U+auhQvX$RTMX9 z8E==3?rmfCshKO1UWt1&{sQX$0#fLNvReSVqm_5~q#r~bbT--}Mr|fzy}QlIt`S7L zVgs6%7g~eg1Ix$}hFjg!rJhZv|2Yx1fVx)w9cqRy1PQg|9k7 z3{dp}b0fr#>*w8;omT@8ZMH%l(5}RqB04fSvE_(JZA)X(*x(|%q115aQiE-Y2XV>h znXb9+venrL&J`Db>ny_6dqkqdymgqcuJzn>tTd#=vX3T>Fghg`4?m(CuT50~ypBgh znnp}R9jjMr^~AQiPV^U!6|=Jpp_DWOMYc{=h02wSJU3iUz>x+|exOfeD(4kM%w?<% zh=NVcZcSutWQAm1ZhC&h?{?5BRh|=m1C{FDFl~mn!=)e>w$+ zJ$)?10sd021oD0C>A?GjmCU4EozX$m1Y>4=qb@W#WxV#zS60JIh^D z;eC-~!XS+hSi2olF}Ss#(~QuWfSkw!)$M?=|ig!?ORcQJ`VzTh2P zaKwXyilo@*!^m?j%#B@I z@Y_29|ALAk3QT*bL9^(o_uqXr+*4Ar&`@qs)`VUOko>aP6RPpDzv&g5DLivz>1j<7 zf7tB8Ca;y9r7uz&o)ICgO9bl$rpS^uEMTL9w@6g%h!@WE}aaH>+tQtK-D`rnMUo=bv%#~X_ii%V0*#O z94@wUd61$9uLlQ!3=Z7I3{pc_o$DP$c$kM(!$`xe>pIu7G<+W#Y%bf@tPxXKO!C?)}$=AT|*ob zv{6Z!Kh6W9#oCwY&|5?NWEOgimDk8vA8bFBAX)`NS0Y@H%1V3m*WE1kORCNq<(HbX zugb1F68Ec3u@9IwJ?J~4Gv|H%m{0MTsbg%*M-|iMuhmiBU4Pp zFdwK8LnHh0S&WoGUTDj!t{?FNzPFq22nHQZ1<;A7>jOKlJ_gKM{O8CJWaun`ohXz# z*Qw;r`y|@RxjOziwP|r~@U~z_U*^T3tAL%(v{nw*>80SLyC~8_OU>d zaH$aZ_5M#(h^6^5t{%lRVsp2obtf9X%-6Qx~;w65b=T$}ZB8o=#;D zUM;HLcnYpV;_O1#Zfm7*84B`lc%o(!zDIk%C)39kpkp5|s-P}kZ6IdqpGL-3KQ+akxFPIfN4kPM$IiatwV;_lfZv-pn_^|PMuPZ)tD;FIZt)x=M zIM}1RdtrA}4S=B(@%HIEg z-%LTydYKc=@S3)9%te%&|E`xWHIK4|Sbuev1BcFxnW&vOA9Lu@m|c5)P3V({NJX+c z39oM7qq}n>6gETd??)>ieB(kSMvKxt(EIsLQkqsO4zkK2&yPr~Uzlkf)$i`;Gf^|qMB>NJyy*R5Ds?=cV7C0Sr&`VN&< z*bN1rJ~FGWJuFGGM5mob@q#+KUVE;SC^VaY$@(@D{P04J;&@fy2%C;<&np77?Zw zsNken{8LHyj!*+;wFSjA4vxCxtg^gba9v4tBrp5S{ zzTDs$=$lh-9V<9cZ_YJrkcjCL>kaq+@rzE@9yaLh64nKhSEkN8T|iM{n$ z@O{MwO}P?X#;iKCZ?~1`;r8v7D^qX3*Ja2~CyUYUs_UY7rH?y4s)iv&#!K?HTN1r& zl$jZP?`njgANF$k0|A{Y+QNS_GC2K&J2x2BP_TWg@Z-CH7m%@Qgl}j=stDX!wj6X? zND8OU6nFjmkg|sqniWiMtmMi|9KWzfyraxCR@LaD6nee%*_YHe?J5#+9Z_&_nGo9) z8T_Chbi76c*$w_QC6@GZ*sh+&W0!FYNI9P$APQLmQDT`KIw%Gc2OXBT47!sv49x}E$F?h!wW>bDCvRf_oT0QVqjq_+c z5lDmEl=XzTB*NxVleh*WXUKAvIsqm-B+wcAn;tjS(OZj2R8}Ix%xGVW z6NzmWsRbHg3rT1Px_7DDJSO5Mvx!(&GKoSv<0v`gV z--mkuvYMW?B|SF9WM7dsD&MB*b<0xO-fKur-%s^dq)B+JzXSsV8GdJ}B!ChN*cij> zS;**E=MeX`WRi5zD)i|aW|v}ybrBuO4ZX=W=PtTi1M)!#i!Z2dxYb-wxnsf zOS`7ia}R0}9_iGgYGCFp*4mfS&FWpPKK;GGQZAm#z;eKKk4B)xu=ydOfZ!+}+xe&l zI)lGN)7#h6NOCsDzIHr~={y+on zUAGdQ?;|#>mE#0H?s(}{x{J^qk7Y(m9T&0I7hh|sf87iiFE(^G*`?Xl-s){Ef#`5I z{;lEE?-2|AF0#BwTdSnU@So>1pdo z($m|U4>i74!70V6RQnhPC!-a)Sw0#<;>VI9(TT+|cW!q>9)wHuBBkX`()0cA9TKg) zKD$(ImrzfXJEhnuRC?I>h@39~i{FPJA|WHXiml_I;pJAi`yv)c`nGh)fQLymY(kw& znn7C5ajaowpsSZ+C_^&oG51S0v<(-|IluY1kRRRFSvDj)ck-nui9j}o2mg0{0#;l= z_XC+b)HY|Co#6C65>kbmTY9yzcR7xAcBYGN2PR;Dtxbiq-VyW)l!10uMF@KNKXh7( zN+yyzxXDz>UEqwDl5x}eon)%SC@%O&fimC`gHOICkZCXp3)`0VT+Y zRVPF!gi&d6QFav$L5_Zm%#}AkJln*Z4=r|+<9?J?*4Reu60yDoGxlhJHAj~F}=3R?&k zZ@-!@-2SZ{1AdUUeopOg4yJbfrh3I8E(8u;p4hoc{onewkE4o5_jh!xGa`Tsfun6v z)7TZ~-4TU=t+g)Mp$xU6VLuy6ZL&D+?W~Iw0vGIbvmb3hEyC8k##NkcU{Q}64H-S( zK{lAsi8UI3Hgg{^8EN{}^CX#VpBYDA7lF!^R6~hV)~Uuz^w4DpXwSXXLJ{}o8rROO zhlOkj#ivwPx(ockW2m2lb(V2_W>dY;ZbKCjaahRdVZWz;wS(ubsAtFEtU0m8az5c^kq$7I-?|U7n)3YhE%_p*>-TYhT zSJ*0}at`hqJ{SF5Qpuo15?0l+x^TCi#X~ZD%Rkv-8dhe~zow2~lAcVGsg|f(ObmCaB@~Bx z%%a4VS;3PCtC-rAl=Xm2>}#N?e2cMm+K%W&yM=X3iOi^s}i ziL45%_OBc`9H@Ju9)`~+OibS~!s6ROmsbjP+pq>Cju=xYU5{Q!%z^E40zK&03jpMQQrIdR(Zd6GzoC31S=#Kn1c-$Kw_?NVSsgbl?qKKOc#T zihuJ13?YXBDfN8;L6`A(J}}#EVWUC1z)vuc|Dqf7dq?K+G3jTdK=r0AUSh$^QCABf zLLMk$CkK3(yuDo&y9__k!0oG6A8G#(Go2rERpdYW=$@)ywho!R2v%Kg#N_jvZa-1cR77V04qiqohF@1|mkl?mDUuG= z^ZChEZIkVWlM0ij(~&6mJu^wAk8I}=)2uAMN#E(0heHv_ zl`d9r;bZze5Utz0@LWYXAzw>VKPd{@mzr;$U_a%M1_?#`TYyI_S7K$n6{tSO>r{%{ z)08C%m2h1f3uJyI-F+nE`1!mjX_m86esj8Y)X&>B2bYN`al%;so^X!4e8;lavWrZC zK0ER}MlzAUth5N;9ffLo>zS_mZWS);Dg0hHAIUUPWAU8iqMKl||Yd!WUm~ z8ehKuzMOL^Er}55tuTx6+-(&B(n3RZ^TSogmmN7|F>01N9Or!#Alk5Z>)p28o8zQy zqFV>lwBym+J!yFUzlfh|lN9UDkSHy8X+Gw!RgO51%?$R`rCP%Y%TBQi=#+ZBkFd{t z!D9M7Q~m93y*sI08A4q!i8!;Cwuf9P%BRcS7m+`}fh6l;E+ewEl!|}Ei^UJD_83;b z?uj6L&)cP~lA}_@F36nyE3*IKo)#(DI+nfovUWfuSI?RBa^o!dMMQql*AdD8=>_3oXl|<$`3UW?K(wAA zUd6Z@TxR_b%t+FmNlfGEr33L83jg=TMg3p!MP`dGJfgk(-&g7KKbxiiYMBt_=(eP# zfA)H_zA`&q>QuaRphxDIa4g!YU;S~98 zdH=PS_rgS_@x*iDMKApKojxMKj{CnDQKvC(IwQOmG4$V0y=21N0Q#sa>E!?4<^Zam zom%#JF>Ln#*s31bs{Z(=#s3ZffRyMQHBf*MFZ}-mm;QP0d?Z}%zogL3cEFka@9T^4 zy#OTae}BRi0UU2%G62s_?51|A0!#52Ku%w`MM&@&A0R9;F>VqHvnt36j^N zls_{1&-rlSj|{(m{9$16`s6c4;-r`S=1ieUcxj>Yy22SF7pG|l`6(GSPz~9CcFzm$ zaU2;gj3&~FzQ}aMnM`^9K zos{x@i+`_AF%qY}#Q)g~F2)4_4PL3_A7{$eJ?lfbnEdA)({D?Z8B)j_0Vesgbp9bD z00zA@U33eMe*WPjrVb|`@btJjc_=3ie3^K$vU%sJ2PV-eNT-eO#%12i&G_GcPcKMQ zo!t;KnECgiT@LBLhx+fOy!1+!hA+dz=KZJo)#6KSNW5i8P9%ZRJe#{4&5-jn0V!KSQ z0R_1r8NF~i;6ZK_cG|qiwKH&+HV!hjA*ou~Q^qQSEKBfhca>6!yuyMyzMRP1&0-&DRdZv60pN{*tvUbcZO zV@_;_IlV!s;ucGop4N;Eb26Ih25s_QncPSr$qr%V03s{hqq}xs9)EofdPKFKvj>sZm;A(xC15DGf2fb{A0JLTD zAcp-B*H!%rKo+oUH3PYEQ|F=$uSb3W7}2r&9i@PYqnpzG8y4D$hZk~b=h?K3jl*it zNjd!-a+tG>XguntD|ff}{OaO(OFL=pJ7&k))6GW}PsKHDRom+9QSd;Iv6Ssx%fxT} zri~6VT6*Vh9n={Q0$HJXI~e^Ptn1x{u~; zBLDgh@g!hAT>{w7+tqP6nm*wLVq^HUNAr#Yfc$~=NpERKS(Z~Y-(SxQKmoo>+|zSj zofOy)Hdi_ZGE4a8HTJPBfCC%tD~R#u@V|c+v1>V=aXurtvL@DnOR+|uflF+F{^ZI- z#2WaE(Ep{%T>!KBieQxBE;;yV;pu)tzXJUGX#g51P^Mb6MUhh)PjQC{_CnHafxfOo z-t`qQX93DJ+N~cd`LARI2lMD)<+|MpUA!85M31=;nE|AuQSoSb}{U5PDj$ubJ zu6Ij51_^!G+Uc-d@g<0Hv0T<4ajR$cep0(0Z7MT%Wi-t&gT7W3( zcI;N1ucv3_eu=oS+;Z$tG$50$NLS-b0;k>H~TWAvZ+b^I%n^R-^+~`Ge zMckjx^X{PQDWR`g>RF%uEef1e?=12u9RTije#OQV0bKZUQziZj&XAlp%8wbal5W%0 z9goz39veMHEAEoSm}LM;;3pR%E(81}mqEVWy(iUW)Hw2wVq7{^Ase=H=&=~P_~a0% z&+YhL2cBWWfHbc(B6qx)8+uSJ%7YUHRmQzJ50c_!Ckw;;F=atvKC|;%O^^ZsS)#SwPd=P14 z80Wd3aYFIsA6=OR9fv4z8XFEI*r}=AZ9u$PBij4QR5_yb2cgHTB$XbiB&s)K9lBbI z1+KVQ4SDM! zR{ghRB)COfe;6N=X}x>SPigI|L1Bt> z6ShyC`b`WVL#6Wv8xx1FQ>4%YE4`lC=DijnL&%BqMiR+PAlOrRW^ouDB?k*Xel41@ zktS`uC!7LJ&?H7l_IE{H3D8C$G8d_M z?>B(9Wk8cn7+KP$uf|d5=)ViGSn}A?nlOfo?f?1#n|6)tk$|VW-p`m=& z=~>b{E7%NI{j6O)3mrP|Xa>w_H9m3jVsO*z5w~cit}aS(^RTAgZR|4m1R`U0N44Sx zZ45z$j3=76j5zG(M%gU)yJEXY#=rc~_gP~si;v}#vSJMr6*MrfpL*X9@z1afY(MwG zP{-@W&w5a_VL!KSYBV(t$NHFm)h)G)z7T)jCF(NO@F_QFpx>wc{L^X)jUjPTXx}J& z9mOd<9~eE^KQ6PjQQXmNfn;g+a^#5!`tcRB>?QbnKtLGe0&4{>;mXm3>UGI{;nhdG z)OieA!{=wVQ_PC>)O{C0iQ1!u;M2TcO42z>@15WedA7b8;2pe?YLZINYgrgdU~Zs_ zKfO-t9$YJNt!(B0;7I{rEu|M1pAkq3e=}KOtbkeM7x)_mx52;tMFkGn$q!7Np4d%11~ikic~v__SAu^2j)r+#H+6mOws zJ~Jk}Qg2cxd&TVHW&X8V%MQ`ye`{I|YcRMx@$CNld>&0Ue+PE`^mnimNXzjW%p66b z`j;(uXe@Hy*pS%%<<^WZrvMFfwVX2rX@UOq8t&`liB#P1Gwn6fNKk4v>17LWV~@mm z&wl*em&n7+w$&c!3coszg$9K4K(D-IB!;pOe6O&BQ1{+>8g%>{zPj5Ags zKwAZ^#k>I0ydwc&+v}XS_v3Cnchf>*t2&TnKyA7oFxOvwDZN0v3App!(&_;8NVk)> z4;H9^sbHElDU4LdGU3*PVwZ`x;sB~_8&3ri$4M-(H+ieaC&!T>)U0yD-1M0c;A(cN z-O)M)+#54KxlYmD*ZO;Xg{NX)Q13FqjZ~x^FQn{}2PkPZ$b%Kw4*LG&1Zh}b-aHHL zwy+9*rm)rB0lgrAawo^!wtsNW9<=S2s_0$=cnKr9AEX6z@{$$d5vyv3415BndO%tc z4mfOK0jL*$Hq$0d7Fhvs!-CT;Z&rF!GK&H4;9z-AV3tq?iju_5y5HYC^S+>^%5#}f z702sMxj4R(5gdja#t>=qhmq5zZzC+nsv~oKf0{Fj1q!4SK+crcmCfQP81KNoys-($ zlN`|MY7{H(UW;XnVMN^x5ZL;UV)bYo7ykM!t7Ko$(YTN!#?Oa4Eqsu-%#b{EV1j z(4VkN;|5|yu6lw4c8dIzyNqt09#h<|ZBZgL)~Fw!-E*E4qNw6|*un+VX_ZR02L?ql z)ydXkt#UY1WH`19j6O%2+o&K}gQ|U1W?!-~Ehs>VDhnWNwCQClEQJ*H5Q1i(2}dmr zBi|h~)!qr^&gy#v^Z48CZ`Hm><4Gd;x5ukI^Q)nLrcX>0n7oCX>pe0Ig%~q_q%}B7 z$9^#e5p&fbQm&&yVeAAY+CiTee0+Jy3cgwgEuACj939=}$Cjj;&WhwBALXY} zw*f;q^*}=SR!QQbfD*e+&*-Lko(+7ny8`sA52=zL+i+g-w+!s5HT>Arni{sfk#Z=m zs{2QRyL@Vganpf(q7~^0TXGKm9vv3c`dh*$NMmiGKS9tA$xY1f4=K$2nruHSAFH9lmc7l>Km9>gywvdp0m}%iraGq~sXKoBCG&|-e+8uxO11X_e?83MU&l4j_lhVSrJq?g&aDI=?u)gb2QzaBqhYs1zK-lO>s;U`(ePEO~jlVR%<-5K8 zqQctb`!Km3r+7zKN8{|_NUUUH@b@1;#mURJxxoic7Z1rFq?;7{X1*`|W$ihmY=|?v zGIKw4Dn7P(jY7huf3w&1DFf+BU$RRC&(5?HnDwbGne7o z)x~b@Nt*E!M1r77a)D&EJbaCyGO7i+V`F^T0afEhU`5IGqwu6l6F7oPK1h%4c z=1WF}&D-i+pGfEYerMV%?*ZzS(f+*tdmgW;>niBfv@>}GQ<3+H6`A{?vXNtY?qQ?A z12p1(pKM8Xjp(llL+sDU6WddynA#sZ-9Kr&6%`bV!#z*hJw}KMhY%85J;o}@k7`|| zxj3J7F-iD5*pP-1^Odc&Q_EkR)d;6Jz(c6rHtBmP&+8=MPQA08fh%9%k8#EkJskGd z)RMU>>NU~MlyaH9;C`1qBN}(``^*>UoQF48NBa_TfQYx41I&HIy?%Wwns~%F`%*oY z!*DyJy1*&Y0DJ>x?me%c$XD6c)ODuZrtXBuz%UD@2ROMdJSP=4d+e#Yd)3#J0@VN%%k*5%3PHVRA} zXI$>5n24G~Jnv}8SR??bZ9Gtj>a79H@@O|hwl9u0X|@8-mf{Bir^P{K!c<|aFEK%O zy~#}Hb!2f6K$uf#HRHn12QNxSnrsJ> zT=!-*7*CCnoprkAj6kIAOm#Xt3n{dw6!>@Eiy2|XGrp2=m&|`5yxpeSD4!LUX?Cma ztm6=@Pxp;k7P{m?zuvVJ$ktnXRv{aM%i=vlyV5szbvn z5WYtk?Ptu7uQ+9k;IUHkYg(e~-?ws{c^cQkyXJis#L_+@$w?qr)*+ncE;xteNw|HFa2zK+%YSb{K~hFJyq_x*U!nKs^o1+Hn#%0P zE4NkxA{8XJ=BA8Bz@)Jzff8Q)X>~bSvkX!x;VuB7)g;AHG&|@#pBCaUoaMgt%7442 zH|}C|IK&GVw`?^c_h80noKw-g_})wLf_Om}#h8^c@^pD_!+MIYl=`!JxzKj@0^myF zY<;u6vBc)@(qHy+BiB(wO+WrsPHi*sXFvM16E`i7NYVD&*nQT!1TN{9^uDZ8g7-8X zyX=7YysBs3$JfFoi<(<;?OXD#-j!C%R!Ko4^ZL49EnlxbE+vHsdhz`spr52{zD-4% zY-9B%m6&d9y0-3HC3Q1tdiFd!F+Ll)vXYnb--@{jy#Dv$=3fP`i|yJ!I654Bx6ii{ zb?2-I+I*2IA$SKKhFY;^3~v1p3W_I1 z^4v?F7a!2cPV6*RPCiP7eO~|aY{whMpwzX*%W*GFu|&T=UQTqOk4;=BbmpL`e3&3o zD^00c665|m;_7^cc@c=lRKpKd2$P@r+_|lkU%DR3Gnbxppbk$Q8Rn69OwaZv7+aFz zgC^A1*y)WK9tpAa+RkBB0HjS;2BZEaB$?$Ei7ckIU{|Qti6=A!CbecQIM?p5eKdt+&xN)ZEMXcRMO^)-<8eO?#Xu!B#Xv77yAt!e6&8+!+wvmJ zn`$!r@yRW`G@4WFhAlL)ZJH^p?a9S(j3y)a9`Y;D{*T~xXIY;KMtf0x8A`o+d$nk!v~2Q((8G; zpzKuaHUQc*Y0>X#2IEOt2GD+%|6yvdWS#20GpjSbF;Ko^3STO)&i1m`{> zx;(Rm8a=-(#c@1T51c|+=6YS$03kDd9H-s)T6O6z9NdWf`MV2?c07sQQoZD0qiwT1 zzwyMSzNtAk9Et->x&8MyKUQlIEj1r{hbhS172ki;6xT=*oSp&Oz~tGjw+HN|4o+rC zNfzQ(Bk{fNV8?a!;KNlc1GuRXB{M;<2yLc{DcDoD8%L!#^1mna9rUs?!Q#%&@b*4Y zX9g@zf2?yzJ1G$X(@#eFOtfy-k7X*!xG!$skt#DlP}rW#8FWPBU$FDka#0Wo zR{W+CD)KSdo877OLnY`WfIEZBl&9cX+v`!m$#wl{n-+@Q@ z;cy|DnJO$kdz8!X803Xc^&4lmhXNjT_QtcHM>Lm0xna3xUT?Rh2!VbQLx-E5t#_tY zm*P8mnfua2>6SyRl35UCs1S~AlrsYxsIhFqDw23hI!u0a-16fY{gUh&89`}UuGktO1~GP+^Ds_$-}nz3p7mk zx@@pBvfc&GUYH)Aav$F(O=w(Jwa0@)Dk9+hG)ZBetbK2@;g{krd3Pje{MlzdW}Bgb zk>tA$l&1lkdKCFj%9I`%o=>aWn_=VrEH*Hg7Ba+T% zO4*}W7PodbS)f??{fhZu!m!YUP>bW(mIz^Wf5($pN>jZ*Iz_*rScxsDz*okjpW4_@ zO6i~3JJezUsQAeJUZG@>!x!&-6K=92!^ck!Urza^8YCk}2w(2IyZKPmZL}NkWmVk2 zuK;_-&LsH+sP%PHB1oGbl;y#mj{VVBizDaTvemjHZxte`+Qu7S{TtUj;!-)`j7fJg z?E>qlfGyBNl3&}3G(-6%S-T7YKdoLmEsOrNo|VJJbc!Vb*j<9h!gid|Kf~NpV3SG)daOqzHjEDJ?DaU!ej&f? zO+Y&FP?Ms27?Qd9O#}Ge{O7@R8NR?@Na42WIwo8CRhYpDGE|g!{)s2N`XF2 z1pe&VEifw?$A3z=ylHRguk3$I8us+r4?HczmU~kIbg=xJ#$oJHd21uKAimriLw(zE zmd2UMR<~7(IXo9u2~(-ssTdXi5E|L`E02BFVDYtd0E-O&K-pMt%GG7C|E&hr61&51 zEK`FSkAG{QKRhsT{D8QGo`GMbUvT!XrZ*4rLyAhL~5ow8p4C(aIDZ@a#N`k+T`)bhogM5Gp}HW{f#)zULp^fet^!mTj&iarKPli7oDu%74P?QmL|=Uaci4NwQv<#!-eaJsT{pKJQ*S$Nup1ea&YY z_N{024K5t28~P~TV#PUd+qBESmt_`Ma8V$ZUTs4TjI=gcUW2G8TN$!QKM2}Fo}9?t zl<(+)@*U2?rc+w9|8wS^r$Imm2U4DQ|A=H?Bu6O;b>*+Ob0?cJ1CIufkxTv_`RWx= zD!!>nH{F!Ml(yFgbDR{JsQKL7vTrO~l7;>$lLDKZEtL~v-a&r-r=S`EIbg*Uj1U4| z7XPcf4!!{@emQA8HwD#|UeZ1qHXY#R4d`Ioh*AExTFi1b8+A!SteD&&wnzE+$v=N> z!F(3G4YXCs*sc1?&lWx{e<}3uA#ve_Z@+0X4%ls4cQbA_xN*N)n&xPC7+JqKXL9{d z^;?JNy6by}M()2Q?pYUBSc!t>$)IKcnv=$a%qXLptw zktt;ouJYeXy|L84WqMlM4<9>h_5x&>bLcKVawJ`y%o0-Sc^)H5%^4hQy{`rehK_)^3*?7j6M+s?R@{cD?SISt)A-X47(VraR!(Ds z66WNWKz&<&&!KOkp>`hjKSV(4{s029^J$%xi`xh&lds@JqSgB+C}#&x7`>w)H$q!+ z-!;8#IsfDlZY)*-1L;oIy zmm99zZEQL^61W>2@rct~Pai3x8qxrbngJoj-Ft^?-_vI5oc_x>NZ|l(Lcrk!;13|n ztI1X$3@q_V@WT1!zGPDK^i2RgY#rL82$r~E{}K)93O9$Jm&#Ls&(CcPguZUKB7v5I z@4QYE1M)Qx3}D?1K@$AuCiY_;6g8r11C^3yHGYMHRxP584T2LiDAL(Uvj&I5wXa@F zs^<01#8rZ*gX3IDY2H}7 zgJpH`fNRyJ^KL$@&!Rb)g(>-O_JRcF#I$VSl7QeuD#XOzJmb`4ZzMgrN}uAo+c*#b zn2!))-;e@Pt`$&B9?FxKzN8>&U6TmEzAP}D$s{aku31H!30i%5lp$gxT=(odDTwa+ znjvVbGZ^0D1$cvbC8MxEw786!@UU;mG4kHaUHf2Kzno&0KImMdx6cjQu$~{zI*?im zq;4oRSG%~uhLOs&YDECE5jV=hMSMGKZo^)l_%XmXMK=jfKB=^1B%XZxZGd*rVHwd~ zYdRr@{d~dcF#AD+VB3G5p{e!vB;tWkst916K4)oG6OtVw7XI#$yZFnB##)=q|dy<+x;HryJ%96ZEOsK5cUgc87zqxSia z_a*wm8%5VQR#7+Yo?x@?(lah)c^E*|P5$5oi7aiE3{u!3hJ^KYq>`iQPg`=;_=wsN1U{N+3O9VM?{ z%1ytb$Q(}R13>3{fCJ1pVEW_rBosPZS7IwT>N#Z-9vWEgv2}U#fY-o{pJCo@Ed+;kBohGg1>kgn7@r)-Sf=(kHgU{HnCV zqVD0(u*Y6jue+^Kr8VNsmFoF83a~?Z;moV2$!QHD->J;o_&26Pt*D&l--xWf;d$F{ z?9LO@_*>!%SkU|yv=W*caO)Tk0loyeyY-l0$>y1(F^d!?DOq&<)^F0zwjsYsF--o_ ztml*dA1Q`uP_#a;j_x6%y(k}=1}q{;(l!C%?kkvBmK$JML4g4TSFczVg8I%5Rvd@2 z#IV3MiBXqvhzPU#>|vFa)r3A8!|?;WL@3zxmqiQN;Fwf#w`o!Hwy@CZvWn+r%4K#X zr9s%AK2H@KM@7l}s6GLDu17#`QNF7`ryzNy8&&)P&=Nn<4K%$)BhkLYwMY^W=eSd$?24j8|eDj2yKk?UuxjnKQ{f~h|Q&~RV(%$KVCWK zSPXfcn)-ur>0E~}*@i#-y|l))gj;Gzv&W|v*}&A?;L}I4g;)2Qj+QpXT~4qFD#xVr zZX2E7na>9KfW~b!o;iYhlxEn>2>3n63~A$&A-K2m{xLA(K-z0dlxfu47OlLv87A5p^%N3;rfGiBUZ&_HB0U{h8B{WDJa zLQc8f8eVmW>L_N-#=~KGwP|ywJlejLpDT$xC?wF;fG2(Frbykpw|t<%WSR5QeA$(y z@fD#RL}D684sb+@nP^Ev8yIAVPobWa$;Zs?m z)7XTE=@dV%>opyq$rPZFb=1>wxp)cETf-~=_NZTJ>+wxe8^Sgm30#~qoCRR z2%i#@ds;a9HRx+&av}ccT_@^A5}C*O6!Ui9LUzE4B);YHVnJ8a$Wp=q19}%PSm|*$ z^~GjJPC^Thhk0B*uG@DJlPv!sTrTi*?_lc2;Pt6mnrKUgQGR)n7ktrfu|Ayc zGN(Na&OblhPpWa5(#=&0C;*msC|j*mcL_uF7@6f?VA88X3E>XH1p)%$B{4rx(%6HA zU_IRO=hJ7vjsN*Mtr0k8d34ah&>*~?4d*)ZwK@wFWB-uTY~vIeaPMLOJ+pxocvH=X zv~FueUDMF@cIFc#4km@bXgE2wA8`zaD*P-q<{f1g52a0G`wR$-Ldnm-u|BMOT^l=cEt_@V@qKNb7@bH@1?xG{mCJEv%=^g z@lIR6QK=6p~y%@M#f7qHa z@x5GxTjQA>I$2br4Rue%&$$LWeu9%5>H`S|9_drt6lQ9Ybobpl`Hz-nruC=xN@MQGN;eV5p!~KGxEOnhlFY!Q2 zNHC^Be^~^tTT}n!eWRiR_k-{=rCiZ8#$(Z*;Vgl)gaPSiOIUpgOmOB0J9y!NWLO-%<2ZBR52aY}=^Nw6cejD|? zn1NV&d5vV4cj?tCUU?~UmM1%r-@5Sh)Upa7(ym>d+K8A=!-poCjr%CfLd+|Oc0ncf z&#x~mC$vId*|cp0)}Y&TV$G8SYU#};L*8ChHrali0B9IwG2~zZ`oy*6w1zeCa9(vF zU3PEO_#d~Or2r5pd1+qFS&>k$7&a3+7x>R6BBN+Uz;p~)rE6^1Xf)P(!^+Q_?Gwrx zFq$ClIQZ?|NStQDLLsmTn&uY5NReQs_QY*lAE0bUdWQFsc+B+wh6M&hxJn$nsvU^` zB|4Cn@_9`6&GD0-vo9ZXn!1<4xiOIZRQm1@^vIaF4^CJ1-4Dr$FZio#hh3M#-2%BB2_)onr!?EEs*!^62PmU zlA)gJsWKgkN56QS3M;atuy4!yiJH?hUaAv1y9N*B{P{dffGYQp3*&CWa6T*|}3>xlVz?GuB&H0>_N<*g0XDQ{u zWodbLY^vcI;q=UVPKd(#Mi2mceU54Yp8>rXr_8}Vl7Ey#Q(@2=1S9~4enDNsE*e|}ycLF_zRaE2__XYcysrX$4FNIng z-Tf%)mm01+ky$E<_at4L<25p@0`W_~d0my9TMgx0M3tPV@wPB>X@trkG`#>`?{h%G z2_FXOAZPX4T`cXT95%qui@)P3C zG^V~0n%ku~JvG44hxJ_Kv>_$Cbo(Z^0U&jiumTR4xCaIT*bCetDxLe=Fm55lLeBJ6 z^oCDH_3Gc4-McB>$`84$$}B|hNO0}q9Qy2!V+?KwrXIkW!8?xx8Z4ymFN;{Pw85KR zq+)0NKMD0s+d2gC2)2Y02MFpl^rt1c=JNmj6~s+il_65QYs$3yu8;H%xJUO*%FINi zn;TUE&0XK`vhUbSt@v~2>YMVMH~OL)6>Y*xdV1Zor`{jZ&`3Me>WyVkWM+Lm7eF5j}v#98Wk`SPrDwV^z!*V zJi5&|mE@+_86eSaQS`9M_+$%8VzqA@B(QcUH7na95fMkguA%AHi>zo8MG6mO;FF;N zkt;9U?&gdm)ViNjJE`kyQ&>xrUTW26&>4jB$oPmx zd2(Kh`a-jL=k$2)oEjPB8_#YRlFdB4^vv(Ah`W#X>ul!PmugVP_^aA%@133cQ!oE|xObO=i< zy^Go1J@YRtu>gr0za+$QReT+=ue<#a(;X+&(O*|gL>faxmHt;-FR1R6bjDk{PvH|> z&F}7>@|O1FGCBRK(iuvRYjZ?6;>?-b&Llhvoqsxh!upMP%FgebaSrt53LI*GGxHwk zLDOrHTZpSS+|1S3!hq z;(@CvL&+NaK+!hyTKNM|F)wDt-UG)$t@3Wiu zv?ne{kt=@w%&hr{C8OER1bG^etXH_I5?hHa!yf0Eq zDDW{^^*2X?g#Su3{n+d)Yfcz&a7}-%S})O7>uC`sE!vRyYuX;G;4fGy!6hR-5|Gwk zYxZ?wL9x&K-jf!$&ac54(d0^(3|a3PS$AHv9t&fmo`r`-ZTBZ$Q!4nj@>f>>gL`_= z_D;p6YhIrR*NFS=`nfE<;j}jq5IPRYa=Z$$>Gv1N(JNF)M2-bhTe*7Gi5M-K78tbT zDPT=Gv3%R5ag&BhJh~8MJR9o_=j#y>GTKaKm!frRmyhxt{IL`jc`i|(*Mn8CHkTr{ zm_5x&{}7XnWOE}eRE|=`oigcjz49ncV1C!ex(GNk9|r-d7GU;B;AMF9Ux}JXraqzC zPNCG#dGw#3UfBQJSL#6;sOqvrufO;NVfQ9H$ov01$l|~+5nv_p09B1_SplL6!h7?4 ze*b>VlkuGYx-R3RfY>WPvGsq%c6a`ty`o(Rh2KB;C~*Iv;hgro-&X*uEfLgnmIRqtc;h##GaO^FS>+R`%eDJZ zJwjAH=0VHR{cw>Y!p*(2l-jGBBffC&F9{g9kb>dN8gM91bE%oQDO3`)9c_gc>t^K! z07jsxXJxr7@Mz7mpP<;G#$cnkW8)dE{3{I1E0E&DTIWY&EmDs81btep;=U=q2Oh{p zu+6PWRT%ODZo@%?-Qo`YtoVbLa|^o%zc8=F=Kvy$Q$F8O=A=2Q_1*j9v7F&>*(h=Y z{EenYFck?G6G*+AB_q~A<3;U4o$&9~ow$kuL5bz7(=KC|?4k#n4kjg>R^0C01A{c1 z_v7FGdJ7Jzyft(pE=(T~Zskd}RNgyQ;=sl;ispeNMoNMoomQw@WcNOcI>B zdoKMRU9Ym|ssRGjR$&}CVrH8$;>4H0Wtp+Mi2TL6F6W<%b=cP>V_IuIIFWQ z^jd#NK)KMe4!Jy}?Bzj_JDn3u*qj8E;=#Bg^RinqNpF&Z`@mS4m9o%#8ilQITh#hG zNZHUu$N0-=6M@-eeq%de4Uh8KUbt2Ed*$#au*jwmCLd;&aeGJT^ z``k{ZdCJ;x+yx3%&@Ua)$L_#ZT^xbKJdUQahpk#+5pmyR>4rnMjHEMp7h_N|sswxb z2@m^dC|oyoqiJQM{2PYz2MFHo^ypq^YvYm}$67o#zy12Nfkp7-b;Y%5AN4!MfIp`4 zz9c~W4e_W*t_wu)yYjE1g<_?&0Fi(Mk>1ZxfAtyfqq}M0JbPLz<359_;IuPU_!FxO zXvq}S_(Jc^S?l@pKC3hF4kCgYQ3056YeqjWWyN!2L2`U5urH6apgkd|^_KD?*~z`) zne^Hhj{cU>%=?c9+qwda$vdVPdaY*G6c!+%DOWXBsCAh#sR6pv_mVyjJ^*S|IKvf& z9<19bc!)$$^W%?-^s{k+3Kti?$*Woi#yd}zlHf{Yu+!_3j!?a~ zl4Mfgen4-s_Hf4md+$1fhP*)-K%o54#|26HuJj zGU}juS5aW{1DG>wuB)^1EYV5?)cz$1GBFGXR^VBtLNmETeUYl~`P*~PPaN<+Tm$K& z63GjiwBB5|en2yod$wB?!lzc?Gq}xtVF>~HgHXk_g|2;$^Fx^7%wR6i!?o^*(I`RW z2+sd$!f*j%1bI+5e@K(}6l`DF^I#J_!r4G-(aTUUd|61mK>=6(JyRL}u%^zEdOS#Z z!gcPc(dQ>r#eO|J^Q)HC0iPmB`1k9~-l4*fEauLVS%UMcWZl%t_}xAR*#o;9RJD2z zb5Ds2G6v6|A+kG%xtyf;|AR0geplQhV8NGoRvp9bj!s^>xH2SFi@ z1kIq(?vQHRxQ@yOfQjCH2AAHeWtN-Z$v!@W0Iue0G7Wc+0_nOpv{!(GvCzYlTGu(H z@j~Pby|bxL8YbFDH^+2P-3Ch50m3<+LyBBV!D1|Tj2vI>H#Te9(Ku2d*3RV)dFv`P zzAZ+En+3D3wv9f5%4$IoaHqpfNH7UC5vJRFD(p8|H*c_S`n#XddQcj+$IkE!|C*6g z`k;CgU)%*!@W90-ewsB5I`e@ODD6jl4wzv)^`;ziZZvy+jvHEl$sBgEhfZN6r zYBe{KFSIKyhb!oZ?AhNPlom88`Jda~o2Fn-BYGA)!U>M=$eiZ(12=TBd@o(~nQ*lg zelwU`Li%g+dMoc{@`=2GkT_g13LV>P*tx1pX#)veKV`T61~Bh- zlPtFFmRDorKpa|Uq%XCKR?g%ESyC%vej9xFp!XIT4qc;WSJ2j%+a{iHNy{!oRQ_!% zO5$gXHex79UW^Z;NdyVC+C>c;$rcjwfBbfSthZI9f>G5C^OITHKmA><=|)30nFDD@FTu-Mo1;OvJ}MzGZ^moti$-_DXik0<#sX|d z<&I-VxD7fE)yEYB{uKC*W}zPX0;D8BL%TQGiYnWVoyUjH35ur%q<8i`pmSD0+ORu`2JJf_<7jRB&v}G-MiyRiFx^-win4r}6?`{#1eg?kvW=DGJxv`u^@4 z7wyahXDM_{aFcVZ+8 zyuQ4hXB?4#-lE9u-QfHfri2E`3*daF{l@OUQKNCV-TTO$cy3`@sBh>5E;4+GGGn+^oM_)4gVV+rODB`nYBO{Gi&Sg5!juDwD_JTsEr&L-Rdvny zgIGy9-N@G}IZ*!2bx?e``>zw+#$;;j!%5_#?P5n0ZobE?C17(5tz!)r@+ltA8V|7* z7ghS{g>&2-%uaZ-XL@KIdJ96;cGv}<0Pg5--3s7yNg?H`)Z<@%!-xchN@R7l9?c{~ zX)-Q0=H5%B5d?xHM$-9o?!ZYRz@2mm%|(z}&&MfqAVP`NZh=B<&Q0jeGeD6~+_W0% z`nuCm3QSpS55TD!*?2Jdtn8M9$K3fEJczu({=^Zf2WE5X56c>Hx?3;oVr8&=ILk30 zAL1yj5<3E=W%#aW%L(px?TtI({;PssZzVar*m_7&5w}PM5DTyy&OVVbl55_RsyiQC zqbS_Nh!=Q84rtwF#e3;`!K_k(mLDmbQf2A8R`}bS(3(t$7f$!kcjNl8yDYK?30CNO z8ko;2qsMH%avFv2S=ytmqaYILubUH!xSjZ}K(mKp2pem%4CdQU3s^mWUu3}^g3R5~ zJeN!<)M?E*b$35#DMUn{M2mU3eFLiBE9{?OYzPh0MoV{uI*6npE%ZCsu;wJV*7vm3 zPCQgP+G;Nk3ul>H8~H%e)*4H_=63fL8;6&@cBJ^$8Ev$6)DVz#30hQkUa?yO+FhCk zjfW--eev{@Cn)FE3JVhxT)OOw2+u#B543arO$|`NpUo<@OskCaaZ~P*>-HT*g|t#zL{gJPzoCcAaAIhN9@V)S9^Ov1 zQ0&!K@IoJUo_rE4OKwMbu;mC-PBi%e2sHG~uO36+WM0Gqd$3GJl+cF6JnfZPQEPXq zwemKm<+K2X@^})B9{Ps20$;VY$~JEUJJiN#q(0-KiOjEqmWj~xGGd&j6mF%C!zz}W zT7zu3GY%4Ct~B<8uIVuD*A>zG`hr;P?VPJGZ3FrAg%Df;+GNpzy%ZI8q@>dHlIw;> zI1L3akPrB%VqkBZ{3vBHC0Uk{|AuSqRD!g|-IqWatsg~dW)sN~sxF_zIN#{1#i~sq zfA6G;FPKFE9QmBWAmBEePq088f16_&8YO#L^b&=6rSy(X_6+tm`Jzz~Vk9E?U|%~^ zOns77!v5}1(04>*gQoBI?$IPR*ktcNoj_j-PO;_zBzCG$W&9#+{oz)>aRgDU(0GM5 z(8Pb>!e&kT!F_&L91c|PbhM|JZB{VZN4{oUbfRQ{OH#J@gA{5w*n%7p_`)>1uH7}9 z-Tq+E?hvd!G@9)bTg{vZE8`!}F$>hG*VGe=n78xVSE3*4MMlbr>g+s^PvnhVtbY2^ z7%Erxgd*&Cvq7|yjU)DkA-k|(^wRa80~Bn;hM|Y$?V1z#YSW!>KeoAMC7#YUnthaS zAa0~lvyi>AgKnoG;nMtCWeAjX_C_^_!B^ifOFU%%!H}wnS=(rkhQbRvACOO6vz4a8 z`G6@k1D$d2cX!pmo}!tmM~yzG-zDIYM^Cd^3t`|q+d!P{(@+@AGTJag({63}97G*t zE|Bmpk{OYV=W)#}py@aBfad-5UOl^uI`qY=OyD)R^`Cxa1XY{dJE)Selr=Xur-iuOBo4nzL(DYDPVmvRh zN(dK#3H1cM^lrS!X4G1Rj^K2AV?J?@!LY7^mrYc+yLtd`Z?m!n+u%h0i;BlZm^EOo zAv_w$iv;^fA1A9kB>4xa&bmUyhz8=Nw*b$$*s^xqjACyeoi0+@E+(g*302k*_7B8k zUV0CLyV~5Js`69ubMM8-&HWitZkg1yHKUq~ud2*GR_3c0mOh)5#G=YqiQ{Q#W7qAY z`C?b*l~>;pwS}cGs$<99B&pP@&jXK1P;Cj)v-0DAtj;Oj@rA$#bdzGny?fny<<&tn z^g58P+otxPak6RCXsGvf%j?n7&ED~q^9!bTO>>^_y0bF#RWbJlT(I)10ef$+-+iIS zfTD11Shlgegp|$av8kPU{9vu~1Xq=6Hiak}J!L*&v+(nMHrFJQn;(1CAQB)9^0ev@ z=vn{497iCc8uLmnUfJa`;{6-5j*(f6j#AYfKwCnxDSwfF{w2hiJbA zE>N9f5@478X0K@+-a_&Oj?+_%sqH><#cE9)q>hJc(zt)Gjt+AZtw;(J?mihGg0f8p zOTCZPRS`mjGI5P+dLR09zvg}gc?nc`0$;Xh2Sq7x?!cGea68hr=R{8+_77cGx5DbP zYe(!h6@c~?SvGWvbx@|*VN^rxW%JIuj?j2Pce#~suKDTV(e#(dmcpnS&q+dxa`(`@ zHa$trI~{4q+DSC};{y{T{TQlZ4Y$e>bS!f>1-_h24N*)Jp#GKh;=d;bs?a9Bh?UQm z_YY~{r!10y6(FY8Je$du3lCR{J_AjeZZzl@?ZP@Q$T1WM-IeXy*W54v;_YN1yM4G= z=)U-@9mW8j%{Gwb)E~>%eyjyX|7wSt2VkRxXe@@&%+hQ=P(jI@jph3tlqad@G=_PO z=t=h$n!UxSPnbe>=tvmMHyzvwE#g)lIs2ahrK#KItgb%J1E8?f{JZTNw}n!$qEX;C z4^D)&U#4o4H*HMw{KL;1`LzOFk4cPPn$&vJCc66N`B(nrSKjZQ{K&dCY1KQqz$y-YcF)YC-8ZwV8w&(jTF{&KaOv#`gD_Ug|G!OjIdg3 zrr!aXwe{#E_9^v4VktR>DpnmoP$P%s{k5GH7ctye-1EC#J%a=^_}aJTK;MlWR`&L7YZT{=&a`U zY#8shY(xYaC-4qO6!42Jx3gfV^4^`SLi4s8o_9P;{=ttVLZ{3u+06bFWfxZ(pI=B9 z)ku*F&q}y#1?#xUh-iyA7%2}iK(#yW%wO!%|B%RwoO#|w>b?r|+B%$%t{^q5UDvCx z$e;cC8SQR-M4|}e#hb7&X=m-L`J+6;rwX+DcCLLtCj~`{lh#O>FFZI}I%j`z%&L zRou4;|3o{;CY4(Bow}}2$Ty44;XCTA3m&^PYHfb7?SA?jQQleOoq1V8?~%Ae#ZNpemJDO z+G#|tibP&}vNT?zxg1t6^PyY*elnwnj-u(ecv6Zhu_TF+gj(PpF%CIcM0+8&t>X9P z#?M4O)-fM{Kj9_CbGS#fsY=wYl>%tnFI}Slp^~tIj2LUX<=kF9u@`ZxbnW0 z&OXXO_wWkajf{Q$CW>wv>0J(|;Z$1f<_`3R(#uP%t@-B@GkrX?dJv{{du8+3TWQxdvDn3N)q6fLGUYY5PWIt&VU6g6XtyMG;_zF;BQgbHu?j;@ zO5~mxRm)=&!9#QSp{@LIOk8s(0^6{uq=_()QWS~QcX6ViGFA(>9Qj-`pu{QcjHYL4 z<4gN`Z8BoAbTal6FPjU^kM@e~cT`SO;7Jq^I>d*wuP!L_+!bi-0K&NL_w(Bgvh@pM z=eG{xMV|{w35_))$BBgfr4 zPRZ3?PYb#-t(;7lsIdK?6BPjk#BdAI%VmoevgZVYzW@78NrVyRSYDsHJN5Gab`M`acI1?u5ChI9Ssib3VT7)njc!D@9opzvGs%v0KoEi;7ybw*0 zH`mUgImIUM5g=U@GAlMTD;d%wQriA6yS_A^6^!#1vc?#e6~UvII5%xi=zY->P8 zO>977$}#c$V%-9WK4S5z14+==dn+EdhN^h-DerN)-W(<1<5HpDRHb_2q(X?rC-id^ zWXFxzC$A-4=MaXuvycSNm#4_;`qX*n0Rr zPGibR#yVaYa=n|ghltY!0<;_4>e=Z9|GDh{9n~%Y5T4W*Ng1-L@?0jTi~34~jDXPo z#E|NtoE4}lfccOk%O(jYc65t6KJi^TQ~5}nNDTQVtQugv@mx{S8sbv$QLQ{;4s zm%yow%PtD~#cKq2%melq9O{Vm;BQq+e>YYAj1lMc?@X0n`QM!ibmE}~TRE}UydL_* zMRLDjy&p!orB90q=~S|Nm7PxTez_|W&k&VD4m*T!mnI4ji+A*=2AZk@z~NZEQM9w4 zp}~-rWtqz>e!MWGWDmH$tUmK=lt{N&|^ZEgOIhy7XaI)QF0p zK>5G~0Z0Fz^&NDp&3=dCM!W_8^27i8y|APr;X5*u=mz~q|Ghg8{yRvo5t={ck3ANf z`}%Jva&j5rz<4<@Q~1Zy??yXNs8Ri2r-c+^vLRT8&0n8Q_IJmKeeU<{DlnUd{-0ZZ z@gSH@&v+-a_q#%WS}}`s&zz@XUtqRT1MCevE^M*FASwEPPxJ-&5R-TIXI&g*8~am? zPM55WK6kHp>{hm8g5@pKo_6PO9b@aCap?z^58Aaly%bVA7!P$Nxqdy4i?6Kz{jcQSR~Jb>x0=hzl@J*;Bq3Y~^lE_bWmtix?{F$p#GsFaFIj&&Jz6pPeC#N@`P0w? zZA*lCCvr*w8J*eGt~UPEr{s6Fg{ZT1*gBH^%Gs@@^;+-v8E?U;_O=}WMA~(}zUJYQ zuayy)_Rhijsr86a5bKA)&wWMSGJy~#c%btDs0^yaflym5jc_3Lb?J6;!sBBUz0$Z@ zW}&wm;u0PziraM*dqq@Qv2&6tzXh5vdLQR^tUj9!s7ALoY6p{>*w5>gaoCo*=2pGKi^rRcZKfRyq<))w zY=&x9F1epL*%qASsJm&x38uhlZ-A#T;S>dQH3%Y9X8k5i%8~On^lo?ue|!;p{?aaE zL=Y^CGDL2*RSC6O|I$8phQjNOQ8{L9IdiIqddihCYFJ->0}4D#^yv^b7kvRxq8rCP zV-MhMF#5D(R`jhJEekR$Z(4ZW*PakLX6dH~!ncKAEPqd}ahW7m(`x^bApy$)Dn1~| z&aEP)W@V~5xT&AT_apN*g}qM7&^#a2Kf&D2G5@Yt{JhZ_<`r8JP;tuZ-~JlMFZbzy z4RM{DS5aDn+W!U@{P%XN$6$Ma{oHjbkHD@+JtNcgF933wlN9~u5#OH37ePj=d$8xv z$3*V!|M^@-PB923jOG!P%vWM}vI7D89SdeMI&#Y&^9hq1@|O{hvi*m3a4IYPsK6OH ze7UzP!7s1iYt_nvcE;m)c%|iz{~CLFT0MvYsS{K?^}!Yg}ura@G5vR@HS;4i&4qw zqLYpFloYq2uk+yixamKad4dUSt-wMW*Iww~V_XB7E_!%dc5C;K$ClZO!`NGoWp!7b z^_<1mXyYH0Fl9wkYOJ^lwQto{KHVdUg{sZs+l7+}yxP^a`l(N0+0bLG@tz;T-`m-> z)N|F%d>lXT$QBLvdL>gsdhzR@Pl92`jWJg%_;@z@<=6Q@&PNKcvJs#He$gvr&+aLU z3Yk26a)Uf*CdPR^NBD7%!|Zgu$AtYJ2F#}^T?nb;TyFj#Z@Ej;NuHI3;-3Z0!u{`l z6^&ihuJv~DG6_M{Vgt2p$9jtPW6v1hZ&T<0ROUYijBjth+LGP*E+UfOZg~BlbvmC73WBlA(gQZ^ z)15ki8D&;szt-z&H~)GM^~7SCP$v`<8?~ZGEIpP3%6jlkHzUe6es0{>p;lZ`EAAa? zRP;^?_&k;tmUCT%R8dKr`p-$;J^4l-T)}TNYmj%(pHG^;35)3Gp}(g%LTG8pdWbmI|x(>ORoh>AshZi3FwheWi2WD zifQOyZ$9)`m8Em>zRVJC>MjwWd^vFi^SOGiw@%ioZ+yb)A5!AX!C01v$TcGY21IWu zZ*9=SeuP(W)~TnJ?D52z$JW}<_G1J8*Zy-7{b@w5nTL&R%f9`oI*+48wxKt+`=!ceP#v9C=OaK`HD z?l~9BV2Wvv*?o~%?+!7|k2RZt8O`xN_dee|X7w5LzSW=vTG3D(7hL^=P)eMV)hZC> zTs(@k;1e_{6KtFs7Psx9lm$cmB@oR{c?L#;Ccp`{#Z9B}h7r);!*=`YS15{&0vaEU zybSSgIy0aDX1O`=pifjJ=LYYzQp2~wB^d9V9ox)8VYr9ERE7uUOC{#xekGjzt2H(xjpD(C}=hkb%D!1 z!@yqd<8G(Mskd-{&lqF5Me;O{n>oLv-ek@R!UcW%!4` z?BTQb>e>x6w)OT|E%x?&K`Yx-Fn1WLd0*FO7J#<*z2*WAwo2)P9O4gh-b%Y#IvO?t zCfeI(w`}JZd-t4x5PjBt;^0FDuI%#%^dGQhc^6v}bFCC~^jicE`st&Sauoe~L661@ zC>^O_98uL#aCzaO~AI1nZdN6)6YrKcbAV+ zm?e*z$0h7F)b>e`u*1wwc$WJCtL#pWY=&QK)~r)(R`%M~V(A2)BBSEtZ(BaR-R|m; z2XO006NE~otk!G_K5nlj!>a!R$+BRa0!};cW=k?jYu+O)13^I0s{Hud1pxc$*QNF8 zqT74MKQR8c$tz8YBJI$2c=T)Pc6TFwLOf%HzjDNV@C$T7jnkz*Lh%PibR0)^^!$h-h;EC~#H zT_h25n~ghamJloL>2yyIvgqfNA&Xfls!VwS-Ct4#Zr{`n>t5+={o>HO`4^sQQYMmU z^)p+jXhs$$;^S6&Qm{|VtfY8O%^9!*sD3>J@(h~Zks$H|P~&`n3Ihs{to{pXNN$27 zP~J^pOnZgtSzuA%jE8M_Rb3G0A}wq0xAeQhHPTwz=YandAIT9|XRwGW?f|wEhCStl zfcgtLvH8Az860Ez$;k?w3f}lVU(m=>2a$&z6J2@i*97hSjja;}UHE~3~CzysM1L>)D1QiRz3FL1Ezwrko2_3}~+|O)Y-2A3W z;{KnXPN9+IOzdJd8ro?md@q3YtvXZSjD5P4%R^H)@E{6e-^EL(OF9`r%~!vSqYN*f zX`cg&enu}2E5J5nGu^0x!F13~Bw*wAQO<2Up?aOEb)M9Mz& z(3djN)Kl|;`0BqcDKn+HB5?o4yS_oq0?0I^f+7&Oc>vZL!&7o%E;8%tf~bmHURYB= zbbM?$<2V4QXf7&}Ox(L{4N1Daz;Z~0_Y}=k;6k@9cofz=Tm$a`%*ZgdfHQ)+oZ~{& zfN9<%$fC!|;dY+Yn$-_dMf>-niyY*K)(K+8_D~MUjkQYo9~Bx%zfivm@}<5shEJAh zaW<#l(xKDrE`@qbxy_l?dEf{I4DK2YoF_2m1Ao8|={lj4dO^d?+T0kq^?T#z=LfSS ztf=~)k(C$CsYDM4l5;H-48QJKi3CWz-z~aqjDa(o{kd&ZxXXkx3iRu_G4bbZF>Yvl z+G---QV0q_{n7IH$~GJP;bNTVQwoM=z^oKLin_cRQSqYV1TyqENZz+U zTm~dC^6rn&_XJ|`_Y4VMp~R=7AL*2aLvm!WY6X*T_j%YUe7$<=K)cXmJ*0m`uqZNA zrV9j`FkL{J2x9~6j%*7c667oaf@)m9{3g=V?8I2AjZYmYu+^FfoSWuG?HvEo9M9wZ zb(Ucy)4OiHY&vvThC>eXLatjI**u!JK~&&-brpq^GkFEZNn7i^YY%!PFdXA_5Tl@Y zG>=kw7xd7<=2Z{Dz}*eS+>sVXTT*^Ui}hJ+I{!)gEDq69i6m_j%y(|MuH&7 zSIv1rYncRy2Y`{K4I=U0U9V$pksOpv(yJ8+Fem!g7&_Ozi+LDy&~7wa`Iq(_u!D1e z-`rf~G9^WOqw9u~#N|WI5Z^6J9$SjM6IO}Bv!g}iosfU;y8u06Ax%H9XMs^}`PG{Q za6o@|_3dzYLEf^3FY`A~1sN2ROcPlcr)fs3K1<;z=<`RWZjzhr0}pyO|LCQ*SSj&f zHSGT`m76YqemcU)5XAcWc&mpuml8w5mAAtdz4*DT`60n)=eL6)MTReMZVb(3yXnPw zn35CDsR0fF^m}?v7cW;+x4(TStKWcafe<04b7*cf)RFDQcd7k7OfSxSK6^ z`_SxLLN@`RJQ)Z2uO>cvie@5e8I@W8ogcLQBJ>nqiu>Iw8#=DWKa?}W!2b0D`l*Uh zDu$+u%zYJpn&}wN&jTlD*Q%b4iPTm2{SF~5086-)Ml5t|btjljc~Zxl&Pn>{wb&C9 zoZhj({CiPOLs|x;`$a>w@esL%C~kr(yEV3Y4;aSZtey3J2I(FUGmdpKx{QvEbw|4G zf^*Un3WEefWIGJ|$aRn^U`z~TSa#74l7Sn-Z{Tl}8M#(a|9Mgch!6{^okWWOa3>(# zNKImzio*wsiBXBX41)1u>@vP5kB!f+Yx&{a-ivgSMN|Fx&@GUzl3`F?g1qK^nZsIt zDLr0fRF_*Q_%P*O9JKx(JH8@;*DK4*SzMU5Xyr&atrk|2to%sMtmf;}*OYH@DRt`%6rSOV-Ff zeD^HK&*37wCdz9*Jf*?!-0xua{(kAghH9vMD`#B;;pdr~w>M2RG1ZL@9f;u-h)BlH zSaAlmy43i?CvDz2S-c}NKY#vIRGit{e{lbY61>F!x?Z*^zA8|)g42>0A~T)J$?mGf z#$^52^4C@eUst-At*4y6gxojnO9!v)7nLf`spnrGcj&tNSG09SUE++g31Uobeb~r; z%clFLMI(EqLd3#@ShEPtXoj_cpzt$&pM?tUM%paMCxue;8s}C3_TLs_g0^4ePG=mT zx^y*PI);JnVN8NB89Zi-X-gxx;;hss_LjJP0L>G*Kn|pUdKN5Q50W#EO#J5XO|q|h zCtO8;+&%-aP>b^6F?Q8zj_)23`R=V({9o4a=6*2ofxrCyK31aGri z-$>TGhzMlXgJ_E0*t)?mm9c&?2XYt5`>c-BbZf1AJ9*coQfrK`KOyPH9l!b`G9fB)j_A20ZW#Pcr#eQQ_mT2T7O6n5JfIQl@}bDW&5 zUjED8*jyg^J@Rsi&lNXQW**7yha;cv3sQ-HF|Ymg@~VOp-a0vPNP}C~DGG1iPQMu!BhH+l z_1ft$KDZmnr9j6=wO!jbbYVg${Xk$b+v9y2&p$WIg)Ikip>c>Mh3eV14udGV(W~)G zI*02YXCrG#*elW58;71TPG36lCAUyl+9_CS`~F^=YTM~*Cr@!_vt5crFwt=-6)trq zj66EOPse8|gRp%P=v>p9`A98+`*~W5f>O0zw>3LQYS@mM`@Dlm@_26B(RhVFn96#p zeyGc`pQ(P9Hml@XzMUBti&f=-sm9jtX(9W!#|8bG}fnTbW$hKJ;r{%zv8$C}JQ&QNj)pdXSqg!U+VaezV=7V-eT}|d4Gi%$W zai8(Fb+O(K{MC_i8YaOd1ux|1!}8WewQrAeiw~#HE5SWry=61{Ys!tuN4EZhXKq1IWlqhty#OMotX2+OWol_v72arbn%alNY$P2Ud$*Ri2dXwgT~3c23oFRm9hJ`N;*5_sIZ;dtY-Hyh%< z{e<$#Ooaavi!i+)v(}}}H^FT;y`2-gBdH(t-_*knw6|X1(_%z943q}7T;&LM+qz8T zd&p8^TJgR#3+L1_bRLPPbsKk%-eFdJoZK4BYl586hz>|B=@h>ux?gLvlr(n9q)s+j ziW}bep}eh+@4^UbK?&fzeUr;{6XTfY9Z_^&;Z$YzT7{`&;-QSk-^!hxExZ4ckY0U^ zc{Qe$8aehrjX^chP|~sz@&G%a$$Xky(upc(WvvUIIu+DpmHqU4EzH-_@s=R5W(4UU zLxzS@NO#caxf+0mB+qUtJ>T`(>Nw>$LlvA2ya+Y))8hUzH`8%^vE_kQq)+xzJO83Q zREFts=MJzd8W3G%+Obrvs3vNWe;#?jve>`{5rZ$QI=&Lk$#j~)Kt$yMh6#n@MdRn@iKDoBHL!$v^5yEY)L zAZ)rrKtj6Nv~+_?*G57>Kw7$M(;d>?-3@2?Jn#3N>pj2DKe%A8*lVtP&N;@o#~A!^ zEwXCg6*hK!HH0nz6ko}cHte%yu-KOsz5tbvV#}N~7z3Ft9(mCmdB$|<309BhI_0a+ zh~D=v(Pv(s>9!Ah;}ASi;~Pg$v)N^S(qZE1l;xC65|S@tx6N6ZO&Vp$Ao&%Gc;BAGdKz#_(G`t?K;X3X!9w(WFs82>0t%` z^7brf!+bsD$YoWijk-R1jogSL${!v84}aAj!9KlpWiMJmaYoxXrf&`|GZ9U~o~*?J zNkv={EqX!IJr?{loaJCOV3b2# z!+eMZwf4vZXVhfF*d?atnX5Mz>00+#q&~^X;(l`8Up}yH4tlZ2<}(_jfy2Ap%=JPU z48f?+PDCnIz3VRv3nq%Bq1?z(uLvA@UoHM&48XQWZ!|uYm3*_R7zQCiqX~ho@xYo- zWi93{wQ*OmIDK` zU!<>B;>7JjKTCb)Ox-#*>CW%sxb#f|)#v(pkc^R|ol3LeHw z>Tq88_4GPE{f)VFueP~qvVKIr&}`hO@gJQ2_YRRuHnB?rSN)a{$O*zw{^}9l3_e}+ zH!?6OdgH_UmKRq}%lHKb1T$ZtO(yCQJ|==R6s45eS9*;CJlt^e!p5yILpFbg@;^g1 zd&kny4?#hScz;5}R2XHI|A1*8Kfko6FUy4bO_BH zVJUG`!PzYRS1a5uFDxq53Z|Qea|K_j|5O@M7?g*8gybuQA=RIsDdUZX_aIyts(2Ll z$vYnok_GO~6q0?FX7pPK53rf;qoRilDS>+sBj;sc-n^$s8-eiZ_^y zCNpTFXd0ZgrLvg_5qlLB$TsCqh-nL4R?^p|Vyv{!zkDiQ3B_d!(7!kL1KYh|-&=#5 zhuX;5W9bgW;R<*#gg(4me)k$Ld|!_L8ARxdh@Sbzd%qE8?9GH_{?650Q@vndK;(ds z1s`-wsv>e8%Sv(5s&FNXB?5?91F)_#KTDs~ONVi8mZyNGsXIHVp#GmcR!l)rhn$o( z#-GuWD#t!a7ZrD@T&~7ebY7rw55!j6<@MamqliteS?uL|>Bnw-)G=g84E|!a&=^Z> z)BfWELs;gL)}P_)+t(FTbnM`bftYzDbZVn%w4NmkqSFf)>DIkwrjc3R=w`hEoVLc4 z+8KsstH7#6Q!N8sWt4f5-$FA1fv(=MN11z7zvg#-RrQ)zu-l04($NI}jiDb_c{okl zTY8sKqM7CwFlm~vJ-+d^$MLk}6cO>C*P;R$%dWwvY=VJ}L?Z0q$osx-7jGV0f0?ZT z%{^fy@n@m!U9K=RyMNBd2Q{Ih<#*)C7W1nnVOsU#epGtnL3|=?iNzgG?N5J~*c$it zHQr1t9uSWsyO5q^`;IXQ{l&oSTm?M$Me~Z zrQmx|I^{U7$y!dAumQ+OsGIHFcjFFZhk;Cp)|+4BEx*thz2W^pwiU0m4u@&5+x8dg zKlQGWk2X#FrTjGlpH`*!=j#w-Vs4%|Uq#psACZH@rQaF+&n3Krnjj`W-j$m6|JE|v z9$xeofzp5pnDpPegJPqiltp&X?CtG?ex{)s$?DYDQBnp+D3mhi=`)DAl(kz82#B4@ zq$(uUcgmF4vX57Ai}=j)ri<iR+bK)q{T}jiRxwS#;=|i)N0K^5nuJHu_f%eUXqb z1e@b!(|HGubb)~_FN_Dp3zw$3`#RV@{tO8+C;9|k4?k9}RhIA>C*iYt&27VMSVKk7z~s| z!f2&-XEzAn1m~GGvnwQSf9-t%`<91~0rR!`jY!y?{svA*JZd+JRIYu`P>2^mO{Uekxw*+Qn5!o9E!6mxy)@W< zGmvkeDJI-5^=8Gpd6TrYI&_49Y8lVTVQN#tfBqF>~F^}>e)~( z;OVPj3+(4t@9eCEyV=feJ8@wp-4vOz4l`+KsTXQX*gNkfvI#gXT54!&rj*1m8HLIh^}>&iP4kw!aNKSv?e0W5ZC?^c=(vT_ z8X&bIgVDbyDZMh=jM`z`S`X4>)7wQ9gC4&!*jcEtFZJb60?=sXW_=+5`qUF(E7s0x z41tmIm|K2uV%C#wQRwdKLi(xtm<>b*stf|;eemwkr1EchGasq+qA3o&JWRlqw6H~5 zGQL%9%*Etym8kG5|A9n>Np|!KKN9#38s_rS4s0u}s%y^M6*1?J%u;TB1}|4T@N?wv zu8!aUc;+HgrQVB|%;^iB`lT1@yfw5#jwKN>xJ)8yrQ8B5sUlN+Dlu$|0Nf&W!jx}a zK8-eLaTxe-SjfVlaVBvhc5#IB(c}W#jD$7#goMA&`g5l?s-3q6eP*1J#NOsXpL z`8|3+AaND`HXpRYf&g-lR>0!-;&MD+ArQ#k+`0IZ9y|9gjh-)&d8FP+<`zt+fdP!u z>?PVo6d9ldox?wl4_;R5L<9FA`6Wh{)HCThEwInie4}&Y;_Tc3B=qu)IJ^p9gU6Vz zhv8}i9vA^sM)B+#svNYhfgPx?DxbCb^iA3D__wY|SFsm`b_NZv1O>G_;ttPTE{kLA z9KGIG+RUh?3ppcG3Rg{YJhEyHF_mQEKULN(0CfIHxhcwnOVWPjn?uai-u*0(j`6mT~g@sRlYoAEM^bm%Qcw3wzxS3*qj1t z-D;bxoHu|m0U*gW<#RaSAC>Y~f9>gV6q2Vnh{##Sp%RYQHJarkQe`_%HZ)ndvg{uy z=(t)tG}p0~3MvFsL%DCkiYZ`HKI@4Q+6Ng~*~v6+)I!coHX-U0|M1!}&eS+r`XT~MF!w5jC*PHd-tByB@GOQ( zE^X@9g;VNC`{*$O!u`dYmo_iqZB!(`S0f$j76HWqZ>_p!YkLGs&YLLC6P_G7+qvq| zJ?=t2??0TBSv2R+pNRc|b43;qgPk8jvy1hv)+>8^ITF!xH0ikQfRk%>3r@@;5UDI? zGt-FXY(6ZTI`PwmRO^@S&#UMJ%fu$@Bz9r+&7B>8N|9<)+Lnohh6^z?FrDas-lc!m zLAPraOwfqHEcXlRWv1pE!`F`%8*vYb+PE84D%8IX?TS0h(ueaL)9st~UFmB%*``fF zGa6<|9l6e=Ta~A2%FXw~u5|-F9l}f3=3?Fwr8f_1_DUSp_W#d0ouilqQnlgqZKW%j^`2R&wq4WW-YMsO$xhehr@z;E z?ghZ0z##L}566I11tL<&3$|sc--w$hpq$A&kefK-Rs4OqZbko@le5K3Izt(Ry{5$B zXd7%q3|#-u)nGyKBD?Hu|NFoQ5R>wZ8;xU^K>-}>3H!@K{BrH|iTmX?sSOmrp2oIF zV4mEL1(vj|)jTceu$Tsv_9xIXB^yy>T&n#d`s5Mrebc5F2Awe5KiB!chdZ@;WjBxF zeH7NUn!CCDh0`bSv5Ec-uvG#|0@c6p67c>+E{XrWNSd#O0Q}N*l=-)AeC^@? z7Xn6tb*^3wmj>p4`GOM^9K7>{#+LujKWq;Jl?6bl{yhwEZG!jLKmjiEy0Ux797p?s z|M&IG76;x>;0|?w!}~s^V(e*CK3_kY&9|8o`9NYGQYW?a*dJm)Nk zw`ao9te8jwmK2UkmplZ=(&au5& zfIfR6Di2N3PAB1C4(BAm!TAixllJmFrbg*H(&1_KnVJ7NZ0~=r5DD^vI(Dv{EFJaT zg`2({C6asw_D!4U>2o3jwDC6@T7w*Q16YVJuiGKN&b(5Ok;K$BpLMvVpojxc<)M<& z0sD{3vDSdzZ@RV(6Gsz4-%3&bQJy?}r~9n_|9Y}YtWfl*=S2DuZw7yX$kHukQ|g(a z^=H?l)whcwXNlH~4eeMl&IT)j!-Pfba=T*6Xd73|JiC={S6u2vWzT6986Gv4ylUDratFs5%F2dXSX*;CH z>PB@7zEqg5SQAeQ?4tRtJFn3h9h{PV5C#PrTJXV0qA&7TwZoqtj`43X$wLQGAf_E+ zT2*_C*y4}rctzDz?Spcyzw$Rxzm|i5L_R$MrPV* z^q}~=BvUWeK1nE1|A{A`#Gc^L3{)Lpg@ymzvh>MkV!_TXQO;r2&-3wzvb3mgNc6Pi zSLaPfEG3s_AqJICGeWh&V2`3^$n(Pe5>VUQB&J9^ZsObd`J=FxYSY=&Yx%UXrpEf{ z5fY&=M91@r7G#3kV;QP*a<1po?Vxs%T~hi1H;IQ$+fl8-1`-!JsTpd(jR+)6l!l!l z5yzh~T6cu=UZ<9(MCeuQLMxYA*~1?X)`co9``9`2x}oc!ZCCOt%g~+3>22G?$4N?2 z$EM|C7J0?T;ov=72;UpZy7fq# zy3^%tIzN{Kaf)Dtc!}C~w$m&xf+Lb-$EyuEjbkuQ2^fppc8_He#PShe)*Hz6@ZifT zWrVI%`G&ED4!`1^3i738$W~fQtYsQyILTc8Qidw}rt^sJPW)l!nBZm-8`|iGc)U;g z-rclwwPgW%i;0aK`(~YZ378Ka`DbK-4dz5PIdhcmXA?!?S4l{)zdOkf6GVVmNNT#o z0G~IB&w5t9LoL8VFNJW3Y%*iCUZbeiWB%o|L8Un#5L*F6T&bG&#rOWHvCmw5TtZTr zA8JEH;j~`_e;iKaYvVQH%FsTpnmYpRc3M|xnFWf>+P4&zqTKn=eBl9sh3e9~!dpX8 zp%_pT=UP~xT#oKRh;S1h7&n4_Axa{VqORO#@A-SZMlz&`#F0;6S`fA0%Bptr!886t z@!(>iGsai-p_Ur-!(oi;9O@K$vFTlTf%zv(9L=5C7a}-66YD~yX}u1;wSTX@YM(q0 z>viV+?5G1@4CDp>RLt>-eI%jRhaqe*(?TBa9Uow*d@(m?pTayc&bIpR=D=$+`YQtwK#cWX zg@E1sTP-mxsId1n&PztR=sKht^$v9%uHVLjlyJFnUj?r$q&2~r^FMVU6{7nxy=Us zoAOIdw!#&9)V`yZ$ceUnFCYK1>bI2R6kT7itxryvZcQzo{+-dZ7?w=}-r0*Y-j}+(pj&T5aVK5LU z&{BCL#;B#G^{|*P&I&9z*nl-vJZeS8b6SEw>wW3Z>zqGEroqjjQSFVr#c!MAwGhl@ zDt(*kZ<~m{J!?$5oIVc4t7u81K|)_rPK?sG$3^zz>DM{^g=Zd-B?S#~9jN1(br6Cv z2q*T)IMs3;j72lwz@4~6&pvn}7?x+tC^u?zVFe+dJ3M5|pzpc7@9;J3cC#$$0H=g} ziasUa&?KOXAeIA#&O4q#DUxG$>J;;~ydB4!fLcG8=WgnYB|G>FR#5+lj?N(%46cNH z@5)oS^(@nBQ{yiZgSk zAM*cTTd&Uluv}{5V4n|@9#vKHOjSglG3p~j=vrMeZ69yzkUJmr1X?MNY!C?SPZ1#5 zuNnLqRA_q4X&^6U6sYZ+UiKK&UMnEV#1Qf%cn9r}ASp;9&9i_;`GL4(w~q7SUO|E;l*@7-Tb* z7CZxH)8@b0AHF+tSntD+x!c`qn>_Yn{JkD!S0d+7Sb0gq9xUp!N4$Z@-Doc^^}9aW zrD|(>uZCCIG1HCZSzjU#HgXIs>N|Y%Q6+NfU}A7fUZbF}E#x7SpRx8`0>9|XjH?kG zmo@))SH>nFfP@9mfFTaaK}>Psv;nSCoxzh9}ws5ZpZW8hsT8gAf@G{ z%Jo5$oEyfQ{h2 zlxod$3#9l@i>MGFQA>V9-m^0s01H}sf3kAtLGoEj8r%=sC4Tz?sUI$xKVBZp(eAnt zr1vGZ0WkFiR-{8bmy~Cdk8B*OW7PW$RkLIvQ)KQU?-GNC2moZ;sk*1}yx0%Nv?4EN zbfzNlSQT@46IrOioRc~WGTuGi=&!fYw*bPRgz?}`Xo7T#4D{epn`U?Zbu?tqdEoe1 z<*iw59RVk9ZXbt8sPCPR!|vvqyJt(>@4<%**j}Cs@OHF*!)kC`&*ng&N?o={U`Xr4 zg}yX8jt->ekxnU-`z2z3p}C-bWU_3K!H^?Oewi6y(W#aJl-b2#a+UfU*tG4LcizTZ z&$*cToo1Ev%le16S81uGr}K{Y0d~li&*plqC4_%LT#8|0R1SLiO?K~0 zO})RRgiM|3+*rt*xcXAQauB*B#C4l0HOgQ9n1zhN?`nEhw=bn8^S!&|zrW4M>(Q$% zfbl;I8e9W_`zv{^0%Z`LLgHINBQr_BqiX!(8AcFwJ1R@sC)NCR;3=LD2IXu5od?Ii zr4lMD`kpg~U{OZUN0aB+rcKqy;)=T;PT;Dj)Nom?qw*FQQAvejcK6`Yo{Qv6F@0DQ z;g7<-Os48@^8nyRxg$eSSES@Kp(B~h{9sfJ3>l8!jX+advWP`Yj8k20?e=r(zhoNV zacgyLJ(m}aTx2X2y5m7PQ2}rnIe%19ioo@P^q5AyZDe=0wc(Epl`{t<_qU0pA5l~IlbnP8sA z9+n&(5MPC#BWZ|rER&iA?069HbC5*mVeRG^c629KcM}fRsw50YpP`KA`>0L))FYQ7 z0;x}W4>gBA^yg=L&5m4qW={HemNGY|o-=%i8tI53*v!sK0FoTS>Hz^ZW?c;b}pTY_Y z(r^7PkyGvtmp!+fc{X$*vU;q+&O^OD&9}|vCd|*85$rjn!D;jOG6+S#a~o#6qF?!3 z|K;5_*o12FO^aPq+0tDJteI*jm^82<+c416a?u!U2S#Q;O7>sDm^L+js>ZtV#;SFE=_paZTm2pwD+RXH)%+uFwAk2Z z!gdTq4oNc_qFD7seGsXB6X)xiMA>M7 zY?hEO-P(BUmgm~mb%N&KL7jR)Xgz|wfjs=?tMDM}@kbD6HsHAlH28=99n)9aqxgeq z0@KIw%FUZ9*8>TI*Zsv?_=cFu6^}Nyc@|W!*Me(`8=XK&Cp>4|TQ{ok6zCPA*2fqH z?=>3&jM2+06GcJJN?LiLn)Wv5X~%BZqIWTbu4&{EY6coY_c z#$uW>yB-;G6DmX77KD)J>Dv%)5ggEvB++nXgteN{%n;!%irzJAOWrAZgGSlWGzt%tAu0 zusHU08Zi8^O(uOaB_6VoxNJ_?uM2#%`I>1X;)}2$8Y9Vi`6>;{Xzv$yLmJ!ug_$=Z27InKxzBB;$6NrlRcp+Y>}qdXTX7h5V4U?C0A8Kj#$aR6Ofu7k?&h1gVX( zia{8%b&x8bU+cF%b}k$s;kCyuF#-pL1Xs3Yx!4xZd%fIpAC_sRKyqxo$}+<^0pNA{ z7c)wk`SW#OYm{+CPhl6{ms`dzTdwA0d#->s#s*L#T|ZP9w8iQAdOBjO+i(+2Ef~MY z_EB!J5h|uv+$N=;7p%sSk#|wYF>e3%d{Wu=8u^SyqcnM`0ZgX2kU#$GX#53VeaTcm zEF?o>P*O>d!m`(Z&3#FbU}N{ZBg0F=QnmegATd?953*{!iD~2Ld;j@*1sl7(+%XiY zjA+TBU$~Cqcn9f`#+$f%YbNdEIUWstT^-{$d;m4n_eg}5F7hVrkCVR=ZjH6IaZ(1Gtv)j;3H_5J& z$_rjXa&mvrkQtX%TC6-yNc9G@=?0Q>=YI1R5dnwV`;HZipQglzdCi%tfA-E0+>);@ zPi&XxErQKnp1qU_Eody5M5DwaxA{k{BS$Q5*CkfWQey4EXPPkeXJ@5$%TIT2VY z=stPHbo~0Z!A#`1lipnjFXpnb_hcG3GOog7=pQ~O_5cm0&7m#wos=wg);7g7k*SkV zDWPv|8nqu&v(@KiYn?XRwYY%s&NB-aL+C)G^dt*W;Z9!;|DKEW9j~mbLS{b6(E+1o zRWN8nRl)Y?FnEJevyxO&J%jFiOv0tah_p*VtF3*(5Q^uBJc%*YTE~f@`12lgb0qhZ zSeWlM!c8T201)Uv=19(}nmyq_wgc0L#j~2$Ew9$Dq+G(Q> z)8UKVJL?#|*N{Va{H3L!LxvJDxfhBL88JLQa5K-Z1)$M@WuOS4;g4ME18Volotal8 zI3sn5(rg!V8W%?@503t#j{v^E=ATGP54Fn-!<)QY3omqOVAS3fTtbK4YDpz<=?Ml$ zBc^4!CGmOAREC`uq?9u9*Qeb*;*jYZcxF3QI&#n$Fx$t9s;QKHB!mVnN~Uppa6VZc zN1DySb6heEYp)pb*jNZV*L^m9Wz17neoEeWI%vUR2{#x;cR8}-;q}-=E1x{!yC=)N zFKP$_RR%ns)uMM5DB5qSCRf0z@wq>Y1gVmo}1AiqOWv*f8d>^4SRCNxC{55!&yhcnalFaH@N zW)VYomFsX4;__{w8e%&N&Q_G$dB`=PLdr7u@h#bvReFQ?6b~%g*i6~gpV*3|@Mf45 z9~P7$a{-nq-_VURgVotIFx1GUxQ!csu-ccR;@xWCH3T0pympmaFGZ%Lj}JYsPA zeQl#J&M8r8453#n4R{mna&Rxo+sw-Jq&wperyoV1;ACq^ZZ1Z&zK z!VPll3B@_3Qcz4IQjy8jF3>1yB3#H^pbPzsONu{K3W{vMkvDE{$NE#}L3o*d*_}f! zr#$wPojq-CXXQS^*TIfk3A^<}gilcKK~dHnFn)L0&10z|*pg@nC~k9{2N4QpJb2xX z7J?l`$-a9x;G$|>6j(gosYq_P%lIVCZ;pRP?17cy4TUg4XZg^(bTOYJ@&)AwQ(9;3 zv7R}GHEjjnYD9hrlw*C5Evj7q7OnV0X8u;&wtfR|VHHKtFE2OK=zjAcFxSe+zNQ1{ zqjc{3u*Pcg9~cA@M`)42%2BwgRE;pB+itr5k~Op7(u4BS-c@4INu%uKTi?~8YZa5h zvuH1f`dt}f$K14Rlai?;Tso{SoXCvXWJAb#o0GpAaWZlpNPa4EyzzWBbmZ99Bjn|> zIG0x=V|ei}V3gCmbz$vzF3)IUZzNqg<}sT60)AGCNSIX`Z60fg zd(dd+7AZUBOjw(b=l7#!u0MXGg)}A1doVbE5%-0%8JT}zQUI>kG!>B2BNt}pX)bvj zoS|K@85WbuS-O^{Uv?&0mRcJ~$J1?kMJOX756Si}ciDaW`@t}|_5)%&D3wKJIJ?o+ zH*2>c7gn^>J5EGkaDsRz-C>5rS!uKP$-62t`cB#J?*++3bl zj8V?7CUnN{w}?`P*PwI{&jc}Q2vSW)JIvf=a}f1|b{|;iU+zW1n(j<{FOB$~6=JQ- zo+y%xG>F_{fr1zEA6%?94CFf} z?85GRP*#11eF1XxNDR?2|Gmt-(n(}%+_rt(|7bJ97dd8F!4JtqUzhHSX_ZYJv#%qm z2n2udW<~@Vp?ZSP!;)Ctan+mDOWVa~&`*F<`CQSourO?g~t1}HO!Km&2$1lN;Pu@F^mGS_F=~Yg1!EQgU_Im&-VqcHEsh zvai0nzi|e8UB0(p8y*YCXE+Z&8Xg!Y>e@R60;!gdj_gxtE41hcp`I=r6c#V-;KiTR zxa{_|qbLQQ^K7wq4$)fR_+EXbOV~ad3oOtRtoK69gQVoP#5%4qm<$DU2`+o0sbIsj zRZ|>}Ha*^_@sgQ#$8^*>n#YpyAm6dKY>vweh=awT;0*!x2Y-Y)(~^ZW(d1V`XeBH zp_Ti~b(7;WD0$N!AA7DJ9+vcf3?t?PNQ!=fGS3UED3IuFw8w+aYIR3@JFD7JUO@pP z6bijBsaS0GAqN7=;4zdUtj^Mx%)U>Tm=G>%ShCo6B<_cA2v4`?ra;^>3dc=Hte8Z1 z1l#gcYlWoA-i#E~$R*IvQgy%dlVoltxvX1Z@PxQ`;IP=uw!jixj><10`=WvNo9i3b zLnKf}1c#W9&>%|hH(LAg9jM*Vxj;lTmegGUlab+8;K%FXSQ&@MYC1sConL_g?MoTo z4@v|?M`-{UAA>UAoo7w`XBD^bG1Mf~f+T=8n^*7#Ir!BpL4vPY)W?muQ4;V6W!Fd) zO#`nhdM^}gkTj5_#br72DqY0=WfF(c)H6=!&G!H%b~~%#;=&8yXt6+dyYA*QTG^;K zu^>@aHNR34A?uOv&)p8auiRITZ|ecEIIs280Qc5Hr|DM~Ep{J&;+dL#V%U2J@d|{l zabNsWJj$g))r=Z+Fn)r@`&!ovPS2WOk&+%2t3|_pomCmIM6-8N^yALyi`=9_%})@7 zCI5stI;q=L@wkTYu*^aX#Qd zBp1)7N7NCD4F@bx9XI+20SHr03im7~oNJnd)R;`zrGOpd${H}UVAL!o8Ou{F>Ob7w zEgW~G0!&Dw0PE&ma}P*nbJ%_cK;}>d0$!RQ0PaE9gyHz(Qw0RdO?`YV|MB*eibLaj zoX;s~^9?l}w?%KEUmEFnUZ>X6Bf-*o5qd1~^R*TOdNtPSs8W#D(0Xr6>p+uX;*WQ4 zb}8y>ZP6dE{5YC1ZgU_{fGjAT`S9*-(yhh)R%PthpEhbiub)AHAbD!ByK}V%p%h`+ z907gqEqgjp{{g;U@_4~H;JB1x<^`0|T`8atYvNMoREEN^cYaC~lTc1+!KngKHSzR<{^|8;^XwPs8F`96hP z*glVv&x(MChNjH#$rsQWqX0>Ut$;k0PZ>9z1k02+!h>9;9C(gvcSkML%YfcP#AdeY z9U|p(tG%gT^{eC*6j1?47`yk{mw0sY9{_!xr;lMLAYm)bvIdMXJgJ_5OwAR*x5Trq z$JZ?O_+vzKh-aNqjG#~2&)1ta!Z8IXu@m>)?S4!WeWiqk*{TBE>c9&V+hOygaWAdYw4sqXUcDr%;0Q=@*|g2`{o-RgK=lwY8C)OA*=WV<)%?&(0mNy z+4GeIg)S|5$0jIh^8Ol>XUyPJFc-}b)zi$FDu~}4_-X*Dq)6ZNR^rL{iZXbywngYi zdbY|t9i7?zmbfLVyI$4iYtPp-9v@x0l$%IEhDry3U2GG^~Y>ObKm(@d+?&hz3aM>B#iJ)G|1>Acb2QQ(~ zG?p$$i=uX(fB>q%prIN@|Cv*jkj%=?3y**x_fFgKA&vpE+k=&(PcTiFJ6URE1ksBO zTjJ4Aa~ZwRklIFeJJgYTZj|B@aH@&z=fyU)W{+@XA`$7WD&@ zX)p!9|D?K-WTZ;1Fm!LZ=tEFV*%SspVdp7#Zyc#IA@aWJ;JDrirBbev#|{#U?%Mf< zF;eD@n|r^(kUN}+au7NYe02c#qy){Kv7peN4KJV4^wZs55uIJ zUGp4>j7~A3T3ucFMKb#f34L=Y3`qW?(U`?#)U11+$2RjKv&<_oeu|sA{Rm+*mg;jK z-5IS$Vf;0nhShqX9y;Z1Y}@2gR5nf|`5~OkRvQw}w)>fv*{4ta)0ccp8O-$BXZfOw zj}5O$O2{?ux|*3BZnHkn)&`RWN;b;wUTb%ZTkQU+wp1q1+-v-{a+ayEY?Dj(D-lg4 zNt1S?Ww2jOctYkNVux)GpbO}*W+=cwC(bgR9=is0PjFOQX$b>UzjRjtuZY`sRZ02zkNSX2mVjCNjh2nJ4jK2yvXb}`?Pdyq zLzMmzL3mz&bGFgttC6*$woVg_v2z2s&;-{c5raz%)Cd!^JVm-92{i-?MLo%3AW&^y zVl+rpK2Qz#Cl|9%$KNG(WvdlR`)z@Qn&+@W@I8X(`F0G@UDRgqYj`7H-$11~9p7rY z@F%mGg`>d_)3|KVLc@-{^Zf%s3l%Vj&8|`UW7+wJMW9ZPNS_6?S-#bN%h{fQDB12S zAgBU3a*mc6hbfN(L<^BFG7VqLPe>!P&T>B56n4LoRSfD*RO#+fVEa8%@KOE;@SL5>A$4@#Pg5I^0wGOahByl}dkH!uOVK1n*6-EI88d zbNoz(PH+@V=v!j3)I48J`uU2~hOGGcX1t`;qEHRHFz@PyX1moBKcs*2I~Coe^yt3} zW^UjE(>>8+(R09JFpXYMkN1k*BS=j(=;85ruvSM~MPb(g6WIj0Fd}8fxK1_OKNXJ& z+V}HAfxk1+xlO`zQC)Ls_l;;CRfNMOEBllLyr#L2>is;s8(2jaN}QS3=17%*8FT%> zz5u7mwF4$4_X|MFmSrBj>qy8T#%Eq-F*T6l=?SQEdcKHJk_qsO-z?NQqX1HZNl0`@ zyCj#}011Wi8<~?&f=T5xy)m;u&-BCL{7>3jooaEQKhI@vmM}*)W`a;kOed4ymHGDk zFj~yVbB|XVemQ;fBHpxBhT~1i55scBy-9q2=kh=)2Ba~i`LuQ8)&_eoA{-t z6>9#{rYl zRB;I>FsadFInNsc3z#(^kLeG0MVF~8*KFs33Nlznt{xRK^_4+(Qrq{iwEW2Xd;96x zwYI>hsaVv6bJ{L@UHLG}HNdy#6vjo#WX?T&#FkekMJ9%g8s9V97f?R_y(y z$-??m_cdjsT$+RN!rS%1bRzM*Yp|UVEoAA(`%r*nrP1oLJ8mvj?e6{{*}tm!Nvzf4 z>6U`2`R?VC?*o!pRKJmgWZ#&er_`@br-i1NS)G;;pCqDz~v z5zb;4#y+7@p;)+fJ?V^%QTf~gYqm>~+_xuKVh`6{+fb^G=E8rk>y(eG`XFd?`3+gL)DMC;GSKLTxiGct;@>bY5H?Gd zM$K=t5m3TfGn&RTank@=K_clsBVXD47)qDa=ZLp^7b$tp`AVLPz*_E$qCXHM`{@gu z+CAWo$yYpG`*?j76!H?~zHIeW5lgA2xb@Q<5*0zpQN%k2L(J-9ug)b(6a_}$L(Q*9 zXiJ zck&rHC)NA8&&*spyc1nDHh@Bwz4%22HOBLEK7^`$Zvr`f$m9?r<#%u9W^>6Y5EqFJ z2`W1MMZdDSzyQU=k5U5jyds#btd0ZXsD3Mc3RWhT4JgfX}AQ zO&ZPmih)bPv8lc;Ko_fyWFkYb_NIL-hq=;eX3tj5S+Y2qE$`M$9)_aGxq+KdNOe>|ZB zcv3r~rP@HRczw~~VZD<&&?=k}^SN@OOQy6x42OmLy~2mpZJpv}jS_7Mjpf^2UYpA} zjfBv>QzkwZ`5y`i6R)O!s>x-97(J_T+}~DFS0&_FqvVq)becB;S9#chpu|-vF!Hx-fDpM&cmh3_QOknbe zmiwHj8g?bo+tos|HGrSIdkZ(}>GM?pax_L?NsKV+RuzC;{0GmY=xqV+d{Tul;C-Fb z#`!BWg3@;sT(SLv^_2Osg-a@chqlX$u)+UR*jqqF^{!#xf`WjA2*}U^N=r9Gh=htT zbV+wNNOz}*AUTxMjYvs%cQ;5Q4BhZP{NsG*eCu87buE{~u-(kw`-%I$uHSXTi>w8t zY!0p`-|cK{23cRTd0F*9)RSj)Q>jj9&1S3El9Q8#R^u zQ_f?`$Oe~PyridPJH27|MP%K*V}SUE*Ez!(OLuAt8a=_R6<>|*6NO8UE&u9GhI7g@ zUc1NWR;iii-`~baP{H1cK%;ih;l7&d%iCUwj57s`*+uhMamv=#pU`oTVQH-@EaTEj zKS@LjCEhNU+I$$HxE+qQMY-Q4{JNHY?coEK76o>9cotfJAcQgLv8N$5dxwvt-ES*i z>Rmx`|Lm7|X6oZyEiuO?ZW{GwI;Q!n^sJVrJ#wj&5Q@=$eQ!U>tTkg z0dG*(Ya&*yyCuz_XcwR}TVS>(3y)%&dFIVUR5w*N$fU4y|Gm{d)kW-8n0CoU=y{X0 zul%ah!YEGaheYNl@X$&kEc>Y9%1;am?#}9)H}?jLt;Jn?PQNgn3lAD|NzQTT&d73j zm+katI_0W;9L)L!npmcrFu&}K0Hqh}WY>9U80o>%XUfv=P&CTL(jd0-sT0!DxtIKP zFL{Rm?I@Heb+BB)>2!DQ=oeSMN~Zm~%*7^K<|~UQJf_29b>Y_uyrB~kj%jF2I~}di z(7bmTNOT@GKU8Z*F=6f*mYnIjBZ6jwX+HdUt@Sda+lwK6mvnb(UHtr4*RHPK=qKM3 zg)G%)!?=xswr3&=M-~jWXMJo>X$A3SA3g0XzFc1ITS;rU)aaIYzE&(hSVz0zb%mN| zy)RNx2#>ex#@X(7P47fj`3?6#<})Ji_$>@^DSMiz};E!wM*&oon#+Pa-ahsR8>a`m@r zt(k5vLkwpy;GVg|WY#mGpSL@LvR4T+kM}o}sVb^58DJeXnft$8c!>$Q{p1gDMs)t1 z+f-Zt|D@dK5inZvDT&``T59e`?O9+%I`v3>BYW2pDQ39zY-Qp>z~$V}_;dtfZDq z9>1hoF%!Oj0vq$g+Bp8~<*Q|{jp?fwhdyAHBI+r1Q&2@{&LuA?4^E_eHsUe+N)Ba1%C3c!}!Ye!wId$X&_oF3J0lP-WO4%yfWkADq;{F`M(N#SxYf2DY2wWEXJdBv>aUiH)LJFBu#a#^M=f!&Ph%Vqq;fOfC)BMHT>8 z5nW^x_fmnlGSg}s!+3wW&7sCN?(}cZ;lEf}mxsPoDQ#ViMUO(bq0mrq#y zU5Il>3A#%K}mcVWwNh9H*M03l@8tOQwg;=FS&S%1`P|;yUV8Uw0dX_XxO5 z%kzHR7UxW6Z<}ukHebc>eiL8*j)4)u7o~C5E?Y(bF#$~c$q<8faf3fMz_;b zlLcOCUM9Y|R~{$R$AW$!qF*I9ik^Z#X z9{3HyG8WFRsjV9vmv8r%>G~GLLSDG}(JEIB6cQV_5PoXw5)w^Ey|!g*geDp!zaLog zTDsRRo$7N>Dani6^Qp{21B7U|mg?nWonwsW%`Ln1eTdQ*3*fd7N#8EsH1xuUpY&OP zelOz4E54*9nWb%&q@a;T?SO?fCgPUMM9 z0@FD?q(>PEQ~rF9;xyweoFUV`fgsMYH`L>ak5+7%`uOF&+Y4=>7FlyE9mFR+h@#YF!2aBd&>q z`rjx&sSfC?OZXRz3~GG6*ZyPNrA)r(+~LYJOIO`DCK`vaUZdSXqFw^d`IW8i7+R$N zjj$p0&OicskYrH$1o*sID#O&v*fqkN1Fu}UDg!k|`y!vMvAi_rbm-ZxHpP;CP&Y#H z*jZtRx_9eHPX|?k4P$gSP_ScQdHK9tm7|@P_PLWAY>=|CtzR={C)@UXesPOm z7ndM;joI*%B4&-nFR2!XYEP)Ke0{)1co|iKyPKf0u=vracj~mnjwa4%zv;0|)_|u- z5~clq{tQa8fCpygjB-;$gk_Eg&@Ru<)NRvu<3&9BHM{o?r{hLS;)@Lf&iWSDqDBRK z=EOEju$^Rzni2pKifzD%BYM`0?-z z)BQZxHwAVRX5oU7p_seed34BQ8=VGi(p^!HZDmelip$5_8n^dL=IwV zD_v|flyWTx+KoU3Y<+<)gw$>gTKIO{w?+EJ2N<^&U496~kBQ{p2R?Nj-DCD6X`eA- zzoOQ+)TqAeDqJl zy(Q)ArZbP!g}Qs) z8iv2LImzjsz8KZ>`F8yw6W?vd<_pO=67>N}tGVCW-P%{!SXRiE2aS{3&Y02i?&h zZ44gI;PraRDVLS6Z49*UD@OS%wmC&kn^u4iQ9uuV_0#ucoL%r$aOy*DmL#8| zKZ$8h(ub!*Icfso$v+-Je7R=EZRwYJqfC9AYd@ktfXtbr zrPi=gq;#4P{9~G8q}-&JVhlAle_SMDtAEQG`*q_7>?7JIQ+fZT&*-{Yx&y&|j{L8$ z{mq86ko>O;@HgV)Cjhho3?I;N{G;0tqnh~--vW$Ze~~l()d7KP__vM&U^1NUs1>wj z=&$|LDjnC}6GcgRyL9H*W2=J~sKcY2V2j+-0|6xIV@2~+r; zL?)P17P`R)Vzo||L%@H?3Bswcwk9OO3KjS1Q=@akP_c|}&w)S$P?gB;^l2d*$$Vv* z1|iEAL4;&v5jiLDGBMJ&( z|M^Hc`y1l@OQA|ba*1lvvflF;L)XBWrdJ51%jNCusLuGHIFv8wrZpd z3UMkofSFTG4!)Z>#H>HpHOJ5|v*!`?`H#Qm&S!9;dP`QDM7u`iLHw`)3W!uWUHD-y z@wO?&^O)!q#?jlt_%mdO>>#|xk9LJBpO?v7Sn#^y_Xl8BV`Nz5W^~3>LL`cXOw}%E zrDCTJH;k%w_>B|x*BMUg1zs)hFf%A<(yy?LqPu0rvb8fxL|WN7WJocXHDn1`^YS$ZQ=_b_~#<Ee{3Z9QJ_Xql)mO*Mu!xjsJceMHY#@9n?Xa%DRQO_LJ%Mmt+YT*+jvYLPm#-u^FPDQ4qah&h(PQ`-N z$?Z%D`72DkxANRQXp7o4l~UOSYXX)$X7rj8UvA9Ra5IcqL~+#nOmZ7P*itU^Zuc;v z^4C-uJN0nbH2INGrXUS%E71K@vgJU>lOL527s4x|(POojRq56EiQ7`k>90^h!)r5! zBdPpev?VcCuJ#Yz1F??cPPN5c6X|43Zl3ILkHsLGHU_$KA-XX61soZIM5#1 zi1%bkmv)Uk9KscX%ztC384$?*Nff>%&XJ+lF@>m4Pb;$){Pr#ek2-GWl})4g5BelL zkFUw{)k!5T@1^i}cQS;8B^KJn*=$qK1wBhkht@W)n;6tM`Q!Tho*W0QB;H~bkj*@$ zS1^(&&LzQxIFNamtx1N3>}Q%hb!O0dNNZi{k%3ORu99hz%Wo6Kot@^~uQ|zzEuQZv zd1k%sOEu(n$4uqLz2D0v2g1#}UyXHvBY+odB zofM#*&TmAm1ZcG&}D*n-K_UbsD(5$MBmGZDPg@ zsCkXXM0g$J^Lk7QC*yl^;`kmCJM9LgU)N^5FZ~Ru=p8FlEX*5soT<2{BsJPr#K@En zCY(6SMumRT&J@AzT7j?XEa_K3AGx2u*md>`h|R94S2>YPr^*cZUwRe%wYHC^W#8D)jR_Xnp6q8|pK2++>M5fpXdJ#lv6K^#6Z!r7rJP5jE43)OclCMd5ZS8>>3PZ>_bEd3oFV#a= z2;C9Mj?XJtZXRZ5y4Pv3mMbugpIC-}c6_M2cQZGc)m`b)p_S~20J<0;PW zH}oZNGrGshpi$1{9FWG(J>?2&4a)AofQRaKzoI^HAoNK3I*52MVtJIKN&ZNtH2s;) z!bjocu(7~wAsL#gLh`_FGHoQ78tI_tqAHVW4eELwgn~27qxEP1Mr2~)#bSXrm7^kF zh=oQ74(vg;d!!BB2Lf!FvHAJ$jFcbYPzD?%y3%WYO6O17CQNkQFA7i2+QK zZNOiBXa7DGIYEKZ%<`8${?5qN7SQ;{|G|RT8)sgbB2wSas{+3J$+Sqcve_0`I|#Pv zkOTzh;psrW! zR5tVDrP8w515kg7dF4y;a76I4UK17cJ_!p0i~=RZsOd$R5G;!pH-5MVc?(-L@a+C> zoypIRlE_#lgkrjuFc!@J*@TOxT;3Y%>==6dZ*=n93&lIvhAiU8c_IpY79Xm#<^7>J zAbTA$K8!9HSCc!y5ao7bqQQ=pMW)>NZ86ua@F3o67*p8DIS(D@K3w_516Z7q8%CMT zyerXT7kG*~8*-m3tR>~F^~IBr#*i~fuByu1*Q2NrUl);xzw#B%-@5nvp&Rok!IfIMw5j?;zoz!yW(SSvgTMu{)% zv`G|tl@#eUNFU*7wwKhLFREs;IPK0wyiDTOTPRi`5D?S1siUGBD`8PCR`cC;?4ed! z;x}@xsd^HSOwwX2((G|8e+RxbN}3tZ2i%}`W%IHrY$F8zh~PMqThG6{C}VVXb;6lZ?(@!1#r;_N zrl~1cnt8I!o?0ONMnww`l~*VNT=eG8(jj~;QpGl#alw^=v@Y(O+~T5itse3r92LO=q9`LU2IdclR8dIvHsHN z5Cm#~ue=Kl2@2JD56didnUi;xi2wNeRj`0^;e3P}F&y7NWiI4cl4aX)0=DbjGaq(Q z-sM0MG%?WB_=>u8C5HriM>RzIT5r@hXtGk5VAgkc(*c%oRpPYi8eh({6n80CFn>LB z$_b43I)y#_588f_YIEdXoiL|{`P_e~8+@S^n6tvJ(+SzBJIhc@1!Fvsb0ShlwD~82 z%KLW4Jr9yV)41M&pii*=~tkE zBU`Ahq^TxNmr_w~*yl?+RsN#tJ<|=xb)FC)=@F%_B-yO~`2&EYV2Bbsd2qK8`7&zw z8u8<4_2C+a-{VU*zTXn{POq1EUC9o{O}}4?uPP6I5%5Cd#itMX)#pYHYnwKkW>39N zeR7XZStbmh*}t>%O*okVDuAzy>$IM8X38b^$Brb&Z8K?<+ygCq(RR#DE_b$w(%#My zZ^o6w9+x@|?Edok$Yb{XOG`Kpdeg`@)9cu<|8Eaxkc9ZQ#`mQVxr47mR%hP@Ki;17 zJg8XYMz^OAP(Gc}4{+4X;N+zk=a;?ye#nd*?sc81u_Mg^7+dw!nUYbWaqo$g3@hSM z8TyOmtDkg#VgBCK4!FppIlGuFEG$e~zt9ZFu6$8QmlS`7%Sh2>gb}>Vn9#ieoq6$1 z`4^5g-LVWA$qH(M3-{LqTU0U{ zeK|TO?D-EA^TMF9+jRy(p^l?h{GA_)$w+DU{9i{u;TPV%T4_<(Qlu|6U6D}QhZZxW zT-s7U6OsI02?3^BK`zf-5Sl!w9;E$-_FO`{X!qZC9C#T?&@Y5jFJtfVDD*8`&^%B zpC{yl*6n;=`tw0tmHEV)JyZ`N}Fp;ol za-=#gJg%l{5u{oY!_St7jR)ZAusy9BYl5X<);M8ptvhtH-$WzQea`o`ZUxVHtVU%| z^UIjC&#r$2(mM8|&;|2IjJw6S$n1A?r+1^Dfn|Iv5X#@!IWIc_d0GgC*AWI%_TK=q>Lu_uN47p0^_fI0O*loAgXzdd zmXm+B?Fv5Bkh=vCr#|yKs{^cXB=5ex5sC@{_vOPgMz#ql=w`>BIC+-6ZGn8u|dD^^EM|?TxN)SvKy|>4! z=jBoK6p}vTW(gO`m9HduBc~AH3VK{}Tg?AL2Q>2$+-J=r0K>&~#`?tZ{NTm=WL_kq z;q2FUDBxE_JWfny2JAdDAIh9)|b|3&Ll|8Y9Xu5hS_p84o!~#Hshl;g@ui^PXx844-!Tp>aT%LeC zS^ZLTfa?b;Ir+co%Ttke)83l5pFR>VuabfjcddmIuVMj82YoHUvy>6P*BdT|N{M!3 z(b>w6$ZWfX%?eRzgFa)pw%2(8_TCS}9wWg-Ep8MjkVT9SQDMO%&jA@;{M1%Y9s7YU z=ZX|iDh+2#)T$;RmzWZb#~x3*5iYiW*C;Bl~!OmQ}tMQV! zEr;b`zIPN>R>!T;1{8Sx&4oE8g%BwbyFnv}^gFr&qJ3(xDk2W7zrAr26Bpmy76r;W zF3t!d4%FM5(*~~JxIX}b$QQhk8P*H+Kw-=+bg@C5@^Gx)!!4YY@5x>2VJJTRV5TIF zVCqP!*9{-gvPS@z(=v$i6iMVXb-+_QxqX)^B5I;Y5{Ehrx24JJOK1M%@)(i5)W?<86wMmJ)mPUi^ zu&m}{lTs`9=Btn8)$F~!lf7y`RpyHUw zux|xwc`CP)oeScXjg4Rc0@~pGwd=4mi7R}46mwGuC`cf3`1>$!Hb`}(^t!p)s#Fox zZUrSkU^DxBm_daSDeHWxG-dfsQH2(X_p`-zOADkiWZvxgtxQUHE?AQvjGBaAU9VGG z|55HtVJmde32AQACUODY$)QZYhd3K=9#cz}8}&DaZ;m)T52jw=0wqUU8PbXCB;F|M zofIJt;vgKd;nz`kz5t(>E6Jn3@EPUNTK?@eCsaC~mHdO^_h^sr@q{BB#Q->C%4=Vw zOaL(Meo0A5LY)@aow`GXJ#?O4mQg^ow(JX*(@P*3avTR0jTc&p4qNcNER6hRXM@h& z#R$@rE^w!tEGN@foc40q2QrhVz{1Xil^h zydz9$y*~wbkcz5?P^*(?@IyX_0vY37k=ei=VesoYk1pe)T+iXporfK4B+(7G?!WiA zG(EJ6wLd4#l%}~{`yT*<-XK_Gky`Ev-=4!rq5Hy;lN?l{7VMJF%W03n^V}qSvyX$t z{ouRT&0%VeR$WbfNeOx?(%t!)a?h;LeNFW^Nw7lYwOJG)lkSeD4wB&kY3lA5o7w!` zqv@|7&KZXews{ySo`T5C(dZ&{Jemzorm#0(6#w()`(^W}Ne0;^Xy+uc2-~f*=-edJ z4p@(bwsBhl87m+-3qB!dw8hsR@2Q88;s@v{Ovt40n>y?HhxkE9^HpFtOif6nyv`4( zMLjN#h77YIFPD$D#`2Fj*EyD39nlTL-^l%XX4{C447t?6{RxR+*P86HEQjGwta{^x zI|I+A_`iz|Vdo5VS#-YiA9|%&Gw?-vwl=g_q<5r>zSkL(n6l4ZDgHg@OMg&K3Q=9$ z{L`9)cgeLc2(#$!xRG(UPJDAD1gx8&i||*=z?Mq=?lqKs5k~Irsb7W^|N9_+m85`N z8gx7Vr&e$BKMS}!BdCnnT>~M5=igZsG$Zbg4E~!sAlv${LjBz*8`A&NHTb6}{ugI@ z>aMe~EcTEE~H|MJ^R34!PupX8}B2IHYry!X^kXL3Q^;lF++DKJ|j zPj7Sa6UmEh?$@~&FOQ7-rRWM(Eu#MStU;d>#Ek@kDZR-B!TDomJHqLq`x4Y3(GX~8 zc}-RS=bb2f>pW~DW<$(Q_6K`Tr04p^qTS0rOjK>3n9k_wiO%Qtv%qBh2RbU|Mii9Pohq7|cGeTA;|c;b zc}6^1oZa(Pw&tuqS}-Y4LiyJt0*2s`Y_B#T3cq2+FN2~G;2-ZT-~eN5lmGt8opTmE zsCYmzDyEDAuPM|1#tIb_WOE&*6J$yMH9t1%6uF~@cP(&UYq^KO$3J{v&k~R}5q&RQ z&;##l^WKLzP)iqI)jtjU%{025*&t_&WQUh~;(=RfX+Jw4o1(D7r?PdH`)Zwk75l#7>^xIc#eMJL6?? z)TkMpC6`NFBW=tkgn~~_`5Xs!TK93PLH|0|y|#CJ9&5csnkOI}rCxELwyKq9x$=d1ed}0z3RE-N1lGqgO`}!S=#X<|17@{-W zmJa^mi)tWLExYZ_I1s%D)uqR}2$Sd2<74NN`6$e?L5hSl43UFs`NKbKK<~F6U24+L?)xC(1 zF1i=zA0WHL!4d)BNo@!gB}qw>$F@Pn`zN#M$=*{ zek=-1PVR?nCyhfvtFYASIzXg$JP##g4CQBth>F6|(1=UR zsG(%FQ@Yc71unORZk7?vtlSQpsR4qkgJ<&EO^HSLbF~&U=}9{6e)OfKB?y~4WcZs* z$a|uZ?Q6A4tCv*G%}O_`$F8f%-CJ31{ybJOrrmk^O;>$0?Ac2{&lYOlgD|{_JT*-} ziXItAcyKUqAI~|uuJydZ?@@cb+H`HqZ$_zsrK82P*v|Fc2Ao_JM;r* zk7+T&fr=NkA0vM2PZhbb@91)m*HWfI^oHOUfM;UZ=KE@OmW`Yp)i4m~Arxm5waF*y zd;R#B^=WC;9@UxAGpm64cKbuX%FSr8ZtfX*r2BD~nuZ1wIJ*#!stdnL1U+neEgdAW z&~n&;v$$tZCghXud^O|RE#+z_{N&XuAGEMv`PqBos4F$uw7#$Rmd_7^(2kCMqr4uI zt5phc3yQ1Sco*TH&s7CHglT_~2b10tLb&4hID(nHYub#tB@w}At;`D|$#n$&SQFG- zycN^yem%H2oFb)NT7D@LrLBUP>!Qe|ed{!de~!iL<~-?U?8AxRT5@tU(3b#b9fVCT z7PUKvOH7>C6y)99yjDwTRl~7r_Ami9$YyOP*8M%FOAp%f~!_;gat^WS&XO5 zdCSD04-SH_H}xC4U9Vk_kL;|iSt=qP$9h&o(zO*g;vqvUbrpkFb-x$`L8z_tUX}aC zAf+o`1LUqyqh2NJr8cYl<_(&LCM?70k9w8+Dm$>%-YrYFSW2At^;|uadk5fxepBVf z+hqeO0+I_*bZyTY&yCsK73&OZRA>Z|AU`v5>-mEg5*}m+g}STr14C?O&j<=L9st%mB<+f$uoano|yC8G6bY9z+ zxM#l5T*bq^dJhTdhF|cM2S}j-RltAx>odn?cr);GKQ8JnH=mHvG%EU#D~OY!x-I` zwK3qIJx;Jtt4Lct%ui%{1b(^Hs%7v_-a~&u=Zv^?@&qNxpC3{hyRP(bIW@)i#k2N`G983-N zyoG(unWhk&QEn7g?e}sIp?Upu8EK-L(EDwQ`C>=0@QC5tlc7_{ucIG)ufeWI{+%L# zzt{Z=2ui&ns-=D9qNxHL z4r}J?T&XmtIf;L(-k2%nr-8UKVlf7#yc}vPV9xaoQZIh9!)u37u5>k< zd_{t}9P%%Q`tnHh*EsBci?ReZ>?0?T8lHZ*F_l>hH~MX{^@aYzE$2gabr^--)^c+qA2!U3WEaF^ILo(QbwJO9&EAA)V&@=tK`e3pta?7 zn9?*%NHT<2daz1@-u=dw-ThN9F&ty-O6YRnG)Fccmw~V=W)M!xh8L1|yJnwGyi5Ku z(pt!$D7q3p;$V)Zd9;R)ShQC2;yrajCN(pUtkO>%$^|9hX9jLT*7%}&Mau?*;to)V zca7VXoN0I%c`i$OCmtgLC_%>3n!8=^>Z%6&dVoA3Bk6CVJbAuw{QIqkETmA!AQTr4 z2vTL=r5pjdT<1jCZ00A{?rexe>U^C;YbJnQyXpj>EN!+ovS2N`*E)sTM2g^ z&C|a|82!wBP0?ml%5us}27r(fPJ#lw2}Oi7!U5QJcBZb`p}28XQDA$ixcWA` zPF-nhu2@5^BdyR0jI<68!P1m0TEBuz^(D3)+CBGG?He(h6+kN7CmKfvLDhiTOGA{n zwY|WObh*qx*V-LIE{D#?SYN@u(GU#FKEpO)Zl`&*E(;HR1{fv$i8E3AF1+)~hO1 zYF>)xmym$O2r+;4wL1Mzf!V2c+!EiA6J5v{Od4%XSg}d%+VL;%#msyiK3tZBA5=o_ zYoU-|?ntiTcYWF!!H@S+U%lYPq{Z25tG|ADRB^QPLfgpSZv-zeyZ3u-p5^_4mVpfS zX`D|?=M8L!jgC9yn+0F9J2g=AqcocT#0NQ_oaL%3fSIlL-IWlGuZ&WADI-VNJkzRX z;(QP*97=$kx*<8aN?4d`l!{dy^l0f+PRc{;53WxS#g`&!|nu~FO8^HS_PEN*S)%x|Hhe!{hViB7J(i(E} zh52P0N;$rW8f;nxWBhPmm~)Ik?z3NI+wpWlo~hbo@B6n(jgxMIoH^ zb#Ja#(oZ(cbbo<`^}a*(2V7SJEkn1mw>KT@CI2WH*Qf;bu%&b>g#~A&;Yi zIEf}DJ5IQMB!X4%hp_}97MpN~Uv~S-_$Ftm+mTR zWej2vM93C?be3>;X2{R(;nc_}Rw+Hb8mejxa=r8$*KA%{#ItdF9}$%>@Q`BptH$@z zqnxkvKoa;wE(9CqP_&~45@d8yWJw0KknpKxJfctZ)m5qeRYqNr-P0%f|js3{2p#QBq*Fr62Jh-Tp1@D!2 z^b2hYin(9CbOXz6VaGA2KzP65DWX!WIVO$HVeGn34p@+LAa5kSm8ewD{xuE`2bAqe zTb3=;g2Ztfdv^;GHQM7^#Q--T%`p>}H{D>TVn@{&9!GGxpMiuqeg3QjZp%C&zV3Vs zrX-Q}pzQNJs_q}*&ZR7nB(?o21jNRz*KY(A&pN0adlTYp+E-rRwQJV3L7(xC{(z}$ zBQ{7yYU@FM3o1uu_j-#LBcz$nryz!(_V&z1OMI+CJ2##&&On{UFO9=~@;JMmF)2rR z^KI@(zlYl6xm{_`(tCFuQ$*?+&Kl2QYF#e`?>niX<1rAS5KzWFrW%Q2I-Fad09g+Ztwjq(|MK z(OP+{m=;4?_w*Vg^*VETk$$;LAG6@A!hPw@d1n4P`V({`C;Hs=wkRkUslHD(8qe>y z*DP4D%#*o$yRQ0OJGSw>E*La2@&02oGF!(_BB3u{=LQ}&G00ei3lsAvE}1rNm9PCu zoo!2~+a9c^Ny4Cc9g0DQOZoa3lmfymkl`j+vS6ijv(vX>^P47d=R`EOZ_oXh`y~$aiXE<)UmlOqr>n`>kw=oorG373Stu(*+FWb2Uyw zd!c%2&b^cF>}yt-YrXKyQ}e#9F_Za%1ah`dGlu8t^xiMknrFRszU1fcX1AA}ouBLd zMAjkaXkID&&}5s5`s6dI;%YoF?bD)t5636IG|C6}*)rmH3if&Wv=PqSZOITb%e9DK zsPhq~CeG!y;aFwjr7)ZC6*FK3>?gLM$)}43aQ-G)28O9aK)N-#INIdL5RV1KqzGcJ z;nV~$BLCcint#s*L)X{8wtS@te?Bq4*20AFNNbL)r@_h(_z%8Zl`E<`tzloCVpSZu znEA_AbVn2Yarm~r!lIBlvq2Qknua2O#Zevk?0VP+lf&aBG-7fkf4yyD8#NrTWdkjE zBU2IKMxYewW>yc(BAs3{LcT(ifjf^hmYWx_o%Bb1V_9%Wr&vxM1*n9V&yJvX#Q|_M#Y>?q> z3vqqy()uH1EWw=vV)CH*Gwh^zUNaH`Ri2Q>|4E7 z8EZk7dNkN24IW%b1kP}cP+cuAN~)gH>Iy7(RMXqL$b6**G=33QlfvmlLY&UF}d24FJ~VCy!ji`0#a?I}3r^He`+ScX#Hp3P(z_PinK zNIkc|E%-{*(G+j}jfE}AnIsQ72xR@S`so9TifwYM%g}Zj0 zFdX7nCKuF*Rv&RR5wI02?PUwY5kV7Z7Y~^rmk0$!86PljZdK2KU394H8UU-3bY0$eW8iByq`!BGgjCOgnAKf4*lqZE%&>CS<L~AVY^LDwBM=;&18@t>ze+;t%M!Kdjzk+DYm(as}(a zannhSs3DrI$x{8Zr63AUv@w7fV;&Y`b8TDNO$c)Q9Wt}%qW6o(tkE0E1X#Xrn4U~! z?BKxXrD3AQx+_R3v-P)-fz;WKA%e{4wGo_8J1cu^ZeGpO2cUIES85Q05bF?6%PJ7B zt3#Sr%C;7p7qzCaeM0L&5>1O;RqD8{3=9{XO>~)s{JD(^?zdXN^N+hs=N$fg|M)&A zEs1B#q%0?nmv))fyPq%a>=b0mk$U@6J+{?B5f7b$D|APC!* zE75tSSgb_`1O|hIBGH}7u|I%`B1na2>GIao|2Kt)FYI<7UFdyQBmI=HTz2K7-YDL` z+kE8+u_S8Q0NI)moiCf*%PEOlAqyzL zez!T`(M96Q=bN@J}8s=YsHlLBe^zvgMI zbtg_)9P_1f>Xp__&o9!iZQ6$m+T(%AExiNxRwZ$W9{V}2v&zMzU@4R^}#Ao!j9<||9_Z*jMo zpO!Tl9Vb2@lAY-(h$}BuwSdiol%AhpW}$GR0G1e_{TVHWE^R9UPTo!i4xqy(pZ_i2ECaf1jjP#0Hze=-Th+!Ne5RD+S$Kg$wCGu46yMImz{PU*|6EoVp zNTWKViJp~JRx(9TPtSqz7g#Gd5W(qa^z=bYrS|8BK6DIAkWdaY7IkEop&`jCj z|NLyJVB-6hd${L;(#H^6Dqc44qr4ovV-n{KOmDqI!Ow)0p$T9k;Pc$XO60%K8FhqJ zR;-_L?~@y*jVrBl2EfpwiVb~ZYncuH_w8nSIunBhXM+U&(&rp=BjA-Q_NVPuoto}d z{I3Je?W?UzyS{{~F?zQD`|E(TWc;h2uI7I^t3aIx+_D*WfLPE)z55vabM*A@2I@cG zto-y>@AR*4frjfHzxO|{-FW$T`}3bKScBNJ{~YGI>!ZIlcz+*vhy>+In3Dd`5~098 Rb`Sh{D=s5eB&y^4e*mPqi%9?g literal 89020 zcmeFZXH=8zwl$nUXcC%$L=Y*`6eWZbrGs?of}+v_C_RAEdsBMnL3-~hO?n3@qI8H5 zKzc8s_maHf+0WkR?DL*|zVn^&zCXS(z8`@R#<+8>`@XKMHRoJ&5u&NCNO6tv8UO&G zP*#$A3IGs&1^@^=NeS?O@o}^IivI<4c&hjqP||;E4gUsYE~6#`0F+0OUl!Z zy>tKoZjN5PfRLe|7ytm5rz|I<<7&8hNscPfeK|wka!__`du+>ewDqugsC;sW_;VHd z6AyES1!l|Ek^j^42U;SicVNGG(7RV6(%qIzpxgYxq_5ampMwGjLOFah-^bq}<6r}F zC_N(LVB?_UsVeqvImb>7`1Bn&XRNqISr;E0Y@9`in3bHil(_Y|4Xk)ipC<_poR`GM zJ4ii!vl8Dx^@jtGOW)5R-TwUFb?-(oydF}O@6I0Z78tg?+hg&{;|Vo^Wn6BW4@luI z!uaY}hgG0Wn_qiMYUe`}8W%aC-n(Hw%jVw8E8bfxg_b6oxXl6Vec@2_`wZM^MnMw9 zg7C|;;E-U7;9Yiq_#+awF0EGnIDj$Aj5q-H)Ee>;%$S+51+w_e&4%s;rB)jZg96kZ z^9!>FUaK-j&|0mzyNSaLerO;Ar^np{Z#liQa-k7qpbnwHfG2zJ!G9H16`4}Er;g~v zfHX~cP2#TESedtJg{xK^yR>Piy|Nz?Vl^IeDykG5%FBM>P8*Vic3)wPy?_CxlE+k- z+TSV~3$-OwrRgytisujL%7HLLxk2J>J~pnJ3}Y_8##?ZTE~R4Q7XlW(hV`_W#p&-6 zg0%J%&dRi4IN9nGZ!5ur{{ED?!Z_`Qu*5oFB^wKKwAu6WBK2Z5<^afYYCe9K81-mU zbP(EN4#7ld+J0qKy z20JVfPL8jy*B@NbaIEA^|p_v>(Upo`h_S#J3SFhe!TW{ z&E9VpiiXr|o=~^n9@|YT89vw#42HFKGtIpCBemB9U1@6-WYwUtX*+5gk%9(tJBGm! zzJcrtOr;OU-H{eg3+$jSft7p#`<{8@k?O@;RTkPC^zx!l>ZKF%GRSz=g;i7PDTtA# z3Varai)36NLLq@C|M6OvQJ!F(|h!+G{8VUT=i8L0SRO=Mu(ED*&Djz0c9l<)OlABvtuj%7ujq zGaz8Yw^G)x`tedwXmsm->_Lpub@yq$B1Y^tm9DMAA^d44*YfORU(4y1K#vaC?tOs zB+8h=8Kth+grP2$>;!k2qE%@0h8Y@u0U6r7&M4^(RvGb0Y%M$GZdMd{1@TVa%E7E7 zf{!^HIC^^VDZ7vW?bxy7koaUXOzN>xjt~NdPO_s?1(zfzMnoU7#GEwXM!LX7ixdEgmN^~%0!p2L9 zVdPwFkRAr;^bID~-X97Tg|S_$vS3Qp$z))s#3&!X64js35tDI(ON^Y2J7}MtUwFGJy z@aqS^Kr4izmH)ODgIfG5YS@rK7})jwqh#)#`9Z@pipfJZu+EpZIwCp~x~hnqPO8v| zj+((Yj%=f58?u36*B#}-(lFNSHk1?Yzg%VmtAW2k1qKsjwdCts9vR&Z039JaqpHEN zPuY0B)tG)+9IZ}ADk=$HJ)5^ifAcr@#@W2^i>58yU(12U$hs--t3*lhn0s3+h3hpK z`MFJ>KTmhS{1o(d`RlOfuw1UbG*5Hds#`I19FkA>)qmSbFHZ0K9WX!$woabiC-ziF zEVkuXAUT|DTIre2ZX57xykY4Ty2+y~my*nP??~9K@wMjAWanYhWElh%Edqd3t0p*8 zhKAJ_nhvV8Blxcq=7rgwDX0?5TkHSGp{O;Hoyj3L(=XemDRZ2tx3E$XySWa@$FL_G z-a}Eo?)%*xW&87!mWEZEl7*^qt3GgtQN!}9s9UAo<_NMwZ%PxfFF&R$R#ReTvhNIRR%GbKf2Hej zu+6;380k?b+%dKu7qk(P0KVtmP+O1lAhr~)*JnwYFeFgxbZwBNP*;$Ut?{C_tY<`s zBNm8|@`GEC&55gw;Tu@p^3op*oB^TJd?n3{mNq0UkiycA4=yPBKq-!$0k_F#d#NSJH3VZK6@vlHDFxR%=jNWhh7s zGIs`1vljw@U8~3p>3aWh0cv5>q5+EMo5UM!&ZJ-~IxAR8qTom-SFBk|7G^jvJwiSL zsVZQh&BRsZ=-#GeWuxy-t1xwFS)$(giYWF;Ltkbw(5u@oQsxa^YYz%uCmkpD5z3yk z_<@ky%(qG4SqkEM3XEFKLc7f1*=Duwqzz%?Ya4KKD2l8V@yGjdqWNbeNY)mZ32oX5 zoc?}!QCf&=-h{$a^P85UH&dd)$m;~*L)Pij4v0OIYOow8JBcEP)8yd`s%lw;W{zgq zct>gyv2cvgBp8{%cW86}|73g?cCQ+w8`m=_79T3uWYf;%`*Xsp1ZhfjCY9Fj-%;Z> zrH#!}d+ZBy?;G);R5k4V=vQbURAF2x_g_8C2o<|;g$rC2nQK1Yib*-`P43!jo5uo`%B1`XrEcy6em}zSdtDV~ z1`q!j>_qT2=VzmoZ~Zzs>!lRXK>^3hKhWa6lzaR|{2arp;W6@8>NIefaynZpXes;d zL$e&pTe8!`DqhGM1p+5e(VBG~jE_i~ZSoLj@^YCASU>`G0~qb|MpF>+G01nOAfgFG zqrS>#3#R24CIHbx)k%VbvP{%Fh3p zLiLXb8aj)B-P?_MvM!DuRm5msS-JOGjWA@cf+3}WA?aY4Xj8B0h^xaV?E;Z+;@b9F zBSg1Q;*kWzg_9lBHYuy94!Lr2Ic_eyr~AHMWc&f_a0|`JG|{O}dX?8H`Z0h~rI-uK ztf$9Pe~)UAdCIUDc=VH+#+c4dm8nSUSgQK(7v*jF;DcFqe^yE1a32OpbB}hnIqHY4 zM%tE+0zBRX2lIzM%#T17p0nuDFbNf6)YG=!p{8+HkNAlP!90UB*LM~y1!_wdaa6i_ z+8$5qZMRfpcgtBsUW;zOcE4XtL*fus(J#7jRi1XfkwfbiV=pRdPq|2mtEi+{uFsmb zuLKP)&Kdiv&C&!v9$C>msJjLMYxzH6X}E_DsTwbQTXZl-ayz1zB#m$PX_zy^6q8%Y zWstvq zq}6T^L;z9!Www&i$3ZMSTUA|ZVnWd8Okkinh4X?qjk4i6fk_3%7C94>Ub$9iZKWv& zOIcfeUHNt`&pESpz7J%w%6XslRluoynx*t)j}nEoK2ls*Z9&-Hl2lYU8_fX-FstW@ zEsJ8@5~XWJe1eP3*l@uLfu&Vm^t7}V)wHYr>)7q~!V1bHJj_o)x>%n_9^|Si8fXVh zgp8{ya_2;-K&uEl>Fv0vWueBvA;wv>p@P+m1*?T3OU6<^71_ZenocetL})}l z=Dionek=<>tX(yJY9<&WL*ZJC`J9+2U6Cfu;8^=7*wcD*_E0m0mKsNvxMi0){q@~? z1aE=<73wY)-zetA?LG`LP}idC6c-1MH@IxOt)#gO$unRkYqr1k@HJfQ^+g^dn~#x#yKvJ?myzT=Ogj}w>A5mK85$kq5Pf_%|BJ=evD|?ZX7k7{>Fs=B zmB}C$(&#U-XgTiYEnHi&fq=y^88Ot zSbQaocfhmfrv|R;uN=ng@_V;&MWR#!SXa4nMSViv$>W${;!Lheg9qcY6&)nX{DF*D zwb@l}$t?#%8=P;_Xplk7Vzz#>9`ji#uCmDiLQ}TuU(Igek|h{0!Jnf4HSiyhKrL4B zog+n~*H6Dyex=VtPJi5ICT8!dyg>lzE~0!&)#sf*b!$G)%+Wxom~-k}y`AW>81O*# zi_2{Y!ITm|pzO}|QMjM)7k&s!z(lWqUvER3nS*xa7Rh$z_%f*Up}{N7&CgS#jI|SU zI=R0_IyB44ka0=;55eC=XL?&zUIbGHR5BXm{%GI}(X4TDKC z$V9ag1KG)PP-i}E{*5L`Fl6KvDT1{?R7pbUJjvN1IAP*kX6n^&)3%U4YbCApK!^K^ zAKPFAh!7ygZj7WQ?Yw6s|Hm^IlPDpV1>`e&(}r;YXm zcHjXn78|dPwOA4v`y#&JqKj?c`0Hyfd5}ew=DuEJp8B?n-00-n{(#hs6w&KnQz_Je&XkJOg4dumf@$07u0$~C_qAySfo%{+kczTn2_**IE9{T9l z^D+LX&_K9wALw{*kQ_`Mlw-SJCb^rP$gKu8dAia0vBR`rRLMxoE}&CHuFYPbejQZX zAL`cRK46cT&Abx;0NgpM^ zD>XqTP(rl7dt{;f(zhb(`y7OR|5;c=zq3@(MsJ<8(?&0ovtqCH;yK^DJrCXVeG*;` zpZ%ZO-d=wZkN}p8*}Da)@0Rhn7|#K{DHdaIM@dbz1U(U?BFkVwVa$n|;6SJ_d!h80 z+tJ`xbq0ero14KCD<$Lnuh^Xf4iRD?V&Q95iE6z`mYTH66@7!wYflHdvb(zS9vY+S z3p)!+olUIP?AO#FPGbdiqV(4EO7}4EfNJ6cHWE?dcr5@_dvcLLZRrS9Ct zUZbw$JP4tF5fEQ+dGs^RNNn?6Xg1IC+eu_in&;k+f(-97k(Ja1DUyW@g1SnaN8#Y5 z4C;0U1?p0ErIps=fUa%UEv^hgmVYO(DjRX0$v7eS;XAi-*_)k1L&v>Et!qj22Xko= ziI(BrLa{%U6gOp`FTrkuAsa@S~+w0l0`TX&3>q?^I4DpN+@O9D!>+1|X#3hGP^D+Kom&ZwnWU z%I-;4>K-=MvnF*`$g(stIQn|SMj6b(RNq&RD}Sb7To;y!u}IsZArgaT7osj%VqQ7E zq$PVPYGX~&*3Tn^`P^eT>i;0b@3m~rOFYW{$#dU@rjogML?RopB2O1z{2Ryg2F_o^T^5FRt|-PO$*T_qXEBaoC^QGnIRbW8lAJPWO#skE6|9 z(Bc)2p2f>+cpU9@eq`Xe+v!cgp+N&4v|yn}Nyd4aaQY_a3-^hK+H{qb4jw2kk0>z& zM)8Kf2mWL?ph2ZU_;2b@xW8SiBCqOO)$T=Hsc_|NIfaBK!zQM_#D-Q)M^*W5bbQRY zQ0LEteE#PL%=hXCg&z|r4a+~&e#~;SzilxTwcHzABHj2mS=lttlK2U0Im5q{agD!yIi8@exIxZdm6JStR-QK5jFqIE57w=Y}# zXro)iNy7slt@o^g7W?BX%(z*nb`|m55la&thjV>1&~WB+?YQQ7`oX$!LdBH$MSQ8} zT2>Iti2&|Fs0qWqAC>29-GJAYWkH(r=u7jaSt96;hTlmTzr8$;YQ9?dWM`*bE-qP- zRBh*FHc#N8M$+6Vck#6MBTdx@;IU;@X>f+#z1XWV)?K0YAIexPqi&|2L_H5 zcMeS~v`19!p;S$+fVYp<;ZYf(2ib`QNdG2j1`dn`sg}<7d^5U+lzXBuVs5vYZRx#L zv}Lt}0*X@Mu}!<`XMg0qPTOv?Y8eT31%=#EQZAh_TbL9&j0?6l95o_CtCh2bTV+&O z?;Om}PntEn?d}Jhw?`q<>v6@x_F5!|!H}CVukIvj8Z>lXAfU+|xhhiXBx-UI^|%~s zND+f1hubO;5hVG?MJlK|qXsiF}B&knAyY9&h24P1)@_B=yHlUc&A zcCL#PF$f#X1{;amzyM{Y)Y1(4p^PRj9je#gzP|r1NiZpm7|z$QDtwzr;8x*kc8JP> z$)nI}wN~l!(rRG{z%nwN|EWc6t^s>N2YU|U4r9)c3uEB^2Y~#b^K%H48-8MHFYV^T{76??1W*$+V@FEkkB&)6#bGQKv!nm=L$ipg=Rt4q^(c2JM0d z*8z^JaD8=i(fvOGt&uX)=kr# zn27P>u`fP@hka&qR_x`VQS4$*5Q!VNL@ay_GhEPOZTAc1ORklJ2Ig2yg1~r`t``7| zUhXEn^MOlwg7e*z`vTYC*)T@00^>(Uq?#b4`4WegYN8G!Sw5GBe-1a9Q}Ufy2N0iC zy>FaQRE{rj9S#Fca)}DVv^EKbLfBe>XeKe>Y1}zZFZrS8`UVfQ1>45+(dT5|Lvnx6 zrvMSIuW`{g;Ds5$aWj|yc{0DQf?gl80NtjYc)6Qgmg>ez{-Vpe-s`$S2K`67c~B|O z5$-K1944doAX%#ET+ryOm!ajtKFy!5vt(&G#jf8)`eFqkj;+nb86@J_bgu(73;nFD zKR4(=Bbt(hiJHda&6}klpOYXxX!QVp!{---Kh6t*|D>054#1O(`bL8sVNETB1~i14 z;9v{>stow`J4oWL!}d7#wrmDRnT{-plw1T0g$jvQq5LEQ!;|I#2dO%x#PSD6S|k!* z8~bb<(R0_*;?GM!U+I5B-Deo{9RpDwE#M@IfeeE6&Ml zm+?z_gAg$!2MFo9vz}daJ&o~zK$e>=dpGmX1)I(o%MDoYF$Xx1^K|f7F$u0G8Zw61 zWvQIM%7yE(40j%2DgUAI-zRr6c}!0nWa|nC~|~m96&w#}<;% zm*J~f{f_i0H|ze-SlVbk-TqY{A}$}|!z&86|A1HOGDFvUPdCt@AHLg3!qR-y554HH z-a4D+l{&FLm%3zn=)HW1e>ogW3Dt%mr|kw z+)rvT)syPtyB!1GM-{Rjci+>fCS*0;wQW8%i(M3Bg}M)gU6>Z$_CK+k-`fPHQ_s_W zGw+I3gsPm`;V>#XA?I0Pj3-bh7RgzcD5L2`wX zoaSCJ;JAm!@%HR;lyB;KhRh{iDxE3c>zy$;U7LAv8lsEuXJcmfjoeosurzLyc%MeL zoM)$`AJj)RF7!iFPXePPPpe#}c6OnXl~YE9#>Y$fLbp6N%ehnSzu_eynB3+&=h+yU zQ8x?d?6k-Bn`OB@MvCDQ3Egk26nM3h zG81$UryNHdt_q~Ywi~|9vRt>4?lFzm_I$9Xw|#uSv!HbK-x6sMWl*EVRb0I@eFwlS za9{s0F7my0sf%`=)5PpCCHlBZDh{PGjr&RoXyVUkor2N)NSSad)T;CQe^@I#FvLtr zX4~8TIob<*->Qn0W4X{VhK%(#CYmfCR2cqCzr_ULUGfbu0BI$5)IWDvC6Y{LJi1CF zTu&)zaUD^n##)?%et4!&1PbN#g0;Z14KSErZMyyCyrum|0AC6O z6|{>jZFw(R;JKWI!&XV*GDa#=0*uVQvwT*UevYGw-eU1TUBLek*`<1(zPlWc+c}HR za9t|v8E2%DxQN&Ap6k&yz$I;8exSOHs3^fzGt3;VUuL-VkVxSSq>i%`4cvReN-r19 zn``@w2zNp6r%v7qqVuygx8LKmTG&b&_kIdT(K{1NQ8t^O!X<;WF=X9*Z?>nK^t-JM zE7mhqCptFdiN_XC7NS^k`(hm;mV#I}z~z z-Y>!KL(!o~da^UiHfI{Zn2m2cRj{V}@-SvT#5*JgiDMCB?-z!3lt)B0em+0 zJQ|CT4`5@iI*ha$GGojUUEm_N5v7F?q4SO%5rn`{Sgw;FJQ_5~CO{G|RP2HpHa2~v zSs$QgU!4T51diTQSEga2UXTYNcjA($@t6Q_`d~S?VGNIX)n4{`5YXhvEv+X()@H^v zTZxI~g4kRijK4sct)`_tY}ev0aAtrx0AtXD{bhY$Oz`fU6h;W+5MvBNPV8xb+W9x0 zR=%bJLMBqpaJFLdN;d7sy|;9REBhZ;nLMqUf`KbOf_NFhYlX!wI$_m4A0pIg zPPL8uI=o!ZCYjs$t(D8N+oB^U+!d=V8uZZ+%0IRcw5dogLZok1sP@wi;tp3D8K!lt z2LJ!yHrV?pGJHMppkpQDH*Q8@N$}E0Ds5vAntq*s_>!^PBAD|7!abs6X{p!+$KXz+ z(0I8&^I|}%t$|QoTC(v3l#2^Oq@Qo$v(I#zulUlKuJ?Qb9-7=Z*^{N3xlDpKolIz8 z_Y-~}jU5}}x*4WVHfJtY`;LG6oL2d`_qsj2v@@UCDK+vwXZgK*O2RVHU+P!ecNTxox`MG%Ii?B?rCSe~#hWuA~oac#Q2pZLAj7Nv(v z9!@S`nsmJYUY*Yhyg^J`U1X_pL|yEBvjQ(OG8kTAbVJvmW3~QZlsD_vjW5397ZN#IDbrx@!{DD?I;#`OH8F6D{N}VDHM(7gY?g z&QU3_Z8X#zQd09=*=SRE4;hXmmCJ{J-JXgO!E1+!>ckU>w}D#x!FbZ=+n7J$brLPL z@A9v;&d>R5Ld6t>NUQpkK0sDdW#o0Jf*kCABE{F|Yw{9|D$J-NEq0Sf(JuK<8hw%1 z#j?@4w%VQDtBenVBd_Z|zuwSf_~$(YEMzm4GUy0BrNzfyM#C0Zd50jTC}PvY<#j*0 zNH{;v5B?(6m=0_*Vad%}TI9?kxj1ma?D(46*ElyD-lVgc&gVO&{*1xNk=wVJoPY0= zCFy@6vyz(ye0k=s71i~W#L4Q9UU0Xd>Z`{l{6Y;|)+omc;Uz=*d46aqRfLC+$W7GJmKW`i;*m?#Oq;qSo_Gj@%->&=%>R>)!t@Jsrco3d_kk_ z61O32^BufLmda;4wl7^CrJ%J~ZX|M?D8g=d4Rt}q@RghluppR?^G4%G^Ex4 zBBEvYAr?D>JD1fAFa~}&sTD8=J6UadYHDsS*C5t}q{W_q{i~FnqCb{w3$6OvjzF5I z?ZVN@!`Zx<)GP^sv}H-j{POf3Et#hxO}wQZndIic)QNj%d4q?V zJ2H_B)~sMLOJNQZ+YmHLsEvm9H)XC#sc%AaU{YIRhu-(R$7Loabiy5w@aj8G?#7UX zK_^^5iSJ`ieMa?GGplcO&o7(If{jzx>+hPN4yn45F5#a*W-#t z$lD=7CFd-TM0E2D!}bJlZQA@o6KD!GQviPo3ce7!%2Av%snt86BDii59tRXWxn_dz z#ibcSx*i>D)#DysxJVm%Uj{(*q(CCCxmhs@k{7fbfA9ol@&ohBBk{*c>SKoQZ@lU4 zctBm++vgEb1e<_|)@G-R47WXhh~W-!&8y2T@0KZe&Gm6UX)Yt_54|`0HKcaB^dvnt zo2fE2vFpkGrGVUIdt0 z_e!jxj~1wE=K`5tq{eATp5kG`qm@(#!-H%F1AH3x2IgLBv!;6;M8(bxEydkAA=M(G zd!BPygV_A_-MR1tl>Hp9kgPqfsOsbbW736SN+&GXb{_;+l*jLdvOcPO0R=+c8B5n| z?iagM*fuG|T~q`JDS)63QA_jXt1O`K)d~-E9QvG~Uhd>4T9`O^QT$II*9%22lW4O| zpe7Y5j3G(s5V8qZ7-=i~iwmV;yyus!8~V<@AZbEql_8y!rPja6iE9P0ppg$UM)Cj9 zKNqv5p?powS=BeaLT`qDFH2yr{?}3`BUoMC2?N1PpP%Xe4D9uzc!+-*pOBuO&9}iV zW!m-&f221*eYRSY7m7MCW-TNpGlC%iVAJltGW)FP+{pC*BWsun`j9#4QOZ#EkdZD; z9eX<6yN&wV$IUvh4_ZvSB-6+f-g69?Ae+Ja_|vd*!cDpISv-;E|cE?q8qi|uNc zDqMV)RaP1g7jTm=(=1MB2Abw(F4u$XPCG6q51|WR&rL>RDIDx;lG5PtvQremz{Yp# z^63a?igEQ%ObyfT-LJJ)?v zg_9M@Qx0PfQh#;i3ma=e>E_Eeip)QKK(`wiQL~xw5sA2kB%QQLtKE8eIASXeu1(5r;=SED*&@T)l!M8*#ev75qKM)D8P>7yL|>Txpv9nL#)%Q*dRZQ&Y$;>u-9 z5-s)5Q7V~gSAy7)h_RWYG9Rl&YagtXVgcAeLs}u*GAVYSjmbpp;c%>x*c->fw$2G6 zQrm(obZk}&?pcOO@kJ-Qd(%=$=|wxQWOE5^blh~qUaCt;>W&Am#yKXQ+oTZ_v7D!@{9c89pK+U`&^V81*gioeU{7+4F2-68vJ_KKv8le|^Sv9m z?J(QA9gNSJxzR+rRLIY+c7xTyEo1WyTfrcL4uIb1&_jWDm9R>WugKdI75uHjN|!ua zeiczp?E`$G3*RgTw%@NQp;tFsyR%@XD2as8t$oEXgtS-?X2O!(6c|V@{L0h5U$vFU zk}yAEfw7u=(nK6~Mb90djd{*}gm#L?wOUMMKN1@KR_SrPg-pp=s3;yxcke)V{VngN zpZ1!k!H}oFWAovd=o$LJB#;udx#%H z9ulhW-e=lBEj3uMIe43hTUwSgN0XdS>?sqN(Y5F>`&MpVyAmYx{xH4FR7l%d0^b?k zzw{}G+2+5O6i5yDL0{CDL}TFRS~Q8Ug54$@0$59Zl-Jb(+K8G|vS9y3d*}@9CzGu9 z15qH82B3)leGlc&YkKo4i2q4@C<6F@?n03!+(S2l$K&&CN*+JU(ghf&0>E?{w|LS6 zDhsH(zN~;ce)vvJ*10{nQiI2BI=6j(6_iO(WRZK_)n``Ic*?^=%-w2;l~m`_=ry|N zH1gaGn}MiH@0n{-rTU&|%tfk8PowZu%y^%h)#zkcw&m@JdCTcnJ(jo2*m%Jb9Iv?{ z?m>djYy$2?``8oPX4JGbf}7d5>)#DpD$Q`ZTrfOpJN8^8pWNe&9$L<5+WMtygu(r= zdpIqmc&%2-oJFjX37tI89KXUoW$T`>+y{d1D+boqrJATVS*7Z(l@tSQTkJsFQ zWEGa&zVw5VkZ6|5n~shTFo*TuFkhqiR(@ikCgFw&Hx`P5oCnT~9&O62lw&#gldE|s zBdT^(STJ?;8`apY4YnXwl7$n(k{0Zlx#WHlKB-<8^TAPepRQzV8$E7Xj8(xO<*zE| zJ~Rrh;wN%Hv`G|*2dG%MzqC_b4pMOn7zz%8kSsfru3$jM2VwxRF%No_$19R8B$Q9i z;T6-)h}7kXYSCp1YrV~N-&i}JGJ<6q8$vo$rHyMmIg7-(>5LtVxvmU$i)X5h>(Qht@t?CZ zxqr>hoXlwizop~v<(OT0EEv!RDH7h>9s0M~qd}Ck5OMfWyt@^3T#}1+5(N!3RBh0C zJk1xVdF=E5N`CO!Xx5&>wObW(-~R9G2{l_{$brk2Q+yJBPAMaP7vh%i$Iz-BhDtzO zRjch}V!dV8xEJ5s^eerLf(HVU7k3fghSPn;cOOaxU2b_aGeSS`C4qsMH=-2R6?TK) z|B%ZXY)TVfdf?)<1jWun(~n072E>4MPD_p&(j`XtHU}OUROv|pPp`BCyfleLJ#)D% zHK!oC<+DNbP<&39rFkwLI_)qMz<|YaW243yWRt(*wwqVGMoO`98o2RQ6dt-(#&B#otte!hGek(Zv`lq9vY?cEwY*hGUvXSrcX6$SJ3y3kmc|S4G-{#biqd0(shLG&7c1knY=&uVrBh7&mTGUhm4T9WMg8Z3> z71j#r=?mP3iIPb*P`BhqE587H1)>D2i$PNDI@Rr@%nw@a? z5uB?P@qT_)@n}UTaXn(;X+qIsNYzd0hCGT@(F22OM||cyU?b&&)P1D$FW_d)S&U5F zwhmX99+a5qW)R{L%904lgnV2kG&*PbL+JQ&?$UL|@ar3tmpj3H(a+V4+|wW^_T(yW zHZGL}adWe>h(owpsiZFAqh^ltdP*=@!1|s3)n>q+?m#1!#puj0!)uIN$^$1$g>M5N z|Gxa-gR^GArmWzXEWvG${^FppUAi7WX?DybdKrCJp`Ydm{u?DO;%bK}(6 zFZi5cwdo4gz^nLBETTDUpED?;~` z!Q8OWeHMzeu&;P_US8$|4CK8bYw?PScmn14Fa`Kn&~mK85w+UI^Z2v5K)ui~C{VB2 zG3m9Ex7C>mBqtcz%QNh5o2y1|b8hwdKk4sJ40!S^Tc#kOgG9<=jF0Jll^5OY+{zDC z4{uYRJ{F4>7j;g?q|#Ic#86N2TM!P9rQW0~qo)}BrDmN!cA3##k258ace1fkC~qjr zrZu&XJ-(#mh>A=z6El~?AUHbU;0fOYVRK?48+k%Ur;+3}Cmi?JEgV`#i#a7(Yt#1A zY6m2B(W`~hf;F$h^XMF5=Dt1n3gs5b;Kn5r~8o5K@)XM$nxDz-NcL9E!} zpGrngNz>DP!<%Pd*O8GH8tgng$X7k9r0wD&FXpl*>|!*V@sQO05=qs9w;&7;ZCEvE zXh@U7^OvCRCAdXh{HN{Zj@fL17Q?6{4@Rk`j&Y3_N4PiJJ2mRKV+XsFn$r4x36|3e z=&{f0K^VTX!|dXXox%Q0!}V-3v42!deS0}0v7NutIG5w%y{@8n5mvbMAYmJwH6t70 zlCm*F2n~^Q!Pzm`a0znGn6z?*Pnh-mWXTX=(CGcporMdp z(`D=x5i*;3Q$|kMNj&!cJ=}O}$ztHm)=#LL$gOgT#ut@zOi#YPW|TF(d(-PDb-D1w z0@bFL1L=f7x^F5z-{BKtGF|~2vv&)DuHoo{@!!?~S#OfXD^rW|=a!|cCi8*YqjPVg zJW|;gCs`hZ$13V}Q?J8i>A(b@fpH5S1lBte;k^*|X0VYp$+ z`n}-~M;!E-)|r#ND|OFv)uHm;(xYr8nURTn548A65w-7&uAEwH!{a(xT=%a*0C$)j z@t!%gPdq00IoWuikU_cYukt&emi_y+FXjv z8+5@YP-z(r+U2fpB@{n01!$3NeQeNxh@dWQ!vysp-dO|)R~9+R_{%V4PJTHzGLX0N zZ_5|(#gidM9)at^s*`4bu?# zIXLpZ4)(uYu%qRTv)crL(6}hapInqO3I$;68~zVn2)=>%c}iO_b4R)c_j4*g4*g!0 z7i=NjziK04*j+KwP!mYET`dQ~oj@Qt@v7*4*b6&nL3fjNGvTk^8*DeK+s6~0eHSUL zi;-iF4=@+UTkx=D^;qidHpA^({>^*w=eJ!~AKGCzU2qp9xb>vZlrq?}X{P3l70Htc zCdrCUJnb0`d+?;;d%8-^Sn4Kxs-$$~nDqwc<7BCL*+^v5drsQ)hMe0Jn2bk5hE$FR z9ydmQ*fD;sa_D9cZ>AyuhkkBC*Cog*rf4hde#J7Bytz720xpc9vZk;D_V71s-W}B! zbsy_im`N6>U*oWsSWXmP&X4#dcKqAnZ|dc-k?V6ef?=!Ke9Igud2ycgt}s>p_T5*kbCepF5zp! zz#-a^yp51-V}_k?WYW1IG4-9ks|P>7%gG4@8x9iD1RdE-_@{Xgj|{ zt)2UraF6E=Nj`4bAT!=7^ zajPEBORCpsqoLwEgDH|bb+{R*=V~dYFRSYiH@{-%u@SVjPtH1gncut8?AVD{KhY|- zZgLI;{+B+@tN8_&U5d8niyyIXeshvsd(hE3m^i0Ub7^$hwk^E4{rv08JQ3#3q5Vk; zY$=xW-0g*cvEofeLAr`#XA_5GOqgq*zfbv_k!XrQ1uE-RYSd{pdF`oPP`ZamjuDmR z&CZ@PqgoowQyZQizb$*cn(`Bi4L+7FLwSmS#KuJ;r9j3qcsQpab$QU_ah&cl?RNSA zf=74+!8`AFcDcm4i9ZLKQ&B~2!G5)$os`budq1qL$sArMJ7~g#m^r~8e{(oWHvQc@ z=)=4$*1RB=-*Pd$!gO}+%IBE*3Ge*nvkD%|uYOeWtW4vW zuwtw>*qSBk*X}>d8XvhQ2c3X8NLXrouuPa4P*S?Brb5fCV1(AqOQ&D5_{zD1&t@Bf zRH;YHQMfdQ-+#zPv|Re9q@SHdd0sR_DP#n1d#=t=dCp@cS`NzKG^UJxkI$dF9}EsYZ%1pQ^mGw+l6gb zdPDPicqG5g80+qIn} zXhNG$Ol}6LM$G)mq~zjjlAD>fNBVf(7dyp0mikhkcBMaZ0*T#UUs*#t1gDU z);8V+ou5w@nKq1mA3v0dzE#g~!>*f@D(`0ek zMUxQl!R!y$p&}=DYR7}yTq;LAjBV@|N>fHN4s8FJg zx?J~jM;F9ExUZHyIjc{0%21eZ{l2;=V*mqT?`&9b%#WOaYJ)F+{F}MIqJz1FR8x|< z9+~)0`sr-a?+lOe3qs;tH)?fApR0yv2SNgdoKe!ock}Brzc2k#HVdA6VpTJxWuXv) zw|y|6VI~ZsN%yGRLHu-_%!EKLPylAqx$>sG-jH?3W5H^m$@kxn1193gX*{Z)*n|%~ z8wuylzBwU|!aQ5Z?w`kZoLph8;O1aRlDOzUJ|KEH}=w748Qy*ocr<@4pT_mQx26T%i zrE*0jdhCf8MsUzK>S{? zV2KZkljTHX8`m2^)pz>%`z4j6BPPx03V90RUWYH)wd{0pHyv$J+0I$BZdp!B9O(!9 zWev6FM^4@4tKPz^kepEs^Fwz7Jq&Q>SiJX3BXP#vcW4Y2&c+>Ryv*`jg}e9pEe651 z6y_7hZOjekR5HTTskjb=pbzxBTO^-(n4_u2jS;uVlCZlG9h?d698I^L+x%GS5jA=g zk5`ELIrv=|9gIq844D~(D{G>h(rs-P*zmX#Z)F$pI!e&Id;n=7oHu&BbeF)Jp6i%@fQjeKypkOG89mpknTO6lox83P@0+K;9|3vhh14 z@U^Yo)+*bdQ_y+A8H?zd-Dp}}WHXCSeksE;JszCY6|8!vDBQ6_^7XUZ3vIqyiGm>n zcf^`3Vz1>CQ&ii=|I0~%$=Q^M&wu+z5Ho)pV@PAr(pkqwDLttF67v2&b9Gf9!kjMo z=+_&lb=$`d>8}*cT{_j4T#5D4k_imk!DCB^$eyk`Pd8kf>r_WhY~XD`R} zu%qO*C*?*>`}nRUznp6AHWrFoR?BeP9GE#9JE9EY`lIEYnTze-{&w^6e##{yX^KX* z21?cgh_CN2C_D`6J%Rz7-j;k5fUA~c$ZN&Ebo*cn#K?vMBdOW(~ z<-O3j{z52XZ9|xVc{|YC+A=NGbv|T6e5{*|)PUGh8{c*CA?Ly|mIUDqOpDg6;;%f_ zeFs9;;_`hsoT%hKc5nNhglmE5t{T?PHOffAl3>Zay)R#@a}rxF3x|4SubRS(rhXbG zgwm6IqtX!PVJjtk7CtB^k^Vsq_lrcn`(NC>1yq#nxA%{LAcBN+gQOze4bsvUqBKau z&@pr)9ZL5gh#(=|-Q5F2cX#J|kNP~n=Q-zh@_*iS*85*emom)EeP3~3*R}Wl?$0*+ z7m?`oFbjCV`v!>M{HK;a6VYH9!lQ~Bfldte1M30t2MBlxstZ!tV|N`wpnghO_gmQR zU`WZei+Q3o>RgtQTSzw&(c$PL-X~uiN~3`)D8^+3)tWyu$7nKt0c-{t#ie1EGVC4% z48H^6l0YDwTV>;h^8eC@M1zX~UB$_X`5g0&5B=6TB-3d~yg@eGNx;(#tWa2k?dqf~ zCRAJjh>nQXZ%i>*YPqtf<9$%+M$TtY^#n4sJ$A?IZa<$|ZXqw_B=X-mhXRMkbwQE+ zp4ltet{l(}bhO-kN50r&`eZ(U(tT|{z+~pMAyyQS8i6jCu6OG$`)`H;;p$?&!|JS% z(OH20)7#An-mA^nS?k__`hlC{h~%~?Hz!px0?X>{GF)XL>tyXsst}zjjBUlpT~E07 zA6WK;fynk`J(5i)U98i|9iha=)qsACRDuzaG7CiZIkbEJER?cDBO*7|X%o1zJ_7uu z)q(No2YJu`B5K62ReCA)P%QL&pyHFloa9k4_91$EO8YcIXwNEzi)z27zz>tPA0Nft z3|KW0SN?rk6H3Hzi4MX~c_L;(LGPf#y<+L`uY>k+;?W2`7KkR~t#yN|PjuKM(Vn<% zeVePv8Z2!Etkp?CBf(Qj?qW23ORhv=H_?&?s2~0vSk+&}lU28ZNkTvGuVd#nG}+T! z5JDZcvp{)=e+>vj03F{ybGxkUu`iZ>-pVR$ck6@Yw$Web+MZ3})IaTUlE~|}^95K0 zlFDZeDLt-tC|z3v>K2VGFHs4n56ZQznzhxh!<&Q_LN;#;2&a#dW-mHqLK@2qK`B*J>Aoc6F6js4 z+aaV11pWcb;H>bTz$iQ!G={?-;Mr`LUgDw8m<@4l4M|2Mhs-%kG^<90H-gYqO4Rgp zs_aHEzCZhWKHS`Wcv7LD(RxVcuS~~(o;c{yvUa5-Az?|FmPM_NecY5?tNlm~{u zN=)jL^~fHPjfhUy!OLk>oU{W_$w)GYhxv0=0EN9cnwpKWZS5ylZc9(JQFaYfo*9tqeNd12CE64KZiUsXr9 zgxr@!Z@e;xEIEzM#3*gj^i_!O?s1eVvJ5PREeCfnI?p$JB-SZV7^RPEF~pF>oy7as z_h>Vm_1D}+xn;(6zx4b-#blzr=cS>UeH=q}96Z#-leEZ0ka3~f)rO^3c*3X@C#kf2 zi)A5&c|b#&bUH!tM}E!+rjJa@h$mSzHzwYWKr4>uL#j51HIjo$@6&#ENECmMbP<6> z?$gES8JlBa<3;cIR9jNI6CG8l2jEJ4<7uSj(Wgon$kM6)2DKih3NO)t}6_*B^v=90yZgq{O=KReS7= z?Os&EC=QDcyY)S8d_?U>H9f3WR|7Nz!+~iVKP$Phx&J0@$(oGYVAxT1|)<+;Q3? z@hBy=AtQxtqirvTxwIgg11_yPfdD2B#cuIC1x`uMHdJu)hH{IgiZ{?C5%N(rnp*Av zd`zAE|B-t0CgZ|%y;7SA_AkK2af5us~V9EoN&BoCQ&0* zRvdN;&6n84_n}5fdrvwLS`L={DccsxJiSFx68lEBWCK+aqX3`H_lxc=i(X&(P+m{@ zP~IFNm3wS>!FIpg3<-2=0(z|CQxE5k(!;N~5gE{Wk6X@^eGCuuEI{I9gJ`3!>~ht( z*qD76MOi$Bl4yf{?_i~?-k+5GmGoK{gz;p}8Xw60Z|wZK%071TI&(rq@-8W>F_X6g zp#bOC2gU0Qo-?x(VP76Lqvfi=roo*<6H-6P0ppQHcAk2}XfK1cFeF1vn335cUXo{0 zBwQ<0^S8+Nu2mVoldn2W_DA=1KwOJ|yDP+o{1+dWx-OdtN@@Jv#CS)a-jyulX{;IX z;$Ac@P*q79RIM7w)+=q!kkUyzxVVL3qv6W5PI2YqcYrHzz}(h*JduT&@nqD} z?19F%)svx(eZ9GiH|c#CIX}?_{sJgk)v|U(nWJluKI^yAhm+$kZeMWm5g%hr1Kk_{ znTz7@$cpNJAS?c$SSi^@fQ?T$w^y)POHX~ON;6$%O)A8U89Y-y9`_+hq>-Zi;UkN{ zM_JTYNmMV4cjkqfTLz6?&yoK#-(d|=#n;zgIVDUDo2J+T)5E;RSss$Z(HgSLZ;Lwh zW&Xro>5rgw^gRyPMy3_2QTM+QjQY9hA=wPcF(g~J5d$ZXW8@_uiFa?;a|@uR9Hb<9 zF5v*k1U9agY;z^CtsxQp!dBE#Mrj)5r*JyKW2r_e`a>Y`yEx;Go&RLSx!_s{6+*MD zlm$2kDy)eI3ma>bmkyzhkHe0i?5J}@1rBCoR`i-G;b79IeQftp*tbh?tvX^b3t>4M z8DTrfKoCe;ME;+Oe*YV61sz(BQko!5D*uw)JCa$J*~m+v_R_JA7RlOwsC})H@j07k zZ0DYl{hKP}jT^NV9z#46Vcwyv`(TOem$Q;zLUy^C1 zAH4+h)_3(}t4YKRHXNRd-8g8Ng(@hFzU)ODe+E&tw5uvIMMwwaH9QW+Co1ItYdRz5 zef~TA+a<$&B9~hLnW}%*+XV1FP~Ypv5UCTRc<8-@%ZT+Z(K&y~gjU2Q4_D$Hexj#5 zz~!u2QX`{7M$D6e@(w7tCeXhcL=Obh{OYg_MRU!g=PwH~p4UA55`+1REJU^xE=c1; zWf3~GN)+{V?HN~g>79zgWA9#C;$O)#5>f3D zV|OR#T*)5Us>lsb;ulwwZzHxDuYG3J0<`Um+cUpNM}NSF5cj`B`+5Pr$zm?rG=||} z2w^L|v7qp(A;QQt2#8dJ>4L@s^@g3QPrZ=1@L_RPw;$8X;++!3T$##jivh9BndviL zp9!HwsUoyVrT$7{1p8Z3!w`S1j|%{rifd-aZ4N=Pm1l(t2!bL0uzjBFi6>>PV(fw5 z1{hE7{dI1aEOloKC#>lQnfnu-ipc>1l7mzg7AuYV(UYiAW$`c~^BRBELxf?o&Nu4V-~Ainw6v>cEcrkFyDoJ@(fV z6jH2z+Dl+S5ZR2gf*+w>e$AH)MI^Gnb^Hh}sa~70Y8^5+`Y`=~M?Pvi7i%4lL5Ju# z>nB-@|HC2!m2xh8HjcI7MhLr{B)MO#p9@j}4BNWdJ0{9vPD*<<=>(}{(@2>f<_d$K z8C1+uSbp!&ND9*oG13=LhK`z%iT(~3qWoH0Ura8qVlJR-3Me=Nb*DE*FuW*!oiPS0 z?JWN9oGh|Grt9IFzksOViVX|+=VSle4J&&78Efe8*vaA@4|sIy&z*PkhEP+((0}-k zoxa4jd%!|lDnVUt@y=flQUF!sZ!{$P+h7(J&SsP7_OPECm&wWxYh?wGdh;^(JwpjM z;0reV%Pd5Ftj#+Yv69 z3mP4+Ebi9bDk>8hiNFj29&QM9`qkh^cD~L_cho4EcBSHE&I|{(hkB%j@9@oEK6a4c zDSohl!_M)jRGKZl$|3l?5#fPU2#*%%$MNJqrqZm|4u**)O7U~06hlFQQtVtAd2W*);V_804BOb)9&siiOzP$hl-d$BJcl>sjv6j z)Zgx6tV>(?uk$nEq@^}=@Q^ zTLh!LUj(BXP2yIm2Cf?UuL~M2PLa3_HuwVtmL?JxP z11(>MTEFx33^)wpZ<%?P2FJ|5d!%>oU!ze8j}((Ur!<%6K2=v0hvy%)QyQHDf8D+U z(!_?Yb>4y`hsCa(OSP2Kx*O!BgbB2cT(y+F;NM)?bLKd}s9($jD3!Z4hb%RF&whCZ z0c9W%lt4A0U=v|zkO>S@{=|cD*Er)JX2YDV{4dkyB(eaCqVmhIK?KzIe<8B9I@y0D zWZxId1j71)ZHaRt%Y#4c1~yFezCw``0cQ`gq_RS6K0}bdW&=6{LL|NP1_4sWaPXJ4 zpM>BwehNJt88o9Ja)vQr7v0?DYfL2#<_e?=?t zOT6%sQttG&%Yd>jjKlSHde=!z^_#vjII{f)o$4nkJpD7LXoXE1>KmnM=j9PnwUl}f zILdI#xxecpfGIEo;y|}<@RLPR2wVe4-0#$uBJ83B=Z5x+z&swDULE$=|3-(xkw;_E zAn!fjIo-wRY8S5W?t3b^I{JH5>{0a6lrzpbqrz_ov&NW$>^|9fv2<@a=X@P!v)JGv zD*4!0s77k|1gUCGy+%tD$4fq#$>G8@twhoE^O|OA%GifJ)oMGQ#w?%bHJxbCptPaM zEQ>^%yEM;h#^%JvJ_1nKHO+ttvjFkl&7lB0A|#@@)^7}Xr(_6zPGbLjmOrKgfVm*8xk-1mp%{{<8~2sp}&Wxn|sMh$@2t8Og>zP2PLd49k59KA(=Gs087`9`1oB>_2sKA;Y}wA~WiKNTC@DmYU;7%~ zep;t6-+z(#n@}i(Nv*F68Qy}RfV>C)f+$=?`q%D==%f*`;@&a9Y2aqI?rWHcTQg&4 zB3@MB@ZN0BG~i|A8)aOHR(fcrbUHm1Sg*=XSe0uFQH$?RAQ$_Kaw6s-I`l9 z`pZ3&PLR$?5p6CMnX+ft03=K^pmhLgI&XkRL5;wyrN2Dg zJr$&aClyZ^rMdyggxWPJ)~do)Aa`Ttw`aS+>kJ!_k~D%o{DB#MQGC^xQ^zyLp)iWO z*yQ8$#(G3R(inVVK0JzXkHAEFb+Jb+BApu$=o$JjaWXCh$hR~j%6f>?Tvz4&lT!~N zX8{Y|X_+nsCM;3IhnEsCfL#4ql_)jo;qR!U@P$}b)00T#_bA%CQVdw^J|jK%FZTMR zd$^WL|7L#wwON8W>po@va zj{W_0i{VBLAS3yA1C{nWDEev2oITW!P%=t`pbFDNmx5$!f?zx`0HE;CsA*Mw(>fSO zCjR`AEn+2aa1wLggFONkO=ZFn0~70hj>PdNEMD006WHsWt@?{Wpc2Ga(VMty;*nMD z`h%L&f~2clVr=N|P-ykn z_!iA%@)%;-6qyu>wYC^l5LhmEgBJ0lMwKEr2e8l;4T-nlNz(-7SXrPW4rl6#}Am4 zFG}I3F+F}DXW+E5|9IBBQ#5cBt)q^j9_3kYu@{3P1qCysNPtt&*8xecl${_QZPN~) z-c?HQL2!_?>4Km(7SE%W2nR_jj?zfC-LM{F!O}K6fV>dQX^u1$0x&?B1A!UM4o{{> zFqHZpM|_fkM7Z#8f;c196#p(`Ca2R13DhI1VhIn}|8dqvI>D!7z)VMZZ(v1Th@Fai5U;mda%g|GS3dhTpu5;&01@x;GW zKvDC)jG%6#SJr54DThnMyM;;>zsP>~3KsY()6x+*Lel8FG0D7wio}J-KIv53Ic6pi zE#T%-$(d07@3<6a&yb04Rcye>wXfe+qC&*#FIR8@~n(i_^_4A)8C7 zm{<&#^+tN*&}o@jQEf^hq9`8aH*b|Tr->Zw+vS}-Ckd-i2^X-rPI7E=hH6Rg6(>QgR;-r+O-G6^+g9S>#GhH z>)C!2LZ|J=g%^Q?TOYs=f-`1DUMdS8_HgzCjyA#?fP=WTkL^1-8+eDpp77M^=`&94 zhl34YzIV%-r^}IpFa%6tC9(HQk<>X+5A@@n_!B?-)A4`u(D)~^*otF=7(7yLu`!BJ zZ8kDwl3DObQ4J{s)x0L{`@KocwVpJdo~&}q-Cgs4$$&m+y8GV`rVRS=Xnkf`H%E-3 zCF*OOb4UjYZoE)$XR{z2Jo=q7TfRWiTZk{dX`+QyYe&;&3`!bj8o6U6BA>;05xDca9 z4Nytzc=pl>7>n7;gCsM+(t*SF)j{iFqBo1A0G4v{bE@ldSNQeSZ#4Mj%xPV=@U}@m zc&zw}qywJW)CTN__G9WPK4)$bfD3f@isCk&XusdD1Hd2}_i{?#4W!JY(C>i^MPcw{ z1J#Xe^C~BPa)Qe{UuTZ?@&{$|cVR>1r!$+zMhyonn@!i#;6Jo+-zVkP&wOn0jR+E_ zI8X;VP4S7 zMw{y1S*;wc4F_VGXgU8#mQEeppxQ~c_Jl-ccu5S0L=CBT(@7B71PBIu)rjH~a}7wL zDyMY9P*xCo&;&AsGzy^nmTF0xX!D`=lIaM9j*()^G|NSWgTG9m7(B%Qp!k#Uq7sP~ z2I%L2`){qKJV&Q;dIePQiq*b41ky>{EE{W3$lnV1Ui5o=35rPbP^%U5AAPs%Q>E=y z^(WHYpvULQSA~8hrcpF`*-F%E?mhSb&h3523MpYt@-f6@OP1bz5D1y4?Ubn?`2AVPV#@NcT65BGhe&+X0*lw9pf>HKReie-o>AP+G&w(Fh%!-cUDMaC}iF{Tm^nZ4vft% zC4byja-)?jn?B#OHR3*ef+U{~D?WC8zH%s{LheA5k~YTv7zgyWH(vB?rX(t zEnm|n018I@`U4aH`Qn$qw4)5D2l6!i@kbot*+;uWX7*nfs@+9=EWW6P}Iq zS{J^Zip4i?d^pZXvJH7kl4R( z?0RQ^x9s8brR9ln~P4K-R%mL^? zHL`Z#D6)bVY5;}?(VnT!Zyd!&D zv&;;d|LnF%I?GprgOa|cHBDirb6Us^*Mbl{kH1=)=S(BNf6$4Pq(0^H!~N`KKb}-C?b>Vbq4kprB&~n^Tbv?c0lS&O^Y+ zH!|j}IcxoCl@35BfFL!s&d&FP4YhiK@>>{k^#sq=`FbM<7CMc;vvqOCL;{g8iQ7O{2yL!z=+SQ9W<_yJVo zS}x42y#U&dt;A*Q94iZ3VwSuAIVMeTn5Y5o?+yU~`Wf2x>N}bYoAFB*luNDzNiKN} z!wC#W1AM+u!3c-$t3jC8x3p8mM*X;{XD#VPmK(@R*lee7bYU^q)Teulp7f4`38{kP zw~?bm6DV35r{V-)9>n2 zhg-*`@wF&rkY0IlG6R*&_I|+Dl|;m1IAAdAhs}Q=nI!d1jjE{-JVe$#2Yy#25phh$ z^3-TN*%Mo0X~6ic(dl+;__(cT+>gXo?u*+e0iM0&2EYtyG#vas6try;=u}>C9`7#W zmPw%rwBNN)>tHY*Yix%A^Sasz7JvDz5~h9lB`H|uNmlaAGn$IvheD^T;hgal1U09% zyQQqh0=)d)yD{9^$+*~We{i_ZH^KBH=$~FVSFf1nb-vN62yGGrl5g3zpN=FH+%z_G zlaU162eHM^6g3{Q?nX!)KJWdo18WqF1{?2gQI6N_A4+(>evQ}GRc#Uxv>pF_DeD?zg&<<8w6--w!@gH72S8R-UH}UNA^ER`L2wV**N83E(d0nK{d!Y770XowER%-yMnVJ|+R|}5gB-HH z>&tmZG!SX=K>c~LqZ!P6fAM(DV=|bsg7djc-Ch(>t2ME1J<+%c{+M97tx2@`qEa|{ z#=%Pvwqe%*mYcHc0==+RzUMPP*52$d zW|e`w25+-YQre~br&4PK*Z3rldalWOVjhEtcjwnYu)z133+JiYqoxcEX~js&LmNZN#za5-T9_$H7}0SRk61zwD|b{TZP!)Bj?H!4obQOad?iKMqdtgYm1A!;CQ zaG-l!=v+n@Dj^vjFZ0NWnV5aT+&_|!*Sy3(V7Z-}W{CFIZf(w#Q-BAe1G?_(e~rDO zs1(w6gzwmA&@i*MEI6-GppYs!rwFZc3xY&j@ZHH-49BTic9^3M^gyyVHYadzi!>On zmnq&hKRT0e=%(%fV-m&`4=agzz7Lea>laP&4s@wXlNjK}wl-PK`FKy{6 zIXnBvHS-TZY!s|u8}K8~?}TGQchos0MCYCeeWT)>2~F{gAeOMRKBqTV3kP>n-;14P zSi^i;g;u*nXOJ~ko&LpAo39{w^6?-#`zn>zZs6ees6;EA^Q{h;7kz58N(FNzY4$F9 zoICbW-7-Bb2299+Xi9kIWT1|_<{b8F?y7T4Da{S_E)9&=Pl8iIb6CrL%b|rRs!pQ% zwq#>1-+vgTwvE%5UCc9I1JS=0!+3Sk8=Lc*pURBBQH%j$kVxldq>p)FDwWjM8jpnx z_FZJ!UU9xj92T~{fi@k>pgv-KpIx$yRsH8oQA=qhCVNnGUjv8tBRb#LT-`=pW3D_S z?uOXUvfAWYZYXpQjr-i@*|2kpYP~pBj2#ce-p**)*@+z4d_=zM--i5X->@`Z3x=HC zr59BuKay8D-ti<|hcx1nfJ0cX<`&KNHLRLMV(V__)8sY?uV95zlb zx*%8F*Q<%qn8qH7R`V^?P`b21ra3I`pq@lemDft!t~xBHs{5q(&^r{ZZLT$?dQP5Y z7A>40hE0-aQaCJ%m_Ua4{q)1tGoR}v>-UBXN$Gp}72xigjn@T}CIM7WSqnx6piebO z3XTctWq)V_;My*x0SK7IDpf<$^n zM&uw8GOwbu!#*&e^&rwoM)Ms{$wabNS38qNCpDm=G)p?ZZPEGukoNFZDpDbkPnA#xb)(Jy7#tJ61r(!9 zqz=`f1B9Bo@E@tkQTqesDlGftEy zENVD8owJthz7P4qBDl)amc1txtB&z~&7s8wZW=lHT{o`nn->IicgJd6wa^i5a1n!$ zO4Ym&B_Mo36B}q90MuHQf$HU1#THt}s>o?2_3nHdJ_Si)tA`>mjXamm^lcCKpXo4A z{@mPHQar6L_usz5lB57is+@Ep4`T_7C0MHNVp*)YjzYZ}ERso89rLZT<@B+& zWNir*R_I5+n(?~G&_{$0-#(Xh?`*Q*7u-7$k|Ov(r0bu=@st>h1HoWEw~@>$XRMb4 zW&;YO#J|)CyNPkzL@HRjD^5`OEf-~6^@v8WVq@^V?F)T~!fNr-8x#AT2C39SSifzP zQR$mhckCoR1^>P11v^Qj#8>XFN$v!8vwT%wE7dmW&InTKlGA%a$+(7yhIyRm{;?E7lnBk}mA%l`KaLwjsr_bs6^sYh4r?ip|*sk}>n; z*-mbYu`C*^xSSV{ynYRezp43bpD%s;t}2#Fy9*e8Jw959NIU&(1Xl~$%FhP?bnik_~QmQG_R&mHqkA-u zLdIg^Y%rN5&Ek!EbtH~1awF5PbP9uLmXxgCo3y=+@qNFOgh$k=HEoD~F%^2vAhQ3F z7ubXBS~iQ&mppYkKLW>qbSco~aBocf{^gfzHwuuZMPAk)MLbca|6=#WB4^~CD zXBKEz>k_sfvO5!zM3chK)=8Z|k&%|H4xuOj#}1O(DSu`Ubiq*7cAVj3?N7wgp!is`6x?|kP=26oCH z4;ZLa0;qJ2C_EY>PaVYoI~H@*c6$RCyA>zUr@9>%yJfJmBTP>?0Ns}Vo06Enbh9zv zOjOMPqfm!4R~cpD%7R2m@@uR2@;B+z#Y?W~(>m3usV-SM{#X93QvlP9yu-<9iH7o{ zV}FV;q$s9GWvmB#rO!h3Ms+WPt%VLl`~hGVMs=%mIa^_N$AZs=0;Kzo-t5O{DeZ{u zo(yi&N}DRrinxLo4S7(Ku_E0adK8XK%R^o;r&_pZ2G8I@G)vl9AygQ9#!|4D-N>W;&onNM>A!}y>-ZDtCCJcv&v2= z35&{o+n*4A5HRQ~)64d5uW|yrQo5r*+60PuZoMs>)UECdS$Z>jku0hi(NOEfH1Rgz zW+Hv*RQoL!z%(aDR(NrWVc2J@01L}0_HnVw&};>YCac= zSAY1_#Y?3a@_4(2Ky!WV;iMw^a4>TiHy6EIk+=&B#EDu|Pw+W}kTSr}9HegtMwEO8Bw*p=?f;?Ko{1 zp%hgR6|C*ixvoS#xlG4kra7#Db>;6TB+eh?y6@}TLfTMdI$!h6FPn+eA ztYYrs5y&C-W5>-$#JmhQ!$OYrIJ?u&cR)XRkz8*)-SD``6FPG{`J=M?bTV1AI}E+~ z75yqjqG0?2qXA$o&oPQ3&oh_nhl|dI3GU2&ndkz!?p;L9`{F7QO$s8o$FP5?WT3)X zrEmb8rQJ9Vh#VJ^Lrn@!j0?SoHpn0?#4~KR64IKW!9L^|^N#CWT+7yLR281mU6(^<_U z4@;?CKCU4rk#Kd@7mSuF$jMpbD~aWJFf&k+&1r4>?49PeW&4fBCjEe};h(iq=!FxbWf8q_3)H-YWCf(IlEO`}x3{`fZ}#j?G6o zR~%>iw-Wa8TKXx|Rg=ACkfnq1;+5emj)X$p;q!0;SJg7rQ&ngm@Br%HCA{Oq)fhL} zUD7J(F<9l*%>UYhuf!HMwY(ZL+@XreBf+
    OY=?g!x8u^OT9-r8Hl+V9sgzi@ne z#^1qI4Y{%W`Vy$=ha)qJ)^W6M7A15p{gj{bj%Yzi|5<}A$@tN*59x}G(v8()MajbT z8Npc*dGj4Z*`9fa*;JEhjdmnIx?a8|?a=wASq?tnGMF|HXv4 zW84DjSf)+NcD_A}eEx{M@vIMuV5b8T5+gBu$ZYe$U3O3Bt^+%i57tSC9WOF`xBI;w z(8UWrC~%}@X)J*pqxB$z+`XB>+>L4j*B|+!r_h*bX@B(Akg){JozTJHqt^Jr@sX~I zi^gdBVDZ}O_JvwAJ(6OyZzb#06!)to&4yPp(T?gX6a*#MND}(oTCb|jl38x1NI}9N z-E7|JhvmS^c?}Ax?8fhCI7(VI{+Km>ug2BRT6~TBYqXlFu$c(2Xb8PI)Yz@UboME+ zwQAW_OELd_+dSY{JL&Z`;Ka1TpkGhg%@(c40N3#*!yebJMuQ|*I05=~QGj*!GDa<0 zy|h>=ecgBb9I23RVPXXro9{lBxRc=a)gqP^tiH0qYYOn#v>)A0^$*Mt@8O0r!3VPX z8rk5&^;ysAq~|>$99X!q$oymxky{~{Y(yD^!3Ey2k#86<-dh(uh4_#f>No<`Z7j=R z)1}%DahJ*^WtZEPFdK17axT8-iNlcl9p|ma^0y60SZug^Bl^O`LNDVe?)$EPan_7L zSGW7ImwxxQgn1%^t&^wWoXz-hcX#fXFib~)^6lyi)&vINoYPu>Q z}U;(e2Z8#dn3oPyfwxmUJ%f#kOBVUK?YS5sL3FnX&GovZzf|x` zGC#nZe~;{S0M%8`Bz`;P!mPyf+U5c}xQD%ctE8T^tDl1f2;fO?&ER6EzNldd9A==r z4^A;<6pPL#=Vqat=YnMm-WN!1xW|U2IP<+ir3$ZD`AZ+}pkZ(%grTHDcSi}2;t~qF z$O3_N!?jYik=&}1)Z?Pr6DujVisSs+DaKSqLAKHi&@x5O7) zr5LkRmXNj*T|7w1%!=h1FuRvf<0iXoWNEo*XYDiC7vPBee1^p0?PcGi#9b2lEteK` zI>YnNBtl?qY#|aU>4g%I$dQXlUFq&84`Fk6+lEcV#ZbTn}(ZSCG&zbToS8NZP?V6rc zDvWu(GVBgCJbc!IFqhAXBJHzcbC2Hk(zYTQVKKu1(cmR6~7feaFyYM_vWQ{l3gfb4a2e?M|WK#3v-2ecIn8<~`fv1S0}GD67{ zYgY(|JuqHm(F=o(>rM0n&i9+<-4jmXC!^0Ws$ecU5=zC>(apet8GHQ=B^1h3cfAdA zbis0(xJsmMM};s8%LN96R0~P4n6empO3B$!2P+XEgIIcpqg~UH;*cKk2RLBSWTDGH zSGfEfp~wpC<0mHmo0>Mcd6c5H`#W8e%u zHc^z^xt4;w!ildrnqG9ax-G3H0mWJVkX&~(OlUdS^HH+jJ4B~ts>+|;QZNFH&YrhA zRsEslZ0=!i?QLwmpC3_6OGIz%<2m~SJIYLorXOIt)Vjw6%xZ;~#(Z&F5Vn?AcAo~9 zS+x(P&R3PX8jv z&v*C=QGy%c(=rt>l{K%az(dg{QSBu|pAYz3)$58_!-Qg{p2!f%^nWH03|JNg1#6;G zmOv>En+=Q!Q3EclHStIn07gm!4&Y*w4;S?vUxo*2?csr1XA@)0F#qez)63lsir=;1 z(stN{wmL*znSj6o*}@t!GGLPTTr=1>k|c^~>`D40Mq@>8dUXig*-wnNz2yzOEjJiM ztq{1wKl#=smrR#TSgopduh?7aeGBHq{TbVS;bz|zc4TtQnA;j=2f`Gi(XuOS718`) zJqfZYTx_diVaM>=-1+^hvhvzcAl&mTzwTl~KU_GbmsDtlJ-m~@2_E49R?M$7J4@qX z69WB@A-EBh1JiNIomp6fLU$$@WzNxLJ$C!gXG&+kY8>3j2ZBR91k+DsD1a`pWHoOs^)<{?uak8tnzD5CIOJ# zMJ*b;UP&%$qk189=xj zlkS(qq1maT(A}Z+9})00KpLSJ@Pi4H@PGT&7Xj%1&~5w@bNr9$HiZ77Z7K8nDFW%* zqhS6+tio94^FN?|`9oL`^dF07-uQdqm;a#~06w?S@z>@C0dgDl^UFVb1o)4Pz+coT zs(7uD%J58wKXfQk)=Mvc4gT*}$j*PynBVV_5&7TvcoEA@t3KsrvFKq``Bh(H?yH;^ zU!H${^7rtsr=^~U-5^0!4xlh_N%dG zhcUCxhimKae|-z^uH}JPwVMMb|9+#^wqF7zJqzjZ8Q>DXzarqvl>O><^J=l);;$Yl z;(^G3;P>$B4b89r{@MQNKY#TkAQvOGKPdE9&$dp6q*VX$sVA>7)rdt>@kxJ+q)Lf} z9skn0d=6I;CLX2VH_Zv&dGklZU-4^vICFhtp7d+FjTs(IegEAjuX1cEy7tb^jSk`B zk3xrszeX&tcdha-?X~(me>j1;vLEho)r=+TdVM^OwM{PZZ(ga)$N30Cc|DKiamIRk z!0I?j4S%?R{xQ!9z<5})Y#3oik>00yUm`8>^xR>f5^Su?y)7K zecYuM^5`FJe)@g51}b>|2atQ?FAYpb>o_7|M_$#LQ<>fKeag$hY@u^G z(9Jfl+fu$DzNpoqV(d=!*=60Sb-()+!&(-hTPd2_pA#yt7#J!CB*ATL1DRA$4aaHwJiMC2~{^tkJapA`Bd_W^4d|Ok0CXPv3W&(SsLfY{V}a6|IZEGG84 zN#2?8sw-EEf9PkobP03=qZwNW0gB;t0oet!=SsXMd&dPHZYqTEdUP1+!akFS*&Y|! zL5{O-r&Q#Rr-0(@S_xKPfHF!N_M@*Q+Ul?5w|?F*2V`|ex?A33$H?QV-Q8{nDA~|k ze@*WoNm+586@rB8l#DKLCmw^id|N2<dCOr#-&w*B6`lBpbCv5wPLkD$7I^P}jANWSiqR72OWHMapsq3KAB~tc8zIvx7+!UQzPmVKSB`<4R ztE^53oSAv&*J1LfnpcaWClDHINb4;7c_SsCCB!3cF5+|V^|bGk*A6=TX1l~wJ*3yy zKQ5#S;m`a87=Aq-hbHQdM&UcoK;yXyELvx;R(MGxw4I27>sCV1St@iQ49%C3X+3!8 z&a)Yw0#8z+{?XL5iu3iR)}_zpS#v6UZhvPmciv}xnt!fFWLbS2gWm5Ec}tTZKGC5V zPAhAFAlKh2kKw0tVm`6Ok1e;hCQ?X#q^5QJynYqbe&P|8t8>-3dz+F?jZw66E5+d1 zq3tpKdVTZ;9}qmYb4hEnr5C6@r#3&zMO7H}JxRVXK{<|GbA4E|KAL9!;h-BmN4A2I zGbip_!LHpKhek2pmG7Wy&5iZCX|q#q&60BMIz-k>zgWYRVY8{O`zlUS9T8V}S?zud z4Xkv|`bJL|vXMex;H-Bk%nCxD*%+pjM-fkwI^iuoR2+U79UDR-$lk5J3GXrf1NeGH zXamI($J{}aJy|010dZ4APPv^<^E1Ia46fGVzPcE%PoZV>DPRoJGy6G9ZbHN9Jdj%s zzNyveZO-1&m04mj?v%z+>bngA5~*00~0jAdZ%hIwYI~nX^qTFmR_v*+U1c!#qrpC+kn@xD7D5IAQBTguUV%8cou~(q>FF);r#~ z&E8*0)je`c869wdb-}+&W~VAzxRcvs?~=yt6@2}I9e@@tZc8S<_X;EHX0J+zDaKwZ znBLYq_EAk0Q~y}+x;1dfPRMfM;W1h3l$bu@en{iOUvApMhRPAa+>Q;or4xB#`7&pH zlZ>n{_ygvIvY{T7qGHbe@tU`zU3?Gi%U&gp*qkU&Jh18z(AmJGGb1oEHe?B~wsn}} z_aof-97W)#=c$+_9zp}=SDpLU{N*L5Z!Mn`OwxUs%aGH>1laQ|OePq5q!JVsc0rAd z$g8FK@HLF46u$H`2kc`nrKNhdq*yvmU_ma0@9K-iJ_RfZ*31o4xwqBS$`8eO)9_`S zys@Fptd#O&@oeq)X(s(h1}V6ndZ~t-_R!U9aaEDMn@aOh??2!by51%Ga8$+g zLLX#(H>qchnN46wkDlu>gs`bjA2;A`8!>7!?~;m(!=s&8H37Jz{K5{x}#__Sz& z9nKGOfW)RRBnIfJ()juIi1X`Zf=agE;JF`zdw%Z;jwyzj(Z>baLwmnRSB>V@p}n7$ zCl)m(UJz?ZHZF1N9zUdP5bxPuEv**aJWog(>+m_|)O*>7chl6qGaVtfqB56E7?;ng zwJbeC$yi4b)Q@PLbn8mj{8}OF%Wrm^KrJu8vtjI&Dl0wCXk3uGzP`D_G;K-XM5dHf z1rZBxP9XJ>uh(pT5FzGk$I>v_GD+N+S2T%4W75g1XxyaYL2KEexJKpL=HSUfJ6Ju; z_}bln@n;j5KUt%FFZ02P$kzd&>yMyd{u0=1;8G|udEyDN=mbR!)P>K{coV{;7UyV}D~ zuvUb!6BLE|qvSgyOr(+6e2i~D&SmwAjee6;!sJaIcXrR;B6DB9O`sAC(;EbP62+AO zaS;Fp1`;9igX9u)@(-0BK{JzG5>xynIs)lGizBaFj@OHfP&nVH$jV2)8%h}O@YKdW zf*`QdUa&|0^hV6IRjGK+oed*A{><-?cWrNGHscmK=vT!H|E{lOb+vp?-rM_G?~n?= zp{*zp@(R-c&V2zILqeKy*2q&f$y|qTIR(3=p7&O+%Aa6S6`PS>&fwVX7ky+3j!Wh@ ziQaT7X=UAR-6%%M<3daYAzfLMq&8vf_8G7r?gX6-xWbiN4g`LkfP*m5$WgRfVVG<; z2~kZmi4kLSl}vTTlTHt_{KXd@?Xg~&_UOYfO(O%XluQ*~3cF4in5?O1*OQ)Q>Sfw_yRQEme(RRl6(zgbU{lH=``#Q6nUlp%c628j&W(M81$`p^B zw=7`0q`kMlrvRcV?jKr-S7eSN)_LlO#GS_xQfPyi7-DQD7Y&{1ew#(rdK^y34^&^D z(*&C}HGj+SOSe`+8a4rg zka@@EoUvF(AWOR@$P_Xn3YX>f+TjC-`>R^hAIVI5A$inpcz~(8lZg@(06cyU#%1@j zy6h`i4p+e^6T$E^z!P{?b5z^jYryB&w^hmBT4m+9IAdo_bGv#quO;UW!tSB)>Y`}h zK5kT5f|OT)O+uZ;zH32w>jR*BXqm}Bi!kgILP;qp2PHI2nj7gS2dY30;ucq+@>nQ5 z99GE5b$%xPvD_vBs_aW$By~eJzuDaOR!fGKpUv(Id9`6!DPF0=Kx>o4QyU67#Qb{a z^z;voo}IBQe_mnHc+mZllRxw1Pt(F=rJbB@0be+xegjv$#UT8Z4OA{MDq zr@H`sAX{xOaU+1j0+!y{eXo{Jl&1j}dye}<%uH)opiB$7FVBT|y#-r@r6ekMX0!d( zNpXLk^hoAfoE6pRo1z0n%wBoGpVYH>OW=o}v`#omknAoL+Ms(?vhO z`<$VI_LgD(y;aMz?$h()4)$b}*x=F{wMr1nU2xY@#|RViG1VeHzn95uJXUB^^K{BV zVY$WmJ6duZszaN_h+0!!`?zHK8>sBzRHUDgaVgDemJHgEC-uX$X2)A994)Wpi}=|u zbOYi{Fx#AWe!E9GxgJQf)9e4{S^bcoc!@}yI=7V4j2JZMR{mmwUsT+?kjEP+lyP{t zcQ#np-M1qmt@Ik7bC=`!!iHBHQtpEys!c^Z__~*>Y#=WBTn#RO#%_gSa^%Cgoh~~d z)9nb{%#mTUyGD)$!RPU(V_8kMfo4|S(Ju;&4byDWQA0RH0-MTGDRYT4lZTs~vsZJf zZf%|G2WL)KeZ624nEs?Aibbi3pId6CCMT-stZIqZ$#6^X@kBu)91NfFYBEo^)lKN) zcf^gxhMiS$zkCX=+jC3%yg>PuCEnl!=xt$XY!!tN8#RJPmV6N7NHe6-`H5i?k>qu2 z=1!4@|GL^(1TF%Bmd?(kKG(0kKU`8#S(_;QAIygH)bf~|U!@c<>+)CEH4v$qz!50!%nrmqv_$aP(sAY{x1lIbi!3YWhFP;0qVoCGGKrk`%3#Wh+i z!Iu~FTAm+%+Nz09v+ax2K%gs~Z z@NxEdT^W~}KxL_iVSmdz>5x1bKb9$@b+=&?&B%o$!EKb!z4X#{*1DxY_U93Gx`hcx zBc3NGr^h72?IWTE7p<02T$2}3qHHAh*i;s_L6sYY%AwSN+Is^?gLx$q&`L!)gxTFf zZY0C6y5P11n$Y)3X#m?bMlyWfzBJzsueGDmrHLIfLDKx&1J?z6;31NNcjNY+lj(C< zgkX7ep(36qAKGm*RGj639QY$?I6gxFkY^Do|3qL+_4)45ASUz44sP?Xb36FWU|u&& z|8TLNq6x!ou=stlx{ed{B*Q0^-0iG|{-vm+@c|wMp#^c=3I!$1)=`)0cj%I?w){`A9!P#9LmP$+Bf=u)+5Bgsl4h+|NaYsrIeT)X?&clug9q zlz2K1NB7$(A2N)Q*XihWFk7DONiGHTKJbQi&a>h5&@qGDOp>kQG%hVo)vyAFVD8q;pj=`HBX)eXp(wZ%ok8u;cJ9#oQo*X8&*R zk{YGqB#4XXb0*QA>o?RNi_&y-EyyyTm!?_YSK(Y=PAI;a?68>i{>u-Pq6hpyy{-}N zCx21*SFfJ&rW$Zb&TXHjPG5NcI+= z^at)R2IDYdGH@WQs@l#6#Uf4N3vr@xJpk~h+ZSv)}CE-)MkhMZlOZL;>H zsl0%Oc9In}U>N-DpNxg`6HNnny9Xd)ddeuXXOfBe1x?a~VUlX!uu5Jq3b32n83lx` zL_J@1VQaVZ3!u3IY8H5@mBX)VDUG{PI=mdyorg4*#YH|Ex;OiFCRH&h!(XVacJ~eO zLGuG58TY4_{nE0m(?F_CI1`2=huap(9Q)U{WXX)5?tjJ7IOF6}hi8J(gMukw{s0Z% z_UFNY-E_=Al9b5yWhyQ`l?%4e=BeY3Qvzd*k|B3D{ed>N1pZt$C={Wk&(hN$uQeg2Jl;@_R0JS|86=a*V;{GM0+9tRD4dv$zwe*Fh+eb(Y}v-^S- z%zKN#rGfvA{{OE$#rz^W6k{FSf00Fv>mH zknDF?@w}-6y2^ftx4+%Czcs(DMW2A!6(|Gnju?`!e10KklDQ+o%LmC>9sEC2N?y5f5 zQxPwd^!NSqxU(U88`=~KfU{A+I>eUx`7+y=Zc9fa)4wyHaM}-fGwUA$9c^^NOS!{M zWca`5fv%ZSdKp>&KZqjwbFk6xUQp2CRc)+jOu{x>0hn_+6bbnSAU_}D81X^giv1ml z>AkKwCs=(Noppq(y?$9_sZD*k03`S6=#NjY&WryE*(^%BzhV)9*7A8}oSGRhW%V*^ z1+bshI|cP;(qV^JPWJyElsUuSC4@Kv^qPg%74Kz7G|L9B_MUM2FQE%~p>I|H{nhad zf3^_f18y)8KP1v8*?V0I9?1)uM6piI^pEsI z2P#UAV*R~R8=^9Kq3x^yV18Fj@Q?wDK%pGqkn;@!&!9Iu{>x~fjYXOvRAKBys1PzR z>(`zE401HSy1gn&kPY5~!QV%oHzxoLvqu7FmbpXx^3~?rJ80-&QM6~wew_a}N1zlt zaI$&MF$n{&i(Uw?XHG@D@iO_-e@qS}tmTQuSZTSw2QQK~ofdeB?6W9%QT2HksI@eq zG%)FRW)gk#O$W%edez~4aunG9@aLFdfj8P!A9&jBw(@k{NCX6`pSM>Z(sT8|3

    x z?^niqBf>N8FFU7AXFvoJR{?sTkNkei_#7|!Fa;~I#cZ*B8!z}=W8isT9FlX?y#}5k z1;Pl{KYS9-exUlE z0=3|IfE;FB?t(3^{d{5;UWNv&o6VD;V0lH@yU0J*OdM04L) zVqzj*AN}ED3bcbok>sz(`HioC2AlmCP5KkS$?OU~`zqf;u9KP{uNUjG{f12l1CZ@X znS*nVfXBI&M(=@#M#>!S_5q6^c=v zvv^CJ-Fp4C1Zr1M+z0U{n1 z6G`@?AUM_&=uJA_0E>=wjOb76u)wk+ah^vkI&N>>*YY|xFbwdf=<6(-(4)C`?7Dn! z39{e49B#j^KJaRq@9LYvW5w!SMQ%F`xaX?fGmxMPyn5z+{e1`g&K)SQH8yA0Kb(Wa zTGW>0h@n5vW`doZJL}AC6af{3@%#GPtg#Q>ye@y??_&JES1A z+lujNhSBdFU7;n@(~@)Pc7W0E;+s3;xm^@R_jm8vW+IZq#93co%M-pC50Z$RErX{m za5)Zp?~QjM*XFmCCwB~PLsdRUA49Hl*MW{$;w^eNRr*YoiTVuUYoPp@pEAWmRwM%2j3dO<4A+ z400z&I#NJY2*ed2fvm~;o_qO(SJY`eCaCBJ_jqorURW;pO9!|x0uO7btVca)(JVKf zGx4V37=(ps5t2xt3tmt++9lr9G?S>YUE7%i6;p{$@OKK54P&GUXok1Op|B2~&Zt~Qx*P#yC|?Pazj&Y=y(qJW;S7uz ztGBk=-~ctnUv&36Vt>8@Jz}t!Mf^vu*>bq^)#!kz6NZQuBN~~S+p+Dr{wW5rK>vC} z`bH>)c`l$;3)Yy4+GV^ql+9WEwdN$7xik1lo+nU$>1h%4xG3rs(DdAPf7}{!t?c_a z>z8ThmTSYs2()eoI_iuQ(ELO@Gk88AdRimOdoVAXqw(Vc7zgbC`{UAITOD>oe^6!Mx#|eUHy$G{@WkQ^j!543`}Az3Vz? z24w_IBQ2PDx}5f4=2`?2=Y#K#yKhKZHHmRBvpkD?5QF1#lk@@(_0XHp%GE}cID0=#lN@)30Q)&A2%?u`uS(kX!xbh}R-G3frDAChE1 z{&%3k?J!x^gVBC2{}2C3gFoEqxI3V;i-q$lhC66Tbla!>R*)seit|n~&4PJ8-yV)& z;j2sWTQ4sGo_b*16W_HyVMYLw7@6~bac~+=4(qkh1V2tNKE7!Pp#&E}X84f^aT>mG13N7T3sp5mv2QMs?<&LqxNDWkE z0egFtL!i4SzuQXp_6yKsv2ZPi788q@*Qpz@aAGi|y`D=R zX#54b8jg-^;ffE0*{-(S{p!?+f)}Wb8d+)(gIl1Vi?_tB=d8 zwv!p10_x&f7a2Rm4a&_OrRh*6(aaTbqq zQt}oRalryS-@V5C?W!DqJ(Vn!!1a99HSq-->MJY2pr6ED{+KorL{89o0(GiHuJSx3QwB~ z;MBhE5Y*OkC!56vIpOULZfD&VG(=0F6gy(U5m%K0(bv{X%c%WU7m)#_VMj#=pgtVo z5IoJiG@hJJ;dsJ19NnVUM|E}bnF^g^{Kxu&D49y)ekY#71_7Hy_;wfBAlr4%kw z_k1BBAPo7Y@X@NMxrE_zjgk58c7ehKi;H&mS)=n!XCu_bLcJ)VcYDwR%g=+LyG_=+ zy$PD~E`!y_UWJmcU_VRD zHx0eY5QwV&EC9Ox&O~E%zOU;X72KaOhYGu*T4degB4qw3(G0Zve%=H~MrUw47)vIp zt8Vog78Xm0mcez;yTN`{Uvcu)IaSstkvY>Az8YFA#BuIZZ33KrAwyvkt_Z;>0l=_R!7-vPP0ATyqK*w9mmj zuW5ZT+8u2s&5Ke)bGvexOTDKcc&9i)^=_T<%{`Zmv~9!w*htrFmh4_s1b|?PiaY*> zUx)+orcI!ro*zb^+uV+91$O!bS4!}=?lbrb@zIo6g`;F-(Of6sy^EgJ#LvN0i)t;{ z#^k$+Xml;lp2R+iee%2zro(EqxmRm}RpZ)=7^N|o`0=}}J1LtpLrq;HbpUPaIbG0e zhDgQ@-v~;t)=sJ~Ei%fLRM7LVIuW7lcSwImN@g16#sp;Q)w^{7>(Oa)SknNSWH+vO z4w&`>&3)+jH#Z7nq1SB1f;9{JCgme#6oIrg*uY1`02jo z*;$J|s!W$SL2Ngk?8ifk<>RIJf-sHs4L+c6S6zSsa%SRi%?5x*IJ&L z=9}#f=f|lUvsVxhLTbPLi35L@70Ja&|MnNd?xZ*fPGHmdVe%wmj*9xUZp*6ZZMEV+ zL4f93;w?yYu(U`=vh!G#?1NgYcl#wu^j~^o zuZ6Jndr#B_5}bI$;H*OOh?CG@^qaijOX1}g+dRxRDzXL!*{L+WDQ0LR2FS$<*_93I zn|e^Wrk-+XKew$+n#(btbai=t2pj`_P$oWzqKfwo!Yfc=OrtX>MQ3)P3^&i!Tg7ih z?3POLilxp;dH^+s7e0eNOh;!X`<70zKte#|&>F)+lLV%X0gM7h<62xl`iubg4wEhF z)t!PXqNhjD{h#Nj)yGzhr;}X?TxX%FHjJBL`l`n=g(qb}J)YkqeNnPHY$eJBno(*` z3;ZGPtsZ`87z`c=^W6*!mbz@?WH*|wIF#l**xP%t$`+MrUC7u88V+38eWH*Jen=Nw zEE`y?xw=052&yT_MOX{{b1zFqya@pZ7~BHU9^-c#F$y#Tuh3vj>w zfS!Hmoc8clC7Z1X>nL)cVs-giQ$$4Pdy-@C}?Xr z^cD7Y$rpz(Pc~$%RCWyCu`Yoe2QeQ__4z`KDbcAhhBxd;^jJR7gY|@Y&ae;={$~MD zU(iZ{qFC2+081&{pZc9~3*HVyC+@|^h7-j2?IAr~Cgu8Ft^NU6V3qU2ufve%7;%)Y zj|Jp5TBX|_*e?3ac9dtKR={I@6UzuH*-%(HE%l|fa-9mmds@>lP>=F0?Qq%Iu-E#A zyhGcdt}fF6d{dm}1FzQ7=2 zrh%tln!ZW)yWLapE6u1*G|DaaZMg)#1612A#J_U5-AXQ_W3PW;$uIE>>Y+Wy3gmI= z-QpS8_{zD$1S@Qru%JDhdEorOm-v%yRQM`N4u z6XS2hMvz_7XV?fH{M9HwHvOi(g-i6L8zV`(7N~`S3{swc9L9@D(mKtH&(G;@4 zM6Vm@P@RO0&_!=NJ30o!b;gt%R#3CWVbsSDS~4D%4LIl?$`9n%>><4RW>vr% z#4`C&8Qx@swadKZZk+04$yBR2sSmPdhfKkkX?dbdblz>j#dJj_Y%4^dfTG^#z0q-6 zF^d9eTGm=|fD}1z9E8wBY*jS4h=ETK5KP>ikiu}^<$6*2yx!$5(1`6!DErgH;4EcDAqN+f)=K*hyCD8OO>|1e&I zwSa9GB%opeX@G|Uli<1Gdr;~`fR5fh_;XZ5ADV|U^g@D9}X@!nw-+$zr`!WE!9Elj0AM&KCamNalgH1vhcBfp0S%o$2;)YUK~=O2fRd zRO?c^LwuJa3gk>XqaR;jj+csL#~IUxV1O}8P+r(+N)M$U==JF&%BRb&ulm-Df^~_A2X(|SpUs`3Co2regYC+4pRJSEB|o}68@x` z`qN<1s!iVKE=N7bh_HqhOkJy3I-ENJ@Bn~+2^PeC1X!`$q6iiYo+b4ZZATeKL$v>_zzQHhhgC}|ES!P|#UL+Cuj z97Mb`G);I{mUikt%9AdO$CO1R^9yF<_3_#33sB1C#ddf1p!JTaV^8v<-(OtFy|W#x zLF}I4c&He6oS>%kp8tB%Q+V;%%4~t_mfkTpwUlUvyf&)>%K+9RlsNG-kn?S~$7^dw znYq5lM7<*(SNk9H2I=Fr9d1t7s4+-3r?F6^aP8RLpJj043YDJsG&%8ArHNWXsC$ri zHk_Ot65mYGx-gSY*)CXy9{Pt;$Gxw7Ur$_V4X>O25Yqu6H_R?i`PL3<0IB+s=RioB zm!n)n20p+!y)z|H&PJ^}f_~BfF+GsT<%e2q2RUgOX^Vgw$)y&+fL0Zx4-V#Op~kQU zn@HWL{I(r|S+T*+&G{unbc4>e!18kzQ!`NdEA?7k>_Sk9R;rDBQUrn104`y^^R;G1 z<_D%(G6`X5=fJu5z>0U7v5ORWpy#47vj~g8=5`9fo5--E8->aXB6-e2Ii!{o%fYJDpsy|vkq$j;wyTDVe?Gssq_y2P7kmFn`ii>G%G!b{7o zN?jR5cU^bF=%O*R`v_PIf9Xzg7oj`*4lODUHnyqjRy{zS(5eGQi-Fvl_7y4_Pw&dw z^8j5Z;zlF2=Co!dvGC^%)PX5!+}m-KX|3rSiJP>nA$qyFC3P~szRNJpj@39r>24?O50-BW1Y2cY5GsWo zd_0pS%WS!`syjfN344M#dhtf5Rnen3L9>2Mk)^~ln6$zENfZ28;Y2XY^}Q{rD;k}ai=W- z9Ne%cB(1>|?&Muf+tnm*(!5me*e%3-4s&iSm7kNl79g}nw#j7oK5Do-Ep-ShjmB(! zxVn279w$Dl8GF9);!pF9!*X2kR(-;$D5L%k+AOi=>8WVs9lRdAz5Hz%=>;vlo$)6B z2<4I7r-wu$yGgiKWQ&zuB-Wkx-h#g0x|Q0Xw&d^uo=x#qJ@n7;xQ%q~II9AZY=|EG zh9Q|T3L>|CpWO4;CTfw15eo7jWar;#Vsx)th%aNS(&eeQRd5;fAq;gdTBsJts=dR- zRU~jmaIq;w81gAXL0X+zEy$N8NDo7shmBR8Oe^V#dfZj|E>%jF#wBbZEbbe}Q>`pr z_np!RW^1=|)@llJe1EUAn)Fv+%e1MgfhCtwVO+3^l_*^p&xiO$Nce6hg4QL^E}pgL z_>dnCJZ(rm&@iqHoFt6FY~FKPzXfi1!a3+AA2p*C6H-uw`JbLw#4UFN16{jz+2S2` zcV&mrIR2EaK`p2L;1|nfT~`<@#CTs^7)a!KS2xtn4p%vPs+(shaIy4AmG$=aBYU~( zjSO4cFoG{**Ch3$*qZp(W7>HHDnLLzNx*aC&gbRT zCUGT1PEH~<%1ktVq83zXfDX^*wC~^@=JX>$DwzDy*5&GqA$u{x*ZmOXKoxYg5l@+J zw2N6%A>y73mHk$lHS*Q{kDdnVsB1N0HpefeRRu-+be482L^Xq=qM~a9o|8T9>H2K( z75*nnrB-p;pNA=a@%C-2zi~}y8G@v7KxTpOZf1HwgctqJ)Pfjbl&ls_C$lUNk0Xj# znRDvbthPxDGkHx?qL@>{le!(0?S^Y8NxlA^ht&SWU$XdjY0*eMl94kAZw`u>s^;XvOCtV zzQyO2`pIgq1VveS0}ZhK?n*bPwvXOrZ+sO5vs!{I2W*e=JyQ%r481V!jtq88h~xJG z{E#o{AKw$BhRE|0W9QLTqq0&s&GnkjGJakQJELSVa=gtcTP+UGfaNJV%k5`>@#?LmHXnlaoSO2iqHx z3vW!_A9>x-^rg!OlA_oski;b)B>}DvL8Ci6Ld0?CEZfO)P%~<+_Gj0$Jo9!c0*F~S zq28;DUu+G{sAGmHbFaO^A?#-lYOF`B>3T8`o8`oTy{X&c64Ilwr(}0_2Yu*sPsP+M z>JB`x*ZAn`RhayM5^9BgK0JmBO8l7qseZ&Kdci|2WGpK>gMfwWkP?vv$QsMl)%O@% zJL310y$@-L`(O}g)P$pkM=m30M5d4D+o?-iIrSjhJkMNBrm8e7`H|Tiw?zD(TJ>KQ zPow?Z;g6(YfGJl#JG%IBuw5!VKrQNp}pt3u5mQ2 z)hq%wC_Q)QE$jpD`Y?HT$a-sl&;#Dp01tV;_U26E)Xl*1Q~*qTH%M z=2Kd1VamL%Gb@rL^H8_lz!^~uMG*U0gvxe2*i;;w)$+r;YMdK}4ma`B>wKY}Oh-(; z$)bF(~f&U36V;;P@eDcIC8Q$}n2v+7;y7_he|~fhEVMy951+aadp|%lehhdA~b;%KE2~Frf{RGR=r`O>=x8N*b3h#3V>z zaLn8L@|`bq7YlOowDH3>9P{>9rZues0t}EH_C-jxZxg16h9NUdvX&T^G%L;nOwtn@ zYpbnYa2I1yMS+%xHa6WAXm+NUGmbz`p+m~h%Nc(_Q;MZxcb|M9nEg=?}V1@97n=y0(m%2yA;P9bpa}RH8dsjR1CJg!(j__z-?f- zW|y7upg;*_5l`4N%Pdi|ouD}fggmXK3liN(w{)(DQtyqbl#jF1F5QC+jvNf;OM=9c25=lACt6^L0vG;Zq4uvWxav3 zk?PYNjHY=JWA}2Tw#b1ymA(&&Nl%)OJDR_B#4!!b(btse_86-#8O8M*<%Sh+=;Su; z=t-U!sQmP-JUi-hpTJ1nyHp#L&{v-_6T7ZhM!V`MLRoB2L>=L5qle*+P-&LO4k5A= zhIy1i3C*Ku>Rc~bhu=>o(uPvk4Z{add`LqzrVNVXVQ|KY+|&u0$Vfb~$lCGO)bPkQ zaR!vX-154A;39TlS3%pDs!?JidDobplEDI}QdIP7tc@Tn?=fm!b^gltTmFG0^{Cf; zx%V;6y~H-h0oGUXR(AzdZ}E7rk0ovtRm4~siIsjAHe${>tUrnePO7m*500`c$hAXo_@!_H_G2eJ5eb{iOfyx`|a1{Szjd=an&NF zIrT$T#m{q~1Ra(qvs=uq4ET;4A2zV1nk>nvK>^7okIF zvemw_=0vf~B0EPRG2DQ+2sBuXH1e#N#vYQL-@lR>H)kb5dv94UhLSN-z;Gefu-JbbFE3AU>K@f&CJ)07ci%2cil-P(9WYPI6XN z?}w%(rBS2E<1U6$$oE3OT@w0oIc4#+FD3o^h=Ao)>KX`ju{?UA)Off!#^l>uI=T2r z2645Ki;V}^QbO^kv@JGMpx0{b$#!FqO7^}k_B|z{8u&4@wiv8zx&fPS zrbkZ~(4J-|4F){uUesi;^sfK#JD-TsFZN6uo2Ig0b??Y36n$d@C3G&wF}GkHa4lt%)BMO&_<`tcB_mEd=k{#${F zW;>(+38$Ko@!U$3yt^r11gIYpU1?Lx|6>eRi$z@2Ypl}d+SdeVy^WPQgc=#&|B%RG zs@^xL-r|i^rLn-{2D|=}a`9D?e0q>WEwCId~cxb}mQ=w<@Al$|ja}%##{5*|}F)zAD`y z^A_aXDzl(dp3smQLV}yFxz*gX&x*)aE>aa1OPxreDuGg~u2ZpEV6KVBQkRrIU^*%d zoOX$tsc?GGRHwSQY}Yfss8{+~7gsU~+~GqN`!}CkxuU6~ly?b(jL;E|bf^89DxI~i znraiENGEFY9L(T(BECTATtw$hGBL>ID{I(evNJl+vAN`5he(=W4KKkRkq7lKaMJOi zEawd?{79r|Di1Rr9+D^#@f4L5yA%%8R}(uce&1D=*IC+6evZdRr=h6e*ogdVOcP^i znj#ND+f*YahJzH4Aj5NJZUVIUbqkn9>{P_w0fb!9kgjtdmZ`iTL?2Z~OjY|8??w?j zgWTusbovKuyscWZA!{^#O8FM~8sg&?Tj+)-5ga za`yUdL`fKZ>}xgqN(q&@;rxN!IiBckl|z3x(1%o_46L^dAC1TNEMr}*?cV%If{!%W}Yc-U@ebWE|REZO`zlA9l9Xkni-2SrHcNrHKyq_P{ zZGqBkb*m_H0n)9TT{h;V`GL?11HTV#JiG^$O zD7ZRY7qqt+Mo|Q1oCG&0wmKoq=6qE=95HtTZQsOFXA)0MJj(sH4m4ra)9QJ{o!T;u z?zxb%Qz-!q3<@6kXjDFNx+lA7b@+|Ez`~lb-diJ`=qh_Evyvh+gcE2hJf53DjgGwR z{TVE(xmyWQ@KS^{z%dZ(^p;*oC7Z(yi-^XHS0-4uH-ZGJA>2Ib*+wvk&A%+rX|Fhh z@ycxaut)EMyPO_m6Y4*|H?XBQpkBR`#tFjqSF1D0-H=TewOmLQUu&UwEtLsH`raz= zQBt%lH_q+7_xEZAvi%u6ZNa;5CW&_!->v3qa_>^9UU2AT#J|ulY*?`xM@u#8Pbl$( zFvCU;S(Vt^yIkRO`FG}T13M(7Fta}fE3xb^Rrd={LZVy0X*eHnDI3EN3pHP-aS+O@ zOu$G*?@&m$-EK0HhPThhhQaA>2ye z-a=dD5h9tjtb4vMnC)>{3Isg1Z|ChWihR0ayJUfZ1i^Me?i75Le>}_O^>;`QRZM3t zo%;a{@a;Z;PrZJb0P3F!a-Dc^qh8tct_Xa(E_fFVj6aXvAZ{$1H;!x%8QBM^)How; z30dN+S)4N599AtV2=v|^p9o?nJLkbM$`zK_<2{mkclvNN;MX%KYdw?)}^OvadtU@YD;rH$Y zyCaYqkclbPhqp!N_;#i3sbklNNQiEa%~Z%h2eL9FcK@j&^(z z8G&*x8(!j<8$6C?eUM&On>JTtMD@lk&jj?I7UAIDdJiMa+FH!uN3awx@t_h0R$~22 zP$j4Jukb|Xi9a>&^@?zyh?%G>sW(PM3vxt@kJ6{Z8m5)_sP4&QAt|2zKR1;whTPl2 zbD`>{n)05O$Z7S?C4PY6@)Txi)SlZFSuPDD@X8yI+$n3Q%<1SyJ=(#Zxg0H zh{s5D6Jq}OV}ZYyg8%nlgFiw1&w@V^yaX|mjIGClKI@Z8lp-bW|Ad7k7V%@6XUm^^ zGM}0J9x+&VGT;5z2u6J$B=f!KUBHRpZEiZ@PiWy1&Y-_zN)qqzV_2)6Yvze2-hT9Z z0)AhaO1z_srX~s}=lM^3gn1mLUyE~P=LmK0@!)lBwE@Mt(%Z9SX{wT zLW~{%;fK?`*hiAbWF5jQ6scd(&A%^{=mN*cvHvkg7@Pj43q;DB{;I}b4p%|XKzKx_ z{Vt7qwch96Epgu>AsQ|1lOqligb-B@2yPi2(7y%dr1&v>_Z!iE)vUFGvP2J;;Uyu# zflyx*8^Lxh2cr{+iTM-eZlUxKqh>#atgaAx5Eb3JABMJ}R-L5~1G?Td0vwRzfdmKM zcG0yD{4wW<;@S~76^eD;Or~_C*Zhg6=)s}2U1;zZb0jTup_Fa>q%Q3INS*jeGtUc8 zBz%&ToKgA#7_lN3mynPUA3xIb6q!+{LAFp`1vUbkLG_#O-EeMh?o+xw%HjtADiXCt zB@!q{m;teil_Y~nJ_Zktp$J8f(ZZU_-ism_1f>^K%Ekcr0)R%+T%4|T^C-stVd1dR zJUP%5RRd;eur{~Y-7y^UtNbKkCUP>( z%P=l6Kkf9+P(tT1R<_~HB!bg4C-Bi$#}XP7MN_+?Dva(1h?BA#HDGe}(EyebqVflG zGQS9b;`!b66bqg=GlqmmqE>y;So=`d(PFjDjU&dhmv157ZD#F9=Ke!$K#CR*AnV3( zni)P?x&k2=@qas-QmWiEbKjfG{+m-;Uo1P(#&)rNK;sf-r3JSd{BS^{je%EU$mhMoyXvtDG`aKw{qY(Vd~Vy~yP8rN zL|<&Mt;=8m5@2eNa6nI;6Fbk-engS=Kn{W)vcKEK6e0-zYMb|@M#PrCX*TZ;utCWuJ#v`tMJ*TdrL-P;)9W9Kq9I#|pp!Wg%x(OTSP%7op15KXUed!}?cokF$3T z1`l^#>A`LA=Ns9eBWu7}Bd?zUBBi;nz*>||`14~f)R0wZrL&O8{l;Mx2ya>aw;UQ) z^Lu}I;pFu&x@$kfy$fWk>(b;V_Sb)B4P+kr%ii8Zqls8{ZFYEmh_UdaF6O=$bxDSL zvp^&>+mVGrkZ4j^x?KxF8E6Z-`L5^n^#igV4#b%8i%S5kRs=3}Nkai1Xc_uPE|sNs zk;op%GftR<2Ew;|&p)LWo^H-YSEE**ja>z*>u=d1Enn%y%r4)XV;G~t{hd<)n0!Zg z2>+z<-Ns))Ls2fX!Gu$vMmmkkNGH6)2>h5tL7v?sR0=H4J1_k<`1NO^4*KW}Z=hn6 z0`F0M1Vc-IVfq%}+iy!#WflNQRCakNKyK8P2Ru+oqXxeOS}$bvaW6J_3jR8zQd5tx z#Z#}v9C{oU;}F4jQ(g&tpGmb#6;T-+CP{S#(y@>Dx^1!F7beLmq>< z#y8*|k>mb%{=>#v8+0;+e`R5_eY&+=41<$UQl-zb_t*ZX>e&wJxXbGhl);DD78qX< z*kFn>WEiY8Utm(_FekCkt2f`;x`W3&X~j-DAzGcp{m+_5edNV~Ud-BnkpOHOw0F5~qayde#Kx2l zuu`%pKQC+ert-{|4Dn9{lxO3AmW0eC(|C7;;xo(Zq z)*#SK&Igci=e;*BMNsE}99II#RuQiCF9ih-~0##AHjFzlcjOKX@!YAH-uE?T$bsc)u>!+ZP5b`QkyJ0EdJpx z#&7gNQEKxj6VdI}qoj}Dg#s%v)Iu9R&+*V1So-84O1IMpKIjGtbet~S1NXLd zKdleG+qg?-QYciE%p&AaecqsAKbu^p{wldTBv;LRF{qbi(ClT^{f7>I-F2f|A^?#)641 ziRWa}Wi$_3njvloJPn!*X%cKD=9Rwncp}n>aurfHeVU~h9}DYLI!<(9)rD^;)UtV) z-m6sT7AjrRP=id{mJxVns-j}4Z5^ht`BVC88{At>!SA?BPqsV=AAm@xTWj)PQTxSKA|Kn*32 zgI2z9g1F?qWS^2t+6el#r5H)Pq*3ArajuwNy)=Ir3nPrNw?RL@vSaSgm~Dy0?d#h5 z6i~ev%qaF$Z=-rZ!v={51Zz@_liq&|?*0Y~I7E!CYLh)|#&ZEaXyc(X9QJq^LR4JD z>OVr}eKWhwYUWm|ED}`Z?nAr3l3$YqCo7)yX*21j4XbZ7+YQO)7tU5FDqGs+ejiW$ zhxsYnq0YMy8Trop$#fd+mVq>uC<0zxJMkBJa}XkBIf`cH^km!j`Go0|fI&a1_@-&3P*N%CT#qz@`sYQ89IH9`w;WES zZkO_mOSbnemp}C1yq{%{?2jbBC@Sq#zV!{Vm7Zj;_flJJ<>MBjTTU%yG7u)^}MbsWAJ%nm6!uFmPcWGYt~1~pJuyt*hbl5 zT2)1LRv*HjCpLT$;N7X)0qHv^fg2@vf`xrnbsO2Rwz(&pt&t>ON~cy-&Kg8PByWT#hsG09+Rv|A`$DqmL#46$)RoD=O;Cd$9*5l{ zCqC3jO)ue^#@8RG8{Hd|SCh==l)~Fcbil&W!%m-kwJfSb6y?Vp`(idNyoExHRzxp0 zNwx;P{foy|f5@jL&Mm(9Dm#`On#dAG-m2SChM*!37h#_Z7O?J}Hk^ih&;mkOzjGI2 zzEO*o)`j>^2TSg^gyFMeXHg0rvDKY+6;1owqup>Z)T; z+2CbbDex9R#pcjQWWt)lv$^Sd=RM2n*;P6Db#-nTF1puG*%^_!d&(`RIUJ2l@CKfy zD%c1L8JDkC;!sZ_zqBiVm0zdBM`duKV#7HCiRRq5H10pz}ffM2PgsHl@cvnbuA z8?5j@Aah`HX~9MU-m3?UGA?v+^Xthd+j;< zkPrpP2FwW^XHT(yof>9}JRrimSlt{i0FKSW$G2T}4|s?2>sN@ogr7C7YDLq|JA(1) zp=$$4J!T+?({B%4J=Mq^$5zu?K)p{m<1}r_Q@A_o>QJNu9jHt5NZS%(;$c zuJ~BW)R&GJ3<83fKfPV(R3o#&xzO%=8CL~SmWeZg-i&7|oW!myEInuC!lK(a2Qsw8 zP>)EnJ9mo{dL_d@BsK_8d|J9_p0gHXwxgo7lsouKK8)$Y9cCF%LmQc7bNFoaOwX~! z3`bgJ(kx`ddosu1E?+Fcc1jd1_$u-4=yn>~uf?9a)Yru1RX=YLMoMj>6x9jSmcB$$ zachZu!_AB8Z_Da^Q*D%;_THftxgbK|TSI%b5y2?@Fd`^tUH`mQmGe8q0EK3?TgCOT zWg~sn>ay?wrx^6 z2TsX8gv0K8Ry7NL;q0H7bviiGa^?C*58>nCklL1r@AT3#)GspLN0&S7Y|Y(%Nkp;6 z+p9JudiwbsdF^DFb9Tx{gH#B6yV>%Db!I3Tmn6%cPKlbb|HA$alCrx=e^ea&_H zrzcebT|u&=+?Qwy#->Rkh8>PVH&l>E-OpDkLM3I8l%FPi_;ayn1~<42e&NAWvrX!i z)JqZ{t)jlTV>(m!_p)V)88dLVVXL5&=NtT()`%7`@lBPzfpRCD>fAxZ;mwcyr(6zV ztDUcnYuLuMtM&WLDlY4=f!F2cj28cO^2-PyEq^eCb|zTYK_-qs9h3WI%BC1IQX2<5 z)-)oBhpwi+H)WeIf?Ksu6X+g&*u50ix=_^0P*dY9sHb3EsO4}$;* zoMvV3q%8-3ChRr59Vw$_ts{3Ju!05@)7CdQ4vX0~)jhOl zflRQpW|bDxH2i%C1C>RR)88A_AvekCBjuQ`9K%X|;B2Tk_tUQEt7pK5^sxNJ+_T1# zHi)nT*rg=%YpX@mWhic$2`1iKo6g3Uq*aJSx$Aw=JfN&!pLa+<^20ePc^Cl|S{Y$}e$i8f~s1%<%|hV}HdV60b1 z=Lb$yjWFc}R{4niOurUL>x(zRh@but#cH7zP&PLG6wtRmCXHxBlX^IuS9ijnYofPM z5VhLw$kENz6SyB1>sUY(IVSj2+V7XMLfahtIsEqtJPGl;{!n2dR471F*}veRO`}kx zrLdG~+1u=+Kpk!ylk~N9mP*d>B5n=BT-DML{raE>$#}-o4?|<_(FHVheY@Esl15p z@b&uOhkb-RMSpV6*tFv3;WKal5j;eQjNme^6Xs@^XBof$#*?0zF&#SGD$CdOF|dvP z+i7s$B`F?79k=MK{(g#wr2}Lo_5>WeJbsp#NbVTun@SYqLN{z3}r*@U-9 zHMUzt)vw`zN`w5-j)VEcdoP+V4z=BZ7wx5?Bs}#nqZ%r|%-I;Rq;L?F%;!cT7um`_ z8NSScV1-W1LwPQdE3_7POtjS`#fW7ttI75Z=!qC2dP+1EjPd9}ToqL(5*Siv<^J$j zbv7Gy3WD8Alv>k%3kpNh`&)KwhGDuncvrF?Khj9FzPXwr#(sM&dSYxdnT$Mb^4PM! z=J_{@@Ja0?7iVEZr>$YcG4kz~>xNNrCj5rGY4QWHUcO*Y*naW=kE-0&a91SPtL~LA zjYt9Mc4TKmKN1N#!Doy+L&VYJ!EMw#oLLA4B8dod=JRf5gzX2yIQh^LdmjhOlp6hJ znrS7kwD0Q`TUCGN$`OO`j{{GeLE=^`^7K?_hB+mghjI>{xz7k$1_MaYIJ~!K>(!7R z{)}1z*Z101z?1h>Ox{*aTa{-%c1q}wB;!pzkAC|0NfeEVG^9mhnt3CM(a&7_&E3dT zm0mLbIv!;&2lJLkF?>)YU1<;-Z+C})-xPtzzj?-elL*`5e z!8wm3m?|hiP21Jz(zBYeVZTL&bGE|mWHT*|G=?2*1T6r$@sAH%w_L#&Xu|{dkI+1_ zp#`5Pf)}mWeb%2oOS`Y?Kh3m;r6$tv%1RnNjb0bcEj$2Qtm9b_uB3x-@B>G(>G|*SM zf?VIe$_~v)Jk}2Fizkg6Wg3&T9Dgr`G&vD|&)`060^#BX!!q@|M#EzqdFf!xClh52QW6`FL;YG0wKH#^17cQM(c2e5vuXHW;VXmeoglNW?;t+ znJ9L&W{9PSd?i2;{X+aS9`&g8Pg~XZ6JYG!o16wAnppk#9w zkVeYV_~68vb*9Ydlg6XVT6)*y0*Lt5OgM+gDuM57>iJ7Et;bK`*%1FV zoL~f&gH!(+umLav&Kza?gU|tppD9@Iu=Z({L{-7TW3@l$GjuSXQ8KLZtfYtM^y$Z) z*{)C5mPa4t(Y+Erx>AMprsC#9W4c=Y=&6txi=s4+U>nn{X%;T}<@#@t6Y~4NNeVlZ zsVZS>sXiEkzQm+|cWKe00+0L+rY`!EnHpWT5uDP82K23YJCLoixZr1HFkMlOE`8~z zOv^wVB7ot&f2oq<5z!>-x6zr+2rv#R5o6Y$S=dWvvmZ$uR)h^WSf*~l7#i?gz!rh} zW=)7g>wEeU>bs-qVH@PMV%2J163Yrmo1vXxpL|!tQZ~YmIKI@(pF13Is6H@!pGi-7 z$J=AWow#me;ps*sqbDaG8tK^hrW4X~wr|xWu|5ko30&i&f0?mALVo%l3~BlWrR%l; zLg&yVAsNka;4DRcHOH%lwP$cly!j}0uM-dxX|H~1vS9R(_k)ZNXaV?ok*M|BDyysf zCG`%ZI&-Im|MPbUNQMnl&Cq7b2DcM-1ut^m5~}hH1unc2cc3_dM;`~n69%LD-=IN?vK zteOA=hV;`A5)d471FFj4>U8H;HV(l4v>Q?~n=&$mE&Ka6HJ{qhoq_nFDa7p)rS1jK zdh>-bBpNO9Q9+yq7wcPJzoCi@9>9E!v9W0uMC|s+Nnfa19SF_{MW&^%F|X}cw$^_B)Lp0ZMc1w**lW&>ual9izdNK#(#hrVBzw`CV&N)ag4!BVWG?#-?y` zZhg_k3$F|gUm(bIHAxOT=XUf9`N&UVy7-$}TxS$=2AmO7-Z%I>GoXzCE&{Yg^??@E zqUzrY;iIzOAW&P^WQGE<1;r?TZrb6_E!L|}R}Oy}y1rV_x1m2_kLcO6Ap(nVz55C3 z%e9j>=1+{{4`mV4CjLngr8yH~Sc^@DpfmIF6{Z8)Qj}k-$|CLpB|mj!e-0D8;&muB zQrnBhzHs>$!?v$EKF^9|bYFD_m|D@4b-GgFj)ziKxgO2-9Q#S-_FW=ZD#KPm(k~A` zM&<_$GVjr&C?XDqo7*VtoArZDn4<_-N2H5l_a!aC@pKj3!YR&wlna zsP;-OlG^7yT6Y4kduJLhtWpf{1%3BOH+!7I&S7P)KxmLQt#2IYw$FWAoVb7bl%3h6 zEmWT<81h)kF&B(fp?`c>gWX{i`0}S9JD^+xv@89!Kla@mv$;ysZ%BS%J>s zq55NNn*Vc7fbNFGSKjrX|Mhou$A5U(zx2C*x#9o8tHGJ|r^@%QQiR{Z8eq7aTK7nO zF%I1-jR0T_$_V~?8ir7AL*kp^d%r6ee*YYxa-_=I1I4EBzkTSh!TDm)Fq)`Uz`;(s z^~ZmGxDawwOgZiAKUd+OJP_#N(9`<^oBlT!jrc2814S1YLMtoVflq%E?|+RJ5S@p1 zPNFEkj~DnqrO7Z0ao4Bc|34ot)i+SCkm7Y|7DELOJM@l`|2-H3PzN|gAr*ZM+O8S7 zVj}*c$^UC;LKDSr-p=_$Z0>*f-(DOhx9k?l30OZ^na974)kQkGM`iZzfBh>_pHYPl zL|A;}P4xTw96>XN_c}yPyQSY%`D&o!t&C9jHGJq*3q%YXOo<(L{qy!%qRv?Cf4=I? znm6C+6okIkdarZOZ57jb@8fZ|OtZ3rGBK$yO=LOkCbesdlr8%|=0^#XI1XG*9`|;g zOS}bd5x0CSl=}oc{pUtbigvBtO6;jW%q-TPTbc|C=>ISqOyk;Il8phHpAg)b}-OB4NH&H>YMP@L_c zqN0^FdtGB+;dz=YzezDW?ew>DQ@`8|`JPcs*_iCI`|}Di^ult!l#xaVIauevyfJ&g zS+J?`2zAd&KE};xV94SD+mag9(Mm; zqG{cvXS7Ig7ZpA5+(xH+gSQdQu_sq|^gS`R)6fKW?f1E_#vTZnKFI~2@M#w}C@55( zbJwN6No@W$XI`vWJQttHoqe;4^v5iN^URfeB=P1A@wyVB`>~h{!DfC*i9(atW#X3g zn?38Si~SAz4ARI947Gtd9ev3T?`fP7#)|mESyXp@2~+0S zzU_Un_p=&Dx9G?8z($0316SF!xB_b91Q;voVdtNEn=(_(&=;p6lZ76^Z@V+Ck`U5m zBQyN+$>LTPlCTnN9Nx|2xe5Y!C%}^ z&^90(4i7@PY1%<19mg{RPwn++v+OFRvSe5v$#A7=EyJpJD`fd;>=1HSqzbDu$tYXx zRT^QMr!MD!Z#_3`Y3z|-aW#nQqjiBv%`p$Neo~8FrPB%tR_SbsnVMlEp8vSa8M{9D zDAI-{IwP&MoC%-e*c4;)<)0g>1NF5XJe#Bx!DsZ8GqXK!55ol=k*uU8??P?Q;AmYS zDi;v%>``bM+#o4Foa zflWaO9w_iVylR%L;W6cmiJoyM7~qn3?t`3E4}cR%Pbc#D~hN62TP-{vS~B!2w9(CWX#2TJ-OEJ+VFN!BAbfQ!)NfwtEF)jK?`uJ%2Yd^ zL}O)a;ngy43<7HVQoaUIsYAt~d17s%H(I6XK2nSdO10M1l~K`<1gkT35>aO>gd?pP|#&Sa;%)1c8<}*sB`n zgilw!JdshX?i znM2cct4LeHT_V0Gj+41_DGl6NT<6t1b4#E5SeWF<>!6v-P2qeMi5Lp~`>G*Dm%0m>{&vld+Nh$NEXD$-Ko zgRutI!J&;Gn1bL`%UVLkpYX@d1W@%!11J%NLWBJRHfhaPKSf#1c{r=*gEm)#Al)rr z0C&b|R@msND=BKOXrjm2mv@_DVLv#@FjRkOvLiJvd^y(g(446MXjFL-ZJLmNdPm`KW2b+^C-E+6twcL(4Z= zA{!vJtdvbR@B6(%#i+0!q_8}PJ7ozS$<`zcJ#(cSms!>K&7gEDJb zK9PCmoARcrEow|#ofeN1^25_G4Y3Pr`#BmVkt=0E3AF^|d}TrDiugeh>c$`kKflX9 z@yV6}-}!Y~sMlKQmlon;cf0Rf&B1l%va7ZYcL<(g#HF5{0`=1rqr|1ERqoGeDphG7 zvW{!kFlT;+XGU+ol-r|F$liZdUqBI`7DCqB(SVMxd~@X?GiQt+&xL$a`0q)6g0%b| z=gn@bcf{Qyt-?lI1M2reBmi@=Oc@UQBItMYoPIqV!nkEFm{ksVju_vi1O(81) z^$aKGcc7JyCSHwII|K(>F+#B81UHHU!FU**62E_(F*M*<5cwqae|%RY?ZkzI?!;z_ zNERTfMdo}A2iifQo=;J=K8$QDv*H zz`^Y43jukf_{BtzG$!wjsSHNE1n7M7oPWQCH|P7_Vb|z8UZwamA_oJ=1&JH_diAjq$3MnD zX1a4^kWVS=BZyWZ3-Qzbdpl}_k8|D4@nqWnhQjz!^2Jy9(gfa?{>N3_&+QQ7ZGcQR zCT*-7BCU#LB)LGfQG`o*M0q^AW?Hr2n^CL5VyD?~ID^{DIo~#6=;Fd>8r+|9~!hWX+b1V{zP_T6?37^Xr5Fg2T4NdpFVswoUUJLjZ|agsi?-N3Z%wwoR`z zeME?HWVJ08+uEI>*g67G78Mrj?=b9SEjau|J*v1=n=A&KUJI-g_3-zWFKFZdFy^wg z4y7FFIJZTUD^9Bhuai()K{&SnAcLJOr*G*r@nvakfxIrlxNw@!KxP{?LWzchJv3~p*FBFzef>adj>HHgj{%P>I{Rnm0(vI=f zHqc!OqE;GEKP!`(;9{}ax^Ew%aqBJRgpzdDdw*yH7POkJ_T61~ro_AU6#kxjj{IEz zdq4WgT-}Mc7x3nY&063U(9^!@C4cymX_@gXABtZb(%R_?#ue_0ahWI3Dw}C)1+M-}An{ zZNFosu>>l|)0YQD#8on_i`M|R#?~OzQ)0EYhajqzv>f_^E}W#+ftozhBzJVreg z2C}!kS2Ob}`paLJwiuE})!g5$L{cl69QSK@tudn2miZ1(o(@H9F$mD-aX5B-#5sj< zzow=xA+r(c*uH5D!y&G_72>RZ{h`@ye|=_zwR!*2Uz@Yr~be z)#_+Sv(4=86tVe2cVd;t+qyxXj`;R=g7 zqplGpi1^{0S&toCHCuIGqkQN2wAeMUWkOq*=yZLpQvJdRr!T)fsFT6-r|H*N#5gId z?G%24iTmI4CUy!2@;`i68l2Nb_jI|Su52()rXj3eu9~_xb9VOr^yk2n#=S-r_UzN7 z$_9?=Od;Kr29LpX-BtXnnCY+OS7(UBS84ug$Hp|nA690;^iWRj^Ci>u7ictj{ zmGAYE?_1)jy5q@Z`1GDDiyi6fmI(=NlKVMZ+uppKNhJ^2XB0y`?}-yND6?n(SbK~8 zj%W^v?hfOdb>tCN$e)t$~@59A2A#-)oX;}Z=ZXmtIAKf;vKZzaO!($%BgFpo7FN{ z7og|~Ic$IZN%SnJ$&35}%T_&CB;t=3TFuj0Z?e8NU>Ld0yB57$jH=w%+G6?4Ahy2^qwRJJ|cMe29mN1~!N}(A#@r>I>*TGj2 z4P0xBXH;?#Ccl-+Za& z;1V)ZE>XHOY-$%t4(+)}(DHg>NaVaDD}|dE`{UgnQwQC+`=U32^GO8m~25i zDza|kB-tm1gX#x1V(xmRHIOhoj)TkcSCnCx#4+)r6N1#vFAQ)a@HCEiH}S^mk=tQ& zcPUrj_h2#=Ww)QxwPKqY8cIF(VEf*K3$gL%#GsyL8gBH~H|-;m((1 z5e;9Dw^0`iID^)#lZpi0jdmQppFdz}MZL!!-uIO~V3fk0_{V6<%sSK7;;rR->kq<@ zEV+1Ng}dIzcyZTSI#o37c8c4Skz>TK=O`feB=1r7=O9^UZ1Ow-|Z4Sf|9>Ko9p?svPof9%)f zNSREBy^Mvl-G$MHPkBfv+)Mb8?Q8iXDvW&#@jdm8o^%>dJ$d=cE6cZVF~|)2Ske3` z_jq_;hHw-CSH9}^SF23$s7ach-CaJNSBw>FeiK0$caOf8?bvsQ915|-6HqjNDb8G` z#zDhYxQs!80|e)98OdLJ!7DV0W8#yO<)@T)2Yc4^T|q<cp)Key<=p*zIEpAM=gEixiO_5f*GsnyTm};wxj`IKt+cz}Gl)48 zkiRi*@+EgEH+vEwm*ly$TbHB8CE3xUG0vA|9QH#v+|?m>RsSS6qGh!IHd8Y3YZwC3 z=A{(T5OdvKy2urthQSNhVUCE;6IzKBs+FG)L1w7?PxKmuPBP-$B>7igvnr?YvI!wj z*E=zpz0r+o9LM~l6S>2>r-ZR-RFJK3%k~msw_=W~|DmaO!6z=M# z-Rd<>Q(;IkXEI4s)z>d^YGUHRN{j~I!;Hj{Zm#g+Lrwy_@3SjJHi@ByL+%snH2M=} z!;qW9I@UK`XZZL@^%z!h2!#4^`;D^6$Tv z6r7;zzry=>e^Ws{OJJ-3-Cx&+0ajRlk{$Qp39{u0?1nCCYNWx}H2;i1~OZ;J^ z!JmVAX*%)`4Eh%v`=>p8DTDvdZNC5d zc^tywKv(@B!R3i_iq}n#zs~h_)mm28bh4()UO8m)$gcn%jtT9z!H{L}YIV5bx{!X& zl?)})^2fC5l4tA!K+Xn83}88LNgFU1(!Y42A<|!l%I;q9ZeTs!wUlcnawAT=A+>}a zd?|SN_d@}>$@}|<`;+fue0ehyQ53f4~v`ZUeHZjYM7s339CWe|{yLzt5bz z^}U1>(sJ7};?uIt{&vEYvRDkTYi7VRO$otl##`A4fuv0v?TC;%_bm5W(d21P5?y5HWtEw1gz>Xca_T=W*)g4x-j27v`^ zDz`_Ml5WIeYJa4*HoJLsHdfxyclJ?u4H%r)()XG~od^VV5PYUKDRloaPM1Cj2U}tm zzm}uY3to~lw5HpP*^;c22%Sfbw;lKcN67NX2a-aj@082n4S{Uy(%l^N*$o`Y*dYp> zi~5m^kWRVDG%NYC{_st@5;HW-t`*c+)ZK%f3E*-5$qims2JqIw3=ajxwXZKaZdZ=v z(Ds%{yao)H+hsoC+qXQy167(DBnHn&Jl?@20T>oW5E&vFj-NK7aPZ-7v=HyQ*v9Cx&>QQzXK|J-Y@dbfRIQjKDLkJn(&iwTD{pl@;vjE%c z)RC5l5MnqU9|VFCl;5*kTw^11x3X+`STLN6pxAN`w-;^!6LH;QYQx*(+MsjrYW=}4 zF+XVN16(u!Qx$U3eAg^@yS0L#X5rQmN1QQp@F`7l7pl?VQhFQv8Z_dSiqQpi9p>!( zu38d0I`bBcz&M_P;G+ruOJG}_$=yAZ{u%6=s^Z8mwDSKV; z6=;;|^nTzw=NQJ@i9&^JRKkUNMYHqIScKxqVUWi%t=Tsp7(GbyG{w29-$fmpVnK>G zb8B^;t0AQF!1jTp4G^qvq`WbOP9iY!FGMKV3R2?w6REouY9?BQzgQrmm{DNOMqn`z zTQ&*O^9kZ>cy968oZ%c1o+sXkhlEpm_-qN^i?K%p`6Q&S3m$;42=7Z`Z7-JkfiOgO{a+>b1d*&Lds0D9Ho-jv5G$xNFwC#3NEw7H%$J}j5ODp(2IgLsDF zadFk-a1Ld6c=s+X2ir={CBBH8X?aW$&jli|d~|Vb{o$%TS)tLpH*=srQ4bZHbGwNX zx7Go<>xuz4iBvS5t#}63YmzW{mX+(HL1%Gsm>-w|KWK2cyE|PaYsNQv?&~HFdZuOW zpd0K~J4s($w~ngu)orW|avx>zTnVe|5_6;6r{Yo@Vrbbx59}NN2reIZ@BB?YyTn52 zN#H5HxG7if@vgT@?-5E%w}`r0m?wtpxLb&ue70RnDXh(^`6nDkr;TCEjjb&uV|CW@ zRux(qBu1h9W4A_bHwR8I9tjcM<=u`{`zw9Kkw%UjuoGJVF~FJsNrWz221 z-JmJXX)|av+S*LNz>kcBfFNgXvH~Ys`%>x3*-CP@E8M`R?I^D9*awLA;bvjYM`CvG z=KJ8y+Jl(@QDL`+^96e6rK8vCmjOlGnq*Ncae~4V3wTU^XS+c2G%^ExMl@(OB-K2jdIAX|KVxpkPpK66miSk`-G5F zaNU#L{mJKU%OZ#VY7DC4pk5z4xBi%F^F^UCSP6+ZbDAj}<9)muL0?`IZHW_)56AGS zvz0w#K}88Rl_GUWO|wk3K^y+)!opkV7#TWV`fAEnV(tli5Haiw@#iM_vHSIzTn<6R zA39k)mb)i%#^7pqw65gR{f$z(rbK!L9y(kKzqG9%7SiZL|yc5@MmuktJhG`VYe zsCNs{WO~+PYVuyJXyrVq9QDRayn=`|Z{$4<<#q36_G%xDO=-t6gy&YXCsRMAN_eIX zBBigEOa}R&tr>&$#^ZXbLaW9P$sSfkKpM=yc~Gi~14w#A+uIe9fmza!VEMz@L{6}x zF1+vf!!Q2H@$DEpNTmZAM18mF<;F6mF(UQ>vTYGR((LG1Bff+X`eP*ueC2}0)eg}J zcH}pA2aDG-;##h(Y$r71eF;`&Ewf9;gA85@uUblJkwQ)% zZv8XFKp08nm64?CH%{)IF(}T7s^Z+weJ>GmTA3?CFHP~9(iV5z%?Ud?YLChx?=N#B zMILKjp`iDKx~y%JQFe8%gerN9(m>%y`L)~#!q3iPb8l{kP-vl5ceP&;y2~M6cN5|z z?lo>mBF7YaCa*eo#IP(99_x1Ar}7)z9_70S6ih5=hb`_~qciaJ5fr2MkPD)|5t;IM zUOHG?P9nAt^}TqQ(nq5Vi5GTwp6uYC-Y2;_-mUrk&&`Jp$xzp*!xG)Z`k7t3%;zhu zappXG`X_j$49~-DejHq1%B}0v;VrasiseBE_g+j~LEq5uMx>#d)W7pK>m1aXYi6z` z2k7FD`}Q-fqWVbWd)=7^EGOHjsJlzuiK{_T2*owjz_k>gN@T;o11XYc#SFYgCM!vYVhuQjx{?(E&C;!ZI(CMTgPnY+m;lbnk)2E5UpcSho3wk-}zuYOT zQg52GC1x0J6;H%Tn0c60)$*PmdNd|K-}nT5qRC(8d7X6pUX(4u)YLm);@#-x1{IQ_ z;oEC-MdspE&a2YrN^%Xy>u;6)p(lM+TZ8>mSdab70E4~LPQHuU*jmCD?&&YFI`=_r zajj>7+#oC`xtY3A6oi$Q-&3kDU&cswxiWQ@t`T_(A9QIl?$#WQV6s|-<4O^mn$iv? zk4e35tC{(tg+#vPm#}W%#UThwH$y+xpsX$t^Ugs|GJ?EHH)3s@NU|s4nW5kM?iFMc z=;V9!_VpfgcO`$O(^;>f2U-m05|Xh6*nV{RLWdnmr0#G5Ck48~zUGSPa+TqT7Vt%) zzNCba&|>=O17eG5tALG@JrnHwr>n7=Y0@!7?R@WYEe#1`bv~o*70K<9sk5+H_2D5G zWc`Tw`Q*WHp~XGW!(m)4WTG=Pi=bS$#Z~OZ;wxvWp2AG_pv~B$=Oa>xOkS|S3!tQi zuOBTvpenb@?D8t;OGApzE_&bP(d{ItC}+lh_;nu}dl#Z^=W zvbaGpv%V%5lAGio*DuPW$vthI*)?$>i*#(=6WR8x>;Q0=_h-Jp5KwK4R<`BUvUJ@@lYehhYiKr9Kw^41p7fB%# z!puV%xLdwRxo&#_DgB9wa_jPq_-+{dyS872Zf`^Qw$KOTohRZ<5-;Yb2n5}(3^uCP zZkOjw?iO!72OG7jk;p3`uQ$P-M@TiNYHF$enei#3_V(ue$2CHiZ^LmiGWRk-SX-xZ zU&qiZkRPgiqnVA?vikJ&N- zEh;a$zZ2~A>OIv;DayEeilJ{aGg9M+BGnaCqv5yFPxrLcLrO4kpRW*p z4j4+v9fA*gjwvG2KN=_??n|i%Dqk!-)0}XEeh{bBxQ8C&ob64Q->pbrWsIW*OjcW` zv{=|9K5CzQSd}63P>8hd!=li)+K|x%@koP%1}{JUT;XyAw$Cdf9X`%fbQ_?boyU#C zMjN8Sh!}IIV9w{_r)fO#U;1B~rXDY|>uDmXlq&{j-4;cORooW2j--n@JSW{i3l68< zfMBV}W2P+ujmq!i5ww`=hg`AHPB0?NmFEvOv7b8)#?N(g?%HO-Yd9YnqH6JY6(38N z%|zmLX9(`jhHd#8@?}zZG`x~lJ(1e7%BQ9rg~y#2wnZWMEQCV-{Z}?9KzaFwX;@QN z=tjlS+7~nzXpqrm#|h@a>!~K_4tjLNb-2m71}+;R$>z%;W1MGU^*=qdXG$l+0R2AC z>vgM|_Oq)Y(o(lhdl0@e{i)knI3zJ?4Gu)OppUSWK7-(Mpw9h>$M10jl$XCr zDLGq>{a{>aoef&&FVNpWE8vfq{f;A`=m_E-hTZv7Eel`6A2gz8m3+`G3$-n(V2{W+ zF_|MLbs-;6DCx6|4?2p$&2|DM14w9aaEY}cO$%q~JuN~WgD0X1v2Iv>!w(yx+lrVJQ8Ep`UU zu7q3Qsoz^ZctDJH5AGMftrfEB0PU@)9Gt(1xR7C*2cGqTM9?CN?C% ztUTJCz-S{M1YkA$75~P78ElrJDZ%(y#{vg7Kso6W4%BNV8UGP4QEO1`0lFG25IP%g^mGrOZdI51QSt?2Aa{C;^) z5cgMhyW+h(n`+xq$(u0wM|f#Q=Kfq*snF@+g4H;h#JI`gGcPO6yY`%Zswp(PW6@d- zcb352cV?5!AGz%Y(+lH_n(C^_4Y){fpLT^8)o;!BXf~4pur75gRvxJh@?f0E&3w<} z0deT-iwJpPq&CebSMSBWVjJcc2$AOB??3g6*`o>GBi-?qn49`igxk+e@_18cTq`~K zIPUqFLJNFc;iQ554VjSWDys~9D(SCNVbyzCAmjN_R)N8gZeKEXKf{kHXO1jUoM zG1lt>6QV}X@oUWTA`FPE0f)55o4Sq$GMzAt!v8{&MoARGnE-#4vj{XoGs(7obRarcgv=lEB|^R_YGFE_ z1>A6xFaIGQFwvq3s)+Rv`L$oY-e4eQysW(-i_S_sQ>FDm_I@pv24G5zF52IE!o@oh zi|)QBFZ-hy-I&%{u%~%3Ymv3v7!b|hvs2I)--HzYSQW^i*s`ne*FuJOJ zxBM(5b|Cw%Vf=(K1$Pv_+fyNgOh5;0x5Z$){X8mr<7_Q(Sie<#<865((MuHmdOVm3 zIc)$3ltupre+k#T8#r0M9IE3;WyelAPvrADH=L^yNQ5?=EQau^^+TFYbw827^#`Sz z(EW&i%nO)OL+Q{oJ0$V~?Nebn8i5Fp)3Ny@(vaPwF18%mMrH#@M^`fbs8rNeG}iv1 zUpZ^F&sZ!6j3*nsra3vB18Cxs_3lTjdfaJHCaNI2i3JNqLO$9HGF-OZoy2^)9i(C% z0V#6>a8u;8ZW@?A;uk{BGYIdx*GPu09lzznl}(rdr6ce>akd`2pZeoq8-NYf=R>tm znRK959p2Q8>265mN3)!r40ZNjRu9HFmLPpB6XT+`>LG+zzd+%ZGO`)P(Iy z^{%XZds-2&&fo94a%rPn6k?KN6^gpWV|N=J3%^fDCk?L^Bic&ejK0Bl77V2OT;UIc zf}OE%&6OebP$=t+SZG)CD16X$V0of!7vPfQ4K87+UDV za6+Dc!1i>qMTr9rf^GY|x3vaMMeLur;4FJ&x;^&IPr%h{!Vtb{8!N}6eC~+C@~)Lh zDdM2rZnKV1)7#;!jxL{~m{azZ2DT;d3XIve z-x(sN2G>$6$!T4TB51(7gTv|!pdy<4Gar=;9u8zSAh1~O7HM>dzV~V?T`QhWa_p3O z|7cI!S$l~=LJ3Xc^ofx`2T&%!RF5#3EqL9Z`*;~bIMema)3bolC(=o_Q|o1;%QRNv)O9La?c zImPk)aRer%cys>Tw8Q=7bFn!*kK@xV^G3v^vE+Q7wRZ)Vd;MNK>k6-zyvLq#?;j_9 zf5Wu4UdWci4R|qK;-DpI^S2i;?0eM3Q7){A-l#0xfT4}5wPZ{H>jcwb$*p$xR6L@y zw(1>N0U7pk{qqAlC||bgriuGp^gdHgvA@^%17}ln2t4|KfjuW`*z{ zP668kVb=YVMF6ER|Dl%t<_!Ke|38U=f3Pb+&@uOyVC6py6dYXR@2`Tk;tU~-WdXVB!)t6&s)(U4VKeY;IjAT z*#_4maO*1O8U1}YxCbx-$dh!*`!C%PUQFMB={=ai{9s`IItuQu&x1*6hH4C*#6bNb zXj|wDq9-w(u3t7LgE>?OML8>IH3L@vuLI~(r~}@oW3t|9w<6E8mzZyH1YD^Dvzw_F z3vb2)n3eHhVRZ)MGFZG~MB2;-J(1L~QVt^ro_5T+X=wgK1i+W@S`FO)4vGPy^whGv zk)rEV{iX(LU1pb%#Iz1XMrDyQ+Z2NcTs&sm?Jtd`D<8fX(5YOhee&rM96wMA{Vy*I zaS#MW7p9wIwe}{?!S`7@d@+#>JGKYu@Qu2!BSPb%5f6TyC8TQf{^Z+`g;1?gBb>x& zk+ad&xw@P;loHd=+^M~)w6=IGC+@4A0OGc38k`K;-2hp1x6XqjLHS?pl(gWoqJiOBWhLD0HY#KN|5x2thDEjhYY(E1G>V`oBPk_HcOxk! zEe%Rbcc+K}BdH7sNVlLg2y8$>kZzAlYRs;+UZCw_VV z?mL{Y*YwzD4Kd`oWIAJ?ghYBYhy)z@2rN=3AtR1xVU0H$a(+0UY3F?sNTe3+YI zeSaTcbA0h<4+-02d3#eS?P1WLu)06Ep6=WYw{B_IHQH4o z9NPFClw$O1>}Hyan4Q-95Glk65rd7}VJOyZcab3kk)%4elGfg{PqcQ_^9kJ?H_dKP zQNtH^TNP*>T=Cr>y!3p?XC+fUMu0(1=QPZl@{bz>d_DtX@ID?2*%;MO?@_|2>5q-- z3|MfPFYSAXy~VpGoXuAYj-jBo9nw%RvWECR_-@m#9Nqvzm^b3@@1{fp$z{x1{p9tN z+xJlh1KmClg)JSPR#XvuV2Bo_1IVteVUE16tt;Q#8IWSz{UaqselrU-_lzbScluef z{pm;IO@`?inyUlS+8=RS&a&LuE zUcPj|T=D`A^Zsw!$Y~LhZs?4yns@+sl1~I610H#8Zv4ipx0)C7frRahmjoRjH)2k6_s&s?s1i68c}}c zQ>a#{gr|_+m?XCguBY1(5J*tB+ZMr@Do3NL;O*%Uvi|ABZw;0Rw&bP@R z_C^*QQGal?nd-ct*8Av5-gPZx7PsZAfsD$bE4l+qtyFA{rBkE#=TX1q~HTg#I<>{u^X%SvWVWW4?3sTaPuqEkT z(zX25)2d9rn8YX(o8oA1wRWwaa?LE)a-~>2KcJ?FX_uUZ_f7(-T3JS0kL!EKsJ;tY zEPW3n3T(Dx?>*DER811XG=B>!hryDUz#NrP>HR@|G<8wk)_9DVuXjJUR1U5=Qa0ff zrfILH9#bQZ?Gqm_wLY0VKFL52q|le)43nyk=0~B|TJ`mVUp?uM649jhtbOW}u4rhM zL@vkVpz<_@mCM;=xlp`wR7TCeaU>PH?xO#aiG2*@(`PvAna}T7Zl|zm9A5688pl2i zm_vT~^~R;5y*!>B&wYdy^Awzlc)3*5k({s6=2|Y==ime;XWfU-WB~qjhy-4m`h%5B zzaaF!?y?`jfGHGifQ8%yBGum0%@NR^f_&@5S!4^)wCbC=7>6bZ;FqVS?xY-QWWC-C zB|=llQu%hHxpu93PPepD>{>25;`}y={=9Yewn8(+UiOExf6FH zRgB~fuFl@SIof>m+)`QCeX;kG|e$AtrN-h^4l;c_i2 zPKxe#71=;&YqzNO&L@?Cv+?;ViK(g-*pI&BJ?dj{kYOfD2C>GxU{grp8N;fVYqO`r z-BhvbV+k&i4LzUtyJN7IlH)HEYFNJZGzIF0-#-iSBj4J6ah!Pcb*BT0U%W_Sn1!ci zWD(p%$h11uP#I6fG9-DkO72e zfgTONLpQ`0gC^iK(T0#t|Cg8#Vi^a|M_x4dj+n$50fZ(hwvcYC@1wgn{u~J^mEt;Y zrWo@sU){}bEC6&YtXxSv%eT43k46&2ytTpmC=1g7B)%p`xgTbSnVMFU=KlyAp*d<( zDMTb{-oPX?OV{||Ew^x6uF1T7P8NccSM4_NXIG;CBk1`VzJhAdlYlNo7opkrSJR2P zLve$vvjg>(~@}~RcrP7P(|Ur zH*NAZ&r4v%psW^(iGS|!zXR}-l}rOP{ebMg{cu6|6Up|IJ2#vph^fU^`280CDhTUN zzDqVMZ6S9XG&J~K0paL`Wt8o?**%o}A|8Fe3>2yZlJ6=YWt|nC#!@xr4e%}VHcF_? z?%O0)2CzU12*}rSi3@xwn8>$tlxVY>lk39ABJWT|w%1-xE#vfuGw=v2&6VtBl<9#F z>WaDrbP-UtxRQpfVCUb|01|va*F5HZ3$$-_psS@9{?F8+v>m6)>XSl=SbwR7{}!8@ zb6Z}$T3FrahB%xdb{~;PH4C&+C`%HMeYc)w96BbZNxgQ2jZ{q;GaA!1mpBqC-<6%>UMZ{YkI^EuSEj6D6Bz=MZ}HE<^Y=1W?XC{ zsSXvo^qymO3cw^2l%3|egOL%dK^^{3isn5nAB&~MA2#rq#uLrjyvz}xDm+Y@Y9ECm zsCEJXn0F!IH-V6>7j=TKdVVKP4-f-?-XV0J+p?1|h2gtT`GZmUw6>l;*=NF>Jk^_p z!K~CGp54fS!u%*w?Y^Msw=h^We0Np%R~8INDdf4uy$9jq+xxbLrF5lyDpf1Zm5n(o z+ZDawp6&wkKG7^ngF>m3os1ZEI|rWi*3NTG?ZMP_M07P!+UEE_J zAOY0QJCcNlCRwJj1d~6&`>p<^QAc)OEcD|#pWH&=o?8ElqBrGlFT<)&|Km;80xy0} zMo(=wJlB>chtvzWyQ<#o{7AR#IB3RFQ~ABN8AU{b+?B%x(vu(|xiR@dy%{HJr6FhP zxe4i#dsY3LtJ#3}95L$t;?wg>`ccK|UleQxP?vz_`Z(x-AfSctg`4Xk*K`5t5P0o5 zr$;XgZla}?qs7JsNoI4LzvA?KWzFrZ^?M-L=s^rK4EnuGjQu!IcLLkNtEhzn1N7!F z=J=4+=W?uj_~c0r*(fZ{`d;sP`4bO`cCsFP{odl% z>=fHmu%z&Ryvb)U`7{`&a`YqL!f)E&At3&6)JSOpXG1XSsT0t97TDONGnRWvk6UhUVB$f=n*3bua@#MJgj>aK0)dERyNjvz1E!idskfp} z4tFQcJJCz-WY1QI)_s_x_2dwd2x0elLpoQ|gG<`9cJ5D@UD{RJaTIDUYq!kntJ`Ub zH;z%k7AVFlEPp{byPcs)(L&~26t!sn1t_kJat@H>R~Ztd!358zehm`!yM3=$n8t<7 zK}y^&G$)_gS{n7h{XTgw2~U|&9u;FBdlXLK+a^CBZGiKG$~0sLRFRzKK$m7^ZwYca zXqJ@Y1WjR;iQ?x#Oa|VDJu@x<2s+MjBW&4aJuwRE%Q?9B71kur0a8N6EFTKBEW{<( z`y`gD`2oaF#*^uNZ;#4H*Xf>xRTKYSKi3>wx}^6@4((tMq444jWNi8(h@Z?^3)1;6 zfgYX0vG%1|ePr?LO=5XTCV#Gp@nOybDat7X>7?D>n8x?%H|n)Noub3#P_-&lQ~O zjlwi=Ipg#jJYKx-G`fSdV1f1xzn27L#z4D6@x%hC!#{@Ot+8L$?f{Q~GsDY$1t_Oi zdHtBn$!||iZ|4*~Z<+)QR$|=1M$GxVEV>$m?1Bj}S*B-T3;4e`4#M7Ed3EyH`^576 z->HY5HQ;dUJ5DA;*zRAIH7f&XGl_}iZ>(daiIH`ZXJL#)=+P1g7XGVt7jg1h4LFqI z;L;NTfi2yV<`t5O!&4kAPJjHZ&wHHp^!Ml5QMNFg_}EH^E(p>6tGvf^3op8hVKWk^dHwr2-I<-P4^k<=_PBi~_MY6jRy8Ki>lfXYN&Htazaea@=#l__eHZb{i z7;)9w6TYcGyyt5bcZmtFdBi86l0pj@FoQ8jE3!YW+akbSRMcZvIekal%HOHnKlW1-h zN-YT>Rt4Ri|2$4sA-G&?>^k0SO$218Q*XsVR`x#+3E3(nuEnTC`lwnBy3)|`|L4I| z0w`pYfOrl`(j}pv*WuqQ$KeFwkbNC?gI-M>WQR1-ix0bWTOKVA)@HL;iP$^=l%s!q zOcHvmz+a z${*DPb5uh*CFG!#N#!vH0H&ino(#F~etexa2omsVx*I)mOUQ-`^f9C#A|ip@7f#cQ z6w$4Z-J^UVOplK?(0=s?U*O3kt0aAU%8@}qI7C2F;Nq;ub3M*uJQs;_hsk8$MmH;i zq}Vx9t(T4x)tVX_0pGO}8~BrbSAA+oAkrt}v15aaYVy-OlEl>R z$DBTZ@KH@o$LjSD<5I_|Z{NOwWFY#{!Bk7BFyPs6%TK?V}w2RA`K6kGm+O%@TEptc#7zc)nLFWQu zTm(}jHFJ+~)l+}@^UuQcYqFCnQD`r;&RbTP!~oi8>kYMd;l^; zp$U*F+>^Z1-1QBp!m*aocm*tZQL34&t*(pj+Q**6aXmOJm1ml_LPQ-Z^I$NoX=rI5AR;v! z*s4>({QO%zN6T=~IfaJHoJiD?+}mHz>Kjwx*{JFs1P&0u^Jfv>>K#ahYm!`GJp4xy zW-+LjSZUDg%8LKYUwvg^^#_*qD#BSi--h5u?w`PAAtD#1$;OHwj{}k$k{v4F9#_!K<5HH9cQ;W=iZ7NuqpSmM^w6qsT(_CU1fKv|bo~xYi_{DVB|l@D-}Q6y(|D zcs_ZdcX_dzmy1%a3|(QoKFZzo#e!VaQkq*c>zOa$__Ug=F8k5OZLXA;D|A3P>w{{& zUlPre$syPoYIonfF}YCwc4EVMH+zi%Qf*z4gU|Fr6m`f}G2sr{wiG4E0d!`J;WjFo z!rr+3IxY}oy)iqm-#*0a6IStR%rtb1zmAw*!qc$qB7PmG1fS^yEs15MC^TIjsfBpX ziHPK^hNf|o-6DFbPQfH(K;GA0f1thQBo7ahJDQq}8}%2QM-A0gW4;NSs$~HJ5vOmf zmLvsLyNkzrCAHKqf+NH$-3@sRg4i6l)$*^CV-N7HQHyWh3`Iw2e9Qdn-u{8LLVnf} z_;U%p-foHuVRKUb(#(naJO-{ta~JnY_(G4KoAphQ+d8gWUOG4x)hwc$ z|4oilzoBT#lcKyTZbLMzNx|aPqihF_fw9;{oxk$7hw8sHuOu?NM4z|=LlBX-3vYig z64<<|Q$+W+YVHaa?+_|GxQc$tgmJV&L1Uj9(2JnFM=5-!51CTG)S0b;;RKkI+xo9g zcb#vg{epuM;_V9*m^v8O_8@F_mS|q6LmP5|1~?3+sRVcvseKo(rgm&BM|n^O9F;(8 z1KiVoum15x3hY3a4QIv^Dqz0?uq5mO)`0Nh%wJOhALP)odNyg@{D(#U1ks8@G<5ih zg?iqv9?7cBP?^iJ3LaaL$msD^Fn7M_RGiN@@LIaiVOx0|(_>K!FacZVtZ!G-y6)m}3tuEYx~LrS z1&0MKR#5c~v$HY;O{O`mZO<3_b1VX#*u1ndkA{K~HH=XJh9BdP>2e4o{w%Y*TDy|X zK1@glpV>&Qh}$1rPd0w>VY8_r#Iz@@3**XTkh~Hw-9+Q1c7)5W1n!gmS++Mf7XveV z%4tSg+SUAHDRXBIxm$?hDCe`gz8szkK=ZwPF;nRORitf2M6>j+wG6qfd4J*c!s9s# zz7o@%_SX4rwh?V&asGUiyD86tqa%H|pzfKv(V55-YtxT&e$-fm%AXgt<+ck=^~plp z7}x^&T>#F9Xea>9gZVIxhNUrPW+8%}GOH>1s;ax-20G%^P}0<<48W|94XAp1Trco- z^--V&!#AJC!+5hh>+X-b2=X5R65c&9pBi=a?ft_KeYAe7^F>D{T@7+Zeu^Qh`vb-1 z$rWCzK!WU>qFiix$|6(hQ3bj2i?eMptGefK)nY#Fqju@dnwKaTZVVD}XXZE?@tRYR zY7uKWA5j=)|6B*A0!5o^JaPno!raQ+G|>o^5wh~4IV-`V z38@1_LJ}`d`taiYOyAukJ`%|J{{ZIJcR%XYmU5XzOE)@Xtupu|m3aX&1!zbod`jn< zuE&OTI>}iCgmx*wzKb^(3b!@<&IR~P_M5+w%_1)((CZS*kB>7-4uRqPM2=vQE;S!B z08+bEe(MHQIr(~wYO{B*&!_O)=d=rmmrOZ2 z5didrF->%eC^ch^W9@VtOLPPG-Ovw@Qwxv-yLW`H z0a-)4lpe0EqWo5-Ux65xDbG?Mm5AqEl%Jnp>tweENJuHmw4A{ZXPs+D0`FUz2BH2g zP+4eC64q(Svz0jr*A%zrm%+*r;h3B{F&??ZPt-<9obAWcB|9f$@6lNI(Uwvn6Uby= zBGj7G*3T3=Nyrk&?%3vtw>|;`PW+)i4+)?pq$7`~sUbN!AY*}Nuwrh%U(giqWA4;Z z^Gpmuu6CXYAdzQYW@;-n8HRUxZIp-Zs##Fx-dN^P76`!hJ2?d=QO;Yc45Mp$=+)P}OEabxnLo3{_p+WgE#pc;eI5&HaXg-D`mh~OKTEsGmY|;f_InoctN5t*Z_|2| z6H2NCr)KE&O+^Ss$J#C$5L(3SoAC_XEf1CJEAg^8V2M#W33n;rGv(t&a+8Y2{vT`G zSfwXT)XM5Bj|Fx3h})w92_H!2Wfjcz)WI2X1Vupi0vpyOFh0d~Q*Kz6WHQ8UcxWiw z2Fx6lC~d!K|GfD*@dB*$q*w#EFIKQqd2Tg*yZ%%F98vd}stO>VBvF@gM(^P#rVAL6b$Razq(LY&x&kK^~J)-vD$u-p$N)B;KSnwFukg zC3N9Gt;NO*<*3lU5K(esw)FVxr>;Jq;qS@GCN7*xgMCW zs%9$nO@VL)sRxhn4a)@(XO~xNg&3K z%_swKV&zBfH# z)Zu$Rij&s5@bLw1`SkpRo1xJt%hgPqLFoa)<&Ru_i2|CEGDrQ*RmI8$;WIvinp(Ot zgC%+UkJWhwh zySGcsvgED!X4A|0s?-%Xp4EZUG{K4=n;~hAB5T>Oe!Nfg&ZQ6F%5|yT5P#I@MlN%e z+V<$m_~XvRVm;lm_N)B1Yk)IN%8!_k@S*^3^i9nt38VOC#A*{bQEhCt={FvzBL)EK zq5pKRsGLTGSxUNW_$JfO$YhoH3BN#d0mro~&JrKNIY~b3G2j-KYLaqe6ORFu+^UM+ z{R3NzeOmqCp7lD0or5V|hC-O?7912GAS+I1Z|dMdO!zpMsUENNKXlFRMAvUDJiHJ6 z{a24g+#_Ec*qaNCjW|(r2Jcx339tDseh#WA2h0SG4Wrc5-ok8loktQmw@Yb9KeH?QamX}L_EDG-ZBbonZXQKrs zK%;J-W(AI8MQ{>hEh*$cS$svnJ^+L*|4==hB$U2Z380Mw^{axrDP*$cxOB2cz6%Eg zs$v#;g=S0PWb;K|(;iFO9jA>Uog|Qi_SNWMK{-{gube_t%V^&N*jf+{Eax?zvqZ)V z|07oF%WTzaBY@I)b8!9IA~;P=`Xzr5%WiTarhFgQwNY$1G&;sj`R9Q!_4 zIu85TVM|nQ6JHat5___`cDI-M(p_NBZSVAyNWp%2G=MdEes28SE}tRjI4Ll8;zUW2 zNgph?7*_#?++y)=vuHaQo`Xih)=9zvR6OuCpW@zEWnEofRvabT@gyd%a;0F^N?NZR zE@z$&JoiI;6WxImNCBnI7MoyKNP62^o;obW9pA|CoXwY9C*&*WOZ}>oRzP5BWVMY)^K*84C0M4p?VI$mq zc!Fr4CkTxAAmgT=xd33y<0s8pb;UjDslVa_?kcLtZPZfAs@4aEBk3R_P>7y};!Q;<=S Jek)}X{9lE;_^B-@o7Y{_Ec3;jz~0^VsXN_v`dLczX4Usl4ny*>&sI z$zQs7&T8E{Y3#an8;)(>1pcOM7v&0gS|4C#dS+c=`+g31A?C(B=*F#X#=^I}=(|#|~W_lx1Q#%b>y>jcKQd3i# zFHIlS*Vn(*(04SmA^WxA)BYjbfmH)1pz4LS3 zzl_VTj~-aiKZwuII?~a3*PdqbyrX=3^rIuk1Fy)-)TZqls7>9sh|{DG1l$$}erIqp z2}oJ#4I5u5o;WfXz(jCf--^4GlYzYhm+(8)f4}D}_6&(OZzQ0@}~)A9!;w{OXWLgJ*h>?eqC}5%vg$SX!%^!wcxAQgA`N0TOG?ydfJ_&7nPGy|a7l!z5j=(HV-vm`7Aw$=q_i{0K0}OU zhcx*U463Xdx`ok5p`(oJJqXGzj9+$1cGfi&`+FGmQ)aHj#wi6`=K`v5As)R&5T+m$ z?|Abn`K}FW$dY-8hh{mX)pyPh{_;hcem?{6M^qD7{RTq}uK91Qs~pFdn1oKMjT2lo zQ>P2a(b$?2(TZ+C>?l8s=Fn6aevP?jX<>6qP9EO`35&J##J^!VIXCrX>X8KSFUG4&qefRAEj^s`dN!@O1M#NW`tY$0-5T*m(Outu&UD@V;hpD7&0&!d z#(#ZK-hDd1 zbGZ_?Qlwg9m`{}m`TnlW_xfc`y?(C~Tu(eAi?)dMGOx%6!9vH6luMc7X7E@g-GX*D z9=C0G0kPXDF|4{!tFXw@j-=NwDefYClPl>j>J2r1$9-R^V$9_=tmfXesm`EeS@%up zm`OHI4%qeMtF`{hpVj6}7t11j>6P6MPMWP9Q{-ti===OwGftK^$52a8G#Os8ilhXh zctJ1})8nUvyyBy{PINW=2m4|$5v_@G_crr9fNy3tQU<3AsFtG#oDgWPszDIdA$>#* z!N?DHbL~vx_srrc1mOalLmymT*W!FfCaz*D67na6Xguy6xuxOECoL$MRs@U0@B2a@ z8Zb9?VYi}jT+as7gycbC^hjBnfGi_&h#0qi)?1nsDC?Ad-o{uw*8u69``OSr*^#*r z@^mkpZr5mdX|&DAq%?GZp13a7J4eSsVNTU?go%FWel6Na*jUC9ebTgJ<33V}Z~T)(_w{1)Dfp_Se% z2Sbx(SWXvtctiog!t+2?dH>1YLGilbtuXmHEYucU>LT;n)f@QFZ1b6%B7TowL(ed{ zod|4Spe)YC`^sL*(3Dw)RmcUtDwQ?|Q|wtd+qiRqZ6>8tqL$;%K)kdscUV5?bxE6EP6{i%E z=CK`da{Z2^EwLthgAYT_S>{{_3{gM6f9b-VK3-&3(Sj7GdzP1D$&l&Tx%v9~4--*} zeivn+VRzxbKkw|+%z1n4=~##P1;`D=(u!#U-{e!iL66vq;t zpuDt25ZLppVQ6?cgdVut23wactm*kB=&@ChAuX28i8KqjH?Ji%Mk&z5+2WV{N4ll7 z&?eJRO-i{OtnerU>-z*%^oi9Gt^3Vs&1xTpcH4~EQO_RZ2_D6!)Z6$TQes&3p>Q~U zxGiQBrPo)crZ}!EP#rdw7HL3u>hzTdv)eiO0~dpzYo+z}hal(>C+C14ow#%ws3zl{ zg8g3VqQt8$nJD9VtoK5=^3X6_gIrr^rrK9?b7l%!k}`kVvvb=8b^Mn3q==;Ufv~=1 z9Q42AL07>wQ(G>4ADH@r$6=RN%>2o(YP1R}yP3K76-`OH-R#8_t9|`C-{frV;K}tE zy1;g7pxk?kO~dRv=5}$PzDH}81ETFP_VsGRC+e~H+n3;GrJ?ZS?Y}s4ws%ez-MZ5^ z(ce|ni2&c;R-hv?%)>Ug3PY$%fj>}J_=VY`uZs~-P7E7-# zi-M(}u}hl$By{;cxIJC4;7SH{O?HSW4pF*#D#SRFJVh-UnJ>lmo53MuVGXHhgk(@6 zstjEGlr(KSG0NiD->JZ4$Yc zV798vVlTIf*@3papq^i&EX^D9zx~Oj{z^GnPzU-*1tw*BsIhqJO^C4^wbUz!4=3x@ zv3=iU`}Cj`Y^y;XW%H*^7ahA#St8P7cP>hD6Qg}T^%f9DNa1c0dTb`;aU6_k)i-5^ zje8_4MWST7c0XIbYa>aM)t(Kq#atU7PNZa|P^RE)u5F1^I>9_A(>S^w<|j}i=7%4u zqCLzH9~C(JgjJP}}nxEId57v8qj@kaoLvXt! zF3IeJOmObyJJK~@0aRvddgI{J2!to@z^a<%)T)QxP_jQV5cuX6RRtV1Opu!^oi_ciW=f z?QjV>-6<>wM3I+U?{*iVXyBGL97CNihL^_*h2c|jg0QgHnZlI97LQR@w|1s(3N2LW zXLjLfMDBhPUzwFM-Q%$^WSj&k7R?%y?QYEZ zbHa>E!bzU#Bdq?pM1E$%V2&_;NW7d$OY!MpFet=m9ub)iVP{4Q1X#tz-ez%&Os-xN z1A5vfLem+elFo-6ai)il;oVD3xfr%xyrn_`!4iYl$)W}0%3SC9oa$P{hP1|klaH(n zXNon`X?7y}^mZ@F+Vb#P_5?8kNndC`m1jvrdi52#hEkPdGFV82^%eepc#_7rVP}23 zkz>V|1YM7X{e0}5zBN);QSWG;YZbeb%#)Y>Gy1GM1Yu}XtB)z&{dc{HNVBhTZ&pV6 zVe9&%iP7Co#?WL!q;TUR>5fE)|3T%(y!QA3jo2{X>Og)Gw!UXLYW&tuJXhp!`KuU< zYrYU}A>!U{=$RGRPDt{7kbXh3Y}Kp%w)~D*b{>7tgdUh&jNh3V!NHzcKGaD z{s#=Lph8tl*#q`$ziASYSj9SrrwW{L5pmBs2g4G0R3VP<52#5KP`4e;V7Bg zWGqy>&*!_iKhs4*X=@DP_g+HwP_wj^HbRAeidJzj8rJVqDUBh|my0xffoKL7NcS!H5*&b(Oyg?w26r`X+lU5XZJ2HC3_O%J1Ow8=QKa9VRoi1juys7l$PxpBlC)_>0 z8_dLHoc)w-oWar`Tx@?GXqQ7^r62!3-}5?FKVgRU;0w4|DFAm@XAeT*$)o z6lCn^Xz?jxMXpvx4fwadEMrs3GWYNG;zJkB19yB=c3C07R8z)t_km+>$XjPIXzA($$oRm+r{G-5eb z3Du5h6dL*VO-U1@>roir3Ljg`Ra-Q#dL0^VStr(*#!K_O1#p@`>JE-i5-(LkoYKo} zNTnuBLz_+H341Mlu*>~99oGj7ENv>KaWnaanJx=?DG|-KJfqL%6BVKX@7yqoGpLAj z;P~vyxm<&HC!0CR;zFG0M&JzW+GB>T&$4-)*{%weOGCLv&|}O!8+M!V7Ro?%^}pVq zNEIsh?5&pn-@@u+Xg(i#M9*ev9&t{x$n`A!mw`gFqmZ+mTWlfM!-**f!k@YOUzB=3 z<%%nLXJWLxQ%Ho%*G;<)N06!aQ4grp92fkqMPx}*oGkY{varGwolhX7)GG^E4(}%3 zYCZ0@`?5u@M<%g_n(6b1k1VK+rU$ou%s}2~sdCd!XEd5ml!^LaS8JZ(B6zCTMcZmX zY3>9_z#9}^(0!R7HdiMT`rnaxT$L?q=e%kRU#t!6_^R4DieO|jYnP5W5BdkfCqyqf z-}mebI?D)uc_hrs4Nl!{ER5XFX&xG7$v`bHLV^|3KK&({R=mtF+Olve?>*w2C8O)x z?08oZQ$Np@7H!pF+iR)Np&vfY@cQ@LHBRvnX!ZfsMz{K$vECampvFkO4yhZMo~5J} zN5wY@u*?>Q==M$+E#EW8Xgc@`d%K>f{r1(v1No$x^Uisu&9)H!do0JtDQQ}HsWW>I zI?R6n*kxA;=AQO&pdA%AlIW9#k-EsTMH~N@z8&j zfbWE}@g|LSrRjq=%bmA=ooO1t7l>b8ea1FWgA%NaOJISE;rUah z$|Y>0q(V3Cx@5Vf05%`#gP)4j^$}a8*$-_B8j}lxffG zsM@d=y%vSSFm<6k?KDVASiX;1I{onO`EpkgyE07Y+gFd}Yyh2ryhOP=d2mizHurvT z1JlElM^F!geKL9Atov^<3-tAk6I$t(!Sx^z6tbkhG7xMAHmfi{>LmrAPgV%Ce>c79 zBoqu~j@{}UC=$MGXXn@NuZvh+AXZyK&M|R3`U!kY#zrRh6&A9lBgw`0^3$cN+|Eq2 z#AULC#k@gHJnd|6;IC3u*7h}}H#Ih;C#J1Cl~}sz^R09IVdYz$Y+l5GK}Y9}gSp9= zO{)S{S4-lx5{u(z=a^}+Un}~Ep1d6EhC)bIly0E~HCXZJ`E$&rVkpV)@rA5GKb)S@ z@>O0S&*^bzbc1Q{rbhR*Uk|p=v{EEE*|akwAPH`?vpWh@Mc4sV!V^gDk#OHO=ltMtjZUU4d=Fr@9g>E*NIVbSCZB%1$^D+2 zM9^!=t6BCFk384Y+M@k1uwY@DMKbR|ZJftXzK@>YRllR-d`+e)p?&S$d9?S|{tv=?LkLRMju?t#uH_L&TKn(NgW032g1r%UYo0(!P z9WRn2@!wH;?1CXqCwSb>W)zEE+1qch2#^+Bh%>z?)`>2!Ju6U4cL}P2E(OB;B+}f` zpnogQCJ{#V(<7Qq;ZT~_l;}7O>VN}-2j&uH^bbIllu?pzk@X6FNiQw7mrU(;AZqoM znceEN1toKNGpR-+w@|r<(MYcqNTGQ6U3wx-RFE_1$WX+X_spW$0j-ig4MzU4Yg$wv zTeKN9z=_(R+>w@*QTz_$tz#`M5 zNyqi@Cv?LXoj4^Eo3a#+gq%VwwacWg(;|^&S)XD#fUOgsRAg)~oh^?h#aKC%! zSG`)J^ZKW<6*Lr2#gqn4NQA>ow+)IGzx6I(zUIBv;pp*qvzS`vs&ILEuLk)OtrMkV z@}JwmZ1;L*|3|ymXN3PsLCUn6r7D{bT(Cvs1(*N*7H+f+6*`{O;%$~%hviaIR#%0! zIpGrV@k@Vg84Cp$$x5$*3%*^djwQyWKI@naLCJ$4YU@!|auPP@6(A`7XoAr@}f z>P8V(j;m@6rPbt9M_|(u-Gaer3bEYDo-Qorm~lGth#G~N09y6knn>_f93LmZV&&yf z6L|8EPRFzs_vM#i(;ZWEVx+*gC1;nN{dmHannx>UiwPER?}eg@1VVYzwA#|j6v;a- zHZzjejFy6a*|NNBja8zcGzJybH1Gl9k8!Z{5foahR9NczCCJCmc!yaqR9FVQ9as*&6B{HU9hyHtfw+s073pvQ^hG%U6i zgVcKaRB!v=V~`#cZiWwD8ok>8-M-II3o?=z)RlYf!x2Q$`L*=dB*V` zd(~G5TgU1)aRR`xzjC48{zt=fmgrZSo^DCg!H-ws9n^+*T!d^ZWt_(jlL0-Fv*XMy<)&TM^;defm=!az#TTssHh@Yi7gg7nMtfRcV> z@L*7HS-(fxxPvokK|{V~zZYcH;<7&v1D!SDnER8#8bdx~&h_?v!tL(u$(%YX-$ZpQ zjVAyAG^YicE_pBqizD50gig;F2Xj3ol4}4nxc%HJ%~6A*OAdrhf7Qfk76!s%1D~0D z5+3Q53Q9HlH*3>JdJ18`VUd(8b1*rc-MkRag@mzj5uy%uc7RqRHC_s-lI(0RIZ3Sj@QL z-K@VScZzZ8E(=%tgsM>6@4wDh8%j1e&2mR)NPwM~qBy&>2=S5}|9urjn(sdv92uEk z$?89LDF*;<8cWBVjGrgO-py+-AzO@TrwNk&pXi8Qhf!ry-w*P%0sr#9`8NFZ;kLH8r*K32#wl$h)IJ? zCF~mrYB#49;_=r%t+sV=mUY|*YO_y$aQd_~evQ+|h$clz;G_t27wzTbZ;@>I%AVZu zVa(VBN1YLjdHb-lCfQj3&N|naw~iqau1t1DgR%K@)VC9o)v*jteq3g!HJw4iD51VG zmaQA5?mReo2mPEI7FyAMPExni*U(wM>wR)K?UZrT*S7GxOSsrjO-QQxzjXtK*qnZ0R94avtU7a-__r%H%RFOd zc*Fs*@A6sx(U7Qf>veuQ`h6UqXC3m0DhkYYt_t@08M)_*l+4!Fwcc8WGH&d&1W=y5 zY8hGcNEL-6AIB2PM&nLpgGEH|mAtu5@wu7J5lanat;fEO?N!ow=@`^)v%u12eanNuC*Qq=eBPz+ zt#Vc4#KhMT(evQXs;@_?+*liSkpCc+5o@cdtyghp$~xM+BKuF8 zDg|9HR1NwFqPcgXvb9sF@TUsnDPyCZ%SA!~ zmNy!NlsCo2rm+cNL6|Q_4gmzoAst{EBaZ?Xt955gcMsJ9PJ^`^f^fF!TTb@r$;sLi zraa%R)qJ=230^cV{CatCCh6bhWDiB%Fh_jCEd*RM6v)ug+g{><5%W5??kY&`do&_VKU9%pH^3$k=kH#CfY~l(Lzp z0Iql2%eVxPr7-F%K<{$$>xX)|x>NlR+RnxgEr-&Dzu{>Ye&%~dx(Mb=S7nzyS%0xJ zb9(2PES}}$OTUm(m*JBYeB9^2I-VDH3b(`O|rN`lFvz|pkK&JKdS`6P7${;JmedSAtNE9Xu4 zeJetsuWn6~2;X@xW%28p?4muPnDean0*R>Hi_o=Sh`zi}(7eXliC~brsr%x&QvQOw z6dhsL)JL(6#5;(0<22uhxNkAc==gNt{X2cr^By}9({z2GvDamcneuzeb2r7ckI`m1 zh#vJpk@yF{R27xiy+$fno9M@ou1H0BTID8MZUMC*_von&Ke756QHOqt^_y0^so_bU zD@OB8s;P(UeapL#?fu<;iZ?cH;!P>HJ$!$g@?m39v*kVIY59h=mC{`?gLTcgiS+wd z*nU;MQ{O)Zd=d`fIycDa#Cv|_&kmk~G&#V6zbM#^g%QEzXu#MXkmZ>XdYH#-SpBDz ziNs;WoE&|xqK2)f#;W_QqpDRtOwMgXwwk$ey20CN%Hc~t4|=UXp!#ih&*2X;^-r*R zHA^EOkz$)2{Gg~}5*U#UC9B5J&ZxZ34 zEPrQ}Pz@TYe#q4H{VrM&97FTU_t|X&OS>|@h?Vnxh0%;10h~;x3ffynyxFGq>WyHo zI<$YLBm1{Mr<&eEfRW)u8SIMh>r56_!#TX!h3348awKj*_8t}z3l^}6vFi4?armjz@b^Z z+XDV{I4nKzU!iKf8TWmeO>o^WOwgn5?$RVaDPTDe_SbbiDh+To=Bq=@hGqN2m32W{ zU-0|-PqrL^#&vZzD(v>Tv6uh_@re5aQ8{H#%zI_+hZ88fXr|A#pmC4FC^gq%#P%uk zPz@c)U#eJ@o8ci{IF5{IO^R^T_3W>;6aI(Wgm+9=?@4Ccp(NtvL%5oV&$!S_y>fU) z@9>NMZHP6yuekREANwGa*^c4f&iY5!s_Yo2%S*c3ONRtf*1ZRaB;)<)Q;gO0&J1B# zJWA;(lHDHR?}ob2=<`A02#>hNO2#|6W0jxZOcmq zR;BblOxWQ7jRuACz-E5ZX7)E_lvU$CfARecv6*{6r?w-pWk>)`r%bkZ|!Q5=P#3!M|VC^ zGj9F<(B<9EGtW%!xR|PFtC*;0ug<5`j>!{Ki_heIzxiBuKI-E(!?h)b@!^+;RuK(zMfK|LOWx>uD-{ zGfsSTZesr(%Xadj+hMt}b)~r%Au9JPFKoNGWNkd~AWWrhn@5L<-w%S)v8@~aDxO&v zqVYYb*ID%GnyqxnhWejF6OMx z>DOCY&yBuW5l|!A@a%yD11q)u>(`DZ4>eMp;V#X}9(PacyziBJ!QGsCA@%$*O}gah z)o``6a-e0P5CPaz-__OIIMY!-;8Tgh>lP5om-(_zO}$aR-?{X*0R@^ye?j3?->w3* zwO0`?0%zeaQ%R!T`bi3EG>r*Zuc`imA!YL#HT&9ZRx`-xwi(l*S;6Y&MA}G+l;EE)0G6U; zWb%lU9-BL)ws%H!fl=G^J~OL@aK{wp7B$_`n!!^Vy14H2;>uF4a9@yVb;=e+kEXIG zlY0$3&N$AFgy*@|wtF=%EN6$82QY)N)XS`}rQc5iM_x4?E7rfue^S;)d0YzBzjxAD zKSJeUdr0uPPoG9}eX3>#3G)g1G0Gk*`-Pv2E?uyBcOZ`$!({C~0m)704n75J90fUk4sytn zP^Zd*+Xc3i2Ct%{Q>>P8*zA{?j4aP8`Acg?+%{@c#vA;s_0UBo{luYI{U_%UF?}vq znfDYoebb>obou$IQ|5J^l-KFkr;W$fXFX);=Q4<7RkW-HXr}+o`l;?BKu7ZSY zH&1=7@VVxn_>0p@4aQFY$V~u+V(UcI-3Jd`LwAZg{m=7{c0O@{53erL7Uqx6Z_x35 zWbeY<7qgz_SK0;(z3?=>kiJ*qHKh|h$ru%8~!+$~mm`v1b zS5-5Zd9Ba3nZrRn0Sm^^5fT)~s(2U>Nnmh6< zYVzUR9mVxSX7QHOl*f1FRnFf&aq+N+{OJctF^XZY_nyxk#M&Kl-QalH13 zHw0zQoHW(6P-tT8K2`B)5oZNO1yZHwxCr^ICj!cZ(x zkxIJo8lWkU7ER2-$h1!h=u4QH9_G|T@za)@_-afNUDk#(^+ll~o=784lLAQwFuxgF z%)_|g?PIEVO}`)%&-V!+`)%#!e>NGq?HQYp`1XmD19!7$|z5c=EJOu9=-)doe)7&??5%l=hrrpgF|K1(rQmfr3w3 zKQ(4ovb{n>6k^P4co|?1?XMyd#goVx&C|n}nFCnA|BEi|Ieq3V*M9=50Kx)V|MD=H8R`CLM?e z%jEK$p5xeKz4TolCZ4KiygtV-da}7BDph~m)`M94O#(0o=Kx)lHv4tkSyb!6o7r1A z2doe{YFMT7&qT`a)XzvE&%#7Bj`uRw}JgR!-mA zqk&?Al?1@%#f@@ljg7itj)9=vuuhEM zl2ltF5Jj*wf=XJsb^$i25L)Dg@KLmnS2s-?`sGQmfy?oMGD<8mIFkqMH?Rc~L76vf zg4xWEAi!OGi3D4^6TaEf6lfzc+8laYqr$J-%P)aAGeS`a|Mornx`ORmnO6aQmtG`b zJm~a{cCN2Px<88+z8i?CHT?ttH7~e=jVROLRM+H%f!W<_kno_qxpx^vPy=00Bu207 zI?`{>JjAsom15&6^fs%ZMGk!xFNsrfW}-`&h9Oe`mLuC9T8u9I7TJgfYTT}wsrSK( zihOm`nN030z5LNdbxsJ(x_&2K|X9$g{r^?F=32&h1nElK> zF&R>yve3|B1Y(%x-?(*o^=O*sIGA)D%pwrQ$-NmokA!G?*z5IW!xE^+hl#3bj`gWM z}^k=J%tnL;Lhoc=t$d%N23@9oQ!VQ zgpx{s=LeXZB73s$f)m;Uqj0(0@r4u=NW+O_dLCdigNyxn>gjwWHK8_Is5$-~cI}2M zxipvc)mB#9kE@mLg4YehIW(F2bDdb`y$Rvc)onsmjzV(HF6xx2t(`j!i&lpM#Tz^A zRZU{!)Gi@Bl0pDPA`QqP6K%#R^9%79plD;V*;CFSljdMRs;&lA%=t?zI#NJ+WjKPc{g?nE#5M}09In0N&21V9^Y*Y^t} zVD*P|>*s+GMBda&;j1fH;vQFGO0>Z420U^`a%~*bkx1EP`@P2oUMF_M<;9h7H0;sd z3%=7-HSq5uX?bmcSFim4MDZ*o@G~XuZXOCaA1t}9zC+QKwe4!gkhE;+uw8{MP{h^m z17`k^v@531_g0u%4!sb4Zj61w3<(a&n5qBOXpDTL=9JlKsQ04joct%AQirbI%m}qx zly+}*EB*C}*BAMJ?URIxhpzG5Z+e>Ot}x}6J?cG*2VO3PP4F*qQN2r4rwGGx&(Ycd zO^}x6v?F2uV~0LWe4jAQ@`lIxy`b?Du7qMk3VF%2zuFIV-0&1!k-C7-=(B(0?wpAf z-DJJUP|)KMqvF!zJ9V(9iGeFS8|E_*014AcUu>NVTt1cANn7fr9PC)QQ3{Uwg2~v8 zrORvlhO=n1Vff@1{&Q8-C0aE+H~H7-W&Tm}M5*JF#5J?ij}~k`>@|Fn9PNICJ@ic% zf3%w8fH-)OIlV$!eLa7!FwTAyZh^(xWv5H1Etb3cPHci-2S3jKs z&|Mwo{`Y#P>rLQAta-d>eBoj%kCT15 zr}XganGH|t!u8|TSF9Bd*>-!h3QYE@*e`hpdGNP+=IvTuSDa<0@7(wN!dH??dhUsu zzREgHy&04A1DQ*9|9FI&ytr!I^5rizc1D-fhM2`ClP;;-&0AHztAtlxX`OTJk;jSR zqarj%FQ^;0GcUBgCEnW+t#d1Ci$0!Dbpo%h=4gsMk3C$;+atP*?}lygZ&KcTWO2`( z_VRZ=;TH(7TiKR(z|OwDDJMV#jo0 z>CfyicfE2OO+Sg5X(Yl7hz4Qxa6%zfu&1DwK$a8?4HyFQKFuXa4gG_8t25;tb_Vit`W*WvIXfkTV1?8qvqVqn0ly7^ihjY!uJ8sMc{5ycvfY%i0du! z>HA=a^;R#KpAK))y~nnEi;G)x%-prrtz zV4a%_E9S9aI1m(rw~9Ex_vHDFML}{px1h6eRbh$B9F*coAg?ky8x>I?W>(!|MR0shbF?-%e)c+~M>baPEX&nN5ug_qi>O04wNfh}o?r%W~C; z)y}+F|5aV@AxFclYrJoN)CiUt=;%VP1*c8!R+`NDyoa%AwCbR%727?x^yLBmw)Uo~ z=fw|>VtMb?lmb3|va(=4l| z+$c>28(gh_+=pe*(NID$9l{$s&jkX3n7*Xbg1YsxRMd;hkE3I+q>CYzmO)Ahej)BI za850~Q*0M(Has(DHA3yFBWw*dbQa%O8*usf50z!8Q#Req-Ro1TBfBj*16il?Huca! z`E_G*Qcg|MoA*q|t1fBlJ`QWzNK!*@-?}u=e;BSV4S}^^GEIhzZHLGF9hSIBN&ms? zr&3Sdn8Q1+9-cp7%n3Wy0eky+;h6r@lh~2BDHWu!tjySxA4)^7m#f2C9>f`Ketrn- zOaO=Z)}h?eiMF24oVl&;1g(z`tQd5XosW8O^RQ(eMN=KwI{7{>-w81Ze>Tba_Wo>X zjIs;#-=#Brlch=bmW~=Q3ET9$2~D}&&ZK#(eW!s4U=^%-@5ISIlOAq(I`AU_iAn{q zKp=ZidZ54AGMUPPV>GcK|qnRh(&hhLzC(SV4)(YrPcTJ z)-R{T^;pgUB`y{t?9Cq=brm3;6$+p~-q-`f(^SFGhIF3k{OBYzQ*5TLF}wV%d`pSL zb<)dr#ui)^e+WeaW&^UBT?t@9a8K+=_n>^u3DAO(iAOC}yo)c#>=u8r! zzKvr#>7$e%cG6a$D!Oc8oG>(iuS9*HnkjbE2HP7gIHF*_RGeLJJ3&oCI2y~5g`9jB zi8NVQgoRd^Of0`#IeBl!_j^z88ThbWfkk{<{jvjCjYGsc5z&DbwT8u}@P+>Eoa#NM z*#W4(Q&Y~TJDu7=gL?=r-uKfD6Q8SHgve74W7okvhWd(Dd{?%4mOl8l-o}5kN;0m$ ztWUjtskvzNbFsyt$irXOAF{O8$G$nu-#m(3)xaNH9OZk->vUp2PJ9a-)qc$KA}m_W z@Mcqk=_IFtDe)12&?ff=r9WxA^V?c^=2g_?8^3H?*pE&hzx`BRNh(<7)H#T`dmkj~ z^rxm6tQV!`+`1+^Q3y0G1z~sTgqlV=lR+wVtxL%S8+%@>jX2xK2JR9Bu(jkz-o8(> zcZ4J-wxc(U7oQ_|@QXfMr2V6hYvpy^g2u1=zyQzqd|*Z_cOoXBfKQ1aq?pN>!H5K7 z$3!1n^(K!QK(yKQeHa7FHS19VC6NG;V>vWsBUPLOjDHjmy4jiKayH?M)wY&>$sKG; zJD1W9^{wQ0c+apjhY~T(e!xeGs7T#{i^1Jmp(CrLhg;1spxp(a9NLqu}L)B!R66Z1T6`D2dU%qNBY{Lp+wI-!&jF zdjvQ=GdOyyVue4)Op-h1IjXEy1w_uEFdhl15@>Q1{_Oh0`DO3iw8yPmN)v4>^24v| z#m4n8rbwmnwZhWX|2}#nNFuXv0ZZ!!&*|G4WRIPg)iJP95!eyKfr3Bn)s-Tk{#M4@ z`%@QS!x%F!0LgQ$OTK1TULCh93BYejY0;?a4ut|@j@#=9)Me(tAohu4$$xM;Ffjd| z{f6d93n!aA0stB{bY1pKG$O)f z21c>WsibMn0;iAyNM>!3Z1r8iJ#{~PQi=-rFBJe^RfDEgsEO<^^0?A`|M!(NZJ*`h z@_xcjV9k^x*0j*v?BJ)x2|&Cv+qroXe=3BS?ej0Ysgw56r{(L}U?A+Nh1}*?@9qsbOX*Y4~B@?f&cbin(-9$3`Z*n!&yo7%4XUZCxHHFFsD4eo$a#^ zQ@WU6+57buL2U^}Glh^eMGkbK?t7pDg{ec{8Net&qTihq?*7Lig!;4x$X9cy6LJNE z*#b^AQ6BgaXKaM8farY=HZKi?-SZ_yFs>@Sygy9Au2MQJ1?a))E7i5sokc+k1{qBT@kHPGV|s*u9b1r8 zBaH#P?|*NHJNDYa;$)?|JH#pVj{?;~hzYfV-=^L&iPl)}oYsHYNrbo|4_5&xGt%PL z@)N*A4I4mFz6mN~?#{Ms~v}@@!Z#2xwsy3{^l=E=PVv z5OkL|E(avG{edygGpy|6+m|)`f`*Qy^H(QlDv0(tAR6-^pggaYu>bF{ihX%Ax*XGz z{}EL8dH=Nbo=&m9vWjt9W7I~D*&NcwD~s$YQ$uX>_&V)-CdtB;tfz$d#tvQx7x>un ze0LA|bzbC+f}p5(w;?DG!B;1}p;UI|h4OYpFhSXpZ$IgJ8`>v}gF-}KfwHpzh)~mF z1Iorru&0COu~4BHa|TbhfG-yxQkwG}$8W~j;}L7gSv1$U-D)_Fc=NNADV+#TwT0_* z?CNf{HCA~kvWMnoT@7xe!$oHCQ2DP(e8JFEmhg9W;iWAl{h2}<9J3QRW*py@x{vj} zg&pt_^c;3hBDxqij*m9j+Kp!x35x-j(hilF)GY%;B2TsFh(QjNv&zryB}k_c!&W+$ z2P*&gptDM^?tRD_xcAj#=1F%C%;#ECdqeh1Lazf|7n6qv=e8CoFzUqO%6g#WD{y{S z02t6LYvU5QOQ$%qURezsEQBTChU2R0eqk?2LcS>m{?V7@*oV=qOf)1rE2NGMeJRlD{0%n0P?D^#j;4kT)v2z zu|vU`WAOg4#Cz=%sn(8$N3Y?+(EC+jFH;yvI(np4~#8`TJW@TGLPUlB=J(0*j4QKN`dR#TP zU_S+&ccUUbOS^8sd=(fzh!M>UhK(N=L$K9bs*Dr>af(3o$Fdb?a~MwB@^nQ)Tqdoz z^Ag%!2rAI`v%w^VX@Lrg8sVftmtU?F(pwTf_6gT%8;ynZx6u`HG`7TJ`h;&Xu9SyN-qSbIV-_`U)G!^$o4)5LN;3rHAN+@ zUU}#O_zeN#yL?Ggy*P=FlF1jR$jdFhu>o`+t?_?Zt<@sLVnCQKt^2#VW_=8Ecjik*@G3xkcpu(~HqL96Rkz^x? zxBaAL4^7JkYY;n=#?%pX7w@V-sx{Fv2piq~ygt&?`6L5dyOK~ShWyN2olbo${H;Nv zc}cDX*NL6dR&>omu}Y!#_&g(6E1=ayD}e=jj@13S_K0%IRncz1O8FVCib`|An^olB zMW7W^sFcToBxem$5~ex3(ii$=eX#ed+E^!GhpWh^PO zFA>d*olp@KA(Ar5z8l7_P|8lWLAF%(ec#H?*s^D5?CV&@`n%@+`JQv$=lteBbK~W8 zy{_f;ysqc{@pw+C*>^uFysd|9y5-?GVO?l=54Xna8LdURor5z=b*C$}Sji}p$`HvY zum?0#7C(69>})!3A~+_nS-WbsL(;tVfG7tOMl*}&pLSdt@;^p( zo0@uF*>^FqT>=?LLOEn;r^KExDywfY@=nK~5s_mxA-sql&UpYt4yND;7B%cTCV9hM zFpmD)FRu8me*W7;J$SLVz-_i+vD?KSGPhTcjNT3_X_omBHE*esX}DIN(8OXji1(~W zp&I0|0z`qRYuC-N%zj?!jwm#g%iD2JFb1oc#n0}e$4drpMV7vA(`m@&*@9jhDSw9; zoHGmE`)%Qw1I-8FwqSLwF$RcwdD(G7BRN{?EvPFop+LA<2HL|XoFtT2rit9mfNAXY z^&UODhwLyr^4n#!8V~d|STQ?#|M?P?#^ht5CV3|l1G2LMN!nO7`yV2|J>}kBLU=wg zl1)~%pUjjpidF^3Yrx9G6DY6C<{u?Q9bbU%%O*5))O4G;vS$@TQP75!EBlr1E+FfQ z8YuEe=+YvZ4m_!h8O`{C>}p zES#uqD~=fJ8jx=R9w@YEA<$X;ptG#r4$t-u-5Vy$~5w&j#BWDPMz{75!t2r73aRO>i7?1p_EjFgF>*(t^|f2{{%OhtR!n# z7V*$MK~HxpW^m{{RQrjP2Z!a3TI#aV0VQwMJM{N%lfJQ?n7&~*U_64J*jBN%=8am_ zu-z%Zl}$4oqqfRqXWE-^Pd*r$*v4Ygw##r#RtC|(vx+uxTlOhVgR1&rxtAvLZdsXj zEPJB8cw4g`BlC2P7d21)xm5a0v#!%cJe56O-=fKSZMn~|F9ds z7S#43s-~;yP_kw6ymxY~3~EaER@Kl*_40_|&t#!cc-8~UrYEnrm#QCv?45l>bJlLv z15RUSWADq~yZ=0vr5af!K(`LzguuoTXfgLm044WinnB}r;s0xc zCN7wIrRfo2%#lh8`hOcSh&^HyiSAg|u&C}TuaCPcXSJLxEZk%rVg?~;z1s9=)lW~NB{QdrH)BQl*CR*1Ep!+0Af;djU zLcb!*{<>(AvpZ?a9&a}Fi?y&xSP)`>l-xY@B18?EyIoYvQ5cQZAQ;FsW;n@PRM$0v zGu6GtT`8Ev(9md9Od7T&=67SJ$owCjfezAyvN1pg1NcBLSqnaJH>-=0Z@oVXt?^no zqXb}*JV{+cM^Ao7Hv>hv-yhPk8*KA>-_ruSieyfChsC3}`9?G=V`B8|E%O2+Y_nl| zY(Oz{&m1l|7cX+i`|Kqm}f2{>3M~*=m2+Xg-S5VR`-EuyUdIxFXO$Zv9lYmD5Xf&`x=w) z)4u`APnB&Niqvhg(aL!Ld^mtGJ&^wwo^86rs?#)z1AH-_iYV{)3E~)D0T8Y*Q5}*E zfZ=SDkbq~B zI*R~4AJ~peJz!|ymGbz8W!Y&)exIhTwQ-gmaZ!4Z@!NQN*OYbNC3S$~X_n;f@pr(k z4rbk2#R{;xTk7hoVXjC4QvhgE3q}|0nRnd6kZqF-PcBJEcYihhtAQE@$B5{39L3`s zc_IV`CXIO|;GL0UqK-6Ot4}VwwYsxIxR;lYZ=XEWAGk{n8W){~Pm$Rm@&G!+S&=#E z0?}16+Qta2hEcHKn-o&jq6^1L&;81Ic={wCSaDeH*b|o7Kz>3WC_9W_C0 zhuNg{gQO1JlS^8{IQBeiDO+qXU68tk_$%pp5+?KIn`!S_{VQs$3O z26Fq4&|PhHw+|ns%zqntuR9uw#_0A#v*xa8brCX|GfVI1B-Qc{ue<`+*k2q-Ph!%B z8|Zu<6y6DG#;@xs8onJ`i27aHQM{-o@jWS_QIgla_TZJ(;Y@%1fTBo>qHvA_ObK49j44Wx^MIb+wI)<$nTFZJ=JIpVrml4PCR-S+>w zN=%?|No|{ZW46d@phnT9o}b=XK+DRdz-~cPs!NZ*>t@%2D~YDnA2`jmhX3BObOiDI zix{%AQAzZ{<^V8_8Yr`!BzoKYm;D%3Z=Ok=`c%Sq;K&f!Q{}p$zWC>d9!I@CezAAf zl8*)r(^&H9O4u3M`Efsre%QfZ=PzjJ3spZP<7~fa)BE|Yw-#(;mqCov*+5c%4w4^(JF}NV?-=Aks zh*4A~gSGGCbTcc=ZS$A@zn#@uf8HWKZQbBfd3=7{)X_$roEX!;P1?kNXwboZ>mPFm zVg7yDuu|^HdtZ^`<@PMRhK3}c;2AWC95I*G;c@zMvZ;P8xunhsrm+a|vgkdqI9>nO z=at6m#h%oDC+r_vwq8>8-V)0pJYblMpA`na=O8-I+_8J{BQ|_zAMnXZ4(5&gL zfZoBX^6d1e9}J`-&(1GmL_M6$DrL&x`PVCxb>8d6*3;LtsJ;fCV!Q5S{4e{s*3KKm ziBh>YYS|B%!dQiacg)6L-XuBC0lZO5dctk?*YH4x^oK?Iwjz9=X4a3q+R83EMvhL^ zrQS5PN+2}SO-6VcME{%`54%CMWh090bd{8pM!}GhFjWXlF#}Yh)IX{Oks7?tk1~E- z)*92ZSK&svkJ402WJe@!D??7T;KY{kbQE-_zcOtnYqL%2ya=!mewNrzY%=0BS4BBj zNW64+%+Q*z{Ar}_v04}R{?jPHZJk>L*!Lk35`73X6R-n740ch-?}_RzWG2|WeNq_c z&{F`Q@Qq?HEszmNpyKFYXTNLRDp^QO;t|2ICD1!ow+q#-VOJ)(tr7Kc= zbEBQ#Ld#2@kU6QhY%6r)ML|hP85iET&x19?bfCTE01y9<{F=^&wyZw&IfDaD* zqej%Qc3QWJA0IT&-TmlT1C+>wxVEdou2k2_jLw_gn(33MZSw9(QRv@I@OA8x8ndzh zEIM|wpF4JELzYD;YCO&7e_hO^F`RT_3#e@#Y85=R4fi)mzPkS)VxG zFgWlQBwUA%Mtp8mSx`lv5^%^nBTa-wqqAe2TtDJyHF9>`P9UdP2RykP17~w=6azde z?ioxlw8)`DsBA7Fn^z}vak?@I=;#>DOqgvRA5F~|r+a1vYBz%b8eQn(cTZUw9)Rdg z3=|iM1A}tIa_HsLE5=@Vb*G2F^xHK}QK|~64re^Y0@yKRvZqu_%_dbBh}rsQVy_IX z0vp16L^fafLBFDRMzSuV4~S@<6D9=PB(N}v>^cQDN89^tf|V9RQPbNUB3eKNu#mpg zKJcRgdK-QDujl^X=nE`s8daO!1%79w5LlQE5cP!sRe_MV{%z!YPEVkTYPSS-8R}LO zJWn?>sGpG91g#Ti?aNhx>A%0=Z^;kX@49r(+pHI9U~iY)Eb<1Ea{QPL!@vcyu{-fD zRiJN(4hpi*s=}pDKH_$Y8QSG)FjzFT!^w~JXQRhpj3(t?7u-)j5?Sw>zB~VCg&`t+xREZorLKBfF5O_4@o`7Lv7Cd6CM!#olD=K|>KIScB4Y+QEx6 zsm1Yr_lqmtepJF=y!MKcU$fiS&z*M)ga6w4?bUFR`F`i?_JA$&$zs?Tfi{1VAEp%- zVCsC3)>Nk%D{OL<8yC}f_k%jM&qjp>S2fi9?bpD_o=t94tC@yC-?gdPsuJ_Po~ME> z2Ig_Ew^Kq&UoBsQW@JdE7wynDM2WA0S0z95YXhr--{NilpF;%^r^7gk!oWBRr{Ha-7?6p3jz&iK-G`Iqca|GlFE>8)HJm(m-kpc09Hd`m0Ubn#kl&yiEEc<_Y26=1SE}vMPe|>o3GCh1C zse#S^!YFC#_;}vo?c_ktHC1;n-%NJiw-T(Gf7?P&KWS@ia|uDZBYI-;s<$9=3RTyiJlt}Laft9KO6z3Y4(Kx7ot?qHGTe`O0H+N`1 zsld=fMqQ}|-yJ}A{aClAT+^yq%nGA1Uc6gO)uCKLz83Gg{2N7RQ1FvmYuo)H{SA3; zUELHTGVYl8@u=~VG8O3p2+B7tp_=H1kXWiaFy(=^cOEIciXc0fYdQ)*QteC4NB2l?ra>Ngy;zf#lZ)D<=CM5t z@@Cpb&yU*Mjv^Fl6Jt+*diXf#7;mS`Y2TPvOK88r1u5adihE+Y(z9R`L#+((J+DG6 zN5GEgA50-wi3b?qMy}fpHj_w(8e|yJy=qeL7UM~vTy6@C+Te}cXaGX7c6*w|uY00y z*m+~+_`o35`i(?iWS#N}xkKb>n?yuyGx;6od5<8MloQ_Ns`1Ia`0uC1?4HD^@RceB zwjFx1s79#xqchFE8<~9kst{?U`ELILR;!lL&3o83oJ9e@S!>=|g2Q+$v{AhP(YzM$ zZ#A0`h(*d_tr{2e+d?HXpf8sxH{2#9B-neKG(Wt5agF&?eGAo<>5L~3YO6QO#u#0L z=>?yM_mnonC)qZ+&Y>Db%Bz26AxF*;cETHPbfE8SH$2|nnfkh3(8575OYAn@j(ggp zM%BN&IEB7y|ChhY2l|?Mr0G-SBWlt?q`B1*K}GKw9EyL4~y!aGOJZrRNUfeL?;7`ayoy(bN8Z z9>kDV!lb*IR$=6VuIWiVlmd!8xRysI8#$BOq=jW+|^+4a4^eNJ;S`emJ2m<$#oPR5pAbjU z9|5j@0bXq<%_Y8Xw1A)zRLzhq>U9 z);)^$5cX+%p-A8r zZS${f+X=3HC3ony(N}6jIvN4FeDC@86OU!34|hC+SL!QxqduWgr`uNZ$8>sh0Y=P+ zf>`_9*qiQd&_{A)(+AT$Fa6MWm{Gd4=nAF--KU3Q8)gA6X%PE|7+t(N*&$x@kY`Ed zeT1rKnAar~wu&+J6mQYpP@^(=6GC~C;NgQ4c%AB1oJ8?Fz#-yusP5=fWvP8~T!z&g zmQXRYgoUjvvPLDjKeDZ5DIdB6oqWkaadnkqpLyR8!B){-3|BPJ#BcWI?WMB0@AbGk zn>frN-hD|urZ{=$@--K)ckBkyEZ5^F#p(yR@(d|rU-#{B%pWRxMM_(%jx2iPg+>#r zNrnt}=WE)k{2d;N^x4}k9~(h(8TT*Y(x2~=lD_^bJoi9$duse(t8)sGrL|(b@V5)z zxtn>`-waDGk8Mqss?S^@?n%XKRFp$&C2}_5zltJkIgYwx(TqVH0oxL)gu$}fe^l+q zxpRchqj*>76c*KEI(x)!QhR1-;EGuT>p~jy6)3~8=4JmI*WLneAzOx(pG6NjrZ(-R zYFf{=w~$jpP0&6&;XRiR>d#kC5%l@z?+TGvG`2LwTjs`*-z`SAVf{b0t6hh_4bVjN zpEqJf%n)32h-824lh?m)XhWRF-Kg)KZk(NpSc4dapyZ@+*GaPhWuS=Heu_X>45BZH zZx&8vF7Sk$b_E(Zrt^Odb+2mE^ey?P@g4LV%lt-vJg|m5O;@1;KV9ax@vyB_sGKV6#B$?y!PHV?BLDpa;FFJek<<7u3Ez zzOX*$sfibn(li5CuYaSVyT`JfE=(~LzS2};&Uw#dnky6o+nTRj{;g&xac;)zwY-uX zkJf17srt3X>M1TOivB$#$M(I-4zH1Fc`84lhf`QA3%PD7Lxz$XgoiMt z(;Tx+@{J|a@Rq7@uQW>~@2N^1GP1&_2g3zJ38%kg-XM1sylLArj*JwKhWB2HKCD4` zMPf(_MllT{L+|eFV=$g`ZSa(%DrG!paj^N{M^7hS2emT6k&7aWPD170ZzM3L=)2m? zXAe{59BMLd()fGOZ%|Cq4McDExzH(bGq{l{3NAit6jbc?7hMUibTpCo`eqcxsQAvq z-(}`hFL~%hvC2Wn?K7!4)eo($)wyT#cePzdllEe@Rik}JVqrJAY!^Gm8560dt78^Z zg`AS@J)K1uGecKo)MQ7arBpbFmh>17p*TJ7bStBqyX3XKd{oxWtIQK)zbs6=2Bui@ z=G~*B_e$mjrP?2Oh2>XksozYkbI7yzYHujgXoSe2U-7^sEFhkX{aWQ5%l^MCNNYS$ z-VSTmt8Gy+4(x8Kz5Dcs*>xsFL;uXc&5+{;h*y}m&zxs>8EldkmK8VBUCyyNt`tZE zMH9mJTI5c*z%KjVH<8)PUE(5?8{Ftjr;k(<7pobOx4x2V>l<$qbt|WT;vdQf_SFC6 za3l1qYY-l4Za%92SjIo4hH@k6|1$7eLqye4;k204Um2koKelJ|c+Fk`DMGkUwdt!K z_>zfK!g=v=R5)$(r*6UbYh{yOeew|yzIzwU9rLlI&>C*vOzDA`E?##&0so7KFX7W> zeW&gES|GGV|1y|)zq8%j=1;{Be$v(m>hIp0Zmtgub?4y3KO?({PU&ajHPu#4?yV=8 zo{fS$8l~$E;V?vUJPhN5xy3ciQqpyOnHRp1Ea@PAZRHAT$01jDG_1&*PR?OxZbA&NGlKGSIG%Xj2F z>rEJQB|NEK26-tZa2{)rZZ*m*iBKz7*i=ug7P1{upzO~2_1Z`aeM$H)kSwVP_uS-% zdOmKH;bbg#DHhnB!leB?=-v1R;r>d#{f>p2Tj{5~yI2a+C!{Cus^qBetwzoW5?0S3 z645zEtU!Q+j){;+r08(J^Si}VBW~_^O}yQP17i1ikj$vwzJPNYe1w$ZQI(x77icG0 z5}nZ#Kvm~LhLmvcU%a&A=aO4j7}Xwnf4Ie#lH+qSmHKmdQIlab3>Qf@Pu=J|*+2B{ zV{Y`7Wz7*hHIP{x#Y)Ybn$c+`?#(7CnfOv?$k_uI8^b>6(%BPb2-e12-|cH)<>t?D zdGnN64sP$!c#=D(iz*!Y(=u9T{Z(X&?TCH4iQw`5foLy_WcG0?yg;~_5tRNJtfd@N zEadsfeVzaC3T^>0bJ#1FEf>J_njHLQ=guetWg?@WpZnLezdwRFFiCS%BMO+~MUqy3 z%O)9Ryu5g@6PNckulIzy3y)^*mEEsG2k)n4IvhW*v^idk2w(Z`@yR3B{T?TfvPQ~T z5biJs2SE3e4|(=^5FdE(q?n}mhOWE6YpE*s-{>7Octx3D?~Zb4lP|wfH>yRcXPtJR zD6%ZcjT_>hA6`b0^hHX0;q6C1dpx}00#12b@l3TcUWfh3nYP|XV{w}W2kWkNcY_zX zR@c%A^CI4HlM1@Gtb-R74y2wD4=X}P4!P*KI(3A+e(g;r2+>cdNbvTOzPWIzn={1Z zuy<=ao%=xp?vFu=Ao{{)gO<{^uM`i(rEblmf-P>SzSDR_GWlB7pn>IlD7mm*8`8j6 zTwy{UFFHJfMqemA4hV&3)`%VXDx8xFA~P2m9+8tcUp$ZJbUzSH;!uWohU{5V_BN?i zU9oXNh+4QV-)Hml4OQzRD`>0_B8j_#s3g?K%Huo1u~8&V;=yeP5DRzAn`K9n{a`@U za-F()^=NVOT*oY?ZqQ}19nJ$&8>!aPTVDft{SB=ORJ`)H9A=)GVH+ZZIeszpNpygn z4qX}$-JwzgNd8fx!nD)6NQRnDWwnlUq_q||Hy19-!+(Y`7ctWZad@opQ7Oj;I0i3H z!|;qW2PlsIJeF6R5k3^AFEsAjdG{{hNsc-s6`?>~bXp9Z_gS5;Xi5op3@0ZwI9icL zNi4n$(@bUpo0Innw4`q+t_3iQ`#)Xhr<{LM=NEJi&w5OEs1&^D8&C-gub z>#bk30#Bebs!sWwx?r!8cX~DTOBo2Ki8*pHuD(i@)UK~j$_NQh<}2cLU%VNEPOE!? zw1DnTu~CNv_v_t(*n6Da`wr$~4aLxBM17I!++{4{9(iuYnl~(#UlX*RrT#W2v=K0X zo5ItW1GYLaSyi zUTvMXoz`B#_@I9QW{6sF)KZdsT19@l<`pdNM9h% z*{DXq&NBxoa3A5dKWBD-l9Oile~4JfbbYo2K`Sdv1T9Vopi7^L6>f3aibA#qfT|$^8H6{yxaso=}CmA@O2~By#o-?lhOoTqx3iH z<0+;GAyEYKQe9YImRsvfrEkC&rc=z~@H**}!>^vAJYniCA9#!23j%w1eoE43=1gMc zVc#I(B6aQDRqK_O#tyeqYkgQAJPnnXB8U4DqKVTfRoYGd^1#g39irbqQ-H z$b>#0Z7SqDWE#S(&?qQYiQO?xNw003@>ih3dXgEH)+{m#{+)T(Nc9JDsZGiHm;4AV znhxwmtT^FNYJ*037I?1`oGbO~BULdn^DK#~UN#|jE&}W65^^2bq)m%OwNKmAQl8n|f=oOPM zxk>3WbbaJ?cO&Z^a?2I{GH*1HAo~V&?YiF~)lgi65H53#J~uFkBUj=i9CDcwtF-(P zisOWIH_0p}8;NYsJ?DIMv=x$uYzgZpe_a3I%DvqtVp@BNxj_pdSlMt| zmhy{Do0+?Q$XMPnUf9PvN)No-w4om~hJHfpm?9(}nw1nS$J@B$l?k*4(CgeD!>REP z2L{_XuCW#~wUOSDgOX8uu~7G-e#nvxy$^l6M>*|JJ{d7td;u3Q3<&=qD59R_aqw^h zld@JEI1&8ak`_=p%dFD%VM-|(Vu|2Hac*+82i}5KqvaLd^HJ9&&K>wH@O&W=TMH2# zo@GPdk!YRqZ7rGBbIGN8MMi2SV5D~#j`&Q^k-KWr)OQ2%Mjb-0yMFf; zOscPb+YWztHR7F#5(`@|Vjz%t0N4;FksAm`&m_k0Hq~CS61RQ_s6{I8_IG*P)8hlA zje*{nwA!e5vSQlNn2eBON(ol3=7BQ(#@|%Rjh(dSeCn+qY1ZgZ8m-?coLf^s-TC0A zxF|p^&Uf<_t3~j~@)tf0R6+7RB6q3ds6%<6JzvTgh|Dk^0q=gbU}d6ID!D zQdFFRjHeH*9AcqKRx)g1c9>;;Nt>guM~^E|QeLgaQJ>WP@T!O#neVtR@APj=@;HX& z-<{X)om+pMjPZIXyH17p@`iNz97<)(G>u(l@F^wsd>_|1`Qe=cMOGcige|&W|D~@~ z3cE_JwsE*!R2+_B>3X97%7zM#6N+iVGcPL~^-RFBmO9>Q9iD?CifQ&`6s!7^H+!j> z17LhS*gK6z$O$zH>&|mYF0&Q#RU^o|sQwL9Dc78BuvIsyx(Wu*e3;lufjJpB9A{2X zwaz9VqU!T0O{pmlh5iK&v*iN6O=rPegcIDDw*w!B$WB)YQ5eD#RLsq-=Ye|%7kB3TAq&d=;y*7 z+Bvm4F0J*O$8ShW1lE+`c%vz$XhdTf^FF)hg_qID3!V?#L5+a5TZaV!cwEbrrHXEAZmarO7a> zUeVjQIk;FqBfLHmUfr2ltSE8bsc-N)>cVJZsJQu+O?r)l-t6A~Oef(PBYjzJc1SWy zZ)uc*M9_gxYN%+JmOUczOK(&CC00_!u1&%XIyjo*AxOf9KBbALKfDIbD&|sTKbX4U z{zaa9vp~a8`~|YUVJaS?$I(4L$Kdq|N%z?p+DaX;I62o+-(W-0rUZ6YCm%#i?JkWp zw%mkfp}%-QX}mbkU%lVIM*(3)yj;sWqkte=uaMoPfYw?C1dBkM<9FpNRA6?r?e|A2 zw0a#8huj4DuwG1bYbKv!uhIqCQ%xj_h)z(yUEEr#W7128dv}|1f&DzsDfbSa>M> zwYM|at3Nd`&lh6p)|JpF^}3Ckdj7Hkc>e7yh<)CVJpJiwb|(eXO{ntsc=`#-c$!CA z<(Wp1!}CKW`05#gViIbiS8larN=AW$p;c4}JNNfnoIJ%)qHJ_`gY&GxH#m!Azuuz6 zfXY6d>9RV9kz6j^f_LC|cc%Penh|;K&H2>oMZQp5>EkyZl&IM>kBB2>Qg_PN&4I^D z$i0#FnjC~`-QbBLLFVSJg4@$xW5|IJ}XHxzeYrb#xqQH|bz(IV)>#J%E%<11BG0Vgrn< zQzOD$(9!TyD!#IHm9h5>K|IU#o=ru89?C^O7xxF$=X+}Ei|%8&M*HQ){uAJVkn3(D z5{m6vIA?;v_D3vE8;0*wU|&y^RU5i#Z6@7ggX0$9AI`vj<<8`W*M3#?H6Lg`YGeD< z4=djSnTm4Nc(>mx?YBr$J(W%2UC@~qUd^WIl|w^zLGp4PLvOah$2s~pHxcI!49)i@ zQ`g)GJCC{p&ym`gGi?emN)LtH5;^gO@R=)%Qu(r6vC`DT~WVe zmjw>He)VyGH}!BF5GMP|ws~e-6om!L{l!_<)Qz2vGO{5Cj&x$G z)$7~)PJL7PN8ArazxO16QI|i9zY^e)z(UL6GSZ1>0NY@(R~g+Mn#o6Q?vzlO&Y&;! zy9rm`xgsPexXcu58N7VxC}A}LzW$SG|Kw|)(qla1xv+J&$}V)4B2}xrs^b`@kLh65 z+n=hvC%*^{Ycc{(~O4)|WWT#!Dm zTP`Ec<69^`c0u)Oja6s4k5gRuP%YRHog@|Rr1)m!oQGUHi5QC7+>A3;hSaI{k!LD% zlC6mhP(beIDILsjZFrv@4S5w%$DKC%xSJn7i9HHI`kUWD_rJqY@0XKfF-t;dEBQM+ z4nru^jm^#k<3OzZ0Q|Dz zI2xxc-Ra?Bw+*;O;TN|*KO-$h61lF{VrImvXYVg}I2))P|NdAA z0K|$@H2MvdGDI44x-I=LzU%s{!RY^n(uUPqP9NC)Z{Upozk#!W|MlVg&-eeQ9_Z+Y z|J;Ex-f4AMj0pBQ1HkX!VBk}d*}frT51~+9VvU?kI#3bdp+6ao1}Pc!zv_g_r#xvm zh_ZicaXiXKyyAc;fYtts`d39L-^JY{PUkhHT@t#lgA5Xk=6!G|6C>o^&*AC ze@k9-GfVD-KN6-XRPwlT`TLK)dSB9hVtFe2$8mjtRZ5g~T~GWB-y6PvFlE?&la502 z6LC1y3z8!w7XZIe4EidQ@w1#TyX&ghf9TElVDPgPyPJGfagQGr*$CqsDNb_NG3zq? z>CuK3oBC7Dme1_{07zqf1(?ipW{lc}5BUFi8bz1gf=CmSU0&WE^G1!!JMnA)E2$t92wLsn6_KZRrPP5rcVJ+uo4?0)``=jQXnRqn&85 zAArkvh6Ve^UBo}R$7-IJQ_y_PIatG7x$yoLFp|2LmFS>xBT&QZ$<%~C@ORy=FbDVE zwjTMP$9a(+zEQoa3gArQ(7DgW>3+Do6dj}gGWd%<{WmJIJiyx?{_35bb2vNM&jR@H zU7_M0MWWdVYlf19?g*Dk`QRkI<|GFJ!1$QAP}(L801Vf zFuz`Eq!Q_LZf@2Q+-@Kb5^Q|PcGtc%jq|iW`BV}|)vJ`~#Rirxx-S{^N<^fVIP)`U za~|L~5y^nP+nHdJ=$G&DlhyW$dA@0RT7knPbOTdNw%o=Ba%kcyNPFXoGhk!qCABY7 z%i`jY7?@eA#zC2ox%^{#I1&Hkz{hmo&XEV3*mh7mXMa2^h)C#J07A55?eDddYTg%N zkilojBv{AnFGj8VhSnudZZKrJ9z76xW7uB4*+_-#BeqcUW|EW6C;<8T03RsbW~?z5 zBQG-(W*?!#_`#%q+L=@nv&=P<0 zz2stg-sw|M0Ez#nu(GYJLBgV`kK?FCRt9k5<&5ObdGtQ}qJJI8sUT=rr33*oqf4|I z%m#?+65uF0JY4isRsco2Jdmw>cp8ir!*+hFK(V5t~mat$Q^Emx4p|%DPJvR7Ro-;eRar$IA__>uF6F+Iw4sqgi|4fi*KS7+mV ze=`e=GeO&Z>wgCD^SYDmZ6wIONp_#v!Y}fa1gH#fZ$31?I+SM39BeW0+_d=^^9da z0h)rHqd7mKa(2|F)}>9D>!}PdW*ozC=+1Tl9Pefev7G(zVTTO@S)oR zSwA#4s7VhIUyLx`w@VqZHjYVyepL1Tp%z9vUD77GdD`3i`D^`8p|axp$#KD}GPA|H{f=1J^L>s-C*6pZ zkbxg99un+vSN`8JbdD^TIuX>yD7n9vpPrpV)2KOR7+^B_jL8YOWiMH!uX@paSH^HrVGG##1?vP0`E%5p`qK%=}$n6 z0?cRP&ofb%bWA6$>4?c6{i@sYBYe^cc17bs4u>pv1G1s>3mb&EU6(0e^3rT~3Ovmz z$;VT4Jqh`%zOXI1>(uE~`=qQNLs=wlMBY7c+z=J^rGCA{1iF>|7c*93G|2lWE5QC` zfeP1=1Fsf?F35vm>4UiF;lQiVpc^_<_$Qd-R@SchSvKJ zHP8f!u4R`Pi$3tJTm>UCQr~L$wlG~%j0s1)`@Jdh)ZYVw%iZp^r3OQwchBuV2EBXS zEwj?;^d~wNCn|9jf%eueO>%17TKdo-{9prOg#gTl80lL(2VWIb5PDKmBl5retL*TBMp#~;PwY`xpnJ@r56@>0V98M)+ zSzpIqaD9bHacaJz5GkMXtI!f-^&es4=FsP8+BKD-?|5_d+mV>1rSG=5SpbV^2&?C$ z&(#;nSC{MW42&9374!QTnPpyfPRaQ*F&KLqfKi9yFUF`84E)IXi;D`+FrYB=7PXtI zzyDBSz;04JCM!9wu>DrWv5~+bSJBj$5|9F!d2gu>HCvbgI+A1p!#Z#7&DwO3I)~|g zq3&N+hFp0(9S&-MA-P*7?l|4MeXa4m5*=KU&Jx0SMQ76Ui5VgkwC=Tl+)AF;Z%#(KB%M(?2*pVrC-_VEizIY~h? ztkqH9r*=5*6ol+}Ob)PTX>K$K@nuF0WlwWS3MQX$it73v zl@o`F0(Tt-Yt>QCsiL3T@FGOv+9UxS@mB&YU;69=HYB1{5x@CdWh9$aLP$gT{7@i? zuy^!?j_J9MpE(xrK{IVyd)11#CyfhbAr(DJY~nn#-_ky}cOb9o>%J$d0~ujPMWE1C zbyr9mA8GozqDT#wc5DD;tKhQUc3f|YmT1+xI6<(0zv0+XbSVr7JyKk2cSbI-vPvqw z?OEu&HjA(ja3-lF6YQuYvW(PX%NOli7lu2xr%zKt3!so+Y_GV7-k*}O{A%u)yz@11 z=^ogh#Y<*{YAiO|+oQfXZ%n|GNmEU~U1y*3m^?B*9Km`?@yiu78(_bWNX#j*v7#6U zN&U&v8+z=2+1MJi^WB}QE({NpgPuxC+FxTeO}h0{)N(n$cM7)ptxBkl9QXPLsVQa0`+i>jfUNJ0bnokj{U)H9axj3roct6CN3#^Jom%L6Zy5^G5NV? zzjjUEckPW?kA2b0fwz7vP5ZQ7yYty;em*uM=k3tUu-WJK-KWVlYl8{>m=Z6g=Sxs> zjvnE$Rl+ycq2xmO3-;`T&yi~ewP$TZGoOZxAGEM}zUuZrlp`FZ$g?66hpuXbtyZgouR!S2Y zw4WY|UbuMF(Gwdt-8>-`b~zrOy7H?}wUzSe!4wsjvZqE-tN|6CCPuSCZxd@B6fHe`>_SFBVqi4^CnWUuE6rA*nLemx zx`UCwFKi*940(sV#&&V)UTQ`8-4Rm<&udH<>AzK9gmow)*p%4Zm@_ zS`JK$Z`Wym>24t`26WyTwQHhrY*BtO-I`p7Fk@n1_9^uM>Q;$xU1u{L7Z)h5!3}Jp z=BtN`KRGyhU40{Emj-y&kAC7h#)Aos6NN@0OV$UGQ0eH^`&>M)q7KPGXZ`ajA7_-XTK4#6|NVch*t{kvAJL&t8SN&MiRo9xc&g%vp=e50Y zv$Fd^^7OPO5M*&LRsFfmJ$gHef0HYrcY4 z5c1l8e%7Wr!g(RLa;EUU8=LpIn8oZTsr!0HF6y!;#kzeJxWwq-Pf0H0h)C@ypB^5A{z zRcrAb9@=Y4pfsXXD`C=pOsHf#F&9qBXrGEff|N%ri>z z@`Ct6BUQI%%O7;5^HP+{u-91g&Ookfu2K%7vwGD2XsvI$#OqwaFJtY4n8T};9Dgep zEJ=cuSbIeVjU7MX57N%MUeClU1t|P7GOA({WUj7x>eB8!A%n#2Wj#FQm7r+;0PYS`qkK5$#V!O<@ZVCiJV6Ebndpd3c(91q(!M!L)x^$7Jf7 zozNHO`t4kx+2aniSf-R<`_dp;)65YS?CGm-+F<^>m>2glv049PgXFBtsRFf*Z!r15 zr)TgmgKHwCF2I!qs9W>HCD$gNu9J_36d=s>O0DS$zkags(HEY?Z;PwGmZE+|H{?@C zhjg?E`dg|4ZEp}1i6K$^IpRfe#r{!GD+DV*>?;}?al{0PL2$Ky9w|)?|t1@FpIDd_BCPY>23T1**;`Zex=IdOupTEtC=c{NZ;y-kir_ZCt+FD%$?-r#Z-$PC%Czheo9 zi89CU`o1!*EHwV~gQq{GL@4>actg$riod^vRNSxoN9bg@9o3WQ#Jvm+8A2S2{31$m z|CV3&a_XSWaN0l&szgY% zi!F0mz;O*Yk6S0N^++E(PW3Eq-iOCOB_f)HO1(1V&99BWD7M_z#6`_T%+hsIJ7-~|c@w245)RZ>t=eLVv0V}O4 zusxmrD;#Z1ZEycfR%OH*e4eiX3gk)8<2h&JGVDwsOG4)z_oYBwz)D^hPOQiD+(WeI zk@wY4A*2Ik;VdC*_I7!Y-G!6vWQ>FO=b-?wv5s8%J}u?8DBdSsnZ>h~PPuzTH*b_h zS!`Y9~j+IzIG!z4lad`CyFOa{hxR)+x<4$!&b>`z5(>=X7Zq#mBd|d~+&m zP#O#b#weCMzQMxuk0prx=*=k2B|xoVwLZ6|u@0NuF7;dqY1xwA>V@EfnxI`y86Jo* z%>Hsjr>twdzv5|v8z26`h5W&lDehb#S~{uk6yfo0DwAYSwnKL<6)HfT5ZJfGo(ias zw`Df?r;HaM(_6X7-pmQ|3RVog9RU4KDzHSwIVwiIoi6RryFz($(|!nT`nfTJ?GmD5 zG(DF9lMlO-@kEno&?e<#z;h#+u3HpGSCm8Ip302jbjrS5GEbKZ*ACaABDa~B%9Q5U z^LMZ*XdsGelMF2>w9|6z|5j(8jG)*1eohw7LnWBN^Q1?OsF?61ORtKC?!Lpb4Ct6h~NK zUMMnFZ1jxW6WWfJrtl&ej%QAf`kQXCPh3=)H*uzDe9E_473W9~d=%l0Z=JkHDht9z zv7W!psiX)Srf;g zAoZ&n-Q7{FcmrA=>+CvnXt90R?z`>H@_OWU?!o#s0pr5W04B4vz)YhIiNg#UbUZ63 z{Zg?)u(veFRab{R(@=2%7WB^J_=`qj4D+0Z9WfTc&z;QoOr5dzt-{?VKJ-Re?Z$!3 zl9mCai|HxYiuh_tH}zZK&~88lfgBL`@M9j&zR3cGV6?W+{UiO?qn2CM`=eYnM_bB= z@cy_TgqvB;#+LATuf<#ubfV0!dEtsb3HZGPN&uI|l&21y6K2hZeRULwA>08!#+1Tyn0+%WI<^v-DS3MsA9E|F6rT4X4XP!Mktu2%`2y;q1HjR z*-U>~V&2?WpX6$bu}z`ZW6nIX;ve+G0-@=v*QbXr%%`spOzTuO#a&}*{c3+_K3nZg z@Z}wmmhER}xdh9Pe!{C&?eS5DbyxXDMayoc5od@*#Bd zFW{wu4u(mYFq9a0;(p+;1M158b$bs}YzXfV5;R?*C+gx&4yi}P$_n8WDd7p-;yOg@BwEYh_RzQcD zp41eNqjpI>zxands_ZO#H0q*K>vz(tzDbVHZ9N|`bB$xzZ8#1QcVoF=DSAJ4%t>;o z-r2R~O0oZE?qRl4RY*VpVIOUkP(%}*+jFV{(w$U5qUOyO`;PQhSs+0c8A z`dt%f8d;BY-KHeX1I}ed9Wi)uyzq0cnhD!xru+ddzaS!A>w+$8wy~h?V&?a!-l8Ic zjd3&gbU~;C^K$E9nDpL=H5Utr9!GNal;Ad}w2lcL-yeI!AjebLNGC@gx$u=cKWw2fsL z?DU?nbjucmdwKv2Wuj@e=rDMIj!?ae4~4~Ao$V$s^sqt2y@jm#upu69s*{if4_7|y zQR;2s1^aBILbNBUMyheH7A%GbE zxki#xR&xJ|o+k1m`DDiB*dI~HhXz~0H?`x;X@O8}q6#WftfujvKhYB7FG2c6 z?T3b!w#-wL^lYncLQ_&*R_k1iy2zuakZxv;zYb-CHwvS?#-@Ic(r6*7L{curEqoGRERa=Hlah z&_9UUu73R+)o_b_24K(ZJ>ixdw2Z_HtJ#ey($*QBQ+(DkDh9*)XeWcL<|2U@w?a}r zbBnOJ<3BYLJ$FqW^sALF-cKF-_=bU#>1PMQ9s5(KVYB`~1}UuQOjUs)`7zsLMUZ9KFCkM=;jzO+$xRoVv)i$$b4!v1NGEaV7U03vPUBi!*Nr5LLW{D2PcSHm&N1903f=2l~<5`@>ECbiJ zYh}U>b~2x78r)p}AkS1Zd?oSzKn#y+dh*_sRS&b&agHE5)ii)n@T>M#ONvH^Uh969 zW4B+|rN!i^*cMr5htNPc2C>-ro@ zSYlp^3NPPyaO+LN%x%7gC>fE)@*#Y;{fkKkLr*M)egG|2jtZ5X-cr6i{LsbDNCx6DgVHZiFWGTUj*uw|y% zo>v+slf|P+jVzd!Bxlv2I%$hl>yr0ZL!EyRPuMRgw~qjmR+~hAs`;$Bw1W2`42mjN z(3 z(4GbROC@33Tg&n+zz__JeL;yQz6+BO?OiwiHTgs?`|?~D78=u9VAr8*m6LLAv%CgC z0f_!yiFcBbSkDo_R%|N|vvMqA$o;4U4MU}t+a%?EN7<D2wGabzFZ`EwU7b~J^K}`-d!m` zHe>QD+xb#0o+ReQi&%21pV?5bxQRN&9SonHgoybCufI!*!aSN5(lq2P=Tbm$(Bj(8 zKN0`wG;fT(?nuRrt#+ONLHF|XWvBb?n9e(7?>sY)NHc1FZ*{($H@w*s>2r77bKGX@ zN|`%v$`}22x^9-0Ov)^kDH-1v|40auwh;BMZZ`GT6!(a;mtXRLuyFL2RJDTM^Lv7x zufQ^FW32=0+yV)gJUJL2dI0lYw`yZ5bNR)j2a?oYZ`AmNj!K?vbUnFEWED=~9u>Ql z*!S^0w%&+|%yS79-kpl&Cs}NZ^>qN&r_z02^H#*K>y-8}oQR-aU+R{1X<~Zo{saJiYg@@Kfy2$X8WSK0$9$y2X|(9i_oUVoA9g zovciXxM0Dq@Wh1Ex1#X*`v~XH@I*xoMbyT|s{wL2tUE_F(>(#!dZ^QXPiJ%z9#fiY z_mYm}?xjE33slH(Ngf6t(YP{5Zwmu`I316dw;5|5`jwd&eX+*|b;O$#FMc)($P4!% zQ&Zu~kfZ$WzNMai<`cJ{)?x$(F%M|W*2u!l~R@4ia18r@(jw#%^43|p2M0ck9XiuPIyi@ZoyWxDpV~+@o zak|vpJr=iJYiqb0Anx?;HPlRw0ap9`@drE4+R4L)5$M@LS+38n6~#tZmrFncodN`M zr?&G8bb9yXGdY0f1K?2%*&FQEdaU#ZSw7mPXp=M101qqr5onC6Q6xA_}AubtkfztpIY$8NQd7Y?%_+*Pg1<|dqEpigsj*Sp+0i* zmiVp$;T*Zuy0+90|BH^AL6=eOGHEgnGJY~I!=X^+v!Sq?;nq)xf*Y}n;>6H(ppGU^5K05K!Y6D<_ZNaNHzJw?UBZTU;K0Hh;QV9P@I>S8u!hOZ@xzq2WL z@6&1tSK>W+@y&MxHo1l}LEGW!%+V3s8*c{APoiLrfh#_$^Q0G1!o78gz)z%l%C&XP z^_LWq=%YJx6yIVw#H3;DAtqC+>IrNrwW8k@&QyMcaUFAn9Di7mtH>x94wX3s;R@5^ zL2k(6HyNfwLre&Y(YJnGZ@hdYv zg6S4XPU-wEEqgc5-&^Om!tzgeYi}(M=WBd{5sK?^y4}``0So)~8@Fe zFkI4o`^fHTZ4E2i!NRVLorfO8J&ONbD$#Rg-93ZX>zJP+d^l zlzC7y2&b8I2->O8acf-x&_PMtc&@2bcI`Y13whhdK-iPg6G8Z48RauRl`bwCA@9QEiXEd9U)2hD|e%|J&ufH!BxNI~>IO z?N!|kyxaT0*!U$EOdk=N7#bKb+{fUEw%?KR>(dGMYNs>WK9gDe^<&;<@A?z*RFBbT z$y&SIqd7HZ8u6CJPY%tRv=+-TvaX{QNMi9s+L0<^LP7SW@vhPIR?3GEL6M43YhC@K zE}oB+uAJ&S?cn)Q?8QGlW}`I4f0Q|()Ai(Ihq5s``zJED3Kl7(jpX(=^o<6(UOe?c zLzFJrm|&s#rmdmLJLR*P)nkO8p~JpNJNjt(r=^PLFGz1pKjhAhw%93X^n-UDwxTqp zHhjft2(+Ixm$5RkmznoUmjPC!B$+je{`;L;3${yUjHk>F;rvmo+LTJi#kYtFL#w*T zhd=Uu1amYXH1enSKF9Md@%&XGz&e}ppp1a%XfPfGzcOMVfjFWlNSZ~a-M1wNnzOBx zKT-~c{UpNnTEwX9>Fhm)9({@@IKghQ-|>hm$}1hxbtNNn48P3dJ%(Ay-Nt?^Qz_7S zM5jc3#*0C*-h1IjqTVJ{cGJ7rJb@`QVC$4fUOJL$d?wh zMFqM4!>RSAbNUxwlLdhp`Q;IOJ?4ebKPPJbm#>Su34{o6-~XZd8g*RgYm&zCmW@ac ztb4)hDuDD~Mo$j^H;iHk6`<#euRz;06A)dy&pWREL(?^<*L4e=@*K}~g(qpN;s4Wy z49~3g)}eF{?*r*=)kJix!aLMoK4wIdEKed=`6fB zTb@#kg9TtpxH!|$|0YcHytRC|!&BYsWBKV4U7PkR??WzQ@54oKZUZFST@vbeU(fyt zbXWXB(kvXe?v={hC9z(OHyX9v_|;(ftKRz`VllV{;9&3FQ4NMEZ}9M+&t2>}*(Tiv zIP#YZ3O$nBSY+^$v2%~R&?%E$b;QvQE()`|4ESAte-Hmj=juSplI4PRN`6o(cn+^% zMb@hWmg3pFq}6%`ka&p z3Oz}N)JQyGav2z*a=QKJcL2%Aq-wQq)?!!t;tXK%vml%nk}Xp1_DrBND><(qw}*FD z`vhO~e!Oc`|K?wB1l|vu7PqGmHX2@e_d9q5z^}P22p#WigaI>m{VK5B)c)tl zhMMnkVJ<4~xy&(0g9CkAP*1q6p7aysEyR25<;)Vn#2sH8Z8SkG#L44>Zs|RcW`C6b z9PrFd+QM1ydHm1$A^3&xOn5djzGzyam<{TekU=mD>>6qIaHLs)`@)Qt+2IMt?5)Nt zhBC(o0JiBQzxzSK&gRmLARyuR- z%ZY#4L?}<`T&7;prGK5U##>9Z9kZfVDkLllfBQCs3i{p(YB1Whm-@ED zMvFu1Gy`uK$sm#Zn8CKYzfNax39UpK=s#^6E5 z`%AiF%2KotVoL1X#b&v711J?!I0E>&+KKN^pa<|yw<#Wbqc^+N5xGj~kscTVAOAY1 zYCxU+%b?4v-s-@Uycc3S@s_=}f#pxN^GGb&F>nQqvaOg2kQ~pdWxz&u zmXZP--}saGKAT5`yXnjq*sK99RxQ@h)73UV((B(h^LpHEg|K@mGp3K3K7$7%AM(Va zOGs1wT=!*rHMHmVyHmm3(gj9W+OS=A%06G|VhsM7i@yLyupx|JU?dqvFTIz(quDcq z+n1#mpV_cLlOL!^fY!o)^8cA-Yzci}Y6W7r?RVtP zp^BM@luJq76&5nUj5>^Qzc>pxpsRgen_I!Ei?>19JhX-X05Tc)aB=4kgelelgUiHQ-)5S}>I>VHjiUZ~ z{(j4=dbvE5t5+5UAC4)gYiTY-8>}*C2J(mjH%W~!7_uL9Hn}n*^0#89#=q`}-zOch z1HQ2(z|}eXretVeQ&KV^&37M{;`wTwz=odU`=1m=Hy7;0_9L$y4kD)B9^lFc+H_ zYYXty+9dwlyRKf2V+T0~mfm}l{l7k$7EQ;6NvTa9g*~*}V~juYxF9YFf-q zs8z0eY`GH`*8h>!^rhwZtZg`Rk`(jQ3#N^kxYgqy7N!HCbo&pOQbxa_j&G!LW$ z!7a9!1%9XR*rqh!IT$L`PX8GU!pzK)jUik?ey~lR-ZbV%uST}UvyqCalEVn%Q z{dLN`FSJMNHz4w34AKJC%q|F8#2q%hXAAP(pZ1cDx{Nh(J=ts>V0*_C`3KyLq)@a8 zyWv^rIbf!@TlN{xN`}kh8T(TciSb8VMWf05er*{eNx<61!OsuwdshBxI`%G- z6E>Cxuu6YExZi*Z&pj`!A@O(-tU`h`f@HTVjHVRwGEd{n@EFWMsKg&p-25(xM#+#q z#i_?X`ZQI-UTle1--Ja+RBh%vmDyHhRnwEc270OS2l8&Or1ULF#Kts)^T^h^4l4lm z)Ljnr28*LA;1qkLZqXcSXgNkhHhhMhh>}uQASA+m>VVMV^+GrkE_%9$eJfGv)nZkE)@q^;9XC#O>Ib-IVl!%dNXA z?}oOtPc~qdGxAm0#|BI(wK>W8iyy=KZ*lE)9P&B7+Ane7omg)Q11|RO)vZ#;BvS1@ zC7k;Z*TpJ^GQ{3?TWz|#F1wz2{pGwtmS(prbU8&>qTKFib-*D}yLXR@h=;BU7;G1Z zE~f1l%iz^fCAh3aR9cgPbR!j|AKq-V1ZXoB7zEz&mT8MGe@-ug2@p44G%?LicJ3&C zakiW9H6JL((TLaVc%E&i;B^157o*6iy~8KNSmETO0v_?^KiZd*zlOM zT%^vRAbe0f6Tr0K9+xa%g^v%Q;l9P^B-HJ%WYxicB`qNBirk zE6RE-F2B4jfi|JbvV0Vkxbx2Ngw3$EW`9be?hVkDojLCQ)LKN#7T8lfxIa!6AlkTI z&_tOy2*^ccdU;kF9^C&^Eb_0IRN*V*kFIZ;N6|f#R*<#w0RrL@<@4u`5sqC#TG?Pi zi*!Sh7q=m!9hJz z$0g3^UJ06Fh3eu5Sq->Z`_zoY6s8m@`a4pp2PegYX8{eCr3n;uLh86E%1ZlJxk;&+ zDZZ^)wh(ExCdCl-?bk~Yw9;u>%ZFzpcdd60N*ubphC7LeQut~5VOo?b(vx4Ts*XQI zSWXJ4EysTv~K(Kd90B7TH={@=VB<`{S0c;mh53n=mRg|!`i-;^qny0 z$$_lJoo_$WCpck@C-Qq6ujXZSw;&@M7QwW|l2q%y&wy(9{J>Cs{hcx6;O3@X*pTumaFyx*RSXC`KwMF?Fr^LgV^K15W z^We>a>pgRpKg#*!&ZrDYINE_0E-nTbRGl<_2dcDwpl0!P#Iyex9#NS`e*#STO4|d# zmwK#_Bv6QbpJ{j?Fnignl59MnFX1x z0u`&hx}F%yuM~(;D+@eLg+uM8{x#r;5a$-*y}cuIH0?KN^Q&TK|I{tx*wCV^%P%LD ze`b3OGP_-Jbo2B{Ak%a{u1+a`|46j7Zqv7<%OBF87Pzn0$vn>Gp}ReL+RZar9$J-{>iNqWnIo zB$Q!CFnvDn`=1WTQ6&6L$(tafm=(6>HD2bP3;F0uir{%*a+8*i*iU?G zD-JB8TRAWVb8|}?<$Ue0PnX{*eFs!LkWY{l`#zXNwpTX1aF8_3-&{i&y4<0BIn6I# z5nJXxQe^X<87xn(3*>8rh(dAa)i@h#ck;@#s=}*px8$0Y+M*os5fMbLvKve0ZHKHw zE|2Bv@y6n=O%`Ln=c3fR*Se0W?<<178Z%Wjw(xzQ5G z+;arnNKB>U!xtnfURSMUKE{PemCCN1)$})rc*Uixo;(&`ke2UvXx&$yl}-*<3_F%& zu|E#9%-gH!f6KL}oO~3foZjl0LMvXP4zg#O&?&zLj|0GhyBsBzx^Zu8?dv|6C@55D zUM?O@pWkSWwM?~=R{E}g=!u!BDa1jKcT@}qcg_>FW2oUCDYRnM>QzU$2;5t)`x&Fq zr4QSlWhBCcuaqbQHl|GH#o4z2+2zFr~5JRf)t6ZH*H4hEDEl7nuxcEenTGX zU%-Lham;nrK_)qffG;{S1?h;uXqWljKso?#>1=$0QqPF-LTC_lrRhCmOoeRBBQB+@ z?bo!PM~o|*&qy7w*?A?d_=X!{7IO@*Y5w+-;QiRCoO|+$YE|v zF+jRyQLaHd%zE@+pK;af0QT<>ulz^v`0mD^gH3Xhh+)7*K;WiEV#8%B;Mv3onX0;T zOHMVI=kcujZO4(&T2rNj^YAHL`X){PgMD)4Z>jy#9%uJvn`ZrV-EpSJS@x*{BQ}E} zUk-CU#@>{4ny*`&$_4H|pp)#VhaJb_29EUqiRt~K(a>UAZn-l6q8wgTqvz|NYZ6#RV&Npz%WVcCB*z4Wi_smQtG&k* zOl&T&p6ff0UJs-n_K@ip%>m-rnk3!|~KCo$n3@fN2%9x8P^3c1!?(;||mX4x=Y zcw&Ircn22%a}D>e^$nQ!X5-Y4_tcK{&yB%!VUKHedwC|YuauZ9@fpQe9{h%X+>hb5 zB+c$~>&pjs^!(~B2EHDsPd?t6&7bDpKHau|HRJMH6{i!jJ7YLeB z|HhX778f=bsYI-DD-{ijesE%e$%2Be-K5i%&e9x1&`|d-Bx)F7Z2J|FnyuQ+k`yCt zETcPNR-8H3y;BgejH^o%qmPh<707ZE!bJ7AxNikl#jq70-7%?#Z+Fdy7y$2%Hq= z$;B+!m;AWotI;}@I#|uvdG};=Lw;z|HDcf++ z?@lkOc1ZXB914`ySt?a6^|k1*f1L)SI5XtsuHNx`S)AYZz-)G_-H%BJ$9o$_5d9#! z46}SfIdN2gOk+XGiO%>{??e44&X1Z`;eO~eivWr_DmN0=>Z^!w?e0qtnqdlqbT>im=@ZYF z6nkooFt{7#?|$Q*-~6-a`Nr_I?z=WslBk=7)Z0LR7i&Xu$j?rO91e9Jwq|N$J9Ufg-Us65xov(oQnpYp;@L~@ zU)79!)E)LWw<(e6T#VEI@dUXwSgM65bp6H42*U7I3c?p-Y=TE-lqQY=r`TCc4OqDh zlATxmfFZ*L@D48jyaeCjVR@_>=t^*ywJ7~pc9dZHe}9LB@1AhR0t?;0le`3q!4G@a zs|5UC_9|aF07h@b31pc6dW*lGpZ)cBi2`kl{}uXmixl)K;@Uwp+J9TRD1G?ntv3Mr zjqdqCYvA%}2kcWbq&$u?3~Dg{9^QBq``$lC@s$C2dc3a=8cM3bi{pQz^!Te0PhRNA z{okfC84vO81r*-Yr3Q6e?)fYe>u!NeenP58uaf4r`&r9 z8NYNEPpki`uL#6C|M-8LdWmJ4MV~*Ns`9DZS;?Mpo$9x>(`;Y?LT2$hdya_&dkcT7 z{_B!_t zBPF34$IrT=yak*l%z)Z(Qe+Zzz-USb6k(vaOFW{H-KR};r&>;T)3EFd;9NgEbX z{yYo-&X`bOk#Mqww~+hib;zkS&WWMby~|s?H(@#MR`)^p`xY_&@(Yz*N+TBd-LK52 z>II+)kd4+f{0i*nRdUZ62}0g{F4`g_1d+W}@Us)Jc~Jx>l)Ug4o-n}oaM|GM&|mciI3|MW(P zTR?kBtHpi0JId+$^vxe>r34~3fER?N_Yfy04;YO+Xl}-PB|JX<0P+)^t8V)mzpBLp zi2?;GIlPxUN3EF-iElc&081FOwn7hpcp^ME-xfKm@3)5!@#9(xYkJQV!FQ!U8Tg{%<56AVX#fzCD3?Wg zFX;kL0rVjya;G?Jj*5kKRBfIwG%JqCRD3P0y>XYw4V@TCQMU~>2&M5lJ1+llx% zNXcz~f!^CCGXTm@rWBhCckiMyfDPjOXw=%)I;5mQ5KyBTAI-A-`Akw%AXFX5_HD&M zFx~bpYW>p_rsBD`QjNR75hr~BG+>aUQ?fiYW55?^V7o^;bsuRmoeVIk zh^3YA8_oedc`yG^&#vZ!MPOe~(Ei%^YZJAQ#>3lHOKBb3toYDNg%Nz{+%YlV0LG2S z|KGD9mL&c`dj&0G%`QP7S(>y zaEWui^*zgp`2cx}>tejb>3&4uz@Jj@CFb+Enk>7W^1~bJSMI*bUnIV1-gztX>oRk~ zkBe>7i@qRs`SGMRY>*|H0?m=TY};ek!!GR>T0i&+5Hg6muuqKJY4xe> z;v1j26m$vEt?FQAVXg%hKwOv%$1N}l@%~s*^N=Bc?&MR;Y2uOb)7taX^=#Y8D%C;F zcR?u>!Xt>NYkqjxF?dMPTSXSy*H9$XDEM~C+eKF0P1XbnAR@7Da(EuAab7!^oFdn# zZcZN!l@}QpaZ;Ftw;@xSo=4T4%=5*Evs#~)e@5oB8go=`ckTKKq1FcX|ftkvurSf1_{DONePx}1+i zBl9+y&$}1vz2Y-tJIp7*($ zT)0cN5axAaI<=h*GG=igDX@)$pqKN<(x}}fL)6ShuMbdaYZp3ueF9BhTIyn7#Ql-E zIPW9&Fv-a65s(B|Y>4+@`qkhoh!l@%5MOi)7@UZzq>@_tmLc!OxuPoI;PBbe-0vGl6Bz zft8>qf(dlDMyhj+{O4m6t;Q-!c#Xw;3Bt?kB>iRZ&{?+E9%<(e74n!gh)%B z90pCJR&uvK9=+wht$up6tI9V_L_|)tUU9mo5I^Xo|whO=!}@2sQ5X_iDn*!?#=X*8{Bi0b@YN2Gs8>15+ywssf)Rlnj)@~ z;`e2ocCdVkdZ6CA1EOPhOST?zFF3m_#Ak0KLdkj@$YU&If@Bdj=MBfW=qU9LH+lk; zOrcr8bxSRMCvzBc&35;=>xGhTaVv`}*>*PJ`+p?X=O~^ZW+sWtN=AsRjTBqtw|G0O zO_Zs5$D{-A5Auyf#$JH~^A;k(Hz&0>s36z^qwt=7mK1h2%qkCs@&(*_^BN4fBSh+J z?TF8v8&*R4di3r11`X*6t}Ch+be`6wB0ky2r>iM)Lxs zhIZQLQQMFC$3KnsUCdKb*rf})@q33(f{A42Gz09Z-*E7-ZYzX!w-$ZxKU`9#vW`ILD$RLz!`AvM4z{Ts4L8#Co^SKh}=NiHW ze}Oe+90i04H`n&2`JlAIW3PNy$18coG;TLd2 zxuWEBxr90Q!On|1TB3@bJ`7=DYdr>(n#YU{7alZQlf=~adQnr0R8rCPzWQlrzfj~1qENIF5 z&Fl&GjR`G<+u(>ZRi7ZBuPny%UNPWYIwW)9tA4I6aL=>a>;>IeT%GW~4UYhITCiu6 zbPRR2O0+5>H09Ku3fK%KRtGH^E2@DGOkD!2YI4|~%t(o@C*DU2?^G%9fd1cm$NsVY zWkF2Lb5HM*v05*cZ{^4Gx*q54-kxjep2-$F)=n$u%2vz=$0bLehWqSm9p6tfMbn9k zd`2N4a@J*5j7$MW0olnN&eaB0f%5Sb)L^~zsmUq*wW-;02%zHf)$ANkhNRBv# zM~qHEgR6!M5k#BhRa-J5P1kjp>b(4=bmu&^rtVGX%EP_AnZv2qHRoi4Xkx)inzE?4 z$1yhTSnvuJLxEQ)E9!kbE6N$WN*^g2Jo|oDRKrmEx=rS!rB37n-Y+SoFP-4PmT)rr zb?WKL*RcmB6J`&jqZtIVzR^9IlB|5Tgu52pE9kU*wFb4E#OCVIb-&q&FECpQ*O*Vr zx;Ps)zGMVz2*yw_ipq2+OK`tK`aZMU?BH3TO_YNguy%L)hJVhMy-i2dK!U7gA%&Ru zMN6N|K&gWx)30ETT>r4kG`GbIX6J3wVw8?LtFlRvva+(&?GDt=N@pt$B?$3e>fb-S zW&9t_a?ADJ5&uLCW%K%VDyy?f^Na~_ujNlK)7{QlArWL-rFi^f-ZMC~SDry-HuN<) zA^nsrN%hV^#Ec)Tacrr4qvUr|En6}ThN`O?88e|`I`?DK{|xeJ5pX<MhRI<2m5k zs(Qt2Ux#()SKkLdLn(d5jkGRH8jF)RGn*H0JHA`ly)F(zsx5swQam# z7{74QKUC(hp${;|f8(`a9#&T=jUcu^TKKu}k>XPdBX88?W z6nEY7E7>B4ZRW9Jm(Nb&W=#RR)brt7pOqKYFt*EYHvG!T*vKGL%Rj$wa^uPkMb~@cr1=p_~^n7ga;qi9h_k!vV(4oP~Tll0OWZbM%5P2eG&;@vl%4UJ8!8 zQ;p_#*pYPE@Kvkp{uQrPtqzueEaUsZ({5VBXzLn`6T77L6lR-Zx8PI5t!FtOeQg!O zg>7_|(_T;aUF;^|31YRY+YR7Q+exu_6|H!QW>Lpa<_W?}YL^Xx#igDfS6S3+$(*ag z#m#~YKLrYirC70xZG|L?>?8qig_smy3>(ZI7V6rg5&I;iK_Hbn_``6%9v8P(POnuO z%jc%hwQ=(Ri&yQt4ubEQBs8bgla%f;Nv6@qiG`&M%*a9IG(L2E_?iCYaTC$ztX)jE{5^dO8Q1- zZ0o}Cm~#616(sx985_u%AFNhGP4wfR?spdr%6eye*gF#2{9wzWugS(YT4Y6Mwil)l z>(CX8?xZirY;h4ifll!P=1*9|JwrCQ@?xpD$1YJ7Qoq=^kOsXkV`eDnO4a;4?=zT< zTtw|*W$5HVGVdNk0hAQ`YpKRdlZPA8bM8Co6Zhw~Sl1a-uSuumF?&9uXyPXaAMC=x z`*P5hHx;TYn&R{mp!`!w6n~bbp2&GDNjF)mFLCp6nu}kr@0*4*mumOzu3>@Kf1Y1+ z7q*+?0FR&M=EB~Z9^+-95GeU!i1OiJTO#CoQR z(&SdSvfOe3snJ4S$_kThOR7JvdSfAXejDFB@?7P5)1^_=9V{bjs6Y;=vkF5a-%O0$cyFgFZ!|_exlVHwc=z0!%4f1VaOhf zLf)MV`xks55EG*ETHywC9b{k1K%jP9j5422oKa@UzF6WO=g!WbNeTCm7ur`~vU!ps z71`|U*!JAl0iS;<5FOo$#g29*HM=RW#PX3)e+1-S&;0x+nGcVWgDy9J0$*6>F-;5b zi$Jb5(sc&0PZ_YyQJ5fuBWhfAqA2O~HS0=##YRsbN zBPtBZcvEM-(69wt|w`@OeUermVQ5Eu(^pmFJATS>|#$U7mK9t9fhPue=^+v zVe2cPqVBrARgjJWq+wv_PLUj9=n#+)k&*_bq!~(NC_!4f1p!4;DGBKmMnnPWl94WH z;XCN_y!YPkUY4%qQepma&ffbMdml-SWG)UuDn4CH_D)f^qAck2hXMEDIj@}sWszRd zC%qZ$qoP8jgwyTYC2e2AtyB0-c$&dku9f_|tA*;nAC1^yC+;o}I0`WJ+cH+*X-vaI zX=2#}9?d;D&nTq5^YF(YZFRu02>*wNUwJZAIo}sE%mj=0l)EVIv#>qiB_k@CElFUt zS?;IgvHSINTC+O_`t~^Re%-^Lw0W_y5^_&TS6B?9gE#xyLVd_==lR8ax0&HR#km5b z-Vgfye9Ay{V8(+#;c9zAUBQ3=IHEW1=?Y={^H3q`c4NFSOJ=QV(xiW^(fG#SLzSTtx}C95EWv50cv>FiD9V?os>-B5XWYh;=FNu|tWpxtuSLUx%a` zk=FQ)c^N!GUw>Z<6N5^@zH~>{RrSDn?eD!&rk+i{FJl-accVyBb+tQz9dbcli52^K zmb4(b?8}E=Un>u~P|=R24wKD)isGA@v+QuPeQQ$p&0BE}OfF==gX2kSS;W;bN4=e( z7Np(eo@Ij0iFVUR)GpK%F>a5$4`zsIuEpWT%hi+a^v=sf#!OL^t!@5Ht;cN|cv_qt zw}_|dJXW4f;4(!&mAfe_b{P{ogkr|oKm|mzp!m#2o!xJQ?IBSj86yqbV&4M4{5Etx z9L*l1G!RMWWc_60TMenXxC?#3^GOxjrML4kF4@w>(s80&i+V*`<+koQy$5^dhnbCy zYrCU;Z#$acjx68Xt+S%tn+L43c?msolt=r3*KYQd&aAn4;IVCkjI76iR3>PJ2 zryKC7%Wa{!-vx;or3^@*GBhphc4%%AS`nobK?{MsAD@yMJXRjA;C*>@JLz`jt)Hj% z^9xcjo(6E(KrQ|2}Q zeStKBR20a;!G*N0TC~SPCw{uvqZH)8V3wr*m|26n@{eHv(Fm@gL3_ngZvtzz*V^4_ zZJMu7uM_T5y5@C7Qx7DvYZ_!pg2s!K&@1l1S3EtN31-{B?)3nf24qN$qx*M0hwXhz z7gY^Qr{uk>w)X9)pb@cfzhOx80+++|AFm8m?mHZMjwn(F6!Hr#8daY5x z+OHr8X1Jd8&MOgN$DaQ_eS=GStsB@RJ>fGqBc+qW>CVDAvgk!tD7+o7^zw7r5L?SY9rhr;i7abq*I7mb7A^MO1(mhZBC>{odA z(ZcTL*o>XLocqj}D{EwhB^A6$jq@Q&C7I&B*pm4Xi_LY5eTuX*2-3OFih&$jX?bJT z|HnhNAFs5elU;JVMq(}lfRMpe>^7V&T5_?)D1>~3}u|2pA;f#XJqkikFEf`EJaAeLNOLqspOx~8oA9c6Tdz4 zcoJVx5nB<1Kr3*0pi@R?6D8>XdD3K*|5+orAzk8RLQiq8Ve7~4J;Q|3D9y?v?4;5_ z6~0y#DePOxj4cUyD1oE6?S{tRn5bD1*MIFH`--c0R>3VlfO@ENht0oRG14oNTfRpn zd;7=L)o>s3(*?7|HTK0-6jz5Bnd~z2=(Al1S08ivynNYY_2z7Q@_F-3nf)YFYUkzl zu_^DNQ2Fb4(veyu)O0^~VgJ{15VpcqVz!g|H%)Xz68w!;>FA`&kD8G}Viv<3{{~E= z;7;QF9?{5OA7%#mu4drF|6N`*DmK_H=p=#Xg=0n({)2-;6v+Rih?rhHhkVY!41+`% zn*o6*Bd>A)Sjv8>{>k+4ARjFKfBuj%^h*|<9}sS-2ek&~e%kIjQ#`a9ca!pNM#6tg zTc@~v`X6cLnjS`B34bWV>>05cm*L%<1cK;T^#jLKcANFPefL^&u>ER#*phjh?Pr(z z64mYx&yD-T2l|rOUwArxk*Nar5WgXg(9s)i-e`zO??3B*!7C+JpANn%%vu5_wveL# zeAOJ;UIlA;*Jd!?=vmx-0mHiiFvApR>TWLd1z*yE8fFQMvp6HcFCXR7THo<#s(>vl z^<`_?4W+@B2U4RU{v(Cj?8^f$zWfR!q&$0$XJbcILY0p8I6w1i@Y%`<0A~A39;me{ znp*J0%=PlmmtRz^e0iW6*v4MzrQq1*yFl;=N|qyZejcl`c`j@UWi}ZhdYn_|cy7O3 zo(Rp;uU2||3?|AJ+73`9^4JoX4PR+697u7$I1ennU-XP5WBQz1pH1ImO$e1|z@4P( zv;xmTl=+QEnN4SuF)4e;#2OnIEl=tisrA#pj z0gju-=OEP=0jMP9U}sjE$X;kTK*e*-@U_7m_*016Gb(OAaEL=fVpp{002P0sW#|cc z7EEn-sqgKnxbt@<_vJy@PnlDe)dyma3{r2sHBsNVFZL^o;~=dWPZZQdG4^f$tc)0x zf;=Alr#?mb3muIZ<6~6sA}R+_L#oz`Etrp+`OZkOK}2kwPT=5(`VI>!$F=o^3NgLL zg3^|Hb)h=jXa6mYj&NcY6!aTx&a@e6NWvt=c6zvx^ucGVA1Fgh9i%gxQdF9Dt@i%p7|wdkm( zkw09WP;6=P(%V#zF!k!WEH-s-u1;Lr9*4CXPD9Y|jL|nHMqq>_d!6fS zO2F~%s+Jk*;bT5qirp9dkM2?;dvR|Dp9eH}|H>euzhw|k!pK6wsU7cs*b>O18lOH< z^S__DoF}g$4nD~z9$JwIweT{@!u8SHdbSg#cnQS|BT0$YCs*;)s|EQ?3G?lDSI9-& zO0oT7@d-34Y_YG~@0*-cpzX6DAf%$A{i(X)Ng!8ASr{rGLWen_qfOWgSR2w zEe8l}{{~;YMcf7E&qo{>0TTq-Kr=DKlgA+IDQVE#mwd>&zxBU2Q zeb5Bzd`p_)r~k%9{LqhT-7%abe%?<*i`J8$>)9SxAar)B-mt%$yxBME_Y6g3Oq-C& zY4cGJzdxKK%0G8+%KDeFqW~%dGqF;>#CjI0pI_=5(rWVl@XKPE`w|j%h7-iWYxtN z>bx+0s>hxb@>Tb4yOKIRr{M8$f+6yt--^Pf3lPBt!oyTJ|m@Kb5e~YJ&|u4kd!BqH~@jXTp4*aE|BC5oHnVqOq%Den?0# z#PgnjNo~xJ)4n9>I%ssH;wFjx&1RQ3co>f)aBm5k^9bejN5c4 zolJzs`~})$zWus!olADv{r5cgYmvVm2AZ`7HOr#@DRYKZKjOoe?VOTczZnj@U9(vg ze`b!*X&xe%+Dk)eOS8d3jWl#$m4rcwLaqxk%$`Z`)j)-NH&XjW-L!M~qRQw~B^xG|zLGG*Z7`|q^ zopBR?mQJz)fjI^mmTh+ot%%(qjaZY_@k@4*OewF|o8sQ<_h`i)CiC5^WS&7DFh2pw zP%@xT&Zxrt>+ip5JtyJ`Ia0)CknQ+8amv$X4$U?wMUi~nPNJ}hwtAfJLe*TsGQ0jF zG_mxKc;CGmuY2S_-155y`SR1ivQBU_Zt|^KIn7n6b)Mt^M-9~&l$#p!+$}3Hhu_)Z z0a`#lr*;W|8 z6>K}$oPOgslY_&e10IGgAmL6jO+I)#J5JSC$pjn;1;iEay+%Q?iDf*g`0wA~-(u*5 zVnbrn;r`xD6v*D+;(og}l-2br!B(U!q)_ek(5lw3sy~(1P8oI<06%sIp3%hlxWggG zdn*F~(!Q^Gp!*Q~t(DVo4t%w5!F^Ln<#T~@5y-eFK^x!SCvx3kk@P<(6HtvX;@{^p zt=Bz`EqP#t)fBw&2Hk;0DH(0bMURNB8(-w#t<3hGYvXIYW^N-Cf_B@2x|$w9jUV4;pNJgELFXTk~}e zn^O%3{(ll!Rpehl1g<6KNLdR7{aC{ZnCEKOS)eKHml{>%v;@;tfcmoOV;YP|hoZ^# zjP^L{Zn-J#{4#kuT2asbd++S69K~^MKekfus2E3`@4crA;m$JaS4gE#54TbQ;9Qdm zwrzFrtw#(#UWgSf4+Jav^X`*t0Lr}zn5edmMq*zj^<28^AwkMie)!{4=KLe&SqjjkGIO>`IR`kNJD_Vv~Ui7+q;#oeN%ed8&*ho_GsXa6d4T^U@v3y+S4r5tG0n zO`WWBT?C64%|cis_1CZza8xTA zhlsMAo+MZLQsu80`@TSsT3tclED#SQ&|XvZL_y^%javd5o>AiwY<}qTz}u1(&*6xK zMBaGfLufAjaVL^hW-cC^-jxzJ|G`pYRJrP>ny29K^+*c8db>j@j~|1xgWZ(03HWe4 zVXfg+PQ;K=$(79 zMK(*i+kGTjo_?Ag2(;NJL03r0Tl7)fpL2mZ%BSxcC9e&jo=(h^#;?feZBJRsVKcQy zKM5q0JeqkBV8Q*xPraE4;`d5Bn+~>#R*96>-dEUWF(R8$yF-?a4*jT2Ka%Q82oJz{ zhc&igw@~n#%qHu>k57OI^9ueR9+X+@4)iDTm8;^`bh#l|k9*z!l&~u6{}Oi8NQ?}` zD*%^wpOTHm_R0<)NPZd|Iyq%n#5lA>b0uQ~Pp`%j`uozkbThkKT*1Don#JM7;4j>%@kBU-DpM@71n{Xi6!wl2gmP25Qy7FJk|D)o zQ;GtTS?MvR${2B&TM#x`i^)DL68)qybd1yrcake&%gl4=H{a1S8B^YzSW{dC!GH@K zDt9Le4qi1|3Gm3jZz;9_8V9L+q#Q#8UYsh$0_nyEugn*Y^~Fxd0}qxo3S@~m^FH%k zKSKDsmw)RqvJd~zS?Dk*&P`9A^9Mp*t)0SQA=~jVMV8JRuHz~+S1&dfY3C4v_jHO? z+I25y>^H_VW=2R*2k()T+)L{?MUSlkeFqP0~zHgVy27+Qf|JW;@=;hjcs$Z}gDCss#Mm zs@xjUQ?7`%=dR6;dt|ICN`ntN=EARL$xS^-3E^Ypch<<35YHA2m5N=SeeAk@PJ7EK zjpV^^g&ATTOZi|exY;=os|#cn1x@wAZ428XU$`<85MZ>^v=dkv8H)}*`Y4M>A+X;6 zNlK-J4L?#6w}A9iA`Uv|uRS}@_^nrzkW_AcKsY%{Xjf$J47hy`==S-XgJNO zeowFbjaSVj;t0aAHs0Uap+O)0*jYTkoTF-Yo(T~xVOudN2@b`L-)7QmNbXxv{xH(x z&bU7x&@uy+$x0fg(_!f^W@616koiNEupS8g4T5=uaGCv6j^Ca_XeCcSs-xm`Q!3vk z3Crtb;RY?u7q_ z=;Cb@)R= z+Gmt8nDYwn?f2Tv-VfgrL-5V&r}9b4wtJ~?>`IJt@+AC~ZdiH#$rcz8O$kqTN#UWl zP{gSe*LJ#m;;HqI#2Z1OO$Nix3MGk_y0(V@fyLk|jZBT)g`Fr`+37JB_csAm$%g$tw15U3ASDqhJHeCD!L*eFZ^;)ho{6 zqGIf6J7ElDoAP*9dnis&D}j29M)0hatTNv4rg- zpa(mgkus$Ff|1HgoAOEsW`&#AlqgbTXcg~Wdu7fUKv=<$$jjO*l-50obG4VAymBE> z389C0i8&jeUA~HNX!GciUWvdGWG8PxhK?(y5nQ9#P-r1mVv8*{C4aT>UJ;n(8Oj!A zX7cZy=M5{PcRq!pbWssNinQq@2CwxmIx=Si-V+@_VkVKZP}) zirC#8hSvDHhH&i9y?weeI6&ohjjYMOmuzWxa>Z7`f6q?>6H3Y;k;hn1CjK93(Kn&9 z1+AZlLd8yU7;|jBkoj_`ZXUOj@wFz)|NeNj+<@>e5B%(RoP)2{lj4I2*}1G=8S(53 zp|w+QJ)d=UgkwD(oUKiDcGN3=_TD42Ie_qHeuTp7ErXtLOC_fNb`yZ6OYd`pkoKthAj#+AEXl@G;^0BB23h_?r-kpZ;H%}Yw7u*Z@myA) z@DOv)w_m2Nd&#~J={5j-+-=i-Cus^!t@xi`UiIaN;(9$?u4Sr=f;`;bww#N(x4=6i zRALv{@1_Hs4R*`4LV2xh$J=06k|BuQ8zbTC`m$Yr{PJ&cfgQ~@yC$Co_xNPeI+X!}V)ZZanqYNo2ZHhlYf z&7{tSU9#Ff2^~M^zSvFt3u9^0L$XnXeE+bql>#Z$UMErhqIhbm!9)H2u$X?uXsNyi zKuZP=4`<8Y8oa%)ytazUbT^;WNNwNaax$5gdS8S%cGv6K``%^0}S){8pg{4zd!_k?8nyU*`2 z^xN~vp@E}7qxMv#ySWWOeR`)@$3ljTWs(yBXC&+8zp{_pbf5bebP0?b>lddf7#P^} zUuoTO4S&4Yt&#uqx~JPl_DftH`pyiPBF?~_VPQNtz>NvN*1r8jc2Z%#^vYSb9Z1mt z&cd&uoc^_CjZnp@{GH63E=zt)EMU;(i$zZDUf{3$s_)P{*9K@}Eq?PRwPE$&I}Gi6 z5r?J}mf*a$vML7n&iG}9Su~c%z+xu;5oTtw%T!5gTmm=6*6zwN<#TpRA_EY05bxdP zPcQof*G9|v0pB!wcu8?iHMsZJS6MFuMwJJ{oaXs+N?ozSArGh@Knd9{ zlFB7_M$II3MN{?l>2n%lU`%n+E`0!||z}Lk6L3lSC+<$DZ2P-yu z|16j{9xbjamQ|NKlkdu-`}(F2%wT(GjtV7)-c*|jSjhM-+%5K;5u_-Nsn8xJ@rl5FbV9q*|(qg@hp=!rxK?AM@ z5S&r&%e$1c5^i|}5-1PYyCVuD)nKk5n5&s=_~veZXB5R!?`PJGwTLNMwx=p(ZEx&1 zrzAz3zu&x_))|Dd3Eb^7o$f}qx27R|w&xTQmpTp&J1wO{1Ipj(wmr>}GD``KAn6;g zvi2l6&J9Ac(cdZ)&*#kfUt-BM4NMfo#pJ-?SZ%VqiwgejTIgTAzryurl(usU+36$oizUnZD`KCZkBlR4dDwwLPmJFmH6$z7Q~8Dd z7|tyATAg|OX0*b{2=^BjE>V06f5uvn%Y`1hX75s8lEF2uSLi+y~@5jH83S`H#{Ud5)zjJz8_qoPFNiWr)oq$7ExGx(;Y!G)+>~!Kz&RAgG z=33BVTmbj9k6D5Xl->(t=Zk-*#%&&P*%}PIP-36bgcVPIt#K~*zeuWRInf|tkYIlQ z@M|J2DHJ0MT8fjvy1w{v!fg)-Z+9@^m-8U_XgmL%!)F9=5mgMlz5hPZ@yn~9{;FVx zCrByjCqZBYu--d|JG7#9F#%vyP~(u0Is4g=d$7la+?znqzAx2c8GwF4vGYqmdI)?UX*`0DeN9U=PpFAy4n zaQ@rk=IF(j9bk(5GML#p65E>z>>8R2ol(oHU*A+)cHpSz$oQc!m*y%z@aez4Dzq9D zDB%MNI~JPBXIve5brZBUF@so`YFuOY)4e6&xDd1poIr!lkL^LOD!g=*r2>nT;G=J4 z2@I0%YJkh}%(iUOsLyqsZe#~8EMEcXz>{}TFaDY<@UQ&i9t%hBZSS-e{YufS-j1&D z^y`kA+}-)6S$#2ZI^x(v`F;rcsP<<;vc*oAfw`9oaa(cMkLb@-NGKf123%nV`OCon z1{h}G;Nk`i(dEc3r>XioKy)i&q?E9H1+=zCB2Nb}dHJp-xQE$`bDv+>PeFhju(&ue z0@_%M0I+1;3uEHM1{#27BFF95E2>NRu2`KpF|?wub!})W$T|0?n*8<}{E91;5_SeNh$BlFajFNDV%`JCiy4<|9z&Ip_t|ie6Z<4A0aKfQ`%BzdD4Yif3n?;wyK28yzkWRpujE$+wm^3EL^iz| zyW3(YhNi$gwFDL<$v0M!qT88wIc{eZPNoQ$@qilgawv4^$}pH`;MokG_`lmq$O@>f ze|&(N7{|)~8PKq$!lU88WY&1frC49IKmTpbvw!7xKX}2mpnQ1< z8~{l@aZGEs%9EO;T_zNI-Ups~6K}L9_0UV*lxp~tDZaJ?w9Mp7hW!>cgZr*&Ymk{T z+isc!7X{$T^_gZ#J`0&&|4fEF+BvA3nf&*f)M)-88f#HGDr>`<%P%a{z8cyW_V_JoGPm+o9Bg z=4I-`_#HPFNFp}^TxMpH{;V!+od4P|w6!Etje;Lsg9QECoo7>L2d0^r`sOF)dh^{T z*Nj(ctv|R1R7_%}181TJ5Ux5>iCDLNGteF@LyVGOx?4D9qHmUM@TnybO&meyI?KJ- z3tl1(J_0TN|0^Vl$tE>TCoZtDSEhQ!cgT`%f8S zgcg6wah1G(wJQj6L6j(OYx)Cqiw#W(Zfgx7A31j~^_~twPT(E0BDIWaIkf_x3oE`0 z;))pCE^ugr(uL~hWL-rQ=&gGQ1Q|d}@hRy9m$QVcaQVy zSm|D||09|`0H_RzW}=q}&2nA`Sd3u!#~@2CgXEUcd4|qcB+G%HPiSJ*Ub%9yudbwE z@aI{_-)II^_`GK8Q*lz!h2>9~MqQ~!*GX@IX8Bs+_7n|xPNuJB5I6q!?&hrj`-kxE zZ$lGs@2mg=DB1k|CMh6kFgPu&erUZx9`|lsB19QHooqS@ue`w^_k~=Rs z$s489geyTMTMfX(M6-WgiXt46;~V6DDNy2&LivD)ZY0nFw+GPI?_z*wRRcJ8-|@Mo z@EI5UTJqTX`X)7*>ka}80xaoUZ-&(k0Y!-A`%aRMY*cSt=h~C2ST|kCoqN1x<3Q{k zxSY?cp2C-&%wx#2AUf~ivBfwV?ac++`H)xqW<8R1CQRukfm}(u)9}Z6x3lneF{WU~!-(@oB0tdYk_f(6^UdA223kj$ zmvIKYmcj1VDY1 z;boa|%|kdhmcrXdW97SGVE=77PIsQSW*_bzUe>tpoG0(jV*P?K>4U9jD5IGp)9~%9 zpKF6u^;?jLk+A@tuHO2?l$bO8jTM(Q6*(2~ZieeVja*!-T8v?GudT^FJdr0u`hJwZ znFjpL0<8PYG!pr^30Giv6>PXriAV~d*pgbX^4ww$%90B zIQT}mWW)XMg8uI3oJx!|Ql2F_(e77Cb7p^U`kYiQ(Ew5Gnbd61sq+!toyXWZbitKO zR%Bzxpc^`@g3`Frv-GSd_$&gsc4g(H_2Tg2bAHfheFWAQ{bGa#0Fg=%DE;ozuWQM;aN<=5MA+9Gh}VszhtKyVRNKLdhCXi@|JZ4q`!dnjpP@sk z2@#|P#76{h6en5Z60xP0?;9|PAtJH{oFQd)_wD^6mg_TY37_&-Ks=Q}lxzp0=dWVG zB%u$$?yQ(frqQ&v!u)O!p9PO=sWXabNawd{I?0K%QWn^d7?EXA+pk2qaeN~aS>~OK ze?m`6D^5XWc?YEQ(@(!3$nZJ}h>Ehbdtf=SU!1&RER(zqD{3&c1eFu?`{ej{44yFS z7Adn6OsyHrXyVZzvvRl$^xe^%4^TP#KS$I~-Z`@M?wu^1y!$M&Wev*Yn#(d7Kl+Gm z-|ZZr-A4$^!zW~n`M6}PTwH3o;=c0p=~%*@QA}F1+VwA7pW5JFi?2Y7+7B^MN;D~! zUU6lVF*PlrLd41Chi&upvw0GHwmRNjo;L}K-oxw=Q?SmGTSaCbFy6t9qjSy2eT*ka zGpoykDB_~XCxqzsIxq36k<}_oP|X=Dp33=d%PUSbO(qP7)+%G>MR%@)Zy22C-H#sy zZ}6=6oa#=F&qRwCOH4FG;5$ zdoD9g#(U$Cr^=gDsz7%~Jl~#y$@I2)L=5nTx+w_I#ddtT?i;@|6ML_{%zy+%v3nq- znEZ$u8xKW>$cET6i{wW{6oH~{b^Q+8lc4)dTE@Orb0L>bDKpjII|f!9ygp@e`759! zjIKas*NWP%`@QfURgTmW)3wx>J<_Tqq`r}Nhms;8qMek~JUGefEi9Y`K#P;eqw98h21B*M#GLB14+G7*>vs1gsP7!hTPw28Fl?dL^b1CC$ zrDlm`s-4^{Wi$JJGY7ZWbfnaS^EYP&sM&*_2Uo5lp)w=KzSorPh+_2FbPhTj=ZF;a zUU@olUpm+LyP_$R$h)HDs)h${t?E`Gu5;gGZuR3zhkpfiTntLt^ac{o(Td;~*w>GS z(%IA#OAhf_NS;0sk0h9>aS{ITq5_S@suF`<>Pt=)$X@XgmAKbMdYFgUwZo=!U!DtW zmyLwENQ5mv7RhvGkngzM@X!LX<{LaI>=zw4y8{ zC&6a{JoBtc{|ry1B!Dn5qA$dK`R2ts&&zZ01ZSSoM&&h-$dp2!KwdZq+8ym4l)w^h zJ|$YdL;9VpDmt)U1;t@^up4HBzW8NvQMB^ln|L0HHYNl#g_LqBYqK8G3fE9s-8h7f z#f_1zET1i{?|e%5YvkCYfFMXW$0gs0CtlmY)o_^CqiYWvPhi(9F(}oW*kjf;du>$l zV{DuXkjPD*U;>N4msi@)$C(tk->k^U@PQ1ZPu_f3?lkr8^PcW|W8lOKW-lNN-RH}P zWhl9C=Y?GQnp;oP(=Gql+gJn$;B2ZK7X)9PE?SBNpP%7v(OL9-esPXQMF_Y`P>V+U5sH!|3MWPPnq}@uxYskl%X&1!y?a7? zn0&v?eFY^^v#ASfd4h5MS=h&&2Wr#3_?^wz0WK}4?t!NCzY5`IEcs20xmEZNl@CO5%F8U6>?HM0_(f7tA z?!j^e-D5V5H;KBkT5{^*pIdKHd5y@4j0(!$ggG z=C`*+CSwA60O<75WGM{vrL%r0-}+t@jf9m(E=i`yAiN%q>219P47vJ;TIZsBpIOM- zNoJJzGsKfv!U#eBdj3^9>K9Pmzk;KD-w%R#@Uwwtyhf*3o3Y3`f<&)GSAjC9gkJJ_ z`|3ACx|<~x^AA2#whu1E{)yUz6v%6YIeyzEj-VT!LoaslQ8#@m(TOccO>txzw*M$D zAUxWX?Izf4%BYLn;3~Buy{262WL(67pZaJlc2tds#t=g_32{EyI5hC6;zE<7+Td>Am3e5%@XPu;;;P ztuk0@T3XPkoyvE|6qpCfsh_QA0zdpsYFz^mRJ8`EK6%mIRZ2gc2~=(N-!3$+e-Ls> zAB1I#&mI-;uZ8SVfL5@P;4=vi|!E`~JxhGe54@_JyMWwzWMroUqeMh|t7qe`~ zLWcyF-A!rNH8B>V&aNTz^<_lcHpoFXzyM87o@jh%)?gKeoGsMMyo-RZ6_6t#o_G~3A@lPc z5k-m-2aUwSVQewLN0?k?-QA1YSzP`SM))4aof>?qrlHQrg|)K^P{l~OnF*y!T3}&N zb0eKySEw)e;f0kTq{UG4-&a!R85+)O@qU}p7_?KMED|&&Ax18-*p?*dYW|C={bjM@ zsrUUHzr9W!LYe#s?RLa8@Ti%t7Th6cFxlC)U-7V3*dg;71{osAud+R$psK|t?IHC9D@!>{wk!59U zyXqyq;VLY%S(FX6hD)DAw;2JUY5p(EA!LP^W3wiq_D#D#?H_o5*xlgZrZ8yaBELZ) zYgpmJNSxpP@LNfKj+k#(ed=|L28pArcX zbwibj%~}r&#ms)0Ci`v;fSo%9|B4(Pk@z97ee9ytb;?JYEmYI&Y{6ud{*b#jX+7R% z=oOQwr~WnpeIkVh>KFMYWty2%@6D&ai#?LTvLe($Lk$oIU5MdWGw--PJ4rn>;o~%kG%D%(n2;i#zF((j(r3 zW4mDLvS;!g9hd#9uzhBY1h#aDkjyj4GYATT1Ws6rgc#a{h%D)WRKZlhslC2;BT+Jm zhyiV}hn+y}0LWKB&?=PPegC@Wb?=YcnWJwUfXH}X9Pw$&@6$rubrgDU%R(uIicAu4 z8(|S|GL=<+*Y%EevVeopD{c}k`u)dH5Q%>^;U%YpN8}9$IkjiRS+L8Z6m0EM=JuGo z*-}2wq-Z^+rGmns{U0gpfW24my~c86fH=)Hyc)yjU7Y~OkF+VT)w+~KV5 z?DWTq`{|K;gPYY$)22hghNF$vrKc;uGJ}6JwCD`xxq_aH{QFKJPoy7?ay0<`_9$az zQ8{%b4s^%9klLt@^G)xCV$|6V@Usni*g6^o&E1RT4>ZdJb9z9f-wErI? zvoP!dqOSVITMj=upX5P50tXsu1a6HbAPNitk-;tY=-c)qr|7|#xYqE6=W?I162hG$ zIf>F}C0JiEPgSmekULGV=Jcy(J6Sd3*y1L%&ZO|>>aj4+3jN)*wqd3N7)m3KQ-7w@ zwUecsz~(h7@1VVPBa71U?0a!=&o<6@?q_E3B&b0Il`wm+kgvRVKfa z^Ne{-9mI!`7QwZts<6LiO<;i6!pmZSeCE#YE)MWde3DxRB!)_ zexld+$9>W(D4SeA(-C4g&+PBDs!fkyrxAeuw{7@6m*CWTke$_hC@A^+Yuw1gfg%S& zIFV8kn|gs?c>t}5P2|#0w#h7$Y`{HmKH|%4BS0;(9B>X+0k&@>UlI2hoVig5IHC+f z!f)kfykI}Ppc8x8Td1D2w6j==Oj>&eVQ&w4I9ARN1b{CJVsjy18oeGdG9*2Ut_JKp zFEQQCctBLVDY=HCn0G`>2uwwhymy+Y-UZyR^6R^Ac`kc5(ER-#`O2uG+du^Yf=cl+ zx%;w=^(~hvF5pE-0lzg~syr_Q8`B*qnbSC)-;=u}afxV{!BpnZaxmXO6f~?GzjH_+ zg38>3TVU!gd(HFjn$qW2F5zIg=7R|k66N%+8Nh_HdIH+s)k^h>_UU**+Y9h{e?F}Q zL6j>J8)=sP?gO~e-MwMU1?C#^gUxA^Th8ALbBV_y-InCXJES8U`AurI#$fxp zB)ObVb->l{dt8(8Gd)e@YXvj3s~?RCG@EZG0rF~%l)-IdG`dp2w!=FFT;>qDPSd7eZP>4M7*2j*UA{ z-_0P^Gn^YsDt!0eO}XDGSVM>E>NolBY!`7}cIso};=UOVsZ5l3Y{jit7zrv(6}UYl zsM@BF1xzD}2Y5#VP(f_A{mDE}&~h-P${-+<0D_Z)RxYS1C3wtqP`G~?G;AGsG2kIx< zex`(OF70KIJCIirRP$I|TXN@%a=_jrfD8b&fB^=<)&`LQ=nh7I%Ly$4se7{aObe4A z16saHFbV?no3tqU7;lArF0;mWo6!%JQPA&G_;=16AbNFRyba}R$fp_qEx5B!;-E!K zfN{{p>Fgu_tL?PEtfdi{0@%a1p#RAL(DX$Gl+IbKsw9-jR~`dHm(@u+%=2-J zeAmCOCsvMsg;Jlf@rb^)do z#Ly|w$tXV>sfB6lzN6k$veii_E@qjG#s7?N2CwbfG`d)SB9E75QF zgAjEsXY-sB-oK@f7c!ZaN5@DDy@(KXUtvL z>;gC&g?MFh8GME38AGoq(Xwl%7(Bing0scLxsU#_9$H7aQWOhHy)Vvqa3G2uKSwK` z&bNiSEfE)(g5G9BEyUn_jT^IF{8q%Hr6aH|e>UJrdOW3WXUKOU@sU;HS^X(1c%V9} zaKjV5=^F?;V3hIIon^g0PrHOTzDD-1?j4i%Us{>4ZCcz_ZCw2CVS8B*QLJq@B6#&{`maS<3pV1dA-l~ z`*j@0^RUCO{fLJcwx4ZmZ84-^-bRW+d||W8OEs3aTa(XbH^Oe*79lx;M*bWey*NBm z!0t_I8h%jTRP84m$_f+2edZ9maz9V9{ElSFkFCGu7(i-bhxPcolP^TN{_cqs)&9HXuIF4q53={^NNjzBV;EX{?(_ zH+iPOfzZ~aN#5YmIS3T|fnhys`^%IQ8tMbSl2hd317< zyWG#N2bjoll{1&u=1>B}EcmBS*%A#9jm&biwfl>r(rk$(-8Q?-hZcvOM_(d;l>1X> zM=V;Ddf=;kdA&nsq>5#NxFI_bE2q8ES1ZSbm>qe<(4;A6wI$J*5CWH3N9IsGrW1N+(ItqlP!w|#1I!Sz>W44wvjlXC*; z^Z9h^s=HD<-fq0LBqNd8Wj5D$40ZcTf0y%WhxxbPqclX6RJ)(Cp|8n9-k>?09G_tB z!^>+R;FRexs$)inD8CEYt!4_8QW`<@entOGsGesI5f)W*Y9>4$^5+grC*=3M9 z{BYL$I1?KK^~bYc8>^_5N}{&&w=OTmRAFAmfNZ!Zd$g8Rop{#n^s9;&t9<2lh{TES zu8GW?kj+6*B;nfyAlb?jmF3$+Rq{iEaM^rj#Eu}*^^pHZ0d5ZC&;=Ax#B;O8vDYE4 z;7s9uW6M{_$9Sy`foH&4L(Hg%5H6&wA*?yQ%33?y_~oY3f};4T=Sh1Z4D^1D#I8Pw zPPsNYGjyLlqcGpy!XQK$F2EqR$w+1*4JSX>T6B1R`?6NTOcg;#0RDoE=FenjxKe(U zoQ@FzQ_Z@~-cFH;Yu@tr$J{&aq~CY`980McZulQK{y9E^aK!1Iqkrg)|2Xeqx8R#1 ziCfIXbi^Wk{M+?tAZ&dy0dKwa#X8Gu?YoKqC1;IhjWV}Zjj%rqCdsv?M9EZ`GvhyG zpPAy7j4YT{<*}2x$gw)6KEEt^r z@%d*oGOsxUZ7);T)VnsHl@oP|b%|>fbTVZQ&Lo>IIh2ygT+HtEm&P#--I0mgA4AFG z6Gyk&1<}#Zo?*#;+3~Ar1MdvgXs*ciz2%^H%1<}m)#IH4k-*>v6U&*)0!L@#`0 z?og$oU2uV2$?QSOn(C`WYI4tIz0PSOx{IP?XUVN)z*V(XSM){mQDtq-z%kW=Tru;A z9ox{;5nK4Ab<%*HwO?;y*NCFONo-%Da;FWW^zh<}>l>5UYxdV89ES}BropbIDMw8p z4&$89*}^A3WKh_@oe;Pjy``!4)_BBDMermlkPuOdZdks`)Zmq!Bk|L#aocqsE!q$y zr#j>xuNY@wr`COLh3*s(wrLi=_@Sj!Nu%klVT#pUzrZL)J#2+=%Y;g}{Bcvo^aFp^ zoLI1y4zi?hF-o#^vY&~%-}Ix<>&R``rvH;(f_t#FL=^M6l3%J|QF@6yg4~GzuTM^Y z7kbdrPF!s;i~u?X4{J7oWb(Pdi^elJ6Kj*o6qj+gWQ(hDgJ*-X4a*)K^I#Zk!Wiwh z;W)1iQSZ0SLun_wK!g+hX?V$_+1=m2nv6FCuO9}V~m{A!p{ru(E3JTEo z)O#?+Bc?oEfTi;MABv_+B<^leh3tv$~@E%oz z5k-a1DGjCvcW{&SURieh+pSLU{I@c{W(fY^79g6TFu%mrN=Ptv5%1%}KZ0oezH1Wp ztc8|uwg2FbNWp&QrHd_gc&GMS?A9nWyXZ?D@80M0V{3Og2tWAe*OmJFiuh}WAxrU3 z2D6jZ!dh)Gkx|k0u5H0F0MY&SWlPZQ${(4W$#veJuA+#wa62(c<@NE&0qWb z91;DG0TGl{-v7)m1d>Hin{arz(c|7WdQGSR^Wfw<{NMZmEBl%9uBdC)Vp(^^GS0WB z+#Nmm32EUIa8N|dphyk8(m^77OoZi#NZ& zmN?Bz`k5E~t{5H_8#!QX{HQ-$*8Vz0cjf-;JpO#K{n*8pE2^)s-bprKl>E!{n4-U7 zBPX%!>SE1tLN7f^wo>vPmVcH?84l%IR~|^WBNg*4TDf767!CS`>!(~S^aI4JIILC( z1FFuiXz~k@dV+Ws;pnr3bKAN1dli0bH#tbGXlJOQ_BN(t(iC3I+0FL^5CG5(Z_&=b zwzIlK1pk?O=}~KRqO4P^K2Rt%J1_{`~r6 zD@jNhh;<)+as@9M7tU!@+Fy_3zi8~a71MEM9U7A!#bft#8zDdli^C_T=fvXN#5CC( z4nS+ODv{AY-t1*HY%IxCd!06GXMW9QJHjZc%Ia$HpTC!WBC@MisJ4nx^4fpG2pgA^ zql_p8bmppC+1R%eaUKsj_H4an%XjH>&$l&W(Gy{bNYdX3Xj=1bntb~wypy_|FIdsF z-~DSlU4rt$Z8gTv<&r@x5YFh@2M^)(^_k|+jG`_xjw>VT1FXf^R0Vz~1-n|8lcbwt z+ztgtB=%fypOY+^4(RZGFWB|p?Z6OBI=R9KUn~1DEu{|$lhmhVN$~XzSYNg33lf3W zh0hl)LVs(0Fe89*YUquPyZQ12%?THE@HSU653pDpv(^L!N#`N2Uy1{K2F2eB_&;8G zG$;e-^-o)y6*s)CA5;AaK~}**Y5u6S;x)KMBu4$NthWmrFIJdBCWnQeKvKAJFRpx} z`@)|7Q4E$5b@FF?yNX!1xkO+kQ2KI(htc~kxw)H;#3;X9cAM1GshKXmI{79GWh}!J&f(m)LGk_rVRt6wNowRUv>3-*4K5NT`FSJ>tPdn zCmc!h~jFJIl z($7`VoiSykQ&k`NW6Te1T4rafB8DxhuDQQhS{pnL9-aSK1>nk)KXyO2lMfX887e+^ zDskjglp^=3xi@t_YH9#PIgH;dS$zk|Bn;}_VVIM+;mA#GgvXdm`8K?*K-pYP7Qy(Y!a+UYzG<&bWR)3?X|3a%W@%nB>s`1O9!6xt!>Q&K3D}GZpj0 z-Q4g`cK2(~TtJtvo|-V(17UYT)_3rk%%uEls`kWYz(49R4^??reI-ma0!fF1qNde7 zp{rN=*V{~$sD=ce__{8BiA=BI(tL+Tl3^+LZC(|M=el8fhr-LA=r6@e#nOG^?FIbT zB;6SQtlMZ9BP;LGG!WKfl6MI^3BC7Pji+GdIBxa#ePmPTn%b!A;&Pi6!(;LFioMA& z-G$1n;n^I3TL0^oVoTuCgW`*xbdkjQS zS~1+WyQUgPf0bnt#0FDweVRs2oMpRp4DqC^m)AR`|L`UX+eDtDZ28F10q(q8<>NRc z0!IFxj6#M%>r88ufuhg^|9EWaMAlUCWVA|cTzVY^MFY7JWd-V`KNSSs{ z)CrFWp<1d|^Pt=r!ekk(z~AhWy*hDDI}?1kx;Y0u8LHgtNg{UW_1RVq7&hLvn*+O7 zB#WNbd{0RfV-*bY;w7zOD{a2#XY}Kz&VuhY0m4ipsrnv>=n62GZE>O>V#}cd{K3Sp z3tj<9SnVGW)SgzD+uJvmR>j)%H}iY7yy~gnSWBRuuRX+4}?<~l^FzRP$n15dbgisM|D5!On8CRK?Bxi|fwG)V+jfu2>`Gl{TyR6cmR zr1Kty3E=AgS!l_JwVod}C;Cy72w8m3HdJlp*JQ4;(0@eSYN{XA@bcpQ0HO;4a>MWM zTWC~pCjKaTah~hbmRX5vT!)xG_3V0uVgcqp;C>$$duUu2kmifgef>OFtMx|fGlAuR z6|6Ju8{Aib(_(kIWPd*v+@=6fT8rv|LEdUN?cpKqbq$i0X;FJal^ zX5{y*M~PSH&eH?tj@%9cuE(s#VL3ZQEJ)nP+x1C^=#g3QSjP?(bhsP0Sv#}_sb{N& zSXVB-FZwykYjXDuq}Dn;KO0Gmpf!F>XPVD6{~UL(qu;042bKJO`OXrC#jnE(%z6uZ zRLWSc2l#r)D>r`wBud8OR0x;jaumDz3&9^eOKJysRb+Qof7Dr|&cYc~&}l&jOa=wm zNi}SyGdd|d&n<0nN6}3lVUbRjqm>o?-dHoT7icK?E^DTqD}+&eA#}nw4*34gw^+Tv zD;| zYU0vJCp1%}Jk#iRd%~O-` zFinpJbxIkg(>kY2-ZfjCO>I*DwwfP*`F?;|OSB4jnmHiv84V9#3t%Rl^lfc(vCi~_ zkDYW6l+7d?yJxZH6}aDPbl81zTUsI5Y45ey+oX2~Y;f;hx#Mj_m2!05%Qf_}gwW9C z#S!o@Oo7~zKpH#^v19)gGEuNYM_`R+QXgf&2tuWmV^p!4VUY>DIS8VztY!@QRy)u4 zWTZ3~Aih2s=7xzUfw5qkst4fnwBy8`pFqgNYd2x^+52L!&R?~uJ|i1Ub4KKfvbpQI5&(F~9CruHGgI63~J*y(_8mtWFpxb0Vi&jI0Szhnj#FT&ZdBV*bcWOD%yPHe3Z!hYy$R0VXg!vnRL2R~1@^~hLOqqC48EL<#- z?%UC(^)D0ef{)kr1p{>TPgDh=`)BKrYJ&zQWomC17l(spI=MzMRplWMt6dm>RARBrgEgEM4P}=R20OFPlkM(G!p`0#K;FLfBHneolPt&if z<{r`xpXS>!lx+5jp`O|fLu~7NZUiU{AKy%r2Q`(|`jCrsu6XT;Q&u8BV3R8V)$5Hv zVupFX*e+hSUlOZ<^cGtkrt>T+)a_Ck^U`xAMNQ3cBi7_|he6CF5pjsi98L>;Zv5K{ z%&hb_@TiF8PH(iw@Wd59{-HJSl3r9R5;R(Ce4-$(GKka*nzx)k;uV!nVc0pHVvJ@6 z!Vk9d1y#p{_~=p8tUf*FuExo>>WSskRbta~Bh+oS1RkWjp{I7PjXGl#@pmY8E_vdm zg%=^@^gN7_HyM%!jCU{Y@b6fgtxC#Y+NO$jRgjr5QoMBaZz^{}8aqFTSFp_E+Wh6Z zs(c|^I;X%YBB*59Vs?6>=ueMzkp#n?0(ELf{djW|SNH5j+Ye4+%*W4_Y!Sr7-;=}< zJTgpvyW>msvKBFb#iL}Usbg_Lt}9eBqS+1jY1ezlXnh`{ZxG89g?e5f+T}MaO&?J> z{Mb20)WnJ&JnMSR2WJQyV8|hw5XqqvIi1Yy@@Ci14fW>tXqB-75-**|R^|6y&^Uug zUP;APXKu{N(#Q_lxjF|B(WW`sKO<%&DkPksaFtudoWdkv%ZuC$eRSpE6{Qn|W0N}D zE<757G@vge@UyAW^I6Bre` zcc&?^W=C~~E{5Ldc(*GL%VerpQH%}KF|XXtXt;f{dB5)ZotIZF zrWJ`muXsB(C7U!h>Iy8s9hp}YBT|?vu70P`LFa2uqdQ?JY7X>i5g|dbe*Jg#D4Fki;u4SUHT(#3wHHj~(bNsBB zd0PQMenwKB`)ipM-p~b7?jeG(5Sc`iC37-kz{e{t*JtJ+A@96w1-S2yT`CeH!|vqzayON8BzTOg=XdK zjvI@gD_<<`R6iN<{0k~RxOtbEK$3gmlLV{vSA!l*8$zO!b#r$H9=3aU{55&74Sa_t zb$w7S>moyhz9%zhB7H1t5v~xaBX$k%B|^S~0)s>M=l$f5Nj#4cW;GYm-$>S9((4FG zqM=`(WP(T$Y(Xf*4I+^WRC!&BQYXBDzEs{QPNR6&L8RRLR&Fp_IEeAar8SOCRk!| z;CE!;)5SM>rq6?&t=jxsNTbHd3i3-j=oumrQRwo_u-xUQKXo$KY8t9A;;1-|%z4!V z*Tw|DJgy}3morH&*hLg2^lNDOT{R`?~Ql59&8Mb%!`6; zb}j-G=Tzo6#$%&3YV0a;gZ!c=E0qw{L6;HNlkidGyCe21b~zh{96CM2&XubbN+Re& z6Js>->qfePiI%A{HCIIUH)mh5|7-?YokO(udd#@661& zq#tXIKhm^m0P14whr`MxruuD#?nPJyT)G4}rm0my*(8)So~vaOZtb_$pLF%Idi1SN z&oI`cB?X>JJLhDJCdIv49*VqwDgyVi-z1HPmacd6D>6=GHqyPAYMY~k2iI<2TjKs; z!@ckRP9^k`m1xpb&c5%i%;RLf)VMVSqWVOM2C$=cX^sO^Zme>e_hS6Jhe3z*bC%J=mTQD`7hj{?!!QsXW^1eFy0m26~Vk!teFfh&U3cJ0eF%Umr=ubga+ z>g4K7;v8D5o&7en0w~y7{VIKq21mu^L%Pt6@90OYJKbW*y#5`KcVA+|z64!8nW{W6 z{tW(#740M0_B10sc71`BW9qt6;S2_v^EqtB&99lfV;dlz{DU&{*6-(SE$$(j*{{w? z61}1c*>|&K9uZlg!h77dD<5=*A=Xcpu~AUQ;ZhJwTVU3}YskV8p#oQPGl{cl?y!v5 z8l53__8Otc9~V=qqm;lkcs);=h2JPRm`?BfNq}B%HdvT^Yf^0ZP2`PNwp`_8G)OI7 z=Zf;3j$87tMf$%#Kbr5#BE;3>@aitne&=_z_Rj9PMG1*;*VE_kEyY)Gt_--(b)mMx z)3Qezan0>{2Rg^%7H7Zv-jglqBOGMH3F~|=_}T~0;O&k@n}w3+V4UoivXNbq0a_U8 zV~9NaAd2N)k#f?H6_kQid}6=xS|{{H3Tr&ko7!Vh99S*>M(A%q3XMpS)qZ%EQUojB zk;YWUe-m=jHo_4p)P zd%ECCmbOY>n!^Q4GK@~Gfv^X|<%HF4XwR)aG&g0g7?)(+vUU-g{(N*k6P z5>ov4#s`JXsqG;yZk@{oFR61s(SAPgmCje zhHAxM;PDYEID=Ig0>~)sROU+Dc6<-Lr=?@)CBI&;J{C`xk^T?%A7dp!I=%cw{a7R3 z-@XO=br=(DQd>)~X)?zA#Dq^4he=-XKGeheEW$HPl`Qz5c{O2?S8HW>j;RRi+Qx}F zgZC~t>3bgtZEa(ts4#HGR-jaQ-zV)L`TSt+6p zitzq9nT|96eURajn4<52uS8o_^TX8Tf<7)bPQ$x@rsL!5$%4V*C%b7P`78{E3K5t7OE!UUK)O0>wSTKhL%^`1)i5A)e}tN6MNBI$kYTg@Wm3Ao6^+91Lw(9s-OBs8Q=8wY?VDCYbG9 zPe3!n{ZW*FJ<(sQ0xLU^FDRB@QuJ6PLuNxy(5!hm@9}sJBVjwYEJ`ogU{;TW-{_`) z>R7%LaLvs$ROw}Kr$Fb54<}pMBhVyS=`M=nU zax(Y?zbH{^=8i=3FR!FC8C$$jIULprmvA_)B$_qF3p_SlSS^>}ic${vb@uy5j$-+k zTo1{|8ndDeMIK?Op{dS9U6}k{1SzoF_e<4LlDTq<(fUjWpI!kbVetNT4_`h|+3ET& zFUC$|(_w!9^{?`#Hhxx3R1}i5k4ZZ(4bF1!V2;<8bwBWhL6 z2DO`zd!5JjH}D&kvO!Wgj!*wuE7-9!peF$v_Q6&xTstMI$*!Kn37hH-2^wz!>!HHi z5V?1Um=7-?&2FLscd+``@1YWH@XxY>V^!usXL5#-RFGIOHD8Yh4*);<*~(zBph?yw z;r_QH1>3gre?L4TXpOQw@@O&hI~@%6Yw6e7Wi7S+m!bqM2lIv2H_e*atIe(4M>wL! zYRuWv|6~H(0~=2YWfWz>s)p-HfMwdu(#G~?02BoUl3VypdqT7ON+l~LPjnn`2yWl~ z@;GaP7S`%!537I+lu0Nm$a;c(M{UQu?enrm%+x9GMVzDBC>@m`e{Xn(`E zKR==*-dfMj)T_C&tg%dpXV-ldVsLL~gJu~=3M|4N4;89Z)nPxghnUepxN@!7S@*A( zS$4l*t@twfp9P2Y7$SliGb0;pX1ij|eWq{Xh{K`Qf}mjLDCJkbhmYA4@$1-9laMWO zRok@|@*W$LLjPn~X_{eXht;DNGGJU`!ypqFU>1A0w~j3o$bibM$jw^PbglXq>q|wW zDj#F{AQ`9MS7z}souu=-HuPIyYgVFpbZ@`YNLjY*N(4rd4j@~;LQ$Ny0&7i$NRG2) zJNY|1QcCVSG8GPKRxaswoon@mUmwS}B?@;sc(-@2yn)#qsn>nba9F@4{e8t#jW|r& zYif=E-zl01ez!6-X)OO2vkwC|<#LoO=}r7%6{hA0Xur%iFL_ccH;qk`i*5N>R82?b zJre3H-Rq`ylkl64U{!or$ygT;S>@x~bC%z)N3!o}wnX!vlwDAPSXLP%m*V;L8hQ@p zXa%g3efW4!X%*eDrgY=h;S?aGY8%Lhxd9gidx$QbpjqzuO`_jFM$3{P5cC$47SGar zQy91n=3Zliy4T?3ZF+V2z8Q>Ku_|qVH;=J|G)N_SZWC5}Q>%u0_J>xYd(&b0bA!5q zodqGUOOIr3ClURW`qN}s^0c!&m}pX=+U665^T20)>icj1=eCX`574AS=4UhF-n5}i z0`5?pXQMqA8`+ijQ>U%D&#l-(x>Kr}_9Cb1Qz*$%ex`amMvV_oCE#%hTe0mA8viGf z>T_H$g~x94C^$LXRt(#J%I#7XHS!)X%{m-rE7SVmH2<>lujWe8Re2x;uMXA%-XrC z&#EfFyFtO`*y2U$c18Z97Hf03WY{_Jcz17>>Uy5}-v$Y9GnGp+&q-dac&EF=v3ZG= ziXf)Iyq#rUqHzV}LYQh@1o&G7B-G5dKj~o`zgp82Qd$6>B!Rntf1$FTnIXag-h=ze zw!D$TQNK#G>d%SY5;wVatZk@lIXIhfnTNe6&U|`}ySFgkH)jjRT3X_`9#{DN) z#HG=HM?@}R7{3&fN2C1A9{*AmbWY}tFH?(Xd(G}2&#w{F#?YW*JHH_I1)7sh8Z$^+ zyD6T7-%|}1X{QTY5O2dCv0pJh~$@Ir>D5Zv^fo(G!|ZSjJN2sw;Cwtq77dLy=- z1;qVcB!9UlBnq<9kSHUjBFjlpjX}o+|8rD2!4%&UJN;T19&EeR=n!Pdbf@yyDWXmKLcLi_MN0v(2UiGi%XkbXP>_Lmz#GltF70n5`ZITo)Tb_Q zd@W|#lyEz=q5X37&TX0Kr<>eU!+oOwn=-B=VWT)N#-C1m?zBaVs-C0Xy-uR8i?X{B zmvP6L+1TVqy#IKrBwqW>rW&i3aK)0ma%-Mm+RGp_*_#q8xs^JvWRJM}wqOV-*gW?) z_mlUZf=Cg+sLB*(J0*Ym0qJAVRF3b_{I6fv1z^MNy=?^=w)Fuf1$N&T=^sFwP{^%> zfa(1;K4{|d;mbxyUMT&(=CEfN#jxJ^)jj>Eh3>S*(st8I!m{RK#c@D+?_Ta<_P9~! z`jdEv)f?EK7Y7Bi$qNfE0G@8Qqcpsn3JcK?yCMy+EH<8TXu^EX(e26PcMxz+_E*?9 zvc}x=&MTogzLpDud==efkQzNxM$NB>pg+LO$g=N$CYV0h0R~47r<}=rnql+}+(5mv3}U%(Q&dyY{*K|nKH-4+*+QD;syw{od-|*nCj_iB zzcQH@sL>T1LLek-41T1ZsDc7OSg?t3DWO1&qx(2^W^`tQx5L=o2UK z4ZJ@XxKoL(?}GQiJM$jeOjvHwyy!z_59@C}INS})nm0-1&kxP`kxF$fzB9;gRP)D{n@DGIvLYg#dhw}8TPaW zRD(kVrpX;+2qpF7$|9-}4+8<7w!_`FRzkL3pV#L<3AE5G++R=x*9x!RO`1uSi8OFG zRky_pLBg1%=dBW{C&Oh^`Q3hM($UE>=gFt!F4^PQu8n^cqMav5?!1SvL}Dp+8I2aY z8C&_PJ=RON^t@;E=gapK91Y!#Zqw&*C2DwbN`8GAF=R!e{MJc7W1?lU$8n}DKVtEq*3_tQw&>UxqAy+8^q{~{oys1-8D5~LVca4-yK2$UeZ zaBJ1%O>htduU1$2(oW;fI+@EtdB}J1ASr&>(e?mLZIzD&3Q7A7z|Jk9X_EvDI7OFS z5m1P;e$uaj!<*%BzV0gI2Y~Eq1iY$Gqg)cT z$j8RFnd+URkE>nF{(cPD9I;b_V1;1qRQ=ad10E9IkZvsXetPTpU=o*H;_WLvK%u9#@vZIprolwc9gEtne8_IGUduNRH=R#pih=%qs~+>9)Rt4_73+bQ)MPX)gyC_ z{JykAhs(;C3BKJxQD?f5OXHd(JAI^AY`)Ky#H9$#>+Q{eebi&rj6J<4w(<9B8(DYk zRyH3}b}f3cG>gYmIPGdzN*Pl7j9|@mL%KClE&i=){mw7Asp&yke^2xyC+_87DrZcx z@zj^>gK6h>=jK0-hX!uhRqTI;kHe!=M3rNiIys1?e)2B~cgBcW?OYEg<}u&Pqt9QK zC;#E`%_WyNqH0GC$E}s3u}$#HRw z_$eyfead~VeX&X=jL14|iS_b9n>&VipR^_Qk6c%3&iLKkN-d54h=Ui4e_g`1|85sd z)tq6E_h)6YV!djZbng7ZpErDYmahxuq<{+Vf;ze|c3Y{d+@3k7=#Fo(G%G zwvks4-9>Ji!?A9(5%oUR@pz`tGblciCy3LYfeaou%{b1f&6|g{q4%o4wSs7JjZKMk zgiB_GzNLZC$CnZv=Iq75u{qXWd#d$04T2lPi?ip5)Jal01ygbvV??LvDME~T1x(Y( zCP-WzSG!D@38TYyh?eR^35HE`RT+G796&YPs(`F9RQrKISeKK?1cDPgyaq7ZU6ml=@R!Osf4Ln7k1O2kMtVv zSr2Y9;g4H;NaK(ZMkKDBG7aS+opV44PnTvzEq-*_HZ>mj3x%QiH_n8%Ca<+kT zPK%Xe)ehI+i}=#5(>9DP5{EV?A71kIrYfh;-%He`5@Mv^&+Rw078S}gmmnicOdK8gce#0ieH8kF)xc=3;G ze>UiYx7{y)*O@`!LPzVHu*#QDFOKIq&rzlLwz}53%agS<@-z{kiOdKZ(eKA&Y%d;H z@AzLT03N`{%+QTTvR81>704$B%9J(4C_0~Sm;oY_`_W-8&zS4)QGtew_q;H3qqKU% z$EpsOAR>V2^enMFZFF-#1O~^o(`|`+u2LI9^dh;7a(9w@&G3l0Rrl(&; zIUyf9uw!=v@2$&_3wYq9&9%HoNxoM*T`o39wt025p6z~K%`hO#v1BOaXKFvnd0wT=I7&U3^d4=uR44Qbpr45mPr7dClIM6l0Lbu(2(F zPo`7!SBa(2f~tFdsD1IZ{=D{GzCu+4a<}3zgu{9}L+w#>#UN||Imk08zWNuP+d+vw zDZVYkn?cWU$ZRW;BM7_j)o42wj-#`#@5)zASSp2>=Ce zctDqDBiUN`!? zNS_diO}i(8yC?=w1Uw@`&@U4197NA}{H--`^)lU9y*F%eaj^{qxfdnwzppCFq&89e zl=moWAfl0nXs0FULF%+!H!3gTQPFht6QL=>y$E@P! z+BUPi<_li$^Q1TW>RlUfMm3z5=oj~?_AS@%+mXn#l@q|c^8L>wVFpdAMil=zYRdk? zO_EuAf>h7A6EW-33E=w96@WtF?&s)=o(ko6Y>4p8-mJj*?9N=cJi!EXI|8;{#>qK#)K2eUOqm{KfG2AJJ(WbZ$uG`MMn*A*cJZOpd7nH|es~)LBM-7`std3UZ^?BzqX*v2g$9I5q zlWtT|iWMOET1SsB=Q$<|S~3~G^;%9!Ma5@;LmxssmDKh(LhOf~_I@%N|NnO_1b*eK zEE=ykGt|t!l_GPZ?kP+eJN~UdcoP*yr%o7miZQKR^dX3j-Ip13*rR6>I)5& zl6m-frY%#=Zr!xcdQ|rvk9XW}#j-nbb3q&P?_YUxcMBgf^5q4(&349V60)@Ff)ih)g)^jz1)4Zh39U1?kD3aqwU{6SYh>#!9u%1Ur&F!bhng&M<>@ONzCaw zO#aDOeHScax$Z+eNmIs{B69F#DsvOE0E~>xSk_P&lQfAjMMDga?i7qY##N6~LqY8D zUUnm45YzE)JzQHImy_%SGS*g6$o_?s2eFRhG!)5R<>PiU)io~!($_8G(nU-)X2LlgwlBTm*D4PGRqCX=co)li zay6x^Ic;=xB!HT5gnRjWOzq`mksZc7zxzot)nY4xzw#;@ys&e_r-vRZMg$$mO-xhu zfeu%sQnY_~)Ws`x8@6uB3Bp$FOl&vK-)tpG^%ei}JzZ%VPKt!U4`;+E^3pRSUA_dEAV zPjZxa9DkXhfxc-{ZH%np@Rz-xp>`x4(-r((e?JK4go8SVIp1# zka)edfVovwZ!TElKRc^s-Ts^axx1?#^Sb=TmAue{9>JpULOIX0o(*OW+%m(UvmW%l z-`$%{G4Dtc1*L2hlk+!^hLC{9@M=0GhxN8mu9w2b5n)9}Q61vht!)%V=7YX;J&uzK zB|sC=bKcX>%3UX~v_1+uCn{T}TcwsqD*yskf z!bjmW#>YU^p(z~YXAXZY2##8;?&i4CuPzr=>a@sxQYj;P;00CTR}S81y+Ep85RPnk zc>%<_E%R?a$G{qC2=e3%6SOz$eAl?&-{?y58itlI9LplDgRDddl82K6TD^fT{3Z5# zkp@%Nva2n_wa4$J?!kpHD0Q6w#3;!iUKrN{gZ|G6SJPcL9snM2)*6xoeeaFbbC}4$ z1Dq`AIEN(OnV=srQm5BVMZ1>lEEOeN9V(A#Bq^Ug-$FYhIs?|*SjgL5SDtC>sc;vj z>=1O%F41lz(JIkWz@`)mkBVQu5OSe++U6x?5R|`r#U^{Y_kpFvY*U-jlStdyaR7^H?)q|}^Svpy1Qs;#q4Ql$6%VS_kY66dfqtEdV3oA)dPv)16ka9?DDE9+PJA8W>IcaQ4{7#hAzwMbT4XKcR>-L22 zSioewxJ79H^R5pB6b-8JJsDHrJMXE`*QLyG3EQo8T5IvUhPquY4NUQX`*zj?IfhY; zlBLq)){}gjg-^b>6!5i)2U<-J+159H#2;UTnw2hFA$h^0R|XD5VqZ+ z@;pm3u zbxi2sy`?tgn|EsQpZr{qVDQ* zcjv!eTj92D3{2P3KS5-yn=W3h+&b^yr1fEoOXb=2&HHcahW?FwyW9e^MHG7s zW`>7tE0!t3jgG%Lgu=KvL;PrJ;&rOvaT7yU!FKtTAGWe`MM$^RIj%3iLwLoV6>b>i z@WfRmpqOkbxF`npOXXgcnH}GQvGr{Y^3c!PWwBD}u>!icp{>XJ z`$xV*smZbPqR&o0#;LkCVj4#`qmiNR0&gnv(vQYr_C92HM?CFMA)RRg5Y?lP#w z3uYW|lWWDaZX}8T-pY`@ya=GX3-Q4g#5EmI?p-KRmnxM!Y7^Rs`q))SRYA!{fJl08Fm)KOdr!`XdycEcP9 zVx=LogcF#Lq&3&2I>#8pqO%Q4AMR>HjzTABp{w$Ba&Vwq-8p$eXZl&TB%)4QbSYAK z-947HeP2xc@H7hXXOHIIzT5Y?;VE@E z=IQyZ;eN~XVyZgQY1acmODFy`MC#5YpTd!)T&%d$@AoTE;lKxG3@`LOLiym2=uTib zYnbp|eTj^=D4t?_ta6VqVHy4(kg9 z9j{bcNMCWQUo(yfSQNOv$QL&~IE*#sdY#dWw{%lt z&VB4q$$*-Z5q1Vv^@cW?gkM)M%4UWpXDb&hK+E9#u&XMI(Bo77B;S6#iucC1JEd4;n$ zG^DgfYlS8Dd-*T4rgl?}Fu6|K5+M_3rzDI3g!C{BGFR{K$mug*Q$R?HI>;l`vl(^+ zqkfb&eXcD5RWyrH3G*J+$DAYzwWULScPn$cHn44fLY-rE02mT#A&{JuAUzBcb+O3U zD70RP=DLL$8gspq0}9qT{ZhVP`dpfP0K9fYPThGll2X*7$sal+)6zVXK97P=_Oxk(yIBwoT4tdJGWEOhgp|yzuad*c6;@8 z5@1_NA|az?m7=yReVqQy58p-VTQ8^c@-OZS|IWhP*gfiM9l^H5Gz~`&mQ$=!?%$RXLa@pKWnjkJ>!n=B^!(YYYEvrH!e)eW%yVD{JEl;| zp9BYjN;7%=Ro>vhZWw7c1~a`ez@eKXhKgPF?KqZ$yUdEvd@yAvcvh7Oy(z?t(1jvh4*OA?xs z&2<(N*?cF@!9cb_?EhiwyW^>T`~Q!Tonvpu%t&^b=h%hpQ3{b25<+rpvP<@eIE0MI z-VU;7MifQ1?0xL;yUwT2eczw^cYpuv@#t}!^B&jrx}Nj4mWf73v2u>(lA^xzC!{^% zd3Dz#_19Be?~l5Cxjj0J%Rh@h6$AYgAc_U*OF1PrrJk_!w55*_hY+Bh#nCnZxSVDP zW_H~KG{yE+G?FEauq}uW5SAw<_@-9C{PoP=oFW5#i6fXnsg1&WyB`PTKqNRH%{l{R z=v7??FF}&@yF8Hm_a$GC%NP1Pu)RMqVHTG8quQ}>_QBut>B|5LFOhZ>8IbImHmhGf zm?<-G+weS|TWfIL{PwVJe?$NK(_`6!S~1Oqg339=;BM;s;X4F6$+y=^R*F1m$I_BX zP+Q!0?KdtJl<(9hEF%=FJvSNKL{J%6aIrZZoWZ`fcY~BM(039;1Z6HJ)B$}IVK%%N zZXJ~AMH)^VFDQ;OMc7c-6AimYqzM=m7jcsLV1`vu(?8IuWOYF5nyT8BF{I4-2<_j! z5u^|l)9wsKm5&CN7J{wnHYh|L%?=wX2FZ2>PjA-VaKFjI*)<4!nfr%wU{n86bYJ{z zqqQMS#MV!i`MTZAaXM?Ur#CkG)(r1Y=1#KCClH6~b%1Xh6Ngf?OdJ%teVn*t^RuI( z{K8UC+H>A2#dTeSzhSq?(9Fen_xfYu6$91Ho*)hgJN}I0oa`wT-a25^?3@^LXCFP@ z=YT2yW-p4c|0Zrja&@C#8J*z#?TI8{b&U_vm|TUl?3|fqo8I z%ov^N=X;u8^GYDYp({ROZSJI&r`L^>xYHZ{LQPFecKHVKfLE`)kPW6@X`eCGh)uy? zeLeEg!HCvj(p_Iwsh=-Q%+6o(v$Q4i>6a-kIP}wka_fAA6>%LlkvP;v&-`1B^R!Tw z;Lf! z`IBrzS~G|+j=vdk!)38yQhv~7`sG84hugIr3yi>XlR)||O#T){z&2(l#Elcefx+e% z^|@`U;&jd5(8vh97oyNc7T2G%l543-V=2#TID0H>(TY#&{zi`~U(zf;*wsKsPWjJ$ zH@XQT#P7Ya)hVS}kygA~T*tmqW1hHSG}vv6A}l0e7AjEHnd;Pmj_pdQK$gDFHM~}o znAnbMq3#?*N86^bNE2Na;_g0e6hH7-e82ssd9OT5EL~yNF`;V*t;*0cA6kAdth?1~ zm9=c3B6@4TZlh_jVQpVaN^gC%3C zd6*&*yR{!xg~W(kY1}}I^Ji_mwN3#XIKSFat%%NoaRc|yHwzX-X+5*Ld#sX5$#95E zvOF_YWz%j6!3wfMUw^`n|}3St?abIPTReUNl}8)zbKu(XL#asC4yW)FdB zcA&@@bDoY3>)UtO7nB}_FE~!l7D#*cQ=w*um7Ta;53f5+(BDt1MAEyAgq>2sozaRkQ+I>=tnetCA`<0sf4-VqawFQY(TY zrh8xU{Bo;MfQV?Tpjw(SfHT5}$k=u60R6~~<}MJx-ZsY6+4m1QKYr0rkm!4xqw8yQzyhC>{z%MkoNIS-Uy!0K3D3KD7EPZ8k z>0VNPLocn!5)KEb!|46z*aLInHXaK#4GlNgj=rK~jfI^owP$08)0L3%*0X=flCcoEASVC4MxJ`|4b#5q=i(Jopji{HZmk3br>L8@ zRTdxo@foNj@X~4L`hjKK{SgW%C04w06>mXWnY)P*EPXC)en;<`4nrBI#@Y0`TKZ)G zXGF2jNnB`we*6!|#tbQNA7QI}J>&8`G3>u)^nxTmJCro?07uko5wsh~Jj?D$OIbYv z3Lu$U8)gv`a^M@`5f5<#IYEBnGY^{m8h@W{`H%4@N|QsgfTXOz7V66~BFH6D1!^?i z2pKyI|3N7H&8ORjpcD<>e*wtr?rKGIm3wlI${@V}W+o9tSm0tY4lL@p`T+dvIY1l2 z*FbhaeW-I4@WS6@0yG&o)N%qPM-qUSS0uUsZiAUzz_F}f0GGN4K*a8yLS0}oyP>0F zXP5trSS->AG(Z0Rg#U@+q!V-^LD1*izK8%1BYy!J^TyEFbwS<4MgOG-E5}4ND3T8H z7yyY<*C$^N*n#DAH4q#1{FBgv7xa-}y=@P2x4t)clr-UP1W_c2+iKH3{zQxb!IEDl zWx)T41@!)!H$F4{m&6+mcd=!mFy+=qK*+^Gg%BrYV8=fLc_F%69BoKia7F%*DDC)I za~|BH6Grfp|NS%Y%F9(O8XTpAsRwXL`fLU9LHt_to&b} z3OcK0Y09O8JOGFMJ3zX$03h-D%X*PKwGKbFx%McQnfG|+d z#>Diea9`(k3oc8$qOmMaj6m*~);?8id_+`X*;&}FlmjyTvr$sOz8^v1$$})Pv;M5W z*1AyZxNr4mr z(!Z1ALiBsmS|Y5E#}9L!#Ts5cIhq*jzb5oo$+5~moi6u4U0t5ij-l)G&u?9w2QPX* z3tlA1PF(Qs3-Bfz@@uV&zGC}de~JDw$Wu!WcLH}>8p-CDo+-qpIwfr?Fx zgR5=V#qFQB`OVZBjCyH$u7I8@zZyh|p3q{RPV%>{gFMDAbbozHBh&wWJTOA3$Ai!q zGSaa)kkvGw?VoHOb@rg?;`fc?M`Q8})2PEDtBK@^bADQloKdUaiHiHGPJXzrK;!clY{a{gG#1+q%`Hfx_N{J z)1vjV+d4nqf7tEoS*RauH;cGpLlcp*^Mc>JxCl#W0hodv$fJ{he776y;M}16ozhIs z$zO#7?#B?YcMd!_Uq0B7V)M`9;P>@^{t_hTC@+Q0n>r!7DumY_9HVn@r*N*Pp&ZvU zuJ?pd!lXCRPdvKb>(Jk&%Nhkcf6mi)FTBXyXA&JZ)27^K;ZBGpVgcFp#Eq%0_Zp`Y z^{I_a^KRHZE;5f2fJ7j(svB(JZDYSl2FbADY*;CzuA z-1i1#U{Z$v`F(TN^*&Mf(2$?P{q@17(H8Hwe-Y5Pd^j_MQDFB`{}pL(^K+p_MF>CS zl`L&WrN$kV0iMLRR~P)pZtr6&?az`I$y&0pG!wuLX;rZ<+n0>Mu;e|Ed<%qv3xW-N z$dO3M({(AS$@fHU$MWVKsXCXl`bvk>GOzte5Y|`kvBm>DbRVQ%1boT#LokB*myAt9 z^Xgr`5di(VxnKvmEc)+Aw=yeHjx0tX+!4!;MKU6cOA^a7eyvy^%>7LRHW4AtoH5M~u7(WXA>|{eX<}_$dKmk$jsnH?MhY{J3-C>6e#(0kVN|fCmUnbJUE> z$LWhLA#yPeA%Fq!^gBFtxDQf_;=ZG%wGPw79)5xhIxnapiUC(tZa2({==^Kh<&vX( z+Vf^4SDm-6{C%vT_%xODzR~ew_w+(pa!)~X_wW_x+rzj8*@+p1Ww`*2Jc(w9MiB85 zA;M*zyhV5?r6JsIB~#jcFf8UiM4VP*ORP+V%_aIYataoETK-OmRCQOZ#P*_n!0wH6bDuX61D+Ezy;fTXNQM~ zrJ|w<&wwjMPkz=9Vpz=m&#E-jM9e}^fFD}DQR)cXs&SyF@JyA8GOT`E*Bg}efIyZi z*y&=jBm&xN@QfLk3OWqtkbU^5-v?+*o=(O$w>bZ0(8^oxwxq3-p5zdP7fgsx8FzFa zZ0d0!m_`*|ge{tAt2q9copza7Vp)1~s!;%NK%=`mM=L|`g0LmTgDqPR!OXN+zU1+j zYJ?1X8m zr->_1zI_06R5$pmT)`Q)X$A5dBw?aN2!J@me|{_Bd7zWcsr^&N9n(? zG1d51ZYC}-ynfEHJ?ME5!T$TZpP5cjF{OVMf_au^K0BWnS?~C>sowOV^uh*V`#+L8 z(sBYF4J3ld!}X~~S)aa=ZD!#4)!)Z|{Js1=FyCp64TAd5&!X1d6peTNtYp3XNE=Vv zXi?LvAhgF`c8;~ub`bX90;K3Z$aVbVlboZ*;m15gu2~Pp-4*(Hn%7-6rlS2@S*XZc z`6kTu_(+yV%q@$2_I3pv`YK#N903g{k_GF#&xawmz0S*6v*@g}lYSu~88MISbGwo{ z@1~Pgf%{;n4%M2aG|ax`POE*@s5ob_ZjTESgFGJ5p}!62|7X*`;8GQ{hls*?lGD zDs9ib1-)Ur{H2yRB9(Y3LT9uO(P@_H-Y-x0KVt=@IS9V?*k*U%KK%}oFF(?oNx_4W zZono!xV6=_%GkGs0Vc={3NNgRdaH#PkuVL+B)&W@Gb_rqbQ@|?^bu)+a`9MSI`#}5 z?ung`zFz&>1}Kr$*Lyib2KqlLo!&#+b%+qC-F)y;zcyS} zBx;=qccr8|!dkUHOv&G`u#V*jA}nNu^%}v%Wz)f6FSOv4Wn9H2X z4QC1uzAl6<2uM>!cn35&17pkyjKZr{8}^W>tF@v_)C*(hJKj?9)nxqdF*fq(Hkcu~ zjpfQPTCwT=N&ajXVUttmIv|MHrqXp!N*VKsG<1l&JrydCH1ACoEHsl0Hox&i*Szsj zxy|K7Y=|syEUmUZBpnRm1YtZ5W0>joQY-4U1KAp94Um3t=bk$1dIWm!+gm2w=Rj=1 zf43+foGR~AGtbv4GlnaJE;a-yiW9Rv)Z-%b`(;iqcPtMZH1w_aFy~Da+0Uy6#_{~| zZ2>uhY4P*wC;egSSxX>K?1|D49u*J>?XFxu z_)QQ?4~?~H52s9Bi;@>2ng-BliP!kd?7ULl(QD4+sEJz_of)*qrI@#2u0Xg%Nm(4C z)=smDjnzHt9##&go3VKn(C*n|-X&mR49|;6OYw34B(r7n2k|*lN(0|c`T$zjyyb4M z&-Dm~Afk)s)zXhn25yMHYDW`nfp+cBA+K-2h zD_M38!l8W$K}+OHpTWJh9veu%icfiR{gLJywGklapp6Elcg4`}+%mViXF1+7%H>ms zj!{^?*694*xP-$Jo$8K)2Iq9Aky`NI+|9X4qo+FgMV&jsZaz+wOG$K(9+#%e#SvuC z?Z8hmno7aTET2G>=#qz*#t$MgPuiXo|Js>#7ReD*t;v;}{@9aN9IB z9cSn_AwMv9V`#dQb@FuC;C39=SU0F8-L3+dAE4!E4BwTkA z_#YU{c&z4BJiY<)iO2FlIpQUzN1vFk+ht-I_rA94>mOXNoYA`uW#Z`PJr~?hJ+9Sa z_8pu-t$cq)BgC!w9tBME`{T0~6`&DOhE`@I6I?Q_KG!ilz;S%U+vk-Q=eUn8huqDl zuJg(7QyBCF^=2Q}L|a>Gd5Tk9%Y%cLo8K(P*mHgE4fl%wJ-KC%?uy^<7hoPr(-lq~5zejAKF^P8 zett$%FSFN!yKknfWkyT()El$>jb!P}Fjr4t9&-+hF$s&cX*RxTFY zko+0ydF_NBBj1ikF`R}BGAs|_neWlvS z>v~kenP(RNAOkHJvYUHX2M9>J?f`dz5|lX0_Y$n)2y4t89{Nb0(YM946$3h?RO>%B zUiE+6pz1ef9cEmzKemuA1Y9+*;eA>jy=g%n;A%?{rGUY=0u783GFI9?96$jF28*Qa z_itJrB0#6pti~;+e?V0D)v7x6<~KNh86ir3Rls}}}PxAgN4nw?E0(2t2aKxuF> z;4T-5ow+KG99?cN@7(SzlJ=4b=CyKaGB|Or7g8r+NoYPCztX%_Yw`+=(iG>sQ0pa=OIp6^Em+@ZF3m2#J#ZVaxkd%Vu3zv-q6k(@Opj8RK%kV4|IFB zKCTD0BQ7u`k9h~>)GBbAgZ&m7G-!d^ zI)?8x&KU#6@xZH@-U3iT|I>+SLq0_^j!}NA&PbV&Xn83iZn!P2qsH!C{6{|$xmVL( ztt49jEf2^zq@ukEr0ds?w=T||wJf#ujZ|13O(}osNtdk|I8g4A@!YjerzKM41CMp8 z=Fbph+4_KvYQF*tr5zYVQu`4gapS7ca5Gko`XVT3pQS%a^^1G;h{fJ_`m2U&wlbCk z98`VaKwuUMWh-8Kr@5;7R&N>zR@8yu!<~5%>ldAPDKRhe`qMw2zTX!Ur=%hU15cdU z1}=P-(6$5j#A0KQxG7lbne8VLwG9m#Pd%W-J@~}M)b z^%(=X`a{=$d~Ng_tEw-ohF60F-QWXy0-C)HNNEVLF_lTs8y@4OY73Ym%1F|Dl>|bFl}SY7d}>!-O1jYK3M~2k3Xm0 zNPXL-rMC01rJ{=;^jrfq*w=iItT7bsB@&e&j@Cwy??72~mnIb=mbUcDNP(L@oEj#^ zE%h9?8e#>JMz(@B(W{SNcLSF+?Qcjh%Q6m)3yu~LoGLs7&~K9LkEHAN`un=OFQ4PO zLEyn&IFS@x2ptssgbBwcKpO5sbkr`hB`pH{`rC4TXLa<2p*B4ix6}Az4?%K77H=?TDVY@Au~L%KH!f_6yh++M$x!w`=_==kODNV>Z+)cSahIeU>Q*!eqt} zM6|^@`6}YtHUZJR3InZ~T%f|Ox%LPffF$T`sUWNaG=oiNKL^>8KO{cdt!X~fYO7BR z;6~zmDn^?OmSJ7>tsKtUC}6%_3;s#0t0I+1Z6>df475d$**vw580Ko{R~8l&pkwB( zP2ioRuHw;$=Q4e|DT{*uUehRJ>XdG2(D}&JbaR@)?L>Qd3`G5BRf~1dGA@gz{Q2n} zw+H~PjLN!1yS#$dbKCu0cjo2$;~U#Vak7!OV;s{oi#~J1Y1(=NQduIsk;k01?wY}Y zc}$xT*KGgUOHv9H4hVhCAouenIFdw^wAwe#T}SWjEu=oeq%(c9DyT9SH!^xhI__W)`$O8uL2)`ma~OH4`{51PDI zPQgL=aX!sc0-eOA41Y5ar~>GQ8+mY3YlU1j`3759*y-pWcv$QcB7$>b-H2vm@n&3M zh=ng4G<{m5p3r5EykS5gfK-v~8>@@4Yuw1rc*0l;8H(k1=|~xAVc0{ehcCr6T~t}1 z|G5gMiGcw9&a-R5^{ORLYdUe3c3GTu{bDL|l9SYdzj|kG#8v zx1_f}NC8Dk;-zi=>VeWD*A1!CSz4XpR&RnWrll1;nwEwz{0<0tun`G|IzU{$IYPLC z6@Lm|kY#p|deuhFp5dxl`orzE(-eb)^dx)YJy+@K+yexV0}!us(6eb51&hMdY07d` z;76S=q9fFz`sFI2IxJ@1iqI)V04b8Oae)k-|C5E0|d6VPE3eP4cNLO&x z#-B>O!Rze}hv%wx^qFBz89=w)3<+>pP~y~l9V2Zpsjq~GIG2P$vsCpuM|4Z8C%}8I z$zw1X_wVbldFA0ib9H*`V^Z?oxOpR+&Op-gg>hPGT8-|Y?aUVD4s%nhdtng9g_4%| zOU}%~?X#k5pW*?Tyn4WG`^)mVB#!g%wQQk-yeIGnXnIAsCy@u|lUI&J9h`&|S#nfd zTtDzNEmFMOrExb)8~ZqD^8F6pJE1rU#^;Dlw9$E{JZmh@t$lVS)FR=&1z0s^k|F@6nXA73yo6r;Ua{nS za=_QVKY6OsqJRs*=2u+E^W#MA+(Oe|m;CE{($rXIcJ;6G8~flQbZ%?*cSlpJX^M#3 z^yYA=M;k{X-sx#ROevLkJgSE9*39kt_z(}V5Xo6qcR@YbZFG}?2ltI@b|5|DQ2Wm( zLq}T91Is@G&ft#2n3WV8vD(vXDP_vMiiLh${m?voC{^jx8n>I~lv% z5LZqp!|_KDg~g0Ws$|u<5)eBUA2oI@TXV~`WKsgD7@HlLMDBGn+kstX4=pQGe#2XLl+Gs zPIptSI-Z|9ivPJmM}K~JY9MO-mBZ(se)oSFw@bl`i7)Mo1@1s=#8O~+QW^84%YZbD zXyRd`ugl(kI6HhUL{E#l0ih32F1-8kdXKbv7Z|Q{=0%>b-}4n?IW7T^5DP1T`o-if z$h5E%`UtY#mt{(bUgI7hIVde&K_+c8eDAus?O4Mfs)E&fAF<6a-cl7-egS43of=+G zStdBL^qW?c07PVrP=VNe2VW6QAx&^@>BAR2X|h0tX9<8lld)M(l_;Ue`tF`fPdNd% z12P#e31j2A*I19y-E5r(2WX1lBRcY57ZY@po;z(4jpSS;XiS(!l>;RY|0kY6S)2KN z{BDlliDf=3?~|WN>&P##%#G_2Ozh++wTsR$7|1zVn65zgE7D5gf9=wmI)86ge{El) z{Bkc~3JRdjcYi8ys0f5a*o9L}v4PYm!$AtCTM(sStt=p%Tp5{9<9z@CU|L8l8S6}d z5jlzn5;A7yEy%uXVIDv-^g>tjFj#&S@(dDCTY?i_8zWj=_lard@@c#XYj~gU51SD~CkeAs9|p9pEqX*}(q0Gwxzl z?>HghTh3+`wnX!ZOjxzIi}WS4>?cy)E=QP)~M+5YGFKDIzi){5*!3_fc=Cp;a-hXI&LhG1@IR^S|Re2a$C(8O}Ots&i+dL z7En4}0qqbYB3IEGrnQu<27J29bhy8svc5;aX`wi`0t~b#M`lEo6Xe*kL7c2@C4s7>K@Sb$|yFQR9Uky{i6l4q{zY1ta>0=ap*m!*qpqV?_x9cse6Q zu61@P(svT&kCvFrv%bO>-g3}V5D(4KPU$a*%ohY81#r;I^p1|@9z*f`5*o*KW&@9g^V!RtY+rH=L7pK9XVJ24*b?6!VnE6BtY+vV=&zm4CCl8-fkxB>>#n9?7qX-B}IpMFWIpJ;){ZX9d zmckxS4LwPnb|seinrT0iw)z0&g*}(48{w0RVEp{1+RJr9ysQ|&y6UmpM2Ok$_8w!K zNh+j{?FuW0AOd*IxVEI?xw=DM{PmDqd;NYXp2>TiTSe*1r2S#THC@j~k6IoQc!8Z< zb52&`jRLflG)#mCLikQ6fMqE~*&m{4Hq_=#=oP>+VD%m=WFRkvSQp$WOyWUwPK4lh zBlFnfD1Zu7yDeEQyx-wrNHb9(Cx&Q{{eZWb9D*;UT+29P4V)CK{K}`q8@Nxlf3(oT z4I#p&{&g0uZ;A4it}pb-f93n@`mEV<~zjb;CTQY zglWukszMO*1We{6@AAW32$WpXc1k(OA|-~5Tp7#A?%ld52=m&BQ&JE;nQ0%dJDg;| z9be{!!2w2wj3ayNYA5T+6&zJAjS3gDPUr)gt!7?%N&QF$LwQ81T<8SND z50b8!1Z?>9eaXG7o11c<;?18`;V9~|#86Ox#3!^3 zUmj#ie#1~g6@Y7nqw8WB$rse5FYLP*+G+lYyc1Wg)qlw%m@nEjP!stT;=|yv+c)z- zd4eJ$p3!JkVe4lklyVg2?4h`%4xOp*o7+ToYbAi|ZVQ<;Lq*0YP_m&3uqj()% z_C>T=WDiIa^1A;T+(zaN(jbTegAlcj)OTVodT%sMsd(ajBrG4jG5pBPNlkaFsVj7l zDE_Luk`3;JAbEU`Mw|6Qkw{Oxyo!=Oq0j`-QM~tRTxJP5lzQB=kJq(hg-vV?I}_&S^bAv2_x?>8+230@l;s@GW1~cr$D^V z+WGM>=5n9!V$)jtuKSxV3f=wdE`L8+|2#ZP;dmik?*_JVe97_6Hy$B>r{8Ro@3nf} z>2R&wOOP}9XW4^7-JZA`DoR$!6FTbEteaC`$Cg4~3y7)xrffMUQ*`$9)LX(*2 zA>9sncgNiHVsdA`RDt+Kvn`$qUgtln2AGNejK|h5U(ewK zZ)%>;zAmHqnC+g@qIiZc#xvjW10!d~K$K6kuZSqn;3U0%B%AU2?5d$0it1|JUPoFa zW2UIxjKcR?mu$Hn%M*+}iP9UpY2oEr_bs!=9G|-KFU|h)E8nULgLBmdLr4~qIg|A4>Z6(RfAX z6ZsY?9UnUgqKyGASG8CVQjO*&-}lcyrtajkfAO(8}o66LdW*8_OA0J zp$GcFu7me6`_XGAV_4@&lkcfr!?I3w(f!Q;-A6hDQZVd=7-{_HLvtnEx*w8?S^2U$ zuSW=laeq#g7*-Ab)swE#(s%X(#w8#NCHT^}nIxTZ2$ulV_#+uxdv#oHv$zmJZF~+qf>oL`x*@xZRUb*|{jwj< z^sk72sZ^&{&yY(m+OBfn%hkdbH-(tl_}GjHZGruf@qb^!1ok-5c|j1bs#OPqoN2DU zF>fKyytI|fy~Ujb0G6MU%hE1$!B6frn~CM<@Pb0O_nDz-@>|?qCT8cS(>V_&s=dUu zSRrXqtTNqeC5<20Lw14oplBoi?#B<@>S=0IJNJ_Z(y>|DR49(dYY*xTEuij{U%;EH zRp+(;0pPj%K%JB~e|8?j!Q^#wVyyUnwnD`2gEw@Jprk7vkn`G8$g>-s`-#ampe!ZT zJ6|be*VuoA=k;Qhk@@hsUP(;`xOxA_`_4KvB4ya}Is0Il_;Lh3LfqD`AiY0XI671a zOk+ma#NU-Kxrv&LZClKkG&x^mtnNf1R}jt?$O9`7;n z5ag?;F0eAnV0^WHue<(&*nzsK{O$Lq-^D<$NnFDVROn@<mR|ltJh;~@UOm&xXxi5@ET;b^#Syy zGCtU8SiLoAJD|>d2nhArH^cx zL1QssG~B$C{}5*b$R`c3ik;MXfZ|T2l7^qhaOEq99i)~lgC|xW)M+|~t>t}>uK>7H zjnjpy+yqiv&e-?XEoUj-w>qZrdTWEdU4_jC6JD#Sk<&g?HRrO&)}K9GkLEt-BeZx% z+Q3YU#U{Z?o?qgnc+VSwQL@D0y;f_Ck%d^NZCh?I5c6^Du1t0xj)%o7zt{hmzu_bC z$nTBM^&6VIlU$7AGeJZ7ujqyNhWJ2QEw<+MCHl13>l@GzY1d5nHfJtj>@P_N(9U!N ztqfM{V+=hlhq^-y${+Pyb3WVC`sqCJ?c?tEH=>|J^nQp4w_#^n*tWp#9=1p9@C*QX zS2#J94s|dGCaXB@_)XS5RInifJw?iW10hdO+3 z{3Y%aEXPg9OvgTJA^+F)d1q3U6(=hEosBUL@aal5bemDezleVtuTPMhFexw7vExmY zS%rD^N=daYFm=DkBZbLbc}YK#(*vX^hI~pwZ=IVT_?c(sfmV`K%o~|sgBc~C!g-(K z7;g99uYOkGg@HJ)jui^<8{`b-^pIV*FrF4NFFt;uMxm90WSD(l0o2FGUM;xa{bvHE z-Xsg%(NDeZbPecg6*aWzDgUm`jZ(66Qfahv)&$DK?6A zqOT!@bfvuG6aUzjq{oD zTK%G2M1G~nH3a$B>4vH$8u7-w<3NO!fO~0IK&8O6AS+a3C#TTMeQipQjsP<|ycDci zR~{e;ba`>$TzPw1&Uc~l+edDPZ~gVfF4>{=MXJ%8!#dSjX1xV~(2|=&gK%;EYE8zE zV~MKdD1biNPXvf?BL`4|gKS)!@w$!#&fP+h(4nsDJQVUH8PN&Gg{qc^MIWR9Bx94!`rMBmspKM*a#jtf>dzofYN|?R(VT%75cX-o;44K;egD(Fc;dNtE z8;$$k6B`HaefIRXm>(RU`-*y((_PD4ny$Iv!b?KMY41gAWOU>$OoVT}FWK@>zQmie z_hP<$Zu?No`q4-sD-O`#n+NkG1x=3ey%1z@IS|bvc9cYRFDGk389Mj zz1Iw)O2FjCyf1{soBlH>rdaofybQhFClvebgG2sxCuYz!VDjw5T{?v{Ckzw?8gr#qWA8Y3*v_O`moa z+I&gc1NZ6;GW7uxS&KgS;UMNbh0cH9Qc`rkq8G5MSyLU_!4H9=RC4uaJbh^<@Pm7O zUh=y5y*Id)OlZy!9Qp{*Utp}EsdAsB+5q*#r62*4^RfEVo`0^1)R}~MqdB){%MzL& zgf0y_SMM>x!~%P-i@#c6&WD6w`AQ3|AB?L$Xg|SnrT{042ky4~E-m&u z#isYMs-}y#*X^_VzLl7l*yuh7PU@{~K8p!#E(#zJZ@9=zP%3rYDAj$ZbfSW2@1WVD zpTXS#u>onLps*O_y(tYm>90aP&%kf4zW{xcpz`tRmr8pBL?|fw8O!n& zrQlv!R#eCc&?$b!!`58q;&ojn|ZD*mt@`*Y%ez8;;8}UVK8*!}}n~B742Q*@bPq|OK8m@f(^ikil z*Qw`x#j6MY_+#*y!|P|JNZkQ5?^4wwJRy)}Q*g#ja}{{Hhjnpr6o?pc2_Uld&o{1O zX@W^nWYUa%>q17}(rinhEyVbpPHG9uK&N_Ql3JJI-VQA+xa~ z-s6$n*YMNz3YkY3N(Pl_ig`_D27%7V!}EINPL>y!bO03*24dLF*zTbOWZYF7k*sG~ zTBD+Vzmeb3o)s|V>PrD-tY1L0;xzA;>q9=E>6MuTJyQa zEaO}S&NZb-Pq3Zu7lgI^bDQ`F4F;&)%5)FSRh{S%o#B_z+b<)eVhHaA9!9UpcCiM4lNwIk&;>wu`Icv8*4w>i zNLoorkiQlJ=z5BG&^U8Xcbeah!$cN(mrUCl!gm1ikmn^eEQw+d_t36>@*O1e{Hhmh z#UmVFzy`QELKkr?1LTPKREQYnUPVZJk?(vlzd7I%b;U|`*8%Uz##y`j4{_|65Dn<1o2td#s%uf| zEBq!or(c40H--huS4R(Be}|2G??Wzaf64S0Dtg(|yk?Gqdu|4Z=7ZLNRJKqoZ9Fp* zY&1kFjLz(dJWG^vvD6Y;4<;lwlL)q@d=B1gp%Arz5Nv=j2|R7v6$ke(-Z+G|Hh77| zOicSclTa5w$EDTe(y|gCy@k~$iq`R=pMWi%1_-fAn3nX;=m)R@^7Z3j5`-SeJl3*S z11Y}|qkSPRSI{s0sF~bB*jWBYKU#M@FVk?^Q#9s_1_?6YDpGLATA(KC`CMbrkrPBo z^ll{Kd{6BcSoNh%NF{@Euj@lnDV${sX)|pk1?BV3bB2vYWPDqMZWSO03VG?f@CMUC znE?N|%j~o8viD679ZdVHm z7Q4UB2YW=5y6h&)FZaZ9h5hQV5bN)V8R9f^^Yz~QESaqwN#Upk(w-HDf{3ng=?q{a zp8?4*VgtE623>%9b=xazbL4^i8wWXN{2?NIuK?js?5$J2zFQFHY=9|o|W4}x%)a_f{jPoSV+&%@`EU@8*&sO2BE0KfX zgRUk8&Kmh+FP3|_%aF<=7D(l?uvLo-W^fCiyWQmK_&@h=@ED4Fzr>Cjoz4ESIcGIJ zZmg2M^4`vgEqywDZyT%CUbal+474ii`%U@ri+eN|NgX%(cy4F;%vRVF3UxAJB3Whc zw!N;+MScb1o_$wE%_AHLGFzmeYYlW4ej+Kwh2XGQz#({_IGvG6M(3GJ+0kA%ZtF%bFgetPCoQh`Vo=@5VybKrszOzaoYhy5v6ASz7P@0DHoe+Ja)% z`Pw0ye|1|!x980ce6Q{CmcB0H<<{DI7J1}-&vy(kV@yc!S8a04P&065*yShfMYU=W z2Xxhn-^C=twJ>ay+MV882A=?`DhFb%Ul~)u=aAgiL&_KSl3f!Khdy-D)36S%Bg#cc z6k8%--u3=~cDcO#ct8)LGyLKb<|(U`$3~LRp>ocH22T?qvy1!WX1~=_g=IPan<}Tb zISC})?FfA3dSblJBh5W|858bAbp=l>fF=0O>;okf46Yi$rfE&7OQ5T$Zy7+bHXbEX zsDKNrZEp-$Hv^mdm21~D5hmLZ7n^zM7ao*0yZBdUC{Onm_;@lGia1oEU4a{R%nyl# zsU;~dahE~stOF1WyE`v<;QmDFxE~W7#>kF0fs~NfyGj1kF%vci8}D1Y8w(7ZR7vT`nB$$N};d zI$mW@A<)Rj?8o_kYjRMPf2a;px*<1VUyrkCG0RgArlzWeqdO@sGcT?o{H}b9Ar#ev zV)&jFiwkX$zcWDwKy0?tTsYv}o_;e`fkx!fGo5XVPL^}a896ES_cqNXaFIjgJVgmw zb_t~ZSsR;U-Un9xNzz-a_!L==13{q|=lgii#*;}!<6Q}5DEi(M;YHQ{qLTZSK2!d& zaBS^N!5c08l7V_P*O6hOV!9Ef*1`1y=T^9=Wro5Ow5ZLyv)R0|>vf?#(uyrAdF(WB z?|ZX9CP?_|kIfCX34Pv0_LGH^rC`->%fs2(QZuYKu-O@l9ggrwq@~I{-yhp8Q!|58!@A+SCE$ZKJl!+yC zHXyP|I~mN>t>*zZePGAeT-)YC-i&@;$`A|mCqnky(sirV(&H*z24w?{P61V;TG9ij z1C!doU=7I2?4w-$*!<&sv z#>)CYTi@8$be8Gn6~h@m5#Zd|hI6S>_XTK9W@AS~ zx5t1()#$@_jhTkIN<5cpXi7d?X|oT27$+TT2yc!GVBJt?DE4GlEjjXfY|g8xFK|%a*GiX?#&{%HV(rP=7W~d z%LRc$#n*H8nGn2Y1r7*w45E_0PHH%NV`FtVJM7nQr2uy4FHbXxq}^*Xa125I$IWCn z1WpvhL5dDTI1?Pu2;m}hLhrtSq5Vx8y1#bpGXs5|5YZ>R@ORFDPKsR?$6bv{m#ivHFE*uJc8ds~qgDI;&kUjsu^%8$5Z(590egHkG zMfB*F0yNXQ|BdL$58@K$Wb~1u0+gcb^txm_f<(PNke}O;z^OK`<`ORA3F&esx$`~h zdFVP$4sva2D(o;2HnDXH0ii7(VK7tSj=hDv9H(C0h zyz(G7lO5Ia#!KvyLA3&zI3fgr+}~zfUtyQ~DtDeNV+){C+Ix}qXJTvTYpfJQ#>J#~oz*;|S--9_9U@zH%g+2Es zW>OX|A;{O;@x6#5vVK-(INIT;S7RQgOL?>2|9$a>O;MBaSMvdoe2IS}?^=))a> z&vkeUI5QN#2<)ubS}TzH_cM2q`W&4|H}p1cYXgZhs=-q`^{*xN<>`NaRU$74lpMnz z$2l_1b0{z`~_!x5Tsg6=U&6vjS6yz1r z6*qMhWogJ-9%%tCE>0>E$^t5%LcVorQA&GmuBE8yysk4U&TK3px}`evsk2$>~$MpS1hJteGdxOzeZV5))Oy;l`drwwM zm9ae~++t0(3cEn(`N1F8nkyFjt~y7bCh)rxLZ!Dw$^%P_U&RQS?yv(sX9F-lu0vRsJS;iDBbOR*H2`9R2{&NLpJ3 z9ktX^5+}ftEZs-lYWPvt8hb~T^y5(G@q-_wy2OJqa$e2mhoa)7us=w@KG;u2 z+DL`jQ3;n4aL`X1yQujnbnDrUle?&UVYz?Hdt6Lha4`^va@)SEHylP|z=8Yb3+8G3 zH|{Ghjgle}JnEqmZ0bLLchDRFV(khRM@IVtT!xlhFVw#d*y?}&iyYydC60be$#sh_ zl7o=K!ba$LH)vTe`HxnF-$_6_00rg^`y$W%$6vWMa-R}wr7L~;SEq*LjV1_3F7p-V(Sx}+tQQX1**5Rg>5JBF^`o}=e^-}kwG z{ByOoEF1iZ2>`I5_Cp%EB_EMR-T_W8tjqf*BoNyd)Zm(nr?%+2J#^ z^H=82o`qOP3tHHHp8l3++8d|qXg-)buj?nK47xv&459PD&~GN9F{J&;vNzXP-gxs_EjQ9sHYWdDgsV>#6*p~F3KsmpRMtiC#(mK7yp8t+3d&gCyD5Uv$4$2E zOo&}cm3LLq^!U$t+k{5<6W5EO+dZyF`?GOgRmWwp-Z~dm=yWyQ?P{~SF01!fC1O^$ z*st7!a?uVss`@PtOf=QZb5_dc|Ngk%J8@Q)bLh-sW~f-opV4CT_R@Nfo644iO&T|( zpv@pzb{)MQ6BoVTDt-6G6%24#f@4d@wL}c+R2u}`WF5)invSNuaOENO@~+zRXFs0e zQa)RdvhNk0^^{~%{Kx<}nJ*?<9=lkNN2}7y^mGx@XG@$Ne80o4Sy^a*|B9PpGg+m| z?x$S(G5RS4>c!)nA4b8aBXYTi=3e!h4xLhAD!4&ZLoS}BIL58V^3cG>YP_=OI3Yy> z;Iv~v8EJ3zHxowX9X%ZbTf-|b@Ebo6db5@>jj950(_eZ;u21Qallu78ZJLhj=LH&3 z%AhD2n3GRCK84hYn!dA3XEmwz=j=houaInEItA6nV>0)uuM!y?+Pu9@C}^O*68ndV zn3f(;yvuiwHh;$1>DS5u?yK2oe$>HwUKT)5f0@$cu=ud0GiZ?>t{NHtQxod7Z(pXJ z{nxz*tULS<0E{6946!$S{;eV|vl4Rkh)(+nmPON&DKWMIQHD5DXxxF}PNe@fC}G^H zVc;-S#p-`9hE2-N>XqxsXh>DfQue`{Tm2*@<`+87tmvB6sLI{?tN6g+yo7#Gjk=~R z8do)Yo>%U^3lsD@*FYG7VmiH^I8J)Ap4j+z?=X`Vjrfjv8H^q z1enfo3Mm4rFN*b8fzMH$N9sfNBbza)gjztNDPku`;SK%Q7)P|$>_OV)G~a@LRlHcA z^yf!g;?YiUv0lxm6B(Wm<{SY`IG$X437%ZeS#b8jClj?d2lr&t`ARhG$8?x>g&E5t zu4xUS-?JaP3{GC4!lY-sG@rPDBzzG2(i)P0EHVt!9H0W!4Z@>Rq?*0lKW-QUJbPW$ z4kkIe<6MrH6A!vmShL_L`{b^3xO1!1_6as;vNN)UXGLD3Jcq75(GdH#KxrLw36jCfE>7NfoRI!>y~&H1BDqN_p4<;%QX=KEY4tt+;UWwrk1uCI%Ksf7|7{FHT-p>N7X|T&=JoF-3D_QA(&ixS`I6|r?>TMG6 z`kMUE7);!%k#?PWPb4J5*l;uok=lms?kfuDvytqYJ9zLeqH_CL5q*rWDDQdJqLlB1 zzIxJ&(@;$}Ojnv^T;Ff&=`hTC* z`j4#Ix|lUvuO14hDD1myZPryFk^`;=dkcZVc2VISVHETi$2;Kzy=bu?dA#c+SUSwp z>@V}}7uv8k=uC}uPyYMag>As-HWZVkL;ty&Rssh9BtF<;a@U}+u8x0?KFR5FiaNvM z{Q5AucJ69*4Y(>B;45HQsWp%aW3F*riT(1N%_g|JbtKEfwO?8i?_NBb$=*A<)jOH; zz65D=E?ur=cQ8>LRWO=v`Ib3%-$kaC@m_|mM9l@c+~Jwm1+%tF=~)uQLpuhG!L;YQ z_r~AUy+Wcp61WY=_KMPAaLd}gb5_IRR}Y0zDv=RWApT^}_4uWMMB7@w=Ll0&hD>vK z$(=}y7iw0c_mk>8J$%rk)L;cX!8F#EWD%e8gnfyQUOT!;R*_@WrDFbm zX?PyoNi=Of5G&gmIhcjiv?g));-G{@vfwx-R(0}71_7JRgB3SlvBqY2)zZ#>} zxNOG5NB1;19D5^e%qNF)N?msiyuN6Z=zn~8!iGN8FdtMfR} zJn9f5vL&XLT&m6utj(Di&Vb@Rg?y~6_k$Kg+z><$(t9%2Xx?va+X{B1jL*Mxnf7t4 z-lmzZx2Y2O-MdLAX=o{ml?HjZB~Shnj4!ga%W^*kybIWfW=A6>$DfO=x&kH`^T9HbYOF9diU)&`Z+9IMDLc@7X8U_n8IV_UT0vipb6&#&j8XZ4h-h3R%%S+%Yp^` zQPK2d&*E|{9?B?B)1`OSsq>r76`HBl$thyV#sDm!9346iv5I|KPaNCtiVqw~eC&6S zEz78+RmEnZD{A%dM?s8BV|2TCGdxS%#*KCEj!0(C!|YI%!afSVjcZ?=H1nU8ij+rf zD6~;uDO5-%^LVUg3X^tZw8^^@CaWaQ95-@W-xPaUd3w=lgnh4d-eCZV@?l#)2smvF zIf4xNl8s6GTBQfBaz?3H&)RjM;`7gX+Ms)fBaHj%mJ--Qq9yDh9JVcB+j)jfdF94* zY9)61xU<$OjcFPMI@0w46X~6~PH6q=-CBbti~Ady3P$)?86M8NnGx@pH3@pJrfrT3 zfIHo4uie-^cisA|v2t^{zNT}DJN0p|Ph*wZJ)a*2xpu`I-RH`CMYAmQV`<@2i_Psp zkzYGxSm#VZE$h)EvGVX;zP)^=2I0wKB!{NkoEIk7E;H16{-R;G06Yifz`BgM0o(bk zu?~YvmKZSKt@qOgm7f}WUU`QmO0*B4!1fUjfK*R8|Hc5}p2!al&6z+#2+0ef6!HrPA zw@veHxX3JAd_zf;qu+uij@wl)>V?z&?A=etrJEWuHO^NyNj3F_56>LaJSq40Yyn#B zJ;;Yh!MdPvAa2VAAU!|FkvP6@CNIxv7bLpByeA597biz>=18dhxCn0 zo+={_9)2EeX^~*Go#K(rf-*;aMgQ7b>9)zEeJqg}XzELn#?Y}8ZTL|3Uif?z5#}9O z7>Z{{1ZCbCd~4L zow&5UEhR^x_)KZ95+0a5MK%kYf|sf)Ph&v;G;FAQE^7!_Dj5Lt`rhrAyf7u??cz$B zE-evU|I%klVW$c#N;cE=X@b5~c6!y_+95 zdYzlY)d1D%g;MLt?(z2Y_kq7+Kh~~^cUOIa)-2eH!` zRpsfW^O<@dv~a&C>Mg>lur0*4`F(ErHU8d-zkv;p)|XIO4t!6`QU)HAxbpB?&P zZ@lsPx%F7#=XB5)G$IF1%`Vgg!Gp}Jg6W(hH}>^M@iW1%2M#A!_@1U~cRJcNoZcz7 z8CUwqZ(p1~i&TU_D(POAHFk9#dhnh~P7QU%J1ARX)IRO!_LrV()f_dX&DT!X6+kl}pCVEWvesHt6$( znX+*KnG9sM_9bER7!;;N45V&eYz10+Daaizb<=~X zdkiqJS``yy5YB7GM#w;j)aC|2FTl}93|~6LEu*&VxD-*OXXHwy#&OxX^t)Lv>2D?w zNk;;}^*i^^57Tc7#c)oMWM?dVe0%{c8bQZw;gerZ*h!X@og&ES^oBoq0eF(JC(;oL z)%Z(DO1e1qxglXt(ag$RfIa?WJBgtY*sab#%JM~GK*SQMzGBbkw29!y@Uh-t*} zhu#j-tkS9^3_{Y4TdJy!7k)_#kNOVofp^J4^uD(z^BTRHOM@M?e zGrWarN)W?4Ej-W`2d&}5+y6|Ld6O>Ni3-jfPLM6%I(J!T(EJjK+8B^Z2v#51EqRu% z6cS&&YP@4G_N+2JpROtLhW9?n*dBlm+$ zGt{mi%s4K69lEzfO>Ivm=`-0HXV4yEvU`FmACf`=@H~+Nj`chuX(neN7s$1=v>;yc zBOTWQdYzZ;fh0z4?RV|TjR;V;Ai=-TlU2ANz28hai6bF?m~;;J6#`#B%phnAd0ZpQ zKhJ{nhuAH0SE7G+V_x%RXX<1DweUz1g;zL;Fws4-9(@NVV;#U}s(W|5+!ZBBN8}z! zPNo5j32RvUz#j55w7W%n;q3zb8p_6=``qR2J_suipuADJP{h}Ot`^N}CdY|y533tb z!Ms?|X?EYhheKN4ZJGfS2*Rn?g7g8CXT1Ki#Oax6zT|&qb=V9T9w`?1Cu3sJ6^s-5 zzZa9s*~U6hMCpn~f3=5KS4R*|Uc>IZO)FP1}#GwKEa(?C2XG|wr6NxBG58L#OBeB~tH z-uW^3Wc+qUv@6VH$;m9F+?m8ygUix)1+Y?=%WH$U(qZH8;AP#lxBvA9?$C^X`>R%5$g7;ed zxl*Chbt9GKm;?Fi8 zt|d1fNT+}@f${4mcBY2%ACxO&U`B$jaUGJRsH_RLPeXVRrd95Y`0-znDKL*0tt`L8 z307HmC(|67lJO%%jTqCFMFN_1&TkXvdbd0h?5yFQFB=q8q+U7|Z&GNX)L$bNtghSr zyXNgMsqvi-K7aX7a{r%ehq~UWYhk+h?RM#gk(D6aSZ#C|gGf0Yesgt_1@h=jHLPmc zL$C3?KVvlTJV2X*yv6(}wp87mg%LsOoyqKj3+3XvbITIdNL<0Yo3I5PUwn-g>jzUZ8eJ~?Pr#_$>s2u|i8Y#_|1(E~U|!K@NLvdb@n*&i;cXF}L%(FUm? zxMX~FD0MMXOfi9Bw8h$iVQ$=xdY70a`&_G^^+sERlDa?jb_Z0eL<`5ejJA5uoUh?5 z6ACRHks9$T3_zJTKGpjPV+%Bh(H&>C-K2A6ZUVH5U&!(7f?!-oL!f~)S4LZs6&iuq&{xJ?W$6&>V}dd)xH0e?-TW8!Wi z#ac)`Cf~wGqGx&$TDv~;*ycaRJ5xmi53uAzl^03V|6{gdbwft2IsB6T9(XY7(O}IA*1-kUkt*w5PN3BsHo@(vJK$hKPkAxZO1}@1~ae z?_bx>cJM(6&=fC}2;jigazMP$D>ssvcfNa3PA8`www zyd{O)yb=KnxP*FMEa;Jx57(*4@!TwqZoI%`y>519<$di>ymcP6ls~35Y|+a|$BKKJ zh~D^TO!>E+IMm?8^{OQk7?gr~48H>m!SF|Fq$To1#V-8=3bd$sWX& z6k2;<{{>CL6b?R^C4oV?{Rg@0F)zj?k$SkV90NReMr@NNC`T6js`HI!()uEcE?xAf zs=j{6Cqd+jw0Es3wu4;|@yP~QMf)4szH;6LC>}$D>T|sVsyQ@#jh6kLK-nJ|m6@yQj0u0&~CDYT`q3rS@MQ{7&L?1i)OY(XY+a^UB>ZjN!)( z$kdr^{6pD?iOrP3C$Y^prVU41oA}xjTr$V6kjPx5?o$5hhaTv^%#AsC+i=d3?lqC% z7=6*_ey&2+JMnaLFUiL(-iChjE;F3{ySIH(B74luRx9tdM^%Ku&g9Hi_up^d|9N-V z@UDUw5vLcdLgt@6tFP*QX~%Vi?Apt9KJUyKO}SEo?|6H8U3aFNtp-sJ+x*5_uf5LJ zFnq1T=IJCw(+DLcWiwXgX`O}8?KX-^0S`ShU?9b5^I2>#P7}Lv3;<6ag9Y?0t=YCl%c%R5Paciw=~~Uf zCzUij8I1sRERLL&oEO=Zaj zS#hhuRQ5b%Fio-mo4BjQfUk*U3bJPGIM9D=X-J*?*ftuZP2^V;C~_PYpKe$Y6B5z^ zwoQDFe0&$^iXd)L!7$UWha->HnY0@~@k53#rVD!$lLd2a_##()PC5=PO^ICMxe>$0+v zP`11hrv0zNY#z~@+aIZ0FedfeuiZeI20_enf4OnulOX)EVr_y1_lIK!2Kxh>^g^Md z&G3y1-Kw0Uo*1Ni^ri%Uush?$-0fn;EYVoNoB`Fg~ zuof8zznaZh6U+*ym$@?@@bSJjulw?{&oj_~xCGAAAG?ya zFOD_~Y?~G_jfhDdSN|uptEPtvYfKU1Br}BTbBUbb*PJFK^!NS!fd=TG{yseLN|IA` zHTpKLj`v%Rk-~8~?j_NS?m#cHEV;|)i*M3vTeC1)3xb!GL~jmgC>n1{iM@Qj1m-AS zP!0uP;6NXNnL-qZPg$!i`J*57dd`}3UpKu3%^A+5g-Ndtjv&)AL zwuV5=mB;}zC`)~?hD3opt)+)d7%>bnqHRVVZ(iS z0a_&P<;_QCPR+E~bUSrpQ`8mR23h(W40|EY!3zM^DwxP{{fev)9RAFM@-)wOcQ;N1!Kxy`aVhT*RCVj1qDqtlnx?C{Q{4 z(>BLT9eKk$AoZc$Bjn_Sz4Dsp(?UGo;Ar~s5(4b!E zdvP%+&V0Gnm()^mDO6$8Tj%a{WW=9uXgIxfZgjlFktmLz{sZhcp527!W&iFmIhZVV zavV9Kcnn6rFC6Y7F1HnHqUn+^1w3OfPk%7~dl}8~ZPLSHDSvxx;#)W4!aYep^42W9 z`Xvp2C0wv2)KB=(jPnAdWdAun~-p10Vd~ytyIpuDD3PhpM zRY1AEgMv_@5Z4hIO?-62;8I)tYS!3Cg64!F^! zLBJhZQw}m;-|>7U98C^p+)%KVHH&nlCBKs^KyX8nWWVd>tB4o54!2=prvl-Q4h)co z@_bRu^>|mJ8Q)(_k!v%##4KXepBUJ9;jc9Z1PedmqByk19T6%f@_Q#qsMhEWQ{?Fv zhb`DJN5E%65l|RNU>*_{Y1em*Cp;>B*^bSb2e0@d#8pfKBK`g(h+oHEJED`vspY!h z0v3rBr#~0o(ed%nfE@x*L)L!+GP!}7ZfNkY#NE+y5q`Ti?p|Z*(WOrGL_7(HR~Re6 z5&wLgjwzAM=TiIF;8L~H;8d0rTEh_3^F00`im)0428kf${8+$`6JuS47eQHPglrK{ z6KP5Y!#cT&FVC}W5(bdP;J=}6>bcIW)Woz3(~o!8=_hbVIQA&H$u|~R^^sCpWFcUx z$pP_`xC5e=PqZiXa*ZqXiEQ%8%m_0aRAuwu9=t!M5K3kfdD`0Qbr@6H+l{f6BtU6iqGCur|HBOHF zy=Df6Z`9a{Ps`}~u={T-R{k3m=L540<-F&e4-E&ybsM|tS`*BMXAVm*5xA4D7ori= zJkRR=caBF{dOCa4rOTEb<( z7is4P&|eA6YQE6B<$#Y1MIim$fxEzFO<0&!urGuwqz@kSg>XfE)=bg4QZFRZ;ZM zmpCs}Lxp{osuyKbf6=;t29=ATAA?}aAdIN~W5njobi;zD1f4TA3WtYc8FqLEG0Oia zjjpk@!Wz_7X;!lQvUKAaHP7~l+rf!{9Zc*JaVw5@7Ywvc#z(?Rs5 zVyVsL^WL%&tDsGKY?`aeSo#^Ab^q0-UB)WVgAaZ=4O;m-jpiy+cE@ujgE00}aN)9M zQ1U@IQmw|(EH&}L8F1akNl-<95(Q~hkTzDF1er%AAw$o7>EF8`u?^0Xq|`E8{y>{b z0C4FZ@XR6ET zsUnh0c?+~LSH*)Po)l*Y;s7On04PPXhqvVIgx03Pr6W#JNPf&Igin^vC%m`U(;6@k zl4qjU0gA5>pW}RIfJTdKA$6`nlNI{~qOSRZ%3`;uR)oMw$n&>1c>4d~7b;JFup+cX zVlrN&%a0B#&jA(yc-B&z%|=zE`k$+WUl51_=35Ij;QQP>bzyL#=c;p?Ynssm-oR01 zei?E3@PLBiS{y^$L*$r%foUkfq6w4)lJvPT>%9BsJ|9Fjy4ew=5fmJ}X-dd~7)N!RB!9v{T5wJ{B)oa+2{t}p|}qYA|qY^ zQ;~TJffJZ!KEwIxOx);p|?T*YJt(0T6^nWzvU4+foc+5soH zC%8*LKk0jZzzl6k#z3+56$H+m@u6oTCW;>)B1INKVdu+s-n5S)6Es?jN2jeG76AWn zetvZ_J8qLp)D-L>T~4QhIdSEi1~zk2vhGg&(As zYT<)je%~7t@X{6IT~_U%ZoAw7bG?%JU|LZP4{}6&L%l{v6|jkG@Pt#Rd`OmzjFYK( zX%xvfzb?fupT7d1CCM;PvqCJ(4|_5E8T8oTJOURLvUwf1qewSFAggY;G@(c7(JPP> zeq9G-r}OUsBqBukC<&UdfU`DV7AS*@4F9Y`gfKHCEg8h#)`>tgiyeUc%gIHPpy>-O z4q5{+s79=!Pp>vIij7;}TGcDLp`dv93h3eMwYZe*U?3nLp%!Vhe{O3mN#xXa!4Lh( z+WMS_{$jGEn(>Tx(nxV+3fEZ}RsLz?uzR1Iw(Iq*s>km}%uEOZ$@Gr~M=)7HToi%f zU>^3cmq;leB!&?RNn3)AT}?KK#Qo^SA?3(7)*2n(}ND8 z8sKEjyjakm>$p1?m_Pu*qA$PYvOX-m*|8YxsAoV3P`NB%65qr=ufbsX6vTOs>6$oX zf9ea6IP%{Qw47gGRd4I2>IqTW z+%3P*-IofcC%^Y)e%vDri#Ux>&*C&^CP<{@j9qV8YVuqR7VspC-Ei9A!U1zit=i=d0 zP}>tnnEow77K9TTd@ms4!;seXshI;r~WFW<$P}>nfVo-p>6czThS+=zSJFHb*=m%oBLPjf&RmH1s^fx+S&T5;nLdA zWXG+GXNyP8>>^Kmo;Tz)!P%)sU`SJ%^qBvoO-q*uc zhGMu6ff+-EBFCc83K((pAX8N*80P}YB0K!#7(H#6=#mhf%2v!P)UHVT;474;5N1t& zei+w-vY1}9rIrU*($l^g5DrI3R7`J$-zK;6{@)J;PW<=VHi3+H!4Li+P%3}LGHQD? z`bU;nx9Ua862d(HCN^Pl;zp){*8i@0xE z>}QFbS&xwA^Nz;uElj@?8SW<>(5W960%n9rGGlQw%ZR8ML(7Bis#~x zdaU4~XnJEP{kW0#U^{(zWnnd2yS*)%_qp#?U!Q;9pI1q&0J5A+#mK38402~mRP^tp zXyLtsPm9+NK&VExC91meG_v{3#vCYozB*6{LW_E_!}Vgu!Y=vZ!R+yc(#?}E@wM#N z{%Mh;(T~00vLvKj&*c~sY$$J-ZYIw(&&-w$rCwahHf&wI&+d+u6ekd4F`{tj`v(B2 zmWx?Ez+wD9qK;mpw?0Vv(;}&Nz~0{rsHgvVQDF`~j-bcA-Vh5Dex9xtd3f_&kmct2 zQO0G%7~Prr_PZxr5f%8|J{M!6>Sq~tuA&{4SY)6WlhLY`Pu4A%FgjOC|Lkik<^2nT z=xJR8V(tAxs-*Kz#63|`EgMI%cW^z{j!)1$d?f&va#XgWEb`%JG`kCyzMso8Ro0Ud z);|jgvGRncVQg7k8=iX0$uN<{iGOa96EzO8 zY12W&Wl@{7gmh97=6?1@dizEqHdfxH$UD?eW#2M+-9N#tc~WkCUmx@ng3V?!mGEmZ zywfc(gB8-o8;rb;Y9)lIg)Fo?AM6+nB3qL7GQ=a$xflT*62vPGTz4kuKpi8z5YoH# z<9}xRfA2fky;`3kC$a09)32{Y9M!*s3$S-jQ^!1{j*#y;?qpOyAu3(pQ|2{qKRLMZ z6(I4NzVM^=kx$IP=!y|62y~@F2DYL#SS7RVf*1~VZGGYlE9)6bFSP|lFWi%Uf#|@* zl}pmlG6}1yfW~m;r3&xEZ8Gf+eP7%(uJ-q&KavLtTZ82T&X01eVwlwGb)M^|b67<` znS1trse5$zZO}%8FL6up#DI^kL0OS*=dpd`k+OEp%OJ$sj6RaRi5(4O4Bc^cri*X- zOCr0cJ&k1wnt01hiU%LAT{karpGAV;7wk3F*XyhE^=msAoypd&t*BYqhc`7RhzCg} zT-U);;q;r6v)c(w)}m!Hf8{i}cNxK6z)V^|YFW>x_m$hQp|GU>Lg28nxd?xhtE&FS zu>@3s%Kol*->y9QcyoN+@p$ID`yg(vYqHqN6t$&xM#HcEiLu&x_SQzKUB{av*XdQe zmEYHPy;tML9JRV<--=GWD}7WB$A~OpD=_=IX^-iZ#$UAqHm17?HEtbJo`n*A8lEk}toR-&Y;)tdsU_4dOzz4WDvr-~HymmX)5MVMzLJy8Z? zezf@Udtwn1X|L|i*w$s+kIJJ+eu=d*J(%-(zvU%sXYVQQeRj-!(EGmeT_Ie_v_IW+ znfWGCVO?F;QcI_MZzec8^9*9BZH3wb6?^*Q{x0$mlcU;t8(ZI(Ml9SDWZ}S$m*mzr z>ZTlzs$y)biCm>^ona8|LB(_bI+|`3ERI#%7aVuEx=1127K_}5l4Q< zE^nE6&u+Q(HvkI9NW;Obcwl1KwfcvX`Wte-7b(ns9Z|NH>=yvT$PK5lr#8q+jqN-h z-Lz%iHm@mY4NtW}>-_+QohLWw16yvDi-`mOBDwn8C%F&8cLT_6v#3W~6Mxv<*ybl( z^nulONV?&D-88Gk|h<43*)5XAh z2Vk1?y9`SIh<1i{H}^prXcLSk*2(tY9&M83241`Zk%aHBmfjKadjAqY(l4FYe`z8S`f z0ZA6Lw8s=59^+);v%e@DvXzf#;hMeKtJnCfC!0`qy;(wbdVHg5j|jfl(5ZbBo`U#& z2T*9A@tWNkr}Vaan5US^mL5)#h2isM_mLNI}1I`bCi>{pw<_AK?C&AbXug?a0lKAqJszKu^(ytw-SK}xW(}kJrh*s92KbZAVsJXc2!y$reVvt|@mjjz(q~71tK^gUKm{)(cN%*DMOsw%v(kY1*z)XGjK&uY z*-kc4&&3OHxW)evT(_pj8zj_lgsKGHq}po z$3C+A0e%M?w~6ps2}k`9mqYfcxyE;{B#Zg{>-?c|+pQm5yY(wf5Ud2^Un zT4S+vkq+L*x5W>KzFvZw2Jm%8YVMgsLC|BC1|`~9^n5&FVs0Kk6t;PY766?+V63(8 zLL7}}w{*_R{!|{2TgM;hvY353W9apL>&qp#y9e7f=`n-A5D{sbYKw3) zO(Qx;7jhOFe*ML;$Jj}>2wb~4dNrl+vge@Gz;ftt`(PPfc6*Cl;I;3JM$}?3Paz0l z_K?gTFZaYEOJUdgr9kQ4tRh%UOoo||yePd3IKcEwrG_iI+ z31M`~4TBR+)M|2j4RSy7B{MKF>`!Li94l6*otx!$MA^?VD6%HOJ=6i^tMHY*kG29| zJ0qxL3blD{D7D|7;Gg+JR77X0>C!*k%b6aj9BW9XQ}S*?n|TVv;gKtzx%evYG8vOU z>+bu(j9^(NB2SC0R@X-{=E9W7z~WG@{cOYcG_S;^gOAB1v>4#erB1obXzEB#2OS%T zCK~`r5D8Acy2f}x%%!Kr+yI>YDq0dS&y&MNLW3vep&{iqWG4i^pFo4RwYyuEfO4D& zsHhIYCMn;(_R7V}cn+Gyj;>9>$WQ18h9$%fIGBrP$bW?z#cm(xc-u+&VIqs+Ts{rL zux98|aNJDy=!u8WOTqyPB1>Thf5!X5wmXt8V5asfXIf_%k+1K!m!6i~t5{xH^}ov^d+@vk*cIdbfUeiQ3Ph4>D4l0O6W)<4kfEc&X`q zAcyrBiLbdXuXcUL56|p;{SSk$9ifnAf!tqxBm86P5l@O|_K(v-Uu}M1ym8-+FT*!M z%WqB&OSTxG84#~@Sq*=Z`}~W>k8jJtPmCxtfVvLm<8 zX)6sP#r$Q9V4M3LHykXi8Z^Yv?T*ZMyU?S?n~O%5y3;Ln(N#7VlrIo#Fx70>)cOcE zknJ*yI#)ay7V`s?!>46V2MQrxQ4w0)HHP=XM3^@{r{^d6R;G8CeF_L?;v&WIZx?pQ z>$Y5Y6Qc=?2PuiUu@4<^k{& z&vq}%{m#8Bdhsf3rqJ#1)TnSVf!vM*nS}=WBLld3KO1hjVW1EILL7s<7e97!_*QE; z8viwf$xg2~fjzHxoyMd^Q5yJ(iM<{8o=s0z+2m#F`L%TRK?fGl)@rtEZ|l{&>+aNP z04%*s4oEH}#&Vr_t@8SD0{7`1avs{LL;qd5hKTAaOVFwe7v8(-{SF3ea_#R)yk>JM zNIvoWSgwsc;At4&zhnWEdZkE;Cv{|NqD1y~Zy=a%f)FF{rO@N)0bz;o8O(3`c}l6- zZu<+^PJ8~eo}mYygO63YGu}OT6XR&1P)UJtoGj|oup`rGNj5M1i#=N*Nevml2NUX% zWjCX0S^lrS51KDP?oLDKK^~qazgJc`1cT{{<76zN#zd^~9ufe^ljtf} zX==M8>a}yzt!eiY6dj1eM1)tJOKGDGS*A;v;0YxnBH8-5lO7ARb>GaV2VDbF1fkwS zyKJsS^049dtyjH({OjBYQL#%wrPw5=IadLRd35JdNt)B0TMdv;xoKt|@UFru8v4`mruo|42-xmEmmZLu^~M+&gi2;nDB5+{NE0UM4T~MC%M^V}aDnY&0I0nl-s)Mi~r+JuhLT9CMPrgOV6?WZ1HwXHV7 zf#4xo&{*dtj_)!b)mkF%ndCImA=}$Pg@2qU3St&vdX(!l{I@{h=I0QnUEQAbCukuE zCc)93ezKk;-Fugu1mKFj7A8+^DDNB#>)^Z@a#~z9G;K*c9DdWTdbYAg60Z6PX%_%i zXC6AUm+$lX!JuKZ05V7-%y4R8;@Iy>Glw=LadQU6n9BwwkDGJ1Z~F#lqBaF}mlnie zai-yW4t~RrvE49*&BiH&)qGH^JeR$dXePoDz@i2H0ePqo$7+Dv{`PAbYS8(m9)@<(ouZq99~cj;I!c4m$C>?G_;tp= z$Td5{uOU^KBuj_Nlqji)$#BA^Fz;%oFqaf|F}j^I0oRGQ*9ic6JIKG`ND$rdT0a99 z>EXa?uJ#tO9vZRS5)|~_x1bQ7J<%_l{}|8rYM$iGUf6?;*>osiJ~QS)S)eN=GsQHmy^O}eF3)j2U)`~+p?jbyVp2N)4a^CeBE{-`w zg6@QD2_xI_mj*U;P=90?*s;>(at=N5oIL1- zD$l*74#}u-xZj9xY;b}GhddUBg>jolv&V=D0^ei9W7FZ}b8tpoZa6RNq+Klps57})p3Q_#8yOfogzM`Q$JJ&c*%+k1V54{6f%4}onauJNk2 zAKosxC84MFA>kI04+M{&T@Nj(P-v)iDUpYcsl&6X6dy_;M%jdEyWkNY@*w7o5t^?b zR;f+Q;ZzfS(9rz`{zGfWRp*kc?F{T*ujN2@Sfy;BU5|aKH3L^<*A;S_jWhI6pJUxRZfC z4-2Ca3mW2_k`)Z}|K?X~1-k_-h+ z0>M@D=z%A9jdjELPu?Ix_S*%51>#eD+!P6!It1JXr8C|Kyb3gT2wNjt{+hP!CmvXW zvW7{&l*s#-%5|za5hY~e!(y*RRGn~Lr)27zCq~jWZg3QnwE{Gml$$L{_Y`>uTStJ` z#0Li_AR&MeecH=A6QZDm37cdxeUN1JQH`$vQ;Mc9&6sK$a+Q|gDGrYyMra7r&i_{G zY9uv``!VZXa^nXJ9+-*tc_>JgTEaZ<54|%H!x|dsN_X761HLqC{ zzS(&I^x*8Z(+(sQj(27!Bw*==_bu#7YfuE2ax}qayu`|Fl4=(BK0g6CRvlG1RHRJ^ zcZb?`PaoFrhElV%~lOf?CXyR{b) z9gRJVsX*yf%*^J8&5I-qZfRRHAP)pBu&>d*x`mI|k_FBO%plSk2@EeA-U@wZ2I&5C zs(#}rF>qS6aZ#o-@{)bHLq>22SLRa)hTY7>Z348&`6nN2Stu=ACn8-j5?kIVr0oy8 z?be?>#NtUKi*5EUG-=rp!=Ek_U4C8mEcySnb>87@whbRntWdSpE}~YK7_F_gQmg1w z)LvDO+AC&bQz}-Cnk}tPRMo28+Oyh}KeDC+&e~5A9h#a}sbzSH0 z{OwJ4B>0b%+Z}VQxsJDDV6=VIN02xaW=%*IO`=KjtX58Q6P|eK;631&tE0qgC>Ts- zP<}oX@;5|47O^1JgS+z3{dh8&FT@zD)GA9#rQ){+#gd>iT?ECL%oMz%eI7Y055s7$ z!N8iZV%`N72mFmdD~0+o>7bYSr(I@NtCC z(~eEiZ9&o(@G!oR!fDTQ&bcEQp5nGA;!D03SZb&+PWtqFtwG;&a4-4K+k=$s_Q8ET z3g2^2;qVbpeGT;hnXETM*9IiyV?e)Az@;HreQ@VT^*a-CDot|h5Vu_PZQa@}jL`B; zi%}@!H>4ySDj;Evl&%fsS+GkCG*pm9$OS+ymo@G`PokUY9w|p)D8iyVQQa0MOFwF5b>q=503oTY}P5A4N}KWu0rm3ovbM2Ik(EfgYV{ zY~adjG&nndH2R9X*~FuS(f_WMn*jn2>7;-IJ4{T=?GWoNv+Sj5IltSMGjPwe+I?b( z+gZ4{W<)BRe(N!lc6t|k(ioa1vTL>s+JycTs3d6;!#(NlQl@6Z;$i$;el$YC?~x>TUpfn5F2cvUk$FJhe9eQ!+9?_K!lun6lCHq8Nf_#TahZGEkWz6JJqGn{j z`B7FvuYVMi5e8w{w@=YkwLUQZZBkgy;OxE%ur!7lGi=XLYRawgNP{`Mny2LskQU;(PjUJn>#l9KCCfZE{y3Wgx0rN8slGsI~#S!3Q;N6bHa7%a(BrvD0a1w%2-k{^hUzuOq!|gyfY^BWCIqN`x#xdGFz6qGpW0h z`~#F}JfA)pg-|Hzl|vCB*0}H38|@m|Im{V&b8KBq36*UWQ7;LU6O~$@K@LMgAmoZI zG`HSsJg67dvkqK`P^OvHhv2S4ABitIR~QD)w!`bGJvi&-%wU6*w;+_cmuawb0Pw^x za+T^-@_7jEUuifx^lAU_KprYkd2*c#%jRZZar7+#0UFi(KKsNFqvRy~S2|`3h$z-l zhTDeO$V5o?E%vK-%TFbhEtg4wMn-Y>mEAS$jrYM=n!sQVhy5tbF~)>_+?uVNn^$O2 z(`TrPZLnJTE!db*ezkSt(R9~)0?Q#4mz;LYJX1%KLz3xn2XeC+E^_hd-RU+8>^H7O z6ur|ooexFd8wxvI&&`C)BWL=^SZ8FRv~q;KNyl?AI+@yQ<7=24jRIXRu>Ww05Dt-l#86ZY#? z8B|^mU;ZJ;`7SrvxqBtk`O0dhhd;+cpe?Nqi-6|lll0-Ysk`oEOTK zj`H?*m$t%y(Qqt>TjzJHDjEC;ni4Mn+ z;dR!X^lWZ8P-$m!GAw+3-$rewmIV#nzPo%+>choOqS^`WiSjH#TpQnM zA?%DgDSS3$Co2(`;KA>e)-M>|Mcs7C=WwD+>ln3_vuOe4c? z1C1dD;gv`n?GE(M` zJ;LgfzXXM`Z5lbVbx0c=7Z!USEj=VN9H=BclJ9SqPJ68u6P4!&fkK$pYg?QWzZP7T zY#+JDIkw5mf$eszCDeGX3J9*bhdRsc-9?$E8*(u9aM1Rv7jp5Q0VmR;sGz5jGp!p% zcbb{{PwhO^JMsx*yb;S@Y_WE+yV)dq`65VKx8mdKtcbU&UD?H9PcI)H zQ@%3XqV9dDkK$K5tc~$$prV#wbN}JOGEWCL{mgKI>^mb_dr%?!d}+XsTP(}t0rEX$ z+q4XP{eCKGV=?=<&(m*Ini?EhFD3HLm*c-f*`!^DG^S56V4owG!9h+5zX#2^aI$mr7@r-dmszZG5=Qo^?-9E- zc$Q<+A2gEV%U`4s5)t`&NCWYf3rc|?S{^CUGAB&yu(`4`{nmn>bz|+lGbZ|@>;PqT z(x%zk1aFaLm4osQq3WLG)7b4v9qBSF?vdE-bOsJvrFHU_7?t*;Qu=BJq80H6W{-P$ zLf-nof?pQvQL4Pw5Rm9n5MVJn+mtAQpPIMs7*PnDbXZ8D?3u_4!qm#|uG?H%HxDQa zI_x0~->Y>94?I9t`=k&{_0umm@$h($1utV|Yxm9j8%xnge!&M!w|WozzN}k)U!uJr ze6C0=U=2C;-KOd107RlRlmH8&@3vXe?CjOYIQD$Zsn{7btk}mIZqB?SYEMW|1@VqR z6sZDv`%%;`#zg7*p6oj#SzpttL6eY-2T|aBCg1)2gru%vsj=Cuwnp%Iaz3l$SKEJu zrcl~u)6{-#4s$%3KJ@+;qMIEos&;oDbfoQ67tUDQ3mmI#IUCa@U?}AUiKS&JjF_7( z&`uXkvHlQtwCCKX6i(a7QXZMhM%{^Tr9~_taEWj~h~!Aj=B{R*qOIi?dAvMC(Q+N7 zS!(GkGZ?8|d8Jjq45g*Q7UtBLBU^=J_;`I3hHF)it6Mlb7+unaOOS+9MDZl|K%r&G zTtt%~KH&m3ChAQb4Q!gNnLjLVp53RFtJ739jN01>cNXEtJle98csfu6Vj7~Fm0$l& z3h;=(w%}C%roxW!oGFaF;K1;`s|RZK#L}Frjm$0SZ%|?Ij2UON-f%r9#{xMW{-KQ>!K0>BFK`=z5Gt)j z@v710LS&Fa@b>7a3d>9;I|@=Fe!I0_E)vEF)>qY_ogQiy9H;U%W)NZV?Nae>`i7TD z?9;D}_g)*@7Ub3=xIs2~#jSa|#UE{&fu-(IG5&jFx^w~;KIke1JpdL3Dcxi?y~26+ zskgT6EwskV0R0P?w%ZGtqWtQ;Q+Ip>q)sR6&*yr0(w6|ymxb84gM8O>s zT*W3e1!sL9Ss|DBna7wP%tZyzufDh9v(>VJ=xk*(o`G*54@%P?;%V6qQUpIe0{~2Rl31`U_2B(@*s4H^il_^AkH@jyx2XQR*gvVHw zev{%jiw!cWEYjr2o>|X;e_vJ7aY^LEF*KJgiy`5mwOF@at`6C~07j=blYCp)LvTUK zzpQw%y$d+n^{kMzDS8j^(f+an0&2auak~``lm3gNZS4F#U9he4op*I|PR6z1Q1=W-2Z6#OjL_ITR^ci6WhC*tr z30Pfs0T$o2ff?jR`^Mct(fXiHbM+Auu%6Az8~E0JLOzTb8AIa4ue6RgQ zoWC(U+Nv>=dQZSe^1ujoz;vT+n{^ko&rvm>HY>NSgt2sF&vs9WzW|)d^Ah@RIu44L zF!7dZh^8MEYN8q=+>G&!pVr~(F$>;Hb052+J}|Xw=84H&#K!weCOr`;BQ<5bv&_-< zbSK@Rf{iWn{9ve2{6pti;+NfvP<&B^@|XBz@+lJft;@*vvJeK==K>Ms^QiQK05kYN zeJn~bu0+vmV}l*TX`2*$L2@u6;Y7@V5QhJQV44$z`}hEB^?1Y1-DS2hlQLo(y%E(i zS-f9mY~9!P=x4ZSrl&7e>=nXvs4ELBE+5o)WX!DztZFFd$}oqvy=aZ!k??m8i2O{C_A;QvKJzxYXa~zbhQSh}Pa;eFgtGGMHnSDL|jB4$B~!o9jQq31FJ~ zjj+_Ma4cMa12Y)-xzX>dWIV{ZF-=z`WuB%kFZ|&cLo1LHA z*Y~3jw!QKA#gxMNHY6md^Ih5{bt>~}r-IztOX}a(km}!W8wyHQ3uTy(rFCXnOl>q6 z2)rp@jSpR(Of4f6r?^%J^wh+E5&}kdXwOAZQutfqAxjfv9jLH`d1Cr!_vq!l-?01K zGU%ew4~UW-+(qy&Gpc7wK@GV_(~olN6*Y%>TtpqDpQOXj=4T%D90?v~5X~={Z8Kz7 zUM#w;IH_e|W5s^}Is&hR3hOMfdI6cwGYtdy5$pz$Un?%B<<+j;ZxF$xaQ?GP?Jju3 z-)xTH>;-qe{`nVHBu1i%!Pboki_=T==XUN&6^iJO9^ahuYf3i_UQN#M>F?ZHop+je zz3!M7)|UzV3@41?vl5n9c>w^LjU^o7PUg&iUt~nkkn)Ial(Us8K<1zG+A2yIruLZ>PbY^ZNNst%1Hx ze_~#0{ZR*jLJ7tAQWJl(0+<8h*W17(6d0i0fi%O|a_9FgiZmZxHOW)|&0C3XrJYU+R({2Jsk=<0UMx>kBkN7A_) zX^4yr_=&CGyUlH}>&RC9`;hda`KPV^TjMvj1s8FXe3u5*e3!S^^IdAS@?ECie0QC_ z6S6+F^hWc%(bV}(gQiz0(w?S?p#RO}?G-0d-}P~BX}!NOr9yy_-t-HpBRQi1e%cMh zcR+x3R?>Ijpso>UpN~cN=PR8BAX0Jwvq&n5N8H1+7u$yaNd3;+Or@JGkS(bDKw~m& zxqt+-l6tMLJ-uoTN_^~2YVDr58ryYga1kK7#-#i#+MCR+2V}d2yFg-xl^*0MUza*t zm@3cJ9{zaWUhfn{(77)e*gOZQxkT%=QS5NGQvH9?>ZIc1oWhblE+9)?>Li}WbQ3Er zPn8kIUlxjZO}*OGLQD}4D3p*hU=iF8zk|S@Yp6;lPnYT&c!gr-nG0<1;(76Dx7+t;DHdpXB`&gICOKZzY z0k!%33&2M+jjXdJAHU_hO$1(ML6dgRNG0?jhcoHKyJ-DS41m;K&%5AKYpoW$l1vX8 zW_Qp5U3cEzI6Ei8lML$LbdOSk1-G%QL%TiiQ-cQmbri8jib2o+di7kUnv}N!+>-9y z*%WIrR3eDrr24sHCa2pXpw~vLJw!+%2mry7I)UvelvEzIM8Xy?fhT23js==Wb+^e?i@EBX{Mg*QUGE`6Pw_q zo;apcv-qwwC%|eRdtK+h_-InYK?^;cEWKpkyRiIF9p+S3_Hw!)L_o^9@0zGr^-)gS zf2SCLuB7esAYOU9G2L0gBg5lVW9AyI;gu&00Xlf|%T8S_FE+o%_*4*9=$`HD!M}R` zc;LueWirXj=##{o*yZ~o7O7*zM9oO%b&4SHv;zr?UyID+yRsYc?3$Pnm` z{bCYZUIy^uE7NL}k8fv79*Y1mm(sE0z{bHKxmx1(IR#Dc%Y8;G80Ycv3sLu%l5536vOm`#NunTU@g`Ct(U`x3a8Z^bS1&IMo(J#hWo@fT1djX^c--)L!p7?%_ zI^u5lY7JOB9)+OKGP|@VRtBZ1nt%Y|M!>@eO3*0Oh z-Q#)|3RlIK6eJBf0zasusu|EUJd%k(J_nuv%Z3opzb*iWHwm9N$dmkOnpqittsdTo zI!Zw;xEI2bNg4gV4wGm0ZMOzZ-d)!Rqc+ME1PuK^vDW7q`#`xJ-%{T@<%JeqXTWt< zgdX^VD-gPoZ$4NVxZxC37~nQYW@r#@GaIl`00z>xV}Zotq?S4yE+3?yc|6;jt*-Qd z8bR*=SJ`!akHoH~PtTonUGS5^Lv?@Y_Tkl)H?Y(3P8Oh_#H%|~#-sTtM=6VvePP-j z$A1$nw`zfTU(zg0gBFv2FM*@o@7TcC5eUcT5(&@!nT(!2`aoEz@tS!wInneqcK<2C ztB2U${X0KplyD%i#+TjUbBDYK>w;yV2pVBB)=*_#aMy#f>gmO^{2n9z=ONfvi-Iv< zkreMPe+4-DThF<8ly{91(j~#-*xi#0b}(j&nU4|kFvI9pec<5+RnK}8F;CA8mfia` zlK9tGhMPFHp(d>78~@cCq2esO6M!!p5@SVQ~qFXU$O8l?!&P*rk4tmwH-=1D+9-0q}DZe!^w&Xet2 z6^%zRoRlxVpIp%X=g#ZT62uTn~*@y_LiJ^cRLGF{sq+)$O^oc0d6T6 zBG`p^Z7X;L{gL(Ob^kmn@sh748^d5co1)}_*b4#p@2X&QPkLrlf*SP<+3r+GuW!-qJU-zqj4qT|xFxM2FaH22_Z_rSW$-TV2qZv4MOn#@{+}1~IZnkpL#Y@L zsko3|2&*NlAN(_|@#pRIu5_8}p*l`$4YFuk?*gRwe{Va;b5%k7e^PG0_61O&7W|)c z(Xad)t09;%`Sa(WzdD@{MmE3FZNH95VUzmgP9on!N;AnjDbkt{u<2+TXq2kiM*I)( C;%03C literal 158281 zcmeFZ1yq#nzBfEGG)N2~(lEe7NeR+OI5dL9fRYLdf^z`2XU6g*?l}f}cc;4T^vV`1%|0gHV90m{CNYA*(9X5* zAvD<$+wv>RFvYCMOz!R87-e~8B2ow<|7#Xur2Hb+^ye2vR^`t_^is&JdiLjAU8Z`G z=UEHIeR*Vbn6mtG_qDXhYvb*S&b-nhMq~P=tq<*Sq_<0|?e{wp~!Qro_3f6L*DFNIrPO-2X^lg^FD3#r=sa{KEA9M=@+T zxAiSM$YLJgCTV6+a8aFQ4yj#Dx<%4$-uLh6*_I)Y?xf zK<=}J>}D>apek(U<#YYOtt9dAmub1&4qmHKYdcY*^X_O#&*#hXMlOm1vM$^`KeWrF zc|j&s)*-iMiJN)BUG8YAMNbQjWrMr|!Wk3s>>A0He$jMHgvs}6GU_zw4YIUQr&?Vb zO(MUEVgs0>88wo! z#e$aLTT%+dt-sCMP@mfBuP>y)Vb>-uQ>e<;b~95^;QQD?p!IR=3;dZ6zO3khM>k7} zWO+11X1un_TA;96T0u-!oeJ9JubI&NzEd;hzU(~`o&G3zNTqrdsHnm`s>qUApdWXp zl2^swA{eBWr0F8hUuhlBYLQzn9?$MaL9$7*^^8i#6_t7`AXu6M0Tm=$40TWh>v-6S zg$`sl%=HyXXg!3Dkr}$Eal3NF>#lsYP9y_RNdDig2?+ zr*#6c+H|4*^k*&vQXW?o;@B(80{^tf@IU?kUG#6>MShNAjT4RI=)P)>WhO&<&+N3Y zDkeJ2-qJAX?YTXk5%6R)a7jq*w^0DI>N;F>&i&_P*|dGrb>+0(^7Cdx7XDkN|3zH&zBB)|9@l_Z(Ui|JQ3$;-PB~Fk2=S&MUSGnCC{FppdFxzPTh)*s+fJ;gc;U$P`B4Rh z!X$!)P}v-(&T*GqSyZ+)Hs7-_3R&eL!`6fHH)NfMntc@|54Z#yjP2l~F>Cu*DgRlm zmfX=HN#kF**mJ9T!;uEVQt7@r)Kmo)zxnY%;(8biN0J~RF@@0TC_xPni-J9I?;wdh z{h*BCNUcat+tI5UsFqrC=b`;33O3ePzZS^g4c>BFf_NE*hq(s26+0C6ROS)nBLKH7--B${e`Nxy=gP0o{-+(qj z`G$!~B{BnRBJCfR1@aM?JyCW};QcU&^m3?%4JAEx{P%pQON@SA$8Mu5nBI(7QMjnXHPPOo~hzdiazABh-G%_}aO;64l_f{o9 zM@5NcTe3JOgkGvAu%QVJ9#z$e(1vJi#jpK1#&uD^mmMP05{i~_g)S4I$byWV6~RT! zOR=RDk%metj5%=$YJP}W-8NhltM&U#hlWi>RXY`!KF7s}K5elExE~X{anzNHv_Nsz zrZn|lA2#>bq&6EmzWf+Zh2+am<7$X<2?`7Bjc5?k2dSmS1)VeASu>RMNwsHy|zm~%6>wmjbN0v2G`@ELZzXYEqc-d?7<@9^U z#uD!rjtg1aZiPlC{_R`4CiQF7xmch4fy?!*jpLr<#jnJm zA;@UTm9%Jmg*lZ_#k4jDSuXmc2#d9#ZON3_pgV9N^30#y+S5(SH2ZRXv0_cc67Un; z47M=XWTdRJ)(ZZ{K6JxH{$X<6kzyaV0&7lRG?waOrkk+P7R1XGyGp|@M3-;V0?86# z8!?Y9Ti{wFt9Ro=FC^1D40w4D5F5!*av7~&mx{i>CV5l=os3IPDD>%pDn`Cm5tAE4t zdGO?~a+clEUO-ok9Ow36Qx*Llo&FcglSuca@?uEmrqKN;@+%Vl%}VIDhp+mo38cWR zusE-|Ki~4lRFU%LEa(E9${oc6@hImb&`SB?jz;`+buUzZST^-5>Q2n=|Fm)~80STh z9a>PC4iU{t&v{u2D{#Zwz;h^+Ex}*uuVsVV<^lnD*~DVO9l3Vv!|jE0rr%%Y_TpJq zZ|i8Nngy;f!EE1tBWO+slnA=+8^^)>SWSf-^63}?u5~@y!ITuaYsFs z@@l4&DL33y*H1V+fExBVR$K#&Ahpl41Ro~RoF!WK z;7H7TxgvYa&P4BEPW!V*?}7h)_4{NDFSr-x5boQBR(IXI9qGjqn?hnppnmHLn&**$_j1&xR#zZ zH=!Ec);4Y9IwczI`H(xRCLCStnT8^?SaC`Ikp;O%nXSgXq|u0j7O-e;ONq@GrC6IV z_K<%rWXCvYq9j@GO~Q@fC~k6dztQ0Fn^A=lQCMqR(ATis{7jiiut?*G; z4{&Dc2uqFc7US~Mkgy=wIzR=a#k|Z2S7yAv30C!?{RyonbQ&%kUwPuT*w#d1YH4($ z2wd@TrS;NAc<557HG1XY_Q@m6RM2TN28RScGA-m+tFKAlaiJVmX%7vjHdYPbV(dj_ zP(#fc392l@E>4d$<^(^x?=NoXTHxNxO?L7papRSN>viMd%_QR1eMaakkd2VR@sbIv z-Kb3JtPO}w?$FB@Du;o!nG6hN3pZs+5=)g5QOl)S%_6BA8iD%U6DobSY_3AN%oLks ze;IEgBK)cGLC87bJUMPyWxK=zAD9K$7)Anx%86kb!xA4VD~5W%ARSco%vmebom{yU zsiL$FB;@$Ov!91<<@eq2R=>LnVc0S7L4J%OC8-u9e)YU4x0xlE1xX@I<*>_L|7xs) zw*Hw|plxrb_;{Vnb>8rMe~W6Q`9oE!5?H8)dn5^vG4C z)W*g{jF$-7V5RX!7jE;;wb>XV4`&Ggf?lP@@oUM{6d#+b#S=*c$MWx*dm+8mZYNBPOX>vt!$Z*pqSWuz(~}O;^>9 zLsI=fEP|m|W>f9%Xt}#O{l|q}UuxpN`ThGmaO~N+c*b~M7`%+0JnQMM#!y;brg3*t zU;4N@E;gB7ElB45bw_kR8dBnKx;nTYOu``Uw9-LmUw^)qVqdd*)3-*|$A@12r~$v* z>+7wkgSBr@2;C(wUhPv+y)K3bzv1*(J+-@2S0)jztdcV=I+y$tFD+g-M1F22?Tk=e zV)|Az0ZmMb4l#F!n4A=t3%5Uaf!%#ecg9b|Z0G(fGnMv=O1kZ|A2cb7YDIw?9qJ<+ z7AvtI$&ER4bj$t8iY6g&R)@ximUNk~e#GA5LdZnxHU-AOGbx}!T)6mF29z|D#v?kx z5N4aPim`Y}0v1T2q8HUNf$|n^vXvBORR3QSy>@~wwXrOkbVzgry7~Et8mM;w4voKCP&c;J;+Ll*7>aJ z@*!5cA6NdP84+1{^SOMQt>09Rj#;+uHC+3eT$S8k15TNHi#gj$>)8{x2bv6oexDE{ zdWJh}f%y5f+lVj@=3=@Rx%*dcbb_ZWl4aRu2Giju14m&GvT_jeF6OybE<#SKdLewV z+J)a`kq8?w3MyurUrzk6&P6pWwlG7v&{SRp_ALbYl@cpZm^bvs&ypVn_rYY9)>GEK zX@O*5L{>xSK6bV%R=;pM#*TIE-ZOyZP=8rBG?$cKW>rz4inQw!4!2X(=;j^@(pJ4o zhhG-TD=Q3HCvvR>TPJ9QL~9>Ys2rOC;Dt$9xd z%e1c07fko7u**z3xjK{~={)V4*pz91OwvhuZ$_hITBiLxx_$MOkMDY6iMZ*r`)u7! z%)<5`ySuxX&)z}{t5O8LwCB-enR(Tm=ay~N?Ap0ln;TYi6$E-VAWPXO1krIZT&WBk zTvG<&8YF^BjdPp%lo^PWxeA0$_u?x!t-aASYX`c z8z;Eg`y8&Bp$NYhcVXBm8*^3)I@RoTU+?;jf2vn#CU-#c!bi>?-2XOR8E;=?7B<_r>~kg_RNb$|qq%dZJPExy3Vx44 zdnQd%^|1donl$$oM-twahJST96d1G8uBCrd8G#f2bQWFfeV_+rUM8xkQ}p`rDr8 zh_=63X}uyrPHk#vzNa=alq;W0@~J(UO>rfgZW+$d?{!vuE-vnDqpSYqm~yn?`LCck zS+ansxd2iFixS<6A^Vc#v`t>~l7Lc2RGm_f1sOHQDex)EFfE&8xN)R1SU2Pz>84`z z$(*n;b3UEyV27upIe|->ES8^Ao1Tszi`%UYQWlBF&EGu?ZE8dn%uVb4D+aJl>OY6;@pea`WdIG}heK9IYTS>jh@-j;ux!!jcLS7aVgTXoymi%P|r z;}}Z}!K{ycU|~#-645C!hPmC05i!}gnSy!RC}@wehuSNh7d1joj89-hYk0u5F> z*?)pWJzvyTO4uK&&kATg3SySm%W7_xw{wk=P`=cdX4GcCkjkf1nDQEN@z1maNz-k$ zhqHfkg%E=np@t8@Z)cun$^>pa16!`!maWcFhQHp&9hRVQZ?GzmEz>v23e+~%P|%g; zg11wS#-@D|#jn&eBrlu{*mx2n(n_B7IW<*Wu&_@N^w;| zPN~j& z>{^XXa5Jk}5m$4Rq9VO?bSgqDZQA(+1}z-Y15pkj$&(&Z%7XELP8vksmyN7S+;wdG~6+kboehSLYw4idMr*b zt3KoOT0h)Hr#1;oDNJP^PV<%?FEpzTT+I%m8Ek?X4fa_XZ3!d%r+M@fHYy0CDOAjN z4n}c=@e^3b#h1^k{*{9C4_X2I=C&1huNI-!wqXadBarPlEXAJ?a;BY-cz{?q=^0~} zD3)J=4=2`1xq^wmt|DCr+|eumry1$(0cb+>_8iNM5eZCmr@zRM5AE!`ruArQYMHCu zoAa2`{|Ev1TJZQAj)r+k>kl@IN>742?RWN`)uYQ(vpsyztXalo6d&EiX;dcjCw$RA zYd$94a3>D(3k8-w`xlsIb(SFS* z5C-Z%LOC}=xtn?7rWFA6)lQG~Z-ZBvQ^_B~<@9yICIvHmW_GMxYqw3`VFW_CQQ%nt6$>n8I3(uEFRX{;yYT zw#B8NXQm6LVK1dvA^*lp7w+HF*W9VA!}o2mWHq>p`+UKVZsdu6r8ObF8EwFZtPc3J zNl~qc?Kz%J67QxGI{%DTBzWT97Eu{ROkaV{QrOgLs_p zR2wH9(DHDa&*5RiKSF0eTSfR}KDBV>=x=b+T&bj3@j~1wJq;jKA`Z8K|DG{JlMI;kSwbUjS=@&bfJrKf4 zs%`s5gr8SQxDbD&E!4!`!PUbhPKtYW*e~(Rg6%gaF@)KPY-#l93w~(g+esef&O=iu z7GS-wA$YAg^QM(5WS}o}&R_R0N*9tgZ24Tt@rTF@@lugnQ$>xu+?_4_}mvX{?G z|4t&?l`U+u{*CaO3{Kp!f0b43LRUer5tk_a?IqjYDK+d|mJ`C^{VV;p=BPD3L-`Eo z>4Jj-N~j#=#*8q#OA+LQkHQ6La4n-+Vgr&q)jr0JyD_xe?2uo53b55Y|GR!QBpJnB zmK-84gRS)j(6TuBW^s9gb=WOPk7!lGPsshPkPQJx9zJL{7cq3kAjCqgex=DGcsY`f zgqO5)y4xL-#*O~EujXT3wyS@W8hzPLicV=iy*_dQ0l;Qw%hY%6`+7Q>7UTBh$pU@H z_31q3t!VvXC{Kx)%f>fAUEC^VI2A4O17zg1D*5o{(@^`{+NM<5&7#4mZ{sFhz4}@C zp4ZNA%ur8iB!u3QnObqf4nvOQH(w5(rqY%C;YI;s365y(!t4M_tvhzcE+HC4Wa81n zYkZonah zoZTO5Y?W#N?^X1YikfMjKhTtP%*HJf8TrnXJ-YH3qFj*?+%5lEXcZg1ReStXS)v%PgpT4#HMZyVl+rQGtg_ko)hLx zy%VjP=zBlbGp_HCTm&iqcpd3$o_l!QFLTD)xDrMiyv$=-1TbwHRHU7kySg=I=R}?J zd%f=_8oc)3>^`c$Fa@T5U1+KF=?q8HS)Uiv^+8_a+1Pr={#kQ#O<1J&3TvtF^%lUw zIROZ`dhu;aZx6=i)%vQk#ioC_@S|tn-gjUrpYnYdQ-~< zZ+f(V$D)KcB8GfB0GS44e<~* z3^6&XBH_5Err=2oGgB;BNk&f{J5zEeoT`82$sY4QQkMYNd8x-t9Qo$9f?^zW%@7X)VH79c~m`W`>HV}a<>UsdiZa1lcz5uCM zvL$k5-zcc+;&ptlwSe?wYp^mHAcb&3YU-TcbCUFNs`SCv+UTY4BULQB`e=Ujp53r` z2}C$QMIL*GG7ZTQ%F8Ulxc1WF&y27T#jpNr;nDtBHw;=}xwRS01FdAWc#jnNjOb2E z`YEyyYg1Opg!4>1(<~%5<`bbKRSlP4<|L0OgqZn97`9MQEX(oD8g{!og!EdG*`g16 z&*eZ0%x?O2>){Asfk&Z_<}!fB#C3O!+4t?NOU6na9wqfekmx5eRvrTytCDt zcmRB2<`4j*S4LJ+jPQ9|EPZUH5_DGxb=3z53hevW4(wlFwb_t6Dpqof3%#GkO^xBz zJI?aEji-A%TAN&tr35C5Lq_Sfs+b98ON)Mz8+9jp4p!CnK+&IdGx{jkN?Zm%6Mto= z=K)GgAd5|qB8kHJ=myJgX)HpPzmw-G>(zwcGVKVV4mvKdbk0h@4fn*-7V&128yXM) z%7h0Es;9bE!*ENL%XU<;{DPn4GnK$6BN89L2DM!L*|fSRi(x8f_HqH^~@C5ATZM{bd4t8fo3vls;y9KX>?j z{{DFgg=zTGMAiKM*{@05$Xq^LG>>k#N4GEy;aiT1(VL!6Z8~@#^3yl{eDm(ze3N_Y zEHHgv?vu_np4G{SGx%*Yrk_taGokx*CYsiTs_IXx7%#7cGB7<8>2!E2SXk?~cj|T< zuU5_$TZ2oR(4Lwd_B%~RzdUxw$eAkqz3auT4-JMA-j;sIy>_$xLj8t9y~V~k8-2lm zdM|83MunR6$L6(cfTkTY!DxjVsm<~5YycZWArFP&qv}VbuzjS2zw5Pg9L(Y=)guU? z_1CC?eYs{N$bvXml2^41JZi8XjXhAXVU|FN5D-oj*=4W9vpKnv1`X|z@Jcka>0dd;_3OblR5T?nzGJZn%9LwtE)gbktn0V zkAlWAfNo!qq42*~cBPW+FV=^0DODc+1W-|J0g@Q5H2Ry|zEv~@R}FiJQQAiE9ksx0B{E-*_h$jT_)Pw#B{8RK~i5d0|@1IN=o0idl3BfAe#Qs101U0;E?g5-|mWkVu z!#%z1&4qT{W>`beFDehc4OZZP=fWW4Gtzuwpfu*iw~$1j8z>a=UBu`i`*Eo7>C@tb zLW^Um92VI~Y}q4L0~jJi16vQQX3325dGeQcb9nb_gG^=7Eq^bfhkKko$9=RT>>*77 z@fVNT03Swj-UQtrmI}BXkzhJAp;p)3-mHoPCxTCfDWQ|HE^u3N%8Z-h(J_WGU1K3W zoaK}n{Llp@73x5u35tJVi;&i|!vDq!Cc8$)DGZ!X8#-Npg-JYkQ z@jo`SU~41d^y^#d1D$}JRa6@7PLqRDN4s_v%Dp7T4*sxLrYy&^C@ z-*k49xmayF9FO!pO<}w$SkAco?j?h%1U~I~>1jP!k{vkIMh$4u~X*xa;%QFqB z%bk(s=L&e<+NNT^U>CKq%Mf+rUJ%#(%}IfgJF9s?mpgTlEa%<(TP1Y^zVAm4_W|Qq zyQw6JI};K;o;XJ~T_0DIGk@7IzePka%GbYHcd3V4o0vfQS~z}XWz6#V2AtUUW5Si z$wdld1)k#(SZx5{73ITzUBF%=Nv#DYjR2Sj_K@s`@Bal5Mk4~A0%1sdhV%V zc74%Zrqw&G^QTRiHGb)f)pv9IAppQ;YFZyL^>|g~>wX2uN$L8y>lwc2AZnAdF4jo( z2xoe)Jz?=vkDjV#3Qeh&0mlQH2gBlCVm?=Aj+Mmj70p&m5zdrVD+{ z=IQJC)3hURdMuH?3iV;D#a1Tt-j*rmqL;7kXAi)sttG#V06b;a#}i(6NTg^u=6+d@ z7`;83Jw(seK%9-dY@D$dy;;{QVyb9tb3~r%>+4%`ePWBuyo<>Q^|25qGknJRFGIH2 zfB2JYCQ2S#4x8AoZNODcs%N^QvYQoa+2Yk%+7cFu-)T_BD&K9pIUA!o3kZ`npJ+MY zWqK3j(dR6n*?j+`2pn3!)EDOb8X2WOY&a&vHlXaqPYJYdBtHO~8@JDGyrjycffMM~ zy1lRQ$!#vIi@OgD4yHkwC<@!3?fX}v)gDi}DSw$SGvS3Sl^gN8n}EpL6*MNs68fb! z9@$3<-cTg&bGiKuv;wE|0ss`T9pj@rL4Yfilr!2I$y>`FS4*MB?ez4n2GXp!gdKKx zA5^P_CB#4^3=$veFrgpxeUpOst1sc&M&O_v+LkH@&k5Grj?na<8w>QUW)IYQc>rHCFUi-g#P$_bN5{i zY0qgYn>=l7S7@qs?{6}^x~}3y4>To`G!NVuymxv$k3N_{kA)2So<_J+5uWt1HE7UcL=itS%-#k!?-thZzDb^}Y1fJ)vwdJlWwdyV&} zH5_&uPEFhwgA$BiefP)0D`_~H0*If>_sdl-znm54{mb>F?)O3S#PuBBS!8mQ_|P=E zrNwF#ZV?MA-j7}YdxyM4tuSUZG2sQ3P+{f$3L1sJ&}2EC@ER>dU;Y%ykOie6k2S7UtYMl0%jv5Y7QWb5PY7phMSkT~EX7kUf&>w8 zW;}odqv4<*Wf%u6x0`Tr=qF(m6e@%Yhd;6APo%N=5r-?*oOugoP0%G*8JH-Y&vtiB z5h0jmEeTK2YWtW^ldWavdNXKd8Yj5=;gmm@L)G^i`9KoHPGXU$5rC+J^<&1fT?^;Bi?8FX8S6(ygQVKx4SC4hUW-7ExV+Pnkc>;{lG;Qn2Ko)=fm^}IVj ziI}#l3$KFkht#7j?W5~uKyJ%%rQSLA$w)HO!}|9EMcIT4BxTU{*hfl1&sAPw)jd=Fyj?y8lZ5SFqciHO$d;i+83yAk!vRQM$Amv)Jv*>TMYS@xv-Vs1 z6CD(&U>9i7MNwF}CF9B^mzBhDv!TA-6eC_S$$2McsK$^_p#_sS>f+F02dae(=ge)B z;ASgQ<0dm^&zVtiZ!r12_RX$C$A&oEG4QM6aj+6L3#tU);kV77v&7$pq_jTQ(md?{ z%An}KP%s_Al2K4Uop=7d>D>T6E>c55+?e~%@>qA?Z_sQ-TUm|lSu0v>tBzXL!YHJ? z;ev3KR~+Ax4Xlv3Tsspn&bZhc%%v zVNaE>Ouk=bfJYAvMApKZlk&^mM4t`r!MistWbYEW-NFgTvy*)5oqJ%Hv1W<+LyUAO znEbOCnUM^SqWuCEkA9VBMV3vo#a$o|BeeA&k=;SmBFn#w`b$9BVQoR)cM#e*4#AU1 zGu4k-@}Fz7Awvl5p0vP;EmunDLJO%8wQ&<76QtrYA< zz*2g9<|!q9dhPbDgQT9i*U1_GG}A50+nQX?dK7mBK9!a$7iIAg7+fKo6*wALHTpkb z1LN9woA6j98TCQ8t_oE%gBfcmS6KvM_ht+sTwjIDjohSkLJRJPC*xr3@^3Pbs;4J^ zELL+&6*a+wN_DQUxici%=fxw=k4QSd-wNc{$L{nwE=W53=<|Be@ZRO#`=&u$i;LP) zPqB1UF%yzb{!@pm32OVZxc10;%l%e2zDA6%=~bF2u#Durv&^`>$jW$qG3Dla!9RNt zZ7=Po_&G4fz>Sb=Aebw=ewSD-l0iM5|*Q_SaRL(6wvY~i_s7Y4!27=7Qbl(>eUR0p=8@O9RGmB*Az^CNb7s@82e zVMInw@rSU_+)L_&8<5i1+b_R&^qQg%Vu$&t3*Lh4x-!m%eAlKMx2J#8@vj8o_^N&v zfT!V~rdg}nTuv{ItN2N&;#-Jk4Gb4=J$O&@?ZNRQoPxK3mdZgnziuWMeUglPpw-T& zLq^hKp(^}<3zZ_QSfwR4FGDUjoZs0G;y5Fa-&DG>Qh5t3;@+VOZ<8WlgljK^3Qh#+ z{v^yFF6t-nToTRA4tOlcs1WiEt0271MeeBj$Q|wfuS>{?v>5-RfQ~~=b!vE|TI4#@ zBf^J!d2EhYxgnF3h@W?G7RhXK;UlrIS`~8_x}d}J7Z%~3GdCOpGME7#_)Q_X==|!Yozzm!!B%RzCv=ix^rz3fFI)G$ZrWdcJ8-y?Q4e0G zzA6RuxgSeaO;=+~*Q@gv_K|a^93}OZjtgzR&MU2#bLZVkGN(t9G6zA2k+YFsCo-hm zmoT24*D~iVgVNVuj4v1Wi%B}ioRbOgHqm0v8m<}cO9XJ=Z0gje9sT%qo7j@8qA)T2 z37pBLr$2w*7!8NgtUl_Cp*bp*j(_fDGfec94v&;^g*(?kX%@g6I!{Fx9>p`;-Ayts zD@pfE7&jT%REml}+pRy;aB<&R*SIJ4>AG0#N7NUlevym`kv+F^2bR9zPvg2`LLa5E z=a1hzIt)smIym#yti)j9kr=%`9-An)fYZMdO(6;XP8>MgNuY(WBhyO`^yK@Ai1K|*U9DSeKTe1Yf# zei_XU%#!KVyBR{)G}!@cd<`+dw-(#^xB`dDaA*5Q*U&H6qyC{-X{I55c|jFUPYHAD zS-INIAv@j+oN%3@*}LDFzo&mASkYymQ4sRsn*Z>kE@Tq?U=`%e1I@2kd z|42RoTTmdorZ@hZWt;RZ|Fu5dgkar@nTZ%V3jz~vfl|hANfZAal zONk}fV7sInxBDbe14yN60Zoj*(?L9!!o(oNKG zA1m&59yx5milx{nF@S4Vnb5J(Pm)QDaA?%p?SY7LC5H<{9D$EpU1^e92&kqBAHNb@ zu)N~>s^GbZz>5_)-6!Ub|HdwN(nSDflV?=_NsgBQq(7;E zj}+Q(yrbP_0NIpf?=1+#cQ;Vxq0W8MBN-!~%D*sx7a=eFWy<(Ham+SBnydy@0Jx-> zIbTb;msrR z1~mdWI&;yKOWt6&dk&OK1=nv<>zwYP1Lz|Tj~hFi%DB_VN{#Q)H}$pdo9+ZJV_xl_ z`mEgmM4XFF=Utx-HO#V%$G7+Uzcz`|tJcWIWmZ%7pNE4+*Cm>mgy7_j318QKY0P}a z)uhtB!%^qDBYtPb=_QAmH(m5!zqX{g&2fR_(}CGasu)tSl6q9%-}HH=^_ytJj|UsK zJ{ea_rKB@dUQmq0CgMsB7N^^Y;eEc5N2DMG-x&PyiR+2^V_L(Lj6=uM<_b@R_*XdU z&Y5&3(vc_k%7v%n)q`yLJL!n{Ha-<*@C;+6R<@GbT^g3XXF1N=fBVMvUa4*KBj(fk z#<^gjmYz2X&;MCu5{s1->Y!#A2 zg#&kTvKxdye%`@QqLk@pots=&2%A_lkjIj6jFC|HawPe08}_jUn@8eqep9@CdS6u- zpomaoi3p3CMNe$Pe2c>6b4`gi&U$iy%5>`&Me!wwE{$0@lgGmSH{}W~VBqJ#iv)}M zs#}lo|H64?xZtjT3?PrbDUj~V%wbI=Dk1kmR{vKsUu1E!KvYBY%=MBSgSViZnaKqa z>oPxX3_QjGgqbH&7}@^F^#T2816H)sa7&D4D2)Tu==Q%j$FK5v7U#m{`Eu?Ejy z_BWm5`3g(=nRtoaqhRQbpCKI~+nT%8>+R8Ku|8|`kr(7V`_@b$9-Ut09q+YjU-)6G zB+~bK+8%Qh0mMT-n5E;U`s%%TexHqbKJ;9ZfzciXuqhQR*Q__9%Lb*L_Xm9s22Ea< zaxD0w_oQWx$|I!@zFYb%Q<$D_VYcqiJFNygiJ^J*)6eW9eO5Y7uf}(!$|W&(*2`Rj zmo=sK1M#B8`8%)%0AAz!pyT?eSC6Cl?LHC3dNbK8%{dv5X0)&i0wuUdu8 zQW$u)Qe)UHwreUpv8Cz=Xg3*OZIS7Hy6NYhWg*H`Z7H%qT<~_Rcb{>b&hP`%Ai%X% zd+KXmwAlLcyb{CitK_B3TY2X2v*iumONmQUy#efFS*d5#njI~_hWOM(<4KGf-}fe8 z%!m8IzZem~jfe(P_e5u1-Z$y}eu%-Z9NebsS0++lC$NU7ai8Tb_&e~J92e@#f!OC| z8^f6aFGS+$`@@iIMX!)%;WiVwO|PNV+j8FBuQ8{-GM66by`~Xn2!`}m$G{%werIPe ztWI!2p?e$kY)pLM=P|+SXK%bMBIHmp2xLG^IK2Otw}NW*_N;`m4d^+KF*LtU@YA6o z_3Qs^@%&4I?B5y;hGfbV0C$)JEz9v>P{U^}7)0Ciy#xnJO8E=%RDA{gP(G~I?JFB^ zRrYsVGV`eX6)hG*)yHZ=Q4jxYNC4y@l5C6avkl!K(kiH3T zK?MH?HVrHM|5pn;0#Xxn?g1jejls?>@R3HNMUhuW_|j8hQ^x3tH&)V;;`DAp%_p^@ zrK@B17?c%N(>iZPkk>;Eq6TkA*KEemhe0TD+`20q{_j%hGU#O)^oqWZuLS*IQ%8-X z7&^M0ipfNr9&`Rm3|*y(ak%Ool)5ZuLVxvj+fr&;?OA?@#er^%<3JzSo?;H?&wefg zOazC_Sq9V!o7_X zsx364o9L3i*CMu{GqXr335|4du`OraUGAM1w%vSd$x&&x{j|s|;<>G|Cc6#|+vU9;I+*S0^1&Q=8OI*USLl|Os#+>ZCWyuK%}^buJ7-x- z$G*c0jobCFIl9izzKhY|acHEvZ@)D4+Ha?35_4#t7xw{Z=u1+kIq$>%U#S#8%GT1Z zF1Vh~`};}|wngB?TYK7_Rvy#y9x)wP2v^kQPTn&(cH?h%LHHt+)zF;5#J51izDP^1Przu;kU8~%I$b9JMa*Tn-7x%bFmwLCe3b4$I+rv4USyaCZZbUC1%b?-W^ z>9X`5I*;^$?ELmt)gfV9fpA?X0|+Ueo*Ojh|?1IO^3X zT`ikho}qZE_@LWv!9$GRa**28d!I_*$nkhg|MDfmu6|$9E;e|%YW9_(*=w$y`6djo z#nc=PtNp-nP-%XBwzG@2Q|8^CuHwf|L%5GTv-niFGNwS##Z&mbLup%XocdgmTmls+(qr7DX3G zl)mo$myg`G9xgz`V?X1GXHt@QDhchbj6IeL2u@U`i%HLxk+Kj>U5EO&ww@4?8;AEk7Wa*pOG8=M=O=k~9FvoBa`qX6Y7bRTQ&QBWq47`tm(;S*K~@b53cW-bOsCAW>d|xmRD~Xyu6X_x!zfO4#PQ)O6Ip!`DNo;;`vc#`Z{!TO6}z3c%!G- zj=!WcYVUa4&HEw}a~8RKapueuyiA%N-nze@etD7CbktYuR^=OfXh>24ocZz|2$z~> zoG>yMar5Y}I)nGFzpVRgm+@nYGcG1G8a!W#`7CKN)UMZ|yYI_jqWRO$oBDo0*U#58 zFrg7deANpN0M2^zDG#FnyPA8oxa2-%`sRSo;jw{b$~4FHXR5@^d18tOJVwt|;}dyj zEo_OUJ0qD+AD-2tcQx&tk8T^G%(hP;(gz$Dr5@d7rFqRYk9JkkMCwxCqmPdI_{T%P zQXRI~I`h1`hiy|H&h`DK&qn$D{8HqkW;YEh$8uZLtTdC1<5Js}$!YDC0hOntfCBVTplXiHk?>6B=DDCYpw!FuHVlAGI*^|{`(0E2Q%|OKv zxprgsHC<~~>-%wO)*h@hW+S@%w?`5}?;wDNre$a3IM;1;qp4D_KuCHXDd)8pE}p%i&PLMW+k1Yf`STPv3em2>*>SbrL={4xqi@9Xa9R;>Rs#O4g-O zW7m6TKH$zs)%n+YPqBNK1$#*^B<@RRuMy=$9KU>3yPcX^{W>`5<3^1@ zS81&YQK}Ax{AH=I!&>ZZU&z$Wn}m3C6u8L&UlLeN-+giONr`Nw+NwFxt6GYE`frICdCx*1@dmMOF2}RlAskNoCba*bnFafHIAGQhFJx(2A1+TcsY|KA6pZ5TIMrH^!rUKCcl*LYH|p*PHpiC}}kcuB&oU{}toZ=3+-Q zI*Hi5e&d*PIc7B72$xf_K$~k`+l_rQ=K@)R%;<1Q30pY4e3D7?b^_y>Z7q^e?)A*o zmc}#Q$pyG3_{kQ$w+R#=O`z79TaFa-GbQK?QJxP)YMX3%QKptb&((lB2kVyW+!8KQ7_I8!#6@=(L` z*70!KMv1KmQd@$!)5TU$;ZyD0d27IhU!i6(GvU~uwdTDL)gIo|a)ZXb@rz5D3+baN z8nsJmwG|K7(0OaqQNNp0PoGNs;s7<#wwTM11un~3cPcUA%Zk6*EGvO<;v8HzDnrY;dm(+81Jr1rjq++nzR=ew*- z-%7iFs{@7XicQb&q=65|)`p)T^=`at^gmR1^A9FVsg-=P$B!PQF)~y|sf1LrSB`pN zqJ#zJXQDI#oC4(lk;J3(8;x9ak#~vNc*L{J!I+%-q^q>vTrl;VQte);q^!6DQx=82 zwp}Ia4>#xLu`h4ImEh)!lm3RHSN*T5KM7PAa5}D_i2V)_w=CHlk7arApU!2aoE#j%_o0Z*fVv%nu4={OFvxB_ z7{?Yb~$Pt@uA zgs4XeVjH>;+WBWSYmSB0`_s?&)+eCf4gRwOxi0)`VIk-BXzC993d6nlq&%M6K=lqj zXgmNl`b#e^EbcCbV1F`6uS+FG`bp{rl^NB!l@MSXmYs{-6?U_rg@ z>I?grCWQ(>c7-AD-!b8l!`ML;UHr`>99?3h0Y)zr<2OPa5NR#!U~0rlg`olYl|E&N zsUii3x;C0jT+rPgFuGc*^T>0L?-e6ZCHl0CSHKZQgFzQM59g)mP3FG-Zr;Eab`bhrqJ_<+Q=+<*_M(3)9MU$Mc~1Vi``78m+}Pr&)Sux6{N z^wx=LH<7NFb-Sg7J2uC;umS=1{UQY2JdltyhtwiTD%GpJitkT|?DQ`*I!lf-cYPEfUQRjC&LwYsD)%^s8X*Nuy0EXIT$%SUI@#1A*ApRH3J@;eeiExFU#*0dh z^hX+^FL8#MQH2lhF!lsxvPc-=k6s#+yc1L*WksEM4_AllYgKr#E~=Vq>Fqm;$M2(6 zZ?L^jVDo%-8J0aFx+ZYQv|0y05E>E=nH~$tuu8T*URLq`-n~@*z5*M8ta( zUvzI{H}f=8(#q5UVt*bT-y*KCPw7sxcl~tLZ~{6CUh!lEDrDOS?&Pu%+1r244q!dU z-#|bV*_no3$u8-Imt0It)Z;xo`>&6diAk+maydS!d|MKC!roN)U@nMj8m-zB6yp^_ zl;HRnhC)E;#T?9od5H>}XGEJ)KCO+cHikKUio!4Cso%BIE949-xib7lPJQVt5)OBh z#PT%cgW?jRB!yM!>v22-!!2m2e{RTYOp$26Hld!S!Y2|q7b96m@Fug2AI&|>=+`!E z>W<#Yks3^I#R8p`^+uHLrKJZeygO&{Vlabo^j z--bi)QZTAHq%s;9HXG{>vDPhA8R&JmIpM3d7g0=}H7@*fu`23|AARun=8B0y{22(lv~*HW>OsDgK95r+E#LTSyr{{@98bopOV(o6xvzT<~-mo#}Et zuDa+_A5BWNjx`#MJpb^;BDmR#-aCX^-un6!djrTdy*g7~VwTWO_czG}^3E&HS@Ioc zdX{x5WPi1B+R^Oq)t*!U3scQ7tgh2qs=eFQiQMAaZga*}-9wJW8SxdJb4Aje0fJ?n zbI++gZCJI(f~oOQ&C82-w_Y{CW>PcV_llZ)*L8(x_iWsOL-Z&XL6-$K>M2xvw6n7q z=-~8jf{@OdqW=69Aa^ZaKV)+bWD%py8!DfWWW{Gsdc27b=&PdWn_lUt~RxRtl%MMF}I0V7`9Y)@M|pLWyBg%m0g>tkY!- zoo4i#mbvT$FMpee!k8xy2>ro<@D*Zz#w!Zp+E{!t=Y(M4!{+TAX z%-a{U{NcB`REl)NJ@76#!zT)Aj3i=e%lD;ZL`zn?w_0ixt5h!`MAw@+Y^VEln;B)3 z%HvdV)h4l!8$t^y$8SAw1?oqsb31(58*|-3_NLdRX3IJ}=lS&m-5SbW#K1nEW_(|lM#zdv>w~`ii)9R?u$8v zwI@v}hyvQ9g>st2uHJ(~5{SB#Oyv1Yxv-B~7*);)vUiyJH)icdrcRcS!=} zM;AY5#iY;7vZvWTP#eQc@=&(GnVTkoTKU8VIAjwpc|G7e`rzren zE|ES_h*7o()#;{opvQC`a{E#dk{qP+&F+!rGP&Tvq=GA()6H`hr6GOY=9mt-S=;6| zPJz!ks-6T$jo+rtdK{^6o+eb^uALG5bXzSwovoM$=!yA&)~90o!zeX0fpw5bpWU}h z>#|l6klXmJnb`M{vY@gAVtFt!uzdhi+0^l2Rycc?`mfXR|xQ+CKa>#iwo!aV!RhrEyIFY8xmRGonQEP zLmAdMvKgglY~k=><~uo1xv(EoPkRdKKbQ*JECN4~y#5py=_mOol~wgEq{<3{9MF(z zCRzrdW+IN>JnnvmEsTmA!Xo|T+@BOs+Gh$VcO(8E`x>v6ZJXn* z?$asYaeoXS->tW&!If%{4Vb)SETB(ArSd@d&iLv1t@CdDYqq<f<0nOQTWiLu#PEU#{Fawwsx=#*=%!z z?9Lq~eAuHXyPZmX$>k1k?-1xX^hgLEKeVxkGmZb&d)LzrfNVG+E*q158v44>`Tb75 ziIrmh$x=M`(pj~K+aXrC8z=;=^f6Do#R5;;U&qIAGU5CpUmw6Q#TodnE*IMS8uv?H&{DF_l><2;nez1tA`i&~aOiyH;$3OJ7%Et$V@TG4-FhBM#l=O#~Z^ z#lx6Q@npjveX_v4w9L9IsSiWxq?395xi+EWKrZd0KPc$TfsLwNYDg`AG6Iv2;ClRB zum!;SM@A2@kZ6nHGpU)gv+icZGviO1hfM}4am_-kJ z&X*)j<%shz+q11U!%4K@$Q1(OgSo41a5yV>1=ab9XdqJxylKh z+Sh_mA%;OUW-6!9V~vecKVARn*CFIgYy#?vVeY$&`fe-E1;>HEocCWMdXJD|H=F?7pnL;fpUb8Nsl&B!C%sf1TY`VX-gTIlKqbQ5ijEnc&)bUqXJ3)8N_Jw&>n@C zo5oZrEVFNtv57uCxcL%Y9&y6Y@Kcj$So(ROzh-)m4!9!<049@@z=aWi|CbwhTl{ni zaBa6UZ{sNw6|?uFI^$py`79oGWmoSm z+(=3dm8_JhqFV~Kc_aiVJpa>h*2nX@;)$`HLgf2jI1g-B zWQra;l~|rfi%>TNIikG~;I|7D;k)x9o8{0YL+FgY&^N@f3Bd{EwA~lc1UX&MKWZg# zpNBj^?C3&vCnrucXb~+^DT&6b!Y`UOy}g0O8d#(7sRbO)N~K5%HYoU4uai^M=Hz0%U5x6o%mTLO^!l^d)MuhL^5}?rEv$7qRSbojV^i>fXZThhdDEFE3x8 zV3i%h4CE<0hpV5%22sF@9pK=Ro-vcHZmCGB)GE2rc=n?3XQw&QOyX0wF+2K40u($wi5S(XGj#9Cv-IZElZeDdVjOPHTZiuFb{(R7(Up-d7L z_mLX3QDYv81u9&$aT>ps5Q7WI5w~QR`{q=|`&9hzGvpGMh%q23 zmqN{ixn+UB5D|6Qeh?ACRsSA4_?-;TGQbg09V5!+*d+dt%m-U51P%RsWuNpC-KwCa z+r5_yTd%E1P1ognF?^~}w=MF>`C>!|aDG(V?E<_{2~(pm5|heXV%$`Cc3UX#Ez3>r zWM-hX=sg9<7{}XWN;|6b(SfYZE8%SlgOuk8xcqY28NOpKnFnxx!Cd|T(EksxB-OAP zQ*pTjubv?r#V))td;VRw!S$iEG2SrkXR7}H03ej?Zcz5!4*Vb_hjW8aEPI&Ydo;ld zyL_9kgV{ev6MR)z`W?Gpr}{VA>Yvf7solO+|ChTRfCcF7yEfpr`pzqmt00n_`Kf3x zZ7{WR*6mM&xr0i`XyPW($Xs?D{2cGRx}jvi_=sGgRpx-GTr0mI1^+PWRf4fEmEb=ac~?Yp_KDKhM@Jb-T`?TQb=Z8W`g5oZG&} z2J=puv*@5d!J8u>jPVk)pnvt=8u!~Z^gzJwDIgZQp7q(OXw(F$rCi$`O~9-_f72MH z;Tf97I(lXXYHD9#IB#~ETb5;9Bl{3p0qVPF1B7O17feJ^cv={jy@`FVWXH}B9@Cap>? z-^Y_AD^JJ93e4#mz9U3LKPbMZpnc0<`-4#><|m5xTN8NElj`24&pIxYZOfoj8M&O9 zy4PCIY~_;cm&#a;RW1LCf^sR3x|xK?N8VxmotjEThFpv}O8!HDa{u4U|J&BrTR2Mr z^e?pK7rAl6Mm@Y~69@^Wk?Re+*+95@##te*hG0JmugzTS^^x5N!9kuvstaTM-m1l} zmtc=@nY9=rl^@qlThP@TBsPqD@tmgPs}|!D=1ck+kc62=>>YTy@^LzZ*+!#_u>0qARsC| zH(P&FA&&Ir@pEBP$ z5fuq847>9AaUQSDWAolC0L|_K?8=9h>%SwWqn@(%*IovyV~G5x-@Pip>0#-5Rb7I# zkf=o!zWV*fLApc06ACy>y?#p--wbQROcu^Ce$0^^Sqo{~Sh8C$3gGO@hc)L0PTxw6 zTPm-mWC~|h?{+!eB$S`w!`O#u?iuSax*YS|8ELRf$w`evs~oWhb$OT5(!~f(GNl?x zQk9c3=b3ZLElW?|BqKnk26-K_P*Gp6b?2m%^|WhqSupfF^05yZ9u*tTiOJuy=f`=0 zP{OA&^C?q2@kl~$&3IrRdRA^oTXknHQOn=%F$k5YiJ0%Y3v=I4OAY7Sv+H>!aHpls z@50lFF#*}X-G1OO28l8;;Hq38{QQpjW>NJ68Sx*<0N78X2|Mg0pDJZ8mAtzZt)woI zD2=N7nonLpl&{Z_ES-Y5i_k@=%kRZ}3aAi~0`M`E@(aE7nnI1C^m4%qz|#(Q*Bkpx z%J(`1{QJL1BZwhZLIK09<^6z~O2N%g#{BA=Wi2sc-<~?ks(_dXP*%G0+kWYf-&#bJ`7&e#&4hRW0$u@A4b;4N@cT}@8ui@r5`dzUqwp_WR~L+z1N%C zR=;M(LWBWW$`hE5Z3)#R>zbdd*bKETZeLB&DCcRxdvYZih%`XBCa^4n`qi87@0Ohl zf1UM2-O173ymKhX``bC4brGhTe_0O;WOjc_=v^2N*6wqp$>q<_mU0>q0z!{m$)r#0 zF+cqd4el|p>pJrjxBP_~)7x{dztHJT$E*H;SdZvqkD&PP;F!k|D+OM<7eXKN3&cD& z{yze&15FuH>hfdp?Jk69B>w;Yf87KL6paJO72zd*wl>93eb0kA4SkPN$n9Th33Ug? z&?$be{Q#N?E-wx2#63Tmah|1SE!-8f7%vi(jDIO8O)ylO3{}3$aMuen+!BR}5C$C; z_%mq|Gl(JmF#qQ$LT=~w&M0IQGh>VfmG#^6BR)0VN>1P2bVF+m0EDR_(Wsmd>(zK)uH1dgphV1nUsrF+{q>zx>>N+n&nc1} zx^`RXj*h8^E~nDVC4P~3SO1ZUI8@DBP^Oq&%ZV~u%Fjq5^{UP5s+z_FQD1Q)e;W-%S+-wX&lvWg2PC857|dV-*?3j1~1t#zy{Z{7hHHuT-HY} z(NHHloDC>H=4r6?IGBr_XF3CZy7G4&2|{kK$ud~uKU@-QS{T7ka>hw#U=XigRKA)@ zD4{1?AI};c$S=L@H~d+WbAX|dMJps^&^0FK>TdyCax7PSjWg;^0baLX8V!ViNfmz& z0mFK!_Nf}y@KZ^*BWgky?~mD0e~nhpLA&tIrP?f(rRcnJE1I$lYiD^p|C=&R+?76q z?aarO!GVPTeyzFbms+#!V=~D7srNjCFY{la1;jn06ZoWBUklq9R_is}h@2u+mUwg_ z{P5H8&$VW1j7ApJ7FATt2Q|8-A4vx>atu*f7+-!JkxRU(uo zMn;rN&CC0uwZ`gA45vFwnxZn&83(*1OkXa_de>6C7=L$NgNTUX-_Iq}{GLlDQjj-| z#rp3CrXeBfajf;C&&y#>@o3d_j@Rij(m%T=1d*6MeKleB&i0}I3^`WHEFNuQ_o z4QG~D+&yZjpO+VU-t<(1T!w7lhfu+x#fZ8VG7u^RsjFB)Ke0Kk1v!E#ddI6!UTQDA z3l}criFxLK_@$6M+ZF-T;yo!;aG=*huFhup*A?_Hy{;7%xF5(`!)^TR^ltq4nt=B& zGF9I~o;PRNA$yAG!F{6NQ%$@$9{rTK(o@KxEb)SN@}0PNIagoYQCsYXeDv=rESch@ z49^xe-`P?tT`fc5q(Wz4xmtWz%%Q4+%yQH&ppmuc9D~Av-3Z#6@H^cWY#pB8fh~Vc z8x3*8{*56i>$1F3f8~y<;=d=Vy%svJ4`8*0N_TTOvKVrcNmC!;$^|itU+9@Joe@aA zXMw86k14Kv?~(tr1&5G%hyp1x0`&Y(^}wjRs&d{eME-&Fu0nsKqm2h^z(1zs{H?C| zRx*NLiHAgAxf}6l?zPiM;UZRI>%f|)hr8`deUQPt1mQ(O071Mth=k;~K}-i9U5uTm zcA431$)MF-IVuIPDcu^Y0|L9#{Iij^h*}|$fAiHqjWN*E#DckAO+(ia?7;U0TY*8~ zeS&q}0Wwv}X?DK#DceTwM#h?X8k~i~y)?U?zDCy}@@`eFTF_E*<;Ng(e})hS_Sf=S zbuwi6W>F-t%Wa#YE4jQzG;pALb<= z=u~CgA@D-sR2MGO8$!YLOv5!)%OjT7{c;cY=KUU4Hp%GM0nG0S;ta`rI3}aNwB-7P z#NkM5TgHPg0)9(Vnr?W`^I%nOl6o?4nYqyXMLBPA={{_owo6Q2;i=`%=1j2Y!6|TN zewkblYY!lz{lge%eGo>LDgJVS@E@lu7n;J@RZ?XfkkQsN2Yil75oX3{6%6-tMvHGH zv4k_{P&turedQMuACLrw|}zV`5a(B#TeNiug{u693DVnFpkC%@YR@a`XY>vAG`z^yHV5on=^otgiNjgPzn&; zrsF*3$mcZb&?}E5n$N{(e`}hlOA&>>;ki2J|L}*_T3ZIG-g3~5z2g5QT*cq(s~-NH z!iDENPwp@7w$m!_&@p(W`H}1xk;$S~i6_X22iC@*on;YZf0QVs6csABN@Dqh&Kxf@ zD-dM!GCl-S-Henx1EpCB1eRkHdkKwPC10Z_-q$4ZLxE^HUuc|VN4TX?w1UP;jJ*9e zIv#g|U=W(IkZ$@5pD)=%nlFDOPL$et(|l@`a|^`2^K1OUnGg(E6ia*JkYYIkrEEak zV^Gq(Ieo6uF<<93);3o!4Z~f+U(>h$l{8J4jeG&sqvKsbAfb3#@D2GqpxXYIV!442 z7_OqU+^h5q=Kvr;j)V;e$sKkDqKWe!LD_{%0qY z0`f)ieJp}vo>K8T$I++h$ccr388{C(-aX7Bhc2i5nq~2Zz@rU-l-~2zZPt6EBll52 zzZr7E7v>8XxpP4N{FVLY(ZObol8g4$7K31{$XIzjc5&}WB_Gz+1qHgUz#AB4vR{HY z(lukF{sP~TZW^Y)joSPEUQp&t|9>-C1iK>6F(**OaF~Fl2k;aAThSj#gv#GjQ3R3^ z>D>G#WB_9hYFg<3fTSyJV$*d7{Xdfdm2I?qD>~{4DO`N*v^sDF98bCnk3z#_4!k!P zP2NL3gW%R+w@hfr*5^IW-IEU>Fj=Q&jr<~HKNJK}0NOd&`VP_nGdR)>hm8565pn^} zXj&2X!HL^z*6Qs9VI)s2H;6yDfiXsdl#_r=pZ?HP;~WUT;G~&^5eaYk|7%8JUpUWI z-ALSK+hsX=m!&d80}YT1R;0np(JWzd4qZGeHIajCq!(?{5f&5JGlnus>@}+rg{_>% zOULwijR((%$55A1?Vk7>Jl!ycY*$`G=}6KdoutcR_dwo^NQ7P>jf4xgWpWg~EoPua zWIW59LSy+bB|t4ExYnBeBMx6pcks}|LJOV1zlRmZNa6nl8*ssu^iE&NW!cDdueqg; zOLyP4(;>q*wwW6fOt%s*1aXTRMRmvl5?@{4_{JpG;Fo1JbTVm%Q}t!9D?Wru8t3>) z9Cz2Atz1rK)*8EzZ9IjaCc5#(vUSo!y#wFv@yuNv2gw_v4y+#*m5YBD6?RXgRLIWj zOEw-zA{UhRrR&txkR~HmdLlNEhMk+-sTp|{D6Jak+$fqkD;{ z3<*ZYGL=yq`Mb}sAoZDgg%tk;o`|_#^2lkBjgox&?+KH05$JygI{y73)`s!05R=&S z1;U}L+$sQ{XkE%Dw2#WWY6POGHM_FX3UE)c#)%0%9m}J!X&~vpanwSZN z97niZQpif0^oA-3$&-jK5GDoNRjFDip7$Eaf50H=jBX=~5~;`@Mn!ka4Bd`lRiT&e z9(TW*GH@*qf7)U8$u;4QxhjqNu`iy>&*)d{S72` zjp(UoC2mA4-Z@be>j+#4!mj6jfe>7(2-V`w2kJo}OeHXF_D9GG9Za$TJn!x&A{|$+s`A3mCP>YgbCi;DD%fBf0cy4v_iOq_`?nX#PT>O-| zorEF*8=h@8!?Y73tj_IJqIl)DSZ>C`F!@;-x3ISHpRH{%3{XHuQy4y|m;hI4CI_o> zryPpLIo6kgWtrR<#EfcJZ0HRWQSJthQ^cfDBUOiwG94{tf)-cpuKeT0s$$1)%@7I9 zt_fAy_ik~c>JVkCt_{BGBE1)_8dC57!WIpi#noKX(+Meu4EniRB$NzQAt%c*zUIY- z_VNR@c5ggdP-HGqML3rN3cZ9i-p6kIyY4t5i06y*(S^qg+m4f`j{3Bh^-T_z>smbP zL}~^>jv{W|nwE~|qs{jOJG7S&J1vaxG9+!9a%~MnL#?$COjPcBr|2G!rRW@YLqvY` z3M|Ne!$8f~TW2XS)hlm5f+!dyIeZBm;~*K()X8BaCuD41<&*N%$#GF%r9Lu7&&D`3 zVz6-a5mL-$I^_`Rwzbj35!k8*lKhCM)L|QyrBg$uj#gaWxh}k%pQDCTqr(TK-Na)U85E2 zm)!}b>7R2&!6Mq9QL<9KB33l_XMut%pV#k#LjS6co%Z|oK}Mg}Qi?*nR50u$=&bu0 z>CL#QyCFY^zk)*OLsPC3x3JY^@gogdJ`ay4?!x-|v^qNP2e1xJ`Ssz&6|)0JiqGNJ zo6q$1YEElcHIEyiaF;RNRik6t8pBNwNXfqbY0EV9uy_&0!T@}zMK-(%jz1Bcd;(+! z0jLWyO&tgnKonHC)a)tgLBtiQf_1OaB0u;moly`8B&i2sML{$RZ1YQHFp$V;Jk%(y z>>oBI0)h7%0y+|^WAWTfixzk9QR+%Iu=nA7GoviWf7kPvH1Tr>udG;PumG#k*V}ks z!fa+Y}=EbkAV6>mdW_rtrJ@DBuqshxb3$FYw+^@?-nG5^N z%tgY5TgxvWF!qn|kH}r?aEQRkgcZStb<9`a1zHy4yHFP}+7)r-yK)O-37+ zX;DO~eo><5?lv{p6}1E3_~7x&!-mQyyC~}AN-)%Ei`x-XB?aky;iYsGX0bIOx;{?b z1Y>IlTgBnnk#sP5;9y54pLp3a(efIJaaG&7UbR6r%Yss;2hC-gST*<>L~71oJER2? z2tP~4D%r?zk6g!-W?jk-kDuqc;YL>}8bF!w!Nv&afI_yZ3F*^vo|dI7M&TtWM< zSCiziP18Oy^Jm0c#yq=9=BV1%VNVe!9Io@aDMVc>!_(&PnzWE0pFOirtKqw5mKvjM z-qEvG8P@DdX_CE8eH9mU&=;$o|j0|EUPdzbQlO?({L5`gRFs6DC;Dd{w7 zlp~KfsKN!qdTGDHb7WNEz!a+iSJG=x9{Y<=jnNJKRxGd=|Il6$t`%htdr2Y6>R6p2(uhS|Rz~Au|J2GcVbQ{0l_lCB|VI5f2|Ka1(-b7Ne zxNi}A_T+Y{j@47@*8ltn^}cO1TL_4ZFrGauVJvuG*80((zcW@yh$|tq+X?6F`E)l} z?<^j9{?y*z|2WA=@aIdLfblc&-u}Z=yRk9t6`<6+ImB_MmRz~LpD*Guv96X#l0fx` z8@c3STi=xZ$2-|$?Fy2||6^CJ;h%i?<#!FJII-tOHs5^hPj{|IwQ<-J(ueB|hu6$-Wayy?ZBmEw_u?|I|?ASVAve{jr@2rxOQff9@w|e}0Zm zBPri%QtgNA*hTY`<%ioIa1C1p3%ftI>*UImFYWQ9iO5zw%k7W<__9q1tQX@VOD+(k zo%I$iAu1>!SO6Xo+H^ErbK{GOV(rn``Za}vN?#;O|9Piqycq_FsL<}-QCtNCeI%SB zI??y6fBoe{MCL=oi!qqxGrfBoogL-cwVr){rc)Nwp-2$k#6i+TrRH@cG(h3=a|{B= z@do513$Z=#xi;Tbxn(Qz+>qLn$D9E0jv!WxfV(Xu71mbiwh9S-O{y z_^uuaav~3_tl{{Fo2K6QLdr&QMSD6r`Y@z@neXy791vzelxUUqqGM}8TBTlc94U*-RL9AU4 z7qcqePP=Te7ghPqHzKo;Q7SiQxFi_%5&0>HbU@xEN~ZQClERWf>X) z6HPaIzX&Vjq!*IZI!?k@`P#4XtQl&ZhLsDy$lj~MbLh|L?rE~s+q0nDnDWsDsacR~ zqf}Na(bjmU_G9aNZ}Qhh1Sbv@@W@7;o~3L{CrqU)e%u}DQb2Z9h0hlQ?LQ1WT!mUI zy7DOym@L|i=BwLCxRV!+E@{UlbaR(=c0!5ju`XGM?tM)TJ&vY~5xdlePC%5-I^Tc5 z&zER@FpnTGIP1rtU+=z+-7GgaJrp`w*}Ggnaj~)9bh}{sl>Fn=J}{D3$Pze;-pgv# zLLWGPHWRE-g~E*#-?xlIXyKDS=eq>gg+wx0AQBtSOd_MTPb+Fpz{@+|)p~+lGAN#( zADyazY9~bcP?xQ92tCzuGv4e4-7$JeKPZKE1107C+-sfvcPZNy zCW=XA9R*)xQIJS^-c~m2HOSS_)dK{_xMSYQ7a?qsMXAb*$z_60J4CO%vzWh@B2H|X zV6BqtP{h&d*pG%>RcPjQeox!GyBU{GX0bCd5;YzYH7zGnp@MPVn?=jVa$YiNyBFfN zL8H*Vg+Y6x_^=uCRPl-keRnrg=|yumwfoH=6;F=i`KocTQqWc+2GYvw0h} zLEpQf;8=hZaThPsUBedfe9q?hF{j&*vwN#^8@$N8Bs zp>NnJUBFD8b^K+@Z-^jy9b;wINGDNye#R39mK$0Aw)~#gDrQ0j_s<_hlWvT4dg_Iz z7|kzI2h6w;n$wcey6NF&ZUE27l2XfqmE)25bp9=+61E-UeLcEy(0ik*E{E;Wa_wS& z{n1=qvoBsAJzW{(QbZ|76b93*rDJ_Cx2_P>aL#@xj`7E{h>wS^VW0AHN=n@%?%DJxg}gXS6O#Yk(^S^qt(eK zt(H}|xdM)fh}kN%z+^96w%%7{ZXT_MTkv>&@ND5Cd-<5`5?C&dH42VzhAv_)4m8kG zLIC>27@K8URWE=WQOl;o8Hb#wOaP=#;XV3kV;Ns}t1x*Tc&D?D-)$hHdw{(-C9>8# zDdoj;`vvz=^13C?#5v=nitvT!~^jvrouzgMua>7G{ z@W=IvCx4GzMCFWndlN@Ey>C2$&b*=z7=v+3vj;`dgr+$79J1OdkC};xed1>2joBL0 zLbMuLp`{|=)-UEPT|Yw`nl5&{L)k@u)rLuK(qVp={Ie%lBopxpLFeBbm0v5bUkT8* zS8ebUN^y7YIPKDhd-&|t?bRN{Y+lwAR=3Z?q7Bs*#J#~jaYwaS-oI0`R(Y>}4-Hn- zoNo0j>%ne+#%fZ2i&{~)MdoV7D3PjhJO}keT{~@q{TcTX$zC>w71_9@b=$U-JiO7zuRJQ zb^YnrZi|ifo~hY*?3$RoIMd7qIUVzau_p3e$Nzq^z8<56D+I?Lf;@~oQo4(_oh&Y6i5YUR$ zykuu8Q%7x*?h~%WJfMA$lWLL~&~h+g(V!kM&>+pUjltKTVu8pm?sKP-D4h06C->aOXZ^m@SC&{!62ouhppb!CN6&r*cj52%Tj(69g{M6@_PoK@m zIqx`VTp(IZ`sVp+W@#L+94~Ll1VO+8A1 z9H=!o;eGb+4`*j7Dpv{jxY4UKW&;@GaRn>p;|XduMibp_=#EmpF)rNg4vsfwb-!S? zp4)j)84&t-UZt{Wov2=Ia`SeNa6RsuZp+Dh+f>B{?Z~;~)r66oO-4&`>1bipC}P)oY5S+?AwA#^L6d=-3sHF8U0R&T2e>DQgFLvNFBG+*@hE=h4n#v=_N zpfx5?`P}UY;Itmlz%{Qz&RHRhSqw0_}o(+kKsEf)dJ|I;>|f|^!c)* zU}h{)!BnJWsA9Wu)GrzzGA%8cGl90~FQ?qP^b(EJo7%PJ77T6vh})N2%vIigszmnu zwwuQCxE+pKN6S|T=gF&ngfj{tc>z-Npa_W~uJwb^cDYK?-pdv2s`l9?4dVoCJgR49Uf4mCMg?$qr4A8iJ9aCVop@*Nk}wM=`pId0 zGQ1!SA#7dUWP4f$ld{-})t{U&YKUHEU4vxdx1vI^_A0#K)C1_@mR_B-{Aso@cw-7? zh29Nh%|iij@gt;YE(grOTs{KH$8-JTX`Vg*XU;BQAa$Pb;7i%jk z@XJ)LIyuE3Mhi6@!m$y71kCIdsu}F8H=XJ}k-;T2fqJ7_PFJPzK&M#*+;;~CqI||n zqrBY;$RqjYmPWp$sH+c@?fSXuBM=H7tXDUhcaf{Ir37Ob4mUqN6o1foG5x`yjcB{;6`)~g?(np@u*c*L5`;NyyzVul?JeO1a4 zP@Gf`;M^%(YfO=RQFrKksPuG~&+~kXo1Q*lti$DVHw0I*ZJKUF{H=E;ypsq}ODxY@@5>3X)EG@ib1HTk&lf#%qBuWz zp>WhIpg1!;0M1 zNgfb1%+y)iZ<6_*R|d|Xv!T;}Zl+m#FrGTp+MrNTzY6ysNJi-@az!N7?5=gzvDE0o z6ioWNyCj`4mTo;dPq3ucA(E3cYALWAPQ0P^htBxDrdq<& z{3JHD24^)kec0QC$wCIVje*>n>6V?S8IWWp1h&VZ8s*b>BJ{283NtsI!W=#+g{etf z{PC3x6S7~1FoITR&q0se)8HfvyWQ9r(2M-edQpGb6`!FAw}ur?h2zyWhrUWOFa$15 z_at<)3 z^j&3A)yyxf&;RO1U&&z!oBzm@T3C0jFUyF#zY9mldA?jAXK=}mup#<7mzydL^w^dL z5)SuHI6U`Zi|X)Qp)ig_H@fxF%7F=XNQe7Y!o&(yxQX6ln03g|Y+oAcjvR?OoJ9v4 zGFosr)-abgn~ttmn7VsyN7bC2$LQ7I60z4rzLsqQ0{=V3{)Us95X-1?t3Qc_#5tnDNl{B+2@ybi^O);)#}d(D)fT`>dLPV+)_xo=C2PZ;Em9Kdo0~OMv>^` zN~in&diJ-=ExPV%wNwYwVTWcer!8YD$wrH?cs&Mry+)a-kk!)`>sbpM_UEy(8Pvh# z6S2&0m1Fs*; z_8krgQ9|r!J=k?agi>6@!!paghvn_qKQvkC(%4dNwa8L!D<1n1BJF^&1a(G15r~C)Q0hNiu-#F`dN%WQBJ=3*Fqp4O zVmKXtDdyy}Fo#1O@pOsp&3-ARs4%J3_!qK!!uIaHnexfqSFi$RtU9u}EDCJ-3*KMn zv1U6}Cz#l~(xWovqA6_@&|99a_oQ?|gYE<^<#bK=!`{$ixN|&-VhC-&`I30I>F!c? zIgiyY_GSe2qF(%G^h)>w!ttGBf1cJ*@lwa9XVmnpN!oq;TJyP9W_ec}WGu3URWiC3 zRps@B0uE!VPKBCekCr(wGPLF{pWjbYV{r5Nq$V&C=Iomp6OL+#R>@-W5x`f{S)v4C|A zs|ZGSnagFBmSz1KY!=Jl2~ss-M~^Q|$r0*(?46%V?6=KUCM|^Vm(!X{p3J^7nUNau zE9qmdp3F$gQJQDooR==vu0E;gXG_KC;cPf(6X4mxb-iz`X{i;`q&J=5`}ygQ zH|VP@K!%sX*UZ!c$veA)>CyvH}DDoRbGPb-$GmI$v4gyQ@bw;1}-<8BK1U}e#;z~dL_8|A! zOZxvq-J3@xxxW3Qw)^hfWoqqA%ZbX$%G69v#i_EiG&M8C5i%{OoN^wJ%F5Ez%G7c! zO-(>?OjD6^A~Qz>)Kn6307n!RLEt>J_j`Wp{hjx(v(7ndooD$6>k*#kzVGY0ukmwV zmw4QWY}~kIJk(>z>fnO*T=qAg!XCG-yr#_VG-y)z@x)ALL|fNILEO_;Sj-*9MOcM2lr|I5esG@oKz}{bun8B5_d`zC{>xOfYEKYlp==Cha9xjeiJsihUI+ zn-|3QgDFx6&&_k48{}_M%6x0s33;AlI(u>-)l8($UK>7FR-?6CA^Dgdm*Cgpti0xm zIy(1mP#Z(>OdBMdOC4;u>f7)4Ucg1k>D&<$3pEjPi{T3&{eKi=FA5w>FQMIAzce-S zesf2zVoDOSL<1M)nmlryYsIhc+pv7n+tI22kUl`)h%{8CSNRZ+;&eQs9zKD=lY;~s z(+R6*-olG?iUxv=&SXsed`K_VkRVjU9qhB7BLB2R>RK|gp-PGC7ZZCANtCq-ZJn}6 z-0c+R+sRKM)4oxIz1#}g{Z00~4n-E!MMwv0zcM#}{$->jbPW=_?KXom{PenYYp>6C zHOVD9K50Kfr^Cuk*H+ikv6Sbqn}6r&;#pi+(jv^xgW+O_N284wULts$xS=`3>m&VA zXK^{-9-o+^6ftvrSTdnBCdRGlxTN=hnbk+^G)4*MeBCI6BV#EXEqYg_VlID}Z*Z#M zoMp*7KgTy7vK3YdM)Cr)zNqnlsRW-{W(uYtC!{h5UXKe4q> zhNWZTb(huW7)5(DmVdez6|({p2fA)4w`mr@l-$hfTv&>9VMI(?{Ph((8bj}HcM{#@ zjC+Jyk7?siNa3wUud$I$LYN)Hhr8Dn-)KL)S({UC&M^HhZ*H)-EFZt>dA=|{BKh4_4$u=@5*-#JC@=_ z&HQlIpZ&0RwM&+|ce||!nRi+iGTcD9wRk7mZnSxlDXS?fY^8E!4WKy52fRg7Ftdai zK$k#{E4N#$|0S7cMS5u58M#G0J1RcmE2s9D@@}!dcbl^=Ts8mxsu4oKWkz!E3#8er z3X}3Y=C7dGA0Pc2PBO6L+~k;r(NFHTW*m&dBxdQB(`pAz6jbT5DOS=`bS?$P1JV;0 zB183314n8YORdtTfI?`Aj_K311FN*Ku9PIu+u@%FUvE2GY~HVF$_QK({vjOP_Emo%MydXEWAiv)oObV&LM*6~oGwQg4?KVQDc4inxP{%kPs zR-cI_xY+*AQ=!z?f$=Y2&UIf~ zM5(+~sVo5=^RWX-l$lnMgfUT3D7zNRRhNs(=&|alx+1DU5&jNutUTfd_wjnnHCiK> zw|3mz%_OHS@W|rJ|R2hrclJ*@|Kk$Zd ze6OBQ5F-AAvEgyI4>cE+4r6xOf%0S4ke=;HivjIP)US0F@cKC&qUUgYiK)i>FCwY2 zH)2iuJoZ|iUSq$doJ}B`L^VFMnj79SKOuF-C|X3JQ>#eL+owH z2BnUpHt)#MyRdzh&MdW&BJkBdA{WDZeoE{mZu1}T-84qTGGdRkdC@(MT7wy-v97{I z<`d7+&B`1Vgxlr=F zRG3#xV#_JlesII*pyLTo@gGYkKkqWT|7g0@99ukE&9Tbj2#>E4;YY2rbm}_l&Y+Kk zqJ}Hn&EWII6QlD?G}b{p!YXi7!}?A)G9niohWZFjN)?)xSu0;n2pU%sD*ZIknon-5 zZ>>=A4#@i`PdaF?a2j-hFrbm=PcGR9wz@KaYm|C5*04|(e2lfTz0s2(-&IteRU+Ts z6*hjNARL!~%h@)$U#PsW{=V5)Q!{C8NA3=)iTt9Q*AAPWz^tLvNk#ZRd)-R)duMx59RnXr25gpWExw={eH2h zgTPyqpz6VY_|)mY+R1a~%`m^w1Z)8-e<$=B-KlPcxkd57Xn@Plg2r zojUq4?Wpy)Lr{BAt>H#`XPT;?Zn9qyp!ZhULjKp$cS1*>$#3a4aTi_m?hO6hO~Y@c z?ZlzZ4Z>-`v#GmmQLikXqt4NudJ?~S`x)tq&oc5eb;Wgk0UM%FrNb@sGD#KpB6d)u z5Nq9AHpo$EogVy$*+zOLK{+YV4%bWkc{!14!rX;dVrP&S7Sa%E#+ys60)O}*&J&W0S8-HV?wcfSQ6B>Q4W6`r2+jlR^57; zrD&aS> zBdN~!+zQ)jk7lXi1;EZ{UU7tyGOglyWf1TRH=*x=&6hNpd6(GCKg7UUNW==Z#^V=t z*AYxAx@rhz;zmCuqq@~9Ax1Z5sQEa z2+ap9fz4UCFxuN+yXT9pt@;JkoS+Bt)j_Vw?jgyx))EWEyv;J@=0%GZ_qy>MX+3k} z?F2qGJ#)P9S4{rO$qX&_2g{KLIsV$LW5Qp|XV{HdMB<$3a!bx0Nvq@B9~STr$HZ@d&g z4H0ck%Q`BezV;%4I9>UlVfwEoBAZ(5{e=4w-qs)NvPVnyLwhNQMU!=!sMk+WPlg+2 z#f9+5b`a{7|@QgP=5y?^T)FW1~L-*gg@B@;^3eiFb^93r;F(7LARS z7;m^3$5K-twz6I@SwT%}V-TQb-Utd3B!Iht9qM>tLTY2Xp zTggXsNcjB7DnLo}51^dRdHXkJpcG!l(%iwKi_MF$+*U5fVAsX4tNJNt*1xKx#!hMH zv&P8bgLW2(O*#m_Hsbd~Xe*z6#(!Ybs=d?ipw8Z!AJa*&;7oYoY#*ycXD>6Z1pElnG-zaf9}sj*?d1A zd&cH3!u^l*z||#$^gs96Myj_(cKSp5*&nRBXil^EKlh{a_EZBN+#Y}k^BfnYe{P;V z0dV@mAVqJ(iJ1Sob?Bd4|9nBLFXS)6mVZARCj=?}-@JX)=+A$Dc{UZ8;lH2RIopN1 z|NVSV*-T&R-_J7!0IUCV-OKxb^!B|or~OB29!bcV0HDkt00hdd@KFLN&M|pJ2E66- zYY~@=uD9w}fbFm{)y-&7@7JA`DTlo??{bLW5l9V<@%+iS9`@g z&H)eoFr8D~%bn0xfJeJ4T(pw`{zxr{Ko)YM_sqNuRso5h@)d3V=;n>&m};OmYK ztJN}c_*1OUyy|}&fqJoZcKCsTfV1%voR&ut#;5Pef&oC=DxU)=Ne#D#>k^Q?(tfS#w*y1kJWR56E|_%rD$sFt)ztm2qnlz1DCE1AlfM4K zM1ABh*#RG$>@(^Jg;>E#eromrK1+1cU8N!SW4vqR#3R;~+6n|OTr;WsS-IH^#cgx? zIr|9t?%LLOasr*xe&mz64B)ue90YmV%hj5}2YIlj{a}byh&tA(x0cGocR;@$@l+WI!uDuWtt^(t(9fo%?%zzPoySet@Eiv?4pr?W220tr+PD;ww@ z3upYv8f(lMDCw|sX zYjZi>$5kA0poF-@?%&VytUl%nEmk^e)Vx_hK`J!bMi{wWSoFtXz_|nKQR$ov@1+DY z@#Bami6KjRX)d4IpGL_$S}4EYmtrasGl(Z3@4WT}TFijy`lsHg+7pWF2S@Z2DcfZh z>%_$rZvwnr_<;aLOc#PSmJGb|!xoJrgfj`f^{i452FLuSHZE*lkMr$d4^_|3wn^u` z{U%?!@F8Zg*-CT4$?HnjNMmhreoT2Yl7fvn?T3XoSdPrD1e zIfB0RHJ(%;`JvJhk%}l<2u$R#ij(Xh?N9$`D0q z0d_?*zN*80woAy9N64LYYC876W-b+cC3TXnM^et(ZNQlw4jN6B-G7E}1PCH&SBywR z)-jn3>+&?W`k)D5!)^8eHE3dn9M0L39@Zvt{hTC5&_p-_zW~mxfLT+#A{30adOh2e zESC#--&wz5{G7l3AEkLf$5Qr_UW{|cYA5OwKF$Sf9Lo2VarTRqy4K|0Ox$=ZJccMD zv`D|Jqfx!YZVUqA-rSiI%UCqwzL3s5N-vLD{KVrg#w^;KI%e0V7AU*2K0mEht@B*f z%l~w2cKBt(YDQ7kcVI=*YwfQS(wiyl+s!xDzGDzW0~#ZCjb8I2K^PB+f3iXJ2@rm% zMPjj;7m!=p69Me2e5|o`y;p0no4DIU^Fw$FEXLZ)SVP{3R==YDIS&0}VXRRhN{Ju9 zGBcnR8nk@udB6AvZbx!XBXwR$X@}o(H0eU%y*{10ae_$7rucsZhra_gBvv<0j~r&< z^MkB16X@4Wi@I;p`kV`usKAiCGmV{&m=A#)b^XX9vCe9BS)J;0a7*jw8y^@?)L=A< zi*+31rQf-*S_m=;p^4kp&u3&;uVH!&c$nZ%QKP+4eH5S)*95@Bn*dF-hDsh4z44B& z8?VywEBTOuK9U4r&oqreg1&q|0_Fvve|?);@V#J5+evzhHlf{}H5NftBF|9LQpnw3jxT-I5QxI$Ypb!@n?JZ=San4K3>+m<$TFOcQa@bMHOLua@@i+(YuiYI#iUu zT|&&`1>f>a!Lq&mW1QM1Ab2=47A85mDK(pYFZY;6wp;=|i2dpt+Us5X;S5H^(9znd z?E4puoSqaM^PLk>&nJaZ6q^&|8oC4gqN9)r=QE*9Q=oQrP5VB^Tfj0)!A8Cq|2r$2 z8<`g-xc&1j#xLMdd0>pSBjZY(6EPOP7>nE{loWSdM{hwtrDD9&(lkta@~dH- zLrLI)IG~6GE^B$~H$xM}b)QQR%UQKUdF2l!-PH5$#6}fVKBTjD&j)X^SGV1({2F&e z!EP+Pt6TNV(gtwwBP2p)jG1XV6F8)5f(16{v}w$zKsf1~a7tTlFVR;r?91Gn5tPY^ zu)Mg1Pg>&a`#Mj;Lod8m4(+5}j0<`gaV4-UEJ+sN?R)Wem2M8j1d`4f2jXt|jH>ZZ znbi_nedLGz86y-g)U~=fC)q5NIJ>!>aJJFdj~#n++72#Bay$yh>%7{Ak#{olLB%1G zs+TpKuQu{VkwOI5`B^ApAoaDqW44nW=kURDM3nLyMMDI zg>X$syI=KgkO(d2;L_5!QNGjbURqqDes%)E3uqP0J@C^A(%m_GVQulTL}v32p~>u7 zTv}@C5k*R~94yjZZd8A+I>2bMH&5-<4uB|Rl0>VLv&k^Z)80i_uRrF-M9ZVN6w6#i zd^SLxR-_4I#&oMEl`%EfI20hzJaH1y$n1Vg!G&h_(1NOZywo~)@ARr)H?t5Lu!h>Iqa36tQ9@fN6L~(;mI@0_K4eA4Q&(i zNc+uqD{ZqzL8G;i{i`1MkXU|$s?u{(=dRl0Q=yeTV0~d&iwkC7gZlpHw->HtcpP?a z!0IvjoB=sxphlb?}8d!5bK; z>6#KYWx@BlzrW{lYli8vmU^;moh%lAqN7%ePTt>M=1ZZ>Aqtj{^CpSkYja>{A-QUA zGY^jjNEl|Qy*+_IqX(*=Xx=*0D-GJz%1+)1aV{#sCSt2j;Cd=)E?*(smm5_S zWZCh=f`%&5zP1N~pB~!@jU9j~97awqA*DRC@LyjTQ*W9j8(?Q@rL4`0ZE{hc7;^*1 zMz{O08qdzBI5hGUE^HQ_g%(4Qz5C>f>SB1gn(cb=`v0MjX>bd6LBto(#T;)@A2fH| zGf>gr)wEv3LddukJRjTtfK$Azb3ncLhXbh`K^mt8xhAAO^&iT3vcFv8jojfo=%@7e zD<6SyjhmcSOk23o5B)0a+i2fEoUQZS%6F5?T;$B6!utH|xwKmZAe855r?Qm`IX>Xc z^3*nY(ThY+5UY7N2d&yoN{!=u z=TXQ|7;_NR+>8XcDIi6l@HYlKGk<0lwwCHAxjgn zRas`w~b@~al~pb)FMK+8* z<6BAvf@WebiIz<_jD!%cfo7hs)do=jnJt&%6LOiqF3Iu%0YcI^9jOcIB?>h5fetvA#!DxkK90hsXg36nW(K@> z&VH5+bHG=w>f%^b_Xyee#1P2*Ua}wbit3^0RvBJI8prIdj>*CS0a-&Zy*pZ=1bgQN zSO$KR|D?~`y-3?2C$^gV=ET&X;rtmtGUoMuCVKHu#L(-G)E=9ph67aWE+dr zt#=aWceS>!f_B74RP&zbIgL`PpXprx?r2}>l11t`ceqipNKwNgI*JMEl2`1*TG~aw zJI%;`E2Y%VS0WImNuDJtkdO*aMD~z6OveiA@9q2Zf!|PHXa$WeR#O77!V5BB7p^k! z0yIXetR${tt!FzeJW&Y5okPg+%>{x)U zd%THNnfy|1o-S2#ymTP#Zeci!+2q_&_RR)}LfX5f+ZgzFf(P+`m{_hgG}^&yjXKnR zc6w6(7=|0_>?uQ4$+hr&|6uqsuC@nOI_4o6buYhljr>vrrA`j)B+Vq*lT@Y9)y!ePS>x?}4u8if zyk}H2l!nM-B8oWk)IWvlkA%xwFij`9hjgW~rxP58S^nQ|9yL{t9k0%8cTrEFo5%*f z$N(w}I%S8x0vykXv4$`%(?knx9jGqnRU7Qs53};SS$|UNKt`l$J=i;<|35W3Hl?gB zUfo$myJ;95_tetB!*09O+pfAGnvUZ(8WO|TVFIi8wl1E?+oKlcnVqnKh)d?0E2Lz? zme}t@R|h{}85frhh>bY?Hg^F--uSuySV#m}d6tL-8Yc0-CL|!(mh{QSmmbYi&TcWT z=69lk+P4Bm&fpjL&gN>zzDXtGoe>{5*(yWJ9(f`doiSp_eKu(rRNYadXpSCmbeL@Y z6bwjtT`$R(Hs1|VMD;AbCt6!j+(1Cf3%S z$;}AE@{Z;9r;C!(>23)e^J^shAI$xRvtVz>b?8Rbv&kLaI`e3~5b}aq+ZO&f@nBV5 z23{h^gaSGNOTJ0ka7ZlNkeAgAi|#|2RH9&hi3J}t%0*sA_;)RW{`Ce%adu*zZTNle zMC9h)@rYCh7Oc^5O-rIsieO!W$E~rSf=8B)`kBIyND}k{#}%pDk0;QbdND=3nRaHD zr|V|jb5^uC*X1bY=W_t7RSuyZ)F@E}b?xWX_jl3CWO;3eorQ9LFVa(zFKVIpuCD8x zEbe&uu?sUIj&jaHL5YJyH)%!#TZ&FZWazKV1#VweFXONO^|FJ@0wk^XiNed=mrOsE zw3E5+cV5jsAY@*loJwYR#O!2msj2?G*+g;9Xuj2O41)d^|-Cwj|jt%46RmYClDR*I827F&IKJ@WokU;!fx!qWaATqy1E=x$ScHcB%V8QCbaXt&C2+YbgjwLjc1E%+biO(GDkm z`f#Kx2@-cuu?1D#P)dU}OSR+QwvlQSW96(G-ydB3fV~%SCE@PIAPogyU}rUkws9Vu z(ZB8xx6*d*=7xL+k=3=EYE`M2!n@gEn;ZBXMae2ShDuTc0wx|x#QDzpLEtpj2e&QKd#%PoAIO(+&g>i8yX14b(BOq_ z$*%wg13jv)TpoI?*Hr0*TEww9wJ05bYbc%U2==Sx-E>&JY_(Mu{(tVS9+|Ce0oEO> zE^B}z&(~+D=0&#b_R><6qne^k+>PI<(aV5XTZA|BEdB44h#fduqhDe~)$9%#xcBNX zAUfr%d!ko3MT?_Wb_uQ2^2;6V$cerrWir9sRKajvdt1ZVkk;T}8NpOvA=$%Kd8-pP z5n8q{g<;B*kEkU-;jmv3=AIqR_ZO6bTXF~u# z#kp_q*Qv$X=go~Z&S5D5eQwMT8J9PNz6uQ}GW%5d8bLT=d`=HV ztGmYdc_JTc&qJ9w?fqY5kqW&cJ*vH6cv&SED{lpO+4slxu0J+38wKJB7VsjN1i=b! znS?xPC$63Z8|}{4gW{UUrm$FQ3TV0M|C~df#Rj#TIHtE~y9gq*}J+f~385Dod2vBOj7Z(1MpQMd_ z*|828D74V3M{fKS&vPUlw(@fH8VSw;CsMYYZS0IY;#X1S*>q%*)9ao?@49(te__MT zQz+{m#=s_^X~OYkmdRjO#qPaOC2KO?s;xD}|x}p7F*Z97ttBG)H243Q-vSwjsMTcWKMRo9;N_G{p*4N++%GUy%KJg|SWmNEH@c$8j7F5Gu& zs=fVceb0Ba=NCjNEd)ojNG_4~c=}sdnQKI{Jhy~C2ULprw@!|Q>GFhG+B1>s%ns>w z15ETQERi=%9N(8=@YF;r3RCSY0DS58?^@wOf0vM|dtOgH)3+WSJf|M4n_+LHG#Ik< zQ)^IdtjoY7w~uIlqMH{R&I)SyLtg!8DqKLNcn{TgdhOPR+d`6qQ303pEhnB|r=u?x z^@r}@qB=rb3L62lt_dciq|>9VrgWYkrjG^tknRsal6QIC^_w?ys(#u|!VD5ECZRC30HfW6EXhP59yZI>e z`+@JIb7`TV+{SPgMkjg5disN`|8f`+7Dp+ir9VR$z0!Q8`N&zPa>zcJxgUG*zl=W% z#tToQyG*4tEGoz~=KvwdpV?Q~L3FV+yl(r5PUG=c!Azy{YH|`RdLjC0b>NmV)C!PN z87-eZbEjtH>89Irfzk)V85hWOQMJUZnQ-F?tPRB@&?69YZ!>=!j9JGmD7|M))W5e~ zS~}0gNY`C*#2$Z4ue@0Jspxtx=HnNOhdinE0{yD`TQXZ6CVQ@VO%;_ZMW5|PW1CS) z_A-SlY)7uUQoI1AU6$qfj7Qv0e)Dnar**q(9gtuKbWkh#piKv4UCOxfAR37Dod4c) z-G*D0==AB^mYXNbZg14u<8^)}6>V)-@-U!cM!Hr?_nanQ?hVry$N03z8W`?|$d_c; zKzPLzRODsd{i^A8%9}np0Qh7a+|U^_1eRtm?W|6OI>ze{b)T@g64HmtOq!&q;a*lY z6`shu$XELbJ)@SqSmyER4;0O>Bx7z+(TtFJIzv9}Da}{KEZre|hqHR~n=o@$L;JuR zlo#J*;p#u(4Voytp-4~+xe`kbO1)s3oIt0UD%4kRrJ?e2i-6!Nm4$0GmpC)Wm^Ew( z6bm^oPc;}jEMOhLL`dKsfHiTxj8X%T9PU-LG{^R6bizz_OYbYFkcQMOD05dT3p&=q zdY$hqdnAE8(ZY(Pe7auLa7`6$ZSi&CH5v7T3Z&-nC02MJ56m2Cx1=}ZQ+3-LIncP< ziSf+bxSw7pidPtarXur?NwUjAEpjg!@wc_I*oQnR;%CJHX$F8aP4-8qJ2lNb7}oYk z2?xT(Cc@#aq=QqUQ0dxb5B+p5LCj6UIZRA$4~{EcU%$T47#oAJl+Y?ck93{$C%?|v z^BvW+_~l(A9imDO@Jbm*r|ctM&c*f~S@>YN4iWDzV>|mehV@;|i`VR_n4Uy6$d~t9 zkINliJDHKNTC)o2^1W=xIT9`o0c-hROOjGD^eWPZBn+&O4#dHImTI)}JfaU|+GrnL z9kx1^q4sm&ue{V|Ung~C_3$M?_Gi75C)!_?G`#M!0d6drhDWcCsyD-&HS)5YZ|1XO z!iRoaY%U^;&5V8Hw1&zK0oWa zD$eyl2v|GTG(%9k6;4q`rNP9hG39IH8{3ETq%P`f2pny? z&O8E06nq&}$p?TkqWqk^C7c3;GPcsdPG#>^ys<^PS`r!i8vPWzhZ8F51G#Tsc8J%2 zCnBG{yx1zrW|j)LWSFL;&VMu%?bYiNC; zG=qfSrW07$W5p zkNgwJOZXW~DqL*TRLlp`&wKtf(RF)R0c*4!J?Cx?J-TynVly!zT^^@Z75E=KBzhua zLX-@R4sJZHD3|NJsbSOoTFXqceB`33WKE8--$gV4dv0bV|MGrnCX+%nWdG--j?FK{EZ6_QFs72X7k2Id8-c}YKtqf%h z0MQ`h;vYo=t?k)uD)S1`S!)>Nm(^;l{`Kq8yTxj<0VM#wc-lr68&Ed(A#V&hX5YT| zEs&qNK0)>JUwjR-?(lb?e|KorpW5tZ49rh+QbvE=Z8qU~sI?UA*PbhTY^m^*qU5}_ zt|0!L<2kS8A1-XEz)eE#xUx-0BS+y~ykbF+t0{F1_C0A#!yQ))B*T(7=c;=c4B6|Y8}Am!-cg+n{Ib!=?syooGk;10iI`xm{HY6lj3+^i_}7Fdq^s+Es>(V zH}DQ6m<}8-foXML;Cp;5uO{x*z{dv9ed;?(Oarxm|JSfM3W2qp{|$q%-$L$ zal6+@ElM$5S{8Z_h|OR7C%tCV;m;f_1>&a@)94L*y_mxQMGAXE-RC>IfLSekn@)J0 zpS~MziI4+wm1F_>vixITgQTwhr)>VhA{>_`AeWmhisKd*FrYt;d1h5*&q9D)+ zEfI{<&3lG!t=aZ)eC(1}i62Q~q8{dl*J^unW2i5AGgGWT;y&!E>d!dU82fpIaX0dC zA9FB1|KokB$*(T#ZyDylQrh_iXlYw}pWle4=>MLXcT&i9u!>OtY-ij2eGW5Y$+4e2 zBa&qsbQSe*YU~2N37+6*_)M{!cmLad}%)lE3@b^NRs8t*j4?tt?m}1(05g}d_wmsrWz-6gx~BrkZQN4bbDInQL$-E{*gX+M>Hm_&{eScRW&YBe zWPs1b#BPY7LSoE~l0~E@ul-->1ejer^LVxu-zz5eSp+c>8w}|g_PT|C{Tpp^(JrAG zD9LLoEi?h}FCsvY*r{j2&3w}e;751>a{|PPfqeu3PPmz`1;(<1Tie9MI;4R`{pWf+ zEqdiYSG3gs_qTf&GXCDe_1QTa8&JQd8XOUZ~( z=J#A)%weZoUepJWd~qv!$Q2>tU+9r{)pq3bhxEN0`nwG-+RZe|Z2mvf zJDVoCC#CVp*W-!u)EyI?K%v9@6iY|Z^m%IFzc8sRjBHBk0g&pUl4HI=rw-u#cKn`m z6ZK7WrP^#l-5>uv$2$CgVsC&l_8YB znEaduQA`Q^cZsu3KBSX2I7^}t4qlr58RXjHK>*6k{R;ro8GdNWiKhy~OyYv{7vvMa zZvO@hwhkEV;^x{HTZiovoTUGni#4ZJM-ls#;IaFay^O9#*w0eBxUvy!CqeobUGv}h zSUX4%(qfxlJjnr4XwOy~37aKbw``o7;M^yq@U#u;{vDNQLYhC##e;gRJHGq^7mQXwMFf^dd&_CaJ+bOk!khBpA;e+*noVt7z ze|%ASrBUG6Vq@$DL9{*%V132R=c&9(y5T<$x_8uYR|@DW z0exuM@zI?mV9bNMGAYxx4nX(8J^y^gyJ}Yobduf zCwNo26;%odjNziGtP-{6SisRePg;ISH9Og>gDsl{AG@=l1(fY!%QY`O0>GwUpk_6( zKKEVYD~1LOznpE*EaJI{F6tMA6A#`ofGjL0oyV zTBH=k6!2wne9>S5ycn-d)#M%49r684!05hKas+PH%{imc_xLB-^Che`Ks3%e0zdoF zSqmh=ITH!9Y#<$K=9}qtJ}2nTCk`!X?3yKi%$jdTj9lucCmk_KbO!X*qrOtJ@2|D! z0EAUqO*H6xAFuCEfkKos?PW+StAs@)6+n~%6~hB86|lH9q-k?>*vLyVXcM4ZbG{Kw zHU&SfTnxwi)85$5`ZZ=JIhqOmXKqAvi9zHPS3V2eRuBIToBUj# zy;N?>HG^c_0}?B`j>t{Hx-q*iUetky(!3_^98S-~$Cf#hjRcW%84!MuEAM0ce!Zqs zEKD-6q(%a{`(eI=N7pyfde_nI*|dootGSg$FToPg3Q3ciV#%4F zuGnnEdPk%d1{AHZCu&GzDFSw?QQVMgAw<{Lo^;h2(%8&=V$zVJ@R7fq2}Q04_r>OY~IsirZr7sW+goW&l`(& z8`Qp2&N`|-qrq_qoit^#h*eu(XbRI=sb|>jba{a z|E;#}^&1>h)O5)30u)|5H_bFosFG^bNxf^)D$}z(aWGP1No`b zO^}7So6~_g>t^YOuNLCSnegl4^Lq_Hn8Z-J7F3kikfY1JmD%RRD*4)7U=kAw#f8t;TOW5POI{15BGx5;s4j1YU0tO- zNZEI0=LW+Ti3$%R-gVul$(jM+Wbmt+1j>0ROk&Eq88|TR;06i{x=}W!>%abDL|NR% z8jd)EC>`4eCbdbFzoU6G(%BD5-Gsf#x1Al3ngsVTLf4tOgPZ4PWOPytpDpT&w#_}* znJfB$&Vo22mjQ{!?zb2R&WNbe12%bhyp8($IB#|68U*PGz}5}`L^<+9H4oHHFKXb)$EyGsZaUNTeJ2S_w0OE?=S)>)UB+Yc!o8+60g1gXqHHH{tr> z3l3!hPCj+Xx1*5HbLs`KoW6E3j{D_*^~yEvBPYZ%?n4LGz#%L5AjDmZ=*|)}UW;!r ztdVzlPS!^XlAv4~wKA0(F&^bdDVLm04*m(aC#sKE8*c8}PfidC+;Cq8B=xumtn4x; z8X4*Jf&ed|2){YM|58}*68_}Fmvf1z@RRA`8hN?w)m0o&0e7kDBMP5MxOfJVJK|qA zR;*H-3>?85x!JrdQWDKdhOnWL@jW_K&_XMXPlx^2J$1yfBWboKrRHw?u?@D2i^u$- zg%8uWNlm1Y+M2eDwC$TI=3`xDqOabp1azW@5XAW%=9OcYg+R)BQK*z*h9c+m?IFyZlfM3-uQJn z^BBy!)XfDq7m$?-wfBOrr-h#Fk2Q(ty(d+Mi<>Pd8_5b^YSW3rn)_a#u6X$Y{NhD4 zP^=KB#n}X`9ZI=E?v^N_ss~jn7~dugs4yCsA4+2NcK&&V!~H zicX|VLO)QQBxd2$^yo`pfYYp9T&j;lE*tVNx@v(he+1&))VWNEx?W_i!mmOvE|

    }RRhPq=AQ`t`T6ZFW8=HAy0xy+Ur5TmBjU+&httE8 z{^7Hk+_$&f?hlxWmQbw2yQPu3YJoag2N+o>xSx=b50uO0>SFHx;^igrIQu>5MJ!wyJt<*>~ zF(Pgu91YHic$!;HdS#)Z;T8KfDS+qHfExIvTR)YfR1kU-4(Dable96amb}zKz@m%= z3Z`}En<9ZA{<~6lKA+zs+ZtU9K|7EbjL{GvKkr=5Gzc6wsudYbzIMV2lb3}+74b+& zk3RibzvQ)F-;I^Zq@?#6#y~O$(Q&VzPBBPe`_u5`>wJO9C_oVOpZ(th@%*(&eRP9N z?Sv|D+%ZZXutMUY=;&gVm`|2Q4YD=P(f-5$JO9O?nQhYV)PBZHhq1yA4U>K^*|Up( z5jsVT=fl4-KO#cn)s2Pw-PxGZTeMFa@vwsIZ3#Abo+=Di2Z z>*1W0qnfM>SgWL- z_iTiC-uJK?KsJAZuhw9tfv9S8Vn@&>s430mGYGluny2IQvLyGZmz`IOFV?hkoAg0|hQ6#uXZS4qH_M%+|K7ETWH4y)L6DJE zf@U+~EZQbV#iF-J1rxU>*F&b0QLVZF;QVYYVIy+sbyG>t1`nB{vN@ct>1$x!ab*5L z(H`Pg-#g~|CTpIqw|jC74sJI?H!XitV}=72pMe@A8%{@HIXu%oUGjlel+N##S6_z=$IU)Ca4xTnPl6RAesMDCZ7THq)Mj=%QfW*2`Q zX|L{^s@~2mG~J9B)u9$SwzxTwYgrp($XV3m-=V=b9RVdtQ!pLkD`<0TArb+>(|*dE zpP=(*@DZ5q1B{?wVFbLfEZ5{5rXO~dXKJ+O+~7PnHKy52-;2!);oA~PgUI?D=%b6b zQa?_51xAqu4;tSjwT)VP?FPj3T6=HiT40-~5;@?J0qF{^9G-L0TRvUg<)gltD?Se4 zjXD*z?74a}eC02%oZ!b$j{~zLZ^7mUfYYlm87vS0fx<6^o=v*Sp`r1wh0bq*gM`jk zVp_T5IKUjemei}Ja8AA5@3d@tp&SG!Yx7z6M@3#xGswZ0m_f6PWk)`$&2#_`mrjtb zg&oDL(GHUUEmvvgxp|F@zwmqYw(U*<+;_74MU(MQ6P%2ET#>9Q9bO;d0n29F)1{2p!Kqke);w`SC}Fhee*kxYY|v~#Lzo~5~JJQmkV$q zChPSNB#$;tyfd~nV+}-(JVKwkRENddN;q-qqgR>xys(ay=f{rP<~7~wlC68fHGG<~ z`#rGbzk|^&tdj-)o5x_MKsv?al2X?!$8uVkGF6do**eohj#pwx=Q8b*Un)BfUTZq) zVP_QmLeq*>pOrmze0aeojYzqKE|@L0m#~gm2ZUIz@0EmAmt(WVlLjGE57U7Ny7f_@ z^1*K%_Ac#P`KMIJO@-fj?1s$m9gz^dEN)s4aFAfmR(SX$0AAH2?SodMKq-rU(#R;{ z=QiQmD3XKrPc!8e%+{H%Ja8V3?2gAij?;A!7fkB)Pz$V?g-WJNb*BBxa93efGhmwP zJP6-h$`m-Mb5R0RpwUJ{9XF^ltNcKG;jD6p!gd!tk2}5?q8e`u=OvpB4 zEMqr`!O)alxUZqk`JC_f{^x!?e)r>k-2Tfs-tX&uU9anUy{_l$`Fg%a#XwQahWL-q zLUX-oB|01Z%jxLGfGF9$YC}xJXU%G$4-~MI8n|s+Ve_0KmUE3Xzpen!AakoFWvRUn zw)s$6^Zqt+X{-h-SUZ1>s<>?+|2=1qRwNO*C0ud6knXwzBm$FZjWnfxSyJ7j>Nco4 zC3|xIP6(^WGNB;1WP!N&4p(GU6{;@MIQ2f6zfQn=*x0LOp-^pMO0P2#c2>Y>SMFmh zj*BcsusPhpS0DiJ^1q?hUSRkL)S9LaQf8QKb2QC=dZM}L=>9ng&PMW=MZw%XQg6L8 zm~IJQxFFejd3aiQL@r=cb^qsPR1i^ZruCxGEXLWmfN9daN(CLs?x#YK4Dk{p6?B9- z$O)^b#G%ReLTS+QL$^t(p%yMI@74F^oE8U*+~#^B&z9Z;dJg>=@{(T5r=?*OfjY&v zn4zKES>EMBaEdXsxYYdUkwkPX*fBZK`CU-sRmWZTiN|%81`p)c*fO9?W-_xl-sChS zDS-NSeTr@RuD+@q6fe#}3Wam$Ikq)HykqHCTWWF}VI@l@=6Gp8&CmwpocEr@!zUEB^oezYC5{Z|1x0 zlZa+pV#s`kUD*+?@C@Iqe+ znBa7@wERYuOP_^$Q-p0X&)EY40s!l_VSAyV%3+j#J6+s8gh9Zxu%O6}wRrFONngIz z@H~?e_4%rx{Ui~)mapv0qV^|77cfxsFi=7fdyyNm_2*hUwTb3!f%lV)wU7LT4(>%v zw+~DNdA^klJeowerD{kqqf>BjaQWlzQ+hQmfd3@7Qda0g5dbnWiRIRyl{|ftIjK+` z$_hkP@|#~Yi6MNxzMWQ4OMJI7*mtn1w?q!V0&x-UG+J4d_%{BOBwl=4xrU1?dIH4Y(Tt77D&qMQg z2&R#;Ex@V5nua?A24D-u#iLhjtX1w!o=NNs2{4=nRh#ROyXB{f5KbdyR?~%{_fn+* zeBWk5qR`{ z>s+#iBv^R@`dhzp6`Vrz)zN}Mo@VyF2i^a*IiEyRj!AGHT%Yz%f^Jl7oad{(3E7DJ zAnNn|OS==5dimE?TV@ZLT)~Nq;-lGUn&jldKqx;r+h~&gHs7*O|2%nEjt!DDlntb< z_?!S%jXk`;_Q%JXofdK&k6!4H{9UU@cj-En%D=j&NW6EgH}VHl;=l;cW$_hdqMg$K zxhe3&$US}u-kT^BfJ5pCfcp-#Yj>xj-gPz{t1ivCsH~~2iUc}N6b-IxjxEnuqggo0 z97ZdFv&k`E%uHhh?`{{~&uzFy$i(@(s zIqQ8f_6!I;BL8xV%-g$NuuH^%4I;~=jz)QYj6z3hRD#E;bab<@n3wY@GyjW8d%af^L-rm;9NVNx6cr<)O#9VwJM!yE*F*Fw3yfCB-&(Z z8+JuQVDYOmD}a4Cc7vzLtV}IVf(* z(`Pvg&t=EYv*z6t^SPi9-7fGrf_S@vNo!m?-Y<0URJvB=x=L*0t5CkjeFhIwI<9=$ zM#wWaiDcho7y-`Q%=ld~A@1XqYRfl_$Ge5vm25`rjz5{u+3(BQ;vg0iRWl zudo~XKHG&^2Mc2b7AwKjRT)2A?+Qs1d2r!k0azqqn$v0=nn`xnTnwq12nAP(TdYy(>@ z-R`IL?M&UT+f3D?LX=RQRHJITNWkTthex@q;F%1={6-IwL=uL2Aq2AqvH}A0;lr&i zwlshuYp#LuyHJ_m^!PGupM(W_8`OAqf};$h%}>o~am3m>)#tH)Xz+36qm9B{vD;PM zw6wH2J3VTwH0f%@#&crCGwJ!Fy}UF8 zE*JDfN)hGjKAMYUt0jxlB=6Og(<=l#TfUs+AgWvh6QJWsGV)Aol&F?=(6-gDKzCiN zBfe;yHM3~%St}`rUC@hxr7bKwOVJQeuS4uI;#U<`gp086@7RsFU^fLK?ia+|E-258 zlX)nurW9e3gGtR!;Guz795+#vcu0J{$kSuYAYQ09$x;$AMPHI+lvK3f|Fi0v(vc(k ztIBt8YkQ1ihSV|j&~eqWYX%rv4qub9XhPgecWJDckB!=dZT5=4iH}npqo6f+;vVPq z^S;_CsuFNBcV^-njGM;cf#sg&LXFly>^M=pplw!9&71=*8WAP-KucgdsI2v3S5+j? zk-Kguz?W9WLYYQwM+tv7kCZK{1QD=5u z2}6c(*k?YmUkTra<-U0 zsnm!1B`&Jv+2@Nn5H(qTaa>KAfhL&f@?ZtGSjBfABOsIVZCR$ma!zrZl^T<^YfVFU za?gemI1mqfm)9oO4?;k7F-Ju@bP2+6x;{{@?37NrpA9^7!R> z@oxPH@fC1bun5}Z#grZuX!;Wv8t5o%*PmyW z;Qj@vrR4Pr*rwQJ+T=!$h^oBYgXu}n|HDOv=GW#!6#KQfpc`%54Rig!+x}VTs++7( z%pcb8kvce2C@SqP2=Vf*11CL7bM~*=Knx;o?yZ^(kH@uj+b@3x@aqIwyeJi zZItia0!pbdH2Q#9#f0Wjt|*mQJ}O?YT+1h7|G@$HDCNo0olu7m|I!z4^&ef0A|7fB07E+c2rmoBRc+ z(Gt_IzDj|5r&Znza{=37(eFc6!_k~10x_GfHM|uD6nG|T-}c#Fo!*?!8JHS9kbLPQ z8gA)dsG~Dhpp8)4C=i>- zJ6e+*N?KXjcsr=^bX?ZX{@b5~^B+KGLk#nKgpA$m;h1=;jidTV-|Z_O-|Bh%*m@lK zULk;D!tfJlEc)3-oOEA}%Dso#FoB9NR;sWlt>iQCTy(hCJ%(&7ts0e4jjPqRKkTJY znv_qO5tF~a;_m4Ij73~%x<^*Djc?)VNkWpw&mG0>b1#_rghdP_rtNQfoUR)JHmmTp z9J+NzZ$*EtxL8BFRi?E;@J?>@b3$hF17y$dm8|84Y-ovui(N>de64$ZUH*Daf_!82 zRzXEnHE8>&B%7gSgd0|Z7O&$U*0@ii-20?Oh@^?0Hx+vJ*W)FW28TbLtabNZ~Z;L@6Iv9SlNQt`*4~hW#QSX}#^=qD0r_i;l30hQ6(FG@azP&fzgx|XA@z5OeOsa-yawjN;h zYXJLCK_;f3J56L8PTVFU*?JLN1mp}{J)D5-%-=?yofumBXl90OR|tJT)xpFp-i&hR zWQmq+8bro3`xJ)XSdNSTTDT7Vfpi{|(`kTb*2QSo>Eu2q5Y;Mfg4mhnVpC2xHv*ka^EEboXj^0Q!2?`3b?_Wrj_M1U= zC0GqRk8vmNDqkL)KUiHL$ClNRM7f7WfIFek7jOlF=Nk;qO=)`pY}VGW$b^eddg)Ht zJ-6W_{PsL|Ynept^Bg)c4Pc(y9%>3Vct@4`=Hx$O8Z0o0?frh2#26dE_k8fnN!E;$ zSuRKgrKsZkP@2~Mdl++h!u-YlCsh2qNg}nSsac}g40n^q%uo=+u&mhVM-Q1q2cG9p zu2l`33pSP|2QgxXBXO|ZYoM^KDue5t-e2SL0e4oWCzz9h=JnPY-XUESBse{6emWd5 zd**FSF2d717p|+jn)wp5c|YKCK={ZIG_&~aZt=*yilw<)Z=51%1>1+h%FuRWd8Xo5?`#=c z4m%qM@4O>Ekx&_Pp#)7;3-6qb!?(QSO63fYMk*X(ETLIsGaCv0VO?-ejN-J+-9}ij z^57C~>&=8!s91FVO0RlUg_L+aM<-m_J%GkkxqqxhhH5UotzKjo8}b!mc;4Jd%?4KH z-cq}i?g5Ql5~&^HWDz$FYNDx!T%2qj+1<-H3tK^$tt2;IBRg=lG4SYYBN#R6d!QUi z4TAy zqqpk(>~>w4(jM%llAR9%BK|&y>1w;J?^Yl#q;;Sifq=53(rQ&W75?!0Ce;fU?|z7d}qjg$vEY&y7*aG{Nt+MM_WwmAc-&T9wpqRVtO z$OYH~9VOeIVZFL4cYsb96heyfrKu&y+jgsT{3T}eTU`22V=XSS2}wht)!yVsBxbpG z*#-@amjx~&F0_9QeSuWql(#z0yh330OgWw_ zT>Hz_p7*e(AV0}^VWEUuQP)BVlnFiJ&UOgh0MR%}iYOoWS^dxd!CyV2e@@8l*{#YA znw`u;y>SkDz2Y%);lOi;pN*&XXhm8BCvWrT{Q--9xnAjf|A$1E4%LEvq*;P09?8dea1 zZkC>plX?pbNI2E8?uY)eFk5`_1M&)$LfDeK zlQec5^AItli~_q;wrHaRv7El_vxEb= zOaXfb(kB)?TB=#Hy?Ki%clA0aZ1w)RsEa=S6+oD0!fA{ zUYv@MuuJfsA=7WVe;)}Tvvy(vGKVL*trmz1F9F$G81+}so__$Y6sUdnib)C|4n^kg zp)~O+r?Ir@TIJv`WKKVtNUF3ku*hLaX_t7$;1GGzHCobdMAKG=7c3(xFhg-|#b9Utu5>p+BE?7ZM>5^-3f{@DGTN4Mb zyxPr!FMS6hNeW`W0Agr0kD|nh@ENpsarz$?ifsa*wAVvYBDOjskJ|)pyET$7e zkU1uh8=OVbojap5T@83;hU&pfGi?Jf&+!5D?plSrb3V=1qH{gUT1uBJp(Np^b~zbH zor0gg*Y^sfX?aS~L(xFEFrGJ3N0t724&R8bHCle;L{59@)M(_ zhM$<2G5e_3yAb0%7Fp}q_=KjB{^0rVu!rdl*uL{vjk6$k1HVsw^^e&{j0nz}9#e~@ zWPVj!W24S~2eNZ2=nBbww+BAc(9+pAHDaL0@?M*mj_u;KeO;tRTbSu?$Cd1$LI79n z^?|4U-37&!3Vl%eq=VPos`{0M*_+dUcThNx(GM1aebLLegOk>3~X{rlk~>?o%(6GTNsLN|8|ZN{v( z0qQ!5t?r`6)x~^{c3PRcf)LQ+qd({P{<(vfAE`ZZnCw}nL-&@PXq=s4UxiXG+jKbbkR8ag|c>J!~A-&uk+_?@C3gpi&t8ac3>_ZNJ zUwiIgC_sr7bx{_cvykI`xXf{f%X}7|S>!x=$m*AV@jF9<|F|WhL+5tj6^@v^`u*#} zkNba|xG4~s-aMILy3<%L8wcP^oFqtO9X#sEAnZ0&W^KXBI*9N#iqA-F3nf&hc0qnk z>2Foe3R(~7vZe7_y5vxkSI7A;gbTRjfBsw|3#4Go_HtrfaM!D(*CseMAfG_a#d0t* zBd=KCFr9Yf2x>5$8olq|&mnk858?cS4gxQLOWHjie4CNCTnzGY<%i#OE0!hP+5dZ5 z>T6CwnyewFJ%R>aX50TFKVk|*QC$8RQW7g1$crI)A#4f$KeH1|@l8Sd&yML?lZrtE zYg^Fx7zl^4Y|p&EaiouS)v3AkK&`eR7u4+Q+>{}uMjG5)mRQzGu;O@?2NnUTMe%|7 zKMoQfPfQ0t9*p7JbdY{r+e~rPcm;bzn?)oi8#g33PaXK9BQ{irF4Wfm_%?}->IFHk z;@+EN)Px%`!ya{P?jfQPs!^7qqHC&0V8$Eou;D59tO(Mgn+;*t<^@t$PPm)hQ<>?&vq3ml7>DuDKIw8&Q`n3G)T)J^S=LR^I=f zxDoGA0u5NfPqzc0IoQc_Kw1(u`8)*^So6Clc{%?JYP3i^5rFYF8{MW zkmVD4^2fxIbM~yW|HFs3sO1CcRZgQ3#^^t#_^ik9ZQvaQcrlXs1MZsXI=n6SbzQ>( ztylO$2uJ}x@jTR^eU}hv1l3Qb2Jv%ye>L*b8ci> zWidNiN|)29TP1mYX@oF~NsW9?NYwzjWl-Jv--af-$M%Vs^fQ;+@~w9v-FS@*^+zmI zzngX$tk-!gZQ9_Yg-)I+|9?-L0d))c(1vVT%ACjOXq*--bcCzpYvfWg!vFRCl3-uH zHJe-|OQ!u4F!Pz;6qsOHP^CkGaDpxMZD2-D7u%;A*V$7ga0y7S%y2Bo#{iq|qdm-> zu9nF$!8Pi3h=rr?gM9B4w7A5rEKQ(nwUVOD4sJt_2zjk8ky9Ffm^AtuEWN`t8c@rx z8G;RZOY$&q>g)2AfXI>tv;g=%Pz};RvX|gJQF^N*9!V|o<&iK zkqVj(Aa44v_ovdLO}Y{U+#d1)tQ9D;YOQO&&6X5pgck@WwY%Tt$6L*IUTm|jxv#Bp zkz%RA>nG7c+t{>)NmY$kBY=6i1quzqZc~EDcg4l0Kq__JmU*-r38+QvHn3}Go7$^A`Be0!1o+sM7Z2*&z5c_pB*2t2bB~`!#+yG zPlDSl$3nZ&7B?NgQ0^V`H@hjbk+E zpQW^r)0sfb5IDG*q&Fe5v_=)zi$)7xqO0R{Y})lS z`34w?3<5X7vH~4^%600HUh!%s}%Oa1TwOtHILR zR#XGnQsa44a$ ztBQ>~P=1f)GXhNGSnYZz{Yx2y?HN_7S;GH%)NHPrj?A87(5j+&gCKaKfJv?UU9qU9 zz3s&U-J(;HbSFn|jG5JG)NeXRrD7h+$Slmg^4lnNEu~ai#KI@83miDdTUCdNbjq|@ z{IqogjNiSlPJ3U0SofJhyDd<8#I`qV5f!p_9IPoTpM(A|``OUqzK2lCD&){{4t=NS z4XZWkfe&}ufT@h5uCK4s5Cbz_gkp3_i)wsg_Tbf)#!`3muWy2{EGk+YD%pV9Zc|9f zz`AlpKR;DvkxUk_#{>Ghk%L)NXNKG7J)S>64Tp_@+4Id9TlU6f)_95!cxUuCiRa1t zeUx&niytWSYJFgVmx8cG{N;X(yBturyP$L)DGd}%Cj-amAQ>O|5(&I5Gi)HIdchG` zP1A7~$Ku;%4Tke**}eBU+BZ_$=DlB+K6uCTu1L_4Kc}~GDk->l6r@gpIjp-EczSu0 zXd5eMiVSgFq>S6BLY8r?ks2RBi&l>HLk5=X@bZ~H`g~}H{v8k;zOy^Lwj6kwO5oc#=AzWIx^fMO0@mAFx1JIwO&zif;w}>4JPgeb`uUem6*M?E62%)wh?w)QF_&-ku10{;%q$OO`xI5aoykDKu=Z3c&(Qy^evF6 zWDVM?7$qNgO&Qh8j-ws6T6IFz+KVprLaI=5^l(3somROoO}7fwSTk<&(j_iu;ASox z@`;A;pP>}!9_b7Cb-!_e%KY_LsbxnD;Q6{XKRZ@6U}L} z2ZduVxjc8*hQcnsqj^Qn?XI>Nb@nG>vVlC-l3VFttInqWiMmB zypYa7k@rri#jD5cE|%GB92Sx_1Fn5ex_=JQ{%JH5SPL>Hb$Sz&=lq~JHHS!_ zFVTuEJ#sCf?H^wlhryfY!M1|Ldhz82%aMfH*UlFZXnGnm#dD@v%T=g>JK!XUhWn36 zhQ{5*BdHf>A5r$xV~y|Yc*RFKPb)@SRW3FBN&ZtLXRqn|Xa#p7Lo2!TW){qn5?elT zJmj?@d0NS!xX=MCQ>~d;sls`&sA^#eBZLQaoN{#1S&mWC>xo9F{N^UA`5U&V_ht~ad*}OZ zSG+d$e|SM*7yB4eVGZ3QuSz=;>>nF*soOS|eT|La@E8Q?1*s|VJu zb%In4OwI1X19t4r%CZ3Uw)JD5}?N0V;yQud(u6CfPIn~2{ ztXlJY1hHvFfz59Uo+?tCCQ68KmWm4{(8`t5J?GukZXb4YAf@v#UA1RiNTb2riOiiK z#6;Bv>5C`sXT07cnGdgy)a4l&_spz(61eL-TJ4=+-s-t&x_&<6nny*H<08neQ{@LMQ^V^eqg3fD7xr(4lNZ^)eK<;Ib5lOs z#|zdlNQ$k{wmKMbXiJ1s6j7p(R32Om}`Y>JX3@|S_ezB@Q<#A_zR zSKq~KYQ{5*ISwE_qh9)W^7#6HsZx9)>8l?`%d}q12R%jA_b z`6K~9CKp`~DczlipA)|(b6u7wMz5wL9-)064;Zwlh>%j%bb<>w8|GLTqx*MJm&_bk z;gtBzOg3>eLV*b$re0Bvoq^2@zGeuu5PT5iUsHWef^44|xf9_b&kgQgQV z1WVUL)~LUXi@5rBuLTJkuG?kltngEL^82N2I$dSDO+B*g;!BBdnGQkE+O;0C1RbPm zC1`&~HJ*;GFw1T5AQIm0@=VNes3TBl%cIV-9J^&y^KiG5Q%N zMD4F;M1W2N>^8G~_qk@ZwOQJ$)bX8sHb56P%$@FL2J)f4TApu02olAn(W@D8d(-Tu z`T;sYH0Q*`2j~$_pf&{U1T;rjcuYCz7RMt5D9L>ZmP7EX*#GM$a7y`Rsja>tb+DGs zL{i~6-QHU~Ru%JVc*Ki-6Lelg3^Yng)}`-+CzU>k2oO;^-I(n@taQGQpLil8R>wl; zhKcW7g<)tUQf+)dyl`OtR(73rO_0KFM4jaTdmYn^R-jGwT>B9ng$?Xu|22E)MAsvk zi79NWg^WywC8Y*?{=}~p5r8BB_qG^sJ5*n&SNzq({)@a-6&F^{2$0_1K!n-~kP6PW__l~;4Rwq? zHIJlRl|TRtUfkF9D=-B6K9;=s=?!J?Qoi01oZ6ccf9-+z&Z?I%O)#=1O9Ma!0ZE$NQj&PC8f91@mTr4!>o?Y%_}DD;p-+LXN*m82|W(`@P}O@Yr3< z<|v?v1=$}_$R($Vb|1EndYABPe}Rj!rN6PU)_GlgsFSUL8mY<5ugu5q`1U-MW)Ee1 zgA!;SInrQ1)b$$3s-kSY}~!mb$SwrltYSPYsPa`W%rhHwKwRNlkj0OImuBcBHivfE49>7QB%q<|onDVHf`AGh3XcsC_8->TFj6X{1~cr0?->9GNV@A`Rpn z0F%?X6wM|OXP6G|PFF8tRQX+GWZ-B20$(0kiy}v~ivGB6p6b7hr?Qk0qs+!LvKg!?nUdvGgAwTB1_vf6qLv z2{dp9!{$G;$Q(vlEe7;U5&r4w&U80pkNu}lp91=Jv0+80xa+o!>l_j0MP=RTQsAXm z*SNm1k(=(ey_M$pvcJBz?W#0&jQu>jHTAupI5|mx?0j0z@w&sl$I1oRPhVV3bQfeu{3Bt<26ue`39z;h;E8Wt7jacXek_GnlBGWdv+d*#{ zpC}zon$c#m%hJ19FagyfJW=sh-C$bvGDX|yi&Q*gt6`wB+tv>^CIz%M^6H%`lX`A@ z;PZ1qxnyuzAcNPhd49*TnHGFl9OZkjB#ZzaVbZGm$d^>Z?oTpvLw%11T}~^epwXw{hew$}rfntL^*KpW5_l zGBRbxZdfi^3F88TefvkC z(3O$%Vl`!R#c$L<2b~5e0-jQ+^sf|Af|IW}-`seD)OP}koReEwK>nC5tHi8BIg#M! z?UtsiW9NZwwOJ#pft7F3l97qf$Z{PZo)|G+?{{yG#o5}tp_A>?2tYb?_^dD0N-Ei3 zMh=ty6e?db4^+zlD4Wn+rfjWs=|el5(cC7|7mSsobn|dC6fZ zw>9yjy6Z&?8CaC?3$LEyvyW8$KdWxnUm(r&NwKz(1EkJ+d=vi2heW=t8K-k~X(Oxd zX#LMM4w>Hk@ZkwPuMCfI*NEB(H7sf?9@si1Syv)mp)szl`s!sx;X2r}$Y8eC3|yj% z-Di{=uZT(|a$LGGDx1D2N4&aI(aYKci`=&H03@XMQAd60vR@Ma3}}SC3P5t@@J#(t z5z*e^36gZQR{u&wfFn|a=JaWM&@dgaSQFRW^T)+2RyQ^%nGATU#l6A+i~8kT;te}~ zcR~1$sw=lu93|d=FPx<1?S*x9@sA`Jw7D>yM(Z?2OaD- z{0@WOe=YI<&94Xy@E}K`AA|G+a9Y+)@htF+JovwIJ|op3pejl;@?UTKCn5ZI3h@8@ zue6iH2(sH-0s=-qFk>PDCac5LbA{f^$RPY)SJ3#Pnwj?uH%w!3zaG_2BMX!O=p>g)0Z|LU&nw^pGg9T0CiVwoNJ8>&2l<;?;052GpKGc& zZ|(hB=tEBOkd5r9z5sHH5q0}kKc)n%rOG%}+jY#V&f=?G2*1QskoUx?GYc@Jm*=_T zACJsT`GKg~aBtbG$*6Wmsg-=tK5lo1!fSol{0ykvkiu9z_07yCS-i&1iXLICd2K27 zJ5~HE8bY*^8+K^5layE7REzS3A^VF?vOz?Gz~lGT1)?8pAOO<@6QbYX>!B~J4_Y6( zpjmR)5t3e^YafAD0g4D@ql)z^{4vVhKH^ETL5+BDCJL4{fudPlBN#(zsy|bb@=p`eA}t^$mcup!vCZrT;f_+;htKcCj34GO{*GBaY0)gO zUT@1T9;cs+jk`NeThp{v#@m|_c*E0Z0bg+XR2w@tA3M*jPAR(t(@QQe+l8&1;hS`B zr8&=Z0u9!{6F{BoYimWO4Th4-qgB0iy(!{a9Jyk?JM3SXL_M*$af*>`&OfUOaKG6& zJxnT0YW9uRm?9O0r>^Uj$A&n{sH;?#{QJcIZ8y`^3mCN7PcT0WW>UT*_QFQ`ljZ*fiQkzr3BFb-Smw_xaJy!<%KV~j zWHWZ|<)Sk_V7T=U8{_{yCu-B1uM{gSrLo@=O*jBWkv98(8+vjJ`3EZ(D2p~`?{Itu z(rp`q&o4gI_GSR%U%mV*O$ULemCw{*T%mz&=Vfc`yH#xiW}5d3tqobrLB8WC-`SWY zE}H`9F}7)=PPT8%+ZREiR6SLyrle$rn43nc_TdDvJG1Kbgc32h1x!od+TpFR!VTJJ zNw{S@zTV1$_jTHzLi8@*<5`T4LoWfy=awp%$UlIT$tXZCTUCzYZ$O$rDdeskmk=PT z3jui*plvhu-a^s#?lK)`{HoBoCujSU(JNOP5C@`yzQ6cFz-BeWWG#dWk3hBW#7L)% zI@URWEIy?_7GcYqIg|jbRch%W?5xAW;$kuoE175s766+v_ugAqV5*M8rR>5LpBnMq zE9S=>@)txf$%;~x`B6KpF zQy?0mWN;O~fGU@X8aM0VF?H~kxkH01g;%0%`mZ#ER7+EC?Eh4vGcm+0!3-`>c*{)e zO?wN2uGN0)_HzUvkfC7Xz)dFdo3l7{lz_5$@K^u%3t|4NBNtUNza9TU26~W`&!rUu zt!>GD1EMF;lF!V5!vp{SVf8# zm9Z`&;UwMdr)iq+%XjJm))sITV;;|{!mDy%e!}i|oz`5(IQgp^J{c9XzZ&cAiu{ZQ z{b$w%)?XzT4mXeSIjU`7T)|M$44LnE8QNPU1EZ0tE=)g#vG8)<|YeTvxj-kGbCK-ESn}N zU9pA5oj$1-EJTAZfQ7uxK@ul@vRSI(7&ZO#wVTAa{;8x7pcY~*V_c-QA>_$0cOJIi z<9-mLPOtSVe$Al4x8m!iuUeT*VzY}5e4m0!38FAJ~DSaQ0ycs69B_O`quN}FqWLy?~y;i1f1GE$8= zhOuubESj$W}yi;ChrJWIgMxv%=QB{yhX{1fE(&4(?= zC@f!!lPZK1f;xKOr1O)rG`-(*K1P6|)vpHDh`8A{qbf&_8J{s1bekGpz5pgg%!(a* zB)B>N1$Fw)1W@k|qJD5MCF$g==y6Jq1=Gne8pd+K>^z0M9kPykJt&a#H4R+Y1_sjV z+j6pk>(U_4N1ufUxxtIC=y~<0J{ri?^h4lwH!04cM*>CrvZLBFilMy6CNSOO6cb;7 zE$W@l%8b$XOz#%}Nv!5%kqtP~KsCgZ*9>&{T0+_JH;9}S-Ugrz17Rh0GvOsvuD^~m zAPju?JDPv8)|4aSqy%V$;t?x6$y@oc@CRbW-`YlHQ}hb~F3C@=0o>!)dXb6F2DdqN zbY^Q#N;VOx!=gTraS2wi{X8cLuSC@{nAm{_l}7c~sj(ZR(K$&h_FIFtuT}UDgEGsP zRXGGnNW!C=#g013S?*{ov#V|57mo2x)MLDc%Fr#H*2x&Tz!+V23M9V&=Y`Re{TI~s0F80Q9Reu zTa3HT%rx@RB7h+3L{P6Im;AALr7t9?g}?j7`lHwIwueevh0Fn2|kt4`>yD zEbEAnIT&SM&%ZXz_@4;S`{j&KByR-Ydn3WCYdIjeX|VbV^j?Zwn0i7)#7YLwMgf_* z>VQXU<+-YI`c)TV16&eQCye+S(LT4wqh?Uh-X+KRJnv4&>uL+TTNxh3QJJJwt2Jtq zZA(V1?n}Mauy5QU^i~LIZ%>y82K(1c<4a{)HeOCV4usVA*tLaUT)1_Yk_SKgzel!n zaw_I=oul&k-baI%wr;Jp*=~w1fI<-83OJHO)YWuC5E1mA6Z29sOf78}2%C|-%+vofBVD{wMx+C z0!80Jdp`jK{!BE$o>Aie+HhjG!GS`NRjRe>B|~3pv8H&_m-k!?O%2nDpd&l?K8iQg z_PEQ&zw^5HmDjzf2lmQa2BYMT8+*acrEG1s9>uSSoPD}#l7&@@P#Kq*kKgcbULq7F zytV6jSyfsDJ1yz_EPaDa0wX+XJ|L#whC9u_Y~>1Y ze`q<1DlQ%|a` znjUvqiUXAvb{eCgGcQU_wV3mPT7OXAZ1_bUcX~scFPTuj9wC`H&e{H}Y72|c32P-$ zOcW&{T1vV~O-{i5-nvj*!L;1x6mg-#ArbiW=8FmLZ2xhUG#s#=C!&IYSnUT|qVNCk z2@3d0rO|`e;ZBoUOF4_-AGr*0Q;MPu#Yc?)2_njs0*dFc803IMuXH<*Zap7yhVr9X zyi!EFQ^d;?d$*mJ0#|rZ`3RJ z393cPRG3e41G#4{RjGjfF@N|7kun#QjsSbjBMIP|^D$yibW{b<>E2NAT1vFXWz*_h zZ}X_zJd8yYpf|iikz+zM%Btl(1Hi}a=D%EiETg-AJt9Lc!L!FV)nm}WHceP*bl3y#6o!RztyR3_! zXZgYQ2Av6;38w?!`Vc#&K-ivQ2Qluihszgeuv0shfMJjw;BIw?QeTM5cA-V@ucl~# zaUaF*ON`=WrZ=A*quO)X$EXUl(eo9^lip_sAe)+k0M30-T93$(sGGZ?AQ_YQ75tzF5?ad8^uilz2aQw58jROy}h%qUL{Hal>E&pum!Txzkfd;pE0 zgyJ9-ZdHzfGxY_migblk=x}GSNI#o*Zd)22W0%g%*wjqZ34WuZH3j%i^I879YWlGP z4T5Grw8OSF96O4mijfLD0XWRhZ7>(F81B~1$HbfZV{Lu8a#%pZ{@j*HmLuq{y8V&C zMA1F7-6cX#E3#h0eY{MjmI>%IP`u7L0t62DMH~AGZxd3!hb+o^H_xtY^>RNp+F$D3 zTeV=@nSTKr=!KX8{;Rsv!-tpcynyG|w)JKv)xczX7psh%+#ylL+pk{>61LkR`T9n zAYv3GA~psrjey|#1stBjT04kQz$Kw)A_-TZx3RXS#<=A`IG}kQx!Zjb&CQlj1!<80 zJYe@nfp`ib9aZnYRfY>y3d1RB1aV^c>+ zBKD#55EX`?>m|hH8@Yg#_Km`%)FCV9(yis=pB5Utdjt4#k5ASN-ix zP89r5%;-#{8#HjqZ{NE!gnF{>%gc?Q-Fk58=>hviw9I;c6B9crhUTVy_WSSI3C0<- z!hd@4G5SCQ0Wc0#SzcK&0~r`FaBwY({n`)kDXgwYagoacLS{f7fs5h7OXSHyQH=NM zqG*w`Gh^AEOHdd6~`V!kpQ8Vk4pjeXE-q;4ePm9QG$(*%OFVq4*c9tTk z9Sw#p9_LvI(JMD9S3C=sbTf;~nwGfx6Qw~1{p+tYQ3ajt1C53_{{g-pMe2$E0)Fdl z!KI$|es=!{ZIUx4GWV0Z>=L9!Qca1Irx#KrLFw(LYc zT%(92bp-gpo&4)ZL*`!9{a?g=Wk6Ni);1hO5TrywN)QwTq`N^%q*NrNQ#v*+sWbu` z0g(m)rMsnj(;(forE}BGH#d6D^`86w|2&>w!dh#NIp&ySJkN+~dh=J`r0J*oHf$|& z^9v=5<>}(PyR%>8Q)V+9Iabj)=tKZ0{?(ML!i(-JH1$uwgX|LTXZ%@MopbNxL(sTe zdpIwaeW60+v{;0~)W~}<^Jx2HPEFmx{g@T`8HEqhx1rf?;^m-A>({~}>FjV{IG7m7 zWmyWdm^zG0UvcE-N%*1yAI@?6#DG|it%HpzyE4CZYRJoF^I$-Oz z71uz~kj~?0Y&THUocsFt(fC4rA$C9E;Qhh*08O3mK}bp}bMC0N=2Yk8;9|?olrLoRhESnV8afR z2gb~zc#A0eQ0GuS%#qejk*w&kLpVmIyx>}1+{MG>Wb;K3R6{9mASRKWc#wq> z(z4bF$I4t`_2-oPgGK847+hvtw1cmYA&nyKG0@n zW_e2oP|UBGM^xA$DsB%|uU6Zf#Zd}u<40<-_$a%s4V~)+@cKp$gVTx$-r3ASWL;3&47HQ*~>U!?iEfH87fzKBeeftW9?dcpi_+ zRy{MH4e`V|Z+&Ae&om(@+G%-@3P1@lpaB80liZrTT^sJJ1<>aqkyXzNv;akBEe;D$=cV0OYvfz*f`%gFY65;F!soDYg`WjZQUEg zVGR6HLUYjPM*##G0-F`72{b#PTmR{XwdW}k#u$cqD;%i$k|o7Kz7Ux90`bngJlF*F zl%QYT$#6J$jmCvpS@9ppF0u$Ilc9AUP)w$!p1i_{d394gld+9Z%NvS}MHoq*`|Edl z69AxFr}p+siH(A#*n*qj9$6&#q#p1+jXpO3Ju*5mb8(<#2E56gvho_s`Q|`S9kYJ2 zza~C%ufXI-3ZQa)Bg=k(BxVqMA)7cA^j`;z+6(DF1Z9r&Yi}#pf&Bc-(A`AalJiYT zGS98b^cuIpnOxA>Z+|EoJLzl%4`XI;N5}K@t>wCIHxLvf+rU*7R(`q}N8XYT4E|l3SEl*b#V_pw1rLHz+lKgP=zRD*4(%pehCA z!MoVluyRsZ0AF_1rj^9lXa8r@eIsj-R2Tl&}CeH9rVBk3snM@+;5pmk|K+^j)E$$^#@6oO4_2|R<~Go=$g zM{~|A@j(& z7X{jj07+T`bQnmlUmdzTn5R=W{leC*taZA^6(lRMF&D& zbsW|6&zu0L7^U;;{WyZD<& z^`+9fa>0`ws3^f0@=pWVKcna!`}PM58_TTzw1vN*no=;7>N4h3@e(qvlvUe%F1ldE zrQ!>Z626#^N<7P4&96H@i=3I+Tp$UxAaUTW1qunq!5~+sSJN2&PgRb(2mPq#Q?0dP)8 zE($2Q#uPYgDK)?n=u5G@?#Q&F?^Zf5RSmwN@HBr!@rnW}d}6X8Y}`X`4J!1$lL}3Y zqhL5IIa0l@^QgH#VuE;VU&Q}8Pn6WnoaINU%jv|7M*})>MjT$2mFcRwr+&XPuLszd z<=9gP#F@hvaL`X2UIe8jw^yV)-OhccmbuUp8(MihZ%&+>MywN(qGkWRIwyNce(X7a zCGOYMHDze3sbQ&!3WAz9Ss1{t_Cy|+8F4drSHQ$cvmg5i-~KxT&5dQNE#8es}QV__OP+(<7r8cKt$^qJ$3v7 za1p>rQb3vs#wZSj$M&?}iD0-LNxnUT22sSG;!mTIO*VKn$(k zwx_mwfq^J8VF%9sQw#*J;Is} zD}p+qEi*!=H+jhM&_V*oUhkJJbrBlIHcS zoE8iGujoL&_GJ}glHgofcUJ0!RYFInSq>J=`g{&biCddlxrZPgnqMfK1Pl6cm+eFYFRBDCUnjVfKOPCE3b|_{x5)+QH;KFn&bjVAP-{i(^RJ ztX(@F(Da!?!Zi{gpX88U=RFc#+K<(n;YReCx>;WVTi>Tx#177qHVOZ5X?`7J#QXSt zrVJsH)CL>Dv^<3y#c=`d-rE3YZgQdSq&5QVH>f+SoAV4^)l-j zVG&fCszTKb;E{nt4FlMAskIxXGrt$?CZl)}8ea!X>t+h$7kSfYMr|l3l$7g@nzgPz z7(UCk#a+i-*;5+&@vL;H6i+_{&FppcuGQ;a_taElPBY@#D5#5E)8pZ zPAc6AxW5B4sg3b0VRdG0!cK)ro+)#c{OX+#Ztr|uH zKY=MafB(VSbz)+VJ>Is1K1#>q`xdhk28mXO>FL2n9FKKkYwzYdbi;orF)bIa4fuP2 z5ZZG87J%vZQJ5QKo=)%c!62{MV6?WSq5iiKK_wTi>QoGt4^dCun>&j@F&ikd%Krg4 z?K4dWhXA`W{h&c9EO8^_ScDIc#psuXti-WE>&XfPz;}k5Ps}J=Kt@xN)X#gYRez;O z-C*>!a-fZ&(6W9-p-!wsyaeiRkB0I+hTI9>{_m<6=bUGjJht;B$&{tfrz$<279zCs zcGV(TgpLOyd+V|)cTOj)N4GgxLLZXPAd^HYdov3pgNQOGfW5Acedwn$Zt|Ll4_MM% zs+_ou)1(YIZ%PU7Nwz<~3R5%~0K+x*{_N4}k?Ci8 zJT+2&X;SGBwvfNK{0He-DB7TObxw>4pT|Ykis8`RC5sj!KGwdz=fEAU?XBF)XMxVv z#A`)l^aQR^ulWuSAK}OK|6bjqcskz0P{1l?%C}&otyME;xF4CVXjA+dL;p>dQL4Cw z??5R8KHOLYE({=4cYv687~^2CCA}Sfkyd0ym>x=xmD{j>`w--5K1P-%DTna8NNE5nG&dJHLk2gC$lW145lZDTTAsEfY}JJe zn2jg-uZN23na0zhJG`vPz)iqQ(59xZjRiv)OGMBI{T=P|%HNkehJZju3?yab zpSN_qua&thT1;w0f@Ub3Adwl_>mLL>cvVNI{#s`elJ1wjNp*Klh6MMEb>fS6zGt26 zIVIwqOEG%%&jP|;Au9&-om3fe?x0Wq+Fk)<36uvpm8LZ6AOV_#6n>>a_D?0q-Hs02w+ z?pSPOObLoEMJd89oeT1MMggsm%Yy0p=IX3`Z6;-h9}=p(+IBw*?V+)rqngp_C&u}y zq^0pauLtFeb2m=7ah9d>UHJNQ^c8Wk7c3H6%=O0t%~e)jXK2}N(`HuwwMhxCR(G&+XReSs@g={~9tg<(lP5o!l>9RF zYN}*94!I|wN~rE&<_*rC{P?lI=gG-8)!LI}yOOh@wrmoAX z4Ty5Vv+bs2dNE{?HOd#PUnigk8&=18f6#Jk{Bqbl`N#EP3X{4^1HIDoBS;sJnTQht zkoRs)a|aEv$(rnnrq-)TPVNy@xE1=*w4yxU45Of~UjvlaUqBCDddX78KLjc^R<8cgTp&(*X|5?4S5R)umU`&woA?OFQ5EW$Y zvDV;ulkxPhPWUkEvMMwAyAk5B1(ec(5l1c3u^?5LZ(CyfzRv0R$ePP;m8ztEZkeey(g-;< z!&9XPcM_QB<$gF-Zol%<6398IM7hXDFfUfUD0*VbExTgCjxSvoa7vpe!zT+ zD5Mj*090kzw#)%cj$0ZM23_qy8S3qI`au)%|0I}S zQK(ipFfhUj0&H=->ZxFt#hN6s)+ZryLD?n{IfFT`;CE2$vHrD^azFSE@Vm1R;Ec7E zfm!w6iJ3JsS_^&PDGNc&m2G&ofkn#5-~26eWFMJd`9Cdl6>eZk=&MtZyf~1{*1|1f zBpG6G6PEvdku-N2%vsi(j0Kn_4H>f7PgLXnRU?Ies7HGz-dY0~bY&pjT&Z%1zRdA> z99TIp&@IE;iPC^~8q_oxFlkmir!hw^!@h@a>1*%R`0qZef926k5kNf;ij#zZhJ#$e z&rBL=@+-qYmoz~q24J#O;Xnb-z!Imym|k@#n^T#Y*$?21$royX&cEcZb?U%5c;k&+ zq6yExB)a)4Rae*kU$6Y9#OuFuMgBYM_@9;jcjETng!kW&WDe-n_L}l|YCz%a962Xr z`l{pDpZt}%Ja6st2br1b3!Y*rFz_b*|9ZrM_2ubE?d7Fm2WlJ7!GsS}S2 zkCXS*@{+1z@`1}p)pY5><|fW+!|GiXv{(KtHlP3yAH03{(O z9q(--=|2V;<}c5dY zja%m0z!w)kjfrR{#~AKW=p*mtj3<32_;Qj9_Co?+--`mE>u0g5OwzBnCe()#N6E?>H=1TQ z;iJQgQm>^(uW@(pr@dwp>>w&vOsiVtr5S_Y^rN)!A4Q*3f_8oSIv>^rx$o0P0XHOm zN6iLf|w{f@8-X}TRiHU($J(7l&;wx%-8**%HU+g1IrDgC~ItjavKh) zbrVTXE>@V5lQEaN@4ww`?nc-c$uQh#CntUqFv+Iii28`Zt~zTi==XCUSn5Vb@!>ku zE~#$d!oM$jikv8Jt)F;SQx|@kB2V9!ql_^P7}ahj>AGDg-}~L~E(UMy{Y74zq_;52y=N5FPDs>H-2mU*B zs=l15xtuxgIrUf)+B)9=gZK_6tm;ZPhKDt}s$OH>mv{$u?H%&7kXq1O`66wR_mg{2 z?|B3tU%mGe@(}^P z|9V*PV#QJnkpkuPMZTco^q0)S$c-$ac$aSzmI5_|&N6wN+uwG^ z!rdk(I@Bk^)F{Vr%a8LiyD>3Odx8h5%NBWI*86=V0{(h2ym%DYdtuj0Sne{Hse=gL{p^q;WH-5)c}vFG zII@kOd-=GhjCaGjm)w7yW2#Jjt_xCi*E$UO@E2DPFAmE0*qmH&O{>GhNvb_6T_PG_ zZ}Y`RZ{;0B7hSBtq_NYyTFvc%9WI!_%x-obnFlxaDN2-XO8+6Ny!#jP81>KlKy*4@02au>J62eI!F@lsVPhvTBH-zlw z7N>qyPT0oyj1_^Zd`fuSy>aKa}&F*=^R+ayjOT zp!30(F^FIPi^@*ZCybBzN`0{;Vq)ReuATYFqkgubb0#aydXK0sn8-5B_lR8mAgW%79#k6iA~ZCrL>yR3o_rtZdm z7GCl~*>>@0Am;E@vasi7kqpzb{*^tD#=1RFA{()=u+W$w=@s>8>*ZZ^IdM!3q&*5T zgu=!Bt9)dsla}W((n*A!28bv5#13Tj{EO-T*?D#@*h86cLCb17Sm;Il%jckM)g)fbw zC5%Qox;5?h`F}xW2$cI=u+WkFECkqKX|n^y2kvEv>2P zX<;s|NPm`yFT1X2^mpvs3=IuI9k95#cv=Ek<}0i%kB?P+iHDT3>;!^*C!H7yk_cVo z7ov7S+_1ps*+k@IWtmx8wn*dIJ38)+K6r?+xVpT|8ba2csg%B*jY?N*)cJXOT04Gg zbE*n5ZxS1i3?9OD|SDkm>*M><76g|NhSKjTs_;O}UFCsp1u){{a{$&1fcIM{l>RN=&%rK%@fjs=5D*3Du z5YyAsuNaI{e6R6fO$N!q{hknfCq9oY z)j$n7_wh$woSAX(rluz6na$~%iIU>*T1Nw`Eg7?eakTkGR_Kblx;p#5`XqC>5UM;+ z!y1m=@yjr>;yF>AUbMvoDW+?4Q^-WLXHOLxV9Y0q$;q}@$lWXDdYfkUl*7R51?}qW z!<>~7L!Il{Y|C$?K1=p37QBKkRtVt#R1 zP^)Zap{0;80pwx)W(6G?8X6iIiIY+xA|e7!RX$c1$txQf85qEijw(*Ae#+|t6>@ft zHU&QhP*?8s($YI(Ki_?k`c`8wO96e6(ax*l`+gI4O_DW1zP_Qk*=I##V`F()*IHg) zUQrQ`$f7cJmU+&=z#uJwyNUdayB}s;X)%ogm^lP0`|Wa^mvf zi!=D@y}go^Abl&VJi4PNf^nC?O_yRuBfL)-L5*{)Owq1pSw%XyXGkA2@ee*@pZ ziq&0k+`>74dB$E1<#o!7AiNJ{tY-{1bVS_*xmedA$;>*n!G`1pubx|ksQOE)q~&MK zLd?w>t3;2oQa&A873Sl1P@}>y@a{>Fk6;;x6y6P(Tkg1Mc}INBIYp# zu6A|?Rs~>EZ}ol9#8$3#m5zAJ(0+_u!UjVZIHh;J0%k3{u1!O?A@KC3O=kr%3b9j? zIl@iuL{@J%9f;afZ zX!m}(reRdek}XwilaR0_XRAVjb;ZTKO$F$T#!*eEF^kCb zDtJo*Zwzbd=!CvV#2cENT-RpP#K^&dxCYjD7>>NzxuvYC3Qw=O?TEEj^;VVaTBM4F zl?E2Z9&9SV%^=qF+9I*d$VwuqyNwf3JyjmxG>R3w+U^kQ-L)~xgWUOA!*{ATn{vM^ z8siWgP6e2IeOdBz#U}iYyzjs+@QRp&Fv^Y6@9?29GFQ~1XdLhaZM1U=DtXz^v_rOr zrIO6dc208qazEb7YJY+6r-!VKmjcb_Un8JU+^##&h;4RuJ&w1Y1s+26Y-x)L?l^ z8NidQ+}hg8Iw{Q7Z8rQg#O*l&xPYk@QhmfH6L@S<+v_Wj)wn-I*AB(%5#LA;w*4h&q-10Sdzxh+S?<1x5Z9KOcjS}g zmu=F0Tv^d?NW}(ROD27VqXe*Z@g+$6HjQr7@uSH1TER6Q?!2}Z_BHEv=Qr1;9q~TY zODo3bLpn0gaTlFGV{{ReZymRp&3zHL)~9zU9N1hM=kModv($j|vn`C~2&FO!a}rVA zOVRG(IL%%(`)2+ih>YGCrYL7AQoL#QZwY-fhl)Fnd`hY-bL-tZtkHfXW>;)(M2H(8TL$LbS-QzrNoTs3cN9)){0%JsaF|`2)2Pb;4*p~f$ z2{0d<{Jp4{dHNAPbVJ{zfQDMb8J_-r_443?Fzj7-tH!!bpZu9ZGhD!4!3_9~#ARs59ch+|f z|=xataG*1~J5!uicQ^8=>TU`r{@s|tPk_h#;J#GNJvPM+nq1Y-b%fT zg1=|}xjWkV^~THZCtA>Z!;Bzl0WY?sZG@8tly7%+qk@J!KB|Sexj0S7Ipytb)w+59 zyE`PkZ4tHu)D1foyEi}AfX1CU$@%%A6Igb)lMp4sVY1GaCVvg6J+#G{9wnDe#`N0M zuP)&*?y(pvLSOP4DNIi{wzBFeZR49vK=&~Z*VLxKzeo1A*2m7l-o7A)-p;}z2N-bU z_bVoQoz%T(zpt+)Z zvDVlRjk4R*6oX%kTox81gqw87iX!O^jZ>^ zcR3qZ3k!=qqIa~@8)2?tXoreQXP>^$M98pjNGcrpqjr(q!<=k!#$FWq92x>Y&`%ke z#{bJ&^LGsR^xkh*%E68t%bLqdnaYm5q_p(DNli<8y9{R&6t4obmZ@BSQ>0xwRppc# z(@Eq1AoAHh`iwuxu`^93E^CM~DJdyy2Pb>{Z5wxG>tbBuE~^3RxxxEG&h;( zf?nTbpHYJ*KN#b(-aFE8=Tw6BN-|UANl8ihnVAi)*1+K;6D1&rGr4TfilqVn6g14_ z;4rB4zBY-q?N{Q-Hc!X1Gq7~Vu6oVc++`;Y32lZx*J?imI&0Ot53=2?thNpn z^t=%C+WgoS@mF4c2kbsuRFyAgJ>T_~qOtrOxUh5}wPqPbOHJ9-lqpL8^6e^fal+_U zhA^T6C+)cbP5RpmzSNkNX^~NjHP_DmQq=g|R8vRoV}9$}h?@gS?6eLpEgc=gwxqn= zHAoDs6GQ9Z{&^cCp`VUh<(t@TRwRZ7_B~$MJ=XOtya`(VQ26#yAUrFJ!4*$J!P1h+ zHX0>*R+ztAG4F8kCWe53zzd8+#oNipPz|=aX_TbDh+wF(d8Hw5q@^)jA@9=8n{J8H zQmfq}Jeqsb&2<@E0xI9)(Zg#pAw{$_N18Myq^S108#KGu_%L^z|JSaylj}qjG(0d?t^t80Jbz+7@eus|S?*#?* zvFkYE10+fqkt#bYKd4OD*^_R|lbDMjP~XPiUL74HBO`mw6qNrAwsdj2RgMNpu6_Z6 z;s8!g&M#^5sds!iovut=hwtWN_P5>lrtQ|CKaY)-GQqkZR_e< z)h))V8S!&x6-8p3p_tTzz3n^w6tumTWp}rdx!R4LN6!^TuWlar*{rDj& zN)qXaBStj8EQ{zh2rU)i(6D{$jp4;Rhpp5mmn_s?N}~88@&fPZTHujS{*Ek>ND^@L zsAJ&fx46}07$UQ9%0{ANWA!6Eo;hqMgn+y%ICp8=jjgH;6>%2Zk7J{w0WW|j%`2La zJmgOTd9I}7ZMF_#b7||*zCx-QX76LQyEsY_Va0s+wBt0oi}N(0lp;_rU8<;%xeT~a zmPNjrmKFsA7;DeX#WnU@jK~|}t*@fpx94tl@v106&EM_q?RC4=zOTJSFd)2kZw%YW zhj(V9fgs>{!MAVd9P?hR0a4x)zPld~jef+0Z;kp&&^PKq<>LU8EfSQ|HHd~&zux9U zPy2<3O4$Ai?ZdhdTqLBVU}!@`X_l6hlvE$^BQ3_WL&>QzZP07Bw628>ee~`EdB%3S z8X9B_8dbZ%e-9|Y=F`&B3MgPC%m^Ke3GH~)f|Vw)E5p_eE?gWgwq}*i+F)S*T%0Pqk9)j4 z%P~hvbe#`WF{lE9{HTyKPy)4GTSR~AQ|I4gevGx_aILL<=kQJ#QYVn$Y4E>n%F};P zdvM|Zf!6&Bw;mu7DqGmUkxERY9k(PWF@7lAD{^@Th-(2Jol7K#N)21VwBr~eA+|%lD}D#@D7PZ5ws6z$mcE4!*iMe z#D)K)xp7kHieLHVbznlo|9KK_aA>FqqM0xagaerO^?!@@m)ug~kue$ag&pdG;Ad)3 zhbgZ-y~5etOUqe2?k~dk^oWLhN@%!ha@8T`;!b?xtgc0 zV8a0PtrTAXX8-$b&#ns^$Fm+q=DSJ$(zEaWL_iCFeSCl|0EZvQyzSs+d?CRPzt#Y# zOt%$Top2aIr0u zIX`^%cq!?!KdN>Q!*d%0PiXHW@(F5$|9ZmC;!!uH(4^bQ^cgr8;m@A7zW)B%{q(@d zsTH;E<1UC2&Lc#Q36aYyq(yG~e?%7Zvm23yx96(Gmo>M@(@7rn^;S4gVR1W6SLF6X zqpOUO#`Frm_IYHC1Ykd<2N&O>L_UlF`@cV=t1=dj!&67HT^@VCqIhc{i(X&wSG4g+lq3`Gh&!1ufBpW5-JCXsw= zy-<07x(Eerz#JWxjw);%^hHeqFH@Rub7ukz=SX{grQ z;?WYodS+CYl=v*p&(EjhQ51>iu$oy};od-5i;2E_cVe4K5 z&lE?O4^md)HPdqXV{4qS(0f9aB_*5!0+wf?2z|%?G?@S(4c6F4UkNi+5J- zjk;tkJR_L?Igz}%r|ZQLU}rI@aoQapMvr%g{o3;X!)m3(zZS70H*=f8Ae(V_J-}(M znU?56fOni`@Zv5%tLowMqnbaS1>WGS@O7wxL=HM01WRK5*_UmvhkvePHt{v4jriyP zsL}8cd9P&1R_#=2BOx1%CTZ4DYio@MrbQW_f^Hp0URqN%A@#*|vzAOuNRT-)W7&S` z{nb9SL}8;@wf%8+P`eNUPCS!mi`7F%n-ed7${)JpqFauw&Dc%e$+dal8n(s;8JE>C3Jbb`E_4Z2n^!2*dzc%2!{^KA|lPf;s@!ScF6jI~%;p;hx0g4})5&ZpD z60)`moFaEHZ$;$txK{);{qo%9@!X98GZ^}k#lhH;OFEI`b}*g-zE}+IX6pJ$p@_c; zCj68xnI7`G<8B_$^%o;kwH~={4og*58hoSpi%0YG)cuXYAwtWzpT52fV^f`1`UyIS z+m9>ryWiRI>csSAk5bhKM3CU(W(?;)3pY~GU*sJGD~=QHqs$d>s>(Zz+ax(4R2gy` z(O#T9yD~!~IBvFr?3fFB&>2T_GUyb^LsPW2XhsCRt=$=pt77Fz^I)j(Znv!V_C^x_ zX(MC4Yr~A^wiiA4{y<=(Wv&zgdGKE>J}`wE6FA)}H>AH1Qsimpu4Tyj&^CEBa)>5-g9F@#BW`n%u^tNuqhYLEbbC`e9 zc^41M+XkL>q2sI9mV2(|{9muliQwB5;`7+0OWM9g3J!L2+}3#K*3S~eJ}0b6*qQZY zRmf?^(!030_+~2?jE=VTN3}B|Wi1qb1lsMD(aU^$2;Te8?eyn{&{yzH+w8`H=edHX z7xeJ%BTq6|*chidbON(f7<~Lv1Mo~0<9XTG*m|f!tnKeZ;VmsKL8zGEUH3`X%El)r z$>~aOguhZ}U;NK)$zl2*gB1TH25AqEfmSlF2l_kg!tPmu!vtjI(L3cdu&=GIZd-Rh zB9RvkmQX%5zStdJ#fO{BZjAaU$V=PnLF7lEe8AEgDex!M+Aef-s3urFws~34IgH@s z`?0fAWEvC_@ZFU*1bH}+_mM=5lBiwvO3xHu7GkQLP9Iq7l0@X!eV8QAuQ}AnJE44g zFjp*s@NzipuHNog)80-v6tR5v0F|Pbm8>33$az~=QnKaZoY6CV^6Bi?ccwXT(|e%D zM`h&+Xd=&MSxCU<)cf^s2Eyl&-LPpdf=klQtp($9G!>ZL?YI*W++1>?>EJGY761F) zbw%-xrSY|~3a1T>4e)wx8@?aLK8IT~ip8Zn>gpOA@=`q@Ok6O^$x}-lyhlPZR$@BP z*Z0xX`u34aj8uaHACMo+_K|@SpxbB zd4mGcS!Rc0bHb3NiFwG0f3!5lY3WE99we^68Bbw#UUYuHyt1+as6Ct)-2ZxDi#}9b z-f1(9?w$(#RCxKJY`A@sQ5VuQ_oBzb11&llUb4fm#j3Rzxf|`^Lr8gu0F7tz09z zY7PWOZd??Fh7U(3ED4|qA}uEO}XT=61Rv`x`_ge*8dvN5=Y+P~Lo?iK2J zlt^`@JI#J#znmUmBF6469sEo;HSvQNWgi4;Hr3f0hAmlE8m%KYgQyjJH_Pdmy(tS(Pzv+e?L1H z*Fr4SBk21!*c!mL{o&pic;iQVdwX47av+5Er)fwa9aRz~{Q!?Xeea`)lm4!d7yWZ% z`18p<^x-a0V&>}N0w|7;?*ak&#@cLetPAc>@sAef^N$;i%NJjdt_4%&b8t*dOtAGa z1#s$;l4y%*+r1J;A8a5=#;tmeH9{$$n3mvGgCbV{+PMp7c>^m(s&Q!hmhNhsQs)lQ zUuCyPg0E?+4bTk(|3)r0g$str!!|f+J^@3e>Od|vm-Y8we&VM`zr9k;K*g{)IAgE3 zKnmZcRF-UIlognBl!J-3Fs zx)qpz5NB0s3N+N+-MzH56chL6P1Yq4qJiK%H#Zma;NW2XZdY$_Dr17e;ojaW6&3x* zUU#biPWCkf3blPKY9s{&!i`Qf(28);t6W@sO)~u+%b`8}GP#p+oz$2p(G_SDY z=pvklSP2xmYqA0)64gJK9?zB@#?qp3GQQR9@xy=%h#%&eCMh82|D&PRkR`p zb#FX(fuPThBC1aBd7g31T-2~6SRPr=EN_vDV7Sl!4As_BsFz7DtprtN#StwGiN!ZS z=zSLzS-f#Gkx=p5OWG23tm8BaAhrNq&>+iHr{=?bupdCFhwancHG#5nmQ%r_0~Q~P zHG(Wh{Bk^ZJMEj+R#s^=ih?6Yvkl%RxO`T;&*mhYgIjcE)S^RB9vEOMG?b*)8$sw6 zA{+GOehJlhPTMCej35}?m24ZOU65)Ux1;fzMdmYEKOS_3_0htn5^#{+ZSc8ah0YSy zozRW|DvzIS1X8wc*mEanPI_ute7DwsTS_ZW5DN#*q9#F)z~NjCgiJ%ecauLJ_%q|W zRTCr3>w7&Zifp0tcOKm@&Uk_T_kA28au$=FRC{)E=&_S!dGCCBH?-$MLzw9zU0T{C zV8(TCz;k;Pa!(vj=cs+Z3SOcjwos}T8rMThoo9Z-aeefCMHSNx*|GO1;#t|*z|6|K z-l;5felhyhy{kq*^DZ8lR76BXfCfj@?(pECGvl770e6j%;$u#P)@AIMoHcvtqMdr< zg4f&?whPZ>3rd4lI*%W(J2-~C=^q^QVJ3sI&9ZGP><(rsnfS4!`Io=BiOAWu@nN+0 z=2d#kYoTY58NkEISr7x)z=YlPQZA&o!bG}BEpMO$BwL%Cj$5icM8fq}q`#v&9DgJd zzViv`WmURDRnODYFFI8>(>QR?^T%eY*AOfN_%r+$UBig21J8vZ&!f@3Erl+js-rCW zD3%hHt81i1Sd^knB5VlFrCx?-X3{%7-Y{5;)VP}z9nETq(Y(<# z7(e2=P2$W*PDYk$5HuDgu0tv#ecJy`_Dx{6vx3vzPq8sE4RKiMf#~pO)H4*}@Ymb? zJlxzxD~*H@dBb{x*#ugxi|v+@K0=t}C@2aAP~c}(fK1)zWhFtK3pi8|rQoC?zKJi* z!eR@xzAyYNRC!Lh9*gAmS};;Ezzqy6b4^Xn)YO!nogM8bl4^e;IT*wDYnBlhK3ebO zW8s3=t)heq3P$u(k}HDRZCEK#xf{{yEBrU+QFY0q4;W}yb@^2a2@d|sm$_@tcJ;5= zuD=4;M-2Ztj{RJ)%l4$ue114iXjg6Ih4aYKcRYo}lg1T|1Iju)dHzKt`v-)WC`PjA z(gl%XP_0WDXxg;#nx7U8r^m&|5X8;*@qvSOS`F1DZPL=x`Mg!IYx`Y?ihgf;>D1 z-IGGCas1>6m1v^|6v$qpusbO%hP@^-iO=p0==r6l=CG|C4)0ujhrl;?5OQ6Tkt=`0pa;)0@n#ycH1uo*csGc%#Pw(^EKsCNo> zz-Tkf^c!-pQp0EB^b*fM?-xEf^kn$!DJb{Hu=tCG=Ghnrx}fv`W*cNIIw-E63PZM0 z!V3BedXV(GQs>(>k%Eu3?5Yv@wMV04JRWmlSkc8O z+-LUyCApwuBM`sxbph`QmP!f2_BTfNqY2;W>Y}7R@0-H*?c@%L@1-7axGqSr<~DbC z`>u0(d%k2yJT7qR{AR28rKO}MT=pS65Xw;-|H=|2K*jD4p9z(RLWDZ9q{*ROT*W?_LM(6Iyv;<+DNs*@}EQ$uCl}F=>AHB ztFwR8L*+eKt-9b6BuWJkpiB#4h~$E;!g&O(N^VctyMEbsSQ+}?j!kHsTPe@eIY zb+XW|vmOjO?4hM;>*2Qi4;*kwH|IgLlz)lRg0WfWO(^NtEwHXal^23Y@0ebZ#O|Rm zAisIehKTE~93`Afqm%sQ!2H!J4OrdU2^_E6qhK_V+-XYgv?X}%oJ~{uP77P#2?bFr z1_s8IA-SE#2DnJ2*b}^n@mwo5FX+G-<838tl@;d@?DM*xDBuRD;A`(qmyluv7x^?i z$%I->Ny%W`JO)0gjx>)N+&X{tfSDlmR3sD>l6|g$1c>;PZ2@FL5J7LvU)7ii2?-X9 zM?^bB!M!;XjKdheHB?BEn-JIs$+W|_*R065EXmKRqiG47} zA(VJmb)B4M9``3R8|dFrVXA{IoVe_eR7R^E&uqurO~Z~8w6e7YTN**SQx%T^m+ zz$Jf?uGmY;=(N^{zm&uX5}pcPIfAq_;T>$gFuyz0@3EyGoGC=d$4jV-i=!Q47}GMd zQ&&VEyf`GEd2*KWO2Zf#Fj-wXQ~lbDmz=P2Bj@^fzsFmuM}YEl9ZU<~ll;eE^St=mcix-Q^>!luxH^}M)UZk}( zOwHr;VJvW&Xz9%!HV5J1;0z587T~J91j#}CARllYomcAGevG%0E|lwS(-+!XHXTpj z$j3j9vShav#@1eHZIyZ@O7RMH_@=dVt*B6y%4lc{sjUQwG@qbQPIJ>(y0hE`N(Xm_br zMsQT{AEvzgYS9yUxe7!ii1qd1AdV(%0)r>Jh)z6uuz+h1t7yR;x2 zxU3h3X6f@{jK&@L_b+G3e**mbrBrABR-Nft507#YY++5Q%X)WdJ%!3~$?o|CV|%SE zs!Q63C@9S9@D%m7sxqdGXen)D?;qR}yHvICLZ^o0=6kv?M~NF78{s~IE-gP?O+)3< zk{uGnEGdRUnRq+c*>%=&TAwKMkC*1chkS+0(enX5tg~ZzCoMTwzdq}St@y<#AFlj4 zhtF&XZ#0oj##MV-IPg$X5PM#&y#(K<7?LT2k3QW$8uakbM-LLd4#EMsJi%Gol}RvHnPlpIg^_uhdHCCr8!40gAO2pz2fMdI`W~TG&nU0 zYe$YblY?rx0CJ?|F^1Fs*7T9)=VOP%$J%^3h1sH&T+r~Qho|n?W5(I{3w8-W=$^lo z!hsSmvr&{KtB)CS&)U0xFu<+Dx-THt$j&ZZ~ZD~|?O z|I>w_q#35|d;9x6Ccm7ZwZ4)z>!zG07BxKkz%%GHWxqWvKzpExv6c7F#f0DB z!=FrHOcSo_tI39RTI3u8Rj}FE{Zn#@=+QxPqcqMV`4G+9&ACn#cq2TuY=ut}YeTd5 ziS?s@?Os=V5z0wvI|B)7YaUY@k|&$Yy=t0!SJwMw>~qkrtL8z?Zi^v-vjM;{$tH{Z zJhC1S4i2W4vB)^gYIY66E!vfx31=3sMOh6zoFos6iMiaey^;Y}HQZ`4#HVbzNa@}i z7JwYfOR3ZyIVVW#DsVzeH@WqqNDF-7OEFST&qGM-y3UrL$2_$*yqidF2V2BRgtY5X zQYxu=_$N~j^GkaU^6DOI&zJ_hdS63m_mdjJ0jYL2QCs?`?P>5)tmHEsN4iW7F3F%a z;+F*YimkQ_-@haT#8%ySZwfRbh~ZU1PI`jO<~h8;_SspB7c^#No>$=BLW{fSj6o2{ zOsF1y8=M7l`0mxL;UK{3FdVsu84jgmKk6^B>N{Ech)_g76&^9%{vQ0#>gFl072@#) zyo36UsUKqE|m| z|0Hvuo(|N*gu(*+bF3{0;`Nq6hV#&ZrR^bv?;MwQ?Ko3X4zUEX;|#1KQFzqTv$OZ` z-P>RDVQ55q)zaQL!R0BUhG&qq*iko^f^=Lx&*>Vbw03N4?AfPFp3u3kxsXHeqfeSs zWZlcBrk?yRCo=BMIoWe|5X}p-`>cR<>T+DWDE^|xzs~Mjgn-?86y?_n1w;Okz zsD*Z+pi}YEX-Pc2zostl>GhrJ;Pd{)Rsr4_L${@URieJH?L_sVP;->SEUw-zC@idW z`MS?zW!(5RyKw+8jyT0Z!Cci4kFmgO2JuL6lM;=4Gv1M500|Q6Vx?+JWseBdccE&B z)(_|xKM`C;U?+Yq>feU#7b1|@Q$Sx@dUYb))IBY6yPyfCkmxmsT-*J>T)glXeE0W} z|4H51{8g^~McpYJ`-|`t{`bfJ|K^V^9-?+uSE-8Tnq|I8+a4v>2Fm#a=YK)-cPwqT za;SDYSuh^PSkNZlcP4$#8REB(gzs~Xe;>H9R^vjq^pKkr}9+4c$1JQQ$i5qskO2oAXY`zP3+SF$frQ+gPerga?|w@Gh-ZT64L zUE|FOX7d+(2|#uqBR4CuW2`LgeJ6Hf0sFfBRqO7sWa!So0=WiPfC#@w(Q6QqlxAlygDu`^ zfhjdVAH_G_>P_i{eqXx}eg9-7znGcXxH>tZqLm^qzj@8)7x}YBdh?R|CF=NOK)=ZL zws-UH$Vhc8diDi_hqUx=E0xE}op#2g)P5Ej^blcU9xycw0`&Cy+f(;2EN7iX9lg>H zEDgO)KPbTX9Hsr{cTUBx5z(w~jI}EmA0LO?Dy}7JtJ2Hu%{8^#w-J)|4cQ{+sCuhy z_tzqu-&0S}qeY=7(v)_5Y&@*TupZmX2?7lXJC(HkOAY7=iESK<*<=kYjEmNZxGBwD zaI)s-=f}$hIWMfxG@_#_Y$&Ce9}WY5yYw_U(qcNKQ}-Vuszb=wPpj{-C7X(ycU$P| zCu2a2my!Yq#hIChwhv7-iNP_k4~_>028MjdyD$;CgmhSBIcA8e0WBD^wIITe+iwXRwu7!$rXH`tWZR z-Pl|1*sX5J&?+yPAs1$DABWB2ZL|fnJjh zjw3reJE^AVt;_rM1zYB`bW};A2qy6icFlcwBXz;XYaTm3Hg?^^#bNE{!~JnEB%vsK zfl%CDVEQN)K1}-iTH@xlk#gBqPd358&%DJB#sXVMOZ>^ z{p*9}tqg0ij(v7DjN?7K8}C`Z9LU{S-?5b5m5J3p2Lp-A+gUfy&51)gOvOY;S1$l_ zZGlhMz)}v(sq2PN(rRab+;mTFH&oXRowLV_vfo$svBv)RSQ=sXEg7R zIZgT}C-NJoiqf4l8FPgT1)rXfT9xWf*WEPTC%JSgTpWa@p!aUt;c?LE=95iNbe z4fqF8;X_RW3c9ixiCz4gSc`=f4XJ@0ustDhIuXkGXj%4gSY-v1Fpa;%y*KL!-9&n5YIV7x7+`* zuPEhMs@!e_DesiZWEQ^c8N@h2`3FZQq!1nZ3!sDQ5 zx8ZgH+mfxW%Vm+dCJPTaQJUSbR0r_l7l z1M2XY7%|3n%JWKaiDb8@o!{7Ss>(;L12u8ug~*_kp(2Qr9pyPl+a>fA;EXLS|3}Uu{(#BQ~EEtL;5F zsJE6J85z0oLTi5olRSfYtHHAUcIsj2V%K7B%*;lYgGR~HR_ykCf=-^6$Bz|y7aB)! zq`p^!|0`@; zhX@Aj%^MCeEr;2D>b&FSF;ct86&}d;+w~;zYa_aOJOz%`)KsxRM8g6kc5nzwOE)#< zeX6MNR5Yl7*%ofuiL+teX+R5$iRFO3P8tt$N7F;<3xc>d!|H{tL;2v1nVA_l=k85@ zfaLa$?1+eC4H#B3;r(LuiIsc4WS=oNE5m8_2}NIKtWeU9v!{_#e-soP3)cN4y;Wb{(n5^^#+!ph z_vghC&b$kAj7Kxa@UtTyYg9{pg`VfPsBwI` zRy^Ul!5Q)?D&fEbw{O$O`M*os)a2+IP z*_rp28ELUOeQ0NpWk=7&MY2s`>O4s>5_bblFv8@fx)YtaQiVvunmbI{4_-cji$YjX zczg4GQ>zlEm_^`His8$vTk< z5MX`Ov8cT%pl7r;qeq{g;%8nUOC!C~Jawec*=QKIy>g$n*@6x>MZJ~h`{Q& zIg?v@24^1&pp*4^@)P)qatVW(9hOtMwY3!?CRE#ua44;8<#<6V4M#p>vn)@Dbvv#0 zZmL!xHQIrSN&u$AVpkefBR&s~jdC2JKeD$yyfKsSLwK`qqay~u=`+~grZLFVQ6R^2@K0!Mwy zj;-TDv~XGGQ$f<1D?xMUkLKeRyqCMA^M-p%H@)ZbR&u4+@|(lUL3l>}6MZ4Dc*g9W zy#d}fdV2cV*yELALi3);oO_}qE{y?C8ubew!dc6Ch>9vpzNH)F^o~btq+H2-@}@}B zWDtXQjK#6AqtfIVh01AKRIw!`q=y+lwGl$7*w5p_?RG7k@dnpnWx;pf8{<{4*0~8 zGO+K1)#@=Jp`wEX?r^Eo6`zMwnI{Td*@sA8w+7N0dY<{%Y06>Gj%e|8fP(K`MuyNu zL1qra2M@l3!T{mtWSLp#ewa=hpPEazSIDDpjazt_m?VVz zh)^yB>$M+Vsd@rR++3o57vEvfrN*;`DUj1QG&ZuWYo=$AM(Yc3O%KYp$&Xtp7#gn$ zr&#OAL@t{jNSbdu*l8mL*Bz}L1@c4zDyimU6(0+ZZbjo|aRi3qH`Zq5$R6`%4NNC_ zJSbNh{E*+}LA#UQQl9X$lz;?wMy=!kQAz5>SKmoL@x^fK{qr&-W+N4H6?9K3d)Gne z7(M@i`*U(i%2~G`+45wyl?Y*lvGtz*qSEivr0;iw+gWY1O}pWElz?^ zg5cA-FYZ`6bRdlR0v=^c)%!uha6w^V&nvKpIXldBd695c_}Y-XI?oHCK9%u!X<^a+ zYKOw7tA*Gt+F_F}+`k@DLlh5kIp$Fu)meAFsVaf!cuTFV&IX%pxDIkGHw4MlXw_@byKHG#n%xKOWd9r)WCa)Y#Z-v(~%pn$j3iUFp?wP2)(5I+aGVYDSwS z$5EpsbxqBSp=)`f?LnO=yF?-bx>j}v{6X4&TfYMjVvuNde_yHv*?e7O+PM+B{K(5E{`^Mru?40Ob) zWF47C*DNj5wk_nZf&JTA(STmS$Kav@#{l3?r)o3X%;nOvvS`oORJJNADRr%|(h_9I zB8-KwLWJRVcQNf%UlKUKoiQ}X4F=!xEKmlT`q?fP*BZKoNy zGqu#Goi23wqn0uBs+KG3*-e8LCi(rBqS;aE;c@9)!i8(s>dVT?zJC3>xLD^P#(9k= zq<|YI*sp&2yH+ym_!x5J$8gId%k4@J_wU};H3@;7(qgl-E?I-WlzyOVGpB^kO(2_k zbFCyjUH7IJH4`(u_`jiN#?cM9xFM}iFe){OpaS7&ezjAgTetYni)cRJ?%ON@nY(K}ZsIc6K%Ov~6-V}SI9>{4$SVmqf!dg0 zMj%AvR3PL9WT3sTduElIm>W364fL$nJF43VE$&ndaaxlJlr!<~*#&+ZtkzyO(kOhI z$^GIzh8z|UM78MLxdZVjGshb1>+9p=`nnc%{bbB788Mv+4*KIS09DApirG zNJ~AdwN=0!z|O<0pr`#wE2Nr{H#wVi)$e-k`~x^FmFdFIVL%mcTmg9nod^WT4!{en z`0Q!|+yddsoPWj%YOljR-X-Uu!Z0!#h2Z{$@X&qu~b#NT6DPiwyme%OsZiQ38FcLn(`wqF=)qo-&S)wf(#MTiO4 zgegbw)%(p5O4=(~k{_&;LvHg_pFAfpumHJ)Xjd??r!yYZx>763-H1*%Zayw*5*&oV zXhY+&Bl*0=BeIA42)kKN4^^mKyO?>Kij5ma}bX;XBvBmYoZ|D9fF_Tn3Jl!zX4 z=LYaEKtVy_H42HWy>|pUR_Eh>B|Iuhl=*-U-tnZH+z61Y89KK_HpeL|D@U&0eGN)O zmZu&6`%fs~ej;Yy2KvVz67UF*!E@h}Yv|+@PUCNEPDRul78Dee3+9s2GFq)N(Nyi; zOe6A$zQ=v1Y9oL?o?t$DbUrbiRBG%|LTYMLG~Dj~bMD=89$UYVr4{7vpweu3V`yw0 zn(t&*CR_`Jm<2iGo^5u;mT%uw?%e5YZM7M#qc?;gjIF51$fe_4Nr4zqI+nY={ymHV(FqkRF>-5)7$>9KbDQ^YV#$9e{2=MXrHT1h+JDcyJF}L?_sL?To?;^ z5Mo;OisHRbh+qRvxXJy(_Oy=y-IuWbo}MCz08b~tkWElTjy)t$GzbBsWkWqb-5ey0 zm<}Bc2Ct^b0VAlFrpbc9X-ZP~?6JgZ_jxbs{Qq27AfwrZ49c90GLaWAai{2!-w&x@ z6c0DZ#S#*#)d#{!EghjgZ}?0iUbm_l{C-6cIw=wRP)9!{@tVe6@%4~qSqu@VB0zSN6>2^n{ z?eH{?`AcB`4b{3lwjS}80K)F}*wKu^Q^}~~_BHKvixBTzy88Xf^V?5;A3sn`0!L7xnc9Bb+uJ+WqL=5VxZNl4D*OtS z<*r)Woc2yROM<}8CHu}1hL|7pX}4#)`g+~K+~?0Au((a$dOowiVhU0Ofu*0{9k>E~oSIJU@L%zt~rPXme1B|L5epp-R_+@aWcX zp9ytebLh_;3Nj8++!-_84Oin~0IsO}=EJopWCWK|lodz5j~bTzNNM_*)Xrg6`Hg?T z+bEl;?wGtVjH!^@hp_t(NmKOSoOgA0K1Plc#P;y7byU3epH#0t=ya~*Cy927hYV68 zR|gk*a#frl2XhiujI*8f=av@tDCOhQj&B|9igXvqO~HMb68SqS{6!esIw|VzHVu&; zre#3rgABt8q%f_;b@?{q)KJ|U9V3I%F2fW?P$?uRg`jCr@W?xr z&&6F2MnI&ZGf2qu-HAiU-f;_yb_loRyR`y%v|e zDlS0#`+@>Mj|FLkM+#@3H^F?pzUcruR??x#P_x*1aYX(i2peE}hTDUvDH5_J2*v?HNJ@flw3`dSk1T;4^2o4EJNtt2r1*t2A z{1jCy=QzZCjWJmp(8oGmo{~j+n$nOtxk~HccwM&OzRsd5Q2%TL`o5yamP9oAfxdo} zvEA~-XB<)N9G5q?{^g^pB!RX`!B!!Ak-{RQV6WDqC_x;vhGlq`6@lPKQ9 z1hd5M_~I^0|K0Bj1W5A88u>@jqSH^~lVcG7{8}drF>}3z48?7=IeF-eKC_9+LWhV!_Fu2sEKfi@8l&7csWnz3pl-z!_#3c+& z-rJHomRUO-G2F(TBY_@z5||aSdGzClD^or6Tq`~1OhJW5$r{fzqB&nrc6HLR6qh!dmLru zOfBrR1vcYKTW?UV>w=B87^2{vj~X)m<$rpMd=48yQ9R+5DuRkzuSjNLZYR`M(`UYTMy(HOtKE?ZvxX+o|r$i;GQw&vVjaFho+-mSUQFf{)* zeCR%YcQ%>8!A9KNA~(X^ij}tYF+g!{JuA#+!>t0ke3bi%X!{T)9j~GRYu%D3o_s(- zlj1Iu00<*{$FGI*gW7jil}9vlf%mD_@xdWtO2oNmHR3+YX?I%32J%Wv`D_}==o=jVIKwx`2{xhiO|dq>iq%iU>qPkQx?&aK!Lv39o4AdZ3sgeh^ZsWuWXEt8~@MOM+OoBcwsk#oodi!MW9Vf5h6Zu&}tViu4za5cQ|8jqE*9|IYiY zUrz*1E|8;BY5JQgSoRitI|--JLnfcX{xaNd#F_`X$}QRRlO+S|Vwa}O>A(Hw|bm)uNlP7E7-1+Wy zdZeXgCjpNs?o5CoQ=C6Vg}dnUUS`=alW3iWQN{86Z-e=-p|STo>x+5>CZ04?;HfO9 z*)}n5_wxAB!X|p7QA>))=3|>@^Jl~wp9`jLk?Vj7$3M<=F&kG?I&Uf#vED~(ik8Qg zS61Tc?P@+{7+_}$=cLDM9UO)o$ad~{B85Q{J9KIhw?1VH;>~?`JT!?*+G^S9m+JZc?WR580|N!0H4r@si5%z zMA}7Y^0~J_UiOWj$6l}|sbJt6Jtrr|4_9?Iw_ScpX>rQ3z1eQm1cQWOOyU z9+API$=^{~4KN=40qCnI7Dpk618!LzY+O-gqR$_CJb~aexSNYv_DO+^yGyo*P?5u*4|zu`iWkLN8psaxF!z3%Te*Y22cygAwaA(Kc7zOJCF$j4!eAKU=dU(;ZLcn zpZs3`X7%lF0@|o;4*`!AmQRe$TCVSlUUT+Z?VmCRXppk_`T4cAwbj+t0o-ZsZeDH# zHeL+{4$|usXB02^=tCaP-xCLLvPN^ujgRymnoW*~g@i@Vzx?DuFe)n;TStewu`w4V zWZM}@Af_=R0F&#ml3ER*CZ}av6bZENayC>Qc#jKex_lUi} z%?0Pk;b$vY94ai2n+2U$;2ogmM`Q};KJ895$0qXypkn^au)X#ED-8D1rAx}nL6bJ; z5Uh+0IpE_057z}jYQ=Vw(HEavTU#MAn3xt8LacxWJ*8joVA_Z8H{qQbRd!) za0Kih;9I^<{SA!VfX^cRScye)a&rwNM!vSU$Jc_6$1g9)omgaRvD`dOxaJMM1E(CV zU@R73JVdpwW3>8V_B^EKV~4h*7*_1T6;)jZfiBoqItcCcPI-#bUA%L9sVU;yGbss) zF7T6ziVD?T8?LZYG~+Hhm#FNc@{j4mqzefGkj_rA{pkoyo|`6n+%PPLOpofx958n8 z?b}q^>dut|FBB`4OPmZZm9Bo`>R)}|S;ew(*6#alcq8xyBZ1Nar_o^A=pnNXzt5jP z?>Vkh?^Zcuh3ASlyK=!RC;Pp|GJO=NR18#)9Jb5Mp?-NeScbti7_|y^7 zv=^)5uW|t^9kGN+N)y1pfYu>-bIkL6F?|QU7lu!^`h{H?! z=fI-jTgKfxo6|0G%3qE+toWwMY;O5qOT2yt~ZkMplFZRitcsVlWyM zaQv`Qq=lNKr4qIuu@TZ2SXp03a^Qp>t#*~c!`i3V{uAfL-Juq}Wo%YjLv?ohl(j!L zvXsn!k9D0aETze;=B~0tZ8he9ZB|T~;)qsi^*%FGb}ND zcP(iTGb|TW%3tTum+-ts_KE;-SZ{@P*YSYF46?^!fk}uvu@;3NE6|6gS;R=1yLLu( zcXzh$4-G$55n{i{`THmQMKRp^;)2<2d|yAg{B6fKKNsO#msRUA-15Rh)ZLzcWeM_V zYj%1;-BBCt_bgPAc(uZdJdyb!NqSE5C_v^u8oaNh=K#l#`Co{lvV7$5?&OE&K93(*1|4^E z^yG?GP;C6A9VYLXt?g3DC2u%~^N zS>{m1Q&;tYI~g&}Q-|q%-s$=(=%(`!G`y!Qp?`tp@9R2ueL6J!{p~*>F4pdTaI3VK z+krl-A$qpSflbs6;%{&;1!O`+4ZBmVZQ8-KAW#u$Wruvfkwmb56c=~h8PISjb_FJ; zBL-LrAlMvzje`9J|MS~?9|I#bY9cLGTU|*f`r5YZ+~=j(={pyk7TX!OCdUG9H$vFBRp`j;%3 zgwruEQBB1uASdjWb=3Jz0*k}XZ=M$06IT7>>#|d&PLVuE34|_W$E%048m>T~B3szD zyzwjnZBw~0wS)Ok2&wRT6I?v<=q5gDRN;x94P_)ev&Ft;(G1G9NPFOZ@jRhui^-h& ztfAiGeuE1)lY+;PaADa}ZGM%!+3mCVpD4aq07~g}(PCGB^d^kd2Y2SdYQ&{VyBI%) zGY(FD;0ju`SM;Ejg@PpBCCFI0UM0=180!E{t3UpMR^aH9UPQC4mA8Qx${xkC8vOX!=YzRZ_XPw5hRHaNieZbL7(uv; zxmBcAEPBMY^ejC@Z>TObpwmbO{!qB^&x7k1iHED56eVM=R|e%`&Tge#%gKivquc|Z z7Ed_va_w!ZySKCv(ZNni>H5x0z2cfhBNd^!wr(5|koT7mFvLXq{v z86Y#^>=NubT^sm$#-Izx%e3U=W$XEa13R2;ClB_~!6|>r$Xh{CF)lYNtJRiRGU|1* zqHYVX?EN7F6)`7W-G}5>jp$ifj9mfISsPd2BHPK9y3$&zl#_8utVA;xe&EGJ%Fs~w zFfc*ZI+6@vjsDMD^%RH^geOL(*Zx30K zwOW<2Z@4|@^XY`B2bzpRe>}c`;}Y#{pFcl3$x;sVAXwz#!iXkuANmUHZ?9ryVL^eQ zC9u1Pr%S$T(|A_H5nX+r`_TDBQ%q1m04wneb}WB`2=;(d_~zqyN?~Y7AV|1^jyTD| zs$P2xIzP2gH~D{%W!5g>ODjC3@%w$`_s=@*x`~x3G#Kh>OCDQ~XK??qXgZcZywySX zZ1lz~q;s+kCPrH5xBf^6ZX8F9Gq^*?bSL`cW=RyvH=~?05^m0#SQM>-SfDA&eGBO) z2xbeU*&O?qo}LB-r!I-P{@SGDYQ$w-m2Nim(@NNG!-K}gq9IqYjkw6R@1iUiCAw z3D2|TZ9=9NV6?=;?QP(fHx}3X3=WU6b^^!#o`;ff)0l$E=L%hGtgN0%YSK86ybAVK zi|Kzi#Ytr&mDfpx}V}3}@{A&A&=P@xcAWdyObN|WROZeG^aA(|^k8ml74KthdEZ~{B8 zC`mY1lNc!rBM#S631BI% znsS}Du~~wUs8?xB^sEFO|6GFz8O`7!im=)@d6aZkcp!+7%IE zA9C+9yn0|_avpQ~{tw|a&e9uIGem=gRB3ldriMntCLSO*)E^{j57nHuz@N9yJd{fl z37Nvzg1iRJ%LrR(p1BxxM;iI;RllcB|6MHbli9%8IW`WhK#&3m$3Uic3)Bf}YU0w; z76k-7Y~_jly#Iq$Ar7=(2svwby0^xDv=^BV<@#qZ#p~o*9iY`CtATH)94%3u$`>zK z54Ydxu`#HP;1{OxC#pTo1t?FRJgJ~VhjfTyZhx3nCR8fb>85p^C2QVufUC_c?Wn5P z>p~?-!TM7b?>R#KvIeZWy>8hH2qadT2CCJKWy1mf!CTGmd?8O+DuUO*e5<|+E*vzP z>gws1q+3-M|JM8Hvhr8HnCue3ZRaxLm z%g6*F#fketO7OV${UKKs48FoSw8A4oC8z;?ZbBvUHcm-dxf!J5Q`z_dve8fu-zFJD zK-&cahBj3V4O1>zqPGhknV*EovRG+(jS=IX2p8t3-rl`gW4n2kse(}LCyLLg4u2|0 zgPoLqYI^!&YeA(ty=N` zdV6mRrIYy=MqClPG{tbkj8)UpGCvjv0(NK@eA&>|HA+(M1)QvrHH6LIh@jv&C*_Y) z0wp`-aox->81A z)%m!^1B#uJ*HA(OS`m6_&nJ50`@hblpBnkR6Qnj#7AAAwPk!a^dCg&#^!)#l$#*N} z=9+bS8Yb&OIarHkKpgkF*ZY08@AzuQ56Ci+F4NZ1I*UYxeQId5-7ZFo>!m?AG7F2b zg!t-dZ3@v|UaHKXI`^|qZRMzq4z@wYM+}FWpF0?7Y7|{YGHZT2G9D?jhwxqGX8-Hx z`z5LX+kX>RD6ThB_ahBM!(87-49jMX28<2pHA$(n!r?iyuUJvfuO{@YJZUdAZRfw( zqm@-jP8swDWqRz+`B4a$I}}t@!79Z(m@_8U2QU!4Zw7xw>XNJX3)GGqvQ!T%2oO4O zHSavMcf346R5{g9C|urc?J!^b9{CZbN!Yvn4}a$0K0LIYJRn|685tsnLA-zW4kAEA zXP!V{RK>jvtuiPy5BCVz5l)zcm8s|BowF554}A(_=6_Vu#C$9qu%evlg{Y{=Rh~g2 zYEA7l&l4e6L0MeTfB$OU<9w}ynBEV#=5ExsX_t{)o9|$hjASKuZ9uu0t%hzE(qwTg zPe;W#7%^;#97N65bMEPauaf_DbpN7q5<41jjo6?RfGIeOQ3N^R&-}BSWv4eHhGDw! z)w9;U!G)w8B?JekI-U!N6mfTOYSG@wW!V3DE)<%%yvBEk&uN*==|`C;ny+^GM3WF_ z4`{WYk-|00pi#h*fCNth=D+vA_wf684~7Cd=%20#^%y3#<_Xt2gg&y7qiJR49QeUn zUVKbj33>Q2vK{TT(fP|-i6CD025W%SxctVEM&cJ>5moD4RVFWLRN~uV*!bj;;q8thWf0kKEt5pf6AJblk+NG5OG0jmyR~W0akec zE0&)M`!2`;kskU)Zov=DTE<<-6w1+Wug7Si#)*`4IrA(Cya$gaufIsDA+#OrC_a|= z(Dn4Q8b%w0kqzFf!PPgE2Q$fukIrf<6Bf50d-52Xx7bshq$?Fxtu2yf;B&u{2>e=pQe3h=E1XU?TNp`??LGn;*>ZQVv>Hqj&rW_RSD`zh|p zUVr9Z|6QZ?q6p+%KezcbCh9zqH1+(I~FXRv3& zp}DEax%hwm|F3JUZT)~3`6ShaYX3WIrEMdh+{`iKgDE)JljGnZK;-zp{5wqtdsIhr zG`g+yd(2%yN`Zv{@&eN9pd~+yM~T^s2Y+HvXj~6Q--hY|$Q}2kq83_T!J??l~hS92-S2}gJemFTyX|xK9LK8d~_P%+qTgs@lMW{ z+dHI!AcW>Te!(+cb6Z3QqKc+mnJG>sE?M!B+1+vW` zw5nRO$nmq*Te~+iOT*fVyq2R1mF&fyTau4*mB4oSm~ecEr;r5uf{xoND><HvjpiFNgPzGxg>yu z*0*j5raD7cktT!G2mIMy;$Hky4_$^Thovw^7`WgO7W)tIyjW;N`rD`-;p5&^d0r>? zUrRkJu3@2D)d9IMq=bnZ|1Rc8PiBdm0MZi}ReWK{F8lpPontu4O_A!=s&7$On zp$xvK-QlS(Lo~rrcXe$Z@&6h(ER(%yPe9B2DwoT)*M;@X)UZeK&_gN@={MvXIcEGr z@r~hOHmi3@HNL=Sd;eM?8|5xaU@?Zv%Reqkxt_l9BW$?S_>sDy*m_Be;4HzM`XQDl z#Nb!gjJ*A4-gW77rNXO8X|mc@jB(e;7OyIhusz5A&dGrfuk_KIO8;0rP}Q{LW0;BU#{S?E>7cviFCt*`>F4%_a#5gNrqP(@obxh(o3 zwXwk2(JMjSs^{<{VpJ4|nY8%4A{Yp$vu%WkWk8f+d1T90B;&Y}pC<{psXRl>@hP8` zWlW5soOxf?UH#7~e!c;{sh-W?a7IW76V=&y2f+narlVKV7+cQUYZ)jg#xu5@po&}{ zBn$RO9djINI3JBud8uLuMN{HuNEzyy4r`NQXyPtWUT5UZRrWU^Ya+@_zRtt4Kk+Yd zs^Kfd-&fbxuK7c?BuvHdvfBHWe-Ic<o+am~G6WtXE_+I5vnJAJk! z96V3G{(B=#E!*cdGT=uC0QoS zZ63Q@=Vr&&tsj~|M!b5fdcubfrVuCx8Fh(T2*9&dRaLuG7G@s#BtQcr)YRBXh95l9 zD4WEb9D7||-LuTQZ~no9|I*86r(D&9`#3=BygWPr2Pj@43{8lSuM~Zb7n%$H1W~^* zC>KCiu(q-izWN8MFXt*iMv01%^D*Tox&$p2YimiG?mu`?mtBA8cgX=4TyUCp=cjg8 zc1Yr;QeC!KZRZ|^@NX>-Q7@YRy5TISLyy(`H*ekm2MPIyklJS!8%6QB9@jY$)B&%L zJ&3qW184}KG%v0uD7bt>hzCC0*w}y)h!EG+P&R?8>7AJj{_pe$Y;S;j8SSf)9r@tF z;PIf=mXMT0TY(R>b&z^mxHyyLibS+FWyvv`fwC-`POsOI2aB?=g!vM1E_E=Es#a$B zN<1+pL|VP*G=fHYs`qHs;u8|Qu-Xii>MR2fwUF~|Wk_Abx9cy8%Vw-!_-c@02MO&5 z%c2>Gr|r(;yPP-V4uzMe8;k=SX7DZo#Exq)M>x|@g(P>!PsM5lPzYlZCu`>m@Ww=1 z&)R34Ie<|Void%F*L#MAuZxTiG+Z0U{H}|D8`)1J)r`|-YZu|T7~8uxvb!>_ta_y8 zm)T~o*J1yr5`C>Z1Kf*(cNFw4ri0o@mS*kqobFQ{i6U*I zfJ;QPS1>1arGvm{jPfg=m&o9}Xob!@IF~GhIFF(Do>IoIoef5%4ASX}>x3q!d@|pS zMW6Y==45LNElx>I?(4q{t??R+=(y?l2#~nEqAN@G_r^672OqvJuGn0glcSYcxI5pB zXMgLMCNbZa5}Ou(HDX>lhLf_Ki%#YxuYtubN5A?&w^38J!QS6}frW@>S&7Bc;I?3( zE-QQD4W)mq{lD-V+{zEx=2gn2Z$t~MKP~3+n6LQ4bTHQJnEPTQ2k(!M(6TB=x$)^% z<1^O6<9$PjPfAB_$(+rX0$cCgzZg z+p0CE6s~U4D?S_nSnoKFjHUB`(k{QrRNoEMz#prq+vhI@A zmk@6G?5U@Cuk9_P`F4`_b?rNHm#PN_SW^X+4wyvInXKL%=7}>&JETJ?X~(H<2n)<4 zxgsC9#zHo#NKtIYaZM*}#$*;W-@!ELwxFzZ({qV#q zungo>7(O&&#ZQ-|y&GL!vU`9y^U9t7Y0E2J+Q~}YvHl^aBUw6exo_cpmieyRYH>W5 ziGSgbs`gm7o$3>}PLbkvCLSK>9N0MxIH*Wb3Zds~sOo|i4kOe6RJbR>tU#C&atN{} z6}zXY_=rVrgJuOtpRnr#T3<@-$C=5@Oij_kKoZtyFkNOl?T_jM9w~7uw~09H^0PTg zuJaTg(Yg@%Z~KX~DS}F%kjM$gwKlJQOd3`t02=v9<&;s^2j23JA0r=kUo%%6gf)4en;@ z?mj!0*Bw+`8?44%&-9q-ZC)sOJ0Z8bo7F}>q#BL2X zYi=)(wwJEGP%~fh7AX3`rSoIf@`)LmY(az4!-jvw=GN4YD@m=(dWw?sFL^!Xf*=i^ z@X-|8Vd;DR{tYLY8z7fa?6fV9!*qvU*NtQatCT?Ui4T9u9TXV8F_EP6RB1W57~x|F zM;{a`UeRosg7*~YGfAQ~Jc{RxP2Ff>1YGc-`7vcwrZgA}yoQf<$e2;beB7=-Kw;{N zNawkn`PhiHzvT6+knpJ9FUF9OXb<*3*x>EYMv)5y2I3)x&pr(Sj0no-D`OXH&vO^O zo@HM+d9me{U(wah{-d)(;O8$FULR+PSUjYEq`eL+bl8eNQR|=WL4GY?`8m{%coKh7 ztJ)^lSfBL-cQgBL;05KK&+DC_2JzVGI=1OBPQntoQe-BP4#7o&xc%7F`LOf*Hot_& zC?TQpMDigpVIq39KePkIHG z2tnvE;)FTA+}3;Mh3+3AyIf@zXAOIZb0Lk(1Hb$M4dUog!L%Np9-2PqmcG#P#cSt# z9qx^&)a}&hDwe!J4}r+&RBdT%2XQ4$K+lDfn=IC1|AVw-Y~AC>_pG(porUU99Su!q zxAx)j`@y?4aa3XY+KC@NwN+IdvB4NF0g2m=f56t&ij3h*Y&zyujdGLYw*$CCJFhklkoPvS~j%ZLz6oiS7mw~ce_28RZ zYb?<$H==;GXGlIcjUm8l0v%<0*Uwt&DB;q`$P!NV%6#Sce-U%BQlpZCNcW=|GMyjq zrgiq}BI6J5Sgw9;wp{{-N<+=2ueHlTjrWBYK!oH|XVN_a@V~lPo(XWO%L~1YAd=WJ zS5dj-^(@}u+z9iPMtvh^A{LaHUKHAPp@Ca6vs5 zYue<}m?dMaFK&*R0Goos3=s~P#@3q_Kg*FMMR*GBkm+sBQgz--LnPStYABh5j84*m z^@UeFN6{&tKYz~43l}ff=DeH-5|=Ik+9l2QbW61`37{)*T6SyxGqe2%hJ>_GFROej zosexP#4BWof~UHx>%AGlr-uMK@U{ZEotn!bTX+`rEToL`Fn&g)jgt4E?Cpix(?}8Mq?@SSQnQ=k66NA|!W3`uir@ zGb;vbZ8x_Dg?2OZ1Z1?%&qrzQ@U65aLjH%l|3?8Id;R5KbZ_kT2li4cMeO|;a6cb9 zceCls5P(8HEY8_0h!Z#`FE1a-u063WI57=a`(A)4-HhvSj}s`_)+dh_gTt$^kZ(m##LX|Av3?6U?(cIYcc?z@S42zwPTs)QKYGkbZ%Vieqyv{;+XkrJ20zPEyMJ!L-G?3p0ErR2<<%2;lGfne|IEbohZ2x1t9>ws2Wf}#ajfTkSpj(P}?TK9fu{uBJ5lY zacGtfE+OU%(QE@FBM5fv==>r?@t-)f8Ji=}B1GUEKlfV1r2KwHEv3;g6S)0jxdoJe zE)Xnka_e@stDU!7!htwDX2+i6(5rjxOG?V^vNI2hdIur}&VdvF4BnM8pr-(C4*+Hi zD8Xg%jC68AnV=nHZ7oCN$w1Pwvd!;$id^A@NNHTm>+S7joUoz__Wi{&H2`jh?UO3C zphdeR0+e3fsDQRvfkHJfoCU|t!<>B!XDPzVXm$!}f~0$AqqCr*pfd-NdkZPM*S3W( zV7x?z5NrTPLe<4ClvzyBE4>@$QJ~N&$>a6RKa#y{UDkg9=zYgEF@{6qPsrAs9Ibff zVS2>Sf|X;wDvj-7*&X#@8~551`iTWbz*0+Z zpf@au^)kT21EpM$T85Yr#0k6DEssh3VV-u5e$Pk;c%A`vvNF;p|@FBRj==GYr zt|aO=>CuVje_M`u>x=Zq3y3%Nnt3tk5S^XbrtIBV)gJ~b_dm##w8cTaeSqo2n-;2C zt`%u4Pa9zO*bf%w=hs;@2<+|bC=9(H@qyE>1Yyq6aE|dV znu|wHznGTjQwDI$`K6`G?GZQm{kd*mUtgdeeZzTY1&C?u4}Dy*pYO>8g`N?bDj+}2 z`Q>*bIjg&W$!}uOV^h5!$l`au7c^)CF{JghyhvR>m-&Xbyp=uPwbu`vmq~ntL)a*~iC46dG}@VQabAtA8>`Ou<(I73o$VNPC1o6xbMrf=sZp0f!y`ExIVo>^8|# zDNsb_pBrKQoeg{Uv`Fzw^QSjx1^?XEb>Bpf9{Fcps)t~6g*3SHsv!N9wpc3ja*dYN z{5*IOes#Rwd=zhyJ-I%JB;YPIyiCnTuo4es{;)_Iv&gF_K%N(f&YytoX}zOl4zNzG zlLjPc*hRbZFzdSxhYP>6fEbAXc=@*ad#ImXWLQk;ZgfKVK_f|S-6LT6mIg)4g5LO0 z_Qy$TZi8FK<_cI6jU1ctjL6~6h*yYCY6)%+Y1^rB=%-cW~`ES*3-9U zs=*Xr#pns*S@;0=9`hQ?6K3mFw5kzt}wy!SliF06Yj_Ndhh? zXuM&GRDyWz^A!X@ab{-b1ss0dgLA>Nx&S_EC*7;7!wgtD+B1`wpbPNk6|X3KLl^d$njjasvl{*! zB%|jZa{q?4G6H_Se}Nsbjyf0jY;$@wSj%e>fH=C)`@{?Ir@?uCSC^l~XXOM>)@rF{ zvjR9)V^@%rS8m7Oas?z{*JQ9|md9}*pWa+=nZOF1^a0@dYq|T+5Cuu#6E31Sv5%Ak z)we(R?0-$-Yj!qAYCayKUyAw~viu6LpOVG^GosR(OK~j;G}o?4lY0`e z=x}VyKDLhzh-}rl#4aFQaGH69{#nt(mX}X4JyPZfZ(z+r-2%=@zSpL2I_?yD@?+VL zURlqAZUjWtvxFvTu?_`};k1CQSz4KiZ*J3K%;Ya`StPo0*$)F|Zb&c*CVw?|O&k!TRn$q^Ni ze%5D}y-vGs_BCfzxy z22(&izTTuk5gV%a@dNKX@H_*25&WN@z{<5VWSWVgOSkRXjcJIY(a}N9VNX&N;)UPbI9Z8Ss$mtPHq=fan%Usl%1ZUT zxlmes={2wVJntLYAKiqvUllvzT=s@j=y75_VjvYb@>>`#at^va8ob*LkP}SOjog0| zdj~WFQeb@td=v_SLB|%U+eX zh7tA|l8vv*4!yB^mf3sL>K+&Fk4!^YFc1_e15=c9<$xQ9NPv-Pl8amc7-WrK8~Gq~ zl9xz4_*aw&5}-tWkjv?o?W4XYa-wXn{+bv0T5jSo#(tOUb#W3yXKv7~r3WP$J?0er zSE9!%?(4M(=GSNw)0(~}Yz=5>I6v~hJihXDh4!CjKIbzc-2XEBp7szR7s!avh3Ig^ zEFmV(wn!{MTNyx(XwZ2}cndgdnfDMZ)wKH>9#9x{+JO!9!xq0UDC5#q2ix0?#sxaz z#o}5zT1Lx_rmnB$7+<9r+5<9r2+@)LE5ge^P1r9PmpY6vpAIzFpCHgbkudLlpg_+H zm_Zb=RV~(W5KoG2v`d=#V}r5yw!V>I4)#&-yhk4BH}wU6x*h}OU5`Al<;ODbrRT#% zH?>AF_ZoaxudG18s`v@_As20^-h&aFBG)~x<=nN#OrX}t`7=b0P{|?y77ps}ySAcj{u?O~01J-Qleuj_u z&FjG^9O!{nGa%2}obN(0_s)=Ipa09lzf+GV&$#56qbfSKOzM8Hih@$xw>ttgfD)(x z@6DC4TtaGZL#7`e32*!IRPq!@C2O9-do%tmA^}%Ez-rwDL6tYyyaX)CnhJo70ld&9 zU^_$IS7M)HeoJ%4{7jh`5n@=G*(+e4!=DkS&J1-%?q#~j(GEHY27?*0XPifkD6ck= zRs=AHli&RG(~t|i<2azu8(ZUsroX*V>U=4)1+AoRzP`KLmS{P$>dqQf%{jhVLt`$D!o zmJBDeq{Q@ZugHaxQWgel2;3faTC4`}4S&!5jsGpmfKuC}|L#PS8pyl=bG~qCX$fHT z!b2~bc&VM|4?WpB%$nzo5y*M%WefQ6e#P}}tY@)kJDH2^oP3M?l^so_V;MCtneF>K z5fv1Cjfn(ewHk@R`77)uoQ}=nye0E((L+pKD4E^kU0KHe1V+0 zW@L@lddrp8%I!FIX@4kICf>)Uy{{jAt30iQ$Po8!`Jtutrt7UoEZ6?GzbkcZB~Wr# zD&~{WjzJri8S)V_&-dGFn1=D7M!SX_P;{DNYoQ?v0|n{RlJsjCi}kS4qhvQfP$07mFGGzQC@NxHJ`(TTyrYA9%76T+a9vV&PHo!py`da*8` ze}dY8ug&k33}E7LB$RMuH@~FNH^ck7wxAW?2{e(d!yoyYP9B7iYieJn?U~_Kqe*tYxo~}I>MNpQzYTVM2maJ zR}~?YJ&+WegJf8F>}rJe)2I9l$lWjgi!kdEPt@{pWSi$MvHcyEXZCTn{C0zxmNFsN zlFR_Np9i>>FUle?;0<8LxZ`J=y*|lTQJx@ZQbPnhOT`;BZ;}c?WG5t-Qq96kTCp-E zq&a%o*O>|`m?=cJANJc52m}J8i%`$E_SnOrMH_xXm);-p#2jy+PnV(@>*zog@$d8)f6)m=e+RcjZ*EDc&Ua~!UAg;Qb zo*lO#Y@0sMdAeP^FdZGreFWP>`T>3dBD$o_Mx1&47Oe(%C!#*ew-FYu`DuFhu|D(` z5ROYEtDF%gRj^fM5~F**+WKY4o@UiNiv?vrZF6(*EDP|lf4)dL>{K7^1Ryf};w zZ;y6-E((3ozC2S^3jn8<>{bU%<8JKbEqPB`#T9ZSe2phw*|k1yuS_7E zp3~Bj-++HV`oN&RHe5McS{#~nzFMpGV=d5+XC&qdpRbmxTJ0!+Prm!FfcnE#+2?p| z6lmbmbq_v8KI&N4i4G?c>PZGLG|q>=+DHZ~DP?T)EWm5qQ4<-n6jNGEF5+iu2wxh1 zly+C)%XIFyp*9hfWSD#|45zAbhrQU?fx@K&j~)9 zv(2!EO~&^Y0%W}?!{S>rQ2(;%*e#H6jM;R;J^-LWlvAe&s52!9hUb_BonOBBq?b0M zunIS!J+cU1BkBICWvtsz1XbiO4pg3B!eGe z6&%R9H3)A|U@1j^M0*2~J2miK>PEyB$V`5 z$5f;ZP-Pkf(Ku$L5^}|uQ3v0(xMz1tWiYj5xZfM!7#c`tPG{QtI60lzf+o=4@&#pz z_yYSm-pssaIzz?wEr}~syL!b`9HBzzd9R*5*&O~?Y+F2zp5Zxz>sG6m`p;y2c9>uQ zF{#@|hv1141(E&1HhsC`uj8-Xx05|5rAB~oO4>AhNvc^77>yKLV^@*(j z7HN^g0rfn0ZBzLxN`#-^)V_V=0?gq?0Q(0CdAT1Y3k)TNIV2>{_^(PX+~wGV?BqF`;_r84w{@f^$F%NIBUZzSoG#zRkv&h*5@tb8NL+8je&zZo z_e2uyEpRxPo{0jW23@4F(ZK6AQzb3h+tLMQXoJDTn7oVw@P;H1Bv%1 zHdj~{QV(VQ#x2y*;XZ)O01du+rX%e+zPvFK%F`5La+~AWD-0xlA4Z+mWklD=4+v_t zVZ)o)G`M%4wy3hVpy6shW=Gd!YH|^FP${20vY7=t#Wz&w+<68>YP@`(IuYxzoM3ow z=_9P&RwSn05?O7$NuxjH%3YslBM>{PQ$g-d*rSZIXKtqLlP?2 z^NyD#Q{d}Ai8VPY95&vVj=V-|iX9?Hc2>EUi;pv|#_{~AvmznU^ph6_sH~s}exj`M z=p88^WaSzK{ne}B`0s3Qe`iK~0}smrRnpUB?qU!q_EJzDb^#B1Fu%;w@Z(1Ozy=G@;{rt}LOG`|8fnIFOxqGPIaX8QK zk+|`!=noT`5^{dA5D@)hCR=RhU?ck@LPgea75i}NHYu>{sA|_~S&gZS6vn0JWYm$h zmp;uJXL%bTB1^HmIBeMdz`dzD1g?)^!&(OMCseHOry->VxW$eFvvp@4oLz-}Q)2f9iIEhht0Jne1oxP+KFI~OM=8US<_ z(1j-eENm`1QYRU^=l3l9w68ebm`TRvV6#9BzD}-q{6SEM8X+&!?%Po5v45`#=(AiB z_@He?7nVe$&(Sd?2l-^i#r5he=?~ivccSV)$s1Cy*1N8AS<$515VHEay%tJiwm(@$ zh0xahJ^=3$5)||rZeZ1X{=8h1S=1P;$%lpjyZI{NiaD1A#<`D`9sfltK_<7|A~OTSaEdz{UE?9@$QUDamZvKm3S5n(#=Aw%p`-)5zWDdI7p%Z?YR z{=2-5?`Jf(h)D3L{-5eL3G-E;|4N!~a`ApYP*T&so^l5C3;|EEkQ%vo@BHR3tmlI< z$KAU*Fo4k#clgY72`8{qc5Mjc9S`K{y_6P#`Bi8N&^jvDiOLrFv{<$imqkLND!}3QGC5gVhS2rNbQ70-%K30T_T37V4E@-tO)n$a$^; zPi)}g!`yUd#Z2lB$E9r&O?rX=V0v=zx6w|V@TJz-+0;FDJP3D`hYvZ{b2dJ(zmDBQ zKn_3b<`ni$nR2sv)sjpnRqK0QLdMXp5!fUO?$e{^NO#`G@2=t=9PIhFQb)!|3&Mal z1Yex)mG2cl_pto`n(QPXlfVa@t%ObeuM><>%Ym>7sFZ*w?>P}A9-cpU9S!*SJ;1(> zF*7^c8URrVw>CC3vioVOE$~S55oA>y5*cSza!5_jE({~#Vx?B4vrJtw>YAFgp2mDU zJT`C9s1U|J5W->{-s2<`e2w%;5Raw;9pD!XhKX1~wMzsq44is*Fz2^{z6$$YZ!?~n zn&doUQ_uzlP}3SOPW&odY735n3Z{l1l(Bey#vJ%hF0Gf=W{QdO@%aU~g|3!$$3{RqmAR{GZ7wQYSa-X9rr7d4Ff!Doib-d10EaEXIp0u>I zKzqKVRq^1DU}6-gAQ({JzoQu(4b~B#*O`&}{?kJ+v9F%I%qTx?O-S_xYT8BO7N{%0V=3hazs7$sYS7zqbb#g1*JrCx(b!m8d&(JH! z$Hf_e$~kolqYNU)O#EV3Pfw{d3u3kG+W=?h>~+SOQYoO=O~wrvzT6-!2CW3dm+J{( zPV>b;ABJ;# z0nw04=f^bm?+RxVnf#Cv1u_KQuP}gK8ccgO)z7`$J=tUPC73FP@&<@+(~~9(AQ!=E z4fYEKNrSj2wtXD9R)0c=k3#P(6z3Nf#w?B12ef6Foo#PgnwilHkA2!tn{jLVHVUgS z^=KIBR&uYiV)-@J-#Xy+Zx*i)LPLk?k=INiCkGZN!u>7|-~&DCE~!Jt9ujS=EQF%G ztjFYZwUgWT2O^}bQoRH`YzFs1nDE=FqYgP|oE7LGD39*WKZB%2CJ0kgT_>!0x(NV@ z^=u2)({&*#{oR?6$5SSv0Zr|@mM|(Ns{NC zp6$TAR#$ELN+hfaC}{Mta4IZjN`K54-!Dc1r<~35d}F$ zhrG2I4II%{u-%KBTtc$kqHl6BpIlNND24u{M?U%I0QJP9kEcZx+?OV;MV+>SfyGRU zPFb$N`j9_8aOMUXQ-Ihy8tFV$Fm1`f&^hh7U%<){Ezyg+sMOYk7)qca*YnUIZeiTt z;igLfW!wX>P&g;Z#guE2Fanv= z4fu=!?8{v>o|n9;coN5gma+&h_k8WHGoKLgJ@0&{M*Z3+rqYG=9X;m04%}nX)U2$n zYpV3beD7hfr{nP~p%GG7v6><(q`D1eH0j0Sp7kyZ6Ll4_5xqbB9YBHxFl0Mb6PGyw z*Z51mE_wnh;`b^HzDyjYv4m)^&N)_69z^D^^f} z9e@bk1Mf6Dk9Oy}>;zWQ;>U!pn!eYuP%cd9^jWDGE^%CyYFhmA*WgU!gHn`NHjIx9 z0bC5&GVbkz1>bY~r1{vIyhn7kr2elI3X!}7dP(@4NCmrjVOPubta@%Z%RYQ(lWCwoWs17@9E{ihGg5k z&<6axPlw++?U;9WBfTPqhdWlo3eIY#qLp`coe=jupncr#SQOQCB4jB_O z$?p8eyCuCqzzybPj#oct+rT64lW?~!J^-oFXbq>gKLW{r#}r~C6AC)Lg%=Nw$J0zzeSpF^#tJ3V)Wf2A;QiVD@HDLYOr}_ z1xM8J<(lPZ4RIIbe1g5yM-qwa(J0wSmx%=8Q|D!6ks|l|FX&zhn^Fdc?5Cz-4al+$ z!Bg( ziq%sqdrwbK;O-bCmtvMNC^q17=8=)&X{waydn9la>VDWN(16xG@&zS;-x}q2i0sSV z79_e`Q!=o?=zy-#?Ol%MgF%#+M?HLP-I{T+LsoYmlLvp*aM-zQx%Xq#eql3Q$I*mw zdlPfi1wu%2#Yu?m2>V@}& z%)ek9>Fo5rUMly3x5a)Ah#i4gsUgx%_U>N_zP z2e!v$zn7N>ska|;b+1pi0g(fsVmE$8jPs?5iJ$g|y}dnBdPTXIpJ+{{vZ3^M8|pD zSL}FQ4EZlx9~>2+oRZ*qH2t*gXi`nOa&u@FmEgG#t|fzkvTa%wF-M+r*0u*fxV3M? zZE!10Rvc?liHl!`^nu>tyDByT9E7-vN+&@1?hxMeoY*Guaxf&KqYnalWZ%sMFzn1u z)C-0n7Xu9$d42pf)r72u3IwlX97TynR=F% zJ`GSNQoQH>=Q>lBl-H!6?r3j+^~qyN$X)*7WKxy#?C>DLAo(;s%T6yTP$Wzqd#3rK zfDCvx%AIK6VO1p5l=|A}5Vf#hHWzmR4O$$MFa^%EAtDzs&S7yp*Tuy;%L)4dK*N3= zfCDLm-LSs?<~L1NC8mF#tMR_nk(K*DxR-YtxvkxR8}sV~q9tytar+)1mXb{8)n?Th zbnXQ4=I&=ZTIm6jZvff`@DwMJr-GtaG}Y9)0n(1=-~mm{_+hm+qkx5oq2(3d?@@$~ z_wFPoPrW~J<1sr*O#kxbOmx17cJDsOy8^%x0dJ)z5a{1x`*r;8J0OhVFBeY}14^1b zEd=9K6xfJbebvmm-@f|Wy*ePwCZ}v-4;fRo7|8#rbN()cY@JOxgo&|F5x;iWzuHCo zo%H}NPYb8p2V~%>f>`p`mercqZCv+APJ6cx>?pgD2d7wvlN-kzM&Og!5jYxsZR)F& zae5Cn1%Pi01vV|^W5u(%$HS8kxET)PrneYe`U>{temCH>_Pj9k%B7sF_7Vm5E zA;@iu+Rk0^y|dtuYIv#L7xQ>iJ{FjpaMGC@xX4`xgQ#`R(~jgJVaoX3i{FW*#d#`J z0<~_8UF-~~8Ccc83B<|jH#+N+{RVq&ub`B(KhAlrK#BObgvsY2Vq!NE`6sTX9|t4gVmn)wt?lxY$BLN>H#sy~E<`<&d)&0! z`ueP1_HInfG2Cq#&sfbdWnbC3m2Nx89u=x?>JSpT)(B)yFJrFF0Lux zu}u^BonZGM!GZ5EI`1p%=sO9zT@0ah^e$ zGU+mdUVz$A_7=Ryfvb0*Y-=DxyDMw&u%3TQ!@l*{J)>k>Cu6hQXo);@lWZ(2-o+bg zRd&M#h?`ju+{_Bc!TxlQxexC~f+%rA^>bWF*hgGL#5Vo;5dn`HM4$mh_gM~6i1qV=BT4xkqdlrdm{NR2)j3R3Lf;&?m~D_=)JWC+!mO|y&$>>)VU zFP%Q$$$z&;Zqy3Fn{9m*eeE!hoq#O?4%hhq_do9(ZC+(R`GPC$eIJo-7iQ@7{(OE? zoOeX9&F0u66T}(pFIDMPiJaRY`^)GO;57J@xnksxIZ^bu*k5@i?)_gMVtD!?IC0ef z`~VV+0QRqOF4+Cw{%@}p0$(P`DxUbFk`xmb z=r6W5X2=RFdS*ImeP=2}_Ppn)nz~Hzb)UTyutw>cZE;@76{nky=>0Z6*HhkNcDn5^ zk8B(=*;l}d67r8eED9`St|)R}8x*qc^qgG+HOc$UD%^QqUcAvYI@uhtfc<8pnv-1t!M-fcIj9;Z zN?mv>qo}T8X~eF5^O=TN<&tl2xpsVGD>bQf3xm&I#J@lMZMglx{HSK$>e%;&tNgx4 z&Mdc|z^u$gD(zsg4AYhaZAUDGo2F3vTS8H29GvLCu6*$)t(ctzoqc`Y(#%a~qrg}z z_?mBFcuFSv-K7*E|VYj%tn%d z(xes?jDL%>g*D~ECLF#Wol2~l+>@pK%{~8bE$;uS9G$a@PV=%2SJ8oh&zApV3?`117C>Xn>LDEdOao+i# zUm$}rQn({L9E%~yyC+$wXkz@!N;*5v#k+jgXL3f!$*_EzyZ)W zY20A_A$`oIZ)#ZwP{DCsCkvFWzXwsKbXUk z!Zr-}aPT57$U*aZLpSX9xYB*-DZ5`vtrHlumOgzqsFW2@gg<5^TNJGV_8c8QpXcoh z?<}5egST@i2jhn%kOe>aB!N@&W7yYDzUA1SKCfK~6*b&*2<~*!`t`8TYWSPVN|I-4 zV}7U7R}z5|Sji%{6>Fy@&QCTi9@@fWozy!Y?KHkEEhrF6q(o~?X3cqCs+^kL&qu;oSKDybNVvLwf}fNu=UF2_qA(@p2RI}n83b; zWtEP4Pu1#b(mAS2n9RD`_lNyrFt?ABdLb!mlHu={?JI>Saan4-FwbPnS6cJ7f96}3 zGCAM1=m9>}kG?ey7SV!q#xGYs@bsr1JYGqq`&oY}X83c)mlqN|RE_zbnTHJ|+maIA zihm2X-z*Wxy`@0%)8-H}tV9MO+|Y8eP3C(So`EQ4E)YDJ;9lLlq+0M%cyYqDZ`iZr zZKE#q+SMOnyTgE4un7&jTFp?x{U$SWYxnX8hoWx1m!3E6Q>A2NWVreshwrAGr%mbm zPXE$KQU?9r;-M#FWCKK@pinZJ?3#Q)H<#G3G)2ozn&$smjEK{!{Wq!K9x0*A2JWGM z#`{>aCVlM~-q6sor7jrMBk-mGqy7EdnztdM&sT_@BF2aw+r+{Sv(VlWL;J zt0-Rf;h7vIqD=t~jhj}U4!O2XMTYatG)T&&Ylg~lS1w1RKinP1r1LmRytn>P+A^6o zK|KCTFZ_RY-f8z)k*yKncE!O~2M0z>Xhr5`vH8A5d8f8qlM}@0Gwv2`d^pWgNU3bZ zXwuEbqQwU_qxC!}sN+?~$vZHzL{ti?TB5J2OQ2Tm`jPYJ#Y7Fc?+Az7#%-rUwpG$d zN159O;h%ck?=#OQU8&rzuU~#~&^S9YquBIFlb(bHyOMY<5wJ(vB6cny`KmiTK~58A z)j+!th|9ZJ=u!2Z1g?<%t=qabmbW!PoU5bk+}0dm%Uzr_qZ?$O6jVej!O~vdJ%~5r ztf_eF%8NRjn33pC#5jLHEDQW8J+sf2KfI`$V!(OJ@1*fh`|REZyd z;6t^nJ)vNyQm1a@4AjcjC#SK%PTfnOJG$QcF=WYYGhIG==x{;ycx7EZUbOv}uQ(}A zH|pOXb%aby{~T;5HV&LwOJZA3i**~piD?2NblG^?`7_Pz$W=^;%y3fUfo=s8CwFhQ z1N*qZ;GUH=!@S0hGDlts|At1}RQi{dGoPI-_Wkw~RU@u^3$Av0s+9LDnVCjYpyq|l z+QULpk%CBrTn}xY?-}&;`6rLt1sOfA*9`QuTOp1mixRCYl z2e^@wOazBZxxznisM!{qeRL5Zf4WRKq!g9#UlTTome?)y(MqbInd%4vPk~T27BcXU zwesg`8U*qp2>XscHRb4VV zE{`)P*dM$Nd6K4^XF9dSXYLBye`JrqE=g=Q^48}uTgh>s<~rXZ86%@dPPvGhg|Wl; zq@luFMMbSG@|S;AGGn&FqBuQVi!B3HS9J;7tKNa#qY{YO2`3Pg zFx865-TK(1>TG)kr-2TnroW$KsYKtlZ9-F^>>iWVr~`)8<)VDI=>}FUi6y9QDfjtx zY~oR8M4Z65&G#O^kIU3PPLr4!ZjMW=_(Ve%S~Fx?Vbzx-j@zh|`#?ABDoSEi@bb6B zudYO_F>UNXQ@X3Tln`|%f)7Qn^*vEh$as7GD^wJOeKEh4_a3iklsXd9{ESwg&dDS) z=&!$9pgs-N1uqa{eM2;Y=wAsNPDKee;K)_0`b(o1ag69Q>t|#R~*`-WMBhO_V%mi87 zDpn(Z$+sY@+!69jUl4zEEoip0LYqCz@ib&%2feq5p0s5ZIkIBl{C&V_r#Nt4a)f=1 z0_WZ*+rQjNLp6gL>+rJGZ%jdi3!C~gIcRK@~}`xd(UEEa1cca*z^fac&}auf;-0V zSA?#!-EPGVqmam$ZDeAyY!n)-&BCQ%kY?5-(nO;IU^bw2>OD7xj7evfv zA=9r4a-4p9dzW~ihK)d5F>44gG9>*j{7RQikO%I_eRv?L^~U|*HKjyluQjliehBjS z`IawVdn#69g7v_jK*lyMDpY<#gLLL_7)D<<&IrF&5d8(*UIby-;0oqGaQSd9bsHtN zxwG!nz1M|y+Xm^o)Z}9`aJM^0^}qWr@j0g0VKdIx7gnM;QAuhb@rar0Z1b zkWX+9V71F{J+jboCUmky^9hCe1?d}kui|8nuc zT2pVvGxXcGI5Tr|&HNX?qBspzc?^C8079V|;46-3^q0Hj(UfCi%qa_ahJ*&tNH#tDC{n2m!12vL0p! z824qDU}Av#3cE&*-qu1t=qIXTKvSDd+G4a)yWoAcviY&4^t2^WE1>@4);FIZx64V zqxV{N<5POe#%!nBSGbVYQ{7O(cu~e~$g=wSNp+*$)X1Zlnf{L&3&=wv`H=3-k4J@v zcVTUnJf>4~)AUh@yK+cxVh{H&uHmfR>{ zR3M?N>5kz}P^x@3I1yu>rIeeQ*%C%>Qtg&Kgr!(~OQoaJlPAM+#&jxij!chnyKWyNE8< z2sILc3c70e^Co~(KYf)ve28a47I>LWxiXr=L{rzkh4*RQrC=klj2wME>Oqeqk$x~= zKZusUwcy&A<_HMUmeaW}yIH0Tr*PhTV?z*F%r$Wa!B9C@bl+|DY#mF!?^E;Vzkqu& zhH`5rJ{PQ)W0Ch$-|R$q9i_?cw_JzW4zO%B(mp?b zDIV?Gy()Hu7MtTOkqmqyv%3dtPikWll+kY~{n7v6bo%a9HDJR_6q@k!`R>IG)d%w6 zK+KJ}o zp>oWNcHI=Qiz_-_O)@DryM^DKW%&7qU=m8AB##uR#2x3V0> zH4qVhNl)WkoB)r{UDa%R$Y}7$aJE-Ho8X}bR82bMLe?B1 zzOx$8@m7{S8AWJ_*io_UZS2Vkepdb`It)XOf0SP4Mjaa;Z4y}TlVy9L#gKcO$L=eL z;}s6w;&JzA^hB5}yHaji+Rr57sH%0FYN{{jtNRwPSMC_x3U3V^ zb-nfGaLn`t4(|PviYiGo+Jt@Iu_q1V>~J-j&oYL~(lDHm`v=uM(^d%alUvYun{k(i zJgkW`f^@-VBFcYazovY84LS--osHq(abgHL`Lmf@2|_eqwVhanOz*1%_-W zx(ZK~WkDlD6Ue+}S%K>K5sYgSSacc1UdS&higl|5TU(cf&uZueu7SM^W(Ta*5zl?g z(SYZQvn~9i7DpY;dLQCl!=bDNnR_xwO~5F|Vcy%tv|ky5U=C)aB5lMUGLL81$(5&O-!dC+wCiJF^$Q4=UbqzNfpl zSMwKuw*pssOR++;84c(c>EPT~Kf`Zx=vEF{Zyh#sw`nBb65*p*{+!+jw8Mx=zB=gh z@bO7=z8rc>nL+MnNC;28grkhj(bGUX8HkZ>&ULe#KXzmWBd^jZ3}#Dq`_s9_Pa3ae zl72bAReQ7qjTa`@7m82c15sM}j08ASRHjeXz22+P&GAI{KkD*nX7&f!@k7%stINFZ zM!JXZ5mx&x}WBQosi}8U|lruBX{MeMqQ>qj<{Z)ib7+91{cU0 z<_1`D%sQEn+Yev9%2EE@v2t4^LM21q*zef+PV}4yKQC`ugLHbbmKFKiXmnODULEG& zABW2Rph;8br8DOKSESbQfo{gI;q(37bokNi=*Pq1l;gc|8JGfH;g%m_(#)RU}PkBQT7r$XEc-YJn2j}qYZwW5hxn}HPW@m$Ozgz1GeA?!^H;oS{Z=Zbb15jwd`#nkd zYa3ryC}R4-i*g*ea6?A7<|JL(3L_v<3PCiGK0M_V5f9k0q+RbD7TGz3Cy+;vlpPuAUUB zduV#u@8UP2|L4cCksLZV;U_RBeNG5SSH0frak&v*-0;}3Wz}~1xN0B6wqLbo>UeMb zt(dDvleLhkJE}}D!KtYpzPdQN*A73H#77>dD^wl_lKFO%OB_D?TcO>dEC}pF@N-Y` z`=AAON+zGlszer5dM4)iTs!Pvwckc*|298rJg5rpqY(u@W|y9L7R}+@RU65O?GY}S z>gBTOvJa4VrAq@p>F`bD60T9*P__SC;rz>>@oAIj)$6yvkM;AI(sH%k?27)~mob86 zrRE}sf#K6LA+VybQ0z=9v)K#V)hF2~M6?Fiwm^zV)XK}nmS6@yzXDQwai?G`2`%4) z&}rG}VaRByV>;83J-s+m7uP88pgC-QvoTKyM0nMbh3$(oa{J*A0fPRoLG_nuzPA8W0ydDV>dxunO^cww)C1Iya1Zk*~G8BHO3Xqa9F;Kp)mgBoNh4FN3{Ws_9OS0eV{RnZhZTmrfx5n<(70}B1Mv)<2VKG zw--{0z0zRi?OpgiQWmH-L-<+C(^;kJBaf%L*A8vfZxc_6X&K$(2X{NL1ou0lV9l#O z3n(ajCjur@@HOMexe`-s*W3&)dFlN>Fn8TrVugAaET&jB@+lQVZ>bqMm8?8*fOVS2 zqFIy?G0NIf-(<}B)>a?Yp?M{j2u&4jSZ^fg%a zxo$>_HskR;3GU&al2yvY)+YaFC@bxz8o_|&W>w|r*IEH9X43?Zo(QVjYqMFUb1ddJ z9^gtyU1sdc9Z=_B0ovjlfd9uBVgYz{0E@$-{Hn&PY>{uOICsLwufR`rMpzoxwIHe^ zL#JZTkJc*Zd8CeOTG;q?)_bT;>!NR|iL%t~sza{xnS4}J3T|Ot^}PNxB_F+*RDRmf zG({%@g(-7qYHf#5sx)3l)ymITD}K@3S5-I6S(4cJY*&Z>7)kDD=Og-%TF3cw6N`7p zdME#jzWLtlUZTCWs>PzwrN+1Kcu=wmhS8&q7c0zJNXk}TREZs}hTN8mdiQ+pm!`FL zu>)C!=S?tat<+Aji%TV)0m9~K;EqzajEw2ps=3UX=nfy6;64dfcHAh-gw<{M>StzM z*V&(=Z!WCDRCjFuPjlz}$oAg<{f^T`aXP3P%{f(76h&1-(b_v!?7g=dLCp@TR#ff1 zcTpo&jFyrjLG7)C*wm^W_d9LR>2p?>m3MC!f!IzQ*JAe05YvN!|2~>$yuT zrpedhyEc={bT-_IGHU-y#F&D$%M{>1wbS&gkR(SiWc0U>6 z{XObJ^8Idi51>p3^Gsh{SQwL%1*zUyW20~r`(!kaw;p4FOx_^+#rJ6AFVn>Z{oo63 zjozWwaiKTQjk@cRp57QJDj6(Lrr&j;dhqor>UU$|^(HD2TW(MUq0$bL+h{yeP|c$c zu93G{F=Ah);yBlpcJ9(m%VYPh(POh>^oI)qY3TatG}AW9s1oKi^s$2yiGDHl%ycQ8_vlL>^mU6Y2@7W~PGL-I+eNb2YqWNH{*} z)SkL|uu1VvgCZ#=RJ?faJ-YO|xPgGO2VMKF`pY?d4nOCDsHM5j0UiQ6Ia{W`$-1!j z`j%vs%QGk8i(nRK|29%kYK;sr>GC~d3CO%4jz772Agh!(X_Bqc>M&DPxK3P%AXx>< zpMm`%U9++vvPrto-30N1<9*d>oMCR)#$CzH!hyfqlf&M?r%A1!JJ6mR)M{&^(`R402IN}$W~Ij& z!sMM>u^uT7My(>}b3fcMz)Z5H9>4hyldVSY+E;@6$CFeK?wEdhO-559$spijxjFZF z@q9O z?xqKGu7?XKNtkJ?nDSxx+{-RA9ckwfkYs~i<6zTq>RoH53yT#%tnKPf^tBDgAQwVAjqgoRqU z^!i~Y>pEABCqVzQw1Q{r0hEl^m*7)64zp%eZ%@p4{rmnhc0MSZu=iZXt@O>z?BK_| zEiy?4+;sKq&J2I&Z9-UphXwgM2UDt6g0NRDh=Z-697KbSB(sf<|>O-4??=GFoGr^TAu{dxDRc5ZT$N$bA`mTAM zaPnr(UD4Tb8+qy7(Ct0*C|-&DBHE*uG$!rQ9At7tM+q^C32zEbhf28{w`N1Tq`}@P z1@cJ`F+_#D5aW%WMIBwmht?s&-C0MMjl>ZV_}fCEGU*OxpBDNGK(KmA51HLabPgOJ zGQMPH>38X-eAPmJL3(8dHVpVy?{^#jGL|{uwn&2~ogYN(?<-}CjE}iVez$Iu300fG z(%f7KLvws`t1Z}QHQI03*U6*LSNjqoXRhgal3#@zQqALhpk}1=*dRXtjxctUI+&u> zGzY)U!P;B!k)Z)tqZM^Bkq&6T0J+a{pTzV&Cc4;nrB^!iW!arX?l%SyG@L!x@943m+qbUy_e z4kZPYpg#|8Pyx{?VOpMNhFGplSD)Y8TFi)j#S;@6JmS!xx4aXzBx!n9+ko!n&B^q} z=uvPp7%hy?1t||y9B9Fp?#kUUYV^}Lc@Rfesageuob&`9K~+sFtg3eSql}4plC;BB zveC58PzUi>@hahRrYs1bC0+-IlABVhnXBRK>|Hib$C<_|tZc_pdTRtEhQBOxpff5J zeA;%qsm-~YENd{h>e>_~G@pou z+UpcwW*W8061TYrBm-F+V?4CTaUWoT`fkgneLTUs;`G(2@g#>%wFk7oj^jm-z=&hf zF~nJ9Q=vn$Yc-%pNK~$5Wjo3qIbz>%Wov2d0qR}&w%@r+x@$uWY?_^9?@m>>09_zX zjsuUh1#Kp41!$HXPt<||cMNC!istfJ#>>uKSeC8&LKH)C$Gb**`nK|?uhzkQeCp-J zwrwuza}fG<9K1U{$4yMC@;_zwv1=5m)!VJSWy?~KS12`3Z;**hJ!s*}f7xjNIecJ= z)gq|(RZUkp+Ql*1ed-*FW?8XlAs#Y=cA4}Z2xd?y{J_AJ*9FHmK?Dp$$J!_t^BY zI*5N}Y#^2)o+m6J;GL9#%=jO+%hvW8t{w5TPjfIgSC}vd)jmy0{|%nGP^T3bmE})p2?Bp95=vu<$`2CoX$5A+uT`5+Almz!in-+eW(>LrriGTQKus4ID&v(s9R3aYUs29 z>1&PC$CUU;xeFJxE{M5(% zc1`6pPY=B&q@7eFeq17(&S+eUcY=c<%7~i7SHp-Ye9k5MwpRMF$!-gi(`K{=CnzMV z#Gle_?+PgK#HZ)^*TwRAa*pw;L1-#oi*Gm(ZPzzdS#unnqgzC{eo}t-)Jl!y)ooaDe>VZJ5HQ*=jR21qV5fh9dK_g zByIO|CMY))W~V~r&a~aZM4*E;3*Qo|;+lbQ)!K0x|23oRuQJZ>57!@aja+)5+pm`! zGsFNJ(-~zKAh%Iay&OlBW#dg0@DH3;8!^2J!>Bb1NTI%`za>eIrF|ph%u{O;Af7QY z1G0E_I07)6aAbFrJy)P+FDYXRy=j`r&|1QvbZZTDPswIN~(_`m=;OG9fVW?k%cQ?5_TAqKiMA6{J+g3mcq~l`MGY zc7=v-;&Bs2wAza_ja!X0*Ri*Hr={>NFBU&gm10|#DX8NULBFB>g$vEu(v}^1m;4cH z9y%G4qn|t;SNj)E!zFMFWxZWphAkeO*M_Vu#ZovI8|l#kNxk!I_d?sw)AQfe<}bab z`{-Gt6(T}Fgzmtua*U9_m3m=s+>=77%p+{+exq=AklIt+!*vlz?x9n?i~5+fqKWiE zC6NAkf0Wi-|1xjFCR{t8dr?n)fCxL)TA7jfAJ>y1a^h&UxM9!SBD14Wz5Hme46pny z4}F`7cf`0?h0xhKxE`Mo-`{qbkFCBm^{ zFvalGSBK~B#Z4MEuE|+HI-Yfu{?uBU6mI2+$A|L@F9zE0-XPvTrbbNyPR2L~%Axl5 zPI`2cE8`@qd)G$Q)0I_gVxug;yqE=7dhurb;b1CAU;mic{#1RA2@`6LBj66*8k7DA z+@~lA=PKU;cHNY~Z&)YpRBih{lo?UYa>jqblt$W<8=5M=VrW^Vbz#c*HZHn1!?SU6J?&-vG-)m7h4_Wq_7`WT$w zt*Eb!6h&ur3iN&Of94m(0`tE)>tv9E@X9I+rrZ`=QCk z6S7IA>jT9G4v-s0{(P8oxCZ*lCcoAy) zK3X1;5bNb(zM#)qbAy%H;p|eF^o$IqM1~0J`G*q3O*k`8eU!;~P1l{vA-uvrkd5_#Phdpr)jW6`O{C~{gxCE{09(LW9>Qri1$oHupI~+d`a3%1Yh1V{Xwqv(AFWGQhA98=wYh;mh{gej5JbEJ`#p9AU z9ynEhHjhWHpVN8Q=_Mxif;l45zs+^P9MWLjY7<7(~KIyYv1wMU2I zS%u$}zRd^n{3HX#2<}cPYfyUq1KbFP|G>H%8ABv|O~{Gj-I~x@7;s6z_id0wYyd0R zjglMzT4~Ql)vn8k@EfOr_1TEj7Arw zrG}hW`rqw%@0Wi^)f*X#(}nr*+hKNI1Eh#So7ACHEdEvmh)E}Db7LYps>-KxxK^Lk z?fc3d5SH;H+F_j|RTF}wQ3m*11`D_2=A3d2Ty;~xhrKT%lf7+}HfGhBui9>pUx4oUJBVC<+~MFX`4q zG;U!7;5jsZ*h0=xy!GqJVVm^O=k;yM`&#wt_6_4B-GC*0wp+t8JiyUFmAdN!h49V)3H(?d7K>2BD%9;i@PNH#6 zoWAB6B4Yf_r+Tze)E+1WT0XqaGjKo;by>5^}vM%mZprFN}r4h?C7}paX8GpX-_5RvtQNJ^;_~F z(I2JZHFkqKL<`l}!e>Y^0&H`4YhEky=;Z7BSTF&-J`0}VK`9T7>d?=x-4#uc%+SPV zf#J8oF?(cScT4Uh9Iv}6QdD<3R{_P~dO6vAGfB4NVX;9CPfp2zgPC-%g!sG)Y<>C1 z)&2O|udJgv(s%bvG3BAS+%4>yb6?Kl(U)kdqeqc}dkJ?i$~Q^bt;11;_wBU->-SvhEet*=KsJ3 ziCdcP%U|eUh|s@u%u}blKcA^n!qT_KbYuedSrp-Nq@S*QDxW;87j_S+V($?Qa{i6$^O0iM?3` zj410R=Yzye3ym^!hO}p-*lJEn0$ybJsK%{j^=OFQQ(v%TaW28eBhk?TnKH+X$=a`A z^q6{x>EWsarIs42?h8rq>DiSqHv}RS0Bhg}3b;#396?wL;6^THLL{)ZpZ&?@VrfRO z++fEAXlRy5pfV4@cIjeP&Z&k0#E?$ds|rc#&n5v>NZJ^9%|nJ6xQ#z5@Q;jzd%{S!Ugz$`Konn23Z0& zU{^uL?qJoO9RRO{ZwZC$4`OWBSriiodwZv^d(15@>7uNo1h%;IFXGaga~0@g6;SKT z94pBgjU(2Y)PJq@|B@cH*Bj5D?allR&=+Tun12o$FrVfWz7D{yjencMz9>FStzPys z%Z>+p-vCT#dwt>_>1q}fyv)6x$+1Kxy%OPpGuUEgU0mIfh6bmUl zNq$GQ4=L1)b*$q9d$TU}J#XiOj04c7h%Xll(5M0&=tIe9Lo0K{F9XG2=|{=kAThSG z;M3;1&jB??3taq6H}hH!ug}5GDRP>*5SP~vn0PUO2NQ9cmOiy}Nh3S^)2XdkJPCab zKk=4Np~*S?Z=`V_QQSlas2kNVuuP8VNd=IP99l^c&#;mFE2l(;WqU#5MZsLA0)>+A8dp;$yW6x^I#0-ssW6xCIBe- z80mL_i9hvL58a;?jEAv2kV-34CBz!ax$t5#q#4nh;k!4(Pt*q+?>+cZkt&?{ik<+}isJWZp3O-29sGzlFg95>uYtus%zL?>?pPs%)GuD z!gbL4s97^1Y7MkPIWI%obH%``gr|u^@B#R8Fby!yVD;L^f!6>V7d~Mpm%QauZSZW# z=ySS68`rW_jEK+7*%)cDECH?sI8A5s)hm}+6d8C-rGaP|uPV7^G}a37=(u@>V)BEbEKjBEA78=w`Nh>z zg#Scwa7=k(fxhX9s5N@eiUVFT~@==>| zL=Z72K}q0ulKQV)KjNGaYJa-Zz>B?L8_BUTpC)`@fM9>vJpXwQtngN^lzr#S{s#8)Kn<009D|!fU_!3u8f|ZKH&USryd3V>diRbc-RbR<%-@M8qA+w9;rmT zq)3M=S!kPE6E!)tZZ5^VUS`YO;c{$L^5^ik(p7x-k~Sp>;usA@?c5R^}hJM z?f{(eQizLdz94k4NJz?A7Yt*;A@E9GCV>E%UwdoDvvZ7op3Q?0sEe!m*i7RWQfVSs zlZR~#A|T-he!E70u}}YPQaPM;6Yq~feam=1fa-(ofrcmen1GlSp;E62n`K$TN=PvH zGs>$xHxOZ$n|z)-0gnwFUEk0#9(s}QY3wU2E5Y?qTJ+9cE6&;rctri8#e^!-l?`tI zRb6mz;=!)K*M=K$vb*?7)3n(Y)vqD6+@eDHF<@r57eeUCNYHd~ z=UgO1>9QD_=X6~pT?N8Vr4&O~Fa$xk1jX%gyq)1a_vW*Vxk2olwuSate}8f|fC|5V z?rXsxpx1x9jOdCKXC&#+{Gy+FdtpQmyxo;`Nc!_IgzV%Cw#} z-cI$p`=@}ah#Dd-Txvhc#t_i!%HhqHqLCqz1q{^8N5@j1u}<*QG7F6@Ckw^3Dk7eL zuHX$)&JI(?e}>SiS?6RgaFU-s^S$B;!!XeBgSk|qAn~79ywYcCKm9~5pM!Jo2mK4e z(bqRIVlyitCy$ALuU3ZqAm5IqlIkqq|Gn5HagO1e7{`|5sZ{?e{P9nswzmk%2}B4E z8VQHKC9Yw9yp+ehNfkl=sNMYa%xoMGP^te}(EWW5{=X-1|DWQ&|Cc|P0Ifc@K$nzY zgM*RcQMZYFIF%esWGiyhAxyaD;MtiQ)U1ExKmUDU_8*)liD4l9_#OesI^Plr+xg;q zGbRU2R`%=c*e=$ji%_iHmIAU0BsaD=uRe4*nr zixz1xU3QMi3+g)@zQmzi1_*1Ccl56cPd{EXO*_(a`qPX2Sp3m^&&1(UL;aiw5Gae0 zQWrTqh^a>{w@JV#HY%!Qpl^bRhZ-sH!Musuq8*c*@p_BH4@dWW75;M=z{dL_$dOAk za}Bzls!iB=4egXoIUKkG1oL7S*}iN=aLJncdm@uOJQttg4aU57@*S4w(7ETF8Pa?> z|F;(f5=r_HBB8i`Gvmd!gV&6Xh@I!&u1Pl+GEui7N6cd`$By(ke1SISQ9zQ(6}~4F z(#{8<{ZafTv)oGPdO;fCK6AP1BzMow{BuP5?)~tej_pCcO_40rdtdVMu?#8P-h2Ip z0OHYE-UK?6ecjz}tR>mYKvP)Il6T+}gPu9o@kh1ke}Mg`p(ooId>=Ol0cLdmE$GBb zdHK$&&KaXY#DJo@;^Zb?8l)7`pWY$XCg1^OLI;l=DgY4-)IaF+(?1VJ@G#7GR3(Q@ zyua)XNw`GDf2hW(?k1DBa;)z-&JnH*%2YLskQvthU?cxJ1x%u1}v1C@fRYM5JjjO8L^xp;%j6td93fYv!Ns z3rD4@NJ#QBoIZ;P-{Sf$7xF_p?e98^zr?xr8W|w{UsYML;iM@Ir@zKp0DRcxE?s2r z;0|N6c#FLX!P0ZPAB`1G)zBL#J5iUBVPbQf(bAScxgU*4&8%*P8mPwD8nMSKljN zCaZ=f(DN4Xo1iq zJHFH4qg4Xs1gL9E{Fss^Cu5Xsn?_z^`hheJVQl1<7V@p^bYsFchp4k|_@vVE<@BJo zHS(6a^uD1DLI+$^N-ChUg!@%4A8&C}&pawm^;Dzdp6ctn_nJKi^m%$F!iE&tmXsBu zcIZ#%Q~%e4@sT1Z2cYuZ&{)9Bi3sGLtkdpTWbrLK>`EYQ8iRNP_c`&&R5NGq;aif-jUC-b|UfnP5BVI)D7uAEk{E(7e*J4H{X__2vLA zm15!4@;B&L?s4qPLQ^0uKWsiKdWH>E@A9QUx|Ja*i33LixPP|3yg2`56WQ~E43ba< ztHkJxU0Zv5%5B4v?4ZfcUUU7qyG<0DN(%qjzqmiRF=(=?kI>f|f|B)x-z8lhnr${y zIr)4uFi?Y4%3YnA6KPt8E z!@$rstS_Q%KkQVJv44!J^~JLb>~x1wBK5!x3+KRqwh_ThEC^j@XI&n#{)0I{Lo90g zW!q&wk?fn-#YK7>de+b!lz#VKUg z_WTsNuCBy1D6$8|gP^(%0;CP9kCy+GS)urD*{TKeS^&}KE9br>AHVm#MoC6OQM^dh H@cI7%+3xD3 diff --git a/windows/deployment/windows-autopilot/images/wg05.png b/windows/deployment/windows-autopilot/images/wg05.png index eeb5a9beb872a64d5c7a4ed78240c14b752ba560..cea36fb6bd9182ecd9686bd0fa066f5747b6a04c 100644 GIT binary patch literal 133517 zcmZ^~2Q*xN^gS9aN}@y$29ppyQuJXkB3kq^x*(!Q^j@QjA!<=yY^|K57<{nvYUEsL33+;#6c`<%1){={f$C{a?dP~5t8i&91Th0d*8#NM}V z5w4Qm2EK`ipZNv+B5>DHg59bdX4?Wj5ZlVD%ip?HlW^zKk_7ln{$AP0{njn2?*D!W zP%g!9Zr!>mPXOzlK zANBty8cIw?!`XJSpd1k%&LwxN=9hSfsQ+%=Fh+7?flK^kA>3%>5c<4sGGpd>o$biN zg-qQ>y}MEEn}H;5wKT#1`ws)dfmMzF=NJET$Pk6#7tH^DXzd%LQ0`>N|9$TNbv1$N zH*P%tudDvI$A%>B(I?2w#p2Dg|9vyQ*O31hNyl`scylfO@PFI#A}r6o7$&VExZST0 zb8eccWiLmswk>YlI0E)U|6ZLej`aU;n;}Ar{kFzBaIvQMBC1D*B`Uajh^Ny_hCbr2 z&!qmYYFEyybepxV+-^SBeD&U?LyNtTq%h8&UzC`B2!RJe?<28Cu)yOmC<~1U7 zbneM*Kbd#F0Wgax%ZD#hz2cV4Wu3yQ18-=kw;mugp3KHGi?)!Vl$lYEp#e`{BG|_{ ziP?tE3j##U)JT`zUdG=Su-t*mUwOSwhwi(=)E%L)i1qshuQ%VHCkJez&PO-!OIls` zplr~WPu`pwiofZRsN&eT&9o)oUHbGr?~()u!ks7};3o|SMPKVRbVqo}XUgS$G#x+x zR!!J7$?d!Q%+h_7M@v7!;RGKd!~O)Z`Q6O}v3D~o`py^4lJg-Psh?Ggs>sy*73 zxvun)1m{%#+(sepI`ouLJmT9E}}^Q4chuvVh1{GXD2X!x6fuIJ(SwRJG6u1nb4Sei+~}<13_V}l zZ(V_4{v7mFt$ke#Cq_a}kT4dqU#$ROdKx(m%!JLyh=R8MJT~ zi@v9fd{p5TfkydkWO-wjd*dQ@Ecex8|JuvpHe<6yI`_3BXdxuXhdsk&Q@C(&<-B&A z>4lOKkHzQb&kX2~I3)Vpj#P!Gif%Zkf=9J(V31!OJydjVO81o0<<<>#l#XnqX(Ut+ z^2gCH5Hx}*_d01MRHw-ZR(KSh42s%I)d)dvZ@;Lr?B$U*oyq*(CnWJQU`5Z4y&?)9w^D<6fmE+gk#7#Wfr0cuD~v(WM5S=*mEkD?eWb$ zxLYv{clWzfKPVbRRzQq={(>xf^syT5F6+95A2+m?!2a3nNezwEL$K4!2njzGQn_~G zh46fAW(m;!*RXduF zA4{ZK(?wbjp7QK&-!i(_Pd-T2o;F(Y$d|BRpojEqtLV@54<9==H^qyQKF5NHelTMA zD-X9%__zHfpZ?66L{SR2B@nqJwZTI6GyROg>~kKBU2R8i+1S99&Hb)pouA{B2)^1K zq}*G9SecV&i9{$CZ+QR>9vm18Ytk5`s0#@f@OoE zKqu#t=0Z_(0cX$Ic0I`9ndV7c--<_hlb3px@`miNqxR6`gqsyBc=R$uBTL+I%13vX zGEnjnkXBpMg~~F|v6#mv40*bX#x^Aj>vdv^4Z{f=%f4cb!h9kfLOdEpT0_TutS-&I zhwI3QJ4_S<-Ky*c`-WjWD!8A71uBRH{s&eYtDh?8W6EdmZ_a`ix*LLhd=4TcA6hHQ zkC+Ey+=Y+c%Unx0v+-&)IxCM!qpRorz8FK?M4^Lh}8(&ZSw zeh|s(@N2Lqr(3`ePVcT#P}N~>;xn3O-H%S+|6si}kj&{V!ajyxMbJopKq*V=RF+TY zz8cGmz}$cKv4!S#n607w!QBs|`^-yoB%D5kp)|@MZZCRO9B*g$P{6A_Udh)3VbhGu zo277EG{-Sv8s^@qMEG#@Qa3l3OqWGBY?I!S^Bq62nzNlrTy;oWP`QS-fLUbBie3fH z_n;%kdtut`94fje^vFC{GoeEICYmYdQ*=6-n> z-z9x*SkX^I^6pYls~gWF?;UJb+77dy&XYI5eun(d0S{q>aA z_M1a=m`vmYjk3qXbVb%}B%X0s<-yP!`}_mC^~0P>xR5_v)0UxacS=r!QI6hhWWxd9 z(IsEGCV&00F|Y5oM1L~P#>dM(9cNob!yKRj{2S6zyHcjMB0sdo9z$)ff->W457i!;Sq7=ngmG8HA*z(>8r0h)5~(Gtai&*t5OBz9 zZ{e+Wj0h1-Iy+oQuLxBGEy?`eHCz7pW%-l`c1g)HP#1_0J2O#d&r+V%$YN)`HuZEV z4g)&KsrF052HnbqPz;{|cGK2K;pIpC%G2^}Z7bXU=zS;@N+X>JQ2_h(L5u<)_E7bx zbGoKXhxXL04u|B@y_oW*3D@9^Hmn&B-m~Md?bR@Bql?bRj?|`LV#u=(k_ExO(WK8% zNf6lasg`o+gUTL_h-&iOK5M=0{X46}#rL`ck>L;X1Gp1YFa)Z5yd`-r5+-Y6qaT?6 zq!r4D&kz zc;(w)q?)oagw}_==DK>(ao!w}BoRCPb|j&4@{hzDN_((Z_>VvO5K3|otAq4wQ*y9B zXE+5f^7-ruc{rkS0ZebD)Ss1T5XKWy9}NDUlP~)r`;g!$G`;#f|T<9iCWNeDL1#w9fRs^&`x+%y~cW<`V%7nkF z!N}~RVU@kJnrS4ysvu6mu}NxMq1gFVfxhjy0aFy?CUB8{WS#KAPglE84NK2(frB&nx47L&;ev4wA&_&e-?zYmUHu!q;gnbYU+&tR@vCTb$~$IhtFm z0H-(6l}8^6kHXp@9JLEIZ)v5mTd;q;xWO?=&h9Y$|t; z^artnX|C5JnQh12rv&+anT%Ocv=AGN0vy-Rg;fZ=FQiaI>c;aUpI#g^*8BVOsK(ER z*F2jP$^fYLPp8$EnQvP;GuCJv8WpQ!CC0X2Mr7)mo-|YD-oQBYZkDwP#5e<>P@ z)NJuv)38BPEj5>>LKJ@S7{T_cYhOZ9{L1$^V4HGdn+{(i1-x`tH4Hl+p2g||H+*29 zX4KX_2qJsb4>I^Chuc$0qk(jj6Qy9ti4%hD@`Eo8X<GWjSUam){AAb*! zX_QH$vDIO^Y|D1tnS02U5K1d0#!i+)fmHAZdwQS|m4EqEGFdD?_}q1&3wx;$o$(Ar zlPtk9<W~%wo_BMFTDPrHBT$XXcu z+bl9tPQol*REYf9*M9NC!PdvHp_|7@3GcB>6)@Wn{QC9(D)gQ1^A_(ly|%FCKFFf& znWB!JwsDugf4Pvl4^&CJh#wRzWkVP{sm_+i69s6giC_Il*P!4w(#`km0A*TuVyoKq zd#G}A!ilu?r)8@7d}=-pfGClC{LPZjjsywxT@>t_8;b6z=g;T8JbmB_n8 zo~wYY@Cm;DEIogb3g>D+|GI`_iPdpIZts_;E7PeEed2^l%>Jm1_o<*7IlH_(t{=++ z#9S%J<6OnS5UC6HI(l9n`SJ|An+?GGo@UmfPH zI^6#h^s0~el}e9~%p3VZ#%N;LnCbz&4HI}ZzDM0I2DA)TH=G!WvUls9i&yVw2%hI% zdH|MkpBHIH>{-8h(ZYP(oa#g3)^; zkhBRtau(Phcrqku(jA+{7tWX9`C4dI)_`lN<*PHtXvOZ3}%y z2G1n=Km~jZo(QTDi#Uc4GNwEJ_e`e_%4`$xlP{$oFZStzqv2!|VGUCUidBsg?*gsN zDAa$`Z9AOh(_GL1r9SfiW6$fWipQx+s24kVu5pHo^s@0NOEygce|`?--+#O+4Fa(< zPb1GAGNfID&?Ox}wAt+Ak^tJW~g<3cq)nLjZ`RyB(!ji}2}ffc)i~y1u?1U|Rq9k%7c4CvaHi z_>JueCQfG6qR#Jx_3t?qGrhsTyHq(gWg^A-!0D1Rsv2aSBcV%_<@yX)tV4buD z-j&RJe1q4v?MjBmnNcg$RGWtk#O;0SO1H$t^GaY}wNOjoRDn1(Ew zMZnuo^tngR>9TvdE0nS(kD0X}#BpqmkEfAdG3~fbtO;PLy_g97NVPLCv-c2~k0%f+PXVUmPk_3yJ|m~!KbJQz)bC*dlfh{|SdotKsJ z`*@U%;Dr`^UoTlQw;dc@aQ9%4g8k3ElRzn{o>V6S)diZ_W;6lVS^7wt5Bb4DW%ksE z)1%AQh~eO+Y+IMXsb7B)T+uKnX|2lakH1Ch2BLB{bVA!o38oAJzvu6v@&miYBENBY z1_Ubyt4f798XhVBaJ#y=7EAQ~aQNLa7jBVR^ei}$$~DXTh`AKLCt&9=<6o_hE&wiR|I+YG>bl`_O6ouMmMJ6OX8=N=6}d#qg}i4hC80zg3Wq`6mD2 z%?$|pdzqu2h1>hoOF+egep3pURRAk37fZOE^M=xM7s0VQ3mTtlfLwAv5JQdmtWLzAGhY)9Nm-By3r54F-_x zF`P2J0Q>yV^qJv%Wb(x>25zprtTG+R8D#nA(vPm*-aoJ2Ro$e6zM5|GpvmT58nq8e z3DGJ?PHc++tc^%{{1IO(Kj^Z&13g2TD!`?w;HDG}GQi1wliNA1o*c~Dqc&O^7c@iC z8SKa{pN`H6e(L7WO4|JNzI>-?yh@JK=TxN35V@kD%!S~_)96H1PrDZZFkCr%&kB|E z;n|UtY<9}TADV*~{a>|1eM%A`478{|QOc)z`wod5%Wr+66Le}H(MYP|ii2bSl9PD~ zsALnWB5sWVXwDta;T7C||6lmm!w2R`qMsh$p307&v(`u0a$1YCi6=r9MijP7-ykM+ z@tx~cB-quVPsd}z?XrU5)qMR-cevf@OX;jod0alRiD;?sQPtX6GcKf=NmAUMy5Tm) zm(`?hN^l&|uFD4=gyC+`N8gpXTGYWf&{&ni4O_d~U(Fr}>M=!yxLLPh zm+Q}a{^t$UQ#M>W8-=f3x_q-Sw1fW6ltQSREcyX;WSXU^MZ%(VXS&kQ1Tm{uRqdq+ zz1i|BhNd>Q<2|14)QGLTkgiL`CjYWT6)%G)j!a;D62c$-f}XY zV@dy?7T2P{sp}TR7CthSdNvn1i7FI*H$FMiXFV|vcXDMFICkhz^*z3R<6P5$B_GIh zg|#&qo3RC7?xW03aPww2*H`o5|Ee^YMh6 z3gL&PJeduno|k3+Vurmv;h9%wP69kIVZzfZw>?Sy`b zink*so48%sarMkPPWzF5J3bHGLB0RpA0E@G4U5E%7q)nfoNFQ*Ya8eQVT%J#;)765 z0)Rb}j}X*$L(Qd5)YzLf=+g2j7AtR648wLO3thjwktu~9@`to@xkNKr-WUERoHmg~ zZf>Dh@04{)RLZkMU;ewDYfHV_?crT5&>CGKd%F{qb#kn?k-pgE(kQJSS=<_rT7>C7 zwnrP8=o@!Y5Ds+L^rdC;0St3@80NkMbSP|3+f7Ma4*|zjpGQgvc)fAS3fm0rw{!u4 zJ;IM_%6terb&VS6j{jLI*oYZCmK{i{=JXmwL(u*>;w02b@-3aN9EHWcBRt`S$1Hw>#0Sa(*-h{p_&dKwo83 zr_;0R<3!5T82>C>u^Xi`vR%nK*Fb`a z`m}o+O~=#11$FI=22=ElDbSpodX0M<4}WcREV)|U7)vQSJ*=n(7%_lc-T$l=$mW14 z)Gyk2ZUdLGEL{{V*H~cyp~w&2+I%4eO;UFnOfvhB!t*yjKj7LgIEo3SUI((?L2@`q zzudXAbNJNag-6i&m*oZcfVf@%6Ysg*rgZxO3%SFz^DfkK4T?Qkv+f+f%`-w$)p6bO z110nv`P{{It!nJw{n}Bp%fTPduF~gO+h|8` z%&jS0vH5|f(eAPTbVEmx_lNYgz9(n+CJeiGyz4GR(`~~eYv=7RGrurf90rNQwf^(k zoon)jo4Q71O8dHvRY`Wfo(;O#ogWFlb{BVD?zw#o=tgt%0f)aSj|6DVeb*S8dKpc) zoSg|!9Kk;VyuZ}uqOxlX_TFqf#$89Tdun?7w{v=*x3t4>;ep<_Dam_2CP8S0`?KQ3 z7hd!y%Iy(zwCbR)tqph|(g@H9tLES0wy>)0D|Fl~u)bQ>BF|15<>N#>#BDQm0St9q zba;f>yO7>hfnP1Je!f~hJx^B;CK^|f#FvEh>AMV-w3CZ{6#t=ZFsE~FY&kfEEgOf1 zukPozS=yVF&RTmIRP6&SS?EN`tw5`htgzJ>*`ct%e^Mc}-wO?q4*~WK0uHYyzrfK@ z=U7HCNLvCNB9=ZkD1)2%7X`b)E`8YtX^Awp4o)~16>Ohx zr;gCutL`BW>DP8sT>h?>EKboNIzh)@qg##%{na_5fFKIhrIGeC1qMm`E-ec++-M|4 zC++MTPXo=&HDkU?o^M-*i=T(nI6@xFDYMJxKFp_TZwpt2@#W^(qxm`&`fZI=cT&o{ zC}1yD?!)GC#45bFT_t4GM)`JofOM?M6L1%)w7=pK_y*hIMdk^3r%cD3%#*JUPs{E2 z0Q5dZ4N(alSvCcdZk-TvGtjWB(3VD|d~v8Rx6Tx>YD&K`G3~_s+7lhUkw9P1p6U^j zH6@}aSd#D{D7Rn%_-AF~&FG??5}(1v+5hwTIu_tD#lw9JrFDMssK%5a6_2NTCFxU< zH7>e=^k4km)Hc)rXlr6+Nu?8Z=9omPCIxQ{u7BUEmI3aB}uXL*`(UoF>f)HHd&U}Z5|vw zhwT+-d2>dC+Jm$>E*{gQf8xLRqr_nbU8Oo0?zk420@$(1Nz-7 zfw$Xoe3EZbt!r4n=`8;KAQP7`g?KO9ZddL9`lsN@%`p4sy8zFYX&qmzWq%?VH@A4* z2w9GP82(D~@Yi$htG#Y&o-3hBA}fa}=}C(}t(vkYU2!rjr+q<$N4HWz7-yx(s6&vOptR z{t_dc8bE;-w;2H$bv|bUg=_wBBdz5rpC!*^rOQYKgd?CAbS3bp?ffsU{5yLt-CRmJAVwAc zzEF6fY&Veg!2C*u@r7mqg7#!oAL51AkO5d(3Epp0`sfDwUhAxNp`kjPmF+5RZr{>= z&>xbH&!gIUM+~ErpE248kEn#oHTp9N{VF{U-_)En)-Yis~ugpvanCK45UYUz%_wBPqlYPnBa1C~Xf2M~JAlpW6Z`2Ife-u1p~%)3_T6pD$tCIq={ z^ux_sKje7s9wQfl+F}dT7Gq`!-^zbTo=cEQerO|+fQsdo^>3G&4vb^likZ}w9WP{>?zEAhi#mD2k{=@PS;y&Vul7Z zxBd;g1DF%OKD5bw$hD{$e6DLGM883x3TT$!*=77v#I756uP*{Sd}W{$bTar+eWiz& zL%q&T^9JkMiRsV4HKz~>kNOB3hyQrUofMS9ld>>u5QDAP8h8Gw4&~q8&xE;svkV3fi3sL2OiJZs?Co*c;uEAIZcotv!CC( zaUEs4VVmtKeB^^}8>>s$MmGf`|50V~3w$98|I4?W2q|DE3)KbtEo%)h-SV{>VB&^X zXLk5&6d)^79VOY{r8H7#ATtGrk|5;^d?$cNl{Huj8nYY$ z6wc}qfZhC0UZVSld|2jv7uj88RF3&GQoHIdxX9j`TU$9x0OO_SRiWeHM?UX6Y3d;f zt=G<11}T4uJeS+y9VIt<7*2^Qr;(Byb=Y!ZZW@>sv@#oP5*ofSuvLgh1u+5~YWeRzYYue5Y{)!T_spSJv?9X}_yb1~(DPqFnJa%2X_`Ykz7L%nAqvRmI+w z*3$uEpgGZZcoz7NJsoQAj^L@gWpDVGh^Qmc&%GXNj!ZEaX3~O66PyjIM$wX!g{%Kf zW3FZ6{;B~Zf1WvKOJp7JEUax+_Qqx{B^B=6zNXMMXCobo$Am_QP8-pN6_u<~33wd) zy-$Pe)lAKQ85v0x@#|-5<$Jz5+&87}nYk$a`wCZRUwg2jl&<+0ek<#I2Q!wg4^@KV zBYXHV(Xvs}`z`qcnnnqT028Op#yu%SVE;;0>&RE!kewXvNT5IKUFH133G&!mJRaj~ zeGO}x%gT%Rb+)AV!L*9peg1a(`9Z)r9nZ0=67*T8kYO|L7jY7=0rTK1d~#!!*Q|=y zM5J`6owiIqVMz0|ZB8I&fG0;VhhydkMSn7-*tA?Uxia8sTIJDsM11$Gan?cLG_`(|515TmCOIY zW6MQ;Az4F8MJ#1G`AIcAIsM|Fbd%jq4L1?AD$(cBLgfZ0gU?=t8pk3;3`2+!hJzGUvd z+i<{KpWv2)$z432_qNzV0koniHf|v->c|jIt-4uF;bwY;OG*JSubMA%1ch zC!D^jah71D5P7CT-gv*3D^Z+A+9}_(!A*%Qg(7A3{_-Jg$IwlwpQ-CXg%tR;v~teu zwFuZpM94R`nHJKt=nK~m+O`I-E$ed9h%a#y2a~t82YeCywyKVfE9}}9D1J3Y0RcN2 z4`k7bzWWwC4REc26&^BLC&odptn{uIPEtJz!9B-gDC^>XvIa=rfjppsmwAy<=0()`Vak|1Vl^8&K*PStn)|DEcZ(_3xBXO*e$C~eau zg)ph=Sh-}GRKNg|zeuH@xtJFyP} zoPtY+yUu&vJsqG^XXehX#{Xm;>T>Z@Xh}xZCq~Pp(*d3Ef4bm`6Z*Db^oKOM58gZm zJ3Tpe5dpcEszE}+n`i@M@MBxIsP`&l?9e|tW)#McxTxAu9=-}sE_Q>{{nT*3Opjc^ z&YTW!1usX-gsv$aK`O%DQG}67^G$wO2xJN-NW7 zMxvw-`g|Ed`@Kx_04O}%Z^kfB8(w|4S56_Kl90RoP$06rikr(YW}-y5C~38ZQ@A}N z@^9{|0F zFJ6q+EgqV0iaso1S<@Ad=0$%1u1Ik&e=C%Tw58*6O;{g#Ynf+K^ma5Ty1C%$mqvfq z1^atVhE=MY&jrCzm6`k}*zqY(|6|FihD@b|dBvLo;;>9qWI#qijt$9sBGDWhhJ1}ndxKbveRb}$RYYW>ND@`P#%WP`hXdY&fBmIdR;e@s!1!<3{q9O|XezkbsBL8>l`{2edT&KJno9O<%99cbnH2gE z!%xjk_xPW_CI=~scIwhdsp3993g+~I&5+dSCPG%Vb(CT_)Ub9}R&GkOua_BB+B6la z0Xvj+S#u+{^ZeeFhyDy9Vr$o`yNS@qQzu*%ml#!@fg#7I#iw!~U9DZ14S;STt>uHa zB#F{4?{Rby!uI6)X&7AtJk}69O}ga^_hiD=L-%RKp?AYIBL0%M$nD6jrm*tS2^$>J z2#f0+SFa-872gF0t^^v1UnEE5fh#NMe9dOB?jH=x1lQ8Oo0syY>@VeA7mhNh%Z~Yd zSqM#RvPXUJ`=$5h>e)-q;;jv{uoWE*DEo*s>s`Q2rF(2h$_rolroVpEkNVDcUGtbh z?Dn?O5A$|oG4$N!*`;{7?%+E-qxyb=XG!%_L)m5g0lF5jPq~zB$TqrOJGC$_*OG0o z)rc)iEtJPUIj(DwsAx&)z)EUVoB?KqT`23V`nO>LlLs2eF5@T4Boa zQZJpxo3YLriK$Xv37~$Ea`v+X>KHX+j~+=LO1L0j8Y|K|CZmv6dZ#mQi(U|Uc(B@A z5Oi=!9g!kGLc!YqRsQ*+_Y^)*Z6|-k@A~(c#gL`Vuzp+E$mq6|rjr2R=1BFm3w{UAa^JP_yX}26dY{|35 zrzp0EQch_S-yhT5=hKOFRjdd9S9d%setI7_5{_~2wexAm}fSUK;kj1r|{{2}C#>T~ru(w9Y z!|4?mPWsFPK6O<9H%);14-JB#LrFkD6MLdS-bj$wY3AIL3;QEe_urxlQm_Q}s#7Km z1<=xZbD9W(AHIo;fzMEUb#w4<`WJMe!e+J61WY~ePVm|~edm2z9NeE$eh_r7dtR@7 zXl_W|6aD~Rm(8ih7OelZnyL|`#- zOcz$fypWR9ciE9Q(v&WuEiLDiehn_y{+_{n%B=@gab}&GQ6>)h{$Sw4+@+-{ttWsUzcwO_zUTDhA z*ix*MEOw~klyBf>Q-Iy_Ny4Tn=PIH{fCiQ>F%|qtX@i1t*EHAiu47X*R0^fPE_x}j zWmvRtti`ci=8VAe^_=NkZ)WHq&U@M$O&#letuoQQL6dKRG2mK^{bJ& zLI2y{kk+%EP-w2x)KH`L=#|=PB(+ac2VD`=!{N~+B!(Q$tKDi`m zEo@*D)6Z_-Qz+4`np&U(<-C<=lLtyGk0S2Wy)FT}AFOT3>f4@LC+baM6RK^Kx z5>9u%NRxtiIOqi7dB_w#Qq}kC^FOh6w_>2?;>RyqQIWqKv|b8T8?VIhWEYRsMEyGH zxCxwLx(y@vuH@|WqdcF;Qsx1{vq*w`dxJ_lBfg|Q!ns~13)4a)Bce~8Jg)-~Zvw$w zhP^Pht`7_n0gX0+A!d^FL~iQV!Z zSPyI%K`Z@nWWF%FZ{fhy8Z958w;JVSKa~0@&8KY-e%(c< z6V=>2s6$7U2ipn$@M3Kk7=3K~Y&r@0)?G?Vz=x}cHYA+9ZKF>MbT^@#YD z+rg4{pTip&l;$~2S0#L}bDV7zffjK11PKZBIPHnO@>fo_I6+&|*{I=)ug}|EknR?D z{f;SS_pp4P{aLmdFK{1oL>DW9_i4Z`&|nAIlhx6gg7}e!7OLR+z^ifsD_hxY=XWey z<~dXK9WUVzHp1yNc;O!t4Rj)}EDZmI?Y3-J(q$&y3qaJbARv>MccW!orv*sAhmDj@ zyT25F`i=rg^hw_Qr>m!eHCb{u6{H;Ft|V*m9hx8G@?*abSCDSbKSbok!FrJGHpmBK zeA*27lT;~mHX+qy?=1@AWmUPKATt&w{f@+-5)~GSi9s&IzvMHNuzp{7VV(JSyrCM( z(sWiK6EU4#DzIyi6){`p5z(${dnxi**cTv7C^~g#+>3hNAH*LX%WZCU*vRkP-3Pe0 zH~POv2O|ezzv!g^i}Qlk42&GG+H_q*ywJmT;;;8M0U6eW7P6KNA^A^K384oBq|neL ze%J%KMtUxJPAh)mkL9ON?7!t$hCb7Vd%6pEXiw z_?EIi;C=&}hnlJ>7Q5czW}Z;$-s4M?M372>-Fu>bfQ6)TDizmxC#b&UwjC=$h{0qWWkj{tjqL0EAYN zRWNCLnvY9@0)|87bqS=UXo@7UfI$y2Sk1V?3A6 zl0Yvb6TCgH2h6#qvURa|F%4#|{kYITAh}4E+!Q)UV1H>y{bePF;=de*&K*o{6;zHm z{zDG=4_kbf@y>|D%&fJ4IT$fNPcVZlJRkpUeB>g&jHkww=`y9S4g(_l@t&pVh!m4% z5(6xN@TEy(TOQygNzZ(Rla{heyFfE2%nLu}SUzsE{g|m6;MMT{&jaz3iimfZUuU>x zR3Ai4Kl1MxhVKd^)K=K4s4dy>ll>_TMdIDd6xhubxen}Ro?PYy=^L^e7Mm-f zBaZKr#;;=~mDW4!?qqel9#6jn_5%YM23<+3YFIYv#}*bM&m;tJB@tluBx^5DQFnFQ^4P zc};$nX8o~Yvnqn&^q>P{`j9ltQnDbx>nM{YP{a`0hfrEQq9IBYQmwod9qOP%dJy9C zVuyZJ{S}t?Pd8LL4WkW+h7f|)J1E9XYJd#}`z!}nh0({Xq_%mn^bI*iyZ$ufe?88U za0UC}wlnxNaPcW3hP7uE@Q`VLt9u;;hbgUOH1+_i3F!;kq6Lr-xe%0BS0p-s?}B}I zgfbV`s!J=$UYlE+B*9+mhoXV>3^72yuOtf&QWGP9nB51KQuMQ`?QKe14uF=QDQ!yf zc44;{PwGzYOa(`8WB8{au9uhiswrskFG;XP|J?g_&R1JPrGexEqmsjsjFVHd))wk0 zC}V?1jrq7k-mX~oL4$pn+RTcG-QcAQ-a+kbqRd)%IYVP>*=L7oqo$>BnoOv?ssYuW zfd~|I*s^LXM5m1eJKszT4_kYx*W5EUv~Wxa6a`%vPK@>Xsf+7ds1;S8(bouRpw5k@ zK;rm=lJ+#s2Iw!e*FxjgG*xpHjoadwzqU=UnnI6_o!yFqrhMRT;NxNIq1tNb&xJeI zt%cofqV-SLY(4+uo8KF;Z8KDS+aHJV{6~b_AJzm| z(SJdy!9!MS|GgaE&bom|9cdC}z9|@cxjlNfGt36zV=VD3=}bSY)~H^u#a%U(%WV?7Dg9kp`ZwA= zc;5h5y@J*Ww!HS~Q`Ypau+mIwCL0UF63>$#h zxJWRfkv@lShW@?J2iPqie80^}!l@@x|ALYjktDHGk(aMQl!WRAbnmJ9O->iVRl}vv zp_}AVFmBJ3zu@pqp1XV2xpp};hKgUs1USt~m)k1{$5u~Xn{(2S6^`1s{J`-l9FS(R z&CLxZ*6dsjGDs`lUpC1X>ZFTefj_Xd?*}>35k@s{@}JX|PyV5)P9l8<3u7G#Qj^m@V?x*}Va1Whqm9qKB*a^&(A@g=Qw9&}yZUee@D(rkN zz@W%=SG=q&b<$^$eY-;Fcw7XGf(HYxLPmT*{avAPtVo3v#Jqeyk`Z7rCMc}4(7^hu zxZFnLV`Hu0%n__e_DFEA(u#qt^JGWOlS!jMr@9tqhccUlPz&tWK1;TymK5_Lu5!g4 zqn-`UWAy^^&~^PD-*WYh_llpZd>8WCDR-Y9LG>0ADB1!aGss%kwHUkN8yX8Y9nT_~ ztCII?f>?Ma{4?<}3h~0?ZX0x~ryBM9BSC5Ny4Ywx^w0XgyI!z@41Z zYzb?yF_@uvB6+wRTBY%mphrM_Bo@jk`c%AL|D7M;nXDFnf!=y57JRB|DbH_@_pzkB^@$9E+0Hv-31wu57 z32Pn-_;5N92L$PZeRRsaPU+PEGJ_uI%giAFx*{01jO@ggGwr#~d!xE&B~{lyvN0U_y-S(a zcH_}V*gq5eWE}%4BZciLOO4$VHo)~efVh2#8LX6E8{l|rtV0o+l>lRx1PKqFAQ$k~ z$+02ecK0CwJZfZDjOV83W-IH)Z*ilNyqwZ@L;*vRFRCscaOIpT8?hLhNo1=>t>`af ztt~gi<4rbyFwJ?g*GC5~2h_++7VWrR``Ppy>wy{;t=rb)hN`{3`BrE;#pSkRndTTK z-yYg2pVcg2mqjdhEbcVy7{7GVY!E$;IqW?)%&A2INpNpY*YgFu3g>!%l1iisALIOV z0)A!H+BNIMPRS=bX=3*E(Z?&t+%&VH=-raWKB#N^H2b#haf(I)D7`{?OO8KBz088G z3ED7bP}OJ*<+LeFty=o3ZUVDg*~bXWKC_$spcQKFOnGlU{f9+B&L1Bv9lv6E6ZqS! zcme*C;rBn9*}k2Xs|Q+}J@QVw|63FH=1sj~^~Ui0NhD>ewOiEhl+c~J=OT#`OLhGH z_c<7){;&csQS8VU{NL&pisjyppM1;pSkmlrDbxLPzVMx$dU|zWO=FFjkavMm6CWK_ewg zf~QUKp1uEJynHL3iRFr|j8+WeUgU?@kjKd#D;om5)GAdtVh8zrx(I(*9*v2C3iHaMDT-j?{5c zk>?T1bG~^A!|)od>xr5=;Kqv_x86aVsyct<-RhdC$IwYbby$<(OUC7pqs`w`8NqDQ(ay+L1v2PdQ*4!ycoid^QbZ zu3FIEJPZ4%ty45{<`eUj!HTr&r&Q@=fxqqN(Rs%$!rMu7Rj2UmGgEbrot>#GcKE z+)b{kDPIc+NM+R|5F{15ly=gS58{i|Xy#hXo`Rh7bX1 zDJ29^xr_kBFy-u-2cV`lF? z*WTBs8M3UhBGu;+sl?NsC6b^6=Y-+rU z73XZ6+c(2(!l(00Xa-5(IH8EIDX*OIWSwjay~9Gx2jsp#3-*-Sph0tcssU4{v8uA5 zoHBQxu+q;sw;vimR<8&Wo=yDdYLmsG=O-F3G!Ut9@X71#$2+~rF@ptwwVQv<&IXVX zG5k8^C_A1LtYDx$XAGN?oez;)*ZxWJq>GTyUwU-H7`=A;Nmy1n%oIS%vO6%ucxBL7 zu9-d5yK+=jXuOPjnubkcQ?H_--0FcbQvF;h9-3mX5v(QAnPL*Ui~oEuZ~MtxWdIiF zSCVBDuNW}Q`K`M3QnvX>F-ZLSqt}Sk{Ku#7l%#;|=Fvk(^DP<8{Xpfa^>}t1nozP+ zt*vkT!y1C5jx2=2*%)%%c@Nki+TCx45hD{qUWrVM(Bj34BA0v!olD?21zJNV`H8nW zfcx9~`23w_&{z2~Iy_AY5D=1eCKbl<63;)Fn5^&fFo*2^?93B`UiH{eie`X_<{Q5XL zV>Gc~qpq}b+$*|=ifBby_wNqJNF74}<9etHz^{PJu&~^NZzd84FABi2>B;j%ktGjI zrNgLDT3d~l(qYt0j^Z`ZqK_R~dT`fv#U7*`n!}_ARaRK8#+Q;X0FeC=7t8Y65T$!| z|CK-QoRX4)hD{W z0lOPc@W|V%8KrwQCg}|jgyxJ<@)^8AJ6b)bcBi==^^nyQ4P||zInyR&m~)|W&{JJ# z?qwluxl>(Q9Vv42a@q)1qsIH_!04IQN%qrfh2tn|-48m6$AHa0vM~CbT?H?=nJmL!kDAeyb*Mo&}Xzzrt@gC3(`)o66}# z*9rzL9<5UTYb_}SQ|0Ts0ILU@1k;pl`i0REHVT@>LPQf4J6ly^Cb5k zFu4|nrlM=+!N3v+fwwM_y0TQE)BviiAVyH*A?Ro-?<^h~60&R>edORRPT=9Gh%F{W z+g~$8zU-9=jtniSKYt{CzSaEGOtZfv8{G2VI?3fDBJ&`s8{m#xkk4+y!z=WDLJ?Y$ zQ6Zl1-jgxZ#%iYFbL?#6fIZbVAw_l0wI;=C`HDmrI{kpf0iKUXgsw|UDVg$yT3WD! zp6SmaL|bEI{gA3pVT6r?;H2Jo<=od6H&)or+sHX$jN8#v$k)kI(aEVD{@@+IN!k6$ zsh+j+L=Lk$hdJzm;cFsY<3}D|=zH@er*)#Pmbw`iv{xA!zSrZA1U}aJ zEfYB>TUDh<3|?h-P?VQsij+u6TNKGjbVcO)U~&)IafK?l+RBxie0w(S?R<@pLq34# z7N0su76sIGv?+*`Aqz5#dmLj$s|`G~$m;xbLar`q~0zw#Kei z{SA<2KC+%o%?dk#`pv(SQ;3JF@hN*c6^Dag@8OSLe-S3&c<ZmSVr5<#hJVLuc5~ z_Ei^>ndF*oon9$_cxaw=`{M@y#%6RV9m5xR?YasiundL#_+N@bo(;-TYYskq%t-ZA z^qYV0wwU&PE0sUZ3P0i9PICJ?Y{I#g=&%km^!D^ zxjqOJ$T!|Hbc85i_PurxQOc~XM&@ty7som05!coiKpMF zjZj-|XIM;f&n->(Ez0W6SxTGc#)EHG-K^em>A6yE=m-Ux{D$xqqgdSx%fUW);LN6YxPs9$Lt45A_ zy)>ZeaY%_q;+;L!gyH?|bb!tl$2n=CKY-C?Gka~(n(&HXjsK^9igc_TTo6ctRX|ds zO-}P^GtxbGNl}{eFe`-;CV)kZw77o;9vUK)UC_y}wXz+b{u9CDu{WmgM@A z3?|pE=n~&JLA=oPUor32k-qcvoY_(6&wF|(F*xyS&UAyL;LbgtP5Nl*eQ`FrUn>j} zCpy$i>6$gw29KjaM1Df?Z-_L zz4jQBOZzt=?YQLZpOop`ut3zLngdTf=d~Tp#VbZCm|SsC61{+Q!ZX@)>bJAt;@vkf zZU7MX@jHY!$ri|q;ub54RcpVzpfWf{5Ca?f6Wg)1NTA@sWm)AuZkDEV368(xDQz^}K&1Gv3? z)S;0XQX$ukn(@M0Vc7n8U&z+7u{v6H7vXi#YGR(JIU=J4b{Z5KKg$Y~x73(igH^P` zJVlTkUx_b#HsokY>Xw^du>Zf_$SHph+*H5VStLTdR8WS(=YYX!Y;nr5N@c| zaDdOxC*C9OP};?p5CHv+Mk7_8!Ph=Tll7bO*ACn9$JVsDw>HQMWxPrFV3VMjUOqmc z+cEV64*qhrqsB&S5e3gTE6SiQ$A>c(?wMgf8nYn40iPPIQod@5VXUtZr3@j<*do+ z0K$2J&!oivNt=RILW5W%MqH|>FPE?^I8JH@Lp`KzR$U8CP!mUE^@pZ*OU)ct@Fu>q z)ff40n*|Q*1+aJVqg$2Z8XK*jV9q=VsZh49JR(C{t}kEc6tM_C(8?sB(cF4B-qVSD zCF~+PeK4dOTQS0*=PNQ(=It-0q$Q)EE-l{8TK6iVR0e@)E!WV;4z#OQovosvm=o;C z7%t=bT{|x0VS6L7B`m040J#uafOk`{+hZE_V#8CgW&R;8S8@AC2nRk!9P?vx(PDoS zsSuoC%E%FpKG#85LyWP z$C+y8ty6dxGwLef;I3>UO%AidTf$%XFUOaoGyQlw{!JGB{sBi(j29L0?>K!zlj(1C zRi9FbUq6jm=1s6_s*h#^L>xdw3Bu-v-*y+_W{Zqxg5T|079|lOJC$rsvXR<$V}g0z zPN_Y(HqDy(p{HFkGwRZid_`xx-J;{^p`DV2;MZ@L6NCDVEn78ayf0@Ue%X@(j zk*|U|nkvBKa(QR93Y2A}tgFJWRe1q^fzf{a5CpU4q|gx62k`L8M&Auooa-A`_VD*@1ERVyurfY=mviv1V7aTCq3px#j{?TwaT$!alNwvBd zVlikEIp_tZYdmNOjnDXk3u56QLz>1l4Ys|R?tO=O(IL;-lw`QQZFn#<&@$TuK{MTwKUpPg?Isv2_MT%VH>mIaC4V#xrxD~lSqPZ#RR zPg~-+^9>-l`BapcOx^4HoK}0QrA2HTt#rv(f~m`pP6^(=2%)>elFN5coU5;aZ$J65 zs=NR;nCW?Ez@x6Mcdx3oK>KtDbnWYd=8XcKnE2fVV78#*&K;nJqKk7OEhv147Dkb2 z{z zi_3z`jF;Q}454Xvj}g`}Q!mxAu|UtBoL#>20TSTQU+=w+j6srT0oYorQdpi3C2h*5 z^!%gVl0T7fmdh*>joA;Ff3S(MB)Ug$sNZ?l_|7QTn<_tQmw#&?NqZK!a(%Jgp?OVs z?W8eS(Z2hD@&fK;@uJRTey6{ZfpXaW&!B@K_UzYUt+X1w{8DT4jEK|1#a!^Tu)`g{ z?Y@IxQ10biYlUEn<~SSMn+YX|3!sYT%$a-Ua%xs*%VZYyMsvdV##3W(>6YT z@*ED-p6OCM{B%()g6>#;1HHAg&Pr?VK@V`OsXvECJMPm`tN>~{T{UfWWuCeBmsp$wfKU{%+g6CR$@>T|g4f*abLOYK z=byr3I)9;$=kQ0zfe}9H9Vx>n!i;~%&c{{B8^WiJXss% zyn);XulhsSGTB_0s3CMk>hR4Z9BsQ|jURi9m0WEL5JD94i371**;i&uM}6P=fU-Z+ z<|^==B6HZw^72?u#w9joXuFK58;?z2hQ~pnOlQO3Yr*{JOMXme&JI* zhABfLGNBD!5wrZL^74?c!xo-7w$sSu_qr&2ZE z?dYttebtTTC^MXyuqoY`s;(68F9qulnH0iEc_AA2>!(H%8X^&1K}rJ^8xw3zjelxx zerP_GnbBH5wHp~uXDzxrE}B(mXgebfoh`m|c=4iNahBL(BIj&kzxekB9uoIB#t8YX z{$*W%oof2E=2V6%i=Nn@tg9!0sfQ~&>#@RX*78-!kVV-Mo@TMNtt8A!#0u%cW;4BM zmm8e_rGd(jWft3)7WrQXDLLRa{{jy~pnm&7o*rnJ4b6Wk-pconDT^6&B`WHs%)770O2=I%_S8G9&Cgnu z?f>Pr@i}e&&Q`Wst{zijlZ_#zF8Ofq8z#2253p4nGfW{Ui+^OOPNRoji@Hs|h=srX#8Lf+lj@Xm z>GH!wMUtj&{QP$z*HYB=RNE_){zc-ybUaECk7`1p-O{E~J@Yi@`51bsxYiOsj@s#t zTi`UqmpJK~^saQQcjt9&4f32VZ!PRNxV8@4?(a0|-S~0E?yrUxHdE{j0i>bitH!P8 z7XVduQZZe)fpzEv3;y}%VRb3 zml?LqC+gYiWc$Z_Sfc8v5`H(5uadRCVE$M7444@t3Cdp>cLd^QVsr-MlNg1jZzck) z!CvS=-~elh?7}0vp zY2234F0yEEd#Rm%zh=YyHMY90qz5Q5mPj16>))LuwI$#dd!x=Z)}#I7tNWN!s>yc? zyQ0%sIwqeT$x9w^nY0t=`R$qTD63^ZZRo`N=`f%X}z(|5d{}v5rPkPV4mU=XPJT1Hh2t`KQ(lTo;&bd!tz7 zb)RzRGEQAbaJFu3{{F7^g^l~`)<+5$9*xgj+{ZRu5Ni6tXpNQDMHh*(Omj|-=fy!O z7#^+Y@p8qhyu{f>xjS`AEkHXhtu_NcqVVhhH0*=|uF@;A24^@nVoC@D5I}J!+Q?C<el=y$$Uc$u^PcMe0Kn;KnfzWo7@PmShJY^W`LMRc#Jna6) zT*twsi%7Z`#pi7G=VD<~G9pgMCT&`!`t7f(2~EAe2#^DoW(k^eH>p;A)u14og_TlQ zS9E3#)=gZD5C9D~55SH|C{1L?Z|IB)3Na$38Lt2NL!QRxa-|TPsAr?3Zc#To(SVM` zq-3{GIt*Yl+m}R9y!p_ovU&5D%Xac0dRR*yML5{mFLE)jmaXYi;Jjd8)v#AN5UxJP z)H*pE$E9gX?4lDS>i=c^&i?KSK{gv+&K>JX3Oe$=Gkmr(wzNS%ewZDvWO>9z@X~(s zyLos^P0-<U9Huni_oZp?ky{h! z%$_bJesZ5@YjBYzpAoPT0qDG1B6dS3LaOY*7 z6bes#?xt;8|A%*u(dKnN3CuRf`cIH9&9y|;j@TZ?qjRbji;53D!fP|!;Y4(e zY;!hmk+Eyj4G5w+kovsuCdi7kkFRWd=FquXCCparw*0xpenrw1IidCFxTDPHCJvmG zQ%M{d;$)pj)rdN13aY2$biaIJ4`A~X-kP4O@Tx}4%U+H45Ks#ywC6f&{7UkmQx?7Y zbQL#TWv)D;V#KUP^GUU+)Qyl?Y-0?9NmB&5zcXFap8g`_3~eJi9L}Ql_szwjRR=4)>C`NT@T=u~|oIeL6Px+R-)WlO?TMl7@FM`MnW3H!n zBVNmVUpLXnY<+B%QcXLo2IUvqa2(`+ifj+recn1rcoGZq*t#6^VT?*|PUybMRJxW2 zWZ{ri`)l*@oBU_e;LJ6D7nRTY*fve!=T+f@7y;OzS8pZQW7~zrmsArsYu1LtCt>HS zWtoV`335R#dwrUEoSJlA(8idSLrRP;TqVOt|AKH_lTNOzG%08`#+=flRVO8Pr0RK=2jbop3deY-oZi0pJMfzL^~D(BR*;) zUZJ%SqIm>@!LdEpwTaVK>B?mMPn|bSl*`&KF9q$UQ4dw^Ziq%dqz%Q?av#LFJ$4ve z6QEe(Pbk^gzSTj6xyK7ve_tEL;!q1Z&I3oU>6+Zpi+LAu&blZVkG<}7ui{*#!f?c= zhtlZ5dCa!v`}$v&LNC1-3Yu$rIO7_F^I_rCV3*(a!u?s0m+|2IEh=d-KIZj^!*9A; zvkDNBOsxv!*fm@<=Dn_wru!JyJD@MZS^=4-bG8n5^PAIVUyzw4P1ia06qRJE%P=U? zz5gfv);`s{FNaR7E;l{W+C^t5$auPRcW4AASkVozK~E{yl-f zwsAWb%Z!JNysD(Z5?k9blkk)m~hixo3G|x3WG#{=Jt7vHO>i*X@27-Glhwy<$>sbS0J?i=Q;84J7gU{w4Nb zvkpR|Jm?ZCWvjei54-WUzaO7CBR~-ORczd0+Is?hCND-BP3Z^44h?;i1%RfD%SgjV`v%A!_0U``uF?!;rr7@VWMa#ln_#F8LZjgko?VL6ve6nn@CC=RZI@psy?0VbVa40BIe(o$ibl8BdbM`q`TR6fXCDus^G@{h!^H$eeU+qQS`G2A`ZZjUE{xFz~+`m89Fhm(`Nh5K1PWe-#hVXoHh#S{llOy6tV$}(B$75AG!|LA z+<0fpj?K@5UD+TE1qI<^y6f^H z$$8Oi$M`xFk$o(8!O?P0M2@Iib|AL8=h$Y3h8Sq|!)XwwS4Mc~<;;)|Gui7U!PDhD zN$+WLNcR~^2d~bx%(o0%aK-{-q3o{OrIPARp3IH{QX$6HXi55e4 z^_EyoCAP$Np-1g!K=F`P8O#+Y=~8g?`?mbOro+|^DST(tp1ByC!$SxT5h)G%Q4ONK zHPHUf?NZgGb(l)dQRcPM1sZ@55(xAuuZ(`o|sow+1BUb3NcHBb9CzBV=Sdy*wYj&$2i`rYnMst6-VjhWk{%YJP#3 zQnhAH%ck5Eo~ODR5)*pjJ5tS^Ywz*M-MYtWnWV4y;Z9k5^b*399|Lm1Lz*jziKjDH%(pP5yI=00G}-s=0Kd9@wJi zceZ?z4kup&hhK%-hV8NSG`~k?nde-Du#Qb=-X)V!jLpk)Y!A3kI*H%9hib)POXMM% zG#Bf=1%1?}2s53th2@92Tq_J7NWv^>>8pc|`>$k0c0Y!Yd+4uvL=(<_g7Z3$^F9aU zjW6V)|J45)ypeLJig=v?HXM3nGfKF!=wEhTBm$`^71+s|Vgi>=QYADFP5fAjxfC4n z7$@FQFtQZpnM`?pdD7e`|JtD&@Pb}YB8hcHd@f0ho~;Np=k!qrIykO|vGhX&2!k|b zvfwn(ja(dWmk#<-cr`)ou~vZBKfc^2zkrpC2seYg4WF#3PiX;+Ys+uaHX@?uC? zSWH!VkfSkCyP`@pM#$GMQEb2x$JWDoJ)tt^L6(eBuJr&O^}PO8w)>GDpgHkQTIQLE z%U8K`cDv~m6^;z$omjr88I7G-p>yW`KXH^y9Z`v`D)hE?t>?e+S2llllJYV1kn>$# zt~@c>>-O9|ipk(xOXiYDuBOu)-VMN%ykQZ$3hO#vkx&9gmngf_S|HBKuW#6Np-)e8 zqcsM|GHj*+m2)TnQ7#`0K<9nLW^HYLOEh|1CYN21B=R&)Fdgq*(Ikb5>iWuXxOctj z<0HBc`O7AWMiq1~-Hv_rheO6M{U)OEg?e5rT~7!`13)u$@LzK}w!68M>*>>AO%j)sOk9Z_M>-t7=Ei9(qN6>cM=sk){ z10()JHx?BO1I3K~Q9o z^Pd@~XGZ2YX0Nex4xD&7{S6Uy_0WBOIb8UNqYYIUsyzKDwSMFSWrGw*L_Iy@iP+^Y z&^kr<@Xm23Kp0KMe(?Tpyu+gP)AB6`)(|zXk&}PL!jB>s zUnW=W9E@X{Hu*6S+ex1GQ;rV@4+OdG^7Zkfkwr$gg}>A$rh8)_kB_ zs78ipakV6!pxdxY#X3P7!STz4et-+d1`q3_$WG+!$TK|u^*E!HwVCn7N=JY%lirIE zN;i&`%`R0rHbPy<%^GclI-%ylktx6@4+#N#CzrCEuY{k*K7)-P1CD+i|EHjHOvKpv zBXD>Kao}kgIP#>#sAMgFScw|SS{)LiPdZzStOY?`tlzloYuADxf}0fPH>yR*4{j7D z%_EwqN8D^^sy3BVppHUXn(KnHR{lb++%vRT?rNXv?;)n7-o4Rf6S_7XQ|F*5dOj~U zul@qj-)-Xp!FV=V3XD8P+HoKjL|FF{!#ky|pc?}@+fhpZn zi83XC&=Xd~*VgTA4Ofw~20mpBsac|Mo!4ewKD|SWN3h+pD6m~xr6j5Yky*dcPuqXlXzf3cKd=Wy?EBKP?6c;PQgFx}_|_^NRWnv( zEz<`lO(ZBvwA~`hAm5a2RL?ho0CQsM{7Mq_>h*&G3|9DP$P?R>X6^V*l#AJ2A6yX@ z6M|#A*@z(E^G2fj zfxq?rZkFzEVZ!`QP9YCgwfMZwf>M>+wS(p6W}HGq+z6wWo;Zg1WGZTYQC47_31OpQ zuAezQ>b{y%%tSW1U8iC@d&_Ll$71sh3LuglItHGB1Ck)r;Nt+7lC^1(A8x&fOP!_o!36M_WJVEyO7_enX|f*~ro(b%5Rd()ZLq6MKt z^l)Rt<#{JXE>Ugnq2!-w34eH$Qg zauaz-!XJI0nxB&p=aWdG(1)`rmhsd9IPQCRFPqAMt&2H@3}yOD!r5%ZVEUo1``Y<- zgMxun=wxg|!k~6}m_$wO|^T_^FXa<=@l6#^Coz$uxtbD-VPwhOmU1)OeW z%}; zUeU{d^};(-yz^JEqCY;}7#95_FSLbma@ zrf^gj)e`w;8?g!>tIhj(VkUc4a&_H7yB>4aYUQ zMT)}fC*?)^e@Wx$^2xS`xR^T0!RPID(Pz4A<0jX-d8y$Y-n z#JvTHhLcN>(?**05Z->;g}Y@c814~@yt=?qQSx;XgbpD&e!i{!K|0Qel=;acn*pS^do+qzjxsnOY22Srl zyND>6dFffhLB&GIGZIh0oYjO&Ez>}#4k%3;HDAJ?hM$M4rM14hg@YGeYqW2sHK)ehwHD&0jIEZ~KpJKrY zryFco7oK%$Vefd|3J5a^)p9SpKc#1kG8{UNlar4ZikU4csr|9HhF%d6eStSi98f`l zup`)NVt@}{$d+395N={y$b|9_ojh0{wDUQoERYiM0*X&6ZyJpZv#t{uSDHE*V;S`? zJ~Pg=vM`mFfE+>Jmj~aR{NWsF&ZhzN%}*{6H{7xPQ}e#nCPuW9yfWbOEEYzaeTT)3 zpj<$ladO#=1JjTyDQI5jX&B_2Rrr=14(TgZABxJ3D2_XI)`3x6@MFmr^1C=-9Y~G! zOMpTppO|p;h$XPn|E!-`_-g>WjWiv{B~f4!ie2XiYmBu^D|(`vo~B>mtZ@MT`uD1W zc9@qu15jEnTw?x#%v&Gwz~3uyw~00&a{fo|VA%CWLgwZ`;+e>KPHZBxtG09Vpx`bJ zQA%aqLjs{at}C)aAgQS&gQZy}!8;OCY`A6+2kF}IS{-^rQAD-om~ z2NIp1ve6id2R0Md{pw||UV)C-p2t`C_YsR^OstV13=F^EHH_(xYWAk($^dD;;>R6| z={eUNx7_i4Y3#JlBOx>FHd1brCa5AlqN;zG{^pur{?j6c z|16lQL-cPKa?yYOpOpRIkK$07mbFix-tqyN?AZT2D$s%3Q2f`y#`S-l2>#xi2FR5C z`;GtkkLu@%Ve{XSTfhG6E)*0cp=Qrr=gk%q{_{U$V@E9izP0~6dK|m3lYC}dTt@Dl zS_V-$o_F(#3ss1lK_tH`3E!SSZG!+Agz3Av?B7)We;uEDAg^xgcU|wW4rbo~B9gHA zU(}AHm^==%1uTsrg4S!Foo{q2i+ldBOVP6j+fN~^fr{b17LV&v8&W)XS2>vnO8=q> z{=cKzK)5-_i3DbUurQT|s)Jy=dw!4+Yqgmb1Mn4Dq!pKOL%nioPb{h!jdMUnKB{n; zznOmk&qFQRe1(0GChao#7ha*=SAOZ&R)23$A?J87q>Vdb!GmCSeYq%U*=w~BV8jaf z`%WH#7rTvIsFg%`WhdD=(uGmVec@1Fg&?hk9owcuhl{Q^Lrt%ST3@(T zpH>~@HqkuoK;)0TlHJsJdmg3HaLgf7C1S0``J@14wT^zKR86X{$xQ%`a05O$OH z2-|z6snabDeHd8FL7DnSr*5un>Z|L1lb2SxP3zt0ZN!)~8r0>|DlP_1I(2r$V07E% zqE~G}PL-tx11hpV*mm;N^%E*0-prRlSv2o}c>ox$K(814kKuizEw~Z`Gj*ixlG@SW zo2~c8S~y~F-(38wVc@&!#wN3}p(cDtc_Qj)70Tq@4hV58V!{^>02Hq`RPj*6Wz?v3 zkLC(dD68kRoU(NDS@m88o*L1%N+7h|%t-IF)koHNjxb_aR}3Gos7Gbw&0COtbqrzd zSDF91Nz*6j`;S!@tN&~K_4Gr>Z`zuV&gfyzSxP#ULrl7lZv2M^SU8QNOja$BVw@Hh zH>fyhgDWSi;Sbu`X1CKXFP!_*3=L_&%~2&o7U2s_Lf#{{KDT8}Gv*MbDE==jV_UTiDBL~-eF;Rre{hw!MBJ}K+dtujk zC)Lc0tw&%-gBAoFanNSiDdIV8E>HPs;3ed?a&9Zcs^QNhs!{0P&WN>-x)h$~QGwv2af5J#h;JeC^?P7Rb1d zjh;(GedgL-S5K@`jJziHS5U`gt;Mk{kbVyS`!(Al{5DpX_B_2gRO`m2@3FiN*;8aT zjnK8AlAy?M>~X&}Sj&Q?Z3N6magR{;&ER$58fI2bW9&qWhu~2*h+X0ILdhj3o2#Hp4%mdO`Gk(uB;zE=u%tnviZA)sW6OUw2K^vC?wLERmU($g|o=rVE#zI6NHdvKr-B!p8o)xiu9j%&(Pz+o!Y>Umb{ z&8H`YlWAe@quNU^a-d1+qliPk>ft52k z%SavUH6Q=T%uBBZbBghO`B4e4yU&gh8jo#^g({DgZ&y4)&d#K|A>uSPoC==cVnlyg z8d*RtlaxBuk;Q#diqt!B?@IeR_^q$<3FzzeE1e|Lfcb{wdjVJPeM)s;IuACL?M-_b z&s={xBmz%!(Dih^tx22LF;AyYeruvX+QzZGNoi*f{tzWI%e@nD>akEWReubYX4x-^ zLc6_g#6E1}v#6>s9pjPp{?H?hTW|$&H+>J3FnXV=@$6=`Ei*=_Q~A1@P_X%^C_3rp z4d@blygBl5Cr-$~rHHkyp*@_qgn>N6r5AC-=b|@r8$~P z$*qCrk14n6DQ${-&e7>`)ZGdsL5wt zb}z=xNgtO_DX>3COv~|o*;ebH>x1oyT7)Gr`O2RTpplH7+yJWS5iU1z3X#fG^@Y_? zBU@FUfk#u9A-IWbdDa|JO!Tg$jVF#5>uXTWZ9%cCz@{Vr)55P&D_7=CjV%|mW4Gsg zZ7z`80nLMz5E_|l4mLWL7h+}uU#M)-<{OZSDf;k;R|>OF%39|;_v;Q9W%d5Izq3k6 zgr#j78jJCkF~7X0cg?pd6eBabd3gZ?-8OxY1n^vIhF-_r&&}4C7Vm>MQ5xwJ{LSl< z$@_IP&q_Tj96O#DCtUpy>TDAysr08iw~(c}3z-P&m7Sr}`1(!3$`>rP&XWV((kiW~ z<@%r#)UiXEUPemzi0_a>24}R{D8J2n$~W{QH}khr>4Ps+%USOTU_ljb za&$N>G6@+hK8^Z1*@s_rqo0?)StjAyjH-{m)RBbus2vIyziYIu6aTG3CMvP!=4D8l zgwLFM{_-j{!cE^Wb<#(+Wk{v0UJ*HK;XDvNH#pBE+x{Y2=#<-aDNB*X^}sv3N@&01 zdYvG7tfJCiVMK6!@WvsdypEZ-8fi^y9lDc#o9Co_puIo!BU$KoL${Mxnv4CxIjw-} zu4`HfUrz&Bvq zA--JlQ2_~?9H6*~f|9CrQIKHUjU1U3mH3iAqWx+u;uzv>Nk~u!tj~-=Osc zEYafGFm2g~hl^R*#jG%`KYK@EC;XOK9M^q%PVquO=iVlgBI?ArWm{idvPVS43AxJ0 z3%s^%xlnOEY0zRCsFbP+4C5l@)R$AN#6}NR|m+Bny4C zP~C1T_Dg>E4z>sOh(&La{VIR@bT4BmWQVD#N!(}IpQT%Vmn#_oxI5pn#29|R0X>Jz zE?Z@)wcWu>p2t6NclPi2@XX~Ir64nJ;_fd(<^1EA4$R;9&tQh|VpSfB>>U}AWI7ya z6eW-7v_P&8gM5olP4>p})c!D6#qPW8_^em4nnsW2l$he_n)2C@KTLUnS`oTNG7Q&o zf}OLckI-Fq-sih(bBBu=zs#Qe-l%Ghlu}*%HnBEyaf8ze%k0sG()Y)<@!>S*Y8;d9E} zq|F^_sbOpm#(Mo|NNmWt`3U`@j=I*B%(ZzKpIZ21DAi5v!e=YlQ`t!!^VEZAq4O^~ zOkW3Q@QqH4yswz*mP9?9)RYDKY?_dhnN1tHlsS*1r;alpy>s2?(UM06AWuPL&154{P=8h(x?S78}eX%A!Lg?%Zk>eDBZa zY}hs&TMybUXhxR2r>HYo4ppRSRMHuGW~1*?mzVAm;^S|VfjY&&uBh(GEcdT5Ko^)h zlgH=`4F=vC@WE52YHXzBu~c{Ku~pc7>|CmLN{lAlR)HOvtJBvR!3Hxsb{u+>Zoni3 zd-Lk;LSp+JOErs`)ywii8Gv_*7jABIj-e{lMZxxoZcwIbG~_m5d{K9~CF9;VbI7&gk;@&P;9_X>mjs-mx;9LJ8Cs2$t>Uf7#dVzhLwkyE5 zw(*gyH`)EJrz7wG(RJQYO>}L$7ZK410Yw3o60m?gC`geG0kI(hD$+|-nn;rxN=U#$ z5u`|y8Wj|g-b)}zktzWJ36O*!Ef64~r$CZ3KHvM5_nhzKk1ST!%$j>Pd+*t^@9X|u z*5g1bvdu~)`D%p+LupF<*xCxajdr;D*nNA2jXi_N%U7R(;7ZBYz;B_Qmp+t1eHQT! zU_N!t;jO`nW%+J**YV!y-sdiXNhdlPC9%9m)B;}+T%SL>8Gtrl$ToM}+I|I6%kb+7 z!=jO*>6vkH&GuVI57<|f++`HDYAUtelg#!eRP2i4Ria^*>7lmD2c|nJwO3E8wcu*U za~+nmznf|XN$Gm(>`BZ*~RiY7Mx|qF<0lgf`M1w1p+8$%IR7KOB=P}7Q#i#VU^>mDz{74(d zioV*bbam|VuMA^{XqCZd5*RH*#}W{1TCbi1-)*{gHmbLu9?qW65nTtyk>w%YJwfow zUCw^^dwTq7C40wqY5BFVmE`DiI+SrIyk6MqQWKa{vNE{ey`bB?VuSnRi@|=W3JQwm zEgg1nizh;aRo0QuWGN^j(Q{ZiW3!3cW5p{vh>odOqv zwW&2ujLg$)D8Uy66X2D5389hlF7+pHY3^5gLG&l&9V0x77GEiA-cxqR)#jEZ|FRMX zJwD*~xA^Yw4RQ2V`==GQ9?m<_IPwTp5$kcO)1~G_aMXLWoY?fl@D7t$=NiRVf{REKW~*L2@fNI%^3;}3-}tIa4ZrFg)!7-T z3_ajtyzk6)#7cbIW<5nhwI`ZxAXV`(4=T15&&zsrC9MuDkdIw=n%xH~6E!hhSyQx0 zl0E7=9&Cx7wOuQd!oEeAlENdP5?h|nehAi&W+O)La~cww%@$SkhCmSz&A&&ZK|kHq z^_sh%Ft#MN4SbArhIZdsTtjs0rGX+1_GbN^z&DB|?@ESFZjW=NF|ki&!^gkVczw%U zFol43nu$SatG?Bm)uLNav!mX?Q&02x=)6TTrimU3IA8XE?4Lk9xtlR|9?HxU?cvq4 zx;i*_WIW|yB^%iA4VH4E@Hzib35znzPu-$F^Oe%dn~*=M-SfUb7ciK|Y`0!02tx|@ zJ#Rk6dDgQ#YKkFj_TSB*O$B(jT_ZKEoWAT+<4xnME$0;vOQLTr^BxJk?T-j&MI<#U&CDF>Pl+_) zPCn4v;Rp^baXnD5Pmz%%nIzQLoL9N})B<_7ZD!*=SFBS;HK+`DG^U$Zik{evUWEMPxue-cDw$1Y>myHQg(c1!bg(kP9Pp zf}1wYg`(rf!?6yh=@o8qEKfIL_)d^p&Xi+7l6uLaf!W^MIPE^ZR;Ju3E-4c!o`_4- zxfIg?LEUG_PO;)miFyKgJTAsUHAx~#d{k^dkMc@d2IT8TBA2fL(ZD)sAw`|}4(_ro z;G2M(c(L;YZNSa!^^FCE_O!Xc69j)(>X7?<^MXsN5XTv(cvIV+iX9T)%JE?)32V`x zaQq!L%NDHkugX;#65LgMd(L3qFn`L%J8aR2VbCI8U$Col$&p(FoJ)r-J=gN@+U<(1 zoM`MYKHBPRXjx%ddLVmL1>ge4QZ=T zjc}f(1Dqur-yhX!lZ=u(V8HeCw|RZ27*GAdle|Z@nXsv>hex`QkFG?G$v`KSgY%+P ze-om8|7vS@#mEuk=i|D1B)%2eWIzxZVf5ZIqvyO5h_r-3B{%!G7th|norQYa$R54u zSy8f%L5<2nr^GX-if>0;L{1xg z5p%cfyNjsperfy{OZ%YE4bFC)uyOkM{X1lF@^wU#_uq{jH%1F;*-jLG)*%gnb0Ryg zQE&HG*bVgm&@_EJUYo{O^@=8L-h4%@~be5v=-@2}KEj-&fneKkD zqGtX@Wb`F&&I5@`IfMN;es=)n6C>jA=)fA*52*Ee6jBIKmI{QXHN;iwCW1OyAK^Ne zC!BCv*t1Yi8yLB3*bJ@iIw5y0Z*s<;Yi2KEwg3acM-Ti-D8bO3eYwD`$w* zHt8Ur>N#e)yry|P`^?#r(4RVjUXlT3RLNmuLrQ@j>S`XiU}lqC^eBzr`7Jr?D&=k+ z(}TshVhG&mZJBNN8yDpCn~A=~sbYU`ss~?W#j%7hE}4If*t;E{l;LxB^@df+-gL&> zcj6JAvFaLek%L8uQXP$o{Wtr+Slv8-OX^WTcgVLc`_YW1MOsdTkLRDdJR@m!dx!5I zr>oV1=CP{VV7FcUeF}1of8H&7)jxkNEWQ2tuHvrMizNF=1v`e4EG4K$$xfxlRG+>wV~R)77Fer+fD4Sv^jRe=7x>d6_p@wWd4K`VHd$D{Tg` zuvC~QdnM&{xCeRU?2Ji059I&b{GmCQoJ3JqX*lVZ#<`wfk zcPIR?VhjC@bbwSgeJ-ZyE+Qc|H+1o@3*Ym?R%D9(>9997rPPft@+>;O+TlAU?;6wQ zB$8k=9HmvMv{TI%UuzWZc2e=~+E21(ohaEiTdf(RX}P}Gr)bGobbGQ=bimh8ob?MH ze+;`Z10StYQMPn0Sm31V10{s}3bQctzls6I_LPm5cU$d#}>o|OoBQL}MHLZ1~3k4iJHH&Fnxgi|}xOZ%{0hzVQ_X?$E zl(kbr?N8J6NCzB%EsDW9cI}tnkl4aQ=|zO+tEP$v@SY+!A3L`)LIs=tt z8&=RX>p$8h0H{w5zy4n?{ueF3={xG1uDPEG`~EQc!o$|I=pBfKWWvy&jKM}yWZq!N z__Mec-+)08OUC=eUamt2dd}^P{5}pMoV&9c0fWhO5{2(estaApx0Hw!I=4a=u;Ehj zV_+buRZkSp9TYT5?H}OvI|o#&ZfZHlmEU63c=8n6j87lIHR2FPWK+GJ+TX#Wak`N; zCdRiZYayb6h2?TSyKmab=R7^1@8FOy2j_!@2b)tEN2#K_seQ}em0iuIiM$;?@9J`TUUfQAA%9(-n@>?X?=Gbd z)GXk7Y0_FTX>{1tvhiO!NoS9mFJ__2rqi>%lR{U2_va@xDaWL#?f9$r&C(-SuP^Mr zjZ+lzlc}9KXs5xByed#dJ`_G^1xZJ^k8J)`^b*}2N4Q=-TW0xZm9Pj*%>81`7dJah z?al?AXg<;n_)}UR`%qx&!6`m|?r`9|&0VDQ;|i|JgNI9N%a3((4~FY#`%Rf6e)AV~ z+>ae2!~?$B>PX}@vRQ%9q>8W(}V z;UK6dhmJ67punaNL)$Fs8}iM3=tW~C3BMgCKW+naEZBM7C>?J5AQ6!3@gLwvp01?w zBOML$3VI~Ad8&7#pRJ2Uo@__X-cQ8x9@x0S@pe!TNH=THIl2Rghn@U*hhv!fV--u; zWZ~n;Bb_FDhts{E|M>gEE4INa4f!`0#B|VJU*toIc9+roe1$KWqi3Ms<_ZmMYWQ|P zVy}jknyDD5*A3Tr+g`Wl2*;`(5NMiWzsl>)p*F9gFYZmgEH9%^6Vo4q+k-bR1{}R` znYB)&$c=xA(^@1Sv%B#%A;QTc$7J|cYrveFvy-BiqI3wOD^1v-Nji(L$0rmsJCi?e zGvwVD1^a2ClVsZTxXWAFb=i6M3`KOgaCMfhD0#1?n}4+}V`nMk&bE?Z>}d2a%ds1} zy@PK=KX$!^nP?)!71{A+nsp@x{#0X4vEL;EBmEyxW!YUnRjCx-B;i!@6z@#;ECw&%_K4ZBaRvuA^t6 z*0st(TRjDr@&mug-UJ5x8Fvp4>tu3Pa%I&&3Bw9Eqf3vYGXNu!6OW1M`<)Ld4vGL7 zrPR@)(j;vqsX=QlZn^8M`+B8^dk)6Pk`LeOaupmdTf~=%JE#6c18&~L5CqO?La@V%+w}xRyAMp%lk|D2UwW3AbyhZtJk5V7iLW( z3e9!rppuIZ*@3wCfU^pqAek4iTwQBCDOj*F-%$u@(t6@@!(9Erf9N!P|MWXidPae* zd{D3weOJaqCV9ihM4z&@q$VFadAgB1II|FJUN?5I_@TlcF5_it#7ce{Ou6gnS%+7{ zW8c7Xl^a?v9$xxU>t_Vq4;JwTJAOhpUDeC?dZBC3cu>l{jJ_*6&licKv2$>b^53Jr zK@>f&aNTPMQTE8u5NM%~!-RaAu+OY1D|JsoGwdY=$WaPKi)+m!7WdbQq;?!!UqJx2 zS$cW9-b~?j?eg)IRE_T6yq;t(15b{gL{8(tQ}62S_Mj7AwFj{CqRVCHXZf|aojBH> zqqOOPjFpjJb{M?Lt&CYrbBPfm1YPh@cnHv5{M|iGY;={;>)rpqC>Q>qM4TAh`xkt~ zN|&atAl~m+LNS<-Vp~ma8(z7;0R6z{M}n8m-<5)<_EbCnC6C&n51h6r4rEtOoWA-) zoYDP@aOvmHvAz5(LPi|RIB}{f^sIMJwiBm0w5YHQwaC;yJxT>|?=-*2j+jbje=NJ6HA_n9iiBaWVo10b1+e)oN$%qr2fX@+MBG0uQ zOm5FJMtN369lZdEp!L$4LNmz1ZUsN9!GANXCptv`nj^{cENf3JuUBgIi0wR^+{y6h zBRL(_-;+x?552&d$))2rHjS@SB5n>&jOB(g-fR?Eyw0()v=3WmQBtcF0{j)q9P0l) zq}vH{vniYZsCl|Jc#)&Ijb8J|<-Zl)RVr$SYpyT=$6c-ScT=qm+<-bOhsEu zqUVpi=OW^c_GU^|a`0e&hooB4nU$s5k@B$pa>J4(=dnH^>^54jI$ ze3X@KB|XPmmdiV$#*?n>`HOHyp+gIhV-nfo)wd5qj46O7f$+n6HT}*9&pu~==Y+P_ z;Sbb?Sy93m+Fp(5+TnUg;?}vH;ot9$>Um;3Y0F&c%^%={5+dxw^4BT*)O;On{dk*4 z+`X_Z#+yPqP88iv7PV>!vi-kF#lE$c?Y&*z92YkF=xQ`nyFB7OxoRhynEZzx^M8G^ zj*a*b`gA#4XN_h)OXg8_n#JgAjo$0OAZF=yeE*ECf5YuOaorz??Fa0OLPDVtjDr+js=^54_~W&WFNuX1J4 zFEzV7nE8a3-u>Jy!IuvuxhxW>jcH-w4^s#vvjA$#vyG}`ZLkAEw_eYhD*JpJzTwnn z20sE%O|HB@8x6L{vZi^7P$FjvN`SU*des9$(T2mvW&V+w{nyt;6##8>;hn1c+iabX zs%&MK*ML_t77u_=@bRZq@GBG51bm}Ep*dtTJr{rMdEq(e-v`WOLX<6o_7En-n zVX}SDa-Ep=SA5x#_{sxj*EXyVwEu~w4RE2(*QcC7x*AXxdHyq&^?O}EGF4Rm^u6?B zM>YT2!Ez;Om5fJ@|MoB8;S)I&TkScA8H7(pOuNU=_4ZiX9HpW*bE&Yx=IQ_JuXh7?`mCYIK^`Z8G4T*NFkjX_rM59h+C?Oz*699{qC<=Q~4}S)Htg*LX&mz2~W4 z@3y;ipcF%M{HV>NiHCNbA!xW$Ax8M98KdNu^`u_wMp2RXw{i8ib;4YuxoStLcxbxR zj?F1wlMHM+y_v9qSEUUPO&H<&_J#3}`~I{a(mdII2wn1fy;0AS;P#GMcxmTl?m}v*$c^}u zzk~3;H)#OI$*uz6FEx}opk%_G@IW2C5fJ!@sdl43M)PJ*;<#Gq){`RR63EZBp0kM! zdg07-Uj4_Dob0?CKf!KXVy1L-)!C-!b;j$RQUxhb3o= zdEfYjcViSsh?-Apb{Br9RZ%GGQMj#=b(c`1Hcb+~&{KZ@N`vkyd+GUjp=MifCDusy z8Gq2?kipK!TN6&6{y(o_moi^dk%P!Z%U#kfb>|tow|P1q$pxfKhtz53zt>5~HkvxP zo%b5x$MDVil^SO0QL;C+;z`xE51UnM&HmM8cEZgo|8$vq9&np<^qokHvm_(}-TdX# zid;dLoqvMC(Zr6rXOP^Tt~0cOjvI|23H7e+(*zjlebJ$A&?-D&&l-!1j|8sNANX-e zIz^;`A4bfDnXPJucN@#1h@Txl z@)P_3A#@5IV4|(Ufr<_QsoH%zD@_(CDQ?68B$fWO3(KYTdCQ|kDV^)5t~^cM1@Hw6 z#16@nE%(A)87a)TE#UrpUI36OmYr1de1`)FW@3w0&iV@%Qb!p8cj9I9A7op0G`{zo zSy$iwo}6gO&>=$T@+Bea=+bFuA~HUv8@&SHtv@ao+9YWMbByqDnLEz_=2|*l-#jR; zn~CuUg9ERoQQk19P37VmlP2LT2_sM#=?F((Z7Q7hu9DJx(+%~=T%@sFQu*^1Qe#=7 ze&@H-d3L4ljZ|j8Rx4%mP09we+4Jk7mf$?gUPh}y>$@)lE!w_p_?yz@D zN*4-}tJn4>d%bQ^4#i@r5ELiPo_R>9b?Jh)F8xHVPv5EMY>(j8!zF^6Jzu9X3i)Ju zmEh0t8uhyt<^;RA_Rd>q^sLCCn0(aEggXASgbY(Bg)n(DJ}@jWbijd5_bj5>Mkn|} zcizdvZ7GAMJM)s-rjyU%C}Wvj9dm-uVAdk~cfZcY&eF%iW{aIua`X1MRsNq>gi-dI zzZ_V1dPcl@VDa}b9`4$cl&>pO*KE61D z+=Zv;>3V%keFaw2l?7{mM>>_aHty#59eL6!;kT)(DYKqjen|+yoK+MxNq2%T_f#q? zRM=g1JjtCCo&OqMWMziwJyvg$0S~L-H9Y#Qx4`-IE1)tpfuCbLDxeCY`%EmT}Fmar~txLSP9ZGPw?e-*}euRG1d>0Ysy{1Xt zIVE&II(M(OY<9$vdpy=7HxsoFtKgJA`z-hV!R~JCb9g6Gk2xEXg0~Vl?J(9d6`amq z4>v(fG=8W=b85j>g0!-&v>oXXD9tG|Os}>I_iGCX@1SoZ_9hZ_ncn#$ zGO7OWa{2bnMy%^MPmLQ7d{WX_h*URCnH7h7^ayG|Mukg)zCD4ytN+~}Vh$<=`7-~` z%kQ9PPj?fqslykvH>QrxHo1}LVLbuR1;c6>`;-N96~-!6bb-ykSF+Ih{zF}QwyWv4 zIdKQOZe2gUy4KE331yfd5*jj0)||*!z>4uFbi2n_R*cx8$Qe?TFIy{XK_PS|khl45whPN(%ZZxA@ zx$T+CVL4?&Wp1%}O>EDF?$H{9vRY+idl?QyTrFUgH6aHtOJwF%EzJVsVxBb9>&;Kh z0Bd+Rx2mHpCB?wcR&rIs8;`?U-^k-`HP#>j$V9&dG4$c}gW#uYv;jHP_dhHl#nnpo zhiFN^KhL&KX`6<`uWvF!+JQ2u{_q7Aq%VTr0mA>`E=^vt{vOGyZ)KJ4E}0?zme(8d zaNH_t76+t54_NDoh*S-v&m*V#PU&dzGjpBg@NM~e03_89zi?dE^aOZ8de1si_2IXO zuYO!!GN3u0?GHLVZz8#QU$X#L+h+h{w6^5N9>A8P3g~X#J&ag;0crp!g!fw1mnEwg_ZYjL~kC$Nz1`$D56o$>|*5? z(d`Fd2|=YNXCaCOp7MW7`JcE=-UEm-K>)lGk(B||d|3bV#X3NnqCxN;)`ln;n&B8~ zbjpm;ht@vU=%iRzcSvCaP%2x<;8PvegE{qk{l5zih6d#FqUXyt1ka)%x+Vd9#1M#N zPLx@AH;Wwq@FoI{kkVjNY=k)DlKJOWw45V%*JF?4OG4t#^M4+&SsBv|ZO*>D>|lfp zre1_jzNj|VKGgkg`k)!yZa6nDcX_8lMjTn?6Sia$OWbSEW=q4WItO7->JazDs9l&t z^OS(^9+aG$kPMCYY*AfCRA;NN#(~~5T)qKVusRmJ5}(rK2b+n;E1P?o(b*HdG-V)%iEuj zTt66KrKfT;paweKIdpT9l+$lP6EolGV5|RlCaQOgyxTt_(-;QHmGxyJwPpr2KO|)F zimf8|m?-bK&CfA{%r~aUIgo&1SotO^a7MQp|As(n3NOo6Xlmq}I)2njM``*JZMj;; z82NUp6MRlZf&43_Nj!MuNH6yjQruaQ*Kg1+do5a_kA5}G?{Uv8ZsBz&p=iW2$xG}4 z=njdRRpy`ZG+xQ^{yz(zjeY$>xKsxN2;w_ZaK_#o=cxQkcRUP@BY%9xE)okj&Cy!a zEV8ibTH;BJW{>JQ#bcMvnD&VVnp=WwagXSJ$COZ@)QI2S5Ew zRnoU%D#T&Ey{B(nn6(`pk0e+0V3E6J2;Xy#J{Lz6M~w#+8MQhacY%`ba$R!q?1SBi zh6L`(4%o-;iQ6%aSLF(2FY? zHTvDP*AUMJmNiB+<99w{gH(9^1#Pn$RS%xqM~c&AdwdUkx;pwQ1D0UI((rjY!aP=3 zz9K$A7gJ_Pgk(1CG^!IM+4e$-m2E{Sc;mC8jj`3DsB#IdsY{{i&0p*}d)eN*#t@Hb z&YO;Il(hNPMv>gS@DYiC%{#FiN{$?b?YMbfFPswgHhRNoL>+|luj$l0SU0grOqmq| z&yC&fI?gR}ix7ic>eiNG$BoFKxZ`Hyw`rTd1jJ?6&qsRU-WyTrZXaVQMu=uE_+EJx z^&|p}lvfK7V`?=wUWPq2ARy+#W6hCNNo@nNX_nG$&`1LCcjd}i9IYm?$pd5_Ez49) z(&+9o-Fu1v<5^irvZ?BAZ-Q4H5Q3Qt6j(^!;*wSS=ZK7_dD=GjGOFb1;&Fp=PP)jY z65tI%$j!%i7%(hzoE=w{d?76G=au4>s`S9r`DFm{D+Zu-3ugT;4f*F#2q@#z?PLy{ z%5jEAHfSvsq}+zUn^s@}*QuGLrzOGC z0`~yKX|%CD*Y5)p*Fy@VU(#3lnfgyyn@CQo#`c%Mgm;BYsQg4dTk^XN#+)ozP8xkw z_oxocZyTV=rs|DCdXe&F4If7hy$yn&gu3i=PS}6{W^AsD40Jr>-1cxbpwfL@?*L6c z9Ee)23q57rt7t{%Np{ebN?uN$g0@R@rXXvE%39V`u&G zO3(oXFNns&oG>?E7a`aW@Tg}*J+jmJrg|OVkAj zfgJioLQ~cbqFmZ{gUNREVMKoq8J^-o3kJ1>M(vtJ7x}HUI_MDs#hQAyB{&IoyFG`| z9O5&Tg%*g#!D&3}(`-#uZYvo2b+pJ*H+BTl($#X-x2yf&s%!>)+8KiEM}|~?1?qjI zymzPaw3q8uo#Gox{hfg2W=2~#2%+Pi*rxf}EU{%b5V{$+NocO;%tIpDD>boO+P*ln zZJ@*I`*n+1NVi)H8&<-(s#zYNHh{?_@2sc-MPZEA(r%dg()Q(r222c2`9wxg$Ovom z^JUq)oN^}9EcbX9Phfrm*<;yz@Yp6lw)nF<@2a#ZuJnzXFD0h1ED}U-{7QX!Iep(c zC|AR1CZ2nv*krx$T~v5MV7Yppc}Rmy)-Y{L7<&xMY+;A$tkhl3_`dmiRb^{@`OUm- z_`jyK5&CdqXYb}S;t*$hG9RsF>ZM&{nh}t>tfuFG+lK0;m@Cum?P*%X<2V;A_q#hj zmC&A0Z%ylrc;%g&FUzdd!4BAMDgOM`#CsnSMy#xu9ojEJvtT;OgVP_F*+kGWR;C%g z-)iZE*{ejw0sE&0txs(t_5`=ewuGIi-LfWrEnQK|=M}og646!us`R749>5?EPxdj<+w{!_Nn+3|}PO+$&qr zGE4BaORUFhQ!Oax-$d?8$U6jA-kA_SdKh4J-sWbd%9-O2ig`-;_Hg~@OodUB=K2P# z#HXVKB* z$%ZZNiA)dx*dCUIc_N0rSIs9o3m-h?p2N9jd-eG}k)O8%O{vo#M`*~WuWD9(BfT|N zIJRF-!Eha*2pU|4aRBakEU}T4Cx1&4y~uSgZQ=Yti~flG@zkNn?0Xkg8uM?p z>;ap3G2`L&4)c%4;V3Uc0s_|tV90w{>z2#-_hwAeq@i19JUk*MTnwv#WuAt6;`-?O z>+HyfPt&{?V4TMxZn9R&cmk%Ij`8Ejx8G{#COM(f;c;>yb(hO!&hVp&J6`%NC zAK2aW536zOVni$TmP68NHp4ZsyjLZg1=a;$kPBH?ZFcORqGT9O-?xXf{7mZ_147f@ zY;lK+^ffwgQspS^vcv#E=GG^(!A%$RJY@gX@NYHh;Ad|1=&N1*NkvqPw2qS+8yIYV z(0(uI*SyZ{y`ydyJ%`}8mv~Llhy+x7Ju&^!VC!mF7^Q?b9IrG}huQvirKj9uuP?Q# z@L65C)h;ior}4AdPhYm;lCl~3E4(hemfWXdp*ys0Qx0w%Ys{lA*WMkb?bu4yL2@-M z%Al~u1x3osi)UY0Y<=16OP6aP0t)-acrLw-7##P;qvIu#C%&j%?c#55qnN8*{$26W!>!_m0qOf zKZVtFy`Ltq*8FYn^ZdTy_)`=YUrnurS*P)JBY2tQrI=57b*xG9ZV< z>OJBL9n8Mf2#?p9S_4zT-R3T6e^_#Rsh zx#u$CFq0%#;(bp{ar1Pv#*oIf1IQCxdp0e+njeGqN&5krn%gt`pS&7nR`I}0{LD)Y@WLMOj+AbO9GATwenNYt;)OUQk;nSp%hkCQv-DrLYhI|T zS$2)@5$Rp(1@^ZD?GAn`b53A-WTD@KO2J-T-8+R|P`v50KNxq->iHqaSTrj|%1M>K z=m3{%__rXOmn<@6oun9AcIn-qbYhHo-lY`uaL^>v?jZ>@c)u=<>o)n@&j{DEK+4Wi zMt^OK{A%EW$_WBT4q67j9M4pA{;Gh!u!R@XG=yn zl`cn#(I$Qww$WdyFo*Z0UnRBqpdfkcwwaPzzaZ4Y)&?WVP&5SP$I54T1;h^>_G zMiO=*T7TmAM&>6l%b@jWJ-ij{lZE&IE8bexmd=sixF1FKf^T4KwjR0L3E58sqU~s% za+D{W{l!gS2UUlF#2v^3at&n0-yOHT>Li1b<$a~~v%Z)DHrOj1+|Agcbz%)c{(9)} z6=(JOFPlxWcYMW=!WbtAr=mVK(Fc;+%Q$-g1^v2JIYY_gBZ!d9pmE?s>IDX9#ly?L z%m)R1H&{rJqGDo*)$rC?FOU+8^;LO=Q6BiOX#uR~e%rm67tRmc=#@>Wvz=}#^jb#R zHcpw7h;`+b4u~*}D(9_483aSZ3Lwvg+n0llIG9B0o4qUATeY;h|8Z!W4xxjl1w)P56#X->cxE}dzUBoBQvQ%&5vC}E>2cvgX}up zcay*4qr*E!9Q_@l(Px)NuRI%d@JVG)zYHTan1gcUeY@Jy2vCsy~~ix zW|ykxwFXbW^i#+Wx0me<^nOx8MXs+-H%)%4kF6OfcE`De4vdQR@7V6oYMrwF3|X}D zI?E~yckOm`TCGIaN!ZGE9b|`2Wg=qK)e1YOGu$QT7@lWb%p(2$r;exXc2q(Klfy3g zhV2n^bWJeErD5+evR~^fW{-B#EOZf1>s@}<+Z(rTVvo@71Q@Gi{N2+b{@#V_6e;>n zs?sig4f++M8T`n(A?PR9iY-{XjQj?C-Kjfqd5=8)-EW1LrSg(|BAURC(%wwIEGf*3 z-)qV_3pmAxO8AwJDS<#831*WY{R?#k$9Oxj=H^LSpl_1LbtXBhUrFaFzqF$7B1f;- zlv8J$?nm>ony=v{QDftITJ;8WqZ?)AD_v<1LRGRU-U)75}BVf?! zHbxEu5|fR53Jv-*Fp6a(8)S}(43n(rX zxNCPF^R?6=0CopLypvY2jqgvxe|cmLetA;POkOZonW+P(;iUy4ALDuppO(Z=JS{H0 z-LBtXJzZVGEvQp*hX^D>ug0&F6bgF#Aw$)&0`4s5cwtNy@BPCLiITeK1`56PSxfmq z;=*ybjxCZS3dfsHSc+Vz1h7Q$@mdk%M&E_y{JI_O2e`cZv?03vt)2*La#;xF5;VQF z(heMx8y0ry>#)t*fd6d>UoLO!tRuUm?y&u6Q7*hKhgK#KIb z6P=2u>Wp_!>?T-Y-ok(RQI}i3tWdYj!cAbc@v|(xbt)#?@pDKpy7uNt(9z(UH_G+s zfX~^eMdByq^BsTmDQ;WSmQXU|9#5nhhA`3$|@aeB0fpY8m^HAeHM%^drwTOx1 z5Y9|~(~0!0(+^;?J-vPdPeO-MqyA%>xJl>rU9B$F!X&}5>o&z;E~mK7B6rM$yWlJK z8KM?j8aZn&iG9wD?4SncZ`HnUCf#ga4o$GTxXH%|$*c>k#~#`oc!a(vpyPjmifhCqd5aLmtr1D?T^_XF82Poce4Q-H2YlH zz~<2=-bu!}gI?uONG(aQ)5TZUVEF0ji%a%jr}a!Ywh|iC=~x$dq2PrKzZ$~0GNx!NvN&qr62E<3}bSEeC)Uiu(>HEys!9*RPbn-vtZ}J-7jm(LHHNJqk732sWTB6FFQ z6H1}y{kMYE2L2YC!OzU=H@iFXtTN^m z5jLM*#C#Oj?S?&fC3#GC9GraWcK(EO`lNJ_B_w=%*i>Tl2FpUwS~E&g==J&+xV-#> zKa7^j)LY5g|JYA`nxD&XyW{T=)ofQVnQ&K@Tz7F}sx??Td&Uv6M!hp-n zUF>anZ(@2yuQJl5G^QQ$!BD0)UH|ziK(f6~&X@ipB(lB@V37V;R@quvTKYxr0keIR zHo2_v)#vSVt+!lzhwIKkQb3n%l6xiCUvpcv5Y!ghUnc#B!*tgtPG=h;QvaA|oidIE z6l}e3&l@lInJ8Wgn04b6->Q}PU^?pMK3|t1Y6Q2W*3@mC+|2vqj^$;zafR_yNN;%| z?_P-(oDhBjmZgnVTi4$H1Y||Z1o?XRvgSTz!e=p!r@>D8?z1`Yg zls4a6EEs@%g2mMC(hKo!t@ZiYkVU7))x}kNZ7LKuZ7T_~U}R`}p#llAXu21zZ_9Sn z8kfvzQ5j(Q5`N)9iKy=uQPa_sPrPM8sJ)Qmw8lYrACi=aszswdXwSsU6H4ki7W9)0 zB5&Ddsc4gzI&P@6sZX|Y^Ol7Y%! zf}{mObZK8u{hN=}`?s>Xg}v8>gmjKWV4bUt+dhO> zgJyE7{TDb{WHpApHmxX-J^lH!r?NJ_-jf=f)>TOD@70EmyA9Gn-liU$`j>pnIbE@I`h$Qgvpf zb?LakRzt#XUQS18{m#>mc3~Y}_)Z?-(>Ho^TN0O~*;O7Zu+&aS2L)POzuSOn*t}-s_TM9E`1CN~Q&hk7Ia}ti;(!vl17L7AD zXnZYuYR4Dw7v_3Z=RRE80l)7W?LBaf@&mLowliPaLiqXWW1X{~+xHAX*OnPHqbP`y zR2+8VG|3VD`<7-oac^SGdrpihVynmrClY?bc`I4Za66P2S6MwFs90|Tab^DV#gZf& z&Mp>5+2BSf*1h3`TyOmQR&Q=!5(}yAmdJk{+Sl>>^aDS)6qeSlrVo3Ax$87g<1a)L z%5L~7>*(Wt=-{$ttDmb5eNM93XKo9MUJ!%hGTGGT3m~S_V~qjsW^#vgV76P$_I>}MlWroj{q|@;>m;GNZkFM{B8g$DOzRB_T=Fvn4f)WYv z($tCdzHI!LQ$E5X;8S`b*^9_icNrJm+B&VSL2r_#Udc$KFa08*n{N_@kq+y}(lrRH}^6zVc zgzY+cPla*hE(Q@leE04&PHgbUEYB@8mv=X{TjVC#Zf|c)tw`S&U=6HOS}Drd-_3ju zv`Bs<6sMV%9>!#6<29!^?Q!LSFAC8%*3F}uH*PyNtn9;5%!&RTA{Pv+hF0midL6a| zU7f!xo41I3_yjOBryhX`%v%(rl`nZ$|H3hp(esXZX(z*|CeZA%ZC@;9miUZCJktH- z7DWTfFtCd$GpB04_0GZjdNcVl!jNW-VNr?~RsYB1q$a`oxtmd}gfoC&QiBo-o98Lo z;pGLZGo~3R-Fn=JLs-WZ?+juX;YKUe&A~4XwH~#M@8xB+Y!SR^9r!C)2dZ}iN6|)cG>>PAHUhC8N=Sy^*bq;Astru5Z=1JQ~=vr$ftt zbno!v6?StMF?!Dwp<5FfjR~?V@=dL5mOi!@#F;Es2-5as_fH!;D58f6!L!?xkLCgw zHmSbBVNk;MqgTUIIF8<8Jsq_ia6NjMB#2remFev2$8u&n6DaRnXwTdrQ@yzrM9jyL zovC0}EoDu&PQ+o>tN$)w5Vg7C!rR+V)+6aTJb4^~Ykg2%-a{kA)aPaom%gA=u^;Rn z-Td5O(wq=}GpVDV`FgkgYjF(mE5v#rd|n>nOA{zglBry?83&DVqUeanX@h-v;7%-V zMoK+worC8S1yRsd%nW>YOF~P;1)o84>Low*6X&6m5Ll6&M_Ld?1<5EWz=b~!gmzRP z|4Wf{P}ld(ZkHR24_zO=qk=rF2jY}yFMjQIxzcTy5Aug>1~MiUX>yj2VAH01{WN=& z#hCA)sZq*tkixs^Ao_g03*NCnHVHXS?Q9`87<^m6`V#CNr5iImy|3?X}nXt+F#QJ4wa0 zI+FCKk&Q3I8W!|B{kj?U6EK~6QX7~JVu!|qQP*OxtW?aI7%d#{hn2!4pn-j6NX(%nEv`!irqD=IE~WPQ4Zw0d-9?mOkSlhpn}OWuk)QAAr< zWK?zyCeLt-oG`xF1}nU0d2|(gSVX&}Rn{GZnx$}yS!9H5Upqn<5He$X?8CUa0#QHl zg(%X)xPj2a9r#`ou9la3ZpG(Ut{b{OnL+nfy2^d%^v?kRJDp?F#;Vl+s}t;?N7j|T zs9PZU;Aqg<3_MDN_t0nE+##K7D@sUx!*NhpYTxUqw-W6T{b6f`7Tcp@+|V4#C@?(Z zvj@mKrx3J{BpK-T@g@}nEYg|JiH>!|Sa|5Mn`dr*eaYepI!kFALOe^e=yv?WaazI3 z)fpo7VhJsILBk%C!Cet|3+kBOoKB)Kzrw>HlJtS4N zak^1-i698Pv#EVFxxa&k6FO2v*_1~+xDuN%E|%?Y9pg3|30>~UB^_?3o-cQ=q^73o zZ+r3M4$vV`E4OwEdu7$OE78$-(U7*KlqXk+n4_dENT@l{bx4x4@piUV^JhNV-ms z;*lL#B_1(eL zI~j_}Dq-yG{~@=u6p*bQqqX;4J@s(=VHvt>x4RE_uQ=>9OBZpn+Yp0oRYSGobo3o^ zQ>KoNR26*Z&Ytx=gq#eF4Hkb3-pvM|DI79mIEd}hXG>C$&HxN|VdYZa7*eST8!5gQ zjf-t9I2+SL9pFxb#M6tDQjYqhTo!*}cDH%7lb8!!X9z@^Qu7_V#*WImQp;18RZkB_ zUJ;O#!qZc<+{3sSGbb139#`sZ%;lX)p6yUdMKR)b)%dIySKg-|H^DIKWQ;A|$yi=Z zh~Dh+w$;+XsQLK@aBR)!!JJTa71GaBYcAh9k!Sm8mvn0I2q6SjK0kwf>O|~;i?;6d zGmz<^MOxGGy&hKKPD7ULMf#gmuigJ}v@l?uC7*JUz`DFQRFVWJA5 zNPDJ61xpn#Y85g;V{h*uf?%aO_NcF*&1> zGJYd2wE1%h?_;&j_Y0*Xd;&+S_S6G#3sd7_iyt(DuwOihpS_~R5e=LpZV4c0I2X~d z`QhvaUtu3Db_;IVm5W(FrtOuAfSRvgJ?uJHyd&zp9p+LJ0g4cMv#vXVbFiyh?j3l@ zbT)OpE9@~?(QarA-(4q-r!RDuy|^b8T7R5HKdCaYrRKETD8L!Az|$0AuLpYvhpgn# z%$l!TAh(esGgx~$491p_slvu{)!yzqhiKWT z;7l>@{=;*t3RFdheTZ*hyoGUg`r(N&3JM!h7$N6U%rZqv^ct@G*lhfAX z-FDze_)Kx}{s4PyQ>|H!L9Zbq(J2M7y8_NL@|)AsT8?$_>*e=TslNwd4LP;p&wdlV zfVkXz6rcOOFP+ZTQm&JsP($n8D?+G_qNl;A>wOh}Qe)iv#(} z2PA*oRor>yV;t_I<+EE)FC^!dN_Xaq%lt|*3U zbfGo^j+jM7MKjE8nPqw8;u$O4BH|t7p=!Qo>HXC#5 zuVY;mn8@9^0-P^Iw8-pmNcg~iA?qq+YT0y;1 zboZMaj+?$y*LCg*meE<$<*E?@3hx<;q7scrxj}reGy1vWqtzg=|t_-xH4YP8V0R zL>ooj4cmQ{(R{n|%R-8}Xr9xP*sw<*k>A7izNtwsyPrOshZq($*@ zO&;uCOg-R(=Q8I@+*L~oMjaH8c4`I7>ipil?Isxefm6}JH9ly{3Z(`5g9aFLK!gy= z49mS%ucGXAq~(Y8@gtp{WyK{%9d>gEBR}3)ta!QJkP{~8H0FA;+--A`AA@4VIab}E zpoKlQSHgKJVi~)3xxLaqjxC2#+qprGNG!jfS9BZN7}v-pwN_}Zs;@~|qim$Wyqty$*=i!+qKEW<`g&wLV>XH`Y<~jh@9pzbxWZ zG|N-fi$^}Uh6>&i|I4*P+jDJfw@Ydzk`jguIm>jZ=}-UI1UJM=SkB>!rbR`rceW%} zQH(H;oCGf`iH?RpG@H=C#j!4{7Jo0r-exp6#IPKu#%i8uJw7K$W~ysv=D1k3{^n>7 zMs+n5^=kM#q6ghVM9co#ZzbQpxZ9oJa0iwjHpIbuaHb9oD^~}Po$e6l{y2&~A{-Q9 zEISI%*{)Z6kS(C+)~$WhysuGPZ+}xk2(p5)1uez1Tlbw6=9vm*|LRV4%yB5QV%D2M zU|oN&(x(-7lfPsKeV^~VPw{9aD#V{hTGgN*O(q_HQAj?n>NYe;^=X48&(oEi-a{kmQ} zvd14-l=;lo-+5Y6BsOa7V}wIIq$x(zBK>IZ7H>_3854I+7tUB#Ov621^!QRxN@-Tx z>z5AZHy-&YrV=Qf9Y1v5IJ+xIt`-g*?Hp+}ybM7b)w?OvXm_VaHO1J~ALrV=5SPpi z(Wp3@KDe>0%4IF+TsSRxRG4Ib&9a+uRH6iuoyJz&L;u;!f=N(+M+(OhACg)xTQ*zE zM5(qJA1SfX^)(@XSqdE4D$H2iFqdMufw383RO(yx&&a2O7eN$3lSmTO0$7^RpF z2sn;df2*V$QLfXqPE0vpvIhv%JeH^+gpYLd{F#|qI%C+QExleg40HH(+@2e&ctm@$ zd#9X($h^HPrZd{&E$&d0hkOvCl#FQAG1%6vvgl9f)NG34hQ*$4jl`FW2^AEL77M-R zrZ@wStk0|Q$JWSS)xju%hcJ7he6fnA$mR6?|sJ`^4$g{+J& zoa_e2kV);H@2BG?BrV$eQln{ensMU!yV&E2^dfGl`#-bZ27hPO;G^b&+6Wdg;f}kd zkWwd2(+8W5&Yc9f265BYlqZPZrlzptBe_1T;;r~ittm6Ic{=QiT(BZ>?ymzu_9H1N zooIZ=`X$Vx*k};zs1h2t8+)*+2IImVIyT7{w(@IM?UlrohFd<90ax~phkKKK>%2pR ze9>hn^@Ls~8DwcA7`5VaX6}xrl-e8H5axrlMwe@C8Ah?;$ZzVgPx%}M!=hJw!usAx zG0BXbvPh8iO)Hcm77{_G=Ox%(Zfx~gr_?#5f2?8<8G>PiC^jk6ZL`dOah-%)0&2lW8mfjVZDmWRWdY=1MM%1<43bA%5 zU&?Cl;nbQCbHLa+JkypxPjq3~Uh8}sMo)asSeO*en!eBdG%~xJ{u5HsG913RI55*y zVKK@~O-GUapiy$tbyGp$edkEkU{iuw0nF{7QIGudn# zQW_UAMOtiF?18s_lSLkhPP=N1y`0z0dw2}Sk-Y3vZQV+^y+Mp#pBBYWbknYSm;+Aw zCqcXX&*6_zXZKv`(X8oli4?cAvEK{#mVR!@VL9iz0=C1n*Xp^akMeWRE;;Du4KA0F zox6T%g1O2`rUV@BR4o!FA9jtgH+hCT`jia<$?0=eci9;_8+a3%g;iCjedq*MdPlOS zyl=V%X`w9m9t6F2kMLqqKl-4dWij@J)&4MtbpPb|g@mKB;wcqxw9E*lcwGfJmfx|; z`or;t_$w3SAVqg|3J)a62)>fsMUdl4LJJ1Z<{+>mPU~baBn1M8j@&e1DE1(U@(6+R57Rdg7GosyvYNjVJ{5lCurJA*) zTZY2%XZvc7{s|iae=PNFX-Gg8U%{pTRQ}LB38W@G*Y!cDyhyDLd|k9N5>tCV@!$j% z?!)XyNw=H-$47n|8(E^~wN^4Ep{g1V6g{c=w7>_C4|^5dw|;=-3%MK#<(%L#+l(fW zHt@7~JsZ;K8;tu8E=1w}cdc6FbS4{j&~on(X%GD$dt;zs23$si`u3miuibZew@mij zQe6Q0+cyGUYVndlw_~3SO#hZB;N>U5YqYvH!E?xep5tjC?f-vn@+KA@-J~trX}F}b zA@s>P`Sl;B9xwn-_+`A%>oKJd9DC27DTW$6f)n4aSk7b<4q7Jr^U;LouS4=pKdx&+ zundLu`~2?qZLFGajxkaB^1QYtpPYmL`*sr!=-Wl3(l(sq`62WL9hJtKuh&)CMSkLU zYE{;{GA4U`XH_^?Y_aAf42@$EY~}XLdZ57uSvft}xcyw?KmW0oNL@(&n*;wRZK|b5 zt*Hm2SMs2wNi(q*`~ zmHYFFS7wYb8@kl@=vA?S7F8NJog zkn7$*-6I zihXrXXe-*bg6~TJH#qXp8Ph`T&SdHS+bIuc_!(GAdJ>rX&=gxh1`=12t3CEGQlPXa`aIGdkS6KcaAM{gASS&ZU z1Iedp{kO+?A)A_#b`UG9Rn5aMRv)D$KV`vXE|xWMvURrWYX5!Py1N&P+S14z9kYIe zVmz+N*e)*#1P8M}>T&}|sf{95k|8VSJ~({OqNq| zBfj1R`C5Od45%5ueMV2RaMuSS3JdJn$>`RN-?w)Tfe$fBDy-{WSG5&=T`5qgKV6fy zqO(RJteB^q$dSExDj(#95I?om_ef`%SZeQ6DMKuGpCc!+AFKF zNQdh)`GL!)->dc~mt7ud2)+G!LYL|v1Js@XXseMwpE2LeoFDR(TKrQv;JblP~vu}ik7|&bXQiD4&vcPb?P2A*% zvLP4$yzx*;koNDJX8x@|zZ;J$C%<`qaW(aS>CEYmJ(Way{|_&oC)TIF^LrrwOZhrc zzAfx20KV@Ax6H*}@~3pZp%ID<{4JdVP_{>YfBxotGm4=9Z!QKF$&&53{;uG5DzD(C z1!r_th0K4%WkJC1!Oh87|O*=C9Sr%DPDj0PyO3S<4Xg|k*E4IBTn_?$*kK=60-heL9spQa}oOZv;{81N8czh z77N{lgE_Ah5)p?9bh8!8KmAE!Pi&zbdUO5LPW69o4%Xw(9{k=MYPp=P2GNj;{Z&ES zBzYk4JfV{2OKthlBhIszALeNF`S5vczJ;Iu`tn_%_Lrl^6k^^%;z?zB#G1IOK~VxbZ20%B{OV zb4Jx+R+Q@w*!sa3gGo#sc0Y4_lZ+2~+4VJ#I>YQVckcO#Gi4DwCBwk~+0##%x8J}#rQG+Zl3k}-l=~qcygUOO zb%iMK>y59G*AJqX;IhQ+43?SX#)z>f^xRUb)oaXTv8rl>cK+bqNcCAzNZ>7&64D5LM zY@qJci+abNBtc6QGPdGX56yw2thANeWTiE>ssz71MGA&6=v9PR0UQ1L+sHwLx97tlU{7o3lLrhB0^097?+5Kyc(_w$eIU5ntGGHpXeOjeTqUi;O+~i?MsmeR= z5+2&QiI}xL!GY!8tmnbQKF4??MhGwcD*WCj(0M1jR6qRC9U7_ zU#nFTVxMESW*ZIZVXgk8HXv!k`{ZH4LRaeOBf=o9h||gO$qBc<*XmZ@y_ZlKGj@^O zB92D3MvxdHyRED~LY5?J-K?@@v8;k>`>DLRqwTr!NuqWH0KODkMSmIzo|?Q#Yl;Sv zx;rA7 ze0@q^Jq~QDNLMV9KpnQTGLV&C(mJ8n{5i?6$F<~dysp8BO;>tTi@fOMvbROO&xxFv z{#uUyzujAXd-QObvEg&-@dC}C*U-wJ9-X1vlvGbW5+5Co%Vy{+& ze0c3-C0)-w^PWf=d6xO!ucsX3HfZLR=Mh@xh@*P(Og4;;9dHfwHeQq&!7GsAb9fJ{FXkg|bi_vj{g`>g_Z_D`X%V5x7xCeH$r7H`HnhXk z);y)xoF4yshF5ztD9#oD6Mm$L1$pD$+NIBZK@_aRd}0o(&6mG2mBinS9mtd+j3wat zaDD1sj{u(h7;Z?)bzOS|{zGUL=tp5+R6y&^@lN$Y2sNqlCtzVKY|l34YGlj$I#;e` zD{Oelj8M?q(2-~Om3OuAt%n9)1&$%_|8jNNCorcUgBRmSCi-;vYF3as&ax}+M9Vw! zR^6Fus+dCXUCtP@r7QNnhjJ(9rw7E{T7Hbym4w}-?>w7RS_%B|%N|dn9AOy4j4+<{ zH$56^dv)s=Hf_)pn)+*~U@iC!NuyL)>CsTa*gfs~3@#o4JMD54<3u_UNq<$mlzPO< zC6ZEnLb8IzRZrqS=H#(%iMj^Yr2!$w#)CM6Ho=-iP;)~&7RZq%pf=#Cb(pTrTz^UC zX*ZM?>d}#eN*cRAeEyQ53(z;%HW$e$i4RTebj0&UH`xjIB}r+8VvOtE3N1;2_6ux; zs7#}0yYn9DAZTxT@D1qCzwG(nj!NvvGMO^olsbcz-0jt{A+=?FkO%3uu}X`fds}^qAb1V@5Bf3(IKPakZkKPaA4~rtLq= z`1E_g*R-{&uUlzO3=|ng^b6S^>yi@M$ws)UD+GDKZ`4`@{D=sgMBw zA=lq!QXgNx%L8&)%~=b}oj4ip3iOd~SMgh*uZs=}ymBseXg^h53rmhe~5JYmEHfTsa6V6l> zNt4w38urT5zmBZV_)_nansOrK(7_YKRS2moc?+G)e#FU$@RTIY*HEXqmy#UbV7%#I zp5SXvOnLegg?~G?7o&U0pQPnp^JgL#57&H>R_k9dLT?0eExxYju7FzM1bm%p9mC$is-1kEBIcyZ!l~{fQs+{nV<= zC1Zf*ZGGvBM47$9+7i5SB>vch)^cSYqpNM|YlFEXqN`-C9?N9QDJ}4qU~j~@UJbCz zl4DwKaCP6r@AqvFFDDYi1va!uvQgwwtcPZ5U7}cg`GRut+RA$}k=>tQV=$Ff0r8~D z_KJY;pzVtK5eW-_o2XfR+BmJu!2XUM_y=D&eUb4Sju`6eR9vsQNz1AnSmnvBpJMKC z8NC>}%A$7h?U@6v{ibiD(xM6SXnIQ(qFL6#Gc2{`Z_=Ade#lU?{!oYItP!Oh-mpd3H!zqf4n=_vH4P&VotllrqO9m(;L`2*W(VLREV%mMSX(dJcZ2nRsdG#9R z(!q0v1kuxm2)AGJPY$O1=IATA(K1h`|7i>X=`H$1Vu{C$u%BFm{4&lofkG`_A|{ss zjqvcP{OIC8GzDOcD$|6lUOo%%xFm7gzcwKM$8^gt87~P%wVcg|fM*xw{g<8h2VX%w zgIEF9Sdsas6D6MSezoLO4m@+tVmx1XHoJn4?mq}kNjGNwU_ttitwGfL#c$*#_?J&l z(gVarGXCW}_D^RPko*an{_kCU!A9M8QPGzlDiP+!vS}D0W4P!w#~qgQ3pVfm%lfwC zg(|vI-9r(o#5_e66AS|8DyKK*khJh{Yl<-TiN*xyzre!8OLW6%ZEDPxuT7v0V`Tw@OA&af)Mp}KD(5C2LpaK`))ZaOGP`|DzEuAnKdoWx9Qz_?xH>`ktEjo z!xf=O_J3ibXnP2HsWZAg3G27-!4G%C(ZaoLVs8r!ex04pOe6RsA~5~&FB7;EK@g+*KC_?9i2{-uHnDx>gBS5jrna#7PKtJg zF5#}C$|ylvrJosh2Qy?sLc+si2Pi0VZG2f#`_#N9G`c<9er?Qv+k)NqDp#1R)!?&4 zS}4#=sC_DGaL;XR{t#2CaBJ#Gp1otk3L3itT%c*)2U)- z{-OTuDP`xTS#_@Ix1}8Fr^$mRVNJECfAt49)YcWE9JE zUVA08G@GlU$zcgM?UCG_@1oEY40km2SXNC%n4{1^RhkPU4Zf9W*?LIdtF4zeh_>lt zKN6+J!1rcmn2^m+Jf_U{P-k^SHq?#*Gc!~v*Wu&)Cm0R%t$!`W&148Gzs|ghC~iKDgF#rg?L_b>dn>8|BT*%> zNff)+$g=Gy!Oi&aFbcaU)G@0sqY0E!Ldb{T z3PmX+8)FIwdb?fUQYlfF5iL>2hc6SQN|Kix`t{?K8Iv``TPj=@?@#c3b?kRy zgZ>dh`^oi}j=WHNx%DKmyM8Q+3rInHYblG~)V#)9InW_iOY187C^maq?a2Rd{zsgv zk9B?S6l)u{v8Y6_N3$ZE$qw+>PP=rpfcJRpYYD<~FwU-NDQFrH5D=|3+7mhXq!(kB z-F`JbeOr(^A)>%PGL(8&P4R9ACmdYLMiiv5PHaGgKdB@M(~kiGHmItyvht&uMo&E- z9A*v!dDgbr9-ixQuzrCm;4W)XQi2IUKj$u>Wl~vOvXK3wsTxPUE^0HtI4=s>T!uDb zQpLTF`MN{+5ZgXRVBTMF`CM_hLiN}Y^}_v?u8oJ9`ZVcMxwy}gmeHB`utQ0_s{nF z2;&$fJYvisE6u+6n&l=ExTMr>0cZvBSwSu|%_R3X#8_2tcDvp_gRG)ZOoWVOLhC0VEw;f)#Qbt4u&zEK7E`^DbW}+XKi)jDYP}8L18Uo%cX5n-Zg1P0L`el1`l@c*(fhF0qIZ zIXGX-M(O?~yzOl231(3&10lj_%0PSI;-;&?NM$loq(f{(F}=ao-hi${)Nc3ejfBvH zbOF4?3QPq#o#7mmX0yDj_xG&JGddh>_fj;L&t`vJ|&-6vC zjHPJn?DrdA){pHseiB;{Tl7dC`*CIE-3Hm$a&VIm9)xhE02UBIm{C^12$--TbNKTD z(3B>75!kumb#;PC;S@;wd7%A`!Gm-2teQ;HH@$U@0O;E6Gi%b5Hh^&#>y_)CIQ6~b zx9Tlu3Mgs*Oa1+}ypSr(s_By6!(DF?UMJdwj2Fblb(xp$k>hNGuj(CXLOTGSXnuM5 ze4-v&zMgW2OBLTsnNH)h?$eIw>BsP_PtYijZ^&C&`v{C@C^RamdgXx+dRCv~ZuHXn2j@3*(~l?b8P~qatP3jumFWY~Umg99;5`|d^*zAXE$nU5FXQ4Lp5xj5 zDU7!jzL+#$`&wx;+(Qbp`SsDvXdF-a{@f+$`gupSx%wNuL`U?8ewpv8OZ30yJ!0Gf zS#;bGG`bCI@5nCC3_`Htm5C}-q<|)|KwJMu#(r)N!v&F#z_{5Dbz^VHYQqW$%W4qi z%AbwX{jjP1Fveq*p*5hny|#71I-a*O?s*2V(SIxu$ zvQ3_2CiQjbiaN{kWxN7PWdbU;)pxJE;ZFs6#ieTqkwSep=}le8dLWm?UnX?!3?2f5=Ah0itrrzpE!*3jAC>qo>;q zUxae_X2Q`oFz!@uIY`>&j#%x5M;E$R+swg;%HSvZ`ZW0|%WGQ~ zqk;P)2P2r|l}j?D^t#g&z3#T^tee?W*9h*Qtv4OXN?Q*G_MRPX+5Fes z-t^tJVGvFRsL3gcg}8GGX4>LNoBGGIk6~~Qcsn+Vm8{TOK8tj%9VHW z56){y_vu7l8=l#3G#n?lH-4~$h=76Jet7$nr2ifk|J3KBhChbD-NbWC5NLKbC+mOH}OKTK;*JP*H<$# zh5}(#F8Q+NZZA{l#f-yB%?oO*yTy+w>Ax^Ycog)Ki(&3O(pI19UR+aU=wEv!+6*VN zvpzjbU3sUU;jypD^J%TW;~3zo6l9WcZ2+w)ahzSwpLK}KzlzX zx&65|c{d9c`Km}#2I94x_w0?q?sH$s8X)RX+{=XKPw|sf`#QV&VSS@;NFy#xoG;wm z1iDh!W~XLM9y+^RQmzosWvp#z2EIlQNhS(9*C68wH&3GlzP9~))idvIXIGOI!Ag|V zPjLqWd!jeqPEyU|PngO3SIj^J)%Po8;(ZG^-Yv-T;O&62RO~{5xjRiMAey(8dgG<&(fVo)_-xd?47r3i+naX&<<@VExLy8Zw5m zN!g%*fW5t?3!GgfQV#^joYaz6wnHul3;o0ScMt+tjx?K;SatKE)ZE*((Nrpz4j_zG z7>6f@OyF!Khu}!Za2vJ^eVfl#U19=o zJ0p?2t2{}mgrvK#wXRrZd?ipPIK*SamwBSjvTI5eDO;l_vO==&z8G+G9!#H_(c(sb z(=U_fl&a3}$~QPb%3b|$EWCGiQZr+_0(=i&-c;`y7+UGaH6#xEO13O`sV=R0F=tsyeT|TApt=baViBDT7a7`QS$bvk0YCQrW_{;9Cn~L)C*QOcA3Ct2Q5M;~l zFOR#5bc%=hc3bS8B|j*4H|9GP4iV?sNNL_5+Jn#2rMtHs*_Z;$vGw{*)>pJIsSlh0 z6kGkQQC;r5=CbMN&*wkBH{3m)yv%QG9+%5xJXk-bPJpcNEs(0@mG&M;>)5t4JQogf z-WN4bMmQ|C&g6`Yzr5`Y=WfTlFs7MWlmm?&l<0;lnT08*7yW$v` z24*Y%JE7utW{dMzIDY?xY=XpcYk!+x&_qy6u-LMiG~s30YuGXRaWVf(sr)gJVQHvSF|n@3;+#k@!N%boj!QHr1hVg4-3Z^4S60@h7xkXuS(0aziQg9I^543DtA!xz_M3Bcw@@0v;YQRncuorF!;vP& zrF?}dsLp4#A=~~yw8&BV1X)2c7vaEk} zbVP~1SxJdhE$75jR*=Bm>L2Sln`)J$+P#u3lTMlC@~hrAQ~uOMn*Lz>Q(ME`I?3h} zDB&9f8|_MQA7`T{sbvNSZ9y=${`<+|wmu^TOAQv&FB7Fs7Ut_oJmmsPY`=CeMQ~#$ zw}<&gFMQFFWQ+vHxHVbzHSPE8H*>HKH{M#`zACe`?>_JI0q!?9{AKOmrGJbbV6 z9obVLsB&hzX6|MbRR6?ET`nu4yG7t(Acm(WD&*aQeRU_i^*MR8C(S=3C<`8aVv4@) zqR9)s#&YON)+$e&1VR&nyPxb6J)oCgehO)yu^66yGED44dGHJw`L0QDn(~m`Do zUq^6U-D|R&k-f-8zQ`#4pIo9uP~&6+n;+=Br7kpUn&n^QvWyQps){SM^V}95wZDxL z`q$5N3WaO!j>InwAi!P17}&$yU|dfUE2qx3#3WdTkuh|wbWlqCT)ni9dh)4r{OkK; zjKQ19{KHM)=Pk=akL8L{(9vye_m;xcjU1oc81WI0;PNYsP*t?{n*B@G{F0dnq0)d; zp@iviZtu2|o$}*A+f*e3GK1GKu@&VSFr??d0aod9Z^`jo=kf&Nb!wj;HoyzIs;Bs3 zR&-m~W-7$2DcZ|@Fg-vn8N{P;c`eqXL&lv0iWZOAz|87cLk^AO1M>BXP*JIiBa%T9 zW}8M4?NC+4=%gQ7hsCV<=$uXHYwPCei`-DfYPuxNq&|`B2_UTbNq0*B23*M{s-B%a zAik~mASrZ8(XuggH|Jlx`s^Mg-)n-;Y-1$rxu$CvukY?|5bh3-Yl?xy)>U@hrCe>y zgatp;BUGP#_g5wJ!d&}Uu4RzXpz~@yJDfqWToKOf)@xGLxcm43<*fcpjVp+{iSyx{ z@!H@%kY4(A=(Z)gVQ9ODrzbUFcOj;e&r&gJxa2U;NS=LlVWcriq~Q6yi0Z^-m~%d| z!9-CpmW`|Yj;GG2yX?##uipi7#DN%%#ov*57Q-I;(wmJ~;n**J0*15d&SYJmY>kaZ z!EaY-opT?&eIM}3j9R98*bU|q#(=zP4arlBpEuJtq--nLx|s}mc%yX4xEkH~>E%*y z=fP+Pz2TGw`rpe%uNyv;d%~!d2#WL(?4pKe2dF0|$b98u6f0AvCFvZ5Y_D#q|3nTU z3K+~^jAn7_p>|UHVl^msK6A)y{fy7Eqo5wbglbQ*Z3hC?gL^;{2XdyK>fP}NpoLDy z$==Gjt$uK+Byfg8|DhygIfMg@m~H|RMkD{$4Mt{Y)8jiVnrZyIO(S$59;mLWPfL<; zOv-W?jWdez6Us=hwdx&B6l%((2}5T|uw@_x&MTRYs@Q)qyJ5opx;J$?b`qHyquf5K z9K_>nRZ+PKG9lYG%8%38?_C59l2Hg@_Oxb)hV0PHtgK3<230xFf^J0#JDLQA9|4t@ zryJ$@e9jMep+HccJ(!aFuskS)R#4B&ma{droD!Xi zSLT)}1>8otB}aj3Q9C;`TJ~cUEanrUM=B@}PHnN_3Wf(BnuAIW?2DlX00PviW>tu< z?f{9Il9_erth<8s5xeU^wiD|{U0MwEKp+_;;jtg_JoxU(SlTa{o){pO&h96tRjB#! zWCM&_2UDy8ZfbXm=ulG}@Ix!&LMnwP$?WB?-B0xWOFeeFK?o^W7Wr3uU6iZo&=$zs zvGg8EJ*h2zgi1gz4Qz|34gv$BS?uZ=?>_zF1#NRT{Ce-QJ!_1N=Ps{i(rjJAo?~`@ z26Gpob!aVC&QQ8)duJrb`3dZ1`Iv zWyYY`!{Z%u>(P=##r7}3cOKuZRtx^C*D&w399p7)E?v+ln)*>$Zo{>ll9t zcYw{zW>zoO>697iqilhaNSd|-fFu^LmfvKOy;5aaVC%Paku{)QsQH{4*6a4*gZNCs zE0vtz$*>`h{Vg?OC}W4ZQvvU~<7=PfV*r*N=6@jYe_E_tngamG3iEa{SW!77Tvb$T zL+pL408||dz^jp6z|hPwYxTF8$g!KKSZ{v~V3$XlganuTy%!RAWTg}NESFXXvTdj# z4b3;+XI|1G$RiKAZ(1C#08o|7{^Zr>^deonzHq-S10Lnd`@RKCDU{OQCLU`K;ci<= ze9(P(nf_PVSlN=nM{qy4oZ&1_lHsuChg^u5VKz@2=gGBzgA^9C*KFdgB( zx2({YCZR*K9tVOtR7rJL00E&Q7xjy9HQ3KGLF^Ld37ai|oF0*`T*4>J@F}n=*eW0{ zD-CjoB`m96jFWyMDMX zb`eJUQaF#lsUT5V9!jaQ9gj_14zNeNhMdqh*L$JzNL2&X2BlmmQeAe ztKSWwNo5=mxzu&~qIc`Hqy28es>h|X;DgGt(8Re37NB(CA8}kj7LtV>i>@Wg2f&-> z2k7n2h#>^BSG#FV-P(9Ll>8V|fSErXOMBHG#9=sp8wB#n)n&nDVLV!f^X?ORE_*=F}fAgWj zQmk9j0Kxx7LJASwMibW7bo^%6Sc5x62MuJkjr6mb@R~5SR_@=YxDi)z;YE9=`jw4@qIml$MAIj9X z4EuKC4-sfQ7jq^A62!V#H^$2K)@>6j!~@I(TXDaSwM zzEoJK?Ijn_fJuky8X?#ldtPSJwz!G7%(9E}FL{H%7V#efn)V7pxVJpdkK*BQ5g>iX z?pr|oPQim$`C2q4i-OFQt=Xd4=Qp1h`gP(0Y@8W%5<8y>qW81t66hx@Cx9eIzPo@> zCYVZX0u(BzsaZdasCVkh$}1lP?J^IAX6D6^6{BZBuvq!Qp0L~kZ-&| zij5;fSM|*3?6`kj>ovY9zTqm~ZPrcO>WB9~{KNj0=vh{kb&_q2*u;}*=c$S6kp^@Z z_um`ze<~_ionNCZ7=e^h-E{JH9u_Zy=@5UQNkGc`zjl%T%XTxFF;FCBY<6o3h{_jc zavd*Dd^Ynt6}$P{SZ2ojk1v9}pPaY|*e{^vu_%G#-B@g$hU%s0n{pe(Dhcyc=?Q(R z-Q^l^JTKR7cQs4FV`s{BpsabCqcQzxYl`w1NpqiB{C`xAbH}S?k%P))(6Ni#f7t{F z?6&VZJyPlCpIV0onO*3n}dep6)r{M&fe+3M-fZ|4tw*gf#nmm zewn_S+Pg@HD63g)s*636R4+pgnq)!=(A47jgxRdw)+dtf*2h2e{nv*Dyv$Zsc0l&R zHR1n;$p~BWx}|$h4?vRHK@Yc6CEjVhC3_VagccM}$`a6tv4U6ORiDNg>xmAI-Z+-% zbP3<-tS`?RpB(P>+<0dciMi&)lgfb^0-IU{-3T{bZ+KO1>NT>8zpmAsrJp zw^oXr)7uH=Va8k0a*FD2{$v_hLmjQ7bTnQy^FI1!7XJMCewDZssNpTIlCowqiXsQs zz@P#KG!Xz!UfHJ2V7k_7Dv;MH0>S91gT~5eQ8W@Ln5bSj!FG?){JLune8D-<3(o@ZAfrJ7ygh#>t_TMBKrwoW}I^REYyE8ku5-DY2}1 zpln$?y0n`qLp_MY;QKyXYRy>F69}{QS|4s5sBuR>J*GNd{mUp@hp|@w^RtUVgz_ZFI?W}A z_ghdgvoh`S!tS!}sr1Xl$`X%CX%tM%ARb zre<842!pe--y%hPkc!6=@jLhd)IjWH1ikOt`#9NcUyy%OYbUrI-*GSvoWU zS%FbkXYc7f%r?Osjz!EEw&B79o8}w8h{a03B(<`5$rlf45ac5yG4cei`h4nh8z^sh zA~h*E@q~k#bJy|rxF4$CcSiE>feEOWMK&08d+5;WY`GCWUQ$~X;8abeFF|2W1UakeWZiUM0a_WiD#k(iqL~Fc@=7J=EV5o zYGMB7-4@l^yp|~H`-v&@@aH&iYM0*@yGp2+8H(?Iwa%Q8mk~}s-=pFUZB`5H^VD^y zr|XO6pd2>nEk?*h073JX<`+}Si(#q5#Q4_BB;B=q2c0E=2=X7mUVCCLKB!14dj$f- z`kZMH%jXhUjQsDlnnk*!;mseQ{WnDk4Rm^aV!Bew0 z2Uy9TSk=?4QI@JxzG!ru;_+W2*{k7yNkOE9sTzlwyo}9+?{5?KZkI~`SL*v6VW<4Yv29a(XcnZRl8|Fgm+dR1M+CIa=9W9ZYP>p8MH|^Zk2MFF_|1w zMEqyp7-hGiD)vyX5YmDYeB`NkHmPj%Bd6Gwozp@AH&zt*81(&xgx}7F2cwAy#VA1b zmzf)TN0EIbR#2b_!N$8#w;OJ52#u*WEzvG0=Ne7!$=A%0E**^$cq;}?E|Rs7-`e>2 z%Ag>nr-O(o`2uyFOoddaq1VfcZ6{CNB&pEUZtOKmr$ms-!|wtOIm@PX6cl}rgM-74 z@AhV81(K{%EQliEi4LOwU|<55%McCmTlM~&$!7fWVTal9YFLOgAMTDt6eY6h(nGQI zs&{;M_@K&~^jGAA>gFVy42yT&14S(S$K24eL<#6k$zqXCv+jpH@z2+VT^B(%GTenD zoo1Ryo_reHRz}7ma~`PM^=@1XkqyvXO3Tg+OO}Rcc~Lrm*%tzDx6NfA_?yk$vKB`k zt8jHcl!~Xpqc(P)trNMk1*^v&Ip0ZY$K1MD=Yx0LMe*{XqcK-27Yf#8tOeacihQC2 zHDZ>C03Oq+pv}a<&rQockgE98o|@ta>S~Lk^Tu7*@2E?{UT&3m({QQOa$z=pYv-I! z8LMVh6725B>F)@F;T96d8@z_EJU4ahwmzM3pWr|=kh?jZ!PVZCr0!0{+W}XwKME@> zlUrZqI0xblr@2MdA%&GC_r z+&FPhr^mZ*bnY)*{El>14k%^@!hN=7BKVR;2N$wwX)%^`#29ys-eWvgm!U%B^GOXMs%qG-_t}CJG-9v$ z;-X+X!Yc78>-FVt(0hl>N7G;K9!)dSBRc(1``j~g<)Kr|D4sJp(L5hoQ&Snp<`^iKD$WY%J=<>14^VxF(k}JY?;XnK7?ZQ*tH8&)9(kvRb--&lM*s zYV-qD?QY=f$9pXsFHZ_KT6PLDDHf28h@To+%CQ$6rH%X6|u$jCH#i(=Z=hTQR z)v*5JqrI&PiJN$FSB#n;JZ(wdoM~u44Hf5Vc?tG`>Jb3i7LWR7I~(3E7jPpllN?M- z)Tw1UA&MkX}OdDtRwG;8t5ice4k*!F<*Zb>^hg;U184V3zh05m7=3$5IMp^T~>{<=!s$* zwO)z2ZZAPN`Wi~Mc0j^>Advwf;nf6k`x^tP0$OonG>TH=S==!=i*{ zw?}Ap_z?C|sDG^an!;N&?nx;F29)cgD8Gjedz>7&jQi1Zm{#VmKi%D!>b5a%R#Io` z`3L3yqq70l?=f|w{K#}R?5e&gny-kZ$EL;m0uCDeA-i4}C<6Dj?>L8Fj9wf?kWZ9F znObv_NMl}U%MM(6_newNs51qd`P$6;NIz~6vp-KWr31f&R!3gxt)py~8(c$-Bd2CYO4V6w2J(^8N4Stb( zb_s4aF}9=dS+Y3jOt7`Z!gTbTw77xqL5@*Kb6(z45L-i$J`X?=jN_L|0=zwJzsQUK z{#c~!dh)59N3v8RGG6y}Lk0)?O_dk;Su8&`i(YiI*-x2K_P(n>02eKgEODLS$!T!7 zlPLbm3p>Qb{EH4RJCNO#urtb4f#>RodB4hvJ1p^`^67PB?^pW83zI{KyDWIgp-&STWv(2 zc+)u5Z+&bj*_GjoR`-fa=XxyQyEm+`1BRXS0{zlBOIeX>O0LA{31|;dNzeH}m_Clr zKu_6+!S&EUE{@X}p6vvlT@?+gi|smtRT{(~JfTLsuKQO2L9Lav)##^yiDM?u`eqCr zo2Auz+WrY#fh^({*u=Lfl`q#xI}D_b+bfbZb{oI+-j9eNA3pAQB1IZyGT9xO4%Giw zWCvC}(ndria-HZTd??)=SvlQ`+=|rgd#~MAeuf&*n=X7#GhPkNm}gFF4yy9<_1h~p zl0VErLS)Cxq-|RXp5F8FQM%GSyeBe^CrF-{fg%XW=zJ{#|01iIACtD|GgY^0C+KBH zIRVg9<#^WX;B@I_IbkImPuML!8lN=;+B^R~KaP;Ri4^-7{&E9YJbPhE>-yyNu33k|!gpxeGWKE5SGghO#q-^g*<=$oPCz;${s1Ut{ zi0?4wvBh+Ebwm*$r1FrN{3-(qb)Zop8-74{t75@|bp#k{$G<^nahJ@5$VSYs;75eV zQjeDv@Z2*KF#iy3(v$xNYW9!=k8GwE?q-%ozE;(q_!K9*$?0QhNW^Mi#wd>$ve_dh zia>azyX1I9D^EMhO+Q7Wn0~F2#mF;N6dDOFUj=Yg0AEwzVXe*RsMFTo%CHPMr_rM6 zV`=MT2B*%GS_A8Jith@-cY-&Z<^gb}*kC_C_VwmV;O5i?0=3iIfqRYJZ#ta`DY+lW zc98Oo;#^-0HG6Cw`cFVhS~EuHrxISTP#%|ScUn0f4>szie#)|7p|!vc+BUE}sWL=v`X2A;uR}!YHTD}g>S*(CGDm5dzF3Q^jc&$QUOzZm*QCsSYSAeq zl}|X*;=Wam2tNFB;!V+(x<7Fbc4?gm)i7+DKSC^CsOj$;)f?K`hX{<$-dOI>R6~OSLQ7xS1(v8qhEW)m zE&-P=>sp3Px%hv6N|6r?joNKK@P<=l3NQQp1wP5WHYiT1K~-hrXVWM29F#bUWuUI- zxmI(BQ9e77?MHqeKn@DPt4X`wR?BX(GDA6y*G3&N?;L4_HT~WWDA&-yOQ~aW+Ch^F zVqO7s#y}x>sFFR0ZrZcD<(tvo)ShVivLi46Lc0Qua0GaExnw=w64oR4v)!%|u#W*J zny2(W(MPl^xFJ$3>|y6&H(n<&=yku*bRMHOYhy|0-AQ8CW7oV>H&^^@fO2FxvNop5 zb8~u)me_C+bC@6cR_!4Kk#MUhadgJXWC&mreZWK=G=ly$AN>1kmNjFLv1%F3rPtk; zTjRI`SJKaHDNpR?_hfa(c}K_?Q?IlrFKqhV5drkYftPXPa{!3p;IC}^Uf6lOG=YcP zbK}Ejjr|lHP*Q4V_`q%?L%ian`-(5-3R4R>7ANw9V~!WQHr-IBJgRk_-+t^0-n!JA z-j^;5V`t|_Rp+J58eR{mm5S+eXTgQuLDd{&EAYfz0Sz+sL(SfkgGt~Q5tdTE=Ej{X z0h$CmLPPldiZYnGyQqQF5{ZWyk~9~;9TTRw8Swrxzs19(CJHr>lRB*x@_x^8;PwiwoUo zK%nZ@vvJaW039G8Ld*tCU0}jlpMH5bHRM;gV{hlyV_1mwP6f0s1prCjDKkA)UV8p! zcDV2=fKts~7Dc@o4%EtPa@cDdY*}@erG(ABp2}LoxbrUT#BL-%96dQte;?DEK6?Oi z@+hqbqh-t5&!&}6#MuazQ&Z6C7-WtyG8471{`lhggE{6Wd%!MMQV*81ln(^RU1_xO zeEAR6gM?hc(g0;kKMl#9>>3%XGW2@|c(AbF(V!%!nw+!l+!QnWW;=T6Jc^oM8NWLK zj)5c)53#cQ7L>=N$_HgMBe#RfDt^TUDrq*Zwu1)@wX*aw3w)ZYF{TPl46c}PbKAZ3 zNucgdmY^Oju1>j8j1eLtJUqkiZEEw;U4+pM*_U>4+6s^~_RWAevr84F6tHe&8YCv6 z!noI(v9gQTGaEn^^mrcghd=nEaaZq|fyWp3$2QFiNu+xTJHI0de&z50Wr2*AQ|zwQ zP+_|5mTVUQ`^OCuiCh9fuW3RBWA6C$6YDocMv4By`jcs}V5^wBtqhl}fqj1mjf`zR z%aMmlR?|n~Qer^yrkk9r8VP9xRONhx@JUIMrNic=g2SR_1Gt~|QpTsn#AN3N@IeJ* zqRcIGRIepd33=rM)vlV{Zt_gP9ECN}+7q6d@=@aOU~}W*8Bh+7i!eq$ymK8tR(E=~ zbGuL@t8&NI4cjbiG@09CtcG~oLSB1n4R$RY;0v&q66n5pIiNWy0>DdyEa{s<64Ug{ z;o*sKFJ1(WXelTzvjoQ|x=2(p{Yu&afOoviV3K%RCZI(_utTIe@j6(V`IA=+ypTm| zX@#m+kQ90NSd>^$`|7Mr)k&P4E~p^@EzL}62}6h@uT%0|ct@7Pa6Ot`YL8==?qAGaC(@6}XACxXnpRqp(7 z_@YU<)m<-J;RPwBP`?p@oSX`JZ~ezQ_K~|4Nw%++G%XFJv2*&TC07q*xUfOiU9I}> zHfibJ`0K|+-a=;h40tQ&^vx7VP7b3J?Jh3)<^?QP4DTr!4S$h3PHB1kqms}5Lr06+ z`T#Y*?($6I^W1v$)%1^`D0DLgQu)&!ya3YuI-aEb%IPzYix{i1e@_b%`+~AhRZ~!d zAY!!ulwLd%Y)bOcbT=>KE*fZwqvJe8y|#)s`5oHWaJIMCOz($8oej?zH8`@xF{{O& zogQKBNZxrJkuxcEf*?+ddP*d!J3iX}gW=$##2RqPgMrLAnXK&dE(C2h_$mBHryjw_}MJr2HomXu(( z`E?k73dejuWKR8?sJA$1D!BuOz2#qOWo9QS>Ue(`Q2(0Dp`~S1?vFVpdyN56gbMU%a_)fVOsNE}+>x^GTpT08P{W#$S%mw1`OM-6w~ zrKZNdRSB4)+7b(X1biMHI(RSv+V^p8v!fLYZDEDKpQrD=8Jg0I1i5gcah>dSO19*B z2{m*K+~1F%OGPur=g}2-8NVOnc?@SnMB!gI$bvoiCu;xxBma35_Kx;v-xOqvI0}gP z>lF);&NMm8>BMocNpMYy=((>u8R1%#`}Fr&Lu39>#3@Qx){`B$Evxd zRsZ+fa%b<_Konb_nC;ffd&6D-c|Riv+_3%A4}!);y!VRzRgM_WL-1)%9ENSc@Icp3 z9T$Z?*5dcR&d+Bl^E?BjSRbeZ$7|slD-N&0so$@{`Vlo4eGCGNcePV| zEerwY?PxNLITfPw0uDmPn*Ml-ptB2^Hb9Du;6ir|Q|4P898`R^F-H_#^bRjUJ1N6M zuvG^-$ivA%bo2{Ak)=4Bz^6UbpuOW~T+jfU(LXKg6fh=xPbE$R5YW-Dwz`++fUGZ#Ix5QYD?LjFF%O&bU!Jvq7WQfBSI|=Gc&zNVQOkO+sGk60PZxe* z5JZoY4*^tCMOx1s8pj>Ab?brSo%8}lo3UJChvXxWW)wjR%7Bt-EKTe&E6|#-f8-;N zq40RGrNU|f%F|L+m}jyXct86_(F%Xj*oVk~@v1@C7_l71lR)u+9j8%we!j?dWxCemg7dfA+fGc367+GU}4ZK9t<7)E!i11*`5hp>)ToGKKZm zgQCPmPQ$*sBjR3sL~)!q3!-33ERt7hkroVuiRM`5R37QT@l`51 z0<5J4NWzUtp!hLt_iNP#TC4FhfU?AT&A}CxKE8(6Dbq;!yhLCyU0#01qxO*2_|^u- z?q_h<+cn}Rl3cqMFBR0n5OMjqtNy*UoRNn-98j{cATFs`URZeIG;plS*j5vd3Xu@;$CM4P0Ol2Q}ek zJX$1S(8BsDHXbDrsa?KQJmDZt2mwO945mphTm8gq-q#?b>^40tMn8kt3L^$vJ{n*v zbnFBAbdtxPj4!NJsnIXiq(BvWw)sGK4c;sX3ZBg14}vl(qobI+-m~u-rThq2GB!5u z=gieTJoj&c7pkk&d1r305D!GzS#M9hty)U(Ydc0@qSUJ{3y!sS zOT4^k<1E&!At8R;psaEie((0&k$%B*BaeHhxYn>%mZBHFhe`h4rV{NZ&y75933tv) z?GfZYazCO8Ptu!1&F?TnuY-fiqt&=8R&xh2Oe}gpalCr8ew4b4Z)bLQWmg7M%^PMxee>lYFq-aF zg{M+r2kY3NBTvLyA<0XhdZ=Wo(;3u;1~32&7lK%Y2VDqx^jU%K0}?`MhH8-7dqI^z zwkE>D%v@-<#bCt70^UP**4pm9a(3cOhLv;MRQwkT2c1PSW8tFh@trEpN^=+69)Hd2 zCcNQwzFTWK@WY$f8*JOE=|TdW5E|BNQfd~zrE-! z!wCqS)q}-2fsJMhvGBFcU=`{uA+e#7)x4B>qrjM{j-!d)D0yh@7m@dGpCO3X-$g5= z9we8>4&~IOr=$ipYD%~L2pu~KWnO&Y&`#0|y7OYW}Sdni!P zzZU8c((=V*_>%(tF5#*#np@N}6~CbpbXtS2B~D3TgCTQ4CPkDo^Ql8R33$!%@xu28 ze(;!YLf|#WQ<9hjAjx+e6|c%Z1@kd#d`Z3=X%(`M4T~Emj%qnd!E; zaz%VG$EE(^CIFyw3(sElPj&eHpgX;P`f7WH$*T9W&w{~h z;wampI~~}gLRpjl2IwNL|MPB-S$UFk?+Dk-LlQrue*t*A3d>2Q`G@66N9l33I7wr!lg*O_AKpKc z(vonxSp>pCm!X)r{m`iki7Zv^w`3AOYWF8QV|TAtZ+Ob#{_c+dFTG^XE3*UQ5cAJH zgz~|{Jw(?(qZiHkqT8~w?_gin<4hft>W^lLZqE4Tpp{HloTSBsw&j}!5zyBPqfYv@ zsjsjZ>=g)?Tt$TkW&`ZpKBJmk_eKP3zr`H~^g{5)rGv-&9HN&#EID7oikbOi+0ZoQ zPSdl5z?$8g&I#VDrIOJ%*q{#+8)(^WioF{I^8q<{acL;YfL*VgC|}?P~7Q3ya#N)lk%66BbJz@=AP6GA30!+bDRodtEkwH>Up8sB>KIc6| zz7k1+e|uYi7*WX8oJgsl2Z1Bk$1aBSKgC_vqss@Ja50ZrwS;>wksf`1ljE?o-9fea zNSRG^w(CDsuUeT*==V|+&|86=f_;I!$9uvn9`)Fb7VTL3>m_{Y*b^iqJ;k<6_h|N2 zguO=jxn%6)QUbv(4A%u&~hmix%q1#nbVa0%5l~{0+iR*+a8K*YQ3DVW=x8=$JuJ ziO##;ka%y{RITCCQ>8!+JpYqz1^YBZb-)YCzwe7<(QCCHN-e0wKtjf7_9qXKr)m5! zc0k@H0#!|kw;*8LmlRI520<2ur87c!YPvTPuL};c<@6E)EEcRgCF~juyj`gU3u}V* z0bQu{bZ04WNA})7UFgnUU=&*<2I3<-ofmgPj%2gKAI(@FotsUE>O8He`ITKTb-v3l=&Ys1#_vmHl}DW>nnWH1AiohS{kqDKaRhFegcQmXO)JyIPc0$P>+wEC{u~ z))R@dvF^wO+sbY`IH`>i37n`hEed&7FmAHi2U013mIVm@S~JQ10S97=DAHmjwRA22 z=wHzgK?Qd4^}ED&JDz>_%JgJWQR;$fghei~i2%kJwZ?DkeAp>a0RRW=9pPOIDl7s^ zryf7h`!qO>x=u*p!kjA|cHfF=^v=>-Uu#^4X(j=+-tF&XWZ{???BZ@c`t)PIUBTPe zXZn#e%3wGVuq9Y-NG4mRbl0L0s%r$lHy0XTYu=@Z0mBR~mq=EHBi^t<-TfFio!=VS z^H@3d&wGX~vT1XS4nQc0DCL8#Wb;8njph=Ll|I7|Si!(t14o{L=PzI01aj$@ zkT-*yovQJVf!I+QXt)X^GeAX$Ie1Y^WU|WCz->#ico(QB#^KrMBo?aL=k?7&urvXu zcnI6N_aFp$6SEFPHvCjyzrp{v5S_BwGLy)di`z7PwmMIENh)Eo?LJ3#fUpVv*{K3hm@|UA)o|ol@DJ zSTL!ULoj_ZJkm4L(=%DAnJLf!9U^KY3aK(}a2jVH7gkM&N@Xw&LJINLg867~>C&Vu z$)K9on?pw&s_MsH8}d>~_&iFr|B&70F>i||Xa6x-{(+TE(KVAOhs{dy5$1Ydb%!ur zj+-d50}0O7fB*AJelG?eYH{a=cN&ZIwQ^d+@qdM=jbY%Q@ccVEhXy--7DT@`!w>V{ z#NcoI;XiQKKd~P4B$j_sX~Cn%hUI5V)t3`42;nv&$SQaI72>;H>i zDsBOp0iaDq5QP~y(&#*Y8wY3G{t&RhV30si_9m$n;_ut=!IoJRgi^#P*`i41E6Y0M zxRr6-9($SXUZ+W7i89%(UT`HX0+vl`mCvhK@voE#T0~)nV$fE=eK$B(pfORz=`T0! z{-$znzdZ$f|$S~%t{^b4-H9uNc_W4Lyyr4rkBdo3zq*I;m}uCw}= z0X=r+n>XC-gd>OqP9{K*X z^9x#0PgN>8nNU0>HbFxwb|7p>0{nkJc*!qqHq9prI*e(e5O1GRSgnnfu=@h$vi8w1 zqaF&B4Fwv`Sy~vY7EGJKKn_YY39Ew+Rq5^_pc8@7h&_ryv@;dVp(%>wO+9pAct`^Lv<7k#CaR^+og!wTFRmrAj6{5L?c~?>0&O7)dajY zAEz5eDjW)>4(=7CC^h1pgZ))@g3Kfh7IehUxi1NAHK64!qujS5vtBmT_GU!Ze7_t-74@iXP! zcP_*(K~|JfKt))eD(b9}My`uBmZ#u_*8Xayvc)%R^zyv<_n)#O+k>jCr*=Fy zM{dRttXAFUx0@9jpR7gtKp$y_7z*S*`S$kq7!08Fh;Kl&(&Nd&?)K}NP@e|8D;RQB zQ1Iu+C*vfrvDf`y{sMiamOr{}HDQ}j5u*a~5^JOS;<$UFQi>k2JvJmwnEJI9SYT*4 zI3gEFbN(eAYTttYCfNUrDy|0;9dcPClvVzya(@#cJGISqKKmjmjqX8sS?yZh1JgHT zmYw3mzdFZUrmt*54TS-^7tHIjWBUX5`u%1z;q|iiuQoAK{m9`@SF4t}+QOTE=GNg^ z!f*a8@_v1%k^0M@&z`V5*5EMtM|<>?#F9YS&@ z7V%cvS8B|!v$*5XK~-A1gE~N#ZUs6~WppIF-6QxcaGnB2#Pn>*^h{2iDdTvGlrw#3 z{nr4Uf3YR5WYLO3SmODNMdHT>r{-QEXs7bFYe;Frc+xJw2ifx!k7*2rPjo%p3tu%!RJ!<=}% zsMY2i`OO`@E6?ftOFCb3@4n=3S8M*#XtqQ{or2rjl>B235nf{g9TV!^#`SAL={_aijgtYI? zc=sP`r6TW?pgz|uDXDlc2WLM1xi3i*692$ceiw`2|1Ns)MZfIu8mtxi@Ku9^Cf`5? zP#^XJ!m50Rhdn;j6*l7+R;ZSixa#5YECi401v?CA7uTFSQs|;`UGB3*xK{n~568h! z>SsRi0>#hLQg-l&gco9R&#()~IJNIyCF3B9m;a|47EBRshrIk~-)8xgyvoSALMI~DC)>|F-X|HL4dy9#{Qb;YfpTtV?(x?W|0K?Pr7NYYkw^yfotva#PFbOBB^Eq~Uzltw%z1K94b# zVdh;b41?W!iHO|g?mxJWA{gvR$s~5e{$T)e3v@Eomd0vRqWo8hKd?+ zSJE(OKY3@mL*n{e#C9Mp5jr1Tp-#o^b?w@J8oLH0L(9^B?DDrVU?#{z5O6e1`($s4FLOlpw}X1X1Yl zj51#k3CM)DM6O~J(&<9{^OIP$q~#VrDb#_qe0Kcv)Fqi|*+=UYO_%ned9e)nKpm?* z4)Flp+e?wA_LC*9fMWVFoDhtiF3izk?z{5$P5cg*BxP}S>K&)Fm6L9B`k(D)>EL@v zTjDa_f3I$9la2vqr3__=HsMi18CdTCf|7AupQw^#q#hn<%buS{OG{&o8(eD^Y<4e} zQEm~WF5t3{PBG_HIuyH2A^_3`XI4)yW{hE2{th;2NxO%Qh@4jJpVSLb<-4!W8shhL zxweI5Xs3v%F9FnWNp6hbJAXe9|Lp<`ageWF5FGpnT~<3tL?~3|xu8qg-Q(?8jX*8dbX41#d`T33?7oL-`QNGKS152&2WJyxn4aCDx$DSIe(R zJ!7nvtxiq){-ow|a`o zwg8ObB(1!A|7tut3;fnZd|>yyhSeHrq$x9e-j?AeLN7jof4$IQYqs^VU_qR?3YF-} z6NnOAxM?Y`cn@96^nt|F{48iFPyZ}cGs7+;P?aM(9(9T!@!b*T-YdN{brw$Yu#Qhp zu4}e>dmJ|TA2&ULoAc^{{8B2Y8$*22q&aHEU6F=dv8R?CdDYliw!q93c9P7qZeNC- z-`~T7#7^f*tf9xd$#K3{bO#^U!w62ym_{xy{5qBa2jS=enSzHawvJIEM8Z+E(j^7kl-dXG~%6)W|+3&{F7ZWON z^7jkgJKW6g{^r7S-b)5|`1GwBnIVr)gE>Jj_K4`NlV*D+8a4r%0J5-^&UPk+D9u<2 zm{AkKA}|j>Q%&X5lDni=VI)_8Hdozv(}TV9NeIL*==C2o$?aN~ZlKVHYg%U??H3}< z-{q(g($ok}gGSYC4xQd-zSl^46pNxDqhcWynXDA+*6@}&R*e0qXV3MPXLDqZB_-|) z($cumtnL-*p-;oC<uH39$(<2bTZ^=7eA2m3+?p8CzOmYlybjPP)clW)g^S-wpKQA+LV=U~0)E;Tb zLvx5n7f~gsoiKM+T(9HxjI4&e8IF}JL<(@vTs=;k9EWceB3~Ci6i3>!*H=hz?cOy) zJ0ds3-LDX0dzzg2HHYINK9Wp<)@1fcx1&~_xZ{NjYNfXwn7y2+aXZA-d+GUM*17P? zE#L{&brFUDjbyMmuzop7JHbg6dl_Iag>Q)56b_A`I(bxEP zhh!5<*UNdAd)|rhi&PnA8iue@-UE(#?O}N#|77z6iXYq|?}S5>p932-ghgOUP*s7% z&H`(Hq&s1+CMWCsWVtj$^LDPEW2~BWS~BeE>Apup#w$atozz%SkuKax;_mW?KJ{cF z(W|>%HJXC0gd^q*sgs2LFN^AH_#S=xq`N7trTgv=mJB@w(x_niN7BTp1xBHIK8k=n z%HP~)#g;r-2=tq{i$R^+XanK<6)>ud0n&A5tvevfYf~DQxQEPm`;7c@W9LiY%TqFg zpiPB5>U$z0Z6CEoT&(GgugGq!c*w2>i^vyy7uswwWX)my#0yF}fq{?2mJ9J1r5>b| zR)JD6Lg2YA7kq$C97%%Al=rbAo#vjkEUL-bAzG^*vZgCafx~mtcmePy1gEdzySk}S zxt(o_lieQmL{EcOD3Gu^pc~1yCBu`E7JqnupqMy=Kn8mi8mWmDa?3o5AwvWF9w7&2 zrbW#b6CP-o_T~SZ-H)dc;e1Q2|=hb=o@h1aO5e8s+g zXT%IRwVqm}9Dh1!?4`|LJ^nd|tTOlMZ~5{9yIYa_`x%B7bdnSui8-LJ-~Ia?**J2%$3M@m@|>4Eo4 zu}70{bXKZ$UjT2Y>+R(Fd%#KQ#>b|7=R+fnacM}%${j4nCTeKTp3Fdo|3;$@s`9RL z1+J{y@+z300vh-K@owq6mz^EIo)ur%T(@%Iu__45d~KAg`-X&_$w$I-g@`OCcex|{ z*)zReZnI;cltlm#PDcb)H};-0|9UWezxQn#(P2U zk`mMQHd6Mxk`)vj_oYfBGqVu0RQsLGC7NZK2n^mU$LJcdm;;#gG|dCQ00g&q32>-b zZ5#!8_E`84N~{@q8;Lp@vp&k zTd2346Ju>ptYpEcVk9{cZ)702aFx8Dp?ePCE=JSFK})Iv6SC)Sdd%tJ%on=vRI!G1*ahE*ZUPc%W-=#LBFH%AkfgoISEsR$_M^`$Kh z$u#!0?|;00{$apo@kA!VZ|-sE$!+UbueqI`Mc%E}ng|wdQfK`Oxb_=mcn#u~3Vz}~ z{|h|E=QZ;4h_kYD{?Rr5MuEane}x8rKjrYO(!KxNQm2aA{bhsvh96|z{)!F${`vsC z1&pn<;?ci6;&0gHKNuIwSIs&n`y)J$_Jm6KcEn50zV~Ru*6d5fyxZa($7OcN;NvZX za&kKVQ0&0Dvh}Y4rBC0j$g*r}XJRdH=hODQ)maUV_K$9^OQr2=xONR|VY*+(hFZA( zSKEbvThUo{-$f>yy}AC<4KE3mM7z++zTq^&r7~wM4BRR9!96%RE6 zwoO{nlDZ=#?3~!g`0=;95<(s-U%X6Tc&=-xG!sOA%BhwA`*(MBV{y*uszn`;89qAc zgO=x?8Z2(lxBsA*vIHZR?C&PposAj#$?mio%^DS!{KGw!16&79+W_{7E#shXZT>+O zc?0U1EQ`9&bzkovjZS&B|Ma7PPW*36oCN)|u5vP`OP29o5(>kb05vnrJQ#DIV(do$S6{#TOR&1Fc;zadEnkNeBk(@d z#6o_2<%Kqv1ndD1pK@LZ{*BuL`f_tXJ0?+$zYcx+j^!qsxuNr@wEIBO@%IAdP@s%F|&C(qzsbLp*bjSBT$ zclb;06*VHk%uZ`$GM(alo9`>MBpZ-Xw*Z|L3yk ztjzIly9t$87=iTk7?{7%_J^sZ^c2kfD2WpEIe@OtRXAiz=%W5kQG=0a<)U6arm2L< zg3tA{6s^9AJvzy_6RP;7tzX;sowq}Z<||JaICOh zwbJYl%LJTFnEQI_G*l`WKiBKFX&c9V5ifl^v^oWJ7MFK!L{X81eLDO;QuU-f@tUF|HVP(&=JW-;qDurFjbo=m&?78I-Ztq4orHLJXX# zf(EP8v*Gj-#t?($(0VD$#ERu>)Z+H>5!a;o2-Px?Nq-dx)cQ#;3AB#MB0km85H4jf z_1WJAm4)@^TZX8l+C84{t0Z^c88NGp-~|N+bu=&OM?g&HJ;nP**Va(DS;-s9Hsul>0`VhhJ{j*of~#P5TNS;`E0}4 zbqlETFO^Hl&})mkM47B>xJ>oFy+8h^xnppU@~n^-K_A3ICR^wCM7&%?FEh!w+=ZTY^eJA2>q_b>rf z>DEJ9U7({;_4mhwp$K$q)wuX)5qysr#D@qPTj#jt0oH2q@s2Sl92n95-2e1X){cXU zCtAHvUp!y=i*(8MU?C|io_%31X>x`z=F&~&d+0o=|2kp6JV+6_e%XH#0U*9uu37D$ z_tk&7im*7FQxKZjvw45ejDOS;*B4iB{>=gOyIzQgpa{-{wz133ZMU0!Y0#0mM;m_i z%`OWeM?QDf>dd>b{OuPl^?Y&qIC7`BZ>C@mK)n704}Vt=z(zzX^iUE_ft}s2HVXi! zyu1D8dh?_0T#+*{2gnkw5O7;oKPMLj_*Xp81C}j;d1n1+8;Gm^xBW@ee!$&Y0v`+y zuoM}B%mGD<$e4#=|C)yW<#B&MAutW`S|cgXQ_+`vg1IXgl(paUj5T#}(Q=;)Z5ukG z=s>;)ApsWOLfbvo^&1H2?)a6rv4^@ln$}rA2TbC8yWV0q;hjCM!w=xJgGj{rc5)<$ zHqsS7(7Fiq1DE?P@ClmzP*3pf3U@Btp9k8lUSJT?6HnqYy$up8v{yd?+fS|gspkFy#WQa zM4%>n8L#;-9Z)tn&omYtUklWC`6^z38Pl~jpoO_rAb4*UB`_!-b4D_c?H$uzYWC34 z!v!y=7C)A!dQMdpj+~JXI}|f${zK(C2HjkK8wZEOA1`1HgTYiztS`^=J43$)RZuu1 zoE8HmBNbnHKu1^LSyB{AfGv9uE_wyJ%s_!p@*H?1s5tg7O##eYjV&73{BcQ3Nhz*C zO!hvpBn6r&$0KpDn1GzkYOs!>$x@vH4XSTS7KUg3b_g&c(IjyEO)1-Cft5w?8RFKh zRKS_#jIyJiim2Ncp?5t^jnl2*FYM2;uKpnVKKCl%QBxZ0DyWUjtJg-nW+(3Fa<-nn z>`B-p{HJ1{@hhM;+{b$Ef2p4EkG+?>^m2U6O@eq^l%F|c+&Td z+%u^x!0}Gd(5~4ntR6j25;{S;dk5nJinWR+GAtg6a%cU`ef)P@L=G$tfE9%vh|Vf_ zg>vjz8>Mc7Ujarxy3cC$-p25^f`DrMy9PRoA4>4ae>VE5~Yz6L1(_nWfB&-*jN=(Phd0*e=f&j*G}q4W@CUw$q+@606kcH}SU z84@AoS7zg~o=u8>7Is3|STipa^Be>R?;OK=Vg1e#y;n|Bi%f=iwq<5^cP^-AW`uXF zg-#S%zs4l#Z9aY}F@EVJ$n37*ojp7PR3|7oMD}IXhS~Aawiv(L3i9)UA7c%P(F2%I<2t6nmyW7aSuO zkd4fhO`aVsx5w)v^&XK&`!Qrj(JK_}p_2X>?hoP{D*_UX+Os=Sy_3G_ejIizJiQ{aB~hOSmVhA!P1Vxzfylt; z-bV7fhYeBEU6|NaXz{^l87t zIQQqX+-QrRM_;#wcJkCJ(N>PpwZnDj>y$gK)&Ce^{JR5enrt`MD=6LJz5D5A`Sk`iL;S1K<*bx=>393uX>>Nc>ma%M|mM!@C=vu%85P5j3a0o`tbj zcWBr`lI3AVogv+aMm+~?+4c39_SAe%4I80n5F=icd+7dSg1h4yl0rn3phO-DjA zXzb#PKeiz{AZ=2jmF!p))Pm0c>?lRHG4J$6Oy-v#?Dj{VE#g3TMmy5-Oi}H~zyO5h z-5mq^1j>P~>n%94Xz*(gr}|n>-TY%6uF;&ai)LEVs`c0q9Tpj_digZ#V$aVRq? zKHH4ENDfC}BV_@PbkGUT4AJP?=~n@yQ$Rc{T*(2S>t9gK|MpSw0M|YiFf&0bzXAg) zkCpN4=ZXTuHd9sEz$?i)0EaZ=zPEsbDYemN+DBlyBV#Z}!l+i7B_k$Mj(Z_4@{Dk$ zExpz=1L_W!A{m5P z>hmCJ$*iFa6@8%f;wl1MP!L_9mJ=YqHT?NQlBl-`L-7lH`_giY5grzp38>9V?}?)t zb%0<#FU(6N^kR3b zYsQrM0JvMwD4k2^>2B z0`cHSZN&XHU@GJ&0#|yA^>pm*vjky_SPp+ZI(5UKd$2g1^=_|N!PiN}zCbQ}z5oMVvYxBNVoSbvSp6~I=tBXE zBRY(79K(wDjjKmF|Fbvr|Hy(ja$k^dunSxyK0nCgclP4fd(R@^qJmz8pg~AbMkkcL zf4=V=mTR#|Q-x0N(?+t~6+d8}M^Ld+3oW9v zOV;IBX0z|8Jk^ z)W1VspX3E1U(&Owq`VQXNZJ&qm+)gvnZz1u-I~<`;r~Plo3DR%yxoMWMj+pvU{m0r zf~>vM(K?b3S;7wRyjOruhjlQr!XPO*@faA2szLQ#2rBO3?igHKh-LLi)mM1?K5iJe zte+?8HotDjtV_%8e52%VAFi%YjWye;DKL%^09^T;*9yYk?@H)6zGCwHXCwg}snnHP zg#DA!**62B+4OKqh?s)|u6X?a@&?BXUaA$voQW;5g4v6hQ=6`Z{Zl=rwf{v+00vQU zyM&Q5G1e@X#Rs;>;!Qz2z1_y0)L&VnMIBuvFZwOB&I)CiT_5T`S*s-=Wc}xh1QAui z_L=_(U;HkE|A#fw@6OUDni`2S-<@VgNQ>Y0U=MQXC7G=^0Srhn@3!1w;^-1du| zl!g9ZSf=K{^HCCXLh)@q_T59kz%rV}NXlE{}(=-}|Rd`}ZvX z*as>N$p{#&TyRsrloYrL-9+(Xe4wj{ z0icKsIC0P}aVYo{Bcr0u5mFNW?{Ej081|um1H)_Rx3_p5&q#ni9{4kg$KQUt3ij{P z)ycz^0ZE|FEZj+?0H!Ebt+jwIsBDHZz6TKv&jC|ykmp&d4=Tuf-+HR*Muw6ib$L_T z6Td7F^|2~>BTc);+rYq}{s-_a3;?15?LtFxFP|jPB0aE8LNz^HTEYPFU;>AyiW!8v z9_8|hc#5KZI69ND7?UR~34kz)A!CL*R76rLDto~r0h9Pq9;~?nG{4u!2}D1Fw4s8{ zyvicn4l5A&)bSqHTz4`qn<}C+gzpMiu{k@2H-Mc zC_T>l%=M?tHd$VNdOU<(zifu`cf19p5(HqZPeXEx4kDu0R&UGhTar#ItjA&Mht`75 z=XLglgZ)ZKB=Bmd`G{Ig#o`tW<^8OkB)wG_};q3 zHO}h+0r&%>^|Ua1zr_ISz`YpKN1 zOPgE=!^cxe0;C88YDylBW+eNVEu?(}HP(%6kPg+K8ujd#LqPM8;7rH6sowTXo7%(N zBk)d&WCOopGx@&B62srBzaPoey=5%i&bNu%AD&B88-Os#v0th)YpU2AWsBc}=-GNe zrwU{Xs$5bGcYHY=mK86@@ht-|IvV)Vo<*9XHGX{0LwDzv-@WH#Y!KOZw{W=RZ?|A={TbjyOU8g z*<%Ap*DX9+x0gg0_4<4D4}2rGQT+2Wy0<49rA9$a_@cM#ja|~PDA0~=r^kJOwayh+ z{r)t0h=79tR>;wj%V%Ix)DKT9#2b2j4zhT5orm$oqVzugsG`9>);F#fYSb3WW5c2p z_AdYfyMkn(pDqp%UJ(GnHi|s8@a(|1W{|iZ6v}+TCt7}^zIGI&RXn*oJ}b~V9eDPD zl?K9Fyl*P;=XnDmI_&gE^}VD_AVK~T4&nmUhnrTV7Eth7Jj>a_bHbVd&*@N~CuqPu z6z8!+@9su#-l7PmjnpKDLdft_zefzaIn5Izz>=;S;yK>EgWdP-{{*$M{q1>KIyuRx z$r6Vp? zsOxz2qr^?AJ{pfQ6nc_=I-=_*{Ib&OH^u+<5w~Mxh2&LsrjnlJGQZmuFArNG5_w|+ zta^b}zjIql&x;DTITt?k9^9o{dZv21g9BWgijoU{`uGLd-LU3bzSx1ut5p}KxH{e+ z=Pw?+=0))ne+RBzYM$Z7ugEFTR`S?ZvAcM#R~1!M%ZE#P-@~Ls(XXxn=KLt_EI!I? z!w;lrSm||5dLA9BHkGE>Y;g)! z|MpT@_WR))3kCB%F$^WamyeV`hYf0$E3A4Qi9e3Qc@^`fwYW3mJ+Cxq0Tw?S6w8$5 z$f?rzYs9M1N`{1kiL*wfxK{HkRwhs_$gC_Y!~*Zg^D0Ki%EeBw{4~KNL`qEo=05UB z=XHfJHmZmORf)X()xKxHGA|cpx0}opIL2-u1vzM4Ab8xe3|@?DfhhN*@;t89(vOpu zG+780j!lE_kPioCQP7?P_l`RqfKrV8RzpW78eLhi35n@kyc1Z04Dmc$plO88`QLhS3U9pgR#E8@@ac?87YoQU zY~p(2>NWx7_-ZHN_xy(3K$t=FFDb9NYH^M~bnq&4#nVn`5O1Hmw-WFWm{0){jv@j& znDDhxVqzW1ZTN(p?4Uxi=&#lD+n10NpF|LXt#`YA^y+DkM>f*APcPB7L>D@&0V7X!TJKuuRxKsp{!`}4bG%0Gr4Iqmty&O1an9_Pr%-v>&VXrMXf00S+A=V=9pne9bhro7Emfm#}s zW_^5x>FiT!3Qjsx!7eU}vJEYp8;jj5zk#T~+#Y8MVM}IzBG#qdlV*J-7WMVgXM6UF z*WV9sPZ2M!`nC3__g(=|AegiYa_LRV@OinxhV%PFvd_b9T< z4;l9L58^aR!7kvqPD6Zoc`%Ju9ZV~Cc-Ygm*)!>WIDOnZ^|e7zux#yCiczl%#V5NK zegksD*X?8Qq^O(M?%~~#dW*#~ruUd`e4*>geR9JnSQyGuMHPrClb6I$dp?fo;?R6yC?)~DWGzf(^=0F?y?YbUQy(!uYWsk z4A*h}`>PolqgK-65NgXqS(*L_9+y*WiSY-A>-ndaQ8%9Ibg4oHaTmWj`YYm0Q~7VB z0xu^U$;1_67^9deuTS!k$h5bQIet2$b zbz^~(Xm?MgNv4D7`ar%$Ae$GhV6RR@*ObWvL&OYM z$s2A-I zPSZz^?-M!jik>BtuB@626ix-Ux61ZG(AH=IV7@u0RnmBvNLdJsTf%8n7LYx_#H2B& zqpY~@VU&n4(|}V-?2Xgj_T1b@o$bu((DsI1^8?xAb$GQB?N$PNkzW0e>+5{*yLq%& z_|-Th$+mFXJ2|AEt*2y0DjLSQOs|LR{frlE!w7v{Df94wLnJ>8DU~fl2#dL)ze+%c zvvyvu-I&0Kw9B5>VB00xn@Ft?VcOyFo3 zOjtX!Zi+HCydHm_*BJy5urM;VgCNp@GLfV@S@~DBOzu725B+#4qnwG>`^+@)E2v^+ zwz#@QHmBWp7Ys4cB|&<@&NstV6@yA^{ibhiEIpIyo`O@>lV6llDxqV?G&q?C+r|Y4 z>4xi`6_D=R#ki6w5Q#1+l8}ssiQ+rBw5`=Y3!a>xxK2Akr(>Zz-$bHtS4|XdHRaJP z1aZibsdz7tuWab>wdA=Ue$%G)nLLLCt$RLvve}fP@C#=NKWh4q2Sr|7M+fl6xL(mq zZGcH%4u0HyOOF> z+uv^mu>SEr@+!+jC9K>vx~32OSCl&b@oT8*BkiGnFCglo*r#W+r`=&MQ2z=?iPFRV z@mK!BPwc4=JOC*eJjZX;zn|zYjrTua#Q!J1C|bKpUQkYHP>$)vzi-E%R}!s#QPd%C zV-j;aB}GagYb1)vt@-whjZ--)qu})~+;|B&$ zPP%^C6WcklD4zP%0Ytcy-ZM4RLW~8F#sB=?bcBk>f35%i0l@7lTaw99faN|%CdIqX z<@P4A8q&)~rnI;J{u!zi$es-GcYA0S1NkcS{I)+H_q^EVx0~}{pIq@?)-5p*muIN( zINu*Zd3vDi!L)1KxaniV*S?h+$^;W72sY=w{P&Y(w1+L7ml$U6uVX8l9T2~&5pJcP zF&JkejgCcjM`her`D>*c_-#>O1EFo#t>yrmy7L!AEHBd*LEW#VR%xvRjBBmsZ$B;l zwR^F0IR`8Jv3ue3BIP@?PmNAjnC+1tEI3T(`-Dz`kC6C7u+nl}IGrJL*}&t!Dmfvc z;1rk*-VIxu`dS(G6h-TM@bIBDz}}#MDwEIy0mFK^36S>@&t(?bG7CrLtAjIJZKBd9 z4wT{MUZWCj9%d9mE)Z>^FkN7(OEm+?F|7D$DWkZyRBfo7R#YS{KxJZ4FJ}`(9p$9E zf<;P7s{GkpP1p-Khr8jRYoiVD_@QI>3u%E!dwe?C@8@|Sr{1$^znM50S6jt!HOUpTqz#t;8|Aljl@EZl4=Vq5^3iw0(PnK;vARP^{(g=0AZJaUI7CPT_x*j;Ul` z3ZhO*c~l(ZsRp1+Hn!UBrzz*WAI#N0m`>Mvz9|H3ro73cRw~a2#!KqTsKr8HgX{s0 z(M`0nMcRlAZ_q`LUIBV$6|@@?m|ghrCy(I4*Y%d+N*n+d#7=yG4i^UZs&lLZ9jZ@; zUw=NDr$pOLFA6hRXp11525ybzz!AEsFKiMdcSs*i>e0<6*-?a0`;HOr+D?BHYsy}`pNA@DKCY-kedL0P(%kR_0SjdEK%FejAkYc-Q5P1R{3ek9yfhyw$UY4PPF_V4m{`Qr ze7OMIlmeqg)#6t=^Lpd;9wqE8q1bblvNb!L&bA`xhLg`MHc{c|;26rt^wi_I%Bv6} z@^p+3qde3s5KI*pv%cW$uuI@@@$3oT@M{eNbQ~>tbLD=p?78l;?TN5tf2E4vjVtqp zdrrPZz{%<`kXWHm!X^X<3;DC5G? z`FJ-%gOTz)zxU7hFA!%Qin<4#xH{n}-uw>=V>hE}*Kj-E7Pe-O&DAIYnPJ^t#znD! zL<#)Mdk#*qg)lU&7fIkG(QU1UOq#mJ*sz9iy~#~O>%F2d?3 zkxZz!d=BCafH!)x^j;siGUIOhr(-|-urhBPKFoQAc*fx@pDd8Q5^APW{7U%zozkOC ze*KOCK&P{>DE0kmKrTWe=O?5z4E)x)a4;Vd$0A_BQnGLYgq1YrV1_j%@T1FaG;(pw z@PGM&>;Wc*M&KPm%zcu(`4-wb*qY8cvM}T&`M?!PN?N(onKWuCa?~l#%`m)i%w)M~ zv~ezjv_d>E+wILS^4R62+#lG@V?kJv_EGyNY8R_?IA&tM=(d*;l zGtWtsGIE}H;9b~yp0n?jFLVT#)!c>hv1K(}7%mm9w9#Zq)?DeL3Az4Mr-WKo`#jrv zf;KXIrXX3pyePLeMQ3TG~>>>A&c)|9U63P zo7lJu`0yC54Huf*mjk=Y%85#g+?JbjAxhT(Xv;D9M7D1m1Ql>k7HX+?ljlf1fMFcp zo57`1crk!J3kHlIBBJ8?#RMazMrzzMa(sjQ!%oBRk&>mRq|kvNrpQM+0v4`0*2{{x zfW!q_z7NJkt3G?kGsR61!#(IwUjjshFM!T00GqM^`T&%p;9@#}6Zv932b2qYH703N z1temmn?3(kCkHo8HVo2|K!D4sQqu!rVPPTYZHvhtVpt6xR~Z=@tEdBTavtk*DS(SS zWS6}+NlWt6Kw>j335T+DOJO0D?Pii77XEsZ$@SI@ib0IyOfOT+D`n{WkA>!L11u7~ zpIodBJpgYS?zqr~H`PKW`ck*mM<@c_QJhlA#zzQGA_Z__d!biIAI`Gv6ywlRQzeA?S*-1a>8JyE~mkr$*yd@01BHZR~Mk#%Llyukv`&U}Iy)ONYjCG=CDyNED!hUwxcy6{pvgzFUO3E6U0__d)t!>56pDfPnI_tS_eJqoz4}f zEZ*}KL1Q+&pKY$VJRX-9A>{EjkXA|%{64PeUQ;*s`mFrttErZmzRpK&f$0^Vp7lzh ziPgxA1PE!0I({PNbhi||3 z_1jlgq?)t6x-RfEZ)6eyYn;%~Slj3G?>HePRR{B)C6fwQz7E?^VOOb==V%*1D^ z6{zwRES{@hW)ww4zChTqUOuPec0sK#Q%?P3*nY z6(5DqeA4VA^r;7@1EUSsETT?h9z*y3+onA>cLLlTg>-8YgdrAXNM1><``F^_nFl&n z58g33u*r~5^4Py0Tsggu1kPi^S@KEbKo>ek2Ied57#Zyd~G$`9QLIMl0$r zLn2GU$%^T!Klt{lJ5`n=(<-b}lKjz19@T`U27%=DEiUnE94w7OHIuD;$ z4q;@sRO=uPh>bSuzd&+s5-EJnrMh~yAJ5(g7i@C}&NLj%gLVN3KOB!INE{-2?uiQN z>+vTcn4fP*+{`-IDyF;I4=kVh5>32XqS|{|iBBVX;F_Z*{(aA-28wNTx&0vtfpiLg zJ=M<1dm{}30xfOVTB?tWeyA;fNoo1+3o*c;ji2NWkZPxkrBsPqOx0DIM{Bw1kH?=Z zT5a7iI*JTqx3*NdanwJ0d^D%O>X7KA={07b8qyyBbTL5?NwO_9ch5|CB|41hSSRt^ zwTrS+zCIedq(v~ABcpV?1xw;_dZ8r{g~j=mE`3uoj&o>jNj6ib4?@_LXGOCm481{?t8g9}k z$YPgGd>aDpK!epg8_Z^ZHDxLudIUHjlp)Hc2n|@PPcK)Fk^Vy1R-u7EXa`nbGd_n$ zLhDZiAud-W>gs8(%&U8na>80adX~+-V>TDL0*Am`Zh&2`$T()sww4I`^iv z%O4b*=5aM!FTlFGfoY{zQPP8#W6&@u9q;;LejSoCz6g9z2fN!9$rBl01#$NH4>aX9 zc-=IP=$&lHqyE_B2a%;o5d76aUrz+BKLVakocITJ(Y?B_ski{q$bzVJEO>N?M53)3|;(OPqCaK$aBA=>x6RwNL1{ zJI!tkQh_cZ1U@DHj<9L(EnywJNqqQ{GOC67`;d9=mixx!tyjSXo-gnPItSX_@9SG^zO(W!TA#>2(ZW z$Bv@F0%7TYhbP#(FYs|~Jq_nat-qf+j+Nlv=V8j0YdeEq{Km|z9bqPiK_5yl2i3;h zcM9aS#Ds>M`0Y0n!ag0Vb$XgtSqkoj%3E~;yOX12cKW?h1+kS9uP|xR?Ri)N?zopl zo|PxE2eamVTSVCyH2u-cD9>#kco>6D3!*;GX;-U`Q*j|;O3XY#Wx(6%UZpk zZ}6tlzL`|zTQzIvbYQtlnJR!!944w~Z)4(3*mT;@m$a3ziMCaL?y#IVew-una+}nq zpi!%Qb>u_tifjT;p_YXJ2^X9wb|$e}*2@|(YO@r7$6P&%el^UaKs-!B^{x5`)*g;nRwqnBwzI5OY{J&cN z|HKkJ=&p(@@#g%|YXAQMMESpmh2p=kJ5#a3D$A)($X6gpUb2Ji^t_Dl(@#r(QJNlH z{8uwgzmh2k-K%O>~RV z9&Cu6SgBIAeyn*Jmb8xu2<)1n&E%}KaM{i{-}1;P zg*X4BsFtDu+nIg(ML%}$KHFkBlZ7U{4_ryr`_;14RZp9wC+ecR_Oi+3&*nh#c=Mr-XS&iP79vR^Kl^vye~L5vXbH!`SfZ?-){X&-+})gyoB8>Ri}4~4~{ zrN9mg1>D%vgszx4U9x*NLh(7X#IGnHE>csb%`Q#5C@@8D=FXaQypNH|J~90wn|(`p zahd>IR0&$Dda4o`K>dMT-25#4YXEhTu$=jM#fJduf;dJ;@0he%Wo#3fb3p;~ql*^U zo)@C7&vL5h@SXh54?$|PFFnc0*$z{rWJUX5t#_mfak;h6i>P*7J~NUPxhW{P?rcbt zd7ak2+EH!(NmjI{r|XLBE+O+;o4wdMTQlT3L(ZcuHmggRABA$5?d-g3;?_Qh$6`EP zzk^)|5-VNL^Bu73_I7SE9)6?27QGxdWxSLs2uNi;tX1{MD-KBYvPe>`t*Z>^R83(} zyGZ&t+xo$aW@u|OeOA&!J|>|~VQ{<2G3WWlj6>hHAGS!OTV0oR9L98Vww3R;6=q%6 zF&Cl8zmWg~PG?KQ*5xw%frWP}W!W>Om*J0gFCS%1WbnA42M7%JiXMJ+o^e(?b=oij zSe5IX`@T#BP`)68dKH#>Q{w>0#u^JtH;xe-G9(p+j?YC;c9US$oVms4UMOR?y!cP!<_%||mlM#^ylbIt< z5d6vZ7j8TY1{PuLPAyh0uP*HM6h|k=+|KahzsyHt&Dd*~h8YEbf$(W0v@JoD&~*D5 zhXOF)VD=jrcxd&VCV$6i(N?JOZBy;e;tW=6-C6%Tf!jAv0r<0MvB_mU$uO8teP3GG z&Hqq;PqEI+lbh;Pu3AU*t2_g)-RMY(A%Hz<3OygkONn{=d2ey}<9;pcadW6V`Zj;o(| zo!miQ`t0?-wjR}&fNO-JbLA`mQq0=ojh{gr#ePLj2CqR1e3EB&=8G7-oD&snxDeMPRvxfjH@5 zgH(V9^?{5A2;*Zw8sSs5^#zgET~C}5Z~5Qcti@UE_| zq{7!IC94B)tDYb_6zRGfePcVD5EF)BEDH#cd$1r5yJXU z<5Z*Xdr2NA_YVv>>VoPLi=2l=U1%KB9-H=8G=v!lP0O-gcFzRHPaNihdD`fAgK)p| zgI7p$^IILCJ&1d~$>;%)e>3iNb&hqm!;bdnsqI1UCLXMPhm5(nM6-Zw=z^}Xd}L2~ zaw~MBflH%=S0l_5Aw6WWQYW36e%YBwzrg7nMlG6RQI3O^!e3@$L1HWqNCtzGzWJ{W z*~b_C+M}9Q^pgNu=CmCJkeQR!5eBc7yFm)j8?0c;ryRt(1R zRzMRwU`qut=@NL#HyqN%-iWAyhVnIvH|Y)%Bcp@rJdW*)c+zgi{<_)mf+jslx2AZ{ z%hw5+Uo3o+;Bi(=T^Y#j1Qu9>Nj~@dPsr~`2-Ta?EZEe0jsO?YBvz%e8_3qBRPUk* zK4^s!Fla1ve5{#7JC3I7^r%d12Ag379m$ME2?5GsZU@WnNWfDagsl3z zT?x^Yk(TcJM43uGFP3@?M)x1+iW- zy_FfaU4P5nZ#PFLUW%D4^{@?wpyn*HIF4z0jr9x-B|w97E0LYf(`%q~{R{ndx(MKrwHhA z6aDx?sGf?^QnXLzzf6BU+za$Kd}XiRvyM!%lSM{EeCSdA)e;iMA<)X2Wm{j5U4z{? z0>KD(52TV7zI)bro;p$bUK7JOBwxjzzasGr9KA5*R~Rj~dWd!JKv=_ZTCiks;FMSB za5^~jP6ok^vzHqw#m0#a&6gYv(5oG_IKAS&hZiO;0>p-_76W1Lf* zr4Z&L&`AAE>VpNd)?ROY2=e20`ZU}VN+zgyu&U}%cLZ1@LGTQG>uGj$|Wgaa@(*>zTj)dAY4UXpyB62@m}c~d=p?R zFFi-y(?El8JkZPllC5_?J2%%%gn_y>13#=Bh^x(vUs{+9 zcg1svI;6`95o(~S`eyx2J%MPeyY+2w0mp*P-FU$wQvH6tPzKrj#z1kto;Opd@*CrR7$C(}QajL1?o45nYrM*V&&6TSBVZLOGWVyC^A4un7F5{nlRZ z`j+@vysk={c8V`*e+~OaoQ^F)5U=#il%8|3%SRvqPvL<7wbV}$TQ*YKRuWanlq`kB zZursFJmqhP1SmSzibw`+`t`AL`9V!NE z^EoOBh>j_UEDJn;;r->w{HZz_Bj+hw_$^A#>^>U-3+*j?F>Y(~_xy;Ro56pDBEL}p za_u`)y)jcGiSYA8lF%+-H)W|v(czZiV)A4P!TB8525*fteN6R(9Nfe1Pf!w~ zQ;5P1d(-6vOcBai;DA2*-nERV>jBIVy|Y}hv5AH zc78pf(zsFAGDU5%8cD7i4f{8|O{PkB@26Tc^y661SAodtMb|&L)|Vhia*VcJ!4R^? zevAmXRe!?!l5hMK7a6Ul56J5HSnuL{4->-CorE8v0aqrOGOFKWEUU%MfmR{$YOmN8 zjhetA`mbN<`mnWwBE|o`*m;R9$LeiMe2hgB6$Y>&4NQTl9z-+v8}4!vI-cQzrN(wV zR$ip=P%n@33x)1T-yw<4issbL{t}C<(_J)}-0bb!PrS5-*L~j^op-U?Zyw!PIWnat z)pq}AsavZe!4uE&A;)N?E#=#HNB-KS=n(4z-!2)QGNn%#zBNAuNHhxBW z4fo=St~1WXNu>pc`4la9K#HpRD9S~C9*9)B1+lU$LrWWY?`Y`(4np)09^ZRcIa|Fv z1w!!4_#j;v>+hdwYHE&hU4_4R!>F9|2mq$wu4%$~Uo|ZI>ieI(2ZPypZM}s0XHU-~ zhN}^saKS4}{+gg@muy6^wfpF=-jcAO0VHt@~RUGuO0 zIl^P5NM9~|&@ie2%!*Q6+6Jf49UCS}Kmu*8l3Lc$<0Y=QqY^k57toUyZ98eU?Dk{) z5y2@l?wKf^wSz^=8-X-zc_G}+wL+fkLc(kBhTM(11IdksectT+49~V-{XtqIZxWUi z=S3K>#4o}y*M_pV%Gzdhf?;r=E3EEZM*1>)OB)6%q|Eo*{wYlVu&kH9 z3LCpn^wm83&gw3>oEfATf=D0d_iLjKN4+-A{TI@@&hp?F%m0n~lw47%g@|Jw0v>-^ zwawQ3W?X^XC*OFS>-+7%vcU9fv?FzFl^$MS=QYt6cu{GBzChNFPw-lZ6|=NE89IM? zABN643>lt~cH`I4oQWfl|0=lVgXQgP;3CNIukt;J99Z_viT_3-(qLrI0HV6*Y4MV8 zbG>i3zj*GZ^drHSpLsal3rxO$iILdUn@UET2x|-S%v~JajH*KKO+1&I0h4qR_wckiqxm$OAYLfBRUwj+_5tJ+};%{_C<`Jqedbm7L zD)X9;_1&+s^*>Ro|54Tc! z>a+fvuJi3&*mc{h42+k{SFlA7Tilh?9YnE3RlGi`G7U*KL7C*jnGSPIkAj$@vd2>+ zxz1jOGAhsGPH~^vZkQ>rRqAk`Db~p5pMJQG9cRv`vO3eJ)O5(3l6ly99%{ViRHN$< zi7|65)#SLj&XT>>^WC;^#xY9L+%s=>)p^@CiW?U1`$N0g01|MtY;eq=6F*obX5 z#%TwqP1w-37Vcr(k}h@TEH5=R16wVJa+6K8bX1%!MbT_&uaVT4NucRb3~@mFnnJe4 zQFff96oMYz?C5wz;`yU>ejJ;A-DFgscHYXuzdUI=zqHq;3)RV; ztzA>-z%abXn0=Ml(-uhk!i>*#%{5-c;Y~nPg*RjT%5(0dqh@G4w{1kg*Ubx=wLz;9 z^(tZ5cY~FSNL#w<};3T&n>KM)Yj~4}w=uQ~V`|srO_=81 z;Q_4*;|yr(6vNx2j9L$@R<2^dkFS;EAle+*&U-Hsm7cmjy#01ew{4qW*VJXS^{dfB z7bRKG%TMYpT}P@-E6;J-PE}yz(Bpfgysl9JD(aLmLGxu?lQtW6@n>F6U-#Mt9;!$b z0_?5ZWU*&Dv)>*TXzcbW`jP-qD}85p2(Mxc|uH0tvO$jfe!V$@AYVufLR^ ze_k8-7U0$-2HdYHJ}axJWCPYuf4Ufk+4RSFUWH&L*}s>}e|}ckh(y7lpdb$0AN6^I zK-Xk8Qc+lLJ*7F6WoKxULZAl!d*}F1>K=-WIZZ7HSYFx;@8Vdx)d5zI!?iDdx~*_|_3uiJo<>XSczCeTWq_xvKz$(Fzc0kylU zoz=~0bDXem()H6IS}Cgk7k~!ut;S?{e|1(E^aLge9Z@MA!-`J}TG>XD0N{3z1s zug{fghW{5Q7WN!2I8^W=0$>hHL9Gl_gZSPN=yqz;MJ#51=#M)qx_P(>2Dvj!}xkCGzT8X55Qqu-s#0dXXd z6Xv?cuwCXL-@uxj{7&|pTw}Np5@Eloq9)_d{-TKyyhCt0Pq%Vx%`5EO{7Eev&xB7W z-;wzfpH70ySx*K;y(1)LZkdAMi?n7aq3)@V{aLkl)CB#O8q2!~;%P0E$rout4)f8Y*NP5STv9m&7II zv-P3iw|}6nL$mM|cwzxh^fDC0GhD2d`}4E;a5NA&%Gld0bXOX8lbP42d2Q7lrVLZ> zKOR?0=Kz@-*+}fw641Jb2Hr!9FID6nq}CtwZVJHG+{}1`xo?o!-T!nWNPyNGF055) z9dkJ2tuT-d06TphKQ z@QdX{Mh}GdkyQLDr8FeubXdFBFu4*pUa)EfIs7 zMT4w-h^5|UT2q+k%_c7PR6EEjV4-8nh>IEH`z3*U*@{Sdx|uCdNOs# z3pJCi+L*3kRw$<+1C zj!-s6`%sF1bKxgJ+|p|>ir}=$_=~t*p{xs)-+48Xbs zRtoBAVjzC1FJECaklPs|lVhJ9EMSjrv8#7N5JFNd-5H`-0xEDeJ{+^}u64GvuQ!`i zS-HNKD`wui1Q>x?;tvw{DT?Sy%N6C&N^bK(Dd8Lt+gu8GqJV2Pg1I{IwUSJ-%?8N2 ztI&H|cadh}fX339#1Cr(cORSTTT>ppBNeAx`KxbWsxOPz#Ga>s;C&Sbl-#SX`csr} zF*;A_D6oc9laM_i_z((Q{Q0$Juw}{D0adl<#U9F<54inDml0Bq4V)(|SmJH#Or(Cp zC;^I)#6YAx1Pn9({nE&HYMwM>PBXp~S>$EK9LU>Vg~>i|oG1XM8kEx*12=vWGFN9$ zz$@PHLhmKJG86h&LiLr5%BH^9(F)_(iUo#*}^CTqksDYlbw^3)8xZ8W8V2s@g(r4 z%+XNKe{S^qAxoI|R?Q)by~pn^rH|Jc#)xn=-MkLY^gnmaGCj3|F5MAT4t3SHnkvYO z5I4;iEJNGL&W*G8NJ$0mwoWVD&@GCXSF!trXhs0urr8+C8)^$8q`ZZqC&u&Iq;w_m zt4La0{h03G_lji2PkqMFpA3S$HeG>E3Zk+gDNzs<8Dgj*1OyC11Vws~ z2I-+&QX~a+Xb>a}x`qy=hgP~_=%Ks5b8yxD-0S)Ceczw=-L|#X50`VzHP>~(+;*uM{i`=z5* zo2Kf~z5<|;(6x^fxcA_a?Bj`M-#Eu_yuQpKFe>O2!MtAMX>SEo`)>jBaRHU`vM{Q7 zYP{Arwt=|24-oOp`?9&g>Q5HPp%@z-^@@t<-v$Zk{+YQiS7J~gsm9u)XfJny&FZ=M zTcA$8@@cht5-IHuH3RUYzx=@Ck}z$y#*9fofx~=$`el=~5X>WyypMAD#rk$EiU2W$ zdV)qqH;~0ZP2dp%U~Zt#8r&K81mOw=>4Xp~ILiPjlh|{15Tnpo1A*WoG*#=?ZZdcQ z3*_uA0*#ao;xIx87v6&RRNk+5F|l*4jYLCa^a2rp1Nga(is$PaD6j+^83X)oaT*}n zdkU2T{)t~_--srQ`SDU;W+!c@n~@Q|VoL;&3ITC(oz|deCcQ+A_FL&OMN@mEA{aMO zQoclHy7zm4RA0Qkmr;&v;bmI_c%BQMy(Iu)qbFv|0L}oh0GO~AkN<3{!b^MnfHQyw_TeF%R!;fRB`IgJy=wquzV9DEyFTuWWy&%2SA|xyMXtR}3V)lsI+W)U;qW3_C7lD9AXEq@JX;;=&&gMA=b zy2&NqP}6)0%Nbr!xP;heMeKr2`||;u3XBJM8Zqgap)@?Crl0VTc8yC-S`Df+-KV@E ztWpQie$kCh$eR$~+#tR-4qslUHods}d$g1$3l|b@kRN5x^laVi8Pi-te<%B(ID-9-Tppl}VbvhDn(3 zaF!un-!QF618IHGwadf?p;Y8x#xz`_6$y8cyiS3rk|+uX9fQna?^N?umct>z1EbkB z>-99$yMHXYr29;BU%H1=GOwPF1buACRS`b1ne*^MGEyeIRJ<*G2ooj66kfxbD{w)a z>4$tdtvx;qGm;o$ur&VwZ-`dIpp7D0Ux7Fzxz<$>?*Q$}XL@-$R7IM|z!8pk<3Y~y zM1rV1yM|V9*CHetBvAz@MuWZNsxKcJ^-)|qqW!DtWloPmU@_N~3JsakDl|=5w(L%| zViZMm9zkA0K9TmXnO;_ypAD}@d0CdqOANSb z6f+;oopMn}ry>qBF?V9<%B+$Ci+7T$Fldf*!PF8x?7wA8zjZ-iFAoMmq`Y|bH44pq zaBf-!|5qw_Q)h>0&%aV(!NU;z((!Teb#@>3v5>35qnGq_Z+~V52_-SUxL(r>=F7OY zzAK#J4F!WL(c)kQ@TNfh!txpulafvoOr7ys^S{i=ECYzXsiCn@i}Xgox+j1SCyRIL zvdM*X3N!TL&%RW+qzA%D8EJ2)AAzzsXU);IK$il`?DmjuA#5E&NJereZXI1HM5D0W z(lLx0=$nng>1601g+$sf4MX>gT0QLM+KRL>N5pfCfp?(Ai8udl#dqnYNlsmi!T~rwTp|XS@*|THW8UFF)pa zV5!7qS8#fVFM;cRKFRvNcPeV~xZnYnGcu_07(io$@ASuenIbLc++BAW2J9z4hjshB z_wtmL$HM(OCYL|Vyz`V_zsgMYtpPR1D(IS8&ICHzm7|Mwk3j z$y=1KgOechuI5QG(&kBQ7>rYSOYAn;7%auik+GU<2O$>05zYeSTL1R_fs{`Wrw=xl zWhD(dV6i}(o?VH&Wi|T#k$ITmZ84r%9uvv4XG4?YU=Ta3d5L7jk>=VFKdeB?+-_7MuNzL=XN^x153ppeVsHoF3je-KaU{FiH2+32v9Q|5{~s>0EBcvAb_Ds4L%}Jc2TFmzG=P7V-ls@lU(?#}NKc?C{I7@j zrv&h?MIgN&op3PvbvZN;drQ5CL0Kg)`rprgv9O)KM-jyI9Bw;O6cs}-&uIaXl`}tRbejrJjGulpr$!Hz@aR(ci8jRj>m3I-4x@HD1{%mh z5+3)*vCH3A|12xHB7u{t=7Zv2+jd33lu|SX%pZ4An{jU;33}>u+wL4ay$27%ULriy zyM|G=|9*O}1ctB~ws!sfsFmaL`U7m`PB^N2RFBJTjDW0c+F}(zId5MXH`Udlxrz3xemwCu02DZGN67;R=-#VRr8t~IJgj~# z=#61~GyoGeA3lh5byzgtS4weTIy#>qY8C^08apkcV~RX0f#cqj)|&fi!PKMO9zY?T zYK!Ryf{RDs+|g(A27|7j_1R}_7nd&&!?9nwiOAlzyyG$#1{lCMc|d`v+XIm?xJ^8H z@~;<-lQ1URDs%q)8cq+R5Z`t)6Iv#I0-HHeHOTnU&-^(eTW;s%7NfDJ9+T@P#XzHe znsSdWYCXTmrH6ffu;@*IzIIKg_q?wqVE2pO(J8wQFo373sYY+El#NvBz@Ubd#4%#} z#W=`k0&4NhqExFSJ65PI8uSa-%fWkbJl1cBm+;UO1s$vdxG1+~>0>}WX$CeO*HI?Q z+zf2txfBlcf{4rzI&sY&fXYOJ*1Lbl433Sm%Yp_neCP>q3~K_~$9jkSj;`z}a6&T# zIiK{2%w=;0#_heXA?=)RTHgQbSOj$ZtxIWYf%^0TsGfaauZURj>NtMh&rMIkP+0#<2kZn<7f5v10r{t|fYE3t#z zP)>`|Wb1cc{8z)x^k_$LDlJBC!%5EHq_D?pe{Fm}3X<*aJCpn(;LgdpG4(XMA*^d@ zpun)VDbm~ud6A2S|*}!=tOV(U{iQl+fFItZPp^Bp&s48u;y?!hCWCDbj5R zY;WlNu@avGyno-7G4?Lf_}!Rvv(SqroIBx9SN&yr7}I!8M+h#j!_d$$JirHzfG02@ zZ3QDdV-ysuLB(km&^l*7ksi#1XlQEFrZ5V=|~gn;-xQ zSjkA~3mU?-IGh;F7tY>e+1h@Jb##)8eL%Fi6@woS^V(8sPH$2TBzO`@~%NNH+_S zA;7$v^tSjg>4w2i$w%e-C#*B(Cl8r!Z4j^UQc*t|U{|^hm^MA1pWfostEzB(HH(h> zkiqYsI!>SmxR&wUb_F#drT~a&f98JKn(p75g24o)@>lnGJ#H0LL@nLw<|i2`o;EfzCb6=DLhJNzp*uo&tI&6YI;H>N&daI91cIAqeo8Q}UNocZ!{$)O;K z=*zO1uYs=Dk;8IRTv>hQUCnZIB=NQZRfuJKikKVh)~!dtwJ>D@*uk0WJl+PBGbs6T zz&1a!SWYbLN3mrz-ogIlF_iI9`LZIw{%U&%3bXK+!wev2NOsqyuD0B}+Rl3^lSD$s zREA(uA>+~x+rrrdu#HdIWS1HX_W>LxpjDc_M+tB1`&Przi<+Z1!axrN#(kIPJ=dd>Of|N*&On~pSVmrPiR<8MS{WtE6lxz6B<_3$w9IV- z>jqu{YxUt}sZ5|j)m;jtsIzHQ8o6+(L_uk-p)qKcfGOJne?W2V4r!Hj+w6#wVuTQO zTM^45G0NBr^LY|@9B)(;jHtWRP<3Rhoo&GErXwd8QRn~!@WO*@06 zg5%Y>!J;o1Uc)9zm#I)80rFYRbOkzY3QNCvn>puemVluRB^%5EyLGJc@?g={#swL| z9qLINt2;Moc38Gkxg&+-S|$?jKYZ9N5Q%-%i{HnvRTIuNxC-2$`UJ9BgT!pAlaEV3 zjJYmyhw{vg3ii*O8CHhS*nYLRjz27O?c_9yfqL;_olP#M_x!PzmPn;lMyHPwf$)us$J?ky`-wJu_ZtMwBrA2SkN zx!gPYw+f^*(!aUym{ofor2)L1KF}g?MW&Z-CRG9eZQTYs>lPV)erM4XI}yC|*F1N42MHZm-LT4R#I330mnA7A0tzX!C>+$t2h^vUzw7j!8B#8%-Q^ zx|6@T^jF<+SsmcGXyv9h<*|s`6r1k4YIOq+P5aqAdFJ!t{hQ|;+5`NUy7yZ)I>Z+h z)oB;#T)j0J%pqe{rdw*6GH>ID`L)M@+rUZ1rxKl8C51-X1F;b$OR#%Wk>HyWDlE4GI7Z)%g?5HOV+oO1tgTh}O(e z#ca+g0DsC#5jR;!>@Z!ndYY0zduuQC?4nX&uo`=fLoDC~Vk}87AaK&-i2Eqr%D$lhW4=kl zsO`PpW=cCOWa>pZU-iAHNIn%$RgY#`e@sT$`f+EaWo|1WhCYQGTXkT?_|wo=h1$x5 zVb)uaFWIB5iQ1hAPRmN}fGsMcaz9%HJo)$%bK#{4X)_mHDb+UMSsSCPoH9 z$B#hob$iQOB2AghLC$sSVORA?IfrY{mEuv468$+JmpmuE>(C2~_P~O~#-q_slmp`I zZbtHCw*5Sxu=q%M_`VgcB?y$;Kt7@LJ(2=bOFu3(eArQOQB;9e_LY*P=(mQZyC$s& zs)%;o90EIe`ra?<%9;QfO&~>_i)d&N6!OlZ=^jX+?djs5Uv|ZF8%iT|lrR?XyI588 z^4hzY`1r4k#vxB?_DT~j!#}*<6@jH3if7p zJyjmx5mf#ZnQ(&@MM3C3vP(-YNT!i=t(3U!J{^prM0an-SLGt)&dY+>A-e| zK1`F^ZBYrt0O~NjvYS@f~i1;`LHmj8(%yRV4el+7y)l((*Ehlrg z%_Od>);FAVYK*_t%_?q_!?rp@Z8Y5;qU;Y_Z!@Bz z%9a}K_7*tji^qw9+Y8`hbe%-*Ec>oS^`^>a7Qmj<_vR#7=mA)xj?E-j9MUUNB7X>H zKECFawoG+NZW*}@R6fz50fbBH5&%a$%QTk_GLV=ti@VIFE0Y@q)3{=RJdxG zAt!JutKyIGQ!7AnXkAem)&k7JH*=2gLc<<_{S&y1oP40BSVe~6cWN|JU57W;XV#dK z9)?3#zuEiPb)M%lj&vCpN|rGby_`8q;kimcR-Ql#h7#ks>A;f-sPXwW&Yp=H0WyAW zLRDV{30fEZg`lb7EhA8tRqrxedYj2w&7MUT)_^6BP(!r0Sw_bv$D?fzZ$~tl&F>;( zI=Mu|PHMOWS5D=&W+^vBvH7c)&(WOw$JFzw1PKqk9r&*~WRoJL0}mQ|nH~6-eT#+U zmv7aqxuW5%>A2f(leC;xjuyAA& zbky3zs*3I69scm_ZJiFc_nlZ^i*@ANdF+`a<(qS4Q$Z*0$c72y$uS*j@1^UXHPw?J z+u;b~wPoqv3cB$Zbisb7Eg{mvi*>eo@Rn+c7|;9{&s!#UR&d-=Isi<|oMqF;QDlt6 zDy^S_@`Eu7z+SD#M+a$UQS9{9FMinJ4EJIMXvKYn#m>>m5T4n6bL5P7Pq*^P69fZ= z8bpUZggJ*IX?dt93K)O}(yyBC?$-MD7y*yJ3CnYA!SHhfwsM&Vz)=QqU3usGJ&#?# z6kpMl$}U?hy{pY&(XCzy0^)P&b{^3&S$iq&(>|8*>eA921Esby{padX9-xkj6;j|V z*XAnuqq4)p;(yKZF(ZTE!(ZVY;L|5uLWt=P0&e}#=;+rPozBmn1jqg%1w4bdjMWZZ;$<^RYG1u zAxBy}eODJ8aY&qq^mXBkR6Q39ho~fJk)i?iwMF<~zH1_NCiq+5&#}^!-`R#1<>;gxT$&9R zK(-iTS-(cTI%r711R)@uk12*Zj1%H<>!Dlwa|R;IvlFBIeQ2V9a8#hGs_MpYIA&Ny z-987-6>COtV1J2|46D*Z?%Z?fE(*e~B0mPjcO1ofOuc9)IN)V$87}y9xGFgD%}l@; zDP)?M9q!Q|2E6!uBRf=40LUq2A|-qUtqvw&cw^j*baH zMfa_TZ0$&|^M4t`@7y-3Mhu4XaE4fva?Rsj?{nw$!{a$MkbFhJ(!qwFR*VGG@nJtD z?6TYt(m54WIj~AzC(3}V7j=}~Pjj9f_esC^Cpejy|rNSm6gJPztWAr%a0RkM7CA%IZ7vSGvyIX5F&s><9@qmSfcDmp`>eg^9r))Tvv0G$jDrEEn7r`DlL~_* zH!Gl}IVHlqc=SNP2_j0c_#EjUeV%oVuxjJM;nd&YGcal$+%eGy!D-lv9tL2q0U&4B zji9veRwKPOW+P?q-1p}*T(;RfJFp`zlllShLXtY99U*1aMSEhlAeskR(%dLNGPg+^S_%`xSJ;+;1%FHFv2VuSe>2d>N9Ss%zZC4*^LX{tx6L z24>xRSVRxYYCSI5)Y!J>GgBSVrmxti(6`U98}i!1==TCHlsNwF5Ypw5a`}uqG0>Ml zgfthO2CR|Zzvs@Up=)^Y?s@0Mc?{@0+S2~S<>Z9cGvwk;0$Wtb50b?rIQP{8TK@H# zy4TN1nywmf7JOn7Nlc^l9i-HA$SX1k`Os{>eg0c|{{b?Y&y*AGEb^1x+J*vvgp6 z5(@rx611$wBlL$q?$dpbD>9`t8CCO_4MYdgBCl<`La~k@?q`b@$=~0gDFU2cFO9CK zehQ}EBzty~jT7jY&b^X~2As(;?9VEX?Q6}zG!*l^m#n9#O|VYb+Rv8U8HS9@Ibery z<^Ow+<|pXUj7mO4GoAEVEZkL;KcR4$%NuhG4^^+#u9a@tTKKhv&6vbddj9eU_#3k| z$I@1gj%Re+{@STaSDFn!QTpt7>}5B0eYIgXLMdsMnx9)*RzD%62SRsm3qLo0ia;^(l?^+?-=SAl3eL+(A4+y z{`&PR(({CR)`V`>zvB|;)xU?%FcL;Z&GSduK__Gt52ye)Om6Y0XKP0S@8g-5uRW9V zY@GF<00771i|Xwfi-VIHy<^!sx)sRFQ8b9%wO~YQ($SJhcfQf1`O(Vq+uEfNj;CD! z5;(lZp|(5z2!%WUVTVd`#P+76*2jG*T5yNTcEaUnC_5t;OpJ*DcedncqI!z7e>|1H za++H{WRS2==-E!}Bd|dfpjJ8{I4ncC$P)Ogl0teb+HOkZTrI7K79ZFJ^ou=21qP1e-XkY z4mc!Ut1UJldI#F6?~|p{`#oP~7ZYc_&_qp($f;NlZqPs2sXnO;&;j(i8{oK4-%$Cu z_@xFJi1T{Rt`wg+QHOcP=cMa8f8*#jgB7)XMlQDNRh5_3`$+-yyAL2vx*l6kp><^c zes5W&XvRaH9TJ|3Q)_<$=Sx>oxtnbX zF!gY$L2!cJ11M(Z3IEA@E04u6Y^5Ug!1D96Z=c`z`?j?ya5ETH9bn7pXY=8;XV4^d zLGgffG_%x9LQ0RM+dVkk=$QSEQ3lLDBOLgq^)Xc&WE~`del}v%COgv!{9(PS=aN#w z$N&oP89sqVjvb)AJq%|OFHEq#?YDhaSdf$R0r~^@4rN^PeGQP;I>V^CUkH$O*WbLU zo*h5zu`?2@r>PmMOHw!i!dNzi>jCK4tBnV#00mLDK3)&efet)uV0kT2@=)sJqoSVM zGL-D#E(`z`N|06?X7BsU{y^U*EEyk;;;>vYc=V3zlibzzMkWWpZRwF~MXU=wfaew3 z=uzRcq8l3CTWr)4-L))vycRxK1z(%|p{Z^P;(X|52^{KY_m#c&qkjGTPG?U%8`MFL zB{aZeB~Sf0>O4gjn#5-m{ENgP0c!C+y|yVUnEKWNYP>2y!{5GvH>h5ZCi;!V>kYYb zgTmNmnpAbXFlYnKf+?1IClNgD*uyz_$?i>n-~JRJD);CzW|!<`bb+6!DvN&tpreXJ zm1;x=$>70&NzzZjx;d$Mw(be~iNuATjPUd~h=gI+NhTRjVZj?WWP8T#&9FuHchb>7 zwOrT7v}}@Xk!Enw8Y{oC*HCFX_{-Zh8Ev!N#oiE7yh2lWqn+@ceG-czNY8Z5Yl|<(}B;h*3Mq!ri((a_4 z;tfRfx|R?DF=<2F^9YVNi>cUP9ok@k`!Z{v$;8tl_tu+KpuchdyFSBd~qAK8>M zzbyBYp^rVmt^gS{gPX^6q^%?hA_aeV7`2g z5LNsZfz-7N`=f%%q`iz|I=d3ZQ{YDnC20(M1)^EBL=*8zvWx&gnJ^%BIf)8~syYQQm1d5(^P8=%K~!b?&W(~1LlU$ryI zh187WR|%eVjEgINQ*4ROqm}h`BUJqr@_L-0F*Zy@g27Z0mW_k3ML#Ypde|yq=utBU z_x$%P`lu7!hf9Rz({{eSHu_*u!r0!3#K#lCjf+70!Mw-StTZ@b{xyQf)%u3T~Z zPJ35eakQrJ-H?(a%jA`?dzOA@YY%m zueaH5I~26aXkH~4-VoY(oj`R0Lc$hejeQjrX{p?S}PtB;>~jtvo&lZHt9`It6R z_hPn1e8vtjLi>F?L$8W`@dFOqtfl^edHuN?W(kAca0z{qK2%CEw(VO^$2)i8u3u^GQua6{mC047K<|01w6QraDagxlj?A9Q@0>;AZOC65b zNElIh&-zBviT24WFq-{`+LWwIqDHds8!VW~i6?J_nUUPF0?E(MYxhbQNe9@RAfKB< zvd=)^7xu?&++*S{GP6`i!f3nje9tB;^xUc1ewE@U$OrHBeqen$>sz_QB70AUa^E~X zksiaDa`?J`p6RW^B)Z6{dMwhwkUG5szCbw%xq!d8hBs~0j;^8@URR`#e-lGK zeTI!ZiN7zcaPbB19l2Mn^@S9AubF&U9#!2g%3UkUIT(4hs4vGg;E=cGQ3CgSE&h{o zhZM_LlCUI-bbUd^lAVX*fEyB&yC1~6Z`C>Bx4j^!`ha$k75x>~XhJ%+0wL7Fy((cI z1G^M4`)?6f8bMR&e0TpCe(6r9rxlETsf_-bhc&~JD{?VdP+D8S(rV1BrkAzbn#9}X zwOJ-%%z=NX<*($?2u2f<)W^$~r^d{Ga z-f%DFCBvr}K<4`r+ZGT7jG&|g&oRoLOVFZ02t(}7BwtOFXKZU?`~VtF79d}h#l3c1 zpLr`!DsT)c1bKVbV!JdM&Frz+Ws^uLnwAXUO3_#68ELd>Xv$>_OK!-K)%Mox)u`1; zz%xpQnz7ee$>iu#m`s`Ze-NA)ggWq3hL^acj8GQC9Os0uk@s~lR{9q6soL0Z>t9Ot z1T4I__X&hl>)mvGmTS1TtO7 zD0$uc3$otX05-E8OUf*=Wxqvka1P z8?o;YkEM_sMcNmv5R|w_5hY25z-v7H^dG*sP9WjiM8Wt{o0*~fj^ogTyTUAe5}kW- zB=Ik6UZVpnXD{J=8{)1^+P42%K;*-q`mLHBhMJu-?Sw7^;}Z31w}vT719L;Gje}XR z)WhngZsk|ueYL%p$5M7jYw{p7Rjo~o(f*?PhzslA&(Tg3Ut_drO!d%rM9v2bTDf3^ zk+~Sn)FX6}^zRwmc#Uk~jp)br-NQ5dKQGO~m34|1gB_i!OKiha$zCqG;tjufZb4>? zDPgM?ELo9+FN_~p)_|MdbN;%~#P zy`)q*^8O~nY^b}9M7sF$=C;VBFpNy$c5nUHW`fS`%v*!!*aYxIX-o+S*1y}Dsx!|; z#DWm>g`lwfy)g%xc;akEL(w+81lgXh#yRSeZ?-w(y0743NXOT`y6Ja>CAB#&TVI}k zjwe%JRo(gE`_Xi9$_U00H}Qq9sJ@Kg>7Ekah_R{7bBs#~wGCq@-;#F8%n%vHP5Wg& z8xIv?gnJ~9!WC_{X=}N${(gtNA@W(@jWbQe0oT`gRX4p?66?ZY3s}!|5_7$2gTX#; zzPt{?S)Yx(YS?3^=r;!~>g2hL@IHIcYtxiCjx8=6x>kMA>g}!~xGvCl{vK}X*DXQN z?xiyWjT80(jx{UZsAu;rTEY=YEMyXHrjoq_f`@HtkER1H2$uLf#)kT>yXlu)X&=9T zeJc~ad_d9fa96ajV9(Mgcg*tOW1XM{i@TMMFEL2T=7%xf1Ei?4zqzJ@w%2gyI%nK+ zKM^+TRIB4$lv}gOV?b1Umya#v6=_v8`dZx>HDWtAH;dPANrm7CzNo7)ucoi~1)m6K zJQCd@Ye%-)I_OK5q4C$idI2Z>|DBJ3L;2pCV=32lYQMzg-Tiiy4!vt1`28~SjM;duJGA) zS*M*uk3E=D@`}z#JW1UFc@m%gw*z-p|8C#g!?opZr-AA~sM}Cd-M;At^Cy=b01!M; z`-&?~{!4JF`Vymbl;||g=irVBQ%TAbaL)XQlQR9Qn2$DZDps^PY52}^<8elarp<@2 zep|A{be)xLjI4@3H#l2!O4{S6aI<;0jxr-wrbw~?LDWgz9SmD z6N0|JKGcbijXgZ9ff_k4u#F($#gJAT$G_NJ6=g+KoTLjkve*M-xq2`gTVFMPp68&6M>Gz{+o8@M4o@z>ZdGodA0$C7=-f(0H4q>@+L`tTn8D zR5yUIS3vQkBR4N9f83FCYkaFq7$E!6k!*5)CA_a16F)-XgDZ6h+Kgh(k3k|dc4P;h zMV#jL;$!St2=z;T{6>~4AZ5j=Z(D$c*H4?f+I#EPm=@wj>_DZK;&oV+?nqfakhf_A zekB?(PUSjPjap2#M?@XeaAeYB=x23`jGT2xBgSUXaT8ZZ;e6#AWB>&&QkRo+!s8~5 z(RGfUUi*96ppygayfj@Ugo$STy7=yY0DYd_=S{t-Pg}1{2m`Zx*IovFRj0IiXrtbe z(7X<{fa`h7QoEU!Rl)4IW(t=no>SidFl7Mu&K2-X=Y{w7GZO?;y{?3LO;2X zQh~PlTfh{(51iy?0Nc`h6h0O}rtvnqS4J@gC}05%MxyRMh5ZFKlaTqYJQ?Cj`1$h* zh5+dV^kL~x`J>#MEa@5OL~$+Px%FvwtmqL983#x)nwMy4iusH;r)w(s|Kr#kF z(~&%8A)?7HrVn>?x~q-3-YFA?>H-r9@Hd)4x?X()RgK;$QxXgbu%c{Ip-?^glMeR8 zBsb%B4_3<6V+GA_gQ$zX+}C>h#~sr{+$SFgkJgqaoVBo~lv*oQLyyVM!pP+)Nm)bQ z`tZJJBRtm-!h1zK#x53WNuO9om|Cx(o*zm^%MVd{aB*NR0h&p>b6YiYbVwz3@pXO&U;M52&^lroGA|WLg$FXUvxFf&eibxrNjy1K>-m7A zE9$-kBU@PfAy4aIc`BLZI1r^V9KH)IOG;4@-zzwpBrJhc?4Tl2VYht zv}pCuOx5bvH=MH=gC|^tfov#Xp-VH`aFZckxGe~v(ciyYiEdqBgFlv-4B5k1WzW+R zA~QfJN@0{9+T|DWHAUiY0aMIF)#=h~H zl-ZJ?A0)rI@HOXeuQS||LU~CXtSP_-`}zF=sIy)5g`@B%-$r(q%ebE8a7Nd=M!z)M$Z1qIZ2Ec@mFcyY$f{FseM}Rk)!k6&PZM_O-mA+Y@ zJbMtVk~<%nn3!%cH%>dv3;4X+F0p*x=ZCgHS`8{JR*E6H%GmX}Cobg^;mjZN+MYTT zWia|4>TFXMtJVfl!fpQajYQh0Fd_Fu&O)6w;v1pMN=@8V9lfLYfK zbfu1F_#vv0c7NmXuB5;n%j0D`S9JAfR8LMlPo>L1-M$b+8ctLr1|hjtA5`+kP10M&c)n}Z@v+T?YU+RWF4g34*yY`cC0{YBtZ6d=_D*wa0s!*4Wcdv!4TR{@W z2i_+*lKNKtwR&f^_suk0(h^M+a#W)&MqxtM`*k95WrHr#4YWQ>`$Lwm+|hGvy+0*5 z4t6!677LE2mT%hnBP@Cq7Z<$6SV~3|HB9+8o{X2iWz}_W$ zyV7K^x+{RFUFJ(U@mk!6Rk>Rk=}$+{iJ#>sVzb2gWj>In&i<{7})0 zyYkAOBIC`ysi98~zvwkr?(BtE|MXYkE@g2p5=pnze;7mOaPNoGUy%Fhdc7u{2SNkt z!^gPa#T{vClAWLsd#f4UE(^*IuFqyL)$bbWf|9}H@wP%yup5cNH%Rx9srQ3E>plU|IWa38pr_4V}k;}}#Dd4zI*}}1f zrlSh&3E~W&o7BvH=KB|#c4?y%fJf=0R3`@4@RZEwEvI$jKR@;3C06W6jZOq4V&m*S zT8idbzhNw+oJ_1EXJKT~p!jVDCY)()QOeHY;A?-o1^kZ-gk0s7zH&#KB}ecjH{-Lb zkD=P7@?7X+=|qbjE#vmX`#rm1|Jz4z>y)WIdGhvCd*?i8mW>{cm}8@pay2iNJ469y zprRU8M5@xp;cKT;gV6V(p4Gc9?ili6}iAZO}2GRFBiY&Gv1t&hB{pmb-3VA z7dTgkW+xx#k=uo*DTglnyaB>^a2Bh840TsHLHYhl*p+<$sVLXYPCkHgf3n4%V_T{p zJ8W6$&+|=;YyM(8B{wmJ_WZuH*e4WU(wqZm4R1lCt@Q^~rmW0iVOlh?1y@ODr6FPH zD|+uiD%Y3W&rd#uXnASe@j4LF$lXnImn;lFb-)DUXgVMn6%}PWahV3Vl52 zHa(LTxxQ*a{mJ3Wv$sG@L@!pgnGIr4PU{yEnuovX48FKz#x*>zNG$MdBqgzVO*A3!a0DQ1fR zD?=P}v@_a6vfG~;Zt96Ez`lOH4RzEkHf6N{P(O8#>#dU#7|)cwV8 z-3eG$&Yp{fiO|tVfPqu-cw;0N>o&fBGX{_c)tR{UbeO)VsXORp5!*A)URJoQcGW8s z!2IdPMCqP@yDS>Noj|m;Wq6Tj_YDG^SI9DIGwG15#zPrEp%Tr@0)?t;dt#K**7dRd z>@=i_gd4MqE(s#`?0x6hZa*FYX*ig`?cAM|mzUG8wVGf`xz1yhM%r$zqvu=K>$TU) zjg|=`MVPNr#KEeq5qAYW_Jm@1caZP0O@E)Nz>N5J<5)QClEEVnKYA82X zXT2CAONSB0RN^ET-o88uRQh>CIqcm`p5o9pX*76KL~Gk?O&e&t8M_}+>=e^3yQ}(S z2IkRm*&qO*aKj5H%@Oe}J#0(3KT|(E|MS+3tKo&E&#Md|%Ut5(+%G)01!q2VwAntr z)Rus0t&Zdg_l)82+-|OJUN_^gYfJdTcT(^r|Hfkcp)!Y#O3s0uuL!DH?Vzv zZ&t{z@!TSaH4_#lVhf~{qw9*Mus2y9U&PR)n@rSIuI(?14mL8PdQkRf&|agl`g8Uwpu1dvj9ntHRY?TmbYjXnzr0+A2LZRjUfZIjv!N+4w7 zoPiGgSCsEXK|r*Q#z#>AeY7wEFXayU2<2d_;rCrp926&+ACZxEd;$e?DLut zZ@4M<{T)ix`WP$Lpj3znJGjDi&iV}>`#DmIjpD4dG^VmS2&fRN8%P0}AZW2u;zT`D z1{^^k@!`tOw`kV$$6olmjw?O~vdtnZ-1{T8*kNI|j~^h8De=}{c%MblJ$|^1K(Yr2 z**?wD>HWKEXt z@?OhsOEBMX>>gfQN=2y_uE&UEn_~aDU44W)DSf+0cbwFRj-RoV&3_^*k!3HAohmtM z9Q|tbeVA7@FI%ToT=tgakDwP&Cwlbrq(?K2InhFmGf%TJ5_d3CDtWjuEo;vq@%InB z_zg96=c7A9aeGZqp^_=E$az~~jd^A6yPn+r5q0c`lQoL54=YDUk}Xp_6|4-^&leRL zickhQdA?>ESbDKYDz;!Wa4m3t_up3rWKJ8$QQ7Dno+b&;#h~G}%h-+C3DaI!N3#Xg zyoER_plNPebiK!`LJ{j+9IL&N7TPkr#+|sNWjK&QD+Rm_ui~B~$gGt)Rg!|5x7C+5z#i^44&+EX_4WJI zg2d@&S87q&A78+LzXc5CS^pltui6s6nYo}D&apYxe7@tdLsqFX-6rbgscZS((P$-N zLT4Zei%fw7>1h&Wx0rxiaYgy9T>N33yEHR#bFrW8iY89!X16 zG*ydZ)uld?%HhSHopPRsl|yOLja8#Z;4%wWB7a{8=Oc})@y;fKRkJ8jMMUlv%$WJ) zf#u0@uNS3AaZ{4@^Eg9YP0PLJ9qXtkMq`oo86IZRppH{13HbeUeqVsn&KHJxCHaJ}GbQ_acD7=@zSU{Z;>Z^hWc`Mpugu@6F8h^W?CcQZRM5I$Ow{eH}+ zr99ZqiC!CGOLHWg9ITwS*A@@%HGtlVYZV|6J?+hFK(l%W9UpTvBb_4b#yp zFrBdf<&zxMDzGuxDQvS=LuiwrQyGHO{Rh~mLFEj#$-j$Vp`eaoI@j{Cw7u*WcTQ_M zp=(3K=PCbuy|TE3vD4>aMVW-MH}u@L=u|JRaxVP~u}%4c;?z^N*Z>CRCEV1%nb zaou`5Q7_*V6q%Z4J?7aBJcFj!8kshjWPmLFbYA@PYL~4)qU@(W1M@hAq)1MFK7OO^ zC6Ro~p$w1+U>w8ml-(8&)oKW1-~l#Kt4xnn^4|WBOT@x>Q^Br{qm!6oZfoQtvVh5t z%Er;q*fE!ScH+D0Eo)6e>}!>=mew+h>=bW z7rVx+6qgPr(JY5aOIyc6R@LD?Qej~IJ-yganBsdv*boTcY;We+m~Cyk>EK9@hj-rg z!96K8mDHIO;zuqUenjN7ETI4OrZh+MC)cP)m#JB1HUL9GzC=ml{}|_;!>{RZ;O5KS zu(qbd`#9a9{2jyQ<~Kt|V=*`EFzeazm!vISmgB#QBiV6MsGj0yk+;;dn*dSclTyOq zs2JsL=`WII&EXl*A5R9*=Jm5cWkAuX1( z57Sivj0>-gT)te7xzs&Xs>Hgb@bJQ{?2qdIcqY=5{=iyME|iHouHCFQlnY4@T&<6zwoKf3h}t8dbFT>w&p>F@R{=5&*@h1#sl+Y$4{j(1?aNyiOo3 zkqcxQyvMPg0XuCPNT|(MYeH&8z{^oC1K!%;blH6*Ok_+R#-n$vs8MR;;~pKu$*ooR zn9T$LxqN2b_n>xHxV3Kr6Yie|5lloiTvy}jICZ4{b0pudcnk&(m^9Np%R|tlFJ6_` z)T=AwqY9el^U%{ab-s3A^#-&>MJkG4Hfi!4?eFa19;=U(Z@WVQ;9XgPY_sl9_Ok$d zRw7SDwAmWSg}*P9@~y*!(YZuLbUuJ#L9Q6FJ}d`RQ7r(3g}yvnF!xhk_m@C%*F8dc zP!>@C4H~aW0{}6LfN1VkyNpP4t^F57WkODlPE)%WGlct#){Boq%1uZZt(0$+%ibrN z8KAQ_|3xc91hV5K$k#}&+-@q!@hEr11tXKm^8t!&8!u&;*+9O3dadoY1Q+dp3@3n5 z1Y1fO-G1wiS+{~ZwR<_Ra5zcQR99qLw{n?E8PN)yV}?1ZT>)q)a6as@G-#@s!=+D% zJxy2G6%H8&;UXsqZ3&=S$_Kj6Ro+gJrr=;miB1@A`H#tYUH2x)V4movXa??@`7dT3 z>Zt8)eoELElEm;Jb9zurF1z~Hi4m6A&BY=0#lRn7d6o=(QS6G{ya5E) z)|{(TyR9%JeLOeq1#z)+Ml*hG^hE&oyj%aVYDYMy0B8M7{rZ6YhOdCiJu^)o0}fzx z;+RTz`Q^LLZtpZ65vP;1T`8cjM)5UJ06BQ=YOMtt&AV$c>P@J>W>`SUx6apSut`Ch zh|5qDYyp(35{$`**PGjd)PIx$f9z3y-$`(2)%o-1%~wGlK)NX^9_FNUg!>*9) znLRPrQK#>dN=+zW;eFY}j>zjdC3d0;dcSB1jX@o6ay?u3cntQ*l;3wTsR1?`F6VWR z_o+|wPBARp|MpO~Hv#-A*AQ!FT=NRozj_ZgIkna4gWIVmL7r*WN!+I!*^ZR$mQEX^ zI}1M_-!zz^qes8*iR$TdTvbpTwNemr%(fp%NC!*~fk*QZel4-VX?86O5{65u1^|tm z5w^4ckJ|};^5^ZOn34kH7qC|zMF0XPdw6YuemxN#AS9@7xk^cSGo`u&08&YXKE-6a4zkQD(xnT1vi z8Q@3jwJ*@Z;+q#4r?MsSWi{XT7gY!lZJUuxXl{(Tv+p8=Hc^fj&n?al=ON0z^z zFu1_)AHa11yt&Nr<{gc&XMph;1-xQf0gex%#;K;km*SrJ>67_U@aIj*e*t_>urQ{4 z)hbZ}Eu0(RBpTj6ytluYQ^{x$e4)&pnF~-|-6_;&oCNkCy`$tdoIj>>}=Km;g76&;1NdFVL`AXCRt=tVh!70`T|@ zR^Sr4e~t!?n5tnd&_h`@Nlem3XIq8TGs#D z(|7OY_Wb!$HlP{=nE&TKZ+)o+O`c#^hCJlzRzF;QFhmE`^k_b4uI@kY%Ga_DbIt*8 z&s#0W_hFW`M}ph?1A>QY);YKHtvuO$v>Lb*bERZ3vMH_l75Wic?7S8*OY2i)jY za;0zPB;e7%j2;Zl?Ah-RJUDm|c_(p@d|?oBX;I|gCyV$ zWZzcEJ}@nxz`(}8EdAhvgCe>!Y$8%5XF3|xplTD}BmTo6!bWl#-?Ajhj2}5BLMt}y73ZkqNttc6Z6mYNEb9X@2|jYlDIU literal 264215 zcmce-Ra6{d(>00(NpJ}6?(Xg~zyO20ySs&;!5s#78wL#lf+P^!-Q8V-2MEbOuYKqJ z*ID1ixj7fJW_7P#-Ss?OwY#eJu2>DABF0;iw{UQ97|Kd=AUHVGX*jqyxu^)RGe7d+}l?=S#;4u6C@q-_7tFnfJ`&*$b zC#~&odj9J0Szyg)E1KLe?P9qRi4kxRAyKsrxCyJ(rcK(sLi;P2q&*GZj1kZo2n-mM`@^SD#l+ItZio9(Z0?{>xknx4-Qcb}Ur>|-2x7%D&v+tYrt!Ed3-yR>J>cOX}jILrI_a4$)ecdiN{Rq$2P-uFBW~CoVyux}6%Us~tBy@FZ*)v%2=Mk~krdm6b2ii(P*QFe z#5q;83R`iGpoo~buFMV9&p>=8t_aRVG-jI&{ubY_f}4~@vav^_2MyC1KE8kxGfhdK z<2{!}lCQ8eWFbyOk3qaFF3E658ZsP8luf|*mW}wzEOEw({MX-$p%GBJzl4IBtWL-Z zMEw5tj8=yFglMDt+&lQgSF!b4ra0Mib%L{ro1fn8o9CQQXhn5NlUR$8_bI7hP})zMRb=4m+mB-#=}hdb~c^*N3+fc>L3PU3n4nu<-MmUbdO$jJGI&OkS^q7v40dWvTZ zcyW|o4`dXc+sRM&anHe?pb3)Us3zB7|8Vvr(YHc&_($j$76JavB~h8xUxkFkg&XxR zOlXLtnze~J`5}x-Ku*hDozR+Q(iTScp2K~lkIOGn-;kuvk>yA=k=c`%Z)GmNq!Dza zt~$jTf09nb`jN!ITEB$;?#H+K)6SfX(g{?vZwu_pgy(r)u9P#qQ0tCdeq|i4edB9T zf;1}fOw6@m9A~7&8okI$gkiAmYTvK~$|;~%emh$QNz`ahTJTh;tf%f_dQ~_#g|^35 z3k5sF&jfo7q~mn%Iv1&oc^mQ?D5%RET(@QNYJFDf$X|K%!!?#x02>h)bT3MeQj z38i)t8f}qUnx^@MmDZyhKI^q1QF8IQg#u!a?YS@du};QGiO$K7MAuY*<=$&hS&;F*m0q2Uf*Z>Ab@=z`C#*|{ zPo>4#pTDLVDrLy<-suUHNE9>z(rAj?xoy#9W=E*5Q-8@c$94)BWsb74vsZ_mu}0fd z)*swIaiaWh_cbp1+qh&q1`4RCkmq*~KES@{Yx!O0_lNc#00y`RV=F2e;SZuv)0Cx- zDC{qOh&oZ^OHCVBjeMTb7g~t@7c{tkDWCmudC>j2TcK6yJKc^ybVi)xrm;qsn=Oge4R!pP6g4L=*lA?*i4+pcgO&IgLc(@_C zmCkedj?eXb1wRmye7n3ly|x^W)*gLLgRG7?B}K%wyZ#M=jxPgdzXy^f?vDGC#h>~o z)&zYY-7eUD3C}hrh1nMsZSyjthl1k4WN4~9Q_{+lq+$l~+YKzK z^pcS|*gVZt!L#@o^2LqPT$NZ7>$N@9sLzu!VJn|Z)o+RR@B=xkx>ccrj2aRSmWGG2 zI_y1nG1UR%aua$2cI^#_hN;thX+b{*PH)AuGy!}nkvZBS`O*(a_PI9U9v>Z2101U} z+R9P+1eCtxQaVJ=R|;b^XALQY(|_{t@=fDy?+iMyic~P?|#5`Fz zIXyl%m;X7*#jh#^!^B5DMig+8h*@o;uy|E9fL~1*a&TgL-6XCADTr&BbmJ8G7O&<0 zjaRn7_taVI8o-&O6P|6s(@DpM;K)2_z;p+;qPt*#rVe8#UP?d|5|JJ5##_F@B}Qe6Mz+j#a6Se4SCCdn~Oeq zYYzZY+=rj;DZDJDURIir=C7J4&6m`hDW7jek?xHPf8dbd2XlnT6py~wNkUOR#t)l% zO%`QDs{Mj0O=3}hVAsCsK1*&9YU7aNu7$9G*DFv$-9-7-KI-UmJBH3CqRm=aw6@D_ zk~_#so1KgslbL||2SQmSHPQ-N9*86e(=33z+vmsH2|h3}XF?Ze_x-pN$-2t=fK6Qu zlOuN1aUCe40eKaU|Au9fT&3v3-S0i9y$GtO_T4@Mxd|DfK!s-358VS_IwV%ODQP3Yzio5dt)h2SCic*sX~b_|)J1EOA0Xr?#6^M`ToN%CBH zro2D;y5f-TZnS$1&8G`PNX(Qf%2?j(AjMj#%mHyRKfPX1m+QweA?rr~d364a&@dt+ z4|i;s&l^-R*il?}kk4;DXgLD>UzZ*!mj0el%rE_|mf2IoYY^c*YQpa|87#Fe^zY59 zOiB-0s%{-6xK>j?k0NRRERcx}wz>ezdGp0FF(P~~q6ywbjyB&m@!=~&{azQ8E)P{f zSKxFmt-Zby^>oxk5FQSNb9R1XZ;KsDJUc99rBp80B$v`p1w;N9(dmPRwZ zOmz+TP>uu2JLH=-r65Ji{5eB!Y{gHoKzlHZ?RG9H5z{E0M&HV7Emd3~`GN%SQnrqow9nbIk*lQa+WvF7cR$B@YGh>&~NW=`N zJlcMDlZtuzoH}nrC>bU!_-W{K>BH#;+pMVcib5TkDiM8+vhc$Okz@6CX%kac`5<8r zH_J+&Ba=CHNNO6ZD3}$a%w>xdJCmr87po)j922m3w(Xl$H6vK>m89RxV^|V&>NpM- z>Q^Xm)F#r)9q0$qXpAs~VuP)d7j#6fgzVlAitaYIiF7dC2^p;gvcrQg_2;J*r(rE}=p z5jZ{8dt=www1aKxxApBT@CzEMDBFM_dmMY`6n}b&SyZT+7l}P*a$+Pe_9h2m5VwM^ zm8Li-3B4yuA~}#;8ogErjd7lc(z<)bKBp8}?=&@>C61&YJ)pq-d9)wwls7Iwe)ZwV z!Y0o#VD6&8E%?I`=j-{M##7+8e}Z-O1zypwe#MZ79Tdud-;EI0jb-t+_SUwRAM1IZ zz&RR7Xr7u)9!rzw@Wd1!D5XEm;e9LskC7oIG?pF@sLW#^R~<{CxYIN+I>8qW186dD zk!YIoCLx`8zH2KI<$8Fzs{KO7U4%-ZIz5LvThD!aXB;R-zN-*sIE4u6!dllgZ&V_4 z3=*#&??Xx;zK#hym!#|sBsuUR*!~lnn)-H1&d9yBYi^b`ZudC~VLUe9BF(}aaf~ry zOmQ}|m2KiAp$o7R;KZL!t7sLkLJ<)W5u7(_JU^F?;F zM?M3EW=2lE?td%_w|_^Q@2E$xYJqBN9pyWw&gJd}b=1C5XN*=P%@Pa~zVPfOybC8G5eV1N+t4Z40~*-WTwuP&!GjL=UHejgF6AXr`X2iI}XSHh0O& zZ&U$NZrcQE_W8a72%q(K2Kkac>pwproPUbksQ;j3Ftd6w3n7hr#^0b0+P=qC$dke4k#Z7x2?< z6K`m|Fk=jqL3kEDog{wPD<61WEjE{dQ2haPkpHu0AJpK&Gok&(GXMUkw(T$yu8`=D z2spBg-4>d6V}_^w#HAR=TO9T2gxg5BxDx@p)X2dg^}#|JAJJnkT#bW@p!$y8=PeR9 zyTwHva<2RgSM;+*rM!Vg{&7~CD9Fx!x7(-OUHz~^( zXLY7@pTHvbkI?DY?0-X~_`kS!PnN@!u*=Iuix(hCq~i{IjfL6m>%ivfKs8gYi{`9EtO8dOV@gB_o5|vbK^bs%2!xawx|u$ z$Y#>(`#ji;bM>Sf;nsgx9TfoD;yGpF{d2Q~(^qlRJcCA-?DkUfRxopnYmD7^dwmvYwHYJ%Q-9#2zT;FvA0aZ8Q8ltf`G&;=ZLQJ`uMfi92S?^h< z_!`_hg55jJ8kS_W+&XUu{220C+~!qsyAwMnE^m^4FMj@vW;y9#x>nw`2@&ko)=#6%TQNUDB}8p3Y!20NbWo#wclYR_5V z0-d5dJaO;uDCuT!LD0%fFy1BP_WgDFjrwp$M;+GFL>~Q(u*8l3B;5hCWYy72!HYCB z?539TQc>~+D3n7euu%3Yydx)A&6qub7Iiv1)7(2^-;z#_5&mVC6EV%DckK0m#%Sph zSU3MBt80E3n+iCxsOl-_+~K5E9a{(}g*q+eGwp&LaC(WNwesE-01_3=Ilt2MQ!KMS zTMaQGpCku270rDr_3ccyNU9bPD;MD9B9h6EyxQ`dffYD`5yWZB7iv8@qMH7e|ay%2wUE9&yG z@iST)zq(d6R8PnSs4~)h^wWa*$}%jyeB={Gu1K5O>HZFfu3c}2_06pK`5aseBRoz%@|{Vs^Y`Fry~U<0H9r(+{#*hS{LpcRY3V^%CJ_TdWIs@H zNjM=F@Ed8gVmVQFu9B%-%=_}Vs~JM9FilaK1!#+La~@%1~#dfb4W#xOcS9Hg^C# zqon_N?rhw^GTck?&GYXc5`PzBycP18=vf-3{<0HE2gR7O?9g;I64yA(S2d1i(^^Vl zUtr`7XQAOHlxUbz_W$P^8M7nO93RvpQl*l?YL5;Y%WXM%nrSy2J0WDfSUy`rYo1Dm zq%v-heFF&52Bhe?OG=-FJw6X1@N{1Iy5zs33M{SCb ztjaNKK9ON@Z{IgN#xS=7g@WJg3OA`4Y~Edb6Ww~)pA?jAyCvL|{I9}SR8sQq$z$+O zS}d_;w}rLfo5jtGh=t3ZYC>W5FbBwqTAA@{=Zc#Yoh2{FN_?+hVl+pVw$p6=zkOG1~wVrYhKA)n~k z8=%(b5pfA~3XR0c*1t*#ywRcd#ikYFBkMC!)7G{llwtq5ZvY>6XvA1xJQO3DqQVxJ z4_JJlyFx#*EN(sc*-4#93{7eyT#32t zAFZzT7kij5yRsVm=^IbM!3(+}gRz*Z!jJ_6`W%rX@6VS@XYAE~_ufKY2O3%PS*G^$ z?ugPqwicGP8j@2|xDbr>^*w5%H*^;lzCLD&%Ns`OIURT;pvY=xU9C3J@V#r))vtXQoXD7KD1PYg4SA~r z%jfxsR^3-?e>5C^$HC>Osu(`t?(!*cHgn|HRgX+v<`(7jAQaQR8Ev4?I7)P<*-dDCSX8IKAsaN4Sxx4^ehI;|Ytq~r2g6|mIl(s7P2j{&}1 z1pdvWu!V*&O~t#yaRE&uWUkRyZbm#{ChNugmPPd)$O^#!%a*tCj*Wb_~uSUOfQLy1NTEFfYr&^>53x3C^#SClTahs+sCwJR8DP}0dCnBHf z$l!8i2A0T~7X1wy;GP#c)MTi9cDJILb7?EiEDb96DAlZKd_KFCe4uq-S;eXNw}EF7 zs9%4nNXG1`_65Y;V#MOUq8gj7%c3hG41zc_lo(Y0-_fc#rHrWI$RNF!p>9=ko@RYc zF$*Cul5bOkgDr1ZCw-YEsbr8lnTLBJniMa`weL*}eghuREX;q>8PEUK@kkW&G&peU z;n$>~_~+ZBkG6qTA39Ckme%fl7kqtv9}0^C{-Q|Sbjv1-U-wU#xHn}9Ug)kmwEr;9 zb5BF`0)mxK>D9odry>4My2@XSbr#-^J&^(>C{+QPHpE(<&5qHh6=Id;2n}_Q<7%7Xz;!DPescwvb&eAnosjw)Rq)t|U_Oms zmR-=myH=K0uOsu<=BqhYbYh0#iKjC)t4U>gk|wpfS~|QhU7O8fKUxHX`=ELn3pbTU zFN}O9Rcv~7E~{pR9E(S=N_13gL4=V*O{-U#tTx+J_LsvF>wV?pN!_peYcElQx?eaY zViFP(CUr@wkJ+#SS4?<^$vt(~-Q8suOI{9-Zd)B5O|mzT#6%_Gv`1X>7hZz!+^?7G z%gFSp>%IlqNrBg#{B(fONZsj2d_w$%JV%5y=7s&U`y@wtJly%a z0w&n#?VjV^W6gN(l&#zLpHY;ThffL|NWstoMD?AMq&_M|KwJO9LHvX8!V74Mlb%q- zf;}ZU&;}L68$Z|5h;cf*`iifu-`uwj7g-Rgjnx_FNnVAC-Bf;D<7vaD!Gi$LVkr~j zAnT|=f26M<3rgdSlN4f}ZxmU*i&7VY@A?+|=9Ubvl0b-n=BCpYm@gjIEpxxSd)GE?DJ{Vx-h zq-t;6Xc)V6SlDR}dJVz3F3N7He4`kAf|pc}2Y0-WD@>i7ia9KI!|vpL?2fA6Hs_d= zys)ShcS{*c1`TPd8g<8*%3{TpDEHy4j6aS|h9K)7{L;_(_AZcGt47b|jxbI>pbmar{tKmQi=cNG5sUEmqDx5UELps+EXO`%0>RazPUAp5%Fym>!&75q1v z^4Btqrg+|;V063KXzMJ}J9VjZ54Zc29-l)Mx`MSXJpILs1z%0k0I6p5JvjxNUcDpk zh;Uty1s)HSp(b>tAi^}W`BFPEO_Fk64`c^Kh%JwyLYSOTrw1X1nR0f&s;f+-=!3{; z6F88UaG{OJw;Xzy(7@$a{0?(Odz{PQ);O11PUFuIrRZE7WXD>O-KdS((xwiaVB<>S z&{<`;iGVRmoQjPaj+QKdXsop_DvuM=r0#-{U%5k^(!CMKgPKbDphuQ-fHKWOXk=P4 z&OUCtyfSuE zhd?vol0CyC>t2Tdf5!)#kl3!x@}swmziy6e350bBsy6|C z8q8IO`*fL#ewe30Ks67aPTv$_nc)7d$Sg~2USv@qBPN`y3 zs4ApZ)Bj8g++)2D&4Kjof}^XnktA7w^1#oNyz>juUM)Q{2aI|`r-WHL)x~`I9K)jm zI*m69kXP$1$P?I9s5icePPlxO@d;_G)Ot+i%ZZMfZC<4q-iEkwRus^u9u=hK_Yu*w zJdYL?H78C{5v-kKGaT6BDY$WsAsI=5q1gRi#k+{2MXTg7s>JHZAyO(G*)u*<6{XD5|zp zXfuMfK3?C6lL4CeXQ4^TLTSSUVS97mX9fA9*PSPyHI}Yx;UR&WB4e@*jy0Bj`UjGb zaJEX8s_TPs2gHLFW;=}&ukbf~Ww?lNCH9_7b@?+(3Y;IS^YPl|lo^`mvZ z{uZB6y7TQA?^Y2sDygcMcPx!F>aRTBQ>yLE-v8h~*iA$eQv0H>cb_yeu!R;i(CdwO z@Z50lX-S_9!=5#96~*R~3Y#R3n8g3ly;`Rso~lcrmnQK1B}+R<@Kxk;BGr4ArrTo- z_k@;FYDWA^6~^pqA}*p!E&rtcdm?rW>Vg^~3?3RlUVHiG11o9>>eRTAD&X1Qwv|=)=;!U)Z*%lfzRdYc+0xSu9woqtms>J2@edk+^mK|U? zbv3QU@uC)pUEc4E*Mf@&Jfj|w+mHBDsKr0SOgT)@P^%8{YI{QCgF}qBF>u>4N+fBw zov+q}O4!aoeBY5Y{qWvPF$(fh=yqKby!--Squyy8($|oC;DwF~FwbzQ%f)73OPd`9 z-1a9u#d&sYnH7p8d=DR=i?=_|lSge?m1KGI1IEp`NqoKjUy6$l`56`l*)0X5l@U1~uQ3)r=LtJ((Mq2p141$B}h_4zj?v z`p39AaP|G7IYP<=>&wLMt@NC>5eQ(g<`dMU>x2wC1ZyiZ5DKs-PqMCQm*WDDU%=jw zZ)12%01>Zqf0pGeZwHxNw%*q;C6kpCDZWl|A` z^=C1-I2#w3eiPGlWN8C3#|a=l4qk6qQVKQYZ~%N&mVosR)u&e&DxRVMh2Fq;szEtj z0CbKmy5Nl`=jg90LP?!QUoGXP;SR3$y#?|hK&PIrzbPjM=g0c!BD}lz8?-y^L;d!1P zOL&>j>SH4b^;?erH6PBYaN7(q({Qs!tqLh z-T6i>Fb@y?bReL4g&DGHyy?AowdnN;kEmhXD<9Eji9%>L(@p0&q#UTKyi}Vh>svy$0jJCZilI!*AQU3|J%-0Pn>6fo#=?CN@f?qd0yzNB@_FCKK*v19En;YM<7(N z3wdw`Hz^DUR1*gBvtIv1OEAXWHhOkzR-fY{|L=G_b}?y4h3lM^%P=1^&6@#v2LI{P z`q%XX_fJLHa58l-@0tbAi44@%`Qzzv^Xy?Sx>L>GoQ!>kh={s{gvm$o&!KpXDto@1 zbl_zqt!aAm;z~?Q3i~CxVxB!No>Y|$gV%})?^@h{!gZ~~lomd)B9^Hqvr{0;3s~ACLYU=#Gz%U9LVns{i;KLHTD{7EAnL-%5QW@aFI` zaqXq`fuQvP(|E@_C}hXzeq1caoo6Hxor%YZdrDh=T*PA+1kpLrWC?4|CFH7$Zat;% zwEn7GK_^T>!$jZxJB8A{lp4GU8kj)ut;4a;S=;|(2{tTGal%>|RU(#7OhZN6HTpIC z*7Niz|6^HDLKGmFxPDN(+{)h~3Lcm2zE3Oe{uk8wv;?>6iKg}8YYEF#HN#NhS4U!Z zrz!DG((mlEd?XC;EOixt#0Nu}q!%;6y>M^j6}X#bJ4#9z+H`y@N zv+gZBMujgLSOc`Kpl5C{VpX6OE6_xeFTmH`-_B3-q=H!(Rs?Uj4VJMu zl;?GR9&y%URdHkIDURux5a-pow-iUXY`9#nt^ksnL6^!qb_Dak^u~T9Fay;(&tTfkk7>^v^-Hu%xu)1r#t8sM(j|kEo=`iaxzZZDG9OQp^&w+RX`pJs91vG9 zneDiM6=}HIfUdQz5hT3_(Ol|?S`xgXMgM`d8*=8xYcS;$bT)UPpKat~P@X z=^B0&jxNtbA<=F#U`Cra7O-^_9)hX(&QivYNXe_ku*jFS0nqB)ZveERK=Ms_Q%8Uh zGqlm|V2zkM=F&0asB?r{;VZ^ps5Q<}wgW8hhG|)%iQ05m6aQ*cRL=nyK30H3(Ws^1 z=r?V_sOuMclMY^n%uII)jSn7?{x*kq_9Fp0Lv6`}&Y=}hY7wPyCyNnl6rN_)>2^UK*M-R`h z6^krI6n6*jKZky8yBf@T@@jZs&&G6E>5Q}A)!=rg=h%Hvh~&sY%4=^wXs?^txqvGZ zGW}R#UoHQ({Q=u~a94LIMNSF(g==*gej?>B!;z#HchcOGq#xCwKt}a^B_j2rB|)(^ z!rr@k?>_G2tjsdn|9KY(od63QL?xKE1Fb3tzy~Lz$8K2ThKj3EGq3j#E0V~k*@jHE zjvMAf$Hf1!*}k>^j}1X=mTdd0vSf|;ts+r$GU5CF1B00MQR718jJnW9p$^vjjaf!# zvbqk{6yI@6vWtZLYN9obYET|#q<*|XCr=K`Cxkr78{ej^&d) zIu%S)Lsx9eG6RQd(qdoNMXe-N2QmYfH5Lo`N;Q%B1(*E*A#yy@X?U$HHeZ;73tpt8=)lxu2*gippnF>{6g zHr#slJ*j9h@$8Q?C_udyWaZ(lw@BA?H;1I!3HY#QzhD#IY(+3vMED2W>Qq0bCHoB% zcw3mlvR`FP$n+oR>+TQ$3(pQWla)%Crn)QG?Wm>Ix9dK(;KyB)Xvj{m=--7kNc8AG zT9B|#q@IhSqM}>S(6`OoO{@>Utgv88L%d`$kG@ElSOU}a^787Q^*-e(K?@fc{uDXK zyi+EAhayCw&4PL<+jswaP;8#Vlc$Cbp6Hx2Q*~V772kc5YebU)ipZ3E9&58*mn2#w zA0xkS&vlsoU5g4n1YpDfA?WX0fITtad2b%ymQAk3^c3sGqc%0&GAkTt` z(7Z^)o8WoJyYLy0$Sy1H2ZA$1Aith1N~{zs*_=$sLM$-_Ab0H-JPdK=YB4oI`CHX~ z{<_MQ3${PDAbLgKh6SMq)W4lW+M%4n?O#uhfvN8wj$UedH-8gDHh@C#KX&HJO|zD+ z<|6VpO@S)8p=c1{Ms1}+Sl!+%&}*r4;pTc-pgkVgXln7p3&c6cgK-v ze{e$nT$AoOpA1bY@fTPN)fXLSh-Vj`WL1WwSL_%cNB=UX<1+`3HdZlw@0d-QBju_r zpaQ#yobxLiCoefYONG$c5+=AWkFbXql@^iK719Pqo1Efj8-YYHQ#v@jJXo#(F>o>n zahGoiC3p#`&>+MMxt^r?N7@s`N==y7aY`JqjK0st&$}nPW`z2zSq@QlRwU=hfv-ePr&>_RZXt$Q?%IzUV~#RCGZlo@~`< z5Wp}V{IZ}DjXl)VvM%OOWh%rr2wawkrx_z(Q_D}%BK*Y&zUNp-W~-6t1s|ho&=9<+ zfYzhhuV1mw(%HLL5ig5Wi-0`y#sTKwvI#k#8<(W4Ga}{hmd%R(?r5V0(7?SQDOGCC9)ikOzcFaDWhX69r`0U^Ca23+9+gbD3|n& zO2d$pzQ2GxQD?MnmQ~EO<9DTK%x{m2{=N}p_h;#u*l02v^yZu+x^x?C#CQc#E63t* z@{U8H(&#eh>W)LDx$f1GVmP6}5p?01r%ve6n@PFo8Q;={VmWcWnghbHxG&$LDh%N~ zCk-q^?4|e@!_Ok;^zgrC3Qm~0jo!c@&d)UD^KHilOwh9av^eC~bz&tN@~2ZYNZe!Z;rsB(_QRju!;9C5KY??XJvYTo zYWJ3%I>C(&+(-E=C0`_JThzcz9ZoA+(?VYti#G4jU|SFr9sxe+m3TnCU{K zn1pcN7qub6y+eEd@7lKd+nSSQhS5gm8b!I3akSDT2HnDfv&IIc4cYU$tI8VZQ$jOE zXec#SUO)gI5FB`NK6ZM%-g-)2JEMIA-Gu0!6$J*&c{cUKeW}LBbf=!V4BsVhQXAeF zunh^ebMv`;x%ACyA#s=#(4lek(+Q{~4T9y5eqPU^c-C{s1vz z)G~$YIUxS2-2J`tdp~@jeJLf+cl$S0B-ZsAGrv4gc-0BS91gHB*-xKV%_$7nNc*f? zVQT~;qpVj~PdY34lkbbGbKW1S{N`JvSnX>&YB;`tw$w_dZREJHf%VW?ugI0BiPIsh z(=kV(B~T%&`$vIZbBLxpR8swDW1tHpL>SrS9@R(c?nhJd&~TD zR$mw)vCG#d12=GtXpM5H^48C|v;-W4b9R3OKn%^i{=P% z2PP1x!N6EP8#$NZOOh$LP+Go{%|Pe*0p=Dnp-L7}P+U>caadY>Xa_cOToEckJUTjR zIfugBgN{(3pkS%yR-1=K+#ej^`6-<%8i^~9?I<1N1YUkcu{MDj#J|DTM)f$N%lO_- zMKtp!?o4t3Ets_9Y)eAx9cpQ_&&*QDpR@a-&`pAPT4Cw|T~)*V`mnpqojSVDdJBuj zq|7DNd2K&iqKyLMf72YAZup$3r(QmFzvFeHpSL7PKrWN`9H-#`1d@^KRO&XEpBv>; z1nYpjSK@79J`fme(Q1S*dRS8MHwn2|g&x(BKz#!~hr{r0J%j zb@rfBqJ1YMuI^O^Kf4G&z|G(uvd05+mK#k#6-k~JtwL}dHa~%td1~RbAgb*mplX1P z2ty&*{C&x6e!h@MwQ8Md&vGlD_;Yo6cIv!Di^B5kkSCo|;+x;kRBvm#_NA>IxhIto zM0O(ODCi%`(spk{VyKfFVH}`ph2?exNsadZwUy_N8KIUPxrTIF(sYdWCr1>9^s$5_ zT)uF@BDO9GGfq$s=hA*>HUxB@UIIl>i|nKOR$xpC$l)w>_aE%g+ee^~O+fn9T+oD; z=+-lg77F%0ntC0d40+o7Z`@sQytk6PPV#%550bo_Nf!S(T?VW2`|$)_CI8IVL0m63 z*EdkUp{Ohgw9lWI`=C0W%r-DlvM6)U!A{K)lWCv>1oSDlgKuq)*InHT_0g9$mV&>n{8k)1{u{}ZDa;nTvRO`}@B73G3)9$%TOm)eiQCiW75nU^O*p)q z3iukd=RMb6=6;FlacTdaCot&XH?F12;TK$KO=wOgV14ebyfn9k3w=up(AF{!gRF$gGY|D<(9zRPTWd$CTjvKety}=Qz&Ok z1vg|@Fuzi4E*~b+v9E{e1KA%>4%7vo@T-sKZ!-WNf?SHbnPVPd#NWJEF5c_;?74- zIMip@#E;= zLM4Q2r6D>?_d>yZEMro@xHKBUB%Ac4HbG)>7;EcL-W91GTq~#2y7HaV8^Gz5YP^*~ zuv3;u($?j9pLVhP~JQX6Pf9jWfQ4pzF# zrUO92lIyxaq9WHS7VP?rrbLdf2hj!gm;oO@7TTwX`dwzs$yMfqDh`gu(@DQ7X{o_l zB0TEvziEK&ju=wJMDpewpjtL*zr0$#fT3%ue`6rp>Bil{0bFo=yiAQbY~l?vfKMNPJtIZB~nOHabr zP?K1{bWDAcb{%eAEF6*;*Lt=gq1&>Qldosw!ULBI7cD%GPBi)Ebyp3Yb73oO=mzHk(rFflb{ zkjqy#u%4lzHsX?Ay=iGh3--U4hMFgvRUnjB={zX?pE%)233LqZ(*7!8C$I`UZds!um<&l>$ zC7g*GVe&O0j|M3gnR)u`P1}wGl=zFx!JA+|yNFu;j0ch-lTtm#rKWAwz-!dpa}3au z7m~Zkm=ZznF?j>%{LtsH)vU#s&vMkfN~V2y=b|L2R1%=*jNW*t%3+`(IV$?g+UAh*8bA%f2fbzQ{=@er2o}(tJ`n%rXBa z_wPOG{6XzQhNMo-iU6JWo2oJIH{XU^y4el$ER*3!0jFH6%m|iqm?6z~ztm!Bo?v9L zCr0G5s0})mv5Zxv%Fd;!&rna*h?DN;Fu4Xd%0|+!3POR zcsjPMxZj^KIBo@DR}wfyivMYmUjNyE?OmnCKkP}Rv6RS_i98CxYWXfdI$s25(_gN zv=(RoI}P&$uTFKWdH;EfT2lGf%2eZeeBiH3&2*WQ7q%|_eYzdGopXeIYWtt}`d%Q7 z^CFpzl2eazJIx$5nB=GBXOQvVv#5a;yxFC{xh$cccXU^nRm7dmt;>Qj%raX^@v=-` z(=1yyFD%Wb-mE&$c3+gVoRpJcn~_@Jh(A~{r35vTj}^@4`S5jjjojx(dHCi$T7FTF z=R^Ml{l-&nSpIX8vdkjFpUK+6qzpLLjqOSFgqX| zmf>Q~>HmK)D}k|&<6+wHz5{jFi56DAe?))N3q^>HFs&fjE*!m=`45jj^cn8Iqyyx9 zWzq_A4qn$fvGYQFgnUNt>&;Rh{X#)S^%T@eiG^N?1iof4bM_qZ$z_xV8 zLT``5?4PYn;hl`flZmmsuK&Z_TSdk7wAMP2-XP!KHDx zMuS_Rao1qM-932lZ{@$=z0bSPKIdG27u+xggIcSrs;lNR=kM|L+^y#Wq`AKZb3Q+> z-SJlMU6odgf8TI*S^O?5#GayW9)P3fpY^|mb7XSghY5N|(a)|ogT#&5KkDB&oU(^7 zXLRIY(;PZ~(V*3o6qJpp(U7AzVJfT3(on`5E@^d@` zgH3mos`o2To?7YTb=E1>74-T#8T&r|g?^J^R8RR_9MDCy&gz<5rQrN0($X8N6NHe# zoKF-52BrIHzXi(7k|+KomXd>Jf=lJOMi)~cSy$Aoqlq+gdM>cXdeJ@j((0sFWhQFJvP zP?92tj!8I$aay@>pr>KbR@4tT2byc+x4ji0ilEETeq5%*0Syq6&_$|Ud!_>>qL0hJ zxj-@p%(7+q7mt3`St!s)t@dyS_aDN7$oFMaTK*k_y;9zf3b3cIQ-mo-<&EEU4vyIl z5fmHoq4NC4GsBl4M^=zBzZR#pU$)V1>WF}0xl>JpJj~wF-yNEu1o3!1_!?TW58_vz zFA`X<;}_0efzH~dqbEgTi|l$1z07@AVQ=%!En+6lx_5|?H=3Z&=s|;lbNj`C?0~fg z3dAOe1oXLRY81((>vsS2cbG=0jc?E?7x+~%uVC-Tw*i05#nOg_jWirejLY$@$E**| z2IXl-(-7p3Rl2p5hZse#FIJ+B(7XyW6KCLcDCMsTYj_ksjv=L(VtK6U38lOR4MaHa zESt%BbsFlbM0Tmb zQNAZG#mmuNvV01JpauWB%YU!rJj6qAd>S-mL+{1dLQ1o?uxRNH}$d=4uA8iz4CZ2(QMVK^$EYEwt8GXp94)CGz5Si?gl8d z0>LD%!vt7phzM!XsYJFD2w^zE)6pEX_Jb>GEI+wrPIL1=l?Tm|dNdH)N)g=7#Y7J^ z$uh1rhsO}ni#c)p%A-f;RV&gV8c-`D)|cbMR#4QR{uG)2ckUj^b0>dpWmqUvvneOx zQKR~zrNAQb75#hSD=)p=;z}(rV?I_jTzC;}Z`*^)9YdUcTz+*Js`}evS;Azj3GsIX zp0ZK(dvNB$B>Eh*`>j7;?2(P?zMNG|ujZw(#3CStILD}WxMIqV0%t~Ab=|@qZ1cS} zh429A+i!Pzg~^;mSj4ebdg`sB&+BIPa${8Q1erF;3Ild2qSM$9Z~c8SfnN_O3WR~) zA-0m6PUmCqlIhp)rG~cdg%SiXZ4vz2qx5~yNTiOzm+|INh=SzPDHQDCcz^p!n`7M+ z{XhR<`5=?O=okV4Xf;-?;ggLfVZrOxfRHKMmFN9rQhnuzhW=QmAG#}Uy2I%w;Ov#C zyMU>G(l0;)2D%EIBTur)n2i6ih{Fu)Nl8c^2GaeH=vS|@Zv1{rk^8N6#)v%Z<*Tgt zlmi0h%ILDMhH{7J;Vl|q3xu%mXW-lrm`{T4krlUVjN2?H3%OLL&Wqy8g)V3q$UMfv zp9^d_=#v0X^*9c5rkUO$85k0fPSv4Q(_ZXfz}A?=WIK^Bp%?kY8JQy@%?@!gVZQ9o zdLf$wmK%9U zBK5hJ?_pES$_^lXt_7HSp-t(yDt4Aq>^5OJP z7ad@J=wvpYEK5`6Jl@2_sZv)i%4Abl4o%nF;-=5=DO^d6|By{~*>VLgnHp^BDtYJM zJs5&BXPg-^CXku-w~p=L-(6yqKU+C1wX!5u;>bTEbn}jZrg}^9qKacMq(EClp%f_6 zEIBkQW+dS{9_RM}k>p!#5ggD=HHhDRXWx8Y0J>0bv;xG4X9hdt&q^8(luL@nggF2a zQ#;b!GUXR=c+A(Eo3@6I%?8}Pbou4{v^HY>i$sM6pGY<4o1(F;Y`jx^7}!IsTlQ8? zQY!Xyn{gCR^scZf5EhFpbB)5GyJqcV%*+oPMRf(WX^rFlB(S7ONevX==>-pXNPj4y zTYJ@XD)&G@0`Hj;AHUn9$AlPNG0aWZX?-cdo_tm7%rrRk3w%#qZMDGp`0hAj&1%~ z!{qy`aE+U~Fy@SMBKhq?3aG*Fd-`GDD)b$i`>l1Bydtk<{slY1%2w%{`B&}zSJ~Hx z;RFHWv(FxmCLd0GpOS?v;p=OCfh#oI3pbSseznP^S3)lit~opzhit68NHBFHNwA31 z#zba?7*(ZIT*Tfoc(XfIW(Mu$MS*!vUdHFC8y8$tPw1$Yck|tJGQDcEG5vH5yJX65 zG@}rDSzb7#XBdl@-;PRcg)#Aeo5h`LOmTfm5z*o{asNuq6{?8k$2cbPOA3eCG?d1A zbo{}K!YLF60&}_ZF3m?)96-`?lF&X+dPj5Oy~V<$5x)I&S*MP?S_!-QecT>117I8f z&-fm7HO7C$^4t*BBmPO#LWmeD$Njl^GgTLgb%HDZ*E2luxjgl&!+2+r)#T5BTJ-bN z@n?`cltf8wIx-

    %pKxhY-d^@=mm;3fKYM|9u0%TAhp3YM`3dwHU#Q%!;Rw8zcbM z=f9qeeVy{XJeSSitgS2P!+N6LD-KFIArqg7-}tdkchA0r4Ha~Li)PI0Zgm%#u3aTH z%8#NVVr!Sle&pD*u4|8&Oq90i7wecr342aJ(Bn}A_xqmLB_1ek?9Fp@A`LHCgG)V3LO zhrtc)E_tg415)_ac>1lK)RaZJ^7w+LJreb{70qVCDdERG)gTG(4HF~pkfq9K=f<`H z$D(@C7jvC>(r`O0iRkI6g#(wBYXG6Z4mOCPe9d$40rivqoe zT<3A?(JtZ0FPaX0Kkhuq(IhvNJmsU*ZysCmsr+LXGN0b2XmL!bM%b*~4b3Rl)!|V! zGW8u$N+Nu89pH%8@VA{Huw;RUsk?jCeehgBQDQbp6M{#Fm*S4bzNkVqdxf3OD_YvW zcYKJI*sq(F=jtFn!Qb^3^kHU8kp8E!`vwC}hN&;ix?1$ZO@D?GKdTMg)SzjU;&w(6 z-#!rUk5}pD%SgJ?f-)|ecMWPudk^15YOp&Bu2!lDX5OPgfzvQF&Y)X!INd`B2+3Z^ zL-Rx@>bQ^Hl5UQcmlo{+6_PdaQ64I?ahe^u>Qt&C@7|Ahs25|=Wv#bfCk*^~u5n4D zm_KZ=PJ`9`K+Cl3tyrq)QvJd%jV=(9;dlP1S7DOD2C?Fph3BJvC-3KyA*V~Ov+&VX z-EmIi!}v`Jl_@m3!`iyIA~F8IM5U!Wy%CytCwPb}7139z()~J(moJRD8%%LR4Ox^u z$!NAs7fM{&>tjy5b0)dfZ>rNi$XG3s!99>EcU@b&HVKbJocUJQl0= z@P!5GZ3J+yWN<)V1X+%k(tQ@(4w1%o5MyLj}uU^5RBzHTI zFKPM`D6913R4J5sMVQiXjFr^ zqWg-H-fJEEpxyk)JoINiWJ#-h1`1+pCl%)3mSiL;52cF_#qe)8I^7b|9HYg#x+e`9 zb=y3|8LM>y?-(daOTP`Unjw^C-@g1hW}@1=q;A{vbu2&e=X$laECfJsEf|!LlW&$r z;&Su#MM}sC64Hob8;9}!H=-7>Nc7&s>Ay9*!pse<64)Zx?H%#o@#xgX$yXO4k!Suv z%mlXM2L0x@!4VPetsd_q%q;|mf7*{(Qe~QA&>9f;O^mGzTjJ!+0pGsbM1V1v;@}fc zA{B1kJ;eN<O%&r_0X~L7N98%I$mG+PlrIgd@%tzzP?#q zj7)l$ATH>(FCOK=AW~w0UjS<}WOpc(;Qt|EW^8JXkFEw}5prT={(us48g($mR_QB8 zDqJ~jC48Ov&}N9<+dd!orau#wi(QQ~_?@TvTRS5v zl#)ICsdU)ytbB~{N81Yd0pd68+71EACS2>&K<#At0S?-JS)JMb`zcfGF+s@qnHngb zB)i{t)sAO9Pwt9>FZYGoFK;a?H9&x2=Q{oK;^N|cE_w5_z1Z#dZ15_wm`T_E1U;GG z(O`d8>pt_9!!c>fU$vjj*6~hmks0-6#gV^K(~nZBvh6ju#rmnq;nZ2 z7GT9=iEBHzS;nML83eUGzB?=k&HQ!vnQq7r^B0Cb+9c6P6_!)P(iO+RvLRbue~||i zErZqyrN85q){MsMPZ>&>5boTgufH?bggKK+zLfQJfJ#Yr^NC*A(h{smLKMP(k`}7p zv$|9=nbEnpZ-)7nHy%`AsQ8qv4DMw3dNz^Z$aYi0YtQ_-ti#YfykuUY3dotz*=(}H ztc(T1DrfLOqA2E-V)8p7Az=Z&Me`kNcdrA>40LUX4}94WlNJ!e37h|5k^U}QC zj+bdOLUzMwH z)hqvlW#|K(KBp!oK7A0YNC1njt~$XRxbbUVU2Jl1LI+k&9uZz(kHvuXmaJd+9pDB} zjTX_kp8C}|w#j}!FJI}>c@v|#fRYPWr5yyv#`bC9GUBSwPJ=dkPi8muXxwnCSVNUm z7)`lFgq|{1*0n)i)-%=PPd;)Ne-50L(#(rjYw-m|i*=o)Us8W5UkI(xPEY<%#dHh>`G8`HNeGBw$D>;bs z#)?+P+%qOX!}*Q=J+|tXo|pXk@1iS!t0Rv#iWf`VdyV`Eql2i*K7BELFeL2l!vFs53m>;kh;cwYbtZ8%3f zKS#8vL@c8NB}b$9TWow2`Y1EzuaoLgTJU6w1ryVIdCA~S+kbb7_ZfPP0bcm;*a$ar z+jGol0rl9ZeZkCFKk}96>j?*8rID!v9ta=^+b^3Kqyho^04<_7wv-L=OyA6WD0JY_ zHr!JY^@+YA5{3@2aST`;74XJ;!C^=z9>iS_f$}&^B;`#bX+V+rDwyWq^yNla|Gus{ z`Txy8zE`;NhloH{kss;3oPFYg)h7rq5?@U(>p#!C)p#u7R2nb4W6xsBBzfX$YOW38~jqUFo!-yNNuaj-t*Xz8i45l^W zr2w1YcEU~w4qujht>Du9{O9AtHbYS}`v&XLkfK_J-yAcD7~EXzbt(8rq$7^0!OYAp zQ{jYvQ}7OX^0;b|++4WCXwzjOFOJPh@D&PTLQSb7*VxEa`-;2=RHrvfvtFBU#msS6 zs)x^;PqhfR)GC99!@|{3oI+Gm=v+5@9MXdL#eO4I_UX4thx;M2y-`|8QO7lg z{}SK>I1u$m3|0e(08oh;4uC#ziQ1m%d4bM$$XdiJ3{Fgw|2e&d;=7v>D=#D=INSJ$85j(j;B}pb6f$b2l({#P%N6lQZuEE}Of^heCdG zCF&BxwU2rxZs_}`0$K;JmeTx>=L5sGCb~E zl-rb4)XAL$=a!Z#?Qkk$R-Gh+K%!T}FLp8bS!bbi8F=*rB}OHUy63hF=3j7v8(7fV zbBrc6&oP@%{;D<5F-*IroD_s&nr@b6GH1UOkK#HFv9?{75@S1N%D1puOelT5dOAezp`$rKCyLco_m#B0zUfK+x_6@M{*9l_fJPEq@rFP@~ls9IrE~ zh&?|lr#5LAl-SFP{+t#;)v8Z%kQh*+_?cLIFM@a8+LhIS6_$2}6F6HK$>rbn0z41o zzcOs8{dXx2e`vzWmg4^+A~tO6+*lq9bht_?`NBakt<_gAiiP_k-^jcysm=|PI(68u z4hZ~=T=q8FHIeLFoy^v4Ku*R&VU#3k_mhgFZ;qg{Y?HuXLAhY`C&@-^Vu*`<1Bv3) zKCK>WIvWUPP3+_cwy9`S02!j%jH+25Sb!~|#JN$QEW(v(i%Z`Zme6fw3V8|+a?f)! z&1mjte$!#hk%Xo(HBYloam@fK!ZTdqmmB>nB~r>xP2t{hRYM_I+3QQJj7h}|nk5Lo z$iW$v*|>dP41d3J?f#Z^6hIM9nYE1g>y8%%qU0mrep|Nl)dbNyWsi*D7TqhlqE+Gk zj-EHFz~K9oneCe|O9Yj4SJ~6LGjrUHCak>_jU+(%`99uCF3~XK1iGRG3#F3yAzNwl z&a&{jV_`0sA%A`&I`^bR2A-;4otBqrd%;eiPZ9ebtLd@>^pQFW@1NyGW5RMJ8UCP< z{XDW2Ma}H8pusK3VWWj}p4jBc z!rQ_r(^DuM2i8|3tG%!7B_&_hh(Nq%{i*bCgpM;^X(Co$qGBBs`3~KKFW7@s6#tji z=hZM!QKJ}N?Jb8fq>UBLjy<>QB{Ao04-YIl=aGCRrK|Nm>7qp^309dKxlQSOZL=!@ zMX7&7cy#EAPoadVdz;uFNhD6#Irq!nO#csthcI3ofg*f_2dA)>+Cu1FHwtiAPgikr z*(jGfDM!eAUji4~18g3f6q)HouWQ~PB?aC|dsMe#@ z-(>X7MXN7ZF;0D^WIdlAygi?$RgNCc{P{&R z{Zbo@Zy#zgNPO>Nmi^CV+q`dMvhKb#F5hj%tln+0`|hNc+=1^m@Uy`OB|5MJEg@JZ z{jt^}0)}wF=&axIEC_I=k}Z1r-*|GVI{Iu9L(d)e?W=WtHu?NE*`GGpLEF1a@45++ zOCItXmY0{w|E!bWRyVd^h=^T00T%tgk& z1^%o441;w<^gquN9P!pYd6VyCovM!j{n_Y3k7X@~O9f&ixR<=2>U6N1(65hZMO}i3 z(J1bakU5n8NiuxvM7KT@GGRzNsmj!d`aUYB_&x2UX%ZhHTH*B(=W>;| zq;jr((=eyslG~X~-y3{7FKMYyd~j0s3Y9ySOQna5bC;qp%z!{HnXtZxN=VWZr~#(#UHp`=w;2Ixp>vKV6PMM1Ab0Ht@-!+rd#V5Z{G{d4hAW5%il9e2m`uBR5jhzdE@HrJ{lJ49ZW}LFj-G$J0Bz;UA?9UqNGO0-0M4{SSJ*tT$Jne11O^#b}<_( zC@y2d_8lkZbw)+IHqcfTN4ihx9Zwr`jR!MSP} zs|q_aAWM_&O4Fk7a|u}T>)a!oU>V8d|4gMPUrqnWq%6{NYQf$#9&_azt%7AeK`R@3 z(D~3rzJc)A^n!aXfK5AoKhdaM$FgpEklsAE<>Ty^-Vd*}Dr~*Zzr-FLIn$jk+OBH~RV2a3tK@o7)5{@lgQILnfNW;t zilRk5Th3-+^Mlxf@e%8?=gBUYjrt+C_bS%|j~*=PGr%ob&kUhd;Iw9<`a&cjMa;&I zxa|TC`QY41;rh|EKu|)1*rCs*d~_+Lbe<~b$5;w49Of~zf==qP+NnSh66j)pfq7<1 zfd2T3r&|L_FN-AIsZ?p=0gYaVNBN`BdI2!W>NMaN2z7X{_Q!5BhlrX7N*aM})QY-Q7LrdpF4&Ya0sqb;Sc;pCXf|r!P(w-Kb7nK}$zIMDr)FZZzYR$?Zp1Rx)J4AjRq z|C6$`A(Qc3Em0Z+OJfy93h%SRqnv(f5D6RO&iF33Gl--?J+FCueRhyyC7zK++Ig# z^rHf_UQ{n;c|VkiU^^j6=ao~7#ss9XIyh0wA{eQ6p|tL0;27EIYqcLcYjy3nU5y!y=0-1Y&8%G>PuTMfs>TQf0kVEYwlQ1LxUy^hBmyV60ir#pE>;9~$`Uz1WPe*JQr?|rD> zmh7tD>9qIhJ>X`=5c|E>PX@l6pl4dY{G-9=xU|v&YcFOOI3@++`E4qWp8g*g3!e-$ z3gf_q(L|6kcZ)23n@aEH#``~&waO5Ay)ow05&8;@n0O!cqSq-NdMTJ`u3|2x?*T5c z%Z4v;f=R9Mhw3-~!Yp%PyujQ39yh5wjLSoCCHF&3C2of#eo~XfbJZg?UY9^o^&pQu zelW}%xhZ+G>!E-ye*~#1t}&3LBmzgsF5?#BJPLu{DmYxHBC2Y}BvMNaMKHvI=N9%8 z9E#0WcqZzWhc6Vx$zzFZ|BZgk0xp}56scB-GSDSf3>&KUNOxNZr*ui=Ou=6B>g#~3 z^O`Th7&SjKn95@-p^Bc&SJlEDCZMfQ$?@_Use9W+*$q2a3Z>t@x+*d{Hvd}ki}&iB z&J`pN6xsHEr9a*cXwYT=gsifuJElq0)ep%b8tqz+wT>xH)P3pxjD*3tqC?Td|8U%X6LBp zIFs+4`L--%$`6`0!V4U_gNFoi%Yh1C%N0R!H<36XS)crc@sjdXlKh9VNdF^YVDgrnDZlf&J#L^>J}n(1FUa8&*1NR=(m{>jvME+5IeqVFhfub5WC z(7$ZkM&U6jD*9K}@B31{KWJ%KF?3{-C0crIy{;h z>$&3Z&Cv)T>uuIR1@-5Y?~H@hTGWv($u+h73O<( z;EwO_GrD8)VkDN=Fc7$Py^m%I{SH5~DT<1D1rWX0&4u!(ZBt@h%;WqJvMlolDYp_y zY<_Nz$;`Z_FTeG_i0HwNJv2DYti+@hqlECQ z2PmHuF4Yv=uy8qk&QVd6SL_i#LWpvz736bvYRPHQZ*;bM`h!Mf8H*|JeB9aJZy~U2Mm0$`A$G z0@UdK@=5OI{vmTl0UlRZz~gHC^kkKTyZh$^L2#S%|3hUZ6E#fz;oT5vF~nF z<>#pl+3dS5@8s;enCH+L|I5bfmCKHQBo3B{jFXnrwjs{Z&vXsuSrp@$W1pjsXDa=! z%8af`OMcflc>MXi)BPO>kh-^7tqXR?1VmJ7cWak_xF34^{|;R}Z)j}aTo!wL!tlKe zCV$jzS3fNQPQUPco;RIQi{6cb>of-I=HUJB!Wx#+Bdn=TV0-$E7YZie!6o$?g^mmj zZWpJH=feuH2HhYFdH^(K8dPY%qoi^+wo0*%dCVxuP%8b6plq6;N6q0liR5ZYi25)U z>y8ZV2Vy7%9MW<%<9*?vscT#!(X39wL_3`ls+^q<9O7Me{xWqrQ8dO2ciA#r3v-9bpYHg<1jpTh z%5L2v`zrB;lFc`Y2|g?*U=OgLhys9b%hlj)Bg-sg-cOrNSD6Ml71mn0_)3;8D2g@f5DWb}{|e=$4OUcPOIk z2cG(=p?7fuDuUkTc&3Wcci@~A5=qCk8TvFwUBv0E5o0^fMd@mFUAn4HBhWOuFcw>n+*kPd6-a5Iw88;vvEds@(-9+}ugU7Y@9fLb zvM7Unt!bd=!W*;J|J)^pOl;}|gX`$AFXVHQIMzj7zatfqPhY;%)W%NdvEa{bj&@fF zsZ!{^{;e_!7qN^ykZ2j7c!YxrAr`gs^{BIi29>5FJ-GcG7>2saWg*FpP8Wo2xe1Di z&~nQZ&{Lkf8SxYr$?ZlBl|yzi0wUsz3gsV;=Y3!N2t^oVkbTS)sxJ*E0073**;PH0gEBwvpS?^FqGD9}2!M_|C*2{m?B`M}Sb4kn*_1vgIm~PZt!Ah(`^D5G_aHZ5{?&L3&yL>)pKH zNsm1`v#9lvgS2Y# z$KNhG18+e5j|=U8W<5nO#v6YRT0U*VO8=H6zcHaUT(Y?=*lY*{a2V+i?e^XCK64q( zTRA_L_+O{p_=AU!INRW{LH$6eOQinduQ@{z;HJ&ey`*31YK=;`n?VneI6MG zVzz(xc@Q*hkGnyd@^ArP4?WoWz^=#lijk-3pQ zRS8U3t8CZkuzdGKeizsHFsIV`Xn1;?3aB8!{y!fha=9lJBmA_tsUq?;9YycB;u1Gi z0Sk_ALB1cpdNQr|uQDhv+E!j7rA59NzEom&2De|=SL(ax$rLiuify`ixnh<#Cq)i5dGCc>$wH0S_J z1jF6%#h9iH@NY;&?qM`V4XQC|kgkx(?24(zb zAS$CsyAqJ{^0eEdJP`V0Z}{yc(dzRh%tc^>LFEz7#hkoP&!y*8MfeoZ=4+Dt zE)PkB10C+JF$PRG|2-f!it zs!~xjle33Bz?7!wiQ|lm*cPEB*%IWTJ9sHx=Ce`{7 zSLo)RnY#WutzPz<}$K(?GI27onm!}>z6sx2|L#=v; zNv)NN-g$v6^bS`Y|0wV{Z+2zDD&9%mlpG|c590w|pp|C`gNgUYA0l$U8Qt+1o= z_8D%{vi{KE8Uh6E=?N8BKTK!B1usZ?~%r|5!Kj3pYlPre3hUkzb0 zg>d2I(FQJTkgrwJ9c?s#ve(gg!1{~cuS32(CdE9PS^{S3(A(T7!FE>xW<4YZ?3G#0 znW`4)c%cxFQW;P;^OeDRopH9CpetaduJ90Saj)V4`ZQ@S{LzM`-$OsAl0EdT>}a>k zj|(Tr(+#Y=PG_QWy!m@kS-%p6+2pwxwjfqM;J{>zE2mpv<0_S_h;wh!+2}Lym=hnk z4|>6J#w9ukO*^Qo<=*yFAN_yq?^z*em*u;&{^9tnit^&8HR)IZ)dSL6UY7ht*&h9$ z_>GG4ReQpvFBSCnRtMI12DBwx-CCa+A<4i6Mv0$vYI}@euxudOJ$7NRENJ$7gYZ$o zw~m+AX``f`{)azCKxbzAS4v2qpvrYL$01|`91(~qoh{V8v=%?}3(LhCThm5KKFoIb z^^kMX$h-)DUm2k1!^0&>=xI3_Y6J6xdT*?0VHc|_AX+OkHb+*qb1@-IXz|z~euR2+ zzryYs5GNtOS;(vZ;rIu~)9Opp5kx;*JE4`~+&|h7AH+wTmogCUSM~}ne){z+)6D!# z2vsqtE+5HaDwXnEyaHw?aZ#E9Ko!CU(Z$xS{+$A=6|-81#Ua?1hP0o5%ylZ5{@SOU zhS=vR4HDP^eE31lW~vC%B0mloj^)hiIs{xhYHloBJB}Cl72yk9km;~s<^gw^lvqVa zuvhr6n-$=mfKLtUy}ZgU6*LQMjQ_FVJ$jRo?YQduXh}cD5Y)C=cj{(ao6G3Jhg`Dw zEeFqd)J}$&rarDjeToCBYNM$j?a;}~n(fVlWgqM0*`HT0=#uc4n?)T%hiE2{`zoTY z*srWOf~KA-i4nfFZ>)gnq?i%Ud)l!8!6 zq)|TsMgMIK*!~FhU63p$Cz&br3qx!YF0U>H^}-QGETG$m9Y>#;l+ESq;$9stYAYOX zi_&QV9A!IA1@$@`Hxd}d!rbN6Ek^n4pEPMQCde%BO^ei{jPPbc=Dsg&SmjTGnDS>i zkmS%ulk#~zkO(@dUp0$9%d&^@@;>SxJ*YUL)ioBkiiZ8`Ib1Ng4xMT^K$01u4E-f? zEE!0xC}X@oOoaINI?{g>XPaHpZX|Q4OEYRi`_^ zh7#I(nK9+4+huJqxwV@w&fN}|gW$ILnI>a|SH!bxe`m}#D+32ao`DUjylVrrnuuk; zld0@yA@Y0r_EX1`C;iIy<_l83r$*qU&ewkNu!k>tKL#`Q*(Sc32v~JqjjHsUdcqJp zdz1axHQX>TsIx2Lxw8YQ^r7Vq4GqORg&au?@}4_;XWeG0_-x?(tzlkBilqTMj&Wwu zyq&LY`oT$c6bgM%i;!I*lD$@JU?tlP@t?va=ChRJL*XXRQQ5LL~9W ze!OK=p6Fw3eKW)#H%rj%;d;YVUGO|`U*L0Gd1xbl2zB&3TwFOj$$kRv3wu(JXi!-) z@ACXlBflMbcu1yVI6x}9Lx?yE*x6^zNH6`DA@R|<5s z3UWL^vN0+=W9GMqP&P4qL_ScY!bQJn;Csw$S5$fWGwTa$6g);Nj0#~YKvbG9s=Q5; zB`@pkt&U9oK#OpYuGbko73B^nQ3c=`ABVE{sHPEp6H2lcRPSD5@f@dfS_Z8Kp6$;t*OmkQ|?Cqd|MXTcCQiAeT<-BQV~j)7r`O>80HS}-RM)T z;1xG86K+X}zD+Fv&0hc$o?n8IQ&rdS2u|y&1TwoXt0U*%?p6RaTro`hs)EkA+_J00 zD6LV@^9xREgr`Tc6`V(tj>@!Hz*%n-{mT|beI$Co zU0pd|12khMsNpzX_FQAe%1Cz2d{tUG-x!S}i9-;PKlBdE1&HzAIwdbZDumP(@wdMj zv-DHI6%w~pRjA~=qtVkw^~88l^@|&$AaBMW3ZXJWfUViV5f|c9(HQ(^UTKbdSvAP5 zB^3G-rHS!4ghle1c#mD~Dio_UBcy*yRqorL#6`D^h*0i#MWrq}*vN$AHHT3@bg|$nWqisQ6eSh!*+aIk zNkkMAGESxddHUciR^nZN(`$G8WzJUWoRSPx`i$0i6-x@st{EU-Jxii=Fb3aBE}$i@ zziXa7h^IJCIG3dVPLfXzX(e5=%bxEB{XU0Ni@@6-&Zhhz1wV-b35M^v9RJgjn`VX0 zRqQxg+4FO3ddYP>u35W90#l9=Z7(;JPP$`L(s_$xZn7Aaqb-1#oIrtCo`om4z*}m&hBh zYl9?z6Owe6hi582+NZ}eyX)WDV1jr|2`&kV_|x~Pyyk6gACp;h7@R~MpB+_9k0?W6 zUwDZTS-j~{qn-N8>9T^9o#~KQUIq-&!bti=5XwG$r%eQ@Ues_TtD^kgJ@)Rk1*uDQ z6#TQOQC$mW$tbNp5-fxuE5|u$vT$Ej_$V9=m@rN6oa21)=k7Q2oc#k^A^#fW|VGxmOZ8aVm(#QsloCGAH*iGEKKn3Y;L5pbT8*5qdG=9mW zTo@`A?&!%}h8CtLGB%g(X`u>`%3Ve}Ni<-;vun&mrDom0u4E;kJf<>s>OwiM*~)l| zqRHq8CV!q89%5%U0@^(^raIl}(r2u|F6dXz0eW~g;B`4QemwU-7h@aceH^=YcrboC z=~Ov++}KITzW;tB@_6cJ$=KWetmF9P@At>+l-z%3-qQGM29E#Z>7`Cu(YZ*&>C?$+ zAIp5AxhTsgsX;n_Ge=xyrYe!_Q&!&%oa}e20j;NP_rGiYeA8*AN~PS$;d?$i&}si+ zW*p~C*tn%L(z)j@z`1y_9}xT=nWd(L@=3GJM$vram2IDuZTrukd=YjwHJ<1~vT*E@ zxt^X4t#e_7z8-L?sH#Xk!l}gINJ{ItV?~ejij2iKBCOa``N5m!6Z&9_-KaiZt?^2a z%aFnEA~)9E11d*__WJvU6&vQ4@r~(xj(+1e&p%_@w)w zTqS;+sr+SmB=9+kx!dvyKsnYCTc=X^Id(OBXFkH5fIdK#`)@&IpgM8%!_USdRmuwC zgnv3+w&Up}j-O1!S4MDZI5}Jek*QdMf^WS+a#wQX^GZW4uAsd*O^GhZPONy1@{*et zQ~k7}DTxiO+-72D>+DR~t#3e4bk!E#8*F52HSb6cSK0H}#6gl;K4|3LVcUun9RA$e zOl?%B3)PfQSIhm}4`~r>PXPrw#2#F3XdUIJSdbKid%X@@wNATGUGWNg^e9)xo~k0M z`fp+0K2KihMQ#JV_~OaGoCdI9SHitaVS%sIa8t3@txQ;3V}k+LW3WU$1sDEeJRrDz^=~0bnRPP`d3yPIqjrc%w;ypTD~16LLN%1YsdjB-&JnV39@U0$Al>{zydnj z{NdZ*j1BT@R3Cz(?-AaAN1d=mFmq4MY|I#LQW-G&H@*gh-#~>mFByEpfV8(|2^2?B>mP5&%;bY*>gzl@M zui~`oY2?@FI0&XbMw;ph){Cy!UI{QQ5ue__n%kl0f%^J zpl!7NYT0nH#R@^npJM*CvZe3DMsJAV#Z7ktL z>|K}7&!RIzo}j$6eG)EG$>+m^V7y_XL>8@5w>Rj9ERzDnW?DIY)|DQTj{IAASa=f0 zTRtc2Z*rsdNx}9e3eXxs4c=lJEKQpaw|QtEIlgCTjEwE#A2Omro=SsViOBH909>^t_qIma?B`Yw>3wtFaTeMf6#`j-V|sl<6gDOdq+j2Ax2 zUPg-bM3l2AY>BFi>Zf5InY9#C|IUBlP2%nis34s{uBr zk%l}?^4dL(mY0_e-~W>Lt*I2MEGkE>7zfv@hDhPOWWu?lWsajt$Wk}(B3%hJDV^bX zZGb3xVvKxaYbuZE9T85awJx_ydPDDj(dR{`-)t#@1_cUH(6+8g%<)y3>JuX| zIATv;5ePk-VuRKScQcGkyBG%x$c=>$E%W^T)_W@o#vmwA*20hb@sE^5L)DHUv~9w3 zLzLCEKdL?odq{0J74D1ONr{c?-X=-5u6UpKu0A(r`xyZ)na}3C>7or62N*{Wsh+0~ z;e4m92i|`L9v|;(K;U`q+HKo5+kg7;m+A{d1A+eRQPrG5rDg32b(BlYL~OAYrlJw}EO%b9uEfZK=Jikq|{ z$sSd*Vm=e~OSGMte}kai6u&8+Yy&G-!|s&*H#;+(sWP9pENL9mP4ky20>jZXN89#? zWoGOa#0g52>}Cz&$2+6x&ujO7zegP(&l=kgMZ_N4F#OiKF?=pNWdZ+BIKatJ#sL9k zXh*>LL&nnUx0|HIp9=K!nsn>3t`{}kGrIZV82X}g$j^O`ir!T*-hDTFL?HL$)1$osii5Y@ouxxEs=^cjYuvr}_Nd^EuIR($ya46VcJ^ zleSV+Ma?h%zUiDqxhchE{Vf>)#Szq$_`9=y+#?ou$z9I;-){DZbFC<6- zg?o@fgIjQSmq2hRY)+o{?VkR6W_qojKLFTOi*wFCzkT1=_2s8hp;@u{>Y;3BTs>V3 zFi(o;qGXDOfGzDmO}j@+Dy8m`TYeekcex>sIA>p{VIKqDC4dup7p=qe`zQ_nZky_g z#tGVWu6Ir$nykC_?PtQUw34Z_57|Q@=SgC%Pt|B-FQoTRq7m^(8zYfpVe^C%%1AcobNjE!wt}*QPG>CYCjS6Vp zI?W9$wz~bzEtmx6HEcph-+u(S2m%tjDFTb3p)C#J+2|zA{j_!VN?Ir-(!yA}>LCZ; zy%Sz*uB+?dUxhKt@7h48eYxgF@y|8tbZvM);tn#T5%j| zLDl!C2NV-C%9$#S38F<`wO}Kds-kMrm3%Gg#VZc48BJUe6fn|qH@ra1SqnhqH+f6e zdsa4S!m;)TFI2SeEy`A<^OZTLlRt53b6ClPT{ppV=v|Ve4^A>cGC@gsMcsqk#dg8j zaM}H@Qx}U*x+ygy!%XQ|639%7npcID!x}nZN2c?sfg(mht-9!;s?8yFJqw3-1_xym z1Wgyj?w0$<8IAlM0<^OQKG(_tUoJGI;adKeIdMpUoDf@{jpN*%X7wd0)C>Vyr zRkzNhId2up*p#_Kkste85Gv zEY>TQM^}Ua`Z*4HyI_}Zh}EVLq2M3C5G!RQehR;*_`f&*?|uutYu0}3hYD1wF3 zDKT&V$NXxW|Hr5B!`&6laA)KZL;lRc%WYA=<~5*PO= zNmxap7yC=LvybT-M9HfQqmq0@_)8`zZD#jExIj}XkAhb~{n|VQ;cXxAFdO)Auk$#caQ#naSo;7z#E&Fa%^%K%UK>SY%1;~&uvB7X4w)V81d zt|9A#4$OV;ccgo*1xW0bgVphCb|EL=FOj9QG$D{MlU5QWneL>=K>cgB14>%W_}Ij=j+~{ zElA74eD>}L782=;iY|7XjY-EAlZS@S`;0dk1Ja}6 z>ALzCA3={eC-2Uji6=dux2!3F`mELR>y^Hjp?IbjXi| zbJ9;*@cbBxWRI=sr65w-$tZTIdfyShu#t<$ba~ariW9|Bq?>&G8q8T4U=NNXLkmzK z;~vFVArFuRr#$46d=wpJ&0EF9zAiHVhTSlP5KwK+C>5nu^6UaRMk-v%CtN$YN51Jh z=hv%PN1BIUtrxOC)U@7oS5q-d_nbIV$Nuowma)*C)|}l)Z^_K33FEV0>DD4MeWcqb z!(u=J66mW7dwGaNfwryBE`H5CE2{84x9A(9oIpf%T`L3`cb_O$q>Ce1%26Xn|JL*Q zAk0|)rnEZ!D+cmZvhRm+eYZ=GE+yH_DuUN4F`acq{&7X8@yu+v`b-}=qdlGcX_yIJ zYu`#_;=RBU{1q9umgUO$vHJZ%rGPlpfh;D5Y4WrDZu*olw)HeVwrN9nt)pS{R8zss zo+JL+Qjcs_2FJQ)h6WT;fGhAV&0sLjwA`_|Wd@um%|8crC&YO8$o=JQPwitAezCm< zK;_Xn{{DU-R9n8<`{R}BcO(MfoF z>?lMOPA*h+PE>WXR|;lK+_@Nz@2b)$_5N!n$T-lR%3m!pZvvO}f0>1vtSkwRE=L%_ zM0zht^4c0RJjpr*ErEFRc$TnZ2Nc(@%P*}FfV|Q_ z;UhC#vt*Lbe1ql73HdAQA(HkC$0TYfS3Ft&XRxsI^0sp7kay=^mM%t|(iTr!G1)nY zqn;s{3{aF58r~bsOw#bV*dBM5L9E1YQrvlvWJpWZOv!+Y-PsPYC!^~2tIQz~|Ekk0 z30CM&lOZWB`(kDsSf@mRAS6vAyU>RemS?Rc5q*p^l0?EvUf5`>$P%S8cBy}&!RP6~jp03lpU7&U%>3|Xc$=CUl< zQ{qCnu0CIb(Hq@g8a-V)`K}fL&zLtyel6%lK&JIdiXKe8#?VLs>8arE37CbhJHge|prpINYama5_FqUY2b4aA&Q=0I@Zmr?xm8_E+D~wqRK$TGfV^ z8`8?w*W385`d=$=du!x8>aVcUcN-2~kphsN6^de=gNL7jD-VFcWlrZn_@aL^7MM%@ zt%rFWUID?_wVmU~kwu^$HU#TA$gN>J^lCjf08U5rR?lWATAm&o5q@kv@~Vca!<#Gb z;833-J;mFd#df&9ynub<}Iy4mQBzs-a z$~CP?ZlH7~miW!gi((KPgYD6>`szaulXxf@Fr?%ps$0BmVh;`tZd|mebmqv7nNRg0 zm{!eQ>$1l$_QShA3FGku)wXR<%4ejlIjoQdW{|U!hy`V+f1G?4HQq7w0?X}7%OguD zvR1j--zeGp?PFl>55o^xFkRs3a@ zKTTvaRD2tF^|-VxvWZVDp{wE(5-rwO0i0ViUP^**%Er9xg4Jo$uOeslF0W=)t-eeq z1wt=XliiSbuXtEJIH+W2I87fLN2r6Gjd8hCL&RNM?6_9h+`({z( zr^E2WaQdv7R*?_F0|UDmdwkkXCU2F6Aw|Noq}wimd}joeGhz%A?`Am}$9U-LFnHIc z+?|_)D_Q~x_N^}=k@r24s!;3EpZ!NPowKFMr+cKx5_bS<(V9Dc46rR0lO!VJBv~hB_-BR>!=}JKZzC&p`s}iyfQ|{a`ny%1LE! zkLlajbt^?*Ly<>pPu05v^4i=2UfO=g@6BS;VB6|fVEMkUnc&d%w!&7R-K{85N^2z0 zqo)SdUgZrIKaI+qYlatr#daR?*<`KTOG3+gqfHTKk62`noQ)4$3#k6M7akZcwQF>p zm-F~Fm0M@}rSVNwZv36CY)l@hr-aD+E#AxVr_w1c;y&N6aIaJO*J(P3&=5(Su2Jp9 zSd9aJB;%~+E$Mv_0BizCPBI5A`|>4h(KFFCnHBN-j-NQA>vZ-D6zn!lae_poERGOe z%D&_h{rObrsc6PPP5d*c)B1gLlmgcu290EqehawcsC?5|Ix7jH}|urjQ_vn3tR|3uq4f3U}A-QMYQMZ z|0sDuV)yp1jnLvKI12^m0*SnG%FzbX0_8LDd%#SPsveF?Zegy^VhaJz#F@;nk7$Da zS-*C)MvRguxYWFv!<38IK!%p&Q<6$!+EDfG`^Jg%BjSGJyb|Ar=}$@iNgzgad{v&Q=L4`Benn-4 z8_Fi1N_G8dO8nu zzd!Mx)$ZEwJ%NvA2JQvw!|YB{tI|zj#lKz2w}JN*3ga`%+c0~Ed5DA)L87ZO=hTel zG_0#;pF7}Wx28J7Whh|3Z5p4~jb67c_hl8VIaPRh$YP20+F_|-$!NYZyXBs#X?M@? zYkHV^K&3LN*X~(RRDS1`P>X|lwnHhp=WdNM&mwF#X|J}T|LGLZQ~*&>LS~mL==J`?y6C+ur1}&3 zV&>}o%xBu`{7o&kPe_oAILpkSCMp^?Bm|=o8~Rc;g)5?=>Xb|u<|1wog2hUCk>bV4 zr`eVw`$>G&^Qe+TRQG+e^Kspx;?si2{ zq50>NiT+dflr7eD>la(0y;~wnI$_2*%K0RU4g1!xW;t#Th43q;=wI^?!vS+QjRqS9 zZku^!B|-kim%L+BVUsKJOO?&W$*4OU^bsC#P!DTE^EWvpbay*$CMIR^tUsF>c89j3 z*bWRJ?B-J{1`>~LsTuCCt6js$$p`Cl0s52N5il^iYqOANLwFv^n|k@cr8kjoIgGCR zr8JXhErW3di+%c%2L#2-yl9l)NYFTx`?YL;X}xr^NdCp)H+|LG8jb}@PfOI@a-We> z`(8#z>Plk;p)W!W*?2v8t0d+FNBowOTxe5qLQq7wsLW5s7g75dG?_KZmd=X=@cb`- zez#{weM^@<8W#OVN5d}pz}pOfM}*p@nq}F;>pwwas7flqlXYtcWCP!4l}NF*`K)5- zRadnRgRYuBHVX0g**1T?DEY#2(Gw_8(yEsFvEqs0kZ{BVP9 zp!13Z#2})ZcX-#~v8lL7U3r?TjkUHti(lWwQQDw^Mn-sv^iuy)`(kMjq&HET%zP%3 zKILfD78a!WR@9#@`DuKK3LqB{;Pe&;+k~P;D2&u;Ze(jSU__wXF_(OiV&swxw7@?I z92yRc`){nZucz|wNH(LSb9JC%U5?!BOw--*b$Kn{^ZH~qQDXCX#=AAh?(D(1fDF$X zVyP%Uo@S$20YWZ4N`nJM;S}K1`%~`!L}{~aNFs<%m-(w!8H_1;iV%LfmeMX z+4IbXo?Q)nf)#IduGsvke!fOCCgsn#43@r8lTUccjKr39&j;b3^~%_y@H7(RzBsbB zEilJh&DbR-fR6ago=EK#d9I%cdXdYz%AXBal{Q2t#V4|k8`mxyfF+tTu`$C#7l4q# zUN$#K{F>gI#nV=w`q?8emAa2*%l7}X*&dO9$K7nC!e>%8^5enBi8tU_$LK@XKIw6w z3wjYicHlhGdpLV~@ST0S^5-3)dAJL_+zGsrl*P_@oMaQyOD{0GUE-wRhff7wVaEa( z&4$-zWHQC-^{Ze$JCVX(#&~0>>3l>0R;w`f%}Cp#xhnvOT;;_Y^@b*4(al};&bfi{qEI>07Yhv)uIrb*TyfQ=*|o2bX)iT7*RQvj+;ZgUO=P&l zW0|?8*E6t3>%{B0bd!DZ)OoiG-~0>HoaF_JoOK{$3&Vd=$BNzqnOKq2DL~8v01*OU z@?#4Qfj-R{!`p8hAz^&mh#!tC4_M=ZSZYqTL;f3gt42)_3tQ6;bvRka1zJe zVOX5B?idYvrc$QZzE!4o1s&wh2W^CXR}A3DA?{_x@LenX{^BzKzI;BreIl;5_nkj9 z&UrVBM2eaPDH`h)k*7i>JAse__c$pce^^Ly=!=MPWGl_rIN^fF{ZYt;A}Jl;YZdA` zxn9Xch{$Ms$R!f{EF#T~|9#&zG@r2pJ9ZyiAp(ahvj=Xjz}+-zWAK3@tEnHo41VbY zYd|M;ZZ6)aYelc&6I#`COp)~h2J3d=S30|St5Dff7IgaLp1UufTI$30HJ89fC8^-V z%26OW8x6ykPpYs2q}Uan2}=Te^Q9Lcn39v1I)4$YYv9qfcJc2ih}NUM;TBi9+rcZ9 zNZ{1z;*w4t78*yPVwDMqFiu-rON=sm)5omcQrtwGvoC6`0)pMH3eS}AAk&GEoHYvE zLW+yKpf>WuREzG^S&y3Cq(RmU6E$j<5T3RV0P5JfE1arkQZX3>ZS$np)y80g)8s`A zdq3OE^v+Nd?j!2!3WH^PHOZ4=`vR6WM)fIQ=UEK;q!PS*L{M%C&16~U3MPJ%ok-x1 z5BADNGqy)XQt`6_m-(O#T6Q0C_SDH6g^&q%`ch6<=+NU>v0s8+W(SvR)N`F!x-+P0 z(aszCB+3jFm~_TB5d|7U6jO~JnH-Q*b0^dJBr`a~HmLd7F+!XR2UA6G@#ja`Qdcy- z#S2iYVIfKhXCg>Y;@5fLgljK@H~<6|F5M_ZD$tV2U>n3wIno z1jli8JZh*DX32NWgyJv8nKyqbCBOQ$QiLHx{D>;^Oz1<%2Fr`gTKE)xhQK$6ndb#D zEM7Qj*D)d{?<*$DDxV0}^-C+8fo9#1;7icOWxI-|-(g6OpuMUNR8A}ZOi8)*kyN&$ zr3r)Y`N`<;G8#i(>KH6TE>1W4e9I!VQ(O=4s-gwjXmDp4I8`*L8+jCPp-#0~$UzeM z7s(DM|2kkH1$<0v$0*E3LgAnrN|t&vC3yihE(ATe=KRk&M=s#Ndrr;8Wh8=U<2PC~}g(y_HU^0%bkPQwji8R{`gQz9)65;82xQFni}y zBz6s;GkJ#1cRrFyO&K8ycXtY>NEl^)>aKE>kA4?IY;Dhg#lX=r$^3l}K}g|U@&ZGj z8cwpaIJ?gu2@2CRRf#S{gFL1;$OIGt7p7T>YkSCc|M8KI+DX2j0SL}H$H)7pn!@L7 zRJ(P_Q@05nH$AlAJp`2dn~nKXn71i&+1vrCA;Gye%;=8j$%hQ(Itz=<-n#!%kNpSO zdEp@K)5!o)=e5w~JW+zP&u*k5pYZt+QEb4vTjf)FQQ*nykL}q^;9!C`V0Crrft2FD zFX!fBmp-2@;51eAZWuuNoIb&?Q-S7!*ETp{)}Qxj^U35kB{S!~D96{5!(Tn~&?b8` zT_lr7{(WopByy^OT8;9T6$X)~qz?b<<*yIPl~FCNctiUAZeD_m+Gl1<`i16y=SFTG zKiW55Ro*1L7Ni!|Z3Chr%r$&QA*?NIowVy8L7ORfXf05uV?`4@(-QOACk&G|H_ zb8w4DzgqPCin+bUvs1Zz{QDduLqX3p{2NvN^}?)wOT9HlY4Y=f6JE%#bT z)pHc2$}oPnwI97yy|O*hE6g}DUv*jBrpmybn*@SX99XuSBV($J^X88VL*kmlByQ@T2D;F>|%N1ra1ogm}!(^c`uBK*0z21&)<4-x`wt;2zMtJxiY*F!0|2Z;CqFy2Ue5& z3(?}y?Fo~oTP;Wpopi-o7wfh&nRErfy+k~W%6#EH84KqR+u`U%tsv~C#-$&vfA!}T zfPsE-3!`WdKD_D-GI|X`{zMD5RR#sl+4OV1x(`c~his+mZzTbgp&{TjyZ|z*J`M0% zDZpvY(Am99qM|D(J$)Ofa>m}HVW1BGgHn0}GoA`}5at4|XnJCI@A!Dw3tZ74B(u>R z5coaV;Ig2}kc$4ms+UpfcT}@Py$vnx&eyvxzm9RRAxUAVrQe2=dNkkm{We$tdNFaj zzCeXCGSJ$9K3oE^5e61xy~V%`<81F^^RMD>?qmHC`&(xxUL&N~WQP%;#2R8gW4-_J zC+k{}T>ElPY0$cX@4Iz$JnB7R%XWfsPu00w+B)u^E(X~d+%?__5{n9O!dz^}m&kHU zg2-I(^%o3;>O{;;#a4u$K$aK}Z(9$>{cikCh52(2h2YO9+kV4E%Z*Sf?K;~!H_3V} z)51i4Vw*mmFTcJ8yB z6)f-IP7DKrs6oS|(|Kv15}Nw^KEm6RfdTJ!$+0|dy2c5w6%2V!tKD6VY)YJEOZlyZVu z66uzOehu8~zbuo+HIlw}+5F+yqAI6XsfS6=AF3yLj(|1Zx{LR-pWtnIiA;Qxot*Yz z!hTvuA%yHI(353zVZ??_pv+et;2$=W7z_y~IeyZqcXBNhV-znDiP7Gl7UZ5U9se(? z$d0}~#uyYEb3`waTvsl!1%X_?UX)`eeHj39E24m|W#(r4vse{3uh$ea&N_}*ih>lG z4lQmEY01SO3y)vo^WNzovT~9XPIV)O)awz#F@9ta@b64w4FOe*q?onRR8s`M_-!l0 zK4D!w4&-Cyka|IEN%KTEdoiF8kUv@Z#87`pbagazN-UFsoiq~RGcXY%elH#*MYI-k zXcyOyOCl9J3m}CQVQQ8}Yx#l-=n9uEbqZ|MMLfMcP!O`izqFBUe!GG8D1e(%SITK? zs&`HXI7k1NpA!-J_$M--BD#2t2Eom_-#7KZCJn)EQ5?Q|EpR@1$R4v!+q$>Cux#_5 zOhjC@+24zIL7U4piHangwd2j~EM+`3*Ee#uu#goIpbqWvcrDsIc#dJL$762Dlu_Lv zIW2lJBU~?MoR64MUHXS8#rX_bj!kiNpOtnd`$f6Wv8A@)1Az1d zZ_Lc5H7uPZJ2y{NkBoYS?*j0Mr$`k(e|YU!tKC!Tqtnymf!9hZ*+lfy)(P86BitgD zw`tn$I$+-|@XqXMEBWd7iVhY!{ms)303_mc5;VA9vdZ>HF9rXd@@E-txmTJ8F{ZQM zn&?u!$X-%bHy zFC8he_3TC7(F4h1mzd^%l1oxPSK(wS)F-en=W zTZTi{`H~>f%9OPI1Wn&ldsV_PvTTt&j86JXpzg>d_ax+aAyH|L7XJj+&<`bMM1BQpe&r@^+8SheuVhE{atvf2JGh<|A#0sTo zsZj?Q#5sau=xN##$V589ELhRFrWCH@Ts;#6J71KaeM;edGs-qusyRtQWO-o4YD0pr z^1KvZbj@AO$Tb5`Whnn#y8VMw`zrM7lAfuzHd|%s7vhRmXKC}ajClDB6J^0NmGT~;%LF%%z7GetJdK_;+`Gox7G09kC)kTG3j^aHQG zOGnP?dD^u0`kb_(ty#HftdQA2B&BOXuu;+<K2bxCvnWv7EhmOb%>$vfxT z{#%WVHlNwmInH+X2U*t~*dhF+C#QdI^F!m>4q@b4B&wHVi*+*te5Z%I{n*PtHq$Zd z%&}UR{#*G6r9iRz3F&bCA*mnsongwS9Rj3h0i2#r-(q&^C!8_Oio7u_@;kW>SUb|ya7RgyPo#pCZboPL(eNvC1;Ax}TS#K>)5aJ4w?iAkQ>_D0 zh-M%EDN{%zT`D7sP9k$sW0>0*;qR{cjJlTHEKizl%q3{ILntj=wnnJXm zk!AHy*w2B!FQ0Jbwz8?epLTi?|Csscz`ch5l664g%E6v} zWrP*b1^~FASoCfx4olE7$g{j8`g>a$D8NlB zrgEw_Gdo=mU9e85WI01+h%!GvT2C6jvw=1qSbV|HT0P|52l&sCuLON}Fp3_YiSh>Y z--CEMfPu}c_8*(u39Bzeb2hsH@fYsdhOpcH(vIwt$Lo#R9`vxV)y3g>g3d5Ea{K`A zEUdYU&jH_JZv-DS&@+7mR{2H-@rIj)Dd4jjk1A4WhI#k{{NMS1v#8lXs~N|VxRn@n zlZWy3UHc1DOMkb1ZD3epLvU%Q@mxf~Me*Wt^&~vNNsn^LwJo#7j>wnQeZ~NKRoHtl z^n+wKL&ocnQ4~cvD1kXMRj_lqvcjV~=UczC2|G!XLPcqQnCXuPBF~yf#!y(HZCLmK z!HCjapgMIh`O000lDR}7)1b;Kn4#qxBD}_V(S4^Rf!W|o8P0q7vNt8#%jBGNA|CO* zLd#_EcbQahX?EP6$5A4FQk&}LneDy=?dFfJ{g)XBy{EVHHYvPs89h;L2i5B<;GDq= z=d}R&Q|V)2(<>hP+5&mea4oJywc=@7LHfNhFR#r+T@`V(e&KbEHA7h6i@jo(Bk2=vypHPNmwvz8qh!Hs*h-pWDks|K>pXFU7y{OZTZ;`pEL1u^O^fFBY|*#3>r*Ena|v=k`XBWN5AhKpU}mMdkyCM zXHlJ>(d2i5N$3A^O~esH|LZk5Pg)UtsJ}lTb^_ESal;g# zP+bw4$PBOwZYrq){Z8#KQZ-~_5cIfoAgTJyDaoL<>-PP9(wv+6-Bf3vn?f2u`0~X{ z^vB~A1^jNP5+37|PX5n10L4S&o#@#Xz39{MtD$6(^II!&KKRAo1B9p1WePX=veS=C zET?%EqXjB@9;58uE8sbFX6LJjgr03K!;?g^*?$GJ;JUW37R|>qKcYmf-t+<^dAy1x zrJOZW^VTC&*HUax<6%RgKFhPul%dKwZ<*-xSF%-~SIxU}ABZE+YEbjXy<$haTyiz&m1*Xyf zSQE&yHaF~Va02&4g@lqC#>4K1&$K_6CR{!CFp6f|t~|~LRmvfayR>618FJT-p;6<=}Ehh?94At$$OCxKhleeCaZ2&iT`a9J~5W~2Pk z81BMqU-M^ylOAx2)Rk%IK$|`*TyDLSluJ{0ZH6dAM|{Q!H1EwU!w?&tiyT#UT3e{~ zM3;{~GjRU`#Y}|-fa)3y;xu1gdW__bPjM#U} zJ|p`=JU@(Rz=Vg12@m^_OWb_r7O!EUPQhvSmuFZ-x{I1Qj!KR`^;R1 z!I0X)gI#5@OsYdoovPtauBOI)>AmUm((kP-AS?u)-am|D&+hhxYHCFa`N`WBQTR(S z#c^>!28{eLRaKiVdClqGv}6;Y-kui{SOPOC9E0kCA6P=&cp zNre+=Gs1+4wC3dIHQzE)dfW*)Q9T-kDL}i)T8qE^KQ!C(wChr1*It%`{q+EV6`57w4xWt^# z+Y^=jl(91|z|TZ>MTGfBo% zjQjqXnHC8+ls>RaHXO8;vKPxMoT1wqm(4%p-M_^K`KFsy7JN%RjwfN3RsPqH{8_xB zw8ZNoc*Z{}BbG#B%_wWTdC|LouE`A^H;8L`D@R4y2$At7Kwwo(*#OL}R&+p2@}{%r zLu59eum?D4KN;0EX}_0nB06+pg0NnmY`25yZbH{EKV3L{hvPqVthRuKas>H)(9;^Z`jUEp~pLE(0 z(Tj=#Z_igRS7M*C+dU7x{CBZVDemhtpH?YE1mIuBR0vZWj2?%HRs!x41NTlS?nmz+ zWUp?XYOgEDQw*m4*>rhr!r$afl9dz|_Q(%8>=vKypKYTW1-@4i_(Xqv0f|N#8^q~$NS;)o|-Weu%>fXFPRC;Htbo+RB61!gA z>PFN)K;s;lOfTo8(Hr6pM;j*ab@~Xw)U!TG!tM3!RHIJHw@r;tgC$$#xE$*sv-yli zHl)c!fbo?DCK~{4S$6EI9=-~;@XelC8xT?Xo*(agrgur0q65&A0ZxBa+l17|1f~4@ z$%y^p9W45-%jh#L-$S%R+UYG{6{xO&$;F}a;pN?hX8gJ>mIQhe{kN~-CPs|;&2i3o zTRw#0WWV8RkqEfOUCI=JzVgqh#WJOwm*S|)Bs9NB;2$?bwg;VGcvG#XQ+`FnWZp~*cZoe|afg=9cAp@1+afjSTP4;TUJ2RaSbEDJ$ zcCLQ>15&2T3J=xz)tKd1JN?161-p-QA^|? zy^n?6vD1g1HHE%`&=9I5C-GHqkD(~jCFLd=kbi41Fx_`ozGX-YK{NAqD{$9uldNo2 zcXds~dnI!=z=gMyfWirrE;m_;MT0;~2#XmQuz-Z^t_`#rb9t++x zCIV`UblHz2qnoTM(V8fj+p}r5VI}oL6Vt^J9vFhlJ_)jG;Ia0>`>}SsNcv`1I&*!p zaIKic0+z*KGjsE)kG}mlIcLGPTa*sO`Ao=W2%1$)7I*K7bc(mgsn!b)tPLb&76-7f z@P2k-NF|44#n`$qZ>MwqsMde>L9O1a1LV~N>hpste4H9znIloY|3LWa>jFg~3p!Y% zsJXJSG`q)&U`yZM1*6bBa1_i4bi|1=_b?G>W-}EQ8>pvES;GtQn$06@i43&rK_Zt^ z8dqel1B%nX9>aiavBH$w?&u;mkA`f%kj7hb9)91e)0H z3ztJRsx?y%RhGZZaSyU;j-8{$)n5EK4{Z9`F@D?LuWwRXn0aSbh;~(4wg9(wuS+p$G~rWASzg-+gYywvqd2MK%waT} z@FLa8qx50%cQHvN7b1FSK%~B05sx~^>e|05NNH$(EuQnIF^cJ3?@v4tl2;P-P>156 z!sWN!tktr~wTbK!C_11fhnQ#FEb4Y*rMXz$#kE&)Z$&UE$;|&*qr25&!*|;cI6mS9 z!1B1Fn4XbHOf$Gl7WZgFbtS5dET(5<^YiO5Td=x=ISA=V4mOQ*ahJZKH9avK4?MIJ zNgd$-l;|!7<-XO7#^a6FwJ(IyqTFd|JNR=6=nhpaz9(ZabIJQI@)9*HvmORr`UX|s zfT%~7Yu1Mvw+}+qUo|qX1lL{DB>gUbp_P;x@J*dMNfe>H(QSK&V%PPg&o&8doF-&5 zmdu2@25JGTXI7Q~z5p0|zRdsd1$351>f=>o`{i$^{Kr(Q#|^u{v)$76rxE(m`+X;hyU#iI{R1byzfa}(I#0Yu zP6HnwNBUGAX0K9n@O-i3oewU4CYyM8TuKA?c|s%IE-b4Iclh7iJT=8rmZ~4TZA|#j zFJxe@G>89ugBKh#n)A&*QFN`Yrmac0R+ctcvsO8&ZKc3A3_ZhHfRk0T$*Y%WxB4bg2Jg(-=wUtIR2aHFe-4pKUjs) zA4R)z!*Hlche5ejr@K$P$J>2C$I&Y zJN0o)&4bvkC`t4C0gj_dqk^I!UTGbJqFp_w;Le_{TEh?r0nJbzEsEW{QpqOt^J8t_ zvA(dGUSTps+g5YDtf*h%4h@ae3KpB`VuGL1(yD^@3KSm+keB9L0ms%CSp zZ#5pIJL~ESPHuw_ocN+wOqf_0a}w70jRFhzk2Y+*2f`1`!pDU!2E8Qdnk~PdP-8B%P!!s(|Wn)v{x}v!?oj`w%1w3fST{H^tCa|mCs?s17%$i+K|;mQ7f3^8%YkimdP!j=2%4o*4?j-IaAi( zK_A0v@S>n87;$zf-QA!GJdZhPlape6uj67XzSlF-VywU&-kpGHD!pxv+cu@hJdGH| zb)W?-;(v8Czo8i{#@iD?s>P=d21PK*xo=HCj&lYvBeQ-jVVim6lzkjKe!~cT59(5R zr>vS?`Vn%zJ^g)yp+sFcu)))cqLZr~Nn_0=(}Ee7tSiVFi`COZ)9u5b7) zQ{4Rv$z!G%XG-FAs!AWu?8Q|=1dG-t`kNXH;c-vkvj;gaYoRDmOOr2jEn2z@@gEAMKkAZZqme8w zREI>}y!~KTg3OLp3fnc4v@^pNKaNJ>RXj4$tO}Rv5x3Hk``}ycFxRJ>J4*5@L^o`- z>FMj|dXjkb>E5qRPmLlxbvyuSXDvUO32FQ2=xNr$h1yYZ zPUN-vjUzCC*}bBX%Xx3~<^5UXN=sCo?rsG0{_W0hWE z;hS(R-K4_$_3+&4@;A)=-^M~1{_AQtD{bO^sa@t|UQl;!(}F$8V62YzaAXx7;q?om zRrnQ!|2f;^8Y$5?c(mx<4DZvup3&1}``kU8^Eq&*EFyfoSymN#SYQjd418MV6om(0 zKHUlGJXN;0UOZHaKJsSdxP&~V8iAjDo%CpHjFSFroByD?*p{q)d_wOz}Wy|b)4%qt*92@!^2^lE5c*YrfXZJ|wmzrCDy3iC8 zsknaqb1u*UW%VKkiALn;r@RK-1v=Drobu7-=UEto7XG$wHlyBE|&sy|{ep4MM=6S<9QbA(}OUp`fOAN3Ty^Jk}kxW7K*D{;3i$7k_{NVlaD^q%3 zxR5aGRLVosh55De0i`0tgGbB`222}6-8L9kp(#4IEVm4*wk@$kY=LG`Ps&Zc-Xt|e zRm(Bw@wqtZ($jCs*8Q$f*G>^<8s|NUTKzdqz&-)>a`n5t=6)?{$SdLO>t)C^9GZw; z6rH%MJ?p~P0#aOcgT98GnZ}_PO-H*0cpt1dhs4{SF<)+A6|qipDezVM&?+_>lFwE;fd#w|j%57DY?3?$K7!Da zcaRloO!8ajG*#ru%#I?CjQzB~M@T05*VhO|@;a&I%-)$(w2!s~)Mwey80kcqgXF2F zXVZq6)TuOHmC!xY!!7?=VuG7Dh4jX!Kg&v9<(HzoAS1!dcY%1^`Xr_y96n`g?PzXB zMjRsxrjybcU30g$)1|rQymPQa#Ex8s!}|#R4`0{j+gSLrsXOh&i}7v=WZmbH>Zcjl zrlCY+(7dQ1-RNQiLMT}M&}N>qoNz1S3!{8Zh6z(*&|uWtGkj2eRQaQWRJ@IzXL?2q z)Zs88$qz4t!{W8F*7v)#nrvDM*Ml0vE`R=K<2JlxATyjzS(J1=vE-kQKh{ zxt%IWpvbem;8b}tKX0ptyg*2miG2Xl$gdp#9PhW0Q#6`WM8jc`Dk5NjuRgW$v7LF$ z94~nWnWaCeAHX+IFiV7k+%?p+4({!`!tt7Ipu;nWFV}^TidH>eP?g4n##rzgOTJ$| zfao@WyrPS}8Cf%qd6K~3!wT-(`?2r^X7wga?=KR$=)2xjNtF4KWxZNQALb0^MVVWG zT{P9&z_bZLfjTT{R)v3RuxHsMscKs8^~?W@w)c!`>g)DKEub`!B3(dAD4{96OAQh_ zB$QC33WQ#jq9|3Q2_!+flt2;)Jt!zDRS1goUIgh)ML?QxxBusq=e*(=bFDVse-Th%Hst#k)$adrn|h|AauoBHp}KJJ#*oYTACDFoav(Nmz&ke;pR*> zwBWw^msdeu@>KLk)?RsyV2_5?r-KnJC43EZB{RCVDJbPTB|Y}xXG4f^dhaqzx9Cf+ zq!jpDI^tvK4KLevn!<@!>WnZn9#*6ab%_TYfLNowR2 z4S5d9>`HbrT}YgSc;vF%nLzVPnzX9XS}25Lthuj%h?qzPn4+BspD-knDX#e5_0Cm%h&6T%ID7+K07_;kp0LJ5T14*sNI2=b?|WqGgcjw0Uo zAaGE`Wid`-N24sNA&sPwF9)U|(dAEBb(IRB>FZxL#`%ZeG!MoR{a*^?TC~01^6>KrW=A;s zI4nd6jGG%w3ut}(@S^s?Wqb^LOAT8&bXb9)5%2$2gY!hgFnrxxJG8~(E zH~&@LPt@(whPR>b-VQcA@^xBDhSQ3<8!3+5&xN*mI_;hOT-r|BgJ}Kc4#xnj%?LBE z6@eB(v}o^?af$a3`I0Y?j>KHv{6L2<9q;Dc^#fNcjNtc}jDerX-w^=}A$ReYP3q$J zZ1;>qZ!g2lX}y`Y-iz$i(l1yXe8(9N9h$n>nzSIv{rG-;Sy0NA^asgP`=i@e0C}O8dCpC#2s#7;ljXp zu#1e6ray&>R)%~s)!;#B>`Y!d@?iLyiKsz6_;LN-p3sO4D8?cZ>JocIV3zpe%*(+7 zon|x(_#lD&GOEfjb2B=~{S9vrL5c!R)oHFhKoE?h>otal4rKUidD!e2VBh|LX8NpE zEJi}r*MRo??1*)bWZFU#r6 zQ~H?NaoH2Ys-TvxS3pv|UqEbymt%;w6P4Xd8Ld_3p#=YpzVU6X0BG9K1GNN~xBfoO zcW_p$zUMs%3qcVkZ^PT&}D2@B@>Lf-zu}qJvbW8+$7|&+ZXFDTrg|ln=2s zAzunUS*vY{2P?|K5`VV2RyY!|^bOL{`vqxNh)Wl^N%D!{X>slt2xaaa*!5t`xL6X~ zRQ$tA%JoV!KAhX?CW16jiPWnQZVP#PRx1y2MzfAIHer1t_Nln85IJd3^oDYr%It20 zwu#hYFw*55pLLQgLkURs-EiMcyI&qy_o?TE(LyG8RGbHYNc`Vwy1nM(C~$O?UdEC1 zVe|La*k!@vI>iew>%qxezEd^-z18h2InHS`>*} zEb8Z2E?_(V;YA)9;SN8|mIK7KmiA#Z>GP#4@b{3_4m9BWo&u`!diUr=8-H05FGIdIp6 z!dLF_X{&H94vQim2{1JNN7w;$#I%e3Dbk~S|Fx169EdmgvK>v&;eJAqhRyBv5W}m`VHKFFAmm@|;Ip(Q zu|O$ut~L4p8lD&lff(QIC{ju8mi_+D#H5PtTbPVtU|0$_``Hd<@S}=Z&Oo!?thJEa z-(VI-_DV-kwK-S9?d9OU*rCCr!?+O{TCq5}6<8)@iLy*`et0n(x|29KmMgxJWh`|F z8D6E`y%yQCR{UvbCvMIkFqN?xbV>I|OsVn$0P4H2zE7E%5))+uR_nwu-XO%3h@BKT z;Y;=oF??@Eh}jq<*G3*w69_cs;>wMTX9r=R8JGC8+y^&r!&5&VQPfpx;bnenPc->f z>TyzM`gcS`5+PWObgNzcwBDLw%ejgY>lsx zJi!lbip$yR*zDsnG{6yTZdAjTXY{LXwP59;&JT~u?!}WMtu>dHxm8lSX|Uz-AU~it zrmyH!s(C9l(D(u7cP8@gy(nmVMkRQTpg@)hsa7r;AlJ~Kmhy#|HRK#dXvhZv>_spu zv^mFDrwn|rRCcJcZG8XX@crByT*as1Ll$x=FdImCRr1m1p^W<%myhQaD9Fu=SS9cn zrEzbDPn`X$qsDJAmgj6CEHNflwczcP17kan$nNTr2}$UKGrGlE9?b$Xc3uZs7XWWWeA-;{_BS} zo-rFJCYn<3LxOZ{IE$oFv6EuM{!4glUG?)s7wr@?uZov313dPxeB_G5r_SxAAp~|e zF?^=$W#sAhR{J(^3W5HGIikYsm4j%&OMwJV$Wu=36a+aOEe6Nk(yF*t%)&ZOe=dUV z)1-e_Re9e$Gh`aUvcMo#IZ1g5xObiV%~gY7{w4w1Qq= z?JoMy?f6GCBDo(N=MhKQc<}?z#rpr)jIoTbEaMbAXet^nVADa;0%_Zb%g~4foR8sZ zWQo3kcq81`fRZq|-OxSCL!yG2#j8Q?^xR?Rx}c8YGxf^!V5cXld9W01in%U~o4O27 zf>#|I^u~N_Q*gBzYEc4u@HbzZ<1{#CL{}gv%cgl4I?<(l-Ev!FG9u&UE6`+mJG+7m zr`c2j`#`J_El@hm%-o@0sUoaBwZ;3ht3@<1)ccmysl(s--?mI)yEh;Pq7Pm)ZKpD; zRf)%8cgu|bkBhR5X;pcY-~Ms=c_Vx)@&^6V$Qi_kk{tS=J2{W(UYlp=gBd2{Cw_ix z_QxGOxPIP7r72m&G1-7$O>hv&DJmfO&^(r?~lt_~{*|J&( za4$)yB9R#2njgQhHfR_HY9WoN#MY41AVI-p)SDNMs!sJq5i z=eeVa3`V?W;A>5Qy!Q~ei6BbYoKstt`HhcBMg$Z{(g)y|-kQ&mQU3D2DnG-2A4MdzM4VB2+lC1(F9(sRBvu;wLpR)i@vHQ6--(v2P0U!1)R3d2Tc-N^_0-U zs)hbOM+Ib$3I>obYEbAV#agEtyN_rIoBm1TU4uCG7sIp4272tQ6p@oo2^ULfT$1|< z?Cw)f|ym+N5XFoAl?D5PX}%e@tRYSvXy)lHn`I%XLu^pZ%QjH2Lp+9H;`T5NY2&_q>EfYx``z+T_bnAOIGz zx=w+;tonx#6mAu5HgB{ZKs?j_UgSj8rQ}A`*7F-bryfbLI6In0Y>0C^Su_0bOyH)k zs_&Ym;v)tMfV(Ri7@L-!PGt;mQ$3uA__%9+5Z*QyX?Hqc(B=pnHFaC;v~EuoXVVgm z-Q>Q8oL024T?!P^>Td-@arGDdaa5z>Z`gr{df3RsAcxE7aw4bG76{4MCKA%_@DLF( z#t>*ibVO_6o@WONa3U3B8Di)l?@_*4hKir*tE1XP)9-BRAE3j3N1iw^8{dsQFc8WM ze?K4W?1_!co}G+eg8s2ola!$$_jj0^jU{=Hgnur%@xlR7PB>fxItp>{8k!vUV%Zhf z_@3VYoFM9r$|{s}&3zrOTlX24)*Qf72_|zEQR9(4F)Fp0{zITf0R@;KqGA z!$w@U!}3qqk5s|r0BwdP(+?lth3?mOv^PYJS9JxE+!BDMA_E1y6gHWOVl=K zHdx0Eyuc`%#(7J?Qf{bS&b7vxT~49uvr^uu=|IZ-vHs9}t<%T=hpBo|^!7YfCna~_ zhXO*;U=xSId38v&Sd3uvQQxiz8$`A1=lD;mhRnte-8|TaX9ijK?l}GLPcjLRmtL}NGZ~R77 z-bF$N$sJ5sDJ4FE58FQFOGEuSV_Ju5!Vp^~mkKv_x7doMgfjLOj$ekTWuO(^g5D`H zx~>O9$66d(wq!2Z?#YwKHi`-qvJo+m#lVC5>*Bh{~+x;T_Q&})c8@KeHPZ;5(7Hs|a( z0C7gRZFPf3XzAq&yYwwJrH$Dy(rdCdo%~=9k~F=6Hz=>;8WVV~U19ry zz?xkbs_R8za*U(Gaf-Sr)_=;|N(#!7Tpu(hkM5I4eJ9UxJfXdO7HGbgN2m6&Ef9vm zqwc5K#WbtBts}1U$o?^fbPop3vUirlKG4IH+TLkr*2Pwa*WO@%n;d^*q$*(1!oREx zrKLV|63i@;{ep%7y?nBx2Udyavb)T5=<4qC_ZBQvMF&m9 zsg79n#{P=(G*7`+j^*$RJh0Hb9=p9`->b#B(8UNd7~Vd)d$Dos{Hu3e4d?#60W204LXcjF;Yie;5J+6PC%h8*O-bXBUEQgn ziOxNRY^m$I}F9fZeIw?t%06srKG#V*FO1Q*^%s814;)qqNWS`UT$bd3ckFRB7Kr z1cP^dKSl`qJ=kOnd{vfwQRlqs}c+y9;-~?C%y?iaSgq~CT z>EviJ9e0{N`}6cS7g8q@O^>?Fxt>XDjV$NCucvqC=;Pd?9gSyO{F_H*=23S9t7szI z|FYALd%m2^uJA@4%zxzhEw)F`qr~Z_c$hIXxPG)i=Cs3CE1)R`5n+Y+Qq+32LV$^5 zU(a=FkhInVR&-rij<~{)$~7z+Ehj+$UR$l88lk)cTr}Mu=avUO_{9)NSP4&4>E7^< ztLQo-M*ZZ`c*gSzKrCotF&w9htDnVX3sSO`*EEM+*>ZyXueYK2GlQ%bgS{q@ze|$Xl2yIRqEvJDZ!L z7p#$N$)_il>;0#zff#r2sw>nRL;NuOLLk$vGfzs)lC`lZ{h3>^D5~XQ@IdfmZ?^C4 z{*S5lrn1RU1gBE8M*#lTzOUgMz2`u|{LAoB;Vc43ZWPLG=Cl6NE7$xK_2+zcK;_O# zVUGZ9?ULA@<>;4#c#A{dmH{qfe^1h4$Yksgx$AJp7W(cDS!_m zRTy_KmtgwN@Jk-E_(a)}!|=|L#d3C}5m}YFEpbUk*IM-UHwrdO^8Jl$e?qkai<8sg z@F3Z9&L8Y2cZ+cuuuV+FkHlKo7k-ujGPhi+dZR(nUHllpn0U3`lW}8SfPyQ>hi`&! zLSNnlgSsGXOCq4|6*v;XyRFL6U;f}lXcD|Zf%<2#k|yjVufS>@lrJ|ZnyM`4n&Az5 zDy@%lzpinUNDODruBvopk7^yVeb504YXi)m3~!tpx-()ICI?0EfhMoutBk^Z_~hiYVNAN9Oc)CV1GTUlx5iHn zP&QO%nqYb4Q?nCco&1-_vm48@WsLZAiC_c^Sy$>Mg%}D*+`Qd8VT{AX=#m)x$_?k{5UP>=F z>$k66%tq#x=jqJk8r3DGq6zR(&J@Ig*Cu7GPdld3XXMA#k;jP25f2}BM*qzDO0x;D zZQOODcc9O9RNF@)_5VnCAqnqmmZ^NHVmv%!JZfo5Zb^i^q?thAI5orn&#cnH-Vlpi zd#2mqabeG_#xlNB$@#zIXgd3*jpsZiFr1B!r+y9;`TA`%_Evo3D34iDU3-wX@`vfO zkRiQR1PANNQ(bseZi0-?$oP@n+@He1Stkm;8X6a0o$GBJ#YpdmjdhGI_c>=G7*;N{ zJo!0_1@)=Po$$S(lm@kU)v`{e7a$l`t$=sH5&|Ad0tcyBEv}oo<{sGabbX+64uXz2 zu>DsM+V>Ib9=DrklK?2laJcz2*J4(E1!Z zw0V=+I8kST@Im1(gbvI{trezMJzXr)*6X!e=T>>t7CV%PMdu(VW0RH=a@V~K<^G~6 zpDPcD;rA>V06&&gEJnR1$(z~jx4H%ChDAkgRHko6kMyknv$ym*8gj?ZJxe|wV|O_I z>5gx``k|{`g=*9-1Lti$HCO3!u1>0PC=~PQ7yZR=Oj`Z$Y^2-%8Eu3OHpeHr(+3qq zU<(Xic~@jdsIaRuLUq(CwfNUoXZcreOjn`jf;dSn{wZU{NC0)3rP$r%6s?W0V85TB z_N0!!#G=KmbP?0gGC=1p%mO!4$=RfAMNCJtOBDUYhQ^z1KgzKTZ@hx1iLx9_{7BP* z;Jd@tiVg@c4bY%6p-AzznVD2Eqd4=Wy6ojMMRuYtip)0WV8U!)&NEcc_TRajH>&XE z;9U_z&WmdDygt<~S&vL+1klbZa^KKUA zAcK&ctH1won^laHtyQkMIaxoHQX&5E6X>OGXn!l zU4*$`fNaE<=B!(-qks1M^~mSjSgUtZWkG2O0E%Wi<@gXf=}8hAw;WaEG08?gQ^6)~h1F3@;yNW+Mu?$wU@5HP0Z8f;DN}BZtGq zQ0g^1zQvlFhP-vYK60gO7Bv*W8ApU@%*6Bxmb|HzR8V>+1ukn12U$z_A+V<~Wj7rM z+(vk`Zj(xm+KjSK?E&A=^$`b{&!hNyUf$e^DG#_rC}W-djTh7W9!7j2750P*M4%W8 zSzHmMj=klD7%~8PTF7XFS}mf!^k^sp#3uB9tjw0HO}z%l^1vd8v$*sEUNG_|s{uZ> zff;nhbo=BRs2rdzNYMipzEGjnh3}tBD%VP*5fc-d*)qsKLM?X`i-30)ecVdlZTKtQ zA|q>+Wuuju2xB{{=1E%Wax-6iWY@jRB89Jd51U{kDK^sja1l1fYJsER-9Xd*XMx2$ zd1t+usODoA@if78fX?Yr{`R2F-tQbFP*m*m&DQM`le7|E|Aid4PvJk!i9S;ALKU^3 z_)2@0$&iL;1dpm|hH?~-PLCyg!g8npO;6zS+if1o`A7;0OlWzsjN8VybHOFM zn8$?wcWg-U`1kGFf+I0g?2TG46hZMutZ+2s!g?7at&Ss(Fgn?YZfCmCM~)3NCrm~V zjII@1#=GO5TW&cPgLA}Q(OYX#W#0gJV|mB7-L}uHZvY4Hcp9513M=v9P#6%v^(nE) z>yLd=R(@w6Gq?s!`8Lx0<>dJlcxHeN8iw;HqNjZ5la}3%^%T49u6SdvuRG0mx|UT}rRthTg*m zhWv^Ij=6tP8gEs(@E$-`U^!ZdK-_*0tH3nRg@XM=(G=!~(k%dP0}!?Lgx=eJp#!7{ zdY+S>P8#(_!Set^wWlFq7SKQ7064zTSGoRmAox*x4{&_uY>`V%%J7fw29X;3m;yA= zW4WUneu}znYm4~$4X!1%^3MYsMxffZve?Z_pmtLWrA@x+=wG}lhj(69;(1S!$N}5h zk=Au0a_JT}6+IKC}RSEWB!eiF%xT5NF6OSFhsk<=9I&&Kwj_mPAt;K zdc{?+kI82tRc@-uPwMEZxde4Zw+76g#Fqz1icQwW5<=gw*U8S8@T}mB zMdu0>QH}teJYDtQOAvKH8jIn%7kV* zNOgXSrs)2uLakuSXslx%Qw>vgZi2jbEi*IPKs)a&KryIFuo&Xh0%GsntP;w&^_<5Tem-Yy|dv{F~-iE`y#=O%97GHVU(wV{Lzp=?x-#5!ja(pNpJR7n|&%6 zN2V^}qJ}w(++Wc>F;^IA2{?;UyL8V-(PhkHaf5McrG(W@1 zX?^kK&_XF2EKWZiBydkZoqo`uAk&S)O+9+*)MLy*nuf;3m{?T~;?^Y?u>S&YN3Sw$ zvbf=#c8#UtIZ3EpWBiOcT+fSG1}e=VGM@N%F;+Nz|2PC zwtDcOYeu%PFZXk!TF0VId_NtO5ot-i@8C@n!EQA=`mIw4>br7q7j0lw8usa@DRS7E z=T2dbKmr+SEIWpodYC4f?pnkh(YXtHV7sm2OIMoPlr?U z-2XJo3BKH7GhFpD_u^2rYBO3KLdId~kXHq?cJE9C$-fL;!gM7JJeOAPobyz+Acvy0 zh(l7C8iDRc=*rOE6&aXs=X&F7hH1C=HH^7amiTnVx?_Rg+j_Ykslqb>2?^<6W7`7z z?&mgt9}?ToaL6D7SPY50t*TtdSl59tU1wEgxJ1#lcvVJE>ucO;}>BgQID zdxlG%%*OuMLqV;o~lcFUYfXVLNnhOy%l4Z;ejUs;Y$_`SFMZ-qxW@$`*9a z4l0I;*nlD-!;e}OX+rqu)dfa{&)CA>nsy4~bLh=QY`Dv8>p;mKs1woc&B{0&wo<7S z%!(U@>DI<_YX-w5IU}SaWZv8ovuV$Q`!E?#s`ZF%JT`q$cU+}9Y8yB?b|JkeG-Y(X z%y2@v!h9j-!%}-)FMkaW9Vst6V3i4RCnS*WU1<)vVO>y^qo^rmP+&-0TH7s?E$I(p zYD-m)YBAX~Pw_B$p`@Vb5XWlp6F)!w5gEE{=xL!TT%3x1>6-2l*I%>v5NYa0&dBC7 zhHJlcH4#C6zRlQ@T-^XZPAlj%{tlN!_K4>{BAohL96Gnuy9=h6Y7XlNp6Mbrz5e}EZ4-6Cgb6PmDncb#0tzsTAI zCSrY4GUAG9n#6Cip%Bi&2}QffJ{9wag!hL7+%F=nd_5!CuZWfmjm}LzEi*$)Pa^f6`=I+OGh+07BFcw( zE>qUgQ<)1~ag%-0HBdExm_do!y2GK74BjKn9MFW(IYdPpl}lkc*fl1hJh{;{VKs?~ zG?P`+aZc<1Vps*ow~=q8oD$E+()h5zZ?^3>d!$UJi>`Gp$J3~&E9?F6z?qDve{B4m z@-&>JP^`eCa=>s=>68c6!&Qzgm}K$L^|Y24D1q$9Hp`$8WZF{JFX`!s@ZC#;ifpQS z3XYR5R{oE7TxC%M6r6ey zLV5QRvi+fgOjeXadE18vEr37h!@`KKMF~7JcW3>TO@ZTX>`>dzdfN_paD8%tyuLH3 zY-b}OTS$R!nnl$uTS2utb%p`UtOSD(X@9fBfr*Y=acPqZjXCsRjc>$4>P{gO* z8wX!6wMJguzjJ1~?(Oq>@87AefjFwlm^DzDH$8Qc%ZmQ^j^ilPpx>jC!-1-QX`qvgprw~LA{4z&U#TKHhA+e2edBR)u zBhG)|d)PqZ+u30N2%TI$#EuMYl>dcBQr^L<-!8)5sY%T`DW}!cX@-S1En>)A#_VjC zeZ#@9!$WM2A)o<9*hPS6{Rutg+n{pCuo1ivrdak6_D;Y05te83PyEmzIIu@P+aEkv zW7XCE78>7kKldfTPrB>pY?~($R+i%f&}3ev+JwNWZn1N7jQ@W^+7GR70h!uOZ0phlA_DqaHM{( zclY_0m_r~qF?!u{*^-$$&s@|bJBaX2wMk!WUtSA6X)1dDEHG5keK8&UJR66Z%{57{ z_;&8*6CJN`3ka?isgAGoSur)<+dKD_?n@v>C^^feo_z1|^CD?kF$P#?Y7{lxEjQNg z)Uc>5$8lJzk*9om$EJcyBWxk9R+2@)HI**2{rMf(Pm@IIwFbi?ga}uWBFga66?XQ~ zIu#Vj&t{A+ZNV`tK9dRlncmX+$%e| zYO)A{pVc0gy`>+?@9~ld%&Xei{(e~aOM;fHKi*roa^_r`=rdu<_}cwOp!IcqtKKRD zLwb?x>!fo9uIK3dcAW~gky4<0Y8lN2Kr{rV_nalH3#O?rj^M|D@X13gmTJk|{|fi# zB%yIBrnhb81PHvpQQ7)vn&#NrJ%x&CLJ~Nc{r@G+Z}5a@&ft%EV{q}02OblcCg3AQ z#4Dr_e{%O<2(A5m(e`P6uF>@((xeZ6Vs+Zz`^H5RZ^)9YNW*YB=e6CxLXxjkrw82T zTd91QE20}mS_gHLwh{4+n*39g7qIk$9)mA#(Lq(srhw05HuUj9vR11k^QY#t$);o< z3O7nOc$_0}Y~!kcXTNOS>YYJ5Ourm_vgTO9P9Ttq{=Xud@$^}sB98bn>qkB;1&5wY zncj3IIChvlR_yOsLfYcBZ220T_5vQvPtX9$0c(~9B0WYD5j-ZH{J$(xG`*Ta?DSKV zm5V^Q0?RAj+02*b$dA^32G3$h0Yh4ULl?P!pTrU!Dgha~Ab<+w(zMaEfzMyyn8(pM zwak7qtGLZ9`}$$P?RZ0}S+xG;vKXQ>&~S+7ya2gKfVx_dln zxL?GI=YPl~E)%*RY`uheCSePlXL-Et+&ojW}$&-CGUI72$2@gIy6~3w#_T$Hs_J4F(%2CeS z9Sc7@m%b$#(DsV4F&U%8mXh|wzisTDtO;f6cbdzH;l}sG`;3;OfuqLnjkT_(L1rT zk?e!lfKTPK{vokF3EU0O3=@!WJ0ijNWPL1)*Ul-tRt?J1_6d>fIx>8Ae9j{h+Aa46 zzL66B+ez1wc;$^P2YEj{&2Z{9wFkFI3bmQnC#ue^-ZF(GjKs#d*X<&_g9u(ICBdKS z&A$#;#hmmgYmoq|hy(VU(HfMw8fA~YZDVedn&W3=u|ro?dOOV>2UZ7Lf4riJza_4g zZHkglLqI*sTg^K$V3(H`)8n!rFXvNFpNp5p0cw)TVf+x31=`fQzqKP7`0&@};Cj!< z4zu2)%-QUvjJUQ3;UT{OGkmLAAA*z;&=r-K$RDZqFDi{BSBpqss%yk<4>#0=FL&&C z4w)HvtpEgE_!}kRIpnjkT>klBpj^(otGs1kyo>?X-NFcAsOWUNHW=x2C|f$WBV#NF zl-iMX%X#Yxo9L6Fo}CPfzhsD(^iSY?2b*t-3*GC$oOzd$%K318^#By`yP2Ew4Q9z8 zi?*K{J!MNT#4D9()bstVFZE6k)e{_>#E(C5Wkvp_7@Uem&V))B>z8)VotKaLK~9L~f`(YXIYYhC=~E z(6H;A#PteePJ`K!HiW6WP58}B*tZF%&x>-><-a-KBv(}|u~#Y;1)jRk3gmzWag|r2 zS$hFa&8dWE8;g#@X=27!4}|A1Z=Wt1wqidT<0!{-B~jBSo7P3WC$;s&=9;?Tn0F?K zB@X_oxh(J*B~uT9Gx_0F>}#9ezI$zn>F8DtUy7Uw_PnY&q801FzBT0TOE#pKX#rkI zIPsI|kAzMK3ro1<1e8lFc?CI25IFOzQz!s`zcRwK;;6_~FLC%@sK7W^zYRiN^K_I4 z{AXYg#taf)&mL^@EldBzGa}0rBQjO|+~VzAxmBj2qUq>gZ5!X%l2qC`@-h#4rcq3* z_Uk9oxPA1W4)JRps}sk9!au@+DR=APUGXJ=FzW$;r>SW)MJI=guACsWB(H=Dhls62 zNh({vmJK@mP$=0j{1~LQg=if#qvU{7JIt7th}$PiT2m5EK(H zW%6W65gavc7V_mi1gK%?r7tIXZ%r=Ql4gD`Luj{x3yFfz@^UwL={$Wr?xlo$ z4y{D(@%E3887aWy6v_cpoPuPGa%?`}Y?e??ylFmbdVHJpPmln?Ss`#ZzCIs0tXX(- zVU)m-Fbmlg>X^Dp-e;u@FE9XfUpFxiR-dDybHpYrfk_4kO8$#-|{W`95HeE8nqd9HV5zh$@kUDoyS-^CyI z|9px$J_Sa5ug$ssWh5E4pPZb`d_Vh~7P)y}{b%;E`dMef`-AQ*o`{nVS%sjvwFESg1n0sz#BWff{B>M6DC(2RAO$z0S09u)9 z)?@M{XIGAo)^pA=gMu=D(*7IEyCKrQV$;Rk1Y-@)ZiwXe)k4AFVjL?*KbtByoQ@(` zAgghsgy$thty|^`cE2E~%8Sw1(+n!q(subQ>g$KC$3~_;(t#xc%&?j9&3uF^tyJW- zP03%=2-M^N_qpM!+AeX0>y{G+8jgZBwi>Yd)Ia5b-JvPU>E7FLMg&w?7O5tBKA$ zB}>%mlq0ArIxi<}?CIrxlCddnL(4Tv&*bly=aSzT34ig;1KB1RS(-Doa9~z$f(s@ zKI&N;-dSIsR8D~FE4HR&6soi|lM^WgFrPmIEXC(R#ytZyZZ=V|(A2Ig^b-5L6sbK3 z2%SHDCTkjf#Y1^@X)&sBp{-SV+_sX>;z_!O6wma@0geZu)Q@@f7Q(JsdodD z|FBtiS;;d*rfT`2UC;PB+Xh+`9k!5cAS`05m1&5%rwG-ecE6tE&0Gf|hmT6?mu09e zEOs>|fh6*?R*q1UMslKeZxk9RIgrD?Ypp-cjAiu_HM@nt(inU&Q>QK=$(i(Xu+${H zymi7?ZsX;pMTiuN1^L=bgi<^;7nj?DS?l#pKfl#%UbJ9E0(#M?0~Rj{7FS#BFOELl zkSv+cJ=XbY6)6^5<>#`QB6=>u7c^~{#p4=l$)^oo;=pp$yOXWfm8i(;kE7U_(Syn9 zpFKyHvW>HNgTO{)TT|?%b$y$*R7i39*_T2oB|&E0tqNmM94r&6Me4n+n}MfUE=0nb ziQgZj)EO;j;v~Mk_3`SN&Wuub4aP=GZuJDZ|l670^jVW;c1cSqb zS&F9wHq?^T_o`d@#+{UZoqpdyya3Y|?|iuEPt6+m#yt^kM3fhiMj&tLnAgp~Lk}}g z&1hOX)!{MPHA}yj$f#_yHGdDzU=U1*t3gy^bx0Nlu<`3|Gtc-zm+w>-Ch?Dg_VI7T5U*-~< z+~cTT-bZr^A2i%CBF){tArLkABYm zS#*E&{q!-RIV zk#>(@b{IjFbvQ!+pUqNLneL82IFQJK&-&s@V3{U-4&Oc3R$ps z`SN72Xq0jPEIQdz*|xF6*>K^&jay7zOfHuDvQ|Oyf!Bw6$Hm-|bc=!G!+#=T> z;UK0|PL>hla(~tw=Icp%w+@^02Uv*!1iMaa2wDMTqW(@3mF8iGJ$XaX--XREI>Qs+ zddnZaT3e_ykZwK14xPTp3@dXy4j&36N`wg&OB5tm4~zN95eurs{Zu5_db4*LE%l`U zOg$H4sd&?bh`DynAUGV`qeLXu4o@Ei4W*IIdX&mtbLHiY(ROrP(J_6Wn5SaYo)~pa zl$Wy6^g8ua4dQ6jC(425YTezXOs);Dy$LmB02U@GRg~=Dt^6>s{whhN?Y z>YlJn2(DoEn;`FS(RlVQ#4{vA0Cg*nNo*x`XO$OW`$`)h?L=o_B6JP=xdg)$$VhFH zasVp_dZA8zV&L>+O?uyRkX~_bd^y0Px{$s8yR|{1}1U=gPeRw{S<%o z#pza0X7m|*%vemurs$T4uBV+@w2j%tfm>K`C~OfYXCH%@MrL@T+zI;&7W?Mc4LLcW z3;x^Qzn3Cv-ny5X3YZ_IX6TejU?I^z(>w*CoK(ZVmNvdiK2{ff13_J}k>!+OJ;nM2 zRD}tU%`PM+>1Tx!^lNwQL0tvz%AS<;cAZ`!Cuav-vZRXJUslm8nXqYwh`s;)6fvW;Ko!cQwNKt#p7DhTp zPfWaq`&?)OCuu&}-Xy>MU+8F2i`Bqwz(K`eF_7M?i}gQ>$NvRBN&q&%c>yZe|ES2U zY5u*$bSZpdWN)`SB;-xf3`~~@P{7H z;8VJzyS6UB;-AH8e22XJ2lM$0ZhalC`WNyv5uubqyohbl9+nr94T{O1c@m^)AU?eu zaFOGD3G9X=aJ>8nTKl)t9|I<$4{0Xi!ew;c{Xgr}CC+08ffHgh=kF_nJlb7WEud{3lqsU#D{iTWKTJ z!^aESSEJT?(;hVm<`t+uIQW|G0%)pJzvNp#2GXCgxP(+yrDW^UNGFzM&LkR?(qNgX zzgMvzEw*P=CSn_(MqQ3RD#+vzn)5Li=_2iQE}>bN?JIP3t;MR%(SGef>a-RAgRx7u z;icS^XgbyBZfH2=YuI;W59znaHZNT51g{z92PzC9MY|@E*&JvgthmzK^^0SW3DMrR z?Y_s7 zc3eyW8Fh413+9DYe-4IIx~U1Y^`}IP{_x{MKz`jMBjCP7J7%kkv=tqd>29_g$X(yk zHsO<|!=2Hf?&cS4aatdo(~j87BWhmjM~atQj*csP&zU1_?1d+7qCO;=ALR!!g?XZd zNaAEG}Of#A&*P75gnCQM}DJEK&mv?4|L9=U~rCQ402e zWbY3tdn8Lm`+7U78fJEDBfJ?V4{)|d?+z%(h`Lzbqak*>4z90*-CctW&gnf#Zn+14 zI(A;p97;tN*YEiQb4g22YIBP5%y->DsTxmEe2V`$+L0zrZ(0I0p>o7LILP)DM=P`s zvS{@!EZz4L%y({yi5n(e63Sb@T=R^VB!?vSu`#QQhNep7$|7SE7vh3eJ)u z8NFnoefxH9&(|94PP>-3hLN;7$nc5J(`nyEN|FxVwj7fuJF{HEzK*KyYc?-GfWQU1aYg zd!O^F?tA}U6%<7;SX0NG->`2WgsQsGh3UH{w#7C~Blo{0lqYTz)U!z}RcXMWdeFe~ z(dKD60!KvWhH%%TOlZRT$op99y(MZ3uMi;yju!R8X$Ef~e(1oYBa~aD0a6$L`*3hK9eNj2J~sZw$-lx5B7-Q0 ztYaiz0V9d{eAQk(E$3%E{}Vzz<=7S`b$vZ~;zlpY(wh%MEXgkvOB`E2#6zyjeuqQL z{ee@aAcR|#E0z*O93Gvx2x^kBeF;~W>at3GTuqQ|Q$zbBYvTtH5Anrbw`#sH1+X+O z+(d`@apbJt)PNrR|2Qe|`;`FY<(~2%{`~Z5jTnjopdr>kJcZAx)r`pi_@@TgBL znKe3$wW7-Ds*NAn;;7v_E4hMY5fGP)HFBpJrYlXdd>l7)X{bSkW`f1l%1ar0n%R8m zUI*GIZD*{bw6vm^gU9HIPiydcK`bpE@OX`TT0#YB0dXq`@66?vWe6Qu<@P;aF`K)F zXv;l&A$K~}uc9UwoMtDJFe{a`0TiD*>#L`o>|R^N8Gn?#%q+0_**yVjKr#m*$gR+? zi_F!JaO*P4nN@qq8=+yYm1mC&1vdd%GYZ_*uW^tGc2zU%zv}DuQK5^{%}nQud8>Q5 z;8xxyy`yuj71sgs9zE|CTGSX)71_(FbGWMkxBI;`S9Z3M@U|oWPmb*J^7r}OQy20@ zI}p|^fd;38+h00UiYdi?3_vWYMM``Y^c7t9Qa7Xev1#@93%An4Iv4A!k@LQvn=xd7 zFG*ilz|Ys&&+GVdl?L{Dp``_zQ^gB%avo_YkvB zGIafM^)rL7tx?k(3@%g}m{`Zx#{K6swFJ>!i|?pH-RYY(+qFO9%IVI*@Nm5UhR&+X z6u}tqLfPU2BUwxOAm8U&Y2<`?*WP9gB%WRkC2y18xoOfoWZzL4Sr zB@*zEvd@-k@WscgUiqzGxjAJYxHQ|60ay(k-GgM#m+9`*%kX@i)G{flU^f4`=Jvjj z+f-ChOa4f!^g391uGN>)-BQ54=IBLf*cZAn^|bVAH-4{QujF-pvAf@}htvU0C_Ygo&!PXL8pv(Bt2=f_bjMI z7`^xiPuM`9W$1-wgwu)QW@cF#wMbIJ=mAtE2Bz&*7mbttEJ`Zf^xnad=hvZD^u4go zP@p)Txh_CDGQmMNiX~GoYjX&_{}%m;e%uFR69{0*t7(-H;vkmaGOMtu+QiX_k&)9# zLkyyC*2~9%5MITD^22+nY-TpgTx5}W3Gvw7Qsw=y_!$)!NnjIR;k17^Mto z#Kj_{mhVa#t>IjsB8HM%uFPnys)3+CzOPt9Kzz9)$+A!KBHpRVcQJ|F@8uE1gG=Tb zmf?Oc+v~&Q)^H^x_>gna;w*G*n`6iY=7dBdaa?{MLE{wgI87Hm>N@sxe=R4g*X6On zZiL9%CqR#vH8u7)!lt57hT;Nn$-@gu>)l(4=8y3z+@`F4SsSH^9N@iU;DE^c$8KBv zVs^^+k1)J2Rl9MRQuS)vCm6W--M!SFMlpXg8S-HG>$aUpq~+AI9dat>=e-(m`;I;n z@X@%D3xSVBP9Ne{?~i>>eotEloL(3`c84SgKNfJD25kIbz@qg3HJ4B7 zg&1rC2m4PB)@*HEU427=YDgWViM;&o)0vzthrFy)xPK~j)C_zPhve&&=6GJstt*|Ow(d^9WPpQocTW9eq@J_3PK8(d$$OkvgF}pc8d4R*pU}&V z{I#coi0B$$amz?Cz1sjvBNj~8Hn6?oz6o{JCdC?|iyf6G zAthY+uhdrijbxqv&n2biPy-sXvhu5VW(1uGUAg5_%b(Jz`^kEIW_s_ZQEWL>T4NzC z?T}v0La+4=Zm=o$J1{(}rvq!H9V=^<8heEUP!D6Fq<{d8PB0JMa zU#Pmy+0=T9N=7gq;)_RUQu4}uhbU1g&eO%g1mwSN_LJG3Ql#DCcnR)0=}iP+Wjx!9 zN*W+kln8C^o6=yzl2x*6_%?H1FeRJdIKq)F2sXvf0Cxxbn)&;k^oC~|^?K!7d>IK% zS^t@(EvCYHc!6%qK&V57RUo;wiB2v($U1$$fmf8_UaK$+1X(3=Rla29s6rHIO;Nvz zB#&dUV+DW9K)z;^|Dn>xRWq#{`|d4c$uH*5$dY_FQY6f5sMXaCXo)Yo=|yLN87v!? zC$;^pN|cAh$7^MEaJ-Xm+UQl>LS0h7S+F*xj6{@c|OPAB*lENGa zF?3bbXgc#RjZY3u8%lP6L6`I`gl8bX^GD97nfjp)-f~Hlr}6Uvb(8Myp;9iUR>lI6|K_c6IIOi+eW%rf2%XkmR*&HiFO|;lNaY(h? zOZ7oc6w2qkWulVY^EU6}!;Kwt{Tjm;Fokj2Ou9|8KIq?cN|p*_3?APUT53RHn1}zsWjZ z{z@Q;fC_XB>HSD?bc%E~53lc8M3c3nB?Vy^<9VYd2`z?1gGjfPe2JxWBv+#-T2EK! ztd3wegnDfXONd%psZ$mC=(Ev5#N-+!M)srOv54y#P6u4OB z4R|tSIf@q&n~yPQ3q*19-ju4IEZ$_8boT(vWbHO=UNcQCr$pOBjAL~?_xpwS4pZ_8 zM-R;*%QySKsj!b9#sHw);peh?5#Y1h(cJ1&ocZn*-lo$LwA!QNl+XVmJK^^UgXq=% zbAD!rvVZ^n#6bJ^rzrRYG3T`(AwXchsQ2F9QeyKR?ZD2CA}je9F;S1l-t(}&JACwu z0S=n}Zv2?HqAH>I=<;u~#Bd4CV*5Hs<#odFr#D`Iy&m;6UGMGQ=-$99sDaC5pl)Mj zSEDSd3ZvVOc~{50mz!I?>u4`MRV?R~XOEBBps`Lan&_yfuj`DcJY1ts?NIQ3K!p@L zfGix*(g9bIHI?3Tf!rj|;ybA+D@j)vU8x++$1)*I=X`Y(RRSOY6$uDHRi*WKwSB*O5l?ZT{QQ&-&Asw=Ui_162uWw;e(|icKQUPCm zb|0aDHKk&E+vsqwx5%Ca*XWebe82zfhN_=}Fp^ttrpBpy`Uc&q6KJBtt5;BF83||(nMZOC5X&{g?K17Ay_}K=&)0Fi zbatxfq{&=6W7?)E8<1nKWCgyeKM#h<(;X}PFd5FPYpUxNg|}^K&5V-qazu!dYi_Ag zRoxyQo@rInIxm|^MRSQWz%#Kdo_WasPCrXM=#LLp(5rI}h+ z@0$HeATn7zvW=igZ}>h%(puM5?Va!VxAGLb&>BQt)5Mn-Cesw-zmdhR-|M7VeaJ?^9{JSw<~R?CvL5r`l%*|?)h*VxQV7-}XR zP?YJ$pVTikb!0;`JV8&4Qra4FQR&QU{pg;SpfZ>BPk+oy1L=RdO1{T>V_v07^=s6# zs=Jye=#n)|tF;C@I2&m4Cd+8e=>FdXq|W{R!;ty!?jr1e~_5@v(S>* z*Z&RgUV73v=J|IoEwFOq@vJ@gG`XgYQ4{5Dus2UjkwX%HV`o9iyy_SnHcTN4J(0?K z6XXOS+~AcQs|25v+(s@=Qq}%8h2|JCFWs`YB%~kz8ANN}3@T^Qnf7ikb#{^|ZUmpd zLvBV<;6ajk|KWWKA+)dLzsErTr>DAq?M=7$=0e=-tpTCv-ALFSBZ6cdJRvKZ9nXcj>Mu2rB#kI%6Ljuxm#Pp!zy8d)hJW(kf{(G zWFmEs+_#%6V#6J5j~$3eesb9iz=2=}0DK%jny3116RPqvK|S(evRYW=2BJ;~CU>0^GYnX46#O;6w${xf@3+?Jbe7_c zS-bN<(uRVbZreYkVusXJzA{q@%NukGp9Wo&W7zhY)H~e{J_-+WH#%)G4(xQ3vw&kaW8f{F<25Lpvn$5fyDiMA z)>d&75Xf%UbF{VnvZ^wUnJP7VWR%B(&|fmn z!wk#IKhwM^$KEDHzRpUCwY7g^rqIq-S;~W`V3T@r z$5-mrX^SwybHhPeq21mpWpni>a1@~26d7+jjmVI+3S~VY`MCx??896#sk1Q!5cE1L zZ~4+jhpLdbrc6>D(fk<2aNAw80Zl_khH)4NqYOK^VnG){em3G3B^<2_rE4~?9=YOI zwyefH6EvFJ#-6~9b0PmZ^GRI`{$Gjhq?VOhP;J!RJCpx2?XWK#{V&nvr4^@jy1VpmrefwpM{FstCouu1O=DEPYTrr>)hP68TEMqE@;MvJ;bYuh z+yItnZ{SkHOs#}U3W-QT1!J3$s{Q^yc<{{RrcY|0_S&&%)X-DnKrBFh=3@M3AAYyS zFa^Kgy5e&#(3zzw&PxhPUJG zIbOMDU;f-Eojzbwt=^o9Hk}%El>Nuiy)~F<6fm~jasGu0uzmRN0`XP*f7zt{PtbFo zHbSt4Z_h#!d{ISzLDQ&~pKd`3Vt3F@C11eZ7I60i9*8!$?F|Zf=y>eKSEBU&wf53; zZQR6cC?q05*lP_(+V3$6zAvxzth1{pnRqxxjg}Vco*Zz|iL>Rr!Wx}6O+!Yb3izan zj7>@NPK#2|cMBD6!|9Aua+s6m-4=XAyw$g93DZUbvq$d(nJ5MuvOIfJClMxhtOy!% zVc)ZH+#!G)FpRegIhBB=Dv?6KZOclf>@~V%6l*#YodR_>cg7S>L{GgycOGq))cCQ> z?O-)y0(n;1^(0}QIdL2|!2dlVp*l$+?DE2AAD2>qS8K>7FB&gkdZ84hjUH;dwei14 zMQ_T?|4g27&>;LduxJ=Q;9q?;Bn3Qt~U=qfhu$L38-&LDR#Y=mf(N4_6SlU zUwqmkfBY4+nIOV-15LU}$fNxHG>H$yh9J-#I1kCTmkT0OtpsdM45-A!KBZAIbo5-+h|-5WVP z2gP>uvkzA1JDu!JcpVkrl8dh}%B_QtSSgZR zB9v0-h@riFQQyTzA~h`z!xDsg4j262G6n?JWaiBI-xhw0V*X|_mh@?RCOF!ae@|-P zvpe#?sP&o6+qAey0f}5NsGE6L62g-6A4J1KA1w4sJvC^cup zqpo2qg$bJvt3g*&Rw|`OW^=ffoQSLZMl~E>vUO^q7gx88f>~ebjqco%~^RImUe`_8T1HrFaFNqy0hAeC}=&k-gx5jnzG(mjnh*;`EYa`*#S$eN* zY8SGWn^50xT^5`lUiqG>?IKDjGu5QrgDDKKvj77%bGJi`D|u@vYz>tO#Ol1=th`35im~xF1&yH0VU*q zrjz<#o;1*($OdI;UtCN-%x&D)UfJCDA*yK9aH5y&P`il{m_ZH(thA+unq3+tRq_iYjw zRYJwOK?FuNXM25~X03Y*T5fqPN4Wej1MuY8Qtr^$)n-nn&ZA5wHKdVccVh{C60IKu zu2(Gu`nm^%e84n07`r8m0X>g>?s;$Q*H(Y}|LkV3gG}11^bA+-;}-%9<2#w1$(i_^ z1E3*fH>TW}*Gjp=MD|1m$oKU;Yow)$;vxsPw^yH^$%&uM!WFAPOnZLR-p9-Vu77%Y}I zYXJ`}=y`3p^3Q(F8^{Aq{L3GbQHpXMQsw~p(nWd`?A|6990@S?E?|D##KGAKdFhkqUH z5#}vt>Hiq*ez~a@#=q^~YQD9e;*)b7n#9js&-?VVis#)?WkGGU0oUNa_Oy2;5Ig_> z7ag7HnaG#zxUR2qAJPc_+virChnv&YrKO`}kszY>v#^Kjc*wTZojT@3yQ`NpfP~|xhV<^4vzc^z+0(ScNuTr3enjriu61$Zi zHe&Q@VMA#3ZZroYu)3`Bwyfj6%+Ys~%wQQM;My`^R>R2A_t@6R6|?GRoil?tLC*qY*Ds%DY|nT0KNlSL_-%N#?ve5GyQLF?Hbp!?-AXMZ$vpy{d{KsM01|B zB?A=9o{HH5Me-XqKv=ME!~3KDOf|cVMaK>b5)-@b_f9CsEyu+3^!*q(;QfD0{W5#| zuav6qdv7^RiGDji9e21Fp86A!po49Mroh#-|0d^6rJw6Vr_^XaD{(izxXl;4&#$k4 zlhZ=&`}@%7X|}O_W=6y6R8shA+UWO;k-Kvha`w~XZfzh;-fIJeCRX5_TSi)ig+a-( z)-rke^Bd#Ote&Gg&9U0Ho2{FR&CR6wvR){Z!rBHI@t%`f2;~KY7yD1 z#aCdhQR^ma@1pRR;JI15S_NJ3>3@s^DzJJM&gVAN*Qsb zbpNuqz7G&m0fg+E@4N2arbuV=WB%8G;A}PBb|M4ijqqBLdt6Bu&*OlN)D?m()E3+t zoZx?%4|Vom3qlsOrE$&=rVYNJyaiskkPgP?Z&^K$_i$o$mG&s?)qp9IBTSb!D>A}A zQ;B!w{|&b_ngJCtj1hPP!g52wJ|q3&ZaA!0g;L6{GO* z4q?&=JqSMG@%@T-JKDFJhy3Ru;OW$IG&Ap@>gm2pNDW>OG5lv0Nw(JxiRRdg8n z{l#ugq-Gy{#hVo$4qB=Qfw+WneQ6={hD6jN+d#0E*HQHVbWsKN;m29mysX&$MDbS> zONAp!JG%AWk{M(@_3D&)mX_$=k&t6Dr5u4VZ0vQy6ATaljoEsA1rpo~QBjl-*jjJ) z83s7;O}5B~7yXBJf{!L6V&^clvYkw`8vP&PM0=gDk&Y&*@fBNf?Y6;hi8KCf=|xpD}xglPblr#8V74OXWQObt?+V!EzbmST7L27=(SiBb-QX?0^i~cEc&U1>qZ>i@35XkAJlCWa zo&rF+`W#Gk*)1d%8{~@z>gbDK@F(9U4KhFS_upRA&Of~U@TEx( zIwWws))msG5U~B(Eqn>|yitcxpB8eA!^q;@Enr|^-G@R5JdnmF?&VEEg7cje)*ED9QD?ouEVg{@Yq~;fj_m3{kmdzF96+)3; z9NW{Cx_o_4R#aNxZWWvnjwDYRQ*Y$D_vtviP|NBJg8~;c^xtqAjf;pbYMfQ%Hlu~E zNG;3{RJ1-_(f12n-+^Df0j!4Ux@M!+f?)1-w;o`^k9IR1T8|r8-oJ63HQpTE3F<8_ zGy~Q_=$~`lT`AA+rMAL^*#PymTwj%p_e1Jxd!sS;M~y}3jQ5vJx>L)7l?Q>SgvhwB z7ik*2SbhIW%~g*H*_qms!_x<$2k4N@cha0WmHHOCOjoWj9JFd)WN`Y_LWteTK9q-$B zmbEV!jVC*EU&I}^V3SBWeAm$%`O$NdPE&P^Ku6l$`$%KFQ97dnUhGZ3uNQ@W|1t?B z8EJE*`+La#c)pgG0TsiI&T~L$rHdg{(YkZur)TAGPI=7@P%r^$;)J<}=bMka@95I~ zIs|jeHO@Aq!mhXMJj#2L#3i9?yUhZd)|=QthmVfWGs~arKj+G{J@c~PkR~i3)ub7D z^xX)Y+YpL2yREDKkII_k@Y>ii=PpwA>B~)`wT{gml%pS*d?8LON*y+9|1x310yo!G z@k>l|{9pE5L-f%=Ls_ET+M6%zwyl;W&Txr=dY46K&zGjpx-GeH+kU*z$v6ot0Z2;( zOY2XT&j=BqB3PjQMKMY1dJ^Y$vyP5EPz|NP(b_+iG@9y7h@fnB=4{)!6ui zS|l$sE{c#ntr)F@bA-#hv^V-Nah;H@jS%a93Tx6V)wWd?yMSPs0n`69NSom1p4Ks4 zJ&4kx5?)R8y)W6|Eu`l`XBs{);u?Pr^mA^YHs?k(!v(TNjumRZNMq}0f?&Q3cdWuB zj8t9g=<~6m%0_`|QG2}ib0C40YaNelpB0=te9u z;$tu2NE|ymH|=d~x4u)Oq$9Fby|`g;>P@uGDVpCsN-h=GY{h3$ZifCPa7Fcoo-Dub zT?&5GAo1oRC^M@f)HTm;5vvu(2)NFBU?HYGTZeS(%05o-+H|O=h_1ogddaDqU>_t4 z0+#WUbyz}JHz3{I57p-=*}^zW6!!QY2h#S4Ixx#_?4xXDXOfWQoq$d-cWpGK}1 zgJMnu!X|-J?R#;V_g;(3q?I40r6E-TUrU<}CDbLfnzcvs7DIL=TgvIg{!$)kVkNlQ zLp5Zbp4b#9-%d5OLT}{=lDmvC31xHeRwhe%W0w|u5^g&~)_*Bt5@Vcs9RD+Lzfa%jNvMY$-%z?NiyrmxU3^+HQLODTF%ocY616^?gMK z0XU$;tHnix^_{o1y*8DI$tL8jci}y`9E;cDi%@WQbfxQ@B3Q0gIv&y( zNE5t=|64|H2IhJN9Q9ib@c+9tmCKv7Qe5q`bzf3rH6b(1^f;+XK|j_^aad}tB0Z81 zM2stTz}>zlbi0o?^-6n{xuN#>q8A>gL&Fgb#r?RWEa(qWLoMI0{maM0Z3l4QAzBuTumrg?XJDN?{gLMKh2PkLq&<%kHfGY-5c zy;KM)F(RfJfl(c7a7lQQLGm)i6ov?|rB>RNq7%r#ax+e}+`*9OeKLrF$Pm*_?w?mo zo`3fAnxj5gADgqex2|Uj6-a$0=zk|9uu55Y#N4Ut@y-{zT?avb8FD)~w~#0zz95p` zgN!Z&@!`%cKK~HPPkfcZ>LOeezzkr~o z9;|?atrwEtU>k|397BN|%x}~UrX*<5AZrJsTOvf+sLed%=Q}7}QmQ$+yM{>Fq(;7$@XM()uye#9BA-j@6*NR0b)K8X}ZtVziDE z$+j{Y+}?74yF>#`r!YyUw|SWEp%gM-%Hs(=1Zi8Cjeub>gO%*OXZRTpKCG~JHp2(2>Ds0w1cptRLInqqj^mb6dWl7k zb?xa;z=61oKAdo@Z9lmvs@<|y$c-?1B)pFTq1!gMTz;7Os98)xe#1pm!^`*$!O*0* z_j3qlTQDhIvL2mn6tJ`fxG>C4V$KXv8l>zG<`f+ca$27zq3p)Wz``yc~qFWL3vZt26);Nh5Fe z_6GgQQpNq<@_L+{M1Ikom71E`qzALvl{9QJNZBE*^5j{NaX3{;$=AXScELn=_il1w zhdtD&c(uk`23IJR6%X+BO+irYK;2ftYUv(7>dqSF?V}fUvU(cp{QJ`cxom3j^y)#! z256gWHjVtj^=qFbKIda{wS4OI3Yz8DhrYCvoZr`5nQ4q*%2{J4^8bYR7o5@? z+ELR~L@BMsZj>)lUji@MAIHK>eSiA%kp4o0ADxPJ%&sBooOAGfzNyRz;s@_iv9`PI z4Y}7iv6FWAwgyB`(VXaCqGQ-wrwM}b_sX|3wGA880d4R@g$IJ6Y%lJp*Z0@(b0R|f12X;Tw);{5SJJ}>AX1rL9QU<)iTL7GEo}(b-8r68;C~rRiZ;4 zf*>Nnu~RLuths73#Lwc)MIz&d*1+9B`IyTuT!UbMUu#d6fFk6_V}XS4fHKaIo zp?SfJi+70swe%unPo@Wa<#h4d%Z{6Mw9exb*B_^=g%povz)G=GTHUK0CSv18u|N-9 ztUNAIlgZU^q;mb;vu7sJ+KrVERTuNYh*TrUA-D0(F->^sf?`gX{oHJ#lEkjodf=iv z3@Hg)kF5}C<#$GjFA!cw4+72-wxo&*^v}AjsN#++#3Z01Z1IFxk~(L7=x17qkBilq z*l3(bR;s5xx5Yg(i$hRvD<8MKg}~0wtZ!=abdlA^nSQd*>1_r6iCx+aqzPX>TsZIj zO5)pOil&D_GenIPL7B?5=!YVB@W$CsTu6wo4V}1?J9BUxCHxCEL7l819CJT^R=>@M zReaOVq;YnO53lZzyR6!-sKB}#Sl~}k*YK|8;EhiM9OIK%AeOQqF_*;$;D)Z&Y%4&~ z|8>%RYkVJ1>Tpc=W4pkk;jJZUy**n?{W+{NC--MXDmHn?qDjn4&8o)1d$%FR*V97d zD2t>6;9X@vbP?s2EZTV;6Xaxs$ay2*!c0$o+YM}^fXILAb5(TY z1aGAtC{)<9nATnkVk)C+M}RFM=;P0`Q;s=GtPYC_B3d@Z;UsS$w#|go%BM&m z%Z*K`=3P>vPz{(n2|LQ*N*^lOWTBDO?X8Qpdr1<8ncT0X) zr-1WYrquydE6P#gSUAAfkdD}VxAP^!!!e2G(m1rKF?;gr)g?{c8d73){e1oVb4^&V6SbPlJBb4lRF}#t)x<_r62w+lMe(S3Su7(C#k2S;7;~!nO z_C>|HYW)SwKI3BaG~TtgU62wNEw|z}H3{Pw2?XZ7WLyY_mOt7;0e*bma#kq(UUIaF zQIC}=KZiQ!Z#SDV`4d#P=-n4}5ybXg$y0ED+!hw^Nr5|-=g&IS+tOV^>S1}~99>&V zc+rGET)wg&r|!T$G0!}POp%Wh?8k0vmnJ+E4oS26>ivVly_`&lQfB-Fbx<1+*I5Kl z76PABClKngcNyOjVXhi;?CeP$D{HFuN*+A1A^&HT!?ABieBm#>W0)H7yjX@E5|Tz; z0vDW+k_g9>ye`eP$A$b2cCF%t$qms9IT3q88Zp^|?{%Hz>{l*>kCgwFztczUU!nO+GW^9B^v2oR32)S8S-cdLc z9dfybN)s3s&cpETQG2z#>#qf#{Ik=7H{8Ct+=66lsBPU z;jHM;(NmSoqsMvR2xWj5<3qxD_ri69i>faJ-o>Q-=i0oN*XtEU*NV-=piP7$k3)Hi z($72;vB3THxvuPXI(NAdzNbfG_{>YfQ3=VnaJ!a;Fk|XXJxpVzx7&w$!dyLo9+Es< z*68%&X?B3n38Rf)3I|pxp8kFt1a{;E_O1+ZyjS@b{I2FH7IF;?Vy{UxJR;3`2hj3cWh9exGNs z`WfC_j*{2wqmnzdx`}U|IUQp12jaR7ZL!6-8IS-06U%#{?g5cgf4&td9`*EE>T>g+`1RXW?VG2 zO#hRJR=Hsvio8Kw68(7)G`7`NIRK7E1hC@V5-**#3wtV&7Yh+qYraQjg#0noG^JOQ z=7yfYD$Va+2TK`U(A=d1#>Z1}!KUpcm(I*ORx>8?_eN#X2+L1kTwP;?q0z4%-{FtB z(2>TLbb6rp+8?lYwKY6az(mJviJR6O8mx*(7;Pn23#E!;dK)kcx1EXu?EXFku4f}$ zNaLn465@`~pz3}mr#Gg*yT)nA7ojGO6#l-8I&OI$FNRw=*IzyI_+9+u!+!GQ5huWE zx)OCeMfuFJN15}Jm!AQG!nf=;byj@`D3ixh!~1*REn(U*rY&s2%ZCcNe24)d{U7k? z7RzohNSbi_MheAf(d7mgai`tA!jS%EHRh&8QhZ2KTv|IL0?{U>$?b1j1xYFx%-MH!kYUA?Psrw

    2SZweVX3o8$X2Sec6?LthA8=0>#W<(&wm=O~)V-q+tRl^m(QX+QYD`S?Hf4bRf$mZ*1&o7@d6Or=erJi4XQ$oR4Ei~Rw9&{SLn z;kOLDOv$7avV;A7!zCHwHDZ#_B=vm@n_78?l*m9N>VEPN@QX*rOf2WIh}d`_E^aRr zw_}9V6a&R(AjZT85X2TDq}lCe-6q3FdN}zj)!-1uMZGzjb8q3szsfmfl#4^B)v)$SXA($K3K^{QM#qu)z$u(tc_X*tWEqB10SlRQ-|D z%QCJwTW){eArQ`cN4$I>QaWC%AJ{;s$VV?xbSx0GJeH%#fJg>I@vu<<0?ryHxgVCU zobMBaP1}h>fiW0T`4>$!JhF>=#?rV_ki4h)SN)zY`TtZ^0edXCz_f9y3l8c_w6#t7 z1Haf%3~@mLwMjs-9mGK!)-<5~+(18RWN6PyXl`aC#)vtmAG)qZ<7WPu1ce(aE&mii z99ybTk7OXmWh>6X#+F8ss%;?)fechKsL+7?_%0#S-h5~*oC%3oTN_F|52VTssY&1+ zsc(tFW2I0IRP*A2V8=oWfZeztiwGVl-ozdX%A`AnE%Ol*|Coye4~u{}22q$_mERl0 zmOw27{Q($gBnRhL>mUGXirCU0*%f;+-F?jfL~ohz$NX1D4P_(+Y7m`C#SBKyzGuBF zt5hE~&`MHjFJf7l(?|eRxBaGM_%IZz@J1d2kpY9HF#sq@7*8<3uL~dyQIx*d=f;3Q zLBr$=si!X6zuM+%ECXQ7foxLXNd6>p$2oEqHy3XYz2~&4TcJ-oVG+DgL~sNa9Q*+#rnILZ2UUkGBugJ>s1N)D{#W2WOcwJmhwI<pv8BdRcVBohu7Km%X~1#$ zUfp`eYQ$#v-AdXdKR%E~~KoaCTk4_#H+C=KDdtpf}Y!yr&_tpPqaSO{tW?WhlNh zm8Wu2SJbFH)-tWBCU;RFG22Ou(#Id0$m-Mj=wduz^%AAmXCnz=L#ibLflr~ed%=O# z`J=N9j10df_0KFGF_D}#$5>X}qaYrv0 z&xjh(PLYr`{<2I_$E*67P%ub-&Z0YEg_|_i>1Tf9krSetVB2?=4XM0l@k4z?4 z<811vTr-WxDd1w1{y^@$Y16J2Q;2k){NqLqf$uJUj4ym4yP2?~vq3z36V6Lf>sn-Wr0Uxsr5zNke)a#%x-0qmL`cl4EzCX9JJuh;n?}Dey7W)!pHR7W4UjST zTeI;E`Lp0Vn5!C~nbD!W92u{{oA8zfGabbZYVIT@j5-`u9Zzd0vY!7-h`BR@QgrCIz=1YLpp0TuqJ~=mZyGB+ zQeVi`>2Mf{cA|+N^I+o5uC#{k5|@dgm40=_yCjiAd-{1MUYO#+R|cxViR3Q|IGz6^ zL4P0s>PiA+nFG;p0i(MPrXwh33=owYr@eG?E+0SY;PXu}_tZscHbfpcIR{K%Cj!tvo)?&E!$mpNK_*!Afm%jaVgy>Qj#?iam#UlAoK2L)>6-lgg-+?VG z2EO|I(chGI#(Vq1`+A8dF2MNXTm29uySDn>J4vL zyF;5ZGoL$oyT8~HpiKAmbWmua9=6#e9{1qT`}%jd`0LvMymI&uu);(d=7@uZc}C5+ zeA{I$EiDyo*NrpFB*lLAXy%C0<%*2f*_Vfjos|irsPFI2_>*AEf1v6qSO1ghC{XY` zE#kg?RM{h6N#kh4+o6V@=9R=kD!(-|jgo9xT5osOw-}$$>iQpjPWHmP0zovz1?ChGOQ=Ch~)xhW+`0x;^0NeLv!qf-6M@lazODMFcA(NE^T*2By@Y2!*cMGV*$!#m$tgug_)YM9&g(W`x$ zE;x5A2y8iPNvSU>`P(H>uw&o)l1J(DH_qLlBsDdw$CYE!YgsFkN9T@a4p^`CY)nc9 zTJG3hxBsiRt}^RBruW=GTc%bIBN_d5_kMqW|9lGkHTZda->$%L2s+g_JNC~3bF(nz zRjVSeu{{ESQNv}R2y!mZk04}gc_L_lP0j6zwRoWn9kTb1TCVcSsu=w3Xz~}@d~FKu(i*iq-WbiZkJ%6tDL>llku6@VYHohj5pb6%WI6WB8P>W<-s<Wlr%xK3={o)>6z z#j$zq&B$mf({$&n0*gPaM;%>G1F6tod#KlXE?6@$(ERC!n}ax*t=7TuVXXU@q9lXt z+i9I9dhYaX(lca)F>`hDCf832ZLSP)A9Jb9E#Qb5jXwhq zn?DfD7@S?i?nlHkrcXrFjui@(XOmaF-K#Jq07ywYF+zaB2rWGu1Y|{?Mhe0hj2nTK ztd^<VT4ul+emZMqfBstMno;`aI>2^D~*6K0M>1-^%^Cmsa2kI zBUN$V{A|b~4cnRH>2|Y~_e}Y^fFKqWitRU^mcYB;%~4qYs{HNS98$F8goEWwZ6clu zl@84Q_Y%5*Lil?SDj;|LympyklP$Ten%%>|R+5BmZR0>NQ}QbuPE4V668cNHt~^yM ze$`}M-FE6#HaK^HO(Xnhr{`qC-!<=(Q0>8juYXpvz4EjuhofwP=g#MwUw3DZroR=` zc9|XF_$$zUK+g>O9$Q+l>isB2+JCYp*CZ@$QZ#HVw0RACHc5)lhR>?zhbDG1(PKC2 z4t}wmVQz>HIAc#B`E|VCw(ulH@3JJQ`k=) zMNme&ev23?Cj>yK>7eOBsW4=j2Cva( zl{dlR(@~ju6>S<7r3MndZjm!1OpYiT5Cg!$8fMfRic5?|MVfs=fq+BEV$~?%2r{(< zst7LOvb}AO}`Y5XLRV6zJT+23Wu2E@YJ^_A@dfbqZ_uV+6yHKxv2qE&&L9 z2Z{I;-xXARF#530MuHd|1zpLZyjk@%jO@2mX)nvkEqae%!O7O!chX8m30uyf&A7+r z|0z7%*=EYT29_`bl?OxBYU;z&aBW=;Hor1J}IUDdjJb`QF7OI|wqEi0R; zv+q^WcB0}_REZk{h5b3<{ox6A?i0eY%#f~_iRG5ZqAa2;GiB4<$qxXb0GINpw-{wE z$LZI40{iZPO_oEK+mg*chQ8QyJZJD)nyK@-yppsL7CvOUnUh^zfnsBY%CpO9fY{kj z=qeUItQy`dN7g*Mag(iFI!h+-XK?C%zKn}I79Sf3?Z)st0ZU;6;2I#vyRRi8*f~HG za12%vO>)6qQ$NyBRqQwf!6-mKz$GA-Nt`+biba7te_q3FaF)U?;vABe<-JiJA~QM5 zvpfHw?Brw>waVjHeB-G3%)OMAWylX9a@Sv_7X!L|e-{8o|75~af(Ca5LOX!i5Sbui zyij?0G#lr}U_lAbU_1Sx!St^%*lTSrX#mg&7l{Nj!I6d4U$cCSkJ=?hUIH(u}p^!QsMEvYAOCkMR3&Zz6TJ11jn)s^8n1th~$Srj8JS;I|zoy z>R*Zz!=_}aL>gBZpGYm}oLuGoVG!p&5?R{1#Vz5pDrc_~bE9(V3t93w|Lps^{<+rU z%kG8Q7oPJM&^SAmEZ?)Xo272E8uj0_kyms#S?~9+XQ%gnO&ZR6o#9UgRrs!OH(v|| z2`)%=t!8E|oXNN7)}E&sw$vQb3fMD4gujneuXYUkF8QY*0vKxp2|hmpjT#GWtl(qx#$7-JX>pTN0+Nd z>fwv06U`n2l(-<=CvF{c3%|Z{dUjmX$`NWSG2z_NB!wX(b4pm#*^(1LPSC@Q1{Lug zYF3__U5G&guSouaF#2Nn&JzTmvAZ#+fI9r$$O5j|da< zhlD%Qx?nFt`JZ}`_bHR&#X;W)oo$3&BMQ>eqgv}XP2t1a#A@A2>Z5Z^p3|h{kct3y zKP!3bJ@)qa>^r#9)i(6X;4spBj7UmAsE|ye-X06vt~kn;i&%+g5A4Su3w}}Piwq6m zIi_ZyuU;>Gd@3R~|EpdXUM6yO$Uc~~`Y;^B%7!%?AA$1fg%Bs|1WkN2hO2{PL%XPq z#uSst--ANiF$|`-^1y&Vuyi*7Bm=-wOD;rTrA<%$IsogwHruT+^xde?;;TJ&t8R8B z-aGSKOq@#-v=vdkYHMn9n5*`@3k0m-s!r=qa^Wit`&2x&II0zX{p+0D_u@+(t#uNY zm=*(Iv|zhF*LJt3_V<>*_6)!!S>UGsOJar71F^%SR?VAwl$WFOLqzptk?*GAeDBLv z^S$sF&MQ;3hQEbUJmx8^%bVVpFOhQFm^zbyv+=};QkngeWrEUYH{U3$o7eGw!@{xe)^=(M!~}CbqkB8w+83^h80bldG6(g;weKO?{R1y`U6~Po4PQ3RY)fY(+2E8Gd&x9UqAHEF5_M;$(H0%Y9qf+t)q2 z;JV1$YHyf+?gvMznr74Gp*44#O|T*Fa_YwX`R{%E{cxg)h$&V1ey=x2=N>m4wNL)}Fx^$%t zWuk>YTscU=W|Cbex6G=_OYY(Xf7tBZ7tEAsHZ$xs6j|c9YP$J-6cE~bDAb|m{`PHV za;sUd=#1{#ZzTJ~SeJJ=05=dpfB>FhZxqw7Y z4%O4#T55gUx9#|jSCf1;8n-JlpO;X}lyT4bw(Ict4t+{-o$r`0A5UxZ?ebo3q^dfM zEY$a=lW;0*r=%rOPpWv~^sRY%>&N)Q^+e3jVkd3q>RY>H=hZp-7ezSIESWchx2G<< zV{gX2avXL~1m_)3j=?xG)C5ygUQqv*5u>Ayz)(Q&v(}%zo0d`T9kklt-~hkcj0(D~ zDY}whOBwgE-&_fbRW3&Q?7kW3NRZ7s|31k3mdtkMjAmLjt4+YS^9zo2j_L=yi&>6| z1#ye>V&9v^w=)m;;5|b(px2HkvhCexNiWCG^;P1|B}CGI8T`>7uUmskL!A75)3xh0Q(8l&|$ z4!@08uy6P*O153yzGkzMvQN8(o^IXiu2|4u!#TBo<+Qvu$N6ReOX!Bou*viG@6@+T zf~%DwL$MDzc-amIzg`_%xI@DwZ!DgE3=(y;x=Gx9Cec*&5&%$Y`(?^8p;y_=O7!*k z*w=>2h2T`)#{O-5{4sgic}PN)qLnk~bMWmso8|+=d&x%o9(B=exYk}dT7>5rV+5yYzxN4?jy&&;8A;=iBBti+aEn>ss!{Qyk&Qkj+e&MgBX z8~d9tAYUABlNGYmULd^H&t&?Q*WuOG>2eP>^@)5l95X{F`7$mEhZ*(OU;cLt;hFu< zpZJ=%WmRb>HR3)VxD-Y-xR^kdu;=!JQy5O-;; zXs(@|t2UeDXrlAnm9GQwv9?|;X6@PUyx)IzPTnFIeup8CvOxnYIgv{Q-d!I6?ocA$ z$j1c)lagCmPuF>llZi$Xg0-)rB#ypXbJO{3A{P*HrkdyN(R(+W&J}`gC!goI=p=tF z?X3$6xSez-VCF{}uC9~Z_w8x%dIL8;UoS`Ri;%(ZGItVX^P`6>gze(}aI| z3E%+-#&ai-V?^tW7I(FksiO9-e|HcL+xQ-I9cZb}!bsmQ{N8xrZad@aC6v_Lo7Z{5 z@=UyHxA%u-FK&(9)%B4#_2s1$)&}Ll@)h0GhcgXB3qG-tM)#iI(X{BD+y8C(Q`1kk zZcg4b<-K-+m8`9=h-!Y`HR1~0^|3n3kr5X!m8b5VQK@qaQmK_SCI{e=fFLph4x&|+ zo;NZ`fXtx1&8xNb2fu#ww4IMWt4pUMV7d2FB~$ETr$d56`KGU|CwfP6+u(tJL7&%8L`0Q#XFXH$BUa z4SGbG1jL{7B}DXmkNa>=1)_=4%9V73Ox`eL1kvzX#QQ(ZSdoqK%sFkb-LUdK$&Qe3iy17q#=f#@fZj6xYR89hKD+ zy*0XUN)F^`C1 zG7@lRNm3e54!=Kf&6 z<(KbGhhebEO^z{KuIRbD)hV@@x*6uv}n1rJF;G%cC`{2@h|9=7CKp(%;?N{c{`m3-1`IA5R z?vu}K-;w{}>+V7d7F3TMdhXc{Is2BIzWV8_v-*N!&sRSGuf1x??yBm`%XF0!0}dPn z1qG_e4dPNVP!n=k7gdYa-@an@qQarm8()9+rJsovuiUn}cFimw#bcPp#=HMs93HnRIf^Wqh?AP^Y<8}mO)^=5lX*yjBY(NO)tt%q9=d$b(xSXFZ6 z%oWQPXNNks9os*8+ci#zH8gi9j)L`TrWS-=``-OKMy|Ya&Mm9v@lJW{@oyb$TU0`d z)Q1u4`MRh7ZdTp!%Mbi)>#sH)IQF;KU;dR(51w{Z%8Er_{+o;Sr()8rC<^C1?RNY& z@mI{9cVn(PXMl;*&;ReM{U=Wx?4DlJv1`9R?S|{Gyywc91p$qSxC8(gj&!vg+I;q@ z?cPuR=FX)xvkJz^icE7WL0=F+MRD%P=PRFMT?oxnFMM~?(8;#8J8u5i|NMEw&Yy^D zKe_haTd&9-7V%e}d|>DB!YgLqymFz|14kbD){)LxIlcWycfIm@)0=T z+5Yq|nHvClfYfXP=)J zg(G~!qfK3%)$v)SvC+}j4>m8mY5vTbVq3xW<`{<2+1dHhOE1Oa@g+-^EL^y7WMpLL z&YeWGa^=e0+>5ssB|6WXXp&fkcNT=5sL zCss{AE5Q-#-`V!(_sqzt;w@)}&mK7Q{E53a{2-b5`lWZxxwI?W*jxex2n39P0iqga zBHtmkygXpe(UHv?e)8WB{_nP<5XtedvQG^T@>~xKxMjT_3HT~{%6c zQ?I>TB%+RaONxCR(+8k0TofI8F;H>^ugRUWsDkN3g@5~zHP1Glm4-+}$xMLeMj{3z zr4&LkjsP5_0#YH=O$H1Y3dN;qL@~G1ljmNkPFXhZLzj;_20gRq-#v5INI_11RfW^t zH|MH_%fEhnsChs%mId)>!_cAa5A1ySfxqJ}Cv$t^w_Fp7G$s-?4o5PWVd|ZL>5qv* zmyHd8 z+4$KneYRMJz!(=dUwPNs zl03{V&7F0{ol9~8KsnQ@tB=ipqqVI~F)J?J6UM~4oSdBe>`6qLOMr-|^T3Ix{%_si zJr6)cRV(h8f2Hc8iptvk-+9_FnZNi;YjZeH2EFLp{qiBPOI!Q+&zBWd=Z_P&5D|ul zjizujVx?qGMiVXsT?bD-{r$CHdlrBcDqD2hoXaOv%`~C4vqwL*@xd(*J_t!;?3>oz zG|i1lu|99!ohxKMk+OLCyrVrUcQpb4^>y|}Yqji|i)Jza2}PGLU;a3?_O$der~$<4 zX|F@YihGlTzc!)<}ZJ8TF#6-d!&8~`uqFuzyE$I<*m2gx^m@8 z0Qlk;zj*)s_ix?0H5!fHb=O@Nog<<=Pm@o!AJ^N8RajF!?@OQm#V6(gxB+whcsHvL!rO!Q>nOFfhc&V4RvAJNFL{@m8_99IdL1tA_6Q;LICm&H z?%a94TIGS?{A31iEyalH%qc`K%8-fX&Td<9-}@Wmc;=44g$R;;_y2ISsqPgieUmGv*H3M993W_ zfDl1tfFL9ZL@5~4h2hdv#?fHHAVW7zhc19|P!z7H03c0}%p4W*7$e=`NU-?{WzE0; z_TQ%DC#JiznFG&wr_3ofgBpMl17ws8RiDyW*x0-^Nh?EZQG)<2k&6K^5@49^pp}up zti_9#txISl-`n`&7e7jF<}`IhatAO7YDWKvKf(G{e@pk!puw9}(_jfj#ooM;ewQQ1 zC*6X9WQ>?fJVe43r|@X3C_no^Xv7)M1ziGQ=6uLf7dr>vYr#a ze4@iGKq;CHD&(1|;&5}n&WY*!<)`(s(AuBU$N?G+A z(+ak2-C@p~#|p=X(Wk)!TVL4o`*$Eq-Tk+#SKey1B%rUj zSR8s|>+svDCUJ)lYi_vnsV8HtFaEZBk+J2>m7nqZ{SI!A*%!o}ciuT;#*EB=Zrr%> z(y~f9Hc!GNIxf8AScU$8*Qa~*&QpDbH!aC3@}x4CX3ff}xUu=@?l3F$th=Ww=+~I^ zdwse`Z$H^rc++KBMP4iMkeRrYE8EyyBmx1rWF)|ZSVC{#`_Ql39COQ8eRxrkG&gUp zH!8C8Jl9@cm-X_&!N!KhxNinH42P4uJfOXq;aQsAz;3&BQnie+=08&+FG=U@;=PGk(j62Q#6GM%C zr&@%_Z-xV#k97~^N%Uw6aF*Og3xOdArbu7{Br;MN018Pu2Prr+Ow;918K8;6Al)!y zj)agN4xDpUK>#w*;ATX`V@L^y7GUu@e&FcYBeR#?GQ$%D4$~Y$s03mJ%ouPtC>|mh zui&z<7td_c5Ln>|aqQnj)>2>6P7fI}fN)=bq`&W2c2!xxIS|bc>(J4%D|_aLa_R;= zzC&k+bI-P3xw=3z2hTJ%mLy8+N{jps40v*e6GCS?D(Xn@K>e#Syv#@l1j)GMDzOj= z)#<9pt7$GMIC|tr_cV{Etca5;5m51%Zf~qvLN65EP>T_1Op&@qMoh#>aS};Ez=$C* zyF1%_z>!QVE-5an&gjDQzPoD7A{&)2uiVfM)MIcxj@c z!ItgM{L4?}(!ZQKb!xdP0N#PUm~o)HWn|>Ir{d4%PMtc?cOniW23p}RDr$pyt{aS4 zIKK1L-unK#rU`&x{*-GfZ(Oq4KNJ9Fkh-!UOZMkY?AIp-p;C{JnckBGQZHG4)%Xp3cg z%|6HJBO8w1byqE@&4=nw9ytomsQ@fHCtK@j3n?cXaOqT#1N#phbN3j9vunn^tq>6u zXZ4a9>dWni_V?;}vBm3agC2+Nm-?0jgTdQxzkS-YX&%qmz0S?eUA=nsr3Ecy=QWj> z%#Z6WcHkLH)nC8!g<;ur+zZHf_T2SLrxw)Atyyrm@tL3g_@M*AfJcGs%EGDhZ=IX( ztzBGdJbtt*dZ_s7zn<>*0|1m&K8r~c{8#8WD7obgsywy}8!&|EoiB$ z%+64c=*cd;Z27ts6>b;|XU&=(+~2yn`Jt|2SAP%W`<)aqdp$vBx(f~;dgN!c=(5Js#BN-FmkvRlO;qrsuj;!ym;5E^-r|@;6#4OutzgTWARE1nWTeo0~eC4 z@a+;n4u=G4l%**KGf21y4MH_xm>!?Yl(9$xB?!OQ<#Vcri>m}&)e^eF!k}a+p%8a_ z6u08^XkI-hckL%?x3#_Y@{c<^gL#@)<7W0Pnb8vsa& zTgjO1nMVmwT6>cuJpqaI@L>DN6VJca>G6!}p|+j@QMTseE6MYH6txulAh`qa@`SIvIm#4C?HaO{n2GdwyfLL)p8ccKgnRZ+kP3OXD@%gLYT zTXa?N=I4I6@o2%Z%0ex#yl(ND8J@ylJR9pg5|E7Xyg64domx@o+J06^T4RkdLL zn(NlIKE3<-Uk)D1Ee<5#6a|Z>7rFAXve5@`Z2Y0I4M$Hj4Y86Mfhx($(yH*@(=R^z zEbm`1{kFL?*WOt0RKxBKKOY#Z^#cH_Sb6zuUu9Y0yu$5IKJbH34a-y74)(v25 zQx>c)8hE33>o30>FIQlw>1?#5Xu5_m=+VC`q9~Zz|FI+3gf+chEPBb6b_4I*V08G(pBK8%ufOG{ zS;3MyQ=lm5S1+xyHa2eoB7)G0YO?n1+Oy-Cqaop>-11NU)jwXpw5Gxf3^nh9>#v=+ z>#OjU#BRpnGt!ljA1dHGsNNj3w&@;fb^2y*m@nM zKBW}|Fc~^S2HY&9L_42*;_;~TDx)y(#)a!{`o!{bw^_daw$H^M-}v-nkDWpPFa)mu ztB)*QUp>X|R1z~+-L~?z?{9tM#Vxx^rsT|?wrak&x~R|z#Qga+wUs5o9CSKN#gSie z^=+S2hQIuy?JsYA)#35gUUg&6)zcQNyZTNw3>$v^+ZUccu8ol9U-?P&lwVfNOi&mD z&PWo8lmjzf;HsmI&7UkNTnuwc=H(n|K78i6!`lEjSL)2!rG>dAfntC0)Ej5&zbRNz zP*9M~kiY>r{njts+xz3kHoX4a!#j{Mjw_04igW$><>fP6B^p!FAnx$zmzU3QmS{|4 z71J-Ps_#Df?53wriRv{o@`9EKWjYbE%jT5jjVDvE>7&pNB$}>mQ9f6XCbBY~l_tfm_(p4Y- zL2cNxL%olF?>8?Tg7W1{0$Rlk zG~61~SjD0nZ;R41r+)U>!z2-FuK3IiYi?LlEp>pbqUqCRS(aZ*`n+NGg4u;XJyyc@ z)?K%ZJ~d@zbKKB{lsDge^Ri{j0)fE0R@V0!c#$Lb zmaRfLJ2tafEf? z8n}9UjQj#O0E~hvTBNUH*fg`%0l)$S%uu(;DRh7l2G!_<>>?0CNNEbq;RGFExC8R? z!l*d_w2odQFJILlBI2WMoq>u1CwRaBIWWMA)Isn&^{89ZdV#rmm@fd}ghXEqG$(23 z)WBpW2o3@n3Wg@Anr@655ue8mpa2jE8RM$U=mxbALg5C#uNHIw-UmF#h%?m*14A9? zEpbGKJwdN75@tkkdt$(Y05CEX54d>(DS@)zbXLP4xB?(a5}1_i#)y;l=eO>$nX!26 zow)v(dDHjR#2cN|24$Rqj3J_F8irwXc6Di*!{_sPy*^CtDL??kQ89#(=pOc#i6GsHKH>0k@Bj=0xd9_Rkmcy>=gwT8 zZxFyOM@Cqn01^a7Tz9*aQ15Wi69fdtIDABwepP{os~gJ*WQp zj=x_a@WO))649w&ed)C>h_3qnSC-p@EdW3?8XX-S&CAQPnxm(ur=z1|;lhO%xMM*k zJv}|UcJ11@apT87{_#0;<}k*>;c$L_el!}j><`1?@aD~%Pj^LoYCpce&pF|Al;(M2 z71}rI9pYl!(U!N~9dre}d6r+S5HhOzeLV>XpedzL9RiS%Q?PI-pg9N}N`Al%!w~gA zR3&dkj6py%0UV||64#kG=pX~)pu}}ESBoJyIg^GUBQdIQp=W37rlKLKh*08JVOU5X zGo8NjYJmm-fCj86Cn`aT_<&5rOw+G$XPz4*f+UegQA$LC1%L&R6QLBqfCF+ty2(-X z#szQ=DsbTF0sti&5@GOawLkzUz;H+jpn;T-6D$D&@CHo*QAnVRLZ;U*02l=P&KT;t zVI*`TTfr#Lc1c1eQApDy#sCo+AdbDGGTsrH8n4tJTgv)Vy+BSxef zpaC->n_^*MFff7;0I6s`BI)o+S3Ci3hg4)Bz;t1Z@|fG@V8DVw55&THO!26SsyF}u z6selAfTj!zm)`)NB8h;Kf$NiXv%9N}jm>*V!`@f+)*o(}dRvKP6HK+=9Hr~!O`Vnf zYWeMR?AO?P21B}-ScQmhBUYi!I3}^QwfQ4J<4W2Bih-&zh5#HnWN6yi?MxMaWxh$)K77$+tfa20@A+Dpk1oj|}DP%11M z5&(co(hW>Shek{hDR*HaRdN?H1yBPAqQnl2BKtc#DHml8~_0r0jQRG zo2<1IvZ_o@P?1?R1puo`$he{aa)wHB7jy)sC@LTjV%kj1dXp0%j(2()7dAfgeSfa> zb;&zW*!)4c(D&8&eYYt6*ZRgL8SIlCg#effG(^S0foTNX8iY^*LO@2SaAho1ASWQ? z#2hF%a3DZ%AaYOu5f}hTAe9jS2OwYw3NYj@&^Rz63CKXxn8F<_?ShZMRSnU{KxJgf zT14qeT&z)ojg5`X+s2G{9eM5b4Ntz-3;@vA+UKmAd-q4Ls3g)ZAlM*^#7O_CZNL8h ztH))mcHN3)t7_cro!ZUp{YN5^ICJLAC5WW4*aht;ea_aDW7s+_n-3yMiHjrvASe!G z8Yd!7oPdx714OO?5D-ZsMxc^{pb#Re005kTGX|Qq6i=iAR|!cVNdRPug4Q+*9DxC$ zwU913kpf5@1p$EsL58IZPyiHUZsq_&5Dbt2B@rpWIiL#>EQyB`FtR3zh^T;KZFnTW z1VRK9f*}%D36KCJaU`Y^5t1YVNr*{-5*(l+5-p1YigbR1iU;)o}@|{s{t!0fGXYm{V#*BuF4bbT~MoGS&kTP*XW6ToRGU z5Vlg|-dLO%8yg#&cL&KdP1BrC1_0$#*G^rtfHW4IB>$AqRP5_phl_ZwbM5?X2p1d>2RAXA&EBcy%0#?)0ALf1L|h*qlf3ro|qi@1?Ce`<`5Mo7v;BF;EV z_t0d|OFjeXFf1uGs}(QM>bj{tvC_Rb+4B)o|F;4mTIPxXKvuU$P=F)>Szr=C$e6jL zRtb{2t+a-YAo<`UIJ8Uk+_$+%48yR#n5JpZG;H34_jOlcc{5huG-LHmna7Nas3gy= zUH!T5u1@~zeb+p11Jg8#NY{01`XPkSG_AI__R{>gnwy*7GMP1&O!mX164!VgS1cC0 zKvkNJ%^xB0csw4DPdI2jZ0QYs(~^w@nUY=rGDMt|p`0cCV0yNgJedf9FeO!tdAwvk zbt$2X(sMtgl&w|r-zhx+rW|F`KOyTGPr@_G7kMNx>(x zq!}V)x(s7>f|T4HmaJJXrZY)Tohf}1W@-q|wH~z2meO8pv(;bzpFc>(dj2$aQ=5{HR+4YlU2~p^s zZW5cfAQZCO+~$G^hr{7;_`NQL&7TrhcpdkWvb+a6aZk z1?T8P&xOV$tBhk~yjd^1uugaZsqFq~V`F3U{(~_VjYj{Vm!R_vF>k5kQWWJ)?0*Ia z2YY*Z2L=X4Mn74C_ z#{yL#WZ3$pyV!(r>)dXYjN+2&fh-kB=3F!S3`@e~nVFW3V;3SIAiICs*x1;-|4@|4 zcOiZUK}<%EI(N95EON$M#VV9i#^dqc-rnZs=ANFOXf$dVhLket&95k3-Cb?%ZRO?V zrKP3W+1U<B{Ig4A!5=hQ4*09QZmLk=gAlb zh%)7H1^`wnDJ5f^F%BRBBoKp?Y=($QOX=iox-O&0TnXfmt9H;q*&rHn)(?d|QyjvX5s8d6m)H#avYC&%aWan9rM`0(&> zfB!&lZ{N_+@X*lE)TvX8i;ERSvE!B5{PDoXqC6m_+@P#3$`AwyVA_P0cmxELC@>xR z6EUgsf(*B(WPRXff%q%Jpn@$hys9t zOqD7rlZ~A>_L(jWC1VwkFooc#AaIs07D^$6DWu9+GPD5!STRFjEEtF+5>g_wLcuWr z35X<<>Bk&X$1a=^Q{LtSLHgcXi+*Ddk9ANc!(mv8t+yB>Qb8~=r7liC#S%aQs_E!8 z<1}*xlz?!=WVVXuX8tw1zKX&YRLqp@p$jF*CYqGPm-vwQsjm-r@sbzOUfQ)T@L4rh( zoEQiK1pz=NCv=PikO{;%vZNs$0g&~ZB}`ZmY8V1bo=5+0LO{+LfPxGev#Oem zl*pOFR3@0^ghLsYl4Gtm$P_>h+^Rf+0Azq{Tu1|}K#+{&L6W3IM8GlM9-H?o6S@H= zx1h5QGXew#3QP7y$gp!wp9@42Z3_u3S&AO+`Mm z7X@u>Y;0`a4%S5QTp7buL|or?toi3pHuVpW z-n6RplQ&G^oCo}Y>C>mVoX+mPTAJ z3`zh22oekxNa~A-0q8Qh-LZ9yz*5O2B_|WM5Ew_EJRcPR zV2mSUmcU4qRFk2#jV({TAI48e({@=LSn{9=l7m17=LG7J1X2ivSvoK&g~>UCWKnJ2 zw@}KEG%1|}0007!kdh=QDgjfH2SFy+Et35zDHT!5!!Rw5C0((SyJ#U&DpDZ{kU+wc z_broLNOxEo_a~)jv)nZiEYn|1K2Mg>;YEiHwz09Xv9U?oD@_6+n?&zK=htx!4h}Xq zHxCUB&zLczva%u&2yo8BQFCxm9zEID-XED)5im{DG))3>yWRQu`LTHX?AfNu%F4>h zN{`0_A|cI&XTNnc=gLJ>medx!$x3(ssip&){^R#YsAAn6H>_Scv)K9WE6E1W?Ax__ z=b^-`Pkm--4!G=D;`;>z3Bx@Q?|yx2$L_4!o35EJHoLZ|KmIPs%H^y#877Bc1zS+j~l@?@#0}n7icG zo7YtO17PCN=^y^`Cx=4Lc&ujI?%i9eerNz1tgm3$jbIrd=~<-t_Bc`C;_v;isP7e5T`YPo%W2Ja6%5ubf{| z699#PNr6BNW#7>q$ItF~^zd-3Ib5^wnk(0r5f?_|8~5+n)No=@#2Ip(m#n|%ldET!<@rWqohP3C)~^oMU4PBm%dVQ0 zlXPH&sqJzuD zzN{|C@vbRl&3HU^^6CHB;<@&!*>h%A2GYm755Mx_t6MsH=H2#pH&g_@T5oE$C7NRD7FsS=G`FHdf@o>=O1{jZR`+tab?jxe{qmZ}Vb2GP*a*#pn~_oK(=-udAx7A&s|0ss*qG;e=+dzYD2b@O!#vuz!=&ASAjw69I> z#|0BZs-@}a>FMq5)iiC&lse0C3jmx7R1|C1FE8#HNldNr8-`&RhOQez2&c=Ll@)Aj zYins~&B@8}cs#_S2DBb{;y`hAao&>Jg7XxYXsGM>w%4D0YIkSdtTHVX0pJe~(NM>! z#^z)3+{;(i285yt$u!PQ+XwCa1Q8*Mj{2P&&px;Nd1uejX-odyF#>}gJ`n3lZ28rr zJ%LhB+c6pE$3QEYr&cL}TvdrfBHmaZJ^aiuUL=SgJloOPH{^FY>swxEYSwbp4^>Pl z&QiocD;snRRVL~WpBfHzEc|kbOEnZk05rm~_q83b2B%&#E9!I)pX?8{^rOkU_wNjk z%F<WfE z&G3T;5>P7O7DG;>D+X@o;EA1`Erv<#^68764%yKc?;i|t4($ha9Xor)tb&TX0C)gg zrVb2{f!WaCva^17U(ZbE@TvVpdD&Gp3j(^XwueCB0x^aV>Tey{GFW)m$FocZQj!!g zpR>F1nXRWH-8f@fuEU7bzw-2}(-o)h>iLEqI=$<`jhh!5zU;hN6*(DV)o@?^p4Wc% z^M^JC=(6jk%qTB<54(=dg_9Py2$JDnq!q6)5gBfK z00lq+37`Ww(%~)A`Z9(xy$5;fGA0ODjv7IiNf^=G+`$b?z$22Tq3edKIgpPz6_P1Q z0pI`t3`t590yr3qqT%+IW4pHOKX|+?swfIE#AB{zPb||kw}xXE+WgGZ z4;?rVyuAD)cg_z^wvuXN^9KMC8DnXmk$8V|XV2gXW#+9$+lgHV_U&yL1re0}2cCJM zG;mYCFP9m89UU4XDDnQ5gNH(5=BzKy&u27vdfTC0n|C(F6~zTyvEor(I07T#t~1+y z`rNLyv0$#VAZJ;PC11(j#?9ML7?pI@wYJ1%0|2IJj*N^nG&Ed-P!S4+E^v2ZF{#pO zGCwW^%cyEH`uqB0u~=SSp5>QCL`1|mE6?}ea!q+6kqCGkx~^Limthz}2vt?Hv$K19 zdLpBd3$GZ8p3}z;@7~7NfA2^CZwVB7FZ|TE1&W^2n_qnPCv8*att@c!EZ_9Y)=$4| z{kwE^n|B8yLcROpXJ0%l;v$sDlTp(Ir{bn~bMuywA2eir{WpKP#^-(gJOA_4*2hn; zT`+r!0s!i0TSI^MPhK3_fBe}|h|o4bpG{$*3{U3=|R zGbiidix0g1vqyh-`o2G#r=kPAkm%`c*z@@Itd$>^OUwNM|B_iZ-F?;Fp(z!ezx~hO z9N50;%&klF{k#9=<-z5*e&VtFRu1j^{SW`<2Z!n(bh`A4c*pmi-`P@9Ax0y!xDo(x z8BBH`+x|+w?}{tFaQ8LKqK)5L`PrjqXH-oqoTdl>F2KQ~?FU-b=Gcn=_cyoQG;`oz zuK&x}>3L1P(-!&wPyuA1d40u|AN#`JexW+I%OhFk;HFJyZZG%y>vA~& zNGWl2@3#FN_4Q_Ou^s-y=3T{EHh;k#^M7;)004+Y+pcGJzVh00Q?H$&9(rPXD3N>R zH@|art#RasxBO4j(Yk|mi3vNKQ@;<;cZX+Z0j?RzI6OA=lf)=VcX-oS~TUF zZ~bU}{-u>fG7X`63hX_8eD&6nSyfAX_CmSMx#+sy+uJ)jI(iA`TGAT5Rp>7wI$zhD zd=xpKj%#>$*f5Oj>}+eh5-U{3a5%pGK<95>X ru3D7yk+sFTuBYTKT?mnvmwV>) znMp-MOJ+mFbR7^G03neHc}`U?EhPs}Mu(%M0e>oCD#-BogQ?Ltm1kOzO(jdm%myjP zTw$z)NJ*rmbX;#DN=5n}x1$SML9uYG7U^FR8Q8Ig|5#y+#dz6Q|MkZp&%FM#jW7S- zpkabjaq`B~$5>0`@{cU>`v>FE`AZ!`!IEdTci&o53!L~+TU&p(XYQZhP^+p;t)4sE z$}Ox%XVfT1JPe%00e@uCT4dmifIC}a`EYL{=#Nn-2p}Tiu%qYo(p!JDeA%?17c^Kl zn>2EPSz7F%?oxRS^2{MU ziwuZzU5PtY4jj4<99Fzt*RE6*x0|o|+|4t-(-(cArQ?d31^KEX0JuKba^QI9BX{3^ zI5^D#ri>}bkU0T(T$L)R0HApS#UHu*iXS~VT;JL_SUDE}0E$YXZ)o(;>5*G%@{*5F zb5r-|@S!WOyzc3<*{Z!S?Vl1U$E&fJf|5{43=Va7^%cztn7YRs1T9#%7^)-?Q+1FU zFc83yG$w!)E24}5P}wL*FR-MEyd>fhK>#5Vpdk(BBnhf&3dw;Z3Lu@N%1Gsw*q7mk zh@26c5{M*%;M|HP6FGZg_v1f(sN_p8tXWpKtPlYJ6epBjx27z4-uVU~NRAPhIm9q9 zX$+8((uvb)(tc^_LvI?@TRsPwquzw-oO@B54-oR~>BBt-HdTH6A4;=#{PI{yZlH4JRPGnB z?AE&iKj#@M1;?>Tug ze0Ily-ozcO}w!bCJ(fQ++JQCIDb{ilr6>6|rd7GoFfuG`nwH!v{p zmdV)pcUqlX;yRy>D;kZGB%jZRh*C-+glU?(t|tUwBps>$B&H0RELx^BADbNs=-`Q2#%sJi-#x88c|$1V#BAx{0|o*%z- zW=9*TS>g5&#x`^cx?!<%X*&b)Oi3z06Zo{sHe{p8Eo{F9JpfEZ4oFkoe+?^d8T_$*UVK{xLsb$ zSw)iw%ms8RG@7F(eA7i&&q#;c>-1_~7Xp|(P+mE3LJWnYz?=Z6GE)elx&ta8cr*yt zUF$wNk~n>2C^$Wqwfm>D%O3HUIRThMVGICFPwkw-rrn1RojFoeHpjc^cy0co&J#gAsK)L2E^ z_KjPb?{A#`&A*&qHrVO*R8{Ae1vm!)E$B_O#70M>01ANtVDxwO_V@}MpPXK+sK`M@ z2ap6Q0e~YJ=U*Z!zjD3zbOblNe(<{6=MxYO9@>AlzfFAVrey;!w4LuPn?FX}YY&;8erF3n>hQ2YuBfI)q*{(%R6^VFj+=*pCyaNghj_J5Yn zXg9a)`t3h$QEpuN?8XLip75wH`uZ@n57BBh8l^?n7Q}fRL;+}tacvoYG_R{0W_kI8R&ph-gWy`<3bh5vx z-|stqs`9H3efBct=+;Lb{pIhrw3-|MmVf$x?zn#S^0G-Tp2l5LQhLKx{O>n3FLYPe zO)r(gjJ0ieqJG}u1x0gRa4MOs;jzDctJe!_8m1_55Mxl(MP_vn>f~e>@Poe)Ag&XFQN0O`Ri9kf7LhG z@#B|gedF43{=h_pT`&LS2fuyhlw$ zWWA@LcKXNu`|H;hmS?Ll+}v>BnSc7)ug(%BSCn5W&ev?XZ+dX z`B$%=eX{9n(=UJW+zm_Cl&)H}xPEwG+epcsAHU(UvdX~V$sI4e^t)Hh<)6EwmfZTO z(=BbAAAGRlYoAz<7a3|gaJ*Ib%)Ii?KT|R_AUj)kZ{HIqdENTY+_$D-<14!#{>iDS z%Vu49-+gPbVdGQBkH20}xoq*eO2pj7w_lqxID5Fizq|d_-~RUK>U;ARuUdR&sBh~~ z$wxoFZ2s)(;*pNs-5tj}ye1?>^Pwkyvuo#&fBn7pl`AlG@ZhP`&m3{|cIfMFV78lZ>sio6Wa zt!m8W;!cODYYrC&=smq_r0J}deN!bT!At-E&|oCm)AQ2(LsRaqn>Me=MaFPf@9FRS z;^m&R#`N5RY4?5Nie*j$p@kuG_DJaTbKx03tZ=&^qJT>RGa;%)8aDrO-*BaW-s0uXiAt(kTz*0}el|NMWy4~)30{@;w%6|;*QBKte)2WE~AcQ8FC z(RaFM`?jAy+t^-JI)BEB@@3hj5R2)I?SFRTw#LI9qQ9>EA3w3``ami4AMI#4++3gU z^7EE~4&C&!h_D*dk>yRqVv%r!0DuxCh6nf6$IdwYS5B{0v}Bk?L_h&R9IdeWV8+6O z`(8fi$||kME%7rL0RT|_msOPPFot#?JazlrDUuJ@AMd3eS+inF)~nJEAor(5+VqcT zO#A}y&#bL7Z~sAGkn=Y$8wi^;%n8EU`?m@oodJ} zc2B{;GRNsWjZN+0}D6uW-GL9f%z}JE~6^a{Grv zEvFy)$GuJY?7G|6cwBe6-Q}z2S9-el{`8@}I~-Sj=o(Cd)X~<}|Hk*eSM~M#E~`q6be!6K z;Apt=;~&1`Zb#?#H|o#6zTx0i%VsUP^O_SKn+tL(sy=+nl7+=y*V*otou~S{>fnOA;h zarsog=9XYjO+N?_5y0@#eW$yJopnp=oC*!zj2!!Y8*-GjRy{^2Xl!%9(b z`uzWI#XJu&Haa>~-x<{kO76Vk&%CU0*Yk&u7v$yTT{Gk2qa-;r;1|QtL`SD-BqJG$Qc`lE(wCsQJjhUZaJm-pK zvnt!p*8lv0XKz?|XCPp9?AyNS(bKs%-?t)LD!r|Pj?PzhMP@I3XRL&6-k;!P+aCjv z6&`v*S~$OsOI1|_jK|}ab}KD$8HT|*S5?*0(=o;XxTS|RO*0;ktEy^+*_f8lUD(OoF-zV**m z2eIB!|Ml%%r%$zvtg8xOesQ_GJ1zzUgk$2=nbQN=vsN!%*xb=^ylu)IpSr6QveZ)@ zR!b4cNaMjbx;w;_%RljjkJb_l9sJd|zIU{F*WsR(3;h59ET?Arst?__5Y0x|_|e0? z9j)z&sReF(iSLgS3BWkB-0LM0FiioDX!)vv5GbdIU`{F=joWNL*+0;)d8WqnTWT0ro<8cQ|)~vn$@`c`R-|^iiYB%pZI(YSrKuH@&(Ipyk&ifWULtgJO#B=*RH>JiHjnyKKWYrXywXl zK6&5G<$@2*V_*MvWAna~{j#Ti_`O z4_+umG# zrI|cx#>L37tuOS^?YCWf?``XHqikSy-xt2o+d8XpFnflnAR-noTz%czYx7$UzxKqF z55C^od;LKEVC#w9n_oQa`pm2flR3=3mR9U@bb~E%*}Mrv=UX1WI6p40$2&3-8W{=c zx?!4DOhVnV9^{;>Dss*lV~hb2gI^8QwGZgTcig|7c$J%6Q za4=e-6<1VO10q89f`wDvqrF1|gAxEZl`fh#YvI&F(=)2fn7vTjV~)hbVFcT*@Q)HA znGASFBn$xnoO9v`PFGA9V1htkq!1y3L{MY(hx+msd#hG14my#+5KyA?c=+gxFKyqe ze)w0H&r8fKRv7>#z7<<~9rGn6`- zQ6tpTcy!m{Et^l&ef?u==PaA*mqQ_Dx)KVHlL+ac2*5d|A zNRZ%x;1v4+=s*|0wUh#-6xvcMv{Y#ELZLu#3lJ?H&nc9Tum z4G{WLWIlgnGjr|SnRDiz=RD8zeWu1Ot_Tp^^x2Az=w8F@Km4>Z9m#h;cfotBmk-YU zX~pyl{ybe40EQ<@hOenvSXZ+UqWd0w@b6F8$Ex+?tMfDUV#Our7rM_63>^OC$t!=g ztT(54QAKXmnMKnHAQ}xZ8sPPS!ayjE#zcxJD?)??LV1uMrD?U_JxPP8f(!+ZvY41`mphAMc0O1*fghj zQn4O3{EvD{g0Dk7jcX_!79<1`5@noBpDF@9<7W@f>DaaYrGGxTviaGvnNMXqs2FP5 zvnATUX&-yEU}0Y0D;2ki=L~l5sE+CRB*)#$yHp zFYj;Z>gvoB3JoWU!IQ8*>;oTDU05K~YAE0|OGe@B%C@y0DHNjsdRvmBcxJ9l29S}N zmZZ*Z@HiY2QGG6~LrSqETZ+?kK*Pw<*DGZSrp(MtU=RbQx~fvf6Z5%T6vno=06->_ zWuAGN@c1F;-c1L1+_Yg={=x?`QtZtnF3?EDu&;f`#~-}6{_Xl67GgeN^C$)YhAI_Y z_E|Fu)6FW-Sd)^|CdKypT(L;N<7(Wr?t^z8{p6@zf>1vcO$HFdtkXA`Ja>9gTDA=_ zU@}cTbF#dZL%{m|QEz`w)ahUKawE@Uj2Kg%I!!_dVJXF8$jDDim|H(AD5cQ4%dX0j zr&UzwL6SfwlSz^kiw(J$q==tkOdQ7vI;(BYoxhs{(70mB%WpjSm~>w5j2okb%PC9G zD6h~1At*Pun%ZR!&sWe|8wsJQ#pM-ZVBm@OJ~~pI;*DZJ0AdIY_PWHPLaQ~!0+>+{ z%ZzCi{w=J}86@$E=oz&o>FF9!n01+%Q_vc}TMQ4ngI;I5w>|LTvxg~z5a5g{#YM6I z-Y1vf`^XqRu2HoLDU4l@OQ+NI5A-`6j$klIDTya>#k00pmPH)HaU9FWl|2!qR20Qf zC^RrIpx5i=3i*Hap1u}rctGlW>(>vsi+_3dYcE%54(xdIC%*%EViElZ!%&X8h9EwI z{0M^_K+ss+eAIuq(M}3Ye23lD5_5;fCu?Zi%4I8h)urnEOhXKTj8J{o>W1Z;|J@Xs z^!NAflhp?lRWX174I11c=rtM{CbqijS*z{|?^%0D4_U37_j!&SM)EMQ&bOqBlq}M#)7)N+nU?yF*-(Q9Lr>9+0!? zpk)XM;E#F(VZoA~URCt-5AL4|fMP!2)ZU>&$OI7)P^v8}lP|w}Z{wd*RZK?uw^#Q_ z!aPc@EK#g&>1tgYE7{z0(*qM!>3Xgi006KQLA~!j_Ey zBgvekR4N?~hr=-#4u_9v5=JD1I5{^0p67X<#~4Q<5tqwlOSY+0Uqj;EVAN`z8qa5I zw?H65z_D%rZpVgQ(`MFz{7ct483~C7QF~icwwY0xRQ>^X+wPC{qe$RXr^4nGi}paQ zXYY;!Kq-ZuPuA26t%JoACL{!Tzl+3EOVkwc5g>p;03bF?x=XHXXzZ3E9{=FhO`*X? zRBlnr<&B#)Mdqw=<5M68AjJaU?|;WHPo2z)r^GT1}V+POCZ&Tt5aTDv+7 z+gDUs>fGSiw_7p{=G2`vSq%_l0Axq^wL4=Urk{IfHKzp@D3BOPf>M>AV?ElXZS-~f zdJng5U-fn%OI?<%)nfnvi9iHmDmKb6l8D6Ml>D^T{cVljs8b&9>fE-a{!N>b3R)B5 zWU*MpsMV%hl0pH0M^~qd#)t%;tyvnSM@ww}<`4ck@0NErbrG@G(bMicKp{XJPWdNI zJNt0MwR$-~-{FI9wnG6{zNm8Qp_;-?H;($OAP&8Bsxz)b+;P!0;KA_->`46{t?WzADJGanSgcQcD z2fBB?x7i)0B4DLi1;8qM+`Q!DSdfbZ!XR)4zB>PA$I7?&ezIAvHf2o7R+AWlA&W~U zrprvZl?8_yTbt^)`@_Kq0RWyim@FFPRrU5QdB^1sgGALJ#xw{p0D%~loPf=?%&ebW zaO3m8n)~cKD>roz001!zogb`g=s4_AsPwEkvT|E}w9kpC_h9qk18=UGJHA9_FrH3& zp@cZFW~K^z16}*~?gNk_(79syCacq1SUB#BA1E?voi#HnI&kFmrR%xrwP^yYWQNw= z2_dMrt=l4tnvKZ;Po#b8x&zT(-zlGxgS~^CWY4mti6U#S-*;&6sGT7SUbH2pG(TTo z-?+OC!ghQ6d(W@%yL%->wOW;)wT70z^esC6j^bG7 zhs!?HV%hkDjMHusLzRY<%EiC@`QR%{*6!G{8zICgq>OZ{Y*SZTQ*$#w*o|A?d~0QS zOqp7kJLZTZ2D4u876#Tl^ICVGC!v&^;7ftV%Hu+#t)P1b!M!V`uuCD~La(}uV1 z{lD!~FaOc}q1_Pz;EJX%oE}=aXYKtz+Ly#g;ecS9R55E-g@E7-76cP~3t@o*03)#k zX=72BTQchyeerp9_QU(P+;_`Qv_=Zyg1Xwu+4-`jU7bl8)2voO3BUryEYsc9e`NQj zgPrRJ>X#|CNCZz&#e(VM%52S_t$6A!2eCUPJFm-^ow;aUQcSzE!DK8{B&8@203a#i z?hhVnJ-F`3ipZ_*O&9@X6&hp8#QAg288?4!^|FTT550Iu7xaLo=92kSij&PMN@IW| z3?`h6!<-}H^@74eO%tzAJFxSkM{aw=h2?5*WcFDXlvE~B0N{8QfKiM)tFrO6&08P; z%Mn$?6I07m3MO5Ylk5-q2R82Pwkyu>3vKn+Fa7lSu2(yIMH|AtqWsBqbBZ8*xaY{D zAHCPxZjX4?Nt}504GXg6MO^ns{=n|;P$a~sWlXP|Fv#zC_xV44@IfTXDuUbyZU`>$>L+E`ROKyMOi`7u6~i$u)HotFE4r zNr5Mfh5?{zOToC=4_zAGeE97re)ZZ*N)BTNbXk+Pmio={P1@- zY&Ie(91wD5O`bJroQwhADL+<(B*baPP0Yz3m=^GlJF7sW;E!!(7zWZNjW@iqbJah7 zbtpv;1ixHl*i-3OU`t7!?VzFIx!>QqR;e|59D$TP3ZPeLDi>dx{f}KQKeY4Rj1*pD z$k1T7oJEAOq!-sNzI(?LAN}p`^-7&u#%NQORp;D2|4Y>dP4GPflPHC@qX&%2TBTkO z5U(C!ow;DH`{Qk&{^7>=^~fz2ojb3#d_q#lapUW!Q59kx2|9h{2M##}No?c*+VKBN0BvlJr`G%~+P@-BW)k%+esQFlJAfbly30(gUlO ze$s8J%dIReP{Vl`&avn~x?K z^H@1YFanH%2;ttA(6~9{t+}ZhRvtD_DAu|?gC3`sQL=)p=0{gfD=s!O02E;iln~Bj zHjBy_+S(qIGf`T0-sH)JbFvX4NkP7}vecSp_C%fj_I<4oQ%9x9gee!-EtpuY^NM_L z`@z;8hbu&6YF<}-)h%*TCIC~`=Ze*TnnfoRNDjgoV0X$>*J6`|> z%8<%tW(+m6s2Dn&1BPK85asW2+tyfMPuQ()cnc}qnfa$X?3{qQ4|S-kYvrND#=g~OmO^VZdGZvLZQH(FhB??`ILgG**X+tjd_KcC8-uU z2COos7#SM#4)lkB#X`okbLLN;kZa>GMKPa`O`BAfo1COO*4rf%4uOzl&8aNOP!OUr z$T(wWdd~PM`BnxHLE#X{OqT5G@)V1~80{yqs7urdmT{BIl1r+pGLkiFilU$`m|m4> z6l4sIMzIL$g6UORX?h)w2{HG8pJhy?WhKeutH$SKXCx_gDK^cZFA@rcQ zDB9Q27e;bp?G+0q7nh}cPBV0D5S35_g+w8HR&AD9sp0`Jiv+Vp!^n)88D*uF3#;?ZNt`4}QY50tnN^!(QYmGz5idzH6~C*vT&~{UUW>(Y8dcST!C-H1uib7RKYo1t4AE#*sZ_>dv3PagXf)c^ z*5>rb{H6(Z|HdK@7qGAqpV`2A>ajHOK&B0HPSAgj4Vw1l=)KCGk`Mb|{!DUi1|cQNsNp zNLGPI1T7N+B!WKzDpPErnM<jL%0-FF)1PFXGPyvVl*iV^Y1b6}D05TvTVIl%T5<((yvMA6Xp}MbL zd@#Xxj1j6CfDjB9g&cay4TixafanHR7X{!cKnOq*LCzjaE_VAs7n8uiIHT?euQOB1 z#E(W01916>SuFy9BOn@;3JJntU>RTq0EkeKBvHZo#Rx+Hc$rKTd6ty`-2G0Y*#KfM zFs49^RdON#CJ0lY6etTAB!HNh$k;du;%M&P`pgY?c;`HL)53-2+27VAw*(0iBsc{v zEiDZV4P|9zr&j^Fp`l^du3cAOeRcc{KA+EQHV1>jc&wk#=UcaK-BEjBpy1m2-jkiQ zh=`*-SH?>F0ssI(5Yp1p6bi+*ZQEK}T3g$sB$LT(HtTe{xK4({>Fn?CcMLj=MniFN zacOC(UY}SGNbs$LB0@o87y%R_28bb`fXytTR02ujm8n1}0hz`y`L5>x0R>4EqXali z<5m-hh(!`bjD&z7JqI9wpCUp)B1l5OFf0Io(s15S7s)AQqF&%M1c3wqGB02?07w!@ zv5<`A7{FSt)W z=7||X3>sSVCICReB#01<61hsF-~q%aAO<4_5JM0KhyoJ=CZRBUGA?`T=69ahlk&3*RI0?|JVAm43C3hh zt-?|BxX{Sw<0!B!YciRpPoJKdnbq0RF)%oAU6s7>g??7EQ`ew z4<<~I;M)d9JYfKU1H=FT3xH_6*JBu7`-q!8!_`|c!;Ty;aeD$$1PIf3#tKi74#{N* z;}N5WV*ybFR0cpXAOJ$+)(ilH0kiQcc69ipm`5X`DG(lZ77zp!Q5MiKK>`*S)rf&Q z+JNO4KpMb20CU{KfZ|bJm}11CA=f$r;D+?_(TI~F0ATTmQ)32Dd@l+B3_?6X7y#4w zC%^(=ihu!-$AwTS0H(mfF{c{>#Ef2$J;C>flLIH{v1(j^vA}V9j06}ST*o#6FaVTe z2%>;!ylW#2yc{rd%y~Ps-T??Rz{wCA9;_TcG!ifdqyogncV~eaI)VjI0q|^m01Sz- zU=9ESV4w&n0Ac{~qYtGY8YCL^wJ!V1?Qd=$Y<3Y6kwt^&-}>wo(<;(*|LdkDNRS}G zw--uBe}qsvN(E#@DMbjzc61?xSeDi4bS%pznM^*PFBl3&A`wa{!!Uv%C>2VzMy=Iq zWwJ!dMS^c76acXpv2?gND;uBW#a|&NZpa`CEIk$(g%OM4_~HeQ8)y_$N-0nRBIOX` zksMImAQ`gMH~@rzA{n9t6A1uO#6#RdK@_q4ur)$}VxR~R4`ldggeau|5~TzIML-Z@ z5Db+N0!BG}Gce*m$89T$S;}kZiCZwnWO!1^9s6ORltB~#QGzJ~f&s@(P(T>Rr_2Zd zD1*?*`6vPo0mN^gVhSt;AQ%`5$K?ev1x({R#ZL%;6LZ=h0K;XtMm|XpU?jur&~t$S zVB&iY^#_&$WswL7$KAUCz)+Tn2O5ruO2h!bFu*Wq=nMeIRzna*NI879_*OJ@F$Dmy z01O&Z&Ov~Hy6!Xd|^Sr6{Zvmaz1-XMOvzg|JLf}CrFSW z!MB00P>+iujD{yzr$(hxeJ#!R1PT7vjMmH1$?u|32M|KT*4ptyhU}41$IkGC@z}^Z zA+H6U=v*3plOEH0!vGW^e0_XnaH(B@V#cZgC8>wC<1hnxixH}9P?R?c=sem*jmH?88L+D@Rdd$OGh?i z6ibR8I~S&iB03akb%O13EE@5c^NpV5g@TitK4R+$RuDqRViboQY$Mw@GBWIhOCP)U z6Sp6;Bu9AQ=;w^t1m9=kUpJ)yC&#sq(G5oSp5fkvMp+RU$%sCDnnwN5;||f|oi;&& z1PKx(I1LaQy<*g8J}v-Czod^VL4xlnCrr)g=x-kf#iQy**@{N_gGQW&o@i0UCwFjM z!wp87DWAJE8fkQ)<5u4>JMe^CLL);NPcR!tuf})6UlgBp9y|S*>n-%S5k*gG_!xH* zzl-BS;h%3{g6}2tq+tQaqf<}n0VgaA(Bo$Ri5-5_YaIWVj@WTHpmC^6esO0*=y>#S zqI)JtkRU;V(}Rwg$2Gc-Yv`aaJa2DrZ)azxy~plwIQ)LUBuO%vOsmxzjmDJJl=SrU zuT%9nL4yB(49%_Rh*zfwq&qeiMvHYi`JEG-SoC;29Re6ura%Y^5H!3zfAXVdG#}S+ zp2^tLFG-RDfk0bZTWf2p+wG>5vK(tP84*H+5K$6)>^;4Gy}iA?nVFf%$;k>uLTop| zw~G_Ywo>F6X zm0@q$khlzD88Kc{0T3VzKt318J66Ku@W@0s(JvDuNRS}G*MUK!tn7{I0 z-EMbNQ&USzizG>LkCs-eRjE`6p-3d+^ZA@Emt)Y;)zuXY2E*ZSPEL+YCOeICV+j)c zf8qp3)QQPOl!{U`j5v%i!=8|pL;)xvI7TST!~>QHB@{+lTtF!qn&%ChL;yo&vX1$? zn320jViLm4iQ|w+k{FGNJi`3QQG);|h?FvMJ^N#OQ-Tl!0LO!YDFJlMs-XZt$%y6* zzl(;iMx!EN3=DJ3;v!;<8M3&549N=;bV53)L}?6$e?UYcaloLFLWUG50YYee5{u#3 zB94?Ww|+33;Q9P~upT846M?}%hiVBR0D7!k!B>D#kSJn7qJ$Z;nh+f}w@ywT96e|d zB_in)BuJ3pdygoJ{r&x?4C)yjpU?Lt_mswn5gel)*VuVnfk2?Wy}hBKL7`9<6%}S? zW-3+ca1{C-p=eanYV@h8si9EF?RFnMag4qAMt0ngM7h5acC6-VFXNkpos{$;ROA8d(?th?KC1K@0uM`G^SoU}sa*+^VcX!bf%w?~ANeRK(aAjH=QB$1LBMJz@P zVupuLJZ5)vO~O&ryH0=t!hjJFf*1*o*Gm4p*3B`+n$b@e1tNkd0K-C}hbBmnAi?(y zK@c)CGb<`8P9yBDudi?0wryX=IX1dl8A4h<@u~;l7#sI)%G=@T<#>S?`#-{xIJdH*J;1i>JUbuRf@rs$_7mUj~ zMU(A2_O5y3M~{96d5eGYe+$l;l%@Z|yZo=?tY5oy!-wmlH4ol9*9y8XW!xtCE+Fx^ z{U{ZimaKGsv|YUF4;M~OWwb=jhU!~Z9k~6`C-!;+6VAEg%<`HW7Ea&*0GJRSkerA6 z?P$@v{mbvDa&3FztxpcDtnX>V?iq{za$arqd6ic0{-qn9c>2SR$o4~#%5xUZzVw%q zCP9W2cT`azE#X~jf4rWXK7Gbz*8XJ=-Sv+*4wLkfg6es5F1~rvR81y!!I49cz3``} zKG>0No~*zBzJI3VS#nhpBQPDikZ;E=zdn$4-B0G8kyj=VmiFS!A3yQto>$j>7Lw^_ z-2BE*=BraoJjWoGAL^;WhBtO?-*nTzJ~47>C6g{+eA{*7GeL`i0jdBgHh83`x&GA` z*S@o>#o_5V^V+}tkSiYluQ{& z_lldITgyp?adnHY{OOG**ctomiEID(fn1v};~*S#DWV#u<&ryoyI}UTLN$OIL|@-0 zpWOfAM|-;WiBXIg5#=rZ^{>yHoS&t0xjHsKf9;>vR{ZGl3+G=x(K7P83byaux8mu$ zUW+cg>z;*E3bOwPKLiQBE_7JBkipTYufKio&wl>o2}gzxKneJqWQ1$Y1>HpUj_GWmSDsHW;O@sAJF5*T1j4>Z;l^%1gDw(*kmI<4do- zy|m@<>|2*yJI{f=e-{^gsE$KF9; zV1;QvfA0FpQp4JJ-+Abr-3-I#T=tJ!&n~IW;2o_SS3LOZR~o??A~{noKKq)x7MBej z*t`ARjj#UYZ<{DW*=POV|DAKrluE;w4u&B8J^MC3bIV^hO}q2)hH7c`vd{#B3qQu|TLjJo6KT7~gEuF>f4>vy@_YK=N0BVD0T z#LX>1hD&pGKfS!z;|~{Qsbj|wMV8~#YBk4mU0q!^n^mLH0Em=$y7zZVgZ|K|n%sS4 z$GTPT>{8TSdscOMS*lL>QaAeb={~xCPs3-fq#GAk>p>+?&YVzprcO%LfRKna`My9Y z1!iE!mQU9nsXw?wfPo@Kn%YD9HOxRyedou|ZB0Mxr?d6W?oG{ZlGId}k#99H06~xk zJLujwU&^ezYrqllqsokY)75!6$~1hs^uun@9?BInGjf>hb4$nhYNq@4ci30`XLWW- zRfxekh;tM-6i9J95ZVc;3$*yxAF8zq6rr=Z7Dc*PI1{d+jryIB4a? zw@p!ddN-Fm%RZkj5iA!qAuS8w#AePw9}O3Wpi;Vd)a>^rjcqvt-_ zvBy&C3Aq249Vfw;=H#$+a!eRL>KSO-w`t|W`8k(Zjo>qYj|qjHZA8c-5{J?7Q|)-6 zgE5UR3P5>I;5i`@+&ydYe6KPqjq&QSCLAU#i&*w^ZnDoOlTi=}jYtxMVt``)?hWt$ z`=d@#o<9AWVmU)8MMw&TLLL1~vH2^00F(l4UGwiP0eyPb+)3kfU)Erwltv_XcSEyg zzS|cYnZ_A#*?8#6K| zUT~diApSDkxx1;U=~E%k%ysWtaj>n|F!$<3DWrYp$M5X1vPq^CtpIHH)e9>T_z$&o z3~YLNdF7uMIa#e%$6a!S5GqL+(ImZ~ z6tG&sM5EDIEOzW)hG9%5)8N2BFcADI4R-Xj*_)3lCjb1#tINUq&50d4d-m_#{B~!~ zqQ&DhppvI%Ri$QCePdTo@Qpzc4M-M?!VE@x07;<08ss{>zo~mYjQj1a*W?Pl^{z*^ zcJ6z(ZSq}4U|3Oz^tIW$_j<~W@k}}u+eaOb_v8%h!g=rNl+eZ+}fy9 z&YF7l^)-dg?Y=keY_iWR4yKu85@3b^i^J`E4!FI1<<+-beukp?^@jUf{g(Pb-Fd(O zWq`;i6Vh5rtIwT!VV0Z^u8sX_-GQb9tx#(Plsx&|5(T5v**kYH|LpI(n(v&Qid1P5 z#KlD90}UISoSjKCe{#)*HoAA&?!O)JWbJU*UR`~~H8miU2xYw8Th?!CBmRr(GOcPv zfC0h)2F!}AEVXLlnb$0ut{L=fx8L^ny@zu%yQ)h~h{IA!8gvfWJ9c%1N=k>uJa#v= z+FMsSwOJIjWc0d%3BHXSe~3_s2e~2!0p`4&_9G2%beVp$=tngs&K&G^bvyPU41n>F zstO)HY()Om$+NE$R1jr~it^bM0L7#j0uXp~LIXw~dt6Os2%bRh6mUgc_ z>@F~B^zyhAY833-Hur|RgM8-Lb@UP>`2T@m%FH%p-aHuqfKpfEYWdo*9G^8kFTCdY zmYB~v^_H7wSYs{PZNEEcZ`{{wnVXzjdj8D99Lk34KX`h>viJ6M;|0ld;K2R^jXqW8 zS=ZfIZ9Kh}NQk41wIn&xbF_JTYEh{rjZauu3I0cnwOTNCJ+9I4cs*iF)a&&e$5Bct zrIIB1f{}ek`=9%$&Fv4*tudzs-AOrw{&So;1lGH4v)Zg1= zcZC8GiDfyW&B#w;!}fs=drw!y$sgQvFq$$xMFz2udoZj{PuI#Qh#`-o&))Bf5Cj0~ zq;#Xvs1qoXB0bGLNRC1x^>{o0pfKko8x(5!SNnJqd@~?~04!CP-Cf1(UH$y(Rl9;= z3I-&g&bHoYxNXwx0#;(dT3VaZ%=Uk>FMz8FAeQfM?TbX)iq5(>3A1d8&Hw;Fh`>>^ z$*S^bvA~!y4@IQ_pa2Q0R4U#`^^8I$0k919xPraCyGky)Dj961Jew&m9{>PYY*K5r z3KK62Kl19l=MZoLz`|Tm2AXN)3dzV^U z08rT(GtEbv{6`MCpg=AI00yIQTYKBUhW4CA)6Nuh-k<<1*7^zMcWhE7gW17E=n;ZEqWN`vXylVOU*iVUn7Y zqp;sS*wNh|AqW_`KFMY?Yh?_e_)`$Y?1%O&dvjav?Q74OWGylQ05A*#=1Jvd002pn zNYL5V*&B#R6sSU>)FkIyloZpb%i#<d;vVen8}!5=+=l(l zmQ+J_ehQ1bqu=wgc1N`O3gKDl>$qnL9e~V zt}rUx{%|lD#Bncs;)9Hf2U^E&%>1>$v z+4p|>w=-VOy)F0c^_#YDZ`5RrpYYSSpI_9z=7GOF^U|s<5^xtT`}AiY{PF6EXC$|` zu72*i%OBs5qzFOfXWw$!FCM#dB1O=!{I@S}+quV)sd;Zz>XTb$_dT}GKj`PCC9V6# zKX(I6zV*39l^R|BA1`@)4*=v|^588$y5_c7CPK*GXD|8VD+gCLNsK9vz2M<(zhHL# z>F-Z3`E-i}%mp7jwD8dvf0mxSzv2C-JM!Lm>he^i_iS7L?7x2V$9E1%001*?edgvL zU9+$x0I>P_%l<7DbB7|mZ@s$_V`kiK@Bi`YiD#8+zxtPz;G2XZpomgQf)EQ)r;|p5 z#mUL>xF)^Ph)|L>2JXc&)!*R;5;v7gh;~d3i7q@KV zu8WH505BccwzH$x9=`tEnTKCF^ySZ!;9CpL$V^UFOx*SO!%NSwE*5ICRL3?k0~_9X z=+Q@>`1BCSDLwyzckjA%fy%S~}EKmtOVWJ(Gz_V3>~e8$RA} z9cRS^roABHSyr%=im8y$6$xJg5C1z-!J<8 z=3m3IyWVQ(KHP28Y}sA%*w%Yzb6Y-o_{oPJS#g*k0GNBvTmN_E`Df*x>eExCq@9@XbhuDkW6|17qdHMnQf%dh|I7r*%k0RTDU-urI2^8O3+ zkQ9O5cb~fL(Iubmld|)RuD(9?;ZO2@d-oX^&#sg8`;RWU_maP@Yxg>t!irhf|9!=e zYhc$qzkGgo(;<73ZbN~#m@=gN_P_o1x@#8X8@_s` z4M~|dJ^a_hz0FU5I_1el$s;#WO3}cICBJ;~+4nYehz!Qe!hdZ4*?DD?Y<>L)K7Mf8 zbGf(WzPD-HwrxjLX=N3+Eq(TKYqnWV0?ln}p1<+3f9?hdqe*jby7|6;F0T78d|C;< zw@~^OeOzPZaUFvYLI{y0DelM$MhU|(EX!hy2_f;cG>q{Vi-CyYu(bO>UFTkZ>*7b0 zNB3@9f5#Iq)}L`j&9835h8*ki{@g#`y|A<(-`2nD{iPo)*<1L}O}{H8`ta^8YYuJu z=O5lq|J4~5i9(B0Wig&{>$YE~rsZ_LD|Kz$8b2%^^Z-P z1l;iapFeEfwr<;@X$uM&JmI>R|9);b6tZ_7-TUf2|JiiWZzlZojvLGwmUjkn|9tmZ zd6`9-_5*u&5kde!gnb`8wdAu#%~}82^lS-$ea)Ni?AZ7sHvH_oSxI699bPjysq~!7 zH{JX*y65Ga-uQG&g{`2ZJUg+#_w5Ezz?6z24I>GN#DX~be&XS6YokqGP30vgBu@q$ z-TRi@c6j-@{!dg7w#k3cAU{sW6<)f7vu9h8#c@Vr3VjsqV)cKd5hP;}vi3ufLlIX8Yy=c>Q` z>+SU`y7a~=7q9r)r1EqPZKZVhKsrX$@z8aNvteh;p_b63b8Rwa%srz4kL!~cR;#Sz z^U`w+7(4&~gel0+U*&VQZrTggWfD7ZpxMh0a%E>GqZXV9Df~WwAT@vTH9vnd_njqo z{N`$sJmW{_Tz1340)n97?FUzO%Vzv^=^x7V0eW!h@_y&e1F>9i#h{}t^>4p_EW0$e zZFg(yBU^XeR$Z1xh4Y4KG#GiLo-M9}c| z-*<+0Z`m}}G@jr2;!mD%7hLi4tEX0}ItF(wxd;4e31QUHxp&J;ckL*-_qD6C4JPm2 zPW!;iZ}$|O6~VFgfFdK~>>scHeR7Uft2)(4V7DW%l4bxTu^*HXK{9MA9{b_n&-Bkm1bCXX0 z!%FbI2ca+T<3bQGr8*jdObGY`!C>&1cPox4iVVYW9LF$B+{!wpf*6a%0)c=a2pl_# zd=kc(rD+uv6?JvB)h3G|x~d-9-Zgk_d2PBa%a$gm=_NHqsi2J>*w__pb!E+5P+eyO zotS|geJ=a~C`q_8#dAlzElv32A9*X=!rED6Jiz3VO~Je}+*C z$lZ3dg$eKlXP#ACW2MMru^+sz-go5C0L)4Pg!Jk8Wz`d>))Y~c(Np%H&9VLgM?lI} zCEU;7YT`aFhCwXP#^~5{`nKJjdUeD$q4HQtp%m#oxOwv@OE&~BK4a#T+5)qTftXCG zE}nDtMb&P%+cmK9wdW4ax&EqZ6RU8vI3j_ris{#Du|96okZ91=xaHL+H#%~Y$Iq;( z$yPFbU$(j)0El7g+WlbzVKS#&TrgXdL>zd$q3L#+EF;e})a9^ePyNw>4m$3lA5~JI z*t6Bus&0^#7S=9$R41!SF)9d_w3d{rbFShXBpS5uUGc_X+nE=fQ=vz)%!#%0Y`Shw zINbQgzxLY~U0s(_Q+r10?h&l}PU z>gJs%N_qQsZEN1V`h_TW<+ZbuS`IeuT;GRv{p~yCBG5UI11AeLg|H_{(#u%kupOrj$a&2vrrqsLlz-s5-rgqQeh2;ent%W8h7Znv2rx1(@P@O3? zx2&eDx`c(nk6MokVs3uzyxLk5!2w}T8Tqk@`UP%b#+CR8a;$u zMgQ5=*B1#`6#AIU*Rt(}5B6cwzpr61#X8RA3n8&>o42&MvUc9gnp`HiS8<^5>2(4F z*z0w79oo2id+-BQt4R>Tc2`W;Upy^3I|@{%O(`g=DVtD{u(p0!U{AxIU`kY*IU|)j zR_AVXsb@_ZgXZPwCUu>Ft&81Z_%9{(aQzy-xUY(|rvRZTQYYrXkbirv^ zTFx9qC~Mw zYoSzjs+D`{3kHK0PMwr&280mkGIOoU6saz0|U2)Bg=T9B4b?o2x!Mb+riiNrkHQC)^)0}D>hcHG! zqRy_ShPCVV_ezSAb82d8D%0f*!)P=bZ!j8&NB}?x@p(LQxm+e2ZQw)#!2=&|Xcg7P zbFaDK=IbwAFdc2&xVz~<_i=riVDo3Y8++}#iI?7d^UXKka+bBHt7-q5PC=hP>4tME zv(0jh5vNZ}sk`W=n{K*k{y0nUz@hpz^>$1tRpw4PW8oD)zI^^gCAf9ND?5+$^e|}! z<7*esF4760QmG_K3IqZ}7YYP;!Yh@^_{(tnju@+w=T&6uNB7djJe_lNBwhQpJDGT5 zb7I@JZQD*~V%xTD+sFw)OS%{?_{XzwXt2R@FME`c&Qb-q-fsN8LMoX`ao~ z)XoNK#3%fgnxJVWvmA4;wX)gxns-AgW{IsRSxB+(wAD5INpZGx1U>-YQLp|#4?U}NMr zx0c95KPWjf#DWt6aLsGuCt8%nTELr~Ze1XRhYDGTX*7z$FspH~uQ zsRM{W{$H6|hhLD<^?jd5cQ(->dBGcL4yOf$*rjc9rZx^`n8+e4OLRe=!0Q9P6vk*X z1xBjstW4C6>!t0q&prS+K#t_kJ}hdqLOCloKnu)PcB1J+hXOl7>gRGS=wgOy20!r1 z999V+Fcy@`6Cy*6B7#?pV1n+bbBx!xz)|r+)PeRI|fJ z4BxpL#f~n*=4}5(0-$vqaKy)or~i$uDg&w<&mOyT;Y$=N7e3<#1;Y=S{)+O8$E$#o zV#9_D%@MAZ5Uq67Ih8ZUa`kz>()@-Y*uO`ajy{gp#s}&LKa|ImnrWx)gOlOjhf`Cb zglyFzixt6z@}O`%Z-sydh?Llcpo#=S8nyDI5&W~Uz8$`GVcP_i?j9v&zQ>5!7#Lpd zSHCQ55*LF9(Qjzf3Z5&gfxyMi$>Ha4(kW7GR5vy_-~MpaRd~$4ysiAWPsphMnkxjw z6D;35$BJ$rNx7fpO<&b>>3GhfS(dT>i6pI? z1Bis`m3)F=TaK9^GYz=*ag&hV?;C^*hZZ8(pb7Y`KH z3G!1|FT%o?rhrrKGyk2cbQLF@FLvn94ha&@Bm$LD*WpEP&S_=8T(HGO1nQf21hMy; zRN=jxoy^?FwoQ?ualk{eH@YBKGIH%As!v?51P7Q@lUXGg+eYV>PPxBZY#K``Y~80QnJ6i%zY(W=<`5O;qH2-$L$Cd(cU+T3Zm}AyoF30F zQW_6fWt_t~qd8d;Ob9Z3cqngQFJZ{3Jmo2-Kve#Psy??w7$xGpl#& z%9w&^WL!8hCt8s5BmZnnpF5JKq~S`P93AI&9YaJ4JIZM>qftaa{x&YepH2?gdB@Bn ziBf-d9sk&Iq@LQ=c;nFN)T-_pc01s8h@kVfahyNaY;c>ekSXQm*~DN|@K1*~*~Lth z+-+>xcWV+9$IkuD*kBVCpAwS#gH>u&6F44qan6{L7 zK)pQ@*qu{GsBkq{Vjy&?I2x`-^~?2~q{heJL#}5-zNho2FZ8#YO{6#8vnRK6 z=jv7-o4A_ICf;*L)IIJw=f49BipQE5RMR7i(u`yo;cC(9t+ao9jh=Q3zx(zGlnQ3> z7XJIbf{Y@9jaNQ96@&1@*ZaiAZK1`iGly`-sU)Q-H+LFSe!z}HY_l=WKL3K4e_J)r zd2V~MaHgikMcL&1fj0|Z@&aD@x@RqC{r1=6g*?IqmtDJi@55fWvSmGlTJ`eDAh!2a zt-1U(fnnu8*`O=ph!L^%&RPK(vZNBi%kav|Hc>Zg|HU68c*43Gd{~$!T|TY@{lFax zC=yhF{e{)j#adc&Dx{wL^mCoXVc7%WlelTg{*XE0sTorr(f<9$?=d;*!)X5(=T+KS zhd+A#c*JCqRHWR=Yj!|8{snls-+?@aAAgIRDo9G1+^6OP5ukFnA?w&@d$upGbDDze zf*^(p8gDz0acS92?mz4~blu$2M)w`8{;2BckR*@q!RiAF(wtKUX#!)j4MGyM=vH66f@+;ESJWoWB9 zP39N6H9tXm0m4ZQt5|OG2u))OnT7i^y(d-wx(WN7 z_J5b!5GA!8oYP|Ev9_m>(bZj1zyp|4RHeFzc>fVmTg=g~43uKF>X!YP7VFKgy| z?vpn!71pWKCO2KN>!`-zXa@J{$Iam@r4Ih_`Xl-`B z$5F0wJV2R>)vlC$T{1S?z`=bGyoIH*MwpL~Yj&<7X>79H2!e-1S$-V7-&xABqsW;G zy>?|yQAq-yaY@X_66`B_Z_94T9yW_^!4ZU>?`Kp0Zb&o zUVQOUiqnHq*Q0H})zkYw<#|?r(Ln>sUd!+pCMvm396R%58S=;YKGGiEe`cMlL>c{F zL_q75Q1_VG`Q-E1@n+n4&ZkV(Dr8pZ{}`^Win7RU$Nrnz|M76%oPUTSVYj_0{T=hm zRr#~gG?7?W@OU+!FZ=F_Tv5RBno1+N5bnH6|EHeF}>DX`XOV#)BIUx4);#l z4<;%_j0j;ki=`i4eV*g|Sn@BF$=Wuq;deI30S0v$K8y9UZ-?26+b`RKDy;G+?28l9 zy^yMMstdHB%p;E-{`hV8<8b3NQykSi3lPp;FFPaY6B*@a3I^{5w0&2mO)etQc5m{L zp>OhWtvOI%@TMLv2#)c6sK~Qbox*aqtu=nj?+pl3W-_M6Rr?rcsGlaX?DOK;eqW>2 zwO9GQ>=Tky@pX@Pl49o5tI0HJYRsIj>*N%nm(fiejA~iMVo%<`^Q1C8joHU~;%XW0LHdY=p8q}Mfz}CqLySGU*5@1aQ3jjS8!iAo@c`L@} znrAL7sPr1lHqil;st%Q2f(&uhmaVD9XwBujpMM4y{!W+zqs@}jUS#mo15z>nIZ)#^ z{gIB(mKhmUIxvQglgj@6fb+Ze764+h#uJT(Mnz31F-6n&fjm?#wJ5%w`R==6n#y1T znUUWnq~-@#`OsO3PU%WU9QZ4Ev$T@P+9qT>%(~kzi^F4b>%+z6W8HUYiy{+syPNaO zu^Jg$C$QnM3|&?Ito)LJ5E(R!uOmr01&1zFCS@hBck>`1BNt2xb#-2iCc0&51}tD# zt?L|i8OyPqj9o=0S+*=Ct>R#i6j(P&*SV5lFK`qKZoCPZZfK}%FUa6pI7!1eA-~wj z%BWp)nT%ZcJ0mIEFw;1h(4b3`oN*58kZ_h}x2bHpL+a_tX|>UPN&3XvlSZO)Cado+ zxT}HRMnS>Cu^f)3+3*bvRS*|l>Qs+v?Rc9OHi+WZH8rt@B|eq9e<3hMYkf2&Esj}x z>tO?@vT<8=OsA$Zoyq_hz)_`0HP3!94(z>G&Q(e^IardDIP94$%2bd64Ct^`TIrSP z(9bVLCSy&gyz!v~L8J-ekc~f%5ixTt+f$V4J!DMCA?(9eT|w zVKBQ)X44(!#0rYiZ+ZZzVLp=5MPPqe2J3@s9LOjlJ5JQz$pN)v^FXS)VJ z@obUMXuF1`MNW-%!e8F73c1F#nV!EqhY$b}Sks9~I{bW7Wk5is&vqvjxw%iYq8T7S znx0-!v8nWo(UWN>sZtJ=3P2K*#F;kReYg#;my@1OVH%(Up)%f*T_0yHU&&L@Gm_@~ z7*rj*X5XtIW5z;EnY~D3o|UsseN0<4BFX?V*o~y5YgZ7iG5sE2E9q&{PB)lBS9jt4 zh02tXI%Ur8DUF#44?isKT-OhFbq*r|n}(CrOerVBN(B?N)YN%=GHD{s^Ou>JZU2uf zq(<6I|II?p%4vc^UT&eu{8DyEgA8yPTm(jIP)`8(qbVaQ>w_dbq0d7`-#Si%T%5ED z_E^9X%`h>&n5)iK#!BKQ2y$IzyyhE@sBj*;!%U|%yRj@PqftQu&W;Tesf0SuSth*$PhWWpwnP|gaef#(mW_^|q^ zRM>jbcVm$H*B_b!ZUS?$B%nfGe33%G;&>r@6NWic)go?|jjAtbcsPo}^k`|4ki%v)lMW65 z2s5r&V7c7faG1n{uWqJghZphEoen)Niit`4q%vmWNXh5!Bhs!dU=bZjnIv4XolH{k zfROS(H*eBYDobsl0o!1$IzoYK(MQt~b~9t=?q4i?jA69!P{^KIgtT)$BW^f#qK zO(Q$$I;*R$<}G{_`d?P)PCL-h5GcsFuTGPy#{d&lphm+TCki88%-p|ob>p$=z&Y9o zs_O5L#Hxa*V>RgcM1!0#k@7k>oi~jQ2hdf3v6A?lG&$6<^@8#{y%gakk zORG3Uc5-&M(dBw3N$Bgctge}wnra;5E0DithX@sXqa~O>3$k!`6+aFL4Yoe?Qp)m> z@0a>2*^bB6^KkGBQ;`z9H3H=q7tHT`V4czj`^|IJ)wAqn*mLg;ch;-3bg;vMCfCx zBqI#p?WF_#-q-+Bm!^*}x#CH4#iE_s_2s&O`k!@aW9px$w#$;29!w$gWBgE4&A3^X zfUlQ^h6c#pCFwmnPb#_P&`u`p)VXQIq*c4Ju#nW#!xual(C4*$4YCA)F&$xRFqaSn z2Lv~onf-6ba7dDQrGIm`-Lw8yqE~@nB8}?B+Rt-o;>|466RPy%|1+i_Wi|Q{p~NJO zVi<0{?h&emBurZ@o;{fFPna}jP(^}dlt1;jO*^nP_rkdc+tEX`p;#ec0XYHXD{3{zU0F}^Z7|BuW1*!MTQI{Mm2`@bNc6t6wo*zf#S@%nUnLqE&}Hc^p~fXY}O7 zBNu+KLiySC?ogppMM;TRr5Xhd5#_UnFu8I}h!&0@%cDBDkPu2Fm<1TKRFw2Q(;j3< ze0&NvI6OMYi9Srv03HxV$AI#is=@Akx&k5tN1N8A0<#k)01PJ9ghmvixNs|y3MI@q zE>-~I#<%mCR%A>nI0`(GNG5Q2zz7flK8A|<|7URUD-5)zz+!oXMgO4-FvO28f~Ig` zp=j9#6yiJ*&j`9k!7}}h6X&|1>bJgwtbLuG+~VTmmDJRYRyClvt*z|1v7hY@6d*4w z94aHx6tjvF{`?w_vKY*8k+O0TD!|;lroc$c!3qnU2vjUEDpHG54#!6MK!F7_3c!X1 z!vus_F^K?zcCm?!ei!bO0SZv1_KaXEq_kjuQvHg^5G$1ugNuR}5ffoSG{FuCKrbw` zf+vfN#It4wNVr4?qB#JBNXRhJV2J@v*v=pSTkii`S%Y7|f7nn%E#EXc(5|1e8tQz%9*{$wvJbk`0q@>jLatb*(QY@BblMa5i zcXV$JW@MyfW!Wr8%_Bo?u5!#ByHm;0h;+up$VCLg2mz?T=upTazkw-Jd-y0@((S=@ zHi^s&WDZW@O~GNLGQ|xV8LE;=y@R1L(bytbNQA-~QN!U=c0%(yiV@5x$V18qiv*BM z`u7(z2BgT;C|Tg#2RZ(Vz#Q_+w=J-pLjuT{+9Vm&rV;K0s^C6$=lb%`fWo(0w`p{z;$R3qJB0(pHBu98=4s5a zNoA->=KE$i6p2uYVF1c>vN8&b)sR2Xs8Ji-Tf)pVnw5(+zf=0CCI-y18@Y$Mw#oIr zmgve|6Ntf&`h1IZ%O{gY{|+)-r`hc?=WH|bm7Jxp9CK|9G zyD#iNh~;1ss}WwwvX!}8E(ssIKZ5n$2+f(QIX7H*a&z9Arinttg0}}(>H(CpuTcPrSl4!Lc$NBr0;a>N(o)&6<7);_~~g%sIlnBRg(T|Tb- zzOF%9lXJ9g#NL;)&|&hUpiEVUt`B#`izfE~ks&c(Jk5`jI__l*jA&3jU>zY_2TB~; zf&feb=j8PHyfa_lYfErjuw#oJyeQ*p*RALM_pC!TuAv4GaK;|EuDeBvq}%qem>R#S zr~co|^~6v>-;>L6&&_?dEIq%csHv^2t*YwuRIsn{ovQS|YT(gTG?1&is;bIn<^B6- z2gT+k|4Vp~y>92}yzZW*!To9~EfO@iJ#U-f&xaOicJ(2(6@|LWj;~UJE&dDufJE7d zqu1$fPqwPM8Z?HjjV(?6=f)^B;wxYg%<^diNimn__*gd0?g!V2&fsG%@0aV=k~HV1 z>Dq2^-jB90h4vjEw=)bGS^SdeU@9j4J zd-f@Vw%L4hlkM+jp#9(ZZ7soS3cfw&{dijCJJB2>xUcbgui?$t?{e-B$M?r0+`Ru) z@5k|!m5Fq9dMBp9GtzuB9`5&8d97W@0}t=9XnWn}b|KbIA_ zxJ=sIgKp1a5BE>6u8<(!L7XR>)+RbUe+e2$i&KxqeRoBtVUZIr1`cpQ!X#v`0kC~z zadGj%i@#LuKuj5(TskV&fShi-X=Mvfv**e9D+qc;k9SQa5xA)GDo?jLzjAS9x7krc zd-myl{3oKIKGV%rVfI3Po%m&hVgFTaQ#WX`PM(PZ1=o*$Icf}3>qSPMw^!L2x?_UiYC=z+i!QcSo_#vf zh#+)osY{)WdF7s=M5mfW5*Jte&ByIKZ@$1yzz=3H`RlC^FQm)up2txC%1e*W3zA%; z`!-(Frnaq$D)ezhTZAkYmIk_>qxtb1y<$$k*fhx3_i4hfPtMs83O&DV!>jJq7#QLj zpdmCd0Y9_vM7jYGI^a1Te*JESQS%G-_&RB$J>u;yZ;dSpYV1W?_6Hgk1^D+ zwb=VMF%C?7dp$5Vl@0;7o{m2GIEHh8vN97rHV>2B@cSEgYnEHyd3sIFk5wvB=d_grv7>Q(~i8(2c{`TAEjcW`!x%@4#(x8sKbui@vj@lt{Au8TZJa+k`C!t1*#!gkH)`-bc@@*G~!B z%xdT=_`+v_tGgVEl(b3%fRg&&%I+&Ei9vhvQfr!M&jq-J5Dvl%(z#@3w{A z+Z;^xk=$~sLJ8~9+|NbI<`O?cmz|Hcw18Es1#M=DT$kxq;<5InrqOa>{5r$}UBmj& zsWa@N@k|f6)l3h1o{^aOSa-XE9qDSCtj}T@hJZ{|M>s2e%>DsPxht^D#Tzk`IoJwO3WQhEcAP$MBi?yu7IWq$#H8 z6WrMNvw!|FrKhwei`q)j2Tf#Y2n1e1WqBEx+vkdx!5w*g?7BrxTw5zdGK~Q?yqSBiyl1K&&(@4ht$ZVffQHBHm#*ZiCGI#^)I0PH>Nz+M_Jxds;jFixss$c>DQoi0^@%YyVIbY2; z8mrwvu-{EKby+Hw2v`ud0&i26JFDtRx*596qZuZ~88F9usCFBFb|t7nHV|79sm5~! z++TnDEU#L{)s;={U7l{WS2uF->SiJ*$y^H>yAWdGvd2e*mzrARz54n|C%N$0>utv( zlSn6VV%yt0_xBer9v0n|gXjSmqZ1^fCd@LG^Hx?sV6>P5V#vVQ@zsT`mZz4w+3CL% zcb?oJnR>=Nc52$qX6Lg$diii4hp()3jY!sV%q+XxhU#+j{gDp`fQYn;j^9y7eHH}6$^C$Ip9Y7#-g{y!AR zB01h^S2nH>9tp164Me7mfZ;m|{1ky!5xp{sBvdg8ai^w%XZRDiz)+*9$ul;x@XXsCDIL|L6BSR2U{_}vA((FhVL0Wl`)%<=^t8&eK!e!7jdg=L~+H z4YXt#$FJO>U)u>>HPlW~M95487ZxsHY>sEg_Gu%Z;BUyfWA#tTq<0lTy3I`~=|~EqmyjC+Na(C-zXHGv`jM#@KQ_ z{1;okyk0Lju335Z^lH|vm>60q=!sUAL$ATLZr%B}J#@W~JxOMvhi709$qu|>DRmhI_S$8Ce*$G=CmTXvR3PNHZU+@$wALz zZinYLm{E=84@PH3iv@J*-CvHXbeM}|SY}5Uv7Eea3>z*5y`3A3Py!P$X_|CYqV~G$ zIl`7oBfR+QUCooze~bkk8+N6<-vg60IC_~VhukJ~Xk>~P^b&X4+6t?cG_9o5nAPCk zbTzM1Zx@q!4=eMCIq&}##)fCFXW^rcz{}*b+2+uTM{o7oL$9_|eUGipb!*?4wxyFE zUM#Z&)t?}{9^3IZTbsiH08;`@oeW-LRauxorL(wNXdSN{qE$R+r;aiPQ%`FfovJtl zWy{Gd5DU8}L?xG)+;X9YgrEZv$bIhC9n9kAsHECmKqpR}&RpJ=3$a7n1MQVFsL=LW zMuO3Q6ribIB|qH|B)7M4N};2{9){N~X6)nSr7RN^2zPSL&Uef`YsCyXtKph zDZz^op=0{f`nD)KA!4d|RRE%WP`keFX{$P=&;$lXjBYJ984n3?0z{x>jg8gS;dI|1vkc4G^K%pn2@nC z#l(UG4S*jGn*Mi&05wbn35EWP5JwhpU*c7gOZY< zU)Y2W+wx<|`+h7fwwwE`ua|y5X%a39-V{(&6e98)s6M|&wT@phwD4|RlfE) zH_4I)PZsjIPTqrj0tYACZI88-f`2wWmZquLMlw&isd4F?FRKju?r$sw&i0YTnyTx2 zPpe!u*goda5}u*o2>STzsN0XK?z@sVK=l$R-0YRU=YN6%wvkZ6aA%8AvUOv9-hNf` ztBqel*wZE~PX?OAC(-gsAU3u24HtU1^F-^Yc1w~h3@I>iEdDf`+^ z_ie@I*2eY_i}LTJxXWsXq2$o>o}~-iULRpoC`+#Yss=Icfq3;qd4U(ezK?qLGsOEF zoU|Bf*TGQ%+TN>nOGCR%AzmGho||8SnuLfRMe`{wQJslR=bj_MXM}H0k8KJ-2M0^Z zZQtbEdz((Xb8qQu-ymdEu0Q`qB6z*M7=pcDq13^%OH{!CB2t!3ok*dTqiE6Ok(YIC zgAGe=CBeoetTx|qg5vSHPi?oGi+5h6-+oLzC)+r5+=P9{Qah;ZYwA^yN2~thYaj03 z|0O+KVrz4Mp0Jv(0%uYJyjpPo>OI=ey$}xjTfuonbN6s8pQH27xuwSc=G4CuSj)Y% zw*K>)s#@;X9i6NLHEq+x@4VnQ0pGiuaLuQm5n;_EjC_U@ih{DE`CT}$esf9_M%dza zxpBL$1hUHe*dYlW!64n6I7y-v+XNH*WE1=lvIt0}2ZQ8Xb@!JD1F3IQwd3ETrCaaU z^A029`rBC2MevEL-$OLsW!G*}kuy+N=j$rlmePE^-S_sjdiDp+*J#|+>eAKwbK@DD z^^oBYkLqkL>fMsMf|;t!r|ygVEoZ+t^30a2oz>pD?gK>-WZ3KUi*A~cztu(bqa*z6 z>+^ey+EIVtToP4P?jclOPO_ljp5zkWB81y z?W)7hs>eNgqz&xnG10&Ph-zjfm-MR<22y6|N3ldCvl2i;iCRsjRe^dRFwp00{yYZd z>*s)K(Fj2W4;UyacnkL5T;O%JI1Q1*!;1FE>aG8LE*I>te(oEYR@g{78&S9RKn9r9 zks|D6x&KPVpy)N0q7#4$3H#Tl`PrFGd}-Yr6-$S~Z;^%q!2lBgo3Jz(5F5)pe20HlJOTALR>Ptq@8QeyW-)WP1L#5|tACoQi~8zdUBh(c`>H z<3}qulh00Z-t&lQv9I-iuZl#Y)aWN#kD}Oe_j7pn1-SwF9q)qH@qT=0pS7g6uPTf! z`G(G>-e3KhU-BB`?VpdTK;*`IW`T|$V!++T5@ zsy@=nPTJA!qM@knKvS7gXEa_dyJjcB^R)BT&{<~9^96OYF z3UgM*hctRQ$y21m$2_p*$b^7~fQBYa8ga1dt>?L$iH?L1$ zY2OR5=j&u9{gR(kdb81P6lF0bTkv^ud2y!uGRd3J&v=}&T|JW>zd$3NnDY4jZN=|B zxpQ2;`s?%DPjb+F_HwiFp}BVQa+3Fcyo_^u`v5-o_HMDU>1Xm$-3`~<`UZ2zR^nwC zy-KLMCGQUf_yq6q{3~zkv&ReC)w<_tb#FoI?H!*1QRG{QlfdJ3n)?1PLEdfO`#{Jw z?|cu_V!^*fY~~ZGn*4pWpk?j-(eGb)5q^=a$(xJvwLa?LIi>FM!ML;8_kJVz4sUOj zK+=nfytLJ4xwYSZS<`dXs;O~V=YQPxHWNwrQm}{@L$Z0Kd0d|B{$*KxnUVkKxyU~F zgeF5x@uADn_UHl)>X|Dvmb3j?`dDbi%4ctVte4-Kz?n7BME4i$DmTnye>r!@;{dMR zPc0EV7FP>y?{fE!98C9Dv5~9aOgY!P1}7sTSSY{|wLFGyd@Tccj@vX(+ktx8Uyt?^ zt6#0J`_tWeLXOBrtCRepSX;041e1B5?^VC}k@_3V2eyV<>~vfGP8JKBx3^!$!(IvM z>G>@6?t|kMR@^{+Q3zxb7q)f`5mRc*n9F^YF$^&Of#bX3Ufp>sHW0m38szcY@92mO zMgHY6wg<}a_z^EzsC2zaRSlj&g{nz}xZ%kNiTU|_0b*H12-BCcVJX&T!0Yd&a*(Tt@98r$7H?zJB9 zRW&tj#GA&Js#|p7zXe@hJ%#ndYd}JPP1*Tp`VSA|hwzOo(Lp6fbu#5J^R>iP@u5Xk z88G*!r`INI+n@T}j4%M|@0N->{cH1EtFZ&%Fy{H%`t0^9eJWUmsul_u+v%RU3|Ijt z_x-I9Uxvb<{9};_P_mGP7GeO2@X7THIa~k{4UedR;vB|bt$G)aeWO4Ujdas_fK-NM zK)BXjcfGyV&FgK?6EH_#H^Ukk(72AjwMY4>(oBj>@b2+Y?u^;%b)0l;)1u~AB1)F? zxd-{;GzHEC$Os|%_UP*0`waQ8yl-=)$3==$z>iL};nDJBU!9%4EKJe88~tlSoQpX>2*Y;S_i~Su#W6hXs56;$m?v zHeaKEP1apH5OQ_B2RR$+d93nVrq5=%YrC#_Hi73kC#u$s!QArPcbVjkC^wrmXezzP+=;C6^SiZd-(?RF!!=oojzwN^Yq)Z&jzuyg%2RN>iH& z(o(4H_9GF6P|;G+r5+1B``O>EgYMq+->zqONBui~Z7vdQe$8iRr#W~W3LBX85YVI5 z2u@Scm+MGq@Klpb+AQ2OiQLU^XDZt9xOj6bcIonAYTA9ixQY!TeJO?K7|&iVdsC*- z(^XT;CLxTrNCzW^7hB)e#S${C-xGp4Hq2%^tvox^fZ2`WQiOhU>?jw+MKBp2&%=oy zJuKPs81Yn>$W~7%yjdg9{chR6br|765|Ny=uwb@~wUXgN(`V+RY@-XbRP<*20ZcQF z!3o>tN;8KAC?#cP>Tne<(KJAGb$f3O-`?)Qmg3jX3B86oQ`Y{Gf#!kMYREbLW(KML z@S?fwzrNPu?N95$n^-v)?UpTwgjZ z`+S9t9C@Unlq2lciaJ}x#WjRwlfKhpMG!upHx_K4{KVg0dA|vdM(QDsKz4hPTb90~ z1*j+#8^iihDe*`+ZdB-mnnrh7wcw_29J=s;sKlFt80{Tm%4XV_Klvt`uvu@EctoW5 zjzA^^8&@4+0T~rlzG8|syT9x`C4X^h7i2_>sAP80LJP&1WgIgWDRBU@Fj}=Tr7X7K z@?ZlfQ^=)6FgzH9oal`ub0;n*;}kK}Dp}|`gCXiSwNln96WE>Th!Ef^SC^Xk+^5S& zd7j#^rdK-z>$UucBs{T@!OZlesv~y>LUSieK`iJ9BUAt;waV4ASRLV%$QogwL=tu) z$pZCE`d@zpZ~!JTe1r*RBYgRiwXg(q?hX za6_^H3L?bxB@vhXdwL4r%biur<#QAAD6qcy3fQW22}b-X1V{;y!FYVwWD;3&!^4XU z0ZbFLa1p@*W)Z>-c+Pptoo?@0%TKxeL9WsskCJJl@e1q}k6Zk$&0Y0S6%c2GOL$}; z;3KwN$7>@y*fP~(8NOcR7A}^#*vte)(gtZWP@t{!_XC`iO%QHosq*kx+o4_Hx3Vr^8L>_#&^dHW_3kw~oyN2{8Y z{CiM%)RLec$lK*uW*Ad?7{@r7uWw;a4QQ}tXXnP}3D8nHi(!cyDrhPzEzMQ#J6ya7 zc3Li%2Rk3DBd9Os!#(|xA@=k4{$19+jc_Huz=`FrA~Ne1>i;6k(qfTC1~P7&qT}ns zjZ5b%R1a(fwiZ!oRfeRuaY&@8g2bd2PK1oWj5`Y!N^#!hNk9(*X_egaVd9fa0ZUG) z169AJ*dhe$-Qy!gkRfW5pkYMW{y}5VR=Vqj)#r0k4kt-w@Lk`6=0#m#&0R0a8g~_}v0NraLI<#v?^{$>5(}e~gs=K99~2x3Y^@r?D3N z#efS9g%D+?LEvyO=r?_UYJ5$ST^w+~PS*G0SCUy%qAQT%v_kg+W1`Zswc&BZPfI|L zl+oIoq|6s&R4hl;nxK-uJ-4fEf zl1fYk7>ppfneaz{;^RFzD9ey0Mo`Isis2{L)-s{DE!m3bESYp{c5trxYS)NQ?^VfF^PvbRa zoo$gT6%0THJwKwjvP=k5O)0O>MXMjjj@<(YTAd94KnxYo9=?&5rU@nq4wA=8L*TfI zT2LUi_Cf_=ypeIO*86~~XBT@#mBX&;+TZ{s=8=F@?~JhdN}K z@urE^`IRHb6CDu6LSc+;+yn(y8aMU_af6vw%=&#G3|?B1?}u`&GO|ae9({>L>Rm~C zB(b}9v!!FbDtkGFVuMcQ>P2iTZwWpr{Q0^qB^S9MJ+;C9^Vp|bLg_}5WIVm_SOTlx zV2mweHverS`>#9_(1cr5%V|Ge%GSHR+AuU>9+Ed2Kly*0DPH#r-y?tk*1`hxqN0rp zNhv92s_r#zZ{n#k<5aPo>Zw@zzQ(U}xA^4rZ-_B`I+jhPD>M5$>uSK5OUvd-m1<}6 z6u~}`F*r4Id5-$i6ZeNF$!7YYKnxii+6os9`SDFc{lsGIQW+M@=2G+7oPS;~y{q;O z355AcMZ+P;=NAoLQa&zno@4mVX2|dfsje! zGBn)|1E#<`DUMXGhF(7E@cuomNUYr!QOv}v2( zAA$b&i$(^6a9{DgcX9E>TzJ>K%@|ma;%rVSZhr++i#V*b?IBVFP~h}4oRZYFoC{)BOdOSmKINL?nk-pC-h;@2Zx+H z2}L-HD>Vg<40B{NYG}hWV#<^?u#+3-ZFQHIadB~=Ft6(6Amk{T4iX4wd<&O|W6!vK z?6Am@I3%cGkn0~Gk(`X;-+jKoKgxyC;o)lhuC%SI{4ts&Q{T}i%}9dnQqDu>5$8Da zWMS&zKu0QA@Vd*iD&n1+{n2i%ZU}5vzFFt0!Mc%C+^mFruG5GZ*2m-)^2=a}VAw>WZyRsJd4Y+cTk64L*d;!H5^{z*GU7%=^xb!p3Lq-NMaOvw-;^n(aud>Cg?ei0rq1?eCuw{7)fg_?!+*Sh}OB3yqO zy7w(TE7=i?WY_E2(^ZuOhg_T{I}D9vps|(FtfV_%^6O@Pot~A;ix)KF89sN0QDEVFkMj-I?#i0yP#Y?%n3qTTL4UYB=s?wjuEbS1iaHkO?{^jpno z@ORo|i?xvj$z>&}g)4erm~OCsX6AFSqLz+y9Do$?)PkRny4LObISCm?1$}e<0*br- z-`EybRu`HEukr~9NB-#h_SA009?wWGt#_WsXzK99*?Dr(S_UEjwDfC0sNo*+ZL9Xf zDW=~0!MX%LKk3sT6W@FJI1$L?6|D|4;V)ixXg3?kEp*bMhNBL)XbNI(ZH|j--M81c zUw8OW2%}Z^Ue0zw>a1QAq#4P#m<+sEH-=vq1R5BRno|lAO?1t5!LjE(Eo8~mGin)1 zhMnas+;(?GBWRL3aftekx^3%LSsnlp7-q5R#mGV>Lt9&2S`IQEg}5q+pJQoB$=p7U z6`un~rycl_?hfmV2^M+!eB`PS$J{_75qy@E8M;l^`?Gx zsjIBt_1-S)LTk_4+v{VdEicPuS7qcR5SV1G0GTau@hXdy#ZJ%nTU*Rjm z#QND!8mrLZaAahp4-O6a8IF92uS(d}$u+!P!-PN6x zl$4c~Wi%Q;efLq?jFlJbsP~RLrd`C)keojIs@uN)+uJG_ipZx~Vq~;2WcD@JKYPvJ z9(d>vP-smlJg->fHAF&LDXE5J>wEWJw(idtKl0CS#*e@BEKIrZYd1nobS{9mn? zGzI1Pm#x0+2M^CH^3V?snl!UXMm_*bf$;8bud}st|N7duE3baT&^jc7Ha0bX`sKIX z_p7U}z2p9S@BjVQYyYq}R-04&mxr#MmS8gj08rKoAheUFbkhPM!iKbQs)Qf@X34$x zKK+-=?y4I^4&zl1ZCWw6H0PuynM}Ru)}hB=edbRqXS5&$(z0Lv`OeF4Di~_sHd=ty zd7BTsc>m8{sgn_*WZDf6-1@cK&r1w*sBg_}_kDP|QoQmo-pxX#CDu z7hH4g5Pklix6Swk0A2Ba@85Od!kICEhzLwqce7ocXRv)53;a=#CEYUP`tMAY;x5WA zDA0iNihYT|36@ah2Yar(=_d>g$-qvzYSB&Kdi$bej8m?>_YUtvk3IZ@mH&*YpqBmg zr(Y{wb;kK>vnIY^9{c0RV!v6Y&&t7Ys_h;_)x0V9!aqIGdDYLJd-9k6CxhN>TlI(i z-&>kJ|MIIDc;UO>xqRt^Kq%p+UcKa&yVrcZbo^XoNjEL~$@=W%d%ykI1CQVBBnWd_ zY3jHC_G@8YQj*1Z;dlNtvU>G3U+?w07)SQ(i|>5;_j9a_7A6*EB*XzKEt(eC@!}sI z-?a4)m;G|*eJ4v|j43U-`nz8bKJvFe-(3ECgk_w4!~K80_^Nr?WaMK#?l}vlPY-;X zb7x)_r#~eE7G+gZ=~WlKf5+p`KXSn%N$TvyOXDQH=3IstIA=~p&EdM&@4e(j0rD=L zrE-@$fCU|=ng5;pF1qSBkN@zoAH-&5tpf;*kzr=EV`;s<^Rti1BUCyQn;Pyb9gi>Y9Q zq-(!-2q6;rSK(XM-DeCm!VeCeT-VwgBqAu9d*89S+?eNA3)uRrLQWqI}L z)fE*Lryd>|8EI^6Jbd`DTBS)yOfZ>@giv2l^2;1ygm|;sZsG|ce!suHy~F8rs#L&^^lEZ4ECw}?Nzm(xZW@gwG%(^C2{0dkceGW@BAXPS2`QqkxAD1K>vA4g zHgjr@U4;PvDEK{f?mkUhPdnmqM2>_>B-T(88yDgEzTO5Df=~!T8s1cpRje@_{l|~C zYqRDSUXn3YZ;5b}2PBR3b@dN*IfsDd5i9t-o|qUbII^bb2YEkRH`whQ8d2-aS*azQ zR%S6U7!V~GNU*-I->6Qp+h{Nx)-qgg$Iuk^AW3HxPMcbV-OeFrck4h9 z0624Ua=a~8Ers3A>H#i0#ir+^k-@&U&c5ghxY3^Ka5yX)go6W3Eu8~ikx;_(f+?*e z(Z~qm@PNzP;}`PM9RdS1INaag-`qU}0M?Yk#2B4U#ZXESa<|vHS(82{)^diuRrF|Q z%>XeNO|drPDbWcCAvEY}uXgh3DOQtK#Zo!!?`!STCMFuS0sxI3)ubmFO-A+UKAsBy zW5{8jYoN2C(?ux-%4lOOw)pILJpe#xq_?NH+c^{_2mn}9Qi|QEMxp*@k0B=|M#nM? zrj(LMps%%V5XHvE#>QLJlu{Y_opny45%ji1qd;Zk?`>%9ANGV~U|B9UZHmLBQbEu& z+~3^R9evtQYj+GvDGj>X+uHj^LWB~8FxJOsCC6F}8brdfZ}3D@w?8ZcAi-!)O-nVY z0Mkf+pVRM_jj0oC`uZAs`iEVjinpc|B%`6GAz95E>`A7m)nwS+*VEh8Hy9=u7*%{q zy4`A2u@px z7n5M%3HA2Yw>w?lAWs4$eB$Aoj+g!Uw(~BXnS*8Ich)zxkA#3wf;dg|0$nXGQDBXZ zWRsGL@+$+S6p7yU8kdk@GFyz}pMBXs)YsS7);EF>j!l~qZ_#LQczhN|f$Gh+n8eI@ z0|EdDyT>M17+KPD6O0zaC(t7ia&q=)F{qILZQHgr^!odAZaLU@ zX0Sj+rHLi3{Lo%sU}A|&lBAK5k%oqb*4DO2B%)HObUK}0uhVL^JkQIr91I5CZuiK@ zNH`oZn@#EI=~-D>f*^c~%TrMJk0S$wK-K~SKmjNa3|OXtP>2X>9R*!D@qYgJE~KPzC{Q`pj>oe&Kn9LEa>>2%FV5;Ei0zb9*01bWsYG$ z3IXB(F#tdi$db%)Oc+3b0Dw9ohb4kF91j45h=3>>U8*2Vhyg7R092xgML+@(iJ`n8 zfJA^5DF{kF0tE$ye>cI7BUNwRd*}1TtADfliWPZwB{YVDg2MkGpM%6z-|HXDx#hq_ z64%6jT<1{cvMg&hoAdMYRVr0mTbtYM4u?Y?x0~a*Xj)`Zl0;EN2;$=6($muu5)#yE z#pYGviwXmTh3NbN0U*Exh!_z$l?nhj05DpMue651P02`v$Q;&iSOY{25Mp_bNHS(e zXCD!nax%q|4|o-@te{eb0VIekS!@H~BmfBj%M=&@Rs{ew1d=REa)jd%U|C>z01W_O zM#V7@0pI~JCQ)4+q979*6}JEYv51HfIUJ%YBLM(lF(~4ef`Y=o2TCalyPFPdtmzGo zgkhw&t#wO({EE`FG?VGS-8TgV1%)px2+odEJIdJ-7X?Zu^W%!bFpSA$DlILIi;L@M z@963285kJw`Fyf03xZ%Y8Xb0fVp3vCO3G*Q-BM8ad^qzZKrExez~R%1s3;;7Q-nAI z2rz?K9)Lk;RLVio++LUgP5{gR00Y2}EnQH6s9i6@%qh(P#=x>HFo>KItY%Ex7X6Qj z);|8vaWKZfsSx@MrtS&~3JMc}s2B-5kG}W#3;TweT?8YmV7%rRcdnR~WL8#o6ciK` zCWFHG#PG}mlR4B*T>cCk4u{=tr(=wrd6G}pT?K{D141Z5fDkZ10T87CR0hC+SVjOi zW!V7%3j#$z5fA_w03jAL?5HkytQZ3T3D zDIjvHR5n^I1qzfhfDj;{c+?SdtVIf#!JG;K;OK=+_L3_oC@6eVFwYsXFZ}KL3kac< z0w9bq$8*XzMnOSA;T)jJR8|O0WK{@oZXMStrz>KW!v8E|*0W>(LqGu`is)I7^q7;@ z*k7Mat%Sx}IIDFyb!lVlAE&%}Ru=PHPaIC8kk2 z>TpR%+Zoj$pVgPs)nN40{fhXdprD|jprD}eUxA)&CDt$YYbJmnYakQPg#d(o+PrQ$?y%jR{X_Kv8rlC@3f>C@3iW zw?PQVL`o|NU={!nkw6N{EK4xU z0S6>10fi*YNx*OjSU^BTkR!kdfLIwoqQD`*qgpYb0EEaa5I{0QOc)qKfJ&5O5XWEu z07MaBKuD57k}1a!785|+Xn!S9#)5=_MZi)3AOM6SmH;pWfQY~-xq%fF6ciK`6cqkD z5DNHX$0|fXCygZ!0O4@Br>E!8p+h4hBkAdBNl8f-i$$Z+a2y8!q9_J~L9f?0G&I=R z+1c3G==b}lPoJ*W>lICx!WRoFQ4*kx1_4VzmPnYx7!U&#XhZ^b{MC?0Lz$VG85tQin++&x?DcNi-{JO$%d=w_OtY!gYK=zC zGHgd@XHQR0O-)U4aj{0D`L|t=g2HD;!UBo-1j!#_)dI&+N*IKJ0ALBLctQ~XP=pwX z0!INMpd4U5BLc%~001xm@lZz3gaE052LO-(tAL9TF^m}@ECXg>T)gnLssa(ue^F20{Tx zAixUw&2FTB&#JroFD6r5XPC4_Js7i)_ZC9$ooy{4unAt50yE{^AULI{$bM>qCq z@)HtLtvZ-g@g?~NT^%*+k91ON?(`{{+3^NEv7+ujiQn1W+SS$NPnt0=#XuP5T<&cO z|651^L`LrVDLtR4+mD_p*lgu+^Su?ZK9Rd?_yXvYc>pOZvh||QT=TDzoVDSOfjE2+j0LXRw zIt}UeSd-i{(!BSCF9AC{^;xC*tg?z&e;D+_K>dN*;kMoZ5HuNS3(^Y(L`5EnVMd3# zY7d@h!zt$C+%zKx#Lvj2rMjl`_=!%eNl4F|Q<$MO>rTJMk*<#B`aQM10AS9ZU6_%O zVm%qmh7jWIZEQY%sCEb_rH;&!wCwzJGawRaKeDx^(=`;3H5zTgvvb_LVd?J?rZah!vtZ(@Vu>H?wnMspq|_ymr_?- zZQF1UwUtdxg3g1LU6Ls_Ej!ntoAi`_i6lv(*1d<^HmhBm2;LLBPV^>~%+8OGx2R7o z78-2pYH6%&Lj`l^B&obT?Ja$SD0y0Wvi@@&jHtKQ*;cous*hN6W)x*-*tP$Ku~^{? z45gIz*X*nINT!%6rCDYK01)h{X>4q)>huC2U>sA*r(|SUHIXoJo>+IN&Fv5CW0T`^ z%BH7k0l?j~udb=BaZo}C$K=f|O1C*opJeq=4*LhYsy6NKNh&GHO-;9rzDI-%HyvyW z5W!wp6sJFT6$%Rf9?+z*3McgA0+`H?tFN!GqoYHX<>KOEtJN9}MHtQ6VYM={ENBHr z9D`D7GMVi5;E^Mh&CShPtu`hm1|fHZ9DVz~t?@s+U_sKn+{pwk5(&5MJ@n?^zx_;G zZ0XHE{+7|6U^IW?3;)CrLV_Nb*Cndr90s1^U~A)!t?zFN%*>x>QDc*07x|@NG+}q$ z2~V)$*|)0R{s_J`eacl1ft4d8gKt*7d+0B(z11NPXOw+yaqHsmfBn2z3?cxB`v<%B zHXii;-y!XWuh|=`-+ATz>W_AJ`8hm&_D^~))L*?U&R?~5+e5D$>pCfBRvFXv)q@ShDykyKqrrp0VG#{otFg z{q2o?wPszm>W=UKj$fHoVAMizaPLe0krRLX*3rDX?=vK3l$a%sKR*2GyBpRuzjf$n zkKUNQ_;>fO&YO{GVA-+9R1OE~Hf?$R^!-tr%7mw+$i+Vk2s zzqg(;evLuEl*h@7ew+IB*~!_l++>y=2-=RXd42n4vEa#q%ebRkU)kx+oW3~W(@R{k zEE7*p^@mSBF*0xF+|)&(BTudV(}yd6`q%GWa#4AbYJ5y4k%6l9@BQPcUu=l^-kT-Y zrqS|ekj0U|i;Mq#qNGYVfF zWGNIJ>1`W1{?cC`apHm{-z&*1LkIv|N8Vcd@|wr?gsd6{VA1N|Sj}l>Zn&fO!zcgr z!tve#moal@>4loCo2Kc&*S7ENx8Gj3wnk(@GA;e-cduW5eyKw>+5Ge@Bxazm^~0xb zx@Z0Q_x|LrYj0SPp;IxGQcN57J^5^nm|AxKlq>Ygin+q)!DN0}h?2>k=!w6h1N{Sj ze;_6%#%8mzEE}Dd#>~J{DvTRh`ibO-Z;yJKH{TH_NC22=KDti+@GbsV8)}NQTi^cSJN-Kw4qbfSQhPYe z2pr`Hn);4C^TAyYtikTBLzXM&fAgN-{zWA)dmb(STYpUONWsi$Q)gy>{g#Wf+#2@S z;pa9z`}^PJoc~9oS;c|KgKxm+-1Pi`;_qKmoY2tGPmNa`JNA&E68FCRy$|c&dc9@N z&3Q)WlYgyFS^3*-&rc24y!Ftm7pgMmsuBm7gMWYK(br$LFD~>arnrY=3Zom zi{eHLU>Hjf zd2+1n)VEj6TXg+5EAG5zrmAP~^{?NwYrWlS%(}*oF)uMw(z^C^bWGhlm^a=@1Z|zQ z2i|$AJ}6E3k3Sg-p9_q?+g1JgUAJ#2{PB@Y{12&JkQ2>Jg-8^}K$py(}XqVVZU9ZNW815ANIiW(yc%06=Y?b-}kP&L@=P z=;x_ol5xY%EgLs)rdK|E;Ky@_UDLez(Z6k6=gWTb_tz#;4X+G~UvYecjay#*-VJ|C zT$RwRU6Ob5TR%M9VxBVVo45Vxdldu$=6DWpZ)Z!*AMfRF-|)(ef}!SrzW?sC&%Cy% z2> zD0~bi6Ba1KpG?O!GBP5GqQznn1OXvLDJ6vXef|TD1KV~vJ%PydJl)(9t0;<*NF@5V zBuTNcF+Dv!!C>$cbeU2@3_O#Po~kxzD8qbSpLI$lNs|3Cr9delggA}^B?8=+3xp7m z`1#j;CrcID_}c!CSN#$I0bttNnpMN?Gm39f2^Lks@7WyWWisIIckfZL|!-mS4}V9u&l@4puwscRZpl3phF&45Q`S8e4;|eHBX< z?j5nCiTzO({+EzK-7N<;zWAE$>%U(zx1`Lb(eOy%g_+;@1{)j8kH&%dPqq&%&+{6M z#vGHLbHT+6U*6u|zM#7>#ccf7%X$R!=deHgm_*#p?&@8>(i?3yo0ajo05HaxF}SH~ zu&K>I%{prQL>o@DFhYA-+2SUo#SsZH9QR+avS6qf9gDM5d4q;vJ|am{I2=A#d@Y5q z5L#pEg3JE+;WSnM&L17;kUV}MjNiDEyb0MC6*# zk8ASsKA%q}ve9T{7={o+2$5yk7m|jY{%t3m!^2e2((-(rcnSz1i^bAV-w+Om&!~-q z;i0CM%}?wx&yTBVXld_us?G7q^KZVabfoRQ*FRXhWmk8g_R$}PR^E2W%+x&nNKf6N z7hm1nPcWe*E`N5};>#AMQUq;#Ua#!z?DU$n4Gp?Wzm@0R)8Gw?sw7kOx=sBAXUx5# zG)XOVY)-fr&ARP9f#bjX zLG|p5@0c5-9cn+m)91M9(o!>0``fDaZ(q0ZsFNT7$eep+MMXuaEey2v!^ie8R;Di; zI(DKS0L9P0?fmkz{5Zw_>5B+L2pGXsFw@91^d)Kr`LGnBgeAU#R;}9=EL@hUW<@zM zCtZ8UIlQx~TV8JCfrJLDydhO%)}lNX0Gne}5Q8WI2EY&uI%FEdsEh!D)f#3%FboWd zJl~sc$9gJ&j0gimZnf(Kl-)GjN;QW4O6{Ow0Ra-JDd=+;!y$Dz5(;~Iv|^tr#f*%`lcN;k z6JkxrJ;TF8ewpF=hq{wlTTC3+;XHKY4~L95oIfo$L9bFl^ch9nT|*Y$Z%WRQSr+S! zQH!ZzZ_w3SIX&+JgC?f`*rA%v^*u4SUs1-lwGqZ`Tj=L-L;gxmX@+js0uD!P42UZP3E0{}2AV@^*4078blt7~??e2B~8s(N&p z)21z&7ia7_{PJ^KT797~L6+o#lJjp}o-VU6aANDBre>0G#RVlMU}%4IGyd|GQ%s!) zo;%=HBV<7}oA)?ngZLoYwKrNtWz6J$=x zFI{=tqBKyC4U&{nLRz*ye;}kwOI|V~Uk?By)gQjGx3acw7^zh1!b@(CXvAE9YD5w;f)$d3$@L=D{D; zR9tcMlANMs#Xsh&46D|g6Q|BiA_p3b4Z{F1YE?DjcMsL<-q~=t|A+<0&Aavd^0d^E zfsw&Jb-^;DhF2rC&2CFd)>qcG1r|?9hz>cDh>$xnY!w)zTK|a!CWMe_%K60&yTy+6 zZy(KEU1B`-D5VsQ9NqB2j{QeETtE@RMHhc}PGLft$u-j2y5X^%vGZfAo4VS%`c$U4 z`1!Y8RjQBGv*33QHXL~Il}%kTM`&vHyz*rim8UDRoWeOFr>9aKXX1QZlNr!O#0aHS z5QM09OP1xRA}bIfE*A`V#h{l;k|fJAAtY*Zh!9e#RFOzTlBF|hlaSBVdt~FoPs)Mi zNDfE(>)o~0@3d!@q$arBexJ`5AR*0w%M*ym(x9{U;I{YQ+;IdMY=jLD^tr;$P<-M| z)01?)wHw~rab!@QGlLB#`bpRE4ewSpdf9p9MyGSwd7^2U)Fvlqv)%pu{j|Skf4gpw z#!ksBG6IDCZqIQ4U|%2*>8v`yF3p)891i;Ze!m=0^$)v;BOc-$t~|K?rH-77FU!*n z_w0Lb=eqrSn`E7tVZEK(!$vRB#Vt#WQ@0#`=7omLL^dfl($fwDwOjkrt;SW!aS7)L z4WjVh1tCDdV2mgQNtVMPiEa;-!a5_*V_<;8STD(g?$9t$0J*2}h}hd@EMIOK4P6KT zfUs}4`rx}q%;r*uA)6JXa46WbVaE=qHzd1=Vd|1!V&<(^6G@b znem5u4{d(($Yzhnop$T8JV*Q~qZBo!m50;<+0aO z%V%U|Bx}Gu7!7v;zCNEVt1zq3&Hw-e+7BPCZ*T4%3WbEc>u2V~8}vhaYYrcJ=5Wph zmz3%JLo6Gw*N@J$v^t$1$u94h5?c=U*0&6}yoOaXQiaJapv0iRqq>b#Ypq(d3cw8j zV9uVctFLE!b|39qnrf%4ud}+z@AO+PUXrp)b>;^|;eV3Qh$kR+xEa*v5y9FkBp2| zA2sCOX*8S0y27errYzG{uAx2J%8_ZyEffdp_tk~L>X<)Odl;$!Ajl3k@87*+eIS4N z#Zyc{_tCA}w{PE5)$Ro?066@SuEcW9BDcH&hCY2E8|R~H4{QW z8mRi%CC)=zAAT$xxB!z#pugE4s(zy_r#N+vMkDwd zD|dge{y?J(YcS&-JZ@I&r%p{zR~FM1CWq3=k{W-qd|Vh|1Sl#{5ke$Mib`CONQ7Y+ zmSr)7wjLY=!KMZf#nvP&JUdp~^nqVKG&yzAF1Z@&S{TJ_UC zS$}-ux+E~6V;`;Avgys?sZV_HtzzT|?tTB6H(q}0(RUZUbVCLP7!hL<6BmE;!HZ%M zInWNS-X2M!B`-exW9zZMeCHR>Z|E#hee-wE|0D(+PwC3umvw56#{sVoJ1)KOnj5Y_8sW*#>_7kg+C(sOb(^ z%P8tu|Ce99-1yPk+lsz@O)5~Pw?0y_bj}^WUMj$mKQ6rEP|bpZ_E|{<{Mi?+@WlWF z0E-X;pb{ZrBC-fmDWny6h*~x=dRZo(po;>4+|zJG>>Uy2d{0l1jH7~d&@)(FdFcJM z!=*pZ%1w#qz~>(hG_Qa3jeYIr6)Q@o-8m!Q=mugUgtT;bbRFNJn*S3cs3-sdN@)b# zz1=%Lc(qx3NnypDJVSrGhc$zmQ9%%c8cSM()*p@xBUz?|ktt#Ta1f9-6al1Rkt(sU zBH`c@Z*N(5bkJg5^|d$kT&y}8NgeDWWC%g8*F(= zCY_39C58+&w{Cg*ch5CMrrmh^irDjVgg}IlacF1tiSUX!0)%TCTJ-v&rE{lQ#_K@-U?AvjPME4!YxvQ<65=S6TU6$6 z2|8Xo9Hm=gP;W(P|Jz9*;+oq(~$Z4u`|xuqcYMEVC@j zaU8=i7$cTtIF1tpL8Ve*j7LUBG#X7bu;H1FF@k`LSFf6xpYDJ}M{NF-3u%Y1Px5(B z7X@9zZnq_1te86!nN&cmGYX0`mQC;I=m1HQ7?POe$SNxx9e5a$STtk)*KS(oU@2cz zQ4%xrqPXm`QVT)|N@q;BvKfA7?*I@&aOIP~{N~lA<>y~?>x1ti$#u?qMf$r3f>~Vr z)RJOA2$8sDi)W~(CJ%P^697PR{_+{+i)N-_wH{_Iny>chT;7q9kMSEQ{I?(gAX7pp zrI=w@l?r1lBF%_DM5F6s0;RI3V^s_u@l+^s4;o6)> zzkBTkQ*vX00oD+2U;4*&A8gtC-QvvQ1Lt3S>t+{tBavX;FpvYe zT7U6S6F=>{kL;}5y5_->{l#x?-+ie2q}?6v+xYyu#}9;-J+kl6frAHc!H=|Tf9Zqa z+@$mG-ShYBmS@`p287g#vb$g2yLa!=n^Di(f4KJhPrc(rlv3-`dw%-&5BC4#TYs>> zzkI>hf49D&Hg@sy8@}_=uUBPguv$LnG;8>98yD|Oo4+D~o*l!QLd&KXeth?eX%$N@ zx$t)}%P+s^!t=9YPB9luEm;_sn%B7I-L9~FXyY3)FK5hI5`XR%75=B7-XI+B?I5Bb zQT^15F8bM%yWacNO~x2IrU1Z#j#C%SD^H3sX^7h&aFc#!Rav>lW+upxpPE;4{gS$& zA=w>1*CT--y?p-io35H?<9QT+*@`(NGsfc_!VDD!a^lqo?zm}D`J7Acx$D*3AO7s} zrNxQ*5np%^^{URFRid_A2r}d+<(J=Z-m#$}*%z8Xjl+fpf}KZpA6r;jlvh@CGSwt4 zoRSeng}aaK!(tF0t{j}LHBMiY_pxqE&f<&ptiFEJwvLGR;2Te>GvX7cPqE=MEom7N zVS5i8txMNi%2zBloYpJQvBH#j)05&YYV7g&N91mP#jFx_j1?h6eq!GAYtOIoy2PN$ zVIA5Zc>53Edb5AXF9SfdaF1|ad5J#8ia?*2lvf@t>T2HfkC*@S+n3YVeD9LtIT_kd-y}*apFQQg8;yT{Vc)=rZ?t|fz;<-@g=fd+ zC1s}r6^u0Tn#-1q*oDA=i(#l1qq3V<&M3-=rMBegMAYw;J?$Q^tMNd~+CN@Yx_EZk zv}^wF-luld_V#}IzA1b)n8c53LaV~bbzCN+X=rG8XlOVP2ofSkbzGt-N|MAd49{bZ z;~0j;7$JnBO0aM^JUBRHHk;LI^~99|uq;b>kPwG4WqJYN4(P+goCr7)A5MmgHVL;*#D`6fJiBgd&)5I?@6aZvGDW!l}hGQ6m*(&15 zh(F{H1=LziptlW(RG68|0zU9soxkYHtn#c(*$+qne{aJFuXOe4)OWo6qqMlI zoGd`tPt++{$*vQTuGXGlRt^af-0#<`^%_n9K)@gXh5?b2{W2y}(A)RkuOa?cT}Ezl zEW*LG8Rat{YwyYI9GshKk6xea_`x7+Q)T3(>Qoq`qJoO|YDi0M>kY*j+?cuuA!N+>Qi2&FAD~P!NSE!tgct#~5>nMn|aVtz%=R zFZ=rMau*!yuKMNbE8Fug``Lxlb(m5B7%vyoFd0r5N zXt4O<;USydrqzCiMGJ#gulA{eHOJ~9D1z*3YH#x#Ybh+sp}h9fgfAlzKj}WSeORkb zDVsSnw=hxb8)R|hoUy7*W{aj>9PVgq14=2lDvvjE{hq|M)K7Ow3jb|n0Pq485ylJw z4uG-5$LTrO`q%me-ZgZrdH+aw*fKj)6K>zSOODfU2?c5$LVAKh?Aux0)i5g;*VN9yuOn`}F4Gm@o@C2yDPvceJ(pBc>?3 zFn2~#jz)zE0Mf>4vS-1LEqFk12Lpo8_V-u%a#CWm?E(M`gispdkcG;W1yErWh|lYA z^S&V$0$>7tE^ohqXiuH|saWuOynVxNH$s$xd#FzgdO2U0^Uyo@{e4qar_VFgKkV#j zp+G5M4WqJ3}JG#!u`|&roel+?1jj3+Bw7J$p`myhVM+;7VCXVp8JV zT<Nh+_qfhIr5B8Xj;iI#hDOojMbz8d z-`%m}*!1KyPOsN%EMe9>Ff>F6A<)s@G2DNG8Oy#+oWsuUx^6Eb5#p*k(P9rmTvCz* z06^ByL?8LRf{o3SkS8Updm+3ZD?;*X)Ohr^K|Oki1sF~*jRtfbEHNZqkxp2_YU60|xsYaoYe+d^&+qTXI-SNry()6x=E zI9$;yH8X%&~j=`};eBqE5|PB1fZz!PnQ{-Ld`XwA2JaV?5{ECp+u6e)RU^ zZyy+tf@15AmtNoS*3J{d!C;`~{rjI2HR^X9 zZ1sgaq`$GH>*&GolA?Itd1!M-utl3Yw`5vjf`;cms{uJt$C^@0?pT&t_s+WAH8rgW zD5JtwtAT6k@9*#F2NDU;{ylrD(nKL9VRHLLS+Ccr7#(=~P<~O_jCu3s&7EFYoMM=) zyn+HmW3)_iWFkMVlYgIy-EQye>uYXqZfk2xNJzjKOOhl>5~Wnb8Qq&3PI0mT1cDM9YOg)9f6J~W`xPgIbq(r3AY!v8=xnhwwF$T6)YY7L zXRX?zZa&uMzC0(@mSf|i-Ib&ek1Zfm761@R%1kcWF+8yMz2^pOCbjcuE1p_rC`dSI z;G|BUl~!9h)cD~`FV&j>8jgwDgv7Fh$Vly$hh9r9DbGzd4s^9NZ0{A#2q9=~Xw$Ry zsU@S%Sm&RKbJsUdc1nQb7{u;?& z#Goy{D5o@8O(~_gyR}Ls&R}d7`P0SuCYZOxrx(tg7I@{=j62hl(qr_*|4A}SD14zo z$ZSn1Sa{{kqc0rTxz5{LWwns7Kh)&P%FBt!JRdbmz^=K z(9S^L#JwUKn=L(g-aP5ZyKC0gX=2cTv&%i0e)WY}stIi$5T{XF^UuG`@n-$*4KH;K zq!~GmPnotNJ5F!5=h_oG6Z+p;4~ZAX#pT$~m_C|}CS!KlP))0MT8uTpcJhEsbV(Tn zY1w%rYjzY~nj3Gk2)OI)rX|El`YE&Kr}rFc-}k~Z{D~L5&iKdaJ=4hx_`wJwqAST$XAy$SqZSnvS;)h$0d+sdlSTZ;mw!>GPIJXB56P)#%VT zn@_uPv);@KLd~J~-e8JmES}oea$wK4_uU1{F3K}?*1WU1+fr0kk&{ZAcR%~4+LUU{ z%t@K#Nl^H*5?y+0Idr(OY0wpN$%6-LVb;|6jI^W}m6(0KWz)8g-l?+=2OC^&O~rYI zChpL|hE{Jc%j_|X>;V7(LrQU8W@@J6Q!dkEjJ2lBl1o?T?)lm7K+q{;U{%yuJbTF- z`#blpf6><+6Tw6E&HRG7>Dd_;BsEW5k4hDnoReIfd*uD+o=>hdoAd%UBv?}mmreQD zsbv+udQ28J0|1>ZaYaKaOaG+M$?jnR>rYSl6t0<6q&YD09BWm%mm z#+V_S1mF+>){#4B)#V@^x$oDH5gbPGr59a)<2NoXq!fWlA0KNWmeDjRm^UQYEb_TF zV}r3;V+_u`;EIe7p5L*1a;l$Lm)ck_JHBbL$|HA*X8xriM7<)?C z$Wx5d7hHL5guMFjV-Nm@Qj9as|MvHnTrww}L?|&CGwdW*tz!u*v8QgrrxFMiJ`Y$x zC`GV(4TT=#uuSX>=nBh9)u8#toj=?8x;!%P(%=1N^~G7V`Oxu?@)A}j#C5Ch5OVz2)=&iz}Cmx-ftcZVN;?xb;{*eU73H$lJjmu&5u0z$dBrhEi*D6z3YzL z47(ZtfU+SB#%}XKXm-=%j02|G}@<0KkIpy?D{0X;Vx9au{Sk zg;bM1F5WOvyaA#!C&e*#t?KjyvIKFAptI&CnDr`wp-7vcExGcp1;~DW)|6x&L6PWD zi$N`XJOeF-FEYG6Cv(+3PsBfQ`=8%??Aa~=Q0dIsH~)S5)T~t9V1q8!mXWMia{>my zw&a2px7-t~`OZ_%eB=#MM^43x)jz+s%m6ADvZj`IwKYBZ_-|?f*qQUPx%g#?u?C)S zNM=Z)LGJCZfA#)n8v$VMUDr*YSC)ia0c?y*kJA~o0(06Jhp{CwZ`ta519jhh=9%?w zk;bHzpMUEwuA62Am8>yXY_UlZqd-}zGbK7mOpKOMV{OLV@7>$}?LVw}W$pVisP&d5 zKc2VRpf|^)*y59y#~=K;_KEc5_%ze$7taU=i> zTvkf?#ot&Ko4PD1*~Wpa9zUw0DucylOAf>^h{wh$SKU11d-}PD|Mu$-003rv?Xl~P z8A;lhnDiv8mJu*uY>CTRa?6hcHQ)K?Ya0grvMpuWiras6V`(g?8xFkj?%RKP=NLwe z1k1j?D!CvhBPpP}<;U(b3YXbHEvwbBW?Qn_I%@Tqnw}G%lhXair+>F&*-sN}G3r>e zEm<(~gdtjEf<0o^8!(SJO>A0{VAQH6OF*OWB?I$1M~tjD@|Xa{7_}dH_oX-A*eGzxTwG`*4^bHf>(P1$QeF zm%_Q3EFTvt{rj21m81Qw!pH%y&m+n5>eZ_&Dk@Gr>i7HG+S+#Q+C^lVlA00|V?_uP zLO6~SctKDJJkLpzx%W^!2F`|@;5fK2f9Q%nj5rSxfW&ngS zMgT0wjdm##k!6`-SdQZ;CF9+olt_{!M#N|zIG$r!Hfn(x4uu(pWmx8n&Cg_xtni^?v^gNzpOYn%P24m1w=uDNQ6eH zh(JVu5nzllVGxxmktxNL#gqjmg4l?_G(K?m;oOjM&0|3aBh(wlTi6Ih07{W1xW7WW* z)6`1Q{0-3v&J4ryJdY5_vMfu4<2i&tmgGnzLV*GR$MG!7VvM4%RJ~(#q)ouB-7zP& ztqCViCbl)PZQJI=wr$(C&53RM>*qb^ylZ{+qyO~kUbX7(ySuvfzV^B_C$^}k9BA!YffW}%V1`S!xcHwn*WbOF0#m47jv8nzmw8XH~ zkLAtEkMw7blK4$pl-W!ylq{rguEp&_2>|G=2c|ihLg{dco$oh@g>Z6;3g0*ZnAV*(@$}!;41`V97QSQkaiym(F#w^#;!S$LCrL-U;_TvA~~n z@e${{YZ&>8B_Qn6U^-J>R(5%Ea&mRWmL_e|Fs8={kk8pUfAj#}RNC~I|5aI*0r4M| ziX`j|I#Jaz@Fb)yBP`J>?3hx2*{wk=$4v=O_#mVa`;sf{of)`~k_|L)0i+;i8Y8Tu z2O`2rw}O3r$mwo6nx-?n3|L)$Bw)fW42`Tjh#zk|qTeA$GVa6yT=U|~kn0v<^i<>$ z3_LDffFDFQ1Ob+xb_CN8wG6)C1;<8H*`lgs3%V(*d^UaM}$qUQP?LsC=1Q)>Y#(95Kt< zi2Gg0Y}xfFHdsV13OL7S+|#m)vvbvT&uzb=cfC6add#qixUSD}=DY5OjXmm=_5HrA zIT|tK?W7xOi8IW7i7YbGh@)v&=gaD^B!o{NbEj7F8{Cnk1(ZNOA zvJu$eTFhFIQit67Tae)(HmhNza(M&c1hZHUbGd=KO38wE@)fmL5fPf6;6^`;A$tB8 zsRaNqtX8s6R8&;9bk^M5?C%fKvvcecGg~K`ZwXMTAgBIsj9E1K47*AI!KqN9(xA$G zId3j7J=yU$_9rnQP4ySL2u<%`u$|rYnooQ~S6f?KXV7xw{|~#BKtg#yn~F@BVDh~=LO8dKBW%V}? z>WS*eOf$K!_Ic{lsYluWWhQfPlmq(!e&Mu4zj5es75D+*Ai~C!xdrwx!w;aTyK`n= zTrfzW1R#D925Bg1~8ks2j@t#?=sl@1OULGTMP}qmYvRes%skkOI zSwr9zKvhG}mn+>z0mGk0^)(UaGmRVSt;>7D!e~2Mkcf5Qq31}MV572NxTs|l! zC;&|vnuy~P5%`Nm6pi#6 zjE}&jcrx$x>HodXUP-Y6pedt}ena~G@)00d0Izf>)@f>W6DEKdXI;}0ls*6+fJPjt zrY9dO>haMh?!+)^SfcQYMob186p))39ihoD*NnkRiTC-e78bNnNr2wHCtcp~7Wvvr zRrD1{p}Ql>8rrB*C0dXtK+_fy!mZ;3y;IVj+91Ndqo;bD+|y#>ZD^rkl^+hm314_P zF!Bs5f{so8S|*yCD0rUSlEES^eI!y;mvbX2CrARq<#kY$ViCDuf`Kk4!Rm9Cj@I4z zfWPIL>uj0ucGrjV zWVH?S$3&|j1NKaJYMnexd@^ZRR$cyOQ9d~Z{1nDdBOj8g(N2{dX#k2vd<*Tnx5JJ3 znTdkkT{as(ZI|RF%Zl_QfbZO|MGD~GSaxkD*wS7om`}rZRMpinsl$D}b^LzPUuEht zTCT+NWLc1VZ+30|6OGwjxp=_{Q=&s?pUnaM<88@}1L$SCZ#OCrNV9&#iT_4@e}~RT|Q*GsO4^VU9oXKVmbXU zOB-qjDDXIXH3j$4=7}8pS}Q2DPeuA61>{;!ELhTHyk!D;I3%kK*H`5QM^wCWdA*ZC zD7jAMluoz4$-TC=Wu*<+hZZNiualy!yi-hV_3V_B*-vgCkKk{bdfI}xg6p2HQ@sT} zameJ|!NE4w9Cky=a*>xA5%2e19_L{2j)n5)6Dri`|pYtwcD7OUems{NjiB6it3q89{KbqE3wrYt;*>4;D zX=Z&|&u;viM%EzMwY2lkFE@3aJOBRdbWje5!7{1m82AQ(JU@%MdOsfKqPE{onkd0E z9sGjwB@O--$X{qyZTazH&@ip3oCysNn9U~je7^Gb)Wsc^-rK}Yk)9ZJgeGHzuhRT# zZ8qsWWGzlUn9*=I4@U+7`Httyjh0I{;iIkkMBiOwxZ=bjP`zE ze*z#T3Igx2jJ|erZEzb|x_YuRHPu$qG)2@u;eX84rew4)<{)cs{`1)ADcmx$wRU|D zEj!jxG25pYiTq!i>KS`yms0yLiVzuL>k(Y;j&{G;-C_Y01oL0_ z+m^(g3-<@$&mkHb=oXje9jsiHR{BoKdTn=9G8A*JkYT9DeBEdA|jI7xO$%7cGL4A$;qvR^@%0?Vvt#E z*xH)fqKoRv;$vSGh zQ_Zklh;AT*kks%xI$?WJErjCM-Ph!6oB=scv+C&-yjx1#t#YtIYyEk&|B`eYYc!vVlSsxa?*fJxVw%~76)2+ zqJ=|Z%7~04rY|lMj5w`kZ`!f8#7&iQP1zY%S+(AYjV4~XIOKv1)2g2nl* z&i$KzWP5}+YKfYSRFfvD%JLSqwlDu|C@TUd&1k&P^i_LGqfvPIB}gr@=zQ_n({=I3 zwIdSUOqwL+%%WU_?PBa}Z23B|z6tmHI(S?=gEy7i)R|rcns{w(e$FvBzH8q!m}&B8 z`T(M#+hqljnY8!fYrnsw1A$yQIsF)mHf@F1(;b-=9MSjTW4R>Teg9;o!IY#A-cR^? zR2&$yw<*<~5l47Tsnc;;kEugDjD_!gzm17#v(ss6ev7`$Q`19VqUAH8-Ew4!`}A#o zn1et|Uq5K*IdCOY^YIuQ1n~+|%M1>P#VdaJhilnB36x^T0`DC{UHKYM{0Al^fei0N z&>TC0g!4PQt5bWi*YP!9>!SU^?q7l{p43)fi(U8q2_lYMnJl*R^A(>0teal$n6I7P zGeowW*1eFmcn19;o}IR36kD_Nwfnvm2Jbo>`%Jp6SY8(bSi-GV%Ti{R>%Np4YX5P{ z>KDx!|CfCT_R997FU)EX08tP;!A|RSmuYrPPa$oe0jDv&l)1(0coN)Iw@LK!+BdMD z+r#oWn`2|K(}=)cjb7Xt|LQ8cyT|t|*t|eVl7zjbS;ePzy9h-FM_pa=BPUdmrj3gm zq3dp?r!ndCBDAG4m1}75rL&vV*EfI=Mr96|fS19F?zZ zXCxWRN=ZlcedlZUL$C547ZXmsMtbx6l$5*{q@2T6zl)CLo6o-IB?lg`tR$mO{r$zv zd^{9|FitgVSK02fvQ3;dJRLBY4u`3u+Iqv>{7LNrXPpG~bj2N{`gs-XNmDA~?X-2h z^L66wy4yg$QWhtw;NsoXN49rav;MhQlOvaEi|{X?PL2gu+2=){%Bt;OUrNexxEO)@ zt+=6aJzb!Y3!(R&{r9};ce_{e;`@4fi>{mHR1sz+#?9zx7*oMsb%)Q_l;RJNe|i@` z8T|*AR(${fqIkSGl1@F9aD-;;6tZhu>+H6M=G9C>ewqTkTnoWksUb5KadJhyFxrIL zNn$`G6+h!T1_U4$X%z5l6bA_;xL}V!2qvh@4@=JtmIwqIDXDoDn@0hXGFSmAT^cXP z%>Qivv=y2-Z<`1CTVXmsh2yiS1uvV)^EijVa> zviLi4n(5r1-C%!kNyW9QTaFL$MFDs*t)W+mK9JXcDp6!5#Jj=x+TD3VmcnF?sC8G@gY@LL_0}M>^o1ioWUe8`VtTSA$HB#8Jx;l08AwO(z zCVR+0VjWTNTksUjqhYdDY+5sQF~wg;ZeDMahRVtnvPA@1p=N z3K$JyQcmokZwq#`Za;a^S|i%-FG67NMUQ0)CRxl?AsRlXe3l*-%_Ox^BQ5)9Jgz%( zr;Jz!Nw&D$ZhzUBM<_iVr--h~^71wUF^n*Uf^9Q-iMf|QFM4ME35qgL)QtEHZ2xpE z{0tnCByGP%Qf$KkjiuSkOK1jplJXCDIOtkhf2?8vd?*N(AZHc;4-uI9(zh`+ARlWF z2APb6;0LCHhYijsQZkZ?ZX}brK?w?Y^kc*0U1MS~;V~LE0_PfoGz=oUV7tIfrUTpm?gNeAKyMar}eD-h|V8nOST8 z$b~W*{%VzOcsn)mD}tG-kwq&xk^a#+Q=Da*eU)}_Ys+mfiJNeH3|PaS_`AbwjMcZ3 z4Rh@A{QGV${LQ3AyWu@{|2-xNzM7NZ>Kt`p6?kS10SJfdahV%GOp#TVC_EeL*dCEe zk=2aXzpC)M+&JH7h}ltCQ`=ZAuQN8%{hA=8Z|0B&b>refta{%9t7!t|IHHr}$FYQx zeLrBnn!zU>)rY;d?~|;#1~iv5ASmBVOpC!9m7yaTz(pqB_7o^D@Nu z-_fTPe`pyeSHpC9Iuh*M+__({xmVmnX&M9-*nC zjmsyqkL{P27d=Ynr*?p7hM08}0nTarNB(t%`U0m9m~2(D0!P3|iizS;w&}@@2%AlX zwu3P}7@)eGv??&`ZYgCFy7Kxvh_AjM6Z!1))b@HumCtmJrGhT`@A@5aklTL&I9Wg5 zpSpa%DOhkXYr?5@>i*qLFdN{s@V)$9sp#B}g@4*i`)l(#)fD_^s`<*pSm{wA{wb@5 zp>6`+CdQ`N$M-QmH678X+kI4=NX7Z4$W;?0UKMBoy+5Mmwx$K1@9ZtYqcg!MNfI;u zvswH2$DqS^bQ@$;d-#X8{gHh|2IL33Ms`s?ytD0xLly%Y_w)GQpOt8H{yg6wpBtJn z1g8ZWRW{RE&)l+|RO$7!jw-tGZ~%T>UN@U({-jjr>#7FpIU+N~QJ#a}Zu0aUOvKy2 z%58=_DNf@LFE%bgK6j6>;TDjIxN3bhc`%tWTgW(_tQY{|(hJ$DEvf|YMZV9taQH-w z)x$q(s=V);Vl)^5(mhX@m~_*!7dzi?3~YAHtz9z7nL}_ktrP>xoj^I=>(FlkH@+`U z{nz^w-!@CInVai=$jY|&`J?j`mB&@^#L;x5{p$wX*C{4L3}&|LM&OEc)%NW_-S5}C zWiYUOYv+YJ+?q)4JN>0(Feu1D8TO{m&KK^U_9N*Uso)wkXyRmJ>?#EjaCA7JKAoG0 z@YIOQf}mN6O-z(3CnCt9>a5tD+Qle^8o}pk*Xm=*?the=q_>AZ6 zGqS^?xURg@<8D8e>9imrMvaq|B+JM!6t;^EPaH19fd>zrc9_<59WvXykRj#E!lz?` zY!DVXh(t~#S#NpIm!sKZ?AfIo4_eQ1{dBBK&y*zC<5syJ!{^4jKb}9ZwB{LBBh|YDud?PhGirr`jK}ZLJxHDi2>^g;k0!*nBK(6+U!Pgdgy0e4$<8;Qt*Db8AJ@N7 zyR%>6_4%5mEu^0vmEkawv|ylyK}=-STF_Gc0MC`3;7p11Kt~n-?SygV{UCgkbagKHTOFk@%UR1)53QnXZS109m z?Y^(@Y(Dk)xc!NNfpL5@5a{i!`BRA9b6i9;`F*1UvFmvz%UjKGsW4Gn=T9yeB$8Wn zSA&hMwy`SK2I^J2y*`k?Jvl!;HCxjiY6Cd+5e=&q;VA3e1|apt-K_5AfOj{yzg1Vu z4+nr2@KZX*#0l}v%vAx;1++5hbYg(4TyAsH+2ALmo0;oK(i(M;Jv+g50#sq)>ua56 z;^QL&gxZ}5G_w`$bfiA~ZhYefMMa0uyQD;lAtD7C7JLzEJY6F#R=CUM zrZY6^%~T7@O}^L5T^iaN2Gy5|*|B+f{$Nni>!|d#n$~A|+r`=$gx+}zzr8K;mIbrG z2EgV*BI3owBqV`Qi>|S@Z}~JH2C08`f$i_^YM9+b&YuxY0lDL{%jX@Wn(rPJF|NAt z832IyNXwJ+dEuhEhGJK59t?qp_Z|IU1eLk^EGET zd^Q;{8S#f#-q-B1V1^ZUqU6Y&cJb8V$Fj1qH#)Ho<5rFJ~CY zK-!7Bk5#?$`A~&bp{8Z$w(xZ?%Lb4V56UL$OYHufF662XH$eZgRLF|x z3+veC>69x#a4_K+PR-jbtrP*eZo`mS)1<4vFm^@-ntG%i=Rv@MSqEti%n$Ef+tDG> zf0VD04aby=CkMTpyhgXY49tdmkxi!$J^lhuFwLUIl#WZrvIr2FXXQDyG`;PDrdUYg zkeikV4_+~SeHGwIpq_SX3nN(3wQd3{7VNX?-c6IhSbseB1-vMMcbR3%wG>%>4Z*3b zuOr%e8E#c+W@H^355cptvR&4!OuHXspEn?Hyllc*%QQ{)+%5lkiReT4v-E5!n!0$8 zYPQH4hqQNYX~EIxeGF1#{S_I|4-O|v5-z^&|CJprD;~iP8Toa@=BgC{@+Z4^8$`9L z=b;(RV2=qPFDY`(?|Im~)sZQg;>>|)Y-ZTK9D)b9Z$bjA_XE+Y30upLc3f)Ng5 zAggdPobjF|uV06@)fY?W){<6{NL2{G3KL0CbQwZX>J%9mi=>4VBK=R?M8eF#wbRdO zSg~|G@dFPD&D`3OEmSU%d1T?>!AOct&m_$*aZzKU_~jbiUDsWWdTBIjtCn72Oi_#M z=*)Vx`9^Sg2o~sB@$vd|VPYOtS^AGwLeOfapk;2J@prSy3@dh{Nr%#KtV(>%z4hk{ z=TEfm)zL7pq(~$Ka#8sAKrp%~)+W}B07VaXhh(ALM13r_>;9jr#uyvvF_mRsc2z&` zi#lxR8;S~=$ER$0zTQh*opfT+9O>T&piys0#iWlmGi>P@5idW_y^d~4SWZnW^4#F+;{H&ChI2h;P5AunhV@J? zPwmXa?S7APSXlL6Mok>gq&>)X9V*|fPo3T;wDx?i^6x*sYIQL2qTlfGdgu22TuSil zn3h`ReAnIv*-8Y~1lNcob3_O858S@BH`xLOA=h{11{8<2r?X2-!q=sQ4sKPg4y(C~ zC;grcO}mMfYAMhuuOHn1?xR}aRDIvu$!2fHHOp@7^+jyS^6{IGEG(m4J-Vc|B3W7I zcP7*f7qQVXjs9o>@^zETbvmA&r@VugKHE5%BH2N?q8%uQa9|%;@_wdM!|BJ>6VsIP z8_Lntoo>-3mV9q&>UP?32onVr65;kU+8z8rbX=pu^#07hr`^>*Uhmnt?bVZ0@O4Yp zxQP3G>0MlTUekF{p4#5-%3kHIKM?z^C|6ih^>h=8OJnW&*_($Fyo-pVHElie`J4!h zgeD0R!1_vhFX>lBU`Zof5w3$Rc&F5s1;%6d-tb>*a4r_vLyJ}c6vdN`3;cndd_Q6e z;>KApq9zXGMWdlST`HW)D66V~(AgS!!yCJ(;JXVt1tP%&mu`)Lp`o(ao8UX5YhpsR zRmPOXBG9yf$l_w-_R%7z@`w;AF0h==WeVKi>2VU%QxtKKve6J4a1t}Hwt1;g2%zJWF_oTGq!4$!j!!ztQxp);t4Akf=_ zwGTbH_-=VrUUou(MKAXIT;wzpiHiRjVEhY0KgZhA8#%GDKmbK7zc%MuO)uY^3A0jP z7i&^hnJ;hv{~qd|?tMOb-2qXA-EZR+eBW{3Xd^?T40uEo_ZesuLb8ylEQ=+W{!bk=fCxsQ^U^|MUSF+#ud7RhidcKXB zj;*+!jyWycR!SK?-Ji^`=eth3ssg(%;&XalEOA4|N2Yh2_^+}an>voR9zHtjB2Zw9 zwcdOGu7Ljey8kBdIds)@uz7h*#AOaQKRW9$>0imB)L`Rjx_j50`QBGrsiD%WEw=)$ zDEwWjA{PNf_UJD`_=)H;P!9yxTQ*;hF{=&m2B!XpMJvA6(;JGUT+q`GLY^KkWA}38 z%zcVLm|(}>#M7@w?ICd0XB%y(<}(wi%u|ug-o-g8yKrD4nMm+Jhnb2 z`g0zaxkX5$y8AQ6qs6XFAWZTa6@jQ z?1z?gY7E?5Ljq!^aPpyi?aD@nfTd9_q!JSqn4d6%7MhX@9#vL8MI7+X4Vv_5(!6p+ zykr)o2hm}scOniFH!zTN%eAeo8W3Q};#R5{D$WG;)*YBl7V6+WS@bkSHDp=URdUrE zc)mindHom6$tiseMR=jB`)%8b4YUd9)u|y}*PNc_vA_U;LG1kSN91Wni(OZrY>KJc zi9G2UaB*KqL$DBRP4=FSAuJ?Op))5+yllah4T zPd45)aDayO(5946a}Re_0aU%%Rti)MA$+-m^P0K>RD6CuM9pQwxg3j-$o3k#q>@di zg?&?3cg+S&EN3%2+YFQKBcTdU6Ca9w2Xf?4ecd|h?|LhEKGjP0-ZJItM%sJj~Nrda`|ewwBTYm}Q^7U8nljT= zzh2}L4(r!*TengskMr<0@%%^sPZ{bPgTJR|W#;BbF(ui?h7HV7BbnKc+)qJl&AL8Y zlA$KD-ISHV!YD<3E6%9M9D-fz=~&EGfIxi{#b#72MRuq_@Zz~}+o zMU6crTQr3g17CShs7`a<2nD@{VN#M((ivY@(^-63toYK9000}=J003z63{-Z3H#p2 zBj#dCZ(sx>Y58`<8LAuX?@^K(u2ByxYkkiwrA3r7U}74Ud0o|0&(JGM6u_8=i|kHE?V;j+m+w~KFjDkud8Ae9J#9e=$ZzEFXV znuhhGH9f1wFe@U$t4y3i_(_a|OEh|}4*tdXCH7Xy;w zjWs0ooGO^emm3I#6oW!I2$z=@Rl(S=kj>A%yaSD?g_Y*Zb=Q_tM?9qE?JsK;C{0}G zxX#KXLIeJ1sG%@FCiv5~ck^~b2GVZX24ACB@?PW>Pide~o5Y2!lOFM>T@6!o(@i89 ze-&_AtD#GdN|#j<*j%3yfqnIzrQ{%xuU1mK46JD%a!l{qIW@DmJUqkzzyte8L)kNw zb60XQIk2l-X5@Xn9XtLiO6I)|65}|nNyu#skIa03rCU#ZZbwglJ%wn%P(fg@wlw8+ z(>H7(At4f4;@l#lM#OTXoNzSKiA^xC?_Or;e2+Z#Xs#e54W$Yj&M>-mzJbFiIv8zr zkRr!46Kx1mL#(MQA3la2ysU0f z-7WqO8ASguzr6I;=7-LUV*SB`|DIMS$8K?HZp*8~9(lmH;rUPAJ36xAz8(M|(^IBN z>H`MCK5}&>>oW@a{lKXTuM=&?=fQJ{0<_|c;QrF2@Q7EY;LU3#v3;&X{jsz}2?kFR zBwc2H%hq6duW4)TqE4Hfh&E6r$B`!*rGlEV#K}Sy`dP9hT}#)(NX}z(aE8*ZdY}s8yjC58m_fy zTF=zca2uK-Y%QK82KOWn!{F6I55u^!Dfe++iQmNQGvGNcjBmd3{7mcdd9K0bGR|@P z=-T=ETI;FYVrE3KzxKT=e%H~^bnh=H9qo?L^9(2`QmwQ#BhpdldbqOWMR*`r+WSMJ zytE6Z?c*ENtEa1~X=xn7Lwwc_4;aW6lCFKKLd13!Pp~4{b7Qd%0ud2{&wNFM?*-_g zNBCidBeDK66cyv2MIY9AO1NJB{e1s9;=&fM*ExXIOtF5Uy}f-EB75M_9=t46W6e6= z|L`Yk@)n1QWDcNTrvVOmua94W?yk;4W@e~H?dA3kwL~hIsUcHkm5LN%Ak2g$vZlMrQ#kgYTe;18;9Q|Y1bj;G z+Z~9{mthKR8E>`8-xtq&@QgV?5=kZ7_a(=-yM@(X?J`cKW;~x(%Zt2kxIZAjPuaPH z@O8~wWj#jlbj)}Hb2Yrf;iqi(FiH;Z75UZq?`@xaci-<@C~n?}t2#7V>Y0cs1bnak z5r$4tDnBWd$Nqjzj1p1~1&JUd@A<{s#R31X}0LTuZTOo;;4}+lg#7&Lo1d zQo6icCXRlH>3$s|uE4@y-lyG5N?{)Sv)eE`fHxpGy zRezpSB6NE2WP*^)M16L}kvD`9W!&$6Ho`BOIh-A*-pz8ImRFcomX@ZHbn)cX-VT(a7z60d#~Uqe zTW_nzNo#mK^yn;!_0FxtV*2yU{2hd8g-LBk3Lo~vOkQV1NUCbQr?b>{0#)) zdAw_k%`PiPq*2so#8Lw)3&!yro#%5k-@Jg)UUkc`j**P4Y;+7=$IDZo<&MYAToonU zj5y=quM!yNpkg)DTAeP(sT>~-zWuulj90CyDw)ttL98io)#te*o4?a&;bEmc&bCD! z!+VXjzfye;flZ*^)8lt>F|t-)Q!#9m5@4ja_okS~$wwz5Nzcps8M?kNCmpmw1Nw6u z&)tV?3DwUxxSCJ+Rp;<8sdiHDi%Sb7Q<7|B0=V+T%P>e)uw55#SCL;_3dlHcBB!r;L6HT||y0 z;#U(zhXj5PRB8OYtv3>G$}1@ zf|mE1V>NbZNCwjxFtfYRb6&`;Aw)4mO^7HiF-1=kTkEY8?Pt#|WV*C|0pE4!ha{ib}`+hh#r6v}jY&pAMeufH?BZiMT^XfhY z$njpd)B2$(LlH~k#hL5SD+A4B!Y~;l0$(w&37^if|L-X4u^XA%{-_*6>ZgO<^A$V$ z{+_Z@!=Cl}Tup^VxN|p&vCJH8H*NB`|NyuEo>Ljm$utF5CNX=^j-qx@KdK z%>+237gNWd95mEmS$oB zVSw!m8YCj`;Tf>S4VvEPagLlNpflao22|7wf55?EhZT@%6( zP5;_Ix}Kh3+4y@8)r)zzAaz}SxQxOIj?wwi~Rf%A) zy|N9Q(l`Obb?26_nPjJ=CuHg?WN$-6NnjGbK$xui9-Km#Dp9erw!|YFl4r)Hf0biP zAWVFM8LS7~0iSZR_$>;wEOIpI5a#eO54l$66%w{QKgroYq|Ac*jGc4BK9M^fI2aiO%{c@sIN00wGh8X%U7I#mSH6%|CTb?yUtK zQ#^Y=B9a4!*4U=?W+!w^Uj~^w=C9feRHhSO77AX8L(sdt4hA)q?cK4Ns8s~uBX|ij zn)FOWBXgHe)tjiJqcWTo%p-zLsf9m~b7Cem7@4;s$!Z46tjn1HDmDhtO;NmbRS%~_ zri@&=oX?Ldp;%GSwsmT$tJF^dFMTy-7g zL&uL$K@rB7le7~ukxS~bbd_@1?Pt*we`!0@f3$`gi-t*LC}&oR;1ysPF(i3tws+b% z&P7T`VYvOzGx621?r)^)4~rL_4{Av)tN!uhB_?DWQx@_s^MOQ+^Flw&ZzYrx=&=0P z(~+cveP?#ZUF7`I93I&*l8cMhqcj4`5^XoN7Zw)y&=`-3r(5r)MQ(9iYJHyj43nmK zCs!U`lQ*4a9`YYR;qGtu^hf~0B*-md261%WDgs)O8a4eiqD4z-Fc55PMSA0%A3^=# z4QxzG*SC?a9Wfo`izmuE?$7KcMyHd%U&Q)RSjlE4Cb!L_}P; za0^nQgqt;K{1;CTKnfRLUtbUDG$1N2+;Bb8;LHb4`uc>|kK|fkL5m|LwMik9s8Fq` zE-l64Ti*Gothsc?DYG9`R8Nlkjgv1ATd(@Dy0A#6>)L(Rt?3r zLB({hiQ~CO+0B!~U@)p@U=_@Zs6!hRSI@|kmT*UES(RmytAOL7w7zMy1#WDe_u8d;CBe9O~ zZUNN6X8%CIDIs$0TNnh5C5<5Op+Sm>Cj8U@07$AZern(=z`_K;`N97IZotoA6d=h! z43JQh>ixvcSmNSI96w{`fYo(tYw9X0A(ZuNyzH_ijyv7n=gUOrv(ex-}H=UJ6s5Ul%$p7xIeNs~X(T3Jhj&`1( z!*Wr0U(aFC?h})BeRW|b>LYHdfoKGvBL>)Y*S-Dz=qdHbych;nzDhf*`!1W)b*p1w zmNLz^ljiXLDj!Iepuz(DKw==s$il|MKx6CXo-47j^ZoKA+K0g`qSegG_3KP-SW6-4gbKPWfp+Jcf|CBfW6 zMg@T17+I*?*$BB|_s&m`^$%L{L`7ha8_1~P;TW}V%!Cy(wnB!s%uUY@-1$zQ_{0+; zuh->iQxrS^Jd?%#XuhMTi7bw!u=U*cPym_dyNl?5hi#EYVu!=(v+LBfR^J_1Kw`<$08CF_g_vb{bEgA?BKMZI9bg<(A zwkQ^3!0jmxd4Vq$q#p>sA69O`f?^O^EIBv|BWP}&vOG9H8BW$6GB_GlUXc7GquHOf z5C9b@f1)@V7y+DO3{~txF#VBM8V!0kjn_OdFZZ-{(*CcXb81($+$z_6hT&uSg|GI* zy_kySCH5LnOc!3kPHSzPpMPzui{SZ>>*@c-gC>TlH{J45A4N;aeP22JjzXFoF_O)} z856HFnoLKxRFONQ?q!Um$jd!(yvzb#E__%tWWPD59}16X`31?IsFZYq&>$ius-S4Z zk_E7oXiFXBXhWZH_?i6K!kzy=R1&rTbX_dRWjrwU432m(fZp;e zN&TMhI2pM7WTX7Zc`t=|M1ojRW9(*HDNgBv|C|IOL6L%hDUm_Y_(`EBsl6h|dM1;q zmcQZ11XBe7VW1F_$dPO@!;$d2MiW?6dHfQKp+9LBMCjltGgyCmJ@SW1mo~lu^~jlk zpU?sd5>t8q5Bagf`8ATygbW!q(hK}xl@y*N@`3w-MyDegfMbCa8JfJj15}I0}zBNukI7VMjk3m1E_d3_i((| zzb~_1M)dC#8uoDhUol&*9ZozRI95hb_M%CaW~6|j0GPre*k8~hex_mg;UIZQ**Rko zOA!_t(Y)JsN+xJw$|XamN>WPWy4$y5&#}E2%vqh?d-5rGxk~V>`#baq$l>3(5wpN@ zL44o(FYKS8zfjLcT zv=zVhmlyN{kDskGzv@z5qfuEY)4lHCX71s;l8v_>^Amy&@$Ny{?byo7+S+(pJ9g(y zcnsvD4z&}uA6oRaym$VRp@={mO8n+u-^Tvul@GgZZ=hxP6^&>}OAzyH7Sq(2`~-2p z$bdM4ddp!7A0B}rF6q#?94D=;%)`#f&c5Q7-Isgrga3a=)~!Ms5G4JdktrLmgsl%IN&}S?bN}YMh{^c=!?YJmZ;%Nx z1bG0ENLp<6XP#vc*)Ecd=ob`vpE&fH6HJP|7a#cpYw@tjg|5%t4m+aKiC1iDZshr8 z%m@TP^7qA~?bfoVuIdJZpXzFxB&bjEV4RsSba*68Cay4QlLlB|1>(<{lExg(q50n% zMgZ?Z(EnW`B?&(oQUiX_I4uD~1xik`%V5B}6ItZAU)*MS^83_u= zUo|~F&@g-X;ldyJk$)sdusG}nL6F1@o0i4hS0vIcq<5#(=7P6rKNXI_K-0~BSKl_k zQqsJG0{nQpO?>~|CMWl#)~O>1%hQYkz-4MDvq`XM$9DDdJEB5`V&T=So`m(B;eIx@ zS8Lk1!{nZ2trPt3G@pMgCtB4J$ry$k!Q%c{6D)VST`Zl@Q#rN+^gfFbhTajLq{M7iUj}=x7x!@)-#DcMe!TLX`Bzq-1_&I{aH%mk@3L-)Da;FIkg9J0v#Ppow_J}4TJvi>|BDhSM0clDO80~q;HPaT zM4p)=ri63%d>6_s?}`>f>uJmS@Vt;!)tXkoJo(!N>^NoM(ija8;C<32+qvL7Pe3)b zKT(_;Y=VS*iT^L7eYBXErQS*#yJvl1#YW^E>+gI*qz?_Oo&+_mv#EwpH{A7&zjg?^ zqh1|)CCQ`6+AhYO6`zW%kEf$DPtLJmTUasQl?9O|l$sO@ca+^0N@?`Hv-L;QS3+~Y zS#a5qohLS*9bS?z)mzvi=j|f;BrbQ^h#3! zsL)y(&FDny<{_A?oUD{?(ax_h2rNR$8{|FKvM6`NkU%d2Zz?0*J1)YiFg(kUL@=6n6_nFf9oSW!_|xp4sOWEu4UYX*#1 z@a*&fAAsMkLHJ=P;eJ$pGJa=e;huSy|TXokMRJ;U!cc$QNzpgh5@(8 zGf_;{!37SMe{!>^|K#2KlX!AuvFQhJRm0>L1ddl|hYNG??o6Rjp_55OF%476tgstI zGAWrwT8vQ*pr|MZ^#2)!Gr!kZEXiM|@p}ajkx)I`nSw%k74kr2-gi@hbL5C0ot}J9 zrYa#cv87&uw4@z?%JhuWGz`Qmh9Ta#^oqFr(d_3Aco3((w>x4Q=oE}iz%v}BBqGyS zWdQM8BVc2e@U~}xUlredVbqhpiH<|q26@s^h-5NGI9Q#4?dO=6JywMp_>XYvZobG~ej00e-BRZtF!+F` z|Bt7$42vq<-u@oCySpTm?(XiC4g~?}kglN{q`ONR1VN-jx?8#jq(ge(o%3G*bDry( z5A$Wmv!5Mnt$W?SPn=^&b61*OIYOXlrZF~Ynn-XaS^I;7Ad(D|qqw228hNA-y&Mbw zFNbJ+AC$W%O%*iALDMhpH+3ihp}LG#ZXi|l?~=d|WQ}CK2OsQGqS2Ll3XiclRZ;10gUE>b7t8TGYX&H%!t=%g{=V11Cd z-79>GM!UA0aA-2Wv6z*mzH*Ydhgo1mQ2Z<+s%o5-VE9sH&{xBaU2C=6w`~D?s$jTi z5srIZct`R5MgYEj!E3@$N00&5u&S$yHZXbtJ7o)ix%E0+4g;u=({F^gyE34ClW~7v z&Z(>o05DGiL<`%9P+HNOvomALJTKDTp6YdG?8`HnjV%O=Nm_`Fb{@+u{6@f9^)~+(QNDr-Y}R2u{55NHx^#Q z1|-e+YXJ8fi#5;o=-M7bs^+NRP4*pDFdbJYsy;DUEDHrZ@YWuPVxd!W>+Oji0JyM7 z09QshJe+S}UL+cLMc^$>nmx*AAk0Pj8=xo~#jUF0CrQPZy)+}`ZPLakMY%MvW5Y>> zb&(nDLVsFtJ29QoOw=sLw<21F1?5pGRC|*s6g;>#uN%7~(??>xN?Xul{}iVG(Pd8A7kD-T*c7Ob7uDVK1yqw7#gP)Bg3y9 zF_@|uFW)5y_oggrxp1U8Ha5lW;RM0qR7XlVOpoF1pg$`w2#iDqN_v}2R0Ovu8?94_ z!HGQH7$zwX0A%p8KpcRf38#yIia>XOH;d3iX937IF~%I-$U<@7LkKo}DVMTBN}yfG zaJ^B?j5OJ$l_a)Gseq~u8J+?GvCfW3G!HBQ#X*`N;36A){MAj8aFE*;D~}sT=Yqu@ z90o`6lcq2!Q3(?Wp36LlYQ2~X31^!RepSzrczT;3%YnKPAgZ`Ntlt=h=!bs1+CzgyJmCwjLS<+PyVQ-f>*ZG{(v$r zmgwzZg%;coXCjR0O?+}RJ`4k8%%r?q09|G=IZIqi!8 zY~6+86~77ps74<1%|z>8i7o^_tPnH^%b~Jg`$yot4NFb2{))=_Pf~;4j$|(|!E6PQ zBiJRD6zx0D9t52Fv0t2uL6A%)vOQ&AUFMUxLwpEYE{Ke)S~81_RNV8BbrM9+h>O!p zaXR&ssOYfOzSI>W<58SNmnt<~7C$e~f+yugm)bkB{%fQ26A_$^or>qpzgv{8pR0RL-e z*5_%Dte3gCS5V!2GcpCXs`H~kbUm~~AVyfn0KR%qK$7!;D>W9wAVMUiMMe>4>DfmH zWiDX()5Xso5lQ^Nl^nk*kiMdZ^_MnB4G~i5lK@&IU&5u{ev)_1O-XVuB1 z-RO{AmH?~is&E`D$2jcSA6gUm+9T8;xJo&&;OT3K`uJ%q$bu5dWw~e&g9G!@g4>>F zFnF*~45cheh{Ay2LwY=)tfBMXyfN({jqrc|QS6!~%@C7{f zlWJ6R`a9AZ$VIvRJJh;X!5p0-nXXxvUwpifXt42^)WZ4b-yvLgnaeXsNyiRv8Rw1# zc2NcK6=`L^AkoVHL<2;}hMzN8vd%S}+?@!swTjnk+`_jrJg-7&8St%Adh&a^S1~a| zIh(%5`HS+0DPI+KAxSgMcVk7!|pFTY(Jl@o z$PV`?g^#*?LuV~>`OW=3WLEZTw=hkvW>0W0D}I*CaJKf^`_WQ@)ddwZio($W0l6$N zW;7mIXJ@HEH|yXnviG}Pq+r2!Tf2yw7Mj11MgroQYj&c)X#1M0(N2?w-&$E;pbTaT z#5JHU9Tcs@gE2Inwy+{@WslzM?hE|QouhDs)Wppb^^Z#Z5_0<+tS=C)`p&Y|UNo1^ zzO~Ox_%URQjjkF{I@F;@D#x7rHk(T!R=cMF?AaD@86lRkjJr41`?m5Zv7KPRw<46MUnU-#8 zB^1M@N7-0lp{XV1l`gUgACn;84$1o@F@0l`!JLGWPE!k3o>dmz<#C0NU|bvo0(ow# ze>o}YNRvXn&YcP97RBTde;oM9z_TRD%nU4L1oFD?8H!M7qZmd5{4utiX*DM3q_-+a3b;?piu_V>T06S z)!4R=0yOD6lu+9WufF`_!)Fm39s<`MGO@1|l%I=w(3-{yH+r!=cj%?a%HReIkqV`N zdZ}atGksN7CBf{ETDT%s!zz~<_=1_HYYe^PN)5|sy)?qp$hepk&ea-7nT`-UxYJl3 z!mm<2W&HfA9|r0;P1Dn3EebL!NVrh8I4|&c&PjW)KYEJ3WyVM%K#*}Mr2fE4Qsd8# zg#SsQcz2i~A1u!yO7{M#GIO!`fe04j{loIC$vMBiPMVNll!P4&in+l!g_0)?YK16s z#!mzYhGPU$izpG9g@SKbV7$?HXSr3Vg>}PE6bL34Ewu=44APGTf;c> zz=C_?)4+>;ez=c|$%zz;IEnudD>a`|jQ>Wj%)enBKGwly2r)v6jIWKYrLfqQRFVc| z`Evv@`7kV zw3A8cEf>SKQqTt-Cx&r$p*SNTktRQjY6Red*2{duK_Hq7Jcwmqfp>RmlM`f0yL@6DL34SX& zporjaY*%Mqafv&c5+*a{#7+wA)tyX+3~1nz1S279YVcd@S%kC5aW23`)4muLaN-~X zun;qHJL?0DwZZ#%Cyo+CnbLQ|s_MD+d(loCgPOmFr$2yW{4%{dS~hSCOiR8$hH!uXZ5 zSwZqcNvE>b@-o6dokG^cvM&nWdDslS1o!xyW8-hefhb#q4BQ&66_S4OPkkq-WTB>x z;Mnaxw~1Bf2Bu(UH)VLO@zJWJilsR!%ejP83_3n`f*qO_edtnNq1fJ$V6hSO_1z{m)$kVOAj zB!C5Vl?0R0c+Ahr1W|wEL8B(^+?q$lXJ+T^J!KnusPa?1o+JOpllVXntSCODFK(2O z3C1>l!6hyoGHn?ix2_nm)!LwELj~;+z7FyO07=-mEh;yNC$cnsgCE)%GASa-iK>NZ zoL8kPxzI3#!5@96fCJPp11M5W64x~0IO8mlEY`Lng9X@$j4Bowbl^VlV4*t>ztD&- zyhWUiaM5fOR!eBMX~!CTHIvko)a@4%>`9B9UF80p3rm|7ejq~t0l)fajN9fSKEbKOhiQK;rJ<7qSdc`4 zA*9}PdSOh0cvuI-qL9osX9b0|QPC+$2L&Vjm4nr_Aw@@M!%R4nA@7OEKf1Ym8ew-m>+-!68ia!?-Sgt`}%cj7DZix@B7ZDFmG)rkLL?zSIl$-DGSPKav zEd8D1riPi2Qyge8(2(PL&w|PD2k57%5g8>F@KpJ8EkP^@mgc+`h)gLB5&%zLv#25& z5|7TQ=Qmy{s$yg9o@J%1m^JM7ly4ge?5^CwN5v`-_()aB=|X|=IgnKb>XixSbm->% z%`hZ1!@uF*&#nENY@e05(rn%M5QHcj|1FJKBYN@hKcX^|Lc0|3$+(#gneN9kAG{lL zCs?&a5!Hhj)OCwvkV?RWgu1D4$;oYONn5VCBWN_Zs*JSO1cDK%qXP)qQaCj|(m3(u zNRJl@wGm4Mv>~){k_b2e50HL_OD6IwBd}mr>8U-AdRG`)*AsjledZH>qh8@=8uQ_- z5kJyrfCSU>#H5k#^{Sff+Q#Bf?q?Hj+KQCbQ?775+sy{su}NQeZ#Zo(#b{0Q;W#>J zdFHXuKc34=W66(W&Us!j3=Al?>K|D8iGn9?FYI`P`3Lkwba@uZt)H5ltk>XmR4rl~ zf6UA<$T+|mQ?c5t(QyJUITkTFcM8F{CaT~v8}+GEur&F6d8$q5aK>n^Y#azpdO7ZT zq60}M2VvD&Sysdyd`1Hk|sf@R2Bynw=6T>I22Kb}_igNOt z`@PbAlmM{B-8WA`f`xK()2Ol$SI6ma9+AeQh@}s8<>&1M&VaDxd zx9Ts8Vp=ywB6V4V>C2k9$UsAk%iTvaWkX}I09W$7h2y)_w5Hg1%LHzA2Onbk(Ag}; zL&N3#t^R)EDcblA?er(6uZRq3ZI#SG)2VvE=#!Pz$g3&2et846Xqm4XayDAqxND5ce`Rk~<@X#Cm<=-F~|7`*UvHpO!dRi-{@Ca(Sgt^=(vTz~5 z8>s{J*b&YqGS&BKcvQN*V7@eXF%K*2>HTzdGA!_nalC8Z(X{IUk#12Z{LbUzq()9m zj2tjSt*J){d{bmem#=zmbQqLl|D8`CweD^oq;K|29y*0;i4>|TVq;Qo0bKY!G*LRc zHJqKp&kUbuBHxw$L}Jd~icGwuBq+NnF@faKp+>fEqtg4IXnXQWk1$hQ+L0%h)}YJ- z39|AEn4_)WImGLC%Nnsf=d8t`Ujb3)I^kpN;bXW+K-J6(|BVAl^h1vjHi7~aN`W-& zez~K4g^#Wy1Ogi*dweNYXrB(PefDkjp0Xp;k~-Bir@&cF+0C5hMw&*~_;V41cmHBF zDb&Pudxz99Coot&ja_g2K@QaAoJLgkwf`sr>t>J!2U}UhrVycuH6-VtpAD7;***N0 z(Z%hgObY-gNDY=s(rcFT>cmxEGX+G+NfVn#GVLk%f64Ufqb>anXD3Npzh&~Ao$m*oTGehx&u)Q$su7H}7JnS>$7#0hY!44G`@GEX z0kIE_`vd3BOfnlUBVsH(4qP!xOawDcaHt_-(kK|PXa4I!#VY@VZ-EgUMMFgV>H_DK zpWX3`#Jn#a73(EHMnSqQ5=ZbW5&)Norc21HNCpNh5ST}>ZwnO=?v)As+myGIlUXVc zq;8v#h^1WIwpl`4slR)Od(&(=tjT=n5M~dIxcq5l$ljVUgm(QLz4w@l(lH);H0W$stvzHum zdaNM?2ZDprv%#pViGfmN0gweqr}ln&n4XpLqc5pn))rqLD4G!VePp07eT|c{_rA$hmfv2{1OQl(;a^b^*Bj=5{)SuT8*PFiCLx<|w99KD!VV?S#5Y9(L*%$*+Wb;^PD9`$;=Iic2z zr|ktOPJ$%Z9T*T|c3qx>MT+kUH_ETVkdCo?Tyd3P{gf^QsGo89+<(2{GYA5TL2F!$ zW&Y;x?)@zwSw1_ohjUN>f{G}jUpfhkz zDu`8j9Im(iR3=7)41goqq4j=X4nwj4G-)u9vy&4mFt#M+<+$HQEi zWGo8$FkH@2!39pFI2=O6x3o3D`&sl$RZ}8qQUUl>{#|Pn*D%3-Iz${0LTXFtR9%{l zD%wz@!(oT9YUy~j>BaH_4K4tFd3iZIJA6IPQA`V ztWVC((Wc7IT)IEuGHL>uk2OLTMZ_8FB%gj{jwzCsQ#e7PR9P_QTsL-E~(UKSYD~P*c6Rh61|5Sn~S9xph?`ad_Z~@ zUkZ_6O8{0bJOs=&hysEe4|Xr~FNMxTeiBQsO^JZ-+oi(XU2u)>kk7=C!hv~~`wx}8 z;hi^nPJI8#USp^p83{>O?}t(C?+4SlcM|$Z&!$2~ngHIV6EKc=y(SjNWAA zJFCna0E`L9%fo#Kc~4dq2>*9biwgFm;E<8-yk%=8+4-Z)B6*~#`#$v2p?Bfi-cFW8 zZpn>-0tP@IhGQWab)6(-1u9XUAsYNTNi!b9zLljbyM+SkEBW^!mwwB3oJ9HPFBbv@ zNYm8y2q<(Y|9gbbIQ;e*dqCdi;ComVb;5u5D$Eot3kQ%sBtH<-sH>~}BD2Ji;2-4E zzU4D|=Hqr9K%p1=#$9+r@`E|WR&a%ZOeZf*OUHIR>?)LWftnRG0x7S5b zm4%N41LjiB!BJn+QBzely6w_Y_VPbHlfMP6puJ2Iq49GmFsGDD03qWcr{+0LT?UQ5 zpNQj<5cSDNm9G=?Ao>zf`m7|Bj7U&aEE3)IO5|Nf%F=9UX#65(!UD5HA)S9PR11UJ#&b zK|za!0#6_JfuXeGTVYuM=l3AcV0M4v5sI*BRi5Zn)L$9;mTOq42IzSR^DuPw6RmR* zT!Trk=jZo4+wJY_Vq#-4zjG0&P@ba>YB$pjX=)|qs4~j*Y8w0bIXgS+=rqmP*3{Ld ze|n(&L-N11aYslXSd7MiNCU@|nfsZb?q-QBk^zx^o9-h(A_!-JK_V9gmk!3Ok~VUs zRix1aSZP=RD%5Xz8wWp)j(O!gtKRyllnDw`12|*?{%D+maj zC}WiQ4f%(?pOdmc0I!UEFxWWlDcxTpm3Ty8)b>!+t9QC84k;$*;yDO8w4&UQFnaqSL^n+o7lePxy`yc6TiI|LqAxW>fHBA zbUZ@sT5t?t+U^Q)7WIA=6WF{H;6N*TAs3r|&7KQ ztLp3PtE=1ps$h$D&!j`172aGw*L4osVM1 z1)Y8y`;euDg#}aS(K*yr;=q!9UQirmHSp$gv+H@vv@ zcRIIwj=P}kgI~XXU30Wu?FM~zCL3R#`2MrNx&3wWIPjvs`_y4Fe{%1_JkWQF&BMb3 zV(R~UIZNTQ`75l&FY9bCUcv|ZZ}4y=C3JnY;1Q~Du)y&RcJxp8cLm;ELaSFvLxH!y z6HAR>mP;Jt;VUSir^n_`3+qSe&iCC*ixe8=!k%ZZr);sr9Cc&d^?^#zj&t#r3L7vS zKvNEE+zza_u89Vz!|rxy$Ya~J_)7}021Ozq1QY~O={9I_*e9k6a8r0?sn!iS1f7bIkafCRE_R&G z)W4qZQyV_Sn!;DC$A{zu-BnMm2Tm{rJ=UA$&u=W8{q_GEEl|7qJV*X_kTd9IG#owX z%H(*xB*6{bA{5?iA54(JK4+Uawwl}!VK~p@~ z8)8RSa_lH@1f61O4!4eurwPpB|D}1qBQ9k~3As|rqM<@zF zki=8i9w>_6eBR#->VEkw!CW|Ef&(gPoa!vO4gI5)I27=*?~9=VVGEtU_u>iL*zh(9 z4Gm3l8Q6A#`N@?xAqYXNvsm-DpGR!0!*`Vpi%MZjzbd8}_QT=MihE!EV`v_u^AbEL*9LF^t$^U%$WbYdiKNR1DF7M1`lQwG;KmF zknLQKXNdif%zT|JPlu+a;KL+CZN2=4HrSZh+xM`H|Jv4DYW-7yNca-(-Y>6gcDpsJ zvcJtW{Diyq?)84%7&k$HpW=!dy0Gg<)&7AW_Y<6?4rG>=JwoQ9}4a(11O)ZY~&3T9U4`q?gb>X}9(9iDIjK*^waCYGuqjmZ zq_$nZ8{EC0WfAg(e0#^Cf*3!SvHt67lyGif`XU|qrENbRuA*^|4j*P8lxgW;xH&8C zQ_yW&nj(qpOLo_BF`a+bH49GH%?!lK-$gLOI$gUNmg$?ggMRt0$E$#Zzr3*sG?mls z8bVtzRF*xq+3x1u+Dm$TZlNDtgPNf~3ZVBR2Kx_VFPoIDZD6hlojk6(e>XZdz4t!t^uZX3V*yj$Jvf8Y|HnPHp;arvn)_88;^il$ic^(?(q>DLfQ~k$151VsF=1RgD-4O?UUwte|4oE60mz?bA|$`A7cpZ>(>0 z$S|2w)G={za_cb215$M))!?|?=->dPX@EB$2UlKF5CIZ}j7XJ`Toc;B$t}|dsXwc=H@Uoqa@nzX9L;R)RwNeR)8XmDW0HD&%>UREzw3$qPvm1 z6Ot89_ffAhH1X{G>pDZRtS^+aW-kZZlfko99fp%3v!DN6o0PxU zh*J@iV@w@O^o1y9-pm&gTtQmN$h}P zC%0fds_TZ)wthW6=NZIm4ww7>eaH50uP=qJ+Dkj6RAB%`S+cW*g@w6|fBsl**5=ZR z*nH=PHYf4dU59=e;d9zPv-+iW_T1Ol{S5Y-;q*gIn&iXMn6U7s_Q8*Fy~z?DQZG4E zzDTxjR|2e-+=I@OD>w}9i_*}ms@F5MmFX1JWhvx$4aE#lJJ;J2Z!%)e^hnlT-=EJ~ zSo24JQ~bO3#lc0s?zbfoE#=PfN{fgc>IW~j1!}-!Lyy7OY`eLm?=t|zJtTJSkqeia z`8};&4XfCP>atXJJN_%C@Zb+RHExHRDm;$CdN1?+lmZP|@U?}SgWT^DZUHdT2K~g$ zhuUVVKk=>lS;-$*$yjjtzNMA;JrqqY;v_+a^ z2@HgU^0BtIx61u|nsgR8q)`mVlJ!@q036L^@HZfgXPN+KSm{xD_j6GOW@dcG)i?Kq zugYa)30eAUaeD8UD&jvs&qVl@_6fIH0RG8qtWoOp*2 zz!d}QFW|KNjEO}hG4I{b$R%9b@iMzYIyY6H7N%I*O@EXrQoTIhfOqBDLgjd*qz!;O zMh*A(_aBHRVQVlQKL&G%U}bX?8+@{WUXk|e%7N~%<4zI4p8MzgCRX?cR0XyB({*Z}&>^*=#?fzqMf>G7h>*2~MirVwu_FH_j_I>_ZW%Rp+Ap z@cD$kIwWbqmeIONRZ!5Xopp@+ec#Mkorh@z;*U2}?fpBFL<+t#1a?h$y?OZhyODR8 zx@Hc{%)@d-6Gq>6+#uOqlFqA*SWcq2$wX5%lC_w$BXVPm88o26k2A&3(4mxC$H2^# zBqiqgBgzZPnE3z)b@jT>&s#wH#O(um#XutRQz(=xwW}d*F%=6DKHw=4*?LI`z|oJ$ z&hdky?v}k{ELgUr_3fH(OB|4`q5WJ~{f>K;)tL1`9oHQ zOl14t!;UUN*)u7z>gBL?6vmwgweSkT0z#O{Z=EWpr9H#%3)gXvzN=(r#&f1u>&Wc+ zImY|aFe_ou(1{)FD%dKKo&0evoT0XfFZV}GI}`ha)9N_f2di$k~m&OiM>Qm07Gz5qt2#q8*XmphPAM;2LdkxJ#X=s&(d_S^F`Nvx0&ykLHAAUK;VD?g0di zLhcFs`5Nq}6v5 zBc0nC*a4z#uOk)aj}Y=4{J+8H0-pYVw>eA&oGU9UFVngMkB_IkNRp~5_hBzdkEMXS z8kbC$xj}P@?><594ly?8`LpLWhSSg-eZMEX^iOY|UhlnCxP>2notuf$R}}6SaY!tv z>Tp3~I0A1qr7TSXm%o`zIj{Vi2Y{se7a5=(s9 zoH}Rya=!ZSx!{-G%Vm!O8sEu!$98o0>tk;%ln$Jp8whQc@V~BITKa%~;=7YCF;IOf z_VLSDgqUhHWc|M9?#$q&=#S7N^nikn01eg7O54flSJ>u(iwo_%`23KMkY!DG89kM% z-c%O3_n!40m z2_2Qr6|+J6nbY2my3ZDMooQDueCC4#)1b7;ed=U_v+QJ+$Hi!F2y{BLKb2uaP7r34 z!#dv#ns_jGBixVAVruo2pS<;UAG_^8z1;~w#-13ft;_%D^v}uvW>8`D^{NTGK3|8X zS~WTnJ_*4|aAnu+?OeJ3cU^OsvBB@{?^(0!7X$=fT4j;R`JKc??>htdUVXm}?40w( zoIO)0_=>T&il7<2y5JNd0D=(Zp-WlrqQLuuKinCN!-G3V;04g0ndr}BE2AkyWsz%A3FpVS4jilbl8@VEOuawPa;EZ3dv@NDg2 zSfl&7o_@wwdN(`;!uGHkd2V_%+2ncp^t8Ds)}`^Q^5A!OClxBjpM&);mlLgle*4oB z=TFy<^c(Eo{bE~fCeqA(x7}BcCA=Lpf?B%;UuB>6p7J?ziC1n$`!z&w_JYNOL(_9T zR_mSHw@0xj1n1cLb9GEQ+|s<~RPu<^eoPM6@3XvFeE54E`a>YUKx6{%52e!7V(UXu zw^-*vWq%b-RF{u=z+r54eP;c?Grxyz@|VAlCmj-Ra4XSqf@2tobi z^%Bo1)Q;MMkjl^0&>KpDfa_nM>0;#)C7=U|uWi;EA}kzrzi!;N^>Zo$?o=|&y8Xp3 zZ_mB2^f$eIgJ`}^zh&g;xs`!+O#GS_8d93498| zSZ9ZaK7mu#-S|^KAFm6b7Yq8VK;LPP24+CPt@mg!J?JaA8A1B?(;S{L(o?&c_VqX{GeQYS%cnn%v&t68fiW7wXR)9d(?x ztWpKuZ^I*FG2li2jwOEG=Lq5=!N@QV^a%)n8uAJjArp`>#fHL5A5O#|kXpuZsm;NX z!vt^YIO7^=P{MEqNnjlcAL8bcFELIv33RqEb~|;Pe%%Qmn?LtYIaP{XR5RUSWUxO@ ziWNLxF*#@XpT0gVoo#M*S}DoBo-O73K29mv1vWWPL{L7NJ)Gw0%)C$sy^c`r*$`;@ zjh{7|KCYX#clmq#U`q6X!7=_!>pWf8inKy6=kgc3UmnblJ*S=*&eq$p#qOhhiY86T zy(nd)aJa80D}w%wpF!J~M4zq`&93?^pR%v*CGLK=ce~w9q|`k;H~9$!p8r~Km*>$V z5q`X)re688W%Lgc;CFi>bkT?X7YWG~_|O+fxjr!@o()yLtx2D~%FRpMbKfTx@-mfl{rBCZu}SEkWlwENkvr(Yfm|%n zgik6&)$sPTx_ZhJJ3eH2tE;n?ZKxy`a!{~+qw!lBsv*(wC%altHG5~$#6_38A0EX}om)>ewaB`{huRgyvf`n^>9G>qTOa_Yt;vd*JO2vDaDrI}E^g zH6dI&Pv6XImm${T00AITXMi7iefW`MzD->F{8HZOcL&P=t=#F0Fo_r~zS=|W>kXY= zmR=@AZYl1^!ei0!ju(;D|7OiZTN4o}5Bsm6D~Ac^+)2Ey`sEKl1ZhBhCSKr=sb4lc z_|(jwPP!8iAB%gGoK?6V>xchVn0rH~&CfgO6xN@1Hp+9$3VaSAtu;SSEU8~spoyYg zFYfN{wRDBIg-zd2{+>Jf?>A)-^?+h`|69uQyX(3fTsdF&yE17(LDy2esQz<%=QTJ#WX}f`9qlmG`=c z{@NEPcvNe?ZK)USgoJNG@7-<3%m}WzqjxtJWmW^P9y&cXU!Ej3mfP?COa(#FUWO%* z`dkq;{br2}-S)j&YTF?(c(FQD&5ss6LJAHpkn{vI=MJa$y`%@F{Y=7C?bp9lG8SJq zquHNk6`b>uUd+TqncwFIK~n-m?i`;NYCL8lYL8po74fj(sIN0)a0*kZD+FnNzpBo!#9&R+uok|JfC>p{(RnvUifKa_Yo@4N3_w=wtiU)>b94?Jxb zF%$19TU97apZs~pVt)DCE3oa;#Cey;!uQ};zrgk0gYCVuy4oTBm*~ljwhwbHYS^#0 zB?1M+ey96Opr1&Ez;v^|-QvHCyv-)zb0UEa@7-J>_XJ9j+hxnd&)MlO-kxe|1iR9^ zi>^h{mL~EgTtxA5Fj7Hnn*1EEbQH6+(I?t4PWjISa;TC0@+DdXLrRVPrW1q}>KvG5SH8gkb*#Mv#T{kyBDed#R%s(hJd?>t_fC^paET}^*>x3*D8 zo1us}XoOc+N98Gk>HWXRy5A&nSQ2xs5{<5l4<7GcAP;2RO>|4+ zsBD?Sr@x%V4T!^wc8>+159E>d9PNMmMlaV`G>?+e4+O{FlQG8baHdSow{7nZc?bUd zcG3TabK@uE)Hwg4+oPSTRYjD~A{Y8cubMq`hjE4z04(BEAPWju)Eie2I`#Hz7>8w6X^uZO2N1hAobq#31Wzt80Ea)84)CB{r$@ zB!?9%8X<3sx!a>O^DKd&z#mM<`n~?0@bK}gcPD0E=Z(bUx#68%9oP2kdB|URX1UU1 zN*0G3%71g^3VT{H6OgI@kRz%!GT`+|UWJdfvq5CfdRpr##H*4A5}uz~nmB6fnHvqS ziN@D>d7H;p#ceZ_?3+;1zx_FJ6RLe5!S#u`zS-sKZs)Viq-(qF z1-+nC@`KyIlaWslbFR5z1V~@34b;+@ne=ZHdCbC>AM-F~spa}Q2&9nfuFh+%NTo}` z!(reb`RlZ)zL~vJS8yoWrEdv8QCg*-|P)d6ry_{@w&tl4U3+;>~!O z1LabXZTH^}kxbQcm}3+o0bcgFdDY<*=|n@ziI zfB?Y>?!_I76AHAryA*dT#R*zmi@Ot`c#B(ccc-{hq(CWF+~MT?_P6DnedY)J;JU(- znYrhgS+j&DG@-r~GW3Ulzh2LES%JEDJBCp;&E})XWKpyI*c5UmA_%)}-FQ33Ll#ZN zY?8vdUg#%hiC}_y8y!=ChBSDPVp-(9q+@MH&L3A{%uTK2T3yV|AG7hVu0LLnVEl;; z`0-=WbuY*;124MVWBP+T1WtfB8u1*)W&mr>RMY2#d2`0E7L2IV2$p7i)sOna*|AS# zT~7+^3w#Y!0{|j*F=w@M$4bPDZ0$nK;d8l-)uOGGq3zo7joVk6_YJQvju#t{^7#~CV5Q-$IOb0cPveH3;3uv3D4(=N|j zt;<(mN4xk18M$ed5|S7}uLU<9VDv?5L5Uu*eA7|RM;J|^2c_3-vfL<0-Pe(FI>AT)kUM#Yt@!;u8YGeK>;N$TgTz=XTq-FcqPKMQXbFh+ZBewS+mq=_=UMgQHg$!?YnP%O0!g|A08H#`dDjmkT9{`rO{YSb@VGTJR~h&v zAxgR@Sef%P5?8P3$ZHRD<&O%HU6Fnf)F2^V&dGpd{!iOiIT9N^77WqvG}W^Nais`m z2IhMT?egBim76;3S=r>#QGKXKD7hQQ)_a`Q&MOnNx|l@K40%I4=!$o5uAP3q{3#JL ze(E)+@}Q4vafslS*;bf)!!l(B&8`6uY1&!|rAdd2DSpf%B4koFfK-n=rla9kde1b7 zluwVf^w9_#3K%*1)oj9K4LtgfcyqKhMXbLNz*KC?1b5@L84WFKb%7xR`YoG} z3Z_U{kV{>Ii|~$(mv5SA(6(d8`0$=UERSV6490-r^qD9rv-Y0anJNv$fBP=WH8?^XS-i<-FGOW-(P3m415 z%T@AY&r93Z;Gx1mhk<{`U2`Tr;LSAcnmtz}4bjcRQ#TY6g>?zEWlqgLoe{P;PPYW+iR(G4YpqmvybNZiCGD<(uW#@D#?EW|;NOEOVYtLeUbTBKFU7ZdSsaug%AoInrQEL zAV=R>u#gc#MXlqGr5TDDij|QL?>{Gg;JbhoEJy1EoTrVU^H%Re?1X3dTG=Hg*LstR z%l~#5+_Wq?8gmVGeEHb_gb08nCc@cHnArDpZ(mi8k0@<3%Jb=8MBBXXcv2K3CYkB; zjYl4lMrKGIJN%Sq&?aD_Yn6F2S)0({-e2>PkT51@c)TtA^LHsuRM3z_XGsukI!1O; zeaAC7y9(&uyi*L25t6?oHdP}xAy9guOtrzBR^zu49K~-y-qbFl#%*ZVD7qgg5 zJ%P{hShr~?lBS7;wUY}TS?q%pz>p6$trJ4fs@ps^q71{FrG_)K*q8%sb@zRR{T( zYfBOW!;<`TkryrLZ`I-8<&%aHM8q;gyxZHWzrL2^=9{)o;NC6AgUz~K^OtR<(!6pI9_4#l*R&fwUaJPK# zyQM{PIr@~Na!p`CeNn^k*i&U&qo+^D#zuI0ru8Gk-kLlz*#bZ6KwQYSM9Kc#nnT2ngdd&a}nJ9<#O|V zbyG)Mb*Yo8#Y6X5nviC6%ZO)<&SYuv{_88thRg+*qVHpE3j$6kZbQECYhGapgg}kn zSj7F4fz4%q;<4WlnXt#(8(3S}4(wV{yfnj2aeP4PDAGFr&jZ3;Ua_!d zoL_!L;nAhcsn}i&>c=~t3VRe-99~TArx1QpxZP5o61^YEbNo2Xm!+dm6xV`7slT|m zuzs^b?!;B{$y%w-c~a<{O6coALBYQLg{@E%ae6AJp2qE3NPtd`khiqewV;XIJ}l@? zAC5+MI2V<+wY9CTx@~&-OsTm|7rEwpX;_(kKJDLduNLs?fPeedcN9^uG$!h0QEAOT z6{yBbwaDBC%V8HPR6%2#d<0W1rU$hPg+87q_UE5E;8@*OGkO|gJkw_$i1cGnHdLW^y1H%Xcl-F(t?e*V^$sgjxH5&bY58|Ux$sM$9sM+b+F zr|-_k7ecJS8OFkQ${y4bAezPC0ZqN$CWl%7p*m@JR%%M@xyz(xty&FWJ9MB;zb*cB z11dotllLtvOBRotj&hW#y~*K=?fzC{&xsjafDO~p#sBp5_oOcy=f;hnkH5;OjfwQC z9It-4!h3;rwkO?q+4Gl};wPpD375eug)to32o?|=WtD=t><=HPsj2hhCdKjF|FJtc z)Nit`oMvw;UG1HwlNGqUZ1TLhx^jH?iFRRLps*2GlzDZrjdbnzK=sbGp!DIEjr>}v zae1ox>n25@CP1J^5d@^*D)K`o?bW4WmS|=Lfkv!~3Df=m(1jf4LcD6)SW;5XG4R_> zWd_vq1CpD}eh=4T`Aq~YFZ)GTwtrd4G{=M+K8%y%p=Cf+N&wWYfXhbL4V3Ye%({Z|CLS>Z`7c+E-7{H${Wmxuua>*q2Til8TAITz{GO8R&> zhF$jH;*|=!E{_YQw;n+Q?=Jt?Rh2!g-$~O!v2SjGp6$<%xq0@tdW=usk7i!4d1*iK zpYNegzI+JjO(GcGuQtAmH8Io)lYD)Wjup+$U#O~K_OkgShdtCm5oF@tTouuk_b$#eqjdkrfHXaD;X^?Rxcg zaZt$0?OOZB@L}YorJ$d>`*YXXu8IHYR9DMxDU+dh*wsx(bHN7hz+$tLI<{#Q;=ymn5q=ecmS@Uj9-U&pEy}#S;$0Ix;qpNgu3Uq{ z$rdzLHyP}X&ZjEXr-%f4|6P%&H}vh(c}x28M2F*dR@WsD0u0x^4%n(< zAVUo zNBObpuE=f+lc#4Z;wQuH?z4u&*PUC*@oW4JmU??xN6oi~)kNBUFP%SM{wDf##engY zEB4}E`77%iYW%7*I?K#^fWznHPA~qtW+yY=>1+2tnuuGEC(&kTnbR;=*7V$Kjb3i2 z`#kM$ceQUiZ||msz!I2yCIP2LBdE{!-3}Q39Ok16)sN?%jx8UhIj{x>9nJ_oroGO{ zD;nIKJ4AQb&S1_n4QyGgGJYr?db!^pd&SI~K9#4F;To5mA%dP+XMb?kH!&5kD;Zr8 zF3%Wv-A4mzVa^;n!H$DbyqFdK98Ngi&;$m?-|tq^WQ;3aFqT;5EumWoSMzk z)e{_=pKEnoKXq)cjlG}`D=S{CejdGfXDA`XcOjYADfcv%+|_x0^G?p?s^E2i-9pku zDIzi}0B+rk-_9d;kVJ|SK@+2e2o5SoM5OLk{55mfd7tlKqSLD4HP=c1qYpF7VUd8Ti4-oi*xt>jcwL-ZM>iT zR&SUE)5FtqNl6JDk}zOT3l5gZo)~4m8TcUA6Pg_@S_D}fCxJ&Mt*?tBAt42e!3ABK zdU`BlJVj6(FZd!I_?>nt$7v5C;G&arwL&k9GZ|cJ-m`T%BtooweRXp^2(`2MG!DZZ zPw}#3=FLLyb2T=z)w`mPCxzf#QXI%Thddqox@l|gk<6WhuNz4watV&X^G)Si$4d7h z?CeLBj_+o;hHGtBj#%{~q)^^yR_V=(SjVNR1*i_yE^NS66N3eRYvaR|Fh^>EYn;*LBjUcveBtp{{Fd ztGX)ZvPG3M%NQOrM{py+=Yf5RER!0ztZAf?a7gnUB1=ZcY6i<(AK0DO95uuWc)BM4 zu$R=5&Yo*M2Kzj+6$cl6ZDUIfsHq^t-JSlWXgFltPY05(BA)zT53mm4JamEYpxzQgZ1s@A5@573#_wl_LWH!9VRc z1&DzqqCgAcATJ%)g9$bXnCjV~WQkJII|Uu^^@a~FJa3ss(ZrxNrBA^OHGcD$rJ2*5 zp7e190cAni>(cX@r9R`ZttB;srm3Md%@Xf%_({=3=V5qAZZW^{q*Hu=9gY%m$^WIg z;u*;`(A(z8zr6k=te@S6l1zZWouZtn4Lfa=SDFpaZgL;d-fi&~D)hwVSYDieD^jtm zl(WSR1)RM49gD*Mkm8C8C@9o~#_E4@53s9#S7ciAOIVJ!6wZpM0`-VJY`uLrTBd5V z@BdcgMEz9T9fc?90N2s@sf#TjmL`l&Ot=%hhhS159{XgsO9p}PG-WDxf`sEIpO%Mo zjOstUQTJ;0yxB^-{B0@KnDBTI&D8Vvj7quY4IA4G`PU0^(<4cvTqYaKb|0dXfiXexN4yLli%$YH$EL!^4d)HlgQF0 zwzs!?iB#E=!DBTNW61>tZU(|Xo-ED2&Y`WsogGv+M9!HS4+`lF!~rwixRxhJ*o2f%hfukSHSOi1 zYrm!Q#og`gaJx}%h{lXpr_!|{$?pRO8`(5z>x-@zqrFB}`AR~PGQhEHcb z@=d3tka;ms?HOh|yfZ$E4eGv;cDBST)*_Jp+^4Ru&l+W}qoV_%h?6NauGUGj(o36- zVoOyh*7(-j+q<%&-?Zu=kWFe4RS;2do7++NyPdB6r@u*$DO9=hvC!$gJ~sl1MPO7| zIqSx0$t>ht3C^xdi0H=;ADwOIiehz<9|QKYkEqJ6t{8!z2r+v@T#9xna#p-}kt z^Yk4?$cWr84m~fI$sxFSt-4pePkB(6kL>Es_keNc51S}n`h+#K1%5kLTUl8NKarG{ zGCg&`yE}V=kdP4G;hgDX*7e+QrJd;;1-Pi|l4Q|f->}^$=kOFVHQ@I)4eIxD2sb|W zer*(h_f76%CC~RhpVDs#5uj%3VfftfDo?PZUoNC)6FByJ@f9Up$4un3dryk}`N{tU zerG@BNEq3lt&?h#q&#E+11HE<=r9*ocU;5IRPBk+5!{TST!SPQw(c29jLC3pH;?NW z{3?0?o)UV0e}8?lF3dyb`f0Dhz~S0gv5`dqmhYjc2=V-Z&q3st zJ!CPDWb*2%y6{4Lufy$W3ucFQSg^9|hKB?Qc0Pj3cpPYLMhB+ ztwe99Z}suL39~r%2#Kpm9*!eED!fpVhS*7I7As>&s}lf&G|FtrBtRD9LaKH#yowdP zN`9viU+bwWd8Zupj9fY%+S7BrCd2>TQ~&W_-q;Mac|46zOo;Z)MTRd1pP3s5;&QUG zW(j*%m6h3cq@-yte**!Si(_gv3DQe!gW=o#g!e&o(d~o-#n3kvY`-T7wX~m{Jhy&s z8?NnJ2rb@p#Z97;KHdMLK8AXK-TXI~ zNa5YeAOj+uHa+-COcQD|QemuPXfx2#JcJnzUB!O+|9#}A0p17Nc1I1GsP zJiLsrp{m3tIT{T7v;{NeQlMh~CAlcePvM$)e>M`=UG@Zij*?B$PMlUYL5Wr&jXAZ^ zFTx`wFC0KKU#x&CXU>z0TG-)(iR^wzjQ`U#ya@?!>>loi(mbIVQ4Ch@1jjVLDQ?k} znp+yJs(m5RvFor^-Jo@1b)Br)@GPP_s%*F*YC2PH+BNk3>0M=$3X6X5W#7MtSIHf9 zp-I3$Qqak`o4G3}Om4CHZS3; zYLr>6LiFxp6sSqi{CmEZkk-!}S(21Tst~a-eFFo3^Xa9p6ZoHNkcx) zlp&*x)Qqj*n*I2mlm?nz>ih9U3&@t<<7It`%A!Qr{T`j>;ik=J5XUcL1MT2C>Qd}8$yZHtkk}#u&MH*MW*>jYTCEMg zA}hz7Ch@Y4r8|_?qe&+%%(8sC6mphNVp_2{)gzF;`)A5aBo)1Q5I=MLyQXEjp8v^l zfKi^VT-7%>FIm?s^QA)L2HhiG2@Zxqkl;G)e-tF@>WO7#2Wt|;3g0Ts&ARK$toU}} z7ilxJ78Pq`_~)c_)-sEk$JXx$^N-}lKS(*oDnQ=y@W!y#He>{k&lGNRtfdN#PTO<}c143q$s@QH2{St5y0 zn9_5+F8ruwofxAgp||Ct!AkRrEp)R;9&n&L^MMN^Hi|QMULZk!iTvyj$p{lgVVn%6 zNL{SuBF1u@RRa?upT5t4>^YX~P2b207sqN~X{<_wNG?G*UIznTM6$(A(LQ|RfktNr%#J#$5Vd>u3(X8Zjx!2*c zc-XRK9k>z)j?^L^K}YYc4JL}{Y5g^D>RhU7XP`&^!$+k`zp-L%Me4QQ4;ECQjE7GH zig)*Yb~e3zV27S-H^Zbp3;%2Vpj%YsyXOk{6M9BK+ zU8bbQYDYM%s;&&0akq8k|I{T--S|~YBPN#c{eUEsrC#H0tKY#0`xB}QkOCt4 z0g*1{hU=d4rYriNU60$d!GFA>ao&JpU+p0BRq1TW9Wfd(3?Kw*Vw2h6p`e9G)Q)nC zYl)HdA@(6|!JJKDylIuTWW2^iGLUsv8{eXVWJyQ_jY1F}HHn#&6s}ZBQASd)RIe1U zinfY5kN^b{5sX0Hi$G_}d@S38Ktr%U9@rB>GeSK8L68Sz21$t1DA6dH=@#h%xd6i; z0!;Ls6yB(sz=Up6)Io03elT4MI%YYAT_9Lo*Yb;oX$%QTVr?2NUolt-4NQVhf`khI z_LDk?gCu|us~GNXL?%SFFik=!1Yn|Vin>A|MmH%Vfkg#gg*hjyT(6k+BpgIm{kL7m zKff-FL!ob<=Ar^#Bq=Ea!SE{-Ks4+$QY70^xj6sjSW*bB3Is5cMS8=; z&|mF<6J0QXz-}}YuuBOro}a?^&Ont?hLMZ8XD*@CaX0wzMBmUp=VSiCQA^@n?IGB1Mi$)^x`{{2U}1L18(DZ z^WS!ybw9I@hrF`J0ml)73;6ip?JuSwwkHJ_I{v>VGYNz1&VC%O=Dtf5_PY-*w^2={ zM8s=tw0E$zyFK9jyne?ot+{XHu{xl+*5b<7EwtT@0L6tMW5ez(9-2fi=kl=&-#EYt z*Cs7Lkmb}{l0J%DpC5LK8eS!4?~RA|5a<28AHNS_Y;yXdGoG2EBO2hJ>;CDnn3&vR z!U&00Kz^8@VQ&!ssXpD9*JdDi+wySZbED4sbK)}Z=!FuGjycGsmmi)3v#~>&o%itk z>Lv*84Efc3gF!Rh|5sIURpQUE67%i9X+NL$b~}tsk`Q^C)efvoZhsZndUIxS5#8(z z+H~D7cH|(@0JvJB;Ax2u-xwNwKaYEN|7<;7c6!_H)8o)&$aC|!vNry@XGP$}3TiT^ z=P|1t?RsgC``?BV&wuro|Uxq3;G|EfI#Y_^Bkye?jvyLhHNNwy>6@>Ve)_R|w-mkFnra{F`i7XeLA|jizh{X>(@labv`F9jZ^F6nUi7+0nfi$)ks42( z&y!g3A}l|>^(vo$<=@->-~im%YRN>*H0=(~b4@bq@I%ho*HIkY1DHdSU$AR_h5e zz-_?G=}Sk5sM*dNn-~-Jlq=R>-7<(;dZ?IHAJF8b7#E9n1=l|5trx9OL=Muu*V|>r zRk9Vcq$ej;b|oWhmddc?N({xr&!7*Xh+u4vm>|-d$BUFxqD`_-QF<@0%*By!8>-$r zuu(;a(?u<#Ltv;ULxEC0(yfug!kUx-NMhBV>bOo$pD5GQw|1aX(ba8sUTHTd<&0#@ zvaE~x_MG!hNhM1&yUDk1ZhgaNyXL(mIw>o=JQAZJBZ0f42#I*#Nwia!wSwMR@2j64 zr!J>+YuJln-#Mf722H^uNvm&5K|7>9Wtyy9T4<^s+EZMyrv7prVA* zfkA>a+rrHk^A57)IP%e_Pa8HRzcvx^9Ca_o7X+W5my+v0zH2gVRnmYDlf&zdn!Zo# zH*ejy#)Ew^a2`+$a=pa`NVwn@6SDD+-e(8+sd-P=Ht#2{39>Z&PdgpDTK1i)7a>P+ zj})O_EbJl z+7`@f*$tb2z&(CK4twFF>-;uuTSBi|0x%hLkz9w^QbsQg4yR4xsMbo|m6|y{OA(7f z#+$AoOI9jiCU1~3oG*~E24`3jgh{c2v1Fda$$lg?7WhWfe`6<$lBy^W%I~LEk)EKp zmC@de0=y?ah?c!gm?BnKQlbR|bLW~1%q8IQp28@jd$-E^&85j2o@-_BVD;2!6!94X z2JsZ5wniQFJZ26U`vjMv$kPzpYLe41>J7pS7XkwJT7d4jPNitYe(r5Vac)v)hk61m7d^aKjHYQjMkG2eLCpWId zNK}1yrtL&`FJCv-g+cGFXVx&M*PX@7$H(Dc!H>UwBp$CeQD$F%Uwl8lc}Ii|5b)e+ zZ#w}3q)_7;DK=I&+aB!#y4;A^Y7kMEGj$&FReydzxh^z7{sf;Y*zd|1{wDkQth?lY!< z+lMK?d%^g(Ek}>3R`bPd{im^`q!Ghs~7^ zV|NDoj@NP4d@P>AQi=VZ%2#iYQ6~nn7(Q#VUeIG)(|b4_bT;#qwl=4bYBQw%NU95E zC^9omsVzcOs>@C;fCpU{qQz`EOMz=G`5?^vuAJs^T&O879#U|(qmVB!r`Kio(+znd zwGThY*U_ZibS+s1EMv_~v*zvjNEtQ`>v>$9y{OHKT&<{NDZWN%F!ln$yka6@;33_9 zU_t_7A|lF{gRRM4{qCPGUuuPzNJX9Y=+U!KGN_l$J$JLCOI~NM5Js^CbqYA4+EM7X zS|YfTs5}fH9_NTEd@7sGnAjkQZTFg9lb6qA3JyAgAro`590_7p2mFc+3b@Ib`3H^o zR}&(>J+gWCFkkKOek7P~=sH3dFG3pyUp9y)&1kE8;ouEj0MA>J%$~s6ol7zXq!Q-2 zj{GxO&sTga$}+N(6%3314g-%u1FK|&A|GfY)nW+vj#g3(d{bw^%I*VsPrcy`I=wfmj8bWUDH5WkfS;L?A*Ep_Z#y-vgix{t+a@=&*r@H)JnmTWP#0)5w zJ3S9qB(<k^H+AB3U zT7<_^e`yZQ56#j5Cs*i7knN^$Q)vdu$K}gZ>#VE`9E!xV%*~4~(Osu0Aq-*$YLLvv z)Qie?2l1p7;qrKmMzQ4xt{dNv>7W|A)~{PA^w&p4Ys|eNF>1ShesrhD5@;B_ia2aZ<=qSh%QzLZvBSjK)h;{LPWq)hxBy-aKe^2=t`7 zn2J$7&c3G9g!P*9_C)6#yC`vBY$|W>r~9j^W6ED@{>v}Vr%8xm@&YtJVYyiz^7(T8 z!QwnQ5ubgL{0$SHZILCf>QeU{Rs~-!BHi6@*xi(Wl@|Qh9{=KPk7H9_lIRDX%=7c} zjWfd7SBJ7Y-h^@AZY7q%A+xwKMOslvX)H_q!M(kR@e|D2Djo!y2vH@!oQ_Hc!_8b| zRL(c6(h7Pr2{9C4iTK&ZOYK7$hr{Fo*eIIn9Ltk!?XyVS^BD$Od>8E))fvYsS_6!) zL~%9L=ZsRvPd zN^?xqs8ukiH^Tx5mvM132I4xKf|$3+5aPgFF!eGrKBV+Y^Ey$y7+2+Dlqexd`Ascp zkeM}4RD^ttMp@a%U}sY~fmNuYD@GRT&D)mB!@edJPm95&;kjggIcq$iIAdW~XQkVF z;~)D@Z~vBFtrHTny}9PTgjGzCqNO=Yyg+WevbtVVJyg5qQDmYg zGNGw1;Um#GiOc;N#lXB1(zu6ffbGowhJIQrWB=<{=JLkv43WaGGH+{aAah&DI7RLv-*|dJE?A%M#5s_Vmh5>lpJenL^$fhL#eTTvd!ps z^ib9qgkoknj0`c1*I4otqzJ9eLt@J8sqq1Tae}mS)ZV+KPhp{sW}`N82zsTCU%p3V4RDuoiZ9Qdz9c&AHwF z-O77;+^34SIolpM&G1H%z@Kx8Eo@dBB=WzcbH?rt;vK~0kI49lK7=T+#6=WY!ad0% zu9EDtzzUt+>MyUxn!0*<{1N=QjFlawO~f>3wDtx1?)I>KMAAwoTY5_t?|QpEHWp|W zizuOlm(k6lVb4mEAl0of0Nmj&mp84`+-6ZiNI(hX#?z`OOTbG-ph{{@9uPt%>meze z`}+gIX()fY^~EJKNF(hR1;7jlq=|vM!11xt1TiKHT~v2iZw#f~XVQUBZu^pkTt$=5 zE6GrTxdv%VD0t!dctDbjZo*&?jkT1vb#rRF{!Ms4zO9^W90oypc1gM2l8snz=)554Fo|| zNHrM}KVU^?88#|n;tz_?;-bb#VcEIh z#o)=lH*ux~uIWaL(KG~!W6ax`Sg@U#-&4#(u5VR2RgEHV%kVHC`PT1^#aPX`=#jtZs zKmH9dBG58lN&_q_$6G+Z#aamC8U3n|IXHtt8pAC^IxD6ABTz$ubT^QJ)_@>5q1N@} zsDPrR@6a*j*m0@pG~|z9Zq(j z)>bwDXPvphtwz6(Le}MWauD*-L=1)~2p1{c36RbPsm znJpW~4LqjzIkzBF%J?i1S7m%mGdSwB8in%|uPu-|TX^Z>sl5KYx;c6H{h70Ce?|}P z4oq^@gxT=Q_@*gVIL>Vo&!%5Zzs_>kDz#2=jzl_0%-<(3;1f-+7&l-$g02W53Tw6~ z2(JmIm>?4#8~$90)75w~Z{$!$5s6*-Jfr%4yy8+yzYVVJykEI(dgre0;#j4ZFw^&L z2vuDvCDI^OvQM5#V5aDs=}J;`)xn$d-dtq_mOq|Z=~L3eRrbXv5dcqmlQj+K2Jd(J!Q8YbjdnpTpQbORqM#E_WX?uKV6eD?k6C z7a&VOK@`slY);vkHZP7_n>pA|za`DndjHmGp!j=po?SN}RVB+~<9i$}d2b3$KbSfk zSC)BELnGk8TT(3}THHbgqkOnFg@8SR_LZRS`|+=hI(w_TepAKo+Xp|CRCM}Qcul)-{QG^=;BO)VQRDx>zaXpF0xgbYu z&R>PSrMQTrh>qARvh};#JNYj9O~9z07NtQUcc#nAshWZd0|vu#i2mq z-G9PxlsV9JxP(6M*~;agb|&0L8~WoG3Ex!=`r zgIbcsnhl&Re!4Iu(B9DYGJ5*6qiB>BgB>g#h)bQ0^c$BlqBO>vDx_OeJ&*m16rX(` zy&1c5R-o)EeF$%2F!NXG;DeWX&y64#a-HV@CzNgv*OsFW`4p)uPQ8gn_8a4!B^Mzk zl`Dpp6h+sTwqKm-+n0vtik#~lamPz8^7dnOR`O|53m& z6kU@G?xgaGF-)zwGLZicu;G(pzTvMlnerIHRZn5w29zS@JUM#0)fh-BN{(eG&MxEs zq7ahB9tJ%sbkavdJR>DP!AQe}QzmXAPV9880BglwXm>n$=5K&-bMHzMd)&k}%C;u2u(e1SRDgmZW@$AE!7!uoeiMMF^l=EEOvBi z^V_wVl7RffQF?1M<{TzSl1e5>3>VZxOS73ZHF|X!WDCh~9AGA)bEf4P^p@){C|G15 zwIM^m-|SnYBHX~poV_gvMMTuBhH0Ug*sR>@jp>4t1Lat$jm7$rj9grd0t zI;x2?Cp$d3+bcvw13p44FnIrl$YoPTxW_B!(H z#Axb5ITyIuY6?XuG=fAmUt9wbfd?ohuaT63M<0v}LV`NbZp12$yo_erp47ZZKq*M|vDXygDFfKh33Oz8fp}bBTUs7x`5H}Fa6FHt{ znk3hcOiZH-01opFI`B&+g{FW4rDAxi4#x3@aT(;~>E-cgEX3rJBDN=N$ZRkJT_Rft zl*IM2gazqzW`%ph$AER+M5^QORR91NE7T-hghUz}*zyD-khTU2UeR=-p`}Jr8vkQ8 zCJ?0>#*RQAoFXNGC<$OJric5mfpGa**iA7L6%)L$2jAzwFIwyOiG8eLhfmdNu&J+y z@$f;0k=jgM@%jmK8C6LrwSrfCk{nW#_}oN*)IlVO&fx$U2!R9<5tpF|jA%=Nx5vhU z3`USo0-{w*w_!Ch*4q4-A?1;x#gkYOU>O8N$V&n6s3X}CY2^W+nA-fOW6IE!Nb^hw zxq4+~xBy)ZQI3TH9$i8|5*dN!is*{l55`RZbK%W&x(_!SVQ#;Oul`^{2!ax&*Fh|C z2!KhUISxRC2>QgQprVB9qnXA5jH7XSP-w<)6w}7A7(BH5DgGj*cNf{)PvTcy68X1Z z)D~ZbNw{=Mx+L;Sc+!mE6Q*-Cg)cX6kDwoa2g;AdA9KhBN{O6_g3$mHrY-{^E(U1{ zjmH=o3XBH*Vr!m>%NK-ncwjx++$5?9?!e~c0_ub$02-K@Wj`TMOb$(o-hrHQP)B2J z9!IyQa)=`{{C z&q?qR=T8t5MhHP5=AI35ddW1{119(M*nZJA-ZsoFT&Y(m;30O>eDdm9hk4Rw?n)M3 zg_AM$yZ1t)zJ@6agUAV>GTOQ)G^{>Qn8YyN^m{Qeu|`;JD#<{X(i|#~CC;6z!R#F4 zK~d=__Ds4#C!ul%PhvVQG-}8x79LWSgl{#ihCHIo)k5+*G~A;uRsj#RgLXz^C8?kS z%7Mr!oTM14P-U-E#1NCdqat}PSj@R{<|^q*qNP>C{NHXp9C*kEV5u~hP^~({?ZJMn^{>`!J~R^rttH^UT_L_AY#XLviSc zJ~SLfvqaey;al7%X;fI8WmGqB_VYb-woPk~gvhb*GTa}+{^3$}?T8RRh@}2MOPpwj zKirdF6E0b?d=tr|4_8FH;P5L$Ar!4ui*s{J-=-ozc!_9fyvCGI!B6=SITInHm#LvU zgX_L$`w+f7r{O-4aQ4x1$GJH}X?;88*LI|JUH(E5n~f#clv0p*2ozX%Kboq;7gpxC%>Sxe*gh_Rd{-i4V=#4mj42eZ zSj{T2&9WY=)N;2V4+!_g-3d}TbN;$TRJ4_E;sn)u>ySJHH~L~nXfraAa5Xb0+sXf3 z`AfS^KV$qIJ+`bRk>Q#cu)+mpAe&4H}Qk$)mWR?Og~w zgXqm;cqc;>B+#Y8G3D{(6XlNL&fYQE*{s-y)7iftiINqSpy=dI6zK@j`S(_fnZSnB zwgcU&Oe%^zz&@Zi)E=A`BV&PW**bZg6TaOn6M;`#gU^tw@f?ZouGk6-Dm=Af<5W@- z6R|IB{w3d-3IZf%z`KW$g^@iPYC0UqPQxH6g%Sw)Wtn-8?xd^GkKbFX(Mb*-No8%- zpv2h0PGQlzoWgFY`p?ZC^G2?E$@m-FDhUHC25A%o>Vgz0sm#ph4-KM3^-8=MYX|)b zs`+TPLdb{jHJXe30p0nb#7um&X5SR1#iW2R-brr=!RXi&@jukwoFeXJY_cp`JAy*1 z-a{^l~Mx zq#$3c9a$;Rbm|_ql)>DAW42<^pD4k0b&*hL9n}*vV_)`PUwhKrIrPfvgY-S5DpA}7 zEmK?y50^yNb~M9w9v*J7x4RSIH`hGGYCv&j0f)VLHivAi&)&2a5`d~@*APKM$~k~cU!V| zO6YGWPPZPH|HnSjTubwX`N9RuA7a>$u)&N=VB_nY7RIkR)EwfBnsJU{(!-pT@O>B|Le^v%s( z?er+*VsK+ebFB2VB%+JW)V6}6h_G3UTiur@Q?12R^i1VSj(;*kU$rs{2}!Z6eqv)$ zVl*4ro`9?837>&M7E3;IOC3X^4&;zD9g-AWqpoA+PBwO$3}uXr&sP2He5WjqLBy~w{&Z%>)Ia~|FUmh|FUIyw@o#{ap=%ASWtGTBWNzDn3uF$03z!wJ*)b`k|DawW@Wlb~W-zt5i@Wm6v%v7+bkqtjn9(0c! zWp~|U?2mF@uLrOI=#jUg9;R*Lw}7wA;vg~QIGIEbS^9dfA%al`iMOtAkAy|KOVXSb zT1klU!+yad*%Z{6EO7x`;A5fpwzAJ6z`M;{@4x)H%Roox-}uBF!91u(4j?8@{)k@T zug%CB&CI%Im&HuM3rMABHUi?NGB70M-4XW_>t1lZ{@3wC4$q6^%@}N;ziq2*Z~m*l z#5^XjEK^5`J?=*^O1y}(_@{f^XTj$z>vu7F1RevFm;fC5tVeSl z`S5xGbNve=5N*37P_7zHXL!!j!yyRr)M3qU1i=1R4FK)NctGWHnJD-#r+(&$~( z_HLg>Qu&%E%=k}B*_j8Kfl+9zD1`hn%n~!XmH(g8Dya6S`aZWM=Q`z}^^t#7u|+;M z5bIk;#u$!%Ak}>{u_R25W4st{*D0WyF#gKS|D-t>h)N&s%de{UXcG9qT23kh7>Tj2 z;{-U0H-}91B|QcBnF(*;;D&=4+3noeqZ6U@;<@nvW@5f{VsezGO9ueIZTJrgcUkrb zWQviIm!4vZ2o;M*rEz<5tKW5mH0DS67v|Bj`7(u{PHafpxa7cZ|5NU2=Cs_+pD#=8 zW9bHe%6d%o-^MWcp$GNbiU$-o-yact1V5}^R+&qYdUncc7?4w4R{g?SQX6mNL=sG& zb5Iw&aLU~3^NVCv#^#Q*%}xMd@}Ww&`;U*k1f3Rn?_S%8Dov0Ej{f08m0>_vwxVjB zeiNrWs>Dki)hQ1qW+S5b8uOKJ7Txgt8@Dxp_@kz3dMgJbJtJ@A?cBDv3W{uc&#mrt1b*)$D#5Zgak>DLt7lD*;-ka>=44Ip)1MI5D= z2k;5rFcC-!GGMTxTkhvkC7-T101Kto&rrPyM1@r9%SM~Y(LTv!lcqjL|A9h|iPbM( zz{H=EKT1&!=#!y$^pGo{!67A)-5>d=XOHxZD<=gNn6YG-%NMaW4SavRM6<+w>xo{m z>)=a`FQ=JO#l}R9H&oJxa`Cb&M;bzL+(e%7!?1ri9TOmkN<%-yJ0!Rx=E!QuYKS#J z2Vl$~=JebHW}P}7w3k+tH1@cm?SJmsnefwjF`z@-L_@8peu%tv{Ga4c@&lLI!R-Kr zfMvQvkT5nbAw4$#?XLlX8^=qB(1UG*MS!-TExy_pBXOUhE7yrM8kFfiN|jLVGG3-{ z(SUCBPGE#BJq0}>+Bm8J_8LG+kbyVCDbguC?l+}pQYN6{MLrW6UU-x;r2{~081+_;39VE7%Qp3>ukYK%@)*g2US<) zDGCM8<497Z15x;g!pl-$ojCs2vU_BOv&~YfDU9ohpIWz#|^&&8TEzc{ye&GuMfG7#65p6X^Owf zK6O12Y2US6{HZe4ues64+&1*7VPmN9zJLy~NEbpO8j;wr5!Xa}yQ6oSCA<`T7WcOD z5;N;L#`r0G(yq7?{_wfx+HCV6iR)gEq&o{mn$fEJ^qtvgh`t=QUq zQQ)Ho3$Z;)j3+j8C}UX3@GEwaX!7>nPss}_0Db(CmcjJE#5GJwCEN2U<_`cZbCfy0 z^uhOkrm+c&QRU${Ssv+T?Bs|vYfD5FqZ6wMbP@>Ry}(Gg7)l{g8~PcMq**H+-0o4| z{9$pPiZttBVl#Qb?W5G9ti zRlgk9^#jB|)LmblQKcAs z$)FEuxi=D`Tw+(g$h4OK#Cu>hsl_ChO=~&hUxN3U!u&smL&T4K!v5XJ>}tEA=R^DW zS{(Mr%Qk~c&3r6uG=RN$!W+7+X_|G2+%}4+9L>P11i2>pPIE8 zi`(FCGg!)>J2l3r=iy>HzG{&{6(8-&)KNjvSdWWL<9#QRDsHnF=}H6!c^J$kU0y_q z`j?eIIjUv=c}Yp_Y#cBo8nT`^2xuoU2j75@&(kNrO;^#-q?K~uD{$PGj+nt66&A|% zTnEUG*4CEEXP5IM8}RYkvr!!NwQi!V6@^a@ykgbAW5jcezm6BsyTJXAa&A>S2MWp3ihk~(q3&6!^Lu|tO2Kb|DLa{6ja-CSmUCo zF9{p1;%m+Lh=OYXf-DC*Um+f7{ns8&K$yrM&_j42jXomFh-Y`hcrZW-z) znLt0B=}U0AR2s$j4xn(J%8iPQQX20}o3W*FjyEEw%0a`fj-gMI8xT0bY0cT)pMs*ilA6$C4oE1Ido@P$uXvB8 zkh@$S9_Yau{DOy0%3A*(r*4FUfDy(I;C|kjC;WJ5fjETWt|Fom)g>OUd=Q&@F zm;cAM=U*>pj^kH2VAF%`i#j_&@mBzK%$jfr?RG6eq{@*#CJ z5>!MtqnwEfgDbWuV6;A2;R}YTM$8Wz$-M>#1QZf@adtOW)NA$&YHoJ<2^4e%9FL13 zoievFsndBuwmFT;YR}(Vxtkt7qGc1s#&Q%%kyVk#(B8M!WA)q`$^i=LDYrQ_O9?)^ zNH_GK%b3F5iNziYJ$iL_aq3Xjd)~4_rcqe%(*0pMJN@!zQlyBYlmMZXTx5PA%?b4n$%FBKG*~NNkC2FN z(D5_!=x>h8smOWEVnDN%q34mQzX&5TgoVX{PD{BNVrSL%Dn)^5Pyzh0hN+xa)MXVjB7X- z*4t2C;I~+Ft#l+cYxvtJcsIYg-?Z)YX4gR9VdqXjCZ<#JgevUzc5l0;;6(i?i>)d? zweZ=`TYCAmUxS=}xaAqcYDtNXKidwcsvOkWjEqeR&O`^AYW^cDD1Vbj1SS87=iAEA;mtTfFG*% zQ-yn66y-7#Mq(bbKRa;nr7yea;K5!MQ#B38e9ELI_u^8i|;WO7ixl!+Y}$u zCJR$djB~G(lWj#L<~NpJo{+QU=)Asy{{{r~gubRUpti)cL)JTPS7vuHylIw<4hn>} z)%g2+jilw6oqFpyunGQko+=uTCWLd^L23QuRukYlS38TfZEq&hq*TuF{y*2F4Id39 zJ=i4kv||VM+~ly`(j<fkUE6Bd0(UJ*;C25jbcC0E`qif9%6snwUZfPd8dxBd*v7 z!@KW4Z&L$qnL$TLL7XWwg}46ljCpTFuD zbImKT;B%v_`ZeZFDDtG`wQ$n3*jw)ezQ6Hw+gyGpJXt&970~{RySBD4&*%`HW_P-J zyfW@tU+p?LnfmZ_D*rtRA@|(w{Nqa!d$Y&Uhgvq?V;8Mvp^xCAwP&AdYB1WKuHHei z3-9OqkCr#H;jI_Zoik%(wQI*0s;5Qm%?=Yhp-+_#OUGhw)Y)B;6-D3(e2%=X5upZ)MAR(m^U7YIxLr6pk=V)LsuAD z@N|B)LrRoJk&GVnaF5=9vl|xRdM2~`^T90#H~j9|Gk6vfsNN#b=P=S42N3R+G zDw4Aq0oUUEa5LEdG(5C-V9mSeTXrsEW5%?TY;M45ufRy;a&Oj#r{D#(3iA_|*>Dmv z{IAM)<7GZ(5SpF!zi%Iz&H7Wg+73stY;*x50h2zA>q^fP`S(TUopm2=lwbbE!kF!O zr02Im6tq_dLQKZ;+)rNZEyAwXNrpJvgCC}P!_Kz1&pLNw-qGcVoY-7A6NFwg zI9ggqrgRjjFUQG6O3mcH2516byk3)FTWGQko%8~#~mp-dN^_FoxcUWUPj(;GBUp1?GBRG3${{BS*Kdld*iBN=kx=Lj>JS0au#f3u1D zYvLakQWHgnzi9oed>?Hr7q4v;vMT;(P<(XIr@H8SdHJC8N>8y)Te*K+_O|~U@pys# z4m*8zlncPDLN#3e(e!V>QzT4_hvFpy@Xe}Pq)4>sJmp-PDV?;C9g}%3L=%V%HGWP~ z{d>>%aYp8m44(oHnIEUmgg=mTY+yNz@=Dq03`-ZT<{M`MFv*cv_l&7J-2=X5Q}I$N z)Jt8d)Y^alHQoz#=$fDtE8dITYEbHc_3ys?9r9TQZWBfCZZ#`EXr(i=$1$hbj&xLz zq$Tz+4Mxj&zBtVFm8xy#1|ohF&ZG?}nsP5;tf#hBHVFfPU4AEbU#UuvO(QVnC;V=7 zbUi}1r|&S<(E&nzuO{a=A_W=%k;U2bx5Dzsfx{V;&is)HJjyQ{Ne52~cs7IL zTgT)>4wH`C(zT8{SELoS^7JzGoa2IA1MY%CLi>BWg$-M>)Gahl0uK3cNzi;>z&n`% z-daOnZC{PwpIj6Ekye9)?%>gH{%t>+2Dp^|Zgi8AV#q-)_q=HF^Pe&ZwUcAu=^fdI zwtzxj3P-^fWsS0%9NUZZ3)2wLmb+LjXwOr9zt8f|f167!cxi4G@AV=uw)p0Z_$k#hJ@CD<$g}^al}c84MJD5{><+*m`1vYBUJPl> zj9a)7Xbiu*=sVm6sSG-QQDFMV#~r`?M>b*FZ4!gh0OXt|9TdD?C35hpH3^kGVYqB0 z$)E7|Bqbny227>D=xYC7*h#8+q>2%QQx3&nk_C6kQy}3ta1`PNOk8?YTUq6sX>ei_ zgwcOCdzc9o;jSxHdAt@Z<4&zJu=e;$)1wEF+2QYoTI zn?=i+TVXN8xV<*la;56PLhfYMm48=Bs`%7DJ`8|dpZul#D-7Np!!NkEjR-jzfDF2z zG3WB(+fp@w&yz#XS~r4*eg17+<7=Vbzm03ESPt@VccKkkF9$BkU2RZ$5E zuIgFt5d&k)EBjasrMmX{;D618o5<++Oh)<*YtnaRVC?$xoSRg$r+;!)hM-d>r3U=h zAKHxt#rG23lBFO&4G;|Lp?jiq8Y_+L)ybY8O?+%b{)7<~I=0>vHH;`dg!6)sKQ& zY5|!~7xDWs4`X>n**n=huRU*SOqJc~`}d@`B%TpL4xt;i+(@!G5`}}<`G*UvDg~a~ z7e`XcR%d@`rHv7Zvv6I}YTYUrjmzy#ONvz5lsGK`@~#Km%KLfASFk;8!J$9V+OE*dWqie;>NZ`+0yX!q)#+?A>Q%3vWPwPn_L8&PIc*gc$c@Jqf z<$f3dwslwTsb=L4TfcbF7Ymw*Yb}o263a;$XUC8%ciChcuT)b({JeZ!nUyO6e;+if z?5vTE%3R<}Rs2PLWhi$H)!X_8!(jNt%>Cr6m#isELORgUe6S;D2}vlcKR;I0R3g#*G92vCIVhN*_35u`IKCVsg`t4 z66@w|QSWk|t01vjG%7EjoPK@p?iYRHXRk?0NG)&jAnNgZgT(lS|4n?rDO&f>QXpBj zn<3zo-=q6ySES#{uy%f)#kg*l+NJ!M4_VP#MdJ6Ck_h%InXHU-5}`PL!7qJrCT6n1 zfV(TCnI=#gCHlL*+Whpvp}DQ1qM<1w{!!uY~^IM%E+AIv_5VRjWiF{EnNVUM8+} z7{Lf2w(genppch|>&ci5!O~9G%50@%1~4{*iyjqah{Fk2w8*p??*>+LKG;zfM=H>+ zYqeRGlz&O}eNhLy$Au8g`mY>~*8IB}+(OK`(@jYL?$Ld?0m zuJjqo9$&sCG0>->GXh3aNdPSO{jQ;ngC04uau)c=O=BjZAl4d{h>F76&x_h>RQLaK zaLhmv2Ow5rWUgRfLAS)JR09AacUsXMi);b1q-X3861smCs?sofTszR&Ni1y{G5Aa( zjq6~?_{!I192^`33bB9L69Z$C^>!d#U{7~<@cq@{S%~Dnx|*1&m=sljiRrQ)Egw#t z`ca&af%vODbE5Rn@L*hxf~_egpfPF-7>1H4Gqg*pLLbxWh{F1oI1T-~z^gPRAh(mV zlnH{q+<0BbR&A@;f|#L%ONM;a^AmB!*LHhmX25etM1m@X36It6h@3}<6Cz=Jyxlc( zbO7BF$O+FzPeV^nbZSLKW_ZsBVHE-M2Iy{Bosre{Z*MycZhn;-CZ4(IF$v!YfUWh zY#Uc3UE?d7;ZM$KAl6o->Lha;xly7ZVEs*Oggp9W_#iL`Q$quv)utjbXGC<40^1rj zoQaPVO%WFtjf;khG5v*s9#DDk8ND@IiL77RX}bOkWO-SEhosXTnq?fmvb-9@P!JIS zKw6zpK_yF7JQCu{?jJ-`uk49!B!J2I3PsB9Jnld9gYb1kAThw6GAfCc=mACX|A&W$S zw1!RmjMATFA%yvOn!m6I1Mri?zMp^d_~)?J$|tM;$;CeyE+3cuIdfhcfVG`aqi!o7 zZ$89ND1>hB@GC*lVz6K~708T&EFVntuy?oTXYF{`kP7@@x}7fo)=Ocw{K?3~iHFwL z2P6?;d8b77l_cXQOX`qvLUE$U=oUPVScVZ}C_*t!QCmz~Owehtj5kN444SVb5Fx0L zkK-xNy#1rV5eon|w4)2{&nEnl_|{vCUrx-s1SrVlNN@9;kiI@DmX6t*jm3@?4UCS7 z^@+Ot193B+smJ)tG<-DlvwXS?v9dA}nXEtu`>np(#h1bLHGaW_s1R9l#+0+1^wZQW zD+^pglpNbc>$mZEsRJnAoau$=iP~U9BkeWVf@tI!k)Pfjq#p3H9NMc1kW(aSDFab!t&0469h#&|*RUOEWYuDvdxlq2&t=Jm zHQJ{_J(*wlI~-WdG{qAXgc-4%>SYjY5`#G+64}g4eC=;&fGLZAXp^j@hPs3i5%5cD zh^X8iFh_o16e=J%y|6fG>gte1ie&^O#UP=XsYRKRF|UwbMoT2&PiJFs7{TfQZv!~G zyX5Arr3JdtaucFh<#H3BVO$Ej^4atCT)LZo9kZ%;|Cyd%mWnGfxWM?6sqwM4*RWaM zi<%$Yl+QikP4B79KO;GC;WC|CfE~A!T4blW)t+(WN8|R-Co8H7tOdWpYotL762EzR4rg;B%J#8%DbW53g9o`yH#;pP*e~2m zO)I?K@TtaxuKxKm&~^7^MK^0Q=gT=Q!Z@h4#@`9nKzkMicFm_s9X+#XA&5N z-^z}qTD|t~hmS7KKz=Gt4%=03G*YsIZ4e1z`n$uQUBHcXx86n>K{by- zJ?x=5CSuk{l-2E+wQI%%pvQqm=;AjUzBHBwzvkLeohj{Z+)(LC<6>k z{vOG_IxjDOc1@EP!k_6v>&6H-G?K8`2_jWIwkiwS7wbG zde>VGTNs?U9(-unsL@em{IcmTf=c09`CKf%4YIk8_D)bj3v`nPa#@GWdWi{?@*YEx z`T0eN!P2#Szx~wtdRH5$_elw;w&e!$!p`?XK9>pXaq#`#me;Vm;uF+0kk%&tHc~zc zi=>R1SjSivbr6>tJ@K8gG4Q9LwG2JE;`%hjoYDvCQNj)>Hz~iMlFf=QbBxKk?v6i2 z0k4wMRMFNWFlYJSMU}}3{OV;&QZ!$iC!QcYUCZZO|6l}qh&z*PXl!U=u|8b0wN;su zxcQ~p<=5Teuv947g;<0(L;-VV90iw+A?=%kpA}8OX@aq*&A-UC-fvrxVa+swoF2x= zEJW0xMN+}daDT(E1M>C&sBBYc`AOQN}>61 zntaoys;&~F^Y>^R@=?;6t+2+?2@_Yu1SWp4p1RwLt+}@8M!O=TdlaRT#T8xT-4;`M z@PMF6PmNjnORH}< z6(rcG49ZK^&tpn=;!%YOk+NwVPP*M$>ug(M$AD%9%#X(5F6#P4wEanYW7tNmEk8XP zOC5_cP50FtV2*JvlP{?|*J{YL8?s+`Gc&aznimXtbOn6z7#@j;Up&9U!V+Gf(hv@6MtdQIYO?9K2b~Q|BVNBkq`G;BVIdjJ%bX zc#m(ggxg(pyf0XT*H*LLB~|q4z&nxyljz4c=7h9Sbd2vA;91=7B)NPt)_ifK*udgX z+L_86g;ug|POI&n69NjmyGzMFQMj{O8Q(~niCgPHP#atGyk;)V_ha1ReHC zJ0l4j1MkXKC1Syie;fs$(^dpARUFO- z&q*q9Lub}h>c8S=zwSBsF5@1Zf-jXa9K|s$(-xKA^4E#iE#A(gl7(W*7h8bQj4yYh z8kzH}Bvo1E&dDe_GG^se0DD=z$Q*?n0|il2rIuU$#2L|vLE)AV~Y48 z?c-F1x3JEb<9vL$ylrlU$0Sh6uz%7n3Ny<|nH_6nBb+a5H5mC?0+Zn*M^VLLz88R4 z)=>Yk<&}-;oZ!$jw^6!n;)=8A61g0EIbr`sx|eHPA3xUv#Sinr4*RxY^Fg5`KKmfu z<%E7g^|?$Ph0>Y&!x3))qY}IN96A7fNMueBFPw8u1)cb7E%at{*~KyuJgCAR%_3;l z7P3;FDgV`Jt+D!NALITSx0Z^NQPw(|uXqN&f&6(%YH?;dkdR{EbgsQ;k$ZY$d4sG> zuyp2|%y=V`HPPOqpOV6jtN=ITvJ>~9a?+h-IZmh%#M=Emn9JlCSxH@S{)`% z7*xyfHf!o)S&@BsOeP1sq78i%WZ{slpvra1_0_i4`ck2!Pb1AXCp)C0$;WSBgfreu z?x3U6g`AN>bDxwuLljL`F11@FL}?v<@iXbfK40XB+(rl6D$ZX-)FHo#MA7Vnb9rW# z(+VHeXhp@1K);r%+MGlK#rKC*kXBb+44rnce`WH1^Cw;(Q{y}2hm87#O%bz z&Ugax=Oj%q{QX-lTApz)PCBaCMpKX{ppU`@Nc^revbci?>1^iF}+-bVf0Zvy61+XFM03(1w3CTMmRt+ECtBbi~Iydqn z3zN@UV`Tc-upzm`M*J!Z;;trt+mGALEzcZc#=kIL(r9y*H*wlc(ZVu`-Q+hBZ}!x- zblbyC90F7#E{%E{sWyabhPE?1``o|2vZb^^^h>~Dv(x6uuoy-zzMwod>I=Ew2j}hH zWKrvl3pTqnP@I7N+1)GOP9`=9AiYQlS%`u#^u!fEJF7Fu`YlmYFzw6?1V4uKn1JjK z2aF-^8K5s*(#3&Jq}V>~bbS@@7}y*O^Ld6wvGJ96y&7`p8N*~-9~`TCMHl%t;}W~k z7)F!4^XnJXV^73H&e$)+Eg;#?(h>y8<9Hm@Z#F?yRJSQq0xj&tJUN9yuPa)phgj*l6Stylh155hts|Ed^M?yZ z3!P&ecE%^= z_;1C!+=h03|8Cbgy0fs>tu92XdD#YD1QOVmkKBGQMkOv+zjf#S>+hs4Bjbw$38~F;vxZ7y~{_o$7 zUSJ%s@T1Rgv-Fy{-i|+|Uw89G%d1?D-b=Uay^F-Y3FkJSYRN)GOIHQ$?e=gOOl7@O zVN^hMCmM0_M^bm_#TPuc$EP#U(_Ilh3gB1w-MH|Y`vA+rIlhA9^7-u8XAsyp(B!Z* zr3QL%@K24v1VQk1qlA2Tp$oJy=tdY6dd;gG1aYo26D%-)c#?#KR`gba0=5P6Hu8N3 zdq9YTpF3Pu^(TKOr8lli^^X1P%0Ew11RV~CA!g!kUavsrd+!a3?m@%&sySUdBuf@y zPXz+8(faj<(#_S6i^8;_UKY*-JZ!XH6J((engSGF?#lCX`kAse1EWfakJc8oVPCWu)a5PStWKO%L|dBW0~`?#K6Pl?wc ztQTH+?ZYM6O<#B4U-x9cVS;!($+lQ;(By?Y<%M~!WW)WJ%FbDG0O5>d9>X?8q1+Pt zTNJ`(5*z{w?fY?>(lmu$=gm|VdN&`R)cp2j5Be-rx2*3P!dxaf9|q5TWbL@zUER zK>XGdLwG@0NHzB?aoH?Iw%N^$8&YkK3Y-h?pSDvFE{YuOK<@iT#D>?5AgIIRE&+7k zM@QhvzPsZr?KglY%z1NW`ga4~ZtW~eEOR_PN4<4nwnxdYdjEX%-iln!tIN&f`+Hu$ z5fZ)jOAW5+y=#qwML`Ee_M#U8d9XUu>n(z%?2vEAhx<#yZ`vFdIKTLeXCt;RKANRi zeC?Oy5=S8MopaCBi=;yAwJkI+vtmy}x%Vxkd);r!RBBqPJhlDQxFiQ7D`t0Dfp zh?{dfi>IRf8(;6Gp1ZZhwjooGB{`Tfz|!oY^>Mc^wlH`TQ~MeZah~Q(YW_yTx84o% zS4&FRNo<|mPgE)Rs@>AsMN-}neix$=QP1w@qTq)a13y74J-yM#mB}wx;8z~?HGU8r z#8Zo68-W57s!Ani#{v8dB0VAaXBr9$@!7An>E#%9h0iegq>U_(OZ9$)?_ep0!taI& zo-yffKJzp87&w9Pj6DyJc?G(fPM|WNCO*KPM!N8KG;10US%L~^u`DD2zzC4y1J@j9(I~OB^^ARUya@B zHx<7h_E_pbK$y+^%FF|y*A{ZsNtv*j?9h8*Doo&G4+J4XXaMicU}t_7CdMlrZ~_bX zxj@fbc)=9h?yknbtnDfxfeER>0>vK11M4}QVVlS*-}q6Q@vuAT6duUxvifXBP7~6U zLPUkNcIi$c@s~R`&r;xbDVlD_^b=)vMfZIt<9h+J&_&6+B!gQ<_}=M{=Bm1O=;^x! zAmHmvpD_IPez72}!Q$?AcCC}F_eK^2_sX^pho>6_@N(%9Y_`PR>3LB-fk-3TcYf3pOo$fOB^e7xc8`p{oC_9#h33x}RYxpzu&A< zCQBg}HQxxnhwlr!apE4rL#XIhZ--)9kHQey(JV8+H-+4!I=5g`AfGY_-p9TWX^`7t zS;>c@M1@t1-HH|h>4))HcxP*iYE_WS1qbXTZC+Og&3F&R?J#RRxm0n%FM1)?=->Vx~JQdfO)~NbX86knR#$O^H=AA#m zgZB%hdl6e>c6z^v#9rgq+>gSF0-e1a=FQBsf<`N8yMtVl=OW(XVZiGAA5$#g+mocj z7NK63Q8aDG?bitwrbksDLY^KFu-k1OP+YB=_XE%U0n-vU$Mt>S0BOYUGH8@`b3Z1r zAbUt8o@?O!`L3pPXZKRSIZox;HJ#s@`(geKR}dY%twk5^FtcXV)I8Aca7IAuUwqMJ z0dluCFJ5rJ9hoeu9eo<2SzWd0UH!{Iz5Q(LS?>v`>)~wG_C%)MW+JyBx55AdFP$>g z6YuIrOEa(XxD$qNr{v{z2Df;rI9KfS)OR5pv~c`r(e?Bvek1oR^mJB&_49!a+a$wm z)i>`B?DOgzvy#fTO897Yq_Ejj@w;`C#ZzeD_MLET&q0ie%U96%9+S?_=UukLI8)ae zv|i`4|!kfogOm6#NLZKT-X&o9l!KH zD0hGzn;`TLAC2ZzoxYwN#JH@t++FUQU5~!rcv`erlmK;%u#Is0#&n87lY^dDzkQLf zMsajhEq;1BUQq9jb#r~)y=dXRq`0S9_@T2;!|GNo(1_d6xK>} z;=1sfkS}cGWQo*w;^^%3gR?RGfW(9}yB&iHnta_&(SGDrM1=!D5=ZGds0Nh~*V|}! zQsN)4-;LFZE}4Y|>7TW7J#-mJciqRRy4Li^a7{@!IobFv`V`%nKFcsOX*~;aKEXNY z^_`u?a231#eRMFNvtVG_WN96GBsv$;@sccLvzC$wzwNlnS@M2Nwa!A)$u(LIzN?rtc#=c9(cr{&E}>v1rgYHA=Vq0T6OyGd+7vOu%Wi9IjJ zU~4~L0-k@aO4oik4O@z0Rj=yZ${lP$;f8_!Ko#+?NHx0eBEX*3)y@OX9EHXakDkO zIn+$q&EGZ9{62Dc=vEbU2tsfVoB3b&=i|=2JUP0BuC`uKbaq^?e0E!)sqK9d$lm9T zxm(b!^89gh>?pbX6;J-THZMg}^{w?6+i#VJ2QxJ5s!~3KTy|t?3qfrzAtwYFUbPRm z>nQf#Lf2F-Jay0_Ug3c^Y@@vu8zEpgp}GG`l3f5w5l>t7Uu=JAKaGQo*2yWG4r*E6 z)qc|hIa|n?L9|lqpi^}o%B>}RWKD| zVt0-2?G|(w2DgYs%qB>Asy8%A&+5RA5Kr!(Lx)R@?AzP!encd3995Wm4c2t@nTg-P zKsVV-uH6R}#`YrZPbyyw92^ig?xh@UA8MKMxUZee}08xNeW8*J8AeJR_YUHma(?%O`3k!P z;9~H!wkyyK`_|q)xLIIMbix)tC?+o~yLY=l>q6mUp!K$|ywt~QEly7jsSdxAV8Py_ z=R$RK#@CfL7!I1CJ&rT0$B;eY~S#N3Wz`GWO__d=$CmHStILT=^) zsZf)~+oqzzs95v+?JO>;c!5ivLf=tIgQc*bn(bK*r0|W-u5vQ?`kq(>l^u`qU6OHs zpTN0tK|tFO(>sMheKbq@LH8v!5BiUr+0IGeTQwSuaA284_eH~JMKSEX(49*=bDX0# z8rRchFG1t^rBzRN6WF6BS9h=VXyTa6)^ld}`nsx`Z9`6;_((ioJKAdJ7Rp*aHZi|}-1zcZ< z?SC$UzZV_u>qNuAuL*hlUZQCs<X&-e{*96rG@M>UoKmJsm^VhRonRMbFuDJ{*De z&0<>^q4(B>6Qh*MUI!m7o+i*;e|yM!_c6*keW(s|42=Q7nWLkW1^->2AXi_>Ja}o|yIO$5 zRvU3%P$#%R$CK-GH(bXBJ9zN@SR)?HmTG3SZEs4RYSHO<(TofSkg`7vRN#z8I-_&Ab=Rwvo<2DYu+WWz12BG_%jLKf@~KQD4y;OP$B`b@@6 zonc3b7h*& zsi25HRRayS*9EVYba9J4j>oL!kn!{$RoG=vGu~dv5j?rY@g z?Yeo{#S96WzKK!!KqF$NYL|yGMOvw4Es4|nI`u!TH?hLUZoxK#MZuoRu7h8WC9l=D zKa9y1GsP~|ZP2=WgDmLi?p!J!fnlePQP9%mCBN<(@Sj-g^j}&I15|l;-SKxgbhpdz zJsbz8vg_8w-cgHIqVC+Oa1j{d;lf55c{({c8B_cC);{lP zD!q~)2|{sG2D?(qu1ZzVb~qCzb?hH;C)3RLo0vau;P<~R-&<;%$6M3N9PuBr#l-*{ ziv?b?nu~aB9*?pV&aZ3B8$oUs!lbAD`dkufdv0?1&Mon=UDgABFV~8lCGu=|*ihIH zC)b8-rtMo8Hx(al81oo?4M?QcoX8)S7G!_Gq`qCupz4wpyc;7h`@OH|jtB!S1l~^1 zz;nuJr=usISZpeJdT-K$HDR||HINfGx9T&l!qihkLbP2kf$oXnqqc<<&|Vfaep=JS zfO@&%Ws71hTc%KHa(*fzx2y} z(CSRJkMpg!7QV?)r7kAirSy zIEeb%=GeDfpND?oP(L;ar_E<%7Qr6+Db&mLPIg+RQa&p#ZRYt@_8}xvoY{SIlo4=p@C`5L~;;D<`gx|P&4^F8ySqe6Y z@bRC6%PA(MYi{^}Ulg5a#FW(3T-tKYoAn+mXPdULRn7;wZx5YtSU@VsvY$=6U(>me zd(-v#ih`XJ++S#Wecd(;(t0sb(Dk)~e@WS%Jklo*vfK^P%_nj1D$za`Zx2w^ZNasN zwX|G`U*(Q-S6$!r;2(Swr$v%}oHby(6>1SGs(;;+z+)yB z6kpfm3|YMwf;fKse*pbJ0>8erWx%f?8Z5(6G5_ML#@1?8fhSjN`@`n_UAI)`lkE^_ z7)JiYX_04p`@7oP0{!j#59BW_-{0ES-rU%p(SC4OXT{8d40j6v7}DYOmQKI*f=y2x z>X|Tq!P2Em^CHCS0l@7ps+@em)mIgH8^xN>Z0m14dOSL{KpPssPNy?FJ9}XN5i=YK zH8&3$z9S);lNC>Y&0_uGjw5R}YE@rZdewz9#>oAL-Z=C;>N*M*YHw;dw0VOu@eeoM zQ0pszmc6U~((~Krw>RBcn*|nVy33bYG3~;erxmqjcK!H?m-cmpZ@=RDg_+(KSJ%(h zZa7r8fAES*kIc%-;>S9AdwawEy#w_Jj&}|QBf~Dy7HFC`Cwu(D>#r-zZ1;BmZ0-6( zb^C%>RCwa4{8+5tYT5bfQ-{qvZoc@6d5cREqi~>Q#m<+m-$)Q-TqFKq2^YKvtqnRC_R*MHcMIq#B-m&}>&@9Av; zMD&-;zhKGIiz++155Kx*`9SX17hQh!1+zT;14lLaLs#i>|(;d_sZagk6VzXnLTma>m6UT9Tz5!A)P> zG;pl(Sa4oR;?;&8>Fhbyyn283lKXDDaxwP^)GLG=@&;>p?CZ(w@=NX1IO#$IB@(> z%f482o-tURowWy!bai#b(p@TzbUG>eqcofS^p%uKGiHqs|?lE*Oe7j zO2p1;y)2fM;X&_&vMHBdHBY(@n5&-HKG-*K zEY_LV{MM%DS9br?KZ(A<>}XT7gcn~w{-KH@p6!bP_m$Tyy4zgy=yLC@n=ZQG;z_P8 zq3%7ez0{fgk!cs+aN&X+&D>q}voC$SW%9Istjq;&Cm=)w)CiaiV{}IH((2XnL3yv7Q}xdoy;bsN`N633;1FFU(>{!I(YeCX5*3UjlnV@+M%GL}fyzznxm zIQatS6UPp3S+kzxxa{omiG@D2pFGG6%dW#mk5*USTvl5(Z%at{89CHhl zuJV%7k{M&)*x1D)0(C2|bZqIgi>7Cx$*QWyc*c;Uq^2|%z{JX`v7Rk780za|;DHz` zo-t#_%$ZeQ4KRD=%<8_4EIJT2Px0vZKz}6Ido2Na{r`>)$XpA{_dX91-TUow;wt3(o@g8cC@1>Xbo80HzwYG43t%6 zPr7Vs79wR%99M31HV!LF#zL|F_7)0+s>F*zkV~z!ii?iL+gL_x6d&}A5tE#HXGc0qUqZJ~-?W@}MI~haG zo10rA&M+SuV?dRQE}A`le1XS-kY7D-eDkJQY%nT@5`ji~n|7~V{qk#1yw&Dr(XOb> z)rS4V%yRnbhmABnk_T4^9xw(%+U5X-rVHr�=Z%Ju||;_{`q z`S9+|Ygk`!Y+-I;X^uaBg`rr;>J4_uX%`h_Waq^YvfRZJmrZM5FCx)F!6 zJU+DqEo{<2xUKAx>#B0fa)l;y3ujy~Lp$u`5Q&6iA>L<996LsHdI7O8zog=V+LkwZ zAz}eQR(Www&DFDt49Uw&3Ue!GHuIV>euD{FR$iF3rSfQRSC@!FU&os(UVd%s+P%$0 zvR6YBPRxOpRg#l6etxA>6QZ=NDB!NF@9pgca>tK?$NC4mnhrEhy0o&Sq-03+v;Mx` zXjUvUe_WL?m=uAU31wMr{rj4_B@s!MUsG0d!GuChi=?UvJ~6$AnS2I$ucCoh@W^(KYFK{!!yNhztPrz<*mpt0GxynR2H0H94b zGYu)3!@(;mYx4Y_QRNl@pj9-nx@!7_QsSnp9zWi*u_GAl>tm2eqGLsZA?b*eE}c`O zXM4EAS6Mc0>J(gsh`hf)I+zu8=Z~+J4o2XcFt#kWt^4TVZfO!{qPV7Z;_M~!GTp{t zrZ&!*U6N5%>C25-VWX&MY+h@RkqLuYxxtsWytwkEy$4^|d|bW(SPb;%x+;TF~0XP9?#5pl(F>z=| zUBiK{j<8GHvoq7_Xz6nH)Yr!bHtjgN>|#GU{8%$>@~oPB7hN$1UH!dZ`N-FIcenCD z<+5rG+yRmXNmEj0DEHbi)#HovWIh)3j;pP9^>ZdQ5SlOn`XyJruJqIq|MSX*2APa%#s`!XNKGG^$&7Se&xbNGp0=~%k~aBswPa%YtR^BzZeLH zj?2D*<2yndn_O91e_qAZX)(7Kgc$|0KmZ~qAWOzfAQPDp%ZNp12XZTlit}>Z`at!x zF%!D?yBbX^54cH8AR!S7$)sQ)SSX4yn3R!GRaIQzb~~9daoQwrFw`n_H@c_K8f>A~ z!8h1IKNxebpBw#oL#WHx-__sLoVVa30Y{3D10oVtOrKCOp|XHH-B?pQiEq+EgM(dz z-iY2?xpYd6ugHfEZ&lHhnNzXeL)?`&b8!tVKFRMvp-`NiP&7~Iy#mwU-g#_$&}Va#9|D9m~3zF9%%1(cv6Z&L;$}oFTec=xP`a$=8xR#;H*;k%ys*Lj&n)`=GdZ$bX7d%yqOy)Dmu{d>Rv>HpE} zYd`ywe<^30HRtk=U3&A!E~y=6B3)Lyw6*;&|NPOfZsYSmd&hmBzH{b14?cTO>+}Eq z-QWH6S8~>kU-+xS?6`3 zBgS)(jCg&P92NHOnwwl2XE-}q^7@cGWFnF=<0K~(5fNux@!<=u{?gSmlU^58zw4#C zGiyWICP^vnE3Pjy)V7|%W1x~&pq_xC(8V$(_|naLc#(QF%lVMAR*K5ldL=F^E$)5 z*c)+${oLObf7fwbx5(nT2ng-mmxH!D^=~e6hzG0Ww^Yo8>8U;BG24zL{ z;*v&OvzoLWOE1V=F%W69{F#0SF@Q*nOjB!X`?lA%d-3KorK4!S*g0S}V{;V3g5(L8UcBh;%i7fMrd2D%f1oD0c_ab`Gl zFNq29i}Zq}E{Wwowfao<jgPWEGK*+U`d6*Om#aT{T6-9_?t_tUd-bx{B&KvFluC+%tPj|C$ZbhPyD-S&zQeJ5Tr{eHi{hxM)c!&7bT z{js;LjJU&-nY~~M?tXm5uApX)nOvTkIp^Yo``0(Nu_9kpO;!|GRF`)xBmS5_g^%<5Zb!>PU-k^3i3UNS=){sJ2??x>+7qwc#d>Tm{~jO z<==_~&4G^H6U*Fgx1+nM?eNhphvSp*=;C-&`{9kdIskyT?>KNII~bjkT9oPaI`SPA z{BJ8)@7;ZP@a>zYIe9@zk-n{`zW%@w&SL%0^2}e~m^k1lsj3>;LY`Tid(%(9fB!`@ zi&@v8bmTj#qo;?gNDwx@`Q~76gY9W1V<76b?mg1f zG)S@L!J~)P?zz0QGPfu%<(Jjb(w4zGDsqYEH1q1hu^t>*_=|X zYfx$h-ZAv@>udI<_6FwGR#){oXx(35ZA)foG`UCD^U5af?hQuz`f-4?-rlqa@WTP%{;RBzz=RJ#ksk;`6X}v z(2s~r7EPbzj2_zl=9_g*bLSTG;yKehWcT5^L%?UvD$?64t9{!_Z33L)TF%aMXi@MmR3dcw!HuBo%S2T%KAY`JnB<>Tj1er?N+y?gcy z4R6XW$n_r6I(Dw#1rZCN+^cyqWQdIt)v9Feh;gYo^65#)KQWpIi=NBuxzU z@$Tj(4<4=}l1+u7g9i`yysz1!@46p z!Wc6c^PraP%l0?}j=ori#yfj<9cX*u(K~(;c;NPlQ%WZHb`La*gNr}^@BjPT)$7)- z+PL=h4X;1(>u-Gbvet0V{>=@-@67fZxfwwy^tll*!W`{`*=?__Kki>z`pI8B{P+u- z-+Xo5`ZcewTmP$nz4V&QwXeU`7!-X4Sw-H#9P@ZLac()9xono-m0@rOhIBY%KHVI{9UQ`KhS%K)I_EsY(h*#Y1-J(z!W77z z=rw)WVXxtKuX=0s%AGCPEn@DRV2d{c4V^i3W^iDdkeomeM$r*wuB@*9%<93t{aX$l zXb!h_?eet#_32mdbGeNIUmuZ9#29lTL&PX&Lens6d2*cFG-}wjt-GaVf7Zad7uSX& zuyk6Pv#6+i(meO^ZLiiHjWx}@vWOMUo!iuXeRYWF@cPHjnPV;AlU?m8tSa<+yT;9$_NSjTdKYPBRe74z5;aTa z1s>Y+)Q-KY1G>;N^NBl5v;D0#E7m=}Y99a$9*6R4@+VfG()>i4K6d`K7lmHky6U_4 z?8w&5n3-8Jf7*phrn(I#Csj`Gd2!2cx3o8}UwrA8uC9(NN?&1S@wls;fBfr%dtS)N zfu3GxF0-G5EzPUPbm+x6tr zJ_mDW!<0L|a%E|0uGc=HTuiK*(fh)d-)?DdUU%`u|90urt3I*x`8DgF`No?s`9Owb z=AtX6O`lfd63Nsc)V%erb*mp*c>n+gkIT}l@@i`f{rdd7{%hGUUVl7U5l#N^SFX%0 z8DnlgwEUrOhF@Rsp|4(5X4i{|D2f&@p0Z=jy8rv;wv{;=FXq;OWgCbD>ck7&M_+#K zSFb-a*eRuS-1V{Pr3FPgCf{9%vZ=MX&m7zM%Wr(~c~53`FU7`shTlS4w!O7(^&el` z4*-M5BPCZBPMA=T;hcNtH)SrIMEf*rrh?W%Zg?#TQ*?5{@l;M@R?`5 z$gq0hEsGW{n&~UO^4jVD_3Hoo@rvL5Dc@movzVBh#Q==ddQ7ck%(O*U-+T1ePk!ma zH+&AK!E?su&%FMtSC`wFGqAUzW!K98d2*X&S>f)8zjFHG>AB#_xcZ(;La*#z`Ge2w ze9Qv?SbOtLwUE)b=l3h>03g&9F1;+Lwy?GJjc307)OOP}?S1FX%uG%JAatLvaLyh7 zdGRA}KKB3CKJrHc9pudW=siVJOEqyO*0w$)26`N~yqKj3-xnBsziQ-V+a@4swxWM@Vj zdi(|c;cdur=1jlyp6Z{h`_+SMA1*I8bYF3aIpE|#T0!OH3$FWU!()H=!gv0H0Oa+S zmVW&1Ik{Tk)FzTb-9=;O&&_&d*NfZ#b4$LPxyetOe)`vE&1vM1yZm2nZ~xQF&wl&G zm;4T=H*5N>|91Jf;yFtfht1W0{m#b^1(;=-8Tr#{uD@(*hQv`?$jO7Qs)_TCzWCfv zw${}zT~d2nO5#QxeXiUYw|(WZC*OSRS6d%@*g#zvnIHM^wDA>rdUxXqr3uu9G3D|* zFYJAJ|LPxqcJC8j0N~@Vy?RNY__Pl)J&cMgDyCn3{kjML@Uz~2>=eEJGhH97S>F`EzX1sxeMGvGAYcM zr*yD*iMOYD9zC(=g#!<4&T;fHUI@BhIGi!mQJ_;02pJYq2+0fyy5({)4?`nrD=vl} zjTr(A)ER4OA6WkK{|jw@MDx0{e4c>oYd`$V1r_B1*U=+ejvdH}p9W#+yItN~R?Kf=y3m(nm=5ANklshIizPZP^apuCsw_RLCrWq0x z64E&(JJP@Z=i9{%wSCc0{pL3}z1H`)mkSF;Tb+OL^$TXtykKl5pcK(4*9Gc@V=kC= z^@o@L=!HKVe(6`9{Opc!?vle9j7awc3MLn{99a3M?|iz$h-#&=j=faoD9d#g4*C|% zyXdgB;^51__{Fiu|J2JnMeRjbE}VMhqN#e!(oHkw_mxe|+`fGIQ~&k#>KPY){<87Y zrjEI+x%tmOd-SbGTce`0FmOrDNB(ncPH$8iE~fLCLyI|b{RP!C+yA!tx9fh;vhaf1 zPflSz(-<`5RXb$w4zMRPm=X~nZ<==kg;XmwH<@IEGJ(-a?cYa~9$M4I? z@?{89lTwo)2_xVPb63EaviR1|9QgfftN#48=QidPV=xxEd|_>E&A5{O`a=d0N9JOP zh*8Et(-|+lZ2Zkl4X^H9^{p?}73N1Gk>Z;BN+y*|tLlu!^hq04x5Kh5(%y@P|$@Dw#Ec(Hd|FidbM@fl?!e!O$fJ-1mdR68Oh2q?V z(*ODqdEqtR7_q6ZZ(p(25e|pu%$eiyc+&1DCDrXeSXNS$o10^Qlbo67_(f^1|~DD23tEU%bYlIOIiVi7TcMpjYP%-T{n=uAW{G_s1SXHG0~N)a=% zE6dBr<>keiHq{3Oq1RtpTs!aTOUD%?9=s3{m=-9{a}0#Z3`caA)9EU%omZ8YRhX9* z2n71t+Q{X0xr!=h%~^8kjB*#_+zf>sfy(mo+TuJX0<%tB%&si2oS2hiG_QO30IST; zDaql)oc_Xj*WEI|COg-qG0n)y_P6#$Ip?1I;=JmqOUtTiE}U8w2xL0Q;gEf%;Vqsp zsj_5DSwU`YZn&oh+#bVWxU=%JN~>mb2dXyJmH z6AN4nnAgqvBs0L1n^Q7&c9lOqe~#|qPH!%238UAMSzb~#e$K4Q%5js6yn@31KvAHe z+}qzDb7tgBSa|9Dxsxh91`vcpTH)jgl_h048UB*$LaQ$#G~|ZE;qiNm#?P+y+u1%4 zF}2>jqMBLN#W^L}(uzd~qv&!w{S_Bocjb(+g#lye=EMfuTH8Ahw+%WR4p089`HQE| z9bc5;$SA2Q5d9IslNC*vQ(c(vA!e`$^LdLV46j%7`h4M-G)>d#_3Ptj%rC5%J$FKR zd4@62u+q{_m= ztV9BN8R~9tZ$Ff5_$CqU}e5sA}cs$OcNwde~H+ocwAD`U3q2mYb!kD)ErJshM`c;zd>2%#&T5ts#h*kPgG)aJUL<$LDdU z3?6I^Ivfsn{;atRXU?w5qn=xrJ&6!($!MJiS(>RdDG-r;zXr#ovai=3DvkNLJ=FFQ=s4)<(17^FuurzC@~V#d?iH{lgAgi+#appWKPSKn^jsht2|qTT?Mscs>+KpoeT&f zgRcBZ)m7z1S&4W_GQ7I3XR*$1;r8T=9Y3yO){OC$W5yOb6IzaGT=NzdWp#vzqYM-k zS58_yD=&M(!pT*+g*n;&f)anQr9(OlhcBma(ws}KSuoDabihbV^XHeAPpK|+AtRPt zEJ`lsl~hb0UyzsWH+v86pq~hbz<7A4DI|EG{lDo>&x!n0o02Q>ya=9tQ`_UsRD7 z4fcgC;x50hpmyo4mrgCp$mCL*2u5zrys3qLV3v`YS5i4`Y>CU6Q<80H%#4`vfs|h} zt~{?S%O@OJ7I2SrRhd)%1vn&Mms0JDNoJ!gDkF?oe_ zy7LP%+j~QXVdPbfs~$IVR%!m&`7?_B89BMRzD!rJvr{;n9#2W_f&~kgOf7RF2RRVY z3dUEL*W~(jfuzZhJF~RBys9AI1wk_s3cHIYj;|h@U(R~-bkN;peZl;i$}zL%PMSDv zQnA+|BZkwTUp=|J!e>~f*I!*$SzS`-hJk1>807gAs>e+zEiiOOIth>z3x#Bi`yGWv z4kSlzIm;XKsn2}0B*Wo$v7VkT-BVONX4=&9fYUHELMAy9Bh<9Kag{llg$@SJY^|_> zQ_So2WMue?^YhDdoVg`arjIWx^&3&svVedgA~*u2g;kSg7P%q=D6@U8oJsW8j#0(e%Ph?nX~$adpMiF_oF_ z+>A_!1dVV@R#u7Ot(rV_((JjF1pz0R7ztZp$f~FvJ7scVsh2xEj=pe4Y311IGb-~O z2xx}Fj@;_XvT@}B7si5)k~!lm3JbDyun_FU@`8%&Om{(XPIF((p|kA#>+1wpXZKe+S}{rV4GaL1Jk^3=8PJOxEt%YoOvck#pJzx@6s7fqa$d3vFM3Wee< z0l5@X0s%;1$Qd%Cr3dMU4 zLEO7CaT~Vp%tR!l03v&e01hN12tmjJIU*tw5|AWm-^&R|NPBk#0+}qy7E6EtwyYx( zf=D6~0ulme3_(gFdsDDW1+t4pw1rcAkq9IaAY%*>5XsJBA^`xAF+@yMWItdaFanOi z009^y#sGi;ARtlPsT3J#3<+3#O`>0rAwwR|83Z6D2ate7ND>5rM36v|2nb0sMBo}| z2mmA)0&>QX5J)1kkP$}&CW(Y4IOoI}Lqrb95aKOC1Ok+jBnU|a2pkAW0>uxLq!0uQ z0FeQ+r_qvt_MsAxee{Tl-j)(fLJ15QB0~;H2ts&P$=GO?5BBv#0?P0mN}9nNJ5ad5uR5lu}AtaoP4XLdF^))4&#kak&Kq zAV>-!C1Z%lfa3Gp*b-5YL?i&lIWk0&KoXG%KoT%QMi@^a3IGI>$O4dn$dEDHIt5Gu zS_lkT+>%5@M3^f2kdPr`j7iCXB%zQRa>fuTem3H}AfBP(LJ{pgvgYLn|Km@GuqQ%t zFf((^mEZc&O;htSj8mNaL!nTdWnkjn-3i&E)6IZPrk?PFA4QTi^p z5-84H{8@PmZvRP+Z$@dMgP((GJ{1auO*{-PVTejX5PuR!LO|e*g9gBo3L$PGO5I`T zuf58C;~6)?B=%s80b<-{0zi@gC=rZjmmr5;s@PR9pgeSD<$K zt)F&xvxorH+!@*9W|ijnnN*Kp3dK1Jjkx}#kj|^{6b)R2^3>9B{e!_616DBQvVsq~ zA&L(e;tof4`JCIz?WGU6H425|Ou@KSCn<~o01{TEq$**6m~hIA??%HtNQPYnM&2G1 z%gnCKo|`3Z_Ofj_jIpFYWAZN|r09?#NtW8iWIJsM2MH5ZVo$rOxI&X6#eS0X=8IeQ z0FV&?NjcEC4`awg(>~N@)RrZDF(jB|C)Tx{V=dj1glpzD=UT z(v;b2hIeJ$cxS6ruvHlXYLIgJD521h?D#tXd+IAl=@nZFru6EN<0m14Bq2>1FAaeu zB0u6s81H5rDbi0F#+WC&c;d1g|d`p-?E!9}<#Nqt!Shg>dA?h(m6136lxzx2Rm zb8D)y-i0E$Jh1ZDEA}7eRiFRNvI5g~7&!HPU;oXk`wp=)*jI5bl1!G7`c;CV2kl{o zq*2~XjwXRd)CX}_wbSCnFtc=JQ(B#Kf_O+NYJ~Pn1T9<6BLQrx`p-`M00vv5-hxFOu z-=B+$r)1L9t3Uav=>nnQ%|E@_PC2DlT{<(svd5Q}_y-R4wzeN>@<-7mrY>`%LiKO` z`K@NtUv~9nGXp4DsJp$nwGWG8ED^Z;UcqE6(%IX#zb(VE=uAV06(f+I@slsrD8`?+tAQgF=@cm(mMAG9PDpyZ*Png#73?~)*C!@e4wavw0(zalv1OEfB(gLsvciG zf8n^mdpm5>LXJ#N`K;?cQItO}5OAH+BkPGEG;Drh^YJF5_?D|@WFfFnZ)a4sHdZ)?WmS{3UdtpLn3AO@m;&tKDDRtp8KYkIM0{&DM_I*q&jaUUJpP*PTCu%ws4r-8c}45roo}a66t@TM3fSTmJ}(N ztTegdNe}1b&F0ICUJ_ym^0LF)q1k<_Gbttax`p zU*V+Lg<#vM-j^CVnUXi{U$JU%!0DQ~VBGss=?IwNb`{lLa!V}$obl@wqMnBB+js5K z2d}zrx?ia0pmzepzMf-s8=qNIbKM=|^BsQY2i>6elN3`*nw6*KbbmUQu2UTFNwGJi z`{H`-gaXnvl5CsWP@;_#g_YWxR0%k|$dU5z#A7_6-k~<9HuwZi@3$JScS!suCo@gc z@^p4YI#F(=tsz-lVwuu!q);dn2}Zp|5T(fu|K7IcbdXZA!L}oNnu(<0$;`+rE6+9n zK*mBn9W70*T~Ucb%P1}>&dt?nAk=iIiF^4#Omq3N$_p~N*?+j9X&`J0G+e%{%9=tC z4Mk-TQGfG+rmn%ksL(W>{1p?6+)j;px_i2tySbNl4^mEHNnVC-1v`%%ZH@{g?)2vr zlojVW_|RK(B4RSu(Ri?}FB&qX!{H2+)#kZHS8EfQPIqyU-$^Kg4r-rhE79jx26RTkA02msK)GR=;ref2VXTp+{kaWEl-HgIfD zmm@2Xm7nRb-Oub+MIsS2Tdw3m|7IqG-p8pZ|`^KWoHGloEkx-_i#f~e<&s?-gO0D z(9!Dc>FsIhNj=_-yt49aN9yV0WOg(jZ0(KM-JVrCq0om+M*F(jjx~2gC8FleD=y2+ zGawjlI@H8GEEFZnvYal5JFmLXhnmJ^EEMYRKG4OhOR~M1+27rs+&8zVG(X>ggOTG0 zk24R8m}s~&vJ2dyqeof?K?vc_$PN@$6?lhUvc_VuP}81cy;j5m?(n(;MPm!Sy~p-N zjeyf%VD|fjdrsgTmc1K$38hgy-#x+G5oMLUQZDAAqh5pPG!(l8I3pei_v9VpP z1;JqO`0i~@G07bMg52EPLf^>W5kz{A9Bu9!j3P4T4%AeaxpYJXDW!l<5ogAoAap6szzrQ8wgZ)zXx8nj$m??BX{Nnci8Mj$WS!vFw+t;c&r1f3;*-h8;( zTT<%F@HsUS(ZPz zGQ3VMrNn68k)zGM!HD5-crvri?*6ROB438jg^}oB-=X^BVUq|bc?e8K+uPd1Jz+gV zZ*K3FQaUmVa&vPFvxYQ{lu|?oj~_e^PKa0tPJcydfz#@-D*`}W&#fL`>^2x!;r{OS zqsQB#5;Fq%T$&DYcuPzCTDY~ol|0VOoP4)|D55P#TI@xa4jApLZ*1uq2m>IxvTCZ! zTsjPPHFdOibcZDX-}PduJUV)v-SOnRCvbb@$C~+?51K0>Rx16bgk3l)4LbcXuzh z21QyZ#a)AI+})G4tY&@BnfH%H0u61szk4h1-R~cKnC#3ma^}pLXXJSX+T;4$xIboi z&91heUwi5E%C=r|$m|JAUifgH761gzCyuOG@!m(<>k$zIlOFi+fg5g6F{+PzJmY&f zg?+L~8b9Wmr7z~EwQhX>_J190)Z1We{E&ICY+E{lhAiS-?P!{=U32?~>+AM4(NGcx zroDFf(V=M?L&cWOKfkjVPG;}grCspCE!R)uVF!MC?B1`cFxroXj9qf;W3SI0+Rw*4 zM*IC#+rAH$e0!j!)CiSvgQmW^|KZ%y10Sw#?2F8P?$KG1K^&It`*3Z8Q%K?LuQS5*Y*OZ)__ly!U&D(AWaRz5cw{c087+-@E#?BGXPJCeRywp*{)%X4OpyX~=0=XI@l{Pnd(?M(>bl_%bt@y4Eq2mkR)x|5#Dpf#>j+eY+XaD00Tr zixw?S#np|rQWarcrtlEiHXKArMIa6D1gE>mX@ zU$Qi+>9HmMs-$}QQ2faGb07PBY5oPrIKbE2R{F(^XSUJxrT`v2GGWfcdmhsr{QUk3 z`SpoY?!GY-002iv8BcGe>P-PGYDD6!r}saZO)>xg06Dum&#d_IaZfKDrHh~W#;zywg`^k&0+_9Bg`drNZA)LDsr(pm`qawno;di(V3z*i zFCTrgV)f}32oOROpWS@-tlUvCSU-)|+J0)&syCipRzpxUm3!mMH{N#N4GC7NYyB6G ze7UWt+d)StVrRd(`^jNs_0cak9^QVsFN?9`fHzjtnmGO8aWn6`DGLAqK=m(QZnL(q zV;-H)Tzkz5#RsoUo{*W&^}Frz*%14iXvJLk!79?$dRhNBxkUiSUUlPv@r z1gAZ>?y>nJ?I-e;$(06@rabknC_fA_pML%AisR>6%>D>7B6JKpR)vO0;|gq*l^d5o_2SxkgeNUr7}Md6go@PnpPQ*G z+WhQFbJFNx_uep3nrxdYvszkcG&ttXrGKrL3!eP`Fwkurbd_Rm&-_3cm1 z7yw}66Hm&T>pM2AEA&Bp>8TYH9)J3l1&>UL{JjA?%%94?@u9ww=J4+`kf!zfrT9E2LS3X;#nwJjJi3?v``(7f;461)wRcUS! z_y}M%`i(oPi4`nk$ed zjlXHuZ4K=mNfAIN^Yz(IAKf-|)QYU6NKwC%KuTZV7xaqf9z6I6s962!){fF6C#%Mc z&jc0UzVcgtE26_&ByzHC9!~*tpqX$a{=pH^;dtk-tqqXFOPYS~~&$DJF~4 z**07+|3dM&z+FO4n^; zEu8*L{D)Z@27~0Opp4nD=i9?Y%~3b5IWR(r2dg(9@;XkOvCZJP0aeo-@#3vF4KCod zb~GNo@8roP>6t(*FzY+@4JFgAe<)6&KlQ_*qUOj@TB>GCp~rdblw~H*59wNC#50R; z9yv*6vQ?dUM)TUs52ht*_)M-yET{W9jR7oKbj~9Ozq^g5f{kT`Wydye-MZkV+>sMX z>KT=FO&~K40MJl!SgsfsJ!D9vf>b=lVI0jP}m6%WglY zxcQY2UPy=vHd>mCmhb9}8LJg5Neaq&F_RwN0a^EMb`Q!=TR3k_lz>50taV* z{pS**sU}Nv(emA0v19x+*3~N%u<{<;@u-O3v~F1oQC!nr+|mceC92~Ub$gJpv9(iQH0I@>x5^v0e7D11bns}|Dmr&`DRV-_UKTuXevBu}^4Nm)c<2~HwP2X;}mFzxVGHq^lKT87vJV0TUCiT77-!y(o zx`5SF^3}bEM6;fI>&f_7)M9HqvHU=H)EKvQ^SVO^`U>7Z_+dKct6lR`XX9z0PW_Fc z2Uy*`XTQCtP&)I;Hy=-m1Fg2k6Uz(r3DQ$%`gHDVzb?Ec2>>9Js-Um6B3sRWrzGl) zXC|b_WoW~`-ou0m6DG|6=ltLGA9y8O7;pfM>+iC`MPnpW7CmbGq@jbfTHM{%>S(WO zY3ilpKwDc|>EUuK+tyLWL&#WNtB{Wo@khzo2v^0Yq-Ufi=tLb26_qC&OMRP`*GL7- zfW_g*%92L=Mv3|>nOsNR@!drytJ)kEW3A1X?1DZD(iq9$L?#azG$@&&4wjU4)|@Cg z9atG`7SOn(t&5q=8af0ty=6e$T-P-`P~4%oyBBwNcc*A^clV;j-J!T!afede-5K27 z9p;9HRu%N8zJ&81k#ywLU=c@&_o>?=T5|Gl z6#QgN2t}&wV6B~BP5YvwH{Y4f`3$$z4CiN6*WA=3yb|g=C_T&!DZ0h-GAE{-y|t32hzm$cf9>>0@A>UtcLpH=#t#Cm^VKOl`7H;VHa; zeaw1qBElxJII>xrhN2Zz!GN3nyEG_Zx>l@qSIqZv|rgtJMC}E(n5+gG+ zts@h`?9N*@hSpr7G>mjYth!D=d;~g@>F+)Erq)G0^9v3xdMOn`FxUI8Po+pnjvTmT{w`3ElUr8d3E%rwr9n*-yhFGgL4697BoM+ zCX3km%fDnM*?9Oa!l%(t($mu;1VL~xt<5cLP?{kr6ADm&lSHE|G&e;csVZ9Q=$v=^ z)47(HE6m}mVOWZ78db5jP#53m6vRu|eYhF^dtj%C9aa+YKt;X-criGh-Eks-98OUy zho8&g=jGFpfn`2IyS8U-J(o@Pt$@jHhm95{BuRR>thlt~bOFXy(OyDZK%H37-_N2Y7_4DmsjLe$__>AaNt-u*VMT9E$9nFPk|qV0IC$|V zN0G4Es~GjHhTSbIPH&iT>L8i&3u%OIQCfogX-0}fuF5|Ua>b8-|1C%gxBvj$%O3vm zmG&PLkS9P|fJ{462aRS|G^ro~j>n~P{PM5Wwu>rd-!5W_0vC+v!uAF(Fdr@nApuU^ z##}%s8zR_nOj7r!4BhsfmjLw?x{JALg$wbSpMQv9N1Zb$tx;1@izK`MFjDfAI0p{^ zFy=@Xmn&>$g!xhgWKsrr!zb!bS(tJRDMluj4GkIPSi&aEFI!%*P$@(u$UL75AAchj zi`1V;hg$(WGeM<_C6xl(`gb1TGr)!9i9-=Cv>3wd$~hUQti#*Y+cr0xA3!vrpGC}vWHxxhb* zGgp2qLLLE`5)2s$a)6VTN=^di!6_A_gRtN>hRDqN(IcXDkJ>j_KoF@B4uvJ2phI?u z6iTan0_Chs3I=`=Z_a&_l?7`U8k|pvzbFY7P5M_8?7#3#(uH`K_Plbc5U9~Z8H{Q4 zLI#7TJ3&;ta_#uNvj_Rs5CWDPVSQ3-KiDH)*T2}ihY91256t%06773>cia6n9XE$U zWHUBXvd|D~i5twv#Z4(UBdb+x+>ahczEhT#5D_vbI>?PzdQ`~q~V zXIJ$>m(9OdLQ-!9{X1nPkUu5J`4x5{My0Hq2vw`(2vWo!agCcS?$pPBsgh z0w!SmrS|OXtP$G&ab@2N{p`I;YM$e;p3e$}niLu%30n3qfe@Q)HYunEoiXTc-$lyA zp*pD8DN}#Sas*PTHDoBLKe8<&2u&`NaRjPshXR8F22&Dj!RcNV0o|zj@C)H^A}t?% z)MaU~M>=Z%yT|CZOo<3Jl5vv;ZhA^k9yROQ)f2QpC_#Lb$}SQYbb$_iYUy#cv>&FV zYCsIb5h6x%u|m$j5;pYsl6-wF)Q)p06y#L7iXa+t8IrIZVoQ~w!)QqX>}VC&)SLPF z0emYvQmPDUE=?2`B-1mKgIgEHH^;S^BEOLnXQ*Pv-^an_)^zl$F>VR4UJ0A3E!L9A zM7&-uYUf+K#o`$(|2_G4%8+8G2wOW4M+|{yj^E6j;PRuVm2z(HlVor2a14T94+~!r zomr6jGxh1Pjhx2!)FY&ZU75GIgM|34c(41@dd}Z!d+*k)q)sxg&cMphFo5)GG>RNa zG?(T$;givH3t8OW7J{En)ID%N{m;n6sB0M$em0G9P8Eu#=e|uA93W_x5J8@h7a3Hm6=O<0p0D-L?YRUcD>eN2l-vZCG$DxJC)fV**R!`kBBd@V)$P6*xU{3gmHin z%7}}aI~_qS=7e3Lcv(k8ALke;o@7!uj7L5}QDrp1_CqI84Hta!sM(*uEoyGFKR^9e z9^#Q2Q|(q-0v4l?r+8eVsF7*lbTwYLGnF?vb^CbA;8bD64#5Fo^k?dR|vj>E+)#7-NSw!5j95`K69nCVU?+-!CO-)$v{5Xw6O$ z$)QB^%Z7JPJm4sJSD+7&hn+FL{!&r6e2*xNQ&idqO_3u)uL54r zrTEj6*t{4agIxJlQ%KpI-OLoGc+Nhbe!o2iH790qxt^O*r$^h~9SQT;>yHh_sK|PQ zkl-|J(pGTG->mgi89io*-1AhbFd@=!OrWqM2HFTsTL)uhV77DaBEI0-aV-?b6Y(F! ztriV{KGo1e(M+9mL~=Pz-izNXK3mFF%z~YKx(%~&W(e_L&$0PsZ)71NBp|5!7p+`< z447cPx_Va&T4Z66hwed{ki)Qao?}uKquq7_FNw=Crpuh(D?ezV$i7hU5;Bt8Ui!~d zo0q{)5il)h$3tf)Hg=Yw(n8T1yWc-NtdgMuf>a5Ev7p+937|L>#mgoMkvd4hKDv}k zTN{@tcwd?$eKcqQKsKb&wJOUq@bSL)G0MJ!ppEr3!2GXOFVKP8gBMCw6$1s^Lj{`} zoC^8z?;SsMCWu4^4(9o7Yi*w{6m4vgP1WCVZ?wc+5$07fDL8{}4V z)t}muK_4b;Nuyt26nlO_vu@QtU4giMW9vG;@6tvMp(JBUjA=Ky3gh*fy>3rBf@HjI zy|&J{>|$tmob;wo1*Yx~lW{6g0McU4N;pJnmiy!GKI4Q+0X@6ZisF&23gSKlsZ;W{ zvdXcjsT@|L3Xk++I5addNGQ6f!hnOr@2PAtZtl&*g5FJugn4D?P62h`lpz2YNva%o z=pr?;IT68xFp+`r)TI&8q+^u1PW^qJy70uDMv z)Np9R7JKvMd?G`sdzB_(#EYnQi9P#~;5`78`aQnyuqqddj1?dZ0 zbIkJWy1T`m&`0VVd8kzu3QS00;?ripy!$e0DqidmqVs>g(w~J=n>K}<`SnuA8af-H zR_DHWSxv#yJn116S6@|KZBjJ2Q-;&5693JKYSDY>*zxHD4Eo<$&c<7jW4At*y-Mz~ z*ktJ?n3AG!Kb5d1>06pxw3aFM>kDfiU=jBSb@bIXsHpj@v%>A_&4$jVx7dW3lV;Bf zb=g!Y1ze8Jbaiw0xP9tq`J`wu*WxeMoFtNSF>;gqBGCoJiq)l~k~D|8>>V7rdBy9P z!heXA%{7dzkBy<^u^3fglLhzX=k=JFlIKJ=(SNJzYVUaVlr;Eteq32qhYHp0|5>XD z9>Qx7lQ&wjMnZk8trAvqx;w1E#iU|q%LS?zBLoJ{EtHtt0k22bis@xZ@KRLxY23%~ z@S)kCu)->01N3zGMU!uLGdHG-SezdS)tHeXoSRW!^yGs5H;u1myDe=Qq9KCN)H1|~ z=EYfk6idNw6zueG+7?|s2&BlUe{sKg4QGuo73VP}6UU0%Y>l3uAN8RlJos|az`8|} zsvL^y`He3t%z0CR9tMhevqW00|L3@7K>Q`ey=K7;{_?yB3HaL^c@tywg>2yZS+|w3 zG+_1mBinVzPYe=(n+awKO?60lvEs+lxq;I!p!AcM>8$|gR**R%g#;g%;&Tu^XNqM9 z08FJ87I04i-xqpN1KwYvt!iaT<*8(*>O35c6&_c3!Bxpr<->1={h_#_iO_h-*n!UD z?dvCSmQkjzhyKr{CyCR-z}r^>D5j;7IPdGTLA-{X_uwp}mOwAiu~8e(h+-nRAcFyN zTt?YZh{3Pl5A%H=f2s~Nxl^`-1i&E@`<}w|93#kD3GlMUR<7JnGI(MK@|^5AI^I8m z7VC0Y^j*8eBTk!^1#o`CkNlj5G7Kl#3);Tc``!DtuKD)q{`QoY$b&#Dz4bA2%&Hri zfUg1>OQYO-BIPr_goPRh{8xbXO)lH{t{N|yEyNEHzU6h*j!>wY z7zZaN_ibL$=YCz<=;QUkGQepLSDjX#_~}BOVpk)}Snur$E6L>nPz)N{ zMe-7PTtlux%ySPJ;_}dOGlTmRkq`h-ugexx~wzHvRRA&Ycq4SxcVx}VAf#dDpJXDfoYsFa+tWtRP}{1JD&YVLcZ5! zs1i4j*c4poh9??iCBHD)5ik2-ekqvBi5e+xog7g!*%tWK{tC{f*<|^aJA}K^K1mBh zg=0G;eDm;yIiUUh<4x%E*I(z_7~;nJMuNsh@)rOApMtg0SmjfC9JRNx;@IqTe?9#h zvB#czYmI*6RYd2q|K#86Ah+Wh)Y#t%>!1@;`!HV*J8$nvJb=g_W|w^;)5F7I_@CSL z=1<-Ci>L8ducxM5f7{t??kVzsPVI3&C1!1$Wnltr8ea>%?RpO9s%$wh=p$mf4@G^4 z`=10KzuvNmm@Q>Ew|2MCb{p?}mG@)tbo6srs^ta;b5fgvPg4Z!%)-0+Z}Sy5@Y!S0 z+TFdyZmR97ft;R> z9c2jb`PtzY_Q@ZkI7MQql#@uKrQyIyv> z)`gKwIJ9&5{3c+ZkSrU$w0m>Ft}Zq4!^-eecaPm-!A#GIAg5?ChF{NPRZ_fWo&oQ~qn_=Y%%5f?msK}hC*h<9b z_~ibpO_?JP#^OI6T0PxRph2`Q!h+;;>7@JSNs#hA zy`HH-qS`9Y}?h+ z24v(={j);jHkoL~FcecScie6WZIg%l=W`w~iUOZev9xj=Yar$!c>Q zLUpF5aTv(3E!lV;`n0C{R}M`w_PqKX`D+<`35)-!foI7KN33WChfqNI_O1t^B7#K6 z4@BYszHubK;?VJ(F|RhYzU>6ue<|o8)SJ&L5==DQl7s(PWRf8ZxIhgf2+-mqG5CH! zcV|P|)E$Ksfy?@Jt5`LPlv{7_W#M~`!#axT9y)R(WoO(AZ>i7(dLe#l)qmjtHEUCn zZmcm*HVAkfdh^eJk~+6MuHf4$p|7ubmJi*z0F@#qQ|PWw5|8=|6}l9IY|`jh2G?h) zm7-{T{6A7m8szb)c_-HM-9KoUG($&5uC2x_0KoQXv8e0~B*x7DOnS*hjCuQO|!@%mZaKb}R)NOPO5L=gf z@#DaxEi|F93O0tDFH`zXSVOdWfqWrV1zs4L*E&Ra*ezCaY)eMryD1Bz7b9g~kOCHP z<(LLokjT&ky@uRXO=&aHOvO?7?Z=u3ii&PK#R}ovEj%bYK~>IVY>0nWt<{HsxHS`3 z2+dMrhFZaC(rC0J>J>vk&+KxbnLFDGCi?lh9Ib>Ob>1YY7kuO%_LdY1D>Nh~B~{i+ zlU-_ptZ4aorVzIU4_Y3xCTP385B^%`Hiy>{u`R@O(GHF*p9jJF@&WPB{*F{cd^l8} z$eK>G{)BoAKCAMFz8noe1b5iZEw{Oe42~=|@qI#f9ye2!!pAu$pPV8Unkkh_ifMqh zMW4&<6Oz$8qc6Zv!!J}$79q7d)DUTxBMLtU3s2nTxUFyRG9V8KA0)s@Ayq0dMqsFj zCFKfg?IMf#FXNWM5=aOK%Y}vtF`?`6!h9MR>ur|0YS#h!e8WN*6gd%Lk+ENCa((_o zW?dosUz&ORpfCXRi2O%~F)S=BH8qvpVq#=;w0$iqw4L5b`Yo<`Yq6aQexBqvJ}9Ev z=Up3KhkpVVEY2psn!tZJnJrA|$16Mm;`UmLKJ)PRzDlor6Y6mn6V1T@%^PuRG@MK- zN=nkc^lKm5F!2#1{cnUnKGEBN4nld#NyWo^FYI>*H(mvLOWhXZQH#RLd3=T?DMoZI znKx=!^ z>^_ngopG(Ox=#}l39ne;HXMjcY5#xql>a7^7_AUO8OyMb1P7r?A7n*((CD7C@;nl3 z&KcSM)Z1kC&v=xCMfG_LKo;89@=y8l*~Zhqo>-K$pq|e0Jd4|2B?b5M!PfzNz;)xM zE$iBi$BBP+QG}CRQ1Gz|{Ge{ZyE`hoC9HRn&*kXQA0NsA;s19Pe|##S;p;>M!y$JK zV|`kIibQ$TF*I2~js1K6#Uhnx(I7Ttd@-4#a#ne53*gQT6gm_xfZU)uClDHu5PUTC zeAXnI>5QAHsUHqeg|tY!K~zyYjVrx*_q~u{w;otJ)tqW#IG>hZ$S8FLyzPdtlnXv1seYo#H9ODsc2I&XTmD27ODc*{>e%SnF@pM+N!~68 z^_S$npZNdc(a@J^7s)^+IHY4;DnCTB|Fix7pA#*b;ZDwWkgtAV7B^FGzZI*8=PGlf z6I}ZkPi_Xf6F(ugurQn2hy+ed5=ChK^k&J`gQ)uhE^q)DM9VF21A;U%RUY1+1070cE zLBp%Sg~|DoXTN~JGbgY?dynW@A{$vk5PQy$*qG(z2?y^Nm3J7!xmFv6vKIo>Hv zzvwI5Y@Lxy%;UOUi($7s8WxqwPvNo&ZA7WJ3$D(JVY-;O&uMIoq7RQw;KBu_gkf{*+Istkz)P?RF=xw_fPZZQa6Ub6r5u2^aq=vwO*j|kxS`-|&OVk`)< zba#@#5TDz6t~l~5jned=Cu%#GMk3UG2YdjQ2a?qxgrdQWKL%WnF4w*L>BgdoaY%x+xe3KvpsZi@ znb4ZF?DZa2cb@_-3om*=^S-|AW_l-)oJIof%X-=jyp*A((--q5;s5fsypJZ+1Nh1# z0$;Qk;}n)2FY*)u%pMBTq?V}=VL8q#H+x_2vJF8Mg4cm|qrxc2RS3O)J2%-RMqP#E zXmIx+c(MiG>ts*xP@nFE&smVW&J=%6b%Y4}d+gbs;nOvGZr=?B3LWvyz2N+W%zcPh z3TU`aH98ffo+f$i$W#7gke=vG+HkT0{!LOGZVkNO9G`yw(+_3!3g)?AH6R#%E3O*X zsy{qABYpv|49$0S0jsr1cYD)V)1FA7llEIri|;gnE8k~(dq8RB(cLHou1TQg?Gus~ zEe+n!vyY<&);nQZ>=5&HBfqON)K+4ykEv(0sIG_9RNM62+J9D<*Fn3EMgh-hH{3!V zSK7lJ_0eHxTawPz-Dl@5%B8~HJtK3oPdG@TxQy!$V-XCSYwuMEYr((!x3=E@MIo2T zUj%Mp;e?`@Z+6~>d2afG(oKhc>i_vHdxMc8=&Wi9WO=zEQN~}(1yQ=6y}$2oSx157 z*FZd=KI?VIAOh4H-?xiaLqk2Qzn>`0pZuR)aGF9~2pZC7i>-ggpIh8ewlQ~>BEl4$=xj(MNG$gy#vltf51lA>b~#*0%mCGH0negj4Z165FJ;cNY{p8lF;z84kFd}+VD-ABUh zMxt$HwI0L6+(JVKgr-p33Y}!SFK6DYCL1Zf9JBz;ba^-C$s4g*R=w{!%4|Xc%*(C7s5iguX$7WRBY$nHHO$~hRZtQDMb?jezytA@LwBBW2V~iEjbIC zwt(GVVn_m;twHTGW2}gI@QU4#I~B`UL1;)7YUv<&|h>KC!v8#@E|cK%xIq+lr1h804I^5(EgEyd`oJSJW}x12e*XCA785A&iJ4w0i&NwRVqF};Lf1y zB2nKct%X;8^9yOT8FA_}007ME{3X+}HgqUdDG)NXu{QL-4JKblJp+Q1A-@I9bYikl z0c>$|y_v&17}&H4XVuTG^LKE>vg{-tS=#~#q-qkneEz|qy}o@m=HDilO2mV9yWb&xcG2?=o+nI>38`9WDA?1{N!Ux&YJ4%s^!g$ zegPw!;}R(qLT)`+>sc+l&_Gj$uK2w+?l4>^3O$=!F#MR+lOv^Nm2800de8Oiz6~ol z^?9G>Ah;B_5rB_lb5NhDJ|8wo)4CpJO>Q6uhOmaRh_5DMBiv}TS9CzcGK;4dl=QqR zNEWgG5*JI(OvlSE|M8$ZNu~EH|2wUwgRy}}a>L>#BtW_!z2WpMI{s?Y=*z?5$C-a^ zWXt*U4lCon0}~_TSxcKg$39$f!K=%NyrGv~e`H5T2R#KcfYhzMf3D~&R*aCVSENDLFE!*U zZth@TPRHa>4+-VuZeeI47mWLOI(=D>S7*sy7>uqjHDf(*w)Y^Ro*s+Em0~gP2#BbYBm1yr=4oPn?IG~s=w+6Ei?zi6hQf_Ub}XQ7U0`i!W}&90mK7dL zp?-5|1ABN)ng(RXlna5FNi9UDux#R5~M1162cigGOWsKw-FoV(gEvrEx=z7AGr-eCU0~_qy47Vxl!O zvj$5Wi;K|D)k{iBo6icd14nkX!u}m(3q0^4?DO;FV#LT+YjggU#|s7O&HlOFdcBA! z_`KB7kO1Q*lKVwM;OeRCs&k?iI0+>|h%?NpCoe0mC>bUMUdhPAkz|wUKNM-WF6tg1 zuMxRB64$d51?VNQlQz`!{Z3~p)_OdaOH((=D27oA#oa}xPK)^Y{g?=-V`hr6z*kSq z%9hTdUMIoI%R^v(>$~5dQq4L~2(Ij}ncNKW;_#{2MS8ji{(1M zgX#l}ex%Z&<)eR7kr+fF7M6(=OY&9FGK{I-a|`3e)fh0BwACcHz3HjkG-jclE0v%^ z9h!ah?SL3mcB0~oa4sguIUj($ERdFXO)6k1}5_`Wg|?yKGL1v9%ww5kGr`@w#O;N zu?9B6!z*ta-3gPd%C{~hB^Ix4F3*~pu*g`yhLSm}K}Vck*i`bb zQ7d3CwVYmf@XHr#m7$Q}O;f-TdRK=pttHc(Rm06@usNvsXlWJ0k;=TR$sttf`S`q| z$+DTcMiiYkmXwq%3Z~fi+c;YEf#dt|J@%HxTprbR;Tp8rwxW;clcYlj#9h`^mlY#X zF}NR1^$uI3>{M8sulfF@s&J&<3KsgW2@8m6KSB)kJSQs@Vd)JFCX&~4s`Dufcqz?h z=jP{})>chUuK{Ts{{LpYGR6LiK%kmCYy?)f4M(D3jJmGo9= zO%iqei<|b8a8k$PSaR}DTv*s??p}~^k(7y96Oipc=6{a0NENM~tuQs09_|OT``_wk z$`R1z`w5AI=h{N6L8}aly(^{WPK7@ak0QPPOX=h5-mtA0XOg7lfF+V*A{k-kSlrU8 z9T#`p z?W_U-fY?%8)UEm(0zF_Y-TBK7wrrACyoJm6kJAU?O-0HJgL# zO+tW2WhEwx=YJwY%>HV)b`51x@W8lsS#8>V)gL?AjFTF?QcQKPalOHw}!u=G3^ zv-G}5zI{_G6{PS#B`s+;vsG;@Sr^??*lZWO1^3nRtrkQsdtAu)N%L#}R3=qxU%0t( zZsP>8WO4#d@swrF(XQ^w!TvOwUzqi5KD%SRl`Ba-f+~8IOWgjV{p2g4GG#|rR+g1K zlwy80HVE9>1{ddl)Yeq6PEI(vFkKVU+7+&lPV?sotECkTw@05?(iIHwQ-TA-5O`i&x7N6?Id~ zLarde0rFY73&&8w5gZ-=Z;YAnuQVNR)mcn^w9XOTH~TGxOcVA)T0p+=Jf@wtvBbRxq1N`nn!OwmYQDg}ReDQgSMI)Ko9-5n8IPo8=2BB>q(vej{n7 zs%BDYqzyDuT%0w~<8q|qVut|Wv70NHH)J`U@O8SZ|Cq6N_Vr=~r(t!iXC*u1G`X~v z)O3cm3jYygk{mI=m`lgX<~+)IU=DAoH<*IfDBi|8x{v_=9=V2mfon1z9b5JSEjzQ0 zI?;`tF=>y7d@_H46dHM3iOEG2Off*TrZiB)qfTZRFXw85y-~z8VN4#c&DujEd$X9u zVqbi(9VJ~hJ&gEC#|gauVCPevU_)yYdrD%9G+W^7Na6_`I7|o-H?_`fAJ)-yF#U5P zQ0sN`M^rWa9$DUW7CbxJSLM#zxEFE6moz`=S?ApR=J&ReJmZ`nJWj{uCn$~VXC?-o za=z6F7|cUBr3HrG7p+I2sC{1>N2z(a?39Bg0VMF|N|&?kmT2o2nAw6EAp*}A%0z+{ z=&EyGUDGy>YfaO6fq`y%Dcr^aIFoA4U<6Qu_+$VfO%{cI$8agKybv?wlTLPYREr%L zDD=0Kp2p1ChXLgrbZ~vS>w$`rz`k0kIf>?k@p2@Msw}@+pm+xE0N~yT0f4S1%uLy1 z=6${+D1n!yICNrxcCcgk_Wlx^6k3eF+^|00S_kYb`X|iTQ}kWhg3d`^Z}9gwVY?cn zhpMhYsDf1FudEONC^k;b-{1H(w9Z^S9N#KNzs0237AEE)WOY`>VG#*CSk*Km&QX5F zJn=M><@vkl(PDD7mRf>Y><82Qxp~$Y;j*r5FQiHGhb`{H;UUu5LPBPbJfWiM-p=}m zb?*9Vqpy9c5pKaRIgxcl!xyum@7e0AU2S#R^Bn-Afs0Y~A zT3(fnxeN2#!Kj@|+d|5qVLom%vQR?cpyb=~6`xn-m>eV^JTatLtzy7X+tq0@s&0Hj z0u5S_++HqNy(|O2Y`azaT*vd;n89&srq&2pH`CvDiSYOutWdbI(1n+j z0-Z={82FrRKFLVNZn)t6>{PZ6-6+UCkx5O5*0(uVGhKt(`?Om1puST{YYeqpfeU;$*B)7RzgfxM@ zXNk4ckqi$9>NchuG^6?YZ;0G2~vjnhUaVtReFk$YOQr6#$+A*a>0}iWwPu$M4 zM@OT#$r}{oI|$9O>-wyl3X{Alm#g2govlP?w~1)4=ckd?y7M&3V*@{ntnQ+X-l&JO z{A(Xi`LasCP*BzZ*}6z)9m)ls_vW*oTaUQ3xK8->a0_KFb*%ppg=lse8`++$cI%~s z)XoQ-H;NSXMEYeOWDNh#1#~&B$A^{J+bhM4A7G6fJb&(isqLH|)$ZfrHu3ZfX?^UR zxvPx_VrvU$bW+6vc_)_wFLz6t!^*8ZysB!8`TO8vgxh8`2iVI4ath{E*SG zKqBK<$^|x`oRQcH>Px&BL`~533%E?SxoT;WHm!HsC_D0O%vqKwU7p?FgjCOprvQpR zy6rWA$cEyhqbNo!EMo7cyFW~m!$e(e_Yz};Kb#7I7sKyr=C2ul^PeloEv!xwf|+`& z+|I_0e5Ita3#w`=v7rS%AvdF=rQ_t$RlDtDrMYSi{R<}#`v2RF)KVeM`R?cGW15nb z7{^Y#Jx1%QvD+O?fXYgyO&Fqu@83AbUXSr@M$bA z7T}N0(H!_Jtkugw6rD`83g=vMc<&Y|Qs=rTR3a8RVZ!mm8W^m%1a=k)cpo+^95~wO zd)O+w9=!hh9>MAK8Wdl&Q-L9dk0YWbu4z5{S$HVoIQ?mqB}iVuVZm`bKQd>at)Z%C zU0dR#70@szUceMeE}?vJpsSZ-<<3JFP5c%DHM` z&s_~;hjyEznVSgcS?pvKKOR2kkRfF2FaY%u#>oNZ0o4%MOD{V-53f5ei(FxoCK%yn%a1s5DtlrSQ5LC4=?XJ)x~JQSUq4WUX}9i{mgC5r ze}(x(#XUWDxe@PuLhn(V8|fE{WUS9>YWINBH5sDB&6V=JkYi$r7z)3cucHv!2?Ejc zaUsQvX$(1S6Xxc;EUvN^Z7Xvi0U}fSoYLr31@}Pklzn%voZ7us#V~j4VWx2}&Ddrm z<7tK5Vj}hYH^*lAyrCfat7i@VlA@z1IF4|Kj%dn-b%QGaYBLX{ed& zta4RURSk=>x=SJM{mB>W=+a4iPk*uD`n<Yg7%V=qu<;Kg0l!!2N!h|3$lUzq#b|FShL7stnmZNG@6 ziL>8wVGDe(`kI-D5w2{suJb&;J}gZ`O;<=X9A^i7*=ylKMTMwSWbJbNhg4vPt1Y5M z><8kv845<{9;VFl@*tw^=|0$#*ZWzz z(Jy(LqcNw{IHk;0{V*Kou-;=~YfDS5 z8IyqD^^K+_=LF#I69{qFM?hUEK|i**?tK_xFKyg9c(G6QtMTJSc3yJgaMviH;w%*< zN-ip@n(ulR$0uxsj>1OXRwVB?)8DJ^AC+>&2%W)DfWHi@zP-W1wY`JXbm2&XrD-7q zqj^HF4&|0l%3FD_K6`!Yo@NIoM;u?RT2;YP5bzG(+k@zccd1|S(ZtJNuHjW5Yg&8W z#*4<(uj2e}>tD%GH(Q>Qzc9aUM?OglxmNSgP_s*;m&p=79)G@%#lzKo#iaev$Tyqi?7RZn*`YOidgv3RE$CmAieKO^?qmGPt_bi0W{jv39W zSHUf~Rn{kdI4w(-qAGSqvM(Xn>iPJ(x$e7_nUgzhT`Aacvq^<|sS?0hManAcqN*32 z^M2i(OwvQM4KZ-jI{aZ=DN{Kz6-Qhi_Tlxq5HTMvbw;_xLB$NRGlZh1I*Y^6_3_P4 z1BC{>Uq}1B9xsu^^?=4NO+76S`)+|%D2oq6Oy582bQ3WHPWzd&tEJ_9>u@^B7`MuM zcf$Bd3<>8|J1i$NXaX3sKK7enFR@1#3gg!>0-n8ku+x*=BdVgrUVNP7FV?2HwPD{~ zm#^~bE}yndTuC+?cgaHMAEcM;f%mfo7xJ~;hkIo!(=}C`@(qSwJ|39JD$cUyzB2(L zghmgC+y;1_z|Xq%y6DD`OQTEO+xZ`mH=H5KR>I+_4jlSV_eAlVgqG!Noh}n!&y=R; ztSJgLKZr@7`OmT^1(Cl7uC=p|{duV3_SAM<@8EvwYfpsxi=FM|aT(l6j7K5zT#vf- zUP^HhH#mN2i0cRe>=kfZkB@+-oI#Q;{SeiuzZAK=h~K!|%`QHAe(b~vbfJ`{Ni*Yq(^|Et6a{a#nB1_&+SYeQiH@3)p;mAG0sRE<@R4;Vg1AVtak05@jZh z3-q|Kk=IPQtId?}O;`DO!urqhIjWvAlN{al?`%!u09g7@a{|}Xwuta8Zo0z;R@ncr2;xRP zZOiFp?WX-@>X=7?R&-l`-XfMCt+sfdU*UcbG72_X&x6%ly2y6UY?E1HxHy{KIdd~# z_E7b9*LpzP$(&VM+ASLoFVh66U8e`k0h$3m(>qCF+y~@P#^V)iv24ym()@W^o(^7* zn;%%xUg#(4;m8Xk0c;L)L@%alsWD|JRDPd}&7)$RbtQIhiCA^q`~JNS9$-Mwig#h* z!#L2O=x7#daR+;!+UV`LQ62V?>Cmz6%%<^b>iPKEv>l_bE>~c^qpGDQ@Cdk9q%Hhr zHmj zL-g_dyRd$Cc9apJqpL3sndpf*aA$V(oLw(q)fIF*S>`B*PiDv8d@ypeSIs;AWQ6mx zo}uTXeoEJ?!T#9ztp(>2n0I}?Z)pk4U_iivQ_`~Yr=h;gpn2F^u8sc76EkOUg-y&q zmeuG7(nsFc2zW9z*!nb`3<=i?yjj87l*|)+xNX{zaDG^`bR6h%0k!8kA@u`Bet+Cj zFd9zuQS>w^8=^+8-F$Wkt`mlA(fN^YF*lv--K_rp$YWm5dR=oz$IXU7tBo1!ecWlr z0EMRhi%5^l<`j^&yTg5&*IA6CKv%!&dMGNp>WlN^J&f$Olseg+BkYO#x+SEU{05A| zfuW(`d8(t7tYxBQh!kAqY#lE>w9~>I$M8pq7*n787OGT zyZ?5TH?0*m7vMyCFwbnXFW4njH-h&%V~~vHe?7oirNkpzMQqdc*^mrVv$bF$Z|%A- zh1(ew2ieDyHSce?{z^nJ!Rtt(pQRja4;%2lTxyW#-$M8BkjW?VBiFz1`S?WHUsxR6 z6xIOX5!|!6RDNnSGm=YE;6s07=l>(PM$vm`rCO`%eowg=MoS|Y*H_d z!-PRw_=hTcck9FEdmNwCihf}J!ci5l$$l4+xr>Lpw8Zc3kU(g|$s#~N-J*QW)oBY% z6e4+Kno-H=AX#3V;g4Gxn$Xf8K~xj!?R8l6n7#u`oyaK}4ga2G7JS{A3T8gK2E@e# zU^JErHJ?hBWGy#eoEicX5P)LIkwn+?kCq+J5Dalims??L>Rv}U3myq zoUA=Rs{7(UUh<}S_e1r)wBnsP)Cqj7hDeTX1>PMSD^_2K=<2RAWFtY}(IT8N);+=Q zmHD?mIRhi(uY7C|TATaJwmzpekBaw4Jso}P8uz_q7Z;9m0xrJLFpH2810P7A(` zsVE<9ego_E?fmRwmhGvs-6|kD`&*3VdnjrA?^Tn)=J+C_roR;0S;H}Ti}fa4(zAHA zn?@*5zw5bPFMN7(Q3Tvig~#84O=Lykb1L=>s#W08rPm12P-C;T1#1W;;PB^Y7OD3w zuyxz`VmG2EJN>+0l zZXBYw?aQz5TmJ9HhITP`UiK%EG~D+{*>$^YnE(JG^t;>J?J?8PM`Au5zZ6@7@$X&hC{#f)BF#7K2L8)kJz-h=xn++Cg>jXO?SAo6F`(ES4 zy2-@AZ*XyMKUsbIt_jM*YWYhyZ(sDH(TkC4s9=RNx(+A0(AmsMz3e`QI0=+v4DU_^ z%wuxEtQ=8hL1}~`{|Jjs6{q?80BtHsXW0|)?(m~{5+gpl3?+pOpS8};%G&mwMyr#| zf75{i>sXwh$szK0*46g&5q0N$jV`$Yk1d%U488mr1pV~BP0AbmffFeleS=p*Hgx<= zCuM=DRJ{Sl)+J?l-g7<+Wfiojs=) zAfU41fA3l{eShB!mtM5oBzah9+$!Dj9{)x{;@20E_v&=cPBYd(-WXAtle zoFjkep_NBdM!ZBz@cw7XviXRYAGs<4FeR{5ZwrEUvK=DKgguC!`tbfJ`)4#|UAx0I z00);0+|u9QZ*#ydk`&GrQOY^HqPToT2Y%EU8vL!Hr6ETv87rQuQ)RW1Dv#LyjIGU% zgN!5#jx04ZwWDSZqug5LRHvh*{Or4?jhur5S`dT~i&yLD#_}IW(52!*wvb7Iao%d8 z+ucO_N&YnIm=^H$WOhlZdp!;}c!LrUr0ckcibIQ0R!RW~^4pmB0o%$|w53mQt@9xj z$SvqD6{Wyrsp3^kS-+ijLc;mx2WFLkj-s=kzzsbfK9H#rZt=eJnnDmdiFr`@g-TS9 zdLP%n;L*d!EBuP7A@Oc2Dhk0xnmp_Y?+#n%*1CAl2&2`mV-NUDIit)-2vIqFmlbc^ z#Zp^jUG^SibTak!Z^Wc=o2QX|1?B!fvctQRL3W>ck*tH(yCWvYF*MPu zgJ+L`6b=ERwHjd2wHB|jAkC6f_XaAa_(XJBX+$}C9*s>dDaQkO?UMVo#xVc?W9lr! z;%c@m+<4;-O$hF;!5xBIaDuxN+})*vyK8U=4#C|$KybIaU$s@fbaz7*|;%ow|v);ET#(bdIodvG=S&zFA% zk7GC=Uj6EI9Go{-IfqS-*57BUSg(F8^-(K*m%{mMwDzQEu#-POklE}%K#p-ZckH~g zv%L-ADRCrAmn|^x-!L zuKnq(%Rc|++Na?9mV$iuje1fV6^hLzif!^i*uTHNH)Q(z&B0h;(N{H{lmwd#X8Nz# z^?gpo0bh}+I%>QAvXr%3rg04c2!W{}ilcj2S@tiMiGBsr1!uKaW4`2b-C3 zf$5Fj+;%Guw-CkWOpYb7B8v(w*xrQMInM9Cu21$bVo0#cP4zXt1=bT#_yw6Bg3v9^#{F z{M^X5lb*86S0za(KwRO<^ik;8tA*O;iC$FnhmKUi7QVS8`ZbWYx(u0Us&e z8JoiaS~wV$vN|HXA6_{K-l~!JVX3`(?El`{HSSUy;bm_AcYvs-w`!C+%FU z6BM>ZU$t;bdYUq*Z*Jjgv){0K<&@ai@hkF_fev0APp-JMwXgaDx$qic&KAC?_>myp zqG~;ApBQ!zqXeR9?H^ByJ~w%;)w?A|b>3Z+yDq+*egEmn_tBByWPHGV;$ud^p6u&Y ze~9Bn+|tLQH1o`=;+Ci3$xs@9L-ND=+cGICg%Q}zg27M+>dawnmxE8@stx4Cd06~4 zneBBmcrK5YNc0}YNl7)kwZK*D2A(9peB(bD{bt)Z6fA;;!`lLDtHHFq!6LtUJbxt} z4;_)hsLB)b+uqZ~DtrsWUuR!EI;sEkyLAjH_m@3UCO{N@KtoG%_vsZXYhmA1iiR0f z0|z@iNnBKk%~lXzB*TV+jPik9tG#N%Y$1~@uFxQrmxW1X7>?FzxSeinMOVlocEsF< zu7Y9Jxi39g9@dwu#M<=a21qWV%*w_q#3z)24Dyr5#B{xyyG=u&u$Ua_EP7Y9g|GfC znfqkhZ2$$p5R=8Evsu>Co_UHq*$N*V@q3<8W_9cZBlgjtC2*v9^q-_-FD|fV;W0pb z1TCWntnHYqH=2*b>Xg&hMtyD@Y%?_2>HR!hAK$VqbY6wJlCdgC`zf*VcUb>8KYUq} zQj(7=mykbf^qgR->YSyRT5E_=Fl>mW4$X$^gMp$0$O8bU?&7Z_bDzXb>}5xeEPg_3 zS9SP8r;>g85K#bZ_}e8@!v1eEa}jk@KmG4*I|SNXvENgoG|7x+rD#7LjjG46p1p0 z&3>lEc292=wlJ+rD5zw`_1sO1hof73v$%oO3y9QuMPA{$`?-~Nt{v9RfZQE=Ymmc@ z2lsYyQ0CbFhff7dCg-WN7Z>#t>{QXi*ryJ#HhE!h9)gIVlL<-^}TVS^eLZOL! zDAIJ9v9A+B7)TEi7}q8Zg)4@9tyd<#zlZ5O1q^E{Pk*Zd0Ns-!1JH=q?h5{(Zrx0(=FD6yLl+rlu?&=b=F3c0Gyyg!F z7;?0VAre9Z(p2ID#GU-->gW~b)Z&~dsA5Cw5djW(!4sO%9p5=mOIR{6#Z$IB_~{w= zcCk|#XL~vea$`nnX65mMjaeOyB$ATG`qL;Oa{oFy3?S@FcPw=I;cmpkqqqqf0Dy7T z|3JyS$GRE8fPaZd90O|Y$1Spait^$=b#K$99N1w9#aDV2OYKo{w|+#>D{n6& zFezIfl=Q8-=N^s35c6wBcXFUk6*mUK19TX1A7#Ms`XT`6E&23_p?z_QpCH>#AbN7t zSxvS|T+f~p?gyyInK*(xT6&DU*T89QQMBj*h{p=B^~J9X-3f?S<1Z=y@sSqAIBrn7 zQI~PMHqGN_Y|&)^#H~tMt;=Rp^c!G=GjeB$c{~;hAQmu&wY^gWII;pKjqUlcLA2Q- zLOLP!5(0Q5`G`RQK1~?Tb2#6fcjku1bw;aP|19`i=X_2PbncJ96mRUB*KwfMOcUT* zt{+=GWZ+~Yyye9{u%duX;R8YeBz~e3$Z1qtan@s%Y^2cqyuo|*01uG^00CDIM@^lI z`pps8-JZr=0i6J#m#>=bzJr;u=nt$CD1cUf+-gYl27r=~%PmGkRdZ3N{v=XxA<61K zmgq*Of-BCL!;woVLR?yu)k8 zQ3);{0j_c{+&z_~0$WkHP8vCjN=FeGs%gO<7z7dRlao{V;04Bi#ETvX6WSGRIQNmF z(pn$BL_SY)cX4qcc{?m4Vl|meOvEN&Cq@H^0JntNhWd=_JlKgHx2lS0k)HCxF=`(% zh8%%QAJL?k4{cCjF~o389a`lZHTwJMx=k<{bJC#1zX!L-Cs2C!7<{9Sqvsak`C!r`Ri|l%%y)`wDuxAl`zUW z&LGd?)_BF>F+#ys(yJFJy-}%F+Ds+JBzE3cso{VjWG&rb$dBp7)XA{6*Y z(m;nF2@Dtx(jgo&F(UFF`RGry(qaivaP(zya>h8BJ;t?^NgIT)eqFhD4C*s|gUrPE z$Ydb^+3f;~w4|v$*CJZ~j(&0Q-@CdF`x>$AF$~!+pGNPxAphv$4LmYSBx2ZOJ2TvYb#LsYX~qXn|CXW4v}1+ zmPrnug8J*Tg{%#Sajl-;!4bK*u9T|A0$8A+IK!;Uo)vMDhoff3$!r{e#7YNmKw4xN z2N`3ia2%&Kcyuw~3~0oZ{m~X4APNA4q4JJS@6f&r$;7GpvBzu&`(0=F6{0=PB- zg|U$u^qYuELm&mh-#vjsIsh^_wuHVtr%+v`wr~iZHIB?Ya^8t81jm>hd`HnWgnj7F z9#o(lfH=}nyQn0Sf}{-_WQ!<=&vei{3xaGsYV4RXb38iTeV)ca6BZn#MTkuS69EGL z01uWLmfm#PVwG+(nQ>&Y{ueiQz>Iyyk5C`i^`G9<`lU4j8VDjBF)b)unIopqDG>yM zw`bw%UcsFZo*>Ivg4v{($1L2AG$R{bj?<#}XrMnFKr8|xhtQ`TwYBHM_iu8^0Ti%ltDK4OO8xF`;J(Z%2@G@l&0T` zY+0T8T8h%4!rrlxvos36*{-57R`~~=si=E{W(o964)X6~HzrWzCNGT~+vL0g0Xy=< zV6ZB1615BB>L;YxJ!10nQN{kfqF#SliM$&(3Ijz9+_UAtW1Q2>c0*Uf16gg<+fWz* zK4{_nY0Nk``m>H!U4+e9UoY(n4dR8K?*zoY(d)UZh|JP%Ube9*DHkaxjBlQQ`%EfE zl}a;C)L2zHI?SoTbAu*6JFO;U+9Dt-vMFC35ef(hpu%!YhlV#peMuQ7HH7T%yX*ug z@BsWNwl6q)P>dNASV)-IfFOq5OAi4Ye%fIGd49;&^`li+TSs%F-LqPSAcByh+FVqFJF;pa?0(Wg1S1 z2xU@m9(MrkU#IJ|_d?wfl0{qyB^CSR6gxmlE^$ydakqS}`P<5rj+_mujQg&XgJ)M4 zf&*eh&DgZYvvcugdg^{mgcIjxj=~ccWO~cY%~E72y4$Y#GGb}4!ZRgFQ)yl?OI^Z! z#7Z1BE|g?!r#o9MBOF)O@G7#`gL_ZMKLCT>xa=<=_Q=4`gMzsB{?5UkNn%h$6Rv{P z6@dhw@^-Hq&DgZ%(KKv0;XmdCBslzHS}Vzbr~p9)ezybP%}Q*t%sm$bxnmVw)R*0p zyjVY|*d|a8Aa#sMc?OdnI?fJO%Ys$rwB8pVnge~f5=WBglP@Xu*Kmdq%XZ_~U6K}G zMG^70%66|h?WLq#>uG4tvThNV=T}xVTAQ-&`#I*MXjGV1xNXa<9#9EDVKY8t2plaZ z9U2VKF0s7zNPe3}yorRYY((?(9ePH;Z|T1`1C_+|R|kyt9gb5btv!H0P=nKq=h?_mAo z6sjwkG=bOOcV#lV7;>?ygaK2YC_iiZWlcSzsqb=AhP=`4n%Cibe>txV+9-Z>FIv3Cb}Ov3afdKC18?rER4@XGuKQT8{Dio&GAiRq>Ao-~dnnfbgWjy{S|$ z!ttu*tKn4?+(=kxy0ESI^z32j0n?z7?E#cboYZxnUzYdf>K5g9>TB_Z@nM|ID1AXb+48QdrgP0M9;(KZr_N&V znY+p-hBhTahZaVhoH|}ijoFS!a3ig~NRzlfGoHuS@VI~U$G0^#scuK(jG6Lu{}E^% zIhBG!SH!B$>#P?7Nf$DA^@HO-a%D1+KKAyg{wTH*yQYVn^j}nOOz?Ck(0#h1VHLRxI*~4p zmi($ZlVl22o3P+@ZPJ{2%BxO2H`g4-=dkX#CO2&G(M7XHU9f;q;!%%}onCg4l4z~2 zpq;sYxH^877?0mPp%7@K=Z^qaCe>sbmyv^M)-L@5A6o*^RMdg{N)X6v)YS4j-w`Hu^k>Lb4PAA{iG}qOd=BCiG4Gd zHtc808vw7?wt*N|6dc$p933eNQr6!{5`U;US!H%MZaai~xQJF}`KD8qyyI}H4x6%@ z38V|$KY2Q){wZ$-AvnX)IalzKT@{E=n@BvM?BbfSb9K!Nj`nir>1*%xdB$qjIjWI?&_Qe@%D&_q!&>@(z~7J~&1`s-lv&<%h?6 zPN6zCl})JTYzxM^-O=f3V_P5w?8n=ACVGKL1}rE;etakkCvC=*B!*+e=P^J3)ZqTS(=d*Vo-}Z^{g%_jW&0DUwq0;g-=adha1KuUfh1$p z*biae)6Iq`TiANLw@mieiRH?#M3g9~CF6MDg*MUN-ee^YTJ%G9Ao7-clLUuPilw)< z_RkizN@e6Q>RMokGwjD%v@AhEYCsa8zPa&lz7TDUx*^ZRPGpwk;dLu3=>?V^5o*sS zE;?a|telg_uuR&r4PUip8HWAI8LO)cG(8kx*uq(wf1lljaK;d~pXjv8%kpa27}wur zxLB_v<*vMOubn10TZo?QPy1=AovVUBt6iG2?sws8XT&!fv&UE{Iuf(RMYrV_zcNbm zi(!#lqr+ZIg5`j>9Ya49sNLw>bRCA{@rBVRxB5t=YzvdmCBx<3%CEH(X+EorRt+~% z32a6ZJ}!Ab8lI;2#jQ+|0e~z9Y&c(hs{7?~LOw4r#GX(dgxPm&RerqI&L5tr$Uiov zaX3-^M=qvLIS#_N;*o7D?kF#dp@^XNq+c2?y34r2LTun)64XOYrfOz1hXUR{ z;P<9Ov^We_3XVz>m*P}K3vlv7N`xE7mbVJ@7*P1O@%@e5JioR?UX zDu4UkEl89}^#6JxW2J?MK?*~W+tB%v}`M)2k2o?#T_qSsGuSf%yWTWsCQ3eoeO zH>5&15FO3m;z*j^G)R`5C9)ad01@-G#+_>eL}HP)^E+01s4gC=XC z7xtbuKe8@opl7%PlnVc`lv6t>F0$g0uV81I@@r|UZciJ)0FC1+e4oaZg8D!qlhCuZ za{ImbQza$N08ZKGk>&kDo!CKMmrHtPQ->BYtA@M#b3XChwPh2#`4s>^4NW1E3Ut;T zjDzA%ZyM%bEmwW}g9W{zZK7X1xZ%6NJ?m^Oyu`Ran(I35Pt#ULV3M>L{6?yZZ535l z3>SmX9pbP9P70K}n!nHA_8dk%cwt$F2A7(Cr)C+lrHw#;q>)%QB~a?# zB?nZl&Ce%`x)yxJ!wf|nJ-)Z)NnlqTw7`yIikEdvr?kenzRuvVaNGWaVejq!MaH=s zTS4ziyT}TvhXVAoqN2Q*S2=To#N}wDKv{$|USYWex7vS!4DV*1Why55!}lU{+YaKfOZCk;sV?4KI1I6tWVW z$|VaVkpke>8sQHIYpcp>}h-!ynL;l4RX|88m5&cD2Hp(l*cymhbtJ zh)qTqEIMs5*SwI!#FU?=?EkZ;$Yjsd?6XSVxvo<`R^ev_rAeU+> znB)Oz_dK9bgw^tIX<21li)B-14bXEI*$4n%^vxw*-iMI|4; zPQ5c@*^vLC*T1aJMNS+XNfJviywrw`x)d!ELsRv>wn{84ZyH2NiYo{*R}F8RTa}8I z#M@QN-iqT4-@V@BEvx!Gghu<5(Eul$6x6^<|9JpO&+rGxN1o60CStFRPcHTpJF>1H zAd=3dPy4&{6JvJE&du3eyp{6bYKF2KH-tfE+1|9SU#|Yu=pqr8@oDF$4NaU}T=ckF z1>DjMR?TH)`Td)f)po216hQ!N2?-inRqWW)mpzdyP_c@H6Rb+BE;A%`_hJ}ZRa;y8 zMaE`Z9sm1x);~U;`=$dqFt=+9TAuqYuxtQMEXkqIk8K|^l+KvGOT&2FA8q5Y5hW*M zichPl>85m*)YP`LXcaXD#f-X@U_UFEAW74zInaf^o+z!1r4fjx9LcNesnYy_0!;Uo zJ{*cj*7ei;D6-h#8%TyDMH1v(mk^hN#L4OufDM)rFII=|QLn5HXJJ zb|JKLZ*0Q{Vh*oK1_+3EpQ@6p_T_P&Cc5cGKYOF6^fWEN0R$A@jMUS(`@g@Mpnrdb z@2*5Ri|H{tx}n<8L`l4mxZI(h7q~pDGN4{{9b;;4=kVSxWEj6^@_P$yM&TmWD3)*g zHek_5Zt2)%Ay=YAr1P+PrJk$%UIms;=at-)+uY*WMk{+Xg%;(}oAIK9ErIsc3A5#!ISy^1y<#}_3s5isc z8!borX%b*C^j)?j1Dr)+3mUDhJ8a?PfBS!QTH|9UPh8(AM<|VVos_EdTbf29#K~ar<8H z4>dM=wK6-75=wDU5MZh~A3VMdN{p!DG51eLrRwXk9w|fs$Prjt&r%3jP#&|f!h+O} z<9&6y+Mcib007vM^|!FI3|+R;wswy9uRwVsVPgzjOjIoD@{8-g8pB4>!v5>y3e7(C zClzKSL&!To?9H_B>L}ex6X@1dRIH)*XF{$(YM(wUEWu1H2{c|R#o5Q z_3rqL*#8Wc?@Pzsajd3)Q^$u*TZt(@yFxB1ZQPkeA!e4_){=eu8?V|PajZYT;(->* zC=N$9(mOKP`x7S9W4T_JVI$wfVKL%6JkAuF{atOI9+`_(%9F}u5Jm?@{&m7tJ${{CDwOqMXO=8BK1Y>cfB#$?CSZ4#BUDNv>pQy~%L*!iJuE ziQjVC>~%4q0n|cmkJY?|)TlXRzN3x@RoCB|pW8*U+0LHYgggY4L@*EUhf1TNa42ej zFW7q6uJ+9X0_dhHbGfWNIH53DycSNh84TVwSDM={Xqns(hcBUiB;Cx>%0gVurg&~2 zD4c}}ZhuENPx{+FG7|Ux@O`G=^)v7zg`33{q%#bhQD+epG^O*9%!&kC>dOIGx_HFT@S1ow4;)S zmaIKZB2ZM1LRU7Dn6Kg;tiw75h__I5Hly+bzC!Q?MTsw946o(EMdg5E+^hs&Di zf_$8xhTMGy4h)ERZnhe0h`n4&`PdREEK}!MudkCoCK%J0KOwIK&rb#+Bz;T>(z0C# zFHwHI{v)2~7l09%_N95@ zm(>WJvzGfZLJqP}RZyUduDk2hn-qRtaOUBGs~qOD#XijF#7A-fNH9s7R0 z{ZMsON}Ta1V~cye5GHo{yX$j`rGmrN%KLqcr<&W=c~*uE;}+Ys(-M=5;0E`v3lWIHQ(2tRq)&?L zO@}E{bR?(*k*e@4E&gM^i~7xOTZ`xZcf_)ZL#B!{eSc7-xldOb><6$nazg-xwRGry zMPnpMjMwzJPopl2+bru(okKyEx+wt$*ZW&i;nbg5MGo5$#RV@TX;9HS+OB4l)=S7@ zusPOwJl=19_avILfvOQw<$qzS=rhv0uUFj*y6d2!U~vAb+=~Q2kx58LYy~?@9-~+K zUK+H;m``=NFH&3|ROwyR#0ov9$zlxcj!O^8pnVUZ_1bMX@-Y}F`h4#fqzxsT<8j$k;Mb=L7@{CjMa5-hAH* zUnKeP%!`VdB5;3n@J)~N6RubY1C2sX!_KQ~uFu1rjtay>#7>2T;R7iE00WQUS7j)# zu?{jUCwRU2a|-C6=%j{H0!4ZEgnBNcZ*;l|74j+xx*r#m$sDfcA8ec^`k7^AC3|yc zy_!&o#4Fd-7i#( z&9KfeZuzIx!G)3dtV$xpI)W^9?DLndE`6I?EhJ=Q1_lO;@wE6v=Sg#Ph>EX+3lX`A`6`t zW-*{eYdSxp4`Ag>50n3kvo#^ug@zOYO@7$m)(jE^k^cDzKWLhuo31e|0fJvaXA=J9 zzPDakRikLC-?ZYVO(r_M^AmJSof#YUzxj&j0VFiDQ+u|SEwhCDsfCr5m3fGE7)U9L zalxK0AEP$+9+Eb7fDAg;ImP%1d4QLoG8W72XcQ-5PZs^@L9gdh8i$`S&ADcA*6_75 z27snT&b)sRW$Gi88#y;^R(f3b{OXrrYD^ivcX{E$N0v%(!$$xW5!m>!Ng-&%2Ricm$$c_zBD2^_Fl+}{Utn^CLWnF z*!Amg}_L+a*FWg(FX;d4lJ#52?*)7Yt{mvDf_Z5A2ekA zLQO$d!2e5_iaR@PZD_-p3a1Tw#SbQ;rhzagZHratu&*t<#vmV6d=e0<=`vufANhEJ z!PqD}ECHNx%gipI?UWET=9DyeQ5R8J$Vt&}8&lfhNgV69%$Faq;CNwf8#vszZWNX<*lX7px{uY+O7G0>FqAMJFS-%1e8`qM7KW z5|M>)c*2T0&<@XA!%^-Xe)572pjiy7v?>fJ@!t_?lAuqPlxC^kds;&aukBb7g~{QQ z9qo_bFm`Zm{ECSz0$fFtqop;S)z9o)T(!A33832Eg6b6M#+4;t1+gx;{|OQblOT`R z{j>8+zD}~&2&P7RV`%P3EI|;>hL)C;u4G`>*+@4z37@m^ubrY2AehHA+N6-vc91HU zQ2No9x?|lI`PMF;UXpsd7AVo`wZey*0|>$}fiRdFxqh>GO>_w14=$AYQw;w`g4|MWdW^&CICa^ph?x#6@wXX{WO_90C!#^OLW17rF2-CT7#>**$fDr8){~BG!F^=C&y09BX1d@zLcSG7v}OnWOf)@{A%wT zokOMxi3?U?+|crZmBVA{w73ycvZJiMWh^q8#PeF11`Ju^HQbBxGI9^H)tX<1Bq!+~ z#&~+gk=tc2M!e`x-AHh3%N9qCH=cCyd|yRoNe_=m`dNWN`l%hwg)6&-WblrG5@d;E zJe2*GU7b>~4jQH3bg}w<7S8Z=;wJDScqtoPv_1H;LxMxm;KNZo3EMsfzztxrNj~2& zJt?QNv_0Y8+bPb0OL@$l3TqasvK%k$E>C>M-OaY?4*fcPh5kT&~$R~gLwc2r5}K}_Fq-bwcZ=1XAHK#B}_PTl!`tuT^jf9)ni z#JJ$8vda#8Gg}yKNvSrkn8OCZN;+xrV2#Y%9ztxN#Z^hA9g^sab;qS5!i2naO7bB_ z7MKbcD6$yo1;)3{gRpeDttE4&u1}UgK$2v?4D3g={kAxk5Rek3DlIOAFG80)V~9dZ z&e?oIvKu#TX8E_)%O?(!-7?0tmD8*r*h0fi2uEmPuL^+F_T01)4gPTB58*6W@`+R< zAlozceHv8$+N8DSU-*d=mH+zfFc_SfM3KTs;Pi%-vEggv7r~mMm7fy*n19LTBHjP@ zW|Jo{L@bA+J4LP^nhWR!nHtjqr*%Z%me1XmyffRF001t7-d?Diz-dz$SV6@KI!+~V zkQ}8Z9VIju%uVk6i(8!NZK!z_&?264#AI7HJ!J~GEbm1U3PDp6W45R)zdz?2H?K?_ zT+1ZfcnEZnJPRYl4j~gEpMTQPsC@H$`h7{ihkKqFjudH>Hg}{(i(}u+4?=+kWGPx0 z85!xtR&ZO5(7o;rrI8Z7G!BMx5@lWw%O)<}lvwHd>y&m5Vtb>V39oV7bm9-u9=*>Z z-m>~5l6|ijB^~!T9XTfddGSFZt&1t{3TpcS-`W2}ftcfDop8|R?JsmF;x#u#k)vQKnxhPkX_@m0j?-GZ+Cy9Qtfj7 zfUo7Vljf-!_MT!?`0i@iMW`hw^k7&>>;ARp@bY!7Km3v6#Xrw+{&;P$UuW{=>yB8D z|Ak=nJ8}MNZHg+yf`YK3ijmQ3kd?{!U2rui^gkHX-j^Xv%I}K1KvkUI0s0QTFYusK z?xsar+hBF|Yy{x34R*z8C`Yz3~BBUgdj!XYp(5D!G9rK}(h|m+H(L1A;~Rhwm;l(QG+GskJ>6oa1y-Xse31Z| zDA;&{OBKu*gXG&72-Y0KHiwp8P?5Ud@rotKT@(lvL8pbmF&)bT51WxBO^WIKmN!uH zE@(M^dPvK>-n4g+((+idM@?z{oZE(WJ+<|2z5RfMHvtuNvG@W1$zWp(8qmiYP*x(; z>h!l&IAp%+okfQ5UU|8t>lX$D9t)KQK*@PN+wA%Ug1oZ(B4s}1Wja&|d8rvHo5|~Z zbe8V#%I1eJB#PE$_Bj8T_`V^I!|ycHL4m*ateHwNZh$NX!=QJ8#D(&{c;E6LvxfgQ z9m3wH4~Y999W93O_H`#{3r6EV9%TQvByz@uR72o@fE1!U>6|)}g+R!6x#jNU`Vw9l zk{3e_qBRo>b518(v2MSIJ*e*4+dA+mu_t4;xAAD0=giC`^^zH8|9zGJP;Ofx(KXl% zhSA4-&eYo>R~DZcz2*1k@faL@c>M!0G-1tMTliXc{H(Wksu=zrwYW*EY4Vsa9v-XK zfMObor6Oda>8)weJa#WtBRtD_dRpJ8@%wIht;bL+6#3tfY* zX=LiY<3ZA&UME$#V9~BEL_#s(?;U$DBSrw=Z4`%03>a?qy#CNiR!VqtGOHcmBb>kj zQAsw2<|@9CS;5dC_IDkwW!Xgh;di+(Nrt=xtcd+5 z+VAbj;d|?f403V#jZO9Csa9*-gBrsC_D>c9#3p=w_Q#!lO`5toP1b8Sj^k8d z1~yGh(-(jUNT>H36&=M4#|J!#Q!euE;h~OVNpYXzpg*MsK_*@ z!WT7GOSXAD*Ypv@M`TwSl37H(nkM)$?Gs3` zVYi<1q;RZ$YCVk7@?wv`I{&hoNr`_w&%SD2E!gCwGy5=74(#gOe^{R{d9f@QUc%@6 zr1s(2I*W~>PI5%~+iU(Ds%W;bzjVgyLzC(RJickIHm3qbh}b)M2yIk>)rS&q!kCjK zO*5n2JvKT_2pQQ5Lf{Al#K>E?oyMf1Djg{2t3eE9NKk@=AR4rh<(k+T>=3u5WP6QAua8j+a1}YYXFA}mKBUgt12f_BI#pn%GXXeS< zLkW4~EJk*3K#1{od7jg;;j84KRz=Im2*qG`y_dZz{+o1JhSA5m7h;3VRb}(T3IM<) zrA_1UyxNV&Mvw`0igTEJwGaUg()RHH>jISfxF$n zNk{#I>)FyGT<9=bz(64guEBck$Sl*x58lA<-tw`#xVRA$=`@d%3IMTm__p5h_?#T; z?+#%>^c5WkrE*i>EDPW%@n`T-YnR81BgH0B;;r($4kYT=G^2+r_hJs3?f!i@`B{zo z&$y2ZgIto|THYvGy>;|1?lI`~RKIEqym&O#WZz$$#(q*TP8cvyqLE8>c9s=CJ#(F!J7C zSJ29x=w}}%FSj7si2z?}XffabR!)6qO@2WO+%%`1uy;Z4>de)~Z&}uiU`NVJx+8)< z>X=a(Y3x5rT+7csU3<#WhgPNTu;bhPLBD^WSneJN+rRI9hm<6R1&|?>5bEgRF$6IO zcU0J~Ecqly4PbA*nuv`~J6KP>o1Ay<>{3s{1G+dUth~F{jyv#I4)h)SP=k*;+_9{o zcPU_jGPE+%V&|U>QPPYv%?a=Acl4|8_3zG_R_~HIuU~5q{NPpPNoTG(hOE97XUDrW zdVS(J_j&0b%FJe@e0#u!JY7MGU-Ok|aY}H6M8!u9?Q~CQ{_cjsRmpynja;d>I4a`j|IM@qbnfg zu|=GLnfK;mex4RK?M)YtLFz7LUN^NlIs5Z6fIvjOZ+#J-Ku0Yf-q`dI6qCV}8&*u0 zZ)_v!)I)Gk)@1*7HMdZ;0vEfocgE84i*^F5=J=G?*aj#t8TG0o{Ee|?Gl(3A+EVOs&o*>Fy(wgK>LQ z|Juv?#SGSwj)(1bMrW~%zM_JNMe1GCfQh30fYe9Y`hL7m0(=d_RHcnt6|?CoQBFjX z`WPZM3bG@j8mQax^0j%5)W!Qj>cPM{oms3z(+Xmr7SA;rWbRLHzo?j*sx0r$saNb6 z$=oHZ)t?V?{T@e%{bvt98q3JZCsaxXl85wX&HdOrxn$9K-10_f86Po`W4}uH{$ahK zc~_Bl@!}?Iieb$<`R_@*s-)iArk$&QPM2fq9Lv(Fr%Cn8PBI0S1ku^S>D_PLkx55r zJUTqs@SSOLl-avd$XNb+Nd12NiM;CL5TVfL*cHcM=i}0DlQ{u+=jJ6D?om5Bym`vrC^9|LzSm0b}&5bPSC;IIQ)- z^q{?dy89b$kV>@9I7pjf`Ig2+q7B}`$NkUji+U&OF`PDp{Fuc+3iTUZoIkz|!2led zx^~oW7IIAS2$K0-;CMOwj02hEP8~S#K&-?lWdNJkj|){gnsZ0)`vzTway;ft{kuJ0 zxNjk;FTn@3pj}6oT?56NhC+Ny^26z0QdCHNK_v4FF7jVuACL2>z)U1v zdxg=CCk6kz5dPJo2RL3Mj89r~?6D;#wgse8m(1{gD+g)7-7$!( zx`&(K9KOhu-(dkcGHDblz<^HwA{{2xWGHkF#I7y{uK6}jndt31<KbDn$L;KHijXDQp^Xxq5rE~nma;5vHDKZ5#8F4n# zx}gy>s(PgVT^;!kHG$KJbw((BB>3Wo5**b3v_5oO3mh-1YKpQvh^w=uh9~t;Q{SRV zDbd#lL*Y-=Jqi>f{$JO4@JwtkfKj#B4UYd@Jal`PG(_>YoWsuuIjc>T|8^oO(XAH} zA97|`Fx^hef7=?mO-Tl_eKG;?7!jtObR>)&31MG(hyedw&1ny0A?#TQ~JNSJdlI}FcM)!6`&{#!%fiOAyN%85C?onoHS(=019A&Vj@q63meEz zJu(~F8@WSKO+v!Y9AyIYj-f0|U!Q5yR}sWneZ*(3er#Vvq@VM8stf?Nkg8+grE|>i2?uMlgLjF17Y!)uf=*_D}aD2S8tdjQTNB*c?9YfC_L_MUqrTjpHF{UNY(c!~(1zSmF^_A<1d~tPmez z+Y8;$VByKlkZY=UQiML9F!&EGATb~m)S%HOD|86erX}M;ZvZbekZm+=JWayHqyqz9 z-ng$1Ls^79FR<1SNSgqK*$sjj#GxPsQvg}>0ZDAKbjftdX4(m61aa~nc+V8jQOSy- z|DAH%-eQNacDliL^dZ3nEQ;z@#;7V0WQJchee!-#69Vo$Kd8_AoG48Rpdq!=?wSVy zX3jOq%Gsm9(GmsK4q2dCWQkDAu8|MPB6k%8)M;eY!4a5?gg_W}N5*wS6%L$Iv=MXP zAeoqQ9@L(X;sJ;?+l|z`mh(ttWnXOSXY!VM!6nt5|FouS4H24_OKTsjb=Rq?hXsoQ z6AeHN6cNmyuA{;G?dpJo+I8A-dQJC)w&!g62VHYQntI~n&un0tB0VZQm=TIS;F&hol@|F&-r9H|EfaD1uEua<9< zMA&|}+r^)kF24dqoI(n&?(Gfem9oF`Q3#iLukd$yniCBg5dgXkmBx797`k>PkFRe1Ia?MD>AcM*aO!ry2Gk{D%@V zK`vlR+Ca`M{B|~7Jh34Xo_Tpu1Kk@;w~*c9n=43TkQ|Qu{{|D0v&usGNqaRgq^&E`Pr~08+%p&#?H6 zSBN}CWG*s%Z0+#Lwk8^6csV>|VIJZ2sfY8!RqKj-lH=J=LQ>2C$>7cP`u57MYG0a* zNCZhLbT({A>?nUPX&bB$OIaluuQ@)4u+EU2Rc)xJ;vt57Y3ZtIvwIFC_V6+rF;J&h zk4k491hnbUTT3gJNyYqu&KV@iUZ`LhQF7O6lrHATbiU!k71i@@uGHyp`0TyCiyW3I z8cp%aTw=3!U31}{CA@0O{erVZ_fNb(c}&NI1~)opUs;u*P3FS^(*W`!YInBP@$$xT zX3+|nf*uXoY{8rO#Ssg%!#@(zQ{{P?8Yvb3G8vdz(Rv?MHR9>a9;#K&4pTCM1zzjs zN`4#=4pgr(pgzB~ZdPO^tj^L|ebL7aq$MfFNM+|@FzF}A8s6%7=nz_rXicmZe!cN9 zz&K7viUTYAQ_2Q>7FW>0v#Y_)b2z)zoFF!W8eCP6HhA%|S*pWb!VZ&m=QvM;D-#`Zc<6wr((EoAs2LSxsaT-@r3ldpxF|>wh!(oGGiS z$Zf4aUqFfY<^OJ~ex|_&rn#0M7w=Y*PpMDX4rnJu+`LkyLlSD5Gj8^U<#d)#rbhI;()Tf~`>pC=?2`xVsm3E$&{d zxVyVM#R|bGE(MCaJG4k}cTLgY!Ch|7!}-sB&)%7tJ!@w9cQaYiQITeH{d*Bp$orJV zTM^}|rrpo3s|pvx}XMdCsHOhjv|~EpIt;BBh2Yi6;}9nZi9X-TL{SiVZ9@dF9h%MFaLU84+CmnEogz zi!Mz5W2g5Pufjb*%tdY%Dzv0 zKQe+jXA#yv7HB^sMNJ!;x=zNDOe>n4 z!Eixw{4VkbiDe;;y(I^k`!DsYLY&_iRyj&q;glbLkeCd(;)&DR@iRvuhSP>Kn1uk? zDa7Pt0LYl(C=}xWICx+NaE}6pvq-bxIwX-3X`sqEN!ja2!=s8s@-xZWo}*vCHF+*! zV{CAY#L)lDZCFO<&5z*mhI+y;j8pNaV!Q|t=ub<6zk zz_B~|+QcLbqodqOyiP41~9OTMVkQOl9r7qGe$BZ+0B7|2s1X^KGz1rXqA`^ zL}GlJ39T>?7I8u==8Xe;)EBRBio`?T+!_9NKtVwZGvWPN6!J65U|4A4-YQ|0!qagk($k=+L zVzAlNVx@k8^pIUc^=cF8;!mije+qUZS0<4Ji5Xm8f_iSuQicbS_FM_9&xf;0Y-5>@ zECalF=17KHA+th5!c~j5CoR$Si2S!q4{#a$g!33&WSWYmRhCn$WkIQy%bNZ$kc+Ts5zRUZcB`PYYe5^J`l zirQ2%D$m0m&FJqghYV(hS|UE~m%mp_3!AB9Knz6+$Zb|koA>&36{tz3JK}29=PyxM z+uB|}w178FFBUEP4}zFv8y0Fazp!E4*goM%Zuy_3GQf!Wg@H(@Mm18%@LjQ|VY*K9oZYX!=1;1}G~rZ9-vl-8O68>ahf^z5NN~s6>`_ z8_;j8Edi~NOo+_MEbI<5QhxTn#5wMmSg2uJi$sK*g_Ei;sV;Gw(9UHJ`rG*)L*frX z5oe>f69Y6mE$z1ZjzP@MR89TiH)$+b4{r(j$$AGH$$36alt%lg(&_op9s+DffiD5h z$ax3a58eug7P`_^OTQq*{MS(W$`Bv&m3f?B+|GypZ-9a5FZ6e$_|Bw6xOn!?k^l;m z-w+N2%6TL0jm1s&o442dCqfMwi*1__sW7jiJMyJ`@IKMTd{9>0U__zb_ew+u-N`dy zw}pTsph|crR5y?e-As*+adC z-V)CO_H$0%t`4GekfBKL3SaK87J-K!b&7LQ)*Y zOg+$F#{_M=xEf^Y?Xq6XW|R>BK%bDq_ZZ)3ozV1&)0bPK!Erqr#W8(R>&=$~AtWv9 zg)*Pdd3QQM9A+H9Q^Ig)IT^urCoi)jGW_Mvo?aPrW4|=<@O2RR?``4dBFIJngnO+O zDjS|5K;3>{(>a*sJRA^>(YM02Z&WpxE&8&PLntW29+$xtiNA68T&EcyjC}a>E3kTgG!5oDL{r$lHYQg`@diP%Sen*EI3OBpP+tO~kcl zC(B;N6}2EIoy76ke;&xi{R5N}uLJ9Usl>`WKGFm-8w3`l=cPz$eVh|36)Buui7m-- z?Uv@E6KtXondD;_cy4M`qCRz1>Nf`<<>+M_e7S9SB4DLzX?$mrEwMofjI5*Y0U#Y3 zER=}8dU5^wx9Pvzl(6#dL5HFJjMKMlKo{w8R7hx?rHzHMBZ3t{{fOo@%X$pc; zRMD{+VuO^p=E?aZL5T zNJ+ipq(B0Gl}Ai9=QNAvpyE;@EQzK9`Cu}b=wc8=D}5NDPzxiJAh9F}G5zq)RNUkb z1}?iq2(1_(HI_n52`d!d{ELL%03{M7qnZ@*qM3|X8Uwt1u}91QJVP$eK85CFUzWSV zLrCGf^rBP}KbqGWMS#6IYeJJrE+lMzaZ&!k#CGHOtR!iKL5++d%|H};PC%`+O+W#{ zkW4il#gL9R18IOXqTQtS>zHF2a02R z_{h+U5Pk|^J^N2g42h;_jzlTK?^R}{J>UQ5I=YV_9`27fEBI&$NIlbUZ)QOyiR34>IN-U>FV82TnRF6B=sqLJZ8J2Ie8Gb*}Ib zj>OMMAX724GPFM!GU1#UwDJ~8@HEsiw0|;oG#ST9am6`24vOLGsjYvAq$;cZfA`W5 z(#xKSpIBsQ0d^$L$$c~`+*6+W4O#b3$v1N3RFf-ubUkc(m|f+P7d+S}nb@$6*>;F3|KMYd7e=m=|OZR2;&-D<1fB;eE z+=TkiGR60F3=$>pd&7eMO7b8eI=2n!O1;Z37XUNHHP7NwX|Xk2f09j8X>C#GT&>!m zt^<;L4xEJvC!qKb0bR5UNeLR);@T4Fmc)x|hlg$~%09o56%{+?$X3ZM*>^Q(_Cu6y z{(->~Y9SqNFBfmp+*6Kk!{qEfr=m(9o*n}?#peIX@tj{4tY3?g6my?k-LDr4a$F2; zT&mS#q2G4A07L)UEq&+(PUDYYCahs6)o)^zQma|Frf3k)BQ@@ayKCfQptk4MyozOD z<+2Rc3=zB~@@gyC4nS{irLTW@Rfnj~P(Drmt^-58@1iDd-{r=zb1Z|w;A0euX4*~W z@Gwe+%$fb^b8yghL8=VAk+ZW@I!38Rk~q^aK|lBE&dJ{}74xQmgzs*g7P@JDuPUW$ zCY~8Lb`nU(1%V$HU)uk2AKmyMV6NE2ie^&Z_lBr5M!XmbljRDil+Km6zn!N8i`bWYkS7`ukc#mN1xP0UP|yHStrBE%a#4 z&a<>85sX`$8r}1)RJE9k7>EQn#(iLSdND$gan0DB<#FRPek)bY6PtQqZ;(Ywc&9u9NRfk%fps>J8Y zstQGAWw+%WvxMOWX8Bpy3q9sd2_OfEVd^S0q_?18anEfZg4R5A<;VmBP)rDN2W1p+ zBif}c20fnS_~ZBXu9`PwDJrVhF}u5II?nk>%)ItQXD&AlABH=Q<=uN+&`%_dpPYCI zBStbH3dHoi*Ei&sg9n1-G+qvaktQGmaQ{FRX@jZ?IBuGE0z)^ACM*-ncD*AKV?o>eYNYfRA9TkQ^x>g~K9Y?(J*)RgUd6bf*>dTrT!fr32`k54}jf;~6#iBYs_ ze7Cx%HrH3UT=nuky7vC7c=mZVd>#E1?EO%Q-h$@tr;xla`phxlb`!~m7j(T1+LWJj zZ~l`)-uoq0U2Cm$>Uk>;*D^?*Q*h`$ze|C-$!g>IlgKN?3bJb}phxFY`n$*AX%?R> z!2FQx6Q70BS#VPi{SOY1$y@1NZ@rhfb{jWeHu(0rSQYxNl95SB>nWd=1OOOj2%%mx z>bhSM9{*##ms_ZQk=Fr=gTCyCX$u#pV4vc}?srzl?;=xY8+V?!cbig=jL4Hd6Frnh zQW+iG?}id@E)(+}xw)y^;=kSWvi9uE4B=}Fb&IE5-$+7wrbRt+1Oz5)9$S=0F#ol5 z1&xde1rV|F(JSAj6YX_jk-W5_4NqK&xk;LOng1tvD&*M_h#_+}YTmzK(Yb`bK8 z9Dmh}4NTN6bxY@d6b>^Kr*bL~6A^Vj4n_y+SpQo_Vi`Dq#mr$Q(bh%$Q859rsSIW^ z!5-li5t?wa{)eM4^R3N}Pm@z3mj*s_MX=(Hs818=1p5qoHceA&O}9{cA!gThh#@!q ziVY`?t)L-e6&=cjIFCjIAs!(XEwhYH-|mwUc|nUVw_fiLe4qGqOFDTfx_1bF-<89n zSy+hS7!(6$r4;|*$^lfOR@J?z%-Xd!6{b~8Pl36=8irZ}5Y z*R!$GfG%~$;0P@q=5uL!-zQ;HCn4kSGZYUQd%`wkweHP&#kUcdt|E<13Wmgp^On#8 zd!OrJxW+xfDkP6Ew0}{Q0#uSKeVskYr7EPn<|i1!>>wNNVWb}8AiP!{%gsN7`JPX` zbhanoie}c9>aJcygR(dw3F$ymj^;lWb6Z1r$_Zo2^|n3TJse4LQm+D9=hk)<_DFyJ z0wd}Nuv5`{(p9AuuAN0B&_ZN2qg)BT%b3kzT*)j@;iGkQqEq3N;1EQ{tH?DSS_DfK zQxX}i>CUZg7(pcd#meMTHsc{ulO*>i%Oht?+R5WdQ3&QLpsA~{??HYes&W4*{8ohd z@R-SP)YS2cjPW(yLId=UGm$k5u&kj0=zXc~F)`Pn$F`0uhLTkE%q*f0nTYK|S><*Xf6H8H zix27j8NXoliyN!jU)9)ce!_gP_OluYTg=HYRe1*h?0b7RxbV9Ugkz>$ejdV%j(z%+ z4t?61w{w>mIS423U_G`yvUgrr8+p=^dKH1feWZz8H`LPVW)=}}8=V3m`}$|E5;0l+ z9F~&l(XV>w4aJZE#up~VlbdQNp(zSabXK63B3{b=p!bbTSNqjlTx=OEhe22@D*gN& z13r$HYYHA9`jYuvieKq0a~53ElOY3xL@WCn9x=Q;tm{6N`*hf4XVI*X?8EhFb0L>5 z4i%%tDZ+)M2zXIpCY{(ZF`4U1autcrDKbkS&kaJ-K?s24&TMIIL!SJgrMjfz!IcXf zz_@FDZN=N`)V?Z^^a2|rrufGj>y_&ZGCH~}lHrg;93{xSWRO7uBZ-peT`kw_+_#lF z>${$;O+7=+2&N8#=>KiLYe>oQlu0`|YD3g~-lc-lPJ zitrrtK%yke*0Pr-duR!(eaA$W)76dVDY&ktpeUgNZ6GyS*g;)ICNY)>)0BWqhBmQi zVeOlyuYh;(AB#A5w0vy~S;m=#Rh`b-3IS#W0L^~<@aU)lH=ty)q1kiZ^tV}EaXYPq zn%m(x&i1wUVp{WiKq9SkUm~zg3gNmlXYcrkMH2g|W6eKDSjmwW5>NiKMx#` z1-+!IVIb_Kl$h({?8_Rlij6GD05SNt0v39E>a)lV9`x$mASA#@F&ApGGVjKgdw8p@ zb6{Ygp>dTTwagy9wLpAFIjb!ERvw5&pRpVH5KB(q_}_HC&9rBkCIBPfFe^7V*Fq}% zCbhOQL9aPlCM!FupOXeXI|+1$)N%B&=>hIfj*zKMiSXa5n0H-gF+4(RdnT!Few~z# z2S798kWOD`_u$lwD4gGw2C#AV`(e=5w|5J*oc(7-VjqVk)D@(SRj=|q7g$M>Gd_z@ zH`^$glKc|Wwv@JXv{$VPx9u<4FBuptAB=AGpURRkjIXI&+Hq^=Z~mLiXR4D$Qnu=E zG8B3wR%(4nH8H(a`ttzYH29^*YjV=_ZhJQjrmm4L%{6%1|IFqXEt^To)8j4~4(j_9 z%{-P<>v>fZL)OX`)?_ESe_%`d?c{VFyu9V1mOH)LpODE;L#t97`E_|or{2syPUD*A zl;=#zeHycf>zZL&OG{U4ZX2jY>3NX4p32`T^TFq-V)2{wPCXxRVLzOb+KmMnt}XlS zbgefq*z*@p-BI9A_wj*3WB`Rg*z-@J#in6QQC`|1NNT*ok||JUcw-YrgeY93$Be{w zi`w7c6Sx-pc)B3w9ccb=X2)j*T;Yncvb3b#I?E+KRuZ^?g)tk~M);d4oiEEga@EG> zY}jYlnqbq6RR@jVj?WiRUoj(_5*^wu8^b8qTSb6GP761$EWA5UzMr0%L)N#@RjqGJ zo2yK9j$=!Im$wL+zb>79;8eVb=Kcf6k1VUQ*L*Zj8V$A`v}h|;`7xfcr9Mo(y{v$S=z3duE#?~{>w~~jWeuw zagWzkVtCCeUBXbm{+#+%q}4lb$LcGeXBY{ZlG6LW%!8D28SM9~yr!Zs3Jws@MwphK zM$Q&4k!xvxj3yZgqA!ywZFF+Z7MNR~p53~8N-(&)Pc|dM4HWk0`PWRvCzgugu0RRM}HwdwPgE%J@^T-9tvaOQDty<5+iKePOMloL7XE zZ>ZqsClJ4Yvm#lF4kq}(aAw-y~%L)7ePtqS(K>7>Xok6hK7dKk$^D~NMx!C zV;UUb_t)Q@b`zVUCaHEijdKlGipkA@5cmxkAsZK+R84`w3yqkMnfh-P)%A4Hfn9}N zMLAH5z23%5#m_BFkfuYA_mtTiv0Uyt{&&-s`3DwcOgtD++ODSB?poqxB;vCb&Orru zjf~IFqfokNFln=C_ljnl+$7PO+ z%1WkM`-I_)r2FIHe-8=^YeO1A1IC6-%Lr-fT@5ih5rqQXg~@cF2Eb(5-m{30UrN7SYw z!?ve4_sOyv1a7)yXP@k1dI%k{?!$q1ZKMb_M; z$kmRuYNGsqvx5vKajE+j}A{O zR+oQIEwp;x_;nlooOFQAlapn8y|vLz)iN+&w8!eY4zi|5iukI7$-#P)d0J!-#% z&TV?7EzrOEeF&V;wZ!*)0XVS_jj!=>LZdk^YB5^h>=(~RBCK5a&YVtMpJ>pRw$u~y zz9m=94SMmLqdgn$S?=AO24bC4rE|VE&GI)MINF_6c@oExo?7m82aTjACM74O;4F8x zgZ4ftKDKGf-qt1A5`os^I*BEfNVRpaYKvr`hgS%r&y$p?KpnXt_b1VW3sBBjxqXARQr~rjdO#oQ%0a-@oX`KE<%H zcdkC+u*|49&hFo;n@q#X*AQeh^grMtaOKmgT2?N(4^=Bg1u&IG4- zQGW~<9B%5LO3S4f za}qO+zUrB{|E#Y5E`@4d)3MNL9|{F`TDAVusgk4zY>N& zPrE<4PTms0dpEwMtE;BFw8&&`WIX)PKkE&3z7X9%$V~h+!4rW&)b#_kfZQKxw`er% zz!>wr3R5jUTCxp}R< zpIo72%U)2?%W#P;$**^SZ>c2U;yFKCnAK^qf6l)Y94whMso%JJmagH{6*Qp5Rjr@r zf4Fz&PpjqVY_pxIJvBk(>>~bw90|l=Mt5+VkL3&2iKD5rL$lW`}cd`ww zljVcd-WhN>F1n1sEZ!I6ZnC>4-3=`*^e3iAPu`dDsQk8$CWeAW)0gzvO$X-tyJ1wV zWx6K5syDX_do9Gbo*roRly{oeHx2by6_>daa2j1@qV>??6kd0|O~QLPY}Bdei8yQe zV*V`N9`7;xZGq1$HK|=F8V-_f%p?c^aVO{Xy6Y4^q6RRLdwshlWkYjI4erl; zr(&E;(P?xLC~&WGk=5w=Zx2Js%;vg%aPW?Ryhh`vz;<;7TW{Zmtca;E%{{Wx$)I@d zC<N*O z&Ds7(A`e?@(IChk7aPgv=$^bsE!D1eyymvTWZEf_*DSTWDP9!xwavG>iY2{A z7a2Rf6@1mMGgq4&x-RcEBiO@M!d^?bjjSZ)g4}&k9CQ!NruhKd=lj9QDVZtk6U^EAoPQ0%7Dp>AF78Fx1Z%q)TcX+I9e+ONx*Aj&y8 zOb@xo;LcOeHwS-rb^*`fT_G7ueFDmP-FDN75;opb_lV=Sm+ScQUan)TWP(_^yt59^ zPQ2PG$LctK8LRQ9{>r62dmm&z=<3xTeQkGVW$b%8yvh3oEeO4U4EfOwjc4K zM0~D(n|%q{lV7D*;LTa-7~hGs@XLH1s_6gdkK}si= z7t9rbRGh3?S>w@r@<9z=x1edO!J?f(3l$|5bi*V@0gI%ND6qf3w4t z^#p2XuTGCcm-{dsyM(*u@qN87`47}R@MR?T3j5WgXWii2#bE_!?K1ycd-sG+F&BAE zo6Ya;fDKvlpv#9m5gve25A6-r_YFpFK1aW|)6ymGXi7Dukv#6B@wHezW8J3am6bKa zUNH4pwts*4yM>MfW4(^zhE4i|iQ95-)dr$wKhG0G#+ct`FB(_=mvpLaEcPY)=i3KD z)+)$QBe%P;bz1WPC+oS}YD1l(>;k|0m>KM=s&Eq!L0HL4en7M1TFVBd)pM)=Rh9o7 zDZHr}#q?&o|KVdoI`@qytj&*-;M;z$K}Kz4Vx`|)MS`e)Q$qteHW7)}D|j5D#DPl| zFg7FSKlqpceshtp3d43*>KHI-E!WTD3ub@IY;HE~Whk+T7r2TE3lk6&_*cH!dD*Sn zt5aW;9V`4$C@=!LA+b4C333|YdrS&D2b@_9BS{Je5!XH~jalZ|i7i`8*oHTjPteL>p} z)ur~(2HILSL*uRM?|*+0x;uVbJ(SPuK+o@Lb#bj4$9B43LL^F^Z-Jps-a01A^Bm&VZZ6&?_%;IX=6!F~S66#%UwiZQjB$Ukf3{F&B6IWIH*8ejj;ppD6VZFv zgj;w()K7OrZx@n(?Q(@|Jhm#jA(9Z!939%O_ns^a3c(xMMzpTWuTAkOD-0Q0#^QH3 z*ab$+CD7zSu4T-d87J+7%uuOqjLmzH%8y z&Rp*8RhPphljHt`oxWE|xm&%~agiboWvRTRQu^LM>3_f2ILV17%wIs8);X3Q-1Yq3 z?rLI3Uqokid5zY3f-LZsCAf!u>d%6M??ZL&gk#V6{C>%azbuYccMG=(Deq%VZ0X@` zkRSNCfa`T!N-cdpQ#v)&6hqRC&N1UCN@a?n~wklf#($gwa&*M<6y;`mD zhc#Iol}@w!+?0=wE7^{fY^9kfoeL@C!dKT^Q{;sbZc^(n(ALGl6$PvHl)bNTF@f&V zt7CW7I`>oft?gROma8`ALOj$w023ngc}Ih{i&AKi?u;sX9FqHF2Qk|`wzM5IudUZ3?>+P&w&k%i# ztE5|rkua5eLulp7^Xe06McC{UYqqUm-EIQg`$&O~uWb(2gxHcD0>N?B{=0nXCyve= z-F_pnQ#D6;VN?^@Zij@Rq!o~f_d_ymZM9)@t#F8C-#}mGPOXsn@-VZr@y2LGE9*3v zzoV<8r??<8LtV+eYRZT{olUDUNWt|J`YuN4jS>wX)bKMMSe5AL6^ zFoTYMdV6@rOCTyEP-4gxdflGyEEy_)Z=XV^1iTgUZwbEqd!=}HcV9TO`+NJx(#MHx ztD23=+qJdPtS|w>W}fn1CV9T&1x7I-M`GV*gQaoT&BDjOioh>IlUS8moyEZ;@nd@3MbZNx4_!F9t zzO2Bv&eMs6qur+2_ci(1K5ZuRYeub?Q0J;IvMy}JzsmnR5S6T^|t%iV24>SyWiL>3#)Y$ zqj|v0%3Y6(quL2qbmG!lxA)*2xfAq8hR^H7J(k7VkiQzhP+W7{F^P-&A4TgvaCIdC z>^|7!TkP5dUg^CmikPZhp4-FJH85MfW>Qq#ClX^CnB>C5DSNg1J7;|A-h#vr%M+dN zw5C7GZejEB_b-~_r|sVQ&UREJu64NQKH13~=#>^P^)#wo9RP`CYvuFdM~7WVyr->@ zqdAh9p2-(`k-)7VS{q^X@GCp}6FmhKQ%1LgJ6EP>$hjhVcW0M@^R;i+aYiFzN<~(# zPxzZ(L{D>JShbSL>jll4r-O&mB@b5$h4Ox@e1B<`OEl86%2%@oeI}8OO{!%jc}O1X zlZ396Ee5fYL)t%cG66r|b6!>utm0}pL0EL*@AUETFI2exXi79>YNhqie}f6n1speA z$NrOTkT)M)&irH>{C+t3d}c!IGvDh>?~5nfiu+mpvrZ0uQk+i9&+0w3`NeC-hT3_$ zH?y^5_7$r}y%3TOTjl{+di2tI7Km^HiN9aWkEp5;)Y<1TXnwhRV%ta7~k=;_N2nQKD$L{ zj#MMh6;b>RC-B8MVZ!>;>NzoM_jQD4FmhdOzR+5H~XW54B#^Y_g?^96Tr`(0=tcUbPLm2$Pv-M)9e z2z5juDO=Ct_Dai~OByf3PQzlVzf-&WY>pXr@Oo4z0!lg?7>A|V*mtf2^$HLIL5vqV zLd)iT;%m(fda5lF|JU-xdvWOOrM)xCQn~KaGp_ht&5d!u^<`d;?4qbJ()|0)jJGWa zbmzoOrq1AIuM?G*Zy^8mWOYpj0erhMr&=iy`PP2WvTLY1 z5qSM(#ME)yFlJ=%7KPmUa=4P<1Qz1<+#N>AjIUDjuJylT&76s>j!k0;yqQa=$@4Yc zR%@pC+W1%4br+buDEfP^MKo~HeC-xZnN+~d>~^cvC#!|^@j3T_n63+!izl!95uK7m z;y+=&tK~{ZU+vBNBTsw_->;BD@W#cNpvt@v7gf3pt;fHjGgN5L1)sBp2Z_$rR(tTP z%hbBQ^}27=Op=pt4dd}3{?r&A)=gX|B7 z@Y5@xdAIT|?|!T=41ZFQZ1-D)oS&awi>T*I)3(qiO-0zuQQ$Ec+|>H{V)l+VFPE`E*trXQvhmz( ze|?A$Mb2|teirXUc-42gCR?TnKXifY`*He%>{9#5UHsmBMp&G;V2MZMKmfOLf19gar3;a`N72=fAr98JsA~xm-B`l$w!c z3~m!dEkx>lRI5wQo$qq;D;7~+v;Y{2-hWR6-k`^ik&_P_vTVxiuyPQ5a{JTrs*_K= zReo1L7CwIpc!jtM+Hd%i2VY;fGxTIc0}xp9>op0l@&l>|gC@1ux;;((yr)XI$v6!^?dgAkTk|^#Ye9 zK;F*C`Igr2_w(O=e#0_owYYec-F$Ue+iS;eI@&GgGvqn!U>d}z6RtIAobC<2i&x`{ zB6~PY32<7xx4mMi74ci6={lXGC4POrwKg_R;uDu;rWX;Ai8wiI1!n1F{C?btKS|Ha z(I!Z@6?xV+=yr0Z5b(RzKd$*qa?hWV*04vs8CYdIentNJdFkZ9sJ*D+bb~ZPwd=0! zwd5|hy)^D+p?GdPEK8Uzs60>Tu_g+fk%ScTPMm*aG8h=nUTxG+^KU)7Ch%yhvkf7C z!}HkwICkd-#g&>lgu}|=J|f{Iei;w{?DvZ57Z0@$Gi6M@RHQKPp|NBB!(?yzE-!0< zUC_M;1Ja3);aeqaN#9_8a;}!Z7rQZ5Ei{zN*`bx zmXqBWRd#+Y_qs<#B^z&~xvtvOSh>EOU95)`Zq&Y7{$%R+d)fAEJdMgT&cPi`3D2JE?Cq1ikbY5zBSsg8RcPb;NgvORILY^$n=HqREuJh) zL6?o`Aes!Va2FB?>h(v5jDKm5!p2=eVEX+i(ZH>yT`H%k$)8O5&vQ`xViD2W@S&zo zj_vY`sn_k7r)_rnH)sK-Wnf5Dc~@Gz-e}2fzRJ1!_2P+Nvt#|BURv3|%=N zHLShPzbf@V6LOacXsz9!>vVcqV(dRX^2L_bGao9u4to#P%Iq1|gRuA+RCRAGxLX+(7p3^~F|l zh%9IgYu^D{@f7fI!e{(kN8tFhU9EKt&VPIOEt;FuM>BuKX<0J)@}g+H{O+{INvvK4 z6UY%WrtJXC4w&Fk-3)9D8k^%HZ*TWK+R!$>U44A-_o8o{`*P4>XwKOf>qtmgoD$q? zx(&5}r4sn;G%8o7vG&|I`F>UcIlh#n4y=6YI%jLN8cN|iMbqT=$PuN{NdCRixnu!Z z&lh#e*!$P~VaSdzsQJ7xqMG`(XTN1etT*Uv0g+g{F>FgIb?eV|I{ry4Ue47C(-L}0 z`{LB=?Lj09xkB1+)RN=Sx-1@h>>)$%6%B8&!}8IHDDCg3okA^5n` zTBO4Yd;ko?a=+bzv{f#3za8Qmp9;Km^G(GjbZdoN&Hh_*-h8qG1Hqd?OA%MU2J15)Sx5>|@hl=R}cSrm#E)>-T zIy<~zuH|06qp{ci>^pu=2U7h_-<{Y89@=2Tw``8&jb784u;#J6R|q{~u&~gL%N%&C zZzsNGRk?P(f#WVh+lf3gZKk)q!eNR!zd1gSp0b^(P`PE|xi>vuaT`%2?N&_&jw;39Q-*?;^ zJB09T(YJ&C1m67HzZwuh&Qm)Helm2AI*UX#kICuANZrB4P36Gd%oUBxn7GZJhR{(e zo7G0kQ|sE!(%$anr`u!26rDK4K@o(+Vz9K%Kx#2{i2B?7is=r~_ zXadc`L*WZEh-d*;(L^Zk!zFWoJQA1Fl=1hO<{CRJf~FSocKKw#<-`yKX(%$?0=_y% zdw3mwV|E(H{zNdTO!E@KD_(8or1D-3MVjb)?raIm4y>y#BkOS8(Yv2GW(1O|+TO;z z%U3e!bB7+O#Z#H=R@AQEt^6o7@M8P6T&l!E=99}PZXWiUSWhzy2_-)a8 zCC+bs*X4gG$=Zypk3m!zCsZ2TK!rV5R$Z&O$oCTT>y?Z@V<51qgax~13c2aIh0|)i z=Aeg$$7bgW!c*wMMAt6x3XNY&(PpG<`=pAdk^*g3SPWhT*m}6uyRNnPtT*a>mL)QL zPSE4HQ(-xl_izFTDJ@dr3H>`jEhB^Foe-tlg=lRkYLxDP^u=#HarNxcjXuGmzI13M zUum0D7JbgP8LfDVP;}eAr?atNo)R&{GF~`v^nQgpg+wlc-?OQOHY+nD9m1~DcR5hL zU;yi;$&=4tR*#bl6?MT*8D7nh+j={lCu{ReBsC6E zLUA&S)6K@HVly;FF~(X-8!1=wgX@v0**{G*++QDq*j$rb z8|iGeCm3;wwAFR^ny>pOzu~!|xpDjU8lRMxqntwhF5`>+Qp6CjTyCg`9{axxUi@$c z<;f6)(F0R)$sE(Ezm1oaH)ueC>eY!I6Xd-e9-yh zb}?Ppbz)KJ;*!HHf$S4UfgFxexLBzPPx;Q3s5@|YfzQAoE9qbwiPOz)h_%}JI61P? zud`e0xb?(1=(y#<&ZH;4r^%f@j|a_!V!Kc#g>}AAuX$^xi{3duFT)m+q+~f@o+AwH z%G8kEqt^>}QM)fJuWgq7{x{8KK)1Eqy!&obQDlw+2Zkztcn&9Nul9!Y1kBCP{=iOY zS`D2;EqXtt(jbEozTBCsam>>dz`#+&JT|?$a!|W|Ju|6wyk99G^QeEM$kllA4Ryh{ zfwj%Aies%{)<*WDy-jXYeMI^v@1-QmOjxE4XHFis!)~hCUk3hp>wK=WMoS!m4^jhp zc^$*cD2O8~hk`#7lQM)}3d@~&q`$wsAd#vO#`V{9pRIG~+PXf9xor-kkc<*1Wf52} zCKk@GN7m1b-a6@OV%InyFID#Xcx*X^cje+9snO1Xl8R~#`J1&EI_^(qe9OJ6EBIMz zZF6+U^zobMySfsS{=?8%jHl4#(d^v+#zl2z(#EPd;9@ zDBA}GPeAm5MVpDN)SUG=wwOb%VH9OB3Cp_l@}CWrUi0%Ojkm8MvKF4HB>yx*6y9Jp znJr+e?i!;@Iw5pbSbjxZ98`<{Jp#1pCKoFZPc8MWa)A*Sk6qeLT`$e`dg02=fj6a| zJJ_?dw5z=m7tX`$PP=-&=Qy@jG{`7XK3LIRd~{-D1%QBw&y^k5ZG4^fQ#AADpL5BY zZ=Ol5&_Px0(R#=0r=`I1LH;9jySeW>kt2@X{$nXxk_xK%Ic0GhtVkiwT~3m2$s<-| zoQxZ016{343&uT;OPgA)r+(V#{L7~*8Q-`&abP=00;$^Qh@_ zTG?98s{ZX^6~Q>bWbs!W2?{rmC{VXSW~sH&+j+3Jf&6j8qcaV{Uu|o$(G|P_dyHS+ z9Nb^b4Cip*4AVcups8rZkVMbB(|nu36-D-+M%={KH}^s!RKn&GpY)8T7J zcmD{L*YCd}7*yddejm-5k;4>0AGXvrU58a>Q48bB#2i)YIIF5U#zDO?_Bs{{$p(l-ZHFpICSawB8<7oQF4CZ z%o>g%wtqiUY%W`3?}+JieSfh&8|wM#Om5O}O`XlF4U`{jBqNc-n06Kx0iRUU68Y6u z&&$uNCk3AD+g2=rBbDvUe*?%)hTqA8_t=7#kTG8FMe2r&nrbc9+R+->tZkp&iQR z{vo}xqFmJLbZQq-hoA}L|8ipSBa~7BQNr}97b&FR0G#v_8Qe~b=es`t=v8tVn6+*? zzf`-HxolczsNKi8ViciS}3BEDJofh5tq>%&P%O3-oSO6HfjI&yhR5v!7*ECM(Y2@EySObhcKMO^s^VH@R6v4A$>?ro}Dz-CG@Sgj>c;qs9l_p4-%)OcLLAM+A_pfjrmqksMnkU~M5@7` zOaN$B8wMkl%a!5qNGLOF;7g|Dys zd|n5eN6(D~{>bZb5t~4h3(*;{BneuL2nOQa_~|cozeZDVBe7#Ikl+{Mye~5Siv4raCKV22R_6q15-+-g763>(V7?s)=f|FU|Hq8? zgN#uThYi1)bmD^99(6!!Bn<%Y@!EFeW3^W0ejyo8srd_K(pCzY%g6vm9Eg5b=h7-c z{vQD#F`P1D&}wB#I%Cq|tNAGkUxZ`Pe$HU&eCr+5|2T9ZuaFCxp>CndK~7S(!(!ap zWoDhieljlb`QIAx263&>QB4B#nCWkEB=@ekasdDL!IDPZ-B+FRLN!vZ3?;e`A!3eR z1U}uyCkg5R3MG8}{|84wxV{&c5NA?D6s#5pHbyiCgNCD6Kvs(tAvsDzq0YXxy`Q{L zWyu|pHdOXBHac4d`8;E)wOA|(W);NF<3nP66_R8%X()}=xE zL-H12>&PjyIYU~buX_GpH@Wjpzjj=5G(=TQUpV2+ndw?VMJR7@sB;}!q4n_IASyBC zw0V~so7=nlHof|nHKgdw+o$EIjvUW73SH9SIUjb6>^B{2|@WeD`Ml;mNC+zCTs2b83Y7?X3jmov7G96ys6k{f)r3;w>< zlRfpSF{yG?#PH=xmSW}EF~Q*}@*2!d?2AcPPJiBj0E zPZ=`o!bzC`2my)9%_y)PezGn?ulVHkB^&a_jvQK45E27&UeTB#S@}s8 z1cY#qS(H;KrWkEpV!glq{U^4$^QK%nHZLP{^xWHm8NtBHMQ?n%A$QEki6aXRMjx^) zOJP0?iDtc8%>lw1y zR;$u6f{3V#PqcrG$x(u_#6g|nNkwsZ1Fmtmt>2@fsJ}2 zZ_x0d1~8i)NaiCl^|rTn?)>bnmW0yr#j0puS-n4u4jn#TV=(L02+7Pme0<@qy^)4h zn{9LCFYDt+7TFUsR7ac%rBIaUK%bam69tNi(P1)~^xy{o8VyR49`tIXQI4g%NHU^2 zj~tc;3TaEW#oLS=Cq>O>E4B&-POVlmRWMdaBuA*Xy`y{A;@4ZPLnr2{M0Z7l$3Ms( zX3P|CGucd9rV1mA#erl@qemVTCI-C`6qYTCNg5)fSh@>Lqa+xOQkzz*HK`cEMAABv zY>`$>BQlbaz=I(<-e%D7NYE0KK92ar5IH_c5<&jGP3W3h}%_t+zOEFfNWG1aZ9Hpy3U&6d1_%@hx!B+1a}L zqn8>i#UnC@gSV>5$->42zo(exQtUTf~^ z^)#(~;fb||qBC!wm}Dn|l7mQpx8EptSs6(ay38KpxK z+G{INNHQlSYt`R1)tVFrNv$#!PQGA97D5;!&YWt_w6kb^NS&aw>8u(AR4pW@S$K_1 zf2L_deh!Z7H;4{RNsM6d^q&mj!Fm;*auT30lU0;OWJ02Xfm7*dq(i3BC=n?DmU%)5 zhcPe-KoXcm3wl8z1vl*6(o5#2AYbr?anL^ofY`iakC1YjUi5HE&>|TGSf6{r#9G$jIyUdcCf} zW=SI|om#E7Clw4k_qq$y2gWWUxw~mk#kamXr_UWZGq<3yta|mopIGvFd-8cH3ARHK z7j*5}yx--tjk@_)GlzusKfS#+eDv{0yhhJ_xUZ|BgC*EO=<9a6n!8an7l2diwSt!h zU0uBh?7)1TEl%PI8{!AMXErDt=yo^metnDizPm1-nopaSF8-{!_9WLm5>uIUCSugI zl+^`Brt0-N004v#(HOM2JLGeFJRqB8-rv^HVV3gsW;1~2d%O-HUZdtf6YlD6Lt+A9 z;O=z?8ha9x9B9yat~icE28|I5DWlJxGoyHzb>OBNqrJyJ`FIoy*q~7nSIFmfyP0em zs6r^)lxYD7eV-~EiKujXPM;8;T5`tCm!=Og4Ij5MPq8{6dD?b2W|-${v{o#t4JKWD&eW?e%CRLH005X60(Ya;vMbQC>Cu+N@YMi1YnMdB9-mcbe6wN)NeI8@X z)Mj09ySpc~s}GrsQlze-DG*@*9LEtIQ9(zqC(!RBOdX1Ny2_fPW!o_xiA0NI#UGC3_Tzq(<=f`2Vr(q@^GpfelQYOB_oHvN)I z3*wWE2mmmRGIBWLB7}gkXxiCDfx1mwm%aDe+VaNKEAr#xW8*m`;0V>J%t0Wb{wS7Z zS?Fr-3Wt3F5S#XZ>v1_levd@70ny#MzcEF1no4W@&bQ$ZLP)PMV-?F7HRgiL&PpC+ z7`ALoD?TkPGrys2<2(QQ>eF`PIJ-X4p)puAmegq%Uoh03t`i_OKa4xcX4~x!cQv<1 zhaB7#qFRpQR5n-04`CS*pU>~^X$2|$xUV~=Q>oSJ1Y1V&>>Dpl7mm-SjkVVJlBpNx zj_%tw|F!u`w|a%BBRePFV8lXV>C9PYPa0!C;zXBLl$qbyzG?oyR(#%O7;8w(JGXes z#W|z;w#|S2-DTUnf|y)VkauuD@ESoYYiYC78I4*Ez_~phPkDEGoQ>#I-#O7EAq4bl zHFSEt-u`|Jx*+m2)pW#>{MZ%ece_H09U~pqIkJb1KL4tDDTB{{L~$S(b$51#*zguP<7Z|m}} zhFQpi)S`2;P=XI!7MN}e^y1Ltt?2vJ!r^_8_ait_DM+ZM- zoSIYX^_(u@wDZp#pHW~MNRvZo*Wla70;e(Ph)y$P+KdZlk54#wu9mCUom>f#tQAZF z-XHLXB><3mdwRk?7k^aQ0HLo$~ zh%RmHx$~yw6q=8l`ifH%bIF{GN_-V7)_k_$gRT8lX*Uju6M5Mm_Iui0K}c6|zSib$ z>>*A5er(P(p!y5S*PE4 zdB(tPI27?x?|zNH+TB^~bQ7~C7-}qQ5q4M>&=I+iWJ|Nio zu^g2-gc#y-ITp-XMCnS@Qk72bW zWSCPbXHKtJUs=0{2;p>#ntE+%*(Pgpc5;7bbM@YhRXHUHcdy$~>4@eOjmZ2iH6|e> zcU4waRwNR2TxVNV)q%)4H)k7@jKpg-BxH8(+*?-zqSv*5e@ja_(M&){#)4MBGVSeZ zYidy2Qf!H7NrCJ6Wkpu*gg5}eTASIdw`-(i z*SaOEFVqcJTe^1dEvv3(`mslh<06E}@flg@)qQ39FH#F}YL938`U9Sxc*aq|s7^>2 zmR8?dQM2EwWGNy)b2Lm8+s z)oKMSfv2ajwTYP0?1O*35JIpuJ1g0{u4VuFLvTfKbyHU$yL8mj>5)NJx(P+@;^EqAp zkaYU#6B;yrW0Yc*Eu$!{Y3Ht;TP-@v5HmuU=xh$H914ZpK1s@%cgeKcReCH3dcA!( zw(gV(t!ke!A|DRPsnKYOH|E4w@7Z3ND%-PBQ}w=vJ#A-Rovk&Qzx{K85aPg~(~154 zEiD~6$thq+NG(opZmF%^yE8!(=MFb+*-|@w`X!DW8##0lfTvz|TA9-eCRw4?u4!$Xji696n;_hjwX(S1p?daYj`h=u-6sNA)y0$87 zC|JUK_LfH){S&Uu$3`;Pr&VLo#oJ1gE4HoOmWBf)Q%?v-bhbqE32MTrS$sxudh@3J zyVu1f#ErB7AfmIy8&9?q8m37}X}Gqfvu1xy4P&HXcSVo8C*`P*Egz9(D)(pOptGSP z(otF2+1!QGW6_$9O0M3{*2WfQy@C3bePkw|8(P!94ggiCV9V zw~b9L+qQLEq9)8`8!;xJPe`*0JkJ3DrIdx-tvx=G&rBIM^K88R)2NG53gGE>g#x=P zYV~^P+)&o;kQ2uY&s7u1$xmN0;yGjn%IH zEG2Qq34PJ7wWA? zwoJenWT1d#Ld3FHHfpDk6$9;xXXFiKEUP{#ZxSBTqzXgXW}w zG5MOmEx&7Y(cBv@kG%8#)3;B50U?C4=KS{lD=$4gn?z22mMl!Q3>T!fEqvxr|7dA& z+R{s=J^tmWWMak0QZRf}&Gtv`pY#>R-00D1vhg%V0Dyxb`Ni_i1+V?(=5>#p`Pk|^ zOXpm7X?XqzPd;|Z)W0GCz@u)y`l{1z&iIy>=0Ji23;yxy;`i580kcp#^^aeqU=rZ!di5ymu0~+*uPeQqIwX`Wa*l9W#YFE9Txm=_`!0W}lf#3MSDY01#Gk z`n6X|3;zAYUDI9z29P!P&U-GuVrIcf_w=>LkG}#hq1@}9cy{V(g_+3N zeS!@!$Vf@FWv8rr_{P&;oc-WqH)Q1<{nwI7^R6JiyMKM=wI~vX#9=coyXLVQC-4Z- zL2gdV$YD*M@!Qv2zx~}SPkr>~hY=7{3OnPGk8l09Io<&PfMS8d=qvBP@!4nIdHt5B z{|3AWIoJH{>B*-Try}=>n#mYs#3#fTrLTS9<{2-{_`~BjW*42{nJQK=`HD+K?%hZJ ze(B7AUUN_eefon-OLL4#7_;$bU-y6gciwU9uiuPDC_-ryGta+wTH55*U&LhWhQ7ix(e);uh)V%W9Q#Zf(nmI22rt6aFjtmeHvKr&3-u;sEclST_ z=u530PGh!@zxLT@#}yls&a+;ceD8zTT=44|X|X?{%0+L!vhdl@%NSOp$mzeG zpFFfMJ3U!@>m%;lZ~yIY{~d`?gp)_5oOj={J4Oy071;9eKi^uvE_LoL%f@cI@7a|b z4zyAfZ*`pY$1l>85)QTtAw;ob(zF?yU;XguS6_WWV}QBSN4lYiA^_lJUPgJgzU3c3 z_0C@^I`n4y^asBzEl6@4G3Z>zc^SDX!-fz4dBduIo%z^1zcL(KrP$LDPhiMJcV88F z>EEwBaM63Qq|(#wx$o+W@0t~x2?uc1;=&2?9C{p3*j646GR$N?^>offNan~Jp z{O<0zgAs~Q(n!ZS_piFMblk6R?S1OCcOJT6Di8pe@!PkqK7ZDYrHXxio1zjN(C_7l{$b@$@8u6%MW z07x+AoVzCedSaFu$KUbf9e;f2tygb<>Inp#+900s*ME<1DciR4UyJr&M51)YZ(dC) zwpQ{eja`nxkF~%{&)8scieEB+ZUy_jL~P@@Z6)5Y(#w$ z-?ogIh`MCbwC2CQbMKp*rrJ@z#Ib`q-b|_~+{nyNOzD7=Gh3|C%r&E&j+6 zfG9I7T@%NB`j6|^KYiw(-?+sx==)VdJb@wS{`%U;>uX*YMPiS2g!Pn5s`W=He1%jyr8?sHfq||2yq7jC0PLmxj{D%6zPXXWw#l zbOEC(xR(^xBuzt=L7L$Gi~Zo8Oh(Py5_=Z zbFmPuz5MbkU&IlLis#&P;jjOA%kZ%`|Mlj-Kl=7_*FE|m(h_yaP0v0#c}!*k*U@;Q zEuqZRG<|~k%g3%<^X!?Ay?k?=@#w#n&N)xTLcjg}lna5QIDXW5S6_Sol_L-u^pH{P zNXnma&&%%HZ-4Uf`8^&4Brcbq`=@1h41RnWQ6W6x+Q)w7dhE>)?s@rnAQ%&N#v@PP zoN|&g&Q+652YKIILL<7Uk&ak9}#M}2Ii#N2e;ev5SD<2SzQvyV=(=_llx z0f4ZQf)cuI!RwFQvi6Cy{<7?jkw5&h?VC|7P#80Mg7eAGA9;PnmLV5k{pD>ZdZr^j zXWD&l+;ztt&;RXRrw0MDX0tOMS$$_|L5c|gz~9AhfBNP>E-!EHV=Oau$k~7SBHl*Y zM3Q3e-`}_KcT@jZNhuw5)nBhXZ)P#(WEgYpL%;I=?d^B}@0HhL11QdT^r`D-TsU#g z+4^wpIal8L67nF(pL*HZcm3(E(cfMd1{uYtpLG@I-~FrWZhB3MGR$X9$-CgU%kLb0 z&26*pePQWeuYcx+BuCM;H>R-78Or2cCn1(A0|wGmFiK^P;}9Bb-!VWVUOD#hR$bLI>yEkKdx=3P;Ke5RFvzr`PD@sshH7KBwm)IdZeN>~!8rK5XqkH6m8 zWlu{=NKHzR%3IwAPAE=}^NR%2w${dwgyK^&O=_QecVk!l&^Ue2;;-A(6u=Z?nIvQ; z#%CsRh;Tp%#h4-qLNW_GTb<5Ur`OkGj?W>b#c+)zEw}oen0Wa+jDc`>_}3pHRjCW=|;+NM2-XkeeDMtdjNo# z^eU#(Gh)onk5fyLzNW6OuFjAeS+ho_Y1I&NI-SjJ-4Tia02z{!9M&Xlq`9nHo1bkn z=?>*{2LL2T`g;5Nx&y}Se3RJG(&6lJ`!FI1S+a_=;`H31-WQZocW0xs+v$lQthMTi zXo^d)SS&i#;S=kTg)~?kY62(%u|k3raydIy5aXGqGk^Zw3`PB|hN(o)T8cT2ewS*(ZFJ+ydaAt|Mjzqhrb)=4pCRByJ& zrQ{?TF^YKFTHCsMJyA*+QKe<)#hLXgLgheTb6K}0FUxAw9HLo}g1-o5hh%=_Anbn6s6tT&#TgsixWRA1P4OB3ER25RQ za_ts_iclJKH67?u=VsbWI?d5zfP?+6{`TqyH{;By>G38N4R*JCZ8

    4dOs_yWEEs zksNmSbT+nh#@<()-foLe&Ng%j?=hB4faaO0TwO4ox*+8gaI_bai$4Bmw}o^paEyF9!R& z+r8H8Y@IIJ-|mbA@W9@X!(E+ShZiHB_O|xU9``^A&8cZgj(8mnx;hRt_E1W7rZ_KalAGuiSPBR<17|OqJfvVaBpoxtFu1}fH<{2Ij1;Y z$2bt(Zg*F!C$_0?STw7_-`m>V)$Ix~thE|A$zrt{EOssR)>pL~)6&fbb=dFjYV}yN zvu!%Uf#~=2wzl}J+1bt|H?Qm)Di6Ev?x`kpusxVk3Sm#vfi6vElG$QL5s$a6s@_G3 zDJ3=0o@CV=QzHZzAxnBedV*PvX+-k(me;ihqm(jARC>XdJ}k``=&tKOuJiLt z^OJFe=LLJ_kOZ^(n73S@uf3?%#bCdywZ|7Lb823y zT_Xkh+K*f}IYp-qhw7`^wMofli&;mau|pP!$N)%XiqFW*Fsp&EXm?k)-y@kbGml?9 zbi8C)_OWhRqi`9{oo2WljDgcB9ZF)|AoSr)-Ep5=%(bL)5?xo0@Rg|cS2E0DE zc<6=?z~gvqvp^ASl^tDgJ#t52Qjf4Qy*MFcGCY$@@{=?Qu! zqkyy8DXKVALb^#s4=q~blMKjTU)8QoNVHfjYL4M(|DcPpH-C3ibyonepwkINtJRnj zGxcg;Z*6aE%jSa};hI*yxOU^REkhPOK1XXe9Cr^V?D6z=l{fbRfYBN+Aj(O^l9d&! zU{_aHYe!FnVun?TX_<+3i-reEUCm|Pf+OB)vmU<~E2Q9vw^%JW>g{T*IV;1$9EOrrsBUsGk12Y@naw8q<#vl9&fVNXkQONT4S7$9Dg zo|A7iYPC2L^0`|pdUORj7K7%PMeujJI~p222rQXJi5e;7^Yn%dS$TGij4@(j$mi~< zZD@_i2xFp;OG!yhF{vn$BWY#(@4PG6N(jsuxM{j?=g!mXE65l z%0jNLuCAso4*()In>G?P8jZ)4iirJvjb*KV4)`N37&LOIr=h#MyECN5w(Jq98a0Hz z^|I}l>xYof-C5D8$;*n&0iRCA0A_g2?6$0pwcPJ^sjLsJd0=@2DJBKm|?ZnXw59jG|^q}|KIx+ z9qRO3&n?Cg05B(HCL|=py8N+_yREgYyU!c@c!DJ>C)s8IuD+IoB3KAsnJ z$;r6etBa32=F;mY5DW$l27@37q0kQ=O7UIj^?E`G0QB{`-g)=^bI(1;Y%!u(28vib z#Q5S0dtxY|FR zpsD&{5!azyY6H(d7;$Nx-Q6oztgfkUIOp8CLrV+wL=;`>phJ+w5Ff^T2!|XRIU40D z;wh4lEP-s&S^(S;7K}t}OqM{BRelkfbP)rAe!oGhmLnl=Si&lU7O*z#>*ftWy$Kr8 zOVu1x5l~AIkx>)@Mu@~xc1S29qlkb60fev=R_is<;E!=XMCxkWv*O9w@29`}+|1K* ziUz;=t5EzhAi3LFzwU|C=O;Y<=&aL+3^9M_VJH8~D5V%Re{%0XyR#-0UU0>1K0dgSiY=S&>&4O#6K|1)9{*Xpl=*)RR|vSfPv5V)VH7@nrJE0%3J z;2w6z5XBMH~*tK*S}9(P(tV z$`y4k+?{^$uAV_6u2V4s@^M*oAQpQaYWiXfC?JLqib^^`F9;DS%yC#im>?k%jba4A zWJ+aVGDD%TOCvBQYGg5l8A1qTqrf4G{ZSdQP&h0gq|+K?qQ*2JX>>*u6_MbPfJq^W z2|>UE5)h(*7-AHFAp{r!CK6+mMwv<#VubuyEzk;uLID5(m`1f}Gm5gZ3gVRR84AUB z7E58;vUhz$ZN;u`70#YHK82~30sRVv;y>mazs(r{z+g%701)~KWYIa zLQ%{ZAS@GxB$>zngfI>PAc8Q9l@CiY0|tlYphCbHk})tq7y;1OqsXvf~qU;OB6!7%;O%gz{Q#mcv;;=c-}T60{2U1u=x%6t14<)}Or zN6d$QqB*usL9W6<7%&RaL(@MaKmZH@!VF`E20}2Ifh05h zBV1m{$evJm#yzV~=LLZf<-?=+Wkbkf&YX6~vWdJP5GCOH?`Jl~Pq}^3IF9EzP6@XZ z004k8CtPyFxQi&qix~gZ^Yh4v$GYq@9{hN=ObN&FyrkR+Q2dvnB!A}JSpbORmHS-3 z1V;>rKK21P7^IwZ8`mkvfHA}XGlnQ;h{&-nhb$zMAX8}&(Ey`J0wx3S0I`{m7z4)8 zp&pM%WqB6k%m`Mo2 zh)FosrUi^4pul47QVakAMt~3l#1K%34R4Fh`Ft?kLMZl=q1cX~h(&>lSQK%XG0KTN zFf0=$W5oUwk*7kTP$(1%g+ihDg<*$&45X_-2%%V4KE{rZx!8%uah>Fxw%@OWu|hIL z8KMlZ%m5H&MAmU(vA?ryev|E-8A&$11|tj{rVL^s6=M`J1PCEO48@wT2DTLIH5iMu zV!y?rucL>g@r)24D(32{ZQHyrm^ghxz90};#*D+1(37q)jRsL~)$08n-arHZc#YAN zGj3G6?)V&%bc%u%kEBHa!P7isztdW{<9*5dpcU1syxl=i;{Dj1W zpUbY3!m_7r^R5naPGMTI!+`vvvu4%4c2S7SPO-(Q#p)_&;>ZcwKKj_>k3as8r=ENM)7=%V?m&bx#>9}XqrSr%h{`er z@OT>6yno~4%l39RMNUZ&%lY>2T>SaxOLkWHe(0t!je2{#dwcqV(O6L2xMjhDPhS4= zYu8aDc!=mD?(HjH`EbR?+WO!x>EadBXn&vca0O5C3-vgAPxTAI!Kp=@%}#$> z);;;wCm(Jp^PZ}YB#L-FZCgKidcperE$z{t^n)MU?QUo1cirs>dBy&(7vA&q=j-a~ z{JkCfR=Tc?Gc|(#UBjgSB@A~lG zXFgw7R~PuXjPJ$K{&3gUCC`1ZW=~^FNR)f)T9!Zk*rSg>_{!3+zW%zpY~4pse6*v{ ze=_?DA+PM;@yUJ9f4QdO8!CvTuIewAeDs%(R=Ze4J|$--N~!EE+wkFMtG?V-=~qsG z3Wee)f(DZI0iYA4%0loHzfkb%{<^apGS^~gC;+cdckxERINEj2Q z!D5O#P`Di~B{HP8`sSnH!UaBRk{Az3qH(v<)3rMWM-ZE`M9F-Gp=}WDgfem3WLPY-vLGC ztDgF#&f^&J`@80*o-kBkDpMrwg8zGK9^trO*6@0Y%GW%zq{3+~{=@IiPL)nwhGB}z z*FE>yflfoo1OGQKMZ`ZwQkD}z&{Vm4+2VgxWxx95*_qg)jCVK=;x%H*ynCLTgD~cQ z*wAE5qrmoj^xF?S!zPZs_R^{GKbNcLp8(UvTZUfo_eB@|^l4NWV+i(sbpHpw)X~Fl zxng?aPu+0A^aUkzbDx5C?OJMk{rRH zL6{IEA{-KZsyJkd&#CZ?_H3u|=@Gv5rI{QHsAIul+AKo5H|6 z-Qh5$r}hs0!58AAIQkQO<%^;i3WdTl5|sq*gNeOkiRMSzIebV8`{jUqs^3LFHwYn) z<2dd=Gvt*q2L5m~8vW+8(6#u)Sbcj!%sPPsxkCNq}04oL&wY*S;*07?Y^bko&C{P z#Ci5@Q9F`Q$*fF6I6t`a?G5cFl^|q{o-|>?&_WIP0yUc!uid_*OSFV_S#h?4+b$U9 zFnVjYZK>TO8qbV#Q^Z!SiCRa@57bS+xEjW$;;c)GrR-mKH&N&x@>d-ra7f9)5YjZs~4 z!uZQC9HuqvRW#^w)$dyP$p$CIj3nfY9zA1DaRTdD``R`S7xp6Tbm79>MlS7^VOfp@ zb12wczx=JQ6D~P_NJgBAxx8IXiw3d(-I6HjQWJ@SG zhG>z{=!=uoD`djrjHsmYGRh=|Jl3m@HmRI0pRbv?#%bc$+m2thzSrv^8TI& zqrKbRo1NXe+qrk<9Rf|;p4!KACZ-jqMSI(iy#MsBc9kcn#AHmIFmKhY6ya3(h;t4w zRQBF0d#k!ST+C>V&Rc%RtP~m*YB_%7z?LmXx)}k0)G5oSPMw+`O$an?e|mo?K`$$E z{lP=sjN~u9wNTUAUw3fhi9P^`nSRZJ;m^K*JyYFesW{6?!|#*M2c znC$xDwqwVS?COfW;*#-JNi7Vt9Xoz_XJ_0M#l3I7xn=*J2A8Jc@9Lw|F1&4iVzShC z;^@K6n-6z0LTTod<+G02sIA>(la6(yb?JU+y}*`EcKm6t`qSfmtBR$YRU|^9s!^yPiAbkJT{F>JA+2 zW+Z;vWpj$N^W(Lrwypf=gN?6m+&9ou|Hv=ur(bmWECB#O_A}?Mx1K&SFfgEs$w{Af z;i?HHL7>8LOU1Fn8#f;8W`vN8$xCO=nx1j$VjxPOr@rjKmiNL3m^^9eq-it52l(zg z+bdcJ1B%VyD7^R^bJ9eO27EpBWe2ye-`ftH^Q7V>(ArreDPo)DLsAiq%?z%Im_3*yQ92iz^{PDV9i^8$J}(u zrgL_dSL|O`Ynx>|bf|t{V89TYl`;LIRTE62I8v)F*YT}Sys)dja?sgdt#X!4UUtWV zIIX*J&+a|D_csgz2Y~E_H`8+WXErTNn_S7qh?cWa}U zX4f4!*wWFXiOVaTbMg40b?@(QZ0hstqBByaufA-8PNk9t$~Pa|zkPE92LPIJ!NO_d z=4Kmx!wp-XDAg=pkeg|S){4@%tD~n!A2?py-`_ua+cQ2iWq;F=t%pi?AMGIkkURgH zspGS=3@&eb`CD&pY4QXDj6@}7)-|-#C>#N(1*~Z)r9lj;* zL(xvGdtrBjuivZK;xqCWT|Ygg{lwb`U4lUEw0hgVUM@sWTsm#igvlv7#u#;$eenLC zBXwPV&`P@Tm)x=-%VN-g&)HUW;N#ayJE&iV`21N@N@h>6wrzc)R9}+m9j>o<<^9rN zcjKA|{e4$0nURzdY~TGxMeLQAM~Y6KJ3dL%y7kFYnyl+{x+`lNMNx_^xn^-uVwwXx10aMx zADqLfeuNx28yWX>?s^egT%S*#^s{#f;iMKE2nPxvQji!IgDz)t^SW2I9rOn|@iR|| z2Ov10$eMtEsJw1NOIgJSyN9DwylYfGX~~HiBdy!_?pxKZvTxc9TV0Fm$o9^v z#=3D6+F4C&OJ7fCQ+c)2E2br9sm;NF&efm{xAim}^YFvlLyITnCojnBZQ8$e)63q( z`O~u;%_r8qTUy>CUpU|2-cI_eO53OtY}siA)=1SQ_K*7%4fhPYi7X8C^b8CS`^;S6L7}I*tXiu$1D%!K-txDbGR7rOpQuxO4TtxC z^wGhp0jeW{tIMy|>I)K9CpPYX<<%yeRY}h=`o$Q&en;;GYP~sL>h7=K^xn%KCS;YE z&E`Vh*i^OcjYHFCO_nQnY^io8Oq?_!-*f1L9fuqH{2*!EvJ@8}LFTMKy8GbPeaCBE zLg4HkeE0({*1dK&N<~lSFg+Mb~}S1p{uWR$ge1hq`3R~TZa!tsoT1oeO0?# zcrS}8%uKXE(~(y{2rShJX$Gl#_wyegmo-sTpkPgRg~U@=9%C#x+|zMr{gyq4Yy0FN zr^b*N=Lg0H8joz*|Iyx^RRM!l0C!irNA2cD$HJsoL(_p*Uu#T?(?*H(3K_e)1J7v7!3M`8!F#^yR@vYI}i{; zUE0pUkLOy|olcL(;|%y|=V0fM-_zZ7?9idj`>VOe3;@w?#XoAoZB9Gtx9vLCVHiJi zVZMpO$;AoNXXRPi4!!-_i%Eu1P3g|Z-|=5MgLzX@a{IcQ zJNq`gcc9X#ND2wGd%0RQX+lbhDm<88@b&h$m%hI7pof~6paMgjH^>+pII(wQ>8_fx zE~hAp(AT$fa;`zmdDX$!ww?%=S(E1W4i9+x54^GIkee8ppyK*iw_hQo>FBx*gT)JY zVQvCxty=fOmYu$Vpid+K3q3%QA&_BPU2wXMr8isHh!_TFP3z2#Y% zWKFW`Rl)w|w!N=?P`7I8B>B`Emh-{-J@4+`T)V$jHrXX_nYYp9O9Wul!#wSk@4dKV zr>n~!Pzegi{`x?U{?ZwfGl%=?4s3ezb>Nq(`r7=Rl|!`+N4x1_OI=k{Z-0Ber@D4$ zSMsEs*;yi20-mA1uJ(4B^TDPnrdFx5(^B=WnmtdwZ;i{drvz#J!EKMe!2|OH{mxKt zjk~I5OJ`bfc1gC#!`)~(=adCIk8j<-d&k}rO~YIV0Ctxg3Ho3RvV3W7mqszWhJJdDgmfbFwroX?x!|PSZ z!0~t2l??_%g@qbHbo1W2(sjEwRqt;JX^dQQw{`mB{9J3DZi*PE;e4>8`p~{j+fTk1 z`dGBdm~EUPR&Iapx!$78P;6FOT0)RfP8322fuY{Upu0CIg!%$z(z;K^CeBy>0YAW;wy}z?^c%b{e zw(L0Te1}!fI%*ET|L)!s{T`x_K$pueOH-%Drl`W1mPo)Ux9)#y%aLBc$VGKPvZV$T zmC|1R-uf~Z6{lor+S&$P9Y?!q0CWk_Idn zo{vA?U)#@29Jmzk8j}6NVD+vS-!mImTQtLigM&Wq8}9EO820)?g99xUTc6mFJ7amg zgZSzW@7uKfaLoYG0(bSvQ3hR3#{6?$fQF#a32ROBi13AcCUHjJW-E?eULr7;PlDng+myXQjKZwalB);uw;LT3Z`Cm7%r|+cTmp3u7&DvMl=tJNvrWkbkJZp|7D^J-2v8 zf~v3L!_7^manp+P5_!Y^=U(j^pRPn31MN*@sOiJ@j3|pf&Ki$dg%CoYmouiR;+#bu z$Q5ZESEO_r{~B`g)d7Hn6AThgfCquQcu3|-ck`~&fBd6y{5?OMcllCl)6SN6|8{w7 zPd)|WJkhu3=+n&xp^RH`wcT6(;maT1ws!kBXQ%u9 z02G)&nE-+d)a^qgCS;kj=BYcy!;gRO;hOq=<&~Ed%owBp2sdaT&T0XW$QgaaIU5-C zStiV#yJDQCf9uOB-}%1_W@qN>x|@$41-WxajriR=zIkchVAIBzSKYbp_}2=O;s$FD zlz#Y1Px{06FL!{Y_5E$lo{hWuS6>B`b$jCH&A;SpHy3ze|IjO&J34YxgQ^~PW38{y za-^*%SjF{fT7NzEg59T<`tHtvR!3$L1W{k#m5P67Z3Re$)_o)ewc>EHg& z!g!!ZpMAco|4{kB-1wL?4oXl1cYnwJ*MIY?x(lDU z^5!{4gxsMHYFPEjwU#7AV-!x5J+3k{<4TIip4sG3cS^QFQY)kL}Roo<3B)*KnfZ z@QBxTC5?!PR63c}t#2%OREy=zv5s|CYi4%8O8W5$!G%$(E+m)QcV+I2+r=VLvL<2E z@$exoZf5EDFn{OMpYxj87 zYw`w^w4GOlr{%If61k)G@WMsLBxJ62ecdZx1n9W$6~1j`Z*Z!W!Cw#@giTMx&1kP@ zrIppn@|c8urW^NNB@p>%?cRk-=WnaGA>_)`xOA-2gOcBG$72N7HQSj$dixuL$H|)-><;W+I0=UvH-|5-U88JD~SrmRr+E&-8Mg}@&#Ob_=w~mh1>A9k7 z#AJ%KmbyF>^KRjkANao~XN&%bp!SUP!EeL3UAO z2+&^3{57C&Q0Y5?{cWA%yv~=;*z5Lv{4VBZhqWW#KkF@qn(VgO?RVeQi3G5oHy{wM=$Ii| z6=v)CJ4;@BEaM$N!2z0Fgev)eDt&d|r*~k?j5C@AW$g4rjo~?Nt@v`AASn0*VYv?D z)3LvL_qi1bgJN`!(EZY-b#_6!_NZSfu&vL_bCvP_PM*DG$gh#py7Hj?A$FZUGKvLu z^WMLa2q1(NPpQl0^~K-&;uzol{B7iFs|mwU$LV_LhuTq;&3f%?-sa2mnHE}=+40)a zZ;qd3b=FhBC3c@R*~*sl{yFT#;t~9X*S#-zvPl!NwHV*ITU?IUD*VhlJvWm`H=c>y z+B%-ReopLa$0>Ne91XCS4$1gjmK|S180-%qufA)}aS&!XjFF<7*1di;JX>ilJMVbL z(mBjSICHyrg}V2AZP7X#`gn2XVX=tptVZ`y{p*fov^-6qh3++BH%a z0rYSUMzA6oepq|Y<=u^se~(j%WY`cMU*XHQEs(I8zrk3mbH7|+^NRMek5kBOyi#BY zjq%093%ZVAK6=skOp}HasF0r4(YI{B^XmJ}LLpi>ZU3<<}#Epkhp_9Bns@GhJZvR>U}ZCXy1G~ypYQPy*Xi{ClIp}O4qpArs3xXyy` z88bO(7IPPVJ6tCtR6({tRAMDpRc$I>KlNL32+GqKhNW;&nW}*SP~tMP;$kzb$$3v$jn z>ULa!yw=WIu+f-IzSj@idy4GTFpsc1;O%tG3IJ%c zajnSgwZ59J>|PdswcKYd;EjIMbA0-h-0Rf>9OSdwiwk5`mkpnWr8|qmWYzm^V|#}L zAH!rqtcfbe@tkk7?zY$q*{+d}mPIH?rnov^5diJ+yi%{_Lg41MKC-z@v0bI*bZg}M zJC>gQ%a2aAr;Syj!kxFLxLG?pa0FM8jEd88&sT^>J{VE}_KngRMR*X;bLo*43%Rbl za5;76!X|aDRNh!RKgE>ABudfD+=AwO`)S59mY_V`egvg#lm>fzb%5<1ws3`dsw%FQ z&zoaJP)Slnn!YNA*pY>WN>pd(-Zr-0qgPXW5ufQwz?>4ZAICOK)hiRl^+Iw!7Wsi_ z?vSnEwY_scAaBg(TSPC}EVeHj{BpWyZv&4++l(pfPGPU-$9nmUZg+_0ABr z^a#lfBn>cjyuXq(X3^}8E~;Y$D=^ArFn72rOA*F`dtTkpB&i1lJ$rmJ@U-5%IzK(_ z_%0H@;oy;Q^;X76kG362M)VZHytcX)%OqG)Y$lE+Ig8V|)zWOKhyTSFs(mff&)Rru z<)rwx=mvRzOv6JEln+lY|JpZ`Ev!8Amx}e~a`HKAwuju>BAsj{`=b876jj+QwDeSt z@N?V)ePQ&#Gk%XX_s#iE>s=tskI?G@MxfhXwS)E4At-Q}Pfb6cixX#9J8g2Q13^G% zR;a%L5K0g#c6r}S)7Bcw4`eMb>Zm-pxbO|WFWF;A&u-9w6VkPpADOFNI6GAj`jMdQ zp&4g>SPF+18DhCqwRLi=LQK*#C;8k8Qm^OXh7P;abf5eLX0gF`*ZDc~02FZt${q3|DxYaCHK|Z} zS+-Ff{;7O)GiPsW5gk244+&(1{;6tc6jTw6xb~O0U4(s;E( zoBQ>=)_%M-0JjPBGX!qtF4la6AqE2|9YVJ9J1p4f&D-U+@1)V}sRRo;^#@2Lk2y(# zhd0|^MsVIg1oQH~iZ09+0)M{`5D8qX6GK7@-_WJHeFk&kEPLW}sM12UQAK@VTmAab z)itSTco-U4rPuhTkib$HbAn*1hrxJ%>y)osTh8SnQj_bS(mR*T=;;`llv!=cF)2vA zGaagwjD=ns7CK|9z_&EBerg<1op~p4?`qZEoT($!wLvMe$u!H(X+{IkjTeVj1IU!m!)fOyhpygzfm|0+lN0 zI$pZ+V;N!qUt4g|EmfJ2Byfb(4)@5MeT9NQ0tKnq^BBAKZ*+q?5$< z<_2Zarw_JH3D{74W0K(DH;IR58No0??@4?$^H9XbXeh!&z)AZ0v>LtN7Ya(^JKl?` zXyAVNac2H5i6hP?Nl+T5`G&zokr1F7rj88`5JsUc=pycg0&w@_e4XBkzb_CwrQvto z58%@vQwC&re=9h*)u`vUC>*zdG86D1lZqvmf3o_2$>nGQPjgJw}v5 ziPv#BMBrxg@J(hZOOw;fqzDMRD;+Kn5&lHtDH=}|SZ(w!D}5K`7K;4p>V<~$jT~oS z4(q4x(=S2!qe=$;hc|xC4x^N(+fHqZZ(wPHyZ(pqHm$^*FUL(ZBn%8^o)aHQK+uD# zpF}Xk)e@9ZcUZ+CEoR~h*B&M<5rA{c9Q;>TyhtR57G|1~PKc{ab2y zJ{(0L!K?0i5pK~qx4NYB)Jy10M>AV6i-<4I_I4f(mq!nb_k6kIEKtw$aJ7@Z{A20U zF_F*jZ&}{2TZ=2^wS8LI)viF9oYhF4#Q{&s^6x)xg)9nm? zs(pJ{n_M_5#!1^yY7xnp?r&_7dTytd`01LPr@HC2&3R^SK=C{QT&+D|IA3ouylAB6 z1|;l3h~~y-%Pw$)IEYbS#8)Y?I2H`l#)WW+YUzb(Ea-XtaF3<3bP3ZHbn-KjXWiTH zwV*bSg%v(|+@`K8s_`}5T;PK?4C_Solo}{Gn?~_u@8z4w-3cj@t`o z?Oeeu(xKVWHDbqrsGbr=e+AK!?06995vGa~RtK5@w-(($5S)SQ;6UV?97HJ}%)eoIb z)LB!uI*Ygd8|U!m0kP-o*}2p~$VcT?a3m3>6p@G#_QDl=7D`A#Wwef0{)h|BAR+UB z0Rkm0q~I6S9uP=9-J;(Rl~$bU>pilbYF!W8eFj62ZqE6>uA=cZzQD(_#bI;|{(83` z|4an~MI10$kM8&N3>t9X!&q`PXG32o9&1Wv__sW(Vtd7je8z+QRO-|qL_}1rH|*SWCCA?%+dP`Qp7vNnsCySGC4@Ldw)f@Yh2YrQCNgi zx2$AHIKMm=>;?2~Z^ds@*k_`*qvXw(n`myG$M-AHv2jI^0(?(Q6}?)nAlau1u#KM@ z=FX}N(LY|!uztt2pSQeSU1ewcmCVg8F)%wkq!*Qngm|=)`x_Lgb#L{!XFn;y)z&p= zkOC9_X?xwv-M5eb@`xcCIUmb07t8UnFW4hZ=2gO`!O6qhDWpK~#HfTCST4fLk* zBY}f`8wzLo*bx}Ztm*REstTvl$nL=3d?^wRI8!xIIlZrr2q+{zk2 zhacnC^B(N}-D}INLJ*e$_s%yijfv<dj9$S`vy5lODOScG zIdIQb@8pC;iPd|cAYj9+xjI{Ng9wi@5ip+OP9LL{hWt#ccP+_I>%oC(ultO>h?ag#xNI5Y?K;Ruw z&9lXKCuC~4o0C%+ru#J^p3mIz^xqPD2DwK?5n0J^01#4K?v*>EVDpngfn1@tz`ocN7%#uRh% zD6*im;Y^{0JsCsFiUoUg!qY|KG3Q4G9Ng0^cL@(B|1E;hgHwgqb89+*+G(E(f$)7b z|3HQpkcHG-EWBG(!O;;J3Gt`n>(6N?gX2rPJDPc%i1Y#v4}W&{?Zc z=-!oiAVgrlRw#*BP6$a@mT@uYVg*GLlyZ8+$>B=b_dZ+n8BHI5)+D{h9nj-k!^v#R zycSlU=v4Nd5K%l9%a{lM@xwsZL|3zctj9x`i3&qjO0v2P!*tnJ&D8w$LJargpuUZb zjp06VG%M^c<9fL$MG;ktTupe~JgF>+u!chH2`TPJ4!aLxeT0*2YTwuQ)4rN1S_+D- zC)w)YhMFp>u$4^e&xQerN4)II1PZ-mysjV0Pw3ir@K!qa6(@PmMtR{4X3brx%q`cn zTsFgu^lt}_mX0h$Js3!O4QegYHK7SADz6}!lR;HrikxwktkHc0@iP@wMu z?jyu5!i1XSh9kbM5xmJbw=ppb^Pp&WQURTUV$}Dq@7`9{39}m(3Ayahgnb^NTJhb= zR5Vm?FIT*FqenOg)70v*%Tl5cvW?HsTb)p!KesgoHXPTlA@wbYL7tdA0rNX&s>=IRZaeIaJ8K{Os2h($Vi{BLwlLa`)^!ElJ>+w&^ zY^j)Hf9*<9Gvd0iQz6PXVi@G`B?i98#Rhxkml>#Nw9cU0y3scr1o+CKR!DKj%SJAz zH@3fpAui5wOYzFdci`W?-|3q9Uks>bo)IO zS{aW4m}F0;qRb3%Z_Ag;6^7al;9r+PCw$Id8hi0)-DRd9xKr;EP7Dm!-=f-WDllh6 zzhystwMk$w+~MNqt#XopW-ubDFfAT^YyXQtPEJnZ zxCJ1jN+q@|>)xtsGYIUA@M*HS7I)E6kIR(g3876(G-Tu1QIr|;i^LD~hr2d_PFre8 zYYFlvtY1yqj6`!PRpMOfP0RdNc4os<_ZHb$>gQe><;?r}DHdPbFSzY=ceiz+Qw=}+ zwP4KgDqwU}`}vU9bQlD}xn^cgyMEVF=`$SB#+?2V$G~02R9ab9;&?hDrE=mg)SZ@@ zmZk|b;db&R7`uJ8^Z@gfqG5KfU96l=XT@e9CnES=Gqt>u@g1N<+mD&F16uT?5ABl) zzFr?Kt5ksQ579trm`gz$YF~aF<4tVkZ06;O_zZDc0TCevt7uj+L^Gr^aQ|>{%!1e`f4olWOnc)QxFs*`R<3(U74 z1EW{5qSI1OZlZ)GJ>OeFrLVB&?xG=zn&4}q%BFPbbjg+q7JY7Tl=bR~g&7B8tB2;Z zT$xEed2jm4es9r4A&OMO_Gxu@|Jx5oFTt}A`_mRj7 z-ubl_;^SiHuo2rQ`}0c(o7gZ#1-YV;n5PmODVl;XdXMS0hp272XI(e3G&2a_-)*?5 za2yhvS2u_0!yIk*-Wl^q{5ln%&zcgqXDH%nuFhduLgG$-_CX#&BcHFPGVGX)GH`j> zj1^1Innq=rtgI=uURNyeT?##y(Z0IjUiNK&gd}CpCAU(Rmv>Z~tM+2-y!w)%Q&s5C z%`C8(WcXAkfs3nD=Z}J!%r>jo>hx^ww=2GzHtY;eev8UfFgLNqQcmoA%UMz7eUR^N0XsVQwwno+us^GYAu^%;-3&tsuE`6RH#5_ zPZSDwH;+ehn5~?{KYrngOGAP5Kgnv0Ue^53e6hj#^r?iSUfft=Pj=*VOu8 z49bbRKM{AkwoSFfFT6(_py(y86x*k^+_XQ&o@>IV}LM#O&*|s(Dq3KgF>pT zdNCcz#-~&LxU%Am@ap*O(FAmr(bprpz~DLW+(=dn4d3{2A?*n^=UpIcuPmzTpe}%q z?-diKXW+;e#~ga+qADmWS|zgc0(>75N3oxR5;|4?=l*!>TV>k9`_*vJSj8o}36(4` zkpO>Ky$jl0i9#Lnp(Ri7d7Ib1P9k(jlil?4KAAx#TV7q#n3H@lPFAyB8tnrLIyUyGarPV5X+s@Q3AOAQTq0&qK&T879a%(}52TDp)pUP?|%abS>S5wHS zQqpF8&-Z9VgUlqNVuH!gY5yf?4T$nfqTSkYyv|jNSQ5Q3k`)zvihHIGAL3G!lYbo% zAY972n49Majefk(elGZWKc;5&xh4e|>#)gx&zsvF+w^1~*nV|CKas) zQPgA$lO z4xAnBDZWY@v&?*6-h*-xL}xA8*^-mkO5c zOWE{=M%wWGG!X>Y=In&EDi`h+;e3w5_i^yJj@Daw>)}1O7mv97xp8KiOSQYxubOD% zaoOByrEBZbpI;i8-q7BX2MtNTe|_H0&CM$2Q#yi6GGCs%I5)OB(Rq`e2XI^~56v|! z{AH406grqdaqyX+K3Mnh;wuDz?qO|#5*xEOYPhB^Fy$a%$Df8Dx#MBrb*8hdosxb) zznZ*XbCz#qLe9aR*?1|i49BPJg;7DEDb!(u?fnWtUB|h!PweT_2xsSA7XnNVjO*h4 zOc8cI-cHJ~&*f^;bJpV3*7GqJ`i;_X50T(0HG{7GCLb=|xyMNkeSjUuw>e~nb{0!F z0Erjz!); zQmjAghN7_keD>SF3mj>C;w_;lS?gZ45xBWKjoV@iyEC?_xg~tTp!g+ zITnjnZzeP1S;w4nj1_GfCec?HS-45U$;fXNx`TS4tv5)gvSC_LTAQ|kDc4zUnbxB)>Bd{ zIeWz)3B>crgDnj=$EJ>cri9bW| zg+5l&z8ebLZX*#{;4b+Td^^HOkL$dr0GW1wdfSQvxlQ2QybS+D2WB6Tz6f;G$_^5sl`Qup6jMfQcAg$oqHL^n|^Z0 zP#T6Qi-p)wYy$uO6Or4|x!YUht9&OoInR2_!!o)GWq&Ccpty+FcI&kB&CcUIJ3J-= zm|Et|#yd>R#)@Wm>w=Wne!cv84#2dXBq*E4PNRf@@oR_nthwSi2b;6)=~7%gBwq#V z?SXMYE`!r@QAEo8<&4Z{6$(t;p7CKxY+>Ej95|Hpv5M7#Jv+9p{~*CEUcP`7{#(mM zt`e;jxqDAf0h&^j;6<;V3w#7CiNj?bf=!zD?L(Q3menw5RcyLK-C*$O!LWB@9&;wyhsg21d+X!<4XJXmnVmbS8H?>kr~FP z?r0Nw+AuN!jaf}J!w-}hnj7%3LjQcf&BLmYvg3)D$Bf_3UIj(BD%}jCN0=%2rFq>% z>g2_s3ORel#LDC}Lj%<3aq9CL=Wy!9NlP3lEv4J!B-r1RQdv<&^n`a#C~=5hXAc=e zmAoGNGqDo^G~O@e(fFB@Z)>tTY7!F9jh(L`c$LAz1le(-WQd|d&)dge z8TbnI3*wsA0Zd{_7-B^;&Mq!K50`tTM^AIujI?-J19C|9RnM-^w*FFAD2e#9VxLsR zvZpF%;BvB!_D)yB{Juu&Utj7bf>IxZ5jwgDYvFy6O8O>~YpySeU1fjQnvuq+?+Y~%#gBFUW+Z{=yXGgtbepygm#$y1u?Rzeazvd_UW*EK@Ecf0}%{GiUJOt-}2HZRXBm%59U_^ zsgRh`tQk9?iyI+Oq+5vT<&!_LGm+=>!MtgM{F3d&cam9m| zKq+3|S1)5%&CXM3&!ygcf+PCgGztJR@7+IRih%({%v>kJNVD8YA_qU`#L$fZ0?`QY??}Z&;F_y6rMw&x%tW^T&6kt z)ShjdmM61Y&DftG;tvd>^+5q$MRVMKyiR2+ARTQpJ%5oRX{IsJHo;RURi~<`d0{q-G z3ar&3gwh*NgtV!wB+a#-hYhxIVVHb|I65`< zbXE~hYCNiv@K4P^K!|jKK^SS+bTf?WQQY$m#K(3V@1g*Il0ar@8Vb<_P%MGl6wF6R zxdc*JUltD9zo}g?lqZ%OHwT)mWa-iWMP^Ow^xxI2P@{qB0|IEF=iR_%HiT3C>VB^+7RjS{^ zX_JXhpH=!>MGyBMC5=T8>aqDMJ#^p#BrnO2&)V6He}S@K( zaf+x`q{aZb=|UJ3;E=w-$4BLy<0UqJw!0x@+f4%IvCM%`ZQfASnAAB5Xi^2a2?3o0 z6p4@*Qp@6P1|ai7TD4%whNt!^al)k|BR~)v`iC$IB;eo}-}SN}S-nEjygCi;B3>{m zn!E{x8WZx{Ah%JyCWN056N;@UFCQVYA&_+s8B*ZoBCix_!M3}iAj4EaP9)_cvqS$r zKM}Sq5}&p{l28-r1@Ufxzqs>ltDmX3mKY@-tSAJcpP+7rB%C6FEs@MD4Lo%OvY9A* z!PBOqPyca3ey zks?ydlXRyYDHs3H2!g@*L2aorDlCjqaML7ikrLP(i+arpf##?c_SxeqULLFd zMs{&}6#M>Wfik|$W5#KONQV4uWijBjiBXwDG_^>HIJf0)NVq6Bt`G{lMf;)=&o%-p z5TDqfWW2-{ts2Mu2jMs>VOPZza1JaG6kA!yY8NOlZJTU1eat#brS^-pZt~ZhPLnNU zUQhHVhHaU;MuN-JJ&UkBK`$i$P#54uQf`4A-JrG{i&h#blXoW*0t(yVH^S-!^lz){?Cw!~180(mO7}5~;jTgJo88_46LwSkn-Ai5e0TlfrGCmSj0W3+BX_e$Qpbk-#*)$&^Tj?=O#xWuIt4 z!o^QL4n(k!vgB)|EhL6T?QA2}o!EB}87M8QmVYwaq!U0Dbm({A2C8vq{gf<$H3*>@4P47SuZ^{xT01P1$E@C*xF|V2%ncr3Hgsm7;`1Zs6dy8XYrx=g4$pYReMBxzG zl8IIxp4NDZXfOTUn$cMtZ&V7d#bHSTCb0vepYC@ObjX2W1hAU{;+fI3(_EE|J6JD{ zS{JHC;jyTO7_bxpia7kun5MGd;PVn^D5aSTBW{m2F6L?{+ghtZ8_V+iMCU<_mS z`_U$-K#M{va@k6QCf_*sb_A2WFDkeY7%W6(Kr)>A!6W76(=b_YTAZca5R|WiyzvWB zq*9`h9HGnNXaHnJ#ctauWU3a@hBB4KdoLmKi{?TufAHHH8qQ&Be0;) z^%RZEguaENicr@Z%VijF7KtBUEP+5!81+CUU}LIz;Kjr2E+<&kH&Yp*0bLRWjO4(8 zYd5<}-yXkt#W$aXk&@VSZSJw{xaX4FINMb&A3KCHi@jV=b#sXi!CNVsz z?RW~yv^7NG&kF}OzS0nfapOP~a1pKsEO||zwd+07fPe670^YDQW^&|h!awwSjT?TqyLxcq}z7hJNCF-H#bq)^2dGDemk!-=E~T;=|wAi?=x_}SRpKK zjg2WeQl8QQGC|W?)_W;=`3_leenP@Ead~XG9yy)}8&Fche>fCaOs#+h?~*rugTTu4 z-_{NQrt@vCFTR9aXp#wYg9{BxKG42A3?W94#U}vQQli<$dfxFdxA6#+5d^*MsqzR1 z_OSk;gCcS;1KTJlFW&6hRDsHk?3$0W&?%V&0?Z5#)Ju1ehed^A#zC|nSNnuX62Odg z*2*=F#gljHQiI86A#dt!@_aHXv{L*9iv*RBzxD^oza(KZL;zfWt#4v-fd0#<;P^n8@wYw1f2E4@R8AUPF%EQjh@ThzPeZUI7^pDWv7gmZ z4fH^mKPh|=e;Gx_rB(m7W2X)H7;OJvM)ApdF`0S!I2!-**@k*W({BfM_vsJ0oa=$d zBAfxJF7E&LmsrR@g}y}~{H2Y*&u4%TCYo7<0HOVd4aYTD5>$L8&vH9$JzKZGEK5%VPBZTUj8n8c!*<=9dJb=U>T$1wc%OsMw38MTY}S--B5Gvg-o_j?#=OM!Ns0 z7YF-~M7-e14F-B7nHdD;9f$t39YBg(`vEgYog{kp9pz7DMbWIups)n)zw(%L!?zS* z2mulh+Dd~mu>OY{kDliVG4}rkWP+Tp#4bP_J2WOK#x}zCFB@(M69bqu_I-9A|H}j= zq_5a_NiiT8t_S9yIXU^bZCKP3g0sE#d*|;6Ut?sxaT%o3ZgDY$Z8!ZD3g2aXWMysa zU^Dz;XO8TjKHRK-J9%s(-T4&3)$~`+iblZe!B$`204UXcf&XLf zC6fKsZb$TjE9$?ch(HUx5Casvg7aTpzwRZCS^&X>*nRW;e{^?V47IajqzV7q4cGijO+c)n_V1OyB2@50(>ENg z!KC@$+-hS+BA=$yg6t3R`UdKm58n_sjpf(m@?NVE3); ze|2C)$T)KQQ;HCH|2K@JkQjs|1eoR^ZNYf>!v+Zk?!GqHISw{h2%iqiU)~&0H>7(r z{bTJh#YZhd{)~?qVu1JwwIo+K&UTO8-`R0PBYHxOV<*56_5UPoCm=2%JgWA$Viqce zXSsNS>o^&tFW?b8*dA3REvJ@S^^9mC1 z5Q7$LO^+R0^qC$4JN}wYK_Zd>ae2PWIbq42fOB&Dh+_oMt~r@euTr^W5F1zg^S^rG z6{rZxd^(w|6Xrv(&u1SW3$j?Ry!wuRWWyh?KK{baX%rPEn-iTe0nZr!BJ3cxsOkfD)ECSZJqIQJ?%4${F>Kd3il26%GBp zMhbf14TR{%0zLfu52XyM@yD<9#jwl_;Cino5q~uH<{Zrq61xkBmDmCCzmu_u`3u=6 z`#r?(e~sFk3kpM-DjswKK#-tn3jhFZTNCV&{D~pKg~2z;v4NnATgl|1%vf=|gUk#f z9b4#;f3+>yCL+oob^nm`q4pmJhFd916oW`Yr7zX@*kVTm2Es@cZL70kn>I$ z00@5(&Bu+YuKug1S<*W=>iNI12ap2)_PrzmvndQ^`^f;o|Bqt5ll6n_4Xf!NO#m4* zvVKf+Xrq7ILlN1JcE~n_toYgYU#f5VSOQ&3;T z*ygzyMmJZ`? zOgMIu+B6GUuUxN8-i}&k_e4 zh`+t1*X?1-EI^TAYD(l`W$0laDr~6ivk3JhjpD9}$3+w+H7Fx3LkVc02+9sB8NYu~ z!BPcg`bB|x#9UTwsr~rRI8W{eTr<~nUBl8dT-hjm8SGY5Yq=c^ZK?bQ5D6T8T#z3Q z3F8C|67H41*skX62_wr%{v06J99|m5W|UI+`Fr9dp*VV|dQWybnZNPcHBLM})ysra zM17?C=<~7*TM)pvSK$+(ptW;lhS1CzJ0_dPKJtUsuq8B@{hm%DMZ+CC;kp*5D6A8P z9v`hB3A^;zX8~Ka%I6Istt{TblfnRCpSoTL1&f#ft+&~PR`*7 zY|IS-<+v0X6K6}9rcAit09fcRIm1U5d%Sr*=uVXZrDbmsX<%<}^|$H9uqy zL+FfGdO_U96@xWjKU7{h3#@>0%wf&a8k|tt{j9eiX|W>u!s!7{Y$?ag-*e+1uG!FW z{f#Mst+kk1?RrkOL?Ql~YX9TSN!9vgw?xu-aZ~vg7tEz|!orE`abCA^>c|K8`cJ<> zsDHbDDbaD!g>B^ugp*ZQA) zMZ0XQ2;%zMdczIyrL$Zc*y)ubSf8Q^&IrvIP8%m|5ic{Ztf*S@b6TQ!SYwkYe&424 z|GS6sauTx^6$`WL?sSr7I8z3HUJ$tGpWO1WZrKk@l;Y1xauRI1T;%6Sq!HjOvD-HU zfyCTQ1~)Q{j}dzMEYn7>BE@j_XWmpx^)^W2>{e@xo$(!*MN?iz{j@EVEi^w=H{`29ZErEF;AXA>2>nb zJkBk=+n+DIZ)M&7P`B1(c5+^7qEXTEX{&bBzZ)el`@OyjN(&<6)a=VzlIDAm)hf0Q z6ucF$tDrC{35IeiGJO<|#qT3}{?W{Zmrq3IjkA-zFLMvjPETd} zHoY6|t^d(M4_Y|Id0WTB$LYKNzF)&^%8bI~Sxs0ZqxN$!eMEIvjP*)bIVnISM5G40 z@++5>UG?e-m5S;3{6gGH?~P-6K0#8^I55vm?Uc~IF-=lWg`IKvq4qcv8)`f?I~p%V zkg;j&ib!F>PRZ)kg6gm~f4pOlx0zz0-uuF*^Knt@ZTScG*s#o)=41DGlnq87)rWf5 z54V|f3-VA7dJ(S~$qFC2E){RQI<-*=HnW3+JiR^);0t=6Fa1ym1=J{nW+m0}B|FFy zd%e{>vL-3mnPD0qt#AhwD!RMN2jQ~efqrSUaEk6vZV zRV^J1!wKTyRjze{T#&IOOYch|9^BGr{USkka)K-o^7^&!(^3i0&B7HFn$k{qu`p^F z#nSY)c=_JAvSD8~Y8fBzu1?5<69H<6fxm(IT&+^~iCO#MD7n+A0lna5bMA{PH48fY z!CIcI{ks*Kw|gC>&egRmbH_(x>8X_zcmu#Wz3`E$lEV_$hr)%{B5jBFtz1@3oe1Vs z-UvGx>t-8c=mHDBQ0QO^=A;<$Tr<$lP>M=v_}6W@GJ+-?EXhjt7o|emah&IThwy)w z5+5cO&}Ip=L4RK(k;;X|s#Pm?xkI|U{T#LU3uYu*jUv|7QngL|#zAW!sLhYfQMJ3=pTClA$*+n>=MAx}>75!=pEqnxNF)m4pO5HVrDUsGF!iU`a$n>6qjlCtA^e>=45|*NS8JtAVTnT4J16Egzn6+13Pdr5)y`FMs~YM;i_1BRu${ld8Vg7IiX zRCRI4yh#+Zg6yls7o>l;&{^Q7s5TyCk=uB+2wSF8(oE2A6+2;fR8GS%^N|j zKDD0HiGrQY`|1K1ULSww#VC@=>inoaDX@&>(|9Ar~CJ}9Bg3JP#-RL-}Sew z(1^_OR6xk5cKI?h`7yFSdh~G9yOl|`MjLv`IP!wXtXcQ+vvw+P$7Q@hO@T2zPN$V;8dBtM_J9WzzKSn$1X%!Z-)+z($}o7b@Kc5AYF`MmSpilQqd zg~N1ZxT^D!Ke0boi49MhhD4MS70b9jP5DImUq7s)hqTCLLnw?$uq?1o#e-v%c}`vJ z%gY9gprouUVxR~pg0~N39*2~M@^fDqhB@ZMmc!$$rWR~VT|WJSv5P)}a?`r<3xZ*N z$XM8F5|^H%9T2w6y8(Y%Pe; z*i_eG7B8KLn=0_sMYLzFqC>=byoVnK35a<;+uZz?%qZ$>FKiWE18Nh^)*~1O+6!oA z^(F615vg?7%<4YkIf`h7Zj}ot#{^iiW<{){czqW&LR9?&<|#1rKl8C87x5o-f57BA z=S7bUW0hw8v;jN%Mv;W39RT!}3Q{^4C|@>*1`GMa&zEdz^U{@TKcZTQ_+m#Qs9(@n1fAB)40r&^Z@;nNU-41#EctUB0FI;z04a(**Xf*p0(f>|>M zpohrUNttIEPA7#%g^7#=W;Ay+cIfne+xeES@E4$khnPqWt`fWvs)>xkbmvc?QNy9t8eq z$>(iwUiezy?iCfN!U96z1&?6%;`n#!Qhy)S4vf{*e&^=j*~upT4G+vWHejDkGK$EG(29+$%k z8di0FHix-nov3#LQXCM<-_z5Ln%;Yj%)h?mr263hG4+)}ZA6XQ!3xETyR=Z;T>}&= z?i8m`io1I$?(SCH-MzRwfubqy1oyy~zVE$rzYN2VFzl?H-LvP>G-}qL&Qt#jU73ra z5Pwjo2E_i^+Ij|-nEx+M3f(8QPN{O%(?>*km_F3`U!>wS9fdfZIqiz0K!3lv_5Mqu z`+rUe?3dv9C`bg%R|DCF-ufe+wSmmh7Kgleo-DbqPkSVcXw4k^*a{%3T-K;goXuD8lS43nME z9x4Sb3Go&nA^`A@W^PJ2m+B&Vq~qU*QLUiWE zU^D(BkI{aLp*T#5-*!MbO>K5`nhcrV$$f5}5Uo+hmP(eRjVOtwB|>q+OpwDt%sP3B z#257ytzp|*e&tI=1U!oZi+&a+bPpu>NW)gIKdAxvi>3WQ7%=v;7e*o@0zRw3{8h7r zyrv2%yHvQ>R@6l3K@!wMMARBZB%bz+5wKeZPm0*uSxWVpbGD4$RF0iU*n0Aul%*3{ zE?B)oq{)^YTdhnJ<~jn`npO!v0s?!D>G9yHU_4^N6u(Z^6^y7w4Z$l0{Lrl;?viMA z;zy3waz0}V3iv&;nY(fY6!C!#>$UwGjv;;rfW%uEq4$#t;GmNd7(j&|)X*&GiWf1_ z$Fx12j6!`48VrYJq%japd${amDt%RW>z`Swp+@x=86Y8hZ%s>tjw2x{P6iV**A3nT zABsAe%&%m=Hj)DXAE&z>=W3u1pErA&5D&Pe$M{|!X8EuJ>kn@C?U>NP^eCMz6?=bS z1#2149Y&Ms?>j{O%qMG>Yy>>9;&q)y`|wlo$ziRQEGDaQ!d~{HXg!_}M>=R#im~8( ztCc`tra@NncY*D4T(20Aoq_jce`Y`5!0k`8@A|NMk#X`8I~5CuwCm2-zg^aM8g7{I zgf6Oim837v4TH30byfikIews7x}KX*mfcAxz&K1!uHzPR#}+H+Y{5@?QU-p!j>fXd ze&`pf&hkH8XpJXl1ZBQH`}y_=96y1-;MDxho*|65>V0WOP&Rt{e(mc%m79@j2c469 ze~ukcP_qtAVXOJ}tjT1~-`xls2qwGM{syZq5~FR~z48(KFurH}cKsN9Kig0Qh;to< z@>ORwRQ~p{^35}Qy6unlKce?Iw3f=Ye>rcvyYtm&I##%yu!b$EBCfMMiuPw@ATOsa zY#^r|^lj}mzgbX=L4y0E;utc?V{B!|ne0W4ma>A4r&+)Cw6LQJ+>Z%RPpc(p%?#-~ z!F73z@CCHTc0~_lHkKy(aFqLMqN8y?Od>in(*psKQeYZf{EjA6l8?m~K=T60v5&aH~emk+;d-AB}{9-8$9iIXcrRF94MuRVrkX*Ush=^ zRafA`8QTka5kI`-$O*( zPrG`aFN;Xd5JgD(* zec$i$=vDyebv{(q;AB(4ca>7}Y60!=U$*Kz%rmMUX&xeRz~h!cfyQo`Mo&fHZ9n#P zvxF#<{c*Z3U>VW`KIwe?@x4{(8~*BX9{YBrm-zK4J(`zy8myZNxEIbd{L(IrW+T`q zfc*Nap?dZ3?Fi?cS7)zrUzEMCZF}~i#sFS+LL82D?89KoN2lDHhWzW9UaVEzZr4>8 zp-9EaN!i&k13PmA_nuHs22x*8eDjL=pHJ|fC%sp$A_@pOSwF(YBO!t*qKD#@~9xaOOay50@iv>n6!R2EHJ&vn;&hdbo5 zG^z>p;=T(Wd6^B10;c$tx%MQ~@Ay)5cvR`Nxy%v_&QAPRYvFNEBxTrf5&a1oa1z;5 z$8Rv->V7&Ns$RoOLRXlUecMZ`DX@7LKK@GiKk-*wqlr zQ%3<^b1Y8Or0jALDOHQtZrGLuxyiayD>R~Ndpo(zO{ zf3mm9xo<$SWS`UB&Km!FWUbE0+IsRc{GqNlqBw?L)iyse7?)d2kXhUt~h*q<3|=R~qaR8Rjc6%5>zls%3v^osP;R zYOx~yl5?$G;%ik;Y`WjV5C5r&CV6Og8gb28-*a;xGqxhFy|<-T{l(xL9681{Ik?pm zN~&DB%*p2)K04r|NEdUqrc#vQvivi0Z%4pJaLXN|X~i9dAn?s|KZ}{not%-X` z2yIx0h2-p%O&PNKG;r&Cf%#8;s73?7*r_oJT5)Ratm9`j;F8uS%zO2*s$N{hH8DZY z%kV>v@{ya1IjYau3;c0xJx!O%Qrb5j$v7LyY_*Y=7RF!aRlW+i%*deN1xCXN9xOK(EPgCcb!`G6 z92fD_YL!&-#9eH9250|gjh2Rvni@98zvrva3qA!scGCzm53pO_b8@z(?{+1uM1}7o z?ckVh;0yt#2?y_A$Hh}C-q;?$*`ETAFhJ}@WLl$T&F}ya`3CT#{?|#F$Xfm^9v)k_ zl~Qrb3iLKRyGvduL?^pFU3`3%bkQcy7uwuTenbF6+R10 z>3dY_1YTNyubj~oV`7Rk)??2jd!>>Fx}-S#Od-eR$|w&xVMnLqYF`jY#71?cbdiJ_ z@pl5J<3?7b{Kxvol%SVvtTU_h!3OVO?`Ykq{ISAG)LSq`NhJh-zg$er>BjZ`TPVqOdYxAoM(X>SRW`om*=L=LkMJ*fd&PTae&%73QPTSa#k!*^`#BlPLn*x_N(jQwGCWuX*ht` z&~>DjkbdCs9a%aNP(&K~K>7ADl^$-|*xvk;bEpvGT&^Z6sD! z#mrople|{*19a0FMgAq_JwPz8?O6TJ=lQ)Bi1$Hn&iPbuoLHbnxU(d&RAlLeWwa_s z9_D9aa`-J#Ow6i{>Xrx+3ENpmIkBAyp_z5jH9_W>@vtR14ma<6`XAWu(=c?ir(|h* zv)E6MD3!Nm7Wp88ZYMh%`q`7daC}6=MSoh0=$Y2aG#6op$2qIU1W+a2cM$*pIWAhd zYStuxL$zaF)YGZ=_f@sw(hu#LH`r1fRqV}GZAEpolesCy1ZlrNW#cD{{50fh@>ol$ zuKU;xqb9F`Ke5BeF(1VEi7zVDQl}bO%If*-8uDpkn!S@JtAe+?(30y9Q*0VyA2%fjF@IzaeauWuQn?DXe|{O%ZXttwb(0`?xnA!` zxmYLV)fQe-t=+>)Eq00l$LlI~@_4TCq`UXjTE`3-JMQFi(CZVJ1$(U7wTw&Aq(>x_ zYE=MjvoAIxR-{9h(lnF2+XE}|BY6k+6~>LW9qaR|hhhi}*SU^U7>vy%Q$Fc->K6NLS zQ9nb4_H^6s*aLxi?b+$D-{W&}y_>6@-Qz^?o{YP>h|_C=)Hd1|@BNJ>zo&wdu}*Qy z9YsAS(A}%kwgNs{lfC!;ETNIt&3POsOt(2{b>f%A`SF~utFPen6$gI zJ0{n_-@nH&&ZK~ObFj3O-k-J+^A>) zkc6Em=<*1&$?KPeNzMq|4`w5J((i?A~h5~Zk zDgppENi^u)lFIz%6>Xo+hbTBP(|4w5^4t(tS69&Wy{x&>O&;3btDHGGgAgn>MN*N0 z+XmvWNNF$6uqA_enq%akU)r?}2B+T~8C8>+gCekD6?lGkaV|Ueb)6^wtox=u z_i-y&hWcQ~FhY^r`ACzXcs35=HF0}qZ|6(IY_IFh#7o>$M$O@*^G%tJ52jI1t?2KI zxSx4?uge$ADvE#tySGyX5pgsY%G>^xUOyR94ve-a^oD9(Q75DPB%Z^+0^3 zT6C*GOM3)A*I!)QOR?)oX{q9Z?wuD?nUrTbt$UPMlEZ15jM>XpE}sq#8t!b>iw$nB zR$q9P<_DEJUp#c&o0qR3f*UpH1s^>z{_>VMmKcD##J?&8{hB^Z3Q zz6lUjhObz@Us)md-c9#kyWK&QI$3|&t4Myz^%oX=S)`5Gwx;wdHW0cB8Gfnd&h!6u zZ4WGgM)li>vafZW&aS?~5kj9!fEnxoS*3sK_vrGOK1woJRtwgiW&?R9JPrcA=OyK* zbGA><+(oSz4Ch`SAvw07iPpVQFq`5DB|UVNEeI|>vZ3ds|CP@;>K%W(YxW|a6!2l< z&61d_=dzxEdFRCo8m{RUF-9YKnc-^*q^9a-Pv3WUjJ78&lfqEZn1>G2gR!D=zS_iU z)8)eego4rgQX2z_PdQhgU&*o@`1)Qoxi`(_;%;B~xddF}Tf3Yl>UtDQ$;fNPVqS?W za#wFz(|vtrRP$J&ZJ%>qMR!?0kK@C#Td;VMf1Vm>D`9j^X#Dr@p*h4H4AU74>pg9~*$sNeyPo zQUX+6s6~r@9aI@cm(>$|+XU|5mS+5utm zVpbZ5=S2~iC)$3k#TDF<+1YQLdY46WKtgFg`LvNAFnt&<3_k>gWg+Z5u3F zB3ApTFf~24xV-y8rXtizw|)=I!@#z|&bc-M9B3!0Sc%oDw%%~}=+HU83o)*EqiBARx&1l6oN&#z1It}sfN`9x#Hzsbxo@>c3uh4Hh+all z?LFa3a7;KoNL#sS>8Cok`|xQQ~srowMc2eBfTy=<{R zRw-3v@0Uff)%i7JQU5S<>z2&xG$F!&h)r`5IK*u?sOorW-jsYPdhzd4o7tCiY<6u- z6Up~I%c@ieRoISJXR=Bzeq7=8d{$p9x*o^MTH{V(Jg-nm&}n(&&kMBeSANyhGD3}{i=c2^Eh0aDI~AuEa*yM| zl)W~zlnMTHhMfsH*=+w&+HTJ^6I#R{+IYQ^PHenEzFE#u}i9Q3n_mFmic^u zQ-9o3>V@*@BRmi1Hr zU71{vb?IakoSLzCH_Ie^F_*TM^<{r{+5_hu3~=BhvL+*xjBt!+bD&QxXL*+Emm zkLLAyEB;i6VdjZO=ds2tx@^Op2@v}fb!a)dfywX}%jdG1+iEle+d57X5Iet(s7=K| z*Z)hM9uRoGz%81p=k{l-pnwyn5>eJmNmt29?z@|G1OozK=)m#;7)GxvttlX1Lffsn zsJYm|_H>OknsmrB)L2gC6}xywav2{%k>l+I=H_Rya*@AO#VGH zV)rS(Hzx!5)iCmKlrAPVcYd?)nb?SP>n&oSm(Fom^i~iy`@qnuD@S0U0qc~3XpJZj z>tcd&{(HjUlSaI3t27wSDUla9u9k*f)ROs=@jGux;WzB^{3s--lk9D|X#yuM?gD(# z#o^+&PdS>qRaXaUIQb^Zr;Oq?lz3({U!omT@JC-evtA#ry?ouN;YvAz{O&Wq9CElwi}>E!rz5P6a{yLy@MR0?uAOptI^DTeF+qKr@q*z6D1e zEkB|jMHmhbht0WoCmsZoak)kw5xX!gl<*2I;7zo7w!KB}%&E`uo3Uza1Vb)7I{_I~ zcdl-?X`i#SY6uZyOSv$SKPhMdo?m9p9r(oh+PqWHNkk3`H&QT-MvB$YU_EgXrMfk= zj^S6VMvkC92GtKn<@Fsk4MlZAzxpSL&E+#VKG=a_ng%SP`p2?_>xUwNlqwx0PYGq6 z;T-bls~XuR_&jFzHACO6kpR>@i##dYmQ@7Dp>L))0gA5M1a!MPQ)x{y3p7PE(u75} z4-URJjZB=AjyM1;&kQ|2yGm#2eG+nxN3KY#sD@&Eu(7`z#L!gxQ;k6Hn}hLBjgm!| z*d@*uVGc~luPQxy7x&S;Oz#%Fs(O}%{+`}(M#^2dyIvy(M!}3;*ix$dWfTrxA{3vc zo?oh~S*4lv0jdZj){PA2i<3azWRv=123Wni_DR(Y5=^URo*MdPLGD*agAn##)VJnS z{Ig7Ev_jpC>0Co5;Sm@}p-+OV`ogLR-Nh@cf79DIta>Ug3i>6UZx*jD$N?qHvZ1lI zYc48EnSxh+_=z?jh9}@Ren{YD%S|KUXeZ@f&i<-c-@Xg1scU5Xoj8e<{=w3@wPo{f zZy zkK3q*@b?NOvCuWzx{{oC7wn^g;^N}?AM*9~jr5($HvoSQ*rb|7c|Pn}nD6FbkY)|T zLQoWB!(zXm=0Z&WH)y*Hms{m)tcQ&7u zCz8|(Zo40(eZAd##&<8he51+-{tRf0Z;oxtxKSQCwCR6{U9#7`TR{W+xM&NR@w<;% z1bv}n)lGRCpH6WLMI0bRKgD_H@daDhS`kj_bXq{ z_z?7f{4NJGjsku5=LeCvml)o{Ip@n*h(E>kB$A4>T_{)GJ^mcJJnHg7fbV%-l^Ge| zB#`Cuw{}4fdaH(^fv^T%NY(1n>gpTRr3%^#jsoaz7jgzBAEw}Od3m$lpE8e-Pa5o` z`B4&$^;eUw_&ilzo7xxSzfIL}kz3r8$X8tZoSn2q6vghvK0$7WSzixfJN+nZbhEP_ z!!Ogbs;||(#ID0J%@z7Xunk0u4VPq z?Fky7A~PE+Io5&wq4bwREu_V*?MZQ`!q5JLNBDhzP^6y*xb@WDePEF zwOBnLT{(f|s$sGy=KTrw$y^oT=Wl(Qu?wXUd~QNs67jsL;nT!I-d$PQ+biCNt=V@` z1@Dqm(?t+CIBrKMR|;J6IlsSe|q2$_WFj6nB^(8g(dz@Y@S=a@v+qL|?LxI7-i9m7ZBfj^PZ0)hUU=*n8p#c*49H=X7WgF7ctiMUI8IuBWbP=!FQS`n6Z4>R8i4$*EfQ&IYCTXo%xh6Nl*Kal{32N z%4LltKZgIhz{EIg^bAt8mQuwoosG|OJQdl4b8s2ZZ}$NdT)PM_5Pt3~7T zyIAvWFeQ_I3s@+dm#>aqNq9anc)f#~cRap@%O0(M-J78N}h2K)St(SD_R3lI9T zRbLIgnoj*V-Lpkf?7eO8KIN@E30E0R2yT5$NKVA7LQ$`I97+gXw0oGhwO;z8@Hv%L z$#_@|1)Fw*O!KnqiLLu)8N2~aU}9imXs-Q+dD8q@e8_oN(dhOjmmlJL-U0R`{{aZk zO{%?KY~qXVxojT9s#<>>)?2Es%fw}CqcRl8xz>!a$d-4T(D6;z>pH9I_ztXsGuqh2 z(s$ildvCa8;K*;bg&J-7?YW3~-1l@cz?Kqtag=N1D~9jK?tH^mommKa`f9gWAJ%$koQzw?RPd0e!aqWnO+xO}S!2%0K0JC1l z)U}q!d^1|r*GkXr(43g>)6G~px=*QmenM(5*U5M5?5lAzb*Izdd+Gag7yzn&U8Scz z$li2bR)dq1MhLvAuYtr&>ZE7k)I2t3!ld|*_JhM2pfm(nT)_!jZQ}-p^CSlTE}h?b zASKPmk0IWt&Qk*BQCtCP;=d?bE_)v*r4ok}na8l~cilShcN6_3+-?_n7E*XzLQ=_e z(k;ty6BGbsoh->_H;UwehS+bLz9lOth0kS5{)h{`(XwSdh80frep4f5zA!NK9o=cA z7noU_o!tQ`XC@UQ@E`$d%zt%R9oG>^5Syp`Y23+ro9>2sRy`Im77_z9g#sj_n6ila zC3;mNr`eq)9$!6bB&LuvV|hEwMsqSL-8s7&{7WlZiuS~+5_oK_!X6);yZY%r;gQ()uXlM(Zs~)2r89)M4!OyVRwkVI?WI#v-Lv6 zgwWrk(q#?aIk;gMQJKa^yW}Sr{|4(p)(8a4m-=Mq@1f_scl~)(us}=rPA7Sa4EXh{ zA>M&T5ItOM!|R_j5^Gh*{Qh6sv66PaETOTy0=`FoIvqXhLfEXn+v7>YoB@_KYksXC z1`wkD=?!Mhr!tZ%xp3Ugt+(SNqpgeJ>8YXMR}$_uuYtO%kA{5o?HuzIwz zmW~t2CV2wD@06_E6nt}YPz}_n0D3tdIkaDtA>(!IxuT@O*T{YCp=?_nJE|}>G8(NK ztSkqP(=(TsWk`c*X*U^*m=D~svi~f9&rEu^Ut5m!aonla6CBXqZKxe)VY}&!N1@~v z(bCmf-rbfr%!KlO06%$WXb1(t*1%Wh$>r)}u|;y;Ui;D5(9}7%U7aTvXTr9!ubQLi zA43p?LM^|4vxxLsoh$#Pb&eFi|G8z15iCb9ZpT*uw1ecd^j1 zOvjVBqyrP)lo|Vg6|7}HG8qva*<_*Q&xJ!f170`uZxpc_OZpNi&BA_XY~=3RVyPDM zDFKlJ9cY~^EHG6LGEpFhaYJh8Z$7p5d@=(6Mzc0Fs4eiBdOIqPGpS)Gbr)Lu%T{s@rNu2mIFkr)d%uqNszJ$^KafeK%n$H;fa{vl2Ex zkJ84#AHQhFBAyHleZPKg4}S=K90z*+9iof%$_ROj;&?Hd3O%x~C{ClfNwd_3K?bnX ztKd^f-0T7KGu-|WhiwgpGf1;NPXRyrPC`-x0J}d01wXEc5r1Gbm?(^-e6eWGRuj%&1*)fbA zqV?xX?EjdVum#zI;_CLc1zQG#fi(Z~pN{|DQE;iU;-` z%z5=w1noZu0n={z%+{@_{Bsx)?f$RC>#Bb^LI>t8h*w^N|F@s8qn$}d2^W5QnbwB- zf416v7N^Uoualw(DMxo7uGk;S>kG#f-pG6(`x#YVz(BTa%3m#6_8k2YF#4H?~l~P_KbiLDo z?;YE0ncx+g9g_6L^m!*?OMrHM?sVMoM~BmP47t#Tzyb!Kp5N~xIkKd9bZV}J za(%(ai&lL6>(&jhy_B72jPuWoOXqb<&6}Do@41)ZH}u|&egdz97po&WE)y(yr7d@u z!kwoc{^l*^u6Y(#Tm4Y^OeqHo=}Jw(EBph3e>xeyq)mkOPt{}jHQZV}_B}Yur9`<0 zQGT3pFWN2fbC$11-m*2K$QL5_d_>ruxkhiLIBWFMJgnXsAy}S1|YDI zt0_1+mCsf$4m**Y8l#$LIlvMRN+red=&9ki6;cp>9>voqVnR0m`>zBdmWhwz>CW9H)AYC6F1@efu2n@FOX&lD5lp>aeJh2kJj9bHM~nV7^+ApQF~90#0p(J* zt8v6Y;ZTKrv_4g?%`EPpIgjsGPYck=-R0e6VkK+2w7^DDi`&Dow!quB$^RT-d2H_@@1Y7KZ5*r=N?P}xUF>jFViHMA`S~9{UpU4H z@I9Z`ql+hL566(cUi`#3HxP&#z zX}1ug$J;yfIDSiBRweMB4lnVSAqqUex!GOo%+pD4!acXc&r8(W-ySNXZ0lQNbyM}A zZ%X#TC*nn(IB}TJNT{0#a39~||8g6zYkQ{b=VaD-`4D2lzaOwMv}eFpqob$oaLmS< zuB}go41=S+njvI3B5-bJ3PedrZ7SV&hfT05(eK4O!^A!CwlHnXc_a7SpH&YV`G>+a z0fL`zzrmhJd9OA;6UB(YyXG{XAxHh4iJrGG*ZKPix-n{qib~QheKg%)Wsc+Yr4q!D zZxkwGgD9GKADIGv^+8eR!}VEy%6!c+mcO;6Qgn%eSKvDx@b?VLpU}$@>H0N$pALz95o+Lum^KqLd{o|rsoXniOZK^u&6_v zVr~UJK#Tz&anpbEEW~+AmK!w6Yx*0KDy52pxEbZA-&t2&Tw2W2P)|M;2dMj`0wTi^|Sp~o|cf&);) zDr{8o`1k9XnId2kHY!-?Qo?+$aMqPE)d<`_F1^|$p zs}CyT!hPQvM}>m38KD<%CV+>E1Rr1=Cz~)JfY!qe!2XpWm!AZGe!iFGEQch4;=n40 zLyh=@DFT*Bgh>WK6vvZ_SA&^yKXGoO1NafB^zmrrEbkeH((ZfLQjJNN1{7ugd+(tgtKxc)+js3N-bDI7O~)0~*m> zk?msHf@-h!#&UjLVP*G?wz_$(%ERIk#1aW+#hNDV}qP(t)raig5x2$l}Rm(f5yL@CvQ z&SZHl!-p#nang;=>uRhK*lSCck0?K34}3FslPLXO5^R_;sZFW@~EKQySQXu zv}jhJB$`_=ZUzY_0dNdJ4+*{rubDo7UR>(mSf7Ud7(%M=s@P6^j}5$ml*TqdgrPnn zgdwW9Ab8zb+-*>$#-HJ2qQWi~0f_h$SPh0ovF^?iDj+Py1q&()(8OLBNl z-V(*rV=CpJ%#kD(Jq{7UE-!cc`5tJ$>-?wLiQX<{+vk@%3ZXt?xXF%-dD64{9a~!l z3{2tcB5+Q`T{c#&_HEHhrt-qN3#7eBJ_UqZECcn1bR3sCmeiC1 z*N(cP9;b5;huI(KUe5#RQhZ!}J!y806Ce}S*J z-{q)`iM2^hjzE|1Q@kHU@Ry zr`nGT6dQJO%_9V#hBL+@K$76I=-lYWXL=&E+n!oj;WJ^m=*wZIL~=61#V4s1O02Bz z<1uv^EW1^(lkN5d)5}>6;d$4z|FLw~sUn7=mEF%h#RWBV*r(gkmB9VD>z(%V7U$CtZ8`n(Isu0T!vZl^P>_y%50T zud0)sa? zM;NP=*5f{X2IxIxRuN+KZtLN25@g zcD4nrdKbtoo!@2XPK2_LgI6nJJLcKSg$rR9TQ5%M{(^d}=-*XlU%(%LLaw)846f=Q>opi%9|wW-gYGf~mL!61 zM>d|i{mh>OB5zp^)W1&{q3+@A_U=Dz0bgw%p<{H_ z-xSdqB~iOMt1EhaJ2+@&;W^%$(tGXMGvsi4-lY_No~UkX(b8rJ|0I<2vRN^ElY8&s z`J2ztO+)BzU@<;jKB6DaerUHh5E+X?xbrI&LD&T=*s&{sQ2(J2@Z$%zhH=);1-g0> zQIeK)efs6x(TamQQBk|~()5caMAoRXL=>M~#J|uTx`xli_*Y^&9)Yc!mwiEa9O##C z_dF1g*BoxM9sDNOs5*PG)@C%}rbStZGHt!b^Dg`aM%p0Fr?BZXXDhkryZ3h@MLRP_ zCIN~QslWMsi;9Dj3qz0R7)qOn(@-#1)l{LNjrdm2LrY5&OlaWl%1By)A+G~CR8;HB zWs^nKXkx3fG8*%c4s19ye|dC(#u zBZ+a4f6QK$VA`*@zAB8a>GA4|^b{3M-2M&=<5pA`cQX*_Gj=%$%7{?T63Ij-$ToN7 z12-4mXv>VPrW!VR-DE`2L_*f;Ooy#i)N#WR6W)^f*e-44?9I*27(=EK@tIzS$*qMV z-Xka@BP(@>y@gqYMhl+aOc|DT9?4U7`-U*m?uDE^T|^EypOEM;>9FRNBU+ogR(9St zFN^YXJsY>gLI`c_o@PZC{|y}UyMaB<{*9?GR8IcG zQvb%3rvhA5Fc*rZ34l|5>?nh9;&sP>GNU*ML5-i@oNImgi_CgniS&2P+bCMg>*sjq z;|(Ei>CAd}ei6r$nH-zZ-(f@e$?~?elaUFV`M->+BUA7-dBs(2ZKzhrqJi%w-r!hi zd@gQ^5~c|?P0%mIC{}~hM5Q)GCzg3578XTqijxTQDt#3U*9fP6ANGxths9N`)@1T& zuk*>sb~lgit;?x@*W8=$Js8qJAH)qV*$Z|x>i22Rq1F{$YowHeKVgzr_Yu<6$1jc zB8am!2Y>6BJWq5lscQp^ULcxdC4?Lvw^8br}Vc z7$GMPsQm(%7#Lq^gA(4kDIx7Te>EH749yG+;S zZOGVO`VE}rVkbkH(qP16ionvk<8w)@=qgA9m>~@?5$+Fpl$lec-34J_lq2FKvFNYm zb;XUw#Bef8{URP0BsHI)SB>>KQfae2&VX%18l3jo z?i#mWMEq}3jXs9a?96Wd?MrT9_B#hJrF>;BC`t_M1;o;?#%+ZKB_xa$avdOu0WC6e zB}RNkpd*^UIATUL!fDg+z9&eGa0(ZRlYD_!LHf3n=s809w!#!y=>+Wjl~f9-sVw&~ zaa3QL$@~k|`}cEm-Iw*3V{;}@Iq-{!oP~jl*ZhuaAT0>g;&V>kbzl3JB$S5k-F~*PyA!wJu&3nnm@HF{);hKU|7lUGd#szGf!2wPZ#1fJI0|gz zOK2T__r_3>X+L|NZx*jmp#P1epb>@SwPmFJ^GJCnu)(bvOf~hU1=w;(ww>M>0&}$T zY3BfZmENnSIAbPwGLi1wf|!X+0ccwGf9}r@b4n;iH_-i$(qHdp6H2i(HFvY-7gEZM zXWK`z@F_bW{WWKg1Ao)My+w45*AN&N*e3?w^Gvm++*0>{rf{QrFUyl$)Z+73+o-L$ zzI5TqZTvqsyoZOg_zsEwJN*q`eEsj+2?2|uBc)|&igM*+JZfgr)ae{UT*4RuHov|Y zv_7AG^I1ikc0DCYyDCGf@T7fHp$$Zy@ZdrQ?^G)}Bz7m3r3xRff;z;N z^oH^m$2RJRE4VwZ>UUArX|$SsLCgWlS}28$#a40fDS%>ls)ui=NK?bH(8HHp7xyw2 zcR#x})PO)NpQqR7dn1Y!E}!&M*T6&7vb$ceZDf{ms0qhT7S~3PJ=lXcF?x_ykVUA? za=7=*C~Ez&m#K{T`RrA(I8^@k$a#>UV|i7x?#I`^z10O>!|l$_mouF`U+&_)Uk+n# z^IkSw1SfSg6_2a<{EiyH=lhn|D^0zn{w{-{>%n&03ss|9TwheW+spbg47~wyN~eD#;>;Y;^99LR($@G%e#L z%njF`&#}OFH^Z@trE9*qF{8iJfq1sv4_xjg%{D7_mgAUlvZyMWrUu3ky|`MIE&i?6d(^^;@QGNhFV zFcyIKLF)4(C*3XZaoT7ji+DKV@r(Ta5&k&1r&T;9l2D#5Hg)h8pNAEM1NZszDU+b4 z9eUrL3%xLR_rD7NE1=10na*drIabqU|Bm$DjG$-~_a;IL2D( zWv9cx#T!IEp33GAVIDLhqsjTjyiL?6Tf@sslgeAXMnC8a8WC)#@*F4(PFdL zRCPr-{LHL4x|wtJnJ2DQL2C*i_%K(Kv)1nFpPCVL;aoO_Rb$lp%`Ztl$;{(%BA&BN z1TRui?ng+d5~a_xUXMpGJr~VG#@>d@Fh;|BR?E`Rabh(cd4roe0n?tBGjk*Kl+;4y z=p<0GsaF!F$jy3mN6dAU6>iqmN`+m-pj@bm`g5MKl=bS-WyjF#`Jcp|HE)yAl{+wh z4IjUaCIZspOcTi45KzEFuU3atX?8F1< zM#I(W>rLBsPl6SR9L_d~%MsXsD9@1Q)>nH!``(pa-w}uOCZj+kwD?2}dcyw)E()*WsqQ1{PluwT>%}77x0P>j? z1RIw{q!|%-_H6&&9$@puX7tanwBt-B__Dp?8UfZJ96FM~egr6VJcWgcm37g*nd1P! zAvwgJnP)1ayttsHv7~Wyr=h8-i813c3V3Uwfa04 zGjCrh%g@{&ECX?&3+)!Ril&-6VsG&V1wy`<>B$%@A06fe6$1tX%o_{U^zo{6Kw7XR zsmITy+AlOjC@CDMMr|gi8P>1X1tgkey?fDWpd4B2-8Z*J*iEhxd`uQX5Z|wcIHjQ?6iFjG5)yiAq$ZCt+ z**_}Dhs$7*_(gWIsv1i@zy6T)Cb-=4G1?mt%hgH=-!%H*6PMZ_quI4(vMYr7Q&e9$ zDqWtAB1WMES?YUuId(F%MYh)O;`5E|Uu17nHDe&LqH7(c~f@;{!_)986UQpPdH0^bj1wK(*dh6KNUxP7tix)LFu z&0iUtb8s{^u?R|1QJrn{gsu46zS${?rTkEHEOJs(pTAy7g9iX!!n~ZUUoHIoS6`q1 zY~?%rh)+?JAIuwTuMlF2+=W%ImQo|9%)&>H6L4z|y!SJm)6~L40WI=QWHr?`R8beg zZc{n2LywH$J~^8q5NWlMa7CWlcapEVH_AqWJ!PC)%v{l#uUZR9gZUUd`02B%8hA!3 z;Ymp{$1629j2Gh&KllCrzUa30LGF%wMwMw2yzeNjtZgGC`+`x;8__Fl6nv{ZX5wyM}|g99_`>N1M6>OVx_vz{}84mBYq(4@vyY|HVpA= zeHw`Khqj2Wl<9i&dH)CU0OH0yyq#S2_qhuMV21&~0>cjc@5gc8p<`k~pHq9i5Y9gzb(7- zVQP26xV?skmwe}zV3NQu50}O=VxEPK)C27TbK*_0laDt`C_=6K%0>43 zHtFBkt)7xs`rA|-GahHv()84pLFnO$W+-j#=;9yZX0*oh!~5{#Yx>&<+S`X`YMj+6 zYFG1$Y~iW0J3I*i*Xl|`9sY>o6uln~$-3LO|60@m3xAOM=g^$yjL=`YMAroV$CKn(y0B~TF%(pf-&fDafVmpE`)At21E z#Iq_VLK&ohhLC|2=Nz+~IB19j1V{)7NPx)c(!Xba({Y*P0bVxn?mE7aY(S5)mzE6_ z;H%daBd8v$&??DuQCYvi2_!2%0cemIcxCgm_x;Bsr&wB}Y_hEWiren_;?2d9GL{C0 zOo)7>krh}Cpq3dQKC$%&|NPjYV0ig^*REU1lhDstE|Os`YC3#9*=4q}3Y+})BLL{p z)Y7Mw4S*@9(OxqiYvj^*)~Ez~KmvO%B1X+z%q9SE#mub#%Qs zU`c4{#J#_Sd=xN`MD7$3%xo;L_Y1KmyOp}auw)@`2D@R1P1eqZxTs3fne#* zyhZ0OcCjc4SSk`PfiYw(UXFoaK^!%_fIG4}%i%7-H>OMnaS9?2(?DvO9K?DmlF2XX_?p*<9$WUjn0uNF;0bhcu&a?F`08G!nL1wcbr6i)kA zymD05=RqVgu;`FNhGX$DhMfCN`iiP9=0Tz{x3^j3wmN(kg9Djh%2#%@FFC9YXH|_M za87`vXDrmlU_vq?y*`E0 ztr-abi8wGv=I3xsw*0`+Ph<>ZCJs)aM4huotkkphCG=u5{&ofNT$+qbjX~5 zp)iz0Ukpa9%_Y!~SIp9Zs30;2ynW^s8>g>z}BJsWdy(enVy-cYzg0yQC8p}nA`7%O%d=i)pn zU$z1cub^h2fUe-;=3V*vgj}zJH~|xf3EDMj^WhG0A#bv3Z-z_I0yjn2uQ>GJl*g@U zudCZhsTvlYHxlPZ$< z>gJLPD+uczR48o31jm$Kdjrp8GYpkd0bS0|jOp zxfpNv$ga-WPAxYnuo4Exqy`)bi7REwtL7F~#PVP-?=Umh;F6n}fY3%qq_mj@3X zJa~XV%OL&MeG=^9&tGq@5{j!3O(Or>Z#fQ;@`=ALyD3z06w6-Mi>?PhW3gd9=s)JcxA*lorx zA>!5^wjpmU8ZFYdEnbFV+g&8LGbIj&RT%%f6$YcEE&u@JmZBq@>g>8g;*uHN&` zN5i8>BsC#RT1u0G1$kUvn6kh7|Ajwu@m%q`k1&L(j(+W+>4C0?l5<(v7PH7UtFV7=V)vTnZNR+aUD$Y@}-(wNSD)jGnqY*c40%K_rx`?Hh*?D(YO&>!rsO$wq0{gzPa-tUsovb` z_{Qck?hU7${DsXMh2{W}pcxQ%a&efqQOnu&gbo!69E~wRd8w*lsLowxti(|`79I{R zZ8Q^BLr^aCzQf_<+CkuL2V0 z24G&@Tp5K<4#VUd7ztGX58Rg3BntoFvvoI~QxHg0q`!`*^#!eaPcW_84vs!va7c z7wK4ZKH%XEu5L2fSYd`^%z#@&y0b?125m$0_@3S8{Z zAzUfvb%rg^Fwbpl9F;}K4S96LoW^Osf@>4vu4BV3oeOb0_gw3&4Y7p2bREVv;e_S$ zE%VCV&Fg;0hO3TD)LA9>jKP+v$3IVvo z3Us&O?&87V?Cy32CD_cYa7vWxaZ@@3BI~+Ks3udN`cnN48SL7#jV#?ElPR89IM*(d zcrG@$MR&9e((*kvg%CGGHrTsQ)SgI(12W_qAUa!}8+w`%vmJ>hkvPl&nZeiG_sASR zEXT{p2K4RA1->R3aQJtfu*3h_f{~GG>*tt@J0Nm2E?7~~tc#}10EEV5#$hHLP~4_M z=MF|tGl`?v!NM5G4K$Oo)jRrF1ai|AIL8?x~BeuJ_G&M8;?|DVrIB&1E_)!6rbyb>&~rStjSe80VZZM$U#fX->}NlKARZEWQ_0 z>vgHUuKa~06w5gFg?Bv`YV+jfU9Vq~Y!{>LH_~etud$1fXL6}7hFX3rrglCBsZe-h zsc9NxtWZhwDgYpHjWNmadq9Xx(^LRNh76giW*tHB{{iDPe*IGr7)SsB002ovPDHLk FV1gnfn)?6% literal 290534 zcmV*wKtI2UP)Px#1ZP1_K>z@;j|==^1poj532;bRa{vGmbN~PnbOGLGA9w%&|D{PpK~#8N?41Q* z6j%Dd&-H)aUhl3~xeC;vSg8TUi@RGA;z}SP4oQF*apFRRIB_Qlad&r@O|mw#63_0= z|9dk-aEgY|?k_KIzo+wN-h9u-epXUerLLx~q^zo}qOPo>qO78*qN=K*szL(3>Z+>B z3X00$sRq8v@(@A>Dl4l&5b07zzbIJBi=@B5pU2~o6{f0=PZ0x|0kPh$P8J%?%-+K0 zVbjx^s0P#&+F64oc}Z0m=hz9gm>^%LGjdT^4YFgd6f{&uM5VM0}a|WtZz{to5?ez@w z_V&`!Gw@t8p&&>K3k#vb63Pbds<5)2;-u>SiP1R9`CQ0k5{-$ztN!`rX*JV~NP|#Q zQ)0Y}m>Sj459SHm+`Mc;T^&UdiD(){o}MOuo(i#8#OL$BUwu67szbb)e_K_e`6)Rq z_0uTeNqCxL-JO3@$@kPHuRfNrJ0nQbG6p31J!0R? zZp#1B+*x4}d7V$DVPdrRPqzPPYa9Lsw4NH5Hvy-eZy21i7n&}DyFAooo ziHQj+_&Fj0?GcM5B9R2i@K1=vVz2=az-Njq7DSUEe=^|dkw6ZRE840AWlnA4M*vk} zAkY=&<>|HfKy+4CmPb&oa!5accN3B-_iGM&4g9{eD5$vZvxJ07{6u8?I0&c4oO8Nu zowAEY2+*y)=b{LL@8cCYO%MgO^+bLND=O5+(Nj!J5t3=UHAgEYL?uQieVT!6)zU9lQ2VuJ_nvRQ zSh8x34VBN+5qr%;oME`mBsC}pS`lbQ`Uz19WG-{`;L$Ih=Fm}elH6Ni&|_CsRo%F8 zgNpP#ncz(FI^eX&#LzZ!iOF%&cWiVLss{vth}SRS_K}_<32M!r0njb>I2@`$1Pl2g&c{q zTgD`46+tN2rxKzGd(TjiD+VfvBKy`bJqvqx6q_KRNi3Rv$|ezz{o6miwKu6ATOD^r zKhAK&7r*?Km{S4%|69Hl%KzUpX@0ufph-NnQpO?F;WvNy3$*zxn2qZ-4y@D$Y}LZ-q@xPF7Y{78Ddv!OxTNNm>9z zXiw%KGED#9D(B}z^4`~667{(j~IYxx$@Y%YnpBN8l5Qx zP2y6MlF^O=Vyfu0h0*5+FT8d*@TU94h4bG2c>*5QBz__v zJ6s++CMlFRvG``sxeqtmK$9r5W7UxZd#J=uL{`8R&?)C?!PUs}TFEpap4?}hNQlO) zZEPX5XP_j+%ii1l%1o1}u~8v<@adbxjf>5=qn(F09noET)_KQHj1ko=S^b!7vts)WX#i)t1gNY`{oc?m73$}(=d}f+N*{!NRoloB+Zu-); zbF}lgqA4_quG_ajlh`}T%4ivl9hfTcIU|H2kfck(y$MZXbY63i;^t5{3yA#fd*8MX zjnG*#b-8G`Lb^0b3`EMm-77q|!31WpnBtM1893v8%#5w`D zeKz|L4NOU7hr}~iG~@XqjC%zUo-?iHL!`D!P(8T|zw#Dq-XOfoCX%a&<@d$^LG!2z z1IZ+&M<^8DlSXQu!hG%_h6-EkDOuzxS>i5Q>>*j~^)zSyqbh7_Y6{%t<>geclxJa@ zykazk3>qd<{q}PnCBnq{lfALIxw$ZL{@rW3Frea27A#l4c6^i4k-uz#i8H&*i_!Wt z>o?RWF>9O%FJ)6>U3!$LvL0knfB8QTT_%J>Go!>cyLBw`pMI1$*qCgteP!Lb)IhVH z$MqcDi<#6~VzP@4JI$KMp6cwXwxMA*pUULvaIkQI zQ6es!Fu#b_1SI3_EF!D1BFjBI$*6_#j7#0OD~y^r!=NJ~BI3m?O}zpHxjxg)0WTB| z$z2t8pks!(aP(k-Y2j2%BJnPV#zYjWi&OjII7Pl)* zOG^vGIk~XO&&PQHhGRoGkBeg*F3uNVd>%xASUfHYlroD94i4T`VdLDU z`do*KNK2QUyE!e_pi1ic1S1&N%~%J+1*Z==T)Ng;HG~aggCl%wl+(@R3U+R>Id9{! z(Y2n=QpyV;Iy#!mMe1>Hg@M-aa1I+|gHB;wCJu2hoQs2nGl*%VR6M=_sUI!?2?tes z0HBu-gbuzBI(XKhH-8^=@SK4z7RkL8Ms{pmHiyIJu-I()odI0PjV#KWwCQZ_h75iH zbnt!9!Lts%`TL-Q=L~eQNbapL=$hKvyW85kNc&FH<#ROv>X6A~v6x`9nJi?}*+`i! z?yoQ|ICdPqD1hl6%<-ntawRY^P1xBxc9eI3;<30;ajf2+Vh$T=A)S+yS>fIa121rB z$ZM1Z7%2aCRY!)m*@B%$dS}4X&e2V4pJ{uUS4FDJNi}&UGtBwwb!mmo9yl7XKe)mk z2vivA#_og6>=l6S!JipAyE~u*o*6p3`+y*UKmY?hkRMQCLZOh1_G1Hw(eCpwbar=e zPlTs7bawZHLb1_NR4+fF3VYQV9UTSxp%v!$qr=nF)63I?{sR#i5Rm0X{@#fP@}WXO zB*P&(!i&!C4yb@K!6J7%IZX3$_7HzKC%SJ)N8L^H_4T}g zmYE7;aFfCtg_T{naVBo062Qj8l06)3*X-u;273DPo%|DP;=E7G8XIR+pHVY0^US_* z{McoMlhFOA+UT%Hg}r>PfmL+#B$3v~Kfd6c#zLh_C-w~u4V^t|sr%v9Fx~akR%V6A ztFRvvd>&fJh7lLolz=>MX)>H)ls^*Ccnkv24=JKZr03JO8PAI!sIY+Zr;cn`Toz#f z^88kkMn-fqgbo9>!&*O)!Tu*$XFz;CSg%g7X7r9JET^Ac0 z?7A$w>BMh8EQs|vx^YQa2+|~rVrG61w`CxQGdyrr{U{5IKeA_w*~*<~C=zvGW@ z$$fXyOGo?Al3go4T>Luh`_ zjmWs{&{#-yH89k&gvH;MPJ2~;NkcCL<<;fE zz@fb=0mHiF-rQVyGc&nrD9+E($;fE}+??$B+}75T8xXC(Ef8#Iwxt6&1k|Xld_lt;ns5cLL9n{G9yairie(3|5yFgWcNMS6fip-_;HS zG1g!o9CRoI3>M&6_YCvFSyx!5wn@FUqBbu#zoeuDj!r`dqoaobnLsEUxR&bH&fdYY zy7sQVp}gGsk_x)ey}f;%3=H-V!!tv7rf$5=!+DexSn6 z9J&a0O)NTh0LTvP;ej5?DP{I~RE61A;=2!D)LpQ(D$Py6Ed@^)){kaiZpgS&+`)%X zl!27l<@pRcq|6%93VX$PK!uHukHe%gCpQOV0Uzd)s81B2iKLX549?>-7=uhElaSn7 zVZ7{|?5)Ph*r>oVxV9$8^^ATbdoVB5>|D^z#-XMns!L0DG|^wQgUm|GY(Q1mFq0_~ zi|*C1^t=MTfa3tO7YB#_uJYt8G(Lo>71#;o17%I+`S3T`Rm_XRV92E$tBoAQw(i61Anc!-`gBtx;-w;loZj@`6Gbi#b6Auh6j_XhVRiZJSR8brFrz?aXaQ%8ZpM^u~AQE zXke)K`S$vB=lt%9%N5wMedo7AT`6bi8wbAsPc7{|hNjDQ z9RBi%w%Ik=-+h_lc@E~w=MJvdHJ~d@ZP}jI5)T}!vd-h2*rX3WZKa-BRoQr3$W6bC zJUknGSgmQiX1~~)T64b)*|&F@DC?^JZFSByD+oII-z{LDOK*v8;^nuXHT#5WbVr!_ z8jZ7S_kj?Smc{P~D~WWh@6UHAXM)eZ|EwQsuh!eYY}?Q+Fyyax((cUrn{m9mlTpd;i%9L@4-9i*MqJ&) zx2r-cu5GNevJf+uLnpCX*91F5nAE$K@eIta!{kTdnC01p+p5#up&#LLBa_>3BmY9! zmbdI7yv+?F8!p+^oaF{SjPeU$KLWDC7)<7HRAJA3gO0o$HjeRmaB8F5McI7mUD+=m zO2dW*8Npd?_f(i5H#6(EZ@m|8VN{uHo7~i2(VK^1Xt563F_<{pMOW*@RoSQXe0e(3 zzogb(7A^Ij*=Nkku`2MPTcqQM^j3WGW^QCG25DO+)!(k9)Yg(}y=bIYj45So$p zp#jja*S9#!uTcP><|4OPi{pxaT9NI2HY2~H)?Z6S-n^oP0YOTa%-40`6{hF^!oe|{i8#8ieY4@!Iqu!uWh|( zWe3T(y!#E=i>=VXqj{3VX$nR@f`XT@|LHqQc{0 zRE0^In@B6{RpRyqOlgI^68u1gt^4NVoiYb_yws{Rw@)@ItXcH#5I)?QNMF~vpSpOb zxSY5*{`|(;ulKH7_#YmVvkcKfT z$T&{`pWE6!#8a4etgsJHY3FqoL{)Wl547hWIAx6<)p=|b|Ad}cxs#aY2VdM#+@;0B z>Mj_%m|x9E}`XQT4G_cwm9c2yUP=aPekxL%?XJc9OgulL@2A1dsB|9kK4_vUk%jO?1;CCk5s z`g@`Zll${uu9+O_i`3`zG~{-%p@^~B=$^a#2|j)C!~eYn!ltu9U0q#Dn-|pks$f{x z_uqaFo9rzJhft`nRZHfrnEwHlq&VL1$5~-g<|YrQF!G8sc2wr{h)@Xa2+|F{All(9 zmEaLn)fFXFci=-m@c8o&a`^CJN=WTME#Y3{+xH&bLquNtT~9Ip1bA?TK{dgF_$nfa z&1R_2-;MLxLB|zie(2`kt3|Z%>_pn2$-}bM+i|=b!?25LIx5Rmwr_K?me(HOB&uHU zp`vAV^H`NmE;(H$o+*^ikDiBA7>?oSmZ@7cgr5JE-ZeERxLsk<(b4M4$|`EA%2010 zsHmu_D8oMq2#QLo>ZG8msG@{IRZ$?=>dH!_h(JEbQ_72CYHA9q4b|2OB{e_$GksYe zrmkt++H}@9=W13NSuLu0ZOzra)j|2iR-x_IIu|nn9m+$j)KpKg`8)-ggQk9AVL93H z-aZ7;?-P5&(^7weH*6P@1-XZ2w^XP2QCpJo?A)#`&>1BaO?5S8H8mAY6%BP&C8TRe zUDQ-n)j;8t(LZ>i8dOnL17FHVO-&6v6_pj0RTYsBsbOj=N}B4*s>;ghYO3mLpqEme zdk)aGm7bms6$ZqRAb}PiO57X+ibU-KK$Y<6ptGBkh(w~oRt)JDNRJ5&MgZFJLktZK z(b5ZsDixp4r`$HXoql($?1uysqPEs3=*3K4Fn;Y7J->2p%XtjkakiuHAxT_p7G57JfEZr9wCJN zq=R1!6C*K^p+OTv#eq6Ddp`JhY%GZm5Q%(b)nrJbO?BnhD1eWj?E2HPa&oeA`X^<4 zEH6%11yV5|231>zhK5vaMdWopnQn)nhMsI*TCRWrer!`FKVSNnu> z!Bt%Z(K=4>s{L~Pot(BT*8tqIAx=Lb8l9AM7DRyzXK@`aniSQLsh=J_TXedw-LjW* zdR*2*hgi()1os$LOVrno;*lMAS(&Ep0&21A*3=w|6q|nuP$_5-BVi=6BCqf+3Cyw z{O3RaCGbb(t06H37Z!n&7|NQSPD81m98R_)bf=VD<|-4RWlf}LG))s>Ijs?0Bj~HH z1aZyIkSMZ0dbP*IAQW0cJ3VHqu@i=pR$!vU?_9SzenwRt}| z?y9Zv@o}mp)H$X8k3an5vyVPlu*}TD*{{lT@85s_cR^)1F`W#Z4NCWfFf;9N7*`O} zExAdN7qkPI#9uV9+qh)U5&2!ZJ`k;bLJTcoQ?e@@1j!gy!kiLLKWozhE#Vle zYsspulr#34o@8oFFx6MrKazr@5!SPCS8e(E`6nm8koF2TQXSDSH9~({d}@krb0(gq z>R%MYbG;$FySAL2uXuXi@m1O92i@Sok9ZoaDUld0Gl9=ss;#-tgIhv5)iWQy_Tll} z8)W3YG|xM>M4tcPA0Kq2UV)a7YPFt}!3?W0vc{79y~7PHY%Lvy87Eq&iJbN!6MMfq zTSDy=4%HG~)H6m2o{ILOgkuU0auzq^F6f`wzH(gHeel2`zxGMRWBVbrEjPkKR#X19 ztwER198=IdeE6_+MEP;^8z+~2OeKF7>f@c)I(5?yg1C|BD47~$j56|jxWSz;pL{0n zsx1!>&+zaF(*OC>Rx?0LFO{TL3LiVayKAfl=B)+>Uh9KigBE3y4 z8!e7&n9dv{q8jeX;fYLg8_~g)tPLa*n#9^6Vy9$LS-%MU6PqPLsggTmK40_ARa&@N zL44tZ4zzB9;>Ii)$Dy`FPVY^ix#BSGrrDOu!6Eb>Nr zc3*_YG7qh-u(0sFynNDM%5wl6TJmxYWl;Y`1w1Wx)z-+!NL3ZOcKp^sXN85w25Y0) zEY3$8PL2z4`2|PAPH%_VamQ1w6V8kYH!SIebB*k2D(@zw`*&3bd=5EkcQ1>vp}E# zC-MM+1o?o?MlW%HAXKXRp@Z*(4xV-B&EE$dJZGSbMRI3L$jdJ%ZENpoYwsdW_l#+6 z@51>4CX3BvvROIL# zv^~JngA9kT+rb{5bar<@2R$=%cDJA^f&!Y!N7a_9;%=oyC&E1*{K=VN&O;hm4*D`Q z`U)9mc*aRloRUgQKM0lf7P(z)9Ub(UtNURv?|OewRw-F{yqYdvKl(T~aPdYL*cgVI zo7CtyXjf_iFEuwagIY&~g3-eVk8C=2iY?$Nzp<5r^P%+d&hZ#e2(i*Shxs^@J2Z$3 zMrD4p9z$Oie>pFD`GMLJaMPf++>R)$vu|4_GK?+6&$OIZ>zUSsHkQ3 zfv3#xUROSFQ0q#X!h7f=X@FHy-_6U15BpT6Ht;QTP~j@PRDEg&soFZST}Q(@_0YdR z_tVwnaJY?(#`^wzw>sXneAp2@x`}7(k=$45S;j7B4#ee$UgqK1aC9+lrAbPU;?DCn zn|77nv<)-S;Elw!rT8b+_hm=>@+Ky$Dyjl<`f;xC&mXLC*OHqMj$7?eXv)d$ZqH8Z z7aY0Zim@v7bX;WrxLQluB-{3woO`8#_4Px4d&k}0k}UOX@Zj2NXuPcrKQ?ZSyQmd2 za^(yM57Lj1gF!=NG6E9Ff8>N9pF7*eW^_0;5p?jGSvwd znXN@GE!g$qfukFjR3+P8mfdvXw;w_T6J3p3F6+>-T`Vkq-KuY~zNV&R^e#khhfhGM zu(^A9=l9>)>0eU%^GfjiSjNr0o^P$Be01$6r#5K&sjRPw)We6mp$){auCG_DjcMlV zYPj!u{hby2v|j1=5dI*XN7U96aCbKYTs`>-ExiE#^*;JgU90}J+|9|}fy5%TeK$KJO9~dvo>QKk~U^>*VOf8mxo(H$3zN7^}T&0NT6L z3YWnrt}zYAyXF40nm617PEX&!+{!ixEovT)@^?+oOZShzl_(DcCT-hM#=9!@Sv z=zGQBti0js>~syBRo!S@Ll?!tLG?;h&j2$c|0Zn9AvCA53(pLW?!s`NNFNAIOO6jn zs|(3$&Pa%ad>+W7Y7359LwQ4cQ$38YhSuUr^Bq&f1dP z;^N}=>U=0iZf-8LQ2Eszr3JZpMdi75{rP$M9X;sNku?qIP@-O+ieh&D6v%097YBows%c#(SVQy7v5p2D!vF^klRzfHomXhjL*kW;gkG+Y8 z-u&&u13loZuBwJZ#Ab6q&d)1=Fi>qLg?{VgFTTEFX#_*T>MTFIfE2l(f2E_O?w(OYW+>$a^6=Uk z8RcN(L%qf0qZ5UF92j_W$C|9ItqT&9Y%in11;_&}=wlkuc31I!=|z^=V5YY2Z3#z4 z$6{}E!6ev2>nv93&gG(;)P4{gtD>ccb7r40C1~zKHzGci@=)si{H+WDOvos|J6Zpq z^|bWl?09!0E!{$6tp+W@zE^wG(k(Q<)ubhuhSvDg(%oQ;C|Y_n_pSQ?f+!_gdL(3R zVFV#bDrvv7w(yZrfq!8?pU1b~cZ|ahmDe>j4$TW~=j)qBaJiAfp>~+%&D`$EXehu+ zT|rfwTLTf*nxE)_7}ORq|CXuVA44 zT23$eewf-0q{SJ9tqPR$VNkUNsuh#hboVG@baWIS;q!2)FjA{9J|?{t_a!rU4yuPjo_@M2L$mrEd>op?fo1dRW%kCAJvG1 zZhiQXwvnYvRohTSY7j)}DEH=bN~kN1hc86c1)S2+aohRtF9VE}E!OVC*+byZrN)kRhW3dvfBoLt+UC=LE|d9Ur}dsyLtP>68ND?% zHKFxAI-W28L$s3NpTdxw*+Ip3c*4C?pw6QL5cu3y9%tBFcURXSzF@a?2d4u)eD@4I@Jc^`VVIyX9E8Rm z4CCSju|BT*kJ{|~z6$3VM|bD;^+QRxy^Rpz+`{z=TP;nTQe=L++|~3bnfle^-aFK0 zYAe}Et2^C_(^*p5UwHVncRqRRJ?w|x!4*&|gxZ42hhtRJ!PL7}``&x+SGdW6GtcfI z9qIA-Y}v})r(L&Q(EDornh)Op;PcNH4Ls!2^Ei8`$m!_o|9<`fyo_`B^kom{WBU?grH#O)MpO4-q3Bu#tQ7GjFa#wAYlvP26 zsjF)!oIYKW?svt;RYh4zT|+}zRrQR8kNu^S%1Wvlnp(;#3QEeV>Z+=$DoSe9hyDQ- zrCiqVc@^c#-YP9sO%)9VB^50?MAg9bjGCH~yoS2Eva$*Q4kdLpWfkSbvMd#OWi=Ib z4OJBd6*Wy2c~w> zi%Z#wVcyn;un8weXE65m_B#3|sv2i}98NXk@)cPkLk1W?Z0MDOE#YZflo_q`16`67FPbvV)f93`0XhU_(1$ob{V53MhF*Q9c7Kx_CV2P%uP;?QPIlwdt z7Z*%TO%D_#2B#KCL=sfA=}8m@dxHu(g?`X}LdjojxqEwiY3T(Z8SQj-cBUQoF*Vl5 z@2Q!IK$V2@3D0e#Jb}8*bV`6j0YPxwDCY}BAP|5}+)ZI&A*Ef>#l2we)h<(;B(UA8 zt6PU~yK8|{jMT#F>WR@fDs=8ZX_shXq@bU0ku_4=t*-s`Ztb@f;(ac3*A`DriFU0x zu601`)OIUBbv=WlI>clsG078&CpFH7PKygBi8y?c70)3Ij6*G>D&xBeVtN8jRnj2P z2~I*eXPN2gDIp(+=Amy=;%0K@?5X5*yM4xQEgr41Z%ecvW2g5_64T7<&23EtF##>d z3oYdf)vk$=7_fWt!i?>%9-4Q!y1GVf*~v5)GjADmLXM3kwdZ+(a48@Q?3t4I$f|+u zQBfPwCNfvpbX9(9bq^nWOm?gTdx}|_SCuZAN}3k3qpPY}t!bcdPEDc$IGC3dOfN=M zJ1MNZP=+#k24=KNS63J8kdTl&wJSKQ4a{xr8hfP}92}$sv<8hn!Gd19iXIl^3;E~* z5PC8fZ1nmMoGaj>_eWAMi6kE_sL`JPFLLp^PXULiuhPvoUA zFgOUMK^KN`0V)`jiVMGdj0gLO%1*u<69RDbR$3lTCwl?FIZaD1o4HdG0K+h_QHOO0 zGuq{w+5qOZc0pKH7HT0r-4(`UGOu5c1fRUZb}|*wmF7B5eZ}`7lqX-KrP(DTJW(Pd zbWa&W6W)-U7=Fbhw`ugknUgp{h$jb{%To*;t`S(ht!F7QRM8}w_H#GyWlz9>@r;=r z4_bX;hn}%HA*?%h*$9S_%-U>omsm?6B1$?ISCQEiXsXLFNU3kK`mGi6UK_UVQ%tPF;v0_5@zTKww?YZuzA%n z&?S@JbCL2;a|HzjUVpLq^@gO&Co?)E?54b{Dd?k_6cPzm*oG65F4{epn9(lEd6#wt z1OzY`jHSnJw6(Pr6cm7uM^LV9QkU{?SDjj{9ACIH{CCq?=?hOPA5+j!t7xr&H`D!E<|m}6wxc}P6MS;J!3QhMIZ?6YeYznpf1S` z;_TA%&pWq^5RFz5L|}3M3WFdHj|-}`!?KVN@d;>v*pozSFEKf8V(Hu-2z!A_52y6S zGvOd;{%O7a&UJ&5!AcBmadtr8CZ8q-2qM(xg2m~0CZDhnk5!a z<`M)S)NPWP-h+~S|L@bR+O&jAhJ>U_FqJD7iy2!X$X{~n50n8pME@JjpjL2F zLBKT8-@+wyeBDG%&fpBK?`hymtmE5nqU*P_P3PS_O1oZFpbU z!HGg7;wds7fC3>Aq#z}TNBNORXs1LnecN-^k%-7*lOol1A?Jh2BS8`8ZeR4{hSsWE zJW9J#Qc|G7`*?fU(9lp^TpaksB-N48h}vM?M>pJA-nO(fyZE^ViA9okmd*pYvnuD( z>Af)(LyB8gq1If~KG|O?qhUj|8M!@!eYf9sIgYPaSah(Fp>(K(BK7m1`fW4FFpASsd_ z&{0i|p1X|3iU?BQrp2NlC$r@;-lW%qao(W~Hube`R<7sROgl68$h1B3#TQ>NTW%b6 zF1{xJWpFJqR2E|zkVgjtVrEM9u!yLqopXstX;;v-pn-vbMaMJS+uNy+`QJG*jJ{|h zo*W$EkGBiy)@Qr$%eRX<_C7HnjG-DU+!K zL`8xRI5%i|78jp5oYhMuw0!!}`$7$k6W0(MeGazrkaSQAm#r8{;R&n|bx_;z>qvdrkki z=;e+K(b?5ZC>uMMI~{_lzPH9|E$>nl^V@9)H8Rw)G!?gdi$tQh);?-v7)mypFP9(N z$Pf*R9yDH(B4ze@ly=3$#DYD4ThQR(U`k3V$ljr7Z38HA*pEH(B#yK=Lrb%ZwdsY) z@zJ0C`S&1~rYY-g_%fgf|MtEAV}X0Bo>LpYY>yf@FJNtO9x>5hhEE$G+|e|I21dX6 z&2PYlsXP)SUH|^yC*UNSW0q-!|Lsq||IP3J0VSCBBC$TQ|@vS9Slql1r-buBGh}&H6Ep1At51seSM2hWOa0OXXylU#K3+{DD3WNxKc|ntyLbI_ zcV~9+JtIS{GoI1LM{kb|wf4fuaJ2l&NOuM`GHkEAKE*E`Y4)BN=_%`~Z{bh9^pRn5 z8=pim=2)zhkz1O8}KJkU#x46Pc4bc~nBk8fm%Dg^zI z3umO0^e30n(DaIQp-LltsTZP3k@6yVly*f%qASR2l%g37Mp{}L$k2D8SOk$`y7dtw z!=bLBR5wf7F^j;SSQ?&}h$jE``Tv14KQc&LX|rou_mMA`b%Pu0!rP0!-=aPo;rF#& zNM})SIVQ0WRM$7HjCxY{;x&yWEo{Z5(b;e~x5 z|M~BmG-V%EN0A1bm`pUFez{DK3y)}pFcL3(^08*Or-HI)x&EF7(WOIlFxhvxr?$R& zBg3$;@ZR3uB{JEaot@d)+2C{M$S~>h8IiD^J6QnfXGVr=SDMJa^&K@bbUA*6z^Z0@ z&G4$Nr1u7!Q#0BVHzl5Ob&49{6T@PmTNYm3I}sln0&}djTTZ#IUqOh*stK`uQrBLy z1V{*t#aZthK8Fe8_{ruLZpY2?tVDAI^Tg9~Fjk~8pBWjZ8SM~AShKHP9{V?d{+F{m zdiaE84(s%)T?Tt)uV~A;Y}+j6WMGUa6iL|J%_FW9bN$*U6JRjhg$78DavQ*I%?^jL zU!Oqum1>myYg=JtsBy{yh2CWCdF`9VR5aX@xpe))&B4>(Y&x~_REqUELNq)!)ipNS z2th9kTg_mwEqASWcbOebH;mlxm~`D587dsxCt(JQCr5Kx{nW@%FX!bq4L`P#p%f`| zhkLcFysY9*?V23rPja?3CN83!87-ryK3hfI3w#$7JZL{&IdFhELo zQn`Hkuy;y>((wa~Ny#*;t*1D4m+YAa?+aT_Uad~?YnmobojjOY!-TXeHy_}R!dz|m z;MVU%ME(BVXx`tG;ILys64 z?%KIad@B@2h85hqVoIjQ0?YER<~4&1BSZU3ew62#oB}9g}2;m=H};bLZ?$M8bv4;8zIo3@bTt`H zSwrueg5Ewt)G}UL#cfH-i14=1J{NHO1gIQD0A@yp1vb0KiJ{rou4tvTGb2NT1kSM~ z$4n0&xU6#6dFOY;U^G24oNDUeN_-kH7#Sw@VsW)-WN5T+4cP5@*I{JXEu2`clR%9O z)zwVEA4Z19{`P4_j0?!h*4GVU1`aJeM2`$5UBaolN#4tx)xgNm_@s%)w*7xS91?bJ zJ@}YgU8RCZRqAVEPafR%_DGLEHq6WKXSd?xmr`5Kg;fh*_B|*+(0APlgD;U9shJCA zV4MKcPnto}9+)5o#)yGQf-#AL7^DGz2KZ0B@KbkyPk_0fM`_p9tgDt6;#_lZGlOf! zK2=M+i1L21VS)sNIcqYzknLTL3VFVUa497`b49LYgzQ!E$^ha(G?Cm!XjBoEgM?lI z@{DdG%u~b=Ik$28U?37)YKf&@L>(>ySvi@=?-AQo5qV9>S;3GLH&14cp-t>fAQS>` zZ+CV~(KNCXn#5&&BK0V%dFpK6e8r44C_Qly*g=m!DI1cS#&Hl)s`MR0p|4l4q??B$2_9 z=;jeiuMyu}MKwBij7An+s-@SFGoc6-51hfV#MeHANfGkQ93)alkO10sElXTpkK*j` z6$O_N>&R4Jc@sCegnl7$tqKL5_LG1Ugt&%jutB?y6r!U!``QJYUVfFRY$U=8bTEH{b8;%z$>iRq#6Bqxc4xTY-|c0JCk zQ>m$`mlaooQ*FP_Mm1;6KP>~fCDCE_S2a#;I2B1gBz`B2E%!c_t8?BiIqL4)5vS2U z&OqG>wdXbTC{5Jq&2#xaLqJ;)#O57 zoq_7eF$qdPb2a(fz2{f{ai!+c<2T(eM(FHhl=#f@)#RLO9t69%VIXm$&K{hHZ8L{C z{Ei+*KqGolL4c#_z`(%Sb!XMy+(WGy8u?@@*~UXqW$)mXpd@Zf<3NAnbXQL zYTM-!T!?Oo+@T*hSn7Lv-aAQGE>iay@?A&an;GuHoFCaQN(XN~T8St~niy;GDV zUDU2yMwe~dR+n8}w$WwVwr#tr%eHOXwr%bF{ z#lmG@Qh;`C0JhTO!g&Y_-T+}8pLz!vr=Fh*Mhl!QG!r=j0Unki^D3-ZY~0L&s<;bN ztvx+Qhl&8yd+=sVdpWB6n;i{_XBD25pe?7@bX_c;eggzuKqfBC$E`VW|59fziv^xK zy%9_|uR|MWf8@YkdvT-D`no8V4FKikD~smlpbr88U;I^;um#X$%ExCFQ_PCUR{w=AG8 zHr}_`S$c>^SRCrhf5n-sRBv4veR@P5G+S%#ERV3mP+>eT@yd4;Nu+-S1qDs6q9QC+ z&&?^&hvci78I1P6B4%kv!9a);O!wQvL!LO;qyEa-9Xj}H6*bXk$0yk@ST@JauD~c6 zobZ=(a!(#PYs3p#9$pUQ|9`5F`t3NkzNIeyAbq&dPC*Qa_kW+kAv}6FAf{SvaDWL; z9>5M8rGW1GPO9g?q+1E0hC1o^p`FO zBmxqIC3>g<_sw#PBAtanCo-ls_qSA8aThRc&ZY;`8wzgAe{ZY09ZrJ2cbZI0DTnSv zeS4djltgB!T_~Yr%WLLKinv>hq!M8<&^@I&JCos2a;PyZw__3}uAWw^Wy&2zpQnKN z1Xw28Rp-DL_Y!wYz`DT8YvI?0!0p`~*6G=3nOPS$@&f-NAJ68zVpc|)iXe5Wa)&O^ zsT8W?7!Ujlsr%XSpEeS@7_0Yy1q4eBFn*-z>TN(@!p+>kkA?O8x1&XmgD&U-cz{X#DQ{u-CbRuAo>x_QZ)h2siAI* zASl{>!gv&nM$0FqmiYiGh<<(4EtI za&oe$l;Sb9mjkd4VXxr+fe`*QK%kiW$w=rcBEeQmiwg<8ua6iT3+)bqdlGZYcs&Xx z*Nbxh#*-Ckf^_=f7e_$q-zk3(b${|8XbwgK0tN90XfFUsn=`rg2)t-$)%Z{6} z=K?v~mnaO63<9f>_MW2_32|pu!368%*3|sD3SA&!Vg&lIzu)tLnj|kzB{oe0z(}Di z>j(i?#(v(eMSjwb-;v}>E!-Q+pj*4F@!E^O{Zlx@Wdv$KO#DLF}NstfcR9LHZ_{Ez1ioUA5ZPiFSQ z!9{+#@7Nt&4{smUdlfY$l(4rezNvlmV=kPRRvddo_aUFEg5$l_6kS6pwNZ<<`Y8(T zEusv-Q=M)@+Kn_bE{x=ojv>2O)4_yuNna21n3}>gQcz;VaPH@h;stL-6sw%>0`Fm& zFVHWI@V%UBS(QMQr?0o_YMb4lLQ^A~4HoT#%$P7)BQ(+?Z{pxrIj(H-aPOCO~zDx``@ zAHT@)KCRu|TVX8`CiuM_d@OfB>^&8v2+}Wb?N!7tjm?ePHLHfM2eXmbXo|(^kl_@_ zXC28%S$V!0S%E5f%Ur6fR)k>p5wkNc6ydMe^0LI9MifS^w!{>CoEMMoXR$@gDLacm zb~;`>H)ltFIzEi+tUsFxW%~GJBoc5%tzS?BTMu!bD#5U=D~U$rV{%CBnNrYlH9F8P zAzfVGx!%ufbvxb@SEWF}pE3x(b-r_wLo=}mD#h}Act@#fHhgv(_D|PBK zb2U?HQB}RiajrFLElei_;9(+d8QPz(hQ0YRDEQM~@XatkgI=9R7^Yg)T>4NTW zEe-fRT&1*Hzfbh4m)DDC4jKnBnrObYHkiSgt*GEdZ{x%$ zljrH6GjAML8E9@k<1NmaupQHXzDlvDgyz7O2KqaxsdC8KY^mj*4u4;4#mZIkJ3r4x zG~HBRMX_o&URsXk+u5BKqEw@w@x~=5sliVxS*no}S5!B`XGOCmC;gBBp|ywR>_IlW zw47a;6&H5^M;8=peg0KtEXEQ`yn-ys26jqNyu2@m7%xe@QxE(DJS_CWup_RbkG4wp z#Fq4MW_ER2SWHn;^#F`VkUExEJOXhHo&*F(oJcb|&5)nP))E8>5|1VAq^`N{NtH`b z)LtE&a&1`JlbNCm%hKe_@7x3+N`iR0T($rO6+DG7nEOu6!Gl|fgbh2;hKqKXW^CIy z{`RA^;BZk1^72f8Tu{R_w6fDc3bJDQ7XjzvEO(z%X=(0BvI+sogJW1BO^xTVL#>8H z+vQ9*&)Zr&YKbF=jk%?$UqgeVa5I7k{TUTFT@%%biI8u4>QpZR&N>pg-VB=@>8 zYhIzBp@zC`eMZ)L*%U;{G-etYx^L5^4qwB{XkT$-9m0)mN@61S+jUN+55^Z;(<_|5 ztn73g^}-Kwj7k&iErThG6Yf>PM#h7uybZesXua*t_^(>OYTBpv9<61@VQkvt+q&sV zo2(M-MQHET<#(lT(Pg&~G_iUl+?1W-8!165dA1NeMPoin2 zpivC+Ebzq^mbIn<9?wwhY{~VT%*a?dAFV5kh#etoE?uJ*4TWOys$=mlB**$Ue38=JWi3Qs^G_$VIWW{z z&}g=VDXpQF+_$@o`y?6%9(XC?ZT!c=dGlr%r4*j7BW#gMWIxdrmyV2ZrUX}EOw^7SisGJL_PM|Tn0Y?BUB2X?4>sho6H?C z*(q}l>;}y?Y;(NxI@YD-^{DV(_NfcZFqdn*1{|OsF>RToR}z@ zYYrW394rH5&oF5}ZyjR~K9tTqjbg3aYp-Z>Gm}5y@nab-b_%PdPRK;ZW0Oi&=rt3F zMaPBXEK*Ua7=D$x{E5FWa09u*CLnRir_757SW)ManO$OoI)s;GN3l$1lX^VC%7QiTg%6{)#UVu(q$*_jp z8Jw@HIj88=7eec%7CfD~0H8B)K8py9zGfMr)NsHxS!z@27&N$>y=8nl`w%zBcvRMC zTf>}2Dd6CK)rYN;(Pb+6LXEE+!t42{H%FPP=lI}c@*kb?lS z^8KrB;a@0+4F@d$Tjo%%*ZtYF@6UsU$>cu6qS}}3_L*gL2KSQ_+^1~y&w62S)5)kV z?1je_LCs4s*Oc!`^fGcRs42+6WUQ}U|HEW*q*i4_z%-s}Q@GGj8h=mKqT^Gi>#EhX z_yhmGLz{d8AV~DMU)c^#m07WW6uuEOU^}khZZ9zRo;apQVlV*2%HH4GpOfuGpxllc zA5q|X)|Juq9@c^W0AG%Y@2iQK?scFw5CGryaH98v6=cTk4F0i*mrG|y^YC%A0?E$c z-BO-8azp{msOn~!d08h6J%q=Z^0X7%9j8-&ws3>i(NI0@d4WjE^ZK;GVWE*b^#e2x zQA`chaJ07s$i-kVvc9jo-p0H+r)?m9p20H7U|0zq3`9vd*|s&+4ocpZ&ZqKCG5}6i z6pf+f4?A&pctDTivg%bbgj@GHev;b*Eh0XR) zcZb8Joq#dUG(Mn85`5PTk=ye!Tz&)tsB-{Fyah-G%rqUnuFJxl@5LYb?bCk^u7wHF z-=;XWcHm2A*LBk#H$4yJm%D53w%1K^$x6vEqgLGCTg*GMStD2>!h7zD#|tmpL7IVC z>0MR3hOI^`1U}!P$Fwbb@0Tw-JG1T!E+xT4mn%w+QXP!5^w5Hg>B9D+RnW#!;*%Y2 zv#v)+$MzIrt0*X#(-_jQw;ih}hJ_$j+O((QvB-BpJiwunZWMVsjgRNEy2qkYGtg2n zi?}@Si#lNpcuh5nW@ki$?pky6G{KoX9!gg*NAOqJgdg-`ZYDY+vMYtEY{SE1j`fc2 zUeZ^wIIluP!z1EBBp~-p%6uO2lP2VG-fmp);pRKLskCNkTf&iprhD{}VcV6J~f z5DJtCzVVRH*3QlI?yezpq{5Dr&%*V&BbcG)ppqy0T>pj0q&wZt6$i~mbG}&kf@Ov< zKNFO1DVoZAKE{4qX`Y8q5FEbJ;(0o@y|ER3*dqv<+Q)UK?q;ca{^>3W!fa?rvg1eK z?&O!bUZjU6(uaf7l`6ZRF!Kp=fgTYbsb`5iLZz?zn)u!I6-xUU-DR|d=|-J8;y`D` zd1I@xnX)n2&g9sEQS{sR%FAhKdpKbC^BrWC{$V!4c%(8xl6r3HZ|JhqaDn*gCyn}a zDlE#C%Gc-TCyG>`xcLY0EIlU1o|}`J@xMBx_POiUN?lzR@#Vpd!QV&ATY5}zZ)%@9 zl^$+g&Gg->#a6~87w6p1?;}S!Fd{AKLLt|0Y$a1V>mL(e%$htpS-lMa%ck514Rmzh zrHQIw(1Z46nmV*RonJRs3)^)I4D6wjt74}fX2)=E`Pq{35hs4F6#N%11rnj`Xg2vKVNxnQbnm8Q% zl?FL)Gz9gS7VV{bdT@y~zh-K@gC4VJo;*$Vbab?-ZEC7}p0jPX=c{nGDQ(+0}O`t&5T%(TwjaX?u!q9}oZLiut6a@7oD1gZ`F=Vk?i{{>d zDN;K=H!aJ<&*e`Ixm5hUNbhJIa?y*0MEreL{QrBh{r}9o|IeFR4PRgVod`4 zegw1Bh=^bA>6jJO7OhHvQd9hWpr6ZDcLr@dECPa5lT<{~$pG)VC@(K`KcLv!ckJJC zRKmR4Sxqi~W^Zoo%z|Hq(ZRaH})3;b6y@E%+!zb^ipi#pJ@$NoW9jRX&4DG`wKI&iLVb^1TH-)G69x9pKizLD;7R(n?oD(!KO*6(yx0gQYa z(LDZS&dqO~THj>t6)lf=C{zQoh{%#TdMd>t9(cv81mYu6`xV~%mPRRBbbif_)d@9xkx_{DH={5f8@$4PE_prN8@I! z=`IJrn}FlowT!(=pW6DGsS|tmQQ19u+?B1BG}L?*l*Suu-}NcK&B0e4w4(Q|ljW`y z@TnVYyUs?>7-lLaHrgHaYy%-v$HL04-3ut70_6Zu+dpWKBD`IDngeZ5tV%yWza*D! z^N&m~`URSNuY=;we?ZQ#7v=r#YFRqfMvSf6)ipOu{o~}TYe3?U8suHps=?sFjHt1r zmN(Q<%Z$RgS6XdW$tk|ofUYGG&CX%v$wwVA75^wgr@hR&D{quQm5T2>|Jrs4&d*CK zf;j_~;z$aD*Y4m)N!E?9svecw;<4yJ>R8XRySIi5@3Daz<4VBa-BoKY;qrE(!C>V@W4!DpbOrJnaQ7#R zY4T8*7AZ4s*9u~pxHr`Dy;YiBFe<8n5xt=&^RAUZ6m~n?x6_gZJR8{0vR1}GoW|{iRO3TZEpd}D~2fZsOswk-` z0<2;?j%2v8{Ij*WagbFW(cT^rk-%&vDG2?jp&^QOuM)VJVmcFGGQYa9 zq1J>(2Cf5!la+2hwqDZ6&D`1d+SBZ@#6Oq&gO1Y@BUR+vQl>hHCOMT*mc{Ad7 zAamxgj}F=KoWG81Cc1aaE-~@IT-Wq2(e8qUTW{l~js?onqQY05CtTha5Aes>YH}79 z;^}8(9=};rNtd6U9ud7#^Q1dw<)vz7JM-bE20|;d6J?_5*EKTMPsgcB%R{x9dhl_p z%Uq_%KFhnq0Scz_n5M3_fAM2yO4!)gDf-2=z$h(g6Btnd6Nho3$yo>$l?G6{MA{{6 zMQ;IkSEgbfK$PM36PjCR+YD@!5>(I?)gYl?ZE*T~n{;Q~S<^o_-qOJ1Bq5~!W+dj( zrlr?uqhC27(R2)lCio&^3K}Q`hoZNoUqMAy?TFrVS{b`LN}^w!eq;B;Nck{@C8?D{LN$AWi8s5qWwDAqAv zGoC;qOvc(1aEBwEYXzFX!_dDdr2u$-{3EI$EGn#kHS7fNsQ48zYn^|FhCLV$aV-0H zRv8*@Zgvv-t1nAZ1Ir4ok!t?H1&lQ{5ICQibIuOQAOVHRn9SIDwLK%D9$ET{P+11a z#KxkQjWXnS#(LSQ_B`Nr4g#STzK-LX5K;xR_f4kg?x`w98G zpfwx(jdMxQ%q-Le4e>JD!h`#sHM`*xU@!%vVgNZ`RrKawl_wcJNl6Fx02rx(r)!Q+ zm;&Ul^VLb^M2w9tWMpJ>H79PeQ9Hm_PultoYk-tdnBbq50NfM6_gS9-hZ2@<3K$Fo z81VY9qy%98S6VTQI%_{=rY5uol-AK`X;F|Z>5edTl-7Xbx@Bqt*izK0k#Xb=wua_^`mx`1qJ+tC|$`xw=Jb_QLi&dkM2mJlYIxPNBO zsczKm2vn!OIk(2fMCadi_Xvj^IV_628gEWXmSq3Sijw_40FSgc^wCG5)9mWr(NUrd zA3!}TENot!?W3xME6GZBWc{Heh;V^dW-B1#9i=LdO3-7CU9LXe*JX4yUuk7TFGg{i z7**GqxWK7-yrF`3=u|bb_{#EZHVvJxcAQX?3Y)9FHW${JYFveJP_x13ZLC08v~qY1 zJ03e5tG?pqfPt>tHa7+hJcLFfBAO2~7i?5>Na`}xwlAB*f)irRqpm@)fIeZc9t9Qm z$8CraAwIhdI=0FZt*hKa?4F^gS>x^Sab-yk7dOG2lhq3|Yv+33 z8%X5T2>wl`EU+YHv=!*DI*iH_j^881$kJ-MjlB7nR?K{_3px}Za}7+~sVgQX#xs{! zUXh_kyTP`KumH>iI*7E$;Lxwa#BqMW17`EM;Ll2 zFQYw{xcq{da^QsARzs4BwZwOkthy2B%}^IA@dBOWj$({1+PewB-Ug1eQ6qqb#aoNHlhLv{RIIItrp zNa{&Bvp?I{$Ae0cCKGh%@QX98(HaHZ2=VbqoH#dg)w`AKj0_grWMab1>$AEuXp$Xb zp`mTKF>VomWs#M@`m(c*VPzQqibD$ttj}uM3*wWLyCs;jE+_bf$iNBu3V;{h9S)Lm z{v8B=6I8HGby;q_SoSaAK=4)*H-&V|1BpqzxkipfR!Ruhk2gx#X2^p6_{~P>_lk^3 zGmq5;q}%AiizLT;6Vd)xT8eZ!RoUzeD{ZbC>w2-;FUo|mrOEO#Ibh5vU`jla~N-O9ULszF=!EMth0eFUon6 z#tDulVAv`hfVDg#tUkb$1s@;(g*3CHmr|10AB*qtj|6HUjELDcG@_tT4Lop*8TOk5 z!1+jssyA5o7>bznV;4pS=~qbQs6Un_6ww2D%bkM&Hy9aVWS~nVYY{7)H&&Zv(Svcy zUCA^_W8{6CR7ZV-V{0dq&V^N)3I{7|FKS!_7^U{F!s5_4@PVo|NSsPU>8RALFglS; z+Z!uR<9{@#)9r`X&?I~}`{b6^Bw2*0Q`17FJxWl5wKA2J0aB#uIk4>5e2H6`_s8!`Q zP_a-zISVgv^s+3{AWnDbra2&q$ZCC13brOk|E`=P4jEtDN}kO(eqG(b=e^qlRtmEl z`+|T454`x8uwyM#h%z&D-6E7bqAlHh%m=o1#;Hs5yq~d@cWHpGX++`0n$~P^GMs>0 z2@LJd4am;8431cD(kBswoyzP18h3w<%vOE`_{=ji6Fon&IgVTXy!3pd*biSq2m_&k z1v3O_v=m96IWGLsjeMrIULessWUUv{W-!+yfRg{{=Pg_jeF(e5eu{s$3}p?V$L9;r z-|{u@)%B|)n3H84kyiUnr_&yFUn2kc^lQPW`P<%7js&agmc4<&NY#c@OJ)j!g-^KaRQx4@zMjeGub~6c)=zRw>tM)Eg zi9&=dFG8UzkdBxy$iOg2ibjE!Si5RbrfQ#oeqH$JyB`VZ56U3+7Z?GJAx8~u0Y@Mv z9T_8E#Ukm*06O;h#G9egf$#uWyyAvogEYgAC(3EAk;P|1G5Fje3%Ds|;}Lo!lYutP zD#E=XVvvf4YnU$(Ha9ZcA$f>pTcyqjz2&z#ufsHQt-HgkxZTEmO&9&W?Rqx1R;(m7|e03J#8B$qo1 z&lTGzpsU}GeCLv@G8?~>{+6=NM*D_zylcQQ$TwHTti{ZN!+FO$O2 z_aPGL6{oQTIzlcC1v@IeAAZr(f|$zH=?#jq{B}ckZ*-A~hTSRF(bv~^cXy|wqXRHR zX4K3l@nOSrrO-@$XaV)|(ntkoNuBiLz=p)|o~Zw{jDV!+^-H0`+>Iph3BICa=cS@R z4gda0JCLx|BhOP)zF~?+nSD^~^-~qdHGO5pKIr?4Fx8iXvNNMpOhy$uQrJ{cG5Ab> z<$)$hLF7zdkp4>(+HY)>&bQIeU&JW>0vL)J8!P)VFHVF!4_86}S(D4n92PXh zY9g-q-#Fi@vr3!c z>F9{Zz+u$9R_1pYJhkZQO<1GDQh2w0(u9M-Pze!mYqcpt45gu&RUyUJeBAp1z0;R> zlrU^<~T2>C0TtJATy?r}k@I7N_(NEW1zt{U(Z;q3H z_c{U>ZQ}oY$Jj;q(+i*U^NsPrqrDL}fqxCYLDx0nQ4CCU768q}32ww7(ym2r>7>|MSMM`AiA+vQK$j#U@F0hbGOf^k#kCm9pWZkG*8lXgznw!45@TnPTmrto}{+QXIoxQZk46Ep3xl~`hiL6OJD+$*p(90-jvb*9U(EMlb3$EK#vQ+62=S)}N>f9&g6T@a$k zz+`5}<)VMJH&l~%Xb0Seu_F=TX5^rgEyf18z0=Zgn;XvJnw$!^-so zP0}(F6hzCRG^f8V^~#3{Q&FF)kcHUtUH|T|41u~EELEp9VbA-3wLFj)-ZiWiLrl+d zu#E$qJ}s00+w(mItsO~A4pa)#Ki{$p`O24<`G$MU$hXV-`kJ%M(=nYgyb5S2Wg7tP z$gX7g{Xwc)-ud*^+=CZdse7HFpE#nhYFP>si;Lc9BkcY>_{fPT2C_b6BelY3V0fK^ zRM8Qj$r9DXDF-=29J@>(FX5ExQe0G2R8q3CvZB|4?li-Ex(T-BCk~B#nKMzAj0X7W zq!FW`5={UxbmvyzeW3zYRRSpVF}pEe?b~qz0|P@tLjx?9ly7mxX^An`=E_;;nLM`S zn0Xhj`UMn-1z&~}iAB;ve5n+3VC4Sk0AiW;cG_^URhsM3$w_3;nKJ3_$^@MG8BuG~ zLcbO9F*`=T$j(RP#Slu6Q9*ap6UNWWiNEAYjq8Me0UooBJ7il7wo{iH%CM z{(Edsr3kbs1|@V8rEli7=gRnB6Yx2F`x|7~%n2@oG*>vgS%LS4rxMEl8L+lL1@OuiK26VTpH>RVoOf44~@CVxbVF-KpsZ0;=` zUKnko-vm^*x#VL2x4!C-K%pmg&eYbGpjmAQr3|%X47wTGTM={8RO_&B=zn*xJqPqP zKg3t@;?X7RyiR89nQ>9~h&U+maAi!KbF6d=M7dV{*aMJM09u>&Xppw%+ij;HQ#r7% zvg487wf$o)QG2K~{FylJXYTISW=3#Hf08x&e5o4!=YG@we*knq zXaiM~3?0Ena*cy8GKgS_bLhrM7bXaW!#GFAoGqDSrX`IsYc-7c-TBheg)yU#1#A?@ zk4=vd)#?r!T4)*JFoMA(ClkoG+A&X{1cx%xVwlEESd%B@EfHze$Npz zW@@r*`m8<_#8>FJ&3$ulSbc4%j-DS?W2vsK+3!gW7GO zHN#Z6D-`cTb|uRYK!42XmiFFg9b89MNXWq0xHvcWho;U1O5PHC_AIJ!L$}Nmss!xd zz}fi}neo-XJz7>Kf-G?m>PdjvnLjDXQ=?NNHKhoE#s1T&!C#bt{Tt5#qdBo8#Wd5l?-MJgHpi13nA zQIEStOhtO=BQcurJck;wRN5o7-Lb}siV7GE=`7b7Yg^ly$;lvh476}Wx#=Basfib0 zLy0FcH+jhERDL_W`lo^>X?BwXLQUNQe}GK&y{5<})5 z;TQF1V~=L%qv(7cFR1-7ch8#M%lG01{8$rt+s+4t8aIpWPWOd_{uw?Yj>1X1`&6?j z`JYy{Bd>6tbQk{=r)Svmj2&8P>I@AQo@UE0I0W9W-S#TW*t1sDZ1u)D-S4!^;h9)` z-iSY82ca(%tyuWYQ%=?-E;d|7cq+bDH+7<+I%S)BoCd@$R`2qELvt%cb!tJ~7EQ6_ zVq-fxz!8qQB%-B1}zu^);O~ z^6X5e>=;Kdz#7Y$Vp0!4F{0^_1IUwmd?0fgewBd5*xAX~U*_`FoVL0<-Kh2%(V2z$ zjwIFBrOSu}2dh2j%*2?e6a02Kq%>Pe&UVP=@J2;Tj!IyJd2o#DTWZ%&Ug?(8M`>?b|x+?sfKxnaDXVlL2F!;FKGLiW&2&}DXDC$<+ zs6%9{D=NdfWC=}HhGl(UBzl9GnaLoB>el}Ar+uogvi0lM(&r^ zz>(dL>=T_FqcURvwFtK9cHJ^npGyB!UGsikfh9wxtq-w(-^on+X=8@FsL%jBN_HA?+dsO%=5S!S&VX#N6pb^0$h0;X+p5TE>9qHE`b z5daF~K?x}g*;aITxRZ}1F%6`CA}GA#x zUPvBsp99<&$*=9W8}x)VQ9AMA0tgRf&!uHYTn*oPZ#lks$+L|cg^~x?|x3P z06NT;&UYbL2qx8|X$^t23bV&9fkZ?0)$u3AP@*{ieNn{ErC6>mV-i#=;~|rZXLc2^ z?0R&Q6zVQ@GjRe3X|jk4TEn&Ht#eu0QYXaSgeugHqhat8k-jxpr&wZ`BZ%X};MZ!pzj={UIeX zx!&m^2>7j}(>$gbU?;j)D-0QWvL!nqfRyIdpFr+qsD0=V0!odkjYoZSEnV z=AXovCYC_w=cFLtPr@iEJ$!9pe>5AFEMl9qhN1;>vp1Nm=1B7&(_-(jMloJ8WRtWO zWB;_k^O&N^hQ}dhv)RSHU38w8V`e&*+|^NAOx?ET9Js$|!_-_lOQ8m$a^x<_7pbyI zem((=U(NIgYTLt7#6UAS%WG^S&d71`vNgplUlTtkQW-e5Yh|YBnHZbe<|u(E8i=m% z-&of2;kVboKcZ*9R2i@opq+E`#mu7Lsot2z(vpMO=ds>{iIJ0cDpNMBiyCHRm84X@ zTF>tIdkVci-PCl0`qEhpPTNiD9z2+@$|F8@L>>~h6K24o^#Hogd}xgZExx5MT0_Nz z)qZDdlDr(i^g2slyi<8e{n)ivJwo;3)3*NfwN7(_HUn9#itJ2e=O%uEQ(kb{$)2QrQcB+aW>ZL_rqSRlRNp zq8ETAX8xEhrpf&!z4v52C#FR{)Rm_L;zQ?Fz&3DpOwPWiF>%~-xJasrtgbdg+GXM< z`VrA1tZj#TUj5$)#tdnU0Ea#cM|e+#db50w=QCaJ~G*YTyin+c@-T z{#QZ8xzv|NGi<8RfC#wb+~#_M(`y=RI)@ov#W$iy@SxZrEjB-r1}hzZ!aU!X;c)o* zeC(!bIft{6H8)=r`e|lZJ?8k8S?Yo7V+(SYQ3B!eXPfd7=c?#!*xmNsSF#yjk;~#U zQf=NxpoYQb_+ut}Is1V0L7+#akwA-JbCPCu2VwYaAz#5TXO93+PZ{{WU6xHJ!j^PO zbomVG`=S!ji=AEv|Kr#CEOJkbU{J@gnqW+rM`)B1&n}`a`OCG~8`y-(oLp3{ROeWY zW^zWfeb6O6U0be{L!qF z51!y7Dg`-RcEjd&xJzC!b30E-^bN6BLR*QxD9%>b`yeTwSIdXr$rKcsQ1@tQ^GfHs zI}ZA}9HE8NCrLO>#3>bqy&h8|X$Krm8F6ty5^a#{cv(YH{n2M|sE#Fdz$p>8s}sVv zC(Pmr?1BQUM)S+JNOou|aTgS#{x>4wJv9bHmzYsBNv;OF0~0dmdY+Cv(r!?Q-@V$5 z$n%h9fj^ahiqKPg(E8evPXh1VAWfA{c{uWe{M|4jsc=UdaWW?&rS7H3HD?)*1{jjA z)aGSe&K+GLNmjF)K63yVe<;X~T`(!^gt%Z$8lDdb+wDzH3isTy4s z-QPt}H&5qp%^k(OO;`kE*kSWVW;zT+Bg}MdlFPo=@M417VFP=PeEXl)xL**a8;Z6< z!)l~B0gaYxG6pJy_Xw7R$`fRhdsJ)$#7&@YelB=j5!mqZq;}W$9a~C*>wDK@lT7Pe znIzg!-^@gDTB1lh?GD-#|=49jmc9690 zjPToBk%Wz5=hOu0H&>7iIr6j#N;{$HT)ixLerj}-4ZA&iD5uo>PU2@9j?TPvB=juy zGv244i?Ok>in6kcvokn^E=mva%~ITbA*9Y2@l79)Fz*l7pY}P&(;^CQ6iDRjw(~aw z_xf&_f!gr9vCI0Da;f$JW^D5}V5eB=Fvzo;i79H0YHYyF+q~f%HT^1! z(*Jz?c~~SRq?*&j=h3~ynMX-Q^+xVE$wF0|%CP#L0zy<4aVttdHR;T{v>u{+iF=ct z=gK!Vd>C;9_Xt#Pt>|PA1#a8<=`#bvqYigyQVl!6f-zj=zVDpti%)np72M)X_776@X5Zni6bkXa zg*vk$-n$R*Sa|N2brd135$Nb?VxH#0Aec9jyUUFQps;`(E>eZ(eU8!4`-eAkQ*)P7 z8-Ig}^3p_(GNjJM+x572Jdn>J6RS=vFfcF~`LUqp{Cod7A8CbsUz=D-cIoKBxjd3j zbfI}o|Cnz8iuaMyt#6Hkyse9R8x7f>BG(Ht$uC&9PHf8*3hnU@dx)e|FM4B$)3M^e|87;C0q74C&ND;IX9i+nUX7np}RJf&Y_&h+6;A zWqCNAS!#A=u&!>>UUljA)-I!J&F;4cuIGa4`GMS)#?!#GXx7hJk(XnyjMnzB_ez9< zec!EsoCiOk2S(Wx8>FJUUeV~Dr7v}pE;qGd%pVi_BI6K@#~uaz}TUqrzm4}C_gnyY_gMxx?erAU2Vw8G z2~T5|n(a!>VuaMsu&EXDvN7?c+MRjMRtJ3puNFR}4&WJH2y_@gXx@ho$JuAGV|<$f_N>}6=1Q1ON4XKE5%OSl8Zk*Gq>E%w%~9ti5}e#x<85^RV|Q^ zp}N-}u-@?bFIeQTtVzp_aL*?DhALH6cJ*`le*L!WC?W?K+}2Z%bjs}Rlwa>3&+WUk zwk%@8FzrYd)0@ys8!O_LY5+U0R>3k55D;P#5)@?QqKE2S)U~p^il(`es3IP|Sy21y zUHmHt=NGZ{qwDKwgE~S?E3>n*QY-dMT_WqZTQ)p zn5hu_`J@qq2oVADSVm@CETmt-Ag?D6eSsqwP_H2PxeR%%2_q+h%zjC82){6H6|irC zP6Zw#eGua|py=Wc%>2k2z~kBi2$t!3Nw)R0RAm$BEk&c^(^|H#nO=Q(6y z$ql6fCzUs$`7-runE6amGO;tJqRgF>zPC;1E7cVb6@IY=0Y)S7jF!E+%F--zJ?4RN z+K9N2j*Di19x1{?HNeK*aku4XtHhgW`Dyc(vD@=Pmo7FaZoJ#kL9N+p zgKSq{4b^yQs)p><&E5_;&>j?n*`jwKjl_w6<5SxugpSa+g^(L)lLa0U<_OGqZ8HId+hJel7%q)*AfxD@q z#&$QwB|54%3@B6=;lSV(Ds`eiKd?_Qqzy%C6y+~&nr!qfQv;j~t+0sIzi$6o?gy;k|XY7RN zxc`G4{Jo#=EDkOeUTB~b92IVFpfCKeknAjL*botlup+&Hn4rDgVYL1v1+eig>HlRU zeYA>qJQMtO4|U0>89iKLhR5((8wC#;GHH<5!yl#GjRgvq8vd7W7{^D69tx`E?lrpj ze;)&`7OCa`03D~pWO_a)E*`%2s3DZR3LRIR+kCiBA_Au|DMC~MAz5Xo&u0KXWqsHNbzJ($A(MJ_X>v^VQCe~wF!Fm5ko9_0Dt;Hh72ACtMLf|T zkcMw(!`cWqgCoYm51*)^HDPvxBgn!55X!tk+m*O5VMc9uV?eC4Nn5Nm z9@ZzQh_9=Z497b*>+c0~7*1qrJ7xyk#?Xk5JmK6 znDHc9r?RC((a7LrtOre_pH!55aUM!GJo2YWYFy5ryUFtJ?(!2oa~NbHcM*LaBORBj z>awVnLB-_S=5W0juzu!ZlR>Jkoxaj{?Q2m+%u+P_3OhADu*HDEKmV%tu5*AY(QHGT zn?U*8WB>Gd36k|CXN3cv$9FqPnf|}CU<$BlECy(3-c53HNCRywS5W@@ZqwWAtDk&! z?m1328t$$Z=0#?FPJC*Lp1k%SaA3tN528Gn7ss(r!k0nc|J2nKTxnXJh*uucMe9$* zc`M=nEozGok7xVe0={+rq^IFD37!rBco_g*0^A9ZscKLSpgqv$H<L(y%1<#)yLv2~q!2vR7&ipdBOQO4 z%a<9E?M;^OF=QLXw-kpQEGZFOx;8P9rshT&(Eq5JHi5p7!^sq{-sb{#AmEf|NuY~F zqO~O;--JB_1%Bp_bxTK;XRCrv!$Yy+;lcLM8%6jq?*^po{Mn;^_hioMA ze@+c}ajBm-{pptn%&o19RrYmfUvH_JVD14uXGhG(UJy-^5V5qGgZekZ+cvLLA}}xd zm}n?*PM)0q#nU-PN7l4$JGO0SVoYpKY_ntAwkNhZv29xuPHeklPBO{Y_w%mx)xYjl zyLPSa+O?~$y3XSSJ2mnX8WX?yIB@;$gy@B*#WRNcDO6X3-l%A$5F6{5>1}8yppF|1=|tw zeg21EM`@K(lyRZ381vKPl{R9I9|(JZq|U+JuVcCIAq3-Xl4(SA+F;TWukL{y+!Tkx zjq7>ThV*^Gc9dr+6|MUqNhsEv~A-Oiepr49A z^L#@Gt@R!_dq+)_he6)pGKrZgbPg# z^76MTfB|eef39G_pYe%5>RFT6E&PGIM78{&^gRu!!;ue`%q<>Js1653)s968GBfP4 zo!W~>_t?EvZ^JiClYNzTy>_R*&3AQjHo4>pF`?k&CLMTF4@EPg)ZsR!PhFs?TjtKIFQXE8`C>^2Tuu2m+>LXg$KNEDH+Oz73Dv!$KYEei(b7z3Q^{;};*M<5v8gRtj*YxRZLxyP z*+SFgGrWDp#McQpwHHA8by;n2tOyLZ#eD>{rFj``OS>ag+2!<}ffzJGI>Zi@Hv#G@ zQKjN@INIEMi5s?V)Uw;nXQchFVgZ8-UV7$H7ClyoYvKwLIOv?4PY`_@W<7sV4V`(2 zV!}u!I(?%&J0Y592^N%{=DAVAGW+%Hnq2RS{CBV0lT^Tge1EI^gJ}vav5Z>W&{xjn zcsb|zLApQK!E*4YigE?!`ggOuEyqt)Qd3ApUwZtyfhj|-?!1C(OfP$U2uNpAm zqJBAcp(jF{%YL`#fY9G3l~s1W6+#r3H<^F#!Sgrf9{aMm2dI8dL5p>O?pYCzm`9R^ z!OHp*v+i@aiSe(8tjLoHkhx~hv-&(Ub2-B=1v3g$kA2hrUF{Y<2#WMB)}WngzeCU!Ow#wUNqpA;ZF~WoIw^AH66{Wuy zlwh3;3B-f?rGo{t93`1Eq>>*rZE;_;9t6(9c80DkBqZqop*nPhxH#yAC7G`%+@cCNht)Ie*7Ga+ofA+jXi6Y5iTwC2wqufEPa6k>Pp~O`rI=sn zmxT{lwvu{$oWDX3S^(Hhry%PZnN18gtK$7!7Y}ekSK9 zKL^Zm>m}H?(G#85vs@d`$`6Oo!(ej?V&Me%cs)tM3a#P!iT;-(%XhjG%_DtX)IsWq zIJmjxmAgOhg143G!SzG*--fvduIH_Wd|g(gW@cRgaBcIl-jEOZuH9iB;dzRfttvp~ z{3&-LcWh7BZ>;h<6{0A2KiIvxueZc?5||33dG`MF?#tnM5$ut5W}{C}u<}^Htf2)4 z{Oht@#?6sJ3shylf6~-Ow#E%`g)6h%d?r?^j*To5`W%?XP0fzFV zdWbTht#LI3tUAAk;W(kR0>XLqL>vGL^&;bx(`8lzR-3;l4T+tVMK3uB0^dtG$1l!y zY8}S9#ND;)O&izd0No`5QWnKGP1OfXAG-n%mp@r;cmEy#3jc=B z<7+jzN+{Y*=C+`9dh>w_s1Ee*)&iiW?5`-nd#NjxD70a8zbTv%a?WFrDRA_BI z18&Rpk2!5doG`Im{W&%K<)3I5n&a;uy>Hi*wS|DtH8POJ`M}GGzs+7&hXwz)*7$u+W^Y9)d--TbJI2jh!7oR`jB*$>0Pv z_qvz(WruxnL!{nEI0SaKwM#e0>KsR*Riow6sp=tm@cOc(0M3hydX(Czx$B~WPSS9- zm||B(V;>R$%v8W;@rhAQ%|jR1V_j0CV z?n>N+72gO$cZ$j$TlZZcc6Mic_O!Bs$$J9+?N+t-HmRr}gWpQal;vb^4=kTM^cU#N ziWdKB>W3kmxeK%m%9x*I^WbVVlJ9%3mH=fT|bax{Sz*$-Cu{vvZfX{V?*Lsq*g68 z9b@fP&Qk{EfBVMhyg&E9zcIP=e@%@JzeKdtVGR%RGEP#j%}k?GsOhNaW$1O`NBb=4 z;?9yt;m*ZY<5oFHiqFQ!TTKw0o~~`}vX7jkwYnY@QxYI1V;~Y3i}SnHD1CaySc?2m za&J@nu~W4>6FQ;k!he5p@8@r{7@mgeRH-l!5IkTvafcjVH}%`a#jVTb7=frDwI;Qy zt!OK{jgVx2`l|~~QHo}KAY`JXOZ53xM8Qx^M_NGlhA!S?&TeQsk9g0@vV3I7Sl$`Y z{RI)^`UK1q+h^_S>hkAy18cG_{)C3vux;OS{`5xH zQE@$6H+%Q+5V>F%RIG-3Mrg@H&zLzlf?-O@KgAAF{D=4@F9--)co>)MouMfwW61>z#hoCu!Y6Sc zceM&HY#R*tvOQa*Ez!sgB${oRUrPSHXB7n&B)q0PDu5yjG3%Qd=bd3s9nk8q_5*jj zsJPpRA<{K(m{7XXq0z13g5b&~P6Hxvp80TFDmO1Lj(dW1-S5YZSnj2a_ie`en^vi4 z8CeO}?Oh!s4NY^GJj>ccGRa>XwyTE~$N0|hvTT^NypPdU)&*G?Zm#Wwy53(kD?|%B zre~EUejlzaX>Iy${m{R=jb>r~C5TRm=vU7VFq3cF@mhiOCWQdpc;X0?+>hZ^rqS!O zlh_j+cXM@&y(J4sTZYT)K}H9;n6(V}?Dupe@+1`P2+w^?B&ND6uSw+NwtM!!0w?{IfH zUlYjl32`n0^3q@?*5Lr3FelTi%&MnN@p@+FF239-W`%IRmIk!;sio$g?M}25u@%lO zdlRTT4u3eU-%|cJXA{2K4zg?W&`b}1)iYER$$3?rk$9qVacDWSMFuN?Gqo2r$akuGw26x5nOz|mjJZ&GzCd^0S z;1WTfc*prm|EG>mFLyJ>qKAhBc}7&sSKJzRF;NyNk{x&?v#N?(`XJX{{F|($Z*XX* zDJDrqLeZwTy*MCvV|i%}30YX3utF5%7eq$N88&0Stc=1F63Qsh-vJ@!`Cf=Z9AP$3 zb$W8rrg6f##O=nRuCBEl^d;gi#6kY%4NXQ_)Dt{?jDwpofb&qzPj>pZ>F>^p?rmhS zsJ*DQuX{kC7QbD_R8?PHU(v6^=F+6OtC>j_bL3~yZ>+xHz^Tc}(rEBQOslsGgz4z$ zXxJ|PJ*e=Oy%GvkB%~vp)MebFcRal+z3%R=A^_Ca!979L)~*3+E!{|@a)Ytwz_ppt zeA#2`@^M-bjvxz5eO-$~VYz8xaZy#1O#?bH>_ks-BsekdkBCrlAlVVpq>jHm_HrC+ zA2baIIG~1nu7%BNw0bJqC~RFv4^9f~SF2XhZ)3OBZT;<~Xb06Ah8f%IQ;_f307{!D zG6$B{64olK4}Ya#$QA+uf*yk_IWmv&hvsTnRr>lS0yG$DV(``?pY*1->LmWz1m#Ot zZF7HR3qo#ZxVgKzx3WS*PD5zy?AS&G7v4azOH-teuP?caFM$6C3^>BdjvyHS+Rj`s zh3GEg26l>pd>(2jK!NkA);`X?g6fLgCSgG4nhk{?aYI5PqNTOgpOr#{`UuI@mr$-s z?{fOVmO-v)4Gp~I(#GfekFyKHUlh1FILN4vN7(76p#U;*V?IK9LOwh+1m0om^&NHL zd5BYzsviyHmQG?E19#sLJ5YwvH!@c zfx`ewnsLbV1jyL+;2E?^?V9~rF9Cr#hy60jqH9!q&l|?GXKIvShu>G^Pz@v=rQd%9j;X7a#NsX zpfQ%AANGN1{)bYsxNgDPxV1|kl5 z?mf6SD>JDd#%`y^5=Z9rpg)Iq_Rt2`M}@&Br>gDQ`upFouh12wNf0cLXUzTS)`}te z?y2ABPB+cljHz0PM;M6V>bJDW&c#|EM-!Db1S_BB_e3w&8|eyzKxH9&MI2H?0~;;-xSZYw`xw! zme@%7ZbE*hlxO%Vc>NafFG*8c!TK(F>*Mdz?WJFqCV_`KOwJG$c}Lp1|30{>O7fc9 zKZT*A+m!>-J*Bn@<9KlqDit2<{Z0}6GsHjn*#AQ=VMNIB6*bWJVNdaq&llksbs;4_ zXmrdp)d_W|uj?a!b7n?xc072R!Rxu*Vej8e7C_i(=`}a`oz(1CqLyU6UH}w?16}Cb zo+tPOy}+Q`#$H%lkpdOa3rZZ-%UpQ$t)ZLbP`I6_x8)KR?^?!TIPm?Pw_0W~X^ z1dCiCo>B?GPpHmYQn)fAOZ)pP9B`;du%4@whvfCOo?L_Y6lLx`MX@)cxH(y?ZZy2% z$&jT2pD2G!HzTmyh3sns_U1EVxUV?-TAwu0hF*s?~=CIL1S1fcW?ARap*h>92ga5GOn-d-T#5wbRD<_OCQD5Uz zthBp~Wb+TSmobL!jr4E`5qy8B|H?fvZF>z3bnVoy!W%8Zd7t&k74o;3tjq*$fAo%t zDVQf|c`WsCMtYmA;#R)-%dG>;RLpIKKg_=PH_7`tKgs|%_7~Eu`W?5f%1bOe{_o%1XsJGtY%ZUwJH;-lFZL9X`N6a*U zo(1Z!jTOopKY%X&*FyK1ivH-$&Lh*0`V5<^+OUa|X8z(({=l7&2$H(!;OJam>VnO` z8-$Ln<(X=Px({Q9hq4DAft^ts$~$PVsrGYPF|ZMx{4XSYwN5%367JpBACX_a)!p=$ z{f4AY8~#q08((`@Ma)Q~RkAwOZf;gqc+c$#%QQ4Jr#ALYB6O_RzhN(tOrGL(=tz0s z6xU>}Q~z*{KJay~Ub89jfk;`TOn?8ruYTcYkv^?AsTuYO8nV?*7WROt&9P@PQFKvn(a39t$ARVNz=H;5#(PJY*+WWVlPeB+7?kiK_?!ax7r2$Z+ zA(u_Cb*}G6Q0u>kCvGHM2cNH*z=rP2(>d{avp&Z6G=pT3&8rp_<fJBeE=M>;)Y^x$x9i9|s11pW_^$W>{ZS(m=bPac#BtX6j0`P6 zwrg@LN({r1(#gOYYej&%<7)Ur#=*1+1Sm!x;p7NoxpWnT#F4%f16HUJWFfLmEq6TZ zoxN*^$oa=jkZ$fqWcQ|`_h&v7Brv4U_Rpzfke@#Lz`!*DToUqHd;-c8Nf(-R9p8h1 zho7~xY zB4JltlXYJXxL45s@pY94ZGJJ3D**+tb3+V`Y`G1#4^ZhNPRoEZAVx zQ9;Kb_BbfHH&?Cepeo_z>lBJd1Icec!|Q?6W|f+$#Yw{K-%K_L(Z23l8uQc>=Lun25zjFd<7s3^GYMQs#B=Th}_`mD}Y@$%1~}u=igDK-*OPYw% zCd0rEnF@P{4LRw!cHwDnYaj{W4*pD7;gr2h4BuK!rOYzDx^`NFq%ViIUhaWc#}NhJ zI$det=eaS@v1qkyfWy%EeFr8NN-E@=eRRcz3xUfk4Z?5RvH8;FKM1&}OU%{LGR*EB zRRuJTvCqCV*PR~LXVeCyGF5n;#U711@`3$egO5--vt}-3I5?~Xw$XhZtlwqu%jfRa z1f=69jhnPt@w%~jEE<6egH(6`kAA!>QvdH~*R=g@;&$)A4mm03tO}gQ;{}SEw;dQ3 z;bQ~ajQB=#yLBTw=iR&;n+BbLfIfYcgh7i39(iUb|!Dk_hNdu3X9ZCVWu)A6sgNqP1 z-&&5Ypb6$K)zf&K$u6mQ>4#Mu7!+Zx_zwJE7uo0l(#Z$I<*m4Yo$5wxy4h`(J3nGi+`XwUD?|LiI-*-J&EK?#~4 z5{*wH^x<&v#6ywF&+xQ0VAB*Jl@Xm^WXb%qXo>8w^}YuYmqbqMr73)U3r(a+(zG%A0_E5qfRna9J7Pcaj1nh z8dNxKZlE0ni*HL*AIWOkF`h#Gsb8A;lZ|MX*%wW7zB68CK7Zo$ZU^d7zYI>=31bHG zdZP%I*VXlP6EPi(SH*{Y6a@O%cg6Hfi2^tUU2mZvHnsQk-`C;OYWWA@59=U=Ym@$V z2#vLF=q`mKdrHQ*)2&O`b5y5BUj^McucKk|MR#A>&h@npkE3fWMcLZx%gO@01Hury z!tnxHu_fL9Y2>r+Fhg+u}kcjy0Yzw?$Kk z)0Df*tV&r0o~?{JG8EQ6b5ZkplozZa_sqT z@g7n+X2wuNLkP({b6jzRayOZfnNiIHfi@cedw)v1ue!(!a%px&Oh%p1C@qmi|p&$)2UZbA^rmqW(e7t}cuH z(UxIpqvIPIJ|vBQEsK2T476Oq^yDm*t$4Sjm8Cb}i;-N`^Dy9XR~MHWUG*5htITh) z^TTOfvaWO#{=0HH@=Xa*p~Xp{8~t(od85HMQCOvWz}nRvE?Q1@xzn;__1tBCdGLF^ zMcX2m`T8H+T#thN@7183KfQH-eZO@3*8TgX}l)4qYTk@$orCt+yjxuQEGKgiiZozXZLeF+fywr`bm@ow~nDBcgB&32ZP z)X!T8Fd>}my?wCB@cM?8Fs-4b1v|Ic6x|)$9mTDDdk2<-oDJ*o_>bm*3&ucZU+RjA z+}p3SePi^{#>OV<2Za*L?&cEn5Q>PQm>ng#cgR~o>t&mxlFu7dVrxv;QJ}~QGe&YG zv`)9QGzrd&RySCaM^fSk>cobG*nI<;EiU}z@WH1IZs3K-jVHQCPz`{JYT(~;ox~1M zQ=jq*?7!>4nk=RNf8~(>YM>(i*NOn+|FzQ5zoB7Zp!na7z6L?petg(^Rs+y9M8xh# zC^5Ey;=-O)0QkGR3J;JI*39f|(>mkSQGyLFJpAO>kz(ug++4!{8ii8Fzw4fSed+Fy zbNqxf15%KClNC;F>3661#Yc(;CjYO}h`lYYI@2x9e?5nE-rRuBAK13ZI0UYU?Y=H} z-r8cv^a1Yolo9-QypGX~Vb|aq^TLjjz^Z=R+phlp{rjs15Nm(gE`{?{u+irG!hTlF zb3s!p-jq}5VZYnw@8lw_YcM)AbnwU3p)}wkG9Ev_LCn_n(=RzUwXPinctDrc0LL8lZy^JYCl$NwY9Q33tVQFG}IIxA7NkNZGEaP z-B`vlwZYg{pEwC?FH}M}&l)|i*=oP6bVnn|33S|@w7R^QW8dZ^ay1b4ja>oc8K`mb zOfGbC$uss~*7XOPP_+F!aND^%456axcfD5c{`T$G zGi9=yfQss62J}OD&n1Q(;qH~U%BiVg3WST1|8E#X6|69ebwl}mZrf;qN2=|7YZIpO zD>0wiq@nt94E-&2Iw<3(k@eb?-+G|JoRY1<-f@%2WbS5FL2G6d;(wNUJbJpKhNr(Q zewL$-3VHAjFc~Lq*zr)ed-p!_x;$d@MxfVnRNup)1gb1yr zY45TQ5L8@VX8fHl4YsKtb9?;G5n4>(u_**A=ZiZHTI>w%hK!mVlAaJw-H;k3n1#BQ z@W-xet@5mU%|iRjoKDI<_wKrvZ)oITVCgOUx`!1X;+f>nQ@#DRsKka% zwp%dwze`C#vHzqkt;mY<-W35>xu}P4xPKbzHANFT)B&QS&kl8Q(2v*M;zK+AS_Hew zF=#tsZM4GLhKB0^SHV;rPBZoK!2r;%m8r;Qd^)G!`>qz~n?SHGL07X$oaPSb8JvT( z$xxJU&(G?uWB%I|o7~Cm-=Za@m$8k8glv$x|8p|J?pCSxOvOvwxI}1nZkr_cbCyI1 z=9JQv@ZtfJ>4Tl;iedsgZSsMw2dbzj-$VYJZ3n~S?KLHbrkryGAnj7IQfs08O*()R z^dKk!eZKy^_>Ngs?*{ZY#5DblnTr={)-f)Ha<75-0KG^9ZU-Y7N=P1ywUxW~UcNpZ zXNtiKP%_|5g_gQnaaj4)~i zV8=%IM+S<<%RIkeKoHyS&YJseZ^1tzj|xmq8)a_&53~Hr-i01MlXWx+UWN3(5sjd1{=cb6If&jBwH2}J9xP*!pM@?-eM>kzaFQsH zAr|)Y!<)p>V8FN`h7POqK{ZM1UFGWC{K{u2iG778=nuwKaD*tAl%7uZ#DL?dkvO@T z)b@M!+RVN_@&gT{9T#Cpg}ge-OISfF)CY|2uXhfr1bk4(NgqbdEb6yF&+&G9uHrMCc(-)QqLlER1JjqZ@S zhbO!D(>7*KjUzYjmll<}1a^Q{jW+o5`7o+5)akKn_u%Qo_?aRxSpL}M&bEW$>r6B% z`5c3mAD)x{$G|vgnC6{ZJc$}&7hjrXpUnAKws3Ud<~PiZ+9q+%wX-YgQ@g`BORYMC zIs8kXuS3WKJgNjnP}gfcoY(YW+*kU1QpYW_&bu4B5F&8j@Ps|$1v5G4m3b!)zMoQN z<=!gh=S0xQJ&O$g)8B3#v8DL|gou$J5{wyUK~(8Bi98po)jwrt7*aGM#Tcx8NWqNhh9MEaaU+7?<%K>53@x< z1TeyhHp)ontAl1(7|G1QiYn2YTN-NW$%zSiIy#2wX}U>ChytRLJ5Avigd`LXf5S7xq9Am?TLo z1cc|$e^^*X!uJF#I~lcZM*Y#2EH-?9JLF{ZH4-K1=q9E`IlLvPd7&pzn&_verzfX# z(~{efUo_K%Ao;^SM1q<^i11n%ymts-f$1k$im)3B(`QnBIyJwSJj(h}uatmDDL zf71*D&$RFYw)aj%O}AQ#;PGNAB=P7blk^kT)>UFC^Zf;dmS)!%7dGZ4&>rG)Gz~eI z)tI6|rL`$BF){gN1Z&8QM1u~6b%iD7NDDP_tv`9F{wtow&d%sqHg0ZMKM?8GFt|(P zG$j>fRCI7QY%w21FZ}cr6LXWhe*J2bGfFLQ?E2{|lH8uACgP;1uWu3svb*7pfWJ4X z#X9C3f(Q)-i5f6J)KlY3Fq4OehQ#W^BLBi#P<@l~)}y605Q`3J|F{*$`;d~xZ*-`^tdM5y^;e0H{-0$qPW;~J1$0A&=>zEOxUydn?%Mvb z&7KbSuBwGvw`tRwV{iWi1Nai1@v6_YJI!g{@fc*QC0bSN838s@n`uiWX-6gI8prGx zT@S+oTae=ZH43Je*^tASt{4JGk0!97rT#w%O2MmG#+2z0rlVsd8=Qz5PC*|!`>N=v zvbLSOb@MDOfl=6ou%;$inxrrqRYCNqCiFkn08GST( z;P6N=94;gU3J4nmKbhB2>lWvs-+LZWR1^CvIXO3^DK)#PH?*&^G`u+HXW1hi9roof z2Lti+_Shq6HGURMHCNMcH8xcQ$$X*N6Z%u?gse5aOr6Y)PCXez^;K7AUP`)hhx7ds zO3G4W8=#GwtPI4q;*a*TbdeXV1yXBk2~$g{IM-7wb8~8Up#3(GWs=_Zl3x%1B1iZ9 zd_qPS;IW#RDB!NRKC7*usX4Tzp#%6IY zFvueB5oBFXnPmt!bJn!8@u!H=dJ2z^j%yg*4P-=hU_#7Vn1C}^3b`$uAj}#Q@Tj8N zP4whfZclbyZDnV8ao(V}j5#Gh2AYm~Q<=0frd)$b-yUh{>2ZdUk@2y0X}RT5Lqq-U zgW>FwkW9(mT|t{7rqr5eBys) zD{fOZW3Wtk*Kb%^QWRZM{46WIr-x`Frl%)4tYpjD++IA5y$P3vzNlQ2)h}5~^~VM! zB@LoY@m5&X78YKl0Fl7uMAfLf?CPMzT^dogvWJ`@@}S8^!Ud_1+XLP877Jgv10y7fWP0tVwvj6O)Aa`99itamxq^E#U-oWe_wm6cGyvX)?uP z}d5UP~eiDp56siJUl#tzg`nCKU|$%psQ0-D8u%_ zjbI(IAd;fKm|p`;D7Pd($U=KmCbr2TI*S13(wu!w%AvP zi;D|{xA5>VO7Apo$Nl<8y0*CvX)<099WWjrb|i#uDCr4vF*>vNB&N@~r`x~270e$g zfDje)GwevKq@h8X3WG^b%K_7UeJha}Bwt`BB`t{E<>vJiA(9t!F^pm<-b{*tOs}c= zeRWmSBhXMBK>D!k$y-U99(A8RTqGPANeb-LIt z#xiDV7t^w`=wAIHrCjtz2Kybq(a@Z`b*+is`-=JD|AX4c0KGhhhll_C`E!6Q?NsO- zY=X`&ogT!tf9GWaJECtpu(Y&fO_j6B?)n?RRgKO9MObU{#8P$U zD)6T1CFgpGE4G1`c%(^48c26m9h*tYBcJZ?$^6eZ-zZ$Lf2y)Df z@Eil2o#XqX;92cdI9RmN;KKZhoJ2=(nT#l2A^GH6v4@2DJCfg?Nh@a!<%=3S;qFml?u}QI7R*k7f!Kn zsxp?);x?m1lhaWWMf`=>0R};Zh4FW!_h@}x{^s`Aj%wh0i^1SW<`rTf0uu>&NRVC$ zVjFT#MMn>iNyI9#MD_RlueG@MmXRtMujLTHns=u&7Bk8BU!(G-mu8KJ=tqi+&>CWP z!=1Hm)TyYP-0lTNM!Rc|;1fIeM!0%3kLDFYguw zAmXx*q2Oq4Cgxs$mcQK?ubrljO!_V1JsM_eiAxqst-{;*uMoP<{%o5R5e76w?D#mV z&7cSXi0epP=%n^s%PT~a*_5t4Lvq=5yNw#oDW1|sAjMH1g;R#RkAVC8X9E%SHk>>w zlRo3>$6yFAvA0*o^P_*`(qhVBs!on=lcM$;(0jb_;3G2{&6PIidH zP(4pGn7&gx8HyLgK&fqGf4^h&bi^!_Dy4iF@@f8d+l8zytS{A~2zQi3sWr(~qOJtD z-=Q=$E+G(+4Uw+qC;JKW3%bg=bDn zoYUK9KYkHfX2t`L7aCJ^08nCU9HFPFY2kFMZs$6OBh&4C!Wb6fmKD*VL*tHd7jC+$ zSbz|68S4abwJ;lfKo;(r9_D83YL~anFSs~8MT|<5j+<-P92iUK*7+Ff8#(Z`DEa~u zZ1h<5s|5Xr5Zyl6UMx`gK1(w0S&y^$04k6nfF2+&E}ovAjszpFq=cF+HT2N7h^@BR zZg+380MCF7w-NLpT1J9|A z?YD!mf3+#*FqSpYF)>NHW9WHm&SUp%8_#V!s=8(9tbTf7WoUY4POb_H2R}aEB=+5l zQ#^9t+~l^QmJ}3-o?F~GmyoNBf0teoDRa7V zH1n3_53U+I2cuQ)&X`Rfnghr@QTI^qp(5Om#C)t*;m82MOl0g0|$1lvXz z7u22~!4vB)2l-Cjw*;6tiN&WxyMEUkkZ}sto~#Y}OPF#?I`(6G61Z;<*_U3*ioP^? zKjym&E^gh|AYw)r4kL$v_c9bYp?5u;l|A_kJ7?m$k0dH1{`~>h z(jshLDF{Lz?dNSj-q`8f1N6hZVZPoTBC8wM{*{=s9{vPh=K1&}2?80?o|LimD%|Z{ z^f4W5gBE1qTjLcBWYy;DTl9d{dPADFFnf?=3@8l^lGM}) z9_=rqE3<+NlU@nNKMy;ObPd_37DIyExCEEs}pG zGjrOxozBG7cr&SLWcrSm@%hIK8vDjp5PAZsNR;f=w6(xdo#?2+*QP70MdCIL?F^z&c>(L=mp2jZH+mU65_ge3 z;Xq@>296CJgdcwTy90b^_U5OgF@91_+2c2hoQ$lhPZ)ZEvC0!m{=R|KcZqsSPJiQ& zVR#RX!v8q(+`mNL!$?k7|G=v~`he-S9*j*( zO6S=D?wJ;6e72mIcn6``s=LlFOi=4^_tuwT8BQ;-F>zMwC_BMu7ji(LrQVQc-=wp}4LSA+* zb*eV~7*|5-_Z=mU|HKT>(*3LUmUzFZO^p3Gd=e6B+ZA|HfUOQqtn(vfm~;63@R3zP zf|R_h$~pF`BP_jU^e0ukAh#~ZyQhkjlmW$MCUf*`l$nOY=aqtSYt92f56%O*!eq8c z99Wy8o<>Uu&?mBOb^XrP;B=ljr2S8V&&OG99t@%E@({@K9-c7ck>@lSyaYvEb^WGp z=RD>dql#%Kw0!Mo<0*YFt+&2s%VH;yLR%E2Es zW`?K?T9*eT0Sn8I3;1nm-P{~~uFL6`q1mr%eirk`)!S-be~|e!=^Gzv%B%nA9HP}F zA}pq*otGZ1^6D7bqq`vICX~AsE#PnnzbfM*7#D4;s_AU=rL(8InSD|F%3(^BZ=HDI z#%10IpU9uH%UqrJvHI3$jS84P?d|_%z%igRC2Fw_$={;p2Db@ zv>M2|=6fDX2j^PJzBcwtOLkxiB&)zBlo#rlHqljvS%l6bNhsds*JzN~lBcG|MJp#; zr)=DQ%qf-oNBC40bT~+z`plrp8`rr9b#6l|eczzKf@1scUe5T2@OTG(MgrdRG~~`$3*r<=#z%cwBRX z5xhmclAT11={-C3mrE=8;S|vxg?q9vSxAcbELaNLy{aDlE1h*k-x^zOc@@2=o~{dMYKgBapAsItbRsL-`ntj@FS_=Iv-A3;ai982f=a+V zzxkyByH;9pH7E$^`MuVLZF5s7fm4Izth5HCG%;468$9WFBESCWXH{Qxj011cv8pdW zGR!D1Lf#UsierKX=)3ZhALLhJH2~Hvtf~uDGE&w%h8i=0)E?Ec(pB$2%Ek>mSV#=9 z;46=JaA)Z_of%P=ft1TrS_Hf3TO>X^h; zPa-o{HibF;)Wp=3<(nhM58;OcQyV8$O+Zg{%u-_IWO`2#;7WdqkYSG7FdZcuapf(qg+ zLiMLhlWGVA2)liE_SAVP_U?}(*6`58a(|aJOm!Ru&S_9Ta}PDceJV65R5Zdi;pu+L z*$k$H=H0v8v$2gU=ttw?TIcgct2SBcV^)pieBg<7brm`e704~Ew>{MqTRDp<$%;wp zN{&*c#YeU|ONg(EU;Xi+u}$Xo_s6P(8b{)}OkhW)0AMQAd8RT4&7BTQGl0(DBXm%n zQIfPM-v9ocx2H)qMELlbgcisc(seI}=eb{q`x7n)ZN?(BOd-m^5^x`atYT;NghQU_ zb<)xT4suxtbK-XPz5F(>#=(&RgMUvg;yI?QYgGe=FYy-o!C1I< zASfVHXe#-Ke<2uA;=!m8?@l$S--?8M1WiOP97!yUgyNtOVt9_-W#A3n*pJ7(15=R_ zAsp-4rQlY}B>0cJ$*GoMK-*+lgY7vV8M!yDK$M$CdBu)Gmoy3AJl~$=RvG#pG8IX~ z6&2F8*i=~LFKsV&pNBRuS*J~o%FWOrR%6LkyX#+W-b_jm#kilX>ox(p*uqctJ z;g7{lqTmM)_oh)+UT#Cs&H+dWFk}j#XxSv@V5oFP#^esaEUwqzzkgSjmVW=9b$@P- z7+dEcU}C3a|Mtydf4sR%CIEdNvZT}*TZka^8^%pCOYr7x1Zr#IfhNW*!*|tC(nlB^ z8`#mts4_Gxn9f9D-Fooc4#?nay;sO#D-%1i=ZOCKe^TfRRg!WBCbu{Qux&ce{;D07 zcq4&@93z%+GN?s=+k*+dwm;(m)_da*ViY)LxV%dIc57dME`R_j)Nhf%~4f=e9ypIMUPs%0GB@> zs?g51evLue3KxNuy!z-hAi>*iQDxN689gWevMsUEf_>9xyg|aavKP?f6g&mUlzDNH z&N~RPi)|aF(rD`PU6_>RSm|J6D{~%6i*Nkkwqv?BrRu7l?kV4dx)`5rah*9vI?0k+ zy?ZMZe@OC)=*)eSUO%k-2cf@J(VN$dSFOCCiW?Ev^bIG1p+`LC?;9HJ5e&iKXH)Im zi_V5R9UgXySYlrlV44UHHy$(IGANbTAGQ@e*V1r0|gysz*|_XQjIm z69Lyq!|Z{(6{#FiS0Ub*=l=YY_z|d*FRiR;w(7o|k>3a9AJldK%Qf_?ozy1pqov#tpB9zP&sr&@C@ntgtdgEb+F_Qs)QIiE;Mg4OmY%lXgEk>RCew<~O;H0N9K63S zm`t*<&(cMQIyAtrYZaCyKIi*%2?wBXTonJ4DT?1B*Uta8L7~Du!c6N}fLnvr#TfmL zi?}x;Fl+vp$*Q|R>;>CB*kd(l_@(_#`35}8hFX=Cl_+rqb%YYvEQVB5!DzKX#G=B4E%JAF($FT{6cogUcS_`vcz%&B$0PmSxtG_8W4YTiM2g8 zI$D|ZXf5YD8+JOPi6Cg>mW3JBhPOI>3x~i4#$7f0_O%>_Q1CEiD_BP7=X@TLOK1;^ zW&`{g(in}cn3G?vrUo8U`oh{5%4y3H~Ww;6YE zerjfd#hzj3GRy!cVoJApv(iGEUEG%kI4yT!0dDM}TPB}l=P1ErCkI*W>Cy|LZN|&2 zD}^Q}#uItB`68_i6G8U|;`$8-dVV%`(FtMvz;VveE0=pLu2f?YTPNEZF&0q=(8p z5T`}}L+#z5y$mHRvc3)G%DSLdrR^_mTdX<9Un_4IrAhmSAk1O<2(PGe3NL zJdZtpi#Fr6*{F5crcQ$)JR%}gw7LBG{@Ct<+`UC=>`lD%7Wr5~u6us`Qd%G{g=Nt* zQJ1Cf(?wf`dhKtlsS5%uN%`_*Y(r`1>uilchH)-_4vig<~z(PjSaa@|e! zSuuq7lyj0!AsNE2-S^TXXyw#{WVi=N^i?1S^LNHMmy9HkRe?>DPfKw+BYegI$jZ6> ztNw)LvdroxK3Jp1_eZOf<}T!3oa_R6a84+Ftr>g1!0AE~>#p#P932RR8D~!#w3yhr z+hMG@7!9K3Vo~YJggysO1Dw>+8l2=wXwJK}Tb_eCqDOi>03>#Q-7MF6y*6kDS>a!u zs?SC^E4Qiaa+pFkX>@bdUQ@F2DY2j_W3_zT??-;eRA`4{ZSf7%M$S>x-43`=9yV2W z=5=^DUN2oj`M&Hv5~wW~Gl)G|& z?vp>y+tVC^r;Bjk^+dI&crkB@XnAEGXN4Eu0yfm__|Kt5O-_~u!d33+vruBT`3B;a zb?Xsp9)AfJI&Uhszj%Lrrxt^1W1!;aR}@&=nBWs&Od9kGg&$yvk{_Toz}nr10kHuM z^W@*(LxMT4^Q?A&hhP7!;}7!gY9(|b;NalsFs&WIByY3&!_S(X-@_WapZc_Pf^B|D`UiVHx)hBh^DDnXa<+wKN1G?qJQago6b}b0Z_55o z3I`>2_P+6|!jpUy402OIdueOE@GSZtTfI07%M{)|HFbw{lQ|X>g`#ICntd>I4O(~u z?3CZf2g-c}u#M3*WUgm+Hp)Y~a=$h*Ho`MWQLJr#g*ikxPruVgNVLvJqAdy=LRwsb z?3kSLg->Fo>H_uc0V-4`o`fpo$tCVP*NL@HBb@!!KPqbcJU{op zE3Iqo4<$mW<$8+{_ZcbpKmuR!6S9O~U+$&!prRw)e%nq@XBoO*8T1u~i#* z{Wvhlz}_IG=H!^yX#&k62jK^R`3zVX&CUIyl%xz3lG3m%>yePkvMB!EaoTp9=0KZg zi?56_#zqd>FTUA)k!yQ{fm`wMZ!GkJ)E%5m6tDzSh-JOQK}T7_t~VS2^awWG0+U(^ zI$Z8$hB0rdg~11%+9s2f{9)w&Ui#|_aWAasrpl3cBG?Ex=p_>mtSjrTv5ummoe2M1 z{6H*EA<*L6p#0V|zphLHks#wwmzhOEz#7S}P2Q1JNu`2~*-0%$dIxioTVGuu4Lbdr zZ`Bs$)Dhc=e{l8N%J`{;xG3?OU}5cpXZdExg*swXp<&brwp9n=HBAv7IeLWWZ)+8X zb5E0J<&n5wTPy=iR7@6acA#@jhl1C3Ypq(0^@-CZLC#4_g*j^Dwy@mSY1_BK6HMq6 zip%CaSpp^8>qM_ZJpzHWuQ}$r>A!R)=SOPGrkrU1r1kr1fNw(@)&)oqH!#f5{Q6*# zPCW{b)%df~c(M5*UuP0(s3K=myM^79IZNtQy68gZH24hD7FEcM$oSE z@#_{BAgLhk#$aH~Y~{JDlyUb5@tu8}N8Y${p`X9GY1BymP>6!rnruSGcJnMrMlXaw zOHW%l%c5>jBj$11NG-4ZoTG}ba%bqz{iA|4`b4bm%XM{m_mN%B*Lb_jxrW^u^Wdm* zf~O;%4hh8oed9qg4uIA8&vJrKj9&e&UPIDdd2j-$smr?_B(r=$3V+sV>8ecIk2#7n zIJWzVAPBStPI5OyX@RbCN5^i#<#}#vrb&gpF2?4{@4bR5hP|t!{jq`g>ZvIOLH%za z5;zyJmPNCu9zdW<<6>_=v(4x~X(k%n0bEn&b54QxjfUy!uxpGhzM>o8hroz77#<7y zT~#g4ZQI!HNAUT&zon@J48n_kNo`?G3*Jw_Ra8fZ6CUFLuo*e|sER^EU|xo@^}lxy zQ+`=#(QBx)@7zzN?@f2TY`{%--+V01A0eP*UkiSxR7tA+hP*gwC5JwA8h(ha@;%=6 zdmX6wo<*!FSvc)}n4=9XsNk|t=4)U2kyh*hpD}n4EX#M|Aa|1q(Xhl5ypCLc;~O!^?XvnUiW5cJ}vZ3oF}Cd9C0iSs5!&Ey=J?15%{_UmDTdS5V1!v)1s_SnM*>LDab4 z*F&T=BlfDNFh`7c*WPxHuj|tz0R~%?iWT^(`)QU-(8C3#8-i%mpZZ@VXg%lMz$O#> zUa2Hm&SL%RE7s1%IwoVkRv0_~?Z-W1a8lIXt(_?_oett7^2bgyp|53bd;megMVT{l zkrZ?6h|){EY!A%p;7P<5eU#g}-Cc$G)YMcd1sPWd*IWDN(XolZ)IE@ReO$KR;QB9M zn&^{v;*laKL_Py>l7o`^Q-NneU;YU{vo`{FPb%*^Lb(RiB=oZf$M7wZ9DmB(NR-$_jn<)5#(ursoUOE!Uca+4m>Z zGT<=Fa&YzRK_b`qdwY8y7NX{p01y2FKY|>(?mRU$ zvB@O|Nj!vR$SSpX7-(;T)Cna;$$=t78_>z9-j|J6EpJ12?1V`N56eIXiou&&P$Jf8NRprVNvRp3 zhOCvsY+2Xo2^#o6(*dA%bu~`lNYZMTk1MG^r|`9>k!9KE#+!)i)Vmyozf7i>@<-mTOMXa?+p*)!bDCkpVwpL+jwUh#3t=>~JsiNlzA@gM z)w>tP`JL&Iu^RdlAs-0!@7_6DctNZs_xxzT*}aR=*Vvery#$UF>4rH;q?RwN`-13q zI!CPFfnSU^d{?P5?(Mw)2z*_pcY-#SvDiy(}eLGVR>&DtqGgV3Z z^so%E#pQBwYkcqBUn(s)=9GZdwYQZzajLZoqRjAsZAhx2`>*jJYVw|V@1Rf$UEokA zCnqPSIV;QS&pp-R@;}nnK%IxNv6fa^WCNU-W_Gb*%34tP4+j2@u7pi#x%sdrws8r4 zPgKB}4NeBbJij?q2U0>}CH*aqL?{FpOh zckSjJI-?&7plVNxH+0jY!M^aDXHsZi>m<#fhW`j!<$z!2Fp2h;Wg=FUe_|H>uvd}Q zA+2$ultt(t%7RDoiuJv+37KyWli1zZ;Df)x#Kb(3$>hvw#DEoVXlRK3np<;-29h6; zoyXxtdwT5~?MV@(mdB2>eRmHv2%HA*S*&NBb zdalchp8tLB6I)1l_?tdZVKHoS6}6;O$*--u7_4Mkm0_*5oH*fqb78Z+Ao zeox#pcHyl_qOqKHf0z6aCC;=NU6RWLIfXsdZS_`SsW88J=`rzoc~R2Qv}@e9R#!#A z*Actu;ijbXh=Ws8e0%iiA~>xFSPlWMOPZf`JTF75(|$hMEtGhXHAWAqSn@P<5x|Zx zsSm^~t5JbPttD0v2%?uad~5bH1*=PFk32Hvst=F%%recEJ~gdP1coJ6<3X20pMvEk zjv;8Qw!QvwlVoI71>m{GIBLgVxOFr$F30>v2JT*lKlqr)hqq%BCtzyYJMyT42YxW_n}|EbY3#LMRV;J`#u zQc_5WI5zak^wwNGxCs1t$iJ{2pkCeEckY?p2@rr?!*Qy z*3`eUhiU$FAX47vM$7SO;P`~U0Bpu!kK z2rG2fq|MI_uWdFueiw5!N#BQA$sDOrXzD-udeCOf=SbBr$lmchOqGJJ`y;eVKKGwg zzvECYR^SRMy78go?`y<=!o!&x~OA zeKbDI5-5p{@Mq+Cu&h?HaEGX8C9ifq4Pg9M0VrjPAX$dlzoZ(?jq*t?*G0bfYH@|h zE9%`xb}75GxpeD$-_0VSayWTcj;>>nN>bsVE07NHJp7ZaSh5W+j$X=q&hrd(2ggQ$ zU%nQ-Uzd>M996ifojsZ(g~gH>{&{W+DDJSCUJW$Cd_C{IBG8Tj|R0C z^znPS zc!a{5>0MLw`l*PS4*)rbw`kgnBG2VhBU5H{+D)fk0Y7K9ieS+6-^4vhz-e4;S7sLC77xFNjre&->alo*2j~7A~2O zjEpEK$lu@Jqot)ODY+HLm6DRWLcz8wv`M^Bt7W-)yPiV9|2T8cd$K=yz3DeMu`0 z9bf#laRAATQeVF5Tw1+#1&10KzrFkzB7CmJ+jb&-<(`nYFkD2si~M=<}CI!tDLkr^;%+BV(<}BE_!@I_BN$jA=CDY_1oOD0a*({ z&ajb=p&4A}9ApyxttjQhB(utq0w9HZe-xBNLyODOln)X#Z@QmghfOzhAC&4`6Y1>v z2siKX_|TX~t^?}X6!)<`=N$}vclCZ_0gJ>OMGe1u1A===yzdDdzIz! zWlIzV-=&Uek>2KeE-QRXX*?@@N`Ut8elk~?m@D`2^ruAC3dtlB0m#kHX|)tM-VIhvu4I$@MAOcl2aX<2G%!wFw7e$lW8-ffod;+MI8>3mMGCHLMEqVdQX{&lbq@Ne1zqJR zas79lgIT^Q@6`3F40CvC9<#t$V%@D81N7f-3*b7sP zPtOY9AUSL4(%fRUaqfqey*QwIC_pa&mw9K0L@z6vVCP6y`SP#ofT23 zT5bf+yS-q@daf*HYQ@l~M17lqkyZ1K&NOt#yTJj>?49z21Vri^R3BnAx!Cn~g2*zx zx+X>o`lJ7n*Wu5*W5_i`jY_|9f!Hw#vaZ&6dL_72QSopvPq31;A*X}rGBnG^s8w!1 z<2(ibJo9_aH^enY*FmH|i)9h`40RLKZn_&Vz6vQletXFd0G3B+F6s;A&&5_-dulyx zdp*;D%70;li z!fwB$XrNM={vy)&!~j~utF|{Gtve31gjdQ!{ms%h4Q#O&Fbk*j{Zl!nFwOHRWIwKA zpG30*5$&og7X6WC&;K&E!fY;bglnY*^g5?L2acrMr9kvQN+ zGOj}DN+N7wU#P|=onizlx^L&-K}ReA1?ulHN&}ky;ed0hbGJbmtY`0W^{iA3j;0HjW{QG3%V6e#Q*HgKg_dY+g~mheJ5lj65W9&KD2(Bc zq5UhcVXiCplhsRUouX=-)jZdE@8Is>W$~+!1i?~D6t_-`h)NTS3Zg+E?%SAb1)B=2 zfx*9rS*n&ftVh5A^n()umILDUudwTv1Udq|pD2i*ZZ9czEpj$88fu%VTWqG5Q-W4+ z$cv%0h9KuJ{?3Uz$B-nI4+H82qy39tfs5Uw zCLiL~V6{!H0Y814h?>Wc-cjwY?6#H*ERtQ|CV;85pir2$f{wMz9vxM zt9a;(uFDk+3XhHfgy`}x$8b%pouHe^z}7J%E;|D+qx(627R2EUTvSd(dIV#wM-~m81_N)sG)T%53_Y51|KHyRRH&Qq- zlp#1=Y>!Bbhn@{D2^qgd66_dLC1NU)db!J)i7cZTV`_jSexf5}C=qQSBdj?CQA|L& z1p&|XxUY1;j-t65haACH0abyAC9KAi5Tg4JB}a1Z!^%tp-L*&xBFS`>(gT$j!(Sm- zma-T-jDU9F;|?On(~z0Ie==Z&hYz}G);FI$SC3d^i&Y#ud6uIFC)NkQQ)wnT0C1^@ zOc-rO0HgCUipHDC-bLpAw1RQL%4ievz7VcyV>i*iHtwYVO8OYMu(Xw!Be{T_FP;jO zQe9Sd$}5v1?;6wQ(3#g*(pNOzoDyj`3W>=?tc$peN=(Zso8n51nd(osj7^HnwEtrQ z8H>i^(N!`m_X=fJ>Rv@uYB|QavKf;^PEj zUHeoeTp7sJUwhL@45t;TcI7McO>kvjkCyOL=v+SU%nf3`pl}`N0FgYwzbmnSVEb8k zlok2%)J$}wWR~sBa;Ilq2`~gQ`wnr1rLZ*RDww{1`l{hIPvQM03idWAg(wG)Z-9;B zyruyVbWgC*_u`|OvGBC!giIDD8eMxu;IA_!yrfm)e61S1?IsSu+ep@s%nsjH+t~4?vzb3 z$I_yr1x+1ynP|XmN|M}X{%4`uIDJ(2Eg$6_yG}1PrRV(-jog9`feJIr& z<4g$oE2BWUaa=sVCXlJc@vGQiq7C&`N2fg6{zqPk9~;3sTG*)$S_xwcO>HG=fViP$ zDU<}atPNG8@F9J^uk98ZsjbiU)YlRx_49nP_~n1;8Sb691!?@|K6rk3lBZONHH+`@65)#H zAL2>bOCUnz&6_|@8Z2&f`@b@R1N)l7sIwA5kTh$!-`x8=HiA@2#La?G4O9Dmz8=DL zCbJDF^U~R0{ZOo>XrDWrpDysl$v=$QC#s->rYfX=U;&L}@dHVofFAaHRM7YKcG##B zKz+T_Ij_WuuCdOU-0dBdhuuHS|AO=!-@hYS{aq~Ie6_E9MjuF7iI<|96WI?#43-n- zRQseF5Kd%-plwEP@rsYy#qNCe?tXS(3tH$;RGzE=sez?ji_yv_uLIt|o@VF1AIg7~ zF^@2tIhv)zrEQ*kCNC*~GBuA*l)d}?5HLC7PQ$qAIY$Kxk&kG*6tW<1;zWA}Nxi!^ zioYW!J zCOTTVj4j^=D1y)8r%%lR%t-TiE+*Ehw4Ef3A99?0^^oXIx;s)0d{_FLr`f(5ZDBhEEzBE6)dGM?9(M zlq**XzqQHeP9?zr^?mfHn|8!R+~fdz{#A~Y35lB|fzGP~k|;fPN3EH8D6h1N^ousf z#GMY;_i~^u4-U(0hf$TE>JK5tYn~mSA-11wxr@Dj1O)6|3n5`93bUjz(3}xm0k)#K zmX5xmxT~zYp@Eg10%MIAnx;}1?r@e@rVlZrx4C0$8$*pp3g-fMFP{R&agK!CG?Nw; z8k_!+-6COWy{GC+N|X+wNeQd{UmHs1?$y!E9^FIHs8?i)HnKrgwm^6=KWBdx;y1L5 zd9(a-se4xhKHmDm)nDBsi*PjUnShh?g~O0svHkFDX2^?xAE7Tiq>lbU#`6LE6hahT`zjI%+c&f5jJuKv8Y9*un%oWSd zJfozNmXRS#7tXS^Je6ta+6*s@kZDojKi+EVj+t?MU`}3Kl&r8zn+=UM+{9UR)nQ2? z3fjd<&wi<`%&h}&+y&J2P1YJNW4F+c+`b5`ZkTD?$8o*iWJu&2P&1ZB>|>CU5p*7!LiAWDK%X z6qk1W<*7yaVEOWxw|ZzQ4x^P;`phXw4;wQsT_#5G%fV1E+q9cb*U-?guC9(r4md-M zmKwzm{rRhimWwNOVD}eQBH(C>aoWV1D>3M%v85#?De3h+@4n?D$)scgRDgr#`GS+6 z5^<0AA2Vk0tGlJ->7R5HwXH?~iRu`hEH03XF>-opor>-IJ+<_^JKn}&VTWhyr~4|k z;RhXS2b%zgY15h1tTCltu=AuU{P-^_O8y zN%HcHL7D@#4vn&pt?5NEMz1e}3AKPc>?Qy50~pW9@4m~D+#joA=eo7YtZp9CqS{W`68-M& zO`zJ*8Vk8~Y6&fxMulgPVEaIJCR{rjc;6sRh3vw#T<_c1l9qxC?6zdX)GMoTYr2WT$`fzQ8o6Y3u{C^H7w!|J_q&*Uy62e zSQr@Wg0acC!F|Y4xg|KpK8ZLMw0L(k9+92J=kha(!GevY67~XS zGsBYDFVO^7N-Ab%N7$jK_H!UUHdq5@!)v`zROOfH=@*kzV+`$E zs3_VJC3y(q$4@D(*wqZ9N7is2fe5ICZEsz?S-7aQf-Lt2D1=8gJ^ zp-XG^A0J>`SOcG%H?({5LP~##-r5;5TLX6Stc`;jDl|H0*c%I@HEI;62P}{0G*!kG zNFVCNne;QVKo3=78L!wj)DfOC%Wbh|;F)LUhCkZM;ysTKq$!AiQ)`e5@ZM$ zFm$ej{{f|HT*5_9R|6HrM}c?SaZXWh3G~VDF$Qy)Jl3{e>s?h!*IkgfEVDD*+rR$% zgu7De5*P4`suDv3`AY}rqAymg7?q#Lbain5x(w&!IG*u7oT_tnL+nF{n0KnZ`0*hk zD(&iOX{>K2Nd8M#8EBK>e3lbmbuWU_Kve(Nsmk3mdv^JaRlUIvKY+!O(T>uV1G;VB zJ_a|mRSXU4$+t6-V@o$DE1737t%q5lo%yUEB64FY6LSeTYbq7jhQUUHQ77NL7U}kgvc}Y>;%F^=m zY$5zJj(A}c#7<8yM?Id(I3U=oNI`V|Pu(ZP@b$~fKVV&OH z!L*X-0&5k6wEnd0Y=AytEL2Y|GZ$!oU}ypKcfxO@tvv|noE%cbVHB@Tmsn0oe^GZS zx`$RPTr*JU~b%e%k3b98WUl^BM^F$Y?6 zN`lpL@7mt<`3=!|2*V#-!#iZ^CL1xlMt~|p+l%>yb@}H2P1Zs}`*vp(KvY0{sHjC|`C@`j3NdS_P`RV3g@C*6 zdC-G@{q3IzVLWQssA*sbFJyb)eyzI>=ACJS79T)Kj9|~+B9ofK%PM_@`iaZg<{QRk zy!OH*)(NV6v)KtK8+`+J_EdH#_Ot)`VDlp8JnG1TYP2z;JPL-#Oz1PL*Q(6B7170b zJU7PnOLyy{5uj=5;@WsxIZfzLkn(7iEZ1N0vwv^dCWu$6zni9)ifUWyJ-A!3N%tSA zjO5^MbgN11rrbZp2w?bbbeV~h8~+M=;xJ< zcgO{A@AR}9Jx#Rrig6~M+9Pv&Y3AR^dP}YQ1A-s7MAzCLB{!NnOJW&AoPKWug4ws@ z*5(X1B`XPuY_GZXOX61(C#u;&&V%@o)usj`L$#hA#wqtut(nxADSbu_t@oDgp$j!* z-?WWpxdn8+4E3}lvvVAF?r|)`{jKxxdhsR6vg2$a9NI3E+a&eb0)mP~bM%Gi^TSk3 zN*Sh4X_Z?#i-}(DK}+NWf}Y6h-5a9k>_ZA~F4i?C$zXo>H!PxR)HgSOlVPm0`v-s^ zij+u!MCN0{UN$!+{fzP;GoY}E!^yUy%{z>4vziolfFBlGpu_BYfyLl8z^ z^gxpG)$ZZFipoYZ^TinVVJV`3If?vz6hacFsX_ekjzg=?&qz+l0Y=Q0k*EIM?%lR( z8KN|?p9!3-lZGtEH9UH-=5=Ou;_A;3J=*X4iOCK;?Jdyj4yhmTi(Rg&0<7cXW)*FP z#@==T8Ex{9I}lDWQ)$`x)5RUYXP+Kh(rLk0@X=5{X) zMtCg>4vT41%1S%7|Gw9i_&1EbZ2o+LBqDjSOs@5DzTkNq;QDH*_|5l$`V#0~VQKVwcd0F6Zp+|Cr%gay8&%Twd zEYSG{(B>j27jw<)vaWn^B{fs^GEJ=j#cTsVxgJ0fa|Vv+=;WM!NK!d-_@M09l{MfK zhH{SY*=y<`0_2e%`)(rWQ*&pjgA$xrCvjZgRxc+!K!Xqln6_S!O1{u=6>)Us6G%~;pshtK?(Ev zlO2dMFi5e##272s@kS!BbPRBGwK#Z%u=!4D@C+IM_5-R(#KC#-h85+0GSdcwujd~a z%98uE!YRUvXzf6G4HfLal7C45x1k6CWW{1=}7 z7l{c~21{Q5%K|X}d`P;Zd_MdI!*KVFIrt(-04VQ|0CXEY&8IZ0LL?#v4G-a z%5GoHy+wxio|&=0kqVH4@MlJ~H4uFnqO9MS4uk^ZzYOHxOz)2+j_=@B2I0Q#+{64I zWGI=_A%&Ijul*B2R0#z!w5669o1h>nT4m&?h3t=uRvf7B9Ne4laN)nR*Dt|bYgE{^ zkqP;7N*1C61uF9mdm5cLEuFp)j*6Q`t(-U;=D7KJIPd>6@rf01`^&Hc6vdXl#KA2@ z@^eeuSzlu^l1bC;$98-CM2>)XS)Lgj7eN&s@6DchwhG3+WyZa2|0^cf5BWVSX%kFJ z;tz%(Pv2i)M4E40V6<=KfJT6ag@J~LfiNg0IU+7OA~`ZR;vX&n6fh#fI}ZE%={U>T zz<&fPI&UPM44NinB?YB`{4em44R=XnISe4@nDk|4ny_&+M;uBJqeJ)hU(?DuH#j+V zdz+#{hV?MK7~5O+w~*pXHQ2w30%9MRFc;**XDCrp#HNQnSu!}~i{>raV54OM1lf3^ zWsK*rOaEe^@aW2v6WbS*H67<3V& z+6TjGwG;`4UKoA=^cYszXiS%xx98?Sj^y5i$s zu>nPAWm;)oF3^}ZO$tPuOr1PG=^i<5@%oSAkoO#cBDKA#{o561bs~1@y>T)DUqqU- zdI`d^eO1g-v{LLWW*K@WROP^g`shkl5rKW{qC%HrjpcpU4=kzqyd)w1|`yaL=xZ zF7b+*M)_OH{9w-+V4S;oP_3)6wzdT~mib4EHLJEX*kkA)04wjum=tZ?`UN^JZ1+SM zlR}X{QMRWtiWt54)(|q$9}S(bIpH4{V#5w8E4h_noPf*$LSoPrYeSr#6DmrEk!8W!}=a48sQZ%IV zzU5#5M8iKA-rI1*4(Vds9UH?Z;-*aQ8#)Cp=^=7J-MaI^MmLO_B0WQ6<|zv?2Hq7H zyYnH&PWNNBMsZ_iOdiPH&XmO5JVD|lvOWa)ZGqZc6q&!fgG0RU*lW^p#Io{FW)1~o zt3mu#5|}k%;Y*AbNQ&vc_lKcE3%bPSm^_rri(buqZA-Ic5cQXTZdAQLE_SbVdjQZN zaZ;i6Ko9<5j^`y|D2CdZO<*8oRXlHGw=GN7b;dHacoS$-fxNgY72z^_6@#x_Rj zvyZWYC>WL4i^U;~ZvA3IhuzQ-1L@|yMG0>Z78f4pZErgvMoA>bcycK?f$sf261&O8 zqh<_6ZPVsqNTgkvb=*akMmg;1)E@=!EmqX_cA{#=xl67rJB7UM%Lzl;8F?uTZ<|HuF8P?ZaL z1)l*%Rc9Q>m{ad#`D$sFrRdKX`i~SYlbg^^Vf?+7*}gfY)&6V8H;6%!L|PBDE2C!`VLoDfMBE{T7sw#*}w`N$1*E-ILzCcbz5rK+GZyct$|bC zjQRN<{=+>_@iEsx8;Yw&gs^pbCL_+emcD&i;oYzmsqTbRyBU_4&d=!a?1u*B2m8*G zr1gJ>vwS^*$IA_)*3Rr4;kX&dwIycm^Yirb0|^N(GK{{Pqj|>I`h%GnXQs?da{iOf zPe`#UR8CG8mJGuebaVXq%1d%shEdHNV^VhfUJB4D;68tORujxDaG3^E=iFWNuaKQu zTTIQ=+1Lda*SCdFb9BVEHF0$_Px;>ean`+(dBfuo667hyJlcn_suZQ@y%l@ci@Z8j zfll%LF-hd-7Cw|SUeSSaL4<`A%qs=ijUZKER(=t?MNJ{iw1B2$;EUf5megwpP;EGy zgO_+VKjWN+4GVmtZLdQVHX`IjOr~RVy$3k+SL1YEEs*KssHAl!v$>tRS5IrD-6Wq< zFR4W*B->l=O)+mWKAArXv5GP`KihV=u9CLLj9(AW7MnuiW9TDiOAKU%xF%OzGMH^@(l&I?IOJ}$KeotYP{Vg+n^+_VYZEOHG z{i8wqtbsL7wYekQm|*-N)e1D5pHhXIgI9W*3SSXvEby0^pTp%^%~B<|0Fxfb93*>T zzseZ7IkvQh?ohj6*Vm%PImZQ`&N?^1F0RrVdpHk1>szEbBD|Z_?9X-JyHoYsxqfX# z$JWXsa>?hbIW5V(ewyxMN&=G2@9doP$||CM(_i#U1TyEAN#4GquT0jJO>&#>xF{RR zzORw&cmf~CSk$^yrc3riuUYS8Xbo@c=bVDijHAQFmx8JXUb=i9X{E#bi@s)gMM};o zdK=C@wK8v;#+&<{?&p!T8Us_yIga#_e}~(FgIXMr6t6D`;&png7T2PY(f?-J+l~lG zwRLp-ep;_lJ|TuYplqss%Sd5pc1T6zM|j&heI-$E9%AFD5WW)(?HIm^tRq|L6YSGC zdTDbizP$z2draul9t)61TUw9#=_V3vLQikU)k{IiR)Q7|FkhTTl}$_*_}^Y|Cfwpjb@9!HkP#MdSMq8vcw#%f?@)H>bj$*lA542 z$A~iL_5nhw58D=Aoy$XJ1!7&j2yJe7=bh|!uOAj#1^}qG!%8_?*K;Uxu5y)Njhh#TTn5c95W?Uptuovti%NmujN#dU6~43 z7kovuTMU)09Rjyug>JrEYE5wKx{=z|lH67%O-x5e9&!@17@sO{3T>|_CFF%(t$f?8 zj)v^EK6K*!n8-y~fkIOyc6TB{wgAr7ZUj!^F-hR__dtUKmL8T`{H ztY1d@S2yT>q#G-|1%rxahgb8wEw3+uyzu-#Kfv`TuJXkuCOhT zJxRFmwG+D09$(Yb6dG7H*=>`w5|9HPzYWk=X@>yoV71hqb z%9$UTgo9aOX?(W&3?`z|@*P!no!o-zdJ0vD#2UW_RHRhjnWI(eBsq!Xr{t9DM85Xf^s7!Z4ZXA*TChfq&kBvPca@hU+ zzSX}+bS2kJ3RSVO9Y4fVjxM&D!bpRnhE_(Ya5}^!hlEUSK$)FtnP%#k9#xv4xbgpl zX{g1q-wNf4-!c=^*w+oU4m0q|k`d&Bd|q7qrhE^4?1Zu)m}Q`HbP%Bn&i4Vikl<=7 zPxtgOo*2GBroxY{|_T3wAsH$sY|g)U-BH_CU~EtkE&lce5{!h93;Zs}dA z1W2Dy^}4`42Cmp?n@}gP{@uOQouAHARR1ZC)!^Bn8y#H*R5kNR(EKuHSsQ8C{49Sr z*IWS5lB~jCy|9`4)^g}d$ZJR}RvN?Z-;P7FFvL9ilEa~7E}@l?IFNF9u^iFN9^#VJwbjG}Jb#FmuS;ncdCk3J|8u8`_l+ zrl(|?oozFX5#Te(j9VQz@?IjSsTHBy7)O-C^JK6i|G`ia+tZJCgukv>rzk~Ch|&xrK?*^N#1?STp@;1iAol~Z zlk-MT`Y^6SvW-wsZbsBkcn^1kctJa|f4PDE&udQ_u&*>J9f6t96+6#PpA1(q|_Q{6FKd-hibR?3h02%*>t+R}3YYV$| zTZ$HIarfeZ7I$|o?(XjHP~5e+yE}xUMT)z-lc2$!n{&?h-En{1U+lpcS=mX}-fQi5 z&i9#1kSjwD{L@7*%H-hHl!BVQ9wTf{E~zsCaI^C)~7uft#-QpJU;Q!tnZ;33JGN;wnp|iZZFOCQY-kWOL29Z%CYHlm3ti9 zpbhc!L!b(y4ERN3bOp1zxUa z!)&f1R*>2gUoQxwp9`Yng5Jz5)%P}WKk%#=S(ch(PUH~sK0S0eAmEUL7|c4?1iCz* zPFvqP-2|pzh0~_=t*C5h@ctONnfkq+C@TmwcLdElLfUU~eIfHLeEP!9lQyINXV%Ao zXAI;`iR*~@x&D64CA7Dv>N%SAFAN*i2hnZ|ewUMnxxW6ZAFGANr--R?teYn(*;Eh2 zmY&QrJV|Bf;9V`NSQ$IF>T9^epU1p6mCBn)#i(@E*VA%*M>uOR_yT94_Px*|_UF6u zQvPT>VHV}bO5Qg}ses@J`m(qY%br`DCbr`}!$QDHMQP7aY4m87>+=)K-3wEp+MoBUeuH`*H3`KR0g{&n;13;AJhBG4YrbDJ}C7 zH0$pJuC*^#D;}}uZrZnJ>T1=-a_hBJiB0nQOYa5%>eKDruNfE}m?8dzke1Gf%s8vcr07IUQ~GZp0J0-1NDhYqbA) z7yZqvR;afoxvi{0#5F6uy!zyi@pO2Yc9Yi~N3JjU=B?uH+v9})HTBXi)a?9vj`nsp zW+%c673wJOdI}kJM`u~5lEXwAAf0W`%)kl0R=f;Q290y2N)yiqC}1E^)k!Ye?sSqv z9YuB6$C0=thI#Pqrn)lf;y608UVO`I#l7=J07hZ6*bD~?0iK#atX zw~#yzLpuGTxqR=hAuczpL%Q77FsH_`QPIx5d1GYrkBIEWvl0W8P2V;K$vR{IGe`; z1}!kcbqG(*oU`%s7(j}HdrBE9fDu6&Np%$c4;Ecq{n41ZtbzoC%zl;|-ui>J|aD(Jpzj&O0Qim4@llhrsVabar(7k6he7 z;eEDOs;tPu326umO1G9jr-c$80Vqq@S$;Q#(gc$wXd5&%!oVZOSMVbZ0peqaNK~eK zt@;V^p)01w@sqC1)!dyuuJJ52(PVW65rcM4iI8kR6glP)KbvH3k4f2;;=9~mXAv%Q ztk6-XY@4W7R(WL77n=36Sony=sF4SzL>R!em?;c zw}hnqxU-!NSZJ9^WaY<+1~dYOi-?_W51Gs7D&JLy!ttd^F9xA)VRD~U>cw;Qa+UTD zY0jwC7$-F@gPqWND_(HP{~L`6<0*%h_}9`kApyaYHu{@(J%>7@Att1X2nkiBbLMVD z;q}<^4chBN7{)|s&dvFp-a0lkG_Sf@_vC*0Ib#O)>G5Z->*?dDwiHTm>`bDRO)Rut za51xhCEeSv>=Mw6$8x_XP-^r2*SACx!f)ot&Ayit?Ov?PY2*3&X%9Qk4w2Vbe+24ach(VH*k!*MB8>6e0rlmikKg=AO!w-ImmVO_yiW;XhN&>@>J@HM|S}AgsF;<1&`cw zUqfz{j^b4jDD*CvZYc{6NApiz&G$wBlUB24oM%w_CtZ&x*vN*58#XqV(1B%TQIji5 zPS0VS{P{d&DW3;lErrT{X9a?gWR9VXUM4c#K%~f5Mr5^`6i20mu`BXF$m2wFW-w zSwV`{J1F~wlbv4_=djBtu=v8&kPT<4tGoCT=Voc&7OPF~>A`}AzhXqTaX&A2*FhT- zZwv3zUMjp>tv#9ax#A}s23&#l_i0B`w)?_L*weo#Uq$lp0t;q*G)C4fuuH^e=)J|=bUMi5dBjv#FR~mSHMZ?e-m59X z`rG@v1}k?mV5}^oNUfd{tjGFyY5_vh z4ex8m5Al!(A@)p|JBx6^vu>B=r9>FuC>U49oz=us*SvOv6c4E|6_C%pJ=Ak3-Q=Q3 z?4^nqEBO>XJ}z(3oLA0ey!YEDo$*`I9YovQrqM#xt)ay+#O3qk`Ev0_S`g0<8R28j zyS0M~!p+*Ti^foa31~Q>Y6u?NO}@kpve&62?6m{YU#Bk0q@G>Z(zAyhS*928;AD#k z(xJOvKq6)>Fd)r#SCu5{2sq-f%h+r{zuQ_&^^G(lp_&6Vg zfjigo#2hhjeMBEg~KV4 zIDgd1^|ut6J0& zw?Zz8?=wJHPt7mh*O|EMN|UeiROHkfViZ+HKjUjOMnAzLPy1HY$|yBUibSfp;uY)e z`n2AAnEKN{^O1{NCABuO0HN;sn##O$Ro9S`y@r|$)+ffxu6Qk5Ym#r<@d5EQy%XXH z-y591^76=tbSXn%a&ta=1w7mR2?#2%!1xpwUB7@ZJKF9rPy2kl8uSVWTD`!WOso6sXlp=y z2PKc~OIgD<#H#xI)@&augC2x2&dORIs&8}AwIUe}M4+NS0nKS%<*2K;IeM}Y@{8gh z$1uB$hbX4Bx(k=xg5CKj8cCB!XwU^_k6UEhOS^hTVuWK9`DlZzMlMv{BkYN)pi{JYIF0O5)&9nw zjePsvamTdwEvYUPNHI?Rm19aA1K1MLq6LW2ISR5kS;|gGvadFSCi5CSQ5~N2(HIj& zVG09RuAqKeP7(4H#^AFds)Ff()KcdKYyeyw22L*`ZLmwW_oMyBG?!tERm2Spte;lq zTp{Ge?Z~H%sUr>M#n=G|9(6%A33g%R$qbW8j-wM9iD_QE`tpbBca58?E8}_??##m; zA4PXn0Xo*uk&`e`5TBz$ycY@{YhFd8DK#6k^D}j}wI{jn|3!EQ_+8ThmMg8RYG`mW zI{h}qj_0Y0V0%hLk2u3~s-c**Meo>W9PKRk^6?0T0J!_Pde=?6>*{aKzA4yp8D4_h zGF_AdYGU>+#C}fzy|CWAa6)!8g$u<~oDWrHrwI5VkEO|-ki|-<@Gk5@JlToA?a{ZeL2YkI00l zZaEri6p5RJ@qpp9?#}bo2>16zGSHOfa8pxa1UF;h{>!RLvh}#z;FA}>fNej!@O7$A z1Mnp7%d;A9p35}oT0#~0k8wzn_y@5D(C_#M4l+6pk+A4wUqJw3U3UT(56@3sLXfqgW}9pXhw zbzSdd?3v=OC+)`3AR&JV-3s@={duodoK%BDKa0S=<~xxzvZtB#XcQx57aeFRjT1M3 zulTS%J5MbK&>tp*LaRDWQ#^I(OTU?1ffd||XNgK1YQ()re;RXSkW9b%)?`cmW9gv0 zD2w^;JInF#lLKXBXHykN{cHacB9r*nU_%*)+g;*v6E~jluL(r>GVi%!hV4>@;p0D^ z5aG*^D{JY+9)vq{DJZFR?J^Qg=XrG(YFhB~^An>g*1?8Bj^Y{LxzMn|#vrfb;zbSP z6Ek<@>0&`$t?wD^?dF`=VJ5}8Fn01h!a@7`PjHr}i>DySXeu2hxX@;2cb$~{ zcR2)tSQp>|mD}l3Dr)irM^hy!F|TK7(MWY){iuou@`R1$5Wi3>h|R~y%1zglE|Db7 zw7NEEcigT<1FUQ#_YEy|wW*JdGnpuxZdr>T^=Ltni1jTksT*A~bW@wH-rqNWFv5Mg zW=Y{OH#puh$TL1elHa@<;?PwhE@bA41~hqW(S(U*GNIH%YZ?cl4S0f8@@EG=gpHxrweM7t?k;o`rhCy}emz*htaw0Mmla zlJmW+y=e&0k@s_Z>sP(??&!Lte`29{IlJpz96j4y>cxaVN2h(I#bk4J%}2l>-xn4T zPzP#MK|3-UG*6a6n)W2MYu3xt#1)@Cn+tdU_=u+zBq+bI`FFM z6w&`S#lIw~@xLf9T~IxM_4ga}cS;l{B4J;>P%-@Ucr0)D_N0FN%`Rx3DM^Vg39(^sqd0Q}_eN z*v)K(iKZy8AZQ#~AK#@X4v}{};stzi`?JlQj-EcS>$JQ^ON>Uy0EiklspFg_oFEL7 zIjsAo9M2({^6iF4@6&%y%EOCKQaJEZD4FBCfiBP(>yUg)d}h084p!rda1Cc%3=V;} zP_h7C!#UXCqV#k;eO9?b2Rk=>C*JNJ41E@Fb@D5z02 zAXXTGpE@{R)x?2^OD_1I6s+k3oD=|d+z^!34#R`oWWXw#ouxAS{cknVU+ersR^>*5 zbHfZcfDS@D;P!ef8fwszGIVq=F}JXFjje9>(_xco;^Y}RJ(pykb0sXExX(?M$2Vzc zyJ}Q+X0chJOd&%bcP`uAWu2&Uh#bxSFq~0({YBrb!=BW5l;qyuAzVRj!-xLTFzM9X zNZt48i$NojDk`{PS!(6c!fAv^QcVS#w_p#SIZyg>R)6NWF;DvGX-414N%|KUwls3T za!1XeyVYkaceF^$o+o4Np(j@j2Pqonlc5xK3pL#D&JX!0+oxJ_vP9@~9$AAs|^Km4>$ zCY6Tp$Dl{FSf0)rRIGb0WuIrVpkOv9yOHFw9Xe`Q|7(_o*Z*y6roozs%T8$EW*PPI z_J)<)J_GTo$lM~UamU$=mr5a{==u}&j0qF$6zz|%sr6hFN}=+vD10JIW1LC77ST?# zal^TL6T&-YVf#v<9#An7g9rRE~UL zV$^K8lMt+UR<96y_g|G#B5Rw*QlHtX$<14FfYh5*LwYt!f*?WPm!>s$sMD;&^Ce@F zpTGWD?8jf05V|TZN~Xq&u3>w#m3ik=8K(xssxp#` zn3dv}eAn9#(7j=|9d{JFp|_pwtRkerrMVc_uVH8Q#=7gi(k8KcMl7shf3k+!8U*{t zuXrJ+oqcdm?iyFSqo=pRGqM}In?V;gQ2dh2_Bvt)<2?7oT2ABTv76m)?YdXbm0T;R zdXMT&yzW}%X*hjg7UU8~VXwp3c{?9fTdm){ePxdt%LZ4L5&AhH0__5&{Z9oVe3L9)AR~M`C#`hq%b8bNf)!z8-M*?3r27dSdipudWw9 zKW4OrPD5IpbSG8F`x;!Ne5l?ZPD|)g6{S=(pN=Z1*>5}#cSE1A$xvHqU1o2cjWNI4 zx0#I2)(UI-)_b~}%Y`TAa3n~2MklGBy*oNCUi7mdV(e&we6a|Pd+hojHfJGV@kh}{ z)+GO9MMF{_(K-L~xqp>bhvWJP+HN6}{r&CO5v4Kk3O_{6MfOXs7{H2Q<7s6Y6~BXu zNr$b0dPG)}!#RW{g96h0NVx$^4(+Pvew-{^9BOMiv(n{oJpRp~`$a$JguocegobVU ze&b#pOrdo*y!v%o4jumEL0<(1x)y#_ZO*s@k4s-|hP)4}rxPi-!0lbkg7bj@f$~aO z63PZJO&O{{!~5UACb{$9SO_NgR$Bai)o|YR7(8mu6NPx^3dM>m(jLKp%)1kbZ4uRz zZ-VG@ZT!ZXEi{f_{;?HeJoxkcW{m^*Ap^2BQLHRU9D^OiA;CugQTyU z88mErK#;{GezX{MRcB?I!^>6^NJrkx|9U;@TB+WZpSA6HJGXzlGa^>${-_x%})t?8q)lsw&DQ&5D9RO!atp7lo)i4bxYCCA5J=L}$oYJk{X!JhlfWTL=SWpq?!7Pk(>4d3M4o_v-;1eIL(Capx|QvJZ}!AucFI znj%wIliA1pOa$zmS6h*#Z$L<5ex?TSmt6WJ-`%r$n1asp9wu-E1x@667tSy~Mw>s> z7HV;{x(gpDG1q%_I36f0g+i5V{+h@HzGO0WT@Tnvp))2mX1+aN>L)+br3qXp_?&mM ztUf{C{PJ&Pn(y1kleAU!W>B%Zp2q{91(O}IYyDTaiE3{&qV?i?LD+$wmi-#~M8FbG zBj92^P2b~npKX7gAs)~;r9_S!^baTYr$|eGS(M`UGVgjbYCSJVv4FiAX~9p+)1dxh znDN-A4f@(-BbP&q{Xh=PNo)5wfVg1Bwxl3=c5m`N!u%SfNZBX~? zO>ORToxSHAEQp3g=ju^llmGHn57+hEC}FVe6LZvk!P_NzjDs1sROj;u!77KH zekvfM6;;^6F@#9Pk5Bi-?)jli0|vrAX%XT)$TL>6PH^5e<_xLB%$t zH>$QPT_;^O8c2T4COC{6^O=PA?t78(=S?_Aj{!Rae@HrptE`%O11eo5S{EK}Ix-t4 z>IQtwuI4({+v`&$lifY|d9xb^q_k9l@ImCf9SHtuPS*F{-6dlQMasbccEDB)6VN%c zyUFzXK281Y^SNyxuRf=eY8oA?sY{^C{$1na42s^%RaCCM2*t0D7;=+evC9&kIW9w7 zrX{>Nx}W;c0Alf&$yb$cuQl)O&jL$uXAfT=C+}xI8qJB(;5E}8Bpv32>EcS{cYTsv zY;RroeY;|9jaJ#`dhE2fc6s+I1dPs35)y*0R>8A>X%WFI-Flweqm14{!0^BEk|J3* z)(wuM?pD8C5f$6ja`>n^)UYp4s&D_uFm?G1(jg|!_}DARlcaHD8gIqFldrzJ(>pz7 z(YPDaSGP&yqHbi+6)n4k7Z5a&M4!-=OXNzv1r~ytGZxodvE_kgvM-ksN!E=_BAW$N z!>{dWdWcNnX?l!&qT4f%GHTt|&r$w<0!^`QS7lLrE1vg-Z^DSbE8@YP(pH{jAH!<> z4T$c$UHT~2mje`qmQ`^`X&r<||Ik5#b{~%u3P)$=Rk0rrDw%wNo&q7M`l&vU@yW_n zi6ECaLHr?Eqob1_*(pz{@Jb;rra*illY;c1Mt@xci;Plw} zxt^5H4B#?ohv^R=kJWygLCNud{b{SV(B1I^Co^VyMl2tyvZYgEwhpABQ75AgrfvM$ z^Kf+BJ$J1)GcS30d6touE@`WavP6v=*cbNhF>dgnflK5#I*0bzkpR-*_0W6FX2}eY z_%4l{rwf@Bg|VLiyNj6?OmQv>)>u%T5&y+Cq6VUBG=u@e8YNCJAy|#wk!z4gVCXfL ztl0bXPP{&UL|YyV8@^77mP^C8`_xAA8g+G%;~Kcx-{01fASUbQ>@qAU`$OLbvNf3o zs6R|}8NYvg!cN6;SkA)3cDJ%3pX9O(VuLa2H&&?UvM3k?G2RE*K%mS694cPTvD*J z|936FWClDW!QicJbqw!^BgbOj)?W9)^}?Shk62|N>O*+@4fukZ$)Ap&B<&LDubD@o z|0R=MmS{L`_;(?%VyKew%o#Z`vb46UaqAMqfcXh5ee9h+2l@N=@65jaYy{mN z?EV$Jd>T@df|DIKer~K2RF2WhpARf*3JQ$QaseCfQN4?l%#J+^TI%2vPu5?mVLRd0NRqnUr~%k*8-i^`#u5$^uaAAv!C(A3 znR$UW;hMN+Fy0YWW(qM)zsf6U%RMpNW8NK6mvH{AdNSyQ0_UL)coCnVj0!FBbxs$7 zq}iG{_r+uDa_tUy461iOwFnL2rF6@Ugp?MnMhuvajfD3?j_9|pN3EppTHj5M$d4$R z|M2nxmPb}7AH0iVL$^CcI~A63)Y5YwA7)ZNOZsMep4*l~9P~YPk$Fv(@Z{8qi;~3c zBNCA<+6LXvY(h2vz*t~pg04zXVW0YWt@5V|%Q5lHdoy+@WE*oZA7+mkxbuRcG4^<0 zhVVC3*97si7M|(LgT6q#<9H{&iD6~}k`ycsYM{TX87}3Q1YHTyDwgEZ^pbkmGe3mw3rJ};_i|x}HCxyg+r$hGYb6JPx zG$7jm{;0xB#h~b|UggH2S@BF+T>qv&Lmy{pCO(BJUBcO?qp1!4V;2p9z;?KLYzzAK zrZ~Bn``57o+dMK^L4T?WCpm&+Ee)@%Rqq$-=f{jWuxlbE0Jbd(< zQl)w57oq;$zS>pUitHvS8d}_lkhEVD^+!)C)xHF}S8r`0|3A<@dVsvr@jQYm)_hMg z(u#v?d}(8_J6tklKjQQqUY@I{mZzn)H9@KnLw;fFh)+miQN3R&;bD=ndm&c%;!5efWu)BrbZ&l**9jR_ zRW?z<+TC0p-@40*CO)VDZ=WSOtNkL1NwvOhw0N04&b*0o(ET7Ml$Q{~46z!a0kS&f zd&4gWh*X~JE7Gc#Bi3&rkCB95eP5iKvH=&$-?D=(%gePMga(E`A=MJ#$2B|MwVxp6 z$8=(n3ndN(hkex*o`TkSiA18Ns(^XFC$`pNx3X@%QvixJwCqtVVP?2qX?rP)sZa1t z3>SysJKpZ*{L-ywZew%Emye*{d2(nv*@pPRadm6n^^#9xmbXu6W(&xMTd_Ak!B{CQE6ooO71LG++B1+lLf zeKmyk&(F6Z7Gy+oZ{59oBBXx52+_wCu#t_aNp;`K7l!$&mwcb^6^}%dmIpfuDIQhC z>1nM2g17TR zC#AF?jCRluEKuO_#f`-chO zbaks|TG8%T61AiLh3E;y`GEZQQlPSXVUty&A>$4Z7x>9X#8*KhzV)OS{TgnHUFd&W|K zs$6BpgpRya)Mr=g+=~LTs)<@}m4`;1Ggjs~74eKM@e!Ef8*oT>0$W|1kWn!nxgmr2 zIdWy>0Y$Xk&4mU5C^M#esbZX0$4Knm4NTm8R4lCl@)9hP(8pIPy}=q!1|gMI*Ttu^`EAzMMlwDNil7uF551mq;Uw+Y8>MM`H~0?Ec{Z_EZ<3re8UvI#3$q5gw!f|1A5pS%2&gCvFt;*C z)oW{YEE8fE7aM=j-n*SgMT=2rL360L+}@)MjcIMp(f)e+kD-HgWWqraxcFa&%ScD{VYx(r}TiQm<4IvQ$iLK>3AxL1L=k

    $iIWf=q+ogzrg5zQjM(>8G+mJ9J_vT? zzD^;XESZS)8AJWlmi%yXv^(e$4Bo@UX~2z_0R$l!`U(Ep$Ze*i&;pcXSR zeqcbSHgyW>Gu^Y&Z+Opx$$$T6dsqFH#_=Jalg69jFP39~Xb{IClFt+s2enako>cj z9E?>wkQ@33BM@FoX_p_0wxb_P!%QQ!2V8~-ctnjKIC7ExqJg)$zWlCJVsT1S7EePS z`N{JG&zx8jWBq?9jlwY|YTZ0t4yiQ7zq?MBDizS4$_HJ3{jI$dr_I6|&G?!fBS=QO zWP<}<-`f@o{6L?Jx2BeK^uNND;})3|PJQTh%nzJUMg}C_P9OhNmvwf9z0$A$Vg(S0 zpEVaJ-{y+a6yE*ULr#f?^gjpxYF#lgaY_GI>w?n786b91}Ayo6>L^t;D%5n`JrE-y{N zK_vf$QjmE{28^sFxwyKz{;zws1@IXmrwgH;p_HWUmW;`0cT!JQEKkb>ErW-9v|gnAEm5Otz~DXlHvhw65Ffx z-7k+aB%!U*Am0}Hl88Yk;0fVKcGN&xzW0^!rRlPeb-IzNaSN|U_w|WfepKN zQTyKBU`jm}W2v6nkr_LIBqy{qY_s7=jJ28QGLW9@b4p_0`4G3bfLBUTwMw)uxgR?~ zV;xopN?Oq;9)F$wjr*^1u*BIwC7Eq9Wqt=KAyG1 zi5xjlqP%4?&(--fviW+uu@cElL0igTv>GOwH)6;c*`4h~l?7k4x0U8Sj?Jt8l4-+{ zbm;lWgg!!Kwerxa-s@Z`7P=oho2M#kSCXzum?lM)1vN}VEz|I2W6b8 zQ^L)DwMDK#@&xjCDvO}Sx5K5>qv#)9Soo6uJ>8W+v5c-R(Mg+!p|7v+9xKX!%J~FQitk22ilOxvS=ze&aqjBd2Z`FIv32y@xom| zR9ZQFKK-Jt?MZQ+28wgoOG&p8@#)PbY;tDyi6 ztMVLue-sDkZTShQhavX*+>g35XY*z9rKZzMMh3!dYxya82M~y^E{TBX=RCF_btSo;@RUu)IGOG_| zdhR}r!H}z%Bm(1S=xG=T9)XcW-kU4lc=Lcurq+>ojG6S1$wB5-+LSF`bt;95^! zy^Qq;{nwo|`<&)&hqma2U;b~G<~+6x0A0kx@wm#ahv!-C7UHMr)%o3%3DMcj7x3XZ z$z7gKP`o`k`&n=5j#qnD$1*Adbn*=9%t$kvU#?ag#Rt?|uiqO0$ zbFRSD7mSQq$BgPnG?}l-+C@8+_|B$h=TYLz!Ge5rBJijq_2!VzTHiE?EEvJwK3ogObfQxwO z4hZHd5I&Qy;0i69m_Mx7U<|XJ{yh=up;O<6+1x1wMm%^MI-8 zgse=)J9q>)Dc8&%JR7#qCbH;uyIfdIQMPI{8NFtO_q@R4m{+qT|2dB1tmtOA=G^{0 zSjqqP1T0pvjG{c}MF>0fo2;awMGFP%SSr$8_h%TK~jZE>)$~W;ZH9rL?kX#PH$Dp8@jY#L{M?Hmj{oM#?2yBe zo7YXC(xeKmxZ+fq;+;5Zzd?IJM&BKa&0#|eEcg|{zm2J{xv?~qkqLMEp?G9s0oAlo zST~y}o4Lf1txJVnI@%J~S#aaxxeY}8%aoKP5vYjyuJ&ce{_a*T#=GKd*=@-`Xj4cT zC*}slAl*J3Xff4B05dHCc-l|8U5;%yd@F~aljrW%?cto?BoyEm}G0qH#bL! zg3sE8^=@=(PAnMipJSPKsrltm{~TKQq`hMhQO5b_aOxiLUc*eTOojow@D9w|6)=f| z#OZUZ)Y4II&uAUk`8R&c22~wl%aQZM6W|@#yUqMSm?PQ05BWui9sFm15-sb#cU7*i zimE(h5`7<*lL{h6cG#>`vCPST^IAy~=kHxB1{QYB9t}wj)-b>}^#Qs!P4;a~wV&q_ z>>&^o$bGT$wjb!wVKjsC_~?wTQGz;1fTB-bio|j1Bp%b8MITQ3Hjc+dY-Vx=Q|lek zO<&FfM~P-1y0aw!+Jzk2zolR9P?k=bwT2{v;bPv%p)>c3DtE&WD<7{F)m&=9nxE}HL!D18>+HqzOFJ$uIqjov(}oYXq^y% zcnu@SkPn1>DtHzgGPzY+lNw(l4h$G)itD!0>5Gc!?sEH7B0wSxU^%*YN|3YAG%Smv zZ;p*+DZ7Nh%Bz{MA(^klZh@n#*IviT*zbV2r*yzG+~WtU)&;gwTXZD;%2b?Kpt5j_tqg%td4S?OIPvt#%1urFO0 z8X=1tdK8as^-kM!gf&UdFxU>_eXam+ivd@97@}jRCaHMsq2HgN+`-T1zta%W?a!Vz z%2(|O>+xazoFl4$^bkV=m2e6PH*+_ljbr^~y1=}L&NaquuQH3Mx$ywiNtm>%Gx59?P)99mo#2)HMOksDhWnHA(tCvZa$Nw?kQL#43+p& z-rD5qss=x#V9yM0f_P1JerTta^3Btqd6z}ulawyjt_6>7=uLhaKXaCGY zf(HxX4bp2xb&ZvSYNd72Ly!w7`X$2s(8B^*>(I$*c7j3zi{nw&;;}sf>|pgm$c)e- z31t8KQpA5>x|>ur)RXpSdr4yz3<5#RjmMT1*49?#mQeO4*a~cEWeqB~CU{r;p7p)M z{LI3F%HkYlF>8+qL0^x8w)UqN5&!K;B9XvwX?)6(!s_zc;@X1hd>C@>6@0oCny0IZ zcv3w02%(0ez&D^4cZJnq^Yyh0>x3{a9%`Azyc>ZLwW8Fk%NNfB)#8YB%FWf=((iSxu%U~1@@7z&o0t*Zf? zZV+w2!B$0-B*H7m>i9@;T>$;vhwTF7Izq*ioYb1~sKVlwoG$*loZ@UgN{{zc!DR># zcuA0DpbUYejEug_aZpJ`XijtCHl8H*`lk^Yj2&=+4tfH(3LT%5)s+Y`%=j2x zUmsrAcBiJvb=%FA^!rG_me$TefX_Ucw&Z71v}f_}Yht>t6t*;<`;YE~)Fmc|#|aEf z@(OG1x3;%I+dG0kEv*SMR)pi@!lG(o0eD~=dz9CfSUX~3;>U}q|E9v>&gf+-5SW@^ zjTE+SU~8JDwrE@cTakkAas?FU24*~hC9`MPraJbr=C#wkRn@PuGC~7mOENb0>AhC8 z=(MPrEb(*{MP6R1f@Sc*6)P(^2|G?C=+y5T%Z`t9bB!lWJuL{1te#5Du()t>!T2Cc z3v2v}ca~*(taI$lii@7&hv19DV6u83X2yF#3qI1NSN@V zh+`F>?(&N(3=N9jBU)I!lY*r*aogk8z)!EJv<8E4t*m>9{@72q36>=dav!p>vCTEt z9$6okS5)FzSmi9v2L??|!M&>8A<8K@vCYr7Np9S)PfbIRk(?S(s%fLIfMDX|Gn?Fa z)zpZi&%Lb%oC1BlP>4M)b9uq$;_Up`n5@iXHz~_7H6@3@GwPpd=tTq<1HbdhV{~B< z+vAg$v8o)(-B{N^yCIV`k@Bwff*U{LH-79;HK}4y2{2Yllh$(?#Q*+t_H0o5s+gXd zmzH|aZq1P1Bx6H+k=+@VMsmiN)Wi&QjGTmDIXSqM#s2aVA{dskcQBX$wqO~M>W!(K z9HY1v9l$bOEEZ^I_}MP4x%p;XSh$mQj*t(gbLL9AFFR&Em?H6e1ECxfciTZ)(ZJyz z7NrL+L4dI7ab{);0rpW@^(i_I4$hYy#IYzBwyUkGtg(wD1bU3s=YzoBEQBQMuaa1^ z?FU;#YKhvIXC}wQ8Ae8Vjt`NJ@=Z}0fxcQ=TB6d)oq-YVes01xN={l;KO^MyW@Qx& zv!Vu4^4hARqmd=FN1H7C74yqT-g9xS{f)k+Jk9x`iFXj5Bvc+%1+HWq3BO{UZMrx< zuaQ-lM1a(Nlfsj|U|-~@KVy`kEd1y81Q!#w9d*q}K)_d2VL<@a<+Zk0{N5bBdvD{~ zPj$X!szXea!_UL=YmHxEP0iu9pdvlTO-x`T*}SG0%nmR&593-MN=A5!!noo|9g@}& zZglin9v`k2`deAoFg*je4*UME^*pISc2t^6U&Uom^xBuv0$mu4s870VGXxb$)pIwj zw zzV)DdQYNyUs&}cqiNOAVte^#_x`xE;CdbH#+%&JuQ&d}6YE8JNp2JP~ALmYjrhX=}nL(iQa(^n2TTXkIyOLK$)U;H`vGRVt!y+(MFA>rw z)89`+ddDuafGyLBGdIgrZ3$Z(hy39Ptg(?g>HU%V@^H0QcLq>t>r9^&;l?uktpT@O zsx$<;Za{DRA{Vf~O-+p>)EF(S2rR9#rst*?+bnRLf~j}Jd3ahbArl+J(}S`U-npwU zva-zh=VqDwd4wbN-|m2bLC9sn$=|xa8tTFQ&uW(5MaFxKT+SmiOLcDITDIPr5~G4K z(5ERu83|pP!{4d$qP9W-2d2;p(n8`4m|T5)Z}9dw7R;Sy%$;%Niu?zRMA3v&WiKBS zrVXkD4K3`!YIGbx$yoRncn9N*;*VdOCs@A@hDm(9x6nmp9F3Y0ww4goZ6p}*KD|MS z8Skt#wp~-Aw*wwoR_4ymF0`AZ&Mznv5D|SoIJB|c*C!-MPX1w2RGG2JshEn7M?zxj zJzs%l?umzo@4Y`S)&W1buhM2!k;y4GK(#nO|D^rnt{aKy(0nN2P#&H{ZO-XnTxgX`VRtAW#5ZQMuhwuJSPf zE-rowgCQ!H{L1|i38WiUSrDtC1AKT<%fPg8LJ}5cACOZVZFeOov8ce=z(D`9j)v~J z%l56^Z60pk0ge{>dbZu&BUKqO+6KBoIi)Q%zOD{#PNoix*o>!RL458G%r0OIzKxIt}_ow zu4rf&S=m}ys+rh3T)SeRscK+irDLS7N31C%Z-N9`TaG3RHC0sfFBxd)YN+aHXdBvk z=xJZpF*dWdcXBn-H8;DWqkGNBKto4Y*TmlTvc8V4;YDLZbqyUevnyAu?3^48v~~3L zHFaIAt!*4EFP&96X=JFar3;LxuA`@OPTRo3&duA=#8R18oi6^M

      )K-xu~b7t7c?kZfjw0=i*>`&CJi$7~c2GnH`i8caX5?Z+9erb4Tky7nax*ryL^eA+D-->){0vz2(GEBre$vF zaHFERJTF>bOIt@*LqkJdS6d&tT~L_RG}YC$w2ZYb0R^e5t6$X8GSX95(*X5KRZSD= zQ(9U&IvSvAX;4cF;X?c+_Cz7w4y=$5T3oNKqk)!hXzJ+bp~dOi5M2Xu(bdt@P}czB zL-(eor>>y^F?4nHwY7m_HORP#6d@MeoF=GS==~BTt))RME`-1E2Snk1G&H~kw~m&} zg9x!EUQXwaZ>2Vd}h3wTRcPnYOl(KapU`Jp>j*V5D0y{w{j%1}!acnfWh($oM=L01Ra z)PSTkHGu1Y2-G!!8Z>pafn}h}Mps}HA}z20VNh7cC$J z>WG2}0rbuaagi3tpmY&~0B;eAAQ7}{3xxvX0#IC#LUPDPu-6I@C29~PY+lP zZ7)WQfnV4?QY<2te#b+yinVLqrBq@`h;8ph1JiH;d2X zEiRWE5fS0(>FI@x7Z?vu4-ZdwZ*MPePfvFM_yJmA-p-ZW^?ph4psL`+P~DsKe^1r@G<;;oz&WUe41BZIPKW@cr9`7Ef=yFrC~ zM^<()H8i=TeuG(L`kn}P{l-p#y5-d^72*Qin^X(H^?OoHBV?|g_g_# zoSmIqoSj`M?o<(Blkk;a;G|L56X!djp7alY3}e=KtKR7qlgwWXi>`=v^0rT6Uc^E zFd#p|`}090L&jeL%+Eo7}@dG>X-BaliR2i1(xq3#341M1uwm z5+af4Zr%!t&ndh;PnvspOI=+(?|&Ob4*?ZSgT~ha^%y+_#l^*><;IO0B_$=`Dl9B0 zEG&dSgegL%s1Urt5RN-xL@)qSpc45mf+{8&H2z~i!>O&Ug=^I3LPJC2KHdt5%g$?^ zCC&Z31$OLz7~+S33jUwRM?papz#3c>iaC9OrU?E95e_lFE7)N%EK@> zHwV|**;$1`L3{@C0RXzv)YQC>xBO$XZ#2)4<~zn)%7=go{+|c^H2-gcdW;?fXk8!x zSDLpT2%5J(3!1k+2Va}F{9>}Q8>dL~IlQ&hkZ@yik#c+y2x0o^{UY4`G~>#VFh4&Z zclW%ib}^1i6=FFimx$$ZnG9S~qW+YaTq+Y|xExbpa=8LJQA{S4O69m*hA9=e5*N!L z68Pf^8HOwHmeitV9uJ&?o?EV-UXg(z0f7-IEt4%Jc>^L`E|*}KR3gV9WvNsmQ$nIB zDkha}#WLReHhPXzT#;XdAK%LxP-0{)|nWy<$1D5SHsrFE2J1-O`( z7!eo{968AlQeNuCExg#w zF$)(jxxcqTKfFt(kVt@3mLxKTyfelxs1NmKICOyu;1{_>DuqrDEJ`^hmML+d7aW6s zV!2o*Rf0t-0V2e0cN|Hd6euwq`ci=Jj$>()KxeodUs8aqT(%^WOXX6Kmq^4wRZ1x? zfwX}0BtV5yq7y|1EO!hIR9QH5M$+Iwump@&T4{kgCfTjQVEDj zgeOM`WD2!dd7uvdTygiVkMQ|>4ha2-)8ftWwSWt{tn`SyronsDI0+Y@|Jg0MtbcyX}&CPP1Gl- ztEl)UlovUv4YDvyIA`vg&l8Q?s{mXEY2NyBxaVnB6gpX^!{A-UYSYoQQY_-Z*N&bs zbm|-*JHPqw|NP)$$&hS$xJXOojIm#y5-1FmuSL$4%by%Ha~0rtU1CN~a=X)`nw;zX=F!4ADfE@~NeOLSd7hVVL43f0lV^)6uU}L> zWfEO4kqc#`g{DVOpSl#tT3m$A_YPgHniUXw!5vV(j{wL92A$E&%#1>*l*%MhCDs*T zq!(KW{_-Up=XTniKD}2}rF~i~Vs~bgcHlBb>eaw;9xKtv>592emlVr(yL{-#!RS^g zE@--PdiM!kHy(z|6u^KA$bib}JBW3_TY#<{-=YD~qp{-b>kO$ZE6_?sRjX=@)n1-e zlotbiTr>>xEl$7k%&QmU+KJfr@RnRGa@f7Ic#>)qpU+!2z0N~|@intjDZ|!4#o($9 zhhK|$OWbYZ7DLJu``d(%+#**eZVs}#1?L{Vt4`L&)A>8 za4pC`<{>EN{vQ1!32?n+oYtrcIEeqoaep>HtFq6lfKcy(syXAGQbbmcPG$VqzlY zcnEKKMWm-zkCNug@s_wr<=F#;m9_S+E=!fBQDwvP{pC)%eMKHuE~VDi#+sjwZK8SW z%i!*(8CMipSmnuN_>yeYURP5gTI?Sh$StrjE|{$GvkYyV;|Z#c{APP%Wuc#kKL+D; zrII1WOB>qaE^CLhGt&%?y%$)#-0r>ifE|wAu(Q1`5#!+V?1)Y_HFJ@l-_~dbiHUY=EqJw_EJMHuP4z@H|REMk(k(K&q=rRs+%F&J_WrpIns+UP?%v<^4-LDnzt;U ze__LG+unS~WuZU$LyH@r&G@<6$r#tw^pNl;r` zYkuHl`UscOw-(dX)m>_fGxj-@l!X}C-%@gFBVK-4Wr0XT!Fvui6;eB68Z(wX|*&mODk=$aWETv`-^B0W|S>Y3A=8)fCvsf@p55IZW7 zDC)27cM^|=2E;bVaE{G8XDX&-QaR||xLhvu*mn5l0xnTv$p-q@$9Zn=oVh+F$K@sV z=BY9{)A_ZdMg3!&fBbPqb$x&LAZTs4Y#Ed~G#*2j`^RMzU#)=heKY`VX?b~Rc4i7! z$Q25?6vh!!2`-UzWZOM+Dc$U?YgNz&6)Z1r&K)2R8$^^Z~uV0~%^yq9>WiD4ejJH6QQQxHAwX&}Hb9hU!P^D^CG&U5Pz{P_>R&@Ur}0ZoZES8v^EVx@lWA+4QZhFYt*(qekd%kXWg*wp&s~XI!mz$V zzc-HBK*aQxZko5g4DRKv;^QA*3IA-GB+&}1g zaF30xU08CyR4P*{6+QW$`ewG5&zy9+&5bqGOP<1)r1d689B{#H^%E)-a2rTEnC7wk$SqBGc1R9kLApXn^z-85nMCY7ksA zndWgq%iPh~$}B3WTO?@L)VS>F=e*$ z>=PE!G&;8o`m9nRg987~7Uy@Ix85*z3=oYn-oNeK{Jos4qRJ--e}vEBEquIU-zVq1{hihHoTVeTAQw{| z!wG(+$!X`VSQU$a%q2q2k~4=iPrZH3(H{iT8fG#BE$#gL)%G5_J}Qbhy3-&e7jEgo zi3<=KbfbMR-{);jzYy=MZ@r{4CmgdskNhv|xev?P6mMZzg1gaST_@r4xBr|yaGvl! zJcPHdCzKD8=5u)Ke-Xs1fCm^V_h>69@MdX7EmZVDzh%d$^%w_R1E?3Is5)hI|WkMu? zw1pL5Oqm#Gb7vNLJSnz_V?5+3kqN+enFGp%R4$jHXPYFg2NW#9S?i6o?t7f>{P-32 zhC%|~nwp+Q9!fBB8K_)PoY*2_H3(l`f;v&KrI>gT&9^S%I20{+fyol$9Gs7|Uhr0c z$UM}wQYMp%mzSUyK@08Cnoydz))79-Ti*nxZ+^PP_F=EDx}&sQs{SV)vaiist|2M0 zrTwJ&j`7xa9ry4SvASBR5R1^96VQtslSt)g%g`b&BKQcG0P`s2%4I3^f(n^bu26`@ zP}>S6t`tkr>TBo$aTu-hB};PXM&-CnA>ly;w6+bcte0S74E(_jVra1&klC^fgG`km zEGE~)W4K%)TZ9zIc+e%It{P2Tp>_9EM^0D?kT<_-d2}EaFHcR+$WZy9@>4Ezp^Feg znW23JOHzW{FeN5~lEme*Mfnn9GbnBeE<>fggo}ZrKx>mKkR*&h1W+@?*cyiTz+7Z5 z-#O5{^;vwwyfxi?)U(=L-aa zMLsej0r+z`Ai?Jez#lF=s521fK^!g!3&3!BLXJSd<%2Jz!WY7SWasg@NQTdYaPS}` zxDW?oLbi|=2nq!}WcbKHu6z+>3VEWmz(wRnWK1MU0wv7nQ$OR80h7rZ9vOks%P*p?# zM(wMADEn8%gQJ1(-2p51`@FvZ4;H0<#v=nzgyBm5b|vUr_m#@3`%9MXXJp7+XwY~R zfL;}UMc#4>ObjpRBF+80Ma9E$NOXLB{QC9lVPRpx!NCy`5g8d7pyE-%H2z~KQ0Irs z$yp;DmthjJ>%-uxz%Uv3qX|3k0Xc;dZS(;%Ct~5~kOy1_ksx^@QD8n4PDDgKF8Dw?=>V<(gIh+LL|_ZEP|_Wr4%i=Ai3G=` z>?Z&8?wRt?D;Lig=Zp)K_;Qf9{#jEmh6u*?%iR9>u*wdZa#=Kzee(Q8_v~3IdP1O6 z6_uwsUOcT^!;laM6Nx8=a#Xa{T@o50xFg>Fg8CW%$_d0sNPUo2WILTZuT{sAjpw*u zJg=&H{_tsCe+h<5F;R&}u$r3Mc`f@nAugP4G7cz&NF=(m+)`>MDaZN(unpoUFbcVV zHEf{r;n{Omy-*^k+R%zYii*%C1SO%xLYd1-Jfr&O=E#RyDna7_0ESU@0wWU)li;ES zZ!>i*P3`J_HVXdg5DRbLsO}-{9fdI_DTAaPkR0e#%OG;4@fEQ=*#^%!f~J1$B)2TV zLqkKeXLeaI(P5~gY3H9nirw_nQq!~=<&v)Z!5Jwt3MmH*JPoz+39THuF4l&(s;jE= z^YfvUA?Y~=ud;bydU|?bVDR?s+c7b*Bf}#~CD&?$N&mgPRS~FnwT!ZVRg?ug1P)R5 zM+K6plV&GWUvg&Q;?{udaxS~n%_(6}1R>p(*{Oqq(vB{Lc-d+1xmz={O_g$7Tz`0n zCr<%1w_x{)cJE~Qtu9cHy009xz*(if0abJLsqRUmlP$@+ov&njHOXZh*FC387_%0C zd9IgFe@am>sihLiFyWNS#kg20Bor>R+HgrkrhrS)@yVDH z?SGJS`}ghIUONejt@u{Q6cPLYKw}Izpjz;daKS>hV<^?I^PJ50?)_wlh1#crpSSU+ z&qs`sAvC@gFiEP7=G0`aomDy}uCesY5(&E&#fl7PhcYGJ5U%f3^m(&TV|9@S-hVc_ zUI0C6oT^sZ^h5jWM+c*$quCEfdV2b2zrXdxymdY0dUtm>hG9!fONlwR|NK!(Pft%v zOG{N%Rc%deTWcH1TYdPv{k98dPab_|?}=$%%i+KM`JXTCs2N!rF7(^6dE+rdSE#3K zJ7;4<-K^mvuPaukx4fq5d85qz8$+Z*P47J-mt@>kal?xgyTTLV+vAO~KopZo&Ah zAlgYRmqM>6lrlZuQXg1`j&Ttmt$0W82F{l*GYWK*22j@sNyu&oXoQX??MY~y#g`X8 zv`N5W94{{p@PiS=Qkwd;>V+wbU+)|ycuUUja@2Fg@j-u|%IPZ4v~lngg8F9a8a#mu zmOvAbcKq{V96nXN$F^#|%+#V7Dco1x0^o|_OZi!egJ`|J0>`B89~}nXQYyDO4s} z`?gJ!86Ye!T>9`Gc>etxL2(;!Kd$}u+i!oO?JVS!Z2rIBJpG=^01T{i{E&E`2cw&47R`pKgQ-#w_x6G^74 z6QBfoiq9yv$;;f|45kxI43} zs|$SU>+35kE5SnY)_`JC?T3FZ?iJonv<#@7yBTN)I+J3t_4LNmoF!#hxVd999)13Z z{VgtzH6Gq_hK(t%9ex)%2V>7@1w$=X=A}4YQFF){qx3C#zy2%gEapwkQ??Kqd-YsY zAK!N4R?n(=d8g~u;1cro)(e1kI_zF{VqsXU-&N$%8NbE7MmCaR>y$x`${VBne6yP{ zT)9wgdB)VnC$?b`!}DVN8uqvV!{qpfWo|tyBeknFRnN%H&FA{e zV4q`T!+55yW!5wSVc3pA`w>kT1V$&G#mUD7bn%8Bh zbT3b@f&P^B%3Gj7DT&uwpvZ{0)5Shl&S+ezoySc-dh4uPWP;wlz>4k*f7sr|5a)%v z*UgHWGX2tq#J>Aaq|bw}QI`mY&hf zxvsM&IjJsYNZ(@ig$DY5{D1E@Glwty&L~rB%SWxV z%JEFSOM#`G87{{!xrNvpY;kE0I=m8^g@^EeA;#0Bbe9KwDTNfRJ#JqXy zs|HryF?~GAxeJ;QIvlm%_Qnhq=UyP*x-rsI7;!3N9C#~Zly`Zl8pv|9#%7udC0<$Yd}WkA7D9~&E6&L)tbVq4HYjJq>P~`#y71+4slDD@$fR;Pp zW2VpBiE-RF#&u4L&r~{U#I+~ttChm@uTZuJ+a+*8&r)!dNYPZ_l3bhTXW3)k`hMV) z;8RW~kMePJY_6zK-L7&-x!89uC_;fIt!{=omMI03CqoKxp$N}252$A;<%<4P6WhEw zNXXP83cXiZWWX&*@TIXLE2j!{P6r2{t-1EMrg?NuA-mr9Ohi5O&)yLMa@q1sj($=P z@tG;KqF~wUjdQ5s5g>W1uPn(c%gZmR1)S@ew}5F@meVM3aZTitrn$E78Vo6Mv0@RI zcWM1*-vAGEm9}HyZNZL#LTu6Zz?th~wden!GKvd;xHzN9`}Wz8LvyqjTp^vRPra1Q zArv`;x(J7~X{71i(EEM+eEa2hjFx5i4aaNI!_rmWGS?5l-h}Mh=RNcN;h3i&2O60&nU5a?dy)?=KAUxHT7JVqK=hbF2+=2B(hf z_Xedw#LTq|Dy>U!NE=4C0X=od5sjSn`O5N(fniu+67l-B%F!sX51eLR)G>O{#p&eZ zKx4>J<*1)<=bhr+AbCp;P3fKQY3|a>7@Rx*f_6Xp5}U#!AabH1+BJ6=m(Q#J@Xg-A z@`KwQpz~b!0CM{8^A<#ijEwB+>h9_3afztfs9HZcIXN>k)6mcu9v&`{NIr+RASlW7 z^hH%Q9esy+`RDPLax~-E(PJ7Knl8mdo!LI`9MP^Bt^wX+FS32~&%u4`ng($c>zKEo z%i&($ZjM$+)FgzQ<~?sPc}Aoxv1Nyp5JF^Ua(kZ z7gh$eCZBEh{J)oX>1k&DgeDSRNwL-pM8^E!4Td_2a^^{nb?4ZU={E$vU|)1V>w zYo1p<{ZVdy_p)3Zb3wO_oTf#m6^R`_JaQjzDTQ-qHhj>?kga3hLX`%;p7`6E?Wl83 zbMFa*>@jI)f$@iLoj$L5F{P)>;Gc)4gg7o^TI}CpmpXzgmL2w=Dj&v&3oK8*ee8;j z-I!P!r+r-Ytd53rI?}%sOES@9q}{m_r!Qz}X(!woWe=AgKXhL8f~sjiwG``E@Jed?Bh6dlnxHuJ!5W-D zVXLd9d2xSw&FDy>Ka`A??&ThV5)`R(XH|9`(;Ruof(w$jz#`{%ZGY<3>yz@9sLQ90 zUQ|DEw&3>s-MrPq=Omb%R5^EE%gUdOyIuk0^tE|wk=6ZR-U2{mP_4?!%IfRudwYBP z`}=R*x)mKA!{t7r(*3 zNA{h>%pY2e2A!l7SBR1NMt;j!iF1U|b%F@`HWY+H2+^Vx#F<0@V68Xp?&IcU&W0|38# zZQc?rJbd3V^j|z4FYiX4kB^U|gJWPo;LV$*kPsD27n9yHH3o zuI=8mY14~Op6%xoj}r|VYXcysugzPm$>xXh7L7Fr(fz>%amp&MKyL@6KzM-*{t|s9 zItrKcA^rfVpyL@a0CM`;yd~t$ z(!BMpfgp*y3<=;JL@6t76hyEN;X(9r&^aOpAxH+TMqZU)NdY-2L%0d+N~BdoB}p05 zi|`>x^3Hz}kS#hy>QUq^R5ED90Q_}VfgtOhdbtlMjPi%SRDs?B8B8AcM1#g710bib z&0Br9%O1*G7>0FrcE-lW#>dAeCnv|n#ep4iqJnAs$Dlf@mHr=-p)VQ(U`P)xVxkWy zf|yt$Y*f#NSZ%fYQ;H>MwuyvHwqghM2%UY0te_l`Igr{J;waKW^`=TpLQWQly6%0|LgzFwCl+^KA5QubI z(t5WnkRfHGLF3T?kki-ZEx<#0tF^T?E-s$QWODf8&H)xAF*Gz385s$QQW7-&QxKel z`ZA&u!03QqrRzkf9Takc2P^5%|khoL8G-x~u7#|-mcsO!$a=s34&Ckz=goFx-MQN!; z!@t-T$!4>srl;CkTRl8H1p)z%3nNbWjgiu;m}}Xxb$eXh{oY>zoF=1FPCRmR%(@4L ziw6sis>E=WOG;70zMUHn*oKlnT{K_0#VT#E*!rC}cBlm1fKDw}YuBs)+Ll~LbaFVh z+!7w!GM;hi?d{ukCRIUou>H+;fBf!&g<%m2?+J6eF@)w3YooSrc+D`1y-W@G@mt~g zuWx<-);Q5$D&;c`(c8DZq2qR4h)YX+R5opU)xA!#TKvt?`dfFr4Z`gS7j|sjv3=un zufFF=tbUiLYaQFNWy_{*XGgg>XCi;EaWoMFp)pw9>jv7#yv{&T4zi%KTV_n|ee0vw zUsJ0f7sMcSiwL;~N`a8=eL<&*gDMV1qrC6%)-rmXDV1|4^!IPxy5pT2Ef3zi`h}3N zDkC$fnf`MD`oCCIQ`6z36;kt{)_U$_wM}_R+(vRNW zcH*)-DVBC=+t#fo9(M5HY)8f}(^Rm)Lvq8>t(^X-#u}YZSW#Y4TwDyLjA2;+2s1vr zdvbEJudlDAr6n;bX=rc=$GNsIUFjvIS5V<^WL{6%zbYyN?fuaXherrXe8D;JiqWeM z45hdz%%?|;SG!+xYFGd|Y0XI}nUf6+Pvh8<_eV#H=NNt6z-F!IU$Evw(~!)W?$@7V z4b=@{a;(|*tfOKk+B?3LJ6UF$*gV;ms}^Gs>{q5#@GL*kX%ui>H@*6L(wsCW}SmGO0Yr-K9*4-wZVi zYyP~`kjLsG&mDa$q;v{;RQh~E5^KU+Nl8h-QgXQ*;v{6Z{c2}YcXxMlbMviRw;CE6 zfW21t9cw-D&i3uk{rbsGlMAN`F8}0*-+OJp9@JBms@~!Kd&9cY zt{y!1#t*-@%P2O}@U`!M|NFk>ENG=4Kl}LOe|WBYycFX8;0HfUtSvCysL5T%v+a+9 z%=?$3<+#XkYZA1~}CPlsJk=(zTh18B9;URLN+TRkZoY-_+bH`0}Q9VHjL zylL7;XiJKo^p|a_!6NJ}(Yvv-Oj*(7crI$(@BNH6o>DmXwi(*VuT+-#1eCyIk*ce5 zbACqa=UPC3NElo2xay!#lm>ej4<;C--lopPyXx+Px>HDOruFAqd3ayu)2HG_({*eL z(55j6MPWEzn(V(w?kmG2o;y$9eLkUUY?$q-Fi4~#)XAebasBQ)zJtyjo1G3T!?fwb z7k~J@|M!D4qsmc@U%d6tr*?dLZof#3;X?(#KkV;%P^A!+^!To)zW=M={t4)$E>!o2 zKltHkhb%I7eWW9KKn4ZDtFx+Umxm;=2HLh!^eL3_ia<$ z67_9w{`yZQ^K&R)kjx*vpSQdkvcqy)pr)b^e`0IY z|LyZ{GX%1+0#ES&e;-+)nB&oZdHnl3T|DiB%iwW3^5p-0@9~#zDP=*Y)b{S(8#_vE zB7Ee~5u=qnGaaY0dd?H+9pvW)o!CW3wNHNdz3*+h$|2kAXF%>dwl!6`!&_5H|N7Bm z(5KZ+;ggLq?j{$Y3U>OS5o2G5F?620^%Kds>lJIlTbUV|t*xy~OG^v}BPgliPkXX} zx7yp=fwaoX$~xLRR(VV92QSu+E_Y_Q_}rSJ&dU(go!+9x6XVT^w&t~Xr0OZ3CJ~M` zo_|kUsFXV${{)V1v?uOQRcL>dPIvd!@v)=S(WE&43 z4mR_JcD&BeVflg`7sunhuHE6S;biCFCPXBdB-2ATp$w_D!p@wK0H14i5x^W}$pO>Q zC*t@LyT``Hrgd`pfxM-ZEhmOVh6INMx$2QegX7%WzAk>j!NCdHW!%BKQO2^2I~5ul zYGv!(!d5H}*8~Oz>KQssO-&`1^-Wzjyoa~gjrQIdB)!3nxxM$!fiv1C-Z@b;z#z}d z$PBccT9$ixdW{VxJqo-9t*)~u_LAoL8{JE`AHEHxp|fwJM_IY%Z?_IGWHo92&GU_W6VAAGVw?H0 z4DY|;b*<*!gPra>=c(1hHL-fS`G$YdJ-o#o&Cu0EBbw?!E#R&7dd?Gp!K=?(FN1;` z=m<oP^1x@zO0RyPaf^dq3n~?(nt$9sA;6a=T0gNb_Vx9HA_d;MF+6kn zU#B~kh*yWq0+kQ#?mmN#(U_v*c@y+AC}+M%S{rX4+slHI4_A4%i`n%#=M$QLtWyVk zC+4}ixqbG0!dvcFwJh!07X;vp7+Ait$D~sx^4z`WzH^?!&8}79^7PBvxkJ-uJ~V+L z5o;*SGO)4{hEFZ%wHW+_NBNv582<$%79d-lt6^j_l=e061o^TEYJaG}*SG}Nv+{<~ zBq!U5Y+RoObH7QVb= z>j6D?C}it|CNk{&UMK^E*n;L0Z*SYa`Bm%q!Kr-H@OtzniC+`^<3GO$p?g%W$b?M8 zv!A~I{s+zD=uifdw=fK=3N_raW$W`7z4(i0UJ(>B8`TdXihFw7K)inH?dhsWQ*a*A zapdv%w&(V5*|O!lS1YK`Po0Qal5&EK4{zG`Vpj74)Tz&I)7z^{2p_~-(4McpakNLE zd_;JwFV}PXw(T1}IzO_o#HtS4`uqkc$(UPJByZs|q1&g=xMXyZyai-4HyF9=r7b&m z?HOZ=GaXKE-LmzKGuC8M&@*=C*z9<9#~W|F8DBZFINx$$+q>I0?R3eTk|{b@c?)!= zO4lRL?NVh3iplc{7iyy4d}Z^N%^wzY@g8tKp{Uiuc_}F= z#9~4k{~ah~Oneb1kEmhPU=qVZpW5}n>o^A-&n zG#(|a6>rJq^6Kj9;NXz-^z@>lqLh@Bz`&r64*IJ+|4m?0@;f8MF+ar7O^TIM3W-CP z&_W1e0lN}M-z&jocPbhk9f-EOA~8&k5sTT-e{xmZ%4bZ-uVbtpfI))>4I2LgSS#KF z(#p!p=J9yrbNrN|K}ceBbTlD8p|i7-lA!S)L%PT(_z8V@OSUXT6op9%`a*;wRkGz0 z#7{ECA}&V$i^N+8LTqUnaT8Czge}Pxiv*!9E0-}ju^(B?AlMF<;v5NxJ@oOQL4yX3 zZvkt|)^5-vf!r7SjzEbI+Z{nKN=`lWT%959sjfv2AT)BBw>680iKS!}8s zSb`F2_Wsdh-`nMLXQ+{C`r+e`Kc0D;I(cNI$p6Pr{P=B6w9P2v@(u{n%DOWfoM!eB z_++&4$}Lb3;D=9~M@Mg960eUof%8W{+R?_v7lxz%ewaF_4Nzvi^GaMhO z_y70!xkN~dAz5Pk>ebWmTLp@+%Ejt zgt7yS4(yElnyEhO;CE({PyQ1>`cq`*e4y@oKl#Z|i+hFhU0Hws_2Zik=#yf8hky9P zAHPz|xTil{#b{%|pN^vqsY<0XR^2dt=D}i*6xM{dZr;3ER#pz_Vi?xcGvyfBFg`xs z)6>(`)O7uNYJYz}xqqww-UeG7eATg;vVT=j`;H$a$Z=6YNzkPYb|RpYK(`JauQS=# zx?~Ol>Wky+S@_)G1cobv&mJxApPd*H;Y%GCHo3AvHxo|js#+~d7}GNn8Qx>7?ZIpE z_es9Ro36VYUd0>hiYfK;^ea{>MCQBAyJV8s5C2_Hp6J9WHZq8mDW@DgsDo;j1RSLj zkI;9h!sQDr0WO(1^K>Si+YWU2~tuTVDpu!IIO4PNQ73!*_h{p@*44 z=$AjA@W_cz+Ghymdnjo0Q(Nfs3I8Kt3*P6i&UZzb_}#+A;}$+iV(~mCSLAuQmnrdl ze}|mG&pS+HtS(YVk)R`o?DaDrGO)cRZ4&efK#}(ByJr ze56w1UD*n6$r#to?K9B6o(?Ss3UPUYYPH>^ttS2>R4Kb!=)LN`~8%_~wf* zz4+wWo~2%mpKN)1=kXI-Cxpv#aaZQEY6&g}&H>r*#wrfK^}@C{-W_9#^Srd7fn0Q< z&L^ylbIzTj-gE+Fvz_~2+xGJFPix1IO0f?07e3g!b?Ym8wV8~P*M9Zuf4+5!At=7E z?cMF~cnr42Zh7wIm!JMyd_Ctr-tuoO3(TkoZO`-IX?qj24S68hSEr+!*>?0YY1yYujVlCKIcg$lR*#Z85#u63)e23eetCy-%}qVKF07_ko%5(%r&4t z1l~%W!WL@0$%-rJ;*Hlw85!uj`0P^~&Fj&sg3wFwY@9WTr6R9WtO;*rXJvzG1rZ=x zU}F8B_hv)y*3r=cp2fw*ogJNb^A-&2h6;RrimCGnac0$-ttLxSWly%d(Jege;`!)q zDULO2eTt6Y^FMPEoJv8y;WryYZup zL9vpN2t#}F_SO;lEnl%;z+}n()|e8PwuNo7F2(u-EE1cD$tPK~+U}Cp1vxI4u_tP) zLOztf7{((g-`k)qG9qe0&<5G9W=-iu` zg;(EiBR`$6Q0eFrRa;vZ7MHfn9OH>3(j`HCeZ8rUVbKgOW{uYtXYAa0adej3KD01* zUH6{z3Fj;9f=a2CkC?>c-5sxN+P?XzV=W6yAti_fw$o4o#}6N z)Hxj9uw?e())!uTo>{48E@sIBfvlWe5ArC7`nx_GEkG1kr3 zfAy#B+jl&-TbE4gR=i8W6q+F>Q5$a`-pv8Z2|D#;C!3#A8S01NY+qZB3+mE(3Glw;P@mAM7 z)|TNBST~Q)H1623-$gD z%I_$kd-d@T<%#b(pHLxPf^ocyxnb@YcJYc6gf8B=WSaWm&+3xA#c9uf+O`Gp))4#R z%colw6-wcptzSIwmO(@lzC5An4cmY5hi%)ozwrJUD)KtTn($Ufdq+Y-;_U3~ z$jFFSROP=9R1FOcjg5`L5W~;Ue`b2-bIy5E@N3U(Rp(3a=IgGmUD)TH^VDGPlF~d; zlj2!0em8G1XLGeLcz|%evrf!_a9yAC)MfdKqX5UFTug?<%DyyTqr6^U3x^H{T3s0E zW>?EYRVx(;W<<+4&JR9zWOAa}&NC7`v4x)VhSq3ONhz0CTDZrTGbV~Jhock975L2n z$0FWz|3RB5P}&Bfc1KptgTEl}>ZSM|;GWA)?wpaUV1%bk5UkOTLPsN^s%eBXZ7@kTC`N%K&Kl#294D67d0J}YJ z|0Vw!KFBKO7`&DwJO2g_=)aDizCOf#`1ypG#Cq@9LKs@`C!AcpKYKo5TZF|i9mBqP z2{=ww;Q6Hoj& zv9u{{MUIiJ$!Qts~14+~C-rfBj*5 z7twH(cyW+>6ZE6}f~&v%{$sy99Z!B01s)Wy(=R;n#1sBSqvSkcsrQ8+Kk?%?)VyWO zLhW~+{n3wpq>lYa&e$Z+NDyU!=Q?R)sg zPrfn5EkV2m6*`gk!V^FK(N8zlEGQmuKB0U*_>#8-qi8JG{KFsr?#bh?zjGgNHO5^1 z=}&*Q>&*}ICvka+>En<8=mTdL(5*54%z-EW06*%lMkS9jZ%L&^AqiDrfok&8dgo_9 z`+3cTqBq?LYJcOWy3n%ZQzftb`0>Y&1dy%lvsgW!P%f8$x?^kFv_d(U_|Km{@sppt z*~`T5IagPp>`OF;lz+bA02z0^Voi7pz+!a0V_aqb`^FolCfgGx+cnv??V608Ysbm9 z&B?Yg*|u%lXMg{{^WZ!=J*-!~T6^8=vu<7Qs}>DCAwEHchL)Cxo7>9TIw3y3uD(7c zWdwcL@;ybcV@YuvPPR3$>G#dbTm%W%3+8(gBXYr_U;|8?DzLr6Og?Ok3BesgtU!A- z9z#TFni4Td89~IQQ1rZsOekzF_XczN_(Mq0hv*I;=GRf*)j8XxE*h0i|-M5z!j9o1+h}aD5g!w`yay3mIVkUBVs_`Be%9*jY1A^WV zcZ!X0{D!3a)8?B=IGBi)aXmfI&MuUSeqOMY{r-U{vHu5=d!I721;Q&|U0&MRT3(!; znba<>vD^cQ+;E^)P>4{WalSL7;R*u%trrwE8}o3a5j4-D5z^q?16tAl$650JuVVaN z*U`bt$awYs{vI404B9}}&}eRJys z#q~g@5JCvFkgNi$l%eazlu>rfM(sS(PKMCS6HRo4t!+VEQLM@IP!RvW(h(k1I?^yO zFwoNnabAePC+8sw=h=hgd+h8{MO9xUWX4T6Fw)VkCe%y_aWRRyam1n;P}d2O5jHps z611CPaxb}I;NPfl=V;f zJtOn+u4BSTC~3r!)}v#g)e%7(F+j4^yX7`HXZ#fP_4XFwfQh{6_4J~-UprG9SOL8e zkQ_7o5~yhFREeweOM5Jl(~agNY3Z{|YaunPYbdCm!s*jAeZjeJzZKhnzc6EPkevVf zrq3&2%9Bza63XZ~pRAXpLL05}Bc{9iw!(8g5XXRttHE@SwOZ}r8j7>J{CbuA$_gQc zzJIOr@jkd&?sPwJ6N(Po0r+&M@I_k{&dmsDpxXtx2)!%z*=kYCH*-Iavrc8gSa$WxoRYFO62E(EMYU^6^;GJhLON2`Z8SUQ`kfk<~f}LZNu8WwU9H%Tij53?qj!?!J<$yzcW&9s&anXdO`>(SkV|)(uR;`9hs+3E06vm(aYPq@{_byqt@ zmayw-WmRhaG%@nMT%&p{QP_>K;qCiRtcW~7c-Ouz6kL{MS>lA{r)&gwP7TLxz5K>v&?!doeag%W6Wt_3>e}0C?dU1lSN0VGA zEgKCRl;g&`VeaRC#^|ZN9Nya0^Y+w++98Gn!B5o5TrBO$+4%x~^w^m+8;;?8V7M!@ z<_cUVL6&$)A9mw_I~Q&?x-RP7$S5FE8!qN9%S6^p=)nAOEdAP4%+(m}SX{n~L@^Hg zENp=a>a8!*@wSi>mPfF$&N)We<^iq$o3re{1hS;bQelXjt$%husr+e3&&Vh*E4$>$ zQ3MTG%B+qr-`q9ke%B8^rnq@|)OvbQj2zyNpcl($FX3X0lBy|WE!NXyjB5ZryJuEZ z-lhzYYB;zXtqY`dzppo!*N*P=Nl33*v%A?WKaK?HKsMhSC>_x`Kp@IPMxQKC!U7+w zJ3K#U4^((^Vybj~b%-R!4QfrL2BbF4h8L3F?vfp7+s<;Z<0rf9ASSXx4I;C_qjn!PZJQzev{;A@Vmn8kOfj^f&_#%35&KSXc ztUP~qi5Nj!rDdgYd*2YW!0T9WBP)~rm==K2>EtT;P&}2RbZ19c&i{D=JA9n!J+kXH zHUinMbevc+enGZ=HUAzH5boGq=#mGiX^!Y1{|>fVVU!157Wsn5`!Rt- z#fqZ%tZ&ji5wEXf>!<4*K z_rlLXekV4L!t%0-52dZ;zj|^E2~@ru{+=AhnQqa6yRSo!eb?B451l%Sf3c+&gDz*q zGBi)DL8g8Gg#1ScHdqLeYP*(++kwdv&i2p%uk>RNuywXQOon#yafCi;x+-2}p_JNx z@uA`KzL)d<9L6f*7|F|6K-TLf`19`eR{L1Nhs>RJo!lup#%S5gAl}sE)VXY1n*O(uFlg4-V0GU8`f+B`N^T~-GGG|o-#bt#n8CVUz^K!KkM6pXP_z5^}rx&b=D5Uo*HV^G#LL;CS}FyIDMr{AshbgrV~GL zf#_KS0SslvN%55Z(gT-*?UH^i=B~Sb%Ug-==B4G82G5y|b7e+IVi6T`f>D<&Y?G8- zv2rl2=HnFs9!{n6qwF6z18oa#Gfc$HU>aX0UNQ&W(N@dk&`C;F8u)+f@D88jgnP0m z$9G$VD)6tkUAi`TxWVFQgGkZv^ear$hjioq_48+rf*I~+4zMW^e9Zy|TMJ12q-Rll zfaGG;$W@RyTW{TQX;||EYcOCEXzZ5aW4|9TTz4a}pIO{mG|pG1q)R@TCgm1d@_qBR z(qt$9Q^eN`kQw845c1MgYX`0GXsxu3zS8bSOf$=C3NLo#@+#Yl{}&J^)u`uYU-p|S z$cX~r%hI;qG^+Ej7ax-7G%W=Y>#A+r8dG1C+rg&yw2_q+4QfQEo*kA5e_3O>t7cRO zv~8>yWioTozhCJnd)7?UtLIY4vz9U;B%WgMg_Efa-gmH`T=*JX(Cr1USy|0Vlk0lP zzlm2uWo0~Cj;7+tIR=zRJ%%ZlKzO=IwrM&|H}J3y_rCdA&&RP`l6tm#4)^zoE7x5n zujRtieJ$atD8?R9e?^Ty#N>{Ba)-+eROYiUdEE~bSTNOY)>3ppNy^DpR#lxGAH#%~ z^SU?Mf}+F9s;s8wdJs|gBrXDy|0XqgYPrK539m<0$IAKOx3{q(33CF6SD$U)-Be}= z7OYyfl~DwLdU3~v52A~&WwLAG+!%;q5QXn?_p%gY5LT9>X(8zYN?)8Z$_NC+&RC=& z5OTa9x%Q^voKH85Y%O-AEwcdoa*40p{>scd9=~w2^0_!WO#7N3)mLU;;{G&9A&A&G z%NrFSze^6MR3;0Qq<~m#US{RKLl))(PL5yFpfoU++tUklbEj^Xhk5 z$j#o|V$QTUAaAWTcxvbMj@!X*{ngz>k^Nv4>-U}dDgF#a9**=q#c2)$0@KI!`l+nC z(0^nRi>*xzrE~r*LN|IY!E9&nw4O8l0;(Vd+t?sx!?}BGIrvGqPQX`ZRZ~T z3JB+!c@7YDn+^;2`4lvj_JWj%jxcVRA;u19t_rB9=?C?~-r-T+R&Hw@#wx9xnE17I zr+v)d?xs4kVYLkv;J)#Ftp8Oa?^-78dKvKb^&0fi3f2(y$Wz3RQT6`hDi|N7x&kc< z{}w5~<;q?Pv9j&IU6g<;L1#rg^H=}d;e9{g+x@&N(|qI*DNyfu6s^E+E3~sHa7#gR zV4f2cU%a~>k@k2$?ARa=O{4nOFEtM?kKJ|muU?_s3!i&xB^m((4l?d&3hWCpsYUqc zWp~J}ZPz8NahKjtFg86Mi;z%BTYGhJ5qc>$c6xW$c-od47S9?iEOkKVJ+nTorZkW1 z^|I=8|A@*jUxL6I9{V-hp88bLhOchF3b8dRFafsnT&6C-l6k|6dIKH(=f z{5psP>-Pt-a41FTu^MK2DwE-)V8szMX@vSj-;5tSFzC_wKcrT`pf9#{IpF_A@_p%5 zZ~+`BZawRBbTSRTc%=U0$?lyA31xQ|iPDxO?h7p&hJJBs6GZwKre<>bL~+Iivwai9 zutg>{g+*bY2?Jf)0liJ!M*0Kt<1>#px#zxP{{8=;v>QG4wO+7UNYZuKe+tQG$p^$* zP|jJnnkr(^48nuDR7+bjl4EO>!(JWttHJC@`HySj`#t(rZx?j|+p=S{E!WecV-yT~ zlZP({BTWg!!_+3aOLdXoBMPs>fzY)+k2|pnN&SZ^Z&a4ssfBa{I~OSzqMS|k?Z*Xs zl>A)2nDpv{4n_(iNHJ@+Tz*3_L|@Mx-#z2d|9ZYYf5sqqwM`#2B#wf2*OxwQpdM0! zem+c5h}XAFp=};Rz@t9ji!zQ>6k?t6lI*Vu2pxEP6Idz08=&msELC;%c8Mn9Yoo2m z{n6^+)xdnS4@#Hj&w-9oc}GbmA^d!f7s-K|*@*vkJg@~h*}BVlURJ}R1J83@}2K7*d_u|p3-#|H8wa(pmA?}*XlF;co{0zTK>=aIxg zq0y%?p}cL~kFjonRbS($_V$dS5q}+Uhsn8JXE}>=?DN;y3D;Bi->#S~pH4YYt&=Ea z<7P`^pqebaza$(ed|Yl)#PS~WG^OhN(45q0bR6+FhAkIxK`X<3+vZUY!5Oqy<+ih2 zi@ZlGE^0E7L&)uOA32DFoHNq)INx3zLwF~i@kbp#l8k=3c7H5O?s2NSn!hcQaVPvb zLYyNw8KVcFjN5>v`t*$hTw_Oi7sCd2bxhb>Bw5;&z!(t--&d2jOD}v`Yw&R%W;%HJ znE_ZIv2@s(r&g#!Bf9ejG)s|G#Zu_;>V6VsMLZ6JyNi*Xv#b~*c3@)fQzVQW0X#}6 z@;{3>NnMrlW5;Ivu%yy0LKxG7VxJ6vD{$VS$vpR6>c8fZPSyACE-4;IjSK$l)|wus zwsEYM^cc|H!cz4P@Ls?Z+Q=%o-z;HTJi%0DPPEvhAX|EPqDvT}OrTXc4B9PlivMP= z{(!dybu=lq?s_Zj6Xf-K1AhRd5T|~lAzGPk)e5JZ+hq;oNGg5&4pBjcghKrNwbN57 zVYGFlsaL4J4#O3h8%_T?3+i>o@}wQ3_%(%Z^``LW)QmmN=>+`SeE$k z#oRqJRbKVhR{!`83y>A2x;HS)POgkB6D#=BqBESD%b|ly3KC;X((QR!c!>rTRHGO< z=Eo%cp?hslpXBb-zQIymwu$(7zgYSPpTqmOY{D|x6_;+l(q~zo2Ta+d$I0k^tr7}s z6uCK{&olWJh3W3mrqAWG3P3IAYV*zsQShriy(u{4zg#7P(ts}S@`#n z{1>6TejJeTv{R%Aa$qj$+WfyoQs49c`lk*`nUo|NEClh* zEsa=9?;x?ty2))PLt2l5K7hg?*PzeNJW)Y(HR;Hcf2FIukeS=H zHa<8Zs?cd;{{qSvqdOet*Ct-3^JpQxpht8>xQh6>^qjKN%;zgMDx>5}#hFvu)u+Z{ z>Et!j^+8TEjHhYN_V$6YM=X&K=+HCgXibJMb*mK^S$F#yGrMQI-wSX6=x3?-D7PJv z*QglIBhPrEL`E@XU;ET5Df3m6>-DF?b8xO5xi?sX{uAtY5LEJ=(_wR)FLG zp2QQ^ekgS9q^>A@E=%A}M-Shz6d6ywB-iIQcOK(3u+2G*T*t?C4X{N=vF!t&Q%eZ! zaSTV3{{Sy@zWOMB1nAwhvx?Zz7S~F$ZdK6ZHUT9o^HXgTt%$GdFL&)joLUCuj?x4=XGet)gOY$FB-l~wa(rGpW%#nrlE)&# zV6wZPz2&|iM{{33qt5#BS$C=qd?j(c_qXsqqM#6pahA;%SK)rjyz94H|G+lEF{f+5 z#x)%W(TeuF_ROX}^5p3Dx<5~HK&e~NQdXY-DGC0p`E)3s%+-`zj>2&H9l~&)nXXLd zd;K$nZ#m3u=>FRzW#rRcHy;O5K?tZX&$em1F767XJ>p#$Tq};rjdXPOSzA?V|LXg& z&GMFkue|z_CyI({lZjFpI=O?r>Z1WnQ0m>cwSp1kwmC_9CTn~!`97-mr?KtgfN|-Y zG*Z`KX;X^+G*F6*py>&YX@+jYKpZjC=CD5M&*4XBo}B+|*5~L#kWMlQRZ+-_aT&p3 zI8l4^%?L3o`}OgvQ2l<;+TGy>?Jo1UF#mjowiw=gxQ4IQ%pv*xSJ>OHM@)ejI+Gtm zr`bnH6!8#nQd40|`ZpbjAJ%V|-8Kle8H2^AUx0-AKO62l1PhEHmHqe{4Nr7EHYWe+ z8=>ju=(Vdw;%IoLEQB@)Aq1UJO^dJB$thE^r&z-^ZIjzSzQxJOs(*?G(S{KnljLjY znB@UEb9sTY(t|tP91VcL9?8KkK`RwBN4@0{YHe)J=fhg!7}%RC z81UrfS#bUM*Jv|ed8E<9OvU7^a*iQr)(?Zd6XS3G#2^LIY3;H$DZuzIw&(OqV1C|d zN^=Lk2H#!iHCBE7?>+e;sB`_z_=l{|3u{t*QI^@Vfxeb}-0kBHEAEco=DX#Xl1F`@jGnHop6Z>&^w;>p}7 zSM2*BOau>_yoDXNe0lu~oove_!9%f#l0ql4yK`*u{OBEz(xY~xw zKX7JfVYknqmKNd*MeQU`BsX~ z`O9nWS3azSw{9~R#V_;z%yvf zuc1|eTJEBJp|sGwVKUsab`5o}Wp~=c@l4`BFx*E|y(0lT&Gtenb(l98|O;GV9?)chnlrlt^StZIey z9B466TVOT|3q?)u=&t$Z4I8C{4GTdDd07!ZeAkV@FGdhqTDF`HD=(ox9JWVk(`QFz zI%b5G@{=mx0XN5P8ouHic?-h~xL4Z@ib|Y`uQ#5z5-xb=iz|5f&>5^5o|9FGeNaOW zIb8Pl|0*b2*wLeLpv!a^rFM9@=S)7HkMCk@!jLS%?sTm2f!TP^p~qkqU#%DXQ$ZAvoc^Z{OjU6=x4UkMA`I){OxV2z5X zsbYkaTKGmzr}HO9O~Qj&Ec2>d4!DRDw8B~UY;0Z;=2UfUM9YQ>Qb2SJR>2)BlPwlF z`g+l?{VwE~lgQBPmCy9dHl;L2X6X$hb&`v6q}g>(uNWb)2_1v9X2BJ03wLG3w;%cs z)xEL@U#_*gPut&ERqotA???0Izxa*`JijJuD`S{S7O;@P+0bt4zESJ2b$LF=fRbm& z)koh`-zN{mwAj|I^XwOWye+(GwhlB6Doix$TCc2BGBU)K^c}_(xq>U6ZE4xkp1+Ce z!6SuCB>hZ(5vsP6X)))IMuei7&SJYk4W(o(?U1t%LJM)c_XA!>p>bcx)IzdB%vf#t z%JCv06FuQ*g(cMn<>+b{E(U2>q*f;%-l#8TD%2S;cJQa+o~r)+^5AVIHVHqY{d6Ia zNy}dh<9~kc@G63IX~HypGpTBRkN`g@W-L+4@wPtg&aGE``;;3kzxZDbd5E?akY-l6 zIjDQ}XwFcq-YIFAdv}3HWXpd8!R~W@BL8FY5|{2LA@L_$o=KAZ*5Ch(|NQ4gHhPPm zm9$3#G2prDaP?MwN>*5wevZDLvb@#EB7Bv_M$4}oOZ>;`bnveRAv4bwFP(2q?8>d| z5NlZAk343cfx8bdC_PPqW1Eq^%|TL4L1Rr4hQp%5R4hCsH3V@uZNl6;b(K4HwmY{3 zJAuf=Km*q;uKE)OCtiZMVNi~#z(%y?xXF3gWNO?lBAg@k&o&^ns=^MvR8{&8%hp2V z$7)47HmDPMts#7)A#xKH2tE}R2qcHu!YK11NAqPDy|rTMA{PA=XF~nPLTjc%)s@!b z4^D~e-28Fb(G_u+u~+&07~@xt&kLukD=lmlIQiM!V~4dCFYtmtq4R&ATD_J2janCG z*)mR%7p7jGo4OsW%0CyA)ZK-j?_vg%(Ksl5zo2&3M1&6h{R)BXqc(sCmsjq_x3%=ceAMhl5|lHAhZw|w})IrM`O;`VPAWxtw5l}`e$JssQ) zS+i#%3^ZY*()t0e)U!pHb{rU<@z<6N&>T|G0%(dwKeMDTrYviUh6#YK=Gs|fS1C27Iju9T5dwSNBz9x{2hfphS7^E`>;B|+wRDK97l7~CeJ zq{_3VAh&eNq5e(0SqD(Hi|KJY+G~s|Ax}--+a`lrmq<)Wh@*72!n}K4i(4*o_p&&i zOmuVP`1F9f)b{U0jaqV5>_A%$^z+(b>JpIN;q|vJCjOd$ErI%1fW8#mNf^|PD)x7K zIp_>!r8I?P(?9h0MjS?wk?0N&si_Vz zRAFphSGMe3yS2I${J8I=jw9Ej;U*k4VV%@T-2!aABJ#I3h)sycHrE-V%wMf@SKnE; z)&Dd@WBqPS7>(&mdLUWPM`-Q}dUD6^HV4W3_+ zVE?gA-vWW!G)ZHAtto{1`yTOWY2er4V_by@}+-SmM%w-osQpx7d7DAMeH2 zZ3dgCF4OiKWI)-IWFiCf9$(i~KWhsRY6k*h^8E$X{3#GT7RHR8M}D{qGuy4?-plu8 zeP$HTGa~1z&1!c&oyw2sXnSKy(lKYSLBl&JCuj*1-cQ<*|L?Tnp@zWbW?2KhWZo zYyj^F3PY4HHq^DaP`5|rIb=i0&DA774f^4TBKzte&lxk%);sfc@W%zsfjf*ryAn=G z%uH;NDDscHJ6XCZ&K26Br6^M(^4LCP@Cr1#KJ2J~#8HOA?LAI?W}2z1f#x7;*T96R z8~KFy==3iJ065{e&fVOehZ4c!;S#Eb<+q>(`uNx6zt(y3`xi1=HZ4gZH&~o!TAWmx zhm|dQ7_-fwu)r6&T}(1#qyD{>cR!}Qeq1nL(2pd2;x~DNcXKYxb=59EA?K$)zr`4I z^rr#R4}7W;4b+*SpM%@RoYP;YAYyNt0CFDd8~V{9snXE1Oh>Ru_EzcbBshdLD~|5X za@1eR8g*txbQ1-aZ}g+rQ|BxIg+Y-AUg?w#CCTSzH*X2eSO3du{UBKN-|h6xK`AP5jNEX0u*2gZV8 zglS5Ax6o zUIFI?>72po!%uj%vloJH>WeJQ8c4-09d%gAIHdEZOz6j0$*8qFFxR9NT3sitU$Yfc ztGItN`;Kf0{ZvC4K>b8X{ijwxrXRUj36BloNAFeR?(`aO0-Dn-$)d`Mcgo__Yr1 z4Cxozz7q?<*H3~@3$E0F%veU;S1C9jv{V)(x2i-xu(U2~%tyQM_=bu}bgRS-+_!Gr zfHO12?4I88$p_m%*^SCdy$~y!TmNE)sH;@b$rnSRZMTu-XCb^4lJ~>d=1a8_NqI`a z3yxvkgs)r)f2O0&W4CS}Jdmk&Uv2(HoIA{5PJSri9v1(ux4zTv?;Ls(G8g17oN(({ zXRO2aDO}>{#F?efUy%$V}I1ADifuuv}Cy-_i^jK+o$y(^@mXL-3 z(`6BqPNeMrOHtJ)ieS7%V$apsL?r3Vk=6XWTv9-`O}t6f!MoLgxzic}HFCtuV>6sg zi`Lud5G?&Z)hIS9foSn0BQf_KjO|yMFNf|C-^?wY6KmI5dvVR_VZI$(i-4s!|CcIG zn=RyK4G@QGOjpqj45GXYq9EL$7?Xy(!#pZ?;rVx>k@#Xl?V!9`g*rmkMp&zaqH&(H zW59c|V|db|m1<>({De^k``6BDa7)0x#RlL*vD|>$L(BYslj}oiD4)M*99=;_GpDhctpr1^ValFBwcy&ZW+&GL^N);NipORjQqTyq;N!7w6aHQi_7+{>J zm}oxb*=MlUEDE7UnzFLz%gd?CrQ_5;Uhm$RfBq8SFi=;|PECb*@e}aPM)s8gqB*vD zSy@>D)1HUlmmn#OSTtiM-B6S24!EF^eHbw~F*bN36kY?IlI!WT_5&yrX#HmoS&n+T zsI*EgnH9(eMJp_?F&GMxdrT&##>bVnGBNJlg)K-GGb4WXpsc^F=7tVI5S1q0#?iya zfqnNbd2$Mrf;V&wmhwVS7%`a)a5BR?D2ZjL+~hKhn>u8a2BAQq=20V$a=%?#Lp_0y zhW8zYb|1q_|Ac1e<>Mp8DhPk$j*Y+;lPPr3>dD&Mv<$Yvdb19=*%G9@U%b2A;yRRz zM7PpKmBF?tU-aI;(Ia?;Cd*RPBY`H$3yX`%@s0%A6p7T%YPDQ?u@l3?7Ut&Wf`UKi zNt_GSf5^UGeMIYNlwD9h4kRGV!}_Q-V3K3W<{>p#K0Y3KUAyUl>$DiV9H<= zDb%&cnU@0pI)Vp9E|^(iPb?-MU~dl3t`#ixn(YVfACkA{2xR{hBFakGFS#o3+CWRl zRLMMYx^N7XojI{Na^m|(@p{;!s&Z*0!>+NF@iVzB?<5|@^HOcXAzmFLV9^}W@m6>J zV+@9af5t#7*1)g`SgAqXRb`8wPE=f{6oH{mBfi0~in-6z_LAfXZ3Pbp$09<&VR0D8 zvHh^AAJXq{-{}S!K7{p}&}{S7kR-y!WYc?GDquy~K>XGwJ`{x#a+db8M4G@&o%0<6 z&)i_n_LAkm>nEu5ddB(&fd&V1;F&FxpxT-Oiyw7(v@{ZEae=|ABM>PK&N?%0`N*Aw z;9@1Y`r4jS5Q{`}#WO%v28Yb{`V%mieOPLS4Vm(z)z!y=y`uH>M=Q`(qpFemrWDQK zEj4sE^AX65u#`MQM>K<>&MCpKM)W%P2Ede~-!-OF8>5Qz^Fl2KFNAo8Hy)FA7Y&`l zA0xw16XK9$-sbM70f4{#$-1v7C*Ab+w%r727eTJ4e$M1*QdUAwMd&M#kdT6AAQMUs zz~=e!F-TD^No_S+?Y|EvO@l>#4)&n3+WW#}cqIRD@cT&h*Pm3!cUMmlk-kF1vf{i4 zbys=srDt7ppsVX6jtWBF0ta9pYaN4*8G>Ej8tP!8#+-+S=TCFdn~q>nl@r3HQEnZo z^6=zjs}80nWe>FMFHJ~**c;E-L2B-=-@YiPO}EMVxb^7EkXRcdV*%fd7=J(ZwnP+lrZH1Z)b!^li&qMr(~rbW@2l;=%+FW$Jc zHMgyzp`)}EcOloJtHlAvJ)-^_q=S^pNYwi~1Wr@^V0)fl17d8W{}VQ}R#JQxE_iFp zp&23X7aziLy}NDm>7S`^YaY`v73eirEebVZ9qY;pda5pZtf>O8`ud~5r)%}>gx0PE zAE7l~w%Rz(3%+&*NPvUHnjlNDCEVq=jo(^YN+(oN>mqd)qxRX2cSjDfZNrLjf=}m`CuQpO=)Rq5Qq#?FLh`y zNFVUI5n`EZ37(*)p#d56CuqMCd|-co=$*5pgmOuYyvmwlY@xr@k2ncIclB0&3Isz6 zB5X)bg>RqF|1Nra>h}34|8zgT62tLh(1q1W7Fkzlj980KT_(@hP{=pBow^@$r0u^| zONPc1{CPhjGoWszVK_*2h5KC(8uPK#hy^{U6U5Cdwd5JmXz=9 znD6^W&@&ec`|-f-I^+9^TQ>tg`g^uu8#kj8K<|h?O zWAWJrTR0RWeU~Sp&t?CdG=hO5+75Qy`YF09DEBeuTH^6rUPVA`xrT`EZ9$JtF4+r# zhgowpC0qA&efr2n2y++u9_lY`ol|miU$nN@j<``!fBj-+R|;6r#$g>tP}gh!&eOaL?&LV$&XL>?Um1 za07z(*57WC^WHhi>}Y)(wqP_4!Qn@?^}knB%#KKO?>#=J?(nF@jRcOIVh;7{=hfy*3}?KwG)ig1d8 zK7S}U+-vpE?d4AatEl*oDd!yt1z#I$>m!tOsg|2be4?v#o>z6fK#^58Zj|HT&8xMe zHO6j}2D&}~r+x%sGBm!T*xZSGYpV~~v4}X)k498W51*S1*__Wl*haYoSsArbRi4Wv#<9-pWQiLD#&?6p%Ar4lx$Qc1?fGfT z4gw=oNlZQXmPikD`29ik-=}o#xvH{eCl=jLrFr16I72*Q*n)YEkoRumB4WI!S%GJJ z<^mm7<~xLhuyKEJs#FCb&N7?9>g(&>c)BS76XWCGprB%+qd~Nmc2QM6r#3S$FMQS3 z%}sr5Yz@VK{4vcnejsCv3!GGh`iAm<2OuT(fH+d^LDGzRF7rB^TWxigj{d3MLi10a z@;P-|&MT$u%3Z^h#JCX{?}BsG;4T#;T=$V##LkzTw4E4*eOY-q1+}xw>8vw3XBlA? z?%S&QqevEFjNt2K_l_tDD^HgifIP>yxQ-zDIsv76XaWwgH%2Hu-b7>TVWsl3xj9x1 z{47at>xxps%$XEfmZ4`2ffjA9e4uY_lfGdRVYwPDN40iL00zg8K-1GK{VU*%F&s2KFH8AcAtLQJLZb(3Ree4 zOyX1r)@thI=wWhVBB0B~ZYZQPz=Rb(G!sShBP07mM)zU-eBVO;Lh(zk8ot-Ip1?Gx z%Vtc`b#p=|k5bKeO*0n&4iFk;#&&JRlAT(B(r(2Bh0bx1y7_tcuP)?0Li^w+#;k?5 zRqolgE28$xJ$g5uyP^@|y^Rn@v$R~mfV$jP-4@jAqJ7X-I|c4_L8|Ty2;3P@`1S1d zJ7c`Hf{2+F{|aAsyrh+#n=9qgl!zl(kAnrlmMFZXr7;&d{h+gaHZ&|cF4_JFfBsDB zwe#y?IbwyEcfUZxxO{LZy^<6#AH&h#x-T@o5)os2W*V*Qvr~C#N1QY9kC{ADo(RhO ztp3?+Gk)YZ@*%yTx3@QF=@-O=G6ITd8zEEa3u-$!+~m3lQT<-gS!*xU?9x+4jpnz*Izl(~=r3sW zHfoK75AtM17LR8{bm;k5Ky*(M#E26I%H8>GYF0X}(q4v2?S6|+N z3kR1ZZq3C8_uEqBsySC#u&8kVFkiGc`&cVV24b|MfvLKt#v;8D<|02YzoewbT|RWo zLCMVtnU~n9zWf|0h{CPd}37vf`Zm|GfDmNhBkpxlYgXm z&Q6PSt&+`Y?i}yn@Pcwn94Mi&4GT$6M$0j%?H^^QqB_QrQ2D>Xj{iBff-+TVZfiOeM0b{%`CT0i&b%DTC+H}>_s3b zuIY3|rC2_TzrZK$Hc!x0BIH=$B2h{L2nO-#|pfGk~8rxyK|tcO&l_eG%sOtMzx9 zjQ{>xlnY#0`VxZbFE$G=dc~L-jUnvoXBeK9r}R-i@A*bx(Jlsc|87X`O`{;6xB+TDV{5j(g+=VxLAa=}q~_GjQe3<~oIosudzvzin%IE?Q#*1t-6 zR3T9|{#yeK`hP?%A?y&N7W6`<^`KD5tCbg0y93?6;Q!g$zJ@;=Z<0Jz?(7ifQVj>O zd@DeqzMc-c-9^hI+f!ue$HXNzl2qVFt{~~MM|D7SxY`cdt(qn>h3U%o`GFcq$2%M( zp$JNBzQujTwfxx^%cV0EyB2BUTdO+(OgVrB;2!OqDU+7Il2 zLh@AVF|+@}nrb5qx$6iDx@qi~u_Fl6pClr7v)5W)6hs!{BnLHG5Ic3TQ|Ws(K;B>2 z%!o042NQShXv8tSMt7|&ScN^=yVooDUHGUNDd6*cd)I+B#1j3eOe+!is4;zpVPsyv z5{UODDkSv08V|X;La;ERhg7R+&7Hq~hWMrM6OA6uU6(kA76UB9 z!H8`TZQ`y7>rhmgfhj@om%v7`kH^&8RY@{y@kYZ_*V|`R7QolyN;&$@jDYd2$!TSI z)>*3NAdHm)lT{ZfVgk!?Mc0ttCqCuyU^=4(0o#G{d`k0?{+|2t%kan(kj0El?Z#hw zv{5OswRJZrK_s@=$dk=-nsWrFb!S7Iv9aK~eZj}$*0~cWApWl3RrBPtDQBql!Q*9BMM+|u2(O4B9Zt~;o(q{tXS3&ZAg;w_4uFdg|84@L1^GN6%(G7c69 zzYfLF_qiZ~*y$7@Gu8q86m`2xYQSp!mSf8B=W;+#myZ2cr0uD~tibb4#^He1q*qc- zk=7x8^?RL3M=b4c_!e2zfU&*79L1OAZ3|CileDeM$3FVz)CXwB%ruN!?4SrO}=dvGX9Y&zAC$uyxd0#r|8xEnvBmRTI1Kk=ceHZtwiD;ziG~ zs@|yp$JwL8-B3H+lm317-eZ=p&6*M^QK66{ZDh12ir76=?)(PmRGRqjsTt&kQk$@b zruhLfYQ`!VvVeMheU0IJ)KpfUz1(Q`eXP#`9nVVOPrDI7Ytw9dutXXrgdLkBx#sef zy;L0RI_`@1f2k0D6_cBsUH)?iPwUm6wGSd=T0%38-b7z}Y2BUqm-D(GrsEPnG;80e{xbI@~s}sr;w(?lVAAo z1eVn~Mo@0C58LDCCq0~i7FD&~++!Ew)@4yzqX;+gk%DyvuqPPyIN%cUNs+GLfFMrm z;{jwZ;AZ~+C|&d|EiGU!;DTED9sB{+Jv!5!0Y+$9(2`?osdRVk&5v;X7g0O| z?zISGHr!Zw%i0V^_ij0DzV?>jg1p2PE=%iADX`QfWY=3V#R${=euD#`augNtj?8fN zo2n!Qp8C%k>k+^EKDg<1mfvVy{1a?F`8b5Ny{U5D{$}60e$9GSw0Q}=X_bzDtG3X=rz-h> z5Ht&~zU5{B(TEP{6`#0de*G5+uaxs=2(#w7B3jsY>71hB-ERz++EMvtc@FN`y3DkaMl~Lf*RYKR z6GRV2!pt3p38&xdV$rEO)lcgy;D_;=(|M1}gRfE)8SOufoptA0n5HlooUm#7WJ$_j zr6FwSr4NOs&S;Sv<9+?G$Kmh%joGc3!p!WH~72(qSbV_ zx>!l|(>U`tdCo}yGFfnbj4cS*4xux&XM-ll@r7CL2L{DeFz&plIU72to{n$rIoa$s z#!`Xr4h31kvX?C1l@D$@)T$QmfWk)QH#ianM~D-LF<^eDIO4?fTT4_)sV-dWJR3CFf= z+nCrB+sVYXCbn%m6WhPowr$(y=6U|_hkf_j{d%rCeX9F3s;ln0>%5Ban$NAL))vE# zR&u-k`sJ!KQ+A`?3|r@DL7`*y6_J1Id6e=UCS%zBe!uX(#~)Pk@DpT;XjJ>Af_3uQ zn$K7Q4f%&Q&wS>ELP0}ALseC5?T0MlhfQ7b-TS4!gPn;h>;Z*{0a?AT7mFlZqem01 zAo#W=h(2jlR5)0PNbiXLHYgGXJhh>A;1G5Ymd+o~jNy(L?6PLhA&4Z!O|uV;4!RXq zm_T_b)zKY0dKa3RBDOv1zJ+dTBTd1N z)$N~?*VSBsd3gWcJ!b2MW)y&J`tatZ;og3pB*$E_XE&my0~=U^D5d%mgW*42$h(c+ z9q-;2J~qk20wIRHoChfff-$n6NpOIU9X75{#{-^0VFF7Hd2N+X@WhA>_H|T>HgA4(=6_3A`BsK6ay$DJkz&{#R3CLK&wTmM!Wv~+a|7A)c z?pM8qm_`7qb=!Z;3N|*dzc;%DeEsG|7>F;y{f16Gpf8{xtGs(yunOZVcsGajvtNcg zC=}`NEh{n@vG9gS*x({CBQbLa4P1F``ScS=k>h5d^1#ovm>B*cK{^<{79cZCL~)=V zSx8}seeQT9$ay?1z{0p-#b_uV#5xK}_MSQ%nY{D=T@&V&puAB48XBvsV|pUu9~Qw4 zAWQgO*gPeFpweG?T0%rxZxS=;D1w-MNbRwTOmX;b_bYVzxM;v1am0l!KS6GelOXu8 z5fJtmP{TNe0kA4)3wtnDl(K@#Fjj6Nma$MG)>6G(J9l7a8aU7kpV&1Vj^A(0EZ0s}0Fl(U=6pfKoV&D@ll2 zG$>Res2AOuD*q-KYedKmSug-`DB>o9%TYpns2V#=W(i4!om(lZ9HQ|W9SVrK=j8QSu;;3450Q*=7>0g zRwk-G5Qpf{9tZQ^b*q8+W9)?wCcL}Dw!{}Q_$!R)GtHWb&(H`U>%0mRvw-#T4k+kR zyjBWHjMRkXo8X*?Xvb0f^0Bb6fUe#Vg%izMa$uav=v5W*0Re|gzUYLQ(%a8ex z9u`IhUJXQCl)$v3K*L<5lRtnq0tzxhWULF^k^}=4;-)`>)DnPoDzxGtQdQd;e%)_TyPXOSR`Z|k%NNHLBD^3)%G)1%n+_2 zJiu(jtyY>JH0J*`$D*$px^V1}`K^I()CMBDz$1|B>4N{T{U#KZQkD~i163z!f+k8O zCFnb7fom;9iAb~u4~d-B3#0B;NK-;c4UxumZrzb*N=H$ao1S=jLM)hP!m5l%p1PoO zs_nM&F-&L&dc)ZNZg9l_aztDG{{Ft&sReTFfexi4_D3Q`A|;jzYd7P}bon9ecXdsz zY;SLWubdeBE&n`X8xZ`VCoj(-4TVPx0{fW1>a5!7qpG{9yY0hAe^8@!)9p8!VFHcC zOA!cdaTi`?F?2(BNpa1QIkh8F$MmHIH%AW!;;+%h+hY4kv_=n)*7k`1 z{bcjC%z0biP4)8Dt>b%}+c0rOmbXgrp zBc{yUs0e1x5T>JM1*>on2z9FqGFF-vn@E%PkC^GCtZ)#h!`vjJC;`r}{(?j)46%X$ zTi?&e%Q_9COgg9x-lSNcdb#~2ou)5~&apELbgS>tHa~hTY=CCfHDhAhXYu>T9p7mg zcMJmqr=6LeLQI>(`?+?2e_!PcpYP_%olE2xg!>Sn??o0XZT7Um+grpsYBYVwd!Xj+ zxt5DHv5w;{Kl^^=x3=QgW8pzcum4>qqfPBtO?v(#CWdhlx~h}LfQE}Vst~89XIrVA zM?DGutB2Nb*o{^JQlT~!7)YJ-t7;qjaOe9w#(?;?kJJ0QW0e(waA*3$R_VYQY&^y@ z4naCWE`@oMk6ddaz|JT_{`w4en!8S|#Kz4sX{zJZrY%_H>{)MDYrRS8t*xrrcUHpL z+=p)ZN|!sH;Eyl!M5l;ZOq)3ttEB2OWorw!R4X;c z_4>Uu40x#5m{^KgQczy(L1=zntk|0LrZ|^7P{sIuPtX<-*~iKzR-*qO&68fY+kSis z;-@Jye?;vyqDIaT#Jbe(5MrjD)@W!90_;vhP%yKzvUK*x#I1yN9L=}4ifMTpto+8E zQ~69S4USPVJkHO5Qr9lD@3X8ht2KGn@wB@d5U-WDspO%2p9|8`)A4a|Ac_p?G;&au zg|$a9=geBP!Qg7)& z8~aGI&oZ%@p5@wXo8F@ropkV@NiOHeKNG&r_+{51s@SvSe;4pBA@u)Q3ooC2A|G@GwjNNTF-QXbrI`e{D)b9h zbJxI9&;dZ<1$3DAp37AMAAMsHCa0g-B^yeb(@xV+6zs?SpnlLfi&cI1X4;a-=W;LO@q{ zba8IF=;i~`|BT9y8rBYa)u^D(AKjY(mISuQa5Pz#xCL3;z*p`LA+6A6Y?KBx(B& z_>kUNxWu|)JZ``4dL=l;0I6&A3&i|CgN>Okn=akJ|B zKYxk{32NXPC*Sr~5MckYem(Ne@*g>A=rh|20hHLk$^RLNFg#)(5JgTtNvh4g|Gbhy z(O2;)aC9|&bg-#@AW9*+L0<@Sl@=FHh>?i#Z2F=9MhF!xI(4lXkp+5{q(oOJ>RyP? z?rWw<^D0uBKq%M>`rlT0N&efa;)s;wCdu#3H-!IoJS{i3+W|7|8`)<=5DBotmdAgf3s3B5Q!~S-UOogu?+80Kv&WYwk&C#7*sc8ZY<2iwjKt-!Sf;106`l8xV3&n!TfPq!W zRj7d$Az+V1#bLo!RBuAdm7tPISVwR`LH^T61s`OA;GYQ`aB^}|)BUAIhS(h@_Cq5E zeU{SP{FfWV-_4wciiWm=hPJ$7jHZHS?5CP4O?mlP5aW7fd3k9iRRvvDX^=BFSx-62 zms$Y&iduhxYH|~ko}!|fq9y`{zC4bKpU6lh6{!_bXCk*rEgs$PB_&N|`Ue#`H8nX8 zFbM@+RTK7!6!id34Zl0aJJJWyFZ8z{O-GW+o)BvXF&Fj)5srrXj)L;aC})wjs_N2m za#}x+(V|g`1caUK49DGHJsB|TLL8aaezoulbd?YJzye{pLJP8py*D>E3A6NyApU~9 zUOGWhUJOECDpSX(ARw6sx6ll^J??l6h@t&i(nwsP zq2tH5U^+Q|?7`EUJN9V@j=bie2+?~9c6o-v-FMtdFZ1h1Ch zrJ2*YfnPw+#_VC+d_PFY|EwK$K(sFQ;{ zIln&>bsBh4lO~1%+F0gbslg5}E4<%F7jXX5sGO#hC9U&d3_Gw~T)mmO-IGWgd$RY$ z{@XiVvG;ZpldxT=H={Hc+v&JII9}acAN*bm@p= z;3P0GA~1yM!45YyV0x%s3XI! zFJPIhK9P@nfzu}b3b5PdKtABch`c0=D3-K)l*lggBDG1*Rvp}WLP7?^8L$ zBaZBjHmKP4!()NM4Wjq4898qW8Q~K4sk75Spkj(DcRdT<&E|etUgp<*w@IcyizuVB zf11uy&pt~nNrjHr_p`H~kRGn{4~5i+Vc2LJ(X?^Erk{ALIwSXr#Tfz$gpT=yM9 zhuz-xf28Ct_J~tg)S%*Rckt{g<}s_3SGi&w-Ve4u98>&}v4Zqutn1|u2N1p|hHAR@ zP(SvvE1rI;Oy!_HTN_MHO$GYY9;b1x@XEPl0HnnQ>|%iE_iA6Qfv>F$37o$s7u z9e#UXP)k*0eZdSMEQCyFnmM^UDfIO^@Rv|96{Rw>E?^q$Ck+`u3&KI~(E{^>j}0Sl z^xbL_MD`o2MCvNsMV;zTdy5P?=pY0oM4u9D4R&fGJmt8+QSigs+HE22aP^ut5XXQn zt1t=;54^uF%P|D+A50IUL;`j?#-HnDR4`9*oX1~g=K?IfMwsS#14$6oNL2Q!gdSv(m+mw+=MwJSq8DpcaAL2 zzLUpkFq`DSm%i#ck8_m65DJZ>C&op*48q1poHWEJ$6GGKL9ErZz5z|CMO&eJz*2=# z@CGL+J>bh0WH)jUi)=@T>V@dooJTAef?5}Ba?cMow%edC(sC&wnKcFZR=`~320GZ7 z|E}e#MC13?73qh)5Cr5omC}@oQGLS_0MVG`af3L+>h$sgJr%AKUef3@>S$76#nD2P zysaQgQDZn>IY8M2y4!~tkUD;^r3(Q0*q53Z43;tIR%#bOuQ@=3qAz?e!@~10lbCkk%3&bKV;K^yl<<>N0G<$x4ERj91t{Y`y zA~0uahcnF@>dw@`@TUNImvqC-P31*5GY>oKG&E;p!ARQ-+n(*&5eVcf~Zh$BGGVyvFS z`8>^Ra-!bC2nlkkVYt>}?YU!B@`J}RF&;N;gT%Gn)j%M$I=Bi57u>oOL4wyHrO}q! zHrW}0C3(Z0J)w7Uxy!h}+IfMsAvQ)n9X)2$`l&XjSW91D|IfXfa>Bj^{Wg-Pjf3Vh zw(03^ljr9rs9X-O#n}mFsgv*q2Y!D-_s2&;Zt6Ow-UuM-S?b%w6F+-h`N9TU-I&(l zp}@r6)3-e_tuRzRFZ&-)jGlnQhn9>K{l${lE}~Ku9_3etFqq!@5(Mg2u$6J?^H3B~nv*3_iIC>_=-7s68A}1I>AABh#%~oqqQp@4 z(%%(eFK#+qRkOcQeP$YXzGqZzN((%#2d*bHJ)eOjP$vr&#z_eY;i*r89k~txYmPKV zNKy07@cr+W-mZA6u#OFDZK@W;eic&iFi-O=PSPa_%b?ajgt+sOxI^vt`Pf|y&2!7| zS~cyzE#j@#xPOt|_n9H(Ah1JdiK?K3WBZittNzj3b(CA%d$TVxzS3Ol?`< zHE#&7m-GXKnrb*$=2g|y=xHf_3R7o}%q>3VVvWSbb3VEP1n!D#mu2Q()z#KoUTAdN zbod9s)F;Awoz##)wC3w#|NgPdDua(_I2}>sFVw*@w|@w8(@|~zyvjaq+yGrbJb_4o zUH0SQTf@b}qobwB6cDZ^9m;*M$AGr%I2SZSRm6hm?x7pit1Z_b5a$ zn3t%EZD=pK%rl~>C`TI*Y(}u=fYUtN%-Bfl0fW%lq9srew}k6)5MgO4r&;?#psVdG zA855@K@Zz@IPYJgb%MhM@p?K!0Z@(XZs{AKbdk}Jj*4&g<(a=7sh%I|^2gCD_ry$S zo#`~`RZr3d<%3)LIv3>Z96sBl)*}>vw+IdpO1ZD&J6;6&tU|a{UP6F@6|mO;7~x!3 zNZvm<2y{rg`;{uc${_cj%XxeB4ffki3pL?zWKIvah$i=K$2!k~dm+q!pF~n$zPLqp zn>m_zdgQ5}&dAz^K1AxV%{uT84Yl5vZ9SPhWcGR#7ySbvNO3s*$G*()Cm!Cy^v8Vw zA2m2^K2`Fpwd#gNo6R{+D96Tjcd}Q1WO>jmH8*soYa9(4D6G;k2gM&I(QuXjxo7L| zA~N};UJdaEZb3t3{Jg0TYs=JjAN%DLEh)OSV7xNrjrnmospea`5gFZ*qxA5A;KI&{ zml?w3_^V&da9i_r4cMb_ih#afL47<@F1}y(lwj%fl3VSJq4UCc*vZm#HztKLDVkMV zWNLs@UX80P$F(fWM(TZ|VC?>*>E+5{^LhEVmb)kIrGu0$c6B6%dgJpWo9_KZOvr~{ z>|sB~6grZ8LJ_`QYqP^^miTKlO8*7P485&qOIn1ci3z&P+PJMV8~g-m>ainfH2hpp z>R=!{;7KmYQnwL8{mamCN6HV=;!iEeCQDsd-~`>|G2WcVSZ_zYfi>pjXOaCkQdK^Lak@P{fPPmN%nzQv#Q4 zq#s`X$3m)2OUao(fWMzhKeZ|~FcO!r`uFBh^Y}z7D&n;{jM22L5lV>}UG0ag$PluC zfUz!ZHopMh)>|DW!(T?xo#|&KaHYGC1e-Xe&w!}P5V^4S7ah5hTIMJRiNnNoPG34x z6gi64jRd6qiluNDn@@b|H!A@x$jKGc93xLLfS<_H$UfYcAV9bZuY&2y{%d&r4`usR zA)QOaFO5Co;(ayU?LHeP?fWep`@3{YH_f!N7F7^80-DF5x$-tsDS$`Kx?2gLM@bWg z(X@$Oy3+}Vt%}T5unRTzX=VfsV-q|nW3-!8x2ZQZcMXosFG;9dweOGAJ72-Ik zhi7``6LZ6C)j2DT7N}u(McT+7XDVfDJ}y#e?~XQ`$~eETb*dvf2 z(FORY9C_`T9qfNUHhmVc1#F?4T}UHrN$m%$ytG5QqWqIPwuFcEiHUW(4O4gCW% zHJS-+r+me!wT=jM~5*# zoc*svOY+SSZ2h#-(QsPbMegkT!+bEq_tGw-dVaNRpqJJet%J*J;Ru{Rd-_;e!mY)Q&3$ z1`hknVBO380#u%X#AC@bjNfxcOY~U%CE_2>(|>12{36+P-BrhdP5t1^+%G}0@{+@^ zl`{umuPd}E$>Ip$K2{{;bqar@Z!Ng?c6i!JaW=R9O$iyVgqyTN>SuwceN-1Qn&eBYYg?W2}MsifwNeu1x70@9D zmgnV4)0V+ZrczA<8%9aYU85!x31>_LmPkyLa) zrr$z(+m{c4!V<0FRaX-w%^1=m>VtBcCbCA;M~SJjO-lT2g(}c=8=yVD%K-A6b(vSQ z^e5j>f~%i<9;~blUmnLXJe++nUmdn$YgS2eQy#QZif!QiaSz?w!5pa?glf0+w1`W} z@>v6vmW;k+d_AqPw#@U7>|PNeky&sc5k67?3LaL*?bEv7m$1bqI)+s8R|(uyxALbL zp{z8|HJpy^VeyW3!!70Dn;<6jpLeX8a5$%t=HKLPs`z$=$ec1Y5gz;7kiUj#2LM@_ zrhEBsza$e2ZOIWFOYC%(Rc~5*`!>3G6P1$N@0=d7D;<`*pW&D)&|S+L>YV8{bM0C< zy<);7o*mo{{&jBR*k$47nlu60A~csbu^2Sl)hpVXid*xSPIoBl_?kSv`FX@P{OD!n zS$`E>Ew3)kZ>ZF`pGEo{xim-fvl0ZGB~QNP-+A2N+W>?#OXWP4NRh$)*lVv^7klCLP>g@Z_+n zf2oXhvGd^+T{~w7M`v`ovenc)kBnazKN@Xs<`COXAoH5b7UbCQCSooB)Df)B!B*3* zwGma5u5R~U6AWpp_vD;^|FAt~S^E%;@YlTK+@3HW^C?E*THE>iRZxv-{XlrGrd?d6 zrZKMKJ$8;{mrR+((JqHC5k@&NH(wPH_xp??{HV`(CHLh;p+%P~dovp=L2@COnu-dG zN3SHnm5Bk~AsDZ_19!Zb&0#2G1xLEcwev+(CS--wz-k_jv??Nx5 zYZz5{*yB?(L_@t#TvqdeN__zmtf|#-}gJLuimrQlClP zMTk!=)bgufL2<|l9b6Kx8cZ?O9ONhyTqCd|uSTns8R;We+DSP=tDqT}G1L^suMUSq z^ud1`pk0-XO2M^{Rm~UeYKy!bf~Wz9tZBQ8y=D_|J1QimtV&jtPywC zr$4^G$b*QFa7stKP8!8XN!1QisP!E)BZ0f#uS`&KF!dhP+SP+k0x+~bXi!%i9oQgo z9fDkmKduMJT(IRtZeDlAUWN#mahx|$FWY;0FJRg|*~j*pVBZvwK`}c&shXpM8gx%| zjakzNPy)uVW{@*79O6v*w=*pKn*H$n4uQkLbT^Rnptu}}-x)pjd*|*NRk$hD!1azeN8N?7)u*ApUl1X`og1-YU=#1l^Z32XQdgZ0C(&;~X zv795(1RZ}vRuSFr2q;YiG3U>K(t#VK0AZjniSzf8vH|S^FYet-f`ib5=w|-26%A$% z0t!ZZgPaE0!Yf4<-+CZUlFwI9DYPGazP7eJ)oq%|OyaZfR2w*JE$z0G!0t5+ z@Sj4TDG<{SV`EYtLN}R-XBJn>uhwz2Zd$?gNM)pM^=lDEXkh4R>6_~|tJWsCl-M)sm$=H%uQg2hFcf(LgJFgK2a@Pl;AiZC zYa^<95JG{&(6MiS0O7%g=2>XlV?Q}nCgDp9WcdZ=Ifh^gjEnTZw7bMdj>cM>398k5 zP02R}_6F!{{2S%h(*r9`mzYhk56ZBBKmi_ywscDM>qHc>mj}cdU*nsd{I`{h_p@7b z<}G`;uKos6LDxlk2?7mR;$n~7gaO1K@9)!++!X2E_urC%Pkv|?S%87tbM>DZT3>%< zlcObm80zDs>}99Do&Y7^mpWUS=LVKmr1uNT^5Ni%nYNl=sofus*rzHp^r;UT?zvJo zqw-0$VdVRuSWC&xcp%5)@)_~Nrk*d_)BNzT5jjb1|FkuHpVqoR(eDB)xNHAlq;huO zJ>i;d@g}f_p++Czd|JJRTrtxPZx0M<;Y={RJ}X3`x~->h=6*d#MDy)uf!*IL#CJ#^ zDVXHF%;JB$?{```9C&-H`b5+z*N`~jM_ zdSn$jy&ayW=BQj`H%#-k zi_GPWW2LTsZ8^!)#}XQaRFr4)G&x;D*1W1E{ELWav$e1)wJ_)I&2icKW@*$E2#s|e z3aBW_ZCjY80Oaj=J^H?OcYnz8QmAMT&dlFjPk#t(z5t&{Ql@Xp3%nrTm76g%Xz!@v}DT~aY6Guvim8%;!2$t*fG!76g$3qcvAkhUx{6`S&{2;R2Akw z3WDfv{)CJ=-#Pu!U6SLmMshp-RY3!Cn@4A`Ddno%elZ^rZIb&X>TXT-)$q(29v*Ik z(r`|9qi|D2V!HP9`S>`0T!Y8$SZLzs6^KW7ZdT!Ww__W)QZ0iBpFFYJTDQ0Pt>OK8 zm)vP)JYp#*HMaq`KZ1MK^FpwhpbYC*x8l~{d}B(%f6{I=KShf<s3WOwUwTZl=!9wtb)CKPq?ZmK%S@jd=-lO7HT4XwB}% z7M9`ub3Z)7g#QgpVP3|w^(87JVb4;BE zAgqmvX{-6;p+{vf*~V}tO$8Eroh9Ga#hJkKD%$9{S{RVpr0nVycZ*RPbC%-d-mkOe z7Fw4a$&{OUP^zCL*fnTGwC!_VEuub!=Pp7|s-)Z37}kp`sh}1+$X&H1#7sKbo2L!l zi-AFY@C91UCa~_Y(-^eU#eTKg2MKgFpgo(BKx1&ZV$Wh7wwhmyZ}m4!@7MD#yTF`y zskV@fa@+cJarA8-HpEfPr>gDLEjw1{Yh>zQH5b)fuk(eOsJz>@616es%H~F;F)A~% z!#N?N8@R|o+tF2W$FxpLJx^SZ=41{-{UXVQr{^1d~xc%EBC;VwWLF=@uB9RwTPsvgX@joG!OFxABL~ZFR20B@E)= zPVzd0<#wViM+7n+deKnVMipwIq{}!?N*KcNdq<8*%ML;K=c*2N%Ds!8nwZQ z1EByO5>AW;FV6L1ys0S)rHMvZHoI*J^RN_p^0!4=u`})T{6tkWny`IQy)K=VwIcen z4kg(bJA!$Adw`0ISj|VC-&~Jc+nL$kt1_>7NOJbQV4bJFII3s!`^R{0Dj=26UELaN z-}w;Y)HsIT=PJzu4BmO1jVU(onb7l)>+wl-OR%l7fF}mEYm6mNyLxzfNQjpcxuWoh zRp-DMPl={7rEuu;4my!c3h=^J(Nvr~CkzI1EBz99vIOQdCvy3+)?_8nWhi}$5wp)X zt7XNn)8KHt+f00y4(HYAygXddjNfILz4hawfy366OCYRzHQz)Aug76X9mQMNYQ_IZ zJG?K3)%oLVH>q_BE3ibLHp|yQII%=6`s0y79%`Js@~vTKD0GhO&r0dCH{PY59c)9N z3yd}9@vT4m*HnRs<{I{gO70Y+lg9G=4xX@T6)*8E&iDCi9(^lC9U&lzK2IScxUYkNKi87*q$ ztd~?Q+v;?3mLz*cLdF>~f>)6QriE|OdX7}pstGs=0dP?9znpq8GlWi;CX6!&B3$(M zw1)7fUAJq!*e4h}oE43(1q9~CH7d1d2pX*P{3gYB+na#Se(j3-Ls|#JS3DU5WQ_Lt z^nAKZj`Kk!a@Q3ljnv<01nmfUE7&>4KYy?|Ve!WQV%2?Gp5~{=Ga)}zo_rr>*BaiZ zUjL#fTZr3LYP{D4q}8`Ex>^dp!8%6sFa35|aK$DjF;jaxCWw4^XV{b=<_N;vGDS@#mNQ1d`OTVPizRy|f=gmVctGQj@y8V%_ z6KZ>G!LpR`cqgnF-MKIzTI1}#T~PM@EHSe9VYIkiNxPu;`d<7w0gvdl@ey{Xr1@2TF+|EeX&_6e)5wKS{?TBxrfB(in2{#C+x72=yN}_{-s}6ifJtrawPV z-!{FcelJa<1!OkaxY+z1tHw;(_KQ$Ra40JWivV>~6)O6o^!ml+88+&vk>g1&0!7DG z+G)Hm)(eQxtZBJPV2ua)q;Ypv?0M&d_n~e#o_f~FamEGzGTW69+asXIe@16f#+&v^ zQW!~8-DaM#^4UMi7hgflSN(l&{hz3QRIfiVm5oiM%_)IyN3oa9Q@wA{Io(>|aYpuhN@-H-?D6aSPA@IHa`~}r&SxV~ z3`jQp=rNMZtTEBM2?M#n0|AOn%PAOy^7eP_mRnJ{t{d>#`9*aSswu2l;E%gzW%lLVykZXxT?t>l3m;KCb^{Sau zXzTrc2|)DBMtbrad`A71torWWhTc5ukfoNQjgT*C>}RH+!RGQLTKgUu86nc4%W@tv zuGIgNJp4Y4WnYYOa(;@Q0_UNiriy6V;U95f={Tb|Qx$XP?CSbFH^i?XHI~MfNdTsf z{ED1p+j~Wj=la#sDD>x^i&+zL5(+Ll!yp`C;r7VuW+z(-R8cxbo$V!yz`DxLuC~+u zp)z0F$gb!C(kvh_K*X>*kU2@L#k0keT*k??2kQnNE;Egw5rxNjsHds5o066WRy<{P zO6vwYRed@Q2l4Ly4o)_pQ^#UB$EsN<5H)a6liXfE)r{Ov)?<=rA@dSGn{Xc$=@&QY zuXJk~I+_aF`-hv#tMm|JB35P^s`51E#ocQT;T&BcpzjAsQ6Uv@*w*KH$<6ww@L*$| z#gzbC7j+XM3q@T{qe9Rr+&s1t)afW#kZII;IxY3=&`=4Pse+m|`_}w18XSy_Rrr5Q zWQ(g=e4WQ|Crb(@C@;4Y7sbw2e#}^e7>J7Mx^h`1q07QvOM0o0re&(1{WgoT{a8cU zV~BFO2D2=r|2jJADa}Gky9)SU))NWqKNn-Gj4UNL#~A#p;#Nhs($(><;pHqnJpRct z;-f2%mlOI=EG5j?)L1u0R0D51PS6!Z8B9~lG5BW_^N;Wm5!pu&|60T^r3C0pi7{TN zICS|i$@@rzV2#VlL_gj}Pt#n}Mh8yJRcoG%?sZt3s~X#)I(rHUlAN5-b#``j^-3Ns zXsWiCUs0>skvn_pSn^>V4-C8oANGesnZS8#V4Oo#pIyUcXPwU43%IUu<~e1+jL1pT zoI~vQ^%N!rVG$DQL9y$bmC{cJ7d$}RK{J_Gg|n)9N^2gvB{xAb67XDW)-D}8qtoysA8vxc&qIQvd$4}u4Umj9Me3Y> zw%}xB9-i-loimD(`F{wm3NXioPjv9I9Qm04=CiTSAWE&9t&?-urntb^jUt?4AJ>|- zSKzdd&dogyqTk-;Uz}h~_t3p3s_(yHf$svl65NpjyVT7-$<`&l?PYl>@=$+os?KKW zxoxvmW-U~u!L6Vto{xU)7L#ZQooO@mh}s#MkhcD#Se!LTG=Us`fhde&9V+v%3Wd6< z^wxw-$WM2H{W*{0B^-NhpbohY6}bfY;KKIzKGX7!R?{?&%a?^0*P&n zBUqQj3HEnKU*q(0Q}vQ02)Y+PNn5K~LSrR|QxV}(<7p4GWf45)|8)Xy5imn9=ReFS zQd0#_#K&at?jGWvXkfAO(6aRK^LGQ|DC1hYIwg zyn9>K*_!Z3^L389*K^!_UZyw)eAtpv3XKVTUuj}xW;c2ap7LvLX8`mZCh$U(*zN8> z#b(~~+-F*s;X3n{VWO5pmJ>xFinRN!SqcKgwcLjlhE{Ed^e;%8mOK2m3CX@r$?u@) z^BTxzSgNs`BUY5ZAw4af8sixsZt{<-1atrYCqimF~*EA>WmY+JlTNTw}V!m03fr7in&Rhx`_b=3xzh z8)2mIGiwFi!C5H!$Jyj?QAEp=vS3r0ecbzZC-QC6&AxKg)#RH>3cc&7sNj^iT689I zS5X~q3z4x1x$|M$+XtVXM`K9=t)tjta7%69dmKU?=CwzF5vn<1XR7xk{n#Mcs` z{Qmt)e^+D9>M&YeW7Z>m&-CCo<$SOcWC_*Ke9EwASe%O08n`Cb@)O`mC_k^T&4)&1 zA@d8M*j={e0;n3`qLJ^63* z;cQw@S6$M`DtF6mtUZ;=W%KV?u&i;F_puA@I>rgxtazV~INn2SGUcCex|rCgUHLZObg;pK@wBhhuTe8lu8u4#bvT2T z)NN0aA~TiKZpO?(*N5PdG_obtVcbr8{)Fv}muF6ukT9B}%`y9_gKI)2Rt*o~{zyl3 ztIGX(|N9nn1(@RogKsb97)dl&N&)vBU=8V42=?xRqANGk>Y)Y4@NZSiJSN=Azbv-keefbM!~YR^_sI`=a`_xB6w;7BnY8X zgH(>=#8l!S5*C-o0v-xd@@DGLslUniO|7# zha$fAoRL&p1%v5r#fsd#KVTebPacYwNeeYby9I1JdA+B4VM4`{T1|icNN}*QoNYTv zK*-!~-I?zAUx3`gAB{S9{j79T+UksTsr84Y7&!##=aJPP1k6lTK)jqJ zQ!z3+@{#wyR_(2|HGk&mOATU7=8yV*$G?^Q28O*kh`E z|1LQ3k5qNKR-;Qos?feISf1Qxv9gx(cFA1nx!X-%q3Yc}*J}*@Iu!Nlju`k=a9U)G0xDnTcQ6t z2Ht00X1IUV>-}5@U$W!Xr_us$%MVK+h9EgAUjQy|RE%OVzg9-`7pJj8xUhgoc}|P9 zQ>0%wgvtV}Fb?m{H2T`abSZafx}pKf$tYOAmgB6gPLBm#^3yj3E5+T5%|({XD`r~KF=(T+lQRs zra~5BAgkuh&rRFar1wDLf)K50C+^#om?6Ie(!%9w6XUb~O|ZQBB2cu^NQI7%}={tkZKGyQAxziN}hn=B;cL`5cSg0i{gBl51_Tzq=cOV~q<&&qn% zAA9zMmyoGbzG{Gx^B|S_ro%V?MM|QDn@E)Oro#7?BKRKe^yP3&D-TPd#owz-i_)lF z5ln*b_sAY~T`i#2^s%LZVfjB(4+W0smM1adh^5PQAsEza*)_w#?vun7=GYC^ZG!A7{noWQ+n`0{z*7{ z6Vqj>Fzfq<4Ddq`6pAz4uKcGt5Tp73i?g>1i(~o1ev@FqAq4jj+}+*Xb6z)O>aObQwcg*mrYJasXO-f$CTO?i<>=#; z_`HMo1!pLW%u|MKdx-6MS6J-Z55Fc` ziI2>W=Hcz>%U+o*T&Z4msQE(jv&qyQzb(TF)3AOk6(cvtJf3sfrrwu9%j&DhuIL3p zL9iPkfLOU?r;~WWPS2}*E5>yw)nVu zlv$p{VVjeeS65Sg+y-J@T85)#uemOWRT0es{DjmzZMQxb#o84F`lX1;=_<+$OD{hk zIZx0g-;WhE>&;${8deRDXT(4uCzR);XP1^!@>AoF4g7NO7+cs=CHvL(zBUN8D&-W- zX)JN4I{y1&p2kw(F}L-Q)j!Osv~uRY$WO;CsJz9CsGM1DcFMa`!)jEH;jP-5u@9!B z5FAQ73PmZ)&GGxT)yF+Ulsk+VTK9MB2s@c%E7% zElmC7mLxro1$}3~^%-d!WJ@0<4EnyKGQ*;@en^h%APyXQ>d($OzMFE^?2`V8)&0B_ zG!d|})W^oAn@?2$osl4i1GF~*_LEdt9GUu#=&6%^y6JGZd*zlX+Kh!X zQWDe=@@s|7z6?bM7AsQgKE_Yc9zfQw?uP-yu6b1RSEWm1TXuE_Ct*T6GH7Vq)7bk@?})rRw}bAEr6lX=ROROc$c?|&_*zk)h7^Cz2X<@@B81g4{j$|kILIa5 zRZ~hop`|_^-w1Vt-=ckg@f&{P!zV#xqCbZ)`m}#PNjsLcw4B+OgiJG6o>+{LkMBNJ z3tw^!ps1ZgNQE%>ML$H<^RndZD$RB*UC@&rsc+#~)RW`+aK!t(*fcezR3G;=QJrUv zh;-=jlA-SC?B)a!Ci(W{q_=uB(6C;)g`5G_X5n@<&p4mRj8O&sqFn7_C@Ux+qnNe$#o#CaJT9P_Ln9;zM0zX5<1>$H z=eS;d^YNMr)iX>tc6D6u0|6KxBBTQ8a^k+pM1G>$W%5=DY0== zO+!m_T~!Ajb>HfvI84R7C?8-j%q)w({$}Uof)wV5gy9|KwPb6q1QI%y*3{IrS@|px zf4)2ExPUzIew97l$wvF_HoOf0XKU)SCe!x%Zaf-e_CB+qHriTGW zn-WFE#p&tk`Dal_=jN3qWoLwj9Th98%OXuU*qEnbC^k*#v;JuItBhjrD4Yscf6yi# zLd_LhdGTrWKV0%1W>>@KeVT)^FG+Q$P>){MnQz%ho|}ixSLu%o523=rKfpJ+=&=9k z3fTaa02%0CAe339VR?Z7oaq_GO2!izN%O$KWh)WRTETIokndNxH*WHP7TISifxiJGN7M_Qot{k`(1aWE``SS zE;+YC_iBRAl!gb+NDeqW^77$+&>d6?_a1T)H$KQ3Mhv(|mVS?CjNzP&U>6?Q%-$j; zj_VK4cY9#JuAn=vO;qBaRrNIuanSWb{b0_R?nMZRdQC-rmR023$`s15$i*}sDY+c6 zK970xJVrrB&v4mOdQi$@@RWOMUHA;4EIHD7leexbG>bp`n?|zlo1m@GE0g?j*)bu3 zUgP{%so-ESeZdPFOH|m_(vpURmrb`nkujwtEE(Cig7%uk1TachZd zg!Ayv1X!PK?i*|2rgJAwCyY5No}ULW8I^?*v4mr<5H1tV6bN>)vyK9FzB&(g#z-z) z9vvNJAsaAv*2FQN1n%6J+E`iPNp%i&$C|0J0#o5D_*ol_>(Oa2;_p zlrjd(6#!7&5O}C0ygSvfxsX2_*kfR>y0}HNW4g9;;Gpr$HILqoHu&^w7BED)Qiv4qWzvkt2K60x+n6t8DoB~I5Sq<5$s?>mUc16pl` zej-l*5U?XE|^acV5tsdz61&*HYEVKFk@#Xq!52p1q=LcZ&ca2EY$o3x-Ih2 zp85v5!w{DJ=61@KAh0Fp!B@f?JjUGQ$NEVTL8#|H7LcD6cnPAF*%W?=(j+NO+dzC~e(6YX?m~ zJUft|fKc^K3!2{JBGGW~La0TQcjd#_W4*8U=O}E?T`(bG~VAu~g06hScRSIDfl~7>A5=yhy5m zj6;8r_#y@ie!GC^hsT75_n3)#h@_pPjb_{}<-!k#O-~oca4e;ro+GLWVdtfIoxCd; zB$EQBz{d%a6bJpox5L)PJBIZeKZ$`%lf{PEMAv2>dH(nZ!hG}8@$5j-n4)rx! zs>N976Z{dZv3DG>jr+MQlX}Z($Uqlyfq1-4hLv0hM9AQ2bRR7+%;%WIFaep(PZnf< zGvOsH${$d7cuicD+EUsm>2N(IW8|hY)P9~>Lp;70afWLYY2L*awpGR3mnB05-&B`? zs=D)G@W6lW$wd6e!U609zyprLy8rvZl|rE<5PbM|KIA`+B?2_0|6=+-DE~SkfR9MS z{_kf*|HAr8pZ=HRY8PMqX6yIl%!j;j&47T5i#t6v=f^|fyQ%%DrW3l~t_r2&-Gff9 zYLL{Gp?lN*@e?1Rx$pPB&H&wxfc|ZJ*t5+2+?T(N?BCgR8eZ+j+`ke;8VK1K8y{V7 zwDTX-_xt55tK#VBCfZwm-cGK1yc|41D{Ey{WE{yXZR>{DiTG(>KTDfufVk0tN1MSP z?Gs;Tw{7@%dNbvp{;EaJH@sA4c)kwoU?PqePL0nbsiFV$bO>#tJTw#zC3hKU<9R;{ zYzM1)R9f;8sd~3IKE2^3b@zW>Q}^HsW*y!38s4Z{z~k#oCiZ9KOX_H1M(`VdJcG`3 zIBo{8@3;LB#yE#&xm!NB@uqGZcar!!?`Y67vaDCzoQ|LMN&(x3OI%t!d`Z6Weq}Q| zvzFvo4(u0lA^ZF)%nsE|v9oY=y^Rn_NuFiK)@Ei!6lXZY>BouMWSWzSr}`#N7v&L5 zVn}xNhHaP;VH{XMUfHc9Rq+0^c9^gM-5( zyDR0_CV~RG@-ArDO*`mHUZ?UfQ?A>n*~sG6XknD%zP;*JQoh3P^_^BfNz>UC>`q5S zr2*v1I;w?bsOExyd%?pK1pww?9%8(_hdIKxmjdz}6+!v=y3-Rh z!Sf{7FD9xiNEVH{cH46$F>)b=_blPe`yf zw}1Q?d0goWz);G6$PH9?KAH&mR&S^tb*7#>iV|-vc$?6dO2SL?-6JK7ls_L(QyQ7h zZ!^Kzo977L;?FZxB>$ax`)XtU*dCzUj%&=PMHM!1i-`yl#VY^~LaRS$dH{-wyF#mA zn}azQpx2_4kQ9(2d&3SE!7$3-`tU%gBCB(qq^+izg(b_;hku>^b*15n5ozoXQsa%F zjP!B6$sKDr^WLMf0VZ2OL&Gp%p^U$41QxTdCyfi1N&uSeTAl~!e#k%>X8`**oE$Sh zu-2wV=Gt#oBQ8Bboh=_g#0JAZjgxUY*Ivfgx$_=xJy?cjVSzZUc$w>1TDami8cb-l z3Ysm5u2KM6f@=g}-2wC{PMe!K{^>?ge*pktf_5MzJe-QU^5HCzVeRQn9Sk;%5)k4l zPfh$GDR`B)Q3N`|-!bUbD_2HMQr+K>)862&!~PL_9#4`-)b%hn>}KiwfrNY7tRiO< z=O*SHE&choT`qFee#F%y$NYJX8IpsPXaA*A%EYT>^PFNnYT2Kswd#-%Ne`Z40RG`w z>9{7in7~l_Qt~3(3o{6umyft?pgU~!l5g29Ai^cr=IlJFdI^OnXLiB-XMyd$aCHhJ z`bI(mPTw1aea+V^0%(5@4j|zTkoG{r#Vw2|E~2h(zEV4L`lD~iT<7(S_KsL#9{uE< zIX~{bn!Hc3sm9q$*m9FJeq_CdS8@&7QtRJymVQ?Sg-MUtk%iBv4d9SMKFDTLlO;Rg z$u(RW*yI@;PkVEl zBvxqvtBy7jmT9oC=*Oj$-+;QtwM*eF#X5eXMnO-{|Hks`pRci>+)l0H)wUbN}t zv#W&?O(Ykj?JpVtb3u2#4FAG}a#ab_D}?BU|XE<(Q*?a}7RF38 zrEQgLnBl%1dTLDh=D-br+ZK`#+sOL0;b)0WXG!=O zGYNj`-v{4N?i?-NPUs9RMlk>{93K-OA1hUHqL=RE$9_GtSBy0+j|)vaE#JW$g_VrB zI%2oDfUQuiCo+*aYcc_dr| zdKBl`-}hZPs6;~g#afCpyxAXf4{gR= zt6L-GGbk=mw1I4wryf4MANyeZw=uuC6W;yu3XQ9l?}tds6Kd@%q$9ssF**Mwq0a%| zQW8DEY*2To@-{%S(1_(Sv@^|&ydx!G@$?d?V`Z4L6Gi-6#o<^)af{f@LAgG>pZvL@ z%ncwjZ?%8TeSDA;+pLdJI!?EX^g2Ymg?fk)MU;y(k?QV5%}2IGPsQ4tp1j;SVwU{4 z3lc5=n*+UZbmUBvdo0|A!6pq&MQ>g}vuxYAa|!52e_W755?9D}TKdh;KECHMY&hkH z@b=ka4xs`PEV1|tvzo3$C5oQy{b1`;Pms$v}^o?JN)vE{4;2U8?1(+3;y zyF~!OxM`DzRy;~fLGCtril?KG09WGM14RpbR8mFh5xvxl{crnOPjiHDOrxwvf!r4x zc){@E)>qNN1J64HB%qjE>J>s*qjkl$SG#gV|EQBYKJbp*1-fIOWym@<9cAs#37H|~ zQ9CyBoM2whlgCCQ{*l4Q`mll<XZ^8ZO2)ka7TkG>)b{<9Kl6wc)tLJSsSAM+FTZIew|yB zZJF*e$%)%}corU=5v)RN3nVn5gnrwFNDZ*)vkGJOe1E;y;}u!MMwV2VP?ArcEmh0p zbAfWSC}49wUM^K{doEBv`yAddq@I88d9jA-&oOM#ocMm9u(35+?3?Hbm}_Z%99W=X zSI{M{iL-9Gz2LlbP@zPh15WxmQp{AAgWoP8-FA|N*gxO{F z%1MHq3$yaCZ#+r)nAea1jd zGbFy(L<5d9OVTi5neJtzren7T;E$q$q*-2hLmN}Pmzgptm**FzH3I9?Q-`+*bvG} zA6;-#ZtfQQB6e{>L7T}ecV-cpEk_miMrUlW?yt-Igd@r7Cn`{+@$vd|l8^#(8U+Vc z=8OJqaFE?>7nvdh>{d`19dP3M6Lg zCoR92r^nKL9p+=Dlf1033QZAZIUEO`dC!YCNmcS6&NA0MXZPyXmlcGgH!~lQW91gh zvD=RMJl+FBxBpEFyB8hqfNo0@+i5XZ2K!3$)J_+x47!71e*VF;_pu&!dL3sTr{gc` zGYT&ye8ziv%(G%l)9t_sq#|^)TMQdkMf*}V!^%Tr5K-|MYq3-8_2ae#`9@g8&MK!q zsGxARpIR^JvOE|?(_=a^BJ6)pgpq+CS)p*D6Q}(n z%s2GjNXd4phTwheGXL8}x>ccp_$`ljM48L&S{$Z4o%eIQ0+l6667O7jbJU4JJJp$~ zFXD+#RrgP}NrT(jgx$@JC3B506>ipx@WW~pqIsN0=?R<`=?bx@GS1KYh3Eyz4}R9@ zNY(CWvij-K==S7(*s(VXh-?MhdrJTZaNz<$tn5*C zRgH~Ul>^6Sw9}fj%!?7q$VGsS#D1e%&D=TzPaXI)exggD^y-V&Y<*34Rg#^X{sFZ! zYZm%8^Y9LG=_Y%7O?yr(!&2#W=VV%BqRaXt12EGqj@kdZQ}X(<{oFF0xRg9->t{ui zU$|aT+whx zpP=PtT&!dKjL=W(_*Fk{n4*!f%C0xch1{{~v(}$PRRoh?DlaS5PSo?fly7_t4WgJsSaEM-0@yVMX`I|4U%Vmtv4FPR|&rKyBRUivf)kV>)5}A6li4- z=&?BYY<7^~W<1>mFNm>4dkJheCD{DwitAcel}3u}`EY46p&t9T(@e+-!HLU$Vnt|t z!QpRDUp{J`TmVErg!$TK*Jl1YXNAkZ@bgbWlQfeB0)(M0>FZgtZ!z4hFtja)uQgP| z6naDD`o&K6ZJDEI?0R-Kpj^0;|8*=m8(XlVaL6RHoU;-`;!w>fFHlIE-KNBsigaG;^8rRY zT_n&IACjUAOxBP#q|=>_Sj5nkUo(H5$!VH(%)Um3E^aL~4ZxL;mw)(wa=+ zj~MPtjDtk4J`~1ems20ITyBro@oe0R(kD$YY4pceapTnqpx@!CM?QS< z`)40T7!8?M7T_|-Tx}Q6FY)Pc*v5Lf;kBFINCJ03ECX)7MS>Wwv<5I!Sx6Z@*SxiF(hSpI|Xx4Nv6MFwx-GZIh8+kGO)XoFi!{YQ`{=T>0B~)pwompu$t3v7 zh$<~mAS1Prorte#>m^A2u1<9ca(k<;)a|VX^LlzKbw)5UvYwh(`-nwU9pDR3&F%&A z98LjtOHF@QPd`fUh@(YE3}f&B-CU7RRkeX-3N0PbzYM2;T^cx}s+!wr5qqY|S5#); z93;jne%|#K1a@3A;QQ;xgYa58)?$^fd}728bEkV(X*1uAu| z1a%DmL@Mg?iQcEM25^wI-U)Mj0eW9#Mh7f}rK0y^=gDLBAjsxE55Lg-NZr7KSuHuF zSbW-Q-}vxoI_{P;JU+*c9K@Y}8|;+{>g^N&{%HNCq=b8j9ieRIgw`$u{LI#uHyLz$ zgRt;YAw4eHux&(joJVHT#M8-x+~3`sAQbe#ERxvphj*-_r6M%&J`%f}GiHsGi+%V$ zewidmcm)1)_@dJ#zc{Wq16^u2u4FViFqo<$Rr;A-{-B&6Iu)^@Iz$xDQuGzEzc$Fd zCsS8(vHy(rGi#(7Edm1r^**erXdyqSCJTU+M5-SjY^;oHy!nYPAHblzN9sP*7BDo^ zl%pIW3&`M*Jj8G*d)Y#j#X8TSsqnSt43X?Zw1fTC9>V8V@XS2SAup* zI|3YQhDqjTsWGVIeQx6r(W-~7z{q!TqAtw69X4@Mof;sl)@N7cF7}SHwhMlp9r-pO zD7C5oV?X-ldf9?Z2zHmdTL;viPD0opHN6J)v_J>^L6 zd2G+*5uiAA(a{_KQ7H(_nSgmMbHI52eH;~3p|1(QdSEW;prGJan`#r*ajH2)2NN6} zBgdB@IQ-ErYNF}Q3((dk#vo80QRea=!F)l-bv;n-PBkdK9q0FCm@MrJ#VS=)4UAEa zR40~)(u)T0!*BO78+YcWqK5}u@+Y#u*17|(O{Y}qLeGJZ1VQRi*Zm}14}NV#*xA;U znmWO>`Sniz2VIlk?u6JUw3aaYXV--8=vV(KU>Id4v+ETU>w9dC4v6?PDQQ`0s;;8j z+Ul96zENqD&X4m~sP{1?#mg+|i_=_7heE-&q-Jh47dtBuK@lTq`AfFv(w`P3kpv}> zDu(%yl90b*-%U?J;w4V6PACIL;U6<)etg=4IoH!*Q5+c6v00l10GAjHRJ!~51uP}mwz|aw1mdPM(zU&4EMj4HDKMW0?D5zf z$LmHzg2Tr)X(&46GA>gtR@+_4{ekl6`nO@-WwggtP^(l2rYrX+Z9%YCJpSX9GfkG# zASkTu`8EDzexj99&WI~qQvJ#?d)80tD)s@2x!$uM#0Z9&F)3Gv%qTqH`BVI-(@Vt9 zj}mtSEiSuxu)v^4guV=Ol|;_UdIWGT#CJc?g>nVV92g3G5%XDh4rpQF=0yGMqC-%A(--ep&7Ulv22kF9O=+YSZ077fuT7nkl`$dyXce8tfBPi^l zpE8M(`!*CdZo`kbU*6+q?aNe6jlb^t7MS$b z460(i?gv4^YiYl}G=9Vw(y>fpoXQuqY2=5Xr-SVOTkr%9*3Mrc#xKHGT$(J+Z zm8~GpCP&s)%5jA6xGKwVKYL8y!&q8sW5AO*f3aO0erFlQg`s?^w!W3Q)z)~P2?Kn; zJ^6H&3s^i0j!+&B)qQg$ti)A^j^gQs_C49q+uf1l! zffTEs#!&|7+zqhHNOr%ko?v0=F+}=hDVV*BO|`oQJkF-m)42~4HBfcGaO|Y9hk`Ez z71zs{x32bGg9$Be-M%uLH5&LSc^bzsNZ!%^Q{C-xBW zjQi>XgJV~9uKMbdTiIAo{djwo<>FJB*GU^_RtMvykDA`2<$7TJ03&MBZWp^II9=LS z&L8>2o&L?iWtgH(14z^Zz^^pSCBC~lwc|`cKrOR?oXI7OD-z+OjnCfl@ThB{WbetLGc4F$nr`CKloAZ>!@z3*dRs`klXp)<$9zRi$t zxAPpSE^)nnxT7Rg^eI?4`gSPeE??%*Vh zAA3DF_#K6O=;hkr@TFCA`_gZlWg9Wcdv9%ppKAN{u%dcL7V@_YVgJCGo_ChP%^peW z{p$>V)o*bmWQ!_A7j$q*GXj5WSP>8_{Y?45=YF4s#-Yg`DJ_q~3;(0Ui`M`wHa;wQ%gN5OoGz7kviw-BLS^ALolbL)Z ze{I}DE;*c}J31E>6;UJK7$=QL>~={QN&VZEfCKkDho<@t3p^HHkx|oy06KfqoC$mmH4LuKdKs01lY2h*0~Rh!7frNGjY=io<7CP#~<6w6roN67gqc!T6<6 zd|IWHz5VvR3l5$i8KWkn@YZmUJajN<7Y{Vi(w#hn5U7nGQ3>TP+Q0oKR(oej6}xC; z4|zr~Xvy$vr++RhaW5%nImt6)dTbu%Z!;y_zy0d2oO${l*ipiWeb4#zoLEMbwJlYA z!$`{{q8LwOb1_--=q^|sS+T-<(C=tUPp+o!ZC0>#;2Wq$ev+phPjfgvzP0g+$jdpY5m;y zEF?w*u+GELtOSOe2VXO2ycF~SBQoPvA=ZKOZ^`px`qdiu&~SUW^5o-!(hj zxBj#8UH_ijOv22R60=^;z6pZTH+ygB3Tgg$X*!)2;g+hoU?aMLQ8m6ADf#Ec@(|NC z%%bY0q@d)Txw(0u760#?8tsT8!eH3DvPHhj==f;X_w)8IY?4_3wvX9;T0<30J5dZI zvy?bTIBS=r9EGeSv!fF|)D>lf+j3AAT*5^xb82F_^`wEuo!MvlWd`PE?7bT^#sNZ3 zcA}?U;LM0jdzIblN29Q|N$pvZ66X|i4BzC58OMDeXD*U{9qf}@ZjpZG-JyjQ=$Cn; zAi)@bBOjJYBP3amh(JvP3+CHW->fjRP@T4rr_OBzZP1~Hx~TCc3hvk|iPa~=Q&qOg zl^oQi?|)8eW))^9E^xXIvzIEI8{T-kfC%8y??t7h&0@Qq*milXfuIyowC2aD0>t3> zaChaZe*GQQhG#0f93^PfZV|#Tf-D)wfP$!Tc*KkfXMd1IaiQV<7Nr&hqp7I&`q{9IueGJNosOQJ)jB&qCzs=+{max*Q@EX; zp?yRJ@QbZ3`tCt~Zm!`GIzP9j^Gz#j;Y`|L?I`gW9jM?^d7E|up~{kA^F;ty09{o6 z0l+`lGu*itcQlyY*OhZu3>vAsakP(;DkIG-@L_u%z+VHMtLR&!A0)_bI~q z(=OO&m1nB}3vl39o+=f4W^#H89#URtr0Cc&?18BJdgbYvO6+vs(e$I7Pi)bdmPhHa z8?{f5E;ldm`VN>KG1Qg`DJlI#H=7!qmL&VGnav{#CoF86XN!9(wMR3Q9 zs)($t(t~0V1{~$gpss^ZYNT6h-J3+*wN&`xCZqAt5jf=rk!|ln9$v5iIEHop{2Ty6 z$3-{W$4A$mAXH;PNqpY`K@CA|PIDY2Mw0nD{cde2_DCC;;?hrBNHC-}NCbOPQF8(1 z?S53;43v;;Ujys!ttSVt2&CqlTzkWYGt8_jrQs75C2gb}W*W?rZ`&K5tCShrdo}}Z zkk_;^_sr(0@RT-P;XyTgCB>;-mb+#)9$CmnD}2(xhlC20@-(<|8TL?K)J?sJ!86S=7W84 z^%wOuDVxh8BW+o8cfJf3>Pdkd`hWhewd?=vhUO+;4@^-Oa?rgg+=~F44H5G;X3bp2 z>af*w`ULhjWwF#b%z5lSm(Ok;)X@^H-N60G)yBxmn;I33Z?!s zPF%)oSL2K2neT({(R=xxpT{~b+t5%icedh2b%JFL#{^%xu`Rr_8e~YD^nNR-!=L+o zL4&-Z;ubW_crRDg31ji@G?sco9d7XWD4FRu$EH`^(b1t=Gr9AO18wo{nQd%Pg>vuP^}AUX@;Qd&f$>O zPoJ^n36+D47YLWI6}mAUMI}p{>E_BgAXKk!#uBj%^Dl5_=ihNv$UuVaY?BEd3&Sr% zFn#$gDL$t#mc`WeGoBYj`bRb`#pv3?VXBO9mBmrOX;>Ny$@|4)0Y07ZsD_G`Ey>K@ zjSf4`*4N*XIL-7@V!hTsh=fKdvg&u9_=ao1UhmA=J7DMaQWvE7$OfI~=gu)n!EGn` z;P7k?c-7jv$TXH(()60a#2A-BJ?7EvDJH9V>$uE}p%_peVs7wd z(=;P~E)Mm&(skvZQ1vCp(FpFjw$1jWR7NClrKG8}Z}kZtQtHA>F^m}Pn?;N^E&f#b z9^c+R@O)d0sWracJe9wbi)IA-1v!aHNj`$5#!ys$cI96- z9%;ir4*sQe+r8AdCBy4XsGsB4)Pa_C(%gmn0`6Mw%SHW716l&)pwzh2?+GV{Txhg) z_(GjT%?4mTn5U zZNUB4s})k^-OPEwa^4!piu}GB*q=_AMzl`)?Os7%Jmkp;;BH=L0f-^C>gi#;@7Qh{gAFIbYB?bRFE3&L1J4hOlOAbTCO%NLhfn#DCTiu zVU3@%7Tb-Ir%N!{RYTgWtF0{;AW4?OhtClO$ZnJl0Tp@(0>NnEO*Vz$eVPY9Z+Dfc zt4L24m!d#sa@9D+~E`Eh{Zg;EbD`Uf)W7E%Maxg7H5+C-mkr z$0|!xQy%*+=kSM4r!D~)@db0RD4PRaVG`DVgloQbtT$I{7hbY z(3^@d0XyH;*8>Fa7{-|)kYHZPfzTH(-$UplUJl4P|MR&WcQ81vuj+SE_=`Qx@gC%} z#nQ=3Wic>{!NF+co7LF1gbm3piNCk9D}QyF#ySA*uuf2jiAX zxnShQ+`O0QIls_jjUr(T3-q-4ad>2>8E(Xs9-CGX{2~%UU=^g$2KP8%t?axE|?DPj}E{XFw4)-W)LEy64Z|UP^rAb&f zBbn<3)$0NMLg{@Khy!8G8n_)QZJte*fy0+-Yp1#I1Z`zszUV{vu7cgEIX9>zyK#1B zksT8ub=9t6?;DaD@i;n5!944^vs_URc0>mabRrT6YP8YXLv)ZTKs#`v20Rw%=8e)R zD{#G|wCy6m0&)AF@lKs!T*HnghMI3FQO?v$B zye6}QjvS5rF+HM5mfl^s{`SP?;2b@SvprE*0NzkuF1K#43QvGLnZwy0mn_!a93Em9;dFE8bJC8O)GoSMiVSyw7>oz0EyFdT!}Wy5Wrk)? z5FjwXY!m}>MHegoVbiq_?L+o-p}ywSpW(pvs*{runiBhiHjfsSPpre(fMy zhO5x;3}p4=_0hKd1+5lf52XNTAF*qfK1|;|FXQ&_%wvP&2qvScFtuylfSE&LL%D&a zkw{!wT*LsHUy23K1_voNW7k1iYRF)G?-X0`<(Mt$E&Xt9nK;0lAn%roBcLjnpj6Sp zd?KxK${=4jjTug;HtYf7Lc%HR#as6w z-K#(WNQ94#tx7yYJCO@mUwuLciLS{@fMZj0d)qv0m}n?Gd~UhVcuDfB??`5UP;Ce0 zi4A$^HywwjKg5& z@oONA8Fj`7(|!F*UVPb$ImU1U^x?053j7@sSy5I7$(+@^-H~FbRPE)ztRH&Cphf|N9|$3tU*i=UBmvO0%|KDlnUo)P=~ z-=;o{K9GXY@$nJ=LJ_o5vH#WLWZ(8a!YKN3pe8B`g>KWS_y2r(7X)RjAO7E&NRjgZ zGxzO zhWMMmIoC=?<-+}g+KQ^ddTC`_$(|0;&=au?8Co|-&VT)VR|a+%S6hFS7XaoN$*O{t zpveS)jjk@S?9zqLerwzt?PXg?87aeDt)&%iffG3;9i*CH(T zgM)!WnlN#yLG zJHhA0e)Si)(COI`Msx4t40V*WZS3s4XyWYI+syC2O*W&2WcsP{3qB7TMRjVf;Hh$R z`a$+}4~KhE3k2!88ARjFxRT?$!aKXm5DnhufIf|g_m}6}_qY3Y`T-LmED>FOkF+Xd zGHwTi9>iB}=}+53PuFoIM+e%5m#s(DJEfP!u3_v-7l-S*uGgbL-F3&W{gtKWf1Q5I zWrLM|*{-ShWt*|=!u@l{57}e`AiT8Z2DL4h4sVi@c}M%#xaSyqX>VfKUwp0Y7|-IH zm#WL=#zcXSyS1w>5ZX#VQ^Lw~B+p^icasN(Zuu@pI}S3D@%5+t6I8SmGF-SY)8|7gL{ElcXzgR}W+8?;(qfhw}W8m_0!!_!IAR>sMqyR_ES2gs?BtkZG)j zM3oBMl;I8k+!rE$=O{Y*?SrEQmy!X!tt#aYwfI_=jz;B*DRCb7W>K@hvxEoLE8Cj3 z1({&xxVqKo;`Gw$yi}=4awjCQhi3Ab|20gL=Imq+LE5y3Dr-$e6nd$Fod>=@8 zOj~YG+1LMDTW$Ivj^^&yy`E1iXUe4ri+6{Uq?5mgOi8050ry5eG9Hj*wbQNfw$}2j zAk4v6h1o3Bo1wF|i;o#)@pW>Si#DQ28v5|;*zjcw&<-2Q72&VKa-L`08QDK9%nV$% zrV_hNmBL6p<8-qPKEyfyAHx1BEY7Cs0!EYI?(XjH?(XjH?(Xgc3+^z$4DJpgKyZRX zaCZyt{PVp3{`NlHeZt9HjC5DuRjXF5W$4^fqG!(X%&|9TUd1uS1T@ZgYK6Tfm&qG> zP2{ep-mVenb;LB5d5OnjKt36cy%Cu6`HRin9E6EPNL^td`m`Oa3l`YPN5ZE7Tm`IeEZse3Yi4`ugfuVzV^jTil^M9I{VRPueaMK>9pY5W5rX?| z0)m-p>MX-*EFwn9AF#ogVv)>DyNa?;PKdUwS=vlN$4}n#t9TWv=RwkfHWq51=T1GZ z7WIpYO&)osyx%kHpc`eZ5zlzKFF!ecinAtxIB#^WCS};uU~b?ln5yY^^)79T)LF#D zlzQg>@tyUIe?*ilQDoIXiop5u@S27lQ-wc*&8N-iK6mp;R$`AdPaz`@@8vtDzzBAm z*S^f?u%|aBO;xwS6JTktrmvbru0?r%@-c8#SecmmNwOwRYW+?$F11LuN?OLwFwv|- zr5W7@2O5_)e|FNucV|M^?}}HLFWZhNpMy;()*}{`$pVBqVmIz`&ICZaa04m3Epovz z$2>Z#I9Q9$8iw5b_Tkn)NP;yYMGX-x1S_nZQ3qZOLs7py$YDX-oia5qHOt3ZBcf_c4QV;mg6|Etxo+QZ%!;gO|-J_WJI~E}UkjJvlje zFZ-C_Nz1^pu;Y78$?gIhFea|28PU1q$4&4GaSWziI1DDRFd4K>mPJaTMz-!3e)c?X zo?ykyzxbWYkF=Wvo)lN4f;H5HS6_xhOpG2Lnf@XoH&g9K;C%Frtm_)AwNvOaSJmXX z-yf5W(`_`hwnkurk@5~1Do%FN?P;-w$$x!H(!jo|ZETUMYeY*3a zsm@?uE2Aplcrv}{KQJfr=n?q(-#qdQp+NqYQAv}!PvWXq<5wL5p4iIwdHh|XMN#}6 zReTaWUS~!S^U_MRW(9k@kbdI=G1n$BafUt;%(nt%o>ngm{f))ixMWz5t8X(*M{l?= zd$P8Ek(oVF-^;u{Xsy7(@Xy!0YuHNhZm4@=?CiNYpvRMFzJoBje}%^F;_)~$)Bgk0 zr|Irg`7hg!$Ea`R)zbZ%GKol!A$w12N#?We*3KP5v1h_}6uP`u^{yXhWfax~#CWN4 zNQz)&2f;4FUp|vH`aKzo3W<-#M{l5u6ASv{qraBaf=0L+%@4K1-?2kYZEKildDjQm5w;irMBT~@jar*GQ$!F?s<_VV*# ziaICP2CI66uUW|%9$)OP4z#H@tJNy==iM_w#|cHPzQK2WP*xZay%0K(o9OBi;B>2s z4D;yq4*;hk8GY82aqk4q4Zxq(+TGx<;fV!oc7P=7zHcq%#pv7iU(2< zwnd_6WMpL3=-IEA@UH*^$XcfEE*#Hlp$U_*b(_HWIHe>>DXEh)ynW=<;K;7~OPrBu zl1&eQy)V4yL`CSKxeEt77sv)jmG~;z6X74sq1?&R-3lwl2e>CW+9a?6CaZSvG8kGL znEMosSD)FBbSf>^D#>lIyW7V^^c|1e&@Ws;>UOtRI5o{cwf9%Q`;>yYkZ8rha@rGu z75}mfX=?7YQs5k8%xpn?0TZv%gOcr=Hb?e$&4Sa#lO`e#rL(=m?OJzD+xcBox?}u3 zk#kJE2H(?+z3k6UL_(dZlHpBJ+ZQvn7zrrF~N}neK+N=8(0eRy@8|>_@6&Sh&35ibD-T#0S7kh%oApuNY zv35VMx4XTG$P~ zvyMVqSJ?bi(W)xZ6ZY$18ZywN0~jF95;sNL#{rC5Fahs827;n zM1akAcJ;p+$07l~=rnaarF@?7Y#DWaoI~A0ZS1;((hx-qpEt$iD8hxRgX~!tpTj(l zufXaNd@*c2^-ika?Iv&4gWhWoX2dsqZ`vQBHcqQOgI;Uf$v(qfa1e*$4so<=bUSZ5 zBtLPVDTXX<4(k52)#x^w=NTg-1~vzIY2JW*_Bb)X?D9$9$vBB3N5goq0MqvEN62RQ zqR7Q8|AuSOZQfPAVIyCcKYn!ZkNG07p!mOq8wtDjp44Imm!9UEjLbGSSGw+c`y+vd zp>d%Hs&qQ&PruvVGHri*{jVyA{5!gKD+X7!{3Rq@tLow#(gPJJSL?EEFtHPgYn}cF zpaT~Ht7I_MO3BeOVnDWMscCuC>&@^NI>8lRqsxSiNg-gDUcQ|baiWzEVlAl5pEge^ znD7gx!pGC0mIJpWwl`S54&vTyMAuE7#y8XRIpQp`SGdvy<6$R@U+v(-{;EDOq(7Tj zmgwXtxJ#Q8dArABDM6gfe;p7U6IJ(>SCnub^ih zzjP6R$CdI%-ob?~Ub#Um4FdP|FbF5J_f6&KTzlqAJ;kSfo8w=QmvreGHaJt-4f+2s zf$)Fjqpx9?)HdXOCO-4`i9L^}m4-o}P^EIg63=%_1d@dwzLBGUP=v@H$tTBQ&sY)GpTWMMpPBrf$qjSPrRt%vFtiA={H<&GgA=Wj$N!IC}*P%!VDP*?%>O zYhXBjK2H!^K(-6bi!?iBw^TjEC>DLooq1D{Paebqd4#4-zxG~)+oH55kZ#?#!xC2J zFckJvQfsYpQ;+-SD<)&puS#p&Qq7Y2{i+2I*aja7dT)fYe=Qo`;i?J-v2i6>^tiBr zg`Rx&9E7KT^BO)-M(@qz=4J1p_Ye?HpEJVT#N{foyzb*CZtn$#kI*l#+42NZ$lZ28 z6ip~L^|_1ksZhrELkS;_CpeHWCJPd9tAcS$6E&uq8X}UKjh;Ez>|^d#FS~4IVf&Y( zC|Vs6OVM8CU18J%dzgEiEcO6;Wam|*r9V_F&7H09rG`5c8f^i8D(=&}|CU+x2)!*N zFSg-XG>B2$ExdP0K7)7YaWdj`iRC>R?il-74U-wiQ|6}y8V^0EuzJx?-+Vs*j+KvS zGi;Zpy&{-9pmUN=E(Gi@E9kEz=z+#!s(n0?e~Eji_Z4S0N3X?F~uAk0$Sy7shsYgGTW! zc%_`GHus>#qgJ6O-U$_Pt=;h`4;qp2s~tDIJ#Z-%{$5K!6IEaKL{@A-Eey=0$En06 z1Y0IV;B^aA=H)I=5uGV`aHvH+bJXp3d)fi&&O{8ow8`EIanZoVg&DC0cvb-lO7L6! z-&-E~X_nWgH?EV0hKd}2mCpr#eTxhW{h*rO7n~PlWqTWCfegF)zdI(pw_crLr9t90 zfPN2oj)Bk2kptKjtga&6B(og(qbWbb!~_&x5&<^dbhP}S$1`me+;1)#9Jir(ACiEi zAle^b;=N1H-p%wpHFsUSjSt0!{!DFS7bgrs5{HauBRK_Lo-ar*F1F77(l`YYS zB>C!arwoAqJ6W~MWEjlo@4Wr7cW-eo^V#=%W=>97+1WgoN}m{9f?<>b;IrSgil*@&{q=^ccAlHMT!^zK*yt(70ru!1rKF7bc{uc1cY| zh=s0J_F{;*#ht7C3U@|2BGI*DO-9lM;)}TpZoP}R^ewZhyX}g62JYDJi$Bd39(pr5 z;--Ch>%DYLW1SxN=IE<7AR>M_EUl-oj^@>#TOq8G+MU7(s&zxJBr;3Qgmu~wjNa(; zSdfx3FzEhvwg)bcaHBUKf3X7$z(wxsaesYb8j5XB#ulB)82Zn{=GNAN8)%-ZB$2$%k2U_r9@iz}t14!_rrislBo2BV=2ushftemzG`u zlpw#Ge6c{l-~LA}#c8Exjl`r<>s*iJE51v0&hdlBqd4K=KP?r02O}n*cgHyz^e@v| z5x47t%?WLK<*zh|v(AAhH-HF(2={KYp5`qUooUp%10t}U1RG1ELKcdV+vLRuQb^>h zk*iEQWJ|@oK)XqbPD;R?}Ta#A3+zj6L6-aty%r-_G{UH$` zF_>%DZ66<@*;V>eAn10Qmc|zJ@aMgm3M}Pw`{ar6n@s+{nZf7VX2Se|gFlVD#kL-f z1GNMzyy-02gK>V;31j9PyBpT9hqfFwYg_Aw|N4q@b8>9vT{gCFVTA|q`=b})-=|~_%4eClEv1;W{LYPdN(m2KT>_vQc4Uuk8Az|7R-Emx~RfQeLW0?^LRpT zp^FllVQ&f_^8^#83ijX+-H>Cx_z)r%4Zq~6Tzi^@nb=xITUFRZ@PVIQ zaL1XduB49Wr`XeG5s_|wfwUAJRkrY+3Yg+zc%%4uR;l4q%9dZCLq-GHohANNjHK}t2$mqORYP4vRkK52;4_|;j*gaYf&oZNM_V;IK|4A&F-|uzAQGPj zFV7AS_6v=_k&lO$kB=XZmzS5n?k^=T|1s9jDu!rmA&NGE-17 z)z>s^!yTFym?E!>rJJceDYOw$k5)8kV*RkRq^dXUrUjBxR02z?0+pm5GSYfFda67m zVK2tua-lZp43*S``RHir(>Hu*=nNr0)I#ebm9^B=wX~>l)Kapv)VnJ{H1(x*pwePy z8UP(#9Wx8K;a3L&!4s%SNy+K?4LpZ)xRdKR{G+^6RxWh{dl(`PL^P$LE0)(bK!SZa zXAr5BRx~m)4luPwss0Ch{cjgImzI{c0&kJ948MBv6Nxhh1--AY8-h{gU_v*&(KvEu zEvp+(BQ+&4V>LMq?L}RljvkMUpuOs~EqLdUpmeX>wK~uj90e*pBli87j2I7RDm^}` z*ou9iuYxbAj=a8xy1u5auC%7Uv=~rcUQq?AuMAK+1SR&Ahc_`wx{SxeyMpTAEB2rH z^G6s)t4A3?p(0Sc6EVk7;?V3*6rZ9gV$i6+PGBlOe|c512SZxPWrmSSGTg}DxXa%h z%DaEXvbY0|we8{>@F6)-VR_kB)zm1A-k;ZvT^cetAtgDWj@XVdREv9Hk`{(O(9%jg zN&S{X9jcdb&n*pyu0fL&$vuS!StBO{TTL1j#0i~R%*brN-X--k zxR}DhwqPz~U~)!=Xho?ZNdiqv8S^#wu`LSeD(8JT)kLTu|;@gAl<>k%i z;^TiKUjl2}kNO9q6>i?&nHISAfm6k#C`j57U-Y6J**iac#A*F@T2MXV@>J@I$Q@Dj zo)mJ^+AMnz9cp14TR}}}@QSAL{^}W88Qm3>PL@?=)uaeUq)64uzbifou&m~PPF6TO zetj z#I$#EYx)ui^Uq8)7H4KSTNdUP=CxHb)jHgjcW5zB=}t!{K*l}PEL05jpz>lsMO{6h z9=h^1O$XC*_{R^*3@ocElJHTIJjnuAk*e5)crMa%)koDurpdyR#m6M>B}^V0s2pIn zojt8_YIAdvihZ^%V~dvdY?k^QyQbQrriQAzW>&^xe|a$(oUvv3;_$Gici zT{A;XQ+r-}kw;B!K9pBQU;C!%TuaXn)^%a5L;45em8EH`=8r{At&BxWtRHpb)z#xC z+2cUa7}!5oR>82x`#v`jaYb&TD-vM&sM409H%14{kpwi>ST3O zD}0n!)_{OjRb(s-H1&+k^<;oAYUSa{b6f}q39InCH|}%n@ww{s*5mfzD)3a5lG#H^ zOj;UdmtN`s!5%b6Pk(A@O2+`8B&$Z8ZOTYg6qOWLK?!2~qb6tc+LC;31q&Y)^xm(! zxHLN(W}mU>nQ>=+YJ2bJ7L0rfjsKGAEp5NA;xS%PXJ*$L;naytFP&Q&MH_z8#gSer zUUTVeKgUa2*V4+kq$i_-L9U9fg(T$n`0L^DEyL8tiOPw{V>vrB=aAFIgn(%L%YUtn z|H1QKf{sI0c3;u5!gJ$u3Dm4ThvX`-dQgg2BY8Y z_4TU%sF`}?Y#!sCXd#L4d>5aZnwo~1I$FAUme16>YTh3zMIcv>nW3ulao`B zKM4WS<5qB5^!4ZU3~c&f|3K+%b!lSjC`rF$^@nJceKjaLYaYg)LmVTV!aP1;4^!JnhSh9yeP`0e8My5Qh>eVN$&cyP<0=u2heF{YH99inW2ZVV-2V*sRKG) zoMmZ?@bkkv@UjZe7-kUKJC>HBYjblWSFdjwZ)xW214^ra;?ZoVkwE;Fze5YHNcV%} zEwhaSVFQQYQ9FUb|PbDWCGu4Z~ z_u#Q>S_wFtTd~!9^|kiC^+)evtexDTz#+(@c@DtS&*7u;+_2{1Y4`N@MEPwcCa$j!%lReA zzFDX^ChdvZ=MNVyug&ZV_zC*fu@8sxGJxW@ur^?x=cdwcR}F{!PGD+Z$-WfAW5W~L z%}FDW5yl{hiEq#JtS9*Vp}qZiYb(EBNGflKt-+w(W$S!uGN@_fSs$a@2`f1#K8l;e>wH_?Cj`9t3hL+Dp>}Gu~eSNcSQL8dFgTX_;GdD z%ep#3RgM*-q7yt*da8=O8jLkTEqub0U37fIRS5?M&(xMBL^(U4L(NniPgdI8jH)_( zLY;%HpjwYW zpJsWT9AD#YJ!#Pk6KlVAJp%d&v}Y7(82BciTj|p5f`K@lbVBw zW$BRtxWw-VG?j%&PGYwAuj}b4h{^qCX5(*niD#QjH&+^V2Z8KQSD~?~p}|7*pGCdR zUsCpX=e;k}4BfNV5B@~`OY?AN8^SHKG_cIHYGhoxw9m;Ao0$B6mq0>uv!H;0;JncM zr_M%mHI{B_5Z_wbtD2oRd>5#z5_A^O-Bo?nRiLswGdVfFIX1P%2XJzAZ(yR~{HY%? zrx~X;crkVV1CIFcH*NZBX)VCQ>?)Nn^1JrXP{kntYq6elI2Z3U?2Y?+Op(Rew9O_U zlg(~eO5*>sZc&ar=;{`q(H!+ld^S4%^;aLHM{8X3|vhiJhZXR&o#9Cqdh(Nw?=-xJ~=oj-yN-Okk@-xdyj80r< z%C8SR8(Czl$ej=`Q$$+eY}MrAbOu!e?egr81q7fml_swViF zoSfPkE38X;;52>5wzj;w%nUtije9Jce!^{baiJAFt~NK%KD*S|dtkz@e9eHKA9UxX z*jnqjF-I`0fHeD1sI4X@=M~`*(OL)M?}9!(rPs#?`AZ*ilXYsnPo}<{ufyUnEEm^w zkivLCa9VXGw6!JyIbY*6~_c`99!A%Z@j+oehfMT`m&G4Kl zEmxt!tQih<=tJa zlH!{K9tKqu+z#}MKS;+*Q?n(5t0rxAoSIt)+n%0qAs=zUlgJQ({>T?H%%v$7SO}PE z+%b_5FVWBh_8a>wdd!3ZSNa>)u%fIUbDRJ!Orkqvd$e@sJ zW4#0bj7z#lD%2G2;oQu=239wgw3U=pl(ZX|3K;ytfF0f~umanyg3p&KM^~^ru!2(H z*Q7LrCMux`6P1#Y7gJEdnZB_#bAiOf+8XbGRsGFT-c7#q3U2Pn=3SD~C{gwqgDa2c zQn#Jix2_dQg{kYVqNlKyMz^(9k)dD<^Cr3}E*TAP&1UqzqQIYQ`7vAT(wzFv!rF?mb|pKG5CG%m z_>%MpA9<=eYn7O-f6igc zHCIyu>q!NeG?p8Vp)++AqsX4}CZo`O+V`U~GcyZ!Z5fOxm}-wfZinm?;g4q59WLNC<&CB!NtJU*vfzyjq z7EOxTCV71$#VSp?@fY7oORMKhx|*tvkq}sXeg!NR#H+DRO93CG4xU9teT9W&t2(fdoLViM zi?fvEj?g3cwe(;cZeTUan3pGF3HiQ#xT*qtYy`U))2VIMsr}DJorupWW!oL8mQXT% z0kqm*^}yPS5+Jl+sVS}a#Fue!g%JS(sI7(};qPkj0C#@RZXAHAFBtBk^CA1pr^Oag zH(D?|wa_6gT=%VBQ{eQq~!_iXPxh< zA1b*jw=lrjB*f0zF_w=h)As*XA9f(}Fc+I{7Dm9<4~_*fDpIM?A*?yUQ6L2aNn#)@ zw8lq8?z9$_5f+jMOMhhSO9`4aPZ=Hc+{l!s#)hbtk_iH59yTn_3SpwF5$j{B_*bVg zK;75qH>HC-dLFq5;>kdXJ8Qa@!|q&Y-AfS9z!J>Ya$rS*Gf+bVny8|pqAXa$ND0dc z!b_~$&lUs{Z{QDIfSN;rAC?NUZhjCz<&?GEKo*k|-6xCTL=B{g5Vfs*BAyKWMU!_~Y7>!;fjHAA5W2g1esR)l&*8#ALFNO`-+653f@qV*ibf?_F z{E4$KdQlv;GK(ey2wfH9>Oj&Ga#xX^Q7+bJcnE!q`l-h7D}6wg?iUMGyqX44GQKR^ zicAx+Et{7S(J1l*6!{EwRhn(c4o~S)73Ft`1(Mo(lz_Sfd+06$f}wW)xw!_LD$@mG zQKz&tO(ld#(97oPzZAOt#N;gcPL>5U3N7+|$-^)4Mi{~VwCX6iUq)5EY|&&@f9crL z(Vy~XX(GCS>`oo%@y_gusW81-w^yn*dw`{Zx73_pnz;A-N)1a`W5dx)q<%6NOQFmn zjHw!J`$SNLG82YAMG{30ii;DC3duyz{C}5V?4Nr=99NQI05m*|5-^kq!JFUT4|ApY z^*o5v1hS$gOgJ#KH2~w>wWW?MmXeY`MKNp$l#!#N|L0gqyPW(RDTO83pveB{q#9oF z&`dz(sCvqaXmV48+$|ASKn$BA5R+aZbUbOb@C6h)F44&J95snDO#5wzB{JpyOKpU` zM1|@x1Z9i&l)pQH(+!hZ`5H?6iz24o=n1{LLn>7>`R5 z`UT-?q@u(H&kG7Mm`_0^;|y3qPOcTtB%MkOM!Q)Nw>Ls1-A7!##6HHQMTS^4TTybK zPFNQhw${AZX3)bKr#lsmH^%?Jl{=FAS-b1*>Z+=vvphdfaRk#M=L2J_hD7A~J-1Id zH%By`))xM&l5iOA%-rnXUJ5iuFU!fYF`^bIUU~>9%_Vr5_mWWe*$bELndR>F4PmI) z_Rj!8$<_BxhSR=oxGs!;-ov92cMazUUEQtZw?@RJ_VJuPBop183?z5-4)!D|6hDf{ zk?@*D{yF2{`Pm@uK3tYo8Oc6(cgL0D&Hev2t0FLS7mU-M_L8(?;e0XJ^&#JiNt8qj z+sn{Fdz30+??jMV=RqGH0DyCZ=Q*|fXknBEIfKUcKDV%!n=e&UcEmK8Nuklv(T4d&-uU``6d3 zv2_7hI=b>|2iq^bm(IgboxJ?~zkmORPJeoRetvz0d3uF`hJ=I;M?i%C2J=(ri#S$t z{DuTtNJv%2W8klmpn`9p6&UNcV+kT}@RsGWkPO=$dx#h2VukXEhV}1Wy{{0dIu~tS zO&p1A3}SzO#{K6dJ)8L76-I2r&dzRaZ4LQt;Pez^$lR~v7DbJd`B=Ysc3Iy+D#OIY z)bgbWbgBe~*Qo#m%k^6wVT6HDJ`wJ;8SpyAv46jlTe8Tf-rR~>l_RQd5nC+$_h0+S zF)K@0AoGi~G&P+!d*U+rv@{}EP`^RIwz@Ltn`z=re>@Vfq;v~`)^|o@g?v=*HjwR0 zs-}n+DmYExH5p35yW^K==j3$o&lg42a6k@aTwxA6Q~mtHNq zrGAbjSUBKw^aauSOX~s?qQZ57wjn19Ty2LfF}l9nY~a^E^kFR2ti0tu*ZNoUcn680 ziT04w$Os#`4G{S;$xyVe>h|>{4KguRD?>af_&EHwp=V|*A_Z-1`94H_zSPqg2feH~ z)c5(F58r~A&2kEYsu{%-|Lqf|CVt;BPnDhAi+}o7g6c$$*+jEKL6JVASB~BUF%H*> zIVee@Z zYLpd^IujjtJb`qzV6(&2B?qf@2wj$EMjE#<_l!93{Qw7rnD=^>rRZt%`^QbUh|v37 z*yD7*0M4>7yC$j)(8?;$xJS;Ey-;)<%c22C9F7_7O37q&-@H*a(V_t&J26FWR#Ehp#Ciyc3n5}?=MF|>XUx^D0kAA{J*bzR+m{8*{da|%NsF?YPUKobZOsb(~ z=*RfH?(ktUUpvDw6ez`0VbjM{4YFdb(1oe7gZgDpQJW`dmb zW`EoDS=tWY{|GfR9X?nUzP~&Byx;d=>3#SQS${q>(Egh!wj@%85&N8wNcVg4oci;j znnIR4>KFQ&jgkb$nGB#go#|t_|9!Au`1TxurT^b47{2$~@3p8n>2&fqJAdVjhM{HF zwsDSsCTPH^?|=Js6>@)T@_w_d(s%tk3<9PehO<@Ki2+>*l{aUUs+Mh>-&$vV?&vC5 zWzK0RaC7`l)T68Da>Qm+=nGVz+f&){kDl9rCGN}RU^0W1gTDif&j7Bv6ybqDs6eXt z2@z(RN~aHF83yLukxcL#D{7xUof`DD0S^cwH5pUT6KX2HRC`!wWvGw9k%eL4B6Al> z(x;9}q0cB+`N#_p%=LH{&LO+r5-CIeLtmMj?#7Okkt+jp;}NXl)B zP&t;jIB+Q25Y_}B9_K5eyzoTQSz(i-*GEZFE}+iJ!tgdD*q%e(!^w?s6hjZ2O3%trlH_k27 z;tzuiLubr}bxP^W4p5ZFHVzHU``Ich*(_$U3z+pod+ z#>Oe6NS|e9ZX2d9j<}JcZkUa`mN`~ll|Duqh4?~^38#*r&wfnnxd@RZ9x!aFj>kMA zrYQ&2L6|GxDR^w5}TBRz&#_7#g#YyKV%d=mPtM3*>6}pRldwX8^u`1Q;0nSo4Fo7Q|E`FHG-|GffXnxcvGg{^q`ERapwECSE z%D->$F@x4^shn=BFCQ~reTv(H8g|1YxV7-N>mQa{8wRHJhylej>%t-Fy%gw!9sVfh z`4m~1yghGmwF<^l?C&e1IzNxp4F?AY8yg!_ba(pG!9`9m+h4t@=Ets(nqB<@mnmhA z`95zc0}Tm-R}CbMEZ6>?tzUO3D zV&P1Q#DkAnPR-=YqK~5!LY@vQnzHLKId@3!FNI<0Pq2*<*#;#wJVj4_3nNknSDkV2 zj>XZ!>FF-!nZbzh%hl)8-$sSZ@nEivJq8Y%2)W z*MRdETZVw7>dJaLJP=8H;(Yhr>!Vf;J^gYDH$;MZB8GU14m;3rnkv@4e_3Ra_3HH4V3nXMpXcQ%=dr%Zeyw}8i}&=zkVE*P zvi;8r)WVc2Y=vcM_21DM(Z8}9_i6EIH$STNkuTB_r;+nhFp&p;UaXeK`$cze6#Rrc z8=#$=6_g$oy`;qihoYh4A-Yct1V5ZUB6Kc-OfstL(hGm!f=ZR`2_y_~Sb)$#p-?!EqY0PTz z^xee8dpXLi<%e#gsdq|J%Xk=nLEcK~K1&mv`ebU^eUUFd>^LtJ_PxmHYV?pbmDN<$ zojP81^vO?6FKE?%VgKRSI=Q$!d#0T`fO z{yh89+*XIrAI*=GOf2GYPm$L{H>;YQH(seC^!PSk-(P=bn;|&9j;V?#Eb1nfZ%B^` zH?sTV!*Yi>ht2nq^Qvgu2zAD1CeuP9Ej??v;B3r z(I;iMsl$_@t-fDGYxyR+BG*CMdM%9{hj*B*x;c>WPssKbc`5?sqnc;l-qgLBzoyt# zP$}>Te~V2uwdQdr)#PpGAmXa93I2hR0B!H~BGtRylM_e*{1^AT_Sa6>VicgQhH^fE zq)1akXP(t@y7d;1qzhBWMzM(v|AUK! zE0Z3xV_T5LVfF2u+n<}aub!@wHH}iA?ZRv-i7vYP3H`H2Eisyg5fKq&WMt0H&T?{c z;PkV&h7>^VoCOZzzS+NcN{Im*BARYYSpb8gk28^=*R`#UgQ$6zfFH3>QtgFY@Chz> z8OkbmR`$ej_65dk#>{^j_-@aM;#7JMw8X&=iV#ecu4+|n=l9d@C2uMwM#Mx>L&Q1r z;?;>EjR|_ReWbQ=ATq1}=d;WEc2WO*Z4vm7$(+Ka%kD!fb;rs3UD_3|3-XcMQNsMj zpPuK7kk_U5{`+^5kA1LgcCE|%p8y!4Ro)pSDs|5&$#E*ki6-(rp3j@Tt4|Ke&-0MN zzWt5w^|Acvtz1lho_=$b2Y!X2(BJb^QWWu4B-}znggK^r?xb9H9Ea<}t(nlS2gfRB zB10kCD5Qb9BJ!$C^aLwVlyNm}jQ-77pwc2&d;D9THYt=^bi38*=}Nx$_aZ}_o#$Ye zjfUl^DGRjfA#5_bTY67QQN`RQZ#}dvboqabGaRjCaUn z8#HIW@maBb!I=`417u4^%5AsH_%!X#c`pLBc5%cTb=BD6iW z{oTYq^nDu9?wqL6s)|WWi5n^{P})&XIoY8Jxm6K)t_=Ci3VGga4|!7gysIsn&iq>j z*`mSLb%L4%n3)_HgQM&sUTL%YXq<^ZW7ugv?6BNT9pCrDU%jw2yzpb72s;lAO?X;U1 zA)v$DCI3Ewp~L6!B7u$>7E@)p-M1h*H{?iQ>-nMm^X zg-D+t8Ys+jc9Rh2_gbiX{pWpqfXq$z)_c}fAyWKw@>tTt^PTk^X0&pK`DdzQ2Ua4Bw`eU!u} zEbE`wg`DJg_-ipJ2$)Nel45zR8abUCIUBZJbF^RMTGzvtr*sSrZqLozc#*N$u&@Q` zkWGms!U&IOS-!4zx7RS_9>MiR_EO-1-1xU^rR0cC+O9{X0SOrk)Y_!#qkNO^W6FSI)6-~5 z4cn1sU77_dovW-0};T|A^CAO7fjR!zZlSMK_TFM}kqu`b7k8E6i{QP_Izh|iMPnUSLL0n)5 zB;s#G4?DYx>n<6DBBSHC*_d&j zz`Y|%$U6#ahmOp!JO|0cRZa(?#fvBre#i{3CRlSD&rbc@sjVIxY%QH$J^?lS;%5^Z zqFiemZlC?Pv5#=tUI>^Z_TQ^Gl%qUJEqFxALYUq#aAd`tkSd}(yhm-!Uz;&4F8k!;w^ zNp*RiPQL>AW=$&BmF-buxm!)1Ry0m^w)NoBZDANdi*Gsaifx)?u0ptJbLK=M1e8okk( zA}db=kNY3%(tH;N=ClHD5gM7JYOpOeVm+Qt15TUpYgmg5;(yWA9gZqnaec)uA|k@U zQFfgI?iJm{Ps-L6^ehLl4Yx93FGvNyjCC$!_PAZwRu3>SaTw-v2&?UQ+_o+wtD$8n zYGJ^P4)}I5{hnMOioCo0g;!LwUW99&M^zeKrBI<3$Fz|bugS@2lK4m6&~=mYx{J3L zfyTt|;aZ`-@9u4lg}57Emz!%alWYQEi)??=oy6+k(L}`ke4|YM_rv(AT&>2QK%{3C z>C`#E2c_q=&ri{I4Ku5K)cJ0S_hxp-#w74?IHJBlr#qiLtT5yk<+a$TU;gkW?1s-D z!l3)w32B=}rQS)$Ih}vQwW<6l%eZR|>saE5K}0UqH%N$_31da*5yLWw*1ot!ymv1G z^})X9@*VY4P!lU1bJ13;Dzg~6=6H$Xk($W64mKW@R0_kaWL0$;Q-hR{D&wi!LROcT zW)*Qc3JKrzG)kN7#7z}8G9A-b(o9={bBS()4H;wQb5 z+hQ7gxnZus?64i1yulLU?liI;D7vAW+LNeN-aYV4_XPlA#5m|OyDQ1hzw%482;4w{ zi|kDs@9nsUj7iWfK}=S`u_E$1<7&@VE=%Yeu}j z6GAsqr0lME23W5bf?>@mh39)75#ErWW$zDxso5;(ZBoW?lVG(FS>1%*oc2xMdsMxc zWs}$IjI?y}>eqj)@e1K6nEU~doARp|WTgAlpgo~FiB^-4+qBNyieO#Kz(rn-)$QPu zyBO8WE#yLx`urKPRClTfDds{lW+S<2PV@ZjzDu2*3ZP2g#dKApgX}%|Ddl zao6=^!Vn3eRyS`8nI;as^zDE>mjI|JX|VQ7vG#kT&i!=n^NXLwBJJE4V^Dl!zZ{WV z#tLs)RUVxgGT7EBm8`yiXHKWLr1D>l^+F~Viey-)*+fq*i4JBIXN(QFr;oaYWp`6xOYpPqZCm7_%Eobt zGm}0YLsMdgn-SK9GGNQ?tBccOHBmWwx)BRul4HR~sc^9ycj#{plo8^|-@>{tpBx)kK1GQch#3^GJ7fA` z(A$R<>;L4=HDkrj%09m!q65y6!F4u7=cBry5k_lvkfq4A9}LlR+8pDnvymO4fwNZ( z*kSharqPOc=cg!WT1$yaRJ3eadMsx-@5nSIaq$QFFvICJv@28cS{{39B`3mCw`FC)M!s)mK+xAWR`UfrZ_v^bSP-6hme<-K{adAhA zUF@U?UMC@!eN^*Q;qa7B7K+Re7cnL9W&CA^JF4gWDc!GMzHj?@-oIHW1v{)+QMQ$AQ67d{F*VU^3?l(cvo zqE7;n%lK04A<*4O;+Tych$+NR_T#6>jA0d64MFVIN)%jn#q7Ij8=8NJt4KxXby3G< zX8MRq&-Yey1!KDdQ^1D3JC)96fec;cKBvOee|WOMjR*yWiT(Zkg(DkN(`_=WECXGA z$Km7N%PR(EP~7~Cpt9)5mu!WE3U%u3W-eBH)e$t8g~VF7(T|-WVxWf8_Wn$P;QFNgjl2GY@O=bi@s7Qv7i58X@Wr_SI3Rc|{ zo-MJ4wat;KBmo{?L19iwF4UrE)o-|D`)*CxMf|Y}nN~_nxge`>TM7d<_uF=hDrxvs zOToZ2vnnN)t2X&B_jFR~+sT=7i{YM{G=_#>VgxDUH~z;V@dGQE<2|Dvb{I-%lublm zd4!bLow;kyJP7{}WA7N<=>JCj&eXQ; znJTq0bvm`}scpAYcWT?V?RILXwrv~pA&8+C(OYg=1BuK64FSnG09i-F~B`4sc2Z$5ggQM-D~x0p76KI7+pnK%18 z8zW?reVa8%d1|IsPH@sZX3`{C6&;jQB1e_DVFU3OpHDgeCC$|Ohsq&iF6hQ7Ei_|V z>W=m2@}j_KRL?C`lyDs$TR5OuxS_Ietq1#{lpp&EC0>^>I5xNd$}6_$yK5j=3JW=8 zF)}eZkXF#a_n^j%IQQB(QqxgT1f=kBawaDwVdLZDV< z$t7NKx~CVH+39NC`M2CPHqSF^6O=A3`kx>pW|1cw$dGy!I`nWcgTzZ1+D`~$nA$ER zB=tBABnlODe-b!wHrkn>8oero2R-E^R|20FyCq$!k%#MZ&yQ2#+{2jLl^l}QTs)IN z-p#-};fu#^3zBB{|Af(WU;-1+VPRo`wz(}~x~kRG%&eiIK~%Kg)9a0si%VGcruF^Q zc1XM;-K`NJVAfM8Mp$ip;$UZIXE%TMxHL6B9s^FrS|0pO`Lbg5C3;Z}GO2d$#W*N6 zc8r<4F98F?@c{1rTCgxy1VKhbvNcFWGM63>Hx+6mC zi2!XP&x0|dj3h@Br$C*MOd`n>i6&jta)2xK4ReRAM`$HhUW=R>))O&76#n~dbD$L5 z3?0P05)pTZ|3jO0Cd4vi8Jqwo40ez#840UuqPP?zRS>8Un>BEBPjpaG2rW?(rVsW7 zG^zJ>U*GY-Q^7~_E)Uisb~oSAZ_FrHdM0itE>#>+JbVN%eHj1wL9xPLpR`HaQ4`tR z4m6aDZe(PRR$6urft>0+B|Ss2gK2{z8<)u-+Sft}Lc;OnM!SDn|&v-ueWMOtML zm`=MIG$!o-SM)PTn z){Esp+5%sx?rz_rB9q#jSPg(##Gr}mbXxE? zuIT>lXMCahgOFp5s9)2>OP%M5+H4~ME;Yp-3PH(-uhGn?xTmOhZCY+v33ya_tDN&)Gt}&HVy`l*=yd-~D0;se&BM^8V^8n#IMBD^hk;OS(BRMpc@y?uM}~K+7JQ5M$T$M z>3CbrGs*%VeG3)MQ$KYn{v@F!zG|&m>MJdD7JAZwh zC;ga4?S2YZbF^d9MwhzdfaS$kV%m<4CJz+C-%)~CGnQR4ImOFf==9M07%C}OuR8a+ zYss?+gL`)PNlfF90|4eA#41oMWO!e_4w0m)0Cw$=4ql3>i{0+69m!Cj1PB28j%6Bu z_ihJ`kjm>2M+DH@e<{Ynrx)S;gewzc0JlTmec0fC^*ywdXxBY-m(vG}dW`ytKhlLM() zD1Rh@u5|R@P%v)x$DCoHIZPd{xai&QDD%1+uKqNwtFH>YPkml?U9W4D=-6z5Hne#p zuLQWNNgS&3S)IH1+C1G;8_Sv1(d;1h`I-4nPbu-0fq@=7=t;+MuA%huy-XtHBzBG_ zb{C>OdYB*TCH;SjUJjX)?Ec-J{8G=V*EVZbz$NRD0Op4m4|2p*7Wo_@rQ0!+g$pHl z*CnxedV0>z&GqmPs;X#UVPh{WF2X>dhx^Nebm`AB&u?euhKhh3x9bIjB_$<5An@(& zO&HkR*f_tqn4FmS{PK#7iY$uaMhl?BJWU87Dlya{u0U{@|1B(FE;5B90!Qcbo7J)4 z4Ti20+>)uV*@gU7+z%oVW~>UuW!6g%d29nC7tJqH^yH}%t56=j`)q?=MbRw1=9`G| z@+jPjyKZ650b8>;#r>|n5fvl(Jh)1V6OI1Nd&;yxUajygsntTzq8mNJ#bjj%24w>R zztnD)nQBK$>+V67C=ii=vu_xPDJN-w?EKn>FJPi4jK=VS611&7SMZS+%26?t#$VV| zXrLfM|MhFb#i5d3P_MP;+AiEU2UHW>^5T&lEN00aDH%6OG9o6h@Noo%NE4-Js zqsQKmcN-&m*_ZGR<-ce^5$kKq@QL4+S+iO#2!SzZ{h;0J0mtl`hJwMWc<~XWgvU1G zT4V=V9T9O#%;ZMy;8v)>i5X%|V*H_OSF?Jp{Zu@CiJ4d#Rt_%0+!wo$lP<(N`=C~e zIIIie8QkM-3@=&}zra9fS!*-%73g8SB-T9Z5xgR_2bXWJr-JBOV@KmGB6Qdy)g!Ak zr|VmMN5<)Dkks2oZJk3$BiP#Gjpf*ft77e&Jv{}lqkVIWJ5d{mgKQL+MVmNGa9 z;FK#UHT4^P071#X_$mO7c7*#lz(@qpH;7TELi2Zqg9XWgR)u8NRm6F&A{OlqG<)|( zh1=Fj-bVAiQICB?D$QtpG#M&|^7rgShPC!eiaV)Si5tc>Ekv39X#!NYNHvD}rtr6< zs)qn+oLJd5rmudpxw$_6g;#yy<5~}Huy&S2zlWbzOY=UYD3j+bJGpFFyQI`?Z2p@%va)Fz?G-6TYsyfBWPr^*hiZ^E8ziUK&= z6mH1DoAw4QcPR;7bi+hNEd@b~?h^2j$2JYL4F$ic*B2(LKDH5}ey?6x#A~|hKEc>^ z6dzt%EFlRZ8at31bTPvWHY%;c-g*1=q;8Y|yzhte3qs-re&6vOAErQK?T53ZyTVCS$S(0og} zx2}V)ykCr{@qMmC$ONyQ`6*mb1)j1C~Ei`}`!0SCI$5NwjyJZw!eu^`=|g!oe#($!$V?_>K2HQ$`IIUF@7h##Gsv4yapS z`H{DFbpTWL5l>wAE_)qMMq6rW5c(A&ca(PWU+AT=WkVZu>QpzxPX^>g(f> zub|!TX4 zu&61wSBY$`H!=h4LHE)5C5XX*WkXAlF zxX+9;A;J;&Y$_Kr^j{>GC^{`wdh@YTyhMt6G6GZ5947E0=U9yzC`XsZH^;hixkR5r zhrzguRK!=PRhTdDJ>w@U~g95`F zGQqhCSy`J-?bVb%3-JDy0A$x)$DC8y{~&vNnkt+G z@d0fq588~ke0n_7JIFZyU=4*(0U6nu?k9<=yL_yB_y6*-wo5b5?%CJpr_jMf!f7+l z{PIpwTvi_kugW(BDfs#M$5b^h%6UpF`>GzmG{Z;#sqjWYUrEd}O;Z2$H{5z?%$1=M znccD7!1Kx{tffUsSsy(eXLox8za7{b3)n-~X`AV&L~yg&&ef)(Q_le={)v&f>)kpg zX($)qRt&FC7w?=YLUd0n=%7jYv>D(bO6YweXV!f={HldxTD`+UF4$+AqW`vX7DB#2 zY;{KOW1^^@I7$5R5s-T*M{-G`_Aq|-cL*dOqwjw9S2m@wurL`vdV9Q$E%=ZgHd2oH z0w!UjKkyy0{h6!|2ebO>Cqr%19|>G3zp!TYWcp4U8E0n(9cv6J={L1fjiL%%{U1da zr;CywU=z zeHaoVVobZq!4B!kS~MVUmOtOm-qRRMUDHC-*;&TN2Qnw7aS<$QgA-l1M^qG)#_w>Y zeV=~D`FqX5jb2}0Z*Lpe+1Y`~K|MWi{SxSS+eM>%@N1TmQSb&%LFF%x4K_Oz7cYn_ zcRafx2#IU8LnZ4bfbaEg1e3tixzq3GQ9>}Npa76$_`sdd)8SmMK4wKy(&|^o*cLEFLG^FK*v1!aU3NnD5~Td22}ZjHtzCF6{Zb* zExm7nU!7HdOGlzthA6r9FX^`(&rj+lW6ma*&K7=e5+U&{hE5qNv_3g}cGvaJoPy>3 zI%$J>j0E__rtuXh52H5tR80{!tdBci+GCSKpxpI!f&4(KVEAm6JX>`G#QZ{dD@Tf) zReN8LV(v^dWuCFZ)cBXaVF)`Mkuw%$@C^z^57k^RwxG9rdG7I2FV4s49>av_XfFsW z`irL!GC4kibEog_Gj$2tF)bR>zn8Uv)p_^$o$(&8$x`#u1ls++OJPSH3Wi!o6zPV^ z92f!GBWZWysaKL6^O5CY^4O>XqZkd)}OsxYcgl_q$(AJ=fzUIldR8xO!f< zO-tFH(p;RmdA^0c+D|d0+|4Zbd_j_|0vg$upP3fVBd4p5vbGxeZ&iyPA^|rMf2VaD zIHRRgQ}z$n}z^kv~c}opS{3vveW9JRiy4E^_4ovA48?dgtfgPejY3us_V?YSx zp|9U@9Suth0IAd|8%^nCM}$?l+1vVf`8KX1P8HGrItyPe#ebQan(|KDVth#W?X#1F ztLMHG_Rm|BsWQ*X$Fq|`7gA-0Wkq=)b$WaHy>U?%a<=XZET+b`~TwwN0siK9ctMSKn~W z&+7X=ROTto!)ek?Qo_TP)JQpun#@j@wB{zStgL{OLH73c5D^iYMwa<2TG?kSbx}&TA{1zUhCi#vCQhhlCa#jt{km|kw zZX6fgmsrgrwzn_zg&a(fr$@%3^!P6K0 zp&RxZC>-CLLu_q`tHToVoRox}f+Yq|w(0H`g!)}r80wfZT4jtTnJa8FPMD>R1_R^o zO}F)rHTCK?c^f8qoY&9+Em-IJIG0dk6c%tjFxGX5cs)`h{uhsMp-lTQeAG$hsjrG% zUF%78J7RAon=X>4M5(X>H01Wxk>4M^H))5uebI*hR5|1eU$|s3uSpHzG}kpQ&ze4! z+)e$Q**8HBLt6y^%&+U~>XhKGG83dtl=6A@At|j8E1t(rh^`9KJs2_R@tj;eOe-Yh ztVeNL{)E%vx`f^d8-n(LFl)^%M+0j{MqWnzBL}Eg9z~PU3oVZ{Fu#qJ*U473GDojx znin{~pKq)u-+3lXojmiJ(M(IX;r(HCtw~aAbW=N|Q;%+#5r!$LrOn&qm;(NAn3orK z!@e}j*(F$xN5HQl?mo(KKMYG@-;3AQz-tz!uLhz$FJR{*f*VNFoskx|&DAe?al4(0 z5I=slFids7%iZrUn$|C^s59x?Ut6x=jLvjb8>5;;nuu3?jN?yp&WzyPqsxRN+s!|d z@YxkP?CN+MNSuVH#@b?vMI8;RGr08Mmf*PIoCa?Bs*ZBdby;arEeD{$q(>~5G1e>h z+=mxS0W#<*?BRqlwI$znf;0fS{+L`trv%}O|7PZx^sg%{vwN(xX+|6xd#P8q(B%=Xk;Md!m0Sb3l0g<+!z+u>+L_ox;Co#t7{Jlo57XZMKJZ;vJ3 z^2e{?R^=QsYpaKUTu%$J5}5C@ru7$D;3l=THVlgi-ybw7r{h;OMOyiJF(d7HMw=z-GXu2$Pi6lKllbWG0gt9G+X1|Y>qi}wwW?piBGtYf~75zWSS z6``#IwoiT=7!~Lz>{lfZNy+BEwV-qIP3Wu&K17Gb8dJ}24O(M6`!$mz@9RV3>K0LfuM zge*3~_HSG_jE}}v@zv@FAea{rme=$+Mtulj#H`M2y84VL8{8&B1>2G;P*qx4T6%8v zTVACZB4=Fx$V_}=nwD4y6Rh6KwLgh$GYN*3)tt~C5`jF%q)eWn!v{4^t=D|@|2{9t& zro~Hr-yySLE`-J|$8VpQXJ$IftBb13s*9@}=O~KHYrT}%)9`bPepOZFl^0kZkS1_3 z_>m}|7Gb7tsleZAHwUVjV`7{sFGR%^^K#|kmzABA>n+VT*rUeS7&~xt*MSo8&PuDi zCg+EEDAM-5a7 zXG^a;?FM?){JuMnR%r!YMJXX+M$kj}l0lC;?`wtQBn6-PjMkqZ1B*_kaZ%N21zlCz zN>5K?O%$4Xm2k}ZY>Mgi;(ER6-EL`ojdeUZ$(hq=9TDD@b8OW#-9VUT9|NeEp4lwZ zV^~pEElyFI9Xr-Dh*=o?GwWqMrSq9%CUbaH)CU+z9 z3b}D++~PSJo&q~Zqk+)RiX0(zb>_G~Ybh3(8teSwonEm#X3u7gm7_COlW?2HKr>z2 z4Q?$Sth6w+jLQ_1IuTm0QZh1-gmQoHY%e9t>Uc-zFURPXc3zzvYb+hEDMLiV1ja-A zyJ|PDYDT6RdOI_Zrf*SwKwwYl~PV4C-6;@eUdO(<_j_NjFnt<3+D z4nzad=!fm@+90vLK?=6)LVzss>FJ@Np?!TnHw6XZ;o)=pR##Ws+uI2U3GZ(2C@Cm) zbvJTNbDNf}wOm2o#BrlgtWP~X<#FwAMK(B-bh`H{v% zLP$jb!_>=yJONPIe}SvP`xnuPq}~`*d#;!XeFoc?Kn5DuWH^?4VdD&uA_eGJKtK=1 zh>o8cfe^eQUmVuPXRwm+pZw2jS(>=`J}fesA`IsXQWU(Y;UbJ~F&dol(Ij32LT;^N zc<$vIMtpJ+o`hk4)I)?ZhQl& zbbbUfnPdd{ewE(23mIC8>AcbbiEE98Y<7maM&=%wMErh(k6mt z9gbZV*rgV^E}K3~aGUZigXg=a42-PCOyL#kLT_$XJ|cnRJ&MC~z&#E(E7Ppvr@$3% z(3m+FV!g3AV$mv%3IWHC9q;iGW<9V%nH7_wZv-wzN>b81AGaT@^m`P3-MI%NCggTD zwyn>&4^871@mS)}P9$MYH`e#+L;u{rrLG9ONTZC6O%$$N z*^W=OOy|BcsHR-n^@#Dr7@xW6|1-Yw+xpqRN?|Qc*y~n~5C5Yd6z}S6tIcHwa00$F zk8Dl6A?0)f04+s1q2#|JPz zn^h?K9)rh6wX@+w==vSVJ^w(hvT20iMPC4F+q@uyGhfa5`^rM4czvlV#f!$qj$`!%~5H!v>*>6?vcJU^^-#M~NWu1ZOv6gpl%wpU-X~6SON2-oC<@=$gr=kH zz9R$ihY0a4FJWP=V}1_}p~o7fW^LQ$6igH$&v8xIY8&+NgJL!Ja&%mgXNh+~kaPf= zG@&MXbM5)Cs4)MRDKYsANiu0-LMB$mCMRcXY>cV0^*eYjr>CY$%E%xfBWI+iL(oD8 z+c*q(EJUg^9e#dh8E5#Z0o-8gwRAO2CMJYF{`ONEJdyn#d<4$`M5@G#mls9gKy&zuF2rBw92EQ}z7l9OU z8@RMQY)02UWAnVo4K!oneBd)UY;t=|HRKqzupdOLNFCtGJ9Vihe~on^8{!_Lv6i6?7aCu!h|f@Mqk4`wJYDLP5B_%5 zGltrSn2bGd;=VT~UugL940#z{MJ_tuGdl1_QL2+`k50aaj!{4SKTA2ktwPHo`Q7oI zC?kGpUfvBgZ8bRNY<|8maUPsM7}Z5^7aTux5_Nqq9CJMNH=U()Zg-dBSQ2CkrVYTg zyUc>hsv= zsEcfg8CigEDW)A6;|&BMJmxPP>BEromSIiRi3ai=R$PKAeE;h88HFcC7wwIF%Q)%x zgUX}Ty@eWU(&E!9d@h&Aa303(Ffs?H+PyK8?pF2+*!HrLf=73R9Sq6QzATgP>Js$*Tq6x>&PEN{x{)xJtl#+>n zn^RC;V&@zuLU({SDxMlx>|0(WpIsQ1zPhJJN$YZAcwAM||Ct@rR=rmQDWAFuwG>lu zD*60Aicv6*qQ$8t2*@LWIoiCDE7RB6!8G?5htdaV;>q3Czo;C=cbFNZ`pF&)5vIb9<6L_hWxYH0b~-92#{XQ75aqDw9%j4`{2&g@3J9G1 z+ezU>W1>VWQRF8}8`}DDp+^Q`0w>3Cj9*G?VM%J@pfHCX2BPB(SNY@9rl9}C!vfe! zHoz#0?R9m(gZ{ZlP<HFLS*i0QiZvK(PR^wX?tgN$3OR%Hq85zP3Nhv8_ULJw30Yr~IUp*qx5Zlh%@@`ZQ-=Ckkt-;PK!b;?- z7~y1td=>{ifjQCI^2*Mobv2_5SzjoiQwqv@k-=En1e!;b`*b1I+#{e*D>ax`K@oF; zSOv@_u$8_bEe^bB3Z5y!Tp*?o7#MlizR_Rm;?;k^x&D&u%=sAn4&ynA0v8e-K0Bdd z(xXS04Dq1tO>q*UWUnFD@7o}=te%2a{+SFcK*Nkf7VhTc)!h46?Xq|Lo|P{wsD0uy zK0ZQkl}S6LEMS^Kq8OpqO1+|GAnxrvSin$_z}{hBr=z!blU(%M{s7PT`{4+#(uB$e z1Y1Um7`K}t^WE*0&K&P*shf);gL+Wwo5to?daNW%fcn98x1E8;6xk^da?Xkm;)K|g zr9^OSY+UJEnVXyC*WN)HQ@7cstqe1c>B?KTX0;UHVKb=1k3fK-6Vi4lel~`z`8F!6 zOSJO#scS)Fek&fQ%4eV?`rF~fBwlRCw$pxil?j2T;-R430z!i4aNXuY3{yJvN?}Z% zx^ciz!YI_nDD5Y&yycnBzm}F`F0vme6N|~AX&(ov$~((Ly129UEWe#BLip`a@1G{^ ztnXNm_MA8kBQ-L!2ndNuNl3D@#IKA48(5OEyQTg4NvCOXeZg_BxqD`J^lTOMd&-&$8vGU!Bwh)nAl`dcBkI^{3 z$jZpjmHS7mSTP(vPk^PR-rg@_QS#Fb%M@kKJ{I3+E{})Hb5^0}Tg7msta|LwSbgQiHCjj0KytK0)pd$ah%Faglk2hMK4Gu6UW;+es-v zc1t^iHK#eTfy_sfH+x#A0;eE!MF-ZhiHRUZosA%>ItBRo|7u{;!FbA088>|Yg)v3Q zCcVG*Vost-LOqz2o=$*{{`JU8%1YQ{ZEa0CvS?)DvSj-3-~EP+O^KF*8Yr=&qr-3w z9FPgjCHzZDj*AQoQbc=LRZ z!%?=wmn@sPOxaHv^;5>Rr)XW&OS+n?lNArP%UhVi+ z0U>Zn@|!-p8wIa*3m1&K=maTpL>@1V-I^+*Kp?EU{O?Mi(P}7bHEtP*!;ujoc{eWy zz5KH_{hXLm;!~o^$QGp^A1QOD9>gyF74)5->C9$bM++jwe_VDH^7@ez#{q|c<`5;E1@J#xU&A8g`KefjNDym6OC$QgGs ziD*xOV^hOWVx`aHalS3iR#2LpN8L?P=iU5+>vB@SZan1}@s2<4F2pxKk=@`iZ36F8Vn2otXZep^GM> z$_#B9Uy%VzK)$2CF75h8{=4z#l~ty?AJ;))s@902f5A9|wxeiejE!GYh#QlCv&n*l zmxuN$)FMie<;OE~RVxXsF~-c$x};0}+``h9*O@AHN9j7tyxKwiCIc}g?5~)S{LARW zkVi>@wdL2!o$PKA+=GA5HBSr;@nhRw=GJ~EPJj(7zGJ=BV1$3hZ_;$M^z@zWewbX9 zk@?ce;(x1VMDAK#CUoE9>3RA1`a&Re`!Hp>#M-vn4UUtyR#sOR)6a>plFm2XwLv4C zUaPF$TR#Zq>n4f-aqC~3S=aD(pHJ_kNCr<1vWORM!Y)IGQI7}jZJBODq%&3IK5v?i zWE#p()A=wN8ksCeJJ6RXHM1|G>I58hUNW2H51y~ri}7ku1%3Aa#u4(O+vo<)Sqs~R z-{AKXhPZ|i+t}FXwzV|MTM@RIa@7b*f(39BG=Aoc+{a2Y9fu1B-mfrYpg<(nQ0!nbELH_jBZqYmHqeWpziO7+FEj)wWD zy~kdqsEmoCuA8>7wP|ap)#G*~X`2PcL?Yy3Q$FH8C#t^j{nUQSqv`rKl)#Uu!e~92j57q_Y z=HH`abN~xoeWHPik60;YGcr%kF2b?Fmq6Dp|NP^ zJFC$73nRkUWv9sKZNjaWCo?85cj_f)Y>6Qa{m(v3lu^n`Rqt;4Z`X^!bQB)lhe=}l z@IR4}>@^zdiC_=U?RVPh^0D&N)aBDt0ze9)mK8Y92;rDC9ZtsDcSq^uN*;&MlRYLn zI)Ey08hkwb{QNvTOrDsitOeEHI5>;H0|q(fh>C8yTDqi7fo-M#7hdqHq#Kyo7DtZd zU88_Ns`lafD)`FpN_rwz)X~v$894) z%28f28n$jorMPXQLwhHa&d`{MD)kpum!IxGSWV?M|D1%m$#FLtN%Mai$%;9qwwNpw zi;RPN#}NyvR>;X1`5Qbvabl<9>Tz3k<@N0WGS+KQOjCxAY}Gwisl;=Vdbpj+4u+k` zzFA4_9%9x9-1l&JLlXQs>Q6Njq{~(0!f@?@on77xe>-~f1Dbo#eot=j^%k9e_NQ7G z^A5a^aj1TP3`G=w`U&vqU%I^ymM~(p^FB@*)Ja=sb_U2cNYcVVtMaXQ23b>U!>>+Id$N7K);ZT(A9T%29R zDWh0~rH^p_ZJXG&-ZQJeZ)D;;f>(%={xjkKCrHroKm^Bob!LUTS@-z`ECSNGN=@ii z-?KX1K7@@|Pq}u!2y1+-VtM@ukIGEGu$FZNdafRC@fQ_(?~Rqf{(H*>-(ifk=$$1l6?F(wEquC zz`Hw%>izE|W=f~6yf6f%c$Bg0z7JVX^_j;-`vDXHEuLi2O)hkY)9B?Peh{QCx+jsK zwbsTS~m2>@D_O zT?bPe^kZ0JtZTE~Aa*6`r;>6YQX zW|H8!;}BPClW9I)&5Vn3?`yN)e7>Tpn)q4V^EMDZEYUplLbpzZT>1}beTfAB=HG&4&n9-9vpt%K`;u_+9|;VlORZo22VwE|Sg}H+G(3Ktn&$3-_btz` zV^|{nl?>Z_1MgWPe;*BvXd{smD`ClwnL6n7*Dgjmj(|HK6ak`@MM>A!RVrF?nsg=p zrku`mE(#ObLl|)yzTu|}>g1S1s$h?gg>FR(;UopJRhnXv1-&^pxN4%LhGby8i?97W zhm%kq%Vqi=g<0=r`@Uh0ARNv1)U9#SRFA&X*vREdiKLcKq)e4Ow`z54g{`w^kBPP2 z9+ZSd{bvvH-SoM(k$f~GGIC2?oq0&#{K$Es&us0NiqiAVbuEaW;WgEf;5l%e>gB1f zZ)F=Fvyj8|4F#?+e{j7wL(NjXUwdD~a&>Hqt}F8=O7iWBwZMVjwV3nPw(dI5unX)P z7VdeCcbgmU?HuXHw%4>3bpd@=$A4fEQL1H*En|2Zbxqbz1@X-55N=H7pX}9rby%PG z*OQp0DnyO&M3Ay^U(F}5?MPPjaK|wA1Szq*pOWzc#xuw26 zsQbRouMLYH%|ve5TFk@z#2Zf zQmvZGHy4Knhk~CH0|$$b{k6j3r3-x_L&>k3p--;!ZgMyFBK2%~8Oi9R=r}3asoJVJ zDL-m^gDtI@qEM5?fdf%W^41WJK^v8Fjq$(y;P+Bq1Vk zAz6EohuNhj<M`dj4QOF|1U^BbBmd~t8P@!JW7Fc#5z4& z{OOf;Tb4uhfLb_RKxusSZ5uY{Vk|-|23k~7LfB+09&ad#i0i0u{q%BjO+crY=p@v& zF{ZF`_ce^z8FNbN_b&^YpaGg<4(7tn4QOo;JcRZM!!Z$QIxsvs=*NbPDkVQJd8Oyh zW?AzGbZ`n13gDJ`b7)aaT162xl2nA;s=J5e6)TCXrTVuuq;5>&RixSx^>7fltx=`G zR{~-o){bT9Z7rb!m={A9+&q|S$ymr)d8{k8BwQ-BTk#=&5eOOKm9!ps>bD`jkVUNQ zCQrF-wE5`lqvQK;p6+F$P^PwlLua19r(JaQz-?fbe-^B(Paaq0PVMLAp{J>02X?rf zoHImnrcjB)C|=Oz*H+lM+WNSba^^W3Yf3W0eYJsHy*BU=kuXtbTKQJyx}dMNwZMyX z5q^u3c%Y2TM?-_-xtRP#;Hr^x_KUyaKKy&Mqnj{tD&L|)CORVJmqPd$q)D3`gZyaP z1URY*|Jfi7%P&$)mS6f&fHnTh=~tKL0L$(gw_l~@bZo2?diCoU?sC0#t z^O@rWRG7mnwc)ih zR+0X{e|KuJ_HkVwP(-PBRLFikCLR{&_ot%8$6?wZq^JuhrH5==lVKZG=G6~ypE7*q zO9jEbu)@+4tYyGFy2c)6d|`hTD6su!LAsSnV*TCk@av(`!ZnTOwO(VFz(R5DuE8G$ zi}N+FTC1hj013F_C9E?i0{OxR4bt=)W}2VdDz$7g3h_A!%8-5gX@*|aC3J+IZti$m zIR%0KGJ?laI*aocHdnXd%{+4#JUiqnS(M5Vx9um=Co#-1vqZSi4^jX$mAX0y@NMowc<> z8!{tCbzsk^jZiA>EO>3pD9knIe@jt#9p(-0kYQ)<2)8mR|DD?bIpH@IUA>vD$*wBN z6e0}HBOSSgqX&TPsYJCT_H9Iz`}0*i;R^rz9N?Gq;V__v10w^2P&fPy{H5(>GETB- zv8ijb>!ep1DQgK)tr)AMss zW##$nYe*h>qb+&FV1R(8jt&tish!=`cUsz?Qc_bRBYs4!I=4xPU{UFteVF9LM( z-B*lfCW?QO2O{@{UAvpwWjX+ypFv6xF4$w_`z`9>y)5wi(rSq0f!&h!Bia5@=TP=3{xJ!}>?fSbc4i@_!{DHI{EV;2;h)HI90{*WI@v2O`|?Ensy3>~Vk=mc;3YtYhQ zA{N#cWz{9Al92BhSRoQl20|8GYy`5=Ya2lvMR3~3*?V~B)pXby*;-n=%6-Xzk3)g* zfrcI_QUd+@MVK1fGP;t!YTyEhu9km9oo1?xqi2J6wMVm?D6$yZ-#6HDU;CRM`E3Zk zaI`SD1n!f{$vUvEF^G;TWt=KVtb0l;jgSNnKP{V3TMt+9s(cNWX17kWL6j=eWI2Nm zL&yxvab@BJovv>kLkk`aV#jzuFFT8bFr*j!3pm{L%zInTxkGZY0+J05dIPL1-SKS1 zS@_v!e{fD8hL?5+z6t{LvcPi#zi<~8Sgc{KV)b2-ZXY0nBsWnd>{|-vGyr%x*;s-OGo~gUFyD_usz=9+(r#zQ1zV7u_U~FdNkHev0E!ahZnWW^u3-z2kWl!Sp8d=A){d~7 zV)Jo`h(J&RIHYm5cC3qtitMbt>}_H0ZsZ%)4@}{}-rhxC#IW*!uA2TSdS^~seR*j+ z0$^i9oGnl-{5fC*kL0p28ClsL7ybDYC!(pgmKnVE1xwYpmEGNf?CcEm^oS7Tp&wU! z`J19{zxNviMi-NTs96s-Oed+((r3~b{I@IBnPOXn)gDez&Wd<1i>ZhPr&YHWgAdPs zyoBB9q?LvSmCpCiE=gt=vxQJ?g@-bBz5&DVUen2kr#oNtbw4u3gt6~fMFz+VTNAe@ zT}*~_I*n#~3Gi#qCa%8!B(*)Zv?_C1t@8Ch&ijYwZI2NKQ+#``wq3J zw|9pu<^iqkB2Dx?hv_P6>?rK=I;a?}TJyTf%Be?yO9PTzg=Rki22a3DWhcjoDH|pm z+WV#FJC}a}GoQp$&Z^BzFI=c;X-3h>ng zn|{N4LFAO))HlD)pR3ubN;}o=0Ml)KvEOjZLKnN)7gRFmXIEzz z#hgSveyLhGS((@x{yDfg(rH*tt9bLG7gRjJJoe~kD{q5w&q`~Tx=;5Sy^B0ja$my(h5diXdh4J#+9=F7!Gb%%Ex5Z&a0u@1uEE`c z2X}V}?(XjH?mi3_bZ~a^?cKX~_x2xM)l=0|Q(e{bzUMsW`8_S{>R*pDhy@Cc4>b7O z!tJYLN=`pU=xTZ%@|9G_-ldHP=cT$+FR$Kj`F1?j=-N{Kh*t_@d@LHNm^4AZaulre ztZZ~7J-xJ)^p$hZopCi^0xs#X>#3+HEwI&Rt)~re-f7*L`|c8hc#-qxpsQv>b+om4 z#|IiR%wf`UJDdRIWLFa$?r=z>Hd-$PCSkJ8_gYs6v^UKBw+oP8bS-x|f)&6AyBjXzjvvl2U1$CrC zAUn0(wDvuu<6~)OKQPV0#M$P@?~%!^)ck*&eZQa{Z?E)~NdLLYHdbW9jB|HHE0Y$w}1I%@r zh)#5crhrn3?MQ4VyTCJW5*m04$;;cDkCzv$;N|av>rMrQnSg-L|G5y896jk4rhW{) zZC!v-5!ct(r)$tyg}T)az6CtnFYD=r{@h*zWHb$SaG2O$#Mp%`%%m(Vq-e@1i;Xdr zq+MSQ7Cdykos}Hr)stfrI>{25jO(=du zcNdK7Ch0hN$vYuLPMNXbDf?9C3fve-R(DW^CM!%=GBU{{H>EVjIE`uK{na>mIde`h zDXkpmqr|m!G96O)lCk#Au)(vY9Zd`FXRM!QH!v|(=9Y6`8GKw7IMJpgE$Q?!S@;Ht z;^iLsM@knyh^o5#K=q{`#1(+1_lH_2%|0>_e$;FPv^Y;{fgX5`&&H@32^~ zM;$M4HS%ZMTZ@4`L}km6ciYAWmCLmQSoa7$@d-3R7~ym?=S8OrOXYlgVfr?@A{}_q z6+Pu_ZfcoT5O;0yRl9%3e~hKa#3;Lqn{6|3gL@i#0%}R#EyqZE?66h>^&B0as>X1k z(sMj=6=*vOzrvrnID#=?S-xA%MRIkkUd3GIPJnMyq04dKfi>SHt_F$SfM>klwTQB& zwe{GyafcsA3~5@yz%jSXM5u^luO(JL|HRmLa6z;z@>{qwTQQTboaj@H)N zw^5(uw&B-oFbJ8c$p@(hDN?vL@5i~XUoC&sj!k^g1*-2=`Y}0`p&H;;Pe~QQDA-iC0{h=H(@~t3|MKoQm=877xypC(7fE+2oCII zLu>$0X?{-o!`mh3edLTa7>-gkER27^+xWt|71;^)a zkEr2F%1|&~nYn`0ADyG&_G(AYHfPkRgGaaOm~hET zlk0A-of1wz)i#^n_CgO4GR<|(O&~-j zqu-+{eRe}3oqPzs(PpMJrFp}3NbF;wkxvzDhQA+No4~tiVKHrWzo*fdeX}&<=?7b4 zGg(TCuNrRh1FK>wKW?S|HNqDc7k~f$U025f5J3-ziZE(e!&pGrJI$WSqI+EP*5aLZ z1<&00`o3*#ZPnU=c^@VwWIm3aN3f)E17PP4sZN^hwZ_u}$lpKRZ0J#)J+4geTsHpu?Pp_{7#KC2x@Igtcp@ln~Y_)XEzmxa@iilxcYli}%ZbHc%& z6K)Qhirn3(Z_6fZL=V`%-nRJNZR}K7AmCQa_KfaJ?TY=XVb}05@P9Y>IP%_k*|q|$ z1997;*4X0zfZoWu(|r|16(L&CYHD+^IcYmY;QS0H$6lwfBx=QMDHQLA0vl100_$?gm&eJ zD9o6q!+c+lX`Igv^;5FM|2f)DjgB4NG%oP-y!Qu1gnxPes`Hf{5o=$LMOlbAWBHUp z(cWa4&vJffpYyTQL(sa1w-j`FME1LVSB2Is)Cd|eYGy4dDN{>AovPUt@&=mdSL_6uC{W{;-!wxh&>5+ccPSBb{yk4#1}T;jCjQ+<%=aUBoOV{fHERom6=rh@gdEaId>TVk`FA{hlxl^mvLA)!4A{$cY_ub;#S2hSVi;vf#9OGqPdxqk+Hh7GfNsJgn^Oq z0V(DSIeV8!+c{SWZ4|!_c-Uk3hlHf0uy0diq3u} zZ(Q6rbPiq4b7a*-jWlL z9{)ej^8eQTh`97}QB7Y0O-SW!1EGM?vXOWEy9+eEa}Zcr@}MNcmstK6I3D}OfmsGt zzVy!~U^do7?;zPd4@KYS%j-Ul>B$1SwkL9tS*gM|CjZfg8Ug_*Ksgpx;{#5q4l z#!F7UB;7a+Ru=Edmj0PBG8WP%H@A4CeUyV5L)dp)!UJiog9G%syU`fpd?vMXj6j zykF811;ppfsqW#uXzk=&{x$m5Q$cq);GqOMx39by^iirzgh&7b;wWYTr-yUNa`kTE z0P=j#i>(ELAn13z9)8@}c9vL1H(Mt6RC3*ppJ4yJKK55MA|s3~s-yu}B^jFPgt4^? z_1wgsMMRo&lXEUm>bNnI>UW>xsBV8Dp-|DB-rEe`{KatMdH#1}) zyec`?pWX~`%@|01AxO`HlEvG~vf}uWm$R{}b&e zb^6W91-)q(ngvoH0t2m~ZkQM+ll$=Da@m;#&{FYZHU9AN+C8i1o#RdyMpPC?K1#1N=YJS5Rl_s!5;_A%e~#AtV-> zR-oz#Z9z;AJ}gi>OaCu&%n$sWT>ID{I|29-Nw+wc&D$9Hf z^fcc~ZrO$vGb95fe>m1@Rwg9O*Vg`xiJ3k<^A!#l*_iH;ZB@j7#3`BZ_F*wqJ33Qe|*DRa3H))oJFSm^%;>IG}R6aVDP!zq6=4 zuc61Y)yAiof^<;*?DtPgCif;j0eZpVHjg+V4E@$$Bp#yB`P=FWxDu{0F_X2LzM?_5 z&I^f=Y=frd3*Ou6F>vB0SjiL;DLrrOd1*Z2T6#F6$^ChdIfBd3*-lZr4Zn$)^a`a0 zMmvWYj}>*A8*co!?-)u6HheoF0kO_bF737$I&94FNSyb}jxs1SX;JfCJk_qlv$isJ zoVa}RxrD~H#)V&%xrea1j?~;i?8wMS$ehiXUu^hY$yz;Z8xI}`Qo%^=vH3ZnAu`WA zcL$QbcN1Tf+=69Sr`jaB;)-%;D2wfq>m65(J->&4o0FTSxhM9nkN35jSgj*$!O3lcR8waXjgKN5iA#MehPbiSRql3fhMZEAr3K!*KFOAG zZN3-99O|TR zRPY3=K14qxwd#I1Bu-M|lrw*K*sN;(G{?!AY3Xn{z9xLxm~t-Zdui0P>S z4M9tlXg39#si|}hc0$W-;MwBr?4*G5#zyYTNsYbb(nwnnUGSDskF(jNe`suJY;NRi zxkpsU7f(k`voy2*`P1!vuPgE}8{m+knGU=g-@`?ebe2POh=5AJ5Lt%F2#V z$Ecy@sx&mMp_zGYYZ;un2H~2fzkV1wmyJO}b`m;_oyv82pHKvL0e^;OOuVS&#D1|5 zqEVTsjQmR&IA(2IR$fs9iNwxeUOB1eL4Y)RMWBOq@t)xnID>1DqiI=XV{Kz)Wm#EK zSpzuJ(=leKvU5Xeymx7AVsBh>xxdRB`VyW)jj*$rR^3;{fU1k$7{eD}S2HOW!_LLQ z+0xYFa<8_?d54G$stl(Pp{%Rp72MvKRo>v49XUqjN5md;pb0Q>DwAbAj-8pQU*6RX zxE+FkNUX=vyI@ee&?DPIieA{rG`23j;542F-k376Yveh*pvfxePGVQG@JfDd@dUh3 zI>S6;4*g|k-I`7R-NP%exV0Rijtl?-bJlz33ho1|)Q)|24&gaWV78On9IXegDUe+! z_}G29MJHot*fe@y3(6hvY26%Mto^K_3pF(iK4ZcQLPTMz!b<#2J79}MkOABfoa$u}6yUi@N>XV`ktms>e|G8UTK1D{ z>*#Hst+kMRDIMMc&nXJB_l%+Cr68D7gz>CGLQ3f9*mz%!o~L}$E+*(-NkeET1c5H; z6=FawEw1+<=GAYu__S@zJ*7BNpI9u++_E-zmQxws@dv=clXF}fLiPVeYy1pp9ILw<*M=8EpMhuBA&k52Y z_kWQrNfF*t+~ll|J8f#ZeNshgTzVTOhgL;|>4@Kp7jRZ$G#yC)ENx{ceCEu|1)X$6 zv!=CS|N9aok}Zx8=oDURYjU@BaNIGI%aDu)3vHh*VLZJ%T3WE@M*>PCVikVKk4=tF zj!#M}$S6ol$3%x1y4>y^9+Iny*Wn^ft)Q>zEq^D)2tBS*B=0-Y_I_~{um7$p2!}{EY(Qe zed)*tTb8jQPwF5^TgjCE2y-L8C}<;DBVv>Os)*t&zjWMguBa6L=wFoPf5+t>nu@M*orjwnCmkIfEp2>B0YXp`)WCm=F^N z)h!fnVsbDwHDzUG1vX!UyN=+I_{PhEr*_iRaI<+iTvDj)Ks05v>4CX7U#S&CAJPOC z)AEg2&#{nT2i#Qq@Y$EfQT)#=5UD@m4)?3NMygHY%n1dK#6!D5NL&5xl^1Ue?Gex2)mUdrN zp`K}la{m*o|D8a8sc9HTTN)bJz-~?^rr06lALQu&39%I!9+$Su3dmGxk1GM)+6D#& z`uaKP=~mX(;5gTqn3$a0+>#VJv6(C>E#D$v3}+id59PIO?5LJH!S%GPtOV6%w(h}z z3rsWv%Gagzy`0b+37E`P?;mJW2LY%}Csj?`&;9+E(BzhiHc1FYf!D*qhl7<_^ZWJH zq{x!f*l5c2`TbY1Xce~@V?h;(6*}ineW&HYfZ)6H)y>X;d@R!3xNtFBb$?MS31t@% zClPh=1z7Fk6iIp6_yt9Rz*QhUE)KEInkh@zFdkWhjEvJke?_buU^kTWuS=(T0X$|b}8j9>8We0D&l3e(2Jbu z?jF|PoQfmB;Q;?hn%Cll%f4pjvyjChGnLnb$|otsEkV`>arxQ3{io`i`b~D&$*HL` z&A9CjAmy~t^uuxjE}hd?XLXI|ab*>iG9eNUXeY~T-DBn0^+cYU81+=lKU6}t(oW!K ztOc6SPoe)B&JWEG!NFp2I*Om>IiGC1pF(04x^7!E6f9rI3NkPaxmnb)(@met#rG)v^;OSn zycdARLTju6d&Z^)V=W`rWFmsRdjh{%o-4+++i$}-p&*DDs}Vgele$EWv795Oh^VVj zXIPe(zm|_@O)~M9sEmKDiwB}h{a#8QdN_37ajnKVHAO^fZaH3dd_+f^u8~pZYI+}} z3#()N29v$bj_g>IaZ)4i7Gmvt614j|BtPw<&{Q@(w)3H>_f(Zz@x+HYnUBpLx!TX3 z+p>dF|D#em=8fz|dnr?&JQp;NW4{=!l_J4+X&=&@Q>-%pqGnZ z@83|04tAbqJ|1UKelFQD+8tOjqZjr`p?wtn!Wb|UEYGOvtkEGisuO3umP(E-Tw`Gy zvgxzzK6OwJy?Nbv>ieM9Y5sNcjv3CvoL}Ox@ue>8|QYu1@hW*YP#N$fzi>?^)bEz zN0T6~t?XmV*J=EjkJqO{E;+qh%3<|ED1XV$(bWaNJU5E zHmXegK~>+}nh5+yi-~~Kv8j1&og_9<$S?YT;rG>Vp^$yEG z8q+0Upc{W1#WA@GtW)~x%kgd#P0%&rQBTP@dmN%OgwCT8dfP6t5J(^xLy$NM3x1AB zVw52r#CPYSAVPH3IZX#U{k!BvahIMv<2sQxS>&k#wg+E^*xhxnoHU_G>%2(k{rd#q zYTkkd+ZR|;7$a7Z&Q%^|b9Yi7b4RPp-dSLXvdhG`KZFwvZlHNYCNuhK@*dAgGPWw4 z$lXA#=K2iphgKD3?JY`H??VzeI$eGDJCyRQu!JIrISIF4p>>kVz9^|P>7|Ho8#cn? zZv$DrC-E2Wh~M2cHfo>c!Vz6Z+#c0KDe0Iq2ki%ikJ22bD$iR%tNodyudDx%gX zT{4T%?bgt7hBW%psYWLYBpmt536l}3-=bUIdlPDH2xZ^S&OEMkmX(_c1jWwT3;7Z3 zD%>4CQh)d7&2vB4MwlUqNE?_sRe$G!BYpS@_d|_L_WG-RGwpoed;^^CQ(e!h$%BMN@09b=!0?QOgn#8jVC%vPQW86z z9R#kAYwBba5fkuQw4^=W2y?pxK4sug;akV*`iMkQ9ZFFe6% za_E_9h@7f9Q|5Q(IA0dO7Q;Myi6kW#YB)f8XCn;ox6fG>){O4R<~H&N4czj5DAd5u zy&Bwt7vj6dyV2jHVD~%Xz@RY;CY(;R!cW_~8anH=Om+vv4mlvo+Y(}vctA9=$Zzdb%sHor z*01GRvRqNTCx1VYru!`wR>-lf+YA+Tp6hqcMW8l)wfvtBe0`5ArjOfse0y$kdeC&C z2G&)8{u8fy>RFZZYgtLI*A0!@%xi-1!*V}$Veiw>SzVC{KyO$?!X|TO%_7(LfoXhO zFx?Je(v^8M&$T9{4IHs}vqFZw?MRD5kiLEhYv@8BbI)s=!Zwx4Qs1Qa&;QAVNzwF_ z;r(O~i=*r@bcZpMERiaB-H}30H_bt5TljawM zEPC14jG;+d7jP|`8}C#U{W-VO7tp3+v3aIGgziH#@pOmF(69?J%uCHUutUh|Ey47M=x1vCSttogEVIxK|luZW9$_YHT(_IU)0w z+1j9Lw~k^n>p%#;-nzaF-sSj~n=to{jDWz2_3c>!ksA=zP*0vkh_v6(Zr1v4pbB&G zPo^$x$7Zoa6?MzMzu>T|{iv0WOHH)jLXN5m^kcGV*o_O`4BdB-c9esK0nf7_?QlkA zr8quf;11_nTH^Dj6ym31jar0F@Y}!t)ff@j(7_SG6=YL9cYBlc=N#3=(@Gp5x-aI- zeSR|<0Um`Pdk~|fqMXZU+M+Fql3p8zzchV3CjK}kAWyl9dN8L(SEvh<-m*j5X8qI` zzL?QjGdUptA?F*C8hT7LR0LbpE0$I}b`l+1+2vFpQD5$p90M~sRh_s}cmiBUx9h3U z5&&0-1W)XOf*=U2ePf@04#hpH@bs5=q>XxHNcogTKZZr zrqTB{_!aK1-qn^<>7&UV$+zA*#R8YGk9Oz%Jy#Wdo^Kh>T+*Vk&)*NEEp@WlX`08m zDseQ%)|`BB@rF?dy-oUAaAn_}0V+c>4y@2{aIy~%4Pj$p+1u4|adPGX!I;-BNR#*L zXeK?HkArkpjH~9ly6f=p@UgM6>ubkZbCMQxbo2w`gW{4oioYG0E3(c>!=UX4#&p7? z0>J^x@Z!!qpG!sE{|%zHRQhb#%}c+u|4W{xuK#DG(sEtrWja?0;NhQn29Ff{y7oXvOzB&thp35_9E$GpF^uz5gHmHUueR;wgj;`7-3b0#N?y$27Hqea9!i zGzhIJXp?W_FzyxF+IUwS_>wUs;@;+s~ zD35e{o#b0bzL8-dnMihSj{qIDIxkQON1LZll0w#~?nJ)hYp7eGKp2|StX0#teYxaQ ziaQ1?nzt3rF`-<^-ROgzWr^|Ly!0#86>rf9=hjbW@PHahu29%Hjde=6fw|c!hGiP3 z=+JhEtwkH9=1WRhvGdT`_u7^voV;%AaL>-JJFAS?ykvfUJ2+^3?slE^QLR46qg zO1yCzKR3o$=+C@rdz7PPoGC0}x7U0+UgF|vYGjXPw1-o=|GOkG#8KPMtoYU5`&ioA zE~7am+TZC2$|5?V2y5lwmrEtnh~%jT_CULPX-U3meHDXw^IVOfLySa(O>M8iK`Irb zHrKIx9KTJB%j;h*N}h=gsodVQ6@#1_5dN(A8y$+WZU8tu2v?(1Ni|N zEgRo5=B(w5kgxbrix9&3dD=R;eO#*DL!$&=&j($hEoCOHrCr`P1<;Db+Jxe4S44%W zlUv8q$zn}oAcB|0LuOj5M=>q!WlFl&@SS>&~=>QY3_ zwBqw3b+ykgQp2d^&`od}Go|?E7*ryPoGgKpH^>Z8D>^mA`u)!LBjcV2nREwe_ruBS zz&-ikikL0Z+Vb+sO3qF2fvw9M1622HH6(s( zNPPf&k3jJ1R9$yDoEKx5$?@0$3S8q?$m#0aWh+7o2O;a)k=?Y{qCaan_9zese&(7RS_h7-U_>cQ^_x?{4xI6A7*^lxMIsZG$J4N{3T^DG`@jc#EoS!3ltJ@eFOs_Tc!YqA&EeD4z)%-y)@f%;`8?jhcaj zY1Q$4?a@v1pFVxu{SXsYZ7NI^KvzygKRC!&Dpre)L5Z$A`_`H0)Spn8sNDIcCwE>Q ztU7}_P$d|k#N(GdP^yYsM?spxhp|at^YNUes&Cl%ja&@41Bjyy7?{_9H%v{ukxNcS`uIygT!Eog(;LK9-)J* z)v7ltE{hu8!Bv435C_}=%*ryh@LJmbo?qK&{q4uqi=+?ROG-1YZ_pC1uq9eRQj)2K zw}3a*OI8YWb0ZlU8ykkIij$LrOI*{#7fu?ahNzq@G5ZNB#$gn&iSxc2{kuJ#99?G8 z>L8}ftfUXm676N~@?T3LLL;nB+$rtp=63nz^iAPJ3w#OGwLX^8LzEae!=cvtko#}Di;{Ha$ z&%(30F>ss`;bc9L5*Kz|3@;FPFUW6}OhA~M@YSlseZ2Bp z`1R}u3K-uPL*@F5u2HY@(L+Cs&P=~QHw~tk?Ja*bsck}Uj);u~E%4hD>1(kIHmqiP z+V7he{}SCSYyHhL+iO0utpu8hs>;mWInRUAJZwZnmj9o2Y@cI1|H9FmnJd0f^_FV7 zhs^0kw(V(qEV;?%oJ8(WTbK zK3%;cT5>Ot4EE(Lkm6Hhi`ii)V_Ojj_iTc7nn35hq7uKS#e6#bwOf&N5Aub>KXobL zZ5krVx~dT^;loG0Nf|7Z)35YH&@iMf3M&mG+lmixaIqoazx5>z zaB;(b|As|CVq#!8J3l`M0xto8^NS07T%zopoX`0~hRiT9F!lBI0|R8>vmpvgR95;o zZ%UG{;Vg)f*_b0C5Ty5n{h&?y*&s4-+8umx6@3W{)i2T%@FIqv_0xEv6Wf*(^h zGuIG^61XjwSJhDaF7P*6ba9BGwazo~<>FjjFzf5^B6hN3Q7HZB{JeO9PXNnMo(zXB zxE~xN2cK6EyZDP5H z7pV==+lswDvp*DyQ;6nzyHZUo4#DwelVzWTIT(^=-60c-Mquk%Vn5M{>JX+g7MRnd zCKd&v&x&pYx0<-+Gs3RsMT*PUmyP^1p`=L!iLczWuQd z*KGOK!aa;E6vfhY9WIvV6h=xfI1>xz*5ulmh7ssqZK0$Kz6|>JJ%})DT4_Eu|Ht)X zI+n%{M;ffVbS&_Ysq%z}h(vK7pH_dh1Q)&Wzgzy@xr3CP@yj3Yj@tkaDS+q-LEhSB zgTo9EbSGS_jzkk`8f*>=4fW-*BJdGNDk8TXDn6`%ga(h6kEdFy^mWv+GXBYughr$) zQ1g%~ec1!>7a-3B#4~=39G55(elqsEmh~E0DhBhpLQX7E{@3q5 z?#L5X$fHam@q~%{sZ1jbKW7|vN7%&Dd#9DJ7>9yRl%h|Isu^VJf+-{%>M1=5r}#cl zAMsVg#ErxX)m-YH6!*98yIf$J0ZyW(qp*Czc7M$Ifh%YS?VeHNhRX?v-7J`~pl4oy z+Mp!r3jtSBBDl_4mNh3Tz^~0AMGZ`>hAuW+&bK&7u(DpCHzqzFNq&=zO%_K<2kr0g#pjqS0ydd~ZiFJ@04a@(0#@|}r*Hwvtdnv4!i4m;X!e=?BptT%HJ zMUfn5j8yo`9%R_N!AttFi4 zyp$S|lap11lrT_*6)$wdQgXN}uVUBIb8ed~yAN|dR=i-}t4(5S>ZfT8e?l#rv#nvM zVVoPW#8f52kH0~me#zL1yUsk`TP%^ZkeVr{W{c9WI0<%*!M+; z*NXV8zUJGLS?Bl!pqc;p4A!+b18eiVV;3rbT1~O``pjHCTFbL+j(G{LDPIS@()I6T ztS}lh<%;0k1H1O6TY*>iI4#7VyERSrtvT!GZNcyeifGm(qHXjPB4QLo z1N_FL^nD(BXebpX(s>NW9kCN;y|)uOgB;`2v3g@fl4SsbJS!B-tUgw}$JN7tQvhCq zGMNAj&9^QwMlfzwtVo(IfgTv6bms273_Q& ze5*&_2y*`Z_*{Cnr1}-u5)lBi^LG4m&yUAsyEwM*)gf=X*pyt;e%;pz6v#joRje(5 zqbxPs1dD}Bnp1MpZaSf+Y&IppW>WFC{O$@EM5tqrcppF9l?j`MX`xLcM3El1amL^K zBj26oajj3cp;I;~*w)HVr$CcH3oG9TsS#$U!bCpyg{DgwF`RoUmO#TE(L>WpBAVi#Bix%>7j=ug@A7x5}xHqE8(oUZq6If&@~HJH8mbtY_$9 zGlfQbdu0}9kJ-{Qgcym7GGDgaXk~E&GAnRNlAzU^&U5^dwb$2g0nhC{1Ss-0*7zIA zN4W3D)7UXzQt7^s)`E_M)YVDh2n$P?x%(@}lRP@~HX!hAUP`ee@}DkOL5@i9>05hz zskSV&u+vvc56bqN+I(+kiPc8e7lqEe_l9qRZXQ>GbYCh6~u)^D67#U4`hW2Tu!-K7;xkcClEa}c33VIB_m3MaiYq41dP(NZ?U zF+iXEW2j8aNL^jY)xu+A@p5oluzjRFU92GZdg44IP~r>}fVPLMadwoO5A&sHcJdP- zG{Qku4GIjj@s@9uEJ{TPK5ws#BSfg)1_?H-+}9tyQ8wZ5mK^Bn)zpq~1X&x|o8;Uk zWaDcv>b1M9?IAqx-79j5ti?GEP2I0*(K#QO(bZ74n1hxe*SV%Fo!}_ zE?iW={n)Bz=^{^9)6>H^X7|))NnFB46(gK>-_dku@_fqiSxLjaedhE?W|`i=X>fUZ zetJo6f}uJx4q0$QBQRaI6puK}GnSgsC`RLV=Ka?zHz1X%nWtrK$H69@nY0rpB|U5e zN}G8~FFpv8jhfLcU_x3HCHC;9t|zHQu=T**tXrPIInFO2xsjse{P>j2=uNJYC6QKa zNI)fwZe)x2&h7r$Zu=k(NA0(|`%;0R=Xu?cddn;8SPOKb(~wmFO;xL*hWfEDFw16F zAkLKeSgX5d>N^-9bN(%*^7P$xgU)>V$6JuKTG_|(0@2SpPrG}!Q-7aI1jX=Ug(=2 zQ=w}OUl(sI`m=MhYOgXHALS|Z5X?mqyXHHXhm|^IwsC90sBFisxr`sKzA2 zur+(8?LTNQ^v;p@b@{6V?|F7TQ=a@R=rBod$aXy1SP5D2?a zmAPCkR00wxVR)T@O*^w$v|HQj)(_oA@q)Yimc6%SIy{?K|8045=;{WmCl6nHB8ADI z`L)z}K1h2GY6!X`@O^a-``d(Oe}+_pU1nL7TP`bzjzWB>b|3zyniS?z3zI(bO=s$i z@O->t!_6xaB8V~QFFvPjXO=EL&=zl(*rO$&I=YyKg_~M)hAXv9@BrogbHv$XxPMt&g<6){W(E(# zsS2M=lxYDc?>e(|QT>>2P?1fXyR_2Q!LOstz=?I}qZY;xFZ~A}Rnp(9Tvz>FI^uw; zZNPYMPQqbuM@xTAI)Ol=Z)l1nTOa=TJzw|J-*y#stHY4Ua*@@o#=n2_e}8pBJ@avC z$yxR0Ww!fOL)321=GriI^pZYV9b-FF_;Hn7gLFlyehnufZk6^F*0Xhyy|G1F>H)BG zvh2%0!?MniB`ZgK;O=t0tSpQ}^M5SyoUBQ?j)=_mW0+hzSF~iRDzh#W;m<18pA-gv zifMRZWRod19TrE$&Z%Ue@}qM{t?(Wkpf^M)bw)jCYhK@Vx;F4Ktgn{Dn zH6zqh5GaN=Ovi{b4=XJB!zpbe#CZf{_uc6bKru5KwnU)FP0bt@b&8JKFigq*<~@sFBhzpd&u(zPub0R3yZ7s^xW;M;5?s2g{zE!FaZw)a&M3o1 z+ww`EL{ea_$ zjfW0{EXXQ6GxGDwPVf8G^BPiv(cj9t!VIEuH_>vE^sWL|?lImdVgOI_pReTSETz-W@PPE7sS+vDL8Aos~uN#=R5x777GyXlr1_l}!M z&g&wGPU7n-r;G5QSQjF=3O05>)^Do5Z9B{);ZFniXXes`X8!%@9chg&t1fUaX)|zZ zEqXUGpykW>a4=Yp_P5--3ye+5+~!ENtYhPXZoUkY)eZ;a1iB(yU0q})&whTn^-7bo zBk6bahANq1Mvq+NNz}$PfliM};kT7uKA!25EO$}!NKamTvz!~x){(CziYn}5i^aYW!1Gp6F0%8nfzor3MXv&OT;o9v> zrW%=-ijNy-yK#K6ZE$9#Bk%8pPgD3_9Aj5(9#6{#L40?unEH*T^48;g)yXnL>d4KD zIX^DsYESW(Bd)o;Nc9$}=1{tj3&?6}d0cnaB17yfCx6c^ho4$q>1n?7jrte7iW{OM z%*lUOP>iJeH-gh3qH*au^MUUwhpgvoq`|K4&~)%>{bkpi@@5;udz`~};Q_W_r>pYH z@MZlbFWQ`-ae+1#%Ffi`G~Zaa`&w(zxl39>CTJwrFj6rdy}k7hr{VbKgs029 zvw2cGe16C3==s4Ql^>@B#C7ZurGSjhd+Ce7O(8q;w6{oO#!)wEsRR~1hXDJqqxQln zsTLV`3k0;MN;G-Ky72s6rr>}^x=3nbgPR%v6$eLh%C>qN#V7+43|w*xpaRe^WAU1px2 zPq>4^KuP+F{k1lF7rDpXXEUa8*YA32LA zP9Ft!eqXR6tbK~zs;scueRwn_OmG9eyXU&udd9JmW-krB)sFuKjcU;Z5by8Kk`VM? zZGA0nBhWpbo101%L6Fnd5{jSQcAmralDJG02i%)$D}*>q<>BicD?x4wa|pQsZ4ui? zBRk0zw-)tIOFue7VjTvXWC?{}D4;wZ?{XX3(7kOUQdfnBXK+*NC+xO|!>W8_Xh*OZ zRc`3;u~t0Xw`~5k9JpJ3*$o~fFL4thFzZ&QxW)4QcyRQV(d`eyc1p@2%2Pn6)Aso2 zQYO(Tk1to<*VR*`t@xcjI$)x#!_2VfLfLF$W2Nwt_GcH}<6*ddEUpNX2u^0pWx;Rn z{U)t|ZwtRHll9l#sNzLw{TkDX*wv3>-=$m^Sy~&hp0T9-sq$nEs63uF*I9|IoOySP z&S0UI)6}M^>?dD=?L8%U00aE>dR9_RwRWrQ*#cJ~{Lq>g5}~%&`*#hU7-4md%$B1% zQ??eoyjhM$$DeKnPqB+^u?B+=`n~RhQ0>Jed~+gi6MDuF1ceYs&Q-eJx7MDXZLm}^ zAN7e9;(qd}Hdjz?Q=}y4FLh6{P=M>=n~@*F+qR|FK3y{$XQGO>o}qiIC>!4P7tdB zD!y){IqicDr-oe4lk=X zF^1fJzjkqTx5z;4v4}1(J^zSalAH$hG(M-y*MXpegv%+{e|ARs@Pj{HNtw%|due0f zT{wO0-F_F#f^D|_d~feBclsVZb%Jxj<+DaXUV}Rs2aG>u?XmUDUA{a_NIG$tvDWF= zz>GDG-UXK{#(H33>vEOXv;YD6mYIld1|!dwd%yMcoH_i-nrc(we$_HzW8>}dyL+T- zA^gEcPGF3gCf;wpJh;uWR&Rav!ghp!=rVnp!?ElpSqnfITd4nZj{Ek}q<_Kg|7dUH zWjB7xpq+-T964^>zvctqLcrc;@y()^ugqtXswSjxKenqPo)Hn&WS~sJm$i_)+gnoY zrD!+uOobM@{p|7>kC4ar{x8n4kh=PkQn67HN%2H#H1pm?!=c?WviHJY{I5pb<95l3 zIqN9Qd5t{QA22kvms2H>>Gn~$NU=|@wlcQUUS0GwRK52> zYMi;{9$&K%f0&bkU?br#ZZmIvbgG?aunlWkjvAXKL_I}7N#qi)MZG7+=F@mMxVR_B z**un(P94F+NlhtRk59}$n7RD=-WMV#hd26F@Nmf^9j2>a#SQ9zN}_aeP%J<4J~dtW z*r5~gWhn9v7_(&>EBNreZBAq5)GM4`ETd3B=}}GFadnygaQ@ARsscLJ&M9N z+%9z=Vf_sG(HsE_+k0$-$o_S98+GDRjOMGLe!b{pZSGg@Bdsw#ptt;~Rpe)eOmR1J z#p{g2oD@1*)cUKs*VfWnD``75wUdI@TQ~bDkow7kS?_dQ#{BE1dfC_9_1*p-HNCr> z&OLN`(X*WT<(b;kmcr8>a)gq+(*bX=Hpny z{|eqCE$u7h`Z{B^PhOMGhflGp`f{|ddBpeQw* zB}cp>Sg;WU<=Yn)h_G2wj)efH_Bjy&twDsf0rJS4yd!~RHi6~rw8fF#DY*P8$5S;s z3z)c*@#3(#wEKv4K)M3UpO{YBG^)4<#N-^=5uu*efHBNR=A;PFZ}z0C!5Eg8yYqUf z+rG=_{(6sv-l^OJ+`b78zJsGS@*%kiG?{RXF6S|=mtSD$L=pPSJShLC>o1Gt3mRGO z)o4wQBQvwFH+c?&p?8o&OR&D8WWxH>COs^vbGkOwT^D0uPcV<6A{L5Yk*XtDLLUsw z5Cc`c3(Khw*btokQk1Llg#o0b@%+L>D3Cb8M8v8_r?4UYWw3+((li=n2gjqqkwPP? z9L)JRxTG^5P|3jWQzE-%{?3lcWaK|Zac!bEVnbgJSYL9p1O9u264d*yNSz{`q8x#h zG}EQL5LK&+o07@OVM&HZ)?vIIT`XiL=@?LoyLluQMdnPFu3V@TF9lo%MsvKTGCO}| z!13KcMzxOU!Itx;2@+) z(f}P`E_~y&9oCYg!ppdE!3twP17FD&Yt`JP;mXxN^n;74nx-@BOOdg3TiGN-XySS> z^#7J=n>~3?V)l$O?-OpxKLF?+0PI6!w?=1Pi58Mh-I5e~q0e_kSn3VX3mDm=uZ6N33=qCrR5l7SF7tx)2>vc{N;b{+o}AuTbprK3B;HR-zWf&N4G#+L6|Ffvnuhd z5a=p-?=!XtZF!ISw%ed+WaaOf8TZVFJc#jQ*BE(MMgKv^-Y5ic!%=h?6)lglfT1jn zYtn6H1+jo(o1BRY!m2|Hh+8O00T=!{cpKOVbj|9|pmS^1=z7xhl@efv<-E_s;Av5WATH8BKAKv=FUwPkUnWnl0fl#9l=s>1~?}Kr_ zYsd&6%A&kflS53)o;L8^{{1n0gSBz}=|CChzEZ@EE=Z4{7%)D;Y_umrTASr>_EM&0 zn^T65N9eswfv#yf#-KFt_!g{<2?zc7N7CgL3GNSlbgQadQOo>n&aT?bnnc0$EtS~- z`VV+^XorDQ9^CQU*=R;e;D%Bj!jhIy?{ ztOu*@Sag?D;C^@&I*@F?#bo;5D*^soxWRmJ_C4mBVcONK_+CJFxr`f=wuM}h!9JYM ze-12#DV$UTJt{=@6~W1tW2EJNb!V=LVaXi>(8TDaNTR}NNs)ph%z#K`xrf!6mxa)# zP_I_0wPww=hcW`ss?*>x`<1zuh2S@A>tX3c()4kZ;GW?FR=e)O7?i8}FR1Vz5ft6Q z>W}_vH~vx>EPMvPYXr1MH#;G=febAi>^v1XG@&iDLe|SLM*`QXXUAY_$>rnwTcNKjrr#XTYhc z33hllf28Ck3BF3aL6B|y57jZ^uH8(SBW$Bfxn1AVA+o3yj50k`c}N!686~R1#j{IN zQ>b=EiLyr;WdbBog75XMn}wmY*>Lk!(ZqH);XGWp7iF_F^wH>y2cpVshN!Xf+>93k z7gkM+1cQ>_m}j^YQB|WA`-*ej7Yg`^%0mC<&kK*MT2_nV#{EH@Q&hulQZ%xkuy_!n z5z{D_wJXnm9o{`YJu^c!eJ>qAyd>SVN_zCXQgeMZZNX4vCY9ji?I3in68MK?Bmxr2V z&WUVjtBGC^I<+D z9Ft<+lhH0skuOBK^$#%muO!HrIHN>_420LJgDh?dlGGB32%d2J+J7mewH7icMDXlr z%k!`wDS<=YcL8SBFuG_qE56mu?3t|#vI8aP5~L^mti1-_v$f=QfXa(q7;Nrp+K5(V zQzR7v&7e>%80IfR)Gg70WVCg@aIW59V;)o`N{ATt@vL9_rMXf2SQ$u``5k}7)!T`0 zGCl{KkzY!F?V^%Qo+T`>NAM{}&@5xByo(V*M$|6R&Evt+DeB}(5>GzHPjoEtEK9J` z1*c<4dP6&W#G7gVlc9eiJM=(ht3hXjh{%{7m>@PLeV z>I+4Xr}JF|fUgX%Fk9j7%NqN**S7BtgdhG*t9H2s zD0OvqqNAw8*n(T-EIbj{5u|D1q4RUc)DYF0V7u@_w{s&(jv(1yS%*7A6fVwvq3RNV z{)3HU`Bv2!U_d39^m^us@RsJWOM0_liKDSj97?5$W zvSwKvOUqc6V8{aYVW&@=SV(60w=6j>dK4F2dmq)-WgyYOxf{>nJD!pbx+~2fQ~^sJ zECJ%?H&rv3Z);5Xx#3b|j$!OA4U4}VKHv~A0N%@nqgKmsq}@omdxC9WerL980dUsMls&r_qt?3ot15s01`sJY}wEF`#M>Z zj*W%y%~F3;*ID`Wvgv0a4V1e!!ClQSDb;sjGT(^vWR9Pd5$`F?7$_f#g<^J(p{}{$ zI$jpc3#-WR-7WVWSkobGPk?b}X5Y*7cJ+sY#3ZnO*5W@!<7Y4<8Vm@EIA-Wv z!Y*30b(!xRv&7cU0B(i}{X4GUZCk{NowB^HD>o~nOY}LK$#y3W;hXa;AQIh-G;>UPVW4A zxaA4fu5p}}Q$-tbe)C!QUJlM67FXtK z`B0y}z&!lam5{Eg_a&{Ahs9JdC{v+LVZI5uRG_IjrcXH$Y0^ba&g7Q zj8qR|QrGE00{z#u17V*d`K-f-+ad>rGC`NBRXatoCbZ-%QQ{nFKH53^s-`vH?Z@v~ zdmMCJpe|_zJ`I~hLc&=yB~+k^F)EZ=h?3@88aNM=+n=EzzQ4wERHX+faxkEhzrD z5|p}&frpOM6cXnSr~vjo)OKFjdpyZZD3XC2Tyox_t!4ItRs;Mst!U@*LGt^4l7XBw zspLgeW5B?YIoeLjK=tr_iu_&TY?I#;Ji9&=igka4M?e|2VpBrI`Rs78e)XYxq~n0; z25uS=?)y?aH)1nT9Ca~xv)aMh$hZ<2f;10c!&)0uGdSh#jg zKIYBXs3|Y>_CGBvLt{+9xm|Zyqq^CsBCLj7c^c7ag|Osmi$sog8JC0gvpI&JktTS; zg52M4&eVcU+eAg%aAg;o*VMR~zEIRmuV3xHr14cv1uBu9!^-JZR~+9JC}x zr{USqE&&*Hj5c2`;&Ky&e5xvu)|c!FYxPRg(x*w^q zAgvAsv5$Rxi*`xH0KvgZ&=|{UzQRv;lDkZ>o_v6EmTS| z;AmGwJ+scG$#0Z`+aW{KosDX@|GnuIynF`BMNrl!wqh`@JH(BUhp%T0Z2b#}3tHqM zOW_g`Rpoa$<^(47Go7b(K%rT8M!f8M;v)Dtja1F@>6RHNa?H(C>+e+rT~KjaU@A1} zhwmzvFKjC~fSi;d@J?HThxCu4p$WF-vG>$PDSH%+)V17YWzSAH48|QyP$e7$e_RLu z_$1pI#b8GPm0W#c+?0Xzr3yMaIQeHsRQFv9*Ub#D+}TgpK^aGkF_aV1?34IvQnl^* z00zKw;*THw>HoQ<&6^z}$B`Lk(-$qYJQs?)GB?Cyo{SF;B`25YNjZ@>T{+OKZMicW z>%^ohz=C=kC%EO>KEYo3;v56GRxgY=juDGC;MkXwBov03k2+?{5)ksUBFg{9WiI-b zXVyYQY;t9;cowu1ZSH=xsyn<+wdNg3fbcCYX4vf$Ol=|l1*!LCS?$T3qo)pTr(vY1 zm|LQ%4?suZZ+Y~Kk30j-Ho~-u>mW9Nq0mD)xWAAO$=?+WN*y%|CGmSVREa?LbwVJf zS!_BZFShD7B?JSSncGaP;)fSSq%N?~?L_fW7Xz?hXG?$MFB4o+i4;;84=MvPZ31@# zYv0ab`Z}>Tt2K0Mag}tcdF2pA5N&B%RFdLrOO}*+yQLf!BW4-2Rqwo1t4c1Df|KI_ z=;hV86#&J}Q=>$y$=@3u2?JpDS^4r3L)9mW+an7z0wKX@Z>&Qvftl^Oz%4Y6%qvhk zlIv1_QS=d|UP$g<1QS#%_&zlAN5Y(nPPYX_Xd0H1@+0eR$bSd}lcWY*P+fb`0U5oN z)Qo#NyLwco`cmGe!f+0xikt$`>9~TOdt%-nvMcN4Ib-Ed*wb`hV# zbr2IC{b!)nprz^k)3K_!G!>E&Q6A)iE?Zy}?JDad6k|J6s>{t##bkGTjhi(gSpU^o3Ww&J{CsytWHohW zAYBU;HS?@AcSo4K#eJRAW?>U#V~9>i6`Z&g{$VtR(n_;uW9N_IIaJ>`2*PD-&tNE+L9Q8`+Tr1L|)l zJdzbCGoy!mhkYGL5Rq+o4sLT+uVSSjg34Zhk%*DzyC0C za8Az70QmThbf-&QUQfGwdn6$sl)1mZAQ91aYwPpcnie${0pkCt*MnX-*&%_XF!z;w zHZj=eL6$IxD}UC@-c(|c?%Anp?dz!u<61>Vsqyg4$gvO8Cdjq-b{*T|Gg?}nF4kKr zD=LUnWw~dj(TdVs$oE^8*q?;Ce&Wkp%bXQTl!F3{c6LznJD|URKY9LN!TiK8j9{(u zWNIkKV&QV)MTF5`0UW*1?2!6WBeQqlf?$@Ch(&~|bf&@5vKG*=AzCD4$s_28E5eih zst`#^A#hM7I8u>`3dym7n^c0uib>+3IHj-gKOVl{jhnI3FiJA=^Aql4g;S3pID$*$ z{w6*Znt#J9_~Kob82)6DWGzz$;R&_1wM|V;jf@h5f{cBAy9J5;|4IuNBouQoHY0Vb zEL40pQ&yae(cSRAkB!%MH%=@a8Nz=ZSxn)o>jg%w2ACd!ufYanyAHg2TC{r2i+@F# zY7o+@q1|FsozPjs@P3|F)^^{|$v7eDx8?R0gDd;n`VU&~-UpZ%x8ovd zwZ%@y%!9dy-&6hfyz-{B{0hr!^6XrtVI`8xx*d8w$hLgDEa#g$Ygygu0Jq(lEb}w|b-GQeadec1hp^v1}o%F~I5E7Cen-4>4 z-C%1z*pgh2yPT{$X{qTT*A<3LW<$fddiTu`UNYJ4VvD}VOSHKwRZ#nyFoz@x4xx4$ zqxXT>{>zv(Q&-~}Z$*tbjJW_|Dc9P2mm5FN?@6kzFa*BHMv9}l{!qWJwpcjX4kJpY z^Vd&pbNcM*T0|F*Hu

      qwc>g-=;K~ z1XuMuKJ=NY+tD)SUsPiGXXuKvA+vBgYC}xYZih^&Y$UsUt==XM^7Py{hO<_PR%v1Z zkJWh{tGi~UX5UIGuqPA(^SQZZ@ezNKb>7|%*LGQA=nWgFZX>emd}plfeqEc3!pVps zJ+8=pg}i#0_IpRdb-=o0b73l&2lK2Ksl9riU$5=FJKe_0d5EAnpbjSyE=izc&+nHE zU_-D8Py&y5$0psE^BL@>()arMFmCB{3Y`YW6=qk&a$6etIIp%KgiI_*LZGJPrp-W@ zlf#X{{j^lYjY$+N!Og;f3KlZ|uH}%BP_C>f4h{S?@LiRq985{g#KOjYK2|!NnL$a$ zRxDRVt81(Wj(^E#tWOrS4ljaov_L?%rY09m%oN4CiHV7k5o#j)yrCg+NwCnQ-rjw9 zm6%R@vlw~&JVhVQ1WcV(47u~DSlgamQwEgGevE*bKb5gIi}#&PAZ~XKtO(Fm$4px?PQf&} zwO+Yis_6cB3VV!?h`$fuIGIiY^U-b#`nfK zPMg=M)O8&nJLkE%8UG5!!~E1$L^w7?d5(^m^}Wg_A)MWJIFCPj2uGt1&F2wtJYyy6 z8OC8SPA%uTlR(otG+xRVcx{F}?H4a!x1p zyn#I?IHOK$2pvP0yIX$zR?D%eHEa>P_-^@N9cyaco`{!`MqSS;eyfqG#P6lYX`)Yh ze8^IKg1m^0ZFK#%fh)FL7U$F%4Z5eNtH4~c_!V~gPN4u7gM;7K*>Zlz*i3I!jzLEi z8+#K*NKEEOi^g@=xOnXG$z@iYR`#9bX$e6OycLJSK&ScpQm70+&P#t!KQa5k)5YXd z54Zh#jmt0@9^G50ONz35BNVpvMf%538Xh3~$)3za#Qiet1;@Wc8=dITW#ZU~KTQ{4 zWb8iJ$5lu~KCh_qo}r6nhuU)5{vG<&FkF>3e-A+3s>9DeO(G{Esn#WRnWn>}i)fc3 z$m)m+4EzQOf|&=#15=pDUGw4db;^3kLir88p>w+IyA!>BXlS*csh@axN<5Jfq24Dn zW@)uku6qZ1lBDdsRf+p1&WylFF#++vA+ypbng&ZUC|cxWJ1VLlQ^__ZVxts#H4f!M z%*gN&5)*e5X$^pg6>&(Htx z@DLxST#k>AAFRXEo?+-FQ)(0OF+4Yt1W>WIvKkv72TCiJ495|P48?~}ie)7xqDdN7 z?OLh2H61?Z1V#2hyWmHc zn8&p5xtSXG)Au-Rk5Ui~?w$Lw<-WHF__`To^co(pOBd<4(AsY{x(f8``g}dJm(BQi z5735U$Uuc&SO2>EBHjk*dEB{F#~&9+5dU@Vo&g7=Oh$^x+U=uvoA$&}_S}on(EC-r zN2p4iNKFyUdeRsD0L}AsvDR|Zw5;cK5YnT-=fzVK{c+y2X5@>j8WY#w33{2~`Or$Q zTm{bPdERQ^Veam*KN!U-mj`~XKKx}^Tes}1$D}4|Bkr?mOGzWr@(dI&Mri;-JRJtV zclJ-ciFpq^w*E4;DX- zEi5LkF7`l56c%Rk4)d<}{DZ*}c6EW`R>rVb%{dFFOOOq6M1IegS+%|2*qvryo!nNsgqwtQG40JgFAFh40n@(svl6vk z_tP}iQ`sGw1ICnk@2~ySpZ7;S9}i!88Qrc!gA;m&70V?M5{L9#jkZsvY*m+!%pF$t z9%r`xU{FK(%lf{))efT08P0;eUs!`KzB`6#yCxq`@?M(^RYBdw$;f}kcw6i`9NvbY z`r(fNbCH#d&yAm%Zp4c%+rCFk+CGJMUi)LQujFw_ei_DgzMh}&FU-C^%sxA}<7&FR z_ZIDDHjl1GV{T zKzvDb^rV0P{*{zaq8Oy6rh<~v8n>ARns(d0o@(-H^_7%REf_|ErjJB?IUcGBcV6wq;}!ohh$eroj50SA z3c1|Wqkoh+yUMQkFw!sX_6i%%eeB3D4;F3p-TWl90fyvtM??{G@3^RIj$CGuY8;Wb zS;0IjMT6qyl1a^Q=H`QH`BZmG@Xm}vV9R!T>SI03XH|;PYbyJvD_=s0Jc_7XQC8by zyV^LG58u(|SB|+$PkFAsfL%|~^(oCR!>#&MNr0_8ZU zkC_yhS50gVut8B;Q>o+srSA997~~))^Gw{Vb=P@`+iC6k;V zzNx8$)fE`S*&no31Bs%S(>DE2>(h-vYxQcarps|RfepWY3Yx;(Ew$>j!>p|f+ru&# zB{iX{<*8Nq3|UnD`A_DtqxO>+{2Cj@6c3PhT~X&r`wj9SK%&&932Bs(WVxJrVPk>0 ze^bBb`SKphTBBC4;r6VY?Z?^qLwRYJlK)&)mb`VzFY+gtJV!*}A69|)xgiZ#4~=@S z?~A_^uSQ}!+s{C%?oTUMm+byFGN;(|;@fy643pq2JbXnC;wp8~%9fAp%bEX#&X9b~rmmp_2Ji{4tUnW5pqj&EsqVKMRa zO{Fm*6c+=R8&eD|V*$lWbLEzm!Oh0g7yDb4gc(Z*6vpz7-vk$?PT11$zyn1Kll|M9 z>$JC7oKEoxU1fB=R?xH6X{A$h?xU>53Fh((zMki)r;SvUYBlz;SxWnbpLJWrQ(-~# zY5ni0l&`BnOQ%$N%{te`0vRG6_txv*qcYB#tKDov5}XtZv4Un)gcie?*g*RI?t=@@D2@XTAvjg1(Hl7|8yL>|98+qVA7(2>6^B>j@TtSTP&x4+KXRfTh_zFw03>x zv7DscBj!-&xhLq5!*!TBK$(=tOxS9*s^5w73)H*@MWx(i$g-mnbws_0vFSOW#ypX3 zFirAd&i^P1xbu~3oLq!g7k}!&C?NgegI+t5e3}5i-x`v@_{f>|?wEd>&@0GCodnma z(?|$SW#TbTrXLripT(=%#AhzF`%8iU!l`pt`MQHEAgftF9B#x&(Dlza;#%hz>jab2y*QR(;4IWz zWoSZ7kV(1NQ_RD8ZT160ytBseQPch1frxU#FY*$0a_0$BKV86{F{37eY3iu>#aWuM zH4u9)H*=vOYTB!WpW5cs#!{BfHtZ$4VD7C?EUaq^hm-?GQV&?UL}9K_i;ucG2wnN1 z@ccbYVlgoUd;FQB#-S{oEV5FE_?$)>22_~N-S5v8=JH1@_8IC|wfaJp74x#hZ8C*= zq=zaZyA-#!VV}R<_Zi!Xq`%x2mOenBy@|I&PMEA!>~6?+)}Lq*mZ}8nKzq?z^~Y8< zwVs)k_&kKRc#-6xv5`f}{6d9{9H;$RiH)(wjH{s+y8q>$m6MIU!=6R99mx+$GFBlVaClGnw*-T~P;dG}rvozWQ$O z6N#i~iNAhb%V~K2zVFd?YfySIzlijHLMkijhoFPhsSh#(mj^>htFEB`u2HJa=F=go zv_r~vd*jYa4C4vG1R3i%}WVxNB*Mwx|K83N)J>HZ%~P_5kswW;w2!byT?yt}BL~zDuYXcM#g@6()841o=s`{h-9LIM`j0(FT4t)9*q2JSXXQa1p&24NJzjw1B#1HU0hri7Z+DOC}KY~$EUESmKdAwYQyM(DEY(O+}x~eY#$%s zf&~t3I`v7wh)s}7IGksMn)+Vg#}!d+*W)Ru1NJ(YNyZ3VRBprq(z{~~E|RFo$b390 zXkX95*ZQ(v%^!S6n$rJG(Nrz;bK!HQ-({2N>t@%Q2_KQbOARPl65mWNs=LCnH@K|l zaj=-C|9Kj}c~SHzl%8ok$f1c-+v?w&I-#@7S1XL?byAF3S_1_L51E)EoK{{&ExAlFBJH=c+m*WaC(l^)=^)EsBF6Ge0{WLf^b?Qs*^>N{=VqrcK^|L37HnF zr$6jWDNVnmP(jz_d868{O^4BQ|F_+6V49xiOHw&oT=2s(8}#e|26k<0 zK1)CGGK%NpbA}fIL+Kq9J8XF22d_HWwsR!o5^= zvOmq=>G{NXIu1!+jCXq|H|CcnN2w4Xx=jWd$-daU0^_$Te2Xg%A4k+eL`2{mPO6Ff zA5gxL+BM0@SKx`}pz`67ZCVzeJe)nz<-KRTb60%Hz5nTps{mMP7qvJR3SheCheE`3_^APWCpQ zUa#^pZyhlfeQe?mN=9bkURPs}gHHOwC!GQZcMUBWG4z853TCH^WDTD$yp68E{cJO) z40{}U-~_qhSU_8=tAX3^-(`PY-V)lro^}`1=BwtsAmczo=6n4S`L*Bc+V=hTfc)>>NDz^a zi(#4<(kYQ|7m-nVgSh7tw@(gpE|F=KGYYh1bOsDoz($raoBsCcua~j6`EBi*uDi;R zM?;I4vn&h^o*puRnd|3hzwZ0Bb$bTxde2!aC$Fbg{$ewKrikUuCg)Rlrq1Wt>^5us z3)k*Hw*|w6q|M5cwigOQ5_{De`oiDuq7L$YnYrF5{{gwsMDtTi*5ugyr3j+s*eirI z1A5lWF`30XAJ?oqbe-6=pfNiuLe~MQou6=vPd!_%k8>hGorq99&9jdzz~hAP+2jv> z-@O!{OT7#RW%6PJ=0w!fS>T?mx!N^aq5a*FIf(Uk?@l4Rj2Lv#%i85 zk2?zt7ch1C702$=@ip)348@B&>E^GU@|Tz4?zn z8;ncWcWm9rWg6CN@QLu1S)OGfB}91bxY!70Xu@uL`h@k}^{iJe4W+nx3KbuzNB%R5 ze+`(^^YCBU@2mf_+=}+c_ONNuK~pm`PS+UtM)WjD)l@;^{J9X_=V06TU-5j9oS-!_ zGtVq8h8(9c>PCi#k4#V7+t`>itj5!e249mVgijx-lpA)#|K6Y^aGs@NaOR){eL#i> z^5Dy%9+=mR%{U*|PJy==fuzo_xw9jmiuFv3?NSj92+$bG*YS9Mre$tnA^DyN1rzgO zB67Tc+`eG9zOfPX#EUR9GZW56H2}EFCW3Y-H}~^+mh8C*zZa?x6d>8>YG=oY`Ax?F z03HuJL*tE3y=m`{#KQHWForz*drrv5Gzrj-`=1T_pZ$=6*F^-G8D2(#3L*mhppLgd z`tEZ9=MJd%YR_)cGn^YM6NKY6NAK_YDFn@j$+<#x_|JT|v z@sW-M)O0`;AW$-iudnap<0B_0fPjFYR?nr&@gTCWFbD$M$T?~tmor>Y=n~oM@8zG_ ze1fq!q#vOyy^4ZsDWOwTO9@SmW};j!N*kn52bnEuRHsNDxRTr_D#K3A5Dx9jZt`tR zQeaH-$gq&O3rZM_NI9s-5R6_}0^Si&Fabqe zmL$1g1keD)k7vbXg?v`20~v7so6t4E6!`i1Np#51=;U;VI=HyB1fsL~1CAkzFya%4 zd%=k>1V_IsyUkbysd9h21rt!FCMg%e6>LN1LExFMaaK0Lji-SjpNnFBWjcr^O~jR@ zr$Dqt4kKbe|Lc|8JKN&hUe14t8jD{wepZhFeR1|Hj_Glx*iey z-#tbE1%%^Z0KT#ApFBAzMOL7ghU8{<&w+Na(St{kqFuZ+ zaeUP1V@0eHst9o4?}7p|R)I^}`4;5=-~*u}3Q+e{@KnKm3L}Xu45K!LpaCUW$Vp*x zWrvJdJ-{O*#q%q12I)in7sm`AZZg18lbCjI6|wTWetPpGk3r%z1(>12!{F?XTpc?6 z>LekF`v(J!Ba9TcOk%ct`$Av?8%2R*A_Y_P3(PT$$-uE~lNSu0lytHmD||H(EEWHr z)!v_BpQX49flDR--$=2}j1WTXuO+51_F`c(rl{%D)Z10kX3-g@9eDD0AsPklzoQT)g};edgB`_)GbUfAQiUX?G;UF_jaN z>Gq$(iFyAQBNy~ydTkR4pI+7qGJuMM+GS2>{s_Tgza{_?9{Fvp_^?ijbLm;f?(c1Y zBYSRF^{;}Ex|C0fr}f1NMiv%o9MCfcoKb%SAWRQb1nucPng%gy_>8HG1%cFG0Q?IY zsy?YWC0d}o@KZ!UoMInfYz16>whNEM?G9ec69gn|2TGI2!+6w#k+d{X{#ZYMDej29 z5-_wdGCJB%oEu1K!W{6>=`t~K-x}GN8<`NbehO(Ab!60^z`9$>_am3BNgo8%K|w%) zbs*D!3@3YpAsTDL5NgvOJ|e>5Ik8nEzfY$DM9$`az1*ZtU-?=dR-kjXi;Ex0P1L+W z7a!fT52UZG;b!Emws@`9GwFXhF9PA$N``7kkkPH{&l+kjJnSlT6)lC*;_1{PaAZlc zX#TN;VK;FB0Sflpo$gl&Dp+Q(sjprNIsDeYd+C}gE8`HiWBq4ma{*^1PKs~IHB%nX z!ZFilrxz>Um-42%-!0Z^+J{V-_BQdF3AihZjcqI}%KR?xd&#J>?GI9Zu!(k-R1Dj_ z`Q5Ei-7V!kb>(df`|JpV3H*P2y>oaaU)L?#aniAqj%{~rc5G+I?AW$#+vwP~opfy5 zc5?Rnd%ySl&OP_u^VhED*}H02)vB6n&auWEqyMZW`O`TfmKx^bo*WqVxSP4joVKTsdz*@BGL>-R(2g5&dfibK57zw3ottp8ARn7jUg$t(}BwBwJ_ zkdNDGIBJfdo8zi$cb)je5aJYvhI+Piw$T06EYKs5#7nHhU7pr^jQJSGD*T!avfeV41di~mS`q~7<(k=_P2NqmfZU@KY-UNXO=dZ;hdsu6& z3_Ops7Q?89^y#>=!~jc#f=W^HZE*;mFye!zlFJ=LgjUtjHje>Xlax?hmFE$qBOlY2 zz?6L_JGbve$`kQ-%EG&^W+hpsa#l^_``2WOL^(7DPmG%OQU#WnUv@Ea?oO!Xob1c% zmUEf)E~4S||QdOWvsVrJ1_ z@>>+y;OH#I_a5$MUY*G*ubu|SH{zF^C3xo+0 zg6zbz5U3u=A!Mfu;yC8`fR&qdf+L?+^Mm}X3^fY^b{H?hQ>vJGKC=UBulkVT^JM!( zQMHt;?qhE%qP#MmS*sh9H5z2L*}NTkwGTYHCs9=wCsS}M-Ol|zCn=c?Fp|FA$){>v zFN2IS4{t3&mB71VwGzuU=XKIYJE2-EQlw*5Y+dplCXvkIzwIs``PQ4AE-R`>`whfHGMDLhk%>PEjYxg_2@ML~np;pl1^lm?NGP1S-7)5qjnZ(e zIWP8e6z7!{?v7XezO>CT7c<8_GmkyZmd+SDyFJg^oVZnOc#M5`d1ENzLNyeV0Yh{V z?I!LfV|*!^5?0-Ty=Q8YKVbj*BYa(XzFpt0(?e>}V_v_uGB;I>&E1zq9RwBHhXoGr z_yYBMsUg8TWrCW|yFW|1e01DZ6`#@D@iI2Pw-95sRD#TDc|}$ySkeW-S6?JZ zwH0_hW^#Iru;$A$ji7}Z!*p>s#1PcElv7=pzNvTC&;F&Rt3!#u0NNk8DQ2sa?@5u; z#)*IRop|u>mrm)p%XNI&}HKT5V1fXy~K+dJxsl;3iV+97$c3?;MuP*-iTQaIZ2M z`2-o^t#-HXA7NNvSF^cH3DE@U2nI{iQ)&p6ie!we0VaRaF)#!0;8EI*bv93dWAl(>+d=uRxXr ze>-o7-~Obtu1}yiH(*SW>dn0METpV@g=88^SUs~B{=(xY-j_i6I_NK}AZIgvVRonF zp@v^WjpB3qeaWR^LI${oN1d;=({D&+oL5X-rFCmFaAKaqtc9iD!CS$?jr_}plmcF&HS*^~m zufx^r*`A!9+S}R+NNMwrdI7vXB7K^N$dUwm1+4R6F9e20)C2xLPNjp}pze{p9v(eB z(4Xeacb}Vnr7o@T^c*#)p{;ki%&oqdXvnZmRBzym&C4Vyl}8jk+g}>?tU-ixz`ir%kiYn7gA2a zOv1uc*(AoW74a{V3aOv;L(BGH!0;TDz+eL$ zKCM#>@76f-iK=4z_nK3TjMkmuCo0fgV4kJ*s|DsKD$6^q4&7It`=~zZkKml(BOiG1 zl^ySl>?gme&8R2+$o0`&S{9$~8|oS4r!I4UE~Z7HuUAt?aa-9OiX9kRoaHU*tWSAR z*2Q_Fi6hI`A%E!+zAhhyVd_d&oL}!H6i#qF*u1stcBUgGvf006_^(P5r~v&lTgJ}G z<;go^*W6O%Y7dldghDV~o)kGe2oy$+5;=?%OsEz}sqqbv9!bh&H|+fa0g)p@3l$}1 z)9pFDUKaNdZ}Gfe7IMr<6!6Wik?qWr^2H}a{0(}X)J@6LE!A_8V%rj1rOZQ!F339| z&TmIpp-hdvF9nqfhSH@@x&uoH>Kc}Zgn}gQ&xao|eI!4fPLX56up2P|iu^2mdmPj^ z5B%o`t`TWcFvC)#_1kCpC5N+fL-#;0PY9gO!-(D^2O_w6AvpA%2!SC%Arwkv_k}t* zJaGFBxgJb$h+U#tUup1Y#rtr^Qc8koNLS%JHzS#yp5DA5@L8$0KtLBX0t`Vk`k#6c z+W0UL`#h{sNym0vG<Xiix)d8D#R4izgNR)NsiNi<9@?DLY{_}_`MA- zI^?!cQHU89963}FiHZ0gMW0@-XV>4Jcmb2ly#;`<|4kFxUmR+Hne3Q7T4cmTN+T=4 zlZ}!+TX`h@_LUTrK2ePrxK?2xNVNi>gv3(Dhz|-NO7j2X-$sH5fh_>if=mAgiIOT$ zoE#FJTBKSkxFZ%E?Rtg@O@dVM-qlmt7KBTA-(s8)0$)VTI6#=H@UP%%gtyEsDcI_0 z;s34jXQ8Z$oXE`bh?Z3b80M%f15L|e{J0zWz`g`Ydk{M1Btd5&uO+nIpu@q+D2iy1X0C@8MM+^QCQ9J-w=ni(6Keo@4WJV>3{HZ-v2%xK7vvLpf0u$ipGi0ude<; zM|V1!%4&DH8uACJaeBJ!Y=1(!27aj5sIOis27B)CGouAYVg(Q<^lXMIAQ-L2PKdiE z(n@|G?7#uT0AtI9N~5u&gajoMBNt9GwL~)7M#XV>lAYLCtF3j(rLBRIP*51Two|69 zlkO)AK$!~?qgUoSMpR)n4?%eSSt|as|5q?Q(QCwaCR|7|3Dv08c3zk~3tr$UGyVIt z$%!1iC;VxWVv zf`Xlb{w(AEW%CL+;h{?{@=%c~k9m!p7vFD^48xb=d*q-Xy&wp^Z>zbW=!k1(KcQcQ zg^JktWNxA7_T_|*^Z$iaO8MEwh`1x`JO6d`=@9~=$M%}Sauu8@NZD+{Pz z6qj2ScJT1>~ z+4snSDkX~Yccx&WmvqaVq*p9bnqUR|sg?}|a*Pn@WLS56a#lkG0>+T0E}4`ZP7?<| z5`rcfraT1p8}jX#6Ic{!F6Woaj54Bd;P>Z-U=s^N87+(9#?6ZFe1Q|xk&Xmw%lnPS zDw^j=M!jp2V;hmA{okNjH^@PVnw3l&C4h{KjIvO_6i+TMDX3rQI67n6`t|j3Pj1F0 zpJ2h^+vFkY^M{r6*xsbYvKeL~Usha<4WaQSA4sBGlx8kwOTY_6?@(xORke?;fUTLS ziw%E5Q1%ysqBMDec-ipET!aT&Zd+;h*6fV^Dwgn>iCn69;HEX3Wxrog!ly*_G zb+D-tpr=~_5KDZ(jSyGU9CLDp1I&Y}fOK{9sC2^lbbX~5mTQ%=1?s5ahFQHIjI4FD zJ&D{*LnC@5Aj%{}!(zA@+gLbuzu4G1BnyH;1=Cmq6-D8wh-hawhC9x8F-|Hfm|D$>};xSY%Fh%nLInX#scs~jQ^@8Awm2l> zLm=ZOh&qR0@?kvs<->$s|C*^h&gT|#SN00zQNb95PGo^QCQB9)q6HKZ#A}(0herxZ z(vwH*Id2qnwW<&%GjjsSQ^rB}eC^b8%VvBKQedegM)e+<(kwAx6H#K&By;1p`EwNI zYe3$RP`v(D3l;0UO5~HO>YFbXqXhi0n=6%$pEJO#l+Sz~Xj< zYBQ1**jU_MnkpyaCH{4VVt#T5w#gkZn&$TpaE`)3?{~=G9~1LRyd@ zrXON29uh`SWQ@}5fmGd2|34)LKhtz^3$U%K8|Yr}?OlJ6EO{opJX00WA88#9EtCEDa6w-Ar6;WC2`6DW4Q7 z1Uf8KK95oyFV5F20TqR{mq2^iKbG1*mU3T`OFzn9APS=`^lyV+`CU%V?G*=!ns{3sfaADDv z=D#VJo!cEUY?PZsg(PtQ5JcM)IH*v&OibUN!*G)F2TOR@o2b4zXHc&uO&TF%^q|Jo z3r_Htu8T%RNYy13(8Ks$HmG#OVbIQ@B$XSFE_WFVDZXEffoxCV_LK@Ja{1q)Vgo$D zJl)*0@s|Yb{;`u& zRa9PWveCGor(r}5cfj3Pr5Xy*f!A9Nj!yc) z1#gqZp=+h{`(|uK&CKBLyt36aJ-kv`a=-wvO}C#I0WGC`yfL_qJWhV#pw3mAzFTet zyY0;FxF@Y~F&kbQBY_4@`Oq~zOS9ExWivw*V2lG?Z-8-wqc4x?)vtZ#VJqp5SlLvM zbGdkS(A5Y@A!ow2_w$F{4eQ@wO7ldJ8ZmX?kcL#$JNKqfnLInV(|q2gjEGS?&JZDE zkKpiR)0Eq@9eEp?8B*%~-$2VSH?~1CjEJwOU4JyHRtPv6`Yv^1qgbF<15FiEzJ<8x z$Ub3vXqVa2#bHTk3#YTu!ewj_&j<@(S6^@`LcOERANKS?wSfh$NbMi(H-g?aGl7Lg1QP8lRi=fkhqj! z+sf13lkwmL?Snw}=wzfIB7ItJF>-3{8D=0P` z-O+P=V=>_k+A1qEW9enIQChwnd>k8VPy*!j*;>r{l!*R@z)=7t@EdYaMobL-2R}ZwBqH zvhsivuqWQ`EDNXl($ciZzY7DB4%`lwTg6W0UFnYt=hH5nXmuIw_&WTK>ZTbg0vb>e z=*B;tI>SWGJU0tGx9YFD+22y7?8QVW(st(lA5ZU#F;$fU7W%?0W(s`0($a}LWLp&M z%=K8Ee`QRCrnFn-{KLZp<#D-;qsDL7_S|M&IN~UF=M*Go=OVWpjatWx@FFDd7v%Cg zWHL!nyU=8(<%@N55clC^_fm#~v0fJLS^WHolH1QRkY_fsEiFXL#rC6*S}W7@CMk*b*Mf6yrJIm;6Pb0s7F|R zp)#O&oetYdntaxk38>MxMnSGmoPW>@m#>jJ^t2v1e@=U9Klq*N}Xxme$DeTY&o+pSvsmukA?}HgznBBIS~| z(+RgvprHT5W#)q}gGRH>S(go9PtqsRV-GrM9><1uz0~VN_NX)&2lgNQ`%ajddEKD@ z5$^vuNh8l*tOC3*JmAdM*49?DE5uXQ;ywEBaL!L^RxucSp>cuP7pMqS$?3GLW69&1 zw){fq7EdKyQ^W@cKo3-i-`k!3kup1-H@f%K)DO(%% z$GS8nI-BLz__4{)-@uy%L+%wmI*5`c4@6r;c%B)O5k^9czyciYx8PI(U&ufyy=wPB z(e#-b=cbKOC4=DCo>9+U zBU?JMytbyvQ(G=~rOZy6{bdHk*#K65>=FMW50KkuX5=W8FH1BRsw8rMTT!d__{vAe zG=f=~^Zq9-m&OP8#Q*;|h`%|Jz+>WCLu_0Z7A^|Aa+)bMc(tzI6D3lxbEf z2gJ`Jef(Fha%afIgAd%D_J13cyshE~crhtj_kd_2uF(UqAC96#AdunX59xA-O0XAS zKY@CZ|H97?SFrfmfct)&|7Xz8mk=sjj(PLs!PmB#85wgIOXq*Um(u@F`Ul*JDzpom z3tV8F&K5)s`Ivz(2XR$GVsj88yu6y=zpv?7|HVTXVHMSCV)2?{GIUrSCwSd6eOL(# z$3%Jr`KV+yW`uqJr}q_1aKF-Ajvd?Si{n?VSP9$M^K!$7S+3B#P_9&9FApkkV4PS? z{9v&PS`z|)3fgZGOpU@(L@5+R!uS!OuS*auXya*Qa48CE}G|B^owzX65V z_U_ozR8xOzv2K&nwS^fj%+_0Ytv$4qQ?=rj zZ7Hk%e?|gRc=##zqim6HR_sFz`;2Qy9^Bpm0BRU@oA3WuKh6nZ4XfF-&eYUXhy+56 zZ8o9lrq=hSR?G@+B+qJj2s{stOwuMs=Cw==@{L?9hN8|Uka|x2*yP?pI0Z4ljr?C* z{U-H;227RM-g-djWcd)*Rot%3Cn_9vN~X8B_wexW^`EEt9dsrG+TQ=`_4Nq;e!9N| ze|3o)k*%Ys8g|MEiSZs}>S&r|4yc;Qhz1%|?2j#vWAvKHePHZsaC&lbn#DfDLK>jp z=SYOboJf8FE}vl-wfpXdmLB*A<#%bOvWEQ1!^5#qfixVPm{i~`0X>SgusM_^7W2~5>1#oyn5yGF>*jN;#KCErL0q!JwBh>)K+DN@8U z3X>e|A?zTipLh=@%**kODlw59?XIMVC)0Og5tmnJQ6v!1YgZv4Jp>)vjWRZtL2L>M z3MHY3JSjtdK==eU2uX%EFb{R3XA)Jw9*j6I&=UhJF(70;&@+*CEQ=Z)8&R=<0&YJM z1i~Mn0M2(3bIA*;I|3Cx9w7JUyk<~T)*w%w7(+_pnxWadWT@;>h9 z!(L}NsP`ReX7boH2!%!6F6zJH-aA)p=s;qexOhR6UU-zryV;l={Hz)5;kqJ|^ragw zk7}du7FGQ9018MvK8j?W?~Gt@BD6aiM$Yh_1BYj}GO7INfPJfSh2G7}#kqA=Ec;JJ z4i3T;L^wiiq7&2aEf=_U47xqYc1EBGy?Z0A21G8Q3@8pzE%IpCHnB86j*}!>8K2x#W?~w%3mu@7zbMz0Gj5{pmyUbZEb@W(!U$3LR>3Nzbh5TL(+{E z>jR3PGJO!9v<~7=_hXyM$dgGo*QCaHU5B2FLlTCd%Y+iiGiV>jfC!W0kaBv*KY{hd zSODJx?hrc<7!`qAmnhTe>`tI56B%n!D-3&QRL5RAX(W?Nk^lFj z=AvI5t!*1ENt@BpKTJ>vfi6B5sGbL^nmCbm4LF3s3YltX*5~#t%yiu$|B~_8W*(HW z!^cSJ2mm&`e?50LlH5h7ys5lxLsb&<`TXQgy%J)HXlVU`_L^IB0fnR7(zp3p?3h!4 zNrJEX^WCgcZCynLiNMHd>_*mDm*Oskx%SOjKvJ1E`fky_L#xlyc+n&f>U9m0w7CcA z?qd^0XVlGenr-c0lscq@m$s+hR80Q?{$6@d=QPJwVYN4CkFuqfuB^mrQjQcNsR+K9jB)TIBTSOwcz5D zHKezfL+e_8tFp+VogcL1DZ>e|-(&jG@4y2S#?AKmo=%idx^An<#KA9=GjB ziR2f9!15ZMd%s_o2uGUs?VdJ77sblT)9h;0LCpI%Yo=_RI2{s#z^0Kk<8Qy)aO3r< z;y(3h;l;cpugMKE)@JLsv<>ldWycX{gbXt9BI)p7zO*>Z^N^(h0z!@X$hq11i-~$r z&1d+{HzE)LFPA{`2Q=>p6TnwzkJ;bw7J&r%Od2)d=BF- zlHqWcycPwuZqUcJt2ZHF-%mVt_gg2)KO4<{4oT~X@L>E*l9FlycEoL3A;~Nkfqe}3 z1a=khT+j1kWV{p`JI+LRljr*LF65c&s+;U&-G7)w`G=o}j)&-KS$&n(7gJD7C|^y) z*W;_?{_L68bXLl;LP51~N0ry8vE)Yrw#8TP$v zR-Z!u-r^aoPK~P!7iJ6w@DrIpLU6Jrn-J_u)f+3^2=D^b%1cYmp z-rfpM6`n?y^w&_O$Hgs?KSh!~_+QtOmo-`Ihwqij60MdRhPg{aB&xxF3SQdlAo(eT zsbB{5-C6_Nh>q0YmQ=#jSZHh*gUh&{*0mPj3;ZiZh(&|ZAam&UA0^a1nGEGg6UJct z%;hPMV90Wxmr;U4r}aaPX*qmxIlO7BeEU^Q_&OXH^@6*8q0SNCIi-sI|%)Tks4a3Nt@o?kn%dG?`U0C=aa(p{W^ z0j*Ub55NeATd0Aou)X;R@J>SBR3Se#&g57~?ZRS<-o_bcyyb8Xii28w-3gY%tR@#wo>ZYk1#U%Ph(|A{GYG zp6qAcQ-$~lmne(C6e+1v#!YImyk<;D4X~O-c=&j2fK|#Dk-8mk5D;{gSvmf3(dcv1 zv6ACeW4q*5&uxX2N-@#-+sJ#ghouXD>eML?a=d9G19U>Gaf4Z7d6AvVE~JO?w<}PT zAPk*Az*mm{*{<7de1Sj@K(a~pf_zaFG-)>mo zA=}gNZMu_;>5V0-nA*4&Ip@LP9`!EBXht_JVqlmq%Dz1B#qh6KW~2hiyNB#cN1|9h zZT)B7#wyL=_9f1|C?w~OkJg?CgWX@BSJj@SSn1>%3@bOO?RoHM)cLX z12V03CyBFN7wwPuI;{`x-{mHD^K=g~=7eq5Y?{PT8Xj-;$m5VN&1-wVH3(u#(V9(% z#ze8TePaEIy{fxd9+S&0&6(2ptd+2r5Uv)OQNTFTZ_obIo9LA+$Yg9tE@z~eEcN*E zno6%;^9^)jt;*1|JS`qK);@Es)rp`0ysTw*kZw|xub80wp_kzE^;W9--QwhiZpzK@ zLBhuHcijoa_>ni{4!@RN>}?U+QtJWK#X5u4$GKtY)h%$|K;#B$>>-y+DPvc3yN#+T z@nzqh#2aT+kvjw`KkSIJp+Tj2-9EPae9TEPbiGf-8)j7R-@bq<>~)?&wqyE8qT7y9 zRj)@v{vjlBRNZ`PTKl#&JB*|k<0fDf2F<*?1c7C#A!*!TTOjlOEN`+(RG0Vb$>;qe z$HuGHHQY{7-wG3*pvxNOD{eTNWooLH@hVWe6rnL=b#+nGe%SK#5=TevzTr`T$z)2a ztH1M4KEx?&^yzU#it}v9O??5MUkrI-T|M>e(cdAtZ_qX4^N8O^O`jslh2Wa$-+n}Y zl}KS!w%g~7k{nfJEl6~c__?G%Z&I6EGek6|Ha%%d+liJyciqHoj7|MnU%Mo)cTPXM zNaO#?ER!>L^AS}F->W)N+R=JGo}+t%^S7Uwo^a&Mb>@AD0Y#A3WroG8LicdeW}dnA zZ=sr6GQ#AV%8~s#M)k_MKPA_3xd8j3$>7TmukBx^sPkP|i~Zqh3yJRXlI>vq+mfDQ zVXp^Utwg-xQe<(&@rYWvfJ(`PLH#$+xF1K`Yl3UZb=>|!+orikiM~GWWdItVe#f~ zBJz6v)Z3%(g5o;8EBlZ{K2<{e6W z88qANEW zBST|>X^#_e`I1VO)EVa2h3ZpLV}`V+e8IdnsO9eJCFaF=y(<#N3p%L}>w zkRIq}2WoV*@-~v>$iPA}KK!Lp#Uj z$^0({{;zia?)%fVt16biH&Q3&k@eX=Gsnx1m0HnO{MeZwsAsS88D8aO433AHFR#t3 zLUObG(JE?z-2As0;@an~!FWIqgE->x#5qq;pPHWwTRxe0`n(%SwWPjwDw z1pt2gc+45T9sE-5c)EnT`m}ht989@vbh3M{>r*ymh}cLWKI7u_&#bAZ03hV>75khP zOcx6*sT*M7XKxIFqeD8}fpj7LOr;Rb`}GEB$5}d1{St zfoO7RDVMv>cI_vV)Xq@VCDp9Nhr2tCEWil%IYC8`?clAfvN??`@#>0;Ar*^d;q3Wh zG5xjUll?Y6tknHiLb7zf!G#P%^oP~6G6_>D(NTNUhpieM;Zu zZ8H3>@s)o2QgWtxZri@pdzEtSmTyhf-9>)s-y34%{kiny^EGuh=bZgB;`afJk%-fI z63bdi_tR_SG+)}w!BVid)e7D_pS5bQ_L89wzyMV(u79G{rl|a`HQJ)GP=)UBk?dKA zum1M#sr&so0FnRMwq5(VQ`1>j+xpKa@mc74!=hkbMHR(S^i4y+Ce@_)vWqfWNyufr zto3hiv;?@zwyOG?i$XiM5D^=q4%%>%?#?L|OI zuqz9D`;`2ND+ZKW-nyK)d=G8DE!2@p2%46IH_D4Q(< ztN%1jewnQ6o1i4%-uS&nCsgO&_D0dg1|EI)apu0ZmEJv51nvk5ok}Q`MV6BVV~OeP zyzao;@Ug5ayk&o1bj{@u0QYoep5sDujsb1Z{W}WQWa0e}sgI2d6x3eA8e8?JZH!k~ zX(z+R+4E!NT+>DOD;5H6GYM2YS4oi+nJ87&{%QCrX^G6&+hQ%I|fQ|RJtL56; zt46C+|FHi1kCfC6x^w8iSxvWvWxAHUuWh20R4GmLtTlI$rNxHd;%|@jLL72znBXUl z&rb~lB2raU5K|o?CbM>BkglLvv;)? z^G)xK4FV19CX8ytuN!n9y#9(Ut&0-@!hiWUN2Vg_Bth1(&Do`^*Uv-PRnhTdffO& z1q5t@SY4ow3y~$ zx%kA4jB^p#Fy4F3OD19OE(V`;HXr+{*s8j*Xbu&{Ec8tV2kYD{u*&?l*7{_d?BOOU z*8shXT%5?@a@b_Kal5Z6Ln+aqbCM z>2*g@&dy!9z}V6;mhl*}IGt0!cfK*@-SmyL^rLnUhfV$0V=fKRi;NrMB{;Wso0*lT z?Ue4(v0Jfma|#cF1JCP_=5T|xJVUP-RFh||afXd3Lju$)BHGC7gDUbyK@b`*FwUO2hsh3t*6^N>OrdzgVSkJU z|MVxkD^BAZc=)6DaD&27t<~WD!TFKuUg!}~g{M_>6&m*yusIt|e!?(?(Alyx2Tw17 z_pkvf_OLM$@n*{3{r6E&%gv##dv;bB7NH$IE~V@Vt>@(FKD)Ci=7l#ikmd}tI=i6q zAd5ILEU|G`(*cuy?T<~;8d0*ih;h>}=J^sIwqtp~?C1%$`AEm!mHkeB+Gd;;jjql~ z>d>^wfhd5(qIUbdQ4uCZ?YPZk^l`ym%w;@?n5lc<^|~V~WZE_4(IpgIG0m6GL=t>` zJ)g0pz(@Oc=DO-a2^t)VC!6qm7G~Qyui?>J*x=vKrawb14pNT9*2PPqBD>M=&$%1p zE-x5GD$S@Jt93Qy9-nQ`mWoa~h$&<^yG(Dh2UhkF1@prji#MTy(o%9z0csg;Hw|gE zor2QCv9T{s3k)nEe%Vsa^VCKxoKigYEEHJKX@z*N7$_6b_K`R4!pWfHa zbYn$?N4skUk%_Q>)?=4bxeRkyFh24x;$LS@oeOky*+={U!^>E#t-kFiwFZ{X2b~wk zUNMW3z&3hkc~LD+Jc4OFF9*ztZRmyhWXnrQBmW$kXWj$doG(>Uaa89yN61^wA6 z_iiHGcza)!oV7UlCd?Hg+#|3TnxObz&N~cU0fr1AD1$w8yt_r z#!W6Xx63OMk6flD1l@oo60@-G4x_tX?UeNlE+bmV_S?+`REx$bbq|xI2L8p*{biNr zkfM&rnfp5&L^Hh1YIKw&RTZ?OJ!AK6ab+!srG5);1ndikP;mVXr}5){IW@dCd)7vY z<+Txs?v~dLx>xpidoD@XD^5#Sk02#W8PSqZg&f=~N3+$OF6OApQHCk;&`v9Y^c6v! zxUk;$lz&oyuxe`D6^PcqeQqLDRdGFZE>;t4KKDb3E5kMsGcnSn@1M@rHwPOzxPB)> zy{Y9I12T3*hvZr&8Uxp(TL1|EKOF438w`zxq)yr=I&Tg4&MQJ=+w?p9?)FdbvKcd{ zI`RM$B{dxFP|#7L!+N)M#cJ)GQ%zk&`iei2cbw1dD}=S-t7JmfhLZ(n9^TwfRN>{E zob!E-dyaG5JfFvdYye=X8}Zv>va&BBeK^Osbz;%~4dKp&b5LiA$-dpdhoyw@;dUvc z|7sbJ-I38Y(#nV}OcM9e+j(N*&YP*bgp9w}`EZ@aWlWwaP)JNlG-=PDVe@qj^uhwf zt$?cEPo~Rx=h)PvI`KB{lhmb=kLz3eq;a0=+B6>L?x!y;KCU0=^q$&egP!aQP-Cmu zZV(yM^y4zuMN=gpm+5WMY3;&;kV+n~skz#wB^^LLWuu*Qm0fqrvl$ z)$QXov2Z4+ze3ku?cIGf6!15=wi(*HUnOYXbHjWSlB8ZQR-z_C`R3dzao3#on(KDB z6{Gis&?z_Y!noG??#uS^HK6cxmQ>HgvUzy>7(WJzIN4YC(#I%fW5E|_QR=^;qkYg} zaM=Ep=`(=*UBhG8d6NJUAVrO@C9W@1_@STG-)>FnAQqx8X@K`N&QqRCD`_WK7X5ib zvn(1;({uRTzLr(jD&u8y^^6~g6mYgkk z41bD1c5aF&*SW9(X z=(}v_RUag~{9`U@2k081W^P1@#>YKsQv6Er(KR~ENY+V4peRMZI^MLru%WQIFq1`u z=Y8Bs3yscisvs1`+dw}$DFja=X}85Fa-ODJdZ51u-mBpK3arw0q_6I7CPG)9IjEVZ zKwIL>GCmU94aPc)zKj=dE7wAyuYNgFNI8Cw8zdG0xQuJ8=`9V7&)APp48nv9%WOO} zW05im*mG1a8`}=CG~sV(j-rw&wl}AzQ&7?`FSyyYE<~X%Cq2$L@YMuG0vnbE#RPmj zyfPng4lkLQj1T0f>7V|7elo`Z6Zey}4QT=;#=Kl&ircXp%q8LNxO(Xp`)XZzNoW}cJ(9i^HT+Z zWPt&;`TDO`wM)#>l&rl*{q%K(j~Q6PwE14dp0=9h($ejB>mR2__xImPs;V}PL9iE8 zfs84QhqfwhSFx3E-7g9?gXs%h8rln4LCD3XQxkJtfU$j8ML^00<4ha=BHu{dBa2bo z(&FX()|pp#GS+@x1d^L4tCpq$(uMu|OHnc6pFbX0ied7LYszufjfbLH^^RnE)2Y1LpIr3rnvE2lysh+<2OJQ{Rf3wlA{AeK!BoP zPG-My=w-WgHuqig^v5NE&*#OJ?#tfQ=WWW?=OK`GR{fL=kVd_8Zz+qGYC6Vqh%{4? z9K3D%Tzi^q%Hg&+zgMS^vltNmL1YoT^+wsh_pV=_o4TU{Shb`R)yS(Rz*U@}c~x=n^h(c0WiR~&zg^^bD4f~}8b-Y&z(pCceL z)T}nW0T$EIbRJ8djTa*F>S7i#zT;)n^er4VD{U9$Y!{n8?>$w*?MLs<(Z(X8f^w$% zg#jyd%|}%$?PrR80r6u^!#kg1T3wl)=5I}SrLIR83?h7=VuKI~QmJw3#Xgg@ZAyt+sma?GU?*TWn3jKA zQP9;wlHDo0MC}@%np1|`IC56otq+_-+r8Ev4cn?NpT^o;EmJKZ339p(AN&tAqYv4~ z#e%^F<%BOjaMrrgYu)ZJIGE+DwP{=w!pDDk9A(R;ob$PTk6-QdzKJGTOcA2y0?%T6 zDne5el42;}+{^2qilSkw(&$F_zu*0p{umEhmV%dpE+wY!}297kf+XH)3_bU+H*6jnznOWr^l~uXL)1W)+cUH z`mDf?YDM#I*S#Sb8n$zh%FBVv*6s`o6oD$cCx@7%R>*TEf! zv~AGz879j%ZrHSV{hmW7 z4jnf?!Ked8Nh)%{2Zeiy~%SJbGf?C-W=l)O&k7%8~k=obX-BO?A;jOb{ z<%(UqccJcl^z|S8DkX}gyeJ=r(Hd& zy<;c!h3?;WK+7gBrL4PCSosviRmtyXx0i;Q8}8kahW~& zx1&!loVk3*hAlg_bhMx)uOQdB>bpA{A9(qk+c{GGBd6@pdMTF&)d$68qZM(lb%-nM zY*j=#tXpq#>RLhzL9hoTylCfT8;nl}hO|lRO8xiGpS5ep>TT!t?>%&I$+X3GX$>8s z^jkJMS__QrN*GLbq|>5}=Z<>bYa$3PF(gj)TzB-?e&_3rElhE%WN2VWOb`Q&ttk$B z{`S|87Ovg2ZsWckhfW^W)4Snc0E)Cv(2#T4U3d9xgZP@Z?j8x3A!Ts}`ry2mYc^|v z!6m(ouEpA3eEa-6Ab(w~)l_R+g-nE#X4H5%EL=9B$3MsPnUC zuRC~P)2@@+r?(wAu;Dj5FDBMk_qXMy*tu(cJY~({y_@zNJiBep(yiOSI`7patdcck zN0>Pr-o9+%!E>8+4{qDH??OPt!xF)OLM9wgutgk2ePN=7`O*(&Y&)^TJ}SSof|26w zue)d2QoY^V_iWj+;`Fi0m*Z>dB)z>7wp1dJ^9Ga*wUpD~zh}lK7+*}BF2*OYI&Rv% zvD?@wF}0824Yap*2bukAleJSyd=IOqJvY&O(bx08+^}u?o`c7SQxS zav7gn#qNqZ`_UFd`=EzxCU;QW$1N|ueEQ_dZ7Vh|KXLTX$(?(47NtVhv~`dSCpF5Pxy-|0QujvAUhxE5X0E$x&_`#2dk zMr$^$`Ty))1z;OT)^3xwSGxb&D>Ele!_3TVi0wFL#+ccTDaJSsn3*wVW+oYB%P4~+ z+mb9M+i9f}ffvs^p22YT2{ow#^tC(?}clAhrlow(6-vPRsr1Qcq&!iS)jSB+?41Y`rfyW_R z@*&&k0c}OL*y9TYJmI`>;r_xm$hPRn`Aj@6vMC<&BMeu-V+%PPWHp5+vU+c8ACYf5>)+LOySvFW!${w74h`-sdA5A96qva()#| z|9r?pz@HZ)XLG?sE<$edfKj7|fAK^x1qnEOK8MTau*DnyK}w-Ov>;l9#4Hw*!{Y!U zMz+%vpTi~2o52&zaCuBFTPWc27WizK@R3zO@Hvn@*%85fj*!C?aM>I_k0BItkur!x z$o7pO8#x#Z3~(RuQ5IQzK9kF2K$Jz%KZU}t5zUZ{*vOlNAe+Z!^5`5W^!&FR{ydY- zm&LdV{;0Q#>W`bM+pUoGrghi`XMyPj>~BPz1^9y{;_<#=ixzpjdC(j&DaeQaK>5XcDI(j(Lvclm$f;#QC=OT1 z<_YN>0SDPq5;?I9>^8q3n1_cVk<9D6{{iMk%1eSxw!C4U*h3^?EDOW`BrwMH7+{PG zV_X<8#)SdHe+ht@hb3-m%!gG>{j^5c&lvc?iT=BhCO!smMw=ng?=rl=wn+ zOax-YVS%H7WQJ^74nU5hf_NYfG7#TKGe$2CU%-TiKo5n&`T2!K_(#0eJL+^m;e^O( zRzM$+7qo$D@R7fPaUqOsesN)OQG^^s49Wmc1J=kxmc}5*uaVEyz$SdK2QV=%5HJuU znCFRwqxLED+8U zAEzv4q+kb#1UiE<$l+m&^Y<5!!XTz&B75`mM93*9$t09q4@W?N$P@z&F5L#e9ppl&g7iY3BgagMFNqZ75|bOamLRz=D@PKN-WAie zhk?qFND{|FmWEI!DNYF#2BoT!>%m_ST~ZB~^pq)rj6PDkpwb`2Lc(G!ON(lWK0*v8 z`4j#FyiKed8c(Vt0W(utvpVCPfJgQgm)r%{LA*J{^<4@M z4pBdpRtlgxP?ee9w=>c!(48%ReehWHxsmqV*xVNUclb9dY#f zK_D3+GSScv$9zZbF{m^>qz(wRJ5WJp)scx23^9n;PzIuB)!8si|z} z9Gsvs1kAZva!*4mzPqEjt-G5r$zrj&w5hJPW=LCI*V588M3p(|6#)584|ldV*MpFT zhQ@k4g~?=rt4f&|>uYKs=0M+l9LjYux--9wW!5H->i?{WTu$`NhXtac~@ zb*=^&m(3;D*dEd_t`794F%f?eDpyG9Z|@x)B{QV1IjU8EH*R2H0AvDMdxnYAORuCe zD5x6fqn~8KJ9wX6N$g&2HPU>!N zL32S(2TcnUo1P>tD{ucKb6NF?c&w@ZHmTVM$s9-vYLG|qs2a5mZG`bzXd4VFrMIyS z+D2PzdsAa`XJ;oG8RS5G>f}&;=jb$z#bwfD(+&`4AT5(Nji&8r$MyD)P#BbvPH4PH zvuW$>8=Xa_bSa?TDfot#26$Lg-`s&4ng+{*k|QIdQfmOG8YB$$jgX;fP4_p-Muw_^ zvX2iF2Koup%o$n61(F|)j503sGgm`ehCyv;qAlG+V-zL`k!4({oqIZ3!OqZ|8aoES z_^8_OggrM%s0%RKbU^EhlYe0sDjC`L9gmaNCVrH%to9*2bDB8Vjy|vHz>iJQkbEGc zUR)d6dLbi71+5oKgm3QX?(T*j)ZE;RA4DQc1X0I^28Vlwrl5|X-;Gbr&WZPq=P;4Cu#9mnMHZK}2I`K=5H}u3Ge<_t+tSk7M;PsF>_m$I`hb0) zaU$b}Oc9`JCPoGcZC#^-__{iA)9o6BUWsOlLR=}cU@?3b(&{?;#t@q>5Ho0%6aMcHu{cN5#<)<4A+3&M@GhqUzg_qrCt#pp{!!iKQ_0nA>o>(rq-r&LA6{So!gdXW9y{le50Th z&>Usu9-0+e+ty#>r@8Xwqh=9dx$T6JuHMEpm({0TLUMB}+gkHu@7-~hix~z#8xQRYXi2|170|XT@$LKYpLX!G%ybt&GV|mboC&ZOrY|3 zxh@;OJfmRl5Zlz-+c(R<=e%LHG&sYnx^Yp}#XdBysJ*$WxcRo0VQ5oPZ*|#ivx{%9 zde0y!y{Nu9+0$NIW8EqLD*h~?Guc~CUj3wjcR_FG@C=hti88L}=I+S|xr5fJ(bbcn zCw;iB!u+qs!6o_K4452IfWIE8bN=X8$M!mBwzjslMw+Ue(U!AHZROITMsCY**E4jx zp4#4CU*4W>r*h!3!;M08B@Klv;~JgoxaV})L{8Nzss%)~=lR&E>S`N@$1y_-oA8dZ~lS_U%1KqRT6(LvU z|N7-SdI_lowXLb%Zn|n;9==)57D(wX(CPUyr}L)%UJ*H9_O7mO@Mu}g&dh5Lc4~G3 zdCj0kV~m4WNb1e1_OX^*+Ry&q5yRkHnT?$#Nx8Rm-@01bIDniPO{`72XSGuyY_wyd zK{jnutRtiis%#^+-qv~UFDDEGZ)UX<8jG6Kojy?sPRv2-x~G2_n1j@w05+RFGtz~_ z;o4f$B7E%Cw(CdtQSmAEW^TbIvAt-VPXFWX-u{8*R3K4kiwY|Zj%;gThw|krR?ZU>U=Da}b%Q|XWzV}9{Y<@Ay zxQa(7r+czoHlB96nUY@K(OR5Ze8);5st-p*s5LZBCX+bQ7G|;WxW3l4+m!?$S3GWA zr0RYnO((D9R^WKJOb7L&>Q+AYkb`cez~^U$dTcX{YG`N#Qw$7`ljx+G-fXwcXB~r* z)5_W(WHeS8XQ6O@({UyLs>YVi-XvQ?j{w~$$*_aFao)?zJFvKCv@5~z|Mt7ZH8fDB zhb!X(wRWC&Kw3M}r|?7MSq5koensEOGBBj16*xv?h@nMjRdzeFp*WNRdg4@nT7agC z`W_9B+^#0VER9i{XsvYY-EHeM?&Q_gH%D7(U(`8l5ZB0Mfv5;I14oO1@ca&`sH`^e z8R96G7*}LJi^*w>P(Nm>VT+u))>zw_<*0dF^Qu>7^~5A)Fw;StRU#a<*-z#rvDUXSAH#)V`G^}loNNY;ARXOs-o{iS2Rdvm+ zu{Jt#x<@qQ>&3suqu}vK6NG4^*WWm<;}MY7+~40nHdx@f{i2gk3K+J%G`;+expGuj z<5*)spn=tii^gFswT*3MQDz!P_w77t4LZ}f$PVvz<`J?RzKero>S&JF4mmfUgw)bD zsi@YR(CgQ)D>@~BwE;t8Q^NywSvM>%ynf(nOl48~1Zf6a#m0aE0|pGgEPivw#rdCI z<9hTwt{XkPsh(IDxzh*MA5_rQ(-*_oHzlRMrmreo{rSDuv-UM}qz4m1|DP zscPsLLL4JYCvbTm{KCy)a4D_1?zW}|y2`p*mlfr9ez?;mrx!=Tl?1yOY}5$qjp!`fbF2#M<3f-x>W0-VeTUN-X&Bj_f7>~}k}3EA#ee2Ou809R>GTX%-nz7?7gHT~$3 z$F!l=0__#HQT3Jmon?`3AUU9mL!yKAx*(|cg&G<}q=UBXIl)9lw1<Wj6#S?4}Yd8tg?pd=}n%2NO5z>yfhf8-OJGsBvp^^~HK zujr~l-E*G;eAY#Jps`9P*|xqUOd@yYHOlyNooROa4rJ@uK5>@m$;CQXRH zrMv6!f!!yUx`w`CP*DkPN)iLG>@~v21rZV@K5JMHI@zuhQc(ss3X40C-zFq@II{5$ z6DQAm(u36N{Eztf_}ne;CRX|%J>r*DN1zJ0K$FOQ@g}bxa*nR8?Wu+F>iEZ&X;X7( z5hfc_Q%ycHOq;~CCGJOF*>dExB5GJeQ%mFU zmfqU9TV8$!_F2$YwA!0-zIV_c8HZ^gKP2$AXaA=-y7?zyZTGsF=C z+$lbLRF-jpSJz+Tr}g}^d#y5aTBjtjWOfnYP=k;PW?lS3zP&G+-=9Fx`sESn>ifnB&RD-eS?840RzY~F7X-1Cp3?1 zx|H(RY!1IK-c#91PcOV$fQWM6^|_8g5Qw6V_27N?uKjSEyh~c~#L#GSu>SK;YXnvn z<2js(?yhvt9nWh60UH!_|4YUNfR=-r2v|_zb>)4210ACkF~+AZ?znh4Vu;CPq1J=O zAj`Orlne@x3cV}(=k{v2d4!`Z5sDvca{9vd3o7A*vT0=*7sTTs8zUnaEAR`uZhIwa z1c@dFf26)O()78#-bqaa60t19NB{U|%0QwJohK^t!rb=kQCHui5!>2}xX2^*T~S7V z+IKy%aR4G``WhVjR0$3hT0#B9B+2^+}3l-VFU()$?Z?|)UwjK913Qau5sm! zk4|=k=>Pe}{U%Xyb;!$<0Hmob84_h&l5>iO`3RL2N?Y4Iq=Cz&A)FZqn0;V@ zZ0*aMVldv=%_rC`yMxpjX84zv51WL=){@XiXq$Y9aY2rgm4%TWs5Rp1`i2BtkqqN% zrA*=TgI$k*vfrb*abQL)gbQ6mC@kDiRV2m^nX8PJII@faVb#rGri%RTw z{q@CdhM`T(r0#|kd)>D_){2|J5n1f<>bxMglb>3rlNjUt=AX;B&?PV9cmD6NPFPgc zgj8Wjo9ZmDzW1DU0e6PZ9!)maKC*M&G0Ug{HkC7!Zn4MO&gD)W8~QIl&+N$NBd4#1 zWf8|G2V>0N`0H_b*1`JOE7~^^jV48k{j0;?f&dRE~%66H#oHEqiT9s7=^a=4T9u5j=#KETG2#4n-p0&K24K+qy(9QXW3hkmJuHj z6_*^JU0$4buWMv>nmIk((^i>Txs)%ma53HAm=PWk5gq|@B2o(OwaEMyF8=5O{PL#E zq&Q>~kg)jVjM`xy@*xKq-(7tVxfK=`lV6gXn%7v-G(ckk8EeWaYU~&QM;y}122p|Y zGlb@{d#JRqu<*#j&R*ikNN+o;mDnw#K(HdC0u7RS>#DM%pnwq-MDpxtPfaakB()?i z!ob5uStn6uDPRd;c8J_i-iStC7F?JeMAe80kBkV<1m9O;*d-uek%`slB?0r{is<9R zt)*zC+>J`9Xz7=hh(F$5o}U5tBO@d46$PrUzTy;cuYL|`atq|{vaEQhqsWM;#Ee1^ z#o!1*@@QWND*4f%L?(NVH(ZyIl7JW~GCnc031|$EVIG|%RRejFRaMgwyu z8qlWFnp4``);&q({z&BV^o){%obd2)&?>jG4RQpaY1@y=>V2$YV!KrCF+yT}%H;b={$!Y5+ zK}Hay&-B$qOFD1Ly^>ZUB;tcs?N#|pT_Y?kuO0d#Xh(H{R8&-6bLa4bw+dw=qxqtdQESxnOrh2QiXs?o$WBiN3DNO) zcm?Fvj&5JVC~V;fVwMI2L_oq_e&y3Jj-YP^Hm*ge}3>YwA!0-nF#<(5>jB)**0lpxIL7nJp!F6T%n?U~h5Q_I%9U2^- zW+IDt7%*VKfC0lF3mD^i3^2xp0RsjM7%*VKfB^%BCjyLdJqAyNaSay+`JG#_a^=bu zD^@&>0RFr3x##}0*)p%Ft-4rd=L|_=@fRS%{zMl!)ywMM(rq?=D~PzArMF!5Hz1o* zEc?pkr-LuElOei;g%rq-=*vFnf6{;~kX(=tN{}GBCx^jmjT=3@W!r50Tr88!A1_b$ zFh8+Q<>wxkj0zEd@qz^B3CUh+msRCm6Z?PrAM%A<;#fz7bYBh0T`~B)zRDO6gU^)w za4gx~K7LUkdqtR?-T(RiFCEI5%%yYH!~pY+#_Ox>-?8wTi= z-^3=;9&D2F+X87uG93YwtV{IK{!s2l18t1@lRDi}^5sPq3w}s)eUdLo4y>mxlPny{ z4AxVZKW!`B{NoRSWd;1Xn4cj`lzSa}bDwp1t?aQ7e+Wp*{+Me2LGbzH8Df&@dxzcb zl*^X)-w*{rl89R!qyovaR^60Wv(~?nIrJ~a z2Q+e!ysNi$T0I~6tdU=2cVYJzD?Z$}!z^V8+1pd19HQ+~6BP>jyYoYI|L?G00kMDj z*B*jE6VUngB~1r)|78V)8e~mp*?xY;IWVVU^7s47E|{G=6zgO_unwZf0Fiz;|aQLKLT*QJg=x+QE&q{^%pHQ#<(7X zC%DE1ZT4U8RfyjFz2O&ST;RaM$j_SGlYbrIu4xS~55 z{wJb5{hEvm96=$c^2S9~8-t*K z$%}p#K=QxGxa#=iIa0dq$D1v@v&si05l{fd>dLz-rC1o_`bB{jF!Zu6_*#$UWB(5R zn2d`fpmMo64ja$AdZZ)UME@)-+hY2+#uIegeh>I>WnABV_Z<}K_sh77f}FHIKVWv- zNA=j@1M5E6cvMyCMiX-Gjrbr`o6Fae24)2l6&@P_c=4tRqnRs?7^*D zH?Cd1PyT>q$_RZV(|ntS`<<{lqzS|PF_&$wd(~C{Zi93e3WQWFF|H{leX21n)c(q$ zjhnV?*}8d+qSf7!su}j|Xt%87J(d~JCD?2>xjsJ3Mq%%&tq@t>-t^**i~1_p9xyIG zzB$>`Xw3(&tbG2%Pgk!~_4ml_;!gGuk}Q=D?ccm<^Og-??caYu@n%QsFn!rq@&j2O zzUo^yZ{ECN%c{3eyWP5nBeO>db1tPpkz| z04>jy++O5B>MD=z=MQfOTYa_n+)k6&K}OAO)#Ll$di{;p-~4pvxh-xLox?>yz%1pR zVg|W<_S|?;fZLU`yVh<3Y+m!p1&8FcMiPZHHqsWR^Xw)QeVq#zE`nBIvDN0KwF7in zrh)JiLp`0H^2VOd%GY5n%?JGPoYXx0+hmYN@H5T)%4T)~)BfD`R}E4V8|A&YL!F`pT@J8c$`>35}`# znuoqXZKZuJCbQ@9z6i>=Owa53=4V>He=(u}*9R<`H8a(d>u~UVXik`&mbv9=CzNsF zA`C1Qc0h5qZr%3kh2XsAQP5e!xLRjA+B3o|)GnUTmcLy$%bp!CyK`MfVc*7WTeoc6 z@`bv4PG{HbgTusyR9u$7p~60>X#`gz8k>f@K$Pys3MhF4GE%MU4sWT5s>L z3h+|7aPrWGk2dc+bJVi|J&Jm`FzA-fHfa3NLEby*;G2+HogHYl{*$*?zVgAxtJYp} zw@b!LB^Tc`mP-E0I3ljHtSQk$_qE-Y{+^dFok|W*4@t-}2R`Th;u6^ZF?a%5;CC*=t9nTggMv{Pm;WA)#K**6N?W z`^ukQ`Eb?7^+tEYs`}`|ZH*BY7k2O1x@GJ3btmLCf|AFnEMAe{$@40E4qi~!I(YU* z!6XxgStt&Onk6KIDA&lc#<79cf*`%apKRN@4GN{|5SrF0)0Oyq<}?vs9pR?D<;ZTN z)MwPpgX;Kmb90jwAwGsk4@D~Ft545bM#NN4fzFiC1k<;6>uIW8RFMON!07muQAU0T zg~=UgPxsOIzip;ArYBCE-0;<^t$U6gaIFSgaX1`GM*$2h&{RPG9cwP?c%>DQ*gO^; zTKHYdi}DANCIkbcQ}#Vq4TTf$zwzdu-}-3N;f?k=)qR80xI)>q+McOpq&Y5aYBLpM+a?(B2kkNbd7SQ~- zs-=6z0EHnw6;1p@On=2Kn@t~o^xR+G|LBXgat@}6Wx%*B-rH|%gdD(kX49JWYrgo> zAPqgagfZID8e;>sk5799*UK-L89aXvNoIW%|XA9UBw=ODO-g@YwiuRr(*D}X4UFEOX z>G>vg68dZWuI}A;Q18Z_qK8?O7*fXNW9yq(8)>`wlaK%O%6lJvzF*Tbph)7%Aj3kW zjrOV!UwiJQ_dj31PV>&~!lJ&sn_4e#Fn7DAdP)BH+RwM{*tgBT3O~Vs!cx0Sa{Y9V zt%Xr&>-H}%Xt_ogPCZ!3N7!0%pyo^K&0O6e?ZGXpckVs3&%O|*NIJLeo{zQq2U}Hj zu58=q7@XhG-j$#4qmGsr2HWFGMvkcja2|lHhA65U98)rNu$9}fap&5Pb|^c0rT0uT zr=^UmYMjj;@9IggxpD}pvTbXRpH;jTJ4T=8B5C!HUNUpEQ{22|>#Fxo=y_iAy>-{> zA~b$*KQ=15T+8T}9^wz+2!{H~Zo*V$;o^8jN#W4eFL&%YxW_iXWr)UNv1mP|`2qT9 zc{i^+qwW+@FiGUh-m_VKSo!#gQ;Is!e@iAy98@JP&~bT9aDk?%wIM1xc2|6nqiBd_ z?&|x{r)MrGdKH(ro!PVF^*7#n^X*UfUfSzbLFlWFby1by`z1u!v12C;kL{25Gbt=q zmff18h8l)2*Pq+6cI(>DHtUARSC7uJ2c?XwcbY!aTUB_&P^zA6{aMU1<~!OtOUfWB{LQ6HNz+25CBr+IAu&Mg}^Z9IJPqI2XJ zOS(xij59(ma}r+ylc~z#4UlTvw(T~Fy&YpruvL-2)*hH7#T9y3LC-d^4=R+)sSVRq z)7^GP&rBc5X4Sjv<((Xps{7jFUABF^`o+Jz^Zuu6&X}u*;Go5}-M)e#NXw}0~GORu15FGsYZ>VcJdbA$YK_Fs&q5=ck~ zX7&_T+|YPSF0Qn9WT+u_$>rMuBjG81@0*3A;B4^ud2XA}I$ujg&j*qQizkLg>cTXh zUZ zU__G9_M^J0y87lw4Q~AGtBF&G5*|acG}3VsEAUHq;YawO4MZ zc`8h=V97`WLn{SmaJ*4b`e!exXkA9ruGhSarbRXUPk^m)JqEuHoa`pH8vWC69g1a15r1}+SL%B4F@;d}XzHZ@a>6qL>g-M#vnYib7S>qwbC7!lr*SNr`?aA~$yy8r7d4E4s1U+*K zR~mld1>3mxx{(L24}jO3o9w9tloBS+w_n<amQ=BdrTZS-!>vj7#(L3zm5k z;Nr09&4o7{)xXlXJupuuWL#H0EG^)=&)@&(l#NkbG0M11L+hGG*dpctzC8HM$|K&H zyP^c8v>N z@&d*c*GuLT!om0sep&T%$OO-yBWGCdb@#g+*Eu3#Tz6}0hk2mYaAlC(vxlJgU~oxh z$b645F1_RCzSZF8iMUK!?QPxbHo9IlG#F5TahY31WDT%|%<09!5QB{xc0L)>j54kE z!BiTH8%7zIQBZN|Fdc~WbWdft!mGAX_0@!KDdQscXZdR!-|*_2U^=K4Fx>|ytn{Mt zC5-DvUPV8X!x$Q^4p#WnX3Nm(`cVOwIXqT#OY!-mUMa1uJ*C+`T3godRSU<1=ONMl zaX=XtaH^=z338R4fywRLIh}n?={e53)WiE*$7<21DB}{fMO`;lSigS#>eZ`XTe00L zx}}BO12jqf&s&eltvhZJ5MGRjiUW66Fc@L5bKRm=% zCtNo;v+tOueI^m6D7XQ>)Q>YRqvOUmT45&U3MMjc>pWzfkB^&agm$8W0g!gt8W+O2 z-Z^QW(cd%0<1$*yqpm4_aw!N$AE(dr2FmgR^w7rt!OI&IY{K)#M}PVn7cef(w@+9k z5xOV2sAT2$m2Y&=pb<)r=jxf^w%h=R;HcKM;BtyY&=UCUIsQnz%^_WLw}cXzyo8iS z=vEir*NW|@PjZl73J7JWS_)i`Jv*un)%3aORR zmd3iLY{8!cUIdKGRO5PN>kRT{BZE@lbj;J!E4q2|v5X6X&7^MGH7-!2>WrryR?n=apKZ696U2zk?O z(AwocyK=XEa#-pfvFAj?QC0`Eui7V8LK}eI%b?`Bp7HST3~M5zjLXRXUcnHP&mJXp zhFyO16zJSa=>^86_4)y{e&^|3H3{DGZ^_@RBaagDL$97*|H>O^Q(6DT2cI0#m-ox1 zG~81BMA1FAQgYg!7|YhUcvHDy7H4GBetcN(l5Zxd?WW>>^RV1@%~O|VhsUmQ0c$dHO}>YxvRLCYy;17# zo^uW_X(qJPhnw$S@yf@aNh)Ra)F{*!gEcM=W4`l_nT3yQXnk*ITam*7*W0$|b^N`eOIjOqL*);96cTVfg;6$^ zDhHg?XOLYkq06@>y7-x#w<_mMQ!9aSL92`DMow*mnfj)@n!=Zx&s;ex@16_9;D;9d zq>M|t#%1-%Nw=H%%a-^aUE>1A1$^5gvZ;BL!)A4LWcXfq<%C}aagb0PYcIe3rPq<4 z57uwku`Xd5%FTyRP8wf&`_Es|MfNlw>Ju z_BEULymhs-f3yJ78eedR$S|^TsX0ChiZHE5cX7ZP5DbvlGSLajn0PP;p^QuW`JLwB z4XDl&&G+sqya_C#7FU|!bV;_npBzv-8d!ibE(`Z0=s4hAuxdR{ZrOOsJT##JIpzfQ zrclO}(mlkk^E|b6)3T@1H7?Lf&>dlM`S_6w=3e;^oq6*JB#g`0Dkh~HIhYh&rc~oi zE+^VwZ?+4!!`Y#@8v zx1G?98yOS-#0E}Id%E4er(gQ$(=XSqUAKPC7i%|e`-^E=_o(Esey9#^f2j7B%MQ1) zs%3xjo2*Rnv{u}1o=6cPot;I;W%>o^9k^N`8kwmF#$|ZUF}NAX3|}-|7^tRgqVAnO zPF}Xg1yA|S;ZAxNQ6*nrxx*&2w{4&<)7L?Dr)dBDw)N4djRoS7Q zDvDkp8OqC^sfOl_GA_gsy<()J5hTs1>ZX>bow0wdgmD>}-A%;JFuBu0O5)WG#|-Qv zvk9De_ACU=H(avzN(Fxy^~6-p9z;E{FTcD3ZX1bKw~TR_Tn$a@okP=_Zd0)GOnD;9 zzZm0s41NX1CHq#PGzdg!f?bU=E@@;ME;rdt<-nL3?C4%J25D(MSNUwm%ekK;?=C?|T$g9A# zo>15G3YRZ={|Mva)BE~!{0^_&eLbtMo63cb1k;J*{x95fIy+=qxd?aL_KK~RWeScn z&6_UsIw9wDGo@r~YOE#E`pu8*6L3xA^IU3Af2RAk72BLsdLCt5vdhyD1Z$u{&>4m* zO?k)A9=en!fs#WFvAQdEd!%-OyCWL}$v?!nh+~yurg{eI4zi;74q%sogy2gicc6{dN{^JaAZ;6q0qgI3E=Ko$c;#TZ{U zIBMuwO@+yIex^CrUe`*?TC7!`=k|+sP6>s?c_8P)$w=cZa#yb zZjZ#~)@kHewq-#gE>aqV_)OaLL~)?4!e%84{~I+^jLH7;@QjweNob|0K!B8SMH4tM zq}JXrb=H?Vr(q#ymqTQ-Slp&~Gh~e`rhAH0@1=Cm!Zx%V&mJSTCYgP?2dEvwxMG~O zUtO(ce(kLORk!f`=0PfQ?%7nF^$s~5>rmjIlAIm~7O}HE-cDoRdzZWlvO2q3Q@yP> z9C9kBj=)e)s?Wb^e&XYcV%F67(1FP0{JTclSB}}<>70G+CsL0xF4?yVWrJXRS3}!N z`jM?%I)A3zUrE`~Bl>4Cu1AAfA6$gs;A{)ZxWWlAP9jRq_Ei`9YhF6KRX%j2V{B;GPVoJz&{u(_%rR55e^sLzZlRq3!XiXPU_0N>vHa}N7XE0200M^@6R`);uH`>5}8g_D3$6T7*GAf{r5~9&iPc45uN#X2->B#Nz z245Ysxt&`{lwI+7m~l;)#aNjr?=uQ)r_x!HKFDK@Oyh2=Y*)FSScjZ#NEzxcaX9|g ze(SrXKf<^`RIIhB>Os?};duyx>j`w)Szjl(L-;_eAAPG(8g#i;T2JVxk9Rxq`U!`e zfnJ$Rr9c_i)enzBWHc=rbPg_ov<(T@PW|60*|gx@%Dz>I_>p`v3iXCGR1MPl z#z#wnUBX@Uoo;#^)z9o3pJP%gp%H>%BZm-&75w;;a2H2iE&on7nO!b@jSwYKx8;wk z?mDex;dtKAGP-<_IL(5JrVQaqB65(`B&luxUB)H*R-tULd$1;-5uJ`2@w>*63KvkN% znerwr?^ZfYpeUd!fpOWdI_K!0T`uDgQaf^zT$L3roBwmG=FJ}OK1(7u~KAz`ke)cOxyNJlrrrxaU z$DZ2myZ{MUpGH+M`is<6EWkG{h?eeTLNg7xgoBqr%clZ_|Tpi zg9Xv9+NZ^g3;eWzD_X$wQ^yc(=Vu7n9!3uK4pF@bO>*CQ-qAG~+)gM0@*>aUf`zyy z)Dw$s90pIUBHG>Tu-c=H%Vn#)Y+8?P7bL;|7#QPv44ydS0uuEo<1*T;CCj)Vh%zqd zLI~q(9%QF$ef8mApMLu3r&g}{Vz*~LbjhVst9R>!HCxu7p%Wm9C5`a3sd=B3XkrbF*DGVr}@-pe_iqH zP7|0#z_$=~`>B8R?rSSnu3Yi@duuiQdPLH34F!1W1zt)Qzj$ipORxWFo9@Xy2VL(V z0}5|ugrBXq;nO!Ezh}N!^~QzEz~wyBx}YbIl!XPIM|56!KHzTIJ)l^!1Po}BG>Ghe z;if1p;4?dnbtCh}8Y1*o?g3FKw~-BwmWSWGfJ9z#&i_tnc3GqwkT)p-s|hhVvm|P- z{;jCC*~#u4zr8Eo`@faXeYER~-52$g)qru4==|<% z{+e^gN6$X>)XEoDtk`Cr+##h{Ixp;UPw9L#D6teYJYGGB(pa_a;)M<9-YvUzZ$`F? z5O-FP@3lkD-Z>FGMKm&G}8JQ-w$770@^4~~&W)A_sw?i^^3mnc_BjT9IL%jUFBBhDW94a& zfV>B<5(#VkuAWpNn} zA8$WnTZDK6qT#Gt#>YNKhOB3vdUm7k?K&yNvUu~jEaQTplyMond0v)rNeLKG_v&En zjn6){a>Yu><=G9F&)lq+aEx=C;6B{^^Q&(vM@_Vi^YIziT#rBX^b3D|N;&>s%Os?& zxuqkU_H+ zDr&`w&yO12${Joi{n2Mg#a18g_~6-R)~lQh%mIo8G)b0mJs?rDqcfErXWoDH|HS$~ z`|id!%}Yi|l93&ySQZ~0mt|ZJg0rL4YA@NeZe)&z_TC2!Io5U}(S28Y}daq+$NyH)gqBMJ*{ z>%VdorAcC~A22R|>m-zMS$}%UWW8lnT+g2Ujk^=vfQyh!IbEx|s?N9e{_G?3D-IBRMqesjWvvf*YD&m; zd69<^(=ut(Fm9Nm7Ewgj#JQE7;jzB$>KwCSx;OxN+CoT3XA zdsDY%i&+UOu0A1{4FDzsF@Qy>)QEMd)~0d{U~!ea&;U2*8hq;&Uo9I7yWm@+x$w0$R`~FM3>e`;F=? z^mNLCb$gd37}j=O;XIZ7-6oo2t@#_R&St8i!Lq*~31NEw@ih)e0>r7tE#!T{?STTA zPJgZ?xLRp=vEEisQ1Rl-OD%hRe6A~2(z>{nBr91&(&)E?%xTWIW9=)sj*tq2CS{*i z=i53ezxyhkQElh>w+@vr&GDG23}^62;2(2hFXy+AV5N}d7M2dbr z_n;68XZTc^6f;qwpKZ(6H_j;mCih~z`R%F3 z7W(YsN1@wODPXNY!PjkoPSr<}n!;XbS1~Rmg~n0W*Q+Tlp^oEujFxZYExfYeXcl|w z%&uSH`pHfGCDiAHrRW6rAeh=}AC#ICZu*;bro^s*GT;5^H>pUYY z4g`^*R<$S<&u|NchiQTJ+|#mOcWRwaz zA$7n`f)Yyac6drUH+kh6mhR;y`y;^sc5;$SEQKg8da|NG*h=H>Q*#$@o`X^GcZGR` zqpj0hT`Hj4fNzm=Uf;VT*a1Bh0T9hnZ|PkM9h^1^1eDD9dW+HTkEjeXqdXu4!uiGg zBXQ~$Lu!*R{0T+4RNRRK(H}vjI3B$`CfL7aq&&P%LiTGl=@@!bWW8$SY`?bPwx3WR z9^`FM4T0S^e`@nX9Qhv1Mrvz}Jw6EF=SndmiuLIltb$%~#>^$>1yIpGZ^0@@SOi|P?zWWm*YxcebcimeW*wZn@;pYS8}q*cuYP~rf2r6QLEOB7 zLlT6`S&%@X<6}Pf=Rar#GjOIpYKvqRzGQ-eg83yz;NNO~WpU0r^KBy19pGw$3|oX-{ zJkIU9orKiVl2AiP`lv!t`jR8yp`gRhK|+id!;o~x*?5Xzs`J-LMrV-)j8kX*1Lr6k zfv%dPxSZ6~gBx^eFP>B6hQ>XWoxpC9&p30x8k2V^BGZ4%ZvWMhU;fJ@8|5fcwtlp8 zcXw9?D$&(Mu+Clx_IfNis$U~Ma0RS|@KR&b)yHbwlL=7?iRBKCI_cdH?r(TODtT&i z{ne^tWcfa=`qbNs3(WTBa6uhkG&#F&|Fr z4?2=AvWV>0jx!{(^LI1~tG-6ILi^>dd{@Xnu{y)uO})K0P6|d_}N#cdE5OP?%e3m*hClsA?FUo+bZ1C8wZR*{h;ouh*(0$;& z({ww@D0o&9H>+D#Npa4P#~wqj6!#wk;hpYZ0|6UEn?-&&i8^CY3Qo?+*UcvI+c-a_ z-TS!#aqaNR89w*GP&vgVoa%Q|7HslSnk7NlZWg5Tu4_8bQXI6$;~f<%I= zRW!@+g5s!xtEk3$V$9^Z^K&ygL?=5%&QFIDt{1YKd$tphUG0$v(FqU-DYzFKf!1R&iTXu>Vc$B|z|R zts=zj-|!Cx;8L70-2rDQ>-e`#U1zaW&je5ipEyf4d>S_BYC&k#d^E~wvC#cu6CHV; zui-VK^O$wGRn_}2r#CAlBqJdK%b!3F$m!ePca@mgWvk1Q?ELpB5P9d1Ny-X}Hi&yG z_0-m^sKV;pnf~)lbJa^(|2{O48F(+T+2x>4NR_jDKSxz}X^nRwnWV5)qra#B=xL)P z&>$~PGyMa#+*5g3TW);}YGWS~;lCd|>|NoXiNHhE9uLNK=gK32J011CFF&cl((Jrn zf6smo+0cpNEj9LT`Qu++fVUueVD+| zLuL(+!u22b1!#7!JqplB{z4f`i-_OD7r{SF!LV^+gnxl#bYbDsnac|Z#ZMRq`y@Ju z(Co29;Rks9(q<;lXUZUOc+|tsMs~!Cj))C{sfXd-5kjmFdco=n``;e}8@2`Yt`LJt z9yzl3rTZO{Zv1vf7CHEYM?|32*Gg4fTw`lXlBLty=ZT$v&7I!GupQ7PFyp%qp}g#L zLLsFl3}q8Ig^B{$m@xeFM&QXohFD1WD?!gLT@lf6two-3$~_Vhxb-?9UAVBjvzH~* zgfuB!WDi5sZfFb;-n0h{egyXW;*Id+a+5 z$jr`eV|h7(qxb^yu+JCoR~uj6-|oBL?V=Q(7l;T#N%2?=z}DY`hMZqKaqfkJ{qu8n z&cQYI#It=CsDv+r5|n4&GneYx3D;p8h!~`sjn_A|u=E)DpZD<vNkzx1?HImVeP60yJYQI=_ zGiniED7Iid8jO!iB7$H^H#d_lsXc$13=y#ar#dOT>GA$Oz9B;b%ijf*TA$-6*z+Oz zjfAcC@Q{H-_hf%xG7%E*cA043NnB%F*QU>Be{NT8uOmm6pGUxg@^yR@REhNZ<*Yq1 z@}k5EzuQ>;zAUujRHtEW0%)J|OPWUAtKv(;96jz9`w*CgLrP~hNXdTHX&qQ#89{qW zR@++qnj_-Vzl;^l-Cv9>o)Q`=+FiGImg9s<|8QMIv=0-1b-#KkS1ZCVQwoC-FEJEe zby9h3?Pal)jQ!`)$4M&acXVKFy&QHT)2@>>q>7fZ_+5=dS@q@!;`$LFH|!zm*OL10 zRTE&Yw|->oRhXF+8D5xFpMAo;g+S+|^%1I1^Ir>%jxuY$K=`INk|+S%Fu&k7MpG3x zu;(IZ_}Jc7V`iQ5AT4=K7Uy7a`}&%cSKq-=i7Ahe_y_8or&qd#mplDYZys&WXha*i zP+3%XqZn%BwF`cdb;&28ftPung_6oHZ8`!g{QsC?U;Hk&23nymKU|VI`3@NgwQcMK zIzlrEy9UXjQ1*2|vQN|djkgFmYlkZsSIg&#o0IDro-__W3ijX~X#G$AGHt40arATDw4|xnFXTrOA(} zW*@d9@Vm+`GwfziD0JHBL)`A%+$E1*N2r=YIcRZa;CnQreT>hWG!ClC&hg@}FHp@P z8H@+^+=)?u@8*;fJ}?kJooh|4jVY00Sn{Pu$y1{dE8bbQZxFH@HyeP-tZuDT<4A{< z!DDaZqyS){M+y@6{`KB<_7VY+hX zD>+zb9yR=$(?f8OVXJ(@%5;P^K834eP3@Yu;>KAV zE^Oj_v1P%*fM)LhP$~up+~ErjSsXQ*_;PkN(bqEd%X7=G1A-Q9B^%MgFz6sk6Jnb- zNVR?_a`amJAj9wtCG#2v#W3Zd@u|8=?fakkmo4~tPoeaCJG;F*r7_F zu8l>ED=dIr51YW6#hUfb)t-~S>tA%xx^v7a7zj%Km`-B4z_x4yqL|_QD1Ph`y0K-sFtoS8Nh!7G)`T&{L#|A1Y z%NzoMo7n^&yGL3}wmR37$4X1p`c2;btK5b@ZW-Xs&rqd+=3N%Z zZy?CF{92x?Ib(BzoKUZXOQUU6uzQuWp}|>GTo+5(($_b0@vouwhT;XW;oRjI>^IZL_}-h4p}Q)a+v1GH&1|JSwt%b=`BZqF3Q*d+ou;+%&u z#461igWpebP%j73Q(C`YlY$HtqDd>PD!b$ zsit+JSG3XeW34^ikoptS8V-sC)s8?u{dRrZJ;8Z$`S355ow#Q6Kiu36c!k)SK;G3B z?6MH~USINj;8b?$6o&hHr^6uEJZ)8R!_N7i^7qc8==f&)O_%M2^~h+=Ng_OrvpqhZ zYoYvUos+uPa$cUgN2j?v-)D^BT>jDvA}!4&sXtEeTadHr6KZtLV_L3Q%m_G6pM4k$ zosY~82F|^Gj|MXzF6?1IFz**?r@PZk0Nz{NPa(`d$?VNbfWT=9L%-`g!49Z39!6q) z)Zt^065IBXfYM)0%F$LRJvzIe54HEDtXj3}-*ab@@vM)`N^1z$1H1H*1Ky{@bWUuS zPV1%RDp(nQn|*rUU8~|bUGMTmjQCP_a;VQnn-;PyMMwaH5j?A(XwvxvZsB2SH+#VX z!(1MgB(B~tApUXfXueo)v$?;UC{J~VI~x&%G2Wj?fF(C=bkZ z)ZBa{pw-GYt0N%5w7l=)t!<#wFO?gx2L$YmL#kk?rZ|lJd>eOO4!#zc$y3-@U$_1S z2sw)AHXjOU+_2~(RW=ap6B%xmvqXKq?t~At%zNfe$zd^7mFOINe7xx1_q}$<*QMEJ z-+6m^q4HN5*uDDU0*x8ONlG3*_>?t)=MXa9jS9aN-StL491``xfgVnNGUzbh&>zTZ z%E_0kN2%uV{zi3>-L2ryq(bn&OFLwH5AgGkK`qr0uEUBDX8;#L{$f1k90vwnRB`;9GvD}g^tI_|Aa*ImJ#bEkq=L-;Lz?bN*-x~ zC@jBbHrA|gODuS18YuJxZn|kW(}-K>72&~F7-iTQ$>H4maQ_{9qZ-lHcs= z;RP9IVTQQf-XL1NZ+g)V$s;hJTO}jCkAeNhocsH#YN{+}dM2E*)?SR93XRN0{jc5M219_VNbnSgR3RHKv`K_kf5Sp6f?q^3^Qa-^`Oc=^^K0#zzrGUxH`+?z)nc|txEnP|A zsl>>BSl{0dfxn0V1nmiXZ{3I$^=(9d3H@S5x8IyJ?izZHl^K(RLkd^;Ff1XktYO^Z zjSWG;V6}#Z2IXgyV)37QN{m3&9_^BV3Wkx5aOj`{RXV9~X|+B7I#oXuqaM@QvgfN; zwK$?Tzgv>zYs+ogG0Z}oF;tPGALo`F3hjZ zjF0sb9{atcPU4;*B!Vnd_+Z~t)W})1_LAiMO0=X?6N}0%$dbAV$QF- zzK0Xp+7Vw;2AKRMEwY2s_oLDPbBsnrnVc=+?JQ-?#UQW`(7Z?U3{i680a3@}3OOyE_EuwElFr~z-IuX!ti>W8y? z&0GFT8ZB;%kSMw}asX|~d3xSoA1Jz6j5y3DVp^7(Fk>cO!p}cT37aJ_eILyZwcur5 zqd6Mt8PXcsKxac6Ce90&-9gcD-mp_}&)hsFcon^Y%6vQ+eyGK`yz~oBd@)AiYt{Rr zTYM(j>p__S7}=mlY3zL6Xg%*L+$!kw@ey+hiLX`KpPs5vR@NSfm?{(8N)v82UNoybokMj%YWWyWzm1DJcVDgaq~ag=pZcs7P6d zMn`+A3Y^O@N!j3qd<|qa;Ec25*>p^%ug(GT||la`T3bkLLy;wedd1=s+?@vJD$tF&iU|^GO{wV zbA1+~qhsvoG?VALM-QH8o7!Rh8-l85N{tt|I@@zdS(4qnjfJR&FOV-5K4alc?30+GtxdF^5Sx!IO&uR*k!J7O(XSF1Wrmy zENG=_rQ*rV#Zjd`V|`TH=lWH}#?KASXyvBj`V2Qq4>$iS?il7rSZXd<*{9+Iexx#< z*8J+%?CfmRdt6lxREIeleyg8CbjnKS+dyEdV9~{%>n)BH2(kT>DvI?d*;&;w;`Sl) zuMIal&7G|tKM`ogKUG_kND)6^vI9)#i*M2o%!C()2FlCUZOF_}GuEvbj6B`^tgNg| zziF^0PVPksGtt2>VVU?pM(0|v9s&mmw7@?su^qTWXQ|Y;Ba+nt;$_K_$KdP2y9Vdz zXzLDXX+trEbVAdDpYJtimFI;m&cF`ItUyO19~YsYowO|6Wb@J!jPN6ePFSr-Vy&y= zA<_wGXO&$xDG*(nbLYy;`Tn}40g_a;T(X94>LEy`jp?$r|D^Fo1%IoU)V5AoPL&ns;O`;Xkg$a$ur;6 zYDAkc?})lED-j;wJKcp;L~gXuj*aAO0!wrU@tT6a72qfHD5s|_akH^cFs9t1Lo_hL5CykwDubk;qV`4BO%EjGsXtt?rKdws^aH1O3e=pw6IY7-hG+cFIuin&9~%;p=6a0O*at+oWE6jp74&0; zjD`^JUP+Vv!Ly6??HMr(E_O!4&xJy;vatyUK&8pc%LnlXVaxEa)b2IUg(eRzFA@%_ubMfi%;RWCKyCPf=fb?Za61ILnaD6{a^t?X7OZqbd>Ix_+fdL8RXsh zNF-_^gWni?*qZWigFskJ2oqLKJjfz8V1>tf$?$GRi6DC+nK zYt@5A$yxr>3{8hNB})F#wsw@o+P+pvUOq(1D%5ovhL%5)q~}!H)$!-mV|OjE&iE+l zD~ecEwPpg`F%o}kN>#Dzygs>;!qxf?E2hl@twhQVuJl4rE1J92W@T@oD;yCwrs@oh zvea({Gi9k??2gJ(XK?k^x(KouZcX!h>B77sOz;ZP=JOgF`k889_4IO5bhtkQ=XF%p zRJS-q^T8b9+4WIb+1V$RSR=^Dk<(;h-fP6N93lq~4n_#Lmvmj^Aeei)D*Hi93(zx(sCHCiYtxEUjc#TpcDbpKw6=QuNV*|Pf_$s4-;I-r%&oG? zvhFAV2UP5z?t-#p*#_$y>jMOgY3wKBB~nLNYEJU@f+|8+dei=rHi}ZRREQK&pP
      W~rR-xQ?_`F?8g)jKvh@yIj(}jn7uNu7se$UQOU0MAC zUqiOmDd})8t1FZ5N3X~S zf49aaDgu|dc)1AK%CM0jP-*N<^O9MrE2bNPIbC2yPSR?e$S7AWo0u(-(8!osRAEV1 zcS&as!Q`R8*9vkL#w$nuBT7j@JPIpYTW4ApPN|x@pWvl5*?SMo-hzHUrtobxzSZuJ z#A7JD#Qk5L2)5LS1CbJ41+*Yzf69La~CejwVYO*LCr{xE!!AZNSQ~|?{Ba2x` zHlgu6hU#q1af}l-Lvn=a&dTD@yI8VVmem6C7jp#eyk1FlSciR8iev%ySVe9n{F~(|#JqG^)fkY%7e|gg0 z3LZ)$5jAQ35py(R9_=mFsTPc92e6GpK7{&O-y+#+CARrV0pTM#a!N|v4X&NpIl9Xt z;}@j_&`ZZADR<+kt}}A&ej*@RE8|1&(A^poZPe&%wUUvH3J*lx`~7|5JR_Hq-P(Or z;wu&f>X*BEVR~?E`*)TUV;qHt+ZIxxeCj=?eeIwhQEc1_zWUEU6(@Of;5YTo(3^Za zHn+OwxJ&{#=qp{i>kUr=3`B*B!v)jbTyNnq@8`Yr#O&M0NDz>J>AMi>X!ksdqrwmh zXSiU*gK#ErPQ+lRsyk1Kl2o_82#gtXWGGXSw*W-nGd78Qmx}m^V?hHF?ZZC|X2d~s z7zcS{tMN-dg%!uSYru72a!K1=!#%_`-<=19QTznQ>r-e)q`ARDNL+EN<-LF8&Xes; z*K!lj%>&{;_4KRr-WNW&5u^VohbfN0!72NxyQa|U(*g0qh&hLLfn-WyVoj2+9(@tQ z@9705nuWTOL}db~qo<08PdlpN3{gh5Uhmx^jiGu&#zJcp11i@`;M!})>Lght8OlwY+}j(!CG(B zS-Nr4X088)f=SH4AX(hJAJ+O0?&MHjY}BT7JBN!6wW#*&#dbqTp{9eya2e#i29kKb>{k~&_*0Q5gDO2CgAq!N)w`hu8}pgl@V8faDu<@JF%eP*0c`)xV5vL z(6R1hrk)&2CMmg1Tj^uD#b(yuK|9I1d(zpzW%DscGy zDX_8i?Z-;q)D4q!`AodLC8UZ`25h;_v9@H5jp~%3JMZ-wz|8)A(0URStMGLZN?lM5 z0%`*`Drzm!mxS?1k%v-Qe(x|kOi~wM=bG`;IvD&y#)BOFBQpt-Vz$k`Cfld)B9wGr zQ-&pN%OGl361$FS|GRZb5Mm2xWj~J#U6e9x+f(-ZAR<;@ntCgd9f3iYDqEcDv4s|W zKklvk`civSvPN!Wdp%-`@)gg?xPiXRq0o!9`|=zCcCEsz&%@b1>!hpu+&#+Ps`O@& z{xQq95a|&^VfIkLk&m5M-NgG~`Ju6@qY15sbPh=x_XDpec}ok=PCEoN@m9mR{StU2 zAGaFfG8cdV<*v|aZR|M8-kd+VPk>0O1)b%BsT4{SlxBr8LDy7>e;9H{U&Rdu^%9W* z(Eh5fJw6Q)Kt$J&HNrU~LG8%j>vvw++C(Ma=vROD?GZA=)6W)onY=>$3%K656HAR7 zPUo)5fmJtqt)xES0x?@P)V6ZQ$*Wn2X3==6X?k>XWbbnpv>j-&ESXSPTw*3cb zn+f;spGx%XMxvrX3=b%0&d0oPjnh-AC`r11BO~qTT!Sm3>pCARWntuhC-96)p5#uQ zO*h8F2%w<|_1@HlZxoH53;_dZs=B==i(N=NeYBJ4Y+GF?#*{X@6|H3s3t5PGV}#lc z)p$@kgI1GNvB2eoo9x_~C(d7I`Ysi{C}ukzCEUtS#p+782afiQ9K6}|pjL3xsN8r^ zr${^*G9*az$)mWuUl%YJZ4A+W3@Evv?E@)1pCjx{eFe3XNUfY2+dXuhlY`56fd@Ss z#*W#lxqmRboA=2=x3dZvWh3)T>lb<2*8adCh$%aQiz*>#!p6-uqS*(%=C(h%yA|z- zDXQ}xYa46tK}t9)b8y}c`GE?R?fRd=}<$0T_r!AaWZar;u^{j2-ZoX+!6B-q%A zcbVdmaAUj+BvIJ;dkgybwCSip2l>ncTzPQQ(V z9QRUnbOU=p7QO%p7fWj;=K#$$W?cIwpo)ISk?;J;zOxE%5j~I8x3&5qZlTa!$y-Z) z#{yWto{H()c%**~BP~~j=A^u^?gFTQ@nl5$!S<6UoD*4L@bs114f@fHT9|ocKJr5c z>*hjpw2W2Z%+Pa0DS5e&fSGSgV;s#76I0v5rE>nY!?Q)yz8U%-dXVyb-oYQR|LaSW zT1)g3owOM*S)HZbXWWRz88TWHZ{O~Da(+9ns5BF>%e}$Z1yx@$>b-5JPW4hN`l}yo zCBqlov8NU)pYeF{?sE95%|CoWf zf3vAeG7n>qAFGO}3;M<-^rTD>mMG+4nnni?vK5OeZ`u(mp7tY`#?V~%-uW42OloXy z9+qoCdq8TP9)sw+?A(xwk>9ZyqjZ#DwXi-(<ntL}mK)suB_*9Z*R1>aH+T3%9cUZENdY_R z82VJh2gjU_!~gE$o*6W7JW(+mK$gr#;o{7I*IV)}vctn!leUn*o6__&c=#Klt?ak( z0ow4i>S;aSAi0}NL$YAU$@zEP%Mq(NHrW8Q=A0mfO>Qjz(%OE&(v|kvAoOY!g+1Ti z5~>A-?0$TNXmWdYL`H-K&sg2O_hCZ`=HyHVz=;Jv0yNpi4zLr1kYdK{Udy+! z4E{1hg*yPW(FKGFIeTGAtK(<ow8~=V zDxQ{_I$-~p$oCBcR=qW-2PbK<-CqHt`+;f)dud5uR<{ftTlAb zLzub7dc*E|95E;PTdd5?L2v*>Vj5UuJ)SuCWGB>B(BJk7c>Ttr?>Z{ys9^w}sAWAVPk7r;2C785qGIsbnLw6~P22Ur&R^XuCOngqAq0F~rthD1{mlr4 z+NF(u9kluY>N)6k8xB^s@I!vs=&7}naP~a>ue{$ZnYXW!i3=A10+D;tB(hx&*22Vgq)R3;0#qT|-z zMz48gf<#s$l#s1}D4(vMUuIM`XQ$aJzgwl8qAhfSt@l*8QT3Pn`uU{dZ3*FxS_2FE zLD#k9N0td=6C%OeM3@U91%hq9nlHt+_9_D_cx8!pw;|z*!f9rD!hC%$x6G*m$q4%* z=$j5X;hld+1f8^gzxWIyMX&;nZOJQQMKQNwM(Ptd0Nvy>1LE%bit8ItbtmMt=H})Q zm7ds#Oo^DI<`*bKAhojz1uF$bhn#M_Hhjr2Ao_Y}ELjvbg{x@b6iK@)9b)`CmH7)1 z6D**^f(!aJElP|NI?kJ-tPZQrb<_PYuSKk>ltbKcI|rk0xwbgDU#3oidZmd!$g7(^@#kpUr%&t`5MeV> z#WjIbr8-=%UjTt7=(Ugv+EMnVF3XjGTq zaEl^A%!Ldjq~|gn5DM_Xel%UzrjU?y$KPm{aXV@mxIiJUZ~kH;A$3~{6udSzCnS-j zv0?*}wU)tOE;{hHmZ=P;XyWIGM!wjSsp{zHrr}yTZQllGk>_o5QHP={pfK4SxNWhm zo132GFHt^o^3^HzwPr1w%uA+xlR%@2{te>?OB{2WX$;{KZ$MJ3wb4<335)m7gPxvV z`Uv0WWR3M3NHbtW<{{2Dr%W!&x3s`8e`Q;;$ncj4q%euCPvb{NWE1y-Z~j?q{pgWQ zj^AMnzrFa!8A}ZMZU_^Ls2d52ZVLY`7OBAmh$gVjYPbS>M22AaS@={ZUHe% zJP#2qF;lKUAYHYIX2QP;+K<%iBGU~Ux>A$Zo(ndL>aepY+CF*4I;`l1zJz_Cw?PUE zLfpc&b~t=FQqwBIBTmrMkB1!NM4&EfCWYZ&Lg*jvf7@3(j>j%CF5bq-(Gf8l0|MPm z3bvi~d+87rZ1v}KO*PHT7#E9Um?j4CEh$?soNWUwKQj${J(ymd^AhT^1Y<^Yr7zqV z1%YQ|1{V9Izq}i5*+616E*r~CkbJgq?J1O}*&4)>;ouNV-C_MLSrrg-UpqHM4yMF2wmN^LoKUi4jwz=m@66wCFO>&cfVL=s1 zdLmV}Sn&Dr%GFgAzrVsCOsfe=%ygx@{fvVNx zlzUR{m)WH;HgPH6ApnVwRS}bHU_qS5x0@6jWrK|#q(Y7rDTArug}K4CL1}G?vmhal z1thSla?30#+{p0!IIZTx>T?GoT0wzzQ!E4v?8lw={mA)mBH13ZS=Cm(kno|>o(WJdmWf* zN4tpTF9XyXxiv6ZSC-cnSV81>C071LYhgl3+r}UbuQ5E=ab?<4KS(Fc3<_-qFCnG> z)?mP8KC?QJbz5!zmfikK@E8^jAslWGJ;{PL29?U0u}1rsyOD#NyQ70+ci!R%{oG0a z?F|dSGXOC{99!AOzQRlQ$b&#W((5I4kz6ZbN$d;_N!lL7ZCYmF-1c*YF`m`qC+UQ- zG?CWKLqW*5QrAME_!P&cyA<;_5^|6Cg1GzJlW&=UJB%}bSUU4Qa^r2SWhx94hW^%g zs3S@@b@w0w!M~yPwQ|hPVS!Q;)TTMIme`ZSvnPfo_M4Ornv<@9mfdV%7`t>rg7AJF zy&U>Px?+>Qvr`u0W1x0lURM@dXt$oi(a!BG6Uu8X@pny3BK;Cog0`IJ=;$rxaa3_p z(9#xGJ@;u&D(Qw!goo4CPlmJR&ic|cf8w2!MxzP=zWFKKE{b*`FY&QbnkE0QZTF_QuRH)8V4wfU8dRQI9p7vXm! zXSiy5s)o(+b*q|>YrpZ(TOkBE#dZQMyVjVPkIpQ}AcXy>eQ2}bVJ3?lkc+Owg2~@> zU)lD-9?ZDd$z6XGFjZoL9pOhAH4T-nGlSpRe?_2Ue1uWI1l z=duz#3^{I$`Mq+-Qef)n>uyriQ8Sx2wZsSuhM|Qp2hjGos(0Hv+S`G07oROZFE5ug zIUP;&LGJL${<~##gRe6LyqX$|9=X%}binhX8xyTW&d_=0Y&HhH=G~TRr@XwggZ(KL zq4K|{g2#{%zy z*OK(=&ez@kxBE*PnG0+KhHFQJULIpI+Lo2)k<<%xA1eMqR{(NN@{=h0^ z!+b+*V}D4v#`5Tn@wtOVR`^jF>-|@A({yfXt4pz9T=k4`Cw)Z{B4XVT^+;OR_=J7S z@lx(u3UfUbSX+#a{kXr-f379>-I=BvfA^O#>aYS9Hol#;%kdJUT020vpp(|&La&!O zr^E!)2tsv2d$WMwOm2W5zgt10qa+9JwX2@Jbo}-q0-OmUFCn%BxEjj~8_KHKU_a{` z1s^^?>E&x&q9tX8h=$x-tK@7AyNOnmFExVnx3>Nq;H;dyoE$2}iGpsm0tnj#ea~+j z**u@(m)v)Ti!y1$9kHGQ`525KG940|Xg$S@^dZ#`~?LO zy)$3aKiIr%Ryd0a!Cl6XJ@Q9`{mH zz_jQ0d9sE$R(}+JP3GO=FFi-U=3lO)>wVhOS~QmM9iT)4%F_Mvt>@7~C zPN2av=1${^mgix|rK0vSH|b3vTTmB#2n_N2%?IpMJ;rtb#G z+zybP2EiBELIov-ICPPp#ifOptDe(Do_Ictb}M$A(kD9005d)AJ<1H(>c#5zT`dGz zH?1wXYiGfZKRS2Ary&J@3^@SMpQ~`;6>TuGyd`NGV`7trD)vb0eplTx2L~3o@n~?< zdNSBHqmJ27ct7yQy+C<`VbkmW-1B0pT4X51o9R({oHJMPtsc@m)VK4}gq;y(d2N5} zV;k%>^R)To({+&IZf9pg^7&QB+|7D)2a;_jcA3vnI|>?|RnEr501l=uw9F4Z5ZMfq z&1-{NX}sjsOW=U{LN1bTDKBTMjv+>4P@|}6yer;^PSQ%;jq8NoU`|Bdb8&Hz6|npi z;U^+~T32^BH#Y*r)zP&;G0eFqB~!fuQ`gpo=WtRJxf9}JTp0N#0QvMAFCoD?gjD2d zdHQ8H!_Z&}x{NMHUYT&t*6Y{%&aIbuSBsN_{=|ZvcCGc=*>^K8497742uIhcJ1BOx zwc5k4%L|{`#EP3oIRHNq7;M`wewtfqX{c#wX}BcBR<-Z4G>($@w?=^bn+kdIfBQ}| z(7YJHGAu5IQ+%BKnUSQ0mCg>x$ZCt3B^lz;S8jHSsg%@3hiDk>e3=KmQXqc)5)OZE zL|lcjRzO8co;(R;r;0&MBxt0kp|Ef}<7R)>6vnjljIn zD&xGA=I=Jka7kTp5)p8yH86GF=QY=(Lx?-Xl+bJb0^mwQu};)*B}3phLeeY^L^o&( zs2qMCU8grJ7hHf{Wp_6P`GQ%PM7w2P6d_1SeZVrmy%k)f!}iU`vS=~ArcTEq$Qj=E z)8WhhwQQQ^&M+1n6fpSq^0C*z8hF3FPoO~=yw`L2aLRmJ&IY*jgy6?wTWr_Oa--Xo z1Yi5vfGyFsbu)@L5{Zw3Z)(u&V6ifb<4 z*IX1){}|vhmZ!dq`3=#E8!(CkgfLSe5@I4kE%oY}COI{e2H_qYjt=BMcEvvYYU26C z#Plim=+}=fmOC&Ey-P5ZPH^?o53kFgyGmJk>pFjQ)5s_ zqx7i;hSJsb_BV}C25NP$*{r!_`!-!cebbLZ_@#|?^zZC@augRQHUQSDO2qW&5x53< zB{a8UYpBuet5=h`>ddS2ziCq4z9BmS;-n%H>QeyA@R8N&~JSUd=G^6SYVJ=VBldqYVXomn=EOne{PDIT0l+ z6h<%~x3Zyzfq^Clon0D3AxRH*Kt`b~23l-z5+wXKHBCqT*XU?vJ%A%rM1)#y z767dp1eCBm5uKAg7t({fwIWr{R()vQeM1ICStr#52DX~PS$OYE2s8~d*kob#pmc{e2| zT7CyYW}L#pc9&{VLH+zejOOd*(=3TL`h}kcOufD&#%FU zJlO)+zMU;i7@y!j{VMBnH4S5BpWMq(pO1$#?xKkoEld6L2QM`?ciK@BqG34r%;xU4 zz#Xq3&qYm={$ z?usK6R1zY8HbhhU!NsjkrTgRJvFhiX~lM79>m+BB)Zg(5?~I(XiuGmU4+ogwN&T zm`0%1f_M<#ZzEi+@hpi2%{p|$qSR&*oY&@C|7q9dp3B5 zaR*DL)xdwKm<*XT=MpM`;vO~~onQW`j&5llkD%fX6U63$ao=2M_5V0~$MDRWt!uP9 zM#r{o+v(U&IyO4CJMP%FeaE(K+qRvYd++`3=l#C(dJ!SZiZj#Mw!kh-Nm{Tr6_=aCM?=75| z04Ig~cZ^5c9D-U&cWXutC_Nil0Z9qxPu2r@Y$?pmqr_RGOz{zs)VFgj>Fw-1y#1rB zS3wX$58u69Ve7p91@5K<*8B`FwlndY3;sDsvhXZlkD}iVT-Y~&wER!1G}vZKLkx*s zD?hBlOX5?3VTfEf1&WaA#_txnk{n1ev52X{{hK5|-mLpb@E-7@TXnlYKJ6l4p%B-< zLjw^2{NmDba`movok)pUI`YGoWM)kY{Z8Q-Is%Cc&*AN=l%b%4CrMD47}-NR)mIGk zF(b+|iZkqs@DmfV-Nl!%fnVF+d<+?847Wsw-uSgOM4mobG>A7`!tCOVLt=;5UEXke zaLGM8HOpS?IL1B4b>A-0!^ghUHw_=b1ckQ;U7?HS**=Hgfe^_L@7-cfAA{j;5+{`fZEC2?KWK;svsXnI>9SA(i6&x`7 zWcV}-iTRfLVv@>!fTP>elE-YN- z_SAJY$e-RosIsCg%swrBj>53I(lGJT$G}gRR8%}P6C>-nPIH*Tt~2C z583xco1Fkf#q+zYbc*v&2YxV$;_=1j} ziT*o+iFWuf^srZgJsCOKa;pcpXo1Q6eKDI{A?T82#%M{lOclahym8m^_*#-y1u`p6)q9Q`8>+4Fa%1yS+g!bJJiDSsN`MuOIa&LkM#>@a_NOsD^ zgu;U5=q-2MV>#2n%(HN-hmF&raLiG*H7!e zZWSkzyZeFr3y#2Zt?*X2){M!E6h}bqpXeI?(f}U_x|SF5Z>V;rmfBj~dhq6AagHCp z287|rb^AAd_SB#&1+XusTL02PD)_R#)^M5;jQb!1rN~bBx~`Bv-aZchG)BJtShxb4 z-VE%8^hEnq%88Pl-&$BM-A`YiCg;aGQ3thjxqUvKV&ln{&mtmE?Q~tfkaOQqA!v=y zbsdz&^on>w1m&wADPx`I%+=j*S^WI*| zs^qehCd+L3H;tjoTaEgk!ObK3O6`oWH*5?B-8||w3GQ4Xq>~8~`s|~;gV-Xm?KM0rX3Sdzrb=^V7gpr>?ek^As9% zsuw*RB}O182!3KvbH;pCm&x4<@gV85X8TK5jhh#D{OGn_YWvTe9A6YA4AI}4{(r}i z>`Sh%h+TJVyEi`veXH5#qW_TOAm4)cJGo>(Sd@?uZZ!(~0oB_AS@Wem@!plwgInS< zSroz^Xcz$$Pzi=B+73Ud77>^M0<<}zKz=lIhp5mG;uW>m{_j|PE{?r=Ac8eMK);|Q z=?{6R?I+Nt8$O4T9%5?Wdp*z1E_ffZ!H2c)9)xwqotH}(cz)t2Mh?+Bn1+$PVUjI$oSwUVYP-<}@U=_Nnoj(f_a=*S4n8AHJcN2$0%>Mxn25=AF!Hy zd1_%Vce0+vVkYn7L;S3}#~QK{PoQs7Ju_V%%{@~7x7q8b<3}gWbsZ+3Sp+^v7ci^KaAWdUhna_^3nD_gK^UT=$0QPEHnqsuW{*Fz}?+oHH_ zxN{u#cgegV@tl*_=(EQl6AxTw-RpI|J{#_AtvTRrEwBylg3qv-0T+#wXSnpjT`e-* z@^`_G7fxts3>m5_D)US=(6;C?#|59e!)-~cFvUArdG9qejjp$0Vo6_85zn!>+F=_9 zEZM%buYC-zG$}fr3*4N#xaIjC?nhLz;_?B&lVixDZG0VLqpy5_RS( z0|N!ZZB^^m<7it}15&8_9@;o~dD6xHR+eL-h(e)$ob6=)Ew8DX>H&ESP_FKaUAI(FI3 z`cYbNQgE;sw!_d=Hh-roA2Sfz&9kI~eqwqb6n6i&^0veZqI?R{r5;REkE`jlPL-fy zlgzfvtIqw81Yv?$h}M}@q>(obg>SuY0iDd*iz@YKGJ{2%=Q{l`(6MVk($%dfOw{FmwmsUjD&$v0Jm%TaTS!dD|yATLC@5DHtAO?)>PW(t53SK!T zI#3lHwQ^_SNq*K>t_62+)rmuxC)W}j;#ooakb!8)zex%zJw>bkQ{pMn-QsygS>Zp`k>wt6&5CS*-NmQ3acyHk>@E*rm|9ux&p7G zwG&7b$kP$KPsnES|37{)a?z#Vh=rayltLVvE!+@ zc47ylXQm%ZI@>R)aeK=M$;rvRJiCDRr5gkd`&gN4DkxmTseX=HQis97h(Bg1cJ0RS z%ZSK%J@R|J-YRmju{cW5bX|=-NM#K-oALOKBV1!mqOfxHR-6YRlD_$Nro6HQ8{xVREfF|A08g>IgRD zLASJHZR97WpFgMelNw{WwB#*vn{EeC93)h;_&g*PCCBoc-4jGinhIKuExmmN=LQuu zHGl40A8s5yu)f1U7L^ghMG?Gj_pxQ$uJ{hjFgAwvQeF!<1DWD~dV8|vUt7-V8x^$` z17I{nbanA9cj7v?CbZv4(YQjN6$javMes{yqaEF*F~+@-YlES8htqR4M^D-`-VV2O z(DDa%_SR}`PCH#7X5l9rjdfY3-+yT|thmlU zC&{~Xq}W?`Io0%IcKcpU4?@IXJ&(}d5 z92Y#57%_UY8>^|F;%ABRpFw*uF7^B*JtN;55_|30P^y*_gs?qrs@ZzyWi*ja6;;I- z<_GSF&pZJT82sbSl>Ms(z^v@O5PHgCn$tBb$}B~d<-!o$fw7!>lecFa%4}|Ggoz(v zIXP!2DI1`5-vTlWK2GSJ(LjM3*s?DuFmFqL;Hq>ST|3K2TrcNeyw4UXLxA{nCeB`9 z;>;k9l!v84PJYN_Sr&^tZcYv7dD>bsE1feaGXxdk=waOkV{Qp1mWbA|VGMhx2kNX8 zDv*e#?+V&ibdar!5djGZpiRm!J~}@^iOWz}#8YKL{>6oj&|Ypx+UbP}&;#mFpZ&6% z=#!-nxnsM79LUu7Ey9syV72^J2pl*M@>|g+#|i7(aWGC$mmdUm98{MdoUS4sQewz9|g5 zXK)UNGk5K%VXV)#m?^~i!BhNSAM<+I9*;rlThDiDM-{m}RNA_KGIzLHw&=-2)$wwR zY+P9>E1x_?on3yWlw~!9xejjcg&65;j{xK_T-^>}180eFOtfb#F}!=3ft-I3wZ9{! z_g1WJM)0-+ZddXH%XrGBE^jB#t*>b09aS~n&ciVDyiN|1zutGl89ujGmDhB_|Jb+u z=7lpZGLC?CtjrmE3ag#kI8Q37Jx6U*=0D*VNBihDpp!>bF6UI_EL_i{@ zvH5hGO0?pTDpJ@u1S)`r@d&sdf)5`|`HDHX8(gUd49nf0Fz1A8{Yxdrm}@A-#&`*g zs2JH_9c{w^a3CGcdkG9FH?6+U-n~`S0Wr6VTuOGOd>xug2=9^yY6IORv|~83*FY3d z8?x@Cm=-K+dz9UWK81HQ^@zJRJG?!Y2rs{<-0(#Gmi^=+6TYVWHY4G2t?FhES*e@h z-(}2FAe&`za}qf+=ihcsVaLV9Wb6FXa)?$SA-=g?iYi6hU;|^yuB-c2@sz(R>7cuN zQ>=^Iq`7DF;~kF<@@mq>WJpH)d1>uKUqi^po1JJs8oJW!&C~f4?^o{_L&rO^L&tq` z6Tfb0s?LfsrF5PssAN_eq|0UOTqs^r91N9DhJDKwpREOsw=H5R2%}2jn2&8&&hR2+ zxO%h>P=ZLKr#zS)hAt)`gR$r#G>jmMZ8dqPyg|LOo#BF6rEQG}2`r^#_)c-{{WC4U zv-wfccmczWpJ?jjT6(JMcJ|Kv``6V(w3@kbVq);inbxT`4E4{=f}bd`e+)mM_R3_N z0e7+Q53O9&Qmm?~+r>4PEr|>r&&;eoh;K)#kOHnH!t9CYpg(xh%$nXB)Zx{(d}*ac>5dlIrJrerv`8HCkU5Qj^y#s>Pyvwu=euJEC(-Yy!$vbgQ)1CX8;F| z^~7=qD1U+<&M#m$q+jLt(J)S4!&;K>F_q8H&u<`$FevoRw>=ZF@ZocXzm zZ8~O_m{{ejv0j5~%$@(tEj#I3DG-s}cMfGBbJ~qiHMVEiUE5bX zm>T@7bI10FAL@EvD9ps)KW~%OvlOG`Mk8VBYC62;d3-N>R@!pVMw@fm^>L{NfLV(n zw^9M#9qv0xW+v7Tv*ZWLOG;*|AoN++VbteoySL5Sfh+!$Lpj8ngFzWDXGc{=h~Z{X zv9U2L2`47GUE&0%u8j<$te4!b@o|5M{Z&qv#fY(Rrp?-HiT(rm^4tZvnrf%F?sTW zFr^5lYJrWe&Y&lcsbzfgJnoAsYJTjd4Ihn%ej8X}`!e7PFy}6ZB!5zND+~^S_h=3| zK)A+vtFtL-Z<%RwD~X&_JwN;1I!K+9DSo&pZfTjOd))!_o}ah}{vk3;rGT&L4jG1p zVxT<{Ey^bQW5%M167Tl#zA7CG{xP@x%^pkzrjzjJ+4f3!r$LZ+ynil%dpRQ9DQ^d? zzjc4B7lGr;!tLQf0%UPGuUAqF=DsBY8itjs$=ElRXb0wO?Gqc!%OczD%c@;X5wvdY zkc@r8wyI;?+|K=^(3;Vax*b$6z0V0CNa^S|$XW7SuJ{e*UYvJ1qJJzzFd~@1$@e`i zZamwfI?7GSneOgs-T-3jZ^W;hHOxv!eX{7estwFmRKij{bk1-(?rX=L;D5){ZKNHT z9O~_a$-cIshoyz|wV~>)p=Ue}L7lVx9a6?E`e$zKA`zNi3S6DyL(-7>e!Jq;0Je!I z`Dz#!q|LUd3&pXL&0DXF0BNUG%Gu<#_aW{jB>LLNFT-O~*ysU#9MTpN*Gn5!rWm*? z%k0`%q+jdgAKPILOh1KcB1CgJfDVm~CyB)Z0^sUhadgEWCvWCE#^n53KCw^uMZSBWte!f_ zC*7$Ntc0km!H0tx^Hw+DFaFbd@Y? zD+2%kE~AJ>#62!sSk@mnHO-LL(BRih(=UxXKF(GGS4tzw7FwC}J6w;*d)Sz%C0*su zqv&hH9(F;oEM8j7RhJt_@!HX}{U6=X!%FBi5%zvH%?T=PA7-+EU=Wl)L<#a`2#c-z zrx@gKaG~Zoj2FQdMVU)u5{`2TgPa&F%4EM1>|gLyYrC*hIf!F_2;ENz8k^(~k1j7t z>&b5Q^~~lv9p*Mw>*u7%ImRk?oZ@Qo|5d>%T-CK6nxR2AQ0TsCc5L zi6Qz}S(IauJ_kwwHt@~rTSI4Qg}LD+-o~f?JJJldm66W=ChxwQ-1j1ioG54GEoMHa zS5rK9yGF8w6|qM~6IQ53AYuSKvvpVB0mpp=5pzkV^=;;EaFFBAAE8dcQ{j76oeo>m zXn7z>`$J^%(CQiW#e98LY7#zYz$~exu{lnyTcG{-0pTesbQtWb7ES4ZxMP7=pqA0G zLwUUc;!?`7&*MUe*vN(sioha<>08;=izSXZW$9p?#GDDozMRD<4+x)Fg%A~#Qiq|n zD~XkU#v)4D+ola&bi(@gR2$|s`>7$Vy^LTTwx6$U5G6OtnCeSz&UtmYx9n&u^|+Iy zpai*f5B16#_9Tk^#7My`vQJ%2Ta+cwM1wyoWp3-{`K^%G`T`(iF8;RUGWZ%te`e}F zj;k~t1%hG?5Q9WqtzkjcL zUUfX#>}{?s<2T*7c_f++vd4h5_(nqPVb)R{(Wm_R+KT4amyE{eixb2C5M!AwLrec^ z-N_WV`kGy)uoQlMz-tkW!!Wbhvp|Yxd%t*c?Nl%Gn2o3ypCHaFdSO;___c^_>$A`^ z&*802d*n){%hl;QCw{i%+wNW!^^#S`;V3?sazVEv z$9OId8H`2hQX$8 zwCJp`AZ^uTy>+Baudax2W4v&<)%?6tws1NK@H*I5#lh&3+N%4y`Dv#H6wr__OM-lj z`;7|^(7L-^L`y29>nj{#cUg+)I5HD`>K)C+m+$;)FV+*2b+qd`DrYSEF zqip{6Fw)W9YxYHv4Ja6G?=mSi`3`+#JWc&K$O*_3_d4FqgR@zD(#wIMef`*11npbG<*(j54jNly==sIp zUiVnA%!8*}_nJvpP6uNHcbkJX;1hgDV>aRQ>#l#d=JCgvI>MWot3vdP-k;-1Ij83^ z`WC~9(y^Vy4X}p_Ofr&jhpnQgV-xqceAUAjIMDS?704qJE4Gf2rK*e%|Fqu|I5cWF z;`8uPpLPxLd|WYbB_P+#(_D`Cj+Iuen^^Pta*o>UxZHK#N1FlJvqn>p^Qs7R@X|(b zSWF%?2JU(@Fk#d*or(DR4GWy@I^5t$&~iZ-k8%r%;A!2r043X~g*W>20VhjKMGlg_ z7fwDB4M8Zm>OX;^Ip^VZT+Knc-E6i#)w8r!09&onV=GDfwrb?lykLS_C^?&A{P8kM zXU=vg`|n?4=lJ&>ypRRrzq?2^Jw7lhL3 zK%`g2*9=yd^n7*rjHeVonmt+qW0t@&=DRM_6u9MdJpDARJfDp$Ll@g?eC~p_O^NDZ zl1jK}mS4p^*x;0{VCQGoT1*cP^RqdZdbubIUjL2_<*JseSGv1D*t9(-xh(cc{4j>u zRB*2!%2KVau1>$=%RAUV&S0jElPvd_!|`bCPmWMb_8=^odYVO9)ZNN;-WgZ-({Z{Y z9xY;Y{phGpvF&(x#NSHC5a>9zr;BYP) zkJWiWZqTcKX;%dA*d$EMc3?T}!pq`dl|${S)#-Lxa*EJ=0o9iD>@*mKBhHdrBfx0~ z@sy@$zW(B62f-6VVPvhY0}i;$+HY5=D~^0itSz$io@#$0ZxB}N_*#Lc;JgTaLZ#H+ zKQQ#2{q8|zPj`9&!)JCoP_}^cWa~tYb)*uU$>!`Fk)@};uVGQ~abj)tC1neqUJ^|H zKq3U5&-I8S?@pm6lFkE5GQrP@qcW98zbnhZA*#38;Q{^uqWch3YGYSwN4sP&XHgYc zHjv#ooWfYS09kCX`dvueFS~9}ap*{wbkfqpK1vZ*p8A;RnB`4ZyQ8(^?S`{oud1AL%9>lB%ENKLqlyRAI_v(j)W!CG07#Q1mU5? ziCZ`6JP*_su3QbE+u>2{Zq6nH%M<=L-PQU`v!u)=Y}NHxH~U(tRegNS_2n7&o?Y%b zwbG*VO&#EAeUMf;Bp~3mIN3`dCS*s}lqW;GUMYN+GN-WYoIVNnaCdNQaiXiS=@$kT z-j(@-4krj)6zW5U_pYDpLugltUQT=TrQaFHV}N+(!}E#IUTEG=SU8rGo_}V1yuGv2 z4-n~a_4#pix$%}%=1b)>1fB{zNp9@0vVOs}h)SdV!3+51+*Fd@7tc&ZMG93aB}Tn~ zFhNX2I((Ec+LGGBmFOTwrH<&(B17)?C8^3+Hn) zlF~5KsosPYEL&1EAi&At5!DU-J+m1X=(Txnw2+2CE)tG~4IR66__66^wGta@8q9Jo zL&qmP=ljXAAtW8z*$)YPn>Y1!%uftObkFj1C#^jnUtA)WX+sz|J~0VB9}4?g+VA|e zc^)BESRnORv^VhCtxh@_D8WF8?&tY*DYD(_N?^G3gvggfX&*b^0aMz~Hn2zv2!4ei z%k4bkVO1&2P@WhUPE!)VWN9 zh(P?~x`LHQGWB69V`p>m_1@_Z?0~ulZBl@EmAxWH3o1;FMn+1CzKxBpo}T=YSU~fF z03#+Ya;tG@ctMrDtgI|>?r@X{>BPOx=DsFikq1YB6a7t4RQ!9Y91|Eunn3z4r21n- z3NNxmPPwWzKsD!6gf9&61Ev>M1%1Rv@A<6j9(b%k`bS zcAd&DGOe7pN`!(GX3v{(PRIuvn{yU5{hYbHy zVcm5GDg6W+{fxhrwnFGDw)$?bmG;w>^2XAZ*BB-?G<2kgVJPfktm*pJfMJcHkr5p& zt)-O}Tfo2Dizqy{%p$MNT)Ms_kipfuU0NEQgTuwaAx;K(donXKJK52u=b)k*861QF zf!A4U|NJgyXHH5^|KG|3L(iBP?TP+#n*}AK9qkti`=8r;QT<(yA2Qm&UIA8>O96ti zWTe0QuTBEq@*y!;?qVB64U&->{qsy3_zXnP_XF;K%fAPqp#SqviL?g)UnQnAR%#`N;`AGSG*o@{*MQEmfnp%j#W=}OVs>zi8zs)bic*b68a&-8o&1NUy za@ybiDO0oe|0)xV95B?~AM~FpJct>AGBE!%9L4YdcgOsHea8Q*O5OSXpK<%!+l2qr zTX&yFPM<3{y*lgvzrEH`5*j|Xx3IAEe|NQE-O9m%iF9VOK0s4b69olj+VDT)hzJs6 ztlQoXUP{5i;aZB4tW+APM*N>w)4~Ew3cNz{JoZef7L^1x&00K2GAwTHmzF1{;AOE!8 z;l3Vask{46dOFVkKC5T6-?)c0m9>Ws3R9t!9OictSIU%PW8vT#I)Wv{6{^x8E%H_Q zSxgG04-E|s%+Ymrc2+=($UDmj`EM80<9-B$N*5{#kr~!t{&zT`=pLgf=%J)ynvqdZ zCMG7%&dv;;J3OC`xxe3o{4)g(jzcNvOTy$dVGaH}PwB+v+3nd_S*IH|+FY;JY`cPd zb20A?|Bu&K*cdu=aR05yoXbNhG#n7`a<$3#f0SzhESErdQHh*>b6(%p%mhcIBnCN6 zNFKzqpb${hp4;lH#UhvsgnsVKOE~(#8Tm6LSVH6tZ8L?eTIsh1w6DKj5+!NKZR{cc z=Lf^sRDQ)<;-w@@@@I#`#PJvU$}g-d zle!7k=4|8e5_PEm{Ag3LzP$EAWZ?jNy56HZU--~)6}w+!C?ejtRC1F`aoFU+?x#%5 z{7jmer$+}T$H!<$NSS(Z-gJ3o$$T$%4&3%9DR_)6NvOUSTli1&jZyY1dHn-;&8m1u zWq{2Ys`i{5lMF(rxMM1KDSEo$i3ynpR|gjd2f0ck7k0Hovdw}pE-pxn`+M2H2KWUk z61A2n{vGR?cp11K-Xxv_H^a#`kyP=b1 zv->d__~3dnChGnyysHUUn3|g$OskrysoO^~RfF|quNme9ZQj}KcOkAWSgR|dZ0p$j zRHEmlQM1!lQIm3$@RPYUEe|9GQ2v^V#!8Ytay~BH6=o^yEvC(trJckp*#K(Bs&X?K z365|787Q(ku+Z=cQ-QPopK>FCBkWa`vmL0Z)8H3)@h-3C9iO4O(qcR2zP2sti&dZ5 z;eOU^GEgQ|lF5zlugU2XES_sEX{7|@fIXXci7b=r$+Gyt z?w`uJq#>G^cN&b$o(TWp6D1$%}19kG1e0fol$tjeX6^am$oP-=Hi%|ClD z4aFVY2g<@hN{eckUI*(mAsJSKp25ZBqaY-p9rA%}@y1aXkXBo62V*Fg1Nn3LbuF)F zOP?nVeUCQa%A~Gf9s*tm1)Gt*i%0Cu|6Y`GkLKqjv>C$y@sBJL+Qdcm6MM_ld`Hz~ zE)U;?$?4l}(>nAtWK4{t8;^=6HV3?EoqMs*EAIuK#wI2O(wcKZ10C{sm*tjjYh%?V z2s4{k-_~e)0qGYUb&--05peZfuZ5+dD5UhMv~#Bue94*2QiBqy{-+H-R#*8Q13D9U z(2Y1>2Ph)y1Ygf!F$qbTT0{F#x*1y`Jw@3&Ka5v=?8k>!$SX7FwqgJesqW^^Vp4+j zU289A&hyT^_;q!Slw|8mSEmD@knqhW_bw66v@+Vjb4ghI&0`mSCvGMpRyr6BHCb_e zK?fxA(!xUs{Tdl+G%`%8MDFm%jP8Hd<)rC3IqhqX2%X)26MLJ5Nmv8-P)+xo0ziXN z1X;40m{)_U-qIvLBLf2o5znyj8SK*b`J>PPXB}1VM`kj-4onMvW-{8@W$xFDo=?ll z=@ltG8(CZDcJL+!!^aLr*Rp=<=9~i!$N0u!etyx+3fGDx$Ndv7ujk@HF$Lgurl#f) zEPA5c#hj-Zj9jGdE}RDD7sa!?y1Y(3_n{W!>-wgp|8MybDOs4XvEYlWY&@IS1v8Jw z@AeP4Eh$yT1*s=K4X#7{D3AggL<$;%rmP(E-MePwq7bLHJOoN=t8-d-XC5aVl^7s* zDCL+xT-2?~+6Ibo1b7Kh@sourOKyW(H~If(aXmgd`PbU&8+w&Ngk-O2^nt*X5>MOt z$`9wTdH+0&$o9M1SKmpBGG2+|WgeVCiIIz!RRZmjniAf1`BnNNXV3tGPfcVz-B?!E z?l{dnP_)}5k_94!6QopI?(fUoUY`mXXy0D`I1{_47GX9Av|P1GOm)&cpC++#2e-A!1&V69 zIxQ1oAnQ~LHN@Iqra_bugB}Ayvj{B;MmlxMfaDm_?$oMkU-RGo6U9C_?EK%Ylt`6l zX>PO$#Hq!87!W?Am~3v_-w{=$!LN(epkl^V}JE`fIK+&TO)Uf&?+)%jH7YjT&c zZ9pq1kGh{d0yy<2{KccJqtiBj9&FIA$@}l++(VJCv_CN>M&Hy_O4ql`dY)@V~pDIlsN+*G~U~k?Z8Qf2_5!nRqGf=nnOr4xog_;aSzyW=C6n zXn4%XfWHM?ry!+{ow#fLyhI!-^iQB56NN`Jo_>xD`JTPIQfUOCgxhy}F6{~Q0P8^v z2~wrdKcK7u_=w$y3B3gf#S8P#--HkiYc!NSJko~tL{!u4Eg7xckc2&tL2%)dr%;BC z=dF)VY6?__4=k}oBGE(==Q&#^rsd2*6N;tEd+e48M1^a#qY&OaPLC&^jDGo2DKenN zp~3_j#_q2)?h}BWp*$+MeV=Rl_D8*4f;7)X0A8FDmCnOJIl3lB;+TS?yK`{wCI>Tl z3?;nu;hR3k&fSZznM0{cna?=r!%#jM#-iX=7c7pLY%fapV)mASZ^bpQ2G9&B$%0O{ zDKHJhp8pmO3JK=?eKHT^eiR8tG+GVz5W~0g@XO^U_ZuzvID8c8DX}(wvOIyWeuBrz zbF>`zabXHW1fuZqOD&`Q%WDXW_z)WjzBnPG;C^a)dO(xWUsWKV`Mn*dkSuVRYHCU= zD+{fD8AGFB6qi!(2QLsQhc7QrFE4BOPW=tcxVM>*sK1xUV?SLF#bfBGd8t>k106wD zpn#QnIhL>m+q*e)zsUFET@Bo3D}OW=HfLM(aJp;uVCc%~IsRW@jn2XJU4B&MNaA)#U6V4hle8wTY1 zx(pE}_Z-uP-A084ZHz7T?`9N+I{R>-{VWMJD2(JV9>nr0McJBL*HuRmvudYgw)FBG%e}a+me4XZG03A zVvbGG#IJe#(|N!)Bq&emWx8hKY%p>7$3z9_P8)}#b*7!@2=E7?lk+i0O<9?ra)0J$ z7I9)tG#h&E@7^I^Rerix6o2~LY9LIxeZSwD$=<+KXSF7Iv7u|ie2_;f7L{mPOxCyC z7w9zc9V-$vqo?K)MB_c>IHftgD2ZDw7@e#7`ECvw%qk7b?77&rVRDu8g(A?MXT`$% zHdn|=YmHKV&|KD8;KjG=@pUnuUUR~G4k0_0NSSdIM5bQt<7DgeOt~$tG&V&3NE~?5 z_j21oR@W1*4j3s4pvUSH1~}~u1r`YNvQI0iYf4a2Q`_JjI+n!S#r|cP)tqM>Muskl z4-4w>dbIO3bN3b(_qMR`oT3!ZiIIHXi+Jsg+eI!Z=q&X%*ZL?evMZ}<=*(-*X)YNpu*3e1$ya5g)ic@Ii<7BfWnI59m0`$m@;vbzm=R_Dm6>m(n)*9)+Phb9+f# z6qr_e*aM9c!PoUzuU?#i4?D-tZa)FVtwf*A%w@Yf2U3*>3CacP?auM^HFT46YXf0h zLOKftuVRS$dl;pId;O_AK%d%~E@V|LRF>g_AVJ(pm6LpHo#c9W5d0 zEPH4CfB3@i_PF_ZsmNya4At-uKz69mJy(-8H97#s#}dP zG)ux7R6hDT<8XEJ?;S(>A!>tcFQt&L>|JCZ&V?n7M~OG`E{rGR#CF#YVTY1_@U^H7 zOpjaTvF6=J$(lckiKuSx)@!|?Syav)g5+^5@qlB!2dHrZLQq7-AHv6?>PE^9{g}l6@2e%~4tTgswcdee8N{=VoWorsU}rI0}rI)q2zA zgIt+z^D}8N>-fyvemSGYdr)XN3%2cZ@x|k3AscOp@u|U;vApss+=iYlGb>;F7Hc<0 zakS5$wy>CpBW*{gmgk*hZtkwF3nli@f1OIRco?*Il_Ub^IwrU{ted*(FBcMrGUHfE zxg7W7K(6FBxvE@0#ME3}rGI)h4kVvN|JtH0&HBe~1;Uu;*Omh|$2VPU9Alpbsy=TY zhX7~;4YpX!L3Qp#py&Guzk%y@$y&41=>Z?lt!^sbRPyQSL z;pW!Z<~v&^rrS}LZ97o|VYE+#z$ADdu>E>ILZeZu zct4{Fky|ZbrDi=E72vZkecjU;*I`&OVZ@h_jtwQ}uHzMWca5KZt!=GMAZ#KD5#cd$ zSf*4?B>MhJP^Eo0INIQO;poBR8Lof6BSM4++X;X;@`tJAQ1k3ajJH);L;SY`vkvLqw2RApjr>B7*Bjkrsz zx=-n$g2&UMOTcesSbS(%EgD$b(KvKfAsy80G|`%V)oE%^HbBVn+-o%Y#1z+6N1fBjD8gGjv`CB6qVI zLtlT}w(Z%TipwJ6LN8#JSl08)Jn6A>kvBH|XhIFr=4*QCe~-FsNyqX3VF*33oYIM4_m+B%rzYZ$15nUKpe|YyPzs@Bfr?-i!%nv_$8RqvWAl!oY zkQZ;1)BuH}A3E=qcHl1A2nb_iRy30|%$q`E*y=8^Oj3Ehu0@j_p+x8^t8{*iSfc}% zA3Td_-aRA0Rv4L!NDL22mtqd6YSD9Sjuqf#CiC};5#$E#)G||r*n#sHhVX4x< z5J~ad1Wp6y)y??d^~x0AZ!vM>Uvvi8ch&skd{|eH%?r%vNM_<|6cl3Q!q$rBTR>Hsir0DdoBzOVNh$|dnyu|sfcqO zXYksOHu#}Ru+H@o%dqUxf7nl8@W5xzvavJO)zr#cry?s}Q5iEhN1h2hH7C`1h@UFi zG;8YCPgziQs&{(X!=_@3?M%W@t zKH{X+q&37ySdlcAd2G7SitF3gPgmBc+=FE$d;jvhbo60$%VQ8$;cqqM^Ds7H8cj|Q zOe!qOcd)R$A_%~O0uu%vY!MH+e``Fv+|W#71u(|o(_26dS!vh*3=L=2O}cbC z&(!-I68M<&m@9CR&_;B2(&am!@5aMD>Vet6E7cpEGa*QCPI1oF>T*MvjGzfFMdSYp zcUSfFst&q5BhVOAr8S=#sa|ko%q)I2gjCTsC32y8_TAy)`Pn~ z4}3f7ZMs0o0c4EX&A$U+$3pZ8iW@sMXk(F^;^^Sdehd808puvFgk8K+}RQ zehnkOlHZ!)GrH0l%*H*vZ0@}KSRgoW`a6t;lX@P;{37sGWSyM4$jawK!?I?$_w~8p z@ewmPSPB?irZM}voh4tJt!-5FptpNg9v!vydIUrz;pwOrFC7t7yy#bHE{8isTA6b0 z75POz8dS+_f~6-PKCVz%omHP-X2nWvP06rex0YDR&WrX^5wF>WtjM-Kqi=!|$7-yv zv8(7Q3vQtMj~$^6X{Bnfn&8azq13-&whcfWS#3i7DO;Ue{9NT03H!rJ1Z8lUV&i8y2CUh7jq zq{VX|)Cb8@b8tVcMbrvCEWuienCuw_tq;2@PVy8$uAZ&yK2`G=m|2Lgvz2G1eJ>aZ z9vVKX($T`@(&qct^;JCsXe^6HF#1<~WBTrFply(iZ&Otr`%ZADGFa%<0i_i2zA5RT zNKpjEa1RDM)eGKRjo|>Lk4@7;az3S^V!yU*wb|dr^8DV-)k;K87DJwB(FHs#{$d?*Zm4*|m`2~kbs!y=2XR_qj7gkjxfD;p%6I)`c1H&0nJyl`S z4m3ewDbw%9zlj>SpubzSmS^C@*M^n-qQLk0f>cPZ6gzcbRyqb@wD#c%$$Ffrk+fK0 z>r0y|Hs}Odv~yST;R)#Tz4rgs>$h6l+rA#ArXeV!EuS711J%;eFv5i3(v-5lpU~cD z5hVzNrQe*-PNvJp%HPmln%yZ2O9<2v9KF?Nbka2Waj1;xT2bkB)@?Gx~~S*2(96YN8>lE*bQ67*o5<+GB2Z(DGZ;P z4LeN_3A)A?ieNu7EAB(&L}iWUYrg>d?G0^K!Cu%H%_ZwQ^R1DPHJ^~=JIqkQei26m zpGT=I{M*%QmmA6HHgGe)n)ENSs=OD`FAQSnJ|( z5L1x_)B?&IB!YU$xP;+UFeg_YE4#$U#>T&}`7;n58s$gCg+{j_5TObt1QkTGU@>6b zk$>mP;{Pl zX)+sbImI=A+KT38PCl;9hwZWKjGCvBlY=%lQ&d~FqURhL)4LKG(?o9Dm+cCT_@2Ol3FV_9)qQ#Mmk zCr^gyzvH(53Qqn{;1G(B?jJwYu|>~+!+XN=u>Xxn0bOAKgbb(WZZpULJg%29_l}AZ zlv1ita|)SC0Hx3)(x$6n9_4m9{Li^jJPd0Y*@*|b-&H|_2XN*6$f+uT7#g!fQ?sj$ z%r;L?IW|WeQ&MzC)WG}8^NI`=2eQCG(!@HcgYgI{E{=Saaq2>cIK&v(VFC(n(~(C;sLb;!J6uc zG5r0@Z*Tg-ATYaS{>Tq2$J*3nhiS-wLMD6Op5}}YLJ0jVJ?+E=_20dF_sJ(NDsDYU zTq=cPMj@Y7N~H1`&RkQbv);uIb$ysKqipHj+uz@o-JX$1N%53SE)%Qn!nAWTp-e2` z3V3n}_YT34Nd?m)F;6NMk|K#xO3V_n8I??RM=X~MMLeNID3rahaZMxnmhg8rZ z3eH@I>Z7&)mv&5TFC;E*OJ;%F@l9^M-J=2+yQmi}Q|i=Y`o-misfi#6u~-Z*GawR) z>A*nW1s;xB^k67V61DS*3(82u60umaFkL_z>CV34@cAme6z-xY*wPlwhPOttqhvCf2+FF#D0*k1 z7C|C~IRdB$riIqdkAm8uB#oZ$PXWuw?u|A4-FAm7)@RLJ^sN&6#OlYj|1fbaTm(Sx zzkpf;BC7TCD;7r4v!xT_=w3JZSG4nBF;3R`2%tHjmQO<_QTQku%H7%ztyzH8pjxuP!Ij z|Hv7APnXz$@M3#kZ=YD_>Ry2|$aw9Fk9VKfcDWf7>>G7q-`e#z9JA`H`VzyuwLbdQ z+S7W@S2D{QhX|SS>)UefZGrr@xV9w7#cG{nigbo0$%{LFLGO@#+|Zoj&TUd5luJfy zlMMY2y|0_07|yUib*)g)bx|>B; z0+bWw*`cocwt3cYASXR$Kc#0B9UUDNd6k-xu6tomXLZz7?N>k8yGP3;G(W3;NGj>b zvbL}@v~%Hp;5?tW?88e78Va&*TAcafa(265T-Zn_uCPAHf*sjc zPnw*)aM3Y5GBhy4?d<6zCiecNty4^D+TXvt^{~G2wa~B|PF{MSzqG+6ppr2upB$`A z^gVp~l2d?RP7?`S|MkbeZF=v$ z4ePe7e`nhX9o^WHNkP2rTgQyAW@e8IzMo@D1d&Fs9JIWaTh8q5Eces;=dHGR!yQxP zccf@mNy=yL5R$JIvRj2A9#-pJ)8u!iiK3*_2F71GCk_xQF?UAv^{i^7I?=^#r(PIC zH7#BiLF>maMeLzYo}0?0*f+mBdUhUAVYp^UQkrtZddudjH0-3OaDs%xj_HjG%>}?ZuTNcFT?1+-ru*WI|8oaDEmXznkEeU9yQ)ikbl>^)AKzNHVZ(+G zsm0!}yU(wIBaqTHAcPP?%g_=et~+KP#iRPWW_kX5fT| zlt~o=)ot-N-%91oFe_{89UF`+&wIs;&9MpbZAD48=ZXD)+Hx#rdWbtKoc*4hnY%M1 z;Rs^v{&@C8b!;X6j%!(a z^cq)ZYMi_2n%x2Qe2HK*$N!@C=>yjDVd*~+78cz`5HabJ0p$F7%FzH-*Ls*0ihcA`{B4#(s)jIYqEgZ*k&+qme?G>$vT`{fBMc3)ytFKq+ghkFq(r>Rq!;UN2k8t&Q;2+p*#=dt9mo z40d(Qr6VV{op7$46-pH|V+Da`=6WZcbGafZSva4#=z8Q`QP-Vp_wLZT^yPm0Qufd^ zA@3{B33Js$YF4Qd&8Wr)Dslp~wJ(~Uzj)D5SI^kV>t@QWi94ig(fk)2*P7 zl=FyL#S9_2E96adXE^EUSs3V_H!?Wy;O3fJFD2TGt|VqvwD)rq#WuzDhdMU0#>&kyfqZi52YXkRTVc3sy#k7cZKf zGjxc`>0q)%w-tOitx@#m#wDgl7IpC+d~Ez;lPMTANj@IN7hqe1pyFZrD}^dTLJ~dM z9?4aeU5mn}Ou=Ifv_u<5H}|t(EkW-zqdeNs=#rtHfw4N9@o^#dViti2-5{Q`BD3x}H?UViCm8TF$ad0WzTXIpsf8R%cNaZGO&i3P-PZANNJ zaB2ffDj_%xN!M?9`}k$G!;9?)zc`YKRFf6)9!_RP)JxaE*h2q$R>J^SND9Y0D$_kK z&d(?-A>UT|?meP3Ns|JSD^!ob7zIjD$lLTjYqAJqV)D(tX z@w#GeW`5$YCxf~KQ$ococd(}<#tB~M`UZvuc0p-1u(PNyYV{WSMrLMI&3_#i^dwk0 z8SdQaGsqRf0aHPawbU1-UkW=E}H}~(~rEW?{$`vXed0V2KQ_RfX zRuSK+L{OZoxFeqVS~2$xp_r9P<#LIP5KClYkwhYtDuvQJLa9O^6Z7xNmESAw--VVd zxO|0df}E8=R1-~+3YGNh?-g_3%|YIii)7*{rA&T@{7x}@SMv1?IWs#apHs?b2)R-& zRmsG&q zHj7E!x<@k#A%qY@KTk`MxVW=VG;z_lhF7B}Q7T9!Nhl#$ElgwZFIAKvso|Oq%1|Y# zAATuR3Y8KnpneAiL*y{W2NSBpo4Qjy_yaoiaP@ywDfM(zM@>haMM1Mkxtx>{q>P%Q zLJoDRJ8E`RM?$Br9wD?`L0;mHbT(v#M?^$~hlfXmXXaM4vfwE7(+&<$PR5&PD~wBx zNh_)E8Rh@ae!GPbLI|N}Vkr_AXXfc9E={tcz5zp>xxh$L3F+oR4kBdmFBQh9s_&ynhc3E2LI@#* z5JG6VSc1gG;;5c(;-XR(m8}TKTvXgqC<&#K$~x5dcVvWI0-;MCeiTZTN~xr}`O8;O z6CKy6q^9oFK}#L0)ZP40;=xd=Dyk42%YJYTOw$~7g>-Y^Pe@!d>f0$&BN0LfA%qY@ z%gK@?F7jz7E~=w`UQYd?4n|aHg1@OKMi6o;kZGn-r!1 Date: Tue, 14 May 2019 14:49:57 +0200 Subject: [PATCH 293/737] Update troubleshoot-tcpip-port-exhaust.md Added to note. --- windows/client-management/troubleshoot-tcpip-port-exhaust.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/client-management/troubleshoot-tcpip-port-exhaust.md b/windows/client-management/troubleshoot-tcpip-port-exhaust.md index bd7c5fd2f8..66d2a7ec38 100644 --- a/windows/client-management/troubleshoot-tcpip-port-exhaust.md +++ b/windows/client-management/troubleshoot-tcpip-port-exhaust.md @@ -99,7 +99,7 @@ You may also see CLOSE_WAIT state connections in the same output, however CLOSE_ >[!Note] >Having huge connections in TIME_WAIT state does not always indicate that the server is currently out of ports unless the first two points are verified. Having lot of TIME_WAIT connections does indicate that the process is creating lot of TCP connections and may eventually lead to port exhaustion. > ->Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. Until 2016/10, netstat was inaccurate. Fixes for netstat were backported to 2012 R2. +>Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. Until 2016/10, netstat was inaccurate. Fixes for netstat were backported to 2012 R2. Network reporting tools, such as Netstat and PowerShell-based Get-NetTcpConnection don't report Transport Control Protocol (TCP) or User Datagram Protocol (UDP) port usage correctly since Windows Vista because some new TCP/IP features are introduced. This update brings some changes to Netstat.exe and Get-NetTcpConnection so that they can correctly report the TCP or UDP port usage in Windows Server 2012 R2. 4. Open a command prompt in admin mode and run the below command From b303dd9df51eea083b0af7dcc32fd81c5b4b24ba Mon Sep 17 00:00:00 2001 From: Lindsay <45809756+lindspea@users.noreply.github.com> Date: Tue, 14 May 2019 16:38:05 +0200 Subject: [PATCH 294/737] Update windows/client-management/troubleshoot-tcpip-port-exhaust.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/client-management/troubleshoot-tcpip-port-exhaust.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/windows/client-management/troubleshoot-tcpip-port-exhaust.md b/windows/client-management/troubleshoot-tcpip-port-exhaust.md index 66d2a7ec38..5b2ce05b0f 100644 --- a/windows/client-management/troubleshoot-tcpip-port-exhaust.md +++ b/windows/client-management/troubleshoot-tcpip-port-exhaust.md @@ -99,7 +99,9 @@ You may also see CLOSE_WAIT state connections in the same output, however CLOSE_ >[!Note] >Having huge connections in TIME_WAIT state does not always indicate that the server is currently out of ports unless the first two points are verified. Having lot of TIME_WAIT connections does indicate that the process is creating lot of TCP connections and may eventually lead to port exhaustion. > ->Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. Until 2016/10, netstat was inaccurate. Fixes for netstat were backported to 2012 R2. Network reporting tools, such as Netstat and PowerShell-based Get-NetTcpConnection don't report Transport Control Protocol (TCP) or User Datagram Protocol (UDP) port usage correctly since Windows Vista because some new TCP/IP features are introduced. This update brings some changes to Netstat.exe and Get-NetTcpConnection so that they can correctly report the TCP or UDP port usage in Windows Server 2012 R2. +>Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012 R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. +> +>Until 10/2016, netstat was inaccurate. Fixes for netstat, back-ported to 2012 R2, allowed Netstat.exe and Get-NetTcpConnection to correctly report TCP or UDP port usage in Windows Server 2012 R2. See [Windows Server 2012 R2: Ephemeral ports hotfixes](https://support.microsoft.com/help/3123245/update-improves-port-exhaustion-identification-in-windows-server-2012) to learn more. 4. Open a command prompt in admin mode and run the below command From 40d597db7bcc86b0bf44975c5919ce5eb9ac3484 Mon Sep 17 00:00:00 2001 From: Reece Peacock <49645174+Reeced40@users.noreply.github.com> Date: Tue, 14 May 2019 16:56:45 +0200 Subject: [PATCH 295/737] Add files via upload Fixed screenshot --- .../wdav-protection-settings-wdsc.png | Bin 200075 -> 211629 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/images/defender/wdav-protection-settings-wdsc.png b/windows/security/threat-protection/windows-defender-antivirus/images/defender/wdav-protection-settings-wdsc.png index f55eea0b2ccea13da9674f04f5164071d9ee6bb2..d04325618767fded194c1c46cd0600df9fa9fc5d 100644 GIT binary patch literal 211629 zcmbTd1yo$i)-H;>1`pnZ;L^Cegy8P(?(R--3ynJjhd>~>Yw+L_+ya3B!GpZT-aGr8 z`^JCoyW`b>L9@D6)vT)N^Q(7C3exB(FHxYNpwMOBNT@(T!8QWFTH7z$Sc{x5)M|);tGe;A1W-ogupf?nhfUuX7v8k=O z8-d56)ki_i)W_D8*9;^qL?PhC2Ml0u z?q*EkWpC%;%I75r`fFT1;Pdli77)c>UEFL1L88wSQfSF5QHVRbm{V{vb1|8MIXEe} zd6~gn>>Rwjj1+9FU>+7$9u_b=6PSySgO!hsjpCmM0%mhDv*1&akospX;6Fi-m7ALr z9}A18rzf)~JF}yUB@39BmzRZ=jfIVk3FyJ(>h0iW?8W5ZO7&+133FFd7i%XsYexr) z=Mjxf9NpanK>($HFTvjF-(ekG|Jf#B!&tnGomjxktj|mOtD~9ezx|xtUF`mv+{~24 z+|JzI+`-Ki=nMY0ualLdo1?3h-vhlI9{@qpH(ahSy`+w@n z4hD|-f9VQvjhV5V@&9LMGgCebM;CizV9nO{#+K$RP7anJihp;KPu$VY(FK?oppN~& zpUa4gE4esYSla<#xT;8tQOHP&bAfrexR}_O!GDn}FV83A;Ob`VU}`QSAqWEYhuPZN zj1O$VVQyk!V#dVAWx>s4&dFiUWMW|ktQl+$HnCteUJEvMPIe{}c4KxXZf*{CCLRt`VmrDY{q#GHGo0 z-=jWLWd@AMWy}UU$Zl1<2=AxFs-u>S&BFq1deph3U|1(|D^t(%`vqycCa)D zR4ohWc|9!8O6l*TVflZb+F#%Omje6K9ngx;AOBUyz(4;gbaMw_Xcs_Ti~ly@fP&@F zmXQ!u^UD75;P0g|mvNO~XiGCIL0%c`fgx!FHZHCHWNI7AMED~LUd6B6R5?U3@|>6{ z^8#Ae9vSB9lrRaUXnre|c8)A{Vm9B(Q0;BVmYT|^L>*_T6(MTu^1?~2==s_p>ZPOW zq4(~4dbU6LUxh&^js*B7#yhVKd^>s`mi9a68|8M{Y^$S^wj>@Ge0Ms2Vw?6yX<;*f zzFulS8O3THkq!l_GHeNn`&gJ1&-mRDb$-T6UaEb@>_uEdWG!mQGrm;*{Y-K)8k$)xmqbi{cw}H#eL$z)X}G^_Ht=| zq~$4y1nbhp;o@<)r)(_X!p4!AkpmgiD8{F3uBWp&k3fo4(B~)E<@mrO6(rIyOHx8n;h&cMc&@OsUH06HWJ-sGJ8e0jR@|W~IiPeQ zmC!1RsvEz0XahHJ=kkad<^oxEsXj;9S7^&E=;=kw5YX1^k@6TZeUeX z9@k5z;(YQN^M(1$P>+4Rj{{;Kp=-q*6;k9}5DM-rpR$;`BKuKWcDKDWdNgmS_Pu(X zi@y(#bH8|XH$0ABPfnluu~=yWzlQ6)&uW6`s8gO66+J#i82^saIZ*CJQETJ$%2~TXF8I7dVK`UGOUixH^2==h!@9ceBP3jS=Q84& z*YRZcBJO)d@lkd|a?ZTNxUh2;0h?6f_+WF>}>@5kyvZ#ULnv~mi4 zsHtpW2zlIWsSd?c!(5LRmOv)Qyvq~PP2%>DT~YY{hI&djaD01vOX4k}Owt(wMS70l zJt=K!m&_0+|9G@sQ`JeJv9*QMFDLOBsn&X>yne-s0Z+^?xM!tEoFXB}i~gPbX=W~I zXRG6n-!S%EPJ|oN!+G_;EZoe*p<+ZJ`=8)R=2#s#W)`g4v~=m-7UkR$C!1Nk!6ZNk zL=Jz%I2Bewh;v(boyx*;<9)!4ANcDb^VE>NMu7)3c!XZ?%HaSXSLMLa{;}!EliBsP zg)-~i+OSGnKk2j~OD;x>F!56D%{u>>mP2@>N~+h>%X4Ao)#&{FhVlJ#S4Hs*$$o=y zA7uA5xjf62bioft*FwJ%d@(sm`1)5xq|JHd=KAz+G(XTLO{hgD1B+FPx_k;a z3%_SkykgdtyY3vn_Z>(jaZA0>65>YGBzl6Z@vO?6KdOr|yyzO+FtBob>-zqQj3|$# zVGiTbS(g1<$QSl(_l1;Pd>7k;B*gc5D|`e6tc|2G8PRN1VZ_+40sWpP`?YhRZ&Q?dm26P(N& z8sDxx@23EpaccHtvCIBpHkq^a{4kXl#7|3WH^1OQL%?sV?R+FV+hiWk?G0RBmC^T??*d5@J@r`frk)$wP9sa_-mUV8?5&d76rCpWZnBtQEcxU#f#>j^wH zd_0GAoy9r+Xi$uaj^^XXGz(ZXe5~Kib`_!mfw<(^nQtEt9i{J&V~GqO2Y)OfR&-OT zMfxjT|N1GS_E(#QhVT|XX3aq?$Gpy|Z|7Kcas+wT_o^n@LGR8UxgTT=b)I%uE`H4u ztgJNMLkF&YvNk=Q)1;Pay5D@7pL~>ZGCq0gFYVy1hCHp@nf!ioymQO)SpL*tKbrPF zE^e^J;o*KgjVUl)(6uk8==V)*w1#wP!hbBUis{p$7&oBz|6u@TVBo^`~F?@KaCHhmWumn z{``gqhg;jgfEjdrd4>B6G zYsn6iVJD@f;cw3_E)Iu(`uv%gfculz+15Y|!4WpzLUlz&ML|JujCvd)I7D`jFP0E2 zra1Nb)Uvt&T-wp0&!DQQxiB@w>VBwZD(CLb=`j2CtBSsU&U*PDd!#H~<+7FFy1hgr zmtF^~>-_w@w6v7dcK(3;lA*+M{(N_|x)C54uvHC~lMdF_8GP;)jT#c&5a6NdP`tgZ z?aXK#xGw@dOUVB&0-YG3NTXUuU0Hb=m`Yu}(cxQbi7aG(Zm!y}tFxklUYFa}-re2Z z-(OIntft1G)2}6f3~VAHFE4Lux_y89%bt>0P?bW6MZZ-|VuE)+J2NvgEiDZm6@M&O zP*)=0qKJGvPq>S_MDkDjUePR;2{s+1tQ-+~-#65PZ(_D;C7UM6m!Go)w>;9aaoB+*0yJ;#Z*#$U3ug*x+(Z|eV6W&{0 zU0t`y&f3wDg@wh@!C~G)>JPEUs<6>Pk|+q|vIRHMKW>3R(9zL}x$M$~{9Bu&cGeKd z^L!4=J9s~|xBK-+VZSs{R#%@}U47;_;OE^iKyq~>&TBc=@L!EphFt--=ezoG6uYex zzdrz5RHf5c@$sW`ew_0^+^eSc^LTz*#H`~B5 ze=@?BqW8Ed(AF zP;WkEPrx9bI5_mq3v2#$wBnKc9hd3>e!u!LG8({WGSSXoyg%J%rtto=@EhF9nwk?p zN`-^K#Q(}mq>4tddDiMp-nkUZHR5;m=*S{$Bi(aRsR`!kQ=nsQWK zUteER5v4;i_eSSVmHk^tK+p zDEikga%oszU?qRG!*5kWw?nT7H6{M^>!>tGaV&u3b%7%O>tT#}>?{8$;rNq(Sz@+L zXCB{d&F_ilh07l{nQhY=#2tH+L>~Abuk`Xnqu^$H>qkL+{6+20AO8EKA5TCJiLa1_ zimmBEgXtXdfLgyu@OkBnfwCFulSww~q7?i}hL4~BQtY9&asFnp210Ba3(m>O85kJQ z3!#^vc_kB)GQ%M`GOv?O1p=Py5OKsESya#24Fwhxod0Q%rb#kKyW+7Z>*wD-E%A9u?Xf<1dg+e~aJ_sK+rP5&q z6WHDklJoQPH@-dSj*rI>l($q!e$`XF^>L8GrRz*>AID1$arvHwjxOmh_qwd?;eAqP zKRJz5Y#$vZ3ih>a9J!-&*To%iEn<(jk*a!TX%N)?8hd6?9+Zf-l*|kVl#-FT6ASJH zVf5G2jHgjBn$JZgM${u=k7gDn_N}^ix)sZJG~_b zWE*I6y3o;K97MFUhM1`s= zLSjVAuB3#128(dfMM_G#fq9f|z1{U2q42wUkV^-ozPteP;{g3c{1nRuAhYWIv<52J z)`_hFvPL@iYI(E(mk=f*pz%%ks{Ei(HClvtw(A(hXin@XxGL6DK(1nI%Y=b*deBfLwKO#L&R5Qx-#0Z0x!B%-W1v-!%`&q6&=IKb`0&8Bx`Pl{6Ck|4MxQWutB ze+U+ZOFn0{MxQI1gL(h{EVZ|v#Et(KA2%-#IlK$;tu~T;U-;OPmlmJOUf|zSKKoc6 zsWl+>J2ai5J2mh}aI7CpA`D!gGM3oSHfS6)l6Sh=)EL|u2#X~+g~m>V>zYWHUpc~W zBQ>wkdH?~Y4bGwpYtsK_Qe8rDMnW3A(o-R!?#z@vqS8!%jdvXz<>uyQ6%M;kDBev4 z1B%?W8!kZ8iCi1@Ni0KV1s|xaf~-n0@;u@*XM!|k(>??YthFz~ zTg$_ka>~5u56*unR?6m+OzzG~iFkAWkIguQ-0c7|%1D$bX4}+HNsz68fW*}r>uWyN zT-2+=O3C^{jO2_|JC$51L}@XI(sn9YaO?*|d_Z(eOe4kyQ|&Dg>Qrkpd}?Tr+A-pu z^%WBA2dw+lul2$nQtIWX-MfWhTlg?M;ve2A1|OifWm?=KnP@G^?AEa3!i^y=(c?=y zS`jq77SYzzL(!c*FxE4vp2Le?j$4)#__9S7y-2sOjKsIv>V;hJ0hO|Bw?_!9Mr*_9w^2T83qH2i)n-}kLtpek;SUt5+O{RSFo0^OO|^= z0&UX5B-SMEz79Zv$1=_=1@=D^GaeeEzxjh&2eAsqOi4jc0r|mn;}qOk6s)J1op4+d^{{!G@;6gT)&?1~Q3RM8xo$7Yt8fR#_{yInt;RQf(q7 zK5(!}t?72o_>8b1Mad3jXJ_zWuhLYDP_)rYM7V?x*agybi5K1fSq9U}hkLxi+i|S{ z^ZQe!`_q^%s2FfaPt+1B%Sj7Xd%ZNTmn{^P!1j-!B|sxLfuO^)8_9{540@h`Ay{s~RC=2ozSlbYceYPP zLR!~wy{Q>DbW}TU(w|=ZqiQfOnI3uEtKeU5ENqDhZ#v09m&U$_!nWWqh#EWLzq?%~ z)VP3kv1VbhbAM%vYQmXg|bqzNu`Vna&ENd8r1P8`Gc%huUJtm$K{ z&%042Y%}AA&JQu)z>7b2&{doLFl3>Ap!Afu7koM#Hi@cMT(s#c!q8DC9QpC%doiyB z3CeQ4a`+peSz@?nzeGuEgBqy{A+7~n{ zt;tz~uTLSZFp)3D_fK}kVjDV?^W*6(JNu|aS@W053-wUnX#o##8?)Lu=Udz8_pj_ipUDBy0-q) z&DdQ5>RW;Q!hZW%ntt(l!>>csr~W-B@h>=c$h>w3X4jYD|H9<_-(N(omS|u zX$L4bH){Bc#*f2iQ{v)*iLD&F$gbVVu{6uD)5=YRS2@Z^7 zv5|PXwNsJ#`oGrz-@EJ98|$WWQ-|lt^)a%K`wyR6zpJW!=2HN6}~6D z@auFU@SoWEFtQ34Zb$6VnP9c9$U0WL(Poa+bM@@B4|99KUz0BEr5H;ob;HYd*FWJK zN|{@O2!0@zg@r<&E(yed^DTu^RI`wcQMBk6eYM#{F(TH^5qF{Xpw_L7>Nw)SxJ>BX zd{ELC^i5H)+b})THhVhE(th}66{gMHpG@I_oa>UY=nz%_l!;py{deY*X=RX6z`%3sVtF1@#CoZvN{H{NsAd59`O zKt)5NRNFn22eI4G$RDgv8OTcYCV7b~)>{FoiSf9!$LXEAUJ$(+nsIqHS+F9O@GDpf z_#(|H{v`JJI6=yEt_c?f>m#8v*Vj=A={IA|2|{38!(a^P&tMo7YKIg#IHWua+6la> zG2{g$^u#xc(abE>3zW@j9E7;soUcJr?4Oz?%?o$}|~x6bWSg|Kl60Qhufj zd=eNe2h=Dcnb!vY`t1a84(FZM9W0lSs~B?pa+Z)KUeje%Bu*!hhFK&ZC7l81_J|1t zJk}yY%ir)n$3x4|wpUFAVNmfkjpqo&iJOO}MjfEiu3)_|H0e^_vA3V8zb%+7YsaG0 zj*f>qBaUXDUfU3GrUQ~ERDg#nss_cAj2t@}%;5NNindK-ERyF0agpBSaDXR62rDJo z!0bS2)44bIlUuoe3;jSeoA^;z7q?wygB2n7=>TQy7&wuC;>x=svZ~Vi`=Kq?UY$x~ zJWS#HI=&%M2hKgp?OuZ(n`DCHFB?%`8STfR9#KW60B1xAH(LGoc;bh$q0Kq)T5xog zEH&i?y>P*SI%NVDx-p~a3zG_QLWJx00aBd?dtzsrzoB)*O(;LfP2i916*j+lLHS}J z!wI6^{yu^p3BE^xoEByALk9Ph-$ld?T&(fHg~)oy&8B*TXzmR(Su@0DDqnP!H{G2u z%19dT=mU9=x(^)mi+i(yZS$O|!eI9Qa28v*Dg}WhruO%MVBe>Q>%i}_hM9uCS3t6< zLBh&!R70Ys<4R|T)3jaon-8bn1lkuG)MMQO%h#Xm(|J(wFCuKLqQug~2#LZ${4-;j zyp%8Z2ocr_Lu4`DEH|6AiglaCem^)MR7 zq(MBf@kIV@`?q{b@?{-eAiPkQ*MEVQ`_w8=mGG?~`;W8tpsdsF@Z~xITj3PabuWpu z(T#tfg-(KPf@&cu;mzg&C?STi@>qG+xeW*UaaQjrqQZlVQ^gH$itY@hi{;BgKf+8%XZMG$9PD~g-s)A_oP4xDZzL)6GE&@XEM@hfz16vm)= z@5KI$braJTb&|+fX?9O+KUd6SaN@6~-=EoNbMity30XuqH9zb%-5A)S(1c2mT5N_h z?fD3TwRx2OJKb|B{f;iZ8#F1b&?b(7i`#h`&Z1?@(tg^T_wd8g+}ylJQ3wZiRpLlY z61}5AD$2=0ePd4BM}7Q?lHWTSQml={9Y^ku{RxRH_Xc<6n>jA#7f$Rv_ilp-F@B!q z_wq_L9|{&u^z6_4-*WY~Ar4O_SmgKoTNK=zcz|>@}9yZ^ig9(G6j+x>O4!ykc6cW1f386QD_*+E;oy> zqyoEppg}I*OCZt1k_7q}GkK2}{y%-m1Bo|a$c=YQ;?0gydy<^z_e%P|)^4ck_yIj`6Eg0%hY; z2DogeJS|9^*8LkjJ)~rD>$;L2r#nNbO*{301Y?mMSVcm&@S8`D^cVgi&;zE5-AAJ8 z-g4gaVCQJZ;}4(i!Rb#uK^XsKTa;9$geJC4qXLHqD9`tWpKc?`18%}_6p*rcWj9+y z-~>OUc#O}n@s@|0r z{X5?bBN&A(s;F?zR6Q}It`G_olKx|!ZiL%l2&@!RE#y|QE$MG+?`ctjxl2{R8 zk(L%|(Ss311)blW`Kt;>PGYVhYY~tZj517PX7k0-U`l_Z7<*kZ{6p*)d577EsZi{H z#S}ntqII_YCc1`vrxzSav;-a%o|H;)IQd>we+u zy(JI14brB;&5o->)a&htEIm80Y@1HczI9{|I5p0G3PnIq{*%B{H#xsfN`v_=ODrBl zm^i;PlJc}I{Adc8qw;fFu3hINp&*3O**2?xAF(uu6mh#~Mk3rS2)W!t58P|q%jL|23DCUwg% z`9OLV+LKwPE;7iIu7sbodRse$*n2InG_?A$C`1idMbZ(hbWSOPjoHjnQ0>`F{1r*T zl=LSltGABU$KQZM`4egjj`5IP!72cRUiVg!gV7aad7Y z;D7dZ!**)`;7%=8+qQ?5-(E<9u+Yp|A@g!VU!q`4#zOqos>35%w*`geoKLy&%MW zKlJ5|8dL)MvgW-VmKxzD_(U{>9F|aVT6oZWahQt;6A#F)3+!3}U|2 zEevaZKMwI>Ght&d!M*?TD(6m_L=5~wEFIP3Gjn$k9jnooZU;De@U#WPJBw0Wy{su1 zmf5!?1ck_An_YCrdQ3z}Qpf`NOOtZlX|aJd2(3Ah3BTdsVGeHRL|O03@K889QAe}C zgacVrAO|dH15^VC(}5aUpZ;GNZD{%#nx{pbj{GA_Vj-*3==HAR-^aYL8mB9h!pCEv z!N6Z9>N$*Zvozy7@TRypK8@pK#;1oQ5ZK-z+i==AY}J+IRsrO4S=V6uluP_5wWiKC zANC)uxkk}^Jrl<s;<;2+SR#pQR(;>HgDneorVOvFY;4%C+}i z6gE{XnBU_ER?^kg74SUaCFkLWrqk2h;-Z$me)WveY?*Ql0gKQo=X1e?uXVPsa#7$( ztCe&L>W2t%wh943{R3Tq1GEK3x~m9c0r$ojR)k;k?6G~?*9kM|BP|G{7$ywPWmjFs zz-|31MzrRP6$V*ZwRfQ$gf2Mibq_EB@y@A#5DGxB6&m_+t1elJ76+o zFB!c<{50_Nc_^F{>v+uE-Wy~}BXkXMm#zZW7jLnGAN%`a6OqTm5e2^dh(FsMiGX*q zvo69yGsoiYMw zNJ*eRs`^3U8&GsBl#Ia#N|Ubp6L)uaK!vzZzxFRo&>P88AfGr`42ROA*w`#7>vhW@ zM7tr$s(>WG{`$>nN~gWzw+Pa-w4ojowE4Jqlla~7-EHBOh-qTh-PnTUSnn))Y1Kt! z^f~B%4<(-!gqMMlET$&y5ZU;OXozAmR_f&vCR^UP2mPoc1f`^q-8CW^nS*b;?V zMM##tH+xAd%mDX_72ZS%YF=RXg>WD|NUFXF^T2F{CyH!y8rh*=Kbj6Vo89R7gez-W z-%6ac?C0hx`tBr2OPDQxvc4Mv3dLio|5C-J41(mWS|Cpv=b6v9_{uW+9=fQeJOvsB7vE1d=G}0LAgBRks;= zKd1RBZBRW>pzcg-a@y=|YHEU2YZU)*yz-fwgQNXykT|jp1dJqIE4T2pOPiN)3nA1S zxDVEXVa2j^!3&}HFuoLXve_tkhshnWXm4kuSSOO_##sm*RM7^Xh#@2#` zpAyLAGuR}3&^~Ilc^m_rZ)Ix-S$8w{w|o!<#)krU z=a>63N4szAi5UlACn+`XAfaO-g<`eS(@gpH;wP^u@Y0$_w2ISmal*d3Eyn7T_WvNFMPo=PADsk***Mbb#O^?n>xE&}i&U%q?+s{G?w+?HMTj*f;cEJ^#>S1LaV%H0z&z$f(p;rx5tg9w<>6e1-L&xIws7=t$MsqaRTj5n z=i}Yc=$9{p3FPaeVmdlHH$UlYlCuzt04M{X@O^sAl#5;x6T8aJ*b=Z9RE>y)Y#2G5 zZ}fy79Ui)b8gMzT2>?H<%)X^pSBoD_C5y|;kvS8}4}g>pMu%PSP4rf~D;{>Qgi(-W z0U?5TPcx4p712f-d{}C8&SpAVeO0JfzvqGojhG1Rj=5=q;S9TqQ@Cn0KAt74>j?eT zeNbq$5|GGQW?ypX@#nQCQVId^0jf^$y&B9-)gSY`J9oxo9^xNjLYG$UBN^^Z5A=qw%0c{UOxW*iAkZQw>t1%(_m?|5U`Y!g4e5n{cCaEf4p1h z3OK6%d{ra_*bD&Hp)-t3lU?V2G!JMKYT2|4wyoQW%9^`{z=s80hZgg#{&$wy&VzvQ z>AD$Ui5|vL6u^elzsLt5F3dWg-beuO2}udzm|*}Z5yD#x3WR1h>K_zx z?hKzU4Y}9-T$>iXf9-K{aLA>zK7%&|Ic_s7bFHnctnBRkw%*ZrDV=owKB=tjY^|!Y z1HOkC_>@Og>3&w2w6nLL+f6ndjMe^RH4Q*)8oPg9c}>Q-dI~7 z`LZIqd>6RY_2B7kj|brE_wxHwdS+1Z#B~k1OyrR8(VoykA8=VO-Yl4L`2>l$q#3Nz zI2^$pWpzfe&)YIdYOu!C;SEKF5`%||1Hu@*;;prYi7oDTpAM~~hK!;xD>9oO)~Z}N zre&cA-(g;Cg{p}W%V`Oha*cvtAS#!xNTcilm?8& zBwbv$+No{0&oDUe6WHAlyvC_97jF$!RFXSJ+n&K7e>?L41PHnFC8v!VpxgkmVgs1FyuSWC*Y{-PYoKG8H3`Xrl)8pS^fUNHWDS`6{rmU)o+mpBGk1U? zwMf#G03`7?U_8= z*1&{C&k9QXHN*M+5!;jV?Y5yy=eS|sQ0)7unsy3g|H}AZuoYOsJE3LT^%3szC?jp+9KfCZBGeM|KK;bQ{-Pu4vTlwi zjD-Q?N8)3z(nhemg?C~;EVp@GAM)aIoGBBbaRwvrX3eE3E31r`RrBZfFb%BBu;u%M zg<3u^GIX@OM%Sq-Z-1rEShz5-S~hoVr5uRlKDls|1Hhp#sdV=C_M%Y(z{-Jr{~(v~ z^|ydS7MDHBMsw{~T%4!M9j)B1z=x$@vdQ{WKWxxC>(5YRqv9S?M z67$B}`}T9^B@;GKcu;q85f|_4divdk$Z2hDt=;Uj2^ z(k&*L3leq_VP)QYO;O6_95X0q@ey)EJ30Mv9`pS~xXvoB7~3;UH1qEoJZr=!yOPj9>x4jhGoAFk}Q> zuLlZ~&k7%EcFejj=r2rWW;^vFZ>7x~M|%8NR0fp8a*$0-Kh&4A9w*eBtJ80hKiQ=f{+AKpmdGwY=@>A|K3-fxrtYOPGWND#CLR_eT=f^c&g!`X~2e zjxGFsXcHrPL>?q@Y=sY$>q)To$|0BXZL`OFSVqjc?PbV)dTBh9ObRb5=kKH;?``IHooDiKYiJJpFrmb*SVM|oO}GLc5%osZB9%9c;afl^gx%2^ ztnvsv#1vGzdvcQk`Yki8rLo0;MI^WX8g9#=S+i5N^qxU8?fv^p>x6d+emhhTRU<$e zqPFYt4p4(St5?(=3-P4<6_u3$NB(R*V(#!b-RJ=nHefJ=N813*9iY$yG}I-8u3IL} zF)PHg#|5i;2!k`TvKSZ`P@;_m7+PlQIQFTuT^{A*A$JfA4UNVY_BkDqt;nmFub|?gOY1a;QV~vj zo%Ke`ASy<*6_yVd#y)xlL@joq3)f=JMOUo45%cDs#|^&DeauLQel3PBiO#o53=!Bd z2{MI)t14Q@9ZHJBkTi}X&6j^lkK43B*u@?~AeS4NPsqb4MI@tS1szD;V|RoJfte`? zaiDl6a_ZBLNzY0Y3vBwjq%{)DKa;vy{ww5fbpnm0m1)t)+|8{{q+-G>0|YjHWR)BQr%qx+{s zpw@(tncREJ;IhpiL8}ARH7}=}PsI6^5a|WvBOWf0GQ%SThqL8>pA0;luL*WG_9%pV zby&aiE#xZ{KJ+JQ=4H+po-I|nQ(7oPER}BV0}ch8o>$RNy}x(5VN;xAmUQQ+B1pba zT!4IE6)-(Ca}!FPy+0Gjm3v(x^|q31+8QlC-?*U8r~pWVdKdUM7dN zing}4sc8|6xv8nCq~w68&OCxSRcHYKCj}bd#V#x?*m^lkMpfPVa~^3^NbLZEyyh~> z)KbtLDG9i?KfDYGGQF%8V)>*nr1*qiGm8T#ahI zE8D*=m2Qmt0)}pij89me_#n)5S^sL3YV7lj`>YAhcuOvqvpmYEI?5S zBr2hM@5HWhTWFmsrW)Y#ad_f)h6LmeoK`2WI=2(NgpkSJD2a1CA!R;A>H|)8O-+r^ z)BUfktgL6Gx7BnZ;66sb0o;!D$K&-i|Lbpvrv?BV8IU2p4j*>_iwzjGXZSuzckk0V zB%4II>u#>rr}OaH+%;Ip0~>LI!Zm+3M9u=z{p>LQfFFzx2-5TGoqpbqhki&LfM*B@ zCs{5|zWqwmyW!y^ss=;*)#kJA1xBF4ToFj$E>PS3_;o9wZa^6$G^V7)uARx18RZSa z514aVI+%2E*#U4y$)fhEtlkesR)`=MCBoMolPya@oDlX?oX|`Sk?&!_gRN!eQX)Yw zKT}iW_S;M4OgRij4ILaDY#b6TlPlD+NgT#@ja`fNAc!#JleNaIOgvcAf#7LQoAY}Q z%7S1vrw}K=P0)x!y-<4@IB10`Z8zW-dV;aIni1r%PStC;u6PgKIkCM&T8QWO!asnl zgQJ~YRZY#~4R9w5(Av)#jLE=9S75(@d{UMS~H zI>PH>%z;oGJ{Ywmh%K;YSnSd^@1)_w_-f$oXGSJxKOK~j)#3;`Tbp5O4eI>hQj9UdX z9uh?WkO5js(X2HfEjC{JXgZX}r0dfFXFrk63ossVEECM%Z2{jI@VNmq3ka^RE-}l( zk@m};ufI7%{M7-pKJd`r-~UQo#MjqXU!U~R3jo1K4|hGRbe-{5YSzwIH-y?YE-$ST zJOlS4<({)_8WP3C7%E?)ccYK)ax7d?&meS6{Oru4wKt-l#iq+hzQ+(e+|bLs_~HE; zx88dA3iTAS{^5v^E8-R9IaJI+b*Q=J2Jyq&1Y7^+vDG(*tIP!*M`4TD3n8Q}4y^n{ zTd>QfQV_I<7;@`zG|LfQ1$`X^J3gzCnzUHQFQNqVIL7j`bl#BnV3+5aA?V9>rJl>?=0tZsqfZH%<5l_tR0Nm4n z7zW%5eNcT4APbZq?*teIbsQUD>#)T!k&@T3T@}CMUj5Ayj*8RxM1yl9Uuok9|`vQ9tq?CCG_C*22SY8 zQe`b_UYtuee1l0f`@+#FjE*A5K7!wjg+@C_if1}+Ha~gHvG%QxCzQ9_WP9IB!(*p- z;sB)>Zj%`P!RWy$Y2!Pn**9nc*7b38a|XDf;M1TJqi$eOW8f$&D=U0^1Eh|$nw^Xd zXUKl4ro5Kd=?Zvw=1c&6^TPUl*W+caCDS2rMaA)3Yhz1GOJ}En1fWP!axyA`8#V?3 zx4Xi3(+Pmbh(`o?+w=?!1dLj&0ry@dn|4w$WGGeTbTH_j7$OHjAsOemtu#AQpP9m^)@!qusE#=KFK*OVltB?sPsJJ8G({??$Mu z16fJX*Tuy$e!IYjBSYa0&S#wNp-lL~eg^wbj6kc&mze<%s=mTbAp}dvHydRd2vnsa zOf=3*9=9dl($YiEH4_nIl_WH{pcF=G%WipC6tf?uzp=df$9uMD2!rJ`^ILs=olxF#4a6yziRb9o>&?-+&a8*Dz>6p^J4!P(f& z@EQH!WO35hG>|}1`f$TykjU&dwEo-gcEXS|V43@cznk0tfJJ_%o- z#yzYkM_3FKuYyVMyQ6bNFG*JdgPeA(bSR>@Xwzhtzxvw8<9BD=qmWG@zunt_-jmE8 zIkBkYmztN_o%&i;glxivd;0~;0{ISXaOzf#dWEmk@dvg)Rfmcx0;n&(&XK$>4jfvpQrx^#druo z8KU1i{WzX4v*3K4lHj-`CQC~MvmJiYkFQ7jc;dVv+)0qy_^Peqq*eiSDy1A(Z}hXc z`VyB^+v$>0FXt+U^I7Q_w;rMh{Vy;p(rO=cPg%IXyClqaFw=)tUlCwyaa!WhM z)Xg-Eh=_$yYC^ujEIKE_mmh<~v(y=cc-#BsP^qZZ)(xppT7Fa+!RjMI1y1m?HLRW# z6_N3C)Imn7r3L{=#?9m#e}MHB!iUCmiYJd>O|02@@4cu3#oqGcvLY42Ny)rsKZD?d z#9t2%slZS=4CH}6mRxj zP(s7;%MJctI6A>84QH?i>S!hlTB@1s;&gKtVpqM>C?|5AsG1R>(B1j(P-VN3be@tB zHi-oANz7m>h06Sb5?VVG$MvPOW{2()6z8jB;T|ym>l(vlU7$g3pdGdIRHBL&eL&MD zHjL1sFHYc3b4oOmP$s89RhkI;%X<|Rqms8CzFtAZHORE|B|&QPvx#3V2AUIBOlZHP z7}gViRzf>Q;fX+%fTx&Ep&P$ZMyHV7_OsQS=yyE86ZnZi`^lA9yvdn&mT)g!^%C}j z)rPB*cvJQ?lbH2SCm~uK_$}8ubVMJO`=R$$oA$%8nB6a7X+ST(Qb^p2C7=)rT{K;O zGbDpR3q4^%P>!9ZeXU`_o^w4w5vAn~r@AJH} zCo~_(*ZBbckZKqq zym}+gsdz%Nfr8e^-tX!+;VY`@S)&z=4P1H0S(A;s%+)y(Ya4Xh~g zSP**TR5?|>Au}gTSMMn1@7km@MU;Q(?;HI0ldRyQZKaFS2||}N@8z6WdDzil3!pDe zt?ChXZF$6mTC+0oNu+8z z_B3e)dflKvXHKi4IN{&N6Vsm9n*{$5cX@2%WYLabnqd-b z2=Q071P(s)1sRj;z`L;FYR%BRHMBs*wZ+;%^m(`ezlgX?^sCQ=Civ2y;q+doFGV-& zvB<1M8Thf;82W`UvEBKzbh$;pgf(fNfIWe2K{UdKhC%Kla%;u~34M9Q=l4P~AE#v< z&fwugFrF}77V9>J9Eoy0+?2S_ApzSt4Ar5*lzB+k_Y?PhqB1RO0q8O&2a64Nt~bNU zpl`u))x0D7pZa9FTf^v1AU5_r3++dT+3|5@?-{b|qBUGYSQt2tsgp=7Djf2zlJ1m( zIByhI$l@0)XX$rnwRYD6)v%3S|7;&&BH44J4^=UTAZEt~HciZie{-F~I~Afb{90ew zu<83vcUJ_Xti%aY1W~~>!1nHn){}lNy@;`q^kz+Ob&HeNJB<#at!N%Ec~OGp$Y6Lo zy-E*IaWWF5){_%JNiThjD@h5I%MX%DJaNJi!F`dG5+vyMUmdj^A?Vr~>J4<2H5C;H zATbJ0COSS^e7U+2epBA>#$k)+N=9SySULy`T^jPTT`s>w*H<0m~G zuLJa`L%AJ8IX6%2X)t8jIq?Tqe$bPV8Fah9O3HzUnBMcYNXb||TwAPpO8x5EzaUM; zm&%;^dcELfFIXDE9b7AkEPP`xzR`g~hZQEi`@siI;X%vN2~Pa1>(zju(o?^R?EwF< zjX~(&AS8!KtnT}XgB0m}LC0-S^;LXqZ>b_0&lWdu%@8JT_&=XG(c_wVED*c#PZpQy z)#0+|<^FRIs>N&~Yq{0+>7vSa8BDjcL_J-=CiwH_smW@t^0{nD3GiM}?!g(_6o8j4 z1PMkjqh*XjLNkGe!0KS7-7}c5{^TIabL(3ZfpwHz%H_0bQMZrvzUt3;^t5CP?k0}8 zICvz1SPo6xichp=5~FGqb7Q|lsG;&W{s>CyA%vs3nK@^8zGLL6;ke}^HC@=a%!TTo zo>s0?M9yfbOn4~I!^bfo;sP{=-jh5A;}2cyXsB$b=o*N4BCnAxEpL`aJ~VMkUr zL7zV-htEl*cZ5_HzwJj|-9O#)4+8%I(U!jI#Bu0pjy{GgVpcx98yJf~Ppg(N-|A`$ zl~aqzo@a5ZD=)jiY){~OB=enwA9z<#UxHp(v&tYg!hqjSx+bgI@o`)m-Hy}GLYk&| zmLw0uW#9aiem1?g9}#}-zV|a2EJ+w1OWwdQG6h+glZK%^^iZ;;VW;M=%lnffq?>4y z@Kw{WBrQ9gi%39t&|nEhcO{n)=f>jBA_icbD1?`GNwO>?@zV4bBpc6VctLAqeD#lX zA!w$7s@ZF2{M*x=@6*x8kDzV??dzY+p#Sxi_ixTD+kc<0^lDG~zJ`Dc`sL;9haha- z9RAl_kn0=0O-A?$rVKe z({tY@^$#CFL)sPeEI<$S;B51`l`}H~W+6UTt*fF4&i@6^h`r*7y3nZk>An}{^7cm; zuru-sF;pnK3iqyK;hk|T_GENqt5^tM)?#(AR=hvqLG%)S*D@}l&*MuZ3qXt* zIkZ|*uhV}-ae2s9=H|v}T2`zS)Nk86+n4ER)bcTmYXzDx9fKdiuAY@Gb{w@qw23OqX-MmPd=gOVy z%YOlOy6fG$bp%2|uW}8YuP&sYT#i;S*{7*IL(=@X@pN#D5!ZLf{Q@>dX}eiAy2#*f zi9I@_UgnCe;rby~$Kt$@;6lF46S?ZS$6~jTcYlCf| zDSK7Oge4k-41a|llb1){LfdB@VxGCNbG3b z2F9FX$oxYZl$5>uLh@9-Dj=G$5KOk8JwsAP@S_s5vSfkv#C{S!vwed_j|>x13?+qg zyBNNuFq3ugCi>?7^wRh<)%Xms@_l~LShs?8NeuGOY$OY-sy;C8OU@EXHepcV38q|3 z0pejy#Fr>vHbQ>{w!Pyv#a9f|yJ0664Om1%Cj@mj6}1kS27!JWxX7M=SMe?_EJPe| z1)~y8&0@PYaOnjT^d7CD|5Ye@7c`Gr_hZqRY*x}Jtjb+vCNyrwgnwHw4+0_ART1{E zWAa&%NMy)-6vA<$b>U&d);lG%q+3eSz^9w&8l?(g@#bBz^6 z#II%mr=A(HIB(H{L4LZ)4Z~E%FdKqG+oq)#gXl$gYW!;yCasAv9S1&ZHpv8bnbb@R zNp}@-lyP(4p(}(&S7-3s){S2%nkt<`iTx|3e#U;}$~vFd4BPvtVeh(kd)k%ntqDX# z-L54rLjt6QgoM<@(>5U!PyYFURx)_l(*z$=AH>ePm8*{Dc8Sbvm4PqlX;2-OQY`4S zdo*yFf)3UHV4QbHQWu7=whpjqjlYo;k;J$jEMCMUZi}zHh0;a2LOX}e#4(E3V@KWX zgo0I(g8ZX&Fup{T?q8FpVo0hO7N^+0WG4^!1u>x;C+0g>*0UEePrX<+KS^|C&gSxb z!*IhM_w|d#G^hNh%pzuJR$#~H(B$@&H8$~%nLj{R?ngZ}s>4NN`ni!fmI~!@+ftVZ z_UG!)GNe~|2=&3Or0vl{=(0V?`6Tm~yOyf?LNG`iz-O!i{vEZo4!}9%xf2YY2bODLj2jSdJT-=u1AUO4<_nNV_Vk%_1rP+y zytC+k{1cM$(3oG%87>)C`t2-y|g@ z+8>FXc{lOj1OwMDT0Q1hW_I=v+2O8&qldTs^RG2?5EwM^^X9*{7-HnEVJ-(P+*a~r zZ1ppnQ-nbRhiH(A<%nwp5{3P-jb-XlODJO;+}X(<>{_SjFSbgs+XYwaEMxn8@EW z`rbA2Oo%vw0k79RXw^XC!|@m?_tBn*0u;e7GdrGf{7mou%--t4fIh_A8hixS$3J#C zN|2Q}wGh@H!%@00#q`HI{BiI195mMSo5#?z4R2wEbcw>zmrMjUCJ|{^``ISRN^ld9 z$$YcX_np|-%bQ!X0i^f7K{ban5l;wB^Dk8bINRf#DLCB*pV6J1>V^Ou6Dk zk*6XYJw_X*nK*~DFfqEU9UNA|XlZ^BEr&lTweo#xyEGd)4KhZOwH*{wfQ}U1pAcFu z*)Nv!MH5?<_oXVX)+l*M>T-W$;X6@3YDcpCQWILLC|k3LNCMQfgxu&1a{N5e9=8GM z9usCUZU@HzOy(w1Vj?AshnE>#UyG4r@v#YsB2Qk`lcD4@ruyjyj`XdPsd&atdD}$_ z2ra1T4THw>a|aiEJ*ejzOfOBEWGu1^NC+@MAmRspvJ8|k^l4qoVgqBr^Lce7WXbU; zjfB}gU9I!;Q77;2lZ;@*uJgN7ob|p;X4$Z^KB`qr52;SG4%gsojbh~uSqF|%&?Yg# z=Y$}`td-MGBv26mtpf@#Ul;d@sPmz&OG7h(7rOl)8RTz86hG~#GW~3bh^{jZL@Bj@ zWM3HC+t(;#P*C_>OJ>$!r9*xd;a~V45_r5c^z>Pqc=}&zDDfG>j}jl(&z>WQH8NjL z_Cb7&PfHoInk?e@&Wi^(b%Xcc(dej44n&!Ym2`FBGbxV`FB=nryqR~M#x8{r4`!lj z%KLY3#Hbp!JnhB99BXk({cr7TbLk>M_3Mv8_K{-i9S!5jbMqL7j`sGy^~5wWWHN4Pgmz6b1><%A z*vj3nuBjP02qxU1P~kW3MLB4Em;ZVz1aadY%;f;aJ50>uc5En?+urUC0_1J7kM8^T zJ?R;;CjY_9ppzdV|NcGRqbXwX^Tng62x)72W~QOBap#BeKn%t6+yl55MU(==AP{83 zcDrwHJ#fBPRqgnq$rKb8_7T?sPbBN~c8f3tTN-xeSGU!ZH_vM?7mN1rb^9=zQHrHS zzyLOp#Ah(@i*q_(`H_N-S~gh8{`l`7?X&JBr2fO*7~ivz z{OOp=8(Lu4IVtdTc1?#`w{Y#mN_d@de*5WflkpOg#Medj$*$|-e|~U1H#d~RX-v5v z$su$9WA>#rz_7Xr($45}4|DWt>>CV*EX(}PZ2#$5U`qZ zUL{k&9!z1}@=%J$m=-p7Tr*11u~gBm~@W0CTl_ z0+_G7l9m>s2N&=S7y;D*V%yZ@{8kU!o z7@shp8E@X~HJRO_HEfNM#4NTDv~D=HxG&>~5%d!j$BPWF(fc4_WYIXTj>)651ta7MmHj4Hyo#xj({ zbER@+06!-VbG3#e$ zi@9viXC&J5@R`H14$o76Nvn!c4* z;orcM2V<{G_o?SN;hK$0SJX9O;q$oh;spBngl;UTJL+@h!w}3s2Zbs#HB7GS@Tf0H zP}E4OaME^Axuv3dHMFuv_>ZWpZJm!0I*Tb~7)Yt%?BZexzit_5gV#unVUVjuX&=Iaf%lc#rymJ{b4{xK zRSV)b+o3tR$m6D;KM~f3`c0yQa_n-WEJCaew;k9m!9(3&U2-kc(bWYT6Ml^h(C+|T z14OA!^H$2*J+K}Fw^Bdh52QM(8X76f`yLS`1Cy(jA>&#Xpo53Wch9jehnJ>DoUI~qlv2upg zm_Fs}cmG)8NwU3Bzpyj^A5Aa()NMGXGVHsNW>;~9&|RXe+-71BeVN{)JoHt_1$`Le zf^QC?)lJ@0-K)S99Bwm@l_SacT*5O(F{mF=jCg4v$fB3d{p8%TP)jCCA-xx`= ziZ4RS`rRaJcAN|U$Y06snvS0&`e#1+*)!lK7Yl^3i~HT+N)PBhaBg|XWXdc8wLza{ z8O-wmtX3hFq0a&AyHx&|eSS7e3m^O$j9zEJob&`H*0bU^D{akyApG&;5{AM2&r!(e z*H1D>$J)=+cb4=@B8~K?H1{^1*f4{W`AZiNRLxpJ%-=kCuh`{&;31Y%XeKUIV zvi(HYEqC(cef-I|s(FwA1{!x&&0QF76p#19fUMklOo|%ySr=C)l*S)+@m7UyKLhCp z@8Qo^_2W^KeLHXyxk9dijSf^Vw!&%efOpmkrMv{|8h*lv$CJ2GoPw{{D=~5pU_onmp7@ z*${$_yK)RJ=x%cvl|{CZ;zDGfii&@*H!K+{{ef}E04gjxQc_3+4FVrA*10eAl5l+- zV==f&tug1V98Y0=D>RL`3@Nw^>r1ypF}wQL2h($r#o!aTQU}2}DeO+%E zzYv6f_f58#?mbc#A%SA#X=mbh{8!7RQg*DgM}WMlLneU0f6t!^j4f;Xld&uT*sY+) z;j0|8Ece$kVyE%3`)8vo|6urDyxim5%XAzEIB^%%Gk^>f5`ZIFS*di?ipBSUP*DF4 z;Jyi8dv zXj0UxNV-|~7XPXKcW8#_NnPqV^Uj>P!7zvwepDFz_|AqAn3HIgFN)s}-sbEAg=MG; zg2>Ax)u=b|3-|(q`4Mm=>}>QMD3m;t{z6)rs@lPm=%O(U8%m1UFX!dr6d~g0!6d(~ z-`oZ;yzp81jE@N6H^Hr|qEhO!R(uxYrUAJlHbTg9{Rofun13V?!NC*( zbyj9oMe5t}5`Uvq4}Bq3VM zZJe}DmV9V%*7+J1MIk&(><9$-Wa0wAe^Q7a8cbF~FiU2CQ%W5nT~-V|yAimO$UVc3 zM(d?|pJqMhUXMSzNl&nigVynZrk!*{eoxKZ9to+4#f7{fbBP#!8gh^Cmp`;GYRc>Y zWB$`R!r8hh9ul!Ni-0WX)3aGIi}rEY(b5R(6Ux^iq~iW*ILJk5*Jpew7ksPJJf9B| zq8Nm?)E5b_`%q^rLP9n30@E+U@fb6m~fDO&@I+39K_2)aa}iE1cS z^tl9S$MC+7a-sllqCNc;>*JJdmgNQwhmOwa{nc#eDg)^Se3@P`iJm29-xok&$srV7 zAu_TQuai?#K?Q}={SI_60F<5%3_M>$!sS8f1bhY)Jr96&;5pS0xaPsFfy@t1{>AnA z->HR6;8+=iWT9m>S7jg$`XGQ^%z*z6*x8nei z_ulmP>#Mfr=5*~kFuTv^wzRSWbNETxc1ZEtZ$cl)UfDxsK8+@-h$%Ey7|9ko4H2x|%y?x?rDoSL;;pucj$Xc5!^UQsVggOZ*er z7OeL}|DtAIX)eDiNZyi?P!I3?jo#R0EPT=9txgZd?O!kQip-JS)jigbh+g{RMp=!uVDxU|emYq0?4{7_ zMpk1N6>hYkL7m5IIuB;^R}2Zca`;OWZ(pY$mvU*P{JvkuJwzLQV-BhXYw=E9L~&*o zeblRUY+twRVDp3q%9Pc=`e+Z7b>NsxE-tnJZpb_9rY6=~iF^Im!!)e5y!!Ndvgsos z^q1qfpqzBvt7`#%4Fws)1?6lpiXEVsqW02utlKpU=F|fYr5|*4%gU_Z`2)!zaFzsV zbb7sJNtv0t4@C)|u`Q~ifFJ=L(PjhVo7E)mXose~HLot;dP_m%!`>U1u-+ec_1V``6 zO=oSFz?fm2s(N8WY7EKgTi7B)1%}upsB7@YbFxpoEY$*VFf;T%FDi$coZKp66X8>n zEJA9+yW``7-)IKIXj~=)-f{}%!*MbjDWcyjMcIUWY(=m5RF`y$K^>-npa|o>FM#j= z4s^!_X7xVgk`IMPnykh5nV-H*pZnEAZc6Q=AqK;ganj%1>E?hEq>KD5FtFbjG8|*7 zz#O-r_*yy!wCT^y!QA2b{&wl6s2Ew~@Gn|Z$o+H^q}+d1onon0pfk$l`*;t2e6lgH zVVK*r9?8+6C36V0LEbA)_tz(1{cW;2m&wre8mKVCBS_Ooc}$~7GuM87{Yv`E-fJYWb*PCp2)KY#JI!I3Uf{(if+4GQ{y$Xnv7Yd~;)a{$@(0v54LC8wtj{ku}ougLT}5ht#|Y87pZ z_0{ssr;k7m;1c!2W_kFvuHv?GmF5@GA&5W^8(tQsI_NEp;R zKr3A2B`v7M0f@E%;@rYW`-?kme{drO5tI=m!Dq8oP-;#4+gMuuKF1>U2L}rwF|`xJ z>9H~%dek3HHbaJ0J6Kkvl3hu8*5drH7G}Bbu=Pkx5$YV>3>xp>8-6r5FOcsBIkmt0 z_=pw{g+h6k$+SwprbsfircCb9=Q>;TAMCIO(S;pis!1T654m-lbcw)Pa;1OJgOxyc z_rHee{dKiCKPljx9-IFAxLXYaX0JbpQEc?&5POV@arzs!fnImNPrVt zbMq4XeWoE#zle~34}5^Kp~h_MClrb365UAz3a1wvQ#hOIlTt`^G>ODa7DIkJdxc59 z@Y(jHn#o+L3;Hs^q3{A#66x|@T)}Bp+YIn>-XKvlF1!2zZVWGJTlgKcwHJODDtcz? zTmvna2WZ6tfE^?bARczuPB)AAlj07}*t~5lh-7~zCsp!2_!uF!NnJ1L~1x z#_8#4z>Iz{SpEEz{@b?$g5F)mF+4KzTq^B%DnF}6s*T`155Q#^MF1xrgl^!M?e=(o zgS=tzL*^FWmv#1czXNSTkp(a{T&d&1tF}jR!BaGtLlT4AgS)kpXaDF3F9U~+ zBRsQSBuQUks}zuZE*10#31P^Ta$njBuX7ezYJFK$C^Ve#JgUF;?;s1@FIp#No8fy* zdi?N_i^feS9d7DhiXz9bUSz2%qy*cx@z!Z{gp+YW4td&*(^2he2tssHAu1BOev56{ zKYfg*js=n(o7<)bogF#ztx&NrL_3%H& zw*4=Vl!3GXnD2`sa9qJ-m0Vg0#1<0();FMy0e-iBkSh!sF2O5KXAmQI6DhmieWC?y2bfBLHeJ+&Z7q($a+uGXl@}RT2wtf1yI#PhZ2e#)?;-IAgHW!;gM_Xv`0f-3C z?%C`TRzXOhojn1<=gQ=yUlmY&CTHzTWE&V5U?)_Tl>s|%W00^xfZ_PCPcvL7zSnIz zd=gvnCyMlu&}Uh&6jlOqpV=dYcPiJg*}IjGxJ4ZUh&EN)N>Zgp?caT-w)-S?C#XtB zt2n{%T=a=$=-zMzKSNu;xoPfMm^Ajx3eapv|JG0l?6L2W7D zQp&6pyd4xYy(1Z9!pAUV%B?yPonGVR^SgmXYTWkB?egpE!~U^tB!z2C!@t~QNQO1k z^U-Y)L2{P4bvJ%n2x$=J&pZQj8q;obx%yJfGm%;SAb zk<7tO$1?#9^a_&_W19xM_aFHRkXc$nPxJGz{GAXf2as6^k+E!SpWVpc1~bqCrrOv8 zfSu?axbZ)J@WmZ!n|+&^oh@orju;t^veWXei!H0=pQ$JQ`u%MzxMP^Brg)SHbby5l ztp8cw+)QGd%_}UI&7KWh)Th5c_n0DVeudspW~rP9Q&x!ufm7Fj1%8?UeD@y_5oiyf zxQ*zPl3Q=e;sYh?ePSW@lh-M1YJ9-Sz%~$X`jU&k;(b^waSdtL48qkhijpL_rV9&w z;9U6upY~Jy378Yf2^>?TuU~uf6T=m26E&mjYV!Yu=+O1;(mi%yEN}&X%B_f1WMsr~KY6-#ANKl8VzjP@?Kh4Q zEczu$`;qBhUy6w}lmwKVmu@@bX?+Dh$yl^}naOmMp`FX7saPj40wlzt+h%06o5x(P zc}g}pCxOUHS&0>l<|QnhS1S6rLh9koZ$qgIMJPv&v^fbHCnv8p%%Oxc>;AB^u-DhG zp`l)OEN-t)5<^ZjFHr5hIHv-*aEE6{3r0Tl(cdSZe9_!ir`YvNi;Mx0{Q33EU;kekMvz;)rk+tQ?)&(QF?F8} zDhQ=rsJJ{sMG!3tT~z@3o}d2LcS)2o772|+@Cq>d5l49WVp2vhQmW(gmOMQ_y~0ua zd%xU`t|OCsjEqLpNx6+}F+P&Y3?Y1k|23&8`R(Fki!?G*_JNAxUV%PpGtWD>xZ1Dz zI8l)zgveJO3~H8~LZ6oUZaNGNLezN?a#v2Foclwu0E>F1v|9>i+g4w+7YIJ2aCwJ*Q7=W|W-8oIwN+u&Pi(47_`T6B1?A z-wAaiZRXy^Q>q1$s`zvQtXmd_DDu!3vVt9p2B~9g)u{%6gdHK&q!+1Y8w|1f< z*@4Hh$x6K0ilv|Ws;o!tW=zbmlhJ~x-o$=6*G;TGNJyE$*m*RGe33@Rf-|aF`ucE* zW~sddb(he!x7_e&;8xXv?4M?~V}n;y!OnO0xu^o!wwAl7j9uDJMUY6dZ`+_>@qb+h zze`OZ+}y-|+53F_8J?i)#W~@hmJe^6lL8&w8hoH~hj6-hsnsbKNal!-5{PjMQDwt= z^D|5e1`w@Wzly{0Q*Ys1UVJ75;$BVI9KlhT2I!$0KMwu~@mEy@9veoV81zFD7oq6v z30M@XH^OM!|*kT>E6xjI&dm5lvp-!I{4-KJ-wVsI_!mOp~{Op=`4OW zzhV$|&qR8ImxjzqCqygzpIfAXFKnD2TFo)OTO%#Xl<2h(^0+mtc_E?@p*5xVqc^+jW47wRs#dI&590n(p^ zHeSnW!FRArh*Xnk^U;z$Q@j)aN3y|;3EdfPN}v46@mT?eUhLBvXH#2yu#e%IhQu^a zph?f7n*L#ki@j=-Gy0;N$wL0;#qGcTraHBSl9{{w)vUJ)-1E^!qO||lq+8v08d+?X z%4u79XF#@6I@gBE0=< z9ZKd4#*?xVzIs1Dneklm6j33U|NnB(^ucqdo5%K+eGr-2RYC!?Hw;?u(K3nzLL~`D zvIMBpei6o5>hHrkzF9-5EknzCul+>eZkH?YdYyv5#eLndr`ldvl_9u=Dy1)zFkJl4x^c|QXXLugSn5%QQhjhc;MXkrw!Cfp`QUeT?kl%<) zByK*HaxHtKzZz-t!tvG6(6>YKna;5l(1&-%CHIk2@)6@gvm`y=)!N96Duwi#KxbF} z(gQmQfiR)EH&Om;>{8NA8h+L>(vaGB!SYGDQ*mVx{SN+1@9x>KnGQ=RfTpQxU0P5n z5934%5|s!DqyG~aOMFT~)m3lUlkAT=Dmr@*l_h?%=JIb~V2+Z61B=mk+Aj2=a;<>0 zepO7MGn5~=%rG%VQqvh_JbZXX#ovK5A~!!k;DEf)u=P6t*qmScKXREsNqsMfmAA#w z))_n~AL7(R*#G>VrD=8cVGDt$M-UCMETgmGmg)(t+$hTZWACbnO}0e9Om7Bb#m$^& zqJ)GM^7>Qy^36*mz07P1<0KJ4ApS@Hs!w;T+T7Q0vF9e|>0a3n5W+A&91Ki!azj?O z1JjcjiCgHlHl-PE7x=XwBZ-ii(*zkn=~7Q2j$|c>saAjD-$)GJ zD_U@AS0BDC(c1f6LeeOJjcJmiVBt&w2cxP!2e~!Em0Am4mw(eQOJ}zm0CBTdhZjh= zgLF?pIhcB_jd*vSPOnK%{rvqT3EK=4)^t|#WB!GNb|Z6$w@v|J`Qr994&z@YIhjqSYa(Qm)8{WWCOuYL|5QwiJ?~u zgFN#SEPZv~h!N8L>U69j(lHHh3QdOM>qu47!@)vCg4d16{+Ru%W$7dMI|VO2>Fc8~ z8aI$(REa3rdP9Haz{C1ViU#J&wFYskQ!4}s{=UUQED52xQul(WFt?MwW+OX|)FrF6 zn33G6(B)i`8~%Tu&uFqN+XGaNDCLxJ_n@wf;!%L*b(6I@gA>B+TVr6ytTAv)a z4k>s%ae3*mr%BI2;eNlqf1zo|ACQUF#u>{@^shSrx;9Zy|z#Woc1@ zszL9#=Vto5d$DC;V>S$-#z|Z~C!=v{x1GRa;QwS8U;}y6M8-t_$%@{Fp8O1%oZ~e+ zO(mRbL?>Yco0h)yK#-Beax!G()IzFcz-}lAS&Bf1Jw$WeobQOGo39u$V>Ix}{%97n zT?M(L>tdR_uU(?iM80Q=;OgVY%&PFa+P7h;*OEEGCzv{2>{n!#D5J7oh(a*k!q)aI7~onq1|L z(iuPQJd8y@v%-J^uTWa2_qe%J)Lkv>Q8Zhj!s`4N67{=RCBEO9#s`V(Sf*OC{)DIV zr`Bf~`Q?ws5-b(iN22~^#5R7+dMwKBktq%j&EtA1IKT8dVKfTttJyo?h|yLsRaKbi z?fhKt`KVC(3=tx>w!CK>Bcjg&liv$Yrc)uYRvh%;#2_i(GnuhP+rEg=_+{~3w{DPy zIyfv-xO-9>tHbzE&av8#Gv|zYkVY|1lEcVy-Am-29OwVpKhn^t?e6f}dVgf_OW=}? z1q{2$-F_W3v>)v=5!Q+md{k4WUubV|Vrk3X4#zq!sC*z^ERTPD89vqjOyI|etW0!y zM;JhSa_7%s_B0V!o{il-+3zexPQHYNWCT&CP>;GRwkpuu`G-aA_X9@a9gC@f^wI76 zMy`*BN=QD8Au|ax!!fK#0j|-nZ@LSl&ib$?wpKndnFMSyq7Bt$3Tnu38@{Z6OA(ZX ziZ=1>$?tEE!2jJcx8J33B5xkKI!{9$!dFkh9Nh-=!Jj8_juWB-A(=p6^dK0TNNT8R z_$$1#0)9Z7dvYx{s&m10tP9=ljno}$)8X!GU7ASsdrXP|Tve`mFR^?^@q0mVd0WYUDJx04y`ToXk34MundkqTuP%?y^FJL~W!&uQ8!D+s(GH#t# zyGFiF`;Om7YSust2P+XWiL>Fgy5>-k5Rm$HphQb*WDw?qTi^r*J#CAkJZJB0#k;Aq zg^}Jt($u<9HENF1f$2ebv!$1>MQp?JUpM`@FYtHC#WJ))kxTnYbB`0ko^3cNgPe+d z!Y8?t!xHrr0G<3l2vq+2PB;5h@L3l&c6_g!R;_(QW4&yr$g0|B?2m|)J1p++4jRSo z)2CuYRh^rR4*qp6JjOiChJv4Dr4<$5Bi~03OeC_oSt;Vb-1rHsvqhfL%DJ}~?^~XL zACe|`N!0V(y<)xhKT$pG${n>Hb%47s7?6_?)#B>J(xHG7)$%ZHuPxkI9{W?4$b&( zthMR0*4+D-#s%JF z3v>O4=f&tO^FBU+N7P+#eg0!P`)<-6`L9bhv4_&}dIYk8XzdE>{Le7GOix}n^zzM< z{kjR|Z$i%=Q&fTu1!2UW#sxN_0Dujw5dgmP2!y|)WN!DLCieRvNLB1^b+JO6?Wh$= z#s;${YG`4)3WdUKXDqgg{&nG5f@kpH^Dm>j8|;i`hiO#w*#m*U*HF!! z7|yvTn+1Btb)8qQ0uwr$FI7Ck!$zt2H>dHC|K4O1>zs~`t_$GJmZwAoo(*7XSKEYU z-A59+KJ?Unxt+PUm$o5&dR%kiFZb5BO%h!PNBPn8juPi)XBhAB;pdP?+@G+sD!1bq z&DA|E(Fb@By$n`bom#NFfoyKmkxJ+g)I){(FKEkrpDsJ2e6z#MgBx_m+Z_MhP>Cs{ z*R0-FgWvlkxS`&VVyks`E1Iz~t)ZgxIFSAHcp&xQK6QPS@z3|F{jIG?`TU8hZO=Ww+6p-(otwDNjWP0h*ql**CV)Z+750W=QKjoggc`ryG-s%Bal{wQQG zAz~!<&FB6n+#!HTGJvtgvUd7T>T8jLLkNPg;*`_TN;?ec$FKc&FC7*8jQADss94|? zbq8x@d)TydrH+S}`h@)ueihU4{q7Vl?}^t zhfu$fSEY<;eBR%lmLz)9<^BIx*B!AxK>PH0C_TP_HD9pxPBXfiX%spaeFQ7n0Ty52 zDeJB6qOCXa=J{BI@9!xwuKE{bAuP1uWS#ueyfhaC8^_%37E|s=pXypp*M*WAo z#tSdD>QHn4jQ&moX1rvhhmFAv*ajUGt@H-NWvrmrn-M*XkIkn+OOD`QVbU*M<=uJl zR`saN))~Xw*1T;m%-oeZ_}_*<-{nrHFIn`%&C%-Y_zl?ZV84A(U&E7*{RR5~qF^Pt za{#5t%{BBn;qVkwSan{kC&mC*!S^MC!P9g11V~;v2xm)<6CX4+SHVjwp2H%^_Ic?2 zC#t*o=U545;2_ghmT{nM*5is}OsjezbE2W`SV_Jl0(2VJ0Qq~+)K^ohb^fP;Sc}fl zW;av%fle-lm5ojG;e0BZi%8$;9Wc)VUy6$8#@MFgnKxNLBbW9mh6F^P6SfaDtz2YT z-G>yDY&oLRcX9>w%=KtVtTO4>eDgaTg~?j|t{-7*8Sv0?AdG1I^+jxjnFHOV9WY}T zI)>yiJW)F0i)3tXnd386?*mWf8vWP$z8I%cz}b8aU?v^xBNhJ_JV_TMfXvVIb^@d0 zClm4+m2}rbiYh7IKiy7b+ehSB$TKv0#K3mj7c=3#E3nnf5i4|pC#{&2X_({V(rdp* zQ97*@Jk3N9e|Lzyq4dC)C&kb(y_2;v5HsMaTrbYC z??E7_<{00Z5_4Rvd5*}jU)+V8i1y0IBx#=X+yf|YMlA*&9k)Vp62WmqLKnS~yOwE7td0*yFt<&e9aXXsECH?F^kFFwoP!C?@5H<)Z4;Ar;bMXJW4dAUacL%nt`jn1`Mb zs|6Bo(AK2*W$?WUdGFlg^4&_{#NAtEMhb(?r<&`h$G=q`!tBqn!cJ60Oss$zs|$jI zpU|LLmrQlL0yRw6&pr>&9WW2;1M7GRvemF?vFfWFu>I`+ka;#lhgtYng2OB_JfX90g3oKXR{)pc0=7Xu<&Z;xk!{}oA?GMtbHUeWpRxP__=Q;m=8{o7B zOq7On?xw+v?{farv&}=prXolC`6}=OIqH0R1Qc83U<3h+vhV>fPBS!ulZuD|oQO=@azYD@Xmq=lXt zH9?*fb#1%RdW2eG)tgfd8~eK{f07LvSfr6vOn>`=^TIwqXx1EUD{}H?qBk~_3Cn5W z=q45!+lJ$H=BgC=vvcAp6|joI)_f~d0K_e)n?sJ=2%0RarUdbM-L$`;57ZBY?@F z;BPVFPhb`6#UD>%qbiz2{Ak$R!HAxoo_>JbarAF-_R7i%JAR{K)Gy6@YIPSvwl`=6 zPB02^b4^SxW^4;3O$a;HX3X`SyhOP3^VUmH6pb}5&BA(S{<*l-4fKi-3>1N|Zi%tr z1fLf+8>0W@N~uM0SlfVRL|wD~rEtTFBz zP3Jio0P|CL#DNL1yZzD+W%c^V1zoU}7E?tHKYm~#2oT0+-)}PBArJ7FjqBAI%N}Yr zE`ddFT>9PVaiIJBhkWh{!d@2mlDpr7atg!Pz456Ko^L(EY(=DmAkAePl{`|!;)Y5b z6b2)~Q{y83`KEP?m;EasqxMJeKcdwPuKqdie?HFjJSvd*=X}!p;RzHStG3?YRj!mA zwAo?}=OAP23U7uqRCR7=K!X!Vtit;E=N>K8j+U0dan?SMtkhYq`(73bYQC0~s*3AQ z-&+=gp9E7s%v&9LIzDiQdwvJsxv5I@RJ^+z#PsV;X8lB?i=*~5LIjKRx52)O=-X9Y zmbq&L;(G1-hc-%VkR2)rv~BHe3wV!Xm#`vDHSKSJuxK4aBRMoaeBe?=qO^pG0l^%M zYJ&whq2+K=HJ#QHI;&Th)M666l^HsLC}n*kPKq^kQml~<5{gUWqf7f9dH;Gz^6a<- zxdH?*w)V7rC396VVA3*rzPOuN9DX>YRm@O7lMX)NQ7ox$46|3RHchE!uYoru8b*F) z`j7ft4*{F_Ay9WmO-#3~$pXAgYaOVzeCgZ>Yi@;}*kmuXPV2CR@pdeM(-TN5PGGHD zyHf75pKh`NZ$NRV17JS=TTs`_FXoJ&{NTU*Ni&Opc;&Oc3CjF;=$C7SFW=LsOIUDZ zP{0-cJ?)nI%l%xg%lTfp*nHcGC4&=o2W23$cV*Ti?6MX708Y@u#?I<*ted6K7~!Gx zG1BvU?2#V?rRxRQ6ju+k`~)3W-)#+!`JYqo%0o7b3XH2UHG~J#;v8s`Fa2WFXZ5Nc z&cnMEI=n4G0g&mwqj4Ut9P3N+)IoyXUX*{+Qy0qc)*PKY|>Hvas-uGGr*1=CY7tbiLPKeyLStIEV~LnT)6~ zpO9Z6iHo4fzBS1gc6*8p`uzaa*$5EAMVr91F?v`cO_9>${MNMCy=(U>ii`A*Ayb-6 zGFhDwQw$;xVJw$k&*P|XX86s7bX4oV(1e7?e*J^&fW{lQFQOn)1Cf#F`J^;Q=Y4I~ zF}TZqbl*z$Sls=UKSK@JmTi!^2*{^hA3Wk#ug^}NO%cKSmH}KaD{iS3yy66G=u0q^ zB?N(b29QjEOUV#+tqj8;>yT}tF7$N!ZD{%VZ}sygszP6$)M@0FOdEt0nmq#K|6x#0Oif3p)OV@flfN{G z2VOn^lw1yAJ5e|)%}I?vn~Yi+-04X97kK5ve87o|b5@F`ddx6UOXgaozC!eyNf=^F zN3`7K#Tt@zg~cRMc~zzZ-rDRVv6GJ~bwY#U`B^!*36*>$?)PtrLw?FF!%{ywcX3O_ zH^IStmi~d`-z>fzlQeeSERjWxGhCdn&a&?o zOej;Zs-B^y&YO(RUlWQctgvHDwy=I+w}QnU6+UV^16f#|7PjD}+)F!Netut2)6Px& zf2exvuqwB%dwA1GZo0cg>6Q*rK)PGHQ$o7Cq(K@f=@L-sZd9aWOAAON4d2@5JkR_5 zzWs;Sbq+i3d);fzHP;+tj)7r)eFe0$--33jKp@Hvo}L-VNZStAfIx{9qdv~TJ)CxS zI>xI%4c|b_`ePu5TVq-7fLrBO?Zf&?mO9|_mjmel&~pU_Kd)66WN^hmyBiBVe8c#m zA`yR@*8caUGMI!XfB!7Hhl;g2Q92g6M9`I2Rf+!okOEjyTwVuDa1IYH*j5_hZv>=7 z&~TtLm;%sE!J9jC5+a%Id7d$#c!9Y z{1vEw%dwn-aRRjDEAG&nPF0vZ5KMz4|EwYu9*LC@pf{^S#`Y`F`}xL|8q(DF(s0C} za7Z};0i~o{r&sveF_}@~W_}Xx%SKoA6~q~!bAkhdfkR#$Q2+2+dAt3mW%cjY{s^1mzKVIRK*%|#$)AgfMf@ora? z<*ADT(}dyVLm)75{T2w?^+sUZJ2?@{FZ$f3YAF8}4l@T&q*y)?mE{#6NS*C`OO&`5 zQiiY?xeYS``RUy@qjt`CUpTeSI+-Ma~Z3zCUv9&@8EeR(f&nSp!wF60OEqE-G{Gyww z8b^a*4dDLuD*(~%L|DY}@}cNLiW0~zMQ zS3v9?bO`0pDpqgbtUlb|Yx00zZq<=Y@y*(u>pzG33bh4wVEgeyW&AVW$a2i9{;0&z zR8r|~33Dd!x5FJ&YrRu`MxhXymQ9`$#sP~<<(YM>mn7@>lKe_RZy3TimT@hwT$_GQ z(wLfJMIVvHa3zF+Tb@cmZ^6+sC0B_@T(rqbVBZz$Nis;O zbNPVdm{*f>Gl{9e4ZG<0@n>=DJwNi)0B1s0 zm#WX2+ZpO{hESxr2tkWBo5$Nns@#7!5Se@Nx@6b>7IwYAsJhE)l{G?#Kv!qv&cj|1 z9)*1gWr)Xg+nhi#N2xu}(sSiJUiT+!^Dd#i=qwa6+Mw#)OjmmKM=PElV&|UHScm?J z00>U~LWB*7zMjm?mo&9vc^R_&JTn3>-ISLO<1z@3Z=;%r;}q*9TO^;kh=eU%%$T&9 zX1>oy`)|Kk=bc2zn_;F5Q4oj;n3cSD3L~9>vx$sJFfEo&39QCwp{y*yzw~74)(3rH z**Z8!lLNBpZwK~p5X|2TyE8{-P-1No*CZk=e5aOt`|p;}cDWWCYI+6+C%A$-;MM6x z2C+m%)_o3=4rvKzz(!Xg5PmDjAk91J0@_$N+Ct=t@W z!6uHeiwPWE&-T#LVkSAHEuL_2QyQm+4&g11xH#OEo6v1-5qypurwfoATPyMiekDZ{ z6FM8Fep)0f^lDJ^UFzxyl32e=$UugB*UMza&r&Ug{GKog7^lF`byA{$n69vQN`_yc zWg%4kCIi+>p$Hf1vro#5vfnDWTS93Od@rLiACR;`u<->u*s(l6+wm@0Pf-i(5-ik! zueyivfRRfs`^sUVDf(_-+_qB@z7c}BQu0$9Yg}Lh$g}Gx;%}8xA6lA+es-PBbsJ%W z_Xi(nWf-~*gYHW(=iI@-Bb#jENEN!it{9xOKl!WI3xsUxl0thad}_h>xdVOH{dY9F zmXXHipcvfi6?ts(nspsbzo3>c^vUH@~kU}?lvd1@@Ovs zcMZ)cg!j^e*JUKBmjz{C@bC9HU#8s8-nd=ZD|y8hRa}@)zSkHRaGCf`A%^CXD=`Oz z4y()7mB$W$sWgu^A=^JQU_{)b7Qi^Q3^TjlkZv7wsKuC{jI&=`<5sQj;u?thKdiIgYI%6*s_eJm^Z*V9*aL^n7fvP*{5`Dae*UeO*Rp{p_-*-y``|gKl zS_=2Y01FA@dElvFU@rnH2((s$%8oDmweHet{p4^vPDa?tZ}nM4%)nd&;-!SzviyRA z66ezzH;&u~UbbKh9swDrbK54dsm&A=FAF4*HH!rAz7@-_`X07lw`C0bOoAaS%k#k~ z?Alk?(b1{ZZ^keIUlRK2;r1IT%c=m6fA6ChcH>-ufLrx=8f@YxN27!u8t z-J#c~LwI0#sxc=$ky!g;=}^q`8EB5H3tGh~3pirUk2CSwJ0Wt3dyV4-5-&kpzEns=S$s9Kn%y=bS zqfZ-r?HHTv1>M~*WW9jtg&aSe^cVbegL_KCO}4b-0LTJQ>wc##2J^G=tQVv%phuXP za@M0IJD$#K@hdppkBle?#ojG#nRhCF0mVnaf*J+kSHO(NJcGyeUPn0#Fe7yTW*Eq9 z4uRCt51vQv7%Q)V);L|R2pO455Qx*Tt%ShufPDG;tZ5wl7uYGW?&1Ykyur4Q+t?+0rF6h+JjqUr>+cQV5>M%7{0A=>h`!4kg6?Q9Oc$HY}qm4_plb~#y zbF9|D{(2g(42}idR6A488NDk`puGzWOamv0__wv$K>uASxqkkV#qjn?-Q}=#z7{$Y z0`@?=nUy%fDwcW3YgK4|dKd674nX2Kd%pM?x?(Di+NU3dOLIy5>`~=v+%-jpOptT; z*wcHb-WaJh0kj$1Iyb3$!xwAmF5Hxr00V4e>5nveBP5?`a}|XFrC$$fpJTNw6E3G4 z$Uf$lROx8`ONWY{BHxL<^aG~v)N!d)%RkMZQSiFU%aruA>DT%#nYUv?(iIIqq#5L8 zAQwGynKgs_2L1O60>y@!nh)my56b~4dVrx2DAmB>kUKvB9VfU@rd8hFl{}-mf%;sn)_seyrOf`%(pFRQx)Qtc4MC+du*WY3{kYEj8vL4bE6*B|vkRifrM*F&=-f zglgi1_hLe1o2ZPfsZh5=;npJz{V#0xT9R+Q?9%cHv4q9^=Zh0`QLc`=N7{;P9^{X4 zZ9+*f6Gge|xX+fhNuMxF7d|x)OV5se;4)=pWrD#>UHJcI9ENAZq~pY;J&wDeZ_K%Z zpU!XFoZxXk6r)DH>1+pS9Mz^CW=J2QD@7Yv*a(%>0gCPy83(rmWzSUZO^iFZo+IQu zD#g2K9N*+p`;{n(z22FDrbBi@qM^@DoM|Ur5b+&qW^eQCQBJz*zDy@-zI(R#k}t$6MMt;gF_ej)gl$d`gAs~1_M4YKj@#Lxzb@^z1y#GJu126 ztVPnn(oOQ{S4DuOUSh@2qOH^W$c5?HA4_u}NArmDyzb?*Ed5mj>(}a%LbVhisSo5y zX$jCWG|aJl^PKgJ>okkFKe#`-6ZzHTBfpUiZQe zIO=D&pwiX#mkx|5$Y2x4d8~K&NX)$ z8|z;2O26(--PRKM5gN?2cNysmpfb;?QfLx*O@Fb=Sh2jffT4bxaX}=p^!q|c*mFR> znsJeY>8;Ef&Q*?1Y{kLEu%(OsTa&Ulr`11AO4O8GxenTuPKVo2ULGZQ4s|m=PxL`t z+}M$E{YE83Q2oNDgv5)`xy+hZs%id6Z(;{a@%=Ac1`ZDIAa-K!v6#+inmvb|B*m4fzyAY|3MtPoEGBiyUy?r^t_-;~4cgWHpomXo0xYC$X__Pjs^c4#n^~=d z1bpU?P_-x!-?$3(Q%Hq=C*@P)CR$9HK_Tn)(qVajHvwU4jLvH84NeaI)7@9Lu5&FbaZD{qX#vwygf{hiPkC)7pz0Lfi%@`ID*(Vs3N`+ zN?@tscW#Fu%|H8qlMjm7va-hhl>kI(5E<_L{c?~5z?rl05goHPyCj?kYmeoq+7#jl z6^_y;2Yq-b6+W@_o5&Gy8- zyNY=JiM`DUlEGri^LOe^k1lw9Z~t3P=4`UuYZ5qb~);j z;?5Oa=Hnf9MKumxzUZr7{`vsFaIDLJ`XT@$#NOE>;3W07DQ&D6fG>Dcjc~ve&%PU8 zxi{7+=zTEnzLssbw~)hdgeH@i&>1E0cKSpZ3_oXH8A3|#LLMri&2kKQZH@7cz8tgm z_q(RipR8jFn4{_4;nh+^U$vB9nGO~7FS=KAwJ<^0a;jcE*HLZp&{BFp_ey#yvp2{E zp(N1P9pF5ET2jqAvajtp)M}a8TRlG@5Fq-FUx%!a*roliO@Z?fcols$`w!)rX~T|ie!zc0p|=r#NGgW z0^zuR8;r$hD&YpK=f1w=Vj)PGG|Zt8@PF{F-*Csm{8~Rm6B>~$?BmDFgVdj5C8@C%;FaaM$xI~hVK zdA5>^JM12HrWWe6mJm^;>Xd4ci63BB$Ci6JIy5z@l)ht)_pO>c%u{hD_=PPdK531< zeo`*Bk@=tmFOE$& zimlT5y5=F*s?yuz03E>RNz>AeN;~vlVZ`V8WGA4=pS2fQcEw%*;v?Y35a&<=1zGF{ zlwS6ei%G@K=}G5W--2>9ZN5PQ<-yBn8tCy)*

      |(DZ^GdB)RIqmne-zG=B&0NU_z5MkUMUR^bl)RG*@DAo$r_S zWWt%j7btx$idz-t1>+BJ&0)BArbnN`>6d;(s9L0&ugC_4y=50_-xSyXF0~^h z-A@}IdVh(~P@ud1U1FW~l*YWK&=f*6h)R0$v3aW%BFt*e^aJMLUsiCa_NDCDo1 zR%RAb5?J&gmo|O`Ma~Sr*ix|d%Lbal>YC+wUC(R^#HCe3h+QucOz<@+yeyi+NzL#T zx|y@MOmZegBk`4jk1P{Lw6#L4O*rdg%=T zuscx~d$K(oTg$b)LTb>+W@!X@gz}Q^j8?ZhSuwI@Lm$T&x?O~NiqUzABb50Fb=#ux z0g=bW#0u|N28DFtL)~mtHt$;9PjX2ufpUhI_!AC60Wx>L`ca3|@UntNcnyku%0o-4 zdJz=#7iN)KOhpK-QxT0d0!N8tv_%$hgq|lw(*^R~$ea3qaz4%s9wuP)?7Bg4BAk>| zEe)t#4tK$nQ%MMc3iJH0S;j(1N_JvZLd8#II&Dq3b`6GV5{xoWODG}vW5dxl;)DQ$ z#d3)E;O?1kPC-&Cv6UWZb09#y>m?0iHpdk> z{$s7&JLVGofM^hY88?dXp{L#oYCR>}>6(pmCOjd($$!qXx^SJ&d&E(~WFv}EVQ?`Z z6Fr~&`Kzr|cxYRg=dlH3$K1^2?(GCD@z#NsLxRtf=%rDDfa?VJbN8VCQ~0|d(*G@U zZ*KnC9BWP&#oZ;qM94tNckQNP45~yCl-y@h6h_d8TaO|F>%1IscD$%`d`{z9j+`73 z`rbjYO~De<65rWVp_hKOOmx*S}d=TQy){YaJCIwAUFs#n;Tb^tQUf*EU5EK8L zVaV&>{640I2sj}Q6XVS&#HWuURcmo?WNT3?uY}iAvWMXfs58+1!HZPf=sc zrrViuBC{hcUwYcSJ2x3&K$FXkj=>@Q_W6Ue4dH?%kK(~p`;HP{{0(K=#;fO39Et;9 zU772n2uVm7gpm7-PPscS$KH{)o~#bDp_KjOQj7 zhUQFWKoT=QHFBXbZo0g_Bew5^U7>hM*#?a&2du6UoSz~&d&*UI|j-CvmRL<_lOJHs0*rzLW zF)*&ioilp|<+1qP{ZZ4^ft5>cNnLchv2s|}JV?2eolcpErZ6l{rip}!_mQhaP*znZ z3g3OKfd$0`cdJqgDW2mKPc&p5I-X#8?3-VD5_TbUTDPF~L;5s_~j%5m>8E*V}*((iJ&m_^!EsFC9IL+qdrSw z7sAKk5J_Q=Q>^M#e`WBIZDlI|k>#_kOzdM@($IujtZR>pauC%V@dVjS-t# zs0szX2xS_s4}@i7B5*9_p!1271@7p7TWS`Z$r!?`$`Csn5(I*TCB{IuVqcZQSUMO-UjpBu zsYk3&J@lGVd4-s=E)zJ#U4o@wM5a{JysL_fn*J)4@|qDXCsp+`$CRBkcWW!#to9J~ zz;@7LSKk~gp0m$rE{||qyEFj$Np%T*mEB`_S&7+`{+PhY2E(q@c0_oTSr5|n`}1nVKBq2G|JR;%UlG}S(B|h*Z4hc% z4J7v9gfDnO)BaBcHU*Fq_zdnX^kp(=<}&nJ_5elD)Mih(%ux21j`uM_V|+tAv3*Su zU$u_gkh!`|M;zW=7B)$9;bppDy>&nic?cuz*9XI7%*-N2X2`^W-dahMf?PF*{qpWl zv6=(1W7bdAl4%uVD^_ZTLJyB6qyZEOm;EY>Ad0&I)`*y6w54pS&1pH{e9+3am{U$o z5>>-%QBcJ4tZw^NwgfTbpWXpf}xE!syJ-UlWi z$plwrqS>W$;n=2UfLQ5} z3PK$i)8*T+J8@#GlGH0qFDYq3Pj@w*jM@uJ7A;IQPU3b1d})G9%g==$jB56J!<}*x zNKklsxvSPa$8@D@7@Y&U4g3G}gwy_}^^~Tx-jkAiDns``@&<=_Ktr~UfNmgRuXKyM z%3qw$gG_YFbC3Sbyp6oWbD&uPo&TJ)ms;eMtTcsbN`m(G1kHb9KkwN?f1rg(>S^Fq zfz-bi=|mpTREoeS1H#2QM6G*>3r4i4>=3@XH zhMQ;ta({Yis>6Ike=DiprRk9wS!GY3uABeS-0KP7sMim_{?i2JE zpU-CutS54!7k^WEAmo(1Fp=d!Hn!>-NzbwEP=shHeRc>#+ad1rMi#=1B^(0!K_wMu zO+Z2f{#Ed*IU0VH%A}}@DuU)ukzVn_E)(${8=Iwjzg9d^BP{>j6XNw>vN;SjQdE+Q zUCOBA6c5J?r09i$Na*JWgrC& zkfWfiFk>NN1>I{o+0)59G|5%FT2?NH)Bm?3;FXdNF~3ZP`>Ft;`B`J%Kfsy&6L4?> z8b38@k4>rQ#(JdY+M|d9j=IriYmB~tKLJo%UKUu82?)H>V5tUOAjX$nNVw?llCnp- zs2n0919&&mVrUj2hXkZPpnTub)TFCGorBE<_3`Hvf5zODK|LT>`}pb8<EG4)T@njECUNKU?2YTqb8h=4eZ#uu4uV5Lx&Sz2^qKd4X}hxTT9&N ziFpHE(p}q@)c{Z=xpTCyb`pQmLFMG)(LTJeTg%3G7j5Op@Xy|@U`OoI>=o{K-k^t?qS0uTFayrKBom6*Q*~uP7kP(;}3Q|+#LdqT2gZ$ z$mj{UQ+9OQ`GFk~29#b)uJnNWat(NIcE4~%kGkNNjO~5^Z2&VLP#-_rB{@o)j{zb; z1`wA4IIMwly9bcmG`U%r#j<=X$qG6gz}tZIX0CvvKH#()7`)Fr`dJ&${NclgrY6m| z3#9I#L1{9Ze-A7`?@8a4(@~TA@A|Qq*qXzn?qJ63Nk10@03|0_iA^mn`Cz^os{90C z2i*1!lzP)rQvv&ud)ClBeq}Ehjk*;;9JOs**+5cOt5TcHoZ9b5s$Iv{_BZHCvWlCp zdo5#YTM-2u|4x9-a`~sbhui#z;%)HX_`Md@a9^4xZNPQR0e~OCOlNA0Dys?JB_}5X zmhVg7^-qgVKX`!)9U%4wJpG&S>>v~19y*=ZT7Qlfoja*y#wL*{6}y;ixSFx#6imN{ z^$=CjU?Nb_FZDMflZ1p;jFzG92^tLV-^z>K@ID;p1lbdil$+m1a@0Kk zPb=^}+i(8>L56|Mn%RzlOgLi){xcB4wM-;Uc%w<+-^P4wx5)ZKrjGv64rx<)EA0?4BR;2g@E4z5`l2S9ChIBF(9_@gI@yzW#IX|vbNp^8Neuf6S3D) zQ*#B+9SD5dFAc3HN^}6)gbS{!E#S(N{{kF}8t{E=KFlvqfDuA2xE=6CS3qX@2*eg8 zz!GWs0a()qfL;yoL;IZ}IH=Ks$r&{S9x~XJ6K!7%gIn?fG5Uk;$DsRAnp;zF$MElf zp-Ef>AwGPdWbu(FU-{J=X`#5Z}Pk{cjdmYbq+bTcmHE z+Sfc z+}s34lOOYr03p&7Fmrr{;iKHPP5mbatTcGK^D-Gew=#@8v(is-AC7S0Ba)FnwIJS_ z3?gNw=-US42EdznxSf2M7U$&T>^%Ff_=68v=X?g~VBk?Gjp(s!yFGhZhyFY{}5!GIiC3tp-ue!;a?M@-JtTRT3h7+L85>{u>FVw z1b@Y6uNwI1*MmGb2QA-UfCG&l!k)!A4Ka6+1I}q)#-O1TE{6-|uh{+N z`im)MLdZuB&bXBtV*D`pOlH@vf`>T7_ zuPBSh+K)k=%_XU1*#Lxy6q$F}%5sXHyk{H+x?@1MO2`sTJO{*4sWfAs-zD&*)sH-q z<3lQybfw6f9aY&E`98Z9otOQbQ!E9>cz`Ub18k>d);P6$$>oJQfS5Q&cU8IdE;0J9 zVGrs;+z>kbHn*HXLvAQD=2dt1ej4Jb1g-b)!P{-Zg&E5=%q@uvyZ=PBfJ)r^`ZOnw z>DBW?zirUR>$3-fQc#q-=M8)@!}ktA3YCW1E-O!TPj&{N`n`xSg7?*c91M)dXP}Y= zM3rjCeSDRKBUaYIV9i@*02i%2K;Hl=xH(%cNlMwTpPn}TP`&{pPzOE+=mIJAbE5Jr{=fR3~Zn2nzWR2@wx$9+%;Zy!N;b0 zMmCpV57&x%lEP?fZx7apy1^N6K;86pTiMiue0doj6ve`ZvRfqhcsfLyhEBjP+!i3 z_x1v9zVY%PuZwJ>!itLDfP8Wo?xyp*#%fIDwvvXiyvH@u4j$rw==VKnK}&RKi|$No zY7JV3Pipvv(S)UA=qjf}Pz6sR6#+?ILBXlx$_o2dReyJXpAv*hIFnVZu&L<{xG4~y z=Yb;}@cq$NS9b%O7HP(flFIX%O8=#*mkw`ep2EA{vq(Iy%Lw*xYMd6 z5)3Cm8TTB{T?U&F&Kr7LkV$x9B}M%DCikXJDI;1qyYqIScmkUP+DzuDqpa zmi|QvA^7JcL-dn|NI%kg;_EZMB5{8OpFeuOk?lINj4$zxj6O&l!FkM`XC<6>z>fxA zIssRh@E=#VBUtyEZgpd0V{5B7NPp%;CZ_It*A9=2c6kR12l|ftEk}xGOBM~ap+g7 zCv${PK?_)}n6E(X<6b5y#eOeqY&jg*b2i8DaVQ(|Yna-!h7AIxQ}BbCVbY)AcJ-Q% zpKuDWVC##=U5~`bT@9ubNy+^t+}x)WgB{0+ri84 zQ~2v+#_o&F&sMhc>8D!2O|^f)FM^ew9nK^60h4D5EN{386JTNg0=5|I*3`9Wzfc-} zp=m?(yNwi=J1j@&$10>WS6)13AN25X7@AD$o zXvxM_+>FD-69`~!6k6+Zazu!tuy)~bJ-NB&d-ZD+m3C;kKiAf#(_R!msxw>&qYrgr z>ABxl#~M1C;@+HhP)M#}l1Tg@-WBSL0e;UC@E80~VeGo1W22TUnNjXKcFCh_wf_Q$I)4FsJtRXizE4FpXf?pw&D$d( z+%O1BEQFU#TN25;GcH9+IX!s`wT99C{rM}y)G8WDmS~zt3@&w%U$d)*G=%TfJ;NbP zcp9T$qrLshnfB_pUZGd$tM zlqqN34&3}chf3Ul)rN!hdOxT%RU>ZIzL@e10!@iUM5<>)M^B0S7Dc{h5Tq<{)tk(u zh&c3I3!(3*P)!BL93`!Y*A-_d*%w#LfoDs^yygt2#$Wn^}jNh-JC;vXSiD=gM4Q)E>>E# zw}3B>|30cVs582g5WkVtV-KZKrYn>Q$@w4J0hozYE}O^oMBZWh5B09B7TojzfD;|i z#u0|i&R{^h$iG76>7w2xDLLuq&{}*8rfQs^Dbfk{8Y5FO_bH7T{+^8V(IPJ0jihiv z${EI2TSkTC8Wtf$iRRSs42RM3{(1cpUGlFN>)SZ%HK>I>_kP7G?wpLd_jU-FE=Ehgbx-=bH+`<$6f5q5H9&}~>^5YPC zrW82WPmmkU?RXDkuL>?LkoLO*Fd*|m&yc7$YcKKBjYFD<3}3p&jgFB_6Idg{u-a?4 zp*XUZ1?`ly-5#F^pN^Yilp;gXj!7>$QwTT)(PRedpjLGHrl5}ZDBQ$)FS=%(fmBG~ zV}JNCs^Uc)%_xE$U)EgQ{?ki#N#4W;iz%oEIu)s?4k-quytBcH4foGNphE;_bAZ>m zM!1lWS0MDFd(|V(q%YR_Bb_S3QMW8TVXAG8#7AJ|{OnjyHknb%4uy!)Fy#@Vl_qu( zIwV$4_Ypc4KUSO!-31?n$FM}}C!k)U6%fB24=Ya?Hx-IP5G-z&X2mMPsLMl>_WMH8 zy!mITHTKDTx%7U?7p300nRRjpssifw#V%2e=%Y=M&Y=_CH1kZ@yQsV2ofGl++pmi! zmQpUYd+Dm&o5QIYUG{*m;D4*JfxDrB4zlWQ$X{X$EbM6UWw_tHv^ppC^^Vdt4S6le zovIr0M`Ybke#KWB4{a60@+VP<#9w)`39PnE8_i@r+VCRMm+`(73A!kyS`m!m=s3g} zW7v{8t7T|?aRwA4;_26T?FgbMZAGp`zJEk@mw3N^!a{X{I?>%DMU4B#1SO6N;y3i3 zTPRO4Bah4*NGd(Bk|n-u1;(b#rl|TCeoTEk1Aq&h^xrZ$5a)}$C8A&UwMKVEf+D*> z&`k^aXryAKk*(ssc{n31zP7~2P+{8+g3jq}mmJ4u9%Y(OVaRrz;Ir~29S&7PBSRlK zRz_SaTGc{x%xz+^b9zxf&}EQd|AJ`0Nmx-vm(&<39vhsOk31jMTRF-WKiA>g-KJHk zD;#_j$MZRsZc>#ttRxD>l`)0_ExS0HHaj980mfihZ2EWn03pX# zTLnFjewAe=3$!BS6{_*;EpDAeOu@GY%=wd=k1hJvD3Rk(@yO$%X96V>E`BeI9f(T9 z7=k#t`p^A7APWSTzJdBeryuV{#HRo{5NpyCRa z#zRZi!m7)IT&P#fLj=`XXwMa8DZAFe_0s|Jzt4W~^*hm4jDCxVC&jX?H@(1Fwab#r zYA^0jtU#%a?d3miB<7OD>}NNKX+Woawo?SzX}fy#ba!o3&3(oCJrZ3Kf7_5_#<=64 z5)8poX>3_qZ|Mi749lEgkjERL?1&|tXhi}#LWH_~SxxDMNY~b15JF5Bx8a zmMFWrT84#@>7$l~45okYc>}fUVO4&50+oWF{qTboq4|di z)Ff6k-k+|{6eJiSgGf|1ikOrhg2V>|{#{*IQfh0Ql6~=)dWa^QsLDrvya#wuzmgB5 zMqCy{Ys~3Mirzk{*f`-vNQn9`&%%Q%^^k^_I{MIXcTzxrIy90*(qfI?|D3i;qX6H) zwF1)v5*ze0(<_)^AG6_(8JVVlb#E{ZqdIKe>l#M%TrB00gC!SHOe&0^tHVJF1Fume zfik$uCZQa)RI+g2HoYN^tU;9QE2-9(=h;WtgfkV? zlTIt$pID76LX)xEFHvpWs1OA;(aG>8f+t8w((sblBOufLa%33Q%0|=3HESQ;6tM5p z5oV_d5JwPTs6jSHMP{j!zMb4;Pd~`a~1y~lWqW*YmB!-XkYODLPO9hZ)JrfwRWN24{xVguXS;Ibbog!MUz>(P+L=f8Nn_S)d~x5oHPIp{%L{+sN%)E5a2)$ zj#aRgD{y7@=b90Xzp6mRl@mC1;Rn`!|AqWj{G%kSO0m#UC60t9X#1zSQitVi>5ka4 zu!Ow%XnD6N=*pm*rx;HON1I|0`Ij_q8SxEi>nKu@3J`K>O*IckCC%A3LVrcS#bIA@ zX)9TB_aQfP|MrVDl8g$O=Ij$)%XihU@(Ku8ai8WprZvBi8%lU+8$zpF-_ zYJ>_CVEOz-D$l6x(GleknokPNdp6~r+?u{a*@Y~x`p+fX! zzQ*s0L-{G9@~`m9T3dx&xI=Ab`>K!E?0=miJkjj#FpClpm}s?B{3P-a66h$?}_;Op~qMq6PchGDS8gg zbe0UdkUerJ2$UJ`$BJG$je_d1uvJUcr*+h~#XjAqk2txN*w(Uc@^82@2bQix$DfG# z9{DF${dWO22kt7~V?3mZaH6i6yeSksiO%mNW+b6R$bIwXjmrU|D=R85=g=>vzQAZ2 zyEtFlCiW=g=jNuZy+V-aReuB<59fef-(wYa?s(io#vRVF$K(tfLG z;(qc6qCf?y0dk_QxFNcpZgpuZ&iC`bu}O+NBKr6!n@BbpTFJz!go89BJR+tZ^I>uO z@L=xkh;g8$&5F7TnJwj!Qx3hebZWgUk1OG#i2Fh}`Tizp@LfK=cL9)2g_9(~YZur; zmTnEucxfOCA$4BQyv=#!I6Ux`=(cHn)(E{H@>YoyVT#sI8$H^k+9TkxiA_#gln+Lm ze?;7Kx~@&POb3^0@^mRIcIQOvI5JR*edcHLrBLV3P)6KXcdIB&zu)XU(-p^Hf$gb$ zaq!-5y5Y?B08gEM47FNq>U!f_w#@UAP1CG`bD0)|cdhBwdN>kYX0m5oYmH=-SD~)# zgu=J_OV@I`H#X)$g;J@AGEYS;V3UE-|6aU^&`4q}ESK|1IBQq8f(->Pog$XR_KeAV z1dT_~6M2*Z7obH-;^ry}IY7ySK`jPw?kSf-mW5DhnU(2Sm29&#*J?`|Ir2!KGwVm% z*(44J0G5RO9-ry1@Bk> z(vk28&NB^}MzP005oL7J5g=sc_`qNCXYlJ6Yi%1nA0z5IO`Sz_hvr^A8(n>~4^}_|y-D+g&exil-ydr-W6FDLR)PM|g3)ozgvHIe72? z0)4<0FtZSffL|%Fk&h?kmcFs;i^B8p@Tko6cVwzO*#oBINio;!2Njs|KvA06v>^1VE7y5hAf}bdN{4H*tpzaQ zCv!z3)d7rEQ&V%lM$!q4?LPTkodBCT;N=_u{A?^OE#XQKp!ZkMdBv}FkMy5n)X$Xb z)XpA*DdMkvXyoLpudotewCGAhrLWi^lDB`xgBl?WOBv31Q;%0?rwnW(;;ItSYZL58 z9juM&*w9f~ihTx9_IVIv4(UVDuS%DQbwi^&r=UNf^0uT2L6+wop!9^lriO+5IOUqV z7L=mEc|Fd@k7$3+louzpD+4BN^nK7)24A9p*uykI3A3tXJ^5`ZSxlcPp+JBp(v~C_ zUxgy(xH+Bd0}xjqeVrU~_#dZKm4K5JPz9s`^~kNq-^T@4ZzDk)HE{ge06v=(cx_2> z+@Rq(@(VFsyGi~F#$C?VfKFzga0pCJ)`VMmm0wU=%@&$W~+d2_x);@)G|}(jrch|`wJCn zsO3cXF}TwEh7Up@n8il3y5^mfne{B6J&4dYA`d}mNY`*W^0I=$Ou$u8Icgj4NT#5S{EfEZl=bBcp6@}M2h4hKUIS#>SMVN5ynCv0&K?V@*W};!9~JF zw!rOu0X>+Y;Q1E#^vt{e$FQ5z=<}NgXj^-GuDL)QH!w`G0an(~pZ~_dU2T&Sov06I zcA3J?pwce5{N@L?;1ax-A2i9Yy7Xc{oNzwCE4FoeS@}0oDV!B@4p){3S zq4a`5EHQJ^7(bYr`RL5|h;Z*1sGH|E-|nX2iNFH{zOY!ph3V{C-H|B-Mdc3QPXWAx zrdfd63#oCN3QboKPwfb|8i*ct~?XJCng+W#|%mc$hB z_y+CXng9gH-3E9(APrdDY)@4RHp7*EMLufoI6AlE%ETy-hQt*QCweJ zyA+M(RW_g9ba^b`bpQhwxDlNz5W!niZwZQS(+L0CDSb5ok&JKI1G0MXlxG*`tO-R70 zewt7azk{vHxg%P*V_YNfY;#~WCNYwKSTQ{KX*ah8{r7L*3KL}_-R`&V$Hn*-+T6>c z;7&SV4FKGfzQOY|a52c}r>_273^m2&~#`g&ikTSl{_%iH*CNT-lEX;Y+j-M5LMgb|m) zU27_FN(A|}lQ6{aS5}=Z5RA6kH_3Hg_N-;Hl8dBLD~U){6AU(N)3Tl4e-?Q(^KG1FhP+K!2|DVx#TzXSq^6)154-qi>)2uc91sFiv=mLSbxD;--u z*Ye{5vFoTXF=S+eV&Q?7@^2i+uEKCh zuKqycwby?hZdF(_%ObBhBVXFTpfpo^k$=_ z1o6~l&pfNx>Q-t#fA#?`AoS`cCW$QcFJw5+ypxX2B_2Pa2m9MV3xE;xz#b-U59X#_ zdpNh%bh#S0pa~fD)Qy|L0P!bP$0TOqLFDJsinVF3l#sqBh?z-Pfu!cZVhF&84*<5W z`;z`Lx%F;NRT(1kNUoqr{DoLIHgaYuVGv!PR_;UK-xaZrkGo430Rza{$SNw;(;1}B zb!Mw(b)QQ0H?^OV(h+@+iE;T{D2$=lJCA6rUZMNGojvAx(t?vr@n6}7i(d1RjR_`wl{_U|SVj zazQG`yswmXsx0hxlvFnr(I9^qUf#hH{4xYYT_E>iN#A72rlvUVgI>~abRf;VJ;nKe zaj@9J$;-4m28*pIDJ~FxFFc8*(pv0U~NC(U+mWc z1w+t;jYY}@15`etX^sm(`@G&@mAS2NzJB1IYMOzwW8g-hg9(-*+yi`ke1t?q!b3e% zk0x<-A++WsP#jC(ta<||QWYxxADf%cfnuf~smaWMHRn@B6vLRugpx)y~rQnvayDcD# zRKTEYM;Fw=gCsBFx94hx=I&UomKf4eJ%-k~^x*>yKEctgf|nc5g5D&Rx{(b3HH#ai z+(h>k86n_}n(oA)RO`n{4hW9k)-b&md6UhS-yg_#!}j-XjtvU;;LVD6t-Kn-rBHSS zaVrq*!+Z90MMXs$j_2*)enOzlEE{=D)v)m;1#V9bVhV4TuJ30X7;+AysIU^R!CF8J zHnOjpimGN-R*hH3(=dsPgC6``-+}2(be41=)4yD3qcR^G zk6o`ekEdWq%W@aMDr_2W;7`0DxBJFMsCIpe(})27*Cz}|Bvu@&u0(+0 zU}y0+OjOD91}n4e$qMwjHLwdPuc){<`IiwJn5cUob<-sbo zZ*b7s+WPyr7HJXx*GR`O%%e&!{iuV zYN;QHJTtB8>T1(BZxG#gc>6|e->WS;))zqVTj?>Bf#T%~c{qqfuEALnP2M6NU58<;v@+>VX zvKmO{1I%jsXpc8DEpl*m%7EyUe(G|5FJ#Y%N01zsl#~@oTUE_#x1=hbwK(D2U?q&Dc#x z$Nu)Ts%k+|QJSz5Ol}2=p%W(Ik;y!K@W9;0#v6tp*VomJ;i+rtHG5qRLT0!#^OZOk zf)sSv;Sbx}+l56%_qa`ha&2FAiB(#I8Aznqx!M2Fbz;U{ID}`Q0uTZqq@bj!uApG+ zrxFKh{DZ^Fs;XIVw$;Ga)>WXoG0Re>DAE0a+rig0|kjcC3xdvANCjGI*er%%EFra` zQmzJoUfNBbZZO~h5^xAo2z-V{B`Pc-VWOM1;ek}ZQ?G$PM_DYRC541pofa6Qy5P(O z(IOlH+d@p<*xZDLGQl$>>adZU5JARe1U}{gALSQ+YrE(Cz1=`xNuoJYZ8MMX-lC6z zxD8iq?0tIRj0mC;@bM=_E;Mb+>FH@zFd6fSA2`|=W&Wh7UCs<=oXaW8lD%gX`r|0K z;HxCIi9rp=Q59ukHQiI zL5{ec%Ud%vZ9lop7x@ju*K{NcAHIfOuZfZTped|2&Z8P_Pr6yq>oRa04CKCH>ogVw z^K4Bh9f)~_15#dKaP{!Tdm;Ce(SK>@^Qzw(PnqfW$Ev;c1b6!pyF=H_zfP0~2zeI* zg#NIdlZEdQ_#iy#PINTp(IA;GeqpH`b2C^eoy@w-Bm8h6N}eMe0YAjS&0j$PvcRJu z^1bB<5wSLYSGRkmrM^sam8oDKc-f3k71_FnMm{hGzicWeEJ^%^4H$dsZzYn}f|v&9PVpL@cL5HCLc%pH=u4O+Uup5{+m(M8@s2PW^$+j{lMO+q@!SRP zPk25O0vHSR>c7|3O(i+^Q^EJt$ryf7WH_Jqk$E>UH|MqA%gnP~&Q*w7Zrn{8>*|V> z>?<4;G>*0SDPDhgnVITHe9@2Ck4n2{;=HsBp&}4*L3mrbmorkP)J8pcp)`t))EHXM zhaN?%dG{CgQm~-wIxcxN**&tPfa4_T_kL7r)XyC6#zuI8EEP^R* zh0n!35of_wyYlb4abjl;7d!QV+NvBS?GyWd`oI^S|0<((R7K=zFn^i~oEE6pU>xvz z$Q($~3hL@~RP|wrccJ1V28#ovnLavu;|Y6!IUEk6(<{Ka7UfAp?A|!IL+8ka|C~0b z15>Z@o5wa57Uj`>Xpl@0`@gh=RF_F^<-xNrqHt)?xrSJAD%CgwQ@q7W)Aa*0`)$m9 zdpJi8&LIxIfP>`o=V<^&6LlH{sAmUUUS2}{9t3R%B(R^%YKi8WealJ>&{EZn!03w5Q#oQ>{B5)c9Ru6pZ>H%PcMSHS6X zcpv_0)r5XQUXgBXIZWOFYtriRJEWxMVmX{R_k8^ppRiEsczD!z7cX8PSa08ExnZe+V}Dh3HOj4UF2L#` zT7uR7&pI}pN{nC6@Dtg(0J=2CoC<*-r|b0V`3!Gtk7U3dJI6we2k&0*5KzmrhYT5x z^OC&i8%_;N^G_OxCNrbxKFS{Sr0B@Ht3rlG9TJ7nCNu4(aCqsP)UU1PdM(1a*?&VD z;@36WmNno_O~PM$W-k99RvA%!c6yWx0xf~&vjMQ|7HTZESYK<}-JG8zJM(60*iYbZ z*^~8U7i@{40T~$_NG>2D5Q3x-O1>@tt%Fs)9%R*&K#F^D{@ieck{m*_k7=o&CWVVk)I>W19UDx!Nbg#Sr4;e_ZMc!Yw6a|#y71>(JdwSA65 zq$;@@2(T31Qx!LS_YNFf#~iGhum0Kq59t6A19HE0I1(TrW%tAN_ODq96CacYG=mmx z5YAzZFbCt?i!p@83}*CR74|*nbKU=vVl8Dh4tgRdU-vbAh=Vlwm4$_mY7H9oKh~g{ zezkP@;cBV(FtZwN%Hy?QoB!zJrD1p=1h*W{%x9a=NXK)gNsp)lSrvGRLTvyS9^W*MY->Vpvp|mvS zy%n0=^t2vZM6-eeoBEA7^%{nHReVzaMqf~&s+gqcT|eSaeNTzYwbV0%vlS)kaJrf7 zYZ%i@lc4v#GCOLHM8^B0TX#fWxA?%*V+}L2>%MQp{fEPK%GmAa|DMS-UCjOiqBspv zB7w*Q)^_orX|l|`p)&&uQ7G(N=tNTRZ9<->4-fU}-ZFlJA416prpI7=-w3iX4+RT# z0|Rg1m?4w>GhDcXQds(hNC$R6#7F{A6G6ljOwnPs^gy_3LWqO0JqSNcsK@NVBgH6y zd9r^V^!e?>mD5a$*vy#*1daYAR|Co)dX4T?L52E_h>F`+O)ML`*2&qkrey9mvS+YM zgpIiWt(r((>%~`Y7@aMWkD&URWQ)Jz<_d*$*c7%|ypIYD{xE?p;sagAZJj#Ul3^gY zyWsV@36}R}fPQL9^+|xk$;wsrl~SBs7@7L>=SQ6!UL!xRZKaz37?Qyd0`EtxtYEF% zwe>Egl7_y+vUk)tLsP zZBU!Q(;6+*6&)_0uwVv^_2&TBs*BEqh8`Wcq05KJ(e@-@Z>4_yIkQ>E*Jfkt ze;KSMvX=j{@WN_|YCGd+bSp#kEY|e%v$*8WQY?eM`)t>qwEQrm?SGx6b(>!?Ie^c( zhR^$TKi>)gSXC!=il?7tKoUrm6KMbf@l)}ewHw4IelETaABaJ^t;)sCg#m?w=SU`Y zvG~PinQ!y8WT&f}+m&%I+346<$A=0y>^A?2e?{Wo9Zp#dcjBtQ+lg%hzt8fs2TC#dgkZoDM?=!}o5d3ws66z}EI7*rXrW2=+3NB}?1SN&{58>g~ zzt5V;(;`RzGfy>x1MK0OZ?69NkB9Hs2rc=ZsY>^y+ltttjpAgqzedOEpl)j*Pf5pL zk(yRMY?~Ddti7$4EkWF&C1WRU8|(ia&-pjDD|$co-au-SFA7$ooF>vjur!8pC3?t# z!U7J##BGx{pJV! z?hvSR%<=~dD#{{qK$X0*w&wdDw$GT!|6DcKj_@AZ{(Qn*mW7Ref?{J;lm@jHP~459 zbgusS1J>I1pTMqr5~Y`Xh>k^{#-F<>mv6j_pK=<`)59T>GW3a~H2Wv>-Wjbyt^VPU zR}Tb91UA$o@Fy*$JGTR`^3~@uv;7cC8B{Oz=gTja6 zGM-Aabuq>4J_V85!UF=`W(qM+S0$xTY36`JqlQ2N+ zBhj+m=kmneFF#!_f!i?Ab(rnP%E=K972eFkIPGT!8k7bCqtF;>ofnLDs#7vuY(IEO z1Y+Km_-0ATSZ5zO)ZCG#jmsx{+K!HD*|9AAf?b$7D3GsR-)ZRymFLk7sL zoCMb1NZdqoPqC@N<-Yr!FDi-u5_H|~V;mfptRxJ>GqOp)X=J$mji}TTKVUwd*dqRV za-!&#^R9=)JN3a$Sy1#rlJ)r*5^vFz?h$pu*{3GT3TPf|#$a;l34FY(n0WGerxNr(@Sbuy#P5&eS8 z9?c@2tcFxZ>@hGzD$3%{RxSLQ(ecv9FB$uBOJ;7P=d}miYq;)}yTAM~`qUHE@QtJG zjZrym`tb+vQn%i?V38UL0kwP5SshRL;&8$imIr4E@%k1z7qB@8f|~htP~SWdV9RHj zJDRvv_SOIyA*?d7E2LKu6Q#6 zOc?64JTyGQ4xD+XvS$QCEWCa$N9|^tl8-i|#Zi{3Je`A*@T-3r2I+0QofO}l)ptnu5=8&uJM z8x~RSEdBNi6AR#0dN~zAM%YCZDf%{!7qffn15Y5gRotcu`8`zOV*UxgK#8SjI-=H$ ziY@f1&Z9+lMHA8k$sGbyMZtz1OfJq)f--`iL=x%6y46t{c|xDIs}97My@&J>7fp!Z zTJi+*bM!SDCHf&Bx={5p+RS^7liQV*H3MB*TNN-(C@O+u<+oawODBTYvwI4oM`(iBAU& z9jBZWJ0Dhp>*w3TcPbK8@p7IDOX;w?Y4&^XLC**-VI2P#b!Cw}|1zp?p4J5)Q!5px zEhYB(+%e}85e`BNGHJ(=Fz#iY)v7(E7c~weF7^=@qWbtXbU^ei9%Z9vw^j^>f)8V` z5gh#5B}w9m@DxNhQPOjbowHeyu^QiueUEQ=tTuT?F( zkjEq+wL1<*qxwRR(MZH+`_{ad#C1W%3|EP76xVE*mI<6D^uE*h`f#U8;67rJ5y#Up zSHFy)eAj`2`dN+s_C&y5kl|Ix0MDwDbQg7yg-vAw_roykv*%UMUcDup(R+e%w4#QU zWs6Kn9u?o9OiA-0?5S-jPKK|mVrDFFcvN2jyz$C|l*$XM+$Q~nZM=f!eaQ@72JHbydYG(H>r*uivHOtAG&zToZ=h>J7%i_DGGE`*xq2d}%9guRi4o;@C8`bhh!77a*SW zAdU#Kr7hvPP_T}r-8!;q_`0!f_vCQiCht*lsrY;hnWe( zvPARiiS34r5!};CXr}Vz*Yu;N>Z;1TPK&OkHvyCf(6^u2ng`&8D+VZDIDOf8Y zS^+g(%`S{1fdf;~Il1e()FvjK{p`Hu?fLB&$u)U3C0m#T_qO9}?wc*8v&@gk5Mm3G zUo<}P^Tn~6F_t1@Q#V6bLF2{}Dp8@6Ixeb64ljCk$b8&Ty2oc>MmXIbmZIR)ebu5J z&uDFo;>MM!VuD?bdJyHor||g(o5x@6WcBPH^rYZ>Yqof7f-{y+i4I)xs5BM;1yK zStO>rUWyURT5rbk0_E{N7CWrPe$q>}X;)?Z{;!_p1jst}sH3F0bUk#h*G={{9e+C$=x*rsYl)*&S{ z5w0Mq%Ut4hW*SYuf9cc8^HfV>|8z4+c%Ji4M6+e@KNmoud(G0~BegsBxI z?h&rJBpp|bQb=I!7=V)e2RBUpvhjz!GXC2xcTS$uw>@$`A{*Q#NBWF`5oNT@^Q27I z@R%g&4P(MNXJB7gl zU+;$zp(#-fr+G;;FHmK5Sdp3OwRF$2cN{8qtve{w;mta~%vdWLo)YPJms#)l(0-KH zfUm3iWXSt}gQE2KoNvGPBcd}CEQ=Owx|b%ejc$g9br|W6e?HfBO|xP-eU8B-5kl2Z z+o9}wV@>=@PcXl-Il3b`;!TfamjnwPCBBpKg7j$W5MC#DccxKT+hF}Er{a2OY^&Qk zIUc9PXicKw>+7!k82F&b+tmZ)~jvM9k2?fpk| zgKd-=Jv@J1cZRMh-}sVqMcTYfkgiPiPiwXP4wT)mF2$tgsi#Gbeh&YE38r3HU& zO$c&NJO46VE3_}u?{!m}a_2^`mdIA&3&_Ph}q7#}4J9C$?4d5-tOxwCWi+$75k zJsr$7X=`_Bx(U^3>95X@mL2@&I`inF?Fw8|SZ<90&`Rmk3-K1pZ;2B6;UbTsz8FRpXzz+oDCc%M(4v;-E-0?8 z>cz6ugN5`suXp*$nvX?J>PFiFZs#~?MF zjI$MuQbEB6P6T_D@%4o5hG&X{*H)%>Vhx7G^b<(N)~} zBf|D``tMxhE0!@obnMx-VJfu%v8$Ot{x7SyjEtOL>_73Wwz9q#Kzh(hje8*8?p;fh z01YzG>qBkw^fi!?P*Br&ey;FqWJFy<11Lbd&#X&-jxfgrEc6BDJ;-ldZXEtmOVQ2S zc-HTBzrx>LVV-hH{@3V<;j(wW(o3y*Sr&w$Z4hrnzn4-()w`Gco2XyI@xe_UO8WWn zUrHIv35ICFwg-|JgNZ*GLL#aTu~N<+uuYLwO0GY~9;2sKTX^5kDOtOWg_1E%LgdcR9pjtKLsiOXkk1)oKU}ahLS(vUM`aHL!@axZI=tR}65@oMx2geF%4yD$@d5D8^1tua4 zdYBBz0^Toq5IW$X<>1E_6a2ZYzWt!N)wIW05GB&y*lI@W?GKZ4JN+*rj2N;m3pH6q z^gb?hjD-uhGHM@_6Wk3Va3vnMD=;k%GEMh*d&v00)_xZcEB5_iZ|RF3hx)sPg+<+g0aUFO>7Q$AI%+9A zdq%ACY|5ElU}4$fgL~7RAaSS@ADZA^F5G7!=&stWs}l}Kdy+Tm$!$FbkGr;Z?2#fY=Hf+$#{_1b;NmeG zuDAO?)1jNHdd{!{uj}~qoABg`SahB)O_FQZg08pgm~*Mu=$bB`GXicHy6v}HIR4yI z_!!x9Oz9Em$}`xNBD0>OM(_9xRgeMQ_MJkW7(aCq)^LY8k+%)CoMj4CkDM{%vvU(( za4?qkAg^zI{*FFdtR~Hxvy~veQiX9xQMe||V)+YEx1%0mj~=d>bN&cf&fE%&RC9cj z7+l{>_RL?!HG2>^}F9qylT$m^h@q5|^(Rpuv4HV`AA76b|iYwO}5O_|NJN))>su)fd&22&h{ z=k1xo0s@PbBh}7%AUm%t05K43a@|{kClBygJQ^|Gp^rHAEOTx<=v?a|Q@ zg|0fl)@uhoV$ek7rQmxF|*S zLT+G-*|W|@?%P~t(NY7I?L z81Y;4OjSvEV9*?>7SSk?{R~Kn&$DuJa+er;`1on}@eV8(S=AtnxE6)oSBM97)|cLP(>RO6eCyYU=lB_(eSLO(&CfJ(Q@ z>z}8Q{NCM&B)h>fdT#iLhko>3w>Wv!5(;F9*W75kO_ns)zmlPL-6^RKqt0X&g=m!W z-HDN-VSjsQJ$#U6=H^F*_`!t$PwMi~ljmmj;o^e}G@-%%>RA5l`HS5g$*oV^@lp&i zGEi&jS8s_D%Ba_#Pe-E|$3|B9&%9UbNgNS%f1OWUktk4ARB zHYdy7h`|wRjAg^|8b0g0a<#_`xPj{B7D_{GD!BgnykY3socmad=3ScBqV%WFf~hw#2m?@mBn>p#)2HEH?2jHP$BTpT z0IaXT0|zn_-@kV_N^(^4sHP*$pIgmBd>Vh{J)a{_aeYWFFT?WhIFnfH-g1(a_q5ia z)t1Z5cQ5n^@sXy{TF!sXrpR<9-Z)34+mA;pOX*39Sn0u?X9@b&tPdX+R$XF=h3yl} z1CN5RkpfBvv)HJ?_fePY>)OHDgFnvL`X-8q zmU})l$cU>!pItFK5UcU7sGeA02KsQ)`V%?}7ZqarFR}Q{cpLkFhr@A3`X;OL^ui$7&7bYXDAE^uKj*Rd2@NyRb7w$wgw(fPZrA~UgwXI420zF zTmL+$29M883Ia2J;@FrM1!Wyc(AyvV(!vK!iH?~L-DQ0^i$bdVH*+P$6M9bMFT3~+ z!6|7GZ&*k=3vTT9Z&CU?wcWk#NdMEvCht!LA8WJ$tKBleb5zGAqAwOjMAIShMo91C z^x4AD!?I)6agVJTqdSn&%;{}N^{`6DqBeRkg0gWK*czCe|(saU|mmgz%&Iy&=#>``DJqu7nm zce>?Em!>P%Rqub%>|-8aU}(o6AaDY6DqAxwNZY+Tg<>8I15fAz2)5_n4`Yj9K_s%$ z5{$2|(*9hBtHa9#r+9$~B0V-XHo~7LGCxLNzftB!=dgBq{9jKE!%j?A#`WZZ_W(vY zXCl7L{An9kHUD+(n!^J7{LM@~Y^pXoi>7!Do+UYY$C>+DW~JP(jR2p6&V0?~ejlJ# z;vBj)1cOP}I`H4!A%MD|z3vR{Paq{UmN^)k9@1O}QVK5KmTJXhT3jLj5sQ=`W0uDi zyxTeXW`N<{TcwM+Co)colnpw48ms8UMJ45XpRCOMW&H9a?-|C?C4N;{qWXF{NQKPH(brGG~|f73FWV82_j1paajV@ceQ%W33vxy{sw zbm)ti3N@6`);PmBALP;dpG(P=F&P+E9|V3|BGRM6Jken}_O-FlrV`=#G>^*W#&T3UV-2gys=8PQ%?ovski!?QRY0T8 z0oq2oCWz+5x!DaA59$HZe7E^};^rLTCkC>izx4(tN0{UvP8ZQV1#PC8l@o`5{|-tP zg*nd58J_zH&b8>3fc;7jCv_*b?(2(ZJ>Pg&i0|``->RX-0C@@YB#WDsAx}Ygw(c&r zGa90-t*n?8A(S>}e-gH;6nL3d!i41?)ecHl-pACR7x`XIK%e3&@i6M{EA?&hvU zgvfJzTx`GRKAtm5M617!pg1S3PP^P*&5ZisK>!wR2f?zZj0eh2>o}s9`q=#tfG=ot z_ojwuw~|EI5-LA@Piu#fUgW5({&x8NXi9oSB{9`Asv$HYJ>({o~OIX$;q$* zK%W>4N2yh@K~srdt}_Cy8rrAq(PQ|b5vtI47q9W|I!KEZdV;#9wNo6mv$=2-nYrVo z{&Z1w)@E=3yX0o`g4xTRhSC`G@YI_D6obZXB^vCu&?TeN(q<+B?p7XhCU^ z#Ii}k+0lxlDt5L4&Uo;&B3OC=0LlRD(oU_FXLSb1@q2YOJ~{X2+}t-{kh8tDhGOVqJ~UIEmolqP`*7_^)4xY2cBf`xxg@y|0$uI+rUy zk-6F@+xUa9oCIG$PMFaeeDGL>pJarNkhb_`S@!qu$H1L466a+FQi=8|h{k=q(iAi3 zdCfnvq-4#J>_h&M_&0WfD@M&IL4bN5O43x?-s8%%p_Z!;2RF|$&f^e0L$`YYkTf1G z(RH8tS>KepS1UEuzwl~iYu8FzX5GDCB;EzPP6O8$VB`TNcl9ldvjt_>_o^y#=p7XGOxEemUPy5ooAJ24n`05gy*u@(VhkeKK3!XWw`tI_t@p8Rx?GwA{f{v zE9M>+eEj(F_}Dp^%Ak8d7B{U_OPXW7-L(e8$V3|J=Nm8XxP@Kw|0jY0N z`}m`imt>5?E$ujONzg*qI9&ukYSjE?y1uj(JfL}g-tzy;IbW?Wm%}{YDT|IBHD7Nv z%P@RW1kDAhc)x{h6EN>TLhC*U*!^JGR`tL-Ph??XA+U86#)uiBpvZ(@ z2yiIW(Y@tvP&oWqS}ow11v?Wo2BftOe!e8Z!3w_Ry7fTEEMt6Bio`F4EnZ z-Gx;ED6>3xpj~5|#qS0$n@A>gXakG@naJ7$WR`b5+Airo-qDXu>lCCU`t3c&Gu%D+ zL(_S=Mxn^WI`v=Uakz4CN^(y0_(y)&8Ec`;6O@m%HQ-$bfSizV|KY|c!UuOjOV@iF zL5vuHzv}oDf}R7$otWEfQd<+*_%1FduL74FH6XMs9H32JQ zxD?G}nVwo$T0Tqk0-2m~6GdeX zfQH%e@p#bEWMtfc?pvlAen{WYkZG63ET~H7!DhFvt`7b#?`g^xJ*WcII{%$QXfBG2 zf&8`wuSyU}|3(O48-SC7!zdhnQ({Ey5Cga~Gkl>oa5?1vUeDnP{nFk&9d z1A2=^7iZ@=VCdH!P=5f;yNS|&y;tQ7MwbW(^#_cM=g_G%1Ka7Y#ICNc==<`3x*>>P zI98?$JAIpjJAVKKfi`G>0Ox^V_DL~!93&r;lV3?ZKo8&o>8rEzV1{_}=g%Ev@KmM8 z##T6PXgn4(8_uM;T9?Ove5eM}b}g-mqX~n^Cqw~@z*=7c2?nmIa5W(ui@!V_RVOC= z8wKwV@n=va!3MX`qZeGF%Nu<+qRfFQrQ_)vKRYGS4sw--j*K*_Y3h^C7eN8~Z>Xj& z(S=P@Z_e}Dgz@wLx5yt@faCd&A%5)p=g%u(*@@j=3J5s(oO3^Ve)Ttl)3EL4GUJ8^ zryZdiz5roE@bc*|^ymfLnsEIfhZYukv$cVg1dwROLyca_(n>gOaA@dmH0T%+GCO#5 zMko;~Z7A}(w;c?L+W^d21Z3g{v8pH?J*XwdK+0zpMh@Bw;3`Rd7sr z5ZneM*<^SJAm)LK1HKe~p$i`_Y&v9ZudxQf>KnkrE;7BYyj}M`w(1!W0qI;rc?np^ zzFTDU-0-o&FcU~h5VS5L+xVHQM7jk5s27{PMnVSsDjoHjojc)gEiElupCA;M$+YwU zr-PuVq@+Y%23?CUO~t@@@(s%x1f1}3x=)JcX?7yI`LIJwmgMKZtaJQ|cL+DDM5dtr z;y?O(ABa}wJ&9LJBgg=@N)O>s@U8=w^Qz3q|Ah#AJLfsXe;rND!_^d2Aj4F!I|J^TeD&^g-N$s}2<`_iVJiRQ*ZcL8 zEN4DJeul2#TML+z>Z6iB*Fb4Iph6oe#g;PPw_~^rU7LZ>P|| z{}cr7*4{8}7uG6>npQA${CyGgZ-Yn?4zmcQRAC{=m{oqAdY3y66D-*xVg&!1&hR4U5f={jy>4sL}%QB$9fzEaq6fy<-g6GX%BQxoFNJJv@F0F&5l|kZv3~VJ`-xfOOk7Oxh8|Y@4E@r(0i#q{xy%`=ghF zS=fH}G~&9)EQ8(34%k3@xm6t2s9jYr=zv}dU^ zR8~g%KBS9?Jpwk6Vlcdccmbfe7FL{Vo$eR%zm+hYT}y^HL;A&w@y91KIrFfydc$ad zWM^Xt_ZA*`8eeHK2H`94I!<51xgfl^!xDk?tcnSC+F{sm80p2oQy&e1U`Q-Y1@e&+ z{l?_2`}AP$Jq^S*-_M*cUl442FBf7)z>)L+3U>9>D+8gV_T^~`q$*ZLjqo+ZkcVvr z*g4dP4d9uFor(8X7uT9ZU*1;4Ni9k0YltWKgHW%0`iu|xKrKDZRv^LL~fzf?^gf82l5er{>(Tl*Q#30L#O;)Wvkpsn z#%~|a?M|^cC4Av{O`~+vK~0WPveKi(-`~c<#${anFv!`3_#?w<$L?>k@uxFh-z$51 zf9?$X(5-#pZ@Q=?$g#CY`EtiP$RX7&&R{*qlQ~Lry1=6ibwq>5ncn{t-}fU?8;c|o4rqadnFTJR$C5p-HV#vBd-u8PP z6dgoI`ftnX@T2}TOYkX{=Ud12UcB57&q%|3!~`=q7WdVewxx@Rcp8bU2qKp{pOSM` zy(}(D4-hk1j-6(q4=FX{j--_$94_m3d%YD_iV?FcV)Rn7w@za~F7$7uo-m_dPvVKb zBwy-T*S#%KS@2*q!?$|-H18Kx`A^IL!A}1>M7p0o7@+Fx`OZkGg%mV6sM4i)dHkwe zB?fkX}WE;uN~1W04iTcED=vc1d;ma{QYltDeU|kxB#itfto# zDL5x9oU*Jd5#+^OkFt%c5@19_;7BWyVd8LOqF+R4e}$F^uJ53O#sT{D=@xQ7ih)8p`>6QS)Ngm-?K*Q*3w4D`RTka0{G{|Lj(STFLOG z-_2c_y=2d4U&0ws+dQ9p8G&KA(3?%n?Kb2*zpy8q#1t5+agtcUzp20py7ks0r7~g+ zso#wr0s_Omj&JF`DIPaKrwPV4vCq`rtyTzn?`t+>b$z$Gt49Zm%~n*)G;WV`L77_5 z3tbNVX+R}1cbKyPjsnYoU6as@-;<8MrZoT z=t$Pp8_UbfyWI84Jk-f^c)5NYsV(e$?_QFAl{>)2L~n|2&t9g!4JzU6(!1%1XEQ^| z@HOj0xqOFWl#P6nLubV9Uo&b**rb@fZun%FR12pe*Q_(D_37(>PlM&@w_|VL=dRg( zE+xuLqW|uGXhOwwHeS4LZ4V>()H^;ux?}Ls#^QC_Sl;A@Yz}5xA-eEzAg1ZhRkI=&if@~ZO^~Lk&FkV4# zsN~zXr33AI_wFgSKo@c*9u*r57Dx_l*|6j>%{-uAFD)(Y!uFg^yZm!Q!^}o8il((S z`-$hj5zyGpfyy34!iSv0P>;%BAa{WBWMNRpwlWhN)ymVyRO_w(svTtdMiP|*B_|iL z&G*QQJL_GE8>3anvG_hrkaZ+DZ=k)6dHLy0&cZEC%%Jx5uFOY!t_GSvyXFTgy8G=Y zQVqgHLU@)HO=JW2F410^Gs~!lElZ*0bv^Xi%*He%@bLMvcip>wYbTI%%3p<^MQh0< zd1dHbY@qs2US*WmG?9Wic^&s3+lsMcE`Mkq>@SP z=5Ia&BeP$i{F#_oTU`~dMobGhbbu1$pi7)e9-QGxm$E*7MD{l(6oTHKfb~pb1Hn=M zzyR2ndqJvrsJeQ(1FN9iYWlmh@3MX|+%?djl%X%r0Cr3xLw;!-eZ_lEhBe=nF8Vru z%SM!C_(AJlJ8}pqn)ge0H{7L>d9UNA;asr9HzrDG^0j(6I+UC#|NNGEkCU4|Y#}Jq zsY0#4jy;0YOoNUow2mYCCQ+$LB0+i5S%^d?@_@fbklwDEEN7ubxMWv4BT;#-w(7-| z=GcH-F=r5!m5htwy5u`4j8L9he6Ek{1Yvx|vfjcfqFsd4MT{4^0FI)37!~ZH^iW$S z%Hug>`!IZ89;ls0#Zo%i&roJRMRm}W0UM8mN7~snFp?r>B)T)yiJc)$#TU=;Yuj>R zaq){9ncu!%{zR2{k2wwG7A!3+9zJ^HSjv|JrDqr(>mexVhTRYU57!0Eu3A}LjiBIr zh?zX~vdPKNa1m0en8GmrZ-FmS+4H`Avw(E#vB(J&5;WWE(Ho(W0XGSZzN_FI2E~4- z5+^}drgw7<+VY~1+@%SV;&%V3t*uo#g8TZAmDP1>lj*rKP0=121x4I6NFhe(m?1Va6!LP11Aa;iOZ=wn+kU9{<#Bvdk~j z?3{1VDyipV-dJup@u)~hp#*R;A4@Fl72>GY-23?6POLpvhKfo9W;3(RV=o{RYbs&n zpuUuh+r;+w2_)NieS7JzxB$8{w+bQ-U#g6Sp!ZHL3gC z1<6|nhCO6%lRT@R{C5Y{#csBS`SDp?NeD@Ly+_IhU4;%LLw{K~bgB^t&U!3f4xJk8 z5RSFui{q%UJ$N7lNw{1%1w6%v;O6n5-MsLd+@$kegDmU(a=b*2G?fgeacx??;9Wv9 zS5U`iR|W(Gz{d&ZL9)3}Be;=}FonY`-fnQv>hAau^r&sj%xp_3-C_9K0&WFAI2}S& z>Ay%tRXNbtH(h2dKU4+n*_P*Z_lM}rK-u`jU}gm3l-MrSIMj9^=k-JIBrOSn1W7Fk zBAN65AtXsSE9>j)iI7_kRzuei=C{bw3p%f=0*fNi0Cj_J->{6eo;|C8p(8M=NcJye zZI(9pRD!l}<7iH!7T{*}s<||ONjlKl4)^+(6te3ZKJThOzk2C~&Gt0b%mWqIhEqN4 z!F2TnD+OIbhk1+I7kvW!=KZ$}F&G~S)eM(8%1`*jA|x9+DJVm5x-I^d34E0mdf!>~ z$&4$B;LQ|Edx8w>&`Xxo`n$(;($x5Yj9bZWeKBPgy*8`N=!a;V?N^cNqisSDDBF3x zRyu7>TqTQ4MupuMH^_eB+eljRG3BK0W z(sC&c?JE6l1CAdvAuGmD!1P{Ue@+rr>D~1AztD@6o`r2^M7hI{Dl@e&ZAUS06sGv~ z)*-s;L}yEzt)V^ecUW;Y^~Tt6P}!LQO3yC8Z#WjUFuAgjVth zfr-yi8mDHULHA3%h>$^U+`xCg`89XbJu-|(`DWRgt?XYq9>~+* zC6~A#Hxq7-VrPd62U4 z0)1zdQ*qJ+iPYvW*PL}}r1!|ib*!rxrAZh8y^RsQeM?roVw!@%NJx;cibufquF{iv zwZbYG+|r#}ihbyX#vh3cZ*m1xnrjL3B z%9~M+&Wt}k{2#8qGAgU6>lUQDySuwP1*B0F1f-=KlvKLAL1`3FB&8ITZlpm#P&z~; zMNs0d$M^ldd&fOL92RxXK6|e<*Nl)0+z$05VtPpr#$$coAxgT#gKh#Dr4QpUT=F|N z>Fd~l-Gv~*cKiMU)`D8BK)VdENsX$_=2iaSTz>b+Dn%UAa$Yl`5v8^8CXG}Q=fC%y zL#c!*W^L{Gt*|T|;8=x3A$TjEIb_$Kg>5b_j(uyM940Z<7JWnnSQ|o}?$V`3MIQf)`SQ z%B=M(_y2?l!3g+kUL|rRP5R_0$hvpVcPe2gf!S|sU0d5l>8mopFecuF4_FZ8kD}8s zGu}k4i9M%#pK{G{NQXyxCr4PxMw=|_tH9gm&dg)RuX?3OFvFCQq;coIHUEn)S$&&J7cI^)^eb^jgL`RupMGa$Lh~g_k3)2-l5wXWX ze|zK@m1a^=K033eI;#9wl3rx_R%s~X14UUq^ry1RrzK;lfE>IJ0S8CBl4 zXk@5|5F)tpwqpv6Hh11jU*??@h@sAU$~6XAn)N+DEy~Ku0vI8@(Jt_wbiR45WoPk5 z(ZKMqO0x_~Pcm{+aN)!-11#^`_L8rwtG_n6nvR`S6WG9fW!l7163-dV-|Ig$*RKl+ z#+km>*x~M=!swB`NA3S{CS5Sk&CQ%JCOX%peli;M_zVMZ{624QfY9 zRvUThvxp+io*`A3Ky!pKtMj{S;A{p_lHfjA&h+OlYk<|uyxx6SkQpMP%ps_&n#Fs6 z^1*@H?f2w~pSzzFwKOf*n7o8e$Hn@#v9aF(7d1LQEhaIYe9##w$WjN>B6(f5L2O0|hGAa{0Av2kxnxb<-7pFhp(@jr1!fzjxiLMO^-)id0#n#K zFGFNw%k`HV9^wa-903b}5#Q_dq1OC3ZepuQm{JB3YL$l~ZGQL6ayh2%Zs@xg%9wtH zV>}7eUZqH@i?%d-BIW1`-rNd?9`Sz0d>^!zC-z|(H?PUxRu;yHowOsPpx_CFU*5iq zTQ=ftnB35(I&Sr>Gd2Kbq{Z#qB_5^D@2VlG6?~ZNoeuh#Bv`RjsD&p~R;6q;G^$6S z;)w3!JBWN{R}4sbNr`ehH$OjuAV)LhgTJ&J336n@d{ z#AjuS4E-rteo1KJ$tWge;4TUV{zbnw>OBJkAqeYC(DlD{3+wT|%=eyK&pyBpdAM*@5Y%j7 zepUm(P+U!IUA{{`pEzsXJhDjQOEC{)L)IQqWVGiuc*D-DxiT0@AH*s1o`396Wn)q! zsp4KEV#!$J)wGT$H0A-u3sC^G4151yFYKl3Uzppy5hz+Pmx6qGtay$H*@l~!EWR-u2y9j?c*(#{> z+!yh;FpHrP(pm6(Bluf(p{p?0+JOC!(yCv7%NXwf>PV!GqRxd<*e8?Is|muY7i&95 zeB=D=fnR+H^=@GQ@hcNPsqK-QMF3t;M5Q|f!(mCH5NMpO?~u%2Bm`0+@R9nN{4W`? z$%!#P;%O}-7Jjp#b)g@Qo5p%`>&Ncku~(olYZGX{A5qkfrZUkesPMv7=R%!O>r8lp ziEb%fcVhh@xx=`T^qd>Dl<}sP6@l)xhl->)3O>JZ5Hi)dc}oP!-3i5{u#WBR!Gt?4 ztyl3SVQ%Dc_l1jp@qFFLi6$NtQpPq@lfn-_@;h9^kS0{)8pEa!pwq0T8TGZZBy>%% zCn4g>i4c!t^(1&#%AD z5W%rO`Xd-Cdvh8C<6MsreNk)+m4jC@w}3aM9&cFnMJ0CyhVz) z#oZ>fwZxld$t%AhnQx263RrZHJA~psR=#-Q7hQMfFg#Sn!(aKcrd$iPhoM?CxB8s|Lo&zE6HWG79Ic(V6yW zeMG-!Mn4k=TwhT9SD4j3)p^#>EMDM^lsnPEJUS-sp3YiYrZU5C^9xsbPIErs!fcBUb&Q zDl)Dmi+n@&X8J%Ax;1`@tram5rI{-oiz}vZ5!KM$gaEH=!S_;ST-#HJX`aqsW#?0> z_#*<8f->pN%ncKGio8eWpP)3a`J(BLW7<(4i~df2Ntq0+k7c1Ez#0GNyHAzllqa{A zq%={^y`Nin!vq~;QHZpZD?;C;=~kW&iphMRepe_7)5a~0E^-XRW%H=VahpyWvWAA& z8>|lEUS*x;Ep+$Fg)(+Or1WR+V#$&*2fCSP&~SNYnN{PeI}}M_7Ius~U@0n|5c|4N zx;|oBcN0Ff>UOOzMyX#MY@zKQ^6T$@p}darnNVF{XpsohnM+cMxvP)2aecx|0L{RT zn91^C8oB0!yv4;A|M&Y=xkGTyBiv`C;h@r_kb8Wf#A!pZ7DkAH*;zsuiKJih=l(K# zg+?(djg!YZk_xeR^4de`{S(*4?3w9Ou8uHn5-LClhm)(E76#- zOwxAp-R#Y`*k!g#72Rwo2|UTIbz;56>9dlu{#Oq-@O{+nyBkxR=MC-ie)@p{4kRu` zL0UAXlaDllogGBu=FYUcTqn%*5*wE2_AC+@zmzrmhiQJSi~#G~Yr*C!JH9tE&qawC zr`_^y$?F#K5nC>^%)fDgY9&9slAW z3ifMvA@Ch8%eM^$h;gjeshQ#@g~`@!{(vRd(mljvct&e_$*UkCFemnwEec^=Z-xUJ znGJSGxBt>eOX+F`(THe^=4uk}kT0har%OkQn8P5wuG_g))!vupnpxyFvfb1OG>6g_ zw2W@kyEdtLOek|{5EFMtWB6*0>TaX~5tmA7}4 zF`eG+cAcTKsrOze+=gE13ydp)?*kVgv}y;Jb4Wt@x(sLhWB??C=EmeWx#8YFeV}?| z7s~JCs-@qip9U?g%noJTRKFd$xAkQ6+zR4K%VMco3Tp}7o6vZO}#j`CAs|awHok^(FTfW#~(W=*I^gYP9x*32drKQ(r5q3>+6Xc z-TJB~HF9VYj;PEU!2#TTb8zlaavN;CWT^_=D5W2 z8l$Tg#09V{{peQpWUMVzS+FEHi(l!UiWx5@)p-AV?3(4}|A)$|#~Zu{TO~N~SRUXY zc7mF(CE*9jOm9|&4-fP&4zz-h$!$=>iQZC}FM2ciJxunBc%%9BIj*@<9TI+-9?jkv z(pksGkFUu0J=9NqsA9(_85c|?W5f%P>M@n1j8m8f>n zmWhpT4o+X-)f}V(x(*^KKz@ykjMmnn zc|t_5Q_mIIN_noTUc#**MkauL0U*rJ3YlQmTY1wKkj;SF(o&XuT?9QAV3&^{VfGBj z@!e*$>esKSq4TYNiJ-SRQ%U0%6%Ak%_E3x}K+>5p$Y+-I1s zfUn^;TX!_U*r!i3Ccu(#*1;F#{qpZ_V-ESm_sjk1C%%*gd)U9N8h;QD!a%0_7Pv2W zxd`?5%uFPXRgW-s&Y3W8zd(j$yhlt}!Ps9}9KO)ob(eNkk(J+5*gmt~mnh%MYI55g zalZ9jUp2*#GANvW+1Yi`K^u>`s`sz33aE1V4aenKe;+5?4~dn$e69l?d|D!}&p@(3kXgGi9wgJoJl0d0G)3&PZp6X*SiH;y}eX8+W4Fu=bYKjTKD#ydt!ybz{Oul~vie z&!MIFg5z1#sWmN?ZT?_iI8TEK(Pm{9lKGa>iUf+RmEcYAgy<(AuK3b98cY|T?0UuU zU}$)_dn*(L!|iJuRWLrKprV39o|^9I=%45xUyZawb&V0TUKk`+22STni^%}^qIK1ud zZ6cx5Y$Rc>YK=!I%eN?E*s~?Mweg6(r@&}ja40IiX}7nx2jn7R0uCgZqdTD`ZBvzI zcl+fw>T1_tm7*AU(@O?9Z+D^-HRHctwT+OI%3d=#>|}q1dkw6J5Lhi z0RaHsRoJT00pRsq+;x=&Xft5}-9WCF{iaN}S|A3J7YcK~P@ap>?EmocJ?SEX-?Ulo zunFj+wEv7jUNXWiM!zzQJe<*J3l?Ce>T;kUxcq(fcRv^;ED!|(bgA43)-HT>`R9Yy zKHK-N>4dB!%n_5(?~b4i2FU`eM2bHq=_;xeB@~0{p6u;E?Sm;&J`Kc=5vyz0Qln4> zkeT){72Uv0x+n74OGeuVY~TfsJ4K)^@!t zM@=t=rcJy%sAy@GO0ZP#P0!2-DYA5h>fQTAyB@;!lAE0MnBPj1S z3e_J@O`7IeO|Ha%W3~^JEh|cdh=W-ehTKd=$X2B@I28OpzO@JI>W%_gR!6S*-8+9! z&;i^9^!RvkKJ4yVVEn7-0IAFV)3b+FuI}#p@ZU{MpTAEAdB^(#E@lL^4hUN$sGSg; zaFT`yQjjUGs>0iN10!`FZ^XuA()b!uAXK99(Mm$&8W`Z)1(JSIq(kJ}`uab=_uHLj zxc9~)aVWsr7fb~2n;;10|4!ZSr;fXC8rS-hE#7%Oya(s&YOL zdoNa{&Bh!1r8D7Bj6DkpwVv>{xt$I@CR63zRjtdG^B8(7?5${2dk_B%K0d3SHGRTw zOW|AXiT8}@2QIe8qQ$TM>Dd{?1@W|f3ECLqeRQ6)3)4t?So-p;fFcae-oRR!8JHie zZ)`9bEKu3!F)_o$4d&CTeG*AEl%Ny>MunaI7dYP1TKSA?mr?G}L1_WXqFVyFGQRxv zu5e&w!70Dcf>4kRV+86eDJl8;ziVoK@dA}g_`ipjGSAZ0GxDox>1*FdmtSYE5pL+& zYIkB{`V1M9N`R#f`5n6nJxUY-UPos@7ffcvlZy$y3v|;-Vc38`h_wKF6%f@7xg$mH zyvm4a1J)?eJs@|EA{F*9;G#RxLyb(G_?s~G{CLazNAy)C9#N_x_sizpA3wBT-iE{i z;?ZfEPlXB=I1|oyUKvW~_v!rd`%i+wO;82hGzAUJ=2&67^Jo65U~r_BMoa`vS_))? zuY%<2VW0fs)~ZuOmKuEhJGdXgo?Qi^J}^|dGbatk8<+yf7Aih}kA^Sq+^RnSdL|GC zxPj|5ky3En03y$6e*PQ+9IT9iIX8uu zw2&l*v$T}bPh)LrY3#q?=sqQvL4xwnc6#z0oDc_07IR*#4uVVJ%! zH|GZuxA*}dhXRyKcwLky;dfwZGXe>4&vnZS{Wqzq)THwZL><$}jZIDeKL2)s?rZR6 zf2X`~ba2q14KkoXy#m(gfuKJEnscLKtU3jR+${%#$`K0KxcN$$1Y{{Lh~~gF5CI*s}<7H_(Xta=@RLJ5v*nUiK{Gj;?_W$gn>k z_`^b*z~JZN=6(+vk&Gqq0D#e8&2L~()u#43ut*qO{sQWxIZZ|6$a9H(`11NBhPR%8 zxw4ZeVp0I*1#zlXcht+NX|Pn?hH-h!w72UN8HobX;g$j?p8|n&&w9F`lqa)uR7q!vm&cx=@>IU{_g2M4X$X<0F z-1omXI8Ob97w_A}ri8+u2}Fut0Voj=!Zx4-6Q_c*^261i-Dlft8`&20q7ErBqTt2M z&I^y`b(TMPo36}SHRv6|Dw6g)SZ36ujcPtd1P$D7%lDbQ1#&3&h7Yd{hi<#{L5|>H zC^985x@3tib2VT3;J8H&fB>)^mIb4-OGBswvVDQzx+g=FRYhxD(Lx0}2Cn61M8*uV z?>=yTk}Tval8)o9suXu^kTds|OTZ(>8fx9y91nX`P`w+xg+~U%LCR zVxBebLgQ1O;zECw;#}py`@e)!q7yMJy2@3(L}T|okcWbRNDZFUaTJTNiPThAqvNq? zd&4S&ngsM2!fr%rTz(e8myaTKlkSq;pmW|sXoKO{HgQHM4f=i8+3p0agU~|nce{1GH-3$Lq-+_JB!9d9OL>5UBSAZ3hVX z1oL%|wa#~|Ta!LtOT{=QOgxOwqgUbyX=(#*bllM>p$4sSZrwO15xip}89B{WMxKB>G@}M&Um+!)5t+&BV8C+ghv0~Y# z+%T1wZ)^$RcEc^H2Qfl8&&dU_PJqY^QnT&5z;CAjRW6uoK&6xER@De^m3Ls^UvLg- za$7<;ql3gE$FJ-QA}I?I|Hw>~0p{Ow(C5K^`k>Al&B-}oBCn?}2fBRt61Ts|xWcWP zDif-6WI_mw{(es^(<^+sk!keZ2+YOrLKjcn2SGeWVE13>3MSYPwrE8O5;+a`^5GEJ zz(gr#?&!&(9cSLZ=SV#7pD2`V=5-5%3Q*}Z20%H0+YL7yL3vMhS$h8q6fd(OKn}K7 z>*sd-0IEVtpS-ds@`0x=uEUVk1V0qG{o*dGV4|YyuFmp~k>?F|ViC{3%(>}dD#Vkv zo=Cl_XZW0^!i)UCa}K=>nMG_YD@3?6G=#w8ismSa;PI6Vp6V`byBP!8MEXA*3Vf={ zex?~|sLA73og}K$?-nq&NyTj5f?TKB7Z`rN6_q*^) zH;h7w4apeaq0a_3DS{)Oo{lmbVUVp`4p@t>>jZ4cVyxY2rn;Oc4?KIx5KMH~-m3#k z5qAB+Q4eqW2@lN`)N|d&pIjO%8|4=Qq1>7A_-@Gk-{_#y!1*VrGR!|8gS56nO8Vj} zFyRlna8k)jAvgfs#}B%Mu>bZ+;3By5KGJfw11TWM{Bl;B-gpXfD>x&nPG{h`!;zV1 z>-r}&(H1|~@}8aTh(^ksAA#=MDG&WO#Ssp~_Bt6@89k+RO@a}~E^AyBc#-EN_h|jc zEDqmf`JpSi^%j2$HZ0guc$Uz5-2UJD%@C=*qW8d0UP7R4WpT;>n$Ol~1Pi@aFOYJt zg=by=^+q4fo@QQUN@<+yyOgGYrggPlBlzi_EQeyirb}M=K?q{`S}?UcGK{7RuXw1$Pjp749=n9ij-%#w>!juRjI?$i+n-``iX z^?h3WHafCQV0lO~? zXpqBu?^kY%WXz)ekI-VdYO#Brs+Eh{7Y4{n%%t+6?o!GuF{fWi7SzXI@%^T!rq_St zEs%HZP~RkE!}Q-rgHb_0``&(NpS&ke3q6wcm7sS-Mv^8bzY@14<~XitLWuImR{E6? zgV->vcql% zIp#>Gsw!rO?ITPYRW!lIL!Es>-(6Dr9^W?}Av2+liF0-VI9!3@cf!W27nCJq3}%_S zE3DE4qo|c#X$Vx2rR`xz9-%Zv`AW!^n(PzG^#4n$Pe}dwR7YgPH-5D7P~uEnGxH_b z4pUIBn2OWQr`XU!f}$SS$of%zWFnyS-6DWWk=Y1EplAQx7X4P0s30lt4Ii7yhqY@I z8)rr_Ty@I2{%Bh$PU*3MR4vGAX@XT!*j0-sVUUU#wbMRXk+j>2e_IX|Wq@p(IsfQp%+lk=!YikaZ#w_)l4K=|UZb$bkbi8)V*ABM_J7mhgoUTX3Vz#00Yi6?2z1TbqfT(`@Xs z(FJj`>%*T|Yq5dz)TCbIbOYXAPuV)PIHhlFyro>G^+C@R)-Q3xf8<#BoYM|vJAvF0 zRj^HOPn%x9&n>7jv}yZg0$msf_EWEp5l=58Q_Z-M)FCD2X;ivh+g>$`x?%pqU#=Ge zD?X({AD&$O-uRJX7^Ppl?0+PJc3G$Hb)OK01#M9^ zLWpt1&_AP_QqqO=1<#2x0G5`h1~@6+KfN3|tt^~b-j0vAx@^hGG^4q%%-dvf^4y5K zky1P}kcPu+b0?R@I#-o#^)q8?HS#a3TJPG--5Tox6$S4fs1>^L%IMY~8@pX~Nkh}W zcPcq;K8WQtr{fi0n#irtQyl(GE7+^VAso?ff`L!KYN<0l#AHLOO7I(G;^zw6$>#r| zd?O@a9_wp|zR4MICq|`r-vDwe*>Ck5$nnt7eFUh4A#g^Xdj{a%NqWS1L9eMR{3zK~ z)?soS$6C?}*L1YitK|vpr`T_gV(pohovmCK9F}Mn^_Qvp$vD-$mO5&R7znvRf%7l~dy!7X zuEg-6EVHGOoq9Bd)oo!S&5KtkR_JZnG~?o>Gk6U7<(e-1YWZbjvhSzp+c^pAQ~3NV zDRH#uYn$R-y(#+gk9v)|-(J#yr%#&qU z_y;o>0Tr|;MQpqFIjsN@fdCJnnSeHMvTBC0!d#1I>AjEd-%~$aT?Z`f=TB2OgUNor z3jiY-4SMbJDNxKonKwf{`}uPznTe@9-jmEaQ`&T60U{zkoiQT<({REQQT#6+(yv>i zASMppn}?#w{+vRnR0PufM4{c`16ERqyePoxfgJoOr)6Q0);>oth~Ys*GVm}s%$F`p z9@F$XlxFw(9ar~L{Wvl0z<3@MRPPn*Qz#MQpIxWMgQVGANVOzJ@*&=rkkFitM4`}T zXRj&ou>%TmsGao(@^9b6E^it>|Mq+r3-?x#Jg*Z8-_ca2Q$YPfBL4f_7J=ap#Yybp zGCw10k>%!7#?veKY-p3qQnrTXx$_J>Hi_vi_5C9)3&@ymc3IMVPaso!g3HJ0^FBsP z<=DTRtUz|?fv0Y`B6fs{`63sxb}!OHsq2G%BeRZ}AXm^wdybxjQhtuwDG1RvkG&qovG<>KPv zf=gKF5e>>yG349qa z5<>3(V-MdCAR1rU<_(r!H8nkk9(-^O-U({8uJHIdVmXNNezk@({#gc}R#IOE<|Xy= zlTb3XJc8X1y2r`Gs#mWj4rewqva@&DAYn$bFxmOsTs=EM2;w%jSP-#+knoew0tJ5d zQxDxMMHs>Sv=rFETd1{Cskcvx@!@zd1CfMDK9A(N>CCRMiz!j&Y<^tqcmlGefW#@jRR?Bife&Yi5I3DwkY7}PAuWkUPRu5&*Ky|Y_Y!ZxNv6Cbq{ zm41BPp51a<;f1jkljzpUn!HjdQb3SKlDt#o4S#L6(N|^~K#lTRfAL&?c6u6y$b#!Y zpJ&8pl8`W}Qax}0(j{mUK%3)n1;%it41K_VhQhtTJ_lRsq?=I<-Hm*diHzfu zdS+p;#o+ZIO$F;4xx%%(^k5?ezn!)R&bMTHX(>v}_M-tL&oytKZrEhzty*753|f8n=ddQ z^(vv`&{$wbeiCbmI?E4o zg_n1fC0ab9RYL*JWQV|c6oe2UIvOYkZ*!l3JJ-tFk3HK`_j)QNcAYK$QnxGmL53WF zO7JWof93Wo(xh$snq&(^Soq<2NjyK~bMB^A4y#v;(~ta-B{~13Tg%eT+;+<^k(j_e z)6We#h4Z=h2w_nKt9cF>o7p&Z#p8ia=b&y!9SW!RBkBin zt&GfJ6BszZJe=EN>|c`$3*_!eN_X{4MHjzx$>_>M_b5e)#I@8qFV6pBHEk&9W`MEj zH?6~(MW(xI$$?r*%Vf#eB4I~E|YU=mhk`JdqqCSmq3}fT( z$B0)@c)Gvx_bz}#uVY-mA?5mFY5yrSig0%epPb&OeYaf_f0l+w(YrRv=q3QG@FA>cLxjhKa+ZPc!I6)+SrZeGWxltqmpWu~_hPaMEf3AsLeXf~FAICZ({2QLS z$K zSaiz{UsSDP(dC!|f*4g1qPUPMp1CURNdjNYD<8$gcUfbGp*rs#j0B61o}A?oy*gL3 z3gWPh4Aj#4bRbZD1H1Ibc90MLGlo7R&U(u!VKi&~xyLv4&<`)jkolywS4(4~1!S(O zMWja)TeO5C^SlH0F81+mIMc&`5{?*rPQ(O?wyzeUglioJNO)v_KEE|1GZS!iMwT)H zN+r_JP$S6&%h4-fx#6 z-j9GDtNQ=O70xa|gcsy~-E@2ecqt44lqo}ESPx;yo{I?V?l93)mss+d`uy=!Ob)T( z(W1+N2LPW!rY3|RzJ=;Yfe`*Z{q{~4pXpCoXq4sUvG4DQ2j66uPbv|jRVOqk4-ib)@>m8rjZ7*h>NZkRU4--B z@0vlSXy_SPIJ6@{9W&!dNNtJ|4UHIIEo2xYw_Y>SN_+0#wV zXV(mGq1~Dbc~eof76j6>RZ%=0^a60|p>t_K!bxoj^6kg&eI5|O?;yz29`;!a zUf@xlb#ejoApJ~7C#NoigcE|`iZmsS^FhOAoS)?)HhvD7>7YxD}-PUu_BgDX^pql;ZfOMNkqhn2;c*SlU%dO^YA07lyKAaW*jL^ zF~}nPwfi}K0KgEy_rbC5ys_qqj!KHynX#PR3?f6YjvU+RPwf-%yWur$!WE(fi>q%i z>mtoB2BRs!pm(-dLtX=6ydxNjDA`tzZ}8VZ&q+%87r7bo62h}w=Id`N-B)#MJ5;Nh z`A@diF(~zR4k4tBLE{8-2n{-uND2^9{CpnaBr>O zF13fuJ94*=^};`Y4W_4tFDmGz;wpUqqcR$bAs+CA0R4u#^jS;IK##Hn)9<9cyINNj zOc)b=zx7j8bwxKRk;uO;u-IjXQYLg|V`OX@uR0Ru&`EXIp?7f$c&Ub_`0}jRdht*O zqy&txYd_SYw^wxJ4B#K*fm2Dige3R(xt4V~xWhkGa8@EVJuE3!NU5)Z(Gx>Ib{z@B=hrjx2Q zCUx*92;v0w%BMOSldUS>0o$Y@EKpGuQDQ4~0Qw4Ehl~6Px_wDr4G`X0aL1H!n$n>C z`*wK1VYOnijQ{)zkKvkP6D}_Zvjqgy&tRE#8UzUE68L={>o zRaC3-mVG$>^Zd4Jp8kR;^{T=i=GOMYsq8oLPpFtODw4I#yMz(+N-;l z6Yuc9VG_kAM(1H8BOm9Y1QT0mMjjjRbi_>xa*`OvJ+F_ZR>SGizR;0aiw_fEp|;73 z&3cpTXDI5O^YZtVvI_-k6P=Z4&x1L2)M}x7(q_XFUSH2-h`M#JY2rH6F4+R!xtI1n zuE1(ie~dn=&+VY9CG)$>e)Q9uYi6|i*nTEUZtTNmLSJ-Jqi!9=C4FiQ>d4yjPqkkl zJE!m3OM(7Z2+N<6l;m39;Xo%3rqMz(YI%_vrg3JL?`*y=hW(y-PZdxNOPwQ0d|3M{ z&1UOjGPaafhoNctJsAS%5J@kKFK=J;OgxcuWKsg5A*9%Kk=X&L|)14xR9ExBj zLz)Wj+8fBe6(E7F_3w|jV~E|C2Fxg!_9Y)eH@_RG`YLi$(s@(>c zhLtev;pbg~)3Qh-<{^B}eD$`=8-bL3={L$eXhr%hb2zt*6c;}4cv?O@Q8ifnddZ^V z_K-N{ccM>FD>lZ@!-nzb(+}O}SzW3AjM|H?H-i^Av3rqKfpvTsfFI3&5b3wPf^F(m z^bX5RC6GO#WabU00gRM)3faVAl#& z^c&lAxgLh#qJZkm##53)<#om*BV(F1R=En!K?4lpu^U!{nd{Bp+rDZH(5FXi3<_uH z-y{A>O_B*V>T$&ZDI!He)pdc{3FK%)MNzo+9z{yIc?;w(rK(ga_;ppV#D~_%^=WHk zYd+ZUk_4=csiFn#tNgt#7EL#<+){MSF`lv;q}^~T+BDgNhVU>~JiyGV?@X;nq@)r~cnOu3QWg&LA_$nM#z+d3}x&P{45uRO<-bO1<&pX=4qXnPA{~sy%^;X|)&w3<^m^mfki5Wvq!FSR%L?Kw}`CoSp4^C5ZcS=S+3z zaeKQ@-vt@*cp75}8i%mW?Tj-X_u_mOUOwg9zxKXR~Hke!?Mq<#=<$R<_iPakxfajmrLBWyJDI{PeQu;bU^F4SFt3K+Z{6L|LPaGJ8 zxo5g^Qf|ZKJ!bi#2qhj#@}NOKM;N=OQM;S_16s7e+U%KTO&2@0<(*8k5^-lU`*YI zWeMfl#YI_JS%TX(oQd}#tham#1~E$;PA$M6fT^o{P@zBM-gW3@Uw_9gxIjxnV(Ve-Du)7N;~Z3!MOKX8k&>BZ_yWa3DpdPbD)JiNDBw(>x>1)GhB{uNd16>ce~Ek7+L z8xgmZxOn{v`h=Gp(^lFbO@3Y*S`114T0&U?ttxWMsE4-{zK^wsYeo}p=K31)%@gT6 z15zZ7Vx$Gbzk6*JnQ*hsZn?21%a7Vx?m=K12Z#DUQV6~tRD7`Y`1ro!OTtD(Z9{c{ zvDy+S6>vW0bu8`wtA^_15UB-|GF1wnwmdp%5IVIcsW>C)H!j=WTg>W|NRd)e6R7f) zglrnJnKdc9eSNls79;C^aZ%PZgkd9hCr`VC4UZn5)*_{>D9?>OVHUDRH@J!pnSHRL zhmYCEwuss@jXqH#q+&o4)x?5Nyn=0&5sLh<1mo-#lEh5|VhPV&76S>7;vSGYy3?z7yZQXH^FqYk@1;HXVzin>MWyy;ge8C!pjO+<{{vl|%wG>1{gOfqQ* zHG?<@Pj(vl=bJ=k>;pSmc~K3mU4o!gNz2fI^dte_cztus*m7+0BVRhVHFwt_D{IC0 z4&|ZGOa|oQK4Sd14xR;R-ynx?C0SZ_NKExf1mUNhpy@a)vP@f1)ll3we~|Z)JN`JJ z8FinNMB4BdYgfOO$1je~KO=N|3Xl(Ck1)T^>3Zz@FKIGDK9KHBfZ}?>`O*lmvJzrl z-_rK|UO+-!#-M5cb9VSxd?#e3{M+|Hd&`G}4+|}Sh#aEUiMvsT*X7X6DXGev9AF>U zaVL;BI68X#%?mRB+Zr`u7`s(uDKPGTUd_<)4B2&JL_67sDyoF5h%xS!V(|C&sQO_~ zZx>Qz>p`>6k2`hIzcK|WxA)$VG^CG|Y~gL#FJhDUtcG>w6H1p%r`xA-7_$0!q$Y@I zE7K;Uxgj)WdFeoFAB;Cmnki+WVs@GmgJX76QobMe$S-2Sq+5uU|>}7y1KJ_nmn4-mHI)Z zMn%xD(6;;h4)W97(I)2Gn59?RvLo6-X3d{$y6lXbQ#TS6#Da3e*&>uBQ{IOblXPNj zb5i#GbF?SGz`N!Cnl-T%2`~R1Dyc-tH}nS4@ia`BW~{QAGaW0LigRnd8!3bP_ad`PYMXKW2D`O2*B73hTPMqh|6pkC?0%>usw5Zg-oAY#^kZfV z>fc`k%+3T(!8_XX^sGPgc4{Pry+ajFw3F-=bANu8MM{32o#d7t z%%})e5J_AyU5L>oL3H3aN2!~ zE3()ZKdee5$?X^OsfCjm_>QmFJ_ABp+by^Y44S@byZ?Du#Ra}^i@dI2(761AVDS|q9u+PF0(V=H>ak&3zc>X~(j^{)E=$4wkIEud zi(QRBNW0WYO$K{5kdhU%v@6>Lo}q|JhK+P8GDL|Oc8sS<8d6>iSytKhA)&UdHA%jx zh;+^oFxC&$g9N7l_K(Mr;_B;8vUK~ZX zQjP0!4wi?7WU=1(CdEx%^J6~Nc2V^qE}xn$ugH>dZJSrpa0E}XQ~2@8+kiUdHiuQK zR$UGj!W*ZuMk7k*L1cE=ymlrV@(OXA!8Lc&ie;pw0cNvAS2*k;Y3rR1#YrWD3KTAA zx&VJc+=dcybzcvCb?N+{+uMYx32J`-LUCR`Rg*f-xW?iF%)12AR~{^;iBa+T3%hyi53ieIRtwgIEy2FEz=(@i3&4spuo-t2L0 zsy*D>=>|wH9HjL-bA8J5VV#eashD!Ma+HvHjPFN=GZHVUn&eKZdEVe8Y3t&QBDlEs zfY>-(rrzJBRPbS$gd$Dy4T%V%**d$^`1-RAJCkv%*qNW)UCopX6Y z?)SXf7{`J^Z6I{ErGue@qBoZwxs82M30q5iTe! z2T1?`0Ut2_ck9GkXaBWRQIK$55Cw)vng%F*0)n8q0goydM@J%}M@jjX)`{~2U@nDF zT2Sr2@@ND9j6eS_813;@m6TY+VhcC`j|`t`*mPdKc{A-!!E0QEL6!u4@~;+p09#a6 zfH|*ndD9js?*VNM4L$&TNPhHOQzM$Ff#C$E1;}SgHJQWA!8z!E#!bU>+W%BmDpN}R z4Dmvc)GZT2)i>U4kT&tCuT!1LXy&#oCx!@RTt6C><;!f9mj>y)!LtNNq&bne&u-27 zP~$a^VJTalc(!R1+G^~sc)Wuaj?*q-=S#ByGk=#uyW9z}A5mUETQ~B}v9}LCEm@Z= zn?wt%U{l!L9vgVI=y>4~7AGVx>}K~v^y^ahxcO8IUEmgb!B~>f#Jt1h%QXy{JCW)` zDPxIt(!N`Lrwfq0qzg{w?@x7^eMy45P(M)$Esl>DX>AvQVZ-+$nTPXh$qMEMEdbno zbnh#{SEU{fopAyD2WD$DFz$x;5Jozs80n$I0QMt!tO2=d0sJ*+_0Z*#;eo)DJR>pR z2M_{UDtL+~3yX_pW_QiZF2J2Ffm-Y}>|_vv(hpWgqA(4F$pI|pt}bQTcJL2N?R?3YP54{_F{9%B;oYcoGKH4oyICd5ZmKZZp_D1)Vq~IkX*?vW8VLtYU<# zSDU$_Js8Lxmq@oTBLeUSZqZC{sd?cNaq;q!roOsU4m@uFH>7K;fm2`zT_<4fz?SX` z0E<7k`XVUvf>dyfz}^J}GP}T+rMpbY&W`p5vO)#Zf_wYrDHP2_>Ycyr16yUD|KpVI zj!%bwo_2*%;)NOUWgkLW1^Vw!Q_CN>tP%zX2d#!bDXGNX@CbLvP3@_Yk*j*~;zeB@ zkpv$%cK~P&)S<#}j0p_&L>ualz&E(8t7D}v@jmye~3auPyw`f#pZtFj)ml!V;|H#4^ zJ%^s*oSU07FPiX}P1G})s@tB^S6D^iH@e%F?9FA{j>@%tVf`orC;Zc@ckb!=DS6iy zq7O^nu>86In^AV;e18P_sfNbrwRs6BIr!H+#XVHiQ!fH4T1uW5wILzRV9LS##11u(}rI?7lRYdRxzsu(iH`}an(yc{{_ zIS|b*d&_5MmKa>v9O5u%LAhWhQ|o(Xfm8(821)f_IcKn}+s0GS{pU`6KIa~=^h zxGb83m5CpSYiq5#TkefW`+w6APTloZEiv8_yby-s#}pW;~P@ll-xaU2G89G z>GVc}n>q;Wuhz^LI}(oDvoS}vF`S_BLf8bI55Q0zaZay|K^0=J9q%~+V!wZ5hNWiM zJ3!Xw;NUPGLa0u?Y6kXNaC)<_i4+!<30LHY^Wfh@jACFmE<9V9`{h;0zoy6Pb+mr( zNPA;e7S&<0gtn6L3#9+U)LVc>*=_y9ba!{BbO=LtBPrbtB8_x+w}doEsHB2~(jC$u zAkw9DH+*|M=ls9d>(T3BX1Hf&-+QmM_Fli}n%{~@Q?$5kp~(rRck5< zi-_KMsd))A#7O%z>Kc>1`t(*752-DMK5!E4P_-Rh59tjSUOmxhq%poq?3oXHXHoNn zl-;rLVF?n4Kx!(BJ%eJe35uAwfx9o`^u5AQ8!*)hJ88#*9|UrAxHs-4!YtXKOsGMr zt^uIv2gJNEJe?gJhJO5bqj;O9!U-Cjn)}l;M6K^#K%V(tUJc@!-A0Q@e(>WBXmIMo z|D2h5f8{<$Al%sP@J#L!sDCcwA*!65kAk8Hh|0-S7DFc{sDCSU0DC4=0#H>+=xA;pnsH*I8u~}-cU496B<%^aWc22sbi%P5 zzKWtE7zIF&IX8t$1cL){s1bzYL2}SJeH%{j_U0zkcK{s7(tQrNIR*XsKRT_#(C$r) zjWN)?2ax7|rcaGtpx@&2q19tY4cY-0c{rcGfZ|BsE2TGxUjgVRV0l#ynECxF+bIkV z0swtrhZ2*?XVD!2MC(^?_iCa174Uk{xH$yTr%WZQ9l*vx7y;OF|3)DI=LZ0phbt&= z;lvwrevpS9fAz3Wiana^5~$v2K|>4;$pr~1KGv@EJiuI6<_LNI zK*0Le-KB^vq?-Eoz2Nz0=^Y7)%c4+eY*Yp1JkJDp64xbE5-9aS=v)^t==L_Hv|ql_ zs<25&h2Rhp5ZK?m%i;h~ho^7L4G#Ed<0Rr;-(XI)M2*XI5c!FTi2hOqMQbSO05l1Z zg`qKWjC`EDJ$onjFQWA5+4m)8#8{&R|9zY&@V12P?3*wL_aE2#kVFB&<`rNEakhb} zIy5$RxWA8Zq8Kol&8R(>qBDwRNfNbkJJ$p~paaa=@B`WRfLR2XD_YOq3WMPSK1D$f z7eDt7=Bkara`V3ZQvv)TUR8tC`E*_(kq^}7uj_!t2iQR!05%`V8I+o50Re}6j}Ldi zod{|N08$P({0Chi^a@Fz$Hu8%i6E8yTB_<>xHdA9=-i7C+FG?pde zFgyp{ncn~p>^BCO9-thsP9T*Cx^DuS{Xk#5o5TaOi=gNC5|1azUBR@G#3}^IY}OLw zhL1Lb)P2b3Lc!bwA?VjC(#)=Tsl;8)0?vkfcTo+mv3f9Hd7AUYAYVg&c(FQe(eM@f z0%3S#lLpOL%@m7%fp(F*-a2JNpLZ-c!wYg|c9ugkOT)!7(}lRZ_j>%gumOzWPtD?P zYM0*))g#M1y+V(`mkoF{{@3(Q-J0za0fZ~{mmP22mlX>x$wJ- z^M{km)o|<@qb49nD^sMlAH}mK5P{Q z;i{}`Q7wkhaMU_1d*okBU+Qt5a-%wT@8jxhk|`~TSn{@ABJwipeow8rnNAyLrg3>y z!=!T8?O+_#iyftr7b1DU3n}rYmYHpx`M?7TJuKC0DLnL_9ba+B5@tZ~334f{^>4x*&%aZzeD^)eVATdkte0C{ z!K7S~k*33EjGgR|c<$o}c1cGkASMaUaLcp+fib|yhSq2FS z>Y|=&MpRLq_{9{fxb#VQD8*U8X%Q@8AbrMB9jh_OTgpvEo>nHLP9{Kw1^Y9TlqUu+ zj|b@f1i|Yt!p8hx9ujWHcMHd>kMN&m+guchrRCc$~)b z{Op#8)GntQ6T71)pb3Mt-7(>z=6y!ZUh`H07)&*pM^oL1!BYn=0X# zfur4M_Q?kIlm5DfW65d+HwM=?z~tiUpup{fstQ1zGx)y%?+$1pQYq8Q^QUDk7mU_* zBQ*2`4oMP#7!UY4fC)l4W`STgl5C4oDL zv$Zf0&QQ@*acJmC)M}e5r<}=9C z5p*NQf$xS(hCX?6)dmbp9ViBMB!c&V7cgPdwFP)k;>x+T2L4TFp<($~J$j`ERH(~g zbFH?8m;u+!8L-{EPU?73=>E9+KveKE^i%YOZ_eqrocUiyj!qzF0DcFk4Io8y%*@EN zL{PJUp&=oV(X~Gibi$$cX<(rsB_I;5jUThVQCb3Arj;g_6&0?w20+>Xc+F9HGzvc3 zQ4$cXflbwqua#4(fC(rb*t&cU+)4nTv8N0ecLLTT=+mk!tv6~G{RN~MK$v}=*p355 z|GoG}v4+~qtam?e*Z_Gz=d(fMD;>ZP657d|o}a%ypH?Tg0yN*}S$y_LDFam1G2cPy zU|tJm#66(w{s1}1leUAlmN6ZZF~GpQJ8o^K|e2|E3{c<6ul!&D5MDp^F1^npe2 zO1b(CFstkn0=|^$$!ru7w-r|ndEn6&r-vk91?>$?vEJdkqUJnk&F zfhWOh>b)@x#2K;cMhNGo3hY;6hj&d5gAacfiaqH)1dQy$M$es@(&2fz2-<`t+Y7$R zHd2>(XkcOp0yhVgvkQPb3tW)L6mS2DZ2(gu&<1wRM!3tzTQP?JnipHalr88&Rrd{K zo%VK9dW~=z;1ro7;6%pV*4AdClFMtO3^-JcKTX-(oKbp?0lSBi&o-ez0$@Xc=~MwA zy8#XzwU{5jV9yP+d+dY)Ze1nDkAxlB^+ zPJv14jWoTDLp&r_akBoIn>ZIe-=;-)g5&$R`WQ3!FdVx;8NBjD?md3}q#zNnfj;p4;!5myKGfS4 zxDz9JJULG8oc91r=x+{2#G)I2b^^AqT)Y@Rd2cNgPTGX+U>^o=E!>R@v2l@)AO~OG zn`u@RTpq^<6XRYKT=?`9F6Zi!I2z7QADQ}I+Ra?eemcJfu>qY>JlOSVor~g&*NA^* zLeO=v#1$*9rt>3+7R#dI)|AEpk*DzZgh4G=hrd7Jgyd7M5*RuHyP0a3)PT}z<{rjK z=I9ip2VL(G4;BrMA#M!7h1S!{>eW*qwSppV78Y0$Fahzp``b13)AfMF&5*hzIq+Ko z6-TpeLyFHOXIsE2a4KO|C!!N@JOEJu9PB_84U084#3oewv&o&C*P_UsSD73;qd1SI ziJ+cK_S>LV;g6(P?ud`68I?gaXHgb?ABsDj*66?z&8g=4`R{4kb1_(2Or`g8_!P|% zmqTTgHfljR>MMTY?&0^6c`S)^yU1wM14W`XViLb zf!t4%DzIf=q36cJi)E5Rz?PK!@qF23x&pG|P6J!}%Zdd-kXe2CvPlfo6Vtz|e_WaN z?|eDsWk4LhJIc{R6SjF)x1RRmmsji{i1m6`-UpdiW5XkATCcq$T^8s12t{aLJs*<* z!~Zw7g)BT22BTI+1N+F5FX4r~m0Rb_;ULql+QuOHDrO1@esDE=s_(Xb;CK1qv}BTr zxHg*hv%21ed{zb}2UR_qWE#Vxt&nEzat#4axg45B`*0Ig6_q)5Cyjm2e0U=W+`Lwd zapSAEF$p9*bnio6cjip9AYW*(d9tSGgvVYdymFl38bA}l@9eK$+H@@vbX{tBR@Cc+ zx8jM!(XH{hEzu*b&2BJwO9(Y>+g(~&t|DD`dJVN&dvjs=Zl?oU_)gY1L>9Ib-8KS8 zXI)^e?M8D-{=C-vKCl)^Goa(dDJeURW2h6Tm{|ud?_{^T??|kjnuy%{SH~Vy|1>*a zkFug4-z6RdEKthECNCTg&)Z7|b0LC>ik@u}-LGZ})K9=S2Wq?b;e7S+RZfyw4E-_j1>`g}r}+!p z$plIbl{fEItg_P^mHuZ}!Ka*3qLbvM#l21Ql6o8MmDpF<>V%#sQAiO#<`bvb`(!o( zUZSFMayv0#HMa%->-Y!4z1KvL@PDk$!gy#n(-~N~DtOz(wL)M?*s9&1UO^aCzNUUe z%Mn%Mf{%+hZ0#ka0C@rt`$fNEB{V@)CkD@rt2Z2NMj7*-PlHU~7A4V^)!WG zU)iu$1f*6wqlX-lOQ8K-xE(-ohSb@>bKBd#pmfRl0y2-LD!ZpkJd?zK` z4Btt$AVWL3(C1c08C4~Xj3`jeI<~2Lnm@NlRoF-Qc@2YU!)`XBuZdnRUu~W*6 zr6;0ws|P;%_6?y>wjszEHau3I(8dV;R)o^=L|xN6(SbiYvG8T#gG(&NV=uO!t>H#e zW6(s0ldj~u`-m%sdHe6&?-;K_`!%M>B}ano4|`cFzkCjg;DvHL>U{%Gt>pyT8JiyE zg&#XGR&2RTst8rAt?Xw-iRwe$vlBzG?mzpiII(!tZFHQHyS6|3Q_>}G(=hvUT>vdk zQa?=Ar6fl=oJM0f_1ehCxk`5EJAfp!xoV%snucK*H{;&r`%t4OK+-5N>6>ZXE1a3U8+g$crlI6X><`KaOMD4+=DG zy7@hi@g-wo7!^Lnr=KU*KW^Wk-v#$ z8a;AvQwu92$5eZa{Bf3{KKD_c*2OO83S@o=EO#7Jk!6UY@mTLrF=D5|wuA8?iPN8l zkj&0>wDeFrbO~Fa=3RKwVFx{m;+g~N&n{s_42RO3B3xuR=!A4{!Jy0+XF!^|OlR*(aLNS(X|e3|){D#V>P-}lw8-NY zxHVZ2B^B7hn^EwaT)LK;e*(6Dc8><^Di(Q)+J!2C0FHbYi2zkeXVsB@_AWS-z3a7y z_@sK69S<23^zg_d-$$n}gy=!MG?JSp(pj8)fiQy)2JKX2>bUQ&Mp)u!r=srPP94!y ztIIvrCr$v8GUWA7*aS$MWVEVSOdf2v!Jufs1?{`3;cTTwGR9_&rRm>TZ-nMT%obv3 z@vLDeq_V4ut(z<|zDU<<3Ahhu^=j2|$9;xLaX^$*jJg~%*WEBG64YR1wDqEB+(uKq zWv(d3S^V3b@+)o(d%eDIm&KS+_7hA?4s2O2xAg-Y1xMt)duWk$jf4bq5vphv3$?dG zVBH_2+FXnh^K9;deiC(F(bVfu1o)3Oe@nwadjNc`37PoB*FjV$OtuA^B=!Oq{x?up zk{S>*pBOqF--xoP%;{|dvrJ$IvVlp&@{|3 z?l@XoS*v;rR2nZ5G976nlJd~LQHwl#QtSR%^o`K!B3If@w2f43jPuFszIB7iPdI|0 zinHb5+$^^EoB`o=_sAo@HO5RpXNn4XJ4*6nI$R+RIX>RTE}!`=&X{4EDHbR3@b6GH zq?IpsNvK3xo-Y3d3xc2(U3wUn%;@omR&ROL1)CWO3wtt+rEk3ss}Y9!k|{kGy+x6ZicGl`tAjAEhG;dj$EOc}}m`n?ob7#umZ=^lD~>uayllB!~I<69;%@A&Qq& z$?U(z{px^Qg)on&CvbbmeJ*S*4SG#8$gO(2A3_dpmL;D4H5P#>pn_P{_(fERt}aEcRaa-IcKMGqu<^@xP%vKZ@bTbIs`G@VDn zc7AY2mkDd#txaie#t1lQh!pJyRl+A7?|*iS&b1>x?Arm+hU;H)12d(Vs;WHUv3`Cx zdPU2Y&C$u780qoB_G@~KbT&LgdjbYygk}P}e@+rWTzMY?7*ezZij*r(nR5!u5yGrNMZj!wO2P)Ynr)WFtVnVJ(vyPLgOSa!RPcaIWc#q@yK_ls~5; znLx06j5x6g7KrQZ6uQ^>KQq0GDznw@vH1Ckj{yyOGs4RHj+s&zZAcfcakuzx`>-5E zC)aL0v5evk0)--?^uo0=YjZJHt^VS1j@$4FSyv;|WBITCEGO86<~21gA*O~zt*@cg zk;@|+2%f1MG+{qs_01KKJgK-UqG7vWykjk?xOeY6VO%}sm(qM=Eu`@o3hKL*{Ml1s z6P%@X;Nve4$b*gD6vbj{gEp8EW)P4B*u5yE(w**cQRFWE1$pCtL7uA?ex~bY;JaVU zN%w@msW}?Aygj)r`v2Cafmp;dTd!j2TMlHFhz9Jl_IQUzqKrFy9cAub3iWgY3Z(30@-%pWqk)<~?CQn~ts?W5o zN-T|_N}#Zs!o`rv=4u)lZZo<~|I|XWrh;tii863Y{<@w15pxe?khI zL(G%$8bm**JRj$n?EK8^gt5Q5F6yo>==lBkU+wHyO2^Sl1QBZ4I48`@c;6oE**N3-AkXH)w%$~?I!Li{TO zQp*S;b5zD!9NrgFCVs|O??a-0G^O{VRdW~I%v(rBPigS%XYOMl-%7+}&biqMA9U+k zG!$X_Um!N{MM_h7N#MeXG$6uL%CB|o3zqIoawcRI>o_Z+8y6S)kE057YU6nGs!7V^ zRb#feVEXn*J4EG+@8_RM+?X8>ltLRf3V-LGG;W9W+TGuO0;W-07pQvn*zQlF#n}ku z@?S|T_<1|mvdCQ`I1K9W+;m8)AG*T=A@LNwtf-De3hdPqRuze*1f4`Ip&z>I_spfy zVbKg>B}klE{&o`V6%iUMX*A-mb*9)2Wo;d!Mk_?RyK%Gf=E5Q8!!}ySz^O|89kYrm zeiJm96`hvIgVHv!VSl=OowVeKdWpM<$3S)4onXJNbeqS7aPobG1&zjekiph$B`0nu zvjhul&FpS#=l((BM)u5SevCUHJ?WR+JKvL2$fkZ)!cMkuTxp}@DY1y>h4^02{w%Uk zG3DY$*+uff+)(+}9JPuRfVIw6!cOXfK`M!lRoEE`-8SLGxqS~U=)|;ccz)tk*l5{o zMH2N&2%aTh1C0uiBgMNxpaJ1W%1F#Nt87=HMJ&Miy7qL>bWo9n z`Hmab&`(0iyFKuhpS5O)`SXWT%e`JIeIbtR`aCJ_e@fyPnw8(~3Gax_y95z^gpN)a z+nG=iisaU;zb?#UPvd7_5>SNN8>7tA#nhg6bJWeN;bCMoEV))sy-hT2mhmI&u**W3 zQO)r9F(DGjq}We`-=?ncoWfFV`?Kq7+t}}>U*jmJ)`^N;){ZP$TAZUYZ!K(S6|)Lu zx>-cu=}q!{SyU~5z8D5X_9e926L+-n!_=Zbx_R@H+H`*+DtR@kZ`^GXDufCRF#G>0 zBDrd@<#HaZ*!mZ7mY8Dmj0fcyPxShus$?fH2H|VpUj1g|9g>yR#^tNxM&^DJ%Ibj- zpoJnnv*EwFCQ6gcWRO2|m!z#qZT>Q1PSBr~v@3@1LQ z;aZK8d)nm3!JM%1QQ7*LO2i)u-)?y(;*k@KU5h9anPeU{;x%>dhTbf0;nMLr@!QNo zoy+k}h_w}7Nj;YH>HCANvz7nO40^5YduNM`4755+he&aHMV#tpIOJnTo6F641VX>W zF|O2nSCkOAx^T_#2Z3102ydF6Y8mCXAtlY*(kO3b<*~?dcx@<4$yj|5k60yXa&3LtClh|=CW66P;Oa_$%o*2x{v{)$T5vr0e?GIKluNgwZ>;k@>sk#9 zCy|eex>Wba4!=neNTUVJcn{o13CH3-i^j;lfiYG59XY()II4ABglX|r-Wk@o8>=w9 zg6UD3db`9UJ|%NbNdGlnRAn)ya@r0b-U$auYM0TmE~)heoBpA1MFbYe(R#q5J4aLs~q=L|RBmPwK)#2TfX^9Hn!ZLd_{ZjPn*5rBW z`|kj|T9H=zrMwrT?#5P{bTEOpp9jgVof)Yl+y`Imd8Z^1Cs#LuGkygs)@KS z`Sn3^D1??^_xjtSK)bRE(ko`Elpmt=(Ys9j^vK1R7xa;3B^2_idG-QmOcu2Sp<{{xUCc!s=Jw0# zNdvgkcpO`+f4CRn`el6;^Q1P5dm&VWXDbi?FK*Dx{vLOb7hm?~eKHJ>co}7y^^1i8 z2EypJml6DvGK-k&Du)Dy(Wh_xzN>=g!?B3xaVAb)z0>}6QsuLr`i;#KW%id$?;`^R z+Q(6%*^VPIdetIHBdZ$?dCw>cV2@8JPhcq8;_xO^AMvw_o>~MU`H0ErBJCEUjMP*OPA6!XUkllElTiP}vJ&rcm7 zC?hMRBImiiZN60E=P-XmPBA0t_nHz0ML83y_f1R3uljc+k|DyPG05}tyR2IqdH*3B z{M%yyMWxN!I?KDuKlliDgR4-%IG{$VX=?ho9?u2zqF22;?tX)oK%w7XR$K#cJ`JSy zZWCPsHl7|=p6*7>9#0ea#(Ylth(X&@Kjfuke2ptk0UL$({jrsVDAw!MteJq`VzjS^ zl5Y%QHR5AynLU)PqP$YZXkX*|Hc18ONpg@13!kS^$;10;KcRMZL&`HQtnJ6cA5W(C zEjtV*lk?c#rf2+tq9Q82bdlo6EGrX1Ig4b)ep0PD+yZhM6W&nhn)cGjhz-u z%63R8ye9{dk>3T8*z-~ngj0NYpEGf+QYuHSY^Ovoqr1#&Djj3S!5zW1oChoycBfh8 z<0hr+zaAp85t)!*qqea8wZkCtjI)$inm<__8L=ci)Bu3{*xca0%>6ZSC2QY$D2z<= zsUs$zz#5mPV3(cJr~6~hUkHyap70qld@P;tOR5w0CFVN0^O@*c1+l6jxtyj4_Nw~? zN7Rtie6rmm5PY|Lbh)LUQ)ucqZ)(4&2BMxa660X{0^L8cLZ}@cRDY7V<65rY1;{hD zf;J)mtOhl|y`SH_%7Us{-zwV375K^o9UI-8jbW^KIm)hG`2&;$6ge}a33bBa*#=}; zz$N`RP%YzuYAAk>J5Tq8z_HExOx1oX-5u}gazl@rYnoX#I|ZnO1AO*Bum-?1A;>c- zMewge3g?!V@_>5y($eTxo|G6a3wFNAQwV-+J@!R}P~5B`_j}D5Amj_qprf%UhxZvH z+=}dKF#g(>>Nx6`R5WSRWk6*3tlXXuGT2G2qXsd{b^4ug0iGBL`&xmXtnGLKW)Px% z$q@KV_WuESv)GU#?fxGjWFG67mq?uSyyP~gcKBD$ zji~n={bM|fz86$~6CMYo_NCJI?>BKMX700C62yhB(#|@*J-H{#KdfN~LjW8CsL@{s zya$~c5Ej1fd;f2M9J9N{pO2scL}sP+ zVa9EMk~nG&tTJNrl^yY`7VninVsW;Z0r_vtuJyF2w6OizpxXz~NL~Q6{pJl+w-pEy zF0{V+)T><~w9G)B36*6&uBoZPrI$yMJK+UV8=WsBWnoqOui33@-Cg0LTY1I5HZ`pT zoc#bOBdBPa{pgg}z_Ux@E{oMSVqFV0LJ845i?UT887$vf2%@GSD`jjx=Y#eoUzgx3t(+nMDFO_^nkRbJr< ztpM~z#Isx#tWp$;SY0jmr!(2-lY4M7O41s>mmA?UtJT(67LQ-(lZJ|r7! zI4AoJ%N5|bzRj}ob0XI{T8ISs!bn!zl{Tsbk)gY>Y1vOj7SOC2)js*SC9fi=sdtf} z`M=#`k5x2wW)~MpB@u|j+pa+(;#-f_#EJ%(JxO(P(7yHR2GK>YN*`9&W0+XlNmQbU zcQm6J_h&K4=22A|+g4t?JuFPWSXcVnOpA9d%I)xjf5Fsj)gj}2DMn@xz2W{*%G@I8 z`HZ)Sy8C{>QY!b4lp-D&A`Ix915hx*v`GTsQXBv<#n8}O3|GC-D|e4&S4Xd+xCi?go_2#ezXbgvJ-?xAkL z^1Fu*bcSwyYfIH~ZsxU!>HyA!A0XENJshB^z5)GSC>1pZ0Drat#td||ODZc_n3(~% z?GAuAK~vc%uh6T!FhsZegJ&&5EVAM`V4YS#JCy*ub1lHe#s*#th>H1RV7Yi*?l0h- z41mG18!vFG{sH8Uot$*e4eBlBychxv){!lm^fK}psoo8u!zwzGw%T8 z1Dr?jS?WY5mhNh;S&CTMbMtQ+C^ciUUCS-CZ38gK*!})a00=1l0azUqdg$0Y2sqKxgRqjSLM<`rsw1 zp!U=OI@01SK9lM$5HkmGbEuf7wEz$`71PqtfN|FC*4FO;^4U8-a+}`l%>icv&|i0+ zdatyb86sW6Q$(gT1-_3Qg3YvCJdp!200I}gfNx&?wig|C7El18b_kQD3QdiT;3?>s zWiu?oLzPP#>eGCvV2am2z$oB6b#A+ntZ*W@&|)Cwms(~&xrV_m-OtnGYDE(y1whUu zFk}jzusB83Az;4z41V~j#GIcYS^yld0iKlFoE93))kIHZ6Mtkw+~|Ve95ntc0P@iQ zq9sZVB7~qz`^`3pMp;nNd3bEmB4j}F&;X_}kxRfnnC>)M;@$!Xm-uaNrmLF*apZ!V zesY)BOU;_e5);t-wH7Q%DPh~}dasyr!&@;!=il<0G!|3T)xi;Tl5!{Oa}dA8yAXo17Qx1tR<$=>J~dofRL z>lWW>-UQbZBv#pFDXF(D{#2$kjR^9bkO?(X#jIXF83rzbp>->7Fs177bwv^QRY@A3dn zR(ON%uYn|nzGKIAAJ;NK+yGIdr>U&=^QSLYPm=~ZcFV{C2QrnF$vW>Z<$_okaw-h% zGNxpudKxTIHId|0RX{_@v6II0{j>rjiv9r#ii4w3HlETOB5ZMbDb{K$8^tPBHdaX5 zK#613fi@m1-lkK$#9yO6+PsHHxB8BNEAcBzd>p0Sc3tAVv6k@#yQj}rI|1X~X1@&Y zz)~;#!I%kG$z=BhxL)WQgQ`1~ zbPiDYgGJ;9RJ`hbF)5t_LI7KxAyf}L4hq-;+VI;z+75_Dq%)8Tyw-p7<^rg*b0uk- z3;6(l^m7>-n=SBs0l>=ZnFThsw+Hpb5gML>@b+|_{G>5OCg{8bV5egr-v{{s^<5z5 zk_p8Se`>JoivwWT*bN{PPZo6XzWL<*!#ABg(9=W zP3$FK%rQVFI|2Pxs1!QDuO9*6qh?DWs4PH1S*noSZ!KAq(B0h)bm@MR@PU#BIx-`> z(ESRKDVn^6#vds7%CtG)#{I!{!6pl69F^eDb5=FZc0XN#-HI?iP;OqFn0V^F$%o{CzATN#&0DCN~teQId%ysU315;%xvkLX#lZYwE!gb}g z2+0FHiRF38E)uoT$=n#547*wT_xJCi3L+q)mN$N_s@mrQLfzGkAl(!~+}7p&r@+!?_w;mu*o4%~i&GN2@K0$UO1H)KA}pfrF+RPdI-xuzQ^5Y3dmm>7GyZ0cwO z!R3vb8CVgZMxz2`Hz+jy&veCxDlN$@Ump*YOMejoFu+~yB|1~Xd#PLjYv`aj&rCpO z-wSgFUn_27QC~%5`6Q$yzAl`ys*{BR0Rs;+q0d~S24g&U)KsQL!{@u}V*O}v!gFoN z3ZmRXx}r1{k7X~w*PEM20--eva05)(87lBgf!PTVCo~ZGjC4-|bdf@&;1H^ckA%

      @T>`QeetCKYYvT+`;2zNuQv%WukbDX}0?8-v>Nhly zY9MPXJH?O4$tIHC-hlFiFtwzFuD>)S6QeB&xr*EhZ2VlHRqi_j>BfT)tebX2J0gX~ zJhP|UpNq%fJ)rIoyG|;fhC|YTXb{wTT0Q7A9jrM@e|zN6D83`{vr)c5Np~QY1~`Q; zAAzwJ6sV>_-H>|oR&SMO@pLJ~4~?&(jPb2TGwv<|CsEZe-ItQ5WnJ@_&H1ezXI^FTAU-EN!;N1*f) z$dm&?;J0#{mzQ2k&LDXM;t9E^4^&*H9tZHZKeV+y0Hh?jko$Y81%Qr=o>>A*t~X{< zyTs`BBsD^}pD~^g*D8UG1FGsYXXNt19kAYS$Di)U^Y-Ub#0Y#UM7t`xA{f+M#k7ze zs~cN|Uzn}4A%7a_CMm^uKcQh_A_gGVK&0g}q@qC+`~DyX>0^|$j zp)?FWA-$C%{|0POUa-*80anv8&aD6{?hVLZpoqAvb_rB*IXQ3%7I`rZiia)g$2DrL zVR0nR8R2A7K3kB)*I%Q80{b=|mD$%C_SJGomLaTa8yo|^kmh>PtqCF(&dq?c!lM|6 zQpbJqjGN@}BI|ap^629H2K6K`!m=tVBS6VMRm5_>A@1C|DIleJ(X92lm7v5E?Ff zA#SP2DIWV=PI+(@5~KIdZD8P5ZUF1yg!)PIr%532BA7+gd3{bGEfytbT4T*h&(0Sb z!>$jUsP@91>C=mGX0U%qh z6sjc$jMg?{yAAKkxB?vjY!o6j>*sg?-m=woOjJWZAtd4s*8ddG_ zNgweei%yMw>LxwC9<5~6R_`UYGPE~kdry9u2_q>inF&MVe3GMnYT;3)f6y}*%E1#S ztOt^z)oY#SK61$*-mk1xcW3X=d`Eo!?po=ULCv(p^Mg-Xl=i3#7Nn9KEiXfj@6{+8 zdd*XtzZ3bOV(AMl5hEh%|13)=yCS6fKI3$e;L!|aAvRMmQ;7QDJh!_@rNmuQ)#2A} zqUXQkk(}S1&D&&P;3+xSmE8MQ#$$a8)7g`_7#7&_HAb=u(;02+t&Yx|EYDIjvl)_P zAF)9?!y4z5vX`gl?s0KqSMP={_s@0CxvNo6@h9!3{NdRACuj_W-m}uAfLs+7wI?@A z(GPh0c)P9%B7;qczsIyt+VGL(LTSS=OGpbqekw(^?8}PoN=hhJCW%7O8C$poE~lwZk-0%-)Q!Nr5Oq^96%wFr?@*4TuQz0(!!k7eD1z3=`BCsB@vo_m7{0e(R>1g8)s5X;h zc-9jt*@h76G>_WsC%k`|7X$+FR2d01r=%IQQ1-0W>KT~)`;i}M%wvKLu{>Yoj$h>l z=1J30=ZdHDsqogo4C!ORP;^SQ*D|`m?;e8;*>`Yik|d!yE2%t#-O3FlDfN4__*>Z+ z`FPx&5uR^~yrKj|dQbM3ft#<6H((#F*9sN1r2xYvWto)U_|w1)%lTlJZ}37;r}iL3 zlX{0-A{W7%edcQQ1ANs7X5=q$Us!gdX9P!4+AvYJ)syr8@5dJDAonyVrrus{%Dd|8 zOAb8Fq)>jw9ka5}*LCc7pOI$GGr@fn)&zs2@GgVFoL%=WL`1qD!`5Ihf<=@Cb_)R# zgJ@B8VR*Xgu7dd?&EXxDsLw>}Xgk{UT(JL`-!pA`Vc3rhGWw8m&J9@M7kO;&SaoB} zgjC4V=}-te;~ILU_9k9oG&M(Hi&jbTqV1jgs9>QLJLU11Vk~7|9(C$1Mc-GvQ4Wyo z6peg8FdiKHpIXO~qHwSgJ&Q*=2>x+a!kyHOuoGpUFk81c2i68cUXOIAy#OH(m`I2J zRf(fTVh4wm_=mCR*Xo5>HXaq~ko}v=;_HTI&eP9#eT|ta*v+5G)%Pn^yVAf67O|0M zv9mWDe?r)ElEyM;`6jIqDR{l43FYi}33J|}C0fd*E6hP0C@A9{HD%H#6E08!+Ef#9 zoNtui52PtO=TImt&?;I2WZ!Msp$5cDA!i{6Zt$VgBX)#e?aROx1QVMt_E#GHuC*xQn!F#Gx&X?oSis{> z-oNSuI^LY}%(a#tCp@^!b=V8-`iuOVL_cl}C=B8XW#Q_&8SEYe$404D87fUX8(9t1 z2;EXhvtSVk&2^GdRr6l4y(h{|;38V;aW92T;%0fEuA1W%o5nxacd(5ll{Gsd)Y$N} zv7a?oKa}62g0HLkajP;-;;PAZ@>VZsIV2}yAT^eogkHDm%V#!kA8xUb@0GN~C~Fdx z7V-MtQi9`B+y07qlC?yX zcwPuQkG!Z>Xx^v{O^Yaos2G5EvW?}2;)exew&8PgrXyiHua8b-W|%b8ME{?;Ei-=~ zlJ_eZLwxn;^lkVLZac-DaC0Vc#Loe2q__m-h%(yW0gz_vfIgC2lmmbNMDbEw*znx=mj9Wsgg7a{rM9kY&X6ho;M@4%+EJu#7wu<%^?WS-T zaB}r;XiuEFy5jwbE+qx_JvtMwt-(Q*&Z%EG=Rnje>3If(-caQqIxkq{csetDcU_b5 zXx0&!o~3vn|E1VXP|<2~Pl_dKilU}}b2HLBUDY@!I3Qf(M#g=WJXM@jMAY|+_xrW$x4nDoyvyg|nR})Y#@)qyN-# z4s>UKuUt1Tso^Wm)m@9-4A6VcbdWY+gZfU4#`Y2A5hyxGUj@$M-#K$LGANaZgt#KQ zGZEv5(b8sjHo|@~;EhG9t<$-Ue2`S+!x|-Ar>C5Li*v#)6P}whg`pIi8DVsYi9_-z z_mgz-4O|n_uQ5l);8DfI@;eYl%T&z-kOed5JviAxAhp^rH=1AX9M4?hr ztP))qaTz}+Y1E&eWBO-R(%u8H{;!6+k(Gphdu$Awa?Fkw^M9deBYWp-xFd;$?c0(> z7WvJYX|Qae`~itok=$W+Yvx)C^X>Ncd?`Vk(n?c zN?ge#%C`JdQClV6;>b1C46L_c|1Ok%QMiDR>9hhkK zYB2Iwa2|>12b||oLALQIt!%El%1qSU<2mMG^%U{nko%P7zaHiM|8pcE)kQFL=}v{( zU1BPf{aLS!hDYl_uG59^f>1-~Kjt@6UcapGmvlv4-^d`93slamf?wTC=)Q*Z0$*e%}I?fI&PWc`ay~WON z@;>>0x!q*bpD%Z#X)X<(_e89AAKzT=1&^HevT_uwlnD#N$wA!$bx=Q7`-f`*c$sxN zPCF@rlmRnDlB{alrliR@iI`HBC>0J&CS)da8RZHd`3udWFE~h{%NPrf;0pUU}050>f8|vBY#gtLWlyI#JLsD8-^U z*A)=Y1!%9OA&)O+T-}WM3<1}B9DB(*W>aXWUY5G>BOfS9y@*-MB$3+NE`p;k2(jxKQOe*mw zkB2Ps|CX@3uNatWk%h84x=A*6#6niR2M>N#*}>8DI=D#3z#F0kjo~+4#%toiFgy}D zhU!*48fLfzSi#32E5MO|Dj%@yL^L!oB#wNB8XK(oOj=}$X9tnOAz)TJ{Or1<=Zk9; z{dH#>!Z!Z8N>tq{E?kz;;+gcF?j6G$e}fI{lNSv_sae0`b3Yq}?8FYm6p6kP=6vT( zSF{%4)!A>yPlP56&z4NH{l3{Czx5&*RfvVVH{rXO@1x4U@EwD@K~mzscShjFjyONk zTZ4diJhvPE&EqvC*`s;`XCX_3M?VI;aGc@^!u&(vm$s6rZqU%u*YD9tt0d z)a_m!c4!$k+HLt&PqT=Tne$nHIXac{64{HdV=JRUNKE@79icy$K2_pTDY6fhNt4Ea z8Zq;YwBJH~2a~;*y91uD>;DSLtZz9DnD43hP z`MXqCtMuF3eO>!_@ZzM_h{HbvK25I`k1)8yF8EZ?qewn#4X49U@wN*vi7PQQ)S*I9 z3fVsM7pYeMe@wk)Se4t?_Dy$6cZbp`Al;oxcS@H^NT-w_-61V4ARt|f4g~>`STqO{ z(z)Kb_TKOP{QcnJ!B#eFUh^7r%rSoBJj0VmjClqsAj5h|fg%cYV@sU}Til3{?45VdAk4MTggk3hL{y8%m2w;zz#`95~VczHo`=JtPqbFSAWm zP$Xs8MhN6@3Kh7*ZJnlahybNlVD*%eWreYBxZ@WNzaN-I_WCLK`*3HW547&z;uXDM23ppwn933KdU}3 zoi}L~ zxrFd!tH~?c&@FpA%^~vE%kLg zh6&RdnD&zv8rs@5aieEVW?(}Wi+#rSEXx(5vLvt*3_o3RtG`W8^8)AOd)RlN%?&;e z>zEZIzx{Y-SsAM{Fh6zH(3n8K(WauJQW!7>&HF_lapz#C* z()A@yuXhS~fEOAk=eV#d5Wig{Srn95SXvSXKL_}!b~QXrnGeoV9B$!SKY0jExL(yCx7u6*kvK~&q9$}x7FD&$o{yN_DaKgPXV zQ7LnnF};-P4acrC5uJJ`$&yc=qs;JG^zlQ4%EXE!cBa|I?a4FkmLpdxi8AvGAb2eA+&%xL^Vd?1dpGC#NY;SO?GIS+|Xj&Ij3KG5riKld>V$O&u(|vjfBm57cVYwq%K3 zP)`rb@muSQtO&{fxv;PR9>j|mgBi0we!w4+nM*2Z?Y!Fx+>hB^e{Q9ngu-`u+2X88E&11F%ng z9MEwwGBnUS25biI$oD)!sa;3_@z^(#DM+w7T!YpNM|-bRiWb1@~0uPH>@D8_nfO+XeU9 z2FTC;xir<`?PgP|yMv&jK9%%5oSfelL$UxcJ9Mq)32AUaE8xP2zXiMow#7B3A_S~J z*V9y`S?neIFbFCJ^7a$i=exy;vC49Ca^QJAaw4M=3cB-6a{+H$^WE>?P6`q)JiN^# zzj#Cf=*15xw{3`gRXfSZ;QGA-;vnP%0)YTh)JdWM@CCqKIPM)SA6?TUH?YCy7J(Vz zEBnc9jyE=;W@Jp|VYCBq@0bA|#`E*@>l+Q`x)9T()8}Z|Cy`I!}_BG3Bkv)ph*HNix^8<=AJ~Nn3~*Ya*7arh#6QWazV4q38Pt-zrT^E8K7g zeGYA#1amS)pHZ`mk_R3$X0Xcp2JpPXe&tEax%7VI?{twIueynGPNp_DVE}5+R%LQh z2J17rzZ1dv5weNYbX)(XnkgdSm2MA{p&sH%BMp#yR8HZW#A>TR6@& z#?fgZjbP>`=UV$C&}FHpz#u57TdkgGm*y$&?hD-U<-T%#SOgYPpsm>nzB61N4yat! zfZnQ{gq?_TvV5B6-ER}ABSasL5d7G@6J*o0o00i5uQ$zTktQt()WvL>n8V4*e9!BE z2%4n_t5Y0_!Ehq>#CLo1UJe`?F_QHfgjF5ib<*^Pc_adtTn}!^2+w64$E*Xf=?hsR zg_&Q80yfET3<@kyyo13T3N1We1gL84(KN=x?Ldcul2tr(j==gA zSGp1#J6k4<9gGBN4*$1|LiAQ|Xgi<>VAcL`Ywcjq6{V@7<5Hf5rfmvXr2yl}s_N=- zzo4#)>S`Akm!+?-IjV_4#0PsHFfdPF^#1WDCL{9}#tE2vZ;faug**g8G;l=!6vGdE zSK0w}2M!g|u^;j}K+eYdn~661eNyA~&upkIt*QQHJ1roj02#UqTDsSSEblbs%X4pc zX!!b&*!8?JfXV18=$r#S@CfWnu-46hjahq2#k1AQH`0He<8d&i-5O=$;@7Tn7dBZ)AR%4T7IFa456g%Q(S*~8P1-p zCM{qpAr?kEwgS8aU;H@ai*djuZ@+1_C(v_nq9OMP)d=Koe?j%gEkPhuy1uFFsP8K1 zk*`3QBysZV+pAm4Vur^?4Wacfg|IgN>R_~{w0O#dk{h|vB$8D_WH50)BL+C2Q$EH0 ziaPZuZ#9GQ7JDj^uZ7*B2;jkuL#Q46M|KqP;Fbh_+mX zXZI7?X(=6KT*k!DlczX&cq~9H2FIyqNnC<%w48DAe$WvnMC;5ghx-b1Nq3YiI85EzmCSB`j4D za}fX%WpLbt3rO)IeX0cy-pT1xUEL6qs&Ms0+;H0+Npzj)UvsMIEM3M(X<1}OW^SLl zqz`1Jd^5-B+I>Lv6t4ZsNTL6`qedohKuM03{Qfi)ofaVg!<7&xQmY1au5zsUE=J2f zp2<=~q6?g2aCuEYCd@D$0fbQ1u`kS7=PC7o2J(-&q^B8#ycI`{_3G5+N@Jgb;MwPLfIA6WV8P)FBPW@q(VS4}FcZf)wm_?

      =h|IGR#A!O_HM|3bl{Km^2q=HKD_#%4}$VTmb>Q`I`c&`Zo*kCmR6PTX?=as2HORX7|m^X!e_JhTgln zxY!DK8hrfp$qBTX{f9u7K0(==CUXSOxX2)t+BNr;t>euKMBurk&xpBTh^|!*&)*fY zevNVmf@ImXn(}kCW@FdVVwegZ6Hz*b@Lv_b&%bHl2zb4?GI{&6@a+8<9-de~+HBsH~2;97sQ8ZB<3=!8s zJfPCDw0f)xQQ~r%IFj$G@r*PlF!!O)PbOO9iwYsLr9Mz=&li$1r|{3gqA*wI6MHn2HrVOl2|I z)I#?T$axz~z>yw2J0sY+lmB*7;&Lez8GXfjN&=3u137R>09AnlK>T9C224a?{`5vh zvyS^jt0fRMKO1TL+0@AShx4~Oi*Dc+8LOOK28TQ%Fp1zS&)x|*FF;s>OOTf5`~LufR2adbYD|J=HODnV3m*>T$jIsXrx8LDBwC+E_LtNxdDf^($teT0gPbQ;zn~o z2aljLf@UC>Qy?>AX1u>SZwHd$)y;qm2)=d$5;wZ;b*R*}l3BoV>I(?;(Y`L2XIiiU=e485unRpj|^s0OJNQ3^O?34ItmofL;Myaqym+h5uHX zf&3m6!33`Jm}_VgfUFVBJIQJUB+d&Ib;+R|9O4MI5JP z0P3;q2|+|gQ_mN_2I8n)fRTqC9z7g_R1twAq$OpoWIKZ$ibo?R zXg8V)3@rAp;mjgj{E*8PfOT-0JB3ZavXgy)8{0uLLF@ps`L&&$G`E{NJcfi>VEuu* zVN(P!F92d{r&Mp2owk4$H`xbJy52+IawIeY)Ej`x080zz`@r$x*T&MAdhrYV38-X> z11=JEG@90bcP*L@at-KWgReKY-LPAr7)xa{35Z=dCRx`BI9K1sL{1(w2(sr{S@nqX z6<#7=D1CqJNu*Y(iXl(oBGw4xx9xO0FM6Xk?i17~FS3)*0up+0zjt?~2g#p?cB~JR z;ERvP^?F=-<^(nVKqThws(LoD(0+S$O2-tJWBt`jV(`)mh%66zP&ssr?3szKc^)R` zZP!}t!GbP+x3hf}Grv3d;WJ^@{q=TlwO}_EbZ<9AqM9#!nV;o6^Klb2IJ=lWqnul` zX(-v5ODsxYX+nroP`ay_$`aTC04|&>gl99scSFIm;RtwYPiTDA#(J^Wp=`mxxdHsw z{3n(EcL4Qz1~3|+!fIe)Q77ovnvbGr+Sx-A3t-t92f+1x#W@85i4H)8r%szh-s1PiQ42)*W z^_Dy?z*-8>6UPaOip0n_>75?;CJ`V=tz32T>2)i@$O052;_qzC7r! zWx~Xz+MbdZh8xo?-)RkNPPp=EUgJd_MGQ=t2l}i&qbZy+QJsoqru?V&?Qg?;y*j)- z8SIkV{CsZ{h#C3~~ly5TlL96HLh(KH9A&rQ*fGQ~a-R3KviUt|j(|h!~xZyLpj`vKfs}Je6v2M6+vmvs_T=VIxAl0Ko6dz*`t(`5^5tF}&-idpQ1GRp;j7a#z)T!$An&iomk{ zD_rc};I5e4b_fSa>NuuANj;#0=mT&&q-VGo&k`7H3F5!;UOME#}Z#}PbsL28SL^H1X zj`|PGtth#I@X7ETFKs+ zBbej4U+fs;Ux3}da9=Qx@`G}fI>fw7-rYZXwQ$Qr@S(ln;eI~HsM>+&Buo&0@!jJxw*>}a-5;y!wQ zC%S!X1w2PG*Oj`<@7Cyn9nx|4gDc1d6t7}CVPOTGH-|g>KEWVtwWQ_?c@5Tf^N60V zQB5ik{S&hwBb0e}so>=cxV1x%4!Gk*1P|tqcfsuv81gvDxd$^RumcAvI0OqUYT!oG zV0bK80(N%_p8$b-$F5#Mo<2WpE;;&Kh7p1EP4@dUQwA{$40@a`Ogt#UxWgWeM0fAg zrqvw2ZTQU>6q2lv6qg6qFbXM%!NkKrj@wt2Jmx!D3;wpyb4yKo-1p2uq~@%~hq0WE ze+`WK`6#hhU3;o4z9hj=gpo<31}_oO$4Bi$z=8hqBA&BxU64EB7vn%RXnKL!ZFw5r zT~VH1;yy=X*-19UqSXFf_K}iusHauH5mw{++D>s649qUX=1yy$-HjIpsn*U{2mM(R zz)Iz8EW-Je`{}|ia`wnQm}9JYCiwV<=b~$B+U4*jji1kA>?!W3sL#k`Fy&^Cm&|42Z;~D$huBwE=!w{!(QZLn#rgXyFHKSD_ z!j}bePsNm8u`c_-E23692td$NuP&FJ6Nw=1H8yBlk_>{slP7TqTDmZc&` z)m>NNkL zE*n!^UVnI8)n(gCLBb+oFHa~6X0Bf=Z56=ob_$!ARX}S7s9YBrg|Q)N_qa>>hG9>Q zCLmfB2B48a%VOW9zme2i5(QxbWTZYnUKo&&l6HYSK6G|xk>=2SC>|qUFSCCqEDUKv z1EPU;&JQt476_f~p+BLBLyvfdg1hP*hwT z-bjzGg?fx&Xp9(B*JLY5rw2sxw8@XT@v~lkdcyI!m-rEqbI}mV26j*HF2ctFYt{=_hj7S{hZ7L zwWX)<^A-?6=6}xqn|y0_)iYkFpKi`3D(vnUDc@lWBNHte_uX);>3X4IvoI0$A#E0- ze#R)3hpH`jU^4KsC;Ta?AUAKm+?&~n<*1!rmKZPyK&G|ZeU)bw1SYECw~_U~3i1=k zSh{z=3*JVNOh6ObS|c8XIJ(&*9LoOXl@u^`eCfCVP2d?YGt4J0*AF|McB<$OsGDW+ z5or2A`!(*UVhRW64bG@avIm;=A)=Zn%XBGJVe*zRfaDDANk4CF7P5$a4i;qaEdLtz zZRoP4dl0ge(EX6|XeR<&6PA(QQbeEy>)n3~TR6#*iC%j>f$i>dPdcNRe;wC}UXOB| z{i80>UR#PhulwSR?yP@V3-&-t3YKTh91%0 zq4XUtgI6(Oy$0xc=y>KBDSRrYnO>@nf3)f!Z`)3vN&sah*x3Ec_4MzJpPnAvW~BFb z#Qks?tt5zfU6jw7P4J;g>IX#{+DY45xfN#NyPoxGzTz`=E@eo4}RQ@bAxfo{4OZ^J*Asz9a~~w8XV1 zJ_*E5=9rf+pjjNG&b>1FquXMJO%~_eK#3o0oI#n$MMwT}UwlRehAu((ywYJZ7|h5wVsUmn z`$qCF&fNJ-mxC&p2?X3wQyy&ZqXLKFFH{SHCzQZF2$36+1x0dF)2USN|At| z;bIkzFXCF#e!nDQy0Q-OQ>-6j`Xp>2{9HA2)?VLHJ?N!oLnF=4FrBQ2c^Ebsw$uNb zRd?f!>q5)!j0@hP)tBlg9rXNEM=5XkARXXOdiizr3UAxemXDkK)fZa~D+xC34F{4d z?pdNfP16nY#~4LiUsKz|0-3~bOixQP#$o?~!4RG3w2sF~-X{%&`$xBttL`3|w#jJZ zEe6z$^zRZPO&~_+MNigwNqHeL?$d$~V_PAwBY3gVi?I4Ra%a+d=lT2jwqD{|Io4~w zAADg-Q4tkC?8Jpi!qVi6U1PuTc#)j_y{s0}!RSQndmN{q<=B5nImJ*|KQ$whNDm?z z|A4Hkzlzj0Msv*&F;UQ#aMPJKfMi%AmMtmfczX6&jhn?{R;Jc% z3%_IT_HCL)XSl;UOpne^!Y8a5&Ss@ciL8+dLt44~jLK1x)^_Ly*AL^9J$f0nNaMV< z7pJL7B`HcgNP51B3>vgF5PW=ERD$)A&_HV`TY%t&D#&~nCzn#buY8l`q_jFV)mS3y8Xx=W{kSk?Aj80>3_!~0u|g%8 z9$%K2e@x_V&6vZI3$L1f6NIHYJhTK*)dGhO$!?Ks4lrquwGN_))r_i3Q{`KeptCd? z)zN@k|2HhJ-fG?l#4GH*DN+jbi^m6V#g9bqnyC~fcdw#5L_8!x;sRdIKOqRMIP{!X z^d*aE!|b-td)i-f)fX0qtffVoq(Y22IlSkLo^x$c^D^VeeR{5L<(G*~_?;*60Hyi? zi8~9Hc^78Bb!hiyhqdsv?23Mh&I?ceF0267iboI*mVFEZeuhRY{DRhMJe*b8kTF-= zk6ZbeVlyJ;5t5}I4C%tNJ)PPVn#{>pD$|^m-JMR}jP3coVlaMpsYAsd`PM6wu1QaWV+UU8_?T`rP6q2Emko)zsU>(+JX zvoS}J-bH8ddi32#hiLfqINzwZAu)+I-X}8U5L3>pn8y(ot2Wmep7z>v7;UO~Nw~rr z%1hfG705F+Nqq@V5ZhX9JAxftNwoMwcwg~|<1bxT)KBa3>T~F5#fw0)pHU}oreI87r!mKs1OyB+jAZw(-%=bB{XjL2D#QV2k^4h#{Wje`8JNn;PO8btdkF3 z#OYpmOHYT}Z@}v{$gSD>UMd)Tt=^X2K#Xki0%!RUon`k$s5@fDbN7YlIzhS8wta)I zryXcG45mo&6r!#Sp>O5o4})$lMfd9<$+@)nojj`VPOKE3&h5m!W6&U!M0xm=5l=eI z+#52?Qs3mLj74HCGWR&rL*ve8Ddah;&4yar0yPTBwk)TSR1FV1ns(_<{Xum5>2(F0 z1D$~8alb~E_BXZ1eyK(ib{9x51fI&pMwxzsp*<5oX2DPVy6>&##NtDbVjl#7K9lWN z)cEW%eoh8Ml$M7Y%zf=$!qJ`^LU^s=AsTh&o=Ksbk&c3fGb^6SV9NK9u4Lrjf0qFd zg}cosDS5$t4>EZJ)jAHYcjpCX0!-)NF2h6ptY;;-SF38uq{%OsOrmRa?&1L(WSXWM zY<94v2z0@4|s)C!>4=vh? zAwMm~noqPAB5$P6qXLb8z|4(4@KnJ1~oj^hK#4M~)` zhB_1*sZ!Kd8;HiC?YkpThPlkPA4>x2xfQg<7nGSwBW=JLZ2e>{1w{;J* zd-U@NuKR5Gv-sf7vm+3G;qZDq*NI2n>>q{b!!5fo+2euSC$^H?CQu7B&Xqvi z4y62Tv{=d9mr|{&nsw18Y+Ma^1O532)lD|BEpRJYm(4Vo|R(e(qvQ?sm zGmv!Fr^xuU!FpQVmqbCjT158HbR&-NvI}Y={ik-NzRthD3p%d(Ej9~+hs208vQOf*wtlNhVTEXw=y z^7vn%wezXlV~KtE0drU$3=17$EK3k?boyid!m#KY+OrWK2|)n}Nc2m;L~8=AHANZC zkqhKr|06o@KM+<%#=7nq&lRJ1P) zv{bGnQK~3pEMjh+qaZ&fVOC)XC5XF-_r^hP%nU_p`w&AQUP6Mbz?YBZr>kSBkB8#J zU+CQ*nK}kFwx5Y0MWr-eV6*jCY=})(#;InL%SNRrwzXFh7lu;DQ|8ovGc9-9Y>7rcJ4xoalWT+J;yW>PvqZo48ExwXd7$m~J6R zK>srLqPkfqb=BZqE>ajyVN$eQF5kQu(C@~ZirMVbaQiG$92Q&5j%5*}cNl(C(iM|+ zYR_Be&2w@Z|5{5#oWqy)cN3v8?GXNx@x#pA3Y^0}eBSEj%Z2|on;3kvfsZq8)@@xl zUb&~)3O!TExvWB$lb3vY*K{+2{BtL%Q&q@->-tD-@_BK6l3}~YLCECR!u$@I_wsKx z{0{g_{1pF1RTJ&qZL$De*V+<1RdTz0`#Xc&SFyLR0XhHX2cgs%xRDNB8&BOr@=j;# z9!k*b%Iv~;mV|L4@x_awU7kBVK1GvBQ}ai2&)(?%A*a*N{7@z9)#ak?zfi z5L-ieUK&U%1n|sGllPOOv!kdBJj80jsx>}tS3}Vvi+{Zs#(8JKuZSV2_f1&(1w*3? zFZUh8s=;_hJ^Ha}U+44>!`EyNE9{7Z*hciz9`&q>Sn4CQlX_yAIHEf$__?tAo517m zNB>_#wMJ)nDi*y51}{ScH^v{mm!ZVA;-!4ly;Zi* zFj72E%_V0~hU$T4Sy_5!xmsj3e|q7Q#?3x*tk0Ox$0o$i1?k@ljC8|v=r75;P{Zw0 zq)@V14u_j?*&rWIE?ldZu%08N<1fu>D~i{W`xsA?rn&@NV&rpZvr?jN_ebV6@x6ZI zYSs+#K|Hb+A>Y@*g;;pXDr#eEHJIqhM6-7DK57nhWU z-AnN(lm3UPvvN01tH!Wz;R{vAN{U>xC4=>LZ0*#p6MT#pQ!=9QFCkkbnx^(*=cM6E zKhYVx5|OG$d=pq=Ai)vJBTQ9?ak+(4G?5#;8|${>owjz1g=)B5#hVn5#G4F1hZIu{ z)}+Wmb`fUYKKz^YfN>}YpS)9hn-m6ebkqn&?9~U&nbhE#-ZwF0wUMVXj|xd4Jo`8} z^d#ndXc~O4DSozEhwfHnpuA+1m!foHtMBU8cP(6GPr@pfk-qQEK#=#K9mVl|udwk5Cw(`D{V>$W$-!&l&7j&c`o#mJ!%klhr{Im-C4gy@-2T$9K45YlvCcJU=Ssf z-?skw5H9h{kk4*?t)0Fcv711N;aC~N^?l*|ItoJ!-a+Pzhx#~_!|FPIJ4TE6luH*T_|E`ip5T5`--PLdY53`Cdb_WAu5+#BsymGru`CC ze)wRl6H9+zE~hiJyg~JmKH}UqL#)F|DmtnJbR3$zYlLVPq?MoyjKmF2Oi)v(C>l`kdV ztUodN|Iav!n&B^v`vtQ%%=a~=8CN}ccVGJ}5Uwm43Hj|P%M*XYd)RA@@4$4!fhDE3 zhXw>?yn?b710l}H5EBDO2q!|0;am`b-!yWw70Mitri-_h}gtUv0g*oP9wS~CkBx{A2FIVdBd zGM~tJ)L&IjM@Z+cmZJ~En}lC*ma6reML-`bUqae-3SoZrtq#7f6e!RhH--n~sEKo8 zM4AkDX6ESqk=#y0jMT;!Y2N!{TXEL4N6*7^rla3H!G!ePTo=8)`hPP+uU~x>+L}#t zU3Wj`cwbemra>Z&fXwoM@)(OSlTUHJ6V)X;O@&>&G#6Rc(jhM$^3=M|=DiFDG+>KG z`z8JA2NMQ7bfO)z?VGsn#wHdnedkPVLyHjkV#C+=$Q)uy?rbQ9m1B+sSGa~s(Pv{u zE63TA=LUkm9fnh6#l#Gv*3uZJk_drDtPFL`x?;8!rNWw@;;G=N;qj=jcr>pA)s8Ho ze}v_^fpYaA5%DFn5Al?)dIx;k>@NEMrp>&lRoi#!cq_Zp-;Kx-3XEJ?oQNhFTTQDE zzsDruDrLFTUi6qr{ro$&;H#Q4o;+qpdDHozO)V{%n^$E{fTUh!5<#4|B{?oNWqizB zu+;m@JthAo$A}&!1Pl7u{cB}RmjIhrPzemDv=?%NC)CtP{_+C8D9-49l9q-=DB;9F zoCkXb6`z8#kHk_L_esoDad5(cq(mLNj;N*EB}9kPs-{~PunZ0 zF^Ha^NLiA?R;p$YV$1T!zh)Fgd|t2ekzIQHK=o!CA8W@uvsTcncGbGts#8Ei?*J|N zE4AywyIyTlZ2hC-nsiLuG&?oudzOqa5mO>5XGG+tB#WQPV~imOg>guQJKJnc6>&UD z6X$Orq9`Fz!`Vwit{D@qL+VgOJM{?bgvzjubvd?$ry;LjiDXAD;l-#CF>E3ziV@tlzCI35{XU6KV9t??_6^36Zz*biBNB+NoFA1fEQw(qJH( zKqS5z{}#o%b@SOr{-uk;{mkLWm$Yh6+U{0_{!b@Ci6&23bE_R*VsouV|4J59Qdz6u9^h(4Mg zLpe$T!iAlc?z_wvp0?;n#iFLT>Y=hfXE^OB1epE!efd7o(mE!89}EtfR^#PnFHq~> zHGCvrb2Mk?EVDlMu~(U1l7E|c_-9tqSCk)j>=*Iv8#kVxa}xv$}m6z|Qjj zrm<(OT+J0Hcj|WgEeU%n&|W?3i9NS4_s%wqDw*}kM%yDiW?fExj_FAj(Eq%*9yNDx zE52N{px1sfKu@{cU%cH9ee9!eDW0nE**aC>$ZL#QZ3f$jJY*=#WEx=-M-;;BpaR8b z{qjkn(5lu?xw_%qc0EF85g}d(t%&r-85QJPrz`H`mAhDStP~qNZ8p)hSDa%{TBp4+ zz7Dpg`Ryv!NZBj%`Uy%mxrFRB{O=C&I^nw)KGhQ1KnkIsSind6G!6ZTAiW-sdzUiB zF*Ois^LxAKgv@*T-sQd?X^#A|09!NviX)KCoZu@XuSc+ z*&tmXPe#x7K7J(XB=rPUj3oszM+uqVri)M)OGmP9TDC#Gie39p{yN(SC{pNhAvFT- zE=rV6Cl7K0%NTk;(J8fl$C{T~+s>JwulKh#_Gk(k6uPr749(w@R+(6kk&9iwxa)Kg z1pY1D@RFON&15$9D-tALKby6jLvm9Ygc>p88A+2JtnW zcV4SsTUMa<5Ptplo@7BqiB2zF+tk&fEY&E$8#bOSENp${#&>SIYas-4vK+|I`C=BQq8*d5Oszqr;csT5B(_^TC}yKod~0J zs>PlsC+gLOx^xwnP9!my$PNyeUA>Y0&h$VW#s#rvsJH*rf5_as%SHhc#8SV1?bRzE zmKFM#qSR^bo zh!+EnO8Wi|G^A(}-{!U3?tlWokMq+%_hg&l8=w|a3(A;un$7=V36GYK4UV&VWYpXf zu4@FlaHmJV-Y*=tl%D)#bUFwoU7vpQYu%b%LQo1?%gTPy5jr`xtatKUY@ zyq~3zt(xW?*d5`lF1~D~er|p`u=dXLtyBF6rm-dM6CDaQVXFA{6OvU+RctO5`G#Hr zIZz?`r(p)TnPNO=meoWjyx>R)bxhKw5kn?CjSzay4T@D`$|Q>6a2bXW5(HfHN@P-_ zF4SP&u~*q4gI2*CS~ zh7f+Z(E?TVE5NXTssSZ6B`6gh0Wf7Ra)&%F4{v?^X_Q4BR0BbYr{O414!jG{*i)^*%R&X* zBT%u%cMZNhzaFFusvG=A7=nl}Z-K;ne+ck`Kd<|e6%YwhriJZglgWdwLTO|_WwInB znIYnE$Wq(iNn~XSEEHy4aU2`sZBF%akq=+FcAdQCs1PMjo&Ro>AG?0hPOKA1 ziI}8aX(iR!>0KbywD2>6n(|L}wWG@K3J$=Bfp99OX0m7~kr@QU-d z?R(?x)r{Qh=5iQ8z_WkB9bIVP#^g14DE<~bCjbW6!#qzx*9TpI#fRHEn4t5l5%}L` zyGy`8DH3|6*L^bs%D0JfE&nYhQS|piAgedXx~+_djzA6jT|T*s$r>WYZtJVORO@0% z=9#Wf3K5a!vZPe28$(VPGqnmn&q0gpDx}+1JHbU*?^Z{bEz(~-dY#)I_Sy&su~q>^;_>E;ozsxPXk3*1G_%Sqk&E&hp`b$VX(!>V z!cRukw%N~}9H?-7KA^ENW3u8?#yt!KHsWLUid-CDuOe@NI&$Tkw`zMv$W!cB!NFJV z5+N0<90^ge-WJ(<-hwwKtRQVK3q8D znI-ng<>d5fFGnv&(8lwgRP(O#uBWs1>ZJjApL#J^228XcwCQ%=AGAaL(R{3EBgHc9 zOmoM}ta8(ny;~ByRq|=SX)Gq2{@S3~3$&Og{`domaf9+&Id30OQ3z?as^J9>xj;+s zL<2~&toEQ%w}f1l<7=?x5c0S6O@qHtJkhN4Tl-Tb_4)>V?#aJv@ln~e42wyUrq@@BF1W<6$jI3?eGy+!a4%bY0YhvAXG?GznIZND1$u!Z5c@hV*W}71a6Q*c>3d zoHy!VXIdMQo(Ijb|IjlMPyXH)Zl4)YD>5oz?H@EoV>3Qri}07G*%mg0{6Oll4nq{H zZ$dNO=r9vzD*GGv_N0OHmW113n}F`tBZm8vnyI8v7Y%ztO~o!ES{Fh&&R+1#RP(`K z<%mDqM(#cqcs?o3C1)>qR>09y`6i3l=)o4EF~aSV8!(x^B#q}VU~9i+jM`UowUihH zDVQ@*?@e`am%c~-g-rL9I6IH2qUMn|XybyNp&t|Iu3c>Ucz^_^!d_TNH}~8rCs~8SBnf-&mCuOR7*;!4WY?B(bP~!N5?!4yTLAA51N0KjdzmMPdoGYam&4U}T@0YH1DnS7j zHnc-*cjVO%Eb5ZOjS4kPOPw)le+gdR#rM%$<}1j47c#c3d68#w=YX?2a7R4wJi9dz z3$c2Rf-Bkdr?3Yl-USG;odV{qt_y8yZy4JKKw0*X%4bq4;Z`2B?Xs=ce{1D+9p&|F zF@czB+T;iOIC1OE{cWEape=z*vIg6MAiTm$=I{#b9SJDhs^gN2uvuX3fM{_SaDNzS zgZ`?!=ARS2SSgy%@7xAH=p^@cukdVAhbH_%Y1DmT@ZR#Wi0cEzwunR4>l~4i&1O5j zva6#?nI}nRp&B@HI8Fgb9L>oxq`4vPr#~5>QSncpQqO8=TS1ye|>R8MQTBA z;Y-TOYWiH5`2K~kMgR}zV(CWMsB%;$a;mzc3Z0ZC?|dx&u95Fx3oma7XWL9>)G5o7 zvMH96oR?Q2$Ei0e*1V*ZkwHLvSSyKdW`FPQ+3_{3Au*71DtMMpa(r6ddl~iY-{i5M zsrm21*xx@pB}@}1u7{jDNk1PM%i|Lgch4bE9z57Bw_CRQo_4B7&#^Q1JoBVL$aJiR zK`4ZXzpq5R(l4Xneq#AdA8YWjH-xLirgr_}^Gf`$lk6w^5v~ei5D_$Hqt1Wsz%`@DK%V902;Q%@r<`8CBf_qf=@L~Q%PG`H^W;KmqI_$5@n&ck5HbA}8 z3aHSW_Mm2v-B7vH`hVR2SItuL4xoAZ9Xk_8XkoU9y2=jCB~i3p3EkypNwVbe>|KX( z$@r@|rrj9N=}U1%e9Hy*d6N2Q^j0lnHPCSsiue7hK&U(^liM6K$cg zZ%nu&gbdC+dM0F)_%2iwT}dotl-eVd@o11xhPaN|q8^`{QKY{zQdCqk!SOQXRwPL9iEux_pxB&f9|HS1Uy<~ueA=De0X0S1G2vs26j2%c7s>N?mgO)BEtN1^o zJt@z=egG;)M=hq*Eqja%1S-ew>BzdH6+K_cIIQj{y6@9h(&S!;M_}@*-n}rb{TrR8 zurF_VA3~zp%H+g2V1mPelR-aOjf%7*;E1?P&Uiw>a_qQhP|d$>>)b`)%EKQ(4$!wPp>ZW8Hyj$AM3xF_=9Bq=_{klJn? zWp{l^p`-aVegW(!%_rVF1tDx`5zfkF8L`1qn z%#pNZW0_k8!-I8mAv>42r5&|F(~GB1Qlg8h(j-u$NHTfH??Q}0ynz%fCN)=X#8>QNj2<*B-9CuOju`i-g#sL5Nva_uI%Uh>1j2 z-;b%hBHdca;;isVqza1f=M*uBACb;ihOsA+={)a!Vof z=#re(lePxPQgKZlI$7v#QCu5pwmV(ikH@Y+N?tX+~VI;rW-#tb=tqlA}d9D>F>Z6}W z|MH`$=?C)Q0_-LFZo(954M|=ddJm|N>)7)1YJo4PX9BmJSn^mB?9Onj;9l6tPg!iH$z$o9EgFd5(*C<)iVC&4**7J>Uq`CebR?FPn_}1RzTRR7K}yV{L;10B)6!559MAc7Dx=7}IB?N-wt%A6?o-6RU~ zr9@wn!(%69v$hu!q@t_1|1!JDyjAe?g=B=hT8HT*8yqHQXODXvUZ)RDW5g~L19hVf zl}rZBH`PG4^doU3@hKwfysF11&c(vvZ4-#1`dE zu|m@02%!e!3;u*Euj4o}nqrLZ=(h0sS0^e7BUCp*`Q|s@RO-YA1YM2w0?lwrGQaPo zxTz29h!G^9B-a})E%6RsJugQB!#4dVC1OF!))Elddk9O5TB7f`;Lq1^_M^RSxiOmz zu2*9)Gwz^@FQkcZP+quO>jSVeBe`qjy`BWjiUI~4wdEU;#} zL|Ii?N%DRdOvv4xHq_GcLF&K%eG?WM@eS`PeC zMykV-0etZ=w>`1fXg8$x(+{f9OD z3zV}yzCg})9Unyupa#v7_Uo<2_)p?yZCF=!o1w2YjW$`@Rq`SqI22FMDn zP0i0slr~QF)P~xPjD1Yu#3>Z8;+erHeAGqsiQ@5Hez{p-;k?t|XU`lwZ2d3?nnK?c zR>Mh2*-iLz08o zjL0@ql_LB`X~rB2rNV@RL4{U!g~MJWWBzayOu9ZH)!$rr!*w!{l~55J701?%HJ6X3 zlf~gATlvCbo<{WbB!bz%9~cPX>J?WW*OaX>xk{b~J^_{lL&rNDI1H;P>8M;LG(PjJ z{=W54+r<3UES;I)-7KKk`ro)SNaeCq#XdkHE-C2&2T4(hh9Qs973!bl4U{L)3mZ$8 zuu3#fo@J?*fKzKqN>>@s--6zZ^HvQCjjbkvdYk`_T%v9Ib&u|B(xN zc^@v3&8$FmZ$AEN>%6Z8=dnd?5+BRPsmvc%b_n)wzNF|ckPFEFy(esXRQCIh@;VDn z_w0Lp)KbEv8mBQiPZ#&+hWA2MeUpjdtBsEq(F(15gl-L($Oy5kO#c>tcpl*Ol42FX ztKmf$3o__4I-}hp!Q2Q>Rf0Y(4qs zv56_GUr{K$oIWg=c0@oy;=1nvfA<6h{*~}Vt*q_%2!pj(2yr+* zCI3O#8jOISMA0m?moQt=)tjqdK1BsPV&*Y9KYzDhaLf3JqXicT7!VezJ|*6)SO3&G zjZ|9g-!a&R39%s8gu?H7B~i9aU{uXV%qq2RykTiD6?V%&s2wJTutB)>`px@|#bjK4 z`O<0?S{`|mH?Pc>w?YDO4}FOV?89J1v&bS#24rKaJ)Drl`0Vl5W@k(xhZ!lwL`J_P zsySD8Oar|Tr*gY5AV%*VRz9(mdb&j-n46sDWGAq{>I``~>n3lzlZHO+q>vfPc^TBk z5m|E5t~7)(9zyA`PpTUiw0=8q9~W(+^ymJ6j*j%B?^9c!=MUr{+S50YRA8W6t|;HL zZ|qCnt8j_raFpAu@^>Si5ie7^W4iH;GjIZ~LMnqd3=V5w^eEWLW;GV6!*}m9H-}3s zhe$c@S*Cd5h_8km~+a{u$XTiKSm#<8T-|yblZaP++R2?_8CY9Zu8t9ra27{viuWc$%a$xv~Z2Mh7 zPAlL3pu969PABL}0v>L-nxWBI$yz)UzL${tbz4-pUZAK`1?2U-C$^rEHd<*!GI}hJ z_MflPFNM5R3`zn0<(U2pce(W@>5#W)hqVN}Ik~PxqXjD9qS2rpN!a-rB#qV=y@O{g z`D};VrE_=^8v6k|;2Qa?PNOKD5GD{ZGeQ2a>p0AF!K8ee!8Q=q-^&a1A?!~p883mLr5%6t%bIlG> zsxvd#wxM&dPq`U@z+H=pH+7(ov?E*1hg7d}w$z?yw3eF*;ds3`Wv1A2M2A;G{9FD# zt%9qUVE6U<**0l{{sBWKVQm)CCHADD2q9+fjLYypb*WK5ddQ0^C8{WWH)=602NUCGPop0L(&5MklVtKhENiE^|5gA!v}O; zRc$$b@{U6oM$-+puaa8SX6@#)jY?Cvmel-P63Xi=hfYYFFRx#3NZh|bPN|;^T^<++ zAnm#VYWN9y5mn?|F_8|RNUXMmG|F>{D8HFz9h686O|U_g=hhNEBz-A~z9T9hD!?40 z%*hS!GpOgIcya@Kg!Ct;|N82cNT56UPI}T36?()8nx{Gs^8wcCv-G*3Lp2uFiv)=% z_EYLW>PsfP$uu@JBwqjxabPolOMqXiOkT`Vhj?5`9qLn{U0Is{$uFf|p`+pE&Zz5S z7pI?+pJzE{IMG@X=xcI`krRa2*3EEY;K^Zb)CE35H6-{?e_q7NlmWz7X#yj+a!k#F zpZ8PH?MC_?LPDr{G2}=W>zsszd~aXMzzFC`gDC!AYblJ86aYheA4vSlnW-K}-3&Sg zM(_$TIzJ53NU$}FvrA+;n3-#}V-oiS5fG@|VlU%Mci%&zk?YNNSazuW*1zQc(iisk z3}_zo8| zeeuuI33tp&LvBG|+nDS#nw^}nt1irRKF{IbGa>2zW``NR@lg|k)CqB7r(kc3?o>nm zy04`W@q_k|1{~i7_{?5jGE`YVd`UUp);ILZ=~qY98&rak(I`^>-16``o0%jEudB=h zq&L(IBbB?t`%LwF&RMQ=GDy4xOhNyvqO-&hOh+3>?Wl@<^762*$wC`%j$;qp6w}M^ zvrof~TH2JPZ$Y@mP-ngqaAsP?KL5NpR`?cJ%m1!CQ0a`*Hpe^ceA-^~I;CHg(L<)t zS8qU73I4W@K$;`pm1I^+>0};kj~~j3YgIj%I+}_~gP^#{NbxldvxRh@C)iPwDXxlv z^!Pn=ALLuV7HnKq)cMOeSLSuI-`BM02!ubI2SeF)vl?LNUR@(#xjzUui@G zuRdnKWX{vTQq_Yy7?vL-w>IU+Uc>9bAQ1ZQ21gxVl~ZzoW{S1mDD>Fvv^RTn5f;wDX0 zbIwYn?sWIWQks`qLo%a$<}uK#jgo1ou+|j(O4dfgcve9n8@#!_&h;ppqbtQ^2?pq= zsVZMS%+jFZkxhm8OVX{A0E;HDGUysyVePw=8`yJIplEbJD4)F0v^shzM7+nE9lgvw zt`&E7^p6P(&_{O|N$Tv`H$%4RLZQ$$Gk*6lIi*VjCc!lHy|V3x?ipcm$fbF?5IJyG zJD0{Z@u3)BT2t3pkQ3Gp6Cl!1Z{|Co`dR6o3gl_;5WJ05<@dtRZ4K? z7&eGFoAEVq6qwJ^>8ba3`sRk1Y(yB@B6*67a-k4Z%r&}{XX25$j;CJ}2JpNJnFq_gfC&%;W#$;$L~=X3C55Mg&yCtm9BZ9)5%eK+vJ`2yj9Y;^q=$ z#jGri!zG52HZsN2mja~}n!@qef4%qVGHjkod}ZaAjnTwwwuQ)yw^5izGmhP@_s7WD_C ziuds=Qv5SA$Kc^EstFvPubXg+V!x~ko8OK=DPM2>Lz*8EG>3_QEdLEL&L%R9MEGIZ z&!Qxk{b`>68}%YeU*PpbApBWsVU0Y6EcW~H@lz=lfib?3NR`<>{Kc-?K#V<)a4pyRw@|m%L{V=vr@?V!tH>h~H(kTRkFi%a2 zK$cr?D9Op&vCZ1wX~)P;{o#CNTI?-9-9SFcs${4tsSg)BcQNV2Us?1zKd!_(FfA?Q zli$Wk<9J1H^*fQpRrV*>$A1g7x6=T1*EkL!uGam;^sG55rB%B78l0bR@Bs8yx>ibo z0)Q?oD4<-+o&WiXNh>GP$DN_|mndEV@(!J(Ce-$uKeq4W+2xPb9^Daya9_Njb~wr~ z!Uo4Rp=2$m1{30@Et4u7tTv%@n zX}oW^m7gyZYV=inxjV|wDFN}9R?*sszX*(uBW7tdx}H)^{3tAgC(>g>EKymY?vVqy zFxg}NZn&-G8G!pOYMl2pP0_tNox<%UvZ(j(J>BK1m4icNNePg|Wnp6K?N-d>&F*6C zzu}7Qa~m`=8T+W!&OCcIfSJ`TcF&_s4nKcTpVepnw)%31s7FuE_7j9}YL5FWfh0A( zqF-426112}Gpwk&Q3lrql65^)2RXUTxxkNaF{XW?E}w%KLKg1CObFgUpTn#ELV^;* zh+)~4>TOt;F8YkJj;bM@iY&}77W%qjn&h(RW)d~g`?Sjv{yl|n4W{zfEs33qO*dO% z3V7+^c>y;S^siFmUVDwzbbC^g+QDH!YkYkCMoz;f4hZuCxn@5e-#@>zM1zTd@c3`!sq+R}zbZSPQ%h%OXGuwz z2}dg{#EISSK>W8}Z22u3uFoe;y~(YNywZbjQ%Td>S$Wd=JwUU28AI1qq%-Mpn3S27 z_4!)b+0Bk11h`z)6D|8LBPZ+Y>yIIG=jK*yalE$qR!H`B-Zyh{D9rVg1*ZreQ@kBv zW7IfYEp5Lkt3*q5FRYu`k``Ouu`;d-p9uSQhWlvqM0$)A^)(r-0mX=H)^+mQI@cCQ zR*+0f&HTbAG*#N~%BP&d^x{J+L7U-?(U8^8$<@JpnBqu`h6nF|5C{5vVO4mYJ>K{+ zjz(WY9=Z+lFXz%(p}b1-)n~U&eO7`qkY(GO%H95CC+=U9`#B>BOX{|ac&%ZvjpF;C z!rWfN^x~oykmc}n=>h6}KUjd+;*{|FgCvt^-J@oX5S&_U{nE(_zLX_BO`LlJ-Xk( z9S7RajPC)i5ZuaV3UVirpobmM0J61ZQt8Og&o3@6E-j5Nd#k56`tV)$>(O$H>yKLV z&B6GldB7Otyy05XCe;x_1vtg|xw-wbxiYPV+1Whzy(938%1hU#f~4zO0e^EGSAIB7 z%)Tjk*Qt04sL8t}Np=ZBpO*NfGy6npWST(Uha)z6da)hdEapnhaKjG0we;wp8{Cn} zfutQ+2`J4}=|>rHbz*^uFkKR8-Igg*Qm>uJQxh)fJ6Z@A3VuQz{feac%QG>^$Spr9 z)g{%zHlb<-Z|h>szm{-0(TgPn!;aDu%XEp@O~l2mdJOAt+_i<2e3O^jOswt_PoUN@ z?YQA0Q7DGWRQ4By!hb;;E_VpHtyJjNDh=CpMVEmZ3#1Teh4jP&CC_$1l+5Y`)a!@5 z)2~(lz1!1ZyHF};pskHK0pzuTrYcM+xVNd^s*>JV2>;Qv&QrkBX>l<(H8s`J#PQhZ zHfXdX{Mi81w}EV$ov0IFR&L$^-KxQOvZ^cbnB;sQE6GIptRM)KLE-KJ{@MZP^Z>1( zCLq2llLJumfPT1+2jsgYi03YsKPer`oeuHx@*eC03Na9&%sU6VGBcAuVPlOUXM;R0 zC%JTwhhFq%jvTCae{6tNAX%UQ1QhWK4Gl1lBGk0gC`! z_;F|X<&Ts46fFz8=~Vh92wjp+4V+boNR@9K$dCKoB;-40xTUd?M|(lQ7|gK2oNi|s8#mJkcUjYV1;xd0_AB&M_4V7lFDxE9RU*4( z44@7XF46~pDB$AkEHx$2>9x`{5%vd4zO%PTj1Zu_cLDqm&_7FPjpG0soHILahHo@9 zK9&9kdhiLkA$revESe5~WiqYC8_DVZKtt#mX_d$Q1F zcC#5a5qq@G_3`QqEB5>m!I)dH!TbyHXUQjv;68#pYTI6!4DptxdTuzB-?g+Ir4bp2 zT6x9Ht}tXQ)?S!a-L3;PZ!E&Oiim=P^6H?S)lw($a6S+t&W?I~xiV^4QXn;Q5QJe8 z)OQ!lzbddMw>xEBl5i4qgO2$=HYNTcave)zh^>2X*dT~1JjWz>VlZ|?7fzXWk9AWo zs3pDF2F!o_>q_|+wzg)hbQvI-i?^*=x=ME#=T=4v0S%lxlc_xMQ)4%5G#SI-r`Fs%e*;;pGjD)@)!}mEbpWE6z!L)5EmF-;pmHs8;wsi}S?!Dy9NmVd@A?&{_zGI(sK3#7^JRxYqyR-5Xx zmSWb9bd93MC|{P@mj9^{8cxhHYx@*_sbnEF)Sl(n)w&X%-$?XTvvzNEC`OkfKUhBP zi2&yZ;;11?g_?{E!Z&j5B;NW2Rx1~|%6D%3k8p_4huyEq<%h=F{F(B@tcoeDH2xNW zO`+Uy0`D2Bli7^6?E@@02^0T;f`-6z3p?1kdt!KFD(Nul4>VefsVZ4kFW^g35SUZ& zygEap7Sd)Gz5dSzxt(ukBD?Hl{MJ|tua!ZXhmY@Kqs6cL#YAfHW3+hyWuhZY4Dek* zC=?eTU(&>&-U=(FV?V6bL0M{KbQGUef6+Tg0LJhmh*Us@{>6-}zR&(=z$F06p%y2h zr7PVl;5pjr>M(bqs=uD)|JuA=4GavF)E!lxfaa^)jP-7|CutQq>f>)YzzT`c(&$ND z1~e4`rdMahB<@={SuW=_4UeqmI%y$;kiiPQ{m;_u-vghVVAeAzTF|#cw9vJ(9$ zeMj8k$gtna2{~a4X%*fK2+&lwyi^KN?`d|oNb#T>NLTP;WRg%ZW5f=aGYD)crk?!) ziBWZ>U<<`8-rsKBC&EBzCMl&OcuO4C*E_%F3`2q^q?H$e#*inm8k=`vEfRK%caty8 zG^|t1BETwk6t2*P#8Sj%MmZQQnd6eOW!NtD-H1BbI*n&Pd5rY`#pyqQWd=fZ3Qgif ziwgc?+%vDDaQ~OcDINf#Wb@dj;B|mx4n!o0jFoz8obuLzG{6q&oX`n=^O6yy1?~?-GYU~l znCuY7?L%&NTY}UnmYX`J8kcRkT=u(@`!^oaLYDpCf|rWEXL~N`n&&FzYO^F zc%2Y0pCWNu`Y?3W(KPq%vm~bG-^5rMJhd{+5m;nODy(MYH&C}YnATZIP`HSVobcP! zgh@=$kQW|=-AuKM2S@mRFp)fkIomGs^N0>5nrsC4j|nGC7T=SFSO_?mQ4A^`qK>ysHa>icWv`+d z`i?;dW_#AaLjA4y@4{tAaYe;SgRNE*L0L;oWA+on3j z^yISuY-WHv-)z@0w%IoFr@(03dc74)GFTqTW`^9NM2HpWImSm1&pqH6!7^N*2t}2k z^2ZO2WY~vMEIJVPMS)n!hu}V=mar7s`h7_W`NQTp1zjJ{$dLh-&%xB?d~mC9uqoyu z^Dk5-i+dz~4-sqR@oD3RLyrhEJE)`1hT@*hng<#4ZU@0f6_h4=SH2nc=s8Awi~E~Y z0ks2e0(CDP*SsEm@(m)z32Yv()yF^iHx}{armumU`}fdHD@m&d_19EstATxe8GEsP~ zp_t=9GUyYj<^Qt6CzW>D!T6xYom>`b?e zrsmXehdM2F_3s9$r)MauDUJX|GXHbaglFP49UHvMEff6bCL<50si(c1qKugl#+2sT z#L}D5v_R$^wbuOtc)&`AdW3#1ci@~j1>m%IAL&I_C5xA z_k2SAke91d{KtZe<=v(?lZZWxSY6c%6>p&zSK#>d1MYJ?0%ulLBkq_EbX@{~=JkFb z4Vv+H33AXxcWc0TN|1l8^A;&VgIk|;ih>wBfe6*hM4zZ3(5=O1%q%F8@sifSuhTk^ zfjN6aR}+WD+l0`bP`QPPzf&p?xiBKA%}xk204@!lt%9q54OVIX`{HA_a9~J+ynr*? z0RHGoFjmcr(!VaQ&C(L#p<)(09UF~iA5*2(-==+jznlU02q`~L>VRr-I! z0*XIBt2Nb@vhQ)DVqaqp-ntY{_osj#lu7uS9Q#VsuFHP2z4EZhldUGYnep2Fx;l4 zut&(ox{*?7-XEPgGfEV@ZVvF+(<=4JWAXTh1Qv{SkZ9{Z_hwQ-4X9OeSg5n8s8{IBxOIQu!>oVh+_JS;LvH52 z?RkCoDksXw?>DcKrX`06f#wY+w4oHvj6x;SVc80OLJlIcGTn0a%VDUJLu=4LyZ_xi z!qJ-X7f-*;RqRc$G+kbJ7I$^T|E8Qc!apu!yBt4=Cve34qWzprq&Bknc|ok$GzHmA zngTQEWw5whmP88mFmUkc1JLd)&Y2;Qb+?L76d$p#xAg+~(YzH19iYWuc%nWkTE9%A zSYyPe@jpk-Vxwj~|3d7CGDYB-P4N^+bGgek{Y&Cp;0+UsM}j=s4+2yjtV<@Lw@y4> zel6dikuk#K!?f{q&dL)LzY<i?acd; zd8`yzsrz^|>;dcjO=gYwBFoPH*xVFqO&t&t#9ligT+wWHlA7?Wj$*D&w!=O<-1VT| zP9$@_q%le8R`gh_WxPOf<$?&bicr%EqH77qb+6N)udusCn{v_0i}&z>@{-?gRH@m8 zv}JAy_Codh`GY#2YtoYe)BpA=uVYQ)Nc>O(!XB+<@y$rOox?@nGoZf1d}3*Ve*>op z)i$d1(4eT`PE@iqAn}G|+ovaiu|9B8ZNhj*pzl}s-*o!e69f1Xg0(zUW>b+(u3ujF_};zyCyGSO6PH^xe?Itp8RGT3ZSa?#x@&uX$l|$|zqJ z!OGt(155K@46DFqIP#m2?398KF=EXZiW**uRHwl8WrJl({l$L{Y4t`g-rq909Odrr zI(6w5&l(Y%$;ONuvYNq|FPnHPu(XLGvqD+CQ+Xq?-;Uh`VYTI*g1F{sPl(e#>NaH= zsvYjqbPbEySQt6~z5NlJ!zdC{=$CAr3u z)rVa(=r#$&;&g4%C>|P*BR2((8z(qH7|hzF$Lgl2Ixb=No>cr}GvMTHjuzT8#`wO_$bc zsA~ibsf|QDX_{+(e|uetorIZkzCu(|(d*+o_9+5QZoHP4p`^V0CU7@AX=N$(+W7|X z0=C3;oGO`ryQiqs|7jcHdyW2CcP?KZ>*?wVSe-reXk+_4tB`d}q0o>m54>^dt{5aZ zB*h|ebKg_wo%?))G%|0$GX7TT0xuU{&!FVdzZ;kqzVMl+5*{}HTp1)~&Jpc1;p^{SPiB{pYe_llg}@#pZq97!JI>fGoDq6(Q@8bQsNf(jklCY9(9CGWddjdO&cfl{k|rAPfsaHwOQ^ zpFI)Y~7ow_Ra zcycT{V_!@$F9r<;nxsj}&9nmPOIE_`+AW?z^7E$Vmr5`?rEV|B0CuzH_zIe6Nb&gB z{|-I7ef&AWJk)Y!YMK~mP|Y9Z3{;*zh+~A~HF5muo<#{8yJK4pa+V;Li5cDMf~D#( zg=(_!8M1LqnYlht{6()ag#Kp?g+0{($BJRsqbps(Kuj`01#cg_X*C8{pBusL6Sb_k zIMkos%|GXmv$BAXutwV#OT}?{$&~R}u=vE}%A<9>>zq=Lj46)e%1AA%v2D z5|~SD5@(w18gGs|8=s)}o0y@aWwDvL*bSI?a(N=z=*KsDE=AxoYdaM%xhR;#mJ}EB zPdD%*6*f0F*VkW4El`4i{&sR~D&7G9CVfA<_;QFTBQz!?$Lqb`>0g$5ZpGz4$XWf3 zg@si4ur@Ld$K1SU)?HH_9STC-0?l%^{eSgOV}AF>U2{Y>X~U4juzjIr_2n2@Cs11<5Z!uzk(R)TMgS$J(}XeQxZ7D8iQ#7IwJs@$^~`J z+YVvy9hI4{K~WhGA0IFvME*VllAa+^u$r|0IzmNaTI{uK@Nk3pj#Ok4u9JMg0&^n? z3ONV@j~mzYXZ?2zvj+05Om}cJtsHK7SCq2A##=r}oLPzoRMiy;qHkLhyUm0KcGD9( zPQL%>pV+MT#U(#fpiV#EERMh9f^n8RL`1Xx1?9oz%;~oACUG<*sI)*NT%TkAmxxmTU90DG`6Uo1wF89?8x<>~P+ zF%i+@AIGQ0m<3Rx2fV$x`FYX>A`coM!7MK?pP8Ad{1#5LLRUjy|K8+NN}Va-$+ZCI zj&Xpx2dFE9}^A4NhtH^4IL4zx;}KYwfqFG znC0l3M>FAsL?HI*Jh7c+b|_L0`$RotoxSKcbfSvM;h{%4&2DmpfRpS7F(foG0BU)f zW#b;Z84HH&jsoamsIL{;4d*7bqE+g=-QjG3nLdhIN(x&F_C=cJbwCz=#5@`pRA!Ul z+GcX31nSLOWF1!LSQ@ZT0a_4TD}7B(UH}X5zS!a6<@GrG+3tH?sn>MetXUOP1K>R=DJeMGK|oGF z0#q-_G_8fdnu6{9G;wcq(aOk)MMaTPdx!!YLQ%rsq_upM{Q!wa)i08VhhOqIz97q= zr0R_GC~@t$tMcO@21`I*p=!*p<)OQfH%YwV-}2CDVvJ$Hdo(@6m6B}nZIR5egPhMuREKbcxp5-E6M%oO(9qQ< zETq%Hh>|+_PVf4}gwvUvQhrN zOZH9Kkv`iWWRqxlczE2m#{jGcyeIf~)8I1(hn$=opxyWs*iIku|B-#S{N(bw@*a0% zJH3aE8&;?-Q)vh{+Q{cU9CIkXj-OczUtUt5CsyFwKFiclJZY#8&Qk=1p@X}p4FdTo zwoJ)SC;>!(18booKSCc9O#U^roSZ&Rc|IgdbTRSX`X2U0m;Nc!$u*QVszYD2^(jT5 zmu&@ODw4N-x7o5bDrNXmLR{vcs-N4AKo<@YE;^>BpFKe})5IC}-pG7QQw!4li|!t- z>&&UmXAwp^qp>uOP0(IL)xOyOnv3@le8v4-P@)|mXw#^wsNfl}0~8woP#$3M`5q$v zYrqJ*$$4`iIvV-tU}k0}s{>sMEG$s)h+*p}#?@|h+Xpy`tFoRR39KLOzMc~(pmjD7 zOGrftuG@WeQ9e49u%W7I{;?E3`s?6LA|2gvsr+UJ(m?eR zixA9L4R^j$`71T#XrQl8;ze+I9!Jb~fW&Us1{g`;lbd}tG;no`3cnP5Ys5D{UhB+l zU(w&SON!$F4`#dBHChWz0R~o(r~cm-P?BmV6IdeN^y=FhPU5p$#3b=MAEpCXA}UJJ zyXkn%a&2eIgR5Nv78aI^opHhGh9N9aslEyD$NEuY8X+QL?MI(f^zG3!>4sKyJsAE% zN{sPFlpz6ub?fOVm>3L5d_wXLu{uL*2)BceSW1#rrrm;ogQvzia)U7=bs4r+4J3Qi zH=PD&Q9^n4B9R%9xfelvZzU1n-A3ndDCyw&(?pqWM<`4c!`xCQ?JE#=}p@ zv^$yv!FF+C$Y{m*@yHS=H{5QLn34llm)=v8LTfh)?IeHnonsKahp=@cBJyPwFkY<$NO7QeCAtrlH5J=IqS!lmy-h>w&TvHM}P+_ZEL#+ zgh=x=VvcuGpvnZAE0;?&@+r^Qle;ceP#?wVh9%<9j$c+06W>8l;`*$T-kb1DhwL@i#0GZKbMx8?3X-% zkbicwT>s5Q^sF4+$vYGm64yMqPfSDWC?&CLIv2!$#A09QmL=b@DtK5T+rNxJarWL= z@(?F3zx{<6$pzTD;^MF@6bp6-YLlD^`4r6`9o{pG44M(!z9%G*3R}1=b~@0+gzh(% z9x4srb2TP$=nI_i#PCB&@CxBTma?q~caWm&uoP=aa#wfrJ;3Wa<3gfhKzB)uHs*HL zkJ%8yxJM1d%eNG(k8Oj3MG+3FhB&@2Q(((@qSHYoU^fQw6m(|(u3mS1b%+Kb7DNb! zMR)A&?QJg0iQji|DQrfoz_t+Qp8qRE)(_gSpv?$4$iK_q|IzBa`xJ>v#7(~&ma6YE zEO^pJMcEsUrv5>yzP`R3w9H$KI(2K!WC33>7q7nT%ar8RvaM`+jiHn) zV(<(tw*}lkpL3oC{qKNnt)=yq-bhmu{3)7PEqetq!5L=2k*{_oh0j-4RyypArGpQP zBDDhzID31IBYmkqCu^eMrU0J}%Kz4iBO@aK^Yw@yaE1>|vlrM70xE%ure=7RQ(**| zfAibij1z0t#*ks_ET0PEyuE1;+aWj;qwkSRuYJ@Uk=Y{83_Y2 zGr+PDBQ!i}&w)gxS=ny`2jI9Cko)+RIJ{2Rrwe5|0Z9y;8J(h<6uKBoppXP8A!f?E zR#-R+i`vb>5T0H2-+sS@IqRt$;s znaU62TYSVDQkivXLH~i<6_`F~sbL(CI)fnhDJA8Z!K=I}sFcBN4c65i_HXcF;MT3J zt@kyw4Eoy{xse4uev4g!Ys_W;lY1GCg$Oj4Q-(jKb6d{U!Zf}2R9VuyaYrHpiIHS4N`zh&v9GtZbNyoIbF-9Z7!(qlpY>1it1;(yyfxCYdk07 zr%0Z~qe)&GO(11Z0(!ePi7^Sa*^^s?DnqSo1QQ9%nKM27$0XcIis)~AW6y%&bDP7$ zH||lHvAODKlM#b`;{{XHWyv4dQEG;C$A{8@3Xmly^8DX3`kthOuX13w>5>@Up{TA5 zC*nu`_i=pfUa{#|OntZbuIBXsqVo}q8$9mtb*A$|GROJW@Q?2f-;NqVTH6HHX?=Yx5s%!{+s1(~U}CDHCm&u4hNBW3?>2u$( zU}*aH3gq!BL;rdP81(>_{n&@23_elltPkhZEox}yv;5N1k~2~!CO>#k#AWNv@<+vi zi`~hE#O`D9s^}r$ZssbACTn!#p6S9@Yzz$PT$UgFdA!fJz^qV3qyIO6CjDy1dXk4ZgW*xBL5%cMD$$#?R+;JT4lIYeAeNy~K^0K0%Qhn4LQg2(iXj6_@(3ScdR zCKcUAjZFfGt$Cbx0CotP&d)4+z{hs41+!7?2JXVGiTklj4d5a$P5=Da>ag-^Q%2>td8&bj zTZNUa?K6QlrK0nupAG&5>e+s>T-_#dIa+b;YKAN;0ho8twyGVT;`U3X!_P*0Jzrm6 zYwHrZ$D^a8s`fv+0J8@0Tg;STeq{zQGi$Gd-AYj-u3Q0L4ysE-Q?ui=2W0~hgKvCy z98Jj-6E;`l?c2bLuZo%QPS3owC(od#w++hmK1^Db`n6_J=ZBzv*1ZPa9JoK3m@kT% zc>Efe0C)P+umbzi0t*-s`Vaw!^M;gA4L1+ZFIkvtweZK46Ms5NFoi}a?8B{FK{gdZ zc|If0W}bu&e6i!+RQ_E{Tbur2wcqVIz!m!P^8@2ztqkAVb0CWz638W(5(bqXS^d{6 z;rYF5iA<1JG$?Un0V!tEXVO!U6=*rGM`FMGvfVlx;upb;C0~J>Em15~msJ|n%~LX9 z#_3zhyjp+h8RqO@(1FY+{p2LM4hzZXP0!1p8oTbHakAQ@*$7p8RP9C@YBY&V3$mhT z9IjJ|jneNtSZb=8=OvIMXK2OuRImzpmGfo~%}ai9|6?|;(B-S-Ze<2f9(W=QiutB5 zu(PCF5b^6j1-Aj5VXWcLf&UuZU*HIe$1i*1z;+7wH((>>hV4F}A1Ey?Eqc?9;iA@z z+}iy#s->aP{_tn138YScj+WdhenuGf`kk$ZU>E|lXm>XXTbqiMq2F2mb23)O=ka?H zC@wvM%1n7#nc$yH(uHvqko0|K{`H;#J|d%E8in^K)#2 z*#bp5+_>~jIC=={JM>0YdlFLAdgba|vaZ>Lxl9@4mne9ac}?k_SfButTkZ_9D=?v0 zVbp23-3zvVFAW4hVwJr_3ce5c0riyU6}oa&co;UBC7^EfNd$l~WwhFl2M8^*^2yGB z*u!|%Mv`2yE&~r@$@uV`-(d-W$akI{u#;{Xji}HY8Sr!+kb1vkhqVtXRe)Ciu}bC{tK`Owj-)92sS0-0ecvXP`UstA~CNW;(Q<_v|jZ9Ske)wgtfro zKU+gV!A6$rgsST_h)cC}d^|kkxuRrZ^SHG_q#V{WMc~9xsjybXq>Mo_kyHFe&u^SJ z&+GrLuNGut{rc{{fIBK9*m#j_^PICecjx|absG+9)i>6B+*7Zc1Oqh_M;DbHo`qSt ze?zlwSA_T>%82cq=>BcD{lcN#;S$9~KDhoT>Gfg~5c18@xDCfmyDXw;sTMyriiIGG z!?2X_$$Pdn#K>OXqF=Bnx$o(YzW3HNCUG`$&WQjg<+ej#gSoT}Ijsuaew|^FWcq*2x8D822xxX#X$2VpSy+RX zEIO?P7SefM4Y{tSrpNy0R2$7uKWX9n)86hgjWW&sr+i7Y5q!quT7h4C8=wjY_^EdT zd>zwK8B1U{NV>c8IJ+zxJiC%{dE__Q`0A_t~qpB^8;mW{MB zQ!`NJv@Z9d{3hE-L!$xw5kMXDgy2QYP1lEqh=3aetd_sW-)@avU0p%h4ov2Dl)dvy zRy8#20J}l3uLHro3#sdDSlJ)D)*Q3&bsU&@O3eY#Z*aVv{tqZT)X>Lxfi(|O)?OR) zT@J9YJ(il9nszVABpr|CtSF4Hl@w$m!SqwHwG>Q8nCpZ9!eh`x$jSNnDBJGa?hr88 zu~=;q@~7y}0SG~3BGC(mzKWu#q(TH58)-t`=OB0(g3t8ZXpOY0%mnWPGWOReiQmaw zet)dO;8A13)!KdkXTtm~W(_RDhF??opDYyrM(+@AKTOeHv5ib4dkZqyKzRuVT`TJZ z_pp1I0qd@ytpOS*jUT(lRxHV@#o#REO>Fd;Kp^`R>2=hNpIddM^m6mvmX1tESe%j`ts#VFVwwX7f*fR9V6w%#myiAh?ltq zWmqs~4t7=Tw>z2f8|T0iT%D{vfsKl8wXwLX>qRgeikk_-hU3#8M{sLarlzXFQ{YhW zxOsU&%E)V}3W_pd`njs41eD&vtPuDy0Izg*KC5V2Z3V>yFn0x}a6vu>2B3G;JK<3Y zraA+jT3cH|`OZ|K{F~3!0eEDT^;>ykqo(>FR_$uYH48Jdowap3u!4a&VqnznKg?6% zy7D_Eua{lpbEbylNCWPjlhuLen3(~4o)INKbU=I72Ghjy@+b$IdU|CYCWf5F7{o@8 z=c!=lR*W?J4CDs2LL=|(PbhfIi_Ol39v?f}=bmd0y!3c${>FnTpFUalG=mK5c`;}k z`5raU(9mSSQoUA=1RK4{Tv1WFh3M~8I(2=Nbswo@92Tpg;G+N@xv0>q!) zzfbhfvNs?H+Xb*uvlCcSRj>gFkqHC5N^9^ecI3iaEd%#CfDmi~;V7%*4m{jzRuvur z#?}qFqjvnxlXAD{aI~dFs&OOz-Y>4MJ_c=m8XU4}TZhxTxkX^;;YM2Kxb!hV%m)e* zxr%3Bh_&HwxTwvbd1|Zs8D^Z=Bn72idHR~74>}irK&kZq7;zF*N+Q`}Q0JA#!9K5p zk6CTDX0R`cl|mCMSU0m^YZnZatxv6ZK>!`@|C`Rzfc=k2uYIKnq;`3@nWT5bYp}N{ zKkB8EXO3q|^8T!m4N?`a(rYvh;*d(r!R2leW6k-3YI^o>EwZ4tP4>QA7o?!28ld6= z?2!;`M!|Hk*u2k7(z9&lVFi2ArLmn_G&6iOE+5Q78XDm z?FsB7O>P5#>jDGmx?p-8yw%$QQg&l8dHI-E6Lbn`?BK}4cqZQkn|Y%)d>+Q{MQ|Lb z(%_p1@U9>UEBkN-s%js$+dX12gp+&E)5E2=KuK`=|M+^#uqv1K50vii5?F*F-6h=u z5+dE5(kR{C-Hig$2+~M*he&rLN=e6=wcr1T^W~i9^4cHNy_U=~bI(1$8qjHLZo%Dm z>VvKfbX47;v~qDP;0Oyku^d*DwRTT1BWFkdJ?n{b@TkGF4VShzHZ*KBOzfw!VP$ig z$%4auFSgi<=Y&8kz!5?FZM%sr_Hdd+uXxH)YuXb2dCTThg7rIo~oR*TA^YM>6i+RoxeMgALD5! zfU$FE?g3fxoWb8pbCic zm|1FiVhVZ1FPDm{(a)n6Tg*6ww79*Wh$5QKy%RE2<`3gWM?(`h;d~|+|7NJs5ULqyqHh~R|Ef(#W>mhB0xXM7!iIk8r9nz z6chyJ*!jGJ;l-*wxP0>1 zQCaWx)$Cgi9)!*_oSApJ{$XR^7n5(RS`&~W+c=J3k-?Qlmhu5RmQneKX^(@j1X(fS z5qBuNZ5yMQ!woA$Zt{)MaEEotK31yqo*N#Y7ia?~q(5+8t_UfbGTDY=?Nsz>eRGBr z%QR+b4#%|c+7q?H!YWav4lfQ|VkDp!ZA8kSX3&)fbr}lh=R~OHHh=&A4|=;i6mXyAMKtyAMe*Nz9(6RIJBiNFmEMvq_2Xj#;lzaDoc{X@$aqB;V z?VozTOmW8Wn%Gu$R5oU$3@|k+;iKo@?zOsl{h$hDoTi;Lf3}6 zk<={ZMazWFOQLn$?j}o-$yS5`SUaRIoTEq>$VUpVy5WQnLO-Xl#I$LxEQwMR%OW#S z>mjZSEnEfN3kNtJqt~&-7H@97le625bafBD!eDilswt1jn(`Y><7+j$lfFZNOwE|H4c5I!cU@muaZEj4J(g3)D*>~ z;Fu=e4Z~c;9>m0oSk8c7mGD!Wc1WI@lx*Vb-Z}0R#!@EF?UA~j~sVuPjleEs~i z4*Y%K#pQfDJM~}j`7~RdpT~PPX2jd+xBuy{uKV@1vbDwkrF3vq{vpm~04nGh3I%oN zwu4Ao5-CHygd)i65{Ox_U+AxcZU@|)7A1K$%ncZZ3-p6IR+Qv11zsXMQiY&%_#R8X zAlXqLQi8JX_R(+oh5Wy}$len^f3t!yEj{|4h9G%mz@fNlbSdaT@K{1Z43m#D?XnI+ ziJxTW52`odTP44EDLxq^Y8vxD4`WjXKEiw$Q|6=8Kl?R|>ddNF$C@eL{Ok-@VhsS@ z+f8J5@RN4#O9K~NPbfM$Ir(Iphe!Wixz^S5fG-3&Jlj=vZ`JU>$_ri|WV&T8WwhVA z*Su-#wffm;m2)%o^+o);9|sk;y2AV$4h4n9zJ)TfGP^Q7GooZREhR3y8*OTg10AXB z{wYGWm_nK$Ox}$}aqkwNx!Gnn{8J>3!xEdQ5BbibjG2?fJ&SXp0wLpjZ#Fm;hW(t( z?NNVYpe{!$3KEMmVArYk7(4&YvrrWo;&_2FJfQQsc_&4QVC%TXhwPK+M4htMKoDOC zvH6l{11#lHSl5z7-WbsIUXOVc>~_;Sv7Gn)d%mA3q$PH^-N3B)PX#U;6EA?JgNoWK zv!)^H@nM_-p3;;TE2o>nY>1bcZWJ~fP8UwRHp` zg+9a`7Eg*QP>zk$Y#?GN`88ke^BE*w>Bb6o@v2EB_TgE-{XYKWZJVE0&@nW9l#;Zy zPDks?M^vp2pk~HRK>kt!x}>#T?f8fxz$wlDt6Jp&7+c{lKc4BixxQ@oVmPvenAVGf zyG#lIW1`-jgoG1v-fHX!-v>`A8qN!3R+GFW;XN%y>f??TZSZ%LMAG~sWLQg8fQN%}I0U!mxu0!q*w#zH3m%y&Gy#b&{Y8v*=2QI3wm6ZgE0P%k~0IhIY z#lm-MM@J}cAm;Dq&JfQMYUXhU(Pe(<&Daky9u<-SxoXXhuo`6~AG1)d&~V|%aQJ9x zLkuB*=JFEt(OXzvC3>;9GZTwh1>HnMPR86H;7dKBxuG=2;;OE61qyfy-0;kSn|Xw7 z-%!Y;QdhV#Ywz`Ss9NpG40UBd9uDv@5Y{7(jUPhho#Ht{FQgLb9`5PRHvefohSDWg6BMF1L$vYlH8tY^zYaB>$;DGX z0)#dv<1V-PAk2@&#XKKQQPNC2WUGb|Z9~O}#jGWoKMAJxsQl#_Dj`g_xtYAVh`xa- zxU!Is^F3!92^xeNeJWGr>)1z~9_3+t7C)?Sblcw$6F9pLb%n%*XZ^dR!d3<_63bZ0 zIV#zGt_pJ-LYp!3O(c!q?TZdF23++0`c$RviaESIKinGje&=`J&>H^%Kc$7#lIzES zX69yo4#NS|9pSs~CTM(Yd<<%-|5L-x-1?LAn5Ve(e;_Jb1V%9(v@~vqU~y@_dp9#T7qacdOZ`8=5Sfpx&6G5t zYkTPd*w~E)WmLbW(%69zK-)P0hW~T*_Pz(!Szvy81Ot4Q7|qto$mkDj|XPoqDVgcH+ELm)wWNLSGvy183mBC_^^+D z^NB?oXgPHHCNWEZD|6yROXAo+;v%X|K;A#2W4lx|8{5{_YMLU3%uQu z{Cv;7OaR*${qHb5&1K|wy9?IBP6OsxzSy((`hDI!>;Teghz=_zcoX&>L%&b~$$$`7 zQ3LOF1%MVUH8t>+aR8n<)&Rw03b~P>4gg>(e&@+It{Yu}g0IUzf0mXj|MF!QU^abc z|D*S@KIr`L@l;n&7J8?u46q2G2nb^PU~8Kt<}cdxUK&Wsme$s)<-pm0)_~!9I`pu* z6OIH{2Wy>XoOKrINn@E=`>jih0V#!A)|V>ME`L}Q-Tm~96~jB&H{UZ@s%8V=f9&|Q ze!Vz6SM;$YvktLFF(XaJQGa1ivZ8e$eq3|b6FPt``{wuo+m<*mA9kxqfFTkma!aXf zlnl6IWsMOxMJoE`q{iC=_lo)Z7>qHPOOWq~`mn3A5YPMgJvI!j1fRufh(4=rjcpSDolcV$uSq7CZhaum`<#eNaWfRan zJ3!nJ%oUub4E&=V9lii*W7ez$p=wvYIW*r_FSJ4yYqYnv9&`qFgQiBiXy*Bif*ukm z-aZK1vCwQ0HAhwDOSX+{;_b42-oRvxb)*x;*!&{)Ba|}cj`@rO(b7W8!6pHu+7x#o z6d+t7+E*FDl1@*ixgDpp|Ek1v-L1kGZP98mfO$P2F|@x`EQamNQ83?xS-`dEGil9B z`|XOU!9=5NQ7l%1f9F!B$vo8QEOl?g1xHxyq#&t%mAark92jpT)U>p&f#m8e@&7cR z2pSAviLIh*6Yvm-`vb+u_GFG0U`{Im)g$J(Pzy*DN$IOUtKVOF2(iXIh_dB}WUBLI5WpP%lNAP;C5UE1G@4InD9H9Sk>gfxXQx@wx)gxiENj z&JVe~Vm^$xmkjYT-rj9O<~*RfRu3{L=QIOyUc>}^GJr1$iOaO9gijB&(^Y*AFo#LO z?O-ie$bu~XWVJF|=UF;UqOS^fkZzJ8cs@iaPR){k2J@;K0s|O+d?om#wEBdy;41|S zx14mC|64nNYtU^-V`lkK6Dw@Z4*e_^XNb(D=3570`iAU=q|_C*RLv^vM<;y>Qodhx zN=0cYx{!_SwhIZxAR*nX=Es-KI4kLPaaet?eIu^BySiBtZ}{{HhInjp31L&l$iz6Z zD*E_&fyiBM%DZ;z;BsTfS5oI0?#c4wV7+>LE=c~ihn^Rb0GJxq&~Yx*%#Du8I>cT5RB50 zWyKKK&-(+tpz(X3*Wc*>B}$CU*m*sn?G|XWvO*l)IM52jUvjKW3%wu!zS-B7+$vZk zh$WsFu%8H?zw!niVJl&fO>jrWbJ!IrDM7~4L>sudCw2(tUS0?wc>TG(c;1NyDi|O< z`Ct!tWRTVJ!xkh1m6y-dDEueTc8dm|MAAcc?Rgz7(wL4_ePKs_iX8_C@VtRS+X z01$`(+!v?`6g?uvtfvaPWWW2~fBYGSj74#?WLL9!^TYSPRlB32y44oUNlI+bE0CxfeCf@<|LIPC1G%i5T z0VJK$K*DMMpK#Q^1qe9OS@o`fRv>B!z@3-IKeD0GSKwXbg7c8Niin1xp&_VWUGUf& z%g_NIVXm>awbcda1o$M-h(7=M`{V#z`~rnlRVUCt{P4k`#bp;@{9t|XJFfZU+<|JB zEC3p?s;J_puU`|}ie4MK|I`34ZY2zp{1ngV1X(_EYHsdx9=PR&wk8W_j(n>B=xeVD z03u`J0cdU5>F4`NeM>1vz#073(o6wXu3OO74fvl4A~ZUP2D1RW5R+{%nN^BJ*kJ}X zbpW)d5eENTgqes1O$UE7g^@Ea=&7MT1Hk(1^29;WaWF(TuH#v}N4kK5>Wm4_N|&lP zq+p=^M)>C9Z+?2Okx9SqyQhG{hcul7hWtp0&YxPR#smqOKVlj^BUW#!;o0zShFFr` zzGDu_9%#aiUZ;^7CcV+k8GHBT4AIQ;MQu7{o4pMMPxoZ-ACK~!@XCJmlDE*BK1Zyex7@8Jc!+z4kytAT1Kbcqb?#PHFZ4qwbqvvfOrDG zzc&z)0!^BiB_II-;|G+XKY?n7msP)!k1f<3G1ESjrzlK3+qw-h7wYkdr>}ziKxcxspiH^uZEk#8W(;%i3^iss1KsIAmk+^~x>hKb zA&8lXMcy#&d6;u*WSVY2f)vk>D&d^{T! zgf*JYoZIGDJ^Mnt#a*L6GmJm0D+|&upL7TT{g=$=uV3Go5CG~8%0j(({gE-)78+(X zH|O*mLnY=nTk=+*u%*QlcnrWA&wl-h4eQ*-s|PIZ8{~J_3M6{sZ@gEKHE-{;G7Fxfh2_xoF%a|!fhoAqT)>!J zqbuzHpfe`(BrstS$Yz>JL8Z!R{hZ-vZ-%pO5Flz^{g%r{h(zkUgOkFBAVb0C8rQQ* ziS`elTcBkDp+N6}vcY*dGRwA@b1QB?u{6`Zg~QkjF5 z#-LC#Wg+>8h#`CxVP|k>O>tA$Pnl0GKSq+DGhjHWSw*0_E|icVVpvn-&jIX2LKMqN ziJ#^Z{Iw2voBq+id)wZR(nBs1z@bW}Ah4o)?z~kI(%vI^1%JFFb#~o|vy>3eDfFdZ z`&1U$@j=b%I69O?rRRAhy+9P>BW$C~BQ~~=?8knamEHpt^XCmc1- z7xIN!oZAV@(IKq#^XtQ;BMo1|G2aK5ng*PcST~xGylV^m{XmFS6b|lCpZsU!P!kV| z+gOeuG-w70FO5NCW639SF~%*k6T>~hINB$t`UOxXNOIq>wn4=LJT5>2iNN{*IhM3# z8er0Z9;VQ{%AKEHCx(P9?P*;0Pg6q|mUX@)i2c6aThM~bfcwtw?unE{*G=ipl3Mpl zlY)#1-$|0Q@X|1hz;wc~Yh!d@`&<&?cfWDp@BXi>+6)7ok|i2^jxZ|f>5VbbZw(~j zrCQlxhAh90(obZKp-eCsOP}ft;Ze6B49%(h#);v53K_tlY4~h?Rmj=~g0%_|%9*0J z9>`zTt91yK-a1#J2;pc#C9MbcNMrn(fhZ-Aeuhu!Zi8tVH~ zTZaw~5;swX5 zun*|UXc>{-T?ucf4~QUW(&0`jMW*d7NYS|iB=+xd16ZjP8-^K^I2-g;03=E0w(@5ew{r4~b!2&iD-x&ZdYyiaSMV3an&E(f)+0gVcX zUjq(>$DcsAAMfzE@_Z}yYz0IGKy$m8`)N%O@aa^~H-li`1we@S4lp-(08YK^CxD7T zR^Icb8#n<&*Vshjjz4j>w{M<6H-_+_CnZeWB7R0MMr2!g{^ohWD^fR-qz#0C<&3{U z>C<2%wD^dTfI>)wEK-JH7we-z6z4qKxBf?)!Z^^LCGz{2o+KqIq>;P98}Wiin~DCH zJvF~>X(5-B6?3FziFvg}Qa!j4=esRr0g-vTnLnAaki3cQCWh@@4PuCYwd|=<&mID# zIAWMCbO`P&QRjr=*ET~`fVvu#XLOm70sR9ooB<(3iE=Iz4e)vf2AcxsCWup81!5sE zh(Z9iy}R?ml_>JV)d5=H>SQzT-pTV7W zs_VuOZcw8sJ$!dd^MRAdT!H^uFHm7VDjMiBZqohk@!J*&@rxj~eq>6~_vHCH^t)&g z*o%v7G8OQXoYe}$o3V8Rs^vK>qC)kJxi@@xQYs4iu+Ex9$A$!_5y()(_Olt)eMX-E zF4$S?K#=7cJ>7o`=d$(Y`RRFwTyIzG=NHzz6v-t+84*1cg%fVVX;7BIU!*gv|cKZ!0_jv_zAfSsT=s${o0l zR+v3fk5$Wgu_h>yKLe(Jy9~U@%s3+~-4<7z-rTxJSeWTj+n$(2_xo5 zvVSK&S!~m7EB}Yz4NHu?K&-G6EpkdP)CVk9Vz=o3ex|hp^H(ZZqRM!0Pzi$aZJndjPS3S`RJ)>$bGq8CA97$e7<`wj zJ0BxEg|Whxj8`*m>|uW!6B3bx>~Yw={DDb;6KUBKRS=NW`tL(CM*-CzoCneXGFR4o zPmeN+Y?ro-=gP^;n;iVF!EZD0bxlf~99<7{o6#6!&nCz#Q_z6($m7X0i`Mc0}l$Iy)X=~aoUlQQ`CbBf+I14W~ZIe>mamhXSFYdfRJ zHTTu8JK^xzK&8}H>6Q)FH15LAEfGXiV zmCn%vHyWZ22*1&>B+uvE-J4Z?>O<(G2=imk1}LZjrY|v1jPLTOo4ywPmEVq#V}f$L zynNi;{XpuqK`9$U-A!$TKk3(L8pAXO(S1~#FU`EK^#a_i%|5QuSt4>%T{?;kdE@J* z3-vaCvF{c@>Jht3U?9Zj@PdDfBE3i{`b~)3~ zmdh)STnF5w;P~-Pqb*vcfeE!*YQLV$1U#-Aq=&(GjLD?=19RwPUEg7~beeLx$_ocK zU2&Fja{~oM=Xjwh&^73?Z6u7k#6T#pf6d z$gA%vNMKpDTqM4p8F4a1!4XU1(G$Z&Y|{^7z;p~!8$f;OvJJ4&P2&;sp}kj8pXU}^ z=swSx%AUDxS>Zv-(TcC&qY<>Rtkuaz7=KyK?_wk!*>pc#|zmK5{afpWnFI6!i9^B_!N*`Gea>vGr8T63iHVd9H z1#8v(&-x7<+yQ?Z{OOUAC>}OJE7*IJ8;4XxT~)Q<(Z+`=D8V(10V$bL-Q(lCLY@RS zO=Tjlhk(SA!HMVJ;3f~zOKAKo4+RwaU~t~K=N;b^YrK*#N9Mp`{%#DH!GdWM{t(Tk zT;6A+LyF-u&=6kp^!&TSH%IfQ=O6zX5ve}aAn`I<*2o}^c)uKayzYDAy^3D*c`MTC!UGWBYN5cA zeqy(dfh>fQSPwY63D`SQq7b)L9jH*v-;#>&kda0Fa`oV(GKxT^tgdB1&dToMO(A(B z(M5vt9yQdM%k{YczZ^u^zWd+fxZCmGgF)|ye_r2cBV7TV+za^}#GYj4VaK1I9f=7d zFA+zRcNq&S308PtG7-0RMisIlP~0!nzOVDPDv}B0ZO#p>kJ*Y(`KK4qR3-dS^URBqskDY#xH%e5LS{cr7 z=U~H-2*qn$_K$JbVo8y|Pi7{07SQ9gH`akGck^vM9OTD#4?Oeeeu_OO1CJwkycpPL z7VCe#-=m6dHf|SOVhP62Z1LzwkH6-$OyTSO3s{ETUN`H{o3(uS`V*D}VF~x;3(*9DoR1i)6;!8_{aV3|TMW~2q z$W;}`qYaDsAJUy&j#`uecop=}SHWG@QMs@yKv;#z%flzj@XHzDyM;iN&{I^mAcRV1 z0!dpMe!7fA(Z(oeBi`4(3-L>d5)%TWs%$j5xw&0jZd|&yG(t}3ABas^r^q>8nFMj2 z?GpqCzUh(b?Z~wtrKJ08oK>W?Si>4C11n%jU^{kA=w-+i619(cv9dL6BnQ!7K85<- zhdRlbe&caqZk8Kav*V8QIG@?5N9*uO7f7v1I35@C=B;XOS`} zv%0E1y{x8)qZXy^cG8kV#(o#kwUE9WV65NsR$S==5mBsQR8~OoFk`&zE(9Kage6pW zg+S(w{g#(kn)oWoxld;NgeEh#(7KG|H{6_HoxU%D>~&;Gb-bk*ki4P+QvX{>U@7dx z{(h!y-gBsbGw96U_$uwkQ|+Y3Tq(-ti}|U(qA}w0%rN4*ODSG&c|O)GC!ZJdUr1f` zwwh@1{WZ6%aZ&f;4Fe!7UI1F@vL?toyH*fh%A1D|NlLS{B0f$nE-tREVX4obGXBE(hbzf5ds{|`&%`ur9RWwG z{V!NF)&osKg1MP&PlX_^C4{SG;!Xf044pw%9+>iFVXz-Xo;>wc4j!c!R{x zO_^SnJ4p`?G}Xn$y)D*Fi0zGhI001l4@cXB*>7;kg#y?wgsqDC(H9v=?)7u1=Lf?$ zNupZ_kGcH$7(I z$(-+m3z}bCFdGed?vm_^e4wVeybNOEEV;Pc#+?f;`^Y=_+#|LO;MLDfK`TY9Mq=&< zyVob8CLYgrVrTnQHjA6-F`C&Q$A8maQalK{-zM8p`M$w^^4?CYbv*8@_nn>4lK$*q ze1eFNwA%a>YCs%6Q{$lh?6Y0Y*J;kP?ly7K_M>SNQGLQhOLVQVR7#pGj59(`K96&S>2E2o!me%KeP#NM{qBco%}Xap5qD@B4W}b&e?V)3&^U>)XAXg+X%n^p zVsV`BNVV<^D}`smjq%h-c)>DF6%nm^Xao~BDR#rs2H_kj|5o~;J@b6uvJSdVIUYAY z6^OK`D*TYvqTPif*L}prj+KUkwkdvu6sC;8P*7}4Vx==*VUR`y%^Vt&6T#+=%Xl)?>TT%G#^MRaA-@_gLFvoHBiO_YMaM+T3P<`2%k4q~XT zgb4Z$_IgiHiADVN>%H6W1cNK`d|djGQ13bSgaJcL9@}B*_K5yk)OEHL%TBPO+QGQW zh|3GSKt8{xGBBLB0+sFZ72{gs=#b&f0d$POiGuV@q|X=a+st9C1eI?XRT z`6(Cgm6ev{cJImjE5$lD1YfdBN4TUgtcAh5eg17l$>8=YW+;;X-xLDYJ0d)$%Phm& z)J`Tuoi4NpO!ojx7EbR%cY8>ifE0ypH=UL)l_;{~!gq7IE4p;}R?~@NN^UgbO^0?G+v9u&t%r9a7wEa$EW8-`L54RJBCkny}@`Zm`onSr0 z?Js}N92Q=4bW#46=dY}|%`APuuqd8~KqeK(%C~%}6lW!#_&addIpC!O><`%I-3Ht` zPl$5r$w%$Q0-5jQRwbN175TThqQxW^Z2aR1XbJWc$Na2BN1L z^<-LHTpR$~x`m0n*tm*eQU(Ph#yMU@ke$zJ8D;)g<9y$PQvUhD_H&ml&xgx^*G=ti zi#sNt96W874q&}b!KT&n@MG0y3H+GYDfN<(bl~O!TfYp16faSPBAIyO9 zw^QXU`BQZn){vcAYk=dg{$fyOz|_-&7rZ)@eN!VxxWznjoz4f!b^3Jpfni||yb|Pr zuO)?}i%my+nXVxzvKwom+&Bcq0P=S>G57G5wt76ZBH2_pc~3%=ZedR?(lpviMErgO zGctZQ&MTVg^zO1SzCJz+mkoO>D=W@|o(3@xeiu{;A!TGdVRxLKZ-FzIKOomSg@XwNaTtN`jx31hp> zJ~NpY=l+#}9i{IZGeUuoPrvf8Tv>lxS=!C-zoaOde&H~kMvHyOK;sT?w>aa+JtzB5 zdgDB2`BSPWH{FTVzl8PJ2%Nrv^(Pu()Ido_I$d9E!K5NRqCWmqt{*0np>%N{S+{5h zBhQz8YO^*E|5T%XhkH_ppyH?;;2G;n8$@N+H&I6|R3cl^vKF`&97LkV3b|KcbP1Ll z(QYUG($2wEg)>q=jh`x6eL4ZlU^k9i+MTSRIN$FC?w6A?+kiH9cSrDHRLt!wpr>2}B_@}X6TiawvG_HtgFVAJ0ju`?4e z4?6vhQo)*dg~YK^`{XIjU{@CWjjP(?d;jTbV`;sI^4FB2b7KY|~}HKo)IW3DKyW`;)n2He_b7a&l}iX5vLq zTfhz-9WlH>c{&D(3{He$^lGiIi6eSsv85V{Y?QBNHH;;0X_^#6LsOF?M18s+Vrrk(EKv(QK*8db=k#6*Mfw-hM@lZ~+=ab2tk! zOs*$Syh``}dwg3zFI0dQp^|$LYo+0WuyRa~`#u6xhxaRnee9&MLzWwR7RljNzL)g% zT-dhyKTG!WIUcAH55T@D32~SvLOcMw+zzN%t3|8|P5iz`wP1ije`sxdX=l5=A1@gy z=H%huN3|`R{qaZE7V}j;Q}ynvc(IQYo{q%Euy7gn7@u2lxVz{Ekysx%Qi_`cJoFP_ z(_~4Rev)&>Z^6U#BVH#;)DLBq{M6CT8X)95*f#AYK^X4FChdQJ<3Vl$?*!NuiYM3v zmpX5>iP0@<%sp@7a0S<Vek)4IlH1xxF& zLm>afOVn0LT>K%sn`}>mpzTo=VoRaS0nL+#boeSq|NCX2i@HDg7){JB`gF5BDRj&N z4R0Dd`dM+kTm{Y~YZ%U6Xhc?q(29GW9}&bT;^`Qdo$4tClvH3h7{n?Kyb(oBu zB=%jA?9EOXvCcnyhjMfFTl_X49G8*RQm8NC$y``3)L|V$)Wm;(r`+G{g-4~-@<8L{ zIUeJ5M$AYHIILtTlUk1Uank3yYg|Cp5PimO{sCed*z}uEcal}AD=L`%+Cb_OxEbeY zA7qU5M-!(Larxd|&bWd!xpqKnJ^Ji|lqg{9r}+jPpCE_>I3S_IMzFYy0GE@&X(s)- zstU941#s^=eaBs^1=qje+5iiItu0ekF94&}^az+~KyUU--}UX;O}Rz|R1}mCc-kp= zutvRVz_)^|rIf!j3kwVL^P2Xryo^D#)E5J2SrhuAczxCD)%J^k4;eQRKkWMNu!PEz z=bnJIy5!fkIN?lC%FIRY~{EeGSG^)qQ(57!>t7^*5O9#Gu2-N0zOnP#EFe1KQgEx^2A!cw)im01ZqH2xI_bu0OOlo(-^3wFy*)oGz0ofQyU# zY2MbXF~_xJ2p#ul;bT48Ua15Bp;NRctB>3P-WfmL7DLu;FI7i#NB$ zZmu}>_ituk6IV+FG~+wJ7cf3}(E3YKzO#6 zfy@j>VV~=R@b>l~g9@8te#Z090x-Eh0M$^l@*j|_lLz#d`Whl{HdD9VEJEbcBb`!j`Ei$9=GGFrinZe@?D@u1+_IW`1trZwG;#l9vvTp)UkKEDDBHY zY}is&^|rzb#824A;%Q!AG@2L6D=Z9X=XMw+eoC_-dmHF?foS%Q z5uY1Lq%@bE!gJDc!g!Hl!it>SV4v|2p`Ka{$@q-IQ6h+qH;)+!u8WBVB~sId4izbD zAERy6y5=ypJoot>VtGYHHZW|1I4?8dRlssycl`DB(FLpyz>)Rn46xp-7C=MVkof<8 z0rTAx8q|>pCi!Yx+ZFl-bvP&m?{VA9peECDnj#G_eo|ARM>pH?T5fEXM^lQ;fzAK8 zCxz=lW$IHC2YE@CXM;SAO0C_Rx>rKe_LOl#{GCsB~1cQz`qdfOLvWC4*R{sK#(#?MU@Q-AO#lALAGenAA3>)(# z^Z$bcu~N9SY$6RkeGu1lXk9glJ~Pz5u=cAJ3`m`{LLbktVvGu;#U9PRG?&RK@{O27 z5O`bDFWT|@6IUAHw&tym)MQC!fY#M3=a(d-iHR|;`Z@pRXNC9x%ZF#x@e}E&!iVa& zY#b9&RGfw1?vE|8={gx{saXN0E@|n48vSINx$^U3Ns zfQa&k0ya$?+{7Pn!xZ0#rH1QIRH8o3ky*g1Py4X(i*^=`B87{LlFJ+gj{Ci}j0&p| zNSwM&q_z-M24S5``Q^1O4Jqe!_-aL#rTCZdWX1(1lrzCYZ^Il-e%s8zL$-0)ic`Mi zonEeyKJYFT1y^(mA*8 z*P)@NN;X|^FdeCC)R>0 z8IY|$$6JCQ#5|^|dGS!g1oUCftwc)Qz;oKk#t@numl0px9?4eoWh=X(_KJP5OieI&Js_Xk)%izRll2mRlth1K4rrRd)4;!Um7~AN)M>-~ zDRK0Aa+b;@Lk}ft_XWMnh%{1XnoiUS4@IJ69Jkz8R1CNB%MZLoWKlT9=^#0!cp~q& zthkcZLXXy#y+hvBn|Z`{PVWqIa>Y#twZz~X_3d4=$XvQ$_Rn?|ymWscP4R44pQaq| zb?lGR;uv?$MO>VfP2r!pwo!O?2$Vq(gbs2W^eDL*#p+1TEroW1AC!9HUN@z{{(Ar2 zPFEd8VEIBHlP7Hu<=-Lmg&3Ha;Q2~C!n{{=VB()3P)nH4E0%>$u3~Ny+nE&N02xS3 zk^CD+?>EbOwro{sFhwWJ*pV0#5S2sZj;hnSSCAr8L)Ol*d%WBJ6#DVLg14>v1o+Ew-R9|8*|_nh~?2R+@MK|_6_(&?X6_B)$! ze1R@8dIRmdXs{RpSQ{KQF_}$tvdA!uRG&6;+i2l6BJu*M@p_4z5UM|`hAI{dT7u-Lmw}Z z@&vdR;paN%LvRl=!n{0$8=h)-OF&nykp|iN8#h`XXIGXw5!^~dcZ8?f2!;$5yRTW^ zM~i{Hgwz8wEkYEFG2Qptc0FqC5s!pHVquLmdfWx%7uskkES!(UPO?svst?0q{7hZB z*gf;HTFpKx-E<|#UH&UL)GxJ2d?NsHOvY&*(+K}vjSE?gq#asUy~Xi- zg`hGYJAtZcNzQXTdkqBSGlIOz($28Jk*5A7U6ikLo$R zgbm|>nu&QMI~Ll$+JJubd4LCgYkcD8%9k?kD0j$t2C;`Ty@X|0dy7BGR%lRd9X&*I zqmWsj;`8yVt1NGgp}}3$gm5~DlM-yAFxuFPFz1b6U$XkKq^M|0uw7>Aw5)zVHbmgh z_Eb6`y`W3fSNH#q@k+Z)`z87}KRn+-mLdTYg=_Kx+~9$~vvC;8)n>#P)fx0XZ7{mp ziBJJ)@BCI07i&QyBUoBQ2G7d5i#bM|XM9@kUk+TNFXR+vfbuV4`rvU_*P9YYgN0XF zq__qQ2tgE@-Fk1fJz-E8F_5=qZ@OZvJ;>VBI97#5m|4z}xVH6886}2=85w8Q1dwHk zKK*jwPlT)__a~sLTRm1{eL6%Pxs%jKzb3;aM)JAu`)`hU*&URqywK#Yy$bs`Np%oK z*U|AFHc|0hOMromuXiIK^(5k@xds`fsnM*uJ>x3P`9c6~0ezvWA_wynf}n5c4SYqh zQ_i#;>M%(%n|5#sSxgl;^9<<+3eo0<7K-ypNbupE2Yqj9auur0!TZUXWfpHi@a1ha z@Obq(`CxrwuV)z)%V>JI(R3X2Mn>CJaUv+D3H&Q)AB>%4Ta4_6jVpreJ4EQZDFVZ` zkBqSfi$GL)h4lYW_0{oozW@I^j^=PQM|V$mGZWL@HPbOncjrtD)3%v59Y=Rf&ak6% zrlKU(Vk|jUo&YZ?)8LkpJ468@&fCgGV{5|FteX0Piqnt~p z7uwNgLBEcGslV%zDEJ}uJyp=~F7P^nQ=io*PkA2i0CZ#(fXYc+{Yg~najXK~OaOQz zNNo-M1_1tE04L>RDz4hqYI%Q_Sg~}MHoe^$ZF=qdGar}W`sTBo`|$&_*@N;Z?)|dc z7(yiijd<`~!3Rn2td_k64Jv;CI%h%2kjMNK#hQ&pKu}q-s(vd!x#`r>sNz~M@)v!0 zqok40iY{Auv1WEgz&~^?ggbNbaRx7e-UK%!2}afagIjNMS};g;QxaFpV&1-BY~8|S z8TGI148pjo=`NyVcD$AFz^;w^CoUnqVT!!oNra?jhvqLvLa|K{nP}MXwzwBdceE{_ zJka>bScKmE*Uc%wcPG& zaYHavw{Olok#bGgrnm%4fXVWl~f;ql7*%MN&m@q~DloyBW?ye-~bu6`U% zfR{OhI;+Z!oCYNxfuI>hLE>vfuPLby<5x4b9-O`?MrlxW4OK@M2}r>rGqctJB+{c6 zN{B7BE%cawMzi(E!A@)%~6Xv6*^OCW$*%T$EpSNIaqSBSE z-EAs@j&y{&2qZI#R2pu|2x${6oQ8>1`B2L~yYlOuvBv(gkCnjK*kXZz@m@+kGsDyrNt zBbu=YL@cjl=;}_+l&E~RHUR1e$THEx&Mr3}gRjz8OAW~8j^B9GJjTE2LT<_e%HJPn z-$DcSDo+htrr+sok4f*VCJ!!AYiTiKtP2v!QdbPmh>k{TCe_W)rlm+dS0h3nlSRX6OvK<)v`x;pYy|K;`RJezsa{X|2S7qj{cpY}1e+{rM zj~OkC)LTwI5jQ*K{-gFRdaHhn=8yd9f3-~KjZeqoXmJF@-6wi60J;{c3YO``Hk$a- zo85NlmE~k9#c%wVVd8L`#JR;nRzEHA325!??=J>&CO`uTqpUyscGjQN8v5)iVdL>S zT8b5Tf6Ij$b3LcB74X><^#cq>#Wxf*MA^9-)+`YP@64>T!sfymUQ2LE+n{` zkACg7%LvKWQ2U7Wd-^vkI8;eHdDA@xSF}ZAELi2KAN%lmEejDq?pNK^An>E5nZl^5 z7}|jKy5ZiXOE2039!WI{2{@3GkQ(hAzamY@Q`U!_K4~2$4Fse4@hA*Nq4=dYKz3`$ z1=7_u5ZuC^htieUN%2EMNB6z6)@U)xKl9Zab^)0{28r+XVrbde2(j|MN``sg`+ofx z379viE60cJe3a>DuMZL649K7~pnu9GM|&YFlk zD6X8lJO1|9^mOPDN|pHA3cq%PxbDc$0(b=9Lrk|R1W3qI;}iN7){Mbhj#A*GssuV0 ziR;WViqr>eXMOz5J}TLVPbenVA)fA6U;Ee>HH8PT*l|xP-xsge;Q1*`Nyi$_h?HMT z<71@GFp*ZhUdK1W?qcw#k(yPsFEy%V|bxVN4R~Z9GDb0>F;_CUMqs z>pKAmchC4nu>SUEy)p8qO6{)#KH2}l7MgD++8{R>1#zxDe%ot&BHrN0kXI8P0 zg_@ok_vn?a!wc*|j+lq;aFCR~a)G6tc@>@p+vV-seNPKf$>OH?@HAqi&)2kgff_3*E z8xW0aXXPW$Z8=QKRv^8{nuj_9?s*1@4l8&|CPY=LFDLZ@-(aTq%fy7bGp&iUrap-W z6Pz79NRC2&;Dky|mouNtwkR|jF$Yucm9=i)VNRaq!+UGjCbz^!h4m3HYCd8^iR#YpZ% z>fTB?zaOaLCt~;u#X8;z%fx&`xpQ13L2c_C^x{P#nvom2N9MXCwD{SpTw<tuO;#jDBXk%Z@K7M44HvFqS7$YIkM} z1zo{Lr!|KYdXfT%rn_g89&>z?9r*e*=w&UjDLG-xp8akj)YQUvA+CMBF_ziF1@^m5HI&v5#5p=?VhCyiH2^#5EkS-hMJk!v3 z6ij6dBZV|s=;F_7QNX|IZp0$pGaGSRGn)^|`JVJ1Q}i^7QNG>5^Zygv zvfT{YcGao#E&Tr3-MNmJ(s#rf)PksTnLZ(!6esdhP(a_20E1COR5=Ug1XJ5 zhQ2zQ(9vo*I3A%^i`8=&t3nw}J+Qda4XfN8O5O4TVaw%zbMiE3kyVPL5YKj&O_%mu$=pY`1^5G{K9^Bbi#Ca7#(ca&7|cbKaF; z#R?7ah|^kg?1ii&3q|adsHDChR1u#-2?DQC6l#b|;JH1!`PVQA6uA8kf5lDe`5i3; zgaGXjNKhfaQ3B&;Vy)kBXqId!3SpOk{gSpDN|8I%BA&x+FVfheHV;f%<bF=+NW3ZyIyt2IhgG43lok=0?SbBTA3;n~)6Hy%$cK)54D_$G2?22*e78$PIgY zHq7F&W68AMQHJp#m?;d7?T@NCHK0av$MByeDd||2d4yejJ~oVDcGA?om0yE<7>H7V z8)9HZ#r-NZ3fE=uvlrI6BIi+po>Aj62#`3qS0TzkZ{&sXF-uQ zcXBK9;%a_6O)}^<8IP2S^CP{+;?Sm*NIs&(Sk1vM z?|>J<1Bx70q}PYClS+~Nh>yB%v7xWkWCiBoOd3o7R+R!}v16gLYH~CX^3~>qkDCKx zjWXO5$L@yErDvy+^g^?6VfT*kM}!;#ID{&J{IChrmXyaEU)7R5GSU|Qyo@9~fl`px zW`w+$oTc|0;pqpQ-)m}p0^vc@T1lI%qZFd%z;%I5NE}>!eV@WZUkgqIDt}L~qZ1)t zz*pq>%ZX2e#~|YTFeV4%l+ADp!>8OJDSNIfE+9EH(Q^cYsrJ?fUi{F2Q z@83TZpEfn@59N5(wEpBN##@yM&tA;?-713tMU~udvksCo?Ze1`BHKxZKpM5AZO@JD zSOcb_c#IF;I{WM`uJQZsuS0HlAmf}KMn?8Ei^SMkN)+$FllBbj#yoW4P4G&-p?&uU z?U*$luI;iYD#&b8SsVN^_FQo z;q0~*^gYZ#tN;A2FROJ4@s}!JN?!W5U~dCUrMC|CU+1Z|(+;B!CS}7Aa3&xi1O!C{ zbB5!OE;@)}Db7-wd=?m}b{bjD-irxLAqvVa&}XgWtz_kn(1` zeA6pnR5u+wjw56kc!Tz)s*AZiowYHh|7D0P6>1evaD2nmv1AMM*osk8*m&Z`YpvHV zC<$9fsf;xVekY#P*B`Z}wnizQ7tLv5G9+h(mKsgCvBjN*P%;rRvc@3`_)dmDhQve_GxBPCP!wB5H=|-;L1(kf(#XaQqFMjI^nt0 zU$pXixVz<`5Z?4EDMt8;?|1kP&cybCtO+`7sh`O`)k=hlPn$!pk+`BS+<}@wlSYXm zILkij|6XN4))(|*bc0<~R7|2DQyPZbPmarjP#PK((KtLu;~ij^lqy`B*~i4*mWIX^ znHGRZUMDQ5vyP2PC{~8eHCEsNmOQpU!YPyX`8FNLQ6da$l4eoVnAKw;ApMmSsD$Q% zjee-xt1+NXVx-Cf&gxdeas|j`H-Lc!KzD9C6kXfBlX> zlBczhWYcwd`KC}e8y3}eT(!*ATlgqlZw}rOZE;#(^#;xhk1Top->j90a>*$~pY2Zv zKyV%lfh@)Krk@3tG=n%0#F)oX9GOtrf^c$=h$!YsQn-Ov-9-eDf?|K&_EsonkS>$$ z@x_hsP)3ocxUtB%lGceIo`hbC`o~Gz2E10@AaPLmn{c|C{`~j4Zs5yHmYz@J3fYO6 zEvMq=Wu{39HdQ54vT~HOS&2^?5j|ki+F9-#rEGV<$MQxV)&8PieiXcJi*^qTvSklq zKQGRJ<`}?9)Zcz*dTKFsb+4Nm#5-k?`ZoPmS63&Ja@fDl|JmJzRe7tS$+i#Wf09Lb z924`f>`uy8(}VUPA04B!mSkw6SZ?aN$xzh@p~rm>XL+#>wqtt-A5OJ(vvf^11lbHP zzB*Kiz2?JPnVJi!dQEjiC5q9mas2$K}5k_xt*ADK{K;D^whl&6BEAd zww%qfT=Er7(H`u_fp~O=uiZT^AG(WpPO6`5pBhn#KW($D^-&FI2SyR+Fnj-zhX*hi zRz3|DDuK$Y@mJK4y^L%Lb?$g<1^M~bW~<{2=xZ6A=H7M>;Q;nYLPMEwUN%v zjmdN}6GegXQ6nXF!z&i&FWmboSB;FKL z0EPq0`Jt4xZ~FAPfaX@JDOa~#kjKTn=lFp_Di}NgNDFg$+JjeMIe7)9E`T7S_n!9RX59~)VCMvhu_5m#(xWcF=~c}nO-{(!by-rr8}gV@c=G}t1kc!cHmAhO`Djn4gkMN06wOZOmRAJ4V;w! zaL1%u|5L!-%UnEHd^&UVZ)%-?0O;f%Fi!Zp0YXkA0HFka<{SX)fX505J$YsppMasg z@aQYXVgL@+O!*54hMkwLzr4Q=?Y-T|>;&R=l1557nP$EmNgcRWwEmcT3qVm-^`8OC zT)=1J{|GxlC2D1x@z7hDqz+b*2ga=U$EFG$?Mx{{Y{9qn-hf{KukG~YK47LP|9r5M zx#@F4vMGva(z2m6VJ;_rG9L;uh(E6Q&?q6CMRlnAHzo>Wd$|v^LB};`I*flYD5Shf zFcJ@&(vVVf^o;;#zpOM@Uw?H=ASDGYZ)J|qpM9ovlmShm?6~hHmUuQaw{-{{XfidK zeSNIF>pKnKC|>oGEmQUr^CWxpp4^3u@My0q3jY!*pY9;F)zDy~lqgyWOC*%|0lOkf zlogNi+g@ww69*M#_|ohFmBpjL8^F<@0>P44f2Hdd_|va`Y9|FTvz#GE|8@O2b6@iY z(BPX$sY%$uswAi+@&bV80KDB&S+~aNzba_}Tgn~qIAQNPfCp?YHRmkj=ty_^1k%L> zxb#3jesCMQ*Jy7CuxGblWq8zejyn~%vx`yIXrC}EFIpaBGZk#ci@6K+fB^LY;^(Ht z#bUe)E=#N>2CxjD0JPs=1-67tT;>ggXw&aK*yGaE$KEx3Jb#}7`E^Fv!ROi=-&a@x zui-FDLMs_!krrfQRexv41&JHALD9mta)^CSSZ0tH$@>pRJr?$40XoPR*fUA{oS6>4J{`1bm+ znEBx+ibdyEirP68o=5=0A4+aGbO7Ydsf7Och2&+DZ|SX(A9rXTyhf(~y#6_J@(^WR4rU)N{+v(mdzd*|NTe3@t z&F)rSkHEf)`y81km9!4mVCp6mKdk&{5~fwu{+9g*PZCY~>x zo>Z++bBy{U@`v=x2($9oE`l~f(|dE1(;;s;kq|oxsp5nQ$**E4`8hIc!@aI}d>~e| zA&;*}51XCO;G^Zbk9XB*dHPbj^qgW(cnN?rZlmr3$+z+M-t6OE7hq-)7A^YJA>uc9 z_WSBCXW0)p+S%{8Kzu)u02{?<%6QX>t_5(i_@RMG8b&%#mtVR-CAk6MiqB#1-lXzw z1E8YibQrav+lXdR-Bm>Qan~$u%HbdH}93G~0$wbYyfg)q<;UV5rBA0 z-d9^%JJ}_t9ZQ*j4rpC*`a6NA21Lywdb0Qx@Dosppe}V?vq9~gUoT9sUtM*eE0Ldl zJ5XPXHs8%_bKl1PYVm^z9cAO2@K8o5GJ*{Z1Hz~0BgD4N?^zh(h6Sf$%boEMg%?bz zzcz%*>L4@EqSzLBGz?=P#N5v3A~#sM66$x4*d`FgMNYNtb~@pIRlT3llC+z_2h^YW zcwEhW29q%7f|{XwQUVRd=6UVMicuno>o$ivvv{H_0*sBGXWfjH+TH3>{?v?Fu}0sX zSeZAE2LLSj12D1y$$M?A7I|DB;AS*PgHnPNvph7|B(4Ex3}BhV{9{aTQPCwtjP&qS z7vvde1Z#YD;;Ek8GEWFOYZAT`jFA7x=?n0j{~^tG0G~zA2=%P;h+OOupbLMdx=FYePn8lhm)+GF&Vm43T z_1b{u3s6<2fVh;-S1MlbNT_NJ7P6`ZB)KWTFEIERR+;sTvJxRrgF-_3SD`Kj1v}1> zs=wT(0$Y0=C$RX|>#YuLPlDNbZ>y)xUdu7v;-cd|fvA5WH*e_Pi)-0JX^hwvK6qY! zNah6s2K0EH-0nn@N^(Li7g*sS4A@=OP%u(gLsi+JL3y=xh{2(V%R8OLyp=&P&3 z1*3&r4F8czDf365w|P1bAdlRzEnDP|D%Ty6LC)`wl=BTswRgQ&~h zofgnk39mZtJE?Bn0*5%2K=O(Y8r<*H7zkMFG`E2y2_3Tr7&7-_t3{QUF9~O7y1soM zdZLe(0Tu}Wwc7xqbVdkbgAy62E!pSlnoZ#vxAzb+GX^}#2MVEV$d`nFjIHLD|JQP78?W>w(9$E z11#Jf*zij?0Z*g;$fJIK1U6QbUzA}zPAdVq{c0?Hg--8LmbP;WaK(?ff?DC->r>83 zcof3vI3A6^wdCH7oyV#~X7?htU6J$}alChpHe3Q~MkpaV_AZj}9VR*k0WOCpzLZoc z^Yg39?~|F!x7d&BIvDSFKR0}Tlgi|kJShX+rsT?Jp+`|i^Lt-j(Oz@UIN zgnkF0Le-q8f5-K~VZYXqMF5M{LB7DZ!_?05w`9M!X1ui=TY4TcD@d)h8l^B88$6(i zA^3LPw(nAOAu*qu!<(+*2+s_k{~(Z$Y_NKXA^yw;ISZi}p&o(87ugKE0iPh;oDe;u z=(hqMo-=w6$ZtUU73S^$#G`+)>T>NuRQszLD&Asr2oBd5CyWgqOz3fs+a`k&88o7X z!q!74Jh^E^n^hQTH@in<59JLvTGCtkVqZM{7*gJlA^M@Wv+gTdd=fwQWuaUw^Mi;p z`RkqlvXER2NboTD>lTKR>=%zmbii0TY)`xNnz)Kck2mLRHG=@o2mPmaJ zSPpr!S#*WI2ItE)&I8;>{y=S1^SRlTs#LCs5B#rS`&2xB%mOwA`xnlBmkyV`hwl=0qG zcJ;(Qp6k>u0?kN?yDo)nBOLKSQYNRXsQm3-kIcB{NegE5p>HSEWA8VO$NJ+OOY5?p z@h)G${RB0DZ;EjLWtU!K7y( zF)}3C6kmgLcAm5s`>$k@{xHiu#v|)FZa22AdiVUC_#>X^F6|T3sJi52sXg}OHb>^> zu5-^cd7!D=h&&}yJ=6EPzx!Z=d&8e>p!PtFK7Mt)O8M)QTl8_YzO+2}6>x2`;Kvyv zUooLeumoy7l9(Hc>my@Q0SwcZI4R1yHz}d-^=2(%mlz-0VQ4by94v&3od zeBOcn1`(dL@1860*GA)T^xkgu$}<2}RGuhtZMYj~=0zQ)>?>PBy~hxBkhkbbqhiyw zs2>%a{orHr9?&1Ccmjgmf{|x^a=w_863eJ^$aj^e*XF0yKnnsiA?QF8p&yyyr{XH7 zYc{UkGngI!RaL|Fa=eio0ZDzRU#I&u)E$lYSpG%3OancQx=`cpE5&w?iAbtg#=cQD zOJT^jh1BbvA&yO>lTLRB)`gD;V;A65Kx3tm+HDY4#_$_N;SAQcQEq3a*f3ReOb*q= zRxDUtpJ$NWE{%wA02Vt??vCLhOQKxx9e4`3ktm5cIR?;UHpHpR<)ZEU!l&~%LQ%pK zxr%F{8K3q)EeSJD#*AvKQRB9JwH6?LcOHAq{SWByw($SxAjjXY2`fD4KGoe3cOKBu zw546uW`=kf5TiRy^%3)siY)bI{pe|5vXj$iNuez+(C9;X4rP-DLD3O#;k3UNv|l6d z;$J99#Aj}3=*;#1`E`LTSd}i!Cf)NkfGhMTBXo=GP5d5>S7&QE*J?AaHFIt1aBp`= z5-kxmt`~hWx%8A)BaV&=%V)A*6X}NW;f9M@9O94X?<9dCJHkhO;(YxY{+mz_r$vp4{Y31E|*V*<)kJqpXv1h z)f=E>rs)v`m$d{yzii)N$xtZ0K<^z;Pvh%M$-nJRQ#CFs&Ed;kTV=}Oq&0` z#{Xe=f5~Gpyu4D^Lv;;Xih83T_M4Rn(cGQp^rNKkNmPg*NM&yF9}*r2j{R=|j94w= zT@+dLSnds%eCuo>1dCX9r2wHo)?yDUA%h=%#TTPXcqc*k$6S}udi7-@u*Zhar9*P=<4?#pAVNrN6j z0c2g@@JT90y4KIpWL7luJA2nxaZ2;3PRrV~++PM~hmdzz>Z9?F#9TJ_LeYsPb?{!} ztYK&iYuJsE1-*wg-BlqJ1GCkC7MUDqp;mt$lVYk+yN+Gqph>&nBUqQ!Q#`0G!3T}) zuy2y(TForLT=bNM;SOuyYVTgtI@wlC4aDyJF{ySN^bJ)Da;}u?f%MwJE&F%nVbkKp zobRUjKb1_~wB&zZE_yh2kEEtR7?cgkLgiIOa$d{HObY8uV3!ZQ;+{mIHeWWyc$s}n zO435(%jKTU<$KvoS-xh;g!MuBgZh9rzDtBcI;ozzhyM6kmzUK)&KO3<--+$YJCfIf z*#}JO7BqE%wcqwwj2h1CQR?0amm^w4s!R;J=4MM}DKjLA__(Vg!qPo)v)#!wH4%L- zvS19&jj}Ga?0x-VZx>zOS%|KCa3NA+)6F{7qOo&-ksO)p6=Ut$$Rq^@)0(>toq%;;lJ~UF7Ov0?@=!dvM<~z3ixnPw-_5<$OPM`E0?w%~Avj*{RAImEPi zzPVn^MdLUnkS_Oo!wr7bBazTRyo~org_@yua=dw9W%Pt%ER`}j)W&a@S5q>M&xa2$ z^j$yC@j2jn_!zN>oon%Mu$vcxl`Y`wR*#SUd-%uJ;R2BVp9~gH$+GG6rQ>6}$0KO~ zth)RH{e$I1>Lhxvnia_ARu2Tor%5PLnK80+qI5_L5p42JEH$d@Wrmx%f8knUn%D#R zP#CFs*kJ)v?k(3UVxLwSzlO+c1PjqGzLdf*2{K7{uYJEuCPnh}#r9BDI*zj9MH%+m zPnlGs4qVq|;m|0(EiM&dOe2a5c00Kd#BYx|7L4wU&U;U+HZ9FH-@jTpMIVt8K3ck$ zz0IEB0f;=FeB@6|zcH)*IoMLGXHa&46pl<9Z60XDd2E?(1}(-qE*x3MMk_!JLF(+O zj4TM1DFIWGk&KJ|{kmgoYyp;ZIf@iUBx(w2I#$yO;O;EOE91BtYoPM7{pz&M{BAOz zPMZpsO^)BIXBcgwu6Qr3DQ?EA8U)GJS{A~3j)^nsAICP_^F@r>1rU82VP}I$rvtW4 ze8th5i4XJ6#6s8Ogfu3Jk0;*dIO>Z1cO6o>`Y(Q}zwdq}{&3pm%1xP08bmuc+XE@6 z5jSKikumokjrXJpLzcB0u#Uw3#$q9EEe~%aOHveFoSXE`5RMO?Aw(hnK?fl4e|#kX zfUm;#H`$X88oQx67st-@X~ePDo>e-nFCIRNulx z!y#utD&bV1QbkzJeD>}IUA#39=@!oB-m!ZLs0UdSQ6ME+O}?h1u{aaifEqpb;)EW> zUju8Qoyg7s5KR(q6W$Qbv;j*?{+&fG^fH2#o?lK9r7pj*51li2kK*^WLsMfE)YN5( zPE^##P_Vs2TD?wT7pfqohoX4GB)QO2x;ts@1$t#>*@`(_S@?@1oD}3Y_H7O40X-82 z`c-7Um3^cE$<}5=G!1A|a33?k=~!F+XFaryOtD*Mau5sTjxWyXp2hcvBk`PV#l3~3>@9Gamk4$cFk+>q)3q4=A3=8o?)}%T!xS3 zg0Vo9VShODo^BMeD*$37GU(NRv7-w3cu&ds&Q+-S1o%y}FN;(ixHsB9BOe{*&M3Uz z-F*3rTu8UPG5vCGql!pYl&CPi5d)DW*a>vfjiC4!$Cf8cHdZ}QW1#oM%&Y&Q!Gg{-IYK|7JC(*8j9cO56EfM+M~-C^)yD8 zfE)kj+~0_RP!WZTmJAI9%afj=g*{JMESF~v*E5t&8SenW`88Skj>u5yteH07c_YeC z>;W~VaLkF&m2&8#pBHI>AKe;zz6c9jyb#A`{+`@_+&fRAT{dC$(%a{6l%(z4$Jhrk zYl_RV!gTMVSY=FE7~*>^5J2@LWEI{Box1MthRB* zhev7oeNCBJdR1o+d1-uHkTp6sFAXRLYQNR{H1 z@v<2aKubehNVS)BhON}Pc%c(o+uR%P7Dayr>)2#*=7*(1$HZmf9vW}W9Dcp}xM|7l zl*{3c@63AY@zz~Ci3IMq4ivWJoTT{eJRX7EY23xDgn=Fzdy6fCzTCdA6TLTG33Mzx zeF^RVUzxle8BDOHWxH~2wT#f5=VYSxY>~yQ4~ua?Gt8xRPpPtek+}CRg!>9x62Vj@ z*Ml?z@dwQG5{w6vk8w?G8a$)}mlOj05aIH0!M0<#6_j1eVKB~WQcgOc%#+xEPM*5} znSi>0YIiuP-_g(D`_4ww-9Y%xCuG*ekN!+Oc_$^QGpj>cBD<7c1wlW7oTM6N;*P6k z5~YC9kS%)$w-h{5jOQtB;loHl$iIyJj}hrS>fqVsWO!)wIpFlX%dI!w#(K}(^$p#A z6N;iYIp)AEy3Lb|O)l*aF~z=@OS0O%Y`cV9=73tl!O}C0>t`Zlvy>)0MP@N>!%FA- z#7dpTS&+=ycd>pC9Rl>7dK<(e&TiO<>}w)|O~_!FUZ|f{&~8 zy&>h0^((DGMi_?1Wj3_o7QO$O)U{7%ELt>Q0Lo7SdwyP|)LuO+!ms$`Z-! z8)`x2l2a^nwasOa(ElU8I{-Ur7hg_r`MIoKQz2cMP?TV-b!PS({-t};kKbxvr|_ea zAFOC{l(>&cGQCCJWH_Wq!hrsI!65qHbpebfbRf*3_s%;S8+=`k(k@?m?y?}>GAAglh>T~VAc36 z5KRyNJ6gs~zO!1t1hgDD5p7N%J2-L0Onxj^uSNx~vkZ=^0mr4lUfD9rvaVyzh+9{l$9jVX*2t2;_ol|T^swd%j?d?+;iWx+61hM`GG9aTk1^i5%kx$LB>LeoHbtzZDLG4PKLY zsQxJ>fXD_E^L|}&jH@(3hveGLPNhGq8r`Gpk8`sx>J{mcAKjU4S9=U_5>)-+DEO?; z03y=%Zu=V^uXL99O{Kd=yav*86ZSVl1M?W$7}1x0lm=t4?fVWhM!IH^D~-orR#J@GphO{S^1p_zvXq+-yZtQNto5Q`k@8V;f)*Gq-_uUbFZS_W8V77z!oz_1bR|NsL}Go%Dtj7l3=a?cC~X zaN?2~Yq8?jMr8{cC3&)31c*ohSN9Ro|J0q!XTg!mn?<$RgJ{sl&&*jiwM=@U!*U&J zf`&f`H^R4ZzTtl(eSf-IANl&VsYaWfGWLjHy8uWFhvmJ>5b9rnavjnuqCbPF^N9zp zuVoi=6_&a4F>^=GO#Viq$$H~3IKLS*=j~mChJGXoiRyR2Pocbt_=q3jv1y6xhAC@Y z>f7_CFa+HTB9v{8Rr5HWFUqC#%LAD=HBP`$v|Kp5;}6Aue%ZYjF9EP``0`ghcQxf9$GZ)_mwsZTp1%KC>l-oxJJNhMC{LwPyqI!AX#@ z+om@lMfM7WR|;Tlp1D7w|J&^S*(&Lobo9G(SG0iEYS{;UxYjpWUqlFrvE=aSAq@fB zXM@{5NT0)+>`D+k3Q^QezeXbK#&3D{YdT*Pp2%R-Q2tKLjBM7`Nv=6EuLitaVs;gKv`?-5*I_xh8j6OQ%Xg#1Dx^X8bVy7d)8o zJpv>7Po&E*D?Vj-h{TE%4V$N_sD|JCu8tX4oC zYV+~(`MbtpSi)s)8f3V29NOhXT{kt%IJy{|lVR37R-qNA!q+)w6IzwPKRBpbWIea> zyMa%5q(uYZjVIHqiVT?sMfL0Oz%}A_AIMj2=qle;QV+k8LDa3?yE)Q=Vf+Da&rMs8 z+0aHvKFdw|=$dX8Iz`XyyE@hlX^&@ zMshLJ-wdd!wAKHoPpvrBa5TKDJ;04X)!YV~vYik7n$hc!6}vgL;;0|zK2(d%j6r+` z#=z%XnoC$5BU)mZ48hHnBCbh;D2wnpoLnwPM_M_=BeLdVhY=uYWA^oCvumFpB~5G09nkRn`>Yp=0|9Z1RA;`~;08Z85;6;n z4@CokD$aE{(ARwO7gCQeDsgowe@*EHim@9ds+y8%UlfI{VOc1OLz$(f&qK3YIDO1+ zKhmzZ4-iR- zZOK|Pi{njGEN2HOX-q26E+wr0j}9ErpMJkTV<<0u&Xx4VYr?X(KA}j9OkNt>kFw~? z;F&C}qE?G6DxkX%g&MQ494f0x1=&JGy zO8KqnhB zk=6bHbripSv;fKSxHcfb2zz#iorpTs&1W4|70yhdZnc7;8FW=9sAWfRsaU%$YZ-OND z=K#K=-CjB#Xy!Y86pt_)>jz%lwy+gr`Be_w6x9CKlm`(2b=67ZT_B$KUDFWML>zAh zU07OENBnlICbF}VR2t$Pmy_ov;>6DecFoldzQ(6C8AWz3ASzB?BEQ+h)V}}MhGIa@ z zWV!xW-+s8M^WM6Wkc6&vIw+8k7a+~j=-8*R z)AJ!_EVz0usVCnKYR_ASr%5KA%o($Y@%1B-QT1cPxfB-2bmC}NXN_!_P zJwr@KvKTSSlKT#dH$l^7DfGY_Fal^rbtWT+KtXSknU25Ztn@^F#TembK~J=*o<7I3 z#?MKRSY&AYm|7bO{UC<2$ku0Xf=m0XSV9J29Xn@Nh@pCy+M&om$4qDiZhV&2TBEMT zLNc$_9+AR6DHr=AZKhSRswVrn14IKYM3PC7+LbAcd|jjdlX~yh+6s(>0L%$q#rpr| zjVJVjtv!{~{3A28;a#FG5BkpE$ol>U=Gu=V*xe0?EW_)Js=_ks_{Igu5AoGSH|Y6r zszS01>F;iCXFUM+HqQ-la_MVA1NKI}D&m+DIOh~rv8oouyETNP;G$0S9u1c1N5;fO ztI1Yjdy#j_I=jg_N1PPFEm5?P28N-*Ln!iZLD(&d;Er2 zyPbDlH1bm5loZv9R4&P9u6KU2y!bCy;7_$A^q8epY~B?V!ha`tHtO&&c8E&O({&So z6|1ES68ng_bm}_?*&S?Om{`};$4n|-Q?E*X$<$Rm>6mAtp4#bl3kx&CDXF(jvtuBn za|Bm$&Ive^BhZ3DJxy})0e3H{MOaQ{bs8+?HF(E&5tV$(rqaZ`xJ8LxY)C3GiujQ& zZ4GC=>1H5#vLLKp;&~$27vax#PxGtPo@p5;AgOQHZmbQhFXHtXZ13I zSs++J2+#dBdp-G#F#*Q$*(BU5XyqC`A4ddDTS%YK?&Xa z*yacX<=}y!lg<0Fyl{Pxcu^^!Es;LOo0I0 zQ4zS$gc2Ea_1j(>CvxMy4j+@(vLFBr0%t#Swx(QSkC=tg#*)PkhKr%#Y$hRn;5$KH5gtOM>W8Re=dm@zn?L)sDen4s zdAX6;oaw;M5F?_i8*BtI*L=@s24WC=$~8P3L-#<5qQUQ#o2 zdxDb@#d1Fsn_K>%X;lZo5`(P4a{X7xF5@ke77c9%&8&l@1^yMF zcch{3Gp{&n@*?_>uz6!_j%za=4YD0G{`82sz_~gtBIKG`yXJTD5hGa7h|wn?HtHMF zNL;^W4uT*`JRef~n=Ph97?5r0n%^s>1IA*%c>cIPZ%b~MOT#{@ywp~ORkM5 zy0iU}jDw6~A(k+D-tdKz6tJFn!{Yx@^_6i|bkS6cY}0yhk&G{ zfCv(Tba!`2cS$!=?>hJWd!GOE?hk&@b3A+RHEY()HP_5V5Uz77DKo!_Qi8O?QxJAd zUHh^)7b%RF*Ye7AM~r#xPqrQRU&)Ap;0Pr{aXc7b8P(%AEw3r{9NB*0haqU@9X;TM zRQ>tiFex2d+QGT7Qi_wtM5ZIxknQ?z?K%*4o+>E~Ch$E!21V$v-q)QxMqSDq{Dzxr zKb;to(dOYzh!g|zBII|BNUe|2&2xoq^J2X7bke?8^MA%mNd(`N0OiJ^OUzERkZ}WJ zGHaZh`eyBGuiq7OSel!=U1K{M}LA)E!SjVT-Y__ntuh3Pf|bOZp$?vpz`Xw zw+zr9fBAR}_|gN8EMCde3D4ywOB=T(>r9Gc_$H&w>pmg#aeWjyNuieuh#ERbjC zX)x6^P2?2A40}Der2r*0LE8?zzQ`P#&iU6R5f3R&rUCZpaoUR2*Fvb<_tC}14e()peXLL?&nE{jEoybF$d|k=ujAV#!qWJ%y z-g~(4+|K%1{->UJC7GU7w!1n>aYy8uGBJyMdz2bP*#EL4pr5w#*M2_=zA^tbW2htg zHqsdg89YLxowr!;u@=_`PPS?*X{{D$yLE63C$i$bV2F9{(=gw-g+e8w@^Mfc?r?es zeoxOdlI~)idCvHfu9w9@=zF|B5h;X)z$IpKO1^GXKqt+=^Y`ro)C(#neTvRj>~B!- zX8WM@*!#Bm&)Y5%+Nd$D-uz6UgyrGm3SsJ9J!iQ24-p5r5{+Y~LJuar96|}GY7)87 zWl?+~Pn^RywM%I)ougc?Owmd3*6P+(wdmkUlEl&I2sv{@luhVl(jzP!w<-lua5UmN zurY+inH&j4h=sc;xau;z!y<8KOfK=L>1_|u;9mdW#)U_5GEM9pHMPXu@D?do7^{i0 zb{!!)Frpg5#os)hdDRi#oBoZf_1x(zzkjdoI_s6u3^^1D_B@z32!BAZr5#HXi@NmLroo4L5g2`3_nQjV-A z@Ki&WgdW+gCY@L3R`^m_WZdeKEzj$}q20gL+dD{8Vgpt#5m^~3W@Wq zJjmZ2$%-;Od&*Yx9eX8uImuG7hz$3-L)&2uA_UPaT|5ZUtowJPh zpFBrHSIyhA=zXsCb$0Vb6Pqb z&?xJMfm&zUK_lzV7a^n$a~TYnT^5*Dh>JL-vVwhuFhnqpz@)z6V)khr=;n-ub{_GT;h$ zLA^%(etl+wh5)Y{SIW*U{0nL}i?JeO*MFdGr!JhrYcG#VD$M7|#z1Hs-&4ij_6Rx!EbCIb-*CtW(&1ZbY-_Xr8Z=Z<)K?Z?^_ z*DO;hPlpNVOnQy)OtfO2Y6HCHrDyO`P zLCm?;?mRZ5X&_=f&9J+aKqbZ6eA>C(`0s#TB@H=!s_mz$B<4~^FB3XCXh-Df z{*7hVv&9pJMOYtBW%IAy3j2&+DW0hMFE-f>GzCm4&w zu8tDILcNPynRA7gmuV{*R;*6g9#JP!p938=VcPmdMSV6lHlWPwMAi03Q+Wp>4}AfM$>^$_)PD8uB&sFhivNX7I|HEhD$42|0@1iU$IsF%~YeAyqb=~<&0bTu70 z*xQqWPc;~UZD;@!rnKa9N)Jp48y-qt2 z`E2JMp_m-|$lYz18?Rzt{qPdx1^a@{I%hLp;|1F0yyrq1ItFXogt;g#%#<*5-FM_q z6o-73MfyDqP!5=j{4Tyx^WlQ*)i43mZNm)SQUssk%$&AZN&WT`gvX4!^Y1LNZ_?iV z-J(WFZ~f!}YmFEB0$RD^>WVBmco$Bc)NVl1mV-gj4)iAYj51!6xT~~p3+74-^9c$H zLOr65FRAd4GV<5!5pkC1?W@W*C7q&4gcm${Hrp$sPHVXK6WLKnL;75GlpxxCVtx-% z_)NoRUTejzM6g+QGmwHCzlE#RNe&zqZkcfrfjmeN_uBO{Cf>T5A{l9vUlUGsgT zyo7oQf9So@CV`}y7rB1|Z7q2;i3_p)ySm}5LStg1KX7UdRaPLS^+hZrDY$S@Aw;p*|l__EUY z>Z4P;!TvD^dhvp+!1Nhn{{)ziX8m4TdH~YvR`8!$^}Nn{2>)n;cZZb-RL7I`!EE~E zH%WAn{a{Z;J^$pE6pvR<=ae3*7-wzS>O^HD<1~$Mv7i2?GH2i~LU;@Qn{^$%o(O)c z-6imi*AOAj^4*!h1$xP|S>UHQInccBz&%~U!PyFf$OYx+=lRdT3`dYXa2XZn6o@dRo&xs-QohF7xL{+YjjPU;;K6icthmW@NuqA$Lz<} zSg#J1sfh6N9b0w(Aipoo8(Gm^vwA&C-5l8BnYJMA4?`!~%g&E--al z3PWIPROm#v*7o;!o)kokK!gAJ=MXEYfb*8D*xw0cuy{G5zU!T#NC7Lgc9{`bV8nDG zq5j7i4Il@Pn+VQjz>flQ4nDuUZ;q#wgzUEZ6T$p@LIa<(W%t#`5@p}-&P|X*@ocki z)n!cN?PunOi%}tEp`#iwv7ckO<@xcXZ8zJS0LU4v>U(adJYOn5e>M13Tg%JC6WI@D zWNYi_R5TuZM>%Ra?L<9kI%yqZYkT;tV^0kB99VgX(TT2u;qYyjlW$KNb}3FCyCZR> zO?#s7PyCo6x6z(u63XiFn@b!1`Nwff_G-m^|i%pr$XpnE?c7;wEQP-&<-&oDzbj0Sb+u> z7DgKBok<8R?D!o8Df|vl-wF!~AkZh83+uHk{@40X)SV>=^IayhA#)Lb3y^OKW;s!k zJ>rqoHDJsLr1094mu8lv$*9_WOH&KDZ%2k7y?$OdxFr{VwN(s?5a~)|{ z8g_vA!S8O!zOoOE!y2-z?3i`0XU0_E-R?yS^cgSP^c>5Hd?*u0e@ol+J*@Bk2@ zf}Fq8#T5PzXFz@c{3W)*x(wg4>r@yzsozEBs^tJUyB>zx9)^Gi171u<=LVQ@RHm@g zMt3x8<2UC%N$?vs_V&EKljGy;KymghYXcnOuP3b;KF{+l_qO|G@Oxk0zW_)2Q3=In zd|~Cc2!rmow%@7VL01}&Nh~mQD~V*xvCm^o1est^yvk8Vzh=_sYw; zaiVa^5(#_32m0(p$iDZ3ctYQ^(B4 z^xI}KShvpc`@7%vcc#M2sSf}EqAyQwM4tFD{YW#TMYRGHUd9j~F|Mg8KCx9!&|VLl<^wd(B`%H=>Ot zs!e@0Lie3-BbE6QNzJa6kl>OuQno_*9?3#1%;Q*ak4TrzkRjBrQ+;SRCQ<7lV-Sl4 z)ol2$3i^WY<%ZiCI^qh?48-wo>fvVA=%&Y&Xw8{@4*4|i9{k^0?+m90BVx)#^u+S5 z@PpU8Q>@zZNAF~zxXI_L)PNlL=&#_&R7k5d?ukO#sq#tyK3PqM5^P~&th3&@CLr}H^v(^#Rg)&QUVr=sl%vbaDY1!O2_JI5_($2QMx zVB_!`2WWIvM2D41w#_!HgC)>wa4w8CixS!Yn&dSX1s3=Vc)8NGqW6c@Bi;cw&ATEy zSt}x%ApXB%(O{2!yTR1#k#{q_hR`fEw;8AZt7$&i)wRL-Wr2mPETSYfltO>z&^$B_ zK8z4N2^N01cy8x6SjQw6HuhcQz%LwTDtIUpxHV7p6$l<{+;D;}doTq=!O19w-Oy$A zzmAEG4hCAHHi_-%g2ozA(0^@{zwrTuhl(pFS<1!JHA#>3qCn76_A-GXj5A*Iuw&NF z!9jKnu~kxR>+F?Gm{P6P2wN%E9~%>aV2WxX7$VN71VA!+{_#o=?FQoc*g!r590K?7 zW$X;t2@tCX0Y0-qs}DFjX=LM?AFmhRGU}r1C28A(b%J~xsEz^Y$qLkol~a=IuVzD^ zW66bP$%L=xO{BN-!YTgl$%=iS5xSaI8xy`52ASfwhK9SV)l0=?w8D~-H+qf)eWhgW z&9o5s-R?-|p$eD2YGhywy0&XfpeqS0yE6(lB4FhlE6Bh0k-o2QEC!yFguZV!z)=x?!AEN3O> zAI)fV1@KK7&FmQv2(e-Q((^j2eS-b4fwK}3x2`O?!d>JTQ(q!Z@JWt{VtW^QjqVih z6uq41@Y@txJX}v+AAhGq??Xo&h&T!bYs^P7a)2)Y+7|I7&fx8kfy3Ez_sfl!F`w8) z`WUdoXYll@_m1aV11(Gzi?wzsT@)Z96aZ-w*u;uCqI&L+^Y@*=jeBp#^4ZT0a<8$t(SGPPz4yWx zB}nWDMic`!De~)EvGI*+IGJ<*U<#9>&g-q(MSBp~n6jZLfT%9oigJ@FYtP#NE-wgE zoJv7joI#XWZ2d5vAQ&Ztnwi$G3*)8adYHp}VUi?DZTSv->sBrdp(-Kl*BX{)A%ve= zxuW7Cxo;GWPAnr$tf3PnuN`GRpz0nPxkOZY94koY4!FX$LATSY*Od zCGa%R*`|)z^(m}DZ(Br;{$xp}Wu7*nhQlM#BFr~+{e`)Xk`*MSEG397<8ui*K`sKN z-lfG>CHj+MfRY`B)JP@ukjY z(@WcHAuCo(K!^pH`A&w-tNI4uh7eG#S1g~d>o?eGa*Ov(VXD3$5UEGO zdtzR_>v}k0!gc>Ke2R6yMEJ0WNRiW# zdnijnG7g2%Tx{-RT9;PQxvUaV%nwcYAm$h8@ag{NnN@$9L2`AArhGn>Y_Bdx!gz4I zT9Fjq5XZ}5e+BJ5+|j(!4Ls)$S$-0d)V#>LOf?4>n3#>E(N&As@g0D2jseXxt8IuEgc^YReHs@I%HB-|#wXt7^f9?plnRayp;=phRUjz1x{ zL!hOm)#Uc$L;Th6F+aEN2yDuy)9}@+a(9u_c3AgSUw7rZQLtqieD2QSQ3;m7-xOzi zeUAW+2NfjNOCU(n0C%vJC_4)Bp3V?tiyYtU>!ZbybN(3++k=H!0_j((|6MBhEr#p) z6&qkVNpy;Wz@3BFuPl1E6;A2r(HBP!&gQHYcW?vXCvHLs^=~7UeKrQ@b0D^$By_~R zVsw1kg-MwBmaRqoHAHg;rIf;<>8SQ-vCc-oItlW?_#0$l803GKPyF1$i}|()1heKR zC#laqN%+p+Qa*3`XSuIyznvIVg^BrMO&$Pm5E!)&?Thz7SjK#jT8cO>o$zf(S44DcR{=@!|Z-Pp3i;MD+ixy`2zx;YeIh17FIsW9rs^DTU%T%Bo?d>pDr_l^0-C-7ti%gmp zqEfwJ?WoW7VMQ<49KgD&;UV{etsCvqcj6B$)wWL9#p}rohns;i%NkZDM+#&&7kHP# z6ko-z>3Q-|jmTaba86(gfd?GP;3)+FG>qvUbu9=xmwj)Rz1#4)zIrQaUNbXUf-va$ z+Tq!4Ba$AHB!Oj{ls5F~guDf?TEk$$7iz44_Z?%YTT;zqaR(A`Aa!y(S!prs0ER~Z z@dGteN{hfqKxn`XyspqmGw89&)~PfMlyIB{Dvuy|=d_t+mhRQJ0sbLF+5>zM{El{w zB_y;@+}r@cm5sHvHkg4>V>M;pdYIPc5puUzQ=0;g8GNUR_ZnCzNY!$&cc+RJ zGkI)g!SlO!z!R!7xB*MPz2*_RZd!dj22b}B#4I3l+}C2$t;Z@^0&J+2(Q|6gv8Sri zwiQ3m$@RMjOgD_@YKE5bck-N6-k5u^X$eHC1>f-qyc^cKknikzw(SFulTQZnOrda` zJ=2{+4Uud^w2fNu40?d%e1G;INg{+fxMn18o?_bfMLw5Wq1*PN`T~7*SV4L_TrWee zO~2&(i)()%bI>ydYTouNX2^NbzQ>Z(Ts|@mgovS(m_D{~&Qt8r^*cp6?_h!`+kby! z5rlT%9n3`p9la0*ALkd4&nftC}mVDS^`gR)eL#Gg~67k zYK?Nsl+?u`WriVx^`^O9WY2H6DtsQ@Wx-s;%^@D0;d?N;qd6%@Y2Qw*_51yM7X0&s z>wV~yc+YT#gLL2cO<)e=pm@({ckCv0{^cD<3$Mwq$@=8RvFG^gNct<9zx)MStZXwh z;_?RE5}{#~b><87ymmBuZ242u4*3XiadP&JuusI?v?~$iasx~4)RqKnM$9`Qm`gG> z@bqg)1;X*Io(bXxKi~ZVkVhppcxUm+@IP5G7lEi6*p$!r-UJ8T{ zoLdr9Y^YpxH1=v_+iGTQ8e?jKp7cmK3%ndB0a%VrI%QZwNj3i4KoyPqBv?;!k;yd9 z39L&26OJi=9Y*3H+V1j00M-G3VtD>U;tY{bzA z;^yl^Jw^pR?n{SV=`=C?JK+Y8N?S)T3YFx08#hC`M%5KW;nzQ%{&an3uCEp+&Z9LR z=4Q8Sm^mEfoDWn};b`T-Lh(mA8b0jj+EGd(YI35oN6a>#cMe_K+z?Nb=-9UPInOQd zT9U@O;N~igXVEzE_4XEWBfH!>$rnF1y~JswY!Bi19puDz-QN&Kw?JwVg(<9D-wyEF zn`-&gT>Qe4sg=Wj0eadirG|>+wtQ3H>>HJQ1bwuv&1rR8^m7S1fk<+m$LfLt*bj}I zgN;ypb6cl4C{|{g_;5+#F<4-r1T2)G$~vf2a-?uxtULP^#7+|^`1R{0ObiOYOE$94 z3ds1=$wL_qO*FbA1SsHL?)+E<>3dmmq6bo<1^CgzfrhpzZQs;)i;N{i`v5 zG-yN-=`ZFrzT~YumfMWvX@N?&j=3mB#A`IK0)~Dss;xW6k($4jB4dgB=0BV^^v&*| zgeYo+{~aw=4t@_oBtcIjKWy0h_Ctqo+!~8_WmZD-Lwyb_cak-uiD_Yq-YTLeWqFfi z?PP^eZd-YX%^S1As(T`=h$(ZR(7Zk>DC2>~V0O&BVh=k-hxwLW#SrX{Ek>4P7ucQ* zi?DyRXdLQ~8~>DZ_kj)lNq%mZk=Dbp73Z6X?)*bprn$DD*-V$C=eeCUB3jD z;CJhl8F6&zwSMo>Ep2`A5|Ss9C@%$z&V;Aj<)49~k5mizSesc>KG^l}sx&T`fQax% z0uFuC***h~c?Y3!esZUonAC>BMYmk2QU^TRTDoP(y`6jGSy*LaM9nVc4yM-OaILqBkiJkCn|7b*|4 zkDmSdC4w<1wcIBn{rU2a9}yc>|J?|QS*3Uepqn^72@HAomFO}kVKX05S9e;|97F!$ zYb4OM48gApXK#CC)#vG{S>Kp9ei26{`Gf{zV!A$c%OCP8@N>u{XD-%eGv{+2X+ye? z5alkn_+ok<@vS3^6sa|;8#C|V)Mq~i=za|yoze+BG*g_DFB58)KZr%A3h6F8vHzIJ zr>#rz0Q}yA2FDcxp$Bo1qJy5yJb02lbiR@gy#sOOuFx9NOLzP<0dTuh&+EhAbp0NE z(aMT<6T`A@VqrAyqSw_W&sUmajn|(aHGBT$49uwlYTwIN>Uj5JlWu6`fb^gI#02?% zM!r^S&?w1RlY_lPsBj4?*6bc1MX#NtP=OnI#p{di!NKHy1=GWgnm!fBtWPBuS{GG! zVfm{YDNYHts%p~)Dsi=zFkK(!l-ND1DX4)=s$G5LYWK;#BZ;@aG>2ynu62^sN`ZaB z(mv1=W?ovXfRcUOlHWZ8qqLJls<<1IMf5dI`^C;caBsdCaddP+uPo$rVSt1V5X3`C z1Z0}ZB3B|Op7D3rIlRm!{7};PW}3B zoN9@FiPXF$_gynwKw0?2L3vuoYQ9-??JnL_Oq{AH*A5fP#NciX2WQl$+q2-()Nm~$ z+sfT6DN(Gvcea=wm9f|ehdA<6!8OV`dIw%B(BZ{>Ck5^ zk=<^ceDW;xIdsX{tsxn}HiSiw&9sbLdx50TUld9+uhAne7E=vHvy|#!WSMgEhXEm( zs$h?%vvhNTbMfxl^TSC z%7QiYY*=&4b1a(<6ROwGAfeuF-~V1(o&oSS0Nq3xh&&&lQlBT%h+c-bd2flphATg; z6Sw)FwOxC||J%`}FZH2^auP>$Gz)j%8LlHb%MqnlpCX(f;B5@C)v4r$+0(F~4{};p z-`k=PVd*uPw)#Hg9{0bJ5_kfkY?<0s;lkjBh0fN?lu|$MztZysV}P&nY~pQ&XUHU zzY4CGW2EbRFsqaF-7_uQqRB!CFD1S-P24w6Qfli=ATUg9_&2j;U z0mGBVc#)tOl*or!TGaSTx0a9MTU;Kx;TCEwYkwLp&TjH1j7@Djhr({mwBftMSj11G z8zPM30{nZOO&-UH|@k27b_!`lE$>e%f2;L6>yN%39NB;rGjvm46my0t6uq~6>t~fP=2rMg zqzEK>2KF+jR*up10i9uneJNhh1VGV8iUcplUT=yQbs*JEZ;Ah>ip*}kqnzp#$!=X} z2Ty%%;PquF%h|Z&5`0VSU>CI+?-gG4P%DkIjfa<6g(kpR$x6+$*>OV*D2N438xh4k)MepnELT? zsd+bFkQ{7q{f0B6#1?gx>1Z8p?PZr?H6=90JQqeBa|*@ggf2*2ZOcUPI=7j)+Y|R_ z7l5zk6y?lce^vg82KDoZEpob`!VmUK$-EkVN;4RgJ8qvLM?l~*(dmEJ=Mg9$_=AW> zIh%EiY(y?rzY{jTdkk}rLo{ypGa#nUo<JavRd*VCe-Z{S$VuiM%vVh?W zVZubY>~P$k&6~oT-yWjzedfV#+RvL_L;rlg$y$!IX>z3)0t z5QRh~k5~dx+k2Gz&tTI2ZPGbs5lO~&Vvk&vrgxf^p5!N(pz2_62Q;p=$vf(hv)IFaf|*L6yj4Dyp&*eh;UZdl z;dad7W+-Z(i+2qVcmKE3%~cLxS4U?^VZZ;eC&1WxpTTm}T#1*ygK*bRYBeLawbcK= zGv*z(ThwnES=LP``&i@*dCW&P{O?SuP`D*(+FwvEmhU37eSU(x2gxwT&ZT_gs0#@txU54PC%4u)|mVGH(x4>ycKuUU- zvo>q*GIbSfh8j{-k?QPNmV$QwXPML;Dh8Nf)J_>buPE&f9|o3p4zU~`U+VUAP)G*$ z?~!p+V&Vwc)qYZWClC4wdi)!F^+pAfur?1$E8IpwF>Cap0eDFO?(y%2p%FW;hY}vI zv}9H+02pLAo$I5QLK?dfzz=q005tlvFxScpI5{E~0F(wmi4-{jv(^i0kjOiao|y-N z!quj+3KI*!jM%1OK+11?jR(L`dHL^3kY%NMs%OS!xi`A~I7b5pt~N`-J%6(Z4bWtl z*GE#>uDDeA2%Y|s2#a_Eizq|IwlqZZnj|*LA<#y$Y{0PlUFfD(X=+b8fn%KD7cT=D zjoO@bjz8pp1x>0Q?)B3q`nX46Pu#?c28&<xmRM+a6@=-DAX+8VnLY|p9pyyKYuw_Sjo zWAXHGxB9TdN9nN^$W+nn48%_%00@8-{)@Z6q6W~|36ODYy4@P2@gB1{CeVF>yLpe0aJAq8kudm!u;gy93AmbbWzk^Se}L-dLn z(+dmVIR@2=6n=w!4r*g@{2LL76dt(^4W42*VA3SG*wojHYeM1$j5vcc@}Nba(M&xG zOTRIznNIgud&<41h32o}UP0CFA2C~lQfTiqU0N?g^>L@l>bd*S|FM0mk8L(xBKi$- zNYLxhfZ++LP(1yz;3MY+mUPXzJUXyOdw{zH^Y`jc--}U^c0QJ#_sGOJM4iH+g8V zaX9-om_nG4)=6&1ROn2U*RfD=Z_z>|dkkwkS}wLK&n2MHF;ISYw;atkyUGzPa= zAp4@xCp?Fc3`Y?sUD9srTgE>3y<28!sq6y@K92yhk_7Yjj{HIS-k zzI61hp@~TW>n14>M2~n_Y@5+8s=lI~*o< z$NCDB3ny098VVd-H@ap>JKOfA($y_4WM?2dv#{x z3MxIm?~k$YHW(R+ZX$~-;kbDVggchRdI&GG1N2E#)Y5*1TOTm{?2 zgm9KW0d%Jijo%4(wXg<1!&97_n*QbQott;~o6!n57C4AcF#Ywl0Tc+j^HIZb!+g59 zkp)O(N610r@UC>4uy~_*Or~!L{sf6nn7R~*L zlf)_}dFmx!gY@yj6zc8pZ+=;^+%O`EOHy|{6zn$iI%%>9kL#sS; z5J*HhG4|HYnfv{le95Zy^(+fi_#~R&6_5B-pE=8m;5yw|y}sK*F%#NzJB}X*N5aG{ z^N4X(VR<8nLht+MT({O>&c7lOjwijb{f5+@915j|yiy&h`ti)$rHGYsah*RK-`IjY zbmeDHMDT-cfRbSo-nF%&BD!1qsAaTOo|%s}f4m7nkchK(jOAKN4%0YnR=pzT4jxq3 zFL*`ccud~nXst2&Q}R%Lt>Azw=OZT8!ER0d1-}aG-L_`@U%vO(bHcklga%t;Gf?){ z);QRDN;hjjLH36Te@BlZ-*SynR~W>ZJ9#Ap)F2O&>rKY2Ett z7O(~eT}B1y8~Pz$VuqPbb-k`;DdL?)^qf z?eCz`9#Rn~JBjiS{V-Io9ke}VJ1Q99o@c~WYw*7IoNjICHtgXV%xl1T6z}d8jj+qB z_=kxh?}gp$_g4<}?BKx+RT0EJXdavD=SAp$3etN;HOID?ZhlMlqe}|i=^d&HTsMlq z5|T1WSUnfS(`b`_Fri=RVTxU|@*I?>yVN;0xu5FE z9Inb+^d+Q5uK$j+=*OSbgHXwcrJe`X;mGJT469QqS^k{^Mxq=!%z5=yQ1TlV#-f5Z{l5yXRRo6O&D_-$n0# zkBw%F=)8V9qkMJ(M5>-CZgI)6yR&%zX6Nm}q9Qt?Ucjqa2E_*@P_w$b*rjyp#)c42 z0TYD7@4@56d7>-@BX#`{IGZsAwy;>A|NkmggUc>;=k48Yj@ZR87w|Xt!0hZ-TYZ6d z0W>CGP&hLm%U+(J_c$M*7kfDE0*tOrz@CFp#rTT<%|cg*H2ko2DEzbf*h-)|Km`EB zzFi4xkUIeFG(Fq!$+gCv#C{jdo+u<14WEExH{EzI!7J$zh!B)MEHE5OEIq<$R{%ry zsbdWa^+{)!kOsqLL_g!?h+e9d&q4~j+zr;Fv zhpy+&;>pb2ty;zmPU^60t#WmqWPQVY(zL{X8@$OyzUBH4AG@Z(63MR;?m)&x8O(t~ z&r9mJsjMvkwFc#20sp55LVb@s%SU~Xj6kA#NNEqCDY0Y%=KyY)MAZO!OA8?9v9(;P zqBCZ5nDhcy1>x6av4esUU}@IW)Ij2&6F|S32b{2t5Ww$Z0i_>MzXWBQsY>)8i(m=v z;-7EhwGaCfX&@{=OutjW*YdeNg>dck8$fM-3{?HM2U8eBr6KWAO6fUf2`Js1U%Uz5 zHOM|Kra|}^ZcZ|7Xb~M-9`k84h=2VKnWfQq6E~u3*Cx;>NP-}%S1Y}*1c%HsiXSob zR3dz)^rNy%g?=3mI2kpr>D6VGAcXH``%@c3y>7q$}3!nEU436k(IeK8WT- z08?Tno7qK_m?olW6UjQdVw{xh8~PwzoP|^F4`Q2`3M}GXv-Ji`+r%~WGSu|GUiV#1 zbTB>#GVs?kb05Uz`jv*zZrgH@$XWj2i!YOY60xY==`oC=&6YdtP=qI2sb=XiE--8_5#Em)mF)(XM^Ui9I_XD7pyk5E zAB*%V3s|l%5cq9dYe5oZ|C+o}CUI@}lo-v*B?U8Y($PX=cuz91Y-!!xT~KNrN6aH_ zNHKiN2-f0Zpa-QPFD_fv@l922_OMm<=N)CLIMb+}WfkRaE6a0RQP3v-zZ3rCymhy` zsy?1a)iRg(~I zuEB7=he0|h%T_rt6VdkZJPeu1^Mq_{62|0oulvGsAT$x*Hb z6MEcMy*kI5SxbE~fVoi<<=zZ0vp|!|Ikic8!_bDZPwcb{`FO}bLkr1O=m`&nk-+Q7 zkX7O!9&i)?J8koO!h@Fl9sdpW z+@b4bT-t9u^}crzla5q5YOV@*$4E0~r^cu7X`eSLFiUgA^W%p1>zSI;=aU4E28y{Q zaS+-mQ|YL-vm~r*JvyS72KX_=nd9IuL`X(M22G2W`>zGUD13uNw#D174HBjc)yc#md{Of80RgPy(|NSO|d2DR}tVC>Eh ziEr^>{OXF2trZ*-h9-`4ABu*eYN+<>hMx=u-;h7JCxUMxf?y3(mnk4Io+i@Qwk+eo z$`_5BNr|eauBAn(pv9bfHXBLj+egwNZp+aD*S2|Z7yHk$v566Y#>uj8d(M&lX=LJ_$`VZ~U+e9i8Z zB5(0R5JK^EcmcJPNEQ4jpc|KzE=2osv9rmUjtb}}!QS(y@f6hH=R&GmR-8PPAt>x` z^J=r)=8~j_S$Z@TT9EX%tu2h~K6eK~qa622+*Dx>wxC$f1~>nqIOrXCjxAXs66RmUR zb{m4e6b*&7Tj#!soJ-vy_VlNEX?9CCHm9+A$Tz2z@g?2-kk?w+j(xu^mlm}~ zk$=Do`p|tbmDmt{ZH_0V2c*wWF(K0D;M$K>N%toU$lyR?=t7=u50bnz8JCaVa9=W{ zkzsfdijx=l2I|e8rfoKdfgtC#xcV0(HZyf1Lg%c25|(PDiucETBw?f^DK_IWY<3u{OA*o&&VC+V)g!13LK%BPH}@7KT*huHtrSJKGiz= z#>y(n=HlG*ELAjn#>&Yjdy?HSO1*v#IF1Q5-zM!uzxy?So78@ zP2?=3@*7x-51;3I5zdXp6-`m=3e)bOlVc`5*8UFur{i-$^T_21 zWmor@#$QFuQQ<3VuW`RgDJCHafswNrA$pH>ZgC)v8j?l%n#1p26E8!h?W9nw@g#3; zIC6DT4B8lRS+?!aNo;;ED*GVnpB||~?ZkqC`(D}8tTK-h;IhlT|BYSGHa!=#+^U(Y2K9!SaS`Shk|OOn*z)cdeE(s!R^P&;Wk>d%jN!@r$z|d? zb*MHy@8~u&u(Iw9OT5mVLN_e$ipcT<>Wn5<1o$oyMPr}dAu1#6mAX;6&L z?7>)E>yJ%rwjYh&l{6)GXY_Jzy)b!^oDdt{$Z?uywNss^wL_#HqcYzdJtie-kcBoX zHRc!qeK4RGem3cC&myUIkpCp^Y&$HmFH?th|?&x@MR^9{!aHVC3rFylFP-Iy;Vp%{9*U*Po~ zFvy8pS{Q~&&L`m@26NUyN2b}6vlw>XyLRcJUV&>sY2iHw&{{K;Q6GzjT9zJN!sfRZxcb8+DGxW7**#OKlqE?{9Uq z->=?z9t%b&4KMG{d-`T$udE)q1QOw`2t z{y!g0O*VCoRUcA=QOME@eB8OQ@L7BKle@el*ay2D5W+GJ)*p;T?(!mNn836nx_J7O z=r3#FMfb#kjxor!@b;+MpP3p*$6X$C4d>yy+NB69cb3qC20@{+0|95UDX=BvTWA65 zSLQ}_J`ovo0fHcdjNskjj90y8;w)u~>g`1NlE@4-3Un_u2}o=La8CNt>)I8x}e)BjKFqx+rB@4)4a%AhtU;vw|3tNLDQQIrk9q4zW_kntDWh>JQ;A=cUl;U zTk>`_k7H|VYxk#$E3|)oztym@DJ7V^Cu#dqV?Fb|Cz_CQPa8t`H@bTDlvc*3%#nCI z@;+|ML(vv_hp{o)e;HaC&>BBzHPMB3V;8|u@tepeVUhpY$LGEHP!btY5x^FA_-3gP zPa!(wRmg|iTBI)ufqQRSQIZE%s^e+$()oWA?uM}&-eJ-F=?da?jVpoui@SY#>nyfK zRRV*Axrr)->pE%*;))u$Q>Kl~zyRr`)V2EzH>dbF4*`Ksvf*hh1tOlOKJOyFmwG-? zYVmM$m+7~7T^-CoGGjn!^$P57F_(}Y1`TJA)g>iX;9pu8cF`wxMl$Eh^-A?P09H3s zs;Qj8UDA2?@#Du*%?i;!W!0Bsy}dH7%b@?FCV{VI5>eaxZtd*vFORd0N!dhja=*lO z`g!uiv1o!*AIKNBhK7Js;R(Z0sad>jN>vb4%s0or;;dZ?S07kWB+x@dEn$Ttvy<(}FeLA)&wtClhMSKJ6Lf#@7TWgQt>JRVDDG&0Pl zBU7vUz_yCq>Ff8kNH1c04*EX0?^AkH#0;2&-wyYiE3vy z&oQe0Up-RU3Tls5bF0qgLWFHk<^<4`FKB<Hzi#aM zI?X=lsHtob*idFvajIJ;O&0cT?k1pwbL*6Vx#qRZq zLrpB%)1tb4U#>d*3Cd2?Et&WvEz=2=y)GmKQ&Jc`Mg~NCIR!M0J7z|{MoQiWgo{IC z2x;1Bav%Ed*MqL&1`X*f!!PpR=$7XQ2@0O-syssU;BEo{!}e+?(*Xj)0*nZ>DrID3 zy#88Mg{|-K_U&6eJv|$nKRk1~G}Nestlb^J>cJX|*a4Q1qt=~=ukRzI%h2b}ndSZK z_Z9j-`0T8#CS2bC&@QA;b1qWOX?5LKZ7GOg)@!VpE?I8&jS;s7~+Cof&lWn`qbDcI9*v)1?e^?7j*r$^8cFp4tS{J|9_I5O;j=qCB)e? zBNRd^D}=JM&R&OXGD_JiSqa%rW;Vy!JA3cz?BnkLzVG+{`2Bw8@$hh*8}Ik)^?t4A z^ZD6GwJ(JOn*{V&>9^hS;MI4j^gf@T`?S+PFl{(JU5>-;I>COsEUS)m0@vGCY`Wbp z7dbTa0lkiF2LI>G6c)2@Ur(0V_%(aXwAyaW35J=8^WU-DDEwB9%m|Y?9yQ>;=4fK_ z7r>wHi&CkHgVrK|lY?GbahVz17W7h`_}@Jfnc(J1IuO39f#?V#B>D7+*P&T>cA;PL zmJ_{!;^GIVURF!VA_Mj|Q!k>}k?%1ac?9M*KNIt`Rom_^a7_12QdwCr&>gkzGDbR! z^d@>is6Fmd3Fc1M-J@PJ*SbYYb6`oJ{QYb8;Ox*)4u4x6xorM}Q=ZBkseV8U{OTVGDXf^iZrFDk;IG6__ zSbOXo9p|cS8Rkt?0^_plUlzae$IQ$N(tm$`Q=iD}9_#k1j}fpAFd}s6y4~eAU}tZS z0l4;pBvEm3yH!*Pi6tMu{q_N4&`i$9=nsc802M7{QtyUZ>M;8JSz8`nT3QNtK7gCnW&dyE%`n7q9 z|IM2>kMnH@x1EfDSiiAmDHm4~rV9}F_vbx#CS69fB;L)ZxD!` zC8!LaMx+vda9!MB-6dq;4>n%*@b0cAb&@QwVTiQN@* zX5F;K7BBY0#}H(D$TQfRYL8u`1>$C9YweTGf-HIL>GIi+^&o!fH+^@tbcu~{R!0EtR4=rsAYZYp`9J5Ju=^`fK?<9|EXQ-X?DUR^k2VPnS8IWA=GsFG^qq-J?E-%vBYYONE zwpH>F_QUOoxCwzEHi9Ro4rDyh5|3WZ4qbH?tnm%~_Fz)my^0qCk${N)B8lZ-SL{a# zVEc;15z$_eMENdejG3VqzY96H$}X%ud_58^sW00CyZwZ?qB;(I;C$pXOg=(h^?uX} zG}(}$&s@5Q@^->I4##QX49fL>GH%>$RlI01{*eA;pnxMQ03UcRj(f=({7H|^kqvbT z!D--D_arz2k3P}|^Zj_0M|XRSn`+Vk!~<~fXne32Q@@!&BliUz7WY8Gs^N*Wj+O@K zVvo3TF$HM!%?(SVI7uGSZ0w&*mRkY=fjB@Tn!*oWn41nlh5QyN@jp*lXI+B9%msk9 ziA9XRq$k!1Ch}_~buXW?eW0AfXL>2b%YMN5lc9+tn<0V3PevfC#E?9oq`i~#2gOGF zUClA0yERO59R#QGrUG$9s=7}ONqlRct6KyPxFserU)&Kj^^xc1h;mJ=GAPlh@kPh? zUHdZ1MlkdZayS2ZKtRiF_*ICYfg~U2T;TR*&(he8OV>Af$#C8;!}p)|@x39zih6R8 z^f|*5`(fx64i}NnmmtG2!*edl@1KGg+Be6Wbp{wErCwk%v504{^vzJ+5NTJ@!qYV| zDphM97dOnWVbs<Mry`IL-N7&wu89tsG#m!%)mHRAtsBLJIKc z7XXh7OoKC@TP|2DV5Wq-SkWy+G_zjIA8*3$B{syI(bPU%ysFenUb?Unq}6KvQ0B

      P>n4 zM~ZRAD`JhW{k0BBpx$g2&swsl`R=eCqhfC@JVd_^V(WC#HoceSbQ(7^EVjFm^O(QK zurO%zO|R^o^3KEVdk!ReSI8s1dvku&sW7YkX}lhFxnS(;8hSS%dB}8i*(d2z3al|c zt^%Q)@>f5rtKES|k`b&*>=&fF_D)yZCy>`wSHFC+kq#X&Z1R&TRF7723xR{Y%S2hZ zO`-`!#fr~<1^@`6vFxBr{t0#V;4ArRmjklQN-DqYZ>?sh?0GqTktRX}UQ$I~H zYw$vaD_oe%0TdZ#a!8F`;O!CljiA#-Qa{G|nm8~a1Bff1mBny&HYwLTZ-nD=y@Dtm zU|YK&fYkx6AIQe$!?a@t4TzjsNe0I*yqYDTYMiw~eIj=SW|J7`mm_#5q$p)REgUtL zH-^$qbr2RkGJWsJvgAIciAyq?}*5oBG@$Mx88-21ZJ_|t}XxX|#X~&sd zKTbXeU*2TN-_GvIDSw)tTK5K#ES&1s|5mxprSUCDe$T-QE7GJI%zzQ>+%qRLOL34^ z9U>q|K7p~ZF;ofDwp8Tg9J8@vDutGQrtlEgjT??9sX>GQ<12a-pA@$x)n{u_I@s70 z>cDP`wEz2>zjiua+cY*gS-9>j6shj-FK74M%*@Pa7o6JX=jR~ry}i-s-~dvtrH<(8 z6%d7|Dy@q{U+37S@>%XqS4%U15Q|S%*}a8I*TsBFu|Amo$ToCY`e{KMsfTbYu%(aq ztO1Dce0|e_2VVkxhtClJEw^55c6mQwz^U4Vf+trttlX*}i1A1cpO;yeUL6wXvVF)Er z_Vu|xjmf@`bm<=`AG;}9EvVBz+zR~cV#Z(_HKL=e{5a;FQelX1(aRW(144hn@)VN? zdK9|NvZ}LEv(A=mGEp0}BFUi_FXHcFs@HB1Y0GyMFvmV@{Y>;5D?8$>m)>Gp*Uq_+ z&v`93pD1Oz|Mb`q3vsSgG?m89qhdYPpFbCSf@Uvh_ybmFtZcR~YQCoyb}vKjyM{nN z{c7a__ip1nKqF}f{QC?v7M{Vnn=f~r07U(!g7E0!TCtm^~7-7q>D_tOe_5+KNHWF2OOF8VS>&rs=Z-OLRk!@^}nXN1V z9B=ZhB?nI_1cu27J)o_sJUe4Ul;`Q zI7e+n9MNvuNhP2pK;gO4WH}2l3eIokWf3Z=q%^OVWOxk!g%h8Mp9xi?Q|WN)-#X&5Zwi6SRxp@O zLHb$kOqNs7;z#{p*8v`KcxuWUUR+=JU41(vqVlOfHoRt)O1AJSwtO7XT@hTP|!8^(RKwS@%0`QY#x*Nc@Kn=mm zWp=T|T-JDOMCZK_MA{j9yO{TIe;$V?m<0{g{`HtqB)#nho)5QbhFz_mFvWndtH_U@ z0QkCnzjYbR$-aUWf~CDOxUeO9T7Q8z65XG|_-4U@{c8faZic?n=z|FOVV*2I;$Hv5 zTozB6$y)nlW#k8Rd=Sg)SVh8VD^8~jO1i2yW~^?B8Qjs99{#Lv0man?_`lUw(Plc}EdY$heNfY0iWL_lwh#4?YBi6w>6Iqb1AB&{o08{~ZN^3xlP%@27EpDM2!15pN8c9fGEU`oi~8XallBGpYLxza+EME3#Xq{2{{+D50Lc^(SJ?nM6o4C?K-LetSY`+G z*8u>oGO$0w!xgyx;kA;$lPv>q0!wJ94a?3I1(uB-rwcg0WOIm1XlR99Hk9Rqs}W)T zQl5LZsH(Ia)nZ3%K7l@sN^u%z8meQNa6oN_GoCLi?D~`R%^03{qx$r@_mQfO+)=LO z)p5p^t;oL}x1;SiVvLt)ttCQFY$yIi>k5M@`w=6D+M(|Hi}P;JhY5!btuwv^ zq6mWkwCBKtesarM_<6OVg=yKScEM?PE0FL z6hQ8)B+sgM8%KWaG7E=>ZJmAm_z|#(URYbNgLN#cTZ+n!mF|@~nLBAZ0slB?9|th6 z0HkckX?E7Df5-V6DZ@G=u9vnG%g>#P!a0+ZzR7;e?qHPu>aB=gg^S=&);aIs)B%^J zp>_d^$3wG9v)m??{2GCrMuXhba%<<{fWD@mLX!FUJx0oN$Dz6g5oz98cC%#fD8M`u zaW&^Q3td1S$019YOjG7roa16~osZJb{~275y||DPIEo`S)z4f9+G3K+F%S|Owx0^S z_%}C)nLBxwD!SPQpuM23m@5l7D(5h!c` zY9=KY#iT8ZQc=CZIoZQtG&DA58|vUlaBoy)sgNL%B!0DVgjK3S{&ZZknALMgY`Ap+ zfo9FmCr^J!$pFulC02iP6=H-4XR#<{u~4eB2()thX`2*e%SrFf7#;I@Nb~&_+M3Er zhP3bMi!Pz?S4-*kJSA$XzBcQe5@Zyu1dD!6AKKm_kI-2`sSj(0)4w~1*kt$fy2)pf8I zN!=hlo}0X~;|Tley^{%zlow)fc8u0lt3)dYZlfyUj*JPZfogd*esab3u?!SQcBKq0QID?RN_7qe=aN*9Nn#!Se z%F{Fa@}1u^_5hGYN-!G?hBhORq`@3(2}H!(cNU>*)jVVK%~5_AECWqcW~QJ#{&Rvjf1&LkIs3au4kJNgkukkQW7dnuTuGb!+>(%1C&*G zF;tK(q(eXRY6pPN57I_A?AiMA-&$TIvcYtM!7Vg}#v}Ix3sBI56HUirAKy!EWPca{ zQfo&ANFXZ&L^Q6Tn5@%X!i)+)OZEbA8$3Wh2#U!4*kEbuTl5T4`MfS}j9X}$FyXLruzM;rb3?@JaCp%wvdzyG*nFOVaa79IOo@7P7 zw^zOwnv=(B8VY>WkGwZWE=S^=@)}0&o3Qb4m9dgP=u`D$&8af!hf!14s551|HKvTvek8^*pqRpfKlmIDsiA3PEx*y;da^@l z7jsXXVojP+@#7ONO3H<(R+1Q%YenfFG?%I!@jL}UwPW*Mp|j%Yv=`^5$_vt~jHl{9 zE%GBziW4zsxBHU3`NgJEGKyK^UHi^WhaV-GRw4|PbW-wsf4=p|29rI0)FrYWRH9){ zcW1quzVlb`C-=Nm8kfasUBHku5R7Ph#loU+DNISJcQ^PGooSj8)?ApW0({OR0tI=(Y^_t(2KN9)tZbVZnO7 zk`43R9~}DHr2-R%WYWTk*K%3x4@5sS#pOyy{r$xBhZg{=cyW^dISY$CeY9|O53rMJ ztv>_Fui8Al#@dM_@*wcMbFo#---#m0j<=Aycn?Iq!dY8zeSFhQ604y)B+`VYAmQ}_ z8jmcz4vC+p|vI1A~|h8w)P9$XyE&|DcgpF2Y2Qda7*JXhE|@-@KjwAvecg3zI}pTZv(Gz9*s#( zq+Xbqs`s)V^yjZBw_L_LO#AqMXqVE*iJ4467n-nzJDn~+QO0O z<-$}tOe6ocSZtxs)B3{VyuHN5OpW9R4}Uj>cdN4*^Y0Q8u9w%m<$sQd@bIfA$c%*d zuWRDcXy3kwvDNH;BOX%HPx{KrF#n}U*xmbKm{bGmk++92H087l&mOWWsrVVd!cq^o z9zzCMUWs0Z-wt6Dmoz6n{jyF}&-g{<_CqPcy<|2PI*7^tWvsnC^Q@XxxE{Hqd1)JN za-Y$$FC?L3s8}hdJdh+5Vp@~e{b%&k$Py%Sin-=4N3wlrYM@S~mo4+KNS)WquW=_Z z@%9}`_zWnqb3en`U8Ay@EbbYk(ffWp4}vUH+^ry>lV11A%i#C@BJ|dIi~8mp!^?5v zc_Tj2;1g|C8fS%-L=P&yblnFJplLK1PD{;{+a?hPk9sylwL4|wrD-^)3l-Q1I3UoL z-f5za2RG!sb`LUdME~DUP`!_JVdjbsIe1DQz!@<5Wq6Xjay5+I%StGax-R^l&K2u} zANMYwCS1|sXJpD|`xW2MQ*|S4D&-o-pZpA(=sZ>_5BZ-8Z7F<&A1y=%mfo2oLes0Y z_-+fO=7tiih1AiiJ<=^jP%=||BH2oLL?%D)Th)LKw-hQJ$!=FhC>4Wzi6fXMBgHyLDkep;7qae zCoPDa^LB&8;0MYgKa-tB&O&DDlsL0GqUDfR{!hABTCQ@tv|n-TKh!y#^J^$ir!k~^ zO;#0HKxt)xSS=*4N`%TRXyyxMbE+3cxEXdMTBrq6iRybRG|@#VSY6cDJ|${?A0~-E zXWnEhEsqMD_biPQyZ-8`1g#Nu>R+S?-!6sNMHf)BD$8zE^ zJ%FocC07+b0cf#d7#!66_*fIFr1&ku2>nt19z~cB}gvY8nfC#GL0YiTVZ` zmol`yq$5Tah>phZ2+Pju8}F(XuqW@lmk?RAd>j?jw3rc|^hbOW5l#`&G(!hv>H_t~3k8S2{}p8ktp6OhO`B9W;9ge=2K( z>6*QRgM+PYQE{=ao)aEq0Oor2RSbBED#^u=C4Eqj;N>B~tO)#SW_sG$4~*>B5cmKI z#%`c@HBz8G!3`$$fJ`B24yrwnIgBEGc+BRer_a$@I6p9%^YxaW(BU5+91J`Ms0KSA zge8e55rTQ)QgNMglTMeC0#G)B`r{d|)OCInQNRB=`7T(xz>{KUCn8R`QX)K4paU|S z8wlt=gxB=-+)z>TB0TBly6ZmVqv!F`W0Cb~88iYu>x-I$BQOKA7=)D2fYeDr?7(zt zYOE|W@k%4}gnJ3YM9R86(&X#dTSGN#>$P;xsjO)kJ3G6^mD?HK&C}DdvYuR~>6ueQ zDbY}G>r$Sa8ks)3*RMuW)>G82_cGkZ`r$vpRaDc_-UWXavZSRmBKky7O%S9#W71<+ zp;pesXC;x6>vxf8gw!tKx?KYj%04alDVjkDzF%*t^$J}O8=Lw7ee>T^`btyrN&CBj z$hrYp<|OxzDM1ak&x8hi-`ffbGEB^+*!MiUbCSbjDhiJv!qs`6scG$hYutV8CJJ6jS{lmxt*i29XDAzk{z!^_-eYSGYwJv@f};}?l)_vj z!@6JQcI~u=;j8TqPap7n?VEnI3A4V3=GK{*+3mWOPxgLICri-%_G(YJ@$pd`tsnka zUsTif{BZ!*NicMH}*$g_t(0k;NLsCWD;<(EHj-M&>0Q6tbEsJwO>J_l|GuHF*BkqVK(n-U}B=5 zu?zuq&{4=aDmU&nI`^gLYnXpu7Q4}Ux~S0argE3kac_O&nLm%COATDdCWX6dYD$gk zY;@5T+tpRLfcp1)4Lk`KAq?_?^>Pho31ub?>iee$Yiid8jUv!zP4nmD5?vVwLGRFO zK0?-+XA^DIB{JIxNMlk>0S?nJh06*UhiDZ`IC&p-;e4wDGG(0Rc8m8;S9p%l|Ev+P8KEWsZ z^U0ib3fko1Vn-yU>~}_k&-d8tUi;~==+{W(<1FEZGMCa3;Ig|VtfJ{~ z*%OoHJ%25&ui+C!DSdzZ(B2ae)rn^3cY1P5?mQvuO05?=sSp$YoW}3GA>PCOFE`8! zDwVcheTF|HZYvFQ*ZQH^=O&2!Jw4{$ust8m>>^uia$1`W5l8yJ|LR^#iNlPIjeLV# zEm1W-9~)oE$uq$<1tSvnU@lD<q-VC=-xgycluH=S= z%6qFPGqq0V{Z0cHE4;sP)_hIOMvJ|6eZwM#LVIVR)6?ad?!Cr~+d-17EzVa&BWIiZ zF~Abi@J%AQ>LI4R2zfsjWG4GOYI)?DfDw`U+KO^k7H8N9X?-a$0yjb~7 zLVeL86tLQ!dw~JveSLjftc+s}C;<8ul0hp5q=dtzH3bSDTSe2~Kpm|Q3LX}S)z5L~ zOCgxl0+NKybCv}`vA(hi%pB+mW7D8W_nc_A7@aK8hx#!&qqG-2x4jrHQCq!xKG`L2 zb-o+PTZ3DZNW-3gwzfk3`H22&H zj8oqui2^dt)cK;fcST;Jvi{J_ZB@QVXJ+{LUj*aJi^t0_YM-$(&mJLc@s34_YC_!a zX8zfps+z^-#T{3el-(O~ z=Hyu)N3~j9Ml+SZHXfJ%$dRSv!@Sp$Y2~;2JK3IUiqYP9(d@M8*?nx~sRCi%-500x zW&ZR?Vd#aJwX61)E#p&+PH%nr_P`=6WDs(y?N#%QvZJFr7)RW;+pr-8$Kht+AMS=K zvJhmO<8WEON#8#q-}E}DklD{jkFw2XeBR{}lfbLt=)rR&y(?@nx@>J0%kA!(Zp(&V zp2(SqD-&lvWDUBp@tV_28?}9^(q3*Qwk6ivW?=oS9b+HFKRUeYyDZAOIckmFmrW8z z^baGw92xHa?S_0D-S8l0pI)!sqZ?;Fa(QRleChCB51CBk0f80Ke?6*E-L~+sOM6Gz z{B6wjm$7+0Yt3&1Q4B`BcJHsFd;jlUmoojD+9!M18p=A!0pN7XDX#iZ-W0HTi$`x literal 200075 zcmX_IbzGD0+Xayj7%4SMKn0~?bV;L#0wP@#gwfq8gV7);Aw60eq`N`7N2j!O_xs@Y z_j&)&51TxX&+hw*bIx_{1uMUk2jPNo(a_L9uN7oe(a<}q z?w~3!g;q2`vkAO-Xey~BiH24hiFXaf1YSR~RnT%kL!%(R|AXH1{73=~?Jn!JjHH^Y z{@-Nm_{XxBoha9o^&bO&=YG0uEsXL8@+L3!r3jgdISi1wW2(oyr+VQgSjo6&2Ot!riTgIjX483`gRyo9S>^p8hvFHq8@OjiT@K4IbO2 ztVPvQ^FDW8LYEsECzp2@gFePbYyIw)@;R*mCYj>uu<@_uY{f$p#Ri9k?PT};ca zGOaP~lGwDFw;7S*FG1A&W42najr$$e`W{KmL~LCL;^Tz}$Oa1HmX(*oh8b}#s;vs% zB@6$)zBq!%E99#e`hD$Amks?>yIq9$iScTuDm61Fr?-pVhbHs9+-gSMtNfsO&Sjxc zoKnoa{PLV;)@6Mlna_LehiOkNyG|zX*x*3?z63tSqWZ%(TGh75Y^2p|lYt~Ee^qLB zh^I=`5bQHfT%exI+{fFSJs)iD)ZMu{Y=)>BhjlDuI*naBu{O+CjK$2%%)Xxw1)~gi zCt@Gdt}y?d;;~EBE;H|SrpG?n*Y{TJ>}O62Zp69U)#*+?3Ug5Ws^Ie3$z&!86j|E5 zNEw(KwmF*9J5i_u*F5-J+C^u-feh?f?g(Ao$}c8Rl}+)!+^iP#?uH>-v?nW0elw@$ z`uvHK&m*+1Kajh)SWm5p!yL=kcyBV8!tQl>tg;PkZF2U?^x1+>(t0zcFD~0Xz^{zxp6cxKZIVSQ}W3;_d zO633jQA6(;2n-qWG)=NY{8?T74Fql*F4pp&f?orwP1bX@Wu6!IR6NE(o#?w(onch= zr&Ffe+l7QWuPpIK z`a46HIj6Y#qX7}{?sP>yn_jJ2o8aAHFDL2^RU_%E4@)~$3lm%;`}2f8Jgt7{xlzkr zjOK0Uzsi0LH+p%Tu!fclZ73@j@d8-{DPD>mLJ}!1#~FAJ`%Ehd%w_JRzn8dCo3RAe zdfbQCb-x9BwU@JLtdhLoL7HBGkHFnds@Lfcar^zsnVXDR_w7P=jv0$V(W9_SSGB{1 zh^`f{v$>qupzC2Mu?Qm+xfJC~kB`~$MuA5$U+Y)4ILS}xaB2Z{`Z@WBVkF^UzGz^_ zHuo{?=iN%JeUlRi5X`C>?zcrfFo?*i$x$+J(WjdkXp3;HU;{=>pR%6AVQj3=4X8_HbDS z#3rRLK(g~RvEhRj7?cr9dJ8Au;^V`92 zaX$R33VCY?PLhu6v0~d&AT6E0jQ%Z$B8PR8GWfb$_0-3r^7^2E%D!1AIIvx8*5N0F zZmo&x39Ef&?t)L{rkS08K<9&u#^IRun)MXcb*FlD^XorNwP^3Xf4zNYCS)K^RVR1q zZB&V$lE{Q|(q+4H4Zt=Bg@ICPR<_?xH4LzUa!hTa8@BtS3qan;lONCkbsBA$=hO6N zqHNZ}tdIPOc;6y-r+*Af!DW%YBXLDh;})pjQ{mY$JtJW|(z-~!3Crv-#X<5H`+*}? zoQk|}7;wDT-Ruv ziU)@zdn5Y;{g`cJXlu~3y#<3VN8c|P*jqLGQP^!1&T_3%4ti#IAe$U+aSROYT_B*J zjMMXlQG7#NQ9$!?9T@D4C();0xwy!tcHA71?J`;n=N}O|q%aaB3T(sE2(zB28kUmI zf@217u|8GcRgEl>_s3i#H{?;|tt7OI?3xy%=y27mmN>|(ddPv#TE>O^Y zU^LaMu{vYes};+%R9>l_4?ZEelM05o%!+vyZEac^R#n#e6Dj;XohKfE*g+8(>WVtB z>tVses(RZUHb1-TV6Ob5U{;7WIR6%SV%yF)ZgzuRLv~vUDx!7?&vmY~c!joau=rc$ zwvYjx@=H{p>^E1?ABWedBk65mMTSN+ZHwBNc&G-&&XSyoGFB+Ru?+pd)Au}(H5NzY-H2U| zYn3-+)1+tNHS8qOZPRp<{q2UFO*4&*s4uDJctp_&(Px&EO#X)?Ioa$ShD7?R_4=g{ zcPf5>$&Hidm=$I-K9mI!mb3*Qc+S8nF8Hifd`}hj_2? zXRhI){YUhXo-}368`MALld@|9)WP?u0bql#X*T;mO#Y!Ic_!NBf6*iLM$J`ji@53> zj|R8T>H#HiNmgl^?!x_M!St+`N*4jBRStPf0tt`o{DjxvIcnnqq_9(10FK7PoFU8E zn^T5?5#6pMHyOSzO*&%4X1TJH|-U+*nDNzA(X zelp^ceaGxpfa0lX_|^2bgMxJ8&736bp8)S$TDXp<3M>6lA3y zxWeh~)|9$xu)S#$moMSt^d;#?1>tQ1N9G&r+WJHu>t=h;N#2Tm#1453W*ZofkTSrFF}1eHR`DLt7^f> zV<&b^jn!Ffdfz6_s{=P6_ZYseYq%@I+Z#PCme4tM_ln)ciP^mgn&rab6hznWH>4)L zqx~U4fwtH9&RWR8dOPXGRE>`Rss~i(uGZD(blv6CUKfcK{ILHR6n#44*g$@$!Mw~C z9X4jDZ|4_Rlu-fZ2DV+B2`@ANK+I6&Fi@_; z;vUB0u@SKSru+P-J8CPEidW9dk8J&AYimH`#15N(q`dk`M$yx)v7Z^CHE5RSaIen@ zLi!@RdQJ?%d89P9+fD`Q&sw5QtjoNceB<4%ht~q4g7E-;mPb z0i3v=dtAE;(7|yoN(k($CqSw4JofDhPj_avOJKg~M~11k@|UZ2od| zKG$}7SpZm8p3JqXRpjQgoK)VM!lcHN-E$ewJKu>9u9Gxyl3@?WT-65SmO^4p)Wne4 zH3PWp6)K7jc%cz?OeYGOF#I+F)kr}l2kLQk*iS`GSW#Au5*pJ94t*rsQ(^L?DEG%N zAm@%jKv~sA)_^QCwUAlQk=dnblpIPTpgJyS-3kVQ;1eLOG>znlcq+-XVMPHgNOCQ( z()QTTZ;rdOS_G34>M)9jaEtwSY&$VjWgf{|wL$CBVzK6zw>JI5UqtIr!Jup^2($cA zgh4cC@yQ^r1`V1{2$j|T*;&Yfx|=*R8$_HyYbS>_7@%VYx5K+quj_cc=}r+!0ks7( z)1jlQ#d`zeWSEtYtz%Z^Q*)S70l*mhSJfjMad*CES+kno5q)~-NE`1^AGbcUdAt4z zjYwYghKceRK8}Ao?*1iAJD$19JBEs&W#u6G%l^Seqdc5d2}v~*xc`hrul$QuCY>yh zOkIBYxMjb70f-k2KxhSj2X>IQ2FWB^ca|g^OB=n#gAM=i0?-90XbxHw2Zl4`1M?XT zhX~b$TyIWLeAeG1hDOrKJ6r$Jk$TLvc%n1zNB^3Rrt*G<75_c=H$q1)!alPp-2d!Q z*jvHxA3nx3Ffz&8`T%YNB+d#rhFF|#Gy3C2_>Oc^)-b?*fvwSmjqyBwj7QKI5T_^9*|}|8#52X#$@rrBc&cwvW54qFk1e5|DaR>$it--Zf(u`eHTQ>2taJg z)a_Iz4j7p*fPc!*t{nK`aeS?>7fp5@fc$$jK6-L~fHsC_G%Is+13{w*mtI1aEE4gn zMpjEnGYoV8qZY~vo-!k?nn7|~QI&u~^Qj12bD$AqHLL~-W-Y(FYP!RdlD$}j6Snfb zBKhJZhK4E&iQbsTBR^lcZ5b#^omF_z({y)Z^Hb}W3DG?uWJ^({nY|+g?f)7OR@8T0 z!u;LS6J0g$u1KL#vz3?cnEW-6-doeUdI_uFV?bzqLy8rUd1~(ITCML?C}(3XuT_N5 z8l_f^eb)TrX3F0pyVcUgd;mq&YMfmlw>L#rOVw>=CoYq>qo2AKAT*I5rAH>|j4D#0 z*}%$zal6@{3T}74u^JnhOp6ev0iY(ND$*`a&sk;tG=%bJAdp-*kus0TX+|~UgBOb^ z3{iS6ASp(RiSz9Pql;H+o8P!?^oPx=I@m8v0hn02K+JKO%N7ApPY6y2`~-{+p3%&S zvJmhiW|G@@xvXhSy6B(>2q0N|hx;|WrUPRjXekS`23?n1wLU-$R{=6V0V&_E?p`l} zwvBZ?NTXc$b7+~ZxwWR8d`6kr_30hWtCbWVp0z>(|5&V4^|cAc&^Emq$4IeL9I1n} zX9gK^;ZL3)wv)c^p7+?JZNEMukhr$3xx2lBKc+t|GJL>Ty_R6{CpRM^+NSYBuBh>H z%ND9^+d-!BkReqm@%qLZCt~H=VNgs!;YG?b#mb%ClNi}tvvUSb<#N$>#brRIQ3Zvy z$}{7JduXnthDk{m6Gpc%hChrD()Z6WL=N5R2P<=*++T zl93H^j!*qFkiSSv0p|m11AuPfACi^XO5~`ImoLKUj^1-$67-GqouDK+yLM);UHxGXYXaigE_x%c_qThArJg6q zL$tLf0ZRjH`%71Vo^=$R%^Bfh*`L5SDkzzVyS=E;p zzf7?iQjyYuTZFqQ7=Un6%B0MLisc^0@Bo?KbfelRcNo$wJjTB$Q>rb3 zq6DkFt)%~H5!_kxI5l#PbGK%l&Z`&1LC;L~+<$%6 zHEEnZ?)W6MgVAJEwGGgz#hKgu(ENthcJk*e-BhgCD0=C&X|BL%1qXR(OAR>i!7QC+ zD}qO^)IUMJ+72F;RPml^_ zAtgFOXJwAOE5NY#w$^ET%fc%Y_49-LDEGrBZ+c_d;a@kZiNbEW;z^U>8dvuyhEDPQ zdz96?*`?KZ6H(*tuZ%`~&gA7olN=7TxCNO~`5MJ3Zxi{I3_kJD&nq_p+JbN&wM|@2 zP9Gp4XEFJp<39YxvCltE>j`%hjNon&dT3KJQ*K7uE<@+O!EjPq)jtqq4#o|}>!0-YCnKJUW-fN@{Tf$0K*$d20;+{N4D*0BVDy3F^50*BMMDTD zO5|#UO*;-7{t$ZZpJpWEawkx-^pl-dI$ijsl-jzNE4C+kxA;mwV<^6as6m26^m6MB zk(A33xvg)CP<1U?)P&h~d@)KI5B6*Aqj>y)Vy^v?p&JhAD+*R0 z9A=ScCr)lkN(+4C1AAlWP8yqlwl9P?y8lStsB~y!lTyfyqzR{;@3)h=o>yddaHEMhYaQ0H&e z;AIokq`)f?4FE-;T%eVu}7v{mO|r^8G9e=$EY2&>dn-8CIj}f_r3y zM5b|NuS^<6#sCF)gOX5f@4e9K|-5w6L{?Jp2@TLl^O|D{L{Dw38sN9Af(=no-45R zUIEj9U~2M+2krK+@#EBB0$x;!Z#BuiwTN^e(=7B$h99@Ucu{5@cHT3S&2;b3uCF|9 zDI=1U0-^yPZYE}4Av)T%plVSy&AS?yu9{)P`b()E8gOs@-Vu4n{t-lBH2|%<9KV~c>0FXY8$Ay^|8{7FaF@SZ;>jrY; z5=O+D-0Q?2FP3Hj`4&KqWW?m)R_lZ)cOV)80VxB3I@QxgcdY&=9O1W^t{ooip)zUY%D}Ucv5cO=EzgIf1(6N3C$mjF=U>tp{~YD$UdMy6%I{XwEn=rF(~0b2J32(pS-hNJ(Sreg_@Cgr^( z35fXYc;dL>kpTH%8G-&)Kf4!0hDK)n?CGQAwp3(BHDUYrZ`n@Z`9+~f1jnK)l)$y=*N&GU%*M9C1P`SJw zJ1?_+7C#-?M>{St+BIXBpdlHt?_AJITDC7X(ZL z_eK%f>k2mvtbF*lbKb~nND~Zs-~~Q6xpc4T?hTBK`D4_WdAzat7pFs1$tR-Wy`lk` z2O-L?-r%blpGkKd>BMimn^+4$-1!BoMUe_~UvhB%IU9uh=}0IBZDUCpT>FMeA^3~Z zmu7UE{@4Tz^^H&^-+o{1>uC1D(-Y>;`>Pvqq}TK=^u^7QUYvUGE)2cTQ?_UMx${?@ z?uI>6{@x(y#mkp;*@MmkO?y*z>q>pk>K!eKoiB3mR-+>+wqzm~8g|#~4njN1np`4X z6;n!uPnlmkm7i{qgK2QXZX=o#Xf1V${S(%-6QkVQ$r5Hr9|X3tMr@869sTaXoghJ< z;c}n?ZIbF za|~3xpLYjc^nu$)F544IH#w=^+NkgCp&xudVhKU1kM{_f4tEh+oO&Urjsr?|#zqBo2tw}V( zb$NkT&2GRHTy1W}zLrC?A;Tj z8lCYmv`dkc{6%wq>8zW0{5JEtJ`W32`cyOuAhvOm>Jagp85>I#iK;3R z%6i9IT+cIGNuSvusOSBT3oEm1Qk7C-5_{Mk?$Q|3NveLKb>B#(r0Jo_gx4xsXhz)A zx8&6R7>$XWV&(!D#aGmXp`b(bZXW=>of9vTzXqg^KVj-r_N%6$f08Ds>|HZz?2qC? zotCe5l5fNZ>gw2{0^QlhzsQ)nyA_{XB6Vk=QFJp=fHux1TGjlf3{vkXV=%uUajWrl zS+8K?t)7|T!sTrmHJ2!pMqILBxj&ie;5io)PB1yqE9m^WYTiWpoogFRV z+?;zT>G;i&D)k4ai)Zo+K!MK7e{6UW%0#_)E^^!n%p4!A7}B|j`sMS5B9Q^ji!SO=~)G9n?VD*Qmfq7P?lHx4iX@TgQM z(53f-AgYm!E5K7oPXYz4vjR}k1pXBvE@!+jb(8zaX;IG}`IACGs#rFUv_?NHHOr(E z_KyHGYx`s%9xTn9{a{Ht-(;T>I!UfL;uP#j&tD7Aer#N10@M5e0` zfx3CmNM-M@)dFXeie2xw*+nY;(@XjfI;m~ODB{^<{yjpcUt1nVeEE7d02y-4O4v|= zzoZnE00L_bZIMU6mt69xgarUtWY*iYcg{LX*?Ic>Cvu8(gzM$IQUn5;r5S>G!(^Ma zdOv|255M<8*jb*1APY2kvD-f09mX|v0}0M~b9wSDTPd*z2tG!u>GCK%j_OxO82BC? z+D??0+I7xW_p<4+@Z@!<#bJSV#hX#<+Rf)e06$#?92bw`QqUvCFLP;Zo6!@zXRNBs zrU7+@B~I5qILWs4kvlCLue9=sJ?csbAoGro5}R&Mibt{(DK^LRHLMOL6xs2aMNRtmB- zG^#U80w?p2ceOJiIUEU@!<> zZsH7GhFwiW*J4jw>g{pP6SeRCi2~S2*OKR?g3CcnW7vEa6KV?$DRrfNz_=gDnWch> zrM$wz^~q9PI(<(vLiAAK1PTN6q+|p&1ePYp>wXOL;wC7Or12KmuUoizcXP1Pl^^Me zh8N^@d$A677W!M#=BNA@*&6sraK9M?uKf4B;cPx%d{O!V_4v}6PNn6KfxSa5#r>=@Uz1bkVx#5*^lD ztR*VWmSFo>1H!X(CK3w4-JGrYbva3li;zpxAD$zblOUBVuytUd06VJ(_r7{(+>D+YAD( zrVjht`g~Lt_sBRhr!)WHgeo=5E!UNd8}io`pG!6y_^-RWhc-E~zUWvQ;evus`N>hg zw1`Vu8?Jr?zw&sT42gM^4VG=O9`&Vt(s2NYR=IaagA(}$B!$`)xKgVaP5ppJML&Db zKvmz-_~WTf4f`VyyY^?c?m^-g%@HVlk-j4{&HXuBw^xKua)BL;Yx z;_o_k|EgrjZKmQie0oUjdyovSq{F@*HG1}V_k+*0Sw5)&H2@W|PQxSC^k zA1+X#T0}*CJ%{I)?(Hic0q9{rKjgdvJA1Huoc?`5D1M%Xm^(7?xp6ufhKJcpO%Z`d zfVC;U1#DU4*w;4~L+y^tbf&jzQlS2iFHk|V{69QqokVaYuJ_?!{}aF1$c^nU%R#$} z@YfY080N6Qe{Df5Dl`#pn=j!TsnndhtZ&Tlv&+J8<+Sy4A9hBBgTeT(M@E+M!(OgC zN9+q8s<#gbMla1e4957}T`hp+L_#>jh6h^di9QOI52EFL%nhmTB}6NywFRl=pvfW9 z+&3o{gsySMYXHO1dycxlJmKE}=h?~dz$YF5aZa_@L)q=$D6U4+6MhrZdkRIwH81$w zH6XeoX!GkrxCxu_OsjhMU_(#lgvm;_TsO1g@)qh`YzpO;el^~l>HvO32gqFR{04-I zk`xq_Ty$TfNS_&W$?^C_UrfHv0B-(Q6Bt6p zxqM4u1zIueBq+CHMC10uno`bw89y9r_0pE>m2j!yr;9Dnt~`M+lfI92*grx_zY(7-cp0r`UUSO}e_?u$gV5wb^$u zI+lwoj24{_0{(9CYX1j8YS-dRZKw7kPRdxvyPGrY7mNb4w$el)>#KX$Dwh?|<=tKE9|>HokYDxBK3R$T)4SGMSmx3&#nXcKZGLnjaGlG`Rj$ZW z!UC>;6_wI!eA6lQ+MwdK``d#ftLd_ju>~`1O!c0|TlPL6qBa(Gb68PS%>dskFf}Ob z;LvtCm>G*9N?IrRX`FM7?5XRZfz`_p3)o`lqg$>#Ch9@ZjoTDvbV|eP`I{FyjXxUo zclR1)B6l%ZH?ZeGwRqHJO%8aLN1czaSm{d$Sgn8cV*U}ClZWFES` zbEkgI2g-o>?+qIYD!&xWqfE94f^Z>Ro?G9RnRm*7Md zww0W*AkA`E)Idom3HI(ZeMe!=mzqx;x+hg^YL2fRGA_SjNyCX-TGDjKL$X^K!n>Aw zFrI5ZC@B3hFMqvM62kS|qBj5U@?cn2UJZFWP$ix)$%WxCJK59XQMeQmH#-TIL}21a zT3FuCYqlID%==!ic-dXpy=BZAhVI}GFne4dbp3PXc`#JdnOYjng#ye)Soa&oS?K4g z(qlmhj0KV51iH?MU@$nQ&xz}K9vIXM1QhfoiC%gdN zaWC^NODY+sEjMspmot)22W}X)3~+NO#lreAxEiKxoz&Uoxr#1FHkXet6JGrCV%y*j?C+To!a*I8qEeK%?bk9K z%rE$qImuRv=;fQ&Sg^mEkGUaWvhZNDUGD6-D&B{R-pty|RvuK~+VlHT2)J;;eCFK? zx2FPnoFr$MZ7b7J59dxj$-V|fHxf=*IigY^&X!Wr4xk`ARI{O)wQyt%MFEN~KnG<_ zxPJq{bNcp>)?|LYH$0hu?N}HHCBh#e_3;9E^gy=-R}QB`h5v+RYdpMG8Rh_niZdkE zBu(s7fQPD_bPZ+TGj8Rb(c|Bcgsj)BCY#xnljP&kZg5 z73)>$PZXTo$jAl#hX+9j(vN(7xpdqP0oQ_7S+!(Sx2jl0E&sZ?GVr)vCv%Q3>B6HA zLiT~_2qtm_n3yF#QL_X7R(~Oas;*Adp~QLw0?Dliqq<3GGsXJoKjhu@Kx~7J|p}$x&0#2EWSMq{EUwFY~!7FRp#$vJg%jE+q5u;DiGL|VW0Ke|C zdPunw-(vWAmN1OeZR!U`TkEzjv<+ca&qEJ1C23+HL570Tx5)b8_bK}tj%+c6S?)tM zgTo^2Q2Y1*tOda0Q?RD@fcsSRUSMgb(Ytq_q#^&13l~_Ug@4s3xeH|P+y>0BsHVEL zShE)VSC{O-&+rGh!v5qUhhZCrj$GNy!dZ%^2`4-v4odNzD`9bgb}OA(nV}IQ0%1Lj z5XeigCzu8lDh`TvTk4Tcmv9?H2HKqOFFlI1Vl_pWSh9`{Qrgu%CeelGS6g;@m* zlw=dvgaquzhEp4Ne`l-tdGdFtL>KOF12nmjSdS0{RcnzwgKmD8ryhx?(XPADNuk+c z+jlZ^O+f;A_&qW-vpy3Kw{-B1__NlW%fBJ#FGM}joAk_^LLw>O@;@wz8V=fs$4c$& zHu~>%mGA~)Nf*N*oS;ZFX<=evyI{OHe-*)bz1k>X$@V>B1=YD@7JIrCX8WFZKh9;X zC&%bUtk1caSCL1Z0(Sm4lIKrv@NJ`+A>efzGpO|bMRTQJTTa`cJ+VgdrVyPq6JXe7 zI#xab`GAG2N6FyaA}(`0;U{WlR7Ai6-c)w5r=R+)!EdljE})v;_o#H3K?2*Oe95zo zCBoJR0w$&*3zZAtPoj3wa}%smLR@lHGu2C&^`mRmj;pG8Kcz@;7BD+e3790!P8|3g z{_dj3mNya|ark*jsi<%Vppkev{5o*L?i~ZSNtATOEXbalpJatuBus}j$BW2DImc&% z5TkAXMTue|Ff-^8)+(P^V8Ci?Xik(U_)evDyVZSXUG*w3fE}k()6b)}v$CV3q@XJ^1R2shN_ueijt}$bK*o{jip~A}DKt z+VixtU#G1!cD>@DD~kW(h0YDH-`+)4_R*hj+!n^6XBg0pNuEJy5O~pv>oErb@R_AS zAY4S;L=kZdL$Vp9ELZVObgM9OxXF0X#3$CoXd3IqL8h1pA5L(D#PuvM*gotmrz7o; zFkHPmE0yg#VEdkEY5eokCQea1oGOpV#Yu~i^EmV-D#F7iB?8{g_iFlRH1jCa>5}_uY9tKF#z?4ITS|$Pc z5o{NNMUN$$;YVl$-vd*(?f-x9Nl9lc4Kakv1(;`e^jWn%!wmRbbSa#nsw@p}Y0jO^ zOW)2lE;<ePYs0Y~il5_p+x3I2~zq4Xz zvrPA=F#sC`XKga+g!3P7%SjRnR4cyB|kJbFkg|`bt0!oMvZ@2=oCz>bQ<=;}b9LGPKuXtxJZqRr#&^CPsFoFrA z_-%fNj^~>ay{UT$A)|Pf5DNk7C|V93g6AB+jj$k>j{g}_jdx;cd@jKXuM+Yf9inR`H0 z!SWuMs@?wGZ69>;(av&cZT`|i!>epz7)vwToO&LtBs$V?v;@A{cz^ux{Ak6~H#qf5 zB++Z}R!9SM_KFJ`6G4L!U8r!4ZfdwBA?}v*V=)}y&8?+OaHYI$_NWh zoDWO6md9>M|6#2b*I9l_n*88ns%#{;fm^dDWGLr7eX=6r^xksH01V`64c}K;&l#`w z#4J4=22QEHU5`hO8viC~%0ocFqJMsiLL6RU~Q^ab2?2JA9kxH5B)~`cp4F%PN7l zu!9Vw8{yieB^2j(E(+SoCD^L;)q6$FLa<4UHNf8 zqZC-eefDd-bj}Ybl4KCeGqx80S5mOxb|3rscmxJktQ!xByr6n?zyZIUC*PB59By1R zbKQ$Hi9O{1RBmU#3ooR9WYT|VaCpDeTNr9fXnDVK57W&x!O!2u6ZwY(W*EIWN=(1m z@Y}LC$!?-ET4?kd$Npt{wYQ8Qpv`M6y-}9VNN;f^%7&_}ewE`hqC@n;XXK=rJMKM7 zHxGua8DaUhOSF#SPp$_<_F&f$BD>0|p<7`zLaHh5TQ7bBh8FM_#c$7*#^l!@fO`1U z%J(LV9=sR7FeW;j3Hf(iMYCElo)8RCxRIy#QuAWFhIf1!I!ypXz*}eFx)CE-)fd1V zwte=h3s2Y+2S0_?VYurc(Yp4v1h2@9fm6KW-nF5lf$A?4rIV=v=^WDOw9Zqe za4QJqcMC}ONT4VY*A!?t|E+GDO8L@u;3 zpe~sIKg`r`6=p5aIBg#2g>kv9Da|wm+|}g zxCFxGR>4&N$w(QJHTNLvC3V}qG%FAAuGN=h;k|rZ8cY8p-Eu4T;q2zd!z=&&LjOmu zmlQPNtnPjNM!*dL>R`+D992RTkw-(*3aLEwU3wFb=iK^;x%&$?UGB}w1O}tHME^45|y@b$d0!t!Hbdpl6*f1Yax=%2Hj&5=2+rQ0m)5oF-+4{E0MvHUC(A{ zx=%_nc5?+TK`thfpI+XWwyl0FuCO>9U9 zUd!bUdmS!~z>lKhz3zD36;7RVuLe8uFt_lz;-B@NNXBEE#Y2Jv>}}aCH3|2rDz)lM z*;N3jGxT-i>)NI5q+kj{4$elHbRPUV29399?nfUQtDM(SzkuZ1<6pbL2+9^ckvYYc zF=t11$J_eLsLXT0uG{M&}>JBzSOIy*?ZZ)LH^n;|D~Rq5VK-+7X!U zu3hIn_Q-{)VA!{*aSHUECjR@R{d^qYC<|q4y3QqPK=~XR3bDwj=}MQw`j3IcjA4a> zV?F-I$4lpAne1nvMRp7kMc&8aJahk8N(&5T=vWk0n!E;nN)z$lU0{L`LB!l~E*u@u zQvuqdk(FzrBI^(y3KjgvhsX;_T3dn^k0@90Kb!zU0l-?qalFTB5VF#6X`27Be^;2M z?eI&+WeAtR{kEt`JA{W|$z<5K6%F3&TBI+v8Kv7;Tqw!$xrY&l_v8oA8;Xdbp_#wG zF>gCd%G0@JW<%i)bb-9myui^h00#uCgNkd`5^Om%Ldn_x08ZgCPs{xOQLD;fn6a%I zyFl0qpch*LISQym;enm)TwVMl4D?692LnC`B_Sv|Q|(~!Uf|H4XjjB!g|;k` z)NYh2c-9CxtVP$BuYTBz%_1%0F&&uYx7QlojVXUMh2J(QXQ?gF1HidTzSkg7GCcyS z7DfWPpBvY%C~5)I80EXHIQ{793Jbu;q5g;?_@6^YAI~srd3iEqN0(-z;K0SP<%W3$ zP^NID#P7lB<>uz*R$Umqgg6eBoalnrS@I|9a{c#K69lm`4C zkpecd=Z65w-G)UQMF`1>-<}(}oz1zN48D)K2D;z4g86t}7SvY|1QNIbEQ39O7n*r$ zYRbNwA#lU%8gTnXQCn9_-p>zij*PTy3p_;~vYX~eT#tw4Pn=}#Pjm=2t1hCU{FXjF z+6NrYJx(Y+=CfIcNV+<}&_2e=#s=6F#I0Sq49PyTF*E{`#U5aa$C{I5AF{@)8tQ(s z6;PDda#t=Gtxnr}6exT=Bt1UZ+dFC(4II?22YP{?Tm;Pv&iZ{n%c(NiGubu~K})G~ zzzmfCrNtF3>`^(dEklU|)OkIlTOp7=Fz8eXlfX}hQ{^JBicD$tl|P>L2HdyyWfD{+r)Df#TgLZW)n00P2!VU1{~<$s<5>Irg96w2Ji1*I#@P8r0V`eFX=-W6D+p^m|w_EQMtlrki0us=EM^#{BQ@q*5h7pLW?~V9s4Z7zOcJ=0C^jE$b%oTS*x?f`G(~eo@K$a4RMzChPWa zwRar)M=U(lT%A~Y<<%!jKDjaK&WJaYR8kmzkx@Hb!tEKjYlvPQr}pDm05<7qS6S0$ zo*UxghH>ELR8=q12`x9K8=9aM#f8b7snfQ!jpk}g$z~i3#m^EDBFusyJoN=~)djlV z7puT`TmVxyL!ywScW9Vm?#DwfI9EEu@l<;Vvp0Pc_$>11F^@JBK2w5o9(=?CbXYH< zH}8OBr0}n>#F<>}v7w=D1?h}EaKbhW=)3iYEa2zX;bH+mba7}3VgvtCAd?!YT;(rMb^a0fsXc&fv~y#gRhVaT3*D|!ZppG z4&8=9i96jDqt37>05km`PwyQ_1^@p4lRb`=aU7dl*$$48nQ*j-Lb4B)EwZ!MAsnMc zBF;G_kyVmI#<8Pt$jHbznb{*Fr4K3`I0SdCtPCaP?^cKAL%+UbFnMbS_P|y9@<`Mo{`vFI(94 zv>6}v6w;p@3^#sHyzF#cx+&i5KKL6gc6`J&ttAXx57V0r=I|d+3Tm&UY0NP0?2dXW z?oi*2rm0eQ?R{C=$d0|g3M_U@b)SLRVLEte>{B^R^-SqcFuuq^Gjt~N$Rbk7pI7BS zjpKANoa>Re$$d~1vR=SF_923^qg>Z1a`!XEHKE^GBo#TR)T@q=;chNN89~_m&`K$_ z+J^v3!gxVxoga}cwUA9ottgnBw=eU6$pm={oTbZF#wFI_f2+c*Q0UNCSq z4O%2S| z&EoPYOBzY(KU!;_PsfKBMMk43poksns89cV7E@?UGN%lTwO#cL`tAKPl#)=WjPe5! z&%~*8b*H9i@u*ZoCr+W=OL?7rX5LyWRRg~O<%4A`mO&^WqxzhgQEIH7G&lQhj6c3B z@sAa_+_$yPsvw|h-xondaA=Pb9{By@5QL|hxAcIU%xF|kV}2$@@fm=jB<$M(&qLG$ zx&OH96DfsuJvJxt&-A6Ud9OMuG`NOtVlUwB+pEPO5Sg2weC&^oD%LsR24iZi{4h+H zsxtKY_w^|iV3d#;dr*(IIBOG#2+{_%u%$eVYXJJD7tY#S1T_1bC+Tzg_C;cv-; z686XRe4`vbMOf5rM$DPa`vhb{08DfXiZ)lqVu@}}W@Ry??Cd#M?u+4nM_kK{HXI6L zW0fnkhF6U!!31V}pOW~Up<0?AZqQhxmKaWANO;_s=sY4vfjwMJ9ibq@&&uiUOF0TB z`DdhI7*@2Qs@Cd`^rPSWwmv>-+T*CQckHPc`gSmvkR%J_-24j;mCm6uTgB@cvhL|= zPs8+HN~qSlUQDx+AP=%mzn@_{l!ufz926hCe$G1ps4=4d`Hdm{G8CFp#=WWO1<%qn zI^Kyzxj$^0n(B{!zWtEi_AIVypDX4EuTB{<%%qtLNXmKfI694FC0-^pxQ%b=d6Fo3YsoMTr!zDgYO#=F!vCOmKbjYxb3j zH%=EW#cRN;*?0BfxQU3f2_#-_o_?K&x6jza>VsZkroA_xvDqDp|J7Ok}Fg$)-Dj&jGr6ZWq)&@h(Q@ z_8s%vzlX26vTE;qzhU$zv*lv=avIG#KXhw>ZL+zD_Z3-J!-Z-p7m0x-tSnN9A`#JG z2!w_Vz>)8!)M+kubP9w!M&^S$M8CX+pFY0bA3U)owVPBfH!6krjImC)nakszbIZ9z z_coQCmy$SateNdk;*@Ci%gYW(&D4i7#bqkz-blPZ9b&=yxqU4^xt$LPT?}cb^-ylM zY7f-yGsp=Mba5?wSd@5FXcJtLwLZDO9&w0~%C_9|J1N5tpQ zE^XRS*voD4r{W3AJDsLJ4N(|7vvyL-3;y>ypu7ze!ne1Fh)d#S+078T(^PX<5`6u~ zYN3yr_@UT(Yb@3mE@zQI6Q|^`_Dy~AyWS6QRpHzP#}Y&Dge=|1{Ws?{t+Gzr&KQ}t zB>@j;_V?8b$#M2o(2X0g8kd$aW0jKVaG3FD6k&t@?Svm^*PJQ1jEoVY?C6AEjzSt8|nyFb}Duxv+Mk1h* z9SC7{R{ZT`XpXH>yh}Ek2Xl|b$UlrtHg-&`LY}z&Z1Yj_3KK;MZsCw4YQIs|fZ2vZ zFaz7?&T-{&EDRdh3wW0R9u4z@S;hy?D)JEz>c`c%rw|ceg@ztpU1t3We6Q#&6pGDLWEySVMOV7ngb zsh@Gh>G$wAP&`LSg}Pjl^!kwPJ$I;m&q#gdt^>jlAcrZX^v36X5k zVKb*R7rr;eQJuCo*(uforz$_t-Z=?*;&A0c;`yn8y{->;F9IK`rTs{0%Icj4!}fl1 z8CIXVVvb%nF)9Sg=qgR_O%Il%((wfaYWo4`1a3t{(>YaIP=|dkuvx%JAgH2;*_PFe z8JOy_Hqz+VVIe1Dcd~PTQ_;)}7kV`N=R)%*2jhP|rIvw{wndeWwj`b;Ca)J< z?=``FLj^Woy%2~<6~ff?a8x%s`RZN0B}Nz8;30Nw{U%iNQ9i|nc>@7@J39ePyMaON zyC1BX&311GJY(KD@I|rG)4L|$g?`x>bJH)E7))lPSM?fY{;~XV5V!bFGY7|yydSG( zgN4DyT;amSSptQb1V7LKP=4As)&HsoGv?5t;}l8%S}u+hVuyDIG6PFPNhG+;uG$Hd z%B6MP%@YHic)`*_`p-m7!l0qdGlAfiQ~_{%HsC^WzhI`IO>WbMpVw@GUp}+U`VjU+ zAUz0O(?BWQ&wAl2{b?G;NPbsd{J4*L%zwQ`+N$&wp2!cr-NVf;EWh0-Zftj-Nq>|+ zbSWi32T6nf(8ED_v21)A90Ol*niGTpe^Ga+-1)#clNU zdF)t=P8cgbR&Tf^D&bnryj2t0t+Fuy4^oTm$tXqDrLtX#z4sL(J*@7M)y;eD2S>Z# z+^1qZcxd2mKf|{@J>qcXm#-j_zERt0N%tAki1(+7fI#P#kxV8YAV%z2fC!7qSM7j1 zbS&eB!%Z5iHRM>c)XCu&lJ4bSGr;ifax?qx_OPv@Jb^CZ{p&tQK4HP#pPxm4ov#1c zzw`D}b7`eZ0UEs;F`R_E+^%MeU=<1NW`6d(y^vnP+E$mdcgG%ZoP?JuEox01&Qjty z?|5F^-ku5nQFW&zb>oow!_i;ss_OF(Om~KrC`^<6a67Mkcj%}h%jWI)`KEg*;UfE} zbYs;^Sq?!KXF|4WoN-P7&e($Q=l!NZNJOGUBnywLX* z#h00>JKU=)SlL<1Jk!L%O9Emg@jk-pW*^easl`9js9{jMGDz{jceVO0et_eflPp%?aCyYNy z{5Io%XQArpqpUjpG7lwL1RTa6F7VrpB6Fn#t*NlKz?1{;j8_)1-xRKqzy2iI!l-iM zQC;_0wS$(zgmFjKu`>}M?%ZGHegoq&sk%B83T%ZXCm>9G3FtqntTm3e#48*H{M3UK z<$=J&a-luV6u2QbYS6TN_V@C=5$X=YHR`aS;|`yfBjfBZ_EGngyr7H?`*Q*l9jvT^ z8fFn*${L`6BKi~vrd~B@W_u12-Z2dv9S-jC9fTOsKU(C7PryzW;YG{n5IW1V2Qo*!WNKJF5PP-{YUT>`<9;3OP7Xup{f0=n3NQUvRR! zm?&G0MUB}OafN$1vbfCT=h^;rHa1<3WugSZcQQqyY^3Nq0c(?oWx!{AICfnqjK_lK^WIF#bOcoq`=+yq`?5vylK85?aD11u=LE%@B^Pn*qLhS(9 za5DuPG0*q}>aWpV2@B7y63UTYiTt{K*tYZu`h*|GZ*K&FOw5L#t=4J!HSp-c=?yMe zkEDvqjk*oI&vbKw<{uT3l17G?^t5I2PWl7xYc5$lR#)P71s zYg=6frFZpxTP&`nWjh%&{b55>0`j-v+*H`{%DpHS$Dz88jaA6*ie{>yz9y^u16FhZ z_;CCtkX(FEfNZ&wT}kGG+Pqt0d=vGqsn5-9{ly>0SGof-{YcyT2OqEIYA7Y`8=fp% zegjgXNIchMH<%oX#3x_xulE44Olu$<6&Zw(^Z5Nj7M-w)b8iL8)!OQIg*v`e$5t_xoKI`QbtwsKp||o(wHOp z&3~$4Q!xy&X6EaEQ3M^AjyD$vGm&(BLdmmpSVsqgE8FwA>i1qA{u#Tc?=|KRq|Q!2 zt;kt-z_~-4pI#*SHsxl5?TE4?; z^xWoJ)QPRKvT|%T`zmK10_w(!Kb%;LO;=3${giMXK=aW~BD5h>cRwc{jNLDwl?(*|Un3+XTo+m5Bu)4EI|b;P?|Wt&;Agqxliv?J zgwbJJM_&4B@%dRA!_qv>5EX8g{U+s%W@;86su|3r!qryAI5n#4SHF!^uJg#Bt>(l6 zqEh;~&sAu1u?ba;JxYCN9r#L<)H(GhGU!5)9f;~DslcsNWsBX=l`2y=h5X53Leox$ zb-GHXk+}`m(V?qFo}+wsky{zo-M9lSxQK9mSS9jIS|qHjWnHr0IRoU( z_NQJ@N>8AkPWL52(+?hQT1bZ6OZdj}n1ap|wa^A^6d6n1mLjPb+&;QpMyy>!Tu`;h ztw!9^ST2{jFCxtob;nW8t1FOSX_?8%#PF5Bkny{%B$AYMt$@?x(5vIE$?aELRL2L= zcwgMvpk$7o+L}wR60o)zI0lac*fK*PyMbm{b@4wU0s*!vy{pE zT63RCI#XWsm58&ru-(<#gA^si(p7!dTf*pteUscWoTmI%kaAxO%zNhH4)Cfjh*_kDFhvS>I82v^nCi<;v~h{sx9? zP#coFve}2a(ca9;#S-l}o3q0a8nPh%AO%`j>pZ@{W^ZsRsor2l9CR4JQDbQw@9*#b zE3Nv&?7fd~Lg;7Th>2h@)9)X>d@1bH{L-TbUQOrWM%a%O!1P#_K}<(f6%J<-I~Oy>8nnv^qysPvE`6~L6QfJVW;yvZzGVu zCalnCX*qI7dKQ>r6i9NAO}R(vdx*kOt-;@#9J$<|;OICbGDLl=NQ;dU@r=vZupN_@K^pQS>pyIol( z@#)k4AhZ`d_#dYx`(i88;Ab?4Gr$dx|F9ZC=|NpD`k`A97W{Z5!%ZuA9ITt|)&Jhb z94+N|dStNC)^p8OzwY+dwc)M-iUccw62PEmtJ`=L93@VUoC>RiAH5y8ot=1@{^m>2 z)h&A!Vf{dXtZG*ul-FaVML4#&Rr#R)u)c@;OZUSajrT(Tnq{Wqv;=Gnk(e|me@p&N zy{d@~`?n|4D(_#J_Ob$sjmVo~F~`u|3boX{hXpFF_wcA4Ss00&*ROgwmix4pTjRS| z=aYB7UnNSi|NQ}1V34Yy7mbDnLHbPQ{~eBIf!k*z`-`B3Ye5-J!7W4Jv47d%`Q~|7 z|Lv3=D12BuvR4l-DzYc4=E&{_cW^O{z4X+SW4mw%Byf^_-g-jsNFoqWHcTR#_G4_N z5<~%}SdRPVXfIkGF7o%Z$nLRr=;vMKOJUx~3~@>_Ca6?LCF$W|y?gDe!ALtrflvSH!FO1Uk18<$)CKGrPpxIHeD4~eYxM`Yepu^=CA&1 zyq9fEP9CKHv5^TIej$Gjn3nU^@BSvZm-qDbiiOqdUO74mnLonsYlpUK&0k&H>bNu4 zt!Mi+%aUNbU4t@Yf_zgI)&SmL`UPM>=kfkh`)%|4r|#J7a^K+K4W6<##bYFoQ&v+2 z6^3qpb%tM*bN5B3$`8g?oCy$;>ot4 zbw#0Q(AT;%WjgZRlXVAWQ!lAl?_EK8O&mq4s4v8!`mgIL_Nb&9#seb`?rkjIA7@a?Thqvi1*2-yH{3Xlm`FCy+KgTAD7QxCv15- z5;a5VjU;G0!j?iJ$LL_k-sTQPHfH(na^QZ8xM52Ldpji!;%Ggd%#)=Wr z&`I!cSb;P}mvO_lvCE)03|l~4K_Ks+RAYgF@j|3wg_$I5mmBCIU$@*uxNhqTkx2m> zMFQ!Rx@$YK4hMN$hvW*$AgtOI_(F+^Td1bC%}i^ertC{HF=!vJ3_sjNI)Gc{75zWwUe z>*pn9Jw@CgL)UKDf}19wfP&?F@mexZcI9I{y4uG83p1_qMz%C7fu@3-{clPP9`Eg> z603l#ct0gYJMgxzO;!kAxb?7f1oedH?@F}@YEa3;8gT}V-$<4k1tWYp$MB5=%2Y!C zvU9&fHgCM)pCYX*yyfzLt1nyEFer32tI{nsj+8HVe~D13=U(Zjy?yqU9%MTU$;5@cDHnUSYN4{ouXqt0v6eU4Jd?_xg+GdIC`iy&~rjq{W&&5*QeBLd`2%( z@hAj)``sT5c_QEHi?`#Q%k{)#k@sziC4=`4wq)#0dtQT>LmW z)|*Cqg_5msgXVLSS8dBnJf~Hx=6No=tTp)TtcH^3NQOr5Bt0aot@Y3-IzFQEmIF z|MrYFaci2;&|oe|>b%x*6wPz)*p*l?F<6)8^QcUB=xJ+l&`0_M`b3`Q3gw%My&?MQ zy%kKt=c(E&1M2T-yYS6-6NyLa?9W#J`aILCmu7j{j)b}hI{BS__tg!fHj$bmsNPBA*#55iIXFTtIPv#|iHf=Zh>wE7nAfS=(N<$n<&@kR78?2; zoj}Q&p||q$zmL9caf=L3%>3wyA-24J_{J$39kd*F?7FXM`)A+K= zv;{fKSq+XFAOP_}Qq$alz`ob{;t3Zkd88wg0K*{mcm((48 zb^PV|1W&dk_1uZyU%#sgZX~vzD!ToAcl%mc=z}87c+c~=V)Xi*e1-lH8_e@f>`e&W zUaF^7`!oJTWz_Vb(aQ@pP1$}JcLyF0C#8|`*b9VG|3a8@@x7wEGYtnlBchXG?a=|S z`}IWGZ84hHIn$O$NILeMT76Z%<)zui!nmmPA{bf!Lwneilm3s%&=nggoz>Fx;E1L~ z>L?aDyA+-m*Z#0V2JN7te2-OS(!qsI#(5CB<}?eHuHAv!1a{betEr8#5g(1tPv06G z9#I2Y1kRvhp(SJ7TvQt!u*XxX32X0(b`0G1lJq#wIxxavoGn8?2};w;#vpZtfStx* zHVhZnuavsY6~9rDNiZYXk+J5arfi@e@KCHXK#^12C~(#+Bvp(9u@0Jh(0OSVq84dq9;nQ34Z!nJ#PCj>ky^Z`!o3n}(>Y?3IJlwPHZCkqPcNP+&#+oK2!mEw-TgB^+F-B6PT?ibcBVU=^zEw z#}QnDSub63quj7nPK>;%^j$_fIQF>ME4Rb{nFwI84$Wp_jh#fYraJr9|3)Q(K-2;z zU-#4jSLkJ63jRWyCsyhG!j8t-^3h_M*n1iGf4>!Q7P379Nbs$H+=cr%}zxAP%wLnXo`@xKn zDs~7!z;Euu4Ou8%;F&U&czVOQIQCiG0|IK!2$;k#pK-(U2*nyn_zwW1=FOkQWUw42 zkoqNfUo40BK<@lG_`Jo%y6j}2pA~6dG61i&Umgd=#7B#Ty7zXdiMO`%s@!}6u2{en z=JQGX^BPr|`cT*B`1v&H`>0^xbM+Lnewirw$n2gOLY=HkgM! z7I=dtF?QqKD6nacO`?ZY;L>*{XQdoW=a9Wq(=Cw7#vDh!%$LnOTlQFF?f|K)JaUIV zst`pq&7!TV`n)wDGx0Sh>|qQ*`aA{IWapL1JB!aQ#?9>wH(OoOi9PD@UF~w3tP)!! z)OvFt=Z^5u@1C!?!xiNDMRpy-H}6DlRNc3IwOh6G$g#pQIF`7oJhDUof^BB>*Vv-K ze`9}rMh4z>eBV)qkCeF+Tt!Fhx&MCh9dnE^LFUNWX#tx8x3Wj1f(2i}#jkN1y>F#j_|hL`K6k0o zZ!wuR!6=yPb%&1MjG<-~@fh6z8M0MK;i-nrY_zp z5_->7qS+-E!x##AcrA}RA#|dznLjG8`G`N}(4Fx#ws~};cuU_waAVypodK%3fBh#yUujd*5vz}YbZtr14{jK}+!<2K|$B=NL+x98eSs-JQvE9F_qym zPw5%)<@RZ>+et;2U!Ph~Z$2JGE=^O!eY{8IK#Quvu#)1Y-*fL4c=A~b1e7B+5&fjI zv%mq|pjS!YP;9dj!uRN~NxJAlfdQN{7RYlj9ws0=;6Sa}losMg%+5NQ%9Eo3YRFA{XMDGUe??=w-hpxR=Cf@T{&gQlaj2D5_`TZ(Q0t1pW&@o`0 zdgaoQ<^iRksvXwA;+p|&AIHiqD{5`;Lq~g%N=^Usfk+A&JrzP*^_0< zFUl&X-j4Q%z#lzuG^+4<{en(=#E*(hXP{72{o$HFxK`;qeL?lYve{*Wx@ok)_g-LD zpDcR0mke&KW7;-;uJBzA9!Mn6AY7X!Hit(DlnjL-Ym0Gi&o>&^HOgNea383|BaK{e z1~yf&O9=*)snm_uJ~zWumE~e+^TkAik$){UW{I|Cy1|WcpeaP#{NF!~0l-CZ7Lam# zD_%G_0NW2!w*l@F?lso2F;c%XvHoSWVmWn~B(<=%`MRbvz!;#iB9tF}yz@haDH801 z5q$zZ{G$NSiNMi{R$6fb%Z^}Y_DTM*po@C`+;b$SfF zd+YaEszWx0vf}K1W1P&&0P7CXU+G-HY zn##G?br=BGaBXG1i(10Wjk_#U&2va@x&H)=VM-$Ff>xS`*;Z+&ck>yczca)PVy%Jc z&7;WC%&g&~X=*Ya-Hu_L#?dp(TZv6eV3t6MhsRDYV)&}U*%SEsXxA#Jj(tJB_W`X3 zm`V|E;`JcM*&%1qE{Acb?M|0;okA2J6m~a=#*Su61$=V%*XizW*C7C`Fe04SLgJt& z1C1t0))=Qw6@ko`HUMx<*C{vj#$l(izJR&rp?gz@nza;c%-aM2JM>zQuYB}wVt7F` zF^&O@f)~0Uf3*>o5Zaaply2;S_ zJXjDGixJYY!lW=8NyeX|U=@M(Ts9oNXP~{DdQKKw%F3H)7z|+Y`|AWcspc z6!&F>-m@K=8U~lYQ=dq&Jsf4)R|hX->q1hx(D1`en9VILZslS{?Q_<&^Gd~vU|yFe z=354GVKle17cEp;|5v5PZPWnmNFeV8GC}2klG1H^V;GkmqQ^sWE9ak(1Hv!N?c`zs zp&3$Du?Lq%o8aK^CtHru+!*V?P-@l zn#te-lpaZkkDD={o$A87!K)~_mS=Le#KGFdTFU|8J`fSaknYXVf0_Jjc~SwCnl0{Y zw>L(=y?5`nl3urSAX?pe-!tjUv9BDres_)b7daoQn?`g!9t=H}G2iz4wmdHXKA=8I zaG$Sqhp&Tp4s0E&t8g(03a2lB3hECzmLA&%)Q5JWj(t|A%vuiB@C1h)jc!@G$=u1- zmkag5;cA^-KXAiT>o*_x39A$<`XwWc!Nz(sFx4L>e6-8;QD^Exx?V~^R%I`VkvTJO%zu;=H} zEv}=-C)HBdf=X0w%-y;7sO7UZe+kQN{H|;8rLa-Q>XprF5w8gi1I{}{Ah0RBrA;zz z+nmUq+o6df)Sm1ll@5%!ja&}h6o_K4e$lYrTVL1BwPTxZQ>t52hL2jNSG)$mvt}De^6IhaBNZ)su|@@c0T2!} zs@w8BVLwQp+j=#zpnBh}1sIRE-bb|UOM%T89}-RyPj06+E-bjzAL>c*%y{;i4SUNy z;p8V=5AI_o0E$6q_h0|~{(e37r~}0_dnH_N>b32UXeM(c@O<-c{T|W1#AeEVmYKXn zoS$jv^vG{ z)YS!ISH+%k&Koys^um2pU#aRLG+_AM?Hvy{(bA!-M-s;+Cg|n0qkZGhs8K?R+G6Eh ziT8IV)#p1WC$~|18(jWH+=Nn>Q z>&(i+EZDpDdY@GWiLV7>SF}s zxi)kA2SWBB>eJ6*CFJe|&n=3XhBhO>;tVf?5(UFCe{^PQ#nQz%+(uuiGtNtUgBU{%d)P{nw-jfX7*FrkHr)6J{l!l8g!G}tlk=W6O@$VeumW2gjH*wt3TfL&@w#mQ?=0SpBnmT1-@TQ!bHd;v47Ym7hE$CS}a$bQfPU9m~8Cr2O!ZmsF=PkMaTKLP_jH_U{$3{;< z)q07+ah0ePM*xhVMbDjxxtj$f)wL(Ux0F&rX7Tcwo<2L5`4d;>sM(7 zEC(J41GlFG$yuqWRr zzjw^d+{Jlh=azlIRyO56ZB_%beT1mSr(qI=36AZ{Ko%V6o*Ec-tPGt|B=P+_uBVj=jH=;*<3Y#xMAPzvPXZR~9L$;rPH4#0|g$ zRq~&^YLbW|?EiZKfyj-XE4Bjt$M+_%<=1^5xOxT)K+QRCwv*jEN|B6I5o|M=7|p_M0+{tv_eMJEV&o5+yiHAfft{p6F76euZIPPMu8xa z4ylaeG@=F0im$yPrcc2}9PX4yJ*8verImi#3j|vQAiR>+K{t12d886147UFQCWSg> zk8n5e&a0Mclr4sqXYK<}R#(*VR=#K(kl&u_ft}a~f+@9N zjWqo^nS7C`Lvygi_;jnYUD(P;{i1*;SNh<;mOy6**hqJ2rN^F8HaGnvB=l(YHV#wx zV@FX(za3?)DDaj;U~zj4TH0H5KA?lNVFcvJxZI#ocbJHVZ^6HX&_p`E1p;t+-e?3| zoA;noqlD`yF}}@a7R8G;HaP(+qn7D$lsNHRZ+-c?_7%<8IRGNamB6)R-fMoIn3X< z+P$AOisS4J44a$k#&o|rCDOlxx#!#e(U`e=LEps_Uo8Z7LRs%E3#fWnWY|3Dnz$gK z8Bmmb$r66MlOq(cY%MQ>3BVin(CS!I?F~a7gtnBJjoU}mQ2}@X6Aa)R72m-2qkm{s z@TzPtU~zG48x-(IpY}%U=?8)orsK4Ma7`>afw;a;(e#Z{c->)5`y6VFqhPr;&#QwO zIus3u0Am+eQ>2F>|6Hs6t>CR%zcXZ;Lre?30TkO>F^}Io3dxB#2Jdt%<;OW-{Q|z?;COqtWl~L<#l+L?$cVwmr?w9 zUyEce4;bCD0*vf)rQA?-<<@)f)}0Li8=l$jTj)|YF5J9q-gWTcb#v@pFyV*3jb;M9 zJG#=q>EC}Za}*VzZV4@?w(pd|Wzs!u0Z5}I;NfPAv1Ww2<97H77K;1UQ%SB-_g8W;$o)J4+k+><2o z{0d3a+2D7gES{M4)trd7CB~A`Vz&Y9&YXPi>lI^j|AA0Q;fBq>v%!4E#?7ZY8I^2# zsZ_ZY-<%MDUK}9o``LqE1pIG)aTla6_;LtoF!R<4Nh8bPq~L^Z6aTipZ#0R6|AC_h zJet;8K^^_LrW)KFGe^G|*q^mcdaA$B0@`^+1;}ykIsa`thjd)~Z=(LT?>OanlDTZh z@{I@nX=gT>qsb=R`oS0b$cKI!f*q%bKC<8H6^z(WzwaX`Ul>=TFUHNEoFR+k5M#D+ zZ^G4S57!IRJ<4~H|974#Ckb$0AoK3g@!ljDIR@)DJ zy-F=rtx+N+ohQJkI9zH|0b#3_YpRwW;hhIrT(AgyU$WDi@_I4M{KV?pjd0guqF3Cvcbv=qe_%fx}1L%4_ zq%`7r?kcb>vzwYhuwb|z{B+e)|M?yw&*3D?izhg`82j={iF4}a-hBlzs|y(W&*q#> z1d8iknC8~4TL*-Z^HpFxw+VzfPvO=70L*gj;aZ%1cP4`XftNu|t)8;njsiT;@3>p? zY5e|`%rNBd1IlJPh;t=LS~qLf9sm%&r3(#JZta6Z8!+~*87nqqgP4uG1?$4dDjP4b z>Qqy@l?3qyEw$V>0#twby%X`&5AZ|-&iWl5v+HbU9Mcz>0k-?qmJtKy;r3v9XkhBe zV-~fLww;ZW_IhVyzgB!5E&f7Zsja#O`nLC`VCy3UO1dS{hT_e_RxksYFs+ zbOBbCgKmF<7Y69_2yL&Iz*QrvsdwjHn|$8=2H@y1+7sGvOtwnJJwf*QmRB?yI-Te1 z%Kwimv??t#?IZ>DiVIud_e3IrzG18w=R}C*#@zTk?ow7jKxunT8GA;J!L(~g*EJSj zJ+89t;IYt-M(t6KwYVpnF^R&$)zGBa-iwCrbSnUIz*%<=qded~1vW6+tTV2h%|nyKJGTU+z>Fo5F!V3SFl=T%SU zo9L`LTa{$ZyH2W4+NNyVv31@1TvS1BObBk?V?7jEcfg41*=%zhQW$Xq>$;Ty#{vuD z2POD%WDT2)#=|a_Nl9ie-o@9U!yZt}hZ1g;yf%JpQMV5l`GW@dU4;w5VhOywYRkw^ zvp#TRH?%Ur5*VAwz)bzI8i!Jc^yn~j_?j?_8-1hwc9CwbC(rgaM+yo$m}1s94$&1; z;}%Zl%pH3_qjYmm%1K)q&;5FON!i7`dRV4Av)RO# z@LuU&oY&?!O@2>iR$b3-d~a{>R){yFc=?y!VrDr1^D7FRJ>>`c^ZA42a&SElTLqSQ z0&-;Y4D+1x3ZuM3cw!6o zS)>4HM>I7JBK0ZvxT;tt-*Ef=n}9n`xU8QgTBS$5xdo>%b&(~`NeSC+ICD?Wk zSgaqIg53nFX%S=aMV=DtuP@ZE4NwWkT5I#|VjdE5ty56*x$!B#rw%mAZsm+L~63TMvi zz6(wA4p`qOB`#E;S_1aZguDKv0ey#pZS_@hb_Ry&>mF;N{x2oY=e9J!19U~m>Y!;Y zVUqFmyr0m!+s*fhyMIB;jY#$1h=7YdKRJChy8WnbCT5aRL30td8ynWPU!zdQfI{A3 zZe%*6ahg$nbLOw}b${-|Nnf^2r&B6r2|RWc(JGNz(O>@5sB66Ar7=_3OP>y_xVo;_ zJU<<_xvNibY1TXjOOm0xF`FGxt$FbnRn-jvXD+q#(A~C6gL^M)jIVAd>X6l&qIgp- zx3v2@N}U~d@q7GrL!@axmoe>x)r;2e8RX>Np4{OdDUn^hq!TS&_E}bagZ&x3^fm^H zbk-|KrB|yaV@P+xWA~!N*ZZndM}$iZb@c1b^$7wM&CEy;)1TzuGj%hcI?jQy&m`+^ z;@{@m5mz6~&HGR=d!*3m?xK+M)OwYJ9R{Q zpEiEqP7UxZd!?gkm9Scnb>^~zX?Wyr4y!?@l$RwPm{#pIS5(yMOpgXzt8?PwHI9oy zl2DQ%(K~w;ZnCYc7n0VdV?Umj*5s&aOX2f`mZ+WYbb4hs$;mDY)v;>pD4qw4l}mJ? zPE^+NA|-GqNyg~G9~&J(M4D0i(o>!g=Y0w7+;yi!^XZzp|G0QRCJ?6`M0sgXr6tn$ z6SlclX-Xz(-q}%8U!=AA;Cu6+sUGL$-bsZTXR$Jg@w>1-A^DQaJ1};dbVq+3B0=~PNUx*L=jI;E6OQE36`hM^fiq;qJHlm>au{QUl(mtNp7b)S3hwb%YE zfZH+bWEYiqfx~cqZVx^Zd7M^qg@S@)Ij8;JxT|2VI$Mzyqa?vw&2xLF^7DD47aGot z4RwxwqSuUvGHiQ}o}gPSjx(l@kG-8hb$cD5iwv#4WK(FmL#RkJ?ejYZ(R16q#!9%h zNh=G7^p({#lkA~6Icli8c8qy96%Kn_FrZdHS@Lnh*m+a67Szw+LD=TBu9z?jCYRXl>D) zIUbTKu5p7&{XG{?%!Upd5#EnNtn=4x@&r2zcT04`q=^+E1H$c7&bL!M_YFGH`P^zf zz&JJQ;4XO2ncg^EkFR{M{3>QU0L97*{Of(f?B}=SBKC-Kj*>C*juHkEmecM9$nC{j z#g#5wES^u;OKOK_1Q-+MC(G%HTO_H` zd&jMf80*|$p>cZ>goQ2J5sWV5G_~Dc%NfzuNt;Y4m186;ubRBHjQ#=_-jMZ<+r1hu zJ~jn1jBYKN4^z`nIOAcQxl`j<77_=+Y(d{6ms4S~F4kIN9xSzc(c%Sd$g!I<#;n+5 zZ9!*<-&^q83tR#j%`X{mpI>|49Y7n1XCo2PvZ(uZ7bC`a-+ImI8`~7_d-jUQgqCsp z9sPHF9=(vdQ_4L>3??0O3!!wkl z9~?1P@jT`y99gcRg7g2_0brs|kc>erOS=282A^Ikm_=DSxvh~qR=lf?*wZ#vYX!7y zgmP>766vWa7z^dglJfd(n}QBg_02M(9E<2|Xsjb7_7!ibl(vaUh01eRAvA_B$>?EQ zhz>JOT=>+bSyaqMMK`Rej>pd=3jPfZFLo&hKRQQlApY^OS;ZZbE;LU{t7xCqH(|X| z4!U@Bb$~4`j6c~fPyITHT8S4enx|7myvc1N%Dah39pmz}ewhv1X-N`&A3ZTpe|_hU(!;!x@}{Gw&pI2)qE9>ahZEe-v&ep+nwf3$ceo;Vx^u|! z*q3mRz-lceu^e9Al4JB!94wC|*MrAS;X-@&`)O!xjAkqamy8T;Vcq77qeMqYK>LFS%ATV&JnP`Gh;jDF*R7nuKwvL^rz}SN<;C zY2^(eTgu|sy%)4z+u~&Ght)#4k-RM3OWzIvwsTGjG=YraVwj`!C+leZofQrNE#L)* zy+Hih=)$E@i00-lXf!={N|WJE_t%YQv`uDyu7#mp$0FCaql4+?w33Tm$>jCIj9qfQ znMi_*81BEk3=3mq_(Mehvuo5KPex`5DnZ@(mf4NysoMs4moP}P!|Dx)G>urr|Ii=n z#$(H8iuI8YI@DGp-UjL2sg{YSBo!MqiwL5if=QUGJjO^Kzw30{L)YywZmG}Ie)ul^nA%|KE@4PND@m22l(TjcMy>s8Qj%qd8Hq|q7iD&p+8_v zwF;N)5BbKli<1-DbD;<`-97JWmJhbpKro4u2}5X78lQsob59*V+i3M;uhJUhCJDn} z36;+k8VD-5Gr7k9gg>U198-oFnA|HPG+9^0u=y}U(Y1cXXP*anzw5l6BbS5)0%XIj zjfke9H5peHV>1sJfT09Opw|&GKxjf>av0ei7@nFt(_>}`mcEggh_Rw;I-8lm%DLM< zqdw>1HFvGLpdA5vsfK!R`k++AX8Cc->-Rab*6go|7$ONnaCk&Tl^OQ z`E6X7_>}Av-ZiW$yzBt0|R|Vg#vBI6meOd10}PMm$jwyJDQOf8C}#vkUaU z^RF_9g8cra8(8t-u2b-ygO(4tojqKe@IUNubb6&VTNZ=1oc;1xZWKHZ`IB-A4W2pYCp6ht>ZCWi2dca4F{H znRP+u)?>tuj5fR*p!_}KeP(Ha8lPIT0R$3=>%bkC}9_f3|Ca* z5Mn=QIMKL;YT549HAcBR1!)7_bA(RmG}Cjx1O`w1EM;ZW{1+@k|L!B;*+#p#bw_t- z{k%|pMQ`XC`SA5|0eo}KOF=k6A|Czo?PG#(_aJ(=`04w$r@( zwJR>w+=;ufIf?@%b_ZZ`8SdQ zrj3|KP9v5y3pz4Mr-8PyCBv#*ZSZE%=RVI38N2$2TMc;Q;{xVe^6bDQkHSy3Gj^iA z!e3n1YpIc?3rg43A0vn#dok~zDsE!s>mjxP@`+^Gdw|$s35NEBW_{je`!3!WjU`O$ z$NL_*Yv*ShePGoksUcWb#Q+3>a1e!ogqgS3Z2K8=L8YH`%-bMhZKR(+Wd)kdVlG^? zECp2q1GPIn!TYmo&O8sTZF zw4oAD@uz+uXgq$1YPorcXd)9hCDg2_VoQ0UKQJlWM_q|Nch+mSqwp%oIB5bi{s#A* z2iOa~Nd>}UdSjm$IBfRmIVdGu^__&oA~3jTeU4yC z%mE&rL=fX%u9(7XPO)K213d}GyRglec{(5ki2-PVbWmUCSMvR!fCb z2j^-oz0^n3-nJH#X9ORrVOJQ+iJBU+=#7&f**XPXEWut~m8qsF`%6NPR~$dwhm-tx z{RbOE@J%e^y2c9#fAOW?A>G+Cu4rpn_La=@&0U|BrPG@Zu@0zd;8LS zT-SSN_NrJvU)35@X4iT0-nYaOheAhve4@eholH3XN7B z`Q_%uSY|>CMrDT`Cv$v$>$3mdyHE-pK3&&??M69eSsHQsP_?vH16_344EPqHV&H*~ z1~t9VDLvY7P6!G@a}N!z%w1FKJh)*~O+gu9Dd-~LL)cFEMQoAiCFJ+QgaX#rhbqa1 zdx6ON#a8XX3XIm_MJr%*R@qGp7^jcj;2G@$ZXdpx6sJx}Jh%?up10oKl=Fzeu24n| z;piG}FoeF3%0jSs^X6>}U{EMMEC>bzI>jE4u4x*yKU!%HXIc;B*+bvDb{M@vgZ3cn zuvbl6P|9jm)wQ?(UVVtSx0K)6_2$W)eQX;X^pc$mFbTE+-e~$@sBAu>LRfKBj;e!{ zTmq6vYeglc2t3z|L#@r2_}Q&KCvP)TVPSM37=)fdVc@&$3&1#*!x>_-Y8Gwp?t(;& zVkQdoyd+?i{g$+3YEW*{ycFJR=-8a>_F{0Z-c_C%4HZL96iG~8y%|gc2fxn@V9+m3 zU0a`n*@wl^Y9E;Rf3(WFhl#&(07m3}sKH&7sPg+9Gh;QJ382~26+}kUimEqw{Qf!+ zJ`Ye#pJ2Ajt_hT_hjG$>*;P|{l56c}x1EDV7{QDl72l{5G1}tqdjaMPe+=%h%mRA~ zexuAP^H?2)7jS7zV4pW#9Brn8Tl&oMe>FDJ$=3OrZ6Tba~8**1ITgsTR8ns7|ta7Ji zvLh6?5ctYz;OLiNB#F?G12Gjs_%dDxzD&G~VtLZyHzQ}+6)>&7TsYz5Fd0~%OHM_)nNBm^03BzNg0+Qr{6LIMC7gmXTdAHD zXQ@R0yHNCEJNOEOvHb5SBH|y4QSOf2QgiJbl^8{83)@L^P!$#mZLsx!*lkLTeJGB_ z+^K#?W3FkFA*5G}qOS$r8j!+_qA1id#kD7Uxj6SWlGnd;qH$1Ji_yX=kwlYn`3M;V zI}}Jf#?0nY>#~4jckU1c8hj@yfcZz&srN94j4%67sEhJt_!%VO?hXc8_qXiKYETv( zYLv_;L&OasGPH~s+njpo+UY>!cjnha4Es-uUw$lfS$6QkFV8z|_@ZpAO`G>T?qtW1i;j(rfn;!k1bIS9EkGr6 zj3H!@fcDmy2VJ;>;Yi#rsL5OaXL`pIMCaa|G@1tqtp_J#JmhA*1qs;?C2!xM6ClpP z1`PFTBsRQ%g+Th+Npc^M%Aa{P-9G~kr0sfqS`jtykFY1ppznB2LI5%SHb{QoKG%Nu z1apW~L^Ly~=U5BT@``Fb*R^~D_Kk+?ECk!hZG}hd_WF1&%{(^3(BEA7?uR&4v=7OL zui+eY5pDO6I|&|_OzpgWDLf1h**S6=Rix}g*YHwevu%%GdEN|v8Y6fd%%h833}g%?rL(1N>GDurA4CH3KG&D07~_*+A$ z&Nm%yRC;)#)YNnFt^3}axnV(5!`+#l3y&s^T%Qp|X|x9Ti(PK!e~>z_6o6o$slG@K zMa8$HVl9|-d{FvuwrWwadiE3Mw-Fk{J#taD|=p%QDU9!dt_3j#WRkZnh)PTQc5YHUD-6pqtKWsgcmf?k3m^>By<6_J)G=uYv zLxb<{uVg|c#NlC#zh0^JfJtnTHz_x?i8ZK(5ETIA9~X`pM*1Ez9oWoLd1X* zo35VV0(!oOx+Pvx9fR1fIJJBome*nG}> zfU;|4xc|~;D{~INKF8-@Vj(7axXXUWlq)93l&C-8>NjQAQ$i2^DKNw@0462br(5kE zz2^kADFEK02Rc-F&(~UZo9u7O`07`>N23NiZJBr1kh6hnsu>FZ@eSuTF6koPy^2Maq*$HO1M%~Ai&aK;yI(WbZ{sG0Un;ydWyzh|w4 zW|l~>$%OYK>=EvHt1J$weHaM8IVn=X#m8bKX9>x7hJ4_B8LjLuN;vM!9iXHA{@SgBt6S6n)O*j6fPer2$R?}-o(M~=8^`nWJ~&9Bsm?!YchfLV8$5bPN!LUMDNvpD=*4uQ0DeN`O&b%u^RnNEo-p0OhrB0 z13q&phSn=!1SugMKIEys&*bH0b&4YPj)VpR&-M0I#aIx}tEO9yomHFvaj=w%EHQ7N zH|=veV0;E+)NDQ6AyT2*oIJU%>SC&TZ&ICJ2uC_xAuXKX7v)2130{Q ziBjYOyW@LqDmZ%4ymw|Xk36zNk31GbUA7H1*`!7PUKdlb3_@d36H%aRxQqD&rKr3! zT7FN6EjxP!Qk~)%NoCf3zwG$+4ILh{#%%BtC_9J50k1Twr5}D=eU2|>Jeo^%0T=1b z{Jq|*EH7ZWJEtumB562J#Vg@6%&{ftP*11pS;b|j?S=^7>0GY+@7D01*P7I<^E3*g zH>yM1^|r6SCh=oU&zU=8^+{H%jz8V2?>rA)?+Np5wl$~xH~j6w3dQI=WfmY3hC+zx zLa?3JbD2gx6(Iy0toX5$Pgk9qINF|4P<4CtP+Rqaz}P&_cdwJo72AkzEo>#tZaOVE zuTnA9&UpyacBA(Lw!eJtM@0e@M8g3*1^5`#P-D|D7uUiwRCBMJ(9z zcs7AxY3mQwsTI1O4An)yJRm=#N<#5v>P14=!#5xe!tA}bX`1IRun0I5HPTI@6S2Nx z%8=ejb)d@Id|&X*Ac8L>q4TWr*~rf?nrmP^bb_twPJrV(#rR4&9F8Y?XT)dn3EfqO z;hh^PJZt));L6O53)x4otC2D3hBN7q0n^W8Fau~Bgzt3lztZ*)Q^G6-AkJ;`hzElj zXp_dCnU~hy%kR|=-ocHy`J9$y$SJE4dA5>y}bF zW;^N*^l3c1f>O~&uhuoZU(KBHxT<+F|1i>_7%WzO_&ctH6_nI1?TaiV)|ak~*J7^$wCNYk>nv-SIfOb;iJh8N(8vTYW{8~O-0m5FOh-@MY>;`HH_=AD+aCX_ zu&k;vO2|}l?;sWm+~O3EB*TORJQC-5pZN?g*-Rci{^PZiCJK3v4>4cRW9%CN5DSD#oRZoSWuXG+YM*w&v|i{-@K* z$IF*`NmSXM;9h4@5s4%4@E*zAL3Wi z+?+M6W5i~jaVS}_wQbCn#QJ)SN$|zITZSgNmPab9PBF?BW&uJGUz(x{!j2T0SYaTA zH~{qGeAfD$>xedSr^%ZsIV=`fsd+3gX%7w9%H2U-h94!os~pB%fci54_C$F>B2Gb> zUYrC`4dAD$VjhLF#v+n;oEZU=G0tI40GP55e8}BVnzYtKa8K5F&+$kNF7#s!Q<}q1 z0_F#$5UneK6m!X@KlUuE4PWvA9hN;eGyPS%>}xQbB{xt7KEJRGfNVV~54=(RVfa30 zqRiM3vlLjOkIq_eCDjp3K~uglK^_y@x?fZ}4h6Hl*Qtl1B&NP%&X&vUR@~s#wk+3h zbpHD~;9%PO^VuXa!z1rHooUGu8-{_N61}Z}atbry z5O#;jDH7+^@efH-xJSgY4%)VrL(~xcdnoavSe=Ym2twe8L(?6NwpzrB$2e^7JzBrf z#vEfDQ}zvl&<>|B8cJTUw6w%*%>rNIZBhu0X9)}ke20rh++g#_ZH>1|>~p1cbN|dtx!3RaYqc(YML6)S?^8 zzI^&|_nox3Fz$puY_-xeahF^oeg7pjxJuCInZ06A%*84+9hSpSVx*{@?J3($q$_dja@rv^+z zV+AYp#cOtvvh$>*VIdglh0|c?nH3c4pI`+HV)cIwVs~i@mR|U6##4|B>E^H-L^p0U zZU``f?J87Na<7r@kqFNCt40rdqd9WvODO0Y#y5%JO!3wY|96^0ls=V;Ck@ks!_5EsluJ8n&m&C@)Zu?gu17Vkimt}ZT zI`7-Sm0&XdbWfx#dLKNugy=d78jK#$9;A5x(Ent$eyf! z;Xufxw>HSsdOhC&fdkyGy7ps#R3&qneOvhrLpL4D*D8B_>w-K?R0#-;6Za#!vKO+D zl3q91r+wTT-}aB-qE@QIMRNG^cT!4bxqQ7>LTwvm{CMns$dvuA&58(`WuSo%6b`6M`()6&|fEbHp*Y)qT| zP6*!hc)gY18`xRn+9c=hMUfYzqQ$2-LsGIQW!?hg`Vzkf;)6NDZn6i(pB;EBnRpqiArvR=gB z{FN&G<9^MXb3JnZrC>~3NI~`_%cu34r%F77n(gvlf?0bEAG4^qkB;hO@U8$U4B2Fx z=T5x#*}Hzh{rVtoVdKRdiu|+aoqh7{ObjFYi4$FEIXl?Y-SV~;UiN*LTyH33ub`A= z;+RZ{UH9tj6A|v5tIRrrIJdw38!~efXC89C%-GQ`46#ZbUM6{NJ>b zv^oRTf|$xpk+Vc5_|mm-n(T=+F|4?S3;vrSMuIlun&K0u4B5kQ0?Y{0g71cj!{j`o zF_UiNTkLlK&YTP$P@X>8{GXB^F-_|*C* znNxv`zOI;RbVF=#han0^9ftJ&wPuZ~GO==VObdx11fhN8Oq0y?ataBq^s$XwgZo*k zjHsIvYE+rQ1Mi~s>!|1Ett*aShQ=|+A{}UsLEG8;?|@Xqv==k5_9lT)Dui_eC&ZQI z974wt9WMS5@{IJjN%IVX|HiS-+(Hlvx=yl(IB`4jIdc-xf`mpwgmfWsaN=4XWz-!7 zwd#VF;M_e({z$xNe3|ZyDkB{Wz9S&*U$C~;O;I6?s%no`aAz=Hp^kkf-5e?yA=cyAcK@Pf) zxHi2io8qI3Y24bYv=%q|L#NBPtos#J&$*`!Q9n{*x894LI50kR#tetgLH$-kE7~jB zdd%JSPN+m=1*6|aPG=;TLAk5-Qq8qMvF>85Rkx{GGUtXvkKE%g(4_)3QnAnAdNdho zfRl%WByc)OV8K)Lv@+sTRGN&!kZR>g8nK0B)g>idVgOLFhSE*|=U-T*RH7D3Dh-^s zbhm$-m{J;=q`V4^rW|C61S3%~7pwWNbg?UcT6!sEW&AV?Ae!w-%K^_f12yrEB<&!p zF5ZVEr!$(aN36?>(~T3A_4B}4<0J%dBK!aVW$cIJB9o5Cuw$bP!|xid@C&?*53Ihw zGTA^{JHg9ZZmZh<_=qg0pgqlB178>i<47kIs?XUB)o=M&!y}recvaQyTI?C$fnnbO zPmR@6aIrF3&Z5@%7xojuJXihidMOGE;Jxu#TlVR;lT)zR(Qw6-zcB6lqY{?8QD#AJ z3aDCgwkrGsgP-fB8D*DpKt%_U4kkF{$9$PA@SVoVVm|PuSPrE0G2Wgl^V)vG1Bub& z2sw$r=SWLXOD3Y9O3VBzHGYVRiRr^d?d!EtBVZK;`{DKU=<|<_-g4XL6=m?g0nJ56ga2|X*^uhI(Py|Kux zW^7j4zxYHDB^3DM(N5D<7BiSW{)C=8t-hUZ{Y&Q`FEwZTz{9_SNyDk7S|YuHojEUUfIVO{r3Nh;#j#~{5|^%AXYQm zdYK#Wz>HK*6cYFt@m73*^i)%V9~%rmo5TJZc~6q&I~J9v4lUp>HOjqMWN3H^aHWMC zJh&Y6&;7ou5%}50E+C_BQdAeIX;Hj1m$b8Vsb9Wd{KT9~*JnXgj43YuiaD~&UR&4~dG6!0=p1u) z38dlMXycld9IOjHly#wf$_nuVj<4YKY!)Vv#XC< z1pEKYZr$7c3H<*2C;^T>94{2RR0KjuKbAll>rD-F9sig*Stvh%XEW>iLM0%eC32QC ze<872DGMRI@SMQWGqU>Q7=N#Z0JstL@zlI|doG>D^pmzpu9JzwI?x+V7(5pwgJ{AQ z%+0wg5q=<}Jk)r*i(e%?wi~2kw0ds=cL6<3O}|BhF*dkaCvO%lDzP|};&)z0Cyflk zX{ZFhlEP{RcU&ljfbbF~eR(D+B&l0=ZI?^8Be`@))N-x)it0lR;(#yIwf^$B`)Hl; zulu;k@jiCRq8>Z87n+bjF*H6^(lnr~{MJ{&(E7?7ZSd+QbK~?Rzz|24b-#tzp_Q+f z9G$y5ABYGLnt&^5uVwaPcA0nU>M+rFV>`kUSa z>0{sbUH;LraTsuR*23FRAzMXZpoNHaZD>yQBF_Qz&_s=>qk`iC_bjjO+vizl0j(bl zFDE~3-((-?*R>KLf4%L_!Fgb<6iE!B`Q;LVkg=HZ$+Ko2BEJuNWCU{CuGKz!G1HNY zb#bbRVcLKDOa|hD6Hj~o3Rtu|eQYv=6*RlP1Fi&UZ$ieyW*RAm_{}_*M^6xlc=4-z zy!tYvnSNc74A$UjBgbga)Jt{&MAYZ$K}GI0iKz$>$fZ7rOCVohB>8JKqWGcWxF@i{hP9Pe354oTNLB1 z9#g;96yvi0;xwn|mtbqT)h9EYf?9SPY(&E0)GfDO<(MCrjnBSU+6uKm&lk#a?&91s zn{eV0u49_~C8qY~xKqsjE~?4bZddXTCGgd>PBuz~;GRV-(pm;n%zT~W=AdHqDpfB) zGPkfpH=0CnSC_L?EkC7V%~8-8v{|1-pGq-W{v5C!U4~{|%*Y*M;3w0g$(mbsTgIRH z=IkD1&iZhVH#VGen_fGb92(f1({K3PqWh_vyys=VJ>?L%-Ko@S#T`44et)nejm8`c znW^0G{+miBbgg^Ghl)w(eAxOVFVWrL#q<`a`_33=?(2)CuYnTM2Dkj*M+YW(Pz^t$ zyDsBtyfjuVo0S%29Z8x9BdJdZ^%6Jo+*|zLUd6u@C;4fJ46iNYh_ZK^b}^>h&{_>( zvi1z1UzCfgDs6GJQTYjd#J%@L`+~mzxV7=y07?DUfZmzQOEp9^StoJz)G5D)DVRf3 zkc(bAOg-zofIb{`F6u1jOJ=g}IYnZXD|%;cM1RHHA4g$NPEY6zCbYO=FXMLWo5kttw5m1wSee}i^eEYylIH&`AIb_T~P82E070#fT(QxY8 zWI4S2Pi7)k1yua90}=OVLa7Je$Ng5IL(`#VW$=f}4_Y)D_Kkx^#Eu=Hvs{Tt z^()OnC4iqpw#20vKwwJ@l6^SUgzRUuHs+IIV3H?^15|D;MzERY5d8eS%(XjQZmlOD zK8GX{D_VvcYmb)b3mQ|e#)vMw;CIC=1(-YmmsJ&fPY`P@b-Brk|KX8lQ7_=^8D*fL z1Fh)4g6$^0CKnB*EsrGo0D6HXQYmn649vUANyii7Cewv&QzWhrI%&!bf0W^Y*Ku{U6 zq0v!6v1k9Zp!{8cAu;v`XfUt9Y859cW5Hp*!RCMXZhRUc1X#9La%UkEQY(RhPo$F% zdGHY{+orpwCoL}4`OFJwxpIgppP)7{fTPUK0sH`az)-RC&O@>AAhpfkO^#>1frAjFB9eJf9weF6*)TaI^TemL@inCEdmlsc>BCJP|D zT3XTS|Ak9;y<b1K;3h4@l8xXx`%$RYI@1@-~5ln1Y23F8t`O1VJfgI-rG`Y)S zXr4B0Ay`WHhIelY?m9PW*6FS=}MD3m3jj6l;R(jCyBLn{Xwe zDWrz>i}v>QQW=~^L>$0)RBtnCuE98odW`7Eyr9}S(rTmfP%P*72nEH+QZC)_&9qq8 zIf+4dMS9P*1pMFMO5jn(QDY$n2~_zV8<%cP4BfHboB!wk0hc6{j6*krB!aTjP0idy zm+s%iYX2l6Na-+lA3|pAe33?JL-xJ+MaK_WX4Lxt{I4`3=Wg8(G|~vrFr8PN!%0@k z!uhjlKf5CTd#9W+xDPA*A=+9Yk+$8Vo`&X5WTN79$eMp70w8lSivTGPeFH*r1H1yv zjJmfnQ$vK=8;JTXy#LfA^ljj|XZB^_v-z)nLH`tN{(NZG`J0b_ zvTCKm3mI&WYI}!Xz3Kl`5(6x3yM7@-we9-$*&VBqM94CyLue-%kLdg}q`Olzd|4N> zGmJ15oHjh+#*omVkH$WqSN8JK3Y4A1{^?_zUu!e@WAJ3!yX?Dzs?Uh$beX}R7z(dRhQZbwB% zM5rDI>rGGBd4Icp_1$~y0GC!9DA*$48hktZ1XZhMuC2|JhjK*2uT}lD;2Ms@|@#V@k$a zglVQM=O3Rl_hZ8p!Rs%ZpQ-|n}#;zG2!8oh0RiM7-$V9hFO6=(l3snJ=72kxIK zQ1$l1&3|p~znpC3X^}3wo#=9x-J|mK)Mr68fUQj*c-*nd;>V>kcmo~9pF^Cgu)7X~ zo`*2MJpcWGdzRhT+a}eo>V?TpYsc06_=!o|Yidl%flrGn8cJuL_?|I_42M;c2Nyne@N7y{z zk0_!x7aFyWZayP3-#=?#%ze1pcf_$p(CQ7D+1grPr0sh!M;4?5IrgT&J%A553HqPXktu|upaZVxe1#@H@iSp z@y8my@|^Vn)_8`58I+;r-40~s))x$i=uS(k zi0jYt>O8b|(+hkmesi4o%|W6mAp&QVdOp)gc-&OLB4YDy7OtFW?rIPwX`2+@7+x=)`V2nH*mG1%eVjc!&wjct1))1uKXOfS=eUP zvt0=Mc<>JkRyqC%^>bJKmyG3fxhtM$GfNj5Arud;K9GfWW@n~l#6?D>IkE)}IzDYB zto5|6lA;e5i*kh@9{1HBcVE``iWjUEr0qk~Ig%fQT6Fh82ra|oh92_V)l!k1(8v;A zv!O4rrF{@K2Wrk`U;;Bd2TU+}o~A!}PA=)V9mCwG1fGFo(3Hs};R&OtqF<5tKX=7z z1_UO!e-w!j3rS>bPrbM@Bqa)U@8)R`8S0h)P)r$Iqkjv#oEIO4S=2Bqb4rlVMG&TN zPueNo`?x*T@YIks&eCtD#q}EZ0}@a2bI|)ac~yzBky7fm@0|uIZdkzqEa9|yZn~Uk^9f}0wNO|Veg~W7dko= zvC@Cf`TTu`OfI@g;19FBSe{Kp$4OnXgN}izCzacfqLj*s3s_O6glfbAz#C^o`qs~{ z#j!7u&2+7Q;&UJFc7-GG$woRpxx0|o;gbFsP^xeNv*?+oEgYA(i3kKqd@SPVJoE#M zy743=G@XQ;!C-wtH-v<@LoVxMzZT*50rRilszcPB``<<>#n6Q6e|I4q5COgnsnBE@0Ml2n0uwolMrq_ED9T-;0@*;5ZN&ixDBQq7xoYT9uKa;jgdlZIDt?Ydu$Y_?CgW;~4Z{ z-Ox-kKw2=To2j*@eQe&f1B|M%-rR<@(U}dH`><4cLtyKsL2ZyCab`eB2?G`Z9n~@B zP99S69SX30yh*o}!|hfZe$T07EjKgZa*MxuiMj=tBKdh_&1dgJ-S%*(RS+m5nh9Xz zr9G52&nEVN@8q%bi#w844uX^TyGu;ut)WvBv4Gb`rsoR(+K-OMg8JA&6Tktj$J0xR z17RW1K`;bfAD&+k>l1#uNy({n46g;?B~va+I`l?HKq0ZC0vtH9M-dOMdc3Qz1|8+$ zL(Um7&)H+rXjAbC|;{p(r4jJX^nn%drr7inZPnT4o{qM3qT1Q_13hL#|SZa-i)+0`pvYz)E zgv1<9IT3i{WZN@>D4dc3Oze%1E)oH?>9u0n)vlo2==O<4{^aqN9sgEdGSy3Tf6c1< z2@ALp_T%8L5gWK>)L?2@PK`U$DO1S~47n)0CSs<2I0#83f3T7kGMr+$GgC`0{_jMi ztXA9#o**gMj=o|E-8M+*2N|ZLnko#r|IRA%pxU}4Nufa>O%fJ06IyS9wZ7_%7}BSB zmOR$r0o3_>acLYO3D76jB}Dqf92P%EtDbUdee8c?sNse>PfrTR3WzvWy4WO0*zSGk zzgKEiBrfu5pjgf3%_ohlOr=)l%8}d&vMj}_kuRmZ5`sN~rqlW!d7$mN&`%W(-P%=K zwyMpXp%-;9@>>6BwQ?xAmZZ7j^PSJ!8SHPUX_8;>yt@5*lXB`IFRtMItx`^4-hJX% zTZ-7#ZZCPta2^I00>rbVhpFR4?|grZGLKVjB%p6kO(zYWuR4k=R32u&@K}ID(k}H1*55n*fd? zMV8|Be4}TyV9YJ>ghn6UoX+y9U%>>2p{(j3mFXM+lQ0eb$A@7Mi($7&^Yd{7pqrU9 zjL-O-|&W(isI5|V8mcYob(VDb+AHtTh7h?QlrRm-N$W09_^Q2 z(YfHv$Ha^wNXBjz69E)K$4|6q>I;DP;me>n|5wBOqAamlEuiy0bEn1UgTKb{RjY zqtEa&!WwyP%~S7n#Gb1=lS)%_sB57z=DU+EeqzM;(6)MH!aastz1bf#(BTw0Ho_qY z!JFJ2j(zJHqfg4cKM!!5&?N_l1a)kK$*Tu=8o78$B<^o0*Ql=gFz-6~)lubW7P79_3nGpk^s9nk zOxqnRm2ieAxwwPb;W-x|p24j~^jhu12(mrA_zWn?y&|qb4cP7Nl@->7+g`c6>?^~5 zA$f4kw891s&HF_XkFh0o;QQ~R=y+a3G)QGT2iBQA+kL!F)%jlL9OIG*1!y*?pvBU+ zJ^_VE0;N!k-ZNzfMHOcSm6ZpwiR{xp9I5(oyt8E`B9cN)WF{M3$&_v(;&qKYkLM|YPk=G{8B4-TvKDCzlT(cScL@XT-} z(w@;b(f1#OR5@}G8;#Bq#1W+YUNU_v^YhOOp%=Q2GL?u3RXj|3k&T}nPE;#Hhs&lm z73F1PQWmDIhYH+uubQ;P{qIqC4D*lAD*yQ;fRUt5cfkIo(>a%QBPeu{4UXrC>!?hL zPiNK45`{~SG1YNck(ZBMtDh=i2fLcW8cvn;;QB1u3CQ?@J42Del=Qn{YUM1*Qr?ns zgi~RYc5S+S*KyNoqUsSPcI>fYrbiu5u<>0DYkmnDK6z=>s^(n(A@<*IfA__V8O}>6G9!{C|+kUcS zQ9%E%P{XAeKP^SPCSg^}(=Jw1k~*n!xBJAbl)e$P4yrV=;HN<_L@)Yx7K>vQ)#_eN zBbGvmvHs2^<@)|4kN=%)-8cr_)&BPq$QjgD6!lcVUzwJe<#A5YHnCTSID=oQHR70; z|DLB{lvh|?W0$4y)KaHfE46yNSLN~lRg*1ZghP>JLHA`p9OyY4Xtt2cQ+wBzt$-iL zes9q_LfjV;xEG6eSd|y@rHs5)&fCDmd95+*-xHj85UN+%*YoWu=U}9P2X%TmVm}vE zrgk&&S~p#CaH`O#C!P0d75Rm7m0Q{w*VrCwuQPlCkF1HufiWZz_69S&u1k3(snoo) z#8R>H#U^;!&>hu6U+dG*b`q{`V#a&%UF@7{9@J}AsY5WSRn#w#p$o329V70Gq+vYG zRkQqc^-?OAoPSL}K{GsI|K9_I0`Vbzjs5>|_0~~Qx83)!A}HOR64I&UFo1+0QU=l? zATTIMBaI;4-Hn2jbSWh@bV?&Ibi>d{{jQPw`>c1p_g}7?iBHXSowN5odkaLr;gIt! z(po3eh|Nzex0D!VO!p9P+W+tJW9hi#TfO$|eBnQFUk@_^{TZV?T~Oja%S&Q0zv}No z40fpPBUqZWay=-Z8fM#`BE#}b<5PLdSG$xkJK^GG)1_%Ay?-UU@pD@O9uIuH5gTKT z#8{2g!Qgmw71@xT;G^FT5dY)vu?2;kf6ZW zcAGml=qIwKeu6cDj^?{oz zC&7bpJUnqpQC8ZMi>1BIbAdP?3bYc)mPsZ^&thDrRkeIFY*(Xwz#S(~1~S#hw4KKXS(Dc)fu?joCpgo5|Xrp%QLuTz;=jiEaoIXHVQ%B9- zJtZe-HRlc6-u`3hKGAgMTl=RH?{gj>)?Cy3w-X0JNZZTG6M&&2X)mB+9jlGPLbxeq zf~i;Cv0C_C(Q_SFeQd1o4-TS`{Of6!nO0h^v7@=SULV!=@fGEe*BiJ59(lZ~N_6l^ zO0YB#(oiw^mYP0MWF0Cu#pZZL9aGCudGzkpAQ;N0;H_JV9t1gp>~9)ekFY^$?D=iF z%!u7$FJ~|Ao+tG)>MQ=(3x_`0aLg$YVgf7J`moLB`Ja_wy{Hw5@eM#TaKhtul?mVtktE61 ztX67@ZBH&(h!QDAvMOAZH2im27k+!_eGp#HApUjX-n}qbw3=!&tQ3>e+yJpLs4bJV z5S6qdAS55gwCsxeJTfCU_??cpJ7M{lkWm`en1IQ+*(Qn)XOT%Xb+@x@bWv!>xK+6( z!FIt$grOtb`(aa*Su^s}Q?rw^f{)J@pWK?)XH-T*oPD1RFBzw!$GA6Negb}7`$jD1f z76{<+n0L#+ay%wBS)UqI2KT&JD2m*Krd`l!wL-@_R>f2;F z3Ff?(2(p%TibuW{+?8$(`4#i&E0>0!^#i)&kV`w6mv)PT&*Pn~KE2_m#qvWB>%SP1 z8zlcSOV_I!&r`=y(<`){8!*R~%}z*M-zsumri$Tn?ZLG-(muy8IAQv5?q|?0 zqoBwo$cki8t;f+A0IfiZ=!GBDdkuus{ z_UpatLWS6nY!CKSRhQ(VH1=`QrL)AJRW?a3oO?+Knff6UlHDr8Y1YmBxv%A-x0xD0 zF5uyC!Bkv(!)2@nuneYRy8LckJS5sz4N71W-SvVkflZSp23uNbj+7~ekRu$Ej2J2t z6eqL%o@#mWpM9P{2xzOfWt@ zwQM+8kZFSJGy8O(pM{Jj)^lLRkg>H_EPScu)}4zdIk{KZL`h1G+8#JqU8EPq1Xb=z zHy2TIsIuF}uyd$6nrh4xyo-SRuRWQ{-VeT4_y9u8oV5S8Ab?-78MCn9y^70!FZi}M z_;4Ugo1kZft0Z##K~Cs$T(u*qrr3Y|k6CA#@l+!jlZ*MJ`}^0+lNUwftZMyp%m4Pm z&-IxCR)%OSLs5yQ2Uae^v8xXlnNaNB2w-96<@Vyfk_qQ zaxb*9Z~7@Y->e{gwH4@y!)lgSQmj=?z-gxtkom-`PA3dLwTw0QQ<;rxf2Nw3^X1$3-ytVT_TF0PN_XosL01E8@BWO~M#65t?z1{;6VNW9V z7ee^LPp+K5Z==8u7wd*24a@V~ln>a<@=In1sNTP<0kG13pkV;;j+q~r`u4wzN8Pp$ zOa|K=qrHHY{r8n(1N%N91emA~gC79X(oiNb(1)C2qQN6X(hqn3h{snjV2({&H_^?4 z8HiH%v;9*-v1!z(xc`W%I8VG60GJTqXu@o(fi-i!5g1Rm&B#ZM-1z~JB2RZ7)H-L+ zEjovSLwyyQ;>g&RN%EAL%nqtj_unpYWRz9|mtcb0!(k;^kkEDDZ<$J7Z{=^&JD;YAr-oqA?M6)#(qu*E&1zDV6z}r~w z{?kC-`!Da@!w)?I8w5&r9t`ypb5#-=Ao&}SPk)wt>4sGPX{Cx|VrXJB^AQe54 z^&(uU3+M?tZQ6(w+8{tRr(;mLH`u8uF5z~J3+6!{AI=i?l$XzN71M*!2liy=k7$et zt;c|XlbvhyFwraJZNr(+Fv!LQse7(^tND59$#WTiv=^dvnlM6uTrYeQww2k;AuvLv zRr0z}0|C0pUIH-`@=`WSWu8iOLSy^(C%(ktpeU{z$e@M0f;T(jf)Y&l9;ZJoiL|WV z7F_IsC^0Km!f-*(-|F;kQ_Kf0ziYD8{#CHS(guUhVrBKLT*|~OzWupYv=u$3Jwem% zx;3C9LDkVcUxy<>@F@*j5$9a+eOq0_BkZJN6m%fE*+Y$i7Zp8eCxb^b<-QyhUslwO zlXQbBh)HjzxQUga-$h1^n?B*vWz8zL7=4i>6lcWA_WywmAY&s;m1yP%EXD=8agkkH z`@YKLsKOec3f+tfEk)l<+n*WdR)$SiPI0J@|2v>ON_Aqvpa{8pWo1mPMA4$!);KZE z9IAC2-{_XPw*M=CvGK*8B@)uhaOosBM&ze=V?B8DFhygg`ahJndN-excEg+1hgj=C5L7ek1J zzE+%3+Qxsp`P}GCM$y-JLJCS{#YWAZ+LVDl3MCGj3&(NOe z`w_DZ>lir3mAJkOd42}I8T1iFD_M%pMK+3oq%{ksJzX^xRYoeN4>wRZ=^v!sSf|KH zOev>e5RcxS>>KRtn6>aOpi)lFH1Xzc6{=u&QMWMPj=|(e7wZ0&ax`BQXc~sXkN)@J zw}=K-ruU29D0UW+b!&QnCj+i+xKBUj^F&O#LN<)Jpa6XIK4w*_&^~(}&re#5n^$CK zs;C9fCdu$+MG-1G6j7KxQ9M%DU@uzqBQ=dJ)LPTo%3ec2V25XDsS@l!in+ zV`c7-|69OWU>d!onp6IXa>2E}N@f7dKFgOhb@%D`-h+Br#u9?vVC!E9gF?x;Wr8C2 z1C?sk*|^@mUXJPbjXDJY$dl10yOd4^zj$q%w9oRqJLaBQ*u#w%{^PknZq8BN8Mb~h zSoFM$`ISy?C7wV~+%V?=uL9jD^UcF*DkNR8z%1(^xD*IO=;Hx^e#UWJAF)+2fDfjD z5TG!?1$h*hU?+&1D%&oD+E&TV7^-f8?*?sVj0}rpARZbE<4Z{-aIf%1S>~fsOdNJ+ zC5m*aIE5?0ifRMa&;U4t7ZepTVuW01e^Famj~*(R`;Y?lGt8p|_gI^#98E5@M5zhX zC5ZhVz6dnboRlAk%)Bq`0H^yXSLOz`q*mYsLh6r4L;j=}n<|S;Y5ArXeQELXDPvjG zi)y>&?lliQV57hb1%u``W7_6^DEtcL0peT#5Os%o~Kha{TWRSF|Lg za(PclA``1dr&4E*)(K`a*KKLf`yrO+Y*Df&n zLeGlB(B{%dbl2YXKj`LQB>6&cOi zpE}0zdAD>9jJ=RZ+6T|d4S^FvuIXO(BXUivtUF%&MXTjhFqQ33+La1gux_Rrmrh9t za)}D_TH{nOeRYlPQ7?(iZ;b!ic=IT|7(8uW&Hfsc$)lHqIbE<;+^!v==sN2YCy=gG z5^TM!aN%5m=@`ebc|W)eubXpYVm}eSmpi5SUt6qQ{pRsP7M`Sp^5sP{f7R}<5C8s4 zNmF5Pc*nk7W6iEzooQWQ{qJ;L9$p@J`4e~0f#aezxA&hm|96r4%_4A6ZGOd*`F~J` zB~ejLCLYy8mg^`r)X#2Gt0*B8`KJQdz(7^3C{dQJ^>63_V_`H|Zi@W*9tCzggJI+a z&5FX$1d;nmDM#MB&B&lsAOwdafOSBqi=Ujkez*c4Tox#B#?Yrr0jwC1ak0dPB$3#} zW-$8$08?2IkC0qpcJ+6>spDwB>plt&fjDhZp4Sy!?gdCGzqh3HM1~lCDZ>WV(IhA` zN$~ZfG3`Or<~t$K;(s_u4*+&{V~`ny<#pC$*n(1rolMXJiCLxmQ9S@evp|-t#k)WA zy4I-LG86=YZlZo_p-67W_TiUC8m4~hInGRXzW6o&2sxU{1D9p``+X+2ujZ2J59 zDyPVAK9Sih@cvrs_xB6qO;?W8_TV~ZgN@Xp=pia;W@N(OTk?57S}3j9!;5t_uV=4> z%+t`ff&I(C$2}Tqbd+6B7EtYF0SXE+s%aRu{$2lPhaf#Qn>U|XLTs!rg@H38?+Fm? zzzFwJPvBBl0<^AcSx5lCh^7J_tc>R$ zm?7cnklg+2>bX~8adj}-IH340%JTY9ilUB5zIi6!A7DZqQzcn22yM39v`1@2v_BWa zBlE8W&h;W59<$ov5Eu%YzNR&l^V8>>-UC1 z#wsZWh7rm$sr8FuOba-3GE|@gM!YJS=W#{G6QT*=@niBA;530gPJo~CH){27heAB3 zOwZRN2Oyh8&kYRd0|adAc0uBRmfBl@je7t%1~EN%@UTrg)cj7U`_~) z>yZSIMu;v1vNr-WA0I5FdKZ)%RpSOUn;?X#(dgn7iO9IVFb65D2BN^1DO;o(*t^IP zmCjqygBT^FwZW_`a0Cb-?CLLB1$)BxCFyNoM}iFKf=mL#5qQUsPxqOfyv{)!p6g(y zv~5}-16cs~7A z2>|)^`@jHh)EK)Y&8xvrSE)D)j;3koc*|c7THK}v@2kS;-7KAfy3-{2T;1V|GYPSv zztpnTHekk#0N+&h`Cc^y3gj6~I`L%%e_B&j_Gf!xq;sGCL zUD#BX{n;fi1y9b;S{begy=ZV>+4TZH=`&}h-fA(v0rek?O-s6Yii z(CC)<2QpeZN8sjPozGq4Q|LRqIJ`@wB1iZwK%@it>$49?x)4mY>*f&Po!Hg=Q1^h= zrunw5I}qB<1~N5`8@RPwDWDS-qvQZ%t4#N7|A3Y!JCJE1P_oA^weCmJx`!x0z%#-e z3Bs9!e{Ju7m9}x@!C(+o+yO`ZUZYOFbUMSxm zEKjGlGQK(b?99H5s1#D4wfhf=Gl~fN(j~-kL1lpp>P7$0ckzO=`k33c?5ZXHk3|Vd z4G`v8&C(WNR!v6_jHI9}(W`rC4KU|mMt0S}ve5V(o~qAf_%i?9In>FCKIDRE1OoAW z&hwWqi5m~U^1Xil`}Wjx@oEWN0eflGGZ6gbiar?~o=hgP;0#0KD}q$&Rr91c{r5LO zE8^o3cgLC)Tpg~DDotG_JC`0HZIA%$Fm8ztO`qw!OafvTzci;Q z4)^W%h9N!Ao4~*#4-akxJ4hYpR3W?T%^+s?Hnc>mjLCr35}QBj-axXI?3PfMxkoLa z(^`NHU|Mc!7}lyi(7vNO2n)a!)PX0R%o@8aJC=+|*;tN!q`V-~D#T2=CEkdRSi&TRLTc zK41M_%N|Hb6!#bU%4xlo{Qf%@YJE?hI(3g~=sQ%s0LV84&HHSQG9)5Wf-{k0$r+bh<`(ZpK4qDOPxdA~ z8cAJ10$|4XU-<>f1#sov%f5m0Mo34JYCL$#`AR>f1Ul?Q)na)$WsE9bH?#6ksGPO? zB8?ESU}nyOqQ$&>}FxfvVukdiM`U z)HJ6UcA_e+=Ok6Tv#hE;RPIAjnN!KwL+>Zv6&AOw4dsla79e;8K(u4T`3xAH*#nGL zz}4kB{NYpsNU1cr01pfvO3?M_X%`7#V5wE>?k>{4Kng7HOQQN z(!xiYW*CAvr`pi@qxZ^xjrIww?3K^9Ut_>C4j$8u!Ci^u>0$;F`avP(S(Y=q|xT>&w%z@&-C|eI^FS=QSx2`Jzdo3$S&VxcrB!s;Ypq`VzS|1 zzXNJSC40O1GOV4iLtTzLGh)DL%?lINT7X{Wc$+5RmY9Zi;(T_vA3mPi+XQ_lEKtR( zi2_@~mZqzt60K@hSb%1nfZ|>2Sk-b?{?rrTaoMrm2tqVv05xMAfQLz)#?tBm0L*t= zZD1{$E(L{Jn_cF?HK@hO#1+E_w9V7V0PI??C2xLykZ}zK__VVFqwWjf?Sk$|- zMR+{_72Aga;H<=evW0`Y_YXyQ9_H+Y7+x^#@WDTs07MerVfQ!_4BRMmVLaME#a6be?VumHKv+ z`<64|)8t=lQw>s!o?v=;Z7c79-vD0#ePS(`xN5pi%N@hjEOQnm_oqp+jC#NYb1-wz zh&O0(9ep}jOKpBS_;QrHpWDH+cj*GGyyUaM=2Wm|g@j`*wSxW&#H#)gPWCaXH52XG z+nPgJ5k51(KKB(xywFA^igpyirPPz4)qpL|Z7$WrBH>MX>v(56}^a*+T#%=e1U@+JKsg9Ak zoNpv(2>|YX7y1aNRS(mWQA^VaGg5Fh_?XZUitYV)&}AHbYQ@ zXC8;nu!~vN|AB_TDBu?CrF@nfEHDHrfip`(&$ya&&}^siwBkM#Gr1uko~#lKZON4g zaRoO^h>rbw_$gDMiv@@ImUBROMLrRRm4QV~{Vm1Ja{9RLVvdOCO!38e(Dxck?{FZb zkZ0l}r4Y&vl$p`6dY{-rAoISgxn34C)DMy+;}ici*QcXVpdKFjr1~eTo^3lBqH;vF z=VMDCuR(T$m;CCt{$kFFovmYmnT}Fz)UeG;1P5B1TpFrb&&81ajQie}7UU`p)<>D? zZvQ~cyi4oe6i|-aIlDGY|MQbY`PjSZ7gc!6uJ>&LtS(Fbyfm@NspyKeG$XOJP;m!!Sc6c zfyNtSC%<88+x0y8xuy*)<{0~Ua5pPr*ylTFtV5@tu!WDqFLPuJ0{ooHrvoy{l9xLp zlgKLRoF*7O)dpG`zM|GBTe~*YQ{IJ&D|8R&Z%~1liyPhZ)@2|lj?5HrHxEEgtZdoP zZ7wfl5)xzSvy&1FLY3mpeUzLs#PGKs8QeE;aQrPdNZG=@Byp#;*fIq@?A#@_hZ{t* zMo`Fs+X<9SL6KyDM{Vm0rbEj3d=)fxqMH65Uu>1=`#2zj&VWS7<*BR6ypfI6XRet7 zR&DTUiAMgJrV%79y$wHPWE58w6tqT5=>`$DhJ0Kwn;xDTIkm9u{4NQF4O>Z`O=egx z_0s9ZkZ&%a;pRnB)q`v>6qN0sN~WC zgcs-4HjycaNlYCTczsXvT-k9zMxjSps{8#y)Wn)W3A*?^{SK{8$ z*$svIt_~~lso2{M5ZPH5vf9*BE>zr?QPwMqk-)~HMg!~bRV>CX`HR~1+?3%|+M=Eh z;sz2flUWvH)_xI2ifw!$Z7)ewC#<8$1UKx|_{D$sSO;Z2Wj(~C5Hz=E=7SMaatRBE zDIS))Xq>Lilpp;L-&a(c7bd^_dlW)4i(3)XUI-3?ey5e1U&fCacd~D8mz~ zG^SacSH&&{J+3fJjI=+XD51&QW`5XK_!*%*1r!!QN$i(uu@6$%e2x(LuSG`bCg7;` z)mHpSdF(GH^?X>Vm-4eWf2FJtRg-JsU2r`BZyl<87Ek1X069p$HcP4IB7%`os1U6dqPv**hM=&paxU4GE3p)&@p zgRsa;=^hEKG@&51*Z%C=oTko_r^C8<~4xmdltX+4_Dg=ga3NfXof6 z8%;RTTfbon-D#*lo_db}cGiKmI0T#{lXvLY&@@K{lA$hksrOqv7m-u=R1+WlBPPwE zAN<+@`3g2Lph@yuU9YWK6-}XjF_^dvd!k^Z@rnQYDQV5}MN(YJ!wn`Fv811lnF&sE z=d6frqw{^3AFCe#V$LG5bw0erTws=dIfEUEx9no1@hz|ruiZ+wn^|>DGzASn1Qll$ zQ(p+R8E;4D^PWvUutHRe4d=Lf#;6da zq7iD@xDfb4qgh=uT`vo|tkfHbqDoW+z75M(F!?gd#OlU;n}j$~>6$Gj$_?FoFll9h znb@;7mdBIhI*PIC0ncT=L2203Q(bT9i?U7vF`e7xx$bQ}xn#Wh_59p=kxEK4<&MRs z2Ppa>k8;VMHt%B>PMC~~F)@8xFx16#DUMH%aK}PK;E+m!i~H%OX#%4ak1py!fjkbf zq-6^fgpqQ}7Tj#=LFO8b_h*hfPHj9k%Z!@jTU+L_OpTD)*aOPhY!%y6?l-3=Cf(yc z|7cTN(Y;)k%%oW&}gr!1LgxM|{cbW&iwzi&skW=a52pekbySb>S8f1vE zGMkz4rR!O=U)I$$Nz1ksT*0U(Zh&A>Y1L1EhdS2zT}5j)S~ifLx!Bx52E&Z-8Eyq- z*-&EoWfH?g-;+jhjx7x@n}sAEOr>rLf3l$FV!a>iy=v(1UaqI^c~N-L|BXnY+k7Wh zWi+i}VD;-BB~N`#gtcXq6u>tHYee^Mx8q^WRWIaZk~fyU9zCfM77^uR@H{n2*7HM@c3S>;i1^~8jLp~B9>BYxV zPGb?H=y)-E?EMV9BDi8wxEbo?#~yEBTCq!WbDqW%8_@%@T`mo+-4B99i#Z9V4gT;c zXT-TBF!xL&dWsU{QHROR>TL53M8zi;WCD-L zEFcR9s&odIq77#-OH<#$a5*!9O9v55=Q__Ca`ZE4Ir|ffSWFQj`vdHug*{J6!vPk; z58}=#4K>3741GHEig)MK)v;{8wTR}9T(T!d?b@PA(KBnzQ-b}n(JJqfl1GTa zrq5B zeB2Ke%XND6X8z#JJt?U~x^NcNmo{M+@!eYVE9Gtc#(lc*um?qq<^o&Eo!T__^f{kQ zq~p3-UvhiN<2%!5K%N4xMUUUk5Vq2}U=nKi#&`b!!&0)r`Uz!3poz3wWe%4!G!TX4 zJCh&#IiZm572iG3=)#?}`RGgmYG_QSFX#?9ks+>?iBdZ43Dw5zBH`((_Y~733E#a< zx{wu`bCx*}w>2cT#sr)Sv=88R1gPevMZ=r+qI1?C<(+No^Wm`dr^W5+(OJ zo;14>e@y53F_7w7ajJ!cc#GsRWj^t6ds<}Y-Zk4_&iR^l>kN+o;APP^hjtG4N-k-$ z_x_czBJ{AuI_2*LJ~{=ATVeWQ2c)AMvY#?5gopM3mx@PYBVO@8d^{FweqE<6B8rmO zVNO$$tjO~9`dbgOt4=&*vorO_T`g15?S3-{-ItTrCH3^^`PAmt!^0&|v8}lD`-7D< zn{2?XqKxp{dj{M(Yxi&6x;|8tlU85r{G_%Zo2Qz#z;?dQ{o9rfaDB+`;B84@Wv!&nr_M8KXCV}t-X$7OKJ0ND`MJTi06e~pHm`qjT z==X&f$pvy!Ozyj;0l09@N3>_57dAiv@OcM*-MQg(0TPY^EHZ4bGh(39k|_ehc_Mp%0V^gUDcx{ zXr)7ZjvOluXFrz0;IsZ+x^OS|x2K4z%a(LlVBXR5JQDV0H#R z&OXljUT9b^IbEly*DrN_L5T*x8$tTQ_$Q8cAPRMHDT#RQC5a=;T`8T1eUarj+V|RB zBav|R9)ml7$NK#(YdN~**P8ldvN&kpP5SmNrOvw=7xllHco$`sHKo1}_lB766Vdx3 zL4-|U6P{;lM+T?iz7!L2E^?oqto5?`GM)HEJy z;_8YP>&ojLg|zGp2#&zMwTeH0vJ^iXx+DL#Xmyn|H#$?%(o(M_=i*Ee;%dSbO_J&x zi&UmYzE&dlT@FF6*!jp)^-Ncj=HV8q5aN3JqO|ifcOx^A_d1=vH}7cz6nT-Kz~@^Q zo|4AkX%@D=)sVo3np+DNTalA>K)8WV^It+ie|j7&>doQjq?!oKg;X*7eE=mFd^af0 zEW_Wx9>X}MXUH(s61nzmg+~J0j-wwqUZ+HyIzM2 zlU&~hrVrBcRE;pg76bM$+X4~N`&3N4=$bp)14&sg>Ny^-)dk4XI9Prvoquf)6@=WX z{Az-J!Mo&g`ov7}Z3<#~Zkv|*R8N2S*$zbyn}gnmQIDBQ32t#t zkh=)bx?SnsmnI4PT;EvGeBR1@+t-i+=Yo%j&bQfBqj^`BPE!2=jP_1Ao^fKsZYTdd z*n?wo?I=>5e_B?w4W|RvJ=WycRktjcg8LwAk;R8)L;kr^x8{;PL#;$>?E)JT9ge7NWeC3BLaQeo~C)N9jy@e3240j9 z^7x!b3$p}!3Yu&^8Bb)xClw#zl9kar8tVxiC{R#G`=XLUK=k;!0aX@6zB<5&MTt2rw}s3Q~>4=G_ZqdBNqV>`Ym#A4&pN z0MvKQGR9e8xP6GP*!6Vs5C^G{xpe>42e7ftH`-SwdWREpD8&iU4TVB5eV-b? z-RypY-;+9P(9@{Rg0y}W zn<{*VqOF>FNutf+jL-d%=MI>ZX|+2dgLP(4VzY1^SuXO448z&z7^h{#9W;KJx9(vW z7YCtXqHR{U+Wdf!JG>>vhp2vM;+ctgOIL*Rn=x_)?bBseMJB$i@Q;KR3}03iAW?|n z5}kDz^s&msb1ZLWXy7cGu&pOTm+PRH4JU%f9favCm-?k2i&3!4e#8AN03l&gzl-pNJ~ZivQY;cPsbR3tY?gS^UQ3 z&Wk2m;w-1PRQe~GJJt^eduma1{o)hUh_`-gOKWNfIWO|d_Uod;w==wV?D1HHvUBx_oAnfU%l7^andjFhQ@obV>jHS-BnDg z`T7%NhL;ePJk!V^1Fg6wGk4slPnPosL!rgaGGq&$YcHomnT}K#vFC$vs{*oPz{9bVu;|fbVVET-SupmlU)AD8t zGsPI}c;HZ(Ax4?iJ2LA z_-PxJx0p5vE?ZC~@l@DWea`={LB@~}3<^ibsxV0AsX-QL-)6R2)EQs7RWXUyglLg`~xAV_MD);!f>|NL0{8@Hc<1WGxi=-C;CPg{~7 ziAgq6l=Ju2+%X*?flv407zw8-N;pd}cXDWxS?!k%?#u6PLjtnqYk zEzu%mHRUjqb#IHdWMp9!+}F0&ym}(pfhSl73GG|*$6-g9^lQI2-9IgBMbN9ayDcNs z(>;a{W>R4>Mcr&12Hc4HsYyeXZHV@#B z2?nNA6Ggbz`WWk%WvrnH>E{h{iI=|x7P2%XT3bICqajQsnspgIxjHw$d7^edk(OY# zFz?vqDr`K;_QGW`IM;x}RaKF12m?Lo=wJo6fj0S`IuZLDhAJuG>|kC$A$`jc+1$EA ztn$R*0jAu6rcXh*7CG7-9W7d&1TY@S#RA8S6hQ1^Rr+#Ty%G0TS!# zE`8BZR)a@h|5~ychnQ!NKSORQkIBkn{${N3A|{rZorHTbh1c_Vi#V?dy(CB1EBT7H zT_J~m$m)_MlD3A2XL+J3zD+s~M_&Hf^`tQLemnOJjrP@fzYL!C)X9piD&Yqx*K83Z zHl8&(v7kYYDZ|q8Oqs`&#^YL{rOxR~F$zj}&=1I*9>2}S1fL}s;0rwS`a6;__BTZf z@cEScvf;#3atbo60@=!D?VL24bUfBpCfLbs-i(iYz47Y?r*H4wJ?yagK5_Jnh6{E~ z_T0VS2a6e#`pC~?TCz0>Gq*s7#QDyo=8MUXEaeTZ z(z__qfKsP6z%0N3Ollwg;BafgL&VuMpRMcuEgpOn3p0`;x{Wgpn`6lLsIit@6=9M# zaelt$^Q)yaqdG*B2kB#q-sh?C?A!%5+rcV5ywmP1lH=h18uVaEAa5^@JAYYd8}%=8FLuipcOT`ZA%_#HmQjsw$9A_9uN zHkKcHHfusponunH{OynWRiT2jzdFS#V`TOmj(jXwacy^mEQ>!LG0rGE12pis>yK5) zN779?pi_bgA_92?Q8#FnZG?Pqv1x921id|PKt>03r0O?uY4bg<3y^0^xWvV9geCMx zo$I)su}{lV@iTrlRjlCoz1*mu^>JZHphC@|d71t@FWomp81n(FjU&biYcQ*Tq}8p{skT|&&Bd1nw6y62#+AGS`KAH1 zA|D9_RlcAGTiAdWNsyQxD@jg~Nsxu8ST-3K=i0*tR$Dr{#_uentySeXWatqiXD1CVO^zR!-jlrT)BmKJrxS!zz*oE;t*vmLvtYL4yX!2@PO43Vm9ny)5 z$6L5mg;+@JFZ_oUgIyR*y8J>&`l4fPLSgc2Lhm$sUwL4~Y}89-3LYwa|6bfQ;upHHn8arVIr|{L({J2W1;+#4+nvB@;7csH z|2m`gM$k6%B{DzlK*j_^g>`5{ z_y3KZyh7(x!TyyZ;~>Zq_*~JwRNHb}32a)sjf!c?>B1Rk?A* z|48!JkJJcq^Ohv;c{>vo=m&kZ`i~ii^T`#=y;ry#CcyEw<**K6E^IDgv3f|HRwSzU$+D3LuKwL2i&0_PA2^nvq=}nKq=K`{Fd)urd6gD83FR`N z?8(QC$(&pkxWVq<*MqtJr`e_ld*!4xJza~fgf&H(%Lo6oftX7eD#m`G=zGcTU2gp4 zd9EF>mGa4jcHbxmzr@Jc@v+745$X{1xSDBKoVA&9=PdJMB^Q(Y_kPqXP6i1d1cj4v zx#&#RcE?#uJk<499Q^iqF#r3_qwrf+_j0-I3lW`+i!L!+oF-ZKqmg~^#E;#~!T{<8 zMcre2EBcwsQf)>(me2Zk>P&z=@UMOPyC~0ek&_JwA4kjL`zkEjEn08xn!zB;b7GpH zB$Yxvm*8m!jWtVc;hh^NhL8*JoC7+BFs-PTELisy4fp#4%cTGAw(8(BF2Je$dZ9y~ z%)MEbPtU~4_$p0iHf;kX;!_m}^yvWZHdI_tjZdUZGLx>=^^qdxnfJ&0D{X$-aVeJ>4HZ<<&XMZevzjm>ht!tIw=VSKeF-cG$r% z5IBUkbq9wF?SrR_ROcv>`ndihtoE$R7IB!T;P)9U8n4VWa22MUEOlJEZ-|uVU9yGm zzC~7soiK=qZ#hpluf>)1EvxJ_N|87dB8g^8oHnPkhuG_pXiQ%}`{OOw5 zJ14CwK{n+Oa^AoS8f&%s>PIONy?hx$RYw1@YI4$CN>D*LoZB&s!egy1iKBs<$9v~7 z`^M&0rc5?)D1<3A36d9Wqe!UjpA`P=70O@($b>%<6juT%Z4sgAL3}J9=3G;*VWN0R zd1O9*`qZO8dA^M%=Bo#mberpngf~C2B@8^E5m>@_H1g!L>1b6`vRMwX-ES61|#|SV3j1NX2l;5MiI)%B;4YuM26RvEL zg@r+N$2-WL{ay;2v}=DK0yx}%qq+cmWCJF#tRUxDe1~DIP_x7aB!~H;49|-7g$jpD zA^0D}1j4Ln{rj}2@nHteG%Gv?RN-!(c59DZZ2t`inF3kdFpwIHa{of+-m$W6 zA|`syR|ZyPK%wTpT|LeF;Z70IlmZzeTSq&fze&N+K}K%DO6b@tnXV&Q*{-l4eIe1< z8A0x{EJPax8+<>S#=pZx_MyejKL7inV8Pc(YHYCq(VN)Tvf5|CrROG#G7-pSARgs5 ztmDMx&`$=#_O`+V*_lW?W0zN8h)p)2yTVrc^(>`DRsO@DmR7&^7J$Bp2sJ!3f|>?G zi8@1Z{F$51|Lk^b7ln%ju`8!FK|@pP1l`Z#jf{}{uLV>jfBR=%E+fhiWokXc>ZS!G zmC5|T)8V<@cBJ4kpsHOWPk^~fU<7(VZQIkcF_veOKy^EohyLLRFX+Ofr75Rb{VKRaZ&bO$pz`a)<9mm$7i(~Hrc&57KxFy9eHMSk!ot8h`Eca zOZbf9J7x)9GJ|Vgt7ip?+U6ewj7_9i9el9d%djNT1qb^ za$3$x)Npoj^*tsue5x(m3u>=KVzv{Z)-K#ReKpahT5R{*wxg|FCA1Yv6hllr7bDCR z2r50wRVp9+h|ndS!cAqUan#dpm-G<)4n0gO7j>Ym<9DEL;QtB=@U%EiO4aE=4dF#i#E zeU!tM&H24Ytpq#tR3A3@nJG$^YCo!r?pEa^5NaAH!`Yd@V`A(4 zx3A6g`J>j1>J-HT7oCn2{KP^ueK%)$!VFfJ z6{iCkE{fM{_X^);eE%RKK|5hAGh^n@XH>$*>T9(Tj;S(Yb+)>=*pimU$vQcB*9xE< zmQPUy3U&~&3-JRkr|usA*Hk@&tVh55JB+~$);~{I6L=_|snUw?YCt8Hb@&e9?Bk)|`y^ zb~nAkXqipAp>R6+nS5j-yQLo(O%&<+;cJ)>czSDj~iAiILVo1dTf8gcq^Vs3hu~ z*g*q0=GKj^K30K}rL&L1Sv0D{^;NeCOL$N-RB|kw125jvc%H1z1u#e*tv!W3VSW{1os z#ydk7TdO~Y;i3#@dwwxchheF?YlLN*?qmu0b`EBuZ|69?>@=jOrfG}{eEp}5hLqWi zx0nTn_oEk^f@Ru>>g5lXEt~5^N`=7>%JolwIeCc?A;WX*N`%jK7P5F%+J`|EE*k|L zH-EjuW7K%?VbVP%&!Ku|Md_kwlpL2CP*}n$uWf7tXj*qucFCUY%(B*tRKGvntT^|} zJO6)7on=^5YrMse9#pzJrMnvjID|@vAT22k(l~>JBFxZT(ujf}-Hnpcjg;t+(%q={ z-RQl~{R{%`+56r9SnIdiVw3fUFK~=8rN!xKc7Zak3gAmJt2ozx@*&SQ*saEF2HwD3 z!)Fo~pAkf3X`Pq`%D);?nFEQ%jK2PA$z{eGBRkt--22^Ja<^aHX|%4yizO4Ouiviz z;cu1z_vmR8Xt*CE4bJLff=PTy+Yl9pc7@YnQb&6oo4&f^Bm)y30K>fkzCD7Um#12u z9<-OMGwAx-wcvx52*s~4J2Y<0ix@BG%#-e~VgU{&W+$s2Skkv31rK_~r8+s#DFkFmR{hWdt$* zo&9t7pE~HVx_kp_4?pkkR~%B{5b#RVz0v;2qxYjoQr>dB{OGuKt#$9D;$mbM!F^s_ zbB(F~&V=j*VJ_Hfe9HscS$STz`$SJ@zIQ!I4~U$ZQSN|H%Wvv3_O+2MZ_+YmxgSQ@~HU86%*)FjqV`lhk#1GlsQ(Y>%L z$iu-#Rz0NSTs)%u;t8g%etG4wOQ@0HhoaId8^)K`W0(o@A~m1^vr|k+CygKSNIWzA zRKa9>k3YTk{85)nnvc=K%)xZcdcB0_!Ka;uOC+cOYUBfeAsZb(Q{Ab2|8=W7+vr0R zt}h;rbIH;s^vy(_->?@YG+n^3S5jWljWDeklgJ=Vt7GqRwe$H^XENJ)M1sf4TE9B& zc%xy=|5mHb8HVF~EAlEYl+|JhtDapZA)6M`2+3bdNyaz@)E5rckGOx26p(XaPRS-} zRloL21FIA#hI>U8RjzuFh|B7H`S|v$_Oo?Q#eRZU&gL(siN!# z-)a+FOcd7tluzQzsR6S0-zakI_8AYy3AdM&#o%N|rcyz|8q9w35Tb;BtNPQQiXAW9 zZP1NVOYP+q6Q-At3Ecfs`RjxyiN^T(2Q=S-h+qoppD2uTurwE4_h4{-K@zP6 z#e{!U+_v19kpjHD=9GNSqEfI#xaEgrK5R?GkfKSAvkqxh_pS!EK^sggk-xY;&~~oI z;Tn`d`U=>mWKPd1Ut_4hxzC~Hv~YFHQs3w)=EIs-mFg?=cvyOT|UhnL#ZSAjzd5u<>)Q_atRK&h#^ol z3L#Vm(vmLKaiCfck|qnv`fN?Rf$&#UjNC7Y{4P*!LY@VnY$8#pvK?#(8PjwiM0U0O zNpC!aeQ|@#wg67k%}<~XlCSwXq!|2IeSfo*!v#ftehXt0#I1rZs;-^5>+>ep+`gijih(N(P4>tHYRA$ITmd^l-$OZEAoXTNq&a$GH9MnvC)l(-sF zphG@9K?Z`Sz@n84EMFBJJ?S(64tM1B9z}>L)eC``@##Q}G|?Hg5BQ%b0uxFH*uhh@ z6xn4V*dVT(AVU`D0^F9O#F0MRv-e`cq_P8lAtbiSJFFTY>aN66r0`;+9DvY@h(7>S z=)3|}Gms1e1aNVcnd0Rw3G78&=5q({ZoY_uqmfu zqd`3paT)Daxebp8MnWt|gRlZxm`HEJ6i99Z3#QTvTl(ygBL?x8M+yi?qPe~sdTx0Q zG(Fp;ha3^`);)!nhxto5wCPntQry6bEDf3LdIP^FMcj_g1g27agnXVbxCJu4SjMsO zRphC+CjvjCl1_i2>85sL?Pu&X7z#i$lynfk&euAC-LHeUZk|{Ug9{|jWHKa^c=cgo zT;AU5xpugdpTvm`%U%Na(hG&Ur(fHFzK(op(jABef{B>#cSV@&>a; zM!98WyZd)C$oLexY~HdOzAdpYGOa`PR>0JlC9>67Q2T~NmB@o~KI8~HAa$FuH^4C|p9#x>0H#NpWmgBug_ z^|!H;G9vB8^*WkaV~c*oOEEK(yLuo;`bkx|hNz0licyzioFCl`0 zca^~M?G3*Y)O~3<0i4t8JLHTa6@iHWd(V5!J7!5;^b{~IHo@<_<8gKsLERU|086m+ zB4?z~gwkh1n})=!*sjaBB%?cLPS1f;$L>aZViyOWYXW{D>z>5xO- z+W*85Jk00UWmH}BN9D*Tpo36YF3bv!l<=VLgJ}*}xM|ZXL3$PQC?k@d9w=92$j#N|jd|4tR)DU8bSBxj; zFp|Sx?E#op_wm?`@zxMV?PSK^z<(8mnBW!(%LS|o9f^Omdc&813W8=1n38ng^hPK& z&pi0rPn;pmeGz)2iZ@1T<30SU(k(mU5Hs}OO)JEX;$ltZFs5wJ5da;BD|A;RoT_Dj zYM#+22QA-8Ltscj=?1_pU5&Kj7UxhUn01GbTzMBL+$!+rUi5T#g(In`eofrN?TPvc zkQx1!K(p=Tm`axI{JycT>b$QichUI%wzUa%?b27m??%PzgIu^OedC3kn^j-u1E1(y z`J6D%6+M4ESs}K`rzf6nFn&VlzjFw#s!d!Q%2tMZ)16am1rVoiD$nz|E+vi<*>yea zmk?D{behyjkm~Bz%%#9Rom3hTBZqq!5%~aBc)^&Ah|+xppvz8`{l%GEW!t4<^-gFb zVaj9X8iRNi?UO`N9S?xdecI*e^1_EeGP|Hg^^ z;W5YMd!HpsHdZ$}3g0 zMe>Ec*T@v*pG~Cl?5LhO%p=N{@_d>qY8P;}^TxwxP};?FJs7mSrvoAkjP zR!aXzBWsX;-S*j@(wa(`hL{*9Y{o{lx}Zq|-@Ik{kWfF_z!5cqov}zm(^@%z<8y9H z&QNsq=A%Jb6R=UAX4ZW_{8?KQ;@Z34K(VkfJa_aVh=T2q^;L~vmi4lzvERWvZG`vj zX6s7rnY01-jKP#<;58GZDJnk985{9jE~ZS;d2p=E4=Sd zXU>5tDk^6ub!~KzB5M!uCIs@KgoS#46E45y_~G*MvTx@@&lX#)&CmM`+5tpn@~XhT z=+*Gj^$5?&{L(l8F*^sME^y39_gsYgzH~1D6waAO?YCbib+`IIfF$k>10BqB;{S3F zHX?`TA4{?AiaS>`Auwl+nK0bjF>N%$Ou5FTby8KX*rR6^);JpGk0d zpXJYjf^O+x`fPux18ArKaE^g&1$OwjL6qtnzx3JnR~^twIz=({tkEa8(Ma)08*rHR zlm-3kI{9HF5TDu;J&2T#iBPOD9d8X z!K{(|s(2vH0v>nr#pXwh*3{KON}IZ_=pFPW5Y(4Zx9N*sKcbb8X8F zqq(1?Nfdw9u?Ju5s$-s3rzb`ftRuJCg5y1XK{xxvXfA7!rb7{U|63`t02l|D%4FAm zL$-AH&l?flA7B1!eMb&3wM5wOFmx&{Q&pOhKo)xiz)b)yMvI5oo7>;o0@HLoAy&W- zszsL)-g#+=5Siuys6=f1_My>8;*vd!zU-9gjE2MZdBmaOOa@Cv+g+q*{82NDCY5_1 zYmm@fDOumFQb(9mBlTJU@o{SE-n}L8zToAs550AcxsX;5d`BICQjnJKc>9eP7#Y7U zOzYTVnG3P2uNBz30`V*|3pifjb7lvv-)Q{V=jRXU7n%FRb#r|aZ8W^Gwxt{sK#`B! z1&eZrBHte@G@_1)`K=PBfj^H&Nvw-n?gfc~WDSu5$5iKzavKfwDAw$1T}AB{P~$*+ zCUsq>J8idiTA;%|mO=yz*D6nd+f2Wj)S$(g&YvJkgus@huDzgKtl`I-2uIkfxLzX2 zZJl;u^-=Fx{=uQC5jm2!4PYTcKymv{@{uPn%s+Tp#EE;E>37iUP_$|v-`9wXSLZNp zTT(mfo}rNqh#i}>w{BOxVJ3?IXU6aKIL7xLk!vF>5VnI6cUs#j@A=aCva;~z0&F|MzzjHX(qyZ zVht(29eCnzLEGw#wG0qp_fr>%Sr>_!6}YX!?fRW%^Dnsawr7LUg+RzIpz&xJDoHf~ z_DQ71=4DFPzx|MmW3l)i#x0_23s;^1tf0GNVrFfC2Ui^EEdom_as)rbMWAXzz7ce! z!Hu2z0V$5C&b2d?2ml2nOm6CotlDHL=2ewDaBJ#+FBT{)O@2f-S=S$1;9G-5_Z^ax z=NGMkJ;Q<(uty=F)J*s8MIe?ZMOn4&N4W+=e)rsfpBD}#la@k*&%k`0BOs%V2ZDyu zg27XiXs$2dTxobZ;tP`?6nh(A6byAmf!|E7Ga}+*{wA+p!{AZYVAV|njuP!R`sn}` z(T0^`>YMK{b6%o&drUH+!#4RWrk?I|`$ z7aVmjd@Ze3kDx>f0?$eNnXx`1gSibg2|!+qau9FQV_?>D(8ul0LI)RFbUJ=8YDoKD07i$!+h zVtO=&E*>C|0ttyvH69UUy5!CTm}B6}UG0^F9^-9c4N5#5@*X=B38dwQ_EgsjP%W>? z{YIn}NnY*L-+=?L);s84QCUXOo>!>_mlxZsyZ|3smIldK^w^Bh>pn*k*@S~v3|DtG z9^uhrW^RKfFJ;xQ;=2ad*6+slN?#SXM;V~eK!XSId782G-q6%U03#HhQ}42Q5Y7Xp zU;Yo}KU~%NJ1whJC)NVShe+2Xz3nDP3Ebt4_>1CRZpaE#EDqoMF0vK@=n=dCzjnq) zo!|=RR`VW_-83>e+UY9V*?$C)-r51?WAM5&zfUTnF_-e$f|#9KJ+)JL#kjPwUV%F; z*wCdzn@RWJ!>jf6=6j0~XC7AdTb2EeN6kiz@DQ>D*P?$%6%!o~rs8<~`lC<_Uv9PD z{N522U9}SbXA4DArSN3D2qj^2t8c32ILwJEoy}~{%@y_G2=wO#l1cKN@V0NjFqsNn zgp9jluC3>`;Isq{T~+;78h}S+TKstCGTep?LXh;%J_Hd;DRk04&S29ulzblo#&FPB z>HpBnuMftmVA290`Ne?%<`M&onH8sW0MG4=kvw?eJ@v0O&>DT;vK+1?)T1b5}afI2hBvlaX0clXF0 zU^F@FD*{~=3+&)CGvHI4DLU7&k%+=I$oS<}KONVEtX~wP4r^-n1VqP=ajsWby!E!`*DVladK%^tHIlDT06AF@0u=@OQ4Gy4 zuk51&k zP=C0o1P`V?+(h%mMkov{IPU;-b5RDPyc7-=0pq!Th8{pXE`I=70s=LFpq_5^>s@ET5 zV-vh#)`=(NG%a`2Nlg#-D@^0pBRRO|6uDB8N~XGmB_#h>bP(_m)9TfayJDEhfRogh zwIRkjKX2=DTq4#d-ZjDftrc zo_bhqW`fAHkG!1bgaKJ_i__Y4!mJIchIm0-s*?U?Z4b+ALVZ2Bosrh?twAvIr0U(8%EKd{&R?$V!CeM)A4j;!&l5&FVay-=%K=F`CbM-XLHkTj<0vmK;0tzdZ){ zpB&Ls-vj|r?(b~G+O!)s2vt8OPT_=C%pQzjxAZvxQeAG~?_Um%+l3p)+D3*C=4xHW zCoTjnKE629sI%Gw*wdc!2Ql=5^LnoVUxMPK$qTG#=)frADZ*0W35(Rh0I6zdap3@; zYd_|8<-s&*884h@ACyDXZSl?E;0}gT!1#sB2>is0o10-8CHQ42i-QMUZvf?S^QgvV zA+`JlECIX{EJDFCY)3sOg8rHSjF6_FUh64L10CDb+1AeP@IkLADHx@U*4e)-6V$c!CVVK2Y>m+XygRsON%5aGBL`h3tHcw7xVuW;<7yF?zc73 z-f9kD-|pYwqr0hs*6omAu1)`=Y(*55#YUL0E6mkHv%P}Y@~fzhUI~Hj6kPn~>_QY;~7Z%2>DDU`yqW86@?so@x-JV#j9c`$Z(rG4g8af5hXJlOm5D$&1 z>y8)!c(2#vW*4JV@1{ZaNUQE!w|flNAh5ep!EUx>^kG*X7(l!xqgz~7d4b7l_Gq#< zJhP9Ci{XPtaSl4SS9s~Uh4UN$Q&LC={^td`2i+FK*jJ@5AqLK>O6Z=@kKmaYT}??= zUv_e-129^b>DH1!2UFfu_-v5*40ujblXEmOr9^#&U%2f{rhsBVJe=#hWa$S~x7aD5 zGzRqGg2W>23RgdRBy0mRBYyBlH#|SxxwZf?ib^9}Nx zQTiY(TK=Is6quND*)^Y&$B8tuo8o>TPo^C@PjGo`we ziS=Tq?c}xq__{j{kqG0kDntTvug9yW09xFtY%^eV)}XB<)gOVtuFVCW;6Cgjbj97n zAQHleI{qh%s>20t*ZFc6u|K(50}?U8N1BxH0Z^O-ndFPEftMzq_)QrA21mzhkL9H| zRH~kDHvuQ;Qp2is&c}+6|K1-l1N}xS%8+@)RKze9qrKr~a25_en6!vO0gpc{)SC=s zll`*>kbU6ZOSB0YqDIv8f+v;+MGa9GFd>jzxSP;MiJN@Ht&&!MM3vrT>dC5 z@)zK2=;s@aun5H`=+Pwp6!B^4M(|FoB7PW?Sisd;YR}1cNx@}gy(U<51QJAu?cbHm z0(54-qn!6Wd#kfS(^u!ifttFKEYlYrN9nGuRHrx4iisR{--zgNR@93|yZ&LS1$dzl zNM}-6St+rO{0R;2mn2KU5WTqPOQ}Odu1PR8q3#LFzmqxtnoNV=kOlgD!6-}*0stGZ z(@>IMTInRF#EOYB(Rr9P=5@cwx?isp*7eAIeUR+AdEvD4``XE!#@e>rq25HLs) z0ig?9I5A$v38?t7{1?1jNS{l_2GCOE@h@9T@*ewF{xwhZo&s@Ei&0za4!D^IMY}id`@h$A8ju$_6qxxhS zX5C#8XK}{)tJ(T;XLrkC9;ZK-4va6Yd@-qSFllngZ%Dlr zflYcpG{*gX^ zHEt-{k~8Jb%0=M-W23XFB>#?uQ-UbPa0)qbDG@}VmBd}5y308&Tu3cfsa9q{Y}og%Ox>QmkYgBwHrD}pw-K4di~_3<!;3SwZ%rhNv2T-gpNHFZmDHYrO@!j^Ld#c2ds<-i$QTTRDzZ^RW(R~L znayEGD5qz~iTDY@&z_`^B(?q}y`Lyzt*Bl`OPj71Vcs$um)78t+V5(U0IT5sA@>-Z zpE6JoRQerB`E-4w5zN%6%SVhncIrO_STfVedRUG|HlJP;xMyMD}wZDjx38 z@TMG>SpX*iv#I+#AUyTc1~_=axjS`f1fKd#|3dykCl=gau@fzlz2B&v)hyON+kVSs zdjOP48G}(A_I|Q#mzwvn;xyEPl}Y$i`&Nh8%M{A>>a@0kTCPSJ z9AD!m%O{;yQ1o`PJ{7`BKHd_jVXd;M3Bj42eGP$D(`gX$RaVTFOwkfRMaPuy#~U%t z`E+y67kg6EMTbZJ^6GH7gFV}ixDl-1qNrYmY`E3k3yPbyvn@jEW{F6uisBwtU4&Rv zMWjo1^=u(;IHNt>4kC`hK~Cy*oP{wOU~Neu&;pbz%5fX+{uY#PG|(hYrlD@Zm)mQ5 zR&)x8ulgNbo`K~n6tL;u08QjzeW6vj=fyGJIw_UlRV?5IIDAvAL%uFen~o4!1pu0^ zedI`rs-U+bxh*K$LoC*ZQvmEak0SK(gftL;3z=I ziLU@$sKhvL9V2s{oK*_Ygb=%}6P5KF%r84vh5&849C+-Z{bFzgf2#!c`&mo30M}^Xl;c5q%46U3D-fS1(fk+(YNj?R^Y&TxaUq^SnS@9Xq$zTS4y7 z&R*RNUvMQcG?4Z(U}TI2gaUlYh_}0DNrbM=xWK3LENq8FZX2WsotPQK+Vbz4G`UbUgxM__v)r^TL1ZE z_0mX#R6Im;fL%hOh6lU2ao0%c({~`30G+6-8Ma*qf_$L~ zC?2@U+}>FZ91B9nznJ(z5L?_Q7JJO-C~l=@7KyarIF(Jmi~DgQi{-HxXtm2CSurt1pyuN6#e$9)jao}?m5_Gf$GsAF7V zR_J5bpmN{v)QW_`q>;>F1OUU^#&cg55lZKfJi5ntUL9iLfY@+&oa)l__h;TW8#xlP z;#Lo5Rt`}LgYjCYJd&ZQ%WpJv(b;-#Z_@bZ!Pas6Oq5_jr20a{=xwY@vtG9Ld9Z%x zlf+4KK6|I@lmYO>ff^vP^D}nr*ug~ogM8m9J@bA;0(@qdeqgVosIC$IbLk#}7P8AR z4D_)m#;Tj_?hxy=I=OeMV*mdih9Il4^K*E7BrJrO3xo-R)62u;fy;-?*`PY7J#4PJ zG^!pD=3(c_ggu+lshDsE@WTvPU;v=Nl_FtT#C=2ec`)2pm0Rn)rt4s(|LfmZ4CFS| z23`vtHbLEm16G`lbbr;3$F3TfyLcRfa)I|{CM%AU^yw7-R27m0F2-vdV*1sU$z;M~ zWdUNMw7>Ss1>7&@_rBdhL4EVerpXOmQwR0UKZOKPa~MBb)P0ZJR54gD;4*bp?zP`O z@_gc2jU>pB%T(P@YMk}AW&s^NJ@q0Ju*`OQmY++j)00t#b&b${z2Y-1za&w|{_s{F?FcdM`5JS0v=K~M3Vq@(m10sb9P zDth{L5msyy;5S{{6|elQbc=Q=@tzzLl7=(2+JHX7$j2&P`Qu_{qI~O zbtSa^E{wQbK|$o%!quL3Pw%z4C$L1E1A8_YD9a2R@6sMlhmI`&R6)y~5`-aY@#c~h zPX9zb5?^PsJqe9MVwC*&d=ZmL7p)N-f$nbbyf!ZppkN|AxYTmeTYi^00*-wdBi}Rk z(XG$eyDgQut%TBTAOESMpqrBK0ao0kV zI0;vCW(*X`NozaVHurQkM;k%i0wKCEc=tzGBrs#iXcd5F{FSZ@Px=E>2i_0$vwuA> zu?!y73T*C`Og4&CE1~h~-V^s9^~dS^|G5T*IV%e*9F|-xPx?AS=c+MOnev6glGV>^ zAOHFKx=b|)EUOA))?s>DqAi&lS-nu{8UhS9JAY(#a-5yvk+|~l|1hfd8DwaKCoi#J z1UvuW?_YN-3ROr%8z~X=N}ExNn6WRBU!Ez^<`xcfiBEO&M!dO+7egHf&|wQ&HeKYk z4^u~DTlXi2JaU*>9cq8a-EqrRT}`*9AEYB<_8UCqd@u%TmDj+5gRq_=WaQS?|DNc2 zPu+cT+@q)rHmB*be^P!6{eF$@T_ItB|L-3nwZEKy?D%PH^P9DD(H;zRiadfjR+^gv zf`+F9sAa5yo_Ao)nvgauPJMyQ2JWVx_}SpSFPE-K=dmj9SltWIYmZF) zPm4@Q=AA!-5BuQyO_Iske{L_eXEwRmkSsti@X48KCH={bUsGPD91RG=V*Y4HQBFU} zLQj((Dl`xs8x1PX?XF{0WDxplnbEc;7Z)t&TcTHP9JYTSV|8zGNU_E*sLLYG+D)O& zra>YZ*v)|LXlVA~9(@{&*GT_6Fh~t|m(-6Um9+aUYPy;_D1yJi1f=G_BJ}GwGRO8- zN9G&%CwwD^v1aqK6GIvq1~3)Z-4cd;`alS#57Yg&`npQ-2fu&z2G0xqe(vpPe>A#9 zNfG+#8$&PFR}DJV4sI28S?BJty|Nz9o4So|h%+rFi)>Z}-~Q*q?af`>c>-Cd7ZZj< zmHN!Glr;i;{|2gJz!&0^(BX9jDDpyh#jl^~TA}Ud-}IEslsnOpQw=A`WWFf0T*7hH z5V`;A^67fXvP3zL-|x~m$T%Um;Q0_y&rbAN9JQ=;@}_pYJ>utT$lAq_hEk2l>eo3J z{WC?TA`mOTB`ckA^-xnnnsx4RmMQG&C@bT?L9N=RFK@dLXykT6<-4%hti8o$w;iVj z%W-CsPtGZ(FCe8h9>nz{V3TKls<`PgQ_s^>jG^wZnM?H0%tT-rZoinD#BV~@nix9y z-l##dl}rBegpS#2A)|}C-GF45t)E%tF$^CTzWHs?dv9^-)GpYLgddY_=rK8;pSAIi z1UTn}-Ph@%sGeXlZpG=%-u+P%MGl`pXTPH@!WbS@bp~aMok_i&&woq`V?-Fy{{QX} zX#(4duO=q8_l8df)vd889*I-$6`$k5jt-9t}8JLruBYgX8T}5wWdaA4u z(*-kU<#&nx3D(9{sXhHjE-6?v=YC&et)_64CS-FirF;8Eb53!NAnh5*0J+dKq78Vx zuO#}!-cmx3o0Sf!BHj;f`DNgGj#QZL{l_hYm2P|_@m|GKY z=cDicSS|;cR2?l$)NHGEe0^*i5+|I}eQ6&$GaknH^hFMO^2X`B83RlXH=~wCL<2TL zK!W~#sA!${{d=Z6U!D1(ljA6y#QFIDWyVt9~;n0-?h0%bL_JzhE zLh=PAqy65m&mlT{x3$cP57#Z$n_mu5$MC3qVJZ6=8d7n{5EmK}B1U=gFI$d%D8751 zZjUO(av#xMgn4N2&Y;ozh}gRVp}dNo@Tck=2+z+!5>F)W&ftGy#-4K6h;?R1!rjdY zX%e@%%ZFmR9~B?AyrrM(@%i_%_a{%X)-jtOtQAJj9~>bu$HX@Hm_B7~fwmn7H>~pK z@{OLCE0PS(Bw3EYD0MJ5Aox0&UJf+(Y4HpmN)}tMCWJN%jfPd3Y&Na*%bi0VjMCSx z--tP5K;@jG^dP^N)=0k6LA~F$Yd9@A>F+FvKvLBiJ1hyKZ>mtU*qNp_3q#i>{?9+W zyOx{eGZ>Lf#vexLps{tA?-R(sQ|-6gE#u7AKK}bYMbQ$`zE;8+c%z3mTcTs=O z*%)w>t!x3l!uj!{p-byUANUP3m0>|*Wglbn#zM7g)sr>2V=jmVSBQ$}(*G1}cY&TQ zP9BcAqQe>E!L4V=7&mrMOE;kMlP08Lk64m}7P-b zDo9F0JW5r1AN%Ybu*Zp&UWj$tNB9Q+9cN|aBc%y9MIzWw>c*OCk5Bv4v%-;}_9s1d7KArmFv(HEP51fi1Pwqsex66F# zoj*c$C=e7|Tdb4izLCzumZD}M1VU(%^*V14!n>}G6#qj;%%iylE@Eo!WS4^4O7s?8{KOLRG0x-`tv zH{Q4YwG>~gj1CvAySlM;AH8{USQ2N~6*tSX1e1e9G0v!2ZV{f&rsUk`3tw{QUL5osM_B2L?ZYK$x4MK2upKbyZ4 zAmEJ#Ccvn65PDHPn2^f(E&Q<$71jB~|5mYp_d2X*^=fY#2K)!P8^m=%??%#i#}()P zUS-HZX~f8t*e#M_zxkxY*%XAfhAXIqrKitz3-rtczxN^-^feKSX0({H&Qo8R(Y77$ ztbw`Dc7!YB%B6wtLW+a$Qby5wg6{AB8&<|X?1T;DIA+b(V6LX(MOE%Hjx&aScSj1q zt0s9;1N;ClQhl_PTWwj5D=HP(st}znRNWpz8)UbBTT5zgF9J$%(DJPkuF(oaaA@qJ znAUM|j*ey;Vb!^D?f?5pEZD{~6Z3N?pn-7Cg7IO+_f@Vt(+$+xE#3R{+b~+U37DeO z@9K~*E_}FwLLn9Vgz_0!1Wol+r`7myE zF@mZf!}rl+*bxeNzYUjqVq(z1HPIeU#%%?7O?^co^LmAo+h71BChtLSd~r@07I)lS ze8$1Y%)9@gG@v%xzsFkVJ(^*&xM~Rd4xN|w8Hi?J0G8jnwm^-P3;#U9+^^*tzd!9W zEXW8&Nj?$;4%@wm=MM@BHPX%H1lYV746^dY?(*3Wu_*(t#A0rVL#n`LAt%c>KBo{J zFtwy|*dPlLy{gbJHKl^KP#m^0zDH0l8y1Qo0DkR+u-=xaoP1mUB|*}4c+B@>vo=Vo zrfjSD89Cy*5l{JzkOwO5F9zQ3C4dz5lha7-OY!W~WIe4p#$I>xW+4q$)Xu7J|WH5R0jsQ8ONgUwAB1UsV9< zUczY~Ilmb#B;}zrr}$y0`qcC>=83B;<2-mniqu%HOL$nG>HO3YZ1w6Yx=yF}QCX{H zQ!S+;zCUc7obUKxL^A-PDzTl!>EPILFq?CpyPSVKSCDcsj3cMPM=U0~%G!QWGlwkT z?0k+;Z<8ulra(Hqy8h#!Y>}#)PeL&BBDI+k2iX(f8|gOmDRXOWa$q~1S)+4-8pI3@ z@>3!&M?l`&UQFN>v#)*U9RhmVO=xU|bYdE<+DpH4ABFsC`%bd=(bZVesI-Z^WqXpV z7J;H_O0Z4X^j!~EyvKy44hGa&8=~w-SW8 zvBYWE81%9V;PUIh@IJeNzS%iFG{E&f52^t;ZJ&eYhoV)GS7cL?eKlGr!t84pa@8Rx|Bv=B%qJvkt!#7+N=r&?HeA7fYZewzP5l8LtRtb9EgzZYVW{DHp9{Q#J zj^l0a=8>1Z=N8#U20jg;&>aD$6m{FoeENPYQbwbdi%&K=^kk0{^-aB%zvSnHL3mo{ znn``M$+ruA!&W~;HE^_Z`>m^)ho5^tEd-bn6Y^Vb8uLkBN^-7-?&j~z#?ZSbKkAi6 zJRCZsp4(#%;j5rp6&K}49TY#bdUh-fav^yN*c5`-Fl5-1Q2gJ7VDssrD>b{CT2dd1 zP{ag*K2~Q>TjF%yZvAXzm|~zp_42@zGUJCzmM?PA=(mS&J3?Gp6zYL9znwSC{_*Kk z2aX0uH?zpkzs<%1PTd>uX#_8aGMPIpht(rHeC1pOxWf5Fc16XnBvhDX+1p@}JOBD6 zdL`ar$=b~A74oT9kIbqOarWNatLF*&0y98TMef3(>(596vq=RBmDMtK$!|t}UC##Kc%V zd)`A8b}B8@9FNH~*Avn%zDr4z@-k3PQuaznvLJ?qf^|!7;Uc~F7S7$(w&!l@)7x?G zI!6IhZh8_sAu1I-I5t}hm)$-Z8BILl^L6pwnHkR33G`JV^i*2zwKjdAxE(7~ z@4cy*9nF9Tg?7@iM0$(3<_Ar`Ovc>>+lc?1#-9a$ek>s42qR}32D2WXbi00*0R8#m ziqbdQ9dc8EnMB_Kw3i`3iKfKA-N#*un?SCKXYj0$<`;aB9{tf8A3uRzBl@`L-`xoO zm(d}bv6qIXHaOh&a&6DN-hKGCfw6r;V5@Y4be^5Fb8ru(U5>X^FQ_Cf_ngL`?HNb^T4Ltvs3NTbrH|-heZm@r5wU+NSYMWa&5v> za%F`ReFTESi6Vc05QbI%cwB*(&7SoNdG%xO_w*Cz5nB2kicvJbI?QVHEU%KoO^vv0 zIqDP60i7`Hmyyw#Ka)W6?zg0L%vS=8i$;WI(#!U@wzqQ+^WO6dZMN|@oQ*6~W8hVg zxUwspzEiT;|6Y}7DlQV9x>Bp8zMrZDx`4&~8v$x2>5LE9K75Z79^fj@VeE5`kyt%f z8P$FDnFX-P_*K4g3G;;^(##kSk+?^A|+haQX1ke;3`HT zb1Lu-@?W5ZU?e%??+(ed*cUoK@fw^OufL$89#~McPCexgyIbBuIX6Ve;a6w&^s^XF zM+WBG@*sV2q73WoGQUr+ethR-WHMk|+uF0^h6%weYojbXdBm%;iMqlWHItTlh2{&b zBk%B5y!Gd{5825zl2@$X?&@nO)4&7WYj@4iFv;!+KL0D3r>NQt($-|>o?d>9Qm-3{ zJ+}sDFbYLDm6%?se11YKc~D|u)bDFmtG@1Rq+^JZn;Ltk@*s`pw8_K==Xb#Rd+mq6 zX)HUp1kum5cB!&{eBmm2B(uvBbi9V@?zXJ7PWWK1#wxESMZj%8>?bSka}{){%=$$i zlbR0SV8<&%TC`~E@jvt!ih46RYi)8;d|UCM+TMw#Ej~fEbu`0xqY7@Td}dU5L@(Q5 zFfn{_a4l;_!#<8}^jtISH3n z=6sEXcRy!YaB7&b-7)g`5nvjq2Y+_9QN>RcP~4|zjXC5S`6B0gp+_63ytT5v9=rVu z4)+^D+UOM~iTT6DXL;LQAi8PX@vglV3w=>&(3ImtWijDs>L>huhEwgef~138laAMA zB#2gD{p83kMl8Dd&gNc3<(3Cm-c!bXT}ge?sr{H5ul=#Tx;v+Mmo>7o`$EYfRSPXl zzK*=NTN9_=(>D{B<~(zRu^oxh-v)m|9tlB&X3F}Ox-4>wNzZHd$BJqx-Op3tF&{DTqGfu5kKJkaf~M^@2s95?@H~D;ynd6d!4sn}@1XZI zG|>~;BO_)M;NwvNn8|4Ip>u11#E8J(=|I0T%f^3P8kN&B?P@l#=EuZFs})T};y0~1 z)nALR93vPM#ZH-`5-sO5mwRF+FS1 zSTQC~0-1@RW`Tv>etqtQhz5&1_js)GjnZp>n!s8!{U6vh@@6`QF>?A#YYh0Tcx^PT z$0M%9f|r(Oj(ORrLL9Cg>0&HoN@{8x8G+OtDY(=Fr7#tG^3wKozaO-_Dt#>W{4ANY zndI%kUleq*j^}d4&0pdCTLf=Dwa6m>K_4r166)>r3SLG_?XoZ8VxFDG4~cHxcmb=vOgQ#q z-uDR2o@s1Pmp)$Mv^@1P>H7SHsx})8okJT!E)&$BI*f>>#1MMwy!^a~nDKOfu;|YC zK6GeEgR9wci2L&MG6gbNwD%UF4qHXJ+&3+l3XD$DIpYqJ@D_z=26Lx~8f}`!$qjTx zl^Mf^pmaF3jXK+yr+3D;r3B9o-`9y4gU{L5geAW;?r}DFxRH7{O9fC&;dH3227Hhx z7_6?xM@lqco~t&-!29R&*CiRBygd&=bx$F|ZpW#;k&k`Kb6=ITs$?THC>j0_{9)JKrms#- z43m@Qm$^N6M zyWiS}84>imLd=B49+ti~L64b+tLf|DaW<|v`7N*{7%I|0;(aI?n>tf|J(;Nbev!fe z_S=DE3eZZr)C%Bbqves>nX^kfe8NkfZr>U_m1u?5WZ&-ePeS2IByYhUEI0zL-^`&q zze-|fUm=C=L)JF`zb5l-JPK(KI8|@*Jv!AElX-RhYZ4wWfH4R+_OBj~jM*;eKn1fK zSAgBZWE9a4T}Id(vZ!|^>3`j-?9-LaRjT-ZKaE9v*`6&#*&a+wKpK5oq{r*AVErEg z3$$BL!s3Inl0Fcgj%9@!6`@*xKp<%LAa)?a{=-`8I zE52YcBxdSjRl;`p=`8DBJo4}K-~C(?th#tw`C}#1J&qedp6>Eh;imoO81m0JC?n_H z_(@f}^(~Hcw$k;Bw=3^@adhcu_>W#{|JhuD`TC}YN@8MxAMR+S0~MmS7*N4@KWGpD zd$+AVNzthT=%`GlIpy`R|f=p>3w;?HCj4$s&3_fT^m31c%XPwHra0nn> zPgHY`3LJBrN2!?0z0&OUMr>^^**&Ur__LZBcVL4T$#84OLIZn~hNpr(&>W_U6z+Wq z{t^O$EK!h|Uc*Jo59BoG0(S%ODnW1o0dL1H6a$bliBW(NOhAQkG8r>)>GU~gkqLD@ zDy{Ex_UF|#f#4w5;ikY8)c@Q8@ZOUl`G%?Y2h2){DGQ9PzDJ2fi({W4D_$2Z}+g_EItP| zn0vaC+Yf&OT|eHtcVy-!tso=C>T;?3QS<9xzz!cacQqh9ynHJPCk*6`uuXv2#{3$F z>Su?8;wbLY`u1x%QM_tUG6+mcW>h8?b>cEGzRAX2jjL~R*B(;D{`gX6UJqOXR#_N$ zmJ-Jky4Lj9(R0N?keCLU?RTI8-|wQZzG}ze$MsxYmdzFd!YBdTfz&-9i0M26EA^!d z!eL;~=jSm=zV!PHWU*8+x8`2SB$pcCmn113E3VG3H1IeD%6NG7HAsBUM; zt;`p4(*IEm*D*JHJr=H8RvVl1334pS6aihdC^q$J%HBsMz@j*~c_UO4IJhO&GCbc{ zOq7|+Mbb(NEhJRo0`x*N_+SM2BT;^&83F=+H0Oij}o$I%~P7F0f zxM?ns_3Dg39>dfgK?Jz3tmhvpk6s9?nSuyxUpaaYYjeWlVly(WZA#2&cfNpE6=TPh-VgOQ6EmmmFkzPC<1 ze)g4YDRdsVNIMq0B9{EcZAqYfWs!9PD;K6y`)%=egjlW~C9DEfv2TTC+$%kN*g-T3$uC`2*_L%^`l z&MP7_RjCK5UktYQ<3eJZuQx`Ki;jxN9L#^B#jke}TDfkI`$?Ici3Js!@BW?lVq>Qr zS7KHz>irL0Zypb2`@WAqMJ2M7ok6l^mt?G=i0ouvvM*VO>{PZ* zEJa&ZWu440w6;Q4^Gj=NrR&>d*$%s@^CSe2pc%aV=oaIG4zgVKGDoHNgqVmEu2uuc z(*RP^S;*XN>tKS!c5c9t*uBXX|1>A8h#}X}zo%Swz!%qm{(7=2yvKYB9ag*J#a0^= zVoOg4<06szX4)5}>$nojTiYR4SCkmzAB72<#J4N$RfVr}sU|5OOm6O8Bn%oetvWcl zHIevy8;)G*yp@g=_U|v!0l0ms8~B(h9ECIrzUZlWS$XtdrU2|}LbvF+#cl~3TK6r# zcrvs+#VnsIIC)-I55RDK4ta-SuV*&5xUR=8@EE3PL`GQwD>?AY%yC?BMR&l*M^XyB zrO2yr@Q=6JD0DpEu0X+L62A_M$SwBkQIrB9w^$9;%wAe={Lkuq2V$TThqQJMQ8@~E zgz~X8=uB`kRdG#GyU6X}6q=atAoM|Dyi4|OobzIZtoMJZ5x7W+8%4^d+z6cxD=ABf z#PvAkm#o^=3`y&ERSeJZa~NZC9bAXA*XMbUZc<4k@JKJM38whCanAApuGGoY%-r(9 zI=$MZVmg`HI`Lo4Cj2h&eG}jfVEMTBojOnp;E&6%^#vqIphE?8Jb~Pmlywsix72Qh zw!&WRwsj&~FJWR&h4amp^NbQ;;vp#^xg`%Ls&-keCw3jePqR7H9{TYU82$e9u>vw9g=rtYcC(7<6bQT}b8Y1AC{eeHu+r|5DppCytuF{I z9+(_r4e-`*N(W$piQ_I6GBgGLJH`Lp{g1x_PynS5K{Sd>Ab*<|pZ}Ig2SUVKws(=Q zyKW%nXgU)oyP=^N=3rpR|8G{wLWFIj|6&CBpcr!DM`u^GW#p zK52xy`C}yI?NN>9b~VP761C?0Jq}RU{{~x6-pl^?H*i+#*CDPU6B4|Mpdj;E*E_oZ zCu;?HO9tv_DcLbk<0zEo93&0lR)qSFl|WqS7uaA!fffNvTwGl6R?VywZU;95_StsC z;16uva$+*g^aq}riKJ5sh~J+bi!E2=airBr`3;zrn*e{#0+j_CU&q;J_!a+#P@B-; zxT*r6^adv_lJ~T@|D&)GIpCYnNhPU+41zJj;XW5Gzu>vk(4u1CbgT#IMGTu%E1AX&RpL1Ses}Wdj=ihOc5=7A5 zS8^k)oE;%=%^E1?!`}+!C1Cr07v9w5SbpISk6 zJI6dI^(5L`A0+~tt*RSQrI4#jKn%f?_cQU*>ISg3LA|TntTP56-EzsMU}QDKY&AT0 z9!QVM0>#km8gn>HA}eEyp`rp$XTJ$mljJ0gK|O0&2*MPXBy(<3F zRhdQ8=&hj+EB*dZ?XEiP$KbC+8#mefZ@xJ{cXNtIRv*uo0H#IMFyW_T+vyLhg^h{D z?_pnkWt68#(wPoAhWYi+rWENN9(*8e;@~Iol@gTN{Ndn7k;3ynp(OlR>9ijuRv;(- z;p`irI!QB{GH#%1Hlc+QUrM736*^s;s*UZY^Y>Y(Lf?$sMKCxvMmxAg=A=<_kMssZ z-|L1VP@gi3U%+I(UTOWjoe;V`N>5v3`0 zos#!DiVXVSrLK?r4X1EFsLr?bLCY5 za~a6b7o(m|hX=8X7Lv$hcTT#GmbDHk^*~Y4*`U!G8>zs(ZUtps`x=nw&{jjPRx-Lm zxlnI>$H~1n!3yPLxSvE{vw_QmK=i)1@N&rWujg3$6U-dCKUrsrL=Z{a3EXY`_R3^a zd7_3Pc2DrcLw6-JKc0pRVV$E<-K zYBi%AGvTU@k3*GjHde+sW?FQ%`9SqKq7LE>L*Y}>NLnhszO9i7$GlMIX{kFt^j(q} z4sLgzL#Bo*6GKN#l5UMe`1T^GZ+)#lOLbqUX?(!qkhnQ8x*gZ)7drC`HqqPwh<#t` zo!#}KiWi3;rw{ffS( zS^C~sgD^BPWKQo+!op#DoAjT$R1RO)DLb>WCE3@r-~3S?F6k3eeA+r}?^Abo<9?Nh z%eTALsa0N|UqLx5AIKf~`vc8j)TdOs{Z~G+hdLEo)7KvPLGy94p>*sk=EKug8cU+i z`RrS12a{Fh&(h}Sv5&NA>wgpuAzdC~ug`y2O1&Lu)C){$dhO*9VJgg*Sfo=pTq|By zY!yfyjaBvLeckMEYel!s5I7^&$*6dWCj86N$pPlQ=0)3_9dx8}N6*uTsuJ&*)WVx%Y2P$*}2Xc7BKkOYI;4Y3__Qw2a>%aG#PClu1?Z!$<1X7H>*2Qx zZ~jTc(3Wsde!6XI+Vs+^_IucmBD|Fl(^+Y;&YS#V0UF6(l!hF897(>gFb26`^sSbT zkVztU5M8R{C(TIf)Nz2b($LU;DknSNiMq25VQO z1&J<4;QkLE%7p`vP}O)&7nXR@$o=NItJ$SQjxEN)#@5)yg`9xIcNPQN+tc6k!4HEZHO>x{igL5Wh-QG@0f;xtU`d}Cms)!@Nb>5aZ znZl{xzCGpiJ8dxyC9U^VdRlaic}>Vi1CsE8{4+UIai(L2yGMjna$15mzwPTM0>RzA zpJfLNSuU@$?xd~`k|>LPB#$XNnUXFbE8r=%`CUvXlU@0Fa3bw*&o`Pg!;w$%)#5&C zivBO$PuAm{1ImPbhzLYCqT%kaJGNe`ArA+CxzHq2cwM{2j2|KL_o$O4IR@2-+u_(*%@fZp6s1kEd2eF4xz4P zwevj7ciST?Vd6NpizN0i7t6+er6P}A6qE2No?v$9nxH6zb!)J{(VX-#swQE+V>=Rj zOYFr`QE~NLQYB7qP#LLScdxNxq{OT%KQ>7HRmz~5!%8_CNbp+w8|LPYj#Lb!mUn@~ z;ypzU^k8^yOeWh*5M`*1R0h3=S_1hr9(P@}>|pI|2N|85?lD#E8#Oq({APNV6}-LZ z=%^{aDVm23C_iNivWDb$NG5?5Y(^!J zFM7|JFkJ?yLe4`*y1>qk5iII2OxfK}iCQO2;s63&@ygWkW3bV(ye|`bkW)o@$6L3D zBYp3yKrR=E8#C0=V^k7PPDjfE?&GkgK9sA&RArm1sXeVCZA^E-r7zS;{zu06D+7)GwH zm67Y1`KKrtFxBax)fsaR>QW>7;*AO@XWWNl#+|JP);$BedX9kJPtw0C5IW>{7ld|; z$+!?!O+qhx8loUgu#84+{3`6cn)`+nqqq;aH9(bRslFeB@dL(_b%- z!+;9ouwnk63=AA@|Ez>&saK~kn}p8dr%Byu`Q<_p^(gZSBQ3eGXjvGU9BkL5|7rim zjCCt1H65ESap`ZPl;^uw(3JyWqFruh-+b#u?P5`4$C8qQ{k2PwdzIP(T6^?0q>y2Uimrt!)ZLytxg7=x3X0h~F@-tVzDQiU6H1#qozcd< zi2M{$^D=e55|XBp4oXy-7F3vZ+#Tr9?~-;Mnk9q`6|6vklVodzOeCXZD}av~a5DTM zO@HfbYO^Lv=C?~oZd_~j(WDX0HeYo%=309DE%>FeDn;d&!jk5vatM!)fB!`N`1$!q z0*58(jD_F9q}gGk`Y(n**!EOZ@NA~!9Sn82%0`-J4gF-myiU0?Vo<1=9_PjI#MTp-F+O2qVb8E1_ak= zP%v`Ya#3kYf?K^B5}R+mF$GJBJP(NVR0aud^5niXBvodY=~>pb@sMYgZ#ah#fUXEs zrj1n_8LWKAvV$OYys&w<=zYgXIfC9aY` zOLny4lCy-V%4l^R!(R!fc`7OL%yNV20IjXE>@xzYw;H$Y30qx;6*)Sh_9(S(n|Nd5 z@77$|S?WN4txx392VOUU_2>kQ3DOq`N5GTrx$*Dj%9ZhcnvI%%`Q6ygVG9Wy%W>)( zAbOPevznddJlky71D2t;IPHY@qqmr^CsJk<-=44{AOhwx0O%Q|BA5h)evFIm`!%xx zzTu0XaP`OT+cT1RKoel=@JAIuYkBjokw9o>2h|kVnZ1EJsw{v%+v2z=XAgYhyz^zW({6+5KeR?74$?F4i^9M`Nemd01#phRc8MLS_Tm8uO;A*Of9~G6Qy`3 zxdpVK1>Z5;V3Lw>DneXwNfkA5c)w?fQ(+kV_^fF4NPpaek8%8gqbGp07xrBsZ-8t2 zlA)+tDrrmI+=DhyeDbWOHyQVIrkS zQZPZbG8%wraY$4}U_m*6*X0%VaH_8)eVMi?xl}UY{Sb?ex?4EO-y8b*p&ZbwxRUFwshYB?86N)TL-T3i zV$$_~_OeU#o2WvFvjQ+c_Cn~Cmwx&CN5I1YS_oCPnd}=8$TKR3CgT#WK%>O7X~Mi@rko+egp~wRFn?rYj02M|E*m_ zyl?ZT!Z%=$Oq0HCdm{1=Y5%*3Trru-gYI!P$5=3!={*>Xz7g!B7%L04@|Uk{fuS9~ zfhQqee#{dIZbT*MH{;|w(_xjY721K*Rm;F6k#}GWy*x_g(X9c5RgT$iNMDk(UH`SV zROgK6C6~+)<|&(xj-oyAoWqF#&ojdzx8xql1j^@kOVZ8FMEz8G#$j7kHZPDFYt{~q{U0Yby^-b=n-X`If3u7!jga%&%PIud!QgtQhWW+gAU1YPnY0n;wVxh)^+(Sf$67YIXyDHET?X*5>YY+Pn>T_k|`>AT9B7%OZ zRpI%YV}!#!0n1)89)TMu|EJGuk^ZuoZ^aQ>$H3q$P%b}5l>JgqGQMJ#gv7!`eGj_& zae!k>69YS+-l_{uqgXgTh=f6HJ;BgP(G6zaT}~@EZ3Ko>}! zR?*b#(TwHzi&u5lFU`A_y|b_|YpROic(T&}>1reM?oGkap4B-v*{`Qk4-2jw5Yake z($gBb*gfYuT+}`S=_PMaW*FsY^+bJe=cx9$peuKlvBtHK_%!@bPT+ z4&ai+dry82fCUgCk*;t(ElVS>M$p_(o z){zW0j&lK==@kHqXCtJmgp`aw33D*A>u@w^O)TLa>KThYj9w9aK}7EQ+cpq8&P&uW%=)sxR@0Rbu5!RwMn&mmq(R ztAq`Oj0|)=C!h?aG25+*U@( zy4m-+b$Vh6?nVk*e+OnvIIAs?!FoB^!jekt8;p3tH6n~Lz1 zC!BG$`*OhUHIO^w%yq~|zg@8;86Dh6RitNm@XC1ZAWN-H&x`hxiE2~nFOS&uxlyae z*;os^0qL$Vi(F4fLKCRi5s7!mBc%jh z?kXckja5wh{Wk}s!}=6NGj^hYoFM#+76JFyhpEgj#sM|@SAUJ)x`+7*rl>}dB6jC{ zc)rcIrBCpa{kmge5^D5B+xt7qcK(u~U10y;K{?Wr-)5TaacV8AvD|^w*RknOW_}d7 zf11N|?HA#1T;``=_K);vAS0e}Lp?=)k8dNDmZ&ylI1zy^pNKF99L^)Vd^x<|?16HJ z1z(9P+m|qY8zJbhlIDo622pRd{6)W;iX0)@ex$^ez^1RlEUR|-7LTFR60I# zGF_i3bA)yih~b&6KV9j5|Jr-%7@#(Kg>u=8Luk88kyp#EkiPL>u=ex)}8gPbWU0+`iCG( zDjE+$TKdcT$cY(P#EuG*f3xx3%J=lLkb1fGG~&wC3#_->m%Y@z&zA=U7txasjZF{^ zrklMff1y%dA0URAk_jV*C*I;xU7D*K|LBWS`Jo`L6vgkUNj4(Rsyd)Ua04iOcZTc* z-`&kmi)|mmBxeyt*S)&`{3iZ#W#?=&?FtgoHR=(+M6^OG+Uq)g>00WzV7uVGdzB1Y zz2~nAOL9JfzN7wCMzXiA=hJ&d@xn1W8@}l)s-Dy@?<>#xG<fN3b%bGi%m&XRwb@0{ zIBmEbEA!g@sGnbmdgU4ZzT#Do6iMW1OTPN=37Q#O{*YF~rI#9cpAm9$l51K*e!{T1 zuWwM7c9%V}9@J)&9aV@>3(xG9J;3_bW}@C|c=|8kyVx38?%C03%6Gf!M2$`_2?huU|uyP|%WbbUkhQT}a>0=1+NtK*~{=Q0L@3~6mqx`)hsIXMuhe+wm z89ei`d`2hu)a+cs5Kd~f=ETmBH2)m60)c^=p;{ML!6n1zo0az9N+h(6BeIvC@Xp=- ztTrCt!{pXOBw(|q)wxdQL3j!xJWs3uwom%|$abeXQaUDtw#O|P*9xB6b% za#~lXxP_i}R}&#hbP+RIS^sDxPMgTbf83$K4GUtz=-6oNP({u3+ndWPSgW4fk*)Fa z)j0(@gX&rZ3d49>+`Dh>WU48> z9|@r&RHg1+o@1c1QdE4MO6oGyZZ^;JsZV5z$GBYMHP1aZWqXB8y4ox9Oms)262HE> z&x7A<*A8M^H1-*&Eu7%@yRx!c8$Zs!7|t2uZGzCzi+YZ&NHe$n8Lyd+i8YuXU$17l z8%fl3X7G|^<#im*R0~`U`U)x)?3O+_cj*tghO=hrQeoan^5P)pz^jzVy+5S2u&3Y8 zOdI7!6rL3lZN%6U2ddGdvLd*@preUCdP)W8cQUEC(wIp_LehsB552oT7!2&~0gWE3&ICz9?D31CeX zoSSxO4KLNU2ol&LmooQhzp0R8aU=X|?=_#f!9z{xoWM7-D7kFL&8Kr?WpNK!Zq|+J zIts`)_i=Ld^R~E_{dU!gyFG<>bTHc}XK_}p@E0*8FOXM2oXfj9zkky)rDT)V^OAdZ0QKrkq(kx z^)xfg9qb+mNqR3ZC!tSDEz^TB509O@+yLU(+&>gf-EoR;XcbQphB zoGYGqP{4oo%ypl?>uFE&dolE1L)#oPaat!e|JTh5``pK0nI5#N$A1-Bu3^-#N#(3j zn~;8euU$sVbN%bi9F3CxEkv8{1oTK`(FMvFh?QGmU*1p@HSOr9e+DLu+BAr|?Mx5( zORlx#N5}`s9^$Q#gmY29*j^$?#GnZmsZt@yyC}cQ9wO9K8xjRr)){8S_Lrn9}K8;}@=@pV6`BqpI%9Y?$Cl z1t#Ft+~EH4_xD|QGhA>__oqDYwq8A0oVLAkI*~TXMfaer9TuXJAt;KKw)2+!&wS1PZ4`5%I z^lQkAn$dU%fsZq(dhc|5Z{U?=g5sX2$n z#nz>8q%Iwlx5F-7G_x1fM!m6ABk>fA{E}Cc8(4kZ**Ld0TtYBq27{!2pts(FRt?_iT!P1qBA>7s!CX;#kR(g z*6!_*?p=4>wbhB}oS+L{Fb?*7IZ<{i%t((b$}gZ-TtK?);`8M-IqY&;3?!-54W4I} zF)J>PN#v3O*Cnu*f!WewI9FJ%wQG|+LBo^{`qOmM;f1Zcx^^LQM7VD}Zp$Rw4qFOt zJo=@Cg{e!arBhu~ppzy(@6rO&K5?cS`HO9Cv3Jn%$P8V5Ayanrd9##iAeGx-C-;K4 zH$oC4(P>F)EFH^>Ryiye|IGqtSJ3LabR-PZN!Ae>zO_AK9{d7&-Yz+&Zwe4kmnLUe>B6~bJN^=^8Dwyh6olQ6ohesY1IyUp%4W5#3% zsn(yCoC-gQ1o5xaYg{F}M~URz66fF0&+7Bn3d@UE?(gOX=3bV`%NR~l?2O>uiz~ov zW92_PyNJ$Q_hy+EFEMiDO66M1*<3nlj5gW0{@)W*AyMg9WY1^iSYpu3EuSVxycZX% zbuo@ZrG%lZ+kQ*oza^3qxcj&zwL-XW6eWn9|33>{2X!QnkwTH6RwT-_9FI&zE?E9= z4EF4F-xS;&90r*EfxlOawmn`3`k`4K= zdpCS7W&z0Mc_us6{P3u5xk|5H1>AXuX1o?7j>M`afMCnYeZ1m6SIOeO9m!2Mj=ieB zpEQ~X;spGA?}G$vZW@xsG0TtjRh)VH@cS03-Owfsw2I%&j2bTYPenlD5-_g?pv-;T z{>{Y#T!NUPMzzWuy%!~)i-Ge%^^DJkewj&=12~6{HT(Pe&WBJtbVo6BIiPuKlu5Q0 z-t+UVe7y0!<%_B0*Zlx5q`!dW$0otd8J)%tUmRa;4?b@0zKYHNzPh&mdBjH_u9lY| zM+G4vkBGiaU_gq>Qi0q*z{{w+r&a4IYZ46(%!odCk#gVhA=?!MPA0E1LS&MYmkAu$ z_P3m0O#yrXIt3ESTH^p~opFHg*A!hHcO3v)FUTL??LM6TSqLC5`CGqM={TN~B;vlH zOs^}=9dZe~NR%S*vYI$a;2swqREFImzgNjSl-fJLk4J$bD)N_F#cowPsv~Y!Uc=<3 zDjlyD+n7v1{1Zv87k`R1yT6$m$KmbWQ^MvjZHzr`QlQ?;R^HWQw~FLy9j;d9D=E4a z*X1agtFp(FZ}o$PeV}TmLyA^7;3w}F`>E;bZHgCevZTI+p2j`b;&Lmlb35zc6-SDW z1|5lXxvOF9nT}2`L0DRc12}uAAk?kMTWU$0mA46iY>yMvr)@%;FxHzRK0jV7mWy=W zdpbt82I6V}kmygqiDD>EHO(GS_^W|3@%MDVD4)Wyf4j5NP8JGaVH2tc{^o|$P*&&- zK95;wQB8?7W32#tVs&Urk-$%ElJ>9djPdT_7Cy3c{nN=4* z${iMbp7IJ7kfBYwKQB1Y=jgC`+AVNA*nC;Yw_H!fpJ@8qS>I}>t`oAOZpiR(UP-%1i9uk+JC*cZ|H|(_SCg0K2ksPS@DLN z5`BlMaQhjs^s&jd@hU(Wx80WtmZJP<>`vxLIuzg7DT!e;ki$a8n%!Aj0AJq+06?zH zodva5$CalC;c^ZQL7o-5roN+m&9;9@95D;6;dhP?i1CP4hQ1(4ln^(3B9ojBsNSg* zdoSLeI{P$lmrgYIfC!%Tbk=*TbKLVi(H-?=E9Y<(>}zt_ra3bI+5Ww4MCCSxcR|-^ zM+j5CXq7s|Wi^&XGb6pU1TJ-dT7(}$;NZDExO8K#z(!$G>;Y-D#XGLKMouEW0DtA= z%XSF9d}!wQRY=g>*en3Y5W*Iu?W$6%zHgfO>1hp zQjfoes39^nVc}0inv*H#{+pFbj)a6VUOJ*#K04~=FUp56Ka5LxYLfcCQ1>@jMowcj zP;Xka9%sKk912-{O880d?1feSjPqvrw}MqcdmnJvdcLOaVe2+q&2N(+&IG-!a@qjF zimKc%v)X+!!R4UH49D3=O#uD$VaLute|&tmBEE0J6Hif6zC)xXecrRxOr~`ojQvmV zb2;9x6&W60xqPq_mXj?O339eKh)aIkk3^}P&Cv*wp@8s7wXSuuhEriROWfiMGlI97wOOdOO zv!D+OsxMTR4>ZgzCeMW{8TCUM76P=aQf&J8whSRXU2RIotF7NVS>Ydio;#B8j#^}! zPhp}Yi&5gjbSyJj{@CzN1Rba6uR~fkxK06-w7+ig&hND=GUcnR@Xqp6rFBIurWJ-; zc~-fJM^+f!+DJpqLAb|yVg4j2IY~_@YyM+zXz}^}W=g|Jdw|#CyO4Xwp~fRSI)<2^ z5t|<$I4jwGYYXtHO?cUg6a7x{yEhm2LP_zY)yDJ+@uPq3rSOVO?26 zXL!c%-|sPp^!)iEYvoFG3*K2$1#u$MakuRdOXPlE8-8RMrJP8?S*2fTJ@Mu5 z9)H97$D&Q(c2I-ntLy#iGGt#pRS6&Gh*cPW$>3ZwVDuZWVLyASr|xd7xUgtd?dsXz z;o(d&zTXYhh=24<{(fk#-p|MUGSDdN+AHNen!F%XYTej3L!kyZo<2le&K5Jye z=}Kr6zP2Hol<5yl5E*aqE98m`jLt^`t!CFmvuNC_S3bVuj1w z-1>{MN2)bBzRjpUPFBkF8f&&whbiS)4EAz&1O#3aSL30ui@XZIs^WN0ovMZg^PKjZ ztfb5DIJH+`O{pT@ulOW5y{wevv~$9{=MyU1u1;*}}=+B0(O$o*Ky0AX!V8EX;C7kjseV zEk+`epL>9wWNYMlHWNH?cKs&4Ou4A7x-H#&7)DhQJ;P=84xPcTmFj8oj-@H`Jd_0y zPVh~(5O$m3k!Y3})OE9&7OrV=?&WytjGia&&qGd5Xw`1eXq{HfqL~RA_FO7r*`GET z?HABtNB8fs`!-ZK0u~1VwP+OcGnlrrzo^;F1V*b5jf)d9sp9?&%EvXsL!ZIqXKs4K z+a>yY^G75w-9v(9RmjNmKuevGLQ~Tgrd?OLi&o}N8YuGfPF4Fa-X|s`zQ&@k^o-7| zjwLooGudw6Rr88arVV6kzZa=^wDO3WnH2m}ZV zrh1d!uS^sGDtoS{LN)$j6xVShG@L8}a)3cpLkUnP83TE9aEJp=pwEM@4fy+>d>GDGW5O{aMkJ;rExV@^$@o^4C$mIK42KeP`>(U({=%FQ&Ti9oWkOsy0TbRBH1dt!Ov=dHpK&7Q!_!2* zwGRQnUMOC!7neV{njfU;3*^GLKxRRiG-;*0uU!L?4=NY9QsHPE-JtT%*uLxA9yUz>XTpQR0@SW)(Z=IOB(R2RPR_5!lj`22eD%)j@5lYzDIJ zCNP@Q;{&zz8*J`Ca6FgaZ1HtfIxcGh<*Pmdh9xShxu9OK8n8zufjuBjCa4lnRrzxF zih+(1O5?+ye&B9J;ejhod`S#wf}^zKc{qV>M>KGFPHIgDI@?uElj%4UnGhz|_M0f2 zCvyX_Dx%Cwi)j}aWG!FZor|p~HIyF8i3?0|pq5msgw)IcI!O?B_GfqeYz5*et7JYD)$4!VzfRBkQH|9HP}=12X@ z%4~$#UB_!A$&u+W^fLstY!)~o6vsf4<)I5zwY47zm;4&t?l9hOt7x?}u>R;rZHd=*6DV4nsH7i; zrR;p_V&u-R%DLT!YZ%Y)lPnZUAQIJrk*A|Y!!)J%JRPK_`Ekv``%{mTH2*db(gXcj zyVxUWjmw5-M+Z1u>$$?{|64;G+k0>11XvACX3o$IJ&_*6IShjHSg|vpJ1J6LZ&ml4 z{%Ax4@7$70Wp$Y%Bf(+jM7KZ{ZMJa7&feD4gFd&0TPsh~8ewghDu04s*FnrtP=Li# z+Y8|)npwIbqAu_bgk`$RyDP^fsi$>mTsw4uvN`9W28QKS1Xvhp9wy(09IUzB>3=xz4_MwKxq3Wo!czr zOO0gAKSw1&(s>_uG zG$jw~8LOgcN|&h$cq)rk2*5Au00qPGPKq;tBZGt0p6h3VWoaM_wbM;& zCd%9@yf>e`Y-bsueSiiI>162*QFPXp0A89E4b{*HX3r;9Qr)j7%)E!XDq1opg+rD&-* zPCg-j2XiF4>}r3}d3#xkGIoslEF3xBNfZeS@w)R;kv--g-QS(>w1b22<+SkSBzqHt zlB%+qQntGg@9}RbBh?G!Pce(w*>H5{&^vd>Rf-7<(^hJ$idkdpxVSpNKUNkQsFzpv zt|O=Gygx6GJov1fe%>!QEOhcdOv&UW*EBzx_DD2C0fA0wjn~0m{FqA^%BF%T21}U* z3vohzOKn<#R|d(;{HkEV3-G!n3)M2`;38$vc_QJO6OD&GI*D^x#=`FZhd|R^4e3U8 zo1u=hVX{IQ@;gdx+Wp~$!^;<4GsLUlEXtZ1m8!{xW`<+B2%LQYPXb0!J)vW)d-0k zdjyPL;sFw^^Yg2~!gbwxr4fk;W!Lk*=^-gGZfl^#d|Ub|%>Oc8985ZILEs-1uZpJ- z_CGNCaGotBL7W?8Yh~kGF}=uxodA8+e)##gM&^^MAfBjp@pIn@32}=F+Fc&$k%>Wg zZx2#XpAVe*1eShz1VQYg+1(WuErSlhXGpaopM8CP+w1>qZ0I;C)7pMS5z&Op@2aq(n)%8TR)Xg+S{ll9A+jkY$q4TJKOCerVX{M`S| zZ3!^BB0SY+nC)m4mKLqzQ*S4Ti{=u8&<$jk-c`tgypoH+cKH%=DNG>Y)KHotBY!bg z_%1r7r{jE_2y5ETL}N%eNxvVAbhl|QkK9ZYhqg9e9K?wUU7ZP|vs<|4!=-5jMk6FP<8DO8fmt19$3RWA3UnX{NR9{TzJLWt0c)_| z{{$_BVUvo~LP9=-|Gs#DfHBcHvWrb#KsFj+Rl{BO%8rBxboHe!5(g~c_SL2KLRos! z$j7wPB@ie7<-ItCQ;F^p!dYU6WA2Q+C~dSD)}B{xlEos_Ft$nmt?U#a7Xyi+h=WAt z!Ja4s35T?0n_i^ZNWPjHwhm(zH2}Z3Q|_ux=c$AKF7CUzwD+vTe*ov(@W#Ou`iMDl9c$T`b*8gI?v6;(SoX5J5J`-b+9!n7sep$b#Of)~qh< z7Tz_IDsoj(=EBdw2KB++HgSPo@w)%5dm(bMEEezDqOlq@BfukQf>PHg8bXiv2>8}8 z9Cz>sm;ozmxpf7WAFnUrZ5CuBDgb_QzsC@SdjGfZd4pY1fY+@kdg?vSWDxco9ATYd zPMj5vH9tfsYk_&pIEX7!om3Wj8|AQ=3dV)=Arp5kr0Rt`z4~%|GGv%sO~MQugR}cm zp(7+xhjUlEe&cKcDGxVH&nB-D)5Q(n0=sh04(5DD+kyk}Z73~NSUNJRou-dKv`T!t zain^}ntlqfjf*|EXSje;%X~HPdYk~2!E`-ZP*}1Q&ws<+2kPnslhV{x22Aa(Z#JEC zq<>KVtlT$mCpZQMFc#oil}&&DY!Kh=E&Ak_wEN#um^aWhXL+K{ey#naJDSDu*IbKY zNDD5R(tt@Yj1g)8H?Gwv_4h5d^<+!l)cU`n%V2Qqof;7rM>--ABv(CdP9#3}8ZU-U zd>LthOG`W*$Qu3rJ->>Egh(qO#E$VIvV5sd&>va|A;W4K`OpLBnqPpi2quZ9Me_~i zBW*;hBK^OU|9QF$^9=KmcL$ma<0{nZFQ$wYl?~y#81^{Wm@^NlYiO{qLmjf)ReNi0lI7-+x!sZ*Y-6#wijV#iiva ztz|u9e><^4CsnRSJyon-9feLZe+Sn7Or30Vv;2Zq=2E1?4WdFZ6GDOV(zi-S635BH~Zr~I@ z!5^?g^x}JIT3_=0B1q+?0HD)bLWBF#C4B*5An}<}WoAKY!t3>zsaA(<{ui#TK2&)D zDjIguJdOo&B{f>wlQSKkOL2<`0hM&T-|>lq{@&^2*z(vbSLY4Qo3q81=LmC`*fRxZA2+Cf7IM_-|@9Xb=@$D)w>9AaWOWo025E&ofIW`VR zH}-0hdvSmsKLyC)KJ=n4nP6$Sm#a_12yDezVZeASWq)h<@*98P*EJ4+ROc>;TevZx z?0W!0#-zuTqs>OymuAUdU-3k&l(5ZyT>(=dI&sYK-&Z__0hdq=auSFnxlh^Ur#S#6 zrkYE5S9x|bBK!w|Jkt~~1p9Zj!zm`EZ2&q;+1;VAsWb?t%% zac4^ZKES>p)i_{uI}V~=GhEERyB&W6h`nu@OyZ;OfYO-?5OAZ%^el*dfd?2m3oF}T z4eCd#BOc6*{{&QNnC+JShs%y9hdYYOek; zrFy6R;|eV2;Nw(=4rTy7apru#Ws!md5vG8@Sz7CBmv}|ViC1wlM+A`lXK)gR;rh>f z)sbGq7PlnYwO;LCoBFV2J@Nk4Fc;(E;ipoNoECgbT+)?4v>%9|-B=ipn%%xOd?)zt z>GrEBpgi`BB#ru&pFj_mOzo)MPF(N7aoo$X@82I3CkpHvgIBT*Q%tB(A-6n@U3XV? zBPfX2hfANd^h=+exEGI`?2_d#UfmS$DP%3KgMON{FPZ=zWV(Vg**+V3ZUGx7i^$~_ zNv$onYND2YXn%coS)&8>u_8tjv99LLQ@K6<-NE<#IpV$9#}$Jf4K0^1yyNDpysR>a z_;)iYDy{$Me>e{(-ilzB3mxamPc=6^p8UQE9--|w9RmoD;2RHMXEvo4up67x{^fMb zd206WeofU5=yd61VY)rvpLI5MaS1@=x$!yJncUV}KHLOh`h!VOQI|%S3^tuITzJ0r zbvW|}49yF)v7ESOL4lIfmp`LroAJ6Pip0C1)}ga`uf&<{lP3U2@?e~aoqy+Ag0vX% ze*%j;3xIS4N&=-UFl}lkfDN6q^xvJx*oTY3X8ynRhF-}10Vfghy-CNaA^EXv1ybMT zB%4hzk5w<17eFliLMSXt^g2kltBJJ;Rl#~ zYfGTo=({7F!J`~Jx%;EX^KhpBkFocRYAWiwg%v?S2u&0WC3Hlj8X!nFNG}2^h!hc# zARR;@Qlz8w-kUU0x>Th|?;YvV0)#3hfb@JjKF@o<_x`(MFdR5cJjvN-pR?ASbIn=V zEz}@w3)~t2yrFl3mBS}i7K8d~mHHm@$udC6RF7&L1{}N&CM=^50qJ@&H9JWdOsT{G zPc@AxMSE5@;?J%b5`hW028E`N13vGGjYr z&kxN{8mT=a*0dOjbiGWx$Iaw60Xle)CwIn2{u5aE#+nQK3N?{JU*^LDG){d=3t>^} zks`6zquUPh4@d64*+}raauR!N@@B#U@`=jZ=K+Tdt{~V%<6s^DfYv}QYj>C7sKHT- zkaD>B7HtgXwD9Hl>hThxFp%$lnKtyNB=B$>KA+3=C7pLBz*@K)BERTU_?ad8@(7WQ zH})-0K47Xnamlk99ErkfZL&`-Vjm5aVpC*Jx104m@;N2m7|6BzV1A10%7rm3IVlI9 z{nU(too@$PB~JtbsfEDU&3|`iW-sI$g(oq!>cQGs@>k16P;#fBpi<*JN5v2DWEKA4 zGI&lD3i*^5=&Rfu$*x{V0`(=Mg#Lz4S_KV#CMBlp&P#n`2wi&v?vQzH+yfce48CpL zM4@R2XwL5+Z|!L$g07*dP%%S@ylH}KUZ~{pYZ3JZJsuE;gk#S zldqCJU;A02T9#vwI zetwFTtC~Ig^LCY^?|iud>G338&^?8hOsCHlJyhNK^ZUvXC**_`q;NdPmkN0ud`r)P zlc}APP8-d=yo}w7`kq0k1qzw$hy;OaA!O6{=!V2hO=ivQU90OT0LyA_l1*~F_8EBj zSh*wW*#~lXqcH#my=2L+K=qj2OK;B@(@Za!zWwbooc_4Z^5=omgB$Vc)Bz2_rm7k2 zx+?;a7m$U~0nt86d@^JWzz0aTm~7yg@-ugE1J|}f^$ZQ<(QX7@9r~HWOiaX<02Uq3 zt%KYmhFCx=_6i0swTe5WIH@RWL;5eVFG|y);JdWMK4}W)RW9!O*ahNsD3GjxxV9Idfhm#t6bty~Oi4;FPAXRwj-IRuk*f`NVh zyR?RT7hahTHGkMv_{lLkZfSG%xrvpNcbk78&YM*Y-;m{*%`R{PaeQPYdhuxfP%WG~mcHJSFihQ4ZSNq$OjPJ*W(V|Z5_PunEw zBiA0}hfRNeCUs~ZApft1C&3Kg9H{QpeitSFL#g_rE%~Hl`7CPowq0DcJZ`(7kI*?h zwaSUrE$%6!3{`=C1B#mi>Hbm2_f|iLd{^ct;2$`NZy+10Pr_GpeWO?}Ua?tu-G0Or8dxkri2r(7pp&~i*7frCweyJx~1u;l-Kc*iUkQlTi! zu7+UUd%SidpP6__@W)2fS_h1|vCDI3%6s5hdfBE8>Af5CJdw=~PYy_T$du4#v=JGs zT1_=UY>G6wWcmk}PAI)Yt99J`oT-FUqJ;Z66{TFVSkINnkyNXIc|H;zRV#tfxPZsm zOHrVd4|3KYz$igeuV&9HT{!UuJ`ae$r$_2SpA^f`Ew1@AQ(u_qZTQ=jurzpzb6;j& zV&;>}I@Q^KT>o|J*4~vD!+9L_Qqz!e{5Lkq7i!FY6kLH%+Lfo$B!)zNxxB@nQTPoA z;CIkOM_znCF-1~q0 zO9!#x>aSn_eHUl~qVgi;lM!F)erfZ27$uG=i}r>($X*HNgXr0RY~OV?QC*D}$@%&) zu1ea(%^k6HvLvl-V*jtp`*&ag@5|oeWrvBv3y+eGR<0>h&hj*KmBZ76S?X_OAUvoQ z+-mcsb9%8JhW3WxLnki$8oA#WbIZRZQ=9+eQvZE+IuzGHo0K=t#pq-PWi@?G;ZCRd zYYSkib-f7P~;Cc6rzJ7pY489UdD(t-TJ_jeqGNf zN3`z9X;*mnmGMka_x-fxSXlQu%l|n^bl}@dedYg~;pV8PI^yablNb43w|WSbn6KSk ztG$lHTHG?SO5_c(>=bT|v~Thw$7RRz-A+^Zw<`&7QqF*D5N5lrKSN~y6B*7&)r?Nc z@W4@4V?IeYt|d{T!EU)itASP1qTb!!EzLdA>OYGE{#4I!q@L_}13@zLlQRqDe#sfE zm1wHF*^PU)b{55`cPyQ{%sq3fwY#?DD}A_**8l&$XEW?!`{LmVU9Hi6VGCbB@Fg~> z#^<%xMnv%y?;gTsdx|;Jk6ryc%QYnb&!P%=e-t8*bluVO3t^Bbb5DHjIe|61mAN#$ zxLPguk=##-M94?R)M5ji4OAz^K9tXMRt*}b|+IF=U4On^WMKPbK)TvSA-i!+os zM1vzJpFx36>0>k-N7&Kv@$v4fSM4D;?m&Mb*B__SV|&{pXM*8z|MONdL!wZUq<6it zP515XV}3?5Mp=FSYf_Gn^b^!V5uj+?nt< zw?xfRw$>TjcL1vR36Sa?HJamsI%9OvHKtd-o9nkU&-f3T{_pN|Bbkh;fqhZx=rD-8 z`Q`f7eVYDsAQ6}*Sn)QLGSI z+#OHGsga9T@dNb9UGx9YN`wP|wZE}opic(>z%2Aa7?u_+W-luvv>!p}xHUoHHUoB+ z#*SK+n*itO!}`(r)`VhTzvQ%7oLLg@W*%)oa2Si!DEeT-3bdG&1hV!3G~{`!q%ikq zXUF>|BY%?ryT%5Fa5~gg<;tq>$2CH8+xJLu&CpV#l+pr*;Gdu)urNL9(%%5pT$#tF zwW<06{(Kg1EiAxaWLUfGrrH5Iri8AS#-gLVrAzC)(Kov>4%cN=D2$HVCx>ZZrKWdIr-Cd`3zt^D_rWizOS|53n* zoh-%ssr(eaKmN>w#_9D2aoPJkbbL5na70?VC>+%nsvsvOc@52+r20`wQ5 z7n>lU7C?FHNasYb_XX^(rm8S#70y?WO zuVLsm6>SZCf*^R-2FC7%FF>_XX$(v#Rpoc0uFd%6SD6Wtp|g1E?Dswbp?2XLFkwFh zV#w_qPM3siYnI}^fnk|(K*^i-l{#$GG5WFXH-H@Vp@>m`@A$6MHT?#)B_rovF}@I6 z*1NA!bYEr<+axw3kW{Mk-V>nL9LDk^-qwR^I`6E_@tJ8V!H}Rqz}EF(uY)sO!{rC? zlOEchW+S_OBwn-=0-u-b5#9%1_t`{lr{w@wlrVX!8b^CSwp*jKy_Vsn=93E1I#hRW zuyA^N@s#$p{&KNWu(v0Rz0R!PfmQEj52hw&LUP{Vc|zgcMq}6lgM@;5>+c(YF2$H9 zQ7?qt9gL9MC}}PLX6Ag%-jX)s!crg@eG|N>DiwGRtWF=6H=ToE_K3~0ZovaW2?%k{ z(cc5KeJMcFr@->2Deh{63yW)1OL8fubyxLDnoG8$s=d9Q&ol+RuR{BWJVvP-cu(tw zAIbckHV49UGfAF~`5fK7?@pTT01}8#)c!h`T%D$48RlH!oVG4FMG)kVhe`cOFlo95 zHsYb*moHZ<;9+r$3CB_cIkSKglAy2}v&e4#mCUwrv`yFX9(iS-H9 zBv`q4bOlhf*E@AA_@>2!BY%5I1VOoqhC~G*rhLdizXMyPFB(PR=C&iCBS|Jq}fdtXKg&ZGGtdwrgI7+(%$AAmNytmo&Ysr7$22k3-W zbEt2ZaLhZCjavN8-Veu)O=rs?ZIGF;cu7h8g3E4uk`(3EF;p2n?U8uhv)%@){#ZI{WPJ_n@>0@QfIN{uw-$@yyq4OSK z0#RP_#m+nlw7KsU`vA=o%J%H|bzC~W763tb^?R9;1DJ#4+0!=9y)4*-x=>xYd_UhK zI`7_V0lhh+O9EF;8wm3UBZmZtt}8P%GrkbmrmVUzARDwq4H?iUM4BmGDRMix6 zz6+x3hrGn|CS{*aw>w#-^Mh|)n5xvDvBOfXx=K<1}q0*4*s;m@tb(?P53B>?C@?_42&b?2#7w4a%{ZrUsaa$jA))Bc6MWe*9Wo zKUx2`ZYyU#%>7bvz9os31HnaPe~)b~447Cr_0)pp@=}3R0HIPXvnWITRJ*f&OFGaR z@rBIa--COA`=r*qw0(QG-W@4|nhCeRg<$LP zH)vi&Zo|p%tsxPmZGuV40U>HF6$$?+0n{t6P23P|DgQju)xI9s` z-dQ1*_s(}bludp%m%tAiDw!}AvcMri@A!}Tj9y15LqJwk-I?i!qbKtPdTvdtyY+2a4EiqFd@i-zXAcm`8A)PqPJmrz}w&AH0)>AGp#Ztf)Qw- zblG?K7MOhdlo}5%jBJk+FZ^FGJ{gz8iGI&G^rV{=rOb<(m4#}@kos+ZA^1pq{&Gcn zbz<|jLV&`R7E)|8SV>!;F1J<7+KW-P7oF;r^pmr?(zSpPCXP&|WtKwAJYoph)k4hs z?R8#NqO>XN{aEv6V{>L{D$~$NUsvuRiV7m#XbvA;7I6oINJ@u4|5&> zwTxoRXpacsa=BE`po~lkzz|execz56Y51Y~c(9e3$l=gxY5aZj0Hv!C@lk&o%oEO0 zZDdTFFcGi)fZ%PLOEOmQ3@blQyD>xS!jYe!B%-Qb3w~kTE9pJOj`Kj*nT5ibAlm@W z&-Unc%<%3x`s)0#jRRu0rs~V0(UPWxc5z)99wgXYxDH_d|hW?c!{Ex%cjcIN2H z56;k?dlPg+1-^Keei^4bOMAoG+St!wB3P26?{7Af>^?f29?Ie5EYerxTG2;xW!i4C z+I6id)F7Ax^*YTlBsP5CS-`A8w3cSR*-O)^rf<->vnHryK7iauI&haDv;<}+e$D|P zJ}eoh-u_{qwr&4XBWa2?a|5Us#D8DlkmDr3`+8;If&H$vsq?hhvN@B}Rf4Hp2*%1+xkonSfH%rgX4Y_GtjZO&oSDt81uA`o}bIMs*X+yQi zY8xX_*clyo;K4Qh*~4;vv>=F>nQ@Fb(GM)JT!*DctV@5Dd{wP#^O<|Czc}Gu$7Fs# zbV$_h9~o0OTeQ`jLpd%Z#tb1+1;lSPtQ;JxOzSi&0@{3_+k^;+`<(CkGS_TrI0$Ir_ZzyC+Aclew4QDFN6!U7| zbN`g}Q(Q?W$6_x|b zyaNc>>eBO*iH6?ICrdoU_$qsVHje^lBBvFjmBK8Iz6KzRt?gtY3Q|AEWMkzBN)xyy z&%km$R|^GvnLB{2J6;tNipc%g?k!yG>VM}^wQ2ki7`n{U@yrz^mlKE{ZO5+b8CYMk zRPiOocKsa~=dJMbXk&4PiUxgXC4bvLK^35|liR@jXVN->s$ab~e3=X`_F{PqQJ5ot ziI`7DwIF@og)F1>;?mHiR`d#Y2CpA0Wy>GOc9wYP~Gzqpx7m=pKFGF>Y2r@6P4UwVHbOg|0ZUCb0O0Q(wPrT2}6~)JT5d8z8 zx=*LtRy5y2$+`(u?rKWjIVE-X6Cbi8Vn_qJFv{kDRQv-<=urBGfKLDlwI zi_=>ifXx6=!I01b)XZHl;Dx7T`k1Jji2sSGNA=K2{!m#6UpRF%Z7yPInBLlUR^cjK zcjVB*mAV;q{TeiBn$N=EYA78P7Mr${&&>=A2px=2GTPY)%ZMlTR=gCzZc$>DRwwSY$?NgR9^H2&v%o)HTVgkJ>q}-%uQwA#5NcNx%?7(S2KM(+t5+i2 zXlgt!Hq6%URN_d;p>6=5xXw{$$;=dRA^>_T6q$BquvtZKjS~4O5B8dyBx#NJqC$qF zc?f>#bZ$~jn}1bOsdqIIs1y$2!z!SHgX5DtJ}@TwMN0_1N%(8U72?3A;gP0>yA|l} zhqbVNvMMrk>~d=+a48o)J@KMm%omeO+ttmAk`~xNPEPN%G!8$rBx4ReWra!@bihioLJ@(iXjC+E z_e-P1{7NFyK%@ud8T#y;Q(8z-o8}}$Vt#Pk;*d4e5q!B@>UtT2K`&j+b1Z|TDP5Kl zc1~l^e`v~k#Tvy2hLKP9hTy+kv4*^j_by3UI#R$D&7Db-&>NDN=AuJbGY39&AOdeBR)-aKNI#v#e4YL%xN@@QBKge_lwD39R zHNqom89T6-Q%AGM=6B>=Wy99l-1t38WC@al#)Yg>d8Wa>wJQxONInUub?-F|&l{Y^ zvRmDc+zfL=)RqpVfvD5%Mwzs%DRp-tOA2Rm9_r>GqCInWe)Py2kx{BZ&D_t+-c$Xp z0iID6XvvCN*-4>ne&gC^nG^e1tLaJF+<2a&UNvI=)Trn(lS_R*RXq3@QH^VJcR!T8$pA9oC2T&@wT1KL;d_mZN zixPH>;>py;Piee?<7N_;am>YO+{F$k30?a;s5#QPClWU>| zm)jOt8^kO#PE`mGn7aT`1DAq!xVTR~9quZM^6J>zx#~Y+mf07#VeO^^mkh1E{0JO_ zfjhucYFkT-P@L?BT(1(k+^ZSxYIqn5bgLxijfn>MMn>ow3Y>^0q8oE8``i=K|K`^A zoE*b{-LwhazAQT99`NmDS8~&7up+8#o|!L1vEXTC$+EgIXM+?1me1P@BD6D`PU!kjrHZE0kyVvhQrrMXL5w-RlgFAn{L= zM!z2q401RRhp#*06t>+QdjA<-@6v&N6#@4l_EJg|g-v z$hy?)Xyz&NUwGk$D25)NXtA^hVo6l9EEV_y&D&oq*k8DS^ykxF&m|2+A8%%-8Qnoh z?782tzficxGe$y-`dMP32(42hla<~7Svo3ib!K#Ov=tdQcyYSc4FCAuOgMYcNVIhl zI(>qtE0!$h4^VQvXs&d|y`PUd5_y@pkGrgs7Fh6l_@gDo4Xqx0s`WLFxHRcLd(-Ql zWb-)^kI>_Gc8WR-e%vy#KaV@}Fj8{fmxE-&xa-c0{?hJ^3~uRD!c>h_y1Nxt#FlR~ zsGW%YXS;B&D_{h|oaG*FYBnh^`)gMmx~~m)ySrAnHEdwSV#m9N9|!9ji=CA#ApHW` z0jw1bou1}i${{8bNlTsgc4CIt!4aci(XOYNXEyruZY9R4m3S=XL`L`u=L}}HJ#l_! zS{7by-gk~{VS8njuv5U$&&b~6`ji8ra3HaS>xs0NcV?9ZLl2O4UnSl;B1WGWiMbuk zT)=Z$d$aBp6GKFxX7F>ykFD#=6@qJ;S*FDqmInMX^yg3Y;YBpWuR3&vx}GwQ^VZ6Q zUl#vFY<{*uO3a5h&WH^9Y~evkZPO<^kj&r~*PY&OLmFxT&7fpjI%-`0xpOaOAlchh z{x$F@UEce?Jw$5<9Z<;?`N-IpY1WVb7_Z{sxotXJk2T87^R-N1H2FNk6)^M2N9oQ& zy2A8kse}h^5*WPZK%*NXpUNBqN0$$Icy=rSmy^ z+TXvnI3G=N+K^9*<-jKOY1`>;%Pmjm)Mux{QiM+5e!e520%%#cwg{^}pHcuH=TbB==jaGE-Cp`AGzOufA@B7>Ly1s;E4~pZ_QKT7LP?LGFXesAl zvNJp9Zg$d{6<_^eR+-g}Yty_)VXywN56+(n;;!YBd_CpFv!P6mri9XWdGfu1-IcWa zFH=v2u%trd^GOQF0O-wIKoJn{XM&+5fP=^<)dXo?Nk)r@4mWmWA-IoO(lR)IRc5}> z-6IRr+@AQnJ-6Bg@T5u@6V)4vTpp%^NTPcjQl=p$5$s0l$){mwO}hChhOq*GWEuJt zH#L}2cKxMC?C$OE6ED?YzvX-@Zwgg^ZYy)AH01bofL)mBcO-!I*M&lf3GO1pcTgrB z9b9h`UeymdapRVr$!Z*3OQR5q&2+hGvK;SmJndd1o8mMexIb8wA!NVX!_m~c07)PU*AYmF;Fm!jfS~|4qm19A8 zT50a6x^d|Wfin7hYNR7={g13uPjd@E>{1$Xn{kS8nPHl7uQgWZyWZ8;@=D>KWjfIWx-hE4JP@P7c#L63q31xrr+-M#~Ktnlw{6cL#Fnn&j-8 z%d+Sd!t|hpdff@TIz^-E(Em;CxuFNR2DogvfGPRT;(c1jo)dT36t@o?8jfIu!ePnG z#Nu6d_qJ6~H^#$2_MfhoaO?p()G1}sJFr;6%e3lrPfez8&g9`ZH0sPh@}@X(eRjXm zV?7Z+--~UIDbh96a2b`>YtT6RA5fh@$$)yl=uq!f75TPJ?B#Q_2e>vp%5ewUij+C%P!WuC0;!07ktA1to=a_iC#1;4IYXr>MsTv)bHL-Fvg2w*S=?KNUJ58t&?~ptz`T;u($!-23#H^to|2YhLiSfqfu@N z!J8y7+@ZTaL!TZvd`T&M;wSCZ&5?G}3B&l;RlZxRmd2OE_`8y(q?U1?;~|-ECNY<6 z>(qZt)mQx$*bUKKFBaOpS=i5?`FZ=5i*CYf+$bT3smobGoj2@P8M4CsTDvf+x8>+} zS;Fj25at?jVel6ra)l0+J=aFgMjl6BTAs#XVQw#xvueD-$zT89g}tm>Q_K4M@MHx~ zKZDdzs6^*6gvoTAcwNrjXJ24BFf8d=bg+BD)XTAnReu%hZzm@Q-O+caWb7gQ3+;I` zhz2bU7aT5jEv3Dp(sBT}#KH-J@C^{d$rsqu4SHG|QkK^dwjdtLiZH-gVOu%T26U2@ z<+bGrV%CrE^6c;LTg`kUOmq@_h?zuRs7St8z2m&x6JW`O#WDjn%ns-@^9hru2LODD zNAlxl-fc}ZlEQ4B+LYd(oLRnWa=?U72I~J9q>teakho0(d6_kVk^+MGH=5@Sal{0H zti-JQ@Tj4+0D<_h0ePZJ3C|Q5#a_j*0PjA6hSe}$(6}ozm}*Su6oT)Z_+}Z8RJQ>F zyf-5{$`jl3&E4$ktbOS_nD#vDgp48(;#qdK6YfL)$?yv87GTWr< zEXCh_WWhc2I@x7s+3LPQ+L;zeRb+Ylz))yjP0wE=6!_3xp{+cXjlytHG-Taq45G=E{WOPd)R_ zI}Pp?;|%Ia%Of?9rz%R8;1cQD`U2FlbHEl~8;=3L=dnosZ*2Q4(yk8Q`*zb6$=oU@ zU-3)L`&}K{x6^qt?%_(%U$1>FwgU-Zf`KuLOiddAHd6kjwBA%?Z??Vu{dBi`6Y#`U zga}e*U8&_N&5D_qrZY`3zX_9{zQwEuNfmVSd7WaO;ZjX(G{NatTw^c=m{@D!J(c4Z8zIddZ{uR)Lz;S zGZYE)m`GTQ>&Lnbi27(Wg_ex+49o$BOqHR&TkuDL4(EHR$9qu(Z<3X>Wva_#wToSbM8anUYuTfJM`)i`{b~gb!2#kS)*T23n}NW;yAhoO}w$;?1X1 z`<=Y$;{fA(M$jiso`c_n_kCo6t~TFH)jZ;C2auE9z`kAPDUiW#67Cp?hIe}_kwX#T zo0*hDWhT(*1wao}08&Qo*J>Aku|}Qi$Xj4cuF{@b5_0sW7`z~)XZg`gzpKm z*{xn%LfC&_&0R$hI7^6(g3ViCur-99U_H3jZcb>6eaJyXN;>rWVh&{&hvvz_rk?$U z65E(}E17{jk*%ecuo5qtvy^bnMn@i*_5=@YV-%x~;FJQ3)osUuas3VbKd*3d=Cfo6 z5P$%Pgp!0^gajJVJ5Uj(nh8v{*wT*0PjK+#2SuUGJ) zG@slnQ*lZ7_$}3!tb>grSffuGMaIm*1Q9(!A$)WNUYVGt*XJ^twNCnWzUDDqzn3qb zenELmv`FkUy~1?GJE!lTP*Lok*l=mNDF{zK=BOl9;!zN8t|0T;V`;Lje&HB+HovxE zn!^0OC_^?~J1_kLb_VDmjWK~R*a?uO;i<-GE4^_6c=CPBX*HN6Vu}p}J&zIW4H&G7 ziL-6O4oIn-r@oowGv<9led4qJtJ)Ex>$x@zLL3%_#+5hp!XPJl_d-0{4u*nTWVu<| zPr;?7;TdGo4=nA)QuP-t)4y#NG)PJ~zPG)1dt2`1Q@+4;(WNVW)|E@(R;@AS(D$y7 zeXU8X)fD-}zCTT77>EbFMe|`}rtaVV-r1XT@>ob}tXxkSLR~M?-e_oNeRrD$W=H4f zE@?UrJCrL@HcGCpIRf;5p8Eo@mscCJL{GW1$c&JicDwkOA>{VFEWEzikDRnrIu=a4 zv?F%@<6uL3u%WC-gQXgy>a*<{2U7ImeH95R)n<`pxn4&L*iQP~ant#Qwcfk0ZQJp> z*F81bW6y$27w;;2E==gBSQ?S$lj0UFSZpY!+9at`-rC$*r%Opr!ETtcNSsp}Rn^QF znz!Sl)@g0o`kdFgJlUvoU5Fb$0m0E%e&VDS3cVZMMr`f~+?96s>h!8aJ)5uh+;>LX znkug2Z$n*&H)Gl_=gyQK^Kmz}(RAz!a%L2o;3r8^099DPWjY7~db@zZ(YrY-uo#M<84Zr;+5SAMc;GG?-H0OFqx%*LuSdXS;J2-6d+dWKcHjeu^SeScjCT)e#^+q;ORORW zGcJs3X8B$AmJ5glAG}5-wSr|abLYOf^4k>2JjuV3c@sj+;RKPp{}SF9`rYQz^G;3? zC3BV?$Z0#{a-77$Yj;KtO=RT$GXAPvxr3|@4_*$c2_*DhS2THmOxv(X6E0rUskEi$ zEPug)MS1RX<5y>IJhe~!84nqD+RT)qsLse9F?PDMXq4yO?^)+dN`8q z(OT2#6^jeT1eo@OOX2y$n8wWI6-)4hNb~aBpXEH?^Np#Der5k<1DopIPs9ivdU0y( zq_ZAykLj3VnTzJ9vloy3O7=>6j=GKnOj~LKyjt<^s$cHF6dr!*y?APRsLf$?h`$nW z?0mME#IDj^YUy<>dO;+>VBw`t-=iXz4P`Hu=d)JtBrmTibXSF1i{PJ}a!mQdmM8tU zI?as9)G9-reR1)XRM;9=Y18+ka0jg@Ub5@{ZA85?z5!P)412j861sL>Kjcf^$sK43m~wuo_I3Fp>UI=anOd~=t9G=BKCQ0{NN+MyB6v=|ebg|YR#1jU3n z3pLKt0Fm&cU(v`>IX|i_lY2xMDUSn180St$Papr)xwzU8UsC6 z2GtaSP^AMQs<7ZqFi9E--7wmy{_J$IHFNRpYiD3@#q6Zwbm+!X^9-ZtocDJ`Pdn#F z<6g)`EtWjZOG6UEs1XMSsHHEb`P0)kgYwNs7(dj=H=%J;GTsF%gSi!hI9#4c%fYwQ zng<<){mvUXAa_YV4`cRp#)ri!-@c)O{pu*Qackp&Em0$PSFL z9XtOO!z4aEFkk&mYt;WiM{)SCxukG;%*zi&*K90v*u#vjT17bh-XTh7r9N-oU}|&; zyDYe$n^uFLlS5ugUKeRk!qY;WnqtG&S*Jo~X_#T>az~mhMUC09L35MYIt;!3_zUf^ z&XC6bidb6MIZq~<#7EK3hWvaEr80%b;cAYbOEb{Cq+__$-n0eHHJ33)mPP^v3jUGG|4T^Mr z%^5a{a0x68P<-5qc}8;1AA<~MIMKq^9 z;^f!#Vdn9r1@1Z3O&!rgaV_-yd9+3Ft~*vkEqj!PSJb;>$4u3v#^~D~x;&Wh)4#>p zaA`UzgVwiW;d$5nhWaC{&YBr0uMoHu1s3 zfn%%N`QG_$sl-sM>C6R7Cd8H%qr`n~?|_JgB{fb*LeH+iFCd^!x{z zgPoeg?eQ_Vu6tH#l03%iGrlZizE9lYPHVGdALLp<*kh)+tQm7V2M1Y4027e0;$ev} zqpLKYr>2s#<891PDKbbO{*(s-bP#w4+X(qAWeKkU|6`5;l)U>buttI=9FRrY_JdTfGeSE54ztcX(#>gJ6|M{nr5ndKL$;Hz=ypf!8+os z#wdX}@><3-toi=TshUVH?!l$Ersr!aNE*F0;KhELV_r1ub@{@V{?YWOrGvm=NrxI6 z*h1s|r@S(BC_g>rgKJ|QYFNhhxOLbjb5TW1uzWLqnJCo!{sa!kuOKW3rGU#mG&UOM zGI0{|U19H`U`gkp#!>@AZ7>!tv;p6@cx5u*l_xB>rMddz2yJ)=aZ4}>{2t$yZ|ajjH_IAs&}9d(9zAKx*Asl6x=ZsMPJia?OeQ>vl>GHG za?l{RFX*b5a^mrTJZeo)Jd7nToD7qay@Pzx^L0?ooHa6ZE_+8K)iKCM0!s`bJz&s^ zK2ys|b3NE12t5KkGz@p6sd?8ktKxC2%Cq!)jE-8R4K;tr6sfVap^tM%yp_O+W4Y%F zg%7QWx_zV1PuYyO!FWHv4|Au>Uc8wtUQF!m!ddR)^q}mAq%^}_C-OF={921a!efAv zq=d0b^LN!|Po>+=Mb<%VCs7`~#&*QQQ+<-Ho}-eg9;-*W%nMH#urQxtiC5AoUr%8) z$i2f-&%U>nwCwj8@gfJ8Abilln9cdq=PYoW{d6S*UG4Mc5#Io5Ja=WNW!^3FLuNnX zbu9jVs&Lmr!#&?$cm@>Q$z(9OQ+EDvefp&V{fXe#=7Rg8VUt_)fun}o%iztq)8}|y z%OY)~@R)RK{snJWW5BMoCtQUL`EYFsDmCwwQ+SaZEx)fN)WR5uOA~k7dJNT}7k?dGrYs!4}PD9R#oq zyqP_YOS!NyPp{P72XaN17W2|hB@nqWonoxxkBgp=Dfe-nvbije52^f>px@C+p$@Vx zDvs$Vv}xba`G*Z}F(r3-8}6Us)z&IS@L7UPmr!zrwf z&?FO8DPK2)*1BYu<=RECFT-2tTow#l@CXL!a+2!v2NGcv>tkLF>Fdgd4z~}(OSZPT zPxZ%N9+11d#5=KMF{d*4>BRX7t!Gtzbk-fa!gAFvWIm6!Cg|1qUuLNxPBw3A2D2Ic z()9eR*h}l?zf<&5vdS$NPin{&e^*~$F}hSFk&S5(lWU+O#$`pyW01exNj2{&0e(eE zwDnGF=`mb`+b>~PxiLY%b{D(c4PtGMgbVKoXv>TQ^AR<{-ChJ+G^_U!8Gk8CG4D{6YDa@omHsd1)aHUkI(nx;z^uL1ja7sKbiz_1Y}+U?Hx*fxsX+@4}zrMpo+>*qIQU(W!MsxAXV(>+{dXgLy`2iB^8idgC6_#weZuNTu{bLd(A_ z1D`l~3@iL^=9=0)Wg_KnI!W2Orizs0U30bd=3Rv8bzJOdJG@vw$90+eoSs1j^=m%1 zPFlX_t>5W-o!c*=`C9Javs)Opn-Igq_g=h9)66DKl!mBGLEkAd< ztD&|j=Hqu-9p4T+~{A=fmd2&9ut<4nl3m{oJ_Jtz0 zROhZcSDa@Y;=QJX{w=A$Wg2@J`f{N{Eus|3DD&VKx|eduyYC_jxYKuR3+{>fJu)qh$cZvQb0S`M);Dm*9L14>^OhVZh-{if7 z!S_qeZPvwgZ;o@XIKp4L)!l``xKqLdc6T&oX*&Pvube%rBM6O~N%@Wrxh!xBPdtcY z!hh`UJdkBo^)*@u$FwW6s;W!FKr*{KP1OF*$G0BaNvt%oJ!Zy@?x*RUgb1u7qiHG z9SPsGoT`vJWE5Q=AWb+bf}RB9?!ox#Fkw=<#^YM`3S8cu=Xn~k^j*g*sl;7o_-}%J z><6Ul3)e>6$r7kzcSZDM+j{Sgx2MD(3k$(`mfV-Jde#(><4&>>aeV79P5*%AJm048 z{v6O#!`7COE$&yf@W8p+SfaOoOKjAJ2^NRlpF7VbI|&Mx(Bpwg^Mo<+x@V{2G}=iq zjL+P|wJd~l0z0%B>`0yGS6{W>UnQW?06cAIz#X zLul#9c4R${vn><_iJ&@j3Im+ggz2~doZ7(E?iz(GV=M*ihtjD7tJ`?}BOs$G40nFq zbgA^GqXGiLDvkKSa6rBA9`DMH(5BrjI9bh07YvNcP$qNCVP)_0u)D{`i&CmI-V+?X0Na^;~v@&D2-IIiv>nehUn{)Y#3hVLU5 z4TY@<&{%fDi=!cB^Ek}5Eyk(`YHEl%t zu~xdQOsYCFtWPye>?GElMP`R^?-!20?44^lu-4U|VV3WWX`zBJY3wA$lj&ABaRtz~ z)%wv6yPM>`z7>6>w(7(QSza#?eqzG2{z`K|Mfur)!z4J}dO}2@gCN;52SAsK(9Iwb zVn!JYMu;Rde)^*RrH1Q7p(gai7iA!<==&>>4BEg1#eY%D`5OE6ZYZwdpBp3jdXm{( zh?|#0kXx5!`255eprLSjzLOX|Emg=PFxZU(SeF*$m4ffp`TM|;1GUF7=WoV9+pT0zrXAeh;%`C}3;_$(0yyXbC?unddjL~3!SnN!2V zfNs)2!Y2{);bvdv->9=pOrz+D2*U+3HbvrlWpo?XYuT(NAgivAb6~uf>}qB5<^sZs zX~HC~Q<*b;pL2ILvG6k1%9&&mutI5mXzraRF+UHDVm1(V3o>t`^GU_E`#taV965iX zn`V@E81`Kxfx<548Of@wlR%MIS5><+l_QwgHYDb9FG#?h*jpr9y=JH#nWf&?+)djc zJr6fxps7u%0(ly5eHp*<3?TkKk*Isc3_FOFzHkZu=(qrxZnp&O^-$rpg>?*A z&5*q>;mb9_vq{gURvyv7-ERaa7DET3y>EVEU&}1Le<`~5JCk-Zxq|n~wuO^4L1g}t z0uBw_lXqL$e1^IaDyn$7J#gNJ$+lbvSxotWA&yqT#@EE5@q6tBqRQwQ#+*$3FsBL` zNtz>ufXSMqV+{Ds>P42%(IgreWBKzh+;J?;9UR@a)MC9sh zjJ3*|%W-rt=6(@w;aW#7q7e+IN1?9wW8l~u2V5S~uO%7f zy_=%+*E4-fwo9l$f0@;#K*=$1a~4^%Aw_(xeWba}?iL#rBA2X0nguI?B|7m>d(rp* zQT3KlQFib9_bs9lk_HV@BAwD9ARsNF^dKO@NP{3Vlt@d7bPh;~NSCy-$$W477{PnY#XfLxM>ia|?{uKiGEZq_-x1K0K6R-5S353ltj2fpSW=nS+e!=#0QO}Q~%nyKr(@}^aFwX)-wk(VBP^y1tN z;(Wazq77VgYWvaxW|2u$R3ed@);X;K6?9>z>H{DKY!9z8f_w|b~MRi_%HGuQA@ZNo}tgq6yosW0cr*~}yDGhp=Z zc`0&h1?pI5JUjx2z90I&OxnbRc|ro#Y!tb0mFMZ}s=6mc=4n`(dHJ?fMga)RplN0C zl}S?MFhJNM`v8^;)`pSM3i{D zFV4Z%F`al0519vMOy~vqJ%CY}0Qvg;RAVP?A{BZ-(`|OU%_>yp5Y( zUGC+eap2e`C;g4_+&R!k+Br>T?~k+8y8jub1YJMbuYEXyY0NG$JKcS}A)7?SJCfR) zW~oP1wmhC(Vh;R2JQgcx)zvG!m*MlPMQy9`mTFEE{TYIJ>J12tNl{iU~fYtp=b-O_7zs!PlB`5QBAH~EIB?HA3$l8VV; z3bWjky)V5f#)}A%LCJk4D}zRn_9!pg2h6L-6GZv$WujgUP7K&+&9~9+pRQ>u=vZ(HRQ}x&#?VSG26?c=qMCqDD`SiGGh9F7N}$1f z5{lDWT0$FF8(C)=#0_WtG)xt4WcwpvPBzNE^kW^x%inxoCg5MTNlUrrC>Z2^_Bo6p zP%C%*=M80gh4oE{6-uScqa2+|X?O2=M(1DV>cwTjFK4W*hK6SQ34f%LS}*wUwWZ;cWd^6H+tkes zG4Hn*b|f^78S3nHaB^?*(0k=0Ya+cfLM6$H0uMc`wta_i{e)^XX(e;^-Ko7}-G=on zZ%R)dtRy!CD!9ua$Gt=l3_{szLf`mi$5I84gG#v;78A@ol7SLv6>Y9dJl#8t-t0~cp7>st zYw7;I(v}k9P8lczee!jvr-aT>^{X@?u!*q#4c< zXxw$S@MZk{4hDh{^ymq=j4H8luR1rKnT7lj>b|SNX0Dn9ZJgWlPS%)j>XSuu@4){1 zYTtv!t1If@>a9w6JfJvHMSXAhXV;?1CR|KBVVNU$1*uGBxtVpK*7)+LR9&otm(SJ+ zQdxYh;r-`Ih|FO;q48_R7w_dx2KNzFIfwW!nwmlJB}n{wfaY(_1;GR^>gae|Gw7}03PX}NHDy{ z#6t#b$UPxgfrqid`~Y097Qz`J9f+0Os5)=wF3RKj-y;G@W!D@I3pI&E@FT?#TFX~% zB;*&x$x(U2Bs-QYhz!yKlS+h&$oQpk@0=H}Hv5&Y<1Di4kYnOd32*DrI>6_YAgGjIEV|a*6PAYc5XwHJyWrDm{P|RwSXt;+0KaDtZB!%@9g5| zKZF}Fdmk7_b)QmIsI_6jvRl|9ez%k-D@SBbKX{1KA@>!`IDB5pkE(gQjoQpDG$$nyb#Wxpp#La9wZ|z zjql%hAtwW7?SV)6VriAFIjG{0qqnHY(=4OWQ^)%fS5tO~W>L3@AF_}wTE9p9pLfgb zb+u^64#V!q#jBoHrjbVFICoQyJr`lWwNI1!aFQ#C0Xy)ISK*3n#pHG2w3oBjqASn{ zn&%s)Lv3fy#x`Et=@z2C3T4GaOS*aHHDe{tqp{WqmF3}U|GN)p4>BeE@5ZoFEUfr6 zEVI91OK=^0Ua`IzMy4{grM+pXB0cc4j+E9$IA2q>HS*PBSKjFOP!CB$#*ud z%G@$&ZAGmdjbOFi9C}}W@4k{{%>MHCF$4bsDb!{l7=3*TrTiOd!sjTEak-5x;^~Qt=C+Bx)##W%F$B@V*l!uA|G8yhZp+jbBBd5!;wda zy28H_tu3eirhFmWtCR{9VC+912AEo=>--N545UtX{KxFRi>C@!v8{X073kfa-WI%p z!tD{=D;^bKZ%xZE(vx(8L5j4IhE-Hy_jus{HM0XtuQt}@ZzUuw^GMgy|!N!U53q3EWxT^|8o!jy2vAq`6{S2q}LBn+u znw!BBrGqzyrWv2eD#L`D9ecg>7@JXT+1LJqr&?f+Vue)wSQzO4_J8*^9LorH)nPYIf`mmG^dMAN9?hRwjkR-YW;ia706vdX1jE6=KPEdp z#U2B*r>Gq=Wy5IZ1&76nFr|~{6*PMGsKc-^uT^ocBCM^{LYO}^bb+yEuM9J*Y~(ZB zzNbJD9|rZIwDV0jF22q2-}~00_`$~4&ygV0aUZO2LWX?4DMG;7a@Q=qaRwGwkvqQ6iBwK(jXpj)5@;W3SB<^!=JSc|S67=U z-)gmUl-ylq2g}$}PukOUnAEcWS;0yX_ScSRA%UJuoXVP!4MdKq1lA$UenCdR*d^En zwuEiIWUsG+jFfZNqs=f3e`bE>KWfUbr>P?Uw&VvGtZ z*(Rf`W)6-##%!iyRR3LL)I*fPsWjzOA`(C1p(dZb;h4I3l8ssem6FD=5ITr6@^`%Q zlF$>HcY1Z4dbGrROFELttR5gp9nb zFL#fmBNGG(IXhr_wB0+8cxBPUF{#|9j_Tc8b7NzaL)E-B4_%fU^hJPcqO>Y~?n} zP(}*1hN4;e^R4Gn*B3PRcXoP&N8vY%g{owY>^9gxQhfpF=W1X~pH}5af6l5B#naVe z4F(G^z^6XFKW=VLTF?V<7j__o$b4OgPT<)CiC6Q~!qy41+jE{$hhg*8<85vB=Uu^* z86b?+4iFbUwxQp672J_A$fb2k#tv$Q?2T!Wuve2hw!8}NR-Zb@KgfDx^?GJw~J3IeYT0Qu2q(d-4YxdP?Z@B$BE_j!tl&orsxwf>|LEe^Bivg>c^jsS}}JIH6(dIQ`&Ssxxp+-SgAJdG}*FV z^}NbbiqyyTq1yOO)l4&8f=bKO5+9p1neCm2*m3vEDDM2*8+_eRH`8d5z?~BhtD&Y_ z2#qvoz3jGXca5V?$@ok)`RknxD->Dcf%kZ9YGGcjj?|W_8%ztKGlc z{!`6>>i5=marL}Iz-D(%XYL7oP2{_!-aq%o%tylK#tg7enhJL32MVfPViMpP`t%1a zH(tb9{axe}7{Cq&5@*$U?z6wW$-x@^+vh8limb*OThgv;6{_v?G{|D&=w; zBOv)2U_nMmGK6J_O-bswNNlbgXT$IS>DmdG?b_ZFRG!a>-@8B8?B(G!eKwahR&1L? zh7cJBDc%}yt$OK*FBydX^PBDVuLuKWj!O>}{Wj`DCQL4`oc>`@PgrkTu@nFmR0)qi>ehR%%glZFolnX8Bq}U_e$R&^&aR{%IaiAJ_ByH2&C^C`Vsrgr!v)bwZ+Iig{X z&)14L45;N#e-K#R;p$7Ps8;gJS0mEgW(Cji)cH@yC z6Hglw8mX-y^Rh+D?C&3OuxjD;uly)7HqD4GuVf6uiWIqoE?~Esop7x!xTY)`ZH3K0 zs97pLOW!=%^T+%tC9Phv@|se=JT?7>FktidL2=bm@o{>U1lrBRIwTb-@v`m1ZQH#{ z*Z^Z_6bM3(%czz7@=4vzoT0g`5s?GQ+zf}3S_Uw3W{4rLOf{z8oiZohX(R92AoB05 zfcAC}SH5&|u?H*?%@6O1pYA+lK09+aD{IzXwMcA~7*kH@c=}TzuGqte0%A{vQ2uTa zx-?GYe=u8t&BAcxW?y9+ZvRFgWR+GTmmd za~nL^d|mV9h4#KrSz5LzkAweRYN8~_TOCH)ugJ@Yi6>6c6;hHKj}+H1Uat({oP_<+ zgb;zZ-&;MrN*|q%iPtagmsR)5C~oEl8U9*gh=&hQ%c>rIu?s>T=X(ar&n?PwK8`dd ztbBcSoWte#*-996b@g))wbbd7&KgN`wztr+}~ENv2Pe&*WMDnXB53vGJ*R9yk5o94gE z?f{UG)(>@+iSaKRGYWf}kblZ9`kO#?gz^k10~NXT>ZOICC?F(=Y3BZDYkWd9E_9T9 z@H-sV>NA-FM1a_*UpVqXF@5l^OVyjEMXYJwBZ z4x@Dq-qzd}%Gqw|LlfPA%nZ)Q7O1Y?@jNjhGGEtA4DO*=G2e~}@LYh2Kqy^Jbr1nW zf-Pdro~Lqex56A_=^%BNY!k?WwW_#@29;0AV3rS4=CFegv7U#OY?+3>wT6DAmiR8O zhKRFKnJhmG_#-Y(?ytX_YMv5FN(34Pp|=2AL{8Quhk#k~12xXx9D!z@c50wzdw ziA^QB=?J<Z|3^?JT{=EhSD@AEuvWT+R3kJ7A{rcA z&Lr3_)KBy>>E0*PU}Ffj?~rW*!P|{sqIU`u3K` zsUF6F%W$7kt9Dz*7@=i-C?bS-iax6Irbaf=_ZG@_=Zhz=zYnqMX2NeN?-&L5Avg(2 z$;gEc{9QO~c}3RchfV0+C>E6T81oA>-u?(VvIbboC+~pEk0~*KR4Adu92EEu={9hp z6fe`g2mv`xO)xcN$6DjN=p2{t9M1 z$e!VVP7`|euWYt#FG@{;Tp4&I&U82SJ=%p!O1rPI+VJZJDl&D{|q#8c(aK{}_e;SoJ(_6s4@jD4OjOTMU@@ zFU#KRneO2nYr;}vXZ)F_0=6PcadSe7TckAzhV!!71B?Kj=!=h&D7f9YL#5BAA48F1 zvmj^xub73+1dQS)N0*OjXkCn`+xqkRg4xH|=F3tODyLnyq3d+(dHcui>iU*FSb^m# z4fxW32=m}3c)A8a5D!vb%2Fx%PQDm1n&x9I>h)!s*qBwJDolA<(})T4IW3JEbJ!M7 zmCPkq4!Yx2i++Udxx_RT;-iiixebJyGJd9^7RK{uo-rkJ87IyUbx5Jg`4G_}GMC)r zLpTh%z}6?i^k1I2$ZcCzHQ>km=GnsTACM$}6SlK}SlNZb`o375mtnTT>!#-q4r=%= zcNus2TG{8*c})YouFAtq<#u67jX_<68XoxgF3_U_(zZ<|r4yVE#TfJ+n@R3?ZFZKQ zBo=l013&dioca-^%@;lQ{r=t~5ut?1tGO-zRm_uC*qLMV<1*x9Gj}YNmpkb6_}|8r z_^PExrV9L+LrF}XdBSa`4=_zZ1ax-UU7F44TsYHncq%tcEKTN=tF7gHmZ0BG(V`WBSWJ}0ho>d7uK`~9oq$gAJEVY^8?_j^@I z1MpH}majbK3tnG;SE+Pd1CJ`Z!N~Y5QCe=|g$6JF6A9k7I~2AKME)3G#9)VOK}eM6 z+=QpYbe2*EGe(PfgrM!Dj;$|=rAJ>Z=%}DSG4aCEi4$}OD3c5_NBd77S5b*mipIA# z95ql|H0b)R$NhL3{fs+-E^rW4Fjl>>3RLr4syFw@hIN~U=oo)wi+5lveQS-uc#MAZ zQ|0rsQ`|syC5ZZB*{oszaY3;tie4MepT;pGaQR3KAk^vyh$egn=m~8oFl1SU0}<$n zz8L#rG*)6RCxw}?!sVXxg!JVCzJmvl3yf+d`ktA>K0u%-9biNJ+986|sci_g-to;y_6mMgcs4-FGqDfy|LZ zIgoGUfCGx+ZQwqyE~sM213+-RKggz&3abQsfNFY^k6s6VE|MLAac}evwGjtWg~45) z)gKqGHsybf(H3M{n*%eNg1P7X72L_e0XH=dSe-pU@k_YM%t0Ot0&#pPU%cHn1N;G1 z0a6;F9C~9K%rLrN4$-GK#*q;C&HTN)v#I!8JpOw5qi9AMd!TLA;Ko+Xh%YuOTNsYK z#uiv3&SKi|ZBTk%sAK7^+FE=Uap4R#o&>UhawV(>fJA!!sCiF9*5be_|FiDR4QIAqym8}sWTWPOHw>rv&%6z{TL z06ZVU;F9gfDs1|1Dwho2O|}1kZ$>KPNWdFrhfnLi?AHP(Hvyk{TDmcSJ{%}QmzXVSaQC!aW0qNr>>f_#KEY8RA5QyNpKYWq*&e(6|@%>KjY^q__-;E|ss z(5*&5G}rUo{1-6bbI0o?tOC9DxWt*!mC*qtw|ERHQQapHS_f=U$yJg@V7}FDoOsP+ za9O_hJlIX|oMe4|2l^_*+-(s z+>BDy8%V+_*PDPl;W+Z`q4+>HKEajXUxSaHQV$Tb$9xmTB`rjbsq|C0+kB!g5Nw1Uu;BWoM_rR~Ab5na(`&mW;kb8Kmk&?%u^(m)9M5e)B!q{=$dKrrVsZ|8 zz1<22dg8#QK)%QPePjSo@K$_2iDg70|5e`&3B!4gzK~9hZv!S32z>!a{ovsD;Ls~VJulR%S}4+kyopH6-s1}A zjJzEI>)`ftgiX%H1;Z|eR2meFb#l%gKfs2qjpxQZv z^Hx7nW>`~tT=D~uGh&AZF0W=$sPkW$?vpjVNnVVjkWVo_e0MDiiP=sw)a%jCWTv0w zgG(3siz}S4+?5vT0g(dpY&^jCgU>6Y0AV9I;~2$H$*{>j&|JZX-iwBO%ImuV|GMh0 zXul@T8Zi+KmIx2p<0QpXYL6ea%G!&qM3uPNg;yg8n{9EXRJ=}v6Zqp=ep9HZ0Qv<0) zDAsn_jf2*|{k{bGy92B8-1mFH`8%@`rRkDH*5BqD!5gUEJDBCP+^t1CjXF(q0tj(UL1vR<8vxxeW1?F(u%&b(QWZl zAB^H6zN?f(4xG))sloBBs;nN7k;?dl-ptMVv!_sAM9@u-PwSFqMuKAiW_zCoH-e~NG_$06UKM0=<(y!; zertKcl@S!FR#;COa%Wk$Idt>Rqs+nBl`FKRo5Vu;Vi(#3y9y2s{2a?R;0g})v@IIe zfj9D;5qV!%Ph6MMgKZ3{sA3H_7Nab8OmF=71)$Fo&pA-TI z7Zgf}EUt4r9B@fwj8SHdyLzYbW{$-n%^eooPb~0NpB&TR!okNcLfIZe*va__1W4K} zf7&Ib(JqNNLcNCs*cp&QK{ch&HE4>AWYE7yJ@ zi+Q5C_>YXV^y~Jf0ns7xWhL6Z+~<&bj_mxcJYGcVWPOAuJ}?0gG12STOYW+l-@ z9y3B?(J7eClSxmq|4^JS;z9QHjGcw$i0+F_<4o(AeXz#3{0aHYO-LKGf&@9{5OHXe zu4GVIpLC?QI!#IHQ3j|TlW89eQm z8fij#Xx&g$?ZoIDW;qfq{P@7o0Rg#gn7&fTi{aqv&ZDBeiF zb+(RBK=n<_?K_*6d5$>Gqt!u6x8o z|JZ!ne5hK;+We8{rH#Av**xpvnak&S=Oh;Pc5~{=>65S1rX^J*5vJ^37!1{c z!T|X(<^eaD_!0>WyPDZf+Q*R1%x%G%wUD0!3hx8uxeCBZ3PK(azt+<8REYso^XO{hrws#T-@S zgW%z#?o%z15Q8@Sx==(eE`P62ZxfZEuLRYj6qaCb#${kL`LWT){_%N}w^8mZuHlmL ze4U2hpJ`x#COEk*XHCu57)H$P{Z|7?xPpsgS^?BXXL60b448%D*Y=oYZo(WjB;<{1 zsRftzT6|s#G+j1Yj42NW?@2mP5ct<1kjegdo~CjL%?sd(Vf0K1U0#K8Kf45#cq}MA z-o@I+zF~o&)$*kQt5XojD)BJM?*A0ZBEDCFneC~8`Elq=K3f6)cS#2>L|troH#u5z zU!@$s(zwqrpOCn);FIwZScuH5bC_|M@{1qvx;VK+z!xH;E87>&w9NhoSkZ2Ejt~pv zsd4MU5yeC0{n>C&)<{IxCsrhU?f>=r<<*~MFjnGnzuF@L--DE!o^Y1d=SStO-d_`} zYY7SyR9uW}K(1S>&zWh%kvqkOxBmZ1KVV^G8JL=C|4|Y9CMIb|p))*7%~C}F~vcHxzB)p77=gkS5EB~)Z&0Hr};V%^kyTi2HhKBKCq3n8T z__2uojmJe=#+dn|@*ZNb`2V~n$hf;3WsiVRviJkHAaMN=GUPs??bYVX)4Qu(Uiafh zk#G0&RAX}+y>&yrkkR+jX+`=qc{DH^(tz>!c}jWJy`IlC zxKh8LemiTQNwnB-G@>={mgxNo%OG?hr>VLDboIK5viGNz}2jyXATi%doUY zp19F}DVrpCkqFi7sp&WcvL(=Cm*cVGVRhcEqy}^x484^D=6s;Z`SCUE)Vbu8K_i2) zDAm~eyW#5d9j>V|b2WC;q?&lWQz+_V%*Hqr`^XErMN`j0)Rg7^~4Z9z@k20!@YKqj;I9#>0M1N_}2j{JuOVLi6s zH)~=~*R=i0acMjqa)7QT>bdW&Tqb?wj;oLDEaTj9rN52}Lwp1b zL)eohF$^p;b|8j43I~t8h35al;L=V3_31&lbkblzN=u$Q-gq&nUI&4G@hioVJI_G| zyuv09G1tX?agVSgfzx1s8{i8l#R!=2Bk|vBASq?2Wo#YlBg#dC9(XnPCt22t@aV8W zeV4}t9lD>>2|K>!eci6&v4d75-Vv?Jq95%oNrllMOrKxp|3oE)H-Y<}{a>SD^Sbs3EFRRg@DOc4UT1@wYPVkAu<=vMR#$X+|B0TW{h z>Vg{Umt<`!`td!tyuz9!irKqbPtzb=MPVV z&d7mVUe(_D&k16GNA?Lr;KN4i zKUSQIZ#;M>RR?Tz0z;~7OUexor$;zrY4N9&`pHz=nBozh{D0!)_^0!2y35A~r?O&x z2nf-d1BjhHt!Q7SIOrImgb_y?l$<~tON(TbsiPkj0UB7X z&z9HEiW2W7ZV#ZNOaSGgTadUD*wT{w%;4uhV3DR1w0tP>Vn;sumW($oMm>7>!<&q5 zrqfjw)teQwiorL>>pOZT%B+S?s3x=N7ZSW16!rfM1b*eYxr*&MK}*_vnEK&JTEXW(_j z>3UA|rc_X=g6R^N$dRf&>YjINQ=30%l#wPB-w%eSQ@$WNaJT*p>%e{;BjOh{1dvVL zh46W6pob2!$mq4IQ`_3>G4i`TyZ3b9*dmF$-^gV~Y|1tpz#4;fgl;BS#7K92M_Y#< z^W5MUpR^3;)n&Ms>gM9|&CQz1?3IpjKklu20ihGzVPwH>vLFx)0~Q0hFaZB?;iVM$J>bWODK1UrZ!Z4UT7#L&zHzOS;};1Toow`h^GR*E0)FgTPuV_A}*r3 zuTr;-yu8Hkk|`ar682jnevFJiCsQnfIT$F*zr7L6iVD-R76^!c>9l6DHVl+EV>J&le%@%#CBJCKXjMCcw@CT z@^%)Gu`y4rtH+q5L_Wgwm`LPkFQU06UJU-ygf)<+2Q!q|F@XR_iMzIuueRo78fjt{ z8bMrJ?t)A+<89EK`=>kg(%Px<2&2du5@$Z5JyWSA=rC?2cJuUNQxt;PEdlA)Jj$qH zn})bL#0K>T5L91j8qaL^OyZ*9D) zLCo)27Bc7iwRAhhCs=fS6z$FT@hNztfEk@o9h>-eTOpSH(odS~kkpkK^0W)*BabZk z1QCR zYcf7E39y3X>X|^D|LSuRm*fC`3klwy6z=w zws0&B54@0?>jZoil0~uoR6L*GIFR}r@2Qpy*`yP+b)1&}wT0e}0&w`dx9~{(727(9 z(@p6)zYLWRF$a6o5E;Yq&uCa{JfUyCcmOc~3)S#j$8g8<-L z_uyP?3=4G4Dcre7-zj+QWvCU1MnXhqY6Mdch37>-=I2{AI|1E-;X>>rsiUj&@Jp9~ ze-=|;O7`tgtm8@!+uG;+gwVtcd9*^_Py?CXS1L=02FR`Bm1J&!eLE|g9ehdn1;|eb$1oexa;zf!byHLsEPnBPDB3?{ep)(gcGx0{)e|vLj ztk!L1PgEYFU$#+PKh+NanXk^ac`I-Mb;SG258ckSu75PO{y{hY2$vtNxMC zqq;uuDYu2D5`sI50t2+Q_K!*F>p4Y+N(=oLxp8z-WZb4#% zMe?`vI1B&9>;tF{1g^+`yCg{^txOBz`}UF9j3OOuzMDCO{=-<){EY99#ll03x$BcI;^GsI})9o6-`VmY7ipm(~Mw8u+3NMt@VACHy{!6~K)hW|>&qLE-mj$Xnb^9Nh72)}=J0Tr}| zyU&C#Z^UZ}xwGS&{tmd(=XNEb647W_m2ZSd5e03QO`3}`yjPar=aPRpXu|Z`e6W7YfKTs&BV(shjYte+&MEerbNfWNB+HR{7X)I{e5Q>7u~s{_L;P zMF^YELh)Ux+FOZ@JJOoD&IlE~=8Q1{1eqs5%hSs0_o_gtZqa(w9kP6J=dPM=-=V|qS7W^&WahMrZbQINQfcO z-1wpCn~CkjlH?yHA>dR6D{LIQsAlb~G7 z$=|o4bd^Q)thC)Mt~;vas<>YP&LMeMX_*RrL1T1Cn3I_J^{?6+{U%$h9fmVb4aCNz zq1Wd;zt=u2;pq?H4E>Gj={u5cvD!w2Xay+)*OYhWJ7$@+bf{auxk}BL#I`L^adB!bcfcDmt zxSmW8Vo)XS9*VpX_}#%kf6f{$Jp{rPpMYIaK!eJq)8tM+AdoB7wS1c<1~8%2J22ws zMNK3VH>J@X99JitKwHuPe%D_04)eRD7luOP^%rk6fu!7KKuyM09R2dQGBUoED_7?$ z6_nCIh>#t~y+ZumyWZ3;>qqDfOC#$;n30{2YG}xKf^g-#t8^uYpe#s43Zg^A=62*4 zex59gamqObFUFq+UgM?fa|*8GBciu~kiY%9ayZOg!3MeBwr!L#YMI`!_;x-%9FPC* z;PgETuZC(r7c${RrF-6%Z>UmBA^5*P`~n>i+f|7bKP2ozRcR?#>|l-xWk{=QC%fyi z7!(~LuwTuo@%EiS7)QK6MFugaliJ4c5;Qcn?29xQZG1UNXZ-;){0~#{9B72nLY$g9 zZkreaP zX*i&NF24^agBN7j7n}zZ^hC&ll|X}I6x1|A=7JBU8|$U*Fn{;NXce?(wbJI=M|;Rl zGiVIvxl$yD58W6yrB?W%(rm=>^ZKGgygDBI8jaQul`fih4WC$K{#MHBqltl@7OaJL z^PY>G-Q=gpu@1XSSoCs-2$_h6B`3r~EXo`Dh{mOd$D*h#ylWz&NzZ>>lY2y>5|L$h zJs?N0U%%0M0;CnB&y9WB(z${pm3DIn-Q{V}z?|K-ydGgwd$yM^H;H2?!Hucw>Ohw- zf8{20f}4Tq-E#c#-gh1iZDA)$C7w^xP3E23hJ9r~hqxm{*O5wsi#gBRLc|1%-Dd*%J~Ak$F*jlp)gHw(5gkvW2XHN>es+tiU?LI}pUpBipdX~hbT5yC-PUa2vRXf>(_uZXeVLD2xF2A=m z>^Rg4*dl6j_XX`ga3ULw1RekR>)wj{#5Dl=Mlac1*_`99w#0Q|y?q&xR}y%%6M=ZT zYhZ$C^-0V7%-t!C=jbA${8u{#>e20BkTJ4j3F=8gMjE`X{$Zme?tr(&=Vnk6Ob zqDA(@`C6*OAW7v%o>uYWbmsyFz z*IU2)3GX-a6>*TMcnfZAlx$i+_R0PgxoinRq!ESxU7VJf2bghUvXQ@&D1+~ZW*X_C zIz1FO3(q%f-D8PbUhH$)7mvoPM|8wRKP zD%Y9U5{(QTM^u%kE|xdk-%fZC0H!C0K4Ci>+$pp2&VJe3l%_7@LF@DtMW|ET}QI|k{g?&ZY$=95h>o+==uHhpvO zfWkI+<-0yvvu|FLuPnrZ(t-NF(LJ|-37=3TEIBVign(Xdt0Sg0|CWNoawVsz-SJH@ z1KO82s;Mz-q%_e3b?0zh4c!Tx8ZaYA&FcWpg_BsB{7%Z;|IAF*fmGr=Q0nWXl$4az0B&|mpEO#d z9xQ6e+5~CTfqcN#+%?o>1u~0R3nbp4K(SZ>h-j@^5=(KF>AXR>X+6H?6IU$IK#|Ph zRQMBzI}5`u%ZFC!lJ06q#Sl_WC^*tEf{pkrvG3B?#SiKzTzm>JQE~8IBkse^r2*x$ zY!>7ZEWQ7Gp9STAegGN<|LiVzkRU1L)R6kf9GzonEp!rpxXnx`+Co-FkAF9bt4ITy zY_pDhOt0KD1}sdhA0BOt6{XICb6LU8DQ@-+j5B_~AKY65;UUx2xPcqKgsawWUQqI< zfN|zYNnt7P2tgQ#94GjZ4Nb)z~k@e%vTME9c$aE^HZ$#EKoK4a?a9{dwR){MHPx8n^JNFOI6UDmRt; z%N#$wEv6IsOTv2L9|ba)6LpXnynC0X?S<^^1KI9ydLFk*iM0L#9n<8+_yoaHEr6ju zt5y5^wIu&yiedRgjLC#KNEZ-q0w_H`i+=V7Hg+TX?nuCtxzzRcdOK1SbAfrNQ}dCo z{dcAqg6kMy{>zs;PrrT#=7Ptxu@4>KD|NnRuKD|N}EF~PX8AZk3eo?u5p)0~ITfJW=_1dh@xW~3Pa*T>0U z*Y8#bZnLVl$J4g6K&F#gZ^AoN|90^4@PwKF<&)}Do&l1mbG%IL_zTrcT>G%P9MAb= zyEAI&+_hf8{X zngQ}2dW)97U_uLi2ZB5^U!0uqI5egz(;0e3ZE=6^xh2x91)(H@A9sZ|5DunYBpP`) zbp!BVN18riepg5(>4q-?F~k~9(EF06$`czsP=rf_GKP>c{gpsK&U=`tLo-M;R=@#FzeU|~ z$D#{_>CA%fo}U4Af+FmlYq;yXbY>r_X*SVNmR28*_m)0@NH6d594~+TOpqEaI+k(S z8OeMGhryCk%kS@)l{y@{zk4P_`>^Rc{>U-8aDf@!t zdbt{@i}2~&lP>9$CED@~YRP3}^(8>|^OK6?o{kSN8scPoUi|Noq=d(>lzApnUY92m zkQ}a$Fh4tOmd-f|Hg{8(*ptH$-=LX9f@wNJxqT`)n-z0EN?R7v2Zk|5k(&{5(+mN~ zo_jm5NG&bXbZMRy*pU zJq*7?T#L7-B<@yTzJ5=puS%QbL31L0a8>&qEA~%It#M019Cra@Gti6FwdVX7kXA?* z6Xr=FsVCi1x}4w}T~~Qh8z~{x2Y?_6645V)q<_`~?PkhAbM%LY<%rHggkbx> zjRQ>yX_`XC?wU(KPjVp@Cwh=>ogEuFoGo*Srz$V+mj;ey0uJhik+z!iZE@OshC|SMM&|;O!PO=>TTjWdss2fai zjus$_LBue`vZXqj3^P6ILxN5EZHLIk~G@I=jf533C_WYly zwrR@zv5Q`P5wm*9zlvHtYZBRa{t1}qzzkO3vvR7fU@QHStNpyv^MRZCAB$)peX))P zs+-u#*q9$T)t)v!>4<}vC1{ir=(FUM`lSr@afVe$3|%A?{p%(LShhHm%}lr;Oh4hTPejb6nhg0VdRS%iey)}_zZqrs{e%iG;r&~GFl`{4s3o8wt_@?J zEg;chHf}16eQEJXroB>n)jO)Q05$eG`T)jK3-r^o8|RDUlUpT4f3hoy({o{GUR$;~5TorPkND@h{3JuhAD}|d*(lTx*v?Nw8j;*K2W0xV;wl(=TKkJ)Dp`Z zZvvYo_G+a@@YlircfSu{5+@PFN(K~la?uF~fYeK{pZQ(VNwy-aNpb(Iu3!6rpSwf? z#F|4FU&0Unnh-Dbr(OddJCg+{*?_{wblA?ckNo+EgTD9(5g$}YWV&5*NJPz>pl+kJ zYnEjjnN>osItXaRvj+3W9&kR^jGChTa%6*8RJX~NZC#?@FK=;RVzTQ!7{2>*ygJr?AM2s@O?~s1 zFLpYG%Kc0H(3Z{43B#ujW8@nHQ?tBJ)CbNf|HqmLgP$VId$hyX}w#;@Vv-j>x{GUSV;C3wsOMq^X@CRNV z#DfA}o-qgAX1rNT-Sh$6x49c|7&;Pi*_8WsvSnW11~b{bu)Q_??)TEC$F#!cA0v4H zQW`h()8L(vhc@inqgQvSt!_~#J)(Admz-fvZ5()$H9baJ@g23C5|K0WHvYc}bd;~c z?EJjR#)8xQ!My30ZO9jKB~Outv!81Q%~0L(a_%)Zxb65);qWih-bzbzqBSnH4!Yx1 z5U}&b@EgGRdz(S$Xq*ax`LZ z3~8jSZNyHp_|Ud&C+axw9xhnT0bxP=8`{`GpSLPv>j|-F!tN930wmw5@o0Kav^f9L zg2s|ADA)kpy{I2A3_J$#EJ?bVLDHWG7i3BZ3?I2OMGnXAwrUq(?EuWmHdPF6GlR*N zL0kH^B)ypIA$F|jHxuz!LzwqueTh;5&2Mxbl6*T>nl*z6N(re-GIWk2BiC6d4G1Sqdu8j{_%;{GZi0{2!nXH z2X;#!<(gGDzX4>&U88uV<-(^a7{2(bxxE!K)M!TeqXdZi_deJfS4ciph^lHIWwo}m z2LiGcAB(Ck&5_DS|M~r6_?vp(**852f=)K(kqI)9(*NVD0GpR&!b6 zA1{g4E|~JN!~J%sP-^inX(0%C#Gu1*X)PS;=h}(s{Lr zu+GcqRf5J985{LBQc&8}k2_M@{qrT!i!6*JdDD?Zh7b6x8wJCdz_%H}`Fy6$ElDep z%mw)-6$~lJx4T^NuV_>2k#>q$3|YnM+E_Y`peT2$lrVSF7m3?!C}b}JDrG?TS;eu4 zc|NUDx~A++jr5<_Fn|Lwr4UEjNYPlZ-exLQdr~A(ABNax%#->W-wM{s^>8La|iKh{gvOq+f-$b5ufb)^t7prU1o ziZ_i-3Ioin6tAnSjOekFX@3yt-MG-{);+SP;+|Nl5E{6s(j4aCu95b2jrf9VK3xn) z1Bv7It2hn4$*zeMn*ba9eyYK)gNK1`0i|Ct36+|ruy}C!gkIn%%Pi`Ctd2N>$1@?O+=P1WZZTL-eN*peVt&lrY=jyP+C^mM|2Qr+F-E z0MIC<;Aen#(#tn9IpVty@I5FfpR+=`PdrBZL<(mUkG3pxdA6hdOva*JA{EZFRgP$c zEws;VOO_%ptMgJ3BDP#KJD*|yuCE!}VNzZJoBs93fu#Hz7d^Z2L?1JHS8_b~<1INY z{r4l`g&@B%b%!tf2#1``DvbsFLj!`gU$p?7kbeT81nBC%r+uG%gO$@NddVDddmvn_ z50F*A!6(X%Ks{dbQWSS_;QB<(eFqTfpg>o<@7;iU+4kBYfV&j94vMlh1AhPoiY=`f zfHn|2tOFeXR}Zwe%|i6WfU%*Yw`d(=@RG4SGaPo(;MM4{O$=?6251z zzQ6m!yfvTC?`&6Al-190;>>L~`vrznaM%i53cja9@a?bfbClOS@E8LirP&Z|JMCeP zUcSVu@X#^O?g)$3f9g> z`Fvr_#C&HRwSL*_AB^%~6bBitF)C3*DMoFL)Tg!7Oz_ zX#|GAp&T5!PyTEqd#aW2xqkeja=ws#MU%=F6a+rbK`uwfMsLNHzovjUQk1a{XOqEX zFGyKr`!B}LE_JX!)Da)?J$+z@;{|^lxYmpHUP~jS641J_12O|2^bOFdbd=@@iBWGk z5{uak`fE}2%Z>XYnUaQGS7_hJXA_DUmz%aV>oC?~yoRk7Fzs4de>61oyN_Is;Nj4K z#`{o!3jH=JPwN=xF=hVV4IolHy%O%@!k;#>D|FdCw~7{ua0Qx;1|hYU#Ovno=@amE zxP<9oXS(lpax@89sPy<~w=VC$TU;T4GF=Asv7H^E%^Le$be7#KF522X-zTiP+B6@D z=}0)P5ZlL)aGl3Eq5tffkV@%7Qppe2a$!KFR02SUJUr;#j9wDcCZwn@fFtw4Y=1E&l zGrLCw@G&m-FyAMBTSM6FSar`CaxNI?Ng#)L9|YzN;+WeGahXW$xX3nGDtfOr&B{PV>Kq=Hp=uU^4n?DvY(YU6<)8w#y|fTVFj5(q4TzASOBWt_>lYbDT(`ge$-GR zKxj01kvfUj7bcQ2c+NR{CqG#U6-jtpof?}LLByJV$;A1>Y?C%11hmL=TaZa}0kD4? z1;o7Qhw{Uux`!sWYt63q6C0u|fBDtq?n~hgq)_uC57N&3oG&8YJ1731?XE?j3fvQqU&v6Pdb#LT zSIFh6p5A`8m7^xoDRFe#Ri9^e7`c*{u}|)CC2m(T={2|kpqPC_0eCg(wBkVcJ*M}_P+hVS*_WL}4@QJ$ zm@`v|L0#Wn9YaMEc$pNR>?&%>(`!gYrV&wF(+G4crC5fINMnCdQy<{Ls*@ZSCZ|*` zIo4RnVA@RG$A9lldq4tne^F&I9~_>oVC|4&RvPa3B-_gR^E&N@a)7+aVI+FA0L)z0 zh`;0njZXf(vASIXCe~(Q*wb{_L~7oag?ylVTWDFZ>YQe|*b2)Biw0~AujV&?ZvW)t zpdv^@d?A zCpIQ55b%)9=RZ>z$*skPFNX3b_b%rkmAN*0-O^y7-X+=tgi`3h@l5~q0etFfb2M`J zsFvODNyH+5=ht|Wt_5W+qq>rfAh&5#YipzN*BSdcJV#k>n{3z;aKchwy*Qu4RHa1N z>cHPZvl!m(3J$G&!EF(IK0sZ=i6)g<+R3cyAmgKWq0aGEn-ayf53@N~9aMsi%*7@2 zLt(Hw6A3nMgJE6B7gDQ%W3ou+zLc{Lmy18=YXo2Z!}Z6*HY)4!tJ*Y5i+`5|M`f$> z$v*77Px&{Qd$Hc&XB!*`{s*6NMe z#c`}b%#okFONxY}uHnnDD(6qO`6UdXM2KNno%p$mB5Y)TCB^}IO?Uf!lgimT)c4Fn zjyMv3H~e{a_F>jzWmmwgBwALX?bfGCjt!ls*B&~q_8Y*qQw?C|EZ-@43LPLCCEn=Z zZwh%hiPLzujT#D|X424sxU@yMAu6iS6z9meZEt4_<#6$q^p-bwtslX{s%;=*41aT6qxZ`G{n}{D=7B}yX{>Kuk?1cEkFy{tlIVqiNK{B_t4HT zwVdrnw(dNf=tcZt^tYCnH@*nj6kcl^LtdvhG!Szev84b$wA0nDA9mloBEPvDln%VC zW(uFH$2s(Qb|<_#aw)g;f$Io+LGwRx?W(;_Pe9}3oJwy>uK6K@-GLM`)-9GdZE?UA z5K@Ufyv9=?SwWk?s{Yv^3@kUkDF~Y>t!-aYu}mR&j#tDMseZ`vcwh} zvut2%Efx%FtJ6BxoF=0vUwr$GCPpi;9jj-|?c~*7p>K>f796SL8i$~;GA+Vfqm0in zl!MG-LgFo?%OASC^3^v_EE=21?IlWtEW1jZ9_*WO;`9{M)cYt09d|$|>g=S_l4$pl z$$$3dpRXph6JR?Ygwo}F)u1V%kXha!mh@U zLRBWN+q7Xq#DcxM8VpNkPsayJ>s@V!ii2lTFTg2sv3^!^GrPY@^q70R?mPaRvtP(s zn2xW~CN~d}g1XGOb}ehgbcFzhOoZGvZ@jM6qIndPv&pl%0y+jjYPXfT%3WSc7?Hu{pi zY_Bj4V@31aAgT!NX=z{$E%8rDhM9bY^i|3uzqMDbTE1ESbF%&1c0(vBG6%9cYuS-r>VAOTq&9c6yQ; z+`&-nY@`T1OvqM1LMO(1xpz!lgvN30QYeP;h*z0&5XS5^)cDgYIZkeX9^TQak0J{xWqb?|E#z7vKVf_ zaH;dY6P^f}cMe;kzqBpbNflr!bN^8&=rEHl4^wuf;#T$53*2f^dz28h{VY!-Wpr5- zI$G-u9nEH;XX`mtFUHvL7^g7Pt7O`0Gg-84cEWyUTQ|&4C5P8UR`lxHAeyaUz315j zUkw}`*@jF$Qi4sLExTI1R`rk(GUw@2)aniXy}OghN`pHIHd0-DbuE3Fyh3Nrrrp}JLm7gCWv=K#@Gzy0TB;s)`9fj+le3H3yDI)w zuTs>SXH)(`@x~9nSGBYYQ^LrBDCndSqBe_rP5musU8K;~c*RR*(gfbhQ%>^<;=CE- zhAOFPd|)@m_hyUGQYuyqG`QE)@&nQGR0w%DYaI`47mj(e5*zHx~kA6;9}5)LYvNqE~~f1fdHRhXNYg$IF>QhhdoNrPj1&qq6l271mR`6qFQ3kCO}IN#OX z!`|SV)6tg5&9g^mUp>BATKIg$oHQod{>yY}Ke!2H`$Fluf&*q2B0jstA<~DQCM`(b6tYo4QLM_q#jgT{TzMIVgD0>hhAM zpZ`}!Ka6nE))Xm`C71JFS&hQ-65`ccBZAX4y$GdmKOu}}lb=nKbt29Eu*=TRM|VnG zBYWPtW~3*aoCy=&SEM!J6Pw@NFKr?zr=8rX?JlTa;A!VF#}$aP=K4$cy%Z~5TlTxp zvm?Ol2yg%DcSR}^#LCkzb=~iv^!J%*7Ek#`K{P03C}{g8!LCnYlp0PWY)GPu(e>cW z;0x!{>1k^wSHQ%#8R7Fw5BGjL+BNs?V%$JE18P?h{S)I?=Dt_x*DtIKA<;b-$!|me ze<9(Z>)G69O4ZriK64j(T>mW9FHbD`ka#E}J!42UTJk)9CtaN1WViqDaDCSsJ%xcR z(K(ya!-asg*N@3Xkt_UM4E6d=q73a(?5~Xf9@{fY84f6UTG&IZIJIc=boBIi!q1BZ z>MZHVtvI9Q4d{$Km$t9fp!9~Q6Rxf@uc6JNAEjR9k#p``9lQfeg!aTeHbl7m?m5(F zp<}YurI_-E*uNE94^R@dK#>G^Y)us}1fYLt9L%td$uUM@o{5IHxTdG1_caEF-n77k z#U6~-j0by_bS- zL#1Q78SaNhfPXZiVRC-J3UY?)`k5AX zP_NOq_9XdkPV=Ohg^jjqQRZjpAQnmqBrVAgL*M2`Eo~@gnixm=Mq=p74d!z~zf*7J z5L=sxI(i}HDb`9wdXL(^-aM1wOK+wjv)-m3EObDZ>j>`DsFq&J4&zxq8K zfSyUb_(FldYHF~B5A8w|*?qDrTS=uf!0|_UosD8ids72Uc_&!Z7ow`_2+Xf$hF(gKgn?8FCt=94h_O zgn@qr)SahM?B}Mfztr1}0QDV_n(^qtBT}lqN-762GK5`>>>Q8lLnZmYkP~fY5V2`6 zNWWtWCiN25Wx7SC8n@Mi@w=fR+Hr5>OGU;r355ru1*t|%%D9~|b9A8XtRGKlJx*sO z4D%wilnG0^L?lQs)HU9`zoeWw_=f2BM=oH>B;iuF(l=3ZZH40SE02l zN0z8}DLoW{8RuDC0rGr-7ii_b$l=zh7u1!rX%w!P==fI(zji!#a#ML^D(|H=vhRfZ z!avh?t-S7UZj*drBD$=D-T~m8dx8s2^&HMdg5ZqOO-s3)rc=OWve-A<79}$cZQ< zw~*!ap2uLFy@?Ieq{E?Xdh(fjO{5xJtP|u^@APFAE9so0zv-&sy|V?GbcqDzNG$F- zf6x8w`qp-@`X190m5Bhfum&BI9e8Cfo16^nyKKOm@L=0@sN+zofCP$j>&OHn<@Ewf z?yv62MMFFnhr#*;&~ts=lPddaT(hf!jfQw3xq3_S;BSQz{@}=8XM9mR6`a@J?KZSj zxsj31MUd@vL!Tjx!Z?BnNJnNjQ~117_d1#A*kT#WpT!E;u?~|~9sUq`uL7f}2u*7d zw|mw2JKlgk`1biyx-0>+{ngd40Pke`2*Z)|gVw$KC47GY0*WyqBsa+^K~S)dF>!0+|*~w!AJjMq#(ZWpn`hv1PQH zy-68`j0fP##Ekuwq--!FEi9A(b4e((y3ytzKjvuyi84%FdLk=JJC;vLjj;0f3hZm6x zYMhcOSww)vn_hqautSl~_MG5wD*W)r|~B<~ZK zb03n_(vxJ99sGznkT^D<%7G}DNJDz?+GX<>a#bSLsP{xPL+RJrsL2|Buk>Zi2inRH zL0cMqR49i+jRL5b4207SmgZKfbWd)L$nfQor}`U>yY?H?VjA90C7Ld_)`{#SqtDKG z6CjJvGbWLO0(ZDN&W=o)I%5w$&gyQRw!Yg4dn~zD1f$Q636&@pUix)$GF9fp&@%On z+;*pEa6r5mA;Qoh*e6X^Jv%S>G`dEe#lb)1RmJv*W@g&y`j}s;oXnq`TbC*=L4;g} zt207n#o_Z=PhleO2g;53=s+$*2eyT3uptM{XJUc)-wX2uhVu`E6UHYdAC?mgq%{A$ zYRopssOv^edHn5{ayGG5QL<#13~%ej2Ka5vG$kM~`Wg#d7=LTOSJr-w7S^*B>*+@0 zC(Fg#L-?{tUJ!n(?1508(z=|~3akQR@dV1s__qcdsJ?nC#0|F31y}68EGa!~w~NmB zU)A|c1gXsPuW=S3Wf*Nxr@G#R3a>f2;f!9XmVrqFHo{sN`n~hG*tP__eVPLQr@HAk z`UH@E^cgZ-WoqjkwZXcA@qHCQ4Y9(b)jVqbS@X1td)9nkr+NQB91g(IX01M|wKnKb z{M8euN6(r?ac_iz*~q@2nmtOJC&TWvsOgZg469Fd!1;Q@6xL<_A4sW8nlM1f)dJ6M z5U9d5=1LV`nV%LSOFZ_q#KE^k>%#Jnsge89E7r6}IhP|Lwg0|Wr+{5EV8RI8M>bFF zdJ-4e^7+n6${!d~TVvR;g{oXJ+U`5?e0A3$YSYq_1{l440e z{-p^?sClujcp9T?viba|TEE=wP|NT#PQF>r%%PyMnrEf&zh9ZgWaqkC*W6k4;03v$ z@`1~}`YMS8C6P{{5$!0YSMf)DW^AKR?&ox38~G!ZRvi8Xp6sx94Ijv9tjEbJEq>V7 zmR<{xNqp6~*CnOGKhX!Mcc75{A|jL^k`Pi^Brwjw{}3LZ zNUdptZr9z~d#zirUkzE^IDXid!}A}c{10>{6{OqLsS(KfAw^#=;e{4_+Vo6+BL27D zZ64s@XWb|UC!pT{8^APXyWcyR&nN^nHrdVesAgjmzH5qJRf}DtueYPly?Byar?ng=FuPzF@RyV6{#>gJb7n<6ddnU;33aavvw}opHdLST868ubl1lX zCGq9J7e?4pdjA^)8ky&Fa@QWbP*X`{BK|a0Tr-;JSF4}TC$~_Ywy!^rSkX(t{7-Go zS0=3xAcV9{83#=9m|o@;hQWwa?ea22&EiWOr%m(gbNBwcB1|&(hDw#1 zQFCXG{)L8%FDyc8JMI|~=Zrq7w-CF{QZHBkVE)4j|HabPnCT_i(Fe#tSKx0DYJ@$9 zQWx$b@~tsVMC3Go2E$I|BWS>$_}0& z6~uat;)`5a_HOKY>@P+T+`=f&vSAcc0B(O$s7T?=Ty|`26wgI}z}arL(mV87xWbw9 zKl^5t2fFt$=Kbg<&|H(#RIau%((BTpYeK+c9upRcv z6OEUCUaQzI_i0^&CVWxBI?vxB2eAUWwD=ZZR}FIHsGy~w>|Xj`fFvGlwf9#F4UQY- z;~5G18fINp4z4H(x32QX#_xtB_QNd7OT+V>UxNo2HdQA5B`WZksIw{gtsdI{>@Yl3G>|$a-tr`u>l%wQb3o8q_S@7o0P!4bQ51>NgX8u&o%ZhKU0Y^KH9-4=o_}D^AYfvIioZTHc4@*84h! zXGsa)nbZxhMhX*uX(nS|8uTx5jp$FR!LZN%dATHAV7&3`i!A#~dciOnVmgBd!UMt4 zGo96TwU*FB<+jqpR_!PfN)!;F65r2ODt*0h(ZE02fj^rY5;Sr8d^|LX{hfs=YgVq` zG;4waqXI2AG{SLt7F+@E^hv(3pudC?0R$1~zY7hBr%07via^EIPA1y@kX#@xevx&x zC^33}|C7@LYvq!(8H;@$RYwelBmCT!_C&z|7Kh4bSs!V)shM`D{}K&=YejjwnT)2S zPc?Ft`aArR6F7Kq`behO5YWm#PZ?KiNGIRK*-KXDXn*K0TrChIH_r?IG$7lIiGtDr zfLC@BVz#72Azb)Z50QTf>{4PVLeJ14smDN>xF|d42Q&qXJQ4r*JyHO<;Yh}bK@xn@wM<*lf zdg95wOP^W#j&pUWW=rn-?<<$IB)ocvD|iO5^=^QswE&Rpt{wmy?gh7tz3u{_yM!Nf zVieB;)k+cdhtrOrI8uWY5CN(bZW>FhRZ6tD=W0-l#SX~xN&6nV)Ye3Fz1rvZWwV&uZaKl@WV54!T(T6~2qyXVh ziN-g&j+r&cNki>Qf>FM0x_7=tBlfr6ukehtSO^{p8(}8Q15k<4!Xn$5CYJFhPMVY! zQjM>yFnVEiVutS3GY{$dqP|28$sTl%SEcRtjJYjw)l|P-(NB&j^PgT9^y$i$51$-* z#xtOjA@Sxd*1zCBG>Fv`^8VXAAKwvBQ(#Abw9~LSsoqjINV@U^kc}c`yQ_;2Bd}Kk zRY)E5Gq*Q}OLMVk6T-WSJP}62>~L2`!+GDSxeLo50FIGzzZCL0_RGf@znY|)w=lzl zw%D`t?Mg!NJGw}UiVDaH4n9)}0FEIA(2R_cLRii*VZ!!XwS`~!Q{ccO69tvE5eD$5 zcVQM#Yj?ChrD`Cj;RBt0EpG=cEWijLSAsMOu=;9^wcAgIMY@2NFhR0tG-T>EjgD@8lLpKW|WbEse_rCtrLiv&~ zBtZ~|zXUA|U9+l-S;6k}rR6_{0sN(4C{08Vjy=tS={q}ISX@n0gyi#RfBHphmNpJ4 z7f4S^7@7tODwUd&u!UZipC}ZtK(P50X`)Q3=_pZ7wt(Y|f>QlV7?{h~P#1-M4RBMn zM_(o*2fC||?k(wxU2kaYKJ{VmcH8+biq43pN&WkLxX8)4w#D?T6YlaW%n|^& zIgXVfeRDE0#=RYN^%ksKE*>8Vj{|LF(W zhC1!y#4IDc#fQDaELnz0pSmyJ8VOSTnDpT&?}rq&sPr(LaziD|86`tVABVhH;VA&5S5N7E*0W%Mb(sp@1_8V6+4A{#)~Uq} zXg@A6Z=YdZc~9q}Xb5O6P-@~^aZdqDXSb`fwE_~vZjiU=a&a*3E7=n;+Oqmb#onDe ze|P0BXJxsfaOr#!m+g!<4tRhOrU?omL#mP<-Yl1wGB;2I@$Ui}!V~iEq^G6dq=%MH zAg#1bpPmi?U^T8VcsQ1%?#0GaFB>19lMKRTv(g<$aB@UMa)StbZ`r)4`#ulAcNj1* z>c5PPRU8XR1bUn_Rn??imNO;lTcqry)hYncL~!L9Sc%SPYi(JfVD-nW@DNSf_r|B9`E(aUKt2r1wR;)&X)7Y2}szsn~!IlnescnM$ulO-p$c)kxbhhy)b(Q!n!T zd@ZV{kKKIe8|!LMe+#|%6BFEif9+m;4jz*J2yvUrtgk;m99rDohX{zPP*gb2lBbmI!r-)uTsU2Yfk1VP~k7M z?Rw(=Mz5P{jV5x&_KI47jdwh?yJZk-v#hlWA44}CoaetDI(6Sw@;6d-6P-BG?LJkH z2YDxql@nz<%7J|^(Bpm!Z|M<;&ZNUL%+D;)@c{hA^7^4NyQ@m9nX%6NkU!=#gyX9aZo`G0)obQI6-X!O86R9?$HQUQ9N-X>Vt^cGcxOF^SA-PX-g| z2ivBIoPZ@)r+%76W*{3NJ7Sssg90H43ab1Hy_4?>#e6NUxGQfk9oGqDaj{x{`Mq_& z_nEUb8)Q`D`+#Yspd>GF>>uav87%LenVT7_cb&Di-_o@NrIiS0=-A7Grp#&m+>M~#1QnGyy`^#|m^4f{c0=FN7AhM-6!g5)^N{iuh%FvmA zhLA*t!uIPy=Brd+Khxx45C4TxPhCtEimPEei_vj1x@Y#$xaX})mwO2K*3?BZ^X)U&lMD`IYHTlxLs%pyO#yc z^HaqOxlcT-*Ye6ReSU(yy$Fs9F0NU39i9ySdGgXlT&;Wrb!>*XIA94lTBtF;yb?e- zigz3U+zYn_@w5N%B1(KGWQ$0!?Ks|w@Nhqzr@#PZlivy_%)309kt*9udp25u*eh|H zr1#7R#ul(eGBhv#*zSF6!s3B6RQ)SSKkX%PG;vMho%{KED#~QHRK%3isYNS_HxfH< zQ)s@D?dv$!8t;f!y7|e$6hT&Ce`>6I#+!A9V4?K6kCupi6?j&rJT}su70IHcVnZsf z!rEdOCeLc7@*$b1nq)>o$^*fcHT^J@iWP=4RK1&Q#TRB1*yYS8giwm+AxLWRg0aYU zttyR?k*L1Oi1Yk=rpB+jn*m<)>Q(l=2%TmMndk2w8~fuq3;Sn$xg1+$Y2C-^hN}I9 zYf4htn#Ouz4HX#%s*A-xSOEJMvNW7=XW97j{%pM6(v+IFgJJseC{NcD3bHQui#Da_ zT-PK@;Qhu01LcoCu?2zMSB$m(=EbgzTkea_W~St}h#(p&mylDn#g?)WubyPz;yPe@ zM8NoI4!nE3m4ON><~OnRk?wIYB(Cz*{bZ1k_jCN~$-DChBW)ci)(P&hz4T7WF+a7^ zY@;5M$p%MnynEX&0;1K)j=5x(OUit`c_H$BIk^#l*M_WXO-4n`hICFq-BB@?qmjRI zZ-Y$pQ8g(MHD+?ZHJTH6>cor1aB?-t!OU+&CTo8uiFzQ29+Na(EPbG|Sw4TKbg3~8 z?>VK^5x4)EyEksjcqb79k*p!FzP@*QuB`7|v76J{9{+L-$%`?_{!oanqRI$}-8x?p z+xA!szJPz13 zgc3p)Z?J2a3)i_&vF}ttuIcvYzX`MQho}Ln_5Jlr#g2xR7Ye+MG+Y_#7~I;S`Ic1g zvTwPw+RpN$T1+abqra8ctZjrd^OyEsMEGih6YIfyOUKE!Xs_Us8bER|SSnjvM0Nt-NQ2)T9z_*FeVMB2}b8 zb-+deijI8oQO3ZDW6JJ&BEz&7<~b5Z#C7bM%d@4bFq5;wXuCM({i&`?PVS8AwBBbw zw@*EX^~Q!_EF^oGc9xi zBC~tZZV2So(QQH2H*yftNR_r0Bh~ceUD5!6gm81T&f-abai;&wqs#xzvuUl|Fw;<7 zUh`!t7^^&y0jnyZ6tC#zY*kPR@x{7CtPl5N0#ODmEq~s@z6b$Lb_h%20P7byHZRJz zHTIfZq;@KtWM-ivtZOV6qiTXHeFgXW$fOAvKEWa+PTpnvsk9|0$tUef>Z?jP6|#mj zk*=1q6%<5rk+oZ$5{@6e(&Qw4+EU!rUG=y!M8yO@Fm2ebPZZJA*v;guE%!0hg>EG2 z?Tzb^OLF@0fiZTh8l>6kD!<5#2B?iqKuq4oxJ$0Ag1l0d2$o?}>d9k+FuS$^$xh8F zzjR-9nAA`lV;tGyXTVM83u9ZSZ9w6jK-h~f4=qB&&e=+oB-?%^72`gN1<1FYGHD|< z(!>#e*>%m|uw7e!di~uH=ed>ATDhn8iH7^8->oxn!tQm(ZNgx2S-ZoChv5VWYHVW8 zdn=7EI_{TGeLQ@Q-~v41Q9U)|@J@lqP$+~@PEpjeG1{O}Q7&o%u%tLal1PZ|6In^iX7h=6mOX^iLO2R z+h1|vD`IPGY5k;tq1(T9Aj(f2+vzx)|N4C4BhvHe7MfPCG;N#O#XskWme9FoiF;|5 znc)U2cYjMljof>)^S(8{jt{^>)alACSU$R4OZ4eQ$AV8{WG{s{>k1JqlMMJb=63Ky z3deLFOK;M^oa880*~-o%$4`ih>1x3UqOsT3)&w*ZRpqASZ676B!&(|Vyydj6NB&@0 z`?j6vnlR1>lXoNcenswwcvcnRF^EDPGN-xo94t+EoMF0J4Et$oaN>ZGe2Nc2#N=Z%3yIgpYA!DbK{fi zBeLr9SJ}9dl5QIrS9=z*P@AeJVs~mWGrKwWPLzoIF#0|{&0TBt#(^_;qr%|Z-fJCx zIA#e_9MKjVt!()D2Nu+3hHyF1<}}1DFURpTJb0XY_%!RUEH^dgVk#NCYPtsjUE~hI z%#({Vi8iY{is{}P_M(gBz=3>8c{Amg>-Uo_Ast*(+c?%=Q3q<+W%8l>E?Rf zDgzK9Mnfz2wp$|3Dh}V_={yJk)9z>L)K5vpuV25+cNp++(!iSX}T zRA_~a%TwwWNH6JZ$UXNm{lH?$)xJlf{)35z%t(0TYCaNJmUbGMdtH6=G_jNk3djWE zSIU`u$<{Ecq1kv|j@5MOj=j?Pvdfut|KM^0noo4$0A9>lv*V3ynkKhGotg zln~M{1*1S*U!6pRwsGVgcVi!Hn_P;1cqo%`CYn>Mp75f4{gLvv8S7a@(9lp77sv1^ z*>#Ox(IwaFfqP4+2vWzeP5+%-KPl&XPb$wCZQY4#`A0eQ%X{jqk_DyWDj&pKmo${l zv}9kJWTlfO(cQ^75ew)#xjmx8ly6oZOe))Cr9&+E;_tIqHXhYC#-7|^5pUBBIKH3! z(o-`+cEsAfH6h3VO?V+Knp|+c8($q5e?GsPmWD zL+=H}FC<8wGS{UFt>`7Gk3Mwg(W2SMTU?W>BoSU;M=Zv_^Hen%VqN9Jt`6<7v-bSz zwN@5htYuGtahug0R@yv`G15z0E<~04H*dyDZl@+?uss*qUA%4jvC3EH7!@wR!cGA1 zAfln52K-HL>|S7++PRldRq>%y+pBxt)z|=g+2%nOF5E}b;CtsRqX#7Myw<=?r;#7| z6qJ^6$6T}1nYXnqqlbusGwM;xGaj1c`~G$=J`Le37T3x8Dt>K7x72l2{A?l!65hYo zt-e496+pC=;7XL3nB;e%7kb66ZFh*(N(oXD?B$dCoZ(?Yi{0U72!GURlc4?DY}eYC zr-=N(d6hE78>zzOC##cDO1?U9iX%qZ zf!x$Gh`_GZkpWf}=!=ge74@U^8jQ`0k*neHE?*+K@!3RD$p7jzz$y`Qu?v3OxB6E= zSC#q7zNqQ;K?#P2oPHTOX&Vi%a)=+IUyJ~#S)39f@7bD!b2Rx6A2BfFgOj_dX*X{! zp2fsJuuHvTs@)ECJ}wy?F&)?cI+(gZqP;+JAuTIM?^Pe3_-$A7ZU=PG&@v$ zUJPL;Vmz{mVD(pbsHpW-PqTk)Y@r@lNsoarKq~QFeR#wjv6MN=hp| zpdc`mltT?&0#YKNbV`?$AWAbLor54D-2xJlBOyadi-(+r zSkfB}y|0yG?q-#~NhId$T6kbi?s7`lyQ>{HfC@L3>sxq>nH=MYeFc$L4O)JaX!N+G znYNRe;*RO~#^%z^3;}v7n=~9JkpXWaR@+6{UO|h* zW`1OJ%%5)ib`y_a+3Q^mh5S3eIXe~Wo92d{Y*nTg?sx12?@S$zfGot%_#C}e{l7?40SlJt-@R9XPy1|q9%qo|;Qd<2S3s6QrMNans3bKPG&vuT$wyBCTVL!sR|9^uTr_ z?Z=EIw)N$U+|Kf?I#%TaK=(m@Jyu%KW4f{b=+mZpO=Q$bw3*Sp^B~-oyVvloIv!|Y zXMLA7CjA}$G255himL_U%yyyA_*SpwDVN1OiI9!!|QIeMO;JZJBx5`0kCJ{4zZ{cRx$Q& zimI?An|>Jlcky^zYZr{UO2-r5hh@F1T48H2O$I?1-Gs{c+Hmg?lnbr*0c&}_aJkW* z1wHC+6hEL^e*M~7qvREvHDJhCH6==cPTx*=d{ynK%Q0OpKJ60;@cDT_r<-we0t+4i2Dj@lFAL}B*o_c6vCAoT| z6Bj)`nD(66!}-|L{g0PzKn+Gz%A#r#AF~mNKQE6qpS#nEx|nBIRsTMA;s%LUbzLqX`jaU&?dZ6Iy!z`{nUBbtv!zkf}uk@u2JIc6>aD~Vuh^G#f zqwb~}gCw531AQz+O&Qc9%1!`fTg4??x#RuS#9LxZnG)(HiOVTK;m(4q?pV%>;8EVi zpdI6yoDV=kcMl_ZAsR*hutd`oytiNqNsY@{7+1~+0D`Cr4B+c2706|OsQTMR#N0u#Z>M1J)&k@8q6 z!wPdHI#5PH<$+6g`!E8DzAjGvHT0I+I0+Z~_Dh9&?<}~13e4OqBoch-p!vgl29&f1 z)G*7wTOg!y+5kl+=M2fxQgfbjVH~-B2jd+3%R?N~pkmM<4c92J4#PD=r0`oPZ(|;k;N5i!b-r{ z;K7$kQ2V!gu7{6V|I&Qs0PC#fWl6-T;@S$2Uq5)3lmTSC4U&Ca{-9JS%G6)hSo>57ZY>60*1|b;s%K8p+)>KaspW)H(E^g@&hY;e$t@ zu*ce%+lY={4lWhDiP-h+g`yUmUG7%3Cq5wS0?|(mTu8g?Bo7VbWK2N8Wr>~A|Boxc zzup(14pHr@lp+;_3hOD=4~7UUml)L?EHs%CyyH9k6%+T#!;%K4qd5CPhe$#X=|g(^ zGUv}}gaMI}qgLMvpxd>}fGD_^yQezb$f zg@j!MT_vv2xC1{UeMLwRoGg{;P~Jg>J#u?M_97Gk9Ed^<32ocMFmDb zH!9buE2bdYzZ}XM{r!yZPl?nNR2ZK3{F&Y}XE_*8`VjbdiA8Y3Z<{{2z938TNRYUF zdme>>I{Ssv4I)m*Di}*JuPkb!}uOO+NCkchsg;D34(|ugDzeEJ4yzMKrV&+q~ENHA{UV)(yzUw6$Q<}S%T@6 z7ah)JrS+>=kdL*5;uL(AF~N^npQ31LN$?M^1cecfR-$2(oW)k4c%?grlO>KUE2R0T zgLfh^t^$Dz|1KY|mZD>Xg5zsKElY?@vEZZo1N`Og?HJ|)Zz>Yzj@mI#qd1ZQxwsqK zJ)*6NC$D#nH&S8aBq;R$?-WfcbO=+yGJEu2IK=T57^%-ED)jH2(%R5s^&!$aKRp-q zj@w z47@Da>a|RYq)MR-USLF5NjQIG!&}Q(HB62>GiQTaduNb}u0@nzVM*Hc1NFD=uXrMz zSM_NhYQo?Y^PyXJ%S#zDGFW z-knJWJ6)a#_nil7CsDa#IbY}5VnfN${A6ljDnIdK{o1=OK>GU67ZF>n=p~u{Z4U+b zRdg})7$1BTT*+0fU#=VgrGeyT@Z;ySOe)uC3Fc?(IEd&Hgvn=TlS^@B1H9R?W#uM~ z4@k+R;Mb*Fca0;H#X2v5KB1vaz?$#_F0#$rHU+Golc*@>YuWEv2HR`BAdx;&PR(1~ zbnZAyOLkQT&ikNnwdac>xzIDa;_8aurmAV$_yVT4G((u94er01az-uY(=ZK(KI8Xa zv4}+Oq6QT*B`5egae9V3(J{LpF@tXDwao^{zabHi?=75RxG=@~OFz8poXizi*1e;d{sP|MwguP&GnvwZ<~O?G1ts{&gR1%4v5w0W z4-)JcC$vh=dR9(*&f0}{5HNT5g|8IuF~uLmknuJIT&suj1|uh$0i`)JqhjyGE_D1D z%ES<})fM$8f8%T3Uo{D<7RdyOXyK8;k-=(33f%E{Tt87&?OLjZCEO8yAdzjSI-zxU zs35{-G25hW4=m9B-oVba+(@m#BFiSrN*s@X zt@-_kefyCw-4+vH{$(S<4HxN{XEX1ki|1fKAkEJ8R^wiMmiuCM1HS$;wOZ@_aH0L| zCex;>F~~uOtJMUD;lH#TFd0-7y(tTW#AF}yn~YwQrM&l4j=nlJ2Ar~dsTu>KnWEky z$F+!h{ZcTD|N9qhu3iuP$pv6Q=$qGJK;?4}3y=M+DfaRn@9Gn($@2Iz7T(y>_VkH3 zs+Qa*;$pwPB}7uTSqMVOK(q>q_Cs0`?r7K zHJTwjH!r2{ZpP$;pfw_=Kjs^Aaf9!7)aY^#b%ZH#thH8sZ)KEU&jLlyl3|dFcTG8O z@(vy1^nZXmw=h8UrFV!CWosQh&ruAwIO=+s8(&JHPvcH*YP3I6q&e#SiprJod|V*A8Tl&SY(b|}7iNnRJ~tAoeqnf^;k~E%^z412iRiU| zUs6Dioj{LxsoDhYSt~>T zxze8odIWY#3UE|EaE8}@2a-8ad!4&-8k7dGM_$2i{hj%PZn2Zi+{3jWj)>UX2H7R>rdx-?+{(YK!f$f36;o z%EujE*ejX=;kTH(4Us_gM^!^?{CZi%roM&`_Hl00VyR!kdiVLt>GyfCY5Dtx{^hRy zPGxNlrfR@f#dQXQqKHY(c4e-Pm}AZpu*7^(&U4&evBVnTm(P7%-huk}83HccflM%r zhA7!O2kcr?=xs{Z%F+!0N@2duBRp` z>?t1oHVJ3lv86a+Rr{(BF&P2h9X)z}TNQ|-KT6#r>fSkKkN*2XE_;@_|02u`Eoi4c zNv=Rd2ZRg=IN)=0tnWv#6acwI_E9+1;SXKd#24Quyfd{VSg_qo@BQ}?tCI-=6>ix$l}jNU8%;>t@dVXWxLavl6)N`>xu zgc817p`G6GaI)`+=h_3^OG-w=F6DB`dUq2=bq-e@S5Npfmz8}h8GnA)+w)pQ)lUrB*;a+EQ$*Prx%K_(Ip+pahQldjv zsjp(sLY{}k45vAAg|2|1I{U%U(ol7aDZ&1n~j7T6cC70J^>UyGX z*cka~jrZxjf(6uheYcr25{md=f|al;nZoBwGaLSFkWxR>%ave6H4Al${#stuSYl^B|GIY5 zj&|~K$JYNMx~seEf)2ju(+}@Cok*eNqCfE8uiVp1FDl`YpDn9JjCtB;I|yc(91Xw@ zsH6NoGp@fWj&%9=GRIj*aE1&)7Hh&p&NSshuEeFV0yyaZl4=+%q}1smP3rYxh2&x|TG+n(4pS_TG(& zqH&c$b;Xa*zX4mUJi|R5*LjGg)vq^`WEj{1dl; zT-D?cxc$^!oSGW9GsM-q;6&)lz)qxuqdV#No=d_0FYMlYLk%e%!6J{#^7=Bb zgSMSzuvXOo5Sbp8)fm|Pr{fA6tGXbmpEQ7-c{z3F)RM}Pn3~6auOiK&CqYQd5$5i5 z-V+5#;@ju;xK&Xp;ueUr%}B?_TexHOqvcv|59#ZzcOTdL3hqB(rt&jOt?=_a6SppH zI<}>HHgo**%OK8XC69vz4WIyTd-hkdrU$xwxR*$sLcfAN?w8r^iDYPiP5ttS!7_;W z=7hZK`+>a;_5V2s!pZ_eT?loxQg!|JJsAu_y!&I7fJ{|rc9TOU*R2&RH-`}qMV0m{ z=jmY<0C2eDYJM)Q1gOPf|iI*PDh{ zVWk0{{ojV?5v93THjz`DLZxq=M?|MUgz__L!*A#iBQ1%o^FkwQz(!S+?Q@|#U790!5%e%4$jJJV6X zUoL#MD|z861{~_H`0M-p*8Q1PKtP^%_t7hJoP?ZCs5HIHHQ`gXkDAh^xcT$HQSW38 zb-Ur=N~f+0w^mkdZA9a7PH6^|`)_nS*I{s5H^b`&vL-*}o4Rs9b-=|QBgaj(fLeDM zDyx$z0q9w?c1Vur+Nh+1_jIkG!>94P4!Yi|9r1XgDN+JS70W* zH@Pz9Us|6S?VE4>dJ&zg)3R!L3QPi%shv5Vclel!{krn^zHdD|zcN>+p{8-+dR$hu zk&``Gbk*@R1a~_tL`IWUZ94#M?(3M)n58gm{f?G>JZ!+!h*B-7-N4@P_`7m*MP%_r zf=$s^;FZucv@e$vn~xNrV=uj#AoL5IXV`!f4@G*1DotF!&ybbm$@pH=VIwb2;B>Qe zl%)Aqb2d3d@~ia|I&oL$p{^-|_}3@;Ld<7*Z3HOEk2=j3hZ4@ok#M{fRTT|d^dtVXQ%omUS1^3+gGd?d;G!=z#7ig;d1+Wyf{ z;j*384Kzy~9B*Ax!=PMh$XL%~vv7H@n&M>hp^fzMk7_e*gx^VCu_H}lZm*H3^Vk2- zsc1l_0?4lqrOQzvmtxu(g%@psx+Yn%F`I@)DfopBW6 zZdy$NWNGhg+m>bA4AErsHMP@9()X9o*0;TVfeCfJ4%=tD;Z} zy($6qW-?S70cidbzheyH7)K$|s_@9Uu}W1TaA?>hPC^!x#sKQj*OQd1yI%Ur*)lql z?4IbxY&6C1*t_W|=Zj0s%ON9mh67C^j6PGMP`|zJ(xP}_m+Zc*`1&p{D4#Y?)kwIN zeue0wpiF)T!5=?sxc?HJAw;cx)o9)WzJc!psRY+NPt*8*^6H-bu0%hIbuoYYeQ8Gb zd`8p?PB%iDacVkKCvfX!icO<#sMGG!#63M{Z>gt1|ebv`^X2SdbqX z;W_wjK7XQIBP)tE_Y2W&mf}@C%+}_u0^b6=*4i+sKihh(apgs!(jagiRcN+WZZ+dO zlXkMVxAIg&6$$gVZtC1SIhQ5KMLrX$5F;5m)FpfSU1hLfw|m>@$+X#wq@%g<%3<<~ zFT;SV%U7>t5i95V26W_J^~(8)le@!?^ZGO|;?Q*jdvO*uzk7D`l&MANxKvqW$n#{s z4Ma&}3P7u}`cfIChoU<}KoMjfE?f6f%qsNE?3G3r%0Q<5PdBw?E>ahhg4WnT?&=$j z28dcZy($y?Mcw(}J7zAO;K`y+z)`!aYVbAv3=}5iWH}BcrtqD1CJdpfHj`g+azgSM zCL0B-wSu{}zLz*a6`&11&9q;&K^b;pT)!d2;2WVLDrNk-8?LZ7eq1vh?#kuwh>__T z=fz^MCIu=%Y|ERI@Wm866aMg3VU?~dRc?NQ9`WqJ6uPD%tkC|;S4J9T z3}LJm?ctjbS(b_*N2M#3=Y1>B7SXcqx6V(hUSM5i@RKCY63ME3xXRVB&36UZkam7e zk~-5qI3nw2;qkSStMld^c!x=S?lrb+c25pDTTS)~n_{DVyp)e;1m5KxZk_2yg`JZv zG#4IgHk&HB>n9#2Ckr<;9A^|ax$aiyAGFmr`yGVhOddN{U?0=Fn(d13pl*o&065cv zqk|vsY2O`S#U0J5Fk0;7sn01b-q&Unx!fR03I7_Ns@_2RAnz9)C%?wVgWfTP3|}HyOR=7&NA_Xy=9L$r)gp zGi1ex1tCH+Vs`M2`F?`Q1ShB_Y_a^asO>kl<5nxHg+*7w;PY6jPa*Gmf1snF?{0q_ z;A3tmCucHwu7$#nAc9h)**4ofG4rvu#*{mF?jG%tj9^V|7Q!<$%*emDzqhan(LuEY zul2-lEnpw@?Jv}+OmJv?)sfkF6mRXPCxku!Gv2oA8q}7{(~X&XyTY*H)e|fcXjzm9 zlVtr8xO#v4b-%@wNj{tceLaD~2$D!|3=`9kNq#aTX|2vaMYU)ZUkhWPpfK%ZM8jd6S9O1e;&Y}dJ|kUVtrgxEv6ePdeZYd}8a&nFu_7eyg& z`6s?dq0-BlCma~NmLr3du;-YgX3ca0|2Qdbtv&=b;TvLPvS!%(8YRA6GIizaY|6@R=cDfG*~;(bt}nf!D=1HX{5C#64U^qHR1^q2 zh*%M0tv!N$kn*XnuMw|oR*r0_tRJn_JDRnU5>k&2fV)39f=LZ;k6RirABt_YUBTOz z4I#0m{t?=(IZ~Z$%Ik8pbD{Q#wUl@FcC}ql7!1&YWy~nKRwTR?a-Ch3 zg)^ZGS$vuu8opSNt?Hih`a{R|^YY>wvv~(Q7FI!zQ}bhM*mQ%oRuHK4{OFWfVVDLHtW+Tr z+ErVU;zTws^O*lKhW)N;WRg?kPsT8`&#PC_c-txh1NYVbV07li_qRWLOKz4xKC50g zDL80j2 zS|wV3di$4)p;fz+6)()#Z}@xbObSVy5wTRf`Ku6m>Fw_EmC5!R%GsU0Rnp+j6;x0y z=VuD*`T(1@qtFROnmDF#EbKSImEg;g(N1?f8?)73Z@2Z#k6@bdXD{BYRJQETS8A~N z;_$#4v;8^?2^`(i#IgFDZma07|1(LNCr0!eciKrY6}J+YcN<^-c09O2H*=YRbu=C= zIKT^Mo=G(+hG8aQ}ztA648K5H~E`b+rMFt}boa0(yIm z%zo=T7k~}()v(x91BjU7iu02AkZ0*r$vY=|w9AEw#mO+|?}mlcdlHgJ6X1cJpiF$-+8s}gue|O{3L(F@DJ>}l z6$_r7vB>>RA2|vNh?l2MEHgw`w9g*-^Gz7W4rLH=h4)T=%UDx z=2iXiZ=S-yF7)k17duj~>5XUp@$A=?>T@p;wY3ygV+GvBz>~YhdolW^5t@)~9SlM) zFvqtjafArI&QXKdcZV>ty!`Z)0&E%8sjN+~-FkyHlP^=R-C`Kax9Nj?IfwaeRiX2K zY>q)6i5}Ed{ZcdhkEHT{!-J9IRrk_c&!g8EW zyV3aXh|&{E-nLfV2*u~~ zHXhHhk|5ZPVZF8(dKY~XM=EU=6iyS47e%yP^H7IE6Rs=t!olNWm^o0siX_nAZhpLz z5bqSMMHiGf(OWT8KpT@KrJ*+$W2b~qHQPbnA*NokLA0TfK*sWpa(s4THO{WFiAvDNY(zj&^1z#dljN;6bIA1Lys=27%sns&nOA&my}f8@=hjd}Hq$i4wc-AAcji0})uCk+(WHZYq+v zbCoV2zyA1wS3bp@T$tZCg$RcJTs@uaUjUMq%Lr&3>rd;`YZP@of+e zhOPsh`)3U#47-^Cyx)wCxLnqMMrUc7D8z8RhE7XL-X( ztkUYmbg^g4;;p>cysTs9LW##Z#}?Sx9!LG|^e8As6z`jPlGXEQFKd^K-rWk~ENu#_ z(kT@g{afuWEYX3OEw4+A%(B5@?12)PcDBT@`4sACRSsRVlSA7Nhk7I6i$#U|>ZhA3 z(gqV%ETlQAO-a95WV|}xN;*54m<=ih6slxGmob}P2M*3g7JM636c*1adnuSZOZT~n z;cVCaV=x9Zo$bLNh#vNACw+2l5|vbK4|rmP;Ou{$XvAbK8qm=HHu2$>Ow4WOz;{P; z4FTn1)OJP^VhUmU9^HmpBD$S>$h;ftWmV)LQxFs;!CUwH*{Q2LqFi#ruVfx2W5#E#AYf3Gm?1V5gV0jt7mNrW+?9r-8BS9aPJ} z&MV-xRNAJQb;9A6m4&E3Uj%jx=6qT2d)M&Ev`3){Vt&svCV$u*SD;7F3;A5T>2-yz zCt;i#FK*t-myiT**Ysy(n}YcR=jGtT6;kV|)P`?wx1D}?eT^eTef);#0V$QyGDC$tKaKa_b*zndl>z8 ziE75EYJ}L}DEjwR_Ng{Pn`ng9?d@518Q+;Q5`3|(XB-0}S*N~zq#p3OgIYToc0~fr zZkLt(VJ<+yM%9`7?<%|gscG!c#8WU;#8a>+Z{R`jf|FFur=U#zY14{|sY=s*4kM0M z^A)ZGYJ^fvmR031<>AH`&VZpRVOEgePDqM@ZYOT*|i_df8&QEJuV9TX=r6<+Hx~k={oXqtrgCpFy;p$ckv+K~fhFZ^AKgWqVe{iPM zrS^wH>iO-Anv@A6xYVHpmbtr)Jo|Qw7F$LL^90I!J}QCmN`?;Ju^bcAr<9h32qi&0 zMW=N2g5&YL6sDbCU96>S%jem|eJxxtvjtx@lJ1sac{A2sQEhyPGuQ zU0W*OPpLe!D|v)!!+Z!8;nieDH*&U&HMN)5>m6x^pl2V%Lt))@dWaPvc7$wJNwD<} zNFrHD_6d!Kl~V{U)@f(GNHd9kcy4gD=|n%P8xy+wZu`wZ_J}8G&uy{|U-czcnc>Jy zg&3b`F+L$|J!9s|8edp7p;2UcC^4>VT#oZ!0 z6n=8t$($j zBWQSPhWt?kI)^Ss^nljmj@#qEo`Oz#$28$-x1p*5dHNiavlYE%kaJd}fT&t~l|0SW zKxUM-4d$rOvlnK(C8o~(teuxD7eOVYtkv`mSMv&M0^JxDniF(RB>cJ6Kc8}`CG+QK z*6(l|RInNOV;60J7(rvTwAp_G49$jmc$?F1iTr+D1zKfu{LhYsB=l|_e+BKdgS?;> z*KL19?+YT#g=HRxhBo_0Q1hyzB`xV+2i*WBxinhd?gU8XCN)3Eup?G=8V*|m`=lo}=$gWcRY>$b8 z5^ilqi^(NzEBE!W?)q#gpT&4RfRCof^#Lr=w;@Q-LV>{<4qPO9*;S&Y`-wZCQJDpY zgxa(OU5)yngO1gJC3mP_oS)INr+XLA8>f?9#$UwMO!%MgBCTFvpL%b1P*;lhfEr&Q z5{a}#g+B%zF#d@z0VgWx_^UyFnchq%V{~+Kw7beM2Hm~kqrbCw)}gpBfJCoLN}RDEF8qcXF`KOuv^B2Qw~lxI<{@l>f>4 zGOlCxaN5%(gXt0I8pib&D-kgII*Ea4x#l zz~=-@ZkPrru??_tT&L)vtlRbSR%cSbhV4#zJ(@F?iohf>P_8os__2gT zImTxM_OWWh%OFl;YV6!`8!N#F>ATlii$hbv*fSZC2<1Fh!k_<>>e#oQoO!X02v9Za zjO_Bxvi-aH2hVU9x&{{MSYN&bFq3U;^Y;IfY&D2$HF5*0keu1JkUU%s3TB+duy1u6 z#fU6rMEy7t2_b(ur7&d{>byZvk{Ia$pP+o}1F+Ve#&7uPyJeeACx7NYO@prJ7Yu(Jdcg}Yxn=v6`T$_Q z4JI388-X|Vk{74Gr7Nzl zH*wH#=_C$KmJFFj9*K4X3X z6;$%u>*#W@^FXxSH_^F?T_YD}KGOT^03fsg_x6xn$ez8*G<_#$t7U=l zgv+mNP-AgL?*y?3%EIQ~n*fnrx#z~+mpnN5v*gKGVoK1=9vg-RJbEve8L|G(H z7EFIaSDrSxiuGEb_-2Ek`SqbfkWj{gelRjzMI@4YpHJ&k5aH~bRnNVqi zSjwEw*~-Nm)Jh4Z^YMTFLqo<9$=lk*X(dza#|$A0ixic)fIm#WAwXt%@k{_d3ND=K zE!!((VPh|_v}MC&(t#a>5HgZJu2Hg&H~fzGx+q@YM@HZNs6dONMN^NGYfAa_37ARX z00A&VP0Rqy`8z%ODZ9v6>yITQ^QMD+?svu9ta+{+&%I*aAuaTkCjp;dhS@s+bZ;vx zM&EuA#ahsAE*Z4+X%h$EW0n~|B7RHtUf+<#UuOxPr+|9|hIQ60-hwSG$Ud^$9(B zzx(S(FxlY~2}!A{V_b#SVH#|c!Dm_o`)oT~Dbk56sME!uh2)CwIkqX(DS&JmBcK=E z_V+Xw|(tUS6A~xHP zm~GPcggTJ7&g4DtR3%{<1fj+qi7y>ZUQGxeuGUBI^g~q`!k*#!o_bnyBsf%qMGpy8 z4}M@V$Ndm3&=iG$wm^cYrC&2WC8G;p7$y?LzhZGj9(K9JhSEARgdd*>&9)5e`XP$f zV+=}I4_Q#12t4R@B}2$M;RkSE=vU}qt*PFOSJNxTTnspc}(f}4g$lXWgJ{23@ z3GkDlal~pbv}5(g>DIT#KKHB#xx3MiG5&@0K!S~PR%wF?nrtT2*^GrXHZz9iLkE9# zgm)yN;xhF~RMRK+%wcMOutc0lkgq$|V=TW(g&Ll=u4yla<3)uTJiB#GHIvj$l~cu9 z0sn0m!wDY58(yRw_-^c5BD;~%K&2I0V%xlq?QFCqnDGUBV6Kt}rFD2FGo=^VH3}6h z5sMP8$SZ@vR)#CEv!a-@KU5yt^=I^)hBopyI{3q`Cd{hMoPL0k)tUr$^xRlR-i^R{ z^u~&Dgp`@7VYpK}6&~4kHA`S8_V?*>n$xcp;A_6RAeN}f^jnO{_qGx1^^W$`-8&su zC_GuJ7Tb-=c(a5;Z?ROn&(Sb$NG8Bp{;&`}f}BhReDe&%r$hQoQ-pE^Q)2WnrWPMb z+KID*83jx!5liIAJDt3N?`Rghuq{DQcRMB90tZRS>&g zwUy!*mdI(#_UegV!f3VGq$*n%D4^8#F47ZUgzgXY4)Z+Kqe%F2KlBD=AqcpF#zn*vu5U*OA~V zYZ#nz@S{@PuC&o3x|7c`P|?(YbKZtZ+U$aX3-9K3Yl0s$xiu;{t%*IM4wIy~D{;$g z_L)m0JTPg>Ig97kLt>+G~j zIEh?Ld|Izu6|?(|gvGayhIn4ejZ7)dM4&d2G~PGb?ZSm;oMe7J%{Gj6G!o4`8gi28 z+Ub{RC0|_?x7&-j;d?H6=*!D_9d$@7X{`9$1yL4ofI1{UBtKwlA7|gpJ&w1@_BAMN=r%RE zj{v^QJ(Z{Hrcd|n&$vTzPZB o#m(qP=`OT=qX#RNVAVK2AVH{?`-xj{%nwrrA481g#;LUdWaL&7a+cOU3t-fP*(U>}`2h^(;m z>oQGF6#35v_32xg%<4u z=>!oT!7#B_zrA}yM*F-GFlWYrEJ>=j^e4>I(_UczG=$srsf#Yg z34&yv{PN0+t`F>32K8iq_B_KVT)?r1=PNg^r_$zVYqr#8t_nCi1Ov`beeH>-S!qIdGG$oDJ-eK zUtHNIhJ`JMgKQoQgy8~|af>24N&izjv5>==fPmv!l7OUJu%q9Cw!``IHVPRapjib{ zEV-Kj7bl|Ax1Yu0(wD_xU%cEeO9C1&-?_Sh63iSm;c>RVX*!1D#)AoLnlnQjsK7K{ z21|1LD(gGfZqU5P#UkCh*b_fF&vyzb&pfN`1fi^_$Kz=K1P{>UC}=bIiKkS2MpS&Q zO!lc+l+aFHK;^6}6c^~*Y&^`By(P*vGg(TYt1|@-R+l}SPmGQic>|IqO(yLt)x<#b zZfI#Bo8H)A>Fd=Q+^!#+F#-PLE{$@nBNqA|&3U-_IWHpx#5YItjc#GEt;D>lpmcU~ zh!>1S8!m8rjr0TX0nGIox)+rDMMSw@aY<21X)3=d*+dTposRF~yXP^BS z+di#;_y0#M4_w(?CmM0Kw=pe_3;ivFMo|^3G-vsYcIZYeGK_*F7gx}E$Ln_>*jO3c z#^p+E%NC`1&4n$4lMaVCo;(JwSgB)CFpR5sJq!E%2HeNU!g2MS!jL2`pEVMREh!k) z!9H#b^LHl;5`$3_i)9F~H{vJ0d}^&nko5tI3x9fR^&&{QdO(Y35-!f^TiT?l`{!sT zlthxvDN59laBfs~&BvltFIX5zOD+EnjL*>S2DMHvvTImDBZ`LPBix+F0RM1#C{J@p z$bJ6RBeTU67e^N)%O_k+)(yl)g>6mfPf4{iTwx}Ev!ebQ65DW|HiB7?0Xb^-BeF=d z84xoSKlOU;1YeuGz{T2JaZ%Dd+zEligxBm_>YYd3-lG_NvhSEH+j<M?pW{?|W9jy>H6f`lGqMo?qCb%lPqbLOTMERP8;$$x9U| zM8yzMQ3TV3(Sl9I3H&A_gccXB&4BaIT2`FmPV3K3F_LIMvU|+7S_Co+NoLVq6svg| zuL?9LI&rPyhd+3GQqrctgI-pUJl3RoplS^+wJ%k;zTq>9JJNzSG72*chqx3mhX4aH zszX$2jZYpwg-LlEmkZXAD91&`Y*vfEr~^u*YhSf$45e%65RZsj2S*o)xMJD{UWj_* ztNm`6m?zvaiGhCr58|Ub96BKZKIT}x^Z3A37hDd_uY-sS)g$6_u$H_zPe`FqG6cRn zQdpB!Im0fc1)O7VB7{R}pa$lqU5zd7i)o2`%WT(M%qgT5o{(Iws{oVFwaWwy{XAKr zRPPns68In`tMdrS43uj-nZn-_DBH>38MUD9c1NflBx-ldJ#I@!I5pNLE**m4q+=Wp zfo4y&S(b^vvB<+`^C67>wVHzvr?8jI$8`rZWb%FYX6{KX#G^0AsBheiEO*_wI{My> zStjcw9_ms`F)f?9T={()>G{jMPV$sYZ4dRR)suZR;(HJ71P=$PPZDm3A7iF=>WpY> zI~l}J;73lIuIt^qZSH?|I}R@$iX0vTjC(X+&D(yj4Wwe6(nn1K&OFLLhLWQU&k6ZK zyEJ#Wh;elDMiW<$2xd>uGu?zYTo`ntZtc|l`HGmohq^)i%t^Y5L*(I<4|}L1%R-Kn zY=iT9okEtB8S?b?z*-0~xXn!?7V(PFUxuo-N7@}E5-Zbps1reZ0+ zeQU9(Ie2$^Wt*+s4O`yWO#({x^}r4o`Wm9QgG- z__9Dm(Hf|9BX&GHTI_yAE+MKNpKKtPkggL7Z)qO`8$neS3XTnqc2ZQXN#E62BZ!vj zFP1fv^E8tcTJe*@)aO43R5O`vlP|GalU^c&crtLbULNBeJk@CotJWGWzC3f(3|wTZHJ3t9FiF}RztppU9}St6gw;=9c> z`R!t*MT&25ky{he;gcL{HK1Rg#3)rJ$iRSdR`ltUbHWzy*(p~OCxix~-J1&y`WynRV9e!XP4nmG6Cpdp zDCZ`lt8^4_mTRhRVb7qN3wlnFZbEjs)Fif8Orj42CgIw`ro$I#o+Y;z3HusEL`eaI zKRu1VlZ4OzhqFJajG~c+<#wVTbbFpAEc2P~c851!Xy}5Ma?E!aEiyp_Z#2D&jU{OQ z&k=Scos$qP%zWv!PcYO;J#^#JnR72(T>obmJmP=`L-0a&I9w@!Vb|_svXt3epXizNKH&;c|K~{9K*Fk2I5gq%WgY3x4PK1zgLvhTEbByBX*dsDhB+7Q|V^b-6R*ro* z{NBgyTlaS#_g@`8pZ9r>*ZcK)J;PY0B@K_ab`rHq&d)KHsYBuHbeEoA=6d0=NADPY zvP@_FRQ!{Bb|KnO3;w1fmsafwH9|+(h7-gwRHys?xi%H_0@`%8Cmgc+&1`8barS=0 zjzdC>*j&<@Ms}0{qaQ6lj%!=nLRD5VHm1&G=tLz&IQI;WINx+q5zIMvA2Ob%)EI0% zXgqznat>9)b%u$6hFc$5jM3L@4+8W&+&b*b4Dxilwz#(b>bR=?b|@hEXJBKBRvN98 zqI&=n>s9REA0KcGC(ZjZwt}r^jaWK0a6hEc7Kg%T=fU{jV~dTrjbrAgLqwh0aVv>s_AQx5o5St~>(FUD5MLJXr*ek!_02-vh7=;_e%4o`mO z#y&K?v|xp%It^(I>=DOoU2@Bxs+-%ps7sdtzh}%e<{{>xQ|(T7n;i;XS5?@Ybm4WJHd?ZWa zS9lVJDrVJVpad;k2!eifI#gePa^JcpZUEV(^|(b{u$@66SG zy&sxyS6#wY^jxfj7or`gxB~+vQ7Nyyp7J(X^t}5~cUA1~>5BIK{HZVd;7a1TQa|#o zhy16|^^f}R-Znk$VVZpW@bZ^AUUvSiqr(OrS0B}}@b`GpU+Guq+7bwfT%F(14`Np_ zq!XXnyJzVw>U))k45x!XzyBQ?@QgP5&b-|H(;Z8l)nGQbP$#^2&B6n_cB^IXgjI_$ zH!g~1=ECgWPjcgf(@L`UbO0zyK7OQR-|E{t>LbScDGfU|d+Q(T<`aL|efMrLc*8>g zI@DG+h_6fUMx^KuJdJHo^V?}6ro_#Zk0=?DlAQL$ciQuft6S(>vjf(X{Pwu0TdqHrg*FB6>N0A{W$q~11UQB`L?+NrRAE%_9!LePS z7gX^SFj&%S?okPsaj#~{(Pjwzvxpzaa5LpIFqPV14t%|=zcXJNls4$(V#a_Wy{w*1 zTXENwY#C_WVu!$RVzu!JjI3L7ItXT>Ji2 z1K{B9r5IsrcGTwc7?tGzgY> zT~w6!p9C+J4!})97-A%vp2A~^g;8Aj>rordd6iY`41qXo@$%(Zotd%=!H60AV4>gT z0RXqM)DJwgAXrIt9FkQFk0G)^#8BDu41uFsuz1nt6oAYSBjAe^s|+edHqEOH(#P5i znGP-_{;PGf{5S2Ac-PMzauy8Tt;#KOdP% z=Xe$nh&ix7B6B@a=bH?oZB!xIGD3;qP+@bPb!FZdv;eFls}X@6m%l5e;aB&Y)i9NQr1jZe>e&{jcW;5a9qAasjW+&fCP}Wk zcn9HIJxxayhrswp$C*d_BYFl@p+tWO>i3WS>SAbi*~}V=|6ncrExVFfrUSD*uVYV4 zF0gEHRt?IY$*Wwnn;Frn_`{|K!e7Ol50fLkHD3FtKrt=jmaqs(m}3`d z=GT(%A?3o*G2{MQI*Ykx4lD=~B%ViE5;?qI@uWLXN(n%p-zsoR$09cR)OQ4iY^sSV zM}LFY9Z8^nGCGWzDa!)6C-BmEK3NeoT5J$eiOu@}yTz+R>QNwD?yaKDrDI=q;lQ!bn8Q4J^N)}P zToTJ@kS@rN-xgd0*F&@y1{u(ib=hbK?bOAADk*$c+*o0>2vR|H)214+d$W3M$>h@i z?^LLu2a+hf7hcA&R%S7&wIgRRE>~}2G^CE?v*wKoR5Q4BMKotH4kYaU2z7v&#-_~< zxk4|8*B-c?jZ$ou2w0>>G`C|ohXT+2ceuG7)|L}*TZXKdK)OYlM zYOrV)TNjG$K5ZtB7@Ot=u*V^G0Y=VyCVMoQ;3`5XR-*`mFX5o4^k*7b|F&jl8;>WC z@8TkkM&Gn^ICae0JE#mn7C#naY@eeCD;54TE^R@a9sEddn@wtyDXbNDyRazE&DPQl z?~iDRen}wO3MOJ++&!fJeF>E(UPGk9qAjf^(0^r#&SqIL!pqLOWoh~fa=b}O z_7*a@I#>b4PcsKfKdJfk{3rrsz%jQ5qLQJ=k$!Y9YR10CRlUabx>b3NOrKGe?v!u` zTI|jCpMDM}lx@H<9dp&3HtoMOKf(KWm1f?R3uJ4w$}CJl0~F)Le-h%F7#9T6Z0fr6!3|S!5z#TpWy0fBp{@A?c4G6dCk_65h@)E% zIMiK2rKE^1@%n3U2iOsfs{=Ybi7~`ATw7k9DHnk57OB5#KEDWLi;M zmBXSB7O7SvHO0tc6U#Ya18m>%BYa9|)m61W`F{X(>!VjkvC?LgP$wen$J8KC`YwFr z2_97a$Vj$*Na)j3EQ=xZ3FL7&kp#vK{#0Cm?(3;!AhAZW(6XYFnaEl|ZXu~d(H$en zTvmNr^(K7Sx4|){-rlpnYM3a+2>p_daFD1MJbD8*46WdcV`(tV^UN{k`NWfJlO(*U z?pGaWlIJ625O@pB;=g@Ul#YrWpEL@yPQd{b57H}?>wmiFi!*V)BWwT-OcK-CO>nZn z7m1kfIDZ<$1pT*);a~h52ox*#Ui1XCCm%bZR&`{hKqgNRsBm!RRwCS*5hq3L8Y*t) z$>g|?S^?nLpBVx46;1(rti@!9Jdd4?rG1XCemb!atQvVR%;lxaq^5n%)>{0}H~^Xw zau`pSrBtLH?DZUEy9Z32UvRP79Xnq|@og-aPmqkhP@27B-czhJ9c+iCHhVK*jC35F zNjn7zZT2Mk$E&Z4s50)1#8!^IYBnr&6T}(v9gL{u5>1};=`xKM6~7bl*rROD9^V9x zmj2!s*ZYCemwo~0kzT-4lSe7!ayPakKAe9MPRNQ=OuGx3j@C1_YWdTFMj7+IHYm5p zDuJW}n%zKlMM1$i=!=b>(ProT&ce*9Mb7! zlzNW0Cevd6C&>WYRZGGAg^RsG#6;|L8!M!=Cup<6 z3D}slDQbQrxBaRQd1E+_J5F9AN)n@L3DksznPjWGzS&-&6Cs;Ybwv@NSEyFP7<3&6 z>J;f59~e@_Sj|iX&wp5-+vSsXmQ&ezc;-UN{zO5eJ|z_yR`#yEFs}G!_W(XNYu9qL z`&3%_rImXf+XJ>gf}8*%I$JrBSqA*cLEal91C$Up@Wfx%G7@voTLPxkmRck@qk$5U zyy`WBcR!UsJjHB(#El@+7X{<&h2j=Q6am;SpX;T>&Z`{JDs(*_FZccf4<<3!VxqgdPO&C1iCUyk5G9p6v(NG#{&;_R4q`#^X?DP#^$01AMsMCQ@vS@gB>xeQb~Mnbfxd`?MHfxHVS@N>HCX(hpacg)zS+3J_E zq>;)>59yEOWZPqTfNBv;+6_IHt7o)dU+3fMZ|B>(w6iy|`q`_<#vpD*bJ zc{!6N+pn*ckv}W{P1x$@h%X5$s~MgXYfmJ(-DOW!G}_q$;4h|{2?Yl`xl%a?_|@B+ z4LMFr=UZ-0aXfu9%^fQI;*~8gBfuQR-ESli+Fk}a%s9>hzE)Dk`F^9zKA;9;^}b}` znxY(eT>Ls=!f5Wy?(ibp-eQ{g0-!v}-Re;KB*#hKz#h-0WCZ1=R-G2q=i(4Q@>}-W zZNsy*Gq8P%C94(8c@-JYF++e6MEVH{C3;B8bdL(g>9{GCpsfeiRTn6%rPj8<^@g`Q zXc|_uqGft%eL)NHQRA_hHE&{8KXHR;kLI3v{pgP6*Shhk5)>topWTywN$O-O^wy>F zZ==VCcP=-32L(^bx%-hvbo?FD|qB0~Cu zFR5R^oR%X!Y*BF?e)`yH_9UNi?>Fn;&h8n=t!x|gt2$Vv_>jo4PD>N6=nKKitLrb$ z20Eg_1-nfPy?Rr(d+GUS-`Ou+-C&ovOd;>pl+fEoR0Ye~+#?YL8wp2yd;r`tFU^&^ zWWS>DYVF*#mPV&;Tuh4jYi#0~hxa@)1|(l7?0+kWVG@iwOMTcK5@$%}qK^&s)$$L3 zk4w5!V#R^G%MicGy(wq<51bksh?@WrWTZ(targ4X))ynx8;73oD5$d2#P+# z_PxudSGAINGV#_umZN9baO|7^B)36-R^wbwUePMnl=fNA^GiI?3B?C`_>MlhYEboZ z0~Ky<`m<^62ng7l>a-o7rrpkqgC=wbIh$qWo(?-Ve0){L9XT#A%FnQnC3NJTt#>zQ zDJhlPS|ezpQ{cY$zC$qaD?-YjY=@2ej~DsW7nDf5X~h;$x7Hg{O=h84{cSbh8BCTV}df z(8BM>yQM==YaieHY$gJt#`N)!eqp6Y|9t-O1-0;gPyS0JwVJN99b54+e_pU$8M z0Gt)Wj3CXQ&L1Y&8-HLgOPnsEhK3}p;1*e0jmVtK5V!M&T&t`1KGV4hGrG1&j4nb=o z#i(xY@A1#5J5(!+MWx-iS_+r_9|Nhd6HKXGa=;shFVX-;hkG z&mhjMzX(-)R_EEowy^w8R3rFcA1FJz@`Af{mOQ<6k1rPTeMETf%y3-42&zC=PoJ)izv+cPvA!^%Z?+`dS1{tF(vp)5skgpErJr(d*q9^qkP!&HV#0=Mo z2)QWR4Z_;*9I0@85y@xSWiFAICy^Xn5y5rA`b<6(SKrWQ#PA`uQJt6C)#*5o`JTCV z&9<7O?}l zQuvR3@^zJyYIb8Fh?D74( z>fi>9#>nXb6!5>322oWbR_k&0-nOV*Pq!(3HT+`nRZ$PS0voJiAc10Kw~FgYP{YVJ z?95@YLngK{>lIis%&oc^v*3QP>E0jbvsdqIv%N7eH9~>p)LsT5MDBuC>mRySwc8J! zc8_mqVc&fG4hpMm8vu{`zqvDwUruJEMbP3hFdMefN;krh{TX zY}TVy{jPjvn~Oml80`csB)#wxyih+->hUE4b~^%2{@$`0!{kP_Vr(o~u#C-OuH`JB zE}t6*yAKjKM#{rZMc42#?_)$K%9$>HGKY^@UQ!{Zu;p(=_NW--D3|B0)j4OIgVn5Y zuB&MW6?&LgoP>zVB=&w6Ela|7!PGdH;>iYm73#60G?j}1k|GxcS#h%ZJ$ z0CZa5KJ?a41X=qI-2n5=)=*#ael@qJSEQuSqn6k5`E2Hby^gJ(bph#CccW^hr#@)q z-%s~z(eAlXqLB#^zy3;Mv#V(Bk!rccrxU%q|bFxPq6r^&lJqwDztmy5;n zE~t}l$*nz(VteQp2!CX>b&3tign3l9eoDDn@)`tZ0Joz6F*9Jvms0sjWjYY$4l1|$ zeN*aU@F)i3uL;l2U6E7C4(GkAu(@oEN~@yvh|RpYg0k6Li0yW7W}uW~^j)WJ0nA>m^@(@|au9P|M^DL)}n| zhy~b{Gc}X_W~9W9~T~MEo0QW*q_DvEv{F!jd~oIjH>I$-TH#=_V)r9w$;hEJASmx4Dz^} z{+iU<Yrd0!+YCcF)3V$+VDGTxBN;fuW{X5qb~3qz|rR|@-u zI6ZnkjPCed;Sxqjn9jCH>VKeq-p-?aG&O)>VRA$?=&pZIJFWJxPf^p!o_ml$+3iP~ z9PptTgWLaUDH1oQzi{vaiI!*S?o@lkvU#r_8+NYrR4oh2wd{ zq=!S8&F$iEpiaRxuutezqdh)>@O!z1Lz8A*_uxkU`|g{&RZH^K{p2ok+*^LF7DeBd zr;cTqOi!^rfS6k&t9miS`)NyyVshzUkG&a#&ZSF;gMN;HQqMRB@^$v~wSh``KFi2Z zr7e-3tRwH_)<3rUMMwV)X_ub)q5`LHcH`@%!vX+FJe~}P|NNAf{9`F|@r&B>nkkn} zR~(1j--jxAC%$i$wGzbvDhgF{yK$NN86sR7D*2tsfwlwaNgx>(Hi}i{Sa^3K+|pQA z-Z8-3_kM;eJwGU6EghX(i3Zn~cY_RUo#rlAwLbT^Ad&W!5DGrKy8~01Te%m)>x4IC z7ZnOxAy80UQ0zKZ7Q#wDJ=kUFu8apqhzuAM+UzJ=3VluSWaq^=UW3L#Qv(EPz-N*3x2&!lUyte4u zv)jmjn8T#1rN>JpRd!!nIDFl?3}-`v;(r+P=PGB0*B5cm$OoWFsami5IMO^!boeVy zYk;#>+xH!}wyEEe0QUS?*;$Na#@fKT?l9T~U;T|uJSa?FjL!N1=4XF}n`(Wgu$cNq z%QL-d{_(Aw>BmV^s)F9`Y17YFm)WrVmZyMqD`~a&EY^u4tE_0O0uBo3yk(}%6mZ6U zZAjZuJ&+Iy-pG=h8O%d?ZzG}Og<=~WMm^X9i}CWad+!(+_;ou=N9K4rh25?{$+d0_ z&-rGnmi^5@E%%$GTFy5~;b%spO+re}zMIdaD;|m*m;QWK#A6!06@dgF*pl*wt>Y+L z=_qtqvg`Th%`~!rzZQs(Ic{svSyv{TMDA;~DxzbV$Tsz5ikN0aoAkw{vD=?@GFjJr z_)bXSZh$EbbU#WvW0i%QQ=8(NbQrCOF-F6&Zc>A`Wf_$uqYI5tkb?eB$^~5-m zREyVHHH3MR)&56qo$f$9RoCG^pdhCdI%G20)**?@|41jL)se40eVd3{8Q{ZcUTpt~ z3hX#*z>!PNPbWBY8(iIhEOkf)g8evYKtWZbLmcy?{Pp0oosRyi^W;>oflXL6QwNWiO<-}> z*$swW14R-ZPi~PT(z{6PbPR}Ai3MsY{inAV*lP8t-AtK8{Xy0swwMuVKTs$NB@gO> zQdBAYR2@F(CKEZUbPt^yyDt#cI`nz}%&*Iw*_Ya_4!wNqS`~A^0&sUk?OSMDd~dug zxXBBEs7!Y#;@q8*v{O_KZgslIPorallG^daw_?A4Wz0z_%L*kR00TH1Ewh{Uw@}TC zW$0!f@t2B*mYX*>4Q6dkUGr*8jH+U6hgtCdxf}@6)Zhh@Gbe|t9?aNMQQRiCX1)i* z`&g^u<XU8z9$(p9+tf#SJwW9YV$^0I|1!z)IJzl@`YAyu8H>+q z-qccmlr4vdFEP3BCaIOIZlFMg^g{&NBqbU{ov;6?j_rn20supz=GQhlX^ELpe6k3# zK%XYwC>3@hcOJTQQ_U<;6*^di2*SHe2u1BS*4R?JefZ}Hg&v`y1ag`E!1!shn@7#3 zla_QBH2+hS(A>T(AlI2=DdE^;OMgL%t#_e`K@Y*L7VS8YLJ3`^dl57j60}7%|3^Hb z0K?lj!?OWv;+f8|*;0$_y>O;|u0H~reNFUhbmgt-b&xRCi90JeRqO~e-;3s| zW$me4#7a_2{*SxsE8~|b^6PIFdCfd7im<-W58&??dnpQYB}i$$=X+G;YC0TDdZ4;d zdNgbn(2JjeNL$V2y{$!~nYU(WVAB+`dQkF)daO|PJHM{5tmES;S*08R4r>N zqjwyXXX)dz&U%>v>gbIkIcP5g*f}$-RW_bQo(mi>3T&>Tx3l-VW$9GR=<2=jy#@Gj z6Lb}KroA>t9US8C17bz)A-X|AXXF{J6qg~Hw4n{m4G$0f%rc+uH6EsqfgE#1-O=a? zKzB%y*YlLR+$aXc!{lh3J?M=9_RL(}^t3Zddq3BUtjI#U6zg~OX_cwBQ?VU^uCG2G z8wE&&eKGZ;;b%C~Ffh{uZbynw`1{|oq9q%q4(aG2i~C*jcVftZ5YwSJxsZqLR+&vQ z(AA`@ZLwU0gTokd11*1X65Y4jzE+S0?pOSd-J9lL`0)2x1n4VUx)@DKjD827c&Mg= zW71`czx&Xg3WCV4;Tp^f;QcCq`a|!b_BrYUVDprd4{aock>D0+)hltD4u%7IYsuiL^e)Rfc#Xh1fJ zRDnf4s|kQbsa+u_g=l&&gG-@|O4zKX`lGyZ$FgG4mu`TH)1rSF4r!IO$0xz`=~M=e z*ymh3FMIE{CH{$qwLa7jWUl*x)jXZzV%N3d4EZU{Po#9Qfq~&%vppHL=KB?6ez$!} zIUD{>EnBZc7m~dE12|5X@1-+|Sw62Cv5DH8x*kmdk&JGE;pO7{TA5>)+$68ZIX zDSVH9Aj>7jS@&itg9Nw_zCkzxq~LZ{qCLC#5GhZOvd>9ca(B~C<({pw;O?F|XKWF_ zW%Xrl*@2Q?rqpz8+6P3uRSYCa$&X!war6D}0kTsj`Dy9h>{JbWn=P`oK)$Mg!LGdg z7EHLmPatce+``-b{7#1r>(ugH;PlGAAZv+}g}X$e6@KL|tZ#J4CX)mK^{8DcyK zg*kKpE~5)S8i%pK>_+b6lV{2@d_Kp>JvtUq*a{7nSHGL`7VxbEdQC{J)cYX0(5X^H zt*l}W*Zf?e1Gh1G@)iI@rd@dGj=VCOlf^Seo49Pj90vxS$2<)o8$xAdO5mTOx2n|K1l_-r6&HUzg_KCl7e9&Ww^ zp+6}^ccRDrKt0YaEPXn0)1|4x31OGT*F)`U#5GcO1%I=8J#MT^G~lu zaG9|PZ$0{&krgf1^5xufZk#79D*6=^_f)KI+lHwrI!c2RDNHTS74HENpJJ6kUBLZw zc_QFG(*v+%IWdj0{~a&iRLtcM;%!WjPD!ulmlx?AV9LBgt>R0pQnBbIWsVM!>dSNs z&+lWT7yU01OunEr-hpE5aq?R=8g*)g4q=F$1vgg~jnCmSUE#dIuIy6V9N%6DHxzVE zikmE4w=NP$=5i~mFOR{GYCZ3(-+bY@lTb1qoEo<>njp42e;4eV-^%{DC8EkB*B~tv z=%{yP@=RmgeRXOF)vt|pgP0(e;~|d}@qr$v=dE^8Q_834XjQ^EdEVZMK0V;Rd^UK+ zJdi5@?|3nAaj%Jn&IzBtVDXuqLn81X%VGiinVntS2IW!jgFYDl6$jp8HAA4zmd{*?*+0x2U zYOF0h=L}32)YI`rU@^WdT7(U!My1K6sd79%D?bGfF2VzNaRcE2 zhRnOk1@+~K87;{t<)_C-N~8k*-FQ-98o<#*%aZe2{>CKAbFkUVX}i^*_7&*!#=jCM zv8l!b|4-R-w`y>R6T=*SQ7CmQH!7OSR-|_&XxVAgN{D@nW36&k5jhgX7NZ8Oh8X`G zTl1NlxtlEe_Rk!Jwj}>h7(h_CyLLb{LQ9-M72LEIkgZ`AeP)rI1)MMKjPDWF_oJi{S#jtpSNpY0XuyJu7cAoniW3rM>7hy5nC#hrL z4T0GD6aD9{Q2=8oQe*@tM@U!DXVj3cnOQ!87W!s54!2_=vOI> z)44QJ0BqOBso~W5;u*+VSQF8M5=0O^vg}8Vyc#gwDUv|iFJi{^moF;!97rJgMsWip zM5V?l%_fcBCSnb#rd*#f-dL&3B3FVsxhaikFIUx=wow!?+VUSyj&x6^$jU`W9y`YL z$Vs8xGX1?aoYlhhI!5#CXB+31lJ4>i*?CVTDY^amsP$830bO;}r)+W=Wwly8zYz0l z;dFk{m88fObe`@;QZgBSFwabWjhz=W@H17nIy_W?P4|h)lT!PsR|+1ajhjreG$R1Qj#m?D_j^56YIhJV~BbID;+UnWgX2%|NpZy3!2gpEqU zC=?xQUx|Dtr-W{;BzEoHH0B?%$?oa-7c0kNYxcOC3haaz^+z-`tfyy~n{SR9sc6jD zgDa~zz$&$0b{8 zD6??dU=Z1i>k~st5X!7}Ug;@?{vIdJ$+BwVJV`dR~$N$x^*c2ajhEFNSwwmD0H0}*dm*|~4 ziryPS4*w?KDa*DI#iQ8`en&_n6DPNa!B7V-vk^~nEPGGrvkEL5?2w-%sJ@P>W6L5n zOs3=y(`(?xe{Fq0-u1)^RZQ?5-Nkg^F-$?(XfQSF-AWy6$NR%h2!dmNpCM*=g&%Xd zLhe9d%o)lUg$+%<)?MD{J z8~Lrf7=hrjhpRU@&cY3@?Emipo$v}e_Hs3W4ls#Wb0AXwu_vQcqTD*wvk)8NrBdb_ z1u|tYQfqB=(1skD;AoILsPt>(iNCzoN@K>`I}1=z-hiHZ89CBaxu;#mXHbn;v0*jh z|85fqyfaQIEnLtl?;wdki^O4icauq-mR&U)H;;Of8Hv-vX>I^URq0}l#0JArqfh!5 zmT+jUQiOWH@1HN_-l?%qRSvzlk%W}^SEvoVEs|ZD;YQ&wlM*fOph52bU>^R}e37Dw z52_&6$G$$>UI;iZ|M!qpK(f2C2^o^hsD=zvE#nq9Wb>xKv3Q*ia&t4>3A^|%)e0uO zn!|j;Wl2&i+2BGT`c9Et#tY#s<2jfA z{f^hb*Am{V1!=5egiD}`OnRzJCimC9-`~ia^T1^- z;t_45=7-{7wV@I27?~74C|AH~Y!FMAte85MHd#eT7^l?DQkrMKe!ohp|1sM9b4@Aq zq>Cs{Rvh1n0y(7W1%qdVIFW`33Dz0^oce$PHKyIzowv}`McyWx>Htlbi9Z9!Vp5jk z*n6-8ln~YUtlB0WC-1s346Z1(*@xbc{@(hFK$r8XX{4uCf^Bw-6aSeE=6C_m?)6C) z6k8PyE42=zGGHK4H~a6{=KK@s?QJh4cJ$`w{Ul5Q%*+)U7gziH*XB5C7Sy$0?(;1~ z!1g>?Jrq1lx%lemLs^8DY_WaGV8`J}v{!PS@=Y>=3W@DTPX5Pa2+Co)o{wDZN*xA6 z55*1~k?A$^=BCCw<+m1ug_jlsmI4;>wx-3lQPf(@$qczbJnkLiS{^I;wBucDKI zhZmJouD63Wnj41cOwfa5{}uADWd|YLD;2^A;eHXyc?b7_OXLOj5yP~Af#VDFMOBN* zm0`DGQTwh_6>hHRWB{8R3@5VeQrt4&$$)v1!fxI`NIHmhQK?PRL^-hn>-JeDRXRRv zLsB6iQ9-xVQ=5_kfR}fgdFeH_W|NqDNJ9Gc*_~FHSO}OoHa;aaM^PIKhTzcNU3+xu z#Fq?O_NJq8MEh#eO}X#&Beo4T_tDEn7moi|4h7m`4;ZArsE~YE;$Qmj@%BlYmjp{C&_%_FelbN*voN}E zGoDf^EcWI~Dk?V*ZJbFJ;h3vQAP}=2KGbwW;1i-`xy}D+lszJZ40g+}44Y zam`Zt&j$ioCA`ocNsU%}U!^rAES@bl1F-=`0&TdL4}N?(RPf$>_AxgDac(o9s`&#| zi$H+~e+O!kl*eS#@>Nhhu&G!%@m8<61ThmG?!}%+!o`aJ-ZKBYrw7Z-E6x}}kuvU& z3?h;F5^*$3!=+Y-9AD6G)b0gJfAc6x5T#xX9JsnQDVf_b`{Y{$z?@2@^mna;Dgrq- zV9#4X@n>j&n!LL|B-2_VKqG|Hgw~YRkfhr0LFvrp2o{*cS08!shE}uo^eXVYS3v9% zRaonkbee99r`Q{HfgyI7;sad!ivkfAt=pdT`r)2B;@Ghg4jieL0BQ~UL~$*SBc92Kd=5S!I{{B-52bT1 zha%4{0P)Gyiqs}ssn^2ams^InNu|EU=(B(I&kNMjevc9!PdEFbm+NXa?Ph znH#JOMoG>{ckAb?Mk)T;InML+GAbuNa!2VY7!GqZBBe*3{ zE8xN8pq(u0HgO!tkJ1YUSdwAvt0O(x@8=YLXi{j|W|fXeCI@v$cWOb#!$zF#e~H!YAF#SUhR_ssEA@o1;XbJt7L|V?E*Kl5?FVy zx>a<^EC9u$O9kcmWpVr61X+~BfBuCNak~8q;mM6D(@F}>chrQWVHXql3SQ3WWN)dK z;YoXB#9rMTyQ&3~d8f(X4-l z($s5`ylu-kyB=uk*u&8^eWuu;DcV;FaN2nR(Q8(bA_(u*vbl|h!y;8<3W`X+u%tgn z*L7AYS`pe*{plu8RuDT8V^F@$S>^kTyC*U5`+aOj@Y1P#2SFY+D7=;KF7{w=ZmnF+ zlHC&w4Tn`3kgtYy|FjLDHyabnm0M97aZRBYINJkNR}39HG$V z4$NuVR5EOsq6^oNSKRYJqFSEPez^1F1*Q1o&=*V*shMnRuT4Lk*tG-&4WYy+H9EJ* zG&HUlp`Pe2wSx@zLuLK@qH=FK)-*vlxjCOaMNtV1q3wwVifUzy$SG5)urW$*km9d? zQ;!HMr*w{R0HoYboLQ01CnfV7w6U3OLfoR(3#Rd3d~M1>NS7)mIV@>1m(j6Ye_JDS zaHqwy3O?v7%sq+l&KB&SxRMne_*3HP$XW9k%^j0GA_0dbF8{$+>h@%6W(u;MJ9-*0 zKno367X)Uf^IjqVC9}3Dz^QBTrmh_fgvi*iEsOstZiV&EdPirfdKh2^(ZV7}3`wd7 z0+}}NYGfAAa>upVN{F6d45$z=zQUU0oluLIx%)qTe8NsFNTPmLzUh>(nQ6x4|f}SroiVKF=W=sV--98?DM-`w+4@Qb5|W* z9fx$zs7onREBcR6tNvu=4rq(=u79*)5+xps%{a38b!W)MH`d_}dyr-V&*A^s!M%h` z>BljxF*6(}1+o3~%N8d0YwX>ozVGW9usUrqfWH)L)^^?1vBM7= zm>+NZJ$ Date: Tue, 14 May 2019 10:44:54 -0500 Subject: [PATCH 296/737] Update user-roles-windows-defender-advanced-threat-protection.md --- ...-roles-windows-defender-advanced-threat-protection.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md index ab60042a21..c68c954776 100644 --- a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md @@ -59,6 +59,10 @@ The following steps guide you on how to create roles in Windows Defender Securit After creating roles, you'll need to create a machine group and provide access to the machine group by assigning it to a role that you just created. +>[!NOTE] +>The Windows Defender ATP administrator (default) role has administrator permissions. The administrator permissions cannot be assigned >to any other role. On>groups assigned the Windows Defender ATP administrator role have access to all machine groups. + + ## Edit roles 1. Select the role you'd like to edit. @@ -76,6 +80,7 @@ After creating roles, you'll need to create a machine group and provide access t 2. Click the drop-down button and select **Delete role**. -##Related topic + +## Related topic - [User basic permissions to access the portal](basic-permissions-windows-defender-advanced-threat-protection.md) -- [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) \ No newline at end of file +- [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md) From 9d4c6f334383da0079c3ca9ac277acbb521a3600 Mon Sep 17 00:00:00 2001 From: Orlando Rodriguez <49177883+ojrb@users.noreply.github.com> Date: Tue, 14 May 2019 10:49:36 -0500 Subject: [PATCH 297/737] Update user-roles-windows-defender-advanced-threat-protection.md --- .../user-roles-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md index c68c954776..70a52291c3 100644 --- a/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/user-roles-windows-defender-advanced-threat-protection.md @@ -60,7 +60,7 @@ After creating roles, you'll need to create a machine group and provide access t >[!NOTE] ->The Windows Defender ATP administrator (default) role has administrator permissions. The administrator permissions cannot be assigned >to any other role. On>groups assigned the Windows Defender ATP administrator role have access to all machine groups. +>The Windows Defender ATP administrator (default) role has administrator permissions. The administrator permissions cannot be assigned to any other role. On groups assigned the Windows Defender ATP administrator role have access to all machine groups. ## Edit roles From 5ff55a4b81ad5d229a7ab3025a8d79c0e143c734 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 14 May 2019 11:13:31 -0700 Subject: [PATCH 298/737] draft0 --- windows/deployment/planning/windows-10-1903-removed-features.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index 97d7fabc26..e2e49ffb14 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -23,7 +23,7 @@ The following features and functionalities are removed from the installed produc |Feature |Status|Details| |-----------|--------------------|--------- -|Cortana will be removed from Windows 10 in all non-English/US markets. Cortana will still be available for en-us markets. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| +|Cortana something here about VCDs. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| |Cortana on Android is removing all Cortana cross-device functionality from it's application in November. |Removed |This will remove all of the mirrored notifications and Cortana natural language skills for texting or calling a mobile device and finding their phone. The **Your Phone** applicaiton on PC is offering a partial replacement for text notifications from Android phones but not the full spectrum of features. | |XDDM-based remote display driver|Pending Removal|Starting with this release the Remote Desktop Services uses a Windows Display Driver Model (WDDM) based Indirect Display Driver (IDD) for a single session remote desktop. The support for Windows 2000 Display Driver Model (XDDM) based remote display drivers will be removed in a future release. Independent Software Vendors that use XDDM-based remote display driver should plan a migration to the WDDM driver model. For more information on implementing remote display indirect display driver ISVs can reach out to [rdsdev@microsoft.com](mailto:rdsdev@microsoft.com). |Desktop messaging app doesn't offer messages sync |Removed|The messaging app on Desktop has a sync feature that can be used to sync SMS text messages received from Windows Mobile and keep a copy of them on the Desktop. We will be removing the messaging app from Desktop devices in a future release. When sync is removed, you will only be able to access messages from the device that received the message.| From fcbdcdfd772c1bab7eb90de3b136b57115c5bf42 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Tue, 14 May 2019 12:35:56 -0700 Subject: [PATCH 299/737] Added 19H1 policy --- .../policy-configuration-service-provider.md | 3 + .../mdm/policy-csp-search.md | 74 ++++++++++++++++++- 2 files changed, 74 insertions(+), 3 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index 0e20484a66..11c7b36a44 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -2896,6 +2896,9 @@ The following diagram shows the Policy configuration service provider in tree fo

      Search/AllowCortanaInAAD
      +
      + Search/AllowFindMyFiles +
      Search/AllowIndexingEncryptedStoresOrItems
      diff --git a/windows/client-management/mdm/policy-csp-search.md b/windows/client-management/mdm/policy-csp-search.md index 3106f2b945..a5c90b4303 100644 --- a/windows/client-management/mdm/policy-csp-search.md +++ b/windows/client-management/mdm/policy-csp-search.md @@ -6,12 +6,13 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 05/01/2019 +ms.date: 05/14/2019 --- # Policy CSP - Search - +> [!WARNING] +> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
      @@ -25,6 +26,9 @@ ms.date: 05/01/2019
      Search/AllowCortanaInAAD
      +
      + Search/AllowFindMyFiles +
      Search/AllowIndexingEncryptedStoresOrItems
      @@ -181,6 +185,69 @@ The following list shows the supported values: +
      + + +**Search/AllowFindMyFiles** + + + + + + + + + + + + + + + + + + + + + +
      HomeProBusinessEnterpriseEducationMobileMobile Enterprise
      cross markcheck mark6check mark6check mark6check mark6
      + + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
      + + + +Controls if the user can configure search to Find My Files mode, which will search files in secondary hard drives and also outside of the user profile. + + + +ADMX Info: +- GP name: *AllowFindMyFiles* +- GP ADMX file name: *Search.admx* + + + +The following list shows the supported values: + +- 1 (Default) - Find My Files feature can be toggled (still off by default), and the settings UI is present. +- 0 - Find My Files feature is turned off completely, and the settings UI is disabled. + + + + + + + + + + +
      @@ -872,4 +939,5 @@ Footnotes: - 2 - Added in Windows 10, version 1703. - 3 - Added in Windows 10, version 1709. - 4 - Added in Windows 10, version 1803. -- 5 - Added in Windows 10, version 1809. \ No newline at end of file +- 5 - Added in Windows 10, version 1809. +- 6 - Added in Windows 10, version 1903. \ No newline at end of file From af4d5fdb6be9dc153f44fa4d221f838b71e267e7 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 14 May 2019 13:02:57 -0700 Subject: [PATCH 300/737] fix link --- .../windows-autopilot/windows-autopilot-reset-local.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md b/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md index c6b59a7df4..9c3466b10e 100644 --- a/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md +++ b/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md @@ -25,8 +25,8 @@ IT admins can perform a local Windows Autopilot Reset to quickly remove personal To enable local Autopilot Reset in Windows 10: -1. [Enable the policy for the feature](#enable-local-autopilot-reset) -2. [Trigger a reset for each device](#trigger-local-autopilot-reset) +1. [Enable the policy for the feature](#enable-local-windows-autopilot-reset) +2. [Trigger a reset for each device](#trigger-local-windows-autopilot-reset) ## Enable local Windows Autopilot Reset From e35bdb8646db66c1c94376432a8ae286df5bf55c Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Tue, 14 May 2019 13:04:24 -0700 Subject: [PATCH 301/737] fix link --- .../windows-autopilot/windows-autopilot-reset-local.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md b/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md index c6b59a7df4..9c3466b10e 100644 --- a/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md +++ b/windows/deployment/windows-autopilot/windows-autopilot-reset-local.md @@ -25,8 +25,8 @@ IT admins can perform a local Windows Autopilot Reset to quickly remove personal To enable local Autopilot Reset in Windows 10: -1. [Enable the policy for the feature](#enable-local-autopilot-reset) -2. [Trigger a reset for each device](#trigger-local-autopilot-reset) +1. [Enable the policy for the feature](#enable-local-windows-autopilot-reset) +2. [Trigger a reset for each device](#trigger-local-windows-autopilot-reset) ## Enable local Windows Autopilot Reset From 82d51ea0db48b88d54d18bce188b1b0976449025 Mon Sep 17 00:00:00 2001 From: "Nisha Mittal (Wipro Ltd.)" Date: Tue, 14 May 2019 14:05:25 -0700 Subject: [PATCH 302/737] Latest changes done for few issues --- .../resolved-issues-windows-10-1607.yml | 20 ++++++++++++++++ .../resolved-issues-windows-10-1703.yml | 10 ++++++++ .../resolved-issues-windows-10-1709.yml | 20 ++++++++++++++++ .../resolved-issues-windows-10-1803.yml | 20 ++++++++++++++++ ...indows-10-1809-and-windows-server-2019.yml | 4 ++++ ...ndows-7-and-windows-server-2008-r2-sp1.yml | 18 ++++++++++++++ ...windows-8.1-and-windows-server-2012-r2.yml | 16 +++++++++++++ ...esolved-issues-windows-server-2008-sp2.yml | 24 +++++++++++++++++++ .../resolved-issues-windows-server-2012.yml | 22 +++++++++++++++++ ...indows-10-1607-and-windows-server-2016.yml | 8 +++---- .../status-windows-10-1703.yml | 4 ++-- .../status-windows-10-1709.yml | 8 +++---- .../status-windows-10-1803.yml | 8 +++---- ...indows-10-1809-and-windows-server-2019.yml | 6 +++-- ...ndows-7-and-windows-server-2008-r2-sp1.yml | 20 ++++++++-------- ...windows-8.1-and-windows-server-2012-r2.yml | 16 ++++++------- .../status-windows-server-2008-sp2.yml | 22 ++++++++++++----- .../status-windows-server-2012.yml | 12 +++++----- .../windows-message-center.yml | 10 ++++++++ 19 files changed, 222 insertions(+), 46 deletions(-) diff --git a/windows/release-information/resolved-issues-windows-10-1607.yml b/windows/release-information/resolved-issues-windows-10-1607.yml index 72407b6ba9..046eea9c71 100644 --- a/windows/release-information/resolved-issues-windows-10-1607.yml +++ b/windows/release-information/resolved-issues-windows-10-1607.yml @@ -32,6 +32,8 @@ sections: - type: markdown text: " + + @@ -60,6 +62,24 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 14393.2848

      March 12, 2019
      KB4489882
      Resolved
      KB4493473
      April 25, 2019
      02:00 PM PT
      End-user-defined characters (EUDC) may cause blue screen at startup
      If you enable per font end-user-defined characters (EUDC), the system will stop working and a blue screen may appear at startup.

      See details >
      OS Build 14393.2879

      March 19, 2019
      KB4489889
      Resolved
      KB4493470
      April 09, 2019
      10:00 AM PT
      Internet Explorer 11 authentication issue with multiple concurrent logons
      Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

      See details >
      OS Build 14393.2724

      January 08, 2019
      KB4480961
      Resolved
      KB4493470
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + +- title: April 2019 +- items: + - type: markdown + text: " + + +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493473
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4494440.

      Back to top
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      + " + - title: March 2019 - items: - type: markdown diff --git a/windows/release-information/resolved-issues-windows-10-1703.yml b/windows/release-information/resolved-issues-windows-10-1703.yml index a32bfe383c..6d20195ba0 100644 --- a/windows/release-information/resolved-issues-windows-10-1703.yml +++ b/windows/release-information/resolved-issues-windows-10-1703.yml @@ -32,6 +32,7 @@ sections: - type: markdown text: " + @@ -57,6 +58,15 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 15063.1784

      April 25, 2019
      KB4493436
      Resolved
      KB4499181
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 15063.1689

      March 12, 2019
      KB4489871
      Resolved
      KB4493436
      April 25, 2019
      02:00 PM PT
      End-user-defined characters (EUDC) may cause blue screen at startup
      If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

      See details >
      OS Build 15063.1716

      March 19, 2019
      KB4489888
      Resolved
      KB4493474
      April 09, 2019
      10:00 AM PT
      MSXML6 may cause applications to stop responding
      MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

      See details >
      OS Build 15063.1563

      January 08, 2019
      KB4480973
      Resolved
      KB4493474
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 15063.1784

      April 25, 2019
      KB4493436
      Resolved
      KB4499181
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + - title: March 2019 - items: - type: markdown diff --git a/windows/release-information/resolved-issues-windows-10-1709.yml b/windows/release-information/resolved-issues-windows-10-1709.yml index 2893c090ed..2d33536532 100644 --- a/windows/release-information/resolved-issues-windows-10-1709.yml +++ b/windows/release-information/resolved-issues-windows-10-1709.yml @@ -32,6 +32,8 @@ sections: - type: markdown text: " + + @@ -57,6 +59,24 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 16299.1029

      March 12, 2019
      KB4489886
      Resolved
      KB4493440
      April 25, 2019
      02:00 PM PT
      End-user-defined characters (EUDC) may cause blue screen at startup
      If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

      See details >
      OS Build 16299.1059

      March 19, 2019
      KB4489890
      Resolved
      KB4493441
      April 09, 2019
      10:00 AM PT
      MSXML6 causes applications to stop responding if an exception was thrown
      MSXML6 causes applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

      See details >
      OS Build 16299.904

      January 08, 2019
      KB4480978
      Resolved
      KB4493441
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + +- title: April 2019 +- items: + - type: markdown + text: " + + +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493440
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4499179.

      Back to top
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      + " + - title: March 2019 - items: - type: markdown diff --git a/windows/release-information/resolved-issues-windows-10-1803.yml b/windows/release-information/resolved-issues-windows-10-1803.yml index 8eaaa3f3c9..1899a16774 100644 --- a/windows/release-information/resolved-issues-windows-10-1803.yml +++ b/windows/release-information/resolved-issues-windows-10-1803.yml @@ -32,6 +32,8 @@ sections: - type: markdown text: " + + @@ -62,6 +64,24 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 17134.648

      March 12, 2019
      KB4489868
      Resolved
      KB4493437
      April 25, 2019
      02:00 PM PT
      End-user-defined characters (EUDC) may cause blue screen at startup
      If you enable per font end-user-defined characters (EUDC), the system may stop working and a blue screen may appear at startup.

      See details >
      OS Build 17134.677

      March 19, 2019
      KB4489894
      Resolved
      KB4493464
      April 09, 2019
      10:00 AM PT
      First character of the Japanese era name not recognized
      The first character of the Japanese era name is not recognized as an abbreviation and may cause date parsing issues.

      See details >
      OS Build 17134.556

      January 15, 2019
      KB4480976
      Resolved
      KB4487029
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + +- title: April 2019 +- items: + - type: markdown + text: " + + +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493437
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4499167.

      Back to top
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      + " + - title: March 2019 - items: - type: markdown diff --git a/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml b/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml index b0d3c9f294..7e3ded548f 100644 --- a/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml +++ b/windows/release-information/resolved-issues-windows-10-1809-and-windows-server-2019.yml @@ -32,6 +32,8 @@ sections: - type: markdown text: " + + @@ -73,6 +75,8 @@ sections: - type: markdown text: "
      SummaryOriginating updateStatusDate resolved
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:18 PM PT
      Latest cumulative update (KB 4495667) installs automatically
      Reports that the optional cumulative update (KB 4495667) installs automatically.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      May 08, 2019
      03:37 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      After further investigation ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809

      See details >
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Resolved
      May 08, 2019
      03:30 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Resolved
      KB4495667
      May 03, 2019
      12:40 PM PT
      + +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4495667
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4494441.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Latest cumulative update (KB 4495667) installs automatically
      Due to a servicing side issue some users were offered KB4495667 (optional update) automatically and rebooted devices. This issue has been mitigated.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Resolution:: This issue has been mitigated on the servicing side to prevent auto installing of this update. Customers do not need to take any action.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      Resolved:
      May 08, 2019
      03:37 PM PT

      Opened:
      May 05, 2019
      12:01 PM PT
      " diff --git a/windows/release-information/resolved-issues-windows-7-and-windows-server-2008-r2-sp1.yml b/windows/release-information/resolved-issues-windows-7-and-windows-server-2008-r2-sp1.yml index d034127b65..cb278e2cc4 100644 --- a/windows/release-information/resolved-issues-windows-7-and-windows-server-2008-r2-sp1.yml +++ b/windows/release-information/resolved-issues-windows-7-and-windows-server-2008-r2-sp1.yml @@ -32,6 +32,11 @@ sections: - type: markdown text: " + + + + + @@ -55,11 +60,23 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:23 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:21 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493453
      Resolved
      KB4499164
      May 14, 2019
      01:18 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489878
      Resolved
      KB4499164
      May 14, 2019
      01:17 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      April 25, 2019
      02:00 PM PT
      Internet Explorer 11 authentication issue with multiple concurrent logons
      Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

      See details >
      January 08, 2019
      KB4480970
      Resolved
      KB4493472
      April 09, 2019
      10:00 AM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      March 12, 2019
      KB4489878
      Resolved
      KB4493472
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493453
      Resolved
      KB4499164
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + - title: April 2019 - items: - type: markdown text: " + + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:23 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Microsoft and Avast have identified an issue on devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software after you install KB4493472 and restart. Devices may become unresponsive at the login or Welcome screen. Additionally, you may be unable to log in or log in after an extended period of time.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1 
      Resolution: Avast has released emergency updates to address this issue. For more information and AV update schedule, see the Avast support KB article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " @@ -69,6 +86,7 @@ sections: - type: markdown text: " +
      DetailsOriginating updateStatusHistory
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489878, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue was resolved in KB4499164.

      Back to top
      March 12, 2019
      KB4489878
      Resolved
      KB4499164
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      Custom URI schemes may not start corresponding application
      After installing KB4489878, custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites on Internet Explorer.

      Affected platforms: 
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2008 R2 SP1 
      Resolution: This issue is resolved in KB4493472.

      Back to top
      March 12, 2019
      KB4489878
      Resolved
      KB4493472
      Resolved:
      April 09, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      NETDOM.EXE fails to run
      After installing KB4489878, NETDOM.EXE fails to run, and the on-screen error, “The command failed to complete successfully.” appears.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue is resolved in KB4493472.

      Back to top
      March 12, 2019
      KB4489878
      Resolved
      KB4493472
      Resolved:
      April 09, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      diff --git a/windows/release-information/resolved-issues-windows-8.1-and-windows-server-2012-r2.yml b/windows/release-information/resolved-issues-windows-8.1-and-windows-server-2012-r2.yml index 1ef62bfe75..2a62a3f335 100644 --- a/windows/release-information/resolved-issues-windows-8.1-and-windows-server-2012-r2.yml +++ b/windows/release-information/resolved-issues-windows-8.1-and-windows-server-2012-r2.yml @@ -32,6 +32,10 @@ sections: - type: markdown text: " + + + + @@ -55,11 +59,23 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:21 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      May 14, 2019
      01:18 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      April 25, 2019
      02:00 PM PT
      Internet Explorer 11 authentication issue with multiple concurrent logons
      Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

      See details >
      January 08, 2019
      KB4480963
      Resolved
      KB4493446
      April 09, 2019
      10:00 AM PT
      MSXML6 may cause applications to stop responding.
      MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

      See details >
      January 08, 2019
      KB4480963
      Resolved
      KB4493446
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + - title: April 2019 - items: - type: markdown text: " + + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Microsoft and Avast have identified an issue on devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software after you install KB4493446 and restart. Devices may become unresponsive at the login or Welcome screen. Additionally, you may be unable to log in or log in after an extended period of time.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1 
      Resolution: Avast has released emergency updates to address this issue. For more information and AV update schedule, see the Avast support KB article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/resolved-issues-windows-server-2008-sp2.yml b/windows/release-information/resolved-issues-windows-server-2008-sp2.yml index fe19c4b36e..36c4a276c4 100644 --- a/windows/release-information/resolved-issues-windows-server-2008-sp2.yml +++ b/windows/release-information/resolved-issues-windows-server-2008-sp2.yml @@ -32,6 +32,10 @@ sections: - type: markdown text: " + + + + @@ -50,11 +54,31 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Resolved
      May 14, 2019
      01:19 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489880
      Resolved
      KB4499149
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493460
      Resolved
      KB4499149
      May 14, 2019
      01:18 PM PT
      Embedded objects may display incorrectly
      Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

      See details >
      February 12, 2019
      KB4487023
      Resolved
      KB4493471
      April 09, 2019
      10:00 AM PT
      NETDOM.EXE fails to run
      NETDOM.EXE fails to run and the error, “The command failed to complete successfully.” appears on screen.

      See details >
      March 12, 2019
      KB4489880
      Resolved
      KB4493471
      April 09, 2019
      10:00 AM PT
      First character of the Japanese era name not recognized as an abbreviation
      The first character of the Japanese era name is not recognized as an abbreviation and may cause date parsing issues.

      See details >
      January 17, 2019
      KB4480974
      Resolved
      KB4489880
      March 12, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493460
      Resolved
      KB4499149
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + +- title: April 2019 +- items: + - type: markdown + text: " + + + +
      DetailsOriginating updateStatusHistory
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493471.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493471
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493471.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493471
      Resolved
      Resolved:
      May 14, 2019
      01:19 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      + " + - title: March 2019 - items: - type: markdown text: " +
      DetailsOriginating updateStatusHistory
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489880, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue was resolved in KB4499149.

      Back to top
      March 12, 2019
      KB4489880
      Resolved
      KB4499149
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      NETDOM.EXE fails to run
      After installing KB4489880, NETDOM.EXE fails to run, and the on-screen error, “The command failed to complete successfully.” appears.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue is resolved in KB4493471.

      Back to top
      March 12, 2019
      KB4489880
      Resolved
      KB4493471
      Resolved:
      April 09, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/resolved-issues-windows-server-2012.yml b/windows/release-information/resolved-issues-windows-server-2012.yml index b2a7ce07c1..a18dd90804 100644 --- a/windows/release-information/resolved-issues-windows-server-2012.yml +++ b/windows/release-information/resolved-issues-windows-server-2012.yml @@ -32,6 +32,9 @@ sections: - type: markdown text: " + + + @@ -53,6 +56,25 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " +
      SummaryOriginating updateStatusDate resolved
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      May 14, 2019
      01:18 PM PT
      Internet Explorer 11 authentication issue with multiple concurrent logons
      Internet Explorer 11 users may encounter issues if two or more people use the same user account for multiple, concurrent login sessions on the same Windows Server machine.

      See details >
      January 08, 2019
      KB4480975
      Resolved
      KB4493451
      April 09, 2019
      10:00 AM PT
      MSXML6 may cause applications to stop responding
      MSXML6 may cause applications to stop responding if an exception was thrown during node operations, such as appendChild(), insertBefore(), and moveNode().

      See details >
      January 08, 2019
      KB4480975
      Resolved
      KB4493451
      April 09, 2019
      10:00 AM PT
      Embedded objects may display incorrectly
      Any compound document (OLE) server application that places embedded objects into the Windows Metafile (WMF) using the PatBlt API may display embedded objects incorrectly.

      See details >
      February 12, 2019
      KB4487025
      Resolved
      KB4493451
      April 09, 2019
      10:00 AM PT
      + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + +- title: April 2019 +- items: + - type: markdown + text: " + + + +
      DetailsOriginating updateStatusHistory
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493451.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493451
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493451.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493451
      Resolved
      Resolved:
      May 14, 2019
      01:19 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      + " + - title: February 2019 - items: - type: markdown diff --git a/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml b/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml index d444c69dac..a892f9ad48 100644 --- a/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml +++ b/windows/release-information/status-windows-10-1607-and-windows-server-2016.yml @@ -60,13 +60,13 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - + +
      SummaryOriginating updateStatusLast updated
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Investigating
      April 25, 2019
      02:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 14393.2931

      April 25, 2019
      KB4492241
      Mitigated
      May 10, 2019
      10:35 AM PT
      Cluster service may fail if the minimum password length is set to greater than 14
      The cluster service may fail to start with the error “2245 (NERR_PasswordTooShort)” if the Group Policy “Minimum Password Length” is configured with greater than 14 characters.

      See details >
      OS Build 14393.2639

      November 27, 2018
      KB4467684
      Mitigated
      April 25, 2019
      02:00 PM PT
      Issue using PXE to start a device from WDS
      There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

      See details >
      OS Build 14393.2848

      March 12, 2019
      KB4489882
      Mitigated
      April 25, 2019
      02:00 PM PT
      SCVMM cannot enumerate and manage logical switches deployed on the host
      For hosts managed by System Center Virtual Machine Manager (VMM), VMM cannot enumerate and manage logical switches deployed on the host.

      See details >
      OS Build 14393.2639

      November 27, 2018
      KB4467684
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 14393.2724

      January 08, 2019
      KB4480961
      Mitigated
      April 25, 2019
      02:00 PM PT
      Windows may not start on certain Lenovo and Fujitsu laptops with less than 8GB of RAM
      Windows may fail to start on certain Lenovo and Fujitsu laptops that have less than 8 GB of RAM.

      See details >
      OS Build 14393.2608

      November 13, 2018
      KB4467691
      Mitigated
      February 19, 2019
      10:00 AM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 14393.2848

      March 12, 2019
      KB4489882
      Resolved
      KB4493473
      April 25, 2019
      02:00 PM PT
      " @@ -83,7 +83,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      OS Build 14393.2931

      April 25, 2019
      KB4492241
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -92,7 +92,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493473
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release. 

      Back to top
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Investigating
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493473
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4494440.

      Back to top
      OS Build 14393.2941

      April 25, 2019
      KB4493473
      Resolved
      KB4494440
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      " diff --git a/windows/release-information/status-windows-10-1703.yml b/windows/release-information/status-windows-10-1703.yml index c0cfa4ac36..6d7e9ed3ed 100644 --- a/windows/release-information/status-windows-10-1703.yml +++ b/windows/release-information/status-windows-10-1703.yml @@ -60,8 +60,8 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - +
      SummaryOriginating updateStatusLast updated
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 15063.1771

      April 25, 2019
      KB4492242
      Mitigated
      May 10, 2019
      10:35 AM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 15063.1563

      January 08, 2019
      KB4480973
      Mitigated
      April 25, 2019
      02:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 15063.1784

      April 25, 2019
      KB4493436
      Resolved
      KB4499181
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 15063.1689

      March 12, 2019
      KB4489871
      Resolved
      KB4493436
      April 25, 2019
      02:00 PM PT
      " @@ -78,7 +78,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      OS Build 15063.1771

      April 25, 2019
      KB4492242
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 15063.1784

      April 25, 2019
      KB4493436
      Resolved
      KB4499181
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " diff --git a/windows/release-information/status-windows-10-1709.yml b/windows/release-information/status-windows-10-1709.yml index 2618d42ebf..432a4cc2de 100644 --- a/windows/release-information/status-windows-10-1709.yml +++ b/windows/release-information/status-windows-10-1709.yml @@ -60,9 +60,9 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - + +
      SummaryOriginating updateStatusLast updated
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Investigating
      April 25, 2019
      02:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 16299.1111

      April 25, 2019
      KB4492243
      Mitigated
      May 10, 2019
      10:35 AM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 16299.904

      January 08, 2019
      KB4480978
      Mitigated
      April 25, 2019
      02:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 16299.1029

      March 12, 2019
      KB4489886
      Resolved
      KB4493440
      April 25, 2019
      02:00 PM PT
      " @@ -79,7 +79,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      OS Build 16299.1111

      April 25, 2019
      KB4492243
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -88,7 +88,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493440
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release. 

      Back to top
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Investigating
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493440
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4499179.

      Back to top
      OS Build 16299.1127

      April 25, 2019
      KB4493440
      Resolved
      KB4499179
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      " diff --git a/windows/release-information/status-windows-10-1803.yml b/windows/release-information/status-windows-10-1803.yml index 9fea9cbeb3..b410878b1a 100644 --- a/windows/release-information/status-windows-10-1803.yml +++ b/windows/release-information/status-windows-10-1803.yml @@ -60,10 +60,10 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - + +
      SummaryOriginating updateStatusLast updated
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Investigating
      April 25, 2019
      02:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17134.730

      April 25, 2019
      KB4492245
      Mitigated
      May 10, 2019
      10:35 AM PT
      Issue using PXE to start a device from WDS
      Using PXE to start a device from a WDS server configured to use Variable Window Extension may cause the connection to the WDS server to terminate prematurely.

      See details >
      OS Build 17134.648

      March 12, 2019
      KB4489868
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 17134.523

      January 08, 2019
      KB4480966
      Mitigated
      April 25, 2019
      02:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      May 14, 2019
      01:18 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 17134.648

      March 12, 2019
      KB4489868
      Resolved
      KB4493437
      April 25, 2019
      02:00 PM PT
      " @@ -80,7 +80,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      OS Build 17134.730

      April 25, 2019
      KB4492245
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -89,7 +89,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493437
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release. 

      Back to top
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Investigating
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4493437
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4499167.

      Back to top
      OS Build 17134.753

      April 25, 2019
      KB4493437
      Resolved
      KB4499167
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      April 25, 2019
      02:00 PM PT
      " diff --git a/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml b/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml index afb53b80c9..08eeb85366 100644 --- a/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml +++ b/windows/release-information/status-windows-10-1809-and-windows-server-2019.yml @@ -65,12 +65,13 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - + + @@ -89,9 +90,10 @@ sections: - type: markdown text: "
      SummaryOriginating updateStatusLast updated
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Mitigated
      May 10, 2019
      10:35 AM PT
      Devices with some Asian language packs installed may receive an error
      After installing the KB4493509 devices with some Asian language packs installed may receive the error, \"0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_F

      See details >
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Mitigated
      May 03, 2019
      10:59 AM PT
      Printing from Microsoft Edge or other UWP apps, you may receive the error 0x80070007
      Attempting to print from Microsoft Edge or other Universal Windows Platform (UWP) applications, you may receive an error.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Mitigated
      May 02, 2019
      04:47 PM PT
      Issue using PXE to start a device from WDS
      Using PXE to start a device from a WDS server configured to use Variable Window Extension may cause the connection to the WDS server to terminate prematurely.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Mitigated
      April 09, 2019
      10:00 AM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 17763.253

      January 08, 2019
      KB4480116
      Mitigated
      April 09, 2019
      10:00 AM PT
      Audio not working on monitors or TV connected to a PC via HDMI, USB, or DisplayPort
      Upgrade block: Microsoft has identified issues with certain new Intel display drivers, which accidentally turn on unsupported features in Windows.

      See details >
      OS Build 17763.134

      November 13, 2018
      KB4467708
      Mitigated
      March 15, 2019
      12:00 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:18 PM PT
      Latest cumulative update (KB 4495667) installs automatically
      Reports that the optional cumulative update (KB 4495667) installs automatically.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      May 08, 2019
      03:37 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      After further investigation ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809

      See details >
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Resolved
      May 08, 2019
      03:30 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Resolved
      KB4495667
      May 03, 2019
      12:40 PM PT
      - + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Devices with some Asian language packs installed may receive an error
      After installing the April 2019 Cumulative Update (KB4493509), devices with some Asian language packs installed may receive the error, \"0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_FOUND.\"

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Workaround:
      1. Uninstall and reinstall any recently added language packs. For instructions, see \"Manage the input and display language settings in Windows 10\".
      2. Click Check for Updates and install the April 2019 Cumulative Update. For instructions, see \"Update Windows 10\".
      Note: If reinstalling the language pack does not mitigate the issue, reset your PC as follows:
      1. Go to Settings app -> Recovery.
      2. Click on Get Started under \"Reset this PC\" recovery option.
      3. Select \"Keep my Files\".
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Mitigated
      Last updated:
      May 03, 2019
      10:59 AM PT

      Opened:
      May 02, 2019
      04:36 PM PT
      Printing from Microsoft Edge or other UWP apps, you may receive the error 0x80070007
      When attempting to print from Microsoft Edge or other Universal Windows Platform (UWP) applications you may receive the error, \"Your printer has experienced an unexpected configuration problem. 0x80070007e.\"
       
      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Workaround: You can use another browser, such as Internet Explorer to print your documents.
       
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Mitigated
      Last updated:
      May 02, 2019
      04:47 PM PT

      Opened:
      May 02, 2019
      04:47 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4495667
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4494441.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Latest cumulative update (KB 4495667) installs automatically
      Due to a servicing side issue some users were offered KB4495667 (optional update) automatically and rebooted devices. This issue has been mitigated.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Resolution:: This issue has been mitigated on the servicing side to prevent auto installing of this update. Customers do not need to take any action.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      Resolved:
      May 08, 2019
      03:37 PM PT

      Opened:
      May 05, 2019
      12:01 PM PT
      " diff --git a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml index 0ce3cb79c0..6f79cac2fd 100644 --- a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml +++ b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml @@ -60,12 +60,12 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - - - - + + + + +
      SummaryOriginating updateStatusLast updated
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493453
      Mitigated
      May 10, 2019
      10:35 AM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Mitigated
      May 08, 2019
      03:29 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Mitigated
      May 03, 2019
      08:50 AM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489878
      Mitigated
      April 25, 2019
      02:00 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Mitigated
      April 25, 2019
      02:00 PM PT
      System may be unresponsive after restart with certain McAfee antivirus products
      Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup.

      See details >
      April 09, 2019
      KB4493472
      Mitigated
      April 25, 2019
      02:00 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:23 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      May 14, 2019
      01:21 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493453
      Resolved
      KB4499164
      May 14, 2019
      01:18 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489878
      Resolved
      KB4499164
      May 14, 2019
      01:17 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >
      April 09, 2019
      KB4493472
      Resolved
      April 25, 2019
      02:00 PM PT
      " @@ -82,7 +82,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      April 25, 2019
      KB4493453
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493453
      Resolved
      KB4499164
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -91,10 +91,10 @@ sections: - type: markdown text: " - - - + + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Microsoft has temporarily blocked devices from receiving this update if ArcaBit antivirus software is installed.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Workaround: ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493472
      Mitigated
      Last updated:
      May 08, 2019
      03:29 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Microsoft has temporarily blocked devices from receiving this update if Avira antivirus software is installed.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Next steps: Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493472
      Mitigated
      Last updated:
      May 03, 2019
      08:50 AM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493472.

      Microsoft has temporarily blocked devices from receiving this update if the Sophos Endpoint is installed until a solution is available.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493472
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart with certain McAfee antivirus products
      Microsoft and McAfee have identified an issue on devices with McAfee Endpoint Security (ENS) Threat Prevention 10.x or McAfee Host Intrusion Prevention (Host IPS) 8.0 or McAfee VirusScan Enterprise (VSE) 8.8 installed. It may cause the system to have slow startup or become unresponsive at restart after installing this update. 

      Affected platforms:
      • Client:  Windows 8.1; Windows 7 SP1
      • Server:  Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Workaround: Guidance for McAfee customers can be found in the following McAfee support articles: 
      Next steps: We are presently investigating this issue with McAfee. We will provide an update once we have more information.

      Back to top
      April 09, 2019
      KB4493472
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:23 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493472.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Microsoft and Avast have identified an issue on devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software after you install KB4493472 and restart. Devices may become unresponsive at the login or Welcome screen. Additionally, you may be unable to log in or log in after an extended period of time.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1 
      Resolution: Avast has released emergency updates to address this issue. For more information and AV update schedule, see the Avast support KB article.

      Back to top
      April 09, 2019
      KB4493472
      Resolved
      Resolved:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " @@ -104,6 +104,6 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489878, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Workaround: To mitigate this issue, use one of the following options:
      • Option 1: Purge the Kerberos tickets on the application server. After the Kerberos ticket expires, the issue will occur again, and you must purge the tickets again.
      • Option 2: If purging does not mitigate the issue, restart the application; for example, restart the Internet Information Services (IIS) app pool associated with the SQL server.
      • Option 3: Use constrained delegation.
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      March 12, 2019
      KB4489878
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489878, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue was resolved in KB4499164.

      Back to top
      March 12, 2019
      KB4489878
      Resolved
      KB4499164
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml index a16b0e0d20..95db74d05b 100644 --- a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml +++ b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml @@ -60,13 +60,13 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - - - + + + +
      SummaryOriginating updateStatusLast updated
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493443
      Mitigated
      May 10, 2019
      10:35 AM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Mitigated
      May 08, 2019
      03:29 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Mitigated
      May 03, 2019
      08:50 AM PT
      Issue using PXE to start a device from WDS
      There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

      See details >
      March 12, 2019
      KB4489881
      Mitigated
      April 25, 2019
      02:00 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

      See details >
      January 08, 2019
      KB4480963
      Mitigated
      April 25, 2019
      02:00 PM PT
      System may be unresponsive after restart with certain McAfee antivirus products
      Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup.

      See details >
      April 09, 2019
      KB4493446
      Mitigated
      April 18, 2019
      05:00 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:21 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      May 14, 2019
      01:18 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      April 25, 2019
      02:00 PM PT
      " @@ -83,7 +83,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      April 25, 2019
      KB4493443
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -92,10 +92,10 @@ sections: - type: markdown text: " - - - + + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Microsoft has temporarily blocked devices from receiving this update if ArcaBit antivirus software is installed.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Workaround: ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493446
      Mitigated
      Last updated:
      May 08, 2019
      03:29 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Microsoft has temporarily blocked devices from receiving this update if Avira antivirus software is installed.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Next steps: Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493446
      Mitigated
      Last updated:
      May 03, 2019
      08:50 AM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493446.

      Microsoft has temporarily blocked devices from receiving this update if the Sophos Endpoint is installed until a solution is available.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493446
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart with certain McAfee antivirus products
      Microsoft and McAfee have identified an issue on devices with McAfee Endpoint Security (ENS) Threat Prevention 10.x or McAfee Host Intrusion Prevention (Host IPS) 8.0 or McAfee VirusScan Enterprise (VSE) 8.8 installed. It may cause the system to have slow startup or become unresponsive at restart after installing this update. 

      Affected platforms:
      • Client:  Windows 8.1; Windows 7 SP1
      • Server:  Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Workaround: Guidance for McAfee customers can be found in the following McAfee support articles:  
      Next steps: We are presently investigating this issue with McAfee. We will provide an update once we have more information. 

      Back to top
      April 09, 2019
      KB4493446
      Mitigated
      Last updated:
      April 18, 2019
      05:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms:
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. ArcaBit has released an update to address this issue. For more information, see the Arcabit support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:22 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493446.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Microsoft and Avast have identified an issue on devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software after you install KB4493446 and restart. Devices may become unresponsive at the login or Welcome screen. Additionally, you may be unable to log in or log in after an extended period of time.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2008 R2 SP1 
      Resolution: Avast has released emergency updates to address this issue. For more information and AV update schedule, see the Avast support KB article.

      Back to top
      April 09, 2019
      KB4493446
      Resolved
      Resolved:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/status-windows-server-2008-sp2.yml b/windows/release-information/status-windows-server-2008-sp2.yml index 689abfde38..b87565393b 100644 --- a/windows/release-information/status-windows-server-2008-sp2.yml +++ b/windows/release-information/status-windows-server-2008-sp2.yml @@ -60,9 +60,10 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - - + + + +
      SummaryOriginating updateStatusLast updated
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Mitigated
      May 03, 2019
      08:51 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Mitigated
      April 25, 2019
      02:00 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489880
      Mitigated
      April 25, 2019
      02:00 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493471
      Resolved
      May 14, 2019
      01:19 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >
      March 12, 2019
      KB4489880
      Resolved
      KB4499149
      May 14, 2019
      01:18 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493460
      Resolved
      KB4499149
      May 14, 2019
      01:18 PM PT
      " @@ -73,13 +74,22 @@ sections:
      " +- title: May 2019 +- items: + - type: markdown + text: " + + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493460
      Resolved
      KB4499149
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      + " + - title: April 2019 - items: - type: markdown text: " - - + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493471.

      Microsoft has temporarily blocked devices from receiving this update if Avira antivirus software is installed.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Next steps: Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article

      Back to top
      April 09, 2019
      KB4493471
      Mitigated
      Last updated:
      May 03, 2019
      08:51 AM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493471.

      Microsoft has temporarily blocked devices from receiving this update if the Sophos Endpoint is installed until a solution is available.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493471
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493471.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493471
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493471.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493471
      Resolved
      Resolved:
      May 14, 2019
      01:19 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " @@ -88,6 +98,6 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489880, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Workaround: To mitigate this issue, use one of the following options:
      • Option 1: Purge the Kerberos tickets on the application server. After the Kerberos ticket expires, the issue will occur again, and you must purge the tickets again.
      • Option 2: If purging does not mitigate the issue, restart the application; for example, restart the Internet Information Services (IIS) app pool associated with the SQL server.
      • Option 3: Use constrained delegation.
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      March 12, 2019
      KB4489880
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      Authentication may fail for services after the Kerberos ticket expires
      After installing KB4489880, some customers report that authentication fails for services that require unconstrained delegation after the Kerberos ticket expires (the default is 10 hours). For example, the SQL server service fails.

      Affected platforms: 
      • Client: Windows 7 SP1
      • Server: Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue was resolved in KB4499149.

      Back to top
      March 12, 2019
      KB4489880
      Resolved
      KB4499149
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      March 12, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/status-windows-server-2012.yml b/windows/release-information/status-windows-server-2012.yml index be5f206c02..3ad111d345 100644 --- a/windows/release-information/status-windows-server-2012.yml +++ b/windows/release-information/status-windows-server-2012.yml @@ -60,11 +60,11 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      - - - + + +
      SummaryOriginating updateStatusLast updated
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493462
      Mitigated
      May 10, 2019
      10:35 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Mitigated
      May 03, 2019
      08:51 AM PT
      Issue using PXE to start a device from WDS
      There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

      See details >
      March 12, 2019
      KB4489891
      Mitigated
      April 25, 2019
      02:00 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

      See details >
      January 08, 2019
      KB4480975
      Mitigated
      April 25, 2019
      02:00 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      May 14, 2019
      01:18 PM PT
      " @@ -80,7 +80,7 @@ sections: - type: markdown text: " - +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Workaround: Until a resolution is released, we recommend switching to a different Japanese font, such as Yu Gothic or MS Mincho. Alternatively, you can uninstall the optional update.

      Next steps: Microsoft is working on a resolution and estimates a solution will be available in mid-May.

      Back to top
      April 25, 2019
      KB4493462
      Mitigated
      Last updated:
      May 10, 2019
      10:35 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " @@ -89,8 +89,8 @@ sections: - type: markdown text: " - - + +
      DetailsOriginating updateStatusHistory
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493451.

      Microsoft has temporarily blocked devices from receiving this update if Avira antivirus software is installed.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Next steps: Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493451
      Mitigated
      Last updated:
      May 03, 2019
      08:51 AM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493451.

      Microsoft has temporarily blocked devices from receiving this update if the Sophos Endpoint is installed until a solution is available.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493451
      Mitigated
      Last updated:
      April 25, 2019
      02:00 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Microsoft and Sophos have identified an issue on devices with Sophos Endpoint Protection installed and managed by either Sophos Central or Sophos Enterprise Console (SEC) that may cause the system to become unresponsive upon restart after installing KB4493451.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Sophos has released an update to address this issue. Guidance for Sophos Endpoint and Sophos Enterprise Console customers can be found in the Sophos support article.

      Back to top
      April 09, 2019
      KB4493451
      Resolved
      Resolved:
      May 14, 2019
      01:21 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Microsoft and Avira have identified an issue on devices with Avira antivirus software installed that may cause the system to become unresponsive upon restart after installing KB4493451.

      Affected platforms: 
      • Client: Windows 8.1; Windows 7 SP1 
      • Server: Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2
      Resolution: This issue has been resolved. Microsoft has removed the temporary block for all affected Windows updates. Avira has released an automatic update to address this issue. Guidance for Avira customers can be found in the Avira support article.

      Back to top
      April 09, 2019
      KB4493451
      Resolved
      Resolved:
      May 14, 2019
      01:19 PM PT

      Opened:
      April 09, 2019
      10:00 AM PT
      " diff --git a/windows/release-information/windows-message-center.yml b/windows/release-information/windows-message-center.yml index bcea3b01d7..8a536a1681 100644 --- a/windows/release-information/windows-message-center.yml +++ b/windows/release-information/windows-message-center.yml @@ -50,6 +50,16 @@ sections: text: " + + + - @@ -93,9 +93,9 @@ sections:
      MessageDate
      Reminder: Install the latest SSU for a smoother update experience
      We strongly recommend that you install the latest servicing stack update (SSU) before installing any Windows update; especially as an SSU may be a prerequisite for some updates. If you have difficulty installing Windows updates, verify that you have installed the latest SSU package for your version of Windows and then try installing the update again. Links to the latest SSU are always provided in the “How to get this update” section of each update KB article (e.g., KB4494441). For more information about SSUs, see our Servicing stack updates guidance.
      May 14, 2019
      10:00 AM PT
      Take action: Update Remote Desktop Services on older versions of Windows
      Today, we released fixes for a critical wormable, remote code execution vulnerability (CVE-2019-0708) in Remote Desktop Services—formerly known as Terminal Services. This vulnerability affects Windows 7, Windows Server 2008 R2, and earlier versions of Windows nearing end of support. It does not affect Windows 8, Windows Server 2012, or newer operating systems. While we have not observed attacks exploiting this vulnerability, affected systems should be patched with priority. Here is what you need to know:
      +Call to action: +
        +
      • If you are running a supported version of Windows and have automatic updates enabled, you are automatically protected and do not need to take any action.
      • +
      • If you are managing updates on behalf of your organization, you should download the latest updates from the Microsoft Security Update Guide and apply them to your Windows 7, Windows Server 2008 R2, and Windows Server 2008 devices as soon as possible.
      • +
      +Given the potential impact to customers and their businesses, we have also released security updates for Windows XP and Windows Server 2003, even though these operating systems have reached end of support (except by custom support agreements). While we recommend that you upgrade to the current version of Windows to benefit from the latest security protections, these updates are available from the Microsoft Update Catalog only. For more information, see KB4500705. +
      +
      May 14, 2019
      10:00 AM PT
      Reminder: Windows 10 update servicing cadence
      This month we received questions about the cadence of updates we released in April and May 2019. Here's a quick recap of our releases and servicing cadence:
      Issue using PXE to start a device from WDS
      Using PXE to start a device from a WDS server configured to use Variable Window Extension may cause the connection to the WDS server to terminate prematurely.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Mitigated
      April 09, 2019
      10:00 AM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, \"STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)\".

      See details >
      OS Build 17763.253

      January 08, 2019
      KB4480116
      Mitigated
      April 09, 2019
      10:00 AM PT
      Audio not working on monitors or TV connected to a PC via HDMI, USB, or DisplayPort
      Upgrade block: Microsoft has identified issues with certain new Intel display drivers, which accidentally turn on unsupported features in Windows.

      See details >
      OS Build 17763.134

      November 13, 2018
      KB4467708
      Mitigated
      March 15, 2019
      12:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 15, 2019
      05:55 PM PT
      Windows 10, version 1809 update history may show an update installed twice
      Some customers are reporting that KB4494441 installed twice on their device

      See details >
      OS Build 17763.503

      May 14, 2019
      KB4494441
      Resolved
      May 15, 2019
      01:25 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      May 14, 2019
      01:18 PM PT
      Latest cumulative update (KB 4495667) installs automatically
      Reports that the optional cumulative update (KB 4495667) installs automatically.

      See details >
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      May 08, 2019
      03:37 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      After further investigation ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809

      See details >
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Resolved
      May 08, 2019
      03:30 PM PT
      Custom URI schemes may not start corresponding application
      Custom URI schemes for application protocol handlers may not start the corresponding application for local intranet and trusted sites in Internet Explorer.

      See details >
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Resolved
      KB4495667
      May 03, 2019
      12:40 PM PT
      + -
      DetailsOriginating updateStatusHistory
      Devices with some Asian language packs installed may receive an error
      After installing the April 2019 Cumulative Update (KB4493509), devices with some Asian language packs installed may receive the error, \"0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_FOUND.\"

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Workaround:
      1. Uninstall and reinstall any recently added language packs. For instructions, see \"Manage the input and display language settings in Windows 10\".
      2. Click Check for Updates and install the April 2019 Cumulative Update. For instructions, see \"Update Windows 10\".
      Note: If reinstalling the language pack does not mitigate the issue, reset your PC as follows:
      1. Go to Settings app -> Recovery.
      2. Click on Get Started under \"Reset this PC\" recovery option.
      3. Select \"Keep my Files\".
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      OS Build 17763.437

      April 09, 2019
      KB4493509
      Mitigated
      Last updated:
      May 03, 2019
      10:59 AM PT

      Opened:
      May 02, 2019
      04:36 PM PT
      Printing from Microsoft Edge or other UWP apps, you may receive the error 0x80070007
      When attempting to print from Microsoft Edge or other Universal Windows Platform (UWP) applications you may receive the error, \"Your printer has experienced an unexpected configuration problem. 0x80070007e.\"
       
      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Workaround: You can use another browser, such as Internet Explorer to print your documents.
       
      Next steps: Microsoft is working on a resolution and will provide an update in an upcoming release.

      Back to top
      OS Build 17763.379

      March 12, 2019
      KB4489899
      Mitigated
      Last updated:
      May 02, 2019
      04:47 PM PT

      Opened:
      May 02, 2019
      04:47 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Windows 10, version 1809 update history may show an update installed twice

      Affected platforms
      • Client: Windows 10, version 1809
      • Server: TBD
      Cause
      In certain situations, installing an update requires multiple download and restart steps. In cased where two intermediate steps of the installation complete successfully, the View your Update history page will report that installation completed successfully twice. 

      Resolution
      No action is required on your part. The update installation may take longer and may require more than one restart, but will install successfully after all intermediate installation steps have completed. We are working on improving this update experience to ensure the Update history correctly reflects the installation of the latest cumulative update (LCU).

      Back to top
      OS Build 17763.503

      May 14, 2019
      KB4494441
      Resolved
      Resolved:
      May 15, 2019
      01:25 PM PT

      Opened:
      May 14, 2019
      02:56 PM PT
      Zone transfers over TCP may fail
      Zone transfers between primary and secondary DNS servers over the Transmission Control Protocol (TCP) may fail after installing KB4495667
       
      Affected platforms:  
      • Client: Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016 
      • Server: Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016 
      Resolution: This issue was resolved in KB4494441.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      KB4494441
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Latest cumulative update (KB 4495667) installs automatically
      Due to a servicing side issue some users were offered KB4495667 (optional update) automatically and rebooted devices. This issue has been mitigated.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019
      • Server: Windows Server, version 1809; Windows Server 2019
      Resolution:: This issue has been mitigated on the servicing side to prevent auto installing of this update. Customers do not need to take any action.

      Back to top
      OS Build 17763.475

      May 03, 2019
      KB4495667
      Resolved
      Resolved:
      May 08, 2019
      03:37 PM PT

      Opened:
      May 05, 2019
      12:01 PM PT
      " diff --git a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml index 6f79cac2fd..1ed8655677 100644 --- a/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml +++ b/windows/release-information/status-windows-7-and-windows-server-2008-r2-sp1.yml @@ -64,7 +64,6 @@ sections:
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >April 09, 2019
      KB4493472Resolved
      May 14, 2019
      01:23 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >April 09, 2019
      KB4493472Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >April 09, 2019
      KB4493472Resolved
      May 14, 2019
      01:21 PM PT -
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >April 25, 2019
      KB4493453Resolved
      KB4499164May 14, 2019
      01:18 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >March 12, 2019
      KB4489878Resolved
      KB4499164May 14, 2019
      01:17 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >April 09, 2019
      KB4493472Resolved
      April 25, 2019
      02:00 PM PT @@ -77,15 +76,6 @@ sections:
      " -- title: May 2019 -- items: - - type: markdown - text: " - - -
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493453
      Resolved
      KB4499164
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      - " - - title: April 2019 - items: - type: markdown diff --git a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml index 95db74d05b..b3c58a5566 100644 --- a/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml +++ b/windows/release-information/status-windows-8.1-and-windows-server-2012-r2.yml @@ -60,13 +60,14 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      + + -
      SummaryOriginating updateStatusLast updated
      Japanese IME doesn't show the new Japanese Era name as a text input option
      If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option.

      See details >
      April 25, 2019
      KB4493443
      Mitigated
      May 15, 2019
      05:53 PM PT
      Issue using PXE to start a device from WDS
      There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

      See details >
      March 12, 2019
      KB4489881
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

      See details >
      January 08, 2019
      KB4480963
      Mitigated
      April 25, 2019
      02:00 PM PT
      System may be unresponsive after restart with certain McAfee antivirus products
      Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup.

      See details >
      April 09, 2019
      KB4493446
      Mitigated
      April 18, 2019
      05:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      May 15, 2019
      05:55 PM PT
      System may be unresponsive after restart if ArcaBit antivirus software installed
      Devices with ArcaBit antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:22 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      May 14, 2019
      01:21 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      May 14, 2019
      01:18 PM PT
      Devices may not respond at login or Welcome screen if running certain Avast software
      Devices running Avast for Business, Avast CloudCare, and AVG Business Edition antivirus software may become unresponsive after restart.

      See details >
      April 09, 2019
      KB4493446
      Resolved
      April 25, 2019
      02:00 PM PT
      " @@ -83,7 +84,8 @@ sections: - type: markdown text: " - + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Japanese IME doesn't show the new Japanese Era name as a text input option
      If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option.

      Affected platforms:
      • Client: Windows 8.1
      • Server: Windows Server 2012 R2; Windows Server 2012
      Workaround:
      If you see any of the previous dictionary updates listed below, uninstall it from Programs and features > Uninstall or change a program. New words that were in previous dictionary updates are also in this update.
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.2013)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.2013)
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.1215)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.1215)
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.1080)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.1080)

      Back to top
      April 25, 2019
      KB4493443
      Mitigated
      Last updated:
      May 15, 2019
      05:53 PM PT

      Opened:
      May 15, 2019
      05:53 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493443
      Resolved
      KB4499151
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " diff --git a/windows/release-information/status-windows-server-2008-sp2.yml b/windows/release-information/status-windows-server-2008-sp2.yml index b87565393b..fc5bd1a5a9 100644 --- a/windows/release-information/status-windows-server-2008-sp2.yml +++ b/windows/release-information/status-windows-server-2008-sp2.yml @@ -63,7 +63,6 @@ sections:
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >April 09, 2019
      KB4493471Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >April 09, 2019
      KB4493471Resolved
      May 14, 2019
      01:19 PM PT
      Authentication may fail for services after the Kerberos ticket expires
      Authentication may fail for services that require unconstrained delegation after the Kerberos ticket expires.

      See details >March 12, 2019
      KB4489880Resolved
      KB4499149May 14, 2019
      01:18 PM PT -
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >April 25, 2019
      KB4493460Resolved
      KB4499149May 14, 2019
      01:18 PM PT " @@ -74,15 +73,6 @@ sections:
      " -- title: May 2019 -- items: - - type: markdown - text: " - - -
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493460
      Resolved
      KB4499149
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      - " - - title: April 2019 - items: - type: markdown diff --git a/windows/release-information/status-windows-server-2012.yml b/windows/release-information/status-windows-server-2012.yml index 3ad111d345..bfca55fdd7 100644 --- a/windows/release-information/status-windows-server-2012.yml +++ b/windows/release-information/status-windows-server-2012.yml @@ -60,11 +60,12 @@ sections: - type: markdown text: "
      This table offers a summary of current active issues and those issues that have been resolved in the last 30 days.

      + + -
      SummaryOriginating updateStatusLast updated
      Japanese IME doesn't show the new Japanese Era name as a text input option
      If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option.

      See details >
      April 25, 2019
      KB4493462
      Mitigated
      May 15, 2019
      05:53 PM PT
      Issue using PXE to start a device from WDS
      There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension.

      See details >
      March 12, 2019
      KB4489891
      Mitigated
      April 25, 2019
      02:00 PM PT
      Certain operations performed on a Cluster Shared Volume may fail
      Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”.

      See details >
      January 08, 2019
      KB4480975
      Mitigated
      April 25, 2019
      02:00 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      May 15, 2019
      05:55 PM PT
      System unresponsive after restart if Sophos Endpoint Protection installed
      Devices with Sophos Endpoint Protection installed and managed by Sophos Central or Sophos Enterprise Console (SEC) may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:21 PM PT
      System may be unresponsive after restart if Avira antivirus software installed
      Devices with Avira antivirus software installed may become unresponsive upon restart.

      See details >
      April 09, 2019
      KB4493451
      Resolved
      May 14, 2019
      01:19 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel.

      See details >
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      May 14, 2019
      01:18 PM PT
      " @@ -80,7 +81,8 @@ sections: - type: markdown text: " - + +
      DetailsOriginating updateStatusHistory
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1; Windows 7 SP1 
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012; Windows Server 2008 R2 SP1; Windows Server 2008 SP2 
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      Japanese IME doesn't show the new Japanese Era name as a text input option
      If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option.

      Affected platforms:
      • Client: Windows 8.1
      • Server: Windows Server 2012 R2; Windows Server 2012
      Workaround:
      If you see any of the previous dictionary updates listed below, uninstall it from Programs and features > Uninstall or change a program. New words that were in previous dictionary updates are also in this update.
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.2013)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.2013)
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.1215)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.1215)
      • Update for Japanese Microsoft IME Standard Dictionary (15.0.1080)
      • Update for Japanese Microsoft IME Standard Extended Dictionary (15.0.1080)

      Back to top
      April 25, 2019
      KB4493462
      Mitigated
      Last updated:
      May 15, 2019
      05:53 PM PT

      Opened:
      May 15, 2019
      05:53 PM PT
      Layout and cell size of Excel sheets may change when using MS UI Gothic
      When using the MS UI Gothic or MS PGothic fonts, the text, layout, or cell size may become narrower or wider than expected in Microsoft Excel. For example, the layout and cell size of Microsoft Excel sheets may change when using MS UI Gothic.

      Affected platforms:
      • Client: Windows 10, version 1809; Windows 10 Enterprise LTSC 2019; Windows 10, version 1803; Windows 10, version 1709; Windows 10, version 1703; Windows 10, version 1607; Windows 10 Enterprise LTSC 2016; Windows 10, version 1507; Windows 10 Enterprise LTSB 2015; Windows 8.1
      • Server: Windows Server, version 1809; Windows Server 2019; Windows Server, version 1803; Windows Server, version 1709; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012
      Resolution: This issue has been resolved.

      Back to top
      April 25, 2019
      KB4493462
      Resolved
      KB4499171
      Resolved:
      May 14, 2019
      10:00 AM PT

      Opened:
      May 10, 2019
      10:35 AM PT
      " From 81777d60508c7cae317dd2ccecb826b7953df165 Mon Sep 17 00:00:00 2001 From: brbrahm <43386070+brbrahm@users.noreply.github.com> Date: Wed, 15 May 2019 21:46:34 -0700 Subject: [PATCH 362/737] Removed duplicate "new supported scenarios" from multiple policies page --- ...ndows-defender-application-control-policies.md | 15 +-------------- 1 file changed, 1 insertion(+), 14 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md index 296060880f..73d0e16c9b 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md @@ -20,7 +20,7 @@ ms.date: 05/10/2019 >[!IMPORTANT] >Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here. -The restriction of only having a single code integrity policy active on a system at any given time has felt limiting for customers in situations where multiple policies with different intents would be useful. Beginning with Windows 10 version 1903, WDAC supports multiple simultaneous code integrity policies for one device in order to light up the following scenarios: +The restriction of only having a single code integrity policy active on a system at any given time has felt limiting for customers in situations where multiple policies with different intents would be useful. Beginning with Windows 10 version 1903, WDAC supports multiple simultaneous code integrity policies for one device in order to enable the following scenarios: 1. Enforce and Audit Side-by-Side - To validate policy changes before deploying in enforcement mode, users can now deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy @@ -38,19 +38,6 @@ The restriction of only having a single code integrity policy active on a system - Base + supplemental policy: union - Files that are allowed by the base policy or the supplemental policy are not blocked -## Newly supported scenarios - -With the ability to support multiple CI policies, three new scenarios are supported: - -1. Enforce and Audit Side-by-Side (Intersection) - - To validate policy changes before deploying in enforcement mode, deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy -2. Multiple Base Policies (Intersection) - - Enforce two or more base policies simultaneously to allow simpler policy targeting for policies with different scope/intent - - Ex. Base1 is a corporate standard policy that is relatively loose to accommodate all organizations while forcing minimum corp standards (e.g. Windows works + Managed Installer + path rules). Base2 is a team-specific policy that further restricts what is allowed to run (e.g. Windows works + Managed Installer + corporate signed apps only) -3. Supplemental Policies (Union) - - Deploy a supplemental policy (or policies) to expand a base policy - - Ex. The Azure host base policy restricts tightly to just allow Windows and hardware drivers. Can add a supplemental policy to allow just the additional signer rules needed to support signed code from the Exchange team. - ## PowerShell parameters New-CIPolicy From df1a051291c22f15ef9ff4ab7f5a5d25d4c0b980 Mon Sep 17 00:00:00 2001 From: brbrahm <43386070+brbrahm@users.noreply.github.com> Date: Wed, 15 May 2019 21:54:11 -0700 Subject: [PATCH 363/737] Add intro to COM objects page --- ...-windows-defender-application-control-policy.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md index 9cd8ba8357..4131cedc9a 100644 --- a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md @@ -22,7 +22,13 @@ ms.date: 05/14/2019 The [Microsoft Component Object Model (COM)](https://docs.microsoft.com/windows/desktop/com/the-component-object-model) is a platform-independent, distributed, object-oriented system for creating binary software components that can interact. COM specifies an object model and programming requirements that enable COM objects to interact with other objects. -Get GUID of application to allow by either: +### COM object configurability in WDAC policy + +Prior to the Windows 10 1903 update, Windows Defender Application Control (WDAC) enforced a built-in allow list for COM object registration. While this mechanism works for most common application usage scenarios, customers have provided feedback that there are cases where additional COM objects need to be allowed. The 1903 update to Windows 10 introduces the ability to specify allowed COM objects via their GUID in the WDAC policy. + +### Get COM object GUID + +Get GUID of application to allow in one of the following ways: - Finding block event in Event Viewer (Application and Service Logs > Microsoft > Windows > AppLocker > MSI and Script) and extracting GUID - Creating audit policy (using New-CIPolicy –Audit), potentially with specific provider, and use info from block events to get GUID @@ -32,11 +38,11 @@ Three elements: - Provider: platform on which code is running (values are Powershell, WSH, IE, VBA, MSI, or a wildcard “AllHostIds”) - Key: GUID for the program you with to run, in the format Key="{33333333-4444-4444-1616-161616161616}" - ValueName: needs to be set to "EnterpriseDefinedClsId" + One attribute: - Value: needs to be “true” for allow and “false” for deny - Note: without quotation marks - Note: deny only works in base policies -- The setting needs to be placed in the order of ASCII values, first by Provider, then Key, then ValueName + - Note that deny only works in base policies, not supplemental +- The setting needs to be placed in the order of ASCII values (first by Provider, then Key, then ValueName) ### Examples From 73c4c68274a2c4b7c52884ab29e822febd5b4534 Mon Sep 17 00:00:00 2001 From: MaratMussabekov <48041687+MaratMussabekov@users.noreply.github.com> Date: Thu, 16 May 2019 10:28:13 +0500 Subject: [PATCH 364/737] update windows-defender-exploit-guard.md --- .../windows-defender-exploit-guard.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md index 957c81811a..da228553fc 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/windows-defender-exploit-guard.md @@ -65,7 +65,7 @@ This section covers requirements for each feature in Windows Defender EG. | Controlled folder access | ![supported, limited reporting](./images/ball_50.png) | ![supported, limited reporting](./images/ball_50.png) | ![supported, limited reporting](./images/ball_50.png) | ![supported, limited reporting](./images/ball_50.png) | ![supported, full reporting](./images/ball_full.png) | >[!NOTE] -> [Identity & Threat Protection package](https://www.microsoft.com/microsoft-365/blog/2019/01/02/introducing-new-advanced-security-and-compliance-offerings-for-microsoft-365/), available for Microsoft 365 E3 customers, provides the same Windows Defender ATP capabilities as Enterprise E5 subscription. +> The [Identity & Threat Protection package](https://www.microsoft.com/microsoft-365/blog/2019/01/02/introducing-new-advanced-security-and-compliance-offerings-for-microsoft-365/), available for Microsoft 365 E3 customers, provides the same Windows Defender ATP capabilities as Enterprise E5 subscription. The following table lists which features in Windows Defender EG require enabling [real-time protection](../windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) from Windows Defender Antivirus. From ad020077ac6c17a8f95057765b4a4e413e7a14e5 Mon Sep 17 00:00:00 2001 From: Jose Ortega Date: Thu, 16 May 2019 01:22:04 -0500 Subject: [PATCH 365/737] Resolving ISsue#915 --- .../whats-new-windows-10-version-1803.md | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index a4846edc0d..359a0c2ae5 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -22,11 +22,8 @@ This article lists new and updated features and content that are of interest to The following 3-minute video summarizes some of the new features that are available for IT Pros in this release. -  - > [!video https://www.microsoft.com/en-us/videoplayer/embed/RE21ada?autoplay=false] - ## Deployment ### Windows Autopilot @@ -135,7 +132,7 @@ Portions of the work done during the offline phases of a Windows update have bee ### Co-management -Intune and System Center Configuration Manager policies have been added to enable hybrid Azure AD-joined authentication. Mobile Device Management (MDM) has added over 150 new policies and settings in this release, including the [MDMWinsOverGP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-controlpolicyconflict) policy, to enable easier transition to cloud-based management. +**Intune** and **System Center Configuration Manager** policies have been added to enable hybrid Azure AD-joined authentication. Mobile Device Management (MDM) has added over 150 new policies and settings in this release, including the [MDMWinsOverGP](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-controlpolicyconflict) policy, to enable easier transition to cloud-based management. For more information, see [What's New in MDM enrollment and management](https://docs.microsoft.com/windows/client-management/mdm/new-in-windows-mdm-enrollment-management#whatsnew1803) @@ -231,8 +228,12 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu ## See Also -[Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features.
      -[What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10.
      -[What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware.
      +[Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. + +[What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. + +[What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. + [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. + From 590ba2a7ecfa171d0dd4abb8dac043d09680fdc7 Mon Sep 17 00:00:00 2001 From: alexander7567 <1144391+alexander7567@users.noreply.github.com> Date: Thu, 16 May 2019 10:16:53 -0400 Subject: [PATCH 366/737] Fixed missing colon in path Fixed missing colon in path --- .../client-management/advanced-troubleshooting-boot-problems.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/client-management/advanced-troubleshooting-boot-problems.md b/windows/client-management/advanced-troubleshooting-boot-problems.md index 101ca103bc..b80840d43d 100644 --- a/windows/client-management/advanced-troubleshooting-boot-problems.md +++ b/windows/client-management/advanced-troubleshooting-boot-problems.md @@ -385,6 +385,6 @@ If the dump file shows an error that is related to a driver (for example, window 1. Start WinRE, and open a Command Prompt window. 2. Start a text editor, such as Notepad. - 3. Navigate to C\Windows\System32\Config\. + 3. Navigate to C:\Windows\System32\Config\. 4. Rename the all five hives by appending ".old" to the name. 5. Copy all the hives from the Regback folder, paste them in the Config folder, and then try to start the computer in Normal mode. From 779c598591eba00dcbca314fd538f4550b02caf7 Mon Sep 17 00:00:00 2001 From: Nicole Turner <39884432+nenonix@users.noreply.github.com> Date: Thu, 16 May 2019 16:50:00 +0200 Subject: [PATCH 367/737] typos typos in bookmark links and metadata --- .../hello-for-business/hello-hybrid-cert-trust-devreg.md | 2 +- .../hello-for-business/hello-hybrid-cert-trust-prereqs.md | 2 +- .../hello-for-business/hello-hybrid-key-trust-dirsync.md | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md index 273991ec82..38abf0762f 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-devreg.md @@ -30,7 +30,7 @@ Your environment is federated and you are ready to configure device registration Use this three-phased approach for configuring device registration. 1. [Configure devices to register in Azure](#configure-azure-for-device-registration) -2. [Synchronize devices to on-premises Active Directory](#configure-active-directory-to-support-azure-device-syncrhonization) +2. [Synchronize devices to on-premises Active Directory](#configure-active-directory-to-support-azure-device-synchronization) 3. [Configure AD FS to use cloud devices](#configure-ad-fs-to-use-azure-registered-devices) > [!NOTE] diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-prereqs.md index 8179a617a8..d95c543ec0 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-trust-prereqs.md @@ -1,5 +1,5 @@ --- -title: Hybrid Windows Hello for Business Prerequistes (Windows Hello for Business) +title: Hybrid Windows Hello for Business Prerequisites (Windows Hello for Business) description: Prerequisites for Hybrid Windows Hello for Business Deployments keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, certificate-trust ms.prod: w10 diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-dirsync.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-dirsync.md index 617e922f94..c18edeac22 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-dirsync.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-dirsync.md @@ -1,7 +1,7 @@ --- title: Configure Directory Synchronization for Hybrid key trust Windows Hello for Business -description: Azure Directory Syncrhonization for Hybrid Certificate Key Deployment (Windows Hello for Business) -keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, key-trust, directory, syncrhonization, AADConnect +description: Azure Directory Synchronization for Hybrid Certificate Key Deployment (Windows Hello for Business) +keywords: identity, PIN, biometric, Hello, passport, WHFB, hybrid, key-trust, directory, synchronization, AADConnect ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library From 2bc6fcfa6f50c675a4a1a1609006e83dc8def78f Mon Sep 17 00:00:00 2001 From: jaimeo Date: Thu, 16 May 2019 07:55:48 -0700 Subject: [PATCH 368/737] corrections from Narkis on re-added troubleshooting steps --- .../update/waas-delivery-optimization.md | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/windows/deployment/update/waas-delivery-optimization.md b/windows/deployment/update/waas-delivery-optimization.md index 6687410667..eb321bebaf 100644 --- a/windows/deployment/update/waas-delivery-optimization.md +++ b/windows/deployment/update/waas-delivery-optimization.md @@ -125,22 +125,27 @@ If you don’t see any bytes coming from peers the cause might be one of the fol ### Clients aren't able to reach the Delivery Optimization cloud services. -To fix this issue, try the following steps: +If you suspect this is the problem, try these steps: + +1. Start a download of an app that is larger than 50 MB from the Store (for example "Candy Crush Saga"). +2. Run `Get-DeliveryOptimizationStatus` from an elevated Powershell window and observe the DownloadMode setting. For peering to work, DownloadMode should be 1, 2, or 3. +3. If **DownloadMode** is 99 it could indicate your device is unable to reach the Delivery Optimization cloud services. Ensure that the Delivery Optimization hostnames are allowed access: most importantly ***.do.dsp.mp.microsoft.com**. -1. Start a download of an app that is larger than 50 MB from the Store (for example Candy Crush Saga). -2. Run `Get-DeliveryOptimizationStatus` from an elevated window and share the output (by setting the `DownloadMode` field to **1**). ### The cloud service doesn't see other peers on the network. If you suspect this is the problem, try these steps: -1. Download the same app on another device on the same network. -2. Run `Get-DeliveryOptimizationPerfSnap` from an elevated window (the `NumberOfPeers` field should be non-zero). +1. Download the same app on two different devices on the same network, waiting 10 – 15 minutes between downloads. +2. Run `Get-DeliveryOptimizationStatus` from an elevated Powershell window and ensure that **DownloadMode** is 1 or 2 on both devices. +3. Run `Get-DeliveryOptimizationPerfSnap` from an elevated Powershell window on the second device. The **NumberOfPeers** field should be non-zero. +4. If the number of peers is zero and you have **DownloadMode** = 1, ensure that both devices are using the same public IP address to reach the internet. To do this, open a browser Windows and search for “what is my IP”. You can **DownloadMode 2** (Group) and a custom GroupID (Guid) to fix this if the devices aren’t reporting the same public IP address. + ### Clients aren't able to connect to peers offered by the cloud service -If you suspect this is the problem, un a Telnet test between two devices on the network to ensure they can connect using port 7680. To do this, follow these steps: +If you suspect this is the problem, try a Telnet test between two devices on the network to ensure they can connect using port 7680. To do this, follow these steps: 1. Install Telnet by running **dism /online /Enable-Feature /FeatureName:TelnetClient** from an elevated command prompt. 2. Run the test. For example, if you are on device with IP 192.168.8.12 and you are trying to test the connection to 192.168.9.17 run **telnet 192.168.9.17 7680** (the syntax is *telnet [destination IP] [port]*. You will either see a connection error or a blinking cursor like this /_. The blinking cursor means success. @@ -148,6 +153,7 @@ If you suspect this is the problem, un a Telnet test between two devices on the + ## Learn more [Windows 10, Delivery Optimization, and WSUS](https://blogs.technet.microsoft.com/mniehaus/2016/08/16/windows-10-delivery-optimization-and-wsus-take-2/) From 3279e783ff5721e26416fe24157a90498403d8cf Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:17:29 -0500 Subject: [PATCH 369/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index 359a0c2ae5..b0aa87146e 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -228,7 +228,7 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu ## See Also -[Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. +- [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. From 7e3c471554b2d1cbb176262bb34acdc35d2846e7 Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:17:42 -0500 Subject: [PATCH 370/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index b0aa87146e..4976aba0c4 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -229,7 +229,6 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu ## See Also - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. - [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. From c307294550eaf40eb189a8a73f2679bfc725dcfa Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:17:49 -0500 Subject: [PATCH 371/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index 4976aba0c4..b303d7d580 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -230,7 +230,6 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. - [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. From 0557f502a02d9a9a7293b12f82d483ee7577396c Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:17:57 -0500 Subject: [PATCH 372/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index b303d7d580..8ff528af58 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -231,7 +231,6 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. - [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. From 66d8ae4a07ab0f86234bf97985d834aec332f5ce Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:18:06 -0500 Subject: [PATCH 373/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index 8ff528af58..0f56c2a037 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -231,6 +231,6 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. -[Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. +- [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. From 800d7f46112996a0c0fd85910340ff7801ac283d Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:18:16 -0500 Subject: [PATCH 374/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index 0f56c2a037..edf483eab6 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -230,7 +230,7 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. -[What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. +- [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. - [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. From 60cf9d4e55b19e1f158a115337ec8a175686c28d Mon Sep 17 00:00:00 2001 From: Jose Gabriel Ortega Castro Date: Thu, 16 May 2019 11:18:42 -0500 Subject: [PATCH 375/737] Update windows/whats-new/whats-new-windows-10-version-1803.md Co-Authored-By: Nicole Turner <39884432+nenonix@users.noreply.github.com> --- windows/whats-new/whats-new-windows-10-version-1803.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1803.md b/windows/whats-new/whats-new-windows-10-version-1803.md index edf483eab6..220d35e86c 100644 --- a/windows/whats-new/whats-new-windows-10-version-1803.md +++ b/windows/whats-new/whats-new-windows-10-version-1803.md @@ -229,7 +229,7 @@ Support in [Windows Defender Application Guard](#windows-defender-application-gu ## See Also - [Windows 10 Features](https://www.microsoft.com/windows/features): Review general information about Windows 10 features. -[What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. +- [What's New in Windows 10](https://docs.microsoft.com/windows/whats-new/): See what’s new in other versions of Windows 10. - [What's new in Windows 10, version 1709](https://docs.microsoft.com/windows-hardware/get-started/what-s-new-in-windows): See what’s new in Windows 10 hardware. - [Windows 10 Fall Creators Update Next Generation Security](https://www.youtube.com/watch?v=JDGMNFwyUg8): YouTube video about Windows Defender ATP in Windows 10, version 1709. From 410252e180e6a506577fa6a76221d826f45190bf Mon Sep 17 00:00:00 2001 From: jaimeo Date: Thu, 16 May 2019 09:36:25 -0700 Subject: [PATCH 376/737] escaping an asterisk --- windows/deployment/update/waas-delivery-optimization.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/update/waas-delivery-optimization.md b/windows/deployment/update/waas-delivery-optimization.md index eb321bebaf..765547a61f 100644 --- a/windows/deployment/update/waas-delivery-optimization.md +++ b/windows/deployment/update/waas-delivery-optimization.md @@ -129,7 +129,7 @@ If you suspect this is the problem, try these steps: 1. Start a download of an app that is larger than 50 MB from the Store (for example "Candy Crush Saga"). 2. Run `Get-DeliveryOptimizationStatus` from an elevated Powershell window and observe the DownloadMode setting. For peering to work, DownloadMode should be 1, 2, or 3. -3. If **DownloadMode** is 99 it could indicate your device is unable to reach the Delivery Optimization cloud services. Ensure that the Delivery Optimization hostnames are allowed access: most importantly ***.do.dsp.mp.microsoft.com**. +3. If **DownloadMode** is 99 it could indicate your device is unable to reach the Delivery Optimization cloud services. Ensure that the Delivery Optimization hostnames are allowed access: most importantly **\*.do.dsp.mp.microsoft.com**. From 8a6efa78e4339e7dbed350a8bafdd5f5e8a08a33 Mon Sep 17 00:00:00 2001 From: Max Velitchko Date: Thu, 16 May 2019 09:37:09 -0700 Subject: [PATCH 377/737] Reflect mdatp diagnostic changes --- .../microsoft-defender-atp-mac-resources.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-resources.md b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-resources.md index 7f138a6ca7..bbd9394358 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-resources.md +++ b/windows/security/threat-protection/windows-defender-antivirus/microsoft-defender-atp-mac-resources.md @@ -41,10 +41,10 @@ If you can reproduce a problem, please increase the logging level, run the syste 2. Reproduce the problem -3. Run `mdatp --diagnostic` to backup Defender ATP's logs. The command will print out location with generated zip file. +3. Run `mdatp --diagnostic --create` to backup Defender ATP's logs. The command will print out location with generated zip file. ```bash - mavel-mojave:~ testuser$ mdatp --diagnostic + mavel-mojave:~ testuser$ mdatp --diagnostic --create Creating connection to daemon Connection established "/Library/Application Support/Microsoft/Defender/wdavdiag/d85e7032-adf8-434a-95aa-ad1d450b9a2f.zip" @@ -120,7 +120,7 @@ Important tasks, such as controlling product settings and triggering on-demand s |Configuration|Turn off PUA protection |`mdatp threat --type-handling --potentially_unwanted_application off` | |Configuration|Turn on audit mode for PUA protection |`mdatp threat --type-handling --potentially_unwanted_application audit`| |Diagnostics |Change the log level |`mdatp log-level --[error/warning/info/verbose]` | -|Diagnostics |Generate diagnostic logs |`mdatp --diagnostic` | +|Diagnostics |Generate diagnostic logs |`mdatp --diagnostic --create` | |Health |Check the product's health |`mdatp --health` | |Protection |Scan a path |`mdatp scan --path [path]` | |Protection |Do a quick scan |`mdatp scan --quick` | From c5ae6b310f7d669c18483802fb3b6c7c49477343 Mon Sep 17 00:00:00 2001 From: John Rajunas Date: Thu, 16 May 2019 12:49:20 -0400 Subject: [PATCH 378/737] Change "Windows Management Instruction" Proposing the correct the phrase "Windows Management Instruction" to "Windows Management Instrumentation" to more accurately reflect the proper meaning of the acronym WMI in this context, and to match the rest of the topic's use of "WMI". --- ...iguration-management-reference-windows-defender-antivirus.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md index 901c6c4995..471d647e37 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md @@ -26,7 +26,7 @@ You can manage and configure Windows Defender Antivirus with the following tools - System Center Configuration Manager - Group Policy - PowerShell cmdlets -- Windows Management Instruction (WMI) +- Windows Management Instrumentation (WMI) - The mpcmdrun.exe utility The topics in this section provide further information, links, and resources for using these tools to manage and configure Windows Defender Antivirus. From 373c66f301b9ce3488857dfc59ba67f2b0e131a0 Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 16 May 2019 10:29:51 -0700 Subject: [PATCH 379/737] syntax fixes --- ...n-windows-defender-application-control-policy.md | 1 + .../create-path-based-rules.md | 6 ++++++ ...windows-defender-application-control-policies.md | 13 +++++++++++++ .../select-types-of-rules-to-create.md | 6 ++++++ 4 files changed, 26 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md index 9cd8ba8357..4e19b9193b 100644 --- a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md @@ -32,6 +32,7 @@ Three elements: - Provider: platform on which code is running (values are Powershell, WSH, IE, VBA, MSI, or a wildcard “AllHostIds”) - Key: GUID for the program you with to run, in the format Key="{33333333-4444-4444-1616-161616161616}" - ValueName: needs to be set to "EnterpriseDefinedClsId" + One attribute: - Value: needs to be “true” for allow and “false” for deny Note: without quotation marks diff --git a/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules.md b/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules.md index 852c003dc0..29db07a119 100644 --- a/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/create-path-based-rules.md @@ -24,18 +24,23 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD - New-CIPolicy parameters - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) + ```powershell New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u ``` + Optionally, add -UserWriteablePaths to ignore user writeability - FilePathRule: create a rule where filepath string is directly set to value of \ + ```powershell New-CIPolicyRule -FilePathRule ``` + Useful for wildcards like C:\foo\\* - Usage follows the same flow as per-app rules: + ```powershell $rules = New-CIPolicyRule … $rules += New-CIPolicyRule … @@ -53,6 +58,7 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD - %OSDRIVE%\\... - Disable default FilePath rule protection of enforcing user-writeability. For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: + ```powershell Set-RuleOption -o 18 .\policy.xml ``` diff --git a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md index 7408abf167..2e1842d5c0 100644 --- a/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md +++ b/windows/security/threat-protection/windows-defender-application-control/deploy-multiple-windows-defender-application-control-policies.md @@ -34,10 +34,14 @@ Beginning with Windows 10 version 1903, WDAC supports multiple code integrity po With the ability to support multiple CI policies, three new scenarios are supported: 1. Enforce and Audit Side-by-Side (Intersection) + - To validate policy changes before deploying in enforcement mode, deploy an audit-mode base policy side-by-side with an existing enforcement-mode base policy + 2. Multiple Base Policies (Intersection) + - Enforce two or more base policies simultaneously to allow simpler policy targeting for policies with different scope/intent - Ex. Base1 is a corporate standard policy that is relatively loose to accommodate all organizations while forcing minimum corp standards (e.g. Windows works + Managed Installer + path rules). Base2 is a team-specific policy that further restricts what is allowed to run (e.g. Windows works + Managed Installer + corporate signed apps only) + 3. Supplemental Policies (Union) - Deploy a supplemental policy (or policies) to expand a base policy - Ex. The Azure host base policy restricts tightly to just allow Windows and hardware drivers. Can add a supplemental policy to allow just the additional signer rules needed to support signed code from the Exchange team. @@ -83,8 +87,11 @@ New-CiPolicy -MulitplePolicyFormat -foo –bar - **MultiplePolicyFormat** switch results in 1) random GUIDs being generated for the policy ID and 2) the policy type being specified as base. Can optionally choose to make it supplementable: + - Set-RuleOption has a new option **Enabled:Allow Supplemental Policies** to set for base policy + - For signed policies that are being made supplementable, need to ensure that supplemental signers are defined. Use “Add-SignerRule” to provide supplemental signers. + ```powershell Add-SignerRule -FilePath -CertificatePath [-Kernel] [-User] [-Update] [-Supplemental] [-Deny] [] ``` @@ -92,18 +99,24 @@ New-CiPolicy -MulitplePolicyFormat -foo –bar **Scenario #2: Creating a new supplemental policy** 1. Scan using `New-CiPolicy –MuliplePolicyFormat` to generate a base policy: + ```powershell New-CIPolicy -Level PcaCertificate -UserPEs -ScanPath -MultiplePolicyFormat 3> -FilePath ``` + 2. Change this new base policy to a supplemental policy + - Provide path of base in `Set-CIPolicyIdInfo –BasePolicytoSupplementPath` - Provide GUID of base in `Set-CIPolicyIdInfo –SupplementsBasePolicyID` + ```powershell Set-CIPolicyIdInfo -BasePolicyToSupplementPath -SupplementsBasePolicyID -FilePath ``` + - Can revert the policy back to being a base policy using `-ResetPolicyID` **Scenario #3: Merging policies** - When merging, the policy type and ID of the leftmost/first policy specified is used + - If the leftmost is a base policy with ID , then regardless of what the GUIDS and types are for any subsequent policies, the merged policy will be a base policy with ID diff --git a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md index ccf9c4559b..342163da92 100644 --- a/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md +++ b/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create.md @@ -109,18 +109,23 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD - New-CIPolicy parameters - FilePath: create path rules under path \ for anything not user-writeable (at the individual file level) + ```powershell New-CIPolicy -f .\mypolicy.xml -l FilePath -s -u ``` + Optionally, add -UserWriteablePaths to ignore user writeability - FilePathRule: create a rule where filepath string is directly set to value of \ + ```powershell New-CIPolicyRule -FilePathRule ``` + Useful for wildcards like C:\foo\\* - Usage follows the same flow as per-app rules: + ```powershell $rules = New-CIPolicyRule … $rules += New-CIPolicyRule … @@ -138,6 +143,7 @@ Beginning with Windows 10 version 1903, Windows Defender Application Control (WD - %OSDRIVE%\\... - Disable default FilePath rule protection of enforcing user-writeability. For example, to add “Disabled:Runtime FilePath Rule Protection” to the policy: + ```powershell Set-RuleOption -o 18 .\policy.xml ``` From 5bc5549a77d1b7c2745fc0fe24c33c4f8dce39ed Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 16 May 2019 10:30:15 -0700 Subject: [PATCH 380/737] draft --- windows/whats-new/whats-new-windows-10-version-1903.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index f44818705c..bb173432f0 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -25,8 +25,8 @@ This article lists new and updated features and content that are of interest to The following Windows Autopilot features are available in Windows 10, version 1903 and later: -- White glove: Windows Autopilot white glove enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. -- ESP enhancements: The Intune enrollment status page (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. +- Windows Autopilot white glove enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. +- The Intune enrollment status page (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. - Cortana voiceover: Cortana voiceover is disabled by default for Windows 10 Pro and above. - Self-updating Autopilot: You can enable new Windows Autopilot functionality without updating Windows.​ From 08e2b9e40325a633f0570e351a095105aaef270b Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 16 May 2019 10:45:23 -0700 Subject: [PATCH 381/737] remove preview mte --- .../configure-microsoft-threat-experts.md | 91 ++++++++----------- 1 file changed, 39 insertions(+), 52 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md index fbc390f046..d9d5087041 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md @@ -19,70 +19,64 @@ ms.date: 02/28/2019 --- # Configure and manage Microsoft Threat Experts capabilities - **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) [!include[Prerelease information](prerelease.md)] -## Before you begin - -To experience the full Microsoft Threat Experts targeted attack notification capability in Microsoft Defender ATP, and preview the experts-on-demand capability, you need to have a valid Premier customer service and support account. Premier charges will not be incurred during for the capability in preview, but for the generally available capability, there will be charges. - -You also need to ensure that you have Microsoft Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. - -## Register to Microsoft Threat Experts preview - -If you're already a Microsoft Defender ATP customer, you can apply through the Microsoft Defender ATP portal. +## Before you begin +To experience the full Microsoft Threat Experts targeted attack notification capability in Microsoft Defender ATP, and preview the experts-on-demand capability, you need to have a valid Premier customer service and support account. Premier charges will not be incurred during for the capability in preview, but for the generally available capability, there will be charges. + +You also need to ensure that you have Microsoft Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. + +## Register to Microsoft Threat Experts managed threat hunting service +If you're already a Microsoft Defender ATP customer, you can apply through the Microsoft Defender ATP portal. 1. From the navigation pane, go to **Settings > General > Advanced features > Microsoft Threat Experts**. -2. Click **Apply**. +2. Click **Apply**. ![Image of Microsoft Threat Experts settings](images/MTE_collaboratewithmte.png) -3. Enter your name and email address so that Microsoft can get back to you on your application. +3. Enter your name and email address so that Microsoft can get back to you on your application. ![Image of Microsoft Threat Experts application](images/MTE_apply.png) -4. Read the privacy statement, then click **Submit** when you're done. You will receive a welcome email once your application is approved. +4. Read the privacy statement, then click **Submit** when you're done. You will receive a welcome email once your application is approved. ![Image of Microsoft Threat Experts application confirmation](images/MTE_applicationconfirmation.png) -6. From the navigation pane, go to **Settings** > **General** > **Advanced features** to turn the **Threat Experts** toggle on. Click **Save preferences**. - -## Receive targeted attack notification from Microsoft Threat Experts - -You can receive targeted attack notification from Microsoft Threat Experts through the following: +6. From the navigation pane, go to **Settings** > **General** > **Advanced features** to turn the **Threat Experts** toggle on. Click **Save preferences**. +## Receive targeted attack notification from Microsoft Threat Experts +You can receive targeted attack notification from Microsoft Threat Experts through the following: - The Microsoft Defender ATP portal's **Alerts** dashboard -- Your email, if you choose to configure it +- Your email, if you choose to configure it To receive targeted attack notifications through email, you need to create an email notification rule. -### Create an email notification rule +### Create an email notification rule +You can create rules to send email notifications for notification recipients. See [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) to create, edit, delete, or troubleshoot email notification, for details. -You can create rules to send email notifications for notification recipients. See [Configure alert notifications](configure-email-notifications.md) to create, edit, delete, or troubleshoot email notification, for details. - -## View the targeted attack notification +## View the targeted attack notification You'll start receiving targeted attack notification from Microsoft Threat Experts in your email after you have configured your system to receive email notification. -1. Click the link in the email to go to the corresponding alert context in the dashboard tagged with **Threat experts**. +1. Click the link in the email to go to the corresponding alert context in the dashboard tagged with **Threat experts**. 2. From the dashboard, select the same alert topic that you got from the email, to view the details. -## Ask a Microsoft threat expert about suspicious cybersecurity activities in your organization +## Ask a Microsoft threat expert about suspicious cybersecurity activities in your organization >[!NOTE] ->The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. +>The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. -You can partner with Microsoft Threat Experts who can be engaged directly from within the Microsoft Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. +You can partner with Microsoft Threat Experts who can be engaged directly from within the Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. -1. Navigate to the portal page with the relevant information that you'd like to investigate, for example, the **Incident** page. Ensure that the page for the relevant alert or machine is in view before raising an inquiry. +1. Navigate to the portal page with the relevant information that you'd like to investigate, for example, the **Incident** page. Ensure that the page for the relevant alert or machine is in view before raising an inquiry. 2. From the upper right-hand menu, click **?**, then select **Ask a threat expert**. -3. Asking a threat expert is a two-step process: you need to provide the necessary information and open a support ticket. +3. Asking a threat expert is a two-step process: you need to provide the necessary information and open a support ticket. - **Step 1: Provide information** - a. Provide enough information to give the Microsoft Threat Experts enough context to start the investigation. Select the inquiry category from the **Provide information > Inquiry** details drop-down menu.
      + **Step 1: Provide information** + a. Provide enough information to give the Microsoft Threat Experts enough context to start the investigation. Select the inquiry category from the **Provide information > Inquiry** details drop-down menu.
      b. Enter the additional details to give the threat experts more context of what you’d like to investigate. Click **Next**, and it takes you to the **Open support ticket** tab.
      @@ -98,54 +92,47 @@ You can partner with Microsoft Threat Experts who can be engaged directly from w **Select a product**: **Microsoft Threat Experts**
      **Select a category that best describes the issue**: **Microsoft Defender ATP**
      **Select a problem that best describes the issue**: Choose according to your inquiry category
      - + b. Fill out the fields with the necessary information about the issue and use the auto-generated ID when you open a Customer Services and Support (CSS) ticket. Then, click **Next**.
      - + c. In the **Select a support plan** page, select **Professional No Charge**.
      d. The severity of your issue has been pre-selected by default, per the support plan, **Professional No Charge**, that you'll use for this public preview. Select the time zone by which you'd like to receive the correspondence. Then, click **Next**.
      - + e. Verify your contact details and add another if necessary. Then, click **Next**.
      f. Review the summary of your support request, and update if necessary. Make sure that you read and understand the **Microsoft Services Agreement** and **Privacy Statement**. Then, click **Submit**. You will see the confirmation page indicating the response time and your support request number.
      ## Sample questions to ask Microsoft Threat Experts - **Alert information** - - We see a new type of alert for a living-off-the-land binary: [AlertID]. Can you tell us something more about this alert and how we can investigate further? - We’ve observed two similar attacks which try to execute malicious PowerShell scripts but generate different alerts. One is "Suspicious Powershell command line" and the other is "A malicious file was detected based on indication provided by O365". What is the difference? -- I receive an odd alert today for abnormal number of failed logins from a high profile user’s device. I cannot find any further evidence around these sign-in attempts. How can Windows Defender see these attempts? What type of sign-ins are being monitored? -- Can you give more context or insights about this alert: “Suspicious behavior by a system utility was observed”. +- I receive an odd alert today for abnormal number of failed logins from a high profile user’s device. I cannot find any further evidence around these sign-in attempts. How can Microsoft Defender ATP see these attempts? What type of sign-ins are being monitored? +- Can you give more context or insights about this alert: “Suspicious behavior by a system utility was observed”. **Possible machine compromise** - - Can you please help answer why we see “Unknown process observed?” This is seen quite frequently on many machines and we would appreciate input on whether this is related to malicious activity. - Can you help validate a possible compromise on the following system on [date] with similar behaviors as the previous [malware name] malware detection on the same system in [month]? **Threat intelligence details** - - This morning, we detected a phishing email that delivered a malicious Word document to a user. This caused a series of suspicious events which triggered multiple Windows Defender alerts for [malware name] malware. Do you have any information on this malware? If yes, can you please send me a link? -- I recently saw a [social media reference e.g. Twitter or blog] post about a threat that is targeting my industry. Can you help me understand what protection Microsoft Defender ATP provides against this threat actor? - -**Microsoft Threat Experts’ alert communications** +- I recently saw a [social media reference e.g. Twitter or blog] post about a threat that is targeting my industry. Can you help me understand what protection Microsoft Defender ATP provides against this threat actor? +**Microsoft Threat Experts’ alert communications** - Can your incident response team help us address the targeted attack notification that we got? - I received this targeted attack notification from Microsoft Threat Experts. We don’t have our own incident response team. What can we do now, and how can we contain the incident? - I received a targeted attack notification from Microsoft Threat Experts. What data can you provide to us that we can pass on to our incident response team? >[!NOTE] - >Microsoft Threat Experts is a managed cybersecurity hunting service and not an incident response service. However, the experts can seamlessly transition the investigation to Microsoft Cybersecurity Solutions Group (CSG)'s Detection and Response Team (DART) services, when necessary. You can also opt to engage with your own incident response team to address issues that requires an incident response. + >Microsoft Threat Experts is a managed cybersecurity hunting service and not an incident response service. However, the experts can seamlessly transition the investigation to Microsoft Cybersecurity Solutions Group (CSG)'s Detection and Response Team (DART) services, when necessary. You can also opt to engage with your own incident response team to address issues that requires an incident response. ## Scenario -### Receive a progress report about your managed hunting inquiry - -Response from Microsoft Threat Experts varies according to your inquiry. They will email a progress report to you regarding the Ask a threat expert inquiry that you've submitted, within two days, to communicate the investigation status from the following categories: - +### Receive a progress report about your managed hunting inquiry +Response from Microsoft Threat Experts varies according to your inquiry. They will email a progress report to you regarding the Ask a threat expert inquiry that you've submitted, within two days, to communicate the investigation status from the following categories: - More information is needed to continue with the investigation -- A file or several file samples are needed to determine the technical context -- Investigation requires more time -- Initial information was enough to conclude the investigation +- A file or several file samples are needed to determine the technical context +- Investigation requires more time +- Initial information was enough to conclude the investigation -It is crucial to respond in a timely manner to keep the investigation moving. See the Premier customer service and support service level agreement for details. \ No newline at end of file +It is crucial to respond in a timely manner to keep the investigation moving. See the Premier customer service and support service level agreement for details. From 92e6cb01a73cf293a0e490a0d76a39d7260159f8 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 16 May 2019 10:47:22 -0700 Subject: [PATCH 382/737] draft --- windows/whats-new/whats-new-windows-10-version-1903.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index bb173432f0..4ad9128ae2 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -25,9 +25,9 @@ This article lists new and updated features and content that are of interest to The following Windows Autopilot features are available in Windows 10, version 1903 and later: -- Windows Autopilot white glove enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. -- The Intune enrollment status page (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. -- Cortana voiceover: Cortana voiceover is disabled by default for Windows 10 Pro and above. +- [Windows Autopilot for white glove deployment](https://docs.microsoft.com/windows/deployment/windows-autopilot/white-glove) enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. +- The Intune [enrollment status page](https://docs.microsoft.com/intune/windows-enrollment-status) (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. +- Cortana voiceover: [Cortana voiceover](https://docs.microsoft.com/windows-hardware/customize/desktop/cortana-voice-support) is disabled by default for Windows 10 Pro and above. - Self-updating Autopilot: You can enable new Windows Autopilot functionality without updating Windows.​ ### Windows 10 Subscription Activation From fce53cd62aa67622ebea8b26d6f114fe4757ed3a Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 16 May 2019 10:48:22 -0700 Subject: [PATCH 383/737] commit --- .../microsoft-defender-atp/add-or-remove-machine-tags.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md index e313d8cf62..2dd101cbc1 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md +++ b/windows/security/threat-protection/microsoft-defender-atp/add-or-remove-machine-tags.md @@ -19,7 +19,7 @@ ms.topic: article # Add or Remove Machine Tags API **Applies to:** -- [Windows Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) This API adds or remove tag to a specific machine. From 6e787137910e4df94613e1c2e97390628a7649e9 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 16 May 2019 11:00:39 -0700 Subject: [PATCH 384/737] Added 19H1 policies and updated bookmarks --- ...ew-in-windows-mdm-enrollment-management.md | 4 - .../policy-configuration-service-provider.md | 127 +++++++- .../mdm/policy-csp-deliveryoptimization.md | 275 +++++++++++++++++- 3 files changed, 391 insertions(+), 15 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index d652e7d5f2..fe4473c45d 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -1063,8 +1063,6 @@ For details about Microsoft mobile device management protocols for Windows 10 s
    1. Games/AllowAdvancedGamingServices
    2. Handwriting/PanelDefaultModeDocked
    3. LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
    4. -
    5. LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus
    6. -
    7. LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus
    8. LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
    9. LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
    10. LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
    11. @@ -2676,8 +2674,6 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware
    12. ExploitGuard/ExploitProtectionSettings
    13. Games/AllowAdvancedGamingServices
    14. LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
    15. -
    16. LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus
    17. -
    18. LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus
    19. LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
    20. LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
    21. LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
    22. diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index af13ba26a5..0fb572e93d 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -913,6 +913,12 @@ The following diagram shows the Policy configuration service provider in tree fo
      DeliveryOptimization/DODelayForegroundDownloadFromHttp
      +
      + DeliveryOptimization/DODelayCacheServerFallbackBackground +
      +
      + DeliveryOptimization/DODelayCacheServerFallbackForeground +
      DeliveryOptimization/DODownloadMode
      @@ -2119,12 +2125,6 @@ The following diagram shows the Policy configuration service provider in tree fo
      LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
      -
      - LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus -
      -
      - LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus -
      LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
      @@ -4366,11 +4366,13 @@ The following diagram shows the Policy configuration service provider in tree fo - [Defender/SignatureUpdateInterval](./policy-csp-defender.md#defender-signatureupdateinterval) - [Defender/SubmitSamplesConsent](./policy-csp-defender.md#defender-submitsamplesconsent) - [Defender/ThreatSeverityDefaultAction](./policy-csp-defender.md#defender-threatseveritydefaultaction) -- [DeliveryOptimization/DOAbsoluteMaxCacheSize](./policy-csp-deliveryoptimization.md#deliveryoptimization-doabsolutemaxcachesize) + [DeliveryOptimization/DOAbsoluteMaxCacheSize](./policy-csp-deliveryoptimization.md#deliveryoptimization-doabsolutemaxcachesize) - [DeliveryOptimization/DOAllowVPNPeerCaching](./policy-csp-deliveryoptimization.md#deliveryoptimization-doallowvpnpeercaching) - [DeliveryOptimization/DOCacheHost](./policy-csp-deliveryoptimization.md#deliveryoptimization-docachehost) - [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](./policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaybackgrounddownloadfromhttp) - [DeliveryOptimization/DODelayForegroundDownloadFromHttp](./policy-csp-deliveryoptimization.md#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](./policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](./policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackforeground) - [DeliveryOptimization/DODownloadMode](./policy-csp-deliveryoptimization.md#deliveryoptimization-dodownloadmode) - [DeliveryOptimization/DOGroupId](./policy-csp-deliveryoptimization.md#deliveryoptimization-dogroupid) - [DeliveryOptimization/DOGroupIdSource](./policy-csp-deliveryoptimization.md#deliveryoptimization-dogroupidsource) @@ -4694,8 +4696,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [Licensing/AllowWindowsEntitlementReactivation](./policy-csp-licensing.md#licensing-allowwindowsentitlementreactivation) - [Licensing/DisallowKMSClientOnlineAVSValidation](./policy-csp-licensing.md#licensing-disallowkmsclientonlineavsvalidation) - [LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-blockmicrosoftaccounts) -- [LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-enableadministratoraccountstatus) -- [LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-enableguestaccountstatus) - [LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-limitlocalaccountuseofblankpasswordstoconsolelogononly) - [LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-renameadministratoraccount) - [LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount](./policy-csp-localpoliciessecurityoptions.md#localpoliciessecurityoptions-accounts-renameguestaccount) @@ -5098,6 +5098,33 @@ The following diagram shows the Policy configuration service provider in tree fo - [Browser/AllowSmartScreen](#browser-allowsmartscreen) - [Connectivity/AllowBluetooth](#connectivity-allowbluetooth) - [Connectivity/AllowUSBConnection](#connectivity-allowusbconnection) +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/AllowSimpleDevicePassword](#devicelock-allowsimpledevicepassword) - [DeviceLock/AlphanumericDevicePasswordRequired](#devicelock-alphanumericdevicepasswordrequired) @@ -5158,6 +5185,33 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/MinDevicePasswordComplexCharacters](#devicelock-mindevicepasswordcomplexcharacters) - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/DevicePasswordEnabled](#devicelock-devicepasswordenabled) +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [Experience/AllowCortana](#experience-allowcortana) - [Privacy/AllowInputPersonalization](#privacy-allowinputpersonalization) - [Search/AllowSearchToUseLocation](#search-allowsearchtouselocation) @@ -5253,6 +5307,33 @@ The following diagram shows the Policy configuration service provider in tree fo - [CredentialProviders/AllowPINLogon](#credentialproviders-allowpinlogon) - [CredentialProviders/BlockPicturePassword](#credentialproviders-blockpicturepassword) - [DataProtection/AllowDirectMemoryAccess](#dataprotection-allowdirectmemoryaccess) +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) - [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) - [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) @@ -5265,7 +5346,33 @@ The following diagram shows the Policy configuration service provider in tree fo ## Policies supported by Windows 10 IoT Enterprise - +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) - [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) - [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) diff --git a/windows/client-management/mdm/policy-csp-deliveryoptimization.md b/windows/client-management/mdm/policy-csp-deliveryoptimization.md index 6883af040b..a6226c81d3 100644 --- a/windows/client-management/mdm/policy-csp-deliveryoptimization.md +++ b/windows/client-management/mdm/policy-csp-deliveryoptimization.md @@ -6,7 +6,7 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 05/01/2019 +ms.date: 05/15/2019 --- # Policy CSP - DeliveryOptimization @@ -36,6 +36,12 @@ ms.date: 05/01/2019
      DeliveryOptimization/DODelayForegroundDownloadFromHttp
      +
      + DeliveryOptimization/DODelayCacheServerFallbackBackground +
      +
      + DeliveryOptimization/DODelayCacheServerFallbackForeground +
      DeliveryOptimization/DODownloadMode
      @@ -403,6 +409,144 @@ The following list shows the supported values as number of seconds:
      + +**DeliveryOptimization/DODelayCacheServerFallbackBackground** + + + + + + + + + + + + + + + + + + + + + +
      HomeProBusinessEnterpriseEducationMobileMobile Enterprise
      cross markcheck mark6check mark6check mark6check mark6
      + + + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
      + + + + +Specifies the time in seconds to delay the fallback from Cache Server to the HTTP source for a background content download. + +> [!NOTE] +> The [DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) policy takes precedence over this policy to allow downloads from peers first. + + + + +ADMX Info: +- GP English name: *Delay Background download Cache Server fallback (in seconds)* +- GP name: *DelayCacheServerFallbackBackground* +- GP element: *DelayCacheServerFallbackBackground* +- GP path: *Windows Components/Delivery Optimization* +- GP ADMX file name: *DeliveryOptimization.admx* + + + + +This policy is specified in seconds. +Supported values: 0 - one month (in seconds) + + + + + + + + + + +
      + + + +**DeliveryOptimization/DODelayCacheServerFallbackForeground** + + + + + + + + + + + + + + + + + + + + + +
      HomeProBusinessEnterpriseEducationMobileMobile Enterprise
      cross markcheck mark6check mark6check mark6check mark6
      + + + + +[Scope](./policy-configuration-service-provider.md#policy-scope): + +> [!div class = "checklist"] +> * Device + +
      + + + + +Specifies the time in seconds to delay the fallback from Cache Server to the HTTP source for foreground content download. + +> [!NOTE] +> The [DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) policy takes precedence over this policy to allow downloads from peers first. + + + + +ADMX Info: +- GP English name: *Delay Foreground download Cache Server fallback (in seconds)* +- GP name: *DelayCacheServerFallbackForeground* +- GP element: *DelayCacheServerFallbackForeground* +- GP path: *Windows Components/Delivery Optimization* +- GP ADMX file name: *DeliveryOptimization.admx* + + + +This policy is specified in seconds. +Supported values: 0 - one month (in seconds) + + + + + + + + +
      + **DeliveryOptimization/DODownloadMode** @@ -1561,6 +1705,135 @@ This policy allows an IT Admin to define the following: + +## DeliveryOptimization policies supported by Windows Holographic + +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) + + + +## DeliveryOptimization policies supported by Windows Holographic for Business + +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) + + + +## DeliveryOptimization policies supported by IoT Core + +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) + + + +## DeliveryOptimization policies supported by IoT Enterprise + +- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) +- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) +- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) +- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) +- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) +- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) +- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) +- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) +- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) +- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) +- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) +- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) +- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) +- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) +- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) +- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) +- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) +- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) +- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) +- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) +- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) +- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) +- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) +- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) +- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) +- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) +- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) + + + ## DeliveryOptimization policies supported by Microsoft Surface Hub From b846412493dc2c0e7681a348dc644a576a79f60f Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Thu, 16 May 2019 11:07:13 -0700 Subject: [PATCH 385/737] fix link --- .../configure-microsoft-threat-experts.md | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md index d9d5087041..826dc3c276 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/configure-microsoft-threat-experts.md @@ -15,7 +15,6 @@ manager: dansimp audience: ITPro ms.collection: M365-security-compliance ms.topic: article -ms.date: 02/28/2019 --- # Configure and manage Microsoft Threat Experts capabilities @@ -26,10 +25,10 @@ ms.date: 02/28/2019 [!include[Prerelease information](prerelease.md)] ## Before you begin -To experience the full Microsoft Threat Experts targeted attack notification capability in Microsoft Defender ATP, and preview the experts-on-demand capability, you need to have a valid Premier customer service and support account. Premier charges will not be incurred during for the capability in preview, but for the generally available capability, there will be charges. - +To experience the full Microsoft Threat Experts targeted attack notification capability in Microsoft Defender ATP, and preview the experts-on-demand capability, you need to have a valid Premier customer service and support account. Premier charges will not be incurred during for the capability in preview, but for the generally available capability, there will be charges. + You also need to ensure that you have Microsoft Defender ATP deployed in your environment with machines enrolled, and not just on a laboratory set-up. - + ## Register to Microsoft Threat Experts managed threat hunting service If you're already a Microsoft Defender ATP customer, you can apply through the Microsoft Defender ATP portal. @@ -54,8 +53,7 @@ You can receive targeted attack notification from Microsoft Threat Experts throu To receive targeted attack notifications through email, you need to create an email notification rule. ### Create an email notification rule -You can create rules to send email notifications for notification recipients. See [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) to create, edit, delete, or troubleshoot email notification, for details. - +You can create rules to send email notifications for notification recipients. See [Configure alert notifications](configure-email-notifications.md) to create, edit, delete, or troubleshoot email notification, for details. ## View the targeted attack notification You'll start receiving targeted attack notification from Microsoft Threat Experts in your email after you have configured your system to receive email notification. @@ -67,7 +65,7 @@ You'll start receiving targeted attack notification from Microsoft Threat Expert ## Ask a Microsoft threat expert about suspicious cybersecurity activities in your organization >[!NOTE] ->The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. +>The Microsoft Threat Experts' experts-on-demand capability is still in preview. You can only use the experts-on-demand capability if you have applied for preview and your application has been approved. You can partner with Microsoft Threat Experts who can be engaged directly from within the Windows Defender Security Center for timely and accurate response. Experts provide insights needed to better understand complex threats, targeted attack notifications that you get, or if you need more information about the alerts, a potentially compromised machine, or a threat intelligence context that you see on your portal dashboard. @@ -104,6 +102,7 @@ You can partner with Microsoft Threat Experts who can be engaged directly from w f. Review the summary of your support request, and update if necessary. Make sure that you read and understand the **Microsoft Services Agreement** and **Privacy Statement**. Then, click **Submit**. You will see the confirmation page indicating the response time and your support request number.
      ## Sample questions to ask Microsoft Threat Experts + **Alert information** - We see a new type of alert for a living-off-the-land binary: [AlertID]. Can you tell us something more about this alert and how we can investigate further? - We’ve observed two similar attacks which try to execute malicious PowerShell scripts but generate different alerts. One is "Suspicious Powershell command line" and the other is "A malicious file was detected based on indication provided by O365". What is the difference? From 6eadf23a58e59aae9b7879cf74dc0807c2f86ee7 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 16 May 2019 11:27:59 -0700 Subject: [PATCH 386/737] Updated what's new doc --- ...ew-in-windows-mdm-enrollment-management.md | 2041 +++++++++-------- 1 file changed, 1041 insertions(+), 1000 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index fe4473c45d..900a9638a9 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -10,45 +10,50 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 12/06/2018 +ms.date: 05/15/2019 --- -# What's new in MDM enrollment and management +# What's new in mobile device enrollment and management This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices. -For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). -## In this section +- **What’s new in MDM for Windows 10 versions** + - [What’s new in MDM for Windows 10, version 1903](#whats-new-in-mdm-for-windows-10-version-1903) + - [What’s new in MDM for Windows 10, version 1809](#whats-new-in-mdm-for-windows-10-version-1809) + - [What’s new in MDM for Windows 10, version 1803](#whats-new-in-mdm-for-windows-10-version-1803) + - [What’s new in MDM for Windows 10, version 1709](#whats-new-in-mdm-for-windows-10-version-1709) + - [What’s new in MDM for Windows 10, version 1703](#whats-new-in-mdm-for-windows-10-version-1703) + - [What’s new in MDM for Windows 10, version 1607](#whats-new-in-mdm-for-windows-10-version-1607) + - [What’s new in MDM for Windows 10, version 1511](#whats-new-in-mdm-for-windows-10-version-1511) -- [What's new in MDM enrollment and management](#whats-new-in-mdm-enrollment-and-management) - - [In this section](#in-this-section) - - [What's new in Windows 10, version 1511](#a-href%22%22-id%22whatsnew%22awhats-new-in-windows-10-version-1511) - - [What's new in Windows 10, version 1607](#a-href%22%22-id%22whatsnew1607%22awhats-new-in-windows-10-version-1607) - - [What's new in Windows 10, version 1703](#a-href%22%22-id%22whatsnew10%22awhats-new-in-windows-10-version-1703) - - [What's new in Windows 10, version 1709](#a-href%22%22-id%22whatsnew1709%22awhats-new-in-windows-10-version-1709) - - [What's new in Windows 10, version 1803](#a-href%22%22-id%22whatsnew1803%22awhats-new-in-windows-10-version-1803) - - [What's new in Windows 10, version 1809](#a-href%22%22-id%22whatsnew1809%22awhats-new-in-windows-10-version-1809) - - [Breaking changes and known issues](#breaking-changes-and-known-issues) - - [Get command inside an atomic command is not supported](#a-href%22%22-id%22getcommand%22aget-command-inside-an-atomic-command-is-not-supported) - - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#a-href%22%22-id%22notification%22anotification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) - - [Apps installed using WMI classes are not removed](#a-href%22%22-id%22appsnotremoved%22aapps-installed-using-wmi-classes-are-not-removed) - - [Passing CDATA in SyncML does not work](#a-href%22%22-id%22cdata%22apassing-cdata-in-syncml-does-not-work) - - [SSL settings in IIS server for SCEP must be set to "Ignore"](#a-href%22%22-id%22sslsettings%22assl-settings-in-iis-server-for-scep-must-be-set-to-%22ignore%22) - - [MDM enrollment fails on the mobile device when traffic is going through proxy](#a-href%22%22-id%22enrollmentviaproxy%22amdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) - - [Server-initiated unenrollment failure](#a-href%22%22-id%22unenrollment%22aserver-initiated-unenrollment-failure) - - [Certificates causing issues with Wi-Fi and VPN](#a-href%22%22-id%22certissues%22acertificates-causing-issues-with-wi-fi-and-vpn) - - [Version information for mobile devices](#a-href%22%22-id%22versioninformation%22aversion-information-for-mobile-devices) - - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#a-href%22%22-id%22whitelist%22aupgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) - - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#a-href%22%22-id%22frameworks%22aapps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) - - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#a-href%22%22-id%22wificertissue%22amultiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) - - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#a-href%22%22-id%22remote%22aremote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) - - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#a-href%22%22-id%22renewwns%22amdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) - - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#a-href%22%22-id%22userprovisioning%22auser-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) - - [Requirements to note for VPN certificates also used for Kerberos Authentication](#a-href%22%22-id%22kerberos%22arequirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) - - [Device management agent for the push-button reset is not working](#a-href%22%22-id%22pushbuttonreset%22adevice-management-agent-for-the-push-button-reset-is-not-working) - - [Change history in MDM documentation](#change-history-in-mdm-documentation) +- **Breaking changes and known issues** + - [Get command inside an atomic command is not supported](#get-command-inside-an-atomic-command-is-not-supported) + - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#notification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) + - [Apps installed using WMI classes are not removed](#apps-installed-using-wmi-classes-are-not-removed) + - [Passing CDATA in SyncML does not work](#passing-cdata-in-syncml-does-not-work) + - [SSL settings in IIS server for SCEP must be set to "Ignore"](#ssl-settings-in-iis-server-for-scep-must-be-set-to-ignore) + - [MDM enrollment fails on the mobile device when traffic is going through proxy](#mdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) + - [Server-initiated unenrollment failure](#server-initiated-unenrollment-failure) + - [Certificates causing issues with Wi-Fi and VPN](#certificates-causing-issues-with-wi-fi-and-vpn) + - [Version information for mobile devices](#version-information-for-mobile-devices) + - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#upgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) + - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#apps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) + - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#multiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) + - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#remote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) + - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#mdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) + - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#user-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) + - [Requirements to note for VPN certificates also used for Kerberos Authentication](#requirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) + - [Device management agent for the push-button reset is not working](#device-management-agent-for-the-push-button-reset-is-not-working) + +- **Frequently Asked Questions** + - [Can there be more than 1 MDM server to enroll and manage devices in Windows 10?](#can-there-be-more-than-1-mdm-server-to-enroll-and-manage-devices-in-windows-10) + - [How do I set the maximum number of Azure Active Directory joined devices per user?](#how-do-i-set-the-maximum-number-of-azure-active-directory-joined-devices-per-user) + - [What is dmwappushsvc?](#what-is-dmwappushsvc) + +- **Change history in MDM documentation** - [February 2019](#february-2019) - [January 2019](#january-2019) - [December 2018](#december-2018) @@ -66,10 +71,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s - [October 2017](#october-2017) - [September 2017](#september-2017) - [August 2017](#august-2017) - - [FAQ](#faq) - -## What's new in Windows 10, version 1511 +## What’s new in MDM for Windows 10, version 1903 @@ -77,130 +80,46 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + +
      ItemNew or updated topic Description

      New configuration service providers added in Windows 10, version 1511

        -
      • [AllJoynManagement CSP](alljoynmanagement-csp.md)
      • -
      • [Maps CSP](maps-csp.md)
      • -
      • [Reporting CSP](reporting-csp.md)
      • -
      • [SurfaceHub CSP](surfacehub-csp.md)
      • -
      • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
      • -

      New and updated policies in Policy CSP

      The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

      +
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies in Windows 10, version 1903:

        -
      • Accounts/DomainNamesForEmailSync
      • -
      • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
      • -
      • Bluetooth/ServicesAllowedList
      • -
      • DataProtection/AllowAzureRMSForEDP
      • -
      • DataProtection/RevokeOnUnenroll
      • -
      • DeviceLock/DevicePasswordExpiration
      • -
      • DeviceLock/DevicePasswordHistory
      • -
      • TextInput/AllowInputPanel
      • -
      • Update/PauseDeferrals
      • -
      • Update/RequireDeferUpdate
      • -
      • Update/RequireUpdateApproval
      • +
      • [DeliveryOptimization/DODelayCacheServerFallbackBackground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground
      • +
      • [DeliveryOptimization/DODelayCacheServerFallbackForeground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackforeground)
      • +
      • [Experience/ShowLockOnUserTile](policy-csp-experience.md#experience-showlockonusertile)
      • +
      • [Power/EnergySaverBatteryThresholdOnBattery](policy-csp-power.md#power-energysaverbatterythresholdonbattery)
      • +
      • [Power/EnergySaverBatteryThresholdPluggedIn](policy-csp-power.md#power-energysaverbatterythresholdpluggedin)
      • +
      • [Power/SelectLidCloseActionOnBattery](policy-csp-power.md#power-selectlidcloseactiononbattery)
      • +
      • [Power/SelectLidCloseActionPluggedIn](policy-csp-power.md#power-selectlidcloseactionpluggedin)
      • +
      • [Power/SelectPowerButtonActionOnBattery](policy-csp-power.md#power-selectpowerbuttonactiononbattery)
      • +
      • [Power/SelectPowerButtonActionPluggedIn](policy-csp-power.md#power-selectpowerbuttonactionpluggedin)
      • +
      • [Power/SelectSleepButtonActionOnBattery](policy-csp-power.md#power-selectsleepbuttonactiononbattery)
      • +
      • [Power/SelectSleepButtonActionPluggedIn](policy-csp-power.md#power-selectsleepbuttonactionpluggedin)
      • +
      • [Power/TurnOffHybridSleepOnBattery](policy-csp-power.md#power-turnoffhybridsleeponbattery)
      • +
      • [Power/TurnOffHybridSleepPluggedIn](policy-csp-power.md#power-turnoffhybridsleeppluggedin)
      • +
      • [Power/UnattendedSleepTimeoutOnBattery](policy-csp-power.md#power-unattendedsleeptimeoutonbattery)
      • +
      • [Power/UnattendedSleepTimeoutPluggedIn](policy-csp-power.md#power-unattendedsleeptimeoutpluggedin)
      • +
      • [Update/AutomaticMaintenanceWakeUp](policy-csp-update.md#update-automaticmaintenancewakeup)
      • +
      • [Update/ConfigureDeadlineForFeatureUpdates](policy-csp-update.md#update-configuredeadlineforfeatureupdates)
      • +
      • [Update/ConfigureDeadlineForQualityUpdates](policy-csp-update.md#update-configuredeadlineforqualityupdates)
      • +
      • [Update/ConfigureDeadlineGracePeriod](policy-csp-update.md#update-configuredeadlinegraceperiod)
      • +
      • [WindowsLogon/AllowAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-allowautomaticrestartsignon)
      • +
      • [WindowsLogon/ConfigAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-configautomaticrestartsignon)
      • +
      • [WindowsLogon/EnableFirstLogonAnimation](policy-csp-windowslogon.md#windowslogon-enablefirstlogonanimation)
      -

      The following policies have been updated in the Policy CSP:

      -
        -
      • System/AllowLocation
      • -
      • Update/RequireDeferUpgrade
      • -
      -

      The following policies have been deprecated in the Policy CSP:

      -
        -
      • TextInput/AllowKoreanExtendedHanja
      • -
      • WiFi/AllowWiFiHotSpotReporting
      • -

      Management tool for the Micosoft Store for Business

      New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

      Custom header for generic alert

      The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

      -MDM-GenericAlert: <AlertType1><AlertType2> -

      If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

      Alert message for slow client response

      When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

      -

      To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

      New node in DMClient CSP

      Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

      New nodes in EnterpriseModernAppManagement CSP

      Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

      -
        -
      • AppManagement/GetInventoryQuery
      • -
      • AppManagement/GetInventoryResults
      • -
      • .../PackageFamilyName/AppSettingPolicy/SettingValue
      • -
      • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
      • -
      • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
      • -
      • AppLicenses/StoreLicenses/LicenseID/RequesterID
      • -
      • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
      • -

      New nodes in EnterpriseExt CSP

      Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

      -
        -
      • DeviceCustomData (CustomID, CustomeString)
      • -
      • Brightness (Default, MaxAuto)
      • -
      • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
      • -

      New node in EnterpriseExtFileSystem CSP

      Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

      New nodes in PassportForWork CSP

      Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

      -
        -
      • TenantId/Policies/PINComplexity/History
      • -
      • TenantId/Policies/PINComplexity/Expiration
      • -
      • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
      • -
      • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
      • -
      • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
      • -

      Updated EnterpriseAssignedAccess CSP

      Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

      -
        -
      • In AssignedAccessXML node, added new page settings and quick action settings.
      • -
      • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
      • -
      • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
      • -

      New nodes in the DevDetail CSP

      Here are the changes to the [DevDetail CSP](devdetail-csp.md):

      -
        -
      • Added TotalStore and TotalRAM settings.
      • -
      • Added support for Replace command for the DeviceName setting.
      • -

      Handling large objects

      Added support for the client to handle uploading of large objects to the server.

      Added new CSP in Windows 10, version 1903.

      +
      - -## What's new in Windows 10, version 1607 +## What’s new in MDM for Windows 10, version 1809 @@ -209,309 +128,574 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - - - - - - - + - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      ItemNew or updated topic Description

      Sideloading of apps

      Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

      New value for [NodeCache CSP](nodecache-csp.md)

      In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

      [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

      New CSP.

      [Policy CSP](policy-configuration-service-provider.md)

      Removed the following policies:

      +

      Added the following new policies in Windows 10, version 1809:

        -
      • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
      • -
      • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
      • +
      • ApplicationManagement/LaunchAppAfterLogOn
      • +
      • ApplicationManagement/ScheduleForceRestartForUpdateFailures
      • +
      • Authentication/EnableFastFirstSignIn (Preview mode only)
      • +
      • Authentication/EnableWebSignIn (Preview mode only)
      • +
      • Authentication/PreferredAadTenantDomainName
      • +
      • Browser/AllowFullScreenMode
      • +
      • Browser/AllowPrelaunch
      • +
      • Browser/AllowPrinting
      • +
      • Browser/AllowSavingHistory
      • +
      • Browser/AllowSideloadingOfExtensions
      • +
      • Browser/AllowTabPreloading
      • +
      • Browser/AllowWebContentOnNewTabPage
      • +
      • Browser/ConfigureFavoritesBar
      • +
      • Browser/ConfigureHomeButton
      • +
      • Browser/ConfigureKioskMode
      • +
      • Browser/ConfigureKioskResetAfterIdleTimeout
      • +
      • Browser/ConfigureOpenMicrosoftEdgeWith
      • +
      • Browser/ConfigureTelemetryForMicrosoft365Analytics
      • +
      • Browser/PreventCertErrorOverrides
      • +
      • Browser/SetHomeButtonURL
      • +
      • Browser/SetNewTabPageURL
      • +
      • Browser/UnlockHomeButton
      • +
      • Defender/CheckForSignaturesBeforeRunningScan
      • +
      • Defender/DisableCatchupFullScan
      • +
      • Defender/DisableCatchupQuickScan
      • +
      • Defender/EnableLowCPUPriority
      • +
      • Defender/SignatureUpdateFallbackOrder
      • +
      • Defender/SignatureUpdateFileSharesSources
      • +
      • DeviceGuard/ConfigureSystemGuardLaunch
      • +
      • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
      • +
      • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
      • +
      • DeviceInstallation/PreventDeviceMetadataFromNetwork
      • +
      • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
      • +
      • DmaGuard/DeviceEnumerationPolicy
      • +
      • Experience/AllowClipboardHistory
      • +
      • Experience/DoNotSyncBrowserSettings
      • +
      • Experience/PreventUsersFromTurningOnBrowserSyncing
      • +
      • Kerberos/UPNNameHints
      • +
      • Privacy/AllowCrossDeviceClipboard
      • +
      • Privacy/DisablePrivacyExperience
      • +
      • Privacy/UploadUserActivities
      • +
      • Security/RecoveryEnvironmentAuthentication
      • +
      • System/AllowDeviceNameInDiagnosticData
      • +
      • System/ConfigureMicrosoft365UploadEndpoint
      • +
      • System/DisableDeviceDelete
      • +
      • System/DisableDiagnosticDataViewer
      • +
      • Storage/RemovableDiskDenyWriteAccess
      • +
      • TaskManager/AllowEndTask
      • +
      • Update/EngagedRestartDeadlineForFeatureUpdates
      • +
      • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
      • +
      • Update/EngagedRestartTransitionScheduleForFeatureUpdates
      • +
      • Update/SetDisablePauseUXAccess
      • +
      • Update/SetDisableUXWUAccess
      • +
      • WindowsDefenderSecurityCenter/DisableClearTpmButton
      • +
      • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
      • +
      • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
      • +
      • WindowsLogon/DontDisplayNetworkSelectionUI
      -

      Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

      -
        -
      • Windows 10 Pro
      • -
      • Windows 10 Enterprise
      • -
      • Windows 10 Education
      • -
      -

      Added the following new policies:

      -
        -
      • AboveLock/AllowCortanaAboveLock
      • -
      • ApplicationManagement/DisableStoreOriginatedApps
      • -
      • Authentication/AllowSecondaryAuthenticationDevice
      • -
      • Bluetooth/AllowPrepairing
      • -
      • Browser/AllowExtensions
      • -
      • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
      • -
      • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
      • -
      • DeliveryOptimization/DOAbsoluteMaxCacheSize
      • -
      • DeliveryOptimization/DOMaxDownloadBandwidth
      • -
      • DeliveryOptimization/DOMinBackgroundQoS
      • -
      • DeliveryOptimization/DOModifyCacheDrive
      • -
      • DeliveryOptimization/DOMonthlyUploadDataCap
      • -
      • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
      • -
      • DeviceLock/EnforceLockScreenAndLogonImage
      • -
      • DeviceLock/EnforceLockScreenProvider
      • -
      • Defender/PUAProtection
      • -
      • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
      • -
      • Experience/AllowWindowsSpotlight
      • -
      • Experience/ConfigureWindowsSpotlightOnLockScreen
      • -
      • Experience/DoNotShowFeedbackNotifications
      • -
      • Licensing/AllowWindowsEntitlementActivation
      • -
      • Licensing/DisallowKMSClientOnlineAVSValidation
      • -
      • LockDown/AllowEdgeSwipe
      • -
      • Maps/EnableOfflineMapsAutoUpdate
      • -
      • Maps/AllowOfflineMapsDownloadOverMeteredConnection
      • -
      • Messaging/AllowMessageSync
      • -
      • NetworkIsolation/EnterpriseCloudResources
      • -
      • NetworkIsolation/EnterpriseInternalProxyServers
      • -
      • NetworkIsolation/EnterpriseIPRange
      • -
      • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
      • -
      • NetworkIsolation/EnterpriseNetworkDomainNames
      • -
      • NetworkIsolation/EnterpriseProxyServers
      • -
      • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
      • -
      • NetworkIsolation/NeutralResources
      • -
      • Notifications/DisallowNotificationMirroring
      • -
      • Privacy/DisableAdvertisingId
      • -
      • Privacy/LetAppsAccessAccountInfo
      • -
      • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCalendar
      • -
      • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory
      • -
      • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCamera
      • -
      • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessContacts
      • -
      • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessEmail
      • -
      • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessLocation
      • -
      • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMessaging
      • -
      • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone
      • -
      • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMotion
      • -
      • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessNotifications
      • -
      • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessPhone
      • -
      • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessRadios
      • -
      • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices
      • -
      • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices
      • -
      • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
      • -
      • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
      • -
      • Settings/AllowEditDeviceName
      • -
      • Speech/AllowSpeechModelUpdate
      • -
      • System/TelemetryProxy
      • -
      • Update/ActiveHoursStart
      • -
      • Update/ActiveHoursEnd
      • -
      • Update/AllowMUUpdateService
      • -
      • Update/BranchReadinessLevel
      • -
      • Update/DeferFeatureUpdatesPeriodInDays
      • -
      • Update/DeferQualityUpdatesPeriodInDays
      • -
      • Update/ExcludeWUDriversInQualityUpdate
      • -
      • Update/PauseFeatureUpdates
      • -
      • Update/PauseQualityUpdates
      • -
      • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
      • -
      • WindowsInkWorkspace/AllowWindowsInkWorkspace
      • -
      • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
      • -
      • WirelessDisplay/AllowProjectionToPC
      • -
      • WirelessDisplay/RequirePinForPairing
      • -
      -

      Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

      -

      Updated DeliveryOptimization/DODownloadMode to add new values.

      -

      Updated Experience/AllowCortana description to clarify what each supported value does.

      -

      Updated Security/AntiTheftMode description to clarify what each supported value does.

      [PassportForWork CSP](passportforwork-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

      +
      [Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

      Added new configuration service provider in Windows 10, version 1809.

      +
      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added S mode settings and SyncML examples in Windows 10, version 1809.

      +
      [SUPL CSP](supl-csp.md)

      Added 3 new certificate nodes in Windows 10, version 1809.

      +
      [Defender CSP](defender-csp.md)

      Added a new node Health/ProductStatus in Windows 10, version 1809.

      +
      [BitLocker CSP](bitlocker-csp.md)

      Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

      +
      [DevDetail CSP](devdetail-csp.md)

      Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

      +
      [Wifi CSP](wifi-csp.md)

      Added a new node WifiCost in Windows 10, version 1809.

      +
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [RemoteWipe CSP](remotewipe-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [TenantLockdown CSP](tenantlockdown-csp.md)

      Added new CSP in Windows 10, version 1809.

      +
      [Office CSP](office-csp.md)

      Added FinalStatus setting in Windows 10, version 1809.

      +
      + +## What’s new in MDM for Windows 10, version 1803 + + ++++ + + + + + + + + + + + + - - + - - - - - - + + + + + + + - +
    23. Rollback
    24. +
    25. Rollback/FeatureUpdate
    26. +
    27. Rollback/QualityUpdateStatus
    28. +
    29. Rollback/FeatureUpdateStatus
    30. + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

      Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

      + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      New or updated topicDescription
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1803:

      +
        +
      • ApplicationDefaults/EnableAppUriHandlers
      • +
      • ApplicationManagement/MSIAllowUserControlOverInstall
      • +
      • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
      • +
      • Bluetooth/AllowPromptedProximalConnections
      • +
      • Browser/AllowConfigurationUpdateForBooksLibrary
      • +
      • Browser/AlwaysEnableBooksLibrary
      • +
      • Browser/EnableExtendedBooksTelemetry
      • +
      • Browser/UseSharedFolderForBooks
      • +
      • Connectivity/AllowPhonePCLinking
      • +
      • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
      • +
      • DeliveryOptimization/DODelayForegroundDownloadFromHttp
      • +
      • DeliveryOptimization/DOGroupIdSource
      • +
      • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
      • +
      • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
      • +
      • DeliveryOptimization/DORestrictPeerSelectionBy
      • +
      • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
      • +
      • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
      • +
      • Display/DisablePerProcessDpiForApps
      • +
      • Display/EnablePerProcessDpi
      • +
      • Display/EnablePerProcessDpiForApps
      • +
      • Experience/AllowWindowsSpotlightOnSettings
      • +
      • KioskBrowser/BlockedUrlExceptions
      • +
      • KioskBrowser/BlockedUrls
      • +
      • KioskBrowser/DefaultURL
      • +
      • KioskBrowser/EnableEndSessionButton
      • +
      • KioskBrowser/EnableHomeButton
      • +
      • KioskBrowser/EnableNavigationButtons
      • +
      • KioskBrowser/RestartOnIdleTime
      • +
      • LanmanWorkstation/EnableInsecureGuestLogons
      • +
      • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
      • +
      • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
      • +
      • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
      • +
      • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
      • +
      • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
      • +
      • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
      • +
      • Notifications/DisallowCloudNotification
      • +
      • RestrictedGroups/ConfigureGroupMembership
      • +
      • Search/AllowCortanaInAAD
      • +
      • Search/DoNotUseWebResults
      • +
      • Security/ConfigureWindowsPasswords
      • +
      • Start/DisableContextMenus
      • +
      • System/FeedbackHubAlwaysSaveDiagnosticsLocally
      • +
      • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
      • +
      • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
      • +
      • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
      • +
      • TaskScheduler/EnableXboxGameSaveTask
      • +
      • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
      • +
      • TextInput/ForceTouchKeyboardDockedState
      • +
      • TextInput/TouchKeyboardDictationButtonAvailability
      • +
      • TextInput/TouchKeyboardEmojiButtonAvailability
      • +
      • TextInput/TouchKeyboardFullModeAvailability
      • +
      • TextInput/TouchKeyboardHandwritingModeAvailability
      • +
      • TextInput/TouchKeyboardNarrowModeAvailability
      • +
      • TextInput/TouchKeyboardSplitModeAvailability
      • +
      • TextInput/TouchKeyboardWideModeAvailability
      • +
      • Update/ConfigureFeatureUpdateUninstallPeriod
      • +
      • UserRights/AccessCredentialManagerAsTrustedCaller
      • +
      • UserRights/AccessFromNetwork
      • +
      • UserRights/ActAsPartOfTheOperatingSystem
      • +
      • UserRights/AllowLocalLogOn
      • +
      • UserRights/BackupFilesAndDirectories
      • +
      • UserRights/ChangeSystemTime
      • +
      • UserRights/CreateGlobalObjects
      • +
      • UserRights/CreatePageFile
      • +
      • UserRights/CreatePermanentSharedObjects
      • +
      • UserRights/CreateSymbolicLinks
      • +
      • UserRights/CreateToken
      • +
      • UserRights/DebugPrograms
      • +
      • UserRights/DenyAccessFromNetwork
      • +
      • UserRights/DenyLocalLogOn
      • +
      • UserRights/DenyRemoteDesktopServicesLogOn
      • +
      • UserRights/EnableDelegation
      • +
      • UserRights/GenerateSecurityAudits
      • +
      • UserRights/ImpersonateClient
      • +
      • UserRights/IncreaseSchedulingPriority
      • +
      • UserRights/LoadUnloadDeviceDrivers
      • +
      • UserRights/LockMemory
      • +
      • UserRights/ManageAuditingAndSecurityLog
      • +
      • UserRights/ManageVolume
      • +
      • UserRights/ModifyFirmwareEnvironment
      • +
      • UserRights/ModifyObjectLabel
      • +
      • UserRights/ProfileSingleProcess
      • +
      • UserRights/RemoteShutdown
      • +
      • UserRights/RestoreFilesAndDirectories
      • +
      • UserRights/TakeOwnership
      • +
      • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
      • +
      • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
      • +
      • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
      • +
      • WindowsDefenderSecurityCenter/HideSecureBoot
      • +
      • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
      • +
      +

      Security/RequireDeviceEncryption - updated to show it is supported in desktop.

      +
      [BitLocker CSP](bitlocker-csp.md)

      Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

      +
      [DMClient CSP](dmclient-csp.md)

      Added the following settings:

      +

      Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

        -
      • ManagementServerAddressList
      • -
      • AADDeviceID
      • -
      • EnrollmentType
      • -
      • HWDevID
      • -
      • CommercialID
      • +
      • AADSendDeviceToken
      • +
      • BlockInStatusPage
      • +
      • AllowCollectLogsButton
      • +
      • CustomErrorText
      • +
      • SkipDeviceStatusPage
      • +
      • SkipUserStatusPage
      -

      Removed the EnrollmentID setting.

      [DeviceManageability CSP](devicemanageability-csp.md)

      New CSP.

      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following new settings:

      +
      [Defender CSP](defender-csp.md)

      Added new node (OfflineScan) in Windows 10, version 1803.

      +
      [UEFI CSP](uefi-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [Update CSP](update-csp.md)

      Added the following nodes in Windows 10, version 1803:

        -
      • DeviceStatus/TPM/SpecificationVersion
      • -
      • DeviceStatus/OS/Edition
      • -
      • DeviceStatus/Antivirus/SignatureStatus
      • -
      • DeviceStatus/Antivirus/Status
      • -
      • DeviceStatus/Antispyware/SignatureStatus
      • -
      • DeviceStatus/Antispyware/Status
      • -
      • DeviceStatus/Firewall/Status
      • -
      • DeviceStatus/UAC/Status
      • -
      • DeviceStatus/Battery/Status
      • -
      • DeviceStatus/Battery/EstimatedChargeRemaining
      • -
      • DeviceStatus/Battery/EstimatedRuntime
      • -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added SyncML examples.

      [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
        -
      • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
      • -
      • Updated the DDF and XSD file sections.
      • -
      [SecureAssessment CSP](secureassessment-csp.md)

      New CSP for Windows 10, version 1607

      [DiagnosticLog CSP](diagnosticlog-csp.md) -

      [DiagnosticLog DDF](diagnosticlog-ddf.md)

      Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

      +

      Added the following nodes in Windows 10, version 1803:

        -
      • DeviceStateData
      • -
      • DeviceStateData/MdmConfiguration
      • -
      [Reboot CSP](reboot-csp.md)

      New CSP for Windows 10, version 1607

      [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

      New CSP for Windows 10, version 1607

      [VPNv2 CSP](vpnv2-csp.md)

      Added the following settings for Windows 10, version 1607

      -
        -
      • ProfileName/RouteList/routeRowId/ExclusionRoute
      • -
      • ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
      • -
      • ProfileName/DomainNameInformationList/dniRowId/Persistent
      • -
      • ProfileName/ProfileXML
      • -
      • ProfileName/DeviceCompliance/Enabled
      • -
      • ProfileName/DeviceCompliance/Sso
      • -
      • ProfileName/DeviceCompliance/Sso/Enabled
      • -
      • ProfileName/DeviceCompliance/Sso/IssuerHash
      • -
      • ProfileName/DeviceCompliance/Sso/Eku
      • -
      • ProfileName/NativeProfile/CryptographySuite
      • -
      • ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
      • -
      • ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
      • -
      • ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
      • -
      • ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
      • -
      • ProfileName/NativeProfile/CryptographySuite/DHGroup
      • -
      • ProfileName/NativeProfile/CryptographySuite/PfsGroup
      • -
      • ProfileName/NativeProfile/L2tpPsk
      • -
      [Win32AppInventory CSP](win32appinventory-csp.md) -

      [Win32AppInventory DDF](win32appinventory-ddf-file.md)

      New CSP for Windows 10, version 1607.

      [SharedPC CSP](sharedpc-csp.md)

      New CSP for Windows 10, version 1607.

      [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

      New CSP for Windows 10, version 1607.

      [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

      Added new classes for Windows 10, version 1607.

      [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

      Topic renamed from "Enrollment UI".

      -

      Completely updated enrollment procedures and screenshots.

      [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) -

      [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

      Added the following new setting for Windows 10, version 1607:

      -
        -
      • NextSession/HORMEnabled
      • -
      [CertificateStore CSP](certificatestore-csp.md) -

      [CertificateStore DDF file](certificatestore-ddf-file.md)

      Added the following new settings in Windows 10, version 1607:

      -
        -
      • My/WSTEP/Renew/LastRenewalAttemptTime
      • -
      • My/WSTEP/Renew/RenewNow
      • -

      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added the following new node and settings in Windows 10, version 1607, but not documented:

      -
        -
      • Subscriptions
      • -
      • Subscriptions/SubscriptionId
      • -
      • Subscriptions/SubscriptionId/Status
      • -
      • Subscriptions/SubscriptionId/Name
      • +
      • Status
      • +
      • ShellLauncher
      • +
      • StatusConfiguration
      -
      [MultiSIM CSP](multisim-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • MaintainProcessorArchitectureOnUpdate
      • +
      +
      [eUICCs CSP](euiccs-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • IsEnabled
      • +
      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • OS/Mode
      • +
      +
      [AccountManagement CSP](accountmanagement-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • UntrustedCertificates
      • +
      +
      [NetworkProxy CSP](\networkproxy--csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • ProxySettingsPerUser
      • +
      +
      [Accounts CSP](accounts-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

      Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

      +
      [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

      Added the DDF download of Windows 10, version 1803 configuration service providers.

      +
      -## What's new in Windows 10, version 1703 +## What’s new in MDM for Windows 10, version 1709 + + ++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      ItemDescription
      The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

      The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

      +
        +
      • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
      • +
      • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
      • +
      • DomainName - fully qualified domain name if the device is domain-joined.
      • +
      +

      For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

      +
      [Firewall CSP](firewall-csp.md)

      Added new CSP in Windows 10, version 1709.

      +
      [eUICCs CSP](euiccs-csp.md)

      Added new CSP in Windows 10, version 1709.

      +
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
      [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
      [VPNv2 CSP](vpnv2-csp.md)

      Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
        +
      • DeviceStatus/DomainName
      • +
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
      • +
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
      • +
      • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
      • +
      +
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following setting in Windows 10, version 1709.

      +
        +
      • Configuration
      • +
      +

      Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

      +
      [DeviceManageability CSP](devicemanageability-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
        +
      • Provider/_ProviderID_/ConfigInfo
      • +
      • Provider/_ProviderID_/EnrollmentInfo
      • +
      +
      [Office CSP](office-csp.md)

      Added the following setting in Windows 10, version 1709:

      +
        +
      • Installation/CurrentStatus
      • +
      +
      [DMClient CSP](dmclient-csp.md)

      Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

      +
      [Bitlocker CSP](bitlocker-csp.md)

      Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

      +
      [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

      Added new policies.

      +
      Microsoft Store for Business and Microsoft Store

      Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

      +
      [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

      New features in the Settings app:

      +
        +
      • User sees installation progress of critical policies during MDM enrollment.
      • +
      • User knows what policies, profiles, apps MDM has configured
      • +
      • IT helpdesk can get detailed MDM diagnostic information using client tools
      • +
      +

      For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

      +
      [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

      Added new topic to introduce a new Group Policy for automatic MDM enrollment.

      +
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1709:

      +
        +
      • Authentication/AllowAadPasswordReset
      • +
      • Authentication/AllowFidoDeviceSignon
      • +
      • Browser/LockdownFavorites
      • +
      • Browser/ProvisionFavorites
      • +
      • Cellular/LetAppsAccessCellularData
      • +
      • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
      • +
      • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
      • +
      • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
      • +
      • CredentialProviders/DisableAutomaticReDeploymentCredentials
      • +
      • DeviceGuard/EnableVirtualizationBasedSecurity
      • +
      • DeviceGuard/RequirePlatformSecurityFeatures
      • +
      • DeviceGuard/LsaCfgFlags
      • +
      • DeviceLock/MinimumPasswordAge
      • +
      • ExploitGuard/ExploitProtectionSettings
      • +
      • Games/AllowAdvancedGamingServices
      • +
      • Handwriting/PanelDefaultModeDocked
      • +
      • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
      • +
      • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
      • +
      • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
      • +
      • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
      • +
      • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
      • +
      • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
      • +
      • Power/DisplayOffTimeoutOnBattery
      • +
      • Power/DisplayOffTimeoutPluggedIn
      • +
      • Power/HibernateTimeoutOnBattery
      • +
      • Power/HibernateTimeoutPluggedIn
      • +
      • Power/StandbyTimeoutOnBattery
      • +
      • Power/StandbyTimeoutPluggedIn
      • +
      • Privacy/EnableActivityFeed
      • +
      • Privacy/PublishUserActivities
      • +
      • Defender/AttackSurfaceReductionOnlyExclusions
      • +
      • Defender/AttackSurfaceReductionRules
      • +
      • Defender/CloudBlockLevel
      • +
      • Defender/CloudExtendedTimeout
      • +
      • Defender/ControlledFolderAccessAllowedApplications
      • +
      • Defender/ControlledFolderAccessProtectedFolders
      • +
      • Defender/EnableControlledFolderAccess
      • +
      • Defender/EnableNetworkProtection
      • +
      • Education/DefaultPrinterName
      • +
      • Education/PreventAddingNewPrinters
      • +
      • Education/PrinterNames
      • +
      • Search/AllowCloudSearch
      • +
      • Security/ClearTPMIfNotReady
      • +
      • Settings/AllowOnlineTips
      • +
      • Start/HidePeopleBar
      • +
      • Storage/AllowDiskHealthModelUpdates
      • +
      • System/DisableEnterpriseAuthProxy
      • +
      • System/LimitEnhancedDiagnosticDataWindowsAnalytics
      • +
      • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
      • +
      • Update/DisableDualScan
      • +
      • Update/ManagePreviewBuilds
      • +
      • Update/ScheduledInstallEveryWeek
      • +
      • Update/ScheduledInstallFirstWeek
      • +
      • Update/ScheduledInstallFourthWeek
      • +
      • Update/ScheduledInstallSecondWeek
      • +
      • Update/ScheduledInstallThirdWeek
      • +
      • WindowsDefenderSecurityCenter/CompanyName
      • +
      • WindowsDefenderSecurityCenter/DisableAppBrowserUI
      • +
      • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
      • +
      • WindowsDefenderSecurityCenter/DisableFamilyUI
      • +
      • WindowsDefenderSecurityCenter/DisableHealthUI
      • +
      • WindowsDefenderSecurityCenter/DisableNetworkUI
      • +
      • WindowsDefenderSecurityCenter/DisableNotifications
      • +
      • WindowsDefenderSecurityCenter/DisableVirusUI
      • +
      • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
      • +
      • WindowsDefenderSecurityCenter/Email
      • +
      • WindowsDefenderSecurityCenter/EnableCustomizedToasts
      • +
      • WindowsDefenderSecurityCenter/EnableInAppCustomization
      • +
      • WindowsDefenderSecurityCenter/Phone
      • +
      • WindowsDefenderSecurityCenter/URL
      • +
      • WirelessDisplay/AllowMdnsAdvertisement
      • +
      • WirelessDisplay/AllowMdnsDiscovery
      • +
      +
      + +## What’s new in MDM for Windows 10, version 1703 @@ -932,7 +1116,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s
        -## What's new in Windows 10, version 1709 + +## What’s new in MDM for Windows 10, version 1607 @@ -946,437 +1131,304 @@ For details about Microsoft mobile device management protocols for Windows 10 s - - - - - - - - - - - + + - - + + - - + + - - + + + - - + - - - +

      Removed the EnrollmentID setting.

      + - - - - - - - - - - - - - - - - - - - - - - - - - -
      The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

      The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

      -
        -
      • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
      • -
      • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
      • -
      • DomainName - fully qualified domain name if the device is domain-joined.
      • -
      -

      For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

      -
      [Firewall CSP](firewall-csp.md)

      Added new CSP in Windows 10, version 1709.

      -
      [eUICCs CSP](euiccs-csp.md)

      Added new CSP in Windows 10, version 1709.

      -
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).

      Sideloading of apps

      Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

      [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.

      New value for [NodeCache CSP](nodecache-csp.md)

      In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

      New CSP.

      [VPNv2 CSP](vpnv2-csp.md)

      Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

      -
      [Policy CSP](policy-configuration-service-provider.md)

      Removed the following policies:

      +
        +
      • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
      • +
      • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
      • +
      +

      Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

      +
        +
      • Windows 10 Pro
      • +
      • Windows 10 Enterprise
      • +
      • Windows 10 Education
      • +
      +

      Added the following new policies:

      +
        +
      • AboveLock/AllowCortanaAboveLock
      • +
      • ApplicationManagement/DisableStoreOriginatedApps
      • +
      • Authentication/AllowSecondaryAuthenticationDevice
      • +
      • Bluetooth/AllowPrepairing
      • +
      • Browser/AllowExtensions
      • +
      • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
      • +
      • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
      • +
      • DeliveryOptimization/DOAbsoluteMaxCacheSize
      • +
      • DeliveryOptimization/DOMaxDownloadBandwidth
      • +
      • DeliveryOptimization/DOMinBackgroundQoS
      • +
      • DeliveryOptimization/DOModifyCacheDrive
      • +
      • DeliveryOptimization/DOMonthlyUploadDataCap
      • +
      • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
      • +
      • DeviceLock/EnforceLockScreenAndLogonImage
      • +
      • DeviceLock/EnforceLockScreenProvider
      • +
      • Defender/PUAProtection
      • +
      • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
      • +
      • Experience/AllowWindowsSpotlight
      • +
      • Experience/ConfigureWindowsSpotlightOnLockScreen
      • +
      • Experience/DoNotShowFeedbackNotifications
      • +
      • Licensing/AllowWindowsEntitlementActivation
      • +
      • Licensing/DisallowKMSClientOnlineAVSValidation
      • +
      • LockDown/AllowEdgeSwipe
      • +
      • Maps/EnableOfflineMapsAutoUpdate
      • +
      • Maps/AllowOfflineMapsDownloadOverMeteredConnection
      • +
      • Messaging/AllowMessageSync
      • +
      • NetworkIsolation/EnterpriseCloudResources
      • +
      • NetworkIsolation/EnterpriseInternalProxyServers
      • +
      • NetworkIsolation/EnterpriseIPRange
      • +
      • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
      • +
      • NetworkIsolation/EnterpriseNetworkDomainNames
      • +
      • NetworkIsolation/EnterpriseProxyServers
      • +
      • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
      • +
      • NetworkIsolation/NeutralResources
      • +
      • Notifications/DisallowNotificationMirroring
      • +
      • Privacy/DisableAdvertisingId
      • +
      • Privacy/LetAppsAccessAccountInfo
      • +
      • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCalendar
      • +
      • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory
      • +
      • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCamera
      • +
      • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessContacts
      • +
      • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessEmail
      • +
      • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessLocation
      • +
      • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMessaging
      • +
      • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone
      • +
      • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMotion
      • +
      • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessNotifications
      • +
      • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessPhone
      • +
      • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessRadios
      • +
      • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices
      • +
      • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices
      • +
      • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
      • +
      • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
      • +
      • Settings/AllowEditDeviceName
      • +
      • Speech/AllowSpeechModelUpdate
      • +
      • System/TelemetryProxy
      • +
      • Update/ActiveHoursStart
      • +
      • Update/ActiveHoursEnd
      • +
      • Update/AllowMUUpdateService
      • +
      • Update/BranchReadinessLevel
      • +
      • Update/DeferFeatureUpdatesPeriodInDays
      • +
      • Update/DeferQualityUpdatesPeriodInDays
      • +
      • Update/ExcludeWUDriversInQualityUpdate
      • +
      • Update/PauseFeatureUpdates
      • +
      • Update/PauseQualityUpdates
      • +
      • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
      • +
      • WindowsInkWorkspace/AllowWindowsInkWorkspace
      • +
      • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
      • +
      • WirelessDisplay/AllowProjectionToPC
      • +
      • WirelessDisplay/RequirePinForPairing
      • +
      +

      Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

      +

      Updated DeliveryOptimization/DODownloadMode to add new values.

      +

      Updated Experience/AllowCortana description to clarify what each supported value does.

      +

      Updated Security/AntiTheftMode description to clarify what each supported value does.

      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
      [DMClient CSP](dmclient-csp.md)

      Added the following settings:

        -
      • DeviceStatus/DomainName
      • -
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
      • -
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
      • -
      • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
      • +
      • ManagementServerAddressList
      • +
      • AADDeviceID
      • +
      • EnrollmentType
      • +
      • HWDevID
      • +
      • CommercialID
      -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following setting in Windows 10, version 1709.

      -
        -
      • Configuration
      • -
      -

      Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

      -
      [DeviceManageability CSP](devicemanageability-csp.md)

      Added the following settings in Windows 10, version 1709:

      -
        -
      • Provider/_ProviderID_/ConfigInfo
      • -
      • Provider/_ProviderID_/EnrollmentInfo
      • -
      -
      [Office CSP](office-csp.md)

      Added the following setting in Windows 10, version 1709:

      -
        -
      • Installation/CurrentStatus
      • -
      -
      [DMClient CSP](dmclient-csp.md)

      Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

      -
      [Bitlocker CSP](bitlocker-csp.md)

      Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

      -
      [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

      Added new policies.

      -
      Microsoft Store for Business and Microsoft Store

      Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

      -
      [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

      New features in the Settings app:

      -
        -
      • User sees installation progress of critical policies during MDM enrollment.
      • -
      • User knows what policies, profiles, apps MDM has configured
      • -
      • IT helpdesk can get detailed MDM diagnostic information using client tools
      • -
      -

      For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

      -
      [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

      Added new topic to introduce a new Group Policy for automatic MDM enrollment.

      -
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1709:

      -
        -
      • Authentication/AllowAadPasswordReset
      • -
      • Authentication/AllowFidoDeviceSignon
      • -
      • Browser/LockdownFavorites
      • -
      • Browser/ProvisionFavorites
      • -
      • Cellular/LetAppsAccessCellularData
      • -
      • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
      • -
      • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
      • -
      • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
      • -
      • CredentialProviders/DisableAutomaticReDeploymentCredentials
      • -
      • DeviceGuard/EnableVirtualizationBasedSecurity
      • -
      • DeviceGuard/RequirePlatformSecurityFeatures
      • -
      • DeviceGuard/LsaCfgFlags
      • -
      • DeviceLock/MinimumPasswordAge
      • -
      • ExploitGuard/ExploitProtectionSettings
      • -
      • Games/AllowAdvancedGamingServices
      • -
      • Handwriting/PanelDefaultModeDocked
      • -
      • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
      • -
      • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
      • -
      • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
      • -
      • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
      • -
      • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
      • -
      • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
      • -
      • Power/DisplayOffTimeoutOnBattery
      • -
      • Power/DisplayOffTimeoutPluggedIn
      • -
      • Power/HibernateTimeoutOnBattery
      • -
      • Power/HibernateTimeoutPluggedIn
      • -
      • Power/StandbyTimeoutOnBattery
      • -
      • Power/StandbyTimeoutPluggedIn
      • -
      • Privacy/EnableActivityFeed
      • -
      • Privacy/PublishUserActivities
      • -
      • Defender/AttackSurfaceReductionOnlyExclusions
      • -
      • Defender/AttackSurfaceReductionRules
      • -
      • Defender/CloudBlockLevel
      • -
      • Defender/CloudExtendedTimeout
      • -
      • Defender/ControlledFolderAccessAllowedApplications
      • -
      • Defender/ControlledFolderAccessProtectedFolders
      • -
      • Defender/EnableControlledFolderAccess
      • -
      • Defender/EnableNetworkProtection
      • -
      • Education/DefaultPrinterName
      • -
      • Education/PreventAddingNewPrinters
      • -
      • Education/PrinterNames
      • -
      • Search/AllowCloudSearch
      • -
      • Security/ClearTPMIfNotReady
      • -
      • Settings/AllowOnlineTips
      • -
      • Start/HidePeopleBar
      • -
      • Storage/AllowDiskHealthModelUpdates
      • -
      • System/DisableEnterpriseAuthProxy
      • -
      • System/LimitEnhancedDiagnosticDataWindowsAnalytics
      • -
      • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
      • -
      • Update/DisableDualScan
      • -
      • Update/ManagePreviewBuilds
      • -
      • Update/ScheduledInstallEveryWeek
      • -
      • Update/ScheduledInstallFirstWeek
      • -
      • Update/ScheduledInstallFourthWeek
      • -
      • Update/ScheduledInstallSecondWeek
      • -
      • Update/ScheduledInstallThirdWeek
      • -
      • WindowsDefenderSecurityCenter/CompanyName
      • -
      • WindowsDefenderSecurityCenter/DisableAppBrowserUI
      • -
      • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
      • -
      • WindowsDefenderSecurityCenter/DisableFamilyUI
      • -
      • WindowsDefenderSecurityCenter/DisableHealthUI
      • -
      • WindowsDefenderSecurityCenter/DisableNetworkUI
      • -
      • WindowsDefenderSecurityCenter/DisableNotifications
      • -
      • WindowsDefenderSecurityCenter/DisableVirusUI
      • -
      • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
      • -
      • WindowsDefenderSecurityCenter/Email
      • -
      • WindowsDefenderSecurityCenter/EnableCustomizedToasts
      • -
      • WindowsDefenderSecurityCenter/EnableInAppCustomization
      • -
      • WindowsDefenderSecurityCenter/Phone
      • -
      • WindowsDefenderSecurityCenter/URL
      • -
      • WirelessDisplay/AllowMdnsAdvertisement
      • -
      • WirelessDisplay/AllowMdnsDiscovery
      • -
      -
      - -## What's new in Windows 10, version 1803 - - ---- - - - - + - - - - - + + - - - - - - - - - - - - - - - - + + + + + + - - + + + + + + + - - + + + + + + + + + - - - + + + + + + + + + + + + + + + + + + + + + + + + - - - + + + + - - - - - - + + + + - - - - - - - - - - - - + +
      New or updated topicDescription

      New CSP.

      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1803:

      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following new settings:

        -
      • ApplicationDefaults/EnableAppUriHandlers
      • -
      • ApplicationManagement/MSIAllowUserControlOverInstall
      • -
      • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
      • -
      • Bluetooth/AllowPromptedProximalConnections
      • -
      • Browser/AllowConfigurationUpdateForBooksLibrary
      • -
      • Browser/AlwaysEnableBooksLibrary
      • -
      • Browser/EnableExtendedBooksTelemetry
      • -
      • Browser/UseSharedFolderForBooks
      • -
      • Connectivity/AllowPhonePCLinking
      • -
      • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
      • -
      • DeliveryOptimization/DODelayForegroundDownloadFromHttp
      • -
      • DeliveryOptimization/DOGroupIdSource
      • -
      • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
      • -
      • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
      • -
      • DeliveryOptimization/DORestrictPeerSelectionBy
      • -
      • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
      • -
      • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
      • -
      • Display/DisablePerProcessDpiForApps
      • -
      • Display/EnablePerProcessDpi
      • -
      • Display/EnablePerProcessDpiForApps
      • -
      • Experience/AllowWindowsSpotlightOnSettings
      • -
      • KioskBrowser/BlockedUrlExceptions
      • -
      • KioskBrowser/BlockedUrls
      • -
      • KioskBrowser/DefaultURL
      • -
      • KioskBrowser/EnableEndSessionButton
      • -
      • KioskBrowser/EnableHomeButton
      • -
      • KioskBrowser/EnableNavigationButtons
      • -
      • KioskBrowser/RestartOnIdleTime
      • -
      • LanmanWorkstation/EnableInsecureGuestLogons
      • -
      • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
      • -
      • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
      • -
      • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
      • -
      • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
      • -
      • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
      • -
      • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
      • -
      • Notifications/DisallowCloudNotification
      • -
      • RestrictedGroups/ConfigureGroupMembership
      • -
      • Search/AllowCortanaInAAD
      • -
      • Search/DoNotUseWebResults
      • -
      • Security/ConfigureWindowsPasswords
      • -
      • Start/DisableContextMenus
      • -
      • System/FeedbackHubAlwaysSaveDiagnosticsLocally
      • -
      • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
      • -
      • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
      • -
      • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
      • -
      • TaskScheduler/EnableXboxGameSaveTask
      • -
      • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
      • -
      • TextInput/ForceTouchKeyboardDockedState
      • -
      • TextInput/TouchKeyboardDictationButtonAvailability
      • -
      • TextInput/TouchKeyboardEmojiButtonAvailability
      • -
      • TextInput/TouchKeyboardFullModeAvailability
      • -
      • TextInput/TouchKeyboardHandwritingModeAvailability
      • -
      • TextInput/TouchKeyboardNarrowModeAvailability
      • -
      • TextInput/TouchKeyboardSplitModeAvailability
      • -
      • TextInput/TouchKeyboardWideModeAvailability
      • -
      • Update/ConfigureFeatureUpdateUninstallPeriod
      • -
      • UserRights/AccessCredentialManagerAsTrustedCaller
      • -
      • UserRights/AccessFromNetwork
      • -
      • UserRights/ActAsPartOfTheOperatingSystem
      • -
      • UserRights/AllowLocalLogOn
      • -
      • UserRights/BackupFilesAndDirectories
      • -
      • UserRights/ChangeSystemTime
      • -
      • UserRights/CreateGlobalObjects
      • -
      • UserRights/CreatePageFile
      • -
      • UserRights/CreatePermanentSharedObjects
      • -
      • UserRights/CreateSymbolicLinks
      • -
      • UserRights/CreateToken
      • -
      • UserRights/DebugPrograms
      • -
      • UserRights/DenyAccessFromNetwork
      • -
      • UserRights/DenyLocalLogOn
      • -
      • UserRights/DenyRemoteDesktopServicesLogOn
      • -
      • UserRights/EnableDelegation
      • -
      • UserRights/GenerateSecurityAudits
      • -
      • UserRights/ImpersonateClient
      • -
      • UserRights/IncreaseSchedulingPriority
      • -
      • UserRights/LoadUnloadDeviceDrivers
      • -
      • UserRights/LockMemory
      • -
      • UserRights/ManageAuditingAndSecurityLog
      • -
      • UserRights/ManageVolume
      • -
      • UserRights/ModifyFirmwareEnvironment
      • -
      • UserRights/ModifyObjectLabel
      • -
      • UserRights/ProfileSingleProcess
      • -
      • UserRights/RemoteShutdown
      • -
      • UserRights/RestoreFilesAndDirectories
      • -
      • UserRights/TakeOwnership
      • -
      • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
      • -
      • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
      • -
      • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
      • -
      • WindowsDefenderSecurityCenter/HideSecureBoot
      • -
      • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
      • -
      -

      Security/RequireDeviceEncryption - updated to show it is supported in desktop.

      +
    31. DeviceStatus/TPM/SpecificationVersion
    32. +
    33. DeviceStatus/OS/Edition
    34. +
    35. DeviceStatus/Antivirus/SignatureStatus
    36. +
    37. DeviceStatus/Antivirus/Status
    38. +
    39. DeviceStatus/Antispyware/SignatureStatus
    40. +
    41. DeviceStatus/Antispyware/Status
    42. +
    43. DeviceStatus/Firewall/Status
    44. +
    45. DeviceStatus/UAC/Status
    46. +
    47. DeviceStatus/Battery/Status
    48. +
    49. DeviceStatus/Battery/EstimatedChargeRemaining
    50. +
    51. DeviceStatus/Battery/EstimatedRuntime
    52. +
      [BitLocker CSP](bitlocker-csp.md)

      Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

      -
      [DMClient CSP](dmclient-csp.md)

      Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

      -
        -
      • AADSendDeviceToken
      • -
      • BlockInStatusPage
      • -
      • AllowCollectLogsButton
      • -
      • CustomErrorText
      • -
      • SkipDeviceStatusPage
      • -
      • SkipUserStatusPage
      • -
      -
      [Defender CSP](defender-csp.md)

      Added new node (OfflineScan) in Windows 10, version 1803.

      -
      [UEFI CSP](uefi-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [Update CSP](update-csp.md)

      Added the following nodes in Windows 10, version 1803:

      -
        -
      • Rollback
      • -
      • Rollback/FeatureUpdate
      • -
      • Rollback/QualityUpdateStatus
      • -
      • Rollback/FeatureUpdateStatus
      • -
      -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following nodes in Windows 10, version 1803:

      -
        -
      • Status
      • -
      • ShellLauncher
      • -
      • StatusConfiguration
      • -
      -

      Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

      -

      Added SyncML examples.

      [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
        +
      • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
      • +
      • Updated the DDF and XSD file sections.
      • +
      [MultiSIM CSP](multisim-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [SecureAssessment CSP](secureassessment-csp.md)

      New CSP for Windows 10, version 1607

      [DiagnosticLog CSP](diagnosticlog-csp.md) +

      [DiagnosticLog DDF](diagnosticlog-ddf.md)

      Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

      +
        +
      • DeviceStateData
      • +
      • DeviceStateData/MdmConfiguration
      • +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added the following node in Windows 10, version 1803:

      +
      [Reboot CSP](reboot-csp.md)

      New CSP for Windows 10, version 1607

      [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

      New CSP for Windows 10, version 1607

      [VPNv2 CSP](vpnv2-csp.md)

      Added the following settings for Windows 10, version 1607

        -
      • MaintainProcessorArchitectureOnUpdate
      • -
      -
      [eUICCs CSP](euiccs-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    53. ProfileName/RouteList/routeRowId/ExclusionRoute
    54. +
    55. ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
    56. +
    57. ProfileName/DomainNameInformationList/dniRowId/Persistent
    58. +
    59. ProfileName/ProfileXML
    60. +
    61. ProfileName/DeviceCompliance/Enabled
    62. +
    63. ProfileName/DeviceCompliance/Sso
    64. +
    65. ProfileName/DeviceCompliance/Sso/Enabled
    66. +
    67. ProfileName/DeviceCompliance/Sso/IssuerHash
    68. +
    69. ProfileName/DeviceCompliance/Sso/Eku
    70. +
    71. ProfileName/NativeProfile/CryptographySuite
    72. +
    73. ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
    74. +
    75. ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
    76. +
    77. ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
    78. +
    79. ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
    80. +
    81. ProfileName/NativeProfile/CryptographySuite/DHGroup
    82. +
    83. ProfileName/NativeProfile/CryptographySuite/PfsGroup
    84. +
    85. ProfileName/NativeProfile/L2tpPsk
    86. +
      [Win32AppInventory CSP](win32appinventory-csp.md) +

      [Win32AppInventory DDF](win32appinventory-ddf-file.md)

      New CSP for Windows 10, version 1607.

      [SharedPC CSP](sharedpc-csp.md)

      New CSP for Windows 10, version 1607.

      [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

      New CSP for Windows 10, version 1607.

      [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

      Added new classes for Windows 10, version 1607.

      [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

      Topic renamed from "Enrollment UI".

      +

      Completely updated enrollment procedures and screenshots.

      [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) +

      [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

      Added the following new setting for Windows 10, version 1607:

        -
      • IsEnabled
      • -
      -
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    87. NextSession/HORMEnabled
    88. +
      [CertificateStore CSP](certificatestore-csp.md) +

      [CertificateStore DDF file](certificatestore-ddf-file.md)

      Added the following new settings in Windows 10, version 1607:

        -
      • OS/Mode
      • -
      -
      [AccountManagement CSP](accountmanagement-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    89. My/WSTEP/Renew/LastRenewalAttemptTime
    90. +
    91. My/WSTEP/Renew/RenewNow
    92. +

      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added the following new node and settings in Windows 10, version 1607, but not documented:

        -
      • UntrustedCertificates
      • +
      • Subscriptions
      • +
      • Subscriptions/SubscriptionId
      • +
      • Subscriptions/SubscriptionId/Status
      • +
      • Subscriptions/SubscriptionId/Name
      -
      [NetworkProxy CSP](\networkproxy--csp.md)

      Added the following node in Windows 10, version 1803:

      -
        -
      • ProxySettingsPerUser
      • -
      -
      [Accounts CSP](accounts-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

      Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

      -
      [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

      Added the DDF download of Windows 10, version 1803 configuration service providers.

      -
      -## What's new in Windows 10, version 1809 +## What’s new in MDM for Windows 10, version 1511 @@ -1385,175 +1437,173 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

      The following policies have been updated in the Policy CSP:

      +
        +
      • System/AllowLocation
      • +
      • Update/RequireDeferUpgrade
      • +
      +

      The following policies have been deprecated in the Policy CSP:

      +
        +
      • TextInput/AllowKoreanExtendedHanja
      • +
      • WiFi/AllowWiFiHotSpotReporting
      • +
      + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      New or updated topicItem Description
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies in Windows 10, version 1809:

      +

      New configuration service providers added in Windows 10, version 1511

        +
      • [AllJoynManagement CSP](alljoynmanagement-csp.md)
      • +
      • [Maps CSP](maps-csp.md)
      • +
      • [Reporting CSP](reporting-csp.md)
      • +
      • [SurfaceHub CSP](surfacehub-csp.md)
      • +
      • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
      • +

      New and updated policies in Policy CSP

      The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

        -
      • ApplicationManagement/LaunchAppAfterLogOn
      • -
      • ApplicationManagement/ScheduleForceRestartForUpdateFailures
      • -
      • Authentication/EnableFastFirstSignIn (Preview mode only)
      • -
      • Authentication/EnableWebSignIn (Preview mode only)
      • -
      • Authentication/PreferredAadTenantDomainName
      • -
      • Browser/AllowFullScreenMode
      • -
      • Browser/AllowPrelaunch
      • -
      • Browser/AllowPrinting
      • -
      • Browser/AllowSavingHistory
      • -
      • Browser/AllowSideloadingOfExtensions
      • -
      • Browser/AllowTabPreloading
      • -
      • Browser/AllowWebContentOnNewTabPage
      • -
      • Browser/ConfigureFavoritesBar
      • -
      • Browser/ConfigureHomeButton
      • -
      • Browser/ConfigureKioskMode
      • -
      • Browser/ConfigureKioskResetAfterIdleTimeout
      • -
      • Browser/ConfigureOpenMicrosoftEdgeWith
      • -
      • Browser/ConfigureTelemetryForMicrosoft365Analytics
      • -
      • Browser/PreventCertErrorOverrides
      • -
      • Browser/SetHomeButtonURL
      • -
      • Browser/SetNewTabPageURL
      • -
      • Browser/UnlockHomeButton
      • -
      • Defender/CheckForSignaturesBeforeRunningScan
      • -
      • Defender/DisableCatchupFullScan
      • -
      • Defender/DisableCatchupQuickScan
      • -
      • Defender/EnableLowCPUPriority
      • -
      • Defender/SignatureUpdateFallbackOrder
      • -
      • Defender/SignatureUpdateFileSharesSources
      • -
      • DeviceGuard/ConfigureSystemGuardLaunch
      • -
      • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
      • -
      • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
      • -
      • DeviceInstallation/PreventDeviceMetadataFromNetwork
      • -
      • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
      • -
      • DmaGuard/DeviceEnumerationPolicy
      • -
      • Experience/AllowClipboardHistory
      • -
      • Experience/DoNotSyncBrowserSettings
      • -
      • Experience/PreventUsersFromTurningOnBrowserSyncing
      • -
      • Kerberos/UPNNameHints
      • -
      • Privacy/AllowCrossDeviceClipboard
      • -
      • Privacy/DisablePrivacyExperience
      • -
      • Privacy/UploadUserActivities
      • -
      • Security/RecoveryEnvironmentAuthentication
      • -
      • System/AllowDeviceNameInDiagnosticData
      • -
      • System/ConfigureMicrosoft365UploadEndpoint
      • -
      • System/DisableDeviceDelete
      • -
      • System/DisableDiagnosticDataViewer
      • -
      • Storage/RemovableDiskDenyWriteAccess
      • -
      • TaskManager/AllowEndTask
      • -
      • Update/EngagedRestartDeadlineForFeatureUpdates
      • -
      • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
      • -
      • Update/EngagedRestartTransitionScheduleForFeatureUpdates
      • -
      • Update/SetDisablePauseUXAccess
      • -
      • Update/SetDisableUXWUAccess
      • -
      • WindowsDefenderSecurityCenter/DisableClearTpmButton
      • -
      • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
      • -
      • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
      • -
      • WindowsLogon/DontDisplayNetworkSelectionUI
      • +
      • Accounts/DomainNamesForEmailSync
      • +
      • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
      • +
      • Bluetooth/ServicesAllowedList
      • +
      • DataProtection/AllowAzureRMSForEDP
      • +
      • DataProtection/RevokeOnUnenroll
      • +
      • DeviceLock/DevicePasswordExpiration
      • +
      • DeviceLock/DevicePasswordHistory
      • +
      • TextInput/AllowInputPanel
      • +
      • Update/PauseDeferrals
      • +
      • Update/RequireDeferUpdate
      • +
      • Update/RequireUpdateApproval
      -
      [PassportForWork CSP](passportforwork-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

      -
      [Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

      Added new configuration service provider in Windows 10, version 1809.

      -
      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added S mode settings and SyncML examples in Windows 10, version 1809.

      -
      [SUPL CSP](supl-csp.md)

      Added 3 new certificate nodes in Windows 10, version 1809.

      -
      [Defender CSP](defender-csp.md)

      Added a new node Health/ProductStatus in Windows 10, version 1809.

      -
      [BitLocker CSP](bitlocker-csp.md)

      Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

      -
      [DevDetail CSP](devdetail-csp.md)

      Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

      -
      [Wifi CSP](wifi-csp.md)

      Added a new node WifiCost in Windows 10, version 1809.

      -
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [RemoteWipe CSP](remotewipe-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [TenantLockdown CSP](tenantlockdown-csp.md)

      Added new CSP in Windows 10, version 1809.

      -
      [Office CSP](office-csp.md)

      Added FinalStatus setting in Windows 10, version 1809.

      -

      Management tool for the Micosoft Store for Business

      New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

      Custom header for generic alert

      The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

      +MDM-GenericAlert: <AlertType1><AlertType2> +

      If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

      Alert message for slow client response

      When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

      +

      To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

      New node in DMClient CSP

      Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

      New nodes in EnterpriseModernAppManagement CSP

      Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

      +
        +
      • AppManagement/GetInventoryQuery
      • +
      • AppManagement/GetInventoryResults
      • +
      • .../PackageFamilyName/AppSettingPolicy/SettingValue
      • +
      • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
      • +
      • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
      • +
      • AppLicenses/StoreLicenses/LicenseID/RequesterID
      • +
      • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
      • +

      New nodes in EnterpriseExt CSP

      Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

      +
        +
      • DeviceCustomData (CustomID, CustomeString)
      • +
      • Brightness (Default, MaxAuto)
      • +
      • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
      • +

      New node in EnterpriseExtFileSystem CSP

      Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

      New nodes in PassportForWork CSP

      Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

      +
        +
      • TenantId/Policies/PINComplexity/History
      • +
      • TenantId/Policies/PINComplexity/Expiration
      • +
      • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
      • +
      • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
      • +
      • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
      • +

      Updated EnterpriseAssignedAccess CSP

      Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

      +
        +
      • In AssignedAccessXML node, added new page settings and quick action settings.
      • +
      • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
      • +
      • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
      • +

      New nodes in the DevDetail CSP

      Here are the changes to the [DevDetail CSP](devdetail-csp.md):

      +
        +
      • Added TotalStore and TotalRAM settings.
      • +
      • Added support for Replace command for the DeviceName setting.
      • +

      Handling large objects

      Added support for the client to handle uploading of large objects to the server.

      - ## Breaking changes and known issues -### Get command inside an atomic command is not supported +### Get command inside an atomic command is not supported In Windows 10, a Get command inside an atomic command is not supported. This was allowed in Windows Phone 8 and Windows Phone 8.1. -### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 +### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 During an upgrade from Windows 8.1 to Windows 10, the notification channel URI information is not preserved. In addition, the MDM client loses the PFN, AppID, and client secret. After upgrading to Windows 10, you should call MDM\_WNSConfiguration class to recreate the notification channel URI. -### Apps installed using WMI classes are not removed +### Apps installed using WMI classes are not removed Applications installed using WMI classes are not removed when the MDM account is removed from device. -### Passing CDATA in SyncML does not work +### Passing CDATA in SyncML does not work Passing CDATA in data in SyncML to ConfigManager and CSPs does not work in Windows 10. It worked in Windows Phone 8. -### SSL settings in IIS server for SCEP must be set to "Ignore" +### SSL settings in IIS server for SCEP must be set to "Ignore" The certificate setting under "SSL Settings" in the IIS server for SCEP must be set to "Ignore" in Windows 10. In Windows Phone 8.1, when you set the client certificate to "Accept," it works fine. ![ssl settings](images/ssl-settings.png) -### MDM enrollment fails on the mobile device when traffic is going through proxy +### MDM enrollment fails on the mobile device when traffic is going through proxy When the mobile device is configured to use a proxy that requires authentication, the enrollment will fail. To work around this issue, the user can use a proxy that does not require authentication or remove the proxy setting from the connected network. -### Server-initiated unenrollment failure +### Server-initiated unenrollment failure Server-initiated unenrollment for a device enrolled by adding a work account silently fails leaving the MDM account active. MDM policies and resources are still in place and the client can continue to sync with the server. Remote server unenrollment is disabled for mobile devices enrolled via Azure Active Directory Join. It returns an error message to the server. The only way to remove enrollment for a mobile device that is Azure AD joined is by remotely wiping the device. -### Certificates causing issues with Wi-Fi and VPN +### Certificates causing issues with Wi-Fi and VPN Currently in Windows 10, version 1511, when using the ClientCertificateInstall to install certificates to the device store and the user store and both certificates are sent to the device in the same MDM payload, the certificate intended for the device store will also get installed in the user store. This may cause issues with Wi-Fi or VPN when choosing the correct certificate to establish a connection. We are working to fix this issue. -### Version information for mobile devices +### Version information for mobile devices The software version information from **DevDetail/SwV** does not match the version in **Settings** under **System/About**. -### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues +### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues - When you upgrade Windows Phone 8.1 devices to Windows 10 Mobile using ApplicationRestrictions with a list of allowed apps, some Windows inbox apps get blocked causing unexpected behavior. To work around this issue, you must include the [inbox apps](applocker-csp.md#inboxappsandcomponents) that you need to your list of allowed apps. @@ -1573,7 +1623,7 @@ The software version information from **DevDetail/SwV** does not match the versi No workaround is available at this time. An OS update to fix this issue is coming soon. -### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 +### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 Applies only to phone prior to build 10586.218: When ApplicationManagement/ApplicationRestrictions policy is deployed to Windows 10 Mobile, installation and update of apps dependent on Microsoft Frameworks may get blocked with error 0x80073CF9. To work around this issue, you must include the Microsoft Framework Id to your list of allowed apps. @@ -1581,7 +1631,7 @@ Applies only to phone prior to build 10586.218: When ApplicationManagement/Appli ``` -### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile +### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile In your deployment, if you have multiple certificates provisioned on the device and the Wi-Fi profile provisioned does not have a strict filtering criteria, you may see connection failures when connecting to Wi-Fi. The solution is to ensure that the Wi-Fi profile provisioned has strict filtering criteria such that it matches only one certificate. @@ -1754,26 +1804,49 @@ Alternatively you can use the following procedure to create an EAP Configuration >You can also set all the other applicable EAP Properties through this UI as well. A guide for what these properties mean can be found in the [Extensible Authentication Protocol (EAP) Settings for Network Access](https://technet.microsoft.com/library/hh945104.aspx) topic. -### Remote PIN reset not supported in Azure Active Directory joined mobile devices +### Remote PIN reset not supported in Azure Active Directory joined mobile devices In Windows 10 Mobile, remote PIN reset in Azure AD joined devices are not supported. Devices are wiped when you issue a remote PIN reset command using the RemoteLock CSP. -### MDM client will immediately check-in with the MDM server after client renews WNS channel URI +### MDM client will immediately check-in with the MDM server after client renews WNS channel URI Starting in Windows 10, after the MDM client automatically renews the WNS channel URI, the MDM client will immediately check-in with the MDM server. Henceforth, for every MDM client check-in, the MDM server should send a GET request for "ProviderID/Push/ChannelURI" to retrieve the latest channel URI and compare it with the existing channel URI; then update the channel URI if necessary. -### User provisioning failure in Azure Active Directory joined Windows 10 PC +### User provisioning failure in Azure Active Directory joined Windows 10 PC In Azure AD joined Windows 10 PC, provisioning /.User resources fails when the user is not logged in as an Azure AD user. If you attempt to join Azure AD from **Settings** > **System** > **About** user interface, make sure to log off and log on with Azure AD credentials to get your organizational configuration from your MDM server. This behavior is by design. -### Requirements to note for VPN certificates also used for Kerberos Authentication +### Requirements to note for VPN certificates also used for Kerberos Authentication If you want to use the certificate used for VPN authentication also for Kerberos authentication (required if you need access to on-premises resources using NTLM or Kerberos), the user's certificate must meet the requirements for smart card certificate, the Subject field should contain the DNS domain name in the DN or the SAN should contain a fully qualified UPN so that the DC can be located from the DNS registrations. If certificates that do not meet these requirements are used for VPN, users may fail to access resources that require Kerberos authentication. This issue primarily impacts Windows Phone. -### Device management agent for the push-button reset is not working +### Device management agent for the push-button reset is not working The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware/commercialize/manufacture/desktop/push-button-reset-overview) keeps the registry settings for OMA DM sessions, but deletes the task schedules. The client enrollment is retained, but it never syncs with the MDM service. +## Frequently Asked Questions + + +###**Can there be more than 1 MDM server to enroll and manage devices in Windows 10?** +No. Only one MDM is allowed. + +###**How do I set the maximum number of Azure Active Directory joined devices per user?** +1. Login to the portal as tenant admin: https://manage.windowsazure.com. +2. Click Active Directory on the left pane. +3. Choose your tenant. +4. Click **Configure**. +5. Set quota to unlimited. + + ![aad maximum joined devices](images/faq-max-devices.png) +  + +###**What is dmwappushsvc?** + +Entry | Description +--------------- | -------------------- +What is dmwappushsvc? | It is a Windows service that ships in Windows 10 operating system as a part of the windows management platform. It is used internally by the operating system as a queue for categorizing and processing all WAP messages, which include Windows management messages, MMS, NabSync, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server. | +What data is handled by dmwappushsvc? | It is a component handling the internal workings of the management platform and involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further: MMS, NabSync, SI/SL. | +How do I turn if off? | The service can be stopped from the "Services" console on the device (Start > Run > services.msc). However, since this is a component part of the OS and required for the proper functioning of the device, we strongly recommend not to do this. | ## Change history in MDM documentation @@ -2716,35 +2789,3 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware - -  - -## FAQ - - -**Can there be more than 1 MDM server to enroll and manage devices in Windows 10?** -No. Only one MDM is allowed. - -**How do I set the maximum number of Azure Active Directory joined devices per user?** -1. Login to the portal as tenant admin: https://manage.windowsazure.com. -2. Click Active Directory on the left pane. -3. Choose your tenant. -4. Click **Configure**. -5. Set quota to unlimited. - - ![aad maximum joined devices](images/faq-max-devices.png) -  - -**What is dmwappushsvc?** - -Entry | Description ---------------- | -------------------- -What is dmwappushsvc? | It is a Windows service that ships in Windows 10 operating system as a part of the windows management platform. It is used internally by the operating system as a queue for categorizing and processing all WAP messages, which include Windows management messages, MMS, NabSync, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server. | -What data is handled by dmwappushsvc? | It is a component handling the internal workings of the management platform and involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further: MMS, NabSync, SI/SL. | -How do I turn if off? | The service can be stopped from the "Services" console on the device (Start > Run > services.msc). However, since this is a component part of the OS and required for the proper functioning of the device, we strongly recommend not to do this. | - - - - - - From 28aa34e1f5f7c427bf87c68cd5e0cb22b6f780b1 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 16 May 2019 12:12:50 -0700 Subject: [PATCH 387/737] Updated what's new --- .../mdm/new-in-windows-mdm-enrollment-management.md | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index 900a9638a9..a7d296a43b 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -89,7 +89,7 @@ For details about Microsoft mobile device management protocols for Windows 10 s [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies in Windows 10, version 1903:

        -
      • [DeliveryOptimization/DODelayCacheServerFallbackBackground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground
      • +
      • [DeliveryOptimization/DODelayCacheServerFallbackBackground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground)
      • [DeliveryOptimization/DODelayCacheServerFallbackForeground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackforeground)
      • [Experience/ShowLockOnUserTile](policy-csp-experience.md#experience-showlockonusertile)
      • [Power/EnergySaverBatteryThresholdOnBattery](policy-csp-power.md#power-energysaverbatterythresholdonbattery)
      • @@ -113,9 +113,6 @@ For details about Microsoft mobile device management protocols for Windows 10 s
      • [WindowsLogon/EnableFirstLogonAnimation](policy-csp-windowslogon.md#windowslogon-enablefirstlogonanimation)
      - -

      Added new CSP in Windows 10, version 1903.

      - From ef4cec8d3bebfb570f8671bb59ddd12890efffc8 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Thu, 16 May 2019 12:26:50 -0700 Subject: [PATCH 388/737] draft --- windows/whats-new/whats-new-windows-10-version-1903.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/windows/whats-new/whats-new-windows-10-version-1903.md b/windows/whats-new/whats-new-windows-10-version-1903.md index 4ad9128ae2..46d03eb41f 100644 --- a/windows/whats-new/whats-new-windows-10-version-1903.md +++ b/windows/whats-new/whats-new-windows-10-version-1903.md @@ -27,12 +27,15 @@ The following Windows Autopilot features are available in Windows 10, version 19 - [Windows Autopilot for white glove deployment](https://docs.microsoft.com/windows/deployment/windows-autopilot/white-glove) enables partners or IT staff to pre-provision devices to be fully configured and business ready for your users. - The Intune [enrollment status page](https://docs.microsoft.com/intune/windows-enrollment-status) (ESP) now tracks Intune Management Extensions, and System Center Configuration Manager and Office installs​. -- Cortana voiceover: [Cortana voiceover](https://docs.microsoft.com/windows-hardware/customize/desktop/cortana-voice-support) is disabled by default for Windows 10 Pro and above. +- Cortana voiceover: [Cortana voiceover](https://docs.microsoft.com/windows-hardware/customize/desktop/cortana-voice-support) and speech recognition during OOBE is DISABLED by default for all Windows 10 Pro variants, including Education, Enterprise, & G. + + - Self-updating Autopilot: You can enable new Windows Autopilot functionality without updating Windows.​ ### Windows 10 Subscription Activation Windows 10 Education support has been added to Windows 10 Subscription Activation. + With Windows 10, version 1903, you can step-up from Windows 10 Pro Education to the enterprise-grade edition for educational institutions – Windows 10 Education. For more information, see [Windows 10 Subscription Activation](https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation). ### SetupDiag From 3b41700ac303962aca1149d250c8aef11c09f49d Mon Sep 17 00:00:00 2001 From: Justin Hall Date: Thu, 16 May 2019 12:43:59 -0700 Subject: [PATCH 389/737] edits to title --- ...tion-in-windows-defender-application-control-policy.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md index 4e19b9193b..09fb275743 100644 --- a/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md +++ b/windows/security/threat-protection/windows-defender-application-control/allow-com-object-registration-in-windows-defender-application-control-policy.md @@ -1,16 +1,16 @@ --- -title: Windows Defender Application Control path-based rules (Windows 10) -description: Windows Defender Application Control restricts which applications users are allowed to run and the code that runs in the system core. +title: Allow COM object registration in a Windows Defender Application Control policy (Windows 10) +description: You can allow COM object registration in a Windows Defender Application Control policy. ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library ms.pagetype: security ms.localizationpriority: medium author: jsuther1974 -ms.date: 05/14/2019 +ms.date: 05/16/2019 --- -# COM Whitelisting +# Allow COM object registration in a Windows Defender Application Control policy **Applies to:** From 8806b28bd01b16e346170ee9dfe2480df91c1346 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Thu, 16 May 2019 13:32:49 -0700 Subject: [PATCH 390/737] Added dev comments --- ...ew-in-windows-mdm-enrollment-management.md | 2047 +++++++++-------- .../mdm/policy-csp-search.md | 2 + 2 files changed, 1043 insertions(+), 1006 deletions(-) diff --git a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md index b7d977b310..28fdfc24a3 100644 --- a/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md +++ b/windows/client-management/mdm/new-in-windows-mdm-enrollment-management.md @@ -10,45 +10,50 @@ ms.topic: article ms.prod: w10 ms.technology: windows author: MariciaAlforque -ms.date: 12/06/2018 +ms.date: 05/15/2019 --- -# What's new in MDM enrollment and management +# What's new in mobile device enrollment and management This topic provides information about what's new and breaking changes in Windows 10 mobile device management (MDM) enrollment and management experience across all Windows 10 devices. -For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +For details about Microsoft mobile device management protocols for Windows 10 see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). -## In this section +- **What’s new in MDM for Windows 10 versions** + - [What’s new in MDM for Windows 10, version 1903](#whats-new-in-mdm-for-windows-10-version-1903) + - [What’s new in MDM for Windows 10, version 1809](#whats-new-in-mdm-for-windows-10-version-1809) + - [What’s new in MDM for Windows 10, version 1803](#whats-new-in-mdm-for-windows-10-version-1803) + - [What’s new in MDM for Windows 10, version 1709](#whats-new-in-mdm-for-windows-10-version-1709) + - [What’s new in MDM for Windows 10, version 1703](#whats-new-in-mdm-for-windows-10-version-1703) + - [What’s new in MDM for Windows 10, version 1607](#whats-new-in-mdm-for-windows-10-version-1607) + - [What’s new in MDM for Windows 10, version 1511](#whats-new-in-mdm-for-windows-10-version-1511) -- [What's new in MDM enrollment and management](#whats-new-in-mdm-enrollment-and-management) - - [In this section](#in-this-section) - - [What's new in Windows 10, version 1511](#a-href%22%22-id%22whatsnew%22awhats-new-in-windows-10-version-1511) - - [What's new in Windows 10, version 1607](#a-href%22%22-id%22whatsnew1607%22awhats-new-in-windows-10-version-1607) - - [What's new in Windows 10, version 1703](#a-href%22%22-id%22whatsnew10%22awhats-new-in-windows-10-version-1703) - - [What's new in Windows 10, version 1709](#a-href%22%22-id%22whatsnew1709%22awhats-new-in-windows-10-version-1709) - - [What's new in Windows 10, version 1803](#a-href%22%22-id%22whatsnew1803%22awhats-new-in-windows-10-version-1803) - - [What's new in Windows 10, version 1809](#a-href%22%22-id%22whatsnew1809%22awhats-new-in-windows-10-version-1809) - - [Breaking changes and known issues](#breaking-changes-and-known-issues) - - [Get command inside an atomic command is not supported](#a-href%22%22-id%22getcommand%22aget-command-inside-an-atomic-command-is-not-supported) - - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#a-href%22%22-id%22notification%22anotification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) - - [Apps installed using WMI classes are not removed](#a-href%22%22-id%22appsnotremoved%22aapps-installed-using-wmi-classes-are-not-removed) - - [Passing CDATA in SyncML does not work](#a-href%22%22-id%22cdata%22apassing-cdata-in-syncml-does-not-work) - - [SSL settings in IIS server for SCEP must be set to "Ignore"](#a-href%22%22-id%22sslsettings%22assl-settings-in-iis-server-for-scep-must-be-set-to-%22ignore%22) - - [MDM enrollment fails on the mobile device when traffic is going through proxy](#a-href%22%22-id%22enrollmentviaproxy%22amdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) - - [Server-initiated unenrollment failure](#a-href%22%22-id%22unenrollment%22aserver-initiated-unenrollment-failure) - - [Certificates causing issues with Wi-Fi and VPN](#a-href%22%22-id%22certissues%22acertificates-causing-issues-with-wi-fi-and-vpn) - - [Version information for mobile devices](#a-href%22%22-id%22versioninformation%22aversion-information-for-mobile-devices) - - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#a-href%22%22-id%22whitelist%22aupgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) - - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#a-href%22%22-id%22frameworks%22aapps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) - - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#a-href%22%22-id%22wificertissue%22amultiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) - - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#a-href%22%22-id%22remote%22aremote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) - - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#a-href%22%22-id%22renewwns%22amdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) - - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#a-href%22%22-id%22userprovisioning%22auser-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) - - [Requirements to note for VPN certificates also used for Kerberos Authentication](#a-href%22%22-id%22kerberos%22arequirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) - - [Device management agent for the push-button reset is not working](#a-href%22%22-id%22pushbuttonreset%22adevice-management-agent-for-the-push-button-reset-is-not-working) - - [Change history in MDM documentation](#change-history-in-mdm-documentation) +- **Breaking changes and known issues** + - [Get command inside an atomic command is not supported](#get-command-inside-an-atomic-command-is-not-supported) + - [Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10](#notification-channel-uri-not-preserved-during-upgrade-from-windows-81-to-windows-10) + - [Apps installed using WMI classes are not removed](#apps-installed-using-wmi-classes-are-not-removed) + - [Passing CDATA in SyncML does not work](#passing-cdata-in-syncml-does-not-work) + - [SSL settings in IIS server for SCEP must be set to "Ignore"](#ssl-settings-in-iis-server-for-scep-must-be-set-to-ignore) + - [MDM enrollment fails on the mobile device when traffic is going through proxy](#mdm-enrollment-fails-on-the-mobile-device-when-traffic-is-going-through-proxy) + - [Server-initiated unenrollment failure](#server-initiated-unenrollment-failure) + - [Certificates causing issues with Wi-Fi and VPN](#certificates-causing-issues-with-wi-fi-and-vpn) + - [Version information for mobile devices](#version-information-for-mobile-devices) + - [Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues](#upgrading-windows-phone-81-devices-with-app-whitelisting-using-applicationrestriction-policy-has-issues) + - [Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218](#apps-dependent-on-microsoft-frameworks-may-get-blocked-in-phones-prior-to-build-10586218) + - [Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile](#multiple-certificates-might-cause-wi-fi-connection-instabilities-in-windows-10-mobile) + - [Remote PIN reset not supported in Azure Active Directory joined mobile devices](#remote-pin-reset-not-supported-in-azure-active-directory-joined-mobile-devices) + - [MDM client will immediately check-in with the MDM server after client renews WNS channel URI](#mdm-client-will-immediately-check-in-with-the-mdm-server-after-client-renews-wns-channel-uri) + - [User provisioning failure in Azure Active Directory joined Windows 10 PC](#user-provisioning-failure-in-azure-active-directory-joined-windows-10-pc) + - [Requirements to note for VPN certificates also used for Kerberos Authentication](#requirements-to-note-for-vpn-certificates-also-used-for-kerberos-authentication) + - [Device management agent for the push-button reset is not working](#device-management-agent-for-the-push-button-reset-is-not-working) + +- **Frequently Asked Questions** + - [Can there be more than 1 MDM server to enroll and manage devices in Windows 10?](#can-there-be-more-than-1-mdm-server-to-enroll-and-manage-devices-in-windows-10) + - [How do I set the maximum number of Azure Active Directory joined devices per user?](#how-do-i-set-the-maximum-number-of-azure-active-directory-joined-devices-per-user) + - [What is dmwappushsvc?](#what-is-dmwappushsvc) + +- **Change history in MDM documentation** - [February 2019](#february-2019) - [January 2019](#january-2019) - [December 2018](#december-2018) @@ -66,10 +71,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s - [October 2017](#october-2017) - [September 2017](#september-2017) - [August 2017](#august-2017) - - [FAQ](#faq) - -## What's new in Windows 10, version 1511 +## What’s new in MDM for Windows 10, version 1903 @@ -77,130 +80,44 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +
      ItemNew or updated topic Description

      New configuration service providers added in Windows 10, version 1511

        -
      • [AllJoynManagement CSP](alljoynmanagement-csp.md)
      • -
      • [Maps CSP](maps-csp.md)
      • -
      • [Reporting CSP](reporting-csp.md)
      • -
      • [SurfaceHub CSP](surfacehub-csp.md)
      • -
      • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
      • -

      New and updated policies in Policy CSP

      The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

      +
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies in Windows 10, version 1903:

        -
      • Accounts/DomainNamesForEmailSync
      • -
      • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
      • -
      • Bluetooth/ServicesAllowedList
      • -
      • DataProtection/AllowAzureRMSForEDP
      • -
      • DataProtection/RevokeOnUnenroll
      • -
      • DeviceLock/DevicePasswordExpiration
      • -
      • DeviceLock/DevicePasswordHistory
      • -
      • TextInput/AllowInputPanel
      • -
      • Update/PauseDeferrals
      • -
      • Update/RequireDeferUpdate
      • -
      • Update/RequireUpdateApproval
      • +
      • [DeliveryOptimization/DODelayCacheServerFallbackBackground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackbackground)
      • +
      • [DeliveryOptimization/DODelayCacheServerFallbackForeground](policy-csp-deliveryoptimization.md#deliveryoptimization-dodelaycacheserverfallbackforeground)
      • +
      • [Experience/ShowLockOnUserTile](policy-csp-experience.md#experience-showlockonusertile)
      • +
      • [Power/EnergySaverBatteryThresholdOnBattery](policy-csp-power.md#power-energysaverbatterythresholdonbattery)
      • +
      • [Power/EnergySaverBatteryThresholdPluggedIn](policy-csp-power.md#power-energysaverbatterythresholdpluggedin)
      • +
      • [Power/SelectLidCloseActionOnBattery](policy-csp-power.md#power-selectlidcloseactiononbattery)
      • +
      • [Power/SelectLidCloseActionPluggedIn](policy-csp-power.md#power-selectlidcloseactionpluggedin)
      • +
      • [Power/SelectPowerButtonActionOnBattery](policy-csp-power.md#power-selectpowerbuttonactiononbattery)
      • +
      • [Power/SelectPowerButtonActionPluggedIn](policy-csp-power.md#power-selectpowerbuttonactionpluggedin)
      • +
      • [Power/SelectSleepButtonActionOnBattery](policy-csp-power.md#power-selectsleepbuttonactiononbattery)
      • +
      • [Power/SelectSleepButtonActionPluggedIn](policy-csp-power.md#power-selectsleepbuttonactionpluggedin)
      • +
      • [Power/TurnOffHybridSleepOnBattery](policy-csp-power.md#power-turnoffhybridsleeponbattery)
      • +
      • [Power/TurnOffHybridSleepPluggedIn](policy-csp-power.md#power-turnoffhybridsleeppluggedin)
      • +
      • [Power/UnattendedSleepTimeoutOnBattery](policy-csp-power.md#power-unattendedsleeptimeoutonbattery)
      • +
      • [Power/UnattendedSleepTimeoutPluggedIn](policy-csp-power.md#power-unattendedsleeptimeoutpluggedin)
      • +
      • [Search/AllowFindMyFiles](policy-csp-search.md#allowfindmyfiles)
      • +
      • [Update/AutomaticMaintenanceWakeUp](policy-csp-update.md#update-automaticmaintenancewakeup)
      • +
      • [Update/ConfigureDeadlineForFeatureUpdates](policy-csp-update.md#update-configuredeadlineforfeatureupdates)
      • +
      • [Update/ConfigureDeadlineForQualityUpdates](policy-csp-update.md#update-configuredeadlineforqualityupdates)
      • +
      • [Update/ConfigureDeadlineGracePeriod](policy-csp-update.md#update-configuredeadlinegraceperiod)
      • +
      • [WindowsLogon/AllowAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-allowautomaticrestartsignon)
      • +
      • [WindowsLogon/ConfigAutomaticRestartSignOn](policy-csp-windowslogon.md#windowslogon-configautomaticrestartsignon)
      • +
      • [WindowsLogon/EnableFirstLogonAnimation](policy-csp-windowslogon.md#windowslogon-enablefirstlogonanimation)
      -

      The following policies have been updated in the Policy CSP:

      -
        -
      • System/AllowLocation
      • -
      • Update/RequireDeferUpgrade
      • -
      -

      The following policies have been deprecated in the Policy CSP:

      -
        -
      • TextInput/AllowKoreanExtendedHanja
      • -
      • WiFi/AllowWiFiHotSpotReporting
      • -

      Management tool for the Micosoft Store for Business

      New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

      Custom header for generic alert

      The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

      -MDM-GenericAlert: <AlertType1><AlertType2> -

      If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

      Alert message for slow client response

      When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

      -

      To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

      New node in DMClient CSP

      Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

      New nodes in EnterpriseModernAppManagement CSP

      Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

      -
        -
      • AppManagement/GetInventoryQuery
      • -
      • AppManagement/GetInventoryResults
      • -
      • .../PackageFamilyName/AppSettingPolicy/SettingValue
      • -
      • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
      • -
      • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
      • -
      • AppLicenses/StoreLicenses/LicenseID/RequesterID
      • -
      • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
      • -

      New nodes in EnterpriseExt CSP

      Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

      -
        -
      • DeviceCustomData (CustomID, CustomeString)
      • -
      • Brightness (Default, MaxAuto)
      • -
      • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
      • -

      New node in EnterpriseExtFileSystem CSP

      Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

      New nodes in PassportForWork CSP

      Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

      -
        -
      • TenantId/Policies/PINComplexity/History
      • -
      • TenantId/Policies/PINComplexity/Expiration
      • -
      • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
      • -
      • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
      • -
      • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
      • -

      Updated EnterpriseAssignedAccess CSP

      Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

      -
        -
      • In AssignedAccessXML node, added new page settings and quick action settings.
      • -
      • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
      • -
      • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
      • -

      New nodes in the DevDetail CSP

      Here are the changes to the [DevDetail CSP](devdetail-csp.md):

      -
        -
      • Added TotalStore and TotalRAM settings.
      • -
      • Added support for Replace command for the DeviceName setting.
      • -

      Handling large objects

      Added support for the client to handle uploading of large objects to the server.

      - -## What's new in Windows 10, version 1607 +## What’s new in MDM for Windows 10, version 1809 @@ -209,309 +126,574 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - - - - - - - - - - - + - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      ItemNew or updated topic Description

      Sideloading of apps

      Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

      New value for [NodeCache CSP](nodecache-csp.md)

      In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

      [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

      New CSP.

      [Policy CSP](policy-configuration-service-provider.md)

      Removed the following policies:

      +

      Added the following new policies in Windows 10, version 1809:

        -
      • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • -
      • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
      • -
      • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
      • -
      • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
      • +
      • ApplicationManagement/LaunchAppAfterLogOn
      • +
      • ApplicationManagement/ScheduleForceRestartForUpdateFailures
      • +
      • Authentication/EnableFastFirstSignIn (Preview mode only)
      • +
      • Authentication/EnableWebSignIn (Preview mode only)
      • +
      • Authentication/PreferredAadTenantDomainName
      • +
      • Browser/AllowFullScreenMode
      • +
      • Browser/AllowPrelaunch
      • +
      • Browser/AllowPrinting
      • +
      • Browser/AllowSavingHistory
      • +
      • Browser/AllowSideloadingOfExtensions
      • +
      • Browser/AllowTabPreloading
      • +
      • Browser/AllowWebContentOnNewTabPage
      • +
      • Browser/ConfigureFavoritesBar
      • +
      • Browser/ConfigureHomeButton
      • +
      • Browser/ConfigureKioskMode
      • +
      • Browser/ConfigureKioskResetAfterIdleTimeout
      • +
      • Browser/ConfigureOpenMicrosoftEdgeWith
      • +
      • Browser/ConfigureTelemetryForMicrosoft365Analytics
      • +
      • Browser/PreventCertErrorOverrides
      • +
      • Browser/SetHomeButtonURL
      • +
      • Browser/SetNewTabPageURL
      • +
      • Browser/UnlockHomeButton
      • +
      • Defender/CheckForSignaturesBeforeRunningScan
      • +
      • Defender/DisableCatchupFullScan
      • +
      • Defender/DisableCatchupQuickScan
      • +
      • Defender/EnableLowCPUPriority
      • +
      • Defender/SignatureUpdateFallbackOrder
      • +
      • Defender/SignatureUpdateFileSharesSources
      • +
      • DeviceGuard/ConfigureSystemGuardLaunch
      • +
      • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
      • +
      • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
      • +
      • DeviceInstallation/PreventDeviceMetadataFromNetwork
      • +
      • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
      • +
      • DmaGuard/DeviceEnumerationPolicy
      • +
      • Experience/AllowClipboardHistory
      • +
      • Experience/DoNotSyncBrowserSettings
      • +
      • Experience/PreventUsersFromTurningOnBrowserSyncing
      • +
      • Kerberos/UPNNameHints
      • +
      • Privacy/AllowCrossDeviceClipboard
      • +
      • Privacy/DisablePrivacyExperience
      • +
      • Privacy/UploadUserActivities
      • +
      • Security/RecoveryEnvironmentAuthentication
      • +
      • System/AllowDeviceNameInDiagnosticData
      • +
      • System/ConfigureMicrosoft365UploadEndpoint
      • +
      • System/DisableDeviceDelete
      • +
      • System/DisableDiagnosticDataViewer
      • +
      • Storage/RemovableDiskDenyWriteAccess
      • +
      • TaskManager/AllowEndTask
      • +
      • Update/EngagedRestartDeadlineForFeatureUpdates
      • +
      • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
      • +
      • Update/EngagedRestartTransitionScheduleForFeatureUpdates
      • +
      • Update/SetDisablePauseUXAccess
      • +
      • Update/SetDisableUXWUAccess
      • +
      • WindowsDefenderSecurityCenter/DisableClearTpmButton
      • +
      • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
      • +
      • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
      • +
      • WindowsLogon/DontDisplayNetworkSelectionUI
      -

      Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

      -
        -
      • Windows 10 Pro
      • -
      • Windows 10 Enterprise
      • -
      • Windows 10 Education
      • -
      -

      Added the following new policies:

      -
        -
      • AboveLock/AllowCortanaAboveLock
      • -
      • ApplicationManagement/DisableStoreOriginatedApps
      • -
      • Authentication/AllowSecondaryAuthenticationDevice
      • -
      • Bluetooth/AllowPrepairing
      • -
      • Browser/AllowExtensions
      • -
      • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
      • -
      • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
      • -
      • DeliveryOptimization/DOAbsoluteMaxCacheSize
      • -
      • DeliveryOptimization/DOMaxDownloadBandwidth
      • -
      • DeliveryOptimization/DOMinBackgroundQoS
      • -
      • DeliveryOptimization/DOModifyCacheDrive
      • -
      • DeliveryOptimization/DOMonthlyUploadDataCap
      • -
      • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
      • -
      • DeviceLock/EnforceLockScreenAndLogonImage
      • -
      • DeviceLock/EnforceLockScreenProvider
      • -
      • Defender/PUAProtection
      • -
      • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
      • -
      • Experience/AllowWindowsSpotlight
      • -
      • Experience/ConfigureWindowsSpotlightOnLockScreen
      • -
      • Experience/DoNotShowFeedbackNotifications
      • -
      • Licensing/AllowWindowsEntitlementActivation
      • -
      • Licensing/DisallowKMSClientOnlineAVSValidation
      • -
      • LockDown/AllowEdgeSwipe
      • -
      • Maps/EnableOfflineMapsAutoUpdate
      • -
      • Maps/AllowOfflineMapsDownloadOverMeteredConnection
      • -
      • Messaging/AllowMessageSync
      • -
      • NetworkIsolation/EnterpriseCloudResources
      • -
      • NetworkIsolation/EnterpriseInternalProxyServers
      • -
      • NetworkIsolation/EnterpriseIPRange
      • -
      • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
      • -
      • NetworkIsolation/EnterpriseNetworkDomainNames
      • -
      • NetworkIsolation/EnterpriseProxyServers
      • -
      • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
      • -
      • NetworkIsolation/NeutralResources
      • -
      • Notifications/DisallowNotificationMirroring
      • -
      • Privacy/DisableAdvertisingId
      • -
      • Privacy/LetAppsAccessAccountInfo
      • -
      • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCalendar
      • -
      • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory
      • -
      • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessCamera
      • -
      • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessContacts
      • -
      • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessEmail
      • -
      • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessLocation
      • -
      • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMessaging
      • -
      • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone
      • -
      • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessMotion
      • -
      • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessNotifications
      • -
      • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessPhone
      • -
      • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessRadios
      • -
      • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices
      • -
      • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
      • -
      • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices
      • -
      • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
      • -
      • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
      • -
      • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
      • -
      • Settings/AllowEditDeviceName
      • -
      • Speech/AllowSpeechModelUpdate
      • -
      • System/TelemetryProxy
      • -
      • Update/ActiveHoursStart
      • -
      • Update/ActiveHoursEnd
      • -
      • Update/AllowMUUpdateService
      • -
      • Update/BranchReadinessLevel
      • -
      • Update/DeferFeatureUpdatesPeriodInDays
      • -
      • Update/DeferQualityUpdatesPeriodInDays
      • -
      • Update/ExcludeWUDriversInQualityUpdate
      • -
      • Update/PauseFeatureUpdates
      • -
      • Update/PauseQualityUpdates
      • -
      • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
      • -
      • WindowsInkWorkspace/AllowWindowsInkWorkspace
      • -
      • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
      • -
      • WirelessDisplay/AllowProjectionToPC
      • -
      • WirelessDisplay/RequirePinForPairing
      • -
      -

      Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

      -

      Updated DeliveryOptimization/DODownloadMode to add new values.

      -

      Updated Experience/AllowCortana description to clarify what each supported value does.

      -

      Updated Security/AntiTheftMode description to clarify what each supported value does.

      [PassportForWork CSP](passportforwork-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

      +
      [Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

      Added new configuration service provider in Windows 10, version 1809.

      +
      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added S mode settings and SyncML examples in Windows 10, version 1809.

      +
      [SUPL CSP](supl-csp.md)

      Added 3 new certificate nodes in Windows 10, version 1809.

      +
      [Defender CSP](defender-csp.md)

      Added a new node Health/ProductStatus in Windows 10, version 1809.

      +
      [BitLocker CSP](bitlocker-csp.md)

      Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

      +
      [DevDetail CSP](devdetail-csp.md)

      Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

      +
      [Wifi CSP](wifi-csp.md)

      Added a new node WifiCost in Windows 10, version 1809.

      +
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [RemoteWipe CSP](remotewipe-csp.md)

      Added new settings in Windows 10, version 1809.

      +
      [TenantLockdown CSP](tenantlockdown-csp.md)

      Added new CSP in Windows 10, version 1809.

      +
      [Office CSP](office-csp.md)

      Added FinalStatus setting in Windows 10, version 1809.

      +
      + +## What’s new in MDM for Windows 10, version 1803 + + ++++ + + + + + + + + + + + + - - + - - - - - - + + + + + + + - +
    93. Rollback
    94. +
    95. Rollback/FeatureUpdate
    96. +
    97. Rollback/QualityUpdateStatus
    98. +
    99. Rollback/FeatureUpdateStatus
    100. + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

      Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

      + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      New or updated topicDescription
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1803:

      +
        +
      • ApplicationDefaults/EnableAppUriHandlers
      • +
      • ApplicationManagement/MSIAllowUserControlOverInstall
      • +
      • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
      • +
      • Bluetooth/AllowPromptedProximalConnections
      • +
      • Browser/AllowConfigurationUpdateForBooksLibrary
      • +
      • Browser/AlwaysEnableBooksLibrary
      • +
      • Browser/EnableExtendedBooksTelemetry
      • +
      • Browser/UseSharedFolderForBooks
      • +
      • Connectivity/AllowPhonePCLinking
      • +
      • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
      • +
      • DeliveryOptimization/DODelayForegroundDownloadFromHttp
      • +
      • DeliveryOptimization/DOGroupIdSource
      • +
      • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
      • +
      • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
      • +
      • DeliveryOptimization/DORestrictPeerSelectionBy
      • +
      • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
      • +
      • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
      • +
      • Display/DisablePerProcessDpiForApps
      • +
      • Display/EnablePerProcessDpi
      • +
      • Display/EnablePerProcessDpiForApps
      • +
      • Experience/AllowWindowsSpotlightOnSettings
      • +
      • KioskBrowser/BlockedUrlExceptions
      • +
      • KioskBrowser/BlockedUrls
      • +
      • KioskBrowser/DefaultURL
      • +
      • KioskBrowser/EnableEndSessionButton
      • +
      • KioskBrowser/EnableHomeButton
      • +
      • KioskBrowser/EnableNavigationButtons
      • +
      • KioskBrowser/RestartOnIdleTime
      • +
      • LanmanWorkstation/EnableInsecureGuestLogons
      • +
      • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
      • +
      • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
      • +
      • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
      • +
      • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
      • +
      • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
      • +
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
      • +
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
      • +
      • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
      • +
      • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
      • +
      • Notifications/DisallowCloudNotification
      • +
      • RestrictedGroups/ConfigureGroupMembership
      • +
      • Search/AllowCortanaInAAD
      • +
      • Search/DoNotUseWebResults
      • +
      • Security/ConfigureWindowsPasswords
      • +
      • Start/DisableContextMenus
      • +
      • System/FeedbackHubAlwaysSaveDiagnosticsLocally
      • +
      • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
      • +
      • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
      • +
      • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
      • +
      • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
      • +
      • TaskScheduler/EnableXboxGameSaveTask
      • +
      • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
      • +
      • TextInput/ForceTouchKeyboardDockedState
      • +
      • TextInput/TouchKeyboardDictationButtonAvailability
      • +
      • TextInput/TouchKeyboardEmojiButtonAvailability
      • +
      • TextInput/TouchKeyboardFullModeAvailability
      • +
      • TextInput/TouchKeyboardHandwritingModeAvailability
      • +
      • TextInput/TouchKeyboardNarrowModeAvailability
      • +
      • TextInput/TouchKeyboardSplitModeAvailability
      • +
      • TextInput/TouchKeyboardWideModeAvailability
      • +
      • Update/ConfigureFeatureUpdateUninstallPeriod
      • +
      • UserRights/AccessCredentialManagerAsTrustedCaller
      • +
      • UserRights/AccessFromNetwork
      • +
      • UserRights/ActAsPartOfTheOperatingSystem
      • +
      • UserRights/AllowLocalLogOn
      • +
      • UserRights/BackupFilesAndDirectories
      • +
      • UserRights/ChangeSystemTime
      • +
      • UserRights/CreateGlobalObjects
      • +
      • UserRights/CreatePageFile
      • +
      • UserRights/CreatePermanentSharedObjects
      • +
      • UserRights/CreateSymbolicLinks
      • +
      • UserRights/CreateToken
      • +
      • UserRights/DebugPrograms
      • +
      • UserRights/DenyAccessFromNetwork
      • +
      • UserRights/DenyLocalLogOn
      • +
      • UserRights/DenyRemoteDesktopServicesLogOn
      • +
      • UserRights/EnableDelegation
      • +
      • UserRights/GenerateSecurityAudits
      • +
      • UserRights/ImpersonateClient
      • +
      • UserRights/IncreaseSchedulingPriority
      • +
      • UserRights/LoadUnloadDeviceDrivers
      • +
      • UserRights/LockMemory
      • +
      • UserRights/ManageAuditingAndSecurityLog
      • +
      • UserRights/ManageVolume
      • +
      • UserRights/ModifyFirmwareEnvironment
      • +
      • UserRights/ModifyObjectLabel
      • +
      • UserRights/ProfileSingleProcess
      • +
      • UserRights/RemoteShutdown
      • +
      • UserRights/RestoreFilesAndDirectories
      • +
      • UserRights/TakeOwnership
      • +
      • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
      • +
      • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
      • +
      • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
      • +
      • WindowsDefenderSecurityCenter/HideSecureBoot
      • +
      • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
      • +
      +

      Security/RequireDeviceEncryption - updated to show it is supported in desktop.

      +
      [BitLocker CSP](bitlocker-csp.md)

      Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

      +
      [DMClient CSP](dmclient-csp.md)

      Added the following settings:

      +

      Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

        -
      • ManagementServerAddressList
      • -
      • AADDeviceID
      • -
      • EnrollmentType
      • -
      • HWDevID
      • -
      • CommercialID
      • +
      • AADSendDeviceToken
      • +
      • BlockInStatusPage
      • +
      • AllowCollectLogsButton
      • +
      • CustomErrorText
      • +
      • SkipDeviceStatusPage
      • +
      • SkipUserStatusPage
      -

      Removed the EnrollmentID setting.

      [DeviceManageability CSP](devicemanageability-csp.md)

      New CSP.

      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following new settings:

      +
      [Defender CSP](defender-csp.md)

      Added new node (OfflineScan) in Windows 10, version 1803.

      +
      [UEFI CSP](uefi-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [Update CSP](update-csp.md)

      Added the following nodes in Windows 10, version 1803:

        -
      • DeviceStatus/TPM/SpecificationVersion
      • -
      • DeviceStatus/OS/Edition
      • -
      • DeviceStatus/Antivirus/SignatureStatus
      • -
      • DeviceStatus/Antivirus/Status
      • -
      • DeviceStatus/Antispyware/SignatureStatus
      • -
      • DeviceStatus/Antispyware/Status
      • -
      • DeviceStatus/Firewall/Status
      • -
      • DeviceStatus/UAC/Status
      • -
      • DeviceStatus/Battery/Status
      • -
      • DeviceStatus/Battery/EstimatedChargeRemaining
      • -
      • DeviceStatus/Battery/EstimatedRuntime
      • -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added SyncML examples.

      [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
        -
      • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
      • -
      • Updated the DDF and XSD file sections.
      • -
      [SecureAssessment CSP](secureassessment-csp.md)

      New CSP for Windows 10, version 1607

      [DiagnosticLog CSP](diagnosticlog-csp.md) -

      [DiagnosticLog DDF](diagnosticlog-ddf.md)

      Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

      +

      Added the following nodes in Windows 10, version 1803:

        -
      • DeviceStateData
      • -
      • DeviceStateData/MdmConfiguration
      • -
      [Reboot CSP](reboot-csp.md)

      New CSP for Windows 10, version 1607

      [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

      New CSP for Windows 10, version 1607

      [VPNv2 CSP](vpnv2-csp.md)

      Added the following settings for Windows 10, version 1607

      -
        -
      • ProfileName/RouteList/routeRowId/ExclusionRoute
      • -
      • ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
      • -
      • ProfileName/DomainNameInformationList/dniRowId/Persistent
      • -
      • ProfileName/ProfileXML
      • -
      • ProfileName/DeviceCompliance/Enabled
      • -
      • ProfileName/DeviceCompliance/Sso
      • -
      • ProfileName/DeviceCompliance/Sso/Enabled
      • -
      • ProfileName/DeviceCompliance/Sso/IssuerHash
      • -
      • ProfileName/DeviceCompliance/Sso/Eku
      • -
      • ProfileName/NativeProfile/CryptographySuite
      • -
      • ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
      • -
      • ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
      • -
      • ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
      • -
      • ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
      • -
      • ProfileName/NativeProfile/CryptographySuite/DHGroup
      • -
      • ProfileName/NativeProfile/CryptographySuite/PfsGroup
      • -
      • ProfileName/NativeProfile/L2tpPsk
      • -
      [Win32AppInventory CSP](win32appinventory-csp.md) -

      [Win32AppInventory DDF](win32appinventory-ddf-file.md)

      New CSP for Windows 10, version 1607.

      [SharedPC CSP](sharedpc-csp.md)

      New CSP for Windows 10, version 1607.

      [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

      New CSP for Windows 10, version 1607.

      [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

      Added new classes for Windows 10, version 1607.

      [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

      Topic renamed from "Enrollment UI".

      -

      Completely updated enrollment procedures and screenshots.

      [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) -

      [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

      Added the following new setting for Windows 10, version 1607:

      -
        -
      • NextSession/HORMEnabled
      • -
      [CertificateStore CSP](certificatestore-csp.md) -

      [CertificateStore DDF file](certificatestore-ddf-file.md)

      Added the following new settings in Windows 10, version 1607:

      -
        -
      • My/WSTEP/Renew/LastRenewalAttemptTime
      • -
      • My/WSTEP/Renew/RenewNow
      • -

      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added the following new node and settings in Windows 10, version 1607, but not documented:

      -
        -
      • Subscriptions
      • -
      • Subscriptions/SubscriptionId
      • -
      • Subscriptions/SubscriptionId/Status
      • -
      • Subscriptions/SubscriptionId/Name
      • +
      • Status
      • +
      • ShellLauncher
      • +
      • StatusConfiguration
      -
      [MultiSIM CSP](multisim-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • MaintainProcessorArchitectureOnUpdate
      • +
      +
      [eUICCs CSP](euiccs-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • IsEnabled
      • +
      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • OS/Mode
      • +
      +
      [AccountManagement CSP](accountmanagement-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • UntrustedCertificates
      • +
      +
      [NetworkProxy CSP](\networkproxy--csp.md)

      Added the following node in Windows 10, version 1803:

      +
        +
      • ProxySettingsPerUser
      • +
      +
      [Accounts CSP](accounts-csp.md)

      Added a new CSP in Windows 10, version 1803.

      +
      [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

      Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

      +
      [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

      Added the DDF download of Windows 10, version 1803 configuration service providers.

      +
      -## What's new in Windows 10, version 1703 +## What’s new in MDM for Windows 10, version 1709 + + ++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      ItemDescription
      The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

      The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

      +
        +
      • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
      • +
      • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
      • +
      • DomainName - fully qualified domain name if the device is domain-joined.
      • +
      +

      For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

      +
      [Firewall CSP](firewall-csp.md)

      Added new CSP in Windows 10, version 1709.

      +
      [eUICCs CSP](euiccs-csp.md)

      Added new CSP in Windows 10, version 1709.

      +
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
      [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).
      [VPNv2 CSP](vpnv2-csp.md)

      Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
        +
      • DeviceStatus/DomainName
      • +
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
      • +
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
      • +
      • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
      • +
      +
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following setting in Windows 10, version 1709.

      +
        +
      • Configuration
      • +
      +

      Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

      +
      [DeviceManageability CSP](devicemanageability-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
        +
      • Provider/_ProviderID_/ConfigInfo
      • +
      • Provider/_ProviderID_/EnrollmentInfo
      • +
      +
      [Office CSP](office-csp.md)

      Added the following setting in Windows 10, version 1709:

      +
        +
      • Installation/CurrentStatus
      • +
      +
      [DMClient CSP](dmclient-csp.md)

      Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

      +
      [Bitlocker CSP](bitlocker-csp.md)

      Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

      +
      [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

      Added new policies.

      +
      Microsoft Store for Business and Microsoft Store

      Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

      +
      [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

      New features in the Settings app:

      +
        +
      • User sees installation progress of critical policies during MDM enrollment.
      • +
      • User knows what policies, profiles, apps MDM has configured
      • +
      • IT helpdesk can get detailed MDM diagnostic information using client tools
      • +
      +

      For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

      +
      [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

      Added new topic to introduce a new Group Policy for automatic MDM enrollment.

      +
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1709:

      +
        +
      • Authentication/AllowAadPasswordReset
      • +
      • Authentication/AllowFidoDeviceSignon
      • +
      • Browser/LockdownFavorites
      • +
      • Browser/ProvisionFavorites
      • +
      • Cellular/LetAppsAccessCellularData
      • +
      • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
      • +
      • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
      • +
      • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
      • +
      • CredentialProviders/DisableAutomaticReDeploymentCredentials
      • +
      • DeviceGuard/EnableVirtualizationBasedSecurity
      • +
      • DeviceGuard/RequirePlatformSecurityFeatures
      • +
      • DeviceGuard/LsaCfgFlags
      • +
      • DeviceLock/MinimumPasswordAge
      • +
      • ExploitGuard/ExploitProtectionSettings
      • +
      • Games/AllowAdvancedGamingServices
      • +
      • Handwriting/PanelDefaultModeDocked
      • +
      • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
      • +
      • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
      • +
      • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
      • +
      • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
      • +
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
      • +
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
      • +
      • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
      • +
      • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
      • +
      • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
      • +
      • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
      • +
      • Power/DisplayOffTimeoutOnBattery
      • +
      • Power/DisplayOffTimeoutPluggedIn
      • +
      • Power/HibernateTimeoutOnBattery
      • +
      • Power/HibernateTimeoutPluggedIn
      • +
      • Power/StandbyTimeoutOnBattery
      • +
      • Power/StandbyTimeoutPluggedIn
      • +
      • Privacy/EnableActivityFeed
      • +
      • Privacy/PublishUserActivities
      • +
      • Defender/AttackSurfaceReductionOnlyExclusions
      • +
      • Defender/AttackSurfaceReductionRules
      • +
      • Defender/CloudBlockLevel
      • +
      • Defender/CloudExtendedTimeout
      • +
      • Defender/ControlledFolderAccessAllowedApplications
      • +
      • Defender/ControlledFolderAccessProtectedFolders
      • +
      • Defender/EnableControlledFolderAccess
      • +
      • Defender/EnableNetworkProtection
      • +
      • Education/DefaultPrinterName
      • +
      • Education/PreventAddingNewPrinters
      • +
      • Education/PrinterNames
      • +
      • Search/AllowCloudSearch
      • +
      • Security/ClearTPMIfNotReady
      • +
      • Settings/AllowOnlineTips
      • +
      • Start/HidePeopleBar
      • +
      • Storage/AllowDiskHealthModelUpdates
      • +
      • System/DisableEnterpriseAuthProxy
      • +
      • System/LimitEnhancedDiagnosticDataWindowsAnalytics
      • +
      • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
      • +
      • Update/DisableDualScan
      • +
      • Update/ManagePreviewBuilds
      • +
      • Update/ScheduledInstallEveryWeek
      • +
      • Update/ScheduledInstallFirstWeek
      • +
      • Update/ScheduledInstallFourthWeek
      • +
      • Update/ScheduledInstallSecondWeek
      • +
      • Update/ScheduledInstallThirdWeek
      • +
      • WindowsDefenderSecurityCenter/CompanyName
      • +
      • WindowsDefenderSecurityCenter/DisableAppBrowserUI
      • +
      • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
      • +
      • WindowsDefenderSecurityCenter/DisableFamilyUI
      • +
      • WindowsDefenderSecurityCenter/DisableHealthUI
      • +
      • WindowsDefenderSecurityCenter/DisableNetworkUI
      • +
      • WindowsDefenderSecurityCenter/DisableNotifications
      • +
      • WindowsDefenderSecurityCenter/DisableVirusUI
      • +
      • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
      • +
      • WindowsDefenderSecurityCenter/Email
      • +
      • WindowsDefenderSecurityCenter/EnableCustomizedToasts
      • +
      • WindowsDefenderSecurityCenter/EnableInAppCustomization
      • +
      • WindowsDefenderSecurityCenter/Phone
      • +
      • WindowsDefenderSecurityCenter/URL
      • +
      • WirelessDisplay/AllowMdnsAdvertisement
      • +
      • WirelessDisplay/AllowMdnsDiscovery
      • +
      +
      + +## What’s new in MDM for Windows 10, version 1703 @@ -932,7 +1114,8 @@ For details about Microsoft mobile device management protocols for Windows 10 s
        -## What's new in Windows 10, version 1709 + +## What’s new in MDM for Windows 10, version 1607 @@ -946,439 +1129,304 @@ For details about Microsoft mobile device management protocols for Windows 10 s - - - - - - - - - - - + + - - + + - - + + - - + + + - - + - - - +

      Removed the EnrollmentID setting.

      + - - - - - - - - - - - - - - - - - - - - - - - - - -
      The [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2](https://msdn.microsoft.com/library/mt221945.aspx)

      The Windows 10 enrollment protocol was updated. The following elements were added to the RequestSecurityToken message:

      -
        -
      • UXInitiated - boolean value that indicates whether the enrollment is user initiated from the Settings page.
      • -
      • ExternalMgmtAgentHint - a string the agent uses to give hints the enrollment server may need.
      • -
      • DomainName - fully qualified domain name if the device is domain-joined.
      • -
      -

      For examples, see section 4.3.1 RequestSecurityToken of the MS-MDE2 protocol documentation.

      -
      [Firewall CSP](firewall-csp.md)

      Added new CSP in Windows 10, version 1709.

      -
      [eUICCs CSP](euiccs-csp.md)

      Added new CSP in Windows 10, version 1709.

      -
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).

      Sideloading of apps

      Starting in Windows 10, version 1607, sideloading of apps is only allowed through [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md). Product keys (5x5) will no longer be supported to enable sideloading on Windows 10, version 1607 devices.

      [CM_ProxyEntries CSP](cm-proxyentries-csp.md) and [CMPolicy CSP](cmpolicy-csp.md)In Windows 10, version 1709, support for desktop SKUs were added to these CSPs. The table of SKU information in the [Configuration service provider reference](configuration-service-provider-reference.md) was updated.

      New value for [NodeCache CSP](nodecache-csp.md)

      In [NodeCache CSP](nodecache-csp.md), the value of NodeCache root node starting in Windows 10, version 1607 is com.microsoft/1.0/MDM/NodeCache.

      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)New CSP added in Windows 10, version 1709. Also added the DDF topic [WindowsDefenderApplicationGuard DDF file](windowsdefenderapplicationguard-ddf-file.md).[EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)

      New CSP.

      [VPNv2 CSP](vpnv2-csp.md)

      Added DeviceTunnel and RegisterDNS settings in Windows 10, version 1709.

      -
      [Policy CSP](policy-configuration-service-provider.md)

      Removed the following policies:

      +
        +
      • DataProtection/AllowAzureRMSForEDP - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/AllowUserDecryption - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/EDPEnforcementLevel - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/RequireProtectionUnderLockConfig - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/RevokeOnUnenroll - moved this policy to [EnterpriseDataProtection CSP](enterprisedataprotection-csp.md)
      • +
      • DataProtection/EnterpriseCloudResources - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseInternalProxyServers - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseIPRange - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseNetworkDomainNames - moved this policy to NetworkIsolation policy
      • +
      • DataProtection/EnterpriseProxyServers - moved this policy to NetworkIsolation policy
      • +
      • Security/AllowAutomaticDeviceEncryptionForAzureADJoinedDevices - this policy has been deprecated.
      • +
      +

      Added the WiFi/AllowManualWiFiConfiguration and WiFi/AllowWiFi policies for Windows 10, version 1607:

      +
        +
      • Windows 10 Pro
      • +
      • Windows 10 Enterprise
      • +
      • Windows 10 Education
      • +
      +

      Added the following new policies:

      +
        +
      • AboveLock/AllowCortanaAboveLock
      • +
      • ApplicationManagement/DisableStoreOriginatedApps
      • +
      • Authentication/AllowSecondaryAuthenticationDevice
      • +
      • Bluetooth/AllowPrepairing
      • +
      • Browser/AllowExtensions
      • +
      • Browser/PreventAccessToAboutFlagsInMicrosoftEdge
      • +
      • Browser/ShowMessageWhenOpeningSitesInInternetExplorer
      • +
      • DeliveryOptimization/DOAbsoluteMaxCacheSize
      • +
      • DeliveryOptimization/DOMaxDownloadBandwidth
      • +
      • DeliveryOptimization/DOMinBackgroundQoS
      • +
      • DeliveryOptimization/DOModifyCacheDrive
      • +
      • DeliveryOptimization/DOMonthlyUploadDataCap
      • +
      • DeliveryOptimization/DOPercentageMaxDownloadBandwidth
      • +
      • DeviceLock/EnforceLockScreenAndLogonImage
      • +
      • DeviceLock/EnforceLockScreenProvider
      • +
      • Defender/PUAProtection
      • +
      • Experience/AllowThirdPartySuggestionsInWindowsSpotlight
      • +
      • Experience/AllowWindowsSpotlight
      • +
      • Experience/ConfigureWindowsSpotlightOnLockScreen
      • +
      • Experience/DoNotShowFeedbackNotifications
      • +
      • Licensing/AllowWindowsEntitlementActivation
      • +
      • Licensing/DisallowKMSClientOnlineAVSValidation
      • +
      • LockDown/AllowEdgeSwipe
      • +
      • Maps/EnableOfflineMapsAutoUpdate
      • +
      • Maps/AllowOfflineMapsDownloadOverMeteredConnection
      • +
      • Messaging/AllowMessageSync
      • +
      • NetworkIsolation/EnterpriseCloudResources
      • +
      • NetworkIsolation/EnterpriseInternalProxyServers
      • +
      • NetworkIsolation/EnterpriseIPRange
      • +
      • NetworkIsolation/EnterpriseIPRangesAreAuthoritative
      • +
      • NetworkIsolation/EnterpriseNetworkDomainNames
      • +
      • NetworkIsolation/EnterpriseProxyServers
      • +
      • NetworkIsolation/EnterpriseProxyServersAreAuthoritative
      • +
      • NetworkIsolation/NeutralResources
      • +
      • Notifications/DisallowNotificationMirroring
      • +
      • Privacy/DisableAdvertisingId
      • +
      • Privacy/LetAppsAccessAccountInfo
      • +
      • Privacy/LetAppsAccessAccountInfo_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessAccountInfo_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessAccountInfo_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCalendar
      • +
      • Privacy/LetAppsAccessCalendar_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCalendar_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCalendar_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory
      • +
      • Privacy/LetAppsAccessCallHistory_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCallHistory_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessCamera
      • +
      • Privacy/LetAppsAccessCamera_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessCamera_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessCamera_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessContacts
      • +
      • Privacy/LetAppsAccessContacts_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessContacts_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessContacts_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessEmail
      • +
      • Privacy/LetAppsAccessEmail_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessEmail_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessEmail_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessLocation
      • +
      • Privacy/LetAppsAccessLocation_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessLocation_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessLocation_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMessaging
      • +
      • Privacy/LetAppsAccessMessaging_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMessaging_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMessaging_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone
      • +
      • Privacy/LetAppsAccessMicrophone_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMicrophone_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessMotion
      • +
      • Privacy/LetAppsAccessMotion_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessMotion_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessMotion_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessNotifications
      • +
      • Privacy/LetAppsAccessNotifications_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessNotifications_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessNotifications_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessPhone
      • +
      • Privacy/LetAppsAccessPhone_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessPhone_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessPhone_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessRadios
      • +
      • Privacy/LetAppsAccessRadios_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessRadios_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessRadios_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices
      • +
      • Privacy/LetAppsAccessTrustedDevices_ForceAllowTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices_ForceDenyTheseApps
      • +
      • Privacy/LetAppsAccessTrustedDevices_UserInControlOfTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices
      • +
      • Privacy/LetAppsSyncWithDevices_ForceAllowTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices_ForceDenyTheseApps
      • +
      • Privacy/LetAppsSyncWithDevices_UserInControlOfTheseApps
      • +
      • Security/PreventAutomaticDeviceEncryptionForAzureADJoinedDevices
      • +
      • Settings/AllowEditDeviceName
      • +
      • Speech/AllowSpeechModelUpdate
      • +
      • System/TelemetryProxy
      • +
      • Update/ActiveHoursStart
      • +
      • Update/ActiveHoursEnd
      • +
      • Update/AllowMUUpdateService
      • +
      • Update/BranchReadinessLevel
      • +
      • Update/DeferFeatureUpdatesPeriodInDays
      • +
      • Update/DeferQualityUpdatesPeriodInDays
      • +
      • Update/ExcludeWUDriversInQualityUpdate
      • +
      • Update/PauseFeatureUpdates
      • +
      • Update/PauseQualityUpdates
      • +
      • Update/UpdateServiceUrlAlternate (Added in the January service release of Windows 10, version 1607)
      • +
      • WindowsInkWorkspace/AllowWindowsInkWorkspace
      • +
      • WindowsInkWorkspace/AllowSuggestedAppsInWindowsInkWorkspace
      • +
      • WirelessDisplay/AllowProjectionToPC
      • +
      • WirelessDisplay/RequirePinForPairing
      • +
      +

      Updated the Privacy/AllowAutoAcceptPairingAndPrivacyConsentPrompts description to remove outdated information.

      +

      Updated DeliveryOptimization/DODownloadMode to add new values.

      +

      Updated Experience/AllowCortana description to clarify what each supported value does.

      +

      Updated Security/AntiTheftMode description to clarify what each supported value does.

      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following settings in Windows 10, version 1709:

      +
      [DMClient CSP](dmclient-csp.md)

      Added the following settings:

        -
      • DeviceStatus/DomainName
      • -
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityHwReq
      • -
      • DeviceStatus/DeviceGuard/VirtualizationBasedSecurityStatus
      • -
      • DeviceStatus/DeviceGuard/LsaCfgCredGuardStatus
      • +
      • ManagementServerAddressList
      • +
      • AADDeviceID
      • +
      • EnrollmentType
      • +
      • HWDevID
      • +
      • CommercialID
      -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following setting in Windows 10, version 1709.

      -
        -
      • Configuration
      • -
      -

      Starting in Windows 10, version 1709, AssignedAccess CSP is supported in Windows 10 Pro.

      -
      [DeviceManageability CSP](devicemanageability-csp.md)

      Added the following settings in Windows 10, version 1709:

      -
        -
      • Provider/_ProviderID_/ConfigInfo
      • -
      • Provider/_ProviderID_/EnrollmentInfo
      • -
      -
      [Office CSP](office-csp.md)

      Added the following setting in Windows 10, version 1709:

      -
        -
      • Installation/CurrentStatus
      • -
      -
      [DMClient CSP](dmclient-csp.md)

      Added new nodes to the DMClient CSP in Windows 10, version 1709. Updated the CSP and DDF topics.

      -
      [Bitlocker CSP](bitlocker-csp.md)

      Changed the minimum personal identification number (PIN) length to 4 digits in SystemDrivesRequireStartupAuthentication and SystemDrivesMinimumPINLength in Windows 10, version 1709.

      -
      [ADMX-backed policies in Policy CSP](policy-configuration-service-provider.md#admx-backed-policies)

      Added new policies.

      -
      Microsoft Store for Business and Microsoft Store

      Windows Store for Business name changed to Microsoft Store for Business. Windows Store name changed to Microsoft Store.

      -
      [MDM enrollment of Windows-based devices](mdm-enrollment-of-windows-devices.md)

      New features in the Settings app:

      -
        -
      • User sees installation progress of critical policies during MDM enrollment.
      • -
      • User knows what policies, profiles, apps MDM has configured
      • -
      • IT helpdesk can get detailed MDM diagnostic information using client tools
      • -
      -

      For details, see [Managing connection](mdm-enrollment-of-windows-devices.md#managing-connections) and [Collecting diagnostic logs](mdm-enrollment-of-windows-devices.md#collecting-diagnostic-logs)

      -
      [Enroll a Windows 10 device automatically using Group Policy](enroll-a-windows-10-device-automatically-using-group-policy.md)

      Added new topic to introduce a new Group Policy for automatic MDM enrollment.

      -
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1709:

      -
        -
      • Authentication/AllowAadPasswordReset
      • -
      • Authentication/AllowFidoDeviceSignon
      • -
      • Browser/LockdownFavorites
      • -
      • Browser/ProvisionFavorites
      • -
      • Cellular/LetAppsAccessCellularData
      • -
      • Cellular/LetAppsAccessCellularData_ForceAllowTheseApps
      • -
      • Cellular/LetAppsAccessCellularData_ForceDenyTheseApps
      • -
      • Cellular/LetAppsAccessCellularData_UserInControlOfTheseApps
      • -
      • CredentialProviders/DisableAutomaticReDeploymentCredentials
      • -
      • DeviceGuard/EnableVirtualizationBasedSecurity
      • -
      • DeviceGuard/RequirePlatformSecurityFeatures
      • -
      • DeviceGuard/LsaCfgFlags
      • -
      • DeviceLock/MinimumPasswordAge
      • -
      • ExploitGuard/ExploitProtectionSettings
      • -
      • Games/AllowAdvancedGamingServices
      • -
      • Handwriting/PanelDefaultModeDocked
      • -
      • LocalPoliciesSecurityOptions/Accounts_BlockMicrosoftAccounts
      • -
      • LocalPoliciesSecurityOptions/Accounts_EnableAdministratorAccountStatus
      • -
      • LocalPoliciesSecurityOptions/Accounts_EnableGuestAccountStatus
      • -
      • LocalPoliciesSecurityOptions/Accounts_LimitLocalAccountUseOfBlankPasswordsToConsoleLogonOnly
      • -
      • LocalPoliciesSecurityOptions/Accounts_RenameAdministratorAccount
      • -
      • LocalPoliciesSecurityOptions/Accounts_RenameGuestAccount
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_DisplayUserInformationWhenTheSessionIsLocked
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayLastSignedIn
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotDisplayUsernameAtSignIn
      • -
      • LocalPoliciesSecurityOptions/Interactivelogon_DoNotRequireCTRLALTDEL
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MachineInactivityLimit
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTextForUsersAttemptingToLogOn
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_MessageTitleForUsersAttemptingToLogOn
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_AllowPKU2UAuthenticationRequests
      • -
      • LocalPoliciesSecurityOptions/RecoveryConsole_AllowAutomaticAdministrativeLogon
      • -
      • LocalPoliciesSecurityOptions/Shutdown_AllowSystemToBeShutDownWithoutHavingToLogOn
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_AllowUIAccessApplicationsToPromptForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForAdministrators
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_BehaviorOfTheElevationPromptForStandardUsers
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateExecutableFilesThatAreSignedAndValidated
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_OnlyElevateUIAccessApplicationsThatAreInstalledInSecureLocations
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_RunAllAdministratorsInAdminApprovalMode
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_SwitchToTheSecureDesktopWhenPromptingForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_VirtualizeFileAndRegistryWriteFailuresToPerUserLocations
      • -
      • Power/DisplayOffTimeoutOnBattery
      • -
      • Power/DisplayOffTimeoutPluggedIn
      • -
      • Power/HibernateTimeoutOnBattery
      • -
      • Power/HibernateTimeoutPluggedIn
      • -
      • Power/StandbyTimeoutOnBattery
      • -
      • Power/StandbyTimeoutPluggedIn
      • -
      • Privacy/EnableActivityFeed
      • -
      • Privacy/PublishUserActivities
      • -
      • Defender/AttackSurfaceReductionOnlyExclusions
      • -
      • Defender/AttackSurfaceReductionRules
      • -
      • Defender/CloudBlockLevel
      • -
      • Defender/CloudExtendedTimeout
      • -
      • Defender/ControlledFolderAccessAllowedApplications
      • -
      • Defender/ControlledFolderAccessProtectedFolders
      • -
      • Defender/EnableControlledFolderAccess
      • -
      • Defender/EnableNetworkProtection
      • -
      • Education/DefaultPrinterName
      • -
      • Education/PreventAddingNewPrinters
      • -
      • Education/PrinterNames
      • -
      • Search/AllowCloudSearch
      • -
      • Security/ClearTPMIfNotReady
      • -
      • Settings/AllowOnlineTips
      • -
      • Start/HidePeopleBar
      • -
      • Storage/AllowDiskHealthModelUpdates
      • -
      • System/DisableEnterpriseAuthProxy
      • -
      • System/LimitEnhancedDiagnosticDataWindowsAnalytics
      • -
      • Update/AllowAutoWindowsUpdateDownloadOverMeteredNetwork
      • -
      • Update/DisableDualScan
      • -
      • Update/ManagePreviewBuilds
      • -
      • Update/ScheduledInstallEveryWeek
      • -
      • Update/ScheduledInstallFirstWeek
      • -
      • Update/ScheduledInstallFourthWeek
      • -
      • Update/ScheduledInstallSecondWeek
      • -
      • Update/ScheduledInstallThirdWeek
      • -
      • WindowsDefenderSecurityCenter/CompanyName
      • -
      • WindowsDefenderSecurityCenter/DisableAppBrowserUI
      • -
      • WindowsDefenderSecurityCenter/DisableEnhancedNotifications
      • -
      • WindowsDefenderSecurityCenter/DisableFamilyUI
      • -
      • WindowsDefenderSecurityCenter/DisableHealthUI
      • -
      • WindowsDefenderSecurityCenter/DisableNetworkUI
      • -
      • WindowsDefenderSecurityCenter/DisableNotifications
      • -
      • WindowsDefenderSecurityCenter/DisableVirusUI
      • -
      • WindowsDefenderSecurityCenter/DisallowExploitProtectionOverride
      • -
      • WindowsDefenderSecurityCenter/Email
      • -
      • WindowsDefenderSecurityCenter/EnableCustomizedToasts
      • -
      • WindowsDefenderSecurityCenter/EnableInAppCustomization
      • -
      • WindowsDefenderSecurityCenter/Phone
      • -
      • WindowsDefenderSecurityCenter/URL
      • -
      • WirelessDisplay/AllowMdnsAdvertisement
      • -
      • WirelessDisplay/AllowMdnsDiscovery
      • -
      -
      - -## What's new in Windows 10, version 1803 - - ---- - - - - + - - - - - + + - - - - - - - - - - - - - - - - + + + + + + - - + + + + + + + - - + + + + + + + + + - - - + + + + + + + + + + + + + + + + + + + + + + + + - - - + + + + - - - - - - + + + + - - - - - - - - - - - - + +
      New or updated topicDescription

      New CSP.

      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies for Windows 10, version 1803:

      +
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following new settings:

        -
      • ApplicationDefaults/EnableAppUriHandlers
      • -
      • ApplicationManagement/MSIAllowUserControlOverInstall
      • -
      • ApplicationManagement/MSIAlwaysInstallWithElevatedPrivileges
      • -
      • Bluetooth/AllowPromptedProximalConnections
      • -
      • Browser/AllowConfigurationUpdateForBooksLibrary
      • -
      • Browser/AlwaysEnableBooksLibrary
      • -
      • Browser/EnableExtendedBooksTelemetry
      • -
      • Browser/UseSharedFolderForBooks
      • -
      • Connectivity/AllowPhonePCLinking
      • -
      • DeliveryOptimization/DODelayBackgroundDownloadFromHttp
      • -
      • DeliveryOptimization/DODelayForegroundDownloadFromHttp
      • -
      • DeliveryOptimization/DOGroupIdSource
      • -
      • DeliveryOptimization/DOPercentageMaxBackDownloadBandwidth
      • -
      • DeliveryOptimization/DOPercentageMaxForeDownloadBandwidth
      • -
      • DeliveryOptimization/DORestrictPeerSelectionBy
      • -
      • DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth
      • -
      • DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth
      • -
      • Display/DisablePerProcessDpiForApps
      • -
      • Display/EnablePerProcessDpi
      • -
      • Display/EnablePerProcessDpiForApps
      • -
      • Experience/AllowWindowsSpotlightOnSettings
      • -
      • KioskBrowser/BlockedUrlExceptions
      • -
      • KioskBrowser/BlockedUrls
      • -
      • KioskBrowser/DefaultURL
      • -
      • KioskBrowser/EnableEndSessionButton
      • -
      • KioskBrowser/EnableHomeButton
      • -
      • KioskBrowser/EnableNavigationButtons
      • -
      • KioskBrowser/RestartOnIdleTime
      • -
      • LanmanWorkstation/EnableInsecureGuestLogons
      • -
      • LocalPoliciesSecurityOptions/Devices_AllowUndockWithoutHavingToLogon
      • -
      • LocalPoliciesSecurityOptions/Devices_AllowedToFormatAndEjectRemovableMedia
      • -
      • LocalPoliciesSecurityOptions/Devices_PreventUsersFromInstallingPrinterDriversWhenConnectingToSharedPrinters
      • -
      • LocalPoliciesSecurityOptions/Devices_RestrictCDROMAccessToLocallyLoggedOnUserOnly
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptOrSignSecureChannelDataAlways
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DigitallyEncryptSecureChannelDataWhenPossible
      • -
      • LocalPoliciesSecurityOptions/DomainMember_DisableMachineAccountPasswordChanges
      • -
      • LocalPoliciesSecurityOptions/InteractiveLogon_SmartCardRemovalBehavior
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_DigitallySignCommunicationsIfServerAgrees
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkClient_SendUnencryptedPasswordToThirdPartySMBServers
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsAlways
      • -
      • LocalPoliciesSecurityOptions/MicrosoftNetworkServer_DigitallySignCommunicationsIfClientAgrees
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSAMAccounts
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowAnonymousEnumerationOfSamAccountsAndShares
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictAnonymousAccessToNamedPipesAndShares
      • -
      • LocalPoliciesSecurityOptions/NetworkAccess_RestrictClientsAllowedToMakeRemoteCallsToSAM
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_DoNotStoreLANManagerHashValueOnNextPasswordChange
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_LANManagerAuthenticationLevel
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_MinimumSessionSecurityForNTLMSSPBasedServers
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AddRemoteServerExceptionsForNTLMAuthentication
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_AuditIncomingNTLMTraffic
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_IncomingNTLMTraffic
      • -
      • LocalPoliciesSecurityOptions/NetworkSecurity_RestrictNTLM_OutgoingNTLMTrafficToRemoteServers
      • -
      • LocalPoliciesSecurityOptions/Shutdown_ClearVirtualMemoryPageFile
      • -
      • LocalPoliciesSecurityOptions/SystemObjects_RequireCaseInsensitivityForNonWindowsSubsystems
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_DetectApplicationInstallationsAndPromptForElevation
      • -
      • LocalPoliciesSecurityOptions/UserAccountControl_UseAdminApprovalMode
      • -
      • Notifications/DisallowCloudNotification
      • -
      • RestrictedGroups/ConfigureGroupMembership
      • -
      • Search/AllowCortanaInAAD
      • -
      • Search/DoNotUseWebResults
      • -
      • Security/ConfigureWindowsPasswords
      • -
      • Start/DisableContextMenus
      • -
      • System/FeedbackHubAlwaysSaveDiagnosticsLocally
      • -
      • SystemServices/ConfigureHomeGroupListenerServiceStartupMode
      • -
      • SystemServices/ConfigureHomeGroupProviderServiceStartupMode
      • -
      • SystemServices/ConfigureXboxAccessoryManagementServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveAuthManagerServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveGameSaveServiceStartupMode
      • -
      • SystemServices/ConfigureXboxLiveNetworkingServiceStartupMode
      • -
      • TaskScheduler/EnableXboxGameSaveTask
      • -
      • TextInput/EnableTouchKeyboardAutoInvokeInDesktopMode
      • -
      • TextInput/ForceTouchKeyboardDockedState
      • -
      • TextInput/TouchKeyboardDictationButtonAvailability
      • -
      • TextInput/TouchKeyboardEmojiButtonAvailability
      • -
      • TextInput/TouchKeyboardFullModeAvailability
      • -
      • TextInput/TouchKeyboardHandwritingModeAvailability
      • -
      • TextInput/TouchKeyboardNarrowModeAvailability
      • -
      • TextInput/TouchKeyboardSplitModeAvailability
      • -
      • TextInput/TouchKeyboardWideModeAvailability
      • -
      • Update/ConfigureFeatureUpdateUninstallPeriod
      • -
      • UserRights/AccessCredentialManagerAsTrustedCaller
      • -
      • UserRights/AccessFromNetwork
      • -
      • UserRights/ActAsPartOfTheOperatingSystem
      • -
      • UserRights/AllowLocalLogOn
      • -
      • UserRights/BackupFilesAndDirectories
      • -
      • UserRights/ChangeSystemTime
      • -
      • UserRights/CreateGlobalObjects
      • -
      • UserRights/CreatePageFile
      • -
      • UserRights/CreatePermanentSharedObjects
      • -
      • UserRights/CreateSymbolicLinks
      • -
      • UserRights/CreateToken
      • -
      • UserRights/DebugPrograms
      • -
      • UserRights/DenyAccessFromNetwork
      • -
      • UserRights/DenyLocalLogOn
      • -
      • UserRights/DenyRemoteDesktopServicesLogOn
      • -
      • UserRights/EnableDelegation
      • -
      • UserRights/GenerateSecurityAudits
      • -
      • UserRights/ImpersonateClient
      • -
      • UserRights/IncreaseSchedulingPriority
      • -
      • UserRights/LoadUnloadDeviceDrivers
      • -
      • UserRights/LockMemory
      • -
      • UserRights/ManageAuditingAndSecurityLog
      • -
      • UserRights/ManageVolume
      • -
      • UserRights/ModifyFirmwareEnvironment
      • -
      • UserRights/ModifyObjectLabel
      • -
      • UserRights/ProfileSingleProcess
      • -
      • UserRights/RemoteShutdown
      • -
      • UserRights/RestoreFilesAndDirectories
      • -
      • UserRights/TakeOwnership
      • -
      • WindowsDefenderSecurityCenter/DisableAccountProtectionUI
      • -
      • WindowsDefenderSecurityCenter/DisableDeviceSecurityUI
      • -
      • WindowsDefenderSecurityCenter/HideRansomwareDataRecovery
      • -
      • WindowsDefenderSecurityCenter/HideSecureBoot
      • -
      • WindowsDefenderSecurityCenter/HideTPMTroubleshooting
      • -
      -

      Security/RequireDeviceEncryption - updated to show it is supported in desktop.

      +
    101. DeviceStatus/TPM/SpecificationVersion
    102. +
    103. DeviceStatus/OS/Edition
    104. +
    105. DeviceStatus/Antivirus/SignatureStatus
    106. +
    107. DeviceStatus/Antivirus/Status
    108. +
    109. DeviceStatus/Antispyware/SignatureStatus
    110. +
    111. DeviceStatus/Antispyware/Status
    112. +
    113. DeviceStatus/Firewall/Status
    114. +
    115. DeviceStatus/UAC/Status
    116. +
    117. DeviceStatus/Battery/Status
    118. +
    119. DeviceStatus/Battery/EstimatedChargeRemaining
    120. +
    121. DeviceStatus/Battery/EstimatedRuntime
    122. +
      [BitLocker CSP](bitlocker-csp.md)

      Updated the description for AllowWarningForOtherDiskEncryption to describe changes added in Windows 10, version 1803.

      -
      [DMClient CSP](dmclient-csp.md)

      Added ./User/Vendor/MSFT/DMClient/Provider/[ProviderID]/FirstSyncStatus node. Also added the following nodes in Windows 10, version 1803:

      -
        -
      • AADSendDeviceToken
      • -
      • BlockInStatusPage
      • -
      • AllowCollectLogsButton
      • -
      • CustomErrorText
      • -
      • SkipDeviceStatusPage
      • -
      • SkipUserStatusPage
      • -
      -
      [Defender CSP](defender-csp.md)

      Added new node (OfflineScan) in Windows 10, version 1803.

      -
      [UEFI CSP](uefi-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [Update CSP](update-csp.md)

      Added the following nodes in Windows 10, version 1803:

      -
        -
      • Rollback
      • -
      • Rollback/FeatureUpdate
      • -
      • Rollback/QualityUpdateStatus
      • -
      • Rollback/FeatureUpdateStatus
      • -
      -
      [AssignedAccess CSP](assignedaccess-csp.md)

      Added the following nodes in Windows 10, version 1803:

      -
        -
      • Status
      • -
      • ShellLauncher
      • -
      • StatusConfiguration
      • -
      -

      Updated the AssigneAccessConfiguration schema. Starting in Windows 10, version 1803 AssignedAccess CSP is supported in Windows Holographic for Business edition. Added example for Windows Holographic for Business edition.

      -

      Added SyncML examples.

      [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md)
        +
      • Added a new Folder table entry in the AssignedAccess/AssignedAccessXml description.
      • +
      • Updated the DDF and XSD file sections.
      • +
      [MultiSIM CSP](multisim-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [SecureAssessment CSP](secureassessment-csp.md)

      New CSP for Windows 10, version 1607

      [DiagnosticLog CSP](diagnosticlog-csp.md) +

      [DiagnosticLog DDF](diagnosticlog-ddf.md)

      Added version 1.3 of the CSP with two new settings. Added the new 1.3 version of the DDF. Added the following new settings in Windows 10, version 1607.

      +
        +
      • DeviceStateData
      • +
      • DeviceStateData/MdmConfiguration
      • +
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added the following node in Windows 10, version 1803:

      +
      [Reboot CSP](reboot-csp.md)

      New CSP for Windows 10, version 1607

      [CMPolicyEnterprise CSP](cmpolicyenterprise-csp.md)

      New CSP for Windows 10, version 1607

      [VPNv2 CSP](vpnv2-csp.md)

      Added the following settings for Windows 10, version 1607

        -
      • MaintainProcessorArchitectureOnUpdate
      • -
      -
      [eUICCs CSP](euiccs-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    123. ProfileName/RouteList/routeRowId/ExclusionRoute
    124. +
    125. ProfileName/DomainNameInformationList/dniRowId/AutoTrigger
    126. +
    127. ProfileName/DomainNameInformationList/dniRowId/Persistent
    128. +
    129. ProfileName/ProfileXML
    130. +
    131. ProfileName/DeviceCompliance/Enabled
    132. +
    133. ProfileName/DeviceCompliance/Sso
    134. +
    135. ProfileName/DeviceCompliance/Sso/Enabled
    136. +
    137. ProfileName/DeviceCompliance/Sso/IssuerHash
    138. +
    139. ProfileName/DeviceCompliance/Sso/Eku
    140. +
    141. ProfileName/NativeProfile/CryptographySuite
    142. +
    143. ProfileName/NativeProfile/CryptographySuite/AuthenticationTransformConstants
    144. +
    145. ProfileName/NativeProfile/CryptographySuite/CipherTransformConstants
    146. +
    147. ProfileName/NativeProfile/CryptographySuite/EncryptionMethod
    148. +
    149. ProfileName/NativeProfile/CryptographySuite/IntegrityCheckMethod
    150. +
    151. ProfileName/NativeProfile/CryptographySuite/DHGroup
    152. +
    153. ProfileName/NativeProfile/CryptographySuite/PfsGroup
    154. +
    155. ProfileName/NativeProfile/L2tpPsk
    156. +
      [Win32AppInventory CSP](win32appinventory-csp.md) +

      [Win32AppInventory DDF](win32appinventory-ddf-file.md)

      New CSP for Windows 10, version 1607.

      [SharedPC CSP](sharedpc-csp.md)

      New CSP for Windows 10, version 1607.

      [WindowsAdvancedThreatProtection CSP](windowsadvancedthreatprotection-csp.md)

      New CSP for Windows 10, version 1607.

      [MDM Bridge WMI Provider](https://msdn.microsoft.com/library/windows/hardware/dn905224)

      Added new classes for Windows 10, version 1607.

      [MDM enrollment of Windows devices](mdm-enrollment-of-windows-devices.md)

      Topic renamed from "Enrollment UI".

      +

      Completely updated enrollment procedures and screenshots.

      [UnifiedWriteFilter CSP](unifiedwritefilter-csp.md) +

      [UnifiedWriteFilter DDF File](unifiedwritefilter-ddf.md)

      Added the following new setting for Windows 10, version 1607:

        -
      • IsEnabled
      • -
      -
      [DeviceStatus CSP](devicestatus-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    157. NextSession/HORMEnabled
    158. +
      [CertificateStore CSP](certificatestore-csp.md) +

      [CertificateStore DDF file](certificatestore-ddf-file.md)

      Added the following new settings in Windows 10, version 1607:

        -
      • OS/Mode
      • -
      -
      [AccountManagement CSP](accountmanagement-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [RootCATrustedCertificates CSP](rootcacertificates-csp.md)

      Added the following node in Windows 10, version 1803:

      +
    159. My/WSTEP/Renew/LastRenewalAttemptTime
    160. +
    161. My/WSTEP/Renew/RenewNow
    162. +

      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added the following new node and settings in Windows 10, version 1607, but not documented:

        -
      • UntrustedCertificates
      • +
      • Subscriptions
      • +
      • Subscriptions/SubscriptionId
      • +
      • Subscriptions/SubscriptionId/Status
      • +
      • Subscriptions/SubscriptionId/Name
      -
      [NetworkProxy CSP](\networkproxy--csp.md)

      Added the following node in Windows 10, version 1803:

      -
        -
      • ProxySettingsPerUser
      • -
      -
      [Accounts CSP](accounts-csp.md)

      Added a new CSP in Windows 10, version 1803.

      -
      [MDM Migration Analysis Too (MMAT)](https://aka.ms/mmat)

      Updated version available. MMAT is a tool you can use to determine which Group Policies are set on a target user/computer and cross-reference them against the list of supported MDM policies.

      -
      [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download)

      Added the DDF download of Windows 10, version 1803 configuration service providers.

      -
      -## What's new in Windows 10, version 1809 +## What’s new in MDM for Windows 10, version 1511 @@ -1387,175 +1435,173 @@ For details about Microsoft mobile device management protocols for Windows 10 s - + - - - + + + + + + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +

      The following policies have been updated in the Policy CSP:

      +
        +
      • System/AllowLocation
      • +
      • Update/RequireDeferUpgrade
      • +
      +

      The following policies have been deprecated in the Policy CSP:

      +
        +
      • TextInput/AllowKoreanExtendedHanja
      • +
      • WiFi/AllowWiFiHotSpotReporting
      • +
      + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
      New or updated topicItem Description
      [Policy CSP](policy-configuration-service-provider.md)

      Added the following new policies in Windows 10, version 1809:

      +

      New configuration service providers added in Windows 10, version 1511

        +
      • [AllJoynManagement CSP](alljoynmanagement-csp.md)
      • +
      • [Maps CSP](maps-csp.md)
      • +
      • [Reporting CSP](reporting-csp.md)
      • +
      • [SurfaceHub CSP](surfacehub-csp.md)
      • +
      • [WindowsSecurityAuditing CSP](windowssecurityauditing-csp.md)
      • +

      New and updated policies in Policy CSP

      The following policies have been added to the [Policy CSP](policy-configuration-service-provider.md):

        -
      • ApplicationManagement/LaunchAppAfterLogOn
      • -
      • ApplicationManagement/ScheduleForceRestartForUpdateFailures
      • -
      • Authentication/EnableFastFirstSignIn
      • -
      • Authentication/EnableWebSignIn
      • -
      • Authentication/PreferredAadTenantDomainName
      • -
      • Browser/AllowFullScreenMode
      • -
      • Browser/AllowPrelaunch
      • -
      • Browser/AllowPrinting
      • -
      • Browser/AllowSavingHistory
      • -
      • Browser/AllowSideloadingOfExtensions
      • -
      • Browser/AllowTabPreloading
      • -
      • Browser/AllowWebContentOnNewTabPage
      • -
      • Browser/ConfigureFavoritesBar
      • -
      • Browser/ConfigureHomeButton
      • -
      • Browser/ConfigureKioskMode
      • -
      • Browser/ConfigureKioskResetAfterIdleTimeout
      • -
      • Browser/ConfigureOpenMicrosoftEdgeWith
      • -
      • Browser/ConfigureTelemetryForMicrosoft365Analytics
      • -
      • Browser/PreventCertErrorOverrides
      • -
      • Browser/SetHomeButtonURL
      • -
      • Browser/SetNewTabPageURL
      • -
      • Browser/UnlockHomeButton
      • -
      • Defender/CheckForSignaturesBeforeRunningScan
      • -
      • Defender/DisableCatchupFullScan
      • -
      • Defender/DisableCatchupQuickScan
      • -
      • Defender/EnableLowCPUPriority
      • -
      • Defender/SignatureUpdateFallbackOrder
      • -
      • Defender/SignatureUpdateFileSharesSources
      • -
      • DeviceGuard/ConfigureSystemGuardLaunch
      • -
      • DeviceInstallation/AllowInstallationOfMatchingDeviceIDs
      • -
      • DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
      • -
      • DeviceInstallation/PreventDeviceMetadataFromNetwork
      • -
      • DeviceInstallation/PreventInstallationOfDevicesNotDescribedByOtherPolicySettings
      • -
      • DmaGuard/DeviceEnumerationPolicy
      • -
      • Experience/AllowClipboardHistory
      • -
      • Experience/DoNotSyncBrowserSettings
      • -
      • Experience/PreventUsersFromTurningOnBrowserSyncing
      • -
      • Kerberos/UPNNameHints
      • -
      • Privacy/AllowCrossDeviceClipboard
      • -
      • Privacy/DisablePrivacyExperience
      • -
      • Privacy/UploadUserActivities
      • -
      • Security/RecoveryEnvironmentAuthentication
      • -
      • System/AllowDeviceNameInDiagnosticData
      • -
      • System/ConfigureMicrosoft365UploadEndpoint
      • -
      • System/DisableDeviceDelete
      • -
      • System/DisableDiagnosticDataViewer
      • -
      • Storage/RemovableDiskDenyWriteAccess
      • -
      • TaskManager/AllowEndTask
      • -
      • Update/EngagedRestartDeadlineForFeatureUpdates
      • -
      • Update/EngagedRestartSnoozeScheduleForFeatureUpdates
      • -
      • Update/EngagedRestartTransitionScheduleForFeatureUpdates
      • -
      • Update/SetDisablePauseUXAccess
      • -
      • Update/SetDisableUXWUAccess
      • -
      • WindowsDefenderSecurityCenter/DisableClearTpmButton
      • -
      • WindowsDefenderSecurityCenter/DisableTpmFirmwareUpdateWarning
      • -
      • WindowsDefenderSecurityCenter/HideWindowsSecurityNotificationAreaControl
      • -
      • WindowsLogon/DontDisplayNetworkSelectionUI
      • +
      • Accounts/DomainNamesForEmailSync
      • +
      • ApplicationManagement/AllowWindowsBridgeForAndroidAppsExecution
      • +
      • Bluetooth/ServicesAllowedList
      • +
      • DataProtection/AllowAzureRMSForEDP
      • +
      • DataProtection/RevokeOnUnenroll
      • +
      • DeviceLock/DevicePasswordExpiration
      • +
      • DeviceLock/DevicePasswordHistory
      • +
      • TextInput/AllowInputPanel
      • +
      • Update/PauseDeferrals
      • +
      • Update/RequireDeferUpdate
      • +
      • Update/RequireUpdateApproval
      -
      [PassportForWork CSP](passportforwork-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md)

      Added NonRemovable setting under AppManagement node in Windows 10, version 1809.

      -
      [Win32CompatibilityAppraiser CSP](win32compatibilityappraiser-csp.md)

      Added new configuration service provider in Windows 10, version 1809.

      -
      [WindowsLicensing CSP](windowslicensing-csp.md)

      Added S mode settings and SyncML examples in Windows 10, version 1809.

      -
      [SUPL CSP](supl-csp.md)

      Added 3 new certificate nodes in Windows 10, version 1809.

      -
      [Defender CSP](defender-csp.md)

      Added a new node Health/ProductStatus in Windows 10, version 1809.

      -
      [BitLocker CSP](bitlocker-csp.md)

      Added a new node AllowStandardUserEncryption in Windows 10, version 1809. Added support for Windows 10 Pro.

      -
      [DevDetail CSP](devdetail-csp.md)

      Added a new node SMBIOSSerialNumber in Windows 10, version 1809.

      -
      [Wifi CSP](wifi-csp.md)

      Added a new node WifiCost in Windows 10, version 1809.

      -
      [WindowsDefenderApplicationGuard CSP](windowsdefenderapplicationguard-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [RemoteWipe CSP](remotewipe-csp.md)

      Added new settings in Windows 10, version 1809.

      -
      [TenantLockdown CSP](tenantlockdown-csp.md)

      Added new CSP in Windows 10, version 1809.

      -
      [Office CSP](office-csp.md)

      Added FinalStatus setting in Windows 10, version 1809.

      -

      Management tool for the Micosoft Store for Business

      New topics. The Store for Business has a new web service designed for the enterprise to acquire, manage, and distribute applications in bulk. It enables several capabilities that are required for the enterprise to manage the lifecycle of applications from acquisition to updates.

      Custom header for generic alert

      The MDM-GenericAlert is a new custom header that hosts one or more alert information provided in the http messages sent by the device to the server during an OMA DM session. The generic alert is sent if the session is triggered by the device due to one or more critical or fatal alerts. Here is alert format:

      +MDM-GenericAlert: <AlertType1><AlertType2> +

      If present, the MDM-GenericAlert is presented in every the outgoing MDM message in the same OMA DM session. For more information about generic alerts, see section 8.7 in the OMA Device Management Protocol, Approved Version 1.2.1 in this [OMA website](https://go.microsoft.com/fwlink/p/?LinkId=267526).

      Alert message for slow client response

      When the MDM server sends a configuration request, sometimes it takes the client longer than the HTTP timeout to get all information together and then the session ends unexpectedly due to timeout. By default, the MDM client does not send an alert that a DM request is pending.

      +

      To work around the timeout, you can use EnableOmaDmKeepAliveMessage setting to keep the session alive by sending a heartbeat message back to the server. This is achieved by sending a SyncML message with a specific device alert element in the body until the client is able to respond back to the server with the requested information. For details, see EnableOmaDmKeepAliveMessage node in the [DMClient CSP](dmclient-csp.md).

      New node in DMClient CSP

      Added a new node EnableOmaDmKeepAliveMessage to the [DMClient CSP](dmclient-csp.md) and updated the ManagementServerAddress to indicate that it can contain a list of URLs.

      New nodes in EnterpriseModernAppManagement CSP

      Added the following nodes to the [EnterpriseModernAppManagement CSP](enterprisemodernappmanagement-csp.md):

      +
        +
      • AppManagement/GetInventoryQuery
      • +
      • AppManagement/GetInventoryResults
      • +
      • .../PackageFamilyName/AppSettingPolicy/SettingValue
      • +
      • AppLicenses/StoreLicenses/LicenseID/LicenseCategory
      • +
      • AppLicenses/StoreLicenses/LicenseID/LicenseUsage
      • +
      • AppLicenses/StoreLicenses/LicenseID/RequesterID
      • +
      • AppLicenses/StoreLicenses/LicenseID/GetLicenseFromStore
      • +

      New nodes in EnterpriseExt CSP

      Added the following nodes to the [EnterpriseExt CSP](enterpriseext-csp.md):

      +
        +
      • DeviceCustomData (CustomID, CustomeString)
      • +
      • Brightness (Default, MaxAuto)
      • +
      • LedAlertNotification (State, Intensity, Period, DutyCycle, Cyclecount)
      • +

      New node in EnterpriseExtFileSystem CSP

      Added OemProfile node to [EnterpriseExtFileSystem CSP](enterpriseextfilessystem-csp.md).

      New nodes in PassportForWork CSP

      Added the following nodes to [PassportForWork CSP](passportforwork-csp.md):

      +
        +
      • TenantId/Policies/PINComplexity/History
      • +
      • TenantId/Policies/PINComplexity/Expiration
      • +
      • TenantId/Policies/Remote/UseRemotePassport (only for ./Device/Vendor/MSFT)
      • +
      • Biometrics/UseBiometrics (only for ./Device/Vendor/MSFT)
      • +
      • Biometrics/FacialFeaturesUseEnhancedAntiSpoofing (only for ./Device/Vendor/MSFT)
      • +

      Updated EnterpriseAssignedAccess CSP

      Here are the changes to the [EnterpriseAssignedAccess CSP](enterpriseassignedaccess-csp.md):

      +
        +
      • In AssignedAccessXML node, added new page settings and quick action settings.
      • +
      • In AssignedAccessXML node, added an example about how to pin applications in multiple app packages using the AUMID.
      • +
      • Updated the [EnterpriseAssignedAccess XSD](enterpriseassignedaccess-xsd.md) topic.
      • +

      New nodes in the DevDetail CSP

      Here are the changes to the [DevDetail CSP](devdetail-csp.md):

      +
        +
      • Added TotalStore and TotalRAM settings.
      • +
      • Added support for Replace command for the DeviceName setting.
      • +

      Handling large objects

      Added support for the client to handle uploading of large objects to the server.

      - ## Breaking changes and known issues -### Get command inside an atomic command is not supported +### Get command inside an atomic command is not supported In Windows 10, a Get command inside an atomic command is not supported. This was allowed in Windows Phone 8 and Windows Phone 8.1. -### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 +### Notification channel URI not preserved during upgrade from Windows 8.1 to Windows 10 During an upgrade from Windows 8.1 to Windows 10, the notification channel URI information is not preserved. In addition, the MDM client loses the PFN, AppID, and client secret. After upgrading to Windows 10, you should call MDM\_WNSConfiguration class to recreate the notification channel URI. -### Apps installed using WMI classes are not removed +### Apps installed using WMI classes are not removed Applications installed using WMI classes are not removed when the MDM account is removed from device. -### Passing CDATA in SyncML does not work +### Passing CDATA in SyncML does not work Passing CDATA in data in SyncML to ConfigManager and CSPs does not work in Windows 10. It worked in Windows Phone 8. -### SSL settings in IIS server for SCEP must be set to "Ignore" +### SSL settings in IIS server for SCEP must be set to "Ignore" The certificate setting under "SSL Settings" in the IIS server for SCEP must be set to "Ignore" in Windows 10. In Windows Phone 8.1, when you set the client certificate to "Accept," it works fine. ![ssl settings](images/ssl-settings.png) -### MDM enrollment fails on the mobile device when traffic is going through proxy +### MDM enrollment fails on the mobile device when traffic is going through proxy When the mobile device is configured to use a proxy that requires authentication, the enrollment will fail. To work around this issue, the user can use a proxy that does not require authentication or remove the proxy setting from the connected network. -### Server-initiated unenrollment failure +### Server-initiated unenrollment failure Server-initiated unenrollment for a device enrolled by adding a work account silently fails leaving the MDM account active. MDM policies and resources are still in place and the client can continue to sync with the server. Remote server unenrollment is disabled for mobile devices enrolled via Azure Active Directory Join. It returns an error message to the server. The only way to remove enrollment for a mobile device that is Azure AD joined is by remotely wiping the device. -### Certificates causing issues with Wi-Fi and VPN +### Certificates causing issues with Wi-Fi and VPN Currently in Windows 10, version 1511, when using the ClientCertificateInstall to install certificates to the device store and the user store and both certificates are sent to the device in the same MDM payload, the certificate intended for the device store will also get installed in the user store. This may cause issues with Wi-Fi or VPN when choosing the correct certificate to establish a connection. We are working to fix this issue. -### Version information for mobile devices +### Version information for mobile devices The software version information from **DevDetail/SwV** does not match the version in **Settings** under **System/About**. -### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues +### Upgrading Windows Phone 8.1 devices with app whitelisting using ApplicationRestriction policy has issues - When you upgrade Windows Phone 8.1 devices to Windows 10 Mobile using ApplicationRestrictions with a list of allowed apps, some Windows inbox apps get blocked causing unexpected behavior. To work around this issue, you must include the [inbox apps](applocker-csp.md#inboxappsandcomponents) that you need to your list of allowed apps. @@ -1575,7 +1621,7 @@ The software version information from **DevDetail/SwV** does not match the versi No workaround is available at this time. An OS update to fix this issue is coming soon. -### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 +### Apps dependent on Microsoft Frameworks may get blocked in phones prior to build 10586.218 Applies only to phone prior to build 10586.218: When ApplicationManagement/ApplicationRestrictions policy is deployed to Windows 10 Mobile, installation and update of apps dependent on Microsoft Frameworks may get blocked with error 0x80073CF9. To work around this issue, you must include the Microsoft Framework Id to your list of allowed apps. @@ -1583,7 +1629,7 @@ Applies only to phone prior to build 10586.218: When ApplicationManagement/Appli ``` -### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile +### Multiple certificates might cause Wi-Fi connection instabilities in Windows 10 Mobile In your deployment, if you have multiple certificates provisioned on the device and the Wi-Fi profile provisioned does not have a strict filtering criteria, you may see connection failures when connecting to Wi-Fi. The solution is to ensure that the Wi-Fi profile provisioned has strict filtering criteria such that it matches only one certificate. @@ -1756,26 +1802,49 @@ Alternatively you can use the following procedure to create an EAP Configuration >You can also set all the other applicable EAP Properties through this UI as well. A guide for what these properties mean can be found in the [Extensible Authentication Protocol (EAP) Settings for Network Access](https://technet.microsoft.com/library/hh945104.aspx) topic. -### Remote PIN reset not supported in Azure Active Directory joined mobile devices +### Remote PIN reset not supported in Azure Active Directory joined mobile devices In Windows 10 Mobile, remote PIN reset in Azure AD joined devices are not supported. Devices are wiped when you issue a remote PIN reset command using the RemoteLock CSP. -### MDM client will immediately check-in with the MDM server after client renews WNS channel URI +### MDM client will immediately check-in with the MDM server after client renews WNS channel URI Starting in Windows 10, after the MDM client automatically renews the WNS channel URI, the MDM client will immediately check-in with the MDM server. Henceforth, for every MDM client check-in, the MDM server should send a GET request for "ProviderID/Push/ChannelURI" to retrieve the latest channel URI and compare it with the existing channel URI; then update the channel URI if necessary. -### User provisioning failure in Azure Active Directory joined Windows 10 PC +### User provisioning failure in Azure Active Directory joined Windows 10 PC In Azure AD joined Windows 10 PC, provisioning /.User resources fails when the user is not logged in as an Azure AD user. If you attempt to join Azure AD from **Settings** > **System** > **About** user interface, make sure to log off and log on with Azure AD credentials to get your organizational configuration from your MDM server. This behavior is by design. -### Requirements to note for VPN certificates also used for Kerberos Authentication +### Requirements to note for VPN certificates also used for Kerberos Authentication If you want to use the certificate used for VPN authentication also for Kerberos authentication (required if you need access to on-premises resources using NTLM or Kerberos), the user's certificate must meet the requirements for smart card certificate, the Subject field should contain the DNS domain name in the DN or the SAN should contain a fully qualified UPN so that the DC can be located from the DNS registrations. If certificates that do not meet these requirements are used for VPN, users may fail to access resources that require Kerberos authentication. This issue primarily impacts Windows Phone. -### Device management agent for the push-button reset is not working +### Device management agent for the push-button reset is not working The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware/commercialize/manufacture/desktop/push-button-reset-overview) keeps the registry settings for OMA DM sessions, but deletes the task schedules. The client enrollment is retained, but it never syncs with the MDM service. +## Frequently Asked Questions + + +###**Can there be more than 1 MDM server to enroll and manage devices in Windows 10?** +No. Only one MDM is allowed. + +###**How do I set the maximum number of Azure Active Directory joined devices per user?** +1. Login to the portal as tenant admin: https://manage.windowsazure.com. +2. Click Active Directory on the left pane. +3. Choose your tenant. +4. Click **Configure**. +5. Set quota to unlimited. + + ![aad maximum joined devices](images/faq-max-devices.png) +  + +###**What is dmwappushsvc?** + +Entry | Description +--------------- | -------------------- +What is dmwappushsvc? | It is a Windows service that ships in Windows 10 operating system as a part of the windows management platform. It is used internally by the operating system as a queue for categorizing and processing all WAP messages, which include Windows management messages, MMS, NabSync, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server. | +What data is handled by dmwappushsvc? | It is a component handling the internal workings of the management platform and involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further: MMS, NabSync, SI/SL. | +How do I turn if off? | The service can be stopped from the "Services" console on the device (Start > Run > services.msc). However, since this is a component part of the OS and required for the proper functioning of the device, we strongly recommend not to do this. | ## Change history in MDM documentation @@ -1943,8 +2012,8 @@ The DM agent for [push-button reset](https://msdn.microsoft.com/windows/hardware

    R;jWaV0WP7X^D-0HqaBMEj+!l}G<$Zy;{0O-SPP$HdcJTAqj_T8QiAKnvdKBE<`QIYok+*%d)&LfXsneEal0?fddN|Bv+-W z+6h~|$57uM;y$JjCt&6cx8D`2i+rzlSF<+2S4*K4i82|sqQZK*5Q@K6dy(w>iK@|= z_+kEWsLNLZ@cQfku*&~}BvVyTEexB1BWlzK34(0s2p8L|!2dE$W2G@+Ucr0gC;8Qn z-T}gDkdOUNCJdipZMr>NHllZP`Y>Nuep#C zyOcU+k(G&TFO0>pqYLJo3b8Co;AHZ5qybj`fR`{!Eo6TRR(*Y(>^tOGkuDS1%zqRd z9=>yP3X==tK&Ua+k=fvXNlaM62J6NiGgSX~9Myo7DcV5U-*3Hc=}B1R$2v)d@eDx1 zL6nEQ<}}HJJ^XBTCxWyv$86!a;aLqLNWMtxMSj=hTkHFgmCN-o44L4VML?&-*@`3R z5&Irj$?&t$&8cLDOb9*Cvi0dTQXEX)4b=8Oe)3ytc#(I0_=Q5dB}> zFCoc$L{HvHkkYJWLR#8QnG#ZB_PKAhj-dh|(pYp|PV6%%Z`2oKAeDdy`eau`i0a4G+{XY(O zfpvt(4^|Ka2y>x3N)zRXU4NV`mv-t}v%<^#4pUfJ+4U8WA>cx9VWAN=BSbGw83dLO(*q7 z0cc^`z+5mqA|%15|D+mLu)FAnx~D_i&ch<1WaUKU8bXRC)o8d_5nF*QOORmaZHzX3 zJsa0|go#7|_(^)W65PpzaJBlQpv%x*^v;1uspdXS&8lNA<2l9EFdKYcwzJELPDq+! z$r-NA>G$bHo1O`@XF#>5V0OfcKs0XR+8L|g*pOmUlzUO;)Y+!U@Ut7YfrUeETm`z0 z#Y>1)qsAVNon35C^)d?B>K_(j;PiwUJE8IYq&{R0lhhmn4KKsfEh+?9iB zT+J{_K@<1LFA@bq)>VZXwCNyy zgKh5-t)S?{ds*8s%*xsAuj^W8zg6&BzYC%)1CDExCTYEn7uO35!|CG|BpaD9(P&GflR)x(}70~-T?Uq24qioq5P zIfiLK7HhAkvi3PUWr7EZ?V^dj3|3qPj`CljNmRQ7fB2{9#F~v>{sk$=NVlE7bK4fW zM{xkc?{UCa969{dq1(&zdeKb>x_LAP|76Yy*;BpHwiID+8Dgrk0=Temp|(x2ZD0YfNGRdTwiC#Q-~hD?IX* zZwUzhwtIWD4!^J`QNp6!9ITuSkYIp(P&_|eVMSNVhGqja1c&v@fVt)j=TIaHo&WdB zuFaRa5D5ULb~^#f7nk+!)NT{`XkDlKu7B;f_UM^9ygy1#yLTHUe7~7m%^iC)#9>2` zh~#C&*9g;Dhg0NaH>pf9iSV0!*7^AoZ%KR? ziT%jso?*JpTm!M*hf!5eSs{6!T6X0c?W98}Q@-7H3F2~UQdOj3C3WIIx`lMEuKn2| zDHxZMEB_w7l^(?H)z8cyFmor@U3liPbNO=W>s^{U=HCb|d(8OKFMlT%ZmQBnoAW zV0SXk<_*aII0^@BxNfG5<+uEq+LERCTiA+H!%12JLX`}ZOIqel`m527rHlTwvjexf zxF_R)@p^d`BlLN~@?|E`8uX73IWF3dw4xPANbtc(<^j1%HzdEDsL?!yp%0aTIO>x;P}envNUg`j4d3I9oB)Fh{z zcAvh?WN1ieVc>>3kWls~s+fYUefL!RlPNR)dWZL(@|K)aK|0zoLVfzvL|^Vb7IlbQ z9QEg&<@T$KfBhrpl6|C%cfqYNx#q%lzF4PfH>qnI^ZPo&k3L6C?kZ@ZCuyIk?+GPkC{OA5)mi zl`B89)5{u#q{EqxTC~c4ilf|Q*~k!gc6#x(*3DJmpSElFSA}EES<(o#jZ@?)X?#PA zb2qHHe(PNtkbX!qOkGSBc&!-Yt=0O{7r1wQo-F#N^5ar?JR9ZoMLOhlb-OtMF1HBh zkj!>%s{{+7mwRf}mt_-3e0qds@ee#AUC37=$m+Pd}Z6!Nds>dW{F}TDSdiZMBD{{eH>P}M3)fwIwXA<$(q2*3;?&=SJ3dpjcdL5k{ z1Fb(%_U=<6cTW3CavCT76)A#+y-Q5{X4U~XGVMTG99_R1iz0EG2fmw{9;N;+N;Uz{2Nb70rHEFM^}HsOwc}BI`kTy7IT?G+~}6zxkUf+}!?V@;V()sb@SmTGRI}6y7GiFVa`~3*4c$)Y@gGxjUvha)%4BEWluIzW+p%X8xL3r{X_G{xe#q?Ws(NuXa7v%%y_Oo<6N) zTar5s;9H;gsp>*T3Ka^Qs#Bq!lXPPrGfrFS4y+X$`$(_<8n+(!O4`W(Bs+Jwwr*ta zR#~y^MLuY)*tGqPxa$`fa!j&zqUKIxSynmwZ1<4bb!^JKPb%{2zGv00U;iZOUXfz@ zy>^k`SRj&Rko0w#)P)wao!Zp93N4z9-wMzYeYYsn<0D=?kPW;TP}{O2(JV+tnjSy5 zTtW_PJY4Di_R<~jweN>rWgnE)C$C7M--k2zE@Ry`d!9JCpf5DZK(y7r^Zf4L?Pcw} zz-Z-?mHv{-)G`Neb^H6kOwnG2BtzN{uU;CGy256X@ED=Re|(N{K|+c~|GC7=4YB=* zA{JLqxn@0J--)S~-je&r%%nuU*^PVy_nfJAYSGIEuh@&I#Jxe}6Zgqt%Y@4xLw1Gr z7D8eaAIp&dB^(9rlCzsW&Zcww5tobjS)JY&_K8B~u3UjXpu%4PMAnE=E^KVDi|u#2!DeNaG*R*KPkY~%cv zZ1mbYfTN*Bq$9=i-v^J_`OKRtCtuLIiBl$WxNa6diFsVFrgZ}-M zPkI8%tK2~3%KY*EyztmA7QQGyGh7nFc3Qxu;G}o=mE-NFzqj~VTCI?uPwyu@dM$BD z8v=tl1KS<(H^0za48DQaOt_KEbnSkK>XX;(P)p=vC-q@#1Du_9EXjRgfd9%`cvUT0 z3)eN#obEp^<&fbF)AOc#VgPYy%J7t`HLdq(#yy1i&-VaqSz(jG<*!RSH-F(cdN-6q zwf_{}ycd7>{f)O$u{`-ZB?(nNcdllAS228ifOS=)8)0pby1`f|FB39XMjZ2(TCa1q z;{IbYYjh$1#qHkEN8YEg9cF$37u;o&EK9Axw<;+Ox)(#&dr6Xe6;0FQ@4d-vbSvCh zwpVg;i<*ov{;3u_Z0>o3`q9B-zMJzYm5&7|$3cayzFGsUh6y-6UIxj3h>B^AjV zt2K1%uBdE#?G&ui{hB7@i)#!1vZi-#z5+`5uR!k3?K#!YO}-Mc6`CV2K@PZ!YJn>= z6U$`{nZPb@%QNASB|@Q28+pL%u?x_a?#og)yraolt#4R50ci8aLmfzO{j+(1BHnwk z8M^iEyyZ5t_d(d7asTSPBG~=$t5-wC70f>0vP6Pnoq3)&n=o@fer%+5R|^#M&9$iq zIVqH~l6h!ls4hLgMa4B$B-#AKowj-k+w2ukq!-6U?1u2n?}>1VY-#{;4#zp_J|}B)aSn~nU%I7T&g9&*^pT)z5`1)M^xWvu-;8eLw4MOB3v=C^xAA?;@ZJN?=kio*>dtYl`Ism>CAaL9l*3<| zvmkjxnrr*>2a?US&af7e_}8D^S{Apcun#mR4@OMYM+-U7=Y*W7?}lGTx&=JL*$Qf? zxa2OKt2G?RG@pFZ1MW1uAWsc*I~Z|ePn;q9ttivFQw_m>4GRAd_MF~dr7pm&w=A-$ zsi`IyzXMRZpY%Q{h}=naJpw=flda?*%o@FI5xngx4l@|t@&QPR%q4aKbz5ns&Y9); zy>Rxq$g&^M>FgWlgm~@;uB`wSqAK@^XW@cC`-7Rs5J=SHD~5A>STiT;RpCcc*=!$?_lE$p&C40Og)s&pY+$pClp6{>jn_JLYpCQ}Y#hdRH@sYeaoe zot!HLX>QW9U9q!@`ZM0oPhYDDIiz=OS^TP_x>0)#TKIz1CiYy+aMs_0otuVvAFZmg zwS53I1F--D~ZlJF?||fH+G{N zare0+OSNSw2aPO+{0|(bEfn!Wje};syV8sz9{_5AG!_b^c%%wuaf0DwgTSUYN5GCL z+{Dzhdyg58RkmY_bjWu-nk-(T|3$rwvy}2V9VvJeJqHkK*y@(rvT5nGrd=-GIw$h3 zs2$hhUY(%lU8dRDuX)WowKTzNeK3nYR@P5sY}j&U6NYHo|}C0D_;Kn^M(qE|B=_r3K$KCM_>3I++;c($CrIG=XhtrOg?npQ9vFX${N*BED8VYe zavLF`J#y5t$LUS+za(>8m49TeyDR5C`KxMtNfSg16!6$yFaqi`j`0||`&R~8Ew~Le z2b6KLvD5*-$##u=mi)MlHb%|`lG9h^b!K^9HiS(?$|DPEfM#QE{iWZ)ux9T`tpQYj z%9VWxBJU974W~GZDp_*4I&^IX3IAEptRZ`|l%Au`2+%nE|020_{>A@yHQ)a(+=}{6 zMV${Ey88dpWOkizI&1vz8bS_d-~THllmAOB`Y%1=?f*@nxmlh6Z?E_CGq5G|-)hi* zd#S&g(En>Bx&J=$bCqfJ6YQ9$D^!8GS#_~`~U49ciisIzyIGq z53btO)o}kG&;R`_y$6=}KYSPPnfYy;|Ns0u=o4}THqyZ*5FP5$hB9;UU9N!BXWG7B* zKvvzfFTXkv(@pdMJ^QtA?nko4HtjxdO0US%jOA-(BL4;mnJGT5^ zHnpg>Z`WF}wYb5N435jkZ>)ijo8O&9K+iwk=l}Z^exDrr&!-%E=$IHN_jiEM??ku? z!6g{`Yi>H2==FVKWe|A6&P@3g>d<@5P<7@vuurDEhn8voX7Q}VfQ{y*3xO6aLgg=77k@3_W zd;19;JCea0c(xP$LCo0{v=jX<0e(^q_s7@35Ogl5UT5H&B_7PurT^H-s`;N_von2! zu*N^$vAVy;Cf_s#nOEh)Tp|8`l`feTy&;cjvp5+rlCk;VLJR^qiexV2J~}%>;QNSJ zHW0BbxYJIH3-f3L@DH$YzG}ds!xGv9n1c%VQJw{%i5j+{hzUX_=M#tMSpzrgxJ`rh z3;N_yZIK}C;V5h+kPW)xgb3bZ@qw;3xdb2H{dKDvikgMq)U>nE`p49SX*K_u8Vm#2 zN49^}{5KhB)+Ux~uSJODehZx|0-&wAs>|>~I(utAH5B%L=;fp+`Mj$wISbbLyN97ucdKi%BC^v`*gA-Ow;m7ke zxJe8YiSlv6@1Ph)**aF((7n>(|7}!2F7y|?7OZv`_W*-@7u-Ho9MikZYjN@%^SI>? z&DGLQLQK$swTNFX_F$C2LOpK>+F?U|5$MmCf#Y2|E!ZP- zzhO+wEJPkDPl|HcB_sU1uYphURL|O`p?Fm1DGajYGYU-jiFwi+8W1iV&{p=3LVF2J2m2aI4xnWF*9 z1r-@#*4LLNqHF=+i$#L0Xqh_5N!MfAuH9>OMVz~5PH`9 z`5WG|RfHUpnGKH=B+f+!5xfwaN_h&s=pi#nOz)$#|Fpo6JaY3f&S-(~Dy|%YXVu@y zT1WEkE&)r&Hf!PDZk<=MR>_&e@TkETSk_lD4ZeVJk`OG~R$NfK)8UmIn~cc~z2tCr z2f;qksJ{rZZv@B1V}d+)EJ~)22;^)K42(Q@kBlw&?}D1+&{e^8OMSsx%}W`5|B4=M z=^0l`|G`6WEEJMEyIMXy^8J4E&NIW`c7$2@G2@QJ!Hk-7QGRYdaZNzSlgCkfSxgPI zB1Vix_#G#}ksTXnp;JH5cpuOi1_AztY3h~hcj-jA2x)Nbbo*SVFkDfV0!g`XF?*=^ zu61^tm=V!9mz;_Fw1VW0!>!of(MaM7aYp81r{4xV0Mm&N!jp7$gK$0(SGfafwf_*) z^0AP-SNXVIwhy(uHK+4IQEYdgAubi#%TFn&KG5$HnX@$P=Mnl++qfvKNq*R~x!}qG<7-O&CL3{Y&iJRehU4`c497xRQ}fELV_!BDUqozslSnnZ z@#o$8xKR14w{}Zk>p44fn2C(j{l?*0)z^=ZgX>pXcoqic%;}v05;Ast8jj*coK{f> zo;BnX7P_I<<_Ya!N^)4-r zP#*nqAWk*xOibqCBVIqcG|!55?b@1m!87B@_hs{3NuADio|H%f)BMIKG~rAiqn`7{ z_wKc&vlU7FvLK4h2|=}ld5?(6WIqFrs+M?V^CB{jxb%sq*PHe}M)QiKLc80VL2!1a zh}$Gqq}}yO(D6ton?rMY9@j=Rq~xW^>%_3$BtD zlipRx-gwL<)nq9RKza`;BlS)8vGH|x21+-D@MJFLD%TIfn>Ps1i=&2@N3$BeZ5Y}z z&prE_CB#`fwSE}>y%y}ed|}c2f>xk{myn2vvTdq~)t(2k5U&4tG-98Q`6{n z*PR;4Z|8CF98UM4h!_kA`$90e(JKf^i}@R&P^L>B#+|F4@a*79$)kJ!vyW#!3Bpwc zcSlM|I*x1s6MK7txNJuZN%#di(pv);pU+y8d@@!Pg;>LwcfBFd!H)-mXYph0uedEW z259zr!f2Ci%7*CQ;lB;PEr~O}-*9)A;m-XZuMlfF3wy>S@U18$4X$~E{0n-fGSjLk zD}pw1D18g!a$)M5*=wzFq+&M0%_f3}#N&eCnO$&=hT2o~`#GU3tGk-ntXOsYy9cqO zP;4%9`xI;1kDo|BY%Tw1OwEE0!Il&(>q~2E`E8bUURX9!V!4P@e{%$$&8PRlrhtNc zVa_ME%drikmrZmvMZ#-~mo`S?Fzc_hTe zzmHr1lb+*$pY1R# z+)8+qe#A{gY2AGsD>wSD+_PdBfPkSRJ1L-oV?m2;FkRwjn`xY`F=p?1rR!c;>F zzhzQW=%6L4zBgSWZG5mBGoe;FltTU!lH!cqg4D@_SF+b;S^~ewdxP@7&u}*Ty3Z)x z!Cmq%x#*vO(hzM_{q*U{-1jJ+v}IF1SmK15%{TL`@9Rz$CUXKsj2|qg3z($!XOG{> zNgAxvrLmgD)iK`Pf({*y8)f(7WALx}H zHut!3{hO+{pD{3Le&>#v{wwo4edlQv2s78xxjl>kZikVdP`hg;06Gp=kw1zWg`$8I z6d4ckhpKP<4MAA&?v7|5nILgraTLM)4@5H6JX-cdBl|6UPt<~u77M2Z)Ik@dcQJ&K zzVm6sfC!z0?xQ~n3>b-E!iM=!3R@tyAWyE1ytTa^Ned#>%#2dAJ^EQOmmGjI4NlEH z@d@6rlEZPTRuB&mM6=NhASs{D0K%N{IzR`ILCtk~!LPwaTO>1ZfLW8TP-VNmCU=z? zf@;(?TKAYA*XQrkD5ZB9(rWS|wovY7*zQrnyCr2}x5a6;2;X`!`UUKr(?AjXvP{$n zKFJyKK7C=7d#s5xj~7iD$XkrLP7&aYhklk=d41h>HjOYNv^f}$5rF(1JXv@(&Db#-g~}!QnMQbrwzJt)~P8A(&X3{X1BCsYZjVhP>3m zr6gJQGD!V8QFHmZFQ;O=!0N+I{#!49RSKWeXYrU5A7SH*1+&UU>gd(3b`ylkTW@!SR#PTJpkvN~2d?&v0xk(qF7>|HEZ;$`v&Cn!8cb2UUSj2N zRkZm5Pj~Ni*Uec@jgnuQ`CXIie{+73f1!(w&jM=B!VeKCA5?s`6ps6o9<(7!y?`Qs z1tga*=C|#1#miY+z!`&3F^l4?XZgXiHG79&2W7R!4Dly=xrfZm^s|@?#KA-7x9>C2 zcbfYqF+LyToZqb$!v)=MoO=Jm&+x5>+;CQlf87GGmYfkXpZzW+k`)L zE$r7^o0J63|Hw7Ua6Mf>EMf|Yf2R6a16%E=1q21oCfNM;p`FKvd4bF?&5Tc}i3Iq~ zs=j>eVesT}hk&&&<@zNMenJi`(#G8HMg{IwJAxwoBvnXkM$elqf8A_$gDTad9dQYc z83^_h6}5qZ&UV?b&+uMp%o5ArWooaO`o$7*U4o$C6t^`j8WD`aPcMhxvoLToq8|;K z0?iG0d%7IzG_5&v0B;!uik?=SVyMlB=lCuNF& z<89KG`novoghndHIPV=bi<$PuMtHC9XGTxtCg+OLY>{<8>(JQtIsd+a+B&j3{(k{5 zPWn6osBNe(Z&HsVO|uTu{fQN-9MD=1g|euZ+8>*%55~7)2(8RO1^4x);VABKYCje zZqDI-_OjbAZsM@0VV=)*APOu4t$;BZN7pI-d0yM_ri$ery-9>j2kR)God=^&&iT@U zg4QpkpA~T32|BVMJ{@hPI%Tl{9j*``!q#^VzL6mUM+SJMCRKZC8WB!z85~6 z;m8yvDj?|KR3qF%Ak#cLZ=3KgA$QnXHzuGL$JdVZ^1)aD zLU(h4Y#->;)YEFR1*~YH{#i-z)l#0!1ZtvIuGXiGT5iT2(X%gKec=wwTc1bI1kL6z zq~&S3-|5RMlrwW*kL%QEb)Oq60`?03F4~(*{=F>AGxw#DK#(N9Q)rtne)SbkbF1LxfEI@XauK#9>|1OJ3u@G(4wKeSwPsf4M66 zD6+G}Z_^(8VEkUwH80~(Hj}%d-=!qTSAO|lZAf!M#5O-=ORp^$=)Ol#SX`!JQ`V@* zlt}key(X7J?jF@op_z_DUCzqQWj2z|!X*iFxFB4zg)er{A^`a}DeJ(%1pnr>#gL%m z4GUtt`I*`g(6P02xy_F|9TB2=7>rWqRv!q+X>0NL;4-=+y{p=5P2JI9;l+8i6x(0% z0i5(A#E$`_*I4*+xmO zM>|Ko1b@B3hElElAENf}zfPtW=Rx~0u#LsTVK9j3AsB>Qj`Y8t4?#4{oaZuMM$ZGE z|2Hk7XLeuLvx{LZohT!(7)>`Y5ckRwX{5iL*_3yaQ@=Wtqn?q8l1ak6YcxrcN&+Y@t|XO1Gp%Vn>pkY!p|mhT_By(Pqty~y8bBK;Vj;rld1J&q)dj6}FyYK*>t0hetD z%~y^|-D*Sq82DK@@>Ade_ety1YP(Tx2}bL&Kef5ADgXxDX@E`}Kl-$%bs|M2P6(@UJuk|_*=pW=Es9#H(~ zxe#@OTb6Y%x9SR!YV<$H^*TZiZS6s&vn9&<#Cx-LvAMt!s|Je;uh;KA^VT+ zzV*iZxNN$5+a94(A9>G{QvGy;_!jYVqV0y<`kzTvYRIod<0Sl?Nz906@`>sjSbyG` zsQ%){yrO2C!D;%Co-{vp`SY_x>1C>`h}jn|C0)Do5xd6&r-L%?Zzh#TYP6`SxaZqx(civ7~ARW;?jN{dkMuQYKs)n+RqJU*GAqUYrCMRu8-GaG$Ki@T=cYNK~ zy!u;d@5`1Jz&y}vMvJaHxyP*S8{bsenaewzGvyG`JGSwi$T?vXjW<(;Gw-A3t}RaK>wmgG$==<+Uh4q%xjzs!@ad5fea!<#LS$k);6<>Nz-ZscE@YFf@-Q$32auVYBfKs zmQkXo0V?-P+IuAQDd$e?oQPt8*W`G!&6o5|HvMc`JW86Y;t%A5!k0#a7`OpP(~V&# ztX7PMS*tY#PnO(#ahxk_*D`PopoG|b^K0`{mBE%mD$c^$56XK6`h0Q^$KAq-x+b>I z#JXWcJh|O6eWhIuK?X~abIPb5R}t>=5o)Q-yq7QhA>hXRrsp~g1V32Dqfam0dw_;N+%6wFL{}E2Lnk^vkO+;aP)`6>w z7*W^$T}Fi^EK7A>;-tWcWA-D;XnwAE&z^K%oJ@CLsMxhAh-X5oTa+DBDXc_G!{dY1 z#Tu%{Nyh0(TMo8a)xD|doVs#PUuCQ`mrzXdM;dswZ3c}2SVvgPuN}3>??#=c20oI7 z^t-+u)7>g6PWuv>KJ1NCW7RfxhUU=Xv2b)!+x0EuPXP_QGPsM0ySkq;d4j`s-wg!v z^~VP!vQj27s?Aj_M@EJfDPiE7xSCzq6JO%JNy&!Lh3p$Kuw#g!S}^rs(1rr@c+T!J zcW{G3v~!f$kdfJ1MW9+qPxQk%{_8i_=Huw`aYuuL^UOiD-o)?ZC;pQ~Hx0jX7vhBE zD3;(N^_K&EB>ELBU-;b48wm61O>xPz%(Q2%jH%7wEPQ=C4;_)|byR41n=Uy;@a!jF zNUb$s=R>v5S%rHKN~f8Er?wJvC$zca^L@8gvz^=b_GLGQ6C8^~+KJ052=Hd#gmW(V z8=Yj1_cw#W(Orv(i52*k_mj^eNf@QPwjWL(YC~MO19k02N*{6=B9oPtI-?w!Q}r*f zpYcCvI@lInR8FVpKr3+4SbXK(R^#l3b-kuyMjGmcnH-14J=l75BCSvP{M3FzD(1CN zfDi1&F9ordw#+u#YLToPgY*xLiG5J-!szNT@5QUbS0Vn}4=cOont3ZbAD-~06ZVjo zDviw$jh6KH*Bnfb_~%h(;oZ@O;}kEh4d`4$cPdfNuMyko)A%prsfbR`)`&WFntO0? z1+$sJWTi-qa+SKObXT)ey3Lm~B^xUvoZ%q-Pm6r3`XqwIhfO$5Du#c)If29IcE{^x zAu(|DH_81{&AoYZ@d|4(@W9Q7ulB-vDnrtA!Bv868K@+KVWQoVLcMfL=W~-x`(Ne{ zKbiu*g`YwI`%q}7B3C=o^0e5LZ6@Rp9%3Bb7LdwuNW+y z>fT>k)^?Oo_uAl|kX1KSo*zi8R1s%4{tAn=)+op{pI^v0;qyS1T-^kgyedfAmZlC$%AMP?3Xs|DPSq$T-J;o{DVX{^L?|Y2unX~| zR5?jJ)3}^ZO9-~d%kkr=VOw!GAqfSY@})tr?T2vZk!Nq}K1WYAeK_LmDG6x0v&2tX z{3FIYv(YGS#)-4Q;|a-ApM&!tB&!mp@qsPeDB-;kjvx@%J{5*Dn?pmwP7M$`k4%iS z)fMO4Fn{!i_63;cG-HYfO+X+fTODE5lP)d&)3D@G7pazkUrRqFo93ODU8Cm^;hNIN z3qMBQlnL8uFc6_T)g6R1wxKpjk>r8Rr4tYgN4PYt-nrL!t@;#gOsmPj++v|T_CTR$ zYyE*(&YAbNz`4W0^STbhE=5yvi?0R7+_2z7f&%UfWf+g| zdd9vsHQwy5FWliOd8bL$CQR#jR@^3>4rkP7cl%QLQYxa)o-BdDuj=7$!}~dtQW14T zc6CFqKG>-19xspB35>;QCNlIOKmW6KxRy!g1CHS+y5ok#`IK84S#)X%6sip@tU4wy zdAB@@76ejw0>;T-u48X)Pt!MODoM>O*2ptyu8hbWei0kN2<)$!)ayGg7=A|0k`l7Vi-C+IJJP z^KB!Jx~WamhS-iWZGgb%rk4=SGba@k9<=K`m!Qd8WEwlrsw{q z(y&uckc!(0-mbM)nlVt=^+k8y1mZcc@z8?1Tg6;CV3kZ}E^vJCdgxC#9bvltkQSb) zbP!(lcP7Y#HoM81<&_lG4YO3gZWBJ1e)^y-Oe#`_4^mhhS4N@Wb&FBjM(lJ5k?X%y z$*s7vKj*a;iVxWHu8%rsHbF-+2o zgZMp(qO85>LL*CrKI|L$^@_&dg}Ps-)*Fe&nKzt#3!m9I8euVKk2>=9{4P z)9ERE5!&+lUfVIK5!Zp-16S=VIh$=4sjIMD2~{G^COkB8vQ&i=mww+f+kA8=YBLCG zoffg^-Qul4&Ync~A(jL;{a_%)oYmq4xdqBNWj@tWbr7xhE?TgMR;Ce@Pu2q-aHyp* zHmRyEC%4t#!)nI7{=oJ9?a4>=H=5PAI`mh)Z(X|k=EvL`?_1NSybd08hJq9Z*rGP) zG4|){?k7|3*-4)>sxqE2tJ}~ruRqB2PHdVs8+u#3N6(T!<~ZLv5H>A?8gn(N3)s3x z#Hp=B<2k?`<;xD3ft}uR$(iB(%?LtzeV?Htc#Jjyo{Mjdk5)ymhAno)-ywzIS(Z#& zvey$`iZmyNw9$@{?N>zU%(EE#dudKDCV6d$(ls=Tw+lrqL?=yZD8^AzXXh-;ULo7> zaeOf-v5`gM9Y*D&Ke2ZN4`nSt~ z@n8Pzg{;?v&RX^5t>&AG@X+L!i%=+zE5GPfPS1L5KK0Dx>vf&^W@+_O6I~cxg(7T$&EGeH;#??Pbt1VH}j@q$*yjNWyndXrOStESUje;27tR*>Ix zv)4ZC$xYd%%3Ba`>LdQ$MgM~3B0&wpvnw_cdio**TaUKBHd}g!%yVRRmOW8AfhOmQ z=y1)6qE3|%x!$WdSR0XTX79e@{D4jnmd*R-+p-@&cnWEI%}@6l0G-WJ(O^xk+u*LB z&mvA6Fz56yFM}3i-O|k`Vk}&aqLptx)Ra_N3K8!7mS;`lA)l((DbSEc|~9r3(g>DQ|wy=!lt^xLnLGsB)C3LUU#uKY-eAE! z-q|`;c+li1(WR_zI6kU-D~V@V)rPK{JeA#8WsBn(lRHCbb2!}LITvvG(Yc~@-?pI%~T zzHcx_<+CG@+PedNXIdf1@Ms08r`Y{-Qv#K14m6ZdH#|6qD}o_{n}0f(xT z!!5>zGsb^8hOAvFvuB|mc$ZZQVzvCs= zWBufQwwcq70OlI__A!`7c{PrNS$8 zrP+l)T#rUMinXpo(eKs#14wwpb2=Jy;R#pq2|v$1o=r&9tV4%}K|3pKki(~YzNp40 zhLG~lpJD&^mQ?2gH?WUfnx_oS%r*rvX$`;68Ym|i;Vv%BSL`is8% zP0vyBc~oy8VlykMJN}$UcP+x+4@A($QztFx@~N6YySDV4_zro?)26J?8*eSPZCa+G z@zST8E(y}hy}u)~Dj)mfWZkdpoA>`B(G49)5K&y4swaN}xKzbve5aS4Zo~73N5}|B zmqhlHVEnTfg*fMZ2UAYGdGc_Cq^Q3n^W2&jw!p%`(u*aNR@eD}vv`W{G7DMIo@2Ad zfDws?qu5ECW|ZoQ#69n_u$b4!ufQ5p5H00#ftr%h5HFV0>AHd;A%$!z)Q*Qb0MN}I z30h5#c7_>@s$f0dL6c+h3{L#EZ+OA&)T^nG|AtM@U_F@LVhL&k>NA_!X$2ZRp1cXp zcKXPqnS>|ur(PA+$YPua4{T5ni3@o(>kOLsrzUQJ#8jYuedn}q)%f$F=%4#++P3;H z$P@SjiMi1-B8tUU3tas#75V*B;IdnDGr_?PRQG;4pypgeLTa21XvubAZX5*&XOREPj z##5LyJF5w|wDG0h9mGWW%vF|8KP-g(lDYPD%9_$`d-k7cF{ea#-04>_@8gVKWvhEm z?vQXJie06ToX!7T$r7Wc7gxvitw+1&#hCBI6;}{>ri^R$_a{GpRW!-L&*f3XBsPJ* zmjZdzH4HuiCZfckURG9{J{c`iTt?sYs=rpF#`Uf-c##VB2zCTNEJAX}>yIVPT}d{V zcnkO4|2mPQue1k#Q}aPY!?0y5LeH5*@0OEJe^Sp7_Lmz&R>{K>_52j~ore?j6|}Y1 zRKSS@tBWO&jU^jtJ(pHOt5rgs?3@a#8`i+c{4ge8Zf8)^3|$tv_*)|RD|}Zo)%5Fr zpc(-UrQ>xE`K(@Z+T^}RmAvSxm2X%MH+!H|9n`%Pvz;|fbLx?Zx6Opbj&5x^+NV=I z&1`!fibxz%I1YNjh+*erQ#~$RF=VDNXD%qTI=;dB$SLRDLiI2YCB2xtu7=F5?iqKx zArU)rQKkoUiowt3m)eB8piui-O*#wtxQ=H9oQ6+lAnB6bOVxq1x#bUl5WEw%H(#zO zLk%%%0|3yrJ^1<7Hx~l}{P_uPy~YA*-jLg6dN4Ki`D>|;@Y=1wqFUmt^}LcKvRh=$ zK%aNJ_^ix89a|*ry;Li#RAp@OW<}ySD9xQbZ@s8~UqF3{eA6bmR@S22t`nTX+{VJZ z?6{g18@+~pkU39pQxcPBYLp3k0Z$n9dOns6IwQNgplRQ)4%pPDU@A-xj~rorpC`QB6T<%rkEe;1o_`z!Z19~e7M_}XFAP} zv~gB9=O|+kqaH{JutnG^LfE@|^|`Ql1BO4F`R81R%;urY2p!L5OQn#-0O$6Hz4{Wy`g0Y*|nnuxJ#&RivH=q=3D#|+F>8ZLimtHjxQ5yu=18TD93>R&or4?pO z+7Zdu-&|so>%H~-_>;H+V?i8pmP_zhD7vG9zzb$5JMJw`HoLZM@y@>UXGzYfk+kga z@W<;OGA=4Iy2 z4yBV^`qGh|YAHCWL?aerVbHZUY7W(C3&>J6EKn1x^4@>!6Xum}VX@|_QuI*m%W=3W zMQ}S$z|DLkosVrd(=rb{Yr(PZh$z94rJxe6tG3TF475ErpwGtChAQv7SY_;12V(E0 z^!uOLqK;L@r~(_By2zsje!MLf#ETa8V043iJ>&`)S7uVO$vyRJzIj5DB{q-dSs2y* z3v{{COOt7^4jY1hc73eKb&$NhYwVlb6+1zbIDS6g=+T;T~21AjsfhGN7O_- zo9d?R!%S02zNx;IiTE(ra~l=S>D@DL*_yY~%y35;EM*uYzpr>#$aGY>NDidBNE`M- zt`Rg_GA}-74cau?6Y%q`fkUp#_gOENNAK15LTQst)oecZ>KPB|lvoo!A~f4k z#P`P3mQU>L_0=ua()6>xR22DWrxe0&Wph>u=Equx>f#bp*=IkTT_~0q2@$Wp{j0KQ z`>nBMWK&8_QP**k`c!NFVi2afNrHv1QuIToa>KtA z)i9*haW+KhIyAS8nA{K3R#eLOJ`KP8VSd#{GpRHCrL~mm`oLy#=VGn7A%3gmU@S7| z3yF=CD*9#Cl#WWPa+T633nWcS=2D9O@}B> zW}#EtN|WU__c+F?)yVCgsRCWy7j8)-Z3_J{+!_$iBjjLp+pOnus@^DUw_R_v^DQzn zJx~^0yH%-Ha&F-L6V4DDbVs%e1b52Vz`b}tW*}|Xg(@|3O{IvHc2L0Q`?Rlh)I9y0 zd){}s70#-NMN8Zd7|rh6cvil=>hUW}Fzrh`aXDD`LCYn!BDtv4ffhc#QhKV}e$u+R zKRi(CsI@R+U9pICc?Sy}nvUS9H})*%J@U2*gJo_lU1%b#$t6K&OwLV|qWLSJc|Z%IwHf(EF3WVhtE zPz!(Z=c~10m<5wJD~Y%1WOcXq4|e_HpV?Ao%-`e@V;KqwmxjD=vG!+p(0tlp9UbvWd1x=@x-CK>Jo@wV!3P)CO1o3Knv|~;oJPy< z?VikeZxPpmAvPfkn*1(Osh*|>IU%O&7ItAQ7b4oO6Mk%Q z_$dkuAQ0meZ(o`;x!SKwU*#{3Cuz9n6}DMaTQmMJUw*m_Do=h-%oTZ7%oYV0udtoD z_kdsW2w};KwmQ>oQNw2e8w#;qa2u`iS@P*yq#kOsBjkWtI{-suwjIgz9gb}fgzPsS z*PJ&y{~x;E0;;X8YZtDZ3KVH^=M;BZ+-Y$L?jE3MAVBc~A?+zrf)!2i;(_2=ENP*X zA}tV{Acf-YF8`+Iz2Enad&kdUBpHys_gZsJpU;}>+6|qMxByi1r)|h!@sf_z$s{i( z=#X-T7Jg!ewDj&89xT*s-dMzMVW68AfM0Q39>m=Ad-I;tly7#L{uvOX4iENya^6*U z0?Rdxc?a&dVPpOi*}u5oO1Py?6EFLlKo}-HQOR)Slf>nvkuPUV@_ z+*kHaXn^pI=iSv(wvL@=)qxXnn_Qmc06uK9=JXCB=VVYwBS$KCgWa-WvPedo`nyG^ zYo^{Abf{?gux!fb!5npTV zvGYx?4QX!zJPh_N#pBhHIuCi1kzy%aI3%^o{-^2~s9i5Ti8UCflewxA!@CmYVj(Ga z*EeT(B$HIm|JTSzAtR7)yH!r`HYN)7Qr?%U2waEK;w4{HbFpd6aWryu{ARbkSDYVK zq{$9bchwrJE-|C5d2?phD67HqG1ztFZh^I-W~yz~q>G`pVXqxIRb&FhtV^h~NO|tI zdsHAqBF42deSh;O6X6b1FA{Tnhy6mB#k%3r#?f@KdUa5n0~)mSj9y~`<_)K|kknX| zdX^yDWh=fs9OX}qfQSYgc38g24O*ruJGzaLUHoe%>27)c1`Z5WHFz{K42Gs_k!iH1 zgL1H9RNj`S67(EVy3P4qucf}=LzT3`s$ZIoCD<7xqoU`I?&N-6AKUIyTlAcdHTl8| z4jT6Q(0JzbnW8-N$7|pD2V-wC>t7hPG5A6i4cO}UQ%b!j(+tPLKkh>Eoe$d<`qc&< z>k2W^mku5zlt;-IMSE9vOBSVlb^T|czJ?_H0NjyGY=PsC)#rc)Q)u5nz*Vg<7;ELJ(<>Nxfe(? zc-a)Vh7Nn+;?>^y*V_EFx96I(moz_JcCUG)zC4?fZ-IYl-2)B>{-;x6>Zm_%3v;C^ zKIM0mJbLwOl3+AD_$TFzc=+*W7^y6s zDEp6~?Re=WS&@SjX+aERVl0XS9iO|DVGP^S$<+%*4F1pqJhF>UDx_epRn`+>(Tx0U z&ZucqtEc8eNtc*Y&4v~I&a3xrREBGfuDrXKh;8GP3BBHtFaVJZ);GaCH(+e zkn`5dNo3PPV^F%GaZzEranD{2^7anYGpBV0DImu4s!ZAF>L9f2#GGBtb|vWNCz#sO z2_UO{?rxG9G&fj1!?K%AZ;f4U<#7Zu?cn2rnIoMLzSEyu6S6Sd>DOLv$k7asbF8ry zyqz=15Vv_rJZDkv)vZSb=d=GmNG!h`vhj9pl znICc`{Kz4+c$51+_%|WPWU@xoazrul0ctg*;_e(HMNTZPxW-D)k4oiv1ekiC!VRU$q#7)L}%N4586um8!B7PVH>PBpi< z>u8Mpr?r&vJ;#~7UsI%fYUv4^LCXU{Ou_T9&CD$;^~}~lDCcA?vyi_d*(aIlwb-b4 z9uLI-hV~MzhOjfs<&h6EwvGUcg;{IA6D$mgvAj~`fjs9@1NSzN$IF!(R9|zD`fgB6 z?qjtOxixu`1sG1kp{e zZDRH6jypLde*Fzk(04~01nsl?IUGR#uBH=$e+E3kU`F3r7 z>+A9tEd_>RpZk?7mu$YOLcnhB9F`y6o@TCZQ%SY;fH!>tKH!JGaNbftMdPwxO1(V) zx--*!hyY|0h)m=84f9`-%6S3w{E;EM1-METtt*GzgYLppPxgMMdtieOW%sRpr`}1v`)H3@v zNs+n+A`7c%Iok7<{u>n6%&GJ&CZ=d7i?}VM^`C#xT=;2y}=2#yY=c%$vfjhSkSt1__ z70Cbg*=;ll_UP8Sh7>HdM6f8L)Q)8LU+iVLU(Mcb_|Xa}*^-!^4D7C z>;ESWZLeCrQGFX9EzXV{#<&n47^KFq)mAswCz@&1FY~mg@9Q@2|9*-Mns}plcr^yU zI*z!~mD)`Vn(+@ldUV#?^|rlr!uS=|B+YN$x}LWiseK$FuZuB%U#eMNYZBIAeQqsU zFwMUg)qaW3uUIeWt$fbSmxs!wcXsVN!3v(^w$SC2x?T9#k|SwWTbmO4jpQNBM%~}A zR~=MTiEd2$;@w+execq=+ys<=VL;ksk13c1%C*TkAlg+nWtZp=E|>1C=KVK;QhBzx zP-E8<{li4B+PenF!v~)wjvOWR5npSUP^Yi|3}D6k`R?u6+#RYaI~YdQ^)IqBf7*h} z17wo8irQknf5|eD=-@th$$Yjoz^Zk4{4=ieyj+quhy1q|<5ua10lU-zZ+T8b;-V+Q zqaU7fs>3f{s7!3nrds8f^V6E^Vi=PfXaoR02?|oTvgkp4^{iFz)i zyHOZVOX-(YdTxFSEZRU`l}kzi)q?4UzO*NoI9HFRjfi-H+A~qu$Rv;pIdmW7cFH>I z4s~y+P*EH_*z|xAb^{J;>E9#LTT$!TQxyObnu0{Zk&{nKdukDq4g7w;3`n?<-bOlCxPCbzOK zT3tC|S1I_-Ci!Z(AJ)Bf4?{58E3r4nP5$#_^RS0kQ6TUCmol`RjeV5rj@kSB1f1Em zOCf>w5(_H1ns|B#^BW1T6c%qEECBmWpz#)z!r7}d+L)O#YOFY;$xNN^-1|L_5cqCP z&9#ZRUJzgWu@etgkTa8R}mI z^lqgklP#o|mcM%9SR3jW3(z5d){v9z0qZF5wf0%hZl%yXZz|d@QvF5WGi?n~TzpGZ!}YSL-3%;ecfQPUY>vX!cPQJp#;* zHjZ9ijgTuXC7P7${==vou0NZ@*^!jPy(G{kbFmecplN{h>K-fPqEC;M9Tc!jnBP}X!@H@)vuvqOF9_+8fSkmSeihD^F^ z83%=Im(6H*`(LhdX|n=@VJw`P-lw*pvc{}9`Tvoj1MtdTwA`>#w)ZvZLc4pg$=bMY z1XtVlQua6FuZr_ME9_&FxJNyA-Bac>=?wsJv1L;Y@$&GF%oij%^SJC{Lp#T-VJaJt zn>`@`UHP{hRmbZE$+<<}xAZJ{msUuHC(i$NiJxWTPZbvPdhJ(~G9y>GR>IV*rT>SE z{yg^2i|&%kTE{hLz&huPH=x+$Yu|;)Ec*X=8-H#4NBzp*_$cfOgDxAhCwGgV=BaVO z90a$>xY?2kVsfcFFJtY{2A`2T)5*C!r|~=nkiX5wYy%vKIIrd~01plA;yab(`Zx6! z#aaak3-jkhuBZFI4}S=$5Ys-hpTApY_<*U&;|D)D(r!8a|NT~Ty_LMrKCT{lB-v)K6}Yy1Jiq14NO59T~;RdIs4GaytR@O6jFV3*pO|Cs?w(c>nOs zf0JqGUnlUt{}dYduX_G(V(J3^HXxS&{ilbk@pmtVJ1_N5KkOr!4^DgHLcXr$F~?ut zdK{Wojy>KZy*kN;AGgB~i-6xb_{GW<-6=La#CbX5a$e_hKJMx`?rMqW#{c|`@t2nG zdVLmzpY({*x{j7xHMmbzgdCv3SEr*DExX;}#PlJ1=`(JVpI#0YY5|4wi4=Z|diSYS zq9VkS;R^}hAnnxI(529a5KKvU;_;w-6mgNfA5#2(9&p21_NPO4FbAtw`d8kHmg{NQ;BDHch{QJ2-oq-lJt_G2MgYbPaoI3YG!<{na`MG3V@biBouDbKAe8 zzrOq#?@KC!VS6D3H1{YpaHDQ?eKZ|-AV76dV4?j(2P z{QKZqQvddA0!n3q?|tZF14cd#-3>Q57HSor3EnGfm@c8y_GR|kEs@f(-r0Bo_)8Vt z6%s}v-&fk}%42F%i*>{|oq-8S9-=a$bmlmvl{X1SMuQ z0{2R6)baq@3Swr5pwjGzWI&M@R2Ob=WO2~z=|%mYF*q}C8j}Op`$#$RDFgFq8KwZP z!kiQ~YHhXb{rrf%T*H>^WOzY2GdM$aAIuXK0g|x%m{T}olKnqJxE_dkWKA-p%R0-% z)?3A1G!;M3>`_9aeRh5T4$Cr#->~;uG(gRh2mv0^kgELYqZQVZ@WF^lqyL>m-}NMJ z-w;lbIh0AXH8wc58ML5X6uSsg>G0H$<#du}4<`pEpa)NVArX0XfEDWNvKqdA@{JoG zVV}}9f%hj*0$QnrQ@@Txe~0Y44;~UZNh}0vCj?CpTmf8o%ZRw>xGWG@Nf6zi%l^F7 zGC2ttJxx@%-|9n~YAuSrLUa41U;dWA%)@)~>}Kc>f6@iwAq&{Lp!_NF5TyMIV5ATK z%SfL$+t%6JH8~#14zo?aTFUH)1_E9BT!}ah)B(;9Jw-Kz59<1>zm-j1GKOA$e%S{i zy*M{Q4zH{SeT&+X++P}%J9Y&@6xAKf$yWRK^A?s}O7Y6yc8>m6!uU4qTZf+#~n5`^200obQhQfG@znaQ7MElqQjN>#V@l;%goCR;YHv zYcJqbo+MAZw`*jY9s8P1A%rl-J~ zDA$E2dS)eFL?l5A0^Q`WHn{XcDYaiAHk<{rK^0F?) zpsg?YCOP{I<4~omG?Dl>d!&O|Z%OzwZ>1e#rI*+C^G7ohtKlVx_8j$^5)Ay zo0MiyaOb+6&o$nX3I7auC1vjw!gXC(E}4saLXKUL!z7a%1zCG-f(`3%MXLJOuu;ZtxAR76T zE***-2{A?W23FFG<`?0K*XzV(;g8&uU#8KWmkPI%dNI}H3p8vT@mzmTHG$b~dyu@P z!M2Y=@IKmJ5QLj~FZ-FiJR>vI|FIfPUe1;DExO>HzYq($t62+svEgxVqqz?Zil3z@ z{sspeSDA|`&MUvm^Ly7y;feR|JUZL5maCWGz=Zj%CvIF&a#(KO9*~M?Ul9}QR|})q z%LAabd0)ZV=cl6;ulj8Ju4Z>YN3whDf(svNFXqz9%DMKb(s5hz=ky>*`{GDK5Xnqx zmA2|XAd%bjE7>7Vji7tc*o#rWXsu69tvw}Por&~OkOM~PU;hyc3vT4ti{k}-%pHukyxMCJvJNaJh)}vvM919A z%Isl0ryYZjtoAq*#fU`DjDW6wo-Pd58^x2ft~!{MGf2^vST6aO70xP#XSa{jwlP!6%Ke)m1>4dmVT4&<8ODANm``~?7BIi|C_IV^ogz~|s zd7|@WRe60|;_iZ+n&Vkg_y;B;ja8d+hA-nd`V>P<$tSOyvSoJ7mW@D@r--HnC3gNn zO2W!P4S3yAZj?ZETmM7vWR_lgA$@e$WTAU|aSq@=DERLCXP@IEn9?dheLuu!@}WH$ zLJrklS(dfmsiO>MJi7%PGW*z(mbrZuM>B9N=qTj{274$QAvgd=mJ7{h5yMZX7A6X? zpi#`MSB}YgQ3W(Yu+jDlI%Oz4p}TfI>utvhnbsUkwG}1C{OVE^S-xAmXFO5fUVd57 zQ?ffni|zj5L8yFBCIH8+ukRHp3-tUytxoczyx56@uj5+VNJjhM9(5p-)QfqJ1^n|Y zYlW!Yv!6^suLuUPf>imJg$ARn<}ZgKYG46Ym?a~9#ntuVMX?qM?q47Ve7YIb$}D!m zOHHfhLWuxGb;!6j{ZQxmvBKhX09%e;-pql7VeE50NVrIXn#B(=RauP!r&bo_^g`tf&O8LjlhLu z6H9lU<4*Xws*!(Wp&kEPdp&4Wxx>)Z$dXPfO8z8KK9b60Da_bXGgXLP#-|Rp(?N|d zU;eeCOxfcTN#v@u^T|iWoNq2#_^0m8Om_id*{=*7aVMJb!$ZjfPzhV<$Dx5mI)J!R z^97iWrlkryIpc*Y8XXZ{mm9@J!P+Hu?ZtDF4#pM*M~D|5$3_d@ zC&XB2h9NlTY8tP69t6t86q@ zdXI7e|Am3^iof;NdKD7+UMCZ4{v5LE!}#9Py`qxVFLFxxKg;aFD-d@v_kHDoR->H= zQs|!knsEye+PI7^Glv*C%)82L4wczn<$HcF_-@voM>-`|E_@uTdb;MfPu~3%y!4lz z?_P#RmfT3xWotb=$8c(c>rFQZSjetS^~^hB5du@pW48ql=ECXSpY(MV1cjwOy*?yo zqyoHE4IJ;805bfQ4fy<4O`IS2=gG7>=(Po`s68YaMSLDE?o4|3$qKZ>nq%#QbXSVx zFN%9g*ku=k^pv?&KPe?&9O4DLd-DZTwa~az{SJAV zS>PnZLqV)Z9{z~=s_J|cPm#Z2Bn^jO_V8>S4i|74w(r(GqB5Xa{YglJ`CzBJHG$dV ztQapBaZ8RYL4!ATtz57D6#e5{bk$)w)+E{0KPU7saay;Jtb+LNKG2LmMucw(q_ukv z@V{1b2hV($W#ePJWAhu4qAy9<$DWV}pwQh#R=1sZxCTkJVB9O{W-?ka;gE#kH1k6} zm-Z41+zYE_rSJ*8*pcrEwxKD^F(S&sd3MIuvRT1BfeoyA^JDGpT`AITs=RYcO8hA4 zWS=u39Cvk_z$1$OoaMZOyulgI`;BY3&Kg{7wwmo{*|zfBIN8Gwpd*I#dFPkV1kvCN zqiq54c8-2QM79oykewYmgcTsLxCLiJJxXUd*wipA#%_v*qF@%C&b}0JCHVSG31bsn zIm%POFAY^$FUkew6~ix7=?;#Rvf>Zh2^^ZEPZg;`7AX_tbN0nEA+BH9cT+US+>Q@$ zwW!Q(ROPwuijZCVg?<^c5iCc2!za|vTYz@1R29R`~>9yP!|ctoWu$a!V+7C+!!sGV7&lMaMrXn>8H z<;(lf0-2patLewduK?-fI~nf_0nQ~63WHjt-p3C=Boet3lB35oG5gvH5U2FUy6w04^mf}DEO#dT64{RI#D`-6KB zopGSdwAn{~Y^9ZVTrO5C2+{t$6O@|WzLG27RZv*y&*mzh}ParcQ#{7$EHMLP_LK}O@*s>)H zYlCU1XqNPg{)aV41t6SV6u!ug&Xo3Fq}OglY*Mg>_7`1lCd!`<+_LgUGn4-Rly`?_?6{b0C*C(HUFfyoT$B!m4FP2|4 zKu!eZ4-48bK4D;aA{ebM2IFd`k57Qom$;{{YX8sx`rqW~*Bri_5#nb%AcLucipfiI z^7C6K3T`3#F|{aZ6P9+wIG3i_W5Ul9wV&Ho56f`<)?np)a8T*%613<=9r1#5{z$P_ zl-56fVKHYk6j(v>yT6(fDYEE}4052nd6Ifo53K1q@WZNJqyz_OP33ay+DGN@l+im) zK41Jj(piWN)TNp7m(NPdFbF{RU}u-l2MVx|5u~9q{I!|3#0FK-Jkn^)ZhTbFf_kR; z4lR{-Rn0Raig5d$oK<)Kl`8yf{)l1k;pxsq25R9653k#u(1SVjecs<>!?z$`;(jU& zgXw)KEJPs8Z@W!dHNtP2@^91~UKpaxc(=!*JWQ<|Ae9p-t9?+|I?w6x@3>|kQUH#@ z)(dzgNKcRb`;xTsXBoFk3w-}p3p<%8)Kt$vBS#4D<4BEC~YD8VG8=mbAJx)l- z_M=zuxoejCq|(#!@@v)faCI*61L~YeeSUbFvoykZjH1A`M6;`&vZbjebs)UUFEU(_ zs@o*?TlpJQzF1o^NuNJ@jqDX@(Mb_L{Larz-H%%7!13sc^zjTPKbI?GT})_Ng1=;9G=+bdH$d=8sWBVJbPAl$9z(%x`yLsh+E) zqV$D~F=DF-y9BLLQPZX40q~l({_pyp&eE94)m5t#szy@vmxX8>hc@R8 zA+)CJWZ)Ok!y#i-#}ZEcH@oy z?mi7^tGR6n(5s6(u7)os@+!=5dpkRVON&9Jsz|QI@}dURhrp_Q-&VT|>6Crc2hn4v zqS8ZFVDoF6HD5`4#Yx@aY6aBv%w)2ny}CMQ)%fYEnq&fKeJsaL!~6lj)M5FBmN|~P zB8gP_P}hojBmEsyq7dYWA)XKyzBp=5Z~VEE$9PQRbQajb#KTkbGycU*-cCPta7%C| zcuMS}z~7f{h9%|1*a&X5rn zJs}2ULU%)cC4;;al&cs;kw7;PUa6Ku?pLN;w&R&^ODq2v@|<4fgGWd7scn?T0-yGV z{+lN}fG+4OyW>&jg5M~QHHk62YYbI#nB0_EzhP{P{8@=O7*#OH7m{k?8;{~qP@g5E zg*=xW_^Yr(f3p=R>;iF3c-F7p0`ouVyHy~~`cNT9?!Z4gcs`za1@Xc?(ZSk(s!mUv z@xs@tox3@Wm~Y*EMUhl?9w+-eJLkaG9Bw7`g)n3H?M$dT?5~FW{!uoV3Ud7{0VWlP zxidaW0Mn_-uV=?o9g6DkAK!X(2?_&I2YbJBrYX_AsSbV|94nS&=qT|QxVP`^c9}A` z&+Tqo2!9Bek9e9eRM;lQ!f~wlM}FVV(@+EIvSMG(;_`+2>E2zWmZmfU12XG95Skn> ziW)J#=qFFk$mq-K5^N2{q_{JvpuDO-ntXhRx(V)~9LvhH8Eo@NEXa-ZdEL82c+M7! zHG$}86(^6`*Mj0T!aBoup(X;2H&s=&yQ(bs!-@jhMoI&dirFh!e{?!_wEYRz{*Lxk zIDg7eUf4mkcuZs2MCw%V!<5DeT!~&L*O8gU$$puU_gaC(@+UG9Tpo{_ChbS0aHVaZ z3V&osZ`khLMHer4nk|e>-69$7@EURna2|hUyXFpHXv+@UZ4i}jj&1m8GwBB6xAY3< z$!Lvn>?KLG)s=R}I4>fLY9D1w7LP8z=fc~#foHp`GePX_W|;%J0UAB?y6w7NcOY|#A*7bvCqwS<=-X_FX+P zf1tHI^Ll zc^1VYpPy|s>-anX>MPyLO>5=D3y$Ns0{B%iwk8AEYbdR!4I38Es78-}o&%CD48o4l za##VYrXh#qZ*rch**%JFw+_uLnKz-xPRz-eI3dgeB>#n%^W6G6d>*c_P-dRn04a=p zw5@B~5_{~RKsk|eF0QE1E;jAag6C%C7?t8^D=Vv z%L}wi-XIuHnc0@>+_u*D%)F=4F65x6BB)lxF9826c*@g~>KTQ-;`;lMVSE94kKF2F zokqJ4?4a?7d06t!-$U=O+$=`uVG?Ww2j-D2(KO2JimOD=^@{Jv3yYl#jmCtxN2};@ zh651gLiVsZy;#!E<|%E3rT*Mfp>6P6eBmOy%Lv=Vhl~nTiW0+A;ov$cl<62o)hhHv zY}*;ZwGHS2Fy(D8?9duuS$U+kXAmj%stA!D27;STN+#;bSvslh46SvDCeA ztBSU~p1J*qY}M2R5QQe_6CnQj-->IjVSVv}nd1J5AnMAiurBJ~s{ozJ z^m2n&AT!5)VlkPtrLb4f^3oN#xr#`Wa!(_9`zhtP{VBTL4#t_rMXcd!@4YDuz1zl+ z=bQj_Z2MIf*mNo;nNq=SjHUayv8$vS>zgJJai{o|_X<(Zepru>tx>MB8{tw`PZf1Ce}E-3a}`HSAol$TC{(NNPlkJ^X`$d$zJ(|Dgj)SCxokdZgNUjEeQ|LHK% zxOautf10rk;Nn^bb+TWnAk!^8F5dK|if?6c6~(U7YmXPW-Pjqi@X$&Z)5^9S?BjK) z^bi_Y+I?U7Y#?H5xgEA&r^P&3Cw}gi1BkVm&_(}N)s6jRAa7%eY4Te!*9b3xcGb%o zbDWdB=-BV*DiB^rYwr(_Rtjp%iSe!^x}53VY`?p#D4N@({L~Z!Et;ZrIkPR}AcJ|t z#omMcFve|iJO6E~t_XOG6q-?$zb+UGH)!;HL4~Tw%H|sw`{UsujDqX^`hKyiloe7* z`q4}3@+gvY7DEYfn}xHwsDF->UNqPTd?S!1!U-#k)sC(xt9P*zwsA@Iw*7ge$CJ`I zb$lG;;Et7Yk!ETx(0uF2@REJ?j-P8UvznA)Zl3ZTK9^3-fbRvsu7PibBkjHm z)CcyS(q`f>%;gAhXJzJ{*-yFTX6nASk`9%7EHV<%kaHhev8Gyw{}$^-Z;;9lh_t2( z$g#^)OIGa7z})E#1WGv6*|FAYw`suh!$@(3Q3zcgtL2!iwESbe9wy*&y$*%yn^YY( zCn3h|JdeARELn<;?x9V6yiTax?AoO}a=9EI{YbB*YI|QAXv#sC$v!y7H&Y*UTA@Qb zQf?J=x>5uOY|ZA1mOd+xA*nSnxxL_Qj!5}9`#1+$+`B!<{_Y*&n2hRG3*p)Tdr8r2 zAeX-(PpA--ejpek&^S80ze{gNjowzGQigFGct!r>LO|U!rQiK&Wv6WGWCHQK@akK^ zp6M|T&$B20tz{iY3vQVk?UsRWIwF6fd@kxJA%oYF{19T`FoXd)q5K_q$dH%vSE^5W zop5g}ntfjH0v^KhP>Jg8hH>3jNbR)lGWPChw5ln9JdtuVlCX{vGpEkcWb6~ri`uOl zWiQFIxJbY9T;Un1CLXMhYjJPg*bQ|Ey~Dsr%EIGlT9~~gWHt62MXT1l{NOahWoEnq zieIememU-dB&HKl0}_m{!yZsi@O%ARo5UG3#>qLq2icpdBb`GJyhhBN8ht(&YNglq z-1{40_r1gX^0-re6L(YW_DC#r27Yx>&#MGD6xvA&LfPs!T}M}k(NnQ9h;YXf+Zw93 zDf%&R;AAwfM%sE_|B$v<_0TXUbsf`hrx*PZa`x(R3uyZfZZ!4vVbGx5!t+mjskyC< z4=BVE?CP^Y_DUBc&pS%p1xsjB43*n^L5~Dbm6|3f4JmZDrpaG{ZvZqw#(-f5t+w^R zhE3?hl8S8Ev(j?D8po+s@6A^KEU%<3Z$uJ}cJ7=cOkyvi8Z`237C31xOAdDWw3EU6 zY@?yMl*#LS-{j!czfQhp8n(lOx=Y+^-j_b9mdEZYDx_e36~Lk8SMJusj{2r?hn;<9 zu3Z!x)w_*NE0N-sjet-?)bWQXEr;;O3sgNnL`sha-SPJ7^#72GLgjgEOj+d&Sxe9x zQq@8({wfm~z&3Z7R_W@!=f3)lPu|+_BU0*YKamgq(eUww3SKJ24Vl9Lh-9I1sJH3T zM?^_P9gEvEMHxFbpo3RKAaI2d>grHe_Sp2Z9}55M+_s`MBzH*7otkM4trqgP!?!Gs znB1mtzYX7Y9=tY)hr3bfxq;YU%q5(qu9Q*p^tJiWAlxB8Ct)7-GEd+S(a~idDG%#~ znUB-9Xpe|;#*kTCw@xe+eq7tlpRgVH;b&0-riC-@W|@h(ic$yen__KGMKkepcpX%+ z|4S)wT)~ThFIx@7Kq!LySZW6wN^9Da4O~zA)yEhgMD$?o=O0U8pTz8ynV@%LBE`)@ zi83mevYz2mh$U$sZ4hc@OLx~XhPvxW-|NGOd8)ZWbDM9i-??7d@8_K@&?uC{wZDua z3%7qt(bY+1Oi*PfphukNtn^qZI)XhQ!>2?_eG?%lOH&n zXlLF}iN4gUG!jV2M&ynm?Cw`JT^gWlZI4k3=N;qO9V%Tri&Qlf$PA#(r5G*~ovsWQ4hw?2*jKgHL_CxA3cH(qaE9*udS1VBa4HI=ErllZ3EHw3 zHB3J&=*qtT*f*^Saj)Ya_fs2tN8G3uLNVecb$i56WQ^;3f|c`KAAK%W6E=qt01p4L zFZD3fDqF_N*o7(J*Ue@?3h(fl*Q#}Vi=lVw>T?(g6XIVfo-}3_`Tj56O${E^_sB%% z+SIy!fB#q@p8Bm3sU9sJ*b!{6Hs&($DYVXWIVS>eBNi=F0lle1XQ5^YTkg;49Z#P`6TMC`E-=Bh# z9i~d3S~BHsG4a@dkIO3MDqLBUulhY^2o9{2@uxnU4YJ+wZqlbD@9k!|h7^V}xm(B| z{cBY3FI75!XDMMCK~$=oXWGS> zt6La2oPJAoiDJ`tvGG8r@E7jO9w7=m3 zWHs6Ou2;`Hl<7pkJHHd(hOzb64fN2Iio#x*N`udWi8<(2#*+kuviLenX&B3iw-(A^ zK?z2{yYeTN7V0K#)K+&LxjM@QybNW-DlT)|o<}5F>dF3*w*WDNnf-3XxW5C;YFb>G zHh+#)2whlN>4Eb-{Q#sGWIRu^i@hZDb}da(UW}nJM+q5Oorf(jUTSiqebWbiU#KBG z&?n-9c~(F?8&($Oc`b7IlKJj#8uqIL7qyuwjvSgc_z^3g0`j|VtyG4Oo5lI1Cyu7f zQvy=qoZ{9jS5lC0x`rc|b+UQHAHlhy=hRx^eD&9{id*s@;~KK+m28dTpV-dk&zleM zjxswZrshTN?u=#=pB0&vHTp35b@Au}X^WK}!e*r@0wA&TQ_>S0J4GcU^-fwL(OMmk$l9 zpLf*uXi&v~OdrJ0+NZYlX+9c>n&_KDLdRhFf}1EESMJRa(3`q}pKeWV1to&lAuh<+U9$a|~7x}ipPhaXK!l#HC+(T;*` zvBB7nttgfx3IRQ3^hZs3&v*+yc7MKp*NjmLfR#Eu0q927s#BjFI;scS@MBjJz$H~& z+dln`y;1nVDEz_%eo%#tzQ)EG__eMEU&EJxR-fwGmRp~GlK|D#SggzMAWXgfb+s`) zJHQ|)BD3aaf{AQxo%ZbetDOz-rtdlgYUz2jR+5WI@!$eB${@uz`wt^@EL^*iSSzk# z2)W3R0;*lQ?P@XuC}sDj9i^HbTezEgy$~MF!VT3s(US#{tL8-YR!S3@@%0|IpOg%$ z7LMnV*StqN`tnKAMQ$vFrZx_;v`N;!d3*W$%3FoAkw z6aCPu2qf4Dr^#bwwdlkcVnz#Y=S~k=CnZ_t{vDm$&R3e=e9HZ= z;EA}Eku)K!gEs1#5Ys^(3p1H=cA)jqi3P{wu7)*R3U8@w4Hf=(&UX<%FHoi@zSNMx za{R>hy_&G1mn-LWt=tfepu7?N+R^TO{ho;eztVi)k}6Z&wa^F|ig&N{UHcQALZneetcJ(()rC*II-MDK(F@k?2|LEdDB=%VKI6s8#m-TU^^npzsq9hqMLlv*crhL#toTsFWOPpWrnChKOXY)Hf)G!(ED7$Ubu~kEM*6}Y7 z8M6uXQ=7s8C$pp9vjrl_Z|qg2A4q`}8Z4Jp_NK7|K+Y9IgyN8>M%2}WAe+SyOMZF!=Cbx?9 zs(3*>u%vnRvs@=j0KGJ}ClW=)@3kUR+S?iwW5Na?dCL zfW`_iZcn&YxFF4eFtF#K{qRHfBjckC&o%-Kqi-2B%(hv9PmFl7pys^@e|tEwL5*TK z(N1C_$h`F(z5A!x^FZf)%2GLfs=^Q7eJ;&Ra>_+4o%zD!RZGJ zN;n{Yk{efa`T^Zne5$rleJiQhibr?Xz^!JIBS#0XoZTo&c$T#lQRCc!TRsIyX<6jBXCQSg5x zWkSpP%0U8IE6oa>Y4eP9%u5mF7jqdfw_rQ85@=n^2iOh~H|9*T@sZFYknV7J)TChx zXt&D$0&u#li(*Z)WcqE^ws=eI<;_ znJthI&rgU-#^oKa^@cM_Dl6`dnWG$#B$ZU>%D4o=z67Q-&SzdL|De36hd2xttfVAU z0%0`!NkYVh19avN3lUBT+qLA&7iouftrid1<1%tz{}GAiw}Y|0wVmN2fN_D?_J4d1 zur8p6MlFr`f&GUf^1UaYX2a<%rP_(^&f;jZ*CJ=_%iH^N6bIG#zE`Tcjz{N)o4Ns< z9%*i@pW2qNSiumuoRdOSr5>=^xMbP1`Vr;eD$|g%w15N~(`r?Ns6W~ferqA5w;9XR zYTh7@yj7_iRm#|2LLs`a2MR9}0!qP3TH}NxsqA~b2$D7yH*J=NzP1s~@EYp5xL3$c zBg!0xSu&&b=O|Bi@2CRjyEw`>m|vEKH;4dG@ZkPl_QiTV-f`pVDEnVSBLoxDhqZTE z6-<1o^oAc~!OhrVYlT_@XaulhyBh#(;@PKKw)v4pNWkQ*jJ=2(mPZLp-Q%m|`UQ4B zE%Q1&UF@0g{W4`?>Hh5|H8!_b(5mrEfpC^(qbyLzG3J9>UTaFA#ExbPRO}+n#%R}B zjsV9I$;!j=O~y~Iet#9^d8nM*i11?R4h6&t<=_y`n{1(}<$}m}9>(e6-^@l`%N0@G z!#dX7rZjeT%C};Coe~#^qruw$8Y3kw(FYbJW!1U9W=3ul0Qe0txd7;=d9pi$EV+`k zb`XQkxP|)`X{bPVtW<3htyWrHu_oht0W@7pjDXDRyy03S-KR)x-5Wd)@04y-SY4HX zl9+;$_EFpmu4HWj6j;V@a>5(`rdld*st9xBHfhQ5(rdfG06>trmGTx)r$TNDACUf* z>V&rwhyzI#d!J4GOL{7Dc0l3;_QhpB81>GP3N}I>m!hGr{RQNF(aV)PW9uivJ(qgA zIR6~tbc-%8qA0P9zXtLYtq408q;YPaO38|zZ8j}gt0WmXrO1etZ)*}beeN{AYr1H7T+q!CK28v|es81EjE<|GAX+BKE6h|A`IK0g4jqkGjZ zP|HZ7Y8rPChoXS}tle6_y4S?`2S6$f@u&UC%?>}2kYBk?o@aDVpR8mO;bGT7H6wqUb^7y;g&DG}wZy2R| zCf98|n70EZ{%isG@Bd@(y@R6MmUvMV5haKyh=72I2$EEC9wjPa5D7!hIp;i}0z(E# zB3W|I3^^zxAX%7!A>&96L(cJisQa9K-uB$O_1?Qxw{E@p$8w7Ao3(m%_v-NL?(|jE zM|nd*P-AYo9FQALprkgbkuonM+ezo_7Z$G=R>1?xD^YU(HcE=&Xj)7Dk?M;N52e^w zqKnDAj7fX;& zfd!enT!V;?Oqdr5UyoLnTsRePJ`>F0jm`5eve&&E$C-8>k%-;4d|~rMe=71m-G{?h zoQD?;PYxeRo(Dh0iCMU)3^ma0dP+IP>@dOe_~+?R1SfJ6`lX#xJ{;3r%qOfdP#R`- z4LJyT)i@k^OLb2gqW0>=32`$CVXSgfrU5`=i0dLzYsMYtoXa~9==^YY`<1~r9?{3TDuC9&jTELSZrL2eI5<@5QlZH61ArrHAf2p>VU78Kq8=w zhA9fK?|wN7UUDF0|+^iQd$}TF;a^-GGc+f8FC=Q%!+qAf z!D1{GYNR5;x@x{llGG1&vhJ`V*GsF*a^>T|r5A(8qlW5d`b6aeVJ7jaQfkWmez^^t zP$gI=^RJuM!7^x^<4`RAGSW=sH1~?BREL>OQ78cQh^=Ih=vZGGjbm*tEgozFs0=jr z)2C<(b~)f5%*L`uGyx+&O_atTAd+aGI4yj`TYV3y_vcd<*+s5cLNw1~$L~v@S5$&Wm#n`rzy>88D z_P$Y>26QXwefJF(buXDYf-b>!1ol0rbxx+9?O|ono!H7u-WZf$E(1?iX7=+jMRxtk zAo3~$UNw+*9<@>C0Wsp13_)CO6fb#CQEBctP|=yg>AhIgFqRxJ;$YF4h0A>v=ypO5 zOUr!O+z$jxDub~Ovz%pvQ@iO#R*vC4KTuo#^}NYf-U zXwR_hTaFGk-;t@6!;R21@i#+o0!DiH2o zNUWVue}}3OMFv<~j5VdIUEnDwxh_fSK?Soo0JO}BMwDjvb6nZx8WyGcpIt5o#OL4u=BVjT&?K9MA0pzSaq zud2h09u7vqxy5Ef>JOb1;bmq}$B2T7P@1b$39|Sofm3R5O{5Sm#$xFUBtG5WtY#HP zOs}CesFDq!P+)@P4D#h&;SS?Xm+CjD;MetsA}^L^hTpUvn|*#k^Z8IR`8t_4oa)+0 zU&FQgpj#?0);PyF;+XmIWPmGl`VqQcl0mFritA(DEmQ8n#pj5NqN9h1mFY+Z?mMxH z7vhRvp~~TlH&g~LWZ$ILe&R4Mq2?a-F*RttR;NBu8xe92~y5SpsuPS&`6?3Exe0xgoA~&Tx z-uW>i5eVks&!v}o_pPfN2-fG2O%?bE;CMsl^vznBwcbEK7c4hZE+ikoXN8pu+*+;nl(=P7og{&RslS z3D1n>SEC8oL70@$a&EImiPKdoS^?*a;72>Pk?1usYRry|Gos7N(|xmpsga8wkR^v< z{Q&Zb3qC-Bpvv%SZ$YPDH(6P*>L)JIii{Xg;m~NFuOLsfc&@$kOc71rn~@&q+DBA- zBHb;QAv@P$QkD!a5Qzzv8HojZ-30*1Qebh3(ei}yv{?<+(W<-(&LRI((X-<%UavGM zht$G>cRd9+E$(Y{qKG*iwwC>@)tY3L0Y}{#sx(SXqqjIvKvP|U6AO6}mn-=!Uuf#% z%Lu-4J8}LFQjz>0GM6$LZrJFG@e8=94P7Pj2;fS{*8|!gjAkDK6)rO8bzfxbMTvaP z^SY|bC9cZ&nO9Z%Yf^ITh`$#N*tP1R+I^i_ybu-^i}1SLxuL{W|Tl}ds-FH2LV{s;YFCz&9e4Hjs{ZzrfOQl zNPzQ=pr)?nDGnkp@L+4+(qtQ*bwn=vo=tImx;?_x+>G)6_Vkp%NjSQB_aux?^aQeG zFkIX0QhRd8Cg>tg<;CLS$JamE#L7k zp8#JQE)P8LuTSy?pa3w}y2b9|zrI=^`r872ef!k(HGt)^NPK)=p!)kGi2G9w`eDvX z41ayTQT{yE2fwRg&%b=#i}T->2K4*hzVZ7>;GgZA|Mh1(Z-ZCO&ubBXe};X}g9iWG zY~&ZS{94=p8ybJ(MJ#Sj@11V)tVLfF-ofqX@cV{C`jZcSz5J=^`JZ&58`gB`Zr?X& z81=tSb@zYz=nl!XZA-lO2NYBHGa4@&uk1)mck9f%49>^A-ac2^CWSx>HOXp;BA2V(6PsMAdf#;Hgz~2 zgPV+;d1y|j&%blCPPM0$XVUUZmV&KwJZ?m>3KC>JzujK!meyrFG>}=*yo?0lUf{q!b|uB1B;|PjlgRDgOFI5bf;4otOr6vG9R}V4v%4ocnw5er47R#6PWk|YhCE0jIWR8^WS4lX|YwylP+osw+ z(W3=I?+D=>pm3<^>|_lh8OK5VQ|6WeV95He943-OvQqRLu1y=Yy*I8?Y8%KgCc2$k z5Y_zZl{Jp{3T2+_2J1N`3wg0H3<{L{Bu)FX&;KAF)TmyqZQ{I0FthIlLqxL3a*2l84!rA^6)E2(aZb9Q(+ zBcn||wc4zsE{qy-ye$o?I~h=f_lc4T-|rWq1&zR|CP^pRFM+>Int~>#FZ@2;4%*3) zU7W2UZD1;@IBw~ml$#1IefaKZ@kry7z*9S8^R9!KtJG^D&Hcf-q7EN{j@o)VIDcro*MHzi+DbB%h>k~n5+_>heFnXF1?}9`ZWr^eg}(G3`)BF3gYS^Fnk^~qC?NO z@O_N8rh%nL@QANl;J#h-jo7gczc*F2n`U_K^>MX{k#C|x5vSc3x&w7~Z#QN20F40*k zwe7_a(Ct3+;U*4Kc^nxE$NHjn&KKTX|euzxVmAk9jjG;RkO}ICl~(Lc6BcfZf_>Ha-z7#{{mF;`vs!_E;D_!(B!YRH2CVY42N`F!)AtRc7>$eVIj;P09vL_ ziXP}QEYiX&sd29}E7EBcb?L0D5lmMjySC9iOI*Ma+EXsQyLEWr-sXK*@ z878Y1LRWKS9YUMF5iE2>3@BfuA1u>k=);rUS@0NX#`@iqe(@9e6~E8o5lP6C zgp&8S!P+Ilc2@hA{3(FOiQI#g(MmR0q5+lT=BT&cEc$X9><6+@8nsy(J)X&8$QOll zXm5zgA8FF>-JvXG<~FVmfh%EVtJGuOZb3BaZGO( zKV8)(|5Q{Ny&J|#A$NOrSECEw(6p|s>pFF!P-nOSE8Srwp&M!BgB+zgDarffbCCb z-?PZio+R)F+U+|DB#`d)h`X~+$;bR)1%~45YC`a;0hmC5vTICLqJ_`9oXt=D@rEt! zHWr50Xo?ba*A_i?-&%0-9AHpdyc4c)G#y@uHTQ>vP6lzqUZT_sAvsyu1*~;BxnhQh zJkzb0W2g~|8h1#e8+O1ycd>)C*xhY(n>$}{Kj4F?2!m*0qVsM*lS(z7c4{g3yB{8s zTJAY|tc0!BG-+?@vd>}g{EyG`5UcKVuJI%(1-ajs$y1+JPq4gGqC_-tPG7{-5nz{; zgoY;_>2M`=JF;ZpDx5q;X@_%o?_#y#U0i*fi^w2CG@$w`=z4#MIJAgU^CEbtfA# zqNuf}LlIFl9 zE!>VaGsF109h>7?#*qyb7)8^G9h(RJDVg4e{QlMENK+8O`ktA8bM+V@B2OkGKP=aM zVqAxz4X;GobC0i2jwGds@_3Pw$FR^)B8EO!)U9-G#y0@GS0c3R;pyCiE5~zL!j|D$ zQkIP;liPM)S2K@WpdZC57& z)#_Q7dY3SzJ*a+k`P146;Z>ek61My^nZ}ep@o&m_tqbicH}#AfQFUg%dm_^*j1!OA zJom!L732gqHzhenLUMyQ9)(eR!EBpl_}@1roqWEkbx5ScH;pWolAr3|egIfUXZE$W zY*xyOGuQgtBe_6-={ALU0mp18CY8@NrE7^xo;RsU3u==`{%Ts$HLp#$N0&%xh5d9J)^g4tv=cMCHh#R~XESAh3MC(N#g3L4!1l_TnipCVq~A(u0mD^Yia$`o zqZ?j5s?cO9a;4^)TU}9mvh{t{psZN8rgH8e4Kosg>sp+oIRC6T{Q@nwV{5o}eN{=k zXOhotv&@qfmBB@UwZ&@GeqHSwN5@Y=(Hx=!RnpO(BVAGsNb56PUr{2Jk}Eh?O%n zLs>LLh{rR+J#z(RRfGL*VFJ$jp5s%8F32tzzd&B(XgimdUH#=dp+=$orpQ^GcX!2Q#=g#4a zvU1au{D|u+F{b=sAIdl_MLakchYNS=Ru$7%;&Z;|Whfuua{HRj*VRsl%1a_jJnaJ_ zK-67heL8n;tqYp@3YpD-3B+M~{Tzc;dmCO=Gqj80(Xj!kexw`IFn1 z1Q{c{BZ3GObekN}#YGBXMIA9WK<25D_{lCkSi%%_0MnXnJvMGjgC{CejNxXtJm~;# z7P+vA4CpSk{r5#B8_jj6S-8W*38M@6ow}uf?wivDDdvy1`38HxWKF`J&V__+ze@x+XWUPnG~CaT}}VYyL3+jjmz@ z{=)=J%CZ~7JzFYYn(!g%4qI>YY$BzXabkPBD5|oRdxO{aLJlexK*#yJP3oL1AtxH66%jO5}cCrf4CU z);r3vlXrQAL^$_iG#leFan9XJyC;_Sy!XPKF@5|&qwQTS!R3bvJ= zoI<;4&mRbD?UM@EoWh&mZI2`+aWNF1Oi92q(xfPrGp2c9x zFr&gCpj#{DL{53uHAR)9;h|gN6q>fM`x^{@LgCe5e%t%yNKB=T4Ytol+o&&JzNBMC zwZ!xWRuMhyq&Z2N`8Gv#yY_B8%TGQGQbWi=4rmRNSeS7T}A(Iojw&^q3h&3X=5 z3`?O_x}jqBnv)$gm_K9LpY?c4fl{O_afz6NQKujQf>HSjPfU2sL%h-Reu1U=dC6Rw zqOJRpti-To?qY=mJx}M8iCN!sXeMOf_ZE;HdF{Tc#g?!U z(cyG9yuS>K7SZ1Bg~g?tB(H+dafSV#E3|!-!k2ix%cb3AZiD-Au%yLPHtLDnDT_?V zaS|SE_1e0xLj7Vq+;;V=7mzXvDWQ&?jc~8zgk@8M?aNlKX4CX36a!>?1dvVt+`jGM zV#He$EnsvT(R6F)b0)FKt7vvZm)Dx!dh8m{`fAn0`&nK~C!^pk<3lh$Iwvq}oiBxD z=G0D+{@HW7qhM-PQj8tf+xY^{O>c`A+wK;-r`sDGeiw_iXTlqAXwOnC0$jMnZtD|t zrG62)l(|2*Nh@M8G(smDtFo?&(6I1EvQ*~2&FgFqM}07Q7Su*gn7hXS`PUuB?2s4= zh;yDzec8CUq!u4# zUNuZff%amT)2E;jkEQy_@^+Pgy|9$!l z0+F($x0<_nB_CPuyI0A~Xn>(92`v;Gj4^*>9(2!sWf#lFT-~`Op7M8wRjHf$EQk|} z8i5(+Sw3VgMCRHloVMO&BMr^7Z@qXt$aII~HyO4Wmg?oDrbKeWxsrBiyf-Rr&Gp7~ z-R)Ka%^;axpti}uD*Mk*^i7I3S;A{}TUX?riHVpz=_cCn+F|iwWS|?${p-tx%_-F2 zBjYvH*v1byL&mXSd4Da%IE_)CD|>vBnrg;eF_IP}NWC(|)P8u8oTft0ka1lK7Jcwa zh_CyRTA)tP{ZZt(AE~X~r?dX7ep&qNI>n$v!Eskz%>F)XZ{Gib$Z8?Yr(NqNf$M9 zP}9sQ-(Mbl$BO{{=n1&f^)RscyJ<*Ej^#1xl8tO0z70!^+Lz;djR^r#jkBvHu$?ki zo!lv<5(pEWtqYKHB{CZrp}P|cL}GH#0=Mc_<^SBEO=zKs<%k>z(wlj09f(+A#Pv7+}BngR}B z|IXsac-HcvRN?xgS+}EAE>6o6)Lo_+5lp4wPEkg_K*j^*qh){0%w}~-lCvAX0Dh8F z`=*a02X&7Bk_ zVVErT)ie`tz>wbU!Zpt%U2VKw-j?Vr8ox=*o$Nk8yj0-u`UyvYs7f0{$;>#1w<}g8 zBj7S$?Agwn1W)8==;k)q%bLWQD939oTQua+PW9)lHK%|^w4iX)zjpH7 zkZx0aS@sLpanE6Q-4$Zrf%iz**fkdwkC*1?DoIo2`tnv1IoKBmf}97op_q(UpHY4; zVxPMXZ^*D2Jd2#{7SEV;*hAOcPi-(csOJF1O%{RaLwfB(l-DmQDD`?1m+h*A&x@6qQpi{*&$Jk?NV zJ6E5<%`r&v*Tdy7Ol9BKvIv_(r&`DM#AWitQLQ75*_;Fy4p(3b@y_eme$(cF8JD3$ zsR$M7;nMt9CWD7oMB3DJLJZtxQax&s?BeL5!aN!AF$i0CcX=Dot5B@wO}$Qj6T}v< z8T6NQVM?u(0t_{YY`awUsF^XJZ6rB0pN&?vQGdhYv=o%PMn36?S;DQ|b-jr~c!Sy% zaxwuYNiDOLpWZn6{yix5b81uC>BPRUh0c>|bf7&+iFdt2i?Z9f{{t%bG@}zXR18ZS z{3>Ghl;5Zf{YEJzFT4&2{qi7+q1x(?7_Qk?AJJeedpi$r^4PwjZdjvyc1F3@RQ4n2 zp){Qc>xZaM!qk8dWh4FgLZk=~w!kMzKHcj1d|e!!=3>zjSD})BK*>`#>22I0GQA57 z@zKcna_<)TVk>Yv6zTb3Z$1SADW~166WV!+0gp~vW(S|_+{+hqW2*W7qGB%TB;9f_ z^qXux(H7x!cAsXYQSzwz29j<9h+3WOT|4UFx`&v~o)hff*|lV)rRBS~ptlxHM*^NJ z{b9d_GUO;3>@|8>wAJVQs^e`MrlE0TB!w~V|P;PiCHXvdJ z3ykuWqP3rW8%tdfjr>=r5~q5Pn(J-+@@TPpBJ|aM14J^T4U&x}zQ@Y7cAOxc%}EUM z9{RERiH|MC`FMSw_)RM;+Ue5^K6b6zCo5SGqEhQpsZ=!Y4jKGxz!Iuw-KGJs?=>?S!VyWO4w`+ zAJ32^cbk!g1)V|O$E!T~(n?r*WdqWXkZn6!sy)>jkoJa^QLW*UJrKep9o$ep^xidf zDoSuP2}tt4$_Vw5U>SAZ#8s!TF{WMje1qoe?xzfBj9xxNKWX zb@8AmBpv!0q48!Gm6PZ0dSJZ+4QXsU`9e<4c&kh&lD1piU#f9%q$Gudn65u47y2>B zRB^Bs#I3sbFhw-=B)q6k9#pscCig=puFgbX{ooBbUHV!k$N1omD5oR&&xDWu@?;!- zOK%shCNTSvY-o9ljN$I30{@J44HTw|EjztkucewX2_f z3{Y8nY^+{)GQ~y$E!nbW0&Fd&3eeGXr|z!Uo5=Qqof}JM2p}SCvMC~aT(BZ0`|t#t zGOBqp>9DkgaXb#<=Z@!Bm9aPN1@yp6Yx!O^iTYu#^acO_1E>RK0Os^k& z`}X6_MBtf9?&pB+k?)(Ag(pgUkB4JsIsP({KK_Jbjsb~ITxy~mk>FLP8Bw>-6~f(0 zpU*ZaOOUv~80htlzmlJ~hxPce`c9xeq%R+b3&*Kxhua+CZ!VL0^E;8Mr{{~QY%jC! zr!)~D2J%c7Yy|ZA{)((Am?vVk4>mk~4iffWj0U;@b7le`C;fZ`e*kWAn1khUpsWAk zf5B3~xvvFZ!P~2#>#sCyuEH3wyX!4>Z{GlUrr$q{<8bns=~f9HR{3H-I@zy9uj zl(7B(D$n`9Aea3AFYVU>{xJjpF&Tz5?M*nYmcBz_e9!N4_KB4; zLyx2;_nlfD4>uJRpZL9OC;SPf`1Q7rT*DJEB!$g>BrqGKZ+w%BD=D*C;Mgzsu~=?} z|9@Z!Rzwlz!&5#F91=4XCbpGq`Bj8-GQeRLzyJcZf3q;qqxrK9XOhFjgNK|z?n)rJ zZrz#KYBrRA%DjyL3x#4j>_x@QstZE@_HG`?p!j{M%b(`9zPB-qJ`X_M1d%U27|usX*VMm+92t&S~rV!6$MkfomzTlp5E30wa8 z%-uAg7c@=vi^Cr@eUhR|xfs)l>u}Xqe}8l3#rbP+9Q4m8pNbI@=N#HZZ!1(k3YW`% zj_7MwFTigC0m#|OLTYSrna0SX$W14}9_Hfq90nJ3enSBM|~-rIk!pnxa`2CN`n z)BBcyT%HF;U}xBliU%{&L!OgsdDI4%jpNV+qF9!5cdT{ztHvD5O(39JJ4bXldMJN5 zpLmQDZN8OZ*v>KD;F#l};yPGht2xmQ&a0Z5@Mo>)7RQLFYwFHM%8XoN?+cw(C!w=WX6jWta-A*kaR#Uzv#V;ww(A^?7nO!5M zMy(n7U+gV-@c-K?nlQ=()=@HmeIF>h7VMFikV8Ny z5VEc{>3#OzuxC|^>uBp)Szn(v#M}mmeyTw8f}3`~UpBV!b_!)w$U}|S+Sursy*Q7S zN;AG&f5z;0`NMCa(|F?;pz-=IX6b+_xmPb1IO+y!WgX_bff3SD6SJL3X~o#F%?@wL z4r=fjr%z+l@|++fPbxaKMEJ1MD}k|S1PEfUaNG@pIutlSrk3cmJGl*whXOB!s%Ch5wWCSAmHA>2Bckwf)uBG@#$VB`R6=p6o+Z zAS>PN-Pw$L(Blf-z`8CKT!x(8SdaL;O2dwsQO@j@j!bP<6E)7}kx@>S!P{VU3V$na zD<^Ahzsv9bxI4yX%nZ-U8tCSMoX)xG_-aHjnBlr02?Q>=q3*NNA2clZjkS+mfGV%9 z_j3zONDI1nF|)hBmH9_+Q`KfFi z558Z4V~og=kR^J*KdyurhSUdnZLqo?AJYNJuP<4y0@?>p>xptsdZC9!Kz_=`ZCy?G zllgvYpG99dMTw)7VhJ(R5qmDpBOT2nA%!dSzZv*Fz`!@y0I1ebp*n}+#lNH&Fbqm2 zcf6EWrhU%h0fl-*%jJXUJ%6wF<_fM?JT!pr$xf?v?6`EYIf?>dJ{4UdHU{Yx6y8p{ z#=jUod&b+tL`wDgHY3(UqmF>H$gT#4T&2Xud5;RF25YFCzubKx9W zV=01KOSk%Zcph{sPLLk~rU#e9N(Oa(4E)?%g!pT-0ac5*8oxDW(WhE*=O@+X!1BEj z*xZocjCcX@5E(d~&7oDhm>hgnxy*lZq{aaw&qQ;bY#|YIKTP;XCmt(b9qqY~Tkbvb z_Tf}6_F~$b-$<{YVr_6QIHdxTl%EziDi1h1(EMb<`+qk)em*a} zbX(R~nCUk~Fa8~tc1{l&GqZ<0Z2wXnwV3UZ5S!rb_=*S8t-I8so3`PCaH)XQ>v7Mn zI4Av$2P_^Q3^W|J{zbnc9spdI`_~P4E{qoOqEHX<>JGIktC1S}X#mlO`_~`;Wip+w z_&>Sv?@+a;tahs}3GM#dzW$}|{sVk>eh%!PoPW~d-G3NF|Dhm$L9hO#w*NsOiwng+ zEz#GP{*KH0Pr3hJxuNgU?1=x9_Va(-0sYTyD6IpAT;DPYZSYnM;XWQu%ve1iW%M`g z@h`6ZW`$ThrVDM@SiEJve^4zk0Ze9q|4s7#b<6#CCO)@*Y(b@LsJJz?!tRo@b$@0M zBsKYfYbu-qPyjT4*DwE)BeOKjj7Ki#d@CeYz-Q2sLpv@c)orAD+8^WhGT@JQ$K#~K z{CHNfwPiwupe@UD@REvEYd60S$*bBocTsYG5-%})DsYa;B$!xxtlC<=d1=u-j<(T9 zxn}L$@I(JyPyZ!$e&IYxbyc>6!;{9?)uquowzA$kpPIs{5L4+O zWqlfmtI)i-2&sZlO*I*`<=R1}fZ<{ zU2L`N3j2h=e@Ub$9^dW_PgX~3kMR|2J*M}#wDdZ9Rjolk#Pf+R zdbf!B)Oz!?P28TjvdQ8D)&V#)dX)bQgoHRp@#d{Ur&a)z;dt^xy*+G&!-UHF%fVJ% z{aEcZ4cuiGqgWOhE4EyHDE30hn^ua}XL*1<)*z9N8oL|L?-i9^N?))9Ypn>U3&;4m zH2;ZB^j)dJz}Z)vvjOaIlO_Zzq$B?%DSxu>@Icp5AilrcvE9-#j$OOXYB3)&Rb2Df zR>U)s&lU)AD!Q}fTaLk0SW2C&TRE0^O}ca3msWG8hSeV`K3q?r6iB37=Cw`2aF-0k zuvT@)X}U@2k#e$Lc20k_a&{!-QY*kV z#VdftX-Hi$K;_6gLp)aJg4Jr)H&g{+*I21Pu}{k?Z_;7<14^(7Y2(RCE62f!UzbktR!YFFBXATCYG~L#(<$Mm`=3iLkc2eUUD_!g8x(B7z(1GZ8`_ZQ8yC zfjD;4<&$|Xt*kalg=?!liE}AV^$G2w(SWAY!WY{3Ekj zduL4wHJ^Ywj}J+7fv!hIo>?i%y^)(kU7@iu=i7oCHc>~(I*JpmGzK6DV@jHiF3*nY$o8A^PA=q0t_UA*n}|(VI_C%$tvqr zNTe5`^yHb$?8D5SKJY=?g$b30m8&_WaJhJSa%wQZjnjn6v62;*t)ZQ}Xxj0QSZBvA zt*nALWm>3)sK{60?+da(47kQ^F`rnoO2y}G{@9apcekUF5U+#a2cQy@x6&nbDwY-W zl|p~BZ2oOm<9@TF619ZydYaAxscO?^vr6Eg0pD$`+c60vxL= zqEWj(w|?U3FDhS*L7nU?Ro|Wp<`9@=RDt(woA&G7~t$k zl3(?*e}2ALX>P7vDj*)vkd;S&JU!e#J1To@NPGd8fULK7Z$fgti?xq2hDX|U?D_8d zhJ;&Eciax;6-uB;S_VK}?T;$*_$M0i%WD?zcHIWgi)bHc=kdLtB0c7hCJ!XeF{5?R zW(JB9Mo<2z{4SXC(+K&T04DFG$6*qi`^()==VDv%Fxrq`#re~Vt#YOi00cHIoS1SO zygWy{0-Qs<+-j?3>reRpO4MAY&K$0no0!LA*kDOX|I-ooYM1*u2 zT#Ohgc~TZX;8Dkpe6uUZ&j&Wy@K}k8$2HmHGN1!={-guWFSqQ1M=<19UvT}wqVq__ zi$sd>oszVQb`O`r6zAtW^Y4P1bCpRn_}zcR2AJ|jM5}WFu(*-)HL>WR3mLrDe)_+j z@=x|~hI)GxQXF4*MM}{Eo%cGnMCj85IerL-S!aE_O~CGkqHfriV+cgJq` zf~eycdjMQ_v4i@G82j&F%|9+66dbC_w>E712)hJiB@3q;rE& z=(*w`UQe8BAF|GQj34Z7QcjYO&7;~`6fA%rs?v|`RF+v8Z!p*yD(t!pLy8_HJ4~_0 z*Q4OpC;6Qp3lCdzRME=PW_$pG`=7SA;E)}`;%JjKax`aN+d+AcOJoALicmRx4e{YzMoZ^@kcKs}2jYij z1f3%Hbw7-gytHW^1 zSf&bc{YjFC1aRk*rM$hv zYxQ9WVw&4UgY%(%D7Z^o=@U?T6!;GhD%%^tqtS|Zyli`ePs{&gx)gD(!Wxq9PDIUX z1+>lL=vVl5EU`Dm!DHy^bhG zDtNIhbYplxR$_T!qSbT>mDkv`o?rif3aEvGw*SKyJB-5^*+ieNrkpuU(yeJ{KUu@T zqAx1B_3$KlpdP@Ke2nypM}gw=0D$PCW%X{Rb3iu9HLP5@d*JzoY$Ox4`2MM zwg7P^0fP?&nLS@5$X2JEx~*}BQ6ln0p|$nISOegV@94#yl*e$rc67@@X22!`S+c)+bh4yE;s)F46Q|uQ$yP zTd>L2*!72(8Fk!{t((B(QwZrC4rytj(CJAL8S{p>ZZ414!KK8kBx-%-p+fQrGKUv| z6SdjDB8hOf;omLPAvRu>FQAb3kF9=*V47qDeZew+YQK3+cbZ^~oBNG7yE3P+9$6J9 zc@WTJ(U?cYlnO4ZqTI%}AOz2CsT=ZVPqHp(2&kN=} znUQFRJ<@gJb$5EK8F4T9ligis?~Jc?gjdJ%Dx~fu@e!&}1LGwK8G0ZURB^IKw$)oV zS(RDy)8&YVfaV(UwOhJ=*F0m(;vp|uZ4YP@;}>pU;X0Y|Y&ppD(YQKWfM*Poj(ISS z?F}^eN}ShArGD_v>6&;;R|Z~^>O(<1GMK{vgZ!Y%aOZHSdQ+Mg{JYSglv_XY`Nw<20HSk5Wd+QR9giA-={+_X^-W=2L?JoE8i6C-A!B)(tg zx%|SgD(Zb6FVG$SCip9GwlL#8WNhBW!vbr4S8d0KTz$mt#TvX)#u^N1(UBpsK-F>P zy$y0`wk>iqq|{Bhwc1=D;W{K;5Tu`IPFWwjqK#jHpFXxh5A^$diYlBc$Q-TAe5uP~ z#cGh_yPJ=vqU@~6X$-4wUUsGb*^9$Fj`2i)XnnYJGk;lV0OnAsj~8mDhzh4mPL}qL zi|E{yVtxz^thqu6@1`1QIH7Cf3%^#w(PH$q4uI#mung;Q$r$F^kgq z&Hcq>@^N$_c;88Q5u-s;WG1(?@A(yhopQ}yVh(ce;N2z5A+J!mGA|R~xzQul0kh1E z>Lj9oJQ*vFSqL0}*^bBNdJ+sLz;Zs6%8^%O`UCxy+e#m! zW}t&zmH`;M1vG>~T(HoL$DF7xKOuN1rjmYoh~Ipu9%!2VtWiS6kN8VO zOH>s$h?Cld%)tKytB2r3DDLIThcMNxS@C6`%#7WU+G}D*?vNmO9HCAX*)e!gABS}v!I9)Y8&$PcMXMhP%<*wn^a*2gSS|)nvs?#fl)7|7%U)*$!R0VqDmu?btC%{wlh3qJg)$yz z15y2%>hBbl%(J5u^?2D8E#FhVSAOM3o8R(Hm>GHWO3}5p+uiHw^+Fn zFoHR+V@dX;&b~=Rs&NKSy=2fh5ez7Ek%S(+zD?cVD6J_fr9^FMnXI@>^EXUr1#Dj~Bc1(4&Vz#Nm^>5qyn`2LF^PjyW_Z}TT5xGl zu&>I34Ff6qdrmGS0$gW|#&^LetE6 zMWXZ>^DL|rsdW}v3S-9VfMFhnD#*!R$-!{wm>C&SjCuIcS9J`NR`9sx2`o}=dhvxR zw{R%Cp4@}i7Xtql?*A1CasGfYay@Yfc{nu{*lo?;LsW2EKYZe8CHCDqZB}5ER6M76 zzU_%jo+J8|C)7_0@p;sGL~AMW67hU(_wZm~RB(G1S7B&7U#`H$7=8b3ByZ8vz%j+^ znYUGUl&!qeuY^?=TU>38*PJxG`9aoAddx)@**zUQOO%0)ea70EXFcMR= z1R7jtR4AxSzj8uNs&X}&5&b+S{(brfmHv4?VLY;i(f+p@?iDf0T~YT!zi5Q4uqq%B zYSAC9opW67=@Q@wQvXp>Ctj2|;*JK|xWbsv$-@5L1f~-Dn5lt+^2Y4^EmkEd0r3LR zK54%e;)PF<>X1ulY{X0N(QMMo?}Un(ksc9(8s$bon<6qA-otLs$s%~ud3g-gWhZKA z@SYLOYU;8iNttCjW1og`DzSa_2@+Uq6 z;`|RPq0hTKTjVUi#6^_eX6a#+u!c!Qq8IP6se_`f%h$W2+Dt+HGxBf8U))rj9#sXp z(n`cj%1eGwiIyEss8a=Vo12>`%Vr8lDFXvaHcxUhSoB}{Afo8|g(W()ls_`xPPJ`B zgYYUL##Z({uLw$t_3!6rVeKA>7iRL%VhYRNx>D~?%SqX46~0~zZq(>DHUjl6>Ul?D$S~N&^mi-awLF^HA>(BM8LcC8B7es6@IO41(X$U-jpE z9+Q#TQ_Iw&%t^r3^CZ2lwl#hJefqyh5fgul{A-v%cf{Kc#^Vwq4YRY#Xi}+H&2Y{q z)E1v<1A=MQabJU5|D<&8uQaEleZF?AnrA;+E3Z!%1?>&#C*&D9DR6a{)qgt0P#enb zzI})p7^IHu_c5W1YUJo+B(PDPQ?&}rmv|CKSy<)iv{x}B97kEtljR23i;|88e0EUp zsj<+@>Dcjuezg{_wLNB9Z2s0=js8n8=FBwl0G0;k+ltB}NdZ8c=V9%18HI>2QCdCK z@&$Qg$;?O!XVT)xo)_`B;*Pmd2_jtgTl&fItP0k);54m<%eh~*>-0{Q(h=Q;We1p< z%O(L5w|&TbOCP5zJ(b9btwKIdSJWhGs%MTLdmDIJ%|t_42d1G)O-V3 z3+UZ?+u?EP3oECF%Aaf)2;zz--w_*DC6&s#X(G9Vj>6ur_YI0>JVxZnHrSuV(1qVs;i0b?L3qURcm5cO6(tUCF!@So{?R5 zNnb3HsVijZznE3zPDR_MShT)!`HvSHFu49bn>r`Ar*8adc&~T7xDR{#)H{`U`uIo2 zcz)zpY|U7d1TgYyktQsZll5eZ;S(U0BX!VCxaDxEe!oa3k4mZ);9ap8UKk5ggrx5` zRW$opV8@7;(>42Gv1Lt#K))I#pHk81AoC&TIY7JncU~cXS;pKOW7f-_$BQ^> zumJjfF9Va@Iv|AJDb{!Och+^PV#_p^CSt#i_A_%E$>xU=pxl3a4!xvO*3qxKQ;>;; z(*t%T0Wj>%m(jW;s;REWHwq(+S`!;)2G~hb=X5x*lUmV4@Qp=}CIf+7eG89DM4Ek6 zl$4H1nAK!uSJtvYMNaMj7Z|_R#s6l3HEGHt@68G|me0erdBngzzL1n@oYn-FI`3^+ zaeZVFWhtO74xd$<@irR**Ibgxhp*d}U$jv2RB0QHpn`aRxCwNtk9?`zxt(EG3(u5) z$P2WjhU9*Ec(>Amg<+s69Z%+w$1PyhlL!H2ee%*q3z-XJ#oS<=1-*ZAwhtxP0PuN~ za=`GT*Db3H{;tBUfXlmLk{bJhP>#($M2nen;-;LVvZdLaLavZ={yH0PwU8m;{)y`0 zWvr)jnv;tc9qjrCOOoJc?zfRgkaGwO+YLCF@?>FzLtus!`NoE*srC0zQmVKK%PJPC zkO!UEu9v<*KdHFlkk*V_WI97ev!X}GUzmf3#Ee_urJ6JP5iBJw2}#UV*IO5bRP^Pu z=cEs6oe>iP zPDda0{O#xNeXW4{l{6)HwDwUTAgtRZt78p25Ni$iYv`0M=Jey5M?d9VlP$SN_ynlME%|Kaz7tFZk(o;gW{D8Kr z+u`(|Z?b$8=h$=ra-#JAxSjlfiqs*a=9wpTyTpn(J$MLnzQ;nIwmPd@e7H9OXZE$u z-w_~xr9|b8WOtw*7}@tY3D;mq06GDa#Q{<#PfPw07kB{lLwU@7B>66ga=IclgHCx* zS{f$-=+m!BEolc22`(&hyZ5W8h{#e^TV1cg~*@7XLl3^}k(m_D`hvnS1_UnQboOOoI6w(vj@9xx&t-pD8vu zeS3yaJ0h;kXmN=ib>WY3WT4oc0p#=bGliDzVZEZXlqZSEcEPmgS4C;4$p7%E)Pr3& zTYl&+N;bU_xCiNf_0Pfi&xmK`7rW83uhR_}r%z9&!gg1m!H^FLbY-qHHAQy-88 zieBVZi4S6N7>}AY!waa3jM668=ch-h{xMW6OT>hn3OzQ8sTgw(J&><=0fNzWn2t%H z%>_N`%^!dM78Mwau2pD;TcX3msH<0hn2w`sHAAdrX3XC{?&^wZRo=6ZHFX2m0IFO;HxN|dZF&Q9XPz6QFR9#~M zr%yeQ_*6f$jkffLEdERdwmLNqNTH#z;&XWXc1xwtB1fr@JX<1J7lxsJPnFPWk+vJ=Q!hBL_}EW_ z;ZM5*&}7>ikv@AtN)N(-oHWK%Yipy=OLSBSI0~lS>ncH1{}*-d8P;Ulv;nirs%t@% zsvsZ&(gZ|$x6vgKAoQXjEtJrEQ4|m`AYCAU)P#g0y@n`NKxz_DdKIaWP(tUsao_jZ zeRlW#etyUC{o}|%?%dZkbIr^-bIx22sJ=eqii#Pj3_bM`m<*5rB#hj_iXwmlVx76o z|2Co9I7+#Ybi)!br@}due6+ld2W>PBoxd2AxdSBxQS?Zt7|++T>2GbtDYF;&AWh~R8{f$%1@V8UR zCF6-SH#2!&n*4i>8(0i*xs?*R9jTSI)BDn%lpPW56-Xw0}O$PEFd^Hm<>V;`vGrdrjRIToucPM>t@%%GMm?3PxHWLi?y*W56Gu9T+w z?A>cI7p3s&tlS^|P;IvQKoexF8f6nosYjSrTem$5NEFzI z3(^!cd}sp3E6gi@q}Kht%HZEBbp3R|ypphr#%b{x@_r5$AX=8Irb!A*SEpIi$^&XW z!U8K;2-h>1TD232*$|`2s>>nk6Dybvow@axJ_BXZB1bXAfrln!{-9s~o0M1jQ?OHq z?SsJOuhH(~1&1o1jU37dn^slcC5Sj>>6X(TU?ZyRasK~9CB#?yf#bd@rJBXGI!+U= zw|#A}#LMG_6oE~?VMcn@OjJz#vA>J-Nw2Mb+Sh{>2~`ru>IiJop}PvUoM1hBa8*i)vp zlh&|bf%m&&o?dulbF^199Ox~aW!t9GgSz@z{R}}oR0s2~1vS86kMLDM&z+s97#3_% zX9@n{Af-^T-NTj&!B^R=du>N+0p+@)O*vKr-~#qrs+6o0h*XQi{DsN16s&(=;GK$& zp&lCfijgnnyl=hbmFnuH2H$qvN=}KteP=wRL_~)C4(}2yd+pJW4gKG%{+Go2UsR}m zzi|A$ucZ>JW9z-uiL2%;WMDP==P84(=%r`$3s^J1yQn=Q-R-4Dgy9kq^~Kd)>Ak++ zX~F$dHv#lmC|R9QVGF%h$YN94+wGTck-e?tFac$Kw3_hb_bQ!#RaZA4O=zI^F;{7O z6a-TUis@d=o#y^3B2;HM3Xtngg&Slp0i-)Nc^`9IOMrS|wNL_Z0;S}~Slhhawn12$ zjfTlOL#_av<&LzWbzRLx;VhMvXlNgYb3&J*Z_8w$SQuYUb>r|KXPZH#^V7O8T(H4H?j~$e}GSH8Og? zWzme%)wq#!a5ptq@6ay~Xjh$lTlTXftM~QyktVN}nXkO7mZrAH32Qp3D+@US7X5PR zLy8LfmDH*R=Lu4XmEm-E>re32X9+GQweGpgx8Msur_|u8FVNZ&$}hf_ z2Lpx1@Yn~O1gKa1v?oxC1I878;z{d@=h3_sEpOYqP>B{JiamT9T^a|UGH++QC= zT!g5be>EHWV10D3J8iZaj`4ixaohtPR{Et!p&{Vj8spt)Oo&Ee=@&BtZJoA)SX5oN z(1_wju{9;@wa{N9T)<*4KFif6hvSt39i1v`lC**0jC%=t(bM86VQ*yNqL0UGA=By$ zoo}Vxa)iTqU<=AMn%*tr^ljgeIhHS`34V{I`J2OAU|ozwpYz*oSAb$2KD>lgxaQOs zWrxl01H#yd=hFm+?YqD|^SZ~0_J*We5D0AVRa(Q?uPueRzaoMYFCKY#JndokNO~u9 znO1(eEAC7%=T9$gw|NPOZDe&1+g#JGJU$kklTFyrT`ugeZz;AM!1PMAl>C!`bKT~d z6B(}qZv6!Ty##{S0s<7cB1GqKJ;`6$$JxYFiWi#-3IFb`9x<-q!1PE{um76l;e@@V z{Z|6k&x&o=mAPPTR?gXfvs;6-cwe3+g8WtQ9f0#4YK&DUv6Gs+;2tu zLc6mQ@CD>w#t5CEsO={AC8ut6?!U^V_?L%`szx5)+XWSsV}15N!)`)Ke! zR_=k1n9UH1f5YG#LV*6!qzoXZqLe2s;ahuW8^`Nvu?^R@=5GuoGDiHr|J)y0ri}|o zKqmlf8VuZbG{P?HX}_nmJX~Zf2GqhVAJ4Q#Dl0KRt&zXqET;qDb++Wgn|1HK$6{Us zTd_8tz@wSGqt^N)g00}%X#Vvi`orzW_^wTxmnula$y`lSxZ~)g=Z1O!F14BnW_Z^B zh3I5-U5bzx-(pzFlEN5m0k=uztd{Z#()32sSU#GKGB7yhly@IX@SBboK);7+uu68a zJKk%%WfEq$J0C0D(zTCjw!Vw1ztf^l|D<4xJqK&>h|gAO_Z)x5C7?{WWxu+^^|0-L zPkj3}H<;HpTIiwBXo>6StC0Z<+zpnDv?{8>PeLXssEkXDOvxm$Iit=C;f!~`LR)W? ztp##7*H|v-mos%;yB%yrOjL4uZEuzn{P>2zJLk5-RX+Jxugg{&HwlR)h@nKah{Hks?5Rbq;kDg?!ubOy!p$xAQGYIV(=FMlK2?2HY-?9DdPF2f zN|F+X(`#FldThe2&J26g zfLYMmB8H_vI607p5xtGyhF+*MHnOCrGe}5K(Ml*ir72p||f)F}v&JZ>tp`0X|A@4Wnqc8?W=iVprwXMeQtwpBkMxM@fLpQQJ2kUj3 zapEH8*8_~<_A=w4>*&+T7l(X2DyPoHUu;!fkQMI4FsdjW2w@S=Sxaek!W@nQdc=>J zhQE&&nwk45nyZ$At*5`4v%HQG?}2D}>DsJ++8BN6GKPJ%gnCc>YBQ47USvodUIX?Q zlC2Tt_AN{{x-m^wD``AH^vYJ!B+Bd5I@O?Q>8XLxh&=4zo2MV%5*yA{EqQZ~CqvW~ z88b127<)&S#!=6@NolNq0;)j6YX0-tb>FDbm?P6=ACW;`qu__^M(e^Tym+4Hvy$s3 z2Axy%?GPvsC z`b}DhxqV&jZV5#*3@S7fKyKd4vP|jj50O`%pAd!M%PATmzqVaj;-p#SlSrQ!Iv@!y z6bx1dJkFd$iLS8usP3xs2zw$&l)H}}yti_K-acfbIqJ|*fF=m|a#a_=LS~qT`2a(*KU#MB60Ig`geS zgnn2(!?ncwd(Jif8;sS zd%%G(M;VsZF9%~-K7>#7EiQ1mW!Lsg=?tza3)y=Cx3>Z%0Sx^>^Ucv;gVZSPXgeg*tB@V^ zxuAMsiwx*k$HeDVhx?2WHBy*E)pt$#Oi%w>If$UHD%{h47pHF`G!Z&uR0N3A;lfO3 z-{eJglA6F~%#wI%L7nasS)i9Tig;NLD*xubwH~NUt%x?D15z?Sqy1nDZ(0aNzxmdM zX`8&CgN<6BYY508D=i&x)Taq7*d-e9D2a{lJQGtTCAQNGDio@&$^mACqi&Y~PkKJ4 zFRCf)1$i3-i2krN>Ky(zbW`Oa^)OUXbEetTeko_C#Vw3bkZju17;E#r(8wc9ywgRM zXSYF8!%{dA5I$MdQE#2}cCsKRhNUw$h$nhQ=S$(~~sXz9@GgW{>4_yWpML)7S1F-jqBF zLvzy%!nEAnFX~)#9|$gksOEXJbk8Uy%t!`-l9r31-0-1Q+9N%*gX2+weO0a7tu(tN zq|)?EZTQ8ab#3eKlcfyS8>VIyNMZo{>CaDR*fy?i;GA~VO|v9*nd|X^s!|d=9NOzK zTQbR6?8-iEORv}@*wwNv^_np3f?SQW=&USds7?dY`qnoz3bDbe|C;x>ql>!4u9O49 z9$3BKcf0Q%ljq8zikzoO6g9K6u6of0!j5*nYWfJpiNQ;Lw@^=Lc-Dt)b&Y7H4-dh` zr!0S{(mW!)_V1(&4jG6k%@i8phpZ|e99s{RmgY3Nu}6h;5Dd*b66gg5O`k@{Ui#UV z!$=4E?cSqXLl({a2268dO+5qlcLj24Qz2uzo%2DAKAh2z$-;H_5>z$k{`~7gi|S5B z`74ugGI58nDF;0))b9z7+Kt((PH621{p2&vTxd~pjTp#BIeXbrQIGVZ&~X(*|3GdD z-rr>M%9-e_Xgv0nCym}K@44U0`1Ybx#Z1&C=c`OEs89=Q6n&|gC@WJ<%G>Ba{o2^< zir{(u_`Sgxlj4mhk&=s>2I(Wpc1MdB%fXDR%+|tdw*C@_sSJUk5*id|)`dJ_r+{X) z;Al(oEQ{>>;1CuTU28uOBl)9mR1|e(qixWq!yOgZqochNpQDI=>E8PHYXn~HqNhdjzk_47^U%c7`OM$hYuG3lt=#6m+M zkz0Ejdr70uim5Luxz$;05OYTORzLMam8Uxsc#+J(ckgc`)6v1jYtY{U;-DWXc2(EX z_a}oKy}TXNdJF93{YxQupO&hrb0+=JG-1q%v4QmV%Jjd+T{I*L^75xq( zLd*76&{t--RDL1ZI=}B16AO>KRiTqjXX zizJtZ^)1%C^>YfKC9}tu@-|<56U$i0fsUZPE9HIlOJsI91h?jKas#MM!$q=63B6!Y z?{<4L;t0A~8iii06{lm4xg%tv!^Tlt*rZ{VuWIVSuQ>qI_p3AYh&?4SFG~$@zC{*t z2V-^%%q+AvMU3`nvB&huN3Zg}*BDhbzPFcOG|VIjIsOoMB=$IWGl?Sr=f~GoRixez zg}*!*Eztk!CH=ii^wC~#T?N)+FF;m^q@!1JL5##GBG{$%)AI?jM;);o!_DDg#|c52 zq%t}ork8{g$$I6?h~ro5*rrJ5#<;)c#IYp=Gc7 z{7BklCu5TDNU;&4R~}%!b6wFlwN)9dU7RX}2~g3u^{r7s%TTz&H)42W8*V<4wdqvr>mP{F-lqc<(YV}RdqA8=6Ath1W*SKYYXX!e&A&Wg5V)Tq&ng47uE$_F~~C+!>4Kqks$03z*&V{Bj=fdOC%Yiv$27kjV*v1wFphd*K_=o+>mC!_uT#>!U1^Q69b z;@0x`J{y^;EiMXn11TE7-R3tV^Em=Zw7TsgbIdVa{Px(tWA6)3sify;-Ql>#xb|5M za#}%xWtfA$^8VIaV)^LsX!b^4W&{E%nfX|K7BLs*71mB)u$I3QAQFRdOL;mFg3CF# z`$gP6iGVDDr69@eekjHTqnTfj!K`vyFXvvA%6X{=kr@)cmX5>&6`2*{CzwX&H9GBA zt$V*CbMoX9zR4);Sh2gNVSXw0`@AJLp?xT2(LXff)Mr>+_MU?+Z7IO`{0n5hv@2NE zf%1`14vI7~ekUcx;fxdG9G3pncKCb&iQ17LNS_DKNAL@D+EoF2#`VVUR={jhI#4+<*{ke$OE zJ@&;!7dHzvZt$&>rWZf<@{w`wi7hdzYH!Z_4#t;E`}uvZWH=+N=w)qlos>S|IUtXs z1XjZBLeFhTnKN>8JPkrKxWkalq#FU;62$#&NJ0h^ggJYc; zl^r3}3N$^BkA2v!JLZGG$%wWM?rsMh_Y%4Qo$tnkF<>Ydm1Xf`d0_#`feaVIgLly1 zPD46sDl5}CUZEc9-y_PupAj-`buzU;*=)_UFi3r0gEnau?6KF?d&K&~S%TJz80*eUZ-bfQ%z2? zI*U2Rx7l7EJ!=tYrd%;0XrOZC%gj-*G9$T6eIU_yds9*wuDGG|!!(POw2@xo-MEy! z^v<6xb8W!R9etg}2%TFjd<(?RQJa@~IVnI@0%KD+$-t&LVO}PX>&Y$b85X>e8wt_d zeJoyGO{(=v&fBTc--5h7t#jO6Xp6sg5kPx9CR;aUf_$m77(7MF20cU7t)Ju+A2C0O z!au$olHJyNQKv7Sc8mw?Fm0v<%TmeV%t@Ucz zF{iP9@E_>{EDvH1XryR@aIyv*5C4dKt|W^^E|zowK?bB`e7u)H(07Z4Y(Yw7;h5yu zrw>Rf5QX?z?0)es+qHF?+?feI(cbna!(mV*_&rrOppl_Hn@L3}P~tmO@xxwnKD0j6 zB8VOx+&$7;Js*~4#8yCpMkZGgi7XCZny^XX#q$T|dhIz@2^{^ zO{5TlBzhlwR5e7{Mk0Aa^auq3`q@YK9IrKYnXAH8!N&=_>bX4)d?v#6jw?a-syVVy zGsaDmMx;#D3e-ilqU@EA*`}}~MzU@1*Q!!-V^h6aM%2yQ#}rN_abhQ}R=T|8q7Oj^ z(%px$0wMu=uK^h1j<3lQbt$hmRgW&z%=*XKck@=2yGlqCovH(QpCIi1nu++Q?2xG! zlkX4_hPd+rpF50;Ow8ZPZl#a<3NW#-f}bd^>Kb-yi}@IGwDBFsFnZ)$kn3*zoCm|8 zCVlxg(J~|WSzgaBAF+-`H@!)rUz73c7R`mh*Qu5t&W^jj zyYIQz?4U4;-~Z@}O$&JlBywqHm6-20pQRTa-*?!9V=YMw>jhhnkiSs+%be=fq*q64 zw2@^M_cV8wAMP!fNYySV8=H3x(3lOg+*|CfJ>We0BMJS-#$pF10Bq;#+O zZ@ZTi$%C-ioK^Zk3E4i@H4AFP2}xf5tqk-}Y0+y+kCQc7GhAm(w|=)8KmCu5y$NtQ zH-9MkG#5t0h@)$v`KoONlCixI55lVS7ESe=8CkCBP5r#q!B_K9$nZqC*_OKW zWkK10EMw5G*@4s>lC+Sl@)~zU@Nw+ODIBm?YvzxCU@7O$O{YjRiLQCWqsvg7Peg9Z zR+y}qN+oF|%TMbA+k(0AkLQ(Nvn-_Ka2!A1jMmC+JwBWcaob`%uC~vETmVViIAn&M zdBM^I5#jNQimx;YT+O_pU`xQr#J$wRU1Pmh^y#09W~}5fuN}+LrZv~Tb668%8D|82 zZB06yP!373h}F1?NkPF+JDQ4^Og4Jea^I@hIJMjgkUTZ8MZLU#PaV6uCjWW=S-Sk z>fwiw<@Sd;z8q(*Wd29saevyMZlLbx*9aZO@sl6%pNQUE-@uOn9C?H4o!p-W zK3QUV^F)K>TTXsDV5jD|rg5%3`q;dzdnQM_nV-k0H&B}2COmU5xe=LpX^EdsUaOBb z-$@T`b`w!9d!9|mxLG|YW1TTX8~#49J^H$V?i<&%B6?ns(_~W+kU_Vzu`;EcMN*%+ zhzeU=Tr}!)nrJjmkKs^aUq0X1{nogo^ClwDzRbO#^Wudt8(+B-C6{IVkBhJ|rUwQ1 z90~F!AMNQ)7SG#R{2*=I4@=(Ii;nsBQtyFP=fIm+8nL1o+XTv@&_gIXF~5B2C0>tB zxc~}?QmpVWc-CPjn?Ka(9^jTk5shDgj#{9HZ+jDX4?p1j%Ifx6*Lbxv_4k45Kv^cZ zZe_GaWQZAfd-Hj(8|b8xSjXFRAWYj}6B|%<`oUpRL`~I?{fla)xso>?9aAEX+fK|l z*}WL8lOBVm1ZBiv{q=f zcG1#-=qrIp0f3?jyxQ&lHdo0UEYIrs+NbQ0;*CA&QmO-?z@P}Uya7}6OL~>EN?61Q z*pVB!_OF}&Kk-2qnFo>S_YrrztQ|xNnAj9Kd<=}d1N;WgvK~g{`rT?C&=B>j^V^g= zb4p`v&#BK?VLK+ps%^TNuqxob_1O+cIe;*YEQ@TUOMX$4E@sl)_kK-gK120kFzP?f zwmk4G5>vWUQ#!H@i)y}c;!)l~l{xQSasf^?BnW0XLZ2Y$BNmZTW5>3X6ztI{oR>E)~J!Sw>;~aCw#|!LBJPBpl!`359 zob#qt>hnv&LlHzNcn9fK-qjz_-ku@zPg7z-J&{bhRsMH=p?dQdvF|1M|90<^AE4~l zCyUoonB!(#YDr||{{CWnjiE9IswWAXC~{vf-u>uM3@jUEQnXoqeMC7It!Kr4x4sRB zO|e{O^IHdyp$C<~z+>HC?-KPqC8eA(<*OvH%38qPq3ZAPlK22V64TZXs*u zK`Kn+bDjl=-7Zg{P=RrB?`r2-_`Y|YMx%P*tenUIdhTkGCp9+s61Q77%WK1`028mS zkMrf(lw3UvZ_>yxCV8!`!yl$LA;|GzY8G7=92e*Q#BB%A1LPU2`A54S9#$-z-k=PJ z#h)90tVoxF0WP5cYYrIjI`SO+?abNRiJ?q7+=-7UB`}QGK`g%Rk4$m2NH)(d=v^STRnOihjc;Bzx$GqqhuhDzmnvj}8 zMRom8!}-4mqf#0$3t!&~8M-!;L7e#6OTE*cD(daiMSuV2$!0 zPEF6#iW!3~p1QO$M*SA6f=RR3e##_-ImP%5W?vHAkk7X{N84M&vuOSUI?KK9S3qcr z#k_rzrBs-KpskqP$FN89)4@4=bQPLEZh1`%Erbk8KhJ#>Iydivl;+b;{Kh-<3)T0? z{~Yl@s%fXrBHPxr7P!aB7Kj9FWkPyaR*7qNh2oa^{@&?&gXOpjAnR9xc@Z#jQy}a3 z1NU-HoW!Irp^Yt2Xqb4K!|%ETcu|A@T9*P^J6~@jh06+Cc}* zzSp+e7B(e0x;>wd!f9Xi%^S+{VY8Xm(s`^_RDm#`Onkf&a&vefbZL(3nhx#?w74wP zAX=Ek^wVTRJM=-o8LA@fe^EC3i1s5IWZH(pVs#ZMoHSYkd!W4zaoAFDp}lFqbivn! zOI=$;OIzEKQwae8J*9g&?t)i4>(po0Tk*MPzgDYc%-47EUux>ziLrA#Xxwz#0w2P-_%v? z-4Cs2DR4Z)p zu|i{|Kp_ZyI+UKyCHn#JQ5(FRH^Hc&Iu@pn5~j}$Vc-ENRXA!;6&c!RCw zjfWB&Wez^zx|rr3s0_&}QA{fdlA~2Nfj9b{>h3?aP^-TwXg^SHv~q06Ub&uCcr?I) zdh$Uj$*my{U=<;4A!6F_3vb9AWtnaUT)2fy`wva`L_qf$)VY!zZIKfY|OQGr7k^>G*F<<*&Wc)M(pP5dA-;&<$@D+yJaiu=hH?ASIj19 zDfTj6dGW!p2qr=k1;U0M-}<<|X* zT%R$3%z#ZXQc9TMa)x9Wb$l}DC1gmuSpj>QE(MF(f~YMlq{-7Fk;pR#Tg5j3R5I2S z)BqA=>jiY!pbf_gSW=evD(uTt@1cL&cB9LSx!XVhJ_bx4s)kKA0i~~sJ7vy(^q>=L z1AI>p%ZaE0AO;{3aqrc0Vd58%9CLs_6n4nVHONrsF;SBi${wHxwS6r)RgAtZDN^Xk zesc+g+yrof$|LKd)Rzgp!a%)Km2?@%2N~J^%{du7+(RkQffBr?K0L2r(v=JF2V$T` z;4Qw$-bt`smxm@fGFW~{! zNZ_R1u|`NAI!=X9S+h|MCI9zXxgvNYh`@dp**OB>KLUa9>^M54ubdkJ0MQZ)@wYi# zG)_PZ>xj650-Lgez|}W=WO(ob-5y&Si@r~}03C=WFNVjUy+R)L{mzD*qV$vZut~)% z#H0I&Q1~G(n;!d^s)z9tG8HV*MPGEnCvf#1EmDVu$TD95Bi=e^%vlaM1NV_cv6_j zsd@T!mo}3N5J?UVS7wuXTZ<1a|N24tZ%4Q2)h0NA8*%efA0s0zEo0O{D^L?TlzxQ^ zEouT|hyb+2jBKxtO5F+!_yQ;yV5+eLXvxP{)_9IJgei1_jKjm2@R7I5KURY|j;3BF z2!3}(kk!xR(6Lo*Jnc1S)W-Op);$Fg{)Wz!?Rl|aP&swRMgJp@I?MZ%=rX^@UUD<+ z=O^;Q2t^L=gK~U;Ip80B&i-~pAGiCY{hOk=rh`eIy(9pz202kp7X_f33<;z?6ZZaw zUSWuu9vI(*e$!;shj|cNaz)*ZbKL+Y?%J_e2W`538sYfw zG+UxZAjW*q*~U=k5GVm)LVXVkPw^LkV9yPR;L^Rt-=0YorZLG!V1WoF;d-tLJ+Utx611B1t;ZvN zc-?-Z41T9ZqUNfgmbeV`UWPwJt8VfaRjEyJ)Um94a0jFVqo@lR!tA`kF3HMT2r-A; z6!tW5`0fkcdg}ktR8@vX-U+K=!ONC1>d7V)eQr6`&C;Q|Dtcrcp$bbZ+48@=^J~U9MV60jK4We>KcC;`Rf<2t zFBYzs7w_-1RLTCuGkJC6i$43Zf`IzQyX^X}2d~|;Pa-KpO|QlgwSf7a`nbdoKkSM3 zgMU}t)}Jvy-RG=jdImQTKYVrmyFT&?bUl*^6J~{>)jJc9lVA_mB*Z0e)aZ&o3;g_| zL(c=b`}C&bL^krdX+Q3Q1*1eOpnfT}FmWa|tbs1hdP_#F|>Zid*oV|rx813qu z@PXD9_F!S?~{WN9OT!zMSSF5Xg{Vh3jWi;o|Gkqw9R)zE&cbkSA$ZRqO^c| zN{;Kc{cXGS%`_%`wPuHbKo7A(SX=eX37{oaH1yYuEC=9E_GgF-JgZz~=4M?32CH_n zGB*VYMmpQYbeSXLI7kXN;{_c3el!vp$L@3SQb!5LTa`pX0FE#eidJ(snq?@=bNj*a z%mmNrxEvlPZ{>t>zmhz>UUSo5W>|U(An-JY9+g0}usiR#tBgIL_)Wj^FvSnG*LBT% z5fTl~TpRDl-#s0xvGJ~Wadq3tSB5`)8sfDI!M5?2igo#(I~*3KNS4@`YR$Gh@a*SZz>rAsM5DH4Dqt8mA?b*uq@e)WzzQMnwx1oK7&Bf ztxB6b){27GEl$7yHt&L@@WE32)^b}E*ul1PiHoeTx2fMh<(*eD)eb>zI~Infcqsds zI|Di3CdQJ>Obr;hq>ip%lL#*;AJL~``_;o5)6PM1Cakf%rT8x?4Ad@8$gq9ue4n)9-<6qwjrv;n;A-F!o21sR(46;W{J>4SX=w@ojJPdH z@k5deSOmZHL#ekse&Cg_pI4ME>=KhnFzo2$dz|C&|?FN=NIl39csM zT5);|>CF4AAPFVkIG0%HJq%E^9qmt`0~<_gZaucL`S@&sI`4bgH;cg_Z-*5gew8Hm zvlgGkJYI~()i?K#b{q;Y%paoJq+LJwv~0{0ujtbOd{f=mJz}XG?*M$5t3e1TqRe@* z?8jSuIFaK`P}y9pE2A?LCYf2%;7#y+WP?GKQK`Kpr2n^X80Eu8SNqsIwJ}HTJO+D@ z0u(M}uugQVCnlD%*vN;~uaCV#-m|XCdCxxj*S&D*>XU{}kV815q40{7VTYo}4=^-e zn5mLg|6`_;=0VaDw&~aA5WibVsBp)niQA?>3Imc3$DdRcff-%%d_Na2;OXZ!S^WpT zKON$i0+0#6YvLjhftpf%UJj73GTlPe{4VHZ%M~n}L(#kDy({#SQzs<2A`#bKE;yR~ zDTqF&xJ-APLn?{ES`%haB*HyPhI+AeF4x{av}J@@o#1u#Aco#Fdy!H}fF~$DGd3ho z+x9gbrGr$>JaUkKlhaS*Uk9F@e#`N&+XDuNxhcF(v>W7}qh?B?W!L`L(!G%;KiOnVQm_4N8De*@Wk_-ls@C!=-icrt@u+hSnK5{6bQo(q4rA#21h?C)F+F zpZ2#q&6VYiv-=y58?PYDare*{K1qJ<0JI_ncQDU!^dmxDS_lUWXo?!NgChmy*5>Z(2BtKs;0aKLazJ%mW7vkcG>+5 zp-VkaSsG!Gg%0B}xqdmLJI4 zr68Do9JC%R!F00?Y<~}n;?}w^%4@(-AJ-V|@4_mB$!6bpoonwy%LS`gzZ=yII3*_i z>?=wB6#nAzTvSH~qu}|aC-#H-GuB{B@Q9eFyaYBot$t>#; z_dk{@?!j>ieoLK{khP}*fx8)&wcpbgtyDv=8@NB*`~K)bg%&wqBxsR~WA{_H#dbMu z@Q)YVh~!k#OBY~%Pj@rz(oSzcu;7@FK19q?t0sFnpwMK?+(}|aGUI}p(5A=KhhK*E zXGg$+ErwC7A9L<+%|JV+Mw`&3&A&t@tH2onV>z9@ccpD3*(D6gpr&}%9};O`j=YkW zd?@@1mW$LXFQpi%`=^_sfP@W*u2zIdFyKc!I0>wCW9~6Cc?GH}R?V(!2A5jSqxBk# z;bD>KS}+8Yyu47u{aIE+hL}4whqY-8yp1Mmys-|Lt}`5fW&gl6Eb5P`-&l`IHs@V0 z0Jx4=eWMF4$cVYZ>sMtnO+-^?QrCyTpr8BPCdcO$dHP+vrwi&7O_P0xgEh@{;J!S2 zPUz;<*yHV>*Zz?6nW~j&ZK;@#qm0ABFk%*+>8%Y?+^a6^?EMxi^^7w9_UM zywk#Qw3~J8M+fQ#FlA7aGt`9Le_^~PJOhIw<=6jD2F2rp5a|SW79f#9K1P-An#d*e zhI}Yhm~&$bW>)tF!2O-XfN|$o&?GZVsD;<-HfgUV{NJ(WTj^P1jHEl)}Kh8 zk}0cq{XTZ_UD_giV=b+3rvIUq14f|3U)x-INBjrM{ji?C2PXj7|Mn-+q?{%z1+mS_ zqWOl}uQQhh^)a9z7V(P>e4FxfB#`+HldZbx7|*34`0^J$ww|X!{!%f#N>3`^9C=0c zD6r_tiXD<5=BnfQ_o60xW=NImwLr%0vCN-X+&Jc?-l3NNeoSA`1`IT|^_4^KV2eKF zTLhwHFSpOqtz+S*F|B$CWDGo-BPU%=#Cn$!vY&7K<`4IxqSo4KJxBGp>`&==X1YQT z#tT?U0S|+Y+YBd)e95E7KVr@_?Ul>ne#|_GbH1@aa99~{SO6MnW97+eV8!*f85zV6 zF5@^HAFqM$AF$lJ7qk?cnQHFw9v&XbyU~#2ZtMT)UM|vusLQpYEcfxa z&EH*)J{wLPP8llQ4j?B*Z~&M)O4I|iv9YmcGu)feRsgwd9TPG-R9sO}p&E0Izbl0o z;X24EAHP2RDp{mqGu|r2Cc3ltGfVUz85cNb@r{7(l>zSW#DjfN07*}+-+VXFK0#Z( zOX4|vW4c#&hw86r*)z$N1>ro{%&K^ZQvFe|j|-gV=xv&PUdPiXGhQEp8}W&^wzVzz zQct!%SSO7K>><&->8|L2VYi;19)|=A-XxE-mCr?Gf8gz*D|8_DKNDaToWPWSL}sR< zANi@%Y1f;F&jDz&OH$rk$PGERW~F*8|7R2{t1eB`Bk3T)gYXX7(=;4guM>6$0gHy7 zEFS3}RV=8~&T-uJNSa@`VUunFaZ^H)4y1V{P7xaW2hrs(ya&xJSAlXZ*v@7yppmOG z+xhaNbMCQITUq`DLr}f0e7a7V|ujNxX2)+9V0g zDF5xCwz4!is8LyZJSik8>-5yEID4O}1W5@MQLu9Da$w29EkmgHL8P;s*x~lzP|muz zzQp%5+K}~Ve`1WELUmF9c{1Uf@k^&_yG}x zOhBJxr}Jvbw06KiW1O<9e#CyDEV7un_CY26v! zSH1z3z`BgqLrRy1<+iJ@IRNZt^bVX4t`jzrs4+%3IA~1Ya@*>DE~BsKwP})wbOm+i z>e{RAF1@91c$L~|x_#4YHBfh;HUcedW~_KvsO?~^%N8*y2hZlS)coTFoe`rNm5F_t^+Jq~+na1zbHT_UIr&aW{-v zVSTPE2dh7hBzKKc91UNOB8BM?#XZ;HqntDTSm>Wav$140F8oGY9vRrpNWC!Y4~lZz5P- zdMh+0{mG-0kab3%pzRL!ok94C%i7Sw?R4U6R`S)P6@1C2z?#EF=|R0xbFoPboq4jA z-GzEc@)=`9!WGeJZsp`=;*#AnLU$nE@XNgD%nl@bO^PigGK7%@w+` z6tGuBh);1Mt#X$51jKJ5$aE1D7WuO1^i(T(Ka`EL#zJ_63Ghy0eVY80)+|I5_)nwq zlToMkr~Pul>B1)0@qW>;qn=3I{yyv*z>QGa3p1z4uUuw0i`-vmDr|-!_Qq;556EY1 zwZEkc2d;NVt?h+nNpyP9jqV*A#kKG!A3VRZK&$ddnkXd48>h>l><2b#eKiYPk&11v z)Ce*I_2pUnSn|8g?0J=xl&#B0MWS<2Q>owz3$Oj?^e^pf8}`=%amkFqI{fe+iRHW$ zS%st^OeTE<^&rBL>;KyFJm20D1^%);-|nn~`F$lHvR=q8jn{TvX_otRG;L6c=(Hy# zHx~1-v_@g)tw5f8TSaMz;{X`UewX=wQgOP zO9fNXRjp0(+24=ot9M234CE8yVr#N;e!h4MqpoW2OkQ4Z4zKrs7~b*S|HIyUM>Uys z|D!t2;D`l9ioyUYO@e?9Jv2q>5Cjr>89}8R@P8UoU# zcR~rh-4k_QnR%V>`rUQ!x@+BgfBuVkp6Bed&u*X3-e)Uk`Ro< z(x`)}n-@vWi!?&zwYlMSurYkFzriA6`x)gqh4S1f_HsMe->Y0^th8Hg5w4uzvAO)E z^nMMd?|}NoHwAW2eRq>@Ugbmv4c8QjpJi*87A3%jMq6!HKdY!%NXg(Hzv22;!S3}& z%ALKB4~I3TY(0&wt#hvuqnB*eFHb-yrexqbYHFe(=jw;^hQ%4cdc_i&Dneiyp;FAL zg9eqtOJTZ7f`RSbr5obAaGj?5%#%6k6gy0>DARgejv=OtO_+1Xwz*tSheX;!n9tw^ zx~B+zftv%ppa@NC{Ue$dQsAQaGlRHLy?McD@0}dn@S2Ek0gC&>x`?8i(oO^X~Jj~ zE=su*f)f;$TbpZH6Cbvo1Kk>XyvObt`*Vi!ip`&^tEw`rDR+Q%?y7Eoqo_`2+Ht;Y zI>xSfYbG>#nR~6%g4v=*HN$0SHg8bR?OdW*KkJBq9hv(8%Eom;jBQOdWIyz$4?ax0 zFE{{icv2T}?@{h^ZKKtB%Eqp)h<#;a2UUZ54&>7#N4np>n_T=x)h<;O;bL%r!LE^y zHy}u!C{SsQ9;ccfA1PFHg~^QEkv0r_CM4?e;#v4dZ3az@$fUYz@C5#{~w!e%QZ$55x->xp^Q*Fz~$KfAz8Vhw#2~tVD zN*{4S2hCsw>6S|h$goA4sMK6`0Vub>e$X5xApy{sp?7vBj}jc;+!yQv7z_u$rfZbd z8C8%zY~1J;dzJDsHdc3G%6s@+M{n-L%#1lxgc6DVT;%U5Jv|>&Es~3Gd+Ey*CBuHd zH24d^$Z7>q-#V2$?^P+NjiYmSt9!ZWm>;^1HrgBv4kvnkRygTu5cVj%O4PfK?U}I_ zv42$^THp4niz|r6bDX{HW-75v$$-=x_%2U_P@rL9b@R&ob7MW1R(D^_re;`(za7>4 zdFQltOBNSKcxx)0_taBF-u1540~@^Vc4grjnhnfC);CAA?fFs zw2w_ygN=9m6}k}kGnqRUFAHIow?I^So`kD-J#e8$T^!;#awP1~KC6guskd^qagz7h zYi;;oJlx2+V=%D{IA~ZNufkh}5jnjTf!pVDU!#Z#&AhmAIN!nzetw74(I%Ku!~A?U zCCiKlCcc1ACLYR{EZ@sT%nep2%Cyj=gbZU_ef`R=)}_nWI|G+y+PZ!EQwcBE%1z1^ zfU?INIY}k<0w2{GTDNafX0^r z-KD*^mgA6P4XB$00NyR~o$m*CGJe5}!s~X3$Ryb^z#^m#=({#+DbD;dQ-}2#{DsHevjj^hR9!CVw2<?VBlimdUUU>Gem!xh^KFGGM&xXe;uIpAggJKPrrc<3*|+&3AVC9rvcJl>;@&wJ zBDqhn8JO_FS95x8?3dU~>d{AAUGbx(KJFHxkQOl>8}ij&H`-g=yD8nUf!8Rl;z~SP z+*6b#^kB70wM!)a?vz#-kbq2*g9%_pjL#(2HJ+ye6|x>poGaE%*~CeMi!;;)Vx}?V ztGO!vC!P@`!+c$ZX7%OgP~*}B%=+9B&}4ASHz>&LGGa*_be6g8 za=f5}zhtpjQ}IZvcAO9hXLzg`pQvF8Szb=39BR&S(SZ+((Glf6%ONDgy)zkV9ihil zv^s(l1R_apUNV9RPR-cO&~$;Ww`(46(o)*tX4VAhgt2S0ph+0>{cJ{Yfsom`elbG5 zZ@r^UYCVUu(r(rvfHPs&Y2U;3ew-hH+0)iyY0Suyi|n1*&~>0m>hf^<@PJ$9RmFah zilz28&|@`bwJo7jTICGhr;iOYeT`OBySHBs%U#}gQ=86RHBrtfdD!%)e-Qqh&|SW|Dh6>=cURG|E5FualcBmyFQRN&V;heK3ACo7 zy3*Yd8Y6@!>G{mJZViudtN_LX&sf4e5} z7#*DdlCp=3Y>uGRJpp_<9uxNAl$$-({bLAFrF$DUV0ZR6Hv7<&UK?hIqQ1M+sR6Klz$yM zmLV;)F6LUWG!eE(ar%|VYBiT`L3uDm3SnD2U`6drMih!oS5v`Gb9$QMeog=#!vwOg zdqeLPg6Y+?-)?jy3ucby>H1Gc-jCM&$KAZiKEWvy>d@r<=zPAb32{h*pPzrfG1Ifs zyGWDut99!L=6CI< z|29LpCi0RYZ9E(noqi{F&Ws+R6fnSe z!xHLw22Hez(DnvT4$RLcXg5(lNiY#!HjIU#q{{ z27NDH_cplfw>|XxVdQvWt4<@z`9|gEeAjP#^xN3MQ;ilQujs|6mWROx=mr2AZrN4i z+MN$@!zwP3VpIY}OSCSa?_RdNlGr7k0LSz8sg=1QYe=#Z3CT=g^uxuGcG=YY_ztlZ zJ)`@)h%gq|*!2}?5bYzgqN6*yLr=`e&HAtMuP>u`&P-RCw8Nc?tUL%^S(Lcgao;_% z;qX25t>L!n`b$sfrKVJfYT}l2ZFF(JKGBx>8XgvQ(x9q6qzrs{6JukW`1NES*u`t> zd_Ml5Q)TN3BUi;#OBtz*i+J3wFeNJfj|(qsu*ZAlkt_F~0^+WT9NmWkoPnDTr8v*{0oZZdsQBL9#~ zk)ZRmv!`3U#{BhQ=a^ZRP&Pe5Hs(-pIvq38z+ zl~=>3j=(b~b|>Awm@=p6?R57RTJ-|mrEonkK=ORg^XNKNg5a!p~{Sts~vM?cuhHXv@k30LFDvJV;t)DGTqo0 zrC{#Bp#Og&jV~-J6Pd3X|MOPe1~{zX&aF45Z3!SY9lqEWE-Z8AJvM7{{4RMht-_h- zigi-07}DIf`((PFR0^v$=e`D(t&kA8TI2mJhgxf?!U{B4l_bY9ztx~OA1AjyR*}4%Swr;Q2rCU{P`d}E%b;4l7EOuxon%WXBgbr*ea-CJwdo@WImcgT z;UIlIU3P<3*wy2-;RJ(smjA=|8c7DpvIx$Lwx0p-T=#pfM`prZ;Qs2CI4sFk>RUFt zywv^l4Is49D9DO=!*MM0+;HshJG+#``3`$PqpzqXQbJTi zZu>_eMzf#N$f;4i31v{2Il6`fUTz_IV)s+v7&+?GGI3CaDEIo6GGR^@nJ_#yBzRUJ zYh(-OUD~l3xLgh8=rckp(ZSF(b%6_DG})PYJr$x%EPHepa>XQcRQrBSHJ6#?keb9+ zr?$2R-`20lYk-T%;PfR+BIsXMYZ?9Xb!qU-QVIpIah(6LabL#dJg5Dds#t#1K`fH% zLgC+i*%zjBUBFi*7JN!B1HNxM_a9gH|Ja|uR(8Iht}mk)vcEdhpTH*{a=(Ya>3{$1 z`xKFHyZHY#ku-I3qFZs>+bY5=%)-{rJ)-o6@IvLYHI&c4DD6L&d(EzD27QtbdLT^H z3lrIxoeQi3J*|I!bt_+bkq=cva;af);F0{fgSdB>fH}ur{b~$=!aWZD9tw3Ls%8eb zQ8aO~&mDx~Rl&qCO|`E{&(|vJ4~^-UX*z%R%}`VPRzULg+RYOga?CDwj=u%jYBKtg zAMe*}@oSCnyLoDkw{@*6Dia=b*QOO3T*@^LA4985sp6(-GsZ@n165e-lF!5X-&)7V z$4l6c%d5f8);#{6a$i%J7Jo&?QzoR9I~qM zS(dN&ajK6kEiTB14=3L!@!9>75lh)BJ|oC8rA7+NvI5m`oCQvbE#8#W^G#dCC8pBz{3A$Z@epA;5*ST)lS%9;U-kBx~D zb(;SK3hIiJlau=Q01ncZr2^?%)TJwa^$T$>mW$y$%tFT?Qzs`qLOs+0>b&%r5}^`_ zm+wLvKKr+Aeo%5A7J#8IcbpwgF>T#90W4M_%QZr zzr(7`%>;RR6u5kwRzv?)ssPi{%>oh~!4Fp!b5O&qD_N-j^{v;CRp$7uxS`z%Ct&*N0B)8`6o4qa#KS73~%Y zJ@mA#B}>U*uSlf1+Grc_X(d{V@)O}IA}y`0lfD49Y6K_%Ji+xM`$+1`#KfK~Cso>C zjf=jf0RKG0pyd@VK2kU{SuNuWo(Z35d*`$v8rPZ#_6=TvK9K<}?&{wW1IdK4FG!bo zAH~^19jDLaw6?TNh;s68z8@xp(QgKt=O6(A?@|}hiPVjYk4I);e!7*N`$Jnm z#%h6ncmc)Gnu?kIM4F^h#eGgYuPU<8SAvg8C6D$McfJ%U);7Kp6B7f9X{pl>NIv1x zJZ1E11s1O}Z~m*5bOBZpo5ykk?4>(65I^6#X8J=b`9R03+T2WJ#1UEy-fja-($s=; z;3#P&PD+_|$vrJ}x;p2gv z|M|x94@J=wpaf=x{lC}#4oBqY zk7VDjmC$)|$xra&vg**C@73VHe?xatqysnI++9VAvv+#VO%43N_&+x0z8ekbsaP+{ zf1}PM;R+w?VjM@{JhmW5o?A~01k^$!!jAsjfvgb~R;w6als+`HMU$*Inp#x~CS}PA zkC?p~E|2&i>ZcyVPUTsYM75rc9|2W{4_-PLrjA)ZuXErK-F>jfNIiEFZcjjHc}(&r z`XjTib5Chr>rRR|b;&Q6wY9{5*1!&R<@+d-ujv97KwNkgVe`xMarM`?7uHSy%7Hf4 z@hNc#C#JdWHlJUgTRNMy>)t+N*CNy$TOLrbp4v}H~PGl?-A&z272)RbMX zIj=h4G8ON(v4~r)V=P`X+lnW;bCzJ!itMdxjhPf1k35-%j-ul-zbDRL+DE^x)uf86 zlBWVLTaJ^|0mEJV&$Y?MpU^Tu5==rQ=;o@O=C6#TdR+x$pc(d#C2toLOn68{(s1P` zN$&KvrHgAUeE#6AMrEQWT5OzuChh)_TaHY2tt#;E5y;^)@TjJLE*uoG<1b7+%4V?% z`yl2NYP)g)q$`zs>-{ML4nQCnSoSH0sd$tjY7iN!Kg*>l!)~ezxvHM2U6-@uyw=Tz-!Q3NNN;-S&omU8^s23ZYWP045rO} zlD|jaAt;KmQX+dg-wqDS-q0(;SD=}s0sk`^k+_*GY_59IZYYhFdP!e7_)d-ZWIF{O z`Js33EEm#LvQlE#K28NBS-@sfG+Diexp=U5PC`wJUQ~RtTKdrBSCI4zODJ?@sk1EG z9yz<+_%eLHx^Y6!A&80=!YOSXlI8+*>=KHZ;*D@#Z_WwX}nGb0qxDBok=Uk zEm*0NXePk!26G>ihI?n@38Y$bmsY=i%R5=O zl?Q8|y+Pw!JnZQ3s#DSaky2XnjW~jnJAuM^ zgiA!eYgG{*97i}XKX|`@B&Gp^aK_d0$ym$I7L<}|;=6Q?UhIlCai?89#C)7VTM^b3 zz#NDu<_Z$tL*#sd&x78j*|VKT)V&P}Bbm|(qIZ4aI`v^hZtJ_a8dn+G*=;B%Zg%9f zN5<~H#mZ`MS690?lWx*<1ACZk=7){+DGV`?F~9d{_@k_F)S&z`edXX&LmdvZ+@>q< zS44kovw?ftdi)}{(v8M+!tMn|3{0XJl3n{Y4JNV`S`mSuZF&0em2-1VP`x4xYRJVj zHB7dSPc+CJ7zP8+N&q>enH=O|E0?kdLn?Nej1bDW#ZY3&deSH5DvX=tUbiVgp%`w+ zi<}O|a}K1&SA1TS{V&^ZQZl@7+v0=Oz~_ z0`)vHA?bM8bnjh-8*Ew*xn>v+ox(onc~OFbL*zTY$SLD~bxyQnmQprp`eTpb+7_|S zBrRlHX>}Y}S=9RcKnZ`q?~suA{Hwsj%&+W_*SeSIxmly7I-G8ErwU_9UL>HvO^SF_ zsl@V?lpUIM{H270E82*3-C}YA70m%>Mx0SeQ0JQg&z*%Hl4sZyFmz4L2=$Dkk4^w; zT<3{g3}r@H_Pby@xSSvk49x`|A^m*y7C%#HD@$~lZs@Ot(7it_EaZs7FS=S62g?u| zJeG))xvwVFhA`Wi&zR?vO;e_IS1bap-|}XQWr2QTp^N1yLKx|6G-lxf#r>XH+<dx za?ACYj`k#ysAk9YFYlf0+Nj(fDfS%CGwDZFq^#^(Zr2!1Y|Qp2ZVNS}B<@5hQcyiq zS$Uq*c0pn!6^xCp97(N`+OhF+aHXzXWfELVF7`;XUaB(kBxxi{te?rsCVB|BCN8O}C#hn~lR+fQ?q1ZasHO7dcI~rog zV&8!LUY41QUt}cWt+AbEYtE;M4WQrJ^$DPl9VRk^SYAQ73xWwo?w!XE#sQrP7`Sz+ zTcWEGZ{)ye(JU84LeY*|hYU=W>q(~lni;9!|MsM=N+Kn`<*;q*;tv}&c_17E*I{t52NiyfP`Ai> zx0fTNQBi}5xFYfDPqI3hms~)kBgdJ|P- zzOguHNO&~uysB{57s?uD_O{5);_gXL`p%JebL5u$eOL)VDXx?LpciJ8=~0I>dWETA zp`F?@xA~2FI)abEOcF2G_Ok_5Gq*?V54LwZuG8&CQ*%q`GTCyxd`jbzs?1;tOqf4s z!jk5-)}|8LvR%nd&S6LU=^djzTa!2Spd7$I&Nteu1fMF)-Iq>Kr6x`b4R425cH1X( zt9z_rd$bQ)Q3-DN=vBhnZTrjMrD>x*gZ+1%!~wwVI3FvRxgH3W zDVXCCmkOUyTI4-6SMLiPU?a$Zw$Ae8ZZH}_I{Nr%Bot0BZ1)NVT_8DVVwp zkON3Z7B{C$k|9Al-z_W8K>>@g#6f?V$PuJMAO~XU1VkYnZ@8at!d&wH5+|gwEGoHg zGyIXHgn0Pg3KXKnl(^-u*crj$!qJH5mDJi3GDjQ>W;hAg7M{4}>MYaaAKTgOC<1lL znKUsYfiSyEYAj+h2POit+xEEEW@ICL2faBPPPS5eew`o&G5^TOv^P*}jN@#h#Z*AL zjC{2sEJY_W(QhEk=IU`S)RuegY}x&`RpyU9PjF5}86JGVXWV7pIuGM>?VoYT%Ut!4 z+Ndp$U!#Mr`>(R2=nvg6@FiO;2E``9;lXZf6rw&dhu0l6>I9uXR*{w~%|l<}6Kj!< z+x?_C^rnx5bL-7Fk+XYd5TErh3y|U|gIM!u3END0t4EVNEZ|%>UimtHc0~vx);ZL~ zAZO=6Dz5^j<>w%)#5;2>r$pxMBXxo6uUtC78HV3g$jETYOB^It*I%O;> zqFK?qby^h%1S-p0v|Sjw-D9vd)!RA8p-V_cn21N_h6hTwtz`@dG%ioYkPVR55*}9T z0H5xzycY)eXLSFZ#Wo?Sl{fLQZ-NVGpbxAp~Q2m+kKSve-xFnp~y?nlKAIFAJ#EL83lX9g^j{SEh@UN(&{Z^9x%=p0kuH4K@E#1i;olBGQN5XP3ekd?azY z%d9bZaQo~dI^rTL=xiKS#g}WuhPPTrG3ksp<;x%rACDtNwUdnu_2%&?Syhpe{q|wo zFrwF5b>A|f*lPiJx(4>#6gs$i@oShFMYq*8D7cSPN@|blbKuZAZ60)YM|l)MOpe9; zG_ny3QC2PR@}bF7GJ1#?EM9@dw8(kTE^l9Rx7qlzzgq% zPYsbCw8(CYrX`)=+yasBHi(cuKZ~O7X{=-?vRB$cCCIU1R^Zjy1uS)>uq0~{^Yo`4 z@>h)`78Vip8IoR#zF~?m;64*K`@I@g)rU76jP#48KBq42Do6b%po&aW6^VCSTLVQl zaqEFE#l=jsm`i@N7rqu|wPQft*`{RB9yi6c#H_&MpX|o6)JXyOeYQ(abYB%(EUTA7`H>sm+_8N@j)c7jXsAaPAq+-L7 zjDeuui8h38wNz>)NvlX~Yk6r2Y;IE}NFF19_vU7zR1(w`NeMw{+a&eAeD^)`2Xtr0 zR$uz~gSZVI1vFTK%oylWegCbv^%!aPC6>;s*t2Y97A@4j?=Pz$(%8}F(Trg&UInrf zlFSFwz&cYF^`*LdSlT{qKewZXQRXDq|7&2 z2AjQHQ|kgz~ql*!+VQ`JBq>Is@vMnfTn0?-{!h_^Q?g!+TlFyA!srK zaUN7!(eXhcyt=$^VM6PRgDGkfD-EnNTdC4xqR82g2U=5jm58kK|kvIFP$YBbT z5R(v04Fmlp%jRkqVoN|%x`1pOGj3VSi_i-S=%7sf$AZqkR$BhgVm%eqqo49kpqU`( zqM1+vmb9g<&GL-HEG|>0=I8S;?k$66lbZR^0u|wbr9jVC%%{@d|0;5Nv$-3?b_!1`%W$Qgs^9LGSss%vF5X}G&>YUx(-ObtA$S_bh z%j@mkJe$1y8`M!w?J^Y#F0VHj54A7R#b4;O6D?Ob**E^@+RlkgN5HB-*Jm)MTA#U{ z@IJy8qNzc$G$JZNl?AbNc#gKn9crG84`tC$7>UA(Md6JaSpx!|FOUdVeXb$>I^)g zE6=k`zv^lySd`6+UW+l1=b|kM0J@NQmjD+Hx??bfT)FE}6qRMJQ*I7gpj!Q$KVk$= zUuqM@+z~j%Cm;GiAxXASuxR)Kb0y$S;Gbcb*T5w8;J!93jjjbt^pF;7&t{QAedYrj zq!?6oV?tOS>snced|%cras+fqCe)EAX8hEdBC&T^FK$b|4LaJJ0_{)TY)stsH`?Jl zVCU1x{|oDxBm0 zO&Z^TWO}XeT|0Ij?0xIYWH?PmI+NL!3CUDso0ajY!<-hEPMs4Fj9N;82Y4QjyMm0B zVvPis%Z^qnW4UJ6<69f$;=tg`3HMy_G#8Hz#Pbs7$7S8YE|%uwt$(Ch{J!a-e+NW1 zpk-N8>l^&=9ts}_X9t|5@N);_hpVFJ?Z z0|q@lBa1$$&3A6*(jJp{c>|iQmKs8s#3m6Tw$nTB{LGX^a{hc2{ukuXoiv(o?bg|v z*yo#^Hiu5x%(W56wKZU+ygF_mmnSU7%Z1BTPp3buKRBHsKAS3UGMn5GntIjsVm=7c zSR&M1B*UPy-u4Rdx6}Zplsyd(xTa;Yc@=fEVJksonaRm)sTO1phk zQ-fwe5-;m%Pjx4AW$WOkTM!9Z-T-IJ=I_U&>{ z;@M*91&15V$RtAKdZep27-;<8AF=I&f4s!UpZ0|wK{=)G+|hN?&~9*>HUSKq zx&lV)&K5qa)aPCM-8k78NCF$All(!AC89uZ=0>`Bmy+v!xg?7)&Ew=f0#y4H%C%~3 zW@X73a9zpgCAHLbLa=6FiONU}--c;=i$5 z;DAO?WB{e$g(w4965<8q($?#^-&G54lbKK!5tLMC{Q|GHmdVdPsJT;{bQ@)cw6^AL zb2lql9*Gm5_3nF%oWmrP-yO-HVC~3CB^>P_UR8Gv=rWgNZ0(hojG5_QQdh`|DmK#6 za29fW+!tZ$@7@6UZ9BK*dfsHjOAgLN7bY1SO4YO~PyV}YUj3Iw;D1f%`VX%v@`0jA ze8J2vK&ah-+17a5Xa@jQ6bR1JEVxD@6n|?5>_(A9at{LF(vM=mJ!mCSQ{bN~{H5zf z3AGWQyB1bXPTle8ltCRYm*lyAJ1whX{?YS^BF_{-pObHfUXoHUd6AN<8XjVVg-vDZ zS~TIgvtC*Br5fn#U@@^8k`Q=?1sl_oVvD>&g+WX@9Xt$`YI`#4RgP!Rtndb4SS;&l zKG(;(tbF8u5z;;qO0zl)kryF+odnMGodB5D?}G;rwiF<3U{{rqk6c%uWf(4X`g5Xz z@rvoBK3>2VEY{h~U*ev=5ux0nguUad>%^D*knp)(S+>%r{%ww4yuY1gRuonLh>FZT zU_KZo45r2sK`SwbZ&YAoIr3n?Ja+P}U6eo!R~y^bWit&Z6tNVXJ4PA2ZD9FZNOFRU z${&VFc0QDXX)CV#av>oe^Cm=V|GzZX?)&kX5g%~`pnk{&V0|mtz|~3Ge=ax8|D26SU3Rb=ih!M4M-jUftTb&tDpGt zs=quMxX<7ahbS`AR-GJ+xAGHitUZaQi#+k{@m}IMg=y;dB1R)cXfFi;uN64TIdkvm>H_mW%`;C55x;h|HWEcL> zyOTqVo^B;yYWS^xKISR^vuwyz8o zlKweVjv0(i)bwxCIC1N&_g{$_xUoe3dqK$(*gDXV#xy=Kps%(_W+#sQn3UA*Ob%6s z>PsxAT8+cWx%hLIAFc=pv5&$2MD2a%A=>*zaPOY zg+o%iBIv$kJ$aa#4!)7`d-71_jVp^Xg$j8?SskwQ^sX-$WEHd0D7P-*7i*wDW~gTO zf-+yFLL+ltcgT6n^#{f@GJWYc;J3P773iEnI%aXQKctasRX#(w$PvVOy3reCf6d2Z z-iXbJW+b=J)HWEXcwb|1T+F#(%52T)m7VpH-E?K;sM(7>UDoc~KXyD;9B8y=OiRU` zR`W2E`e0Cs3RP4Ccq&9)61GHRq};1c zD8V&DM=eg=%977G6hI$Aa6>%aj#}YJ8XKj7R^Tb{4Tw+M8 zBWF`#B_$=>Nxa6mul)}Hr1ycEmO5K+y0{k1B-+D{@zJ*VYI_PxYZl0Rdg^>n=%Gqs zldh78s8N`yMu6=voDb0}I$=KHSN5F9-Cm)ra$uWQDrhY9*&!R6Q|1h-vY1~G?G~Z? zcE2mc4Mg;z=hW`aHX})~>xycmWA#H5%t%qio zx>yx_!*ykSIoKg8l_g{(f_a#$X;lOeLJ5Fb*|E|I2#tLmTa0#^9Bnn3mYg;^WR&!T}ok=VU?}*tQ zqi#kh;z_T)#kipzf3swhABz0&H!2Ld)z|0kx3C`6^Re)RDdZSe^SQ5t6%RO!xs|qv z*OCv%W5Q%M2N+VYu4xb`+YvLg-CbN-b>;8d`2Cs1t>mX5iyk94X2ljqZI zS~XKtJh;YZ^R8I_9P(V-UQwBptEpot+ZU~RZ^3U|#q}W0@x(T6cn8OZ-u^F|9aLGw zYNv%&MmH1O(3e-aVNh9lKLq+sKo27T+HKVd0W|XeLU4zuVbSGl30E!`o?0$6NZgI= zkDk)#InEX}+``Osg6#qrz0wbLUw?9-L5a* zCRLcSN8vSu{zG=+kb+H~he@ryEemv4#lG7)8B+giD~bQOq*2#z68kf`suer8pP9Jx zeA}3G7+SsE-|V|K z(9Y$b(yVs7kL!8m8-6=d41gdHu8unPU!05_4z%aqv1ftvu>McWNqn-y9`1X3URv{= zLcFf45;q1yze(z;556!d$|rD%e&<3s zzNr8ho2dC;XYPL0%;{pU=upJmEJTNqRIpd4(dfkUEy85H@3TUx=i!AQt z4b#uh6Dtn#FWh>#$f#=QI%h;9NYB)^#fPeIm-}{_7!9m=tH>(ysS@|j@yE>RZo{gX zQq*r;ze7#xl!o}-hO392SBM9ZhOie^H7H9J#EVKU7x1DBJCJxu}&L zQWQ_F^G@b)7X1(7hePkWHX^XMSQen)n&o$}_tb3+c+q~&@O8J!4L9-yZfiY8EOX5; z1Ir@}ve|rP{nlkxZ}?w76bIb%F6BDKiPE{;x#^&UP0>?Fv?=VEMAg3Iv){WebMk%g zA%l*pq0Krx%Vl0m%OX$z99?hx1nxYjC;%3JzMw65?YV=fjr$m*iN~KP7r>s!JRrlI zQB4ehdDW{6{h4PcBvVtlcAC}w^Pk6I8+P3~+pIy!ANz;**QX>mN^+M-8BzwPvpgRi zdtAi(H~Brf4iv;wrj1&>jr_)Fr1o-P)jU z#%N~tIJz`APHyKSP^C9Ct&%(Q;5)GuYx8A8Z61pbCLSNai=86H&K1Fh=km%|no3jD zGA&PE8muuoA;7QdwT(A$>o~#5 zGKf!DFNCUIv$*5+fLXS(()x%t_U{oF$g>?gWTaddih5wGs+E(1c_p8pweh`8aOgeR z=2pGadeE{%qx;gegFAq7N@7fZf!ktSr>*?;C&jZhOKmiP_(ucO-0jGYe{Gl;9cJNslGlBth`YscZkn+`5v7&OY zQi6PC9MKzNxzLZ~O^v*w_nP8b8yjC+IRQsr-G#pFx9eh4fwzJss|wmA^}G@~U#^gb zAB`F^B>MjJxQO%b+d^heY&>@`S_z{kFDoV?!Lzp6$S^gK+`d(AP%J`-ct+U<8m`LI zo!n<4wV(^BzEDeHN`lqm`apm2w*@o|EsV0=LI%iYk$8!S`N~ zx6WN`r-?i7`5LpA2DcZB$%G4U?fW{ixjvZeAVs zMEzEM({AU!|F|eynf=I(^if!`lDZRQkh14VWvpt#&cGC%QF}%XgtV&eN?61^A?8d` z3}{ypD|QO=`a2%mlr6lii<^X?vXlcBsi_)~0xQLpdkgtVa?fJkW~Cgxt;qlC0To9N zU&@Q8Ilr(3TR?BW`ryWa@Ek<;lz75!w`7!xII%?cXNQ2P)I>uECaQ|ikleHVt|1@H zeXQjKAg3kYt|b|Cie+k@78HW((6u~;_+_vM4d_W+r=285P`rS24M?{VVHS!fw`#hl zK7NkjOMPg9OU~JYg&0Gg3O(@TE6;Ypi@TMutR-9I|8&ICK)>)X5~_r@-Nw*Y*n<06 z*!f(RUD`y1X%he}f}zJ5H4hO0ZKNZGTRa;z zH%`$Mt48_R^iCP&t^tcM*!Va@V!_-r(c|sOi69&I6pM7ya~t2C)-@!cbnR8yRF9YW zDWcz=+nA`6QNdi#YbQ#2Hr;&3inHiF@z_0@+YR%kD^?4^F9k(rNuMSl#UJuGW1&rY z?ROC$;w)T#zuBzY9?Tmmp!SQEI@9SPllFWwgg5EE`(sG~o*GFB$=`5U`U6^?o4PG> zxdZ`1vUFr79?lsgWPw%)PghAu>;hx578;rdBPfWJMaP+)Zz6$&nTmevZ~gctHMUjA zf7a3xs;*jgMg=K;B#{a-A5EIwSbWE|mOwEXN;CD^RqdYL>#dLU1KAdJuC?)XO))E& z7fC8H^~4EdYs>xH*1H&ROG@}?^5Hl{XVeGJZMeSzhAZvP5n*1>hN{{GgP1eCKFy3~ zFuzz)g<_WB(x5AvY(K!9xTE=?8xdn9%20p(?trAul~#w;vbNTD&V-F#Jf6ArUMgak zGCJbI*iL>BUUced^X>{3*F{|4( z{QenbJ$wIg2(RY$-92~tQEG)P>JW``$Rf9@aS3dw^)tqa5A2*11mlKr$rEUtyx2T^ z#ttRZQj?*RaJGrFd&lC|?W|S5+6&^e>S!v4PJEna#Z?6yTaZeLF2pYW1HaJ{FN0II zR$ zp*&{e7aKJAB;Su>7(&=IU9mF1bf8a7=f1SaqjUMS?OuX4R~J#MvN*-4#AR~l!L82n zt;|3RAcqBHQ%%8*&)T!7jC{=KZ-zA=%X+0f!|1Uk#xJZD`OnU&2vl9cck{7KYTy!} zN3{F@t{4Ck8^5q8nt^W<0(fcdVxYVTd8+IOSUfb18n@V2QjiInIEwwg7o^B# z2g_?CB&mv0 zs+e>nTuW_Xk7*ET*lsKd!iWP zAe2So&XbmVvM;j2Mh!^L2zY5EIqx|p~9Eq)QJr4#mxa#kI(#VecJ_? z))Flvqm0JQv0Z0cBgqGAjyLp*~l$G6AvPJ5sIBM*O!(8gG{6>98b?!A~|O z_i}Tu|3ME1@25`duPCH-r27O-EiB-OZ?K%@(`sNaWRh0+(GWwOy+r{b1dWBu^ex)$ zpz9s^8)A70`=pGi!P8cX3j&kXUA|2zoj*lRX9v?B(H8!@mXHUz-EN-RYpCUw+B@xb zQfj_%<|)dYFcDojZtA&(W7&H@uTT%FbNUI<`c5uDDGl2xZYLPmlJMCtfJw=-OV zX|jd7QY>TTq0NHVd8RHFeVFZ-oV~bo!8na7B*{#Jy_Ssz@X8I;i|?MQ$R7qnkPL1$ zL%1rcRnTv)BU-gRU0UJ#=8U*n1qI z2v1T(z~eRbGQRNszK1Cr@vTQhiXl3c6>SK7LfrdLit#^!X?; zStaX*x`wVi5}r#9xLoh_C|n{6?Z zP~nNND_SGVsnWykS|}F{&&j&xt@F~OW$QBc)Z5-)Z9GBHig%~D!!A>rnb}R8R%eFk z9alw~R0jEqYF$-#gtBxw-{6s4hx!}KOkDAQneoIOGAXAEv`v?X;&YX;CneYwT$d-g zJM^|`MfayityXkXNl}R8756j8g#|zF!jptfC!9T^&H0bB04R84$(HGO-hcyAqR~d~ z4oj1UN^lxLLV)HM;2b;1Y)NUY=JWhAPio4>7asMO3QCNOH-S0sTl}hAq2aMSVcc8+ zw@L*~Jyw_ruflKcQOjFPsjiyQ3trKc_m$~#<3hKFCZ*VKwVR-dpq%iJ{#bvfwtDyJ zb|#2&8L_W~-v~LLa)pCDr3eSo;Zlp?&@Vc#S2e?Ou*>;1zg2=v*v#tndotV((60hk zCLS0;kaC92fh+jTaZ{P_WQ*KO)<$}WjA0dbD%G;G*jU0F#smgJf zDLm#~yn|*@^(y8B+HBt6#8(B2U(9mOoMj8@bpUrYV^d#Nd#Y@OsFj&%8Wg0f)S{g` zx7mL=`bSPc;M+q5@dv-3;Pe$LY0dN4RSgu^2mpL-Ab8#DISC-RZRMf8Nbei2+?wKC z?`h6xlXITAPita!5G!NPE|c%3SW0smI-^cpw6!*ubbHi1g4>?Rq{&!SQ@O~+S^PBE zqQ+!nF$)b5*=9$tkRq!uUW+d41ANmJ%J1pg-XxKU*Isn2<_$aAb6jPk=IE*OAX@J_ zMkQ{msk&F_V}tM6D3UAD$$N;8CxHxd=WV|=o`Yu!HAI}-yBR@=u)0|%y|ev)aQBvR zQJ`J;uxp_rprn$E#7L`vG$=^J&@G^Zl$3OfhzJNsD-0lA0@A|3Pyzx=GjumY$IvkE zJ-WNblN3h$_LIvUVizV%j~n6m#-IRFCw_ieSSXxwdoem0BvhH9?ojf%5Be(1J1Pc8 zP|i+9waEk!dIHU)Ax-m&mMqZHQb6gcRsLjm3+qdP+ zbzWQ8;nC!4>3%OveyZH;nd;=%m<@Qni5OkFV1hNiq#K^|q)ScL|KpeEOq<+xxh- zNh<&#L7!ZbuO&?IAEkJx6b}q&k@3UmK+|>n)fpNZX7B_z?lSLlJ7?|GNr^waz%!~a zl4)42qLTc|e9LfEqwr1mZ+N8K1k{4#=ija#Jy5IiYkz5sW!YmZ&X1<^#&rK$&ryiG zpoEAV$VB!s0FKF1^?xXgsq+xOs_PsxY{a>s#Yu9l_VGQej(``K)<_3;hO?W?x45>l zT)z*&E7130j!3%UOVOv7j-%UT@;iZLm!2zIGfDERtT9C@tA}Pp&^mH>dJ>ckI}K|FyWndC>8syC;t_=xhFMkq|H$@38!MW$y!l$*3Fy@NqLe03qII zaPk%=$p}jV_0<|Yp*4m<~i8hMui$BOQL65QTg9N6uO&Wk{CVj`fp;va!fn?_g zcI-^gBElbBu4cdzWr8J0Y2iV1$-Npg^mlolE917k-&KkiypLu4Ww)iJs7cB^O})D< zTh2R`R6{m{zk}r1>E_^iw5*1?70xMr%U+d^8ZHVd2a8Z^6sq(vR8Oc$=BQBpQ+wik z*cTxR2acUJpEA7zDH*5>+Ru$kIP?jvQc(ESvanrWXb@X2B6|Wmq%LX1x!oKSMXU2Z zm<5rlHirfUux3VZIG$|!Kx${705DMEeCd1GqrZYw&k^8 zf=B8{$;>`g?E zplIn(o3P32g0h)0`^|6_=W2)1K+V}Nci!~8n`UG$-)kFJcI|cdEqa(9qN;vM{%_Rm zhor*@BaD(vms2+-hH_LJ0#kjm9BW-Rt|bzqtqFi#B8qg<_>_TSyYwivTRc2Y)1N~D zRLv(4c8k*7#M9F=ZAU=Cb$P}E$~_wd>U>nFa!93FEtL~*moXJ*1`lhHr!=akI}$UA zCF?44WImGF%+R8G#=N^m5i6ra1DBlfki3d~*|-fvXDcyLCw(g5yaaQ>XR_`JKyd8G2M3_XCTe-s-qm_iR^)f5yIFg>{X znh`AQZb!$U5Q+`6;U?nRX%`>8tqcRHw**YZT;@Quo{O>GC`Z71X=_eC*E@u=uL>N|qx55>al?;YDY4>J>Nex^l@G>=SzK9@K zGOZpQIYo-(2-EqLf~6dksuMvszJPISMM1el&^(tu-J88%v524Tlzn$%Q-3q2PfkHW z-)*_L-KA}&z85Q=E`v?JOcPrcG??xd{SD5{f~llHPgVKMyWH6`1}ynS6VFwY`W-Gp zEiSWs4c2%kxIBh*#h;~H+Q-=Jm*!a?Ifwtn0r=Me6Suq0`f^lmG%v(wms+wQ^j7VC zb3_(t95+zQ1nzsfJ0kW#l%z>0T?F!+_gadzRez7VU1B+sMRW~A3ZFSo2+bDyq7rx~ z=*gD&v{PKP#naEH^9&#RUoocm3!N4J9_RwSs347n@t`hJ56zq&h=PH%jzwDK2Q=B( z8_a!`fUT4s(Eg#U|K6*sK$+I}je$OBNPYLx!!Z@mJ^V`-Dr-v!O!!ce=3uOG*PwFc zPYq-s`_tb80DRN>;hfMa%5td9t)WbO@A`UJbcH6I!%E-4W;c8Duuc_QqLgJ?oKbcW zl;r>Y6Vp6it7{^jt&l+X_LrSXwF?j{guvOpuZUFjjUTnHeXPwj^+&)J1fkF)z&(T1 zfF@etH3gc)N3j8R!1k9{z4ttPcsE{wm?`1%R4HaRAC6dau5um~5Yg$OVQBN3>b%mM z^w(wmK-l;O-;cUV@iw*W&@d5-5c#hj)Vqmng@!b~A^mR*gzN8H>Abb%O8h7zX|q*asbD6DDvxZ-|+TcME_iO0J6__7VEdJG!0g%3pEBUqeO? zZ)^(sj@oo}MNlA@v+9XSwDl^={EB}4lXmhAHd?$rVI*=83_tE$NX4k72adY83kW;& z?rSRlB}qR}IlhBv0SDm892jzqM9|4bI`Z#m1S8NM2`|$G{@YK|!@~64FcU1Jo;y_) ziRhiBBZWM~DhQ|MxL3;;F*|;;hi6=if67|DsJelutLiZ(6uV|Df{s}xTRlqf zI)3Gsa7=^QLtu>e!^bePJI8DB$yh9~>exxdb}lY|>ehcbN-)16TlNd)3MBj&NEm45 z{d2O)HyHp!4}QV=`F8yDuwU?VzTfHpIXa7(!+!xL|KD{qI&5F7Sdic97QR3Je-in= zwaEHcxx;_@Sd;)jareluU8(ge40piTnnkBtr8p>yJ(s>R1tQ{85=Gl zPi#BS-ThTvLKkSWH%SHeLY+#mWn8EUAA6FAolqsiF_XWXoG|9lUKh~kh3ZTgJz5l3 z`K~+|kTJe%qKkD1P4qFn*Aliqg^xKl@{C|+RGnMa^M;S+rwBxjc}61y*HZIH@CZ-m zcm0A^$Ozl^+CoH_%dGD!2$2iz#M@y<GBo|fR)JFj;;aXlqeA9FR}X$Pw@{wB z3=B0Z@z~lFpCSI@EbCsPYrxhRy$GS?Q;s0|r2LE96rQlJ!PTo+jQ1OH4drnKV*xA= z>lsOI3-?Df7M2`8?(Dp73+UX%B0M}A5gc}4?w-k4+u4|XCI`#{E6(T@2k?9OUzN`% zPQ0W02F$a1)GqK@ySA5vc#h_bJvn4yGPDOrMKX})M}whIdl|XvJ_km#ajE5swUSZ= z5i&IvV%gx`1@(a8DEI=~u9ODbAN%?2g@TG5hPERJmYit*fkIXj#lf82hq~-D*TnxaB0F(!qgybB* z04Bfzo^@z6=r8*7My1#`z0b%h`kNBrG#-Mk8G_*Etlie~BP5h7HrB+xNMMWzvDzo` zJ~^@xykHRUa(}d3>{St}@0~d>GHMTgU7YXk`?o)*2m^PTz5LN&Q{oV{JF6>iH<5zp z0T|2&dm_bzyC2mF@ith4}rw$(I>Ev=ELW$?qIXM=FLA4)jbdAv3uMA=h(Hg z3YvzJ>etLYVH?KI_1nrKeeoy^v`)ZwubtW|T{fc!oesKbQ*z8Qn71Y}(s1r$NF%&T zn-mmXPN4gC%x)hpMQ1QkJwd3A@aaPM|JZ-Xx*R`yw{F}l2Tl1?F~#D3#(86_(~7PJ znKqbV9+i`s!TYg0J-*shI+&P-|JgyPg$!J^2b zB~hy23*63m{DN6qpOia;Yp0rsq+C8G8;Ej|FxyvIReipZN_%!P;KA0YyL9p zu3|w5I{-0u1@nY!Y#L03d;%6meb5`OWL@I}shW{b7MW0`*ClSF1!)7;$m_8Cq5C=u zhZhx@L6XuijFeRVgFZk0=cOC~CU@ONTURFS_{ep-GhhNL8ZwBWUb`KAl?w%Z1Q-T-zp70( zg^AsV?;@&fd7YF6X{T-C8I7HaSkd8fRsm3dp?~sEP}t0@~|A;9sohe=1+VebB8iEDaX}>XXxzSEZR6 z9jFuR#gO&LsvOfYxCOHG+V*`{7AQ~wPrM@UyKYHNutKM%gvH}$w|*ymBI0t7H*_E_gFck?Am=j9+Dnv z4$@61QNW;H;2yj8zVw&6qfH2N5)$M%vT3um7PpEOYZ}i(>y6cB_(5l5DNrCxbv;*H z&ZNKdJQNqv1&7s^IbS?`TH5uR$sN+hcG}cWuc8<%7YQB)pH{AoCpW9U$$z^Y2VDirOj;Q>m03r`ZS>VN6N<~^g-Uo zDLY`Tjh)tj;f7`=1N}MdoAg8km69VCt`J~ZwO5mr+_1)RaYn=-!mnFufh+`8pBc^o zptF>)ZaOR18}p%hPgpQ_(=O8~@VclTh207M?K~vJ(aNgLA;2#v;CXnV%ATQ~xbuUY z0!i^F!M~CtKnBvqdP-n2t(Du_O{cZ-ChHlOWFSg2{*bC=`J@~@kKOgE0pO9iv|f`q z6c!Sx>0S+`!+cVbk>nGjt9P2@^9kdbGzS@N7siIB*qZiJnM`Ud8$6!O*Nr^{vs4E1 z`1w@XA}@lJn&5-Vtk9%9(9d-3lp53Gtdz*XbUuk>){H8)r}v)5HWO)_16{Ag&)u^H zP|7(sw%@sRqZ@#oq?vT$#~CUc;QZLLQWbr~$&P9X=83O{3f`{?nc@xP>`UG-6v}-U z=FSoMl9S&RG*^GgoN+Jv)V?zBRXQ+Dqmx}*jbkskO}7bvQ{)|BU zYNF*D$lgh2;iPXgW^QsrG0cl^bo_aEl9Xa< z$5S;u%FqPO4fdo*n+RfUc|&z>Dp7M6aI#Ei7|@7Mu3x7Q{?lc!53^Ao-b*Ja_tBvC zyxvYd6B?#`gnca}G>6kB0S(d2FCN({I}3`_-o5nmp4XrujPf6Xhta49cWM`+ru5f; zUjnkDoBoa(c+y^5lda+{vj3?_&F?&-R&Ig z`cEGMsKxr9ZhR3Spqx`f08Pe1zHse7)Wpq5@$zBEd17;X*Gg4CZF(O0fQ;q{+D9HV z&3^c&3|I4Sg?PF~{eI4%Rq`;L=SMJ=sUA3$OZ5Vd`XI_^KR^=*e;K25uwR<>S`c*O zY4}sOJ$1X!3?VJJIU*7C{G0+h0`@YA&?nnLq$bYnsqlbY; z{c>C^HW8WCN-Q3 zrWVQ?!C;n-a3k((c+7c(zuk#5F&0`Uf8)Zq`pItdqBP9t#Z@V}j}5kAkcX@ccTW1S z$vw~}w4Kj?rWjGw@J6#izB-5k=lxBIhLb}bD4YBnQdgem8`Dp6m7F0xJH4$&7@$oy zRWjpvAiA{EhsNwYvRG9?I+X9*t2udyELOS30W8if!7j@v3)Pq@^Q^SCA(;E-&3v~V zD4t9_nc^d=HlVvDR=WwlPkfhLLRUTTt|g-f?+JhGTL3k9?9 z^oz|S=VZmto;}OR$XLPiw5*$tralSR_r}wtEOxK9;>fDm+^5*`suM=%VAli8GY>sX zTmpZ$ks&X3uQ@{oiZ?$Mz!DQ_xf{v=^;W^!I*$!!P?w4;A_w)XpFOE9QK)0ryvVwa zh;80rduPYO1+;V=HH#_fh2yk1zFn7$w0G`R;nMy{*NiWq)Ngte?%tx#4X3uEN{n(S z;J-X3C~uN7FonN&Dv{JuIoY(ov-7RUqhqAu9*Mp zST#>U0+sLSAWgG-AKKU`wn(!Y1(AkpK1kLr%G1m;s);-=QbFt~-%M&Rgv^kgJ2K~b zG;fjOwW4273*lPr{oB1IiB8iAvZ z*4i7fvQ(~aZsCpBoxosmdQI{xS3bzY9hW!K%)ptK%Ac5(nR6!&WGAjY5s+1W$k(S{ ztT7zcBltAD$(eu``O@zV(;MW7J8v` zQrO!SVjM1q>_bC$s!!@uHAsE7qoX5) zu#g6@b!|Q}9Anj;rI!6Toc%qIICxp+I=}tl-?n$XAn^vA|i^Xi_6FZV8lKe z@#LD-lasUR;CzQj1y)@qi+ykugjc=SGVR^D&%v@t^|!6E&+c`Ah3CqzR&2k_A>?h9 zUYIP>T_$m2aL0~5`dw`No|3BU%&I_(&P#8VYtp7YPinR*W$qFd_4Cq_l2cM%yc~Fy zii(Pyyi2?zxUySB-YAy!x31Je{Z~nb9$?wmlpcsknZC>MwfZHb2B0L;lI)%H49@5{;W6!Ioil4K1Skkb;~M)x<2i@M^A22h){-5?ez>i zs=aB-Cz4XzFwIY&&1l6+c`wW{?p<6axxw6i)I@?I0vPx(55 z0%@xXS08mk4f?H!2%>L#(4I`s8tBdw2&^`Xw?Limv)T@WU%=L~op?=alXN{Rbz>)P zhV9vyjZ8+}8O}3MLIc{s=-Lr%Z?{f!_mEJo@S4+(8n5v(m}ETqVE&sqwQ|>$oTYq& znoNCtci-X~)OMHez9>HpLd#^z)SbKENG1(D_K1xH{@xOSW%=q|WsaccAG=nJZYq zS{y!e1bzx~ydc)8V01O`(*=dr73%Ka5qkHcN9`BKsJ00C7*1Qn}&inN^R&b{$lbI$+ z&!ycE?pmg7npXn$YDjjqSozBF+!y~;?Yb1azM4{AQ+LFDbl`cCV;|-giw`r?(;>se zk%gBmY;0}>7hEt)GNQ~eU;B_e!_!2iVg4%Q!;J{$$8x!1o?7%)Jt_QG{7neRK2e{e zlB+9+NE?%3iloFC^*gP!6U~Vkaf~Kpiu|}cxB;-g9G>DwIBv9|t z6(ta?Gi8B8Fi3D$YlFCpj?GkUnn)JC~@u#~DQ{UE|Q27?{W0S@s6 zYhbz#shkYnD$di9%XoQgZUx;Xhg9)ge~6Q|?oeY1(?-~d#-z&M*0y98N#X5OGNJe+ zVcPNLzF%!i7?*ZM%GKp_mX1ei$wHU*E!b3Wc#hmOf@tU#78f_Kn`uu~n}InM-}a5& zA+J5S+Y5EnxUfm1&xn^CR!Rxr$&k%S8wd=(i5}T~88xLTd&Hf042BD}S30ges2CKo zH!d%EM8z9duwUb!9xt@E#<{*M)3@yU81+ozl=)$b!mY=pk-7=n1<}K5|Fk7}v8Nz$ z2=b}vhNWDO_W0Wa>N&IUklCZOY*1`mr&#qzc%;nkHo&9ALF7@SJ7GT?zOcKmM3p$V0Bl? zN6cFHoSsL&l@kB5(7}cAE3*eDPGGjA@7-0kOOD$SoLJ&l&Zt)yiX zIoy?UbLvvI+x#_qORe#qJC)T<1*tn$Z(T3clZ;K+Z@7>WD6y;oK*9{t5+S!H+B7re(|UVMIPVda82VtvGTA zGFoix-HlfaW_&l_M&iPj(qkX<v+A?Jy!Cm{hz z+RR>KTGZYuBuf_aTYY_Gaiiq=W;JQ@v4ZMZhQMsW7cuIjPqh}o!x*w^p=w;#h^u9j z=R6A~RcXD#tHo|ysu1TsdMb)DuG6cUzkdYUK&3enXp|J`!#7wed14q1?MbPJD%AVyCZ}T0Y_waLBUJLp{1248{u4sM+4uG ziM*XDR)8z6M5PBD7QvJ0d?~V}U@GV6sGhE-wf64T@P~7)@3jganVNns{Y~=&c8M+} z3%!zk_*9jcwI09Y8lbaK=FbyUVs6@mfpw0jMD7g8%X*{zK{s6(OWLG25GvCP)>+Hh zq{U>TbVxk=6qhB4k%ZfhJ)!v~P8yk*_AD($1u#1M;c zs%|!(vG=-Rw$}qte_-wGW!~TJkfE>&`0WVHzN`5Fs8*X5q+fg4@JFInn5b=jLePK$!!hgQ+n2biFN zQwXP)9!?uzZLG`PL_N0pu4Qy24#{XFFCTI{o%!lpsaTE|J!*xsn(Tw+dD*t-Ss$zf zRz2CtyPeAc+C+NojO!29TozDLor?xhOGx$k6Xl9n6OI9fuXyXTOpCNkkK8yt@a$@n z=qTo19iQ@bV%5UY&+N4C9qWUK=;p7yS3e1fR1X0Q8-&EWZi6?epmp>>_?=^g1t#2_ z*g?Itn4+XJb_a!~vJ^ZQKZEaeZAq6@IOx!= z+C3ggBsCr{vK|xG-S_sE4clfm2T6q(S+8)%fSBwbo=K;#=#@K4YSAKdgU#P!n@w`w z84?p&Uv7A{S^dTg9UYyap`l|~czAena=zt1DwLb!iMd9a#rVH8THsWNbux; zJeo(B&q6gUhk5zr6~@k;DcjJH12H*a?IbAk&u+^L!)QB!=s9&yX!}4 z)h%B6PD?jl#hi^~EH|HO_>jy@S<hhv=8Gjca0JPvv?){CRnr`|~|n|Cr&NxNS$SCxhF$>a6dT!&lTe!1VD>6qt2~jOJ)_5GyE}Klp8wEr&{wFGiH$Igo)YWq3)JPFH+{1FpYR!Jym# zyL5rEOV}sxaMuPu^YqtC8BsQdDjC!4Ne&(!sN2HA)Y?l|=&!b(Ox(49L}^~YDBNaq zftf0H-;Z9-_^vkZBY{k32|VQQWGSRFe<~D^WeV8+TZujrKA8?)V)ol!ubHQ$TYcKp zE|YJqY1|L#1PFAi<{ny74FIafNeEJnf(Huqa=ITjlfg>vUl&$ekimGGz6tdzRoddW z*7N6sB1azd?4IbM^^e|&sx2tQ&35d!wK7UgW_}#Pa#f}UJhzA3>@87YaSvHn6aS`3fr9A947=w&D#&OuZ*fW&O;g!lEmB?Zn^G`CgL~)J@D4XO zTb_Hym~NQPJNG7`y6M)N&?NnEX2BC6&=GRmHqE9gA)Ul`2}G8I&S^s>=GQEXuglh| z3oM=WyIjge-K@>^fI4x2)#Z)RvSZqIkh|fbRd*80pW+8vlU(*{)%^|I<>$obKP1Pu z4xPMO5JC!G3JX;#Yy`rGDN)4_GP@vE4)=7%HWoVhF2deV_A|K;4SoLnQa$!irm~|| z9nE8JdVi1Svu{BPWSV_(e}Abl=pOE%xt$s9Qc|;yy`v*;=&O(ri)?7CL1IUG&BI2& z&Oa3Sp%$I!;X)II!y~ubszMWT%gupM&f^Us^Sggp*b^r*UVd}mW*2y1s$f>qyV=4q z8`rf7h-Hm(YTgJZiQ!={iBr4FxKVL#o^?TkRcrqB>zL!x6xP#Sh?2qI%b4CXhEqq% zrz8igQYr_Q`yy*eTdXe>CVb$Zdf1O>y_ni{8K1zqq+hxyx>!eHIoJQm`kV52)FZeB z%*G|tSLaW?0f-paj$_~_zdHACL#h{EVeCpr`nUWC~&O#56?eiA0a+ zU%KR9mua-#RZ1Xy{F$hIesy!~C})kqZ5C^JfEB~{4i^MQk|tP0O=+B1eKC~^Xmc|y z*~4OMV~~q1p8VY0TuYzt)2Ywqr{nv6X)gHDMOaVL)GHm)C{pdE51X9DE@B<2Ggtj& zn(@2XU$Q|=ZW`A6lNH&b`_~oPTyeaZ_2|WgxSYpE2SF_8 z(#w-ts)GzgrfW9A%xrzs;aerl<~7({G}f#8hs>?=z%DG3ja9iBjoDI3eujlHgG7Y8 zvAeswe$W|OU>|^Cyt4C(Gcu*nlyBvIL8w@}W*28q`JlC=Szdnr&1Km&+xLgrm|7`LQsd>`740B72`Q%c=*cj4D8x^U ztrtw1krq#K^ZlKcT&I zuu0HSZ09!8OLHS#WXEsy7*n}ktFO10h&h~f%GTQ&6xqwe9I-zNR<^f=Zn{P8%xWko@>_TwFVLv;TAioPK5#zyAr6 z#f3bg`6CN(m)yj99{?lD{2q?wla{Oi^r?hg zfH_vFhjZmpn=J0b3upz;SefjHm#9k6eFdZyl0oECbe&Tx6sQl!j`d6C)0@2lPSVg; zc3~a1)vCr2wQwW70oEwd3@%YyV7UIw*`6fkC$M z_^XC%L58+Qyc@nJ#Zqh!lEE~iKW1+RiMKun=y|hbL`1@D16%Bch zY!<@&#DaS7E*T-Ia}&{>`m0KT?iDjEv@j%4g~@GSDQK}$hq|}8e4?!}d^<&gK&X|$QnA?Ne(bl5!8cj#6Y>uCu%Q{t zPc(LTedC>@!v1s}uf3V)Khx28P{#d}V$$Pj$hv9BPNUidQnD#ND}Ld81LkNGrJ;BoaDP%eJ{tda1D zYiT(EFGeUE!awbtX9)XPs~*m@<(zr*6E*)5y~CwNq6Q_C9L9mLcz^|`i_pQ3d#l#V zhL+F;7vNgV1m%<4)BJBLl(ISXCLWzke}pf+vG9rA(3$r_h#R+DBW}3!}q@~Y84o;y7mPutuvUc7g@UmOx7q42j z)@4;F(alTk9~>;dVSq_JbiK?o_z*%xKhXIsToi3U%Ln*lCFYl?`eOz?1P!9I*US1^ ztU>LYf~VF!BHwirLEB{H)w~b7YWkVUZ^goD7wluq2_)5=r`LJW)VKTzir=z4s6!>1 zt^Lj@C>gMYMqB1FRn#%LPf(M-1v=dEIId^|q0%R8kD15}S-`!_tJaF$-)ZRPeHDd| zj+LBaKFo~P_KKn=OR6<*?%|85l*h%iWE2=DW-YYrN=LdyT>X~aIB5jQnoue zSHx7sN*MB%vZ{#!*H4C=g60(yrDRz5`#$;Qi41UY)af65z=l5PjPi1Er9eW+(GN(1 z-vTVI!1Ks;sK{wm&ze8fvi=&@#|IzFzaLf=tIczI?}W& zhTFmwdiWb{P}*ItCj~GI!MNKq(c+Ugaobs}St* ?uTrHik}f;ldf5SV^c|1fdUc zh-l0ombxCGn2efITC(2uce?!F#4lP?SLosv@6 zrhqo_`UZKApr%MN^6d%RAt%a2~!%R^C}F2 zleKVP9>04)dtEkO)D`ps$%@Ts22_Neq$-3k)m_VSw37ZRIsamAj{3>;mQn?wQ*2_& zT44H%b2S!;Y3PvD;WnG^uuSc?7N``>c=;7*WKaOatLM_5;-zomD|&EMlQ*>X zDXm%2-ASK|V=u_|Uj+x7tNAo)+zATmF5o3TZ}`HW9OgD*@2%^iYpI`?A09x#{W0w& zNAMZub!3P66boyUID5}Dt(n@S$;%hTQ-D8H8HSr}sBZYt-nX4=k%-(9wrj*-CdZCo z|A^n9fzqtB8y1EjQK)ElV1OW1fYZHMgP`$FPIZg}_+ZK1X4cvzT{lKe0 zIMmrt0pzZTvQZnA=YsC*OK@8O;Mo*%C6T4On0v8$0pOWXLG+ThUxL52M!8j=p$Zun zx#ASWBkUnOXKBAE`rE6U<+b5AnUNLVABcXu*Q+{6j1udsc&-z7-8?_)PZ7(%mk3xh z>1kHLKhiE~KdO5Qd?j<$z(J%W>v3i@MEd2!TJ~)fxe~SIps7m&SpeJ`(!h1>fB2kH z#c%hD{WHgyrr=(}*#ef=W8@_L^_}Y(g+XSGr0g0~b_(nt=M7$XSg!3pD2h3)>R4@F zB#e5zLt!@H#zn?EKqck)n7mtu6Ud-Lhx7o`kg<{>FGsROK7NUGi!D!(nF1TU!k|yR zP8&zbq}Vh(ua7=RyJR!$aFVzydG;%W3^+&It7FzW`Je3pL}6)*nMiL3#FvpI`$4yD zl358X=F?{}`CjS>NsD2wNYQPfO)mJ%T$U#F@zd?p5!2u#=~Lusj+SIc*JjD8Hq;6n>sY`-fQg8f!j7F z1yA4G*bJ*snlo_mnWuC}^A$jO<7?c(9UL4-&{$rWGd9esimDrs_OT;l^GjBy0p9MI z<77>L*&I%?1jT)-C3Q}=Mo22wu$h{3%lK4FKN6%bwlLDQJSw*0znil^YsTNU_GYm6 zu*=MdTbrk|B4(r%ISpZvPHxMtIfs4>*hi;QV}O4We#(Fr3lI){Hh{p1*A=+5#-~}j zCmV{zB#ZAmJ4Fm4yQA9YMK0aSvdjI#V<>uuAES!9eG0m#Am(r?&bcq@43wt_vC7Ug zq{?AakYH6X^KnuqtrkzA3~14daC^1Az0&U(dTCi>HU)o3dxdXn9CgNG*0S;t3wH2m z%SuQt55dvMVlU#$@q%+c>bPa?bzuCqN%~eWJto!(_&4Upm$O3&)E~P>;s@d)8OgH3MT;D$tYWW`#{bhyCl%{ z1%AX2G#HS#Qps@LxqURyN3;8R#cOxo3E%R#rt=c7R^|GzNTB3ye|U zemUJ@+vGMIeYW%g01gxshs#Q48&cEIDAY!RTO0;`iJsxMH~01sZI;c2Nx;WiZZkyJ zlTVR4CLrPN_P~p|za$fW_KVQJ|-K?`_bj+3ZTz5LT z7qASElmh34{&kvcrPM@x!9%%Q<8GyLLZ`6Uei|IoBk9HV>;hGJjy?Ba+c&^05(k=I zwYMzYV`MBc*z>Me7mk$pI5QjT@UHMB$S- zEUa#74x<-}S+8eW%ENubqpTM3XU6*f7!P5iI&*EC5v!I)rj7K|oB&Ow(eSnk76+zU z?u%V|k?5*lA5|z|c=jxN=LWzUCv{aF6M~Kh&F9muS|;%hgOqd`Intmm_|>aFuFwte z)S5M>RDR%!3I0?|5-Zw0bATG25*{jXd6Qls!DdPs%fIsOj71NV>Ga{a!#;2s9G@jE zzScJpkfM;Zrw^(k=_qFiN?f`|7B70=(L|?9N=@m{obP|Z`BU?pk+H(10{$`YM@2U3 z=pQyO5+w{Ii4DV@tOq!{RRE5rcA(9gpPQ%9;tN_}JR=GeYd#AFV7m5=66wvsr*7Lz zN?w8PTcvkrjY@eky}I-?$sw;Y2kMApxQ+*fWKD~tsd_Bk-35i2ED0?%a28q1?ahl| zO(j`3%g84@lRG<=hInAs^F;W!R)EaYayUe#+*Ca_oju|<>+;LW{U692#opc7$Mday zo~tjB$T6yeO)7%hZ}~=S#_9-!_|d)>LBM}>lqwtcFqR2dO0>u@JII=%;FYDsUG#Kfd)4O z=%~t$U-2W@W|J%T5SG;92WT*$VFR8_HhN!$R3uR%5_v#$%Iy z6A|tB76$vnE}HQa#9xIn(xIhFA6odF>pDlv>#)QN*`pJgOY97?Iq!9Ri28av_#%8I zn)I~Q40)4X{mKpYo)lZ0)?p(_)XJ=)53*&Tdd!_>NM{*S`aiHLNX|lA+JqNbN`th#@jI<^R{e+^PaY?zd8u+hPWJb>upM~yy zj%s|q%WS4VE{2q~-7vp2ouL%FbZ+?*1OnNdZ;{bqFk=;bHT|iWQaLqc$zZTxwm7~O z77@AcH-gKu@F1K25jX~3)vT`nVWnzkzN|FAky^m>aGl;}AD9$f_aW~?;q;x5Lz_*4 z;89`6!v!yQbw7tyx^SN1owc{CyDdijkIWagoCX+{lap2Q4seNL=wQdiw8l z@kNLmw;FNA=ev;^80z3h+%_tWhZr|!oRTR|Bz@`ksjYVkc|fYG!>JrsgM5v@-2G{ zf}EwH4B|`|8CxI6+YxeK+f^By0UOyCkQ7XFoxvQ8g@?v6!Bf-Xcipz%FCFYmo~X;x zOH*dHQ7#pgo>S!XMC)hN%6)FeXAYL^nHse{ST5Pe zAaZz~%h~F>9@H4?th%gP;!wM8Nux_CVy!-|PIOEt;N)E}ysc0BL3%KUb-BO9(!w;q zpV7)+HkPq4Z?>@7u%WtXHl|*qd?0w8O3>FhQ`xgFs#zk#i7eC-&pRlJ;c;=Z7?m0& zZzii+vq`?+yS3`~Tl3SL4XHV3{{9+>57~B~cV=j{88x>02n$u|{yHE3hsU`6+IS7N z5Nlw-#5byHf2oyL;sSa?05h?jKjnDI590a6FdP{vP_>iA=_&B4!(Hnsv1n)t>+^HA z5yrRiZk=yYo#bV9*B=8Wt~GK@AhmPjH6uHGp}9fM)jWI_FK7>Fm~(YskbIJoETH6T zf7g!sfNb99!iO!P7OqULJ3Mz(eW)*=((utISDJdNK6Qk_tmmntD!B-?V&qOA?Z88> z&2S~vz(29Sr|c2#jIv6^#n)Rf;eG1gQZ{b^IUDT4tOH09pOrfZ`W$B3R<*+H>pTd& zJjQkbH{W1#!ArHBPC@V}=v2rHSQDz;I_S8Krb3uHaSxDI{52;F@Btr6b0cvE5Ji?g zYntGO8`;~d1|68|H>Vo|uvfI2NJA?9v6DRUBL!DR5(A1(cJlk8vi%;q`U!E*_Fuhv zWqM(eNb=UiS`oK>M`*u#q&mZU?aV6j@Tr~^^PaH|gB=QK-n#5BCS}Ub zM04(7BXw4NYJ#LGIsEFuDbh&e+rahBIy@a-Swv3wt`^@#YwnH2m8)0JI~g;~#9iAn zQ%3%RD!^-_T{x>tZV!U$XwNkt5D&`am`?-`S$i$zH$E2L8_kEXnroM!sgXKWg8QAT zlm$f#bvz?`6nR?Y5^hZ_`czR&-?*?pqN{%lV_tNVS%0i)6z&|YbQ5u$iDc=m+#wL& zWeSWDtpri2zSmyV*n$uS_%>>SJzje)EqWDOLAHQ79H;(MBpf_->0-cm6$amh4ecUH zvE<#TI1lx%IW@1X+3vAJ$0LuKus#T1IEo?99UV9dN@t?C6ZYS(TF?&204D5T3gt)6 z1jwan=aF%EOnG@?X7wu;B-1_3Fkcq5F@zCXxTB=%_wx_(bJ-NQb`BjJgGmxmT*|~q zrJp0@!T6v>Ub9Aan8bI)*B@c!?oMohVVwR?cm4yK`r|qOh{*o9uOCp|AAjx}PWpcz z#r~16_6=P6{{cY%|AnnRW#3YG+EIzmujFeU~xY zk|6XQ%k*b#15@Rfm#$~+ZI~$N{0v_F+wPr-A-;Axz#MTn(EXjM_(7b%k^{UMeb0F( z#c+6S7kyVKJ1cDC+8uk`h;qt}A3}LZu3oKjalLgJyc5MA;--$2OSForn=|e4-!oDv zaiA@3QC?HEeQ(bo8_J@WVvPAuf>Pu!5Tkzh$e=MO*T9yea=JJ>YvM|VP^0lq1YpxQ zcfv)V-%)Cf7IFKYBw|O&tGmtPwV9eTBwT=|Xek-x^h4LQ>eB<3ciW%jI`aES&G3=g zF`#?<^7N~&6`CWnM&M3vkP{GWM)K$9JqRcmz-&p&KD^AUq}uprB!tUj6Z7WH6>4fd zP~t2pC*D)zcIxG?S7(U}8+9A<_M`StmRy^`@r-!f90=;M`Ae`dVjw778vry9iJ+u2 zIr}f>;spT0xWBW#ZLXrA&^|ssK0mJ@9Cl9Z|6=dGgPKhH{!!P4f`Ebs=@yD0K~#EG zdXe6Ph%|xF6%eV52#6S}^j+-TTlsA+D&|epFpKoXl;N`Uj0Naa;(aHHq9&bOeehgNVff+looy63J^v=fkt|}J{M+Cw7R_-^9%_(c`H!ny zuW?(BX5Q>+>^qnXP+J2Bqhdu9;C!ny5}B7(O>~0faugut79HH&a2b;`1(R2HQ%j*j+eGzhb!mi6&=?y{j==>qp`>gaVqdA9mad`A0AR@dEI4Nv@J(pryeUF17K zDYk7^J(%;V&T2mVc8fJAG?HxMX6Y`zlSbA8Sy4vylTS=388<;1LlQ=mIFap(PZE{Y z*8Ta#=G19)Ku$X!Nd1xpS)7VtuccwnIydP$1L!gDYn!D7M`Y zeEuwKLXRQ@;M$X>Z%czz3qEKgrbnE1D>?!2?i-*~V9s%7LXw$04?8=}<)PW@r9`DCP=Jo@1thN%*xF5KcpH*XT5E(( zYvg`8!C!<~6*rr~yE>POjA*9F$2~!I{6=mr^65+V-19M@6kWJ&!Ire&;$~DdU^dPx zTBSb)iZnL7BO)XuudAX4aI*eH0=P_WEKYTEPBdFG^% z#fTTOKHTrhAdl2d#&l>bc-ZXh#T^t2eHml?R|$}#?1op+jj{USYtyAcNzU-{^NKrg zeP~(h+;MD70?Y(#3rwtumY#^B1WQn))!hE`#6>}(kdE=2%z(twqOzLzQDjqN5-QOM zY2+~u^f^SW4)asxUJI{Rbqd;*yS6&+O@^m`zGI{D?=uA(Rm;nimd4-KedUtm$4+}M z4^l7ItaQhhkCaYc-)MH%=c5&b8a~cKWcisz0FJh}Eh9a>63!wY^q7J}Lf8>cw1ciX zq*eS_&U_9fSU&51megQY20uyO@H5!Dxw$#8$OpBUpr1R6 zK4_)?>Tw^a>gP>cycvY=moFB(qI<76Xef(0<2oKZ*8T89)4Fz1(6(~6v$)0H<6GFq z5)O&AuAOCmD*k;g!nd4xcj`t+;rr2j>%F3dg z0R>oL=QY}X41+wWFm?Ze4>dZ4NG>i1W(l-(bR}oAf%?~s2hwWEfc}yn0s$SM`LvvP zL{?j7^-|lUjrG)Bx`da5F*Q_yEhy^KEjFvo^{L^&^qcy;OCLu-iVDr$XknEeQVSaN z@Le1&xynJaHkSe^bv(Z<7%eInj?Wc<3N}o7hbXCgl<=e}l_;J|TV(FPxm-1S+CDK* z_^InS3P|moL!X3Gbxf!+DzOi4@vUG=NtnE50D{VfPnD%q-ecYmZ+->l4<7+zCGcAl z{OP!vbH_$-Lgk(~pVxPh0AllNH2!PtQn0Tso>mimQSh)6o;xab5Acj}u;qQ^Ntto2 zk$KG@Y67zB4sZw4?(y-5OaU)dIv!uDJcr~#Dp=-iW7=N59?41%oAM338r$s4+v$qR z;XwwraEXRh6+2{S6t8?Z?l-aoVcpTG9vvP1QkGFagqOW0^08Sr$7f=~xGU_+ag{r3 zKOP)F#sGcy0F)Bdav&-s^v7m{4!KDh_0l&u+xTTb!{~J^`whFqQ48vWhQVF*0ajo` zAH&NIBn(yS*Oj+!oYse20Qs(X(p?t0(;vEeSuJph8sO0&e5|BT%Q^3b_y-6CIPzwl z43R1VL?2+smL0MWu5x`G7}+>s8WH6^as&W)g!^2LIx-otc8pG*D7vR_doKy|RJu`x zm_lJ{N*CGNnLgnf;DV3nhkC^k$qY%6+>#!oTZWbu{wo~qll*+SX~Z@fG{3HO5)pd6 z(M@%ikn&<=!K@8t*{vC;aF=u~$rZBrkVCgKtDCSvpw>r4%)+OKVzQ6qm3|u4LE^!-yeOsB;Ejd?I0Hc_C;Y%|t#!dezpHY~u@O3c% z=}but^mOo)%Q@8eu<+|dN%jFi8<`gbD#$BVRGR6`){pH?Q}eic=yxuA&_GH>C)5+hM!D znzHuUqL?ENymig$<&M%b94aDk-IPlXCFk0|eVYNVRPRjs2~E(JN@B{Xh4DV8xYHIT zijdiO$j2%&JAD4_vZnr?4X=fZ-lj)MkwmJLmW^q>&Ja(l{ytEK zV=KTd;RM>5WKWIM=WbhTC$2Ss9$~!U2uA2kVW1=lG_UDoF$LlV4PP?x776&P5lPi; zaHBAba?EiTcTEOqRz@Npv)V>znF~~pm$|IO9bQFHk!M3z2(bM(%(=zX3U;BSHrZe7 zF2~=r!;HsWd7W}Xsp=7p-~}dy{0HUx`(7P+$NG!_g>awB2#&W4z%R<^DtLxJ>B5gx z4ghb3m~0*gPLE4}782Qoopa#jBMUu0M&S(ztJ00PG636fnMg=OJv}ey(qY-|}=RgS;okQpEpmzOQ1U?E(=V_snPg+TSj{ zKA>0Gj44^ivPD8{%%FM!DuuXbsMx;=ArRwn6hKbcA?(7r0I^HR52VLaz0fA}0uUw^ zN@1fFHPi^r#f{!3Q5i0?WfWf#$mDu@8Ua{%D-SqDI2j90o6H}&^o5rMiEbR<5SO}oFU`k3DyC2 z@vFJjf4%n?_mRL>As}}O^@cU@nj}dvy)Wuv{CCPyB(lY&n8F%9_MYbGX|yHUah%2Y z0Z2_nSWRutz~&QtPH%1ZR^U-8DU^$1bBPArxF0D?EKxb z)TrTvlP?kZFWynzr4uvo1n8>)A0(CqaanbhaP8v?VLpoJzTidk$)EIYupYBf>;uFs zyef#*ELx`gPE+k&^PT1Zma-kd5C}akF?;`}^Txf0BlXHEeo{bo+bU+zf6)yWTyaV` zhX-cS>*(T@2#hE)?-I`^Fas3Ia%F>RG?qabN0}2+klRIsFQ3)to;>4;3jOS3<|+9+ zQzKb48vf`CIX%fEmv{^igZo3UhC9hxR{p-5a;7PBgFRw~Sepm4PPC(pHQ++&(Ol9sms}GeNA52H-@v^!GKTJ@W ztZucGf{(8ya47r}x0N7Sq%&EbUrT<;yX*Nlv~o>imn2(dYiptE>Y#d}Ch=x)f<~~l zGf@OE6QLEMWZdsAv5qAVKb929`2E>>PhPg)=QBi*#@xRMh$P*Q)r!iO7=+OWI>&Fc{mpb-qr(n)Vr z&?tN$AmYC{j-caHe|O7-=97SGP?4_+%XlztA#0pChjX0M>qiZE*g;MIId&Ue;*>(h6*hp5R0&(^2F%E9vrU#P*<;1*f2 z-hLcK@28gQaE(#hwiEEUYT-Y=V??~^TC$=w+RdL*|t>$g8y5|6_(}iA{L4DBTWhSQZ^mO?nXA{YPuP`-<4JDD&Dt^IVDqu+M-oKRW8AzYc4+{dKKu{E6pRxg ztO~90P*e*?kQLjqRTZ3WW9V5IwF_mGV*Dg?3S8Ww_W|U7qT8gs8ko&=ED9^<$t#@c z7-yg75xJAeBEown-V|Sa`Z)R|YMp>@&ob`d3wd8{Ax4no6+M}6W|gN4b&g+Mj?CXc zhLzNKhTCih<^8qls}Mnb%=Z=}Cgtr$ZGJ!sfhtGA2gy}eKxK$6tW!N2E_(O0Ijusk z-mts>#YaGe9l>`vNwcBDDJwU_ zVB%&TDhM|<1eN{NRL(oEnA>E+zBg@$?Bw_%cZFdLrmnN+3On2)+Cw?aOM@G4FWXn! zqol%HAmHhMvLnFg_%2!ro9qcz2cRD7|C(WmA`9$6g%j2uazb5 z+TJfcmEdn(%VQ>S)XeBg^cY0*$9$2#5f#SU7js4<###Rq%JjieWc@M~11+t3Iw0Hc z&1g#dGk#DAViJJ|o|yJhOYC>))qd&@ z)o~W!N=9ss^|_`H*VjOy;m*eLM#m8%>(&OyDz{Fjwb>xT=lDi@Ch|IN7bJzeyk3;72#^^lnJX*U&^CNpQOB70oNb+ zR^gs%Gow~3`MuKkIpD)_Pn2NuIj!V8qAo|_Z>KFQi*bxc2k{O$qQ@&_Wkf3=EF5Q} zJ;Zt{kNi1vn>;Cf1Xqhj6wk|oWfQMIqDSZBmg^s8)b}#1NxWoLFZ9Dt`)P4o;Ydob;)8C1pD-eqnUPqAGY%l6bsL}ro1 zdX6OzbgLVjX7N#Fj7RqFr@;qw9WG(@LEW)V35*Yx^GDiw!8Lh;CY&qgJ$|&cd$z(b zB!|^WEokHsaa+Nr^*(2nx;zCepXf;gCw zu87|?gn-7mK^ufC*5g`F@PZY-%>HqM=7h}LJr`2O2VmN@YcQlwJJ@SptDIHfa?sF! zl@3wz<$BjEIhc!W_K8?nA`keAJIJ7$28*!jXvQ z{nol`0iS}-COp}%9IFP!6m}VAs0T!YAKdpBidGj4%DLxh2Z-%{-Kt&l*88`kJPi%r z>9TQD9yjJwRh#U+bXk}b0gM2+;)~bw`0d(Bat16~s*bC0c356U%*i{6^2fPQdgdDl zsu-37Z2HB{tNfeaQN-zafvHrnGFvRx)7ABfpnSZTQ@8PpQ;I0}cZ639FaE)Q`S+eX zz&PTH_rHIB(sko;r;xph8-NkFeu3>odE4(D+uwHN%MNbC24f57`U3ZNyuFosBS7>2 zpB69wiqZg;EmF67^@8^bjrRoj@aTGfIa?yYad-b0KQ@;JKp2>{I@)KQ^-?0329hX8(&({#!En%kk$oSl~As zn_oKCAJ#PgJK^rXTdDm2knaB*n(O})Al?6ma`JyZT9&O(A2XM``Z8zCoA zGBeWZWT=1r#@k~)nhE@#Q$8Cx^_;QPGSJ4KOZlJ7h4w0N6U3Rx-64Kc#lL@(w~wYV z&P;N~X-Htdfxc@;pfwoS2R#0D?(fZeizcVdlqNmxGfmB(Mixn&hmEd}jUuDG9Xs|? zrUtEJ4fa!~s%H06t^Iti5J1N7WQ$)I3msBmX@+LUgPqQ!YS=PY=S zegFh88RtH|fEeCH&n@^tfOKw-6#U0$=sERMP&X$`nj9x;?wnQ-Q%852oIcd8Q7S0u zG`y$u3TkdB4I=hLGAKzMuI>kkJYX;S%_Hr$D$vWLTC-OgD!uk6eHS-?q z)<=$XcYyP1AyYY5(1Fw_D;l$O3t2|O1Dw8e{~|H?ql#ER9ZRpQJ4^b#W5cLK@dK7^vJ8YuGLwi->48-xpiPT#Md{Fe$(Al zUJdh|%wD3WW3{63qO4re9SMMY0T=(vc;*K~FnattA^RD3jRqz73wK zpj@Th=*gu+w{B-YG4^-DHY51cvrCC|Zcu6gdopWx8r4+s1s)+GD^FCu;UvY@){F%* zozy_vn1=pyMb1syAx@zq&V8H4c^&2kd{e~!Ds4k%_ecI5{}SaDaP#qfQJw8aG|Q{< zqbJ%&JQ^x77k+FMf)a4(t>sWgHmng|QYggx`}=!%#^Fum22cC+0qMV!v9oAg)11>u z5)y#9 zhY~KNxE)u)h|>5FyNMM;fNEkz8Xw^@VpOiNR4-(wq2L7p_eoPn(waJ9ES9`@iy!=vbY#j&E z)7{m_mhNtDn6&lX%iT}JZLksd_waYm z;lCzk4Y3i+21)UJ;#n6;N94Z<%Dcv!nsKWDx4zJkk`{D)111yG) zMVw{$CKJE77u=Y*#n}6tR1vNM;?Op$B_rj0;15WldV67Y+pU9WKVfMVAfQaoz@U{r zBEef(*J?s(WaSflSMJ&tqXazgDy_0Wax^NGJBQVHOWCyIPq@*ONzX@7nqY-E0>M67 zfigh=`$ZSalq0ALpZ=u!A7&yC3x`NbYL05%XgqQrAWB`eWq-RFw}bg=?>z>f7SH`k z`xV+-s-kNl6K&rm#Q@%2vn3tTC0a85^*|`VM>G6oqq(uF@jDaq9sjUJWwRmeiSwy8 zV}b%DL<_>)Nl>yl1S!;98aIBz#MuA?9D6LS4-(*SNIg&>@IMx>i{p`%rL>SbO z?1$M_`JH3Pq$DOrq>SLR!S40CR*FmSO=Wcr5D*&{p8yr))9w9?-SPOFz)Frnio~=> z*EFsW3|*7N7ImH8%=rMRC>5-TNTt7{SF90sw3QU@$(icU}qg^+27~QQypC~fN#Z%P&QljHI?I&J!ZmGKYKOr z*n8DPMq#1gTvHldWsaC9&2v0rYCtCS2FxC_7SO2xUb~~*$u85XIYY6u2yAdp_Q7JJO&-&nYwp7B_&9u(VcrC#9(ci58)HXeHJo?3a{Rit0H4Vy6t}6rYn%J{z``KT1X^BB6 zsSpt44Iz>AX3wL9d)zs}-CsrXI{5hvJselbuC!jwJcqKmnq6C{;I#vL=xF+wQu7|; zqypY5;&a3KQr|%44bgigO6MiWfrYl!wXQc=LvINLoIL6izW%s!U27$VKxJhr*Xo!_O5CZTuy5bw^j~q%<~D7E#40yXCaSiI<6m)C ziFxv`hq^|={e!m454Lxoj)fmrVSYCa(!~sI`v4g~1T6P7?8eycZYVT|d-&O>rCv7T z;D4G?rYqoLEUs&%ivn5itBv8j?`HfnaQ zQuVrmW4>xhTvuUpw{3Ij+s*~GkK2~1qnCu!fzT5oqOiK>g*i&J>>YhhmJpn<$>&xU zXLbZ}j2+*r8RWqgz|()NKf7;$`*K3}a~&xYvvBMSKd}ix+v5fZ&9lXpocXv9N(>0S z+;gy1>UL8~k#teU)3Y&sSq_npGUg{c`5$|SgKUGp~q;P0V_1Q29d1?y~Ov z)o&lNs*5D4F`q-+x!8k8p|P7b7(G&DOeIvO+2X#t*R?&}a3D z;OtD8toYs^0hKDb(Gk%x_RRBC6ltCoE(0D4Y&z>XcG=1|L0|Y_oe8O|K!Qk_7Ti3I zy<~n`d->87vqnjLwiAnEfXAp=c556^Yjg_d_s1I|QsZUp$RDSewb#REH0F4m>K3Ay zDbbe>@u=~m?3K*dYMx}*)=HdKUrmwByFB>zoYU7bx<)*|x#D5^Jh!Ow}GtFHaZuMxOWxU#Zx7CU%J0T{YZy$G}AI}jFB zGKo8#uqqzaJvd=?10hu2S$8$#5ZhG0vq5-* zlD-D3v7C}7P{vKlH@m!PUI}E(ptxESsMzLW!~c+JYw$x}@m-+$*Sn~*1Dq8h+SN*L zoJuwOX`9#uMXQERmeap=5?$fQcIuG~GECdmV9_)vuRkC9qt6J~OgVSC&S{XhuEo5Q zO1ctbRjixH@WJh_d`ePT`Uw8~7z!Aj(+!J#FLr6Ad=TDTrRt^O zclTu=GN|daK6k8S+eA40UIB!H{%PrTT07I;`x9}4v^hvd)k006qM{w96$ll^15p;cS-=f@qksebTccvlVo-&Rxi&|u-4sW5+DDVpM$A12xJ zts?PuQu@pUcd?52)cXdwYeF0A3nX165QHI6H{hTdM8)_;vlN%7VSrzn8{(#-q5_LK zUmp%=C|Z>;ROLy9ifIm|`@&50qW6s3sK#!ajo5gQ=Y4=4*KqG;XNdIg&1LjYj58$V z>mO!)LpNnNaom}pJj0eAq7OhP4cBNs55O70O9Uz0>*SD<|M|s|M~v5|2%ci zAJ!3SL8_v~Ne>S-jt^Np!#0;a}V z^8p`fTZU$cb?=*jMA#VJiHYk3(nX(<9cM=_W8nkrF;%e@ClB|&OnY251zd|6Jw`w; zw@55yOuyCk_TKcBGN#U)yiPc53UE>;Xk8yTSRGs1B^JF};2gxS4OsHol*BpXGD>(^ zX##kGroDWZ&4!L?l%WhpWHnA-za=bOQCQS986k+&ulRD05BA9<=e2BMbV=idE6g1x zl|da;Py03}1hE~>n8zO6#@XHB4B;n>#Z#qff+E42(E)`Y`M_N=I#CsWUir;z!#*pa zns5TQ%*!km<_MVHPx6mu0&}C&700MhBn?ct_Z;3N&&Tt|eamuDsYJjVX+Q|}%N;b5 z%6**wldtH6&OI_C1AqJAayWb1htMKo^+{I!go zqx;8Lr~X!`3H*kK1N~e27~ZU+!ur>zST8|-%4AGj<1sB6H0uGp}h~hu*LYIB4 zj;r`N&&OwZ6=Ef`m_63Sq4ql;JIdy#^7sw*odyPKib^awKT|mG=aB$KA}ZPzTVk7* z|FdN?bJaluy3>{%w3Y#`aFc5T3~o!qEB!jXY_C9Hhu9`0yXMf_!<~0<0S>GZF4tKy z2wrIBbP>2m<&zz zVU}AKf%|fu{ecEY`{SkT$y6sEc=2)WXV=L3t`d4$w-sftTK9TfE2a(%QCs53Fbu!x zthFA)7CjO?rVDp+g$LfQuTs6;Uj&T$dQr_kQd>^^EFK_oirab9J_7fx;#p27Fo|z| zT%a*@>RH}HK=Nhs)h`H0o=RAVWL0?TX}f^d*(JEa_IpxSHlx@UO>4KD+W5+?gfcX9 zmBvsvximR{9*ECK6SOQ2npA5vZg?aoZGD)48dF<=-fBLvw+c-bS1&Yl z_9hHbN)klw=H})Uw*c}hqF8S9u<_+uBn;`5P{~n{4@!r#(3&8xw$e_M5a&#bU3G5^ z{7hK*w6O3)zE|Apx8(|xa7s>1OWT$-ZOy34r=PfUxDySpcWA`psr?+|UQmY=<-YiS z?e)WRy4CdIugh@K+w{Tx%{>#WnlFP}%HR(1O;lG;4?y24_bV^CqTF{wSv`-A-4CD` zPS3C+KZ*nweEgUM!I6b0VCk5?(FYWZMn&PWTY>*@WO#wmZuh`s!QJY0Zs596#O>K9 zy8{y~=20N5XlsteFwQFEt{I6rmoI{np(bhzjie1abU_}m*#||##{^KpzUn&o`~+0B zs~~XUl5JY{3D{wWh)QrM@uu~H_jFvR4C6`bF;4;0ah3(@@DOkt#mC6$S6YvqieAc2 zg6BU?*RH29Sj9A6NgJhJ&Iunnp<+V9=ID?n*Ka~q{F1fn;p2+)bREwbdI&w}UbU4P zxN6~Ryt!krB@H9eK4|c2W8pxj#pGCBFVY^R$IR{rUP4%&`1rSqLCWN|2mD`XKz z5&222C+=+@uX$fXtVC0^`Yr)}G;gO8KmH>xA)pdxa;PDfgvSM zna_t)CV$M~Cu`5SqzVqQKMWME%M8#H&l+Uv6`avcF1;dM%L$s6yX?L zkdpu5r1Eq;<5jJ}jq}7`()|+{z~8!gGptdm7)%S>v6@8G=?g^Wl!zjeVBkn=hU`(K z4!Bm5=RO!eUt?T!*Kj)vA+b5*xv-0&R(+DEdEX9Fpm2k$>zD2!hnQ~wjo?tTEI z1Yi&Q_9o{MHdh-y@ibnIW9Lr4E>8iEgWFu;u{)4T0nyQ$N8xB8r?dK9)KdzEH26I~gJ*6ku@bcZ3f1oPeem`b%eVqcA)b?1>JC@Py zZbK538*$z5)khR3dupf}weTKAo&=66xh>v+P(ZEPV)W)I*anwK60}-r=4`<>NoQ=< zRzB6tedFg}EhBnELxX>g)E%0V!>xD$Oh}`YXq!Epwg|QaoQ#G8Ppj8K6k%S?0Yd$7 z3ntIyaVR-6pTnNC|3P56k8KZq>Qh;+OkSBnrVDnfi0M?N=ApUq+@t@%E{WI2hcMr| z`JJ(g=%6SYZ0_F22sj~#8@E~O&s4Gar@d4o_c?7nKc5Kn!8ekCrK95e>479J%apaf z8Oj07qL1Q}+$QH;sV_turmg?Y-uox6`O`f3-@51jl#>2id;ImUfX_pz;m7~ck){0= z*Li5=@w3hUTLZ&^|xJLWQRQvA69`ul75|NE#M!IIrPA_I6QYri8W|IpI@bXit< zapX^cOYLs`E|LEi-D3~yrlJ@;DF`Im0a#7|U>83_{0_r~4&QY)lMgjt*H4^8_E(_d zVNl5%k6TJ0QN?rH-W)37xtH3#T6VB5j@}Kj{z?h8cO#g?x5}fJPeW^K&C+3B6GaE& zsNGKeWQ{g&!wo|B>Zfvh^|m&*+KaFUtFyz{$IS-*Qf)U3QA$vy2ky?6Tfp_$0P6kS zAUYr_d2dq;{;aLY^Ac*e-NGw7s{CNm$S=yD^VzO5b9DU6zfXUpiaq2^xY$mrfc&E@9G z=nA6dKIO@TNLu!!r$fXvQe{F?VBanMA!484Jy)4v-|wjfC0$6B>4Ko=VyR)@Uuy($ zqO$*)r1Bpc*ULM4QE4*;lV|Dx$|XtW69NA9=%-TXAB*Mx1hesfqQn1OTmM9N|G)BR zvF|ApIyXD|X5XqDAarXNB8$|jmj;aD?tw5-_J3F612=~4WPA7FgIJMhBd;w#ng_1? zD2YwqG1aW}Yq|KJ=p#5KezR+j1t3Cyq2Z#jdK-5wV7~x`ZW14McmDk>TOTlMU;nw~ zf)D-f+#dj>emDS1p2zz9`?so`Ng#e55L>9m0#(v~{r|vUA0-q%B`;eVS@znf)G6w; zp8gcs>I9-*|4a5ti%*}q_nLqauA(4vyWK)!r`5U;n!i!K?D;=FwV!(H2QZt%;!rWa zXmrqDZkH^B#}PV;y!U3R#CP6zMUy4~eJ4nJxW&)^h+PQ$BP=Y;}LvF{VJAEWK7inr?Ka}o5w5(qu8xw%Fb_A|n)bnqzhP;jB})uML+pnH1Q7{`5S=g0HK zeN!^ynBwUbbz(*sk+C4knENw68Dub-O-Ls|FGOvh6@-Gr zn;r?n6c#u#53|na^wfu0>LtQ@FW(^ad>9;0GiNmGm5XGsSj9gVHe!tQq)eT=2>8)A zZER<#hO*wtm{Tfypz#+mb^(UNR=HAwkA_*#g|mxvZkk0jq|6{i#X0{<8$e23_>nDn zkJYCSVYIa{V7Kjdn-B?%D@v1hb}hg=Y9`F5b|{}z0k_csePtCD$Vq4}Bi{mu!?J4w z=@_;|dOIvQtrqxv;mq<{E#bPRgPf2wy~-0jurgj5&-!3agy|oFIBd&mIFHI_&3KFn z39U(_L$;s!%4@gaey^2}vfXfoh8IsTA6gXt`sQhp>t^j6+{ym zjXgr*@Y$MV&|FdDUej|D44A6O7CB;Q-{FFG%KjOP0~QEw9ox0EsbU1`ys}PG(oFEkUKM0{Gh$3#qtn@&(mWKR9sWiyAwsn{ z%|$nAFxOnk(aY3)UOn8ZLl4K=uD5(dlCMTJdrK+9{Io&ADhO7I`m#fbhc}Ldw^^F+ zbZ(wiTT^3Vjy$Ym=8&Ve6oI$S+@ZJ5-!nP#xQfx%Hv7TX{U>x7fn@`iz73;2;EjxK z1ug?5ia->RiB6^?E!Nzxe6Z<*>lKpIYNHrx^0JVp&EIx#CvI?PY@`%GuFFJw1;=t zD`}G6$=t8#{EWq{|6FeWkx%h!S@-$ZS#jEKf3Rl@)0m2r88^GoqT<+{h85gW!;(p8 zL0mzv3zs|1t+1b30pBj;?6F+1PnDk=8sAUFsW24}ZW6w%`2)C>rY2F9O!y={XM&aQ zF|`iY1I@K)`8KLDn0~VBuG_Kx^`y%Vy;rR(gJz(joN%vCKlZGjxqMWYkECR8ae42f zBY&;5b`KJjQo!i|S&{ku1cGw^3;TzCvFxpiYgVr^1r_#-!HyMwrRI-o3W{|1QeBFt zL#eDT4_wkOMiKLUCU~{^-#`Tfk3=%s&L!yjj@XWEfpjS+wC&j*Nsq~2^Xq5a#c$xF zY5?cY)X7}H1?jKshx8-H+!o2bHv-J_mh1(m%?0TFY^2&8S5tv0sJiLxF&d!`Jo?H^r=7oDy0A3*ntmEnO&vvFk*n6umw%7S?{B_&>gs64x0am z`ARNJdc_{kJ`3_V1bU7cTK2@Y-(TEQ;DBqx%UM9ljjcq)`Nz zLl!qfUdSTSu`F@D3Vf#wxg2}cCakA1CVfpLMy|n^vr2$9>*mpgQw@IzJPTZUki7}F z4BdT*%8z0@hGdyjT<2Vp>QH^=p#>6WO)KbtH^}h&C&;3%6Ns#vd?iKYvImo(&BFa| z{HT!}d(Pz6vBP|Kh~bsvf1&QHzjm5fsDm$jCVt8?7KNJzy=q3S{KS?k}v0h5iUD?`Wq10Kw(_q} z6jEo^B4*)5_}UkKCPxb>VgZcc0UR5{&)nwc&x+cNV#E@Us5e(|bmhR`w&B*r;wqM4 z4K0x5w}+tD277mX3~mKf5%{wB3?yihx~zp3G>@!aZSA_kfj8+1+P0R9*KKobHXY&B zx~Ok3B~qv*yz1}*ve3B3|0Gb0P$=ucv(5v8R;_r+(_|A98SwxqE|6LE&6p_#XDyL{ z0b1D)K+rvazd$#;I)^TiS@1GHFE3_zc=0-8%F>$LK~ukGMcQn0W8;hci8*G#gLw-H zW)fSV?~Vl0I6bGpvq#hb>r3JQ_o*-SuZYvty7_*0ui7S*0!WWX-BAjWrXo|vND|8& zgA@SS7XhdBfNGFn6Pl~zQ)gxTe*8I^ldWgwu{WOkTHikp)_NZR*g@9}2rJP*<+uET z`!Jm5w|nE?+duZCipa93)S^`c+>u0OUCez2p>rPnCvkB@EXRRAZu*qy<1Zh9as=?4 zs?bNxkNG}2E2tfC7!Pw(RJ00?GBD?n_l{LYK`dusv)fVM_^?Yj2WlWhXt zoA$NebsLPTQV11xYX|xaK7GI*HQe5d{^GmFn&Tn%FVZ2FU|Ebxo=I>TY|FB@0myk* ztt8X~UJD+_xw`~J{IYF*mUuzEkaHLH8T>|S31Ic&94g4uty8>SCs}lIYzaxRvI*lp zbK(2h!6J=7S+W3lOY-NY%$s~#n1p&tbxL{9iL#aMiFOT8cZ(DZAER z?aXbntRR7Y#E%c%VX|j?#S~HeHeD>m7=q7yW~*r$*J+w*1s|&Mbf>y&3vkP)cLs>@ z>i<4kpn4bQ72G5$IDV^g@C^M|P9-d*4O8Ay*u0STMfc4$_#fI((Kv+PMM1*GMv;DL zbCmNJu)vhU|4c+n%Z-5D1CY?1WrZ1c-abGsC1xFCcYdq-tqE2?o+gVPoZY8mp}o6w zB)oYX*r?ETJSyhkjYeAziHL0^l(BiD;1Re@h1bT2ZR9E(q*>@yVpdiXozr$t&vSe6 zFqOOU^~DPB#BT?uWAz!5VEIxPhaTx#EQg&?0g(=KMV@Fnru*o@bZTL}dzO^hC(E0= zTh`$Zfl~?Lc_uIru#bz{y;`3}RPd$!>tqJfm+G(1Mb(q9LLO9G_4yw>X_Dg}<0*IU z6q;q}gT4dh9q|0a*ja@Ggcq=99PELOhBc>1TqFQx8HHA?zuP!FICSeEJo9g?Sjx=+DWW_mBJ#GD=$d(9^NFo+e^3R|*_5EsUTUbB3r z{KhBH-0Jdf_t(@?{B^&r53iq0FP(QfVqC%FSMciOYhYlW29DGkM`l*6V-`i>mk9-1BsC0`ZZ1FJb!+(g>-@YoM!T+%N~ekU#!jde zLbTbS8_+e1D#w)_hJ+A%tZ`+)i78z!1gCSTr2a2Q#T2o@Wp|ypn>hINf$WA|pBk3= zph4uiLh~h;WW|@VTnR4&s1WJRp^~i0OJH8fJ{c;pG_plRL`qY!Uo^DEUywY}5xG$; zg*I=it9QhmYqmgYCk8=>#~pLe#XA-z82Xsq5y_~(*VY)o0#lyBhGnaF-7!k;T&p)P zCK2}1li36Cx@B<-Mi(AOE7xXDsfvoTK=417PYs_{r?j6_-LsV|=CPd|KrK5J z@RsHD8LsMX!4)`_{)uPO#^DX6@m8cmANwWDF1pk>@~2=O>Z0DTY$@_g-GBdu6a@3M zq&I)~aF;Q#gNi~ST$_VI2P*7kP)5!1Cd24vM;b+qMqj%ijN9Ece3@0@{F{*U#ryz` zgBn!P$Rb-!!Ca1YSFz-?47$FnlR_G1SY9IubziceCM2*4!(W4N0CS|tPyv}!2{2=t zDAGgYp=h`7-F<#|fzMm6y(%4rMAUfgS6T4m33L7AN{infWe;*7ZDQV=O~%n%Qzq}v zPP|ZezX%1-r*ewZyu0I4$;}bc^b*u-@j8?(JocNghUmvlj*}XR_ios7`=j(V)-DM3fapV-LtJSZS zE!tWIA&^%t7>S#<*oIu~Va|mdVAU~rs-hky&)XS*!UBJYLDmCu_S3cBUf6Ym1@3Y_ z=ncpw65ksEAt&~UvVhg${z=_&NLgjMYF+-bD-gzMJCb1)hx&@D|E}_W_|6dzXX6tp z!kjyT;>O9ifR8K(m{Gm6RN{N(*XpB8Aqj&eCj*~`?c)SCt?u?&Y5G#`Ei%gX7EafH zz5;M;TH9WS@`ymW?57%8vG1w2E`+{Q?*g2Ur^77N(`!U3fVIaJ!WVbG+bW_(u`AzL z#+1T`ag&Z*1(+v%H3wWmqJ-B^qwB9)$r@*1e!`q{Cx0UURv>9=ZW(0Vto8#a^N?1d z>lM-GT*;)_23$o>L$!jm-Ph5vzwQ-3JKLFZrElLJMJA;sOH(Dv@7}ETgcoVP#n#mr zLOnj)Clgwd_k&KHG#=ZX@`_jT#>%xsEHRb-d3m3T-*jGG5Le$I|01FF)@|U6Mu&d! zrGY{(z#=d3(Tw63-8+-bRlbb2f-DL;nGS>R45p}aT2#7;3zI!*pdE-8)sX7Hj*@cmmpL3KLOAiI6D+}~+QgGmS;m1D! zMWjXaci{N3RiJ*hQd~;|h(dFMOi%X#M|=?1Gqky$)ptWY%=ijV3*HRz& zrJuq2OrVPKx0En+be7V3$B^a9S78=>Ve?texyjjpRKxJwhMMVrtQ}XX47k)-&qUz5 z7a5muUB~srq^v=Ix@o-hR30lsI7^;}pv~ukZ_=1SLARc-xa&ja&5o1LI$j5`!y?a4 zyv%x;96%M4UJDDJMF&WERA+}+)_rNs4}9eD6{PS1e$8n)gNuSqnh$%3Sz{uK3>=9- z=LpR9?ZI3)M7o0tz4ZXn-FYDZrR@!UMvOtKBFUOBQF{jVus;kL$YSj(+$GzHaVZ%Z zMAwRGRj}UQeM-x55Fw@tVA!0y9{_`avcOl?3#|iof0uVZ+OFttmi!R4akC9}ME_RK zWip{j)%AgV{XSyl)I&R@Q_!5_>qi|mnH@5SXM=rXa(+&NuoAP_{ZqVAN%#nPCL=yH zT;J&o{B(e^Mcj)!E{m_{)Yr1C;IDnp2HmWGAJj~V>~06LVD*46q>Tt*Q8Le4GI+jU z|8QfNe?+4g4NH_6P%HiN%%Ht6d^@|=rM#K8MPcTGv!>}(Ln)}qcE{P=S*Hg3nzx6I z2OEqH5Ohr^QH+F_c_F|eAJ1Pzuzv_JHYQeO>$8Bd(UZ>px!tF!;Bdw{W@OaD#PMP~ zHW4g7eMDOrt7%VQEhA6Xf2BYB75!y!Agq?K%mZVOfw9d+0?K22!eY`OE%rf+%} zDcKRKlA}_)c}Fixa-I{N_#Z3pM}LqoKkE*;o0!1VxwCMMMg4sjn!wjvwY(ix*`Agd2q6X^@236Uidphj-d*dIm;@(?19l~C*|yV;l0UY>u6UK<8Y!% z7DWf(@I%)lqR&~|E>1Io&sl%CF0#b&Z;I_HTaV=UBiMnN>vPaL*QzHo!dzfA-X&=W`1MJa;VfOA-vwtp;xpK%A$bl zS{TV83Qubntq#X?sd74jESCibMLbC|%B^pN`tvX*Who6E{U2}XNBeC{k=BJ$`F45C z!*d2_efk<3rNf1$0gs|9dfqwpuxMZj3%~C&g<)hN+QU>Tln_uGOV_LX0jUH$zZ>yD zwW~lIMCWro2k{*WP?if{;lx3CiuW!##GOk8?u~@Xv6>Gc|LxQXscY4ZdnBRHtGDx2 z+^O`$Il)-q{OJD9DGi{{R@58(&d9@G@x>=%F!3H7=-vH@4+;R+3Ho(9%sdVAyZNs< z2d`B{30&pE(|m+4)&jpSQ9p5{!(R7lB->n^WjkO`0eXR*ef?3=g!V$i%I`NkA3l5t zGDJc86>xPJtM#t6m)iJ&cLN_H;Acm)F9e5=Vi}IJb^^m*-#AiaYWfdoP)NN6esL<}gsBc0GoLN7`c=_QoV zM0yFm*SoUa=jY!0@9#Mu?(^JxJ{-UJMYGm=-?`?R?;K-}A!`FM0tAo{wM}eKbTrj! z;s358el+GxA+NRvCx~jF)RjX3&Gv;JAdxtt4rKbG%L~(+%x}t806n<8L_kRJ5Xof$ zxD_YX216=!0A>N8r%*H{MbuW>3))cCKmK_9B8+?gT+Ob%haMYIJ+J(O1}@PX_U}|r zY}5zc2MlqA28e}0IA9$$L^sc2C;+I2VTmSQfGAj+_qJ|ZHlO>=UFK*j-4O2FdcYh$ z4GopDfXqRJvfyQY;brXsYJ{N+Y{qigOqlx>Y$p!}8nTYx*gcJ@#EL3VE zO$^8@fKyL7u#8@ex8Q+U^?=7-?lGY2fIlw|KWYI!YV0Gyc^;lD2V{{n}902zPTfyiDwL!1*! z@`cU(>(lxdF!GmG@2@%(e*t~}+n(rOwaedE^_M5!zlZj@|A}({zh1zN7+yK`{uJI* zH50@Cx_bW@nEqD<{Ywn!$G7#b-6W!&|4NL1HAw%7bNyq>h&Il@e7}E~KmU4P{s~z9 zBUFeI-Tz69?c(QE1&sGsqD&9c(~1gBc51t_TzVf7wReAoRm6mRT1e-aIDQ*)Jk~bg zbsHkU>!vwpDpeo_N!ldBTzzYz5KKhOLMw+3M}2>z=rs!uu=yP1EDs*3#Uz zA%4qNz*nvqZK6NhZ~4b{qFqKp@BF+?FEfDbl^^6TEwMR59j=P<#r|@Uf&LV$7*rBg zT+C$ZGszXU(~Na(je+YJJQCK=1Jn=)ii(QTyqf{=XK8Qmd9SE0=(MK|zzG>zoHw8R zrW%y-OH>T-04u0Dx?Z9hmunUEfGD`vH0s3#np86 z{_C#+ZEm1{7U9igif$*umTo%RD`v64K*<1NR|<3+u#FWsmnrwZn$-V@6sr}IOa!Da z$M;aTz8KeLvY(PBw;gAFqERgt)DHQf6e$QOMfye<5tSn4$*z6@nx6kqifmW^yHaFI z)DNY|#cE6yhqahyf>y6)`T{_-&fv_U$XRdTw0(#6JKn(ofarWiaRJNY;IH{+UO~|p z205@(MJKI(#!gk-)6)s++^Q69gpCY6KKyxu`_(OVLDTug&W2j#nP@%iRz!aIYi6E z59}_$=!@%O>a(C%G8fb2FEPo+MGp8Ja!ax=q2&Rcy{|xUm1rwx3n3}xj~iSKE>_W) z;L0VoFl!p99z8{ApneErk`Je z0|VMi-2^Jci66)Sd44cWz;6>_gsVD?n_GM+Z#|4xRnFH(`v(3 zV@NWIu_bb>r$fWAX}m$Uu68pGqR+P;19--*UgF9}c4tYpy3!IF%aG_M^HR}nji8}o zrqaqLPh|M*2Vg>k5pFt{57rw2^x&7jzgF}M$PHSI|K*EA?1gRR*=C%}4DpfxJOXxi zd|5)%u81Ndfz5#|?HstA8rvL=i5yjfvW5DA>Gd>!?}e}K0nN?NViazw4%LXVarxK+ zQJ3~Itg+&aHqT2eP`+blYLjkBp^Z9;y5Yj zIv5_tJ{x4O(;48qnVn!fE-1P5KE4SZ-C?qq@KQ_Rmsn}c;e_J`iz8yf`g^lf?V4$V zZ-bP?YN`~qPuYU|#M)+#)P5iIk}2AH>|~ejM9N|1a4?y}OJSlQX^@4%nwR|U_vfwl z+)67UXycbcj$cU_Bal3b7O+)d0RS36H84=fgkAkyl57c>8xL`Wqpb9UQDLv4$r9rt zNuBoOh+vpK526@kF(=;+;160ZB12s40uc+{>_S zbf(j{wB8vq-N&Sms5YPHttr2Q?F{X`+TmKXtGFcyA-3m)6G$%|{9@6LyVr4$Uj{6I zZ)xROs}eKXawMm+`LaLPF$$ao$c^GZK>+bEO{tGU59obC@!ROzjv7I<&I2vkj$&#Cg#_~M=5Otx5gqrCEO3_X0uQKBw->ewoEDcYL zW)LugQ2V~4md!qQhr(fBLI}%q_wW!u7`H1R=y3s01PEr z4qea|O(5hy#3HW{Z1kggR<4nAr39gIM;Z5cs=k#PtuD({aTd4V>6{Mjb)^M^YL&DM zfB8uThUw8h$JHmgUdyW{KfVz-1l|(lX3;Y}U5PKCMgj8LhT8B;^-#ZW3Mi+p@_Q9? z&7sMFh!&^%+h<&?^szag(BmScv%n2KdsO)Zpgc@gZ3943_W9@Qtp?fQ@wHzm*^Jic zNx1k%EG(&XM!D`V`2%)qS|h&<1}#QW^j9lYmk42Wy~Mo(!{@t?|5T|86>an}yB%EI zZ&nO1QN7XV99teTCdKZ;EQ%KTphKw5e*y%c8eEHo$$Hd0y{BJNSeQ2CsR%@WnTA0d zerqvz{oxc5^15=J5oT zwhObe5$0O%5brVlg$n%dYcxv}gk0wXH08%Jtqkyc)*Zqm;xU%}Z1#Gfc zPbVpmGPT=r8<3a*?_4d(ALocNavspP_OKO+83|DWvpW_CXxDB6{~SP-LV4OFJoYfg zeoMYrH}2GvFvV@NwNa;vZLYCHQk%TtEBlNqLP3T#-}<=BkNz?)Wk+UF86L>b~f@ ztboeuw>8;hkXWhhji8-TNZ;uiW*!A@t=BMfJ*38?$rUQc1 zHl6QbmzJ;BWSx?K`t9sgVpsulhORRax{^Q~flrS%y}f+mftK+TT@49^{>8IaUHB}E2%n`^lv=Q{q|O<@6*3U-htBmB7S zB<`e+&fYf>=fQFuW2r}U+xiP=63AVTIH)K6xbw`$TIF;l*!wp6YCrM1-hNBT)1gvc?qzEdNa@Jp@2p$OLdxu5>@6diJ18DJ`>%ww%{YCse z@tb&_y3*J|d;da8G3SZ*MN{vZNYQ>&0oEZ^4p}|C1E!=;=b~8xndHaw&D@S^H4d8# z9pyu%%=)u}zVY;h${XUEirOM3`l#8vtc~GSl`(|Em!McyEL)nF-@7u|u@2vpd})YW7r|4C|)6GYM|rTGmLl>Ms;7IJRc>X%^me zQ0mI>Htm=42pt4Zyq3^dXS12J4SCf($lFTIX?MNjnggs5U1Y@!W{U1?Qq}ifPI}m$ zDCHDzwCs!wDS#E9ZJ_6%8%`v_>yn$fZx6m0PYu2xs1z1r=a-{CvickRJVO@`wEtV} z{hI8cj}}>kd)U~Uj{|=8N*BsMEriDTilwO#>Dl|lS{;}vBx6DEA-s23-yjAgqt-(B z0G2A;fZ%ep*(GHfx4e1vQqq^9y~W%-a~9<5t{L1$FurUbNx5@&z`b^piNc&kS#jRN z^Lnoi;Tq+`W2~p>yZD2gkb=j`45081#^6TDnBG^rU*JXLDYQ%_gp}0c$igUE3^eJ= zd5_ctw;L@PsylCoFQP(p+Sa4Rg!7tN?n1OZ1C3i9rwy*~4Pj9%<~?CXs8|HFTbaMe zHs$<;*R6zC!bl5hFxqh;)CrKje~ZX&O0+U~fAq?3q_pE;4}nV5bxLJ&JbGPpHjHZ9 z^-S%3J_ts;=atRv3CCNWl3abmt^QMGeQF19jIBNIv$LExNIeeg;a|5gpUYaxRgrHi zMXwtjgHgPFdP%VY6VORFCUIOgv@IBl7?g>f_ zO&jS${6*n}Rn0BON4;66m+>Z=egmD4d~x}d2HmcBgAwPz*<#~s_%z9#Ge}ZpJ_D>Z zvZ&ed18jPFXi@#Nz7sy|o&KP;?p#mB$d`kh9t=Y%QGJ86wBWU5X@M{V6#N`U2lR^p zWhrZ*nZcKJ&xpma`+UDCqo7@}F@sc9W2r$EjQh~xYsST6pydn=JOv>=GH0VDC*s{M zhI~wLxL^F*S8~U)RC7Rw2|iTzIioq&Yk6z%;Pob|#bLHCr2+wj8P0Y6#bQPnS=6nY z@cGndwndakhOVI_ww$_ayO%N{76vSQ%13qQ%uGgj_PfvkOoY#tptqxA)XbSAbCvv= zz&pv}`N!6MTOicHOp==qku(KB0m~1&E+h^9R)F@t80yt*$pURmvKg`#f|hB+-b(RF zz?Y*Bk|Mp|-8f+ENS9pCWM1sv6UDKvviQCUE9_g3fDpxbfh18klufe|8ehyG3#e=v zGPCCFEdK>tv|G)Muw2*bpf9?N<)yCD#)L$ zb!KqFAElrZw@0UlUZ+z>Okk%K}$$@mMPJ#keZ#i_gu zKD9@OMxdJ!LV*8f+7U0iq$;W)(vctFA{DCiW@XxV(OzTmrFb#+yiF$+a zdr1+-No(zp+%?%o%B~@t{SkYSB8N}8pCj;-tsFQRAKLZvn3L918Bm4pC|6`sEvoz5 zFbBTL>e65%b2#Uz3exW~$y<<;4X^lwku#YA?)P=K(x3u3-%=Llrc@Cqp=0Q2-@8~Z zn(sMK1veenkx1j|y)W2Y$=+{d?R$I8nNJ6~#UH~jx26d{9Sya)YazP+Tmx82`EXmwzdKa zvybt2pr46N7UJx#q^ZrChsslySL|0i$)TqT#-=fFJS4M;1U+Z#9cf>)}`3Xzc+*lXLvoLfm>qJoct3eV7nbJJdyOXy)r_%+Nz>{+@TI;jU!nZRWb7;-jsbEf)%Qli^bp z%VO+mX`I6(G>MGx_h$K)wybWC@*OuE%T8Wnt}=LiXDP8z<&WZjdLOC6kng+U7@el> z*GOd}Lnoc!olePk*Eh|zNvNE!>w6u0Q9bolm28#f{7fsmwF&xd0dXx0x(6q(jqT`+ z^-R0iqrT`&amgn?7a&&;^{@~FyS-8KZMKfGd9a|lI1%pFsm2a**zgL|v^jE^IJtA( ztK_vJJtH*?R99e=TzpiDSBmzVv2l!_5g#BgCREC z4cxSpH2mm*j-9Dk2 zIyqde+xW`UC3WhB`Uqe8Hu6?dq=?Ft40JMWV@RN5>df|*j@))wb9(F}7Aiz*5}$T& zyovvjB*Zzm%WxXXoXEA9aPLv0tk0ym zt?Bvh3+yZChO9xpNG~x+&g9eO7qADBm-A<)H6Hcq4RM)u%}t+E@-ib_BuDxx4VX&6 zv_qaA?OTY)+GsKhM$^xU=^Xlw+G^7kj)&zX9-S=?=%VDE;1*-Xw$D-bQa*H9NLCE> zGn%|Nq6j>lTi=UPgXixRQ}Y(hxR0zu)jsgV%WZu^dJ{rvp|hX!MC4>LKiaplT`wU` zAIFvEWL9|9a5~r>NpWoF>-p6zPgwc2b4ndsow#HIHyC~Z2%q_WTugAdC5f~;0b4XI z-uPZ3Od;H1LmOf|Y7?R*>2PwU2~b>5|J-(gg0UdBzWL+&yFBq?MT?q-+uKQfmO!-z z=lz+ZfzjS7=I6U%UGENA#dk-0TIvpy4Sj_JV{@&p5>2h9rl-^VnTTZV)bn{z)`ekp z&|SyYp`jt8baO!E@WK828da526_l(VN@87#K+UI34RoGF{^V4D1jy@wyNW_uUm1J~`Op3lVjjDIRsI;jYZ1WJm93D!3_aHmCIUF=#tUF}*fz98Es z-*QNnxZ6@ zzn}hQ1O}x@Z;sy{oXVFJqcgUE)^_5fql`MpPK=b)t5;Pq&yw?>n^=7iE*Wbr9S zAlh(}rUJo|5!ajMkZ##TG@k1vfW*dhU{ZvpLD@A|_Vo>B1X??$~2&$}eulO^+t{w=9 zlAfYplCW%z7Br!_BmS=V^nr?wikU^rPl_R6_^=hT8oxd*IF&uJYwA2jb+QMjZQ`7~ z4!?1QX0>M9eZv5FRv1XpITc3~4ovTZ0_v8PlrGmq7jEg5VgQ)U@)OWkUmY&tvX9B> zHHy6lNvljIo;=Q;SKYY-7fce!3PBtwsZ6PvOzROm*HpplbmXB<8`8j_0fJ?irnoEc zyC}5TqD@T!*atR6hAHDkl~|03U~VL+m`?=KY{qBwPLoWL^XnWRK;xq|eL2hF3GvE< z@|%V-0H+!Wx5&&U;lF>cE zB}-bqL2x1G+_mGD&nM4nzMU7a;f#M@|Cvzq#G)8WP|eUf_vxSfpI&Xn;NPCKc{>2r}94sYYPw;~=-^(p2j1~SI&Cxv>wrQeNRU*4cZ zsWoQ#RRTsavHK$04sWNqK`!jql4S17kW`uv z$!pHng)gA2?PflxFl;tNH~FfDX=@G*75$_T;;)Dj5Z}gP_jZn>h8F#ePvvs}wTDny z6`f}!nJ-_Wcds)g@?9Ue3An;IXv%%or~zgK@x)wvo<=nAxXyek#F&gD$^8a4{5W?9 zi9J=QE1=mfirgz1q@QWAO8Ua3*dt6GeAMnLLBQ|4AwZd>935oP@!ouIfvPw&oZPA?`v zj?|i)?`)ffMysf=MqBK7?L<7Tc?d$%J+S9pzB_e2&PiaY`d@>=bF;Y9754Sj>|ZgZZv#O4CoHuxuB0T>2bco|Ta8(8PKyM#IVs}@@P%rce| zNz|NUhiPcji2{z3v%rCCd1QyvR>~e@zQ2(c0tH-S(VLrn=c=05*MVELCR>++*-@>}ig3^A z5|GB@j&~ys8!N)GkA`~qwVc1=8CV?6n^Unfdwu+#d*9Wf{-Wb1K^I=Nut0N)KDU&I z8j0NT;vZg4Ru4$l2H~L=kzZ}}j<+*n>q!QRnKQ~Wn@HBfx($dSgW_Fxon(G!Qgr3vt07CrR&HFX6WzGXPQ3 zYXsejh)s)2aG3I)YJDg6R6@~<9k_YnZ zYl(C2JHCmn;-?imc+Z4m1iUtBoyB??G-%|~fgKnJSNbg1z(TG?E}4dJ zOQ1p&PerY;&&?-PuAR7RNddx}p_$K;LnTU`pBY>D=xokG8_G1xY{(c7bshzX{k{w! z0%yK#@j6x>1hWZ@oQ$lVPMq%Qi!iSpCz<3#Qo+EYsMy?WV1BObv5HFGO=fsbuTq_> z{n9`lAVayYQxwv4cTpHXi~Qnmgf*V%K*P&z#)M&bo4{Z_tuXuiIw*#gAQK`-no)sSF9L?9vgHHAWNRN8lJTXO2|x%7_qr&I(c1VpPgH7XzWmPTGzQLAazLHC;y z404*wVPX>CwIdq!&2$+rt+6Ar_~~Hqif9^KK+iV{=OeD@o5wLuV)?eD2Fi3tF9TAm0gNbL;}2QuNNSc0AcfJT1XZb+b`h z+gBA%xw&Xo(T;WS4$i9vQI7g!9}awj(?AuuEWif$H><8LTA0aK3M{3r;}miqw!+M} zo!B1XZQQHuB%y;}gguV2o!@EG9rXq~DDNivR&~$p-hvI9C3B9i_Hi?|9N1vGQv>6? z?|9NeboLcXxE_mNhhJi^QNEG%8e8#Lt(jjM@y))7xeN@JI>>2$Zq8U6{;os1*Dw+| z%{&$eL$L_Fh3B=DW_y_$XsN|zXJrnp*gbU1r_lU3eGaXj(~GS^$N*BEpLO)r%7U~e zucGT18e~+)J5|)M=|d^VAWg@ z>K+;T+50(Xd%({z4O4hqgwhpvx90}j$!qynF4ROK7%rDlT<`b zqt5Wu=xBa|t=+7#kgl^g?9+3m?N2*4wsH*_K^cYjv`^l}Zbo!4!X7fpmc%xUpbdqP zC~uy$hfG)C#DKM|WCApPJL_t9=SHwo1gV37uHb~i_24P(olBWZs|G88)F%#bdc9wq z4!7y6kUKC-z?grzYG_`3&5(DHK4-JZRahqMWgk%gHY;+4Iphyl(vo)pc3tK{N`BKQ z$nckKN^!pJm~6!oo;dk;UdxzAM>bJP$9eapQp#W1mSxp{q=}ris zU#3LzW{pWJuTBkR7rqDJhJdkyJEM!i_(5Nse|)V+c9Yl5?J`D<14f6ctb6uZaDoiD zSR2_{Fm|`N6Or4otw&YAc+2U2iZ{edL z$W+|y6p#zaGWM=_X4}E=dd=EoJ&#$on;vtmw7b7p2n_I8sp?9sw+Gc+*`PK&(YR0R z2hr9`RDT}R8O9Hl&J$Yb~B(<|G0zHL{eE!N)M zKTl9a;g$8WdR~;8DpFO;*0@{;qK&`q)x!Fs1ESg>UCxk0CBIi+JIJK1G&*hs+r}8@ zLD!MqV$0Zkf*&=Z+o@NtVqSWg=LW=F&z<4ac_(qk#lC4E@Ib2Z)v8E??AnA%IiN@@ zlM(AbYX*q_p7|qV(Bg-kKmNEc9AILKXYaf=sJDDvCL*DiXwY=2Vi`N~} z&nV_;O){DZ{1Cyw!EaFJ74NkP0OI;0aiO>jl|FZXaNQm;@Ya@>cf>+6TopgvPFi99 zZMrkLGm)Wh7_T*z^0hc!REt;nw<({cgj>*Btv4araUn0M#WG_IwdP-+$Bv-Q&YtPE zk8DMr{}}Z14z2D2bl2~A2g;@)$QT~$6mgypqKvm^RjRqmsgrm^AFcj9#jUNSRYYx< zS(!2W-m#8^a+8wer8Mk!2J*Jq_f*daJ9?Wv7T89tj2AihNVze z1>xqde@|V!82=uqKQGm6x#Hta?~;I+p1SVrreDRxT~V9fQklnK>zFWXZ|4N)hqlseYo|a^U}f- z($`GH^boT`s@k_8BLSm|&()!%Qo{{pdhkx(U}PLIXsoTvHzU(1XxK8t2mnLFQG>&| z%Oq<1)+N2gS-I6A5tV^VZk-1jMUGU9$;v0_7BBXFmNw_VXU>Nmau%r6@i5dy_vYMx4xc1I$A&qk>#D zMY|HLs$`mcV9<7Ncy-PAi&#HAU_}dLpN%A0=V!_N06EdNOF0#tY3rK4pA}-Ygol+L zFd8nu`JVFCDskry@43u<6IRLW;7^zCoXfQD^%xkIoPPiCQQVm`H?&xp7GD$ss!L~n z@B92|VJ4vNOS%dj?6^as4o|;h#7-4I?l`boX*Q<=`DXdy@yUn`1oRHZ>!j#wtO%%Q zG)4{p!81KQ-PqXJo6PEVJE=6nJICaR>@(uoT-s5|6S%AkdAwcy`r(o5Df3a+qd z6Ez;roN;~hvz%}R)L4zT(ob*pWhmF~yu+EEU~N~uHVM1=1-f(NTbF^tSZx1+eftIj z{cy3{tnIqFvE%3cod`r}`SYG03ln9f2X_CRNW$3o9eV|d!U7Q8utd91r#Fo z?m9b8Jcmn^d4<5<=48UYAJ{tC&2oLrjZ+O`ZlvVyU@f)rU+nYxHtk=$x*Oz)>Akr@ zvH5e`fSdgz;AezBwkF9OOkk+hUM(in9fz2n)EPzh7tXGEBWPcL0ahX(7?01$$mk8( z$jv>@4#RVCa$;HmCxT~kkSo^?ZGLmR!pIFTOk>a2wmxisGM*XpNwG>Zh={at8DlX! z>a2OaIz>g*->2mQGANp61&ZRl-zx*;7q?}6!FHhMAPL{>A$Bu9G5^B{K4{M@^xd(= zMQiI;or<%098z-qUg%#hG2q)+Gxv3(%I?s?_Z!dYXQU#9EpFCSYSCAG5H(O3Nl5{4 zj|}|HfUxTSE;(-@(bC*(&Yh|vFJIai!lMsSA8C%4_wEh(0|LAG`4uh5plc}8BvxZ6 z|1-?=U`dkOvIuqfNXG+$5KHmTlyNESVhs$I3+by7VgV>aqRuv`u zK_^flMtD1cXgb|(vCla!CF%qVJgP8NPRTm?FFOGOb^^Md+$ObtS{|=Re8eP2{7V6k z{UD>$;|k(VBLUYt1^Lo)Z5o`^uh$7k7CKz<@NW~ovr>&&ka?2RKq^4+Pdx9Jo4>{B zSS&V)A(=QyKHbZ13aEqwBBJWZy{yXp>!LLWxB|&t?qLf>n!EwVev?8`gs!U)kOx9W>Xd%yRsk@z{PkMnn4U(d)d9ZjNRQ=mnh5QQ5 zHmm2kq2Vu5!B1`HdXx(SmWBM0olBk6<%-6VJEcoGVfxy>iC%FLC$yX&Hjgj$x%}#u zF2+|Xf(flYU`=cHvI)|KPh26WZ#@rHEu@(u% zji1GHWE5%4iJThI$}M3N5U$WXI}_YwSgEMTSGYj z%i%3uFl?6Y{zmHEh+2BJ65PtxABGS^k)l~heXPd`!9>`u^^()_NAoioEtRzPE}+@n zYNJ#>=&JBX|6=9b4^x_QC2n(H#g?QGZgxK&o#{4@N@8Cu7(*iIofOO}-V9`iFnKB| z#G2%0M=1(PfQ?fsDvXD+HkFQMy@N!+(Bb#>TANXn8y8HdH_NO2New8<+`oU1?n zYmKGs;afU&rcuu~2Q65!ODk)dPMxvQ3H--c#SFiB>B$JPHjqbZb8E<0u#mO`!s%0} z@}1b|MD_vcQN>bejo3f*bkn9ebZXfkqLZN(4zuY@w2RfuW0qtKvCVT4^Tm~!I)ZF1 ztu}^?jd-?g-6~ZXy~Mmp{_igLc?YLa2K`TB{U~mzVdeQf2tzs$7J@`l_P9nbC4+w4 zYqwVVZq|8eaT2k&N0%lpGs;$VGh?emKN8^qimtOghc(p2Y>m_?IO9LQ7WyQ zsCiVcea$dQ)gMq@WrUL)Tb8=o4Oo_>IUk;VYrZF}v6O;baM=X9pCDV+7;CAQn0zTq zg13L@DiSHb9BGRXHF)e0f%oV$U9zxNP|hKM&2 zNHw!aMLqF}z}a{PdfS;V+<|Vyyr)Vb9gvp5T~jC&e44|cvrJ#LfFt5wyaY~ajN6-1 zM6h_fs6`mJ)p`fcU~FL-H@NepnjFk%@GOYap+7}6b!c+v@$$=|FVLQE3y=HFne0|m zuJ&hjCbzU>b*kLnbiFM^%wEAL`A%gkosNn+U8#~^uw>5%!MS^xAoqMrv&Is0*0*gl z@ugn{aymnW)vFTJmU!ViTe@8A`M56#JI0;5pH;yRo-47)*c5Z@{SKU^`wm6t2JLIZ zCj_rmtzV^uE{`i9s0U!SY&mKO<(c=>CZ$du8c=aiW z#}_`C^BjpaYgO>^M^UyU%w2;oiz%CV%wB7Z%S&nU`eQIlF0kut0xc8TpqJ;Fu3#NF zaz%NW*|Zuo8pfq4=A*S5NU*srVpbJ)+pI#qB{A`nGXr1Zm7=~l=8p-jp-VSJ6qAbJ zNm}*JR~aAF$lF^=bekg(c@N_qC0|YJ>IW^5f92#Yy}g*)&DpcaMs?q<&L_8 zUhgKeso>GavWH(YV{12U)cfs&gfk43OzsbG)qG6>bf?U%L7hrUl-(KOEXcG?OdDND zQwB{Y%*bLtM@<4`rI*!kfwv;uoHQ}fvS>J?uOzbYNdTcUVJItx2_$Hy&H}qZ3l*{x z6d)AdEz#Rh>T0?-HOj6kAS^8CEJp9S`-RJNRYNMey-fu z_wZ$}j41769ILm#Aq!(>L|MnLKODY5x_DblX6H`Oq+DlKK;+y?Z{8XRhM9N%h(&x{7JG(WL&(G$!(B(5L&d~LTziuxnp9aJoo3d=8It8 zXB`6QTZ$e!dVft?n-Pj_#^Tw%#uZ{P6E7EByHOQg(cI-+NuFo3LHt9-xxL}k%Ovy3lv}LYm}>TxE!v)(vGfb~fq! z+)&v48lc0?<1(!i{CkT=zL^x?-7>HU z>iW&LpWM`?56EFvOJnclyZssXc)M;!q2dd!cj)tpU0;M8qFQ+D)yd`xBKJZA)w1Iy zx?l|Ws6_4sl{p!tOQ|0jIcPwI1aCgcZk)IvTFra(uV1o>J>glkN#HhfSQBs`z{c|N&W1Hnwy=JyOBC4>3V#2`C zV`RDFm&sDZvABx0&C2KNt?Le0n(=Q}KpADKxp4+|E-eT1FAvJA9u;S7MNMlmNR6RK z?``_sB)2~8lpYNdn|Df+vlXebHOh7k5r8q z@^8e!^=xDX_}yqJQgRAlpr@4;_&&KXVOscm1VO#wgPdk>O2S$9$TZ7A^AK_Yb9`1E zBKHK^K6A`An5EdPn^UX{nVDEQ}ET+MkPIYN2N-i6#JOPy7{1eA67E=v)%V& z9)s8y>)8F&IyT@$=HU2dEc+t)c2)XU_e@P|cSEIfH;Av+&{+Idu%aO8^qGO|cv6!Mlzkb^g;0;1NuyIl$ zJiLpzzqG7hg)R$v9+AFwD+A@?!wC?J-wr7Yj1R%G0LgwfbWa|Zaec)tFY)m+bEzMGCY7a2;l;VSq0^2*c?T`GqRQ$61E?jOa0ac{> zQwuL}-VgZ4!cSL+m`F!<7}9E-K%swI`Pll+)yf&ez#8}AZ%98;WWW{BW)~`~>uZK3 zY5`wy{P4+hr9OKk6IsXPe_QW~PpvB|;S-P1?x!-S^?^Wj<<{dTkl73GkFA@`Si>ex zIx~|cDR#}5C7lJ!tZr7_%j;-xma%>+z0pSCSf+Gt@K~H5JsbH%4Mk6DRW2_9kGfOC zW;L2ZV*(!RfKLaHT?pyAC$Vx8)|hzB-aOWSX@EU0x$0r2g_@e&C8k(m_bxGaSvY4y z{X0yLJGMt)bp)9@(S}+93*Y&|U~6&U zQa`@iK%v2yCXsMs$$#cS4O}*8Ut3j8W^z2C{-NXOb>7Ux6}`sJY^#X;goYA1vNGqf zt@5KhkoLl#D=##X05VJd;NUgIIN4+OqYeMJsGsX&7`x%*6mBMd`d z8TP)!Q*CCq{vH1l#DlLhyO{v|!m?OQ>qg!t=iU)pL1F`TF2Oe6=-QfAOz9bI%$1X9 zaPHeke!LmgD*s5JW^5y@aJ114Bi$P&0JpbDlA%x#hEoy@rh8%;#y%TZEbBkN3cOaO zi-N2$*Df+o6_AGt=#`i)rcnH$MfRBeVKcV0?>UdD-NwScdyt0cDJCvm2XQ~MOB>WY z=MVm)3PxZ^t!FD`V!=M>E>wDvGXzMZZ%W)&45HYMTPghxvWpR!_%hjPDbZGWmM zmkq*m^Y+su`VOiDg{t0{y0nkgN!qH(S-bM14gk{@r4IalZLo84_*SVlVyDrK$Jf?P zLHDl>i#rL}eS4iJwl#iBsuL&3+fMrfw)-)qMg(!IDdU&n4X@6V>)?E3{_rJqKGHMR ztWvvwtbDop5CEY>~p_|d4^`eSK z%oY;DpU>$ULhi@DVEQ1dHd-z#J0@ z-9imwBeiye``QB**z%xxhPj=`j~KW0s)7Y>p*Z0XJ4Xt=k*pW;-J-x^bMcoK5Dad@Pe80+mN9!G3PvYhE_?%y%yHz!{7`nI@2H)GK42rZ7Pjea# zmfQQQV0qdLFPcG%m9~S>z%EixlM1?GcyhDoNViyAA_@G7m=~jx1(e!wq&>JlD{|wK zvd^+`ILc19&&vF`$@s&cQKF=&O-f;3Rhq*I)D#`>jD{4b2h?pag+``=Ro$bQ8%fO! z4}8fWfBTNb(ZUkpr3Ci!Jcg65xcY}rf+RjScIc3%bZq-S4SL`PZ!s6*$#b^Nku+>< z4&1z#Z@6!mLyI*9v!*0|KapE9WM%rQ7pj%`AY%6t7-;C8x&LFl4QTe-n~teI<*u>1(-__N8nn+9XxD9MH%a^9{X$x|!6B7@g)5?wH`u zB8Zv9hF3jCpt4+A1!bAO-{~dc!=uS_;%bA}-(cJmZZWA(`lC4&XyeR$vhzxI(j^vO zPU}{z-I_(YJm*XUG%v%hf=SlpGD)F5jdu4kVb}lNJ^k_-NEWst5y&f z*03{bK_s7H zbAU|`5#4@0D>Y*IKi7(=21A5NIv|p;(0^~!4=07c!973wcmER;{LfKP>`w=vj}L!V zutZ2*nd-3b^h6|})_(uMdWN-!a}e(%9)X)DnRJyDcit|}{TgQy0VGnC zP3~5od=#>NJ9CaJ2Q}fZJWB}?+Z zz^vSkV*6Wj6?W)CqiQWZYwz&(z?6fsU*GSCKNl$c$UaP`#=WmZ$LM4^OwD&(pT&DJ zKytT*v2Ons-Tey0nBhqy;T3R6BG@%(`EBbNF$;UMjVcrWzRz?i-hYr~S|&r!z-`Zz zHcdg{XeJ3Zv?CKG*o5EfpsP5c0r}dlr=)V(0tlpj+d!V-Hne|YsKq47sVIr(Pw<`y z)NKYIn_dV0{(bP|)54x+;;Ia1j*Eln8nC3hy}Cy+OGyLzEO~JcYFylA1O^PngfMPP z1IATwq{Ud7S_pup@tU||mWC7F3I^VLSW}#Mu!KjS6m0EV0dOb4K8xOAb-e$>KZ|(V zm*4G>s`BvrmIlS|$bLd#^68=F`L5>5Lp}mqwNN zm>2+C4Ykx)i0fQ;#l#kM($g38MYi2@vK|Z$4Mp>Z*)GctYbQoWNBh(h@ad#*P@90* zOJEj?cs<}xyDbb*K0yp6(Vigs)(-r>N{xi;)T|DGm%mum={eZhJ#G+jcU&CCT*Lq2Xz-?F!{E^Y)byte8?6^V)ESCL-Ds84}^`oa+} zGK&=^Rc)zVui%Fki!GMF>f%ap8;Ic^%o6)9aM~`XqT}G%#Zr-o#M%=Kn1%pNI`>+! z0_Zm(KpO@y*DxG4$Vq?r(7^U3{Yy>89NRfTz(Eoi?C`KK_)YasdlKR`?iOGlI3mV2 z{EYk45UUy1753RV`3L=guPDeb&Y`k3PXnNa1R3Ge4oq3>7nSz`s1sz@Fripn+$G+$ zD$!R8jEwA;5?A%S+mTnc>2Cv@&Dn+=qAZNrr>T ze+x+9Nk4tEarw5jLrz|+wu+&WY;glGxG7^+iBG$bS@3+xaN_$ww&YfY6kvP0SZzxQ zAKNGn5z+s>zmQfy3}1iwn2CvLOpLk#;7O(jHf5+V;%p#F%c(oWHO9QL8O%3E@bW_* z@yK5-4g7!F`|_wJudZJ!R%=mdMZtnVTNM-;N|`~x)}jIi6v8~oBxAx15(r4CA|j-U zfIk@1VP=9|Pdv^Hhrs%2dZAvV&b$VO3qMkN(dF^BRBolW?TGSVj7E)vX` zC9-zjS37Rr=ynovJKoe0R9(1eX&2BZI`90{)LDD6II~+!sP9H5zM#Q(>L2U4&G%o( zpp4IQp(CzX%XbtTj)P}a%ip%fVu0rSnc@k0>=p{H&h+H@&fRwCyT$OUJSN=`hfR=^ zygat21=^MQ)T-gMt@B*qa`BW(T8zI?acob9_uFEkqeMhc@#%zsS%9KI?GV3%t~!ME zMs=BI1t+w{c^Q>z6!}gcz z)OSD2mAn(HvgupPE2wgdxp_xkCJ_~=o25CLs_HKOpUj=QIP9}D-Qhg|y>y(_>^|fb zdBcNfnBtWUT|iEXsIii^W~t^W>s%yBY5z)mngsWm13%4%$;NtWe(3{FQ9b>{Od!1HfO(&xp3P->%5Jg zjyy1wFi&7T9CQszhUD&9t2vJU{P#nzz~Tm_1ixpCcB0P=sn=142^X&1k!XE!_vbk~ z*Rj-Ci1geI!FzrfzsUSzC*Gp`QXNL4*RwY(-_cA{f)#t=k0V@ku*7F>#=&`QrVs=Ye@rIcazIQ`oT)_UR2vVpEV$#OU zC+{f#)jZd!-eoU{>wsd5AMZUGr!YO$kFoDkHv`Gm4g?UXToRCEcAn5tb+gS2G3$}k z)knb!{-$9S6JRp}L`amv!KkN=E(M*(XT}t?ToEhEU+V(a)~UOUhEr05tn;XlraSi{ z5ojqFdr7Lho2Sr5#YZQCEq({?gMCI?ZC1~++g`qk^&`o^w{=ugtQsES3OyQJ<=ml| zT(OqPUy&Tpx3GFeS2yG36&sL!l;tREjg9a5njh^x3^IRP3T zk@uyH0j7ZZnB6pqoH}cFePsISLU9Sk#;;7@xjcz3k2BG+QN#LAOs2(RpmA8a`xl`B zM{H6W3tzm1m`KX}SYTO>g7wMSio|YfNNGW0+skxM`beUZj81pgN=x(MjGJkGao_S* zZcq1gUgyLO!i#>Lz$>cnV&M;aR;G#?Nwz>a9L6eNFJ&p7QqA_f2BsW%D6Qk?|Fl?6 zA;UhKXFB|^8RXn~LP$L&eR}g(HAC4UjAIE%lZ$&gOD<`-ebKB0xJJFl@E9q-tK+{# zbMr_D-ZeMP&_8BT(fs_IwnndSJikJjjUJakYH5_F^HF|Dnp`<;`iBjW8;MieJbmhe zCp~TbZmB3cOC7CjxcW-nKi#=JCg-JHBqcD1d^tF4ezP~cz~T^wOV8kkGOe8HPDfO} zCPW_QoZ%KkGO+?0Auv~rX-w6Oi1ceGT<{i>5Fy6MmQHO>-5n*oPCh*EuZee?NO`6fEw^JcbjI2$l3xgB^AJeXd{%^{%mEYS zb8ZDu8=%h;d;mw>D9>py%Lz;WF)!>OX!e$&E>)v_7WFeUPR_}Yoaq%+n%ice+9fRc zl{Ui(q`b!Z#rqX$c82yYnrT0aQ!2Pg?;;$obne7qCD6Qr5TW7-zOk!7%3K83v1FOJ zEA=XA&nqCd*lS&Ul^#_0IyAwHs<1d zjLMPEc0+c8X~|<{%c48Q*nJ?&zkzueWIXe4Oi!ocomDllpNU)hUfnE%!DS2n6Y{3y z_v!g-vWf!4+lBe=?N}mRz}V<^7_l_&;$LXBA^$6`5mJYc*~AaObdTAoST* z$gr!H*$t7=gE-$A;8fp?o~4wzlJX#l3OM)?htH>a0_5r~c3%hwVN+pxaeMX1d0!?{-634lcru^}%y1^tbJ9tp9&VHZ`ta|9?qK-1=c9 zCb?-0nqpiIWq%Gli16($z??+)Yjas1SkB*ftsMGjdfrkHYitK8i4UEkxCadPjO|AdX@Tqxg=VN{m)vGF{GrQP{2`)o&T1*uchmmN|+7 ztrWKq=S*W)H6f~YT7+d2OJ4!YUT^nLra!E=3RwDD#JmJ%oMTYqv#Mnt{64`~v1-jB zT&U>g1IWw@!MOal)Ay(yUmlKK+KWuMbI_Q&xW8WHGC`CmSfdo&6(^DzjbAbIeX-C( zsq}a6N2g{6=WScaKT5Le(swlNt*Q`6$6tA^*qa=^H8W=A+1=?Fw9b(7C@gNGzIo;^ zcS|Oczv3B~LH(Cz08pr;g>#U~iY*p{cC*ubaJ(x+wq|2Y&O?P>r-!9fuMTEI z+Er#+l`eN=`{mIqF5XLpZf8zMxESBo`I+GR=sZf5sq6_4a=web zeG9mm<(f93xjiH%IMX}CLiLRr{+znGJSxlY0B71$Lh-L=#m39`WVR6Zffc0tzVZ}H z17SjO{_JHg%yZokJnnm?xo`*LHhKLW;LzaGOqq1h^<^HBq{oP^=+S~p$!krhkbw5v zsuqgd$RrrMI8?`$9^+-PyL+68lREz zFhkT2$iNWmsbl##ssRWRf)=V*U2a$&LIV^_Nk&EnsZF0Fd;|A(MMZl44fY&iLBT`- zR;9A21!lHoH=6HcDN^dXq>9;hHdfH!x5Z-ju%ue9!JY8CXntBWO7lTVG#b zE|GL0@s^XEueWRjgE-M+fE*RY`kc+`;NWt;8T0CkJ&nTIZJPz*!WA~l_^pN~8rQ0W zmoNCM*{Ap+mXggE7*S7HAFv@Ou21L>ZscLDyn4^-RoFlOTGxGTbWN)y1>#U|vz6bchS;t5yJx*zJ?lwkZA$g#YXd6|us1$7NiwkCgka(rzTi?=8FT78G=@ zT|rp4+Rpg-E3g<5E-^|Z%jE*4lFxGDNXIi@!b)-we%MLShTR>bN6@_k* zklwx>YOAyT6$W~-3&@4QvY}vxWLf_bjol(R(Vevvk3aY8uZ022H+Ewxy7z?ySi{ID zwY3)B@EiF8IQQkSIAyic^{{6TzQ{cu01xxyXJ2T#2aq0ISSZYFqNZ|7Z%!r18-aL8 z%Pk*j$R+0bgP>rfBye8U40)f&PaDL3t?&?@Uic_o-^%s^XeS5|N6*T)C++A4XFMJ* zt(y;@bpAHIP}#}4pkZ&fle1!*_T<$$5TSL!0lfr%Q84RkCGc@BfSvH5o*!WH_>+E4 zZxk8uC^a|CE?U*achTo4-jjN{r?}CIUbN8UuXU5oMoKj|Txlpw2R>$bMXZDPB0;&-&_XaQrWX`}{g$HBe8)xIqmZ=? z^BBeM#@ty(g~o7)L+Rh2axL>d?M${$=gouz%&^pnAvvoxEElpPN>76~@FH1|jlm{I zhM|#0-+O{t_>;e!{f3X=qZcA5d5p!`gAANYBWGf_20gV}gY~0zZs9DDPsc(DXX4#_ zX!o86^*%)`wj5HWuB=M48cUqhMS@*wBya$9eH+&QuGP5A)UgF>`}5%zvYnz@TzSu* zF+pcz{T|TWOcbEYp)s0DD!4j`+rqlIytaj#7t8N(aeldikqT_aNGaizi2#8Qc6PNu zJUeSLikiZ)u5I>lVr_#bKI*{=*39Ct?9E9GwjP>YZ@pzi%6*c>k25iyc!r<0RVzr8B#)IFS|l2+ z59Ydr5s!{NLCAyJ%xXX%x~wnj6DgH6R3xN*=wVvjdfJIc_cOY(u-G$!7F`7Ti~u&^ z+O`?TGUb=KbU~}-#j+mtx<~tTL$-!t1nba>1%8d-_v=N9(_8=Ie=bSVaiQ|vG($?| zIxf#_ibU5^cHSf~sa$H`prK+1LVld{>vgpb0Y=W-IVQ_BG)AE_%;LEH2GnrB+tR{Q zooofa>r8N$sBWnzSL%Xz4lpcadxUO@du<}cU1{3gEh4rZZ!>IfAo&9%-Efa?nB~qq zX@k|OF5d9X{g_4!tDsbgS4l0XC5$k)qkFUzenZv09C=uY*0D9qSqRz07B{&pd)DY_ zJc@a(F_5qRHnCQVmPJB4A+0tG>#d6B_wvh|`u^l$R^|u8ndE2a8G46CAstd&CC&(D z4Z5|kPa-7!?mf9$-PwKGv!H1`evfXcHRVB4{RCb=-vhr#cbRisVz7_uND;w8HpF;( z)^)3%40&u!5Au`Deji?0iz(?)Q(GSpoFM2aHvEg2l0Ampj_D91)jawD!U~A5Hnq)t zuq>#;-N*O+OGaLGk768DWXg2d=XE^Z9m!&71icx*Qh)>fy@dq2Y)3kdq{}0-3Ts96 zY$cw7rm6mOryMR26JfHk7ynQozj+f^ZsbsO4+#ZAz=z4m;FC_E6`2FnbhH0qx;97$ z$|$r(-&-zVQr&02i>!5K8F9`x&oigG0%y6dpezGi_?j*0O>E#Eb(zVJtxav)y1xSym{5sR7Avn zc_VF@@(}S_HpA|u!DD66=hP^l?mA;AGUYJr1KhSFEFXiM z`8~QaPEXM2<3d72alzk0>_oP=DgZSCCKTuL0qI{ciMl-`VXVJxXFxYsa*42$HGMHd zPO-3wQgBzrT>WH$Ud(b?t(MTqLr#HEo!N|glW+YnUrD|u*e3kc7fe$ueFbhmrWy)Z zxDsUbXdxUYqP-i%TD+v!+bTj~yq{>>V(~k&-buGttqNHqrt-pF0=jC%7AnTE);AI2 zAd`Ja<0fT=QoG4Gg(1su*!k4o;;`)GM%T~=V2w`lJY%&KI3BT3tqHj@(A9MxVl@_F z%`AwFU!v*`rV(s3PaA7?6y9UVnGIG&2BW8cJvy>!|T-R{xO}DWb8qnP#413~S~rhV9|C z=GJU2vJYAYid)@@^}s8GTHSs^Kodj(*MMqmw5eKFJtFn*#z;W}Ji4}s?>6m*-;vLV zbMDS{H{lqj{0kK$gN>ph`%_#th!;=`Ya@fP3zQKAu2xGh`R0sW$qQ;zAUx?Pgyv0* z-ifNJ#~wbeAR2Nb!O`lf#e(9jA=o)xOr*SBPQmoI_s^~6vl?ED`c`{%g~WG@Wkvl* z>@;;0O#fMF%1Br`!nZAZv$R^g@znV?Xo7OdLj~-{`HtNfLQP?PgATZC=9~EqI#Yq8 z!JhzAG9 zUKUZi99zvQCsvu?sGR}Rff#K-5QjrLurAw+(s3`R{I3(j`dL`MU(8S?g+FMcxzmN< z$`llV$#$5pq&pLm)ka?S|B6w6TU0xJ(E7MPm>N0PQd915J98Mp-^OY?2r68j_~MKqj}X(Q2PgC5$C z@5Xe9EU0EGh)iB`tqJxU$iN5m5G0(If|rRR6?xd!CeQs>11gG}1k9Vz8|NLjFGkjI z048GIxAEU{B(-|<;bT!?X}-43aHP?QHulR;P9XPX3mG$H5_2dWDy?1V7|Av1Mu{J+ z)P1Nj9a{sK-I58g>lGe zhKFXSU|N>q+e=8MZRjZUt1d#vp8MyU24BC7PNv^MZJzVXGX^^o)ldtJU-sX}Z|hbg zk(f7Qs2hravE(phxXDmOFRK4a6mvOhXfw_oz1iNOD8zdhGi0iekV|8SURFW@_EXl6 z6-*mirzaA(H;9i}enO$VpONSWHS4yziuTNMWB3Dz*04_#f%zu4yKHEg|0hqCbE`g}gvyljw@wkd)Y8?CL4 zx9*$IP%|8YH7NNQWv@6>iAhn}KV2>&wUrTMEzQGs^U~=nuK0EG*Y2ZS2Q- zCVV?+!P4GXb9dF5>n({YYl6B$S?cFM!Nxv8N!XhHh%HbSk4WUO`Zr6fe*OJI5u~kPJApf}&SboIg;NTJ^M~Zd{cxYYG8o(nrjN>i9Q0X1toM_Q= zUv=f4QRQbK4Y8N-$d?iO%*Z~q1U_pIy`E=JIZ@@VPoSY4bYbsbI=0$?7V4+7jIV)O zCkaEV3>Td68u@*8h^r_J(Vpl|o>n~)53GrlvB-}esi(8jIr}VUF15G7T&i)C8yV_@ z_O$oOzpUxO>Dg4Gq$5L3A!QA8(;_IdO5J~@ zW^Q4?pDBn841lS(FOdUtl-e&$ULjiF-E{@Gl{{CWIg!v|U ziR@W2 zAGdaB+!rVs7{%9k)3_z^&`q`}eLE>+VX}aK35$*WuOeW!YGFM$1~E!uW+MaV4~2y+ zAIFzI0bfXIGN2WV|Ku)Sw8;(6&iSu|?ji@FQGX`n(?Y5i>ha@(iTQzft1eHMa%V&h`Wn1Oru^eqk0G8`P8m(7W>PO7KdZvxI=NKiQw*!v%8JLCuZUkf~1ZA z{uJI5&*}k#-R}Dz#$g-RL)}Sc%M4mbJr?pm{cg;K@dG0-fatRu{5E82#W7JONdfzd z;FmR!9#iKw05XACh4D4?l6+;~KI{U3*gCRJnKi3PHKQw}lobRiCN*;>p4&m@*(%eg z_id4{w1>*#D?Izh$a(J+MqS(kgzsVlKYnb^-Ct1u2=QNe0=K>zVFOLSn1hVAv1ql4 z6jDf?gU%`6X@~ggjr?e@u&YOiDWBr{A75zX!i+DNB?o6sHy;#KXHG{^%C=^>c+S0l za{{$F%8y?w3#puRrIaG+MWoG^l9V!a{*bl$l(l!UErSKE2Q{xjML4d@C&q`p^rVC6 zcD02nITsw0u3875DIa+)C|x;Qs28-Po$cMO+;|Xlg~R{r{DEz^*sls5K--d6Dms`g zM3M!spULtoUX(gkL+{)M!8*u)p?;M~?HsVtY`b$%@C|6Tuw5R9Q`Z5=#)m~wG*)8Nwl;_&Nl2z;%j%}fBkrY8FH`<;`2&8%{|_FHDvGxt@gqgN@Lv# zv}nxxLA6Px1q{fiF}Xs;t2BSit>a`!?kMc6*zG=WMri5Ta1;a)YY+se98YGZan9D-n9Zzs{!79Y7e++2=g$Gc-scvS^lDJ_D9Z{x_!D)(k~pWiR?i5NqzUTM=Cx1^Nj-!GVjl|85|;WJs!zob z{oaSAAYX#!Li6FTa|?tS>S`df5phS}s=_AhYh6fiHbCCS#s~}${f+jRv4H?`LBaHa z`@lCb`=`PP+rDuxi zerXj1$Uh`U@)503+?9Q!pyE<`rIm_YnrYwFUu9&Tb@q!DcUx!6qw;r8=^?&jygI4HuAOq}l3m$K z_;ZWlw9Y>y$*+VPD?lZ}(l(;$oWQH4w1|iZIqxnrd6%;@64c`)eW)Ji@N6fLtF4`a z4%kHmZ3kTXRlEq!13;>Iql&O{Sl`_y;(qX*TZ;$-2lS_;I&(J#9Gz^YYS< za{f;9np)0hr{P7R1YSLL)|)YW&};-&EI9~@%I%!3@mi0LIpk!b8m~SU5l(NF^yso{ zakKbac00Q)V^I$WGmEnXjl6qPPic+ni9T`?P)#n*hITXD&`d+zV@`sjhhiLYuSkL#R*! zexZ6m;B19g{a$XguF}XJpeA0}`^dDW-=Bh1)YpwhX7?9)z%JhQg=K_SZ#wWPA*lw& zeTRY<-{Ttr4!Oq5V;;Dy9@KP-Pe~}?)d;X0v6x>M4IriB!DOxUhGScqVSJTau?PjP zWos-5TWE%yK$Ja6@N6>*I+^UB?4YaaH~RwF&sa8>fMp@;rnOw%^f%S3WjoFh<}$6u zv8`|3@RgVdJYprsXiGY8+V!E3_s`^l#8MX#5s|V6`d-~Q@dlJky2CY7i&mbfRK!ks zFwTc|?Y+q0m?&;^UjK`i^hMC(We(v%!9#*C@Z_Wi#3SGR%8gFgR97=hZU&jvE8Wnw z^~{wqhjHRdZd1`g__L`_9+^dcFa5lN~Ilur= zB#ITl6qE4Afejy~Xn>l();Bg073BGX<5I-7Mwnfy1R5SGQd74$im#& zGmFm%z(_K5=TjbCFM6E9%%3ygJ_6|(nMfZWAE027^UEe=?WjGvQ0sr~b0Ej-LG5%V ze$yTBY2JIwi!tZ_m!+W(CATcsa#e;K9j!(`Ru=hC{EEY@>f%!7#i#&y8k~>2sk{4; zaOJ@glX4r`Py*2O#+Ph!Q+eZ9y=146^D76#n@&fFlutJ}PC^fstz)_Nx@7|h$|Wg$ zU025V*|^G=;OKehEa4+HRE{cP*A5}tV&SVPo$3FwU3?X($K2qOOsC-D6qTq<`K0QN6R+OF}1tK>kLFS^4o<| zpdQ|~rF*gUO_}mnyQ=vH<5iy)fi%ML=2#hT+*-W|>pf^QRbf+K3ZsYwy!)Q}iSW(g zPzt;n5*2TSFuk9kj`JHR^p`jR14XX#-&^T}xP5yf43tMA@26*1Mk*%ApG0ih|k*w*zcy&EEe&wLfPF<~C*SEfhd+*+bkgSsSKMzh-vq?2{dC(YK z%G}GhU3n7iQMW(nMFhKK)#^h~M{xUFy&->5(7SF~aWAw8y{)c2)3aX;{bE+AB`)7Y z-NJj~iKEM6uN_Kx>2AHH9=Mf(uM5-yCHS^qozFzq8e|vTO&=fm)1-L*rrLjBl z#4YBf^0xiErb^z|^nb+(Hb$z`a3I57P{FNybE&1C$VB3)7Klnr3HpR~meWdtI<#M~KagK>hcxwa)WvGgWk_Kxdinl%b zTfv~x5Qif13FZ@ja8QInog0kTiZ$O06ZyF?(#UBY$-TO1knJ_CRD2};17&+K*&~`I z(2;8UQl8-VVUx*$a8RmaH-?yPoPwnHkRo6`o{ZD@;#p_}`eA1pHYoGEZ z%Q&Q5&Yjheb=thZk#c!cDfk&K>;twVI)8H59r~nNhJ1ywKR4A$ou{JpZ^DwgjpN_ diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index 6f0bf9c606..65b0660df7 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -49,56 +49,56 @@ To ensure that your Intune tenant has been flighted with the needed white glove ![AAD](images/wg03.png) -The tenant ID can be found under “Azure Active Directory” and then “Properties” (click the icon next to the ID to copy to the clipboard): +The tenant ID can be found under **Azure Active Directory** and then **Properties**. Click the icon next to the ID to copy to the clipboard.: ![AAD](images/wg04.png) -Note: Please use a non-critical tenant for this evaluation process. If you do not currently have a non-critical tenant, you can create a new Azure Active Directory tenant and then add an EMS trial license to it. +>[!NOTE] +>Please use a non-critical tenant for this evaluation process. If you do not currently have a non-critical tenant, you can create a new Azure Active Directory tenant and then add an EMS trial license to it. Two features will be enabled as part of the flighting process: -• Support for Windows Autopilot “White Glove.” This will enable devices performing “White Glove” processes to enroll in Intune, and will expose a new Autopilot profile setting that enables “White Glove” for any devices that have been assigned that profile. -• Support for tracking Intune Management Extensions activities (Win32 apps, PowerShell scripts) in the Enrollment Status Page (ESP). This is needed to ensure that all Win32 apps are installed before the “White Glove” process completes. +- Support for Windows Autopilot for white glove deployment This will enable devices performing white glove deployment processes to enroll in Intune, and will expose a new Autopilot profile setting that enables white glove deployment for any devices that have been assigned that profile. +- Support for tracking Intune Management Extensions activities (Win32 apps, PowerShell scripts) in the Enrollment Status Page (ESP). This is needed to ensure that all Win32 apps are installed before the white glove deployment process completes. -Once the flighting is complete, you will be able to enable Windows Autopilot “White Glove” in any Autopilot profile; all devices with that profile assigned will be able to leverage the “White Glove” process. +Once the flighting is complete, you will be able to enable Windows Autopilot for white glove deployment in any Autopilot profile; all devices with that profile assigned will be able to leverage the "white glove" process. -Note: To see the “White Glove” Autopilot profile setting, use this URL to access the Intune portal: -https://portal.azure.com/?microsoft_intune_enrollment_enableWhiteGlove=true -This is a temporary requirement. +>[!TIP] +>To see the “White Glove” Autopilot profile setting, use this URL to access the Intune portal: https://portal.azure.com/?microsoft_intune_enrollment_enableWhiteGlove=true. This is a temporary requirement. ![OOBE](images/wg05.png) -The Windows Autopilot “White Glove” pre-provisioning process will apply all device-targeted policies from Intune. That includes certificates, security templates, settings, apps, and more – anything targeting the device. Additionally, any apps that are targeted to the user that has been pre-assigned to the Autopilot device will also be installed. (Note that other user-targeted policies will not apply until the user signs into the device.) To verify these behaviors, be sure to create appropriate apps and policies, targeted to devices and users. +The Windows Autopilot for white glove deployment pre-provisioning process will apply all device-targeted policies from Intune. That includes certificates, security templates, settings, apps, and more – anything targeting the device. Additionally, any apps that are targeted to the user that has been pre-assigned to the Autopilot device will also be installed. (Note that other user-targeted policies will not apply until the user signs into the device.) To verify these behaviors, be sure to create appropriate apps and policies, targeted to devices and users. ## Scenarios -Windows Autopilot “White Glove” supports two distinct scenarios: +Windows Autopilot for white glove deployment supports two distinct scenarios: - User-driven deployments with Azure AD Join. The device will be joined to an Azure AD tenant. - User-driven deployments with Hybrid Azure AD Join. The device will be joined to an on-premises Active Directory domain, and separately registered with Azure AD. Each of these scenarios consists of two parts, a technician flow and a user flow. At a high level, these parts are the same for Azure AD Join and Hybrid Azure AD join; differences are primarily seen by the end user in the authentication steps. ### Technican flow -The first part of the Windows Autopilot “White Glove” process is designed to be carried out by a technician; this could be a member of the IT staff, a services partner, or an OEM – each organization can decide who should perform these activities. +The first part of the Windows Autopilot for white glove deployment process is designed to be carried out by a technician; this could be a member of the IT staff, a services partner, or an OEM – each organization can decide who should perform these activities. Regardless of the scenario, the process to be performed by the technician is the same: - Boot the device (running Windows 10 Pro, Enterprise, or Education SKUs, Insider Preview build 18342 or higher). -- From the first OOBE screen (which could be a language selection or locale selection screen), do not click “Next.” Instead, press the Windows key five times to view an additional options dialog. From that screen, choose the “Windows Autopilot provisioning” option and then click “Continue.” +- From the first OOBE screen (which could be a language selection or locale selection screen), do not click **Next**. Instead, press the Windows key five times to view an additional options dialog. From that screen, choose the **Windows Autopilot provisioning** option and then click **Continue**. ![Autopilot](images/wg05.png) -- On the “Windows Autopilot Configuration” screen, information will be displayed about the device: +- On the **Windows Autopilot Configuration** screen, information will be displayed about the device: - The Autopilot profile assigned to the device. - The organization name for the device. - The user assigned to the device (if there is one). - A QR code containing a unique identifier for the device, useful to look up the device in Intune to make any configuration changes needed (e.g. assigning a user, adding the device to any additional groups needed for app or policy targeting). -- Validate the information displayed. If any changes are needed, make these and then click “Refresh” to re-download the updated Autopilot profile details. +- Validate the information displayed. If any changes are needed, make these and then click **Refresh** to re-download the updated Autopilot profile details. ![Autopilot](images/wg06.png) -- Click “Provision” to begin the provisioning process. +- Click **Provision** to begin the provisioning process. If the pre-provisioning process completes successfully: - A green status screen will be displayed with information about the device, including the same details presented previously (e.g. Autopilot profile, organization name, assigned user, QR code), as well as the elapsed time for the pre-provisioning steps. -- Click “Reseal” to shut the device down. At that point, the device can be shipped to the end user. +- Click **Reseal** to shut the device down. At that point, the device can be shipped to the end user. If the pre-provisioning process fails: - A red status screen will be displayed with information about the device, including the same details presented previously (e.g. Autopilot profile, organization name, assigned user, QR code), as well as the elapsed time for the pre-provisioning steps. - Diagnostic logs can be gathered from the device, and then it can be reset to start the process over again. @@ -117,25 +117,24 @@ If the pre-provisioning process completed successfully and the device was reseal ## Fixed issues Each Windows 10 19H1 Insider Preview build can contain additional fixes for Windows Autopilot and related functionality. These issues should already be addressed: -• Some failures may be displayed on the Enrollment Status Page, instead of advancing to the red “White Glove” summary page. Fixed in build 10.0.18345. (20355940) +• Some failures may be displayed on the Enrollment Status Page, instead of advancing to the red "white glove" summary page. Fixed in build 10.0.18345. (20355940) • Connectivity to the corporate network is presently required during the Hybrid AAD Join technician flow, even though it is only used to check that an Active Directory domain controller is accessible. Fixed in build 10.0.18345. (20301592) -• When enrolling a device in Intune during the technician flow, an enrollment error 80180003 is reported, indicating that White Glove is not enabled. Fixed in Intune on March 8th, 2019. -• When editing the Autopilot profile to enable White Glove, the setting change is not saved properly. Fixed in Intune on March 12th, 2019. - +• When enrolling a device in Intune during the technician flow, an enrollment error 80180003 is reported, indicating that white glove is not enabled. This is fixed in Intune on March 8th, 2019. +• When editing the Autopilot profile to enable white glove deployment, the setting change is not saved properly. This is fixed in Intune on March 12th, 2019. ## Known issues ### All scenarios -When installing Win32 apps via the Intune Management Extensions, the Enrollment Status Page may time out even though the apps are installed successfully. In some cases, this may indicate that the detection rules for the app are not correct, but this may happen even with properly configured apps. (Under investigation.) +When installing Win32 apps via the Intune Management Extensions, the Enrollment Status Page may time out even though the apps are installed successfully. In some cases, this may indicate that the detection rules for the app are not correct, but this may happen even with properly configured apps. This issue is currently under investigation. ### Hybrid Azure AD Join -The process of TPM attestation, joining the device to Active Directory, and enrolling in Intune happens when the “Provision” button is clicked from the initial “Windows Autopilot Configuration” screen. Additional status is being added. (20212277) +The process of TPM attestation, joining the device to Active Directory, and enrolling in Intune happens when the **Provision** button is clicked from the initial **Windows Autopilot Configuration** screen. Additional status is being added. (20212277) ### Azure AD Join -There are currently no existing known issues specific to Azure AD Join. +There are currently no known issues specific to Azure AD Join. ## Feedback From 023c770e62ea2ff8cc29b17f44d6a501afafd20d Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 13 May 2019 13:25:58 -0700 Subject: [PATCH 284/737] draft4 --- windows/deployment/windows-autopilot/TOC.md | 2 +- windows/deployment/windows-autopilot/white-glove.md | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/deployment/windows-autopilot/TOC.md b/windows/deployment/windows-autopilot/TOC.md index e497301f56..30a33a05ff 100644 --- a/windows/deployment/windows-autopilot/TOC.md +++ b/windows/deployment/windows-autopilot/TOC.md @@ -5,8 +5,8 @@ ### [Network requirements](windows-autopilot-requirements-network.md) ### [Licensing requirements](windows-autopilot-requirements-licensing.md) ## [Scenarios and Capabilities](windows-autopilot-scenarios.md) -### [White glove](white-glove.md) ### [Support for existing devices](existing-devices.md) +### [White glove](white-glove.md) ### [User-driven mode](user-driven.md) #### [Azure Active Directory joined](user-driven-aad.md) #### [Hybrid Azure Active Directory joined](user-driven-hybrid.md) diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index 65b0660df7..c466935433 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -25,7 +25,7 @@ Windows Autopilot can also provide a "white glove" service enabling partners or ![OEM](images/wg02.png) -Enabled with Microsoft Intune in Windows 10, version 1903 and later, white glove deployment capabilities build on top of existing Windows Autopilot [user-driven scenarios](user-driven.md), supporting the user-driven [Azure AD join](user-driven-aad) and [Hybrid Azure AD](user-driven-hybrid.md) join scenarios. +Enabled with Microsoft Intune in Windows 10, version 1903 and later, white glove deployment capabilities build on top of existing Windows Autopilot [user-driven scenarios](user-driven.md), supporting the user-driven [Azure AD join](user-driven-aad.md) and [Hybrid Azure AD](user-driven-hybrid.md) join scenarios. ## Prerequisites @@ -64,7 +64,7 @@ Two features will be enabled as part of the flighting process: Once the flighting is complete, you will be able to enable Windows Autopilot for white glove deployment in any Autopilot profile; all devices with that profile assigned will be able to leverage the "white glove" process. >[!TIP] ->To see the “White Glove” Autopilot profile setting, use this URL to access the Intune portal: https://portal.azure.com/?microsoft_intune_enrollment_enableWhiteGlove=true. This is a temporary requirement. +>To see the white glove deployment Autopilot profile setting, use this URL to access the Intune portal: https://portal.azure.com/?microsoft_intune_enrollment_enableWhiteGlove=true. This is a temporary requirement. ![OOBE](images/wg05.png) @@ -136,10 +136,10 @@ The process of TPM attestation, joining the device to Active Directory, and enro There are currently no known issues specific to Azure AD Join. -## Feedback +## Questions and comments Depending on your method of participation in the Windows Autopilot for white glove deployment process, your feedback mechanism may be different. - If you are participating in the Windows TAP program, please provide feedback via the **Windows 10 TAP** Yammer group. - If you are participating via MVP programs, please provide feedback via the MVP distribution list for your specialty. -- For others, please provide feedback via the [Feedback Hub](https://www.microsoft.com/p/feedback-hub/9nblggh4r32n#activetab=pivot:overviewtab) or your specific Windows Autopilot team contact. +- For others, please use the feedback links provided below or your specific Windows Autopilot team contact. From ca6bb81791cf65f6bab765baaf73cb502ce8faa3 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 13 May 2019 13:37:25 -0700 Subject: [PATCH 285/737] draft5 --- .../windows-autopilot/white-glove.md | 22 ++++++++++--------- 1 file changed, 12 insertions(+), 10 deletions(-) diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index c466935433..41952b7b78 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -49,7 +49,7 @@ To ensure that your Intune tenant has been flighted with the needed white glove ![AAD](images/wg03.png) -The tenant ID can be found under **Azure Active Directory** and then **Properties**. Click the icon next to the ID to copy to the clipboard.: +The tenant ID can be found under **Azure Active Directory** and then **Properties**. Click the icon next to the ID to copy to the clipboard. ![AAD](images/wg04.png) @@ -58,17 +58,19 @@ The tenant ID can be found under **Azure Active Directory** and then **Propertie Two features will be enabled as part of the flighting process: -- Support for Windows Autopilot for white glove deployment This will enable devices performing white glove deployment processes to enroll in Intune, and will expose a new Autopilot profile setting that enables white glove deployment for any devices that have been assigned that profile. -- Support for tracking Intune Management Extensions activities (Win32 apps, PowerShell scripts) in the Enrollment Status Page (ESP). This is needed to ensure that all Win32 apps are installed before the white glove deployment process completes. +- Support for Windows Autopilot for white glove deployment. + - This will enable devices performing white glove deployment processes to enroll in Intune, and will expose a new Autopilot profile setting that enables white glove deployment for any devices that have been assigned that profile. +- Support for tracking Intune Management Extensions activities (Win32 apps, PowerShell scripts) in the Enrollment Status Page (ESP). + - This is needed to ensure that all Win32 apps are installed before the white glove deployment process completes. -Once the flighting is complete, you will be able to enable Windows Autopilot for white glove deployment in any Autopilot profile; all devices with that profile assigned will be able to leverage the "white glove" process. +Once the flighting is complete, you will be able to enable Windows Autopilot for white glove deployment in any Autopilot profile; all devices with that profile assigned will be able to leverage the white glove deployment process. >[!TIP] >To see the white glove deployment Autopilot profile setting, use this URL to access the Intune portal: https://portal.azure.com/?microsoft_intune_enrollment_enableWhiteGlove=true. This is a temporary requirement. ![OOBE](images/wg05.png) -The Windows Autopilot for white glove deployment pre-provisioning process will apply all device-targeted policies from Intune. That includes certificates, security templates, settings, apps, and more – anything targeting the device. Additionally, any apps that are targeted to the user that has been pre-assigned to the Autopilot device will also be installed. (Note that other user-targeted policies will not apply until the user signs into the device.) To verify these behaviors, be sure to create appropriate apps and policies, targeted to devices and users. +The Windows Autopilot for white glove deployment pre-provisioning process will apply all device-targeted policies from Intune. That includes certificates, security templates, settings, apps, and more – anything targeting the device. Additionally, any apps that are targeted to the user that has been pre-assigned to the Autopilot device will also be installed. **Note**: other user-targeted policies will not apply until the user signs into the device. To verify these behaviors, be sure to create appropriate apps and policies targeted to devices and users. ## Scenarios @@ -116,11 +118,11 @@ If the pre-provisioning process completed successfully and the device was reseal ## Fixed issues -Each Windows 10 19H1 Insider Preview build can contain additional fixes for Windows Autopilot and related functionality. These issues should already be addressed: -• Some failures may be displayed on the Enrollment Status Page, instead of advancing to the red "white glove" summary page. Fixed in build 10.0.18345. (20355940) -• Connectivity to the corporate network is presently required during the Hybrid AAD Join technician flow, even though it is only used to check that an Active Directory domain controller is accessible. Fixed in build 10.0.18345. (20301592) -• When enrolling a device in Intune during the technician flow, an enrollment error 80180003 is reported, indicating that white glove is not enabled. This is fixed in Intune on March 8th, 2019. -• When editing the Autopilot profile to enable white glove deployment, the setting change is not saved properly. This is fixed in Intune on March 12th, 2019. +Each Windows 10 19H1 Insider Preview build can contain additional fixes for Windows Autopilot and related functionality. The following issues should already be addressed: +- Some failures may be displayed on the Enrollment Status Page, instead of advancing to the red "white glove" summary page. This is fixed in build 10.0.18345. (20355940) +- Connectivity to the corporate network is presently required during the Hybrid AAD Join technician flow, even though it is only used to check that an Active Directory domain controller is accessible. This is fixed in build 10.0.18345. (20301592) +- When enrolling a device in Intune during the technician flow, an enrollment error 80180003 is reported, indicating that white glove is not enabled. This is fixed in Intune on March 8th, 2019. +- When editing the Autopilot profile to enable white glove deployment, the setting change is not saved properly. This is fixed in Intune on March 12th, 2019. ## Known issues From ab1a1d41333cd9417a031508f8bb98b6c8dd56b9 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 13 May 2019 14:23:06 -0700 Subject: [PATCH 286/737] draft6 --- windows/deployment/windows-autopilot/white-glove.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index 41952b7b78..9854786c6a 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -17,15 +17,17 @@ ms.topic: article **Applies to: Windows 10, version 1903** -Windows Autopilot enables organizations to easily provision new devices, leveraging the preinstalled OEM image and drivers resulting in a simple process that can be performed by the end user. +Windows Autopilot enables organizations to easily provision new devices - leveraging the preinstalled OEM image and drivers with a simple process that can be performed by the end user to help get their device business-ready. ![OEM](images/wg01.png) -Windows Autopilot can also provide a "white glove" service enabling partners or IT staff to pre-provision a Windows 10 PC to be fully configured and business-ready​. With Windows Autopilot for white glove deployment, the provisioning process is split, with the time-consuming portions performed by IT, partners, or OEMs. From the end user’s perspective, the process is exactly the same, just faster – the Windows Autopilot user-driven experience is unchanged. +Windows Autopilot can also provide a white glove service that enables partners or IT staff to pre-provision a Windows 10 PC so that it is fully configured and business-ready​. From the end user’s perspective, the Windows Autopilot user-driven experience is unchanged, but getting their device to a fully provisioned state is faster. + +With **Windows Autopilot for white glove deployment**, the provisioning process is split. The time-consuming portions are performed by IT, partners, or OEMs. The end user simply completes a few neceesary settings and polices and then they can begin using their device. ![OEM](images/wg02.png) -Enabled with Microsoft Intune in Windows 10, version 1903 and later, white glove deployment capabilities build on top of existing Windows Autopilot [user-driven scenarios](user-driven.md), supporting the user-driven [Azure AD join](user-driven-aad.md) and [Hybrid Azure AD](user-driven-hybrid.md) join scenarios. +Enabled with Microsoft Intune in Windows 10, version 1903 and later, white glove deployment capabilities build on top of existing Windows Autopilot [user-driven scenarios](user-driven.md), supporting both the user-driven [Azure AD join](user-driven-aad.md) and [Hybrid Azure AD](user-driven-hybrid.md) join scenarios. ## Prerequisites @@ -144,4 +146,4 @@ Depending on your method of participation in the Windows Autopilot for white glo - If you are participating in the Windows TAP program, please provide feedback via the **Windows 10 TAP** Yammer group. - If you are participating via MVP programs, please provide feedback via the MVP distribution list for your specialty. -- For others, please use the feedback links provided below or your specific Windows Autopilot team contact. +- For others, please use the feedback link provided below (next to **This product**) or your specific Windows Autopilot team contact. From d3ed76ec25d361a5d558833ff41544c38d0fee03 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Mon, 13 May 2019 15:01:37 -0700 Subject: [PATCH 287/737] Formatting updates --- .../client-management/mdm/enrollmentstatustracking-csp.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/client-management/mdm/enrollmentstatustracking-csp.md b/windows/client-management/mdm/enrollmentstatustracking-csp.md index 975a1a8c3b..b8c8725a1e 100644 --- a/windows/client-management/mdm/enrollmentstatustracking-csp.md +++ b/windows/client-management/mdm/enrollmentstatustracking-csp.md @@ -74,13 +74,13 @@ Root node for the app installations being tracked by the ESP. Scope is permanent. Supported operation is Get. -**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*** +**EnrollmentStatusTracking/Setup/Apps/Tracking/_ProviderName_** Optional. This node is supported in both user context and device context. Indicates the provider name responsible for installing the apps and providing status back to ESP. Scope is dynamic. Supported operations are Get, Add, Delete, and Replace. -**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*/*AppName*** +**EnrollmentStatusTracking/Setup/Apps/Tracking/*ProviderName*/_AppName_** Optional. This node is supported in both user context and device context. Represents a unique name for the app whose progress should be tracked by the ESP. The policy provider can define any arbitrary app name as ESP does not use the app name directly. @@ -131,7 +131,7 @@ Indicates to the ESP that it should wait in the device preparation phase until a Scope is permanent. Supported operation is Get. -**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/*ProviderName*** +**EnrollmentStatusTracking/DevicePreparation/PolicyProviders/_ProviderName_** Optional. This node is supported only in device context. Represents a policy provider for the ESP. The node should be given a unique name for the policy provider. Registration of a policy provider indicates to ESP that it should block in the device preparation phase until the provider sets its InstallationState node to 2 (NotRequired) or 3 (Completed). Once all the registered policy providers are marked as Completed or NotRequired, the ESP progresses to the device setup phase. From 14dda06cdce07261d5b21e92d470bc045903c78b Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Mon, 13 May 2019 15:38:34 -0700 Subject: [PATCH 288/737] draft7 --- windows/deployment/windows-autopilot/white-glove.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/deployment/windows-autopilot/white-glove.md b/windows/deployment/windows-autopilot/white-glove.md index 9854786c6a..1896289840 100644 --- a/windows/deployment/windows-autopilot/white-glove.md +++ b/windows/deployment/windows-autopilot/white-glove.md @@ -33,7 +33,7 @@ Enabled with Microsoft Intune in Windows 10, version 1903 and later, white glove In addition to [Windows Autopilot requirements](windows-autopilot-requirements.md), Windows Autopilot for white glove deployment adds the following: -- Windows 10, version 1903 or later is required. Note: If you are a Windows Insider, Windows 10 build 18342 and above is required. The Insider Skip Ahead builds for the Windows 10 20H1 release with build numbers greater than 18800 may work, but 19H1 build numbers in the 18300 range are recommended. +- Windows 10, version 1903 or later is required. - Microsoft Intune subscriptions with additional flighted features that are not yet available publicly. Attempts to perform white glove deployment without these flighted features will fail with an Intune enrollment error. - Physical devices that support TPM 2.0 and device attestation; virtual machines are not supported. The white glove provisioning process leverages Windows Autopilot self-deploying capabilities, hence the TPM 2.0 requirements. - Physical devices with Ethernet connectivity; Wi-fi connectivity is not supported due to the requirement to choose a language, locale, and keyboard to make that Wi-fi connection; doing that in a pre-provisioning process could prevent the user from choosing their own language, locale, and keyboard when they receive the device. @@ -85,7 +85,7 @@ Each of these scenarios consists of two parts, a technician flow and a user flow The first part of the Windows Autopilot for white glove deployment process is designed to be carried out by a technician; this could be a member of the IT staff, a services partner, or an OEM – each organization can decide who should perform these activities. Regardless of the scenario, the process to be performed by the technician is the same: -- Boot the device (running Windows 10 Pro, Enterprise, or Education SKUs, Insider Preview build 18342 or higher). +- Boot the device (running Windows 10 Pro, Enterprise, or Education SKUs, version 1903 or later). - From the first OOBE screen (which could be a language selection or locale selection screen), do not click **Next**. Instead, press the Windows key five times to view an additional options dialog. From that screen, choose the **Windows Autopilot provisioning** option and then click **Continue**. ![Autopilot](images/wg05.png) @@ -120,7 +120,7 @@ If the pre-provisioning process completed successfully and the device was reseal ## Fixed issues -Each Windows 10 19H1 Insider Preview build can contain additional fixes for Windows Autopilot and related functionality. The following issues should already be addressed: +The following issues were fixed in Windows Insider 19H1 builds: - Some failures may be displayed on the Enrollment Status Page, instead of advancing to the red "white glove" summary page. This is fixed in build 10.0.18345. (20355940) - Connectivity to the corporate network is presently required during the Hybrid AAD Join technician flow, even though it is only used to check that an Active Directory domain controller is accessible. This is fixed in build 10.0.18345. (20301592) - When enrolling a device in Intune during the technician flow, an enrollment error 80180003 is reported, indicating that white glove is not enabled. This is fixed in Intune on March 8th, 2019. From a86151ad466a3af1c0a8319715ca5dd7cddfb8eb Mon Sep 17 00:00:00 2001 From: Denis Gundarev Date: Mon, 13 May 2019 23:05:36 -0700 Subject: [PATCH 289/737] Changed XDDM deprecation notice --- windows/deployment/planning/windows-10-1903-removed-features.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/planning/windows-10-1903-removed-features.md b/windows/deployment/planning/windows-10-1903-removed-features.md index c7352cabdb..97d7fabc26 100644 --- a/windows/deployment/planning/windows-10-1903-removed-features.md +++ b/windows/deployment/planning/windows-10-1903-removed-features.md @@ -25,7 +25,7 @@ The following features and functionalities are removed from the installed produc |-----------|--------------------|--------- |Cortana will be removed from Windows 10 in all non-English/US markets. Cortana will still be available for en-us markets. |Pending removal|A new Cortana UWP app is being developed. Precise dates for release not yet available.| |Cortana on Android is removing all Cortana cross-device functionality from it's application in November. |Removed |This will remove all of the mirrored notifications and Cortana natural language skills for texting or calling a mobile device and finding their phone. The **Your Phone** applicaiton on PC is offering a partial replacement for text notifications from Android phones but not the full spectrum of features. | -|XDDM-based Remote Desktop driver|Removed|The default driver for remote desktop was switched to the IDD for a single-user scenarios. We plan to use IDD as default for all use cases and anounce deprecation of XP Display Driver Model (XDDM) based RD fdriver| +|XDDM-based remote display driver|Pending Removal|Starting with this release the Remote Desktop Services uses a Windows Display Driver Model (WDDM) based Indirect Display Driver (IDD) for a single session remote desktop. The support for Windows 2000 Display Driver Model (XDDM) based remote display drivers will be removed in a future release. Independent Software Vendors that use XDDM-based remote display driver should plan a migration to the WDDM driver model. For more information on implementing remote display indirect display driver ISVs can reach out to [rdsdev@microsoft.com](mailto:rdsdev@microsoft.com). |Desktop messaging app doesn't offer messages sync |Removed|The messaging app on Desktop has a sync feature that can be used to sync SMS text messages received from Windows Mobile and keep a copy of them on the Desktop. We will be removing the messaging app from Desktop devices in a future release. When sync is removed, you will only be able to access messages from the device that received the message.| |Print 3D app|Removed|The Print 3D app will no longer be installed automatically in a future release of Windows. It will remain available for download from the Store. To 3D print objects on a new Windows devices, you must first install the app (1P or 3P app) from the Store.| |My People / People|Pending removal|The **My People** experience will be removed in a future release.| From da0b5bab3173f4f76393ebb99c18ee787d942890 Mon Sep 17 00:00:00 2001 From: Deland-Han Date: Tue, 14 May 2019 15:59:53 +0800 Subject: [PATCH 290/737] finish --- ...windows-10-device-automatically-using-group-policy.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md b/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md index 24e4a9039a..b79c6c1219 100644 --- a/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md +++ b/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy.md @@ -108,6 +108,15 @@ Requirements: - Ensure that PCs belong to same computer group. 1. Create a Group Policy Object (GPO) and enable the Group Policy **Computer Configuration** > **Policies** > **Administrative Templates** > **Windows Components** > **MDM** > **Enable automatic MDM enrollment using default Azure AD credentials**. + >[!Note] + >If you do not see the policy, it may be caused because you don’t have the ADMX installed for Windows 10, version 1803. To fix the issue, follow these steps: + > 1. Download [Administrative Templates (.admx) for Windows 10 April 2018 Update (1803) +](https://www.microsoft.com/en-us/download/details.aspx?id=56880). + > 2. Install the package on the Primary Domain Controller. + > 3. Navigate to the folder **C:\Program Files (x86)\Microsoft Group Policy\Windows 10 April 2018 Update (1803) v2**. + > 4. Copy policy definitions folder to **C:\Windows\SYSVOL\domain\Policies**. + > 5. Restart the Primary Domain Controller for the policy to be available. + 2. Create a Security Group for the PCs. 3. Link the GPO. 4. Filter using Security Groups. From 5fc15e6d8011d504592ad1eb4cac67532c55f208 Mon Sep 17 00:00:00 2001 From: Lindsay <45809756+lindspea@users.noreply.github.com> Date: Tue, 14 May 2019 10:47:09 +0200 Subject: [PATCH 291/737] Update troubleshoot-tcpip-port-exhaust.md Added updated blog link and added note. --- windows/client-management/troubleshoot-tcpip-port-exhaust.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/client-management/troubleshoot-tcpip-port-exhaust.md b/windows/client-management/troubleshoot-tcpip-port-exhaust.md index 8fb6da7063..bd7c5fd2f8 100644 --- a/windows/client-management/troubleshoot-tcpip-port-exhaust.md +++ b/windows/client-management/troubleshoot-tcpip-port-exhaust.md @@ -99,7 +99,7 @@ You may also see CLOSE_WAIT state connections in the same output, however CLOSE_ >[!Note] >Having huge connections in TIME_WAIT state does not always indicate that the server is currently out of ports unless the first two points are verified. Having lot of TIME_WAIT connections does indicate that the process is creating lot of TCP connections and may eventually lead to port exhaustion. > ->Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. +>Netstat has been updated in Windows 10 with the addition of the **-Q** switch to show ports that have transitioned out of time wait as in the BOUND state. An update for Windows 8.1 and Windows Server 2012R2 has been released that contains this functionality. The PowerShell cmdlet `Get-NetTCPConnection` in Windows 10 also shows these BOUND ports. Until 2016/10, netstat was inaccurate. Fixes for netstat were backported to 2012 R2. 4. Open a command prompt in admin mode and run the below command @@ -192,5 +192,5 @@ goto loop - [Port Exhaustion and You!](https://blogs.technet.microsoft.com/askds/2008/10/29/port-exhaustion-and-you-or-why-the-netstat-tool-is-your-friend/) - this article gives a detail on netstat states and how you can use netstat output to determine the port status -- [Detecting ephemeral port exhaustion](https://blogs.technet.microsoft.com/clinth/2013/08/09/detecting-ephemeral-port-exhaustion/): this article has a script which will run in a loop to report the port status. (Applicable for Windows 2012 R2, Windows 8, Windows 10) +- [Detecting ephemeral port exhaustion](https://blogs.technet.microsoft.com/yongrhee/2018/01/09/windows-server-2012-r2-ephemeral-ports-a-k-a-dynamic-ports-hotfixes/): this article has a script which will run in a loop to report the port status. (Applicable for Windows 2012 R2, Windows 8, Windows 10) From 0e1b2941d4194dc493eab21bc2c21ad9c8c16d05 Mon Sep 17 00:00:00 2001 From: Lindsay <45809756+lindspea@users.noreply.github.com> Date: Tue, 14 May 2019 11:08:49 +0200 Subject: [PATCH 292/737] Add files via upload Changed screenshot. --- .../client-management/images/tcp-ts-14.png | Bin 290534 -> 273444 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/windows/client-management/images/tcp-ts-14.png b/windows/client-management/images/tcp-ts-14.png index f3a3cc4a35df26eb8895c9d5582853fcd241f873..b1db37cd1a1844165e20e0c2b2dea8f9ca8c9c2d 100644 GIT binary patch literal 273444 zcmb@t1yq#nw>LcCC?Oyz0}{h9w7@WQ4=_jwh%`zw#L%50AuTa&6<0zd*8dR-`-c<6Q-&nM~F|24*&oN737g>007V% z0KoRZ#lCIva`)i8{lasQ*L4N}NL~JXu;$I_Jph1v9cT?57ae6K5mS3xE@PCvi5ZuN zt-~!h03asm;b3fPZRP?tF|$D1i9`0A+8|&wN*toiuMAUmkTJ7F%X>MQse7qtn0i^8 z3Zo#B5@0b8ky`<_W-i8H4_g~MXAuu^$X{|rZm<6|b3?#?vA9@^L!|yF1nVfPf@SQT z%)tCy0-UBieEeWRVJ;p4UOr*r$6z>&M~E9H#LdIY$s-`b2NQwA!T%=6tu`l=xriF_ z$-i~o{t|~+y0|!qaC5u6yK}koa@jjsaPtTY3v5R!Pem)v3Ab?4%2PGxIK&=xOuo>e_Z;D5oP)h zpM$HD&0oqNUChKGf9`X__&IraHF#hmJp3a30vs^72n_Zw zR%Lq>+T8R1WaSaz<^SLKZXts*b}|0%IZ>t}=Jrmu#<$+0ZH+C=xE<^)AmD#uC?aET zWAAjU^42ci|J<%1BctkMZ;rOPz2U4TCk%{T@4;Jk1?0TVM5KGfgOBkfIH z|MdT#=l_)oD0|ae8UJCPF)s`*AP6_%MDYspahjm`j5&qi{ARaT0>VPVJc7n>Grqs2 zJ##|eW}~sqf0p{kD%7n+L17^iQyxxZe#a9fgtz)&3GBxHELjB|Y|7ra#WZ@z_e1D_%|E2Z+4vwj%v7Lq4ZIR`M{D1K0 ze}v9|8Tw!P^G^!?|LP3)pW6B_oN@m@A^6w5|5S%>`|_`*+v5J`@}E)V_QyZtl9}CY zoSbe)9TC{7J^;vsr+}2w@JQcjarcADxt`w`Xu3ZmN^_oXNq@t|@>x9*a5oT$3&SQ5 zSjejE=oS!qWNHe7ghGL&U_7%;mCgL7@zwP4z4^6t3pX`)?Un_4abD4;I+nSNK%km0 zqRLtP+c(W`-}FzmfcQIXfxEHn*SKM9w3iQwxZgmi?p`KZg))RZ%*i|rSVNb1t?^-YxGwt z!L!l^N>H^{Ys!r61MoYfs)zE252N^zjbkapqo_!S>#X^}qiU;04u+^Ufymz?tx8m@ z@|5&3(8WM+MO;K+C=l4^jvr-~u1ltLqg-cj_zo|c^>&Vd71i{z_`X4}y0F$;N6)Ax z3cf`xRA%tcE81AV@b3yaow1G1^z~yqN(!0l+4g!o%<0M3HXc0>3C#}qcf(v&e}X$aV^eD zL^12mdacq&$_!p$=lQ7HCx_G_W4$vaN+x}EBxL(=^C>a0c@+8by(#B3vtKpx*dM-% z+Ll^kyz1VmC?;C$fC1nFgBKVteDHEHmEm~U+3Ku>SWXt|b-}>{OoG3XK*7BF0}$2M6>mj|qT-a?e3SV4ZIm}76R&cOWWk=QdCkz#J!RLN0YTM|>C4F@ zySy`ZyCoZnZFJ2=QC~$&Z4}nTT47ZBl-qLfG-m)M3B`>4GWcFr%C3OK z!8s~9wfxxtgR=+i0-P+aAl1@jE#=u^pb|VfeLpvaKZ8#f9?7TSGexrP(&e2()sj4U zbw#WsE=tz=5?A}V^|v0z>r`izP6cRr^Pcw6i~u+f#a(Hj7w8uV=mm`TD5xFMCez(x z^Q31o7n7TSrM#lVzJu9pF!5scqsm}kR>%HuaMZNoh#lPbYDiEjd4-HOOByw?Y_8mn zhq4Ma!j)EeWyRYw;n>iErUJw;$P1s+N!Z(wMQ1}(tM}q2-eMKLFprJBF_vVJKc_s! zOQyDETlR1Q0%GGY=z7JH3Jhz=hLulPQ!x@3%)-z54syLmXRgG~S`FJRtc)5qI9{|^ zmPRGHoSYSzaTOc3+;`tHnfV#rFt~6re6&#GUP0TPv>09an?>L17vuG-m&2d(_vfEB zr7gd!*BPH{2xZ)be&;6Pn_vkk-djfO(Z0a35f)7IuHI9^WyDt(~|4 z2_fU}qs{F1++NclH@m7wnlR=QWO<@*M%RWwtd2iOl>lS_e*jjDE*bJkD4-}u)jtp^ zRn$-&Gip2pT23c{$jHyDLx9p4`GNjG00{d20Io3Kmf3^ zOPK@*zE~^{#f6;m$u;n$VD7DI46~P)_fvgu{k^eKWFiENF#-aNHeE_Dv9OJtI0e`i zpp=qS#MrpqOmf8Kv!x%ub8HRh&pc|n_e2StyYihrK+{^O%uDyP;&!B(FYc5M&N~ft z2UI!_Molq1b>-M%Jwf@UV4e_scEqc(qT!u;7Yu;q4|=-k4nQ>~Q(27;Jk^zpJLDyW zDHbRsQ3BdyGw#ZVtvENL`0T)fevW*OHsbru;QISpg_>FqSF8y92q*R}cW8F-;@0rU zm0oJ4b*AHoj<$B3j$fsH;xm}sdaox`z}M7Xft`Yod3Q#$PZRN(nAXns`YY47=?&DH zrJ?mqO7H}33u-B*BQ_hq7yLW(MIP`-?kNg{| zXu3~0zvAGnEJ+_1em$=5T`pe4Chlo9G(m5s@4F~m=zXW){@BW=HF?&@qBo|yKWg!U zCt{uEMn<2KYx8jm>A=SBNy^iv%bA8mWoo2=L5D1|i`--@zmFxR9zcSXk_*TM!V91k zorVt6tJ;IQY7ec%T+XKjzyB)GT&;RYz)l-`22cR%W8KTn309IFp#rh0;u6!uV96Ac z!pkhp_l{S!Rh}V-e(kl7URT)`BHk&e5Z#k`Q>>zqVYFqmg%`@gx(JNEujj}{s#Zip zK@`E3?${|0G7sQEL?LMWbm5a}%4MZ;#JHh;xSn($wzkaPTBVeJed2tPBNGWLWgkVh z>#M1WR^;wam6HX6&YaNMumUUG&&Zry)xaNxs^kgeg!uqAc`0>SV|f@57Q_+$sSlHX zzxVJihlN3<`G-y9x`R;q4<+VgC0sRVk&@=~=ObS`M()O9sojmdBLg*pG7)2$_6lLh z)l$1M+B3jQtV^W5P&JS`$XNv6f;&@_hbeicW!Xl4pXwVUGlMpHxkI5mI+jn!BArJe zHlNS$QM<5Wl-eD28TBMR7L^UK3#$>k5%t*Df?|eo3=@bMAElvuBcc$BhIEW69(_d6m&Yq-T`q~Jn)oAsnWW2LIprr3U8TqHTq z(R&LG?(?4mr9Hk)P4tY7@>wqh_QS1Kl}dk)T)V}EN{a~cm3^>sn+y2%wCj{m4kzSO zB@#j+_rO`x&}YV`rm|&OL+)|i(w6uBiR3|7&SiP|^Q%E)Q&ZC;1BX`EqB^|-uR3|d zN5e;Rif`60UQ1k8Px{PfH1Q5i@VNqqbk(aopLW+VNR1h!sr`nv5ZL>$TO z99>P8>M{lr7luWAUOp%+EIh3rUUuwZaUKxSUdpX@bFL%*E;;J ztj&}vuvR?<$t?Omm(B$~5AY9plg36chZ~53DFlolmT2k$$`<8%AtE(U>w~YQg~93S z2NJSd%nbw%q^Sgi-QwY$Z^@OaX{4 z0N&;&a{Y_@LEAhQ@hEZE83F z{;kSld^1YLhtC)rFxmXk%PJvMkia!#bLUB?*hn?%g|__d>?qc zo}%upVl+LQyQJq{+o2T66znwvN!3z&`EmzKBZJAg#A5UL4thsjf4;v!opxinu-N03 zaQM8F%hl`7QuZSDRCNOyOjxE4WYMA6T#uiuFiPUt$l}U@hde#nb6JBC9}x%W7Pgey z+MZfZ{-qMyj!I8q7zF#&hutG954c-pPOv9Iy{zUWE44y8lEFHh@tm5^w3CqKk#Z6> z$Kwp$SVAvDAGs@et<_w(^8TVP5 zcM9NP+{Q3B+W^r-e1lVUbH_QNKF2uO6a1df-Dtm$j?v0;EMuEJ<)a9!{zO#{_v_(d z?$+UK%m%Iyh(Bw0Z!Cz{;&Q9l%Gq#aTS^nA+3$ZDXF*XQ#8D@boVFVx{4_~`&UW+O zkQ0a1J8};wAW&r3h3HA%i;iY#k=G@azF*_fR|t}~Pp|;>Yp`EfW_&bnKYx0nBPhKK z04P|4{bO{JT~hcOkw#s#vzH{yCPVM_r?*qaRp?X?xiw96nf0n`!!mEw+}| zCcf4u*A(fzTF&d_31zDsIj9=FJ3Wo{OwfXcS^Xbp_TM3t4%sCY+dE^iE0JFg+iOVaqVzb_MkKR#_|hZMU%;1 z|Egw#8BD3!>L7qkQ-X$$PC5B&%c9p05DLovAq`c(Y1cMJdJ%zv zq?)Sd_rEylN!V*;;uqGvJbv=5ng}#M`!QAbKIOn5rL??qa0}5q)gusFX3f?|wNB!g zYlk9D$q5*~m{c#u`;~vd=Fvm0UVH~af2!c}EZSF&^ut-2n$Hur&FyqPxM7J&!bC*E z35bc80^0**)yUHAXmTHUsas;S<(bA4E% z%S$J9q^6Bfua6lh>-Xd~OdS2+TIB zYYq_wTh-!xBz+vTXnsGO>|B+c;&7#k45`!Jg5 zG<~|Isu_2#_4_BZ>!kA4z}V2}@*{)q-iPw_%R1isOCJwE1ss+>kKQ_ClaaZT@w=R& zPRPl$vRl9BR8YL(%8z~ERYecapo36(W`?AL+gY?b9bSgjV-7v|ZuyLL3k#9WT+Nxw zRN4AK{ca;#yG$SIE=m?m47Wn28u)B(gubZq8vM9A{tME4mO_}(@MU69M?>&k>80ZS zG$(9|j1q`ca4$c4kq05p24VnRW|`RcqGS5V7;Vceg1;7=8Hny{WU*235z0DsE7k4E zFqL!@n?Z6sX7Svy3AlP?@l9j=7Sz{3b0-69J>PSKc=zisCYnl!>~};jW(DatSPibG zqxD;}KQz~6o3iGL-q|QhV>WoTIZ{5?Y4&u@_k7~PAett8^SOoX>5^u@^UXm;7&0-r zs;GB6U3A>r$X?Ge725r;F!?C&OnsSnE@7JIQZ z_YaTI9@!N&wpP14rHtOeu*uznhrmnGT0Y`Lu4K_k9xt~edwLNv?y>uc6|P16HLI12 z*$ikEl_h@`dMh4|N}IX5{l>!6pc|2&Ui%KE_7}5biR*Nd-#Mt?eBt6&KYEmPRq-wg zj{)Gf`ZW=CzY~_9ZaK15_M+Kny2QHVuJx;fCho6wr@?ADL>OlSxV1StCyU_jIKEB%$U-Pr`eu>rOAW;hf`)?fD z*vxZI5N^orPzKK%K5szLQ)JYNaS^ehx*4d(5cSPc`2&%|k z2>;vN&(p#hKk$KbKD2VDG;3N?CLVGg(Q}?1OSnF^bF1;2pD+8=xHAj9cp_(# z3wxWOe8A?vQ^GMhX;4%D?#uc_^M$b2jZ{KDKvqZ&neUkWUKDm>rOz>flg2kX@{NAW z{_Rlu+KOG4oH4@)(3S~6?!Gi$E%3Y?Z>{D%sqI>%|b z${z`S@Hx-rRHNw3#M=@APa<5 zqD&Y;?PqZWBiFn8{t6Ku%}o5x+UrT|yoVOEmuPqES&|*eudh)Krg>6=0|z3}jXdvQ z$*aTLo`+q1r$5p+U$1}Ur&la}Ax?dNeQjOj(V(_lO+V22W7mPUp@0{yxXc}_XB+iY z16d*&ZXxMj&DDIMAhY3$5YU|p#ZGJd7pUuzT2;Gy(NoLb6d@QEd z=KS(1r&EGHv7&x6>LMm@=9ETAO|ldlNV(wBL$2*xbntC~o+|&SzK@hJrLy)i&a(>t zunK3EcrW~0*4)?^#>UW7g7~`$=msfJV?E1XGrd2vz3#O!sq|M{;c<$37=l0|;3wc* zpb!E$BJ9zaH1OKTcld)YsM+a>O8J(Pv#DiuRjVhefUolQ%MDJy*rX`%mOh zr|Buq?1v?5^FQ(2S5sPM+#Yz$mM8!~366t(N7&cdXXNOz$ zqAY!FJP^HV_f~%3Ju$$G2n8qsr4fBfSi(dh*w~EbI$N}6Q}-E3A})nll_2s8Vq7Un z{sAcVk`fl=q&yDu<Vf{aHE|(NQ?A3f#1@-M`#4 zQq(PrCf6^mDkn2Is%UXg+Tn@No$;UWZ^a>bu_-1Rj*ZZx&r1RM#Cm3(k%S>Q5!a6m z=Nql<)?_Tsvc#R2P`*Wi0(~vSVWXp6mXF1tj8hu!-kH3_$08XRLFaG%h>i2j@xe0v zmc?Yp>z8anQW9;E}c|}2DA&G-Fa&{n*!T@=p(gwM*pEoWBFCY*TSX2^@exjMEO0K3knAf1Ig>a4pk?g5| zeCvY&QEl!X1GnYXyX2Qg$#y|8=7CDV)9rlsvJZtAqX8KRQoMUz7zMt90Y@QW`LALF z>ZKQNc&NiZ$md|=GX}?oeg@vh#${HP9X$?=km|BM&Ds;IZu%ApAdpfQD}lS51LxIW zY(3_RsO@pI7zQ`em}?}ln%Z`rghaV}>zVf=>x{~OK?pl279*6#zjUO4B1u?yN<;!k ze~%`E8Gz19@}`ENgePWK)-)XyPuZV}lE%bvz4Ludq7<6$uRFbml!ihYp)}M{GGYu= zLT~8ocg-~CeIBV~+U?S+G*9cJO5~0xHCB*$?{XJABpl2(&6pCdO?OE`xJ5;027@m} z$Yd_oj>WQu*Sm#|fbX6;KT#o!h-gK({(}>NBw&Ep0@uAbdA<1ARuC4#DFM^;M%Ik? zVSMyuwK1<@_GFr725&qs{JRiribN4g6BT?pG@82=;3qKqkREMC7{d7Cz@_esAUQSY ztB=os;Mfd`I2&dvE+MC;Q>EVl66;<=^F{YIRN4UpD=b+lV`EiCg0j z*SH&UXQ!>gL)o63U==VS!4z>~Kx%mB_mxLH{xHQt;gN^O&r+TnrJo+s@Yk6Kznp;+ znx2gKfZq#PciuN#TQ0{J>KQPJC&pUBz0p8kJpAD zJDi;a4`ovE=n+6q-Op-IJu@h*t=7LDsmf`nn^rPNkZ#hGbmA%b1%&4a5#T5m@^)5yqsG_RjpI#X>1Ly4y$m~Qz%)TpoILoBASiuW%R|hEd zRzz}nbK>T=w-%FkuY4|Q8YBdqb}U1LW5?O8XYcYKZ9AFzf7fg0_ipsdCl1|(S0Wa0sr z1rZ%ZKY^2_E$ls11L!^Bxu(rDCwKa-Cy z0YAtIejE;j-tD|i%9*L3U7aEO4QE?3N%KQ8;*VX{Rp6cD=S{qv)1%syaIjSGEFAh73JR0KrqGag+#-q}Fmi&9((HfXDol7^ z(em!sMj@^8sLoKcsMbR)fa>@VOVdkgLLS%HUMlmcm#t2lslux&L4fSnoo7UuHdgLK znW^g8+5`1f@RR}EGs2zA6GoXYTH0(wIdRXLT}*V83=d+g*ELqn7`lQRha_%xTOwhg zgeea%jlQd2a{Dhofm~>(nvU8hf?@5al(psyjdq`HwbyT%Qw`4deJs#0tG6%zDP+EY zq2(S~zxp5kVQu8K61rm-0ZT3bKOmR?edY5*A6fiJW-$UN&gP+lmG}(VL%h%Q>R*tP40L5!TZrt#p zad94Fp;rcVsoQQWUp;gpL-KSDcp(uv{-J6*d^JWzi@-<_UWK;<@Jr!}`L;|8;}a;! zbA83p_>vr6&KNuWHS*O-;lZfq<-#eQcQ;&)1&?LZgJ&YTH9{CGYPAR-1POnpV#>v{ z+21Ws7U%pv!5Kp4SV1O_jfWzL2{92FpIxQEQuLSuxmH^Gewi-HLqYS+DTLm#e+-VM zr5p8cs0zfWVTx0OO_E1#qUAW)GzMYyDcaHeAxIQ7aZZwyy{v@m0g?JX;wiUGo51aX z!SWHSE}c6POId2LIEb{V4>UcFc&>P-{0ml&tmO!L~$+zaz|%HbPMs4x1k+P9QR z$*;@=j3o`l2r=GmK&1zg2SACj01!BGt<)r{jut;=WjZqX)Pz(wew_R8p!~%&0g!-}iK}lj(ADQ

    R;jWaV0WP7X^D-0HqaBMEj+!l}G<$Zy;{0O-SPP$HdcJTAqj_T8QiAKnvdKBE<`QIYok+*%d)&LfXsneEal0?fddN|Bv+-W z+6h~|$57uM;y$JjCt&6cx8D`2i+rzlSF<+2S4*K4i82|sqQZK*5Q@K6dy(w>iK@|= z_+kEWsLNLZ@cQfku*&~}BvVyTEexB1BWlzK34(0s2p8L|!2dE$W2G@+Ucr0gC;8Qn z-T}gDkdOUNCJdipZMr>NHllZP`Y>Nuep#C zyOcU+k(G&TFO0>pqYLJo3b8Co;AHZ5qybj`fR`{!Eo6TRR(*Y(>^tOGkuDS1%zqRd z9=>yP3X==tK&Ua+k=fvXNlaM62J6NiGgSX~9Myo7DcV5U-*3Hc=}B1R$2v)d@eDx1 zL6nEQ<}}HJJ^XBTCxWyv$86!a;aLqLNWMtxMSj=hTkHFgmCN-o44L4VML?&-*@`3R z5&Irj$?&t$&8cLDOb9*Cvi0dTQXEX)4b=8Oe)3ytc#(I0_=Q5dB}> zFCoc$L{HvHkkYJWLR#8QnG#ZB_PKAhj-dh|(pYp|PV6%%Z`2oKAeDdy`eau`i0a4G+{XY(O zfpvt(4^|Ka2y>x3N)zRXU4NV`mv-t}v%<^#4pUfJ+4U8WA>cx9VWAN=BSbGw83dLO(*q7 z0cc^`z+5mqA|%15|D+mLu)FAnx~D_i&ch<1WaUKU8bXRC)o8d_5nF*QOORmaZHzX3 zJsa0|go#7|_(^)W65PpzaJBlQpv%x*^v;1uspdXS&8lNA<2l9EFdKYcwzJELPDq+! z$r-NA>G$bHo1O`@XF#>5V0OfcKs0XR+8L|g*pOmUlzUO;)Y+!U@Ut7YfrUeETm`z0 z#Y>1)qsAVNon35C^)d?B>K_(j;PiwUJE8IYq&{R0lhhmn4KKsfEh+?9iB zT+J{_K@<1LFA@bq)>VZXwCNyy zgKh5-t)S?{ds*8s%*xsAuj^W8zg6&BzYC%)1CDExCTYEn7uO35!|CG|BpaD9(P&GflR)x(}70~-T?Uq24qioq5P zIfiLK7HhAkvi3PUWr7EZ?V^dj3|3qPj`CljNmRQ7fB2{9#F~v>{sk$=NVlE7bK4fW zM{xkc?{UCa969{dq1(&zdeKb>x_LAP|76Yy*;BpHwiID+8Dgrk0=Temp|(x2ZD0YfNGRdTwiC#Q-~hD?IX* zZwUzhwtIWD4!^J`QNp6!9ITuSkYIp(P&_|eVMSNVhGqja1c&v@fVt)j=TIaHo&WdB zuFaRa5D5ULb~^#f7nk+!)NT{`XkDlKu7B;f_UM^9ygy1#yLTHUe7~7m%^iC)#9>2` zh~#C&*9g;Dhg0NaH>pf9iSV0!*7^AoZ%KR? ziT%jso?*JpTm!M*hf!5eSs{6!T6X0c?W98}Q@-7H3F2~UQdOj3C3WIIx`lMEuKn2| zDHxZMEB_w7l^(?H)z8cyFmor@U3liPbNO=W>s^{U=HCb|d(8OKFMlT%ZmQBnoAW zV0SXk<_*aII0^@BxNfG5<+uEq+LERCTiA+H!%12JLX`}ZOIqel`m527rHlTwvjexf zxF_R)@p^d`BlLN~@?|E`8uX73IWF3dw4xPANbtc(<^j1%HzdEDsL?!yp%0aTIO>x;P}envNUg`j4d3I9oB)Fh{z zcAvh?WN1ieVc>>3kWls~s+fYUefL!RlPNR)dWZL(@|K)aK|0zoLVfzvL|^Vb7IlbQ z9QEg&<@T$KfBhrpl6|C%cfqYNx#q%lzF4PfH>qnI^ZPo&k3L6C?kZ@ZCuyIk?+GPkC{OA5)mi zl`B89)5{u#q{EqxTC~c4ilf|Q*~k!gc6#x(*3DJmpSElFSA}EES<(o#jZ@?)X?#PA zb2qHHe(PNtkbX!qOkGSBc&!-Yt=0O{7r1wQo-F#N^5ar?JR9ZoMLOhlb-OtMF1HBh zkj!>%s{{+7mwRf}mt_-3e0qds@ee#AUC37=$m+Pd}Z6!Nds>dW{F}TDSdiZMBD{{eH>P}M3)fwIwXA<$(q2*3;?&=SJ3dpjcdL5k{ z1Fb(%_U=<6cTW3CavCT76)A#+y-Q5{X4U~XGVMTG99_R1iz0EG2fmw{9;N;+N;Uz{2Nb70rHEFM^}HsOwc}BI`kTy7IT?G+~}6zxkUf+}!?V@;V()sb@SmTGRI}6y7GiFVa`~3*4c$)Y@gGxjUvha)%4BEWluIzW+p%X8xL3r{X_G{xe#q?Ws(NuXa7v%%y_Oo<6N) zTar5s;9H;gsp>*T3Ka^Qs#Bq!lXPPrGfrFS4y+X$`$(_<8n+(!O4`W(Bs+Jwwr*ta zR#~y^MLuY)*tGqPxa$`fa!j&zqUKIxSynmwZ1<4bb!^JKPb%{2zGv00U;iZOUXfz@ zy>^k`SRj&Rko0w#)P)wao!Zp93N4z9-wMzYeYYsn<0D=?kPW;TP}{O2(JV+tnjSy5 zTtW_PJY4Di_R<~jweN>rWgnE)C$C7M--k2zE@Ry`d!9JCpf5DZK(y7r^Zf4L?Pcw} zz-Z-?mHv{-)G`Neb^H6kOwnG2BtzN{uU;CGy256X@ED=Re|(N{K|+c~|GC7=4YB=* zA{JLqxn@0J--)S~-je&r%%nuU*^PVy_nfJAYSGIEuh@&I#Jxe}6Zgqt%Y@4xLw1Gr z7D8eaAIp&dB^(9rlCzsW&Zcww5tobjS)JY&_K8B~u3UjXpu%4PMAnE=E^KVDi|u#2!DeNaG*R*KPkY~%cv zZ1mbYfTN*Bq$9=i-v^J_`OKRtCtuLIiBl$WxNa6diFsVFrgZ}-M zPkI8%tK2~3%KY*EyztmA7QQGyGh7nFc3Qxu;G}o=mE-NFzqj~VTCI?uPwyu@dM$BD z8v=tl1KS<(H^0za48DQaOt_KEbnSkK>XX;(P)p=vC-q@#1Du_9EXjRgfd9%`cvUT0 z3)eN#obEp^<&fbF)AOc#VgPYy%J7t`HLdq(#yy1i&-VaqSz(jG<*!RSH-F(cdN-6q zwf_{}ycd7>{f)O$u{`-ZB?(nNcdllAS228ifOS=)8)0pby1`f|FB39XMjZ2(TCa1q z;{IbYYjh$1#qHkEN8YEg9cF$37u;o&EK9Axw<;+Ox)(#&dr6Xe6;0FQ@4d-vbSvCh zwpVg;i<*ov{;3u_Z0>o3`q9B-zMJzYm5&7|$3cayzFGsUh6y-6UIxj3h>B^AjV zt2K1%uBdE#?G&ui{hB7@i)#!1vZi-#z5+`5uR!k3?K#!YO}-Mc6`CV2K@PZ!YJn>= z6U$`{nZPb@%QNASB|@Q28+pL%u?x_a?#og)yraolt#4R50ci8aLmfzO{j+(1BHnwk z8M^iEyyZ5t_d(d7asTSPBG~=$t5-wC70f>0vP6Pnoq3)&n=o@fer%+5R|^#M&9$iq zIVqH~l6h!ls4hLgMa4B$B-#AKowj-k+w2ukq!-6U?1u2n?}>1VY-#{;4#zp_J|}B)aSn~nU%I7T&g9&*^pT)z5`1)M^xWvu-;8eLw4MOB3v=C^xAA?;@ZJN?=kio*>dtYl`Ism>CAaL9l*3<| zvmkjxnrr*>2a?US&af7e_}8D^S{Apcun#mR4@OMYM+-U7=Y*W7?}lGTx&=JL*$Qf? zxa2OKt2G?RG@pFZ1MW1uAWsc*I~Z|ePn;q9ttivFQw_m>4GRAd_MF~dr7pm&w=A-$ zsi`IyzXMRZpY%Q{h}=naJpw=flda?*%o@FI5xngx4l@|t@&QPR%q4aKbz5ns&Y9); zy>Rxq$g&^M>FgWlgm~@;uB`wSqAK@^XW@cC`-7Rs5J=SHD~5A>STiT;RpCcc*=!$?_lE$p&C40Og)s&pY+$pClp6{>jn_JLYpCQ}Y#hdRH@sYeaoe zot!HLX>QW9U9q!@`ZM0oPhYDDIiz=OS^TP_x>0)#TKIz1CiYy+aMs_0otuVvAFZmg zwS53I1F--D~ZlJF?||fH+G{N zare0+OSNSw2aPO+{0|(bEfn!Wje};syV8sz9{_5AG!_b^c%%wuaf0DwgTSUYN5GCL z+{Dzhdyg58RkmY_bjWu-nk-(T|3$rwvy}2V9VvJeJqHkK*y@(rvT5nGrd=-GIw$h3 zs2$hhUY(%lU8dRDuX)WowKTzNeK3nYR@P5sY}j&U6NYHo|}C0D_;Kn^M(qE|B=_r3K$KCM_>3I++;c($CrIG=XhtrOg?npQ9vFX${N*BED8VYe zavLF`J#y5t$LUS+za(>8m49TeyDR5C`KxMtNfSg16!6$yFaqi`j`0||`&R~8Ew~Le z2b6KLvD5*-$##u=mi)MlHb%|`lG9h^b!K^9HiS(?$|DPEfM#QE{iWZ)ux9T`tpQYj z%9VWxBJU974W~GZDp_*4I&^IX3IAEptRZ`|l%Au`2+%nE|020_{>A@yHQ)a(+=}{6 zMV${Ey88dpWOkizI&1vz8bS_d-~THllmAOB`Y%1=?f*@nxmlh6Z?E_CGq5G|-)hi* zd#S&g(En>Bx&J=$bCqfJ6YQ9$D^!8GS#_~`~U49ciisIzyIGq z53btO)o}kG&;R`_y$6=}KYSPPnfYy;|Ns0u=o4}THqyZ*5FP5$hB9;UU9N!BXWG7B* zKvvzfFTXkv(@pdMJ^QtA?nko4HtjxdO0US%jOA-(BL4;mnJGT5^ zHnpg>Z`WF}wYb5N435jkZ>)ijo8O&9K+iwk=l}Z^exDrr&!-%E=$IHN_jiEM??ku? z!6g{`Yi>H2==FVKWe|A6&P@3g>d<@5P<7@vuurDEhn8voX7Q}VfQ{y*3xO6aLgg=77k@3_W zd;19;JCea0c(xP$LCo0{v=jX<0e(^q_s7@35Ogl5UT5H&B_7PurT^H-s`;N_von2! zu*N^$vAVy;Cf_s#nOEh)Tp|8`l`feTy&;cjvp5+rlCk;VLJR^qiexV2J~}%>;QNSJ zHW0BbxYJIH3-f3L@DH$YzG}ds!xGv9n1c%VQJw{%i5j+{hzUX_=M#tMSpzrgxJ`rh z3;N_yZIK}C;V5h+kPW)xgb3bZ@qw;3xdb2H{dKDvikgMq)U>nE`p49SX*K_u8Vm#2 zN49^}{5KhB)+Ux~uSJODehZx|0-&wAs>|>~I(utAH5B%L=;fp+`Mj$wISbbLyN97ucdKi%BC^v`*gA-Ow;m7ke zxJe8YiSlv6@1Ph)**aF((7n>(|7}!2F7y|?7OZv`_W*-@7u-Ho9MikZYjN@%^SI>? z&DGLQLQK$swTNFX_F$C2LOpK>+F?U|5$MmCf#Y2|E!ZP- zzhO+wEJPkDPl|HcB_sU1uYphURL|O`p?Fm1DGajYGYU-jiFwi+8W1iV&{p=3LVF2J2m2aI4xnWF*9 z1r-@#*4LLNqHF=+i$#L0Xqh_5N!MfAuH9>OMVz~5PH`9 z`5WG|RfHUpnGKH=B+f+!5xfwaN_h&s=pi#nOz)$#|Fpo6JaY3f&S-(~Dy|%YXVu@y zT1WEkE&)r&Hf!PDZk<=MR>_&e@TkETSk_lD4ZeVJk`OG~R$NfK)8UmIn~cc~z2tCr z2f;qksJ{rZZv@B1V}d+)EJ~)22;^)K42(Q@kBlw&?}D1+&{e^8OMSsx%}W`5|B4=M z=^0l`|G`6WEEJMEyIMXy^8J4E&NIW`c7$2@G2@QJ!Hk-7QGRYdaZNzSlgCkfSxgPI zB1Vix_#G#}ksTXnp;JH5cpuOi1_AztY3h~hcj-jA2x)Nbbo*SVFkDfV0!g`XF?*=^ zu61^tm=V!9mz;_Fw1VW0!>!of(MaM7aYp81r{4xV0Mm&N!jp7$gK$0(SGfafwf_*) z^0AP-SNXVIwhy(uHK+4IQEYdgAubi#%TFn&KG5$HnX@$P=Mnl++qfvKNq*R~x!}qG<7-O&CL3{Y&iJRehU4`c497xRQ}fELV_!BDUqozslSnnZ z@#o$8xKR14w{}Zk>p44fn2C(j{l?*0)z^=ZgX>pXcoqic%;}v05;Ast8jj*coK{f> zo;BnX7P_I<<_Ya!N^)4-r zP#*nqAWk*xOibqCBVIqcG|!55?b@1m!87B@_hs{3NuADio|H%f)BMIKG~rAiqn`7{ z_wKc&vlU7FvLK4h2|=}ld5?(6WIqFrs+M?V^CB{jxb%sq*PHe}M)QiKLc80VL2!1a zh}$Gqq}}yO(D6ton?rMY9@j=Rq~xW^>%_3$BtD zlipRx-gwL<)nq9RKza`;BlS)8vGH|x21+-D@MJFLD%TIfn>Ps1i=&2@N3$BeZ5Y}z z&prE_CB#`fwSE}>y%y}ed|}c2f>xk{myn2vvTdq~)t(2k5U&4tG-98Q`6{n z*PR;4Z|8CF98UM4h!_kA`$90e(JKf^i}@R&P^L>B#+|F4@a*79$)kJ!vyW#!3Bpwc zcSlM|I*x1s6MK7txNJuZN%#di(pv);pU+y8d@@!Pg;>LwcfBFd!H)-mXYph0uedEW z259zr!f2Ci%7*CQ;lB;PEr~O}-*9)A;m-XZuMlfF3wy>S@U18$4X$~E{0n-fGSjLk zD}pw1D18g!a$)M5*=wzFq+&M0%_f3}#N&eCnO$&=hT2o~`#GU3tGk-ntXOsYy9cqO zP;4%9`xI;1kDo|BY%Tw1OwEE0!Il&(>q~2E`E8bUURX9!V!4P@e{%$$&8PRlrhtNc zVa_ME%drikmrZmvMZ#-~mo`S?Fzc_hTe zzmHr1lb+*$pY1R# z+)8+qe#A{gY2AGsD>wSD+_PdBfPkSRJ1L-oV?m2;FkRwjn`xY`F=p?1rR!c;>F zzhzQW=%6L4zBgSWZG5mBGoe;FltTU!lH!cqg4D@_SF+b;S^~ewdxP@7&u}*Ty3Z)x z!Cmq%x#*vO(hzM_{q*U{-1jJ+v}IF1SmK15%{TL`@9Rz$CUXKsj2|qg3z($!XOG{> zNgAxvrLmgD)iK`Pf({*y8)f(7WALx}H zHut!3{hO+{pD{3Le&>#v{wwo4edlQv2s78xxjl>kZikVdP`hg;06Gp=kw1zWg`$8I z6d4ckhpKP<4MAA&?v7|5nILgraTLM)4@5H6JX-cdBl|6UPt<~u77M2Z)Ik@dcQJ&K zzVm6sfC!z0?xQ~n3>b-E!iM=!3R@tyAWyE1ytTa^Ned#>%#2dAJ^EQOmmGjI4NlEH z@d@6rlEZPTRuB&mM6=NhASs{D0K%N{IzR`ILCtk~!LPwaTO>1ZfLW8TP-VNmCU=z? zf@;(?TKAYA*XQrkD5ZB9(rWS|wovY7*zQrnyCr2}x5a6;2;X`!`UUKr(?AjXvP{$n zKFJyKK7C=7d#s5xj~7iD$XkrLP7&aYhklk=d41h>HjOYNv^f}$5rF(1JXv@(&Db#-g~}!QnMQbrwzJt)~P8A(&X3{X1BCsYZjVhP>3m zr6gJQGD!V8QFHmZFQ;O=!0N+I{#!49RSKWeXYrU5A7SH*1+&UU>gd(3b`ylkTW@!SR#PTJpkvN~2d?&v0xk(qF7>|HEZ;$`v&Cn!8cb2UUSj2N zRkZm5Pj~Ni*Uec@jgnuQ`CXIie{+73f1!(w&jM=B!VeKCA5?s`6ps6o9<(7!y?`Qs z1tga*=C|#1#miY+z!`&3F^l4?XZgXiHG79&2W7R!4Dly=xrfZm^s|@?#KA-7x9>C2 zcbfYqF+LyToZqb$!v)=MoO=Jm&+x5>+;CQlf87GGmYfkXpZzW+k`)L zE$r7^o0J63|Hw7Ua6Mf>EMf|Yf2R6a16%E=1q21oCfNM;p`FKvd4bF?&5Tc}i3Iq~ zs=j>eVesT}hk&&&<@zNMenJi`(#G8HMg{IwJAxwoBvnXkM$elqf8A_$gDTad9dQYc z83^_h6}5qZ&UV?b&+uMp%o5ArWooaO`o$7*U4o$C6t^`j8WD`aPcMhxvoLToq8|;K z0?iG0d%7IzG_5&v0B;!uik?=SVyMlB=lCuNF& z<89KG`novoghndHIPV=bi<$PuMtHC9XGTxtCg+OLY>{<8>(JQtIsd+a+B&j3{(k{5 zPWn6osBNe(Z&HsVO|uTu{fQN-9MD=1g|euZ+8>*%55~7)2(8RO1^4x);VABKYCje zZqDI-_OjbAZsM@0VV=)*APOu4t$;BZN7pI-d0yM_ri$ery-9>j2kR)God=^&&iT@U zg4QpkpA~T32|BVMJ{@hPI%Tl{9j*``!q#^VzL6mUM+SJMCRKZC8WB!z85~6 z;m8yvDj?|KR3qF%Ak#cLZ=3KgA$QnXHzuGL$JdVZ^1)aD zLU(h4Y#->;)YEFR1*~YH{#i-z)l#0!1ZtvIuGXiGT5iT2(X%gKec=wwTc1bI1kL6z zq~&S3-|5RMlrwW*kL%QEb)Oq60`?03F4~(*{=F>AGxw#DK#(N9Q)rtne)SbkbF1LxfEI@XauK#9>|1OJ3u@G(4wKeSwPsf4M66 zD6+G}Z_^(8VEkUwH80~(Hj}%d-=!qTSAO|lZAf!M#5O-=ORp^$=)Ol#SX`!JQ`V@* zlt}key(X7J?jF@op_z_DUCzqQWj2z|!X*iFxFB4zg)er{A^`a}DeJ(%1pnr>#gL%m z4GUtt`I*`g(6P02xy_F|9TB2=7>rWqRv!q+X>0NL;4-=+y{p=5P2JI9;l+8i6x(0% z0i5(A#E$`_*I4*+xmO zM>|Ko1b@B3hElElAENf}zfPtW=Rx~0u#LsTVK9j3AsB>Qj`Y8t4?#4{oaZuMM$ZGE z|2Hk7XLeuLvx{LZohT!(7)>`Y5ckRwX{5iL*_3yaQ@=Wtqn?q8l1ak6YcxrcN&+Y@t|XO1Gp%Vn>pkY!p|mhT_By(Pqty~y8bBK;Vj;rld1J&q)dj6}FyYK*>t0hetD z%~y^|-D*Sq82DK@@>Ade_ety1YP(Tx2}bL&Kef5ADgXxDX@E`}Kl-$%bs|M2P6(@UJuk|_*=pW=Es9#H(~ zxe#@OTb6Y%x9SR!YV<$H^*TZiZS6s&vn9&<#Cx-LvAMt!s|Je;uh;KA^VT+ zzV*iZxNN$5+a94(A9>G{QvGy;_!jYVqV0y<`kzTvYRIod<0Sl?Nz906@`>sjSbyG` zsQ%){yrO2C!D;%Co-{vp`SY_x>1C>`h}jn|C0)Do5xd6&r-L%?Zzh#TYP6`SxaZqx(civ7~ARW;?jN{dkMuQYKs)n+RqJU*GAqUYrCMRu8-GaG$Ki@T=cYNK~ zy!u;d@5`1Jz&y}vMvJaHxyP*S8{bsenaewzGvyG`JGSwi$T?vXjW<(;Gw-A3t}RaK>wmgG$==<+Uh4q%xjzs!@ad5fea!<#LS$k);6<>Nz-ZscE@YFf@-Q$32auVYBfKs zmQkXo0V?-P+IuAQDd$e?oQPt8*W`G!&6o5|HvMc`JW86Y;t%A5!k0#a7`OpP(~V&# ztX7PMS*tY#PnO(#ahxk_*D`PopoG|b^K0`{mBE%mD$c^$56XK6`h0Q^$KAq-x+b>I z#JXWcJh|O6eWhIuK?X~abIPb5R}t>=5o)Q-yq7QhA>hXRrsp~g1V32Dqfam0dw_;N+%6wFL{}E2Lnk^vkO+;aP)`6>w z7*W^$T}Fi^EK7A>;-tWcWA-D;XnwAE&z^K%oJ@CLsMxhAh-X5oTa+DBDXc_G!{dY1 z#Tu%{Nyh0(TMo8a)xD|doVs#PUuCQ`mrzXdM;dswZ3c}2SVvgPuN}3>??#=c20oI7 z^t-+u)7>g6PWuv>KJ1NCW7RfxhUU=Xv2b)!+x0EuPXP_QGPsM0ySkq;d4j`s-wg!v z^~VP!vQj27s?Aj_M@EJfDPiE7xSCzq6JO%JNy&!Lh3p$Kuw#g!S}^rs(1rr@c+T!J zcW{G3v~!f$kdfJ1MW9+qPxQk%{_8i_=Huw`aYuuL^UOiD-o)?ZC;pQ~Hx0jX7vhBE zD3;(N^_K&EB>ELBU-;b48wm61O>xPz%(Q2%jH%7wEPQ=C4;_)|byR41n=Uy;@a!jF zNUb$s=R>v5S%rHKN~f8Er?wJvC$zca^L@8gvz^=b_GLGQ6C8^~+KJ052=Hd#gmW(V z8=Yj1_cw#W(Orv(i52*k_mj^eNf@QPwjWL(YC~MO19k02N*{6=B9oPtI-?w!Q}r*f zpYcCvI@lInR8FVpKr3+4SbXK(R^#l3b-kuyMjGmcnH-14J=l75BCSvP{M3FzD(1CN zfDi1&F9ordw#+u#YLToPgY*xLiG5J-!szNT@5QUbS0Vn}4=cOont3ZbAD-~06ZVjo zDviw$jh6KH*Bnfb_~%h(;oZ@O;}kEh4d`4$cPdfNuMyko)A%prsfbR`)`&WFntO0? z1+$sJWTi-qa+SKObXT)ey3Lm~B^xUvoZ%q-Pm6r3`XqwIhfO$5Du#c)If29IcE{^x zAu(|DH_81{&AoYZ@d|4(@W9Q7ulB-vDnrtA!Bv868K@+KVWQoVLcMfL=W~-x`(Ne{ zKbiu*g`YwI`%q}7B3C=o^0e5LZ6@Rp9%3Bb7LdwuNW+y z>fT>k)^?Oo_uAl|kX1KSo*zi8R1s%4{tAn=)+op{pI^v0;qyS1T-^kgyedfAmZlC$%AMP?3Xs|DPSq$T-J;o{DVX{^L?|Y2unX~| zR5?jJ)3}^ZO9-~d%kkr=VOw!GAqfSY@})tr?T2vZk!Nq}K1WYAeK_LmDG6x0v&2tX z{3FIYv(YGS#)-4Q;|a-ApM&!tB&!mp@qsPeDB-;kjvx@%J{5*Dn?pmwP7M$`k4%iS z)fMO4Fn{!i_63;cG-HYfO+X+fTODE5lP)d&)3D@G7pazkUrRqFo93ODU8Cm^;hNIN z3qMBQlnL8uFc6_T)g6R1wxKpjk>r8Rr4tYgN4PYt-nrL!t@;#gOsmPj++v|T_CTR$ zYyE*(&YAbNz`4W0^STbhE=5yvi?0R7+_2z7f&%UfWf+g| zdd9vsHQwy5FWliOd8bL$CQR#jR@^3>4rkP7cl%QLQYxa)o-BdDuj=7$!}~dtQW14T zc6CFqKG>-19xspB35>;QCNlIOKmW6KxRy!g1CHS+y5ok#`IK84S#)X%6sip@tU4wy zdAB@@76ejw0>;T-u48X)Pt!MODoM>O*2ptyu8hbWei0kN2<)$!)ayGg7=A|0k`l7Vi-C+IJJP z^KB!Jx~WamhS-iWZGgb%rk4=SGba@k9<=K`m!Qd8WEwlrsw{q z(y&uckc!(0-mbM)nlVt=^+k8y1mZcc@z8?1Tg6;CV3kZ}E^vJCdgxC#9bvltkQSb) zbP!(lcP7Y#HoM81<&_lG4YO3gZWBJ1e)^y-Oe#`_4^mhhS4N@Wb&FBjM(lJ5k?X%y z$*s7vKj*a;iVxWHu8%rsHbF-+2o zgZMp(qO85>LL*CrKI|L$^@_&dg}Ps-)*Fe&nKzt#3!m9I8euVKk2>=9{4P z)9ERE5!&+lUfVIK5!Zp-16S=VIh$=4sjIMD2~{G^COkB8vQ&i=mww+f+kA8=YBLCG zoffg^-Qul4&Ync~A(jL;{a_%)oYmq4xdqBNWj@tWbr7xhE?TgMR;Ce@Pu2q-aHyp* zHmRyEC%4t#!)nI7{=oJ9?a4>=H=5PAI`mh)Z(X|k=EvL`?_1NSybd08hJq9Z*rGP) zG4|){?k7|3*-4)>sxqE2tJ}~ruRqB2PHdVs8+u#3N6(T!<~ZLv5H>A?8gn(N3)s3x z#Hp=B<2k?`<;xD3ft}uR$(iB(%?LtzeV?Htc#Jjyo{Mjdk5)ymhAno)-ywzIS(Z#& zvey$`iZmyNw9$@{?N>zU%(EE#dudKDCV6d$(ls=Tw+lrqL?=yZD8^AzXXh-;ULo7> zaeOf-v5`gM9Y*D&Ke2ZN4`nSt~ z@n8Pzg{;?v&RX^5t>&AG@X+L!i%=+zE5GPfPS1L5KK0Dx>vf&^W@+_O6I~cxg(7T$&EGeH;#??Pbt1VH}j@q$*yjNWyndXrOStESUje;27tR*>Ix zv)4ZC$xYd%%3Ba`>LdQ$MgM~3B0&wpvnw_cdio**TaUKBHd}g!%yVRRmOW8AfhOmQ z=y1)6qE3|%x!$WdSR0XTX79e@{D4jnmd*R-+p-@&cnWEI%}@6l0G-WJ(O^xk+u*LB z&mvA6Fz56yFM}3i-O|k`Vk}&aqLptx)Ra_N3K8!7mS;`lA)l((DbSEc|~9r3(g>DQ|wy=!lt^xLnLGsB)C3LUU#uKY-eAE! z-q|`;c+li1(WR_zI6kU-D~V@V)rPK{JeA#8WsBn(lRHCbb2!}LITvvG(Yc~@-?pI%~T zzHcx_<+CG@+PedNXIdf1@Ms08r`Y{-Qv#K14m6ZdH#|6qD}o_{n}0f(xT z!!5>zGsb^8hOAvFvuB|mc$ZZQVzvCs= zWBufQwwcq70OlI__A!`7c{PrNS$8 zrP+l)T#rUMinXpo(eKs#14wwpb2=Jy;R#pq2|v$1o=r&9tV4%}K|3pKki(~YzNp40 zhLG~lpJD&^mQ?2gH?WUfnx_oS%r*rvX$`;68Ym|i;Vv%BSL`is8% zP0vyBc~oy8VlykMJN}$UcP+x+4@A($QztFx@~N6YySDV4_zro?)26J?8*eSPZCa+G z@zST8E(y}hy}u)~Dj)mfWZkdpoA>`B(G49)5K&y4swaN}xKzbve5aS4Zo~73N5}|B zmqhlHVEnTfg*fMZ2UAYGdGc_Cq^Q3n^W2&jw!p%`(u*aNR@eD}vv`W{G7DMIo@2Ad zfDws?qu5ECW|ZoQ#69n_u$b4!ufQ5p5H00#ftr%h5HFV0>AHd;A%$!z)Q*Qb0MN}I z30h5#c7_>@s$f0dL6c+h3{L#EZ+OA&)T^nG|AtM@U_F@LVhL&k>NA_!X$2ZRp1cXp zcKXPqnS>|ur(PA+$YPua4{T5ni3@o(>kOLsrzUQJ#8jYuedn}q)%f$F=%4#++P3;H z$P@SjiMi1-B8tUU3tas#75V*B;IdnDGr_?PRQG;4pypgeLTa21XvubAZX5*&XOREPj z##5LyJF5w|wDG0h9mGWW%vF|8KP-g(lDYPD%9_$`d-k7cF{ea#-04>_@8gVKWvhEm z?vQXJie06ToX!7T$r7Wc7gxvitw+1&#hCBI6;}{>ri^R$_a{GpRW!-L&*f3XBsPJ* zmjZdzH4HuiCZfckURG9{J{c`iTt?sYs=rpF#`Uf-c##VB2zCTNEJAX}>yIVPT}d{V zcnkO4|2mPQue1k#Q}aPY!?0y5LeH5*@0OEJe^Sp7_Lmz&R>{K>_52j~ore?j6|}Y1 zRKSS@tBWO&jU^jtJ(pHOt5rgs?3@a#8`i+c{4ge8Zf8)^3|$tv_*)|RD|}Zo)%5Fr zpc(-UrQ>xE`K(@Z+T^}RmAvSxm2X%MH+!H|9n`%Pvz;|fbLx?Zx6Opbj&5x^+NV=I z&1`!fibxz%I1YNjh+*erQ#~$RF=VDNXD%qTI=;dB$SLRDLiI2YCB2xtu7=F5?iqKx zArU)rQKkoUiowt3m)eB8piui-O*#wtxQ=H9oQ6+lAnB6bOVxq1x#bUl5WEw%H(#zO zLk%%%0|3yrJ^1<7Hx~l}{P_uPy~YA*-jLg6dN4Ki`D>|;@Y=1wqFUmt^}LcKvRh=$ zK%aNJ_^ix89a|*ry;Li#RAp@OW<}ySD9xQbZ@s8~UqF3{eA6bmR@S22t`nTX+{VJZ z?6{g18@+~pkU39pQxcPBYLp3k0Z$n9dOns6IwQNgplRQ)4%pPDU@A-xj~rorpC`QB6T<%rkEe;1o_`z!Z19~e7M_}XFAP} zv~gB9=O|+kqaH{JutnG^LfE@|^|`Ql1BO4F`R81R%;urY2p!L5OQn#-0O$6Hz4{Wy`g0Y*|nnuxJ#&RivH=q=3D#|+F>8ZLimtHjxQ5yu=18TD93>R&or4?pO z+7Zdu-&|so>%H~-_>;H+V?i8pmP_zhD7vG9zzb$5JMJw`HoLZM@y@>UXGzYfk+kga z@W<;OGA=4Iy2 z4yBV^`qGh|YAHCWL?aerVbHZUY7W(C3&>J6EKn1x^4@>!6Xum}VX@|_QuI*m%W=3W zMQ}S$z|DLkosVrd(=rb{Yr(PZh$z94rJxe6tG3TF475ErpwGtChAQv7SY_;12V(E0 z^!uOLqK;L@r~(_By2zsje!MLf#ETa8V043iJ>&`)S7uVO$vyRJzIj5DB{q-dSs2y* z3v{{COOt7^4jY1hc73eKb&$NhYwVlb6+1zbIDS6g=+T;T~21AjsfhGN7O_- zo9d?R!%S02zNx;IiTE(ra~l=S>D@DL*_yY~%y35;EM*uYzpr>#$aGY>NDidBNE`M- zt`Rg_GA}-74cau?6Y%q`fkUp#_gOENNAK15LTQst)oecZ>KPB|lvoo!A~f4k z#P`P3mQU>L_0=ua()6>xR22DWrxe0&Wph>u=Equx>f#bp*=IkTT_~0q2@$Wp{j0KQ z`>nBMWK&8_QP**k`c!NFVi2afNrHv1QuIToa>KtA z)i9*haW+KhIyAS8nA{K3R#eLOJ`KP8VSd#{GpRHCrL~mm`oLy#=VGn7A%3gmU@S7| z3yF=CD*9#Cl#WWPa+T633nWcS=2D9O@}B> zW}#EtN|WU__c+F?)yVCgsRCWy7j8)-Z3_J{+!_$iBjjLp+pOnus@^DUw_R_v^DQzn zJx~^0yH%-Ha&F-L6V4DDbVs%e1b52Vz`b}tW*}|Xg(@|3O{IvHc2L0Q`?Rlh)I9y0 zd){}s70#-NMN8Zd7|rh6cvil=>hUW}Fzrh`aXDD`LCYn!BDtv4ffhc#QhKV}e$u+R zKRi(CsI@R+U9pICc?Sy}nvUS9H})*%J@U2*gJo_lU1%b#$t6K&OwLV|qWLSJc|Z%IwHf(EF3WVhtE zPz!(Z=c~10m<5wJD~Y%1WOcXq4|e_HpV?Ao%-`e@V;KqwmxjD=vG!+p(0tlp9UbvWd1x=@x-CK>Jo@wV!3P)CO1o3Knv|~;oJPy< z?VikeZxPpmAvPfkn*1(Osh*|>IU%O&7ItAQ7b4oO6Mk%Q z_$dkuAQ0meZ(o`;x!SKwU*#{3Cuz9n6}DMaTQmMJUw*m_Do=h-%oTZ7%oYV0udtoD z_kdsW2w};KwmQ>oQNw2e8w#;qa2u`iS@P*yq#kOsBjkWtI{-suwjIgz9gb}fgzPsS z*PJ&y{~x;E0;;X8YZtDZ3KVH^=M;BZ+-Y$L?jE3MAVBc~A?+zrf)!2i;(_2=ENP*X zA}tV{Acf-YF8`+Iz2Enad&kdUBpHys_gZsJpU;}>+6|qMxByi1r)|h!@sf_z$s{i( z=#X-T7Jg!ewDj&89xT*s-dMzMVW68AfM0Q39>m=Ad-I;tly7#L{uvOX4iENya^6*U z0?Rdxc?a&dVPpOi*}u5oO1Py?6EFLlKo}-HQOR)Slf>nvkuPUV@_ z+*kHaXn^pI=iSv(wvL@=)qxXnn_Qmc06uK9=JXCB=VVYwBS$KCgWa-WvPedo`nyG^ zYo^{Abf{?gux!fb!5npTV zvGYx?4QX!zJPh_N#pBhHIuCi1kzy%aI3%^o{-^2~s9i5Ti8UCflewxA!@CmYVj(Ga z*EeT(B$HIm|JTSzAtR7)yH!r`HYN)7Qr?%U2waEK;w4{HbFpd6aWryu{ARbkSDYVK zq{$9bchwrJE-|C5d2?phD67HqG1ztFZh^I-W~yz~q>G`pVXqxIRb&FhtV^h~NO|tI zdsHAqBF42deSh;O6X6b1FA{Tnhy6mB#k%3r#?f@KdUa5n0~)mSj9y~`<_)K|kknX| zdX^yDWh=fs9OX}qfQSYgc38g24O*ruJGzaLUHoe%>27)c1`Z5WHFz{K42Gs_k!iH1 zgL1H9RNj`S67(EVy3P4qucf}=LzT3`s$ZIoCD<7xqoU`I?&N-6AKUIyTlAcdHTl8| z4jT6Q(0JzbnW8-N$7|pD2V-wC>t7hPG5A6i4cO}UQ%b!j(+tPLKkh>Eoe$d<`qc&< z>k2W^mku5zlt;-IMSE9vOBSVlb^T|czJ?_H0NjyGY=PsC)#rc)Q)u5nz*Vg<7;ELJ(<>Nxfe(? zc-a)Vh7Nn+;?>^y*V_EFx96I(moz_JcCUG)zC4?fZ-IYl-2)B>{-;x6>Zm_%3v;C^ zKIM0mJbLwOl3+AD_$TFzc=+*W7^y6s zDEp6~?Re=WS&@SjX+aERVl0XS9iO|DVGP^S$<+%*4F1pqJhF>UDx_epRn`+>(Tx0U z&ZucqtEc8eNtc*Y&4v~I&a3xrREBGfuDrXKh;8GP3BBHtFaVJZ);GaCH(+e zkn`5dNo3PPV^F%GaZzEranD{2^7anYGpBV0DImu4s!ZAF>L9f2#GGBtb|vWNCz#sO z2_UO{?rxG9G&fj1!?K%AZ;f4U<#7Zu?cn2rnIoMLzSEyu6S6Sd>DOLv$k7asbF8ry zyqz=15Vv_rJZDkv)vZSb=d=GmNG!h`vhj9pl znICc`{Kz4+c$51+_%|WPWU@xoazrul0ctg*;_e(HMNTZPxW-D)k4oiv1ekiC!VRU$q#7)L}%N4586um8!B7PVH>PBpi< z>u8Mpr?r&vJ;#~7UsI%fYUv4^LCXU{Ou_T9&CD$;^~}~lDCcA?vyi_d*(aIlwb-b4 z9uLI-hV~MzhOjfs<&h6EwvGUcg;{IA6D$mgvAj~`fjs9@1NSzN$IF!(R9|zD`fgB6 z?qjtOxixu`1sG1kp{e zZDRH6jypLde*Fzk(04~01nsl?IUGR#uBH=$e+E3kU`F3r7 z>+A9tEd_>RpZk?7mu$YOLcnhB9F`y6o@TCZQ%SY;fH!>tKH!JGaNbftMdPwxO1(V) zx--*!hyY|0h)m=84f9`-%6S3w{E;EM1-METtt*GzgYLppPxgMMdtieOW%sRpr`}1v`)H3@v zNs+n+A`7c%Iok7<{u>n6%&GJ&CZ=d7i?}VM^`C#xT=;2y}=2#yY=c%$vfjhSkSt1__ z70Cbg*=;ll_UP8Sh7>HdM6f8L)Q)8LU+iVLU(Mcb_|Xa}*^-!^4D7C z>;ESWZLeCrQGFX9EzXV{#<&n47^KFq)mAswCz@&1FY~mg@9Q@2|9*-Mns}plcr^yU zI*z!~mD)`Vn(+@ldUV#?^|rlr!uS=|B+YN$x}LWiseK$FuZuB%U#eMNYZBIAeQqsU zFwMUg)qaW3uUIeWt$fbSmxs!wcXsVN!3v(^w$SC2x?T9#k|SwWTbmO4jpQNBM%~}A zR~=MTiEd2$;@w+execq=+ys<=VL;ksk13c1%C*TkAlg+nWtZp=E|>1C=KVK;QhBzx zP-E8<{li4B+PenF!v~)wjvOWR5npSUP^Yi|3}D6k`R?u6+#RYaI~YdQ^)IqBf7*h} z17wo8irQknf5|eD=-@th$$Yjoz^Zk4{4=ieyj+quhy1q|<5ua10lU-zZ+T8b;-V+Q zqaU7fs>3f{s7!3nrds8f^V6E^Vi=PfXaoR02?|oTvgkp4^{iFz)i zyHOZVOX-(YdTxFSEZRU`l}kzi)q?4UzO*NoI9HFRjfi-H+A~qu$Rv;pIdmW7cFH>I z4s~y+P*EH_*z|xAb^{J;>E9#LTT$!TQxyObnu0{Zk&{nKdukDq4g7w;3`n?<-bOlCxPCbzOK zT3tC|S1I_-Ci!Z(AJ)Bf4?{58E3r4nP5$#_^RS0kQ6TUCmol`RjeV5rj@kSB1f1Em zOCf>w5(_H1ns|B#^BW1T6c%qEECBmWpz#)z!r7}d+L)O#YOFY;$xNN^-1|L_5cqCP z&9#ZRUJzgWu@etgkTa8R}mI z^lqgklP#o|mcM%9SR3jW3(z5d){v9z0qZF5wf0%hZl%yXZz|d@QvF5WGi?n~TzpGZ!}YSL-3%;ecfQPUY>vX!cPQJp#;* zHjZ9ijgTuXC7P7${==vou0NZ@*^!jPy(G{kbFmecplN{h>K-fPqEC;M9Tc!jnBP}X!@H@)vuvqOF9_+8fSkmSeihD^F^ z83%=Im(6H*`(LhdX|n=@VJw`P-lw*pvc{}9`Tvoj1MtdTwA`>#w)ZvZLc4pg$=bMY z1XtVlQua6FuZr_ME9_&FxJNyA-Bac>=?wsJv1L;Y@$&GF%oij%^SJC{Lp#T-VJaJt zn>`@`UHP{hRmbZE$+<<}xAZJ{msUuHC(i$NiJxWTPZbvPdhJ(~G9y>GR>IV*rT>SE z{yg^2i|&%kTE{hLz&huPH=x+$Yu|;)Ec*X=8-H#4NBzp*_$cfOgDxAhCwGgV=BaVO z90a$>xY?2kVsfcFFJtY{2A`2T)5*C!r|~=nkiX5wYy%vKIIrd~01plA;yab(`Zx6! z#aaak3-jkhuBZFI4}S=$5Ys-hpTApY_<*U&;|D)D(r!8a|NT~Ty_LMrKCT{lB-v)K6}Yy1Jiq14NO59T~;RdIs4GaytR@O6jFV3*pO|Cs?w(c>nOs zf0JqGUnlUt{}dYduX_G(V(J3^HXxS&{ilbk@pmtVJ1_N5KkOr!4^DgHLcXr$F~?ut zdK{Wojy>KZy*kN;AGgB~i-6xb_{GW<-6=La#CbX5a$e_hKJMx`?rMqW#{c|`@t2nG zdVLmzpY({*x{j7xHMmbzgdCv3SEr*DExX;}#PlJ1=`(JVpI#0YY5|4wi4=Z|diSYS zq9VkS;R^}hAnnxI(529a5KKvU;_;w-6mgNfA5#2(9&p21_NPO4FbAtw`d8kHmg{NQ;BDHch{QJ2-oq-lJt_G2MgYbPaoI3YG!<{na`MG3V@biBouDbKAe8 zzrOq#?@KC!VS6D3H1{YpaHDQ?eKZ|-AV76dV4?j(2P z{QKZqQvddA0!n3q?|tZF14cd#-3>Q57HSor3EnGfm@c8y_GR|kEs@f(-r0Bo_)8Vt z6%s}v-&fk}%42F%i*>{|oq-8S9-=a$bmlmvl{X1SMuQ z0{2R6)baq@3Swr5pwjGzWI&M@R2Ob=WO2~z=|%mYF*q}C8j}Op`$#$RDFgFq8KwZP z!kiQ~YHhXb{rrf%T*H>^WOzY2GdM$aAIuXK0g|x%m{T}olKnqJxE_dkWKA-p%R0-% z)?3A1G!;M3>`_9aeRh5T4$Cr#->~;uG(gRh2mv0^kgELYqZQVZ@WF^lqyL>m-}NMJ z-w;lbIh0AXH8wc58ML5X6uSsg>G0H$<#du}4<`pEpa)NVArX0XfEDWNvKqdA@{JoG zVV}}9f%hj*0$QnrQ@@Txe~0Y44;~UZNh}0vCj?CpTmf8o%ZRw>xGWG@Nf6zi%l^F7 zGC2ttJxx@%-|9n~YAuSrLUa41U;dWA%)@)~>}Kc>f6@iwAq&{Lp!_NF5TyMIV5ATK z%SfL$+t%6JH8~#14zo?aTFUH)1_E9BT!}ah)B(;9Jw-Kz59<1>zm-j1GKOA$e%S{i zy*M{Q4zH{SeT&+X++P}%J9Y&@6xAKf$yWRK^A?s}O7Y6yc8>m6!uU4qTZf+#~n5`^200obQhQfG@znaQ7MElqQjN>#V@l;%goCR;YHv zYcJqbo+MAZw`*jY9s8P1A%rl-J~ zDA$E2dS)eFL?l5A0^Q`WHn{XcDYaiAHk<{rK^0F?) zpsg?YCOP{I<4~omG?Dl>d!&O|Z%OzwZ>1e#rI*+C^G7ohtKlVx_8j$^5)Ay zo0MiyaOb+6&o$nX3I7auC1vjw!gXC(E}4saLXKUL!z7a%1zCG-f(`3%MXLJOuu;ZtxAR76T zE***-2{A?W23FFG<`?0K*XzV(;g8&uU#8KWmkPI%dNI}H3p8vT@mzmTHG$b~dyu@P z!M2Y=@IKmJ5QLj~FZ-FiJR>vI|FIfPUe1;DExO>HzYq($t62+svEgxVqqz?Zil3z@ z{sspeSDA|`&MUvm^Ly7y;feR|JUZL5maCWGz=Zj%CvIF&a#(KO9*~M?Ul9}QR|})q z%LAabd0)ZV=cl6;ulj8Ju4Z>YN3whDf(svNFXqz9%DMKb(s5hz=ky>*`{GDK5Xnqx zmA2|XAd%bjE7>7Vji7tc*o#rWXsu69tvw}Por&~OkOM~PU;hyc3vT4ti{k}-%pHukyxMCJvJNaJh)}vvM919A z%Isl0ryYZjtoAq*#fU`DjDW6wo-Pd58^x2ft~!{MGf2^vST6aO70xP#XSa{jwlP!6%Ke)m1>4dmVT4&<8ODANm``~?7BIi|C_IV^ogz~|s zd7|@WRe60|;_iZ+n&Vkg_y;B;ja8d+hA-nd`V>P<$tSOyvSoJ7mW@D@r--HnC3gNn zO2W!P4S3yAZj?ZETmM7vWR_lgA$@e$WTAU|aSq@=DERLCXP@IEn9?dheLuu!@}WH$ zLJrklS(dfmsiO>MJi7%PGW*z(mbrZuM>B9N=qTj{274$QAvgd=mJ7{h5yMZX7A6X? zpi#`MSB}YgQ3W(Yu+jDlI%Oz4p}TfI>utvhnbsUkwG}1C{OVE^S-xAmXFO5fUVd57 zQ?ffni|zj5L8yFBCIH8+ukRHp3-tUytxoczyx56@uj5+VNJjhM9(5p-)QfqJ1^n|Y zYlW!Yv!6^suLuUPf>imJg$ARn<}ZgKYG46Ym?a~9#ntuVMX?qM?q47Ve7YIb$}D!m zOHHfhLWuxGb;!6j{ZQxmvBKhX09%e;-pql7VeE50NVrIXn#B(=RauP!r&bo_^g`tf&O8LjlhLu z6H9lU<4*Xws*!(Wp&kEPdp&4Wxx>)Z$dXPfO8z8KK9b60Da_bXGgXLP#-|Rp(?N|d zU;eeCOxfcTN#v@u^T|iWoNq2#_^0m8Om_id*{=*7aVMJb!$ZjfPzhV<$Dx5mI)J!R z^97iWrlkryIpc*Y8XXZ{mm9@J!P+Hu?ZtDF4#pM*M~D|5$3_d@ zC&XB2h9NlTY8tP69t6t86q@ zdXI7e|Am3^iof;NdKD7+UMCZ4{v5LE!}#9Py`qxVFLFxxKg;aFD-d@v_kHDoR->H= zQs|!knsEye+PI7^Glv*C%)82L4wczn<$HcF_-@voM>-`|E_@uTdb;MfPu~3%y!4lz z?_P#RmfT3xWotb=$8c(c>rFQZSjetS^~^hB5du@pW48ql=ECXSpY(MV1cjwOy*?yo zqyoHE4IJ;805bfQ4fy<4O`IS2=gG7>=(Po`s68YaMSLDE?o4|3$qKZ>nq%#QbXSVx zFN%9g*ku=k^pv?&KPe?&9O4DLd-DZTwa~az{SJAV zS>PnZLqV)Z9{z~=s_J|cPm#Z2Bn^jO_V8>S4i|74w(r(GqB5Xa{YglJ`CzBJHG$dV ztQapBaZ8RYL4!ATtz57D6#e5{bk$)w)+E{0KPU7saay;Jtb+LNKG2LmMucw(q_ukv z@V{1b2hV($W#ePJWAhu4qAy9<$DWV}pwQh#R=1sZxCTkJVB9O{W-?ka;gE#kH1k6} zm-Z41+zYE_rSJ*8*pcrEwxKD^F(S&sd3MIuvRT1BfeoyA^JDGpT`AITs=RYcO8hA4 zWS=u39Cvk_z$1$OoaMZOyulgI`;BY3&Kg{7wwmo{*|zfBIN8Gwpd*I#dFPkV1kvCN zqiq54c8-2QM79oykewYmgcTsLxCLiJJxXUd*wipA#%_v*qF@%C&b}0JCHVSG31bsn zIm%POFAY^$FUkew6~ix7=?;#Rvf>Zh2^^ZEPZg;`7AX_tbN0nEA+BH9cT+US+>Q@$ zwW!Q(ROPwuijZCVg?<^c5iCc2!za|vTYz@1R29R`~>9yP!|ctoWu$a!V+7C+!!sGV7&lMaMrXn>8H z<;(lf0-2patLewduK?-fI~nf_0nQ~63WHjt-p3C=Boet3lB35oG5gvH5U2FUy6w04^mf}DEO#dT64{RI#D`-6KB zopGSdwAn{~Y^9ZVTrO5C2+{t$6O@|WzLG27RZv*y&*mzh}ParcQ#{7$EHMLP_LK}O@*s>)H zYlCU1XqNPg{)aV41t6SV6u!ug&Xo3Fq}OglY*Mg>_7`1lCd!`<+_LgUGn4-Rly`?_?6{b0C*C(HUFfyoT$B!m4FP2|4 zKu!eZ4-48bK4D;aA{ebM2IFd`k57Qom$;{{YX8sx`rqW~*Bri_5#nb%AcLucipfiI z^7C6K3T`3#F|{aZ6P9+wIG3i_W5Ul9wV&Ho56f`<)?np)a8T*%613<=9r1#5{z$P_ zl-56fVKHYk6j(v>yT6(fDYEE}4052nd6Ifo53K1q@WZNJqyz_OP33ay+DGN@l+im) zK41Jj(piWN)TNp7m(NPdFbF{RU}u-l2MVx|5u~9q{I!|3#0FK-Jkn^)ZhTbFf_kR; z4lR{-Rn0Raig5d$oK<)Kl`8yf{)l1k;pxsq25R9653k#u(1SVjecs<>!?z$`;(jU& zgXw)KEJPs8Z@W!dHNtP2@^91~UKpaxc(=!*JWQ<|Ae9p-t9?+|I?w6x@3>|kQUH#@ z)(dzgNKcRb`;xTsXBoFk3w-}p3p<%8)Kt$vBS#4D<4BEC~YD8VG8=mbAJx)l- z_M=zuxoejCq|(#!@@v)faCI*61L~YeeSUbFvoykZjH1A`M6;`&vZbjebs)UUFEU(_ zs@o*?TlpJQzF1o^NuNJ@jqDX@(Mb_L{Larz-H%%7!13sc^zjTPKbI?GT})_Ng1=;9G=+bdH$d=8sWBVJbPAl$9z(%x`yLsh+E) zqV$D~F=DF-y9BLLQPZX40q~l({_pyp&eE94)m5t#szy@vmxX8>hc@R8 zA+)CJWZ)Ok!y#i-#}ZEcH@oy z?mi7^tGR6n(5s6(u7)os@+!=5dpkRVON&9Jsz|QI@}dURhrp_Q-&VT|>6Crc2hn4v zqS8ZFVDoF6HD5`4#Yx@aY6aBv%w)2ny}CMQ)%fYEnq&fKeJsaL!~6lj)M5FBmN|~P zB8gP_P}hojBmEsyq7dYWA)XKyzBp=5Z~VEE$9PQRbQajb#KTkbGycU*-cCPta7%C| zcuMS}z~7f{h9%|1*a&X5rn zJs}2ULU%)cC4;;al&cs;kw7;PUa6Ku?pLN;w&R&^ODq2v@|<4fgGWd7scn?T0-yGV z{+lN}fG+4OyW>&jg5M~QHHk62YYbI#nB0_EzhP{P{8@=O7*#OH7m{k?8;{~qP@g5E zg*=xW_^Yr(f3p=R>;iF3c-F7p0`ouVyHy~~`cNT9?!Z4gcs`za1@Xc?(ZSk(s!mUv z@xs@tox3@Wm~Y*EMUhl?9w+-eJLkaG9Bw7`g)n3H?M$dT?5~FW{!uoV3Ud7{0VWlP zxidaW0Mn_-uV=?o9g6DkAK!X(2?_&I2YbJBrYX_AsSbV|94nS&=qT|QxVP`^c9}A` z&+Tqo2!9Bek9e9eRM;lQ!f~wlM}FVV(@+EIvSMG(;_`+2>E2zWmZmfU12XG95Skn> ziW)J#=qFFk$mq-K5^N2{q_{JvpuDO-ntXhRx(V)~9LvhH8Eo@NEXa-ZdEL82c+M7! zHG$}86(^6`*Mj0T!aBoup(X;2H&s=&yQ(bs!-@jhMoI&dirFh!e{?!_wEYRz{*Lxk zIDg7eUf4mkcuZs2MCw%V!<5DeT!~&L*O8gU$$puU_gaC(@+UG9Tpo{_ChbS0aHVaZ z3V&osZ`khLMHer4nk|e>-69$7@EURna2|hUyXFpHXv+@UZ4i}jj&1m8GwBB6xAY3< z$!Lvn>?KLG)s=R}I4>fLY9D1w7LP8z=fc~#foHp`GePX_W|;%J0UAB?y6w7NcOY|#A*7bvCqwS<=-X_FX+P zf1tHI^Ll zc^1VYpPy|s>-anX>MPyLO>5=D3y$Ns0{B%iwk8AEYbdR!4I38Es78-}o&%CD48o4l za##VYrXh#qZ*rch**%JFw+_uLnKz-xPRz-eI3dgeB>#n%^W6G6d>*c_P-dRn04a=p zw5@B~5_{~RKsk|eF0QE1E;jAag6C%C7?t8^D=Vv z%L}wi-XIuHnc0@>+_u*D%)F=4F65x6BB)lxF9826c*@g~>KTQ-;`;lMVSE94kKF2F zokqJ4?4a?7d06t!-$U=O+$=`uVG?Ww2j-D2(KO2JimOD=^@{Jv3yYl#jmCtxN2};@ zh651gLiVsZy;#!E<|%E3rT*Mfp>6P6eBmOy%Lv=Vhl~nTiW0+A;ov$cl<62o)hhHv zY}*;ZwGHS2Fy(D8?9duuS$U+kXAmj%stA!D27;STN+#;bSvslh46SvDCeA ztBSU~p1J*qY}M2R5QQe_6CnQj-->IjVSVv}nd1J5AnMAiurBJ~s{ozJ z^m2n&AT!5)VlkPtrLb4f^3oN#xr#`Wa!(_9`zhtP{VBTL4#t_rMXcd!@4YDuz1zl+ z=bQj_Z2MIf*mNo;nNq=SjHUayv8$vS>zgJJai{o|_X<(Zepru>tx>MB8{tw`PZf1Ce}E-3a}`HSAol$TC{(NNPlkJ^X`$d$zJ(|Dgj)SCxokdZgNUjEeQ|LHK% zxOautf10rk;Nn^bb+TWnAk!^8F5dK|if?6c6~(U7YmXPW-Pjqi@X$&Z)5^9S?BjK) z^bi_Y+I?U7Y#?H5xgEA&r^P&3Cw}gi1BkVm&_(}N)s6jRAa7%eY4Te!*9b3xcGb%o zbDWdB=-BV*DiB^rYwr(_Rtjp%iSe!^x}53VY`?p#D4N@({L~Z!Et;ZrIkPR}AcJ|t z#omMcFve|iJO6E~t_XOG6q-?$zb+UGH)!;HL4~Tw%H|sw`{UsujDqX^`hKyiloe7* z`q4}3@+gvY7DEYfn}xHwsDF->UNqPTd?S!1!U-#k)sC(xt9P*zwsA@Iw*7ge$CJ`I zb$lG;;Et7Yk!ETx(0uF2@REJ?j-P8UvznA)Zl3ZTK9^3-fbRvsu7PibBkjHm z)CcyS(q`f>%;gAhXJzJ{*-yFTX6nASk`9%7EHV<%kaHhev8Gyw{}$^-Z;;9lh_t2( z$g#^)OIGa7z})E#1WGv6*|FAYw`suh!$@(3Q3zcgtL2!iwESbe9wy*&y$*%yn^YY( zCn3h|JdeARELn<;?x9V6yiTax?AoO}a=9EI{YbB*YI|QAXv#sC$v!y7H&Y*UTA@Qb zQf?J=x>5uOY|ZA1mOd+xA*nSnxxL_Qj!5}9`#1+$+`B!<{_Y*&n2hRG3*p)Tdr8r2 zAeX-(PpA--ejpek&^S80ze{gNjowzGQigFGct!r>LO|U!rQiK&Wv6WGWCHQK@akK^ zp6M|T&$B20tz{iY3vQVk?UsRWIwF6fd@kxJA%oYF{19T`FoXd)q5K_q$dH%vSE^5W zop5g}ntfjH0v^KhP>Jg8hH>3jNbR)lGWPChw5ln9JdtuVlCX{vGpEkcWb6~ri`uOl zWiQFIxJbY9T;Un1CLXMhYjJPg*bQ|Ey~Dsr%EIGlT9~~gWHt62MXT1l{NOahWoEnq zieIememU-dB&HKl0}_m{!yZsi@O%ARo5UG3#>qLq2icpdBb`GJyhhBN8ht(&YNglq z-1{40_r1gX^0-re6L(YW_DC#r27Yx>&#MGD6xvA&LfPs!T}M}k(NnQ9h;YXf+Zw93 zDf%&R;AAwfM%sE_|B$v<_0TXUbsf`hrx*PZa`x(R3uyZfZZ!4vVbGx5!t+mjskyC< z4=BVE?CP^Y_DUBc&pS%p1xsjB43*n^L5~Dbm6|3f4JmZDrpaG{ZvZqw#(-f5t+w^R zhE3?hl8S8Ev(j?D8po+s@6A^KEU%<3Z$uJ}cJ7=cOkyvi8Z`237C31xOAdDWw3EU6 zY@?yMl*#LS-{j!czfQhp8n(lOx=Y+^-j_b9mdEZYDx_e36~Lk8SMJusj{2r?hn;<9 zu3Z!x)w_*NE0N-sjet-?)bWQXEr;;O3sgNnL`sha-SPJ7^#72GLgjgEOj+d&Sxe9x zQq@8({wfm~z&3Z7R_W@!=f3)lPu|+_BU0*YKamgq(eUww3SKJ24Vl9Lh-9I1sJH3T zM?^_P9gEvEMHxFbpo3RKAaI2d>grHe_Sp2Z9}55M+_s`MBzH*7otkM4trqgP!?!Gs znB1mtzYX7Y9=tY)hr3bfxq;YU%q5(qu9Q*p^tJiWAlxB8Ct)7-GEd+S(a~idDG%#~ znUB-9Xpe|;#*kTCw@xe+eq7tlpRgVH;b&0-riC-@W|@h(ic$yen__KGMKkepcpX%+ z|4S)wT)~ThFIx@7Kq!LySZW6wN^9Da4O~zA)yEhgMD$?o=O0U8pTz8ynV@%LBE`)@ zi83mevYz2mh$U$sZ4hc@OLx~XhPvxW-|NGOd8)ZWbDM9i-??7d@8_K@&?uC{wZDua z3%7qt(bY+1Oi*PfphukNtn^qZI)XhQ!>2?_eG?%lOH&n zXlLF}iN4gUG!jV2M&ynm?Cw`JT^gWlZI4k3=N;qO9V%Tri&Qlf$PA#(r5G*~ovsWQ4hw?2*jKgHL_CxA3cH(qaE9*udS1VBa4HI=ErllZ3EHw3 zHB3J&=*qtT*f*^Saj)Ya_fs2tN8G3uLNVecb$i56WQ^;3f|c`KAAK%W6E=qt01p4L zFZD3fDqF_N*o7(J*Ue@?3h(fl*Q#}Vi=lVw>T?(g6XIVfo-}3_`Tj56O${E^_sB%% z+SIy!fB#q@p8Bm3sU9sJ*b!{6Hs&($DYVXWIVS>eBNi=F0lle1XQ5^YTkg;49Z#P`6TMC`E-=Bh# z9i~d3S~BHsG4a@dkIO3MDqLBUulhY^2o9{2@uxnU4YJ+wZqlbD@9k!|h7^V}xm(B| z{cBY3FI75!XDMMCK~$=oXWGS> zt6La2oPJAoiDJ`tvGG8r@E7jO9w7=m3 zWHs6Ou2;`Hl<7pkJHHd(hOzb64fN2Iio#x*N`udWi8<(2#*+kuviLenX&B3iw-(A^ zK?z2{yYeTN7V0K#)K+&LxjM@QybNW-DlT)|o<}5F>dF3*w*WDNnf-3XxW5C;YFb>G zHh+#)2whlN>4Eb-{Q#sGWIRu^i@hZDb}da(UW}nJM+q5Oorf(jUTSiqebWbiU#KBG z&?n-9c~(F?8&($Oc`b7IlKJj#8uqIL7qyuwjvSgc_z^3g0`j|VtyG4Oo5lI1Cyu7f zQvy=qoZ{9jS5lC0x`rc|b+UQHAHlhy=hRx^eD&9{id*s@;~KK+m28dTpV-dk&zleM zjxswZrshTN?u=#=pB0&vHTp35b@Au}X^WK}!e*r@0wA&TQ_>S0J4GcU^-fwL(OMmk$l9 zpLf*uXi&v~OdrJ0+NZYlX+9c>n&_KDLdRhFf}1EESMJRa(3`q}pKeWV1to&lAuh<+U9$a|~7x}ipPhaXK!l#HC+(T;*` zvBB7nttgfx3IRQ3^hZs3&v*+yc7MKp*NjmLfR#Eu0q927s#BjFI;scS@MBjJz$H~& z+dln`y;1nVDEz_%eo%#tzQ)EG__eMEU&EJxR-fwGmRp~GlK|D#SggzMAWXgfb+s`) zJHQ|)BD3aaf{AQxo%ZbetDOz-rtdlgYUz2jR+5WI@!$eB${@uz`wt^@EL^*iSSzk# z2)W3R0;*lQ?P@XuC}sDj9i^HbTezEgy$~MF!VT3s(US#{tL8-YR!S3@@%0|IpOg%$ z7LMnV*StqN`tnKAMQ$vFrZx_;v`N;!d3*W$%3FoAkw z6aCPu2qf4Dr^#bwwdlkcVnz#Y=S~k=CnZ_t{vDm$&R3e=e9HZ= z;EA}Eku)K!gEs1#5Ys^(3p1H=cA)jqi3P{wu7)*R3U8@w4Hf=(&UX<%FHoi@zSNMx za{R>hy_&G1mn-LWt=tfepu7?N+R^TO{ho;eztVi)k}6Z&wa^F|ig&N{UHcQALZneetcJ(()rC*II-MDK(F@k?2|LEdDB=%VKI6s8#m-TU^^npzsq9hqMLlv*crhL#toTsFWOPpWrnChKOXY)Hf)G!(ED7$Ubu~kEM*6}Y7 z8M6uXQ=7s8C$pp9vjrl_Z|qg2A4q`}8Z4Jp_NK7|K+Y9IgyN8>M%2}WAe+SyOMZF!=Cbx?9 zs(3*>u%vnRvs@=j0KGJ}ClW=)@3kUR+S?iwW5Na?dCL zfW`_iZcn&YxFF4eFtF#K{qRHfBjckC&o%-Kqi-2B%(hv9PmFl7pys^@e|tEwL5*TK z(N1C_$h`F(z5A!x^FZf)%2GLfs=^Q7eJ;&Ra>_+4o%zD!RZGJ zN;n{Yk{efa`T^Zne5$rleJiQhibr?Xz^!JIBS#0XoZTo&c$T#lQRCc!TRsIyX<6jBXCQSg5x zWkSpP%0U8IE6oa>Y4eP9%u5mF7jqdfw_rQ85@=n^2iOh~H|9*T@sZFYknV7J)TChx zXt&D$0&u#li(*Z)WcqE^ws=eI<;_ znJthI&rgU-#^oKa^@cM_Dl6`dnWG$#B$ZU>%D4o=z67Q-&SzdL|De36hd2xttfVAU z0%0`!NkYVh19avN3lUBT+qLA&7iouftrid1<1%tz{}GAiw}Y|0wVmN2fN_D?_J4d1 zur8p6MlFr`f&GUf^1UaYX2a<%rP_(^&f;jZ*CJ=_%iH^N6bIG#zE`Tcjz{N)o4Ns< z9%*i@pW2qNSiumuoRdOSr5>=^xMbP1`Vr;eD$|g%w15N~(`r?Ns6W~ferqA5w;9XR zYTh7@yj7_iRm#|2LLs`a2MR9}0!qP3TH}NxsqA~b2$D7yH*J=NzP1s~@EYp5xL3$c zBg!0xSu&&b=O|Bi@2CRjyEw`>m|vEKH;4dG@ZkPl_QiTV-f`pVDEnVSBLoxDhqZTE z6-<1o^oAc~!OhrVYlT_@XaulhyBh#(;@PKKw)v4pNWkQ*jJ=2(mPZLp-Q%m|`UQ4B zE%Q1&UF@0g{W4`?>Hh5|H8!_b(5mrEfpC^(qbyLzG3J9>UTaFA#ExbPRO}+n#%R}B zjsV9I$;!j=O~y~Iet#9^d8nM*i11?R4h6&t<=_y`n{1(}<$}m}9>(e6-^@l`%N0@G z!#dX7rZjeT%C};Coe~#^qruw$8Y3kw(FYbJW!1U9W=3ul0Qe0txd7;=d9pi$EV+`k zb`XQkxP|)`X{bPVtW<3htyWrHu_oht0W@7pjDXDRyy03S-KR)x-5Wd)@04y-SY4HX zl9+;$_EFpmu4HWj6j;V@a>5(`rdld*st9xBHfhQ5(rdfG06>trmGTx)r$TNDACUf* z>V&rwhyzI#d!J4GOL{7Dc0l3;_QhpB81>GP3N}I>m!hGr{RQNF(aV)PW9uivJ(qgA zIR6~tbc-%8qA0P9zXtLYtq408q;YPaO38|zZ8j}gt0WmXrO1etZ)*}beeN{AYr1H7T+q!CK28v|es81EjE<|GAX+BKE6h|A`IK0g4jqkGjZ zP|HZ7Y8rPChoXS}tle6_y4S?`2S6$f@u&UC%?>}2kYBk?o@aDVpR8mO;bGT7H6wqUb^7y;g&DG}wZy2R| zCf98|n70EZ{%isG@Bd@(y@R6MmUvMV5haKyh=72I2$EEC9wjPa5D7!hIp;i}0z(E# zB3W|I3^^zxAX%7!A>&96L(cJisQa9K-uB$O_1?Qxw{E@p$8w7Ao3(m%_v-NL?(|jE zM|nd*P-AYo9FQALprkgbkuonM+ezo_7Z$G=R>1?xD^YU(HcE=&Xj)7Dk?M;N52e^w zqKnDAj7fX;& zfd!enT!V;?Oqdr5UyoLnTsRePJ`>F0jm`5eve&&E$C-8>k%-;4d|~rMe=71m-G{?h zoQD?;PYxeRo(Dh0iCMU)3^ma0dP+IP>@dOe_~+?R1SfJ6`lX#xJ{;3r%qOfdP#R`- z4LJyT)i@k^OLb2gqW0>=32`$CVXSgfrU5`=i0dLzYsMYtoXa~9==^YY`<1~r9?{3TDuC9&jTELSZrL2eI5<@5QlZH61ArrHAf2p>VU78Kq8=w zhA9fK?|wN7UUDF0|+^iQd$}TF;a^-GGc+f8FC=Q%!+qAf z!D1{GYNR5;x@x{llGG1&vhJ`V*GsF*a^>T|r5A(8qlW5d`b6aeVJ7jaQfkWmez^^t zP$gI=^RJuM!7^x^<4`RAGSW=sH1~?BREL>OQ78cQh^=Ih=vZGGjbm*tEgozFs0=jr z)2C<(b~)f5%*L`uGyx+&O_atTAd+aGI4yj`TYV3y_vcd<*+s5cLNw1~$L~v@S5$&Wm#n`rzy>88D z_P$Y>26QXwefJF(buXDYf-b>!1ol0rbxx+9?O|ono!H7u-WZf$E(1?iX7=+jMRxtk zAo3~$UNw+*9<@>C0Wsp13_)CO6fb#CQEBctP|=yg>AhIgFqRxJ;$YF4h0A>v=ypO5 zOUr!O+z$jxDub~Ovz%pvQ@iO#R*vC4KTuo#^}NYf-U zXwR_hTaFGk-;t@6!;R21@i#+o0!DiH2o zNUWVue}}3OMFv<~j5VdIUEnDwxh_fSK?Soo0JO}BMwDjvb6nZx8WyGcpIt5o#OL4u=BVjT&?K9MA0pzSaq zud2h09u7vqxy5Ef>JOb1;bmq}$B2T7P@1b$39|Sofm3R5O{5Sm#$xFUBtG5WtY#HP zOs}CesFDq!P+)@P4D#h&;SS?Xm+CjD;MetsA}^L^hTpUvn|*#k^Z8IR`8t_4oa)+0 zU&FQgpj#?0);PyF;+XmIWPmGl`VqQcl0mFritA(DEmQ8n#pj5NqN9h1mFY+Z?mMxH z7vhRvp~~TlH&g~LWZ$ILe&R4Mq2?a-F*RttR;NBu8xe92~y5SpsuPS&`6?3Exe0xgoA~&Tx z-uW>i5eVks&!v}o_pPfN2-fG2O%?bE;CMsl^vznBwcbEK7c4hZE+ikoXN8pu+*+;nl(=P7og{&RslS z3D1n>SEC8oL70@$a&EImiPKdoS^?*a;72>Pk?1usYRry|Gos7N(|xmpsga8wkR^v< z{Q&Zb3qC-Bpvv%SZ$YPDH(6P*>L)JIii{Xg;m~NFuOLsfc&@$kOc71rn~@&q+DBA- zBHb;QAv@P$QkD!a5Qzzv8HojZ-30*1Qebh3(ei}yv{?<+(W<-(&LRI((X-<%UavGM zht$G>cRd9+E$(Y{qKG*iwwC>@)tY3L0Y}{#sx(SXqqjIvKvP|U6AO6}mn-=!Uuf#% z%Lu-4J8}LFQjz>0GM6$LZrJFG@e8=94P7Pj2;fS{*8|!gjAkDK6)rO8bzfxbMTvaP z^SY|bC9cZ&nO9Z%Yf^ITh`$#N*tP1R+I^i_ybu-^i}1SLxuL{W|Tl}ds-FH2LV{s;YFCz&9e4Hjs{ZzrfOQl zNPzQ=pr)?nDGnkp@L+4+(qtQ*bwn=vo=tImx;?_x+>G)6_Vkp%NjSQB_aux?^aQeG zFkIX0QhRd8Cg>tg<;CLS$JamE#L7k zp8#JQE)P8LuTSy?pa3w}y2b9|zrI=^`r872ef!k(HGt)^NPK)=p!)kGi2G9w`eDvX z41ayTQT{yE2fwRg&%b=#i}T->2K4*hzVZ7>;GgZA|Mh1(Z-ZCO&ubBXe};X}g9iWG zY~&ZS{94=p8ybJ(MJ#Sj@11V)tVLfF-ofqX@cV{C`jZcSz5J=^`JZ&58`gB`Zr?X& z81=tSb@zYz=nl!XZA-lO2NYBHGa4@&uk1)mck9f%49>^A-ac2^CWSx>HOXp;BA2V(6PsMAdf#;Hgz~2 zgPV+;d1y|j&%blCPPM0$XVUUZmV&KwJZ?m>3KC>JzujK!meyrFG>}=*yo?0lUf{q!b|uB1B;|PjlgRDgOFI5bf;4otOr6vG9R}V4v%4ocnw5er47R#6PWk|YhCE0jIWR8^WS4lX|YwylP+osw+ z(W3=I?+D=>pm3<^>|_lh8OK5VQ|6WeV95He943-OvQqRLu1y=Yy*I8?Y8%KgCc2$k z5Y_zZl{Jp{3T2+_2J1N`3wg0H3<{L{Bu)FX&;KAF)TmyqZQ{I0FthIlLqxL3a*2l84!rA^6)E2(aZb9Q(+ zBcn||wc4zsE{qy-ye$o?I~h=f_lc4T-|rWq1&zR|CP^pRFM+>Int~>#FZ@2;4%*3) zU7W2UZD1;@IBw~ml$#1IefaKZ@kry7z*9S8^R9!KtJG^D&Hcf-q7EN{j@o)VIDcro*MHzi+DbB%h>k~n5+_>heFnXF1?}9`ZWr^eg}(G3`)BF3gYS^Fnk^~qC?NO z@O_N8rh%nL@QANl;J#h-jo7gczc*F2n`U_K^>MX{k#C|x5vSc3x&w7~Z#QN20F40*k zwe7_a(Ct3+;U*4Kc^nxE$NHjn&KKTX|euzxVmAk9jjG;RkO}ICl~(Lc6BcfZf_>Ha-z7#{{mF;`vs!_E;D_!(B!YRH2CVY42N`F!)AtRc7>$eVIj;P09vL_ ziXP}QEYiX&sd29}E7EBcb?L0D5lmMjySC9iOI*Ma+EXsQyLEWr-sXK*@ z878Y1LRWKS9YUMF5iE2>3@BfuA1u>k=);rUS@0NX#`@iqe(@9e6~E8o5lP6C zgp&8S!P+Ilc2@hA{3(FOiQI#g(MmR0q5+lT=BT&cEc$X9><6+@8nsy(J)X&8$QOll zXm5zgA8FF>-JvXG<~FVmfh%EVtJGuOZb3BaZGO( zKV8)(|5Q{Ny&J|#A$NOrSECEw(6p|s>pFF!P-nOSE8Srwp&M!BgB+zgDarffbCCb z-?PZio+R)F+U+|DB#`d)h`X~+$;bR)1%~45YC`a;0hmC5vTICLqJ_`9oXt=D@rEt! zHWr50Xo?ba*A_i?-&%0-9AHpdyc4c)G#y@uHTQ>vP6lzqUZT_sAvsyu1*~;BxnhQh zJkzb0W2g~|8h1#e8+O1ycd>)C*xhY(n>$}{Kj4F?2!m*0qVsM*lS(z7c4{g3yB{8s zTJAY|tc0!BG-+?@vd>}g{EyG`5UcKVuJI%(1-ajs$y1+JPq4gGqC_-tPG7{-5nz{; zgoY;_>2M`=JF;ZpDx5q;X@_%o?_#y#U0i*fi^w2CG@$w`=z4#MIJAgU^CEbtfA# zqNuf}LlIFl9 zE!>VaGsF109h>7?#*qyb7)8^G9h(RJDVg4e{QlMENK+8O`ktA8bM+V@B2OkGKP=aM zVqAxz4X;GobC0i2jwGds@_3Pw$FR^)B8EO!)U9-G#y0@GS0c3R;pyCiE5~zL!j|D$ zQkIP;liPM)S2K@WpdZC57& z)#_Q7dY3SzJ*a+k`P146;Z>ek61My^nZ}ep@o&m_tqbicH}#AfQFUg%dm_^*j1!OA zJom!L732gqHzhenLUMyQ9)(eR!EBpl_}@1roqWEkbx5ScH;pWolAr3|egIfUXZE$W zY*xyOGuQgtBe_6-={ALU0mp18CY8@NrE7^xo;RsU3u==`{%Ts$HLp#$N0&%xh5d9J)^g4tv=cMCHh#R~XESAh3MC(N#g3L4!1l_TnipCVq~A(u0mD^Yia$`o zqZ?j5s?cO9a;4^)TU}9mvh{t{psZN8rgH8e4Kosg>sp+oIRC6T{Q@nwV{5o}eN{=k zXOhotv&@qfmBB@UwZ&@GeqHSwN5@Y=(Hx=!RnpO(BVAGsNb56PUr{2Jk}Eh?O%n zLs>LLh{rR+J#z(RRfGL*VFJ$jp5s%8F32tzzd&B(XgimdUH#=dp+=$orpQ^GcX!2Q#=g#4a zvU1au{D|u+F{b=sAIdl_MLakchYNS=Ru$7%;&Z;|Whfuua{HRj*VRsl%1a_jJnaJ_ zK-67heL8n;tqYp@3YpD-3B+M~{Tzc;dmCO=Gqj80(Xj!kexw`IFn1 z1Q{c{BZ3GObekN}#YGBXMIA9WK<25D_{lCkSi%%_0MnXnJvMGjgC{CejNxXtJm~;# z7P+vA4CpSk{r5#B8_jj6S-8W*38M@6ow}uf?wivDDdvy1`38HxWKF`J&V__+ze@x+XWUPnG~CaT}}VYyL3+jjmz@ z{=)=J%CZ~7JzFYYn(!g%4qI>YY$BzXabkPBD5|oRdxO{aLJlexK*#yJP3oL1AtxH66%jO5}cCrf4CU z);r3vlXrQAL^$_iG#leFan9XJyC;_Sy!XPKF@5|&qwQTS!R3bvJ= zoI<;4&mRbD?UM@EoWh&mZI2`+aWNF1Oi92q(xfPrGp2c9x zFr&gCpj#{DL{53uHAR)9;h|gN6q>fM`x^{@LgCe5e%t%yNKB=T4Ytol+o&&JzNBMC zwZ!xWRuMhyq&Z2N`8Gv#yY_B8%TGQGQbWi=4rmRNSeS7T}A(Iojw&^q3h&3X=5 z3`?O_x}jqBnv)$gm_K9LpY?c4fl{O_afz6NQKujQf>HSjPfU2sL%h-Reu1U=dC6Rw zqOJRpti-To?qY=mJx}M8iCN!sXeMOf_ZE;HdF{Tc#g?!U z(cyG9yuS>K7SZ1Bg~g?tB(H+dafSV#E3|!-!k2ix%cb3AZiD-Au%yLPHtLDnDT_?V zaS|SE_1e0xLj7Vq+;;V=7mzXvDWQ&?jc~8zgk@8M?aNlKX4CX36a!>?1dvVt+`jGM zV#He$EnsvT(R6F)b0)FKt7vvZm)Dx!dh8m{`fAn0`&nK~C!^pk<3lh$Iwvq}oiBxD z=G0D+{@HW7qhM-PQj8tf+xY^{O>c`A+wK;-r`sDGeiw_iXTlqAXwOnC0$jMnZtD|t zrG62)l(|2*Nh@M8G(smDtFo?&(6I1EvQ*~2&FgFqM}07Q7Su*gn7hXS`PUuB?2s4= zh;yDzec8CUq!u4# zUNuZff%amT)2E;jkEQy_@^+Pgy|9$!l z0+F($x0<_nB_CPuyI0A~Xn>(92`v;Gj4^*>9(2!sWf#lFT-~`Op7M8wRjHf$EQk|} z8i5(+Sw3VgMCRHloVMO&BMr^7Z@qXt$aII~HyO4Wmg?oDrbKeWxsrBiyf-Rr&Gp7~ z-R)Ka%^;axpti}uD*Mk*^i7I3S;A{}TUX?riHVpz=_cCn+F|iwWS|?${p-tx%_-F2 zBjYvH*v1byL&mXSd4Da%IE_)CD|>vBnrg;eF_IP}NWC(|)P8u8oTft0ka1lK7Jcwa zh_CyRTA)tP{ZZt(AE~X~r?dX7ep&qNI>n$v!Eskz%>F)XZ{Gib$Z8?Yr(NqNf$M9 zP}9sQ-(Mbl$BO{{=n1&f^)RscyJ<*Ej^#1xl8tO0z70!^+Lz;djR^r#jkBvHu$?ki zo!lv<5(pEWtqYKHB{CZrp}P|cL}GH#0=Mc_<^SBEO=zKs<%k>z(wlj09f(+A#Pv7+}BngR}B z|IXsac-HcvRN?xgS+}EAE>6o6)Lo_+5lp4wPEkg_K*j^*qh){0%w}~-lCvAX0Dh8F z`=*a02X&7Bk_ zVVErT)ie`tz>wbU!Zpt%U2VKw-j?Vr8ox=*o$Nk8yj0-u`UyvYs7f0{$;>#1w<}g8 zBj7S$?Agwn1W)8==;k)q%bLWQD939oTQua+PW9)lHK%|^w4iX)zjpH7 zkZx0aS@sLpanE6Q-4$Zrf%iz**fkdwkC*1?DoIo2`tnv1IoKBmf}97op_q(UpHY4; zVxPMXZ^*D2Jd2#{7SEV;*hAOcPi-(csOJF1O%{RaLwfB(l-DmQDD`?1m+h*A&x@6qQpi{*&$Jk?NV zJ6E5<%`r&v*Tdy7Ol9BKvIv_(r&`DM#AWitQLQ75*_;Fy4p(3b@y_eme$(cF8JD3$ zsR$M7;nMt9CWD7oMB3DJLJZtxQax&s?BeL5!aN!AF$i0CcX=Dot5B@wO}$Qj6T}v< z8T6NQVM?u(0t_{YY`awUsF^XJZ6rB0pN&?vQGdhYv=o%PMn36?S;DQ|b-jr~c!Sy% zaxwuYNiDOLpWZn6{yix5b81uC>BPRUh0c>|bf7&+iFdt2i?Z9f{{t%bG@}zXR18ZS z{3>Ghl;5Zf{YEJzFT4&2{qi7+q1x(?7_Qk?AJJeedpi$r^4PwjZdjvyc1F3@RQ4n2 zp){Qc>xZaM!qk8dWh4FgLZk=~w!kMzKHcj1d|e!!=3>zjSD})BK*>`#>22I0GQA57 z@zKcna_<)TVk>Yv6zTb3Z$1SADW~166WV!+0gp~vW(S|_+{+hqW2*W7qGB%TB;9f_ z^qXux(H7x!cAsXYQSzwz29j<9h+3WOT|4UFx`&v~o)hff*|lV)rRBS~ptlxHM*^NJ z{b9d_GUO;3>@|8>wAJVQs^e`MrlE0TB!w~V|P;PiCHXvdJ z3ykuWqP3rW8%tdfjr>=r5~q5Pn(J-+@@TPpBJ|aM14J^T4U&x}zQ@Y7cAOxc%}EUM z9{RERiH|MC`FMSw_)RM;+Ue5^K6b6zCo5SGqEhQpsZ=!Y4jKGxz!Iuw-KGJs?=>?S!VyWO4w`+ zAJ32^cbk!g1)V|O$E!T~(n?r*WdqWXkZn6!sy)>jkoJa^QLW*UJrKep9o$ep^xidf zDoSuP2}tt4$_Vw5U>SAZ#8s!TF{WMje1qoe?xzfBj9xxNKWX zb@8AmBpv!0q48!Gm6PZ0dSJZ+4QXsU`9e<4c&kh&lD1piU#f9%q$Gudn65u47y2>B zRB^Bs#I3sbFhw-=B)q6k9#pscCig=puFgbX{ooBbUHV!k$N1omD5oR&&xDWu@?;!- zOK%shCNTSvY-o9ljN$I30{@J44HTw|EjztkucewX2_f z3{Y8nY^+{)GQ~y$E!nbW0&Fd&3eeGXr|z!Uo5=Qqof}JM2p}SCvMC~aT(BZ0`|t#t zGOBqp>9DkgaXb#<=Z@!Bm9aPN1@yp6Yx!O^iTYu#^acO_1E>RK0Os^k& z`}X6_MBtf9?&pB+k?)(Ag(pgUkB4JsIsP({KK_Jbjsb~ITxy~mk>FLP8Bw>-6~f(0 zpU*ZaOOUv~80htlzmlJ~hxPce`c9xeq%R+b3&*Kxhua+CZ!VL0^E;8Mr{{~QY%jC! zr!)~D2J%c7Yy|ZA{)((Am?vVk4>mk~4iffWj0U;@b7le`C;fZ`e*kWAn1khUpsWAk zf5B3~xvvFZ!P~2#>#sCyuEH3wyX!4>Z{GlUrr$q{<8bns=~f9HR{3H-I@zy9uj zl(7B(D$n`9Aea3AFYVU>{xJjpF&Tz5?M*nYmcBz_e9!N4_KB4; zLyx2;_nlfD4>uJRpZL9OC;SPf`1Q7rT*DJEB!$g>BrqGKZ+w%BD=D*C;Mgzsu~=?} z|9@Z!Rzwlz!&5#F91=4XCbpGq`Bj8-GQeRLzyJcZf3q;qqxrK9XOhFjgNK|z?n)rJ zZrz#KYBrRA%DjyL3x#4j>_x@QstZE@_HG`?p!j{M%b(`9zPB-qJ`X_M1d%U27|usX*VMm+92t&S~rV!6$MkfomzTlp5E30wa8 z%-uAg7c@=vi^Cr@eUhR|xfs)l>u}Xqe}8l3#rbP+9Q4m8pNbI@=N#HZZ!1(k3YW`% zj_7MwFTigC0m#|OLTYSrna0SX$W14}9_Hfq90nJ3enSBM|~-rIk!pnxa`2CN`n z)BBcyT%HF;U}xBliU%{&L!OgsdDI4%jpNV+qF9!5cdT{ztHvD5O(39JJ4bXldMJN5 zpLmQDZN8OZ*v>KD;F#l};yPGht2xmQ&a0Z5@Mo>)7RQLFYwFHM%8XoN?+cw(C!w=WX6jWta-A*kaR#Uzv#V;ww(A^?7nO!5M zMy(n7U+gV-@c-K?nlQ=()=@HmeIF>h7VMFikV8Ny z5VEc{>3#OzuxC|^>uBp)Szn(v#M}mmeyTw8f}3`~UpBV!b_!)w$U}|S+Sursy*Q7S zN;AG&f5z;0`NMCa(|F?;pz-=IX6b+_xmPb1IO+y!WgX_bff3SD6SJL3X~o#F%?@wL z4r=fjr%z+l@|++fPbxaKMEJ1MD}k|S1PEfUaNG@pIutlSrk3cmJGl*whXOB!s%Ch5wWCSAmHA>2Bckwf)uBG@#$VB`R6=p6o+Z zAS>PN-Pw$L(Blf-z`8CKT!x(8SdaL;O2dwsQO@j@j!bP<6E)7}kx@>S!P{VU3V$na zD<^Ahzsv9bxI4yX%nZ-U8tCSMoX)xG_-aHjnBlr02?Q>=q3*NNA2clZjkS+mfGV%9 z_j3zONDI1nF|)hBmH9_+Q`KfFi z558Z4V~og=kR^J*KdyurhSUdnZLqo?AJYNJuP<4y0@?>p>xptsdZC9!Kz_=`ZCy?G zllgvYpG99dMTw)7VhJ(R5qmDpBOT2nA%!dSzZv*Fz`!@y0I1ebp*n}+#lNH&Fbqm2 zcf6EWrhU%h0fl-*%jJXUJ%6wF<_fM?JT!pr$xf?v?6`EYIf?>dJ{4UdHU{Yx6y8p{ z#=jUod&b+tL`wDgHY3(UqmF>H$gT#4T&2Xud5;RF25YFCzubKx9W zV=01KOSk%Zcph{sPLLk~rU#e9N(Oa(4E)?%g!pT-0ac5*8oxDW(WhE*=O@+X!1BEj z*xZocjCcX@5E(d~&7oDhm>hgnxy*lZq{aaw&qQ;bY#|YIKTP;XCmt(b9qqY~Tkbvb z_Tf}6_F~$b-$<{YVr_6QIHdxTl%EziDi1h1(EMb<`+qk)em*a} zbX(R~nCUk~Fa8~tc1{l&GqZ<0Z2wXnwV3UZ5S!rb_=*S8t-I8so3`PCaH)XQ>v7Mn zI4Av$2P_^Q3^W|J{zbnc9spdI`_~P4E{qoOqEHX<>JGIktC1S}X#mlO`_~`;Wip+w z_&>Sv?@+a;tahs}3GM#dzW$}|{sVk>eh%!PoPW~d-G3NF|Dhm$L9hO#w*NsOiwng+ zEz#GP{*KH0Pr3hJxuNgU?1=x9_Va(-0sYTyD6IpAT;DPYZSYnM;XWQu%ve1iW%M`g z@h`6ZW`$ThrVDM@SiEJve^4zk0Ze9q|4s7#b<6#CCO)@*Y(b@LsJJz?!tRo@b$@0M zBsKYfYbu-qPyjT4*DwE)BeOKjj7Ki#d@CeYz-Q2sLpv@c)orAD+8^WhGT@JQ$K#~K z{CHNfwPiwupe@UD@REvEYd60S$*bBocTsYG5-%})DsYa;B$!xxtlC<=d1=u-j<(T9 zxn}L$@I(JyPyZ!$e&IYxbyc>6!;{9?)uquowzA$kpPIs{5L4+O zWqlfmtI)i-2&sZlO*I*`<=R1}fZ<{ zU2L`N3j2h=e@Ub$9^dW_PgX~3kMR|2J*M}#wDdZ9Rjolk#Pf+R zdbf!B)Oz!?P28TjvdQ8D)&V#)dX)bQgoHRp@#d{Ur&a)z;dt^xy*+G&!-UHF%fVJ% z{aEcZ4cuiGqgWOhE4EyHDE30hn^ua}XL*1<)*z9N8oL|L?-i9^N?))9Ypn>U3&;4m zH2;ZB^j)dJz}Z)vvjOaIlO_Zzq$B?%DSxu>@Icp5AilrcvE9-#j$OOXYB3)&Rb2Df zR>U)s&lU)AD!Q}fTaLk0SW2C&TRE0^O}ca3msWG8hSeV`K3q?r6iB37=Cw`2aF-0k zuvT@)X}U@2k#e$Lc20k_a&{!-QY*kV z#VdftX-Hi$K;_6gLp)aJg4Jr)H&g{+*I21Pu}{k?Z_;7<14^(7Y2(RCE62f!UzbktR!YFFBXATCYG~L#(<$Mm`=3iLkc2eUUD_!g8x(B7z(1GZ8`_ZQ8yC zfjD;4<&$|Xt*kalg=?!liE}AV^$G2w(SWAY!WY{3Ekj zduL4wHJ^Ywj}J+7fv!hIo>?i%y^)(kU7@iu=i7oCHc>~(I*JpmGzK6DV@jHiF3*nY$o8A^PA=q0t_UA*n}|(VI_C%$tvqr zNTe5`^yHb$?8D5SKJY=?g$b30m8&_WaJhJSa%wQZjnjn6v62;*t)ZQ}Xxj0QSZBvA zt*nALWm>3)sK{60?+da(47kQ^F`rnoO2y}G{@9apcekUF5U+#a2cQy@x6&nbDwY-W zl|p~BZ2oOm<9@TF619ZydYaAxscO?^vr6Eg0pD$`+c60vxL= zqEWj(w|?U3FDhS*L7nU?Ro|Wp<`9@=RDt(woA&G7~t$k zl3(?*e}2ALX>P7vDj*)vkd;S&JU!e#J1To@NPGd8fULK7Z$fgti?xq2hDX|U?D_8d zhJ;&Eciax;6-uB;S_VK}?T;$*_$M0i%WD?zcHIWgi)bHc=kdLtB0c7hCJ!XeF{5?R zW(JB9Mo<2z{4SXC(+K&T04DFG$6*qi`^()==VDv%Fxrq`#re~Vt#YOi00cHIoS1SO zygWy{0-Qs<+-j?3>reRpO4MAY&K$0no0!LA*kDOX|I-ooYM1*u2 zT#Ohgc~TZX;8Dkpe6uUZ&j&Wy@K}k8$2HmHGN1!={-guWFSqQ1M=<19UvT}wqVq__ zi$sd>oszVQb`O`r6zAtW^Y4P1bCpRn_}zcR2AJ|jM5}WFu(*-)HL>WR3mLrDe)_+j z@=x|~hI)GxQXF4*MM}{Eo%cGnMCj85IerL-S!aE_O~CGkqHfriV+cgJq` zf~eycdjMQ_v4i@G82j&F%|9+66dbC_w>E712)hJiB@3q;rE& z=(*w`UQe8BAF|GQj34Z7QcjYO&7;~`6fA%rs?v|`RF+v8Z!p*yD(t!pLy8_HJ4~_0 z*Q4OpC;6Qp3lCdzRME=PW_$pG`=7SA;E)}`;%JjKax`aN+d+AcOJoALicmRx4e{YzMoZ^@kcKs}2jYij z1f3%Hbw7-gytHW^1 zSf&bc{YjFC1aRk*rM$hv zYxQ9WVw&4UgY%(%D7Z^o=@U?T6!;GhD%%^tqtS|Zyli`ePs{&gx)gD(!Wxq9PDIUX z1+>lL=vVl5EU`Dm!DHy^bhG zDtNIhbYplxR$_T!qSbT>mDkv`o?rif3aEvGw*SKyJB-5^*+ieNrkpuU(yeJ{KUu@T zqAx1B_3$KlpdP@Ke2nypM}gw=0D$PCW%X{Rb3iu9HLP5@d*JzoY$Ox4`2MM zwg7P^0fP?&nLS@5$X2JEx~*}BQ6ln0p|$nISOegV@94#yl*e$rc67@@X22!`S+c)+bh4yE;s)F46Q|uQ$yP zTd>L2*!72(8Fk!{t((B(QwZrC4rytj(CJAL8S{p>ZZ414!KK8kBx-%-p+fQrGKUv| z6SdjDB8hOf;omLPAvRu>FQAb3kF9=*V47qDeZew+YQK3+cbZ^~oBNG7yE3P+9$6J9 zc@WTJ(U?cYlnO4ZqTI%}AOz2CsT=ZVPqHp(2&kN=} znUQFRJ<@gJb$5EK8F4T9ligis?~Jc?gjdJ%Dx~fu@e!&}1LGwK8G0ZURB^IKw$)oV zS(RDy)8&YVfaV(UwOhJ=*F0m(;vp|uZ4YP@;}>pU;X0Y|Y&ppD(YQKWfM*Poj(ISS z?F}^eN}ShArGD_v>6&;;R|Z~^>O(<1GMK{vgZ!Y%aOZHSdQ+Mg{JYSglv_XY`Nw<20HSk5Wd+QR9giA-={+_X^-W=2L?JoE8i6C-A!B)(tg zx%|SgD(Zb6FVG$SCip9GwlL#8WNhBW!vbr4S8d0KTz$mt#TvX)#u^N1(UBpsK-F>P zy$y0`wk>iqq|{Bhwc1=D;W{K;5Tu`IPFWwjqK#jHpFXxh5A^$diYlBc$Q-TAe5uP~ z#cGh_yPJ=vqU@~6X$-4wUUsGb*^9$Fj`2i)XnnYJGk;lV0OnAsj~8mDhzh4mPL}qL zi|E{yVtxz^thqu6@1`1QIH7Cf3%^#w(PH$q4uI#mung;Q$r$F^kgq z&Hcq>@^N$_c;88Q5u-s;WG1(?@A(yhopQ}yVh(ce;N2z5A+J!mGA|R~xzQul0kh1E z>Lj9oJQ*vFSqL0}*^bBNdJ+sLz;Zs6%8^%O`UCxy+e#m! zW}t&zmH`;M1vG>~T(HoL$DF7xKOuN1rjmYoh~Ipu9%!2VtWiS6kN8VO zOH>s$h?Cld%)tKytB2r3DDLIThcMNxS@C6`%#7WU+G}D*?vNmO9HCAX*)e!gABS}v!I9)Y8&$PcMXMhP%<*wn^a*2gSS|)nvs?#fl)7|7%U)*$!R0VqDmu?btC%{wlh3qJg)$yz z15y2%>hBbl%(J5u^?2D8E#FhVSAOM3o8R(Hm>GHWO3}5p+uiHw^+Fn zFoHR+V@dX;&b~=Rs&NKSy=2fh5ez7Ek%S(+zD?cVD6J_fr9^FMnXI@>^EXUr1#Dj~Bc1(4&Vz#Nm^>5qyn`2LF^PjyW_Z}TT5xGl zu&>I34Ff6qdrmGS0$gW|#&^LetE6 zMWXZ>^DL|rsdW}v3S-9VfMFhnD#*!R$-!{wm>C&SjCuIcS9J`NR`9sx2`o}=dhvxR zw{R%Cp4@}i7Xtql?*A1CasGfYay@Yfc{nu{*lo?;LsW2EKYZe8CHCDqZB}5ER6M76 zzU_%jo+J8|C)7_0@p;sGL~AMW67hU(_wZm~RB(G1S7B&7U#`H$7=8b3ByZ8vz%j+^ znYUGUl&!qeuY^?=TU>38*PJxG`9aoAddx)@**zUQOO%0)ea70EXFcMR= z1R7jtR4AxSzj8uNs&X}&5&b+S{(brfmHv4?VLY;i(f+p@?iDf0T~YT!zi5Q4uqq%B zYSAC9opW67=@Q@wQvXp>Ctj2|;*JK|xWbsv$-@5L1f~-Dn5lt+^2Y4^EmkEd0r3LR zK54%e;)PF<>X1ulY{X0N(QMMo?}Un(ksc9(8s$bon<6qA-otLs$s%~ud3g-gWhZKA z@SYLOYU;8iNttCjW1og`DzSa_2@+Uq6 z;`|RPq0hTKTjVUi#6^_eX6a#+u!c!Qq8IP6se_`f%h$W2+Dt+HGxBf8U))rj9#sXp z(n`cj%1eGwiIyEss8a=Vo12>`%Vr8lDFXvaHcxUhSoB}{Afo8|g(W()ls_`xPPJ`B zgYYUL##Z({uLw$t_3!6rVeKA>7iRL%VhYRNx>D~?%SqX46~0~zZq(>DHUjl6>Ul?D$S~N&^mi-awLF^HA>(BM8LcC8B7es6@IO41(X$U-jpE z9+Q#TQ_Iw&%t^r3^CZ2lwl#hJefqyh5fgul{A-v%cf{Kc#^Vwq4YRY#Xi}+H&2Y{q z)E1v<1A=MQabJU5|D<&8uQaEleZF?AnrA;+E3Z!%1?>&#C*&D9DR6a{)qgt0P#enb zzI})p7^IHu_c5W1YUJo+B(PDPQ?&}rmv|CKSy<)iv{x}B97kEtljR23i;|88e0EUp zsj<+@>Dcjuezg{_wLNB9Z2s0=js8n8=FBwl0G0;k+ltB}NdZ8c=V9%18HI>2QCdCK z@&$Qg$;?O!XVT)xo)_`B;*Pmd2_jtgTl&fItP0k);54m<%eh~*>-0{Q(h=Q;We1p< z%O(L5w|&TbOCP5zJ(b9btwKIdSJWhGs%MTLdmDIJ%|t_42d1G)O-V3 z3+UZ?+u?EP3oECF%Aaf)2;zz--w_*DC6&s#X(G9Vj>6ur_YI0>JVxZnHrSuV(1qVs;i0b?L3qURcm5cO6(tUCF!@So{?R5 zNnb3HsVijZznE3zPDR_MShT)!`HvSHFu49bn>r`Ar*8adc&~T7xDR{#)H{`U`uIo2 zcz)zpY|U7d1TgYyktQsZll5eZ;S(U0BX!VCxaDxEe!oa3k4mZ);9ap8UKk5ggrx5` zRW$opV8@7;(>42Gv1Lt#K))I#pHk81AoC&TIY7JncU~cXS;pKOW7f-_$BQ^> zumJjfF9Va@Iv|AJDb{!Och+^PV#_p^CSt#i_A_%E$>xU=pxl3a4!xvO*3qxKQ;>;; z(*t%T0Wj>%m(jW;s;REWHwq(+S`!;)2G~hb=X5x*lUmV4@Qp=}CIf+7eG89DM4Ek6 zl$4H1nAK!uSJtvYMNaMj7Z|_R#s6l3HEGHt@68G|me0erdBngzzL1n@oYn-FI`3^+ zaeZVFWhtO74xd$<@irR**Ibgxhp*d}U$jv2RB0QHpn`aRxCwNtk9?`zxt(EG3(u5) z$P2WjhU9*Ec(>Amg<+s69Z%+w$1PyhlL!H2ee%*q3z-XJ#oS<=1-*ZAwhtxP0PuN~ za=`GT*Db3H{;tBUfXlmLk{bJhP>#($M2nen;-;LVvZdLaLavZ={yH0PwU8m;{)y`0 zWvr)jnv;tc9qjrCOOoJc?zfRgkaGwO+YLCF@?>FzLtus!`NoE*srC0zQmVKK%PJPC zkO!UEu9v<*KdHFlkk*V_WI97ev!X}GUzmf3#Ee_urJ6JP5iBJw2}#UV*IO5bRP^Pu z=cEs6oe>iP zPDda0{O#xNeXW4{l{6)HwDwUTAgtRZt78p25Ni$iYv`0M=Jey5M?d9VlP$SN_ynlME%|Kaz7tFZk(o;gW{D8Kr z+u`(|Z?b$8=h$=ra-#JAxSjlfiqs*a=9wpTyTpn(J$MLnzQ;nIwmPd@e7H9OXZE$u z-w_~xr9|b8WOtw*7}@tY3D;mq06GDa#Q{<#PfPw07kB{lLwU@7B>66ga=IclgHCx* zS{f$-=+m!BEolc22`(&hyZ5W8h{#e^TV1cg~*@7XLl3^}k(m_D`hvnS1_UnQboOOoI6w(vj@9xx&t-pD8vu zeS3yaJ0h;kXmN=ib>WY3WT4oc0p#=bGliDzVZEZXlqZSEcEPmgS4C;4$p7%E)Pr3& zTYl&+N;bU_xCiNf_0Pfi&xmK`7rW83uhR_}r%z9&!gg1m!H^FLbY-qHHAQy-88 zieBVZi4S6N7>}AY!waa3jM668=ch-h{xMW6OT>hn3OzQ8sTgw(J&><=0fNzWn2t%H z%>_N`%^!dM78Mwau2pD;TcX3msH<0hn2w`sHAAdrX3XC{?&^wZRo=6ZHFX2m0IFO;HxN|dZF&Q9XPz6QFR9#~M zr%yeQ_*6f$jkffLEdERdwmLNqNTH#z;&XWXc1xwtB1fr@JX<1J7lxsJPnFPWk+vJ=Q!hBL_}EW_ z;ZM5*&}7>ikv@AtN)N(-oHWK%Yipy=OLSBSI0~lS>ncH1{}*-d8P;Ulv;nirs%t@% zsvsZ&(gZ|$x6vgKAoQXjEtJrEQ4|m`AYCAU)P#g0y@n`NKxz_DdKIaWP(tUsao_jZ zeRlW#etyUC{o}|%?%dZkbIr^-bIx22sJ=eqii#Pj3_bM`m<*5rB#hj_iXwmlVx76o z|2Co9I7+#Ybi)!br@}due6+ld2W>PBoxd2AxdSBxQS?Zt7|++T>2GbtDYF;&AWh~R8{f$%1@V8UR zCF6-SH#2!&n*4i>8(0i*xs?*R9jTSI)BDn%lpPW56-Xw0}O$PEFd^Hm<>V;`vGrdrjRIToucPM>t@%%GMm?3PxHWLi?y*W56Gu9T+w z?A>cI7p3s&tlS^|P;IvQKoexF8f6nosYjSrTem$5NEFzI z3(^!cd}sp3E6gi@q}Kht%HZEBbp3R|ypphr#%b{x@_r5$AX=8Irb!A*SEpIi$^&XW z!U8K;2-h>1TD232*$|`2s>>nk6Dybvow@axJ_BXZB1bXAfrln!{-9s~o0M1jQ?OHq z?SsJOuhH(~1&1o1jU37dn^slcC5Sj>>6X(TU?ZyRasK~9CB#?yf#bd@rJBXGI!+U= zw|#A}#LMG_6oE~?VMcn@OjJz#vA>J-Nw2Mb+Sh{>2~`ru>IiJop}PvUoM1hBa8*i)vp zlh&|bf%m&&o?dulbF^199Ox~aW!t9GgSz@z{R}}oR0s2~1vS86kMLDM&z+s97#3_% zX9@n{Af-^T-NTj&!B^R=du>N+0p+@)O*vKr-~#qrs+6o0h*XQi{DsN16s&(=;GK$& zp&lCfijgnnyl=hbmFnuH2H$qvN=}KteP=wRL_~)C4(}2yd+pJW4gKG%{+Go2UsR}m zzi|A$ucZ>JW9z-uiL2%;WMDP==P84(=%r`$3s^J1yQn=Q-R-4Dgy9kq^~Kd)>Ak++ zX~F$dHv#lmC|R9QVGF%h$YN94+wGTck-e?tFac$Kw3_hb_bQ!#RaZA4O=zI^F;{7O z6a-TUis@d=o#y^3B2;HM3Xtngg&Slp0i-)Nc^`9IOMrS|wNL_Z0;S}~Slhhawn12$ zjfTlOL#_av<&LzWbzRLx;VhMvXlNgYb3&J*Z_8w$SQuYUb>r|KXPZH#^V7O8T(H4H?j~$e}GSH8Og? zWzme%)wq#!a5ptq@6ay~Xjh$lTlTXftM~QyktVN}nXkO7mZrAH32Qp3D+@US7X5PR zLy8LfmDH*R=Lu4XmEm-E>re32X9+GQweGpgx8Msur_|u8FVNZ&$}hf_ z2Lpx1@Yn~O1gKa1v?oxC1I878;z{d@=h3_sEpOYqP>B{JiamT9T^a|UGH++QC= zT!g5be>EHWV10D3J8iZaj`4ixaohtPR{Et!p&{Vj8spt)Oo&Ee=@&BtZJoA)SX5oN z(1_wju{9;@wa{N9T)<*4KFif6hvSt39i1v`lC**0jC%=t(bM86VQ*yNqL0UGA=By$ zoo}Vxa)iTqU<=AMn%*tr^ljgeIhHS`34V{I`J2OAU|ozwpYz*oSAb$2KD>lgxaQOs zWrxl01H#yd=hFm+?YqD|^SZ~0_J*We5D0AVRa(Q?uPueRzaoMYFCKY#JndokNO~u9 znO1(eEAC7%=T9$gw|NPOZDe&1+g#JGJU$kklTFyrT`ugeZz;AM!1PMAl>C!`bKT~d z6B(}qZv6!Ty##{S0s<7cB1GqKJ;`6$$JxYFiWi#-3IFb`9x<-q!1PE{um76l;e@@V z{Z|6k&x&o=mAPPTR?gXfvs;6-cwe3+g8WtQ9f0#4YK&DUv6Gs+;2tu zLc6mQ@CD>w#t5CEsO={AC8ut6?!U^V_?L%`szx5)+XWSsV}15N!)`)Ke! zR_=k1n9UH1f5YG#LV*6!qzoXZqLe2s;ahuW8^`Nvu?^R@=5GuoGDiHr|J)y0ri}|o zKqmlf8VuZbG{P?HX}_nmJX~Zf2GqhVAJ4Q#Dl0KRt&zXqET;qDb++Wgn|1HK$6{Us zTd_8tz@wSGqt^N)g00}%X#Vvi`orzW_^wTxmnula$y`lSxZ~)g=Z1O!F14BnW_Z^B zh3I5-U5bzx-(pzFlEN5m0k=uztd{Z#()32sSU#GKGB7yhly@IX@SBboK);7+uu68a zJKk%%WfEq$J0C0D(zTCjw!Vw1ztf^l|D<4xJqK&>h|gAO_Z)x5C7?{WWxu+^^|0-L zPkj3}H<;HpTIiwBXo>6StC0Z<+zpnDv?{8>PeLXssEkXDOvxm$Iit=C;f!~`LR)W? ztp##7*H|v-mos%;yB%yrOjL4uZEuzn{P>2zJLk5-RX+Jxugg{&HwlR)h@nKah{Hks?5Rbq;kDg?!ubOy!p$xAQGYIV(=FMlK2?2HY-?9DdPF2f zN|F+X(`#FldThe2&J26g zfLYMmB8H_vI607p5xtGyhF+*MHnOCrGe}5K(Ml*ir72p||f)F}v&JZ>tp`0X|A@4Wnqc8?W=iVprwXMeQtwpBkMxM@fLpQQJ2kUj3 zapEH8*8_~<_A=w4>*&+T7l(X2DyPoHUu;!fkQMI4FsdjW2w@S=Sxaek!W@nQdc=>J zhQE&&nwk45nyZ$At*5`4v%HQG?}2D}>DsJ++8BN6GKPJ%gnCc>YBQ47USvodUIX?Q zlC2Tt_AN{{x-m^wD``AH^vYJ!B+Bd5I@O?Q>8XLxh&=4zo2MV%5*yA{EqQZ~CqvW~ z88b127<)&S#!=6@NolNq0;)j6YX0-tb>FDbm?P6=ACW;`qu__^M(e^Tym+4Hvy$s3 z2Axy%?GPvsC z`b}DhxqV&jZV5#*3@S7fKyKd4vP|jj50O`%pAd!M%PATmzqVaj;-p#SlSrQ!Iv@!y z6bx1dJkFd$iLS8usP3xs2zw$&l)H}}yti_K-acfbIqJ|*fF=m|a#a_=LS~qT`2a(*KU#MB60Ig`geS zgnn2(!?ncwd(Jif8;sS zd%%G(M;VsZF9%~-K7>#7EiQ1mW!Lsg=?tza3)y=Cx3>Z%0Sx^>^Ucv;gVZSPXgeg*tB@V^ zxuAMsiwx*k$HeDVhx?2WHBy*E)pt$#Oi%w>If$UHD%{h47pHF`G!Z&uR0N3A;lfO3 z-{eJglA6F~%#wI%L7nasS)i9Tig;NLD*xubwH~NUt%x?D15z?Sqy1nDZ(0aNzxmdM zX`8&CgN<6BYY508D=i&x)Taq7*d-e9D2a{lJQGtTCAQNGDio@&$^mACqi&Y~PkKJ4 zFRCf)1$i3-i2krN>Ky(zbW`Oa^)OUXbEetTeko_C#Vw3bkZju17;E#r(8wc9ywgRM zXSYF8!%{dA5I$MdQE#2}cCsKRhNUw$h$nhQ=S$(~~sXz9@GgW{>4_yWpML)7S1F-jqBF zLvzy%!nEAnFX~)#9|$gksOEXJbk8Uy%t!`-l9r31-0-1Q+9N%*gX2+weO0a7tu(tN zq|)?EZTQ8ab#3eKlcfyS8>VIyNMZo{>CaDR*fy?i;GA~VO|v9*nd|X^s!|d=9NOzK zTQbR6?8-iEORv}@*wwNv^_np3f?SQW=&USds7?dY`qnoz3bDbe|C;x>ql>!4u9O49 z9$3BKcf0Q%ljq8zikzoO6g9K6u6of0!j5*nYWfJpiNQ;Lw@^=Lc-Dt)b&Y7H4-dh` zr!0S{(mW!)_V1(&4jG6k%@i8phpZ|e99s{RmgY3Nu}6h;5Dd*b66gg5O`k@{Ui#UV z!$=4E?cSqXLl({a2268dO+5qlcLj24Qz2uzo%2DAKAh2z$-;H_5>z$k{`~7gi|S5B z`74ugGI58nDF;0))b9z7+Kt((PH621{p2&vTxd~pjTp#BIeXbrQIGVZ&~X(*|3GdD z-rr>M%9-e_Xgv0nCym}K@44U0`1Ybx#Z1&C=c`OEs89=Q6n&|gC@WJ<%G>Ba{o2^< zir{(u_`Sgxlj4mhk&=s>2I(Wpc1MdB%fXDR%+|tdw*C@_sSJUk5*id|)`dJ_r+{X) z;Al(oEQ{>>;1CuTU28uOBl)9mR1|e(qixWq!yOgZqochNpQDI=>E8PHYXn~HqNhdjzk_47^U%c7`OM$hYuG3lt=#6m+M zkz0Ejdr70uim5Luxz$;05OYTORzLMam8Uxsc#+J(ckgc`)6v1jYtY{U;-DWXc2(EX z_a}oKy}TXNdJF93{YxQupO&hrb0+=JG-1q%v4QmV%Jjd+T{I*L^75xq( zLd*76&{t--RDL1ZI=}B16AO>KRiTqjXX zizJtZ^)1%C^>YfKC9}tu@-|<56U$i0fsUZPE9HIlOJsI91h?jKas#MM!$q=63B6!Y z?{<4L;t0A~8iii06{lm4xg%tv!^Tlt*rZ{VuWIVSuQ>qI_p3AYh&?4SFG~$@zC{*t z2V-^%%q+AvMU3`nvB&huN3Zg}*BDhbzPFcOG|VIjIsOoMB=$IWGl?Sr=f~GoRixez zg}*!*Eztk!CH=ii^wC~#T?N)+FF;m^q@!1JL5##GBG{$%)AI?jM;);o!_DDg#|c52 zq%t}ork8{g$$I6?h~ro5*rrJ5#<;)c#IYp=Gc7 z{7BklCu5TDNU;&4R~}%!b6wFlwN)9dU7RX}2~g3u^{r7s%TTz&H)42W8*V<4wdqvr>mP{F-lqc<(YV}RdqA8=6Ath1W*SKYYXX!e&A&Wg5V)Tq&ng47uE$_F~~C+!>4Kqks$03z*&V{Bj=fdOC%Yiv$27kjV*v1wFphd*K_=o+>mC!_uT#>!U1^Q69b z;@0x`J{y^;EiMXn11TE7-R3tV^Em=Zw7TsgbIdVa{Px(tWA6)3sify;-Ql>#xb|5M za#}%xWtfA$^8VIaV)^LsX!b^4W&{E%nfX|K7BLs*71mB)u$I3QAQFRdOL;mFg3CF# z`$gP6iGVDDr69@eekjHTqnTfj!K`vyFXvvA%6X{=kr@)cmX5>&6`2*{CzwX&H9GBA zt$V*CbMoX9zR4);Sh2gNVSXw0`@AJLp?xT2(LXff)Mr>+_MU?+Z7IO`{0n5hv@2NE zf%1`14vI7~ekUcx;fxdG9G3pncKCb&iQ17LNS_DKNAL@D+EoF2#`VVUR={jhI#4+<*{ke$OE zJ@&;!7dHzvZt$&>rWZf<@{w`wi7hdzYH!Z_4#t;E`}uvZWH=+N=w)qlos>S|IUtXs z1XjZBLeFhTnKN>8JPkrKxWkalq#FU;62$#&NJ0h^ggJYc; zl^r3}3N$^BkA2v!JLZGG$%wWM?rsMh_Y%4Qo$tnkF<>Ydm1Xf`d0_#`feaVIgLly1 zPD46sDl5}CUZEc9-y_PupAj-`buzU;*=)_UFi3r0gEnau?6KF?d&K&~S%TJz80*eUZ-bfQ%z2? zI*U2Rx7l7EJ!=tYrd%;0XrOZC%gj-*G9$T6eIU_yds9*wuDGG|!!(POw2@xo-MEy! z^v<6xb8W!R9etg}2%TFjd<(?RQJa@~IVnI@0%KD+$-t&LVO}PX>&Y$b85X>e8wt_d zeJoyGO{(=v&fBTc--5h7t#jO6Xp6sg5kPx9CR;aUf_$m77(7MF20cU7t)Ju+A2C0O z!au$olHJyNQKv7Sc8mw?Fm0v<%TmeV%t@Ucz zF{iP9@E_>{EDvH1XryR@aIyv*5C4dKt|W^^E|zowK?bB`e7u)H(07Z4Y(Yw7;h5yu zrw>Rf5QX?z?0)es+qHF?+?feI(cbna!(mV*_&rrOppl_Hn@L3}P~tmO@xxwnKD0j6 zB8VOx+&$7;Js*~4#8yCpMkZGgi7XCZny^XX#q$T|dhIz@2^{^ zO{5TlBzhlwR5e7{Mk0Aa^auq3`q@YK9IrKYnXAH8!N&=_>bX4)d?v#6jw?a-syVVy zGsaDmMx;#D3e-ilqU@EA*`}}~MzU@1*Q!!-V^h6aM%2yQ#}rN_abhQ}R=T|8q7Oj^ z(%px$0wMu=uK^h1j<3lQbt$hmRgW&z%=*XKck@=2yGlqCovH(QpCIi1nu++Q?2xG! zlkX4_hPd+rpF50;Ow8ZPZl#a<3NW#-f}bd^>Kb-yi}@IGwDBFsFnZ)$kn3*zoCm|8 zCVlxg(J~|WSzgaBAF+-`H@!)rUz73c7R`mh*Qu5t&W^jj zyYIQz?4U4;-~Z@}O$&JlBywqHm6-20pQRTa-*?!9V=YMw>jhhnkiSs+%be=fq*q64 zw2@^M_cV8wAMP!fNYySV8=H3x(3lOg+*|CfJ>We0BMJS-#$pF10Bq;#+O zZ@ZTi$%C-ioK^Zk3E4i@H4AFP2}xf5tqk-}Y0+y+kCQc7GhAm(w|=)8KmCu5y$NtQ zH-9MkG#5t0h@)$v`KoONlCixI55lVS7ESe=8CkCBP5r#q!B_K9$nZqC*_OKW zWkK10EMw5G*@4s>lC+Sl@)~zU@Nw+ODIBm?YvzxCU@7O$O{YjRiLQCWqsvg7Peg9Z zR+y}qN+oF|%TMbA+k(0AkLQ(Nvn-_Ka2!A1jMmC+JwBWcaob`%uC~vETmVViIAn&M zdBM^I5#jNQimx;YT+O_pU`xQr#J$wRU1Pmh^y#09W~}5fuN}+LrZv~Tb668%8D|82 zZB06yP!373h}F1?NkPF+JDQ4^Og4Jea^I@hIJMjgkUTZ8MZLU#PaV6uCjWW=S-Sk z>fwiw<@Sd;z8q(*Wd29saevyMZlLbx*9aZO@sl6%pNQUE-@uOn9C?H4o!p-W zK3QUV^F)K>TTXsDV5jD|rg5%3`q;dzdnQM_nV-k0H&B}2COmU5xe=LpX^EdsUaOBb z-$@T`b`w!9d!9|mxLG|YW1TTX8~#49J^H$V?i<&%B6?ns(_~W+kU_Vzu`;EcMN*%+ zhzeU=Tr}!)nrJjmkKs^aUq0X1{nogo^ClwDzRbO#^Wudt8(+B-C6{IVkBhJ|rUwQ1 z90~F!AMNQ)7SG#R{2*=I4@=(Ii;nsBQtyFP=fIm+8nL1o+XTv@&_gIXF~5B2C0>tB zxc~}?QmpVWc-CPjn?Ka(9^jTk5shDgj#{9HZ+jDX4?p1j%Ifx6*Lbxv_4k45Kv^cZ zZe_GaWQZAfd-Hj(8|b8xSjXFRAWYj}6B|%<`oUpRL`~I?{fla)xso>?9aAEX+fK|l z*}WL8lOBVm1ZBiv{q=f zcG1#-=qrIp0f3?jyxQ&lHdo0UEYIrs+NbQ0;*CA&QmO-?z@P}Uya7}6OL~>EN?61Q z*pVB!_OF}&Kk-2qnFo>S_YrrztQ|xNnAj9Kd<=}d1N;WgvK~g{`rT?C&=B>j^V^g= zb4p`v&#BK?VLK+ps%^TNuqxob_1O+cIe;*YEQ@TUOMX$4E@sl)_kK-gK120kFzP?f zwmk4G5>vWUQ#!H@i)y}c;!)l~l{xQSasf^?BnW0XLZ2Y$BNmZTW5>3X6ztI{oR>E)~J!Sw>;~aCw#|!LBJPBpl!`359 zob#qt>hnv&LlHzNcn9fK-qjz_-ku@zPg7z-J&{bhRsMH=p?dQdvF|1M|90<^AE4~l zCyUoonB!(#YDr||{{CWnjiE9IswWAXC~{vf-u>uM3@jUEQnXoqeMC7It!Kr4x4sRB zO|e{O^IHdyp$C<~z+>HC?-KPqC8eA(<*OvH%38qPq3ZAPlK22V64TZXs*u zK`Kn+bDjl=-7Zg{P=RrB?`r2-_`Y|YMx%P*tenUIdhTkGCp9+s61Q77%WK1`028mS zkMrf(lw3UvZ_>yxCV8!`!yl$LA;|GzY8G7=92e*Q#BB%A1LPU2`A54S9#$-z-k=PJ z#h)90tVoxF0WP5cYYrIjI`SO+?abNRiJ?q7+=-7UB`}QGK`g%Rk4$m2NH)(d=v^STRnOihjc;Bzx$GqqhuhDzmnvj}8 zMRom8!}-4mqf#0$3t!&~8M-!;L7e#6OTE*cD(daiMSuV2$!0 zPEF6#iW!3~p1QO$M*SA6f=RR3e##_-ImP%5W?vHAkk7X{N84M&vuOSUI?KK9S3qcr z#k_rzrBs-KpskqP$FN89)4@4=bQPLEZh1`%Erbk8KhJ#>Iydivl;+b;{Kh-<3)T0? z{~Yl@s%fXrBHPxr7P!aB7Kj9FWkPyaR*7qNh2oa^{@&?&gXOpjAnR9xc@Z#jQy}a3 z1NU-HoW!Irp^Yt2Xqb4K!|%ETcu|A@T9*P^J6~@jh06+Cc}* zzSp+e7B(e0x;>wd!f9Xi%^S+{VY8Xm(s`^_RDm#`Onkf&a&vefbZL(3nhx#?w74wP zAX=Ek^wVTRJM=-o8LA@fe^EC3i1s5IWZH(pVs#ZMoHSYkd!W4zaoAFDp}lFqbivn! zOI=$;OIzEKQwae8J*9g&?t)i4>(po0Tk*MPzgDYc%-47EUux>ziLrA#Xxwz#0w2P-_%v? z-4Cs2DR4Z)p zu|i{|Kp_ZyI+UKyCHn#JQ5(FRH^Hc&Iu@pn5~j}$Vc-ENRXA!;6&c!RCw zjfWB&Wez^zx|rr3s0_&}QA{fdlA~2Nfj9b{>h3?aP^-TwXg^SHv~q06Ub&uCcr?I) zdh$Uj$*my{U=<;4A!6F_3vb9AWtnaUT)2fy`wva`L_qf$)VY!zZIKfY|OQGr7k^>G*F<<*&Wc)M(pP5dA-;&<$@D+yJaiu=hH?ASIj19 zDfTj6dGW!p2qr=k1;U0M-}<<|X* zT%R$3%z#ZXQc9TMa)x9Wb$l}DC1gmuSpj>QE(MF(f~YMlq{-7Fk;pR#Tg5j3R5I2S z)BqA=>jiY!pbf_gSW=evD(uTt@1cL&cB9LSx!XVhJ_bx4s)kKA0i~~sJ7vy(^q>=L z1AI>p%ZaE0AO;{3aqrc0Vd58%9CLs_6n4nVHONrsF;SBi${wHxwS6r)RgAtZDN^Xk zesc+g+yrof$|LKd)Rzgp!a%)Km2?@%2N~J^%{du7+(RkQffBr?K0L2r(v=JF2V$T` z;4Qw$-bt`smxm@fGFW~{! zNZ_R1u|`NAI!=X9S+h|MCI9zXxgvNYh`@dp**OB>KLUa9>^M54ubdkJ0MQZ)@wYi# zG)_PZ>xj650-Lgez|}W=WO(ob-5y&Si@r~}03C=WFNVjUy+R)L{mzD*qV$vZut~)% z#H0I&Q1~G(n;!d^s)z9tG8HV*MPGEnCvf#1EmDVu$TD95Bi=e^%vlaM1NV_cv6_j zsd@T!mo}3N5J?UVS7wuXTZ<1a|N24tZ%4Q2)h0NA8*%efA0s0zEo0O{D^L?TlzxQ^ zEouT|hyb+2jBKxtO5F+!_yQ;yV5+eLXvxP{)_9IJgei1_jKjm2@R7I5KURY|j;3BF z2!3}(kk!xR(6Lo*Jnc1S)W-Op);$Fg{)Wz!?Rl|aP&swRMgJp@I?MZ%=rX^@UUD<+ z=O^;Q2t^L=gK~U;Ip80B&i-~pAGiCY{hOk=rh`eIy(9pz202kp7X_f33<;z?6ZZaw zUSWuu9vI(*e$!;shj|cNaz)*ZbKL+Y?%J_e2W`538sYfw zG+UxZAjW*q*~U=k5GVm)LVXVkPw^LkV9yPR;L^Rt-=0YorZLG!V1WoF;d-tLJ+Utx611B1t;ZvN zc-?-Z41T9ZqUNfgmbeV`UWPwJt8VfaRjEyJ)Um94a0jFVqo@lR!tA`kF3HMT2r-A; z6!tW5`0fkcdg}ktR8@vX-U+K=!ONC1>d7V)eQr6`&C;Q|Dtcrcp$bbZ+48@=^J~U9MV60jK4We>KcC;`Rf<2t zFBYzs7w_-1RLTCuGkJC6i$43Zf`IzQyX^X}2d~|;Pa-KpO|QlgwSf7a`nbdoKkSM3 zgMU}t)}Jvy-RG=jdImQTKYVrmyFT&?bUl*^6J~{>)jJc9lVA_mB*Z0e)aZ&o3;g_| zL(c=b`}C&bL^krdX+Q3Q1*1eOpnfT}FmWa|tbs1hdP_#F|>Zid*oV|rx813qu z@PXD9_F!S?~{WN9OT!zMSSF5Xg{Vh3jWi;o|Gkqw9R)zE&cbkSA$ZRqO^c| zN{;Kc{cXGS%`_%`wPuHbKo7A(SX=eX37{oaH1yYuEC=9E_GgF-JgZz~=4M?32CH_n zGB*VYMmpQYbeSXLI7kXN;{_c3el!vp$L@3SQb!5LTa`pX0FE#eidJ(snq?@=bNj*a z%mmNrxEvlPZ{>t>zmhz>UUSo5W>|U(An-JY9+g0}usiR#tBgIL_)Wj^FvSnG*LBT% z5fTl~TpRDl-#s0xvGJ~Wadq3tSB5`)8sfDI!M5?2igo#(I~*3KNS4@`YR$Gh@a*SZz>rAsM5DH4Dqt8mA?b*uq@e)WzzQMnwx1oK7&Bf ztxB6b){27GEl$7yHt&L@@WE32)^b}E*ul1PiHoeTx2fMh<(*eD)eb>zI~Infcqsds zI|Di3CdQJ>Obr;hq>ip%lL#*;AJL~``_;o5)6PM1Cakf%rT8x?4Ad@8$gq9ue4n)9-<6qwjrv;n;A-F!o21sR(46;W{J>4SX=w@ojJPdH z@k5deSOmZHL#ekse&Cg_pI4ME>=KhnFzo2$dz|C&|?FN=NIl39csM zT5);|>CF4AAPFVkIG0%HJq%E^9qmt`0~<_gZaucL`S@&sI`4bgH;cg_Z-*5gew8Hm zvlgGkJYI~()i?K#b{q;Y%paoJq+LJwv~0{0ujtbOd{f=mJz}XG?*M$5t3e1TqRe@* z?8jSuIFaK`P}y9pE2A?LCYf2%;7#y+WP?GKQK`Kpr2n^X80Eu8SNqsIwJ}HTJO+D@ z0u(M}uugQVCnlD%*vN;~uaCV#-m|XCdCxxj*S&D*>XU{}kV815q40{7VTYo}4=^-e zn5mLg|6`_;=0VaDw&~aA5WibVsBp)niQA?>3Imc3$DdRcff-%%d_Na2;OXZ!S^WpT zKON$i0+0#6YvLjhftpf%UJj73GTlPe{4VHZ%M~n}L(#kDy({#SQzs<2A`#bKE;yR~ zDTqF&xJ-APLn?{ES`%haB*HyPhI+AeF4x{av}J@@o#1u#Aco#Fdy!H}fF~$DGd3ho z+x9gbrGr$>JaUkKlhaS*Uk9F@e#`N&+XDuNxhcF(v>W7}qh?B?W!L`L(!G%;KiOnVQm_4N8De*@Wk_-ls@C!=-icrt@u+hSnK5{6bQo(q4rA#21h?C)F+F zpZ2#q&6VYiv-=y58?PYDare*{K1qJ<0JI_ncQDU!^dmxDS_lUWXo?!NgChmy*5>Z(2BtKs;0aKLazJ%mW7vkcG>+5 zp-VkaSsG!Gg%0B}xqdmLJI4 zr68Do9JC%R!F00?Y<~}n;?}w^%4@(-AJ-V|@4_mB$!6bpoonwy%LS`gzZ=yII3*_i z>?=wB6#nAzTvSH~qu}|aC-#H-GuB{B@Q9eFyaYBot$t>#; z_dk{@?!j>ieoLK{khP}*fx8)&wcpbgtyDv=8@NB*`~K)bg%&wqBxsR~WA{_H#dbMu z@Q)YVh~!k#OBY~%Pj@rz(oSzcu;7@FK19q?t0sFnpwMK?+(}|aGUI}p(5A=KhhK*E zXGg$+ErwC7A9L<+%|JV+Mw`&3&A&t@tH2onV>z9@ccpD3*(D6gpr&}%9};O`j=YkW zd?@@1mW$LXFQpi%`=^_sfP@W*u2zIdFyKc!I0>wCW9~6Cc?GH}R?V(!2A5jSqxBk# z;bD>KS}+8Yyu47u{aIE+hL}4whqY-8yp1Mmys-|Lt}`5fW&gl6Eb5P`-&l`IHs@V0 z0Jx4=eWMF4$cVYZ>sMtnO+-^?QrCyTpr8BPCdcO$dHP+vrwi&7O_P0xgEh@{;J!S2 zPUz;<*yHV>*Zz?6nW~j&ZK;@#qm0ABFk%*+>8%Y?+^a6^?EMxi^^7w9_UM zywk#Qw3~J8M+fQ#FlA7aGt`9Le_^~PJOhIw<=6jD2F2rp5a|SW79f#9K1P-An#d*e zhI}Yhm~&$bW>)tF!2O-XfN|$o&?GZVsD;<-HfgUV{NJ(WTj^P1jHEl)}Kh8 zk}0cq{XTZ_UD_giV=b+3rvIUq14f|3U)x-INBjrM{ji?C2PXj7|Mn-+q?{%z1+mS_ zqWOl}uQQhh^)a9z7V(P>e4FxfB#`+HldZbx7|*34`0^J$ww|X!{!%f#N>3`^9C=0c zD6r_tiXD<5=BnfQ_o60xW=NImwLr%0vCN-X+&Jc?-l3NNeoSA`1`IT|^_4^KV2eKF zTLhwHFSpOqtz+S*F|B$CWDGo-BPU%=#Cn$!vY&7K<`4IxqSo4KJxBGp>`&==X1YQT z#tT?U0S|+Y+YBd)e95E7KVr@_?Ul>ne#|_GbH1@aa99~{SO6MnW97+eV8!*f85zV6 zF5@^HAFqM$AF$lJ7qk?cnQHFw9v&XbyU~#2ZtMT)UM|vusLQpYEcfxa z&EH*)J{wLPP8llQ4j?B*Z~&M)O4I|iv9YmcGu)feRsgwd9TPG-R9sO}p&E0Izbl0o z;X24EAHP2RDp{mqGu|r2Cc3ltGfVUz85cNb@r{7(l>zSW#DjfN07*}+-+VXFK0#Z( zOX4|vW4c#&hw86r*)z$N1>ro{%&K^ZQvFe|j|-gV=xv&PUdPiXGhQEp8}W&^wzVzz zQct!%SSO7K>><&->8|L2VYi;19)|=A-XxE-mCr?Gf8gz*D|8_DKNDaToWPWSL}sR< zANi@%Y1f;F&jDz&OH$rk$PGERW~F*8|7R2{t1eB`Bk3T)gYXX7(=;4guM>6$0gHy7 zEFS3}RV=8~&T-uJNSa@`VUunFaZ^H)4y1V{P7xaW2hrs(ya&xJSAlXZ*v@7yppmOG z+xhaNbMCQITUq`DLr}f0e7a7V|ujNxX2)+9V0g zDF5xCwz4!is8LyZJSik8>-5yEID4O}1W5@MQLu9Da$w29EkmgHL8P;s*x~lzP|muz zzQp%5+K}~Ve`1WELUmF9c{1Uf@k^&_yG}x zOhBJxr}Jvbw06KiW1O<9e#CyDEV7un_CY26v! zSH1z3z`BgqLrRy1<+iJ@IRNZt^bVX4t`jzrs4+%3IA~1Ya@*>DE~BsKwP})wbOm+i z>e{RAF1@91c$L~|x_#4YHBfh;HUcedW~_KvsO?~^%N8*y2hZlS)coTFoe`rNm5F_t^+Jq~+na1zbHT_UIr&aW{-v zVSTPE2dh7hBzKKc91UNOB8BM?#XZ;HqntDTSm>Wav$140F8oGY9vRrpNWC!Y4~lZz5P- zdMh+0{mG-0kab3%pzRL!ok94C%i7Sw?R4U6R`S)P6@1C2z?#EF=|R0xbFoPboq4jA z-GzEc@)=`9!WGeJZsp`=;*#AnLU$nE@XNgD%nl@bO^PigGK7%@w+` z6tGuBh);1Mt#X$51jKJ5$aE1D7WuO1^i(T(Ka`EL#zJ_63Ghy0eVY80)+|I5_)nwq zlToMkr~Pul>B1)0@qW>;qn=3I{yyv*z>QGa3p1z4uUuw0i`-vmDr|-!_Qq;556EY1 zwZEkc2d;NVt?h+nNpyP9jqV*A#kKG!A3VRZK&$ddnkXd48>h>l><2b#eKiYPk&11v z)Ce*I_2pUnSn|8g?0J=xl&#B0MWS<2Q>owz3$Oj?^e^pf8}`=%amkFqI{fe+iRHW$ zS%st^OeTE<^&rBL>;KyFJm20D1^%);-|nn~`F$lHvR=q8jn{TvX_otRG;L6c=(Hy# zHx~1-v_@g)tw5f8TSaMz;{X`UewX=wQgOP zO9fNXRjp0(+24=ot9M234CE8yVr#N;e!h4MqpoW2OkQ4Z4zKrs7~b*S|HIyUM>Uys z|D!t2;D`l9ioyUYO@e?9Jv2q>5Cjr>89}8R@P8UoU# zcR~rh-4k_QnR%V>`rUQ!x@+BgfBuVkp6Bed&u*X3-e)Uk`Ro< z(x`)}n-@vWi!?&zwYlMSurYkFzriA6`x)gqh4S1f_HsMe->Y0^th8Hg5w4uzvAO)E z^nMMd?|}NoHwAW2eRq>@Ugbmv4c8QjpJi*87A3%jMq6!HKdY!%NXg(Hzv22;!S3}& z%ALKB4~I3TY(0&wt#hvuqnB*eFHb-yrexqbYHFe(=jw;^hQ%4cdc_i&Dneiyp;FAL zg9eqtOJTZ7f`RSbr5obAaGj?5%#%6k6gy0>DARgejv=OtO_+1Xwz*tSheX;!n9tw^ zx~B+zftv%ppa@NC{Ue$dQsAQaGlRHLy?McD@0}dn@S2Ek0gC&>x`?8i(oO^X~Jj~ zE=su*f)f;$TbpZH6Cbvo1Kk>XyvObt`*Vi!ip`&^tEw`rDR+Q%?y7Eoqo_`2+Ht;Y zI>xSfYbG>#nR~6%g4v=*HN$0SHg8bR?OdW*KkJBq9hv(8%Eom;jBQOdWIyz$4?ax0 zFE{{icv2T}?@{h^ZKKtB%Eqp)h<#;a2UUZ54&>7#N4np>n_T=x)h<;O;bL%r!LE^y zHy}u!C{SsQ9;ccfA1PFHg~^QEkv0r_CM4?e;#v4dZ3az@$fUYz@C5#{~w!e%QZ$55x->xp^Q*Fz~$KfAz8Vhw#2~tVD zN*{4S2hCsw>6S|h$goA4sMK6`0Vub>e$X5xApy{sp?7vBj}jc;+!yQv7z_u$rfZbd z8C8%zY~1J;dzJDsHdc3G%6s@+M{n-L%#1lxgc6DVT;%U5Jv|>&Es~3Gd+Ey*CBuHd zH24d^$Z7>q-#V2$?^P+NjiYmSt9!ZWm>;^1HrgBv4kvnkRygTu5cVj%O4PfK?U}I_ zv42$^THp4niz|r6bDX{HW-75v$$-=x_%2U_P@rL9b@R&ob7MW1R(D^_re;`(za7>4 zdFQltOBNSKcxx)0_taBF-u1540~@^Vc4grjnhnfC);CAA?fFs zw2w_ygN=9m6}k}kGnqRUFAHIow?I^So`kD-J#e8$T^!;#awP1~KC6guskd^qagz7h zYi;;oJlx2+V=%D{IA~ZNufkh}5jnjTf!pVDU!#Z#&AhmAIN!nzetw74(I%Ku!~A?U zCCiKlCcc1ACLYR{EZ@sT%nep2%Cyj=gbZU_ef`R=)}_nWI|G+y+PZ!EQwcBE%1z1^ zfU?INIY}k<0w2{GTDNafX0^r z-KD*^mgA6P4XB$00NyR~o$m*CGJe5}!s~X3$Ryb^z#^m#=({#+DbD;dQ-}2#{DsHevjj^hR9!CVw2<?VBlimdUUU>Gem!xh^KFGGM&xXe;uIpAggJKPrrc<3*|+&3AVC9rvcJl>;@&wJ zBDqhn8JO_FS95x8?3dU~>d{AAUGbx(KJFHxkQOl>8}ij&H`-g=yD8nUf!8Rl;z~SP z+*6b#^kB70wM!)a?vz#-kbq2*g9%_pjL#(2HJ+ye6|x>poGaE%*~CeMi!;;)Vx}?V ztGO!vC!P@`!+c$ZX7%OgP~*}B%=+9B&}4ASHz>&LGGa*_be6g8 za=f5}zhtpjQ}IZvcAO9hXLzg`pQvF8Szb=39BR&S(SZ+((Glf6%ONDgy)zkV9ihil zv^s(l1R_apUNV9RPR-cO&~$;Ww`(46(o)*tX4VAhgt2S0ph+0>{cJ{Yfsom`elbG5 zZ@r^UYCVUu(r(rvfHPs&Y2U;3ew-hH+0)iyY0Suyi|n1*&~>0m>hf^<@PJ$9RmFah zilz28&|@`bwJo7jTICGhr;iOYeT`OBySHBs%U#}gQ=86RHBrtfdD!%)e-Qqh&|SW|Dh6>=cURG|E5FualcBmyFQRN&V;heK3ACo7 zy3*Yd8Y6@!>G{mJZViudtN_LX&sf4e5} z7#*DdlCp=3Y>uGRJpp_<9uxNAl$$-({bLAFrF$DUV0ZR6Hv7<&UK?hIqQ1M+sR6Klz$yM zmLV;)F6LUWG!eE(ar%|VYBiT`L3uDm3SnD2U`6drMih!oS5v`Gb9$QMeog=#!vwOg zdqeLPg6Y+?-)?jy3ucby>H1Gc-jCM&$KAZiKEWvy>d@r<=zPAb32{h*pPzrfG1Ifs zyGWDut99!L=6CI< z|29LpCi0RYZ9E(noqi{F&Ws+R6fnSe z!xHLw22Hez(DnvT4$RLcXg5(lNiY#!HjIU#q{{ z27NDH_cplfw>|XxVdQvWt4<@z`9|gEeAjP#^xN3MQ;ilQujs|6mWROx=mr2AZrN4i z+MN$@!zwP3VpIY}OSCSa?_RdNlGr7k0LSz8sg=1QYe=#Z3CT=g^uxuGcG=YY_ztlZ zJ)`@)h%gq|*!2}?5bYzgqN6*yLr=`e&HAtMuP>u`&P-RCw8Nc?tUL%^S(Lcgao;_% z;qX25t>L!n`b$sfrKVJfYT}l2ZFF(JKGBx>8XgvQ(x9q6qzrs{6JukW`1NES*u`t> zd_Ml5Q)TN3BUi;#OBtz*i+J3wFeNJfj|(qsu*ZAlkt_F~0^+WT9NmWkoPnDTr8v*{0oZZdsQBL9#~ zk)ZRmv!`3U#{BhQ=a^ZRP&Pe5Hs(-pIvq38z+ zl~=>3j=(b~b|>Awm@=p6?R57RTJ-|mrEonkK=ORg^XNKNg5a!p~{Sts~vM?cuhHXv@k30LFDvJV;t)DGTqo0 zrC{#Bp#Og&jV~-J6Pd3X|MOPe1~{zX&aF45Z3!SY9lqEWE-Z8AJvM7{{4RMht-_h- zigi-07}DIf`((PFR0^v$=e`D(t&kA8TI2mJhgxf?!U{B4l_bY9ztx~OA1AjyR*}4%Swr;Q2rCU{P`d}E%b;4l7EOuxon%WXBgbr*ea-CJwdo@WImcgT z;UIlIU3P<3*wy2-;RJ(smjA=|8c7DpvIx$Lwx0p-T=#pfM`prZ;Qs2CI4sFk>RUFt zywv^l4Is49D9DO=!*MM0+;HshJG+#``3`$PqpzqXQbJTi zZu>_eMzf#N$f;4i31v{2Il6`fUTz_IV)s+v7&+?GGI3CaDEIo6GGR^@nJ_#yBzRUJ zYh(-OUD~l3xLgh8=rckp(ZSF(b%6_DG})PYJr$x%EPHepa>XQcRQrBSHJ6#?keb9+ zr?$2R-`20lYk-T%;PfR+BIsXMYZ?9Xb!qU-QVIpIah(6LabL#dJg5Dds#t#1K`fH% zLgC+i*%zjBUBFi*7JN!B1HNxM_a9gH|Ja|uR(8Iht}mk)vcEdhpTH*{a=(Ya>3{$1 z`xKFHyZHY#ku-I3qFZs>+bY5=%)-{rJ)-o6@IvLYHI&c4DD6L&d(EzD27QtbdLT^H z3lrIxoeQi3J*|I!bt_+bkq=cva;af);F0{fgSdB>fH}ur{b~$=!aWZD9tw3Ls%8eb zQ8aO~&mDx~Rl&qCO|`E{&(|vJ4~^-UX*z%R%}`VPRzULg+RYOga?CDwj=u%jYBKtg zAMe*}@oSCnyLoDkw{@*6Dia=b*QOO3T*@^LA4985sp6(-GsZ@n165e-lF!5X-&)7V z$4l6c%d5f8);#{6a$i%J7Jo&?QzoR9I~qM zS(dN&ajK6kEiTB14=3L!@!9>75lh)BJ|oC8rA7+NvI5m`oCQvbE#8#W^G#dCC8pBz{3A$Z@epA;5*ST)lS%9;U-kBx~D zb(;SK3hIiJlau=Q01ncZr2^?%)TJwa^$T$>mW$y$%tFT?Qzs`qLOs+0>b&%r5}^`_ zm+wLvKKr+Aeo%5A7J#8IcbpwgF>T#90W4M_%QZr zzr(7`%>;RR6u5kwRzv?)ssPi{%>oh~!4Fp!b5O&qD_N-j^{v;CRp$7uxS`z%Ct&*N0B)8`6o4qa#KS73~%Y zJ@mA#B}>U*uSlf1+Grc_X(d{V@)O}IA}y`0lfD49Y6K_%Ji+xM`$+1`#KfK~Cso>C zjf=jf0RKG0pyd@VK2kU{SuNuWo(Z35d*`$v8rPZ#_6=TvK9K<}?&{wW1IdK4FG!bo zAH~^19jDLaw6?TNh;s68z8@xp(QgKt=O6(A?@|}hiPVjYk4I);e!7*N`$Jnm z#%h6ncmc)Gnu?kIM4F^h#eGgYuPU<8SAvg8C6D$McfJ%U);7Kp6B7f9X{pl>NIv1x zJZ1E11s1O}Z~m*5bOBZpo5ykk?4>(65I^6#X8J=b`9R03+T2WJ#1UEy-fja-($s=; z;3#P&PD+_|$vrJ}x;p2gv z|M|x94@J=wpaf=x{lC}#4oBqY zk7VDjmC$)|$xra&vg**C@73VHe?xatqysnI++9VAvv+#VO%43N_&+x0z8ekbsaP+{ zf1}PM;R+w?VjM@{JhmW5o?A~01k^$!!jAsjfvgb~R;w6als+`HMU$*Inp#x~CS}PA zkC?p~E|2&i>ZcyVPUTsYM75rc9|2W{4_-PLrjA)ZuXErK-F>jfNIiEFZcjjHc}(&r z`XjTib5Chr>rRR|b;&Q6wY9{5*1!&R<@+d-ujv97KwNkgVe`xMarM`?7uHSy%7Hf4 z@hNc#C#JdWHlJUgTRNMy>)t+N*CNy$TOLrbp4v}H~PGl?-A&z272)RbMX zIj=h4G8ON(v4~r)V=P`X+lnW;bCzJ!itMdxjhPf1k35-%j-ul-zbDRL+DE^x)uf86 zlBWVLTaJ^|0mEJV&$Y?MpU^Tu5==rQ=;o@O=C6#TdR+x$pc(d#C2toLOn68{(s1P` zN$&KvrHgAUeE#6AMrEQWT5OzuChh)_TaHY2tt#;E5y;^)@TjJLE*uoG<1b7+%4V?% z`yl2NYP)g)q$`zs>-{ML4nQCnSoSH0sd$tjY7iN!Kg*>l!)~ezxvHM2U6-@uyw=Tz-!Q3NNN;-S&omU8^s23ZYWP045rO} zlD|jaAt;KmQX+dg-wqDS-q0(;SD=}s0sk`^k+_*GY_59IZYYhFdP!e7_)d-ZWIF{O z`Js33EEm#LvQlE#K28NBS-@sfG+Diexp=U5PC`wJUQ~RtTKdrBSCI4zODJ?@sk1EG z9yz<+_%eLHx^Y6!A&80=!YOSXlI8+*>=KHZ;*D@#Z_WwX}nGb0qxDBok=Uk zEm*0NXePk!26G>ihI?n@38Y$bmsY=i%R5=O zl?Q8|y+Pw!JnZQ3s#DSaky2XnjW~jnJAuM^ zgiA!eYgG{*97i}XKX|`@B&Gp^aK_d0$ym$I7L<}|;=6Q?UhIlCai?89#C)7VTM^b3 zz#NDu<_Z$tL*#sd&x78j*|VKT)V&P}Bbm|(qIZ4aI`v^hZtJ_a8dn+G*=;B%Zg%9f zN5<~H#mZ`MS690?lWx*<1ACZk=7){+DGV`?F~9d{_@k_F)S&z`edXX&LmdvZ+@>q< zS44kovw?ftdi)}{(v8M+!tMn|3{0XJl3n{Y4JNV`S`mSuZF&0em2-1VP`x4xYRJVj zHB7dSPc+CJ7zP8+N&q>enH=O|E0?kdLn?Nej1bDW#ZY3&deSH5DvX=tUbiVgp%`w+ zi<}O|a}K1&SA1TS{V&^ZQZl@7+v0=Oz~_ z0`)vHA?bM8bnjh-8*Ew*xn>v+ox(onc~OFbL*zTY$SLD~bxyQnmQprp`eTpb+7_|S zBrRlHX>}Y}S=9RcKnZ`q?~suA{Hwsj%&+W_*SeSIxmly7I-G8ErwU_9UL>HvO^SF_ zsl@V?lpUIM{H270E82*3-C}YA70m%>Mx0SeQ0JQg&z*%Hl4sZyFmz4L2=$Dkk4^w; zT<3{g3}r@H_Pby@xSSvk49x`|A^m*y7C%#HD@$~lZs@Ot(7it_EaZs7FS=S62g?u| zJeG))xvwVFhA`Wi&zR?vO;e_IS1bap-|}XQWr2QTp^N1yLKx|6G-lxf#r>XH+<dx za?ACYj`k#ysAk9YFYlf0+Nj(fDfS%CGwDZFq^#^(Zr2!1Y|Qp2ZVNS}B<@5hQcyiq zS$Uq*c0pn!6^xCp97(N`+OhF+aHXzXWfELVF7`;XUaB(kBxxi{te?rsCVB|BCN8O}C#hn~lR+fQ?q1ZasHO7dcI~rog zV&8!LUY41QUt}cWt+AbEYtE;M4WQrJ^$DPl9VRk^SYAQ73xWwo?w!XE#sQrP7`Sz+ zTcWEGZ{)ye(JU84LeY*|hYU=W>q(~lni;9!|MsM=N+Kn`<*;q*;tv}&c_17E*I{t52NiyfP`Ai> zx0fTNQBi}5xFYfDPqI3hms~)kBgdJ|P- zzOguHNO&~uysB{57s?uD_O{5);_gXL`p%JebL5u$eOL)VDXx?LpciJ8=~0I>dWETA zp`F?@xA~2FI)abEOcF2G_Ok_5Gq*?V54LwZuG8&CQ*%q`GTCyxd`jbzs?1;tOqf4s z!jk5-)}|8LvR%nd&S6LU=^djzTa!2Spd7$I&Nteu1fMF)-Iq>Kr6x`b4R425cH1X( zt9z_rd$bQ)Q3-DN=vBhnZTrjMrD>x*gZ+1%!~wwVI3FvRxgH3W zDVXCCmkOUyTI4-6SMLiPU?a$Zw$Ae8ZZH}_I{Nr%Bot0BZ1)NVT_8DVVwp zkON3Z7B{C$k|9Al-z_W8K>>@g#6f?V$PuJMAO~XU1VkYnZ@8at!d&wH5+|gwEGoHg zGyIXHgn0Pg3KXKnl(^-u*crj$!qJH5mDJi3GDjQ>W;hAg7M{4}>MYaaAKTgOC<1lL znKUsYfiSyEYAj+h2POit+xEEEW@ICL2faBPPPS5eew`o&G5^TOv^P*}jN@#h#Z*AL zjC{2sEJY_W(QhEk=IU`S)RuegY}x&`RpyU9PjF5}86JGVXWV7pIuGM>?VoYT%Ut!4 z+Ndp$U!#Mr`>(R2=nvg6@FiO;2E``9;lXZf6rw&dhu0l6>I9uXR*{w~%|l<}6Kj!< z+x?_C^rnx5bL-7Fk+XYd5TErh3y|U|gIM!u3END0t4EVNEZ|%>UimtHc0~vx);ZL~ zAZO=6Dz5^j<>w%)#5;2>r$pxMBXxo6uUtC78HV3g$jETYOB^It*I%O;> zqFK?qby^h%1S-p0v|Sjw-D9vd)!RA8p-V_cn21N_h6hTwtz`@dG%ioYkPVR55*}9T z0H5xzycY)eXLSFZ#Wo?Sl{fLQZ-NVGpbxAp~Q2m+kKSve-xFnp~y?nlKAIFAJ#EL83lX9g^j{SEh@UN(&{Z^9x%=p0kuH4K@E#1i;olBGQN5XP3ekd?azY z%d9bZaQo~dI^rTL=xiKS#g}WuhPPTrG3ksp<;x%rACDtNwUdnu_2%&?Syhpe{q|wo zFrwF5b>A|f*lPiJx(4>#6gs$i@oShFMYq*8D7cSPN@|blbKuZAZ60)YM|l)MOpe9; zG_ny3QC2PR@}bF7GJ1#?EM9@dw8(kTE^l9Rx7qlzzgq% zPYsbCw8(CYrX`)=+yasBHi(cuKZ~O7X{=-?vRB$cCCIU1R^Zjy1uS)>uq0~{^Yo`4 z@>h)`78Vip8IoR#zF~?m;64*K`@I@g)rU76jP#48KBq42Do6b%po&aW6^VCSTLVQl zaqEFE#l=jsm`i@N7rqu|wPQft*`{RB9yi6c#H_&MpX|o6)JXyOeYQ(abYB%(EUTA7`H>sm+_8N@j)c7jXsAaPAq+-L7 zjDeuui8h38wNz>)NvlX~Yk6r2Y;IE}NFF19_vU7zR1(w`NeMw{+a&eAeD^)`2Xtr0 zR$uz~gSZVI1vFTK%oylWegCbv^%!aPC6>;s*t2Y97A@4j?=Pz$(%8}F(Trg&UInrf zlFSFwz&cYF^`*LdSlT{qKewZXQRXDq|7&2 z2AjQHQ|kgz~ql*!+VQ`JBq>Is@vMnfTn0?-{!h_^Q?g!+TlFyA!srK zaUN7!(eXhcyt=$^VM6PRgDGkfD-EnNTdC4xqR82g2U=5jm58kK|kvIFP$YBbT z5R(v04Fmlp%jRkqVoN|%x`1pOGj3VSi_i-S=%7sf$AZqkR$BhgVm%eqqo49kpqU`( zqM1+vmb9g<&GL-HEG|>0=I8S;?k$66lbZR^0u|wbr9jVC%%{@d|0;5Nv$-3?b_!1`%W$Qgs^9LGSss%vF5X}G&>YUx(-ObtA$S_bh z%j@mkJe$1y8`M!w?J^Y#F0VHj54A7R#b4;O6D?Ob**E^@+RlkgN5HB-*Jm)MTA#U{ z@IJy8qNzc$G$JZNl?AbNc#gKn9crG84`tC$7>UA(Md6JaSpx!|FOUdVeXb$>I^)g zE6=k`zv^lySd`6+UW+l1=b|kM0J@NQmjD+Hx??bfT)FE}6qRMJQ*I7gpj!Q$KVk$= zUuqM@+z~j%Cm;GiAxXASuxR)Kb0y$S;Gbcb*T5w8;J!93jjjbt^pF;7&t{QAedYrj zq!?6oV?tOS>snced|%cras+fqCe)EAX8hEdBC&T^FK$b|4LaJJ0_{)TY)stsH`?Jl zVCU1x{|oDxBm0 zO&Z^TWO}XeT|0Ij?0xIYWH?PmI+NL!3CUDso0ajY!<-hEPMs4Fj9N;82Y4QjyMm0B zVvPis%Z^qnW4UJ6<69f$;=tg`3HMy_G#8Hz#Pbs7$7S8YE|%uwt$(Ch{J!a-e+NW1 zpk-N8>l^&=9ts}_X9t|5@N);_hpVFJ?Z z0|q@lBa1$$&3A6*(jJp{c>|iQmKs8s#3m6Tw$nTB{LGX^a{hc2{ukuXoiv(o?bg|v z*yo#^Hiu5x%(W56wKZU+ygF_mmnSU7%Z1BTPp3buKRBHsKAS3UGMn5GntIjsVm=7c zSR&M1B*UPy-u4Rdx6}Zplsyd(xTa;Yc@=fEVJksonaRm)sTO1phk zQ-fwe5-;m%Pjx4AW$WOkTM!9Z-T-IJ=I_U&>{ z;@M*91&15V$RtAKdZep27-;<8AF=I&f4s!UpZ0|wK{=)G+|hN?&~9*>HUSKq zx&lV)&K5qa)aPCM-8k78NCF$All(!AC89uZ=0>`Bmy+v!xg?7)&Ew=f0#y4H%C%~3 zW@X73a9zpgCAHLbLa=6FiONU}--c;=i$5 z;DAO?WB{e$g(w4965<8q($?#^-&G54lbKK!5tLMC{Q|GHmdVdPsJT;{bQ@)cw6^AL zb2lql9*Gm5_3nF%oWmrP-yO-HVC~3CB^>P_UR8Gv=rWgNZ0(hojG5_QQdh`|DmK#6 za29fW+!tZ$@7@6UZ9BK*dfsHjOAgLN7bY1SO4YO~PyV}YUj3Iw;D1f%`VX%v@`0jA ze8J2vK&ah-+17a5Xa@jQ6bR1JEVxD@6n|?5>_(A9at{LF(vM=mJ!mCSQ{bN~{H5zf z3AGWQyB1bXPTle8ltCRYm*lyAJ1whX{?YS^BF_{-pObHfUXoHUd6AN<8XjVVg-vDZ zS~TIgvtC*Br5fn#U@@^8k`Q=?1sl_oVvD>&g+WX@9Xt$`YI`#4RgP!Rtndb4SS;&l zKG(;(tbF8u5z;;qO0zl)kryF+odnMGodB5D?}G;rwiF<3U{{rqk6c%uWf(4X`g5Xz z@rvoBK3>2VEY{h~U*ev=5ux0nguUad>%^D*knp)(S+>%r{%ww4yuY1gRuonLh>FZT zU_KZo45r2sK`SwbZ&YAoIr3n?Ja+P}U6eo!R~y^bWit&Z6tNVXJ4PA2ZD9FZNOFRU z${&VFc0QDXX)CV#av>oe^Cm=V|GzZX?)&kX5g%~`pnk{&V0|mtz|~3Ge=ax8|D26SU3Rb=ih!M4M-jUftTb&tDpGt zs=quMxX<7ahbS`AR-GJ+xAGHitUZaQi#+k{@m}IMg=y;dB1R)cXfFi;uN64TIdkvm>H_mW%`;C55x;h|HWEcL> zyOTqVo^B;yYWS^xKISR^vuwyz8o zlKweVjv0(i)bwxCIC1N&_g{$_xUoe3dqK$(*gDXV#xy=Kps%(_W+#sQn3UA*Ob%6s z>PsxAT8+cWx%hLIAFc=pv5&$2MD2a%A=>*zaPOY zg+o%iBIv$kJ$aa#4!)7`d-71_jVp^Xg$j8?SskwQ^sX-$WEHd0D7P-*7i*wDW~gTO zf-+yFLL+ltcgT6n^#{f@GJWYc;J3P773iEnI%aXQKctasRX#(w$PvVOy3reCf6d2Z z-iXbJW+b=J)HWEXcwb|1T+F#(%52T)m7VpH-E?K;sM(7>UDoc~KXyD;9B8y=OiRU` zR`W2E`e0Cs3RP4Ccq&9)61GHRq};1c zD8V&DM=eg=%977G6hI$Aa6>%aj#}YJ8XKj7R^Tb{4Tw+M8 zBWF`#B_$=>Nxa6mul)}Hr1ycEmO5K+y0{k1B-+D{@zJ*VYI_PxYZl0Rdg^>n=%Gqs zldh78s8N`yMu6=voDb0}I$=KHSN5F9-Cm)ra$uWQDrhY9*&!R6Q|1h-vY1~G?G~Z? zcE2mc4Mg;z=hW`aHX})~>xycmWA#H5%t%qio zx>yx_!*ykSIoKg8l_g{(f_a#$X;lOeLJ5Fb*|E|I2#tLmTa0#^9Bnn3mYg;^WR&!T}ok=VU?}*tQ zqi#kh;z_T)#kipzf3swhABz0&H!2Ld)z|0kx3C`6^Re)RDdZSe^SQ5t6%RO!xs|qv z*OCv%W5Q%M2N+VYu4xb`+YvLg-CbN-b>;8d`2Cs1t>mX5iyk94X2ljqZI zS~XKtJh;YZ^R8I_9P(V-UQwBptEpot+ZU~RZ^3U|#q}W0@x(T6cn8OZ-u^F|9aLGw zYNv%&MmH1O(3e-aVNh9lKLq+sKo27T+HKVd0W|XeLU4zuVbSGl30E!`o?0$6NZgI= zkDk)#InEX}+``Osg6#qrz0wbLUw?9-L5a* zCRLcSN8vSu{zG=+kb+H~he@ryEemv4#lG7)8B+giD~bQOq*2#z68kf`suer8pP9Jx zeA}3G7+SsE-|V|K z(9Y$b(yVs7kL!8m8-6=d41gdHu8unPU!05_4z%aqv1ftvu>McWNqn-y9`1X3URv{= zLcFf45;q1yze(z;556!d$|rD%e&<3s zzNr8ho2dC;XYPL0%;{pU=upJmEJTNqRIpd4(dfkUEy85H@3TUx=i!AQt z4b#uh6Dtn#FWh>#$f#=QI%h;9NYB)^#fPeIm-}{_7!9m=tH>(ysS@|j@yE>RZo{gX zQq*r;ze7#xl!o}-hO392SBM9ZhOie^H7H9J#EVKU7x1DBJCJxu}&L zQWQ_F^G@b)7X1(7hePkWHX^XMSQen)n&o$}_tb3+c+q~&@O8J!4L9-yZfiY8EOX5; z1Ir@}ve|rP{nlkxZ}?w76bIb%F6BDKiPE{;x#^&UP0>?Fv?=VEMAg3Iv){WebMk%g zA%l*pq0Krx%Vl0m%OX$z99?hx1nxYjC;%3JzMw65?YV=fjr$m*iN~KP7r>s!JRrlI zQB4ehdDW{6{h4PcBvVtlcAC}w^Pk6I8+P3~+pIy!ANz;**QX>mN^+M-8BzwPvpgRi zdtAi(H~Brf4iv;wrj1&>jr_)Fr1o-P)jU z#%N~tIJz`APHyKSP^C9Ct&%(Q;5)GuYx8A8Z61pbCLSNai=86H&K1Fh=km%|no3jD zGA&PE8muuoA;7QdwT(A$>o~#5 zGKf!DFNCUIv$*5+fLXS(()x%t_U{oF$g>?gWTaddih5wGs+E(1c_p8pweh`8aOgeR z=2pGadeE{%qx;gegFAq7N@7fZf!ktSr>*?;C&jZhOKmiP_(ucO-0jGYe{Gl;9cJNslGlBth`YscZkn+`5v7&OY zQi6PC9MKzNxzLZ~O^v*w_nP8b8yjC+IRQsr-G#pFx9eh4fwzJss|wmA^}G@~U#^gb zAB`F^B>MjJxQO%b+d^heY&>@`S_z{kFDoV?!Lzp6$S^gK+`d(AP%J`-ct+U<8m`LI zo!n<4wV(^BzEDeHN`lqm`apm2w*@o|EsV0=LI%iYk$8!S`N~ zx6WN`r-?i7`5LpA2DcZB$%G4U?fW{ixjvZeAVs zMEzEM({AU!|F|eynf=I(^if!`lDZRQkh14VWvpt#&cGC%QF}%XgtV&eN?61^A?8d` z3}{ypD|QO=`a2%mlr6lii<^X?vXlcBsi_)~0xQLpdkgtVa?fJkW~Cgxt;qlC0To9N zU&@Q8Ilr(3TR?BW`ryWa@Ek<;lz75!w`7!xII%?cXNQ2P)I>uECaQ|ikleHVt|1@H zeXQjKAg3kYt|b|Cie+k@78HW((6u~;_+_vM4d_W+r=285P`rS24M?{VVHS!fw`#hl zK7NkjOMPg9OU~JYg&0Gg3O(@TE6;Ypi@TMutR-9I|8&ICK)>)X5~_r@-Nw*Y*n<06 z*!f(RUD`y1X%he}f}zJ5H4hO0ZKNZGTRa;z zH%`$Mt48_R^iCP&t^tcM*!Va@V!_-r(c|sOi69&I6pM7ya~t2C)-@!cbnR8yRF9YW zDWcz=+nA`6QNdi#YbQ#2Hr;&3inHiF@z_0@+YR%kD^?4^F9k(rNuMSl#UJuGW1&rY z?ROC$;w)T#zuBzY9?Tmmp!SQEI@9SPllFWwgg5EE`(sG~o*GFB$=`5U`U6^?o4PG> zxdZ`1vUFr79?lsgWPw%)PghAu>;hx578;rdBPfWJMaP+)Zz6$&nTmevZ~gctHMUjA zf7a3xs;*jgMg=K;B#{a-A5EIwSbWE|mOwEXN;CD^RqdYL>#dLU1KAdJuC?)XO))E& z7fC8H^~4EdYs>xH*1H&ROG@}?^5Hl{XVeGJZMeSzhAZvP5n*1>hN{{GgP1eCKFy3~ zFuzz)g<_WB(x5AvY(K!9xTE=?8xdn9%20p(?trAul~#w;vbNTD&V-F#Jf6ArUMgak zGCJbI*iL>BUUced^X>{3*F{|4( z{QenbJ$wIg2(RY$-92~tQEG)P>JW``$Rf9@aS3dw^)tqa5A2*11mlKr$rEUtyx2T^ z#ttRZQj?*RaJGrFd&lC|?W|S5+6&^e>S!v4PJEna#Z?6yTaZeLF2pYW1HaJ{FN0II zR$ zp*&{e7aKJAB;Su>7(&=IU9mF1bf8a7=f1SaqjUMS?OuX4R~J#MvN*-4#AR~l!L82n zt;|3RAcqBHQ%%8*&)T!7jC{=KZ-zA=%X+0f!|1Uk#xJZD`OnU&2vl9cck{7KYTy!} zN3{F@t{4Ck8^5q8nt^W<0(fcdVxYVTd8+IOSUfb18n@V2QjiInIEwwg7o^B# z2g_?CB&mv0 zs+e>nTuW_Xk7*ET*lsKd!iWP zAe2So&XbmVvM;j2Mh!^L2zY5EIqx|p~9Eq)QJr4#mxa#kI(#VecJ_? z))Flvqm0JQv0Z0cBgqGAjyLp*~l$G6AvPJ5sIBM*O!(8gG{6>98b?!A~|O z_i}Tu|3ME1@25`duPCH-r27O-EiB-OZ?K%@(`sNaWRh0+(GWwOy+r{b1dWBu^ex)$ zpz9s^8)A70`=pGi!P8cX3j&kXUA|2zoj*lRX9v?B(H8!@mXHUz-EN-RYpCUw+B@xb zQfj_%<|)dYFcDojZtA&(W7&H@uTT%FbNUI<`c5uDDGl2xZYLPmlJMCtfJw=-OV zX|jd7QY>TTq0NHVd8RHFeVFZ-oV~bo!8na7B*{#Jy_Ssz@X8I;i|?MQ$R7qnkPL1$ zL%1rcRnTv)BU-gRU0UJ#=8U*n1qI z2v1T(z~eRbGQRNszK1Cr@vTQhiXl3c6>SK7LfrdLit#^!X?; zStaX*x`wVi5}r#9xLoh_C|n{6?Z zP~nNND_SGVsnWykS|}F{&&j&xt@F~OW$QBc)Z5-)Z9GBHig%~D!!A>rnb}R8R%eFk z9alw~R0jEqYF$-#gtBxw-{6s4hx!}KOkDAQneoIOGAXAEv`v?X;&YX;CneYwT$d-g zJM^|`MfayityXkXNl}R8756j8g#|zF!jptfC!9T^&H0bB04R84$(HGO-hcyAqR~d~ z4oj1UN^lxLLV)HM;2b;1Y)NUY=JWhAPio4>7asMO3QCNOH-S0sTl}hAq2aMSVcc8+ zw@L*~Jyw_ruflKcQOjFPsjiyQ3trKc_m$~#<3hKFCZ*VKwVR-dpq%iJ{#bvfwtDyJ zb|#2&8L_W~-v~LLa)pCDr3eSo;Zlp?&@Vc#S2e?Ou*>;1zg2=v*v#tndotV((60hk zCLS0;kaC92fh+jTaZ{P_WQ*KO)<$}WjA0dbD%G;G*jU0F#smgJf zDLm#~yn|*@^(y8B+HBt6#8(B2U(9mOoMj8@bpUrYV^d#Nd#Y@OsFj&%8Wg0f)S{g` zx7mL=`bSPc;M+q5@dv-3;Pe$LY0dN4RSgu^2mpL-Ab8#DISC-RZRMf8Nbei2+?wKC z?`h6xlXITAPita!5G!NPE|c%3SW0smI-^cpw6!*ubbHi1g4>?Rq{&!SQ@O~+S^PBE zqQ+!nF$)b5*=9$tkRq!uUW+d41ANmJ%J1pg-XxKU*Isn2<_$aAb6jPk=IE*OAX@J_ zMkQ{msk&F_V}tM6D3UAD$$N;8CxHxd=WV|=o`Yu!HAI}-yBR@=u)0|%y|ev)aQBvR zQJ`J;uxp_rprn$E#7L`vG$=^J&@G^Zl$3OfhzJNsD-0lA0@A|3Pyzx=GjumY$IvkE zJ-WNblN3h$_LIvUVizV%j~n6m#-IRFCw_ieSSXxwdoem0BvhH9?ojf%5Be(1J1Pc8 zP|i+9waEk!dIHU)Ax-m&mMqZHQb6gcRsLjm3+qdP+ zbzWQ8;nC!4>3%OveyZH;nd;=%m<@Qni5OkFV1hNiq#K^|q)ScL|KpeEOq<+xxh- zNh<&#L7!ZbuO&?IAEkJx6b}q&k@3UmK+|>n)fpNZX7B_z?lSLlJ7?|GNr^waz%!~a zl4)42qLTc|e9LfEqwr1mZ+N8K1k{4#=ija#Jy5IiYkz5sW!YmZ&X1<^#&rK$&ryiG zpoEAV$VB!s0FKF1^?xXgsq+xOs_PsxY{a>s#Yu9l_VGQej(``K)<_3;hO?W?x45>l zT)z*&E7130j!3%UOVOv7j-%UT@;iZLm!2zIGfDERtT9C@tA}Pp&^mH>dJ>ckI}K|FyWndC>8syC;t_=xhFMkq|H$@38!MW$y!l$*3Fy@NqLe03qII zaPk%=$p}jV_0<|Yp*4m<~i8hMui$BOQL65QTg9N6uO&Wk{CVj`fp;va!fn?_g zcI-^gBElbBu4cdzWr8J0Y2iV1$-Npg^mlolE917k-&KkiypLu4Ww)iJs7cB^O})D< zTh2R`R6{m{zk}r1>E_^iw5*1?70xMr%U+d^8ZHVd2a8Z^6sq(vR8Oc$=BQBpQ+wik z*cTxR2acUJpEA7zDH*5>+Ru$kIP?jvQc(ESvanrWXb@X2B6|Wmq%LX1x!oKSMXU2Z zm<5rlHirfUux3VZIG$|!Kx${705DMEeCd1GqrZYw&k^8 zf=B8{$;>`g?E zplIn(o3P32g0h)0`^|6_=W2)1K+V}Nci!~8n`UG$-)kFJcI|cdEqa(9qN;vM{%_Rm zhor*@BaD(vms2+-hH_LJ0#kjm9BW-Rt|bzqtqFi#B8qg<_>_TSyYwivTRc2Y)1N~D zRLv(4c8k*7#M9F=ZAU=Cb$P}E$~_wd>U>nFa!93FEtL~*moXJ*1`lhHr!=akI}$UA zCF?44WImGF%+R8G#=N^m5i6ra1DBlfki3d~*|-fvXDcyLCw(g5yaaQ>XR_`JKyd8G2M3_XCTe-s-qm_iR^)f5yIFg>{X znh`AQZb!$U5Q+`6;U?nRX%`>8tqcRHw**YZT;@Quo{O>GC`Z71X=_eC*E@u=uL>N|qx55>al?;YDY4>J>Nex^l@G>=SzK9@K zGOZpQIYo-(2-EqLf~6dksuMvszJPISMM1el&^(tu-J88%v524Tlzn$%Q-3q2PfkHW z-)*_L-KA}&z85Q=E`v?JOcPrcG??xd{SD5{f~llHPgVKMyWH6`1}ynS6VFwY`W-Gp zEiSWs4c2%kxIBh*#h;~H+Q-=Jm*!a?Ifwtn0r=Me6Suq0`f^lmG%v(wms+wQ^j7VC zb3_(t95+zQ1nzsfJ0kW#l%z>0T?F!+_gadzRez7VU1B+sMRW~A3ZFSo2+bDyq7rx~ z=*gD&v{PKP#naEH^9&#RUoocm3!N4J9_RwSs347n@t`hJ56zq&h=PH%jzwDK2Q=B( z8_a!`fUT4s(Eg#U|K6*sK$+I}je$OBNPYLx!!Z@mJ^V`-Dr-v!O!!ce=3uOG*PwFc zPYq-s`_tb80DRN>;hfMa%5td9t)WbO@A`UJbcH6I!%E-4W;c8Duuc_QqLgJ?oKbcW zl;r>Y6Vp6it7{^jt&l+X_LrSXwF?j{guvOpuZUFjjUTnHeXPwj^+&)J1fkF)z&(T1 zfF@etH3gc)N3j8R!1k9{z4ttPcsE{wm?`1%R4HaRAC6dau5um~5Yg$OVQBN3>b%mM z^w(wmK-l;O-;cUV@iw*W&@d5-5c#hj)Vqmng@!b~A^mR*gzN8H>Abb%O8h7zX|q*asbD6DDvxZ-|+TcME_iO0J6__7VEdJG!0g%3pEBUqeO? zZ)^(sj@oo}MNlA@v+9XSwDl^={EB}4lXmhAHd?$rVI*=83_tE$NX4k72adY83kW;& z?rSRlB}qR}IlhBv0SDm892jzqM9|4bI`Z#m1S8NM2`|$G{@YK|!@~64FcU1Jo;y_) ziRhiBBZWM~DhQ|MxL3;;F*|;;hi6=if67|DsJelutLiZ(6uV|Df{s}xTRlqf zI)3Gsa7=^QLtu>e!^bePJI8DB$yh9~>exxdb}lY|>ehcbN-)16TlNd)3MBj&NEm45 z{d2O)HyHp!4}QV=`F8yDuwU?VzTfHpIXa7(!+!xL|KD{qI&5F7Sdic97QR3Je-in= zwaEHcxx;_@Sd;)jareluU8(ge40piTnnkBtr8p>yJ(s>R1tQ{85=Gl zPi#BS-ThTvLKkSWH%SHeLY+#mWn8EUAA6FAolqsiF_XWXoG|9lUKh~kh3ZTgJz5l3 z`K~+|kTJe%qKkD1P4qFn*Aliqg^xKl@{C|+RGnMa^M;S+rwBxjc}61y*HZIH@CZ-m zcm0A^$Ozl^+CoH_%dGD!2$2iz#M@y<GBo|fR)JFj;;aXlqeA9FR}X$Pw@{wB z3=B0Z@z~lFpCSI@EbCsPYrxhRy$GS?Q;s0|r2LE96rQlJ!PTo+jQ1OH4drnKV*xA= z>lsOI3-?Df7M2`8?(Dp73+UX%B0M}A5gc}4?w-k4+u4|XCI`#{E6(T@2k?9OUzN`% zPQ0W02F$a1)GqK@ySA5vc#h_bJvn4yGPDOrMKX})M}whIdl|XvJ_km#ajE5swUSZ= z5i&IvV%gx`1@(a8DEI=~u9ODbAN%?2g@TG5hPERJmYit*fkIXj#lf82hq~-D*TnxaB0F(!qgybB* z04Bfzo^@z6=r8*7My1#`z0b%h`kNBrG#-Mk8G_*Etlie~BP5h7HrB+xNMMWzvDzo` zJ~^@xykHRUa(}d3>{St}@0~d>GHMTgU7YXk`?o)*2m^PTz5LN&Q{oV{JF6>iH<5zp z0T|2&dm_bzyC2mF@ith4}rw$(I>Ev=ELW$?qIXM=FLA4)jbdAv3uMA=h(Hg z3YvzJ>etLYVH?KI_1nrKeeoy^v`)ZwubtW|T{fc!oesKbQ*z8Qn71Y}(s1r$NF%&T zn-mmXPN4gC%x)hpMQ1QkJwd3A@aaPM|JZ-Xx*R`yw{F}l2Tl1?F~#D3#(86_(~7PJ znKqbV9+i`s!TYg0J-*shI+&P-|JgyPg$!J^2b zB~hy23*63m{DN6qpOia;Yp0rsq+C8G8;Ej|FxyvIReipZN_%!P;KA0YyL9p zu3|w5I{-0u1@nY!Y#L03d;%6meb5`OWL@I}shW{b7MW0`*ClSF1!)7;$m_8Cq5C=u zhZhx@L6XuijFeRVgFZk0=cOC~CU@ONTURFS_{ep-GhhNL8ZwBWUb`KAl?w%Z1Q-T-zp70( zg^AsV?;@&fd7YF6X{T-C8I7HaSkd8fRsm3dp?~sEP}t0@~|A;9sohe=1+VebB8iEDaX}>XXxzSEZR6 z9jFuR#gO&LsvOfYxCOHG+V*`{7AQ~wPrM@UyKYHNutKM%gvH}$w|*ymBI0t7H*_E_gFck?Am=j9+Dnv z4$@61QNW;H;2yj8zVw&6qfH2N5)$M%vT3um7PpEOYZ}i(>y6cB_(5l5DNrCxbv;*H z&ZNKdJQNqv1&7s^IbS?`TH5uR$sN+hcG}cWuc8<%7YQB)pH{AoCpW9U$$z^Y2VDirOj;Q>m03r`ZS>VN6N<~^g-Uo zDLY`Tjh)tj;f7`=1N}MdoAg8km69VCt`J~ZwO5mr+_1)RaYn=-!mnFufh+`8pBc^o zptF>)ZaOR18}p%hPgpQ_(=O8~@VclTh207M?K~vJ(aNgLA;2#v;CXnV%ATQ~xbuUY z0!i^F!M~CtKnBvqdP-n2t(Du_O{cZ-ChHlOWFSg2{*bC=`J@~@kKOgE0pO9iv|f`q z6c!Sx>0S+`!+cVbk>nGjt9P2@^9kdbGzS@N7siIB*qZiJnM`Ud8$6!O*Nr^{vs4E1 z`1w@XA}@lJn&5-Vtk9%9(9d-3lp53Gtdz*XbUuk>){H8)r}v)5HWO)_16{Ag&)u^H zP|7(sw%@sRqZ@#oq?vT$#~CUc;QZLLQWbr~$&P9X=83O{3f`{?nc@xP>`UG-6v}-U z=FSoMl9S&RG*^GgoN+Jv)V?zBRXQ+Dqmx}*jbkskO}7bvQ{)|BU zYNF*D$lgh2;iPXgW^QsrG0cl^bo_aEl9Xa< z$5S;u%FqPO4fdo*n+RfUc|&z>Dp7M6aI#Ei7|@7Mu3x7Q{?lc!53^Ao-b*Ja_tBvC zyxvYd6B?#`gnca}G>6kB0S(d2FCN({I}3`_-o5nmp4XrujPf6Xhta49cWM`+ru5f; zUjnkDoBoa(c+y^5lda+{vj3?_&F?&-R&Ig z`cEGMsKxr9ZhR3Spqx`f08Pe1zHse7)Wpq5@$zBEd17;X*Gg4CZF(O0fQ;q{+D9HV z&3^c&3|I4Sg?PF~{eI4%Rq`;L=SMJ=sUA3$OZ5Vd`XI_^KR^=*e;K25uwR<>S`c*O zY4}sOJ$1X!3?VJJIU*7C{G0+h0`@YA&?nnLq$bYnsqlbY; z{c>C^HW8WCN-Q3 zrWVQ?!C;n-a3k((c+7c(zuk#5F&0`Uf8)Zq`pItdqBP9t#Z@V}j}5kAkcX@ccTW1S z$vw~}w4Kj?rWjGw@J6#izB-5k=lxBIhLb}bD4YBnQdgem8`Dp6m7F0xJH4$&7@$oy zRWjpvAiA{EhsNwYvRG9?I+X9*t2udyELOS30W8if!7j@v3)Pq@^Q^SCA(;E-&3v~V zD4t9_nc^d=HlVvDR=WwlPkfhLLRUTTt|g-f?+JhGTL3k9?9 z^oz|S=VZmto;}OR$XLPiw5*$tralSR_r}wtEOxK9;>fDm+^5*`suM=%VAli8GY>sX zTmpZ$ks&X3uQ@{oiZ?$Mz!DQ_xf{v=^;W^!I*$!!P?w4;A_w)XpFOE9QK)0ryvVwa zh;80rduPYO1+;V=HH#_fh2yk1zFn7$w0G`R;nMy{*NiWq)Ngte?%tx#4X3uEN{n(S z;J-X3C~uN7FonN&Dv{JuIoY(ov-7RUqhqAu9*Mp zST#>U0+sLSAWgG-AKKU`wn(!Y1(AkpK1kLr%G1m;s);-=QbFt~-%M&Rgv^kgJ2K~b zG;fjOwW4273*lPr{oB1IiB8iAvZ z*4i7fvQ(~aZsCpBoxosmdQI{xS3bzY9hW!K%)ptK%Ac5(nR6!&WGAjY5s+1W$k(S{ ztT7zcBltAD$(eu``O@zV(;MW7J8v` zQrO!SVjM1q>_bC$s!!@uHAsE7qoX5) zu#g6@b!|Q}9Anj;rI!6Toc%qIICxp+I=}tl-?n$XAn^vA|i^Xi_6FZV8lKe z@#LD-lasUR;CzQj1y)@qi+ykugjc=SGVR^D&%v@t^|!6E&+c`Ah3CqzR&2k_A>?h9 zUYIP>T_$m2aL0~5`dw`No|3BU%&I_(&P#8VYtp7YPinR*W$qFd_4Cq_l2cM%yc~Fy zii(Pyyi2?zxUySB-YAy!x31Je{Z~nb9$?wmlpcsknZC>MwfZHb2B0L;lI)%H49@5{;W6!Ioil4K1Skkb;~M)x<2i@M^A22h){-5?ez>i zs=aB-Cz4XzFwIY&&1l6+c`wW{?p<6axxw6i)I@?I0vPx(55 z0%@xXS08mk4f?H!2%>L#(4I`s8tBdw2&^`Xw?Limv)T@WU%=L~op?=alXN{Rbz>)P zhV9vyjZ8+}8O}3MLIc{s=-Lr%Z?{f!_mEJo@S4+(8n5v(m}ETqVE&sqwQ|>$oTYq& znoNCtci-X~)OMHez9>HpLd#^z)SbKENG1(D_K1xH{@xOSW%=q|WsaccAG=nJZYq zS{y!e1bzx~ydc)8V01O`(*=dr73%Ka5qkHcN9`BKsJ00C7*1Qn}&inN^R&b{$lbI$+ z&!ycE?pmg7npXn$YDjjqSozBF+!y~;?Yb1azM4{AQ+LFDbl`cCV;|-giw`r?(;>se zk%gBmY;0}>7hEt)GNQ~eU;B_e!_!2iVg4%Q!;J{$$8x!1o?7%)Jt_QG{7neRK2e{e zlB+9+NE?%3iloFC^*gP!6U~Vkaf~Kpiu|}cxB;-g9G>DwIBv9|t z6(ta?Gi8B8Fi3D$YlFCpj?GkUnn)JC~@u#~DQ{UE|Q27?{W0S@s6 zYhbz#shkYnD$di9%XoQgZUx;Xhg9)ge~6Q|?oeY1(?-~d#-z&M*0y98N#X5OGNJe+ zVcPNLzF%!i7?*ZM%GKp_mX1ei$wHU*E!b3Wc#hmOf@tU#78f_Kn`uu~n}InM-}a5& zA+J5S+Y5EnxUfm1&xn^CR!Rxr$&k%S8wd=(i5}T~88xLTd&Hf042BD}S30ges2CKo zH!d%EM8z9duwUb!9xt@E#<{*M)3@yU81+ozl=)$b!mY=pk-7=n1<}K5|Fk7}v8Nz$ z2=b}vhNWDO_W0Wa>N&IUklCZOY*1`mr&#qzc%;nkHo&9ALF7@SJ7GT?zOcKmM3p$V0Bl? zN6cFHoSsL&l@kB5(7}cAE3*eDPGGjA@7-0kOOD$SoLJ&l&Zt)yiX zIoy?UbLvvI+x#_qORe#qJC)T<1*tn$Z(T3clZ;K+Z@7>WD6y;oK*9{t5+S!H+B7re(|UVMIPVda82VtvGTA zGFoix-HlfaW_&l_M&iPj(qkX<v+A?Jy!Cm{hz z+RR>KTGZYuBuf_aTYY_Gaiiq=W;JQ@v4ZMZhQMsW7cuIjPqh}o!x*w^p=w;#h^u9j z=R6A~RcXD#tHo|ysu1TsdMb)DuG6cUzkdYUK&3enXp|J`!#7wed14q1?MbPJD%AVyCZ}T0Y_waLBUJLp{1248{u4sM+4uG ziM*XDR)8z6M5PBD7QvJ0d?~V}U@GV6sGhE-wf64T@P~7)@3jganVNns{Y~=&c8M+} z3%!zk_*9jcwI09Y8lbaK=FbyUVs6@mfpw0jMD7g8%X*{zK{s6(OWLG25GvCP)>+Hh zq{U>TbVxk=6qhB4k%ZfhJ)!v~P8yk*_AD($1u#1M;c zs%|!(vG=-Rw$}qte_-wGW!~TJkfE>&`0WVHzN`5Fs8*X5q+fg4@JFInn5b=jLePK$!!hgQ+n2biFN zQwXP)9!?uzZLG`PL_N0pu4Qy24#{XFFCTI{o%!lpsaTE|J!*xsn(Tw+dD*t-Ss$zf zRz2CtyPeAc+C+NojO!29TozDLor?xhOGx$k6Xl9n6OI9fuXyXTOpCNkkK8yt@a$@n z=qTo19iQ@bV%5UY&+N4C9qWUK=;p7yS3e1fR1X0Q8-&EWZi6?epmp>>_?=^g1t#2_ z*g?Itn4+XJb_a!~vJ^ZQKZEaeZAq6@IOx!= z+C3ggBsCr{vK|xG-S_sE4clfm2T6q(S+8)%fSBwbo=K;#=#@K4YSAKdgU#P!n@w`w z84?p&Uv7A{S^dTg9UYyap`l|~czAena=zt1DwLb!iMd9a#rVH8THsWNbux; zJeo(B&q6gUhk5zr6~@k;DcjJH12H*a?IbAk&u+^L!)QB!=s9&yX!}4 z)h%B6PD?jl#hi^~EH|HO_>jy@S<hhv=8Gjca0JPvv?){CRnr`|~|n|Cr&NxNS$SCxhF$>a6dT!&lTe!1VD>6qt2~jOJ)_5GyE}Klp8wEr&{wFGiH$Igo)YWq3)JPFH+{1FpYR!Jym# zyL5rEOV}sxaMuPu^YqtC8BsQdDjC!4Ne&(!sN2HA)Y?l|=&!b(Ox(49L}^~YDBNaq zftf0H-;Z9-_^vkZBY{k32|VQQWGSRFe<~D^WeV8+TZujrKA8?)V)ol!ubHQ$TYcKp zE|YJqY1|L#1PFAi<{ny74FIafNeEJnf(Huqa=ITjlfg>vUl&$ekimGGz6tdzRoddW z*7N6sB1azd?4IbM^^e|&sx2tQ&35d!wK7UgW_}#Pa#f}UJhzA3>@87YaSvHn6aS`3fr9A947=w&D#&OuZ*fW&O;g!lEmB?Zn^G`CgL~)J@D4XO zTb_Hym~NQPJNG7`y6M)N&?NnEX2BC6&=GRmHqE9gA)Ul`2}G8I&S^s>=GQEXuglh| z3oM=WyIjge-K@>^fI4x2)#Z)RvSZqIkh|fbRd*80pW+8vlU(*{)%^|I<>$obKP1Pu z4xPMO5JC!G3JX;#Yy`rGDN)4_GP@vE4)=7%HWoVhF2deV_A|K;4SoLnQa$!irm~|| z9nE8JdVi1Svu{BPWSV_(e}Abl=pOE%xt$s9Qc|;yy`v*;=&O(ri)?7CL1IUG&BI2& z&Oa3Sp%$I!;X)II!y~ubszMWT%gupM&f^Us^Sggp*b^r*UVd}mW*2y1s$f>qyV=4q z8`rf7h-Hm(YTgJZiQ!={iBr4FxKVL#o^?TkRcrqB>zL!x6xP#Sh?2qI%b4CXhEqq% zrz8igQYr_Q`yy*eTdXe>CVb$Zdf1O>y_ni{8K1zqq+hxyx>!eHIoJQm`kV52)FZeB z%*G|tSLaW?0f-paj$_~_zdHACL#h{EVeCpr`nUWC~&O#56?eiA0a+ zU%KR9mua-#RZ1Xy{F$hIesy!~C})kqZ5C^JfEB~{4i^MQk|tP0O=+B1eKC~^Xmc|y z*~4OMV~~q1p8VY0TuYzt)2Ywqr{nv6X)gHDMOaVL)GHm)C{pdE51X9DE@B<2Ggtj& zn(@2XU$Q|=ZW`A6lNH&b`_~oPTyeaZ_2|WgxSYpE2SF_8 z(#w-ts)GzgrfW9A%xrzs;aerl<~7({G}f#8hs>?=z%DG3ja9iBjoDI3eujlHgG7Y8 zvAeswe$W|OU>|^Cyt4C(Gcu*nlyBvIL8w@}W*28q`JlC=Szdnr&1Km&+xLgrm|7`LQsd>`740B72`Q%c=*cj4D8x^U ztrtw1krq#K^ZlKcT&I zuu0HSZ09!8OLHS#WXEsy7*n}ktFO10h&h~f%GTQ&6xqwe9I-zNR<^f=Zn{P8%xWko@>_TwFVLv;TAioPK5#zyAr6 z#f3bg`6CN(m)yj99{?lD{2q?wla{Oi^r?hg zfH_vFhjZmpn=J0b3upz;SefjHm#9k6eFdZyl0oECbe&Tx6sQl!j`d6C)0@2lPSVg; zc3~a1)vCr2wQwW70oEwd3@%YyV7UIw*`6fkC$M z_^XC%L58+Qyc@nJ#Zqh!lEE~iKW1+RiMKun=y|hbL`1@D16%Bch zY!<@&#DaS7E*T-Ia}&{>`m0KT?iDjEv@j%4g~@GSDQK}$hq|}8e4?!}d^<&gK&X|$QnA?Ne(bl5!8cj#6Y>uCu%Q{t zPc(LTedC>@!v1s}uf3V)Khx28P{#d}V$$Pj$hv9BPNUidQnD#ND}Ld81LkNGrJ;BoaDP%eJ{tda1D zYiT(EFGeUE!awbtX9)XPs~*m@<(zr*6E*)5y~CwNq6Q_C9L9mLcz^|`i_pQ3d#l#V zhL+F;7vNgV1m%<4)BJBLl(ISXCLWzke}pf+vG9rA(3$r_h#R+DBW}3!}q@~Y84o;y7mPutuvUc7g@UmOx7q42j z)@4;F(alTk9~>;dVSq_JbiK?o_z*%xKhXIsToi3U%Ln*lCFYl?`eOz?1P!9I*US1^ ztU>LYf~VF!BHwirLEB{H)w~b7YWkVUZ^goD7wluq2_)5=r`LJW)VKTzir=z4s6!>1 zt^Lj@C>gMYMqB1FRn#%LPf(M-1v=dEIId^|q0%R8kD15}S-`!_tJaF$-)ZRPeHDd| zj+LBaKFo~P_KKn=OR6<*?%|85l*h%iWE2=DW-YYrN=LdyT>X~aIB5jQnoue zSHx7sN*MB%vZ{#!*H4C=g60(yrDRz5`#$;Qi41UY)af65z=l5PjPi1Er9eW+(GN(1 z-vTVI!1Ks;sK{wm&ze8fvi=&@#|IzFzaLf=tIczI?}W& zhTFmwdiWb{P}*ItCj~GI!MNKq(c+Ugaobs}St* ?uTrHik}f;ldf5SV^c|1fdUc zh-l0ombxCGn2efITC(2uce?!F#4lP?SLosv@6 zrhqo_`UZKApr%MN^6d%RAt%a2~!%R^C}F2 zleKVP9>04)dtEkO)D`ps$%@Ts22_Neq$-3k)m_VSw37ZRIsamAj{3>;mQn?wQ*2_& zT44H%b2S!;Y3PvD;WnG^uuSc?7N``>c=;7*WKaOatLM_5;-zomD|&EMlQ*>X zDXm%2-ASK|V=u_|Uj+x7tNAo)+zATmF5o3TZ}`HW9OgD*@2%^iYpI`?A09x#{W0w& zNAMZub!3P66boyUID5}Dt(n@S$;%hTQ-D8H8HSr}sBZYt-nX4=k%-(9wrj*-CdZCo z|A^n9fzqtB8y1EjQK)ElV1OW1fYZHMgP`$FPIZg}_+ZK1X4cvzT{lKe0 zIMmrt0pzZTvQZnA=YsC*OK@8O;Mo*%C6T4On0v8$0pOWXLG+ThUxL52M!8j=p$Zun zx#ASWBkUnOXKBAE`rE6U<+b5AnUNLVABcXu*Q+{6j1udsc&-z7-8?_)PZ7(%mk3xh z>1kHLKhiE~KdO5Qd?j<$z(J%W>v3i@MEd2!TJ~)fxe~SIps7m&SpeJ`(!h1>fB2kH z#c%hD{WHgyrr=(}*#ef=W8@_L^_}Y(g+XSGr0g0~b_(nt=M7$XSg!3pD2h3)>R4@F zB#e5zLt!@H#zn?EKqck)n7mtu6Ud-Lhx7o`kg<{>FGsROK7NUGi!D!(nF1TU!k|yR zP8&zbq}Vh(ua7=RyJR!$aFVzydG;%W3^+&It7FzW`Je3pL}6)*nMiL3#FvpI`$4yD zl358X=F?{}`CjS>NsD2wNYQPfO)mJ%T$U#F@zd?p5!2u#=~Lusj+SIc*JjD8Hq;6n>sY`-fQg8f!j7F z1yA4G*bJ*snlo_mnWuC}^A$jO<7?c(9UL4-&{$rWGd9esimDrs_OT;l^GjBy0p9MI z<77>L*&I%?1jT)-C3Q}=Mo22wu$h{3%lK4FKN6%bwlLDQJSw*0znil^YsTNU_GYm6 zu*=MdTbrk|B4(r%ISpZvPHxMtIfs4>*hi;QV}O4We#(Fr3lI){Hh{p1*A=+5#-~}j zCmV{zB#ZAmJ4Fm4yQA9YMK0aSvdjI#V<>uuAES!9eG0m#Am(r?&bcq@43wt_vC7Ug zq{?AakYH6X^KnuqtrkzA3~14daC^1Az0&U(dTCi>HU)o3dxdXn9CgNG*0S;t3wH2m z%SuQt55dvMVlU#$@q%+c>bPa?bzuCqN%~eWJto!(_&4Upm$O3&)E~P>;s@d)8OgH3MT;D$tYWW`#{bhyCl%{ z1%AX2G#HS#Qps@LxqURyN3;8R#cOxo3E%R#rt=c7R^|GzNTB3ye|U zemUJ@+vGMIeYW%g01gxshs#Q48&cEIDAY!RTO0;`iJsxMH~01sZI;c2Nx;WiZZkyJ zlTVR4CLrPN_P~p|za$fW_KVQJ|-K?`_bj+3ZTz5LT z7qASElmh34{&kvcrPM@x!9%%Q<8GyLLZ`6Uei|IoBk9HV>;hGJjy?Ba+c&^05(k=I zwYMzYV`MBc*z>Me7mk$pI5QjT@UHMB$S- zEUa#74x<-}S+8eW%ENubqpTM3XU6*f7!P5iI&*EC5v!I)rj7K|oB&Ow(eSnk76+zU z?u%V|k?5*lA5|z|c=jxN=LWzUCv{aF6M~Kh&F9muS|;%hgOqd`Intmm_|>aFuFwte z)S5M>RDR%!3I0?|5-Zw0bATG25*{jXd6Qls!DdPs%fIsOj71NV>Ga{a!#;2s9G@jE zzScJpkfM;Zrw^(k=_qFiN?f`|7B70=(L|?9N=@m{obP|Z`BU?pk+H(10{$`YM@2U3 z=pQyO5+w{Ii4DV@tOq!{RRE5rcA(9gpPQ%9;tN_}JR=GeYd#AFV7m5=66wvsr*7Lz zN?w8PTcvkrjY@eky}I-?$sw;Y2kMApxQ+*fWKD~tsd_Bk-35i2ED0?%a28q1?ahl| zO(j`3%g84@lRG<=hInAs^F;W!R)EaYayUe#+*Ca_oju|<>+;LW{U692#opc7$Mday zo~tjB$T6yeO)7%hZ}~=S#_9-!_|d)>LBM}>lqwtcFqR2dO0>u@JII=%;FYDsUG#Kfd)4O z=%~t$U-2W@W|J%T5SG;92WT*$VFR8_HhN!$R3uR%5_v#$%Iy z6A|tB76$vnE}HQa#9xIn(xIhFA6odF>pDlv>#)QN*`pJgOY97?Iq!9Ri28av_#%8I zn)I~Q40)4X{mKpYo)lZ0)?p(_)XJ=)53*&Tdd!_>NM{*S`aiHLNX|lA+JqNbN`th#@jI<^R{e+^PaY?zd8u+hPWJb>upM~yy zj%s|q%WS4VE{2q~-7vp2ouL%FbZ+?*1OnNdZ;{bqFk=;bHT|iWQaLqc$zZTxwm7~O z77@AcH-gKu@F1K25jX~3)vT`nVWnzkzN|FAky^m>aGl;}AD9$f_aW~?;q;x5Lz_*4 z;89`6!v!yQbw7tyx^SN1owc{CyDdijkIWagoCX+{lap2Q4seNL=wQdiw8l z@kNLmw;FNA=ev;^80z3h+%_tWhZr|!oRTR|Bz@`ksjYVkc|fYG!>JrsgM5v@-2G{ zf}EwH4B|`|8CxI6+YxeK+f^By0UOyCkQ7XFoxvQ8g@?v6!Bf-Xcipz%FCFYmo~X;x zOH*dHQ7#pgo>S!XMC)hN%6)FeXAYL^nHse{ST5Pe zAaZz~%h~F>9@H4?th%gP;!wM8Nux_CVy!-|PIOEt;N)E}ysc0BL3%KUb-BO9(!w;q zpV7)+HkPq4Z?>@7u%WtXHl|*qd?0w8O3>FhQ`xgFs#zk#i7eC-&pRlJ;c;=Z7?m0& zZzii+vq`?+yS3`~Tl3SL4XHV3{{9+>57~B~cV=j{88x>02n$u|{yHE3hsU`6+IS7N z5Nlw-#5byHf2oyL;sSa?05h?jKjnDI590a6FdP{vP_>iA=_&B4!(Hnsv1n)t>+^HA z5yrRiZk=yYo#bV9*B=8Wt~GK@AhmPjH6uHGp}9fM)jWI_FK7>Fm~(YskbIJoETH6T zf7g!sfNb99!iO!P7OqULJ3Mz(eW)*=((utISDJdNK6Qk_tmmntD!B-?V&qOA?Z88> z&2S~vz(29Sr|c2#jIv6^#n)Rf;eG1gQZ{b^IUDT4tOH09pOrfZ`W$B3R<*+H>pTd& zJjQkbH{W1#!ArHBPC@V}=v2rHSQDz;I_S8Krb3uHaSxDI{52;F@Btr6b0cvE5Ji?g zYntGO8`;~d1|68|H>Vo|uvfI2NJA?9v6DRUBL!DR5(A1(cJlk8vi%;q`U!E*_Fuhv zWqM(eNb=UiS`oK>M`*u#q&mZU?aV6j@Tr~^^PaH|gB=QK-n#5BCS}Ub zM04(7BXw4NYJ#LGIsEFuDbh&e+rahBIy@a-Swv3wt`^@#YwnH2m8)0JI~g;~#9iAn zQ%3%RD!^-_T{x>tZV!U$XwNkt5D&`am`?-`S$i$zH$E2L8_kEXnroM!sgXKWg8QAT zlm$f#bvz?`6nR?Y5^hZ_`czR&-?*?pqN{%lV_tNVS%0i)6z&|YbQ5u$iDc=m+#wL& zWeSWDtpri2zSmyV*n$uS_%>>SJzje)EqWDOLAHQ79H;(MBpf_->0-cm6$amh4ecUH zvE<#TI1lx%IW@1X+3vAJ$0LuKus#T1IEo?99UV9dN@t?C6ZYS(TF?&204D5T3gt)6 z1jwan=aF%EOnG@?X7wu;B-1_3Fkcq5F@zCXxTB=%_wx_(bJ-NQb`BjJgGmxmT*|~q zrJp0@!T6v>Ub9Aan8bI)*B@c!?oMohVVwR?cm4yK`r|qOh{*o9uOCp|AAjx}PWpcz z#r~16_6=P6{{cY%|AnnRW#3YG+EIzmujFeU~xY zk|6XQ%k*b#15@Rfm#$~+ZI~$N{0v_F+wPr-A-;Axz#MTn(EXjM_(7b%k^{UMeb0F( z#c+6S7kyVKJ1cDC+8uk`h;qt}A3}LZu3oKjalLgJyc5MA;--$2OSForn=|e4-!oDv zaiA@3QC?HEeQ(bo8_J@WVvPAuf>Pu!5Tkzh$e=MO*T9yea=JJ>YvM|VP^0lq1YpxQ zcfv)V-%)Cf7IFKYBw|O&tGmtPwV9eTBwT=|Xek-x^h4LQ>eB<3ciW%jI`aES&G3=g zF`#?<^7N~&6`CWnM&M3vkP{GWM)K$9JqRcmz-&p&KD^AUq}uprB!tUj6Z7WH6>4fd zP~t2pC*D)zcIxG?S7(U}8+9A<_M`StmRy^`@r-!f90=;M`Ae`dVjw778vry9iJ+u2 zIr}f>;spT0xWBW#ZLXrA&^|ssK0mJ@9Cl9Z|6=dGgPKhH{!!P4f`Ebs=@yD0K~#EG zdXe6Ph%|xF6%eV52#6S}^j+-TTlsA+D&|epFpKoXl;N`Uj0Naa;(aHHq9&bOeehgNVff+looy63J^v=fkt|}J{M+Cw7R_-^9%_(c`H!ny zuW?(BX5Q>+>^qnXP+J2Bqhdu9;C!ny5}B7(O>~0faugut79HH&a2b;`1(R2HQ%j*j+eGzhb!mi6&=?y{j==>qp`>gaVqdA9mad`A0AR@dEI4Nv@J(pryeUF17K zDYk7^J(%;V&T2mVc8fJAG?HxMX6Y`zlSbA8Sy4vylTS=388<;1LlQ=mIFap(PZE{Y z*8Ta#=G19)Ku$X!Nd1xpS)7VtuccwnIydP$1L!gDYn!D7M`Y zeEuwKLXRQ@;M$X>Z%czz3qEKgrbnE1D>?!2?i-*~V9s%7LXw$04?8=}<)PW@r9`DCP=Jo@1thN%*xF5KcpH*XT5E(( zYvg`8!C!<~6*rr~yE>POjA*9F$2~!I{6=mr^65+V-19M@6kWJ&!Ire&;$~DdU^dPx zTBSb)iZnL7BO)XuudAX4aI*eH0=P_WEKYTEPBdFG^% z#fTTOKHTrhAdl2d#&l>bc-ZXh#T^t2eHml?R|$}#?1op+jj{USYtyAcNzU-{^NKrg zeP~(h+;MD70?Y(#3rwtumY#^B1WQn))!hE`#6>}(kdE=2%z(twqOzLzQDjqN5-QOM zY2+~u^f^SW4)asxUJI{Rbqd;*yS6&+O@^m`zGI{D?=uA(Rm;nimd4-KedUtm$4+}M z4^l7ItaQhhkCaYc-)MH%=c5&b8a~cKWcisz0FJh}Eh9a>63!wY^q7J}Lf8>cw1ciX zq*eS_&U_9fSU&51megQY20uyO@H5!Dxw$#8$OpBUpr1R6 zK4_)?>Tw^a>gP>cycvY=moFB(qI<76Xef(0<2oKZ*8T89)4Fz1(6(~6v$)0H<6GFq z5)O&AuAOCmD*k;g!nd4xcj`t+;rr2j>%F3dg z0R>oL=QY}X41+wWFm?Ze4>dZ4NG>i1W(l-(bR}oAf%?~s2hwWEfc}yn0s$SM`LvvP zL{?j7^-|lUjrG)Bx`da5F*Q_yEhy^KEjFvo^{L^&^qcy;OCLu-iVDr$XknEeQVSaN z@Le1&xynJaHkSe^bv(Z<7%eInj?Wc<3N}o7hbXCgl<=e}l_;J|TV(FPxm-1S+CDK* z_^InS3P|moL!X3Gbxf!+DzOi4@vUG=NtnE50D{VfPnD%q-ecYmZ+->l4<7+zCGcAl z{OP!vbH_$-Lgk(~pVxPh0AllNH2!PtQn0Tso>mimQSh)6o;xab5Acj}u;qQ^Ntto2 zk$KG@Y67zB4sZw4?(y-5OaU)dIv!uDJcr~#Dp=-iW7=N59?41%oAM338r$s4+v$qR z;XwwraEXRh6+2{S6t8?Z?l-aoVcpTG9vvP1QkGFagqOW0^08Sr$7f=~xGU_+ag{r3 zKOP)F#sGcy0F)Bdav&-s^v7m{4!KDh_0l&u+xTTb!{~J^`whFqQ48vWhQVF*0ajo` zAH&NIBn(yS*Oj+!oYse20Qs(X(p?t0(;vEeSuJph8sO0&e5|BT%Q^3b_y-6CIPzwl z43R1VL?2+smL0MWu5x`G7}+>s8WH6^as&W)g!^2LIx-otc8pG*D7vR_doKy|RJu`x zm_lJ{N*CGNnLgnf;DV3nhkC^k$qY%6+>#!oTZWbu{wo~qll*+SX~Z@fG{3HO5)pd6 z(M@%ikn&<=!K@8t*{vC;aF=u~$rZBrkVCgKtDCSvpw>r4%)+OKVzQ6qm3|u4LE^!-yeOsB;Ejd?I0Hc_C;Y%|t#!dezpHY~u@O3c% z=}but^mOo)%Q@8eu<+|dN%jFi8<`gbD#$BVRGR6`){pH?Q}eic=yxuA&_GH>C)5+hM!D znzHuUqL?ENymig$<&M%b94aDk-IPlXCFk0|eVYNVRPRjs2~E(JN@B{Xh4DV8xYHIT zijdiO$j2%&JAD4_vZnr?4X=fZ-lj)MkwmJLmW^q>&Ja(l{ytEK zV=KTd;RM>5WKWIM=WbhTC$2Ss9$~!U2uA2kVW1=lG_UDoF$LlV4PP?x776&P5lPi; zaHBAba?EiTcTEOqRz@Npv)V>znF~~pm$|IO9bQFHk!M3z2(bM(%(=zX3U;BSHrZe7 zF2~=r!;HsWd7W}Xsp=7p-~}dy{0HUx`(7P+$NG!_g>awB2#&W4z%R<^DtLxJ>B5gx z4ghb3m~0*gPLE4}782Qoopa#jBMUu0M&S(ztJ00PG636fnMg=OJv}ey(qY-|}=RgS;okQpEpmzOQ1U?E(=V_snPg+TSj{ zKA>0Gj44^ivPD8{%%FM!DuuXbsMx;=ArRwn6hKbcA?(7r0I^HR52VLaz0fA}0uUw^ zN@1fFHPi^r#f{!3Q5i0?WfWf#$mDu@8Ua{%D-SqDI2j90o6H}&^o5rMiEbR<5SO}oFU`k3DyC2 z@vFJjf4%n?_mRL>As}}O^@cU@nj}dvy)Wuv{CCPyB(lY&n8F%9_MYbGX|yHUah%2Y z0Z2_nSWRutz~&QtPH%1ZR^U-8DU^$1bBPArxF0D?EKxb z)TrTvlP?kZFWynzr4uvo1n8>)A0(CqaanbhaP8v?VLpoJzTidk$)EIYupYBf>;uFs zyef#*ELx`gPE+k&^PT1Zma-kd5C}akF?;`}^Txf0BlXHEeo{bo+bU+zf6)yWTyaV` zhX-cS>*(T@2#hE)?-I`^Fas3Ia%F>RG?qabN0}2+klRIsFQ3)to;>4;3jOS3<|+9+ zQzKb48vf`CIX%fEmv{^igZo3UhC9hxR{p-5a;7PBgFRw~Sepm4PPC(pHQ++&(Ol9sms}GeNA52H-@v^!GKTJ@W ztZucGf{(8ya47r}x0N7Sq%&EbUrT<;yX*Nlv~o>imn2(dYiptE>Y#d}Ch=x)f<~~l zGf@OE6QLEMWZdsAv5qAVKb929`2E>>PhPg)=QBi*#@xRMh$P*Q)r!iO7=+OWI>&Fc{mpb-qr(n)Vr z&?tN$AmYC{j-caHe|O7-=97SGP?4_+%XlztA#0pChjX0M>qiZE*g;MIId&Ue;*>(h6*hp5R0&(^2F%E9vrU#P*<;1*f2 z-hLcK@28gQaE(#hwiEEUYT-Y=V??~^TC$=w+RdL*|t>$g8y5|6_(}iA{L4DBTWhSQZ^mO?nXA{YPuP`-<4JDD&Dt^IVDqu+M-oKRW8AzYc4+{dKKu{E6pRxg ztO~90P*e*?kQLjqRTZ3WW9V5IwF_mGV*Dg?3S8Ww_W|U7qT8gs8ko&=ED9^<$t#@c z7-yg75xJAeBEown-V|Sa`Z)R|YMp>@&ob`d3wd8{Ax4no6+M}6W|gN4b&g+Mj?CXc zhLzNKhTCih<^8qls}Mnb%=Z=}Cgtr$ZGJ!sfhtGA2gy}eKxK$6tW!N2E_(O0Ijusk z-mts>#YaGe9l>`vNwcBDDJwU_ zVB%&TDhM|<1eN{NRL(oEnA>E+zBg@$?Bw_%cZFdLrmnN+3On2)+Cw?aOM@G4FWXn! zqol%HAmHhMvLnFg_%2!ro9qcz2cRD7|C(WmA`9$6g%j2uazb5 z+TJfcmEdn(%VQ>S)XeBg^cY0*$9$2#5f#SU7js4<###Rq%JjieWc@M~11+t3Iw0Hc z&1g#dGk#DAViJJ|o|yJhOYC>))qd&@ z)o~W!N=9ss^|_`H*VjOy;m*eLM#m8%>(&OyDz{Fjwb>xT=lDi@Ch|IN7bJzeyk3;72#^^lnJX*U&^CNpQOB70oNb+ zR^gs%Gow~3`MuKkIpD)_Pn2NuIj!V8qAo|_Z>KFQi*bxc2k{O$qQ@&_Wkf3=EF5Q} zJ;Zt{kNi1vn>;Cf1Xqhj6wk|oWfQMIqDSZBmg^s8)b}#1NxWoLFZ9Dt`)P4o;Ydob;)8C1pD-eqnUPqAGY%l6bsL}ro1 zdX6OzbgLVjX7N#Fj7RqFr@;qw9WG(@LEW)V35*Yx^GDiw!8Lh;CY&qgJ$|&cd$z(b zB!|^WEokHsaa+Nr^*(2nx;zCepXf;gCw zu87|?gn-7mK^ufC*5g`F@PZY-%>HqM=7h}LJr`2O2VmN@YcQlwJJ@SptDIHfa?sF! zl@3wz<$BjEIhc!W_K8?nA`keAJIJ7$28*!jXvQ z{nol`0iS}-COp}%9IFP!6m}VAs0T!YAKdpBidGj4%DLxh2Z-%{-Kt&l*88`kJPi%r z>9TQD9yjJwRh#U+bXk}b0gM2+;)~bw`0d(Bat16~s*bC0c356U%*i{6^2fPQdgdDl zsu-37Z2HB{tNfeaQN-zafvHrnGFvRx)7ABfpnSZTQ@8PpQ;I0}cZ639FaE)Q`S+eX zz&PTH_rHIB(sko;r;xph8-NkFeu3>odE4(D+uwHN%MNbC24f57`U3ZNyuFosBS7>2 zpB69wiqZg;EmF67^@8^bjrRoj@aTGfIa?yYad-b0KQ@;JKp2>{I@)KQ^-?0329hX8(&({#!En%kk$oSl~As zn_oKCAJ#PgJK^rXTdDm2knaB*n(O})Al?6ma`JyZT9&O(A2XM``Z8zCoA zGBeWZWT=1r#@k~)nhE@#Q$8Cx^_;QPGSJ4KOZlJ7h4w0N6U3Rx-64Kc#lL@(w~wYV z&P;N~X-Htdfxc@;pfwoS2R#0D?(fZeizcVdlqNmxGfmB(Mixn&hmEd}jUuDG9Xs|? zrUtEJ4fa!~s%H06t^Iti5J1N7WQ$)I3msBmX@+LUgPqQ!YS=PY=S zegFh88RtH|fEeCH&n@^tfOKw-6#U0$=sERMP&X$`nj9x;?wnQ-Q%852oIcd8Q7S0u zG`y$u3TkdB4I=hLGAKzMuI>kkJYX;S%_Hr$D$vWLTC-OgD!uk6eHS-?q z)<=$XcYyP1AyYY5(1Fw_D;l$O3t2|O1Dw8e{~|H?ql#ER9ZRpQJ4^b#W5cLK@dK7^vJ8YuGLwi->48-xpiPT#Md{Fe$(Al zUJdh|%wD3WW3{63qO4re9SMMY0T=(vc;*K~FnattA^RD3jRqz73wK zpj@Th=*gu+w{B-YG4^-DHY51cvrCC|Zcu6gdopWx8r4+s1s)+GD^FCu;UvY@){F%* zozy_vn1=pyMb1syAx@zq&V8H4c^&2kd{e~!Ds4k%_ecI5{}SaDaP#qfQJw8aG|Q{< zqbJ%&JQ^x77k+FMf)a4(t>sWgHmng|QYggx`}=!%#^Fum22cC+0qMV!v9oAg)11>u z5)y#9 zhY~KNxE)u)h|>5FyNMM;fNEkz8Xw^@VpOiNR4-(wq2L7p_eoPn(waJ9ES9`@iy!=vbY#j&E z)7{m_mhNtDn6&lX%iT}JZLksd_waYm z;lCzk4Y3i+21)UJ;#n6;N94Z<%Dcv!nsKWDx4zJkk`{D)111yG) zMVw{$CKJE77u=Y*#n}6tR1vNM;?Op$B_rj0;15WldV67Y+pU9WKVfMVAfQaoz@U{r zBEef(*J?s(WaSflSMJ&tqXazgDy_0Wax^NGJBQVHOWCyIPq@*ONzX@7nqY-E0>M67 zfigh=`$ZSalq0ALpZ=u!A7&yC3x`NbYL05%XgqQrAWB`eWq-RFw}bg=?>z>f7SH`k z`xV+-s-kNl6K&rm#Q@%2vn3tTC0a85^*|`VM>G6oqq(uF@jDaq9sjUJWwRmeiSwy8 zV}b%DL<_>)Nl>yl1S!;98aIBz#MuA?9D6LS4-(*SNIg&>@IMx>i{p`%rL>SbO z?1$M_`JH3Pq$DOrq>SLR!S40CR*FmSO=Wcr5D*&{p8yr))9w9?-SPOFz)Frnio~=> z*EFsW3|*7N7ImH8%=rMRC>5-TNTt7{SF90sw3QU@$(icU}qg^+27~QQypC~fN#Z%P&QljHI?I&J!ZmGKYKOr z*n8DPMq#1gTvHldWsaC9&2v0rYCtCS2FxC_7SO2xUb~~*$u85XIYY6u2yAdp_Q7JJO&-&nYwp7B_&9u(VcrC#9(ci58)HXeHJo?3a{Rit0H4Vy6t}6rYn%J{z``KT1X^BB6 zsSpt44Iz>AX3wL9d)zs}-CsrXI{5hvJselbuC!jwJcqKmnq6C{;I#vL=xF+wQu7|; zqypY5;&a3KQr|%44bgigO6MiWfrYl!wXQc=LvINLoIL6izW%s!U27$VKxJhr*Xo!_O5CZTuy5bw^j~q%<~D7E#40yXCaSiI<6m)C ziFxv`hq^|={e!m454Lxoj)fmrVSYCa(!~sI`v4g~1T6P7?8eycZYVT|d-&O>rCv7T z;D4G?rYqoLEUs&%ivn5itBv8j?`HfnaQ zQuVrmW4>xhTvuUpw{3Ij+s*~GkK2~1qnCu!fzT5oqOiK>g*i&J>>YhhmJpn<$>&xU zXLbZ}j2+*r8RWqgz|()NKf7;$`*K3}a~&xYvvBMSKd}ix+v5fZ&9lXpocXv9N(>0S z+;gy1>UL8~k#teU)3Y&sSq_npGUg{c`5$|SgKUGp~q;P0V_1Q29d1?y~Ov z)o&lNs*5D4F`q-+x!8k8p|P7b7(G&DOeIvO+2X#t*R?&}a3D z;OtD8toYs^0hKDb(Gk%x_RRBC6ltCoE(0D4Y&z>XcG=1|L0|Y_oe8O|K!Qk_7Ti3I zy<~n`d->87vqnjLwiAnEfXAp=c556^Yjg_d_s1I|QsZUp$RDSewb#REH0F4m>K3Ay zDbbe>@u=~m?3K*dYMx}*)=HdKUrmwByFB>zoYU7bx<)*|x#D5^Jh!Ow}GtFHaZuMxOWxU#Zx7CU%J0T{YZy$G}AI}jFB zGKo8#uqqzaJvd=?10hu2S$8$#5ZhG0vq5-* zlD-D3v7C}7P{vKlH@m!PUI}E(ptxESsMzLW!~c+JYw$x}@m-+$*Sn~*1Dq8h+SN*L zoJuwOX`9#uMXQERmeap=5?$fQcIuG~GECdmV9_)vuRkC9qt6J~OgVSC&S{XhuEo5Q zO1ctbRjixH@WJh_d`ePT`Uw8~7z!Aj(+!J#FLr6Ad=TDTrRt^O zclTu=GN|daK6k8S+eA40UIB!H{%PrTT07I;`x9}4v^hvd)k006qM{w96$ll^15p;cS-=f@qksebTccvlVo-&Rxi&|u-4sW5+DDVpM$A12xJ zts?PuQu@pUcd?52)cXdwYeF0A3nX165QHI6H{hTdM8)_;vlN%7VSrzn8{(#-q5_LK zUmp%=C|Z>;ROLy9ifIm|`@&50qW6s3sK#!ajo5gQ=Y4=4*KqG;XNdIg&1LjYj58$V z>mO!)LpNnNaom}pJj0eAq7OhP4cBNs55O70O9Uz0>*SD<|M|s|M~v5|2%ci zAJ!3SL8_v~Ne>S-jt^Np!#0;a}V z^8p`fTZU$cb?=*jMA#VJiHYk3(nX(<9cM=_W8nkrF;%e@ClB|&OnY251zd|6Jw`w; zw@55yOuyCk_TKcBGN#U)yiPc53UE>;Xk8yTSRGs1B^JF};2gxS4OsHol*BpXGD>(^ zX##kGroDWZ&4!L?l%WhpWHnA-za=bOQCQS986k+&ulRD05BA9<=e2BMbV=idE6g1x zl|da;Py03}1hE~>n8zO6#@XHB4B;n>#Z#qff+E42(E)`Y`M_N=I#CsWUir;z!#*pa zns5TQ%*!km<_MVHPx6mu0&}C&700MhBn?ct_Z;3N&&Tt|eamuDsYJjVX+Q|}%N;b5 z%6**wldtH6&OI_C1AqJAayWb1htMKo^+{I!go zqx;8Lr~X!`3H*kK1N~e27~ZU+!ur>zST8|-%4AGj<1sB6H0uGp}h~hu*LYIB4 zj;r`N&&OwZ6=Ef`m_63Sq4ql;JIdy#^7sw*odyPKib^awKT|mG=aB$KA}ZPzTVk7* z|FdN?bJaluy3>{%w3Y#`aFc5T3~o!qEB!jXY_C9Hhu9`0yXMf_!<~0<0S>GZF4tKy z2wrIBbP>2m<&zz zVU}AKf%|fu{ecEY`{SkT$y6sEc=2)WXV=L3t`d4$w-sftTK9TfE2a(%QCs53Fbu!x zthFA)7CjO?rVDp+g$LfQuTs6;Uj&T$dQr_kQd>^^EFK_oirab9J_7fx;#p27Fo|z| zT%a*@>RH}HK=Nhs)h`H0o=RAVWL0?TX}f^d*(JEa_IpxSHlx@UO>4KD+W5+?gfcX9 zmBvsvximR{9*ECK6SOQ2npA5vZg?aoZGD)48dF<=-fBLvw+c-bS1&Yl z_9hHbN)klw=H})Uw*c}hqF8S9u<_+uBn;`5P{~n{4@!r#(3&8xw$e_M5a&#bU3G5^ z{7hK*w6O3)zE|Apx8(|xa7s>1OWT$-ZOy34r=PfUxDySpcWA`psr?+|UQmY=<-YiS z?e)WRy4CdIugh@K+w{Tx%{>#WnlFP}%HR(1O;lG;4?y24_bV^CqTF{wSv`-A-4CD` zPS3C+KZ*nweEgUM!I6b0VCk5?(FYWZMn&PWTY>*@WO#wmZuh`s!QJY0Zs596#O>K9 zy8{y~=20N5XlsteFwQFEt{I6rmoI{np(bhzjie1abU_}m*#||##{^KpzUn&o`~+0B zs~~XUl5JY{3D{wWh)QrM@uu~H_jFvR4C6`bF;4;0ah3(@@DOkt#mC6$S6YvqieAc2 zg6BU?*RH29Sj9A6NgJhJ&Iunnp<+V9=ID?n*Ka~q{F1fn;p2+)bREwbdI&w}UbU4P zxN6~Ryt!krB@H9eK4|c2W8pxj#pGCBFVY^R$IR{rUP4%&`1rSqLCWN|2mD`XKz z5&222C+=+@uX$fXtVC0^`Yr)}G;gO8KmH>xA)pdxa;PDfgvSM zna_t)CV$M~Cu`5SqzVqQKMWME%M8#H&l+Uv6`avcF1;dM%L$s6yX?L zkdpu5r1Eq;<5jJ}jq}7`()|+{z~8!gGptdm7)%S>v6@8G=?g^Wl!zjeVBkn=hU`(K z4!Bm5=RO!eUt?T!*Kj)vA+b5*xv-0&R(+DEdEX9Fpm2k$>zD2!hnQ~wjo?tTEI z1Yi&Q_9o{MHdh-y@ibnIW9Lr4E>8iEgWFu;u{)4T0nyQ$N8xB8r?dK9)KdzEH26I~gJ*6ku@bcZ3f1oPeem`b%eVqcA)b?1>JC@Py zZbK538*$z5)khR3dupf}weTKAo&=66xh>v+P(ZEPV)W)I*anwK60}-r=4`<>NoQ=< zRzB6tedFg}EhBnELxX>g)E%0V!>xD$Oh}`YXq!Epwg|QaoQ#G8Ppj8K6k%S?0Yd$7 z3ntIyaVR-6pTnNC|3P56k8KZq>Qh;+OkSBnrVDnfi0M?N=ApUq+@t@%E{WI2hcMr| z`JJ(g=%6SYZ0_F22sj~#8@E~O&s4Gar@d4o_c?7nKc5Kn!8ekCrK95e>479J%apaf z8Oj07qL1Q}+$QH;sV_turmg?Y-uox6`O`f3-@51jl#>2id;ImUfX_pz;m7~ck){0= z*Li5=@w3hUTLZ&^|xJLWQRQvA69`ul75|NE#M!IIrPA_I6QYri8W|IpI@bXit< zapX^cOYLs`E|LEi-D3~yrlJ@;DF`Im0a#7|U>83_{0_r~4&QY)lMgjt*H4^8_E(_d zVNl5%k6TJ0QN?rH-W)37xtH3#T6VB5j@}Kj{z?h8cO#g?x5}fJPeW^K&C+3B6GaE& zsNGKeWQ{g&!wo|B>Zfvh^|m&*+KaFUtFyz{$IS-*Qf)U3QA$vy2ky?6Tfp_$0P6kS zAUYr_d2dq;{;aLY^Ac*e-NGw7s{CNm$S=yD^VzO5b9DU6zfXUpiaq2^xY$mrfc&E@9G z=nA6dKIO@TNLu!!r$fXvQe{F?VBanMA!484Jy)4v-|wjfC0$6B>4Ko=VyR)@Uuy($ zqO$*)r1Bpc*ULM4QE4*;lV|Dx$|XtW69NA9=%-TXAB*Mx1hesfqQn1OTmM9N|G)BR zvF|ApIyXD|X5XqDAarXNB8$|jmj;aD?tw5-_J3F612=~4WPA7FgIJMhBd;w#ng_1? zD2YwqG1aW}Yq|KJ=p#5KezR+j1t3Cyq2Z#jdK-5wV7~x`ZW14McmDk>TOTlMU;nw~ zf)D-f+#dj>emDS1p2zz9`?so`Ng#e55L>9m0#(v~{r|vUA0-q%B`;eVS@znf)G6w; zp8gcs>I9-*|4a5ti%*}q_nLqauA(4vyWK)!r`5U;n!i!K?D;=FwV!(H2QZt%;!rWa zXmrqDZkH^B#}PV;y!U3R#CP6zMUy4~eJ4nJxW&)^h+PQ$BP=Y;}LvF{VJAEWK7inr?Ka}o5w5(qu8xw%Fb_A|n)bnqzhP;jB})uML+pnH1Q7{`5S=g0HK zeN!^ynBwUbbz(*sk+C4knENw68Dub-O-Ls|FGOvh6@-Gr zn;r?n6c#u#53|na^wfu0>LtQ@FW(^ad>9;0GiNmGm5XGsSj9gVHe!tQq)eT=2>8)A zZER<#hO*wtm{Tfypz#+mb^(UNR=HAwkA_*#g|mxvZkk0jq|6{i#X0{<8$e23_>nDn zkJYCSVYIa{V7Kjdn-B?%D@v1hb}hg=Y9`F5b|{}z0k_csePtCD$Vq4}Bi{mu!?J4w z=@_;|dOIvQtrqxv;mq<{E#bPRgPf2wy~-0jurgj5&-!3agy|oFIBd&mIFHI_&3KFn z39U(_L$;s!%4@gaey^2}vfXfoh8IsTA6gXt`sQhp>t^j6+{ym zjXgr*@Y$MV&|FdDUej|D44A6O7CB;Q-{FFG%KjOP0~QEw9ox0EsbU1`ys}PG(oFEkUKM0{Gh$3#qtn@&(mWKR9sWiyAwsn{ z%|$nAFxOnk(aY3)UOn8ZLl4K=uD5(dlCMTJdrK+9{Io&ADhO7I`m#fbhc}Ldw^^F+ zbZ(wiTT^3Vjy$Ym=8&Ve6oI$S+@ZJ5-!nP#xQfx%Hv7TX{U>x7fn@`iz73;2;EjxK z1ug?5ia->RiB6^?E!Nzxe6Z<*>lKpIYNHrx^0JVp&EIx#CvI?PY@`%GuFFJw1;=t zD`}G6$=t8#{EWq{|6FeWkx%h!S@-$ZS#jEKf3Rl@)0m2r88^GoqT<+{h85gW!;(p8 zL0mzv3zs|1t+1b30pBj;?6F+1PnDk=8sAUFsW24}ZW6w%`2)C>rY2F9O!y={XM&aQ zF|`iY1I@K)`8KLDn0~VBuG_Kx^`y%Vy;rR(gJz(joN%vCKlZGjxqMWYkECR8ae42f zBY&;5b`KJjQo!i|S&{ku1cGw^3;TzCvFxpiYgVr^1r_#-!HyMwrRI-o3W{|1QeBFt zL#eDT4_wkOMiKLUCU~{^-#`Tfk3=%s&L!yjj@XWEfpjS+wC&j*Nsq~2^Xq5a#c$xF zY5?cY)X7}H1?jKshx8-H+!o2bHv-J_mh1(m%?0TFY^2&8S5tv0sJiLxF&d!`Jo?H^r=7oDy0A3*ntmEnO&vvFk*n6umw%7S?{B_&>gs64x0am z`ARNJdc_{kJ`3_V1bU7cTK2@Y-(TEQ;DBqx%UM9ljjcq)`Nz zLl!qfUdSTSu`F@D3Vf#wxg2}cCakA1CVfpLMy|n^vr2$9>*mpgQw@IzJPTZUki7}F z4BdT*%8z0@hGdyjT<2Vp>QH^=p#>6WO)KbtH^}h&C&;3%6Ns#vd?iKYvImo(&BFa| z{HT!}d(Pz6vBP|Kh~bsvf1&QHzjm5fsDm$jCVt8?7KNJzy=q3S{KS?k}v0h5iUD?`Wq10Kw(_q} z6jEo^B4*)5_}UkKCPxb>VgZcc0UR5{&)nwc&x+cNV#E@Us5e(|bmhR`w&B*r;wqM4 z4K0x5w}+tD277mX3~mKf5%{wB3?yihx~zp3G>@!aZSA_kfj8+1+P0R9*KKobHXY&B zx~Ok3B~qv*yz1}*ve3B3|0Gb0P$=ucv(5v8R;_r+(_|A98SwxqE|6LE&6p_#XDyL{ z0b1D)K+rvazd$#;I)^TiS@1GHFE3_zc=0-8%F>$LK~ukGMcQn0W8;hci8*G#gLw-H zW)fSV?~Vl0I6bGpvq#hb>r3JQ_o*-SuZYvty7_*0ui7S*0!WWX-BAjWrXo|vND|8& zgA@SS7XhdBfNGFn6Pl~zQ)gxTe*8I^ldWgwu{WOkTHikp)_NZR*g@9}2rJP*<+uET z`!Jm5w|nE?+duZCipa93)S^`c+>u0OUCez2p>rPnCvkB@EXRRAZu*qy<1Zh9as=?4 zs?bNxkNG}2E2tfC7!Pw(RJ00?GBD?n_l{LYK`dusv)fVM_^?Yj2WlWhXt zoA$NebsLPTQV11xYX|xaK7GI*HQe5d{^GmFn&Tn%FVZ2FU|Ebxo=I>TY|FB@0myk* ztt8X~UJD+_xw`~J{IYF*mUuzEkaHLH8T>|S31Ic&94g4uty8>SCs}lIYzaxRvI*lp zbK(2h!6J=7S+W3lOY-NY%$s~#n1p&tbxL{9iL#aMiFOT8cZ(DZAER z?aXbntRR7Y#E%c%VX|j?#S~HeHeD>m7=q7yW~*r$*J+w*1s|&Mbf>y&3vkP)cLs>@ z>i<4kpn4bQ72G5$IDV^g@C^M|P9-d*4O8Ay*u0STMfc4$_#fI((Kv+PMM1*GMv;DL zbCmNJu)vhU|4c+n%Z-5D1CY?1WrZ1c-abGsC1xFCcYdq-tqE2?o+gVPoZY8mp}o6w zB)oYX*r?ETJSyhkjYeAziHL0^l(BiD;1Re@h1bT2ZR9E(q*>@yVpdiXozr$t&vSe6 zFqOOU^~DPB#BT?uWAz!5VEIxPhaTx#EQg&?0g(=KMV@Fnru*o@bZTL}dzO^hC(E0= zTh`$Zfl~?Lc_uIru#bz{y;`3}RPd$!>tqJfm+G(1Mb(q9LLO9G_4yw>X_Dg}<0*IU z6q;q}gT4dh9q|0a*ja@Ggcq=99PELOhBc>1TqFQx8HHA?zuP!FICSeEJo9g?Sjx=+DWW_mBJ#GD=$d(9^NFo+e^3R|*_5EsUTUbB3r z{KhBH-0Jdf_t(@?{B^&r53iq0FP(QfVqC%FSMciOYhYlW29DGkM`l*6V-`i>mk9-1BsC0`ZZ1FJb!+(g>-@YoM!T+%N~ekU#!jde zLbTbS8_+e1D#w)_hJ+A%tZ`+)i78z!1gCSTr2a2Q#T2o@Wp|ypn>hINf$WA|pBk3= zph4uiLh~h;WW|@VTnR4&s1WJRp^~i0OJH8fJ{c;pG_plRL`qY!Uo^DEUywY}5xG$; zg*I=it9QhmYqmgYCk8=>#~pLe#XA-z82Xsq5y_~(*VY)o0#lyBhGnaF-7!k;T&p)P zCK2}1li36Cx@B<-Mi(AOE7xXDsfvoTK=417PYs_{r?j6_-LsV|=CPd|KrK5J z@RsHD8LsMX!4)`_{)uPO#^DX6@m8cmANwWDF1pk>@~2=O>Z0DTY$@_g-GBdu6a@3M zq&I)~aF;Q#gNi~ST$_VI2P*7kP)5!1Cd24vM;b+qMqj%ijN9Ece3@0@{F{*U#ryz` zgBn!P$Rb-!!Ca1YSFz-?47$FnlR_G1SY9IubziceCM2*4!(W4N0CS|tPyv}!2{2=t zDAGgYp=h`7-F<#|fzMm6y(%4rMAUfgS6T4m33L7AN{infWe;*7ZDQV=O~%n%Qzq}v zPP|ZezX%1-r*ewZyu0I4$;}bc^b*u-@j8?(JocNghUmvlj*}XR_ios7`=j(V)-DM3fapV-LtJSZS zE!tWIA&^%t7>S#<*oIu~Va|mdVAU~rs-hky&)XS*!UBJYLDmCu_S3cBUf6Ym1@3Y_ z=ncpw65ksEAt&~UvVhg${z=_&NLgjMYF+-bD-gzMJCb1)hx&@D|E}_W_|6dzXX6tp z!kjyT;>O9ifR8K(m{Gm6RN{N(*XpB8Aqj&eCj*~`?c)SCt?u?&Y5G#`Ei%gX7EafH zz5;M;TH9WS@`ymW?57%8vG1w2E`+{Q?*g2Ur^77N(`!U3fVIaJ!WVbG+bW_(u`AzL z#+1T`ag&Z*1(+v%H3wWmqJ-B^qwB9)$r@*1e!`q{Cx0UURv>9=ZW(0Vto8#a^N?1d z>lM-GT*;)_23$o>L$!jm-Ph5vzwQ-3JKLFZrElLJMJA;sOH(Dv@7}ETgcoVP#n#mr zLOnj)Clgwd_k&KHG#=ZX@`_jT#>%xsEHRb-d3m3T-*jGG5Le$I|01FF)@|U6Mu&d! zrGY{(z#=d3(Tw63-8+-bRlbb2f-DL;nGS>R45p}aT2#7;3zI!*pdE-8)sX7Hj*@cmmpL3KLOAiI6D+}~+QgGmS;m1D! zMWjXaci{N3RiJ*hQd~;|h(dFMOi%X#M|=?1Gqky$)ptWY%=ijV3*HRz& zrJuq2OrVPKx0En+be7V3$B^a9S78=>Ve?texyjjpRKxJwhMMVrtQ}XX47k)-&qUz5 z7a5muUB~srq^v=Ix@o-hR30lsI7^;}pv~ukZ_=1SLARc-xa&ja&5o1LI$j5`!y?a4 zyv%x;96%M4UJDDJMF&WERA+}+)_rNs4}9eD6{PS1e$8n)gNuSqnh$%3Sz{uK3>=9- z=LpR9?ZI3)M7o0tz4ZXn-FYDZrR@!UMvOtKBFUOBQF{jVus;kL$YSj(+$GzHaVZ%Z zMAwRGRj}UQeM-x55Fw@tVA!0y9{_`avcOl?3#|iof0uVZ+OFttmi!R4akC9}ME_RK zWip{j)%AgV{XSyl)I&R@Q_!5_>qi|mnH@5SXM=rXa(+&NuoAP_{ZqVAN%#nPCL=yH zT;J&o{B(e^Mcj)!E{m_{)Yr1C;IDnp2HmWGAJj~V>~06LVD*46q>Tt*Q8Le4GI+jU z|8QfNe?+4g4NH_6P%HiN%%Ht6d^@|=rM#K8MPcTGv!>}(Ln)}qcE{P=S*Hg3nzx6I z2OEqH5Ohr^QH+F_c_F|eAJ1Pzuzv_JHYQeO>$8Bd(UZ>px!tF!;Bdw{W@OaD#PMP~ zHW4g7eMDOrt7%VQEhA6Xf2BYB75!y!Agq?K%mZVOfw9d+0?K22!eY`OE%rf+%} zDcKRKlA}_)c}Fixa-I{N_#Z3pM}LqoKkE*;o0!1VxwCMMMg4sjn!wjvwY(ix*`Agd2q6X^@236Uidphj-d*dIm;@(?19l~C*|yV;l0UY>u6UK<8Y!% z7DWf(@I%)lqR&~|E>1Io&sl%CF0#b&Z;I_HTaV=UBiMnN>vPaL*QzHo!dzfA-X&=W`1MJa;VfOA-vwtp;xpK%A$bl zS{TV83Qubntq#X?sd74jESCibMLbC|%B^pN`tvX*Who6E{U2}XNBeC{k=BJ$`F45C z!*d2_efk<3rNf1$0gs|9dfqwpuxMZj3%~C&g<)hN+QU>Tln_uGOV_LX0jUH$zZ>yD zwW~lIMCWro2k{*WP?if{;lx3CiuW!##GOk8?u~@Xv6>Gc|LxQXscY4ZdnBRHtGDx2 z+^O`$Il)-q{OJD9DGi{{R@58(&d9@G@x>=%F!3H7=-vH@4+;R+3Ho(9%sdVAyZNs< z2d`B{30&pE(|m+4)&jpSQ9p5{!(R7lB->n^WjkO`0eXR*ef?3=g!V$i%I`NkA3l5t zGDJc86>xPJtM#t6m)iJ&cLN_H;Acm)F9e5=Vi}IJb^^m*-#AiaYWfdoP)NN6esL<}gsBc0GoLN7`c=_QoV zM0yFm*SoUa=jY!0@9#Mu?(^JxJ{-UJMYGm=-?`?R?;K-}A!`FM0tAo{wM}eKbTrj! z;s358el+GxA+NRvCx~jF)RjX3&Gv;JAdxtt4rKbG%L~(+%x}t806n<8L_kRJ5Xof$ zxD_YX216=!0A>N8r%*H{MbuW>3))cCKmK_9B8+?gT+Ob%haMYIJ+J(O1}@PX_U}|r zY}5zc2MlqA28e}0IA9$$L^sc2C;+I2VTmSQfGAj+_qJ|ZHlO>=UFK*j-4O2FdcYh$ z4GopDfXqRJvfyQY;brXsYJ{N+Y{qigOqlx>Y$p!}8nTYx*gcJ@#EL3VE zO$^8@fKyL7u#8@ex8Q+U^?=7-?lGY2fIlw|KWYI!YV0Gyc^;lD2V{{n}902zPTfyiDwL!1*! z@`cU(>(lxdF!GmG@2@%(e*t~}+n(rOwaedE^_M5!zlZj@|A}({zh1zN7+yK`{uJI* zH50@Cx_bW@nEqD<{Ywn!$G7#b-6W!&|4NL1HAw%7bNyq>h&Il@e7}E~KmU4P{s~z9 zBUFeI-Tz69?c(QE1&sGsqD&9c(~1gBc51t_TzVf7wReAoRm6mRT1e-aIDQ*)Jk~bg zbsHkU>!vwpDpeo_N!ldBTzzYz5KKhOLMw+3M}2>z=rs!uu=yP1EDs*3#Uz zA%4qNz*nvqZK6NhZ~4b{qFqKp@BF+?FEfDbl^^6TEwMR59j=P<#r|@Uf&LV$7*rBg zT+C$ZGszXU(~Na(je+YJJQCK=1Jn=)ii(QTyqf{=XK8Qmd9SE0=(MK|zzG>zoHw8R zrW%y-OH>T-04u0Dx?Z9hmunUEfGD`vH0s3#np86 z{_C#+ZEm1{7U9igif$*umTo%RD`v64K*<1NR|<3+u#FWsmnrwZn$-V@6sr}IOa!Da z$M;aTz8KeLvY(PBw;gAFqERgt)DHQf6e$QOMfye<5tSn4$*z6@nx6kqifmW^yHaFI z)DNY|#cE6yhqahyf>y6)`T{_-&fv_U$XRdTw0(#6JKn(ofarWiaRJNY;IH{+UO~|p z205@(MJKI(#!gk-)6)s++^Q69gpCY6KKyxu`_(OVLDTug&W2j#nP@%iRz!aIYi6E z59}_$=!@%O>a(C%G8fb2FEPo+MGp8Ja!ax=q2&Rcy{|xUm1rwx3n3}xj~iSKE>_W) z;L0VoFl!p99z8{ApneErk`Je z0|VMi-2^Jci66)Sd44cWz;6>_gsVD?n_GM+Z#|4xRnFH(`v(3 zV@NWIu_bb>r$fWAX}m$Uu68pGqR+P;19--*UgF9}c4tYpy3!IF%aG_M^HR}nji8}o zrqaqLPh|M*2Vg>k5pFt{57rw2^x&7jzgF}M$PHSI|K*EA?1gRR*=C%}4DpfxJOXxi zd|5)%u81Ndfz5#|?HstA8rvL=i5yjfvW5DA>Gd>!?}e}K0nN?NViazw4%LXVarxK+ zQJ3~Itg+&aHqT2eP`+blYLjkBp^Z9;y5Yj zIv5_tJ{x4O(;48qnVn!fE-1P5KE4SZ-C?qq@KQ_Rmsn}c;e_J`iz8yf`g^lf?V4$V zZ-bP?YN`~qPuYU|#M)+#)P5iIk}2AH>|~ejM9N|1a4?y}OJSlQX^@4%nwR|U_vfwl z+)67UXycbcj$cU_Bal3b7O+)d0RS36H84=fgkAkyl57c>8xL`Wqpb9UQDLv4$r9rt zNuBoOh+vpK526@kF(=;+;160ZB12s40uc+{>_S zbf(j{wB8vq-N&Sms5YPHttr2Q?F{X`+TmKXtGFcyA-3m)6G$%|{9@6LyVr4$Uj{6I zZ)xROs}eKXawMm+`LaLPF$$ao$c^GZK>+bEO{tGU59obC@!ROzjv7I<&I2vkj$&#Cg#_~M=5Otx5gqrCEO3_X0uQKBw->ewoEDcYL zW)LugQ2V~4md!qQhr(fBLI}%q_wW!u7`H1R=y3s01PEr z4qea|O(5hy#3HW{Z1kggR<4nAr39gIM;Z5cs=k#PtuD({aTd4V>6{Mjb)^M^YL&DM zfB8uThUw8h$JHmgUdyW{KfVz-1l|(lX3;Y}U5PKCMgj8LhT8B;^-#ZW3Mi+p@_Q9? z&7sMFh!&^%+h<&?^szag(BmScv%n2KdsO)Zpgc@gZ3943_W9@Qtp?fQ@wHzm*^Jic zNx1k%EG(&XM!D`V`2%)qS|h&<1}#QW^j9lYmk42Wy~Mo(!{@t?|5T|86>an}yB%EI zZ&nO1QN7XV99teTCdKZ;EQ%KTphKw5e*y%c8eEHo$$Hd0y{BJNSeQ2CsR%@WnTA0d zerqvz{oxc5^15=J5oT zwhObe5$0O%5brVlg$n%dYcxv}gk0wXH08%Jtqkyc)*Zqm;xU%}Z1#Gfc zPbVpmGPT=r8<3a*?_4d(ALocNavspP_OKO+83|DWvpW_CXxDB6{~SP-LV4OFJoYfg zeoMYrH}2GvFvV@NwNa;vZLYCHQk%TtEBlNqLP3T#-}<=BkNz?)Wk+UF86L>b~f@ ztboeuw>8;hkXWhhji8-TNZ;uiW*!A@t=BMfJ*38?$rUQc1 zHl6QbmzJ;BWSx?K`t9sgVpsulhORRax{^Q~flrS%y}f+mftK+TT@49^{>8IaUHB}E2%n`^lv=Q{q|O<@6*3U-htBmB7S zB<`e+&fYf>=fQFuW2r}U+xiP=63AVTIH)K6xbw`$TIF;l*!wp6YCrM1-hNBT)1gvc?qzEdNa@Jp@2p$OLdxu5>@6diJ18DJ`>%ww%{YCse z@tb&_y3*J|d;da8G3SZ*MN{vZNYQ>&0oEZ^4p}|C1E!=;=b~8xndHaw&D@S^H4d8# z9pyu%%=)u}zVY;h${XUEirOM3`l#8vtc~GSl`(|Em!McyEL)nF-@7u|u@2vpd})YW7r|4C|)6GYM|rTGmLl>Ms;7IJRc>X%^me zQ0mI>Htm=42pt4Zyq3^dXS12J4SCf($lFTIX?MNjnggs5U1Y@!W{U1?Qq}ifPI}m$ zDCHDzwCs!wDS#E9ZJ_6%8%`v_>yn$fZx6m0PYu2xs1z1r=a-{CvickRJVO@`wEtV} z{hI8cj}}>kd)U~Uj{|=8N*BsMEriDTilwO#>Dl|lS{;}vBx6DEA-s23-yjAgqt-(B z0G2A;fZ%ep*(GHfx4e1vQqq^9y~W%-a~9<5t{L1$FurUbNx5@&z`b^piNc&kS#jRN z^Lnoi;Tq+`W2~p>yZD2gkb=j`45081#^6TDnBG^rU*JXLDYQ%_gp}0c$igUE3^eJ= zd5_ctw;L@PsylCoFQP(p+Sa4Rg!7tN?n1OZ1C3i9rwy*~4Pj9%<~?CXs8|HFTbaMe zHs$<;*R6zC!bl5hFxqh;)CrKje~ZX&O0+U~fAq?3q_pE;4}nV5bxLJ&JbGPpHjHZ9 z^-S%3J_ts;=atRv3CCNWl3abmt^QMGeQF19jIBNIv$LExNIeeg;a|5gpUYaxRgrHi zMXwtjgHgPFdP%VY6VORFCUIOgv@IBl7?g>f_ zO&jS${6*n}Rn0BON4;66m+>Z=egmD4d~x}d2HmcBgAwPz*<#~s_%z9#Ge}ZpJ_D>Z zvZ&ed18jPFXi@#Nz7sy|o&KP;?p#mB$d`kh9t=Y%QGJ86wBWU5X@M{V6#N`U2lR^p zWhrZ*nZcKJ&xpma`+UDCqo7@}F@sc9W2r$EjQh~xYsST6pydn=JOv>=GH0VDC*s{M zhI~wLxL^F*S8~U)RC7Rw2|iTzIioq&Yk6z%;Pob|#bLHCr2+wj8P0Y6#bQPnS=6nY z@cGndwndakhOVI_ww$_ayO%N{76vSQ%13qQ%uGgj_PfvkOoY#tptqxA)XbSAbCvv= zz&pv}`N!6MTOicHOp==qku(KB0m~1&E+h^9R)F@t80yt*$pURmvKg`#f|hB+-b(RF zz?Y*Bk|Mp|-8f+ENS9pCWM1sv6UDKvviQCUE9_g3fDpxbfh18klufe|8ehyG3#e=v zGPCCFEdK>tv|G)Muw2*bpf9?N<)yCD#)L$ zb!KqFAElrZw@0UlUZ+z>Okk%K}$$@mMPJ#keZ#i_gu zKD9@OMxdJ!LV*8f+7U0iq$;W)(vctFA{DCiW@XxV(OzTmrFb#+yiF$+a zdr1+-No(zp+%?%o%B~@t{SkYSB8N}8pCj;-tsFQRAKLZvn3L918Bm4pC|6`sEvoz5 zFbBTL>e65%b2#Uz3exW~$y<<;4X^lwku#YA?)P=K(x3u3-%=Llrc@Cqp=0Q2-@8~Z zn(sMK1veenkx1j|y)W2Y$=+{d?R$I8nNJ6~#UH~jx26d{9Sya)YazP+Tmx82`EXmwzdKa zvybt2pr46N7UJx#q^ZrChsslySL|0i$)TqT#-=fFJS4M;1U+Z#9cf>)}`3Xzc+*lXLvoLfm>qJoct3eV7nbJJdyOXy)r_%+Nz>{+@TI;jU!nZRWb7;-jsbEf)%Qli^bp z%VO+mX`I6(G>MGx_h$K)wybWC@*OuE%T8Wnt}=LiXDP8z<&WZjdLOC6kng+U7@el> z*GOd}Lnoc!olePk*Eh|zNvNE!>w6u0Q9bolm28#f{7fsmwF&xd0dXx0x(6q(jqT`+ z^-R0iqrT`&amgn?7a&&;^{@~FyS-8KZMKfGd9a|lI1%pFsm2a**zgL|v^jE^IJtA( ztK_vJJtH*?R99e=TzpiDSBmzVv2l!_5g#BgCREC z4cxSpH2mm*j-9Dk2 zIyqde+xW`UC3WhB`Uqe8Hu6?dq=?Ft40JMWV@RN5>df|*j@))wb9(F}7Aiz*5}$T& zyovvjB*Zzm%WxXXoXEA9aPLv0tk0ym zt?Bvh3+yZChO9xpNG~x+&g9eO7qADBm-A<)H6Hcq4RM)u%}t+E@-ib_BuDxx4VX&6 zv_qaA?OTY)+GsKhM$^xU=^Xlw+G^7kj)&zX9-S=?=%VDE;1*-Xw$D-bQa*H9NLCE> zGn%|Nq6j>lTi=UPgXixRQ}Y(hxR0zu)jsgV%WZu^dJ{rvp|hX!MC4>LKiaplT`wU` zAIFvEWL9|9a5~r>NpWoF>-p6zPgwc2b4ndsow#HIHyC~Z2%q_WTugAdC5f~;0b4XI z-uPZ3Od;H1LmOf|Y7?R*>2PwU2~b>5|J-(gg0UdBzWL+&yFBq?MT?q-+uKQfmO!-z z=lz+ZfzjS7=I6U%UGENA#dk-0TIvpy4Sj_JV{@&p5>2h9rl-^VnTTZV)bn{z)`ekp z&|SyYp`jt8baO!E@WK828da526_l(VN@87#K+UI34RoGF{^V4D1jy@wyNW_uUm1J~`Op3lVjjDIRsI;jYZ1WJm93D!3_aHmCIUF=#tUF}*fz98Es z-*QNnxZ6@ zzn}hQ1O}x@Z;sy{oXVFJqcgUE)^_5fql`MpPK=b)t5;Pq&yw?>n^=7iE*Wbr9S zAlh(}rUJo|5!ajMkZ##TG@k1vfW*dhU{ZvpLD@A|_Vo>B1X??$~2&$}eulO^+t{w=9 zlAfYplCW%z7Br!_BmS=V^nr?wikU^rPl_R6_^=hT8oxd*IF&uJYwA2jb+QMjZQ`7~ z4!?1QX0>M9eZv5FRv1XpITc3~4ovTZ0_v8PlrGmq7jEg5VgQ)U@)OWkUmY&tvX9B> zHHy6lNvljIo;=Q;SKYY-7fce!3PBtwsZ6PvOzROm*HpplbmXB<8`8j_0fJ?irnoEc zyC}5TqD@T!*atR6hAHDkl~|03U~VL+m`?=KY{qBwPLoWL^XnWRK;xq|eL2hF3GvE< z@|%V-0H+!Wx5&&U;lF>cE zB}-bqL2x1G+_mGD&nM4nzMU7a;f#M@|Cvzq#G)8WP|eUf_vxSfpI&Xn;NPCKc{>2r}94sYYPw;~=-^(p2j1~SI&Cxv>wrQeNRU*4cZ zsWoQ#RRTsavHK$04sWNqK`!jql4S17kW`uv z$!pHng)gA2?PflxFl;tNH~FfDX=@G*75$_T;;)Dj5Z}gP_jZn>h8F#ePvvs}wTDny z6`f}!nJ-_Wcds)g@?9Ue3An;IXv%%or~zgK@x)wvo<=nAxXyek#F&gD$^8a4{5W?9 zi9J=QE1=mfirgz1q@QWAO8Ua3*dt6GeAMnLLBQ|4AwZd>935oP@!ouIfvPw&oZPA?`v zj?|i)?`)ffMysf=MqBK7?L<7Tc?d$%J+S9pzB_e2&PiaY`d@>=bF;Y9754Sj>|ZgZZv#O4CoHuxuB0T>2bco|Ta8(8PKyM#IVs}@@P%rce| zNz|NUhiPcji2{z3v%rCCd1QyvR>~e@zQ2(c0tH-S(VLrn=c=05*MVELCR>++*-@>}ig3^A z5|GB@j&~ys8!N)GkA`~qwVc1=8CV?6n^Unfdwu+#d*9Wf{-Wb1K^I=Nut0N)KDU&I z8j0NT;vZg4Ru4$l2H~L=kzZ}}j<+*n>q!QRnKQ~Wn@HBfx($dSgW_Fxon(G!Qgr3vt07CrR&HFX6WzGXPQ3 zYXsejh)s)2aG3I)YJDg6R6@~<9k_YnZ zYl(C2JHCmn;-?imc+Z4m1iUtBoyB??G-%|~fgKnJSNbg1z(TG?E}4dJ zOQ1p&PerY;&&?-PuAR7RNddx}p_$K;LnTU`pBY>D=xokG8_G1xY{(c7bshzX{k{w! z0%yK#@j6x>1hWZ@oQ$lVPMq%Qi!iSpCz<3#Qo+EYsMy?WV1BObv5HFGO=fsbuTq_> z{n9`lAVayYQxwv4cTpHXi~Qnmgf*V%K*P&z#)M&bo4{Z_tuXuiIw*#gAQK`-no)sSF9L?9vgHHAWNRN8lJTXO2|x%7_qr&I(c1VpPgH7XzWmPTGzQLAazLHC;y z404*wVPX>CwIdq!&2$+rt+6Ar_~~Hqif9^KK+iV{=OeD@o5wLuV)?eD2Fi3tF9TAm0gNbL;}2QuNNSc0AcfJT1XZb+b`h z+gBA%xw&Xo(T;WS4$i9vQI7g!9}awj(?AuuEWif$H><8LTA0aK3M{3r;}miqw!+M} zo!B1XZQQHuB%y;}gguV2o!@EG9rXq~DDNivR&~$p-hvI9C3B9i_Hi?|9N1vGQv>6? z?|9NeboLcXxE_mNhhJi^QNEG%8e8#Lt(jjM@y))7xeN@JI>>2$Zq8U6{;os1*Dw+| z%{&$eL$L_Fh3B=DW_y_$XsN|zXJrnp*gbU1r_lU3eGaXj(~GS^$N*BEpLO)r%7U~e zucGT18e~+)J5|)M=|d^VAWg@ z>K+;T+50(Xd%({z4O4hqgwhpvx90}j$!qynF4ROK7%rDlT<`b zqt5Wu=xBa|t=+7#kgl^g?9+3m?N2*4wsH*_K^cYjv`^l}Zbo!4!X7fpmc%xUpbdqP zC~uy$hfG)C#DKM|WCApPJL_t9=SHwo1gV37uHb~i_24P(olBWZs|G88)F%#bdc9wq z4!7y6kUKC-z?grzYG_`3&5(DHK4-JZRahqMWgk%gHY;+4Iphyl(vo)pc3tK{N`BKQ z$nckKN^!pJm~6!oo;dk;UdxzAM>bJP$9eapQp#W1mSxp{q=}ris zU#3LzW{pWJuTBkR7rqDJhJdkyJEM!i_(5Nse|)V+c9Yl5?J`D<14f6ctb6uZaDoiD zSR2_{Fm|`N6Or4otw&YAc+2U2iZ{edL z$W+|y6p#zaGWM=_X4}E=dd=EoJ&#$on;vtmw7b7p2n_I8sp?9sw+Gc+*`PK&(YR0R z2hr9`RDT}R8O9Hl&J$Yb~B(<|G0zHL{eE!N)M zKTl9a;g$8WdR~;8DpFO;*0@{;qK&`q)x!Fs1ESg>UCxk0CBIi+JIJK1G&*hs+r}8@ zLD!MqV$0Zkf*&=Z+o@NtVqSWg=LW=F&z<4ac_(qk#lC4E@Ib2Z)v8E??AnA%IiN@@ zlM(AbYX*q_p7|qV(Bg-kKmNEc9AILKXYaf=sJDDvCL*DiXwY=2Vi`N~} z&nV_;O){DZ{1Cyw!EaFJ74NkP0OI;0aiO>jl|FZXaNQm;@Ya@>cf>+6TopgvPFi99 zZMrkLGm)Wh7_T*z^0hc!REt;nw<({cgj>*Btv4araUn0M#WG_IwdP-+$Bv-Q&YtPE zk8DMr{}}Z14z2D2bl2~A2g;@)$QT~$6mgypqKvm^RjRqmsgrm^AFcj9#jUNSRYYx< zS(!2W-m#8^a+8wer8Mk!2J*Jq_f*daJ9?Wv7T89tj2AihNVze z1>xqde@|V!82=uqKQGm6x#Hta?~;I+p1SVrreDRxT~V9fQklnK>zFWXZ|4N)hqlseYo|a^U}f- z($`GH^boT`s@k_8BLSm|&()!%Qo{{pdhkx(U}PLIXsoTvHzU(1XxK8t2mnLFQG>&| z%Oq<1)+N2gS-I6A5tV^VZk-1jMUGU9$;v0_7BBXFmNw_VXU>Nmau%r6@i5dy_vYMx4xc1I$A&qk>#D zMY|HLs$`mcV9<7Ncy-PAi&#HAU_}dLpN%A0=V!_N06EdNOF0#tY3rK4pA}-Ygol+L zFd8nu`JVFCDskry@43u<6IRLW;7^zCoXfQD^%xkIoPPiCQQVm`H?&xp7GD$ss!L~n z@B92|VJ4vNOS%dj?6^as4o|;h#7-4I?l`boX*Q<=`DXdy@yUn`1oRHZ>!j#wtO%%Q zG)4{p!81KQ-PqXJo6PEVJE=6nJICaR>@(uoT-s5|6S%AkdAwcy`r(o5Df3a+qd z6Ez;roN;~hvz%}R)L4zT(ob*pWhmF~yu+EEU~N~uHVM1=1-f(NTbF^tSZx1+eftIj z{cy3{tnIqFvE%3cod`r}`SYG03ln9f2X_CRNW$3o9eV|d!U7Q8utd91r#Fo z?m9b8Jcmn^d4<5<=48UYAJ{tC&2oLrjZ+O`ZlvVyU@f)rU+nYxHtk=$x*Oz)>Akr@ zvH5e`fSdgz;AezBwkF9OOkk+hUM(in9fz2n)EPzh7tXGEBWPcL0ahX(7?01$$mk8( z$jv>@4#RVCa$;HmCxT~kkSo^?ZGLmR!pIFTOk>a2wmxisGM*XpNwG>Zh={at8DlX! z>a2OaIz>g*->2mQGANp61&ZRl-zx*;7q?}6!FHhMAPL{>A$Bu9G5^B{K4{M@^xd(= zMQiI;or<%098z-qUg%#hG2q)+Gxv3(%I?s?_Z!dYXQU#9EpFCSYSCAG5H(O3Nl5{4 zj|}|HfUxTSE;(-@(bC*(&Yh|vFJIai!lMsSA8C%4_wEh(0|LAG`4uh5plc}8BvxZ6 z|1-?=U`dkOvIuqfNXG+$5KHmTlyNESVhs$I3+by7VgV>aqRuv`u zK_^flMtD1cXgb|(vCla!CF%qVJgP8NPRTm?FFOGOb^^Md+$ObtS{|=Re8eP2{7V6k z{UD>$;|k(VBLUYt1^Lo)Z5o`^uh$7k7CKz<@NW~ovr>&&ka?2RKq^4+Pdx9Jo4>{B zSS&V)A(=QyKHbZ13aEqwBBJWZy{yXp>!LLWxB|&t?qLf>n!EwVev?8`gs!U)kOx9W>Xd%yRsk@z{PkMnn4U(d)d9ZjNRQ=mnh5QQ5 zHmm2kq2Vu5!B1`HdXx(SmWBM0olBk6<%-6VJEcoGVfxy>iC%FLC$yX&Hjgj$x%}#u zF2+|Xf(flYU`=cHvI)|KPh26WZ#@rHEu@(u% zji1GHWE5%4iJThI$}M3N5U$WXI}_YwSgEMTSGYj z%i%3uFl?6Y{zmHEh+2BJ65PtxABGS^k)l~heXPd`!9>`u^^()_NAoioEtRzPE}+@n zYNJ#>=&JBX|6=9b4^x_QC2n(H#g?QGZgxK&o#{4@N@8Cu7(*iIofOO}-V9`iFnKB| z#G2%0M=1(PfQ?fsDvXD+HkFQMy@N!+(Bb#>TANXn8y8HdH_NO2New8<+`oU1?n zYmKGs;afU&rcuu~2Q65!ODk)dPMxvQ3H--c#SFiB>B$JPHjqbZb8E<0u#mO`!s%0} z@}1b|MD_vcQN>bejo3f*bkn9ebZXfkqLZN(4zuY@w2RfuW0qtKvCVT4^Tm~!I)ZF1 ztu}^?jd-?g-6~ZXy~Mmp{_igLc?YLa2K`TB{U~mzVdeQf2tzs$7J@`l_P9nbC4+w4 zYqwVVZq|8eaT2k&N0%lpGs;$VGh?emKN8^qimtOghc(p2Y>m_?IO9LQ7WyQ zsCiVcea$dQ)gMq@WrUL)Tb8=o4Oo_>IUk;VYrZF}v6O;baM=X9pCDV+7;CAQn0zTq zg13L@DiSHb9BGRXHF)e0f%oV$U9zxNP|hKM&2 zNHw!aMLqF}z}a{PdfS;V+<|Vyyr)Vb9gvp5T~jC&e44|cvrJ#LfFt5wyaY~ajN6-1 zM6h_fs6`mJ)p`fcU~FL-H@NepnjFk%@GOYap+7}6b!c+v@$$=|FVLQE3y=HFne0|m zuJ&hjCbzU>b*kLnbiFM^%wEAL`A%gkosNn+U8#~^uw>5%!MS^xAoqMrv&Is0*0*gl z@ugn{aymnW)vFTJmU!ViTe@8A`M56#JI0;5pH;yRo-47)*c5Z@{SKU^`wm6t2JLIZ zCj_rmtzV^uE{`i9s0U!SY&mKO<(c=>CZ$du8c=aiW z#}_`C^BjpaYgO>^M^UyU%w2;oiz%CV%wB7Z%S&nU`eQIlF0kut0xc8TpqJ;Fu3#NF zaz%NW*|Zuo8pfq4=A*S5NU*srVpbJ)+pI#qB{A`nGXr1Zm7=~l=8p-jp-VSJ6qAbJ zNm}*JR~aAF$lF^=bekg(c@N_qC0|YJ>IW^5f92#Yy}g*)&DpcaMs?q<&L_8 zUhgKeso>GavWH(YV{12U)cfs&gfk43OzsbG)qG6>bf?U%L7hrUl-(KOEXcG?OdDND zQwB{Y%*bLtM@<4`rI*!kfwv;uoHQ}fvS>J?uOzbYNdTcUVJItx2_$Hy&H}qZ3l*{x z6d)AdEz#Rh>T0?-HOj6kAS^8CEJp9S`-RJNRYNMey-fu z_wZ$}j41769ILm#Aq!(>L|MnLKODY5x_DblX6H`Oq+DlKK;+y?Z{8XRhM9N%h(&x{7JG(WL&(G$!(B(5L&d~LTziuxnp9aJoo3d=8It8 zXB`6QTZ$e!dVft?n-Pj_#^Tw%#uZ{P6E7EByHOQg(cI-+NuFo3LHt9-xxL}k%Ovy3lv}LYm}>TxE!v)(vGfb~fq! z+)&v48lc0?<1(!i{CkT=zL^x?-7>HU z>iW&LpWM`?56EFvOJnclyZssXc)M;!q2dd!cj)tpU0;M8qFQ+D)yd`xBKJZA)w1Iy zx?l|Ws6_4sl{p!tOQ|0jIcPwI1aCgcZk)IvTFra(uV1o>J>glkN#HhfSQBs`z{c|N&W1Hnwy=JyOBC4>3V#2`C zV`RDFm&sDZvABx0&C2KNt?Le0n(=Q}KpADKxp4+|E-eT1FAvJA9u;S7MNMlmNR6RK z?``_sB)2~8lpYNdn|Df+vlXebHOh7k5r8q z@^8e!^=xDX_}yqJQgRAlpr@4;_&&KXVOscm1VO#wgPdk>O2S$9$TZ7A^AK_Yb9`1E zBKHK^K6A`An5EdPn^UX{nVDEQ}ET+MkPIYN2N-i6#JOPy7{1eA67E=v)%V& z9)s8y>)8F&IyT@$=HU2dEc+t)c2)XU_e@P|cSEIfH;Av+&{+Idu%aO8^qGO|cv6!Mlzkb^g;0;1NuyIl$ zJiLpzzqG7hg)R$v9+AFwD+A@?!wC?J-wr7Yj1R%G0LgwfbWa|Zaec)tFY)m+bEzMGCY7a2;l;VSq0^2*c?T`GqRQ$61E?jOa0ac{> zQwuL}-VgZ4!cSL+m`F!<7}9E-K%swI`Pll+)yf&ez#8}AZ%98;WWW{BW)~`~>uZK3 zY5`wy{P4+hr9OKk6IsXPe_QW~PpvB|;S-P1?x!-S^?^Wj<<{dTkl73GkFA@`Si>ex zIx~|cDR#}5C7lJ!tZr7_%j;-xma%>+z0pSCSf+Gt@K~H5JsbH%4Mk6DRW2_9kGfOC zW;L2ZV*(!RfKLaHT?pyAC$Vx8)|hzB-aOWSX@EU0x$0r2g_@e&C8k(m_bxGaSvY4y z{X0yLJGMt)bp)9@(S}+93*Y&|U~6&U zQa`@iK%v2yCXsMs$$#cS4O}*8Ut3j8W^z2C{-NXOb>7Ux6}`sJY^#X;goYA1vNGqf zt@5KhkoLl#D=##X05VJd;NUgIIN4+OqYeMJsGsX&7`x%*6mBMd`d z8TP)!Q*CCq{vH1l#DlLhyO{v|!m?OQ>qg!t=iU)pL1F`TF2Oe6=-QfAOz9bI%$1X9 zaPHeke!LmgD*s5JW^5y@aJ114Bi$P&0JpbDlA%x#hEoy@rh8%;#y%TZEbBkN3cOaO zi-N2$*Df+o6_AGt=#`i)rcnH$MfRBeVKcV0?>UdD-NwScdyt0cDJCvm2XQ~MOB>WY z=MVm)3PxZ^t!FD`V!=M>E>wDvGXzMZZ%W)&45HYMTPghxvWpR!_%hjPDbZGWmM zmkq*m^Y+su`VOiDg{t0{y0nkgN!qH(S-bM14gk{@r4IalZLo84_*SVlVyDrK$Jf?P zLHDl>i#rL}eS4iJwl#iBsuL&3+fMrfw)-)qMg(!IDdU&n4X@6V>)?E3{_rJqKGHMR ztWvvwtbDop5CEY>~p_|d4^`eSK z%oY;DpU>$ULhi@DVEQ1dHd-z#J0@ z-9imwBeiye``QB**z%xxhPj=`j~KW0s)7Y>p*Z0XJ4Xt=k*pW;-J-x^bMcoK5Dad@Pe80+mN9!G3PvYhE_?%y%yHz!{7`nI@2H)GK42rZ7Pjea# zmfQQQV0qdLFPcG%m9~S>z%EixlM1?GcyhDoNViyAA_@G7m=~jx1(e!wq&>JlD{|wK zvd^+`ILc19&&vF`$@s&cQKF=&O-f;3Rhq*I)D#`>jD{4b2h?pag+``=Ro$bQ8%fO! z4}8fWfBTNb(ZUkpr3Ci!Jcg65xcY}rf+RjScIc3%bZq-S4SL`PZ!s6*$#b^Nku+>< z4&1z#Z@6!mLyI*9v!*0|KapE9WM%rQ7pj%`AY%6t7-;C8x&LFl4QTe-n~teI<*u>1(-__N8nn+9XxD9MH%a^9{X$x|!6B7@g)5?wH`u zB8Zv9hF3jCpt4+A1!bAO-{~dc!=uS_;%bA}-(cJmZZWA(`lC4&XyeR$vhzxI(j^vO zPU}{z-I_(YJm*XUG%v%hf=SlpGD)F5jdu4kVb}lNJ^k_-NEWst5y&f z*03{bK_s7H zbAU|`5#4@0D>Y*IKi7(=21A5NIv|p;(0^~!4=07c!973wcmER;{LfKP>`w=vj}L!V zutZ2*nd-3b^h6|})_(uMdWN-!a}e(%9)X)DnRJyDcit|}{TgQy0VGnC zP3~5od=#>NJ9CaJ2Q}fZJWB}?+Z zz^vSkV*6Wj6?W)CqiQWZYwz&(z?6fsU*GSCKNl$c$UaP`#=WmZ$LM4^OwD&(pT&DJ zKytT*v2Ons-Tey0nBhqy;T3R6BG@%(`EBbNF$;UMjVcrWzRz?i-hYr~S|&r!z-`Zz zHcdg{XeJ3Zv?CKG*o5EfpsP5c0r}dlr=)V(0tlpj+d!V-Hne|YsKq47sVIr(Pw<`y z)NKYIn_dV0{(bP|)54x+;;Ia1j*Eln8nC3hy}Cy+OGyLzEO~JcYFylA1O^PngfMPP z1IATwq{Ud7S_pup@tU||mWC7F3I^VLSW}#Mu!KjS6m0EV0dOb4K8xOAb-e$>KZ|(V zm*4G>s`BvrmIlS|$bLd#^68=F`L5>5Lp}mqwNN zm>2+C4Ykx)i0fQ;#l#kM($g38MYi2@vK|Z$4Mp>Z*)GctYbQoWNBh(h@ad#*P@90* zOJEj?cs<}xyDbb*K0yp6(Vigs)(-r>N{xi;)T|DGm%mum={eZhJ#G+jcU&CCT*Lq2Xz-?F!{E^Y)byte8?6^V)ESCL-Ds84}^`oa+} zGK&=^Rc)zVui%Fki!GMF>f%ap8;Ic^%o6)9aM~`XqT}G%#Zr-o#M%=Kn1%pNI`>+! z0_Zm(KpO@y*DxG4$Vq?r(7^U3{Yy>89NRfTz(Eoi?C`KK_)YasdlKR`?iOGlI3mV2 z{EYk45UUy1753RV`3L=guPDeb&Y`k3PXnNa1R3Ge4oq3>7nSz`s1sz@Fripn+$G+$ zD$!R8jEwA;5?A%S+mTnc>2Cv@&Dn+=qAZNrr>T ze+x+9Nk4tEarw5jLrz|+wu+&WY;glGxG7^+iBG$bS@3+xaN_$ww&YfY6kvP0SZzxQ zAKNGn5z+s>zmQfy3}1iwn2CvLOpLk#;7O(jHf5+V;%p#F%c(oWHO9QL8O%3E@bW_* z@yK5-4g7!F`|_wJudZJ!R%=mdMZtnVTNM-;N|`~x)}jIi6v8~oBxAx15(r4CA|j-U zfIk@1VP=9|Pdv^Hhrs%2dZAvV&b$VO3qMkN(dF^BRBolW?TGSVj7E)vX` zC9-zjS37Rr=ynovJKoe0R9(1eX&2BZI`90{)LDD6II~+!sP9H5zM#Q(>L2U4&G%o( zpp4IQp(CzX%XbtTj)P}a%ip%fVu0rSnc@k0>=p{H&h+H@&fRwCyT$OUJSN=`hfR=^ zygat21=^MQ)T-gMt@B*qa`BW(T8zI?acob9_uFEkqeMhc@#%zsS%9KI?GV3%t~!ME zMs=BI1t+w{c^Q>z6!}gcz z)OSD2mAn(HvgupPE2wgdxp_xkCJ_~=o25CLs_HKOpUj=QIP9}D-Qhg|y>y(_>^|fb zdBcNfnBtWUT|iEXsIii^W~t^W>s%yBY5z)mngsWm13%4%$;NtWe(3{FQ9b>{Od!1HfO(&xp3P->%5Jg zjyy1wFi&7T9CQszhUD&9t2vJU{P#nzz~Tm_1ixpCcB0P=sn=142^X&1k!XE!_vbk~ z*Rj-Ci1geI!FzrfzsUSzC*Gp`QXNL4*RwY(-_cA{f)#t=k0V@ku*7F>#=&`QrVs=Ye@rIcazIQ`oT)_UR2vVpEV$#OU zC+{f#)jZd!-eoU{>wsd5AMZUGr!YO$kFoDkHv`Gm4g?UXToRCEcAn5tb+gS2G3$}k z)knb!{-$9S6JRp}L`amv!KkN=E(M*(XT}t?ToEhEU+V(a)~UOUhEr05tn;XlraSi{ z5ojqFdr7Lho2Sr5#YZQCEq({?gMCI?ZC1~++g`qk^&`o^w{=ugtQsES3OyQJ<=ml| zT(OqPUy&Tpx3GFeS2yG36&sL!l;tREjg9a5njh^x3^IRP3T zk@uyH0j7ZZnB6pqoH}cFePsISLU9Sk#;;7@xjcz3k2BG+QN#LAOs2(RpmA8a`xl`B zM{H6W3tzm1m`KX}SYTO>g7wMSio|YfNNGW0+skxM`beUZj81pgN=x(MjGJkGao_S* zZcq1gUgyLO!i#>Lz$>cnV&M;aR;G#?Nwz>a9L6eNFJ&p7QqA_f2BsW%D6Qk?|Fl?6 zA;UhKXFB|^8RXn~LP$L&eR}g(HAC4UjAIE%lZ$&gOD<`-ebKB0xJJFl@E9q-tK+{# zbMr_D-ZeMP&_8BT(fs_IwnndSJikJjjUJakYH5_F^HF|Dnp`<;`iBjW8;MieJbmhe zCp~TbZmB3cOC7CjxcW-nKi#=JCg-JHBqcD1d^tF4ezP~cz~T^wOV8kkGOe8HPDfO} zCPW_QoZ%KkGO+?0Auv~rX-w6Oi1ceGT<{i>5Fy6MmQHO>-5n*oPCh*EuZee?NO`6fEw^JcbjI2$l3xgB^AJeXd{%^{%mEYS zb8ZDu8=%h;d;mw>D9>py%Lz;WF)!>OX!e$&E>)v_7WFeUPR_}Yoaq%+n%ice+9fRc zl{Ui(q`b!Z#rqX$c82yYnrT0aQ!2Pg?;;$obne7qCD6Qr5TW7-zOk!7%3K83v1FOJ zEA=XA&nqCd*lS&Ul^#_0IyAwHs<1d zjLMPEc0+c8X~|<{%c48Q*nJ?&zkzueWIXe4Oi!ocomDllpNU)hUfnE%!DS2n6Y{3y z_v!g-vWf!4+lBe=?N}mRz}V<^7_l_&;$LXBA^$6`5mJYc*~AaObdTAoST* z$gr!H*$t7=gE-$A;8fp?o~4wzlJX#l3OM)?htH>a0_5r~c3%hwVN+pxaeMX1d0!?{-634lcru^}%y1^tbJ9tp9&VHZ`ta|9?qK-1=c9 zCb?-0nqpiIWq%Gli16($z??+)Yjas1SkB*ftsMGjdfrkHYitK8i4UEkxCadPjO|AdX@Tqxg=VN{m)vGF{GrQP{2`)o&T1*uchmmN|+7 ztrWKq=S*W)H6f~YT7+d2OJ4!YUT^nLra!E=3RwDD#JmJ%oMTYqv#Mnt{64`~v1-jB zT&U>g1IWw@!MOal)Ay(yUmlKK+KWuMbI_Q&xW8WHGC`CmSfdo&6(^DzjbAbIeX-C( zsq}a6N2g{6=WScaKT5Le(swlNt*Q`6$6tA^*qa=^H8W=A+1=?Fw9b(7C@gNGzIo;^ zcS|Oczv3B~LH(Cz08pr;g>#U~iY*p{cC*ubaJ(x+wq|2Y&O?P>r-!9fuMTEI z+Er#+l`eN=`{mIqF5XLpZf8zMxESBo`I+GR=sZf5sq6_4a=web zeG9mm<(f93xjiH%IMX}CLiLRr{+znGJSxlY0B71$Lh-L=#m39`WVR6Zffc0tzVZ}H z17SjO{_JHg%yZokJnnm?xo`*LHhKLW;LzaGOqq1h^<^HBq{oP^=+S~p$!krhkbw5v zsuqgd$RrrMI8?`$9^+-PyL+68lREz zFhkT2$iNWmsbl##ssRWRf)=V*U2a$&LIV^_Nk&EnsZF0Fd;|A(MMZl44fY&iLBT`- zR;9A21!lHoH=6HcDN^dXq>9;hHdfH!x5Z-ju%ue9!JY8CXntBWO7lTVG#b zE|GL0@s^XEueWRjgE-M+fE*RY`kc+`;NWt;8T0CkJ&nTIZJPz*!WA~l_^pN~8rQ0W zmoNCM*{Ap+mXggE7*S7HAFv@Ou21L>ZscLDyn4^-RoFlOTGxGTbWN)y1>#U|vz6bchS;t5yJx*zJ?lwkZA$g#YXd6|us1$7NiwkCgka(rzTi?=8FT78G=@ zT|rp4+Rpg-E3g<5E-^|Z%jE*4lFxGDNXIi@!b)-we%MLShTR>bN6@_k* zklwx>YOAyT6$W~-3&@4QvY}vxWLf_bjol(R(Vevvk3aY8uZ022H+Ewxy7z?ySi{ID zwY3)B@EiF8IQQkSIAyic^{{6TzQ{cu01xxyXJ2T#2aq0ISSZYFqNZ|7Z%!r18-aL8 z%Pk*j$R+0bgP>rfBye8U40)f&PaDL3t?&?@Uic_o-^%s^XeS5|N6*T)C++A4XFMJ* zt(y;@bpAHIP}#}4pkZ&fle1!*_T<$$5TSL!0lfr%Q84RkCGc@BfSvH5o*!WH_>+E4 zZxk8uC^a|CE?U*achTo4-jjN{r?}CIUbN8UuXU5oMoKj|Txlpw2R>$bMXZDPB0;&-&_XaQrWX`}{g$HBe8)xIqmZ=? z^BBeM#@ty(g~o7)L+Rh2axL>d?M${$=gouz%&^pnAvvoxEElpPN>76~@FH1|jlm{I zhM|#0-+O{t_>;e!{f3X=qZcA5d5p!`gAANYBWGf_20gV}gY~0zZs9DDPsc(DXX4#_ zX!o86^*%)`wj5HWuB=M48cUqhMS@*wBya$9eH+&QuGP5A)UgF>`}5%zvYnz@TzSu* zF+pcz{T|TWOcbEYp)s0DD!4j`+rqlIytaj#7t8N(aeldikqT_aNGaizi2#8Qc6PNu zJUeSLikiZ)u5I>lVr_#bKI*{=*39Ct?9E9GwjP>YZ@pzi%6*c>k25iyc!r<0RVzr8B#)IFS|l2+ z59Ydr5s!{NLCAyJ%xXX%x~wnj6DgH6R3xN*=wVvjdfJIc_cOY(u-G$!7F`7Ti~u&^ z+O`?TGUb=KbU~}-#j+mtx<~tTL$-!t1nba>1%8d-_v=N9(_8=Ie=bSVaiQ|vG($?| zIxf#_ibU5^cHSf~sa$H`prK+1LVld{>vgpb0Y=W-IVQ_BG)AE_%;LEH2GnrB+tR{Q zooofa>r8N$sBWnzSL%Xz4lpcadxUO@du<}cU1{3gEh4rZZ!>IfAo&9%-Efa?nB~qq zX@k|OF5d9X{g_4!tDsbgS4l0XC5$k)qkFUzenZv09C=uY*0D9qSqRz07B{&pd)DY_ zJc@a(F_5qRHnCQVmPJB4A+0tG>#d6B_wvh|`u^l$R^|u8ndE2a8G46CAstd&CC&(D z4Z5|kPa-7!?mf9$-PwKGv!H1`evfXcHRVB4{RCb=-vhr#cbRisVz7_uND;w8HpF;( z)^)3%40&u!5Au`Deji?0iz(?)Q(GSpoFM2aHvEg2l0Ampj_D91)jawD!U~A5Hnq)t zuq>#;-N*O+OGaLGk768DWXg2d=XE^Z9m!&71icx*Qh)>fy@dq2Y)3kdq{}0-3Ts96 zY$cw7rm6mOryMR26JfHk7ynQozj+f^ZsbsO4+#ZAz=z4m;FC_E6`2FnbhH0qx;97$ z$|$r(-&-zVQr&02i>!5K8F9`x&oigG0%y6dpezGi_?j*0O>E#Eb(zVJtxav)y1xSym{5sR7Avn zc_VF@@(}S_HpA|u!DD66=hP^l?mA;AGUYJr1KhSFEFXiM z`8~QaPEXM2<3d72alzk0>_oP=DgZSCCKTuL0qI{ciMl-`VXVJxXFxYsa*42$HGMHd zPO-3wQgBzrT>WH$Ud(b?t(MTqLr#HEo!N|glW+YnUrD|u*e3kc7fe$ueFbhmrWy)Z zxDsUbXdxUYqP-i%TD+v!+bTj~yq{>>V(~k&-buGttqNHqrt-pF0=jC%7AnTE);AI2 zAd`Ja<0fT=QoG4Gg(1su*!k4o;;`)GM%T~=V2w`lJY%&KI3BT3tqHj@(A9MxVl@_F z%`AwFU!v*`rV(s3PaA7?6y9UVnGIG&2BW8cJvy>!|T-R{xO}DWb8qnP#413~S~rhV9|C z=GJU2vJYAYid)@@^}s8GTHSs^Kodj(*MMqmw5eKFJtFn*#z;W}Ji4}s?>6m*-;vLV zbMDS{H{lqj{0kK$gN>ph`%_#th!;=`Ya@fP3zQKAu2xGh`R0sW$qQ;zAUx?Pgyv0* z-ifNJ#~wbeAR2Nb!O`lf#e(9jA=o)xOr*SBPQmoI_s^~6vl?ED`c`{%g~WG@Wkvl* z>@;;0O#fMF%1Br`!nZAZv$R^g@znV?Xo7OdLj~-{`HtNfLQP?PgATZC=9~EqI#Yq8 z!JhzAG9 zUKUZi99zvQCsvu?sGR}Rff#K-5QjrLurAw+(s3`R{I3(j`dL`MU(8S?g+FMcxzmN< z$`llV$#$5pq&pLm)ka?S|B6w6TU0xJ(E7MPm>N0PQd915J98Mp-^OY?2r68j_~MKqj}X(Q2PgC5$C z@5Xe9EU0EGh)iB`tqJxU$iN5m5G0(If|rRR6?xd!CeQs>11gG}1k9Vz8|NLjFGkjI z048GIxAEU{B(-|<;bT!?X}-43aHP?QHulR;P9XPX3mG$H5_2dWDy?1V7|Av1Mu{J+ z)P1Nj9a{sK-I58g>lGe zhKFXSU|N>q+e=8MZRjZUt1d#vp8MyU24BC7PNv^MZJzVXGX^^o)ldtJU-sX}Z|hbg zk(f7Qs2hravE(phxXDmOFRK4a6mvOhXfw_oz1iNOD8zdhGi0iekV|8SURFW@_EXl6 z6-*mirzaA(H;9i}enO$VpONSWHS4yziuTNMWB3Dz*04_#f%zu4yKHEg|0hqCbE`g}gvyljw@wkd)Y8?CL4 zx9*$IP%|8YH7NNQWv@6>iAhn}KV2>&wUrTMEzQGs^U~=nuK0EG*Y2ZS2Q- zCVV?+!P4GXb9dF5>n({YYl6B$S?cFM!Nxv8N!XhHh%HbSk4WUO`Zr6fe*OJI5u~kPJApf}&SboIg;NTJ^M~Zd{cxYYG8o(nrjN>i9Q0X1toM_Q= zUv=f4QRQbK4Y8N-$d?iO%*Z~q1U_pIy`E=JIZ@@VPoSY4bYbsbI=0$?7V4+7jIV)O zCkaEV3>Td68u@*8h^r_J(Vpl|o>n~)53GrlvB-}esi(8jIr}VUF15G7T&i)C8yV_@ z_O$oOzpUxO>Dg4Gq$5L3A!QA8(;_IdO5J~@ zW^Q4?pDBn841lS(FOdUtl-e&$ULjiF-E{@Gl{{CWIg!v|U ziR@W2 zAGdaB+!rVs7{%9k)3_z^&`q`}eLE>+VX}aK35$*WuOeW!YGFM$1~E!uW+MaV4~2y+ zAIFzI0bfXIGN2WV|Ku)Sw8;(6&iSu|?ji@FQGX`n(?Y5i>ha@(iTQzft1eHMa%V&h`Wn1Oru^eqk0G8`P8m(7W>PO7KdZvxI=NKiQw*!v%8JLCuZUkf~1ZA z{uJI5&*}k#-R}Dz#$g-RL)}Sc%M4mbJr?pm{cg;K@dG0-fatRu{5E82#W7JONdfzd z;FmR!9#iKw05XACh4D4?l6+;~KI{U3*gCRJnKi3PHKQw}lobRiCN*;>p4&m@*(%eg z_id4{w1>*#D?Izh$a(J+MqS(kgzsVlKYnb^-Ct1u2=QNe0=K>zVFOLSn1hVAv1ql4 z6jDf?gU%`6X@~ggjr?e@u&YOiDWBr{A75zX!i+DNB?o6sHy;#KXHG{^%C=^>c+S0l za{{$F%8y?w3#puRrIaG+MWoG^l9V!a{*bl$l(l!UErSKE2Q{xjML4d@C&q`p^rVC6 zcD02nITsw0u3875DIa+)C|x;Qs28-Po$cMO+;|Xlg~R{r{DEz^*sls5K--d6Dms`g zM3M!spULtoUX(gkL+{)M!8*u)p?;M~?HsVtY`b$%@C|6Tuw5R9Q`Z5=#)m~wG*)8Nwl;_&Nl2z;%j%}fBkrY8FH`<;`2&8%{|_FHDvGxt@gqgN@Lv# zv}nxxLA6Px1q{fiF}Xs;t2BSit>a`!?kMc6*zG=WMri5Ta1;a)YY+se98YGZan9D-n9Zzs{!79Y7e++2=g$Gc-scvS^lDJ_D9Z{x_!D)(k~pWiR?i5NqzUTM=Cx1^Nj-!GVjl|85|;WJs!zob z{oaSAAYX#!Li6FTa|?tS>S`df5phS}s=_AhYh6fiHbCCS#s~}${f+jRv4H?`LBaHa z`@lCb`=`PP+rDuxi zerXj1$Uh`U@)503+?9Q!pyE<`rIm_YnrYwFUu9&Tb@q!DcUx!6qw;r8=^?&jygI4HuAOq}l3m$K z_;ZWlw9Y>y$*+VPD?lZ}(l(;$oWQH4w1|iZIqxnrd6%;@64c`)eW)Ji@N6fLtF4`a z4%kHmZ3kTXRlEq!13;>Iql&O{Sl`_y;(qX*TZ;$-2lS_;I&(J#9Gz^YYS< za{f;9np)0hr{P7R1YSLL)|)YW&};-&EI9~@%I%!3@mi0LIpk!b8m~SU5l(NF^yso{ zakKbac00Q)V^I$WGmEnXjl6qPPic+ni9T`?P)#n*hITXD&`d+zV@`sjhhiLYuSkL#R*! zexZ6m;B19g{a$XguF}XJpeA0}`^dDW-=Bh1)YpwhX7?9)z%JhQg=K_SZ#wWPA*lw& zeTRY<-{Ttr4!Oq5V;;Dy9@KP-Pe~}?)d;X0v6x>M4IriB!DOxUhGScqVSJTau?PjP zWos-5TWE%yK$Ja6@N6>*I+^UB?4YaaH~RwF&sa8>fMp@;rnOw%^f%S3WjoFh<}$6u zv8`|3@RgVdJYprsXiGY8+V!E3_s`^l#8MX#5s|V6`d-~Q@dlJky2CY7i&mbfRK!ks zFwTc|?Y+q0m?&;^UjK`i^hMC(We(v%!9#*C@Z_Wi#3SGR%8gFgR97=hZU&jvE8Wnw z^~{wqhjHRdZd1`g__L`_9+^dcFa5lN~Ilur= zB#ITl6qE4Afejy~Xn>l();Bg073BGX<5I-7Mwnfy1R5SGQd74$im#& zGmFm%z(_K5=TjbCFM6E9%%3ygJ_6|(nMfZWAE027^UEe=?WjGvQ0sr~b0Ej-LG5%V ze$yTBY2JIwi!tZ_m!+W(CATcsa#e;K9j!(`Ru=hC{EEY@>f%!7#i#&y8k~>2sk{4; zaOJ@glX4r`Py*2O#+Ph!Q+eZ9y=146^D76#n@&fFlutJ}PC^fstz)_Nx@7|h$|Wg$ zU025V*|^G=;OKehEa4+HRE{cP*A5}tV&SVPo$3FwU3?X($K2qOOsC-D6qTq<`K0QN6R+OF}1tK>kLFS^4o<| zpdQ|~rF*gUO_}mnyQ=vH<5iy)fi%ML=2#hT+*-W|>pf^QRbf+K3ZsYwy!)Q}iSW(g zPzt;n5*2TSFuk9kj`JHR^p`jR14XX#-&^T}xP5yf43tMA@26*1Mk*%ApG0ih|k*w*zcy&EEe&wLfPF<~C*SEfhd+*+bkgSsSKMzh-vq?2{dC(YK z%G}GhU3n7iQMW(nMFhKK)#^h~M{xUFy&->5(7SF~aWAw8y{)c2)3aX;{bE+AB`)7Y z-NJj~iKEM6uN_Kx>2AHH9=Mf(uM5-yCHS^qozFzq8e|vTO&=fm)1-L*rrLjBl z#4YBf^0xiErb^z|^nb+(Hb$z`a3I57P{FNybE&1C$VB3)7Klnr3HpR~meWdtI<#M~KagK>hcxwa)WvGgWk_Kxdinl%b zTfv~x5Qif13FZ@ja8QInog0kTiZ$O06ZyF?(#UBY$-TO1knJ_CRD2};17&+K*&~`I z(2;8UQl8-VVUx*$a8RmaH-?yPoPwnHkRo6`o{ZD@;#p_}`eA1pHYoGEZ z%Q&Q5&Yjheb=thZk#c!cDfk&K>;twVI)8H59r~nNhJ1ywKR4A$ou{JpZ^DwgjpN_ literal 0 HcmV?d00001 diff --git a/windows/deployment/windows-autopilot/images/wg06.png b/windows/deployment/windows-autopilot/images/wg06.png new file mode 100644 index 0000000000000000000000000000000000000000..68cd29c24ddaff4f0ce7833284021651f35ff321 GIT binary patch literal 124860 zcmeFZdpy+nA3v&XvE{aH8&PPt4dqsZT*hSEl3dIEI!QywCD#ly+JtQ-m0NB@2{9NE z<2I&9a+hJ;Ni`V8eJ&Vg&ihl__tfwEJ^!Bbc$~-f*vn(4Vm|Np>+*a(pU;=u7G{Pb zJEeB=@$rcmo&DniAD>V)AD>{)58r`z#{8pw!2h-dUNHQfue57F4ZQf?!@$&lkMCK6 z(55Rtc)i2_tbHIK-)}R}zuRuQ@$cv3`173)MZasP|>k4G+e@ zg#88H=bW&*7qVBQqQKoG8#TH%8C8Yg33=x=qbaWiv+iO0I%u&zY2yn2q{0Q#m%oFO zOrl+V-FGmA6Ot|3zV|=b#+>+^C;Wwh7E^tmmbIGmeGFD#;ciTYORW*&W3TZ)N%91f z@hQU!4+M+0-5LIcm{(Cr+9W#1Z29Wt^Oui^3{yD>BV(N+X0fI>+9%OjKt#;^a@(zEg7eQj zwYr~7#issqC56-fd?(M!C^f{85B*N>&Cdr>rBcG2&x(;zuXH<2FxBV) z(1<)Ci%km|Oj*uH47v6_XN;$*=bNicTwNR7VVR%eYd@XSVOyntH6Yb9%d)_9??_mJ zbg136CX}qpm#f68e>%uLPhL-Rw|IuD&FWlvnV#y zk*V#P{deNq;!0*2O?vU6rh7s#PUZGgJbqa2KCM5bU5r2osD=xFQi`xPVkNl z#G&u*-K=0BMD*&vL@&(apWDoeQiBD}-gXlkUKkn6GS1Isvi9p-sgQ}eQhSGRXKX%> z=0oysZ|coCw>O7Y;{rb5@Y0PHPJaAQNov8c{g#;Om)P$9T(EccdI=))P1BCDa$uV4 z4kFtX`hBjySe6b|-zrlkXJBlnqwYdcV2Uf8Hb_%lP?O6tbszpKJ2>k#t!CqY97@-t z`{3LPugo%5`tO|Ue5ezW9gi!$@Vu5XOj`=#{JoySZgIH_E349-zh*HNR~K)(_;ibL zlnMWz4{M!zeB-11z(ylMbIfh#m}UEJb#*zB;j+}-?ZwP!JjN}{G_q<{CMrf$RzKu- zYOyJGjK_BQpt~3}JNPNNaoVn?2~leBefJlhVk?^ZwwAs`Iy3W2mT4*^I)s1NE|*vH z00dx>zEAt`oG<(ebR9R^M3?`hDcjbP2>6IT9wqJI?U>~ zQ6WP?S@@W^y(Qd*0q#_OxUe+5rrkQ-y(=@M&t+1|94DQm&AlN)&X~nj{g2FfZII?G zXkDdu71c75A3r>)Nb`9lwW#ks@8_#=h0aMml@9X8*~1zom9+la57^l75l9mlfp{P{l^c(dhVRp4U)8mjxQ0u|AER*4fG(zG@**I z_TM+te_Wx0LTT!)adZC^gz<|L&s!2}u156i@HC2#QnSx0DAW$=LD5X@VWMsIB+TnI zB3GAKa=SM2`j=vg>iUF*tnPX3OIYN~Y7@cXh7H^?iqb5m9{-==Nfd1>-s&`E?+qC(^la`(Ymw;*{*fA2 zcjqvo;L3{Y2)bmB-s*rDxzux>46Z=4MDLR2HMZ`Z^kczvgAqJ0`UJk5^;$3~*1PuZ zM~04q<+1zfZYzH|*Vc@DI`EfpV_yG@rY|j|FYuqD-KVV(IQ#tY9@8u?mv-@->Ap(K z=A)no)KF4lgRx%jQ+H^IEwcKXq48NqOWdlUY@Mgf?>9>ogsF^OSzBsqF<*#yQxw?5 z0D;d;mOf)LzYE}m6lXax{!3QnP`Fh zejggBF_vAHKOi{IdTFB$eaTLN_<0?r-5JLow@V^>M{02`aNL(tHuj~I5k=xNb$mc) zI3*Yy82`Amgt)+pI%EFuLD$Fy9pm;Mn5L0@HVp&9#2f9pH7_V48|gG%V#B@&bu{Px zP+hl;KDw{iup8O0G>fuXTKivN_$37Xg||@6`}Y+7Up$4K6JT5_oF~c~Ne$*L3V!Z6 zQrGiJPOHB9hTr>?9lb9Uefn`_l1YanXm&}z8TlyrB%XU9 z;6>y7`8j(8Ts(0u(VaOalg2HNe>3uO^USb%aNNRpLhSSJA747>$UJgY0J#&PBYw!} z!an1XCl8+d>9B!0@F^Fb{AoK}Wb3M~V7bO6EpCc~sTTTmCF;2~zR}$xe<|ASr_XQk zy)pXoCmWCL_~*TkzkT_5lMlcD=e>XjRkPLrGydG*Zvsuy&@XMHFQ4Ls+_uke-N=0M z<Gac71>TBF2WqkrBzAphkFg<5|5=e>K0|9-rGPw(H@`!_ZIEiC_* z<$t>d-@iTgUr6vTpyK-%j{b|5|D84doz(svB>DdT2??I}MDjKU*++zg_=XRlw;f?8 zo-!8^+Ng<}n#jPS3e`(%)s=2+o2etgev$r(+ITZ$qa|DVKK73q9*4NSNh(Kd>#cy` zlcC7kpIvl5HWG(mngN9k@p(-lGPQqd-H)8^TKU>dUhjha1p>3X#y-;LUD z*am5C0QnJ3@K5KBm97s>e=Ilnle9)j|d#}a7vSD7(MTS*hjGfC&>_` z30Y`Isg(&_Y0c?aj129$EisYlizh5MHmMYXx zIdE;#cN?Eq(${=akVDlamH;~MMpGDkglT7+k$_NP22u9$gQhd zXB5tNQu%8Z>V}zNcA)ddB%)?S=DJ$3XGXGLeKPhB#MS%UR<@W)!dPBezM}y01{aD) z4+{YbU#D1GL@>dvR~ffc(YF2b_tCi=IV9O`J1T;nrCEimtdhI+s)naI{6(nVQZeNA@HgC&KT?ibm8dq;1CEu zEx(uV3F8>~5}en%B7SSG%P`vTd%l^|U(ih z3UxX=5_1{V7r=&bo$ScFqttv@_v2&fn2s^kHH=-tP%qS|3yoor;J{p5V{ec`rS25B*dmusaWyMk#8wa+I$#x<$&-SGVn zT?}!i1{;4OQX9%X43^2+a3(aDA_Bf`yg3W2Q5KgmVL9t5ZT zQV~x~;}+HHNbePHGszBjY?0j@v&NOCllO-Ngoum}A1uc0RtMZ$9PA zu>>U}_^M*)yFTNlbf@6(3v({@%H^E!TS$aJT4(lG>@#Kc_5ef0KGinNfpmc)d3YU#6 zrA96dCF3uYn`MNC+imBwQ2si(eh|p|vAZCEOiYN?SYMx!6D%++nFZD3R04fGMZ+q^i6nh?Gk#7VT^jA3@FD_fSkKb(8?!<3$N(~DVJZmIe zTqG%cd{)L^6Wlk=uO8FedVx2N94&2^*?Rw`qW6?druzNcSIz56gY7#!V?-_-m5yV)=}c%0Ga#(pB+0S{#GedT); zWg}+S8M1jS_%$=TiGT#9uwP(yHDx)W0?1)G;Wnp$_AS?K!k1|;6h0M20pyiC25En` z=9r9QQQSPnePt>mh3|#eH=)vBQ~*mUxzd6h(2@)YK-ELBu$1X7kCyNd-;D!b$H9yZ zlrrpcmPVeewicS#Tc9(JQZd1dFjvz>C^kJ;ea%5^ zN_3L6zKYGS4sfK0mYSDvwQxFx^b=4~zW*9AoFq(*Z=BpnL(~|^JME`DA2r4|U}cK? zKK#rXF;_s5CXF1j+mkr6zAd*ja7d8f?#{s;8$YIkj^+G6!e#{YM%qEg*}`eW zP9Z+Nn_mk}Ir30r#n5e4NbNG{kdY>`TN0-mCKpogO+J-hpp`tr85Gj>8~lB;Ps85T zKp6@gNziOOzPh{)anMJ&589&np(_7z{$U{ATz2S!?P$XZB|g3%zCj+?2v8hpEf^{m zeGK0&Gavarld(5XCek--x=#Q3z;w06WlMEzhj(nBw>$EaSnrfkw-3uuw6~$q!s~c}pbQnqPP5+fB%~09Ltk^CfLf%jX zi?zl$*HJevBzBRW&4o{oMj%jzHBe116-u|=s;hDo&E7@ndpv27CRR$|fpW66da&z6 z1jSmun>fEYw^%dV6{}J={}R9keO9rzK$ib9XsN7exZZE0MfeEMf@|=7FvW124_&n^ zhT=l?%H7y<(n}#JfX)Lq^YMfh*s&KL0UJr?}F`#qy7#`wzx=m_*gC zTcMS&NQ)@OHp?mDEX>eflD0uV2uZO3NF54TyF&}~!!1|fax)gge+^edOrU?SCfKxM zd;hdloln{tYPzYnIrEO@EPH&nc%K6LP8(H6VU>^}HW9p8lR6p@i7M-7zUrk8NyLt4 zUm!^(wTj|SnKfMP*&(qAZc&;$+Y%e25yqL$mQ6!TwqjpDCFAK!&4@cf-cn1P32DaG zOL^(Q1*VujGh)MTz=FkOfkNr*N7~&)tZYjSks5fAo1>CFvhWuReue0up^!+tH{-S1 zWF{o!b)TJM5;6)6Y@qDAuh28f7e%ET)7>w(ScO<12up7n^zeCr*t%*$Cc*fLzMlKb zBxd6_eeS~bEVA{99S9q{p1LJF5zYq@K@U|_LN<)|_K<4+^!Za@p8B|CZ@aaq-x3?{ zxEc}IZDiO{yTO%D$%n7c)?y}ehZH;LXNB41!mTK^xrOk?hw7y+Yi}Mfu4^Qr)%J(K zjEA4NGAuYS0v~mRhki^Ocmh9F$S&1#I5Y+nT1c&(4L;Pqpv3B zcO3&`#NCH#(^Fa#82K^hQ^b|w45maXf4;y(~w(Mzn2zFsqVgR+mJ4wX*m#~SH@NVbWeMZgtAAlN7g=Qo0z;`euXh`##`1TrfnrvtCpauj zaj-vlJG>tWmra$)>6=NjjppwRcOUv2++@05Zbu{?Wx`yn)*_!WR~@<5VLy33eU|{T z6wH6k2)~fQK5fF2aKBQ}X8#F5Qz_hb2Zp0tk2-)4unXBhg9>XwpvPCIvmSRz)p(5o&^CG z0L*#0({h=ir>^IW=VeeWbOn)WVlbi-%)chZJOe3*MLb&_TY zFcH?K_A?iXtj$%>AY*NLJ1B3J+3;l$wXud*P4*_$OqEiy&2bLD2q0Mx{W0;R6Wqpj zMKW)$a*rZHY{Gs6#MwHaez50i@N_l(;?{1PgJ#g>h6^6QzV-5;yK~mU;}|S@Ihh_8 zzLC(Mj6S$VJwJUb)*F2BR+ryy@rNB%u*7EyAY;r(N@LEcIC`Ap z!=3Ym>i7mly+34UW24ldG1*x?Y$z7Sak21-?$IP_OQhI)I)qfunT#RQ9-6pKOw9FV6#h;(CdXVI-R%e+L`Z z52%Q=6r29xiQ*Eh(atf@%K=!ed;2aCYT=}DdRf;#?!=<>L)d!BnM}-Z{RkqWhC}R6 zvmJk1gQ@KG33%EGIJgl^n3JFfZN-*MOl{YX1U+Q`QKVVz#09^4W{90dE^pNB{fBO5 z2>MU@^-;f-<_Xz|UVv42ws8IDt1+@e*WV0}B(ygCY@)Xqb2!i!6Vw_<6BuIxC^%E^ z+62a383`y61@_n?2b#wb)0GNFr@e1ELis;X+sNl9L-Yi<-wztSn~>&u!`06UKQTA*2Uj1!8ReA;{Q2 zrhUCx1MD=PGaj;k(ko`5!9)JK5R%=q{+9@th!^We*0iXAQ7E*PiBjWa+bzfE=ZdiX z{FRDv72*2#O<1PWFA7uLRbN196}hs-FkAyu4$|-?G%cgywUgME-rk~FlyxGGtEsRG zin-m=J4+gCEcnCY7E$f>aynuguVLxcN6@jIr!nu2Nd2=7s#e$+1 zq=Fiovl8r-CdN6{F0X&Az`q`PwgeBC<(ZEp&``<51m6IER{x3cUy`=!-ra3BFX&J1 zbS$f0C7&P}q|ve6xOCZh2Ugal4oO=-Fi!f>^_LSJ@6tC5I>9*mqM%ADjd(2FmR0bE z`vlxYFr8nyq1P9;A7BmI;gnk1cnbvmvENMmL{3jk6xn=RJB+z$>}slRR;u^x6@8r@ z!=KeCmZVCg{#lmeN|R|f1*s3JNEzJ*w0AL3xsxo zhkfbDT%5*-iBOo%Sa52Uq_(<}_iIpD?k^DfmMiv2J{;LBBcpWSJW$3rKlWI{0Z-(g z=n?^NdbnwAS%LX5{mss~xjmrZ*ME3ac0g<^!eR;{6vB&@IOXe6QC_g2!Nn3?1&+x~ z$oM5dS_T)>`~X4siR3jcv_(X!E4^v;sJe|fDXL3dDRZwZSKSqt{dYmt>=i)Q&7YVm zhPa;5ClcAC0UrUSnMs;i4w6WQken-;2m)T6jDwhee2Q2b9nk)?yS04}D)!oB?>aIE zrdDM3>&VeD|By;^AC2-6q2G~N0Yf*-s?BdnXukyfc`DWyqEsfI+020|!5xx77$sQQ zvvf4WTZe;phE$eIoUgm1E6?$LxbV1K4*%Vdyyo8H)Of;?()@w9fTIz^YO)a_PlHpa zWXJef)^Dy^sm#58TRf1{7SKG}@PCEAHDHN0&7i8rW=?(1X5K3hAP+3ro<% zytL07@ZH4yBHny_sBfH|#gr&>ST;u7t~6SHLA2oIAkry8!uP2@JZu`Dt?35PP=1}_ zK*ypA8#GAT=00*pTReQaHo^A-TN{qiV1CaB*2bW7qSTyOkUDn&JF;q zcF|H$^BS~9f9=~62u#U`w$Lqqi~J38F>5Ht-AZ;$!*@P(7>FErYqRyBAi%0~XWr%K z3xtC5G#hA-%o=@F?+G}sdL~QP)j&qLtq%tlm|PcYa^>J~by+(PQk>u4h-#bS2sEiR zKJ)fRW8L^Vi0W~vJq`vMS7f9mdcCSFC%SQYWGGljcI;wLQdzYMP;|}{BsM&!*NI@l z&dbl;tx`+tj$Grmx_PCd$;JBQk&i=K$i+4{iz&x&X?9TPfL!>y);v?Qc|TpRsiyAw zdkdw;Lk6kDUZFTnn-0g!%pB(w;vWrA8u9Gce5H-|$2)7r&q2x@E%xlt3dw%B@NBdt zQcbCtX0?^b29I^D*z@Fx@DLk2i&QLVvL--ZsOtkDjyHf!)bX>%M~Y$S$I{- z_jaZ3^NU7`;Pf{dZ}vkak(T0I>$XhJ5Z2Z%zS;rj(*Lpt7;u4LENGIp+lHbd+}7cE z)L#$@al^O;`c$n`0>%z&C{g1TL$p`AlB3KJShO+!@J`Vj|jDUL01qGM274Qbgzw52_}j= zy6IPsbBC56ER>GU$7Q!+!|d!+cd3`2W%uXN6Mjr#D*Eh88Va$}vQ#ryb$na2TbA3O zASN=Au6v}dxC3x~PdrBR=#@PiQR!O}rc6Vwtzq`Sib2|JWOeZK#bt@;WD#70lc$Z4 z`N82kq_K$WEY)g8=DB!mm^ENzd+NSsqApfK)I2$1dwZo<(}}A)5FnFX4QwNqb02v+ z*Ie^(-bXq9ZoDPiIMjAFCR|2HXtsAg$7B#w2dX`sXk8+4bhZ^V>OyXGm)|1V$<78J zWSAEs9qD`B&#fGOm3iAM9ZovEH%WVX7z0ySC2{s=W3SZ6nTPaRvs&*hJTJ0||8Pra z;j-)|s7@2>rknhu#d8w+8>tzhB8nMSuzN|&5~7rzN~7;6k^tK){_#y9gp?X(nXIUxeg z-r=mKzqP$FUEtO)$^FX}e^2fs5dTYAK+ z%~}~JCQU1yUpLE!Y4Mt~ zB>ZqHS|7}5;(m9ce<`4gVY!GxjGDqK*>(9cUx}0g-ROku>%WunvHV0_gGmRNx;Tw@ z-I~f%1_R&o(~h+f>%6Sp5JIKmj73GdWRf=Rfg_oi)UH1z()}yDbmNa0`*>%;szc?fp=@hz zt_DZTlbCAoJ>Q#ekWl5r^TEp;IsBW%b$V570p|#T#d2#*zsTD?{Unddb)CyM>ntY^ zR*jQu#R>deI@Zv(_5cwf=j8@ej zdjs0MRv3$}7E>L##hpSM8M7h}Y_?eIjVh#fy66QT#kxC{V-X0U(f}qryoEe@i=UVg zMwO;Rj)&W#w`Gl+|2&Xbb~+vH4S0u( z7Wpnf&c2NQjjUYP_rQBEvc;_0-JWIWyI#tYj>|Sx=9@z|Y6<_(oh&Za`F~9hnB`47__j|fSDU<;@HzJD zm~&xPOBQ++y@xE&nO%J-GnWdnRzj#}fEXrsw!vx`d6c_x!MKf|v_&!>9{@VQ^nT8k zkHr+=!Hq)CmmZQ2pP@)Z9$SbfjGKvB+Viwum}A2oQD#(q!q_fXQ{4WLHY&)KevI!E z5q5UEFFB9rMJsHq)gaD(Aiqf6II6G;>QduPJt%(?A>wTxPsx6WP*zraY}y(#iQ4KU zI0paHSXxwY_Oo1W4kCmw;kle+!a~Ub9@ZKM1j)aR`&Fuc!5;Sp(R@o|>*WAO;};ky zfDM1fU{icPI)zs51+*IDsI>-|Ze;6Z5`8D~=-%#jlz_=S=P3Yl-_i(c=OPI~>p0q^ zF;cYxUe)@Gt0dpa_-{xcsl05_6fo;hT@8q(M9zJ1LuWdwe^r{HW|(o0=4vm)^#&8870W^`$}(k0J1UjmQil2T<+^^j0V1 zUS2sK?rIw852WjYXr8yYybfN^4XSKTjTIekUe zxW=2q);!F#RtDFH10df5=CYC9&=ElX>cGwv+PZkR96BNu*n5bO?_ob1ooXAy4mvkjA6=cX^EJcW;iTzTLcKn1 zpT;FqOc7oeoLv++knmDk4_*N2i*S0zUZ=<5H=7dz>hGS3^?w-Dhc}aih<2K1G78Xq zprsd?e`F;)zmC;_wd(hiecGI_ao(2!=q-af2V5CLsW;2=q4JbxE7JCx_iM1tAF7)_ zcj!CaVebp=F}Is6em7Pz7)(^<{)(lQvFv+8c1EfBRRw_o;3w^1Q>KPz%Q25UL*>*7 zCo4BdO-H#?rF7rVUf4?QJ->pDs)#~BpQ=D&%ri3grE#+Om~9SJb&LI&cuow z0?Pe$H_K^!(RrR^()#$efHrE2*wzsfq_a{=}nYD8VVGVMB*Q<+~3I}ZODl$jpZ>& z{0?$fN;~Jc`(&Rqq@mdL$bvcrsnSYU&YXzscl0Ac5{sC30HputwWtJlItM!)C>H@r zhAYZFZy}5^RCYj~FfNNXNb7%*W3sj&D)%KSC_T82z@UoRCO!yh&n=G5F1MzIdn zXH3S&+(Pp4F~70>c`@FazSq8}0?``zA=56l%a$K*Pfz?P&iJ_9dH^p8TP*^2GATHx ztnK^_{;MLW(kleccH&38c=<_0f=PmOhXg>p?O@{TKw65{ApQV8ITllVMgTbr9aTu8#}QS96b-<|xZ10i(ZL!31LJ>{|@-Ru$xvuQDa3IxUy+j5DE zH0@+aHg`2Os{#@(>~iWXn6PoOvgy9|rCHPRb4#5?ah?kRx&kjk5h)rXuUM;xzvE;4 z`n56R=@?Y(F)nrspHb4=3_nuh!sEV;C^KOp)HN3>%g2qBzTUD=)Qq4?=zJrdSwtK$ zNP9$96>4|zo;+yWdobCHCw_X~1*)1##`DJ}!E_P=EIs3i(TrqZ)Jel$D~xG5pySl= z?q!hSB9U;3%CVK##)LE%TCnu1UK%@WLiW%)1zQdmQN7j-S(+dN8?bu;Txl+bSm;5? zC6=E$JXUPQN|sl81B`b^RPrgdQEJ(EJ=ODIbXzZTm{jwz2faRj?$N+oK?hXTli3RM zXnx|S=_Dh-hda*`o&3&vdLVEOg!(kXt7UyV#2Ablq?!9_s|jComktO}L>#b2D3*!X zPOiUseX2Jqne)=X^GYQTT%n@lHEN5fhjqi=_KjY%d42pOWLmi%mWJNF!+WC*kVY9; z%fe9Gk`3T-iUnPPD-v6b5=4sPbU0JurXAH1_RIL(33eLwy5!C?;U0koKC&g+z;V zfgoLlRpyxdEo8}_((+?|26d4G6(NA!6E@!;)SCxLZP0QLr|xmHkh@cMc?)V#-d>E@ zIa`xwLDG9R-o7N09gQ_M=SaX$a39?M0|^%ZtS-PF1ZCm?+XBhN;H#x3dZhOO z+oxR!N5M6GLc+F1pkWlLRxVA$uTErIK1_Tw3z$4G!acy+*OVA$%21AffP5kxWep-$ zoucG;{#bk{O9G@cM^rzWJISP_|J08Vaie8PXxV-FqZHw72OSHI~a+ zXP+*HrJk!nFI&=<&uN5}R_lQ~{6rF7>5wfZMAo(hC~NDwZEw8jJr9_+Wa(Xa;<63O zEKf(}{*dN?E%xW5&_##Kpf$(JtysjvN>>tQ=Xe;s>{U%9Z?7;3%W?qo`gEl4eDPyd*HUYf9rk>RX||Tc1DEz0=$4XV!x{v)?10&fYR2 z5f*Z~*c6pbbU!AoB3pKs>gi>?uIwJlb3^7?r+N8qv8G?Aoks2g;yEf)25$vAf)c9u zl3#HrDT@atc4IN8QZR&EZrma4aN43n<(qHzm-Cj$zX~gP{u2`T$09RCqld9_O{3DR-#I9!= zM35rB(%k|mC$|TjXY0SeoMBCxT^kKCyrnU3i+)kHo^H`U9aZRUF~#$d!q)-!WC-F^ zMN_tKkOfMBstLP{vLpXA`8biSw{f-U10DRdw{QBv>`y9bj3sr|Tl|#}?hE2v$QX$H zX%P&bS)llS8r5tRGkKA3p4YebJ{2NRP-PbYd_Jx;1HW5W_CDf>yi<@R zV95PtvJ!;=q&4cU9vvDOl@{-NI;Zhw9L32JvvCoe2h``;Ma9aOIftDm9CLvtW=>FL zMyH3)6?7Et{i61tc>EPay3TyA^Y_&12=WSfJ znCgzaezw-W#xy2#Kjovc6Adp5e!3K(T^S$Sw#LK{Hm1M6961=2kSBA!{H`huG>YZ< z19J!W5kB0J8bkT6E7FXT04ypQxB&|PytXz7Z&d#Yg;h{>8`c}-d;bmq`n0B!_c-L@ z{?r0<`tG{TVjugO>^N}f%L1M|;dmXNoN;^yBU=lmL^#Tlij(CIkR zUJ1(ae3Zr1y+ltOVcRBvyaa-IrqILHk zquSY8c`KMt1^byqK0Dd#-AD7uk6Hke_}cZv0eV&iG=d54JW#5s483zAI*%w5v7(7T ziU@zyxcKo-gKW}{@YD7@KXM4~3{#nHOD|?OfhrI50$5Fe^13x=b|M4sT^IVgegwcV z;N*(RhASVNp5pYbDp+$6mw<7%TT3HKjah`WkPH7aw9|QyM_6k*uqnCP8*g@xFVp29 zBwgIvIvu({1NePCsyxZ31{CTooPfo;Ea#Z(Z|pW*nVmwzwES>Im4zW&i3s|U`f=T@ zzjYgL)}sNb2Al|>&?TagXSEdjv5Dc#%d?q|;M)h!k0spV?-a`JhM#!qXO{3iU-8g4 zGhOW_#MHIKQXz+r9l5SdWOVTMa?^8D3XhJCup`GEJ=L@Hbvx^Z z@eSkY>a)|6;1Z0x%dMK^En9CTsytusJ=!@43^n*Oxn84a~Xuv$figpQ_lipv*EDxPNc)!?eNBNcK5b>0#sc>W*UXhvZq{ zA3S<{P+tD~+K(w5a#Jd#`ldn7D=eZgB_apXQUO=kcyk<#D$T9Eki%8!O2N`?##&%I zfZ`zT3$T%gKLgi(;4+4YC3bTAV&Do`S};vGKbsXgw|C)cFJkM2%OiKS76TtAb%UUqG~5y!F;Ydd~)`*}RCNN?4U!t7qH#J}Sr`Ny2TVn}+SxAzsqMvD&Ne=;AI}$Z;UI%F)f|VW2-U!LrAwqavoT);zzb z(c?M~Fo@0f0heOC;7v;Zk<#}Gw4syJgD}$ar`I|(ubDGE(5U76vipxK!x9337Ju1} zTvDQ_#msi{vXDDW$?1sJQaQJ%kUA%k=&$)#h}qiKcx_Z~ZpsMb-e~NTxt|1(<*7Zc z2HUxA18%)z$s=no8uYfebSIoR2)>@|_|t9`z0@76ZT3TkO2w@s5IqMAsTl?u0&r6X zWduMbdJtB#-GtBJ_6|M!H-L(ngv8&s@p<3*nt{)8fm}daKRz3UyiLV4BPL!G6OLQjd8>9hU{{BLq)iVrJU07HdMIS1=SP29q*w`A8t`kZKQ7H6I5AuE8i1V2Nq4m* zu`J&nKNx=Ko($dz%xXVhv6zCqn10Hkz^0%xkr8W{0{EIjD>r$it9D@a9=V$?Db6VI zHzBSC2sNnkg6#BQ|M>az|MI9R@Ao!ZzbpeTSkNESK5Re5M9hHD^SwYr)S3b1df*eAz)X)Z zguQUAxOY~dUjA*62GqC1N;BQ845wq~9x&N(=!hkQKa^HjXGRI`^oF^}*18ht^@U>jX04o>X z!#N63YLk67s`!Y5N>AHc1O1Fct%}CoJmQ+nj0s8u1P=*LuE=|t`7@P7haUzC!auPF zdREyyIi(q~ztt3Wcm0suAA`@HR6E(y-9Uqf!18gC6U>>-TLW;2M$jWR0Ny>N#7uuPVtFh+S>kJ&6O`cEz0x=0RGB~7dPdH0ZO1}1wBv+ zmV7}s-e>4%zqKaTd`%$V4GqU{Xbn7MG+_k33V<{OJ946;FCx>|a+Z*&3N}jE@)Pi* zW5zYvve(XlyoO9Yz813^(Frm9olm*XRsf{1up`SC&(Bb_l7I^aJ8%X>H!G)AqUqfKl4Tz7t7NTu`6BbkNo z-yWLZn>4g`5;Sb^v+Ug4GXM75X5Z=L{_IS@r9IkF9q+da1W;@wtsjtLf>~C_et<}^ z#+#bB1}lsCz|F89Z2jti?HRmt1^noxjo%z2>nGop<#(2MKVw({crp1NxGsj+`9TGF zRgy!bt{?dMijBT$4gz{CdK}I0Hh^~lo_0MYv%B|1c;W5?db_lC^%2nc%t-I=mgP7S zR53>Y&F7M+A}j>i;cTj?f6Rq}y)|GshZYG%*m@}o#NhtmyNL%j8#k6KrepcHMlHK- zO{DrY)ESKOJv8@4VrcU`G5*nI*~#aneW4h2Z9wQQMiMSH$|)+%jDb7?nGsCU2#w|U zv4N!|Nf)@95*jU>!I_I{*Cc>EL=WTwwvO4VdS3znoK?_y$rVcdOC~QCS~61?9y{5A zVfuRkXtPA=3aJ!PT<*0Qv(GGkbxD1GE$Zs=wI_`0po4RBcw%iPI=t6lk777*#}o6b zySn9i36L9hQj%2ygukFLA#l$J-T>psF7fAx>T<6M7e2+zUy4OOTCtN3Q)LFB|N{cqX39wo#ruxseB7EIKY z_440dO?F8q`OTU2VeqQ|CD}mruO4W*!E%e6uVE=a0N~z5pR9 z9;E0rK(E#5u7$csfn&<-YT}kvw&%q};Jniq+c|L03$RAO0FmFK*v~ac^LND;>#rYL z`A($mRw5q~+6dVJrpfj#^Cu&zUKfS@>GpdhgyvRpSR_QPF|MAIwi#i(m;zfU^V*iD zt8JWtQ&^UsR-Sv{xFAMoYb7m2SfSo<&$D#2^_rjx1AK<(?0Rk-{XvaQ5p2B4 z`Xu8HCCzT}Ul=b>t)_(~r324vS&j&F_UyH|UY~QYPiP#Is`~WA(By3i0{xU!sg^@K z$!pvH!ABf_x3A9J1b$A50O6=~FUYX(;OqsqJQ{DJpsNT%P;J5=|1~cLKd7wCq{k@_ z9+^1;Alb6bc|l~A%(ac1f{JFuiebp*8zv-f4g!amK=cRJA7rF1iQrpLw>oj2_sQ#2 zsY@*fh2KrJ`k2zpbVKdPFxhsOD-a7fYEA&d{%KRNc8K4!o@#`c z1p})OHq`CrDyCZ37m52MVB+JB%Jh9qeLM0b9|syBU!N`M50@OU0f{77Z>Doh+4?f##Wt)xN@LZ18lkZL z;(fn5d6jhIQ7JnnOwFLh)1DG&iT3mLLFCeBBm|{||96jyt2*1PvUkosZ}-dAnND#B zJKcfGX7$zkhH$w{!W=Ll*aJ%g0H~$-{ZVsb@~k>0_iy9XJATZ#&Dv4h^;z$wB;(KZ ze+uknfRP3nIp%7>iFWN7$HN>_nS$04+tvX|23huOzWJegQh}h<7G%q%phEkLCV0Mj z=(Dzyj|CD`!j36jF{%Ec&x;`6WIyDH*#)VGHg5%x(9+p-imk9w5bJ$A-r2wDF|fJM zfb`mIVv7BsRs1$*w~84ski5@W06PW}UF(QfAn$R{#Pn*8D?Jr2Re8p{9oTr&3(|y2 zR4RuP3n80^r)MG9#Z*zUD>Y&h1Qknq=Qa)%y zNm6P)V30R6S1H*mrT_6G)QUmlm2*O`0GDMf|9mKy$$sKtc_e&~wD@s)yKaJcs6)}X zI$*B*zS-Lb$E#;ZVT(SLq6BHsHvdMXX8XIC4j}AGf>~Laz)A&-=5}`E!i`~ZSA$g$ z(7=Sf4|rm%qttZoXseGkl!G5!P{AgR4nu27G&8_PB<#cBpZ^7ZN^$A16YmqT^%7c9 zOi6L@9(n6(Q0adMTGn$lfJQBF;@k6!G2-&otOdi~cw=M>#;(U5cyZ67j!+xmYfpf# zH+kwU7I1dkv4FGV2qH0IecGVoLCPdxATL2_^`!lcBvA2)gTNyX(3F(^9(!V9u20!o zArc%_(Y1*ULqRsct<1wl|D5_JuoJHV+yqU~h1_ziOVzI&o&CP!4*jaP8tPZq%G?hK zsSa0=?gO~vs)kPs{JyFU@=Ie)3&CcO78tkvZ|3Q16HV2D`PQ`bVLJMgM9hg!O;y&r z{T9?#EGRla+7c1s<8wIlH6MD#Zo~6Z&3NSZ`!&rPi0o^w22H)NlsT%?E?2>gPwR`F z5Pvn~<_l)fGg0Q}v=(|Hi|G6mj %zENiL5MfkSyl>%&@lH6z$~BD2?Cug1x(P7^ zDU{U_qBDM(0ZHuPQT)KO^P_$C7;6cPU|qP)gw9YF~*8W z?x3I|5@QskDphF{V~{9KdIu3H(mPVe21F20X;Mc)K-z#5N7@iU+R&s6Op)G(4l}^O z%zqtx-sgXtJ9(Z@@0a(Ne98|GhjaGcXYIAFbzRpEmY(%QT4)nmIht+nx>{bSJ^vgq zRw|3cM?|jUc#Q+)WN!HJF@SA~qIh>z}wT1}&5Biy$`kkF7zrc6kQe%G`*(y zrev4xo_*22rKU;}2K zy(u;Sq66_EWS8Q;YHkJ34QtCwS!NBGB<@%O6JK-R__)$c4j|&dw!Z~YriaIlF?mKh z<;T;>55AOgzDNA^>&|yVvWZ|Q!z=%l>qCj0K%D`C**xau%XH*Z z0H(TpUy1&6!hkQa-}3#>Z+*vJsHuvjbD5u0U}>LVpTFpgdYbC!I)~!x4c*d!+YPjms69J2T1VkQ>xWMgLxAXX=$BC%PRvVv62&#tM@kpzd^v;1?2@@=i` zf_d|<(_#0|eT2F_Fu*w6H8Em9{P(!PORBiDJqs<@%xbD&S@81(q>rjN^ z6LOoHK%24icg-uP;kKZpQbL-9nJEassu-mme!^cy#O}eiqHi1N+0^N|-D!NMpSXJy z+7p00)3=+|t&QfJrhyZ+{lc@rUmKoNi91f5l>Tl9o8MPd7O9b@jKc!&@j#}wyfn`L z_Cze%EQe+`JwU?08>X*uUMx%EvQfJ*AF?v1U8~_V7Cb9|7|s{~cbkl)*mBU+)ZFLZ zFOXIpaB1X$gn+58n{^z7pj#&pYXe(BY0zlY+&{?AYAP&A>xL%des(|H!qd~xXaKO` zrRAm2ZTl3vVb4Rn97<<_$R<83B?bVZYb|mj<~4=6f>> zE}JhxNez%_C<25UC=Zy!$LC*d2}ig6ac)~@!(dEo`w=`WmN0d_EL$t3z8`gbp0+ZM z7^C?4WTPq4@jCWA&et>jth}~qOxy^=d&=?}Bs|i-v|}I?@UyAYM_6CqaeMBym48i7 zUI2mOQ)i=XdEu@E1RAcY=thhv*tcmLtNKL({JkYzq}a>9aJ9_@9m+QTWaQY69YoAz zq6~6Cm6~u`yfWEY-+nyS=ix4=?{+sLP#L!L&4AG#uEWXWw$EyO$`P&%BqY(onkT($ z6%|vPh4wC&8es;6=o}r>W&jJIVCPV?Aq9?jv>~h`NU#ISKD}~1T#N|VU~Ksfg5>>g zU8NUDO&`|yJ+>-!AN#;

    @@ -38,12 +39,13 @@ Surface Hub 2S blah blah blah. @@ -55,12 +57,13 @@ Surface Hub 2S blah blah blah. @@ -75,12 +78,13 @@ Surface Hub 2S blah blah blah. @@ -92,12 +96,14 @@ Surface Hub 2S blah blah blah. @@ -109,12 +115,13 @@ Surface Hub 2S blah blah blah. @@ -131,8 +138,9 @@ Surface Hub 2S blah blah blah.

    Get ready for Surface Hub 2S

    -

    Prepare your environment for Surface Hub 2S

    -

    Surface Hub 2S Readiness Guide

    +

    Prepare your environment for Surface Hub 2S

    +

    Unpacking Surface Hub 2S

    +

    Install & mount Surface Hub 2S

    @@ -144,8 +152,10 @@ Surface Hub 2S blah blah blah. @@ -157,7 +167,7 @@ Surface Hub 2S blah blah blah. diff --git a/devices/surface-hub/surface-hub-2s-connect.md b/devices/surface-hub/surface-hub-2s-connect.md index f950367367..d08debef62 100644 --- a/devices/surface-hub/surface-hub-2s-connect.md +++ b/devices/surface-hub/surface-hub-2s-connect.md @@ -13,13 +13,7 @@ ms.localizationpriority: Normal # Connect devices to Surface Hub 2S -With Surface Hub 2S, you can connect external devices such as a PC; mirror the display on Surface Hub 2S to another device; and connect a wide variety of third-party peripherals including video conference cameras, conference phones, and room system devices. - -# Connect devices to Surface Hub 2S - -- [Connecting external PCs and related devices](#) -- [Mirroring Surface Hub 2S display on another device](#) -- [Connecting peripherals](#) +Surface Hub 2S lets you connect external devices, mirror the display on Surface Hub 2S to another device, and connect a wide variety of third-party peripherals including video conference cameras, conference phones, and room system devices. ## Connect external PCs and related devices @@ -37,7 +31,7 @@ In general, it’s recommended to use native cable connections whenever possible | Mode | Connection | Functionality| Comments | | ---- | ---------- | ------------ | -------- | | Wired “Connect” Application | USB-C (via underside compute module) | Video, audio, TouchBack/InkBack into Surface Hub 2S.| Provides display port video, audio, and TouchBack/InkBack on a single cable. | -| | HDMI + USB-C | HDMI-in for Audio/Video
    USB-C for TouchBack/InkBack | USB-C supports TouchBack/InkBack with the HDMI A/V connection

    Use USB-C to USB-A to connect to legacy computers

    NOTE: For best results, connect HDMI before connecting USB-C cable. If the computer you are using for HDMI is not compatible with TouchBack and InkBack, you won't need a USB-C cable. | +| | HDMI + USB-C | HDMI-in for Audio/Video
    USB-C for TouchBack/InkBack | USB-C supports TouchBack/InkBack with the HDMI A/V connection

    Use USB-C to USB-A to connect to legacy computers

    *NOTE: For best results, connect HDMI before connecting USB-C cable. If the computer you are using for HDMI is not compatible with TouchBack and InkBack, you won't need a USB-C cable.* | | “Source” selection experience
    (bypasses the OS, full screen requires source selection with keypad button) | USB-C (port in compute module) | Video, Audio into Surface Hub 2S | Single cable needed for A/V
    Touchback not supported
    HDCP enabled | | | HDMI (in port) | Video, Audio into Surface Hub 2S | Single cable needed for A/V
    TouchBack not supported
    HDCP enabled | From 793ff13d99c1ff6ba80410495690483e7c6f4607 Mon Sep 17 00:00:00 2001 From: ImranHabib <47118050+joinimran@users.noreply.github.com> Date: Thu, 23 May 2019 01:31:01 +0500 Subject: [PATCH 636/737] Link was not working The link was pointing to the wrong doc and that doc was also not available. I have updated it to point to the correct doc for Azure AD Connect. Problem: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/2405 --- .../hello-for-business/hello-hybrid-key-trust-prereqs.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md index dd447eb2b1..dc00790f7f 100644 --- a/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md +++ b/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs.md @@ -85,7 +85,7 @@ Organizations using older directory synchronization technology, such as DirSync
    ## Federation with Azure ## -You can deploy Windows Hello for Business key trust in non-federated and federated environments. For non-federated environments, key trust deployments work in environments that have deployed [Password Synchronization with Azure AD Connect](https://docs.microsoft.com/azure/active-directory/connect/active-directory-aadconnectsync-implement-password-synchronization) and [Azure Active Directory Pass-through-Authentication](https://docs.microsoft.com/azure/active-directory/connect/active-directory-aadconnect-pass-through-authentication). For federated environments, you can deploy Windows Hello for Business key trust using Active Directory Federation Services (AD FS) beginning with Windows Server 2012 R2. +You can deploy Windows Hello for Business key trust in non-federated and federated environments. For non-federated environments, key trust deployments work in environments that have deployed [Password Synchronization with Azure AD Connect](https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-phs) and [Azure Active Directory Pass-through-Authentication](https://docs.microsoft.com/azure/active-directory/connect/active-directory-aadconnect-pass-through-authentication). For federated environments, you can deploy Windows Hello for Business key trust using Active Directory Federation Services (AD FS) beginning with Windows Server 2012 R2. ### Section Review ### > [!div class="checklist"] From cfed15eef6afdc0081951e43d88fce79384e51ee Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 22 May 2019 13:45:06 -0700 Subject: [PATCH 637/737] optimize onboarding content --- .../minimum-requirements.md | 123 +++++++++++++++- .../onboard-configure.md | 137 ++---------------- 2 files changed, 132 insertions(+), 128 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md index b9112f5c8c..f04b35c833 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md +++ b/windows/security/threat-protection/microsoft-defender-atp/minimum-requirements.md @@ -22,7 +22,7 @@ ms.topic: conceptual **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -There are some minimum requirements for onboarding machines to the service. +There are some minimum requirements for onboarding machines to the service. Learn about the licensing, hardware and software requirements, and other configuration settings to onboard devices to the service. >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-minreqs-abovefoldlink) @@ -45,6 +45,127 @@ For a detailed comparison table of Windows 10 commercial edition comparison, see For more information about licensing requirements for Microsoft Defender ATP platform on Windows Server, see [Protecting Windows Servers with Microsoft Defender ATP](https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Protecting-Windows-Server-with-Windows-Defender-ATP/ba-p/267114). +## Hardware and software requirements +### Supported Windows versions +- Windows 7 SP1 Enterprise +- Windows 7 SP1 Pro +- Windows 8.1 Enterprise +- Windows 8.1 Pro +- Windows 10, version 1607 or later + - Windows 10 Enterprise + - Windows 10 Education + - Windows 10 Pro + - Windows 10 Pro Education +- Windows server + - Windows Server 2012 R2 + - Windows Server 2016 + - Windows Server 2016, version 1803 + - Windows Server 2019 + +Machines on your network must be running one of these editions. + +The hardware requirements for Microsoft Defender ATP on machines is the same as those for the supported editions. + +> [!NOTE] +> Machines that are running mobile versions of Windows are not supported. + + +### Other supported operating systems +- macOSX +- Linux +- Android + +>[!NOTE] +>You'll need to know the exact Linux distros, Android, and macOS versions that are compatible with Microsoft Defender ATP for the integration to work. + + +### Network and data storage and configuration requirements +When you run the onboarding wizard for the first time, you must choose where your Microsoft Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter. + +> [!NOTE] +> - You cannot change your data storage location after the first-time setup. +> - Review the [Microsoft Defender ATP data storage and privacy](data-storage-privacy.md) for more information on where and how Microsoft stores your data. + + +### Diagnostic data settings +You must ensure that the diagnostic data service is enabled on all the machines in your organization. +By default, this service is enabled, but it's good practice to check to ensure that you'll get sensor data from them. + +**Use the command line to check the Windows 10 diagnostic data service startup type**: + +1. Open an elevated command-line prompt on the machine: + + a. Go to **Start** and type **cmd**. + + b. Right-click **Command prompt** and select **Run as administrator**. + +2. Enter the following command, and press **Enter**: + + ```text + sc qc diagtrack + ``` + +If the service is enabled, then the result should look like the following screenshot: + +![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png) + +If the **START_TYPE** is not set to **AUTO_START**, then you'll need to set the service to automatically start. + + + +**Use the command line to set the Windows 10 diagnostic data service to automatically start:** + +1. Open an elevated command-line prompt on the endpoint: + + a. Go to **Start** and type **cmd**. + + b. Right-click **Command prompt** and select **Run as administrator**. + +2. Enter the following command, and press **Enter**: + + ```text + sc config diagtrack start=auto + ``` + +3. A success message is displayed. Verify the change by entering the following command, and press **Enter**: + + ```text + sc qc diagtrack + ``` + + + +#### Internet connectivity +Internet connectivity on machines is required either directly or through proxy. + +The Microsoft Defender ATP sensor can utilize a daily average bandwidth of 5MB to communicate with the Microsoft Defender ATP cloud service and report cyber data. One-off activities such as file uploads and investigation package collection are not included in this daily average bandwidth. + +For more information on additional proxy configuration settings see, [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) . + +Before you onboard machines, the diagnostic data service must be enabled. The service is enabled by default in Windows 10. + + +## Windows Defender Antivirus configuration requirement +The Microsoft Defender ATP agent depends on the ability of Windows Defender Antivirus to scan files and provide information about them. + +You must configure Security intelligence updates on the Microsoft Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). + +When Windows Defender Antivirus is not the active antimalware in your organization and you use the Microsoft Defender ATP service, Windows Defender Antivirus goes on passive mode. If your organization has disabled Windows Defender Antivirus through group policy or other methods, machines that are onboarded to Microsoft Defender ATP must be excluded from this group policy. + +If you are onboarding servers and Windows Defender Antivirus is not the active antimalware on your servers, you shouldn't uninstall Windows Defender Antivirus. You'll need to configure it to run on passive mode. For more information, see [Onboard servers](configure-server-endpoints.md). + + +For more information, see [Windows Defender Antivirus compatibility](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). + +## Windows Defender Antivirus Early Launch Antimalware (ELAM) driver is enabled +If you're running Windows Defender Antivirus as the primary antimalware product on your machines, the Microsoft Defender ATP agent will successfully onboard. + +If you're running a third-party antimalware client and use Mobile Device Management solutions or System Center Configuration Manager (current branch) version 1606, you'll need to ensure that the Windows Defender Antivirus ELAM driver is enabled. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). + + + + + ## Related topic - [Validate licensing and complete setup](licensing.md) - [Onboard machines](onboard-configure.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md index ad3404e068..e6720fb5ed 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboard-configure.md @@ -22,139 +22,18 @@ ms.topic: conceptual **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -You need to turn on the sensor to give visibility within Microsoft Defender ATP. - -For more information, see [Onboard your Windows 10 machines to Microsoft Defender ATP](https://www.youtube.com/watch?v=JT7VGYfeRlA&feature=youtu.be). - [!include[Prerelease information](prerelease.md)] >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-abovefoldlink) -## Licensing requirements -Microsoft Defender Advanced Threat Protection requires one of the following Microsoft Volume Licensing offers: +You'll need to go the onboarding section of the Microsoft Defender ATP portal to onboard any of the supported devices. Depending on the device, you'll be guided with appropriate steps and provided management and deployment tool options suitable for the device. - - Windows 10 Enterprise E5 - - Windows 10 Education E5 - - Microsoft 365 Enterprise E5 which includes Windows 10 Enterprise E5 - -For more information, see [Windows 10 Licensing](https://www.microsoft.com/en-us/Licensing/product-licensing/windows10.aspx#tab=2). - -## Hardware and software requirements -### Supported Windows versions -- Windows 7 SP1 Enterprise -- Windows 7 SP1 Pro -- Windows 8.1 Enterprise -- Windows 8.1 Pro -- Windows 10, version 1607 or later - - Windows 10 Enterprise - - Windows 10 Education - - Windows 10 Pro - - Windows 10 Pro Education -- Windows server - - Windows Server 2012 R2 - - Windows Server 2016 - - Windows Server 2016, version 1803 - - Windows Server 2019 - -Machines on your network must be running one of these editions. - -The hardware requirements for Microsoft Defender ATP on machines is the same as those for the supported editions. - -> [!NOTE] -> Machines that are running mobile versions of Windows are not supported. - - -### Other supported operating systems -- macOSX -- Linux - ->[!NOTE] ->You'll need to know the exact Linux distros and macOS versions that are compatible with Microsoft Defender ATP for the integration to work. - - -### Network and data storage and configuration requirements -When you run the onboarding wizard for the first time, you must choose where your Microsoft Defender Advanced Threat Protection-related information is stored: in the European Union, the United Kingdom, or the United States datacenter. - -> [!NOTE] -> - You cannot change your data storage location after the first-time setup. -> - Review the [Microsoft Defender ATP data storage and privacy](data-storage-privacy.md) for more information on where and how Microsoft stores your data. - - -### Diagnostic data settings -You must ensure that the diagnostic data service is enabled on all the machines in your organization. -By default, this service is enabled, but it's good practice to check to ensure that you'll get sensor data from them. - -**Use the command line to check the Windows 10 diagnostic data service startup type**: - -1. Open an elevated command-line prompt on the machine: - - a. Go to **Start** and type **cmd**. - - b. Right-click **Command prompt** and select **Run as administrator**. - -2. Enter the following command, and press **Enter**: - - ```text - sc qc diagtrack - ``` - -If the service is enabled, then the result should look like the following screenshot: - -![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png) - -If the **START_TYPE** is not set to **AUTO_START**, then you'll need to set the service to automatically start. - - - -**Use the command line to set the Windows 10 diagnostic data service to automatically start:** - -1. Open an elevated command-line prompt on the endpoint: - - a. Go to **Start** and type **cmd**. - - b. Right-click **Command prompt** and select **Run as administrator**. - -2. Enter the following command, and press **Enter**: - - ```text - sc config diagtrack start=auto - ``` - -3. A success message is displayed. Verify the change by entering the following command, and press **Enter**: - - ```text - sc qc diagtrack - ``` - - - -#### Internet connectivity -Internet connectivity on machines is required either directly or through proxy. - -The Microsoft Defender ATP sensor can utilize a daily average bandwidth of 5MB to communicate with the Microsoft Defender ATP cloud service and report cyber data. One-off activities such as file uploads and investigation package collection are not included in this daily average bandwidth. - -For more information on additional proxy configuration settings see, [Configure machine proxy and Internet connectivity settings](configure-proxy-internet.md) . - -Before you onboard machines, the diagnostic data service must be enabled. The service is enabled by default in Windows 10. - - -## Windows Defender Antivirus configuration requirement -The Microsoft Defender ATP agent depends on the ability of Windows Defender Antivirus to scan files and provide information about them. - -You must configure Security intelligence updates on the Microsoft Defender ATP machines whether Windows Defender Antivirus is the active antimalware or not. For more information, see [Manage Windows Defender Antivirus updates and apply baselines](../windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md). - -When Windows Defender Antivirus is not the active antimalware in your organization and you use the Microsoft Defender ATP service, Windows Defender Antivirus goes on passive mode. If your organization has disabled Windows Defender Antivirus through group policy or other methods, machines that are onboarded to Microsoft Defender ATP must be excluded from this group policy. - -If you are onboarding servers and Windows Defender Antivirus is not the active antimalware on your servers, you shouldn't uninstall Windows Defender Antivirus. You'll need to configure it to run on passive mode. For more information, see [Onboard servers](configure-server-endpoints.md). - - -For more information, see [Windows Defender Antivirus compatibility](../windows-defender-antivirus/windows-defender-antivirus-compatibility.md). - -## Windows Defender Antivirus Early Launch Antimalware (ELAM) driver is enabled -If you're running Windows Defender Antivirus as the primary antimalware product on your machines, the Microsoft Defender ATP agent will successfully onboard. - -If you're running a third-party antimalware client and use Mobile Device Management solutions or System Center Configuration Manager (current branch) version 1606, you'll need to ensure that the Windows Defender Antivirus ELAM driver is enabled. For more information, see [Ensure that Windows Defender Antivirus is not disabled by policy](troubleshoot-onboarding.md#ensure-that-windows-defender-antivirus-is-not-disabled-by-a-policy). +In general, to onboard devices to the service: +- Verify that the device fulfills the [minimum requirements](minimum-requirements.md) +- Depending on the device, follow the configuration steps provided in the onboarding section of the Microsoft Defender ATP portal +- Use the appropriate management tool and deployment method for your devices +- Run a detection test to verify that the devices are properly onboarded and reporting to the service ## In this section Topic | Description @@ -168,3 +47,7 @@ Topic | Description [Troubleshoot onboarding issues](troubleshoot-onboarding.md) | Learn about resolving issues that might arise during onboarding. >Want to experience Microsoft Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-onboardconfigure-belowfoldlink) + + + + From 0821c6519db96b9b6011916e15960b582453f58b Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 22 May 2019 13:46:44 -0700 Subject: [PATCH 638/737] preview language --- .../threat-protection/microsoft-defender-atp/preview.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview.md b/windows/security/threat-protection/microsoft-defender-atp/preview.md index 3659e79b88..738e008f9e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview.md @@ -28,7 +28,7 @@ The Microsoft Defender ATP service is constantly being updated to include new fe Learn about new features in the Microsoft Defender ATP preview release and be among the first to try upcoming features by turning on the preview experience. -For more information on capabilities that are generally available or in preview, see [What's new in Microsoft Defender ATP](whats-new-in-microsoft-defender-atp.md). +For more information on new capabilities that are generally available, see [What's new in Microsoft Defender ATP](whats-new-in-microsoft-defender-atp.md). ## Turn on preview features You'll have access to upcoming features which you can provide feedback on to help improve the overall experience before features are generally available. From ce0279f79b42448a26a4f5fcd9e257f3cc093ff0 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 22 May 2019 13:48:53 -0700 Subject: [PATCH 639/737] fix link --- .../threat-protection/microsoft-defender-atp/preview.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/preview.md b/windows/security/threat-protection/microsoft-defender-atp/preview.md index 738e008f9e..5daf8735f5 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/preview.md +++ b/windows/security/threat-protection/microsoft-defender-atp/preview.md @@ -42,7 +42,7 @@ Turn on the preview experience setting to be among the first to try upcoming fea ## Preview features The following features are included in the preview release: -- [Live response](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/live-response)
    Get instantaneous access to a machine using a remote shell connection. Do in-depth investigative work and take immediate response actions to promptly contain identified threats – real-time. +- [Live response](live-response.md)
    Get instantaneous access to a machine using a remote shell connection. Do in-depth investigative work and take immediate response actions to promptly contain identified threats – real-time. - [Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)
    A new built-in capability that uses a risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. From 38a53c1ecf3b81a8b61801e92de75586f2de5898 Mon Sep 17 00:00:00 2001 From: MatthewMWR Date: Wed, 22 May 2019 13:52:23 -0700 Subject: [PATCH 640/737] Fix AllowTelemetry precedence info --- .../update/windows-analytics-FAQ-troubleshooting.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md b/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md index 9942044960..e2e21a62bc 100644 --- a/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md +++ b/windows/deployment/update/windows-analytics-FAQ-troubleshooting.md @@ -84,11 +84,13 @@ If you have devices that appear in other solutions, but not Device Health (the D 1. Using the Azure portal, remove the Device Health (appears as DeviceHealthProd on some pages) solution from your Log Analytics workspace. After completing this, add the Device Health solution to you workspace again. 2. Confirm that the devices are running Windows 10. 3. Verify that the Commercial ID is present in the device's registry. For details see [https://gpsearch.azurewebsites.net/#13551](https://gpsearch.azurewebsites.net/#13551). -4. Confirm that devices have opted in to provide diagnostic data by checking in the registry that **AllowTelemetry** is set to 2 (Enhanced) or 3 (Full) in **HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection** (or **HKLM\Software\Policies\Microsoft\Windows\DataCollection**, which takes precedence if set). +4. Confirm that devices are opted in to send diagnostic data by checking in the registry that **AllowTelemetry** is set to either 2 (Enhanced) or 3 (Full). + - **AllowTelemetry** under **HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection** is the location set by Group Policy or MDM + - **AllowTelemetry** under **HKLM\Software\Policies\Microsoft\Windows\DataCollection** is the location set by local tools such as the Settings app. + - By convention the Group Policy location would take precedence if both are set. Starting with Windows 10, version 1803, the default precedence is modified to enable a device user to lower the diagnostic data level from that set by IT. For organizations which have no requirement to allow the user to override IT, the conventional (IT wins) behavior can be re-enabled using **DisableTelemetryOptInSettingsUx**. This policy can be set via Group Policy as **Computer Configuration\Administrative Templates\Windows Components\Data Collection and Preview Builds\Configure telemetry opt-in setting user interface**. 5. Verify that devices can reach the endpoints specified in [Enrolling devices in Windows Analytics](windows-analytics-get-started.md). Also check settings for SSL inspection and proxy authentication; see [Configuring endpoint access with SSL inspection](https://docs.microsoft.com/windows/deployment/update/windows-analytics-get-started#configuring-endpoint-access-with-ssl-inspection) for more information. -6. Add the Device Health solution back to your Log Analytics workspace. -7. Wait 48 hours for activity to appear in the reports. -8. If you need additional troubleshooting, contact Microsoft Support. +6. Wait 48 hours for activity to appear in the reports. +7. If you need additional troubleshooting, contact Microsoft Support. ### Device crashes not appearing in Device Health Device Reliability From ac3870cc74221d48c29cf5c66c59a8e8d76862ec Mon Sep 17 00:00:00 2001 From: Robert Mazzoli Date: Wed, 22 May 2019 13:53:15 -0700 Subject: [PATCH 641/737] fixed link typo on Surface Hub landing page --- devices/surface-hub/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/surface-hub/index.md b/devices/surface-hub/index.md index 23e2a7d565..2085210b3f 100644 --- a/devices/surface-hub/index.md +++ b/devices/surface-hub/index.md @@ -102,7 +102,7 @@ Microsoft Surface Hub 2S and Surface Hub are all-in one productivity devices for
    From deeb5d921044d4aed6c6db9eb3e826cc27b0f2ab Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 22 May 2019 14:16:20 -0700 Subject: [PATCH 642/737] update what's new in deployment --- windows/deployment/deploy-whats-new.md | 29 +++++++++++++++++++++----- 1 file changed, 24 insertions(+), 5 deletions(-) diff --git a/windows/deployment/deploy-whats-new.md b/windows/deployment/deploy-whats-new.md index 3b74f5101f..7a4115d70e 100644 --- a/windows/deployment/deploy-whats-new.md +++ b/windows/deployment/deploy-whats-new.md @@ -28,7 +28,7 @@ This topic provides an overview of new solutions and online content related to d [SetupDiag](#setupdiag) 1.4.1 is released.
    [MDT](#microsoft-deployment-toolkit-mdt) 8456 is released.
    New [Windows Autopilot](#windows-autopilot) content is available.
    -The [Microsoft 365](#microsoft-365) section was added. +[Windows 10 Subscription Activation](#windows-10-subscription-activation) now supports Windows 10 Education. ## The Modern Desktop Deployment Center @@ -45,7 +45,16 @@ See [Deploy Windows 10 with Microsoft 365](deploy-m365.md) for an overview, whic ## Windows 10 servicing and support -Microsoft is [extending support](https://www.microsoft.com/microsoft-365/blog/2018/09/06/helping-customers-shift-to-a-modern-desktop) for Windows 10 Enterprise and Windows 10 Education editions to 30 months from the version release date. This includes all past versions and future versions that are targeted for release in September (versions ending in 09, ex: 1809). Future releases that are targeted for release in March (versions ending in 03, ex: 1903) will continue to be supported for 18 months from their release date. All releases of Windows 10 Home, Windows 10 Pro, and Office 365 ProPlus will continue to be supported for 18 months (there is no change for these editions). These support policies are summarized in the table below. +- [**Delivery Optimization**](https://docs.microsoft.com/windows/deployment/update/waas-delivery-optimization): Improved Peer Efficiency for enterprises and educational institutions with complex networks is enabled with of [new policies](https://docs.microsoft.com/windows/client-management/mdm/policy-csp-deliveryoptimization). This now supports Office 365 ProPlus updates, and Intune content, with System Center Configuration Manager content coming soon! +- [**Automatic Restart Sign-on (ARSO)**](https://docs.microsoft.com/en-us/windows-insider/at-work-pro/wip-4-biz-whats-new#automatic-restart-and-sign-on-arso-for-enterprises-build-18305): Windows will automatically logon as the user and lock their device in order to complete the update, ensuring that when the user returns and unlocks the device, the update will be completed. +- [**Windows Update for Business**](https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-Update-for-Business-and-the-retirement-of-SAC-T/ba-p/339523): There will now be a single, common start date for phased deployments (no more SAC-T designation). In addition, there will a new notification and reboot scheduling experience for end users, the ability to enforce update installation and reboot deadlines, and the ability to provide end user control over reboots for a specific time period. +- **Update rollback improvements**: You can now automatically recover from startup failures by removing updates if the startup failure was introduced after the installation of recent driver or quality updates. When a device is unable to start up properly after the recent installation of Quality of driver updates, Windows will now automatically uninstall the updates to get the device back up and running normally. +- **Pause updates**: We have extended the ability to pause updates for both feature and monthly updates. This extension ability is for all editions of Windows 10, including Home. You can pause both feature and monthly updates for up to 35 days (seven days at a time, up to five times). Once the 35-day pause period is reached, you will need to update your device before pausing again. +- **Improved update notifications**: When there’s an update requiring you to restart your device, you’ll see a colored dot on the Power button in the Start menu and on the Windows icon in your taskbar. +- **Intelligent active hours**: To further enhance active hours, users will now have the option to let Windows Update intelligently adjust active hours based on their device-specific usage patterns. You must enable the intelligent active hours feature for the system to predict device-specific usage patterns. +- **Improved update orchestration to improve system responsiveness**: This feature will improve system performance by intelligently coordinating Windows updates and Microsoft Store updates, so they occur when users are away from their devices to minimize disruptions. + +Microsoft previously announced that we are [extending support](https://www.microsoft.com/microsoft-365/blog/2018/09/06/helping-customers-shift-to-a-modern-desktop) for Windows 10 Enterprise and Windows 10 Education editions to 30 months from the version release date. This includes all past versions and future versions that are targeted for release in September (versions ending in 09, ex: 1809). Future releases that are targeted for release in March (versions ending in 03, ex: 1903) will continue to be supported for 18 months from their release date. All releases of Windows 10 Home, Windows 10 Pro, and Office 365 ProPlus will continue to be supported for 18 months (there is no change for these editions). These support policies are summarized in the table below. ![Support lifecycle](images/support-cycle.png) @@ -62,11 +71,21 @@ For more information, see [Windows 10 Enterprise E3 in CSP](windows-10-enterpris ### Windows Autopilot -Windows Autopilot streamlines and automates the process of setting up and configuring new devices, with minimal interaction required from the end user. You can also use Windows Autopilot to reset, repurpose and recover devices. +[Windows Autopilot](https://docs.microsoft.com/windows/deployment/windows-autopilot/windows-autopilot) streamlines and automates the process of setting up and configuring new devices, with minimal interaction required from the end user. You can also use Windows Autopilot to reset, repurpose and recover devices. -Windows Autopilot joins devices to Azure Active Directory (Azure AD), optionally enrolls into MDM services, configures security policies, and sets a custom out-of-box-experience (OOBE) for the end user. For more information, see [Overview of Windows Autopilot](windows-autopilot/windows-autopilot.md). +The following Windows Autopilot features are available in Windows 10, version 1903 and later: -Recent Autopilot content includes new instructions for CSPs and OEMs on how to [obtain and use customer authorization](windows-autopilot/registration-auth.md) to register Windows Autopilot devices on the customer’s behalf. +- [Windows Autopilot for white glove deployment](https://docs.microsoft.com/windows/deployment/windows-autopilot/white-glove) is new in Windows 10, version 1903. "White glove" deployment enables partners or IT staff to pre-provision devices so they are fully configured and business ready for your users. +- The Intune [enrollment status page](https://docs.microsoft.com/intune/windows-enrollment-status) (ESP) now tracks Intune Management Extensions​. +- [Cortana voiceover](https://docs.microsoft.com/windows-hardware/customize/desktop/cortana-voice-support) and speech recognition during OOBE is disabled by default for all Windows 10 Pro Education, and Enterprise SKUs. +- Windows Autopilot is self-updating during OOBE. Starting with the Windows 10, version 1903 Autopilot functional and critical updates will begin downloading automatically during OOBE. +- Windows Autopilot will set the [diagnostics data](https://docs.microsoft.com/windows/privacy/windows-diagnostic-data) level to Full on Windows 10 version 1903 and later during OOBE. + +### Windows 10 Subscription Activation + +Windows 10 Education support has been added to Windows 10 Subscription Activation. + +With Windows 10, version 1903, you can step-up from Windows 10 Pro Education to the enterprise-grade edition for educational institutions – Windows 10 Education. For more information, see [Windows 10 Subscription Activation](https://docs.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation). ### SetupDiag From 1f7b6107a620522875adbb37c0968e24cb43a5c9 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Wed, 22 May 2019 14:19:06 -0700 Subject: [PATCH 644/737] Removed 7 DO and 4 Update polocies from Hololens --- .../policy-configuration-service-provider.md | 22 ------------------- .../mdm/policy-csp-deliveryoptimization.md | 14 ------------ .../mdm/policy-csp-update.md | 14 ++++-------- 3 files changed, 4 insertions(+), 46 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index 586c0e380e..6921c8f6f4 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -5144,13 +5144,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [Browser/AllowSmartScreen](#browser-allowsmartscreen) - [Connectivity/AllowBluetooth](#connectivity-allowbluetooth) - [Connectivity/AllowUSBConnection](#connectivity-allowusbconnection) -- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) -- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) -- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) -- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) -- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) -- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) -- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) - [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) - [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) - [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) @@ -5194,10 +5187,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [System/AllowTelemetry](#system-allowtelemetry) - [Update/AllowAutoUpdate](#update-allowautoupdate) - [Update/AllowUpdateService](#update-allowupdateservice) -- [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) -- [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) -- [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) -- [Update/ConfigureDeadlineNoAutoReboot](#update-configuredeadlinenoautoreboot) - [Update/RequireDeferUpgrade](#update-requiredeferupgrade) - [Update/RequireUpdateApproval](#update-requireupdateapproval) - [Update/ScheduledInstallDay](#update-scheduledinstallday) @@ -5234,13 +5223,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/MinDevicePasswordComplexCharacters](#devicelock-mindevicepasswordcomplexcharacters) - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/DevicePasswordEnabled](#devicelock-devicepasswordenabled) -- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) -- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) -- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) -- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) -- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) -- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) -- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) - [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) - [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) - [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) @@ -5275,10 +5257,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [System/AllowLocation](#system-allowlocation) - [Update/AllowAutoUpdate](#update-allowautoupdate) - [Update/AllowUpdateService](#update-allowupdateservice) -- [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) -- [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) -- [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) -- [Update/ConfigureDeadlineNoAutoReboot](#update-configuredeadlinenoautoreboot) - [Update/RequireUpdateApproval](#update-requireupdateapproval) - [Update/ScheduledInstallDay](#update-scheduledinstallday) - [Update/ScheduledInstallTime](#update-scheduledinstalltime) diff --git a/windows/client-management/mdm/policy-csp-deliveryoptimization.md b/windows/client-management/mdm/policy-csp-deliveryoptimization.md index bc9b57fc40..5cb0dd35f7 100644 --- a/windows/client-management/mdm/policy-csp-deliveryoptimization.md +++ b/windows/client-management/mdm/policy-csp-deliveryoptimization.md @@ -1705,13 +1705,6 @@ This policy allows an IT Admin to define the following: ## DeliveryOptimization policies supported by Windows Holographic -- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) -- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) -- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) -- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) -- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) -- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) -- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) - [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) - [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) - [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) @@ -1737,13 +1730,6 @@ This policy allows an IT Admin to define the following: ## DeliveryOptimization policies supported by Windows Holographic for Business -- [DeliveryOptimization/DOAbsoluteMaxCacheSize](#deliveryoptimization-doabsolutemaxcachesize) -- [DeliveryOptimization/DOAllowVPNPeerCaching](#deliveryoptimization-doallowvpnpeercaching) -- [DeliveryOptimization/DOCacheHost](#deliveryoptimization-docachehost) -- [DeliveryOptimization/DODelayBackgroundDownloadFromHttp](#deliveryoptimization-dodelaybackgrounddownloadfromhttp) -- [DeliveryOptimization/DODelayForegroundDownloadFromHttp](#deliveryoptimization-dodelayforegrounddownloadfromhttp) -- [DeliveryOptimization/DODelayCacheServerFallbackBackground](#deliveryoptimization-dodelaycacheserverfallbackbackground) -- [DeliveryOptimization/DODelayCacheServerFallbackForeground](#deliveryoptimization-dodelaycacheserverfallbackforeground) - [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) - [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) - [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) diff --git a/windows/client-management/mdm/policy-csp-update.md b/windows/client-management/mdm/policy-csp-update.md index 78dfe6c171..1f9522e70b 100644 --- a/windows/client-management/mdm/policy-csp-update.md +++ b/windows/client-management/mdm/policy-csp-update.md @@ -3961,15 +3961,12 @@ ADMX Info: - [Update/AllowAutoUpdate](#update-allowautoupdate) - [Update/AllowUpdateService](#update-allowupdateservice) -- [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) -- [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) -- [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) -- [Update/ConfigureDeadlineNoAutoReboot](#update-configuredeadlinenoautoreboot) +- [Update/RequireDeferUpgrade](#update-requiredeferupgrade) - [Update/RequireUpdateApproval](#update-requireupdateapproval) - [Update/ScheduledInstallDay](#update-scheduledinstallday) - [Update/ScheduledInstallTime](#update-scheduledinstalltime) - [Update/UpdateServiceUrl](#update-updateserviceurl) -- [Update/RequireDeferUpgrade](#update-requiredeferupgrade) + @@ -3977,15 +3974,12 @@ ADMX Info: - [Update/AllowAutoUpdate](#update-allowautoupdate) - [Update/AllowUpdateService](#update-allowupdateservice) -- [Update/ConfigureDeadlineForFeatureUpdates](#update-configuredeadlineforfeatureupdates) -- [Update/ConfigureDeadlineForQualityUpdates](#update-configuredeadlineforqualityupdates) -- [Update/ConfigureDeadlineGracePeriod](#update-configuredeadlinegraceperiod) -- [Update/ConfigureDeadlineNoAutoReboot](#update-configuredeadlinenoautoreboot) +- [Update/RequireDeferUpgrade](#update-requiredeferupgrade) - [Update/RequireUpdateApproval](#update-requireupdateapproval) - [Update/ScheduledInstallDay](#update-scheduledinstallday) - [Update/ScheduledInstallTime](#update-scheduledinstalltime) - [Update/UpdateServiceUrl](#update-updateserviceurl) -- [Update/RequireDeferUpgrade](#update-requiredeferupgrade) + From cfba73b9a665978174817a7a221948d3d41d6746 Mon Sep 17 00:00:00 2001 From: Greg Lindsay Date: Wed, 22 May 2019 14:20:47 -0700 Subject: [PATCH 645/737] update --- windows/deployment/deploy-whats-new.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/deployment/deploy-whats-new.md b/windows/deployment/deploy-whats-new.md index 7a4115d70e..7ca878471d 100644 --- a/windows/deployment/deploy-whats-new.md +++ b/windows/deployment/deploy-whats-new.md @@ -26,7 +26,7 @@ This topic provides an overview of new solutions and online content related to d ## Recent additions to this page [SetupDiag](#setupdiag) 1.4.1 is released.
    -[MDT](#microsoft-deployment-toolkit-mdt) 8456 is released.
    +The [Windows ADK for Windows 10, version 1903](https://docs.microsoft.com/en-us/windows-hardware/get-started/adk-install) is available.
    New [Windows Autopilot](#windows-autopilot) content is available.
    [Windows 10 Subscription Activation](#windows-10-subscription-activation) now supports Windows 10 Education. From 456b8135a4dc5fa12c4e22b7e21a5e78d377cac7 Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Wed, 22 May 2019 15:01:24 -0700 Subject: [PATCH 646/737] Removed all DO policies from Hololens --- .../policy-configuration-service-provider.md | 40 ----------------- .../mdm/policy-csp-deliveryoptimization.md | 43 ------------------- 2 files changed, 83 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index 6921c8f6f4..bdcf382e09 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -5144,26 +5144,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [Browser/AllowSmartScreen](#browser-allowsmartscreen) - [Connectivity/AllowBluetooth](#connectivity-allowbluetooth) - [Connectivity/AllowUSBConnection](#connectivity-allowusbconnection) -- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) -- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) -- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) -- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) -- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) -- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) -- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) -- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) -- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) -- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) -- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) -- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) -- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) -- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) -- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) -- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) -- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) -- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) -- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) -- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/AllowSimpleDevicePassword](#devicelock-allowsimpledevicepassword) - [DeviceLock/AlphanumericDevicePasswordRequired](#devicelock-alphanumericdevicepasswordrequired) @@ -5223,26 +5203,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/MinDevicePasswordComplexCharacters](#devicelock-mindevicepasswordcomplexcharacters) - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/DevicePasswordEnabled](#devicelock-devicepasswordenabled) -- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) -- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) -- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) -- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) -- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) -- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) -- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) -- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) -- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) -- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) -- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) -- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) -- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) -- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) -- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) -- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) -- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) -- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) -- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) -- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) - [Experience/AllowCortana](#experience-allowcortana) - [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) - [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) diff --git a/windows/client-management/mdm/policy-csp-deliveryoptimization.md b/windows/client-management/mdm/policy-csp-deliveryoptimization.md index 5cb0dd35f7..c41848da3b 100644 --- a/windows/client-management/mdm/policy-csp-deliveryoptimization.md +++ b/windows/client-management/mdm/policy-csp-deliveryoptimization.md @@ -1703,53 +1703,10 @@ This policy allows an IT Admin to define the following: -## DeliveryOptimization policies supported by Windows Holographic -- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) -- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) -- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) -- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) -- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) -- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) -- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) -- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) -- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) -- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) -- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) -- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) -- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) -- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) -- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) -- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) -- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) -- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) -- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) -- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) -## DeliveryOptimization policies supported by Windows Holographic for Business - -- [DeliveryOptimization/DODownloadMode](#deliveryoptimization-dodownloadmode) -- [DeliveryOptimization/DOGroupId](#deliveryoptimization-dogroupid) -- [DeliveryOptimization/DOGroupIdSource](#deliveryoptimization-dogroupidsource) -- [DeliveryOptimization/DOMaxCacheAge](#deliveryoptimization-domaxcacheage) -- [DeliveryOptimization/DOMaxCacheSize](#deliveryoptimization-domaxcachesize) -- [DeliveryOptimization/DOMaxDownloadBandwidth](#deliveryoptimization-domaxdownloadbandwidth) -- [DeliveryOptimization/DOMaxUploadBandwidth](#deliveryoptimization-domaxuploadbandwidth) -- [DeliveryOptimization/DOMinBackgroundQos](#deliveryoptimization-dominbackgroundqos) -- [DeliveryOptimization/DOMinBatteryPercentageAllowedToUpload](#deliveryoptimization-dominbatterypercentageallowedtoupload) -- [DeliveryOptimization/DOMinDiskSizeAllowedToPeer](#deliveryoptimization-domindisksizeallowedtopeer) -- [DeliveryOptimization/DOMinFileSizeToCache](#deliveryoptimization-dominfilesizetocache) -- [DeliveryOptimization/DOMinRAMAllowedToPeer](#deliveryoptimization-dominramallowedtopeer) -- [DeliveryOptimization/DOModifyCacheDrive](#deliveryoptimization-domodifycachedrive) -- [DeliveryOptimization/DOMonthlyUploadDataCap](#deliveryoptimization-domonthlyuploaddatacap) -- [DeliveryOptimization/DOPercentageMaxBackgroundBandwidth](#deliveryoptimization-dopercentagemaxbackgroundbandwidth) -- [DeliveryOptimization/DOPercentageMaxDownloadBandwidth](#deliveryoptimization-dopercentagemaxdownloadbandwidth) -- [DeliveryOptimization/DOPercentageMaxForegroundBandwidth](#deliveryoptimization-dopercentagemaxforegroundbandwidth) -- [DeliveryOptimization/DORestrictPeerSelectionBy](#deliveryoptimization-dorestrictpeerselectionby) -- [DeliveryOptimization/DOSetHoursToLimitBackgroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitbackgrounddownloadbandwidth) -- [DeliveryOptimization/DOSetHoursToLimitForegroundDownloadBandwidth](#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth) From 19294cb9f5884671af9631992328244842f6567e Mon Sep 17 00:00:00 2001 From: ManikaDhiman Date: Wed, 22 May 2019 15:30:54 -0700 Subject: [PATCH 647/737] Removed IE policies from Hololens sections --- .../mdm/policy-configuration-service-provider.md | 6 ------ .../client-management/mdm/policy-csp-internetexplorer.md | 8 -------- 2 files changed, 14 deletions(-) diff --git a/windows/client-management/mdm/policy-configuration-service-provider.md b/windows/client-management/mdm/policy-configuration-service-provider.md index bdcf382e09..46a8f4ff4e 100644 --- a/windows/client-management/mdm/policy-configuration-service-provider.md +++ b/windows/client-management/mdm/policy-configuration-service-provider.md @@ -5154,9 +5154,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/MinDevicePasswordComplexCharacters](#devicelock-mindevicepasswordcomplexcharacters) - [DeviceLock/MinDevicePasswordLength](#devicelock-mindevicepasswordlength) - [Experience/AllowCortana](#experience-allowcortana) -- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) -- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) -- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) - [Privacy/AllowInputPersonalization](#privacy-allowinputpersonalization) - [Search/AllowSearchToUseLocation](#search-allowsearchtouselocation) - [Security/RequireDeviceEncryption](#security-requiredeviceencryption) @@ -5204,9 +5201,6 @@ The following diagram shows the Policy configuration service provider in tree fo - [DeviceLock/AllowIdleReturnWithoutPassword](#devicelock-allowidlereturnwithoutpassword) - [DeviceLock/DevicePasswordEnabled](#devicelock-devicepasswordenabled) - [Experience/AllowCortana](#experience-allowcortana) -- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) -- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) -- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) - [Privacy/AllowInputPersonalization](#privacy-allowinputpersonalization) - [Search/AllowSearchToUseLocation](#search-allowsearchtouselocation) - [Security/RequireDeviceEncryption](#security-requiredeviceencryption) diff --git a/windows/client-management/mdm/policy-csp-internetexplorer.md b/windows/client-management/mdm/policy-csp-internetexplorer.md index c9be35eac1..eef9f657f6 100644 --- a/windows/client-management/mdm/policy-csp-internetexplorer.md +++ b/windows/client-management/mdm/policy-csp-internetexplorer.md @@ -17429,19 +17429,11 @@ ADMX Info: -## InternetExplorer policies supported by Windows Holographic -- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) -- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) -- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) -## InternetExplorer policies supported by Windows Holographic for Business -- [InternetExplorer/DisableActiveXVersionListAutoDownload](#internetexplorer-disableactivexversionlistautodownload) -- [InternetExplorer/DisableCompatView](#internetexplorer-disablecompatview) -- [InternetExplorer/DisableGeolocation](#internetexplorer-disablegeolocation) From 214e5eb1f34f9461444803dc11b10db7e445e823 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Wed, 22 May 2019 16:00:11 -0700 Subject: [PATCH 648/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...erating-system-components-to-microsoft-services.md | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index ef5baca3de..23fa72cfee 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -32,11 +32,8 @@ If you want to minimize connections from Windows to Microsoft services, or confi You can configure diagnostic data at the Security/Basic level, turn off Windows Defender diagnostic data and MSRT reporting, and turn off all other connections to Microsoft network endpoints as described in this article to help prevent Windows from sending any data to Microsoft. There are many reasons why these communications are enabled by default, such as updating malware definitions and maintain current certificate revocation lists, which is why we strongly recommend against this. This data helps us deliver a secure, reliable, and more delightful personalized experience. -To help make it easier to deploy settings to restrict connections from Windows 10 to Microsoft, you can apply the [Windows Restricted Traffic Limited Functionality Baseline](https://go.microsoft.com/fwlink/?linkid=828887). -This baseline was created in the same way as the [Windows security baselines](/windows/device-security/windows-security-baselines) that are often used to efficiently configure Windows to a known secure state. -Running the Windows Restricted Traffic Limited Functionality Baseline on devices in your organization will allow you to quickly configure all of the settings covered in this document. -However, some of the settings reduce the functionality and security configuration of your device and are therefore not recommended. -Make sure you've chosen the right settings configuration for your environment before applying. +To help make it easier to deploy settings to restrict connections from Windows 10 to Microsoft, you can apply the [Windows Restricted Traffic Limited Functionality Baseline](https://go.microsoft.com/fwlink/?linkid=828887), but **before applying it please ensure that Windows and Windows Defender are fully up to date**. Failure to do so may result in errors. This baseline was created in the same way as the [Windows security baselines](/windows/device-security/windows-security-baselines) that are often used to efficiently configure Windows to a known secure state. +Running the Windows Restricted Traffic Limited Functionality Baseline on devices in your organization will allow you to quickly configure all of the settings covered in this document. However, some of the settings reduce the functionality and security configuration of your device and are therefore not recommended. Make sure you've chosen the right settings configuration for your environment before applying. You should not extract this package to the windows\\system32 folder because it will not apply correctly. Applying the Windows Restricted Traffic Limited Functionality Baseline is the same as applying each setting covered in this article. @@ -1593,7 +1590,9 @@ When turned off, the Wi-Fi Sense settings still appear on the Wi-Fi Settings scr You can disconnect from the Microsoft Antimalware Protection Service. -On Windows 10 1903 Client operating systems and newer search on "Tamper Protection" from the Windows search button next to the Start button on the desktop commmand bar. Scroll down to the Tamper Protection toggle and turn it **Off**. This will allow you to modify the Registry key and allow the Group Policy to make the setting. Alternatively, go to Windows Security Settings -> Virus & threat protection, click on Manage settings and then scroll down to the Tamper Protection toggle and set it to **Off**. +**Required Steps BEFORE setting the windows Defender Group Policy or RegKey on Windows 10 version 1903** +1. Ensure Windows and Windows Defender are fully up to date. +2. Search the Start menu for "Tamper Protection" by clicking on the search icon next to the Windows Start button. Then scroll down to the Tamper Protection toggle and turn it **Off**. This will allow you to modify the Registry key and allow the Group Policy to make the setting. Alternatively, you can go to **Windows Security Settings -> Virus & threat protection, click on Manage Settings** link and then scroll down to the Tamper Protection toggle to set it to **Off**. - **Enable** the Group Policy **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Defender Antivirus** > **MAPS** > **Join Microsoft MAPS** and then select **Disabled** from the drop down box named **Join Microsoft MAPS** From ed9124788c51a67e9aaf20f6941faf236e7412ae Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Wed, 22 May 2019 16:01:27 -0700 Subject: [PATCH 649/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 23fa72cfee..e4a1de926d 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -1590,7 +1590,7 @@ When turned off, the Wi-Fi Sense settings still appear on the Wi-Fi Settings scr You can disconnect from the Microsoft Antimalware Protection Service. -**Required Steps BEFORE setting the windows Defender Group Policy or RegKey on Windows 10 version 1903** +**Required Steps BEFORE setting the Windows Defender Group Policy or RegKey on Windows 10 version 1903** 1. Ensure Windows and Windows Defender are fully up to date. 2. Search the Start menu for "Tamper Protection" by clicking on the search icon next to the Windows Start button. Then scroll down to the Tamper Protection toggle and turn it **Off**. This will allow you to modify the Registry key and allow the Group Policy to make the setting. Alternatively, you can go to **Windows Security Settings -> Virus & threat protection, click on Manage Settings** link and then scroll down to the Tamper Protection toggle to set it to **Off**. From 7c680615f1f4a68ef7df0a9a27e50400c69dfa83 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Wed, 22 May 2019 16:05:26 -0700 Subject: [PATCH 650/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...ws-operating-system-components-to-microsoft-services.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index e4a1de926d..1b75343f35 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -1590,9 +1590,10 @@ When turned off, the Wi-Fi Sense settings still appear on the Wi-Fi Settings scr You can disconnect from the Microsoft Antimalware Protection Service. -**Required Steps BEFORE setting the Windows Defender Group Policy or RegKey on Windows 10 version 1903** -1. Ensure Windows and Windows Defender are fully up to date. -2. Search the Start menu for "Tamper Protection" by clicking on the search icon next to the Windows Start button. Then scroll down to the Tamper Protection toggle and turn it **Off**. This will allow you to modify the Registry key and allow the Group Policy to make the setting. Alternatively, you can go to **Windows Security Settings -> Virus & threat protection, click on Manage Settings** link and then scroll down to the Tamper Protection toggle to set it to **Off**. +>[!IMPORTANT] +>**Required Steps BEFORE setting the Windows Defender Group Policy or RegKey on Windows 10 version 1903** +>1. Ensure Windows and Windows Defender are fully up to date. +>2. Search the Start menu for "Tamper Protection" by clicking on the search icon next to the Windows Start button. Then scroll down to >the Tamper Protection toggle and turn it **Off**. This will allow you to modify the Registry key and allow the Group Policy to make >the setting. Alternatively, you can go to **Windows Security Settings -> Virus & threat protection, click on Manage Settings** link >and then scroll down to the Tamper Protection toggle to set it to **Off**. - **Enable** the Group Policy **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Windows Defender Antivirus** > **MAPS** > **Join Microsoft MAPS** and then select **Disabled** from the drop down box named **Join Microsoft MAPS** From f376c502ac6dc66ca2004fa5c6b89e3c83380f91 Mon Sep 17 00:00:00 2001 From: Mike Edgar <49731348+medgarmedgar@users.noreply.github.com> Date: Wed, 22 May 2019 16:08:08 -0700 Subject: [PATCH 651/737] Update manage-connections-from-windows-operating-system-components-to-microsoft-services.md --- ...windows-operating-system-components-to-microsoft-services.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md index 1b75343f35..c68d13cadf 100644 --- a/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md +++ b/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services.md @@ -32,7 +32,7 @@ If you want to minimize connections from Windows to Microsoft services, or confi You can configure diagnostic data at the Security/Basic level, turn off Windows Defender diagnostic data and MSRT reporting, and turn off all other connections to Microsoft network endpoints as described in this article to help prevent Windows from sending any data to Microsoft. There are many reasons why these communications are enabled by default, such as updating malware definitions and maintain current certificate revocation lists, which is why we strongly recommend against this. This data helps us deliver a secure, reliable, and more delightful personalized experience. -To help make it easier to deploy settings to restrict connections from Windows 10 to Microsoft, you can apply the [Windows Restricted Traffic Limited Functionality Baseline](https://go.microsoft.com/fwlink/?linkid=828887), but **before applying it please ensure that Windows and Windows Defender are fully up to date**. Failure to do so may result in errors. This baseline was created in the same way as the [Windows security baselines](/windows/device-security/windows-security-baselines) that are often used to efficiently configure Windows to a known secure state. +To help make it easier to deploy settings to restrict connections from Windows 10 to Microsoft, you can apply the [Windows Restricted Traffic Limited Functionality Baseline](https://go.microsoft.com/fwlink/?linkid=828887), but **before application please ensure that Windows and Windows Defender are fully up to date**. Failure to do so may result in errors. This baseline was created in the same way as the [Windows security baselines](/windows/device-security/windows-security-baselines) that are often used to efficiently configure Windows to a known secure state. Running the Windows Restricted Traffic Limited Functionality Baseline on devices in your organization will allow you to quickly configure all of the settings covered in this document. However, some of the settings reduce the functionality and security configuration of your device and are therefore not recommended. Make sure you've chosen the right settings configuration for your environment before applying. You should not extract this package to the windows\\system32 folder because it will not apply correctly. From 9d7c8b2a10ec71d6f3d1a2707048dd45f088cb84 Mon Sep 17 00:00:00 2001 From: Max Velitchko Date: Wed, 22 May 2019 16:16:36 -0700 Subject: [PATCH 652/737] Microsoft Defender for macOS: move JAMF based uninstallation to the JAMF article --- .../images/MDATP_26_Uninstall.png | Bin 22356 -> 30951 bytes ...soft-defender-atp-mac-install-with-jamf.md | 31 +++++++++++++++- .../microsoft-defender-atp-mac-resources.md | 33 ++---------------- 3 files changed, 32 insertions(+), 32 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/images/MDATP_26_Uninstall.png b/windows/security/threat-protection/windows-defender-antivirus/images/MDATP_26_Uninstall.png index aa0d5c7caf671bb8d1ece4ad8a56c34427c5e530..6463593a6c9735f7ae3b2f49316860c634253eda 100644 GIT binary patch literal 30951 zcmcG$WmH|s*7v({x8SZp65O5OkPsvgEI2^|1b26L5+K2y1PJc#5IneBaCd^<+TG_l zeeO8pz2kj8+}-qUSbOcYR?VuKbJqO-s>75OWie1mP$3WqhP<5A8wdoJ0Rn+>Lq-Hg zq=dtJ!G92qUdc*99-;qaHWws-BPh0VS`H8hD=qY27}q>8XK)b7QU0|w(mDbGAr`~j zN6kZUh}cnD(^1mq<3|%~M~I}oiJ_y(dn%U?j^Uy2pFWmi&-%gyt+|vz$*e595%9(0EfHQ0>NR;R2_J& z%bc8f1g%SlBR${c(#-L(0WWEd)bWkr@r})Bs_Y_vM}dg=*FrI?w(@XQ@yIdLA(5ZV z7s?$uBM}b-^rsK@CA}ONdJ3e(e}ys%jrk)t660hMkg?cE&7Ke}xOrjH4ONf#kI!#) z&(B9^SJdEVGrqX|!@
    wmlZQt*~Pa>DX)E<#b3t;Ow%OjE)A;>5?x5l{9f$?<5( zG_?rR>DLG4dJ)c_mWqa+_IT%lI}W-@a|z_G4rkQomu@f+?GnUV=G0L6opQov78`F{ zB8U838W!rc?=z;Lt=Zp;Eu}w>e-J*I>@L$nxAl0x&-Oh?J)of;l}!JOdgXOpg|u)5rhx|=4~1APx1LSp}dhjm1` zc;s5y9;C)s<*kK?XlA)Stn)6Hc6GV>J0jL<6R8~&#qf}}9acg`?rI=G37=A;i;9WPsfI7?zh_PsC4ksAWs&Pf>oGzCBQ%2*84R5j zpBd3g{SvDF;7DkaJ|J)h&yY=M| zYzwZe??3Ph8r@?PvBNx)l!EBO%nxjh7V}{p1w3#_O+pq;yJiBBBVR{$y`!WMSGDA$ zi}I~k9cTA=xf|N@Tf)ketn{P*^mAG!!@vYIyWAO;rdu!%#%zVj?t^*_)`Nkc9u@v}Fo;Cysik*-)X z!arRf8`k0$b%!?e5Onpeh9aX8tGqkAy+3yKI=;oPCXy#FV+9WxH6Nkuos9soUCgCp zPWkKyZ83O!@L*-;J^W<+>P6m(XP9bjh0|-Ul0xT#C<9xjG$I@pqr4f1_J(^coPDAQ zW2*!U+j*&WPV;m z29kLW7j2SFCDMq7O-$|@M{fx*?P zMVIvaNnT2R`;mri@hM$JPmjU!7%sSJdjQ`^+c`>D-@HD|?2)X(dt}t`y;w5BXxm0& zirEm_yo+REQA~Lb!(BUeVn;hiHcbz;<^Y z8XQt8UDJojL0Yp+Gx}<9weMu!Cp+~y4atQ`sLv6RmD+T6J~yM`wRj&CG?p16UMi{T zKnj5|O)$Ksw2lhJj=)KA`D|b&j{kMO!LXLdu$qVp;>uTw952(wclb4`UiH_CZ9NXT zskFEqxlS{MujM-3)gXu zY@(sIIxHr^a)j{cT5Qv>rNS@DSbzm~SWdNqTSAI#isq5lCwZv+7GoKZM04)kTqLD#+B`ENt(c z>BPa=7gwOnt{WK&Ilz92C&ub7&8%O9Nu3o<=^lMFu^FX)R@^Gbnc{f-=YH3nzB^DH z4*|rc!Q|x7-G-WoqnAg{Sq0Nkfyv6?!P*YuICwdp;Pc$KmUT)f$c4r5o7v@0TEw#V zM0Y;DFgHI8+&`mzdN{7X&szz@FyC-o8--L>aLk_xA;+A~bmAj++|A2$Xx{YfeUvyj zl(_vhxg|dS&H8=5%(|l)RzqrYp8|2f_lBvnAA1`{yu_K~^4rdrk*>tR=EoC03%()N z0|<~iyG{zLIXm=45$mcd7g|0cVi0NLr4$BUDtnw&^h6WedlZ|(84c^K5hsxam0{z4 z)%F+bB}ky4R;T5)V(RiUt}c5Qg5ZV!plq!UYk{!d_VIvOJ1fAH z{5iqD`iQ)1HD1uX`bh&>v&A$&L;-`Q0)F_&YiI@a9~Tux#JlWM#VU!0h}JZeA-Es8_kZ3)hZ}tTKl{GS!_C2(POV@ceIA)zh4A`B)B+GQX0 z1@6pxQeA~Pb-XAvSrBs>WIAYX+3l<%wd)j!Na0etZTpW%DUAGOFS9CY9;b`vX>+PO z-8Sj={M3J~G=#~!x^5_hX0xx&Gbzsn13vdDM9J8_t#tRWTkOYtfjyyLMA*4?)j7K->JWdHQ+G=D#JGd%1H2pwj<>YH zS&N=)b3jBo$EtcVx?te^P;y#=Kj`wl{!qyUc2AYR!rf$qN@H z%6KCQyW4mx=3(-Xo6TXIkDWWw)>Snw73|bTBmI3+L0aXNnW#coZzX?)#(H@J>l&#$ zqjJYXbHnQlJ{MZSh45%=LQd7*m77`OP|Vtn$-Q<<(#w?|H{94KgwZjVpK|h7x#QP5 zS-%&UcHg16?sd|-x_ID7NGc!;IGi$lH}ANF`y7g1**3c_<8F`Fu}^#J9}$KrtKfM3 z^oSurJfgHDH4K`Dj6BrkwQ3$e?~{w_Iqm;48cMUP=)BV1Y8}vB98%dE)o7CpJI>BZ z9O~~IAYDE4RvDvKBY4rG3#2cjAD-s+gscw@-NOk;t0*I}XLyk%jtq3%u*k;x{N}&& zM$ncI0C^E-vHs*ZJzcs0j`qYmEf|Bf8KOJOJr%X7YKel$Os5y6UG;zWioBiSmX!-( zBL?44im%fn>kIiwd2?=(x@OM97Vn>KXkjs{-wq8cPhrVC`e zrV0vDMhc8gdRmK{Ag%pGVG~?50vGYE6=T`MZzKJcW+8@Q7O%G|u2(y9cs65_gI~pd zNarL{Q9pa(z|4`x=;An1gbL+(D)a5w*2(uXBYs_LBFDLiL;FN8?~6+fgtlc~iniY; zqZe2dJ=#7m(|ov8CGRyESpTFIEU%{x+%y`MTG-H*=Z*g?xEdtk=)Xjvl9c zW&Ycf${5KN&CqQA;w8o(RzA=$DV4h1>C~g^jM7EJ7SlpLTqAU zf{cM7t)sJ$InB$QI4&K+G^qWHw|ML|wZ&UeT(fKjh5AC;L)SeVSX zH~KB*)$M&@VWIE%4w=0!(y6O3BNLM!V|d@-V4!-DNd)m)orf?*Bq<+eJYD;aV|H;d z`iBo6z`Zsw!Lrw|(Mp7&ySv-dOg%=bQw6&NY9**j{CA8e$9)LtGpK+kC@zLD8P2_4Jp!MORwC;`1 zgPaN;KN;rv`8kNx;BJ_LKT1kUTrX$M?C!4Zyc4;N^%*dkyXLlUv8zOPe3`_8VRBD ztnmqXiw&PVv>CDcl!U2vK1%;?jqv&`<8e?476(Vyqg&p}ikV&^*>`PiEmMCjJUg=t zqz&{6zMZQtjE#*)_Y~8G!x|a{6_VLu5Cg=$bmHj(0|VQvYl|M~mC_^4(%lf*nvP*l zPfw3)Tkk(AE1^U1@bKE+bN*%6t}xtkr@g668af&p*!ueVnMyM(3row8h4h*l-u;FL*f=(~J7QlF@s={+w zbRq;pQCUq5@4NwgR<~%a@RfTf+XHWNI4#2Cupa5C=?qgbl^^HaQ$vGL^x@ig@GB46 zmoHy5%M4&J$@sC=@KF4H-Oe`KH|(=AGY$H#1l-RVU%q-(?zr(NW)whx3BE`^)*0l>jWG`~$$kFVEbjJw0}{~E8FnnaF&de@=f5^dvaIl(B_EQi&p#UmO40b;h6YZ_jg zrQ(*Uy$hp(L>6%oAy5p1PSbRcLxE!bRtlFTH-?szD4Vt&$2A7AKVjNb{S}eZ`aa~P zEjQ1s8xMGe@6X4tK_^58AYrYAh}}^O3JHxgz7D}8@0f0VaN_3UTaS~aXircQ4I3R* z7C!01ovHdTj!z0FDJ2E3)6?h#p`xaS`S$G_BQtYXs(=F(GVJ%FBE!mAY<&D6`2>2y z@%-23Ha4<4I%H&+NIwS#;?mMEiY5h%uSmE|(ZPHe9UX;eB~r^j5vIVZv0e-h!(}k) z2t`}nAVSpjm3uCyF4=MHsFm2pP_?E$>DLipGji?j8}Ji*a-Zn z-K>i{7_aIj+If0CU%AXM9R_^Ub#!u3Y zJdvJ0eJUp}?>D|93@U-}yw(e$2xtU_w{fAN=4w}|fx*Ev&!3~^<>lE5rp1~N z%SMxlo0`%y6QDu;!1&I@D~{K%Ul*2?bbn$}mGR_L(9lQ{Jfu@rW7evW5^>vg6a=k3 zPlYocA0Lm)$e`qQHktmR3$g7+>=;fH;xqS*QY?T*15eRq1dpfj@$vrQh>$W(=CWC< zU0!5=kVORi`t|05Q!%rbiI?}%e~%Cc$B#)hzisQRebu(@=t?r44!m?G1fSsGM15V8 zDw;II5KynvRPdiA?-AvHDi z^{=Fsz$j8aqyG4((3yL3*m#s(QgV>3cjPE|^6M3w;lte@%_?&osJ}_lbN?`!rVehG z)4~tqd$QgO2LZ!uY-R>IrZ?czC%lWKTVO+FZS8R2^Y91>u^NJ|jV7n3b82b`n3$Nr zLMkmSZKm0SZ*6^jY+)f1%&MYCFdA{l$wjsg$;7c^Q&J+J?sBn_@Wo^D=Z+4E!4y8W zLYH-mN~>AUCg6x%59_zENl3!Mv!L)TdvZO135n?zqUy^$;JO~gS7tfQTC7!xh=fG} z9Y;S}AKX39$7JuiuyMxlU1rS)A|fI>>+IH*-@NgUj>gQ*&4tIO1dj$LNAFmUtctpN zu+UMH!;G}=z(z-kO-mSuagV`V)dz?#=)+Hmi4ut$XNo`6m6d(Z&mAv(3i9)5fDaLJ z-fzp6jwo~5Q_n3Z(6^=9p9EpUc;{E1W`iRWm{Ln_TjY0tMtpjj+|FX-;y8X=y1Tn8 zgR3+iwUExv&hD;*IMhb&vfx*{?46Q9LPOKg;I3G#{yhJ6N-*d>BQXC0Hrc|$!zEl@ z`Imeiy{c+!_0L(lV1S>3IuU448kNMN78TVaM@~skj~+_l%K`p=v^7o0#b_*BI^b{^ z1wE4G*)s`X7F0B}a@*AoL##k@{u z8~+ubd>`J0r+odYtg9?UI@oNw?C?ezWZmVu1 z@m-nQnW^yEAQyDDLp%ksop&d`ZQXgWf`~n>>p~8mB7}@6<^ zH=vVxgUv_$?OS}Pl|UMx4+0d_;ceL~!;PPn>bL5#blu$Cl$i_=$i)Y4Z*OOMzJ84{ zH#Y}PMys5S>`!1Y1|F~Q`}a3o7#JAhXPF?u(`C~5jnxBh%>>+ZKsc5-_5@6kmX_95 zQ&8QHADEASG9HP~XJ*Qc?Uuc+RyR{@)Q<#F&;y<7bu^n?Puz}fzVKKQ7#SObAg>M$ zA%ba&EbIheazVe@4ic`oPoKDp)3ZxGH=b)&Ti~~x=dpd;`?GlDO-K;&)Lf!r`_}8J`@8TjEH9CJobS~O?-;BFZ)g~Jw%qhyRAMajTL zbaTFsQ3m1qy;kt773Q-;V9k{acSClfAG_`C|D&0hcS#+>{+EvOzsjHgmSg@-xBr%7 z{#I%JPQ(9FY5rDk{#I%J^YoiLxuJr&k-LH?*JAJwVjz5snY{)>A$<8L1pH((0-xdC zs*eGmK5kL1{7ESy(P0C`6Nf>LUNY$0La2lPzy=toDsX;;H=d#wJ`vf-Q8Ktyqc5mC z|2hNu<|5$ms|}T2IoG^eJ2bnHfH|A-JDLif^nJmY`NU6IZ1~M&<7ffsTm7qH`D{js zM3d@QCMyYWXi1fg`opZ+|MRiHCabI>s$-U`Fa@$dw&QC??8`r%qdSfe5IiRrX8+?f z9)>WZ$Hgx9X3;__Vt#&JTXJMy_aSqGX@$(`pucVfeLH;Pu+}!f2gi1B{g)?a49`~Q zgKN}OzG^l$_{SD9o|{eE#xx?hAa}ZN)KjZgDt6ID`ns za0?}1L$kkI1x{?F5m1Sz1K~(35v=m4<=>2c6!mVU)GO7{4P_p
    System/AllowBuildPreview